Skip to content

build: update to Go 1.27 and refresh dependencies - #2

Merged
pjcdawkins merged 3 commits into
mainfrom
claude/maintenance-dependencies-e2b8ac
Sep 2, 2026
Merged

pjcdawkins merged 3 commits into
mainfrom
claude/maintenance-dependencies-e2b8ac

Conversation

@pjcdawkins

Copy link
Copy Markdown
Contributor

Routine maintenance: Go 1.27 and a dependency refresh.

Dependencies

module from to
github.com/landlock-lsm/go-landlock v0.7.0 v0.10.0
github.com/spf13/pflag v1.0.9 v1.0.10
github.com/stretchr/testify v1.11.1 v1.12.1
golang.org/x/crypto v0.49.0 v0.56.0
golang.org/x/net v0.51.0 v0.58.0
golang.org/x/sys v0.42.0 v0.47.0
golang.org/x/term v0.41.0 v0.45.0
kernel.org/pub/linux/libs/security/libcap/psx v1.2.77 v1.2.78
golang.org/x/vuln (tool) v1.1.4 v1.7.0

go 1.27.1 in go.mod, plus the three setup-go pins and the golang container image in CI.

What a reviewer should know

go-landlock v0.10.0 does not change enforcement. The API this code uses is unchanged, and policy/filesystem.go still enforces with V5.BestEffort(), so the V6-V10 ABI presets the new version adds are not adopted here. Two of them look worth a separate look later: V8 adds tsync for multithreaded enforcement (gated on abi.version >= 8, so unreachable at the V5 preset), and V9 restricts connect(2)/sendmsg(2) on pathname UNIX sockets under RestrictPaths, which overlaps the existing seccomp AF_UNIX blocking. Both are enforcement-semantics changes and deliberately out of scope for a dependency bump.

Go 1.27 permits initializing promoted embedded fields in composite literals, and its fixer rewrites the proxy tests to drop the FilterBase{...} wrapper. The make lint gate requires an empty go fix -diff, so this had to be applied rather than deferred. The fixer left closing braces jammed onto the same line in proxy/socks5_test.go; those are hand-corrected. The fixer also switched resources.closeAll to slices.Backward.

The pinned golangci-lint v2.10 would have failed CI outright. Verified by downloading it and running it against the updated module:

can't load config: the Go language version (go1.26) used to build golangci-lint
is lower than the targeted Go version (1.27.1)

Hence the bump to v2.13, which is built with go1.27.

The style: apply gofmt commit is unrelated drift. Six files were already out of gofmt shape on main — go1.26 gofmt flags the same files — so this is not a consequence of the Go 1.27 change. Kept as its own commit.

Verification

go build, go test ./..., make lint (0 issues) and make govulncheck (no vulnerabilities) all run locally.

Four sandbox tests fail on the development host: TestCurb_Exec_WritableDirNotExecutable, TestCurb_MountFS_WriteSysPathBlocked, TestCurb_MountFS_ExecTmpDirBlocked and TestCurb_Proxy_PidNS_FreshProc. They fail identically on the base commit (checked by stashing and re-running), so they are the host's AppArmor unprivileged-userns restrictions degrading mount and PID namespaces, not this change. CI runs those in a Debian container.

No documentation referenced a Go version or a dependency version, so no docs changed.

Note: the usual codex review pre-MR step could not run — that account is over its usage limit until Sep 27.

🤖 Generated with Claude Code

pjcdawkins and others added 3 commits September 2, 2026 21:41
Six files had drifted out of gofmt shape: struct field and comment
alignment, and trailing blank lines. Unrelated to any Go version
change — go1.26's gofmt flags the same files.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Go 1.27.1 in go.mod, and the three setup-go pins plus the golang
container image in CI.

Dependency updates:

  go-landlock         v0.7.0  -> v0.10.0
  pflag               v1.0.9  -> v1.0.10
  testify             v1.11.1 -> v1.12.1
  x/crypto            v0.49.0 -> v0.56.0
  x/net               v0.51.0 -> v0.58.0
  x/sys               v0.42.0 -> v0.47.0
  x/term              v0.41.0 -> v0.45.0
  libcap/psx          v1.2.77 -> v1.2.78
  x/vuln (tool)       v1.1.4  -> v1.7.0

go-landlock v0.10.0 keeps the API this code uses unchanged. The
V6-V10 ABI presets it adds are not adopted here: policy/filesystem.go
still enforces with V5.BestEffort(), so enforcement semantics are
untouched.

Go 1.27's fixer proposes two modernizations, applied here:

  - Embedded struct fields are now settable directly in a composite
    literal, so the proxy tests drop their FilterBase wrapper.
  - resources.closeAll uses slices.Backward.

Verified: go build, go test ./..., make lint, make govulncheck. Four
sandbox tests fail locally both before and after this change — the
host's AppArmor unprivileged-userns restrictions degrade mount and PID
namespaces. CI runs those in a Debian container.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
golangci-lint bundles the Go type checker, so the pinned v2.10 (built
with go1.26) refuses a module targeting Go 1.27:

  can't load config: the Go language version (go1.26) used to build
  golangci-lint is lower than the targeted Go version (1.27.1)

Verified locally with v2.13.1, which is built with go1.27.0: 0 issues.
v2.12.2 and earlier predate Go 1.27, so v2.13 is the floor.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@pjcdawkins
pjcdawkins merged commit 80e5d82 into main Sep 2, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant