Skip to content

makefile: fetch tailscale.com via the module proxy in update-oss - #880

Merged
bradfitz merged 1 commit into
mainfrom
bradfitz/update-oss-proxy
Sep 21, 2026
Merged

bradfitz merged 1 commit into
mainfrom
bradfitz/update-oss-proxy

Conversation

@bradfitz

@bradfitz bradfitz commented Sep 21, 2026 •

Copy link
Copy Markdown
Member

The update-oss target set GOPROXY=direct for the whole go get because
proxy.golang.org caches branch resolution and often returned a stale
commit for tailscale.com@main. But direct mode also made every
dependency a slow git clone.

Instead, resolve the tip of main ourselves with git ls-remote and go get
that exact commit. The proxy fetches explicit revisions on demand, so
tailscale.com and all of its dependencies come from the proxy. If that
fails, fall back to GONOPROXY=tailscale.com so only tailscale.com is
fetched directly while everything else still uses the proxy.

This is motivated by a wireguard-go tag that changed after
sum.golang.org grabbed it, so:

go: upgraded golang.zx2c4.com/wireguard/windows v0.5.3 => v1.0.1: error finding sum for golang.zx2c4.com/wireguard/windows@v1.0.1: golang.zx2c4.com/wireguard/windows@v1.0.1: verifying module: checksum mismatch
    downloaded: h1:zRLGRx84kiOcxqkYLoeKYCQNBO2tKYOKXu7AvlSZ6h4=
    sum.golang.org: h1:eOxiDVbywPC+ZQqvdCK7x+ZwWXKbYv50TtH8ysFIbw8=

Instead, get it from proxy.golang.org which doesn't match the upstream
git tag anymore, but passes the sum.golang.org validation.

Fixes tailscale/corp#48607

@bradfitz
bradfitz requested a review from kari-ts September 21, 2026 20:33
The update-oss target set GOPROXY=direct for the whole go get because
proxy.golang.org caches branch resolution and often returned a stale
commit for tailscale.com@main. But direct mode also made every
dependency a slow git clone.

Instead, resolve the tip of main ourselves with git ls-remote and go get
that exact commit. The proxy fetches explicit revisions on demand, so
tailscale.com and all of its dependencies come from the proxy. If that
fails, fall back to GONOPROXY=tailscale.com so only tailscale.com is
fetched directly while everything else still uses the proxy.

This is motivated by a wireguard-go tag that changed after
sum.golang.org grabbed it, so:

    go: upgraded golang.zx2c4.com/wireguard/windows v0.5.3 => v1.0.1: error finding sum for golang.zx2c4.com/wireguard/windows@v1.0.1: golang.zx2c4.com/wireguard/windows@v1.0.1: verifying module: checksum mismatch
        downloaded: h1:zRLGRx84kiOcxqkYLoeKYCQNBO2tKYOKXu7AvlSZ6h4=
        sum.golang.org: h1:eOxiDVbywPC+ZQqvdCK7x+ZwWXKbYv50TtH8ysFIbw8=

Instead, get it from proxy.golang.org which doesn't match the upstream
git tag anymore, but passes the sum.golang.org validation.

Fixes tailscale/corp#48607

Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>
Change-Id: I7c2e4f9a1b3d5e6f8a0b2c4d6e8f0a1b3c5d7e9f
@bradfitz
bradfitz force-pushed the bradfitz/update-oss-proxy branch from 8b8ae46 to a048cf7 Compare September 21, 2026 22:35
@bradfitz
bradfitz merged commit 418b8ba into main Sep 21, 2026
5 checks passed
@bradfitz
bradfitz deleted the bradfitz/update-oss-proxy branch September 21, 2026 22:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants