Skip to content

Refresh the toolchain images' golang pin to 1.26.6 and gate it in CI - #11

Merged
josephschorr merged 1 commit into
mainfrom
fix/toolchain-golang-pin
Sep 30, 2026
Merged

josephschorr merged 1 commit into
mainfrom
fix/toolchain-golang-pin

Conversation

@josephschorr

@josephschorr josephschorr commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

What broke

mage desktop:devapp failed on HEAD of main:

go: go.mod requires go >= 1.26.6 (running go 1.26.1; GOTOOLCHAIN=local)

go.mod's go directive moved to 1.26.6 without the pinned golang digest in images/toolchain-go/Dockerfile and images/toolchain-claude/Dockerfile moving with it. Both pinned golang:1.26.1-bookworm, and the official golang images set GOTOOLCHAIN=local, so go mod download in toolchain-claude's shim stage fails outright instead of auto-downloading a newer toolchain. Every test suite was green because no suite runs a docker build.

The fix

  • Repin both Dockerfiles to golang:1.26.6-bookworm (sha256:116d58cb…), following the refresh procedure documented in each file. Still bookworm — the toolchain-go payload resolves libc from the sandbox rootfs (debian 12), so the builder base must not move off it.
  • Bump toolchain-go's goprobe module directive to 1.26.6. That probe exists to prove the shipped toolchain can build a module declaring the repo's go directive; left at 1.26.1 it would pass with a pin that still can't build this repo.
  • Refresh config/toolchains/go.yaml's measured-size comment: 306964 KB (314,331,136 bytes) on Go 1.26.6, re-measured from the rebuilt image. sizeBytes unchanged — the headroom was designed to absorb patch bumps.

The CI gate

New mage build:toolchains target: builds every apimage.Toolchains overlay (go, node, claude) for the docker daemon's native platform, exporting nothing (--output=type=cacheonly, same shape as desktop:images' GoBuilder prebuild). A new toolchain-images CI job runs it — the only job that runs a docker build, so a go.mod bump without a pin refresh now fails the PR instead of the next mage desktop:devapp.

Native platform rather than the bake's linux/arm64: the pinned digest is one multi-arch manifest list carrying a single Go version, so the pin-vs-directive invariant is arch-independent, and native builds avoid paying qemu emulation in CI.

Note: the earlier format/frontend failures were main's, not this branch's

The first CI run here failed format and frontend at setup — inherited from main (red since a8e8743's root packageManager: pnpm@12.3.4 pin conflicted with the workflow's hardcoded version: 10.34.5; pnpm/action-setup@v6 refuses that combination). This branch briefly carried the fix, but main has since landed the same change independently, so the rebase dropped that commit — the diff here is the toolchain pin + CI gate only.

Verification

  • mage desktop:devapp end-to-end green after the repin (app builds, signs, and passes codesign --verify --strict; a full VM boot + shutdown afterward left no stray processes, listeners, or vmnet interfaces).
  • mage build:toolchains green natively (arm64) — and green in this PR's own CI (toolchain-images, 6m57s on amd64).
  • All three images also built for linux/amd64 locally before the job shipped — including the gopls compile and the goprobe at 1.26.6.
  • mage test:unit green locally. Integration/e2e run in this PR's CI; the diff touches no Go code under pkg/, internal/, or cmd/.

@vercel

vercel Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
openagentprimitives Ready Ready Preview Sep 30, 2026 4:25am UTC

Request Review

go.mod's `go` directive moved to 1.26.6 without the pinned golang
digest in images/toolchain-go and images/toolchain-claude moving with
it. Under the golang image's GOTOOLCHAIN=local that is fatal — `go mod
download` in toolchain-claude's shim stage refuses to run — so `mage
desktop:devapp` broke with every test suite green, because no suite
runs a docker build.

- Repin both Dockerfiles to golang:1.26.6-bookworm (still bookworm: the
  toolchain payloads resolve libc from the sandbox rootfs) and bump
  toolchain-go's goprobe module directive, which exists to prove the
  shipped toolchain can build a module declaring the repo's directive.
- Add `mage build:toolchains`: builds every apimage.Toolchains overlay
  for the docker daemon's native platform, exporting nothing — a build
  check cheap enough for CI. New toolchain-images CI job runs it.
- Refresh config/toolchains/go.yaml's measured-size comment (306964 KB
  on 1.26.6; the sizeBytes headroom absorbs it, as designed).
@josephschorr
josephschorr force-pushed the fix/toolchain-golang-pin branch from d5d53b5 to 5a37981 Compare September 30, 2026 04:25
@josephschorr
josephschorr merged commit 92f61c4 into main Sep 30, 2026
13 of 14 checks passed

This branch was successfully deployed

1 active deployment
Preview — 5a379819 Deployed Sep 30, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant