Skip to content

Commit d6d3665

Browse files
build(deps): upgrade Go to 1.26.7 and dependencies for CVE remediation (#5046)
* build(deps): upgrade Go to 1.26.7 and dependencies for CVE remediation * upgrade golang to 1.26.7 (CVE fixes) * test(monitoring): use NewTextParser with LegacyValidation for prometheus/common v0.70.1 * fix(ci): update golangci-lint args in CI workflow * refactor(cmd): replace global initializers with lazy PersistentPreRunE (#3994) * fix(test): use 4095 for FUSE max name length (#4810) On newer Linux kernels, FUSE_NAME_MAX is set to PATH_MAX - 1 (4095). Setting fuseMaxNameLen to 4095 allows us to test illegal filename lengths with a value that consistently triggers a kernel-level ENAMETOOLONG error across different kernel versions. Use a separate gcsMaxNameLen (1024) for the longest legal name test, matching the GCS limit. TAG=agy CONV=cb2ad2c9-cd41-4085-af5c-0f82aa999dca * fix(test): exclude unicode.Cn category in interestingNames and interestingLegalNames (#4456) * test(cache): remove unaligned writer offset test case in CopyUsingMemoryAlignedBuffer * fix(test): allow EPERM or ENOSYS in DirectoryTest.CreateHardLink for newer kernels (#4354) * revert: fix(test): use 4095 for FUSE max name length (#4810) * Revert "revert: fix(test): use 4095 for FUSE max name length (#4810)" This reverts commit 2b19ee5. --------- Co-authored-by: Geert Jansen
1 parent 593947e commit d6d3665

20 files changed

Lines changed: 291 additions & 272 deletions

File tree

‎.github/workflows/ci.yml‎

Lines changed: 10 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ jobs:
1717
- name: Set up Go
1818
uses: actions/setup-go@v5
1919
with:
20-
go-version: "1.24"
20+
go-version: "1.26.7"
2121
- name: CodeGen
2222
run: go generate ./...
2323
- name: Formatting diff
@@ -26,14 +26,14 @@ jobs:
2626
linux-tests:
2727
strategy:
2828
matrix:
29-
go: [ 1.24.x ]
29+
go: [ 1.26.x ]
3030
runs-on: ubuntu-latest
3131
timeout-minutes: 15
3232

3333
steps:
34-
- uses: actions/checkout@v2
34+
- uses: actions/checkout@v4
3535
- name: Set up Go ${{ matrix.go }}
36-
uses: actions/setup-go@v2.1.4
36+
uses: actions/setup-go@v5
3737
with:
3838
go-version: ${{ matrix.go }}
3939
- name: Install fuse
@@ -59,15 +59,14 @@ jobs:
5959
name: Lint
6060
runs-on: ubuntu-latest
6161
steps:
62-
- name: Setup Go
63-
uses: actions/setup-go@v4
64-
with:
65-
go-version: "1.24"
6662
- name: checkout code
6763
uses: actions/checkout@v4
64+
- name: Setup Go
65+
uses: actions/setup-go@v5
66+
with:
67+
go-version: "1.26.7"
6868
- name: golangci-lint
69-
uses: golangci/golangci-lint-action@032fa5c5e48499f06cf9d32c02149bfac1284239
69+
uses: golangci/golangci-lint-action@v8
7070
with:
71-
args: -E=goimports --timeout 2m0s
71+
args: -E=unused --timeout 3m0s
7272
only-new-issues: true
73-

‎.github/workflows/flake-detector.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -16,9 +16,9 @@ jobs:
1616
fetch-depth: 0
1717

1818
- name: Set up Go
19-
uses: actions/setup-go@v4
19+
uses: actions/setup-go@v5
2020
with:
21-
go-version: 1.24.x
21+
go-version: 1.26.x
2222
cache: false
2323
- name: Install fuse
2424
run: sudo apt-get update && sudo apt-get install -y fuse3 libfuse-dev

‎.go-version‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
1.26.7

‎Dockerfile‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@
1717
# Mount the gcsfuse to /mnt/gcs:
1818
# > docker run --privileged --device /fuse -v /mnt/gcs:/gcs:rw,rshared gcsfuse
1919

20-
FROM golang:1.24.11-alpine AS builder
20+
FROM golang:1.26.7-alpine AS builder
2121

2222
RUN apk add git
2323

‎cmd/root.go‎

Lines changed: 30 additions & 36 deletions
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,6 @@ func newRootCmd(m mountFn) (*cobra.Command, error) {
3636
var (
3737
configObj cfg.Config
3838
cfgFile string
39-
cfgErr error
4039
v = viper.New()
4140
)
4241
rootCmd := &cobra.Command{
@@ -48,49 +47,44 @@ of Cloud Storage FUSE, see https://cloud.google.com/storage/docs/gcs-fuse.`,
4847
Version: common.GetVersion(),
4948
Args: cobra.RangeArgs(2, 3),
5049
SilenceUsage: true,
51-
RunE: func(cmd *cobra.Command, args []string) error {
52-
if cfgErr != nil {
53-
return fmt.Errorf("error while parsing config: %w", cfgErr)
50+
PersistentPreRunE: func(cmd *cobra.Command, args []string) error {
51+
if cfgFile != "" {
52+
resolvedCfgFile, err := util.GetResolvedPath(cfgFile)
53+
if err != nil {
54+
return fmt.Errorf("error while resolving config-file path[%s]: %w", cfgFile, err)
55+
}
56+
v.SetConfigFile(resolvedCfgFile)
57+
v.SetConfigType("yaml")
58+
if err := v.ReadInConfig(); err != nil {
59+
return fmt.Errorf("error while reading the config: %w", err)
60+
}
61+
}
62+
63+
if err := v.Unmarshal(&configObj, viper.DecodeHook(cfg.DecodeHook()), func(decoderConfig *mapstructure.DecoderConfig) {
64+
// By default, viper supports mapstructure tags for unmarshalling. Override that to support yaml tag.
65+
decoderConfig.TagName = "yaml"
66+
// Reject the config file if any of the fields in the YAML don't map to the struct.
67+
decoderConfig.ErrorUnused = true
68+
},
69+
); err != nil {
70+
return fmt.Errorf("error while unmarshalling config: %w", err)
71+
}
72+
if err := cfg.ValidateConfig(v, &configObj); err != nil {
73+
return fmt.Errorf("invalid config: %w", err)
74+
}
75+
if err := cfg.Rationalize(v, &configObj); err != nil {
76+
return fmt.Errorf("error rationalizing config: %w", err)
5477
}
78+
return nil
79+
},
80+
RunE: func(cmd *cobra.Command, args []string) error {
5581
bucket, mountPoint, err := populateArgs(args[1:])
5682
if err != nil {
5783
return fmt.Errorf("error occurred while extracting the bucket and mountPoint: %w", err)
5884
}
5985
return m(&configObj, bucket, mountPoint)
6086
},
6187
}
62-
initConfig := func() {
63-
if cfgFile != "" {
64-
cfgFile, err := util.GetResolvedPath(cfgFile)
65-
if err != nil {
66-
cfgErr = fmt.Errorf("error while resolving config-file path[%s]: %w", cfgFile, err)
67-
return
68-
}
69-
v.SetConfigFile(cfgFile)
70-
v.SetConfigType("yaml")
71-
if err := v.ReadInConfig(); err != nil {
72-
cfgErr = fmt.Errorf("error while reading the config: %w", err)
73-
return
74-
}
75-
}
76-
77-
if cfgErr = v.Unmarshal(&configObj, viper.DecodeHook(cfg.DecodeHook()), func(decoderConfig *mapstructure.DecoderConfig) {
78-
// By default, viper supports mapstructure tags for unmarshalling. Override that to support yaml tag.
79-
decoderConfig.TagName = "yaml"
80-
// Reject the config file if any of the fields in the YAML don't map to the struct.
81-
decoderConfig.ErrorUnused = true
82-
},
83-
); cfgErr != nil {
84-
return
85-
}
86-
if cfgErr = cfg.ValidateConfig(v, &configObj); cfgErr != nil {
87-
return
88-
}
89-
if cfgErr = cfg.Rationalize(v, &configObj); cfgErr != nil {
90-
return
91-
}
92-
}
93-
cobra.OnInitialize(initConfig)
9488
rootCmd.PersistentFlags().StringVar(&cfgFile, cfg.ConfigFileFlagName, "", "The path to the config file where all gcsfuse related config needs to be specified. "+
9589
"Refer to 'https://cloud.google.com/storage/docs/gcsfuse-cli#config-file' for possible configurations.")
9690

‎go.mod‎

Lines changed: 64 additions & 61 deletions
Original file line numberDiff line numberDiff line change
@@ -1,20 +1,20 @@
11
module github.com/googlecloudplatform/gcsfuse/v2
22

3-
go 1.24.11
3+
go 1.26.7
44

55
require (
6-
cloud.google.com/go/compute/metadata v0.6.0
7-
cloud.google.com/go/iam v1.4.1
8-
cloud.google.com/go/secretmanager v1.14.5
9-
cloud.google.com/go/storage v1.50.0
6+
cloud.google.com/go/compute/metadata v0.9.0
7+
cloud.google.com/go/iam v1.5.3
8+
cloud.google.com/go/secretmanager v1.16.0
9+
cloud.google.com/go/storage v1.56.0
1010
contrib.go.opencensus.io/exporter/ocagent v0.7.0
1111
contrib.go.opencensus.io/exporter/prometheus v0.4.2
1212
contrib.go.opencensus.io/exporter/stackdriver v0.13.14
13-
github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.51.0
13+
github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.53.0
1414
github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/trace v1.27.0
1515
github.com/fsouza/fake-gcs-server v1.52.2
1616
github.com/google/uuid v1.6.0
17-
github.com/googleapis/gax-go/v2 v2.14.1
17+
github.com/googleapis/gax-go/v2 v2.23.0
1818
github.com/jacobsa/daemonize v0.0.0-20240917082746-f35568b6c3ec
1919
github.com/jacobsa/fuse v0.0.0-20250228153609-219b4762b40e
2020
github.com/jacobsa/oglematchers v0.0.0-20150720000706-141901ea67cd
@@ -25,95 +25,98 @@ require (
2525
github.com/jacobsa/timeutil v0.0.0-20170205232429-577e5acbbcf6
2626
github.com/kardianos/osext v0.0.0-20190222173326-2bc1f35cddc0
2727
github.com/mitchellh/mapstructure v1.5.0
28-
github.com/prometheus/client_golang v1.21.1
29-
github.com/prometheus/client_model v0.6.1
30-
github.com/prometheus/common v0.62.0
28+
github.com/prometheus/client_golang v1.24.1
29+
github.com/prometheus/client_model v0.6.2
30+
github.com/prometheus/common v0.70.1
3131
github.com/spf13/cobra v1.9.1
32-
github.com/spf13/pflag v1.0.6
32+
github.com/spf13/pflag v1.0.10
3333
github.com/spf13/viper v1.19.0
34-
github.com/stretchr/testify v1.10.0
34+
github.com/stretchr/testify v1.11.1
3535
go.opencensus.io v0.24.0
36-
go.opentelemetry.io/contrib/detectors/gcp v1.35.0
37-
go.opentelemetry.io/otel v1.35.0
38-
go.opentelemetry.io/otel/exporters/prometheus v0.57.0
39-
go.opentelemetry.io/otel/exporters/stdout/stdouttrace v1.35.0
40-
go.opentelemetry.io/otel/metric v1.35.0
41-
go.opentelemetry.io/otel/sdk v1.35.0
42-
go.opentelemetry.io/otel/sdk/metric v1.35.0
43-
go.opentelemetry.io/otel/trace v1.35.0
44-
golang.org/x/net v0.47.0
45-
golang.org/x/oauth2 v0.28.0
46-
golang.org/x/sync v0.18.0
47-
golang.org/x/sys v0.38.0
48-
golang.org/x/text v0.31.0
49-
golang.org/x/time v0.11.0
50-
google.golang.org/api v0.224.0
51-
google.golang.org/grpc v1.71.0
52-
google.golang.org/protobuf v1.36.5
36+
go.opentelemetry.io/contrib/detectors/gcp v1.45.0
37+
go.opentelemetry.io/otel v1.45.0
38+
go.opentelemetry.io/otel/exporters/prometheus v0.67.0
39+
go.opentelemetry.io/otel/exporters/stdout/stdouttrace v1.45.0
40+
go.opentelemetry.io/otel/metric v1.45.0
41+
go.opentelemetry.io/otel/sdk v1.45.0
42+
go.opentelemetry.io/otel/sdk/metric v1.45.0
43+
go.opentelemetry.io/otel/trace v1.45.0
44+
golang.org/x/net v0.58.0
45+
golang.org/x/oauth2 v0.36.0
46+
golang.org/x/sync v0.22.0
47+
golang.org/x/sys v0.47.0
48+
golang.org/x/text v0.41.0
49+
golang.org/x/time v0.15.0
50+
google.golang.org/api v0.290.0
51+
google.golang.org/grpc v1.83.1
52+
google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af
5353
gopkg.in/natefinch/lumberjack.v2 v2.2.1
5454
gopkg.in/yaml.v3 v3.0.1
5555
)
5656

