On 22/12/15 17:00, Mike Gerwitz wrote:
> There is ongoing discussion about reproducible builds within GNU.  I'm
> having trouble figuring out the best approach for deterministic
> distribution archives using Automake.

I've not thought much about this, but I'm
wondering about how useful deterministic tarballs are?

The main thrust of reproducible builds is to verify what's
running on the system, and there are so many variables
between the tarball and build, that I'm not sure it's
worth worrying about non determinism in the intermediate steps?

Perhaps the main focus for tarballs should just to
ensure they're properly signed.

cheers,
Pádraig.

p.s. It would be good to give more control to upstream devs
to config archiving options in Makefile.am etc.

Reply via email to