Skip to content

ci: move to Go 1.26.6, pin actions by SHA, and gate Windows as compile-only - #3

Open
Patel230 wants to merge 2 commits into
mainfrom
ci/go-toolchain-gates
Open

Patel230 wants to merge 2 commits into
mainfrom
ci/go-toolchain-gates

Conversation

@Patel230

@Patel230 Patel230 commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Moves Across to the ecosystem Go toolchain (1.26.6) and makes CI deterministic and supply-chain pinned. This is the first of three PRs split out of the chore/phase-zero-trust work; it applies cleanly to main on its own and chore/phase-zero-trust (#5) is stacked on these two commits.

  • go.mod: go 1.26.6 (was 1.24, outside the Go support window). go mod tidy -diff is clean.
  • Makefile: fmt-check, test-e2e, coverage, cross-check (windows/amd64 vet + build) and vulncheck (govulncheck pinned to v1.8.0); make check = gofmt check + vet + race; fuzz no longer swallows failures with || true.
  • Bug found while reviewing: the draft fmt-check recipe @test -z "$(gofmt -l .)" is expanded by make to test -z "", so the gate could never fail (make -n fmt-check printed test -z ""). The recipe now escapes the substitution and lists offending files; checked with a deliberately misformatted file (exit 2).
  • ci.yml: every action pinned to a commit SHA with a version comment (same pins as rho/flux), persist-credentials: false, read-only token, GOTOOLCHAIN=local, GOWORK=off, concurrency group. Jobs: quality (tidy -diff, gofmt, build, vet, test on ubuntu + macOS), cross-compile (Windows compile-only), race, E2E, coverage, govulncheck — each runs the Makefile target a contributor runs locally.
  • Windows is compile-only until qualified: the suites exec sh/python3, create symlinks and need cgo, and no test is gated by GOOS. .gitattributes (eol=lf) prevents a CRLF checkout from turning every file into a gofmt failure. README keeps Windows listed as untested.
  • AGENTS.md / README / CONTRIBUTING document the targets, Go 1.26.6 and the cgo requirement.

Findings addressed

  • F047 — CI security job could not pass on Go 1.24 (govulncheck@latest → x/vuln v1.8.0 requires go ≥ 1.26; 1.24 stdlib vulns). Now Go 1.26.6 + GOTOOLCHAIN=local + govulncheck pinned to v1.8.0; docs updated.
  • F055 — unqualified windows-latest test job with concrete failure hazards. Replaced by a Windows compile-only job; .gitattributes added.
  • F247 (CI half, reproduced from source: actions/checkout@v4, actions/setup-go@v5, actions/upload-artifact@v4 were tag-pinned on main and in the draft) — all CI actions SHA-pinned, credentials not persisted. The release half is in ci: release per-target archives with one checksum file and provenance #4.

Not reproduced / deferred

  • None for this PR. Windows runtime qualification is deferred by design (see Follow-ups).

Verification

Run on this branch (ci/go-toolchain-gates, main's code) on darwin/arm64 with go1.26.6:

Command Result
GOWORK=off make check pass (gofmt check, vet, go test -race -count=1 ./...)
GOWORK=off make test-e2e pass (ok github.com/graycodeai/across/e2e 31.8s)
GOOS=linux GOARCH=amd64 GOWORK=off go build ./... pass
GOOS=windows GOARCH=amd64 GOWORK=off go build ./... pass
GOWORK=off make cross-check pass
GOWORK=off go mod tidy -diff no diff
GOWORK=off make vulncheck No vulnerabilities found.
actionlint .github/workflows/ci.yml (v1.7.12) clean
make -n fmt-check before the fix test -z "" (no-op)

The macOS and Linux CI jobs themselves have not run yet; they run on this PR.

Follow-ups

  • Qualify Windows (gate sh/python3/symlink tests by GOOS or make them portable, verify the SQLite file: URI) before adding a Windows test job or Windows release artifacts.

🤖 Generated with Claude Code

across added 2 commits September 27, 2026 04:37
govulncheck v1.8.0 (the version @latest resolves to) refuses to run on
Go 1.24, and Go 1.24 is outside the upstream support window; the
reachable stdlib fixes the security job needs ship in Go 1.26.6, the
toolchain the rest of the GrayCode ecosystem already uses.

- go.mod: go 1.26.6 (go mod tidy -diff is clean)
- Makefile: add fmt-check, test-e2e, coverage, cross-check and
  vulncheck (govulncheck pinned to v1.8.0); make check now runs the
  gofmt gate; fuzz no longer swallows failures with || true
- fmt-check escapes its command substitution: the unescaped
  $(gofmt -l .) was expanded by make to an empty string, so the gate
  could never fail
- AGENTS.md, README.md, CONTRIBUTING.md: document the targets, the Go
  version, and the cgo requirement
- Pin every action to a full commit SHA with a version comment (same
  pins as rho/flux), check out without persisted credentials, and keep
  the workflow token read-only.
- Use Go 1.26.6 with GOTOOLCHAIN=local so the job runs the toolchain it
  names instead of silently switching.
- Split quality (tidy -diff, gofmt, build, vet, test on Linux and
  macOS), race, E2E, coverage and govulncheck (pinned) jobs; each runs
  the Makefile target a contributor runs locally.
- Windows was added to the test matrix without qualification: the E2E
  and unit suites exec sh/python3, create symlinks and rely on cgo, and
  no test is gated by GOOS. Keep Windows as a compile-only check until
  it is qualified; README already lists it as untested.
- Add .gitattributes (eol=lf) so a Windows checkout cannot turn every
  file into a gofmt failure.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant