Build provenance of GCC runtime libraries in NumPy 2.5.2 macOS arm64 wheel
まだ誰も着手していません。
評価
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 初心者へのやさしさ
- 35/100
- issue の種類
- ドキュメント
- 明瞭さ
- おおむね明確
- 活発さ
- 活発
- 領域
- build-system, release
調査の方向性
numpy/numpy-release の公開レコード、リビジョン 72af5b09acd111d80b0e5bd9c1bcfcbec4b940b4 から始め、固定された OpenBLAS 要件と保持されている Producer/Provider レシピを追跡してください。これらのレコードを、一覧にある 3 つの wheel-member ハッシュと比較してください。正確な入力ハッシュ、GCC/Conda のビルド ID、ソースおよびパッチの参照、ならびにそれらを NumPy wheel に結び付ける修復前後の記録があれば、完了です。
索引モデルが issue の本文から書いたものです。
説明
We are checking the corresponding source and build provenance of compiler runtime libraries in the NumPy2.5.2 CPython3.13 macOS arm64 wheel. We have retained these public evidence joins:
- NumPy wheel SHA256:52c808f96484f5571a5cc863775ce50247c17dfb3b0361f8ed6b4b0456f80080.
- The publication record points to numpy/numpy-release revision72af5b09acd111d80b0e5bd9c1bcfcbec4b940b4. Its OpenBLAS requirements pin scipy-openblas32/64==0.3.34.0.0, consistent with the wheel's reported OpenBLAS version.
- The retained OpenBLAS producer recipe selects the gcc-11.3.0-2 arm64-native provider package. That provider recipe selects versioned Conda components and removes conda-meta; the public records we found do not identify the exact underlying package builds and patches.
The three final wheel members are:
| Member | SHA256 |
|---|---|
| numpy/.dylibs/libgfortran.5.dylib | 728b8a719b0b015422632c74de2913ed14d82b319bc3a0643830bd506492662e |
| numpy/.dylibs/libgcc_s.1.1.dylib | baee2e6118dd54c0852f881d718516d70884de84bfaa085de5d8d8f90baa3b06 |
| numpy/.dylibs/libquadmath.0.dylib | 1b341ae276c4adcb30c070b774ec6e68e819c883e897f0de8941d553f7989a0d |
Could you provide the exact producer wheel/input hashes, GCC/Conda package build identities and corresponding source/patch references for these three libraries, ideally with the build or repair record that ties them to this NumPy wheel? Loader-path repair or signing can change final bytes, so an explicit before/after record would also help.
We are not reporting an exploit or evidence of tampering. The question is limited to exact source and packaging provenance. We do not need credentials, private user data or access to your infrastructure.
- 主要言語
- Shell
- スター
- 4
- フォーク
- 10
- 平均マージ
- 8時間 5分
- マージ済み PR(30日)
- 1
コントリビューションガイド
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
numpy/numpy-release のほかの issue
-
難易度 3/5 1〜2日 初心者へのやさしさ 55/100
numpy/numpy-release#41 · コメント 2 件 · リアクション 1 件 ·
-
難易度 4/5 3〜5日 初心者へのやさしさ 35/100
numpy/numpy-release#13 ·
-
難易度 3/5 1〜2日 初心者へのやさしさ 58/100
numpy/numpy-release#11 · コメント 5 件 ·
numpy/numpy-release の issue をすべて見る
似ている issue
-
難易度 1/5 1時間未満 初心者へのやさしさ 92/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
community-scripts/ProxmoxVE#17425 · コメント 1 件 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 90/100
danielmiessler/LifeOS#2218 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
conda-forge/python-feedstock#934 ·
-
docs(agents): strengthen the no-backslash-escaped-backticks rule with an issue-creation example オープン
難易度 1/5 1時間未満 初心者へのやさしさ 92/100