mirror of
https://github.com/jmcorgan/fips.git
synced 2026-07-30 19:46:15 +00:00
Add reproducible build infrastructure
Pin Rust toolchain to 1.94.0 via rust-toolchain.toml for deterministic compiler output across environments. Set SOURCE_DATE_EPOCH from git commit timestamp in CI workflows and packaging scripts to normalize embedded timestamps. Make packaging archives reproducible: pass --mtime=@$SOURCE_DATE_EPOCH to tar in .deb, .ipk, and systemd tarball builds. Normalize ownership to root:root in systemd tarballs. Pin cargo-zigbuild to 0.19.8 for cross-compilation stability. Add SHA-256 hash output to CI build and OpenWrt packaging workflows for binary verification.
This commit is contained in:
committed by
Johnathan Corgan
parent
fed6cc6987
commit
c164de8808
@@ -18,6 +18,7 @@ permissions:
|
||||
env:
|
||||
CARGO_TERM_COLOR: always
|
||||
RUST_BACKTRACE: 1
|
||||
SOURCE_DATE_EPOCH: 0 # overridden per-step after checkout
|
||||
|
||||
# ─────────────────────────────────────────────────────────────────────────────
|
||||
# Job 1 – Build matrix
|
||||
@@ -40,6 +41,9 @@ jobs:
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- name: Set SOURCE_DATE_EPOCH from git
|
||||
run: echo "SOURCE_DATE_EPOCH=$(git log -1 --format=%ct)" >> "$GITHUB_ENV"
|
||||
|
||||
- name: Install Rust toolchain
|
||||
uses: dtolnay/rust-toolchain@stable
|
||||
|
||||
@@ -57,6 +61,9 @@ jobs:
|
||||
- name: Build
|
||||
run: cargo build --release
|
||||
|
||||
- name: SHA-256 hashes
|
||||
run: sha256sum target/release/fips target/release/fipsctl target/release/fipstop
|
||||
|
||||
# Upload the Linux binary so integration jobs can use it without rebuilding
|
||||
- name: Upload Linux binary
|
||||
if: matrix.os == 'ubuntu-latest'
|
||||
@@ -82,6 +89,9 @@ jobs:
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- name: Set SOURCE_DATE_EPOCH from git
|
||||
run: echo "SOURCE_DATE_EPOCH=$(git log -1 --format=%ct)" >> "$GITHUB_ENV"
|
||||
|
||||
- name: Install Rust toolchain
|
||||
uses: dtolnay/rust-toolchain@stable
|
||||
|
||||
|
||||
@@ -11,6 +11,7 @@ on:
|
||||
|
||||
env:
|
||||
CARGO_TERM_COLOR: always
|
||||
SOURCE_DATE_EPOCH: 0 # overridden per-step after checkout
|
||||
|
||||
jobs:
|
||||
build:
|
||||
@@ -46,6 +47,9 @@ jobs:
|
||||
with:
|
||||
fetch-depth: 0
|
||||
|
||||
- name: Set SOURCE_DATE_EPOCH from git
|
||||
run: echo "SOURCE_DATE_EPOCH=$(git log -1 --format=%ct)" >> "$GITHUB_ENV"
|
||||
|
||||
- name: Derive package version
|
||||
id: version
|
||||
run: |
|
||||
@@ -84,7 +88,7 @@ jobs:
|
||||
openwrt-${{ matrix.rust_target }}-
|
||||
|
||||
- name: Install cargo-zigbuild
|
||||
run: cargo install cargo-zigbuild --locked
|
||||
run: cargo install cargo-zigbuild --version 0.19.8 --locked
|
||||
|
||||
- name: Install zig (required by cargo-zigbuild)
|
||||
uses: goto-bus-stop/setup-zig@v2
|
||||
@@ -98,6 +102,13 @@ jobs:
|
||||
LLVM_STRIP: llvm-strip
|
||||
run: ./packaging/openwrt-ipk/build-ipk.sh --arch ${{ matrix.build_arch }}
|
||||
|
||||
- name: SHA-256 hashes
|
||||
run: |
|
||||
echo "==> Binaries:"
|
||||
sha256sum target/${{ matrix.rust_target }}/release/fips target/${{ matrix.rust_target }}/release/fipsctl target/${{ matrix.rust_target }}/release/fipstop
|
||||
echo "==> Package:"
|
||||
sha256sum dist/${{ steps.version.outputs.filename }}
|
||||
|
||||
- name: Upload artifact
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
|
||||
@@ -19,6 +19,11 @@ if ! command -v cargo-deb &>/dev/null; then
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Derive SOURCE_DATE_EPOCH from git if not already set (reproducible builds)
|
||||
if [ -z "${SOURCE_DATE_EPOCH:-}" ]; then
|
||||
export SOURCE_DATE_EPOCH=$(git log -1 --format=%ct)
|
||||
fi
|
||||
|
||||
# Build the .deb package
|
||||
echo "Building .deb package..."
|
||||
cargo deb
|
||||
|
||||
@@ -244,7 +244,11 @@ fi
|
||||
ipk_tar() {
|
||||
# ipk_tar <output.tar.gz> <source-dir> [paths...]
|
||||
local out="$1" src="$2"; shift 2
|
||||
COPYFILE_DISABLE=1 "$TAR_CMD" $TAR_EXTRA_FLAGS -czf "$out" -C "$src" "$@"
|
||||
local mtime_flags=""
|
||||
if [ -n "${SOURCE_DATE_EPOCH:-}" ]; then
|
||||
mtime_flags="--mtime=@$SOURCE_DATE_EPOCH"
|
||||
fi
|
||||
COPYFILE_DISABLE=1 "$TAR_CMD" $TAR_EXTRA_FLAGS $mtime_flags -czf "$out" -C "$src" "$@"
|
||||
}
|
||||
|
||||
ipk_tar "$IPK_WORK/control.tar.gz" "$CONTROL_DIR" .
|
||||
|
||||
@@ -45,9 +45,16 @@ cp "${SCRIPT_DIR}/README.install.md" "${STAGING_DIR}/"
|
||||
|
||||
chmod +x "${STAGING_DIR}/install.sh" "${STAGING_DIR}/uninstall.sh"
|
||||
|
||||
# Create tarball
|
||||
# Create tarball (reproducible: normalize timestamps and ownership)
|
||||
cd "${DEPLOY_DIR}"
|
||||
tar czf "${TARBALL_NAME}.tar.gz" "${TARBALL_NAME}/"
|
||||
TAR_REPRO_FLAGS=""
|
||||
if [ -n "${SOURCE_DATE_EPOCH:-}" ]; then
|
||||
TAR_REPRO_FLAGS="--mtime=@${SOURCE_DATE_EPOCH}"
|
||||
fi
|
||||
if tar --version 2>/dev/null | grep -q 'GNU tar'; then
|
||||
TAR_REPRO_FLAGS="${TAR_REPRO_FLAGS} --numeric-owner --owner=0 --group=0"
|
||||
fi
|
||||
COPYFILE_DISABLE=1 tar ${TAR_REPRO_FLAGS} -czf "${TARBALL_NAME}.tar.gz" "${TARBALL_NAME}/"
|
||||
rm -rf "${STAGING_DIR}"
|
||||
|
||||
echo ""
|
||||
|
||||
@@ -0,0 +1,2 @@
|
||||
[toolchain]
|
||||
channel = "1.94.0"
|
||||
Reference in New Issue
Block a user