Release linux/amd64 binary is dynamically linked, contradicting the "single static binary" claim
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức phù hợp với người mới
- 68/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- github-actions, go
- Lĩnh vực
- build-system, cli, release
Hướng nghiên cứu
Start with the release build matrix in .github/workflows/go.yml, especially the build step around line 192, and inspect how its Linux legs compile and name their assets. Check the resulting Linux binaries with file and add a CI assertion that verifies they are statically linked. Done means Linux release assets meet the issue's stated static/stripped criteria and CI catches regressions.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Why it matters
The repo description, README and site all promise a "single static Go binary". The v0.8.0 subenum-linux-amd64 release asset is actually dynamically linked against glibc (file reports dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2 ... not stripped). It will not run on Alpine/musl, in scratch/distroless images, or on older glibc hosts, which are common pentest/CI environments. Oddly the cross-compiled linux-arm64 asset is static, so behaviour differs by arch.
Evidence
.github/workflows/go.yml:192— the release matrix builds with
go build -v -buildvcs=false -ldflags "-X main.Version=..."and noCGO_ENABLED=0. The linux/amd64 leg compiles natively onubuntu-latest, so cgo is on andnetlinks the cgo resolver.- No
-trimpathand no-s -w, so binaries embed local paths and debug info (larger, not reproducible). -buildvcs=falsestrips VCS info, sogo version -m subenumshows nothing useful for provenance.
Suggested approach
- Set
CGO_ENABLED: 0in the build step env for all legs. - Build with
-trimpath -ldflags "-s -w -X main.Version=..."; drop-buildvcs=falsein CI (keep it only where.gitis absent, e.g. Docker). - Add a CI assertion on Linux legs:
file subenum-linux-* | grep -q 'statically linked'. - (Covered more broadly by the GoReleaser issue, but this one-line fix should ship as a patch release now.)
Done when
- All Linux release assets report
statically linked, are stripped, and CI fails if that regresses. - A v0.8.1 patch release replaces the dynamic binary.
- Ngôn ngữ chính
- Go
- Star
- 1
- Fork
- 1
- Merge trung bình
- 5 ngày 2 giờ
- Pull request đã merge (30 ngày)
- 3
Chuẩn bị môi trường
Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.
- Có Dockerfile hoặc tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của TMHSDigital/subenum
-
area: cli enhancement good first issue
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
TMHSDigital/subenum#136 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
community documentation good first issue
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
TMHSDigital/subenum#135 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
area: dns enhancement good first issue
Độ khó 2/5 Dưới một giờ Mức phù hợp với người mới 90/100
TMHSDigital/subenum#134 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
community marketing priority: low
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 35/100
TMHSDigital/subenum#132 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
feature priority: low
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 35/100
TMHSDigital/subenum#131 ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của TMHSDigital/subenum
Issue tương tự
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 88/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 67/100
vanderheijden86/b9s#20 ·
-
go-battery needs an ndsctl on PATH: TestPurchaseSessionGuardHoldsThroughTheOutcomeUnknownWindow fails on bare hosts (passes with stub)Có thể đã có người làm Có pull request liên kết đang mở hoặc đã được merge. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
OpenTollGate/tollgate-module-basic-go#726 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
ux waiting for feedback
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 63/100
evcc-io/evcc#34527 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
phase:v3 type:harness
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
Maintainer thường phản hồi trong vòng 1 ngày