mbox

[bug#35511,0/1] Add configure flag to emacs to improve repoducibility

Message ID 20190430212805.3252-1-jessejohngildersleve@zohomail.eu
Headers show

Message

wednesday April 30, 2019, 9:28 p.m. UTC
This patch adds the --disable-build-details configure-flag to the emacs package.
By default the emacs binary stores some information about how it was build, as
stated here:
"By default the dumped emacs executable records details such as the build time and host name. Use the --disable-build-details option of configure to suppress these details, so that building and installing Emacs twice from the same sources is more likely to result in identical copies of Emacs."
https://www.gnu.org/software/emacs/manual/html_node/elisp/Building-Emacs.html

There is also this mailing list post about emacs repoducibility:
https://lists.gnu.org/archive/html/emacs-devel/2016-11/msg00711.html

wednesday (1):
  gnu: emacs: Make build more reproducible

 gnu/packages/emacs.scm | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

Comments

Nils Gillmann May 4, 2019, 4:53 p.m. UTC | #1
wednesday transcribed 853 bytes:
> This patch adds the --disable-build-details configure-flag to the emacs package.
> By default the emacs binary stores some information about how it was build, as
> stated here:
> "By default the dumped emacs executable records details such as the build time and host name. Use the --disable-build-details option of configure to suppress these details, so that building and installing Emacs twice from the same sources is more likely to result in identical copies of Emacs."
> https://www.gnu.org/software/emacs/manual/html_node/elisp/Building-Emacs.html
> 
> There is also this mailing list post about emacs repoducibility:
> https://lists.gnu.org/archive/html/emacs-devel/2016-11/msg00711.html

This email states:
# The configuration option --disable-build-details can be used to omit some information, such as build host name, which make the build not reproducible across machines.

There is either a typo (not reproducible -> reproducible?) or this should not be used.

searching in the tip of emacs, because they are really vague about the option
gives away more details:

 /* Set system-name to nil so that the build is deterministic.  */

Then there's some more info in related commits, such as setting build time
to nil.

If we have nil instead of the time of our environment, this won't really add
any value.
When the time is epoch+1 or similar anyway, recording it does no harm.

Furthermore we reset the system name to localhost (at least when guix still
follows nix in that regard), so we end up with "localhost" in the build
recorded somewhere.

This, and some follow-up commits which fixed errors related to this, is everything
I can find on the details.

I'm not even sure if this makes sense in PMs where your environment does not default
to being reset and readjusted in a chroot, as you can still have chrooted automatic
builds for batch building, and then you end up with this mixture (I was about to
apply this for pkgsrc until I went and read into the code).

Imo there's no need for this switch in guix.
 
> wednesday (1):
>   gnu: emacs: Make build more reproducible
> 
>  gnu/packages/emacs.scm | 3 ++-
>  1 file changed, 2 insertions(+), 1 deletion(-)
> 
> -- 
> 2.21.0
> 
> 
> 
> 
> 
>
Tobias Geerinckx-Rice May 4, 2019, 11:51 p.m. UTC | #2
ng0@n0.is wrote:
> This email states:
> # The configuration option --disable-build-details can be used 
> to omit some information, such as build host name, which make 
> the build not reproducible across machines.
>
> There is either a typo (not reproducible -> reproducible?) or 
> this should not be used.

I think the original e-mail is correct: ‘the information … make[s] 
the build not reproducible’.  The option can't be the subject 
here.

> If we have nil instead of the time of our environment, this 
> won't really add
> any value.
> When the time is epoch+1 or similar anyway, recording it does no 
> harm.

The time in our environment isn't reproducible AFAIK.

Kind regards,

T G-R
Ludovic Courtès May 21, 2019, 8:50 p.m. UTC | #3
Hi wednesday,

wednesday <jessejohngildersleve@zohomail.eu> skribis:

> This patch adds the --disable-build-details configure-flag to the emacs package.
> By default the emacs binary stores some information about how it was build, as
> stated here:
> "By default the dumped emacs executable records details such as the build time and host name. Use the --disable-build-details option of configure to suppress these details, so that building and installing Emacs twice from the same sources is more likely to result in identical copies of Emacs."
> https://www.gnu.org/software/emacs/manual/html_node/elisp/Building-Emacs.html
>
> There is also this mailing list post about emacs repoducibility:
> https://lists.gnu.org/archive/html/emacs-devel/2016-11/msg00711.html

This is the right thing to do, applied!

I’m committing a followup that does the same for ‘emacs-minimal’ (even
though ‘emacs-minimal’ has 784 dependent packages, I’m committing to
‘master’ because most of these build in a few seconds.)

I’ve run:

  guix challenge emacs \
    --substitute-urls='https://mirror.hydra.gnu.org https://berlin.guix.gnu.org'

on a commit before this patch, and there’s the ‘.emacs-real’ binary
alongside a dozen of .elc files that differ.  So this may not be the end
of the road, but we should keep monitoring with ‘challenge’ and ‘--check’.

Thank you!

Ludo’.