Skip to content

Consider not stripping the symbol table on binaries #506

Description

@amoeba

I realized while running govulncheck in binary mode, if the binary is stripped of its symbol table, govulncheck falls back to reporting vulns based entirely on the version of modules rather than based on what's being called from that module. It's reasonable to think that users may run govulncheck in binary mode as part of their security auditing process.

For example, when I build as we do now, with -s (strip symbols) and -w (strip debug info) set,

go build -ldflags="-s -w" -o dbc ./cmd/dbc
# I get four vulns

But if I build without setting -s, I get none:

go build -ldflags="-w" -o dbc ./cmd/dbc
# no vulns

Basically, including symbols makes govulncheck binary analysis smarter. I had an agent rebuild all of our binaries without -s and the binary size impact isn't nothing but it's not a huge deal:

 ┌───────────────┬───────────────┬──────────────┬─────────┐
 │ Target        │ Binary MiB¹   │ Archive MiB¹ │ Growth² │
 ├───────────────┼───────────────┼──────────────┼─────────┤
 │ Linux amd64   │ 10.23 → 11.02 │ 4.08 → 4.25  │ 4.0%    │
 ├───────────────┼───────────────┼──────────────┼─────────┤
 │ Linux arm64   │ 9.50 → 10.29  │ 3.68 → 3.83  │ 4.3%    │
 ├───────────────┼───────────────┼──────────────┼─────────┤
 │ macOS amd64   │ 10.42 → 11.13 │ 4.13 → 4.27  │ 3.5%    │
 ├───────────────┼───────────────┼──────────────┼─────────┤
 │ macOS arm64   │ 9.68 → 10.38  │ 3.80 → 3.94  │ 3.9%    │
 ├───────────────┼───────────────┼──────────────┼─────────┤
 │ Windows amd64 │ 10.61 → 11.35 │ 4.20 → 4.34  │ 3.5%    │
 └───────────────┴───────────────┴──────────────┴─────────┘

I think doing this would be a net positive.

PS: This came up recently on apache/arrow-adbc#4752.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions