Diff of the two buildlogs:

--
--- b1/build.log	2025-01-27 23:14:03.778684054 +0000
+++ b2/build.log	2025-01-27 23:12:09.367829583 +0000
@@ -1,6 +1,6 @@
 I: pbuilder: network access will be disabled during build
-I: Current time: Mon Jan 27 11:12:19 -12 2025
-I: pbuilder-time-stamp: 1738019539
+I: Current time: Mon Mar  2 19:31:24 +14 2026
+I: pbuilder-time-stamp: 1772429484
 I: Building the build Environment
 I: extracting base tarball [/var/cache/pbuilder/unstable-reproducible-base.tgz]
 I: copying local configuration
@@ -23,54 +23,86 @@
 dpkg-source: info: unpacking sigsum-go_0.10.1-1.debian.tar.xz
 I: Not using root during the build.
 I: Installing the build-deps
-I: user script /srv/workspace/pbuilder/52563/tmp/hooks/D02_print_environment starting
+I: user script /srv/workspace/pbuilder/127311/tmp/hooks/D01_modify_environment starting
+debug: Running on ionos6-i386.
+I: Changing host+domainname to test build reproducibility
+I: Adding a custom variable just for the fun of it...
+I: Changing /bin/sh to bash
+'/bin/sh' -> '/bin/bash'
+lrwxrwxrwx 1 root root 9 Mar  2 05:31 /bin/sh -> /bin/bash
+I: Setting pbuilder2's login shell to /bin/bash
+I: Setting pbuilder2's GECOS to second user,second room,second work-phone,second home-phone,second other
+I: user script /srv/workspace/pbuilder/127311/tmp/hooks/D01_modify_environment finished
+I: user script /srv/workspace/pbuilder/127311/tmp/hooks/D02_print_environment starting
 I: set
-  BUILDDIR='/build/reproducible-path'
-  BUILDUSERGECOS='first user,first room,first work-phone,first home-phone,first other'
-  BUILDUSERNAME='pbuilder1'
-  BUILD_ARCH='i386'
-  DEBIAN_FRONTEND='noninteractive'
-  DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=11 '
-  DISTRIBUTION='unstable'
-  HOME='/root'
-  HOST_ARCH='i386'
+  BASH=/bin/sh
+  BASHOPTS=checkwinsize:cmdhist:complete_fullquote:extquote:force_fignore:globasciiranges:globskipdots:hostcomplete:interactive_comments:patsub_replacement:progcomp:promptvars:sourcepath
+  BASH_ALIASES=()
+  BASH_ARGC=()
+  BASH_ARGV=()
+  BASH_CMDS=()
+  BASH_LINENO=([0]="12" [1]="0")
+  BASH_LOADABLES_PATH=/usr/local/lib/bash:/usr/lib/bash:/opt/local/lib/bash:/usr/pkg/lib/bash:/opt/pkg/lib/bash:.
+  BASH_SOURCE=([0]="/tmp/hooks/D02_print_environment" [1]="/tmp/hooks/D02_print_environment")
+  BASH_VERSINFO=([0]="5" [1]="2" [2]="37" [3]="1" [4]="release" [5]="i686-pc-linux-gnu")
+  BASH_VERSION='5.2.37(1)-release'
+  BUILDDIR=/build/reproducible-path
+  BUILDUSERGECOS='second user,second room,second work-phone,second home-phone,second other'
+  BUILDUSERNAME=pbuilder2
+  BUILD_ARCH=i386
+  DEBIAN_FRONTEND=noninteractive
+  DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=21 '
+  DIRSTACK=()
+  DISTRIBUTION=unstable
+  EUID=0
+  FUNCNAME=([0]="Echo" [1]="main")
+  GROUPS=()
+  HOME=/root
+  HOSTNAME=i-capture-the-hostname
+  HOSTTYPE=i686
+  HOST_ARCH=i386
   IFS=' 	
   '
-  INVOCATION_ID='f2e1f15182e44a2c9656bf35d1afec3a'
-  LANG='C'
-  LANGUAGE='en_US:en'
-  LC_ALL='C'
-  LD_LIBRARY_PATH='/usr/lib/libeatmydata'
-  LD_PRELOAD='libeatmydata.so'
-  MAIL='/var/mail/root'
-  OPTIND='1'
-  PATH='/usr/sbin:/usr/bin:/sbin:/bin:/usr/games'
-  PBCURRENTCOMMANDLINEOPERATION='build'
-  PBUILDER_OPERATION='build'
-  PBUILDER_PKGDATADIR='/usr/share/pbuilder'
-  PBUILDER_PKGLIBDIR='/usr/lib/pbuilder'
-  PBUILDER_SYSCONFDIR='/etc'
-  PPID='52563'
-  PS1='# '
-  PS2='> '
+  INVOCATION_ID=b00ac174402e42889c146de9cae83199
+  LANG=C
+  LANGUAGE=de_CH:de
+  LC_ALL=C
+  LD_LIBRARY_PATH=/usr/lib/libeatmydata
+  LD_PRELOAD=libeatmydata.so
+  MACHTYPE=i686-pc-linux-gnu
+  MAIL=/var/mail/root
+  OPTERR=1
+  OPTIND=1
+  OSTYPE=linux-gnu
+  PATH=/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path
+  PBCURRENTCOMMANDLINEOPERATION=build
+  PBUILDER_OPERATION=build
+  PBUILDER_PKGDATADIR=/usr/share/pbuilder
+  PBUILDER_PKGLIBDIR=/usr/lib/pbuilder
+  PBUILDER_SYSCONFDIR=/etc
+  PIPESTATUS=([0]="0")
+  POSIXLY_CORRECT=y
+  PPID=127311
   PS4='+ '
-  PWD='/'
-  SHELL='/bin/bash'
-  SHLVL='2'
-  SUDO_COMMAND='/usr/bin/timeout -k 18.1h 18h /usr/bin/ionice -c 3 /usr/bin/nice /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.3uqZ6Bqd/pbuilderrc_PmRR --distribution unstable --hookdir /etc/pbuilder/first-build-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/unstable-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.3uqZ6Bqd/b1 --logfile b1/build.log sigsum-go_0.10.1-1.dsc'
-  SUDO_GID='112'
-  SUDO_UID='107'
-  SUDO_USER='jenkins'
-  TERM='unknown'
-  TZ='/usr/share/zoneinfo/Etc/GMT+12'
-  USER='root'
-  _='/usr/bin/systemd-run'
-  http_proxy='http://46.16.76.132:3128'
+  PWD=/
+  SHELL=/bin/bash
+  SHELLOPTS=braceexpand:errexit:hashall:interactive-comments:posix
+  SHLVL=3
+  SUDO_COMMAND='/usr/bin/timeout -k 24.1h 24h /usr/bin/ionice -c 3 /usr/bin/nice -n 11 /usr/bin/unshare --uts -- /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.3uqZ6Bqd/pbuilderrc_Jb7f --distribution unstable --hookdir /etc/pbuilder/rebuild-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/unstable-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.3uqZ6Bqd/b2 --logfile b2/build.log sigsum-go_0.10.1-1.dsc'
+  SUDO_GID=112
+  SUDO_UID=107
+  SUDO_USER=jenkins
+  TERM=unknown
+  TZ=/usr/share/zoneinfo/Etc/GMT-14
+  UID=0
+  USER=root
+  _='I: set'
+  http_proxy=http://213.165.73.152:3128
 I: uname -a
-  Linux ionos2-i386 6.1.0-30-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.124-1 (2025-01-12) x86_64 GNU/Linux
+  Linux i-capture-the-hostname 6.1.0-30-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.124-1 (2025-01-12) x86_64 GNU/Linux
 I: ls -l /bin
-  lrwxrwxrwx 1 root root 7 Nov 22 14:40 /bin -> usr/bin
-I: user script /srv/workspace/pbuilder/52563/tmp/hooks/D02_print_environment finished
+  lrwxrwxrwx 1 root root 7 Nov 22  2024 /bin -> usr/bin
+I: user script /srv/workspace/pbuilder/127311/tmp/hooks/D02_print_environment finished
  -> Attempting to satisfy build-dependencies
  -> Creating pbuilder-satisfydepends-dummy package
 Package: pbuilder-satisfydepends-dummy
@@ -166,7 +198,7 @@
 Get: 44 http://deb.debian.org/debian unstable/main i386 golang-golang-x-crypto-dev all 1:0.25.0-1 [1682 kB]
 Get: 45 http://deb.debian.org/debian unstable/main i386 golang-golang-x-net-dev all 1:0.27.0-1 [898 kB]
 Get: 46 http://deb.debian.org/debian unstable/main i386 help2man i386 1.49.3 [198 kB]
-Fetched 72.4 MB in 1s (90.4 MB/s)
+Fetched 72.4 MB in 2s (45.1 MB/s)
 Preconfiguring packages ...
 Selecting previously unselected package liblocale-gettext-perl.
 (Reading database ... 
(Reading database ... 5%
(Reading database ... 10%
(Reading database ... 15%
(Reading database ... 20%
(Reading database ... 25%
(Reading database ... 30%
(Reading database ... 35%
(Reading database ... 40%
(Reading database ... 45%
(Reading database ... 50%
(Reading database ... 55%
(Reading database ... 60%
(Reading database ... 65%
(Reading database ... 70%
(Reading database ... 75%
(Reading database ... 80%
(Reading database ... 85%
(Reading database ... 90%
(Reading database ... 95%
(Reading database ... 100%
(Reading database ... 19829 files and directories currently installed.)
@@ -365,7 +397,11 @@
 Building tag database...
  -> Finished parsing the build-deps
 I: Building the package
-I: Running cd /build/reproducible-path/sigsum-go-0.10.1/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-genchanges -S  > ../sigsum-go_0.10.1-1_source.changes
+I: user script /srv/workspace/pbuilder/127311/tmp/hooks/A99_set_merged_usr starting
+Not re-configuring usrmerge for unstable
+I: user script /srv/workspace/pbuilder/127311/tmp/hooks/A99_set_merged_usr finished
+hostname: Name or service not known
+I: Running cd /build/reproducible-path/sigsum-go-0.10.1/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-genchanges -S  > ../sigsum-go_0.10.1-1_source.changes
 dpkg-buildpackage: info: source package sigsum-go
 dpkg-buildpackage: info: source version 0.10.1-1
 dpkg-buildpackage: info: source distribution unstable
@@ -383,176 +419,176 @@
    dh_autoreconf -O--builddirectory=_build -O--buildsystem=golang
    dh_auto_configure -O--builddirectory=_build -O--buildsystem=golang
    dh_auto_build -O--builddirectory=_build -O--buildsystem=golang
-	cd _build && go install -trimpath -v -p 11 sigsum.org/sigsum-go/cmd/sigsum-key sigsum.org/sigsum-go/cmd/sigsum-monitor sigsum.org/sigsum-go/cmd/sigsum-submit sigsum.org/sigsum-go/cmd/sigsum-token sigsum.org/sigsum-go/cmd/sigsum-verify sigsum.org/sigsum-go/cmd/sigsum-witness sigsum.org/sigsum-go/internal/mocks/signer sigsum.org/sigsum-go/internal/ssh sigsum.org/sigsum-go/internal/version sigsum.org/sigsum-go/pkg/api sigsum.org/sigsum-go/pkg/ascii sigsum.org/sigsum-go/pkg/checkpoint sigsum.org/sigsum-go/pkg/client sigsum.org/sigsum-go/pkg/crypto sigsum.org/sigsum-go/pkg/key sigsum.org/sigsum-go/pkg/log sigsum.org/sigsum-go/pkg/merkle sigsum.org/sigsum-go/pkg/mocks sigsum.org/sigsum-go/pkg/monitor sigsum.org/sigsum-go/pkg/policy sigsum.org/sigsum-go/pkg/proof sigsum.org/sigsum-go/pkg/requests sigsum.org/sigsum-go/pkg/server sigsum.org/sigsum-go/pkg/submit sigsum.org/sigsum-go/pkg/submit-token sigsum.org/sigsum-go/pkg/types sigsum.org/sigsum-go/tests/mk-add-checkpoint-request sigsum.org/sigsum-go/tests/sha256-n sigsum.org/sigsum-go/tests/use-agent
-internal/godebugs
-internal/race
-internal/profilerecord
-internal/unsafeheader
-internal/goarch
-internal/coverage/rtcov
-internal/runtime/syscall
-internal/goos
+	cd _build && go install -trimpath -v -p 21 sigsum.org/sigsum-go/cmd/sigsum-key sigsum.org/sigsum-go/cmd/sigsum-monitor sigsum.org/sigsum-go/cmd/sigsum-submit sigsum.org/sigsum-go/cmd/sigsum-token sigsum.org/sigsum-go/cmd/sigsum-verify sigsum.org/sigsum-go/cmd/sigsum-witness sigsum.org/sigsum-go/internal/mocks/signer sigsum.org/sigsum-go/internal/ssh sigsum.org/sigsum-go/internal/version sigsum.org/sigsum-go/pkg/api sigsum.org/sigsum-go/pkg/ascii sigsum.org/sigsum-go/pkg/checkpoint sigsum.org/sigsum-go/pkg/client sigsum.org/sigsum-go/pkg/crypto sigsum.org/sigsum-go/pkg/key sigsum.org/sigsum-go/pkg/log sigsum.org/sigsum-go/pkg/merkle sigsum.org/sigsum-go/pkg/mocks sigsum.org/sigsum-go/pkg/monitor sigsum.org/sigsum-go/pkg/policy sigsum.org/sigsum-go/pkg/proof sigsum.org/sigsum-go/pkg/requests sigsum.org/sigsum-go/pkg/server sigsum.org/sigsum-go/pkg/submit sigsum.org/sigsum-go/pkg/submit-token sigsum.org/sigsum-go/pkg/types sigsum.org/sigsum-go/tests/mk-add-checkpoint-request sigsum.org/sigsum-go/tests/sha256-n sigsum.org/sigsum-go/tests/use-agent
 internal/byteorder
-internal/runtime/atomic
-internal/goexperiment
-internal/cpu
-sync/atomic
-unicode
-unicode/utf8
-internal/abi
-runtime/internal/math
-runtime/internal/sys
-cmp
+internal/coverage/rtcov
 internal/itoa
-internal/chacha8rand
-math/bits
+internal/goarch
+internal/race
 internal/asan
-internal/msan
 log/internal
+internal/unsafeheader
+internal/msan
+unicode/utf8
+internal/godebugs
+math/bits
 crypto/internal/alias
-crypto/internal/boring/sig
 internal/nettrace
 container/list
-internal/bytealg
 unicode/utf16
 vendor/golang.org/x/crypto/cryptobyte/asn1
+internal/goos
+sync/atomic
 vendor/golang.org/x/crypto/internal/alias
-internal/runtime/exithook
+internal/runtime/atomic
+internal/cpu
+internal/chacha8rand
+unicode
+internal/goexperiment
+crypto/internal/boring/sig
 math
+cmp
+runtime/internal/math
+internal/profilerecord
+runtime/internal/sys
+internal/abi
+internal/runtime/syscall
+internal/runtime/exithook
+internal/bytealg
 internal/stringslite
 runtime
-iter
 internal/reflectlite
-crypto/subtle
 internal/weak
+crypto/subtle
+iter
 sync
 maps
 slices
+internal/bisect
 internal/testlog
 internal/singleflight
-internal/bisect
 runtime/cgo
 errors
 sort
 internal/oserror
-path
 io
-math/rand/v2
-crypto/internal/edwards25519/field
+path
 vendor/golang.org/x/net/dns/dnsmessage
-crypto/internal/nistec/fiat
 strconv
-internal/godebug
+crypto/internal/edwards25519/field
+math/rand/v2
 syscall
+crypto/internal/nistec/fiat
+internal/godebug
 bytes
 reflect
-hash
-crypto/cipher
-internal/concurrent
-math/rand
+encoding/base32
 crypto/internal/randutil
 strings
+math/rand
+internal/concurrent
+crypto/rc4
 crypto/internal/edwards25519
+hash
 crypto
 unique
 hash/crc32
+vendor/golang.org/x/text/transform
+crypto/cipher
+golang.org/x/text/transform
 crypto/md5
-crypto/rc4
+time
+internal/syscall/unix
+internal/syscall/execenv
+net/http/internal/ascii
+bufio
+net/netip
 crypto/internal/boring
 crypto/des
-vendor/golang.org/x/text/transform
-net/netip
 crypto/sha512
 crypto/sha256
 crypto/aes
-bufio
 crypto/hmac
 crypto/sha1
-net/http/internal/ascii
 vendor/golang.org/x/crypto/hkdf
-golang.org/x/text/transform
-encoding/base32
-time
-internal/syscall/unix
-internal/syscall/execenv
 crypto/internal/nistec
 io/fs
 context
 internal/poll
-internal/filepathlite
 crypto/ecdh
-os
 internal/fmtsort
 encoding/binary
+internal/filepathlite
+os
 encoding/base64
-vendor/golang.org/x/crypto/internal/poly1305
 vendor/golang.org/x/crypto/chacha20
+vendor/golang.org/x/crypto/internal/poly1305
 encoding/pem
 vendor/golang.org/x/crypto/chacha20poly1305
 fmt
 vendor/golang.org/x/sys/cpu
-path/filepath
 os/signal
+path/filepath
 net
 vendor/golang.org/x/crypto/sha3
 github.com/pborman/getopt/v2
-log
 encoding/hex
 runtime/debug
-net/url
+log
 math/big
 compress/flate
+net/url
 vendor/golang.org/x/net/http2/hpack
 mime
 vendor/golang.org/x/text/unicode/norm
 mime/quotedprintable
-sigsum.org/sigsum-go/internal/version
+github.com/golang/mock/gomock
 net/http/internal
+golang.org/x/text/unicode/norm
+vendor/golang.org/x/text/unicode/bidi
 sigsum.org/sigsum-go/pkg/log
 golang.org/x/text/unicode/bidi
-vendor/golang.org/x/text/unicode/bidi
-golang.org/x/text/unicode/norm
-github.com/golang/mock/gomock
 compress/gzip
 golang.org/x/text/secure/bidirule
+sigsum.org/sigsum-go/internal/version
 vendor/golang.org/x/text/secure/bidirule
 vendor/golang.org/x/net/idna
 golang.org/x/net/idna
 crypto/rand
 crypto/internal/bigmod
-crypto/elliptic
 crypto/internal/boring/bbig
 encoding/asn1
+crypto/elliptic
 crypto/dsa
 crypto/ed25519
 crypto/internal/hpke
 crypto/internal/mlkem768
 github.com/dchest/safefile
-crypto/rsa
 sigsum.org/sigsum-go/pkg/crypto
+crypto/rsa
 sigsum.org/sigsum-go/pkg/ascii
+sigsum.org/sigsum-go/pkg/merkle
 sigsum.org/sigsum-go/internal/mocks/signer
 sigsum.org/sigsum-go/tests/sha256-n
-sigsum.org/sigsum-go/pkg/merkle
-crypto/x509/pkix
 vendor/golang.org/x/crypto/cryptobyte
+crypto/x509/pkix
 crypto/ecdsa
+crypto/x509
 sigsum.org/sigsum-go/internal/ssh
+net/textproto
 vendor/golang.org/x/net/http/httpproxy
 sigsum.org/sigsum-go/pkg/submit-token
-net/textproto
-crypto/x509
-sigsum.org/sigsum-go/pkg/types
 sigsum.org/sigsum-go/pkg/key
+sigsum.org/sigsum-go/pkg/types
+sigsum.org/sigsum-go/tests/use-agent
+sigsum.org/sigsum-go/cmd/sigsum-token
 vendor/golang.org/x/net/http/httpguts
 mime/multipart
-sigsum.org/sigsum-go/cmd/sigsum-token
-sigsum.org/sigsum-go/tests/use-agent
 sigsum.org/sigsum-go/pkg/checkpoint
 sigsum.org/sigsum-go/pkg/policy
 sigsum.org/sigsum-go/pkg/requests
-sigsum.org/sigsum-go/tests/mk-add-checkpoint-request
 sigsum.org/sigsum-go/cmd/sigsum-key
+sigsum.org/sigsum-go/tests/mk-add-checkpoint-request
 sigsum.org/sigsum-go/pkg/proof
 sigsum.org/sigsum-go/pkg/mocks
 sigsum.org/sigsum-go/cmd/sigsum-verify
@@ -562,24 +598,24 @@
 sigsum.org/sigsum-go/pkg/api
 sigsum.org/sigsum-go/pkg/client
 sigsum.org/sigsum-go/pkg/server
-sigsum.org/sigsum-go/pkg/monitor
 sigsum.org/sigsum-go/pkg/submit
+sigsum.org/sigsum-go/pkg/monitor
 sigsum.org/sigsum-go/cmd/sigsum-witness
 sigsum.org/sigsum-go/cmd/sigsum-submit
 sigsum.org/sigsum-go/cmd/sigsum-monitor
    debian/rules override_dh_auto_test
 make[1]: Entering directory '/build/reproducible-path/sigsum-go-0.10.1'
 env DH_GOLANG_EXCLUDES=sigsum.org/sigsum-go/pkg/server dh_auto_test 
-	cd _build && go test -vet=off -v -p 11 sigsum.org/sigsum-go/cmd/sigsum-key sigsum.org/sigsum-go/cmd/sigsum-monitor sigsum.org/sigsum-go/cmd/sigsum-submit sigsum.org/sigsum-go/cmd/sigsum-token sigsum.org/sigsum-go/cmd/sigsum-verify sigsum.org/sigsum-go/cmd/sigsum-witness sigsum.org/sigsum-go/internal/mocks/signer sigsum.org/sigsum-go/internal/ssh sigsum.org/sigsum-go/internal/version sigsum.org/sigsum-go/pkg/api sigsum.org/sigsum-go/pkg/ascii sigsum.org/sigsum-go/pkg/checkpoint sigsum.org/sigsum-go/pkg/client sigsum.org/sigsum-go/pkg/crypto sigsum.org/sigsum-go/pkg/key sigsum.org/sigsum-go/pkg/log sigsum.org/sigsum-go/pkg/merkle sigsum.org/sigsum-go/pkg/mocks sigsum.org/sigsum-go/pkg/monitor sigsum.org/sigsum-go/pkg/policy sigsum.org/sigsum-go/pkg/proof sigsum.org/sigsum-go/pkg/requests sigsum.org/sigsum-go/pkg/submit sigsum.org/sigsum-go/pkg/submit-token sigsum.org/sigsum-go/pkg/types sigsum.org/sigsum-go/tests/mk-add-checkpoint-request sigsum.org/sigsum-go/tests/sha256-n sigsum.org/sigsum-go/tests/use-agent
+	cd _build && go test -vet=off -v -p 21 sigsum.org/sigsum-go/cmd/sigsum-key sigsum.org/sigsum-go/cmd/sigsum-monitor sigsum.org/sigsum-go/cmd/sigsum-submit sigsum.org/sigsum-go/cmd/sigsum-token sigsum.org/sigsum-go/cmd/sigsum-verify sigsum.org/sigsum-go/cmd/sigsum-witness sigsum.org/sigsum-go/internal/mocks/signer sigsum.org/sigsum-go/internal/ssh sigsum.org/sigsum-go/internal/version sigsum.org/sigsum-go/pkg/api sigsum.org/sigsum-go/pkg/ascii sigsum.org/sigsum-go/pkg/checkpoint sigsum.org/sigsum-go/pkg/client sigsum.org/sigsum-go/pkg/crypto sigsum.org/sigsum-go/pkg/key sigsum.org/sigsum-go/pkg/log sigsum.org/sigsum-go/pkg/merkle sigsum.org/sigsum-go/pkg/mocks sigsum.org/sigsum-go/pkg/monitor sigsum.org/sigsum-go/pkg/policy sigsum.org/sigsum-go/pkg/proof sigsum.org/sigsum-go/pkg/requests sigsum.org/sigsum-go/pkg/submit sigsum.org/sigsum-go/pkg/submit-token sigsum.org/sigsum-go/pkg/types sigsum.org/sigsum-go/tests/mk-add-checkpoint-request sigsum.org/sigsum-go/tests/sha256-n sigsum.org/sigsum-go/tests/use-agent
 ?   	sigsum.org/sigsum-go/cmd/sigsum-key	[no test files]
 ?   	sigsum.org/sigsum-go/cmd/sigsum-monitor	[no test files]
 ?   	sigsum.org/sigsum-go/cmd/sigsum-submit	[no test files]
-?   	sigsum.org/sigsum-go/cmd/sigsum-verify	[no test files]
 ?   	sigsum.org/sigsum-go/cmd/sigsum-token	[no test files]
+?   	sigsum.org/sigsum-go/cmd/sigsum-verify	[no test files]
 ?   	sigsum.org/sigsum-go/cmd/sigsum-witness	[no test files]
+?   	sigsum.org/sigsum-go/internal/mocks/signer	[no test files]
 ?   	sigsum.org/sigsum-go/internal/version	[no test files]
 ?   	sigsum.org/sigsum-go/pkg/api	[no test files]
-?   	sigsum.org/sigsum-go/internal/mocks/signer	[no test files]
 === RUN   TestRequest
 --- PASS: TestRequest (0.00s)
 === RUN   TestSignEd25519
@@ -597,7 +633,7 @@
 === RUN   TestSignedData
 --- PASS: TestSignedData (0.00s)
 PASS
-ok  	sigsum.org/sigsum-go/internal/ssh	0.039s
+ok  	sigsum.org/sigsum-go/internal/ssh	0.057s
 === RUN   TestLineReaderGetLine
 --- PASS: TestLineReaderGetLine (0.00s)
 === RUN   TestLineReaderGetEOF
@@ -627,7 +663,7 @@
 === RUN   TestCheckpointSigned
 --- PASS: TestCheckpointSigned (0.03s)
 === RUN   TestCheckpointVerify
---- PASS: TestCheckpointVerify (0.01s)
+--- PASS: TestCheckpointVerify (0.02s)
 === RUN   TestCheckpointVerifyIgnoreExtraSignature
 --- PASS: TestCheckpointVerifyIgnoreExtraSignature (0.01s)
 === RUN   TestCheckpointCosignVerify
@@ -657,12 +693,12 @@
 === RUN   TestGoSumDBVerifier
 --- PASS: TestGoSumDBVerifier (0.00s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/checkpoint	0.069s
+ok  	sigsum.org/sigsum-go/pkg/checkpoint	0.087s
 ?   	sigsum.org/sigsum-go/pkg/mocks	[no test files]
 === RUN   TestProcessConflictResponse
 --- PASS: TestProcessConflictResponse (0.00s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/client	0.009s
+ok  	sigsum.org/sigsum-go/pkg/client	0.825s
 === RUN   TestValidHashFromHex
 --- PASS: TestValidHashFromHex (0.00s)
 === RUN   TestInvalidHashFromHex
@@ -682,15 +718,15 @@
 === RUN   TestVerify
 --- PASS: TestVerify (0.01s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/crypto	0.049s
+ok  	sigsum.org/sigsum-go/pkg/crypto	0.685s
 === RUN   TestParsePublicKeysFile
 --- PASS: TestParsePublicKeysFile (0.00s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/key	0.009s
+ok  	sigsum.org/sigsum-go/pkg/key	0.474s
 === RUN   Example
 --- PASS: Example (0.00s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/log	0.008s
+ok  	sigsum.org/sigsum-go/pkg/log	0.680s
 ?   	sigsum.org/sigsum-go/tests/mk-add-checkpoint-request	[no test files]
 ?   	sigsum.org/sigsum-go/tests/sha256-n	[no test files]
 ?   	sigsum.org/sigsum-go/tests/use-agent	[no test files]
@@ -705,26 +741,26 @@
 === RUN   TestInclusion
 --- PASS: TestInclusion (0.00s)
 === RUN   TestInclusionValid
---- PASS: TestInclusionValid (0.71s)
+--- PASS: TestInclusionValid (1.01s)
 === RUN   TestInclusionBatchValid
---- PASS: TestInclusionBatchValid (1.24s)
+--- PASS: TestInclusionBatchValid (2.27s)
 === RUN   TestInclusionTailValid
---- PASS: TestInclusionTailValid (1.10s)
+--- PASS: TestInclusionTailValid (1.64s)
 === RUN   TestConsistency
 --- PASS: TestConsistency (0.00s)
 === RUN   TestConsistencyValid
---- PASS: TestConsistencyValid (0.60s)
+--- PASS: TestConsistencyValid (0.97s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/merkle	3.660s
+ok  	sigsum.org/sigsum-go/pkg/merkle	6.356s
 === RUN   TestGetTreeHead
---- PASS: TestGetTreeHead (4.08s)
+--- PASS: TestGetTreeHead (5.27s)
 === RUN   TestGetTreeHeadErrors
     client_test.go:171: bad signature: (expected) failure: monitoring alert: Invalid log signature: log signature invalid
     client_test.go:171: bad signature (hash): (expected) failure: monitoring alert: Invalid log signature: log signature invalid
     client_test.go:171: bad consistency: (expected) failure: monitoring alert: Log tree head not consistent: consistency proof not valid: invalid proof: old root mismatch
---- PASS: TestGetTreeHeadErrors (0.08s)
+--- PASS: TestGetTreeHeadErrors (0.10s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/monitor	4.173s
+ok  	sigsum.org/sigsum-go/pkg/monitor	5.403s
 === RUN   TestValidConfig
 --- PASS: TestValidConfig (0.00s)
 === RUN   TestNumericThreshold
@@ -732,11 +768,11 @@
 === RUN   TestInvalidConfig
 --- PASS: TestInvalidConfig (0.00s)
 === RUN   TestLogPolicy
---- PASS: TestLogPolicy (0.05s)
+--- PASS: TestLogPolicy (0.08s)
 === RUN   TestWitnessPolicy
 --- PASS: TestWitnessPolicy (0.05s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/policy	0.117s
+ok  	sigsum.org/sigsum-go/pkg/policy	0.159s
 === RUN   TestASCII
 --- PASS: TestASCII (0.00s)
 === RUN   TestASCIIV1
@@ -746,7 +782,7 @@
 === RUN   TestVerify
 --- PASS: TestVerify (0.01s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/proof	0.044s
+ok  	sigsum.org/sigsum-go/pkg/proof	0.059s
 === RUN   TestLeafToASCII
 --- PASS: TestLeafToASCII (0.00s)
 === RUN   TestLeavesToURL
@@ -768,7 +804,7 @@
 === RUN   TestAddCheckpointFromASCII
 --- PASS: TestAddCheckpointFromASCII (0.00s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/requests	0.020s
+ok  	sigsum.org/sigsum-go/pkg/requests	0.047s
 === RUN   TestSubmitSuccess
 === RUN   TestSubmitSuccess/leaf_1
 === RUN   TestSubmitSuccess/leaf_2
@@ -779,8 +815,8 @@
 === RUN   TestSubmitSuccess/leaf_7
 === RUN   TestSubmitSuccess/leaf_8
 === RUN   TestSubmitSuccess/leaf_9
---- PASS: TestSubmitSuccess (0.10s)
-    --- PASS: TestSubmitSuccess/leaf_1 (0.01s)
+--- PASS: TestSubmitSuccess (0.12s)
+    --- PASS: TestSubmitSuccess/leaf_1 (0.02s)
     --- PASS: TestSubmitSuccess/leaf_2 (0.01s)
     --- PASS: TestSubmitSuccess/leaf_3 (0.01s)
     --- PASS: TestSubmitSuccess/leaf_4 (0.01s)
@@ -797,7 +833,7 @@
 === RUN   TestSubmitFailure/leaf_5
 === RUN   TestSubmitFailure/leaf_6
 === RUN   TestSubmitFailure/leaf_7
---- PASS: TestSubmitFailure (0.03s)
+--- PASS: TestSubmitFailure (0.04s)
     --- PASS: TestSubmitFailure/leaf_1 (0.01s)
     --- PASS: TestSubmitFailure/leaf_2 (0.00s)
     --- PASS: TestSubmitFailure/leaf_3 (0.00s)
@@ -806,7 +842,7 @@
     --- PASS: TestSubmitFailure/leaf_6 (0.00s)
     --- PASS: TestSubmitFailure/leaf_7 (0.00s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/submit	0.129s
+ok  	sigsum.org/sigsum-go/pkg/submit	0.184s
 === RUN   TestNormalize
 --- PASS: TestNormalize (0.00s)
 === RUN   TestNormalizeReject
@@ -821,15 +857,15 @@
 === RUN   TestSubmitHeaderToHeader
 --- PASS: TestSubmitHeaderToHeader (0.00s)
 === RUN   TestVerify
---- PASS: TestVerify (0.05s)
+--- PASS: TestVerify (0.10s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/submit-token	0.057s
+ok  	sigsum.org/sigsum-go/pkg/submit-token	0.140s
 === RUN   TestLeafSignedData
 --- PASS: TestLeafSignedData (0.00s)
 === RUN   TestSignLeaf
 --- PASS: TestSignLeaf (0.00s)
 === RUN   TestLeafVerify
---- PASS: TestLeafVerify (0.04s)
+--- PASS: TestLeafVerify (0.06s)
 === RUN   TestLeafToBinary
 --- PASS: TestLeafToBinary (0.00s)
 === RUN   TestLeafFromBinary
@@ -879,9 +915,9 @@
 === RUN   TestCosignedTreeHeadFromASCII
 --- PASS: TestCosignedTreeHeadFromASCII (0.00s)
 PASS
-ok  	sigsum.org/sigsum-go/pkg/types	0.073s
+ok  	sigsum.org/sigsum-go/pkg/types	0.126s
 env DH_GOLANG_BUILDPKG=sigsum.org/sigsum-go/pkg/server dh_auto_test 
-	cd _build && go test -vet=off -v -p 11 sigsum.org/sigsum-go/pkg/server
+	cd _build && go test -vet=off -v -p 21 sigsum.org/sigsum-go/pkg/server
 === RUN   TestGetTreeHead
     log_test.go:48: Unexpected status code, got 404, want 200
     controller.go:269: missing call(s) to *mocks.MockLog.GetTreeHead(is anything) /build/reproducible-path/sigsum-go-0.10.1/_build/src/sigsum.org/sigsum-go/pkg/server/log_test.go:44
@@ -960,9 +996,9 @@
     controller.go:269: aborting test due to missing call(s)
 --- FAIL: TestAddCheckpoint (0.00s)
 FAIL
-FAIL	sigsum.org/sigsum-go/pkg/server	0.012s
+FAIL	sigsum.org/sigsum-go/pkg/server	0.018s
 FAIL
-dh_auto_test: error: cd _build && go test -vet=off -v -p 11 sigsum.org/sigsum-go/pkg/server returned exit code 1
+dh_auto_test: error: cd _build && go test -vet=off -v -p 21 sigsum.org/sigsum-go/pkg/server returned exit code 1
 make[1]: [debian/rules:10: override_dh_auto_test] Error 25 (ignored)
 make[1]: Leaving directory '/build/reproducible-path/sigsum-go-0.10.1'
    create-stamp debian/debhelper-build-stamp
@@ -999,12 +1035,12 @@
    dh_fixperms -O--builddirectory=_build -O--buildsystem=golang
    dh_missing -O--builddirectory=_build -O--buildsystem=golang
    dh_strip -a -O--builddirectory=_build -O--buildsystem=golang
-dh_strip: warning: Could not find the BuildID in debian/sigsum-go/usr/bin/sigsum-submit
+dh_strip: warning: Could not find the BuildID in debian/sigsum-go/usr/bin/sigsum-verify
 dh_strip: warning: Could not find the BuildID in debian/sigsum-go/usr/bin/sigsum-token
-dh_strip: warning: Could not find the BuildID in debian/sigsum-go/usr/bin/sigsum-key
 dh_strip: warning: Could not find the BuildID in debian/sigsum-go/usr/bin/sigsum-monitor
-dh_strip: warning: Could not find the BuildID in debian/sigsum-go/usr/bin/sigsum-verify
+dh_strip: warning: Could not find the BuildID in debian/sigsum-go/usr/bin/sigsum-key
 dh_strip: warning: Could not find the BuildID in debian/sigsum-go/usr/bin/sigsum-witness
+dh_strip: warning: Could not find the BuildID in debian/sigsum-go/usr/bin/sigsum-submit
    dh_makeshlibs -a -O--builddirectory=_build -O--buildsystem=golang
    dh_shlibdeps -a -O--builddirectory=_build -O--buildsystem=golang
    dh_installdeb -O--builddirectory=_build -O--buildsystem=golang
@@ -1022,12 +1058,14 @@
 dpkg-buildpackage: info: binary-only upload (no source included)
 dpkg-genchanges: info: including full source code in upload
 I: copying local configuration
+I: user script /srv/workspace/pbuilder/127311/tmp/hooks/B01_cleanup starting
+I: user script /srv/workspace/pbuilder/127311/tmp/hooks/B01_cleanup finished
 I: unmounting dev/ptmx filesystem
 I: unmounting dev/pts filesystem
 I: unmounting dev/shm filesystem
 I: unmounting proc filesystem
 I: unmounting sys filesystem
 I: cleaning the build env 
-I: removing directory /srv/workspace/pbuilder/52563 and its subdirectories
-I: Current time: Mon Jan 27 11:14:03 -12 2025
-I: pbuilder-time-stamp: 1738019643
+I: removing directory /srv/workspace/pbuilder/127311 and its subdirectories
+I: Current time: Mon Mar  2 19:35:07 +14 2026
+I: pbuilder-time-stamp: 1772429707