Files
amethyst/tools
Claude ea8326f759 fix(build): close two gaps in the Arti ABI guard
Audit of the previous commit turned up two ways the new checks could
still pass while the APK ships a dead Tor.

verify-reproducible.sh kept its own copy of the ABI list, a fourth one
next to splits.abi, rust-toolchain.toml and build-arti.sh's TARGETS. Add
an ABI that copy misses and the script rebuilds it twice, hashes neither,
and still prints REPRODUCIBLE — the same false pass its own comment says
was fixed for --release. It now asks `build-arti.sh --print-abis` with
the flags it is about to pass on, so the set it hashes is by construction
the set that was just built.

verifyArtiAbis only tested File.exists(). A zero-byte placeholder, a
truncated file, or arm64's library copied into x86/ all satisfied that
and all load as nothing on device — and unlike a missing file, they look
fine in git. It now reads the ELF header and checks the class and
e_machine for the ABI, which is what separates arm64's .so from armv7's
when both are the right size and both exist.

Verified: the guard still passes on the four committed libraries, and
rejects an empty file, a 64-bit .so in a 32-bit dir, and armv7's .so in
x86/ (same bitness, wrong machine) with the right rebuild command each
time.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MX1p385SiQMd2Lhkbg2YKc
2026-09-18 17:15:05 +00:00
..