Skip to content

parser: upgrade x/text to v0.39.0 - #70244

Merged
ti-chi-bot[bot] merged 1 commit into
pingcap:masterfrom
YangKeao:security/bump-vulnerable-deps-master
Aug 24, 2026
Merged

ti-chi-bot[bot] merged 1 commit into
pingcap:masterfrom
YangKeao:security/bump-vulnerable-deps-master

Conversation

@YangKeao

@YangKeao YangKeao commented Jul 30, 2026 •

Copy link
Copy Markdown
Member

What problem does this PR solve?

Issue Number: ref #70242

Problem Summary:

The parser submodule still used golang.org/x/text v0.19.0, which is affected by CVE-2026-56852. The root module dependencies listed in #70242 have already been upgraded on the current master branch.

The Prometheus upgrade was intentionally removed from this PR pending security-owner confirmation. TiDB imports github.com/prometheus/prometheus only from pkg/infoschema/metrics_schema_test.go to validate PromQL syntax; no github.com/prometheus/prometheus/* package is linked into the production tidb-server dependency graph. The four reported Prometheus CVEs affect the Prometheus web UI, configuration API, Azure AD remote write, and remote-read HTTP endpoint, none of which TiDB builds or exposes. Keeping the Prometheus upgrade would also force otelgrpc v0.61.0, which is incompatible with etcd v3.5's removed interceptor APIs and previously required an unacceptable Bazel-only patch.

What changed and how does it work?

  • Upgrade pkg/parser from golang.org/x/text v0.19.0 to v0.39.0.
  • Normalize the parser submodule's Go directive through go mod tidy.
  • Do not add any replace directive or third-party patch.
  • Keep the root module on Prometheus v0.50.1, otelgrpc v0.60.0, and etcd v3.5.15 while the Prometheus findings are reviewed as test-only and unreachable.

Check List

Tests

  • Unit test
    • ./tools/check/failpoint-go-test.sh pkg/parser ./... -count=1
  • Integration test
  • Manual test (add detailed scripts or steps below)
    • go mod verify
    • (cd pkg/parser && go mod verify)
    • CC=clang CXX=clang++ make bazel_prepare (run twice; the second run left DEPS.bzl unchanged)
  • No need to test
    • I checked and no code files have been changed.

Side effects

  • Performance regression: Consumes more CPU
  • Performance regression: Consumes more Memory
  • Breaking backward compatibility

Documentation

  • Affects user behaviors
  • Contains syntax changes
  • Contains variable changes
  • Contains experimental features
  • Changes MySQL compatibility

Release note

Please refer to Release Notes Language Style Guide to write a quality release note.

None

@ti-chi-bot ti-chi-bot Bot added release-note-none Denotes a PR that doesn't merit a release note. size/XXL Denotes a PR that changes 1000+ lines, ignoring generated files. labels Jul 30, 2026
@coderabbitai

coderabbitai Bot commented Jul 30, 2026 •

Copy link
Copy Markdown

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

This PR refreshes Go and Bazel dependency pins, adds clean build-file generation wiring, updates etcd OpenTelemetry tracing, reuses a PromQL parser in a test, and changes GCS missing-object error classification to use errors.Is.

Changes

Dependency refresh and integration updates

Layer / File(s) Summary
Go module dependency refresh
go.mod, pkg/parser/go.mod
Direct and indirect cloud, AWS, Prometheus, gRPC, Kubernetes, OpenTelemetry, parser, and tooling dependencies are updated.
Bazel repository lock refresh
DEPS.bzl
Pinned repositories are broadly refreshed, obsolete entries are removed, etcd repositories are reorganized, and selected repositories receive clean build generation settings and patch wiring.
Bazel build-generation wiring
cmd/mirror/mirror.go
The dependency generator emits build_file_generation = "clean" for selected repositories.
etcd tracing wiring
build/patches/io_etcd_go_etcd_server_v3.patch
The etcd gRPC server switches OpenTelemetry registration from interceptor chains to a StatsHandler.
Validation and error classification
pkg/infoschema/metrics_schema_test.go, pkg/objstore/gcs.go
Metric schema parsing reuses one PromQL parser, and GCS not-found detection uses errors.Is.

Estimated code review effort: 4 (Complex) | ~45 minutes

Possibly related PRs

Suggested reviewers: lcwangchao, joechenrh

Poem

A rabbit bounds through pins anew,
With Bazel locks and modules too.
Etcd traces softly hop,
PromQL parses never stop.
Wrapped GCS errors now show—
Fresh green carrots in the flow!

🚥 Pre-merge checks | ✅ 2 | ❌ 3

❌ Failed checks (2 warnings, 1 inconclusive)

Check name Status Explanation Resolution
Out of Scope Changes check ⚠️ Warning pkg/objstore/gcs.go changes error handling behavior and appears unrelated to the dependency-upgrade objective. Remove or justify the gcs.go behavior change if it is required for the dependency upgrade.
Docstring Coverage ⚠️ Warning Docstring coverage is 7.50% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
Linked Issues check ❓ Inconclusive The dependency refresh is aligned, but the summary does not explicitly verify every required fix version, especially stdlib and x/net. Provide the exact version updates for x/net, stdlib, grpc, and prometheus so the issue requirements can be verified.
✅ Passed checks (2 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the parser x/text upgrade, which is a central dependency change in the pull request.
Description check ✅ Passed The description includes the issue reference, problem, implementation details, test evidence, side-effect review, documentation review, and release note.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Jul 30, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 73.2923%. Comparing base (70b0c5d) to head (e6fb0da).
⚠️ Report is 1 commits behind head on master.

Additional details and impacted files
@@               Coverage Diff                @@
##             master     #70244        +/-   ##
================================================
- Coverage   76.3192%   73.2923%   -3.0269%     
================================================
  Files          2041       2085        +44     
  Lines        557600     585177     +27577     
================================================
+ Hits         425556     428890      +3334     
- Misses       131144     155654     +24510     
+ Partials        900        633       -267     
Flag Coverage Δ
integration 40.7616% <ø> (+1.0930%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

Components Coverage Δ
dumpling 58.6514% <ø> (ø)
parser ∅ <ø> (∅)
br 46.6167% <ø> (-16.0923%) ⬇️
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@coderabbitai coderabbitai Bot mentioned this pull request Jul 30, 2026
2 of 13 tasks

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
pkg/owner/fail_test.go (1)

43-43: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value

Correct the stale Windows skip explanations.

The skips still blame integration.NewCluster, but the affected tests do not call that constructor. Use an explanation that matches the actual code, and remove the skip from TestGetOwnerOpValueBeforeSet because owner.NewMockManager does not create the colon-containing Unix socket/filesystem resource.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@pkg/owner/fail_test.go` at line 43, Update the Windows skip handling in
pkg/owner/fail_test.go:43 and pkg/owner/manager_test.go:256 to describe the
actual colon-containing Unix socket/filesystem resource used by each affected
test instead of blaming integration.NewCluster; remove the skip from
TestGetOwnerOpValueBeforeSet because its owner.NewMockManager setup does not
create that resource.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In `@pkg/owner/fail_test.go`:
- Line 43: Update the Windows skip handling in pkg/owner/fail_test.go:43 and
pkg/owner/manager_test.go:256 to describe the actual colon-containing Unix
socket/filesystem resource used by each affected test instead of blaming
integration.NewCluster; remove the skip from TestGetOwnerOpValueBeforeSet
because its owner.NewMockManager setup does not create that resource.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: acc25ea2-3455-40f0-a46b-eb97293f4f8f

📥 Commits

Reviewing files that changed from the base of the PR and between 8931b4a and 940f859.

📒 Files selected for processing (42)
  • br/pkg/utils/BUILD.bazel
  • br/pkg/utils/register_test.go
  • lightning/pkg/importer/BUILD.bazel
  • lightning/pkg/importer/precheck_impl_test.go
  • pkg/autoid_service/BUILD.bazel
  • pkg/autoid_service/autoid_test.go
  • pkg/ddl/BUILD.bazel
  • pkg/ddl/integration_test.go
  • pkg/ddl/schemaver/BUILD.bazel
  • pkg/ddl/schemaver/syncer_nokit_test.go
  • pkg/ddl/schemaver/syncer_test.go
  • pkg/ddl/serverstate/BUILD.bazel
  • pkg/ddl/serverstate/syncer_test.go
  • pkg/domain/BUILD.bazel
  • pkg/domain/crossks/BUILD.bazel
  • pkg/domain/crossks/cross_ks_test.go
  • pkg/domain/domain_test.go
  • pkg/domain/globalconfigsync/BUILD.bazel
  • pkg/domain/globalconfigsync/globalconfig_test.go
  • pkg/domain/serverinfo/BUILD.bazel
  • pkg/domain/serverinfo/syncer_test.go
  • pkg/dxf/importinto/BUILD.bazel
  • pkg/dxf/importinto/job_testkit_test.go
  • pkg/executor/importer/BUILD.bazel
  • pkg/executor/importer/importer_testkit_test.go
  • pkg/metaservice/BUILD.bazel
  • pkg/metaservice/etcd_test.go
  • pkg/owner/BUILD.bazel
  • pkg/owner/fail_test.go
  • pkg/owner/manager_test.go
  • pkg/server/handler/tests/BUILD.bazel
  • pkg/server/handler/tests/http_handler_test.go
  • pkg/session/BUILD.bazel
  • pkg/session/bootstrap_test.go
  • pkg/timer/BUILD.bazel
  • pkg/timer/store_intergartion_test.go
  • pkg/ttl/client/BUILD.bazel
  • pkg/ttl/client/command_test.go
  • pkg/util/cdcutil/BUILD.bazel
  • pkg/util/cdcutil/cdc_test.go
  • pkg/util/etcd/BUILD.bazel
  • pkg/util/etcd/etcd_test.go

@YangKeao

Copy link
Copy Markdown
Member Author

/retest

@ti-chi-bot ti-chi-bot Bot added the needs-cherry-pick-release-8.5 Should cherry pick this PR to release-8.5 branch. label Jul 31, 2026
@coderabbitai coderabbitai Bot mentioned this pull request Aug 3, 2026
1 of 13 tasks
@ti-chi-bot ti-chi-bot Bot added the needs-1-more-lgtm Indicates a PR needs 1 more LGTM. label Aug 3, 2026
@ti-chi-bot ti-chi-bot Bot added lgtm and removed needs-1-more-lgtm Indicates a PR needs 1 more LGTM. labels Aug 3, 2026
@ti-chi-bot

ti-chi-bot Bot commented Aug 3, 2026

Copy link
Copy Markdown

[LGTM Timeline notifier]

Timeline:

  • 2026-08-03 10:44:12.739351241 +0000 UTC m=+2438438.775446327: ☑️ agreed by D3Hunter.
  • 2026-08-03 14:50:53.356323763 +0000 UTC m=+2453239.392418809: ☑️ agreed by winoros.

@YangKeao YangKeao changed the title build: upgrade vulnerable dependencies build: upgrade vulnerable dependencies [PIN-89] Aug 10, 2026
@YangKeao YangKeao changed the title build: upgrade vulnerable dependencies [PIN-89] build: upgrade vulnerable dependencies Aug 10, 2026
@YangKeao
YangKeao force-pushed the security/bump-vulnerable-deps-master branch 2 times, most recently from 74adb03 to 5402730 Compare August 24, 2026 04:15
@YangKeao
YangKeao force-pushed the security/bump-vulnerable-deps-master branch from e92f0c2 to e6fb0da Compare August 24, 2026 06:30
@ti-chi-bot ti-chi-bot Bot added size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. and removed size/XXL Denotes a PR that changes 1000+ lines, ignoring generated files. labels Aug 24, 2026
@ti-chi-bot

ti-chi-bot Bot commented Aug 24, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: D3Hunter, winoros

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@ti-chi-bot ti-chi-bot Bot added the approved label Aug 24, 2026
@YangKeao YangKeao changed the title build: upgrade vulnerable dependencies parser: upgrade x/text to v0.39.0 Aug 24, 2026
@YangKeao

Copy link
Copy Markdown
Member Author

/hold

@ti-chi-bot ti-chi-bot Bot added the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Aug 24, 2026
@YangKeao

Copy link
Copy Markdown
Member Author

/unhold

Most of the dependencies upgrade has been done in other PRs. This PR only upgrades the go.mod in pkg/parser.

@ti-chi-bot ti-chi-bot Bot removed the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Aug 24, 2026
@YangKeao

Copy link
Copy Markdown
Member Author

Ref #69942

@ti-chi-bot
ti-chi-bot Bot merged commit f6d1410 into pingcap:master Aug 24, 2026
34 checks passed
@ti-chi-bot

Copy link
Copy Markdown
Member

In response to a cherrypick label: new pull request created to branch release-8.5: #70625.
But this PR has conflicts, please resolve them!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved lgtm needs-cherry-pick-release-8.5 Should cherry pick this PR to release-8.5 branch. release-note-none Denotes a PR that doesn't merit a release note. size/XS Denotes a PR that changes 0-9 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants