Skip to content

build: update go and dependencies - #800

Open
vfusco wants to merge 14 commits into
fix/keep-nonaccepted-reportsfrom
feature/bump-go-and-deps
Open

vfusco wants to merge 14 commits into
fix/keep-nonaccepted-reportsfrom
feature/bump-go-and-deps

Conversation

@vfusco

@vfusco vfusco commented Oct 1, 2026

Copy link
Copy Markdown
Member

Dependencies

  • Set Go to 1.27.1 and update the modules. This includes go-ethereum v1.17.7, pgx v5.11.0, jet v2.16.0, tint v1.2.0 and aws-sdk-go-v2.
  • Use oapi-codegen v2.8.0 from its new module path, github.com/oapi-codegen/oapi-codegen/v2.
  • Regenerate the contract bindings and the inspect client.

Fixes for the new versions

  • From v1.17.5, go-ethereum rejects a response that has "error": null. The node and the CLI remove this member from the responses.
  • From v5.11, pgx reads a database URL like libpq. The configuration rejects a database URL that has a # or a repeated parameter.

Key derivation

  • Replace go-bip32 with an internal BIP-32 implementation. The derived keys do not change.
  • Reject an account index of 2^31 or more.
  • make unit-test also runs the tests of the pure Go binaries without cgo. These binaries use a different secp256k1 implementation.

License notices

  • Generate THIRD_PARTY_LICENSES.md for linux/amd64 and linux/arm64, with manual entries and corrections.
  • Add the LGPL-3.0 and GPL-3.0 texts. Install the notices in the Debian package, in /usr/share/doc.
  • CI checks the third party licenses and makes sure that the notices are current.

Other

  • Set the version to 2.0.0-alpha.13.

@vfusco vfusco added this to the 2.0.0 milestone Oct 1, 2026
@vfusco
vfusco requested review from mpolitzer and renatomaia and a balanced review from Copilot October 1, 2026 17:56
@vfusco vfusco self-assigned this Oct 1, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

License generation and CI omit the dependency graphs of released CGO-disabled binaries.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)
What changed in this PR

Updates Go and dependencies, regenerates clients/contracts, improves compatibility, and expands licensing automation.

Changes:

  • Upgrades Go, modules, generated bindings, and release version.
  • Adds JSON-RPC compatibility, database URL validation, and internal BIP-32 derivation.
  • Adds multi-platform license notices and Debian packaging support.
File Description
THIRD_PARTY_LICENSES.md Updates dependency notices.
README.md Updates requirements and licensing details.
pkg/​service/​service.go Adopts tint’s renamed handler.
pkg/​inspectclient/​main.go Updates generator module path.
pkg/​inspectclient/​generated.go Regenerates the inspect client.
pkg/​ethutil/​rpc_response.go Filters null JSON-RPC errors.
pkg/​ethutil/​rpc_response_test.go Tests response filtering.
pkg/​ethutil/​mnemonic.go Uses internal BIP-32 derivation.
pkg/​ethutil/​mnemonic_test.go Expands key derivation tests.
pkg/​ethutil/​client.go Integrates compatible RPC transports.
pkg/​ethutil/​bip32.go Implements BIP-32 derivation.
pkg/​ethutil/​bip32_test.go Tests BIP-32 vectors.
pkg/​contracts/​outputs/​outputs.go Regenerates contract bindings.
pkg/​contracts/​iusdwithdrawaloutputbuilder/​iusdwithdrawaloutputbuilder.go Regenerates contract bindings.
pkg/​contracts/​itournament/​itournament.go Regenerates tournament bindings.
pkg/​contracts/​iselfhostedapplicationfactory/​iselfhostedapplicationfactory.go Regenerates factory bindings.
pkg/​contracts/​iquorumfactory/​iquorumfactory.go Regenerates quorum factory bindings.
pkg/​contracts/​iquorum/​iquorum.go Regenerates quorum bindings.
pkg/​contracts/​inputs/​inputs.go Regenerates input bindings.
pkg/​contracts/​imultileveltournamentfactory/​imultileveltournamentfactory.go Regenerates tournament factory bindings.
pkg/​contracts/​iinputbox/​iinputbox.go Regenerates input-box bindings.
pkg/​contracts/​ierc20portal/​ierc20portal.go Regenerates portal bindings.
pkg/​contracts/​ierc20metadata/​ierc20metadata.go Regenerates ERC-20 bindings.
pkg/​contracts/​ierc20errors/​ierc20errors.go Regenerates ERC-20 error bindings.
pkg/​contracts/​idaveconsensus/​idaveconsensus.go Regenerates Dave bindings.
pkg/​contracts/​idaveappfactory/​idaveappfactory.go Regenerates Dave factory bindings.
pkg/​contracts/​iconsensus/​iconsensus.go Regenerates consensus bindings.
pkg/​contracts/​iauthorityfactory/​iauthorityfactory.go Regenerates authority factory bindings.
pkg/​contracts/​iauthority/​iauthority.go Regenerates authority bindings.
pkg/​contracts/​iapplicationfactory/​iapplicationfactory.go Regenerates application factory bindings.
pkg/​contracts/​iapplication/​iapplication.go Regenerates application bindings.
Makefile Updates version, testing, licenses, and packaging.
licenses/​LGPL-3.0.txt Adds LGPL-3.0 text.
licenses/​GPL-3.0.txt Adds GPL-3.0 text.
internal/​config/​config.go Rejects ambiguous PostgreSQL URLs.
internal/​config/​config_test.go Tests database URL validation.
internal/​claimer/​fixtures_test.go Updates tint test setup.
go.mod Upgrades Go and dependencies.
Dockerfile Installs Go 1.27.1.
dev/​tools.go Updates oapi-codegen path.
dev/​licenses.tpl Adjusts generated notice template.
dev/​licenses-overrides.tsv Adds license corrections.
dev/​licenses-manual.md Adds manually maintained notices.
dev/​licenses-generate.sh Generates merged license notices.
cmd/​cartesi-rollups-machine-tool/​main.go Validates replay database URLs.
cmd/​cartesi-rollups-cli/​root/​withdraw/​withdraw.go Uses compatible RPC dialing.
cmd/​cartesi-rollups-cli/​root/​validate/​validate.go Uses compatible RPC dialing.
cmd/​cartesi-rollups-cli/​root/​send/​send.go Uses compatible RPC dialing.
cmd/​cartesi-rollups-cli/​root/​refund/​refund.go Uses compatible RPC dialing.
cmd/​cartesi-rollups-cli/​root/​refund/​refund_test.go Updates receipt test RPC behavior.
cmd/​cartesi-rollups-cli/​root/​provedriveroot/​provedriveroot.go Uses compatible RPC dialing.
cmd/​cartesi-rollups-cli/​root/​foreclose/​foreclose.go Uses compatible RPC dialing.
cmd/​cartesi-rollups-cli/​root/​execute/​execute.go Uses compatible RPC dialing.
cmd/​cartesi-rollups-cli/​root/​deposit/​deposit.go Uses compatible RPC dialing.
cmd/​cartesi-rollups-cli/​root/​deploy/​quorum.go Uses compatible RPC dialing.
cmd/​cartesi-rollups-cli/​root/​deploy/​authority.go Uses compatible RPC dialing.
cmd/​cartesi-rollups-cli/​root/​deploy/​application.go Uses compatible RPC dialing.
cmd/​cartesi-rollups-cli/​root/​contract/​contract.go Uses compatible RPC dialing.
cmd/​cartesi-rollups-cli/​root/​app/​register/​register.go Uses compatible RPC dialing.
.github/​workflows/​build.yml Adds third-party license checks.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/build.yml
Comment thread dev/licenses-generate.sh
@vfusco
vfusco force-pushed the feature/bump-go-and-deps branch 2 times, most recently from f5a3ba7 to 2ac8436 Compare October 1, 2026 20:09
vfusco added 14 commits October 1, 2026 21:46
Set the Go version to 1.27.1 and update the module versions.
Update THIRD_PARTY_LICENSES.md for the new module versions.
Set the Go version in the README file to 1.27.1.
Set the emulator version to 0.21 in the README file and the notices file.
Use tint.NewTextHandler, because tint v1.2.0 replaces NewHandler with it.
Use oapi-codegen from github.com/oapi-codegen/oapi-codegen/v2. The
project moved there, and the new versions declare this module path.
Return an untyped nil for a pending receipt in the refund test, because
the go-ethereum RPC server calls MarshalJSON on a nil *Receipt since
v1.17.5.
JSON-RPC 2.0 requires a successful response to leave out the error
member. Some providers send it as null instead. Since v1.17.5,
go-ethereum reports any error member as a failed call, so every call to
such a provider would fail.
Remove a null error member from the responses that NewEthClient
receives, in a single response and in each response of a batch.
Add ethutil.DialEthClient. It connects like ethclient.DialContext, and
it removes a null error member from the responses like NewEthClient.
The CLI commands use DialEthClient, so they also work with providers
that send this member.
From v5.11, pgx reads a database URL like libpq. The last of repeated
parameters wins, and a '#' is part of the text. net/url and the lib/pq
driver of the migrations take the first parameter and cut the URL at
'#'. So the node and the migrations can read one URL differently, for
example with TLS on in one and off in the other.
Reject a database URL with a '#' or with a repeated parameter.
Parse the --database-connection flag of the machine tool like the
configuration, so the tool and the node read the same URL the same way.
Generate the bindings again with abigen from go-ethereum v1.17.7.
This version of abigen adds two imports and two blank identifiers.
The Watch functions of the events skip a log with a different event
signature, instead of returning an error.
Generate the inspect client again with oapi-codegen v2.8.0.
This version adds a Valid method to the enums, accessors to the
responses, and the examples of the schema to the comments.
Add a BIP-32 implementation on the secp256k1 curve from go-ethereum.
MnemonicToPrivateKey uses this implementation.
Remove the go-bip32 module and the two modules that it needs.
Add tests with the four published BIP-32 test vectors. Add tests that
compare the keys and the addresses of the ten Anvil accounts.
The BIP-39 step continues to use go-bip39, because that standard needs
the normative word lists.
The configuration accepts any 32-bit account index. From 2^31, the
last level of m/44'/60'/0'/0/i is a hardened child. That key is valid,
but it is not on the path that wallets use, so an operator cannot check
the address with other tools.
Reject an account index from 2^31 in MnemonicToPrivateKey. The error
does not show the index, because the configuration keeps it redacted.
The pure Go artifacts are built with CGO_ENABLED=0. Without cgo,
go-ethereum uses a pure Go secp256k1 instead of libsecp256k1, so the
claimer and the prt derive keys and sign with code that the unit tests
did not run.
After the usual run, unit-test runs the tests of the packages that the
pure Go artifacts link again, with CGO_ENABLED=0. The package list comes
from PURE_GO_ARTIFACTS, and TEST_PACKAGES and TEST_PATTERN apply to it.
The second run does not collect coverage.
The Debian package installed the copyright file in /usr/doc. Debian
expects /usr/share/doc/<package>, which is where tools and users look
for the copyright file of a package.
Keep the entries that go-licenses cannot find in dev/licenses-manual.md.
Keep the corrections for the generated entries in
dev/licenses-overrides.tsv.
Add dev/licenses-generate.sh. The script makes a report for each
released target, with cgo and without it, merges the reports, applies
the corrections, and adds the manual entries. The machine artifacts
are built with cgo and the other artifacts without it, and the two
builds link different packages. The THIRD_PARTY_LICENSES.md recipe
calls this script.

The script fails when go-licenses is not v1.6.0, when an entry has an
unknown license or license URL, and when a correction matches no entry.
go-licenses resolves some URLs over the network, so without network
access the script fails and does not write a degraded file.
The script sets GOROOT to the GOROOT of the go command. go-licenses
recognizes the standard library by its GOROOT, and a go-licenses built
by another Go installation fails without it. The script collects the
reports first, so a go-licenses failure stops it at once.
The THIRD_PARTY_LICENSES.md target is phony, because the notices
depend on more than the files make can see. A failed run keeps the
current file.

Correct the go-ethereum license to LGPL-3.0. go-licenses reads the
COPYING file at the root of the module. The project uses only the
library packages, which are outside cmd/. These packages are LGPL-3.0.
Set the license URL of aws-sdk-go-v2/internal/endpoints/v2. go-licenses
finds its v2 directory with a network request, and without network
access it drops this directory from the URL.
Add a note to go-ethereum/crypto/secp256k1. With cgo, this package
compiles the bundled libsecp256k1 C library, which is MIT.
Set the license URL of decred/dcrd/dcrec/secp256k1/v4. Its module
directory has no license file, so the module zip carries the license
at the repository root. go-licenses links the missing file.

Add the LGPL-3.0 and GPL-3.0 texts from the FSF to the licenses
directory. The LGPL-3.0 adds permissions to the GPL-3.0. Both texts are
necessary. The notices file refers to them.

Add an entry for cartesi/rollups-contracts and for cartesi/dave. The
bindings in pkg/contracts come from the artifacts of these two
repositories.

Describe the two LGPL dependencies in the README file and in the notices
file. The emulator is a dynamic library in its own package. A user can
replace it without a new build of the node. go-ethereum is in the
binaries. To use a different go-ethereum module, a user adds a replace
directive to go.mod and builds the node again.

Set the project name and the unit name in the Authors paragraph of the
README file.
Install THIRD_PARTY_LICENSES.md and the two license texts in the
document directory of the Debian package.
Add a reference to these files at the end of the copyright file.
Add a step that runs go-licenses check for each released target, with
cgo and without it, like dev/licenses-generate.sh. This step does not
permit the forbidden, restricted and unknown license types. go-ethereum
is an approved exception, because go-licenses reads the COPYING file at
the root of the module.
Add a step that fails when a package under go-ethereum/cmd is linked,
in either cgo mode. The exception holds only for the library packages
outside cmd/.
Add a step that makes THIRD_PARTY_LICENSES.md again and compares it with
the file in the repository.
@vfusco
vfusco force-pushed the feature/bump-go-and-deps branch from 2ac8436 to 3615548 Compare October 2, 2026 00:52
@vfusco
vfusco changed the base branch from feature/contracts-bump to fix/keep-nonaccepted-reports October 2, 2026 00:56
@vfusco
vfusco added this pull request to stack #802 October 2, 2026 00:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Todo

Development

Successfully merging this pull request may close these issues.

2 participants