Re: 答复: Can OProfile support reproducible build?

William Cohen <[email protected]>
Newsgroups gmane.linux.oprofile
Message-ID <[email protected]>
On 08/31/2017 04:56 AM, Michael Petlan wrote:
> So in such case, I suggest either removing the strings entirely
> or making them conditional as I mentioned before. What would you
> prefer William?

Hi,

It would be fine to have a patch that strips out those things that prevent the build from being reproducible.  Both Fedora and Debian are have talked about moving towards reproducible builds:

https://reproducible.alioth.debian.org/presentations/2017-01-27-devconf.cz-reproducible-builds+fedora.pdf
https://wiki.debian.org/ReproducibleBuilds/About
https://fedoraproject.org/wiki/Changes/RPM-4.14

-Will

> 
> On Thu, 31 Aug 2017, Zhongwenlin wrote:
>> Thank you.
>> I tried to replace the time stamps __DATE__ and __TIME__ macros by a fixed time string, and it works.
>> Can Oprofile add configurations or just remove the time stamps(if they are not necessary ) in future versions?
>>
>> -----邮件原件-----
>> 发件人: Michael Petlan [mailto:[email protected]] 
>> 发送时间: 2017年8月30日 22:35
>> 收件人: Zhongwenlin
>> 抄送: William Cohen; Gaokun (King); [email protected]
>> 主题: RE: Can OProfile support reproducible build?
>>
>> Well, if just these three points are the whole show-stopper, we might make them conditional like
>>
>> #ifdef REPRODUCIBLE_BUILD
>>   cout << argv[0] << ": " << PACKAGE << " " << VERSION << endl; #else // the original stuff #endif
>>
>> ... or just remove the timestamps entirely...
>>
>> If you replace the __DATE__ and __TIME__ macros there by some dummy string, does it build reproducibly?
>>
>> Michael
>>
>> On Wed, 30 Aug 2017, Zhongwenlin wrote:
>>> Hi,
>>> I use the latest version 1.2.0. And I found that the code below would generate timestamps----just they cause the difference.
>>> How
>>>
>>>     libutil/op_version.c: 
>>>                     21: printf("%s: " PACKAGE " " VERSION " compiled on "
>>> 	                22:__DATE__ " " __TIME__ "\n", app_name);
>>>            
>>> 	pe_counting/ocount.cpp:
>>>                         659: case 'v':
>>> 			            660: cout << argv[0] << ": " << PACKAGE << " " << VERSION << " compiled on " << __DATE__
>>> 			            661:<< " " << __TIME__ << endl;
>>>
>>> 	pe_profiling/operf.cpp: 
>>>                       1344:case 'v':
>>> 			          1345:cout << argv[0] << ": " << PACKAGE << " " << VERSION << " compiled on " << __DATE__
>>> 			          1346:<< " " << __TIME__ << endl;
>>>
>>> How can I eliminate the timestamps?
>>>
>>>
>>> -----邮件原件-----
>>> 发件人: William Cohen [mailto:[email protected]]
>>> 发送时间: 2017年8月29日 2:14
>>> 收件人: [email protected]; Zhongwenlin
>>> 抄送: Gaokun (King)
>>> 主题: Can OProfile support reproducible build?
>>>
>>> From [email protected]:
>>>
>>>
>>> Hi,
>>>
>>> When I build Oprofile, I find the build results are different every time. It seems to be caused by some time stamps. How can I get rid of the time stamps?
>>>
>>> As we know, reproducible build is a good way to counter malicious attacks that generate malicious executables, by making it easy to recreate the executable to determine if the result is correct.  How can I eliminate the differences caused by the time stamps? Just remove some code? Or is there any configuration?
>>>
>>> Can Oprofile support reproducible build in later versions?
>>>
>>> Thank you.
>>>
>>>
>>>
>>> ---------------
>>>
>>>
>>> Hi,
>>>
>>> It would be helpful to describe in more detail which version of OProfile is being built, how OProfile is being built, and specific differences between the repeated builds.
>>>
>>> Debian does have some information on techniques on indentify reproducible build issues and ways to address them:
>>>
>>> https://wiki.debian.org/ReproducibleBuilds/Howto
>>>
>>> -Will
>>> ----------------------------------------------------------------------
>>> -------- Check out the vibrant tech community on one of the world's 
>>> most engaging tech sites, Slashdot.org! http://sdm.link/slashdot 
>>> _______________________________________________
>>> oprofile-list mailing list
>>> [email protected]
>>> https://lists.sourceforge.net/lists/listinfo/oprofile-list
>>>


------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
oprofile-list mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/oprofile-list
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.