Reproducible builds for Debian iso images?

Vagrant Cascadian vagrant at reproducible-builds.org
Mon Aug 10 20:52:00 BST 2020


On 2020-08-10, Garlic Gambit wrote:
> Are the Debian install and live iso images deterministically reproducible?

Unfortunately no. There has been some work in that direction, and it
would be a good thing to improve further!

Tails (which is based on Debian packages, largely) has demonstrated this
sort of thing is possible with their .iso images.

There's also the disconnect of reproducibly building an .iso out of
packages that themselves aren't reproducible, though I still see value
in it; the work can be done in parallel with fixing the individual
packages.

It can also clarify a set of packages to prioritize fixing; ones that
are used in an installer or live image form interesting package sets,
though at the moment some key packages aren't reproducible (e.g. linux's
documentation packages).


live well,
  vagrant
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 227 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/reproducible-builds/attachments/20200810/ada6c9c0/attachment.sig>


More information about the Reproducible-builds mailing list