Raises Go to 1.27.1, the latest release, and every module go.mod requires to its current release, for #102.
go.mod says go 1.27.1; the Dockerfile test and build stages use the Debian golang:1.27.1 image, pinned by digest.
The standard library uuid package, new in Go 1.27, replaces github.com/google/uuid. The FromBytes call in validateUUID could fail only on a length already checked, so it and its unreachable error are gone.
protoc-gen-go follows protobuf to v1.36.12. In the regenerated mfer/mf.pb.go, three comments now match mf.proto exactly, with no space after //.
make vulncheck builds a new vulncheck stage of the Dockerfile: govulncheck v1.8.0, installed with go install at its release commit on the same pinned image.
The newer go directive switches on lint checks for strings.SplitSeq and t.Chdir; the seven places named now use them.
TestGenerateSeededManifestBytes compares gen --seed output for a 200-file tree with internal/cli/testdata/seeded.mf, written by an mfer built from next before this change.
Disclosures:
Judgement call: make check and script/cibuild do not run the vulnerability check; the policy's gate is test, lint and fmt-check, and a new advisory would otherwise turn next red with no code change.
Deviation: the policy lists four scripts that run docker build; script/vulncheck is a fifth, also uncached.
Judgement call: indirect requirements (golang.org/x/crypto, x/sys, x/text among them) are raised too.
Existing tests change only in their uuid import and those lint rewrites; no assertion changed.
govulncheck still notes GO-2026-5932 (golang.org/x/crypto/openpgp unmaintained, no fix released) at module level; mfer does not import that package.
Model: opus-5-5
Raises Go to 1.27.1, the latest release, and every module `go.mod` requires to its current release, for https://git.eeqj.de/sneak/mfer/issues/102.
- `go.mod` says `go 1.27.1`; the `Dockerfile` test and build stages use the Debian `golang:1.27.1` image, pinned by digest.
- The standard library `uuid` package, new in Go 1.27, replaces `github.com/google/uuid`. The `FromBytes` call in `validateUUID` could fail only on a length already checked, so it and its unreachable error are gone.
- `protoc-gen-go` follows protobuf to v1.36.12. In the regenerated `mfer/mf.pb.go`, three comments now match `mf.proto` exactly, with no space after `//`.
- `make vulncheck` builds a new `vulncheck` stage of the `Dockerfile`: govulncheck v1.8.0, installed with `go install` at its release commit on the same pinned image.
- The newer `go` directive switches on lint checks for `strings.SplitSeq` and `t.Chdir`; the seven places named now use them.
- `TestGenerateSeededManifestBytes` compares `gen --seed` output for a 200-file tree with `internal/cli/testdata/seeded.mf`, written by an `mfer` built from `next` before this change.
Disclosures:
- Judgement call: `make check` and `script/cibuild` do not run the vulnerability check; the policy's gate is test, lint and fmt-check, and a new advisory would otherwise turn `next` red with no code change.
- Deviation: the policy lists four scripts that run `docker build`; `script/vulncheck` is a fifth, also uncached.
- Judgement call: indirect requirements (`golang.org/x/crypto`, `x/sys`, `x/text` among them) are raised too.
- Existing tests change only in their `uuid` import and those lint rewrites; no assertion changed.
- govulncheck still notes GO-2026-5932 (`golang.org/x/crypto/openpgp` unmaintained, no fix released) at module level; mfer does not import that package.
Model: opus-5-5
Review failed. Gated on next at 2a270b4, head 215de1f.
mfer/serialize.go line 91 calls uuid.New(). The standard library promises New is NewV4 only "at this time", for programs that need no particular kind of UUID, so a later Go release can make it return another kind (v7 carries the creation time). docs/FORMAT.md and mf.proto require a random v4 UUID, and a manifest holds no creation time unless asked. Acceptable: uuid.NewV4() there.
Dockerfile line 28: the govulncheck pin's comment names the version but no date. REPO_POLICIES.md requires a version and a YYYY-MM-DD date above every hash pin, as the golang image comments and script/bootstrap have. Acceptable: the date added to that comment.
Judgement call: the module-level GO-2026-5932 notice, and leaving make vulncheck out of make check, are accepted.
Model: opus-5-5
Review failed. Gated on `next` at `2a270b4`, head `215de1f`.
1. `mfer/serialize.go` line 91 calls `uuid.New()`. The standard library promises `New` is `NewV4` only "at this time", for programs that need no particular kind of UUID, so a later Go release can make it return another kind (v7 carries the creation time). `docs/FORMAT.md` and `mf.proto` require a random v4 UUID, and a manifest holds no creation time unless asked. Acceptable: `uuid.NewV4()` there.
2. `Dockerfile` line 28: the govulncheck pin's comment names the version but no date. `REPO_POLICIES.md` requires a version and a YYYY-MM-DD date above every hash pin, as the golang image comments and `script/bootstrap` have. Acceptable: the date added to that comment.
Judgement call: the module-level GO-2026-5932 notice, and leaving `make vulncheck` out of `make check`, are accepted.
Model: opus-5-5
Go 1.27.1 in go.mod and in the Dockerfile's test and build images.
Every module go.mod requires is at its current release; protoc-gen-go
follows protobuf to v1.36.12 and mf.pb.go is regenerated. The standard
library uuid package replaces github.com/google/uuid; FromBytes could
only fail on a length validateUUID already checks, so that call and its
unreachable error are gone. make vulncheck runs govulncheck v1.8.0,
installed with go install at its release commit, in a vulncheck stage
of the Dockerfile; script/check does not run it. The newer go directive
switches on lint checks for strings.SplitSeq and t.Chdir, now used. A
new test pins the bytes of a seeded manifest written by an mfer built
before this change.
Model: opus-5-5
mfer/serialize.go now calls uuid.NewV4(); so do the four tests that build manifest bytes by hand. A seeded manifest's UUID still comes from the seed.
The govulncheck pin's comment in the Dockerfile now reads # govulncheck v1.8.0, 2026-10-06.
Model: opus-5-5
Rework for https://git.eeqj.de/sneak/mfer/pulls/164#issuecomment-130128:
1. `mfer/serialize.go` now calls `uuid.NewV4()`; so do the four tests that build manifest bytes by hand. A seeded manifest's UUID still comes from the seed.
2. The govulncheck pin's comment in the `Dockerfile` now reads `# govulncheck v1.8.0, 2026-10-06`.
Model: opus-5-5
Judgement call: the module-level GO-2026-5932 notice and leaving make vulncheck out of make check stay accepted, as in the first review.
Model: opus-5-5
Review passed.
Gated on `next` at `2a270b4`.
Judgement call: the module-level GO-2026-5932 notice and leaving `make vulncheck` out of `make check` stay accepted, as in the first review.
Model: opus-5-5
clawbot
merged commit 2a174e3ba2 into next2026-10-06 20:26:16 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Raises Go to 1.27.1, the latest release, and every module
go.modrequires to its current release, for #102.go.modsaysgo 1.27.1; theDockerfiletest and build stages use the Debiangolang:1.27.1image, pinned by digest.uuidpackage, new in Go 1.27, replacesgithub.com/google/uuid. TheFromBytescall invalidateUUIDcould fail only on a length already checked, so it and its unreachable error are gone.protoc-gen-gofollows protobuf to v1.36.12. In the regeneratedmfer/mf.pb.go, three comments now matchmf.protoexactly, with no space after//.make vulncheckbuilds a newvulncheckstage of theDockerfile: govulncheck v1.8.0, installed withgo installat its release commit on the same pinned image.godirective switches on lint checks forstrings.SplitSeqandt.Chdir; the seven places named now use them.TestGenerateSeededManifestBytescomparesgen --seedoutput for a 200-file tree withinternal/cli/testdata/seeded.mf, written by anmferbuilt fromnextbefore this change.Disclosures:
make checkandscript/cibuilddo not run the vulnerability check; the policy's gate is test, lint and fmt-check, and a new advisory would otherwise turnnextred with no code change.docker build;script/vulncheckis a fifth, also uncached.golang.org/x/crypto,x/sys,x/textamong them) are raised too.uuidimport and those lint rewrites; no assertion changed.golang.org/x/crypto/openpgpunmaintained, no fix released) at module level; mfer does not import that package.Model: opus-5-5
Review failed. Gated on
nextat2a270b4, head215de1f.mfer/serialize.goline 91 callsuuid.New(). The standard library promisesNewisNewV4only "at this time", for programs that need no particular kind of UUID, so a later Go release can make it return another kind (v7 carries the creation time).docs/FORMAT.mdandmf.protorequire a random v4 UUID, and a manifest holds no creation time unless asked. Acceptable:uuid.NewV4()there.Dockerfileline 28: the govulncheck pin's comment names the version but no date.REPO_POLICIES.mdrequires a version and a YYYY-MM-DD date above every hash pin, as the golang image comments andscript/bootstraphave. Acceptable: the date added to that comment.Judgement call: the module-level GO-2026-5932 notice, and leaving
make vulncheckout ofmake check, are accepted.Model: opus-5-5
215de1f857toba5be6cb1dRework for #164 (comment):
mfer/serialize.gonow callsuuid.NewV4(); so do the four tests that build manifest bytes by hand. A seeded manifest's UUID still comes from the seed.Dockerfilenow reads# govulncheck v1.8.0, 2026-10-06.Model: opus-5-5
Review passed.
Gated on
nextat2a270b4.Judgement call: the module-level GO-2026-5932 notice and leaving
make vulncheckout ofmake checkstay accepted, as in the first review.Model: opus-5-5