Hi,
could you change the reproducible builds to find bugs like #843433,
ideally with a rebuild of everything that is currently building
reproducibly?
If one of the builds would use merged /usr and the other would not,
then bugs like #843433 should show up as difference in the build.
Thanks
On Tue, Aug 15, 2017 at 11:49:22AM -0700, Russ Allbery wrote:
> Adrian Bunk <b...@debian.org> writes:
>
> > I would expect the reproducible builds team to not submit any bugs
> > regarding varied environment variables as long as as the official
> > definition of re
On Tue, Aug 15, 2017 at 01:00:00PM -0700, Russ Allbery wrote:
>...
> This in absolutely no way constrains the reproducible build team from
> working on raising the bar in the future, just as the absence of this
> language from Policy did not prevent them from starting to work on this
> problem
On Wed, Aug 16, 2017 at 10:24:07AM +, Mattia Rizzolo wrote:
> On Tue, 15 Aug 2017, 11:02 p.m. Adrian Bunk <b...@debian.org> wrote:
>
> > Tracker:
> > https://tracker.debian.org/pkg/hsqldb1.8.0
> > "Does not build reproducibly during testing"
>
&
On Wed, Aug 16, 2017 at 03:43:00PM +, Ximin Luo wrote:
> Adrian Bunk:
> > On Wed, Aug 16, 2017 at 11:37:00AM +, Ximin Luo wrote:
> >> [..]
> >>
> >> Fair enough. I actually spotted that but thought it was better to get
> >> "something"
On Sun, Jul 23, 2017 at 01:54:32PM +0200, Mattia Rizzolo wrote:
>...
> Buildinfo files
> ===
>
> We have been playing with .buildinfo files [9] for more than two years,
> and dpkg finally started producing them with version 1.18.11 (Nov 2016).
>
> Some weeks later dak started to
>...
> Debian Policy
> =
>
> We are in the process of making reproducibility of packages something
> properly documented in policy. Writing patches for policy is not easy,
> so we welcome input from everyone to be able to better consider all the
> needed facets. See bug #844431 [16]
On Mon, Jul 24, 2017 at 09:46:27PM +0100, Chris Lamb wrote:
>...
> Related to this is how we show/expose reproducibility to end users, if it
> all. Some discussion of sorts is happening on #863622 (src:apt).
>...
How is this supposed to work for DSAs?
Do you want to claim a security update is
On Wed, Jun 21, 2017 at 10:09:00AM +, Ximin Luo wrote:
> Adrian Bunk:
> > On Wed, Jun 21, 2017 at 09:28:00AM +, Ximin Luo wrote:
> >> Adrian Bunk:
> >>> On Tue, Jun 20, 2017 at 02:47:20PM -0400, Daniel Kahn Gillmor wrote:
> >>>> Hi Ian--
> &
On Wed, Jun 21, 2017 at 09:30:14AM +, Holger Levsen wrote:
> Hi,
>
> trigger warning: nitpicking.
>
> On Wed, Jun 21, 2017 at 11:34:17AM +0300, Adrian Bunk wrote:
> > > I do source-only uploads because i don't want the binaries built on my
> > > own
On Wed, Jun 21, 2017 at 09:28:00AM +, Ximin Luo wrote:
> Adrian Bunk:
> > On Tue, Jun 20, 2017 at 02:47:20PM -0400, Daniel Kahn Gillmor wrote:
> >> Hi Ian--
> >>
> >> On Tue 2017-06-20 18:10:49 +0100, Ian Jackson wrote:
> >>> A .buildinfo f
On Thu, Jun 22, 2017 at 08:26:00AM +, Ximin Luo wrote:
>...
> One way to give security that is independent of third parties, is to provide
> some sort of mathematically-verifiable proof. However the world isn't at that
> stage yet for compiler technology.
What changes in compiler technology
Source: reprotest
Version: 0.7.5
Severity: serious
https://buildd.debian.org/status/fetch.php?pkg=reprotest=all=0.7.5=1513272013=0
...
===
Reproduction successful
===
No differences in ./../*.deb
Control: reassign -1 qtbase5-dev
Control: reassign 876917 qtbase5-dev
Control: reassign 876933 qtbase5-dev
Control: forcemerge -1 876917 876933
Control: retitle -1 QFINDTESTDATA uses __FILE__
Control: severity -1 normal
Control: affects -1 src:karchive src:ki18n src:kcodecs src:kparts
thanks
The
Source: diffoscope
Version: 91
Severity: serious
https://tests.reproducible-builds.org/debian/rb-pkg/unstable/amd64/diffoscope.html
...
___ test_diff_javap
differences_javap = []
@skip_unless_tool_is_at_least('javap',
15 matches
Mail list logo