mirror of
https://github.com/pgsty/minio.git
synced 2026-08-08 23:33:30 +03:00
2ca4971d91
gen-ldflags injected -X cmd.GOPATH / cmd.GOROOT from the builder's environment, baking absolute paths like /Users/<user>/go into every released binary. That defeats -trimpath and makes the build unreproducible: a third party rebuilding the same tag gets different bytes and cannot verify checksums.txt. The values only seed logger.Init's source-path trim list, and under -trimpath the binary's paths are already relative, so there is no build-machine prefix left to trim - the trim list also still gets runtime.GOROOT() and build.Default.GOPATH at run time. Dropping the two stamps changes no observable logging behaviour; cmd.GOPATH/GOROOT keep the empty defaults a plain go build leaves. Verified: gen-ldflags output no longer contains cmd.GOPATH/GOROOT; a -trimpath release build has zero occurrences of the builder path (was 1); Version, ReleaseTag and CommitID stamps are intact. Co-authored-by: Claude <noreply@anthropic.com>
126 lines
3.6 KiB
Go
126 lines
3.6 KiB
Go
//go:build ignore
|
|
// +build ignore
|
|
|
|
// Copyright (c) 2015-2021 MinIO, Inc.
|
|
//
|
|
// This file is part of MinIO Object Storage stack
|
|
//
|
|
// This program is free software: you can redistribute it and/or modify
|
|
// it under the terms of the GNU Affero General Public License as published by
|
|
// the Free Software Foundation, either version 3 of the License, or
|
|
// (at your option) any later version.
|
|
//
|
|
// This program is distributed in the hope that it will be useful
|
|
// but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
// GNU Affero General Public License for more details.
|
|
//
|
|
// You should have received a copy of the GNU Affero General Public License
|
|
// along with this program. If not, see <http://www.gnu.org/licenses/>.
|
|
|
|
package main
|
|
|
|
import (
|
|
"fmt"
|
|
"os"
|
|
"os/exec"
|
|
"strconv"
|
|
"strings"
|
|
"time"
|
|
)
|
|
|
|
func genLDFlags(version string) string {
|
|
releaseTag, date := releaseTag(version)
|
|
copyrightYear := strconv.Itoa(date.Year())
|
|
ldflagsStr := "-s -w"
|
|
ldflagsStr += " -X github.com/minio/minio/cmd.Version=" + version
|
|
ldflagsStr += " -X github.com/minio/minio/cmd.CopyrightYear=" + copyrightYear
|
|
ldflagsStr += " -X github.com/minio/minio/cmd.ReleaseTag=" + releaseTag
|
|
ldflagsStr += " -X github.com/minio/minio/cmd.CommitID=" + commitID()
|
|
ldflagsStr += " -X github.com/minio/minio/cmd.ShortCommitID=" + commitID()[:12]
|
|
// GOPATH/GOROOT are deliberately not stamped in. They only seed the logger's
|
|
// source-path trim list, which -trimpath already makes moot (paths are
|
|
// relative in the binary, so there is no build-machine prefix left to trim),
|
|
// and stamping them baked the builder's absolute paths into the released
|
|
// binary - defeating -trimpath and reproducible builds. cmd.GOPATH/GOROOT
|
|
// keep their empty defaults, exactly as a plain `go build` leaves them.
|
|
return ldflagsStr
|
|
}
|
|
|
|
// genReleaseTag prints release tag to the console for easy git tagging.
|
|
func releaseTag(version string) (string, time.Time) {
|
|
relPrefix := "DEVELOPMENT"
|
|
if prefix := os.Getenv("MINIO_RELEASE"); prefix != "" {
|
|
relPrefix = prefix
|
|
}
|
|
|
|
relSuffix := ""
|
|
if hotfix := os.Getenv("MINIO_HOTFIX"); hotfix != "" {
|
|
relSuffix = hotfix
|
|
}
|
|
|
|
relTag := strings.Replace(version, " ", "-", -1)
|
|
relTag = strings.Replace(relTag, ":", "-", -1)
|
|
t, err := time.Parse("2006-01-02T15-04-05Z", relTag)
|
|
if err != nil {
|
|
panic(err)
|
|
}
|
|
relTag = strings.Replace(relTag, ",", "", -1)
|
|
relTag = relPrefix + "." + relTag
|
|
if relSuffix != "" {
|
|
relTag += "." + relSuffix
|
|
}
|
|
|
|
return relTag, t
|
|
}
|
|
|
|
// commitID returns the abbreviated commit-id hash of the last commit.
|
|
func commitID() string {
|
|
// git log --format="%H" -n1
|
|
var (
|
|
commit []byte
|
|
err error
|
|
)
|
|
cmdName := "git"
|
|
cmdArgs := []string{"log", "--format=%H", "-n1"}
|
|
if commit, err = exec.Command(cmdName, cmdArgs...).Output(); err != nil {
|
|
fmt.Fprintln(os.Stderr, "Error generating git commit-id: ", err)
|
|
os.Exit(1)
|
|
}
|
|
|
|
return strings.TrimSpace(string(commit))
|
|
}
|
|
|
|
func commitTime() time.Time {
|
|
// git log --format=%cD -n1
|
|
var (
|
|
commitUnix []byte
|
|
err error
|
|
)
|
|
cmdName := "git"
|
|
cmdArgs := []string{"log", "--format=%cI", "-n1"}
|
|
if commitUnix, err = exec.Command(cmdName, cmdArgs...).Output(); err != nil {
|
|
fmt.Fprintln(os.Stderr, "Error generating git commit-time: ", err)
|
|
os.Exit(1)
|
|
}
|
|
|
|
t, err := time.Parse(time.RFC3339, strings.TrimSpace(string(commitUnix)))
|
|
if err != nil {
|
|
fmt.Fprintln(os.Stderr, "Error generating git commit-time: ", err)
|
|
os.Exit(1)
|
|
}
|
|
|
|
return t.UTC()
|
|
}
|
|
|
|
func main() {
|
|
var version string
|
|
if len(os.Args) > 1 {
|
|
version = os.Args[1]
|
|
} else {
|
|
version = commitTime().Format(time.RFC3339)
|
|
}
|
|
|
|
fmt.Println(genLDFlags(version))
|
|
}
|