nmu: multiple binNMUs to fix build reproducibility

Aurelien Jarno aurel32 at debian.org
Sun May 25 15:34:40 BST 2025


Hi,

On 2025-05-25 16:12, Aurelien Jarno wrote:
> Reproducible builds are based on the assumption that the build date is
> always newer than the latest changelog entry.
> 
> Unfortunately some source packages recently got uploaded from a computer
> with the wrong time, causing the binary packages in the archive to not
> be reproducible, as this can be checked on reproduce.debian.net. They
> however appear as reproducible on tests.reproducible-builds.org as
> instead of comparing a new build to the version in the archive, it does
> two new builds and check they matches.
> 
> After doing a full check of the testing suite, I have found that this
> problem actually existed for other packages. Here is a list of binNMUs
> to fix many of them:

[ snip ]

> Unfortunately some others will require a sourceful upload as they
> include one or more arch:all packages.

I someone is interested by fixing those (I guess by doing a no change 
source upload, and then asking the release team for an unblock), here is 
the list. On my side I am not sure to have the spoons for that.

bluebrain-hpc-coding-conventions_1.0.0+git20221201-2 
cheese_44.1-5 
d-spy_48.0-3 
epiphany-browser_48.3-2 
fonts-inconsolata_001.010-6 
foomatic-db_20230202-1 
gedit_48.1-4 
golang-github-apparentlymart-go-dump_0.0~git20190214.042adf3-3 
golang-gopkg-mail.v2_2.3.1-2 
libmessage-passing-perl_0.117-1 
libwww-indexparser-perl_0.91-2 
pocsuite3_2.0.3-1 
python-pbs-installer_2025.04.09-1 
referencing_0.36.2-1 

In addition gimp_3.0.2-3 is already fixed in sid, but it requires an 
unblock from the release team.

Regards
Aurelien

-- 
Aurelien Jarno                          GPG: 4096R/1DDD8C9B
aurelien at aurel32.net                     http://aurel32.net



More information about the Reproducible-bugs mailing list