3 ms·
They only mentioned it briefly, and not by number, but this release includes 95%+ bit-for-bit reproducibility on AMD64, ARM64, and RISC-V across more than 30,00
by morserer 1y ago
They only mentioned it briefly, and not by number, but this release includes 95%+ bit-for-bit reproducibility on AMD64, ARM64, and RISC-V across more than 30,000 packages (92% mean across all architectures).
Congratulations to the team--phenomenal work!
https://reproduce.debian.net/ https://reproduce.debian.net/
- guerby 1y agoIs there a tool on a given debian trixie system to know what installed packages are not currently reproducible? Alternative to parsing the reproduce web site :)
- morserer 1y agoYes! From the site: sudo apt install debian-repro-status; debian-repro-status
- MuffinFlavored 1y agoCould you help me understand why the remaining 5% is not bit-for-bit reproducible? For example... if you download a tar of sources pinned to a version, and you run `./configure` and `make` in some kind of container and it doesn't embed some kind of timestamp... why are 95% reproducible and some aren't? Would like to learn/understand.
- JonChesterfield 1y agoHashtables keyed off the address of objects would be an example. On multiple runs, malloc gives out different addresses (thanks to threads or security concerns) which means things end up in different slots in the table. Then you iterate through it in memory order and you're seeing objects in non-deterministic order, which you do things with. Embedding file paths / timestamps / git shas and similar was popular for a while too and unhelpful for reproducible builds.