Migrate YAML parsers and backport production dependency owners - #535
Open
ai-collaboration-app[bot] wants to merge 9 commits into
Open
ai-collaboration-app[bot] wants to merge 9 commits into
ai-collaboration-app[bot] wants to merge 9 commits into
Conversation
Keep Kubernetes collection/configuration on the v2 API and installer/test parsing on v3. Replace Windows ghodss conversions with sigs.k8s.io/yaml v1.6.0, preserving YAML-to-JSON schema validation and JSON behavior. Upgrade Testify to v1.12.1 to remove its legacy parser import from both production-reachable helpers and tests. Its maintained v3 requirement advances the workspace to v3.0.5; synchronize and tidy registered modules without changing ignored or unregistered dependency fixtures. Add configuration fixtures for aliases, merges, multiline strings, boolean and integer interpretation, and explicit nulls. Correct stale development commands and maintained-parser references in active documentation. Kubernetes parser/event regressions, installer, profiler, configuration and core telemetry/configuration tests pass. The root and 185 registered submodules tidy successfully. Existing Windows configuration fixtures retain identical JSON conversion. Product package graphs resolve on Linux amd64/arm64. A native cluster-agent amd64 build passes with pinned Go 1.26.6. Diff-aware root lint and the changed installer package lint pass; broader lint retains pre-existing findings. The Kubernetes bundled-events timeout and inherited Windows compile errors also occur at baseline dd1cba0. Transitive NetFlow, ordered-map, Cloud Foundry and Datadog OPA parser imports remain; Windows E2E tooling retains Pulumi/ESC dependencies. No blanket parser replacement or upstream agent upgrade is applied. Tracking: StackVista/stackstate#717
The repository check-mod-tidy workflow identifies 28 redundant indirect requirements for go-internal and 44 missing module checksum entries after workspace synchronization. Apply its normalized metadata without changing selected dependency versions or parser identities. Keep ignored and unregistered module fixtures untouched. Diff-aware lint passes with the pinned Go 1.26.6 toolchain. The complete module consistency check and native build provenance are qualified in the handoff result. Tracking: StackVista/stackstate#717
Compatible releases still select legacy YAML: goflow2 v1.3.8 remains on legacy v3, ordered-map latest is v2.1.8, go-cfclient's tagged v2.0.0 is older than the selected pseudo-version, and Datadog lightweight OPA is still d2e1e78e0816. Retain the selected exact sources, licenses and tests; change only matching parser imports and required test module metadata. Root and workspace explicitly select all four modules. The independent network-device profile module selects ordered-map too. No old parser module replacement is added. Preserve Datadog OPA lightweight patches. This signed checkpoint preserves source before long upstream and native consumer validation. Qualification is pending and will follow separately. Tracking: StackVista/stackstate#717
Retain OPA source tools and public test-only TLS keys/fixtures that the agent's root ignore rules otherwise omit. These files come unchanged from DataDog/opa d2e1e78e081663d4b11109032715b68eb9b9d17a. All three smaller owner suites pass with GOWORK=off. OPA AST, util, loader, configuration and strvals suites pass. Bundle fixtures pass with vet off; its two fatal-format vet errors reproduce on unmodified Datadog source. Tidy each independent backport without changing non-parser dependency versions. Cobra's documentation generator retains a test/tool legacy v3 requirement in standalone OPA, distinct from selected product packages. Tracking: StackVista/stackstate#717
Preserve 124 long upstream fixture/document paths byte-for-byte in module LONG_PATHS archives with SHA256 manifests and restoration instructions. No Go source or production embedded resource is archived. Filename lint passes without changing its Windows path limit or weakening any gate. Select source owners explicitly in go.work through replacements instead of registering external modules as workspace main modules. This prevents go work sync from rewriting their independent dependency minima while retaining the explicit root and profile consumer selections. NetFlow adapter/server and unbranded profiledefinition contracts pass. Profile schema repository-ID mismatches reproduce at prior d3ff12d. All owner source edits remain limited to matching YAML imports; original Datadog OPA patches, upstream fixtures and licenses are retained. Tracking: StackVista/stackstate#717
Tidy all 186 registered modules after explicit owner selection. Remove unused transitive requirements from root/profile without changing their selected non-parser dependencies. Upgrade standalone OPA's Cobra tooling to v1.10.2, already selected by the agent, for its maintained YAML docs encoder. The independent backports retain their original Go minima. All three smaller upstream suites and OPA AST/config/YAML fixtures pass; OPA bundle tests require vet off for two reproduced upstream assertions. NetFlow/server, Cloud Foundry/autodiscovery, standalone/workspace profile contracts, full compliance with fixture-appropriate process-local umask, and Kubernetes contracts pass. All 21 configuration profiles round-trip. Add durable source provenance, restoration commands, parser identity and reproduced packaging/tooling limitations. Native linking and final module consistency/CI qualification continue against this signed checkpoint. Tracking: StackVista/stackstate#717
Verify curl.se CA-extract dated publication and cacert-2026-09-25.pem.sha256: a41b5d356aea97a529fe27e0f7316d2f9d946d75927476cf9cf1b90637d00505, 188900 bytes, 121 certificates. Preserve target filename, trust paths, modes and checksum enforcement. Tracking: StackVista/stackstate#717
Initial supported bazel mod tidy prunes removed ghodss/legacy parser imports and adds ordered-map. Link third_party into the filtered workspace so local owner replacements resolve; exclude retained upstream trees from root Gazelle generation. Tracking: StackVista/stackstate#717
Supported workspace sync, registered tidy, second mod tidy and Gazelle generation pass without BUILD or Go manifest drift. Four local owner repositories and maintained parser identities verified; actual Omnibus OpenSSL install target passes analysis. Tracking: StackVista/stackstate#717
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Migrate matching YAML APIs with exact-source owner backports and explicit selections; preserve Windows JSON conversion. Pin the verified dated CA bundle and reconcile Bazel metadata/local replacements.
Tracking: https://github.com/StackVista/stackstate/issues/717
Reviewed head d6ac306 passes full lint/unit and both-architecture binaries. Real amd64 DEB binary uses maintained parsers and runs its version command; trust bundle/hash/mode/symlink verified. Both cluster images pass smoke and inform-mode vulnerability/secret scans. DEB run 36866263588 attempt 2 is the single authorized rerun after missing arm64 logs; arm64/package-dependent agent images remain pending. Source evidence: docs/dev/go-yaml-owner-backports.md. No release/adoption claim.