source-only builds and .buildinfo
bunk at debian.org
Wed Jun 21 11:16:00 UTC 2017
On Wed, Jun 21, 2017 at 09:30:14AM +0000, Holger Levsen wrote:
> trigger warning: nitpicking.
> On Wed, Jun 21, 2017 at 11:34:17AM +0300, Adrian Bunk wrote:
> > > I do source-only uploads because i don't want the binaries built on my
> > > own personal infrastructure to reach the public. But i want to upload
> > > the .buildinfo because i want to provide a corroboration of what i
> > > *expect* the buildds to produce.
> > If you expect that, then your expectation is incorrect.
> I actually think that dkg's expectation is right, "just" that reality is wrong.
> The design of the Debian buildd network is from times when machines were much
> less powerful than what we have today and it shows.
> I'd rather have deterministic builds than the current unpredictable mess.
I understand what you want, but using buildinfo is not a good idea here.
Based on how many broken binaries get uploaded from developers,
the environment of the person uploading the sources is not a good
basis for determining what package versions to install when building
on the buildds.
"Is there not promise of rain?" Ling Tan asked suddenly out
of the darkness. There had been need of rain for many days.
"Only a promise," Lao Er said.
Pearl S. Buck - Dragon Seed
More information about the Reproducible-builds