Epic: Support reproducible builds
還沒有人認領這個 Issue。
評估
- 難度
- 5/5
- 預估耗時
- 一週以上
- 新手友好度
- 20/100
- Issue 類型
- 功能
- 描述清晰度
- 需要釐清
- 活躍度
- 停滯
- 技術堆疊
- github-actions, macos, vim
- 領域
- build-system, ci-cd, release
研究方向
此 issue 未指定具體檔案或測試;請先檢視現有的 build 腳本與 binary-release CI workflow。當本機與 CI 建置使用一致的 flags 與環境資料、可以比較未簽署或 ad-hoc-signed 的 app,且 CI 驗證受支援 build 環境之間的可重現性時,即表示完成。
由索引模型根據 Issue 內容生成。
描述
We currently distribute binary releases that people can use to download and install MacVim. We should add reproducible builds so that the binary we release is deterministic and reproducible and can be easily built on a local machine by any third party in an identical fashion.
Some motivations include the fact that supply chain attacks are real and while MacVim is unlikely a high-value target, it's still useful to reduce the likelihood of such problem happening to begin with. Also, with the deprecation of the macos-12 GitHub Action runner we will need to find another way to build the legacy MacVim binaries (either via a custom VM, or another CI service like Circle CI), and it would be nice to have some standard way to compare the generated artifacts and to have trust in the process working.
Note that we distribute signed apps, which is signed by a private key that only the maintainer controls, so it's impossible to have an artifact (MacVim.app) that can be compared bit-by-bit to a local build. We will need to provide a script that could strip the app signature before comparing.
- Use relative paths for debug symbols and reproducible linker flags when building Vim
- Use
SOURCE_DATE_EPOCHto make builds not dependent on date/time. - Add documentation, and refactor build scripts (also necessary when adding another CI system) to make it more easily to build locally with the same flags.
- Add CI output artifacts that contain necessary environment info.
- #1586
- Add user script that could compare two apps by stripping the signature, resign with adhoc signature, and then compare the result binaries. We also need to compare the entitlements.
- CI test to validate reproducible builds.
- Test in older versions of Xcode to make sure didn't break anything.
Related:
- Add support for exporting dSYM files as part of build steps. These contain debug symbols and help diagnose crash issues for users. Make sure to use relative paths as it's necessary for reproducibility. This is a bit annoying to do due to a clang issue llvm/llvm-project#113973.
- 主要語言
- Vim Script
- 星號
- 7.9k
- 分支
- 691
- 平均合併
- 20 分鐘
- 30 天內合併 PR
- 4
環境準備
- 沒有 Dockerfile 或 Docker Compose 檔案
- 沒有 Pull Request 範本
- 閱讀貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
macvim-dev/macvim 的其他 Issue
-
難度 2/5 1-3 小時 新手友好度 68/100
macvim-dev/macvim#1697 · 6 則留言 ·
-
難度 2/5 1-3 小時 新手友好度 76/100
macvim-dev/macvim#1658 ·
-
難度 2/5 1-3 小時 新手友好度 76/100
macvim-dev/macvim#1657 ·
-
難度 2/5 1-3 小時 新手友好度 76/100
macvim-dev/macvim#1655 ·
-
難度 2/5 半天 新手友好度 72/100
macvim-dev/macvim#1653 ·
查看 macvim-dev/macvim 的全部 Issue
相似的 Issue
-
good first issue needs-triage priority: medium
難度 2/5 1-3 小時 新手友好度 72/100
melodic-software/claude-code-plugins#7014 · 1 則留言 ·
維護者通常 1 天內回覆
-
0.kind: enhancement 9.needs: package (update)
難度 2/5 1-3 小時 新手友好度 68/100
維護者通常 1 天內回覆
-
bug
難度 2/5 1-3 小時 新手友好度 62/100
hpi-swa-teaching/AutoTDD#135 ·
-
bug pixi-build-r
難度 2/5 1-3 小時 新手友好度 70/100
prefix-dev/pixi#7229 ·
維護者通常 1 天內回覆
-
難度 2/5 1-3 小時 新手友好度 75/100
mesonbuild/wrapdb#2961 ·
維護者通常 1 天內回覆