#1064648 allegro5-doc: please make the build reproducible.

Package:
src:allegro5
Source:
src:allegro5
Submitter:
James Addison
Date:
2024-05-09 10:21:03 UTC
Severity:
normal
Tags:
#1064648#5
Date:
2024-02-25 17:23:55 UTC
From:
To:
Dear Maintainer,

I'm an occasional volunteer contributor to the Reproducible Builds[1] project,
and noticed recently that your package allegro5-doc failed an automated Debian
package build reproducibility test[2].

There appear to be two problems that contribute to the non-reproducibility:

  * The 'Last updated' message on each page does not use the SOURCE_DATE_EPOCH
    build timestamp (you can find documentation and C code to use it here[3]).

  * When sorting example documents to reference alongside functions, the
    documentation generation code selects the top-three most popular pages to
    cross-reference, but it does not have a tie-breaker in the case of equally
    popular pages.  This means that the ordering of those examples may vary
    between builds, depending on the order in which the files are discovered
    from the filesystem.

For the latter case, it might be acceptable to use string comparison of the
filenames as a tiebreaker.

Regards,
James

[1] - https://reproducible-builds.org

[2] - https://tests.reproducible-builds.org/debian/rb-pkg/trixie/i386/diffoscope-results/allegro5.html

[3] - https://reproducible-builds.org/docs/source-date-epoch/

#1064648#10
Date:
2024-02-25 17:30:21 UTC
From:
To:
My apologies - I meant to include a link to the doc-generator comparison
function that lacks an equal-popularity sort tiebreaker.  It can be found at:

https://sources.debian.org/src/allegro5/2%3A5.2.9.1%2Bdfsg-1/docs/scripts/scan_examples.c/#L59-L61

#1064648#15
Date:
2024-02-26 18:12:09 UTC
From:
To:
Thanks for the report - I have pushed two commits to a branch of
allegro5 on github, which I would be glad if you could take a look at
and see if they seem reasonable to you, or if you can discover any
problems with them. If they're fine, I'll make a pull request upstream
and try to make a new debian package release soon(ish).

https://github.com/gusnan/allegro5/commit/e4369e13b1edb96b8ae4821c5363ac7b61002d3e
https://github.com/gusnan/allegro5/commit/842af9e5d6cd9c8fd0d0d2f8095f872e7bd77cef

best
/Andreas
gusnan@debian.org

#1064648#20
Date:
2024-02-27 10:40:25 UTC
From:
To:
Nah, my mistake, that didn't seem to fix the reproducibility - The
SOURCE_DATE_EPOCH stuff seems to work, but the other one needs more
work.

/Andreas
gusnan@debian.org

#1064648#25
Date:
2024-02-27 14:37:30 UTC
From:
To:
Hi Andreas - thanks for investigating!

Looks good - I noticed you fixed the typo already :)

Yep, also looks good to me.

Huh, strange - what differences do you find?  Two doc packages that I built a
few moments ago using reprotest here are identical -- although I did have time
variance disabled during that test.

James

#1064648#30
Date:
2024-02-27 14:59:36 UTC
From:
To:
Oh, it's quite likely that my test case is flawed and it does already
work - maybe we should just upload it and see what the reproducibility
tests say then, and handle any problems that come up then.

But, this will have to wait a while - Allegro5 is involved in the time_t
transition which has asked to avoid uploads during the transition.
(We'll have to wait a few days if I'm not mistaken).

best
/Andreas
gusnan@debian.org

#1064648#35
Date:
2024-02-27 22:29:58 UTC
From:
To:
Now I managed to build it twice and debdiff those builds which showed
no differences. So I assume the patches work fine - but we still have
the time_t transition we will have to wait for before uploading.

Meanwhile i will try to get the patches into Allegro upstream, and see
what they say about them.

