An environment for reproducible smart contract builds for deterministic outputs and auditability.
316
This repository provides Dockerized environments to produce reproducible and verifiable builds of Dusk smart contracts. Each version corresponds to a specific, locked build environment. This ensures identical outputs and allows for auditability.
Verifiable builds ensure that the same source code always produces the same output and that developers and auditors can verify that a smart contract corresponds to a specific build artifact.
This Dockerized approach locks down the build environment, including the Rust
toolchain and dependencies, ensuring deterministic outputs for wasm32 and
wasm64 targets.
To build the image for a specific version:
cd docker/0.1.0
docker build --platform linux/amd64 . -t dusknode/dusk-verifiable-builds:0.1.0
You can pull the prebuilt Docker image for a specific version from the container registry:
docker pull dusknode/dusk-verifiable-builds:0.1.0
To use the Docker image for building your smart contracts:
docker run --rm \
-v <path-to-contract-code>:/source \
-v <path-to-output-folder>:/target \
--mount type=volume,source=dusk_registry_cache,target=/root/.cargo/registry \
dusknode/dusk-verifiable-builds:0.1.0
<path-to-contract-code>: Path to your smart contract's project.<path-to-output-folder>: Path where you want to build artifacts.After running the container, all builds artifacts will be in
<path-to-output-folder>. Final reproducible outputs will be in
<path-to-output-folder>/final-output/wasm32 and
<path-to-output-folder>/final-output/wasm64, depending on the specified
target.
By default, the container runs cargo build with the following arguments:
--locked --color=always --release --target wasm32-unknown-unknownRUSTFLAGS set to -C link-args=-zstack-size=65536.To override the default --target argument, you can specify a different target:
docker run --rm \
-v <path-to-contract-code>:/source \
-v <path-to-output-folder>:/target \
--mount type=volume,source=dusk_registry_cache,target=/root/.cargo/registry \
dusknode/dusk-verifiable-builds:0.1.0
--target wasm64-unknown-unknown
To provide additional custom arguments, simply append them. For example:
docker run --rm \
-v <path-to-contract-code>:/source \
-v <path-to-output-folder>:/target \
--mount type=volume,source=dusk_registry_cache,target=/root/.cargo/registry \
dusknode/dusk-verifiable-builds:0.1.0
--manifest-path contracts/charlie/Cargo.toml
This will run:
`cargo build --locked --color=always --release --manifest-path contracts/charlie/Cargo.toml`
Each version of the Docker image corresponds to a reproducible build environment. To add a new version:
cp -r docker/0.1.0 docker/0.2.0
Update Dependencies. If the Rust toolchain, dependencies or other components
are updated, modify the setup-compiler.sh and Dockerfile where
applicable.
Test the build environment. Run the container and verify that it produces deterministic outputs for sample contracts.
Update the README by adding the necessary documentation.
Push the image to the registry:
docker build --platform linux/amd64 -t dusknode/dusk-verifiable-builds:0.2.0 ./docker/0.2.0
docker push dusknode/dusk-verifiable-builds:0.2.0
Each version is immutable. Once released, it should NOT be modified. For
example, version 0.1.0 will always correspond to the chosen Rust toolchain. If
an update is required, create a new version.
Content type
Image
Digest
sha256:405fb14cb…
Size
648.7 MB
Last updated
over 1 year ago
docker pull dusknode/dusk-verifiable-builds