Skip to content

Update Go crypto dependencies and align the Go toolchain - #20

Merged
piotr-roslaniec merged 2 commits into
devfrom
codex/deps-go-crypto
Sep 29, 2026
Merged

piotr-roslaniec merged 2 commits into
devfrom
codex/deps-go-crypto

Conversation

@mswilkison

@mswilkison mswilkison commented Sep 14, 2026 •

Copy link
Copy Markdown

Depends on #19 and is stacked on codex/deps-protobuf-runtime.

Upgrade golang.org/x/crypto to v0.52.0 and its required golang.org/x/sys to v0.45.0. These versions cover the 25 current x/crypto Dependabot alerts and the single x/sys alert, including the published June 2026 SSH fixes. The inherited protobuf update remains v1.33.0.

Raise the Go minimum to 1.25.7 and select Go 1.26.8 in the module and both CI workflows. This aligns with keep-core #4312; downstream adoption requires the Go upgrade. Modern module pruning makes existing indirect dependencies explicit without upgrading their versions. The selected x/sys version supersedes the older upgrade in #11/#17 and must be retained when those branches are integrated.

Validation on the final stacked commit with Go 1.26.8:

  • Complete CKD, tss, and signing suites pass, including all 12 existing xpub derivation vectors, inherited binary protobuf compatibility tests, and ordinary/HD signing E2E tests.
  • Full build, vet, module-tidy consistency, formatting, and diff checks pass.
  • Selected dependencies are x/crypto v0.52.0, x/sys v0.45.0, and protobuf v1.33.0. Independent review also checked Linux dependency selection and module checksums.
  • Before stacking, the remaining inexpensive crypto packages and nine keygen controls passed. Full repository CI subsequently passed at the current stacked head, including the keygen, MtA, Paillier, and prime-generation suites.

The library imports RIPEMD-160 from x/crypto. This removes advisory-affected dependency versions without claiming that the SSH vulnerabilities were reachable through tss-lib.

Full test CI and formatting CI passed at the current head a1dc49cecbe436d45e03cf4c6ebe2e5f042691e5. These workflows were dispatched explicitly because this stacked PR does not target master.

Select x/crypto v0.52.0 and its required x/sys v0.45.0. Align the minimum Go version to 1.25.7 and development and CI toolchain to 1.26.8 while preserving runtime source and existing compatibility vectors.
@piotr-roslaniec
piotr-roslaniec changed the base branch from codex/deps-protobuf-runtime to dev September 29, 2026 09:10
Keep this PR's Go 1.25.7 minimum, go1.26.8 toolchain, and x/sys v0.45.0
(supersedes the x/sys v0.11.0 from #11). Add filippo.io/bigmod v0.1.0
required by the constant-time code from #11; go mod tidy under go1.26.8.
@piotr-roslaniec
piotr-roslaniec merged commit b7b6695 into dev Sep 29, 2026
2 checks passed
@piotr-roslaniec

Copy link
Copy Markdown

Merged into dev.

Before merging, origin/dev (#11, #18, #24) was merged into this branch (a91a6e2). The only conflict was go.mod/go.sum. Kept this PR's Go 1.25.7 minimum, the go1.26.8 toolchain, and x/sys v0.45.0 (it replaces the x/sys v0.11.0 from #11). Added filippo.io/bigmod v0.1.0 for the constant-time code. Ran go mod tidy under go1.26.8.

Checks on the merged head:

  • go1.26.8: go build, go vet, gofmt -l, and go mod verify all clean. Full go test ./... passes locally (1360 s). CI is green.
  • govulncheck: none of the module advisories are reachable from code. The 4 x/crypto v0.52.0 advisories (ssh/openpgp) are in the module graph but not the import graph; tss-lib only imports ripemd160.
  • The go directive moves from 1.23 to 1.25.7. Checked the goroutine-in-loop closures for the Go 1.22 loop-variable change: behavior is the same.
  • keep-core builds with GOTOOLCHAIN=auto. The 1.25.7 minimum makes consumers still on 1.25.6 or older download a newer toolchain.

Full report: agent-docs/pr-integration/20.md (local).

piotr-roslaniec added a commit that referenced this pull request Sep 29, 2026
Merge origin/dev (contains #18/#20/#21) into the input-guards branch.
Auto-merged cleanly (no textual conflicts); key choices:
- go.mod/go.sum: adopt origin/dev toolchain and dependencies
  (go 1.25.7, toolchain go1.26.8, x/crypto v0.52.0, x/sys v0.45.0,
  protobuf v1.33.0, btcd v0.24.2, btcec/v2 v2.2.0, btcutil v1.1.5,
  bigmod v0.1.0) per the integration contract.
- crypto/mta/proofs.go: keep #12 decoder guards (ProofBobWC 12-part
  arity, Bytes nil-receiver panics) plus dev's CT/sampling changes;
  changes were in disjoint regions and both survived.
piotr-roslaniec added a commit that referenced this pull request Sep 29, 2026
Merge current origin/dev (includes #18/#20/#21) into the PR #14 branch.

Conflict choices:
- No textual conflicts; clean automatic merge.
- Go toolchain/deps kept from origin/dev (go 1.25.7, toolchain go1.26.8,
  x/crypto v0.52.0, x/sys v0.45.0, protobuf v1.33.0, btcd v0.24.2,
  btcec/v2 v2.2.0, btcutil v1.1.5, bigmod v0.1.0).
- Preserved PR #14 changes on top of dev: BaseParty fatal-error latch
  (abort/abortedWith) and keygen unmarshalVSSCommitment part-count guard
  in ecdsa/keygen/round_3.go.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants