Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

x/build/cmd/release: ensure fully reproducible builds, including tar.gz/zip archives #24904

bradfitz opened this issue Apr 17, 2018 · 4 comments


Copy link

@bradfitz bradfitz commented Apr 17, 2018

Go already supports reproducible builds (with no action required), but our Go releases have .tar.gz/.zip archives that have timestamps.

We should probably make cmd/release also produce reproducible output and pin the archive file entry timestamps to the git commit time of the tagged commit we're building.

/cc @FiloSottile

@bradfitz bradfitz added this to the Go1.11 milestone Apr 17, 2018
@gopherbot gopherbot added the Builders label Apr 17, 2018
Copy link
Contributor Author

@bradfitz bradfitz commented Aug 13, 2018

@FiloSottile, were you going to do something here?

Copy link

@FiloSottile FiloSottile commented Aug 13, 2018

I treated this as lower priority than the changes that would go in the release, but I am going to try to make the final tar.gz/zip reproducible.

Copy link

@rsc rsc commented Aug 17, 2018

Are we going out of our way to set time stamps in the archives?
I was pretty sure archive/tar and archive/zip do not add the time themselves anymore.

Copy link
Contributor Author

@bradfitz bradfitz commented Aug 17, 2018

The buildlet sends a tarball to the x/build/cmd/release client.

The buildlet uses tar.FileInfoHeader.

The source on the buildlet ultimately comes from git (via git archive, via the gitmirror service, via the coordinator), but when the buildlet writes the git archive to disk, it clamps the file time to system time:

So it might all work for free today, assuming we have no files with future modtimes in the git repo.

But it's a little fragile.

It'd be nice if x/build/cmd/release enforced all the modtimes with something predictable, like using the same modtime for all files, picking the time of the git commit of the whole release.

/cc @andybons @dmitshur

@andybons andybons modified the milestones: Go1.11, Go1.11.1 Aug 25, 2018
@FiloSottile FiloSottile modified the milestones: Go1.11.1, Go1.12 Aug 31, 2018
@FiloSottile FiloSottile self-assigned this Aug 31, 2018
@andybons andybons modified the milestones: Go1.12, Go1.13 Feb 12, 2019
@FiloSottile FiloSottile removed their assignment Mar 8, 2019
@andybons andybons modified the milestones: Go1.13, Go1.14 Jul 8, 2019
@rsc rsc modified the milestones: Go1.14, Backlog Oct 9, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
None yet
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
5 participants