Release linux/amd64 binary is dynamically linked, contradicting the "single static binary" claim
維護者通常 1 天內回覆
還沒有人認領這個 Issue。
評估
- 難度
- 3/5
- 預估耗時
- 1-2 天
- 新手友好度
- 68/100
- Issue 類型
- 缺陷
- 描述清晰度
- 描述清楚
- 活躍度
- 活躍
- 技術堆疊
- github-actions, go
- 領域
- build-system, cli, release
研究方向
Start with the release build matrix in .github/workflows/go.yml, especially the build step around line 192, and inspect how its Linux legs compile and name their assets. Check the resulting Linux binaries with file and add a CI assertion that verifies they are statically linked. Done means Linux release assets meet the issue's stated static/stripped criteria and CI catches regressions.
由索引模型根據 Issue 內容生成。
描述
Why it matters
The repo description, README and site all promise a "single static Go binary". The v0.8.0 subenum-linux-amd64 release asset is actually dynamically linked against glibc (file reports dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2 ... not stripped). It will not run on Alpine/musl, in scratch/distroless images, or on older glibc hosts, which are common pentest/CI environments. Oddly the cross-compiled linux-arm64 asset is static, so behaviour differs by arch.
Evidence
.github/workflows/go.yml:192— the release matrix builds with
go build -v -buildvcs=false -ldflags "-X main.Version=..."and noCGO_ENABLED=0. The linux/amd64 leg compiles natively onubuntu-latest, so cgo is on andnetlinks the cgo resolver.- No
-trimpathand no-s -w, so binaries embed local paths and debug info (larger, not reproducible). -buildvcs=falsestrips VCS info, sogo version -m subenumshows nothing useful for provenance.
Suggested approach
- Set
CGO_ENABLED: 0in the build step env for all legs. - Build with
-trimpath -ldflags "-s -w -X main.Version=..."; drop-buildvcs=falsein CI (keep it only where.gitis absent, e.g. Docker). - Add a CI assertion on Linux legs:
file subenum-linux-* | grep -q 'statically linked'. - (Covered more broadly by the GoReleaser issue, but this one-line fix should ship as a patch release now.)
Done when
- All Linux release assets report
statically linked, are stripped, and CI fails if that regresses. - A v0.8.1 patch release replaces the dynamic binary.
- 主要語言
- Go
- 星號
- 1
- 分支
- 1
- 平均合併
- 5 天 2 小時
- 30 天內合併 PR
- 3
環境準備
在瀏覽器裡用你自己的 GitHub 帳號啟動這個專案的開發容器。
- 提供 Dockerfile 或 Docker Compose 檔案
- 有 Pull Request 範本
- 閱讀貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
TMHSDigital/subenum 的其他 Issue
-
area: cli enhancement good first issue
難度 2/5 1-3 小時 新手友好度 88/100
TMHSDigital/subenum#136 ·
維護者通常 1 天內回覆
-
community documentation good first issue
難度 2/5 1-3 小時 新手友好度 85/100
TMHSDigital/subenum#135 ·
維護者通常 1 天內回覆
-
area: dns enhancement good first issue
難度 2/5 1 小時以內 新手友好度 90/100
TMHSDigital/subenum#134 ·
維護者通常 1 天內回覆
-
community marketing priority: low
難度 5/5 一週以上 新手友好度 35/100
TMHSDigital/subenum#132 · 1 則留言 ·
維護者通常 1 天內回覆
-
feature priority: low
難度 5/5 一週以上 新手友好度 35/100
TMHSDigital/subenum#131 ·
維護者通常 1 天內回覆
查看 TMHSDigital/subenum 的全部 Issue
相似的 Issue
-
status:approved type:bug
難度 2/5 1-3 小時 新手友好度 85/100
Gentleman-Programming/gentle-ai#5326 ·
維護者通常 1 天內回覆
-
area/testing kind/cleanup priority/backlog triage/accepted
難度 2/5 1-3 小時 新手友好度 78/100
lexfrei/cloudflare-tunnel-gateway-controller#999 ·
維護者通常 1 天內回覆
-
automation models
難度 2/5 1-3 小時 新手友好度 75/100
維護者通常 1 天內回覆
-
bug
難度 2/5 1-3 小時 新手友好度 72/100
維護者通常 1 天內回覆
-
Can the search results with Year Released be in enclosed in the ( ) like Movie/TV(Year Released)未關閉
難度 2/5 1-3 小時 新手友好度 85/100
Dhairya3391/kari#32 ·