How does one source pinned translations for reproducible release tarballs?

kpcyrd kpcyrd at archlinux.org
Wed Sep 30 15:38:25 UTC 2026


On 9/29/26 10:43 PM, Bruno Haible via rb-general wrote:
> Yes. Neither the TP nor Weblate instances have the concept of branches or dates.
> They just store the newest translation of a POT file for a given language,
> and when that translation gets updated, the previous one becomes inaccessible.
> [1][2]
Arch Linux also ran into this problem with many GNU projects when trying to 
implement the "Upstream package sources" RFC:

https://rfc.archlinux.page/0046-upstream-package-sources/

The only practical solution we found was "using both git and the tarball as 
build input". For "GNU grep 3.12", we use the following:

https://gitlab.archlinux.org/archlinux/packaging/packages/grep/-/blob/b6557325ffa4abe40e4785823939a42093218acd/PKGBUILD

	source = git+https://git.savannah.gnu.org/git/grep.git?signed#tag=v3.12
	source = git+https://git.savannah.gnu.org/git/gnulib.git
	source = https://ftp.gnu.org/gnu/grep/grep-3.12.tar.gz
	source = https://ftp.gnu.org/gnu/grep/grep-3.12.tar.gz.sig

The build steps are then:

1) In the grep.git repository, link gnulib.git as a submodule. The tarball 
contains files that aren't present in git, and without this submodule you won't 
be able to generate them from source.

2) Run `./bootstrap --skip-po` in the git repository checkout, to generate the 
build system files and explicitly disable the translation downloader.

3) Run `./configure` and `make` in the git repository checkout

4) In the extracted tarball, navigate to the po/ directory and run `msgfmt` on 
each .po file to generate the respective .mo file.

5) Run `make install` in the git repository checkout that we've built our 
binaries inside of.

6) In the po/ directory of the extracted tarfile, copy each .mo file to 
/usr/share/locale/...

Some of the packages flagged in Arch Linux are on this list (but note this list 
is likely incomplete because it's difficult to search for this in an automatic way):

https://archlinux.org/todo/unstable-gnu-translations/

The files inside of `grep-3.12.tar.gz` could in theory get repacked into 
`grep-translations-3.12.tar.gz`, even though anybody could do this, this would 
ideally be done by the upstream developers themselves so the file can carry a 
valid signature.

cheers,
kpcyrd


More information about the rb-general mailing list