Diff of the two buildlogs:

--
--- b1/build.log	2025-03-23 13:02:24.474986009 +0000
+++ b2/build.log	2025-03-23 13:07:31.409206868 +0000
@@ -1,6 +1,6 @@
 I: pbuilder: network access will be disabled during build
-I: Current time: Sat Apr 25 07:21:15 -12 2026
-I: pbuilder-time-stamp: 1777144875
+I: Current time: Mon Mar 24 03:02:28 +14 2025
+I: pbuilder-time-stamp: 1742734948
 I: Building the build Environment
 I: extracting base tarball [/var/cache/pbuilder/unstable-reproducible-base.tgz]
 I: copying local configuration
@@ -24,52 +24,84 @@
 dpkg-source: info: applying fix-manpages.patch
 I: Not using root during the build.
 I: Installing the build-deps
-I: user script /srv/workspace/pbuilder/500832/tmp/hooks/D02_print_environment starting
+I: user script /srv/workspace/pbuilder/3708126/tmp/hooks/D01_modify_environment starting
+debug: Running on ionos11-amd64.
+I: Changing host+domainname to test build reproducibility
+I: Adding a custom variable just for the fun of it...
+I: Changing /bin/sh to bash
+'/bin/sh' -> '/bin/bash'
+lrwxrwxrwx 1 root root 9 Mar 23 13:02 /bin/sh -> /bin/bash
+I: Setting pbuilder2's login shell to /bin/bash
+I: Setting pbuilder2's GECOS to second user,second room,second work-phone,second home-phone,second other
+I: user script /srv/workspace/pbuilder/3708126/tmp/hooks/D01_modify_environment finished
+I: user script /srv/workspace/pbuilder/3708126/tmp/hooks/D02_print_environment starting
 I: set
-  BUILDDIR='/build/reproducible-path'
-  BUILDUSERGECOS='first user,first room,first work-phone,first home-phone,first other'
-  BUILDUSERNAME='pbuilder1'
-  BUILD_ARCH='amd64'
-  DEBIAN_FRONTEND='noninteractive'
-  DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=42 '
-  DISTRIBUTION='unstable'
-  HOME='/root'
-  HOST_ARCH='amd64'
+  BASH=/bin/sh
+  BASHOPTS=checkwinsize:cmdhist:complete_fullquote:extquote:force_fignore:globasciiranges:globskipdots:hostcomplete:interactive_comments:patsub_replacement:progcomp:promptvars:sourcepath
+  BASH_ALIASES=()
+  BASH_ARGC=()
+  BASH_ARGV=()
+  BASH_CMDS=()
+  BASH_LINENO=([0]="12" [1]="0")
+  BASH_LOADABLES_PATH=/usr/local/lib/bash:/usr/lib/bash:/opt/local/lib/bash:/usr/pkg/lib/bash:/opt/pkg/lib/bash:.
+  BASH_SOURCE=([0]="/tmp/hooks/D02_print_environment" [1]="/tmp/hooks/D02_print_environment")
+  BASH_VERSINFO=([0]="5" [1]="2" [2]="37" [3]="1" [4]="release" [5]="x86_64-pc-linux-gnu")
+  BASH_VERSION='5.2.37(1)-release'
+  BUILDDIR=/build/reproducible-path
+  BUILDUSERGECOS='second user,second room,second work-phone,second home-phone,second other'
+  BUILDUSERNAME=pbuilder2
+  BUILD_ARCH=amd64
+  DEBIAN_FRONTEND=noninteractive
+  DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=20 '
+  DIRSTACK=()
+  DISTRIBUTION=unstable
+  EUID=0
+  FUNCNAME=([0]="Echo" [1]="main")
+  GROUPS=()
+  HOME=/root
+  HOSTNAME=i-capture-the-hostname
+  HOSTTYPE=x86_64
+  HOST_ARCH=amd64
   IFS=' 	
   '
-  INVOCATION_ID='03ace4f12fa14662be5c865e360588af'
-  LANG='C'
-  LANGUAGE='en_US:en'
-  LC_ALL='C'
-  MAIL='/var/mail/root'
-  OPTIND='1'
-  PATH='/usr/sbin:/usr/bin:/sbin:/bin:/usr/games'
-  PBCURRENTCOMMANDLINEOPERATION='build'
-  PBUILDER_OPERATION='build'
-  PBUILDER_PKGDATADIR='/usr/share/pbuilder'
-  PBUILDER_PKGLIBDIR='/usr/lib/pbuilder'
-  PBUILDER_SYSCONFDIR='/etc'
-  PPID='500832'
-  PS1='# '
-  PS2='> '
+  INVOCATION_ID=51f56f69d8d345059329d2979be77f1b
+  LANG=C
+  LANGUAGE=et_EE:et
+  LC_ALL=C
+  MACHTYPE=x86_64-pc-linux-gnu
+  MAIL=/var/mail/root
+  OPTERR=1
+  OPTIND=1
+  OSTYPE=linux-gnu
+  PATH=/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path
+  PBCURRENTCOMMANDLINEOPERATION=build
+  PBUILDER_OPERATION=build
+  PBUILDER_PKGDATADIR=/usr/share/pbuilder
+  PBUILDER_PKGLIBDIR=/usr/lib/pbuilder
+  PBUILDER_SYSCONFDIR=/etc
+  PIPESTATUS=([0]="0")
+  POSIXLY_CORRECT=y
+  PPID=3708126
   PS4='+ '
-  PWD='/'
-  SHELL='/bin/bash'
-  SHLVL='2'
-  SUDO_COMMAND='/usr/bin/timeout -k 18.1h 18h /usr/bin/ionice -c 3 /usr/bin/nice /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.qafq0Y8S/pbuilderrc_4g46 --distribution unstable --hookdir /etc/pbuilder/first-build-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/unstable-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.qafq0Y8S/b1 --logfile b1/build.log sigsum-go_0.11.2-1.dsc'
-  SUDO_GID='110'
-  SUDO_UID='105'
-  SUDO_USER='jenkins'
-  TERM='unknown'
-  TZ='/usr/share/zoneinfo/Etc/GMT+12'
-  USER='root'
-  _='/usr/bin/systemd-run'
-  http_proxy='http://213.165.73.152:3128'
+  PWD=/
+  SHELL=/bin/bash
+  SHELLOPTS=braceexpand:errexit:hashall:interactive-comments:posix
+  SHLVL=3
+  SUDO_COMMAND='/usr/bin/timeout -k 24.1h 24h /usr/bin/ionice -c 3 /usr/bin/nice -n 11 /usr/bin/unshare --uts -- /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.qafq0Y8S/pbuilderrc_BUFq --distribution unstable --hookdir /etc/pbuilder/rebuild-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/unstable-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.qafq0Y8S/b2 --logfile b2/build.log sigsum-go_0.11.2-1.dsc'
+  SUDO_GID=111
+  SUDO_UID=106
+  SUDO_USER=jenkins
+  TERM=unknown
+  TZ=/usr/share/zoneinfo/Etc/GMT-14
+  UID=0
+  USER=root
+  _='I: set'
+  http_proxy=http://46.16.76.132:3128
 I: uname -a
-  Linux ionos5-amd64 6.12.12+bpo-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.12.12-1~bpo12+1 (2025-02-23) x86_64 GNU/Linux
+  Linux i-capture-the-hostname 6.1.0-32-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.129-1 (2025-03-06) x86_64 GNU/Linux
 I: ls -l /bin
-  lrwxrwxrwx 1 root root 7 Mar  4  2025 /bin -> usr/bin
-I: user script /srv/workspace/pbuilder/500832/tmp/hooks/D02_print_environment finished
+  lrwxrwxrwx 1 root root 7 Mar  4 11:20 /bin -> usr/bin
+I: user script /srv/workspace/pbuilder/3708126/tmp/hooks/D02_print_environment finished
  -> Attempting to satisfy build-dependencies
  -> Creating pbuilder-satisfydepends-dummy package
 Package: pbuilder-satisfydepends-dummy
@@ -173,7 +205,7 @@
 Get: 50 http://deb.debian.org/debian unstable/main amd64 libyaml-0-2 amd64 0.2.5-2 [52.5 kB]
 Get: 51 http://deb.debian.org/debian unstable/main amd64 pandoc-data all 3.1.11.1-3 [459 kB]
 Get: 52 http://deb.debian.org/debian unstable/main amd64 pandoc amd64 3.1.11.1+ds-2 [26.4 MB]
-Fetched 105 MB in 3s (30.4 MB/s)
+Fetched 105 MB in 5s (19.8 MB/s)
 Preconfiguring packages ...
 Selecting previously unselected package liblocale-gettext-perl.
 (Reading database ... 
(Reading database ... 5%
(Reading database ... 10%
(Reading database ... 15%
(Reading database ... 20%
(Reading database ... 25%
(Reading database ... 30%
(Reading database ... 35%
(Reading database ... 40%
(Reading database ... 45%
(Reading database ... 50%
(Reading database ... 55%
(Reading database ... 60%
(Reading database ... 65%
(Reading database ... 70%
(Reading database ... 75%
(Reading database ... 80%
(Reading database ... 85%
(Reading database ... 90%
(Reading database ... 95%
(Reading database ... 100%
(Reading database ... 19807 files and directories currently installed.)
@@ -396,7 +428,11 @@
 Building tag database...
  -> Finished parsing the build-deps
 I: Building the package
-I: Running cd /build/reproducible-path/sigsum-go-0.11.2/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-genchanges -S  > ../sigsum-go_0.11.2-1_source.changes
+I: user script /srv/workspace/pbuilder/3708126/tmp/hooks/A99_set_merged_usr starting
+Not re-configuring usrmerge for unstable
+I: user script /srv/workspace/pbuilder/3708126/tmp/hooks/A99_set_merged_usr finished
+hostname: Name or service not known
+I: Running cd /build/reproducible-path/sigsum-go-0.11.2/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-genchanges -S  > ../sigsum-go_0.11.2-1_source.changes
 dpkg-buildpackage: info: source package sigsum-go
 dpkg-buildpackage: info: source version 0.11.2-1
 dpkg-buildpackage: info: source distribution unstable
@@ -414,205 +450,205 @@
    dh_autoreconf -O--builddirectory=_build -O--buildsystem=golang
    dh_auto_configure -O--builddirectory=_build -O--buildsystem=golang
    dh_auto_build -O--builddirectory=_build -O--buildsystem=golang
-	cd _build && go install -trimpath -v -p 42 sigsum.org/sigsum-go/cmd/sigsum-key sigsum.org/sigsum-go/cmd/sigsum-monitor sigsum.org/sigsum-go/cmd/sigsum-submit sigsum.org/sigsum-go/cmd/sigsum-token sigsum.org/sigsum-go/cmd/sigsum-verify sigsum.org/sigsum-go/cmd/sigsum-witness sigsum.org/sigsum-go/internal/mocks/signer sigsum.org/sigsum-go/internal/ssh sigsum.org/sigsum-go/internal/version sigsum.org/sigsum-go/pkg/api sigsum.org/sigsum-go/pkg/ascii sigsum.org/sigsum-go/pkg/checkpoint sigsum.org/sigsum-go/pkg/client sigsum.org/sigsum-go/pkg/crypto sigsum.org/sigsum-go/pkg/key sigsum.org/sigsum-go/pkg/log sigsum.org/sigsum-go/pkg/merkle sigsum.org/sigsum-go/pkg/mocks sigsum.org/sigsum-go/pkg/monitor sigsum.org/sigsum-go/pkg/policy sigsum.org/sigsum-go/pkg/proof sigsum.org/sigsum-go/pkg/requests sigsum.org/sigsum-go/pkg/server sigsum.org/sigsum-go/pkg/submit sigsum.org/sigsum-go/pkg/submit-token sigsum.org/sigsum-go/pkg/types sigsum.org/sigsum-go/tests/mk-add-checkpoint-request sigsum.org/sigsum-go/tests/sha256-n sigsum.org/sigsum-go/tests/use-agent
-internal/goos
-internal/asan
-internal/unsafeheader
+	cd _build && go install -trimpath -v -p 20 sigsum.org/sigsum-go/cmd/sigsum-key sigsum.org/sigsum-go/cmd/sigsum-monitor sigsum.org/sigsum-go/cmd/sigsum-submit sigsum.org/sigsum-go/cmd/sigsum-token sigsum.org/sigsum-go/cmd/sigsum-verify sigsum.org/sigsum-go/cmd/sigsum-witness sigsum.org/sigsum-go/internal/mocks/signer sigsum.org/sigsum-go/internal/ssh sigsum.org/sigsum-go/internal/version sigsum.org/sigsum-go/pkg/api sigsum.org/sigsum-go/pkg/ascii sigsum.org/sigsum-go/pkg/checkpoint sigsum.org/sigsum-go/pkg/client sigsum.org/sigsum-go/pkg/crypto sigsum.org/sigsum-go/pkg/key sigsum.org/sigsum-go/pkg/log sigsum.org/sigsum-go/pkg/merkle sigsum.org/sigsum-go/pkg/mocks sigsum.org/sigsum-go/pkg/monitor sigsum.org/sigsum-go/pkg/policy sigsum.org/sigsum-go/pkg/proof sigsum.org/sigsum-go/pkg/requests sigsum.org/sigsum-go/pkg/server sigsum.org/sigsum-go/pkg/submit sigsum.org/sigsum-go/pkg/submit-token sigsum.org/sigsum-go/pkg/types sigsum.org/sigsum-go/tests/mk-add-checkpoint-request sigsum.org/sigsum-go/tests/sha256-n sigsum.org/sigsum-go/tests/use-agent
+math/bits
+unicode/utf8
 cmp
-internal/godebugs
+internal/unsafeheader
 internal/msan
-internal/byteorder
-unicode/utf8
-crypto/internal/fips140deps/byteorder
 internal/goarch
-internal/cpu
-internal/coverage/rtcov
-unicode/utf16
 log/internal
-internal/itoa
-internal/goexperiment
 crypto/internal/fips140/alias
-vendor/golang.org/x/crypto/cryptobyte/asn1
-vendor/golang.org/x/crypto/internal/alias
 sync/atomic
+internal/runtime/syscall
+internal/godebugs
+internal/itoa
+internal/asan
+internal/cpu
 internal/profilerecord
-internal/nettrace
+internal/runtime/atomic
+internal/goos
+internal/coverage/rtcov
 crypto/internal/boring/sig
-internal/runtime/syscall
+internal/goexperiment
+internal/nettrace
+internal/byteorder
 container/list
-math/bits
+crypto/internal/fips140/subtle
 unicode
-internal/runtime/atomic
-internal/chacha8rand
-internal/abi
+unicode/utf16
+vendor/golang.org/x/crypto/cryptobyte/asn1
+vendor/golang.org/x/crypto/internal/alias
 internal/runtime/math
 internal/runtime/sys
-crypto/internal/fips140/subtle
+internal/chacha8rand
+crypto/internal/fips140deps/byteorder
+internal/abi
+internal/runtime/exithook
 internal/bytealg
 crypto/internal/fips140deps/cpu
 math
-internal/runtime/exithook
 internal/stringslite
 internal/race
-internal/sync
 internal/runtime/maps
+internal/sync
 runtime
+internal/reflectlite
+sync
 iter
 crypto/subtle
-internal/reflectlite
 weak
-sync
-maps
 slices
-errors
-sort
+maps
 internal/bisect
-unique
-internal/testlog
 internal/singleflight
-io
-vendor/golang.org/x/net/dns/dnsmessage
-internal/oserror
+internal/testlog
+unique
+runtime/cgo
+errors
+sort
 path
-strconv
+internal/godebug
 math/rand/v2
-runtime/cgo
+strconv
+internal/oserror
+vendor/golang.org/x/net/dns/dnsmessage
+io
 syscall
-internal/godebug
 bytes
 strings
 hash
 crypto/internal/randutil
-hash/crc32
-math/rand
 crypto/internal/fips140deps/godebug
+math/rand
+hash/crc32
 crypto
 net/netip
 encoding/base32
 reflect
-crypto/internal/impl
-net/http/internal/ascii
-crypto/internal/fips140
 vendor/golang.org/x/text/transform
 golang.org/x/text/transform
+crypto/internal/impl
 bufio
-crypto/internal/fips140/sha256
+net/http/internal/ascii
+crypto/internal/fips140
 crypto/internal/fips140/sha3
 crypto/tls/internal/fips140tls
+crypto/internal/fips140/sha256
 crypto/internal/fips140/sha512
 crypto/sha3
 crypto/internal/fips140/hmac
-crypto/internal/fips140hash
+time
+internal/syscall/execenv
 crypto/internal/fips140/check
-crypto/internal/fips140/bigmod
-crypto/internal/fips140/hkdf
+internal/syscall/unix
+crypto/internal/fips140hash
 crypto/internal/fips140/edwards25519/field
-crypto/internal/fips140/aes
+crypto/internal/fips140/hkdf
+crypto/internal/fips140/bigmod
 crypto/internal/fips140/tls12
+crypto/internal/fips140/aes
 crypto/internal/fips140/nistec/fiat
-internal/syscall/execenv
-internal/syscall/unix
-time
 crypto/internal/fips140/tls13
 crypto/internal/fips140/edwards25519
-crypto/internal/fips140/nistec
-context
 io/fs
+context
 internal/poll
 internal/filepathlite
+crypto/internal/fips140/nistec
 os
 internal/fmtsort
 encoding/binary
 encoding/base64
 vendor/golang.org/x/crypto/internal/poly1305
 encoding/pem
+fmt
 crypto/internal/sysrand
 os/signal
-fmt
 vendor/golang.org/x/sys/cpu
 path/filepath
 net
 crypto/internal/entropy
 crypto/internal/fips140/drbg
+crypto/internal/fips140/aes/gcm
 crypto/internal/fips140only
 crypto/internal/fips140/ecdh
 crypto/internal/fips140/ed25519
-crypto/internal/fips140/mlkem
-crypto/internal/fips140/aes/gcm
 crypto/internal/fips140/ecdsa
 crypto/internal/fips140/rsa
-crypto/rc4
+crypto/internal/fips140/mlkem
 crypto/md5
+crypto/rc4
 crypto/cipher
+github.com/pborman/getopt/v2
 log
-runtime/debug
-math/big
 encoding/hex
-net/http/internal
-mime/quotedprintable
-vendor/golang.org/x/net/http2/hpack
-golang.org/x/text/unicode/norm
 compress/flate
 net/url
-github.com/golang/mock/gomock
-github.com/pborman/getopt/v2
+vendor/golang.org/x/net/http2/hpack
 mime
+golang.org/x/text/unicode/norm
+mime/quotedprintable
+net/http/internal
 vendor/golang.org/x/text/unicode/norm
+github.com/golang/mock/gomock
+runtime/debug
+math/big
 crypto/internal/boring
 crypto/des
 vendor/golang.org/x/crypto/chacha20
+sigsum.org/sigsum-go/pkg/log
+vendor/golang.org/x/text/unicode/bidi
+golang.org/x/text/unicode/bidi
 crypto/sha256
+crypto/ecdh
 crypto/aes
 crypto/sha512
-crypto/ecdh
 crypto/hmac
 crypto/sha1
-vendor/golang.org/x/crypto/chacha20poly1305
-sigsum.org/sigsum-go/pkg/log
-vendor/golang.org/x/text/unicode/bidi
-golang.org/x/text/unicode/bidi
-sigsum.org/sigsum-go/internal/version
 compress/gzip
-vendor/golang.org/x/text/secure/bidirule
+sigsum.org/sigsum-go/internal/version
+vendor/golang.org/x/crypto/chacha20poly1305
 golang.org/x/text/secure/bidirule
-vendor/golang.org/x/net/idna
-golang.org/x/net/idna
+vendor/golang.org/x/text/secure/bidirule
 crypto/rand
-crypto/elliptic
 crypto/internal/boring/bbig
+crypto/elliptic
 encoding/asn1
 crypto/dsa
+golang.org/x/net/idna
 crypto/ed25519
 crypto/internal/hpke
-crypto/rsa
 github.com/dchest/safefile
+crypto/rsa
+vendor/golang.org/x/net/idna
 sigsum.org/sigsum-go/pkg/crypto
+sigsum.org/sigsum-go/pkg/ascii
 sigsum.org/sigsum-go/pkg/merkle
-sigsum.org/sigsum-go/tests/sha256-n
 sigsum.org/sigsum-go/internal/mocks/signer
-sigsum.org/sigsum-go/pkg/ascii
-crypto/x509/pkix
+sigsum.org/sigsum-go/tests/sha256-n
 vendor/golang.org/x/crypto/cryptobyte
+crypto/x509/pkix
 crypto/ecdsa
-vendor/golang.org/x/net/http/httpproxy
-net/textproto
-sigsum.org/sigsum-go/pkg/submit-token
 sigsum.org/sigsum-go/internal/ssh
 crypto/x509
-sigsum.org/sigsum-go/pkg/key
+net/textproto
+vendor/golang.org/x/net/http/httpproxy
+sigsum.org/sigsum-go/pkg/submit-token
 sigsum.org/sigsum-go/pkg/types
+sigsum.org/sigsum-go/pkg/key
 vendor/golang.org/x/net/http/httpguts
 mime/multipart
-sigsum.org/sigsum-go/tests/use-agent
 sigsum.org/sigsum-go/cmd/sigsum-token
+sigsum.org/sigsum-go/tests/use-agent
 sigsum.org/sigsum-go/pkg/checkpoint
 sigsum.org/sigsum-go/pkg/policy
-sigsum.org/sigsum-go/pkg/proof
-sigsum.org/sigsum-go/tests/mk-add-checkpoint-request
-sigsum.org/sigsum-go/cmd/sigsum-key
 sigsum.org/sigsum-go/pkg/requests
-sigsum.org/sigsum-go/cmd/sigsum-verify
+sigsum.org/sigsum-go/cmd/sigsum-key
+sigsum.org/sigsum-go/tests/mk-add-checkpoint-request
+sigsum.org/sigsum-go/pkg/proof
 sigsum.org/sigsum-go/pkg/mocks
+sigsum.org/sigsum-go/cmd/sigsum-verify
 crypto/tls
 net/http/httptrace
 net/http
@@ -627,7 +663,7 @@
    debian/rules override_dh_auto_test
 make[1]: Entering directory '/build/reproducible-path/sigsum-go-0.11.2'
 env DH_GOLANG_EXCLUDES=sigsum.org/sigsum-go/pkg/server dh_auto_test 
-	cd _build && go test -vet=off -v -p 42 sigsum.org/sigsum-go/cmd/sigsum-key sigsum.org/sigsum-go/cmd/sigsum-monitor sigsum.org/sigsum-go/cmd/sigsum-submit sigsum.org/sigsum-go/cmd/sigsum-token sigsum.org/sigsum-go/cmd/sigsum-verify sigsum.org/sigsum-go/cmd/sigsum-witness sigsum.org/sigsum-go/internal/mocks/signer sigsum.org/sigsum-go/internal/ssh sigsum.org/sigsum-go/internal/version sigsum.org/sigsum-go/pkg/api sigsum.org/sigsum-go/pkg/ascii sigsum.org/sigsum-go/pkg/checkpoint sigsum.org/sigsum-go/pkg/client sigsum.org/sigsum-go/pkg/crypto sigsum.org/sigsum-go/pkg/key sigsum.org/sigsum-go/pkg/log sigsum.org/sigsum-go/pkg/merkle sigsum.org/sigsum-go/pkg/mocks sigsum.org/sigsum-go/pkg/monitor sigsum.org/sigsum-go/pkg/policy sigsum.org/sigsum-go/pkg/proof sigsum.org/sigsum-go/pkg/requests sigsum.org/sigsum-go/pkg/submit sigsum.org/sigsum-go/pkg/submit-token sigsum.org/sigsum-go/pkg/types sigsum.org/sigsum-go/tests/mk-add-checkpoint-request sigsum.org/sigsum-go/tests/sha256-n sigsum.org/sigsum-go/tests/use-agent
+	cd _build && go test -vet=off -v -p 20 sigsum.org/sigsum-go/cmd/sigsum-key sigsum.org/sigsum-go/cmd/sigsum-monitor sigsum.org/sigsum-go/cmd/sigsum-submit sigsum.org/sigsum-go/cmd/sigsum-token sigsum.org/sigsum-go/cmd/sigsum-verify sigsum.org/sigsum-go/cmd/sigsum-witness sigsum.org/sigsum-go/internal/mocks/signer sigsum.org/sigsum-go/internal/ssh sigsum.org/sigsum-go/internal/version sigsum.org/sigsum-go/pkg/api sigsum.org/sigsum-go/pkg/ascii sigsum.org/sigsum-go/pkg/checkpoint sigsum.org/sigsum-go/pkg/client sigsum.org/sigsum-go/pkg/crypto sigsum.org/sigsum-go/pkg/key sigsum.org/sigsum-go/pkg/log sigsum.org/sigsum-go/pkg/merkle sigsum.org/sigsum-go/pkg/mocks sigsum.org/sigsum-go/pkg/monitor sigsum.org/sigsum-go/pkg/policy sigsum.org/sigsum-go/pkg/proof sigsum.org/sigsum-go/pkg/requests sigsum.org/sigsum-go/pkg/submit sigsum.org/sigsum-go/pkg/submit-token sigsum.org/sigsum-go/pkg/types sigsum.org/sigsum-go/tests/mk-add-checkpoint-request sigsum.org/sigsum-go/tests/sha256-n sigsum.org/sigsum-go/tests/use-agent
 ?   	sigsum.org/sigsum-go/cmd/sigsum-key	[no test files]
 ?   	sigsum.org/sigsum-go/cmd/sigsum-monitor	[no test files]
 ?   	sigsum.org/sigsum-go/cmd/sigsum-submit	[no test files]
@@ -638,7 +674,7 @@
 === RUN   TestRequest
 --- PASS: TestRequest (0.00s)
 === RUN   TestSignEd25519
---- PASS: TestSignEd25519 (0.01s)
+--- PASS: TestSignEd25519 (0.00s)
 === RUN   TestSignEd25519Fail
 --- PASS: TestSignEd25519Fail (0.00s)
 === RUN   TestParsePrivateKeyFile
@@ -652,7 +688,7 @@
 === RUN   TestSignedData
 --- PASS: TestSignedData (0.00s)
 PASS
-ok  	sigsum.org/sigsum-go/internal/ssh	0.033s
+ok  	sigsum.org/sigsum-go/internal/ssh	0.060s
 ?   	sigsum.org/sigsum-go/internal/version	[no test files]
 ?   	sigsum.org/sigsum-go/pkg/api	[no test files]
 === RUN   TestLineReaderGetLine
@@ -676,15 +712,15 @@
 === RUN   TestParserEOFGarbage
 --- PASS: TestParserEOFGarbage (0.00s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/ascii	0.013s
+ok  	sigsum.org/sigsum-go/pkg/ascii	0.044s
 === RUN   TestCheckpointToASCII
 --- PASS: TestCheckpointToASCII (0.00s)
 === RUN   TestCheckpointFromASCII
 --- PASS: TestCheckpointFromASCII (0.00s)
 === RUN   TestCheckpointSigned
---- PASS: TestCheckpointSigned (0.00s)
+--- PASS: TestCheckpointSigned (0.01s)
 === RUN   TestCheckpointVerify
---- PASS: TestCheckpointVerify (0.00s)
+--- PASS: TestCheckpointVerify (0.01s)
 === RUN   TestCheckpointVerifyIgnoreExtraSignature
 --- PASS: TestCheckpointVerifyIgnoreExtraSignature (0.00s)
 === RUN   TestCheckpointCosignVerify
@@ -692,7 +728,7 @@
         
 --- PASS: TestCheckpointCosignVerify (0.00s)
 === RUN   TestCheckpointVerifyCosignatureByKey
---- PASS: TestCheckpointVerifyCosignatureByKey (0.00s)
+--- PASS: TestCheckpointVerifyCosignatureByKey (0.01s)
 === RUN   TestGoSumDBCheckpoint
 --- PASS: TestGoSumDBCheckpoint (0.00s)
 === RUN   TestCosignatureLineToASCII
@@ -714,11 +750,11 @@
 === RUN   TestGoSumDBVerifier
 --- PASS: TestGoSumDBVerifier (0.00s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/checkpoint	0.042s
+ok  	sigsum.org/sigsum-go/pkg/checkpoint	0.076s
 === RUN   TestProcessConflictResponse
 --- PASS: TestProcessConflictResponse (0.00s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/client	0.030s
+ok  	sigsum.org/sigsum-go/pkg/client	0.066s
 === RUN   TestValidHashFromHex
 --- PASS: TestValidHashFromHex (0.00s)
 === RUN   TestInvalidHashFromHex
@@ -736,17 +772,17 @@
 === RUN   TestSign
 --- PASS: TestSign (0.01s)
 === RUN   TestVerify
---- PASS: TestVerify (0.00s)
+--- PASS: TestVerify (0.01s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/crypto	0.023s
+ok  	sigsum.org/sigsum-go/pkg/crypto	0.056s
 === RUN   TestParsePublicKeysFile
 --- PASS: TestParsePublicKeysFile (0.00s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/key	0.020s
+ok  	sigsum.org/sigsum-go/pkg/key	0.069s
 === RUN   Example
 --- PASS: Example (0.00s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/log	0.011s
+ok  	sigsum.org/sigsum-go/pkg/log	0.024s
 === RUN   TestSize
 --- PASS: TestSize (0.00s)
 === RUN   TestGetLeafIndex
@@ -758,27 +794,27 @@
 === RUN   TestInclusion
 --- PASS: TestInclusion (0.00s)
 === RUN   TestInclusionValid
---- PASS: TestInclusionValid (0.72s)
+--- PASS: TestInclusionValid (1.26s)
 === RUN   TestInclusionBatchValid
---- PASS: TestInclusionBatchValid (3.17s)
+--- PASS: TestInclusionBatchValid (2.95s)
 === RUN   TestInclusionTailValid
---- PASS: TestInclusionTailValid (1.39s)
+--- PASS: TestInclusionTailValid (2.69s)
 === RUN   TestConsistency
 --- PASS: TestConsistency (0.00s)
 === RUN   TestConsistencyValid
---- PASS: TestConsistencyValid (0.66s)
+--- PASS: TestConsistencyValid (1.47s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/merkle	5.954s
+ok  	sigsum.org/sigsum-go/pkg/merkle	8.396s
 ?   	sigsum.org/sigsum-go/pkg/mocks	[no test files]
 === RUN   TestGetTreeHead
---- PASS: TestGetTreeHead (0.56s)
+--- PASS: TestGetTreeHead (0.92s)
 === RUN   TestGetTreeHeadErrors
     client_test.go:171: bad signature: (expected) failure: monitoring alert: Invalid log signature: log signature invalid
     client_test.go:171: bad signature (hash): (expected) failure: monitoring alert: Invalid log signature: log signature invalid
     client_test.go:171: bad consistency: (expected) failure: monitoring alert: Log tree head not consistent: consistency proof not valid: invalid proof: old root mismatch
 --- PASS: TestGetTreeHeadErrors (0.02s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/monitor	0.601s
+ok  	sigsum.org/sigsum-go/pkg/monitor	0.997s
 === RUN   TestValidConfig
 --- PASS: TestValidConfig (0.00s)
 === RUN   TestNumericThreshold
@@ -790,7 +826,7 @@
 === RUN   TestWitnessPolicy
 --- PASS: TestWitnessPolicy (0.01s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/policy	0.046s
+ok  	sigsum.org/sigsum-go/pkg/policy	0.072s
 === RUN   TestASCII
 --- PASS: TestASCII (0.00s)
 === RUN   TestASCIIV1
@@ -800,7 +836,7 @@
 === RUN   TestVerify
 --- PASS: TestVerify (0.00s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/proof	0.020s
+ok  	sigsum.org/sigsum-go/pkg/proof	0.052s
 === RUN   TestLeafToASCII
 --- PASS: TestLeafToASCII (0.00s)
 === RUN   TestLeavesToURL
@@ -822,64 +858,64 @@
 === RUN   TestAddCheckpointFromASCII
 --- PASS: TestAddCheckpointFromASCII (0.00s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/requests	0.021s
+ok  	sigsum.org/sigsum-go/pkg/requests	0.052s
 === RUN   TestSubmitSuccess
 === RUN   TestSubmitSuccess/leaf_1
-2026/04/25 19:23:58 [INFO] Attempting to submit checksum#1 to log: http://example.org
-2026/04/25 19:23:58 [INFO] Attempting to retrieve proof for checksum#1
+2025/03/23 13:06:20 [INFO] Attempting to submit checksum#1 to log: http://example.org
+2025/03/23 13:06:20 [INFO] Attempting to retrieve proof for checksum#1
 === RUN   TestSubmitSuccess/leaf_2
-2026/04/25 19:23:58 [INFO] Attempting to submit checksum#1 to log: http://example.org
-2026/04/25 19:23:58 [INFO] Attempting to retrieve proof for checksum#1
+2025/03/23 13:06:20 [INFO] Attempting to submit checksum#1 to log: http://example.org
+2025/03/23 13:06:20 [INFO] Attempting to retrieve proof for checksum#1
 === RUN   TestSubmitSuccess/leaf_3
-2026/04/25 19:23:58 [INFO] Attempting to submit checksum#1 to log: http://example.org
-2026/04/25 19:23:58 [INFO] Attempting to retrieve proof for checksum#1
+2025/03/23 13:06:20 [INFO] Attempting to submit checksum#1 to log: http://example.org
+2025/03/23 13:06:20 [INFO] Attempting to retrieve proof for checksum#1
 === RUN   TestSubmitSuccess/leaf_4
-2026/04/25 19:23:58 [INFO] Attempting to submit checksum#1 to log: http://example.org
-2026/04/25 19:23:58 [INFO] Attempting to retrieve proof for checksum#1
+2025/03/23 13:06:20 [INFO] Attempting to submit checksum#1 to log: http://example.org
+2025/03/23 13:06:20 [INFO] Attempting to retrieve proof for checksum#1
 === RUN   TestSubmitSuccess/leaf_5
-2026/04/25 19:23:58 [INFO] Attempting to submit checksum#1 to log: http://example.org
-2026/04/25 19:23:58 [INFO] Attempting to retrieve proof for checksum#1
+2025/03/23 13:06:20 [INFO] Attempting to submit checksum#1 to log: http://example.org
+2025/03/23 13:06:20 [INFO] Attempting to retrieve proof for checksum#1
 === RUN   TestSubmitSuccess/leaf_6
-2026/04/25 19:23:58 [INFO] Attempting to submit checksum#1 to log: http://example.org
-2026/04/25 19:23:58 [INFO] Attempting to retrieve proof for checksum#1
+2025/03/23 13:06:20 [INFO] Attempting to submit checksum#1 to log: http://example.org
+2025/03/23 13:06:20 [INFO] Attempting to retrieve proof for checksum#1
 === RUN   TestSubmitSuccess/leaf_7
-2026/04/25 19:23:58 [INFO] Attempting to submit checksum#1 to log: http://example.org
-2026/04/25 19:23:58 [INFO] Attempting to retrieve proof for checksum#1
+2025/03/23 13:06:20 [INFO] Attempting to submit checksum#1 to log: http://example.org
+2025/03/23 13:06:20 [INFO] Attempting to retrieve proof for checksum#1
 === RUN   TestSubmitSuccess/leaf_8
-2026/04/25 19:23:58 [INFO] Attempting to submit checksum#1 to log: http://example.org
-2026/04/25 19:23:58 [INFO] Attempting to retrieve proof for checksum#1
+2025/03/23 13:06:20 [INFO] Attempting to submit checksum#1 to log: http://example.org
+2025/03/23 13:06:20 [INFO] Attempting to retrieve proof for checksum#1
 === RUN   TestSubmitSuccess/leaf_9
-2026/04/25 19:23:58 [INFO] Attempting to submit checksum#1 to log: http://example.org
-2026/04/25 19:23:58 [INFO] Attempting to retrieve proof for checksum#1
---- PASS: TestSubmitSuccess (0.02s)
-    --- PASS: TestSubmitSuccess/leaf_1 (0.01s)
+2025/03/23 13:06:20 [INFO] Attempting to submit checksum#1 to log: http://example.org
+2025/03/23 13:06:20 [INFO] Attempting to retrieve proof for checksum#1
+--- PASS: TestSubmitSuccess (0.05s)
+    --- PASS: TestSubmitSuccess/leaf_1 (0.00s)
     --- PASS: TestSubmitSuccess/leaf_2 (0.00s)
     --- PASS: TestSubmitSuccess/leaf_3 (0.00s)
-    --- PASS: TestSubmitSuccess/leaf_4 (0.00s)
+    --- PASS: TestSubmitSuccess/leaf_4 (0.01s)
     --- PASS: TestSubmitSuccess/leaf_5 (0.00s)
     --- PASS: TestSubmitSuccess/leaf_6 (0.00s)
     --- PASS: TestSubmitSuccess/leaf_7 (0.01s)
     --- PASS: TestSubmitSuccess/leaf_8 (0.00s)
-    --- PASS: TestSubmitSuccess/leaf_9 (0.00s)
+    --- PASS: TestSubmitSuccess/leaf_9 (0.01s)
 === RUN   TestSubmitWithFailure
-2026/04/25 19:23:58 [INFO] Attempting to submit checksum#1 to log: http://always-fail.example.org
-2026/04/25 19:23:58 [ERRO] Submitting to log "http://always-fail.example.org" failed: mock error
-2026/04/25 19:23:58 [INFO] Attempting to submit checksum#1 to log: http://example.org
-2026/04/25 19:23:58 [ERRO] Submitting to log "http://example.org" failed: mock error
-2026/04/25 19:23:58 [INFO] Attempting to submit checksum#1 to log: http://always-fail.example.org
-2026/04/25 19:23:58 [ERRO] Submitting to log "http://always-fail.example.org" failed: mock error
-2026/04/25 19:23:58 [INFO] Attempting to submit checksum#1 to log: http://example.org
-2026/04/25 19:23:58 [INFO] Attempting to retrieve proof for checksum#1
-2026/04/25 19:23:58 [INFO] Attempting to retrieve proof for checksum#1
-2026/04/25 19:24:01 [INFO] Attempting to retrieve proof for checksum#1
-2026/04/25 19:24:01 [INFO] Attempting to retrieve proof for checksum#1
-2026/04/25 19:24:01 [INFO] Verifying latest tree head: invalid log signature
-2026/04/25 19:24:01 [INFO] Attempting to retrieve proof for checksum#1
-2026/04/25 19:24:01 [INFO] Attempting to retrieve proof for checksum#1
-2026/04/25 19:24:01 [INFO] Attempting to retrieve proof for checksum#1
---- PASS: TestSubmitWithFailure (3.05s)
+2025/03/23 13:06:20 [INFO] Attempting to submit checksum#1 to log: http://always-fail.example.org
+2025/03/23 13:06:20 [ERRO] Submitting to log "http://always-fail.example.org" failed: mock error
+2025/03/23 13:06:20 [INFO] Attempting to submit checksum#1 to log: http://example.org
+2025/03/23 13:06:20 [ERRO] Submitting to log "http://example.org" failed: mock error
+2025/03/23 13:06:20 [INFO] Attempting to submit checksum#1 to log: http://always-fail.example.org
+2025/03/23 13:06:20 [ERRO] Submitting to log "http://always-fail.example.org" failed: mock error
+2025/03/23 13:06:20 [INFO] Attempting to submit checksum#1 to log: http://example.org
+2025/03/23 13:06:20 [INFO] Attempting to retrieve proof for checksum#1
+2025/03/23 13:06:20 [INFO] Attempting to retrieve proof for checksum#1
+2025/03/23 13:06:20 [INFO] Attempting to retrieve proof for checksum#1
+2025/03/23 13:06:20 [INFO] Attempting to retrieve proof for checksum#1
+2025/03/23 13:06:20 [INFO] Verifying latest tree head: invalid log signature
+2025/03/23 13:06:20 [INFO] Attempting to retrieve proof for checksum#1
+2025/03/23 13:06:20 [INFO] Attempting to retrieve proof for checksum#1
+2025/03/23 13:06:20 [INFO] Attempting to retrieve proof for checksum#1
