Skip to content

build: resolve Bazel Go deps through GOPROXY (#69503) - #69842

Open
ti-chi-bot wants to merge 1 commit into
pingcap:release-8.5from
ti-chi-bot:cherry-pick-69503-to-release-8.5
Open

ti-chi-bot wants to merge 1 commit into
pingcap:release-8.5from
ti-chi-bot:cherry-pick-69503-to-release-8.5

Conversation

@ti-chi-bot

@ti-chi-bot ti-chi-bot commented Jul 14, 2026 •

Copy link
Copy Markdown
Member

This is an automated cherry-pick of #69503

Issue Number: close #69513

Summary

  • change cmd/mirror to generate go_repository entries with sum and version instead of mirrored urls, sha256, and strip_prefix
  • remove the pingcapmirror Go module upload path and deprecated bazel_mirror_upload
  • regenerate DEPS.bzl so Bazel Go dependencies are resolved by rules_go through the configured Go module environment, e.g. GOPROXY=...|...,direct

Test Plan

  • make tidy
  • go test ./cmd/mirror
  • PATH=/tmp/tidb-bazel-shim:$PATH make bazel_prepare
  • PATH=/tmp/tidb-bazel-shim:$PATH make bazel_mirror_upload
  • PATH=/tmp/tidb-bazel-shim:$PATH make lint
  • git -c core.whitespace=-tab-in-indent diff --check
  • verified DEPS.bzl has no pingcapmirror, cache.hawkingrei.com, urls, sha256, or strip_prefix entries for Go modules

Tests

  • Unit test
  • Integration test
  • Manual test (add detailed scripts or steps below)

Release note

None

Summary by CodeRabbit

  • New Features
    • Dependency metadata is now generated directly from GOPROXY downloads, improving consistency when preparing Bazel dependencies.
  • Deprecations
    • Mirror and upload options are deprecated and ignored.
    • The previous mirror upload workflow is no longer supported; regenerate dependency definitions using the standard mirror preparation command.
  • Bug Fixes
    • Updated Bazel dependency preparation commands to use the current mirror workflow.

Signed-off-by: ti-chi-bot <ti-community-prow-bot@tidb.io>
@ti-chi-bot ti-chi-bot added contribution This PR is from a community contributor. do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. first-time-contributor Indicates that the PR was contributed by an external member and is a first-time contributor. ok-to-test Indicates a PR is ready to be tested. release-note-none Denotes a PR that doesn't merit a release note. size/XXL Denotes a PR that changes 1000+ lines, ignoring generated files. type/cherry-pick-for-release-8.5 This PR is cherry-picked to release-8.5 from a source PR. labels Jul 14, 2026
@ti-chi-bot

ti-chi-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown

This cherry pick PR is for a release branch and has not yet been approved by triage owners.
Adding the do-not-merge/cherry-pick-not-approved label.

To merge this cherry pick:

  1. It must be LGTMed and approved by the reviewers firstly.
  2. For pull requests to TiDB-x branches, it must have no failed tests.
  3. AFTER it has lgtm and approved labels, please wait for the cherry-pick merging approval from triage owners.
Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@ti-chi-bot

ti-chi-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign yisaer for approval. For more information see the Code Review Process.
Please ensure that each of them provides their approval before proceeding.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@coderabbitai

coderabbitai Bot commented Jul 14, 2026 •

Copy link
Copy Markdown

Review Change Stack

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 09ba4287-652a-4618-9707-3c20ea330d3a

📥 Commits

Reviewing files that changed from the base of the PR and between 202b7f4 and c101674.

⛔ Files ignored due to path filters (1)
  • go.sum is excluded by !**/*.sum
📒 Files selected for processing (6)
  • DEPS.bzl
  • Makefile
  • cmd/mirror/BUILD.bazel
  • cmd/mirror/mirror.go
  • cmd/mirror/skylarkutil.go
  • go.mod
💤 Files with no reviewable changes (1)
  • cmd/mirror/skylarkutil.go

📝 Walkthrough

Walkthrough

The mirror tool now resolves Go modules through GOPROXY and emits their versions and sums directly into DEPS.bzl. Legacy Skylark parsing and upload logic are removed, while Bazel targets, Makefile workflows, and module requirements are updated.

