Bug#1105019: sbuild: source.changes includes binary build info
Holger Levsen <[email protected]>
| Newsgroups | gmane.linux.debian.devel.dpkg.bugs |
|---|---|
| Message-ID | <aCNB9tzrAIYsDumW__13135.461839714$1747141406$gmane$org@layer-acht.org> |
On Tue, May 13, 2025 at 02:24:38PM +0200, Guillem Jover wrote: > We have had reproducible source packages (barring OpenPGP signatures in > the .dsc files) since pretty much the same time dpkg-deb gained support have you actually tried that? > > why do you think they are important? > For QA alone this seems important (test suites for example), but in a > security context, to me this seems like a rather important part TBH, > the foundation on which binary package reproducibility is sitting. More > so in scenarios such as the xz attack for example. Reviewing diffoscope > differences is very helpful, but in the end we need to review and modify > the sources, from which the binaries get derived. :) obviously I agree that being able to reproduce the content would be nice, however in our tests years ago, not even that was possible, yet alone bit by bit (thus including timestamps). I guess someone would need to actually investigate some hundred packages today, to see how things are really today. -- cheers, Holger ⢀⣴⠾⠻⢶⣦⠀ ⣾⠁⢠⠒⠀⣿⡁ holger@(debian|reproducible-builds|layer-acht).org ⢿⡄⠘⠷⠚⠋⠀ OpenPGP: B8BF54137B09D35CF026FE9D 091AB856069AAA1C ⠈⠳⣄ Life may not be the party we hoped for, but while we're here we might as well dance!
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEuL9UE3sJ01zwJv6dCRq4VgaaqhwFAmgjQfYACgkQCRq4Vgaa qhwCvw/+M8/Nslq78ONji/YbqFZ1/CDCfsVpXbcjQW2+TmSpjmzCZ2HQoxKkfJlQ HedgmNOlfH5ZNTyyhTsjnZZ6zKcg/HkqWOR2wNbIsXaTkzxYL+XGgj4VV/hTfoeq IBDxYQyJ1enmLdPApeG3rPABtL36O36mY7FGcpNSbjKvuA+EUvJLyINRQ77eq2F6 guabkuQXAQa9yW8PXVNyJSsbNsGcbhDe0xf3wRptSU3aWhmsOifOYRmix5mqflvi s724W15Zd9lr7mxVBo/ItIoiqnuJmA1BjNgpczIHVWjTZuj9jm+nxJDhcESDC8md NQltq+LrMWd0unj/j4HaED6v/U+8o9e4Ix8/v9SfvdroBmJgiSBHw3Oil6HoQXjB YAvJ/S1fCf4e/XfedWjT9+yuA1K1kd+3M/jVKdlG9bP6msdtm9SMYIt23fuXomwo s+oVcPbraPfu54U3KdaX/U1IyPMEQA7BzYHxzTTIMClvCkBnzbnsKjCh4qc3AaMG 4OSUW2TA/PDfkfKh9CYjCAhuu/zP6ymCnOj6LCyROUNLNmYs8AjfySG/NPPOA1SC G0yQdXsHkw4HHp/rRvy9EegqDtgcqUIYt40nhAEVpVauJN1/byLWK4ocfgSgTrXD /dEgK6ChqLgxSMZWv+Mt7+wmNdHLFJDYT+VjaW3q5Xgls7ouIMs= =eJMe -----END PGP SIGNATURE-----