Skip to content

Keep one copy of the C library rules for the Linux release binaries #1043

Description

@auxesis

#1018 checks which C library each Linux binary links. The same rules now exist in three files, and nothing keeps them the same. cipherstash-bot and freshtonic both raised this in review of #1018.

Three copies can drift apart

The rules are in these files:

  • .github/workflows/_build-auth-artifacts.yml, which every @cipherstash/auth release build runs;
  • .github/workflows/auth-preflight.yml, the dry run of that release;
  • .github/workflows/ffi-preflight.yml, the dry run of the protect-ffi release.

If someone changes a rule or adds a platform in one file, the others keep the old rule. The release build could then accept a binary that the preflight rejects, or the reverse. The test in scripts/__tests__/auth-build-artifacts.test.mjs reads only the first file.

Fix

  1. Put the rules in one script, for example .github/scripts/check-c-library.sh <platform> <binary-path>.
  2. Call it from all three workflows, and from _build-ffi-artifacts.yml when Check protect-ffi's C library in every build, and stop downloading from musl.cc #1041 adds the check there.
  3. Test the script directly. Give it a gnu binary, a musl binary and a statically linked binary, and check that it accepts only the right ones for each platform.

If the copies stay, add a test that reads the case block from each file and checks that they match. scripts/__tests__/eql-workflow-filters.test.mjs already does this for other repeated workflow logic.

Fixed by #1027

#1027 merged on 3 October 2026. scripts/check-c-library.sh <platform> <binary> now holds the only copy of the rules. Both release build workflows call it on each Linux binary before packing, and both preflights call it on the packed tarballs.

The old copy in ffi-preflight.yml had drifted: it never required musl, so it would have accepted a statically linked binary.

scripts/__tests__/check-c-library.test.mjs runs the real readelf against small ELF files that the test writes: gnu, musl, static, no C library, and two with long dynamic sections.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    SDKgithub-actionsPull request modifies GitHub Actions

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions