Raise Go to the latest release, update dependencies, use the standard library uuid, add a vulnerability check (closes #102) #164

Merged
clawbot merged 1 commits from issue-102-go-latest into next 2026-10-06 20:26:16 +02:00
Collaborator

Raises Go to 1.27.1, the latest release, and every module go.mod requires to its current release, for #102.

  • go.mod says go 1.27.1; the Dockerfile test and build stages use the Debian golang:1.27.1 image, pinned by digest.
  • The standard library uuid package, new in Go 1.27, replaces github.com/google/uuid. The FromBytes call in validateUUID could fail only on a length already checked, so it and its unreachable error are gone.
  • protoc-gen-go follows protobuf to v1.36.12. In the regenerated mfer/mf.pb.go, three comments now match mf.proto exactly, with no space after //.
  • make vulncheck builds a new vulncheck stage of the Dockerfile: govulncheck v1.8.0, installed with go install at its release commit on the same pinned image.
  • The newer go directive switches on lint checks for strings.SplitSeq and t.Chdir; the seven places named now use them.
  • TestGenerateSeededManifestBytes compares gen --seed output for a 200-file tree with internal/cli/testdata/seeded.mf, written by an mfer built from next before this change.

Disclosures:

  • Judgement call: make check and script/cibuild do not run the vulnerability check; the policy's gate is test, lint and fmt-check, and a new advisory would otherwise turn next red with no code change.
  • Deviation: the policy lists four scripts that run docker build; script/vulncheck is a fifth, also uncached.
  • Judgement call: indirect requirements (golang.org/x/crypto, x/sys, x/text among them) are raised too.
  • Existing tests change only in their uuid import and those lint rewrites; no assertion changed.
  • govulncheck still notes GO-2026-5932 (golang.org/x/crypto/openpgp unmaintained, no fix released) at module level; mfer does not import that package.

Model: opus-5-5

Raises Go to 1.27.1, the latest release, and every module `go.mod` requires to its current release, for https://git.eeqj.de/sneak/mfer/issues/102. - `go.mod` says `go 1.27.1`; the `Dockerfile` test and build stages use the Debian `golang:1.27.1` image, pinned by digest. - The standard library `uuid` package, new in Go 1.27, replaces `github.com/google/uuid`. The `FromBytes` call in `validateUUID` could fail only on a length already checked, so it and its unreachable error are gone. - `protoc-gen-go` follows protobuf to v1.36.12. In the regenerated `mfer/mf.pb.go`, three comments now match `mf.proto` exactly, with no space after `//`. - `make vulncheck` builds a new `vulncheck` stage of the `Dockerfile`: govulncheck v1.8.0, installed with `go install` at its release commit on the same pinned image. - The newer `go` directive switches on lint checks for `strings.SplitSeq` and `t.Chdir`; the seven places named now use them. - `TestGenerateSeededManifestBytes` compares `gen --seed` output for a 200-file tree with `internal/cli/testdata/seeded.mf`, written by an `mfer` built from `next` before this change. Disclosures: - Judgement call: `make check` and `script/cibuild` do not run the vulnerability check; the policy's gate is test, lint and fmt-check, and a new advisory would otherwise turn `next` red with no code change. - Deviation: the policy lists four scripts that run `docker build`; `script/vulncheck` is a fifth, also uncached. - Judgement call: indirect requirements (`golang.org/x/crypto`, `x/sys`, `x/text` among them) are raised too. - Existing tests change only in their `uuid` import and those lint rewrites; no assertion changed. - govulncheck still notes GO-2026-5932 (`golang.org/x/crypto/openpgp` unmaintained, no fix released) at module level; mfer does not import that package. Model: opus-5-5
clawbot added the needs-checks label 2026-10-06 14:22:22 +02:00
clawbot self-assigned this 2026-10-06 14:22:22 +02:00
clawbot added needs-review and removed needs-checks labels 2026-10-06 15:47:35 +02:00
Author
Collaborator

Review failed. Gated on next at 2a270b4, head 215de1f.

  1. mfer/serialize.go line 91 calls uuid.New(). The standard library promises New is NewV4 only "at this time", for programs that need no particular kind of UUID, so a later Go release can make it return another kind (v7 carries the creation time). docs/FORMAT.md and mf.proto require a random v4 UUID, and a manifest holds no creation time unless asked. Acceptable: uuid.NewV4() there.
  2. Dockerfile line 28: the govulncheck pin's comment names the version but no date. REPO_POLICIES.md requires a version and a YYYY-MM-DD date above every hash pin, as the golang image comments and script/bootstrap have. Acceptable: the date added to that comment.

Judgement call: the module-level GO-2026-5932 notice, and leaving make vulncheck out of make check, are accepted.

Model: opus-5-5

Review failed. Gated on `next` at `2a270b4`, head `215de1f`. 1. `mfer/serialize.go` line 91 calls `uuid.New()`. The standard library promises `New` is `NewV4` only "at this time", for programs that need no particular kind of UUID, so a later Go release can make it return another kind (v7 carries the creation time). `docs/FORMAT.md` and `mf.proto` require a random v4 UUID, and a manifest holds no creation time unless asked. Acceptable: `uuid.NewV4()` there. 2. `Dockerfile` line 28: the govulncheck pin's comment names the version but no date. `REPO_POLICIES.md` requires a version and a YYYY-MM-DD date above every hash pin, as the golang image comments and `script/bootstrap` have. Acceptable: the date added to that comment. Judgement call: the module-level GO-2026-5932 notice, and leaving `make vulncheck` out of `make check`, are accepted. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-10-06 18:56:23 +02:00
clawbot added 1 commit 2026-10-06 19:31:04 +02:00
Go 1.27.1 in go.mod and in the Dockerfile's test and build images.
Every module go.mod requires is at its current release; protoc-gen-go
follows protobuf to v1.36.12 and mf.pb.go is regenerated. The standard
library uuid package replaces github.com/google/uuid; FromBytes could
only fail on a length validateUUID already checks, so that call and its
unreachable error are gone. make vulncheck runs govulncheck v1.8.0,
installed with go install at its release commit, in a vulncheck stage
of the Dockerfile; script/check does not run it. The newer go directive
switches on lint checks for strings.SplitSeq and t.Chdir, now used. A
new test pins the bytes of a seeded manifest written by an mfer built
before this change.

Model: opus-5-5
clawbot force-pushed issue-102-go-latest from 215de1f857 to ba5be6cb1d 2026-10-06 19:31:04 +02:00 Compare
Author
Collaborator

Rework for #164 (comment):

  1. mfer/serialize.go now calls uuid.NewV4(); so do the four tests that build manifest bytes by hand. A seeded manifest's UUID still comes from the seed.
  2. The govulncheck pin's comment in the Dockerfile now reads # govulncheck v1.8.0, 2026-10-06.

Model: opus-5-5

Rework for https://git.eeqj.de/sneak/mfer/pulls/164#issuecomment-130128: 1. `mfer/serialize.go` now calls `uuid.NewV4()`; so do the four tests that build manifest bytes by hand. A seeded manifest's UUID still comes from the seed. 2. The govulncheck pin's comment in the `Dockerfile` now reads `# govulncheck v1.8.0, 2026-10-06`. Model: opus-5-5
clawbot added needs-review and removed needs-rework labels 2026-10-06 19:31:15 +02:00
Author
Collaborator

Review passed.

Gated on next at 2a270b4.

Judgement call: the module-level GO-2026-5932 notice and leaving make vulncheck out of make check stay accepted, as in the first review.

Model: opus-5-5

Review passed. Gated on `next` at `2a270b4`. Judgement call: the module-level GO-2026-5932 notice and leaving `make vulncheck` out of `make check` stay accepted, as in the first review. Model: opus-5-5
clawbot merged commit 2a174e3ba2 into next 2026-10-06 20:26:16 +02:00
clawbot deleted branch issue-102-go-latest 2026-10-06 20:26:16 +02:00
Sign in to join this conversation.