cap-audit: allow supplying vmlinux.h for reproducible builds - #81
cap-audit: allow supplying vmlinux.h for reproducible builds#81daandemeyer wants to merge 1 commit into
Conversation
|
With my Reproducible Builds SIG-hat on, I tested |
|
Output from Details--- a/usr/src/debug/libcap-ng-0.9.3-1.fc44.x86_64/utils/cap-audit/cap_audit.skel.h 2026-07-07 09:16:59.890714631 +0000
+++ b/usr/src/debug/libcap-ng-0.9.3-1.fc44.x86_64/utils/cap-audit/cap_audit.skel.h 2026-07-07 09:16:59.942715141 +0000
@@ -272,7 +272,7 @@
{
static const char data[] __attribute__((__aligned__(8))) = "\
\x7f\x45\x4c\x46\x02\x01\x01\0\0\0\0\0\0\0\0\0\x01\0\xf7\0\x01\0\0\0\0\0\0\0\0\
-\0\0\0\0\0\0\0\0\0\0\0\x40\x9c\x0d\0\0\0\0\0\0\0\0\0\x40\0\0\0\0\0\x40\0\x34\0\
+\0\0\0\0\0\0\0\0\0\0\0\x68\x2e\x0d\0\0\0\0\0\0\0\0\0\x40\0\0\0\0\0\x40\0\x34\0\
\x01\0\xbf\x17\0\0\0\0\0\0\x79\x76\x68\0\0\0\0\0\x79\x79\x60\0\0\0\0\0\x79\x78\
\x58\0\0\0\0\0\xb7\x01\0\0\0\0\0\0\x7b\x1a\xd8\xff\0\0\0\0\x7b\x1a\xd0\xff\0\0\
\0\0\x7b\x1a\xc8\xff\0\0\0\0\x7b\x1a\xc0\xff\0\0\0\0\x7b\x1a\xb8\xff\0\0\0\0\
@@ -301,7 +301,7 @@
\x01\0\0\xf8\xff\xff\xff\xb4\x02\0\0\x08\0\0\0\x85\0\0\0\x71\0\0\0\x79\xa1\xf8\
\xff\0\0\0\0\x63\x1a\xb8\xff\0\0\0\0\xbf\x71\0\0\0\0\0\0\x18\x02\0\0\0\0\0\0\0\
\0\0\0\0\0\0\0\xb7\x03\0\0\0\x01\0\0\x85\0\0\0\x1b\0\0\0\x63\x8a\xdc\xff\0\0\0\
-\0\x7b\x0a\xd0\xff\0\0\0\0\x15\x06\x09\0\0\0\0\0\xb7\x01\0\0\x18\0\0\0\x0f\x16\
+\0\x7b\x0a\xd0\xff\0\0\0\0\x15\x06\x09\0\0\0\0\0\xb7\x01\0\0\x10\0\0\0\x0f\x16\
\0\0\0\0\0\0\xbf\xa1\0\0\0\0\0\0\x07\x01\0\0\xe0\xff\xff\xff\xb4\x02\0\0\x04\0\
\0\0\xbf\x63\0\0\0\0\0\0\x85\0\0\0\x71\0\0\0\x61\xa1\xe0\xff\0\0\0\0\x63\x1a\
\xd8\xff\0\0\0\0\x85\0\0\0\x0e\0\0\0\x7b\x0a\xe0\xff\0\0\0\0\xbf\xa2\0\0\0\0\0\
@@ -355,7 +355,7 @@
\xb4\x02\0\0\x08\0\0\0\x85\0\0\0\x71\0\0\0\x79\xa1\xf8\xff\0\0\0\0\x63\x1a\xb8\
\xff\0\0\0\0\xbf\x71\0\0\0\0\0\0\x18\x02\0\0\0\0\0\0\0\0\0\0\0\0\0\0\xb7\x03\0\
\0\0\x01\0\0\x85\0\0\0\x1b\0\0\0\xb4\x01\0\0\0\0\0\0\x63\x1a\xdc\xff\0\0\0\0\
-\x7b\x0a\xd0\xff\0\0\0\0\x15\x06\x09\0\0\0\0\0\xb7\x01\0\0\x18\0\0\0\x0f\x16\0\
+\x7b\x0a\xd0\xff\0\0\0\0\x15\x06\x09\0\0\0\0\0\xb7\x01\0\0\x10\0\0\0\x0f\x16\0\
\0\0\0\0\0\xbf\xa1\0\0\0\0\0\0\x07\x01\0\0\xe0\xff\xff\xff\xb4\x02\0\0\x04\0\0\
\0\xbf\x63\0\0\0\0\0\0\x85\0\0\0\x71\0\0\0\x61\xa1\xe0\xff\0\0\0\0\x63\x1a\xd8\
\xff\0\0\0\0\x85\0\0\0\x0e\0\0\0\x7b\x0a\xe0\xff\0\0\0\0\xbf\xa2\0\0\0\0\0\0\
@@ -403,7 +403,7 @@
\x02\0\0\x08\0\0\0\x85\0\0\0\x71\0\0\0\x79\xa1\xf8\xff\0\0\0\0\x63\x1a\xb8\xff\
\0\0\0\0\xbf\x71\0\0\0\0\0\0\x18\x02\0\0\0\0\0\0\0\0\0\0\0\0\0\0\xb7\x03\0\0\0\
\x01\0\0\x85\0\0\0\x1b\0\0\0\xb4\x01\0\0\0\0\0\0\x63\x1a\xdc\xff\0\0\0\0\x7b\
-\x0a\xd0\xff\0\0\0\0\x15\x06\x09\0\0\0\0\0\xb7\x01\0\0\x18\0\0\0\x0f\x16\0\0\0\
+\x0a\xd0\xff\0\0\0\0\x15\x06\x09\0\0\0\0\0\xb7\x01\0\0\x10\0\0\0\x0f\x16\0\0\0\
\0\0\0\xbf\xa1\0\0\0\0\0\0\x07\x01\0\0\xe0\xff\xff\xff\xb4\x02\0\0\x04\0\0\0\
\xbf\x63\0\0\0\0\0\0\x85\0\0\0\x71\0\0\0\x61\xa1\xe0\xff\0\0\0\0\x63\x1a\xd8\
\xff\0\0\0\0\x85\0\0\0\x0e\0\0\0\x7b\x0a\xe0\xff\0\0\0\0\xbf\xa2\0\0\0\0\0\0\
@@ -480,7 +480,7 @@
\0\0\0\x01\0\0\0\x55\0\x01\0\0\0\0\0\x05\0\x07\0\0\0\0\0\x71\x01\0\0\0\0\0\0\
\x16\x01\x05\0\0\0\0\0\xbf\xa2\0\0\0\0\0\0\x07\x02\0\0\xf0\xff\xff\xff\x18\x01\
\0\0\0\0\0\0\0\0\0\0\0\0\0\0\x85\0\0\0\x03\0\0\0\xb4\0\0\0\0\0\0\0\x95\0\0\0\0\
-\0\0\0\x61\x12\x0c\0\0\0\0\0\x63\x2a\xfc\xff\0\0\0\0\x61\x11\x14\0\0\0\0\0\x63\
+\0\0\0\x61\x12\x18\0\0\0\0\0\x63\x2a\xfc\xff\0\0\0\0\x61\x11\x2c\0\0\0\0\0\x63\
\x1a\xf8\xff\0\0\0\0\xbf\xa2\0\0\0\0\0\0\x07\x02\0\0\xfc\xff\xff\xff\x18\x01\0\
\0\0\0\0\0\0\0\0\0\0\0\0\0\x85\0\0\0\x01\0\0\0\x15\0\x0a\0\0\0\0\0\x71\x01\0\0\
\0\0\0\0\x73\x1a\xf7\xff\0\0\0\0\xbf\xa2\0\0\0\0\0\0\x07\x02\0\0\xf8\xff\xff\
@@ -491,7 +491,7 @@
\xff\xff\xff\x18\x01\0\0\0\0\0\0\0\0\0\0\0\0\0\0\x85\0\0\0\x01\0\0\0\x15\0\x08\
\0\0\0\0\0\xbf\xa2\0\0\0\0\0\0\x07\x02\0\0\xfc\xff\xff\xff\xbf\xa3\0\0\0\0\0\0\
\x07\x03\0\0\xfb\xff\xff\xff\x18\x01\0\0\0\0\0\0\0\0\0\0\0\0\0\0\xb7\x04\0\0\0\
-\0\0\0\x85\0\0\0\x02\0\0\0\xb4\0\0\0\0\0\0\0\x95\0\0\0\0\0\0\0\x61\x11\x0c\0\0\
+\0\0\0\x85\0\0\0\x02\0\0\0\xb4\0\0\0\0\0\0\0\x95\0\0\0\0\0\0\0\x61\x11\x18\0\0\
\0\0\0\x63\x1a\xfc\xff\0\0\0\0\xbf\xa2\0\0\0\0\0\0\x07\x02\0\0\xfc\xff\xff\xff\
\x18\x01\0\0\0\0\0\0\0\0\0\0\0\0\0\0\x85\0\0\0\x03\0\0\0\xb4\0\0\0\0\0\0\0\x95\
\0\0\0\0\0\0\0\x47\x50\x4c\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\
@@ -586,19002 +586,18593 @@
\x13\x37\x06\0\0\x16\x13\x01\x03\x25\x0b\x0b\x3a\x0b\x3b\x0b\0\0\x17\x15\x01\
\x27\x19\0\0\x18\x04\x01\x49\x13\x0b\x0b\x3a\x0b\x3b\x05\0\0\x19\x28\0\x03\x25\
\x1c\x0f\0\0\x1a\x04\x01\x49\x13\x03\x25\x0b\x0b\x3a\x0b\x3b\x05\0\0\x1b\x28\0\
-\x03\x25\x1c\x0d\0\0\x1c\x13\x01\x03\x26\x0b\x0b\x3a\x0b\x3b\x06\0\0\x1d\x0d\0\
-\x49\x13\x3a\x0b\x3b\x06\x38\x0b\0\0\x1e\x17\x01\x0b\x0b\x3a\x0b\x3b\x06\0\0\
-\x1f\x13\x01\x0b\x0b\x3a\x0b\x3b\x06\0\0\x20\x0d\0\x03\x25\x49\x13\x3a\x0b\x3b\
-\x06\x38\x0b\0\0\x21\x0d\0\x03\x26\x49\x13\x3a\x0b\x3b\x06\x38\x0b\0\0\x22\x04\
-\x01\x49\x13\x0b\x0b\x3a\x0b\x3b\x06\0\0\x23\x28\0\x03\x26\x1c\x0f\0\0\x24\x13\
-\x01\x03\x25\x0b\x0b\x3a\x0b\x3b\x06\0\0\x25\x16\0\x49\x13\x03\x25\x3a\x0b\x3b\
-\x06\0\0\x26\x13\x01\x0b\x0b\x3a\x0b\x3b\x05\0\0\x27\x0d\0\x03\x25\x49\x13\x3a\
-\x0b\x3b\x05\x38\x0b\0\0\x28\x13\x01\x03\x25\x0b\x0b\x3a\x0b\x3b\x05\0\0\x29\
-\x0d\0\x49\x13\x3a\x0b\x3b\x05\x38\x0b\0\0\x2a\x17\x01\x0b\x0b\x3a\x0b\x3b\x05\
...
+\0\0\x20\x04\0\0\0\0\0\0\x01\0\0\0\x18\0\0\0\x08\0\0\0\0\0\0\0\x18\0\0\0\0\0\0\
+\0";
*sz = sizeof(data) - 1;
return (const void *)data; |
By default cap-audit generates vmlinux.h from the running kernel's BTF data in /sys/kernel/btf/vmlinux, which makes the build depend on the host kernel and is therefore not reproducible. Add --with-vmlinux-h=auto|provided|generated and --with-vmlinux-h-path=PATH so a pre-generated vmlinux.h can be supplied at configure time instead. In provided mode the file is copied as-is and /sys is never read; generated mode keeps the existing behaviour.
6e7bae2 to
6d4364c
Compare
|
Thanks for the patch. I'm busy with some other things at the moment, but I will look at this soon. I tried making a generic vmlinux.h twice and had bad results. Maybe this one is better? |
|
Works great here, thanks @daandemeyer ! |
This doesn't actually provide the |
|
ok, audit and fapolicyd had their releases. I am now free to work on this project again. There is only one issue: The minimal fix is to make both rules depend on the configured Makefile: If you could, make that change and I'll merge it. |
By default cap-audit generates vmlinux.h from the running kernel's BTF data in /sys/kernel/btf/vmlinux, which makes the build depend on the host kernel and is therefore not reproducible.
Add --with-vmlinux-h=auto|provided|generated and --with-vmlinux-h-path=PATH so a pre-generated vmlinux.h can be supplied at configure time instead. In provided mode the file is copied as-is and /sys is never read; generated mode keeps the existing behaviour.