Skip to content

fix: Fix CVE-2026-56854 by bumping golang.org/x/crypto and our Go version - #660

Open
Anton-Kalpakchiev wants to merge 2 commits into
masterfrom
fix-x-crypto-cve-2026-56854
Open

Anton-Kalpakchiev wants to merge 2 commits into
masterfrom
fix-x-crypto-cve-2026-56854

Conversation

@Anton-Kalpakchiev

@Anton-Kalpakchiev Anton-Kalpakchiev commented Sep 9, 2026 •

Copy link
Copy Markdown
Collaborator

Before this commit, the Kraken repo is vulnerable to CVE-2026-56854, as shown by our security scanner. To fix it, we need to bump golang.org/x/crypto from 0.46.0 to 0.55.0, which requires Go 1.26+. Thus, in this commit I bump both.

This should be ok, as Go is renowned for its backwards compatability.

… from 1.24 to 1.27

Before this commit, the Kraken repo is vulnerable to X
[ref](https://github.com/uber/kraken/actions/runs/34343753316/job/102440351025?pr=659#step:3:357), as shown by our security scanner.
To fix it, we need to bump `golang.org/x/crypto` from 0.46.0 to 0.55.0,
which requires Go 1.26+. Thus, in this commit I bump both.
@github-actions github-actions Bot added the size/m label Sep 9, 2026
@Anton-Kalpakchiev Anton-Kalpakchiev changed the title fix: Fix CVE-2026-56854 by bumping golang.org/x/crypto and bumping Go… fix: Fix CVE-2026-56854 by bumping golang.org/x/crypto and our Go version Sep 9, 2026
@gkeesh7

gkeesh7 commented Sep 10, 2026

Copy link
Copy Markdown
Collaborator

Not blocking the CVE fix, but two runtime behavior changes ride along with it. They
come from different mechanisms, so they need different fixes.

1. GOMAXPROCS now follows the cgroup CPU limit

From the go.mod directive (1.24.0 → 1.27.1). Crossing Go 1.25 turns on
containermaxprocs=1 and updatemaxprocs=1, so the runtime sets GOMAXPROCS from
the cgroup limit and re-reads it periodically.

Kraken has no automaxprocs and sets GOMAXPROCS nowhere (grepped *.go, *.yaml,
Makefile, Dockerfile*). So an agent on a 96-core node with a 2-core limit moves
from GOMAXPROCS=96 to 2. That changes hashing throughput, torrent concurrency,
and GC worker count. Probably an improvement, but it needs a measurement of its own.

Suggestion: pin it, then remove the block after load testing.

godebug (
      containermaxprocs=0
      updatemaxprocs=0
)

2. Green Tea GC becomes the default, with no opt-out

This comes from the toolchain, not the directive. GO_VERSION: '1.27' gets Green Tea,
which became default in Go 1.26. Lowering the go.mod directive does not avoid it,
and GOEXPERIMENT=nogreenteagc was removed in 1.27.

Agent and origin hold large blob caches and big piece buffers, so expect a different
heap growth curve and RSS profile.

Suggestion: soak-test origin and agent at production memory limits, and watch RSS.

@gkeesh7

gkeesh7 commented Sep 10, 2026

Copy link
Copy Markdown
Collaborator

Also why not go only up-to go 1.26 to fix the CVE, Does anything needs 1.27 ? Kraken is a public library, for anyone importing it would set a hard floor.

@gkeesh7 gkeesh7 added security Security Related. Will never go stale or Autoclose keep-open Prevents a PR from getting marked as Stale and auto-closed due to inactivity labels Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

keep-open Prevents a PR from getting marked as Stale and auto-closed due to inactivity security Security Related. Will never go stale or Autoclose size/m

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants