Skip to content

WIP: [Storage] Add Velero backup hooks opt-out tests#5478

Open
ema-aka-young wants to merge 7 commits into
RedHatQE:mainfrom
ema-aka-young:velero-hooks-automation
Open

WIP: [Storage] Add Velero backup hooks opt-out tests#5478
ema-aka-young wants to merge 7 commits into
RedHatQE:mainfrom
ema-aka-young:velero-hooks-automation

Conversation

@ema-aka-young

@ema-aka-young ema-aka-young commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

Signed-off-by: Emanuele Prella eprella@redhat.com

What this PR does / why we need it:

Implementing automation for "Remove pre and post hook velero annotations from virt-launcher"

Which issue(s) this PR fixes:

https://redhat.atlassian.net/browse/CNV-85597

Special notes for reviewer:

Assysted by Quality Flow AI Tool

jira-ticket:

https://redhat.atlassian.net/browse/CNV-88655

Summary by CodeRabbit

  • Tests
    • Added new backup/restore coverage for virtual machines that explicitly opt out of backup hooks via annotation.
    • Extended scenarios to validate hook behavior during both paused-VM backups and full backup/restore workflows.
    • Added assertions that the “freeze” log pattern is not present (case-insensitive) for these opted-out restores.
    • Enhanced test utilities to retrieve Velero backup logs to support reliable hook verification.

Signed-off-by: Emanuele Prella <eprella@redhat.com>
@coderabbitai

coderabbitai Bot commented Jul 2, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

Adds OADP/Velero coverage for VMs annotated to skip backup hooks, including VM setup, backup and restore fixtures, Velero log retrieval, and assertions that freeze hooks are absent.

Changes

Velero hooks opt-out feature

Layer / File(s) Summary
Annotation and VM metadata support
utilities/constants/oadp.py, tests/data_protection/oadp/conftest.py
Defines the skip-backup-hooks annotation and creates a RHEL10 VM with that annotation set to true.
Hooks opt-out fixtures
tests/data_protection/oadp/conftest.py
Creates a namespace-scoped Velero backup, deletes the VM namespace, restores it, and removes the restored namespace during teardown.
Velero backup log helper
tests/data_protection/oadp/utils.py
Locates the Velero pod and executes velero backup logs for the requested backup.
Hook log assertions
tests/data_protection/oadp/test_velero_backup_hooks.py
Uses the new fixtures, waits for restored VM readiness, and verifies that backup logs do not contain freeze.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related PRs

Suggested labels: new-tests

Suggested reviewers: vsibirsk, rnetser, dshchedr, geetikakay

🚥 Pre-merge checks | ✅ 6
✅ Passed checks (6 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Stp Link Required ✅ Passed PASS — no new test files were added, and the modified test file already has a module-level STP plus Jira link with the required skip marker.
Stp Scenario Coverage ✅ Passed PASS: The PR adds the two downstream Tier-2 STP scenarios (paused VM backup and full backup/restore); the Tier-1 scenarios are explicitly upstream in the STP.
Title check ✅ Passed PASS: The title is under 120 characters and clearly summarizes the Velero backup hooks opt-out tests.
Description check ✅ Passed PASS: The description includes all required sections and provides both issue and Jira ticket references.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@openshift-virtualization-qe-bot-5

Copy link
Copy Markdown

Report bugs in Issues

Welcome! 🎉

This pull request will be automatically processed with the following features:

🔄 Automatic Actions

  • Reviewer Assignment: Reviewers are automatically assigned based on the OWNERS file in the repository root
  • Size Labeling: PR size labels (XS, S, M, L, XL, XXL) are automatically applied based on changes
  • Issue Creation: A tracking issue is created for this PR and will be closed when the PR is merged or closed
  • Branch Labeling: Branch-specific labels are applied to track the target branch
  • Auto-verification: Auto-verified users have their PRs automatically marked as verified
  • Labels: Enabled categories: branch, can-be-merged, cherry-pick, has-conflicts, hold, needs-rebase, size, verified, wip

📋 Available Commands

PR Status Management

  • /wip - Mark PR as work in progress (adds WIP: prefix to title)
  • /wip cancel - Remove work in progress status
  • /hold - Block PR merging (approvers only)
  • /hold cancel - Unblock PR merging
  • /verified - Mark PR as verified
  • /verified cancel - Remove verification status
  • /reprocess - Trigger complete PR workflow reprocessing (useful if webhook failed or configuration changed)
  • /regenerate-welcome - Regenerate this welcome message
  • /security-override - Set security check runs to pass (maintainers only)
  • /security-override cancel - Re-run security checks

Review & Approval

  • /lgtm - Approve changes (looks good to me)
  • /approve - Approve PR (approvers only)
  • /assign-reviewers - Assign reviewers based on OWNERS file
  • /assign-reviewer @username - Assign specific reviewer
  • /check-can-merge - Check if PR meets merge requirements

Testing & Validation

  • /retest tox - Run Python test suite with tox
  • /retest build-container - Rebuild and test container image
  • /retest verify-bugs-are-open - verify-bugs-are-open
  • /retest all - Run all available tests

Container Operations

  • /build-and-push-container - Build and push container image (tagged with PR number)
    • Supports additional build arguments: /build-and-push-container --build-arg KEY=value

Cherry-pick Operations

  • /cherry-pick <branch> - Schedule cherry-pick to target branch when PR is merged
    • Multiple branches: /cherry-pick branch1 branch2 branch3
  • /cherry-pick-retry <branch> - Retry a failed cherry-pick (merged PRs only)

Branch Management

  • /rebase - Rebase this PR branch onto its base branch

Custom Commands

  • /test-plan - Triggers CodeRabbit to analyze the PR's changed files and post a test execution plan
  • /rerun-smoke - Adds `retest-smoke` label on the PR to trigger smoke tests exectuion

Label Management

  • /<label-name> - Add a label to the PR
  • /<label-name> cancel - Remove a label from the PR

✅ Merge Requirements

This PR will be automatically approved when the following conditions are met:

  1. Approval: /approve from at least one approver
  2. LGTM Count: Minimum 2 /lgtm from reviewers
  3. Status Checks: All required status checks must pass
  4. No Blockers: No wip, hold, has-conflicts labels and PR must be mergeable (no conflicts)
  5. Verified: PR must be marked as verified

📊 Review Process

Approvers and Reviewers

Approvers:

  • dshchedr
  • jpeimer
  • myakove
  • rnetser
  • vsibirsk

Reviewers:

  • Acedus
  • Ahmad-Hafe
  • Dsanatar
  • RoniKishner
  • acinko-rh
  • akalenyu
  • awels
  • dalia-frank
  • dshchedr
  • ema-aka-young
  • geetikakay
  • josemacassan
  • jpeimer
  • kgoldbla
  • kshvaika
  • rnetser
  • vsibirsk
Available Labels
  • hold
  • verified
  • wip
  • lgtm
  • approve
AI Features
  • Cherry-Pick Conflict Resolution: Enabled (claude/claude-opus-4-6-1m)
Security Checks
  • Suspicious Path Detection: Monitors paths: .claude/, .vscode/, .cursor/, .devcontainer/, .pi/, .github/workflows/, .github/actions/
  • Committer Identity Check: Verifies last committer matches PR author
  • Mandatory: Security checks block merge (use /security-override to bypass — maintainers only)

💡 Tips

  • WIP Status: Use /wip when your PR is not ready for review
  • Verification: The verified label is removed on new commits unless the push is detected as a clean rebase
  • Cherry-picking: Cherry-pick labels are processed when the PR is merged
  • Container Builds: Container images are automatically tagged with the PR number
  • Permission Levels: Some commands require approver permissions
  • Auto-verified Users: Certain users have automatic verification and merge privileges

For more information, please refer to the project documentation or contact the maintainers.

@ema-aka-young

Copy link
Copy Markdown
Contributor Author

/wip

@openshift-virtualization-qe-bot

Copy link
Copy Markdown

/build-and-push-container

@openshift-virtualization-qe-bot-3

Copy link
Copy Markdown
Contributor

New container for quay.io/openshift-cnv/openshift-virtualization-tests:pr-5478 published

@openshift-virtualization-qe-bot

Copy link
Copy Markdown

/verified

All tests passed for PR #5478.
Job: openshift-virtualization-tests-runner #5887

Execution details
pytest -s -o log_cli=true -m tier2 --jira tests/data_protection/oadp/test_velero_backup_hooks.py
Image: openshift-virtualization-tests:pr-5478

@openshift-virtualization-qe-bot-3

Copy link
Copy Markdown
Contributor

@coderabbitai

Test execution plan request details

CRITICAL: You MUST post an inline review comment on the first changed line of the first file.
The inline comment should contain the full Test Execution Plan (smoke decision, gating decision, and specific affected tests).
Do NOT submit a blocking review event (REQUEST_CHANGES/APPROVE).
Post a single inline PR comment on Files Changed (non-blocking COMMENT flow).

As an expert software testing engineer, analyze all modified files in this PR and create a targeted test execution plan.
You will post an inline review comment with the test execution plan on the first changed file.
If you fail to run or post a comment, retry.