Changes

GOPROXY mirror migration

Layer / File(s) Summary
Remove legacy mirror dependencies
cmd/mirror/BUILD.bazel, cmd/mirror/mirror.go, cmd/mirror/skylarkutil.go, go.mod
The Skylark parser, upload helpers, mirror dependencies, and related module requirements are removed.
Generate DEPS.bzl from GOPROXY
cmd/mirror/mirror.go
Deprecated flags are ignored, and repository metadata is generated from downloaded module versions and checksums. The file still contains unresolved merge-conflict markers.
Update Bazel mirror workflows
Makefile
Mirror-related targets use revised bazel run argument forms, validation settings, and upload deprecation behavior; unresolved conflict markers remain in several commands.

Estimated code review effort: 4 (Complex) | ~45 minutes

Sequence Diagram(s)

sequenceDiagram
  participant Makefile
  participant BazelMirror
  participant GOPROXY
  Makefile->>BazelMirror: run mirror target
  BazelMirror->>GOPROXY: resolve and download Go modules
  GOPROXY-->>BazelMirror: return module version and checksum
  BazelMirror-->>Makefile: generate DEPS.bzl
Loading

Possibly related PRs

  • pingcap/tidb#69503: Directly overlaps the GOPROXY-only mirror implementation, Skylark removal, and Makefile updates.
  • pingcap/tidb#69320: Also changes mirror URL generation to use GOPROXY behavior.

Suggested reviewers: cfzjywxk, d3hunter, jmpotato, yangkeao

Poem

I’m a rabbit hopping through GOPROXY bright,
No mirror uploads weighing down the night.
Versions and sums now neatly align,
DEPS.bzl blooms in a single straight line.
Conflict markers? Please make them take flight!

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 inconclusive)

Check name Status Explanation Resolution
Linked Issues check ❓ Inconclusive The change matches the requested pingcapmirror-to-GOPROXY refactor, but unresolved merge-conflict markers make the final implementation ambiguous. Resolve the conflict markers in Makefile and mirror.go, then verify only the final GOPROXY-based flow remains.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly states the Bazel Go dependency resolution change via GOPROXY.
Description check ✅ Passed The description includes the issue link, summary, test plan, tests, and release note, though section headings are less exact than the template.
Out of Scope Changes check ✅ Passed No clearly unrelated changes stand out; the dependency cleanup and Go module updates support the mirror refactor.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 golangci-lint (2.12.2)

Error: can't load config: unsupported version of the configuration: "" See https://golangci-lint.run/docs/product/migration-guide for migration instructions
The command is terminated due to an error: can't load config: unsupported version of the configuration: "" See https://golangci-lint.run/docs/product/migration-guide for migration instructions


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@ti-chi-bot

ti-chi-bot Bot commented Jul 14, 2026

Copy link
Copy Markdown

@ti-chi-bot: The following tests failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
idc-jenkins-ci-tidb/check_dev c101674 link true /test check-dev
idc-jenkins-ci-tidb/check_dev_2 c101674 link true /test check-dev2
idc-jenkins-ci-tidb/mysql-test c101674 link true /test mysql-test
idc-jenkins-ci-tidb/unit-test c101674 link true /test unit-test
idc-jenkins-ci-tidb/build c101674 link true /test build

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 5

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (2)
cmd/mirror/mirror.go (2)

52-150: 🎯 Functional Correctness | 🔴 Critical | ⚡ Quick win

Unresolved merge/cherry-pick conflict markers left in source — file will not compile.

Lines 53 and 146-149 contain literal <<<<<<< HEAD / ======= / >>>>>>> 6c90f90bea7 (...) markers inside init(), and the enclosed block still defines formatSubURL, formatGoProxyURL, and getSha256OfFile (which use sha256/hex) even though the import block for this file was already updated elsewhere to drop crypto/sha256 and encoding/hex. This is invalid Go syntax and/or will fail to build due to missing imports regardless of resolution choice.

🐛 Resolve the conflict by keeping only the new deprecated-flag registration
 func init() {
-<<<<<<< HEAD
-	flag.BoolVar(&isMirror, "mirror", false, "enable mirror mode")
-	flag.BoolVar(&isUpload, "upload", false, "enable upload mode")
-}
-
-func formatSubURL(path, version string) string {
-	return fmt.Sprintf("gomod/%s/%s-%s.zip", path, modulePathToBazelRepoName(path), version)
-}
-...
-func getSha256OfFile(path string) (string, error) {
-	...
-	return hex.EncodeToString(h.Sum(nil)), nil
-=======
-	flag.BoolVar(&isMirror, "mirror", false, "deprecated; ignored")
-	flag.BoolVar(&isUpload, "upload", false, "deprecated; ignored")
->>>>>>> 6c90f90bea7 (build: resolve Bazel Go deps through GOPROXY (`#69503`))
+	flag.BoolVar(&isMirror, "mirror", false, "deprecated; ignored")
+	flag.BoolVar(&isUpload, "upload", false, "deprecated; ignored")
 }

Also drop the now-dead formatSubURL/formatGoProxyURL/getSha256OfFile helpers if nothing else in the resolved file calls them.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@cmd/mirror/mirror.go` around lines 52 - 150, Resolve the conflict in init by
removing all merge markers and retaining only the deprecated, ignored
registrations for isMirror and isUpload. Delete the obsolete formatSubURL,
formatGoProxyURL, getSha256OfFile, and related unused fallback helpers if no
remaining code references them, leaving imports consistent with the resolved
implementation.

372-461: 🎯 Functional Correctness | 🔴 Critical | ⚡ Quick win

Second unresolved conflict block in dumpNewDepsBzl — mixes removed mirror/upload logic with the new GOPROXY-based emission.

This block still contains <<<<<<< HEAD / ======= / >>>>>>> markers and the HEAD side references existingMirrors, ctx, client, g.Go, uploadFile, needGoProxyFallback, and the formatVPCPrivateURL/formatCDNURL/formatPublicURL/formatVPCPublicURL helpers — all of which are removed by companion hunks in this same diff (uploadFile deleted at 160-167, getExistingMirrors deleted at 270-280). Resolving this incorrectly, or leaving it as-is, breaks the build.

🐛 Resolve to keep only the GOPROXY-based emission path
-<<<<<<< HEAD
-		expectedVPCPrivateURL := formatVPCPrivateURL(replaced.Path, replaced.Version)
-		expectedCDNURL := formatCDNURL(replaced.Path, replaced.Version)
-		expectedPublicURL := formatPublicURL(replaced.Path, replaced.Version)
-		expectedVPCPublicURL := formatVPCPublicURL(replaced.Path, replaced.Version)
-		expectedGoProxyURL := formatGoProxyURL(replaced.Path, replaced.Version)
-=======
-=======
->>>>>>> 6c90f90bea7 (build: resolve Bazel Go deps through GOPROXY (`#69503`))
 		fmt.Printf("        importpath = \"%s\",\n", mod.Path)
 		if err := dumpPatchArgsForRepo(repoName); err != nil {
 			return err
 		}
-<<<<<<< HEAD
-		oldMirror, ok := existingMirrors[repoName]
-		... (entire mirror/upload branch removed) ...
-=======
-		d, ok := downloaded[replaced.Path]
+		d, ok := downloaded[replaced.Path]
 		if !ok {
 			return fmt.Errorf("could not find downloaded module for %s@%s", replaced.Path, replaced.Version)
-<<<<<<< HEAD
 		}
 		if mod.Replace != nil {
 			fmt.Printf("        replace = \"%s\",\n", replaced.Path)
 		}
 		fmt.Printf(`        sum = "%s",
         version = "%s",
 `, d.Sum, d.Version)
 		fmt.Println("    )")
 	}
 	return nil
 }
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@cmd/mirror/mirror.go` around lines 372 - 461, Resolve the conflict in
dumpNewDepsBzl by removing all conflict markers and the obsolete mirror
reuse/upload branch, including references to existingMirrors, URL-formatting
helpers, ctx, client, g.Go, uploadFile, and needGoProxyFallback. Keep the
GOPROXY-based path that validates downloaded[replaced.Path], emits replace when
applicable, and prints the module’s sum and version before closing the
repository block.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@DEPS.bzl`:
- Around line 7-24: Resolve all remaining merge-conflict blocks in DEPS.bzl,
including the cc_mvdan_gofumpt go_repository declaration, by removing every
conflict marker and choosing the correct dependency definition. Regenerate or
normalize the affected go_repository entries so DEPS.bzl contains one valid
Starlark declaration per dependency and parses successfully.

In `@go.mod`:
- Around line 69-78: Resolve the merge conflict in go.mod by removing all
conflict markers and retaining only the cherry-picked target versions of
github.com/google/pprof, github.com/google/uuid, and
github.com/gordonklaus/ineffassign. Ensure the resulting module requirements are
valid syntax.

In `@Makefile`:
- Around line 832-838: Resolve the conflict in the bazel_mirror_upload target by
removing all merge-conflict markers and retaining only the deprecation notice
that directs users to make bazel_mirror; remove the obsolete Bazel mirror upload
command.
- Around line 817-826: Resolve the conflict markers in the bazel_mirror target
and keep only the GOPROXY-based Bazel invocation, including the
--norun_validations option. Remove the obsolete --mirror variant and preserve
the existing temporary-file, copy, and cleanup steps.
- Around line 589-593: Resolve the merge conflict in the bazel_prepare target by
removing all conflict markers and retaining only the GOPROXY-based Bazel
invocation using BAZEL_GLOBAL_CONFIG and BAZEL_CMD_CONFIG; discard the stale
--mirror invocation.

---

Outside diff comments:
In `@cmd/mirror/mirror.go`:
- Around line 52-150: Resolve the conflict in init by removing all merge markers
and retaining only the deprecated, ignored registrations for isMirror and
isUpload. Delete the obsolete formatSubURL, formatGoProxyURL, getSha256OfFile,
and related unused fallback helpers if no remaining code references them,
leaving imports consistent with the resolved implementation.
- Around line 372-461: Resolve the conflict in dumpNewDepsBzl by removing all
conflict markers and the obsolete mirror reuse/upload branch, including
references to existingMirrors, URL-formatting helpers, ctx, client, g.Go,
uploadFile, and needGoProxyFallback. Keep the GOPROXY-based path that validates
downloaded[replaced.Path], emits replace when applicable, and prints the
module’s sum and version before closing the repository block.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 09ba4287-652a-4618-9707-3c20ea330d3a

📥 Commits

Reviewing files that changed from the base of the PR and between 202b7f4 and c101674.

⛔ Files ignored due to path filters (1)
  • go.sum is excluded by !**/*.sum
📒 Files selected for processing (6)
  • DEPS.bzl
  • Makefile
  • cmd/mirror/BUILD.bazel
  • cmd/mirror/mirror.go
  • cmd/mirror/skylarkutil.go
  • go.mod
💤 Files with no reviewable changes (1)
  • cmd/mirror/skylarkutil.go

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Inline review comments failed to post. This is likely due to GitHub's internal server error or limits when posting large numbers of comments. If you are seeing this consistently it is likely a permissions issue. Please check "Moderation" -> "Code review limits" under your organization settings.

Actionable comments posted: 5

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (2)
cmd/mirror/mirror.go (2)

52-150: 🎯 Functional Correctness | 🔴 Critical | ⚡ Quick win

Unresolved merge/cherry-pick conflict markers left in source — file will not compile.

Lines 53 and 146-149 contain literal <<<<<<< HEAD / ======= / >>>>>>> 6c90f90bea7 (...) markers inside init(), and the enclosed block still defines formatSubURL, formatGoProxyURL, and getSha256OfFile (which use sha256/hex) even though the import block for this file was already updated elsewhere to drop crypto/sha256 and encoding/hex. This is invalid Go syntax and/or will fail to build due to missing imports regardless of resolution choice.

🐛 Resolve the conflict by keeping only the new deprecated-flag registration
 func init() {
-<<<<<<< HEAD
-	flag.BoolVar(&isMirror, "mirror", false, "enable mirror mode")
-	flag.BoolVar(&isUpload, "upload", false, "enable upload mode")
-}
-
-func formatSubURL(path, version string) string {
-	return fmt.Sprintf("gomod/%s/%s-%s.zip", path, modulePathToBazelRepoName(path), version)
-}
-...
-func getSha256OfFile(path string) (string, error) {
-	...
-	return hex.EncodeToString(h.Sum(nil)), nil
-=======
-	flag.BoolVar(&isMirror, "mirror", false, "deprecated; ignored")
-	flag.BoolVar(&isUpload, "upload", false, "deprecated; ignored")
->>>>>>> 6c90f90bea7 (build: resolve Bazel Go deps through GOPROXY (`#69503`))
+	flag.BoolVar(&isMirror, "mirror", false, "deprecated; ignored")
+	flag.BoolVar(&isUpload, "upload", false, "deprecated; ignored")
 }

Also drop the now-dead formatSubURL/formatGoProxyURL/getSha256OfFile helpers if nothing else in the resolved file calls them.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@cmd/mirror/mirror.go` around lines 52 - 150, Resolve the conflict in init by
removing all merge markers and retaining only the deprecated, ignored
registrations for isMirror and isUpload. Delete the obsolete formatSubURL,
formatGoProxyURL, getSha256OfFile, and related unused fallback helpers if no
remaining code references them, leaving imports consistent with the resolved
implementation.

372-461: 🎯 Functional Correctness | 🔴 Critical | ⚡ Quick win

Second unresolved conflict block in dumpNewDepsBzl — mixes removed mirror/upload logic with the new GOPROXY-based emission.

This block still contains <<<<<<< HEAD / ======= / >>>>>>> markers and the HEAD side references existingMirrors, ctx, client, g.Go, uploadFile, needGoProxyFallback, and the formatVPCPrivateURL/formatCDNURL/formatPublicURL/formatVPCPublicURL helpers — all of which are removed by companion hunks in this same diff (uploadFile deleted at 160-167, getExistingMirrors deleted at 270-280). Resolving this incorrectly, or leaving it as-is, breaks the build.

🐛 Resolve to keep only the GOPROXY-based emission path
-<<<<<<< HEAD
-		expectedVPCPrivateURL := formatVPCPrivateURL(replaced.Path, replaced.Version)
-		expectedCDNURL := formatCDNURL(replaced.Path, replaced.Version)
-		expectedPublicURL := formatPublicURL(replaced.Path, replaced.Version)
-		expectedVPCPublicURL := formatVPCPublicURL(replaced.Path, replaced.Version)
-		expectedGoProxyURL := formatGoProxyURL(replaced.Path, replaced.Version)
-=======
-=======
->>>>>>> 6c90f90bea7 (build: resolve Bazel Go deps through GOPROXY (`#69503`))
 		fmt.Printf("        importpath = \"%s\",\n", mod.Path)
 		if err := dumpPatchArgsForRepo(repoName); err != nil {
 			return err
 		}
-<<<<<<< HEAD
-		oldMirror, ok := existingMirrors[repoName]
-		... (entire mirror/upload branch removed) ...
-=======
-		d, ok := downloaded[replaced.Path]
+		d, ok := downloaded[replaced.Path]
 		if !ok {
 			return fmt.Errorf("could not find downloaded module for %s@%s", replaced.Path, replaced.Version)
-<<<<<<< HEAD
 		}
 		if mod.Replace != nil {
 			fmt.Printf("        replace = \"%s\",\n", replaced.Path)
 		}
 		fmt.Printf(`        sum = "%s",
         version = "%s",
 `, d.Sum, d.Version)
 		fmt.Println("    )")
 	}
 	return nil
 }
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@cmd/mirror/mirror.go` around lines 372 - 461, Resolve the conflict in
dumpNewDepsBzl by removing all conflict markers and the obsolete mirror
reuse/upload branch, including references to existingMirrors, URL-formatting
helpers, ctx, client, g.Go, uploadFile, and needGoProxyFallback. Keep the
GOPROXY-based path that validates downloaded[replaced.Path], emits replace when
applicable, and prints the module’s sum and version before closing the
repository block.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@DEPS.bzl`:
- Around line 7-24: Resolve all remaining merge-conflict blocks in DEPS.bzl,
including the cc_mvdan_gofumpt go_repository declaration, by removing every
conflict marker and choosing the correct dependency definition. Regenerate or
normalize the affected go_repository entries so DEPS.bzl contains one valid
Starlark declaration per dependency and parses successfully.

