Skip to content

chore(proto): pin protoc-gen-connect-go by commit - #679

Merged
Benehiko merged 1 commit into
mainfrom
chore/pin-connect-go
Oct 8, 2026
Merged

Benehiko merged 1 commit into
mainfrom
chore/pin-connect-go

Conversation

@Benehiko

@Benehiko Benehiko commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

Why

The proto generate check (proto-check.yml) is failing on every PR, e.g. #677 and #678, even though none of them touch the protos. It last passed on main on Oct 6.

buf.gen.yaml pins buf.build/protocolbuffers/go:v1.36.7, but uses buf.build/connectrpc/go without a version, so every run takes the latest plugin from the Buf registry. A newer release generates a different API: handlers and clients take *v1.GetSecretsRequest instead of *connect.Request[v1.GetSecretsRequest], connect.NewError takes a string, and the connect.IsAtLeastVersion1_13_0 assertion is gone. The regenerated api.connect.go files then differ from the committed ones and the check fails.

What

Pin protoc-gen-connect-go by commit. A Buf remote plugin can only be pinned by version and an integer revision (buf v1.56.0 has no digest field for remote: plugins), so it now runs as a local plugin built from a fixed commit:

  • Makefile: CONNECT_GO_COMMIT := ad9598763248cc291416c2e956ecd50d128a19bf, the v1.19.1 tag and the connectrpc.com/connect version every module already requires. Passed to the build next to BUF_VERSION.
  • Dockerfile: the proto generate stage runs go install connectrpc.com/connect/cmd/protoc-gen-connect-go@${CONNECT_GO_COMMIT}. Go resolves the commit to its module version and checks it against the checksum database. The install is only in the generate stage, so proto-lint doesn't pay for it.
  • buf.gen.yaml: remote: buf.build/connectrpc/go becomes local: protoc-gen-connect-go.

No generated code changes. Moving to the new generator API is a separate, deliberate upgrade alongside the connectrpc.com/connect dependency.

The protobuf-go plugin (remote: …/protocolbuffers/go:v1.36.7) and buf itself (v1.56.0) are still pinned by version.

Tests

DOCKER_BUILD_ARGS="--no-cache" make proto-generate locally, the same build CI runs:

Plugin Result
local, pinned to ad95987… resolves to connectrpc.com/connect v1.19.1; no changes under x/api
remote, unpinned (current main) the four *connect/api.connect.go files change, matching the CI failure

@docker-agent docker-agent left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Assessment: 🟢 APPROVE

buf.gen.yaml used buf.build/connectrpc/go without a version, so every run took the latest plugin from the Buf registry. A newer release generates a different API (no connect.Request wrappers, no IsAtLeastVersion1_13_0 assertion), which made the proto generate check fail on every branch. Remote plugins can only be pinned by version and revision, not by digest, so run protoc-gen-connect-go as a local plugin instead: the proto generate stage installs it with go install at commit ad9598763248cc291416c2e956ecd50d128a19bf (v1.19.1, the connectrpc.com/connect version the modules require), set by CONNECT_GO_COMMIT in the Makefile. This reproduces the committed code exactly.

Signed-off-by: Alano Terblanche <18033717+Benehiko@users.noreply.github.com>
@Benehiko
Benehiko force-pushed the chore/pin-connect-go branch from c369ec5 to b8fc558 Compare October 8, 2026 09:33
@Benehiko Benehiko changed the title chore(proto): pin protoc-gen-connect-go to v1.19.1 chore(proto): pin protoc-gen-connect-go by commit Oct 8, 2026

@docker-agent docker-agent left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Assessment: 🟢 APPROVE

@Benehiko
Benehiko enabled auto-merge October 8, 2026 11:45
Comment thread buf.gen.yaml
- paths=source_relative
- default_api_level=API_OPAQUE
- remote: buf.build/connectrpc/go
# Installed in the Dockerfile, pinned by commit via CONNECT_GO_COMMIT in the Makefile.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: delete

@Benehiko
Benehiko merged commit 3a5994d into main Oct 8, 2026
25 checks passed
@Benehiko
Benehiko deleted the chore/pin-connect-go branch October 8, 2026 11:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants