-
-
Notifications
You must be signed in to change notification settings - Fork 3
reproducible builds
Status: settings only. No CI job checks it.
The release build uses deterministic settings.
scripts/repro-env.sh prints the environment. release.yml adds it to GITHUB_ENV before every platform build:
-
SOURCE_DATE_EPOCHis the commit time. -
CARGO_INCREMENTAL=0. -
RUSTFLAGShas--remap-path-prefixfor the home and checkout paths, so the binary holds no build path.
The build runs npx tauri build --no-bundle -- --locked, then scripts/split-debug.sh, then npx tauri bundle.
Do not treat any release file as reproducible. Nobody checks it on any PR or release. The last check, in PR #37, found the stripped Linux binary and the frontend dist/ identical in two builds. It found the .deb different, because of packaging time stamps. The AppImage, the macOS .dmg files and the Windows installer were never checked.
scripts/check-hardening.sh checks the Linux binary. The Linux leg of leak-test runs it on every PR, and the release build runs it again:
ok PIE (ELF type): Type: DYN (Position-Independent Executable file)
ok PIE (FLAGS_1): Flags: NOW PIE
ok RELRO segment: GNU_RELRO
ok BIND_NOW (full RELRO): (FLAGS) BIND_NOW
ok NX stack (GNU_STACK RW, not RWE): GNU_STACK ... RW
That means: position-independent (PIE), full RELRO with BIND_NOW, and a non-executable stack (NX).
To check one binary on your machine:
./scripts/check-hardening.sh src-tauri/target/x86_64-unknown-linux-gnu/release/eepviewGenerated from docs/wiki in the repository. Edit there, not here.