Repository navigation
build: update to Go 1.27 and refresh dependencies - #2
Merged
Merged
Conversation
Six files had drifted out of gofmt shape: struct field and comment alignment, and trailing blank lines. Unrelated to any Go version change — go1.26's gofmt flags the same files. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Go 1.27.1 in go.mod, and the three setup-go pins plus the golang
container image in CI.
Dependency updates:
go-landlock v0.7.0 -> v0.10.0
pflag v1.0.9 -> v1.0.10
testify v1.11.1 -> v1.12.1
x/crypto v0.49.0 -> v0.56.0
x/net v0.51.0 -> v0.58.0
x/sys v0.42.0 -> v0.47.0
x/term v0.41.0 -> v0.45.0
libcap/psx v1.2.77 -> v1.2.78
x/vuln (tool) v1.1.4 -> v1.7.0
go-landlock v0.10.0 keeps the API this code uses unchanged. The
V6-V10 ABI presets it adds are not adopted here: policy/filesystem.go
still enforces with V5.BestEffort(), so enforcement semantics are
untouched.
Go 1.27's fixer proposes two modernizations, applied here:
- Embedded struct fields are now settable directly in a composite
literal, so the proxy tests drop their FilterBase wrapper.
- resources.closeAll uses slices.Backward.
Verified: go build, go test ./..., make lint, make govulncheck. Four
sandbox tests fail locally both before and after this change — the
host's AppArmor unprivileged-userns restrictions degrade mount and PID
namespaces. CI runs those in a Debian container.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
golangci-lint bundles the Go type checker, so the pinned v2.10 (built with go1.26) refuses a module targeting Go 1.27: can't load config: the Go language version (go1.26) used to build golangci-lint is lower than the targeted Go version (1.27.1) Verified locally with v2.13.1, which is built with go1.27.0: 0 issues. v2.12.2 and earlier predate Go 1.27, so v2.13 is the floor. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Routine maintenance: Go 1.27 and a dependency refresh.
Dependencies
github.com/landlock-lsm/go-landlockgithub.com/spf13/pflaggithub.com/stretchr/testifygolang.org/x/cryptogolang.org/x/netgolang.org/x/sysgolang.org/x/termkernel.org/pub/linux/libs/security/libcap/psxgolang.org/x/vuln(tool)go 1.27.1ingo.mod, plus the threesetup-gopins and thegolangcontainer image in CI.What a reviewer should know
go-landlock v0.10.0 does not change enforcement. The API this code uses is unchanged, and
policy/filesystem.gostill enforces withV5.BestEffort(), so the V6-V10 ABI presets the new version adds are not adopted here. Two of them look worth a separate look later: V8 addstsyncfor multithreaded enforcement (gated onabi.version >= 8, so unreachable at the V5 preset), and V9 restrictsconnect(2)/sendmsg(2)on pathname UNIX sockets underRestrictPaths, which overlaps the existing seccomp AF_UNIX blocking. Both are enforcement-semantics changes and deliberately out of scope for a dependency bump.Go 1.27 permits initializing promoted embedded fields in composite literals, and its fixer rewrites the proxy tests to drop the
FilterBase{...}wrapper. Themake lintgate requires an emptygo fix -diff, so this had to be applied rather than deferred. The fixer left closing braces jammed onto the same line inproxy/socks5_test.go; those are hand-corrected. The fixer also switchedresources.closeAlltoslices.Backward.The pinned golangci-lint v2.10 would have failed CI outright. Verified by downloading it and running it against the updated module:
Hence the bump to v2.13, which is built with go1.27.
The
style: apply gofmtcommit is unrelated drift. Six files were already out of gofmt shape onmain— go1.26 gofmt flags the same files — so this is not a consequence of the Go 1.27 change. Kept as its own commit.Verification
go build,go test ./...,make lint(0 issues) andmake govulncheck(no vulnerabilities) all run locally.Four
sandboxtests fail on the development host:TestCurb_Exec_WritableDirNotExecutable,TestCurb_MountFS_WriteSysPathBlocked,TestCurb_MountFS_ExecTmpDirBlockedandTestCurb_Proxy_PidNS_FreshProc. They fail identically on the base commit (checked by stashing and re-running), so they are the host's AppArmor unprivileged-userns restrictions degrading mount and PID namespaces, not this change. CI runs those in a Debian container.No documentation referenced a Go version or a dependency version, so no docs changed.
Note: the usual
codex reviewpre-MR step could not run — that account is over its usage limit until Sep 27.🤖 Generated with Claude Code