# Best practice using PackageCompiler.jl (or something else!) for code obfuscation and extensibility

**URL:** <https://discourse.julialang.org/t/best-practice-using-packagecompiler-jl-or-something-else-for-code-obfuscation-and-extensibility/85806>\
**Category:** General Usage\
**Tags:** question, package-compiler\
**Created:** [August 16, 2022, 1:42am UTC](https://discourse.julialang.org/t/best-practice-using-packagecompiler-jl-or-something-else-for-code-obfuscation-and-extensibility/85806 "2022-08-16T01:42:54Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![pdetrempe](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/pdetrempe/32/38815_2.png) [@pdetrempe](https://discourse.julialang.org/u/pdetrempe)\
**Post date:** [August 16, 2022, 1:42am UTC](https://discourse.julialang.org/t/best-practice-using-packagecompiler-jl-or-something-else-for-code-obfuscation-and-extensibility/85806/1 "2022-08-16T01:42:54Z")

</div>

I want to use Julia for a new, _proprietary_, software package being developed at work, however, a couple of requirements are that the package be deliverable to customers without visible source code _and_ be extensible to allow custom types/functions/objects.

I was able to achieve this by using PackageCompiler.jl to build a relocatable sysimage (as a .dll), which allowed me to access my package’s structs/functions on another machine without being able to view the source.

I’m a noob when it comes to the pre-compilation stuff (and Julia generally), and just want to know if this is best practice? Right now I have to specify the sysimage at startup via the following and I’d like it if I could provide simple instructions to other users to be able to load up this sysimage into their chosen IDE (i.e. VSCode/Pluto/Jupyter)

```julia
$ julia --sysimage MyPackageSysimage.dll

julia> using .MyPackage

```

Thanks!

---

<div class="post-metadata">

**Author:** ![ffevotte](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/ffevotte/32/6587_2.png) [@ffevotte](https://discourse.julialang.org/u/ffevotte)\
**Post date:** [August 16, 2022, 7:22am UTC](https://discourse.julialang.org/t/best-practice-using-packagecompiler-jl-or-something-else-for-code-obfuscation-and-extensibility/85806/2 "2022-08-16T07:22:32Z")

</div>

As for the “obfuscation” part, the following paragraph from the PackageCompiler documentation comes to mind:

[https://julialang.github.io/PackageCompiler.jl/dev/apps.html#Reverse-engineering-the-compiled-app](https://julialang.github.io/PackageCompiler.jl/dev/apps.html#Reverse-engineering-the-compiled-app)

However, IIUC part of the above might be alleviated by new 1.8 features (but I’m not sure exactly how these are meant to be used…)

> <https://github.com/JuliaLang/julia/pull/42513>
>
> This is a fairly common request to make it possible to deploy lighter-weight sys…tem images, that also hide IP to some extent (though the IR is still present; I will have another PR for that).

> <https://github.com/JuliaLang/julia/pull/42925>
>
> This is another step towards being able to ship more traditional binaries that d…on't contain compiler data, for both smaller system images and more hidden program code.

---

<div class="post-metadata">

**Author:** ![pdetrempe](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/pdetrempe/32/38815_2.png) [@pdetrempe](https://discourse.julialang.org/u/pdetrempe)\
**Post date:** [August 16, 2022, 3:08pm UTC](https://discourse.julialang.org/t/best-practice-using-packagecompiler-jl-or-something-else-for-code-obfuscation-and-extensibility/85806/3 "2022-08-16T15:08:45Z")

</div>

Thanks for the response! Regarding the [reverse engineering of PackageCompiler compiled apps](https://julialang.github.io/PackageCompiler.jl/dev/apps.html#Reverse-engineering-the-compiled-app), I’m not worried about the user seeing the build machine paths or the function/type names. Python is also being considered, and it looks like it may have similar [reverse engineering issues](https://wiki.python.org/moin/Asking%20for%20Help/How%20do%20you%20protect%20Python%20source%20code%3F). The lowered code is more concerning, but if it would require _significant_ effort to recreate the whole package source from the delivered sysimage/app, then that meets our requirements. Do you know if it would be straightforward for someone to use Julia’s metaprogramming (or other) capabilities to back out the source from the metadata available from macros like `@code_lowered` and `@code_warntype`? Am I understanding correctly that the `--strip-ir` and `--strip-metadata` remove this capability from the julia sysimage compiled with those options?

Thanks for the links to the `--strip-ir` and `--strip-metadata` options. I think that’ll address some concerns. Looks like I can pass those arguments to PackageCompiler.jl via the [`sysimage_build_args` option](https://julialang.github.io/PackageCompiler.jl/dev/refs.html#References). I found [this comment in another thread](https://discourse.julialang.org/t/obfuscate-julia-module-and-import-it-python/73026/10) helpful as well.
