Skip to content

Build go-licenses with the same toolchain as the main module - #1003

Open
tiffanny29631 wants to merge 1 commit into
kubernetes:masterfrom
tiffanny29631:makefile
Open

tiffanny29631 wants to merge 1 commit into
kubernetes:masterfrom
tiffanny29631:makefile

Conversation

@tiffanny29631

@tiffanny29631 tiffanny29631 commented Sep 18, 2026 •

Copy link
Copy Markdown

/kind bug
go-licenses decides whether a package is stdlib by comparing it against the GOROOT it was compiled with (isStdLib). The Makefile builds go-licenses from tools/ but runs it on the main module, and with GOTOOLCHAIN=auto those can resolve to different toolchains (tools/go.mod has toolchain go1.24.1, go.mod has go 1.25.0). When they differ, every stdlib package fails with "does not have module info" and make container fails.
CI doesn't hit this because it pins Go 1.25.x. Any host Go older than the main module's go line reproduces it:
docker run --rm -e GOTOOLCHAIN=auto -v "$PWD":/src -w /src golang:1.23.0 make .licenses
E... library.go:159] Package net/url does not have module info. Non go modules projects are no longer supported...
F... main.go:75] some errors occurred when loading direct and transitive dependency packages
This pins GOTOOLCHAIN for the tools build to the version the main module resolves to (go env GOVERSION in the repo root), so both steps use the same GOROOT. Tested with golang:1.23.0, 1.24, and 1.25 (GOTOOLCHAIN=auto and local).

Dropped the earlier toolchain removal (it didn't fix the mismatch) and the CI step (per review).

@kubernetes-prow kubernetes-prow Bot added kind/bug Categorizes issue or PR as related to a bug. kind/cleanup Categorizes issue or PR as related to cleaning up code, process, or technical debt. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. labels Sep 18, 2026
@kubernetes-prow

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: tiffanny29631
Once this PR has been reviewed and has the lgtm label, please assign stp-ip for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@kubernetes-prow
kubernetes-prow Bot requested review from sdowell and stp-ip September 18, 2026 23:57
@kubernetes-prow kubernetes-prow Bot added the size/S Denotes a PR that changes 10-29 lines, ignoring generated files. label Sep 18, 2026
@tiffanny29631 tiffanny29631 changed the title tools: align toolchain with root go.mod and verify licenses in CI fix: align toolchain with root go.mod and verify licenses in CI Sep 19, 2026
Comment thread .github/workflows/main.yml Outdated
- name: Check licenses
working-directory: git-sync
run: |
make licenses

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This doesn't verify licenses, this generates licenses

What is the intent of the change?

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The target is removed and change is reworked.

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

CI already uses a Go new enough for both modules it couldn't catch this anyway. I dropped the CI step and the tools/go.mod change. The PR is now just the Makefile fix.

@thockin

thockin commented Sep 19, 2026

Copy link
Copy Markdown
Member

fixes a build failure during make container

Can you explain more? It doesn't fail for me.

go-licenses decides whether a package is part of the standard library by
comparing its directory against the GOROOT it was compiled with.  The
Makefile builds go-licenses from the tools/ module but runs it against the
main module, and with GOTOOLCHAIN=auto those can resolve to different
toolchains (tools/go.mod has `toolchain go1.24.1`, go.mod has `go 1.25.0`).
When that happens every stdlib package is reported as "does not have module
info" and `make container` fails.

This does not show up in CI because CI pins a Go version that satisfies
both modules, but it reproduces with any host Go older than the main
module's `go` line:

    docker run --rm -e GOTOOLCHAIN=auto -v "$PWD":/src -w /src \
        golang:1.23.0 make .licenses

Pin GOTOOLCHAIN for the tools build to the version the main module
resolves to, so both steps use the same GOROOT.
@kubernetes-prow kubernetes-prow Bot added size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. and removed size/S Denotes a PR that changes 10-29 lines, ignoring generated files. labels Oct 7, 2026
@tiffanny29631

Copy link
Copy Markdown
Author

fixes a build failure during make container

Can you explain more? It doesn't fail for me.

Sorry, the original description was thin, and the original change didn't actually fix the root cause. I've reworked the PR. It fails when the host Go is older than the main module's go line and GOTOOLCHAIN=auto (the default for tarball installs; our CI image has Go 1.23.0). tools/ then builds go-licenses with one toolchain and go list ./... runs with another, and go-licenses misclassifies every stdlib package because it compares against its compiled-in GOROOT. Repro:

docker run --rm -e GOTOOLCHAIN=auto -v "$PWD":/src -w /src golang:1.23.0 make .licenses

CI doesn't hit it because it pins Go 1.25.x. The fix is one line: build go-licenses with whatever toolchain the main module resolves to.

@tiffanny29631 tiffanny29631 changed the title fix: align toolchain with root go.mod and verify licenses in CI Build go-licenses with the same toolchain as the main module Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. kind/bug Categorizes issue or PR as related to a bug. kind/cleanup Categorizes issue or PR as related to cleaning up code, process, or technical debt. size/XS Denotes a PR that changes 0-9 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants