Package: dh-go
Version: 1.68
Severity: important

In _create_go_work_file, the loop over dependencies that are present on disk
writes a replace directive for any path that exists, and only checks for a
go.mod when the path is a symlink:

    my $filepath = $this->get_buildpath("src/$module");
    next if not -e $filepath;
    if (-l $filepath) {
        next if not -e "$filepath/go.mod";
        ...
    } else {
        print $gowork "replace $module => ./src/$module\n";
    }

A real directory with no go.mod therefore gets a replace it cannot satisfy.
This happens whenever Debian ships only the /vN form of a module: the parent
directory exists because the /vN symlink lives in it, but it holds no go.mod.
golang-github-klauspost-cpuid-dev 2.4.0-1 installs only
github.com/klauspost/cpuid/v2, and something in syft's module graph
(dsnet/compress) requires github.com/klauspost/cpuid v1.2.0, so the build
stops with 124 copies of:

    github.com/dsnet/[email protected] requires
      github.com/klauspost/[email protected] (replaced by 
./src/github.com/klauspost/cpuid):
      reading src/github.com/klauspost/cpuid/go.mod: no such file or directory

Still present in debian/sid at commit 260d81a4525e (2026-09-20).

Checking for the go.mod in the non-symlink branch too would send the module to
the "dummy modules" section a few lines below, which already writes a minimal
go.mod for exactly this case.

I am working around both of these in debian/rules for now, and would rather
not ship that.

Reply via email to