buildinfo question
Mattia Rizzolo
mattia at mapreri.org
Sun Dec 18 22:29:37 UTC 2022
On Tue, Dec 13, 2022 at 10:14:55AM -0800, Vagrant Cascadian wrote:
> On 2022-12-13, James Addison via rb-general wrote:
> > As Debian's buildinfo[1] wiki page hints, it's difficult to determine
> > whether a build dependency is genuinely required at build-time,
> > compared to: it was required in the past, but has become dependency
> > cruft.
> >
> > I was wondering: are there reproducible-builds efforts underway (in
> > Debian or other ecosystems) to determine the packages that were
> > involved (first-pass approximation: at least one file belonging to the
> > package was read from the filesystem by a child of the build process
> > -- anything else?) during a reproducible package build?
>
> I have certainly used an ad-hoc simpler but related technique, building
> with and without a build-dependency, and checking for bit-for-bit
> identical results.
>
> It would be interesting to do something more systematic like your
> suggestion, though I'm not aware of anything at the moment.
I've also talked with others that were interested in doing something
like that more systematically, IIRC like jelmer from janitor.debian.net.
I have no idea how far that went.
--
regards,
Mattia Rizzolo
GPG Key: 66AE 2B4A FCCF 3F52 DA18 4D18 4B04 3FCD B944 4540 .''`.
More about me: https://mapreri.org : :' :
Launchpad user: https://launchpad.net/~mapreri `. `'`
Debian QA page: https://qa.debian.org/developer.php?login=mattia `-
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://lists.reproducible-builds.org/pipermail/rb-general/attachments/20221218/2e2c6c52/attachment.sig>
More information about the rb-general
mailing list