Skip to content

Fix stdlib detection across Go toolchain versions - #364

Open
Ahmetshbzz wants to merge 1 commit into
google:masterfrom
Ahmetshbzz:fix/active-toolchain-goroot
Open

Fix stdlib detection across Go toolchain versions#364
Ahmetshbzz wants to merge 1 commit into
google:masterfrom
Ahmetshbzz:fix/active-toolchain-goroot

Conversation

@Ahmetshbzz

Copy link
Copy Markdown

Summary

  • resolve GOROOT from the active go command used for package loading
  • classify standard-library files relative to the active GOROOT/src
  • reject path-prefix collisions and preserve the unsafe special case
  • add regression coverage for binaries built with a different Go toolchain root

Problem

isStdLib currently reads build.Default.GOROOT, which belongs to the toolchain that compiled the go-licenses binary. When that prebuilt binary scans a module through a different or auto-downloaded Go toolchain, packages.Load returns standard-library files from the active toolchain GOROOT. The paths no longer match, so standard-library packages are treated as third-party packages without module metadata.

This reproduces the Package ... does not have module info failures reported in #302 and #335.

Verification

  • go test ./licenses ./internal/...
  • go vet ./...
  • built the patched binary with -ldflags "-X runtime.defaultGOROOT=/tmp/go-licenses-build-toolchain" and ran go-licenses csv ./... with Go 1.26.6; no standard-library module-info errors were emitted
  • go test ./... reaches the existing E2E suite but locally has an unrelated golden drift for golang.org/x/sys (golang.org/x/sys versus golang.org/x/sys/unix)
  • current local golangci-lint reports 15 pre-existing findings outside this change

Fixes #302
Fixes #335

Resolve GOROOT through the same go command used by package loading instead of relying on the tool build-time go/build default. This keeps standard-library detection correct when a prebuilt go-licenses binary scans a module with a newer downloaded toolchain.

Use filepath.Rel against GOROOT/src to avoid path-prefix collisions and add regression coverage for mismatched build and active toolchain roots, prefix collisions, and the unsafe package special case.
@google-cla

google-cla Bot commented Aug 15, 2026

Copy link
Copy Markdown

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

@Ahmetshbzz

Copy link
Copy Markdown
Author

I have completed the Google Individual Contributor License Agreement. The CLA check still appears to show the earlier failed invocation; please let me know if any additional action is required on my side.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Misinterprets ./... and checks stdlib unless on go 1.25 E0918 error for stdlib imports: "Package bytes does not have module info"

1 participant