Skip to content

fix(deps): move to golusoris v0.13.1 and core v0.10.1 - #2656

Merged
lusoris merged 1 commit into
masterfrom
chore/golusoris-v0.13.0
Oct 9, 2026
Merged

lusoris merged 1 commit into
masterfrom
chore/golusoris-v0.13.0

Conversation

@lusoris

@lusoris lusoris commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Moves the Go module to golusoris v0.13.1 and golusoris/core v0.10.1 (from v0.12.0 and v0.9.2) and applies the breaking changes of golusoris #633 that reach VMAFx call sites. Of the packages VMAFx imports, three changed under it: jobs.Register now returns an error, testutil/pg refuses a test image without a digest, and http.limits.body=0 now keeps the 10 MiB request-body cap instead of removing it. v0.13.1 over v0.13.0 is bug fixes only; none touches a package VMAFx imports.

Migrations applied:

  • jobs.Register returns error: backend.RegisterLeaseSweep returns it and newSweepClient stops the River start on it (cmd/vmafx-controller/backend/sweep.go, cmd/vmafx-controller/store_wiring.go, the call in backend/postgres_test.go). Before, River's AddWorker panicked on a duplicate registration. New tests in backend/sweep_test.go cover a fresh registry, nil and uninitialised registries, a nil sweeper and a second registration. If the error is swallowed, both negative tests fail.
  • testutil/pg accepts only tag@sha256:<digest> images: storetest.Image and storetest.OldestImage are pinned to the multi-platform index digests of postgres:18.6-alpine and postgres:16.15-alpine. The registry's tag API and docker buildx imagetools inspect return the same digests. Without the pin, every Postgres-backed test in cmd/vmafx-controller, backend and store fails at start (testutil/pg: validate image: test image must use tag@sha256:...).
  • httpx/server: VMAFX_HTTP_LIMITS_BODY=0 now keeps the default cap, and http.limits.unlimited is the explicit opt-out. api/vmafx-platform.toml documents both. The generated env tables (docs/usage/env-vars.md, docs/server/{controller,grpc,node}.md) are regenerated, and cmd/vmafx-server/hardening_test.go pins both behaviours on the production graph.

Nothing else in the v0.13.0 migration guide (docs/migrations/v0.13.0.md in golusoris) reaches VMAFx: it uses none of the auth, cors, llm, webhooks, notify, storage, certmagic, tenancy, idempotency or workflow packages.

Type

  • feat — new feature
  • fix — bug fix
  • perf — performance improvement
  • refactor — no behavior change
  • docs — documentation only
  • test — test-only
  • build / ci — tooling / infra
  • port — cherry-pick from upstream Netflix/vmaf
  • sycl / cuda / simd — backend-specific

Checklist

  • Commits follow Conventional Commits (the commit-msg hook enforces this).
  • Every commit is signed off (git commit -s; fix a branch with git rebase --signoff origin/master). See DCO sign-off.
  • make format && make lint is green locally. Not run in full: only Go, TOML and generated Markdown changed. Ran gofmt, go vet, go fix -diff, make lint-go (the 5 gosec findings already on master, none new), scripts/codegen/vmafx-api.py --check and the pre-commit hook set.
  • Unit tests pass: python3 scripts/ci/run_meson_test.py -- -C build. Not run: no file under core/ changed. The Go suite ran instead (see Reproducer).
  • If I touched any SIMD/GPU code path, I ran /cross-backend-diff and the worst ULP is ≤ 2. No SIMD/GPU path touched.
  • If I touched a feature extractor with SIMD/GPU twins, I either updated every twin or listed the gap under "Known follow-ups" below. No extractor touched.
  • If I added a new .c / .cpp / .cu / .h / .hpp, it has the appropriate license header (see CONTRIBUTING.md). No C/C++ file added; the new Go test file carries the EUPL-1.2 header.
  • If this is a breaking change, the commit message uses ! or BREAKING CHANGE: and the migration path is documented below. Not breaking for VMAFx users; see "Breaking changes / migration" for the one changed setting.
  • If this PR adds an ADR, the ADR row lives in docs/adr/_index_fragments/<NNNN-slug>.md and nothing else is touched for the index. No ADR.

Bug-status hygiene (ADR-0165)

  • docs/state.md updated in this PR with a row in the appropriate section (Open / Recently closed / Confirmed not-affected / Deferred). Not needed — no state delta: dependency bump with call-site migrations; no bug opened, closed or ruled out.

Netflix golden-data gate (ADR-0024)

  • I did not modify any assertAlmostEqual(...) score in the Netflix golden Python tests, except by porting Netflix's own updated assertion verbatim from upstream.
  • If I believe a golden value must change, I have explained why below AND pinged @lusoris for a CODEOWNERS exception. Not applicable.

Cross-backend numerical results

Not applicable: no scoring code changed.

Deep-dive deliverables (ADR-0108)

  • Research digest — no digest needed: dependency bump; the migrations follow golusoris docs/migrations/v0.13.0.md and the fix(mcp-server): asyncio.current_task() guard + sync ffprobe in async path + bare-except gather #633 commit body.
  • Decision matrix — no alternatives: only-one-way fix (each migration is dictated by the new golusoris API).
  • AGENTS.md invariant note — cmd/vmafx-controller/AGENTS.md (storetest images stay tag@sha256; a tag bump changes the digest in the same edit).
  • Reproducer / smoke-test command — see "Reproducer" below.
  • CHANGELOG fragment — changelog.d/changed/golusoris-v0.13.1.md.
  • Rebase note — no rebase impact: fork-only Go module and Go call sites; no Netflix upstream file touched.

Reproducer

meson setup core/build-cpu core -Denable_cuda=false -Denable_sycl=false -Denable_hip=false \
  -Denable_metal=disabled -Denable_avx512=false -Denable_dnn=enabled $(scripts/ci/werror-args.sh true)
ninja -C core/build-cpu
export CGO_LDFLAGS="-L$PWD/core/build-cpu/src -lvmaf -lvmafx -lm" LD_LIBRARY_PATH="$PWD/core/build-cpu/src"
go build ./... && go vet ./... && go fix -diff ./...
go test -count=1 ./...
go test -count=1 -run 'RegisterLeaseSweep|BodyLimit' ./cmd/vmafx-controller/backend/ ./cmd/vmafx-server/
python3 scripts/ci/govulncheck-gate.py
make lint-go
python3 scripts/codegen/vmafx-api.py --check

Known follow-ups

  • golusoris v0.13 ships capabilities VMAFx still implements locally (gRPC keepalive config, grpc.CompoundKeys(), core/retry, River lifecycle and drain in jobs.Module, the k8s/health readiness drain, the observability metric catalog and its dashboard and rule generators, testutil/promcheck, gRPC client TLS from config). Moving to them is out of scope for a version bump and is tracked under the RC4 cloud-native issue (RC4 — Cloud-native platform: Postgres (CNPG) + River, two-tier cache, OCI artifacts, queue-driven scaling, generated from the API #2431).
  • The new golusoris gRPC keys (grpc.ca_file, grpc.client_auth, grpc.keepalive.*, grpc.health, grpc.client.*) are not yet reachable through VMAFX_* variables: underscore-bearing keys need entries in api/vmafx-platform.toml.
  • No Renovate manager tracks the storetest image digests; a tag bump is manual, as it was before.

Breaking changes / migration

VMAFX_HTTP_LIMITS_BODY=0 on vmafx-server, vmafx-controller or vmafx-node no longer removes the request-body cap; it keeps the 10 MiB default. To serve bodies of any size, set VMAFX_HTTP_LIMITS_UNLIMITED=true. No shipped chart or default sets the variable to 0.

* fix(deps): move to golusoris v0.13.1 and core v0.10.1

Moves the Go module from golusoris v0.12.0 and core v0.9.2 to v0.13.1 and
v0.10.1, and applies the breaking changes of golusoris#633 that reach VMAFx
call sites:

- jobs.Register returns an error. backend.RegisterLeaseSweep returns it and
  the controller stops the River start on it, where River used to panic on a
  duplicate registration. sweep_test.go covers fresh, nil and uninitialised
  registries, a nil sweeper and a second registration.
- testutil/pg refuses a test image without a digest. storetest.Image and
  OldestImage are pinned to the index digests of postgres:18.6-alpine and
  postgres:16.15-alpine; without the pin every Postgres-backed controller
  test fails at start.
- httpx/server treats http.limits.body=0 as the 10 MiB default and adds
  http.limits.unlimited. The platform definition documents both keys, the
  env tables are regenerated, and hardening_test.go pins both behaviours on
  the production graph.

No other item of the golusoris v0.13.0 migration guide reaches a package
VMAFx imports. v0.13.1 over v0.13.0 is bug fixes in packages VMAFx does not
import.

Signed-off-by: Lusoris <lusoris@proton.me>
@lusoris
lusoris force-pushed the chore/golusoris-v0.13.0 branch from 0377d19 to f231bd1 Compare October 9, 2026 09:53
@lusoris
lusoris merged commit f231bd1 into master Oct 9, 2026
12 of 37 checks passed
@lusoris
lusoris deleted the chore/golusoris-v0.13.0 branch October 9, 2026 09:56
lusoris added a commit that referenced this pull request Oct 9, 2026
…ovate (#2670)

* chore(deps): track the store tests' PostgreSQL image digests with Renovate

#2656 pins storetest.Image and storetest.OldestImage as
postgres:<tag>@sha256:<digest> Go constants, because golusoris
testutil/pg refuses an undigested image. No built-in Renovate manager
reads a Go string, so neither digest would ever be updated: a full
local extraction with the master config never lists storetest.go.

A regex custom manager (depNameTemplate postgres) matches both
constants; Renovate 44.56.3 extracts them with tag and digest and, for
planted older tags, proposes minor, major and digest updates for Image
and only 16.x updates for OldestImage, which a package rule holds on
its major line. Two fixture tests evaluate the configured patterns.
The JavaScript-to-Python named-group conversion three Renovate tests
each spelled moves to scripts/lib/renovate_regex.py.

Signed-off-by: Lusoris <lusoris@proton.me>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type:bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant