[rb-general] Reproducible system images
Holger Levsen
holger at layer-acht.org
Thu Dec 19 12:32:14 UTC 2019
Hi Lars,
On Mon, Dec 16, 2019 at 09:53:46AM +0100, Bernhard M. Wiedemann wrote:
> On 15/12/2019 09.12, Lars Wirzenius wrote:
> > What do others on the list think? Is reproducible system images a goal
> > worth pursuing?
absolutly!
> Others worked on this before:
> https://wiki.debian.org/ReproducibleInstalls
> https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=900918
indeed.
Also, tails releases are now reproducible and are system images as well,
see eg
https://redmine.tails.boum.org/code/issues/5630
https://reproducible-builds.org/docs/recording/#tails
https://tails.boum.org/blueprint/reproducible_builds/
https://tails.boum.org/news/reproducible_Tails/index.en.html
Though I sadly couldnt find a document which describes the current hash
(though https://tails.boum.org/install/expert/usb/index.en.html has it)
*and* the steps to reproduce this image :/ Can someone point me/us to
it?
> and I looked into openSUSE's installation-images package, that has
> similar problems.
> There were also several post-install scripts creating files in
> unreproducible ways. For normal packages that is not a problem, but for
> images it is.
indeed. (eg apt installs packages in arbitrary order and then the postinst
scripts eg create uids in a non-determistic way.)
--
cheers,
Holger
-------------------------------------------------------------------------------
holger@(debian|reproducible-builds|layer-acht).org
PGP fingerprint: B8BF 5413 7B09 D35C F026 FE9D 091A B856 069A AA1C
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://lists.reproducible-builds.org/pipermail/rb-general/attachments/20191219/fd35d573/attachment.sig>
More information about the rb-general
mailing list