From: Holger Levsen <holger@layer-acht.org>
To: u-boot@lists.denx.de
Subject: [U-Boot] about reproducible builds (was Re: [PATCH v3 2/2] Makefile: Add SOURCE_DATE_TZ)
Date: Wed, 26 Aug 2015 11:29:09 +0200 [thread overview]
Message-ID: <201508261129.18281.holger@layer-acht.org> (raw)
In-Reply-To: <CAFOYHZBq-Nkf+wqcq7PHzTp85LTm+uG+hoMkFQvsBXaGTTTDEw@mail.gmail.com>
Hi Chris,
On Mittwoch, 26. August 2015, Chris Packham wrote:
> Just for my own understanding is the "reproducible team" a u-boot
> thing or a debian thing? I'm not really active in any of the debian
> projects so maybe someone there should pick this up if it's a debian
> thing.
the "reproducible team" so far involved has indeed been the "Debian
reproducible builds team", but we care about free software in general
and we also think that reproducible builds shall become the norm one day.
very short one paragraph summary:
With free software, anyone can inspect the source code for malicious flaws.
But Debian like most distributions provides binary packages to its users. The
idea of ?deterministic? or ?reproducible? builds is to empower anyone to
verify that no flaws have been introduced during the build process by
reproducing byte-for-byte identical binary packages from a given source.
for a longer summary you might want to watch
http://media.ccc.de/browse/conferences/camp2015/camp2015-6657-how_to_make_your_software_build_reproducibly.html
or
http://media.ccc.de/browse/congress/2014/31c3_-_6240_-_en_-_saal_g_-_201412271400_-_reproducible_builds_-_mike_perry_-_seth_schoen_-_hans_steiner.html
- the latter explains the motivation behind our work in greater detail.
Or you can also read about this,
https://wiki.debian.org/ReproducibleBuilds/About (alone, the wiki has much
more information on other pages as well) has the following contents:
Why do we want reproducible builds?
Reproducing builds
Recording the environment
Reproduce the build environment
References
Presentations
Publicity
Related projects
Further work
Last but not least, the Debian reproducible builds team has also been
investigating other projects, see eg
https://reproducible.debian.net/openwrt/
https://reproducible.debian.net/netbsd/
https://reproducible.debian.net/coreboot/
(and more will be coming.)
cheers,
Holger
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 828 bytes
Desc: This is a digitally signed message part.
URL: <http://lists.denx.de/pipermail/u-boot/attachments/20150826/5f3d3002/attachment.sig>
next prev parent reply other threads:[~2015-08-26 9:29 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-08-13 6:08 [U-Boot] [PATCH v3 1/2] Makefile: Use correct timezone for U_BOOT_TZ Chris Packham
2015-08-13 6:08 ` [U-Boot] [PATCH v3 2/2] Makefile: Add SOURCE_DATE_TZ Chris Packham
2015-08-25 12:09 ` Paul Kocialkowski
2015-08-26 9:08 ` Chris Packham
2015-08-26 9:29 ` Holger Levsen [this message]
2015-08-26 10:01 ` Paul Kocialkowski
2015-08-27 11:50 ` Tom Rini
2015-08-25 10:22 ` [U-Boot] [PATCH v3 1/2] Makefile: Use correct timezone for U_BOOT_TZ Andreas Bießmann
2015-08-25 12:10 ` Paul Kocialkowski
2015-08-28 21:02 ` [U-Boot] [U-Boot, v3, " Tom Rini
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=201508261129.18281.holger@layer-acht.org \
--to=holger@layer-acht.org \
--cc=u-boot@lists.denx.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox