Conversation
vfusco
requested review from
mpolitzer and
renatomaia
and
a balanced review from Copilot
October 1, 2026 17:56
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub. |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
License generation and CI omit the dependency graphs of released CGO-disabled binaries.
Review effort: Balanced
Findings: 2
Open (2)
What changed in this PR
Updates Go and dependencies, regenerates clients/contracts, improves compatibility, and expands licensing automation.
Changes:
- Upgrades Go, modules, generated bindings, and release version.
- Adds JSON-RPC compatibility, database URL validation, and internal BIP-32 derivation.
- Adds multi-platform license notices and Debian packaging support.
| File | Description |
|---|---|
THIRD_PARTY_LICENSES.md |
Updates dependency notices. |
README.md |
Updates requirements and licensing details. |
pkg/service/service.go |
Adopts tint’s renamed handler. |
pkg/inspectclient/main.go |
Updates generator module path. |
pkg/inspectclient/generated.go |
Regenerates the inspect client. |
pkg/ethutil/rpc_response.go |
Filters null JSON-RPC errors. |
pkg/ethutil/rpc_response_test.go |
Tests response filtering. |
pkg/ethutil/mnemonic.go |
Uses internal BIP-32 derivation. |
pkg/ethutil/mnemonic_test.go |
Expands key derivation tests. |
pkg/ethutil/client.go |
Integrates compatible RPC transports. |
pkg/ethutil/bip32.go |
Implements BIP-32 derivation. |
pkg/ethutil/bip32_test.go |
Tests BIP-32 vectors. |
pkg/contracts/outputs/outputs.go |
Regenerates contract bindings. |
pkg/contracts/iusdwithdrawaloutputbuilder/iusdwithdrawaloutputbuilder.go |
Regenerates contract bindings. |
pkg/contracts/itournament/itournament.go |
Regenerates tournament bindings. |
pkg/contracts/iselfhostedapplicationfactory/iselfhostedapplicationfactory.go |
Regenerates factory bindings. |
pkg/contracts/iquorumfactory/iquorumfactory.go |
Regenerates quorum factory bindings. |
pkg/contracts/iquorum/iquorum.go |
Regenerates quorum bindings. |
pkg/contracts/inputs/inputs.go |
Regenerates input bindings. |
pkg/contracts/imultileveltournamentfactory/imultileveltournamentfactory.go |
Regenerates tournament factory bindings. |
pkg/contracts/iinputbox/iinputbox.go |
Regenerates input-box bindings. |
pkg/contracts/ierc20portal/ierc20portal.go |
Regenerates portal bindings. |
pkg/contracts/ierc20metadata/ierc20metadata.go |
Regenerates ERC-20 bindings. |
pkg/contracts/ierc20errors/ierc20errors.go |
Regenerates ERC-20 error bindings. |
pkg/contracts/idaveconsensus/idaveconsensus.go |
Regenerates Dave bindings. |
pkg/contracts/idaveappfactory/idaveappfactory.go |
Regenerates Dave factory bindings. |
pkg/contracts/iconsensus/iconsensus.go |
Regenerates consensus bindings. |
pkg/contracts/iauthorityfactory/iauthorityfactory.go |
Regenerates authority factory bindings. |
pkg/contracts/iauthority/iauthority.go |
Regenerates authority bindings. |
pkg/contracts/iapplicationfactory/iapplicationfactory.go |
Regenerates application factory bindings. |
pkg/contracts/iapplication/iapplication.go |
Regenerates application bindings. |
Makefile |
Updates version, testing, licenses, and packaging. |
licenses/LGPL-3.0.txt |
Adds LGPL-3.0 text. |
licenses/GPL-3.0.txt |
Adds GPL-3.0 text. |
internal/config/config.go |
Rejects ambiguous PostgreSQL URLs. |
internal/config/config_test.go |
Tests database URL validation. |
internal/claimer/fixtures_test.go |
Updates tint test setup. |
go.mod |
Upgrades Go and dependencies. |
Dockerfile |
Installs Go 1.27.1. |
dev/tools.go |
Updates oapi-codegen path. |
dev/licenses.tpl |
Adjusts generated notice template. |
dev/licenses-overrides.tsv |
Adds license corrections. |
dev/licenses-manual.md |
Adds manually maintained notices. |
dev/licenses-generate.sh |
Generates merged license notices. |
cmd/cartesi-rollups-machine-tool/main.go |
Validates replay database URLs. |
cmd/cartesi-rollups-cli/root/withdraw/withdraw.go |
Uses compatible RPC dialing. |
cmd/cartesi-rollups-cli/root/validate/validate.go |
Uses compatible RPC dialing. |
cmd/cartesi-rollups-cli/root/send/send.go |
Uses compatible RPC dialing. |
cmd/cartesi-rollups-cli/root/refund/refund.go |
Uses compatible RPC dialing. |
cmd/cartesi-rollups-cli/root/refund/refund_test.go |
Updates receipt test RPC behavior. |
cmd/cartesi-rollups-cli/root/provedriveroot/provedriveroot.go |
Uses compatible RPC dialing. |
cmd/cartesi-rollups-cli/root/foreclose/foreclose.go |
Uses compatible RPC dialing. |
cmd/cartesi-rollups-cli/root/execute/execute.go |
Uses compatible RPC dialing. |
cmd/cartesi-rollups-cli/root/deposit/deposit.go |
Uses compatible RPC dialing. |
cmd/cartesi-rollups-cli/root/deploy/quorum.go |
Uses compatible RPC dialing. |
cmd/cartesi-rollups-cli/root/deploy/authority.go |
Uses compatible RPC dialing. |
cmd/cartesi-rollups-cli/root/deploy/application.go |
Uses compatible RPC dialing. |
cmd/cartesi-rollups-cli/root/contract/contract.go |
Uses compatible RPC dialing. |
cmd/cartesi-rollups-cli/root/app/register/register.go |
Uses compatible RPC dialing. |
.github/workflows/build.yml |
Adds third-party license checks. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
vfusco
force-pushed
the
feature/bump-go-and-deps
branch
2 times, most recently
from
October 1, 2026 20:09
f5a3ba7 to
2ac8436
Compare
Set the Go version to 1.27.1 and update the module versions. Update THIRD_PARTY_LICENSES.md for the new module versions. Set the Go version in the README file to 1.27.1. Set the emulator version to 0.21 in the README file and the notices file. Use tint.NewTextHandler, because tint v1.2.0 replaces NewHandler with it. Use oapi-codegen from github.com/oapi-codegen/oapi-codegen/v2. The project moved there, and the new versions declare this module path. Return an untyped nil for a pending receipt in the refund test, because the go-ethereum RPC server calls MarshalJSON on a nil *Receipt since v1.17.5.
JSON-RPC 2.0 requires a successful response to leave out the error member. Some providers send it as null instead. Since v1.17.5, go-ethereum reports any error member as a failed call, so every call to such a provider would fail. Remove a null error member from the responses that NewEthClient receives, in a single response and in each response of a batch.
Add ethutil.DialEthClient. It connects like ethclient.DialContext, and it removes a null error member from the responses like NewEthClient. The CLI commands use DialEthClient, so they also work with providers that send this member.
From v5.11, pgx reads a database URL like libpq. The last of repeated parameters wins, and a '#' is part of the text. net/url and the lib/pq driver of the migrations take the first parameter and cut the URL at '#'. So the node and the migrations can read one URL differently, for example with TLS on in one and off in the other. Reject a database URL with a '#' or with a repeated parameter. Parse the --database-connection flag of the machine tool like the configuration, so the tool and the node read the same URL the same way.
Generate the bindings again with abigen from go-ethereum v1.17.7. This version of abigen adds two imports and two blank identifiers. The Watch functions of the events skip a log with a different event signature, instead of returning an error.
Generate the inspect client again with oapi-codegen v2.8.0. This version adds a Valid method to the enums, accessors to the responses, and the examples of the schema to the comments.
Add a BIP-32 implementation on the secp256k1 curve from go-ethereum. MnemonicToPrivateKey uses this implementation. Remove the go-bip32 module and the two modules that it needs. Add tests with the four published BIP-32 test vectors. Add tests that compare the keys and the addresses of the ten Anvil accounts. The BIP-39 step continues to use go-bip39, because that standard needs the normative word lists.
The configuration accepts any 32-bit account index. From 2^31, the last level of m/44'/60'/0'/0/i is a hardened child. That key is valid, but it is not on the path that wallets use, so an operator cannot check the address with other tools. Reject an account index from 2^31 in MnemonicToPrivateKey. The error does not show the index, because the configuration keeps it redacted.
The pure Go artifacts are built with CGO_ENABLED=0. Without cgo, go-ethereum uses a pure Go secp256k1 instead of libsecp256k1, so the claimer and the prt derive keys and sign with code that the unit tests did not run. After the usual run, unit-test runs the tests of the packages that the pure Go artifacts link again, with CGO_ENABLED=0. The package list comes from PURE_GO_ARTIFACTS, and TEST_PACKAGES and TEST_PATTERN apply to it. The second run does not collect coverage.
The Debian package installed the copyright file in /usr/doc. Debian expects /usr/share/doc/<package>, which is where tools and users look for the copyright file of a package.
Keep the entries that go-licenses cannot find in dev/licenses-manual.md. Keep the corrections for the generated entries in dev/licenses-overrides.tsv. Add dev/licenses-generate.sh. The script makes a report for each released target, with cgo and without it, merges the reports, applies the corrections, and adds the manual entries. The machine artifacts are built with cgo and the other artifacts without it, and the two builds link different packages. The THIRD_PARTY_LICENSES.md recipe calls this script. The script fails when go-licenses is not v1.6.0, when an entry has an unknown license or license URL, and when a correction matches no entry. go-licenses resolves some URLs over the network, so without network access the script fails and does not write a degraded file. The script sets GOROOT to the GOROOT of the go command. go-licenses recognizes the standard library by its GOROOT, and a go-licenses built by another Go installation fails without it. The script collects the reports first, so a go-licenses failure stops it at once. The THIRD_PARTY_LICENSES.md target is phony, because the notices depend on more than the files make can see. A failed run keeps the current file. Correct the go-ethereum license to LGPL-3.0. go-licenses reads the COPYING file at the root of the module. The project uses only the library packages, which are outside cmd/. These packages are LGPL-3.0. Set the license URL of aws-sdk-go-v2/internal/endpoints/v2. go-licenses finds its v2 directory with a network request, and without network access it drops this directory from the URL. Add a note to go-ethereum/crypto/secp256k1. With cgo, this package compiles the bundled libsecp256k1 C library, which is MIT. Set the license URL of decred/dcrd/dcrec/secp256k1/v4. Its module directory has no license file, so the module zip carries the license at the repository root. go-licenses links the missing file. Add the LGPL-3.0 and GPL-3.0 texts from the FSF to the licenses directory. The LGPL-3.0 adds permissions to the GPL-3.0. Both texts are necessary. The notices file refers to them. Add an entry for cartesi/rollups-contracts and for cartesi/dave. The bindings in pkg/contracts come from the artifacts of these two repositories. Describe the two LGPL dependencies in the README file and in the notices file. The emulator is a dynamic library in its own package. A user can replace it without a new build of the node. go-ethereum is in the binaries. To use a different go-ethereum module, a user adds a replace directive to go.mod and builds the node again. Set the project name and the unit name in the Authors paragraph of the README file.
Install THIRD_PARTY_LICENSES.md and the two license texts in the document directory of the Debian package. Add a reference to these files at the end of the copyright file.
Add a step that runs go-licenses check for each released target, with cgo and without it, like dev/licenses-generate.sh. This step does not permit the forbidden, restricted and unknown license types. go-ethereum is an approved exception, because go-licenses reads the COPYING file at the root of the module. Add a step that fails when a package under go-ethereum/cmd is linked, in either cgo mode. The exception holds only for the library packages outside cmd/. Add a step that makes THIRD_PARTY_LICENSES.md again and compares it with the file in the repository.
vfusco
force-pushed
the
feature/bump-go-and-deps
branch
from
October 2, 2026 00:52
2ac8436 to
3615548
Compare
vfusco
changed the base branch from
feature/contracts-bump
to
fix/keep-nonaccepted-reports
October 2, 2026 00:56
vfusco
added this pull request to stack #802
October 2, 2026 00:58
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Dependencies
github.com/oapi-codegen/oapi-codegen/v2.Fixes for the new versions
"error": null. The node and the CLI remove this member from the responses.#or a repeated parameter.Key derivation
make unit-testalso runs the tests of the pure Go binaries without cgo. These binaries use a different secp256k1 implementation.License notices
THIRD_PARTY_LICENSES.mdfor linux/amd64 and linux/arm64, with manual entries and corrections./usr/share/doc.Other