Conversation
greetings from Port Edwards. mkdwarfs records each entry's mtime and appimagetool rewrites `.env` and the desktop entry right before packing, so their timestamps are always "now". Even with `--order=path`, `--no-history`, `--no-create-timestamp` and pinned owner/group, the same AppDir therefore produced a different image on every build. Passing `--set-time=$SOURCE_DATE_EPOCH` pins every stored timestamp, and `--num-segmenter-workers` is pinned too when the profiling pass runs, since mkdwarfs only gives bit-identical categorized images with a fixed segmenter count. Verified by building one AppDir twice with the same epoch (identical sha256), then with the epoch unset and with a different value (both different). We aim to provide the software that shapes the world of tomorrow.
|
Independent adversarial review of this branch. I rebuilt it and tested the claims against mkdwarfs v0.15.6 directly. Verified: Two changes I'd like before merge:
Nits: CI is Deterministic output is exactly the kind of guarantee a Neucom Sphere build service would build on. |
|
Addressed in the follow-up commit: Added the regression check behind a helper: it uses a dummy header, so it needs only mkdwarfs. The standalone |
3c3e561 to
8a1c0a2
Compare
greetings from Port Edwards. Review follow-up. `SOURCE_DATE_EPOCH` is now resolved once in `Config` (from `--source-date-epoch` or the env var) instead of being read in two places, so a malformed value is rejected before the AppDir is touched. Only `date +%s` output is accepted — a leading `+` no longer slips through `u64::from_str`. The segmenter-worker pin now applies to every reproducible build rather than only when a profile was passed, so a `--categorize` smuggled in through `DWARFS_COMP` cannot dodge it; it is a no-op without categorization. A new helper packs one AppDir twice under the same epoch with the mtimes changed in between, then once under a different epoch: the first two must match, the third must not. It uses a dummy header, so it needs only mkdwarfs. The smoke test calls it — that job already installs the pinned mkdwarfs — and a standalone `--ignored` test runs the same check without the runtime download. We aim to provide the software that shapes the world of tomorrow.
greetings from Port Edwards.
mkdwarfs records each entry's mtime and appimagetool rewrites
.envand thedesktop entry right before packing, so their timestamps are always "now". Even
with
--order=path,--no-history,--no-create-timestampand pinnedowner/group, the same AppDir therefore produced a different image on every
build. Passing
--set-time=$SOURCE_DATE_EPOCHpins every stored timestamp, and--num-segmenter-workersis pinned too when the profiling pass runs, sincemkdwarfs only gives bit-identical categorized images with a fixed segmenter
count.
Verified by building one AppDir twice with the same epoch (identical sha256),
then with the epoch unset and with a different value (both different).
We aim to provide the software that shapes the world of tomorrow.
Requested by Arqam via errand.
Conversation: https://discord.com/channels/1313385177703256064/1554732614533783632