Bug#1009196: [Dev-luatex] Bug#1009196: texlive-binaries: Reproducible content of .fmt files

2022-05-04 Thread Roland Clobus
On 04/05/2022 15:16, luigi scarso wrote: On Wed, May 4, 2022 at 3:09 PM Roland Clobus On 19/04/2022 09:52, luigi scarso wrote: Thank you very much for your patch, I will check it this weekend. Have you found the time already to review my patch? [1] Yes, Hans and I are discussing. If

Bug#1009196: [Dev-luatex] Bug#1009196: texlive-binaries: Reproducible content of .fmt files

2022-05-04 Thread luigi scarso
On Wed, May 4, 2022 at 3:09 PM Roland Clobus wrote: > Hello luigi, list, > > > On 19/04/2022 09:52, luigi scarso wrote: >> Thank you very much for your > patch, I will check it this weekend. > Have you found the time already to review my patch? [1] > Yes, Hans and I are discussing. If possible,

Bug#1009196: [Dev-luatex] Bug#1009196: texlive-binaries: Reproducible content of .fmt files

2022-05-04 Thread Roland Clobus
Hello luigi, list, On 19/04/2022 09:52, luigi scarso wrote: >> Thank you very much for your patch, I will check it this weekend. Have you found the time already to review my patch? [1] With kind regards, Roland Clobus [1] https://mailman.ntg.nl/pipermail/dev-luatex/2022-April/006659.html

Bug#1009196: [Dev-luatex] Bug#1009196: texlive-binaries: Reproducible content of .fmt files

2022-04-19 Thread Roland Clobus
Hello list, On 19/04/2022 09:52, luigi scarso wrote: Thank you very much for your patch, I will check it this weekend. Another note: While preparing for a generic change request for Lua, I found a mail by Hans Hagen [1], stating that all cases have been found in luatex. Sorting the table

Bug#1009196: [Dev-luatex] Bug#1009196: texlive-binaries: Reproducible content of .fmt files

2022-04-19 Thread luigi scarso
On Tue, Apr 19, 2022 at 9:16 AM Roland Clobus wrote: > Hello list, > > On 12/04/2022 08:44, Roland Clobus wrote: > > I'll follow-up soon with an updated patch. > > As discussed, I've updated the patch. > > For Lua-based TeX binaries, only when FORCE_SOURCE_DATE=1 and > SOURCE_DATE_EPOCH are set,

Bug#1009196: [Dev-luatex] Bug#1009196: texlive-binaries: Reproducible content of .fmt files

2022-04-19 Thread Roland Clobus
Hello list, On 12/04/2022 08:44, Roland Clobus wrote: I'll follow-up soon with an updated patch. As discussed, I've updated the patch. For Lua-based TeX binaries, only when FORCE_SOURCE_DATE=1 and SOURCE_DATE_EPOCH are set, this will initialise the Lua seed to the value of

Bug#1009196: [Dev-luatex] Bug#1009196: texlive-binaries: Reproducible content of .fmt files

2022-04-11 Thread Hans Hagen
On 4/11/2022 4:34 PM, Roland Clobus wrote: The texlive-binaries in Debian contain an embedded copy of Lua 5.3. The Lua 5.4 version of luai_makeseed is more complex, see [2]. I'll write a feature request for Lua later, that is out-of-scope for this scenario. fyi: it is unlikely that luatex will

Bug#1009196: [Dev-luatex] Bug#1009196: texlive-binaries: Reproducible content of .fmt files

2022-04-11 Thread Roland Clobus
Hello Hans, Norbert, Thanks for your answers. On 11/04/2022 13:01, Norbert Preining wrote: it actually defeats one of the security properties of lua (which was explicitly introduced at some point: make sure that hashes have random order each run so that it's harder to retrieve sensitive data

Bug#1009196: [Dev-luatex] Bug#1009196: texlive-binaries: Reproducible content of .fmt files

2022-04-11 Thread Norbert Preining
> not only fmt, every output could suffer from the same problem if it If the final output (pdf) has traces of that, it might be of concern. But for now the discussion is about the fmt dump, which is independent of these items. Best regards Norbert -- PREINING Norbert

Bug#1009196: [Dev-luatex] Bug#1009196: texlive-binaries: Reproducible content of .fmt files

2022-04-11 Thread luigi scarso
On Mon, Apr 11, 2022 at 1:01 PM Norbert Preining wrote: > Hi Hans, hi Roland, > > thanks for your answer. > > > it actually defeats one of the security properties of lua (which was > > explicitly introduced at some point: make sure that hashes have random > order > > each run so that it's harder

Bug#1009196: [Dev-luatex] Bug#1009196: texlive-binaries: Reproducible content of .fmt files

2022-04-11 Thread Norbert Preining
Hi Hans, hi Roland, thanks for your answer. > it actually defeats one of the security properties of lua (which was > explicitly introduced at some point: make sure that hashes have random order > each run so that it's harder to retrieve sensitive data from mem) Well, that is a good point to

Bug#1009196: [Dev-luatex] Bug#1009196: texlive-binaries: Reproducible content of .fmt files

2022-04-11 Thread Hans Hagen
On 4/11/2022 6:56 AM, Norbert Preining wrote: Hi Luigi, hi all luatex devs, here at Debian we got a bug report about reproducability of luatex format dumps. It contains a patch to make the hyphenation exception list sorted. (I attach the patch) Could you please take a look whether this is

Bug#1009196: texlive-binaries: Reproducible content of .fmt files

2022-04-10 Thread Norbert Preining
Hi Luigi, hi all luatex devs, here at Debian we got a bug report about reproducability of luatex format dumps. It contains a patch to make the hyphenation exception list sorted. (I attach the patch) Could you please take a look whether this is still relevant for the latest release of luatex.

Bug#1009196: texlive-binaries: Reproducible content of .fmt files

2022-04-08 Thread Roland Clobus
Package: texlive-binaries Version: 2021.20210626.59705-1 Severity: wishlist Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: randomness X-Debbugs-Cc: reproducible-b...@lists.alioth.debian.org Hello maintainers of texlive-binaries, While working on the “reproducible builds”