Diff of the two buildlogs: -- --- b1/build.log 2024-12-16 08:19:09.723218870 +0000 +++ b2/build.log 2024-12-16 08:27:01.333877385 +0000 @@ -1,6 +1,6 @@ I: pbuilder: network access will be disabled during build -I: Current time: Sun Dec 15 20:13:15 -12 2024 -I: pbuilder-time-stamp: 1734336795 +I: Current time: Mon Dec 16 22:19:18 +14 2024 +I: pbuilder-time-stamp: 1734337158 I: Building the build Environment I: extracting base tarball [/var/cache/pbuilder/trixie-reproducible-base.tgz] I: copying local configuration @@ -30,52 +30,84 @@ dpkg-source: info: applying disable-TestGetCode.patch I: Not using root during the build. I: Installing the build-deps -I: user script /srv/workspace/pbuilder/6760/tmp/hooks/D02_print_environment starting +I: user script /srv/workspace/pbuilder/25194/tmp/hooks/D01_modify_environment starting +debug: Running on virt32a. +I: Changing host+domainname to test build reproducibility +I: Adding a custom variable just for the fun of it... +I: Changing /bin/sh to bash +'/bin/sh' -> '/bin/bash' +lrwxrwxrwx 1 root root 9 Dec 16 08:20 /bin/sh -> /bin/bash +I: Setting pbuilder2's login shell to /bin/bash +I: Setting pbuilder2's GECOS to second user,second room,second work-phone,second home-phone,second other +I: user script /srv/workspace/pbuilder/25194/tmp/hooks/D01_modify_environment finished +I: user script /srv/workspace/pbuilder/25194/tmp/hooks/D02_print_environment starting I: set - BUILDDIR='/build/reproducible-path' - BUILDUSERGECOS='first user,first room,first work-phone,first home-phone,first other' - BUILDUSERNAME='pbuilder1' - BUILD_ARCH='armhf' - DEBIAN_FRONTEND='noninteractive' - DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=3 ' - DISTRIBUTION='trixie' - HOME='/root' - HOST_ARCH='armhf' + BASH=/bin/sh + BASHOPTS=checkwinsize:cmdhist:complete_fullquote:extquote:force_fignore:globasciiranges:globskipdots:hostcomplete:interactive_comments:patsub_replacement:progcomp:promptvars:sourcepath + BASH_ALIASES=() + BASH_ARGC=() + BASH_ARGV=() + BASH_CMDS=() + BASH_LINENO=([0]="12" [1]="0") + BASH_LOADABLES_PATH=/usr/local/lib/bash:/usr/lib/bash:/opt/local/lib/bash:/usr/pkg/lib/bash:/opt/pkg/lib/bash:. + BASH_SOURCE=([0]="/tmp/hooks/D02_print_environment" [1]="/tmp/hooks/D02_print_environment") + BASH_VERSINFO=([0]="5" [1]="2" [2]="37" [3]="1" [4]="release" [5]="arm-unknown-linux-gnueabihf") + BASH_VERSION='5.2.37(1)-release' + BUILDDIR=/build/reproducible-path + BUILDUSERGECOS='second user,second room,second work-phone,second home-phone,second other' + BUILDUSERNAME=pbuilder2 + BUILD_ARCH=armhf + DEBIAN_FRONTEND=noninteractive + DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=4 ' + DIRSTACK=() + DISTRIBUTION=trixie + EUID=0 + FUNCNAME=([0]="Echo" [1]="main") + GROUPS=() + HOME=/root + HOSTNAME=i-capture-the-hostname + HOSTTYPE=arm + HOST_ARCH=armhf IFS=' ' - INVOCATION_ID='c80c1162221847bebb61f5108b0bb17d' - LANG='C' - LANGUAGE='en_US:en' - LC_ALL='C' - MAIL='/var/mail/root' - OPTIND='1' - PATH='/usr/sbin:/usr/bin:/sbin:/bin:/usr/games' - PBCURRENTCOMMANDLINEOPERATION='build' - PBUILDER_OPERATION='build' - PBUILDER_PKGDATADIR='/usr/share/pbuilder' - PBUILDER_PKGLIBDIR='/usr/lib/pbuilder' - PBUILDER_SYSCONFDIR='/etc' - PPID='6760' - PS1='# ' - PS2='> ' + INVOCATION_ID=1d27cd0c96ee4c6b9897fc78fed8647d + LANG=C + LANGUAGE=it_CH:it + LC_ALL=C + MACHTYPE=arm-unknown-linux-gnueabihf + MAIL=/var/mail/root + OPTERR=1 + OPTIND=1 + OSTYPE=linux-gnueabihf + PATH=/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path + PBCURRENTCOMMANDLINEOPERATION=build + PBUILDER_OPERATION=build + PBUILDER_PKGDATADIR=/usr/share/pbuilder + PBUILDER_PKGLIBDIR=/usr/lib/pbuilder + PBUILDER_SYSCONFDIR=/etc + PIPESTATUS=([0]="0") + POSIXLY_CORRECT=y + PPID=25194 PS4='+ ' - PWD='/' - SHELL='/bin/bash' - SHLVL='2' - SUDO_COMMAND='/usr/bin/timeout -k 18.1h 18h /usr/bin/ionice -c 3 /usr/bin/nice /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.YOwEVtLA/pbuilderrc_Z8a6 --distribution trixie --hookdir /etc/pbuilder/first-build-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/trixie-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.YOwEVtLA/b1 --logfile b1/build.log golang-github-sigstore-sigstore_1.8.10-3.dsc' - SUDO_GID='110' - SUDO_UID='103' - SUDO_USER='jenkins' - TERM='unknown' - TZ='/usr/share/zoneinfo/Etc/GMT+12' - USER='root' - _='/usr/bin/systemd-run' - http_proxy='http://10.0.0.15:3142/' + PWD=/ + SHELL=/bin/bash + SHELLOPTS=braceexpand:errexit:hashall:interactive-comments:posix + SHLVL=3 + SUDO_COMMAND='/usr/bin/timeout -k 24.1h 24h /usr/bin/ionice -c 3 /usr/bin/nice -n 11 /usr/bin/unshare --uts -- /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.YOwEVtLA/pbuilderrc_lWvt --distribution trixie --hookdir /etc/pbuilder/rebuild-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/trixie-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.YOwEVtLA/b2 --logfile b2/build.log golang-github-sigstore-sigstore_1.8.10-3.dsc' + SUDO_GID=113 + SUDO_UID=107 + SUDO_USER=jenkins + TERM=unknown + TZ=/usr/share/zoneinfo/Etc/GMT-14 + UID=0 + USER=root + _='I: set' + http_proxy=http://10.0.0.15:3142/ I: uname -a - Linux virt64z 6.1.0-28-arm64 #1 SMP Debian 6.1.119-1 (2024-11-22) aarch64 GNU/Linux + Linux i-capture-the-hostname 6.1.0-28-armmp-lpae #1 SMP Debian 6.1.119-1 (2024-11-22) armv7l GNU/Linux I: ls -l /bin lrwxrwxrwx 1 root root 7 Nov 22 14:40 /bin -> usr/bin -I: user script /srv/workspace/pbuilder/6760/tmp/hooks/D02_print_environment finished +I: user script /srv/workspace/pbuilder/25194/tmp/hooks/D02_print_environment finished -> Attempting to satisfy build-dependencies -> Creating pbuilder-satisfydepends-dummy package Package: pbuilder-satisfydepends-dummy @@ -598,7 +630,7 @@ Get: 435 http://deb.debian.org/debian trixie/main armhf golang-github-skratchdot-open-golang-dev all 0.0~git20160302.0.75fb7ed-2.1 [4156 B] Get: 436 http://deb.debian.org/debian trixie/main armhf golang-github-theupdateframework-go-tuf-dev all 2.0.2+0.7.0-1 [200 kB] Get: 437 http://deb.debian.org/debian trixie/main armhf golang-github-sigstore-sigstore-dev all 1.8.10-3 [150 kB] -Fetched 215 MB in 7s (31.4 MB/s) +Fetched 215 MB in 4s (49.2 MB/s) debconf: delaying package configuration, since apt-utils is not installed Selecting previously unselected package golang-golang-x-sys-dev. (Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 19680 files and directories currently installed.) @@ -2003,8 +2035,8 @@ Setting up tzdata (2024b-4) ... Current default time zone: 'Etc/UTC' -Local time is now: Mon Dec 16 08:15:54 UTC 2024. -Universal Time is now: Mon Dec 16 08:15:54 UTC 2024. +Local time is now: Mon Dec 16 08:23:26 UTC 2024. +Universal Time is now: Mon Dec 16 08:23:26 UTC 2024. Run 'dpkg-reconfigure tzdata' if you wish to change it. Setting up golang-github-coreos-go-semver-dev (0.3.0-1) ... @@ -2367,7 +2399,11 @@ Building tag database... -> Finished parsing the build-deps I: Building the package -I: Running cd /build/reproducible-path/golang-github-sigstore-sigstore-1.8.10/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-genchanges -S > ../golang-github-sigstore-sigstore_1.8.10-3_source.changes +I: user script /srv/workspace/pbuilder/25194/tmp/hooks/A99_set_merged_usr starting +Not re-configuring usrmerge for trixie +I: user script /srv/workspace/pbuilder/25194/tmp/hooks/A99_set_merged_usr finished +hostname: Name or service not known +I: Running cd /build/reproducible-path/golang-github-sigstore-sigstore-1.8.10/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-genchanges -S > ../golang-github-sigstore-sigstore_1.8.10-3_source.changes dpkg-buildpackage: info: source package golang-github-sigstore-sigstore dpkg-buildpackage: info: source version 1.8.10-3 dpkg-buildpackage: info: source distribution unstable @@ -2394,17 +2430,17 @@ perl -pi -e 's,github.com/theupdateframework/go-tuf,github.com/theupdateframework/go-tuf/v0,' make[1]: Leaving directory '/build/reproducible-path/golang-github-sigstore-sigstore-1.8.10' dh_auto_build -O--builddirectory=_build -O--buildsystem=golang - cd _build && go install -trimpath -v -p 3 github.com/sigstore/sigstore/pkg/cryptoutils github.com/sigstore/sigstore/pkg/fulcioroots github.com/sigstore/sigstore/pkg/oauth github.com/sigstore/sigstore/pkg/oauth/internal github.com/sigstore/sigstore/pkg/oauth/oidc github.com/sigstore/sigstore/pkg/oauthflow github.com/sigstore/sigstore/pkg/signature github.com/sigstore/sigstore/pkg/signature/dsse github.com/sigstore/sigstore/pkg/signature/kms github.com/sigstore/sigstore/pkg/signature/kms/aws github.com/sigstore/sigstore/pkg/signature/kms/fake github.com/sigstore/sigstore/pkg/signature/options github.com/sigstore/sigstore/pkg/signature/payload github.com/sigstore/sigstore/pkg/signature/ssh github.com/sigstore/sigstore/pkg/tuf github.com/sigstore/sigstore/test + cd _build && go install -trimpath -v -p 4 github.com/sigstore/sigstore/pkg/cryptoutils github.com/sigstore/sigstore/pkg/fulcioroots github.com/sigstore/sigstore/pkg/oauth github.com/sigstore/sigstore/pkg/oauth/internal github.com/sigstore/sigstore/pkg/oauth/oidc github.com/sigstore/sigstore/pkg/oauthflow github.com/sigstore/sigstore/pkg/signature github.com/sigstore/sigstore/pkg/signature/dsse github.com/sigstore/sigstore/pkg/signature/kms github.com/sigstore/sigstore/pkg/signature/kms/aws github.com/sigstore/sigstore/pkg/signature/kms/fake github.com/sigstore/sigstore/pkg/signature/options github.com/sigstore/sigstore/pkg/signature/payload github.com/sigstore/sigstore/pkg/signature/ssh github.com/sigstore/sigstore/pkg/tuf github.com/sigstore/sigstore/test internal/unsafeheader +internal/byteorder internal/goarch +internal/coverage/rtcov internal/cpu -internal/byteorder internal/abi -internal/chacha8rand -internal/bytealg -internal/coverage/rtcov internal/godebugs +internal/chacha8rand internal/goexperiment +internal/bytealg internal/goos internal/profilerecord internal/runtime/atomic @@ -2412,20 +2448,20 @@ internal/stringslite runtime/internal/math runtime/internal/sys -internal/runtime/exithook internal/race sync/atomic unicode +internal/runtime/exithook unicode/utf8 -runtime math/bits -math crypto/internal/alias crypto/internal/boring/sig cmp +math internal/itoa internal/asan internal/msan +runtime unicode/utf16 vendor/golang.org/x/crypto/cryptobyte/asn1 internal/nettrace @@ -2437,22 +2473,23 @@ container/list vendor/golang.org/x/crypto/internal/alias github.com/aws/aws-sdk-go-v2/internal/sdkio +iter crypto/subtle sync internal/reflectlite -iter slices internal/weak maps -internal/bisect internal/testlog internal/singleflight +internal/bisect +runtime/cgo errors sort io strconv -bytes hash +bytes crypto/internal/edwards25519/field crypto/internal/nistec/fiat crypto/cipher @@ -2465,39 +2502,47 @@ path internal/godebug syscall +math/rand +strings time crypto/internal/nistec -internal/fmtsort internal/syscall/unix +internal/fmtsort internal/syscall/execenv -math/rand -crypto/ecdh -strings crypto/sha512 -io/fs -internal/poll crypto/internal/edwards25519 -internal/filepathlite crypto/sha1 +crypto/ecdh crypto/des crypto/md5 -os crypto/sha256 encoding/binary +io/fs +internal/poll context +internal/filepathlite vendor/golang.org/x/net/dns/dnsmessage +math/rand/v2 encoding/base64 +os encoding/pem -math/rand/v2 internal/concurrent -fmt unique -runtime/cgo +golang.org/x/crypto/internal/poly1305 net/netip +golang.org/x/crypto/nacl/secretbox +crypto/hmac +golang.org/x/sys/unix +golang.org/x/crypto/pbkdf2 +golang.org/x/crypto/scrypt +embed +regexp/syntax +fmt +net +path/filepath math/big encoding/hex net/url -path/filepath encoding/json crypto/elliptic crypto/internal/bigmod @@ -2507,106 +2552,95 @@ crypto/ed25519 crypto/rsa crypto/dsa -golang.org/x/crypto/internal/poly1305 -net -golang.org/x/crypto/nacl/secretbox -crypto/hmac +github.com/secure-systems-lab/go-securesystemslib/encrypted vendor/golang.org/x/crypto/cryptobyte crypto/x509/pkix -golang.org/x/crypto/pbkdf2 -golang.org/x/crypto/scrypt -github.com/secure-systems-lab/go-securesystemslib/encrypted -crypto/ecdsa -golang.org/x/sys/unix -embed -regexp/syntax +golang.org/x/term regexp -github.com/opencontainers/go-digest github.com/sigstore/sigstore/pkg/signature/options +crypto/ecdsa golang.org/x/sys/cpu -golang.org/x/crypto/sha3 -golang.org/x/term github.com/secure-systems-lab/go-securesystemslib/cjson +golang.org/x/crypto/sha3 +github.com/opencontainers/go-digest github.com/theupdateframework/go-tuf/v0/data github.com/theupdateframework/go-tuf/v0/internal/fsutil github.com/theupdateframework/go-tuf/v0/internal/roles log -github.com/theupdateframework/go-tuf/v0/util bufio +github.com/theupdateframework/go-tuf/v0/util hash/crc32 vendor/golang.org/x/crypto/chacha20 compress/flate vendor/golang.org/x/crypto/internal/poly1305 -vendor/golang.org/x/crypto/chacha20poly1305 vendor/golang.org/x/crypto/hkdf -crypto/internal/hpke +vendor/golang.org/x/crypto/chacha20poly1305 vendor/golang.org/x/sys/cpu -compress/gzip +crypto/internal/hpke vendor/golang.org/x/crypto/sha3 crypto/rc4 vendor/golang.org/x/text/transform -crypto/internal/mlkem768 +compress/gzip vendor/golang.org/x/text/unicode/bidi +crypto/internal/mlkem768 vendor/golang.org/x/text/unicode/norm -vendor/golang.org/x/text/secure/bidirule vendor/golang.org/x/net/http2/hpack +vendor/golang.org/x/text/secure/bidirule mime -vendor/golang.org/x/net/idna mime/quotedprintable net/http/internal -crypto/x509 -github.com/google/go-containerregistry/pkg/name -net/textproto -github.com/sigstore/sigstore/pkg/signature/payload -vendor/golang.org/x/net/http/httpproxy -vendor/golang.org/x/net/http/httpguts -mime/multipart net/http/internal/ascii github.com/syndtr/goleveldb/leveldb/util -github.com/syndtr/goleveldb/leveldb/cache github.com/syndtr/goleveldb/leveldb/comparer io/ioutil +github.com/syndtr/goleveldb/leveldb/cache +github.com/syndtr/goleveldb/leveldb/storage github.com/syndtr/goleveldb/leveldb/filter github.com/syndtr/goleveldb/leveldb/opt -github.com/syndtr/goleveldb/leveldb/storage +vendor/golang.org/x/net/idna github.com/golang/snappy flag -github.com/sigstore/sigstore/pkg/cryptoutils -github.com/theupdateframework/go-tuf/v0/pkg/keys -github.com/sigstore/sigstore/pkg/signature -crypto/tls -github.com/theupdateframework/go-tuf/v0/internal/signer -github.com/theupdateframework/go-tuf/v0/verify -github.com/theupdateframework/go-tuf/v0/pkg/targets -github.com/theupdateframework/go-tuf/v0/sign +crypto/x509 +github.com/google/go-containerregistry/pkg/name +github.com/sigstore/sigstore/pkg/signature/payload +net/textproto github.com/syndtr/goleveldb/leveldb/errors -github.com/theupdateframework/go-tuf/v0 +vendor/golang.org/x/net/http/httpproxy github.com/syndtr/goleveldb/leveldb/iterator github.com/syndtr/goleveldb/leveldb/journal +vendor/golang.org/x/net/http/httpguts +mime/multipart github.com/syndtr/goleveldb/leveldb/memdb github.com/syndtr/goleveldb/leveldb/table net/http/internal/testcert internal/sysinfo runtime/debug -github.com/syndtr/goleveldb/leveldb runtime/trace +github.com/syndtr/goleveldb/leveldb +github.com/sigstore/sigstore/pkg/cryptoutils testing text/template/parse -net/http/httptrace -net/http +github.com/sigstore/sigstore/pkg/signature +github.com/theupdateframework/go-tuf/v0/pkg/keys +crypto/tls +text/template +github.com/theupdateframework/go-tuf/v0/internal/signer +github.com/theupdateframework/go-tuf/v0/verify +github.com/theupdateframework/go-tuf/v0/pkg/targets +github.com/theupdateframework/go-tuf/v0/sign +github.com/theupdateframework/go-tuf/v0 golang.org/x/crypto/ed25519 gopkg.in/square/go-jose.v2/cipher gopkg.in/square/go-jose.v2/json -text/template -gopkg.in/square/go-jose.v2 github.com/sigstore/sigstore/pkg/oauth os/exec -github.com/pkg/browser database/sql/driver github.com/segmentio/ksuid +github.com/pkg/browser github.com/go-jose/go-jose/v3/cipher github.com/go-jose/go-jose/v3/json github.com/skratchdot/open-golang/open +gopkg.in/square/go-jose.v2 golang.org/x/crypto/chacha20 golang.org/x/crypto/curve25519 golang.org/x/crypto/blowfish @@ -2615,37 +2649,22 @@ github.com/go-jose/go-jose/v3 github.com/sigstore/sigstore/pkg/signature/kms github.com/aws/aws-sdk-go-v2/internal/rand +net/http/httptrace github.com/aws/aws-sdk-go-v2/internal/sdk github.com/aws/aws-sdk-go-v2/internal/sync/singleflight github.com/aws/smithy-go/context +net/http github.com/aws/smithy-go/internal/sync/singleflight github.com/aws/smithy-go/logging github.com/aws/smithy-go/middleware github.com/aws/smithy-go -github.com/secure-systems-lab/go-securesystemslib/dsse -github.com/aws/smithy-go/auth github.com/aws/smithy-go/time -github.com/sigstore/sigstore/pkg/signature/dsse github.com/aws/smithy-go/transport/http/internal/io +github.com/aws/smithy-go/auth github.com/aws/smithy-go/ptr github.com/aws/smithy-go/rand -github.com/theupdateframework/go-tuf/v0/client -net/http/httptest -golang.org/x/oauth2/internal -golang.org/x/oauth2 -net/http/httputil -github.com/theupdateframework/go-tuf/v0/client/leveldbstore -github.com/sigstore/sigstore/pkg/oauth/internal -github.com/sigstore/sigstore/pkg/tuf -github.com/coreos/go-oidc/v3/oidc -github.com/aws/smithy-go/transport/http -github.com/sigstore/sigstore/pkg/fulcioroots -github.com/sigstore/sigstore/pkg/oauth/oidc -github.com/sigstore/sigstore/pkg/oauthflow github.com/aws/aws-sdk-go-v2/aws/middleware/private/metrics -github.com/aws/smithy-go/auth/bearer github.com/aws/aws-sdk-go-v2/aws/ratelimit -github.com/aws/aws-sdk-go-v2/aws github.com/aws/aws-sdk-go-v2/internal/context github.com/aws/aws-sdk-go-v2/internal/timeconv github.com/aws/aws-sdk-go-v2/feature/ec2/imds/internal/config @@ -2653,58 +2672,75 @@ os/user github.com/aws/aws-sdk-go-v2/aws/protocol/restjson github.com/aws/aws-sdk-go-v2/internal/strings -github.com/aws/aws-sdk-go-v2/internal/auth -github.com/aws/smithy-go/encoding/httpbinding -github.com/aws/aws-sdk-go-v2/aws/middleware -github.com/aws/aws-sdk-go-v2/credentials -github.com/aws/aws-sdk-go-v2/credentials/processcreds -github.com/aws/aws-sdk-go-v2/aws/defaults -github.com/aws/aws-sdk-go-v2/aws/transport/http -github.com/aws/aws-sdk-go-v2/aws/retry -github.com/aws/aws-sdk-go-v2/aws/signer/internal/v4 -github.com/aws/aws-sdk-go-v2/feature/ec2/imds -github.com/aws/aws-sdk-go-v2/credentials/endpointcreds/internal/client -github.com/aws/aws-sdk-go-v2/credentials/endpointcreds -github.com/aws/aws-sdk-go-v2/credentials/ec2rolecreds -github.com/aws/aws-sdk-go-v2/aws/signer/v4 -github.com/aws/aws-sdk-go-v2/internal/configsources -github.com/aws/aws-sdk-go-v2/internal/endpoints -github.com/aws/aws-sdk-go-v2/internal/shareddefaults -github.com/aws/aws-sdk-go-v2/internal/endpoints/awsrulesfn github.com/aws/aws-sdk-go-v2/internal/middleware -github.com/aws/aws-sdk-go-v2/internal/auth/smithy -github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 github.com/aws/smithy-go/document -github.com/aws/smithy-go/endpoints -github.com/aws/aws-sdk-go-v2/service/sso/internal/endpoints -github.com/aws/aws-sdk-go-v2/service/ssooidc/internal/endpoints +github.com/secure-systems-lab/go-securesystemslib/dsse github.com/aws/aws-sdk-go-v2/service/sso/types -github.com/aws/smithy-go/encoding github.com/aws/aws-sdk-go-v2/service/ssooidc/types -github.com/aws/aws-sdk-go-v2/service/sso -github.com/aws/smithy-go/encoding/json +github.com/sigstore/sigstore/pkg/signature/dsse +github.com/aws/smithy-go/encoding encoding/xml -github.com/aws/aws-sdk-go-v2/service/ssooidc -github.com/aws/aws-sdk-go-v2/aws/protocol/query -github.com/aws/aws-sdk-go-v2/aws/protocol/xml -github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding -github.com/aws/aws-sdk-go-v2/service/internal/presigned-url -github.com/aws/aws-sdk-go-v2/service/sts/internal/endpoints +github.com/aws/smithy-go/encoding/json github.com/aws/aws-sdk-go-v2/service/sts/types -github.com/aws/aws-sdk-go-v2/credentials/ssocreds -github.com/aws/smithy-go/encoding/xml github.com/aws/aws-sdk-go-v2/internal/ini -github.com/aws/smithy-go/private/requestcompression -github.com/aws/aws-sdk-go-v2/service/kms/internal/endpoints -github.com/aws/aws-sdk-go-v2/service/sts github.com/aws/aws-sdk-go-v2/service/kms/types +github.com/aws/aws-sdk-go-v2/aws/protocol/xml +github.com/aws/smithy-go/encoding/xml container/heap golang.org/x/sync/singleflight github.com/jellydator/ttlcache github.com/sigstore/sigstore/pkg/signature/kms/fake github.com/sigstore/sigstore/pkg/signature/ssh github.com/sigstore/sigstore/test +github.com/aws/aws-sdk-go-v2/internal/shareddefaults +golang.org/x/oauth2/internal +github.com/theupdateframework/go-tuf/v0/client +net/http/httptest +net/http/httputil +golang.org/x/oauth2 +github.com/aws/smithy-go/encoding/httpbinding +github.com/theupdateframework/go-tuf/v0/client/leveldbstore +github.com/aws/smithy-go/transport/http +github.com/sigstore/sigstore/pkg/oauth/internal +github.com/sigstore/sigstore/pkg/tuf +github.com/coreos/go-oidc/v3/oidc +github.com/aws/smithy-go/endpoints +github.com/sigstore/sigstore/pkg/fulcioroots +github.com/sigstore/sigstore/pkg/oauth/oidc +github.com/sigstore/sigstore/pkg/oauthflow +github.com/aws/smithy-go/auth/bearer +github.com/aws/aws-sdk-go-v2/internal/auth +github.com/aws/aws-sdk-go-v2/aws +github.com/aws/aws-sdk-go-v2/internal/endpoints/awsrulesfn +github.com/aws/aws-sdk-go-v2/aws/protocol/query +github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding +github.com/aws/smithy-go/private/requestcompression +github.com/aws/aws-sdk-go-v2/credentials/processcreds +github.com/aws/aws-sdk-go-v2/aws/middleware +github.com/aws/aws-sdk-go-v2/aws/defaults +github.com/aws/aws-sdk-go-v2/credentials +github.com/aws/aws-sdk-go-v2/aws/signer/internal/v4 +github.com/aws/aws-sdk-go-v2/internal/configsources +github.com/aws/aws-sdk-go-v2/internal/endpoints +github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 +github.com/aws/aws-sdk-go-v2/service/ssooidc/internal/endpoints +github.com/aws/aws-sdk-go-v2/service/sso/internal/endpoints +github.com/aws/aws-sdk-go-v2/aws/transport/http +github.com/aws/aws-sdk-go-v2/aws/signer/v4 +github.com/aws/aws-sdk-go-v2/service/sts/internal/endpoints +github.com/aws/aws-sdk-go-v2/aws/retry +github.com/aws/aws-sdk-go-v2/service/kms/internal/endpoints +github.com/aws/aws-sdk-go-v2/service/internal/presigned-url +github.com/aws/aws-sdk-go-v2/internal/auth/smithy +github.com/aws/aws-sdk-go-v2/feature/ec2/imds +github.com/aws/aws-sdk-go-v2/credentials/endpointcreds/internal/client +github.com/aws/aws-sdk-go-v2/service/sso +github.com/aws/aws-sdk-go-v2/service/ssooidc +github.com/aws/aws-sdk-go-v2/credentials/endpointcreds +github.com/aws/aws-sdk-go-v2/service/sts +github.com/aws/aws-sdk-go-v2/credentials/ec2rolecreds github.com/aws/aws-sdk-go-v2/service/kms +github.com/aws/aws-sdk-go-v2/credentials/ssocreds github.com/aws/aws-sdk-go-v2/credentials/stscreds github.com/aws/aws-sdk-go-v2/config github.com/sigstore/sigstore/pkg/signature/kms/aws @@ -2720,6 +2756,7 @@ cd _build && go test -vet=off -v -p 2 -tags github.com/sigstore/sigstore/pkg/cryptoutils github.com/sigstore/sigstore/pkg/fulcioroots github.com/sigstore/sigstore/pkg/oauth github.com/sigstore/sigstore/pkg/oauth/internal github.com/sigstore/sigstore/pkg/oauth/oidc github.com/sigstore/sigstore/pkg/oauthflow github.com/sigstore/sigstore/pkg/signature github.com/sigstore/sigstore/pkg/signature/dsse github.com/sigstore/sigstore/pkg/signature/kms github.com/sigstore/sigstore/pkg/signature/kms/aws github.com/sigstore/sigstore/pkg/signature/kms/fake github.com/sigstore/sigstore/pkg/signature/options github.com/sigstore/sigstore/pkg/signature/payload github.com/sigstore/sigstore/pkg/signature/ssh github.com/sigstore/sigstore/pkg/tuf github.com/sigstore/sigstore/test ? github.com/sigstore/sigstore/pkg/fulcioroots [no test files] ? github.com/sigstore/sigstore/pkg/oauth [no test files] +? github.com/sigstore/sigstore/pkg/oauth/oidc [no test files] === RUN TestCertificatesFromPEM === RUN TestCertificatesFromPEM/one_cert === RUN TestCertificatesFromPEM/one_cert/Unmarshal @@ -2815,7 +2852,7 @@ === RUN TestRSAPrivateKeyPEMRoundtrip === PAUSE TestRSAPrivateKeyPEMRoundtrip === RUN TestUnmarshalPEMToPrivateKey ---- PASS: TestUnmarshalPEMToPrivateKey (5.95s) +--- PASS: TestUnmarshalPEMToPrivateKey (12.47s) === RUN TestECDSAPublicKeyPEMRoundtrip === PAUSE TestECDSAPublicKeyPEMRoundtrip === RUN TestEd25519PublicKeyPEMRoundtrip @@ -2823,13 +2860,13 @@ === RUN TestRSAPublicKeyPEMRoundtrip === PAUSE TestRSAPublicKeyPEMRoundtrip === RUN TestSKIDRSA ---- PASS: TestSKIDRSA (1.00s) +--- PASS: TestSKIDRSA (1.18s) === RUN TestSKIDECDSA --- PASS: TestSKIDECDSA (0.00s) === RUN TestSKIDED25519 ---- PASS: TestSKIDED25519 (0.04s) +--- PASS: TestSKIDED25519 (0.03s) === RUN TestEqualKeys ---- PASS: TestEqualKeys (5.28s) +--- PASS: TestEqualKeys (5.93s) === RUN TestValidatePubKeyUnsupported --- PASS: TestValidatePubKeyUnsupported (0.00s) === RUN TestValidatePubKeyRsa @@ -2841,7 +2878,7 @@ === RUN TestValidatePubKeyEd25519 --- PASS: TestValidatePubKeyEd25519 (0.00s) === RUN TestUnmarshalPEMToPublicKey ---- PASS: TestUnmarshalPEMToPublicKey (3.89s) +--- PASS: TestUnmarshalPEMToPublicKey (5.24s) === RUN TestMarshalAndUnmarshalOtherNameSAN --- PASS: TestMarshalAndUnmarshalOtherNameSAN (0.00s) === RUN TestUnmarshalOtherNameSANFailures @@ -2860,8 +2897,10 @@ --- PASS: TestEd25519PrivateKeyPEMRoundtrip (0.00s) === CONT TestRSAPublicKeyPEMRoundtrip === CONT TestECDSAPublicKeyPEMRoundtrip -=== CONT TestEd25519PublicKeyPEMRoundtrip --- PASS: TestECDSAPublicKeyPEMRoundtrip (0.00s) +=== CONT TestEd25519PublicKeyPEMRoundtrip +--- PASS: TestEd25519PublicKeyPEMRoundtrip (0.00s) +=== CONT TestRSAPrivateKeyPEMRoundtrip === CONT TestGeneratePEMEncodedECDSAKeyPair === RUN TestGeneratePEMEncodedECDSAKeyPair/encrypted === PAUSE TestGeneratePEMEncodedECDSAKeyPair/encrypted @@ -2870,26 +2909,24 @@ === RUN TestGeneratePEMEncodedECDSAKeyPair/SkipPassword_func === PAUSE TestGeneratePEMEncodedECDSAKeyPair/SkipPassword_func === CONT TestGeneratePEMEncodedECDSAKeyPair/encrypted ---- PASS: TestEd25519PublicKeyPEMRoundtrip (0.00s) -=== CONT TestRSAPrivateKeyPEMRoundtrip === CONT TestGeneratePEMEncodedRSAKeyPair/SkipPassword_func +--- PASS: TestRSAPrivateKeyPEMRoundtrip (2.37s) === CONT TestGeneratePEMEncodedRSAKeyPair/nil_pass_func ---- PASS: TestRSAPrivateKeyPEMRoundtrip (4.01s) === CONT TestECDSAPrivateKeyPEMRoundtrip ---- PASS: TestECDSAPrivateKeyPEMRoundtrip (0.01s) +--- PASS: TestECDSAPrivateKeyPEMRoundtrip (0.00s) === CONT TestGeneratePEMEncodedECDSAKeyPair/SkipPassword_func === CONT TestGeneratePEMEncodedECDSAKeyPair/nil_pass_func --- PASS: TestGeneratePEMEncodedECDSAKeyPair (0.00s) - --- PASS: TestGeneratePEMEncodedECDSAKeyPair/encrypted (1.58s) - --- PASS: TestGeneratePEMEncodedECDSAKeyPair/SkipPassword_func (0.01s) - --- PASS: TestGeneratePEMEncodedECDSAKeyPair/nil_pass_func (0.01s) ---- PASS: TestRSAPublicKeyPEMRoundtrip (4.39s) + --- PASS: TestGeneratePEMEncodedECDSAKeyPair/encrypted (1.85s) + --- PASS: TestGeneratePEMEncodedECDSAKeyPair/SkipPassword_func (0.00s) + --- PASS: TestGeneratePEMEncodedECDSAKeyPair/nil_pass_func (0.00s) --- PASS: TestGeneratePEMEncodedRSAKeyPair (0.00s) - --- PASS: TestGeneratePEMEncodedRSAKeyPair/SkipPassword_func (1.83s) - --- PASS: TestGeneratePEMEncodedRSAKeyPair/encrypted (5.14s) - --- PASS: TestGeneratePEMEncodedRSAKeyPair/nil_pass_func (3.17s) + --- PASS: TestGeneratePEMEncodedRSAKeyPair/encrypted (4.86s) + --- PASS: TestGeneratePEMEncodedRSAKeyPair/SkipPassword_func (3.51s) + --- PASS: TestGeneratePEMEncodedRSAKeyPair/nil_pass_func (4.80s) +--- PASS: TestRSAPublicKeyPEMRoundtrip (9.61s) PASS -ok github.com/sigstore/sigstore/pkg/cryptoutils 22.844s +ok github.com/sigstore/sigstore/pkg/cryptoutils 34.569s === RUN TestParseAccessTokenSuccessResponse === RUN TestParseAccessTokenSuccessResponse/json === RUN TestParseAccessTokenSuccessResponse/json_no_access_token @@ -2911,8 +2948,7 @@ === RUN FuzzParseAccessTokenSuccess --- PASS: FuzzParseAccessTokenSuccess (0.00s) PASS -ok github.com/sigstore/sigstore/pkg/oauth/internal 0.012s -? github.com/sigstore/sigstore/pkg/oauth/oidc [no test files] +ok github.com/sigstore/sigstore/pkg/oauth/internal 0.018s === RUN TestClientCredentialsFlowTokenGetter_ccFlow client_credentials_test.go:36: got request: /.well-known/openid-configuration client_credentials_test.go:36: got request: /.well-known/openid-configuration @@ -2932,7 +2968,7 @@ --- PASS: TestInteractiveFlow_IO/default (0.00s) --- PASS: TestInteractiveFlow_IO/buffer (0.00s) PASS -ok github.com/sigstore/sigstore/pkg/oauthflow 0.023s +ok github.com/sigstore/sigstore/pkg/oauthflow 0.033s ? github.com/sigstore/sigstore/pkg/signature/kms [no test files] === RUN TestECDSASignerVerifier --- PASS: TestECDSASignerVerifier (0.07s) @@ -2951,11 +2987,11 @@ === RUN TestED25519phVerifier --- PASS: TestED25519phVerifier (0.00s) === RUN TestRSAPKCS1v15SignerVerifier ---- PASS: TestRSAPKCS1v15SignerVerifier (0.21s) +--- PASS: TestRSAPKCS1v15SignerVerifier (0.28s) === RUN TestRSAPKCS1v15SignerVerifierUnsupportedHash --- PASS: TestRSAPKCS1v15SignerVerifierUnsupportedHash (0.00s) === RUN TestRSAPSSSignerVerifier ---- PASS: TestRSAPSSSignerVerifier (0.39s) +--- PASS: TestRSAPSSSignerVerifier (0.55s) === RUN TestRSAPSSSignerVerifierUnsupportedHash --- PASS: TestRSAPSSSignerVerifierUnsupportedHash (0.00s) === RUN TestLoadEd25519Signer @@ -2963,21 +2999,21 @@ === RUN TestLoadEd25519phSigner --- PASS: TestLoadEd25519phSigner (0.00s) === RUN TestLoadRSAPSSSignerVerifier ---- PASS: TestLoadRSAPSSSignerVerifier (0.02s) +--- PASS: TestLoadRSAPSSSignerVerifier (0.03s) === RUN TestConvertED25519ph --- PASS: TestConvertED25519ph (0.01s) === RUN TestProviderRoundtrip === RUN TestProviderRoundtrip/ECDSA === RUN TestProviderRoundtrip/RSA ---- PASS: TestProviderRoundtrip (3.99s) +--- PASS: TestProviderRoundtrip (1.75s) --- PASS: TestProviderRoundtrip/ECDSA (0.01s) - --- PASS: TestProviderRoundtrip/RSA (0.02s) + --- PASS: TestProviderRoundtrip/RSA (0.03s) === RUN TestLoadUnsafeVerifier ---- PASS: TestLoadUnsafeVerifier (1.00s) +--- PASS: TestLoadUnsafeVerifier (7.26s) === RUN TestLoadVerifier ---- PASS: TestLoadVerifier (1.96s) +--- PASS: TestLoadVerifier (2.14s) PASS -ok github.com/sigstore/sigstore/pkg/signature 7.736s +ok github.com/sigstore/sigstore/pkg/signature 12.183s === RUN TestImplementsDSSESigner --- PASS: TestImplementsDSSESigner (0.00s) === RUN TestImplementsDSSEVerifier @@ -2985,13 +3021,13 @@ === RUN TestRoundTrip --- PASS: TestRoundTrip (0.02s) === RUN TestMultiRoundTrip ---- PASS: TestMultiRoundTrip (0.01s) +--- PASS: TestMultiRoundTrip (0.02s) === RUN TestInvalidThresholdMultiRoundTrip --- PASS: TestInvalidThresholdMultiRoundTrip (0.01s) === RUN TestInvalidSignature --- PASS: TestInvalidSignature (0.00s) PASS -ok github.com/sigstore/sigstore/pkg/signature/dsse 0.051s +ok github.com/sigstore/sigstore/pkg/signature/dsse 0.054s === RUN TestParseReference === RUN TestParseReference/awskms:///1234abcd-12ab-34cd-56ef-1234567890ab === RUN TestParseReference/awskms:///mrk-1234abcd12ab34cd56ef1234567890ab @@ -3025,52 +3061,52 @@ --- PASS: TestParseReference/awskms:///1234abcd-12ab-YYYY-56ef-1234567890ab (0.00s) --- PASS: TestParseReference/awskms://1234abcd-12ab-34cd-56ef-1234567890ab (0.00s) PASS -ok github.com/sigstore/sigstore/pkg/signature/kms/aws 0.015s +ok github.com/sigstore/sigstore/pkg/signature/kms/aws 0.021s ? github.com/sigstore/sigstore/pkg/signature/options [no test files] === RUN TestFakeSigner --- PASS: TestFakeSigner (0.02s) === RUN TestFakeSignerWithPrivateKey --- PASS: TestFakeSignerWithPrivateKey (0.01s) PASS -ok github.com/sigstore/sigstore/pkg/signature/kms/fake 0.040s +ok github.com/sigstore/sigstore/pkg/signature/kms/fake 0.043s === RUN TestMarshalCosign === PAUSE TestMarshalCosign === RUN TestUnmarshalCosign === PAUSE TestUnmarshalCosign === CONT TestMarshalCosign +=== CONT TestUnmarshalCosign === RUN TestMarshalCosign/no_claims === PAUSE TestMarshalCosign/no_claims +=== RUN TestUnmarshalCosign/no_claims === RUN TestMarshalCosign/standard_atomic_signature === PAUSE TestMarshalCosign/standard_atomic_signature -=== RUN TestMarshalCosign/arbitrary_claims -=== PAUSE TestMarshalCosign/arbitrary_claims -=== RUN TestMarshalCosign/custom_identity -=== PAUSE TestMarshalCosign/custom_identity -=== CONT TestMarshalCosign/no_claims -=== CONT TestUnmarshalCosign -=== RUN TestUnmarshalCosign/no_claims === PAUSE TestUnmarshalCosign/no_claims +=== RUN TestMarshalCosign/arbitrary_claims === RUN TestUnmarshalCosign/arbitrary_claims === PAUSE TestUnmarshalCosign/arbitrary_claims === RUN TestUnmarshalCosign/unknown_type === PAUSE TestUnmarshalCosign/unknown_type === CONT TestUnmarshalCosign/no_claims +=== PAUSE TestMarshalCosign/arbitrary_claims +=== RUN TestMarshalCosign/custom_identity +=== PAUSE TestMarshalCosign/custom_identity +=== CONT TestMarshalCosign/no_claims === CONT TestMarshalCosign/custom_identity === CONT TestMarshalCosign/arbitrary_claims === CONT TestMarshalCosign/standard_atomic_signature ---- PASS: TestMarshalCosign (0.00s) - --- PASS: TestMarshalCosign/no_claims (0.00s) - --- PASS: TestMarshalCosign/custom_identity (0.00s) - --- PASS: TestMarshalCosign/arbitrary_claims (0.00s) - --- PASS: TestMarshalCosign/standard_atomic_signature (0.00s) -=== CONT TestUnmarshalCosign/unknown_type === CONT TestUnmarshalCosign/arbitrary_claims +=== CONT TestUnmarshalCosign/unknown_type --- PASS: TestUnmarshalCosign (0.00s) --- PASS: TestUnmarshalCosign/no_claims (0.00s) --- PASS: TestUnmarshalCosign/unknown_type (0.00s) --- PASS: TestUnmarshalCosign/arbitrary_claims (0.00s) +--- PASS: TestMarshalCosign (0.00s) + --- PASS: TestMarshalCosign/no_claims (0.00s) + --- PASS: TestMarshalCosign/standard_atomic_signature (0.00s) + --- PASS: TestMarshalCosign/arbitrary_claims (0.00s) + --- PASS: TestMarshalCosign/custom_identity (0.00s) PASS -ok github.com/sigstore/sigstore/pkg/signature/payload 0.012s +ok github.com/sigstore/sigstore/pkg/signature/payload 0.018s === RUN TestFromOpenSSH sign_test.go:154: skip TestFromOpenSSH: missing ssh-keygen in PATH --- SKIP: TestFromOpenSSH (0.00s) @@ -3080,11 +3116,11 @@ === RUN TestRoundTrip === RUN TestRoundTrip/rsa === RUN TestRoundTrip/ed25519 ---- PASS: TestRoundTrip (0.19s) - --- PASS: TestRoundTrip/rsa (0.08s) +--- PASS: TestRoundTrip (0.23s) + --- PASS: TestRoundTrip/rsa (0.10s) --- PASS: TestRoundTrip/ed25519 (0.04s) PASS -ok github.com/sigstore/sigstore/pkg/signature/ssh 0.224s +ok github.com/sigstore/sigstore/pkg/signature/ssh 0.243s ? github.com/sigstore/sigstore/test [no test files] === RUN TestMarshalStatusType --- PASS: TestMarshalStatusType (0.00s) @@ -3107,8 +3143,8 @@ === RUN TestUnmarshalInvalidUsageType --- PASS: TestUnmarshalInvalidUsageType (0.00s) PASS -ok github.com/sigstore/sigstore/pkg/tuf 0.011s - rm -fr -- /tmp/dh-xdg-rundir-LvZ3PJ8c +ok github.com/sigstore/sigstore/pkg/tuf 0.016s + rm -fr -- /tmp/dh-xdg-rundir-rMscKodA rm -rf /build/reproducible-path/golang-github-sigstore-sigstore-1.8.10/debian/tmp-home make[1]: Leaving directory '/build/reproducible-path/golang-github-sigstore-sigstore-1.8.10' create-stamp debian/debhelper-build-stamp @@ -3137,12 +3173,14 @@ dpkg-buildpackage: info: binary-only upload (no source included) dpkg-genchanges: info: not including original source code in upload I: copying local configuration +I: user script /srv/workspace/pbuilder/25194/tmp/hooks/B01_cleanup starting +I: user script /srv/workspace/pbuilder/25194/tmp/hooks/B01_cleanup finished I: unmounting dev/ptmx filesystem I: unmounting dev/pts filesystem I: unmounting dev/shm filesystem I: unmounting proc filesystem I: unmounting sys filesystem I: cleaning the build env -I: removing directory /srv/workspace/pbuilder/6760 and its subdirectories -I: Current time: Sun Dec 15 20:19:05 -12 2024 -I: pbuilder-time-stamp: 1734337145 +I: removing directory /srv/workspace/pbuilder/25194 and its subdirectories +I: Current time: Mon Dec 16 22:26:56 +14 2024 +I: pbuilder-time-stamp: 1734337616