Skip to content

fix(runtime): update shared Go and Rust security dependencies - #2231

Merged
sbaum1994 merged 2 commits into
mainfrom
fix/security-shared-runtime-20261002
Oct 2, 2026
Merged

sbaum1994 merged 2 commits into
mainfrom
fix/security-shared-runtime-20261002

Conversation

@sbaum1994

@sbaum1994 sbaum1994 commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

TL;DR

Refresh the shared Go toolchain and Rust runtime base so rebuilt service images receive the patched Go standard library and glibc. Go moves from 1.26.5 to 1.26.8. NVIDIA distroless cc moves from v4.1.2 to v4.1.4, with the same immutable multi-architecture digest in Bazel and Stargate's Dockerfile.

Additional Details

The central toolchain file and matching go.work.bazel declaration move together. MODULE.bazel.lock was regenerated by Bazel. The Go change affects all consumers of the root SDK, and the cc change affects consumers of the shared Rust base, including function-autoscaler and http-invocation. Stargate's Dockerfile publishing path is updated explicitly.

Package metadata extracted from the runtime layers confirms libc6 changes from 2.41-12+deb13u3 to 2.41-12+deb13u4 on the inspected current/candidate amd64 images. The candidate arm64 image also contains 2.41-12+deb13u4.

This is the dependency stage of #2230. Every affected producer still needs a verified published image before chart image pins change. Shared root changes do not automatically trigger all path-scoped semantic releases. Chart updates follow image publication; stack pins follow chart publication. No future version is assumed here.

The commits separate the Go and libc updates for later maintenance backports. Record the final merge commit as well; regenerate the Bazel lock on each maintenance branch instead of copying unrelated main dependencies. The 1.0.x delivery must repeat the image -> chart -> stack sequence using its retained service trains.

For the Reviewer

Review the central SDK declaration, generated lock changes, and agreement between the Bazel and Dockerfile runtime digests. #2161 separately updates NVCA gRPC and distroless/go; this PR preserves that work's scope. #1952 and #2019 are downstream chart/stack bump PRs to reconcile after patched images exist.

Dependency licenses: Go remains BSD-3-Clause. The runtime is a patch update of the existing base, with its existing package attributions. No new vendored source or repository NOTICE paths are introduced.

For QA

  • Passed tools/ci/check-go-version and git diff --check.
  • Downloaded and verified Go 1.26.8; Bazel generated the updated SDK checksums.
  • Ran the grpc-proxy, ratelimiter, and ess-agent Bazel suites: 49 of 50 targets passed initially. The ESS TestStop_noWaitForSplay wall-clock assertion failed during the concurrent build; its test target then passed all three isolated reruns.
  • Inspected the candidate runtime package metadata on amd64 and arm64.
  • Attempted bazel test //...; it stopped on the byoo-otel-collector genrule's missing host Go prerequisite, before completing the full suite. The collector's separate host-toolchain contract is unchanged.

Linux image build/startup validation and replacement security scans are still required before consuming the new releases. This pin-only change adds no implementation tests; existing service suites and artifact checks validate it.

Issues

Relates to #2230

References: Go release history, Debian glibc fix.

Summary by CodeRabbit

  • Chores
    • Updated the Go toolchain version used by the workspace and related build tooling.
    • Updated the container image version used for the Stargate runtime, with its image digest pinned.
    • Updated the pinned digest for the existing container image; its name and supported platforms remain unchanged.

Rebuild Bazel Go consumers with the patched standard library. Update the
central toolchain, matching workspace declaration, and generated SDK checksums.

Dependency: Go 1.26.5 -> 1.26.8 (BSD-3-Clause).
Relates to #2230

Signed-off-by: Stephanie Baum <sbaum@nvidia.com>
Use the same immutable multi-architecture runtime in Bazel and Stargate.
Verified libc6 2.41-12+deb13u4 in both amd64 and arm64 base manifests.

Dependency: NVIDIA distroless cc v4.1.2 -> v4.1.4.
Relates to #2230

Signed-off-by: Stephanie Baum <sbaum@nvidia.com>
@sbaum1994
sbaum1994 requested review from a team as code owners October 2, 2026 08:21
@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

🧰 Additional context used
📚 Code guidelines (1)
tools/AGENTS.md — auto-discovered

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: NVIDIA/nvcf/.coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 9a695c0a-e30e-4eb9-a201-72880a5e836d

📥 Commits

Reviewing files that changed from the base of the PR and between 9958541 and 3dca091.

⛔ Files ignored due to path filters (1)
  • MODULE.bazel.lock is excluded by !**/*.lock, !**/MODULE.bazel.lock
📒 Files selected for processing (4)
  • MODULE.bazel
  • go.work.bazel
  • src/libraries/rust/stargate/Dockerfile
  • tools/go-toolchain/go.mod

Included review availability: This review used your included allowance. Your plan provides up to 12 included reviews per hour; 10 remain after this review.


📝 Walkthrough

Walkthrough

The pull request updates a pinned distroless image digest, changes the Stargate runtime base image, and updates Go version declarations.

Changes

Runtime image pins

Layer / File(s) Summary
Distroless image references
MODULE.bazel, src/libraries/rust/stargate/Dockerfile
The distroless_cc image digest changes. The Stargate runtime-base stage changes to NVIDIA distroless cc:v4.1.4 pinned by digest.

Go version declarations

Layer / File(s) Summary
Go workspace and toolchain versions
go.work.bazel, tools/go-toolchain/go.mod
The workspace Go version and toolchain directive change from 1.26.5 to 1.26.8.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~8 minutes

Change: Other

Suggested reviewers: balajinvda

Merge Risk: ⚪ Minimal · up to 3dca0

No actionable merge-blocking defect is established. Confirm the pinned image contents and complete the reported image validation and security scans before release.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title follows Conventional Commits syntax with the required runtime scope. The fix type accurately describes security updates to shared Go and Rust runtime dependencies.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 2…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.

Warning

Some tools did not complete. Review the errors below.

🔧 golangci-lint (2.13.2)

level=error msg="Running error: context loading failed: no go files to analyze: running go mod tidy may solve the problem"


Comment @coderabbitai help to get the list of available commands.

@sbaum1994
sbaum1994 added this pull request to the merge queue Oct 2, 2026
Merged via the queue into main with commit c56b1ab Oct 2, 2026
29 checks passed
@sbaum1994
sbaum1994 deleted the fix/security-shared-runtime-20261002 branch October 2, 2026 15:41
@balajinvda

Copy link
Copy Markdown
Contributor

🎉 This PR is included in src/libraries/rust/stargate/v0.19.9 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

@balajinvda

Copy link
Copy Markdown
Contributor

This PR is included in version 1.29.2.

The release is available on GitHub release.

@balajinvda

Copy link
Copy Markdown
Contributor

This PR is included in version 1.69.1.

The release is available on GitHub release.

@balajinvda

Copy link
Copy Markdown
Contributor

This PR is included in version 1.25.1.

The release is available on GitHub release.

@balajinvda

Copy link
Copy Markdown
Contributor

This PR is included in version 1.14.2.

The release is available on GitHub release.

@balajinvda

Copy link
Copy Markdown
Contributor

This PR is included in version 1.10.1.

The release is available on GitHub release.

@balajinvda

Copy link
Copy Markdown
Contributor

This PR is included in version 0.5.1.

The release is available on GitHub release.

@balajinvda

Copy link
Copy Markdown
Contributor

This PR is included in version 0.9.1.

The release is available on GitHub release.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants