[OTR-dev] Reproducible builds of pidgin-otr for Windows
Jurre van Bergen
drwhax at 2600nl.net
Sun Mar 20 16:39:11 EDT 2016
On 03/20/2016 09:30 PM, Ian Goldberg wrote:
> On Sun, Mar 20, 2016 at 09:23:20PM +0100, Jurre van Bergen wrote:
>> Whee!
>>
>> cab715f8805a800cef678adc1b46c1aa551e3e14e454a909d8269a0afac05d8c
>> pidgin-otr-4.0.2.exe
>> f93499735b0d2f66091ab4fd1f2de99ff525b69e0bcd623b486d5b755a3cbe59
>> pidgin-otr-4.0.2.zip
>>
>> The zip isn't correct, I have uploaded it for reference:
>> http://jurrevanbergen.nl/otr/pidgin-otr-4.0.2.zip
> The zip files are in fact different, but they have identical content (as
> expected, since the nsis installer is indeed reproducible). And the
> differences aren't just in the header, either! (Maybe a per-file
> header?)
https://wiki.debian.org/ReproducibleBuilds/TimestampsInZip
I think that tells us all we need to know!
>
> Can you confirm the zip program you are using is:
>
> ii zip 3.0-8 amd64 Archiver for .zip files
>
> $ ls -l /usr/bin/zip
> -rwxr-xr-x 1 root root 188296 Oct 21 2013 /usr/bin/zip
>
> $ sha256sum /usr/bin/zip
> 999c1a1ee93fb610bd86d18533fea233d06eaa52a070f424779a5b9d989fcf48 /usr/bin/zip
>
root at 861d243e8262:~/pidgin-otr-4.0.2# dpkg --list | grep zip
ii bzip2 1.0.6-5
amd64 high-quality block-sorting file compressor - utilities
ii gzip 1.6-3ubuntu1
amd64 GNU compression utilities
ii unzip 6.0-9ubuntu1.5
amd64 De-archiver for .zip files
ii zip 3.0-8
amd64 Archiver for .zip files
root at 861d243e8262:~/pidgin-otr-4.0.2# ls -l /usr/bin/zip
-rwxr-xr-x 1 root root 188296 Oct 21 2013 /usr/bin/zip
root at 861d243e8262:~/pidgin-otr-4.0.2# sha256sum /usr/bin/zip
999c1a1ee93fb610bd86d18533fea233d06eaa52a070f424779a5b9d989fcf48
/usr/bin/zip
More information about the OTR-dev
mailing list