RPM Community Forums

Mailing List Message of <rpm-devel>

Re: Mandatory/enforcing checks for "reproducible builds"

From: Jeff Johnson <n3npq@mac.com>
Date: Sun 28 Sep 2008 - 22:45:55 CEST
Message-id: <BEC11BB8-9922-42DC-A9CE-EFDB34D38416@mac.com>

On Sep 28, 2008, at 4:10 PM, R P Herrold wrote:

>>
>>
>> Opinions?
>
> The saying is:
>     If you are not the lead dog, the view never changes.
>
> Looking at:
>     https://www.redhat.com/archives/rpm-list/2003-January/ 
> msg00136.html
>
> I am pretty sure we have been on this Iditarod before. Infinite  
> looping, anyone?  ;)
>

With global warming, the race is shorter every year. ;-)

And there's no reason (imho) not to attempt a general implementation for
capturing an opaque test for build configuration now that more than  
openpkg
is attempting reproducibility hardening.

But the flaw will be "opaquely" imho, all that will be known with a  
digest
compare is that the representation is somehow different.

The digest comparison is enough to trigger a rebuild on assertion  
failure even if not generally useful.

73 de Jeff
Received on Sun Sep 28 22:46:00 2008
Driven by Jeff Johnson and the RPM project team.
Hosted by OpenPKG and Ralf S. Engelschall.
Powered by FreeBSD and OpenPKG.