Bug#783151: [Reproducible-builds] Bug#783151: mailman: please make the build reproducibly

2015-04-22 Thread Jérémy Bobbio
* Make the package build reproducibly: +- Use install instead of cp for qmail-to-mailman.py to avoid + umask variations. + + -- Jérémy Bobbio Wed, 22 Apr 2015 21:54:14 + + mailman (1:2.1.18-2) unstable; urgency=high * Fix security issue: path traversal through local_part. diff -

Bug#783152: kmod: please make the build reproducible

2015-04-22 Thread Jérémy Bobbio
ake the package build reproducibly: +- Add revision date extracted from Git to manpages in order + to make them stable one build to another. + + -- Jérémy Bobbio Wed, 22 Apr 2015 22:06:45 + + kmod (20-1) unstable; urgency=medium * New upstream release. diff --git a

Bug#783210: glibc: please make the package build reproducibly

2015-04-23 Thread Jérémy Bobbio
t variable when running ./configure. + This is then used in nscd. +- Set the previously mentioned build date to the latest debian/changelog + entry. +- Create source tarball in a deterministic manner: adjust file + modification time, user, group, permissions, and file order. + + -

Bug#783210: glibc: please make the package build reproducibly

2015-04-23 Thread Jérémy Bobbio
Jérémy Bobbio: > 3. nscd uses the date and time of the build as a version marker. So a >patch is added to allow the build date to be set externally. The date >of the latest debian/changelog entry will be used instead of the >current time for Debian. Reiner Herrmann noti

Bug#783239: kexec-tools: please make the package build reproducibly

2015-04-24 Thread Jérémy Bobbio
changelog entry. + + -- Jérémy Bobbio Fri, 24 Apr 2015 13:46:29 +0200 + kexec-tools (1:2.0.7-5.1) unstable; urgency=medium * Non-maintainer upload. diff -Nru kexec-tools-2.0.7/debian/patches/allow-external-build-date.patch kexec-tools-2.0.7/debian/patches/allow-external-build-date.patch --- ke

Bug#783210: glibc: please make the package build reproducibly

2015-08-23 Thread Jérémy Bobbio
Aurelien Jarno: > I have just applied the part concerning point 1. For the 2 other points, > from what I have understood there are now patches for gcc to define > __DATE__ and __TIME__. So the question is should we still want to get > this changes in the glibc? In that case I would try to get these

Bug#795984: [Pkg-postgresql-public] Bug#795984: postgresql-plproxy: please make the build reproducible

2015-08-23 Thread Jérémy Bobbio
Hi Peter, Peter Eisentraut: > On 8/18/15 9:15 AM, Dhole wrote: > > The attached patch sets the timezone to UTC before calling asciidoc to > > avoid timezone differences in the generated docs. Once applied, > > postgresql-plproxy can be built reproducibly in our current experimental > > framework.

Bug#797218: O: openbgpd

2015-08-28 Thread Jérémy Bobbio
Package: wnpp Severity: normal Having openbgpd in Debian was a pretty fun experiment to show that kFreeBSD could be useful, but I actually never used it and stop caring a while ago. I'll probably ask for removal before stretch if nobody takes over. -- Lunar.''`.

Bug#797297: RM: zope-quotafolder -- ROM; dead upstream

2015-08-29 Thread Jérémy Bobbio
Package: ftp.debian.org Severity: normal Hi! There has been no new releases of zope-quotafolder since 2002. I'm not even sure it can still be used in any ways. Please remove it from Debian. -- Lunar.''`. lu...@debian.org: :Ⓐ : # apt-get ins

Bug#797525: [Reproducible-builds] Bug#797525: diffoscope: multiarch mode

2015-08-31 Thread Jérémy Bobbio
clone 797525 -1 retitle -1 diffoscope: provide option to disable fuzzy-matching thanks Hi! Jakub Wilk: > I want to use diffoscope to compare two "Multi-Arch: same" debs of the same > version but different architecture, to see differences that will cause > co-installation conflicts. > > This almos

Bug#795984: [Pkg-postgresql-public] Bug#795984: postgresql-plproxy: please make the build reproducible

2015-08-31 Thread Jérémy Bobbio
Peter Eisentraut: > Well, nothing is mandatory for building a Debian package, since you can > just assemble the archives manually. But you could say, if you want a > reproducible build, you need to use dpkg-buildpackage. We want to provide ways to reproduce an initial build. I don't consider that

Bug#806149: diffoscope TypeError processing openjfx/8u60-b27-4

2015-11-25 Thread Jérémy Bobbio
Control: merge 805774 806149 Control: tag 805774 pending Mattia Rizzolo: > Seen on rb.d.n with openjfx/8u60-b27-4 on testing (trying it on unstable > resulted with a FTBFS of the package...) Same problem as #805774. Fixed in Git. -- Lunar.''`. lu...@debian.org

Bug#806321: coreutils: please make the build reproducible (timestamps)

2015-11-26 Thread Jérémy Bobbio
ree help2man by the one in the help2man package. Add + the required Build-Depends. The in-tree help2man doesn't support + SOURCE_DATE_EPOCH. +- Set SOURCE_DATE_EPOCH to the date of the latest debian/changelog entry. + + -- Jérémy Bobbio Thu, 26 Nov 2015 12:43:39 +0100 + coreuti

