mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-06 03:28:24 +00:00
The package's Depends comes from cargo-deb's "$auto", which runs dpkg-shlibdeps over each binary. cargo-deb deliberately removes every libgcc entry from that result, on the grounds that every system has one, so the package never declared the libgcc-s1 all four binaries link. Otherwise it passes the dpkg-shlibdeps output through unchanged, with one more gap: when dpkg-shlibdeps fails on a binary it only warns and builds anyway, leaving that binary's libraries out of the list. testing/check-deb-depends.sh runs dpkg-shlibdeps once over every ELF object in the built package and compares the result with the shipped Depends. Every derived entry must be shipped, and the highest shipped floor for it must equal the derived floor. A missing or lower entry means the package installs where its binaries cannot run; a higher one means a hand-written floor no longer tracks what the binaries need. Both fail the build. build-deb-container.sh runs it inside the build image, so it reads the same symbols files and C library cargo-deb did, and every producer of the package is gated. libgcc-s1 (>= 4.2) is now declared by hand beside "$auto". There is no exception for it in the check, so its floor is held equal to the derived one and cannot fall behind or run ahead unnoticed.