arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.18180cs.SEcs.CR

可复现性还不够:去中心化构建包生态系统中的制品可验证性

Reproducibility is Not Enough: Artifact Verifiability in Decentralized-Build Package Ecosystems

Oreofe Solarin, Kelechi Kalu, James C. Davis, Paschal Amusuo

首次发表
浏览论文内容

中文总结 AI 辅助

本文针对四个去中心化构建包生态系统,提出基于注册表元数据的独立验证器模型,发现可验证性受元数据缺失等因素限制,提出需补充元数据缺口以实现包注册表规模的实用制品验证。

中文摘要 AI 辅助

可复现且可验证的构建通过让独立方检测到由被入侵的构建或发布管道生成的制品,从而提高了对分布式软件制品的信任。然而,制品验证所需的不仅仅是确定性构建:验证者还必须恢复生成该制品的源代码状态、构建环境、依赖项和构建指令。去中心化构建生态系统使这一点变得困难,因为制品是通过异构工具、维护者控制的工作流以及碎片化的元数据生成的。因此,目前尚不清楚这些生态系统中的制品能够被独立验证的频率。本文研究了四个流行的去中心化构建包生态系统中的制品可验证性。我们定义了一个仅依赖于可从注册表派生的元数据的独立验证器模型,以及一个具有分层等价级别的制品比较模型。我们在Artifact Verification Pipeline中实现了这些模型,并使用它来测量目标生态系统中的制品可验证性。我们的结果表明,除了构建确定性之外,可验证性还受到缺失的源代码和构建元数据、隐式发布转换以及非常规构建实践的限制。来源证明和嵌入的VCS元数据有助于验证,但它们并未提供完整的重建规范。这些发现确定了具体的元数据缺口,以及使制品验证在包注册表规模上切实可行所需的生态系统层面的变更。

英文摘要

Reproducible and verifiable builds increase trust in distributed software artifacts by enabling independent parties to detect artifacts produced by compromised build or release pipelines. However, artifact verification requires more than deterministic builds: a verifier must also recover the source state, build environment, dependencies, and build instructions that produced the artifact. Decentralized-build ecosystems make this difficult because artifacts are produced through heterogeneous tools, maintainer-controlled workflows, and fragmented metadata. As a result, it remains unclear how often artifacts in these ecosystems can be independently verified. This paper studies artifact verifiability across four popular decentralized-build package ecosystems. We define an independent verifier model that relies only on registry-derivable metadata and an artifact comparison model with tiered equivalence levels. We implement these models in an Artifact Verification Pipeline and use it to measure artifact verifiability across the target ecosystems. Our results show that, beyond build determinism, verifiability is limited by missing source and build metadata, implicit release transformations, and unconventional build practices. Provenance attestations and embedded VCS metadata improve verification, but they do not provide complete rebuild specifications. These findings identify concrete metadata gaps and ecosystem-level changes needed to make artifact verification practical at package-registry scale.

补充信息

↑