Bug#806328: xz-utils: please ship xz.pot

2015-11-26 Thread Jérémy Bobbio
Source: xz-utils Version: 5.1.1alpha+20120614-2.1 Severity: wishlist User: reproducible-bui...@lists.alioth.debian.org Usertags: timestamps X-Debbugs-Cc: reproducible-bui...@lists.alioth.debian.org, sanv...@debian.org Hi! While working on the “reproducible builds” effort [1], we have noticed that

Bug#806331: xz-utils: make the selected POSIX shell stable accross build environments

2015-11-26 Thread Jérémy Bobbio
Source: xz-utils Version: 5.1.1alpha+20120614-2.1 Severity: normal User: reproducible-bui...@lists.alioth.debian.org Usertags: environment X-Debbugs-Cc: reproducible-bui...@lists.alioth.debian.org, sanv...@debian.org Hi! While working on the “reproducible builds” effort [1], we have noticed that

Bug#806891: [Reproducible-commits] [diffoscope] 01/01: Multi-file HTML output

2015-12-02 Thread Jérémy Bobbio
Joachim Breitner: > Multi-file HTML output Really great idea. :) Thanks for the initial patch! > +parser.add_argument('--jquery', metavar='url', dest='jquery_url', > +help='link to the jquery url, with --html-dir. By > default, a symlink to /usr/share/javascript/j

Bug#807084: libjs-jcrop: please make the build reproducible

2015-12-05 Thread Jérémy Bobbio
Chris Lamb: > --- a/debian/rules2015-12-05 09:42:10.758251726 +0200 > --- b/debian/rules2015-12-05 09:51:58.484426475 +0200 > @@ -1,6 +1,7 @@ > #!/usr/bin/make -f > > export JCROP_BUILD = debian/$(shell dpkg-parsechangelog --show-field Version) > +export JCROP_COPYRIGHT = $(shell date -

Bug#798325: the tag on github for the new release.

2015-10-03 Thread Jérémy Bobbio
shirish शिरीष: > I am able to see this tag > > https://github.com/EFForg/https-everywhere/releases/tag/5.1.1 > > What more is needed, can anybody share ? All previous tags were pushed on git.torproject.org. This situation is annoying. I'll see if I can make an upload from this tag. -- Lunar

Bug#780628: [Pkg-privacy-maintainers] Bug#780628: parcimonie: support gpg2

2015-10-04 Thread Jérémy Bobbio
clone 780628 -1 reassign -1 gnupg2 retitle -1 gnupg2: please add support for reaching out to keyservers through Tor tags -1 + upstream block 780628 by -1 thanks Daniel Kahn Gillmor: > > That said, it seems Werner is thinking about this problem upstream, by > > adding --use-tor and --force-tor swit

Bug#801092: [Pkg-mozext-maintainers] Bug#801092: xul-ext-https-everywhere: xul-ext-httpseverywhere still shows it is unsigned

2015-10-06 Thread Jérémy Bobbio
shirish शिरीष: > Iceweasel still shows the extension unsigned, this should not happen, > corect ? I don't know what you are talking about. Could you give me more input, please? -- Lunar.''`. lu...@debian.org: :Ⓐ : # apt-get install anarchism

Bug#797759: [Reproducible-builds] Bug#797759: diffoscope: tar.gz and tar.bz2 archives compared wrongly

2015-09-02 Thread Jérémy Bobbio
Control: retitle -1 diffoscope: implement fuzzy-matching across containers Control: severity -1 wishlist Michele Alessandrini: > When comparing tar.gz or tar.bz2 archives containing text files, some > of which different, the output is a binary diff. Perhaps it only > applies decompression and comp

Bug#797759: [Reproducible-builds] Bug#797759: Bug#797759: diffoscope: tar.gz and tar.bz2 archives compared wrongly

2015-09-02 Thread Jérémy Bobbio
Michele Alessandrini: > Il 02/09/2015 14:38, Jérémy Bobbio ha scritto: > >Control: retitle -1 diffoscope: implement fuzzy-matching across containers > >Control: severity -1 wishlist > > > >Michele Alessandrini: > >>When comparing tar.gz or tar.bz2 archives cont

Bug#797560: diffoscope: option to treat absent files as empty

2015-09-03 Thread Jérémy Bobbio
Control: tag -1 + pending Jakub Wilk: > I'd like an option for treating absent files as if they were empty, similar > to "diff -N". This has not been easy, but this will be in the next release (--new-file is the switch). -- Lunar.''`. lu...@debian.org

Bug#788364: libmagic1: misdetect some Coreboot images as text

2015-09-03 Thread Jérémy Bobbio
retitle 788364 diffoscope: garbled output when comparing some Coreboot images clone 788364 -1 reassign -1 libmagic1 severity -1 libmagic1 normal retitle -1 libmagic1: misdetect Coreboot images as text files thanks Hi Christoph, diffoscope is the tool that we have created as part of the “reproduci

Bug#797525: [Reproducible-builds] Bug#797525: diffoscope: multiarch mode

2015-09-03 Thread Jérémy Bobbio
Control: retitle -1 diffoscope: provide a way to ignore all differences in control.tar Jérémy Bobbio: > Jakub Wilk: > > I want to use diffoscope to compare two "Multi-Arch: same" debs of the same > > version but different architecture, to see differences that will

Bug#798088: linux: /proc/sys/kernel/random/write_wakeup_threshold can be set too an unreachable amount of entropy

2015-09-05 Thread Jérémy Bobbio
Package: linux-image-4.1.0-2-amd64 Severity: normal Hi! I was reported #740117 on haveged. The bug is basically that when the entropy watermark is set too high, haveged will busy loop like hell. I've worked around the issue in haveged the same way rngd does, but I believe the problem is in the ke

Bug#798224: (no subject)

2015-09-07 Thread Jérémy Bobbio
Control: tag -1 moreinfo > Subject: florence: exits when zoom in/out, does not show up when clicking > into any text box, no tray icon etc Sorry but I can't work with so little information. Could you fill in the template? > *** Reporter, please consider answering these questions, where appropri

Bug#798224: (no subject)

2015-09-07 Thread Jérémy Bobbio
colosist...@gmail.com: > Sorry for the too short report. This was the first time I used the > command line bug reporter as a necessary package is not installrd on > Debian for the GUI version. So I missed something. I will install that > and send a new report with more data. Using a different piec

Bug#798325: new upstream (5.1.1)

2015-09-08 Thread Jérémy Bobbio
Daniel Baumann: > it would be nice if you could upgrade to the current upstream version > (5.1.1). Upstream has still not pushed the tag on the Git repository. I'm asking again. -- Lunar.''`. lu...@debian.org: :Ⓐ : # apt-get install anarchis

Bug#798359: lintian: list of autopkgtest restrictions is not up-to-date

2015-09-08 Thread Jérémy Bobbio
Package: lintian Version: 2.5.36.1 Hi! It seems that the list of known restrictions for debian/tests/control is not up-to-date. Several packages raise unknown-runtime-tests-restriction [1] despite using restrictions properly listed in the reference documentation [2]. [1]: https://lintian.debia

Bug#798384: strip-nondeterminism: should preserve file permissions

2015-09-08 Thread Jérémy Bobbio
Package: strip-nondeterminism Severity: important Hi! I'm opening a bug report to track the following issue discussed on the reproducible-builds mailing list: Eugene Zhukov: > On Mon, Sep 7, 2015 at 8:11 PM, Andrew Ayer wrote: > > On Mon, 7 Sep 2015 19:49:56 +0300 > > Eugene Zhukov wrote: > >>

Bug#798386: ITP: ruby-network-interface -- Ruby library to get network interface information

2015-09-08 Thread Jérémy Bobbio
Package: wnpp Severity: wishlist Owner: Jérémy Bobbio * Package name: ruby-network-interface Version : 0.0.1 Upstream Author : Brandon Turner, Lance Sanchez * URL : https://github.com/rapid7/network_interface * License : Expat Programming Lang: Ruby

Bug#778681: Add Recommends dep (ruby-redcarpet) for rendering README

2015-09-12 Thread Jérémy Bobbio
Hi Rowan, First, I owe you big apologies for taking so long to reply to your patches. I shall buy you a $BEVERAGE if we meet one day. Rowan Thorpe: > Following on from the patches I provided for bug #774859 and then for #774944 > this patch just adds ruby-redcarpet as a Recommends, as it is used

Bug#778754: Add defaults file, improve init script

2015-09-12 Thread Jérémy Bobbio
Hi! Rowan Thorpe: > This is another patchset following from patches I provided for #774859 and > then > #774944. The first patch adds a defaults file with "VERBOSE='yes'", handling > in > the init script for defaults overrides, and extra typical initscript > sanity-checking and instructional com

Bug#802466: man refers to missing control-spec.txt

2015-10-20 Thread Jérémy Bobbio
Jean-Michel Vourgère: > I'd like to switch virtual circuits in some cases. > > I can do that interactively using vidalia "New identity" option. So I looked > in the manual how it's done. But tor manual says "using the Tor Control > Protocol (described in control-spec.txt)." It's unrelated to this

Bug#719845: [PATCH] Deterministic file order for control and data archives

2015-10-08 Thread Jérémy Bobbio
Jérémy Bobbio: > Jérémy Bobbio: > > Jérémy Bobbio: > > > Here are four patches based on the current master (1e059955) that will > > > write files in deterministic order in the control and data archives. > > > File names are sorted by forking `sort` before bei

Bug#801329: dpkg: scripts/t/mk.t uses system modules to compute reference values

2015-10-08 Thread Jérémy Bobbio
Source: dpkg Version: 1.18.3 Severity: normal Tags: patch Hi! scripts/t/mk.t will shell out to dpkg-architecture.pl and dpkg-buildpackage.pl. Both scripts are called from the current development tree. But they will use Perl modules to compute some of their values. As PERL5LIB is not set, system m

Bug#759886: debhelper: please make mtimes of packaged files deterministic

2015-10-12 Thread Jérémy Bobbio
Lunar: > The attached patch will add a new helper `dh_fixmtimes`, largely > inspired by `dh_fixperms`, that will change the modification time of any > file that has been created later than the time of the latest > debian/changelog entry to the time of the latest debian/changelog entry. A quick upd

