From 2ca4971d91ef5b4d8d4382edb57476144374b655 Mon Sep 17 00:00:00 2001 From: Feng Ruohang Date: Wed, 5 Aug 2026 00:59:06 +0800 Subject: [PATCH] build: stop stamping the build machine's GOPATH/GOROOT into the binary gen-ldflags injected -X cmd.GOPATH / cmd.GOROOT from the builder's environment, baking absolute paths like /Users//go into every released binary. That defeats -trimpath and makes the build unreproducible: a third party rebuilding the same tag gets different bytes and cannot verify checksums.txt. The values only seed logger.Init's source-path trim list, and under -trimpath the binary's paths are already relative, so there is no build-machine prefix left to trim - the trim list also still gets runtime.GOROOT() and build.Default.GOPATH at run time. Dropping the two stamps changes no observable logging behaviour; cmd.GOPATH/GOROOT keep the empty defaults a plain go build leaves. Verified: gen-ldflags output no longer contains cmd.GOPATH/GOROOT; a -trimpath release build has zero occurrences of the builder path (was 1); Version, ReleaseTag and CommitID stamps are intact. Co-authored-by: Claude --- buildscripts/gen-ldflags.go | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/buildscripts/gen-ldflags.go b/buildscripts/gen-ldflags.go index a7649056f..b130e569a 100644 --- a/buildscripts/gen-ldflags.go +++ b/buildscripts/gen-ldflags.go @@ -38,8 +38,12 @@ func genLDFlags(version string) string { ldflagsStr += " -X github.com/minio/minio/cmd.ReleaseTag=" + releaseTag ldflagsStr += " -X github.com/minio/minio/cmd.CommitID=" + commitID() ldflagsStr += " -X github.com/minio/minio/cmd.ShortCommitID=" + commitID()[:12] - ldflagsStr += " -X github.com/minio/minio/cmd.GOPATH=" + os.Getenv("GOPATH") - ldflagsStr += " -X github.com/minio/minio/cmd.GOROOT=" + os.Getenv("GOROOT") + // GOPATH/GOROOT are deliberately not stamped in. They only seed the logger's + // source-path trim list, which -trimpath already makes moot (paths are + // relative in the binary, so there is no build-machine prefix left to trim), + // and stamping them baked the builder's absolute paths into the released + // binary - defeating -trimpath and reproducible builds. cmd.GOPATH/GOROOT + // keep their empty defaults, exactly as a plain `go build` leaves them. return ldflagsStr }