Repository navigation
CLI: Update Hypeman Go SDK to da50c337d8e3c05c89a07e9b0b25636f1b50e526 - #68
kernel-internal[bot] wants to merge 5 commits into
Conversation
Bumps github.com/kernel/hypeman-go to v0.28.1-0.20260902045311-0872a65a3733, which integrates vendor VFIO vGPUs into the instance lifecycle. The SDK now documents InstanceGPU.MdevUuid as populated on mdev hosts only, and adds InstanceGPU.DevicePath for the sysfs path of an assigned vGPU device. `hypeman ps` gated its GPU column on MdevUuid alone, so an instance with a vendor VFIO vGPU and no profile name rendered as "-". formatGPU now also checks DevicePath. A full enumeration of api.md methods and CLI commands found no other coverage gaps: every SDK method has a CLI command and every param field has a corresponding flag. Co-authored-by: Cursor <cursoragent@cursor.com>
Bumps github.com/kernel/hypeman-go to v0.28.1-0.20260902143136-e6c2b7bc0171, which adds the "swtpm" value to InstanceLogsParamsSource as part of the Windows hypervisor primitives. Teaches `hypeman logs --source` about swtpm and validates the flag up front instead of forwarding an arbitrary string to the API, matching the parseInstanceWaitState / parseSnapshotTargetHypervisor pattern. Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com> # Conflicts: # go.sum
Bumps github.com/kernel/hypeman-go to v0.28.1-0.20261001160305-134587a222ac, which carries the SDK's 2026-09-30 vulnerability remediation. This commit is on main, whereas the branch previously pinned e6c2b7b from the SDK's next branch. The Windows hypervisor primitives generated there are therefore absent, dropping InstanceLogsParamsSourceSwtpm and InstanceGPU.DevicePath. Both values are still specified by the API, so rather than regress `hypeman logs --source swtpm` and the vendor VFIO vGPU column in `hypeman ps`, read them without the generated bindings: the log source is a string-backed enum, and device_path arrives in JSON.ExtraFields. Both can go back to typed access once next lands on main. Co-authored-by: Cursor <cursoragent@cursor.com>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 22e9c31. Configure here.
| github.com/charmbracelet/lipgloss v1.1.0 | ||
| github.com/charmbracelet/x/term v0.2.1 | ||
| github.com/docker/docker v28.5.2+incompatible | ||
| github.com/docker/docker v28.5.3-0.20260325120914-0afb41ce194c+incompatible |
There was a problem hiding this comment.
Insufficient docker dependency pin
Medium Severity
go.mod now pins github.com/docker/docker to a pseudo-version instead of upgrading go-containerregistry. That keeps the old docker client on the graph, so a pin in this range may not include the docker cp fix for GHSA-rg2x-37c3-w2rh.
Triggered by learned rule: Prefer upgrading go-containerregistry over docker/docker replace pins
Reviewed by Cursor Bugbot for commit 22e9c31. Configure here.
Co-authored-by: Cursor <cursoragent@cursor.com>


This PR updates the Hypeman Go SDK dependency to the latest version.
SDK Update
Coverage Analysis
A full enumeration of SDK methods and CLI commands was performed. No coverage gaps were found.
All 63 methods in
api.mdhave a CLI command, and every field of every*Paramsstruct (including nested param types such asIngressRuleParam,HealthCheckParam,VolumeMountParam,AutoStandbyPolicyParam,SnapshotCompressionConfigParam,MemoryReclaimRequestParamandCreatePushRequestParam) maps to an existing flag, positional argument, or mount-spec segment.openapi.yamlmarks no endpoint withx-cli-skip, so nothing was excluded on that basis.client.Instances.Get,client.Instances.Stat,client.Volumes.NewFromArchive,client.Health.Check,client.Instances.Logsandclient.Builds.Eventsare reached internally or through streaming variants, as documented in the mapping guide.The API surface is unchanged by this bump:
da50c33differs from the previously pinned134587aonly ingo.modandgo.sum. Both reportconfigured_endpoints: 63with an identical method list, andda50c33is the merge of the 2026-10-07 vulnerability remediation, which carries transitive dependency updates only.Still pinned to
main, so two generated symbols remain absentAs with the previous bump, this pin is a
maincommit and therefore does not include the "Windows hypervisor primitives" generation that lives on the SDK'snextbranch. Two symbols the CLI needs still do not exist in the generated bindings:InstanceLogsParamsSourceSwtpmhypeman logs --source swtpmInstanceGPU.DevicePathformatGPUinhypeman psopenapi.yamlonmainstill specifies both (thesourceenum is[app, vmm, hypeman, swtpm], anddevice_pathis on the GPU schema), so the API supports them and only the generated bindings lag. The existing workarounds on this branch are therefore retained unchanged:sourceis a string-backed enum, so the localinstanceLogsSourceSwtpmconstant serializes identically.device_patharrives inJSON.ExtraFields, soformatGPUdecodes it from the raw JSON.Both are commented at the call site and should return to typed access once
nextmerges tomain.Verification
go build ./...,go vet ./...andgo test ./...all pass. Becausego mod tidypruned 100+ now-unneededgo.sumentries, cross-compilation was also checked forwindows/amd64,darwin/arm64andlinux/arm64, andgo mod verifyreports all modules verified.This branch also carries a merge of
main(resolving ago.sumconflict). History was preserved rather than rebased, so no force push was needed and the earlier work on the branch is intact.Triggered by: kernel/hypeman-go@da50c33
Reviewer: @ulziibay-kernel