Re: Upstream Tarball Signature Files

2017-08-12 Thread Paul Hardy
Russ, On Sat, Aug 12, 2017 at 7:59 PM, Russ Allbery wrote: > Paul Hardy writes: > > > Osamu: I did not mean just accept one format--I meant accept both ".asc" > > and ".sig" files for ".changes", ".dsc", and uscan files. I suppose all > > three manuals you mentioned could be modified to docume

Re: Upstream Tarball Signature Files

2017-08-12 Thread Russ Allbery
Paul Hardy writes: > Osamu: I did not mean just accept one format--I meant accept both ".asc" > and ".sig" files for ".changes", ".dsc", and uscan files. I suppose all > three manuals you mentioned could be modified to document this. > I had not brought this up until the latest lintian check on

Bug#844431: Revised patch: seeking seconds

2017-08-12 Thread Ximin Luo
Sean Whitton: > [..] > > Here is an updated patch addressing these. I reworded it to use > 'recommended' and changed the tone to better suit policy. > > Thank you Ximin, Russ and Johannes! > >> "precisification" -> "more precise version" > > Our definition is not actually a /version/ of the >

Bug#844431: Revised patch: seeking seconds

2017-08-12 Thread Sean Whitton
Hello, On Sat, Aug 12 2017, Russ Allbery wrote: > I suspect we want to say build and host architecture for right now. > (Maybe we can later aspire to making the build architecture not > matter.) On Sat, Aug 12 2017, Ximin Luo wrote: > To echo dkg and others' comments, it would be nice if we cou

Re: Upstream Tarball Signature Files

2017-08-12 Thread Paul Hardy
On Tue, Aug 8, 2017 at 5:13 AM, Osamu Aoki wrote: > Hi, > > On Tue, Aug 08, 2017 at 10:48:08AM +0200, Guillem Jover wrote: > ... > > On Mon, 2017-08-07 at 20:26:41 -0700, Paul Hardy wrote: > > > Also, where signature files are desired, I think it would be > beneficial to > > > also accept binary

Bug#844431: Reproducibility in Policy

2017-08-12 Thread Holger Levsen
On Fri, Aug 11, 2017 at 08:35:47PM -0700, Russ Allbery wrote: > Daniel Kahn Gillmor writes: > > I don't like the idea of hard-coding a fixed build path requirement into > > debian policy. I don't *like* it neither but I think it's the sensible thing to do now. > > We're over 80% with variable b

Bug#587279: Clarify restrictions on main to non-free dependencies

2017-08-12 Thread Russ Allbery
Control: tags -1 pending Sean Whitton writes: > On Sun, Jun 25, 2017 at 02:43:36PM -0700, Russ Allbery wrote: >> diff --git a/policy.xml b/policy.xml >> index 7ba5fc0..daf4c3c 100644 >> --- a/policy.xml >> +++ b/policy.xml >> @@ -595,7 +595,9 @@ >>Build-Depends, >>

Processed: Re: Bug#587279: Clarify restrictions on main to non-free dependencies

2017-08-12 Thread Debian Bug Tracking System
Processing control commands: > tags -1 pending Bug #587279 [debian-policy] Clarify restrictions on main to non-free dependencies Bug #616462 [debian-policy] debian-policy: clarify wording of parenthetical in section 2.2.1 Added tag(s) pending. Added tag(s) pending. -- 587279: https://bugs.debi

Processed: user debian-pol...@packages.debian.org, limit package to debian-policy ...

2017-08-12 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > user debian-pol...@packages.debian.org Setting user to debian-pol...@packages.debian.org (was r...@debian.org). > limit package debian-policy Limiting to bugs with field 'package' containing at least one of 'debian-policy' Limit currently set to '

Bug#844431: Reproducibility in Policy

2017-08-12 Thread Russ Allbery
Bill Allombert writes: > This require policy to define the build environment and build > instruction much more precisely than it does now, which does not seems > to be practical. Unless maybe if a reference implementation is provided. I don't see anything in this proposal that would require a mo

Bug#844431: Revised patch: seeking seconds

2017-08-12 Thread Russ Allbery
Johannes Schauer writes: > Policy §4.9 defines "build architecture" in the context of > dpkg-architecture already and I think what you mean here is either "host > architecture" or at least "build and host architecture" or you need to > mention that you are only talking about native builds where b

Bug#844431: Revised patch: seeking seconds

2017-08-12 Thread Johannes Schauer
Hi, Quoting Sean Whitton (2017-08-13 03:23:14) > +Reproducibility > +--- > + > +Packages should build reproducibly, which for the purposes of this > +document [#]_ means that given > + > +- a version of a source package unpacked at a given path; > +- a set of versions of installed buil

Bug#844431: Revised patch: seeking seconds

2017-08-12 Thread Holger Levsen
On Sat, Aug 12, 2017 at 01:18:23PM -0700, Russ Allbery wrote: > > +Packages are encouraged to produce bit-for-bit identical binary packages > > even > > +if most environment variables and build paths are varied. This is > > technically > > +more difficult at the time of writing, but it is intende

Bug#844431: Revised patch: seeking seconds

2017-08-12 Thread Russ Allbery
Ximin Luo writes: > To echo dkg and others' comments, it would be nice if we could add here: > +Packages are encouraged to produce bit-for-bit identical binary packages even > +if most environment variables and build paths are varied. This is technically > +more difficult at the time of writing,

Bug#844431: Revised patch: seeking seconds

2017-08-12 Thread Ximin Luo
Sean Whitton: > diff --git a/policy/ch-source.rst b/policy/ch-source.rst > index 127b125..cc4b020 100644 > --- a/policy/ch-source.rst > +++ b/policy/ch-source.rst > @@ -661,6 +661,22 @@ particularly complex or unintuitive source layout or > build system (for > example, a package that builds the s

Bug#844431: Revised patch: seeking seconds

2017-08-12 Thread Russ Allbery
Sean Whitton writes: > diff --git a/policy/ch-source.rst b/policy/ch-source.rst > index 127b125..cc4b020 100644 > --- a/policy/ch-source.rst > +++ b/policy/ch-source.rst > @@ -661,6 +661,22 @@ particularly complex or unintuitive source layout or > build system (for > example, a package that bui

Bug#844431: Revised patch: seeking seconds

2017-08-12 Thread Ondrej Novy
Hi, 2017-08-12 14:23 GMT-04:00 Sean Whitton : > control: tag -1 +patch > > This patch incorporates the feedback given on the proposal I sent > yesterday, both in this bug and in person from Russ and Holger (thank > you to all). > seconded, thanks for working on this. -- Best regards Ondřej No

Bug#844431: Revised patch: seeking seconds

2017-08-12 Thread Holger Levsen
On Sat, Aug 12, 2017 at 11:23:14AM -0700, Sean Whitton wrote: > I am seeking formal seconds for this patch, from any DD. > > In particular: > > - for now, we only require reproducibility when the set of environment > variable values set is exactly the same > > This is because > > - the re

Bug#844431: Revised patch: seeking seconds

2017-08-12 Thread Sean Whitton
control: tag -1 +patch This patch incorporates the feedback given on the proposal I sent yesterday, both in this bug and in person from Russ and Holger (thank you to all). I am seeking formal seconds for this patch, from any DD. In particular: - for now, we only require reproducibility when the

Processed: Revised patch: seeking seconds

2017-08-12 Thread Debian Bug Tracking System
Processing control commands: > tag -1 +patch Bug #844431 [debian-policy] debian-policy: Packages should be reproducible Added tag(s) patch. -- 844431: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=844431 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Processed: owner 844431

2017-08-12 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > owner 844431 ! Bug #844431 [debian-policy] debian-policy: Packages should be reproducible Owner recorded as Sean Whitton . > thanks Stopping processing here. Please contact me if you need assistance. -- 844431: https://bugs.debian.org/cgi-bin/bu

Bug#871534: debian-policy: Clarify whether mailing lists in Maintainers/Uploaders may be moderated

2017-08-12 Thread Bill Allombert
On Tue, Aug 08, 2017 at 08:06:46PM -0400, Chris Lamb wrote: > Hi Bill, > > > How do you define "moderated" ? > > I can't really, sorry. I guess getting a "Your message awaits moderator > approval" quasi-bounce… but that's not exactly right. If the list is moderated correctly, the message will g

Bug#844431: Reproducibility in Policy

2017-08-12 Thread Bill Allombert
On Fri, Aug 11, 2017 at 04:08:47PM -0700, Sean Whitton wrote: > control: user debian-pol...@packages.debian.org > control: usertag = normative proposal > > Hello, > > Proposal: > > This is what Holger and I think we should add to Policy, after > readability tweaks: > > Packages sh

Bug#844431: Reproducibility in Policy

2017-08-12 Thread Johannes Schauer
Hi, Quoting Russ Allbery (2017-08-12 09:57:44) > I think we need to add all environment variables starting with DEB_* to > the prerequisites. If you set DEB_BUILD_OPTIONS=nostrip or > DEB_BUILD_MAINT_OPTIONS=hardening=all, you'll definitely get a different > package, for instance. > > I feel lik