• Reproducible builds of ports using rebuilderd - 1 year later

    From cen@imbacen@gmail.com to muc.lists.freebsd.ports on Wed Sep 16 23:22:28 2026
    From Newsgroup: muc.lists.freebsd.ports

    Hello,

    This is my status update after about a year diving into reproducible
    builds of ports via rebuilderd.

    I successfully added FreeBSD support to rebuilderd which is now live for
    some time at https://rebuilderd.xpam.pl:2096/
    It's still experimental and not upstreamable but mostly works. And I
    still have lots of failures due to insufficient
    infrastructure but reinforcements are coming soon.

    On FreeBSD 15 amd64, latest, my efforts got me up to 33%+ reproducibility.

    This is not bit-for-bit reproducibility to be precise, I only compare
    .pkg ->content<- of local and upstream pkg,
    ignoring pkg metadata which is not yet reproducible. Otherwise it would
    be 0%.

    On the technical level;
    1. I fetch the whole packagesite and store it in local rebuilderd db.
    2. I take all of the packages ports_top_git_hash-es, then sort them from oldest to newest by commit time.
    3. Send them to rebuild queues in that order.
    4. Each build worker checks out the tree at the specific commit as it
    receives a package for a rebuild.
    5. This is intended to improve reuse of locally built poudriere
    dependencies by reducing switches between ports-tree revisions.

    This sorting procedure is specific to FreeBSD ports implementation and
    not in original rebuilderd scheduler.
    Debian uses a snapshot repo for rebuilds so the order of packages is irrelavant. Other distros are similar.

    I currently set the SOURCE_DATE_EPOCH to commit time but that will
    change to distfile's TIMESTAMP when/if point 2 below is implemented.

    The sorting approach seems logical on the surface however, I don't know
    the exact process how the official archive is built so a comment from
    someone in the know would help. Does it make sense or is it a pointless exercise?

    During this work, I encountered:
    1. port_git_hash and ports_top_git_hash written into MANIFEST can have different commit hash length depending on the clone depth and git config.
    This was fixed by poudriere which now always saves full commit length,
    making MANIFEST more reproducible.

    2. Setting SOURCE_DATE_EPOCH for the tree globally, THE issue to watch
    is https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=291905
    First exp-run showed some failures which are now fixed. I'd like to ask maintainers to perhaps raise the priority of this and give it a bit more attention.

    I saw some numbers from Ed Maste from a presentation 10 years ago which indicate that enabling this globally should improve reproducibility up
    to 80%.
    I'm not sure what the numbers from more recent re-runs are, I couldn't
    find any.

    In the near future I'll probably revert to doing 2 local rebuilds
    instead of comparing to upstream because at some point it becomes
    pointless without the S_D_E.
    However, comparing to upstream has it's advantages:
    1. It saves me 1 rebuild
    2. Diversity of build environments can sometime uncover surprising non-reproducible edge cases.
    3. Is the final goal. Local rebuilds are fine but what I actually care
    about is if we can reproduce what the OS ships.


    Best regards, Klemen



    --
    Posted automagically by a mail2news gateway at muc.de e.V.
    Please direct questions, flames, donations, etc. to news-admin@muc.de
    --- Synchronet 3.22a-Linux NewsLink 1.2