Skip to content

lightwalletd: pull master for three dependency CVE fixes - #78

Merged
aphelionz merged 3 commits into
mainfrom
subtree-update/lightwalletd-2026-09-15
Sep 15, 2026
Merged

aphelionz merged 3 commits into
mainfrom
subtree-update/lightwalletd-2026-09-15

Conversation

@aphelionz

Copy link
Copy Markdown
Member

Pulls lightwalletd/ from v0.5.4 (09593edbee) to up-lightwalletd/master at aa9acac2f9, nine commits.

Motivated by the 2026-09-15 upstream watch, where this was the clearest action on the board for the second week running.

Why now

Upstream cut v0.5.4 and then shipped three dependency CVE fixes after the tag, and has not cut another. Staying pinned means sitting on known CVEs in a network-facing Go service.

Also included: 1cb42c5166 grpc 1.82.1 to 1.83.1, 0e398d79cf staged Docker build shipping on debian:13-slim, and a CI mirror-step fix.

Conflicts

None. Our only diverged file in this subtree (README.md) is not in the incoming set. Four files changed: go.mod, go.sum, Dockerfile, and a workflow.

The tag pin

This deliberately un-pins from v0.5.4 until upstream cuts v0.5.5. That is recorded in SUBTREES.md with the reason, so the next watch run reads it as a decision rather than drift. The alternative, carrying the three dependency commits as [upstream-pending] to keep the tag pin exact, buys nothing here: there is no divergence to protect and the whole range is dependency and packaging work.

Testing

go test -count=1 ./... green across all seven packages with test files.

Note

This branch and #(zaino) both add an ## Unreleased CHANGELOG section, so whichever merges second will conflict there trivially.

🤖 Generated with Claude Code

Mark Henderson and others added 3 commits September 15, 2026 08:46
aa9acac2f9 Merge pull request #599 from zcash/fix/crane-mirror-creds
d79cd11005 Merge pull request #601 from zcash/dependabot/go_modules/google.golang.org/grpc-1.83.1
1cb42c5166 build(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.1
51aba684c2 Merge pull request #600 from zecrocks/be/cve-dep-bumps
0e398d79cf docker: build in a stage, ship on debian:13-slim
5044f4b924 deps: bump golang.org/x/crypto for CVE-2026-56854
96fe9a145e deps: bump golang.org/x/net for CVE-2026-46600
a3cb34c5e6 deps: bump golang.org/x/text for CVE-2026-56852
77df3be44e CI: fix the zodlinc mirror step, which has never succeeded

git-subtree-dir: lightwalletd
git-subtree-split: aa9acac2f95e596f0edf9a3750ec7751d943e614
Upstream cut v0.5.4 before shipping fixes for CVE-2026-56854 (x/crypto),
CVE-2026-46600 (x/net) and CVE-2026-56852 (x/text), and has not cut another
tag. Take master at aa9acac2f9 and note the un-pin so the next watch run does
not read it as drift.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The Docker runtime still runs as root; configure it to use the restricted lightwalletd user.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Updates vendored lightwalletd with post-v0.5.4 CVE fixes, dependency upgrades, and packaging/CI changes.

Changes:

  • Upgrades vulnerable Go dependencies and gRPC.
  • Adds a staged Debian runtime image.
  • Updates subtree metadata, changelog, and image mirroring.
File summaries
File Summary
SUBTREES.md Documents the temporary unpinned revision.
lightwalletd/go.sum Refreshes dependency checksums.
lightwalletd/go.mod Updates Go dependencies.
lightwalletd/Dockerfile Adds a staged Debian runtime image.
lightwalletd/.github/workflows/CI.yaml Updates authenticated image mirroring.
CHANGELOG.md Records security and packaging updates.
Review details
  • Files reviewed: 5/6 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread lightwalletd/Dockerfile
"$LWD_USER"
"$LWD_USER" \
&& mkdir -p /var/lib/lightwalletd/db \
&& chown "$LWD_UID:$LWD_UID" /var/lib/lightwalletd/db

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Correct about the vendored file, but it is not something this PR introduced and not something Zero ships.

Pre-existing upstream. The v0.5.4 Dockerfile we were already pinned to has no USER either. Upstream's 0e398d79cf changed the base image and moved the chown; root-by-default is unchanged across the pull.

Zero does not build this Dockerfile. images.yml builds docker/lightwalletd/Dockerfile, which we own precisely because upstream's cannot satisfy target: runtime (single stage, lightwalletd_base) and ships the whole Go toolchain in the final layer. Ours ends with:

WORKDIR /srv/lightwalletd
USER lightwalletd

So the hardening you are asking for is already in the image that actually runs, on the same uid 2002 and datadir.

Not fixing it here on purpose. Patching a vendored file we never build would add permanent [zero] divergence for no runtime benefit, which is the thing MAINTENANCE.md exists to prevent. The gap is real upstream though (creating uid 2002, chowning the datadir to it, then never switching is setup that only makes sense with a USER line), so it belongs in a PR to zcash/lightwalletd, not in this CVE pull.

@aphelionz
aphelionz merged commit f3a79f5 into main Sep 15, 2026
25 checks passed
@aphelionz
aphelionz deleted the subtree-update/lightwalletd-2026-09-15 branch September 15, 2026 13:47
aphelionz pushed a commit that referenced this pull request Sep 15, 2026
Resolves the expected CHANGELOG conflict: #78 (lightwalletd CVEs) and this
branch each opened an `## Unreleased` section. Both sets of entries are kept,
folded into one section under Security / Changed / Removed. No content dropped
from either side.

SUBTREES.md auto-merged; the lightwalletd un-pin note and the zaino 0.10.0 pin
note are both present.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants