tests/packages/ruby/extractor.wasm is reproducible from exactly one directory on earth, and we publish it as reproducible #132
Labels
No labels
code-review
correctness
dos
performance
security
severity/high
severity/low
severity/medium
tech-debt
Kind/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Priority
Critical
Priority
High
Priority
Low
Priority
Medium
Reviewed
Confirmed
Reviewed
Duplicate
Reviewed
Invalid
Reviewed
Won't Fix
Status
Abandoned
Status
Blocked
Status
Need More Info
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
h-dv/code-index#132
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Found while fixing the example guest's reproducibility (commit
a5f91c2). Measured, not inferred. Deliberately not fixed there, for a reason given below.The measurement
Same source, two absolute paths, one rustc:
29 551 bytes each, 547 differing bytes, every one inside
[23876, 29321)— thenamecustom section.Same cause as the example guest:
crates/guest/rubytakes a path dependency oncrates/guest, cargo derives-C metadatafrom the package's absolute path, rustc hashes it into the crate disambiguator, and the disambiguator is spelled into every mangled name.The checked-in
tests/packages/ruby/extractor.wasmstill carriesCskmEPAwE88Sg_16code_index_guest— one particular machine's disambiguator.Why this is worse than the example-guest instance
The example guest is a test fixture. This is a shipped, operator-installed, digest-pinned package component.
WASM_ARTIFACTSrecords the claim "reproducible IN THIS REPOSITORY:crates/guest/ruby/build.sh". That statement is true from exactly one directory on earth. Anyone who clones this repository and runs the script gets different bytes and therefore a differentpackage_digest— and the digest is package identity, the thingplugin install --sha256and every signature check are keyed on.So the provenance claim a third party would rely on to verify what they installed is one they cannot reproduce. That is a supply-chain honesty defect, not a build annoyance.
CI is not red for it, and that is the trap
ruby_package_e2e::the_shipped_package_is_the_artifact_that_was_recordedre-packs the checked-in bytes and compares digests. Nothing rebuilds the wasm. So the gate passes, permanently, while the reproducibility claim beside it is false — the same shape as a green check over an untrue property that this project has hit repeatedly today.Why it was not fixed in
a5f91c2Applying
--strip-name-sectionto the Ruby guest movespackage_digestandextraction_identity. Pertests/packages/ruby.digest's own discipline that is a package version bump, a re-record, and release notes — not a build-script edit, and not something to leave sitting uncommitted in a tree whose purpose that hour was unblocking a red CI.Doing it badly would have been worse than leaving it measured and named.
What closing it needs
--strip-name-sectionincrates/guest/ruby/build.sh, matching whatcrates/guest/example/build.shnow does — one implementation, already inplugin-host.extractor.wasm; bump the package version (0.2.0 → 0.3.0) because the identity moves.tests/packages/ruby.digestand theWASM_ARTIFACTSrow.ClaimTableand to the e2e's install-by-digest path.The general form, worth considering
Any guest built from
crates/guestinherits this, because the cause is the path dependency, not the language. A third-party author following our own SDK will ship an irreproducible artifact unless the strip step is part of the documented build. That belongs in_prdoc/guides/80-package-authoring.mdas a requirement, not a footnote — the SDK is the authoring path the whole "every language ships as a plugin" direction rests on.Related
a5f91c2(the example guest, fixed and proven from three locations). #84 (which required, and got, exactly this property oftree-sitter-ruby.wasm— "two independent build dirs must produce byte-identical output" — so the standard already exists in this epic and the guest simply did not meet it).