+--- PASS: TestSubmitWithFailure (0.03s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/submit	3.186s
+ok  	sigsum.org/sigsum-go/pkg/submit	0.140s
 === RUN   TestNormalize
 --- PASS: TestNormalize (0.00s)
 === RUN   TestNormalizeReject
@@ -894,15 +930,15 @@
 === RUN   TestSubmitHeaderToHeader
 --- PASS: TestSubmitHeaderToHeader (0.00s)
 === RUN   TestVerify
---- PASS: TestVerify (0.01s)
+--- PASS: TestVerify (0.02s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/submit-token	0.029s
+ok  	sigsum.org/sigsum-go/pkg/submit-token	0.075s
 === RUN   TestLeafSignedData
 --- PASS: TestLeafSignedData (0.00s)
 === RUN   TestSignLeaf
 --- PASS: TestSignLeaf (0.00s)
 === RUN   TestLeafVerify
---- PASS: TestLeafVerify (0.00s)
+--- PASS: TestLeafVerify (0.01s)
 === RUN   TestLeafToBinary
 --- PASS: TestLeafToBinary (0.00s)
 === RUN   TestLeafFromBinary
@@ -952,12 +988,12 @@
 === RUN   TestCosignedTreeHeadFromASCII
 --- PASS: TestCosignedTreeHeadFromASCII (0.00s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/types	0.022s
+ok  	sigsum.org/sigsum-go/pkg/types	0.092s
 ?   	sigsum.org/sigsum-go/tests/mk-add-checkpoint-request	[no test files]
 ?   	sigsum.org/sigsum-go/tests/sha256-n	[no test files]
 ?   	sigsum.org/sigsum-go/tests/use-agent	[no test files]
 env DH_GOLANG_BUILDPKG=sigsum.org/sigsum-go/pkg/server dh_auto_test 
-	cd _build && go test -vet=off -v -p 42 sigsum.org/sigsum-go/pkg/server
+	cd _build && go test -vet=off -v -p 20 sigsum.org/sigsum-go/pkg/server
 === RUN   TestGetTreeHead
     log_test.go:48: Unexpected status code, got 404, want 200
     controller.go:269: missing call(s) to *mocks.MockLog.GetTreeHead(is anything) /build/reproducible-path/sigsum-go-0.11.2/_build/src/sigsum.org/sigsum-go/pkg/server/log_test.go:44
@@ -992,7 +1028,7 @@
     log_test.go:242: Unexpected response for "/foo/get-leaves/2/5", got "404 page not found\n", want "leaf=0000000000000000000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 0000000000000000000000000000000000000000000000000000000000000000\nleaf=0000000000000000000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 0000000000000000000000000000000000000000000000000000000000000000\nleaf=0000000000000000000000000000000000000000000000000000000000000000 00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 0000000000000000000000000000000000000000000000000000000000000000\n"
     controller.go:269: missing call(s) to *mocks.MockLog.GetLeaves(is anything, is equal to {2 5} (requests.Leaves)) /build/reproducible-path/sigsum-go-0.11.2/_build/src/sigsum.org/sigsum-go/pkg/server/log_test.go:229
     controller.go:269: aborting test due to missing call(s)
---- FAIL: TestGetLeaves (0.00s)
+--- FAIL: TestGetLeaves (0.02s)
 === RUN   TestAddLeaf
     log_test.go:351: accepted: Unexpected status code for, got 404, want 202
     log_test.go:354: accepted: response body: "404 page not found\n"
@@ -1036,9 +1072,9 @@
     controller.go:269: aborting test due to missing call(s)
 --- FAIL: TestAddCheckpoint (0.00s)
 FAIL
-FAIL	sigsum.org/sigsum-go/pkg/server	0.013s
+FAIL	sigsum.org/sigsum-go/pkg/server	0.076s
 FAIL
-dh_auto_test: error: cd _build && go test -vet=off -v -p 42 sigsum.org/sigsum-go/pkg/server returned exit code 1
+dh_auto_test: error: cd _build && go test -vet=off -v -p 20 sigsum.org/sigsum-go/pkg/server returned exit code 1
 make[1]: [debian/rules:10: override_dh_auto_test] Error 25 (ignored)
 make[1]: Leaving directory '/build/reproducible-path/sigsum-go-0.11.2'
    create-stamp debian/debhelper-build-stamp
@@ -1139,12 +1175,14 @@
 dpkg-buildpackage: info: binary-only upload (no source included)
 dpkg-genchanges: info: including full source code in upload
 I: copying local configuration
+I: user script /srv/workspace/pbuilder/3708126/tmp/hooks/B01_cleanup starting
+I: user script /srv/workspace/pbuilder/3708126/tmp/hooks/B01_cleanup finished
 I: unmounting dev/ptmx filesystem
 I: unmounting dev/pts filesystem
 I: unmounting dev/shm filesystem
 I: unmounting proc filesystem
 I: unmounting sys filesystem
 I: cleaning the build env 
-I: removing directory /srv/workspace/pbuilder/500832 and its subdirectories
-I: Current time: Sat Apr 25 07:25:23 -12 2026
-I: pbuilder-time-stamp: 1777145123
+I: removing directory /srv/workspace/pbuilder/3708126 and its subdirectories
+I: Current time: Mon Mar 24 03:07:30 +14 2025
+I: pbuilder-time-stamp: 1742735250