Reproducible Builds for recent Debian security updates

2024-03-29 Thread Vagrant Cascadian
Philipp Kern asked about trying to do reproducible builds checks for recent security updates to try to gain confidence about Debian's buildd infrastructure, given that they run builds in sid chroots which may have used or built or run a vulnerable xz-utils... So far, I have not found any

Re: Arch Linux minimal container userland 100% reproducible - now what?

2024-03-29 Thread HW42
John Gilmore: > kpcyrd wrote: >> 1) There's currently no way to tell if a package can be built offline >> (without trying yourself). > > Packages that can't be built offline are not reproducible, by > definition. They depend on outside events and circumstances > in order for a third party to

Re: Arch Linux minimal container userland 100% reproducible - now what?

2024-03-29 Thread John Gilmore
kpcyrd wrote: > 1) There's currently no way to tell if a package can be built offline > (without trying yourself). Packages that can't be built offline are not reproducible, by definition. They depend on outside events and circumstances in order for a third party to reproduce them

Re: Arch Linux minimal container userland 100% reproducible - now what?

2024-03-29 Thread kpcyrd
On 3/29/24 6:48 AM, John Gilmore wrote: John Gilmore wrote: Bootstrappable builds are a different thing. Worthwhile, but not what I was asking for. I just wanted provable reproducibility from two ISO images and nothing more. I was asking that a bare amd64 be able to boot from an Arch Linux

The upstream xz repository and the xz tarballs have been backdoored

2024-03-29 Thread kpcyrd
https://www.openwall.com/lists/oss-security/2024/03/29/4 Exciting times

Re: Two questions about build-path reproducibility in Debian

2024-03-29 Thread James Addison via rb-general
Hi again, On Mon, 11 Mar 2024 at 18:24, James Addison wrote: > > Hi folks, > > On Wed, 6 Mar 2024 at 01:04, James Addison wrote: > > [ ... snip ...] > > > > The Debian bug severity descriptions[1] provide some more nuance, and that > > reassures me that wishlist should be appropriate for most

diffoscope 262 released 

2024-03-29 Thread Chris Lamb
Hi, The diffoscope maintainers are pleased to announce the release of version 262 of diffoscope. diffoscope tries to get to the bottom of what makes files or directories different. It will recursively unpack archives of many kinds and transform various binary formats into more human-readable