Skip to content

fix(schema): list every missing property of an anyOf of required keys - #7115

Open
wak327 wants to merge 1 commit into
canonical:mainfrom
wak327:fix/schema-anyof-required-message
Open

wak327 wants to merge 1 commit into
canonical:mainfrom
wak327:fix/schema-anyof-required-message

Conversation

@wak327

@wak327 wak327 commented Sep 29, 2026 •

Copy link
Copy Markdown

Proposed Commit Message

fix(schema): list every missing property of an anyOf of required keys

When no subschema of an anyOf matches, the anyOf validator reports
best_match() of the collected errors followed by a generic "... is not
valid under any of the given schemas" error. For anyOf clauses made of
alternative required keys, such as the one for yum_repos, best_match()
just picks the first alternative, so a repo without any URL reported
that 'baseurl' is required and never mentioned metalink or mirrorlist.

When every subschema fails only because it lacks one required property,
report all of those properties in a single error instead:

  yum_repos.epel-testing: 'baseurl', 'metalink' or 'mirrorlist' is a
  required property

Other anyOf failures are reported as before.

Fixes GH-5502

Additional Context

Fixes #5502

Output of cloud-init schema -c yum.yaml for the config in the Test Steps below.

Before:

Error: Cloud config schema errors: yum_repos.epel-testing: 'baseurl' is a required property, yum_repos.epel-testing: {'name': 'Extra Packages for Enterprise Linux 5 - Testing', 'enabled': False} is not valid under any of the given schemas

After:

Error: Cloud config schema errors: yum_repos.epel-testing: 'baseurl', 'metalink' or 'mirrorlist' is a required property

chpasswd.users benefits as well. A user entry with only name now reports chpasswd.users.0: 'type' or 'password' is a required property. Previously it reported only 'type' plus the generic error.

The combined message is used only when every anyOf subschema fails with a single required error on the object itself. All other failures still go through best_match() as before. This includes a subschema that lacks two properties, type or enum errors, and the network anyOf_type_* handling. The missing property comes from the error's validator_value rather than from parsing the message, so this works the same on jsonschema 3.2.0 (lowest supported) and on current releases.

Verified with the pinned black, isort, ruff, pylint and mypy. The full unit suite passes with current jsonschema (5,783 tests) and with jsonschema 3.2.0 (5,779 tests).

Test Steps

cat > yum.yaml <<'YAML'
#cloud-config
yum_repos:
  epel-testing:
    name: Extra Packages for Enterprise Linux 5 - Testing
    enabled: false
YAML
cloud-init schema -c yum.yaml
tox -e py3 -- tests/unittests/config/test_schema.py tests/unittests/config/test_cc_yum_add_repo.py tests/unittests/config/test_cc_set_passwords.py

Merge type

  • Squash merge using "Proposed Commit Message"
  • Rebase and merge unique commits. Requires commit messages per-commit each referencing the pull request number (#<PR_NUM>)

@holmanb

holmanb commented Sep 29, 2026

Copy link
Copy Markdown
Member

@wak327 please sign the cla

@wak327

wak327 commented Sep 29, 2026 •

Copy link
Copy Markdown
Author

@holmanb Thanks, I've signed the CLA now. Could you re-run the cla check here and on #7113 and #7114 when you get a chance?

When no subschema of an anyOf matches, the anyOf validator reports
best_match() of the collected errors followed by a generic "... is not
valid under any of the given schemas" error. For anyOf clauses made of
alternative required keys, such as the one for yum_repos, best_match()
just picks the first alternative, so a repo without any URL reported
that 'baseurl' is required and never mentioned metalink or mirrorlist.

When every subschema fails only because it lacks one required property,
report all of those properties in a single error instead:

  yum_repos.epel-testing: 'baseurl', 'metalink' or 'mirrorlist' is a
  required property

Other anyOf failures are reported as before.

Fixes canonicalGH-5502
@wak327
wak327 force-pushed the fix/schema-anyof-required-message branch from 3421043 to 6c76d59 Compare September 30, 2026 20:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Schema error messaging doesn't handle 'anyof' with 'required'

2 participants