2019-02-13 23:14:00 +01:00
|
|
|
#!/bin/bash
|
|
|
|
#
|
2021-06-10 19:16:22 +02:00
|
|
|
# makerepropkg - rebuild a package to see if it is reproducible
|
2019-02-13 23:14:00 +01:00
|
|
|
#
|
2021-06-10 19:16:22 +02:00
|
|
|
# Copyright (c) 2019 by Eli Schwartz <eschwartz@archlinux.org>
|
2019-02-13 23:14:00 +01:00
|
|
|
#
|
2021-06-10 19:16:22 +02:00
|
|
|
# SPDX-License-Identifier: GPL-3.0-or-later
|
2019-02-13 23:14:00 +01:00
|
|
|
|
|
|
|
m4_include(lib/common.sh)
|
|
|
|
m4_include(lib/archroot.sh)
|
|
|
|
|
|
|
|
source /usr/share/makepkg/util/config.sh
|
|
|
|
source /usr/share/makepkg/util/message.sh
|
|
|
|
|
|
|
|
declare -A buildinfo
|
|
|
|
declare -a buildenv buildopts installed installpkgs
|
|
|
|
|
|
|
|
archiveurl='https://archive.archlinux.org/packages'
|
|
|
|
buildroot=/var/lib/archbuild/reproducible
|
2019-12-08 20:58:42 +01:00
|
|
|
diffoscope=0
|
2019-02-13 23:14:00 +01:00
|
|
|
|
2021-11-11 23:39:29 +01:00
|
|
|
chroot=$USER
|
|
|
|
[[ -n ${SUDO_USER:-} ]] && chroot=$SUDO_USER
|
|
|
|
[[ -z "$chroot" || $chroot = root ]] && chroot=copy
|
|
|
|
|
2019-02-13 23:14:00 +01:00
|
|
|
parse_buildinfo() {
|
|
|
|
local line var val
|
|
|
|
|
|
|
|
while read -r line; do
|
|
|
|
var="${line%% = *}"
|
|
|
|
val="${line#* = }"
|
|
|
|
case ${var} in
|
|
|
|
buildenv)
|
|
|
|
buildenv+=("${val}")
|
|
|
|
;;
|
|
|
|
options)
|
|
|
|
buildopts+=("${val}")
|
|
|
|
;;
|
|
|
|
installed)
|
|
|
|
installed+=("${val}")
|
|
|
|
;;
|
|
|
|
*)
|
|
|
|
buildinfo["${var}"]="${val}"
|
|
|
|
;;
|
|
|
|
esac
|
|
|
|
done
|
|
|
|
}
|
|
|
|
|
|
|
|
get_pkgfile() {
|
|
|
|
local cdir=${cache_dirs[0]}
|
|
|
|
local pkgfilebase=${1}
|
2020-05-25 01:32:38 +02:00
|
|
|
local mode=${2}
|
2019-02-13 23:14:00 +01:00
|
|
|
local pkgname=${pkgfilebase%-*-*-*}
|
|
|
|
local pkgfile ext
|
|
|
|
|
2020-05-25 01:32:38 +02:00
|
|
|
# try without downloading
|
|
|
|
if [[ ${mode} != localonly ]] && get_pkgfile "${pkgfilebase}" localonly; then
|
|
|
|
return 0
|
|
|
|
fi
|
|
|
|
|
2020-02-21 00:03:59 +01:00
|
|
|
for ext in .zst .xz ''; do
|
2019-02-13 23:14:00 +01:00
|
|
|
pkgfile=${pkgfilebase}.pkg.tar${ext}
|
|
|
|
|
|
|
|
for c in "${cache_dirs[@]}"; do
|
|
|
|
if [[ -f ${c}/${pkgfile} ]]; then
|
|
|
|
cdir=${c}
|
|
|
|
break
|
|
|
|
fi
|
|
|
|
done
|
|
|
|
|
|
|
|
for f in "${pkgfile}" "${pkgfile}.sig"; do
|
|
|
|
if [[ ! -f "${cdir}/${f}" ]]; then
|
2020-05-25 01:32:38 +02:00
|
|
|
if [[ ${mode} = localonly ]]; then
|
|
|
|
continue 2
|
|
|
|
fi
|
2019-02-13 23:14:00 +01:00
|
|
|
msg2 "retrieving '%s'..." "${f}" >&2
|
|
|
|
curl -Llf -# -o "${cdir}/${f}" "${archiveurl}/${pkgname:0:1}/${pkgname}/${f}" || continue 2
|
|
|
|
fi
|
|
|
|
done
|
|
|
|
printf '%s\n' "file://${cdir}/${pkgfile}"
|
|
|
|
return 0
|
|
|
|
done
|
|
|
|
|
|
|
|
return 1
|
|
|
|
}
|
|
|
|
|
2021-07-18 18:27:14 +02:00
|
|
|
get_makepkg_conf() {
|
|
|
|
local fname=${1}
|
2022-10-17 23:33:27 +02:00
|
|
|
local arch="${2}"
|
|
|
|
local makepkg_conf="${3}"
|
2021-07-18 18:27:14 +02:00
|
|
|
if ! buildtool_file=$(get_pkgfile "${fname}"); then
|
|
|
|
error "failed to retrieve ${fname}"
|
|
|
|
return 1
|
|
|
|
fi
|
|
|
|
msg2 "using makepkg.conf from ${fname}"
|
2022-10-17 23:33:27 +02:00
|
|
|
bsdtar xOqf "${buildtool_file/file:\/\//}" "usr/share/devtools/makepkg-${arch}.conf" > "${makepkg_conf}"
|
2021-07-18 18:27:14 +02:00
|
|
|
return 0
|
|
|
|
}
|
|
|
|
|
2019-02-13 23:14:00 +01:00
|
|
|
usage() {
|
|
|
|
cat << __EOF__
|
|
|
|
usage: ${BASH_SOURCE[0]##*/} [options] <package_file>
|
|
|
|
|
|
|
|
Run this script in a PKGBUILD dir to build a package inside a
|
|
|
|
clean chroot while attempting to reproduce it. The package file
|
|
|
|
will be used to derive metadata needed for reproducing the
|
|
|
|
package, including the .PKGINFO as well as the buildinfo.
|
|
|
|
|
|
|
|
For more details see https://reproducible-builds.org/
|
|
|
|
|
|
|
|
OPTIONS
|
2019-12-08 20:58:42 +01:00
|
|
|
-d Run diffoscope if the package is unreproducible
|
2019-02-13 23:14:00 +01:00
|
|
|
-c <dir> Set pacman cache
|
|
|
|
-M <file> Location of a makepkg config file
|
2021-11-11 23:39:29 +01:00
|
|
|
-l <chroot> The directory name to use as the chroot namespace
|
|
|
|
Useful for maintaining multiple copies
|
|
|
|
Default: $chroot
|
2019-02-13 23:14:00 +01:00
|
|
|
-h Show this usage message
|
|
|
|
__EOF__
|
|
|
|
}
|
|
|
|
|
2021-11-11 23:39:29 +01:00
|
|
|
while getopts 'dM:c:l:h' arg; do
|
2019-12-08 20:46:10 +01:00
|
|
|
case "$arg" in
|
2019-12-08 20:58:42 +01:00
|
|
|
d) diffoscope=1 ;;
|
2019-12-08 20:46:10 +01:00
|
|
|
M) archroot_args+=(-M "$OPTARG") ;;
|
|
|
|
c) cache_dirs+=("$OPTARG") ;;
|
2021-11-11 23:39:29 +01:00
|
|
|
l) chroot="$OPTARG" ;;
|
2019-12-08 20:46:10 +01:00
|
|
|
h) usage; exit 0 ;;
|
|
|
|
*|?) usage; exit 1 ;;
|
|
|
|
esac
|
2019-02-13 23:14:00 +01:00
|
|
|
done
|
|
|
|
shift $((OPTIND - 1))
|
|
|
|
|
|
|
|
check_root
|
|
|
|
|
2020-06-08 21:13:41 +02:00
|
|
|
[[ -f PKGBUILD ]] || { error "No PKGBUILD in current directory."; exit 1; }
|
|
|
|
|
|
|
|
# without arguments, get list of packages from PKGBUILD
|
|
|
|
if [[ -z $1 ]]; then
|
|
|
|
mapfile -t pkgnames < <(source PKGBUILD; pacman -Sddp --print-format '%r/%n' "${pkgname[@]}")
|
|
|
|
wait $! || {
|
|
|
|
error "No package file specified and failed to retrieve package names from './PKGBUILD'."
|
|
|
|
plain "Try '${BASH_SOURCE[0]##*/} -h' for more information." >&2
|
|
|
|
exit 1
|
|
|
|
}
|
|
|
|
msg "Reproducing all pkgnames listed in ./PKGBUILD"
|
|
|
|
set -- "${pkgnames[@]}"
|
2019-02-13 23:14:00 +01:00
|
|
|
fi
|
|
|
|
|
2020-06-08 21:13:41 +02:00
|
|
|
# check each package to see if it's a file, and if not, try to download it
|
|
|
|
# using pacman -Sw, and get the filename from there
|
|
|
|
splitpkgs=()
|
|
|
|
for p in "$@"; do
|
|
|
|
if [[ -f ${p} ]]; then
|
|
|
|
splitpkgs+=("${p}")
|
|
|
|
else
|
|
|
|
pkgfile_remote=$(pacman -Sddp "${p}" 2>/dev/null) || { error "package name '%s' not in repos" "${p}"; exit 1; }
|
|
|
|
pkgfile=${pkgfile_remote#file://}
|
|
|
|
if [[ ! -f ${pkgfile} ]]; then
|
|
|
|
msg "Downloading package '%s' into pacman's cache" "${pkgfile}"
|
|
|
|
sudo pacman -Swdd --noconfirm --logfile /dev/null "${p}" || exit 1
|
|
|
|
pkgfile_remote=$(pacman -Sddp "${p}" 2>/dev/null)
|
|
|
|
pkgfile="${pkgfile_remote#file://}"
|
|
|
|
fi
|
|
|
|
splitpkgs+=("${pkgfile}")
|
|
|
|
fi
|
|
|
|
done
|
|
|
|
|
|
|
|
for f in "${splitpkgs[@]}"; do
|
|
|
|
if ! bsdtar -tqf "${f}" .BUILDINFO >/dev/null 2>&1; then
|
|
|
|
error "file is not a valid pacman package: '%s'" "${f}"
|
|
|
|
exit 1
|
|
|
|
fi
|
|
|
|
done
|
|
|
|
|
2019-02-13 23:14:00 +01:00
|
|
|
if (( ${#cache_dirs[@]} == 0 )); then
|
|
|
|
mapfile -t cache_dirs < <(pacman-conf CacheDir)
|
|
|
|
fi
|
|
|
|
|
|
|
|
ORIG_HOME=${HOME}
|
|
|
|
IFS=: read -r _ _ _ _ _ HOME _ < <(getent passwd "${SUDO_USER:-$USER}")
|
|
|
|
load_makepkg_config
|
|
|
|
HOME=${ORIG_HOME}
|
|
|
|
[[ -d ${SRCDEST} ]] || SRCDEST=${PWD}
|
|
|
|
|
2020-06-08 21:13:41 +02:00
|
|
|
parse_buildinfo < <(bsdtar -xOqf "${splitpkgs[0]}" .BUILDINFO)
|
2019-02-13 23:14:00 +01:00
|
|
|
export SOURCE_DATE_EPOCH="${buildinfo[builddate]}"
|
|
|
|
PACKAGER="${buildinfo[packager]}"
|
|
|
|
BUILDDIR="${buildinfo[builddir]}"
|
2021-06-21 20:46:16 +02:00
|
|
|
BUILDTOOL="${buildinfo[buildtool]}"
|
|
|
|
BUILDTOOLVER="${buildinfo[buildtoolver]}"
|
2020-06-08 21:13:41 +02:00
|
|
|
PKGEXT=${splitpkgs[0]#${splitpkgs[0]%.pkg.tar*}}
|
2019-02-13 23:14:00 +01:00
|
|
|
|
|
|
|
# nuke and restore reproducible testenv
|
2021-11-11 23:39:29 +01:00
|
|
|
namespace="$buildroot/$chroot"
|
|
|
|
lock 9 "${namespace}.lock" "Locking chroot namespace '%s'" "${namespace}"
|
|
|
|
for copy in "${namespace}"/*/; do
|
2019-02-13 23:14:00 +01:00
|
|
|
[[ -d ${copy} ]] || continue
|
|
|
|
subvolume_delete_recursive "${copy}"
|
|
|
|
done
|
2021-11-11 23:39:29 +01:00
|
|
|
rm -rf --one-file-system "${namespace}"
|
|
|
|
(umask 0022; mkdir -p "${namespace}")
|
2019-02-13 23:14:00 +01:00
|
|
|
|
|
|
|
for fname in "${installed[@]}"; do
|
|
|
|
if ! allpkgfiles+=("$(get_pkgfile "${fname}")"); then
|
|
|
|
error "failed to retrieve ${fname}"
|
|
|
|
exit 1
|
|
|
|
fi
|
|
|
|
done
|
2021-07-18 18:27:14 +02:00
|
|
|
|
|
|
|
trap 'rm -rf $TEMPDIR' EXIT INT TERM QUIT
|
|
|
|
TEMPDIR=$(mktemp -d --tmpdir makerepropkg.XXXXXXXXXX)
|
|
|
|
|
|
|
|
makepkg_conf="${TEMPDIR}/makepkg.conf"
|
|
|
|
# anything before buildtool support is pinned to the last none buildtool aware release
|
|
|
|
if [[ -z "${BUILDTOOL}" ]]; then
|
2022-10-17 23:33:27 +02:00
|
|
|
get_makepkg_conf "devtools-20210202-3-any" "${CARCH}" "${makepkg_conf}" || exit 1
|
2021-07-18 18:27:14 +02:00
|
|
|
# prefere to assume devtools up until matching makepkg version so repository packages remain reproducible
|
|
|
|
elif [[ "${BUILDTOOL}" = makepkg ]] && (( $(vercmp "${BUILDTOOLVER}" 6.0.1) <= 0 )); then
|
2022-10-17 23:33:27 +02:00
|
|
|
get_makepkg_conf "devtools-20210202-3-any" "${CARCH}" "${makepkg_conf}" || exit 1
|
2021-07-18 18:27:14 +02:00
|
|
|
# all devtools builds
|
2022-10-17 23:33:27 +02:00
|
|
|
elif [[ "${BUILDTOOL}" = devtools ]] && get_makepkg_conf "${BUILDTOOL}-${BUILDTOOLVER}" "${CARCH}" "${makepkg_conf}"; then
|
2021-07-18 18:27:14 +02:00
|
|
|
true
|
|
|
|
# fallback to current makepkg.conf
|
|
|
|
else
|
|
|
|
warning "Unknown buildtool (${BUILDTOOL}-${BUILDTOOLVER}), using fallback"
|
2022-10-17 23:33:27 +02:00
|
|
|
makepkg_conf=@pkgdatadir@/makepkg-${CARCH}.conf
|
2021-07-18 18:27:14 +02:00
|
|
|
fi
|
2021-11-11 23:39:29 +01:00
|
|
|
printf '%s\n' "${allpkgfiles[@]}" | mkarchroot -M "${makepkg_conf}" -U "${archroot_args[@]}" "${namespace}/root" - || exit 1
|
2019-02-13 23:14:00 +01:00
|
|
|
|
|
|
|
# use makechrootpkg to prep the build directory
|
2021-11-11 23:39:29 +01:00
|
|
|
makechrootpkg -r "${namespace}" -l build -- --packagelist || exit 1
|
2019-02-13 23:14:00 +01:00
|
|
|
|
|
|
|
# set detected makepkg.conf options
|
|
|
|
{
|
2021-06-21 20:46:16 +02:00
|
|
|
for var in PACKAGER BUILDDIR BUILDTOOL BUILDTOOLVER PKGEXT; do
|
2019-02-13 23:14:00 +01:00
|
|
|
printf '%s=%s\n' "${var}" "${!var@Q}"
|
|
|
|
done
|
|
|
|
printf 'OPTIONS=(%s)\n' "${buildopts[*]@Q}"
|
|
|
|
printf 'BUILDENV=(%s)\n' "${buildenv[*]@Q}"
|
2021-11-11 23:39:29 +01:00
|
|
|
} >> "${namespace}/build"/etc/makepkg.conf
|
|
|
|
install -d -o "${SUDO_UID:-$UID}" -g "$(id -g "${SUDO_UID:-$UID}")" "${namespace}/build/${BUILDDIR}"
|
2019-02-13 23:14:00 +01:00
|
|
|
|
|
|
|
# kick off the build
|
2021-11-11 23:39:29 +01:00
|
|
|
arch-nspawn "${namespace}/build" \
|
2019-02-13 23:14:00 +01:00
|
|
|
--bind="${PWD}:/startdir" \
|
|
|
|
--bind="${SRCDEST}:/srcdest" \
|
|
|
|
/chrootbuild -C --noconfirm --log --holdver --skipinteg
|
2019-12-08 21:07:00 +01:00
|
|
|
ret=$?
|
2019-02-13 23:14:00 +01:00
|
|
|
|
2019-12-08 21:07:00 +01:00
|
|
|
if (( ${ret} == 0 )); then
|
2021-11-11 23:39:29 +01:00
|
|
|
msg2 "built succeeded! built packages can be found in ${namespace}/build/pkgdest"
|
2019-02-13 23:14:00 +01:00
|
|
|
msg "comparing artifacts..."
|
2019-12-08 20:58:42 +01:00
|
|
|
|
2019-12-08 21:07:00 +01:00
|
|
|
for pkgfile in "${splitpkgs[@]}"; do
|
2021-11-11 23:39:29 +01:00
|
|
|
comparefiles=("${pkgfile}" "${namespace}/build/pkgdest/${pkgfile##*/}")
|
2019-12-08 21:07:00 +01:00
|
|
|
if cmp -s "${comparefiles[@]}"; then
|
|
|
|
msg2 "Package '%s' successfully reproduced!" "${pkgfile}"
|
|
|
|
else
|
|
|
|
ret=1
|
|
|
|
warning "Package '%s' is not reproducible. :(" "${pkgfile}"
|
|
|
|
sha256sum "${comparefiles[@]}"
|
|
|
|
if (( diffoscope )); then
|
|
|
|
diffoscope "${comparefiles[@]}"
|
|
|
|
fi
|
2019-12-08 20:58:42 +01:00
|
|
|
fi
|
2019-12-08 21:07:00 +01:00
|
|
|
done
|
2019-02-13 23:14:00 +01:00
|
|
|
fi
|
|
|
|
|
2019-12-08 21:07:00 +01:00
|
|
|
# return failure from chrootbuild, or the reproducibility status
|
|
|
|
exit ${ret}
|