[Git][reproducible-builds/reproducible-website][master] gothenburg: Add d1-imagebuilds.md
Bernhard M. Wiedemann (@bmwiedemann-guest)
gitlab at salsa.debian.org
Thu Sep 24 15:52:07 UTC 2026
Bernhard M. Wiedemann pushed to branch master at Reproducible Builds / reproducible-website
Commits:
c93ad519 by Bernhard M. Wiedemann at 2026-09-24T17:52:00+02:00
gothenburg: Add d1-imagebuilds.md
- - - - -
1 changed file:
- + _events/gothenburg2026/agenda/d1-imagebuilds.md
Changes:
=====================================
_events/gothenburg2026/agenda/d1-imagebuilds.md
=====================================
@@ -0,0 +1,24 @@
+What was necessary for making arch images reproducible:
+Goal is to make a rootfs that's reproducible
+Lots of timestamp cleanup
+Handling logs, some build tools can be piped to dev null
+Need an archive for bootstrapping, use yesterday's archive to bootstrap today's image
+Pacman has some non-determinism (key material embedded in the binary) which is stripped from the image. This breaks pacman out of the box, you need to run a command to fix pacman. Pacman also supports redirecting logs (to dev null) and use `SOURCE_DATE_EPOCH` for installed package metadata. Comment: does apt support this?
+For WSL the rootfs is enough, very little translation after that
+For containers, the builder takes the rootfs but needs additional flags to make the container image itself reproducible. One of the major ones is epoch time, arch uses the release timestamp
+One difficult quirk is that the name of the container is embedded in the file as annotation, making comparing two containers eg diff on the same system (in the same registry) is impossible because they need to be named differently.
+diffoci helps do this diff, allows ignoring those diffs
+
+Version of the image is the current date, archive date is set to -1 day for consistency of the archive. Weekly rebuilds. Reproducibility is also tested for the userland - if the default packages are reproducible but does not block the release.
+Recommended to use CI, pull-through mirror for docker hub (or AWS/GCP mirrors as fallback due to Hub rate limiting). From end user perspective, archive/snapshot repos can be slow as they don't have mirrors, potential SPOF.
+
+## Actionable tasks?
+- ?
+
+## Resources
+- [https://antiz.fr/blog/the-archlinux-wsl-image-is-now-reproducible/](https://antiz.fr/blog/the-archlinux-wsl-image-is-now-reproducible/)
+- [https://antiz.fr/blog/archlinux-now-has-a-reproducible-docker-image/](https://antiz.fr/blog/archlinux-now-has-a-reproducible-docker-image/)
+- [https://vdwaa.nl/mkosi-reproducible-arch-images.html#mkosi-reproducible-arch-images](https://vdwaa.nl/mkosi-reproducible-arch-images.html#mkosi-reproducible-arch-images)
+- [https://vdwaa.nl/mkosi-reproducible-images.html#mkosi-reproducible-images](https://vdwaa.nl/mkosi-reproducible-images.html#mkosi-reproducible-images)
+- [https://gitlab.archlinux.org/archlinux/archlinux-docker/-/blob/master/REPRO.md](https://gitlab.archlinux.org/archlinux/archlinux-docker/-/blob/master/REPRO.md)
+- [https://gitlab.archlinux.org/archlinux/archlinux-wsl/-/blob/main/REPRO.md](https://gitlab.archlinux.org/archlinux/archlinux-wsl/-/blob/main/REPRO.md)
View it on GitLab: https://salsa.debian.org/reproducible-builds/reproducible-website/-/commit/c93ad519995d24d9d17356aa63ab645e4c8ae011
--
View it on GitLab: https://salsa.debian.org/reproducible-builds/reproducible-website/-/commit/c93ad519995d24d9d17356aa63ab645e4c8ae011
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.reproducible-builds.org/pipermail/rb-commits/attachments/20260924/4fcce831/attachment.htm>
More information about the rb-commits
mailing list