test
7055f2c added
.gitignore +0 -0 | new file mode 100644 |
| new file mode 100644 |
added
go.mod +3 -0 | new file mode 100644 | ||
| @@ -0,0 +1,3 @@ | ||
| 1 | +module demo | |
| 2 | + | |
| 3 | +go 1.26.2 | |
| new file mode 100644 | |||
| @@ -0,0 +1,3 @@ | |||
| 1 | +module demo | ||
| 2 | + | ||
| 3 | +go 1.26.2 | ||
added
main.go +7 -0 | new file mode 100644 | ||
| @@ -0,0 +1,7 @@ | ||
| 1 | +package main | |
| 2 | + | |
| 3 | +import "rickub.com/bots-garden/hello" | |
| 4 | + | |
| 5 | +func main() { | |
| 6 | + hello.Greet("Bob") | |
| 7 | +} | |
| new file mode 100644 | |||
| @@ -0,0 +1,7 @@ | |||
| 1 | +package main | ||
| 2 | + | ||
| 3 | +import "rickub.com/bots-garden/hello" | ||
| 4 | + | ||
| 5 | +func main() { | ||
| 6 | + hello.Greet("Bob") | ||
| 7 | +} | ||
added
tmp/ISSUE.md +136 -0 | new file mode 100644 | ||
| @@ -0,0 +1,136 @@ | ||
| 1 | +# Go modules hosted on rickub.com cannot be resolved by the Go toolchain | |
| 2 | + | |
| 3 | +## Summary | |
| 4 | + | |
| 5 | +A Go library hosted on Rickub cannot be used as a dependency. `go get` and `go mod tidy` both fail before any network fetch of the code happens, because Rickub does not implement the two HTTP endpoints the Go toolchain relies on to locate a repository from an import path. | |
| 6 | + | |
| 7 | +This is not a packaging mistake on our side and it is not specific to one repository: it affects every Go module that would live on rickub.com. | |
| 8 | + | |
| 9 | +## Steps to reproduce | |
| 10 | + | |
| 11 | +`bots-garden/call-hello` is a minimal consumer of `bots-garden/hello`, a Go library hosted on Rickub. | |
| 12 | + | |
| 13 | +`go.mod`: | |
| 14 | + | |
| 15 | +``` | |
| 16 | +module demo | |
| 17 | + | |
| 18 | +go 1.26.2 | |
| 19 | +``` | |
| 20 | + | |
| 21 | +`main.go`: | |
| 22 | + | |
| 23 | +```go | |
| 24 | +package main | |
| 25 | + | |
| 26 | +import "rickub.com/bots-garden/hello" | |
| 27 | + | |
| 28 | +func main() { | |
| 29 | + hello.Greet("Bob") | |
| 30 | +} | |
| 31 | +``` | |
| 32 | + | |
| 33 | +Then: | |
| 34 | + | |
| 35 | +```console | |
| 36 | +$ go mod tidy | |
| 37 | +go: finding module for package rickub.com/bots-garden/hello | |
| 38 | +go: demo imports | |
| 39 | + rickub.com/bots-garden/hello: cannot find module providing package rickub.com/bots-garden/hello: unrecognized import path "rickub.com/bots-garden/hello": parse https://rickub.com/bots-garden/hello?go-get=1: no go-import meta tags () | |
| 40 | +``` | |
| 41 | + | |
| 42 | +Bypassing the public module proxy changes nothing: | |
| 43 | + | |
| 44 | +```console | |
| 45 | +$ GOPRIVATE=rickub.com go get rickub.com/bots-garden/hello | |
| 46 | +go: unrecognized import path "rickub.com/bots-garden/hello": parse https://rickub.com/bots-garden/hello?go-get=1: no go-import meta tags () | |
| 47 | +``` | |
| 48 | + | |
| 49 | +It is not caused by the repository being new or empty. The same error comes back for `turbo-editors/turbo-core`, which has content: | |
| 50 | + | |
| 51 | +```console | |
| 52 | +$ GOPRIVATE=rickub.com go get rickub.com/turbo-editors/turbo-core@main | |
| 53 | +go: rickub.com/turbo-editors/turbo-core@main: unrecognized import path "rickub.com/turbo-editors/turbo-core": parse https://rickub.com/turbo-editors/turbo-core?go-get=1: no go-import meta tags () | |
| 54 | +``` | |
| 55 | + | |
| 56 | +## What is missing | |
| 57 | + | |
| 58 | +Two endpoints, and both are required. The first tells Go *where* the repository is; the second lets it actually be cloned. | |
| 59 | + | |
| 60 | +| Request | Rickub today | Needed | | |
| 61 | +|---|---|---| | |
| 62 | +| `GET /bots-garden/hello?go-get=1` | `200`, HTML with **no** `go-import` meta tag | `200` with the meta tag below | | |
| 63 | +| `GET /bots-garden/hello.git/info/refs?service=git-upload-pack` | `404` | `200` (git smart HTTP) | | |
| 64 | + | |
| 65 | +Measured on both `bots-garden/hello` and `turbo-editors/turbo-core`; identical in both cases. The repository pages themselves return `200` — only the meta tag is absent. | |
| 66 | + | |
| 67 | +### 1. The `go-import` meta tag | |
| 68 | + | |
| 69 | +When the Go toolchain meets an import path whose host it does not have a built-in rule for, it does a `GET` on the path with `?go-get=1` and looks for a single meta tag in the HTML head. For this repository it should be: | |
| 70 | + | |
| 71 | +```html | |
| 72 | +<meta name="go-import" content="rickub.com/bots-garden/hello git https://rickub.com/bots-garden/hello.git"> | |
| 73 | +``` | |
| 74 | + | |
| 75 | +The three space-separated fields are: the module path prefix, the VCS, and the clone URL. | |
| 76 | + | |
| 77 | +Optionally, a second tag makes source links work on pkg.go.dev: | |
| 78 | + | |
| 79 | +```html | |
| 80 | +<meta name="go-source" content="rickub.com/bots-garden/hello _ https://rickub.com/bots-garden/hello/src/branch/main{/dir} https://rickub.com/bots-garden/hello/src/branch/main{/dir}/{file}#L{line}"> | |
| 81 | +``` | |
| 82 | + | |
| 83 | +This is what other forges already emit. Codeberg, for the same project: | |
| 84 | + | |
| 85 | +```html | |
| 86 | +<meta name="go-import" content="codeberg.org/turbo-editors/turbo-core git https://codeberg.org/turbo-editors/turbo-core.git"> | |
| 87 | +``` | |
| 88 | + | |
| 89 | +Serving the tag on sub-paths too is worth doing, though not strictly required. Importing `rickub.com/bots-garden/hello/subpkg` makes Go request that full path first; if it gets no usable tag it retries with successively shorter prefixes until it reaches the repository root. Answering at every depth — with the repository root as the prefix in all of them — saves those extra round trips, and is what Codeberg does, including for paths that do not exist in the tree. | |
| 90 | + | |
| 91 | +### 2. Git over HTTPS | |
| 92 | + | |
| 93 | +Rickub currently serves git over SSH only. That is not enough, for a reason that is easy to miss: with the default `GOPROXY=https://proxy.golang.org,direct`, **the machine that clones the repository is not the developer's** — it is `proxy.golang.org`, which fetches anonymously over the public internet. It has no SSH key and no account. | |
| 94 | + | |
| 95 | +So public Go modules on Rickub need the repository to be cloneable over HTTPS without authentication. Private modules can stay SSH-only, but then every consumer has to opt out of the proxy and rewrite the URL: | |
| 96 | + | |
| 97 | +```bash | |
| 98 | +go env -w GOPRIVATE=rickub.com | |
| 99 | +git config --global url."ssh://git@rickub.com/".insteadOf "https://rickub.com/" | |
| 100 | +``` | |
| 101 | + | |
| 102 | +Even then the `go-import` meta tag is still required — that is the discovery step, and it happens over HTTPS before git is ever invoked. | |