Bug#801333: retitle

2015-10-14 Thread Jérémy Bobbio
retitle 801333 diffoscope: UnicodeDecodeError with haskell-authenticate-oauth/1.5.1.1-4 clone 801333 -1 retitle -1 diffoscope: UnicodeDecodeError in test_text_option_with_file severity -1 minor thanks Holger Levsen: > someone just reported the same problem on irc: […] It was not the same problem

Bug#801855: ongl: test strings depend on default character encoding of the build system

2015-10-15 Thread Jérémy Bobbio
Source: ognl Version: 2.7.3-6 Severity: minor User: reproducible-bui...@lists.alioth.debian.org Usertags: locale Hi! It seems that depending on the build system default character encoding, the non-ASCII characters in org/ognl/test/QuotingTest.java might get mistranslated. This also prevents ongl

Bug#788568: [Reproducible-builds] Bug#788568: debbindiff: leaves temporary files under /tmp

2015-06-13 Thread Jérémy Bobbio
Hi! Mattia Rizzolo: > In jenkins.d.n i can see this: > > mattia@jenkins ~ % find /tmp -maxdepth 1 -name tmp*debbindiff | xargs ls -ld > drwx-- 2 jenkins jenkins 4096 Jun 8 12:02 /tmp/tmp114lHtdebbindiff > drwx-- 2 jenkins jenkins 4096 Jun 4 17:58 /tmp/tmp12TNVEdebbindiff > drwx-- 2

Bug#782905: [Reproducible-builds] Bug#782905: seabios: please make seabios build reproducible

2015-06-14 Thread Jérémy Bobbio
Control: tag -1 - patch Holger Levsen: > On Sonntag, 19. April 2015, Lunar wrote: > > While working on the “reproducible builds” effort [1], we have noticed > > that seabios could not be built reproducibly. > > upstream is working on fixing this, see > http://www.seabios.org/pipermail/seabios/20

Bug#719845: [PATCH] Deterministic file order for control and data archives

2015-06-24 Thread Jérémy Bobbio
Jérémy Bobbio: > Jérémy Bobbio: > > Here are four patches based on the current master (1e059955) that will > > write files in deterministic order in the control and data archives. > > File names are sorted by forking `sort` before being piped to `tar`. > > Attached are

Bug#780280: dak: generate rejection mail for mails with expired signature

2015-11-13 Thread Jérémy Bobbio
Ansgar Burchardt: > It would be nice if dak would generate rejection mails for uploads that > have a valid signature, but where the signature is expired or from an > expired key. It would not only be nice, it would help not being trapped in very silly situation: files uploaded with a valid signatu

Bug#765494: dpkg-dev: dpkg-buildpackage should allow hooks to be specified via environment variable or configuration file

2015-11-14 Thread Jérémy Bobbio
Guillem Jover: > On Wed, 2014-10-15 at 17:48:01 +0200, Axel Beckert wrote: > > Package: dpkg-dev > > Version: 1.17.18 > > Severity: wishlist > > > according to dpkg-buildpackage's man page there seems no other way to > > specify hooks as via the --hook-* commandline parameter. > > > > If I'm righ

Bug#789715: simgrid: please make the build reproducible

2015-06-28 Thread Jérémy Bobbio
Martin Quinson: > On Wed, Jun 24, 2015 at 11:09:47AM +0200, marivalen wrote: > > Using `GZIP=-9n cmake -E tar` does not work. It seems that cmake does > > not pass environment variables to the command it runs. This explains the > > introduction of the env cmake command. > > What about patching the

Bug#790415: tar: please add --clamp-mtime to only update mtimes after a given time

2015-06-29 Thread Jérémy Bobbio
Package: tar Version: 1.27.1-2 Severity: wishlist Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: toolchain timestamps Hi! Within the “reproducible builds” effort [1], we are always trying to find better solutions to make it either to create determenistic build systems. O

Bug#790490: python-rpm: fail to load when rpm-common is not installed

2015-06-29 Thread Jérémy Bobbio
Package: python-rpm Version: 4.12.0.1+dfsg1-2 Severity: serious Hi! python-rpm is unusable when rpm-common is not installed: # pbuilder --login # apt-get install python-rpm # python Python 2.7.10 (default, Jun 1 2015, 16:21:46) [GCC 4.9.2] on linux2 Type "help", "copyright", "credits" or "lice

Bug#790868: [Reproducible-builds] Bug#790868: sbuild: Please allow sbuild to use a deterministic build path to build packages

2015-07-02 Thread Jérémy Bobbio
Hi! Maria Valentina Marin: > The attached patch allows users to specify a deterministic build path by > using the new command line option --build-path or the configuration > variable $build_path in the ~/.sbuilrc. I don't know enough of sbuild to comment on the patch, but: > +.BR \-\-build\-path

Bug#791455: [Pkg-anonymity-tools] Bug#791455: obfs4proxy: Unable to install/configure obfs4proxy

2015-07-05 Thread Jérémy Bobbio
Control: reassign -1 adequate shirish: > I dunno if this is related or not to #777245 but was unable to install > it on a client machine. > […] > E: Problem executing scripts DPkg::Post-Invoke 'adequate --help >/dev/null > 2>&1 || exit 0; DEBIAN_FRONTEND=readline exec adequate --debconf --user >

Bug#791533: python-lmdb: typo in package description

2015-07-05 Thread Jérémy Bobbio
Package: python-lmdb Version: 0.86-1 Severity: minor Hi! The package description reads “Python binding for LMDB Lightning Memory-Mapped Database”. Meanwhile, the first line of the extended description contains “Lighting Memory-Mapped Database (LMDB)”. I guess either there's an extra 'n' or one m

Bug#762388: ifupdown: please make method order deterministic when generating C code

2014-09-21 Thread Jérémy Bobbio
w + + * Output methods in stable order when generating C code to make +builds reproducible. + + -- Jérémy Bobbio Sun, 21 Sep 2014 18:19:56 + + ifupdown (0.7.48.1) unstable; urgency=low * Add --ignore-errors option. diff -Nru ifupdown-0.7.48.1/defn2c.pl ifupdown-0.7.48.2~reproduc

Bug#762397: libgpg-error: please do not capture the current time during the build process

2014-09-21 Thread Jérémy Bobbio
build timestamp in order +to get reproducible builds. + + -- Jérémy Bobbio Sun, 21 Sep 2014 20:37:15 + + libgpg-error (1.16-1) unstable; urgency=medium * New upstream release diff -Nru libgpg-error-1.16/debian/patches/series libgpg-error-1.16/debian/patches/series --- libgpg-er

Bug#762433: lsof: please stop capturing environment information during the build process

2014-09-22 Thread Jérémy Bobbio
@@ +lsof (4.86+dfsg-1.0reproducible1) UNRELEASED; urgency=medium + + * Allow LSOF_CCDATE to be overriden by an environment variable. + * Ensure build reproducibility by preventing Configure to capture +username, hostname, kernel version, and build time. + + -- Jérémy Bobbio Mon, 22 Sep 2014

Bug#762397: [Reproducible-builds] Bug#762397: libgpg-error: please do not capture the current time during the build process

2014-09-22 Thread Jérémy Bobbio
Jeroen Dekkers: > Jérémy actually already wrote a patch for dpkg-buildpackage to export > DEB_BUILD_TIMESTAMP: > > https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=75 > > But if we want to push these things upstream, wouldn't it be better to > remove the DEB_ prefix from the name of the envi

Bug#762622: discount: please mangle email addresses deterministically

2014-09-23 Thread Jérémy Bobbio
Package: discount Version: 2.1.7-1 Severity: wishlist Tags: patches Forwarded: https://github.com/Orc/discount/pull/112 User: reproducible-bui...@lists.alioth.debian.org Usertags: randomness Hi! As part of the “reproducible builds” project [1], we have identified that currently discount output wa

Bug#762622: [Reproducible-builds] Bug#762622: discount: please mangle email addresses deterministically

2014-09-23 Thread Jérémy Bobbio
Control: tags -1 + patch Jérémy Bobbio: > The attached patch changes the `mangle()` function accordingly. For real, this time. -- Lunar.''`. lu...@debian.org: :Ⓐ : # apt-get inst

Bug#762666: cwidget: please stop writing timestamps in Doxygen generated documentation

2014-09-24 Thread Jérémy Bobbio
ckage builds to be reproducible. + + -- Jérémy Bobbio Wed, 24 Sep 2014 09:05:52 + + cwidget (0.5.17-1) unstable; urgency=medium * New upstream release diff -Nru cwidget-0.5.17/debian/patches/do-not-write-timestamps-in-documentation cwidget-0.5.17/debian/patches/do-not-write-timestamps-i

Bug#762674: python-apt: please don't embed the date and time of the build in apt_pkg

2014-09-24 Thread Jérémy Bobbio
ME as they make the build + unreproducible. + + -- Jérémy Bobbio Wed, 24 Sep 2014 10:08:36 + + python-apt (0.9.3.10) unstable; urgency=medium * python/tag.cc: ensure that the final \n is there when diff -Nru python-apt-0.9.3.10/python/apt_pkgmodule.cc python-apt-0.9.3.10.0reproducible1/python/ap

Bug#762732: libdebian-installer: please do not write timestamps in Doxygen generated documentation

2014-09-24 Thread Jérémy Bobbio
te timesamps in Doxygen generated documentation for +reproducibility of the build process. + + -- Jérémy Bobbio Wed, 24 Sep 2014 19:08:26 + + libdebian-installer (0.96) unstable; urgency=medium * arm64: Detect UEFI based systems as "efi" subarch. diff -Nru libdebian-insta

Bug#719845: [PATCH] Deterministic file order for control and data archives

2014-08-28 Thread Jérémy Bobbio
Hi! Jérémy Bobbio: > Here are four patches based on the current master (1e059955) that will > write files in deterministic order in the control and data archives. > File names are sorted by forking `sort` before being piped to `tar`. Attached are the same patches rebased on the curre

Bug#759886: debhelper: please make mtimes of packaged files deterministic

2014-08-30 Thread Jérémy Bobbio
Package: debhelper Version: 9.20140817 User: reproducible-bui...@lists.alioth.debian.org Usertags: toolchain, timestamps X-Debbugs-Cc: reproducible-bui...@lists.alioth.debian.org Hi! As part of the “reproducible builds” project [1], it would be great to get the files shipped in the Debian package

Bug#759886: debhelper: please make mtimes of packaged files deterministic

2014-08-30 Thread Jérémy Bobbio
quot;! \\( $dh{EXCLUDE_FIND} \\)"; + } + + complex_doit("find $tmp -newermt '$dh{DATE}' $find_options -print0", + "2>/dev/null | xargs -0r touch --no-dereference --date='$dh{DATE}'"); +} + +=head1 SEE ALSO + +L + +This program is a part of debhelper

Bug#759895: debhelper: please strip non-deterministic data from static libraries

2014-08-30 Thread Jérémy Bobbio
Package: debhelper Version: 9.20140817 Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: toolchain, timestamps X-Debbugs-Cc: reproducible-bui...@lists.alioth.debian.org Hi! Currently, static libraries shipped in Debian package capture the time when the package is built. As p

Bug#759999: dpkg: please set reproducible timestamps in .deb ar file headers

2014-08-30 Thread Jérémy Bobbio
Package: dpkg Version: 1.17.14 Severity: wishlist Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: toolchain, timestamps X-Debbugs-Cc: reproducible-bui...@lists.alioth.debian.org Hi! `.deb` are ar archives. The archive internal headers currently capture the time when the bu

Bug#760075: torsocks: SIGSEGV with torsocks 2.0.0 on some browsers, failure to anonimize others

2014-08-31 Thread Jérémy Bobbio
js: > I upgraded torsocks from the 1.3.3 to 2.0.0 and it either SIGSEV on some > browsers > or else fails to anonimize others (in other words, running under tor they > cannot > access sites blocked by my firewall) Please be aware that browsing the web with anything else than the Tor Browser is n

Bug#759895: [debhelper-devel] Bug#759895: debhelper: please strip non-deterministic data from static libraries

2014-08-31 Thread Jérémy Bobbio
Joey Hess: > Jérémy Bobbio wrote: > > Currently, static libraries shipped in Debian package capture the time > > when the package is built. As part of the “reproducible builds” > > project [1], it would be great to have static libriaries normalized. > > > > The a

Bug#759886: [debhelper-devel] Bug#759886: debhelper: please make mtimes of packaged files deterministic

2014-08-31 Thread Jérémy Bobbio
Joey Hess: > Do you have a plan to get packages not using dh or cdbs to use this new > command? Its heart is a single find+xargs+touch command. I had in mind that packages not using dh or cdbs could have their own way on how to make the mtimes deterministic. Possibly by adding such a find command

Bug#760594: ITP: golang-siphash-dev -- Go implementation of SipHash-2-4

2014-09-05 Thread Jérémy Bobbio
Package: wnpp Severity: wishlist Owner: Jérémy Bobbio X-Debbugs-Cc: pkg-anonymity-to...@lists.alioth.debian.org * Package name: golang-siphash-dev Version : 1.0.0 Upstream Author : Dmitry Chestnykh * URL : https://github.com/dchest/siphash * License

Bug#760595: ITP: golang-ed25519-dev -- Go implementation of Ed25519 signature algorithm

2014-09-05 Thread Jérémy Bobbio
Package: wnpp Severity: wishlist Owner: Jérémy Bobbio X-Debbugs-Cc: pkg-anonymity-to...@lists.alioth.debian.org * Package name: golang-ed25519-dev Version : HEAD Upstream Author : Adam Langley * URL : https://github.com/agl/ed25519 * License : BSD-3

Bug#760596: ITP: obfs4proxy -- pluggable transport proxy for Tor, implementing obfs4

2014-09-05 Thread Jérémy Bobbio
Package: wnpp Severity: wishlist Owner: Jérémy Bobbio X-Debbugs-Cc: pkg-anonymity-to...@lists.alioth.debian.org * Package name: obfs4proxy Version : 0.0.1 Upstream Author : Yawning Angel * URL : https://gitweb.torproject.org/pluggable-transports/obfs4.git

Bug#757234: xul-ext-https-everywhere: update Debian rules from master and my patches

2014-08-12 Thread Jérémy Bobbio
Paul Wise: > I've been submitting changes to the rules for debian.org/debian.net as > DSA add more SSL-enabled domains[1]. I'm not sure if upstream will make > a release containing them in time for the jessie release so I thought I > would submit a diff against 3.5.3 so we can at least have recent

Bug#766384: debhelper: please register conffiles in a stable order

2014-10-22 Thread Jérémy Bobbio
Package: debhelper Version: 9.20141010 Severity: wishlist Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: toolchain fileordering Hi! As part of the “reproducible builds” effort [1], we have noticed that dh_installdeb is registering conffiles depending on the file system or

Bug#766736: geoip-database: outdated license information; more databases could be in main!

2014-10-25 Thread Jérémy Bobbio
Package: geoip-database Hi! According to , “The GeoLite databases are distributed under the Creative Commons Attribution-ShareAlike 3.0 Unported License”. This probably means that debian/copyright should be updated. But this also means that all GeoLi

Bug#762854: groff: please provide a way to specify a creation date

2014-09-25 Thread Jérémy Bobbio
Package: groff Version: 1.22.2-8 Severity: wishlist User: reproducible-bui...@lists.alioth.debian.org Usertags: toolchain timestamps Hi! For the reasons outlined in , it would be great if groff could be given a creation date instead

Bug#762666: cwidget: please stop writing timestamps in Doxygen generated documentation

