From 73b12486eb38010a7b1e3183ec5e6a1a69735b1c Mon Sep 17 00:00:00 2001 From: maclane Date: Tue, 8 Sep 2026 09:28:33 -0500 Subject: [PATCH 1/3] build: align Go builders and CI on 1.26.8 --- .github/workflows/client.yml | 12 ++++++------ Dockerfile | 7 ++++--- go.mod | 4 ++-- 3 files changed, 12 insertions(+), 11 deletions(-) diff --git a/.github/workflows/client.yml b/.github/workflows/client.yml index d6e2bdad72..7b1e1c75ca 100644 --- a/.github/workflows/client.yml +++ b/.github/workflows/client.yml @@ -81,9 +81,9 @@ jobs: - uses: actions/checkout@v4 - name: Set up Go - uses: actions/setup-go@v5 + uses: actions/setup-go@v6 with: - go-version: '1.24.1' + go-version-file: "go.mod" - name: Verify vendored btcec byte identity vs upstream v0.22.3 run: | @@ -339,7 +339,7 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - - uses: actions/setup-go@v5 + - uses: actions/setup-go@v6 with: go-version-file: "go.mod" - name: gofmt @@ -357,7 +357,7 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - - uses: actions/setup-go@v5 + - uses: actions/setup-go@v6 with: go-version-file: "go.mod" - run: go vet @@ -370,13 +370,13 @@ jobs: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - - uses: actions/setup-go@v5 + - uses: actions/setup-go@v6 with: go-version-file: "go.mod" - name: Staticcheck uses: dominikh/staticcheck-action@v1.4.0 with: - version: "2025.1.1" + version: "2026.1" install-go: false checks: "-SA1019" diff --git a/Dockerfile b/Dockerfile index dce9eba139..11f96a5242 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,4 +1,5 @@ -FROM golang:1.24-alpine3.21 AS build-sources +# Keep both builders aligned with the toolchain directive in go.mod. +FROM golang:1.26.8-alpine3.23 AS build-sources ENV GOPATH=/go \ GOBIN=/go/bin \ @@ -91,7 +92,7 @@ RUN GOOS=linux make build \ version=$VERSION \ revision=$REVISION -FROM alpine:3.21 as runtime-docker +FROM alpine:3.23 as runtime-docker ENV APP_NAME=keep-client \ APP_DIR=/go/src/github.com/keep-network/keep-core \ @@ -111,7 +112,7 @@ CMD [] # # Build Binaries # -FROM golang:1.24-bullseye AS build-bins +FROM golang:1.26.8-bookworm AS build-bins ENV APP_DIR=/go/src/github.com/keep-network/keep-core diff --git a/go.mod b/go.mod index be68423897..989c35b390 100644 --- a/go.mod +++ b/go.mod @@ -1,8 +1,8 @@ module github.com/keep-network/keep-core -go 1.24.0 +go 1.25.7 -toolchain go1.24.1 +toolchain go1.26.8 replace ( github.com/bnb-chain/tss-lib => github.com/threshold-network/tss-lib v0.0.0-20230901144531-2e712689cfbe From 10b0812e2a07f716143253917be590ee9f52724d Mon Sep 17 00:00:00 2001 From: maclane Date: Tue, 8 Sep 2026 10:04:59 -0500 Subject: [PATCH 2/3] build: preserve glibc 2.31 for Linux releases Keep Bullseye's C compiler and libc while copying the Go 1.26.8 toolchain from the official image. Run packaged Linux binaries on Debian 11 and Ubuntu 20.04 before publication. Align the benchmark job inherited from dev with the module-selected Go toolchain. --- .github/workflows/client.yml | 18 ++++++++++++++++-- Dockerfile | 10 ++++++++-- 2 files changed, 24 insertions(+), 4 deletions(-) diff --git a/.github/workflows/client.yml b/.github/workflows/client.yml index 7b1e1c75ca..539c08a234 100644 --- a/.github/workflows/client.yml +++ b/.github/workflows/client.yml @@ -268,6 +268,17 @@ jobs: push: false context: . + - name: Verify Linux release compatibility + run: | + release_dir=$(mktemp -d) + trap 'rm -rf "$release_dir"' EXIT + tar -xzf out/bin/*-linux-amd64.tar.gz -C "$release_dir" + for image in debian:bullseye-slim ubuntu:20.04; do + docker run --rm --platform linux/amd64 \ + --mount "type=bind,src=$release_dir,dst=/release,readonly" \ + "$image" sh -ec 'getconf GNU_LIBC_VERSION; /release/keep-client --version' + done + - name: Archive Client Binaries uses: actions/upload-artifact@v4 with: @@ -386,14 +397,17 @@ jobs: runs-on: ubuntu-latest permissions: actions: read + contents: read steps: + - uses: actions/checkout@v4 + - name: Set up Docker Buildx uses: docker/setup-buildx-action@v3 - name: Set up Go - uses: actions/setup-go@v5 + uses: actions/setup-go@v6 with: - go-version: "1.24" + go-version-file: "go.mod" cache: false - name: Download Docker Build Image diff --git a/Dockerfile b/Dockerfile index 11f96a5242..6230f82edd 100644 --- a/Dockerfile +++ b/Dockerfile @@ -112,9 +112,15 @@ CMD [] # # Build Binaries # -FROM golang:1.26.8-bookworm AS build-bins +# Keep cgo release binaries compatible with glibc 2.31 (Debian 11/Ubuntu 20.04). +# Copy only Go so the C compiler and libc still come from Bullseye. +FROM buildpack-deps:bullseye AS build-bins -ENV APP_DIR=/go/src/github.com/keep-network/keep-core +COPY --from=golang:1.26.8-bookworm /usr/local/go /usr/local/go + +ENV PATH=/usr/local/go/bin:$PATH \ + GOTOOLCHAIN=local \ + APP_DIR=/go/src/github.com/keep-network/keep-core WORKDIR $APP_DIR From 97b4e1ce5a26a6db467f322e619de059d844b61d Mon Sep 17 00:00:00 2001 From: maclane Date: Tue, 8 Sep 2026 10:28:40 -0500 Subject: [PATCH 3/3] ci: verify Linux compatibility before tagged releases --- .github/workflows/release.yml | 13 ++++++++++++- 1 file changed, 12 insertions(+), 1 deletion(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 7df458d649..43c26f7d62 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -67,6 +67,17 @@ jobs: push: false context: . + - name: Verify Linux release compatibility + run: | + release_dir=$(mktemp -d) + trap 'rm -rf "$release_dir"' EXIT + tar -xzf out/bin/*-linux-amd64.tar.gz -C "$release_dir" + for image in debian:bullseye-slim ubuntu:20.04; do + docker run --rm --platform linux/amd64 \ + --mount "type=bind,src=$release_dir,dst=/release,readonly" \ + "$image" sh -ec 'getconf GNU_LIBC_VERSION; /release/keep-client --version' + done + - name: Generate release notes id: release_notes run: | @@ -172,4 +183,4 @@ jobs: - name: Move Docker cache run: | rm -rf /tmp/.buildx-cache - mv /tmp/.buildx-cache-docker-new /tmp/.buildx-cache \ No newline at end of file + mv /tmp/.buildx-cache-docker-new /tmp/.buildx-cache