Bug#1105019: sbuild: source.changes includes binary build info

Holger Levsen <[email protected]>
Newsgroups gmane.linux.debian.devel.dpkg.bugs
Message-ID <aCNB9tzrAIYsDumW__13135.461839714$1747141406$gmane$org@layer-acht.org>
On Tue, May 13, 2025 at 02:24:38PM +0200, Guillem Jover wrote:
> We have had reproducible source packages (barring OpenPGP signatures in
> the .dsc files) since pretty much the same time dpkg-deb gained support

have you actually tried that?

> > why do you think they are important?
> For QA alone this seems important (test suites for example), but in a
> security context, to me this seems like a rather important part TBH,
> the foundation on which binary package reproducibility is sitting. More
> so in scenarios such as the xz attack for example. Reviewing diffoscope
> differences is very helpful, but in the end we need to review and modify
> the sources, from which the binaries get derived. :)

obviously I agree that being able to reproduce the content would be nice,
however in our tests years ago, not even that was possible, yet alone
bit by bit (thus including timestamps).

I guess someone would need to actually investigate some hundred packages
today, to see how things are really today.


-- 
cheers,
	Holger

 ⢀⣴⠾⠻⢶⣦⠀
 ⣾⠁⢠⠒⠀⣿⡁  holger@(debian|reproducible-builds|layer-acht).org
 ⢿⡄⠘⠷⠚⠋⠀  OpenPGP: B8BF54137B09D35CF026FE9D 091AB856069AAA1C
 ⠈⠳⣄

Life may not be the party we hoped for, but while we're here we might as well
dance!
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEEuL9UE3sJ01zwJv6dCRq4VgaaqhwFAmgjQfYACgkQCRq4Vgaa
qhwCvw/+M8/Nslq78ONji/YbqFZ1/CDCfsVpXbcjQW2+TmSpjmzCZ2HQoxKkfJlQ
HedgmNOlfH5ZNTyyhTsjnZZ6zKcg/HkqWOR2wNbIsXaTkzxYL+XGgj4VV/hTfoeq
IBDxYQyJ1enmLdPApeG3rPABtL36O36mY7FGcpNSbjKvuA+EUvJLyINRQ77eq2F6
guabkuQXAQa9yW8PXVNyJSsbNsGcbhDe0xf3wRptSU3aWhmsOifOYRmix5mqflvi
s724W15Zd9lr7mxVBo/ItIoiqnuJmA1BjNgpczIHVWjTZuj9jm+nxJDhcESDC8md
NQltq+LrMWd0unj/j4HaED6v/U+8o9e4Ix8/v9SfvdroBmJgiSBHw3Oil6HoQXjB
YAvJ/S1fCf4e/XfedWjT9+yuA1K1kd+3M/jVKdlG9bP6msdtm9SMYIt23fuXomwo
s+oVcPbraPfu54U3KdaX/U1IyPMEQA7BzYHxzTTIMClvCkBnzbnsKjCh4qc3AaMG
4OSUW2TA/PDfkfKh9CYjCAhuu/zP6ymCnOj6LCyROUNLNmYs8AjfySG/NPPOA1SC
G0yQdXsHkw4HHp/rRvy9EegqDtgcqUIYt40nhAEVpVauJN1/byLWK4ocfgSgTrXD
/dEgK6ChqLgxSMZWv+Mt7+wmNdHLFJDYT+VjaW3q5Xgls7ouIMs=
=eJMe
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.