Skip to content

Build from an untouched upstream tree so the version is not +dirty - #6

Merged
edimarlnx merged 1 commit into
mainfrom
fix/clean-version-stamp
Sep 25, 2026
Merged

edimarlnx merged 1 commit into
mainfrom
fix/clean-version-stamp

Conversation

@edimarlnx

Copy link
Copy Markdown
Contributor

The mirror's headscale reports v0.29.3+dirty (tui-tools/pkgs#13). headscale takes its version, commit and build time from Go's VCS stamping (debug.ReadBuildInfo), not from an ldflag, and scripts/harden-deps.sh rewrote go.mod/go.sum inside src/, so Go stamped the tree as modified. The -X main.version ldflag was a no-op: headscale has no such symbol.

Change

  • scripts/harden-deps.sh writes the lifted go.mod/go.sum to hardened/ (gitignored), outside the upstream checkout, and runs every go command with GOFLAGS=-modfile=…/hardened/go.mod. It fails if src/ ends up modified, and writes hardened/dependency-floor.diff (upstream go.mod vs ours).
  • .goreleaser.yaml builds with the same -modfile, uses upstream's own ldflags (-s -w) instead of the no-op -X main.version, and ships dependency-floor.diff as a release asset included in the signed checksums.txt; the release header says what it is.
  • scripts/check-version-stamp.sh asserts every built binary has mod = VERSION, vcs.revision = upstream commit, vcs.modified=false; it runs in both the build and the release job.
  • govulncheck reads the hardened modfile too, so it scans what we ship.

Evidence (local snapshot build of v0.29.3)

ok: dist/headscale_linux_amd64_v1/headscale reports v0.29.3 at 5aff68b5b9921db5ccb88013bb1740077ab872fb (clean)
ok: dist/headscale_linux_arm64_v8.0/headscale reports v0.29.3 at 5aff68b5b9921db5ccb88013bb1740077ab872fb (clean)
$ headscale version
headscale version v0.29.3
commit: 5aff68b5b9921db5ccb88013bb1740077ab872fb
$ go version -m headscale | grep -E 'x/crypto|grpc\s'
dep golang.org/x/crypto v0.57.0
dep google.golang.org/grpc v1.84.0

The already published v0.29.3 packages keep their bytes (pkgs never replaces a published filename), so the clean version reaches the package repository with the next mirror release (upstream v0.29.4 is out; bump-headscale-v0.29.4 exists without a PR).

Closes tui-tools/pkgs#13

🤖 Generated with Claude Code

https://claude.ai/code/session_01MbCfX3T8khyd9hsrN5kMo3

headscale has no version variable: it reads version, commit and build
time from Go's VCS stamping. harden-deps.sh rewrote go.mod and go.sum
inside src/, so Go stamped the binary `v0.29.3+dirty`, which reads the
same as an accidental change, and the `-X main.version` ldflag set a
symbol that does not exist.

The lifted go.mod/go.sum now live in hardened/, outside the checkout,
and every go command (harden-deps, goreleaser, govulncheck) reads them
through -modfile. src/ stays byte-for-byte the tag, so the binary
reports the upstream tag and commit; harden-deps fails if the checkout
was modified, and check-version-stamp.sh fails CI and the release job
if any binary says otherwise. The deliberate difference ships as
dependency-floor.diff, covered by the signed checksums.txt. ldflags are
now upstream's own (-s -w).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MbCfX3T8khyd9hsrN5kMo3
@edimarlnx
edimarlnx merged commit c55c70e into main Sep 25, 2026
2 checks passed
@edimarlnx
edimarlnx deleted the fix/clean-version-stamp branch September 25, 2026 21:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant