[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#1006358: libxmlb2: Ensure reproducible results when importing a node



Package: libxmlb2
Version: 0.3.6-2
Severity: wishlist
Tags: patch upstream
User: reproducible-builds@lists.alioth.debian.org
Usertags: randomness
X-Debbugs-Cc: reproducible-bugs@lists.alioth.debian.org

Dear maintainer,

While working on the “reproducible builds” effort [1], I have noticed
that libxmlb2 was using pointer addresses (%p) for generating hash-values.
I've reported this upstream [2][3], and now a new release is ready (0.3.7).

Please consider updating libxmlb2, now that appstream is also updated.
The patch for this specific issue is at [4].

With kind regards,
Roland Clobus

[1]: https://wiki.debian.org/ReproducibleBuilds
[2]: https://github.com/hughsie/libxmlb/issues/110
[3]: https://github.com/hughsie/libxmlb/pull/112
[4]:
https://github.com/hughsie/libxmlb/pull/112/commits/3ac10d25e14dcab2c68d70a735e64c8492d7584e


-- System Information:
Debian Release: bookworm/sid
  APT prefers testing
  APT policy: (990, 'testing'), (500, 'testing-debug'), (50, 'unstable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 5.16.0-1-amd64 (SMP w/8 CPU threads; PREEMPT)
Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8), LANGUAGE=en_GB:en
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages libxmlb2 depends on:
ii  libc6         2.33-6
ii  libglib2.0-0  2.70.4-1
ii  liblzma5      5.2.5-2

libxmlb2 recommends no packages.

libxmlb2 suggests no packages.

-- no debconf information

Reply to: