Reproducible builds enable anyone to reproduce bit by bit identical binary packages from a given source, so that anyone can verify that a given binary derived from the source it was said to be derived. There is more information about reproducible builds on the Debian wiki and on https://reproducible-builds.org. These pages explain in more depth why this is useful, what common issues exist and which workarounds and solutions are known.
Reproducible FreeBSD is an effort to apply this to FreeBSD. Thus FreeBSD is build twice, with a few variations added and then the resulting filesystems from the two builds are put into a compressed tar archive, which is finally compared using diffoscope. Please note that the toolchain is not varied at all as the rebuild happens on exactly the same system. More variations are expected to be seen in the wild.
There is a weekly run jenkins job to test the
main branch of freebsd.git. The jenkins job is running reproducible_freebsd.sh, which via ssh triggers a build on a FreeBSD system and this script is solely responsible for creating this page. Feel invited to join
#reproducible-builds (on irc.oftc.net) to request job runs whenever sensible. Patches and other feedback are very much appreciated - if you want to help, please start by looking at the ToDo list for FreeBSD, you might find something easy to contribute.
Thanks to IONOS for donating the virtual machines this is running on!
0 (0%) out of 0 FreeBSD files were reproducible in our test setup . These tests were last run on 2021-09-23 for the branch main at commit cb1305966 using diffoscope 185.
|variation||first build||second build|
|hostname||osuosl169-amd64 or osuosl170-amd64||the other one|
|domainname||is not yet varied between rebuilds of FreeBSD.|
|env LC_ALL||not set||LC_ALL="et_EE.UTF-8"|
|env PATH||is not yet varied between rebuilds of FreeBSD.|
|env USER||is not yet varied between rebuilds of FreeBSD.|
|uid||is not yet varied between rebuilds of FreeBSD.|
|gid||is not yet varied between rebuilds of FreeBSD.|
|FreeBSD kernel version||is not yet varied between rebuilds of FreeBSD.|
|umask||is not yet varied between rebuilds of FreeBSD.|
|CPU type||AMD Opteron 62xx class CPU||same for both builds|
|/bin/sh||is not yet varied between rebuilds of FreeBSD.|
|year, month, date||osuosl171-amd64: today (2021-09-23) or osuosl172-amd64: 398 days in the future (2022-10-26)||the other one|
|year, month, date||today (2021-09-23)||the 2nd build is done with the build node set 1 year, 1 month and 1 day in the future|
|hour, minute||hour and minute will vary between two builds||additionally the "future build" also runs 6h and 23min ahead|
|filesystem of the build directory||ufs||same for both builds|
|everything else...||is likely the same. There will be more variations in the wild.|
|Artifacts for |
|freebsd_main_gitcb1305966 failed to build from source.|
commit cb13059663e455b3fc69c293dadec53c164490dc Author: Kristof Provost
Date: Thu Sep 23 10:39:49 2021 +0200 pf: fix pagefault in pf_getstatus() We can't copyout() while holding a lock, in case it triggers a page fault. Release the lock before copyout, which is safe because we've already copied all the data into the nvlist. PR: 258601 Reviewed by: mjg MFC after: 1 week Sponsored by: Modirum MDPay Differential Revision: https://reviews.freebsd.org/D32076