Your message dated Tue, 15 Aug 2023 01:49:35 +0000 with message-id <e1qvjbf-006cte...@fasolo.debian.org> and subject line Bug#1009342: fixed in xfce4-panel-profiles 1.0.14-1 has caused the Debian Bug report #1009342, regarding xfce4-panel-profiles: reproducible builds: demo tarballs include user, group and file mode of build user to be marked as done.
This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact ow...@bugs.debian.org immediately.) -- 1009342: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1009342 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems
--- Begin Message ---Source: xfce4-panel-profiles Severity: normal Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: umask username X-Debbugs-Cc: reproducible-b...@lists.alioth.debian.org Several of the tarballs shipped in /usr/share/xfce4-panel-profiles/layouts/ embed the username, userid, groupname, groupid and umask of the build user: https://tests.reproducible-builds.org/debian/rb-pkg/unstable/amd64/diffoscope-results/xfce4-panel-profiles.html /usr/share/xfce4-panel-profiles/layouts/Cupertino.tar.bz2 -rw-r--r--···0·pbuilder1··(1111)·pbuilder1··(1111)·····4925·2021-02-21·22:44:32.000000·config.txt vs. -rw-rw-r--···0·pbuilder2··(2222)·pbuilder2··(2222)·····4925·2021-02-21·22:44:32.000000·config.txt The attached patch fixes this by passing arguments to tar in Makefile.in.in to ensure consistent user, group, uid, gid and file permissions in the generated tarballs. I have not verified that these changes work correctly in the resulting packages, only that it builds reproducibly; please be sure to verify before uploading. With this patch applied, xfce4-panel-profiles should become reproducible on tests.reproducible-builds.org! Thanks for maintaining xfce4-panel-profiles! live well, vagrantFrom 8cf9f8941c20e1527ac73829687c0ea5f2f4b608 Mon Sep 17 00:00:00 2001 From: Vagrant Cascadian <vagr...@reproducible-builds.org> Date: Tue, 12 Apr 2022 01:28:32 +0000 Subject: [PATCH 1/3] Makefile.in.in: Pass arguments to tar to make build reproducible regardless of user or umask. https://reproducible-builds.org/docs/archives/ --- Makefile.in.in | 2 ++ 1 file changed, 2 insertions(+) diff --git a/Makefile.in.in b/Makefile.in.in index a34e177..180da38 100644 --- a/Makefile.in.in +++ b/Makefile.in.in @@ -31,6 +31,8 @@ pot: ifeq ($(shell tar --help|grep -o sort=),sort=) TAROPTS := --sort=name --format ustar + TAROPTS += --owner=0 --group=0 --numeric-owner + TAROPTS += --mode=u=wrX,og= endif layouts: cd data/layouts/cupertino; tar $(TAROPTS) -cvjf "../Cupertino.tar.bz2" * -- 2.30.2signature.asc
Description: PGP signature
--- End Message ---
--- Begin Message ---Source: xfce4-panel-profiles Source-Version: 1.0.14-1 Done: Unit 193 <unit...@debian.org> We believe that the bug you reported is fixed in the latest version of xfce4-panel-profiles, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1009...@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Unit 193 <unit...@debian.org> (supplier of updated xfce4-panel-profiles package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmas...@ftp-master.debian.org) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA384 Format: 1.8 Date: Mon, 14 Aug 2023 21:14:12 -0400 Source: xfce4-panel-profiles Architecture: source Version: 1.0.14-1 Distribution: unstable Urgency: medium Maintainer: Debian Xfce Maintainers <debian-xfce@lists.debian.org> Changed-By: Unit 193 <unit...@debian.org> Closes: 1009342 1009812 Changes: xfce4-panel-profiles (1.0.14-1) unstable; urgency=medium . * Team upload. . [ Akbarkhon Variskhanov ] * Add upstream metadata and bump Standards-Version . [ Unit 193 ] * d/gbp.conf: Add for xfce-team standard layout. * New upstream version 1.0.14. - Makefile.in.in: Pass arguments to tar to make build reproducible regardless of user or umask. (Closes: #1009342) - Save and restore rc-files. (Closes: #1009812) * d/rules: Opt-out of trimmed changelogs, install NEWS as changelog. * d/control: Update 'homepage' field. * d/copyright: Update years. * Update Standards-Version to 4.6.2. Checksums-Sha1: 070761bf1acf803327dc3c78375f30da3f4f646b 2122 xfce4-panel-profiles_1.0.14-1.dsc 606c293ded2edd8a06a596480b7a2ae4c5a7b0d6 101521 xfce4-panel-profiles_1.0.14.orig.tar.bz2 c342a4cce0e1fa887439a844a19a753a3645b96a 8556 xfce4-panel-profiles_1.0.14-1.debian.tar.xz 8e6c4338f62640a99540601beafd9dd64b379604 7280 xfce4-panel-profiles_1.0.14-1_amd64.buildinfo Checksums-Sha256: 9cd2a6ddcf1a0a1bcb63aba30dedaca0c12e5b0ac91d1adf09186c736ff94f05 2122 xfce4-panel-profiles_1.0.14-1.dsc 6d08354e8c44d4b0370150809c1ed601d09c8b488b68986477260609a78be3f9 101521 xfce4-panel-profiles_1.0.14.orig.tar.bz2 de4bf4f174e487a014ac28682a6a59afb63b5d1c9a249ed026cd5443777ff3b8 8556 xfce4-panel-profiles_1.0.14-1.debian.tar.xz 5971290f483c702651bbbe19eecedf472737e015d676bd6cd3a00f68cef1c752 7280 xfce4-panel-profiles_1.0.14-1_amd64.buildinfo Files: 7989999942827213003b91e9539e63a0 2122 xfce optional xfce4-panel-profiles_1.0.14-1.dsc c1d6c291469fb251af853171607450a9 101521 xfce optional xfce4-panel-profiles_1.0.14.orig.tar.bz2 35a7b6c0dca88379d312ab765a111b85 8556 xfce optional xfce4-panel-profiles_1.0.14-1.debian.tar.xz 104f706124c2bc870322c627ff6f3803 7280 xfce optional xfce4-panel-profiles_1.0.14-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCQAdFiEEjbPlhoZdK0orGFpcUAHhsJqjdEsFAmTa09kACgkQUAHhsJqj dEvc/hAA2UF0bn7L14ghUS5iM6iKlP9xAFtktyYfWDubSRTCIZGbaRTJeK/rGZcJ lUgrK4q03O5xTqVxnhJI81BZtEiMJmCSOluYkRpuTmMndKwGisQIiHwru30QKHxZ zK1UjMpa7z78vU0NOLjZSk9V47URpmsAwL64ZMuEJ967yxL9Syz/bXMwYelw0BCg ZN2hfcurIH0slf8rWSyl6dLNLA5FHiMBPrMIlCWPIQ7W5QGRaRH9nz7c42KJTcA1 TnCslQh0IZa5BSpfD69VPqDGBoAIAObTbC8dOlLEL9qEfy36PupODGmu+3EB1ysF qlEXk4HrOIYF+GZfYDSD0vGyfVCxCpiqGkH3uyaYNUJVTilXsMaGr5eQLgesOCns WIFUL5+GRCsvB9W6EdCZ+e0RarGcXV3++EZXFNmARV8IqJJf++BQY2jlQATfZ1zu /D1fx0C6D1X1Ag3twOm0Xn+gKt1R0J782TsdzbWvJmWn0nqsX18LehzH3ppn1Znr A1ezsxQftH7P0ibSStlvVPFqKFvTjWCWijol2BgmMUR69VCcIR1sdt7Z/yeqocVE rfIx8KYEW3S13zV4nJ+nkwlR7gAZ7u4ZUzga8B1+CQmqqorjeaypn20neUtIxk1h /CjMHF7T6ZCSuv7iW9HDM354weGKiCT40Ex6un3I9YwdkOD5WCQ= =3F8/ -----END PGP SIGNATURE-----
--- End Message ---