Skip to content

replace x/mod semver with local implementation - #320

Open
tariq1890 wants to merge 1 commit into
containerd:mainfrom
tariq1890:remove-x-mod-dep
Open

tariq1890 wants to merge 1 commit into
containerd:mainfrom
tariq1890:remove-x-mod-dep

Conversation

@tariq1890

@tariq1890 tariq1890 commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Motivation

golang.org/x/mod is a pretty big dependency as its scope extends beyond semver. Considering that the semver parsing requirements are minimal, importing a third party module may not be all that necessary.

With this change, we decrease the CVE surface further as golang.org/x/mod is known to have CVEs. Moreover, this change shaves off one dependency from the dep-tree which is a win.

@thaJeztah thaJeztah left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks! I like this; I think this looks like a reasonable alternative for this repo.

I found some issues, and left some suggestions; feel free to take those and amend your commit (no need to use a second commit for it, because we'd probably ask you to squash those anyway)

Comment thread pkg/version/version.go Outdated
Comment thread pkg/version/version.go Outdated
Comment thread pkg/version/version.go Outdated
Comment thread pkg/version/version.go Outdated

@thaJeztah thaJeztah left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thx!

left a minor comment

@tariq1890

Copy link
Copy Markdown
Contributor Author

@thaJeztah Thank you for the lightning fast reviews!

@tariq1890
tariq1890 requested a review from thaJeztah September 24, 2026 17:52
@thaJeztah

Copy link
Copy Markdown
Member

Thanks!

klihub
klihub previously approved these changes Sep 25, 2026

@klihub klihub left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

SemVer parsing and prerelease ordering have correctness issues, and one module contains unrelated dependency upgrades.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 2 Medium severity

Open (2)
What changed in this PR

Replaces golang.org/x/mod/semver with a local SemVer implementation.

Changes:

  • Adds local version parsing, comparison, and tests.
  • Removes x/mod metadata across modules.
  • Refreshes network-device-injector dependencies.
File Summary
plugins/​writable-cgroups/​go.sum Removes dependency checksums.
plugins/​writable-cgroups/​go.mod Removes x/mod.
plugins/​wasm/​go.sum Removes dependency checksums.
plugins/​wasm/​go.mod Removes x/mod.
plugins/​ulimit-adjuster/​go.sum Removes dependency checksums.
plugins/​ulimit-adjuster/​go.mod Removes x/mod.
plugins/​template/​go.sum Removes dependency checksums.
plugins/​template/​go.mod Removes x/mod.
plugins/​rdt/​go.sum Removes dependency checksums.
plugins/​rdt/​go.mod Removes x/mod.
plugins/​network-logger/​go.sum Removes dependency checksums.
plugins/​network-logger/​go.mod Removes x/mod.
plugins/​network-device-injector/​go.sum Refreshes dependency checksums.
plugins/​network-device-injector/​go.mod Removes x/mod and updates dependencies.
plugins/​logger/​go.sum Removes dependency checksums.
plugins/​logger/​go.mod Removes x/mod.
plugins/​hook-injector/​go.sum Removes dependency checksums.
plugins/​hook-injector/​go.mod Removes x/mod.
plugins/​differ/​go.sum Removes dependency checksums.
plugins/​differ/​go.mod Removes x/mod.
plugins/​device-injector/​go.sum Removes dependency checksums.
plugins/​device-injector/​go.mod Removes x/mod.
pkg/​version/​version.go Adds local SemVer parsing and comparison.
pkg/​version/​version_test.go Tests version comparison.
go.sum Removes x/mod checksums.
go.mod Removes the x/mod dependency.
examples/​go.sum Removes x/mod checksums.
examples/​go.mod Removes the x/mod dependency.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread pkg/version/version.go Outdated
Comment thread pkg/version/version.go Outdated
Comment thread pkg/version/version.go Outdated
Comment thread pkg/version/version.go Outdated
@tariq1890
tariq1890 force-pushed the remove-x-mod-dep branch 3 times, most recently from c6f197c to 55d33f0 Compare October 4, 2026 04:47
@tariq1890

Copy link
Copy Markdown
Contributor Author

@samuelkarp Sorry for the delayed response, I've addressed the Copilot review comments. Requesting another round of review

@klihub
klihub requested review from klihub and a lite review from Copilot October 4, 2026 08:51
@klihub

klihub commented Oct 4, 2026

Copy link
Copy Markdown
Member

@tariq1890 We've had several issues in this replacement implementation which at least I missed totally in the previous review round, some potential divergences from semver.Compare(). So I think it would make sense to lift over the test corpus from https://cs.opensource.google/go/x/mod/+/master:semver/semver_test.go and make sure our version comparison agrees with semver.Compare() for the relevant cases:

var tests = []struct {
	in  string
	out string
}{
	{"bad", ""},
	{"v1-alpha.beta.gamma", ""},
	{"v1-pre", ""},
	{"v1+meta", ""},
	{"v1-pre+meta", ""},
	{"v1.2-pre", ""},
	{"v1.2+meta", ""},
	{"v1.2-pre+meta", ""},
	{"v1.0.0-alpha", "v1.0.0-alpha"},
	{"v1.0.0-alpha.1", "v1.0.0-alpha.1"},
	{"v1.0.0-alpha.beta", "v1.0.0-alpha.beta"},
	{"v1.0.0-beta", "v1.0.0-beta"},
	{"v1.0.0-beta.2", "v1.0.0-beta.2"},
	{"v1.0.0-beta.11", "v1.0.0-beta.11"},
	{"v1.0.0-rc.1", "v1.0.0-rc.1"},
	{"v1", "v1.0.0"},
	{"v1.0", "v1.0.0"},
	{"v1.0.0", "v1.0.0"},
	{"v1.2", "v1.2.0"},
	{"v1.2.0", "v1.2.0"},
	{"v1.2.3-456", "v1.2.3-456"},
	{"v1.2.3-456.789", "v1.2.3-456.789"},
	{"v1.2.3-456-789", "v1.2.3-456-789"},
	{"v1.2.3-456a", "v1.2.3-456a"},
	{"v1.2.3-pre", "v1.2.3-pre"},
	{"v1.2.3-pre+meta", "v1.2.3-pre"},
	{"v1.2.3-pre.1", "v1.2.3-pre.1"},
	{"v1.2.3-zzz", "v1.2.3-zzz"},
	{"v1.2.3", "v1.2.3"},
	{"v1.2.3+meta", "v1.2.3"},
	{"v1.2.3+meta-pre", "v1.2.3"},
	{"v1.2.3+meta-pre.sha.256a", "v1.2.3"},
}

@klihub
klihub dismissed their stale review October 4, 2026 09:04

I'd suggest pulling in the test corpus from mod/x/semver and making sure our comparison implementation agrees semver.Compare() for the relevant cases.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The local SemVer implementation has compatibility and large-version handling issues that must be addressed before approval.

Review effort: Lite
Findings: 1 Medium severity

Open (1)
Resolved since last review (2)

Comment thread pkg/version/version.go Outdated

@klihub klihub left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please update the tests.

@tariq1890
tariq1890 requested review from klihub and a lite review from Copilot October 4, 2026 18:43

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Revert the unrelated x/net and x/tools dependency changes in network-device-injector.

Review effort: Lite
Findings: None

Resolved since last review (1)

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The dependency remains declared in the network-device-injector module and its checksums.

Review effort: Lite
Findings: 1 Medium severity

Open (1)

Comment thread go.mod
@tariq1890
tariq1890 force-pushed the remove-x-mod-dep branch 2 times, most recently from d8e81fd to 8b6c661 Compare October 4, 2026 19:03
@tariq1890
tariq1890 requested a lite review from Copilot October 4, 2026 19:05

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Regenerate the network-device-injector sums and fix Git-described versions with build metadata.

Review effort: Lite
Findings: 1 Medium severity · 1 Low severity

Open (2)

Comment thread plugins/network-device-injector/go.mod
Signed-off-by: Tariq Ibrahim <tibrahim@nvidia.com>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

All reviewed changes have no unresolved blocking issues.

Review effort: Lite
Findings: 1 Medium severity · 1 Low severity

Open (2)

@tariq1890

Copy link
Copy Markdown
Contributor Author

@klihub I've added the x/mod test cases and addressed comments from copilot.

@tariq1890
tariq1890 requested a review from samuelkarp October 4, 2026 19:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants