Bug#1020736: libreswan: reproducible builds: Embeds build username and hostname in binaries

Vagrant Cascadian vagrant at reproducible-builds.org
Sun Sep 25 21:58:43 BST 2022


Source: libreswan
Version: 4.6-1
Severity: normal
Tags: patch
User: reproducible-builds at lists.alioth.debian.org
Usertags: hostname
X-Debbugs-Cc: reproducible-bugs at lists.alioth.debian.org

Ever since version 4.6-1, libreswan has been embedding the hostname in
various binaries:

  https://tests.reproducible-builds.org/debian/rb-pkg/bullseye/amd64/diffoscope-results/libreswan.html

  /usr/libexec/ipsec/_import_crl

  ./lib/libipsecconf/../../OBJ.linux.amd64.ionos5-amd64/lib/libipsecconf/lex.yy.c.tmp:1806
  vs.
  ./lib/libipsecconf/../../OBJ.linux.amd64.i-capture-the-hostname/lib/libipsecconf/lex.yy.c.tmp:1806

The attached patch fixes this by setting OBJDIR from debian/rules.

I am not positive there are not other outstanding issue, but this
*might* be enough to make libreswan build reproducibly again.

Thanks for maintaining libreswan!

live well,
  vagrant
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 0001-debian-rules-Pass-OBJDIR-to-avoid-embedding-hostname.patch
Type: text/x-diff
Size: 872 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/reproducible-bugs/attachments/20220925/8e7e4b3d/attachment.patch>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 227 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/reproducible-bugs/attachments/20220925/8e7e4b3d/attachment.sig>


More information about the Reproducible-bugs mailing list