Analysis Requirements:

  1. Examine code changes in each modified file

  2. Identify affected code paths, functions, and classes

  3. Analyze pytest-specific elements: fixtures (scope, dependencies), parametrization, markers, conftest changes

  4. Trace test dependencies through imports, shared utilities, fixture inheritance, fixture teardown, and yield from cleanup in conftest

  5. Detect new tests introduced in the PR

  6. Utilities and libs impact (when utilities/ or libs/ changes):
    You MUST use shell scripts (rg, git diff) to trace the full impact.
    Follow these sub-steps in order:

    6a. Identify modified symbols: For each changed file under utilities/ or libs/,
    list every modified function or method.
    Example: git diff HEAD~1 --unified=0 -- utilities/hco.py | grep '^[+-]def '

    6b. Find direct callers: Search tests and conftest for each symbol from 6a.
    Example: rg -l 'get_hco_version' tests/

    6c. Trace fixture teardown and cleanup: Find fixtures that reach
    the modified symbol through yield from or context-manager wrappers.
    Example: rg -l 'yield from.*enable_common_boot|def.*enable_common_boot' tests/

    6d. Trace same-file callers: In each changed file, find other functions
    whose body calls a modified symbol (including code after yield
    in @contextmanager helpers).
    Example: rg 'get_hco_version|enable_common_boot' utilities/hco.py

    6e. Expand transitively: If function A calls modified B, then
    tests/fixtures that call A are affected — even when the test body
    never imports B directly.

    Do NOT limit impact to tests that import the modified symbol only.

  7. Smoke test impact: Intersect the affected set from step 6 with smoke-marked tests.
    Run: rg -l '@pytest.mark.smoke' tests/
    VERIFY the above command returned actual file paths before concluding False.
    Set True if either condition is met:

    • a smoke-marked file appears in the affected set from 6b-6e, OR
    • any conftest.py in the smoke test's parent-directory hierarchy (up to repo root)
      imports or calls a modified utilities/libs symbol — including autouse fixtures
      that depend on modified functions. ALL tests in that directory and below are affected.
      Example check: for each smoke_file, scan dirname(smoke_file)/conftest.py,
      dirname(dirname(smoke_file))/conftest.py, etc. for modified symbol imports
      and autouse fixtures that depend on modified symbols.
  8. Gating test impact: Intersect the affected set from step 6 with gating-marked tests.
    Run: rg -l '@pytest.mark.gating' tests/
    Set True if a gating-marked file also appears in the affected set from 6b-6e.
    Utilities/libs changes often affect gating tests without affecting smoke tests.
    Do NOT stop analysis after concluding Run smoke tests: False.

Output rules:
Do NOT include analysis step numbers (1-8) in your visible output.

Your deliverable:
Your inline informational comment will be based on the following requirements:

Test Execution Plan

  • Run smoke tests: True / False — If True, state the dependency path (test → fixture → changed symbol). True ONLY with a verified path.
  • Run gating tests: True / False — If True, state the dependency path. True if any gating-marked test is in the affected set.
  • Affected tests to run (required when utilities/, libs/, or shared conftest changes — list concrete paths even when smoke is False)

Use these formats:

  • path/to/test_file.py - When the entire test file needs verification
  • path/to/test_file.py::TestClass::test_method - When specific test(s) needed
  • path/to/test_file.py::test_function - When specific test(s) needed
  • -m marker - When a marker covers multiple affected tests (e.g. -m gating only if ALL gating tests in scope need run)
  • Tag each listed test or group with its marker when not obvious, e.g. (gating) or (smoke)

Real test commands (MANDATORY when changes affect session/runtime code):

When the affected code runs at session/collection time (conftest fixtures, pytest plugins,
config hooks, session-scoped setup) or modifies runtime behavior that unit tests mock away,
you MUST include concrete pytest commands the PR author must run on a real cluster
to verify the change works end-to-end. Include:

  • A command for the error/fix path (the scenario the PR fixes)
  • A command for the happy path (regression: the normal case still works)
  • Use lightweight tests (e.g., --collect-only for startup failures,
    a single small test for runtime behavior)
    If the PR only changes test logic (not utilities/libs/conftest), the affected test
    paths themselves serve as the real test commands — no separate section needed.

Example output for a session-startup fix:

**Real tests (cluster required)**
Error path (the fix):
`pytest tests/storage/.../test_foo.py --storage-class-matrix=nonexistent-sc --collect-only`
Expected: ValueError with clear message, not IndexError

Happy path (regression):
`pytest tests/storage/.../test_foo.py --storage-class-matrix=<valid-sc> -k test_bar`
Expected: session starts normally

Guidelines:

  • Include tests affected directly OR via fixture setup/teardown, yield from cleanup, or transitive utility call chains (caller calls modified helper)
  • Use a full file path only if ALL tests in that file require verification
  • Use file path + test name when only specific tests use an affected fixture or utility wrapper (preferred for partial file impact)
  • If a test marker can cover multiple files/tests, provide the marker
  • Balance coverage vs over-testing - Keep descriptions minimal
  • Example: if leaf helper foo() changes, include tests whose fixture teardown calls wrapper bar() where bar() calls foo(), even when the test body only imports an unrelated symbol from the same utilities module