/Andreas

#1064648#46
Date:
2024-05-03 12:49:17 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
allegro5, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1064648@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Andreas Rönnquist <gusnan@debian.org> (supplier of updated allegro5 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 03 May 2024 12:28:35 +0200
Source: allegro5
Architecture: source
Version: 2:5.2.9.1+dfsg-2
Distribution: unstable
Urgency: medium
Maintainer: Debian Games Team <pkg-games-devel@lists.alioth.debian.org>
Changed-By: Andreas Rönnquist <gusnan@debian.org>
Closes: 1061885 1064648
Changes:
 allegro5 (2:5.2.9.1+dfsg-2) unstable; urgency=medium
 .
   * Add patch to build reproducible (Closes: #1064648)
   * Fix mismatched override package-name-doesnt-match-sonames
   * Upgrade to Standards Versin 4.7.0 (No changes required)
   * Add myself to copyright
   * Acknowledge Non-maintainer upload (Closes: #1061885)
Checksums-Sha1:
 2b681ec825fd67d3f4e6b1c0897eb4840b4172c2 3636 allegro5_5.2.9.1+dfsg-2.dsc
 0125a46978bd9e8e102289a3f3029f1de7e9ce25 18496 allegro5_5.2.9.1+dfsg-2.debian.tar.xz
 18d13e93409aede157b4beb17899e1974c98a081 17133 allegro5_5.2.9.1+dfsg-2_source.buildinfo
Checksums-Sha256:
 e87d6cfbe93ec8f715b9872e6ebf859b71a628c8c2c4af74cf8aca0b5d05937a 3636 allegro5_5.2.9.1+dfsg-2.dsc
 9cb34c8287e9f2cea041067e513ababf7f66b0cd60a42c60e9cc979f66faef6d 18496 allegro5_5.2.9.1+dfsg-2.debian.tar.xz
 c1226fbcaac026e6d088dd3c6bb81b014ad423b5821323a256324d514206cac1 17133 allegro5_5.2.9.1+dfsg-2_source.buildinfo
Files:
 5df42c96f52c5dffa996a0d1df8a3919 3636 libs optional allegro5_5.2.9.1+dfsg-2.dsc
 af5cc0d34d43349df5fca7ebab801985 18496 libs optional allegro5_5.2.9.1+dfsg-2.debian.tar.xz
 d98c7f34e145e4e5f282677745bceae9 17133 libs optional allegro5_5.2.9.1+dfsg-2_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEETq74h7WfgJdjc9ALCHsqoZ75O8IFAmY02A0ACgkQCHsqoZ75
O8K31Q//WK/ur1w5O2qEK3MQtTvICJn3WW1LZqlRiKt4pqYqK6KcgNSxHUcfQxAC
038dQT6HxcTIF+6GZ5WWJgQJeQvdpB2JpJtt7KyLu7vRRNJpb0e2rJJD8Y39FqfQ
MMRA9nQKI/UVxJhLoy2UY2l7q/gMq0Erz/mI2v478HbsexywPyZGPlw4dE93aTSZ
rGqdSp+enpCwjDpr0rd3650vKictPJFjJgV0C4mQ7XB+pZVLjLOtwyfvoqfoJEic
DOjFWlFEPCJpWEToxIoBFTWCGOWOZkKke2ogF64nbBPTCx8HRjB4ZdYdFctq3J2B
UHWl4+b3K7Gfo8ITN5K8TsETXQxLsynGmaurANh29cVtHWhahU8nrPQtckgfqjww
mwt2LoumCsk90MAJC+VPuVDERxb4EiV3OtM0p0rUiFrpkakjG1dV6+g9JoL4XoV1
nAQEygDf1jtGnUIvK/GljLclYoXBlcDVVUGNTXhoZHj68sKqnlJKZbQmAvKuOfks
faQu+5t7FcGHMZ0FUIl1SdbeNsY7YHAA9WcBbG13LgfEmT3+HEtfwzHeDIbXoxIR
KE8bInt/97HMneDVrNaD9S/itgIBYd+PPaDfsIwklW/xLJOoI1L/VdstDHlhjA7J
jXgYGQletn45gwpWWTDR/hzixscOA8zMBjipvc5R2+deXtz9Lco=
=q6+s
-----END PGP SIGNATURE-----

#1064648#51
Date:
2024-05-09 10:17:02 UTC
From:
To:
Those fixes was obviously not enough, just see the repro reports.

The strange thing is that it according to the tests does seem to build
reproducible on arm64...

One other detail is that on armhf the only change seems to be the
architecture which is included in the ALLEGRO_PKG_HOST_SYSTEM variable.

Is there some magic like SOURCE_DATE_EPOCH to use that would avoid this
problem in this case?

best
/Andreas
gusnan@debian.org