4 ms·
If you wish, you can ensure that the compilation step in particular doesn't need/use the network, by first manually fetching the dependencies: someproject% g
by nishs 4y ago
If you wish, you can ensure that the compilation step in particular doesn't need/use the network, by first manually fetching the dependencies:
someproject% go get ./... # or 'go mod download'
Next disable network access for the go command, or for the whole system.
Then compile:
someproject% go build
- jeroenhd 4y agoThat's true. However, because of the design of go tooling, you still call the same command line method to get the tool to compile your code. This leads to the compiler having access to the internet and possibly exercising its access. In a perfect world of separated concerns the compiler binary wouldn't have any networking code at all, necessitating a go-get before calling go-build. I understand why the Golang team decided to go with this approach, but it does have side effects that people coming from different tooling (say, C) wouldn't expect.
- mindslight 4y agoSounds like a great reason to adopt Nix or the like! Run each tool in a sandbox appropriate to what it's supposed to do, and store the entirety of the inputs and outputs so they can be audited if the need arises. Nix got there via reproducibility, but it's exactly what's needed to mitigate compilers with surveillance features or other backdoors.