[Git][reproducible-builds/reproducible-website][master] gothenburg: Add d2-cross-distro.md

kpcyrd (@kpcyrd) gitlab at salsa.debian.org
Thu Sep 24 15:54:54 UTC 2026



kpcyrd pushed to branch master at Reproducible Builds / reproducible-website


Commits:
5c47ecc4 by kpcyrd at 2026-09-24T17:54:49+02:00
gothenburg: Add d2-cross-distro.md

- - - - -


1 changed file:

- + _events/gothenburg2026/agenda/d2-cross-distro.md


Changes:

=====================================
_events/gothenburg2026/agenda/d2-cross-distro.md
=====================================
@@ -0,0 +1,11 @@
+## Cross-distro reproducibility
+
+Things needed to get started as a new distribution:
+
+* Step 0: Pick any package, build it twice (with `SOURCE_DATE_EPOCH=123`), run diffoscope on both packages and check the package manager build tooling itself is reproducible (e.g. the tool itself doesn't record filesystem timestamps in all packages, regardless of the software you're building). Other metadata should also be identical, if the only difference is a signature we can ignore that for now.
+* Step 1: You need an archive of old packages (e.g. a package mirror that only adds, but never deletes). If older version of build dependencies are not available anymore, we can not recreate the build environment necessary to reproduce the package
+* Step 2: Document your build environment. With the archived package versions available, we now need to document which of them are needed to recreate the build environment. This list needs to include the name of all (recursive) dependencies, their versions, and it's incuraged to include a cryptographic checksum of the package file (if technically possible). The list may be embedded into the binary package (Arch Linux style), distributed along with the binary packages (Debian style), or embedded in the build log, if they are reliably retained longterm and can be parsed securely (Alpine style).
+* Step 3: Have a way to derive the `SOURCE_DATE_EPOCH` value. You may derive this from your source package (Debian style) or record a canonical reference value in the buildinfo file (Arch style)
+* Step 4: Have a build command that is able setup the reference build environment described in the buildinfo file. This also needs to ensure the `SOURCE_DATE_EPOCH` value is set accordingly.
+
+With all of them in place, you are good to go!



View it on GitLab: https://salsa.debian.org/reproducible-builds/reproducible-website/-/commit/5c47ecc44ccf50fadeb51fa7f57393efecd7d529

-- 
View it on GitLab: https://salsa.debian.org/reproducible-builds/reproducible-website/-/commit/5c47ecc44ccf50fadeb51fa7f57393efecd7d529
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.reproducible-builds.org/pipermail/rb-commits/attachments/20260924/b607f6be/attachment.htm>


More information about the rb-commits mailing list