Your message dated Sun, 25 Aug 2024 08:34:38 +0000
with message-id <[email protected]>
and subject line Bug#1079041: fixed in apg 2.2.3.dfsg.1-7
has caused the Debian Bug report #1079041,
regarding apg: please make the build reproducible
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1079041: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1079041
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: apg
Version: 2.2.3.dfsg.1-6
Severity: wishlist
Tags: patch
User: [email protected]
Usertags: timestamps
X-Debbugs-Cc: [email protected]

Hi,

Whilst working on the Reproducible Builds effort [0], we noticed that
apg could not be built reproducibly.

Although a value is passed to --mtime, as it is not prefixed by @,
tar gets confused about what date format it is in, leading to the
strange message:

   tar: Option --mtime: Treating date '1715341018' as 171534-10-18 00:00:00

This would actually still be deterministic (!) but, as it was not
parsed as a UNIX timestamp, a timezone variation is then applied.

Patch attached that adds the @.

 [0] https://reproducible-builds.org/


Regards,

-- 
      ,''`.
     : :'  :     Chris Lamb
     `. `'`      [email protected] / chris-lamb.co.uk
       `-

--- a/debian/rules      2024-08-19 10:07:43.882848830 +0100
--- b/debian/rules      2024-08-19 10:13:49.059285956 +0100
@@ -21,7 +21,7 @@
        make install INSTALL_PREFIX=$(CURDIR)/debian/apg/usr
        mv $(CURDIR)/debian/apg/usr/bin/apg $(CURDIR)/debian/apg/usr/lib/apg/apg
        tar --create --verbose --file - --directory $(CURDIR)/php/apgonline/ \
-         --clamp-mtime --mtime="$(SOURCE_DATE_EPOCH)" \
+         --clamp-mtime --mtime="@$(SOURCE_DATE_EPOCH)" \
          --mode=u=rwX,go=rX --sort=name . | gzip --no-name > php.tar.gz
        install -D --mode=0644 php.tar.gz 
$(CURDIR)/debian/apg/usr/share/doc/apg/php.tar.gz
        rm php.tar.gz

--- End Message ---
--- Begin Message ---
Source: apg
Source-Version: 2.2.3.dfsg.1-7
Done: Marc Haber <[email protected]>

We believe that the bug you reported is fixed in the latest version of
apg, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Marc Haber <[email protected]> (supplier of updated apg package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Sun, 25 Aug 2024 09:34:03 +0200
Source: apg
Architecture: source
Version: 2.2.3.dfsg.1-7
Distribution: unstable
Urgency: medium
Maintainer: Marc Haber <[email protected]>
Changed-By: Marc Haber <[email protected]>
Closes: 987952 1079041
Changes:
 apg (2.2.3.dfsg.1-7) unstable; urgency=medium
 .
   * fix wrong clamp-mtime expression in debian/rules.
     Thanks to Chris Lamb (Closes: #1079041)
   * apply more man page pages regarding security warnings.
     Thanks to Christoph Anton Mitterer (Closes: #987952)
Checksums-Sha1:
 996ce15bb4832a8281c349b1d531476abfb908e2 1830 apg_2.2.3.dfsg.1-7.dsc
 d52aadaeb678452f904f6343b5c028dcea9cc05e 11200 apg_2.2.3.dfsg.1-7.debian.tar.xz
 47aa8ee2115196ba7022bbaa7027c5e5736f1e1b 5664 
apg_2.2.3.dfsg.1-7_source.buildinfo
Checksums-Sha256:
 65cd166ad098318693a7da889af5e6dd0481896656bb28e5bf5f9b0118138ea3 1830 
apg_2.2.3.dfsg.1-7.dsc
 b0ad9f6ad18e8ed5ad32b4cf359438f57eda4dce071664fa5f7a359537132bc6 11200 
apg_2.2.3.dfsg.1-7.debian.tar.xz
 b001b17249e8da0c08616c5b7fe5bc7882cb9efa0c080b8f5cbb11802dcf2032 5664 
apg_2.2.3.dfsg.1-7_source.buildinfo
Files:
 d23fe6ff5695f87a0de40a13a767f762 1830 admin optional apg_2.2.3.dfsg.1-7.dsc
 479338431f72b0955d3ae001c5de73b5 11200 admin optional 
apg_2.2.3.dfsg.1-7.debian.tar.xz
 2a520f0e9d3f0a85b74ce589ddd50760 5664 admin optional 
apg_2.2.3.dfsg.1-7_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEE6QL5UJ/L0pcuNEbjj3cgEwEyBEIFAmbK45wACgkQj3cgEwEy
BEIbkBAA1KeIL97rqSWl1wxd2yTdOUNYTF4v9J/d3QmdfZAKpUPoc8rUaDLT8iXh
ATUNuAMaSuoE6vjQ+7WE3mVh8szJkEqLs8PCK05Zm8pBnZ4DnvfYT4oIRqUfJ/Uz
OBO+wGPGCZ/iYnn2D4HibEA+E4Hre0E/Kc8TuaaO3nJURDnASUnWTw7Y43/3lDng
QLLdZfISS8CZzJksgef3TQnDX0Sp0+EOnj4y81YRObJv+joL5we4Qv4tLMlp1fyN
UYNu+sqRBibYelmJ9h74XNWjGV5pwazE4Z2HJ8QpMIJ0IEvHTwIPozpzPRLD5S3Y
NCx0Xn8NPsf216xcMkMMBC5Tq8eh+ace6SJXxUK6I0aIKtth2hl/OtN3GtJBW8IZ
vEsLjco5bHz++BUH3UFrxp+DgcR37C0e5oQgyYxZ2QTlo0IWuA/PIgyUQcotmHTx
4Af0NUzkYYxdlRB56Wfg1lwfxdMoYqNPgVXJSIPu3WKldSdiQ4NNiSAOXLiyOJfi
VcE0j/gr76AqaJSGB16aGl2H6J8kfhU2SALaPD5px146vQIzwKSsJrTv5JAMD4IS
2BG9gsuHmlCO0ayoKadG4YB/RO5GHVeNOPmCP33PIxijL0XjimqQ2RqWMjkfanin
skB8DVGbj9a7VYOraNR3dHTIZeuErIuqPl88MSxlqfZ2j6dazJs=
=s/kj
-----END PGP SIGNATURE-----

Attachment: pgpGNferuzaNn.pgp
Description: PGP signature


--- End Message ---

Reply via email to