2 ms·
> Archlinux's PKGBUILD doesn't https://github.com/archlinux/svntogit-community/blob/cf04bef https://github.com/archlinux/svntogit-community/blob/cf04bef... > Be
by Foxboron 4y ago
> Archlinux's PKGBUILD doesn't https://github.com/archlinux/svntogit-community/blob/cf04bef https://github.com/archlinux/svntogit-community/blob/cf04bef...
> Because of that, "docker version" on arch linux outputs that it was built on the actual day it was built, whenever that was, and each time it's built that string changes. Hence, not reproducible.
Fwiw, I'm the maintainer of Docker on Arch and this is a bit more complicated.
Arch doesn't need to care about build time because `pacman` sets `SOURCE_DATE_EPOCH` during package building which is then utilized by the docker build system.
https://github.com/moby/moby/commit/760763e9957840f1983a5006f4e66d6920ec496e https://github.com/moby/moby/commit/760763e9957840f1983a5006...
If you look at the diff from an actual reproduction of the `docker` package (the Debian Reproducible Builds CI is a fuzzer), you will see there is no issues around build time.
https://reproducible.archlinux.org/api/v0/builds/359851/diffoscope https://reproducible.archlinux.org/api/v0/builds/359851/diff...
What you do see is some weird differences around `NT_GNU_BUILD_ID` and `GO BUILDID`.
This is because of `lto`. In Arch we try to build most Go packages with cgo for the purpose of utilizing hardening flags. The issue is that the C code generation in Golang isn't actually reproducible with `lto` enabled.
One issue is what I submitted here; https://github.com/golang/go/pull/53528 https://github.com/golang/go/pull/53528
Another issue which I have been trying to debug is why the code snippet located here doesn't reproduce.
https://pub.linderud.dev/cg/ https://pub.linderud.dev/cg/
This results in the BUILDID generated and sat by the cgo build process isn't reproducible.
I could disable lto and all the binary hardening and docker would probably be reproducible, but where is the fun in that :)?
- TheDong 4y agoNeat, thanks for the explanation and links! Sorry for being so off the mark there for your package, though my incorrect understanding I think did allow for a good explanation of what reproducibility is about and one thing that commonly fails!
- Foxboron 4y agoNo worries :) I should blog more about these things so people do get better insight into obscure issues like the one above.