In `@go.mod`:
- Around line 69-78: Resolve the merge conflict in go.mod by removing all
conflict markers and retaining only the cherry-picked target versions of
github.com/google/pprof, github.com/google/uuid, and
github.com/gordonklaus/ineffassign. Ensure the resulting module requirements are
valid syntax.

In `@Makefile`:
- Around line 832-838: Resolve the conflict in the bazel_mirror_upload target by
removing all merge-conflict markers and retaining only the deprecation notice
that directs users to make bazel_mirror; remove the obsolete Bazel mirror upload
command.
- Around line 817-826: Resolve the conflict markers in the bazel_mirror target
and keep only the GOPROXY-based Bazel invocation, including the
--norun_validations option. Remove the obsolete --mirror variant and preserve
the existing temporary-file, copy, and cleanup steps.
- Around line 589-593: Resolve the merge conflict in the bazel_prepare target by
removing all conflict markers and retaining only the GOPROXY-based Bazel
invocation using BAZEL_GLOBAL_CONFIG and BAZEL_CMD_CONFIG; discard the stale
--mirror invocation.

---

Outside diff comments:
In `@cmd/mirror/mirror.go`:
- Around line 52-150: Resolve the conflict in init by removing all merge markers
and retaining only the deprecated, ignored registrations for isMirror and
isUpload. Delete the obsolete formatSubURL, formatGoProxyURL, getSha256OfFile,
and related unused fallback helpers if no remaining code references them,
leaving imports consistent with the resolved implementation.
- Around line 372-461: Resolve the conflict in dumpNewDepsBzl by removing all
conflict markers and the obsolete mirror reuse/upload branch, including
references to existingMirrors, URL-formatting helpers, ctx, client, g.Go,
uploadFile, and needGoProxyFallback. Keep the GOPROXY-based path that validates
downloaded[replaced.Path], emits replace when applicable, and prints the
module’s sum and version before closing the repository block.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 09ba4287-652a-4618-9707-3c20ea330d3a

📥 Commits

Reviewing files that changed from the base of the PR and between 202b7f4 and c101674.

⛔ Files ignored due to path filters (1)
  • go.sum is excluded by !**/*.sum
📒 Files selected for processing (6)
  • DEPS.bzl
  • Makefile
  • cmd/mirror/BUILD.bazel
  • cmd/mirror/mirror.go
  • cmd/mirror/skylarkutil.go
  • go.mod
💤 Files with no reviewable changes (1)
  • cmd/mirror/skylarkutil.go
🛑 Comments failed to post (5)
DEPS.bzl (1)

7-24: 🎯 Functional Correctness | 🔴 Critical | 🏗️ Heavy lift

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
# Confirm the file actually contains literal git conflict markers as committed.
rg -n '^(<<<<<<<|=======|>>>>>>>)' DEPS.bzl | head -50
rg -c '^<<<<<<< HEAD' DEPS.bzl

Repository: pingcap/tidb

Length of output: 1912


Critical: remove the unresolved cherry-pick conflict markers from DEPS.bzl.

DEPS.bzl still contains literal <<<<<<< HEAD, =======, and >>>>>>> 6c90f90bea7 (build: resolve Bazel Go deps through GOPROXY (#69503)) blocks throughout the file, starting here and repeating later. Those markers are invalid Starlark, so Bazel cannot parse this file, and the duplicated go_repository() entries on both sides of the conflict need to be regenerated cleanly.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@DEPS.bzl` around lines 7 - 24, Resolve all remaining merge-conflict blocks in
DEPS.bzl, including the cc_mvdan_gofumpt go_repository declaration, by removing
every conflict marker and choosing the correct dependency definition. Regenerate
or normalize the affected go_repository entries so DEPS.bzl contains one valid
Starlark declaration per dependency and parses successfully.
go.mod (1)

69-78: 🎯 Functional Correctness | 🔴 Critical | ⚡ Quick win

Unresolved merge conflict markers in go.mod.

Lines 69, 74, and 78 still contain literal <<<<<<< HEAD / ======= / >>>>>>> 6c90f90bea7 (...) markers. A go.mod with these markers is not valid module syntax and will break go build, go mod tidy, and any Bazel gazelle/mirror invocation that parses it.

🐛 Resolve to keep only the cherry-picked (target) versions
-<<<<<<< HEAD
-	github.com/google/pprof v0.0.0-20241001023024-f4c0cfd0cf1d
-	github.com/google/skylark v0.0.0-20181101142754-a5f7082aabed
-	github.com/google/uuid v1.6.0
-	github.com/gordonklaus/ineffassign v0.1.0
-=======
+	github.com/google/pprof v0.0.0-20250903194437-c28834ac2320
 	github.com/google/uuid v1.6.1-0.20241114170450-2d3c2a9cc518
 	github.com/gordonklaus/ineffassign v0.2.0
->>>>>>> 6c90f90bea7 (build: resolve Bazel Go deps through GOPROXY (`#69503`))
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

	github.com/google/pprof v0.0.0-20250903194437-c28834ac2320
	github.com/google/uuid v1.6.1-0.20241114170450-2d3c2a9cc518
	github.com/gordonklaus/ineffassign v0.2.0
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@go.mod` around lines 69 - 78, Resolve the merge conflict in go.mod by
removing all conflict markers and retaining only the cherry-picked target
versions of github.com/google/pprof, github.com/google/uuid, and
github.com/gordonklaus/ineffassign. Ensure the resulting module requirements are
valid syntax.
Makefile (3)

589-593: 🎯 Functional Correctness | 🔴 Critical | ⚡ Quick win

Unresolved merge conflict markers in bazel_prepare target.

Lines 589, 591, and 593 still contain literal <<<<<<< HEAD / ======= / >>>>>>> markers. make will treat these as recipe lines and either fail outright or execute the wrong (stale, --mirror-flag) invocation.

🐛 Resolve to keep only the GOPROXY-based invocation
 	$(eval $@TMP_OUT := $(shell mktemp -d -t tidbbzl.XXXXXX))
-<<<<<<< HEAD
-	bazel run  //cmd/mirror -- --mirror> $($@TMP_OUT)/tmp.txt
-=======
-	bazel $(BAZEL_GLOBAL_CONFIG) run $(BAZEL_CMD_CONFIG) //cmd/mirror > $($@TMP_OUT)/tmp.txt
->>>>>>> 6c90f90bea7 (build: resolve Bazel Go deps through GOPROXY (`#69503`))
+	bazel $(BAZEL_GLOBAL_CONFIG) run $(BAZEL_CMD_CONFIG) //cmd/mirror > $($@TMP_OUT)/tmp.txt
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

	bazel $(BAZEL_GLOBAL_CONFIG) run $(BAZEL_CMD_CONFIG) //cmd/mirror > $($@TMP_OUT)/tmp.txt
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@Makefile` around lines 589 - 593, Resolve the merge conflict in the
bazel_prepare target by removing all conflict markers and retaining only the
GOPROXY-based Bazel invocation using BAZEL_GLOBAL_CONFIG and BAZEL_CMD_CONFIG;
discard the stale --mirror invocation.

817-826: 🎯 Functional Correctness | 🔴 Critical | ⚡ Quick win

Unresolved merge conflict markers in bazel_mirror target.

Lines 820, 822, and 824 still contain literal conflict markers. Static analysis (checkmake) is misinterpreting the raw recipe fragments as separate targets ("bazel $(BAZEL_GLOBAL_CONFIG) run $(BAZEL_CMD_CONFIG) //cmd/mirror" at line 821, and the --norun_validations variant at line 823) needing .PHONY — a direct symptom of the corrupted Makefile syntax rather than an independent phonydeclared issue.

🐛 Resolve to keep only the GOPROXY-based invocation
 	$(eval $@TMP_OUT := $(shell mktemp -d -t tidbbzl.XXXXXX))
-<<<<<<< HEAD
-	bazel $(BAZEL_GLOBAL_CONFIG) run $(BAZEL_CMD_CONFIG)  //cmd/mirror:mirror -- --mirror> $($@TMP_OUT)/tmp.txt
-=======
-	bazel $(BAZEL_GLOBAL_CONFIG) run $(BAZEL_CMD_CONFIG) --norun_validations //cmd/mirror:mirror > $($@TMP_OUT)/tmp.txt
->>>>>>> 6c90f90bea7 (build: resolve Bazel Go deps through GOPROXY (`#69503`))
+	bazel $(BAZEL_GLOBAL_CONFIG) run $(BAZEL_CMD_CONFIG) --norun_validations //cmd/mirror:mirror > $($@TMP_OUT)/tmp.txt
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

.PHONY: bazel_mirror
bazel_mirror:
	$(eval $@TMP_OUT := $(shell mktemp -d -t tidbbzl.XXXXXX))
	bazel $(BAZEL_GLOBAL_CONFIG) run $(BAZEL_CMD_CONFIG) --norun_validations //cmd/mirror:mirror > $($@TMP_OUT)/tmp.txt
	cp $($@TMP_OUT)/tmp.txt DEPS.bzl
	rm -rf $($@TMP_OUT)
🧰 Tools
🪛 checkmake (0.3.2)

[warning] 821-821: Target "bazel $(BAZEL_GLOBAL_CONFIG) run $(BAZEL_CMD_CONFIG) //cmd/mirror" should be declared PHONY.

(phonydeclared)


[warning] 823-823: Target "bazel $(BAZEL_GLOBAL_CONFIG) run $(BAZEL_CMD_CONFIG) --norun_validations //cmd/mirror" should be declared PHONY.

(phonydeclared)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@Makefile` around lines 817 - 826, Resolve the conflict markers in the
bazel_mirror target and keep only the GOPROXY-based Bazel invocation, including
the --norun_validations option. Remove the obsolete --mirror variant and
preserve the existing temporary-file, copy, and cleanup steps.

Source: Linters/SAST tools


832-838: 🎯 Functional Correctness | 🔴 Critical | ⚡ Quick win

Unresolved merge conflict markers in bazel_mirror_upload target.

Lines 834, 836, and 838 still contain literal conflict markers around the target's body.

🐛 Resolve to keep only the deprecation-notice body
 .PHONY: bazel_mirror_upload
 bazel_mirror_upload:
-<<<<<<< HEAD
-	bazel $(BAZEL_GLOBAL_CONFIG) run $(BAZEL_CMD_CONFIG)  //cmd/mirror -- --mirror --upload
-=======
-	`@echo` "bazel_mirror_upload is deprecated; Go modules are resolved through GOPROXY. Run 'make bazel_mirror' to regenerate DEPS.bzl."
->>>>>>> 6c90f90bea7 (build: resolve Bazel Go deps through GOPROXY (`#69503`))
+	`@echo` "bazel_mirror_upload is deprecated; Go modules are resolved through GOPROXY. Run 'make bazel_mirror' to regenerate DEPS.bzl."
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

.PHONY: bazel_mirror_upload
bazel_mirror_upload:
	`@echo` "bazel_mirror_upload is deprecated; Go modules are resolved through GOPROXY. Run 'make bazel_mirror' to regenerate DEPS.bzl."
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@Makefile` around lines 832 - 838, Resolve the conflict in the
bazel_mirror_upload target by removing all merge-conflict markers and retaining
only the deprecation notice that directs users to make bazel_mirror; remove the
obsolete Bazel mirror upload command.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contribution This PR is from a community contributor. do-not-merge/cherry-pick-not-approved do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. first-time-contributor Indicates that the PR was contributed by an external member and is a first-time contributor. ok-to-test Indicates a PR is ready to be tested. release-note-none Denotes a PR that doesn't merit a release note. size/XXL Denotes a PR that changes 1000+ lines, ignoring generated files. type/cherry-pick-for-release-8.5 This PR is cherry-picked to release-8.5 from a source PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants