Repository navigation
parser: upgrade x/text to v0.39.0 - #70244
ti-chi-bot[bot] merged 1 commit into
Conversation
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
📝 WalkthroughWalkthroughThis PR refreshes Go and Bazel dependency pins, adds clean build-file generation wiring, updates etcd OpenTelemetry tracing, reuses a PromQL parser in a test, and changes GCS missing-object error classification to use ChangesDependency refresh and integration updates
Estimated code review effort: 4 (Complex) | ~45 minutes Possibly related PRs
Suggested reviewers: Poem
🚥 Pre-merge checks | ✅ 2 | ❌ 3❌ Failed checks (2 warnings, 1 inconclusive)
✅ Passed checks (2 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #70244 +/- ##
================================================
- Coverage 76.3192% 73.2923% -3.0269%
================================================
Files 2041 2085 +44
Lines 557600 585177 +27577
================================================
+ Hits 425556 428890 +3334
- Misses 131144 155654 +24510
+ Partials 900 633 -267
Flags with carried forward coverage won't be shown. Click here to find out more.
🚀 New features to boost your workflow:
|
There was a problem hiding this comment.
🧹 Nitpick comments (1)
pkg/owner/fail_test.go (1)
43-43: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low valueCorrect the stale Windows skip explanations.
The skips still blame
integration.NewCluster, but the affected tests do not call that constructor. Use an explanation that matches the actual code, and remove the skip fromTestGetOwnerOpValueBeforeSetbecauseowner.NewMockManagerdoes not create the colon-containing Unix socket/filesystem resource.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@pkg/owner/fail_test.go` at line 43, Update the Windows skip handling in pkg/owner/fail_test.go:43 and pkg/owner/manager_test.go:256 to describe the actual colon-containing Unix socket/filesystem resource used by each affected test instead of blaming integration.NewCluster; remove the skip from TestGetOwnerOpValueBeforeSet because its owner.NewMockManager setup does not create that resource.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@pkg/owner/fail_test.go`:
- Line 43: Update the Windows skip handling in pkg/owner/fail_test.go:43 and
pkg/owner/manager_test.go:256 to describe the actual colon-containing Unix
socket/filesystem resource used by each affected test instead of blaming
integration.NewCluster; remove the skip from TestGetOwnerOpValueBeforeSet
because its owner.NewMockManager setup does not create that resource.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository UI
Review profile: CHILL
Plan: Pro Plus
Run ID: acc25ea2-3455-40f0-a46b-eb97293f4f8f
📒 Files selected for processing (42)
br/pkg/utils/BUILD.bazelbr/pkg/utils/register_test.golightning/pkg/importer/BUILD.bazellightning/pkg/importer/precheck_impl_test.gopkg/autoid_service/BUILD.bazelpkg/autoid_service/autoid_test.gopkg/ddl/BUILD.bazelpkg/ddl/integration_test.gopkg/ddl/schemaver/BUILD.bazelpkg/ddl/schemaver/syncer_nokit_test.gopkg/ddl/schemaver/syncer_test.gopkg/ddl/serverstate/BUILD.bazelpkg/ddl/serverstate/syncer_test.gopkg/domain/BUILD.bazelpkg/domain/crossks/BUILD.bazelpkg/domain/crossks/cross_ks_test.gopkg/domain/domain_test.gopkg/domain/globalconfigsync/BUILD.bazelpkg/domain/globalconfigsync/globalconfig_test.gopkg/domain/serverinfo/BUILD.bazelpkg/domain/serverinfo/syncer_test.gopkg/dxf/importinto/BUILD.bazelpkg/dxf/importinto/job_testkit_test.gopkg/executor/importer/BUILD.bazelpkg/executor/importer/importer_testkit_test.gopkg/metaservice/BUILD.bazelpkg/metaservice/etcd_test.gopkg/owner/BUILD.bazelpkg/owner/fail_test.gopkg/owner/manager_test.gopkg/server/handler/tests/BUILD.bazelpkg/server/handler/tests/http_handler_test.gopkg/session/BUILD.bazelpkg/session/bootstrap_test.gopkg/timer/BUILD.bazelpkg/timer/store_intergartion_test.gopkg/ttl/client/BUILD.bazelpkg/ttl/client/command_test.gopkg/util/cdcutil/BUILD.bazelpkg/util/cdcutil/cdc_test.gopkg/util/etcd/BUILD.bazelpkg/util/etcd/etcd_test.go
|
/retest |
74adb03 to
5402730
Compare
e92f0c2 to
e6fb0da
Compare
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: D3Hunter, winoros The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
/hold |
|
/unhold Most of the dependencies upgrade has been done in other PRs. This PR only upgrades the go.mod in |
|
Ref #69942 |
|
In response to a cherrypick label: new pull request created to branch |
What problem does this PR solve?
Issue Number: ref #70242
Problem Summary:
The parser submodule still used
golang.org/x/text v0.19.0, which is affected by CVE-2026-56852. The root module dependencies listed in #70242 have already been upgraded on the current master branch.The Prometheus upgrade was intentionally removed from this PR pending security-owner confirmation. TiDB imports
github.com/prometheus/prometheusonly frompkg/infoschema/metrics_schema_test.goto validate PromQL syntax; nogithub.com/prometheus/prometheus/*package is linked into the productiontidb-serverdependency graph. The four reported Prometheus CVEs affect the Prometheus web UI, configuration API, Azure AD remote write, and remote-read HTTP endpoint, none of which TiDB builds or exposes. Keeping the Prometheus upgrade would also forceotelgrpc v0.61.0, which is incompatible with etcd v3.5's removed interceptor APIs and previously required an unacceptable Bazel-only patch.What changed and how does it work?
pkg/parserfromgolang.org/x/text v0.19.0tov0.39.0.go mod tidy.replacedirective or third-party patch.v0.50.1,otelgrpc v0.60.0, and etcdv3.5.15while the Prometheus findings are reviewed as test-only and unreachable.Check List
Tests
./tools/check/failpoint-go-test.sh pkg/parser ./... -count=1go mod verify(cd pkg/parser && go mod verify)CC=clang CXX=clang++ make bazel_prepare(run twice; the second run leftDEPS.bzlunchanged)Side effects
Documentation
Release note
Please refer to Release Notes Language Style Guide to write a quality release note.