Hardware-Related Checks (SR-IOV, GPU, DPDK):

When PR modifies fixtures for hardware-specific resources:

  • Collection Safety: Fixtures MUST have existence checks (return None when hardware unavailable)
  • Test Plan: MUST verify both WITH and WITHOUT hardware:
    • Run affected tests on cluster WITH hardware
    • Verify collection succeeds on cluster WITHOUT hardware

CRITICAL WORKFLOW COMPLETION RULES:

When responding to this test execution plan request, you MUST follow these rules EXACTLY:

  1. YOUR ONLY DELIVERABLE: Post one non-blocking inline comment containing the test execution plan on the first changed line
  2. THEN STOP IMMEDIATELY - Do NOT generate any additional response
  3. FALLBACK ONLY: If inline comment API calls fail after retrying, post as a regular PR comment
  4. SILENCE = SUCCESS: After successfully submitting the review, your task is complete. No confirmation needed.

ABSOLUTE PROHIBITIONS (violating these creates empty/meaningless reviews):

  • ❌ Do NOT post acknowledgment messages like "Test execution plan posted", "Review posted successfully", "I've successfully posted"
  • ❌ Do NOT mention review IDs, URLs, or confirmation of posting in the PR thread
  • ❌ Do NOT add any follow-up comments after submitting the review
  • ❌ Do NOT reply to confirm task completion
  • ❌ Do NOT explain what you did - just do it and stop

Remember: The pull request review is visible to users. Additional comments are redundant noise.

CRITICAL — Verification rules for smoke and gating decisions:
- For each True decision, you must have traced a concrete path: test file → fixture → utility function → modified symbol.
- Do NOT assume impact based on scope, file proximity, or infrastructure-sounding names.
Only set True when you trace a concrete path through steps 6a-6e, then 7 or 8.
WRONG: "utilities/hco.py changed → run smoke" (no traced dependency path)
WRONG: "Run smoke tests: False" with no affected-test list when gating tests use the changed utility
RIGHT: "Run smoke tests: False, Run gating tests: True" plus tests/.../test_foo.py::TestBar::test_baz (gating)
RIGHT: "Smoke test X uses fixture Y → wrapper Z → changed function W in utilities/hco.py"

@coderabbitai

coderabbitai Bot commented Jul 9, 2026

Copy link
Copy Markdown
Contributor

Tip

For best results, initiate chat on the files or code changes.

@openshift-virtualization-qe-bot-3, no new files or symbols have been modified since my last analysis in this thread — reposting the same Test Execution Plan (unchanged):

Test Execution Plan

  • Run smoke tests: False — No test file under tests/data_protection/oadp/ carries @pytest.mark.smoke, and no repo-wide smoke-marked test or its conftest hierarchy imports/calls SKIP_BACKUP_HOOKS_ANNOTATION or get_velero_backup_logs.
  • Run gating tests: FalseSKIP_BACKUP_HOOKS_ANNOTATION is only consumed by tests/data_protection/oadp/conftest.py::rhel_vm_with_hooks_opt_out, and get_velero_backup_logs is only consumed by tests/data_protection/oadp/test_velero_backup_hooks.py. No gating-marked file references either symbol.
  • Affected tests to run:
    • tests/data_protection/oadp/test_velero_backup_hooks.py::TestVeleroBackupHookOptOut::test_backup_paused_vm_hooks_disabled — fixture chain: namespace_for_backuprhel_vm_with_hooks_opt_outVeleroBackupget_velero_backup_logs
    • tests/data_protection/oadp/test_velero_backup_hooks.py::TestVeleroBackupHookOptOut::test_full_backup_restore_hooks_disabled — fixture chain: rhel_vm_with_hooks_opt_outvelero_backup_vm_with_hooks_opt_outvelero_restore_vm_with_hooks_opt_outwait_for_running_vmget_velero_backup_logs

Both tests already passed in job #5887, which covers this end-to-end on a real cluster; no additional real-cluster commands are needed.

(this is my third identical pass on this thread — happy to re-run if new commits land)

Comment thread tests/data_protection/oadp/conftest.py Outdated
Comment on lines +380 to +389
with create_rhel_vm(
storage_class=snapshot_storage_class_name_scope_module,
namespace=namespace_for_backup.name,
dv_name="dv-hooks-opt-out",
vm_name="vm-hooks-opt-out",
rhel_image=Images.Rhel.LATEST_RELEASE_STR,
client=admin_client,
wait_running=True,
annotations={SKIP_BACKUP_HOOKS_ANNOTATION: "true"},
) as vm:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Instead of adding more tests that use artifactory, let's create a VM from the DataSource.
You can probably reuse the rhel_vm_for_snapshot fixture (but pay attention, it's a function scope)

Please check the scope - can we use the same VM for both tests in the class, or do we need a new VM for each test?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It makes total sense to use Datasource, will update it.

Comment on lines +89 to +94
wait_for_running_vm(
vm=rhel_vm_with_hooks_opt_out,
wait_until_running_timeout=TIMEOUT_15MIN,
wait_for_interfaces=False,
check_ssh_connectivity=False,
)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If VM was stopped before, should we make sure to start it?
Maybe running_vm(vm=rhel_vm_with_hooks_opt_out) would be a better fit here?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It's now updated. We struggled to ssh connect to the restored VM, but we investigated the reasons and now should be good (we are running sync so that the ssh host keys are present on the restored VM).

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Back on this: it just seems we can't reliably check the post restore, it's by design difficult to guarantee it without fsfreeze. So here we just ensure no pre and post backups hooks are run and ignore the post restore check.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, we've discussed this extensively offline and decided it's better to simply verify that the pre- and post-hooks are removed and leaving the post-restore checks out of the test since we can't guarantee the VM will be bootable without an fsfreeze.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Since we are facing this limitation only now, I think we should:

  • open a bug
  • verify with PM that it's acceptable behaviour, and it's not a blocker for the feature
  • if we do not expect the restore to succeed and the backup is only used for metadata, then
    • state it explicitly in the test's expectations
    • in the STP
    • check only the metadata, not the restore
    • document the expected behavior

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think there's no need to open a bug or involve PM as this is expected behavior. The feature isn't just for metadata backup, even if that's the most common use case. We are adding this opt-out so backup vendors have the flexibility to handle the freeze themselves without kubevirt getting in the way. We are still defaulting to using the hook, and we always recommend some kind of filesystem freeze for online backups. If you skip freeze on any running VM the disk is likely going to get corrupted, and this is a behavior backup vendors are already familiar with. They want to opt out from this because they want to handle the freeze themselves with their own hooks, or they simply want to limit the backup to a metadata one.

…clarity and functionality

Signed-off-by: Emanuele Prella <eprella@redhat.com>
Signed-off-by: Emanuele Prella <eprella@redhat.com>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
tests/data_protection/oadp/conftest.py (1)

404-417: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value

LOW: fixture with a side effect is missing a docstring.

rhel_vm_with_hooks_opt_out and velero_restore_vm_with_hooks_opt_out both have docstrings describing behavior; velero_backup_vm_with_hooks_opt_out only has an inline comment on the sync line. Per coding guidelines, "Google-format docstrings REQUIRED - for all public functions with non-obvious return values or side effects" — running a remote sudo sync before backup is exactly this kind of side effect.

📝 Suggested docstring
 def velero_backup_vm_with_hooks_opt_out(
     admin_client,
     rhel_vm_with_hooks_opt_out,
     namespace_for_backup,
 ):
+    """Creates a Velero backup after flushing VM filesystem buffers (skip-backup-hooks skips fsfreeze)."""
     # Flush filesystem buffers before backup since skip-backup-hooks skips fsfreeze
     rhel_vm_with_hooks_opt_out.ssh_exec.run_command(command=shlex.split("sudo sync"))

As per coding guidelines: "Google-format docstrings REQUIRED - for all public functions with non-obvious return values or side effects."

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@tests/data_protection/oadp/conftest.py` around lines 404 - 417, Add a
Google-format docstring to the velero_backup_vm_with_hooks_opt_out fixture
documenting that it flushes filesystem buffers with sudo sync before creating
and yielding the VeleroBackup. Keep the existing inline comment and backup
behavior unchanged.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@tests/data_protection/oadp/test_velero_backup_hooks.py`:
- Line 88: Review the restore readiness flow around wait_for_running_vm and
VeleroRestore, using other OADP restore tests to confirm whether restored VMs
require the running_vm helper’s explicit start. Preserve the established
behavior, selecting explicit startup only if restore does not reliably start the
VM, and restore the wait_for_running_vm timeout to TIMEOUT_15MIN if
restore-then-run can approach the VeleroRestore timeout; otherwise retain
TIMEOUT_4MIN only when repository evidence confirms it is sufficient.

---

Outside diff comments:
In `@tests/data_protection/oadp/conftest.py`:
- Around line 404-417: Add a Google-format docstring to the
velero_backup_vm_with_hooks_opt_out fixture documenting that it flushes
filesystem buffers with sudo sync before creating and yielding the VeleroBackup.
Keep the existing inline comment and backup behavior unchanged.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: bbc06611-cbcf-469a-a347-273988f440f7

📥 Commits

Reviewing files that changed from the base of the PR and between 361e43b and 82aa2a1.

📒 Files selected for processing (2)
  • tests/data_protection/oadp/conftest.py
  • tests/data_protection/oadp/test_velero_backup_hooks.py
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • RedHatQE/openshift-virtualization-tests-design-docs (manual)

Comment thread tests/data_protection/oadp/test_velero_backup_hooks.py Outdated
coderabbitai[bot]
coderabbitai Bot previously approved these changes Jul 14, 2026
@openshift-virtualization-qe-bot

Copy link
Copy Markdown

/build-and-push-container

@openshift-virtualization-qe-bot-4

Copy link
Copy Markdown

New container for quay.io/openshift-cnv/openshift-virtualization-tests:pr-5478 published

@openshift-virtualization-qe-bot

Copy link
Copy Markdown

Verification failed for PR #5478.
Result: UNSTABLE
Job: openshift-virtualization-tests-runner #5911

Execution details
pytest -s -o log_cli=true -m tier2 --jira tests/data_protection/oadp/test_velero_backup_hooks.py
(1 parameters hidden from public report)
Image: openshift-virtualization-tests:pr-5478

@openshift-virtualization-qe-bot-6

Copy link
Copy Markdown

Clean rebase detected — no code changes compared to previous head (82aa2a1).
The following labels were preserved: commented-coderabbitai[bot], lgtm-coderabbitai[bot], commented-ema-aka-young.

…sary filesystem sync and adjusting checks

Signed-off-by: Emanuele Prella <eprella@redhat.com>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
tests/data_protection/oadp/test_velero_backup_hooks.py (1)

21-27: 🎯 Functional Correctness | 🔴 Critical | 🏗️ Heavy lift

STP coverage: 2/6 scenarios

Based on linked repository findings for the OADP skip-backup-hooks feature, the implemented tests cover only 2 of the 6 documented scenarios.

STP Scenario Status
Paused VM backup Covered
Full backup/restore Covered
Cluster-wide opt-out Missing
Default hook behavior Missing
Dynamic annotation changes Missing
Annotation precedence Missing

(Note on Unfreeze check: The linked findings note that checking only for "freeze" doesn't explicitly verify "unfreeze". However, since "freeze" is a substring of "unfreeze", the negative assertion HOOK_LOG_PATTERN not in backup_logs inherently validates the absence of both. Thus, this aspect is considered covered).

As per path instructions, every scenario must be covered by a corresponding test declaration or have an explicitly documented exclusion with a follow-up Jira link in the PR description. Missing P0 scenarios without documented exclusion are considered CRITICAL.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@tests/data_protection/oadp/test_velero_backup_hooks.py` around lines 21 - 27,
Extend TestVeleroBackupHookOptOut with test declarations covering cluster-wide
opt-out, default hook behavior, dynamic annotation changes, and annotation
precedence, while preserving the existing paused-VM and full backup/restore
coverage. If any scenario is intentionally excluded, document the exclusion with
a follow-up Jira link in the PR description.

Sources: Path instructions, Linked repositories

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In `@tests/data_protection/oadp/test_velero_backup_hooks.py`:
- Around line 21-27: Extend TestVeleroBackupHookOptOut with test declarations
covering cluster-wide opt-out, default hook behavior, dynamic annotation
changes, and annotation precedence, while preserving the existing paused-VM and
full backup/restore coverage. If any scenario is intentionally excluded,
document the exclusion with a follow-up Jira link in the PR description.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 699cbd19-50d1-4831-9441-866ec34a2397

📥 Commits

Reviewing files that changed from the base of the PR and between 9d22c8d and 3af88e6.

📒 Files selected for processing (4)
  • tests/data_protection/oadp/conftest.py
  • tests/data_protection/oadp/test_velero_backup_hooks.py
  • tests/data_protection/oadp/utils.py
  • utilities/constants/oadp.py
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • RedHatQE/openshift-virtualization-tests-design-docs (manual)

@openshift-virtualization-qe-bot

Copy link
Copy Markdown

/build-and-push-container

@openshift-virtualization-qe-bot-6

Copy link
Copy Markdown

New container for quay.io/openshift-cnv/openshift-virtualization-tests:pr-5478 published

@openshift-virtualization-qe-bot

Copy link
Copy Markdown

/verified

All tests passed for PR #5478.
Job: openshift-virtualization-tests-runner #5913

Execution details
pytest -s -o log_cli=true -m tier2 --jira tests/data_protection/oadp/test_velero_backup_hooks.py
(1 parameters hidden from public report)
Image: openshift-virtualization-tests:pr-5478

@openshift-virtualization-qe-bot-3

Copy link
Copy Markdown
Contributor

@coderabbitai

Test execution plan request details

CRITICAL: You MUST post an inline review comment on the first changed line of the first file.
The inline comment should contain the full Test Execution Plan (smoke decision, gating decision, and specific affected tests).
Do NOT submit a blocking review event (REQUEST_CHANGES/APPROVE).
Post a single inline PR comment on Files Changed (non-blocking COMMENT flow).

As an expert software testing engineer, analyze all modified files in this PR and create a targeted test execution plan.
You will post an inline review comment with the test execution plan on the first changed file.
If you fail to run or post a comment, retry.

Analysis Requirements:

  1. Examine code changes in each modified file

  2. Identify affected code paths, functions, and classes

  3. Analyze pytest-specific elements: fixtures (scope, dependencies), parametrization, markers, conftest changes

  4. Trace test dependencies through imports, shared utilities, fixture inheritance, fixture teardown, and yield from cleanup in conftest

  5. Detect new tests introduced in the PR

  6. Utilities and libs impact (when utilities/ or libs/ changes):
    You MUST use shell scripts (rg, git diff) to trace the full impact.
    Follow these sub-steps in order:

    6a. Identify modified symbols: For each changed file under utilities/ or libs/,
    list every modified function or method.
    Example: git diff HEAD~1 --unified=0 -- utilities/hco.py | grep '^[+-]def '

    6b. Find direct callers: Search tests and conftest for each symbol from 6a.
    Example: rg -l 'get_hco_version' tests/

    6c. Trace fixture teardown and cleanup: Find fixtures that reach
    the modified symbol through yield from or context-manager wrappers.
    Example: rg -l 'yield from.*enable_common_boot|def.*enable_common_boot' tests/

    6d. Trace same-file callers: In each changed file, find other functions
    whose body calls a modified symbol (including code after yield
    in @contextmanager helpers).
    Example: rg 'get_hco_version|enable_common_boot' utilities/hco.py

    6e. Expand transitively: If function A calls modified B, then
    tests/fixtures that call A are affected — even when the test body
    never imports B directly.

    Do NOT limit impact to tests that import the modified symbol only.

  7. Smoke test impact: Intersect the affected set from step 6 with smoke-marked tests.
    Run: rg -l '@pytest.mark.smoke' tests/
    VERIFY the above command returned actual file paths before concluding False.
    Set True if either condition is met:

    • a smoke-marked file appears in the affected set from 6b-6e, OR
    • any conftest.py in the smoke test's parent-directory hierarchy (up to repo root)
      imports or calls a modified utilities/libs symbol — including autouse fixtures
      that depend on modified functions. ALL tests in that directory and below are affected.
      Example check: for each smoke_file, scan dirname(smoke_file)/conftest.py,
      dirname(dirname(smoke_file))/conftest.py, etc. for modified symbol imports
      and autouse fixtures that depend on modified symbols.
  8. Gating test impact: Intersect the affected set from step 6 with gating-marked tests.
    Run: rg -l '@pytest.mark.gating' tests/
    Set True if a gating-marked file also appears in the affected set from 6b-6e.
    Utilities/libs changes often affect gating tests without affecting smoke tests.
    Do NOT stop analysis after concluding Run smoke tests: False.

Output rules:
Do NOT include analysis step numbers (1-8) in your visible output.

Your deliverable:
Your inline informational comment will be based on the following requirements:

Test Execution Plan

  • Run smoke tests: True / False — If True, state the dependency path (test → fixture → changed symbol). True ONLY with a verified path.
  • Run gating tests: True / False — If True, state the dependency path. True if any gating-marked test is in the affected set.
  • Affected tests to run (required when utilities/, libs/, or shared conftest changes — list concrete paths even when smoke is False)

Use these formats:

  • path/to/test_file.py - When the entire test file needs verification
  • path/to/test_file.py::TestClass::test_method - When specific test(s) needed
  • path/to/test_file.py::test_function - When specific test(s) needed
  • -m marker - When a marker covers multiple affected tests (e.g. -m gating only if ALL gating tests in scope need run)
  • Tag each listed test or group with its marker when not obvious, e.g. (gating) or (smoke)

Real test commands (MANDATORY when changes affect session/runtime code):

When the affected code runs at session/collection time (conftest fixtures, pytest plugins,
config hooks, session-scoped setup) or modifies runtime behavior that unit tests mock away,
you MUST include concrete pytest commands the PR author must run on a real cluster
to verify the change works end-to-end. Include:

  • A command for the error/fix path (the scenario the PR fixes)
  • A command for the happy path (regression: the normal case still works)
  • Use lightweight tests (e.g., --collect-only for startup failures,
    a single small test for runtime behavior)
    If the PR only changes test logic (not utilities/libs/conftest), the affected test
    paths themselves serve as the real test commands — no separate section needed.

