[rb-general] Core Debian reproducibility: 57% and rising!

Vagrant Cascadian vagrant at debian.org
Tue Nov 13 22:14:31 CET 2018


On 2018-11-08, Mattia Rizzolo wrote:
> On Sun, Oct 28, 2018 at 05:42:58PM -0700, Vagrant Cascadian wrote:
>> The unreproducible numbers include simply unknown things; packages which
>> have no .buildinfo files available, haven't been (re)built recently
>> enough to have a .buildinfo file, only unsigned .buildinfo files,
>> etc.

> Could you please extrapolate which of those packages in the base system
> lack any .buildinfo file in the archive?

I didn't do any specific analysis; those were just the types of things
that keep some .buildinfo files off of buildinfo.debian.net, and the
process relies on the .buildinfo files being on buildinfo.debian.net.

Another issue would be buildinfo files signed with ed25519 keys, if my
hunches about this issue are correct:

  https://github.com/lamby/buildinfo.debian.net/issues/51

Which *might* be resolved by the recent update to gnupg in Debian
stretch:

  https://bugs.debian.org/906545
  https://bugs.debian.org/910398


live well,
  vagrant
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 227 bytes
Desc: not available
URL: <http://lists.reproducible-builds.org/pipermail/rb-general/attachments/20181113/418de4e2/attachment.sig>


More information about the rb-general mailing list