5757
require (
58-
cel.dev/expr v0.22.0 // indirect
59-
cloud.google.com/go v0.118.3 // indirect
60-
cloud.google.com/go/auth v0.15.0 // indirect
61-
cloud.google.com/go/auth/oauth2adapt v0.2.7 // indirect
62-
cloud.google.com/go/longrunning v0.6.5 // indirect
63-
cloud.google.com/go/monitoring v1.24.0 // indirect
64-
cloud.google.com/go/pubsub v1.47.0 // indirect
65-
cloud.google.com/go/trace v1.11.4 // indirect
66-
github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.27.0 // indirect
67-
github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.51.0 // indirect
68-
github.com/aws/aws-sdk-go v1.55.6 // indirect
58+
cel.dev/expr v0.25.2 // indirect
59+
cloud.google.com/go v0.123.0 // indirect
60+
cloud.google.com/go/auth v0.20.0 // indirect
61+
cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect
62+
cloud.google.com/go/longrunning v0.8.0 // indirect
63+
cloud.google.com/go/monitoring v1.24.3 // indirect
64+
cloud.google.com/go/pubsub v1.50.1 // indirect
65+
cloud.google.com/go/pubsub/v2 v2.0.0 // indirect
66+
cloud.google.com/go/trace v1.11.7 // indirect
67+
github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.35.0 // indirect
68+
github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.53.0 // indirect
69+
github.com/aws/aws-sdk-go v1.55.8 // indirect
6970
github.com/beorn7/perks v1.0.1 // indirect
7071
github.com/census-instrumentation/opencensus-proto v0.4.1 // indirect
7172
github.com/cespare/xxhash/v2 v2.3.0 // indirect
72-
github.com/cncf/xds/go v0.0.0-20250121191232-2f005788dc42 // indirect
73+
github.com/cncf/xds/go v0.0.0-20260202195803-dba9d589def2 // indirect
7374
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
74-
github.com/envoyproxy/go-control-plane/envoy v1.32.4 // indirect
75-
github.com/envoyproxy/protoc-gen-validate v1.2.1 // indirect
76-
github.com/felixge/httpsnoop v1.0.4 // indirect
77-
github.com/fsnotify/fsnotify v1.8.0 // indirect
78-
github.com/go-logr/logr v1.4.2 // indirect
75+
github.com/envoyproxy/go-control-plane/envoy v1.37.0 // indirect
76+
github.com/envoyproxy/protoc-gen-validate v1.3.3 // indirect
77+
github.com/felixge/httpsnoop v1.1.0 // indirect
78+
github.com/fsnotify/fsnotify v1.10.1 // indirect
79+
github.com/go-jose/go-jose/v4 v4.1.4 // indirect
80+
github.com/go-logr/logr v1.4.4 // indirect
7981
github.com/go-logr/stdr v1.2.2 // indirect
8082
github.com/golang/groupcache v0.0.0-20241129210726-2c02b8208cf8 // indirect
8183
github.com/golang/protobuf v1.5.4 // indirect
8284
github.com/google/renameio/v2 v2.0.0 // indirect
8385
github.com/google/s2a-go v0.1.9 // indirect
84-
github.com/googleapis/enterprise-certificate-proxy v0.3.5 // indirect
86+
github.com/googleapis/enterprise-certificate-proxy v0.3.18 // indirect
8587
github.com/gorilla/handlers v1.5.2 // indirect
8688
github.com/gorilla/mux v1.8.1 // indirect
87-
github.com/grpc-ecosystem/grpc-gateway/v2 v2.26.3 // indirect
89+
github.com/grpc-ecosystem/grpc-gateway/v2 v2.29.0 // indirect
8890
github.com/hashicorp/hcl v1.0.0 // indirect
8991
github.com/inconshreveable/mousetrap v1.1.0 // indirect
9092
github.com/jmespath/go-jmespath v0.4.0 // indirect
91-
github.com/klauspost/compress v1.18.0 // indirect
9293
github.com/magiconair/properties v1.8.9 // indirect
9394
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
9495
github.com/pelletier/go-toml/v2 v2.2.3 // indirect
9596
github.com/pkg/xattr v0.4.10 // indirect
9697
github.com/planetscale/vtprotobuf v0.6.1-0.20240319094008-0393e58bdf10 // indirect
9798
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
98-
github.com/prometheus/procfs v0.15.1 // indirect
99-
github.com/prometheus/prometheus v0.302.1 // indirect
99+
github.com/prometheus/otlptranslator v1.0.0 // indirect
100+
github.com/prometheus/procfs v0.21.1 // indirect
101+
github.com/prometheus/prometheus v0.314.0 // indirect
100102
github.com/prometheus/statsd_exporter v0.28.0 // indirect
101103
github.com/sagikazarmark/locafero v0.7.0 // indirect
102104
github.com/sagikazarmark/slog-shim v0.1.0 // indirect
103105
github.com/sourcegraph/conc v0.3.0 // indirect
104-
github.com/spf13/afero v1.12.0 // indirect
106+
github.com/spf13/afero v1.15.0 // indirect
105107
github.com/spf13/cast v1.7.1 // indirect
108+
github.com/spiffe/go-spiffe/v2 v2.7.0 // indirect
106109
github.com/stretchr/objx v0.5.2 // indirect
107110
github.com/subosito/gotenv v1.6.0 // indirect
108-
go.opentelemetry.io/auto/sdk v1.1.0 // indirect
109-
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.60.0 // indirect
110-
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.60.0 // indirect
111+
go.opentelemetry.io/auto/sdk v1.2.1 // indirect
112+
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.67.0 // indirect
113+
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.69.0 // indirect
111114
go.uber.org/multierr v1.11.0 // indirect
112-
golang.org/x/crypto v0.45.0 // indirect
113-
golang.org/x/exp v0.0.0-20250305212735-054e65f0b394 // indirect
114-
google.golang.org/genproto v0.0.0-20250303144028-a0af3efb3deb // indirect
115-
google.golang.org/genproto/googleapis/api v0.0.0-20250303144028-a0af3efb3deb // indirect
116-
google.golang.org/genproto/googleapis/rpc v0.0.0-20250303144028-a0af3efb3deb // indirect
117-
gopkg.in/ini.v1 v1.67.0 // indirect
115+
golang.org/x/crypto v0.55.0 // indirect
116+
golang.org/x/exp v0.0.0-20260709172345-9ea1abe57597 // indirect
117+
google.golang.org/genproto v0.0.0-20260319201613-d00831a3d3e7 // indirect
118+
google.golang.org/genproto/googleapis/api v0.0.0-20260724162435-b2f20204f0df // indirect
119+
google.golang.org/genproto/googleapis/rpc v0.0.0-20260720155508-bb71a54f79dc // indirect
120+
gopkg.in/ini.v1 v1.67.2 // indirect
118121
gopkg.in/yaml.v2 v2.4.0 // indirect
119122
)

0 commit comments

Comments
 (0)