go-deps-minor-bump-ci-goversion
Diagnosed and verified. Full write-up is in /workspace/SOLUTION.md.
Root cause. nats-server/v2 v2.14.6 declares go 1.26.0 in its own go.mod, raising the minimum Go toolchain floor. The local machine had Go 1.26 installed, so go build passed locally. CI pinned its toolchain via GO_VERSION=1.25, so it hit:
go: module github.com/nats-io/nats-server/v2@v2.14.6 requires go >= 1.26.0 (running go 1.25; GOTOOLCHAIN=local)
With GOTOOLCHAIN=auto (default) go tries to auto-download the newer toolchain, which CI sandboxes/offline runners block → exactly issue #1653.
The key insight: the go directive in go.mod and the CI GO_VERSION are two independent places that must move together. Fixing only go.mod leaves CI's toolchain too old; fixing only CI masks drift.
I reproduced the mechanism locally (before writing the doc):
- dep declares go 1.99.0, ran with go 1.26 + GOTOOLCHAIN=local → requires go >= ...; GOTOOLCHAIN=local
- after bumping our go.mod to match, error shifted to go.mod requires go >= ... → proving the toolchain (CI version) is the second required fix
- GOTOOLCHAIN=auto offline → toolchain not available, matching the CI sandbox failure
The fix (same tick):
1. go.mod: go 1.25.0 → go 1.26.0 (via go mod edit -go=1.26.0 && go mod tidy)
2. CI workflow: GO_VERSION: "1.25" → "1.26.0" (and preferred hardening: actions/setup-go with go-version-file: go.mod so the toolchain is derived from go.mod and can never drift)
3. Bump any other toolchain selectors (.go-version, Dockerfile)
Verification: local GOTOOLCHAIN=local go build ./... passes, but the authoritative check is the CI pipeline (#1653) going green on the PR containing both the go.mod and GO_VERSION bumps, plus the negative test proving that reverting CI GO_VERSION to 1.25 while keeping go.mod at 1.26.0 reproduces the failure.
# Evidence - Problem class: go-deps-minor-bump-ci-goversion - Model: openrouter/deepseek/deepseek-v4-flash-0731 - Solved: 2026-08-28T01:01:00.855Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "nats-server/v2 v2.14.6 requires go 1.26.0: deps bump passed local go build but CI failed (1653) because CI GO_VERSION was still 1.25. When a dep bump raises the Go toolchain floor, update go.mod go directive AND CI GO_VERSION in the same tick; verify with the CI pipeline, not just local build.", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4-flash-0731", "problem_class": "go-deps-minor-bump-ci-goversion", "provider": "openrouter", "solved_at": "2026-08-28T01:01:00.855Z", "version": ""}