3 ms·
Slight misunderstanding in the blog post there. > Archlinux is 78% reproducible on amd64 packages > Debian is 95.7% reproducible on amd64 packages This refer
by Foxboron 4y ago
Slight misunderstanding in the blog post there.
> Archlinux is 78% reproducible on amd64 packages
> Debian is 95.7% reproducible on amd64 packages
This references the "fuzzing" infrastructure hosted by the Reproducible Builds project, and doesn't show "true" reproduction of binaries. It's designed to help us figure out where impurites occur in builds.
Proper package reproduction is much better in Arch because we don't have to care about all differences that can occur since our build systems are mostly static.
The true number hover around 86%-90%, which is better than the CI system.
https://reproducible.archlinux.org/ https://reproducible.archlinux.org/
The main issues here is regressions in compilers, build tooling and leaky abstractions that needs to be found and patched. An example is how i spent a month tracking down a gcc bug that caused cgo builds to be unreproducible.
https://go-review.googlesource.com/c/go/+/413974 https://go-review.googlesource.com/c/go/+/413974
- oflor 4y ago> This references the "fuzzing" infrastructure hosted by the Reproducible Builds project, and doesn't show "true" reproduction of binaries. It's designed to help us figure out where impurites occur in builds. I think the "fuzzing" approach is actually the correct one. The fact that build systems are static does not improve reproducibility on its own, as the idea is that the packages could be built on different systems and result in the same binaries. If I built some Arch PKGBUILDs from the official community repo, I should still get the same binary, despite the fact that my machine has a different setup from the Arch project's own infra.
- Reventlov 4y agoThanks for the details, i'll update the numbers for Arch !