Release linux/amd64 binary is dynamically linked, contradicting the "single static binary" claim
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 3/5
- 見積もり時間
- 1〜2日
- 初心者へのやさしさ
- 68/100
- issue の種類
- バグ
- 明瞭さ
- 明確に書かれている
- 活発さ
- 活発
- 技術スタック
- github-actions, go
- 領域
- build-system, cli, release
調査の方向性
Start with the release build matrix in .github/workflows/go.yml, especially the build step around line 192, and inspect how its Linux legs compile and name their assets. Check the resulting Linux binaries with file and add a CI assertion that verifies they are statically linked. Done means Linux release assets meet the issue's stated static/stripped criteria and CI catches regressions.
索引モデルが issue の本文から書いたものです。
説明
Why it matters
The repo description, README and site all promise a "single static Go binary". The v0.8.0 subenum-linux-amd64 release asset is actually dynamically linked against glibc (file reports dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2 ... not stripped). It will not run on Alpine/musl, in scratch/distroless images, or on older glibc hosts, which are common pentest/CI environments. Oddly the cross-compiled linux-arm64 asset is static, so behaviour differs by arch.
Evidence
.github/workflows/go.yml:192— the release matrix builds with
go build -v -buildvcs=false -ldflags "-X main.Version=..."and noCGO_ENABLED=0. The linux/amd64 leg compiles natively onubuntu-latest, so cgo is on andnetlinks the cgo resolver.- No
-trimpathand no-s -w, so binaries embed local paths and debug info (larger, not reproducible). -buildvcs=falsestrips VCS info, sogo version -m subenumshows nothing useful for provenance.
Suggested approach
- Set
CGO_ENABLED: 0in the build step env for all legs. - Build with
-trimpath -ldflags "-s -w -X main.Version=..."; drop-buildvcs=falsein CI (keep it only where.gitis absent, e.g. Docker). - Add a CI assertion on Linux legs:
file subenum-linux-* | grep -q 'statically linked'. - (Covered more broadly by the GoReleaser issue, but this one-line fix should ship as a patch release now.)
Done when
- All Linux release assets report
statically linked, are stripped, and CI fails if that regresses. - A v0.8.1 patch release replaces the dynamic binary.
- 主要言語
- Go
- スター
- 1
- フォーク
- 1
- 平均マージ
- 5日 2時間
- マージ済み PR(30日)
- 3
環境構築
このプロジェクトの開発コンテナを、あなたの GitHub アカウントでブラウザ上に起動します。
- Dockerfile または Docker Compose ファイルあり
- プルリクエストのテンプレートあり
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
TMHSDigital/subenum のほかの issue
-
area: cli enhancement good first issue
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
TMHSDigital/subenum#136 ·
メンテナーはふだん 1 日以内に返信
-
community documentation good first issue
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
TMHSDigital/subenum#135 ·
メンテナーはふだん 1 日以内に返信
-
area: dns enhancement good first issue
難易度 2/5 1時間未満 初心者へのやさしさ 90/100
TMHSDigital/subenum#134 ·
メンテナーはふだん 1 日以内に返信
-
community marketing priority: low
難易度 5/5 1週間以上 初心者へのやさしさ 35/100
TMHSDigital/subenum#132 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
feature priority: low
難易度 5/5 1週間以上 初心者へのやさしさ 35/100
TMHSDigital/subenum#131 ·
メンテナーはふだん 1 日以内に返信
TMHSDigital/subenum の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
prime-radiant-inc/evener#4223 ·
メンテナーはふだん 1 日以内に返信
-
bug
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
open-telemetry/opentelemetry-go-compile-instrumentation#1467 ·
メンテナーはふだん 3 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
yetone/magpie#1490 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
bug
難易度 1/5 1時間未満 初心者へのやさしさ 72/100
メンテナーはふだん 1 日以内に返信
-
a:bug
難易度 2/5 1〜3時間 初心者へのやさしさ 80/100
gotify/server#1068 · リアクション 1 件 ·
メンテナーはふだん 2 日以内に返信