Gothenburg 2026 - Day 2 - Build infrastructure
Improve serving and format of buildinfo files
- can we include hashes of build dependencies in buildinfo files?
- there will be a discussion with the dpkg maintainer.
- would be nice for to have insight Debian but just an optimization
- required in a multiple distribution setup
- how to integrate the buildinfo files into the Debian archive
- keep buildinfo files in distro specific archives
- integrate them into the normal Debian archive pool
-
Add a pointer to the bulidinfo file to the Packages file
- Let dak check if the hashes in the buildinfo file matches the uploaded .deb
- also syntax check, source name, version, date
- make sure that all used build dependency package version are also in the archive
- Should dak check that buildinfos are signed?
- already done via the .changes file
-
Should dak refuse uploads without a buildinfo file?
- What is the attack vector of a malicious buildinfo file?
- For now we don’t care
-
Still need to look into transparency logs for buildinfo files
- We want to construct the chain of reproducible packages
- make sure that all build dependency of a package are reproducible
- how to bootstrap?