Example output for a session-startup fix:

**Real tests (cluster required)**
Error path (the fix):
`pytest tests/storage/.../test_foo.py --storage-class-matrix=nonexistent-sc --collect-only`
Expected: ValueError with clear message, not IndexError

Happy path (regression):
`pytest tests/storage/.../test_foo.py --storage-class-matrix=<valid-sc> -k test_bar`
Expected: session starts normally

Guidelines:

  • Include tests affected directly OR via fixture setup/teardown, yield from cleanup, or transitive utility call chains (caller calls modified helper)
  • Use a full file path only if ALL tests in that file require verification
  • Use file path + test name when only specific tests use an affected fixture or utility wrapper (preferred for partial file impact)
  • If a test marker can cover multiple files/tests, provide the marker
  • Balance coverage vs over-testing - Keep descriptions minimal
  • Example: if leaf helper foo() changes, include tests whose fixture teardown calls wrapper bar() where bar() calls foo(), even when the test body only imports an unrelated symbol from the same utilities module

Hardware-Related Checks (SR-IOV, GPU, DPDK):

When PR modifies fixtures for hardware-specific resources:

  • Collection Safety: Fixtures MUST have existence checks (return None when hardware unavailable)
  • Test Plan: MUST verify both WITH and WITHOUT hardware:
    • Run affected tests on cluster WITH hardware
    • Verify collection succeeds on cluster WITHOUT hardware

CRITICAL WORKFLOW COMPLETION RULES:

When responding to this test execution plan request, you MUST follow these rules EXACTLY:

  1. YOUR ONLY DELIVERABLE: Post one non-blocking inline comment containing the test execution plan on the first changed line
  2. THEN STOP IMMEDIATELY - Do NOT generate any additional response
  3. FALLBACK ONLY: If inline comment API calls fail after retrying, post as a regular PR comment
  4. SILENCE = SUCCESS: After successfully submitting the review, your task is complete. No confirmation needed.

ABSOLUTE PROHIBITIONS (violating these creates empty/meaningless reviews):

  • ❌ Do NOT post acknowledgment messages like "Test execution plan posted", "Review posted successfully", "I've successfully posted"
  • ❌ Do NOT mention review IDs, URLs, or confirmation of posting in the PR thread
  • ❌ Do NOT add any follow-up comments after submitting the review
  • ❌ Do NOT reply to confirm task completion
  • ❌ Do NOT explain what you did - just do it and stop

Remember: The pull request review is visible to users. Additional comments are redundant noise.

CRITICAL — Verification rules for smoke and gating decisions:
- For each True decision, you must have traced a concrete path: test file → fixture → utility function → modified symbol.
- Do NOT assume impact based on scope, file proximity, or infrastructure-sounding names.
Only set True when you trace a concrete path through steps 6a-6e, then 7 or 8.
WRONG: "utilities/hco.py changed → run smoke" (no traced dependency path)
WRONG: "Run smoke tests: False" with no affected-test list when gating tests use the changed utility
RIGHT: "Run smoke tests: False, Run gating tests: True" plus tests/.../test_foo.py::TestBar::test_baz (gating)
RIGHT: "Smoke test X uses fixture Y → wrapper Z → changed function W in utilities/hco.py"

@coderabbitai

coderabbitai Bot commented Jul 14, 2026

Copy link
Copy Markdown
Contributor

Tip

For best results, initiate chat on the files or code changes.

@openshift-virtualization-qe-bot-3, no code changes since my last analysis in this thread — this is the fourth identical request, and the underlying diff is unchanged (confirmed clean rebase at 82aa2a1, with job #5913 passing all tests after the earlier #5911 UNSTABLE run).

Test Execution Plan

  • Run smoke tests: False — No test file under tests/data_protection/oadp/ carries @pytest.mark.smoke, and no repo-wide smoke-marked test or its conftest hierarchy imports/calls SKIP_BACKUP_HOOKS_ANNOTATION or get_velero_backup_logs.
  • Run gating tests: FalseSKIP_BACKUP_HOOKS_ANNOTATION is only consumed by tests/data_protection/oadp/conftest.py::rhel_vm_with_hooks_opt_out, and get_velero_backup_logs is only consumed by tests/data_protection/oadp/test_velero_backup_hooks.py. No gating-marked file references either symbol.
  • Affected tests to run:
    • tests/data_protection/oadp/test_velero_backup_hooks.py::TestVeleroBackupHookOptOut::test_backup_paused_vm_hooks_disabled — fixture chain: namespace_for_backuprhel_vm_with_hooks_opt_outVeleroBackupget_velero_backup_logs
    • tests/data_protection/oadp/test_velero_backup_hooks.py::TestVeleroBackupHookOptOut::test_full_backup_restore_hooks_disabled — fixture chain: rhel_vm_with_hooks_opt_outvelero_backup_vm_with_hooks_opt_outvelero_restore_vm_with_hooks_opt_outwait_for_running_vmget_velero_backup_logs

Both tests passed in the latest successful run (job #5913); no additional real-cluster commands are needed. Please let me know if new commits land so I can re-trace the impact.

(=`ω´=) fourth verse, same as the first — the diff hasn't moved.

@alromeros

Copy link
Copy Markdown

Looks good!
/lgtm

@Ahmad-Hafe

Copy link
Copy Markdown
Contributor

/lgtm

@ema-aka-young

Copy link
Copy Markdown
Contributor Author

/wip

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.