coreboot

coreboot™: fast, flexible and reproducible Open Source firmware!

Reproducible Coreboot

Reproducible builds enable anyone to reproduce bit by bit identical binary packages from a given source, so that anyone can verify that a given binary derived from the source it was said to be derived. There is more information about reproducible builds on the Debian wiki and on https://reproducible-builds.org. These pages explain in more depth why this is useful, what common issues exist and which workarounds and solutions are known.

Reproducible Coreboot is an effort to apply this to coreboot. Thus each coreboot.rom is build twice (without payloads), with a few variations added and then those two ROMs are compared using diffoscope. Please note that the toolchain is not varied at all as the rebuild happens on exactly the same system. More variations are expected to be seen in the wild.

There is a weekly run jenkins job to test the master branch of coreboot.git. The jenkins job is running reproducible_coreboot.sh in a Debian environment and this script is solely responsible for creating this page. Feel invited to join #debian-reproducible (on irc.oftc.net) to request job runs whenever sensible. Patches and other feedback are very much appreciated - if you want to help, please start by looking at the ToDo list for coreboot, you might find something easy to contribute.
Thanks to Profitbricks for donating the virtual machines this is running on!

341 (100.0%) out of 341 built coreboot images were reproducible in our test setup ! These tests were last run on 2017-12-11 for version 4.6-2345-gd46e216d00 using diffoscope 88.

variationfirst buildsecond build
hostname profitbricks-build3-amd64 or profitbricks-build4-amd64the other one
domainname is not yet varied between rebuilds of coreboot.
env CAPTURE_ENVIRONMENTnot setCAPTURE_ENVIRONMENT="I capture the environment"
env TZTZ="/usr/share/zoneinfo/Etc/GMT+12"TZ="/usr/share/zoneinfo/Etc/GMT-14"
env LANGLANG="en_GB.UTF-8"LANG="fr_CH.UTF-8"
env LC_ALLnot setLC_ALL="fr_CH.UTF-8"
env PATHPATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:"PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path"
env USER is not yet varied between rebuilds of coreboot.
uid is not yet varied between rebuilds of coreboot.
gid is not yet varied between rebuilds of coreboot.
UTS namespace is not yet varied between rebuilds of coreboot.
kernel version, modified using /usr/bin/linux64 --uname-2.6Linux 4.9.0-4-amd64Linux 2.6.69-4-amd64
umask00220002
CPU type AMD Opteron 62xx class CPUsame for both builds
/bin/sh is not yet varied between rebuilds of coreboot.
year, month, datetoday (2017-12-11)same for both builds (currently, work in progress)
hour, minutehour and minute will probably vary between two builds...the future system actually runs 398 days, 6 hours and 23 minutes ahead...
Filesystemtmpfssame for both builds (currently, this could be varied using disorderfs)
everything else...is likely the same. There will be more variations in the wild.

commit d46e216d003b706ad5cbaa922b5faf3d1513a0e6
Author: Furquan Shaikh 
Date:   Fri Dec 8 11:58:37 2017 -0800

    mb/google/poppy/variants/soraka: Tune I2C5 params
    
    This change updates scl_lcnt value for I2C5 to bring the bus frequency
    closer to 400kHz.
    
    BUG=b:65062416
    TEST=Verified that I2C5 frequency is between 389-396kHz.
    
    Change-Id: Ibaccab0c797174332633cb75e30d18ff5af76a43
    Signed-off-by: Furquan Shaikh 
    Reviewed-on: https://review.coreboot.org/22788
    Tested-by: build bot (Jenkins) 
    Reviewed-by: Aaron Durbin      

cross toolchain sourcesha256sum
acpica-unix2-20161222.tar.gz bac650fd93d101a6ef2e9a30b449b32a480b0ac4f6f253c49aa80511b017b7fa
binutils-2.29.1.tar.xz e7010a46969f9d3e53b650a518663f98a5dde3c3ae21b7d71e5e6803bc36b577
elfutils-0.170.tar.bz2 1f844775576b79bdc9f9c717a50058d08620323c1e935458223a12f249c9e066
gcc-6.3.0.tar.bz2 f06ae7f3f790fbf0f018f6d40e844451e6bc3b7bc96e128e63b09825c1f8b29f
gmp-6.1.2.tar.xz 87b565e89a9a684fe4ebeeddb8399dce2599f9c9049854ca8c0dfbdea0e21912
mpc-1.0.3.tar.gz 617decc6ea09889fb08ede330917a00b16809b8db88c29c31bfbb49cbf88ecc3
mpfr-3.1.5.tar.xz 015fde82b3979fbe5f83501986d328331ba8ddf008c1ff3da3c238f49ca062bc
Debian 9.3 package on amd64installed version
gcc 4:6.3.0-4
g++ 4:6.3.0-4
make 4.1-9.1
cmake 3.7.2-1
flex 2.6.1-1.3
bison 2:3.0.4.dfsg-1+b1
iasl