Skip to content

fix(oauth2-proxy.github.io): update Go build dependency - #14531

Open
brandon-julio-t wants to merge 1 commit into
pkgxdev:mainfrom
brandon-julio-t:codex/oauth2-proxy-go-toolchain
Open

brandon-julio-t wants to merge 1 commit into
pkgxdev:mainfrom
brandon-julio-t:codex/oauth2-proxy-go-toolchain

Conversation

@brandon-julio-t

@brandon-julio-t brandon-julio-t commented Oct 2, 2026 •

Copy link
Copy Markdown

Summary

  • What changed: update OAuth2 Proxy's Go build dependency from 1.22.4 to ~1.26.8.
  • Why: OAuth2 Proxy v7.15.5 explicitly upgrades its release toolchain to Go 1.26.8, but freshly downloaded Pantry v7.15.5 Linux bottles still embed Go 1.26.0. The module declares go 1.26.0; automatic toolchain selection satisfies that minimum without ensuring the release's newer patch toolchain. Selecting the compiler in the recipe preserves the release's intended runtime patch level and permits subsequent Go 1.26 patch updates.

Please rebuild the existing v7.15.5 bottles when landing this change. A recipe update alone cannot change bottles already on the CDN.

Searched open and closed pkgxdev issues/PRs and discussions for OAuth2 Proxy before submitting; the only package-specific result was the original addition, #7319. This follows the targeted Go dependency updates in #12190.

Reproduce the published-bottle mismatch

Prerequisites: Bash, curl, tar with xz support, sha256sum, and Go on PATH. This inspects embedded build metadata; it does not execute either downloaded binary, so both architectures can be checked on one host.

set -euo pipefail
repro_dir=$(mktemp -d)
cd "$repro_dir"
for arch in aarch64 x86-64; do
  curl --fail --silent --show-error --location \
    "https://dist.pkgx.dev/oauth2-proxy.github.io/linux/$arch/v7.15.5.tar.xz" \
    --output "$arch.tar.xz"
  sha256sum "$arch.tar.xz"
  mkdir "$arch"
  tar -xJf "$arch.tar.xz" -C "$arch"
  go version "$arch/oauth2-proxy.github.io/v7.15.5/bin/oauth2-proxy"
done

Observed on re-download during this review:

1d56fb2fa0f81f37b60011d8aea0b9d8a9f9bf2986b213540dd4bfbdd1a61111  aarch64.tar.xz
aarch64/oauth2-proxy.github.io/v7.15.5/bin/oauth2-proxy: go1.26.0
f63940a84116d939742c7e32f9785bc41f52e5d3239754bcf8d72b471b90e3af  x86-64.tar.xz
x86-64/oauth2-proxy.github.io/v7.15.5/bin/oauth2-proxy: go1.26.0

Expected: rebuilt v7.15.5 bottles embed Go 1.26.8 or a later Go 1.26 patch, matching the release's toolchain baseline. These hashes identify the observed archives; replacement bottles should change them.

The concrete defect established here is the compiler/runtime patch-level mismatch. The recipe's old compiler constraint plus the module's go 1.26.0 minimum explains how automatic toolchain selection can produce it; historical publisher build logs were not inspected. This report does not establish exploitability or attribute every advisory in the application release notes to this compiler mismatch.

Reproduce the patched build

With pkgx installed and GitHub API access configured as described in the repository README, fetch this PR into a fresh checkout:

git clone https://github.com/pkgxdev/pantry.git pantry-pr-14531
cd pantry-pr-14531
git fetch origin pull/14531/head
git checkout --detach 43f9aac3ec1e0b4e8a743fabfc2f1a84c3470125
export PKGX_PANTRY_PATH="$PWD"
export PKGX_PANTRY_DIR="$PWD"
export PKGX_DIR="$(mktemp -d)"
pkgx bk build oauth2-proxy.github.io@7.15.5
pkgx bk test oauth2-proxy.github.io@7.15.5
pkgx bk audit oauth2-proxy.github.io@7.15.5
"$PKGX_DIR/oauth2-proxy.github.io/v7.15.5/bin/oauth2-proxy" --version

The last command must run on the build host's architecture. The local Linux aarch64 build reported oauth2-proxy 2df061b-dirty (built with go1.26.8). The application version text is existing recipe behavior; the relevant before/after evidence is the embedded Go version. The commands above express the same isolated-prefix build procedure with portable paths.

Acceptance: platform build/test/audit succeeds, then replacement v7.15.5 bottles are published and their embedded Go version is rechecked. Merging the recipe alone does not complete the CDN remediation.

AI Intent

  • Prompt or task statement: verify that the outdated OAuth2 Proxy toolchain remains an issue, avoid duplicating existing work, and contribute a tested upstream fix.
  • Scope of AI-assisted changes: investigation, the single recipe dependency change, validation, and this PR description were assisted by OpenAI Codex.

Risk Assessment

  • Risk level: low.
  • Primary risks: compiler changes can affect generated binaries; other platforms require CI validation.
  • Compatibility impact: application sources, build command, installed paths, and runtime dependencies are unchanged. Go 1.26.8 is available in Pantry for Linux/macOS on aarch64/x86-64. This does not claim that independently built Pantry binaries are byte-identical to official release binaries.

Rollback Plan

  • Revert path: revert this recipe change; any published replacement bottles would require maintainer rebuild/republication.
  • Forward-fix path (if revert is not possible): correct the compiler constraint and rebuild affected bottles.

Validation

Local validation on Linux aarch64 with pkgx 2.11.0 / Brewkit 1.23.2:

  • bk build oauth2-proxy.github.io@7.15.5 — passed with the edited recipe and an isolated package prefix; resulting binary reports built with go1.26.8.
  • bk test oauth2-proxy.github.io@7.15.5 — passed.
  • bk audit oauth2-proxy.github.io@7.15.5 — passed.
  • Local server smoke check — /ping returned 200; /oauth2/auth without a session returned 401. No external identity-provider login was tested.
  • git diff --check — passed.
  • Fresh downloads of both Linux aarch64 and Linux x86-64 bottles report go1.26.0 via go version <binary>.

Brewkit emitted a nonfatal patchelf warning about a missing .dynamic section; both the existing and rebuilt ARM64 binaries are statically linked. Build, test, and audit all exited 0. The existing recipe's Git-derived application version string remains unchanged in behavior.

CI checks expected: Pantry's platform build/audit/test matrix. macOS and native x86-64 execution were not tested locally.

Internal/Public Boundary Check

  • No internal-only data, private URLs, secrets, or private runbooks were added.

OAuth2 Proxy v7.15.5 upgrades its release toolchain to Go 1.26.8, but
Pantry's published Linux bottles still embed Go 1.26.0. The old 1.22.4
build dependency allows automatic toolchain selection to satisfy only
the module's 1.26.0 minimum, missing the intended runtime patch level.

Select Go ~1.26.8 so rebuilt packages include that runtime patch level
and can pick up subsequent patches in the same Go release line.

Release: https://github.com/oauth2-proxy/oauth2-proxy/releases/tag/v7.15.5

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant