Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Release linux/amd64 binary is dynamically linked, contradicting the "single static binary" claim

Đã đóng
#46 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức phù hợp với người mới
68/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
github-actions, go
Lĩnh vực
build-system, cli, release

Hướng nghiên cứu

Start with the release build matrix in .github/workflows/go.yml, especially the build step around line 192, and inspect how its Linux legs compile and name their assets. Check the resulting Linux binaries with file and add a CI assertion that verifies they are statically linked. Done means Linux release assets meet the issue's stated static/stripped criteria and CI catches regressions.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

area: release bug ci priority: high

Why it matters

The repo description, README and site all promise a "single static Go binary". The v0.8.0 subenum-linux-amd64 release asset is actually dynamically linked against glibc (file reports dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2 ... not stripped). It will not run on Alpine/musl, in scratch/distroless images, or on older glibc hosts, which are common pentest/CI environments. Oddly the cross-compiled linux-arm64 asset is static, so behaviour differs by arch.

Evidence

  • .github/workflows/go.yml:192 — the release matrix builds with
    go build -v -buildvcs=false -ldflags "-X main.Version=..." and no CGO_ENABLED=0. The linux/amd64 leg compiles natively on ubuntu-latest, so cgo is on and net links the cgo resolver.
  • No -trimpath and no -s -w, so binaries embed local paths and debug info (larger, not reproducible).
  • -buildvcs=false strips VCS info, so go version -m subenum shows nothing useful for provenance.

Suggested approach

  • Set CGO_ENABLED: 0 in the build step env for all legs.
  • Build with -trimpath -ldflags "-s -w -X main.Version=..."; drop -buildvcs=false in CI (keep it only where .git is absent, e.g. Docker).
  • Add a CI assertion on Linux legs: file subenum-linux-* | grep -q 'statically linked'.
  • (Covered more broadly by the GoReleaser issue, but this one-line fix should ship as a patch release now.)

Done when

  • All Linux release assets report statically linked, are stripped, and CI fails if that regresses.
  • A v0.8.1 patch release replaces the dynamic binary.
Ngôn ngữ chính
Go
Star
1
Fork
1
Merge trung bình
5 ngày 2 giờ
Pull request đã merge (30 ngày)
3

Chuẩn bị môi trường

Mở trong Codespaces

Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của TMHSDigital/subenum

Tất cả issue của TMHSDigital/subenum

Issue tương tự

Thêm issue về Go

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.