Files
fips/packaging/debian
Johnathan Corgan d4acdfc39f Check the package's declared dependencies against the libraries its binaries need
The package's Depends comes from cargo-deb's "$auto", which runs
dpkg-shlibdeps over each binary. cargo-deb deliberately removes every libgcc
entry from that result, on the grounds that every system has one, so the
package never declared the libgcc-s1 all four binaries link. Otherwise it
passes the dpkg-shlibdeps output through unchanged, with one more gap: when
dpkg-shlibdeps fails on a binary it only warns and builds anyway, leaving that
binary's libraries out of the list.

testing/check-deb-depends.sh runs dpkg-shlibdeps once over every ELF object in
the built package and compares the result with the shipped Depends. Every
derived entry must be shipped, and the highest shipped floor for it must equal
the derived floor. A missing or lower entry means the package installs where
its binaries cannot run; a higher one means a hand-written floor no longer
tracks what the binaries need. Both fail the build. build-deb-container.sh
runs it inside the build image, so it reads the same symbols files and C
library cargo-deb did, and every producer of the package is gated.

libgcc-s1 (>= 4.2) is now declared by hand beside "$auto". There is no
exception for it in the check, so its floor is held equal to the derived one
and cannot fall behind or run ahead unnoticed.
2026-09-19 10:08:39 +00:00
..