coreboot

coreboot™: fast, flexible and reproducible Open Source firmware?

Reproducible Coreboot

Reproducible builds enable anyone to reproduce bit by bit identical binary packages from a given source, so that anyone can verify that a given binary derived from the source it was said to be derived. There is more information about reproducible builds on the Debian wiki and on https://reproducible-builds.org. These pages explain in more depth why this is useful, what common issues exist and which workarounds and solutions are known.

Reproducible Coreboot is an effort to apply this to coreboot. Thus each coreboot.rom is build twice (without payloads), with a few variations added and then those two ROMs are compared using diffoscope. Please note that the toolchain is not varied at all as the rebuild happens on exactly the same system. More variations are expected to be seen in the wild.

There is a weekly run jenkins job to test the master branch of coreboot.git. The jenkins job is running reproducible_coreboot.sh in a Debian environment and this script is solely responsible for creating this page. Feel invited to join #reproducible-builds (on irc.oftc.net) to request job runs whenever sensible. Patches and other feedback are very much appreciated - if you want to help, please start by looking at the ToDo list for coreboot, you might find something easy to contribute.
Thanks to Profitbricks for donating the virtual machines this is running on!

284 (99.6%) out of 285 built coreboot images were reproducible in our test setup , while 0 (0%) failed to build from source. These tests were last run on 2019-09-20 for version 4.10-723-g26e59a6280 using diffoscope 125.

variationfirst buildsecond build
hostname osuosl-build169-amd64 or osuosl-build170-amd64the other one
domainname is not yet varied between rebuilds of coreboot.
env CAPTURE_ENVIRONMENTnot setCAPTURE_ENVIRONMENT="I capture the environment"
env TZTZ="/usr/share/zoneinfo/Etc/GMT+12"TZ="/usr/share/zoneinfo/Etc/GMT-14"
env LANGLANG="en_GB.UTF-8"LANG="fr_CH.UTF-8"
env LC_ALLnot setLC_ALL="fr_CH.UTF-8"
env PATHPATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:"PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path"
env USER is not yet varied between rebuilds of coreboot.
uid is not yet varied between rebuilds of coreboot.
gid is not yet varied between rebuilds of coreboot.
UTS namespace is not yet varied between rebuilds of coreboot.
kernel version, modified using /usr/bin/linux64 --uname-2.6Linux 4.19.0-6-amd64Linux 2.6.79-6-amd64
umask00220002
CPU type Intel(R) Xeon(R) CPU E5-2660 0 @ 2.20GHzsame for both builds
/bin/sh is not yet varied between rebuilds of coreboot.
year, month, datetoday (2019-09-20)same for both builds (currently, work in progress)
hour, minutehour and minute will probably vary between two builds...the future system actually runs 398 days, 6 hours and 23 minutes ahead...
Filesystemtmpfssame for both builds (currently, this could be varied using disorderfs)
everything else...is likely the same. There will be more variations in the wild.

commit 26e59a62809d5f0f8d5f4469441490544506978d
Author: Nico Huber 
Date:   Sat Jun 8 19:49:48 2019 +0200

    sb/intel/common/fw: Make make aware that it needs binaries
    
    As we redirect all `dd` output to /dev/null (it would clutter the
    console otherwise), there is no error message if a binary to be
    added isn't found. If we add them as dependency, OTOH, `make` will
    complain properly.
    
    Change-Id: I40c3979b84341cb88c7e9a5084c1a97230ea5503
    Signed-off-by: Nico Huber 
    Reviewed-on: https://review.coreboot.org/c/coreboot/+/33327
    Reviewed-by: Angel Pons 
    Tested-by: build bot (Jenkins)      

cross toolchain sourcesha256sum
acpica-unix2-20190703.tar.gz 9f539986b91749947dfc32b3b00d338ba565ee1a394b95c049dd393aac8ae34e
binutils-2.32.tar.xz 0ab6c55dd86a92ed561972ba15b9b70a8b9f75557f896446c82e8b36e473ee04
gcc-8.3.0.tar.xz 64baadfe6cc0f4947a84cb12d7f0dfaf45bb58b7e92461639596c21e02d97d2c
gmp-6.1.2.tar.xz 87b565e89a9a684fe4ebeeddb8399dce2599f9c9049854ca8c0dfbdea0e21912
mpc-1.1.0.tar.gz 6985c538143c1208dcb1ac42cedad6ff52e267b47e5f970183a3e75125b43c2e
mpfr-4.0.2.tar.xz 1d3be708604eae0e42d578ba93b390c2a145f17743a744d8f3f8c2ad5855a38a
Debian 10.1 package on amd64installed version
gcc 4:8.3.0-1
g++ 4:8.3.0-1
make 4.2.1-1.2
cmake 3.13.4-1
flex 2.6.4-6.2
bison 2:3.3.2.dfsg-1