#1021464 stfl: reproducible-builds: build path embedded in binaries

Package:
src:stfl
Source:
src:stfl
Submitter:
Vagrant Cascadian
Date:
2024-03-13 09:22:03 UTC
Severity:
normal
Tags:
#1021464#5
Date:
2022-10-08 23:57:56 UTC
From:
To:
The build path is embedded in various binaries:

https://tests.reproducible-builds.org/debian/rb-pkg/unstable/amd64/diffoscope-results/stfl.html

  /usr/lib/x86_64-linux-gnu/perl5/5.34/auto/stfl/stfl.so

  /build/1st/stfl-0.22/public.c:401
  vs.
  /build/2/stfl-0.22/2nd/public.c:401

The attached three patches to debian/rules fix this by adjusting the
make call to use dh_auto_make and passing CFLAGS via the CC variable,
adds -ffile-prefix-map to CFLAGS, and patches the generated
perl5/Makefile to add -ffile-prefix-map to CCFLAGS.

According to my local tests, with these patches applied, stfl should
build reproducibly on tests.reproducible-builds.org!

Thanks for maintaining stfl!

live well,
  vagrant

#1021464#10
Date:
2024-03-12 22:33:24 UTC
From:
To:
Dear Maintainer,

Because Debian builds packages from a fixed build path, neither the 'reprotest'
utility in Salsa-CI, nor the Reproducible Builds team's package test
infrastructure for Debian[1] currently check for equivalent binary package
output from differing source package build paths.

This means that your package will pass current reproducibility tests; however
we believe that source code and/or build steps still embed the build path into
the binary package output, making it more difficult than necessary for
independent consumers to check the integrity of those packages by rebuilding
them themselves.

As a result, this bugreport will remain open and be re-assigned the 'wishlist'
severity[2].

For more information about build paths and how they can affect reproducibility,
please refer to: https://reproducible-builds.org/docs/build-path/

Thanks,
James

[1] - https://tests.reproducible-builds.org/debian/reproducible.html

[2] - https://www.debian.org/Bugs/Developer#severities

#1021464#17
Date:
2024-03-13 09:18:02 UTC
From:
To:
A correction for a mistake in my previous message:

Currently the 'reprotest' job in Salsa-CI does in fact continue to exercise
variations of the build-path, and will fail if it builds binary packages that
contain different contents as a result.