Diff of the two buildlogs:

--
--- b1/build.log	2025-02-25 23:01:08.938706509 +0000
+++ b2/build.log	2025-02-25 23:06:20.140650638 +0000
@@ -1,6 +1,6 @@
 I: pbuilder: network access will be disabled during build
-I: Current time: Mon Mar 30 17:21:21 -12 2026
-I: pbuilder-time-stamp: 1774934481
+I: Current time: Wed Feb 26 13:01:11 +14 2025
+I: pbuilder-time-stamp: 1740524471
 I: Building the build Environment
 I: extracting base tarball [/var/cache/pbuilder/trixie-reproducible-base.tgz]
 I: copying local configuration
@@ -22,52 +22,84 @@
 dpkg-source: info: unpacking sigsum-go_0.10.1-1.debian.tar.xz
 I: Not using root during the build.
 I: Installing the build-deps
-I: user script /srv/workspace/pbuilder/3894392/tmp/hooks/D02_print_environment starting
+I: user script /srv/workspace/pbuilder/2535278/tmp/hooks/D01_modify_environment starting
+debug: Running on ionos11-amd64.
+I: Changing host+domainname to test build reproducibility
+I: Adding a custom variable just for the fun of it...
+I: Changing /bin/sh to bash
+'/bin/sh' -> '/bin/bash'
+lrwxrwxrwx 1 root root 9 Feb 25 23:01 /bin/sh -> /bin/bash
+I: Setting pbuilder2's login shell to /bin/bash
+I: Setting pbuilder2's GECOS to second user,second room,second work-phone,second home-phone,second other
+I: user script /srv/workspace/pbuilder/2535278/tmp/hooks/D01_modify_environment finished
+I: user script /srv/workspace/pbuilder/2535278/tmp/hooks/D02_print_environment starting
 I: set
-  BUILDDIR='/build/reproducible-path'
-  BUILDUSERGECOS='first user,first room,first work-phone,first home-phone,first other'
-  BUILDUSERNAME='pbuilder1'
-  BUILD_ARCH='amd64'
-  DEBIAN_FRONTEND='noninteractive'
-  DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=42 '
-  DISTRIBUTION='trixie'
-  HOME='/root'
-  HOST_ARCH='amd64'
+  BASH=/bin/sh
+  BASHOPTS=checkwinsize:cmdhist:complete_fullquote:extquote:force_fignore:globasciiranges:globskipdots:hostcomplete:interactive_comments:patsub_replacement:progcomp:promptvars:sourcepath
+  BASH_ALIASES=()
+  BASH_ARGC=()
+  BASH_ARGV=()
+  BASH_CMDS=()
+  BASH_LINENO=([0]="12" [1]="0")
+  BASH_LOADABLES_PATH=/usr/local/lib/bash:/usr/lib/bash:/opt/local/lib/bash:/usr/pkg/lib/bash:/opt/pkg/lib/bash:.
+  BASH_SOURCE=([0]="/tmp/hooks/D02_print_environment" [1]="/tmp/hooks/D02_print_environment")
+  BASH_VERSINFO=([0]="5" [1]="2" [2]="37" [3]="1" [4]="release" [5]="x86_64-pc-linux-gnu")
+  BASH_VERSION='5.2.37(1)-release'
+  BUILDDIR=/build/reproducible-path
+  BUILDUSERGECOS='second user,second room,second work-phone,second home-phone,second other'
+  BUILDUSERNAME=pbuilder2
+  BUILD_ARCH=amd64
+  DEBIAN_FRONTEND=noninteractive
+  DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=20 '
+  DIRSTACK=()
+  DISTRIBUTION=trixie
+  EUID=0
+  FUNCNAME=([0]="Echo" [1]="main")
+  GROUPS=()
+  HOME=/root
+  HOSTNAME=i-capture-the-hostname
+  HOSTTYPE=x86_64
+  HOST_ARCH=amd64
   IFS=' 	
   '
-  INVOCATION_ID='b5b780d01e884c609c328e1ecf4f7302'
-  LANG='C'
-  LANGUAGE='en_US:en'
-  LC_ALL='C'
-  MAIL='/var/mail/root'
-  OPTIND='1'
-  PATH='/usr/sbin:/usr/bin:/sbin:/bin:/usr/games'
-  PBCURRENTCOMMANDLINEOPERATION='build'
-  PBUILDER_OPERATION='build'
-  PBUILDER_PKGDATADIR='/usr/share/pbuilder'
-  PBUILDER_PKGLIBDIR='/usr/lib/pbuilder'
-  PBUILDER_SYSCONFDIR='/etc'
-  PPID='3894392'
-  PS1='# '
-  PS2='> '
+  INVOCATION_ID=288866e988204fa282f450087c010ce7
+  LANG=C
+  LANGUAGE=et_EE:et
+  LC_ALL=C
+  MACHTYPE=x86_64-pc-linux-gnu
+  MAIL=/var/mail/root
+  OPTERR=1
+  OPTIND=1
+  OSTYPE=linux-gnu
+  PATH=/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path
+  PBCURRENTCOMMANDLINEOPERATION=build
+  PBUILDER_OPERATION=build
+  PBUILDER_PKGDATADIR=/usr/share/pbuilder
+  PBUILDER_PKGLIBDIR=/usr/lib/pbuilder
+  PBUILDER_SYSCONFDIR=/etc
+  PIPESTATUS=([0]="0")
+  POSIXLY_CORRECT=y
+  PPID=2535278
   PS4='+ '
-  PWD='/'
-  SHELL='/bin/bash'
-  SHLVL='2'
-  SUDO_COMMAND='/usr/bin/timeout -k 18.1h 18h /usr/bin/ionice -c 3 /usr/bin/nice /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.KbAbFCjb/pbuilderrc_9Gdr --distribution trixie --hookdir /etc/pbuilder/first-build-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/trixie-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.KbAbFCjb/b1 --logfile b1/build.log sigsum-go_0.10.1-1.dsc'
-  SUDO_GID='111'
-  SUDO_UID='106'
-  SUDO_USER='jenkins'
-  TERM='unknown'
-  TZ='/usr/share/zoneinfo/Etc/GMT+12'
-  USER='root'
-  _='/usr/bin/systemd-run'
-  http_proxy='http://213.165.73.152:3128'
+  PWD=/
+  SHELL=/bin/bash
+  SHELLOPTS=braceexpand:errexit:hashall:interactive-comments:posix
+  SHLVL=3
+  SUDO_COMMAND='/usr/bin/timeout -k 24.1h 24h /usr/bin/ionice -c 3 /usr/bin/nice -n 11 /usr/bin/unshare --uts -- /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.KbAbFCjb/pbuilderrc_A5AZ --distribution trixie --hookdir /etc/pbuilder/rebuild-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/trixie-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.KbAbFCjb/b2 --logfile b2/build.log sigsum-go_0.10.1-1.dsc'
+  SUDO_GID=111
+  SUDO_UID=106
+  SUDO_USER=jenkins
+  TERM=unknown
+  TZ=/usr/share/zoneinfo/Etc/GMT-14
+  UID=0
+  USER=root
+  _='I: set'
+  http_proxy=http://46.16.76.132:3128
 I: uname -a
-  Linux ionos15-amd64 6.12.9+bpo-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.12.9-1~bpo12+1 (2025-01-19) x86_64 GNU/Linux
+  Linux i-capture-the-hostname 6.1.0-31-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.128-1 (2025-02-07) x86_64 GNU/Linux
 I: ls -l /bin
-  lrwxrwxrwx 1 root root 7 Nov 22  2024 /bin -> usr/bin
-I: user script /srv/workspace/pbuilder/3894392/tmp/hooks/D02_print_environment finished
+  lrwxrwxrwx 1 root root 7 Nov 22 14:40 /bin -> usr/bin
+I: user script /srv/workspace/pbuilder/2535278/tmp/hooks/D02_print_environment finished
  -> Attempting to satisfy build-dependencies
  -> Creating pbuilder-satisfydepends-dummy package
 Package: pbuilder-satisfydepends-dummy
@@ -163,7 +195,7 @@
 Get: 44 http://deb.debian.org/debian trixie/main amd64 golang-golang-x-crypto-dev all 1:0.25.0-1 [1682 kB]
 Get: 45 http://deb.debian.org/debian trixie/main amd64 golang-golang-x-net-dev all 1:0.27.0-1 [898 kB]
 Get: 46 http://deb.debian.org/debian trixie/main amd64 help2man amd64 1.49.3 [198 kB]
-Fetched 76.9 MB in 1s (63.4 MB/s)
+Fetched 76.9 MB in 4s (21.7 MB/s)
 Preconfiguring packages ...
 Selecting previously unselected package liblocale-gettext-perl.
 (Reading database ... 
(Reading database ... 5%
(Reading database ... 10%
(Reading database ... 15%
(Reading database ... 20%
(Reading database ... 25%
(Reading database ... 30%
(Reading database ... 35%
(Reading database ... 40%
(Reading database ... 45%
(Reading database ... 50%
(Reading database ... 55%
(Reading database ... 60%
(Reading database ... 65%
(Reading database ... 70%
(Reading database ... 75%
(Reading database ... 80%
(Reading database ... 85%
(Reading database ... 90%
(Reading database ... 95%
(Reading database ... 100%
(Reading database ... 19802 files and directories currently installed.)
@@ -362,7 +394,11 @@
 Building tag database...
  -> Finished parsing the build-deps
 I: Building the package
-I: Running cd /build/reproducible-path/sigsum-go-0.10.1/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-genchanges -S  > ../sigsum-go_0.10.1-1_source.changes
+I: user script /srv/workspace/pbuilder/2535278/tmp/hooks/A99_set_merged_usr starting
+Not re-configuring usrmerge for trixie
+I: user script /srv/workspace/pbuilder/2535278/tmp/hooks/A99_set_merged_usr finished
+hostname: Name or service not known
+I: Running cd /build/reproducible-path/sigsum-go-0.10.1/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-genchanges -S  > ../sigsum-go_0.10.1-1_source.changes
 dpkg-buildpackage: info: source package sigsum-go
 dpkg-buildpackage: info: source version 0.10.1-1
 dpkg-buildpackage: info: source distribution unstable
@@ -380,110 +416,110 @@
    dh_autoreconf -O--builddirectory=_build -O--buildsystem=golang
    dh_auto_configure -O--builddirectory=_build -O--buildsystem=golang
    dh_auto_build -O--builddirectory=_build -O--buildsystem=golang
-	cd _build && go install -trimpath -v -p 42 sigsum.org/sigsum-go/cmd/sigsum-key sigsum.org/sigsum-go/cmd/sigsum-monitor sigsum.org/sigsum-go/cmd/sigsum-submit sigsum.org/sigsum-go/cmd/sigsum-token sigsum.org/sigsum-go/cmd/sigsum-verify sigsum.org/sigsum-go/cmd/sigsum-witness sigsum.org/sigsum-go/internal/mocks/signer sigsum.org/sigsum-go/internal/ssh sigsum.org/sigsum-go/internal/version sigsum.org/sigsum-go/pkg/api sigsum.org/sigsum-go/pkg/ascii sigsum.org/sigsum-go/pkg/checkpoint sigsum.org/sigsum-go/pkg/client sigsum.org/sigsum-go/pkg/crypto sigsum.org/sigsum-go/pkg/key sigsum.org/sigsum-go/pkg/log sigsum.org/sigsum-go/pkg/merkle sigsum.org/sigsum-go/pkg/mocks sigsum.org/sigsum-go/pkg/monitor sigsum.org/sigsum-go/pkg/policy sigsum.org/sigsum-go/pkg/proof sigsum.org/sigsum-go/pkg/requests sigsum.org/sigsum-go/pkg/server sigsum.org/sigsum-go/pkg/submit sigsum.org/sigsum-go/pkg/submit-token sigsum.org/sigsum-go/pkg/types sigsum.org/sigsum-go/tests/mk-add-checkpoint-request sigsum.org/sigsum-go/tests/sha256-n sigsum.org/sigsum-go/tests/use-agent
-internal/runtime/atomic
+	cd _build && go install -trimpath -v -p 20 sigsum.org/sigsum-go/cmd/sigsum-key sigsum.org/sigsum-go/cmd/sigsum-monitor sigsum.org/sigsum-go/cmd/sigsum-submit sigsum.org/sigsum-go/cmd/sigsum-token sigsum.org/sigsum-go/cmd/sigsum-verify sigsum.org/sigsum-go/cmd/sigsum-witness sigsum.org/sigsum-go/internal/mocks/signer sigsum.org/sigsum-go/internal/ssh sigsum.org/sigsum-go/internal/version sigsum.org/sigsum-go/pkg/api sigsum.org/sigsum-go/pkg/ascii sigsum.org/sigsum-go/pkg/checkpoint sigsum.org/sigsum-go/pkg/client sigsum.org/sigsum-go/pkg/crypto sigsum.org/sigsum-go/pkg/key sigsum.org/sigsum-go/pkg/log sigsum.org/sigsum-go/pkg/merkle sigsum.org/sigsum-go/pkg/mocks sigsum.org/sigsum-go/pkg/monitor sigsum.org/sigsum-go/pkg/policy sigsum.org/sigsum-go/pkg/proof sigsum.org/sigsum-go/pkg/requests sigsum.org/sigsum-go/pkg/server sigsum.org/sigsum-go/pkg/submit sigsum.org/sigsum-go/pkg/submit-token sigsum.org/sigsum-go/pkg/types sigsum.org/sigsum-go/tests/mk-add-checkpoint-request sigsum.org/sigsum-go/tests/sha256-n sigsum.org/sigsum-go/tests/use-agent
+internal/byteorder
+unicode
+cmp
+math/bits
+internal/goarch
+log/internal
 internal/unsafeheader
 internal/coverage/rtcov
 unicode/utf8
-cmp
-internal/asan
-unicode/utf16
-internal/cpu
 internal/runtime/syscall
-crypto/internal/boring/sig
-internal/byteorder
-container/list
+internal/msan
+internal/goexperiment
+internal/itoa
 sync/atomic
-internal/goos
 internal/godebugs
-log/internal
-vendor/golang.org/x/crypto/internal/alias
+internal/cpu
 internal/profilerecord
-internal/msan
-vendor/golang.org/x/crypto/cryptobyte/asn1
-internal/nettrace
-math/bits
-unicode
-internal/itoa
-internal/goarch
+internal/goos
+internal/runtime/atomic
 crypto/internal/fips140/alias
-internal/goexperiment
 internal/runtime/math
-crypto/internal/fips140/subtle
-internal/runtime/sys
+crypto/internal/boring/sig
 internal/abi
-crypto/internal/fips140deps/byteorder
+internal/asan
 internal/chacha8rand
-internal/runtime/exithook
-crypto/internal/fips140deps/cpu
+crypto/internal/fips140deps/byteorder
+internal/nettrace
+container/list
+unicode/utf16
+vendor/golang.org/x/crypto/cryptobyte/asn1
+crypto/internal/fips140/subtle
+internal/runtime/sys
+vendor/golang.org/x/crypto/internal/alias
 internal/bytealg
+crypto/internal/fips140deps/cpu
 math
+internal/runtime/exithook
 internal/stringslite
 internal/race
-internal/sync
 internal/runtime/maps
+internal/sync
 runtime
-iter
-weak
-crypto/subtle
 internal/reflectlite
 sync
+iter
+crypto/subtle
+weak
 slices
 maps
+errors
+sort
+internal/bisect
 internal/singleflight
 internal/testlog
-internal/bisect
 unique
-runtime/cgo
-errors
-sort
+io
 internal/oserror
-internal/godebug
 path
+strconv
 vendor/golang.org/x/net/dns/dnsmessage
 math/rand/v2
-io
-strconv
+runtime/cgo
 syscall
-bytes
-hash
+internal/godebug
 crypto/internal/randutil
+bytes
 strings
-crypto/internal/fips140deps/godebug
-math/rand
+hash
 hash/crc32
-reflect
 crypto
+reflect
 encoding/base32
 net/netip
+math/rand
+crypto/internal/fips140deps/godebug
 vendor/golang.org/x/text/transform
 golang.org/x/text/transform
 crypto/internal/impl
-crypto/internal/fips140
 bufio
 net/http/internal/ascii
-crypto/internal/fips140/sha256
+crypto/internal/fips140
 crypto/internal/fips140/sha3
 crypto/internal/fips140/sha512
 crypto/tls/internal/fips140tls
+crypto/internal/fips140/sha256
+time
+internal/syscall/unix
+internal/syscall/execenv
 crypto/internal/fips140/hmac
 crypto/sha3
 crypto/internal/fips140/check
 crypto/internal/fips140hash
-internal/syscall/execenv
-internal/syscall/unix
-time
 crypto/internal/fips140/edwards25519/field
 crypto/internal/fips140/aes
-crypto/internal/fips140/hkdf
+crypto/internal/fips140/nistec/fiat
 crypto/internal/fips140/bigmod
+crypto/internal/fips140/hkdf
 crypto/internal/fips140/tls12
-crypto/internal/fips140/nistec/fiat
 crypto/internal/fips140/tls13
 crypto/internal/fips140/edwards25519
-context
 io/fs
 internal/poll
+context
 internal/filepathlite
 crypto/internal/fips140/nistec
 os
@@ -492,93 +528,93 @@
 encoding/base64
 vendor/golang.org/x/crypto/internal/poly1305
 encoding/pem
-crypto/internal/sysrand
 fmt
+crypto/internal/sysrand
 os/signal
 vendor/golang.org/x/sys/cpu
 path/filepath
 net
 crypto/internal/entropy
 crypto/internal/fips140/drbg
-crypto/internal/fips140only
 crypto/internal/fips140/aes/gcm
+crypto/internal/fips140only
 crypto/internal/fips140/ed25519
 crypto/internal/fips140/mlkem
+crypto/internal/fips140/rsa
 crypto/internal/fips140/ecdh
 crypto/internal/fips140/ecdsa
-crypto/internal/fips140/rsa
-crypto/rc4
 crypto/md5
+crypto/rc4
 crypto/cipher
+crypto/internal/boring
 crypto/des
 vendor/golang.org/x/crypto/chacha20
-crypto/internal/boring
-crypto/sha256
-crypto/sha512
-crypto/aes
-crypto/ecdh
-crypto/hmac
-crypto/sha1
 log
 encoding/hex
-vendor/golang.org/x/net/http2/hpack
-mime/quotedprintable
-net/http/internal
-mime
 runtime/debug
 github.com/pborman/getopt/v2
 net/url
-github.com/golang/mock/gomock
 compress/flate
+vendor/golang.org/x/net/http2/hpack
+mime
+mime/quotedprintable
+net/http/internal
+golang.org/x/text/unicode/norm
+github.com/golang/mock/gomock
 math/big
 vendor/golang.org/x/text/unicode/norm
-golang.org/x/text/unicode/norm
+crypto/sha256
+crypto/aes
+crypto/ecdh
+crypto/sha512
+crypto/hmac
 vendor/golang.org/x/crypto/chacha20poly1305
+crypto/sha1
 sigsum.org/sigsum-go/pkg/log
-golang.org/x/text/unicode/bidi
 vendor/golang.org/x/text/unicode/bidi
+golang.org/x/text/unicode/bidi
 sigsum.org/sigsum-go/internal/version
 compress/gzip
-golang.org/x/text/secure/bidirule
 vendor/golang.org/x/text/secure/bidirule
-vendor/golang.org/x/net/idna
+golang.org/x/text/secure/bidirule
 golang.org/x/net/idna
-crypto/internal/boring/bbig
+vendor/golang.org/x/net/idna
 crypto/rand
 crypto/elliptic
-crypto/dsa
+crypto/internal/boring/bbig
 encoding/asn1
+crypto/dsa
 crypto/ed25519
 crypto/internal/hpke
-github.com/dchest/safefile
 crypto/rsa
+github.com/dchest/safefile
 sigsum.org/sigsum-go/pkg/crypto
-sigsum.org/sigsum-go/internal/mocks/signer
 sigsum.org/sigsum-go/pkg/ascii
 sigsum.org/sigsum-go/pkg/merkle
 sigsum.org/sigsum-go/tests/sha256-n
-crypto/x509/pkix
+sigsum.org/sigsum-go/internal/mocks/signer
 vendor/golang.org/x/crypto/cryptobyte
+crypto/x509/pkix
 crypto/ecdsa
-vendor/golang.org/x/net/http/httpproxy
-sigsum.org/sigsum-go/pkg/submit-token
 sigsum.org/sigsum-go/internal/ssh
 crypto/x509
+vendor/golang.org/x/net/http/httpproxy
 net/textproto
+sigsum.org/sigsum-go/pkg/submit-token
 sigsum.org/sigsum-go/pkg/types
 sigsum.org/sigsum-go/pkg/key
-vendor/golang.org/x/net/http/httpguts
-mime/multipart
 sigsum.org/sigsum-go/cmd/sigsum-token
+vendor/golang.org/x/net/http/httpguts
 sigsum.org/sigsum-go/tests/use-agent
-sigsum.org/sigsum-go/pkg/policy
+mime/multipart
 sigsum.org/sigsum-go/pkg/checkpoint
+sigsum.org/sigsum-go/pkg/policy
 sigsum.org/sigsum-go/cmd/sigsum-key
 sigsum.org/sigsum-go/pkg/requests
 sigsum.org/sigsum-go/tests/mk-add-checkpoint-request
 sigsum.org/sigsum-go/pkg/proof
-sigsum.org/sigsum-go/cmd/sigsum-verify
 sigsum.org/sigsum-go/pkg/mocks
+sigsum.org/sigsum-go/cmd/sigsum-verify
 crypto/tls
 net/http/httptrace
 net/http
@@ -593,7 +629,7 @@
    debian/rules override_dh_auto_test
 make[1]: Entering directory '/build/reproducible-path/sigsum-go-0.10.1'
 env DH_GOLANG_EXCLUDES=sigsum.org/sigsum-go/pkg/server dh_auto_test 
-	cd _build && go test -vet=off -v -p 42 sigsum.org/sigsum-go/cmd/sigsum-key sigsum.org/sigsum-go/cmd/sigsum-monitor sigsum.org/sigsum-go/cmd/sigsum-submit sigsum.org/sigsum-go/cmd/sigsum-token sigsum.org/sigsum-go/cmd/sigsum-verify sigsum.org/sigsum-go/cmd/sigsum-witness sigsum.org/sigsum-go/internal/mocks/signer sigsum.org/sigsum-go/internal/ssh sigsum.org/sigsum-go/internal/version sigsum.org/sigsum-go/pkg/api sigsum.org/sigsum-go/pkg/ascii sigsum.org/sigsum-go/pkg/checkpoint sigsum.org/sigsum-go/pkg/client sigsum.org/sigsum-go/pkg/crypto sigsum.org/sigsum-go/pkg/key sigsum.org/sigsum-go/pkg/log sigsum.org/sigsum-go/pkg/merkle sigsum.org/sigsum-go/pkg/mocks sigsum.org/sigsum-go/pkg/monitor sigsum.org/sigsum-go/pkg/policy sigsum.org/sigsum-go/pkg/proof sigsum.org/sigsum-go/pkg/requests sigsum.org/sigsum-go/pkg/submit sigsum.org/sigsum-go/pkg/submit-token sigsum.org/sigsum-go/pkg/types sigsum.org/sigsum-go/tests/mk-add-checkpoint-request sigsum.org/sigsum-go/tests/sha256-n sigsum.org/sigsum-go/tests/use-agent
+	cd _build && go test -vet=off -v -p 20 sigsum.org/sigsum-go/cmd/sigsum-key sigsum.org/sigsum-go/cmd/sigsum-monitor sigsum.org/sigsum-go/cmd/sigsum-submit sigsum.org/sigsum-go/cmd/sigsum-token sigsum.org/sigsum-go/cmd/sigsum-verify sigsum.org/sigsum-go/cmd/sigsum-witness sigsum.org/sigsum-go/internal/mocks/signer sigsum.org/sigsum-go/internal/ssh sigsum.org/sigsum-go/internal/version sigsum.org/sigsum-go/pkg/api sigsum.org/sigsum-go/pkg/ascii sigsum.org/sigsum-go/pkg/checkpoint sigsum.org/sigsum-go/pkg/client sigsum.org/sigsum-go/pkg/crypto sigsum.org/sigsum-go/pkg/key sigsum.org/sigsum-go/pkg/log sigsum.org/sigsum-go/pkg/merkle sigsum.org/sigsum-go/pkg/mocks sigsum.org/sigsum-go/pkg/monitor sigsum.org/sigsum-go/pkg/policy sigsum.org/sigsum-go/pkg/proof sigsum.org/sigsum-go/pkg/requests sigsum.org/sigsum-go/pkg/submit sigsum.org/sigsum-go/pkg/submit-token sigsum.org/sigsum-go/pkg/types sigsum.org/sigsum-go/tests/mk-add-checkpoint-request sigsum.org/sigsum-go/tests/sha256-n sigsum.org/sigsum-go/tests/use-agent
 ?   	sigsum.org/sigsum-go/cmd/sigsum-key	[no test files]
 ?   	sigsum.org/sigsum-go/cmd/sigsum-monitor	[no test files]
 ?   	sigsum.org/sigsum-go/cmd/sigsum-submit	[no test files]
@@ -604,7 +640,7 @@
 === RUN   TestRequest
 --- PASS: TestRequest (0.00s)
 === RUN   TestSignEd25519
---- PASS: TestSignEd25519 (0.00s)
+--- PASS: TestSignEd25519 (0.01s)
 === RUN   TestSignEd25519Fail
 --- PASS: TestSignEd25519Fail (0.00s)
 === RUN   TestParsePrivateKeyFile
@@ -618,7 +654,7 @@
 === RUN   TestSignedData
 --- PASS: TestSignedData (0.00s)
 PASS
-ok  	sigsum.org/sigsum-go/internal/ssh	0.026s
+ok  	sigsum.org/sigsum-go/internal/ssh	0.032s
 ?   	sigsum.org/sigsum-go/internal/version	[no test files]
 ?   	sigsum.org/sigsum-go/pkg/api	[no test files]
 === RUN   TestLineReaderGetLine
@@ -642,15 +678,15 @@
 === RUN   TestParserEOFGarbage
 --- PASS: TestParserEOFGarbage (0.00s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/ascii	0.010s
+ok  	sigsum.org/sigsum-go/pkg/ascii	0.028s
 === RUN   TestCheckpointToASCII
 --- PASS: TestCheckpointToASCII (0.00s)
 === RUN   TestCheckpointFromASCII
 --- PASS: TestCheckpointFromASCII (0.00s)
 === RUN   TestCheckpointSigned
---- PASS: TestCheckpointSigned (0.00s)
+--- PASS: TestCheckpointSigned (0.01s)
 === RUN   TestCheckpointVerify
---- PASS: TestCheckpointVerify (0.01s)
+--- PASS: TestCheckpointVerify (0.00s)
 === RUN   TestCheckpointVerifyIgnoreExtraSignature
 --- PASS: TestCheckpointVerifyIgnoreExtraSignature (0.00s)
 === RUN   TestCheckpointCosignVerify
@@ -680,11 +716,11 @@
 === RUN   TestGoSumDBVerifier
 --- PASS: TestGoSumDBVerifier (0.00s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/checkpoint	0.025s
+ok  	sigsum.org/sigsum-go/pkg/checkpoint	0.052s
 === RUN   TestProcessConflictResponse
 --- PASS: TestProcessConflictResponse (0.00s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/client	0.013s
+ok  	sigsum.org/sigsum-go/pkg/client	0.045s
 === RUN   TestValidHashFromHex
 --- PASS: TestValidHashFromHex (0.00s)
 === RUN   TestInvalidHashFromHex
@@ -704,15 +740,15 @@
 === RUN   TestVerify
 --- PASS: TestVerify (0.00s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/crypto	0.019s
+ok  	sigsum.org/sigsum-go/pkg/crypto	0.060s
 === RUN   TestParsePublicKeysFile
 --- PASS: TestParsePublicKeysFile (0.00s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/key	0.016s
+ok  	sigsum.org/sigsum-go/pkg/key	0.054s
 === RUN   Example
 --- PASS: Example (0.00s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/log	0.011s
+ok  	sigsum.org/sigsum-go/pkg/log	0.058s
 === RUN   TestSize
 --- PASS: TestSize (0.00s)
 === RUN   TestGetLeafIndex
@@ -724,27 +760,27 @@
 === RUN   TestInclusion
 --- PASS: TestInclusion (0.00s)
 === RUN   TestInclusionValid
---- PASS: TestInclusionValid (0.71s)
+--- PASS: TestInclusionValid (0.90s)
 === RUN   TestInclusionBatchValid
---- PASS: TestInclusionBatchValid (1.50s)
+--- PASS: TestInclusionBatchValid (2.35s)
 === RUN   TestInclusionTailValid
---- PASS: TestInclusionTailValid (1.33s)
+--- PASS: TestInclusionTailValid (1.94s)
 === RUN   TestConsistency
 --- PASS: TestConsistency (0.00s)
 === RUN   TestConsistencyValid
---- PASS: TestConsistencyValid (0.63s)
+--- PASS: TestConsistencyValid (1.01s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/merkle	4.176s
+ok  	sigsum.org/sigsum-go/pkg/merkle	6.237s
 ?   	sigsum.org/sigsum-go/pkg/mocks	[no test files]
 === RUN   TestGetTreeHead
---- PASS: TestGetTreeHead (0.92s)
+--- PASS: TestGetTreeHead (1.39s)
 === RUN   TestGetTreeHeadErrors
     client_test.go:171: bad signature: (expected) failure: monitoring alert: Invalid log signature: log signature invalid
     client_test.go:171: bad signature (hash): (expected) failure: monitoring alert: Invalid log signature: log signature invalid
     client_test.go:171: bad consistency: (expected) failure: monitoring alert: Log tree head not consistent: consistency proof not valid: invalid proof: old root mismatch
---- PASS: TestGetTreeHeadErrors (0.02s)
+--- PASS: TestGetTreeHeadErrors (0.04s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/monitor	0.959s
+ok  	sigsum.org/sigsum-go/pkg/monitor	1.477s
 === RUN   TestValidConfig
 --- PASS: TestValidConfig (0.00s)
 === RUN   TestNumericThreshold
@@ -754,9 +790,9 @@
 === RUN   TestLogPolicy
 --- PASS: TestLogPolicy (0.01s)
 === RUN   TestWitnessPolicy
---- PASS: TestWitnessPolicy (0.01s)
+--- PASS: TestWitnessPolicy (0.02s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/policy	0.034s
+ok  	sigsum.org/sigsum-go/pkg/policy	0.072s
 === RUN   TestASCII
 --- PASS: TestASCII (0.00s)
 === RUN   TestASCIIV1
@@ -766,7 +802,7 @@
 === RUN   TestVerify
 --- PASS: TestVerify (0.00s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/proof	0.022s
+ok  	sigsum.org/sigsum-go/pkg/proof	0.042s
 === RUN   TestLeafToASCII
 --- PASS: TestLeafToASCII (0.00s)
 === RUN   TestLeavesToURL
@@ -788,7 +824,7 @@
 === RUN   TestAddCheckpointFromASCII
 --- PASS: TestAddCheckpointFromASCII (0.00s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/requests	0.013s
+ok  	sigsum.org/sigsum-go/pkg/requests	0.047s
 === RUN   TestSubmitSuccess
 === RUN   TestSubmitSuccess/leaf_1
 === RUN   TestSubmitSuccess/leaf_2
@@ -799,15 +835,15 @@
 === RUN   TestSubmitSuccess/leaf_7
 === RUN   TestSubmitSuccess/leaf_8
 === RUN   TestSubmitSuccess/leaf_9
---- PASS: TestSubmitSuccess (0.02s)
-    --- PASS: TestSubmitSuccess/leaf_1 (0.00s)
+--- PASS: TestSubmitSuccess (0.04s)
+    --- PASS: TestSubmitSuccess/leaf_1 (0.01s)
     --- PASS: TestSubmitSuccess/leaf_2 (0.00s)
     --- PASS: TestSubmitSuccess/leaf_3 (0.00s)
-    --- PASS: TestSubmitSuccess/leaf_4 (0.01s)
+    --- PASS: TestSubmitSuccess/leaf_4 (0.00s)
     --- PASS: TestSubmitSuccess/leaf_5 (0.00s)
-    --- PASS: TestSubmitSuccess/leaf_6 (0.00s)
+    --- PASS: TestSubmitSuccess/leaf_6 (0.01s)
     --- PASS: TestSubmitSuccess/leaf_7 (0.00s)
-    --- PASS: TestSubmitSuccess/leaf_8 (0.01s)
+    --- PASS: TestSubmitSuccess/leaf_8 (0.00s)
     --- PASS: TestSubmitSuccess/leaf_9 (0.00s)
 === RUN   TestSubmitFailure
 === RUN   TestSubmitFailure/leaf_1
@@ -818,7 +854,7 @@
 === RUN   TestSubmitFailure/leaf_6
 === RUN   TestSubmitFailure/leaf_7
 --- PASS: TestSubmitFailure (0.01s)
-    --- PASS: TestSubmitFailure/leaf_1 (0.00s)
+    --- PASS: TestSubmitFailure/leaf_1 (0.01s)
     --- PASS: TestSubmitFailure/leaf_2 (0.00s)
     --- PASS: TestSubmitFailure/leaf_3 (0.00s)
     --- PASS: TestSubmitFailure/leaf_4 (0.00s)
@@ -826,7 +862,7 @@
     --- PASS: TestSubmitFailure/leaf_6 (0.00s)
     --- PASS: TestSubmitFailure/leaf_7 (0.00s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/submit	0.046s
+ok  	sigsum.org/sigsum-go/pkg/submit	0.108s
 === RUN   TestNormalize
 --- PASS: TestNormalize (0.00s)
 === RUN   TestNormalizeReject
@@ -841,21 +877,21 @@
 === RUN   TestSubmitHeaderToHeader
 --- PASS: TestSubmitHeaderToHeader (0.00s)
 === RUN   TestVerify
---- PASS: TestVerify (0.01s)
+--- PASS: TestVerify (0.02s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/submit-token	0.022s
+ok  	sigsum.org/sigsum-go/pkg/submit-token	0.076s
 === RUN   TestLeafSignedData
 --- PASS: TestLeafSignedData (0.00s)
 === RUN   TestSignLeaf
 --- PASS: TestSignLeaf (0.00s)
 === RUN   TestLeafVerify
---- PASS: TestLeafVerify (0.00s)
+--- PASS: TestLeafVerify (0.01s)
 === RUN   TestLeafToBinary
 --- PASS: TestLeafToBinary (0.00s)
 === RUN   TestLeafFromBinary
 --- PASS: TestLeafFromBinary (0.00s)
 === RUN   TestLeafToASCII
---- PASS: TestLeafToASCII (0.00s)
+--- PASS: TestLeafToASCII (0.01s)
 === RUN   TestLeafFromASCII
 --- PASS: TestLeafFromASCII (0.00s)
 === RUN   TestLeavesFromASCII
@@ -893,18 +929,18 @@
 === RUN   TestCosignatureFromASCII
 --- PASS: TestCosignatureFromASCII (0.00s)
 === RUN   TestCosignAndVerify
---- PASS: TestCosignAndVerify (0.00s)
+--- PASS: TestCosignAndVerify (0.01s)
 === RUN   TestCosignedTreeHeadToASCII
 --- PASS: TestCosignedTreeHeadToASCII (0.00s)
 === RUN   TestCosignedTreeHeadFromASCII
 --- PASS: TestCosignedTreeHeadFromASCII (0.00s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/types	0.030s
+ok  	sigsum.org/sigsum-go/pkg/types	0.077s
 ?   	sigsum.org/sigsum-go/tests/mk-add-checkpoint-request	[no test files]
 ?   	sigsum.org/sigsum-go/tests/sha256-n	[no test files]
 ?   	sigsum.org/sigsum-go/tests/use-agent	[no test files]
 env DH_GOLANG_BUILDPKG=sigsum.org/sigsum-go/pkg/server dh_auto_test 
-	cd _build && go test -vet=off -v -p 42 sigsum.org/sigsum-go/pkg/server
+	cd _build && go test -vet=off -v -p 20 sigsum.org/sigsum-go/pkg/server
 === RUN   TestGetTreeHead
     log_test.go:48: Unexpected status code, got 404, want 200
     controller.go:269: missing call(s) to *mocks.MockLog.GetTreeHead(is anything) /build/reproducible-path/sigsum-go-0.10.1/_build/src/sigsum.org/sigsum-go/pkg/server/log_test.go:44
@@ -919,7 +955,7 @@
     log_test.go:115: Unexpected response for "/foo/get-inclusion-proof/2/aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa", got "404 page not found\n", want "leaf_index=1\nnode_hash=0200000000000000000000000000000000000000000000000000000000000000\n"
     controller.go:269: missing call(s) to *mocks.MockLog.GetInclusionProof(is anything, is equal to {2 [170 170 170 170 170 170 170 170 170 170 170 170 170 170 170 170 170 170 170 170 170 170 170 170 170 170 170 170 170 170 170 170]} (requests.InclusionProof)) /build/reproducible-path/sigsum-go-0.10.1/_build/src/sigsum.org/sigsum-go/pkg/server/log_test.go:104
     controller.go:269: aborting test due to missing call(s)
---- FAIL: TestGetInclusionProof (0.01s)
+--- FAIL: TestGetInclusionProof (0.00s)
 === RUN   TestGetConsistencyProof
     log_test.go:171: Unexpected status code for "/foo/get-consistency-proof", got 404, want 301
     log_test.go:171: Unexpected status code for "/foo/get-consistency-proof/", got 404, want 400
@@ -983,9 +1019,9 @@
     controller.go:269: aborting test due to missing call(s)
 --- FAIL: TestAddCheckpoint (0.00s)
 FAIL
-FAIL	sigsum.org/sigsum-go/pkg/server	0.027s
+FAIL	sigsum.org/sigsum-go/pkg/server	0.035s
 FAIL
-dh_auto_test: error: cd _build && go test -vet=off -v -p 42 sigsum.org/sigsum-go/pkg/server returned exit code 1
+dh_auto_test: error: cd _build && go test -vet=off -v -p 20 sigsum.org/sigsum-go/pkg/server returned exit code 1
 make[1]: [debian/rules:10: override_dh_auto_test] Error 25 (ignored)
 make[1]: Leaving directory '/build/reproducible-path/sigsum-go-0.10.1'
    create-stamp debian/debhelper-build-stamp
@@ -1041,12 +1077,14 @@
 dpkg-buildpackage: info: binary-only upload (no source included)
 dpkg-genchanges: info: including full source code in upload
 I: copying local configuration
+I: user script /srv/workspace/pbuilder/2535278/tmp/hooks/B01_cleanup starting
+I: user script /srv/workspace/pbuilder/2535278/tmp/hooks/B01_cleanup finished
 I: unmounting dev/ptmx filesystem
 I: unmounting dev/pts filesystem
 I: unmounting dev/shm filesystem
 I: unmounting proc filesystem
 I: unmounting sys filesystem
 I: cleaning the build env 
-I: removing directory /srv/workspace/pbuilder/3894392 and its subdirectories
-I: Current time: Mon Mar 30 17:24:07 -12 2026
-I: pbuilder-time-stamp: 1774934647
+I: removing directory /srv/workspace/pbuilder/2535278 and its subdirectories
+I: Current time: Wed Feb 26 13:06:19 +14 2025
+I: pbuilder-time-stamp: 1740524779