| 103 | + | |
| 104 | +## Alternatives that do not work | |
| 105 | + | |
| 106 | +**Putting `.git` in the module path.** Go can infer a repository root from a VCS qualifier, so `rickub.com/bots-garden/hello.git` skips the meta tag requirement. It does not help here, because Go still has to clone, and it only probes schemes it considers secure — `https`, then `ssh`. Anything else is refused outright: | |
| 107 | + | |
| 108 | +``` | |
| 109 | +no secure protocol found for repository | |
| 110 | +``` | |
| 111 | + | |
| 112 | +So this route still needs endpoint 2. | |
| 113 | + | |
| 114 | +**A vanity domain.** A static page elsewhere serving the `go-import` tag and pointing at Rickub would solve discovery, but it points the clone URL back at Rickub — which again needs endpoint 2. It also gives up `rickub.com` as the module path. | |
| 115 | + | |
| 116 | +## Impact | |
| 117 | + | |
| 118 | +Any Go library on Rickub is unusable as a dependency. The current workaround is a local checkout wired in with a workspace, which is fine for one developer and not a distribution mechanism: | |
| 119 | + | |
| 120 | +```bash | |
| 121 | +go work init . ../hello | |
| 122 | +``` | |
| 123 | + | |
| 124 | +The practical consequence today is that `turbo-editors/turbo-core` keeps `codeberg.org/...` as its module path and depends on Codeberg staying reachable, even though development has moved to Rickub. | |
| 125 | + | |
| 126 | +## Environment | |
| 127 | + | |
| 128 | +- `go version go1.26.2 linux/arm64` | |
| 129 | +- `GOPROXY=https://proxy.golang.org,direct` | |
| 130 | +- `GOSUMDB=sum.golang.org` | |
| 131 | +- Repositories: `bots-garden/call-hello` (consumer), `bots-garden/hello` (library), `turbo-editors/turbo-core` (second case, non-empty) | |
| 132 | + | |
| 133 | +## References | |
| 134 | + | |
| 135 | +- `go help importpath` — remote import path syntax and the meta tag format | |
| 136 | +- [Go Modules Reference — Finding a repository for a module path](https://go.dev/ref/mod#vcs-find) | |
| new file mode 100644 | |||
| @@ -0,0 +1,136 @@ | |||
| 1 | +# Go modules hosted on rickub.com cannot be resolved by the Go toolchain | ||
| 2 | + | ||
| 3 | +## Summary | ||
| 4 | + | ||
| 5 | +A Go library hosted on Rickub cannot be used as a dependency. `go get` and `go mod tidy` both fail before any network fetch of the code happens, because Rickub does not implement the two HTTP endpoints the Go toolchain relies on to locate a repository from an import path. | ||
| 6 | + | ||
| 7 | +This is not a packaging mistake on our side and it is not specific to one repository: it affects every Go module that would live on rickub.com. | ||
| 8 | + | ||
| 9 | +## Steps to reproduce | ||
| 10 | + | ||
| 11 | +`bots-garden/call-hello` is a minimal consumer of `bots-garden/hello`, a Go library hosted on Rickub. | ||
| 12 | + | ||
| 13 | +`go.mod`: | ||
| 14 | + | ||
| 15 | +``` | ||
| 16 | +module demo | ||
| 17 | + | ||
| 18 | +go 1.26.2 | ||
| 19 | +``` | ||
| 20 | + | ||
| 21 | +`main.go`: | ||
| 22 | + | ||
| 23 | +```go | ||
| 24 | +package main | ||
| 25 | + | ||
| 26 | +import "rickub.com/bots-garden/hello" | ||
| 27 | + | ||
| 28 | +func main() { | ||
| 29 | + hello.Greet("Bob") | ||
| 30 | +} | ||
| 31 | +``` | ||
| 32 | + | ||
| 33 | +Then: | ||
| 34 | + | ||
| 35 | +```console | ||
| 36 | +$ go mod tidy | ||
| 37 | +go: finding module for package rickub.com/bots-garden/hello | ||
| 38 | +go: demo imports | ||
| 39 | + rickub.com/bots-garden/hello: cannot find module providing package rickub.com/bots-garden/hello: unrecognized import path "rickub.com/bots-garden/hello": parse https://rickub.com/bots-garden/hello?go-get=1: no go-import meta tags () | ||
| 40 | +``` | ||
| 41 | + | ||
| 42 | +Bypassing the public module proxy changes nothing: | ||
| 43 | + | ||
| 44 | +```console | ||
| 45 | +$ GOPRIVATE=rickub.com go get rickub.com/bots-garden/hello | ||
| 46 | +go: unrecognized import path "rickub.com/bots-garden/hello": parse https://rickub.com/bots-garden/hello?go-get=1: no go-import meta tags () | ||
| 47 | +``` | ||
| 48 | + | ||
| 49 | +It is not caused by the repository being new or empty. The same error comes back for `turbo-editors/turbo-core`, which has content: | ||
| 50 | + | ||
| 51 | +```console | ||
| 52 | +$ GOPRIVATE=rickub.com go get rickub.com/turbo-editors/turbo-core@main | ||
| 53 | +go: rickub.com/turbo-editors/turbo-core@main: unrecognized import path "rickub.com/turbo-editors/turbo-core": parse https://rickub.com/turbo-editors/turbo-core?go-get=1: no go-import meta tags () | ||
| 54 | +``` | ||
| 55 | + | ||
| 56 | +## What is missing | ||
| 57 | + | ||
| 58 | +Two endpoints, and both are required. The first tells Go *where* the repository is; the second lets it actually be cloned. | ||
| 59 | + | ||
| 60 | +| Request | Rickub today | Needed | | ||
| 61 | +|---|---|---| | ||
| 62 | +| `GET /bots-garden/hello?go-get=1` | `200`, HTML with **no** `go-import` meta tag | `200` with the meta tag below | | ||
| 63 | +| `GET /bots-garden/hello.git/info/refs?service=git-upload-pack` | `404` | `200` (git smart HTTP) | | ||
| 64 | + | ||
| 65 | +Measured on both `bots-garden/hello` and `turbo-editors/turbo-core`; identical in both cases. The repository pages themselves return `200` — only the meta tag is absent. | ||
| 66 | + | ||
| 67 | +### 1. The `go-import` meta tag | ||
| 68 | + | ||
| 69 | +When the Go toolchain meets an import path whose host it does not have a built-in rule for, it does a `GET` on the path with `?go-get=1` and looks for a single meta tag in the HTML head. For this repository it should be: | ||
| 70 | + | ||
| 71 | +```html | ||
| 72 | +<meta name="go-import" content="rickub.com/bots-garden/hello git https://rickub.com/bots-garden/hello.git"> | ||
| 73 | +``` | ||
| 74 | + | ||
| 75 | +The three space-separated fields are: the module path prefix, the VCS, and the clone URL. | ||
| 76 | + | ||
| 77 | +Optionally, a second tag makes source links work on pkg.go.dev: | ||
| 78 | + | ||
| 79 | +```html | ||
| 80 | +<meta name="go-source" content="rickub.com/bots-garden/hello _ https://rickub.com/bots-garden/hello/src/branch/main{/dir} https://rickub.com/bots-garden/hello/src/branch/main{/dir}/{file}#L{line}"> | ||
| 81 | +``` | ||
| 82 | + | ||
| 83 | +This is what other forges already emit. Codeberg, for the same project: | ||
| 84 | + | ||
| 85 | +```html | ||
| 86 | +<meta name="go-import" content="codeberg.org/turbo-editors/turbo-core git https://codeberg.org/turbo-editors/turbo-core.git"> | ||
| 87 | +``` | ||
| 88 | + | ||
| 89 | +Serving the tag on sub-paths too is worth doing, though not strictly required. Importing `rickub.com/bots-garden/hello/subpkg` makes Go request that full path first; if it gets no usable tag it retries with successively shorter prefixes until it reaches the repository root. Answering at every depth — with the repository root as the prefix in all of them — saves those extra round trips, and is what Codeberg does, including for paths that do not exist in the tree. | ||
| 90 | + | ||
| 91 | +### 2. Git over HTTPS | ||
| 92 | + | ||
| 93 | +Rickub currently serves git over SSH only. That is not enough, for a reason that is easy to miss: with the default `GOPROXY=https://proxy.golang.org,direct`, **the machine that clones the repository is not the developer's** — it is `proxy.golang.org`, which fetches anonymously over the public internet. It has no SSH key and no account. | ||
| 94 | + | ||
| 95 | +So public Go modules on Rickub need the repository to be cloneable over HTTPS without authentication. Private modules can stay SSH-only, but then every consumer has to opt out of the proxy and rewrite the URL: | ||
| 96 | + | ||
| 97 | +```bash | ||
| 98 | +go env -w GOPRIVATE=rickub.com | ||
| 99 | +git config --global url."ssh://git@rickub.com/".insteadOf "https://rickub.com/" | ||
| 100 | +``` | ||
| 101 | + | ||
| 102 | +Even then the `go-import` meta tag is still required — that is the discovery step, and it happens over HTTPS before git is ever invoked. | ||
| 103 | + | ||
| 104 | +## Alternatives that do not work | ||
| 105 | + | ||
| 106 | +**Putting `.git` in the module path.** Go can infer a repository root from a VCS qualifier, so `rickub.com/bots-garden/hello.git` skips the meta tag requirement. It does not help here, because Go still has to clone, and it only probes schemes it considers secure — `https`, then `ssh`. Anything else is refused outright: | ||
| 107 | + | ||
| 108 | +``` | ||
| 109 | +no secure protocol found for repository | ||
| 110 | +``` | ||
| 111 | + | ||
| 112 | +So this route still needs endpoint 2. | ||
| 113 | + | ||
| 114 | +**A vanity domain.** A static page elsewhere serving the `go-import` tag and pointing at Rickub would solve discovery, but it points the clone URL back at Rickub — which again needs endpoint 2. It also gives up `rickub.com` as the module path. | ||
| 115 | + | ||
| 116 | +## Impact | ||
| 117 | + | ||
| 118 | +Any Go library on Rickub is unusable as a dependency. The current workaround is a local checkout wired in with a workspace, which is fine for one developer and not a distribution mechanism: | ||
| 119 | + | ||
| 120 | +```bash | ||
| 121 | +go work init . ../hello | ||
| 122 | +``` | ||
| 123 | + | ||
| 124 | +The practical consequence today is that `turbo-editors/turbo-core` keeps `codeberg.org/...` as its module path and depends on Codeberg staying reachable, even though development has moved to Rickub. | ||
| 125 | + | ||
| 126 | +## Environment | ||
| 127 | + | ||
| 128 | +- `go version go1.26.2 linux/arm64` | ||
| 129 | +- `GOPROXY=https://proxy.golang.org,direct` | ||
| 130 | +- `GOSUMDB=sum.golang.org` | ||
| 131 | +- Repositories: `bots-garden/call-hello` (consumer), `bots-garden/hello` (library), `turbo-editors/turbo-core` (second case, non-empty) | ||
| 132 | + | ||
| 133 | +## References | ||
| 134 | + | ||
| 135 | +- `go help importpath` — remote import path syntax and the meta tag format | ||
| 136 | +- [Go Modules Reference — Finding a repository for a module path](https://go.dev/ref/mod#vcs-find) | ||