[rb-general] Reproducible system images

Holger Levsen holger at layer-acht.org
Thu Dec 19 12:32:14 UTC 2019


Hi Lars,

On Mon, Dec 16, 2019 at 09:53:46AM +0100, Bernhard M. Wiedemann wrote:
> On 15/12/2019 09.12, Lars Wirzenius wrote:
> > What do others on the list think? Is reproducible system images a goal
> > worth pursuing?

absolutly!

> Others worked on this before:
> https://wiki.debian.org/ReproducibleInstalls
> https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=900918

indeed.

Also, tails releases are now reproducible and are system images as well,
see eg

https://redmine.tails.boum.org/code/issues/5630
https://reproducible-builds.org/docs/recording/#tails
https://tails.boum.org/blueprint/reproducible_builds/
https://tails.boum.org/news/reproducible_Tails/index.en.html

Though I sadly couldnt find a document which describes the current hash
(though https://tails.boum.org/install/expert/usb/index.en.html has it)
*and* the steps to reproduce this image :/ Can someone point me/us to
it?

> and I looked into openSUSE's installation-images package, that has
> similar problems.
> There were also several post-install scripts creating files in
> unreproducible ways. For normal packages that is not a problem, but for
> images it is.

indeed. (eg apt installs packages in arbitrary order and then the postinst
scripts eg create uids in a non-determistic way.)


-- 
cheers,
	Holger

-------------------------------------------------------------------------------
               holger@(debian|reproducible-builds|layer-acht).org
       PGP fingerprint: B8BF 5413 7B09 D35C F026 FE9D 091A B856 069A AA1C

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://lists.reproducible-builds.org/pipermail/rb-general/attachments/20191219/fd35d573/attachment.sig>


More information about the rb-general mailing list