You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
#1018 checks which C library each Linux binary links. The same rules now exist in three files, and nothing keeps them the same. cipherstash-bot and freshtonic both raised this in review of #1018.
Three copies can drift apart
The rules are in these files:
.github/workflows/_build-auth-artifacts.yml, which every @cipherstash/auth release build runs;
.github/workflows/auth-preflight.yml, the dry run of that release;
.github/workflows/ffi-preflight.yml, the dry run of the protect-ffi release.
If someone changes a rule or adds a platform in one file, the others keep the old rule. The release build could then accept a binary that the preflight rejects, or the reverse. The test in scripts/__tests__/auth-build-artifacts.test.mjs reads only the first file.
Fix
Put the rules in one script, for example .github/scripts/check-c-library.sh <platform> <binary-path>.
Test the script directly. Give it a gnu binary, a musl binary and a statically linked binary, and check that it accepts only the right ones for each platform.
If the copies stay, add a test that reads the case block from each file and checks that they match. scripts/__tests__/eql-workflow-filters.test.mjs already does this for other repeated workflow logic.
#1027 merged on 3 October 2026. scripts/check-c-library.sh <platform> <binary> now holds the only copy of the rules. Both release build workflows call it on each Linux binary before packing, and both preflights call it on the packed tarballs.
The old copy in ffi-preflight.yml had drifted: it never required musl, so it would have accepted a statically linked binary.
scripts/__tests__/check-c-library.test.mjs runs the real readelf against small ELF files that the test writes: gnu, musl, static, no C library, and two with long dynamic sections.
#1018 checks which C library each Linux binary links. The same rules now exist in three files, and nothing keeps them the same. cipherstash-bot and freshtonic both raised this in review of #1018.
Three copies can drift apart
The rules are in these files:
.github/workflows/_build-auth-artifacts.yml, which every@cipherstash/authrelease build runs;.github/workflows/auth-preflight.yml, the dry run of that release;.github/workflows/ffi-preflight.yml, the dry run of the protect-ffi release.If someone changes a rule or adds a platform in one file, the others keep the old rule. The release build could then accept a binary that the preflight rejects, or the reverse. The test in
scripts/__tests__/auth-build-artifacts.test.mjsreads only the first file.Fix
.github/scripts/check-c-library.sh <platform> <binary-path>._build-ffi-artifacts.ymlwhen Check protect-ffi's C library in every build, and stop downloading from musl.cc #1041 adds the check there.If the copies stay, add a test that reads the
caseblock from each file and checks that they match.scripts/__tests__/eql-workflow-filters.test.mjsalready does this for other repeated workflow logic.Fixed by #1027
#1027 merged on 3 October 2026.
scripts/check-c-library.sh <platform> <binary>now holds the only copy of the rules. Both release build workflows call it on each Linux binary before packing, and both preflights call it on the packed tarballs.The old copy in
ffi-preflight.ymlhad drifted: it never required musl, so it would have accepted a statically linked binary.scripts/__tests__/check-c-library.test.mjsruns the realreadelfagainst small ELF files that the test writes: gnu, musl, static, no C library, and two with long dynamic sections.