[Bug 1230361] New: scap-security-guide: reproducible builds issue (date)
https://bugzilla.suse.com/show_bug.cgi?id=1230361 Bug ID: 1230361 Summary: scap-security-guide: reproducible builds issue (date) Classification: openSUSE Product: openSUSE Tumbleweed Version: Current Hardware: Other OS: All Status: NEW Severity: Normal Priority: P5 - None Component: Other Assignee: rumen.chikov@suse.com Reporter: bwiedemann@suse.com QA Contact: qa-bugs@suse.de CC: meissner@suse.com Blocks: 1047218 Target Milestone: --- Found By: Development Blocker: --- While working on reproducible builds for openSUSE, I found that our scap-security-guide varied in each build, even when varying as little as possible. This is because, there is a build date+time embedded in the output: --- old//usr/share/scap-security-guide/tailoring/rhel8_stig_delta_tailoring.xml 2024-09-02 13:58:51.000000000 +0000 +++ new//usr/share/scap-security-guide/tailoring/rhel8_stig_delta_tailoring.xml 2024-09-02 13:58:51.000000000 +0000 @@ -1,4 +1,4 @@ -<xccdf-1.2:Tailoring xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2" id="xccdf_content-disa-delta_tailoring_default"><xccdf-1.2:version time="2024-09-06T15:14:18.947277+00:00">1</xccdf-1.2:version><xccdf-1.2:Profile id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring" extends="xccdf_org.ssgproject.content_profile_stig"><xccdf-1.2:title override="true">DISA STIG for Red Hat Enterprise Linux 8</xccdf-1.2:title> +<xccdf-1.2:Tailoring xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2" id="xccdf_content-disa-delta_tailoring_default"><xccdf-1.2:version time="2024-09-06T15:15:45.696526+00:00">1</xccdf-1.2:version><xccdf-1.2:Profile id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring" extends="xccdf_org.ssgproject.content_profile_stig"><xccdf-1.2:title override="true">DISA STIG for Red Hat Enterprise Linux 8</xccdf-1.2:title> If timestamps cannot be dropped, they should use $SOURCE_DATE_EPOCH https://reproducible-builds.org/docs/source-date-epoch/ -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1230361 https://bugzilla.suse.com/show_bug.cgi?id=1230361#c1 --- Comment #1 from Bernhard Wiedemann <bwiedemann@suse.com> --- There is also a date embedded in various files: /usr/share/doc/scap-security-guide/guides/ssg-opensuse-guide-standard.html [...] <p>Current version: <strong>0.1.73</strong></p><ul><li><strong>draft</strong> - (as of 2024-06-04) + (as of 2040-07-06) -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1230361 https://bugzilla.suse.com/show_bug.cgi?id=1230361#c3 --- Comment #3 from Bernhard Wiedemann <bwiedemann@suse.com> --- There is still the same problem with 0.1.74 See the %build section in https://build.opensuse.org/projects/openSUSE:Factory/packages/scap-security-... for how we build it. -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1230361 https://bugzilla.suse.com/show_bug.cgi?id=1230361#c9 --- Comment #9 from OBSbugzilla Bot <bwiedemann+obsbugzillabot@suse.com> --- This is an autogenerated message for OBS integration: This bug (1230361) was mentioned in https://build.opensuse.org/request/show/1229844 Factory / scap-security-guide -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com