Refresh the toolchain images' golang pin to 1.26.6 and gate it in CI - #11
Merged
Merged
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
go.mod's `go` directive moved to 1.26.6 without the pinned golang digest in images/toolchain-go and images/toolchain-claude moving with it. Under the golang image's GOTOOLCHAIN=local that is fatal — `go mod download` in toolchain-claude's shim stage refuses to run — so `mage desktop:devapp` broke with every test suite green, because no suite runs a docker build. - Repin both Dockerfiles to golang:1.26.6-bookworm (still bookworm: the toolchain payloads resolve libc from the sandbox rootfs) and bump toolchain-go's goprobe module directive, which exists to prove the shipped toolchain can build a module declaring the repo's directive. - Add `mage build:toolchains`: builds every apimage.Toolchains overlay for the docker daemon's native platform, exporting nothing — a build check cheap enough for CI. New toolchain-images CI job runs it. - Refresh config/toolchains/go.yaml's measured-size comment (306964 KB on 1.26.6; the sizeBytes headroom absorbs it, as designed).
josephschorr
force-pushed
the
fix/toolchain-golang-pin
branch
from
September 30, 2026 04:25
d5d53b5 to
5a37981
Compare
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What broke
mage desktop:devappfailed on HEAD of main:go.mod's
godirective moved to 1.26.6 without the pinned golang digest inimages/toolchain-go/Dockerfileandimages/toolchain-claude/Dockerfilemoving with it. Both pinnedgolang:1.26.1-bookworm, and the official golang images setGOTOOLCHAIN=local, sogo mod downloadin toolchain-claude's shim stage fails outright instead of auto-downloading a newer toolchain. Every test suite was green because no suite runs a docker build.The fix
golang:1.26.6-bookworm(sha256:116d58cb…), following the refresh procedure documented in each file. Still bookworm — the toolchain-go payload resolves libc from the sandbox rootfs (debian 12), so the builder base must not move off it.goprobemodule directive to 1.26.6. That probe exists to prove the shipped toolchain can build a module declaring the repo'sgodirective; left at 1.26.1 it would pass with a pin that still can't build this repo.config/toolchains/go.yaml's measured-size comment: 306964 KB (314,331,136 bytes) on Go 1.26.6, re-measured from the rebuilt image.sizeBytesunchanged — the headroom was designed to absorb patch bumps.The CI gate
New
mage build:toolchainstarget: builds everyapimage.Toolchainsoverlay (go, node, claude) for the docker daemon's native platform, exporting nothing (--output=type=cacheonly, same shape asdesktop:images' GoBuilder prebuild). A newtoolchain-imagesCI job runs it — the only job that runs a docker build, so a go.mod bump without a pin refresh now fails the PR instead of the nextmage desktop:devapp.Native platform rather than the bake's linux/arm64: the pinned digest is one multi-arch manifest list carrying a single Go version, so the pin-vs-directive invariant is arch-independent, and native builds avoid paying qemu emulation in CI.
Note: the earlier format/frontend failures were main's, not this branch's
The first CI run here failed
formatandfrontendat setup — inherited from main (red since a8e8743's rootpackageManager: pnpm@12.3.4pin conflicted with the workflow's hardcodedversion: 10.34.5;pnpm/action-setup@v6refuses that combination). This branch briefly carried the fix, but main has since landed the same change independently, so the rebase dropped that commit — the diff here is the toolchain pin + CI gate only.Verification
mage desktop:devappend-to-end green after the repin (app builds, signs, and passescodesign --verify --strict; a full VM boot + shutdown afterward left no stray processes, listeners, or vmnet interfaces).mage build:toolchainsgreen natively (arm64) — and green in this PR's own CI (toolchain-images, 6m57s on amd64).mage test:unitgreen locally. Integration/e2e run in this PR's CI; the diff touches no Go code underpkg/,internal/, orcmd/.