Gothenburg 2026 - Day 2 - Cross-distro reproducibility
Cross-distro reproducibility
Things needed to get started as a new distribution:
- Step 0: Pick any package, build it twice (with
SOURCE_DATE_EPOCH=123), run diffoscope on both packages and check the package manager build tooling itself is reproducible (e.g. the tool itself doesn’t record filesystem timestamps in all packages, regardless of the software you’re building). Other metadata should also be identical, if the only difference is a signature we can ignore that for now. - Step 1: You need an archive of old packages (e.g. a package mirror that only adds, but never deletes). If older version of build dependencies are not available anymore, we can not recreate the build environment necessary to reproduce the package
- Step 2: Document your build environment. With the archived package versions available, we now need to document which of them are needed to recreate the build environment. This list needs to include the name of all (recursive) dependencies, their versions, and it’s incuraged to include a cryptographic checksum of the package file (if technically possible). The list may be embedded into the binary package (Arch Linux style), distributed along with the binary packages (Debian style), or embedded in the build log, if they are reliably retained longterm and can be parsed securely (Alpine style).
- Step 3: Have a way to derive the
SOURCE_DATE_EPOCHvalue. You may derive this from your source package (Debian style) or record a canonical reference value in the buildinfo file (Arch style) - Step 4: Have a build command that is able setup the reference build environment described in the buildinfo file. This also needs to ensure the
SOURCE_DATE_EPOCHvalue is set accordingly.
With all of them in place, you are good to go!