Build from an untouched upstream tree so the version is not +dirty - #6
Merged
Merged
Conversation
headscale has no version variable: it reads version, commit and build time from Go's VCS stamping. harden-deps.sh rewrote go.mod and go.sum inside src/, so Go stamped the binary `v0.29.3+dirty`, which reads the same as an accidental change, and the `-X main.version` ldflag set a symbol that does not exist. The lifted go.mod/go.sum now live in hardened/, outside the checkout, and every go command (harden-deps, goreleaser, govulncheck) reads them through -modfile. src/ stays byte-for-byte the tag, so the binary reports the upstream tag and commit; harden-deps fails if the checkout was modified, and check-version-stamp.sh fails CI and the release job if any binary says otherwise. The deliberate difference ships as dependency-floor.diff, covered by the signed checksums.txt. ldflags are now upstream's own (-s -w). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MbCfX3T8khyd9hsrN5kMo3
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The mirror's headscale reports
v0.29.3+dirty(tui-tools/pkgs#13). headscale takes its version, commit and build time from Go's VCS stamping (debug.ReadBuildInfo), not from an ldflag, andscripts/harden-deps.shrewrotego.mod/go.suminsidesrc/, so Go stamped the tree as modified. The-X main.versionldflag was a no-op: headscale has no such symbol.Change
scripts/harden-deps.shwrites the liftedgo.mod/go.sumtohardened/(gitignored), outside the upstream checkout, and runs every go command withGOFLAGS=-modfile=…/hardened/go.mod. It fails ifsrc/ends up modified, and writeshardened/dependency-floor.diff(upstream go.mod vs ours)..goreleaser.yamlbuilds with the same-modfile, uses upstream's own ldflags (-s -w) instead of the no-op-X main.version, and shipsdependency-floor.diffas a release asset included in the signedchecksums.txt; the release header says what it is.scripts/check-version-stamp.shasserts every built binary hasmod = VERSION,vcs.revision = upstream commit,vcs.modified=false; it runs in both the build and the release job.Evidence (local snapshot build of v0.29.3)
The already published
v0.29.3packages keep their bytes (pkgs never replaces a published filename), so the clean version reaches the package repository with the next mirror release (upstreamv0.29.4is out;bump-headscale-v0.29.4exists without a PR).Closes tui-tools/pkgs#13
🤖 Generated with Claude Code
https://claude.ai/code/session_01MbCfX3T8khyd9hsrN5kMo3