Re: Nearly reproducible Bookworm 12.6 live images

2024-07-16 Thread Roland Clobus
repo could require similar co-ordination during rebuilds. fixed commit ID / signed tag, or other mechanism for example) I'm using the timestamp from InRelease, which was confirmed to be 'the' timestamp of the archive [1]. Therefore I don't need tags. With kind regards, Roland Clob

Nearly reproducible Bookworm 12.6 live images

2024-07-03 Thread Roland Clobus
#x27; (caused by git clone), which would be properly truncated to SOURCE_DATE_EPOCH, and therefore be reproducible. I'll prepare a patch, and hopefully the next set of live images (12.6.1 or 12.7.0) will be fully reproducible. With kind regards, Roland Clobus [1] https://get.debian.org/im

Slashdotted

2024-04-21 Thread Roland Clobus
Hello list, The SUSE effort has been mentioned on Slashdot [1], a repost of a blog entry on Phoronix [2], which was triggered by a news entry on openSUSE [3]. With kind regards, Roland [1] https://linux.slashdot.org/story/24/04/19/2148247/opensuse-factory-achieves-bit-by-bit-reproducible-bui

Irregular status update about reproducible live-build ISO images

2024-03-31 Thread Roland Clobus
tests) * Currently in progress: finalise arm64 support (native and cross-build) * Currently in progress: firmware support in live-build (it looks like /usr-merge affects the location of the firmware files) * See the TODO page [10] With kind regards, Roland Clobus [1] https://wiki.debia

Irregular status update about reproducible live-build ISO images

2024-02-27 Thread Roland Clobus
script (including documentation) * Unfinished: pre-release work-around for #1051607 (Calamares installation on UEFI Secure Boot systems fails to boot after installation) Work to be done: * Visit to the MiniDebCamp in Hamburg [6] * See the TODO page [7] With kind regards, Roland Clobus [1] http

Re: Questions about report 22

2024-02-02 Thread Roland Clobus
or me are missing from your update. One may just be improving a simple explanation. Plus I have a question. Roland Clobus wrote: Reproducible status: * All major desktops build reproducibly with bullseye, bookworm, trixie and sid ... ** ... provided they are built for a second time within the

Irregular status update about reproducible live-build ISO images

2024-01-29 Thread Roland Clobus
February 2024) * Many other things. See the TODO page [4] With kind regards, Roland Clobus [1] https://wiki.debian.org/ReproducibleInstalls/LiveImages [2] https://salsa.debian.org/live-team/live-build/-/merge_requests/337 [3] https://salsa.debian.org/live-team/live-build/-/merge_requests/334 [4

Re: Irregular status update about reproducible live-build ISO images

2024-01-06 Thread Roland Clobus
On 04/01/2024 14:58, Roland Clobus wrote: Single line summary: Very near the finishing line Reproducible status: * All major desktops build reproducibly with bullseye, bookworm, trixie and sid ... ** ... provided they are built for a second time within the same DAK run (i.e. 6 hours

Irregular status update about reproducible live-build ISO images

2024-01-04 Thread Roland Clobus
2024) * Many other things. See the TODO page [8] With kind regards, Roland Clobus [1] https://wiki.debian.org/ReproducibleInstalls/LiveImages [2] https://salsa.debian.org/live-team/live-build/-/merge_requests/331 https://salsa.debian.org/live-team/live-build/-/merge_requests/332 https

Irregular status update about reproducible live-build ISO images

2023-10-18 Thread Roland Clobus
content of the live-build image ** Fix the few remaining reproducible issues in time before 12.3.0 (planned for early December 2023) * Many other things. Moved to the TODO page [10] With kind regards, Roland Clobus [1] https://wiki.debian.org/ReproducibleInstalls/LiveImages [2] I once wrote that

Re: Fixes for make_ext4fs / mkfs.ext4(mke2fs)

2023-10-16 Thread Roland Clobus
kind regards, Roland Clobus OpenPGP_signature.asc Description: OpenPGP digital signature

Irregular status update about reproducible live-build ISO images

2023-08-27 Thread Roland Clobus
ge, but they are not activated, which results in a silly GNOME welcome screen [4] * Bug triaging for issues reported against live-build [3] and debian-live [8] * Many other things. See the TODO page [6] With kind regards, Roland Clobus [1] https://wiki.debian.org/ReproducibleInstalls/

Rebuilding the official Debian live images -> nearly reproducible

2023-08-16 Thread Roland Clobus
results in two expected differences: the isoinfo 'Data preparer id' field and the .disk/mkisofs file refer to the current live-build version. With kind regards, Roland Clobus -- [1] /home/roland/git.nobackup/live-build/test/rebuild.sh --configuration standard --debian-version

Re: Please review the draft for July's report

2023-08-02 Thread Roland Clobus
ng Debian Bookworm live images. With kind regards, Roland Clobus OpenPGP_signature Description: OpenPGP digital signature

Re: Irregular status update about reproducible live-build ISO images

2023-07-05 Thread Roland Clobus
On 04/07/2023 22:32, Vagrant Cascadian wrote: On 2023-07-04, David A. Wheeler wrote: On Jul 2, 2023, at 11:37 AM, Roland Clobus wrote: Reproducible status: * All major desktops build reproducibly with bullseye, bookworm, trixie and sid How close are things to having the *released* versions

Irregular status update about reproducible live-build ISO images

2023-07-02 Thread Roland Clobus
rrent TODO page [5] With kind regards, Roland Clobus [1] https://wiki.debian.org/ReproducibleInstalls/LiveImages [2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1037295 [3] https://lists.debian.org/debian-live/2023/06/msg00017.html [4] https://lists.debian.org/debian-live/2023/06/msg00023

Re: Does diffoscope compares disk partitions -> The German word is 'jein' (yes and no)

2023-03-01 Thread Roland Clobus
Hello, On 01/03/2023 22:59, Thomas Schmitt wrote: Mattia Rizzolo wrote: ... ... The file tree and the data files' content is only a part of a bootable ISO 9660 image. There's executable code in the blind spots of such a view: MBR legacy BIOS boot code, EFI programs in the EFI partition, "hidde

Monthly status update about reproducible live-build ISO images

2023-02-27 Thread Roland Clobus
map creates a logfile with the timestamps of files that it just has generated [4] * Priority is now very low, since the package is not used in live images any more ** This section will be removed from my next report With kind regards, Roland Clobus [1] https://wiki.debian.org/Reproducibl

Monthly status update about reproducible live-build ISO images

2023-01-29 Thread Roland Clobus
removed from my next report With kind regards, Roland Clobus [1] https://wiki.debian.org/ReproducibleInstalls/LiveImages [2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1003449 [3] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1009196 [4] https://salsa.d

Monthly status update about reproducible live-build ISO images

2022-11-28 Thread Roland Clobus
a short time frame, to capture more variations * Use disorderfs * Transfer the special features of the (now disabled) live-wrapper live images to live-build With kind regards, Roland Clobus [1] https://wiki.debian.org/ReproducibleInstalls/LiveImages [2] https://bugs.debian.org/cgi-bin/bugrepo

Re: Unreproducible Tomacat Issue

2022-11-12 Thread Roland Clobus
in the file `/usr/share/java/tomcat9-embed-websocket-9.0.68.jar` the order of the file `module-info.class` is different. Can the order be guaranteed (e.g. by sorting)? With kind regards, Roland Clobus OpenPGP_signature Description: OpenPGP digital signature

Monthly status update about reproducible live-build ISO images

2022-10-30 Thread Roland Clobus
cial live-images again [6][8] With kind regards, Roland Clobus [1] https://wiki.debian.org/ReproducibleInstalls/LiveImages [2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1003449 [3] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1009196 [4] https://salsa.debian.org/live

Re: Please review the draft for September's report

2022-10-05 Thread Roland Clobus
ision: The cannonical timestamp is for Debian, not 'an archive'. You might want to split this now into two sentences, since the content is not related. With kind regards, Roland Clobus OpenPGP_signature Description: OpenPGP digital signature

Monthly status update about reproducible live-build ISO images

2022-09-25 Thread Roland Clobus
ithout a short time frame, to capture more variations * Use disorderfs * Transfer the special features of the (now disabled) live-wrapper live images to live-build * Start building official live-images again [6][8] With kind regards, Roland Clobus [1] https://wiki.debian.org/Rep

12th status update about reproducible live-build ISO images

2022-08-28 Thread Roland Clobus
uilding official live-images again [6][8] With kind regards, Roland Clobus [1] https://wiki.debian.org/ReproducibleInstalls/LiveImages [2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1003449 [3] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1009196 [4] https://salsa.

Eleventh status update about reproducible live-build ISO images

2022-07-27 Thread Roland Clobus
ild * Start building official live-images again [6][12] With kind regards, Roland Clobus [1] https://wiki.debian.org/ReproducibleInstalls/LiveImages [2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1003449 [3] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1009196 [4] https://salsa.debia

Tenth status update about reproducible live-build ISO images in Jenkins

2022-06-28 Thread Roland Clobus
.g. the netinst images or perhaps even Docker images * Transfer the special features of the (now disabled) live-wrapper live images to live-build * Start building official live-images again [11] With kind regards, Roland Clobus [1] https://wiki.debian.org/ReproducibleInstalls/LiveImages [4] ht

Fwd: enabling link time optimizations in package builds

2022-06-17 Thread Roland Clobus
Hello reproducible-builds members, would enabling LTO cause reproducible issues? If I remember correctly, Bernhard mentioned some issues, which got 'solved' by using less parallel builds (-j1 or -j4?). With kind regards, Roland Forwarded Message Subject: enabling link time o

Re: debconf cache is non-reproducible issue while creating system image

2022-04-26 Thread Roland Clobus
t; /etc/locale.gen" chroot rootfs /bin/bash -c "DEBIAN_FRONTEND=noninteractive apt --yes install localepurge" grep tmp rootfs/var/cache/debconf/config.dat (I've added some settings to make the step run without user interaction) With kind regards, Roland Clobus [1]

Ninth status update about reproducible live-build ISO images in Jenkins

2022-04-24 Thread Roland Clobus
extended to other images, e.g. the netinst images or perhaps even Docker images * Transfer the special features of the (now disabled) live-wrapper live images to live-build * Start building official live-images again [11] With kind regards, Roland Clobus [1] https://wiki.debian.org

Eighth status update about reproducible live-build ISO images in Jenkins

2022-03-28 Thread Roland Clobus
be extended to other images, e.g. the netinst images or perhaps even Docker images * Transfer the special features of the (now disabled) live-wrapper live images to live-build * Start building official live-images again With kind regards, Roland Clobus [1] https://wiki.debian.org

Re: Unsubscribe request

2022-03-06 Thread Roland Clobus
ucible-builds.org/options/rb-general With kind regards, Roland Clobus OpenPGP_signature Description: OpenPGP digital signature

Re: Bug#1006800: debian-installer: kernel mismatch for bookworm and sid installer. New release needed?

2022-03-05 Thread Roland Clobus
+mailing list rb-general Hi, On 05/03/2022 12:40, Cyril Brulebois wrote: Roland Clobus (2022-03-05): I have noticed that the officially released version debian-installer [2][3] will not work for bookworm and sid, because the kernel version in the debian- installer does not match the current

Seventh status update about reproducible live-build ISO images in Jenkins

2022-02-22 Thread Roland Clobus
features of the (now disabled) live-wrapper live images to live-build With kind regards, Roland Clobus [1] https://wiki.debian.org/ReproducibleInstalls/LiveImages [2] https://salsa.debian.org/live-team/live-build/-/merge_requests/273 [3] Pending merge for Jenkins

Sixth status update about reproducible live-build ISO images in Jenkins

2022-01-24 Thread Roland Clobus
mages * When it is ready, switch to snapshot.reproducible-builds.org? With kind regards, Roland Clobus [1] https://wiki.debian.org/ReproducibleInstalls/LiveImages [2] https://jenkins.debian.net/view/live/ [3] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1000674 [4] https://bugs.debian.org/cg

Re: Please review the draft for December's report

2022-01-04 Thread Roland Clobus
page. Feel free to reword where needed. With kind regards, Roland Clobus OpenPGP_signature Description: OpenPGP digital signature

Fifth status update about reproducible live-build ISO images in Jenkins

2021-11-27 Thread Roland Clobus
aps even Docker images * When it is ready, switch to snapshot.reproducible-builds.org? With kind regards, Roland Clobus [1] https://wiki.debian.org/ReproducibleInstalls/LiveImages [2] https://jenkins.debian.net/view/live/ [3] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1000674 [4] https://bugs

Fourth status update about reproducible live-build ISO images in Jenkins

2021-09-25 Thread Roland Clobus
** I've already contacted Philip Hands for an introductore meeting * Long term: When live-build images are working fine, the work could be extended to other images, e.g. the live-wrapper images, the netinst images or perhaps even Docker images With kind regards, Roland Clobus [1] htt

Re: Recoding the configuration for live-build images (Was: Third status update about reproducible live-build ISO images in Jenkins)

2021-08-31 Thread Roland Clobus
ion for the lb commands could be embedded into the ISO image. Then you can, after obtaining a live image, use the config provided there to rebuild exactly the same image. With kind regards, Roland Clobus [1] https://manpages.debian.org/bullseye/dpkg-dev/deb-buildinfo.5.en.html OpenPGP_signature Description: OpenPGP digital signature

Third status update about reproducible live-build ISO images in Jenkins

2021-08-30 Thread Roland Clobus
image. ** OpenQA was presented on DebConf21, it already tests the current daily images [5] * Long term: When live-build images are working fine, the work could be extended to other images, e.g. the live-wrapper images, the netinst images or perhaps even Docker images With kind regards, Roland Clobus

Re: Help us map the reproducible builds ecosystem

2021-08-05 Thread Roland Clobus
ges (the official ones or generated by simple-cdd or ...) * live images (generated by live-wrapper, live-build or ...) * Docker images Would it be useful to add such additional category in the ecosystem? With kind regards, Roland Clobus OpenPGP_signature Description: OpenPGP digital signature

Second status update about reproducible live-build ISO images in Jenkins

2021-07-25 Thread Roland Clobus
g release times * When live-build images are working fine, the work could be extended to other images, e.g. the live-wrapper images, the netinst images or perhaps even Docker images With kind regards, Roland Clobus [1] https://wiki.debian.org/ReproducibleInstalls/LiveImages [2] https://jenkins.

Re: Status update about reproducible live-build ISO images in Jenkins

2021-06-28 Thread Roland Clobus
Hello list, Here is a quick update with answers I received on IRC by h01ger and fepitre: On 27/06/2021 17:03, Roland Clobus wrote: > Weak points and Future plans: > * Both images must be built within the same mirror-sync time, ... > ** Question: could/should Jenkins use snapshot.d.o?

Status update about reproducible live-build ISO images in Jenkins

2021-06-27 Thread Roland Clobus
personally think that an automated (easy to manage) test suite would be beneficial With kind regards, Roland Clobus [1] https://jenkins.debian.net/job/reproducible_debian_live_build [2] https://tests.reproducible-builds.org/debian_live_build/smallest-build.html [3] https://wiki.debian.org/Reprod

Re: Possible new category for non-reproducible builds: --build-id=sha1 -> actually cmake_rpath_contains_build_path_issue

2021-05-30 Thread Roland Clobus
Hello again, On 25/04/2021 02:26, Bernhard M. Wiedemann wrote: > On 24/04/2021 17.59, Roland Clobus wrote: >> I've looked the reproducible report for apt-cacher-ng. >> It looks like it is caused by a linker flag: -Wl,--build-id=sha1 > If you see variations in build-id w

Re: How can I contribute? -> broken URL fixed

2021-05-22 Thread Roland Clobus
Hello Felix, list, I've fixed the website, you should now be able to read the Debian-specific instructions again. With kind regards, Roland Clobus git hash: 884ceefd5fc8bdd0de73c2022b4dd390ed9b6510 On 20/05/2021 19:16, Felix C. Stegerman wrote: > Hi! > > I'd like to contrib

Re: Progress on reproducible Debian Live images

2021-05-13 Thread Roland Clobus
Hello Holger and lists, On 08/05/2021 01:18, Holger Levsen wrote: > On Wed, Feb 10, 2021 at 11:13:03PM +0100, Roland Clobus wrote: >> I've created a Wiki page that details my progress in creating >> reproducible live images, since I wrote to these lists on 2020-11-11. >&g

Possible new category for non-reproducible builds: --build-id=sha1

2021-04-24 Thread Roland Clobus
As I understand it, this linker flag was introduced at Red Hat [3] to have unique identifier for builds of a package. The formula appears not to be very clear [4]. It could be solved by changing the linker, or by changing the build configuration of each package. With kind regards, Roland Clobus [1]

Progress on reproducible Debian Live images

2021-02-10 Thread Roland Clobus
for all other tool that might who need it. For mdadm I'm finalizing a patch. * Buster images have more non-reproducible packages, but many issues have been fixed for Bullseye already Long summary: Read the full Wiki page, which contains the command lines, etc. With kind regards, Roland Clobus

Reproducible Debian live ISO image

2020-09-11 Thread Roland Clobus
changes to a MR, that publishes my work so far. With kind regards, Roland Clobus [1] https://lists.reproducible-builds.org/pipermail/rb-general/2020-August/002018.html [2] https://rclobus.nl/blog/?p=190 signature.asc Description: OpenPGP digital signature