repo could require similar co-ordination during
rebuilds. fixed commit ID / signed tag, or other mechanism for example)
I'm using the timestamp from InRelease, which was confirmed to be 'the'
timestamp of the archive [1]. Therefore I don't need tags.
With kind regards,
Roland Clob
#x27; (caused by git clone), which
would be properly truncated to SOURCE_DATE_EPOCH, and therefore be
reproducible.
I'll prepare a patch, and hopefully the next set of live images (12.6.1
or 12.7.0) will be fully reproducible.
With kind regards,
Roland Clobus
[1] https://get.debian.org/im
Hello list,
The SUSE effort has been mentioned on Slashdot [1], a repost of a blog
entry on Phoronix [2], which was triggered by a news entry on openSUSE [3].
With kind regards,
Roland
[1]
https://linux.slashdot.org/story/24/04/19/2148247/opensuse-factory-achieves-bit-by-bit-reproducible-bui
tests)
* Currently in progress: finalise arm64 support (native and cross-build)
* Currently in progress: firmware support in live-build (it looks like
/usr-merge affects the location of the firmware files)
* See the TODO page [10]
With kind regards,
Roland Clobus
[1] https://wiki.debia
script
(including documentation)
* Unfinished: pre-release work-around for #1051607 (Calamares
installation on UEFI Secure Boot systems fails to boot after installation)
Work to be done:
* Visit to the MiniDebCamp in Hamburg [6]
* See the TODO page [7]
With kind regards,
Roland Clobus
[1] http
or me are missing from your update. One may just be
improving a simple explanation. Plus I have a question.
Roland Clobus wrote:
Reproducible status:
* All major desktops build reproducibly with bullseye, bookworm,
trixie and sid ...
** ... provided they are built for a second time within the
February 2024)
* Many other things. See the TODO page [4]
With kind regards,
Roland Clobus
[1] https://wiki.debian.org/ReproducibleInstalls/LiveImages
[2] https://salsa.debian.org/live-team/live-build/-/merge_requests/337
[3] https://salsa.debian.org/live-team/live-build/-/merge_requests/334
[4
On 04/01/2024 14:58, Roland Clobus wrote:
Single line summary: Very near the finishing line
Reproducible status:
* All major desktops build reproducibly with bullseye, bookworm, trixie
and sid ...
** ... provided they are built for a second time within the same DAK run
(i.e. 6 hours
2024)
* Many other things. See the TODO page [8]
With kind regards,
Roland Clobus
[1] https://wiki.debian.org/ReproducibleInstalls/LiveImages
[2] https://salsa.debian.org/live-team/live-build/-/merge_requests/331
https://salsa.debian.org/live-team/live-build/-/merge_requests/332
https
content of the live-build image
** Fix the few remaining reproducible issues in time before 12.3.0
(planned for early December 2023)
* Many other things. Moved to the TODO page [10]
With kind regards,
Roland Clobus
[1] https://wiki.debian.org/ReproducibleInstalls/LiveImages
[2] I once wrote that
kind regards,
Roland Clobus
OpenPGP_signature.asc
Description: OpenPGP digital signature
ge, but they are not
activated, which results in a silly GNOME welcome screen [4]
* Bug triaging for issues reported against live-build [3] and
debian-live [8]
* Many other things. See the TODO page [6]
With kind regards,
Roland Clobus
[1] https://wiki.debian.org/ReproducibleInstalls/
results in two expected
differences: the isoinfo 'Data preparer id' field and the .disk/mkisofs
file refer to the current live-build version.
With kind regards,
Roland Clobus
--
[1] /home/roland/git.nobackup/live-build/test/rebuild.sh --configuration
standard --debian-version
ng Debian Bookworm live images.
With kind regards,
Roland Clobus
OpenPGP_signature
Description: OpenPGP digital signature
On 04/07/2023 22:32, Vagrant Cascadian wrote:
On 2023-07-04, David A. Wheeler wrote:
On Jul 2, 2023, at 11:37 AM, Roland Clobus wrote:
Reproducible status:
* All major desktops build reproducibly with bullseye, bookworm, trixie and sid
How close are things to having the *released* versions
rrent TODO page [5]
With kind regards,
Roland Clobus
[1] https://wiki.debian.org/ReproducibleInstalls/LiveImages
[2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1037295
[3] https://lists.debian.org/debian-live/2023/06/msg00017.html
[4] https://lists.debian.org/debian-live/2023/06/msg00023
Hello,
On 01/03/2023 22:59, Thomas Schmitt wrote:
Mattia Rizzolo wrote:
...
... The file tree and the data files' content is only
a part of a bootable ISO 9660 image. There's executable code in the
blind spots of such a view: MBR legacy BIOS boot code, EFI programs in
the EFI partition, "hidde
map creates a logfile with the timestamps of
files that it just has generated [4]
* Priority is now very low, since the package is not used in live images
any more
** This section will be removed from my next report
With kind regards,
Roland Clobus
[1] https://wiki.debian.org/Reproducibl
removed from my next report
With kind regards,
Roland Clobus
[1] https://wiki.debian.org/ReproducibleInstalls/LiveImages
[2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1003449
[3] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1009196
[4]
https://salsa.d
a short time
frame, to capture more variations
* Use disorderfs
* Transfer the special features of the (now disabled) live-wrapper live
images to live-build
With kind regards,
Roland Clobus
[1] https://wiki.debian.org/ReproducibleInstalls/LiveImages
[2] https://bugs.debian.org/cgi-bin/bugrepo
in the file `/usr/share/java/tomcat9-embed-websocket-9.0.68.jar` the
order of the file `module-info.class` is different.
Can the order be guaranteed (e.g. by sorting)?
With kind regards,
Roland Clobus
OpenPGP_signature
Description: OpenPGP digital signature
cial live-images again [6][8]
With kind regards,
Roland Clobus
[1] https://wiki.debian.org/ReproducibleInstalls/LiveImages
[2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1003449
[3] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1009196
[4]
https://salsa.debian.org/live
ision: The cannonical timestamp is for Debian, not 'an archive'.
You might want to split this now into two sentences, since the content
is not related.
With kind regards,
Roland Clobus
OpenPGP_signature
Description: OpenPGP digital signature
ithout a short time
frame, to capture more variations
* Use disorderfs
* Transfer the special features of the (now disabled) live-wrapper live
images to live-build
* Start building official live-images again [6][8]
With kind regards,
Roland Clobus
[1] https://wiki.debian.org/Rep
uilding official live-images again [6][8]
With kind regards,
Roland Clobus
[1] https://wiki.debian.org/ReproducibleInstalls/LiveImages
[2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1003449
[3] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1009196
[4]
https://salsa.
ild
* Start building official live-images again [6][12]
With kind regards,
Roland Clobus
[1] https://wiki.debian.org/ReproducibleInstalls/LiveImages
[2] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1003449
[3] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1009196
[4]
https://salsa.debia
.g. the netinst images or perhaps even Docker
images
* Transfer the special features of the (now disabled) live-wrapper live
images to live-build
* Start building official live-images again [11]
With kind regards,
Roland Clobus
[1] https://wiki.debian.org/ReproducibleInstalls/LiveImages
[4]
ht
Hello reproducible-builds members,
would enabling LTO cause reproducible issues?
If I remember correctly, Bernhard mentioned some issues, which got
'solved' by using less parallel builds (-j1 or -j4?).
With kind regards,
Roland
Forwarded Message
Subject: enabling link time o
t; /etc/locale.gen"
chroot rootfs /bin/bash -c "DEBIAN_FRONTEND=noninteractive apt --yes
install localepurge"
grep tmp rootfs/var/cache/debconf/config.dat
(I've added some settings to make the step run without user interaction)
With kind regards,
Roland Clobus
[1]
extended to other images, e.g. the netinst images or perhaps even Docker
images
* Transfer the special features of the (now disabled) live-wrapper live
images to live-build
* Start building official live-images again [11]
With kind regards,
Roland Clobus
[1] https://wiki.debian.org
be
extended to other images, e.g. the netinst images or perhaps even Docker
images
* Transfer the special features of the (now disabled) live-wrapper live
images to live-build
* Start building official live-images again
With kind regards,
Roland Clobus
[1] https://wiki.debian.org
ucible-builds.org/options/rb-general
With kind regards,
Roland Clobus
OpenPGP_signature
Description: OpenPGP digital signature
+mailing list rb-general
Hi,
On 05/03/2022 12:40, Cyril Brulebois wrote:
Roland Clobus (2022-03-05):
I have noticed that the officially released version debian-installer
[2][3] will not work for bookworm and sid, because the kernel version
in the debian- installer does not match the current
features of the (now disabled) live-wrapper live
images to live-build
With kind regards,
Roland Clobus
[1] https://wiki.debian.org/ReproducibleInstalls/LiveImages
[2] https://salsa.debian.org/live-team/live-build/-/merge_requests/273
[3] Pending merge for Jenkins
mages
* When it is ready, switch to snapshot.reproducible-builds.org?
With kind regards,
Roland Clobus
[1] https://wiki.debian.org/ReproducibleInstalls/LiveImages
[2] https://jenkins.debian.net/view/live/
[3] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1000674
[4] https://bugs.debian.org/cg
page. Feel free to reword where needed.
With kind regards,
Roland Clobus
OpenPGP_signature
Description: OpenPGP digital signature
aps even Docker images
* When it is ready, switch to snapshot.reproducible-builds.org?
With kind regards,
Roland Clobus
[1] https://wiki.debian.org/ReproducibleInstalls/LiveImages
[2] https://jenkins.debian.net/view/live/
[3] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1000674
[4] https://bugs
** I've already contacted Philip Hands for an introductore meeting
* Long term: When live-build images are working fine, the work could be
extended to other images, e.g. the live-wrapper images, the netinst
images or perhaps even Docker images
With kind regards,
Roland Clobus
[1] htt
ion for the lb commands could be embedded
into the ISO image.
Then you can, after obtaining a live image, use the config provided
there to rebuild exactly the same image.
With kind regards,
Roland Clobus
[1] https://manpages.debian.org/bullseye/dpkg-dev/deb-buildinfo.5.en.html
OpenPGP_signature
Description: OpenPGP digital signature
image.
** OpenQA was presented on DebConf21, it already tests the current daily
images [5]
* Long term: When live-build images are working fine, the work could be
extended to other images, e.g. the live-wrapper images, the netinst
images or perhaps even Docker images
With kind regards,
Roland Clobus
ges (the official ones or generated
by simple-cdd or ...)
* live images (generated by live-wrapper, live-build or ...)
* Docker images
Would it be useful to add such additional category in the ecosystem?
With kind regards,
Roland Clobus
OpenPGP_signature
Description: OpenPGP digital signature
g release times
* When live-build images are working fine, the work could be extended to
other images, e.g. the live-wrapper images, the netinst images or
perhaps even Docker images
With kind regards,
Roland Clobus
[1] https://wiki.debian.org/ReproducibleInstalls/LiveImages
[2] https://jenkins.
Hello list,
Here is a quick update with answers I received on IRC by h01ger and fepitre:
On 27/06/2021 17:03, Roland Clobus wrote:
> Weak points and Future plans:
> * Both images must be built within the same mirror-sync time, ...
> ** Question: could/should Jenkins use snapshot.d.o?
personally think that an
automated (easy to manage) test suite would be beneficial
With kind regards,
Roland Clobus
[1] https://jenkins.debian.net/job/reproducible_debian_live_build
[2]
https://tests.reproducible-builds.org/debian_live_build/smallest-build.html
[3] https://wiki.debian.org/Reprod
Hello again,
On 25/04/2021 02:26, Bernhard M. Wiedemann wrote:
> On 24/04/2021 17.59, Roland Clobus wrote:
>> I've looked the reproducible report for apt-cacher-ng.
>> It looks like it is caused by a linker flag: -Wl,--build-id=sha1
> If you see variations in build-id w
Hello Felix, list,
I've fixed the website, you should now be able to read the
Debian-specific instructions again.
With kind regards,
Roland Clobus
git hash: 884ceefd5fc8bdd0de73c2022b4dd390ed9b6510
On 20/05/2021 19:16, Felix C. Stegerman wrote:
> Hi!
>
> I'd like to contrib
Hello Holger and lists,
On 08/05/2021 01:18, Holger Levsen wrote:
> On Wed, Feb 10, 2021 at 11:13:03PM +0100, Roland Clobus wrote:
>> I've created a Wiki page that details my progress in creating
>> reproducible live images, since I wrote to these lists on 2020-11-11.
>&g
As I understand it, this linker flag
was introduced at Red Hat [3] to have unique identifier for builds of a
package. The formula appears not to be very clear [4].
It could be solved by changing the linker, or by changing the build
configuration of each package.
With kind regards,
Roland Clobus
[1]
for all other tool that might who need it. For mdadm I'm
finalizing a patch.
* Buster images have more non-reproducible packages, but many issues
have been fixed for Bullseye already
Long summary:
Read the full Wiki page, which contains the command lines, etc.
With kind regards,
Roland Clobus
changes to a MR, that publishes my
work so far.
With kind regards,
Roland Clobus
[1]
https://lists.reproducible-builds.org/pipermail/rb-general/2020-August/002018.html
[2] https://rclobus.nl/blog/?p=190
signature.asc
Description: OpenPGP digital signature
50 matches
Mail list logo