Преглед на файлове

Dpkg::Source::Archive: Add support for reproducible source packages

Clamp the mtime of the source files when building the tarball to the
first defined value from the source_date option, SOURCE_DATE_EPOCH
environment variable or time().

This makes sure the generated source tarballs always contain the same
mtime for files or directories that have been modified during the build.
Guillem Jover преди 10 години
родител
ревизия
d959233560
променени са 3 файла, в които са добавени 13 реда и са изтрити 2 реда
  1. 3 0
      debian/changelog
  2. 6 1
      debian/control
  3. 4 1
      scripts/Dpkg/Source/Archive.pm

+ 3 - 0
debian/changelog

@@ -9,6 +9,9 @@ dpkg (1.18.10) UNRELEASED; urgency=medium
     Regression introduced in dpkg 1.18.8. Closes: #830267
   * Perl modules:
     - Disable fixdebugpath feature on unsafe characters in the path.
+    - Generate reproducible source tarballs by using the new GNU tar
+      --clamp-mtime option in Dpkg::Source::Archive, to make sure no file
+      in source packages has an mtime later than the changelog entry time.
   * Documentation:
     - Document Testsuite-Triggers in dsc(5).
     - Fix deb-changes(5) description to talk about .changes instead of .dsc.

+ 6 - 1
debian/control

@@ -50,7 +50,12 @@ Section: utils
 Priority: optional
 Architecture: all
 Multi-Arch: foreign
-Depends: libdpkg-perl (= ${source:Version}), bzip2, xz-utils,
+Depends:
+ libdpkg-perl (= ${source:Version}),
+# Needed for --clamp-mtime.
+ tar (>= 1.28-1),
+ bzip2,
+ xz-utils,
  patch (>= 2.7), make, binutils, base-files (>= 5.0.0), ${misc:Depends}
 Recommends: gcc | c-compiler, build-essential, fakeroot,
  gnupg | gnupg2, gpgv | gpgv2, libalgorithm-merge-perl

+ 4 - 1
scripts/Dpkg/Source/Archive.pm

@@ -46,9 +46,12 @@ sub create {
     $self->ensure_open('w');
     $spawn_opts{to_handle} = $self->get_filehandle();
     $spawn_opts{from_pipe} = \*$self->{tar_input};
+    # Try to use a deterministic mtime.
+    my $mtime = $opts{source_date} // $ENV{SOURCE_DATE_EPOCH} // time;
     # Call tar creation process
     $spawn_opts{delete_env} = [ 'TAR_OPTIONS' ];
-    $spawn_opts{exec} = [ 'tar', '-cf', '-', '--format=gnu', '--null',
+    $spawn_opts{exec} = [ 'tar', '-cf', '-', '--format=gnu',
+                          '--mtime', "\@$mtime", '--clamp-mtime', '--null',
                           '--numeric-owner', '--owner=0', '--group=0',
                           @{$opts{options}}, '-T', '-' ];
     *$self->{pid} = spawn(%spawn_opts);