Skip to content

cap-audit: allow supplying vmlinux.h for reproducible builds - #81

Open
daandemeyer wants to merge 1 commit into
stevegrubb:masterfrom
daandemeyer:push-rpkzrpootmpv
Open

cap-audit: allow supplying vmlinux.h for reproducible builds#81
daandemeyer wants to merge 1 commit into
stevegrubb:masterfrom
daandemeyer:push-rpkzrpootmpv

Conversation

@daandemeyer

Copy link
Copy Markdown

By default cap-audit generates vmlinux.h from the running kernel's BTF data in /sys/kernel/btf/vmlinux, which makes the build depend on the host kernel and is therefore not reproducible.

Add --with-vmlinux-h=auto|provided|generated and --with-vmlinux-h-path=PATH so a pre-generated vmlinux.h can be supplied at configure time instead. In provided mode the file is copied as-is and /sys is never read; generated mode keeps the existing behaviour.

@keszybz

keszybz commented Jul 7, 2026

Copy link
Copy Markdown

With my Reproducible Builds SIG-hat on, I tested libcap-ng-0.9.3-1.fc44. The koji build does not reproduce in the test environment, /usr/src/debug/libcap-ng-0.9.3-1.fc44.x86_64/utils/cap-audit/cap_audit.skel.h differs (attached below). So this PR would be very welcome. We could then tweak the rpm build to use vmlinux.h from kernel-devel and the package builds should become reproducible.

@keszybz

keszybz commented Jul 7, 2026

Copy link
Copy Markdown

Output from diff -u a/usr/src/debug/libcap-ng-0.9.3-1.fc44.x86_64/utils/cap-audit/cap_audit.skel.h b/usr/src/debug/libcap-ng-0.9.3-1.fc44.x86_64/utils/cap-audit/cap_audit.skel.h (a is orig, b is the build):

Details
--- a/usr/src/debug/libcap-ng-0.9.3-1.fc44.x86_64/utils/cap-audit/cap_audit.skel.h	2026-07-07 09:16:59.890714631 +0000
+++ b/usr/src/debug/libcap-ng-0.9.3-1.fc44.x86_64/utils/cap-audit/cap_audit.skel.h	2026-07-07 09:16:59.942715141 +0000
@@ -272,7 +272,7 @@
 {
 	static const char data[] __attribute__((__aligned__(8))) = "\
 \x7f\x45\x4c\x46\x02\x01\x01\0\0\0\0\0\0\0\0\0\x01\0\xf7\0\x01\0\0\0\0\0\0\0\0\
-\0\0\0\0\0\0\0\0\0\0\0\x40\x9c\x0d\0\0\0\0\0\0\0\0\0\x40\0\0\0\0\0\x40\0\x34\0\
+\0\0\0\0\0\0\0\0\0\0\0\x68\x2e\x0d\0\0\0\0\0\0\0\0\0\x40\0\0\0\0\0\x40\0\x34\0\
 \x01\0\xbf\x17\0\0\0\0\0\0\x79\x76\x68\0\0\0\0\0\x79\x79\x60\0\0\0\0\0\x79\x78\
 \x58\0\0\0\0\0\xb7\x01\0\0\0\0\0\0\x7b\x1a\xd8\xff\0\0\0\0\x7b\x1a\xd0\xff\0\0\
 \0\0\x7b\x1a\xc8\xff\0\0\0\0\x7b\x1a\xc0\xff\0\0\0\0\x7b\x1a\xb8\xff\0\0\0\0\
@@ -301,7 +301,7 @@
 \x01\0\0\xf8\xff\xff\xff\xb4\x02\0\0\x08\0\0\0\x85\0\0\0\x71\0\0\0\x79\xa1\xf8\
 \xff\0\0\0\0\x63\x1a\xb8\xff\0\0\0\0\xbf\x71\0\0\0\0\0\0\x18\x02\0\0\0\0\0\0\0\
 \0\0\0\0\0\0\0\xb7\x03\0\0\0\x01\0\0\x85\0\0\0\x1b\0\0\0\x63\x8a\xdc\xff\0\0\0\
-\0\x7b\x0a\xd0\xff\0\0\0\0\x15\x06\x09\0\0\0\0\0\xb7\x01\0\0\x18\0\0\0\x0f\x16\
+\0\x7b\x0a\xd0\xff\0\0\0\0\x15\x06\x09\0\0\0\0\0\xb7\x01\0\0\x10\0\0\0\x0f\x16\
 \0\0\0\0\0\0\xbf\xa1\0\0\0\0\0\0\x07\x01\0\0\xe0\xff\xff\xff\xb4\x02\0\0\x04\0\
 \0\0\xbf\x63\0\0\0\0\0\0\x85\0\0\0\x71\0\0\0\x61\xa1\xe0\xff\0\0\0\0\x63\x1a\
 \xd8\xff\0\0\0\0\x85\0\0\0\x0e\0\0\0\x7b\x0a\xe0\xff\0\0\0\0\xbf\xa2\0\0\0\0\0\
@@ -355,7 +355,7 @@
 \xb4\x02\0\0\x08\0\0\0\x85\0\0\0\x71\0\0\0\x79\xa1\xf8\xff\0\0\0\0\x63\x1a\xb8\
 \xff\0\0\0\0\xbf\x71\0\0\0\0\0\0\x18\x02\0\0\0\0\0\0\0\0\0\0\0\0\0\0\xb7\x03\0\
 \0\0\x01\0\0\x85\0\0\0\x1b\0\0\0\xb4\x01\0\0\0\0\0\0\x63\x1a\xdc\xff\0\0\0\0\
-\x7b\x0a\xd0\xff\0\0\0\0\x15\x06\x09\0\0\0\0\0\xb7\x01\0\0\x18\0\0\0\x0f\x16\0\
+\x7b\x0a\xd0\xff\0\0\0\0\x15\x06\x09\0\0\0\0\0\xb7\x01\0\0\x10\0\0\0\x0f\x16\0\
 \0\0\0\0\0\xbf\xa1\0\0\0\0\0\0\x07\x01\0\0\xe0\xff\xff\xff\xb4\x02\0\0\x04\0\0\
 \0\xbf\x63\0\0\0\0\0\0\x85\0\0\0\x71\0\0\0\x61\xa1\xe0\xff\0\0\0\0\x63\x1a\xd8\
 \xff\0\0\0\0\x85\0\0\0\x0e\0\0\0\x7b\x0a\xe0\xff\0\0\0\0\xbf\xa2\0\0\0\0\0\0\
@@ -403,7 +403,7 @@
 \x02\0\0\x08\0\0\0\x85\0\0\0\x71\0\0\0\x79\xa1\xf8\xff\0\0\0\0\x63\x1a\xb8\xff\
 \0\0\0\0\xbf\x71\0\0\0\0\0\0\x18\x02\0\0\0\0\0\0\0\0\0\0\0\0\0\0\xb7\x03\0\0\0\
 \x01\0\0\x85\0\0\0\x1b\0\0\0\xb4\x01\0\0\0\0\0\0\x63\x1a\xdc\xff\0\0\0\0\x7b\
-\x0a\xd0\xff\0\0\0\0\x15\x06\x09\0\0\0\0\0\xb7\x01\0\0\x18\0\0\0\x0f\x16\0\0\0\
+\x0a\xd0\xff\0\0\0\0\x15\x06\x09\0\0\0\0\0\xb7\x01\0\0\x10\0\0\0\x0f\x16\0\0\0\
 \0\0\0\xbf\xa1\0\0\0\0\0\0\x07\x01\0\0\xe0\xff\xff\xff\xb4\x02\0\0\x04\0\0\0\
 \xbf\x63\0\0\0\0\0\0\x85\0\0\0\x71\0\0\0\x61\xa1\xe0\xff\0\0\0\0\x63\x1a\xd8\
 \xff\0\0\0\0\x85\0\0\0\x0e\0\0\0\x7b\x0a\xe0\xff\0\0\0\0\xbf\xa2\0\0\0\0\0\0\
@@ -480,7 +480,7 @@
 \0\0\0\x01\0\0\0\x55\0\x01\0\0\0\0\0\x05\0\x07\0\0\0\0\0\x71\x01\0\0\0\0\0\0\
 \x16\x01\x05\0\0\0\0\0\xbf\xa2\0\0\0\0\0\0\x07\x02\0\0\xf0\xff\xff\xff\x18\x01\
 \0\0\0\0\0\0\0\0\0\0\0\0\0\0\x85\0\0\0\x03\0\0\0\xb4\0\0\0\0\0\0\0\x95\0\0\0\0\
-\0\0\0\x61\x12\x0c\0\0\0\0\0\x63\x2a\xfc\xff\0\0\0\0\x61\x11\x14\0\0\0\0\0\x63\
+\0\0\0\x61\x12\x18\0\0\0\0\0\x63\x2a\xfc\xff\0\0\0\0\x61\x11\x2c\0\0\0\0\0\x63\
 \x1a\xf8\xff\0\0\0\0\xbf\xa2\0\0\0\0\0\0\x07\x02\0\0\xfc\xff\xff\xff\x18\x01\0\
 \0\0\0\0\0\0\0\0\0\0\0\0\0\x85\0\0\0\x01\0\0\0\x15\0\x0a\0\0\0\0\0\x71\x01\0\0\
 \0\0\0\0\x73\x1a\xf7\xff\0\0\0\0\xbf\xa2\0\0\0\0\0\0\x07\x02\0\0\xf8\xff\xff\
@@ -491,7 +491,7 @@
 \xff\xff\xff\x18\x01\0\0\0\0\0\0\0\0\0\0\0\0\0\0\x85\0\0\0\x01\0\0\0\x15\0\x08\
 \0\0\0\0\0\xbf\xa2\0\0\0\0\0\0\x07\x02\0\0\xfc\xff\xff\xff\xbf\xa3\0\0\0\0\0\0\
 \x07\x03\0\0\xfb\xff\xff\xff\x18\x01\0\0\0\0\0\0\0\0\0\0\0\0\0\0\xb7\x04\0\0\0\
-\0\0\0\x85\0\0\0\x02\0\0\0\xb4\0\0\0\0\0\0\0\x95\0\0\0\0\0\0\0\x61\x11\x0c\0\0\
+\0\0\0\x85\0\0\0\x02\0\0\0\xb4\0\0\0\0\0\0\0\x95\0\0\0\0\0\0\0\x61\x11\x18\0\0\
 \0\0\0\x63\x1a\xfc\xff\0\0\0\0\xbf\xa2\0\0\0\0\0\0\x07\x02\0\0\xfc\xff\xff\xff\
 \x18\x01\0\0\0\0\0\0\0\0\0\0\0\0\0\0\x85\0\0\0\x03\0\0\0\xb4\0\0\0\0\0\0\0\x95\
 \0\0\0\0\0\0\0\x47\x50\x4c\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\
@@ -586,19002 +586,18593 @@
 \x13\x37\x06\0\0\x16\x13\x01\x03\x25\x0b\x0b\x3a\x0b\x3b\x0b\0\0\x17\x15\x01\
 \x27\x19\0\0\x18\x04\x01\x49\x13\x0b\x0b\x3a\x0b\x3b\x05\0\0\x19\x28\0\x03\x25\
 \x1c\x0f\0\0\x1a\x04\x01\x49\x13\x03\x25\x0b\x0b\x3a\x0b\x3b\x05\0\0\x1b\x28\0\
-\x03\x25\x1c\x0d\0\0\x1c\x13\x01\x03\x26\x0b\x0b\x3a\x0b\x3b\x06\0\0\x1d\x0d\0\
-\x49\x13\x3a\x0b\x3b\x06\x38\x0b\0\0\x1e\x17\x01\x0b\x0b\x3a\x0b\x3b\x06\0\0\
-\x1f\x13\x01\x0b\x0b\x3a\x0b\x3b\x06\0\0\x20\x0d\0\x03\x25\x49\x13\x3a\x0b\x3b\
-\x06\x38\x0b\0\0\x21\x0d\0\x03\x26\x49\x13\x3a\x0b\x3b\x06\x38\x0b\0\0\x22\x04\
-\x01\x49\x13\x0b\x0b\x3a\x0b\x3b\x06\0\0\x23\x28\0\x03\x26\x1c\x0f\0\0\x24\x13\
-\x01\x03\x25\x0b\x0b\x3a\x0b\x3b\x06\0\0\x25\x16\0\x49\x13\x03\x25\x3a\x0b\x3b\
-\x06\0\0\x26\x13\x01\x0b\x0b\x3a\x0b\x3b\x05\0\0\x27\x0d\0\x03\x25\x49\x13\x3a\
-\x0b\x3b\x05\x38\x0b\0\0\x28\x13\x01\x03\x25\x0b\x0b\x3a\x0b\x3b\x05\0\0\x29\
-\x0d\0\x49\x13\x3a\x0b\x3b\x05\x38\x0b\0\0\x2a\x17\x01\x0b\x0b\x3a\x0b\x3b\x05\
...
+\0\0\x20\x04\0\0\0\0\0\0\x01\0\0\0\x18\0\0\0\x08\0\0\0\0\0\0\0\x18\0\0\0\0\0\0\
+\0";
 
 	*sz = sizeof(data) - 1;
 	return (const void *)data;

Comment thread README.md Outdated
By default cap-audit generates vmlinux.h from the running kernel's BTF
data in /sys/kernel/btf/vmlinux, which makes the build depend on the host
kernel and is therefore not reproducible.

Add --with-vmlinux-h=auto|provided|generated and --with-vmlinux-h-path=PATH
so a pre-generated vmlinux.h can be supplied at configure time instead. In
provided mode the file is copied as-is and /sys is never read; generated
mode keeps the existing behaviour.
@stevegrubb

Copy link
Copy Markdown
Owner

Thanks for the patch. I'm busy with some other things at the moment, but I will look at this soon. I tried making a generic vmlinux.h twice and had bad results. Maybe this one is better?

@martinpitt

Copy link
Copy Markdown

Works great here, thanks @daandemeyer !

@keszybz

keszybz commented Jul 9, 2026

Copy link
Copy Markdown

I tried making a generic vmlinux.h twice and had bad results. Maybe this one is better?

This doesn't actually provide the vmlinux.h file, just consumes it. It has to be provided externally, and the idea is to get it from the kernel. This is what is done in https://src.fedoraproject.org/rpms/libcap-ng/pull-request/6.

@stevegrubb

stevegrubb commented Jul 31, 2026

Copy link
Copy Markdown
Owner

ok, audit and fapolicyd had their releases. I am now free to work on this project again. There is only one issue:
Reconfiguring an existing build directory must invalidate vmlinux.h. Currently, switching between generated and provided modes can silently retain the old header when it has a newer timestamp than the supplied file.

The minimal fix is to make both rules depend on the configured Makefile:

  if PROVIDED_VMLINUX_H
  vmlinux.h: $(VMLINUX_H_PATH) Makefile
  	$(AM_V_GEN)cp $< $@
  else
  vmlinux.h: Makefile
  	$(AM_V_GEN)$(BPFTOOL) btf dump \
  		file /sys/kernel/btf/vmlinux format c > $@
  endif

If you could, make that change and I'll merge it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants