Diff of the two buildlogs:

--
--- b1/build.log	2025-03-19 18:17:17.508913449 +0000
+++ b2/build.log	2025-03-19 18:18:57.280419856 +0000
@@ -1,6 +1,6 @@
 I: pbuilder: network access will be disabled during build
-I: Current time: Tue Apr 21 12:39:34 -12 2026
-I: pbuilder-time-stamp: 1776818374
+I: Current time: Thu Mar 20 08:17:20 +14 2025
+I: pbuilder-time-stamp: 1742408240
 I: Building the build Environment
 I: extracting base tarball [/var/cache/pbuilder/trixie-reproducible-base.tgz]
 I: copying local configuration
@@ -31,52 +31,84 @@
 dpkg-source: info: applying no-efi-on-aarch64.patch
 I: using fakeroot in build.
 I: Installing the build-deps
-I: user script /srv/workspace/pbuilder/1893909/tmp/hooks/D02_print_environment starting
+I: user script /srv/workspace/pbuilder/1401574/tmp/hooks/D01_modify_environment starting
+debug: Running on codethink04-arm64.
+I: Changing host+domainname to test build reproducibility
+I: Adding a custom variable just for the fun of it...
+I: Changing /bin/sh to bash
+'/bin/sh' -> '/bin/bash'
+lrwxrwxrwx 1 root root 9 Mar 19 18:17 /bin/sh -> /bin/bash
+I: Setting pbuilder2's login shell to /bin/bash
+I: Setting pbuilder2's GECOS to second user,second room,second work-phone,second home-phone,second other
+I: user script /srv/workspace/pbuilder/1401574/tmp/hooks/D01_modify_environment finished
+I: user script /srv/workspace/pbuilder/1401574/tmp/hooks/D02_print_environment starting
 I: set
-  BUILDDIR='/build/reproducible-path'
-  BUILDUSERGECOS='first user,first room,first work-phone,first home-phone,first other'
-  BUILDUSERNAME='pbuilder1'
-  BUILD_ARCH='arm64'
-  DEBIAN_FRONTEND='noninteractive'
+  BASH=/bin/sh
+  BASHOPTS=checkwinsize:cmdhist:complete_fullquote:extquote:force_fignore:globasciiranges:globskipdots:hostcomplete:interactive_comments:patsub_replacement:progcomp:promptvars:sourcepath
+  BASH_ALIASES=()
+  BASH_ARGC=()
+  BASH_ARGV=()
+  BASH_CMDS=()
+  BASH_LINENO=([0]="12" [1]="0")
+  BASH_LOADABLES_PATH=/usr/local/lib/bash:/usr/lib/bash:/opt/local/lib/bash:/usr/pkg/lib/bash:/opt/pkg/lib/bash:.
+  BASH_SOURCE=([0]="/tmp/hooks/D02_print_environment" [1]="/tmp/hooks/D02_print_environment")
+  BASH_VERSINFO=([0]="5" [1]="2" [2]="37" [3]="1" [4]="release" [5]="aarch64-unknown-linux-gnu")
+  BASH_VERSION='5.2.37(1)-release'
+  BUILDDIR=/build/reproducible-path
+  BUILDUSERGECOS='second user,second room,second work-phone,second home-phone,second other'
+  BUILDUSERNAME=pbuilder2
+  BUILD_ARCH=arm64
+  DEBIAN_FRONTEND=noninteractive
   DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=12 '
-  DISTRIBUTION='trixie'
-  HOME='/root'
-  HOST_ARCH='arm64'
+  DIRSTACK=()
+  DISTRIBUTION=trixie
+  EUID=0
+  FUNCNAME=([0]="Echo" [1]="main")
+  GROUPS=()
+  HOME=/root
+  HOSTNAME=i-capture-the-hostname
+  HOSTTYPE=aarch64
+  HOST_ARCH=arm64
   IFS=' 	
   '
-  INVOCATION_ID='c2b431fa921e47b38fca9a85ef6ce2d9'
-  LANG='C'
-  LANGUAGE='en_US:en'
-  LC_ALL='C'
-  MAIL='/var/mail/root'
-  OPTIND='1'
-  PATH='/usr/sbin:/usr/bin:/sbin:/bin:/usr/games'
-  PBCURRENTCOMMANDLINEOPERATION='build'
-  PBUILDER_OPERATION='build'
-  PBUILDER_PKGDATADIR='/usr/share/pbuilder'
-  PBUILDER_PKGLIBDIR='/usr/lib/pbuilder'
-  PBUILDER_SYSCONFDIR='/etc'
-  PPID='1893909'
-  PS1='# '
-  PS2='> '
+  INVOCATION_ID=75447fe3bd834628b4212904e4aae4eb
+  LANG=C
+  LANGUAGE=nl_BE:nl
+  LC_ALL=C
+  MACHTYPE=aarch64-unknown-linux-gnu
+  MAIL=/var/mail/root
+  OPTERR=1
+  OPTIND=1
+  OSTYPE=linux-gnu
+  PATH=/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path
+  PBCURRENTCOMMANDLINEOPERATION=build
+  PBUILDER_OPERATION=build
+  PBUILDER_PKGDATADIR=/usr/share/pbuilder
+  PBUILDER_PKGLIBDIR=/usr/lib/pbuilder
+  PBUILDER_SYSCONFDIR=/etc
+  PIPESTATUS=([0]="0")
+  POSIXLY_CORRECT=y
+  PPID=1401574
   PS4='+ '
-  PWD='/'
-  SHELL='/bin/bash'
-  SHLVL='2'
-  SUDO_COMMAND='/usr/bin/timeout -k 18.1h 18h /usr/bin/ionice -c 3 /usr/bin/nice /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.QipFsTjg/pbuilderrc_AMEp --distribution trixie --hookdir /etc/pbuilder/first-build-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/trixie-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.QipFsTjg/b1 --logfile b1/build.log efitools_1.9.2-3.5.dsc'
-  SUDO_GID='109'
-  SUDO_UID='104'
-  SUDO_USER='jenkins'
-  TERM='unknown'
-  TZ='/usr/share/zoneinfo/Etc/GMT+12'
-  USER='root'
-  _='/usr/bin/systemd-run'
-  http_proxy='http://192.168.101.4:3128'
+  PWD=/
+  SHELL=/bin/bash
+  SHELLOPTS=braceexpand:errexit:hashall:interactive-comments:posix
+  SHLVL=3
+  SUDO_COMMAND='/usr/bin/timeout -k 24.1h 24h /usr/bin/ionice -c 3 /usr/bin/nice -n 11 /usr/bin/unshare --uts -- /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.QipFsTjg/pbuilderrc_2Fzh --distribution trixie --hookdir /etc/pbuilder/rebuild-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/trixie-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.QipFsTjg/b2 --logfile b2/build.log efitools_1.9.2-3.5.dsc'
+  SUDO_GID=109
+  SUDO_UID=104
+  SUDO_USER=jenkins
+  TERM=unknown
+  TZ=/usr/share/zoneinfo/Etc/GMT-14
+  UID=0
+  USER=root
+  _='I: set'
+  http_proxy=http://192.168.101.4:3128
 I: uname -a
-  Linux codethink03-arm64 6.1.0-32-cloud-arm64 #1 SMP Debian 6.1.129-1 (2025-03-06) aarch64 GNU/Linux
+  Linux i-capture-the-hostname 6.1.0-32-cloud-arm64 #1 SMP Debian 6.1.129-1 (2025-03-06) aarch64 GNU/Linux
 I: ls -l /bin
-  lrwxrwxrwx 1 root root 7 Mar  4  2025 /bin -> usr/bin
-I: user script /srv/workspace/pbuilder/1893909/tmp/hooks/D02_print_environment finished
+  lrwxrwxrwx 1 root root 7 Mar  4 11:20 /bin -> usr/bin
+I: user script /srv/workspace/pbuilder/1401574/tmp/hooks/D02_print_environment finished
  -> Attempting to satisfy build-dependencies
  -> Creating pbuilder-satisfydepends-dummy package
 Package: pbuilder-satisfydepends-dummy
@@ -161,7 +193,7 @@
 Get: 35 http://deb.debian.org/debian trixie/main arm64 libssl-dev arm64 3.4.1-1 [3232 kB]
 Get: 36 http://deb.debian.org/debian trixie/main arm64 openssl arm64 3.4.1-1 [1390 kB]
 Get: 37 http://deb.debian.org/debian trixie/main arm64 sbsigntool arm64 0.9.4-3.2 [59.1 kB]
-Fetched 25.2 MB in 0s (88.5 MB/s)
+Fetched 25.2 MB in 0s (108 MB/s)
 Preconfiguring packages ...
 Selecting previously unselected package liblocale-gettext-perl.
 (Reading database ... 
(Reading database ... 5%
(Reading database ... 10%
(Reading database ... 15%
(Reading database ... 20%
(Reading database ... 25%
(Reading database ... 30%
(Reading database ... 35%
(Reading database ... 40%
(Reading database ... 45%
(Reading database ... 50%
(Reading database ... 55%
(Reading database ... 60%
(Reading database ... 65%
(Reading database ... 70%
(Reading database ... 75%
(Reading database ... 80%
(Reading database ... 85%
(Reading database ... 90%
(Reading database ... 95%
(Reading database ... 100%
(Reading database ... 19899 files and directories currently installed.)
@@ -329,7 +361,11 @@
 fakeroot is already the newest version (1.37.1-1).
 0 upgraded, 0 newly installed, 0 to remove and 0 not upgraded.
 I: Building the package
-I: Running cd /build/reproducible-path/efitools-1.9.2/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-genchanges -S  > ../efitools_1.9.2-3.5_source.changes
+I: user script /srv/workspace/pbuilder/1401574/tmp/hooks/A99_set_merged_usr starting
+Not re-configuring usrmerge for trixie
+I: user script /srv/workspace/pbuilder/1401574/tmp/hooks/A99_set_merged_usr finished
+hostname: Name or service not known
+I: Running cd /build/reproducible-path/efitools-1.9.2/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-genchanges -S  > ../efitools_1.9.2-3.5_source.changes
 dpkg-buildpackage: info: source package efitools
 dpkg-buildpackage: info: source version 1.9.2-3.5
 dpkg-buildpackage: info: source distribution unstable
@@ -397,7 +433,6 @@
 pecoff.c:197:17: note: in expansion of macro 'Print'
   197 |                 Print(L"Reloc table overflows binary %d %d\n",
       |                 ^~~~~
-cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/aarch64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DCONFIG_aarch64 -c guid.c -o guid.o
 hash-to-efi-sig-list.c: In function 'main':
 hash-to-efi-sig-list.c:96:60: warning: format '%d' expects argument of type 'int', but argument 3 has type 'EFI_STATUS' {aka 'long unsigned int'} [-Wformat=]
    96 |                         printf("Failed to get hash of %s: %d\n", argv[i+1],
@@ -410,54 +445,58 @@
       |                                |
       |                                EFI_STATUS {aka long unsigned int}
 cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/aarch64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DCONFIG_aarch64 -c efi-readvar.c -o efi-readvar.o
-cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/aarch64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DCONFIG_aarch64 -c sha256.c -o sha256.o
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/aarch64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DCONFIG_aarch64 -c guid.c -o guid.o
 cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/aarch64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DCONFIG_aarch64 -c efi-updatevar.c -o efi-updatevar.o
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/aarch64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DCONFIG_aarch64 -c sha256.c -o sha256.o
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/aarch64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DCONFIG_aarch64 -c cert-to-efi-hash-list.c -o cert-to-efi-hash-list.o
 In file included from sha256.c:35:
 sha256.c: In function 'sha256_get_pecoff_digest_mem':
-cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/aarch64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DCONFIG_aarch64 -c console.c -o console.o
 /build/reproducible-path/efitools-1.9.2/include/buildefi.h:8:27: warning: too many arguments for format [-Wformat-extra-args]
     8 | #define Print(...) printf("%ls", __VA_ARGS__)
       |                           ^~~~~
 sha256.c:360:17: note: in expansion of macro 'Print'
   360 |                 Print(L"Invalid Data Size %d bytes too small\n", DataSize + context.SecDir->Size - sum_of_bytes);
       |                 ^~~~~
-cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/aarch64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DCONFIG_aarch64 -c cert-to-efi-hash-list.c -o cert-to-efi-hash-list.o
-cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/aarch64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DCONFIG_aarch64 -c execute.c -o execute.o
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/aarch64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DCONFIG_aarch64 -c console.c -o console.o
 cert-to-efi-hash-list.c:9:9: warning: "_XOPEN_SOURCE" redefined
     9 | #define _XOPEN_SOURCE
       |         ^~~~~~~~~~~~~
 <command-line>: note: this is the location of the previous definition
 cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/aarch64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DCONFIG_aarch64 -c flash-var.c -o flash-var.o
-cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/aarch64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DCONFIG_aarch64 -c configtable.c -o configtable.o
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/aarch64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DCONFIG_aarch64 -c execute.c -o execute.o
 > noPK.esl
-openssl req -new -x509 -newkey rsa:2048 -subj "/CN=PK/" -keyout PK.key -out PK.crt -days 3650 -nodes -sha256
-cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/aarch64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DCONFIG_aarch64 -c shell.c -o shell.o
 flash-var.c: In function 'main':
 flash-var.c:185:9: warning: 'memset' offset [0, 56] is out of the bounds [0, 0] [-Warray-bounds=]
   185 |         memset(vh, 0, sizeof(*vh));
       |         ^~~~~~~~~~~~~~~~~~~~~~~~~~
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/aarch64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DCONFIG_aarch64 -c configtable.c -o configtable.o
+openssl req -new -x509 -newkey rsa:2048 -subj "/CN=PK/" -keyout PK.key -out PK.crt -days 3650 -nodes -sha256
 openssl req -new -x509 -newkey rsa:2048 -subj "/CN=KEK/" -keyout KEK.key -out KEK.crt -days 3650 -nodes -sha256
-....+........+......+....+..+.......+.....+.+.....+....+++++++++++++++++++++++++++++++++++++++*..+.+..+++++++++++++++++++++++++++++++++++++++*...+............+...+......+.+...+...+..+......+.+...........+...+..........+......++++++
-..+......+.+++++++++++++++++++++++++++++++++++++++*.....+...+.......+...+...+++++++++++++++++++++++++++++++++++++++*..+...+..+.+.....+.........+...............+...+............+......+.............+..+...+.........+......+......+...+......+.+...............+...+........+...+.......+.....+.......+........+...+.+..............++++++
+...........+++++++++++++++++++++++++++++++++++++++*....+....+++++++++++++++++++++++++++++++++++++++*.....+......+......+........+.+........+............+...+.+..+....+++cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/aarch64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DCONFIG_aarch64 -c shell.c -o shell.o
++++
+.+..+....+......+......+.....+...+....+......+.....+.+.....+.........+......+++++++++++++++++++++++++++++++++++++++*...+.........+...+++++++++++++++++++++++++++++++++++++++*..........+.....................+.........+...+.+......+.........+.....+...............+....+..+....+.....+.+.....+......+.......+.....+............+.+...+.....+......+.+...+.........+..+......+...+...................+...........+.+........+.+......+...+..+.+....................+...+............+.........+......+....+...+.....+......+.+........+.............+...+..+.......+...+..+......+...............+......+.+.....+....+.....+....+......+...+.....+......+......+...+......+......+...+.+..+....+.....+.+........+....+......+.........+........+.......+............+...+.....+......+....+..+.........++++++
 -----
 openssl req -new -x509 -newkey rsa:2048 -subj "/CN=DB/" -keyout DB.key -out DB.crt -days 3650 -nodes -sha256
-.+..+.......+.....+.+..+++++++++++++++++++++++++++++++++++++++*.....+.......+......+...+..+...+....+..+....+..+............+.+.....+++++++++++++++++++++++++++++++++++++++*.................+.........+.....+...+.+...............+.....+..........+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/aarch64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DCONFIG_aarch64 -c security_policy.c -o security_policy.o
-......+.........+..+....+.....+...+...++++++
-...+.....+...+....+......+++++++++++++++++++++++++++++++++++++++*....+.+........+.........+...+...+.+......+..+.......+...+........+..........+++++++++++++++++++++++++++++++++++++++*...+.........................+..+......+...................+....................+....+......+.....................+.....+...+....+....................................+..+....+...+...+.....+.......+..+.+..............+....+..+...+.....................+....++++++
+..+....+..+++++++++++++++++++++++++++++++++++++++*...+....+..+......+.......+..+....+++++++++++++++++++++++++++++++++++++++*......+...+......+..+....+........+.+.........+..+...+.+.....+.+...........+.........+.+.........+...+..+.........+....+...+.....+.......+..+......+.......+.................................+..+.+......+...+...+..+.......+......+............+...............+..+..........+...+...........+......+.+..+......+................+........+..................+.......+..+....+..+..................+.+........+......+.+......+...+......+........+..........+.....+...+...+..........+...........+......+....+...+........+....+........+.+..+...+...............+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/aarch64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DCONFIG_aarch64 -c security_policy.c -o security_policy.o
+......+.........................+...+...+...............+..+.......+........+......+....+........+....+...+..+...+.............+.....+...+....+........+...............+...+..........+.........+.....+.+........................+...+...+...........+..........+......+.....+...+.+...........+.........+......+....+...+..+......+.......+...+.................+.+.....+.......+.....+openssl req -new -x509 -newkey rsa:2048 -subj "/CN=DB1/" -keyout DB1.key -out DB1.crt -days 3650 -nodes -sha256
+.......+..+...+...+....+...+.......+..+.+.....+.........++...+..+++.++++++++++++++++++++++++++++++++++++*.....+.++..+++++++++++++++++++++++++++++++++++++*.......+.....+.......+..............+......+...++.......+......+...+......+.+..++....+.................+.+...+..............+............+..+............++.......+...++..+.........+.+.....+..+.+.....................+.....+...............+...............++...+....+.......+...+......+.+...............+....................+........++.........+......................+......+.....+........+...+.........+.........++....+...........+.+........+....+.......+........++...................++.+++
+......+........+......+......+++++.+.++++++++++++++++++++++...+++++++++++++*.+.........+...+.........+....+.....+....+...............+......+.+...+....+..+.+..............+.+..........+..+......+.....+...+.......+....................+....+.+++++++++++++++++++++++++++++++++++++++*.+.....+...+......+.....+..+..........+...+.....+...+..+......+.....+....+.........++....++.....+............+.+........++..+....++......+....+.
+................+...+.++++++++++++++++++++++++++++++++++++++++*...+.+......+...+...+...+..+...+.+........+............+.+++++++++++++++++++++++++++++++++++++++*......+..+.....+................+.......+...+..+.+....+....+..............+.........+.......+..+...+.......+....++.......+....+....................+.....+..+.........++......+..++......+..+.............+...++............+++..............+.........+.++
+...+...+...+.....+....+......+...........+......+...+......+.+.....+.......+-----
+..+.........+....+..+.............+.....+.............+.......................+......+.+..+......+....+...+.....+....+.....+....+...........+...+............+....+..............+.......+.....+....+......+.....+.........+......+...+............+.............+.................+...+...+...+....+...+.....+..........+...+.....+......................+........+.+.....+....+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/aarch64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DCONFIG_aarch64 -c shim_protocol.c -o shim_protocol.o
+..+.......+............+...+openssl req -new -x509 -newkey rsa:2048 -subj "/CN=DB2/" -keyout DB2.key -out DB2.crt -days 3650 -nodes -sha256
+.....+.+......+...+....+..............+.+..+...+..+.+++++++++++++++++++++++++++++++++++++++*......+.........+.+...+..+......+++++++++++++++++++++++++++++...+......+++++++++++*..........+.........+..+...+....+.........+......+......+..+......+..........+....+...++.....+..+................++.......+......+..+...+....+..+.....+.....+.+..+............+........+....+....+...+.....+............+......+...+........+...+....+..+...+.............+......+......+........+....+.............+...................+........................+......++.+..+........+..+.......+..+..............+........+....+............++.........+...+...+....++.....+.....+...+.+....+.....+...+...+....+..+..+.......+........+.......+....+...........+......+....+.....+.....+....+..+.............+....+......+...+...........+......+.....+...+......+.+.........+.....+.+.....+.........+.+.....+.......+....+...............+......+............+........+........+...........+....++..++++
+.......+.++++-----
+++
+.+.....+......+++++++++++++++++++++++++++++++++++++++*....+.+......+...+...........+.+........+++++++++++++++++++++++++++++++++++++++*....+.....+....+..+.+............+..+...+..........+......+..+....+...+..+...+.+...........++++++
 -----
-openssl req -new -x509 -newkey rsa:2048 -subj "/CN=DB1/" -keyout DB1.key -out DB1.crt -days 3650 -nodes -sha256
-....+.+...+......+........+.+..+....+......+...+.....+++++++++++++++++++++++++++++++++++++++*...+.....+....+...+...+...............+.....+....+..+...+...+...+......+....+..+.......+......+..+....+.....+..........+...+...+..+......+++++++++++++++++++++++++++++++++++++++*......+.+..............+...+......+.........+..........+..+.+..+...............+......+....+..+...................+.....+......+.+...+...........+..........+...+...+...+......++++++
-...+++++++++++++++++++++++++++++++++++++++*.........+...+...+..+++++++++++++++++++++++++++++++++++++++*....+........+...+....+.....+...+............+......+.......cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/aarch64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DCONFIG_aarch64 -c shim_protocol.c -o shim_protocol.o
-..+............+.+........+.......+.........+......+..+......+......+.+............+...+.................+.......+...+......+..+.......+..+.........+......+openssl req -new -x509 -newkey rsa:2048 -subj "/CN=DB2/" -keyout DB2.key -out DB2.crt -days 3650 -nodes -sha256
-...+.+......+...+..+.+........+....+...+...+....+..+...+......+.+.....+.+...............+...+...........+++++++++++++++++++++++++++++++++++++++*.......+.+.........+..+.......+............+.........+..+.............+......+...+++++++++++++++++++++++++++++++++++++++*............+..+..+.........+...+..........+........+............+.+.+.....+....+..+.++....++++++
-+++
-.....++++++++++++++++++++-----
-+++++++++++++++++++*......+.+............+.........+...+..+...+.+...........+++++++++++++++++++++++++++++++++++++++*...+...+...........+.+........+.+.....+....+...+..+..........+......+..+...+......+..........+...+......+.....+.+...+...........+.........+.+...........+...............+.+.....+.........+....+...........+...............+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/aarch64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DCONFIG_aarch64 -c pkcs7verify.c -o pkcs7verify.o
-...+.+..+...+.+...+.....+...+..........+.........+......+.....+..+++++++++++++....++++++++++++++++++++++++++*.+....+...+..+.+..+....+..............+.+......+...+..+....+.....+.........+......+.........+.+......+........+++++++++++++++++++++++++++++++++++++++*....++...+.......+.............+.+........++........+..+.....+...........+...............+.+...+..............+....+......+..+.+...+.........+...+..+.......+....+..+..+.................++.........++...........+........+...........+..........+.+..............+..........+............+.......+..+.....+...........+.....+......................................++.+....+......+.+....+.........................+..+...+................+..+............++........+...+.+..........+.....+.......+.....+.+.....+.+.................++.....+.++......++
-...+.....+....+..+.+..+.............+...+-----
-...........+..........+.....+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/aarch64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DCONFIG_aarch64 -c kernel_efivars.c -o kernel_efivars.o
-...+......+.........+..........+.................+...+...+...+.........+.........................+..+....+...........+....+..+.......+.....+..........+.....+......+.+.....+....+............+.....+...+......+.........+....+........+.......+..+..........+...+...+...+.....+.+........+......+..........+..+.......+.....+......+....+...........+.......+........................+...+......+..+....+........+......+.......+...+......+...+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/aarch64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DCONFIG_aarch64 -c openssl_sign.c -o openssl_sign.o
-...........+...................+..+....+......+...+............+........+.+..+............+.+......+........+.+......+......+.....+....+...+..+....+...............+..............+.+..+.......+...+..+...+..........+..+......+......+.+..+......+.+...+............+...+..+....+.........+......+......+.....+...+......+..............................+............+...+.......+............+..+.............+.....+...+.........+....+..+++++openssl_sign.c: In function 'read_engine_private_key':
+....+.+.....+.+........+....+............+...+.....+.+.....+.........+............+...+++++++++++++++++++++++++++++++++++++++*.+...+...+.........+...+.........+.+...+.....+....+..+......+............+.+......+..............+.......+.................+......+.+.....+......+...+.+...+...+...+..+.......+......+.........+.....+......+.+......+.........+...+...+...+......+........+.+++++++++++++++++++++++++++++++++++++++*..+.+..............+......+...+.+......+.....+...+...............+.+.....+......+.+..+.+.....+.+.....+....+.........+.....+...+.........+.+...+.........+.................+...+.+.........+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/aarch64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DCONFIG_aarch64 -c pkcs7verify.c -o pkcs7verify.o
+....................+.......+.....+.+..+.++++++
+.....+....+........+...+......+++++++++++++++++++++++++++++++++++++++*........+......+......+.+..+..........+...+.........+...........+.........+.+.....+.........+...+.......+...+...+...+..+.......+..+++++++++++++++++++++++++++++++++++++++*..+.+..+...+....+...+.....+...+....+......+..+..........+...+..++++++
+-----
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/aarch64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DCONFIG_aarch64 -c kernel_efivars.c -o kernel_efivars.o
+cc -I/build/reproducible-path/efitools-1.9.2/include/ -I/usr/include/efi -I/usr/include/efi/aarch64 -I/usr/include/efi/protocol -O2 -g  -fno-stack-protector -fpic -Wall -fshort-wchar -fno-strict-aliasing -fno-merge-constants -D_XOPEN_SOURCE=700 -DGNU_EFI_USE_MS_ABI -DCONFIG_aarch64 -c openssl_sign.c -o openssl_sign.o
+openssl_sign.c: In function 'read_engine_private_key':
 openssl_sign.c:118:9: warning: 'ENGINE_load_builtin_engines' is deprecated: Since OpenSSL 3.0 [-Wdeprecated-declarations]
   118 |         ENGINE_load_builtin_engines();
       |         ^~~~~~~~~~~~~~~~~~~~~~~~~~~
@@ -495,9 +534,8 @@
 /usr/include/openssl/engine.h:493:27: note: declared here
   493 | OSSL_DEPRECATEDIN_3_0 int ENGINE_free(ENGINE *e);
       |                           ^~~~~~~~~~~
-+
-..+...+....+..+......+...+.+...........+.......+...+..+...+.......+..................+..+++++++++++++++++++++++++++++++++++++++*........+......+++++++++++++++++++++++++++++++++++++++*..+.+..+...+............+.+...............+..+...................+...........+...+.......+..+......+...................+..+....+..+.........+...+......+.......+ar rcv lib.a simple_file.o pecoff.o guid.o sha256.o console.o execute.o configtable.o shell.o security_policy.o shim_protocol.o pkcs7verify.o kernel_efivars.o openssl_sign.o
-..+.+............+..+............+...+.+.........+........+...+.+...+......+............+.....+............++a - simple_file.o
+ar rcv lib.a simple_file.o pecoff.o guid.o sha256.o console.o execute.o configtable.o shell.o security_policy.o shim_protocol.o pkcs7verify.o kernel_efivars.o openssl_sign.o
+a - simple_file.o
 a - pecoff.o
 a - guid.o
 a - sha256.o
@@ -510,10 +548,8 @@
 a - pkcs7verify.o
 a - kernel_efivars.o
 a - openssl_sign.o
-+++make[2]: Leaving directory '/build/reproducible-path/efitools-1.9.2/lib'
+make[2]: Leaving directory '/build/reproducible-path/efitools-1.9.2/lib'
 cc  -o cert-to-efi-sig-list cert-to-efi-sig-list.o -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -fstack-clash-protection -Wformat -Werror=format-security -mbranch-protection=standard -Wl,-z,relro lib/lib.a -lcrypto
-+
------
 cc  -o sig-list-to-certs sig-list-to-certs.o -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -fstack-clash-protection -Wformat -Werror=format-security -mbranch-protection=standard -Wl,-z,relro lib/lib.a -lcrypto
 cc  -o sign-efi-sig-list sign-efi-sig-list.o -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -fstack-clash-protection -Wformat -Werror=format-security -mbranch-protection=standard -Wl,-z,relro lib/lib.a -lcrypto
 cc  -o hash-to-efi-sig-list hash-to-efi-sig-list.o -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -fstack-clash-protection -Wformat -Werror=format-security -mbranch-protection=standard -Wl,-z,relro lib/lib.a
@@ -521,15 +557,16 @@
 cc  -o efi-updatevar efi-updatevar.o -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -fstack-clash-protection -Wformat -Werror=format-security -mbranch-protection=standard -Wl,-z,relro lib/lib.a -lcrypto
 cc  -o cert-to-efi-hash-list cert-to-efi-hash-list.o -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -fstack-clash-protection -Wformat -Werror=format-security -mbranch-protection=standard -Wl,-z,relro lib/lib.a -lcrypto
 cc  -o flash-var flash-var.o -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/efitools-1.9.2=. -fstack-protector-strong -fstack-clash-protection -Wformat -Werror=format-security -mbranch-protection=standard -Wl,-z,relro lib/lib.a
+help2man --no-info -i doc/cert-to-efi-hash-list.1.in -o doc/cert-to-efi-hash-list.1 ./cert-to-efi-hash-list
 help2man --no-info -i doc/cert-to-efi-sig-list.1.in -o doc/cert-to-efi-sig-list.1 ./cert-to-efi-sig-list
 help2man --no-info -i doc/efi-readvar.1.in -o doc/efi-readvar.1 ./efi-readvar
 help2man --no-info -i doc/efi-updatevar.1.in -o doc/efi-updatevar.1 ./efi-updatevar
 help2man --no-info -i doc/hash-to-efi-sig-list.1.in -o doc/hash-to-efi-sig-list.1 ./hash-to-efi-sig-list
 help2man --no-info -i doc/sig-list-to-certs.1.in -o doc/sig-list-to-certs.1 ./sig-list-to-certs
 help2man --no-info -i doc/sign-efi-sig-list.1.in -o doc/sign-efi-sig-list.1 ./sign-efi-sig-list
-./sign-efi-sig-list -t "2026-04-22 00:40:08" -c PK.crt -k PK.key PK noPK.esl noPK.auth
+./sign-efi-sig-list -t "2025-03-19 18:18:17" -c PK.crt -k PK.key PK noPK.esl noPK.auth
 ./cert-to-efi-sig-list -g 11111111-2222-3333-4444-123456789abc PK.crt PK.esl
-Timestamp is 2026-4-22 00:40:08
+Timestamp is 2025-3-19 18:18:17
 Authentication Payload size 40
 Signature of size 1148
 Signature at: 40
@@ -621,49 +658,48 @@
 TimeOfRevocation is 0-0-0 00:00:00
 ./cert-to-efi-hash-list DB.crt DB-hash-blacklist.esl
 TimeOfRevocation is 0-0-0 00:00:00
-./cert-to-efi-hash-list DB1.crt DB1-hash-blacklist.esl
 TimeOfRevocation is 0-0-0 00:00:00
+./cert-to-efi-hash-list DB1.crt DB1-hash-blacklist.esl
 ./cert-to-efi-hash-list DB2.crt DB2-hash-blacklist.esl
 TimeOfRevocation is 0-0-0 00:00:00
+TimeOfRevocation is 0-0-0 00:00:00
 ./cert-to-efi-hash-list ms-uefi.crt ms-uefi-hash-blacklist.esl
 TimeOfRevocation is 0-0-0 00:00:00
 ./cert-to-efi-hash-list ms-kek.crt ms-kek-hash-blacklist.esl
 TimeOfRevocation is 0-0-0 00:00:00
-help2man --no-info -i doc/cert-to-efi-hash-list.1.in -o doc/cert-to-efi-hash-list.1 ./cert-to-efi-hash-list
-TimeOfRevocation is 0-0-0 00:00:00
 ./sign-efi-sig-list -c PK.crt -k PK.key PK PK.esl PK.auth
-Timestamp is 2026-4-22 00:40:09
+Timestamp is 2025-3-19 18:18:34
 Authentication Payload size 851
 Signature of size 1148
 Signature at: 40
 ./sign-efi-sig-list -c PK.crt -k PK.key KEK KEK.esl KEK.auth
-Timestamp is 2026-4-22 00:40:09
+Timestamp is 2025-3-19 18:18:35
 Authentication Payload size 855
 Signature of size 1148
 Signature at: 40
 ./sign-efi-sig-list -c KEK.crt -k KEK.key db DB.esl DB.auth
-Timestamp is 2026-4-22 00:40:09
+Timestamp is 2025-3-19 18:18:36
 Authentication Payload size 851
 Signature of size 1151
 Signature at: 40
 ./sign-efi-sig-list -c KEK.crt -k KEK.key db DB1.esl DB1.auth
-Timestamp is 2026-4-22 00:40:09
+Timestamp is 2025-3-19 18:18:37
 Authentication Payload size 853
 Signature of size 1151
 Signature at: 40
 ./sign-efi-sig-list -c KEK.crt -k KEK.key db DB2.esl DB2.auth
-Timestamp is 2026-4-22 00:40:09
+Timestamp is 2025-3-19 18:18:37
 Authentication Payload size 853
 Signature of size 1151
 Signature at: 40
 ./sign-efi-sig-list -c KEK.crt -k KEK.key db ms-uefi.esl ms-uefi.auth
-Timestamp is 2026-4-22 00:40:09
+Timestamp is 2025-3-19 18:18:38
 Authentication Payload size 1640
 Signature of size 1151
 Signature at: 40
 ./sign-efi-sig-list -c KEK.crt -k KEK.key db ms-kek.esl ms-kek.auth
 ./sign-efi-sig-list -a -c KEK.crt -k KEK.key dbx PK-blacklist.esl PK-blacklist.auth
-Timestamp is 2026-4-22 00:40:09
+Timestamp is 2025-3-19 18:18:39
 Authentication Payload size 1600
 Signature of size 1151
 Signature at: 40
@@ -781,26 +817,26 @@
 	install -p -m0644 debian/.debhelper/generated/efitools/dh_installchangelogs.dch.trimmed debian/efitools/usr/share/doc/efitools/changelog.Debian
    dh_installman
 	man-recode --to-code UTF-8 --suffix .dh-new debian/efitools/usr/share/man/man1/cert-to-efi-hash-list.1
-	man-recode --to-code UTF-8 --suffix .dh-new debian/efitools/usr/share/man/man1/cert-to-efi-sig-list.1
-	man-recode --to-code UTF-8 --suffix .dh-new debian/efitools/usr/share/man/man1/efi-readvar.1
 	man-recode --to-code UTF-8 --suffix .dh-new debian/efitools/usr/share/man/man1/efi-updatevar.1
-	man-recode --to-code UTF-8 --suffix .dh-new debian/efitools/usr/share/man/man1/hash-to-efi-sig-list.1
+	man-recode --to-code UTF-8 --suffix .dh-new debian/efitools/usr/share/man/man1/efi-readvar.1
 	man-recode --to-code UTF-8 --suffix .dh-new debian/efitools/usr/share/man/man1/sig-list-to-certs.1
+	man-recode --to-code UTF-8 --suffix .dh-new debian/efitools/usr/share/man/man1/hash-to-efi-sig-list.1
 	man-recode --to-code UTF-8 --suffix .dh-new debian/efitools/usr/share/man/man1/sign-efi-sig-list.1
+	man-recode --to-code UTF-8 --suffix .dh-new debian/efitools/usr/share/man/man1/cert-to-efi-sig-list.1
+	mv debian/efitools/usr/share/man/man1/sig-list-to-certs.1.dh-new debian/efitools/usr/share/man/man1/sig-list-to-certs.1
+	chmod 0644 -- debian/efitools/usr/share/man/man1/sig-list-to-certs.1
 	mv debian/efitools/usr/share/man/man1/efi-readvar.1.dh-new debian/efitools/usr/share/man/man1/efi-readvar.1
 	chmod 0644 -- debian/efitools/usr/share/man/man1/efi-readvar.1
-	mv debian/efitools/usr/share/man/man1/cert-to-efi-sig-list.1.dh-new debian/efitools/usr/share/man/man1/cert-to-efi-sig-list.1
-	chmod 0644 -- debian/efitools/usr/share/man/man1/cert-to-efi-sig-list.1
 	mv debian/efitools/usr/share/man/man1/hash-to-efi-sig-list.1.dh-new debian/efitools/usr/share/man/man1/hash-to-efi-sig-list.1
 	chmod 0644 -- debian/efitools/usr/share/man/man1/hash-to-efi-sig-list.1
-	mv debian/efitools/usr/share/man/man1/sig-list-to-certs.1.dh-new debian/efitools/usr/share/man/man1/sig-list-to-certs.1
-	chmod 0644 -- debian/efitools/usr/share/man/man1/sig-list-to-certs.1
-	mv debian/efitools/usr/share/man/man1/efi-updatevar.1.dh-new debian/efitools/usr/share/man/man1/efi-updatevar.1
-	chmod 0644 -- debian/efitools/usr/share/man/man1/efi-updatevar.1
 	mv debian/efitools/usr/share/man/man1/cert-to-efi-hash-list.1.dh-new debian/efitools/usr/share/man/man1/cert-to-efi-hash-list.1
 	chmod 0644 -- debian/efitools/usr/share/man/man1/cert-to-efi-hash-list.1
 	mv debian/efitools/usr/share/man/man1/sign-efi-sig-list.1.dh-new debian/efitools/usr/share/man/man1/sign-efi-sig-list.1
 	chmod 0644 -- debian/efitools/usr/share/man/man1/sign-efi-sig-list.1
+	mv debian/efitools/usr/share/man/man1/cert-to-efi-sig-list.1.dh-new debian/efitools/usr/share/man/man1/cert-to-efi-sig-list.1
+	chmod 0644 -- debian/efitools/usr/share/man/man1/cert-to-efi-sig-list.1
+	mv debian/efitools/usr/share/man/man1/efi-updatevar.1.dh-new debian/efitools/usr/share/man/man1/efi-updatevar.1
+	chmod 0644 -- debian/efitools/usr/share/man/man1/efi-updatevar.1
    dh_perl
    dh_link
    dh_strip_nondeterminism
@@ -828,11 +864,6 @@
 	chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/84/3c142d2755a38e3c7aa02ba4ca45809d0020bc.debug
 	strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/sign-efi-sig-list
 	objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/84/3c142d2755a38e3c7aa02ba4ca45809d0020bc.debug debian/efitools/usr/bin/sign-efi-sig-list
-	install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/04
-	objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/efi-updatevar debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/04/27eb839d4c4857ca40c496a03cce6bb2cfb89d.debug
-	chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/04/27eb839d4c4857ca40c496a03cce6bb2cfb89d.debug
-	strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/efi-updatevar
-	objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/04/27eb839d4c4857ca40c496a03cce6bb2cfb89d.debug debian/efitools/usr/bin/efi-updatevar
 	install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/91
 	objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/sig-list-to-certs debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/91/7542c4d1808889db97939a2b4a662cecf88cb6.debug
 	chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/91/7542c4d1808889db97939a2b4a662cecf88cb6.debug
@@ -843,26 +874,31 @@
 	chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/ca/205ec0dba4970557a5a81f4b7af8adaddf9914.debug
 	strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/hash-to-efi-sig-list
 	objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/ca/205ec0dba4970557a5a81f4b7af8adaddf9914.debug debian/efitools/usr/bin/hash-to-efi-sig-list
-	install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/90
-	objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/flash-var debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/90/ee0d75966d70309567b59318edd6b1347d6984.debug
-	chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/90/ee0d75966d70309567b59318edd6b1347d6984.debug
-	strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/flash-var
-	objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/90/ee0d75966d70309567b59318edd6b1347d6984.debug debian/efitools/usr/bin/flash-var
+	install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/04
+	objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/efi-updatevar debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/04/27eb839d4c4857ca40c496a03cce6bb2cfb89d.debug
+	chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/04/27eb839d4c4857ca40c496a03cce6bb2cfb89d.debug
+	strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/efi-updatevar
+	objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/04/27eb839d4c4857ca40c496a03cce6bb2cfb89d.debug debian/efitools/usr/bin/efi-updatevar
 	install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/db
 	objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/efi-readvar debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/db/bca55e0300eef20bddf1444bb119b1cc81dc28.debug
 	chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/db/bca55e0300eef20bddf1444bb119b1cc81dc28.debug
 	strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/efi-readvar
 	objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/db/bca55e0300eef20bddf1444bb119b1cc81dc28.debug debian/efitools/usr/bin/efi-readvar
-	install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/88
-	objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/cert-to-efi-hash-list debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/88/304b46093f5f0ff627a199c13daa29c17dd515.debug
-	chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/88/304b46093f5f0ff627a199c13daa29c17dd515.debug
-	strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/cert-to-efi-hash-list
-	objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/88/304b46093f5f0ff627a199c13daa29c17dd515.debug debian/efitools/usr/bin/cert-to-efi-hash-list
+	install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/90
+	objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/flash-var debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/90/ee0d75966d70309567b59318edd6b1347d6984.debug
+	chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/90/ee0d75966d70309567b59318edd6b1347d6984.debug
+	strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/flash-var
+	objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/90/ee0d75966d70309567b59318edd6b1347d6984.debug debian/efitools/usr/bin/flash-var
 	install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/3c
 	objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/cert-to-efi-sig-list debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/3c/102d1402caf61d8e79cf63e8d07ab4be7f9d58.debug
 	chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/3c/102d1402caf61d8e79cf63e8d07ab4be7f9d58.debug
 	strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/cert-to-efi-sig-list
 	objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/3c/102d1402caf61d8e79cf63e8d07ab4be7f9d58.debug debian/efitools/usr/bin/cert-to-efi-sig-list
+	install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/88
+	objcopy --only-keep-debug --compress-debug-sections debian/efitools/usr/bin/cert-to-efi-hash-list debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/88/304b46093f5f0ff627a199c13daa29c17dd515.debug
+	chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/88/304b46093f5f0ff627a199c13daa29c17dd515.debug
+	strip --remove-section=.comment --remove-section=.note debian/efitools/usr/bin/cert-to-efi-hash-list
+	objcopy --add-gnu-debuglink debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.build-id/88/304b46093f5f0ff627a199c13daa29c17dd515.debug debian/efitools/usr/bin/cert-to-efi-hash-list
 	install -m0755 -d debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.dwz
 	cp --reflink=auto -a debian/efitools/usr/lib/debug/.dwz/aarch64-linux-gnu debian/.debhelper/efitools/dbgsym-root/usr/lib/debug/.dwz
 	rm -fr debian/efitools/usr/lib/debug/.dwz
@@ -874,7 +910,7 @@
 	rm -f debian/efitools/DEBIAN/shlibs
    dh_shlibdeps
 	install -m0755 -d debian/efitools/DEBIAN
-	dpkg-shlibdeps -Tdebian/efitools.substvars debian/efitools/usr/bin/sign-efi-sig-list debian/efitools/usr/bin/efi-updatevar debian/efitools/usr/bin/sig-list-to-certs debian/efitools/usr/bin/hash-to-efi-sig-list debian/efitools/usr/bin/flash-var debian/efitools/usr/bin/efi-readvar debian/efitools/usr/bin/cert-to-efi-hash-list debian/efitools/usr/bin/cert-to-efi-sig-list
+	dpkg-shlibdeps -Tdebian/efitools.substvars debian/efitools/usr/bin/sign-efi-sig-list debian/efitools/usr/bin/sig-list-to-certs debian/efitools/usr/bin/hash-to-efi-sig-list debian/efitools/usr/bin/efi-updatevar debian/efitools/usr/bin/efi-readvar debian/efitools/usr/bin/flash-var debian/efitools/usr/bin/cert-to-efi-sig-list debian/efitools/usr/bin/cert-to-efi-hash-list
    dh_installdeb
 	install -m0755 -d debian/efitools/DEBIAN
    dh_gencontrol
@@ -894,10 +930,10 @@
 	cd debian/.debhelper/efitools/dbgsym-root >/dev/null && xargs -r0 md5sum | perl -pe 'if (s@^\\@@) { s/\\\\/\\/g; }' > DEBIAN/md5sums
 	chmod 0644 -- debian/.debhelper/efitools/dbgsym-root/DEBIAN/md5sums
    dh_builddeb
-	dpkg-deb --root-owner-group --build debian/efitools ..
 	dpkg-deb --root-owner-group --build debian/.debhelper/efitools/dbgsym-root ..
-dpkg-deb: building package 'efitools' in '../efitools_1.9.2-3.5_arm64.deb'.
+	dpkg-deb --root-owner-group --build debian/efitools ..
 dpkg-deb: building package 'efitools-dbgsym' in '../efitools-dbgsym_1.9.2-3.5_arm64.deb'.
+dpkg-deb: building package 'efitools' in '../efitools_1.9.2-3.5_arm64.deb'.
  dpkg-genbuildinfo --build=binary -O../efitools_1.9.2-3.5_arm64.buildinfo
  dpkg-genchanges --build=binary -O../efitools_1.9.2-3.5_arm64.changes
 dpkg-genchanges: info: binary-only upload (no source code included)
@@ -905,12 +941,14 @@
 dpkg-buildpackage: info: binary-only upload (no source included)
 dpkg-genchanges: info: not including original source code in upload
 I: copying local configuration
+I: user script /srv/workspace/pbuilder/1401574/tmp/hooks/B01_cleanup starting
+I: user script /srv/workspace/pbuilder/1401574/tmp/hooks/B01_cleanup finished
 I: unmounting dev/ptmx filesystem
 I: unmounting dev/pts filesystem
 I: unmounting dev/shm filesystem
 I: unmounting proc filesystem
 I: unmounting sys filesystem
 I: cleaning the build env 
-I: removing directory /srv/workspace/pbuilder/1893909 and its subdirectories
-I: Current time: Tue Apr 21 12:40:15 -12 2026
-I: pbuilder-time-stamp: 1776818415
+I: removing directory /srv/workspace/pbuilder/1401574 and its subdirectories
+I: Current time: Thu Mar 20 08:18:56 +14 2025
+I: pbuilder-time-stamp: 1742408336