Bug#862059: sbuild: please sign buildinfo files

2017-05-07 Thread Steven Chamberlain
Package: sbuild Version: 0.73.0-4 Tags: patch User: reproducible-builds@lists.alioth.debian.org Usertags: infrastructure Hello, dpkg-buildpackage typically generates a .changes and .buildinfo file, and signs both (since at least dpkg 1.18.19). But when using sbuild, dpkg-buildpackage inside of

Re: [Reproducible-builds] Bug#816439: linux-grsec: feeding the seed with SOURCE_DATE_EPOCH

2016-07-12 Thread Steven Chamberlain
d. There might still be other reproducibility issues after this. Thanks, Regards, -- Steven Chamberlain ste...@pyro.eu.org diff -Nru linux-grsec-4.6.3/debian/patches/features/all/grsec/reproducible-randstruct.patch linux-grsec-4.6.3/debian/patches/features/all/grsec/reproducible-randstruct.patch

Re: [Reproducible-builds] Bug#816072: tar: Please upstream --clamp-mtime option

2016-05-17 Thread Steven Chamberlain
tags 816072 + fixed-upstream thanks tar 1.29 is released today with this feature \o/ Please consider packaging it so that dpkg can fix #759886 Thanks, Regards, -- Steven Chamberlain ste...@pyro.eu.org signature.asc Description: Digital signature

[Reproducible-builds] Performance of armhf boards

2016-04-17 Thread Steven Chamberlain
hese armhf nodes! Regards, -- Steven Chamberlain ste...@pyro.eu.org signature.asc Description: Digital signature ___ Reproducible-builds mailing list Reproducible-builds@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/reproducible-builds

Re: [Reproducible-builds] arm64 reproducible build network

2016-03-25 Thread Steven Chamberlain
Hi, I'm curious if anyone has tried using a network filesystem in this kind of setup. I would think, "diskless" boards sharing a NAS allows for easier provisioning and probably cheaper storage by centralising it. Though I don't know how that performs in practice? Regards, -- Steven C

Re: [Reproducible-builds] Raspi 3 suitable for arm64?

2016-03-21 Thread Steven Chamberlain
ork is still needed yet. (Annoying that there are so many cheap boards that claim to be/do so much and yet, are of little practical use if they can only boot a vendor-supplied kernel). Regards, -- Steven Chamberlain ste...@pyro.eu.org signature.asc Description: Digital signat

[Reproducible-builds] Bug#813052: : Bug#813052: diffoscope takes more than an hour on foreign arch libc6

2016-02-17 Thread Steven Chamberlain
Jérémy Bobbio wrote: > [...] It missed another bit. Thanks for double-checking, I hadn't > tested the other change properly. And thanks for fixing this! The changes from diffoscope/48 to 49 have made it 26x faster for this particular test case. Regards, -- Steven Chamberlain ste...@pyro.

[Reproducible-builds] Bug#813052: Bug#813052: diffoscope takes more than an hour on foreign arch libc6

2016-02-17 Thread Steven Chamberlain
Jérémy Bobbio wrote: > Steven Chamberlain: > > But it will still stat() everything in the containing directory, > > looking for .debs. It also opens some files and reads them - even > > decompressing random .gz files along the way! > > Are you sure that it is a

[Reproducible-builds] symlink permission bits on non-Linux

2016-02-15 Thread Steven Chamberlain
an use? Probably a new flag, that would apply --mode a=rwx only to symlinks. Or are there other ideas how to fix this? Thanks, Regards, -- Steven Chamberlain ste...@pyro.eu.org signature.asc Description: Digital signature ___ Reproducible-builds mailin

Re: [Reproducible-builds] please don't build on archs that packages don't declare support for

2016-02-14 Thread Steven Chamberlain
amd64, but it only produces armel and arch:all binaries, so it is quite reasonable that this is now only built and tested for reproducibility on armhf. Regards, -- Steven Chamberlain ste...@pyro.eu.org signature.asc Description: Digital sig

Re: [Reproducible-builds] please don't build on archs that packages don't declare support for

2016-02-09 Thread Steven Chamberlain
sion over current behaviour, but can be substituted for ARCHITECTURES="amd64" if too many arch:all packages FTBFS on armhf. From a759d049b1fd6deeb24985e57a3b6f4fa2e1f72b Mon Sep 17 00:00:00 2001 From: Steven Chamberlain <ste...@pyro.eu.org> Date: Tue, 9 Feb 2016 13:02:13 + Subject: [PATC

Re: [Reproducible-builds] Cross-building across architectures (reproducibly?)

2016-01-02 Thread Steven Chamberlain
Steven Chamberlain wrote: > using Helmut's tool, I've been able to rebootstrap a minimal Debian > linux-i386 chroot (445 binary packages[3]). These were cross-compiled > from source, by only running kfreebsd-amd64 binaries on a FreeBSD > kernel, and having some Arch:all packages inst

[Reproducible-builds] Cross-building across architectures (reproducibly?)

2016-01-01 Thread Steven Chamberlain
://lists.alioth.debian.org/pipermail/reproducible-builds/Week-of-Mon-20151123/003992.html Regards, -- Steven Chamberlain ste...@pyro.eu.org signature.asc Description: Digital signature ___ Reproducible-builds mailing list Reproducible-builds@lists.alioth.debian.org

Re: [Reproducible-builds] Juniper ScreenOS backdoor

2015-12-21 Thread Steven Chamberlain
a nice demo of diffoscope if it can do this, although it might not know how to disassemble this properly. I uploaded the firmwares here but I think something broke... it has been "in queue, please wait" for over an hour :( The files were 25MB each. https://try.diffoscope.org/quvzskqbuysh Regards,

[Reproducible-builds] Juniper ScreenOS backdoor

2015-12-21 Thread Steven Chamberlain
thought this was a good example of the current state-of-the-art, and why we'd like our binaries and eventually, installer and VM images reproducible IMHO. Regards, -- Steven Chamberlain ste...@pyro.eu.org signature.asc Description: Digital signature

Re: [Reproducible-builds] Juniper ScreenOS backdoor

2015-12-21 Thread Steven Chamberlain
Steven Chamberlain wrote: > I uploaded the firmwares here but I think something broke... it has been > "in queue, please wait" for over an hour :( The files were 25MB each. > https://try.diffoscope.org/quvzskqbuysh Okay, I did eventually finish. As suspected, diffoscope (

Re: [Reproducible-builds] Juniper ScreenOS backdoor

2015-12-21 Thread Steven Chamberlain
pe/commit/302190ac958b35fe95a0c2bc2d2a30f214822fc1 Regards, -- Steven Chamberlain ste...@pyro.eu.org signature.asc Description: Digital signature ___ Reproducible-builds mailing list Reproducible-builds@lists.alioth.debian.org http://lists.alioth.debia

Re: [Reproducible-builds] Bug#805321: Bug#805321: debian-installer: builds unreproducible netboot images

2015-11-27 Thread Steven Chamberlain
defined (since ../debian/changelog may not exist), which we need when calling makefs from within that Makefile. We export it for use by gen-tarball to avoid duplication there. Regards, -- Steven Chamberlain ste...@pyro.eu.org signature.

Re: [Reproducible-builds] reproducible builds of FreeBSD in a chroot on Linux

2015-07-20 Thread Steven Chamberlain
of a directory? Regards, -- Steven Chamberlain ste...@pyro.eu.org signature.asc Description: Digital signature ___ Reproducible-builds mailing list Reproducible-builds@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo

[Reproducible-builds] Bug#791584: kfreebsd-source-10.1: umask setting can affect build

2015-07-06 Thread Steven Chamberlain
Package: kfreebsd-source-10.1 Version: 10.1~svn274115-6 Severity: wishlist Tags: patch pending User: reproducible-builds@lists.alioth.debian.org

[Reproducible-builds] Bug#791584: kfreebsd-source-10.1: umask setting can affect build

2015-07-06 Thread Steven Chamberlain
Steven Chamberlain wrote: [...] I guess we could chmod before building the tarball: On second thoughts, that's not as efficient as using tar's --mode option so I'll use that. The example given on the Debian Wiki page is more comprehensive than my chmod anyway. --- debian/rules(revision

Re: [Reproducible-builds] Bug#782878: [debhelper-devel] Bug#782879 + Bug#782878: lib{test-log4perl, scalar-defer}-perl: please make the build reproducible

2015-05-26 Thread Steven Chamberlain
or deduplication. I suggest to only 'clamp' timestamps to the latest entry in debian/changelog. I think only timestamps newer than this are likely an issue for reproducibility. Older timestamps are potentially still useful. Regards, -- Steven Chamberlain ste...@pyro.eu.org

[Reproducible-builds] Bug#786615: kfreebsd-10: source tarballs have unreproducible file order

2015-05-23 Thread Steven Chamberlain
Package: src:kfreebsd-10 Version: 10.1~svn274115-4 Severity: wishlist Tags: patch pending User: reproducible-builds@lists.alioth.debian.org Usertags: fileordering Hi, The kfreebsd-10 (kernel) packaging creates two source tarballs: * orig.tar.xz, updated by the package maintainer for each new

[Reproducible-builds] Create tar archive with deterministic file order

2015-02-14 Thread Steven Chamberlain
that seem like the neatest way, or do you have better suggestions? (I thought this problem would be quite common, so I could add it to the Wiki FAQ). Thanks! Regards, -- Steven Chamberlain ste...@pyro.eu.org ___ Reproducible-builds mailing list Reproducible