[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#839977: marked as done (apache2: please make the build reproducible (timestamps/timezones))



Your message dated Wed, 09 Nov 2016 23:18:55 +0000
with message-id <E1c4c8t-0002fs-5D@fasolo.debian.org>
and subject line Bug#839977: fixed in apache2 2.4.23-6
has caused the Debian Bug report #839977,
regarding apache2: please make the build reproducible (timestamps/timezones)
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
839977: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=839977
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems
--- Begin Message ---
Package: apache2
Version: 2.4.23-5
Severity: wishlist
Tags: patch
User: reproducible-builds@lists.alioth.debian.org
Usertags: timestamps

Dear Maintainer,

Following up on the following change in 2.4.23-5:

  * Tweak creation of .tar.gz embedded in preinst to get reproducible
    build.

The build is not yet reproducible; a further tweak is required:

[[[
diff --git a/debian/rules b/debian/rules
index 5a96c95..800686e 100755
--- a/debian/rules
+++ b/debian/rules
@@ -57,7 +57,7 @@ debian/fixup_conffiles.tgz: \
     debian/config-dir/mods-available/imagemap.load
 	@# mtime/owner/group/mode are for reproducible build
 	tar \
-		--mtime=2000-01-01T00:00 \
+		--mtime=2000-01-01T00:00Z \
 		--owner=root:0 \
 		--group=root:0 \
 		--mode=0644 \
]]]

Without this, the mtime is interpreted in the build environment's
timezone, causing irreproducibility.  (Another form of irreproducibility
in the package is the -fdebug-prefix-map in config.nice, but we'll fix
that globally in the reproducibility infrastructure.)

Thanks for making the package reproducible!

Cheers,

Daniel
('Z' here stands for the 'Zulu' timezone, i.e., UTC+0)

--- End Message ---
--- Begin Message ---
Source: apache2
Source-Version: 2.4.23-6

We believe that the bug you reported is fixed in the latest version of
apache2, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 839977@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Stefan Fritsch <sf@debian.org> (supplier of updated apache2 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Wed, 09 Nov 2016 23:51:25 +0100
Source: apache2
Binary: apache2 apache2-data apache2-bin apache2-utils apache2-suexec-pristine apache2-suexec-custom apache2-doc apache2-dev apache2-dbg
Architecture: source amd64 all
Version: 2.4.23-6
Distribution: unstable
Urgency: medium
Maintainer: Debian Apache Maintainers <debian-apache@lists.debian.org>
Changed-By: Stefan Fritsch <sf@debian.org>
Description:
 apache2    - Apache HTTP Server
 apache2-bin - Apache HTTP Server (modules and other binary files)
 apache2-data - Apache HTTP Server (common files)
 apache2-dbg - Apache debugging symbols
 apache2-dev - Apache HTTP Server (development headers)
 apache2-doc - Apache HTTP Server (on-site documentation)
 apache2-suexec-custom - Apache HTTP Server configurable suexec program for mod_suexec
 apache2-suexec-pristine - Apache HTTP Server standard suexec program for mod_suexec
 apache2-utils - Apache HTTP Server (utility programs for web servers)
Closes: 839977
Changes:
 apache2 (2.4.23-6) unstable; urgency=medium
 .
   * One more tweak for reproducible build. Thanks to Daniel Shahaf for the
     patch. Closes: #839977
   * Avoid building with openssl 1.1 for now. See #828236
Checksums-Sha1:
 b71284286c081b2c6abe4498fe41a9c6609d5111 2738 apache2_2.4.23-6.dsc
 af78ae5429bec20d544cf0a073fc2566a140561a 352572 apache2_2.4.23-6.debian.tar.xz
 e41dae1295574ed3b2838937f163d2c17545676f 1150018 apache2-bin_2.4.23-6_amd64.deb
 902c7b47277632d58c96766b068a2e0f88aa4cb1 162258 apache2-data_2.4.23-6_all.deb
 f6dea0c8b5d162338e800a6cc6caa86828022478 2417436 apache2-dbg_2.4.23-6_amd64.deb
 3f72eab5ce324402aa7f14732221541a53c69fee 306150 apache2-dev_2.4.23-6_amd64.deb
 b37fc80b2c1d86f21cc46a046b8abe21453869be 3753392 apache2-doc_2.4.23-6_all.deb
 4112738c9aa60c644f341f246ee887baccd105d2 148998 apache2-suexec-custom_2.4.23-6_amd64.deb
 d385cc6ba292b2385bd4163f4750dc3af2d13c83 147472 apache2-suexec-pristine_2.4.23-6_amd64.deb
 425be7f3946fd7dbf910a6de70f83003a0c13e57 211082 apache2-utils_2.4.23-6_amd64.deb
 96020cd0984dd727ab42cb1d7a10e825eac25535 8407 apache2_2.4.23-6_20161109T225420z-f94e7ad5.buildinfo
 a48b60e30257e2b092eb0c3d3b4620b754e4405f 229132 apache2_2.4.23-6_amd64.deb
Checksums-Sha256:
 fc7c1c6b5a902ec53687465a655af43ed4abd21ebcc837bd501d78a502ac00e7 2738 apache2_2.4.23-6.dsc
 0996ecd8abfe34f209484e966cb2d16086f5381c60ce3045d9be096a4452f756 352572 apache2_2.4.23-6.debian.tar.xz
 29f319f6a3a334cb303dff358fa0d5261b080a3aa91d55bd84b419dbf3579960 1150018 apache2-bin_2.4.23-6_amd64.deb
 803330d66217077faeb5056ee6b0f54080a803f48fefa7dacb695c0725265198 162258 apache2-data_2.4.23-6_all.deb
 0dbd858bff5966a4e86ad55eccb112e563cc6456c2369f74e2d999d45cd94861 2417436 apache2-dbg_2.4.23-6_amd64.deb
 8e7830881583229aafa99223a5c7483c8737584b5cb835a093764b46da71c6e2 306150 apache2-dev_2.4.23-6_amd64.deb
 38e82c478eb970688e9d5ece373fc0e8ba94cd206a5d4513c3e29c38ee20cb22 3753392 apache2-doc_2.4.23-6_all.deb
 0bc9f596d141a1c589bf99790a01f261c0bae19f744daf133c652f5fda363204 148998 apache2-suexec-custom_2.4.23-6_amd64.deb
 f486509e56d6d8792d1b913582fac3920ff64ab70ca241edfec01ec3dd181047 147472 apache2-suexec-pristine_2.4.23-6_amd64.deb
 1eae3ff21e2e491e8862222a08d62e6d10fba51d253663ff71c122235be7b2a4 211082 apache2-utils_2.4.23-6_amd64.deb
 16ea6bded472379f10c4eb816192acba7afcfc830e0fabced3df2c2636fb351f 8407 apache2_2.4.23-6_20161109T225420z-f94e7ad5.buildinfo
 5ea960c48c496828b4f6ff8aa890ffc4dd468f8c938c1091fcd0c5e059d39f94 229132 apache2_2.4.23-6_amd64.deb
Files:
 745d97ef19987bd679c0bb770dc5190b 2738 httpd optional apache2_2.4.23-6.dsc
 4aa443d1c335cea1723f6f7eac1d1633 352572 httpd optional apache2_2.4.23-6.debian.tar.xz
 025753cbf8f681f56d5458ea41c25716 1150018 httpd optional apache2-bin_2.4.23-6_amd64.deb
 5f273774f65457b864b9f91a2b65484b 162258 httpd optional apache2-data_2.4.23-6_all.deb
 96532281e86e24f56f04ed743b965845 2417436 debug extra apache2-dbg_2.4.23-6_amd64.deb
 fd3423139cda607c8bd4c9d30144d16c 306150 httpd optional apache2-dev_2.4.23-6_amd64.deb
 aa03792e69936eb646aff3e2823d6241 3753392 doc optional apache2-doc_2.4.23-6_all.deb
 d7040d51b9c75f1524581aa25884db08 148998 httpd extra apache2-suexec-custom_2.4.23-6_amd64.deb
 b183036efe7541deee487170d4931cb3 147472 httpd optional apache2-suexec-pristine_2.4.23-6_amd64.deb
 8a172399be5e217e3597723958a90fd2 211082 httpd optional apache2-utils_2.4.23-6_amd64.deb
 f94e7ad53076e0b43d81ac2b8b6b6d55 8407 httpd optional apache2_2.4.23-6_20161109T225420z-f94e7ad5.buildinfo
 5fd9f6afdbda130265fb424c82f0bc0a 229132 httpd optional apache2_2.4.23-6_amd64.deb

-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJYI6oyAAoJEMaHXzVBzv3g6LMP/RIQ1XX0EYgK14OrT3Emospm
UnkaOSEDUw+Zsq8Hw4DAL1+Ml8fLYuZQf9zO9SiG3WQVkQ+Q3yuqstVgNoCmUfe4
E1GXWyJWI3l9t5iIqnl95j3LDBaGXUbXkTyHrgkKGPvxnQKuAJBvsJrpSju/32cq
Dceeu4ecAyFZ0RDbHFrCsZrk506ujkjjiuk06PTvxfta+oXyXBcdc5dJFImnwk3Z
TK8Ta3EEpZ0APajd1N53JJoXj18LQJQlBMZfsZ9qss5B61l2ncgC5N/8nKtaNQp+
tuQdPfFuH97DtnNkECfyWLB96FewOHOSQK8tdrhjsW0QzVidwL1pFfEzzR+Y/3Uf
Lss0uWuDeHRS1v4f4EJ9Z44ru+cJrNKQLWy0dyOXZc8XpimeKnVaNxZoYxutfUJK
DAKs44Hc1KkMhEUKBTIaKIK4XVcvx1ggxG75hOerXj9Jl4iw2GhMQAJxSqA/n9ed
fhALh9Wxr21NKZFpTLYtKdpfNVWs5AErnu3thz3PTz3oMMepvolPvxcPdBEJdrkr
cg4g3A97ugv4cgsnr+NUH/WfXzd3R/yTfnjIxTaUudNUnicmiy6190SNxcCzURyF
+yGew7Syqy0M4F+jrc1vSDd/BhwnoS5Pucmm6i4POlf9Pf4JrtGwL7Q2HGsV6onZ
xXTBUhbhSyn0y4hK9CVp
=6Z8c
-----END PGP SIGNATURE-----

--- End Message ---

Reply to: