<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[&quot;Packages that can&#x27;t be rebuilt byte-for-byte are now blocked from entering Debian&#x27;s testing branch.&quot;]]></title><description><![CDATA[<p>"Packages that can't be rebuilt byte-for-byte are now blocked from entering Debian's testing branch."</p><p><a href="https://itsfoss.com/news/debian-makes-reproducible-builds-mandatory/" rel="nofollow noopener"><span>https://</span><span>itsfoss.com/news/debian-makes-</span><span>reproducible-builds-mandatory/</span></a></p>]]></description><link>https://forum.fedi.dk/topic/7d439223-1e49-4714-88d9-5f764a87c86e/packages-that-can-t-be-rebuilt-byte-for-byte-are-now-blocked-from-entering-debian-s-testing-branch.</link><generator>RSS for Node</generator><lastBuildDate>Wed, 13 May 2026 16:08:02 GMT</lastBuildDate><atom:link href="https://forum.fedi.dk/topic/7d439223-1e49-4714-88d9-5f764a87c86e.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 13 May 2026 08:49:24 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to &quot;Packages that can&#x27;t be rebuilt byte-for-byte are now blocked from entering Debian&#x27;s testing branch.&quot; on Wed, 13 May 2026 12:48:25 GMT]]></title><description><![CDATA[<p><span><a href="/user/pol%40mathstodon.xyz">@<span>Pol</span></a></span> <span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> <span><a href="/user/gonzo_askold%40mastodon.social">@<span>gonzo_askold</span></a></span> <span><a href="/user/orpach.neocities.org%40bsky.brid.gy">@<span>orpach.neocities.org</span></a></span> indeed, "replayable" and "hermetic" are better terms for what Nix provides. Some of the bitwise reproducibility of nixpkgs comes from rigorously defining all build inputs, various patches we apply and default build settings we default to. But the brunt of the work is the massive and steller upstream work of <a href="https://reproducible-builds.org/" rel="nofollow noopener"><span>https://</span><span>reproducible-builds.org/</span><span></span></a>, without which nixpkgs would not even be close to bitwise reproducible</p>]]></description><link>https://forum.fedi.dk/post/https://snabelen.no/users/pbsds/statuses/116567343486096777</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://snabelen.no/users/pbsds/statuses/116567343486096777</guid><dc:creator><![CDATA[pbsds@snabelen.no]]></dc:creator><pubDate>Wed, 13 May 2026 12:48:25 GMT</pubDate></item><item><title><![CDATA[Reply to &quot;Packages that can&#x27;t be rebuilt byte-for-byte are now blocked from entering Debian&#x27;s testing branch.&quot; on Wed, 13 May 2026 12:35:09 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> <span><a href="/user/gonzo_askold%40mastodon.social">@<span>gonzo_askold</span></a></span> <span><a href="/user/orpach.neocities.org%40bsky.brid.gy">@<span>orpach.neocities.org</span></a></span> Indeed, Nix greatly increases the chances of producing reproducible packages by controlling the build environment.</p><p>That said, it does not magically make the final artefact reproducible. There can still be sources of non-determinism, and we try to track them down as much as possible.</p><p>So far, things are going well! <img src="https://forum.fedi.dk/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=7979fdcf9c7" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /></p>]]></description><link>https://forum.fedi.dk/post/https://mathstodon.xyz/users/Pol/statuses/116567291268770567</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mathstodon.xyz/users/Pol/statuses/116567291268770567</guid><dc:creator><![CDATA[pol@mathstodon.xyz]]></dc:creator><pubDate>Wed, 13 May 2026 12:35:09 GMT</pubDate></item><item><title><![CDATA[Reply to &quot;Packages that can&#x27;t be rebuilt byte-for-byte are now blocked from entering Debian&#x27;s testing branch.&quot; on Wed, 13 May 2026 11:38:10 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> Wow, that's awesome! Does anyone know if Ubuntu also will force reproducible builds considering that Ubuntu is based on Debian?</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/harmone/statuses/116567067198657412</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/harmone/statuses/116567067198657412</guid><dc:creator><![CDATA[harmone@mastodon.social]]></dc:creator><pubDate>Wed, 13 May 2026 11:38:10 GMT</pubDate></item><item><title><![CDATA[Reply to &quot;Packages that can&#x27;t be rebuilt byte-for-byte are now blocked from entering Debian&#x27;s testing branch.&quot; on Wed, 13 May 2026 11:35:17 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> </p><p>Does this mean derivatives like Devuan automatically do this too?</p>]]></description><link>https://forum.fedi.dk/post/https://todon.nl/ap/users/116512023332271913/statuses/116567055887108431</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://todon.nl/ap/users/116512023332271913/statuses/116567055887108431</guid><dc:creator><![CDATA[allende1973@todon.nl]]></dc:creator><pubDate>Wed, 13 May 2026 11:35:17 GMT</pubDate></item><item><title><![CDATA[Reply to &quot;Packages that can&#x27;t be rebuilt byte-for-byte are now blocked from entering Debian&#x27;s testing branch.&quot; on Wed, 13 May 2026 11:20:25 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> this is also what fdroid does on Android i i think</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/andreasio/statuses/116566997418955664</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/andreasio/statuses/116566997418955664</guid><dc:creator><![CDATA[andreasio@mastodon.social]]></dc:creator><pubDate>Wed, 13 May 2026 11:20:25 GMT</pubDate></item><item><title><![CDATA[Reply to &quot;Packages that can&#x27;t be rebuilt byte-for-byte are now blocked from entering Debian&#x27;s testing branch.&quot; on Wed, 13 May 2026 11:11:22 GMT]]></title><description><![CDATA[<p><span><a href="/user/gonzo_askold%40mastodon.social">@<span>gonzo_askold</span></a></span>  In fact <a href="https://mastodon.social/tags/Debian" rel="tag">#<span>Debian</span></a> and others are reproductible too.<br />You can visit <a href="https://reproducible-builds.org/" rel="nofollow noopener"><span>https://</span><span>reproducible-builds.org/</span><span></span></a> to have an idea. When I  worked in administration, we have a server with window NT to install via network on 200 same machines.</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/domdel/statuses/116566961849872203</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/domdel/statuses/116566961849872203</guid><dc:creator><![CDATA[domdel@mastodon.social]]></dc:creator><pubDate>Wed, 13 May 2026 11:11:22 GMT</pubDate></item><item><title><![CDATA[Reply to &quot;Packages that can&#x27;t be rebuilt byte-for-byte are now blocked from entering Debian&#x27;s testing branch.&quot; on Wed, 13 May 2026 11:03:45 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> idk what would be practical differences between these two systems and how one or the other would be more secure against supply chain attacks or other mitms </p><p>would be pretty interested in some reference materials</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/gonzo_askold/statuses/116566931913847350</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/gonzo_askold/statuses/116566931913847350</guid><dc:creator><![CDATA[gonzo_askold@mastodon.social]]></dc:creator><pubDate>Wed, 13 May 2026 11:03:45 GMT</pubDate></item><item><title><![CDATA[Reply to &quot;Packages that can&#x27;t be rebuilt byte-for-byte are now blocked from entering Debian&#x27;s testing branch.&quot; on Wed, 13 May 2026 11:03:42 GMT]]></title><description><![CDATA[<p><span><a href="/user/gonzo_askold%40mastodon.social">@<span>gonzo_askold</span></a></span>: this isn't true, as some builds embed things like the timestamp and build hostname in the artifacts. Nix sets some notion of the timestamp to epoch to account for this, but cannot fix every impurity everywhere (maven builds are notoriously finnicky, for instance).</p><p>Nix is great at this, but somewhat suffers from embracing the package without submitting the changes it makes to the package upstream. Because nix is so flexible (and doesn't always have the pull that Debian does with packagers), i believe nix has been less influential here than you would hope. </p><p>This change from Debian is awesome as we will all benefit from the fixes.</p>]]></description><link>https://forum.fedi.dk/post/https://tilde.zone/users/BryanBennett/statuses/116566931711105716</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://tilde.zone/users/BryanBennett/statuses/116566931711105716</guid><dc:creator><![CDATA[bryanbennett@tilde.zone]]></dc:creator><pubDate>Wed, 13 May 2026 11:03:42 GMT</pubDate></item><item><title><![CDATA[Reply to &quot;Packages that can&#x27;t be rebuilt byte-for-byte are now blocked from entering Debian&#x27;s testing branch.&quot; on Wed, 13 May 2026 10:58:30 GMT]]></title><description><![CDATA[<p><span><a href="/user/gonzo_askold%40mastodon.social">@<span>gonzo_askold</span></a></span> I'm only pointing out the difference, I'm not suggesting nix did anything bad or wrong.</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/bagder/statuses/116566911222050563</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/bagder/statuses/116566911222050563</guid><dc:creator><![CDATA[bagder@mastodon.social]]></dc:creator><pubDate>Wed, 13 May 2026 10:58:30 GMT</pubDate></item><item><title><![CDATA[Reply to &quot;Packages that can&#x27;t be rebuilt byte-for-byte are now blocked from entering Debian&#x27;s testing branch.&quot; on Wed, 13 May 2026 10:58:19 GMT]]></title><description><![CDATA[<p><span><a href="/user/gonzo_askold%40mastodon.social">@<span>gonzo_askold</span></a></span> <span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> sadly, that is not the case. <br />There are many corner cases, but the simplest example is "yes all your dependencies are reproducible, but you decide to `cat /dev/random &gt; $PREFIX/my-seed`" or whatever.</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.tetaneutral.net/users/nim/statuses/116566910564674202</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.tetaneutral.net/users/nim/statuses/116566910564674202</guid><dc:creator><![CDATA[nim@mastodon.tetaneutral.net]]></dc:creator><pubDate>Wed, 13 May 2026 10:58:19 GMT</pubDate></item><item><title><![CDATA[Reply to &quot;Packages that can&#x27;t be rebuilt byte-for-byte are now blocked from entering Debian&#x27;s testing branch.&quot; on Wed, 13 May 2026 10:58:11 GMT]]></title><description><![CDATA[<p><span><a href="/user/domdel%40mastodon.social">@<span>domdel</span></a></span> maybe I want there at that time</p><p>quick search of "net install reproducible" yields only dotnet stuff</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/gonzo_askold/statuses/116566910030755116</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/gonzo_askold/statuses/116566910030755116</guid><dc:creator><![CDATA[gonzo_askold@mastodon.social]]></dc:creator><pubDate>Wed, 13 May 2026 10:58:11 GMT</pubDate></item><item><title><![CDATA[Reply to &quot;Packages that can&#x27;t be rebuilt byte-for-byte are now blocked from entering Debian&#x27;s testing branch.&quot; on Wed, 13 May 2026 10:55:24 GMT]]></title><description><![CDATA[<p><span><a href="/user/gonzo_askold%40mastodon.social">@<span>gonzo_askold</span></a></span> <span><a href="/user/orpach.neocities.org%40bsky.brid.gy">@<span>orpach.neocities.org</span></a></span> <span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> About reprocductibility, net install was there before ...</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/domdel/statuses/116566899057818913</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/domdel/statuses/116566899057818913</guid><dc:creator><![CDATA[domdel@mastodon.social]]></dc:creator><pubDate>Wed, 13 May 2026 10:55:24 GMT</pubDate></item><item><title><![CDATA[Reply to &quot;Packages that can&#x27;t be rebuilt byte-for-byte are now blocked from entering Debian&#x27;s testing branch.&quot; on Wed, 13 May 2026 10:53:42 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> </p><p>I'm not that knowledgeable about inside workings, but in theory (in my head) hashing all inputs does equate to byte-to-byte reproducibility, even if previous steps in the build process weren't written specifically to be reproduced</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/gonzo_askold/statuses/116566892356435796</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/gonzo_askold/statuses/116566892356435796</guid><dc:creator><![CDATA[gonzo_askold@mastodon.social]]></dc:creator><pubDate>Wed, 13 May 2026 10:53:42 GMT</pubDate></item><item><title><![CDATA[Reply to &quot;Packages that can&#x27;t be rebuilt byte-for-byte are now blocked from entering Debian&#x27;s testing branch.&quot; on Wed, 13 May 2026 10:51:16 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> <span><a href="/user/gonzo_askold%40mastodon.social">@<span>gonzo_askold</span></a></span> <span><a href="/user/orpach.neocities.org%40bsky.brid.gy">@<span>orpach.neocities.org</span></a></span> yes, <a href="https://reproducible-builds.org/" rel="nofollow noopener"><span>https://</span><span>reproducible-builds.org/</span><span></span></a> also apply to nix : <a href="https://reproducible.nixos.org/" rel="nofollow noopener"><span>https://</span><span>reproducible.nixos.org/</span><span></span></a> <br />there was 100% on minimal iso in december, but there is no hard constraint on the whole 100k+ package set from nixkpgs</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.tetaneutral.net/users/nim/statuses/116566882803264595</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.tetaneutral.net/users/nim/statuses/116566882803264595</guid><dc:creator><![CDATA[nim@mastodon.tetaneutral.net]]></dc:creator><pubDate>Wed, 13 May 2026 10:51:16 GMT</pubDate></item><item><title><![CDATA[Reply to &quot;Packages that can&#x27;t be rebuilt byte-for-byte are now blocked from entering Debian&#x27;s testing branch.&quot; on Wed, 13 May 2026 10:47:45 GMT]]></title><description><![CDATA[<p><span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> it’s been 3 days and your post is still trending… what a great motto.”</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/seharinsights/statuses/116566869009342672</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/seharinsights/statuses/116566869009342672</guid><dc:creator><![CDATA[seharinsights@mastodon.social]]></dc:creator><pubDate>Wed, 13 May 2026 10:47:45 GMT</pubDate></item><item><title><![CDATA[Reply to &quot;Packages that can&#x27;t be rebuilt byte-for-byte are now blocked from entering Debian&#x27;s testing branch.&quot; on Wed, 13 May 2026 10:47:02 GMT]]></title><description><![CDATA[<p><span><a href="/user/gonzo_askold%40mastodon.social">@<span>gonzo_askold</span></a></span> <span><a href="/user/orpach.neocities.org%40bsky.brid.gy">@<span>orpach.neocities.org</span></a></span> sure, but nix has still included packages that not in themselves were done reproducible I'm pretty sure.</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/bagder/statuses/116566866178233105</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/bagder/statuses/116566866178233105</guid><dc:creator><![CDATA[bagder@mastodon.social]]></dc:creator><pubDate>Wed, 13 May 2026 10:47:02 GMT</pubDate></item><item><title><![CDATA[Reply to &quot;Packages that can&#x27;t be rebuilt byte-for-byte are now blocked from entering Debian&#x27;s testing branch.&quot; on Wed, 13 May 2026 10:23:20 GMT]]></title><description><![CDATA[<p><span><a href="/user/orpach.neocities.org%40bsky.brid.gy">@<span>orpach.neocities.org</span></a></span> <span><a href="/user/bagder%40mastodon.social">@<span>bagder</span></a></span> </p><p><a href="https://mastodon.social/tags/nixos" rel="tag">#<span>nixos</span></a> is somewhat of pioneer in the space of reproducible builds and is 20 years old</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/gonzo_askold/statuses/116566772985473139</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/gonzo_askold/statuses/116566772985473139</guid><dc:creator><![CDATA[gonzo_askold@mastodon.social]]></dc:creator><pubDate>Wed, 13 May 2026 10:23:20 GMT</pubDate></item></channel></rss>