2014-09-27 Thread Jérémy Bobbio
Manuel A. Fernandez Montecelo: > > As part of the “reproducible builds” project [1], we have discovered > > that the documentation generated by Doxygen during cwidget build process > > contained timestamps. > > > > Together with #762622, this prevents cwidget builds to be reproducible. > > We belie

Bug#763328: [Reproducible-builds] Bug#763328: RFP: reproducible/misc.git

2014-09-30 Thread Jérémy Bobbio
Control: retitle -1 RFP: debbindiff Holger Levsen: > please package git.debian.org/git/reproducible/misc.git - I mostly care about > having the diffp tool installable via apt-get, so maybe move this into an > existing package instead? But then I believe the other stuff is also useful, > hence t

Bug#763699: keepassx: please use source mtime as creation date when generating icons

2014-10-01 Thread Jérémy Bobbio
dium + + * Non-maintainer upload. + * Use source file mtime as creation and modfication time while converting +icons for build reproducibility. + + -- Jérémy Bobbio Wed, 01 Oct 2014 21:54:51 + + keepassx (0.4.3+dfsg-0.1) unstable; urgency=high * Non-maintainer upload. diff -Nru

Bug#763822: ftp.debian.org: please include .buildinfo file in the archive

2014-10-02 Thread Jérémy Bobbio
Package: ftp.debian.org Severity: wishlist User: ftp.debian@packages.debian.org Usertags: archive Hi! As part of the “reproducible builds” effort [1], we came up with the idea of a new control file, currently named “.buildinfo” .buildinfo files would capture from the build environment as muc

Bug#765343: systemd: localed wrote a /etc/default/keyboard withouth XKBMODEL

2014-10-14 Thread Jérémy Bobbio
Package: systemd Version: 215-5+b1 Hi! What happened: 1. Install Debian with GNOME desktop using Jessie d-i beta 2. 2. Upgrade to sid. 3. Add new layouts in Input Sources through the Region & Language interface. 4. Install Plymouth. 5. Restart. 6. Be unable to enter disk passphrase. I hadn't

Bug#769844: linux: please make linux build reproducibly

2014-11-16 Thread Jérémy Bobbio
Source: linux Version: 3.16.7-2 Severity: wishlist User: reproducible-bui...@lists.alioth.debian.org Usertags: timestamps randomness Control: block -1 by 759886 Hi! I have been doing some experimentation on making linux build reproducibly [1]. With the attached patches, we are down to three binar

Bug#769844: linux: please make linux build reproducibly

2014-11-17 Thread Jérémy Bobbio
Bastian Blank: > On Mon, Nov 17, 2014 at 12:46:45AM +0100, Jérémy Bobbio wrote: > > The first patch adds call to `dh_strip_nondeterminism` and > > `dh_fixmtimes`, both being part of the custom toolchain currently used > > for reproducible builds. Hence not tagging the b

Bug#769893: ghc: Make compilation deterministic

2014-11-17 Thread Jérémy Bobbio
user reproducible-bui...@lists.alioth.debian.org usertags 769893 + toolchain randomness Joachim Breitner: > > It'd be much appreciated if this was applied to 7.6.3, which would affect > > > 300 > > Haskell packages that are currently not reproducible. > > glad to hear this! Very good news! :)

Bug#813052: [Reproducible-builds] Bug#813052: Bug#813052: diffoscope takes more than an hour on foreign arch libc6

2016-02-05 Thread Jérémy Bobbio
Hi Helmut, Helmut Grohne: > On Fri, Jan 29, 2016 at 03:11:55PM +0100, Jérémy Bobbio wrote: > > Helmut Grohne: > > > Even though I cannot reproduce the issue at hand, I think that the code > > > adding automatic debug symbols looks fishy to me. It appears to recurse &g

Bug#800774: ic2-tools: python3 support etc

2016-02-05 Thread Jérémy Bobbio
/changelog 2014-03-02 22:32:21.0 + +++ i2c-tools-3.1.1/debian/changelog 2016-02-05 11:45:15.0 + @@ -1,3 +1,9 @@ +i2c-tools (3.1.1-1.0~python3) UNRELEASED; urgency=medium + + * Add support for Python 3 inspired by the Raspbian package. + + -- Jérémy Bobbio Fri, 05 Feb 2016

Bug#814832: libpgm: please make the build reproducible (timestamps)

2016-02-15 Thread Jérémy Bobbio
URCE_DATE_EPOCH + in the environment. More details can be found on: + https://reproducible-builds.org/specs/source-date-epoch/ +Author: Jérémy Bobbio + +--- libpgm-5.1.118-1~dfsg.orig/openpgm/pgm/version_generator.py libpgm-5.1.118-1~dfsg/openpgm/pgm/version_generator.py +@@ -4,8 +4,9 @@ imp

Bug#814883: lcms2: please add a way for clients to set the creation date/time in profile headers

2016-02-16 Thread Jérémy Bobbio
escription: add cmsSetHeaderCreationDateTime + Clients might want to set an explicit value for the creation date/time + of a profile, e.g. to match the creation date/time of a description + file. +Author: Jérémy Bobbio + +--- lcms2-2.6.orig/include/lcms2.h lcms2-2.6/include/lcms2.h +@@ -1446,6 +1

Bug#813052: [Reproducible-builds] Bug#813052: Bug#813052: Bug#813052: Bug#813052: diffoscope takes more than an hour on foreign arch libc6

2016-02-16 Thread Jérémy Bobbio
Steven Chamberlain: > With your patch, it doesn't recurse any more. Thanks for the feedback! :) > But it will still stat() everything in the containing directory, > looking for .debs. It also opens some files and reads them - even > decompressing random .gz files along the way! Are you sure tha

Bug#813052: [Reproducible-builds] Bug#813052: Bug#813052: diffoscope takes more than an hour on foreign arch libc6

2016-02-17 Thread Jérémy Bobbio
Steven Chamberlain: > > Anyway, I've just pushed another patch to filter by filenames before > > looking at content. This should further improve the situation. > > I don't think it worked? It's still doing as before, looking at > text, gzip files and validating the sha1sums in a .buildinfo: > >

Bug#813023: flash-kernel: quoting error with bootargs in generic U-Boot boot script

2016-02-20 Thread Jérémy Bobbio
Ian Campbell: > Lunar -- which platform did you see an issue on and what do the above > test commands give in that case? The version in Debian: https://packages.debian.org/sid/u-boot-rpi > I'm going to push a change relating to the other suggestion here (the > ability to set a defaults before ${b

Bug#815248: liblcms2: Writes uninitialized strings when writing named colors

2016-02-20 Thread Jérémy Bobbio
e + placeholder allocated on the stack are zero'ed before a copy of the + actual string is made. + . + For consistency, we also remove unneeded extra allocated bytes in + Type_ColorantTable_Write() and Type_NamedColor_Write(). +Author: Jérémy Bobbio + +diff --git a/src/cmstypes.c b/src/cmstypes.c +in

Bug#815252: colord: please make the build reproducible (timestamps)

2016-02-20 Thread Jérémy Bobbio
Source: colord Version: 1.2.12-1 Severity: wishlist Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: timestamps Control: block -1 by 814883 Hi! While working on the “reproducible builds” effort [1], we have noticed that colord could not be built reproducibly. The attached

Bug#813023: flash-kernel: quoting error with bootargs in generic U-Boot boot script

2016-02-20 Thread Jérémy Bobbio
Ian Campbell: > On Sat, 2016-02-20 at 13:29 +0100, Jérémy Bobbio wrote: > > Ian Campbell: > > > Lunar -- which platform did you see an issue on and what do the > > > above > > > test commands give in that case? > > > > The version in Debian: https:/

Bug#813023: flash-kernel: quoting error with bootargs in generic U-Boot boot script

2016-02-20 Thread Jérémy Bobbio
Ian Campbell: > On Sat, 2016-02-20 at 14:41 +0100, Jérémy Bobbio wrote: > > Ian Campbell: > > > On Sat, 2016-02-20 at 13:29 +0100, Jérémy Bobbio wrote: > > > > Ian Campbell: > > > > > Lunar -- which platform did you see an issue on and what do the &g

Bug#813023: flash-kernel: quoting error with bootargs in generic U-Boot boot script

2016-02-20 Thread Jérémy Bobbio
Ian Campbell: > So I'm afraid I'm still not clear exactly what issue you are seeing. > > Please can you post: > > * the contents of your /boot/cmdline.txt > * the contents of the flash kernel db entry you have added for the >RPi2 > * the resulting generated boot.scr. > * a full serial con

Bug#815171: diffoscope: build time tests fail on armhf

2016-02-21 Thread Jérémy Bobbio
Control: retitle -1 diffoscope: tests for directory are brittle Control: severity -1 normal Holger Levsen: > diffoscope fails to build from source in unstable/armhf but has > successfully built in the past: […] > […] > tests/comparators/test_directory.py:53: AssertionError > […] > tests/comparato

Bug#806493: closed by Yaroslav Halchenko (Bug#806493: fixed in cython 0.23.4+git4-g7eed8d8-1)

2016-02-21 Thread Jérémy Bobbio
Debian Bug Tracking System: > This is an automatic notification regarding your Bug report > which was filed against the src:cython package: > > #806493: cython: please make the output reproducible > > It has been closed by Yaroslav Halchenko . Sadly, this doesn't seem to fix all issues: https://

Bug#815252: colord: please make the build reproducible (timestamps)

2016-02-21 Thread Jérémy Bobbio
Christopher James Halse Rogers: > Thanks for the patches! I'll add the necessary autofoo checks and propose > them upstream. Great! :) Do you have any contacts with lcms2 upstream? Because I guess they would need to accept the required patch as well before it makes sense to write such a test. It'

Bug#797778: Please package pyroute2 >= 0.3.10

2016-02-21 Thread Jérémy Bobbio
Hi Florian, I also would like to see an updated version of pyroute2 in Debian as I'd like to use it to fiddle with ipsets. Florian Pelgrim: > I will update the package soon. > Guess this will be done next week. Do you need any help to do the update? Thanks, -- Lunar

Bug#815171: [Reproducible-builds] Bug#815171: Bug#815171: diffoscope: build time tests fail on armhf

2016-02-22 Thread Jérémy Bobbio
Holger Levsen: > I dont see why this should be a normal bug, ftbfs are > serious by default. Because it's just a test that is brittle. It doesn't affect normal use of the installed package and does only prevent a successful build one times out of ten. To please the cruel god of FTBFS I can also

<    1   2   3   4   5   6   7   8   9   10   >