Diff of the two buildlogs: -- --- b1/build.log 2025-03-16 04:52:56.794525049 +0000 +++ b2/build.log 2025-03-16 04:55:46.462895296 +0000 @@ -1,6 +1,6 @@ I: pbuilder: network access will be disabled during build -I: Current time: Fri Apr 17 23:11:33 -12 2026 -I: pbuilder-time-stamp: 1776510693 +I: Current time: Sun Mar 16 18:52:59 +14 2025 +I: pbuilder-time-stamp: 1742100779 I: Building the build Environment I: extracting base tarball [/var/cache/pbuilder/trixie-reproducible-base.tgz] I: copying local configuration @@ -25,52 +25,84 @@ dpkg-source: info: applying disable-tests-that-download.patch I: Not using root during the build. I: Installing the build-deps -I: user script /srv/workspace/pbuilder/725686/tmp/hooks/D02_print_environment starting +I: user script /srv/workspace/pbuilder/2931246/tmp/hooks/D01_modify_environment starting +debug: Running on codethink04-arm64. +I: Changing host+domainname to test build reproducibility +I: Adding a custom variable just for the fun of it... +I: Changing /bin/sh to bash +'/bin/sh' -> '/bin/bash' +lrwxrwxrwx 1 root root 9 Mar 16 04:53 /bin/sh -> /bin/bash +I: Setting pbuilder2's login shell to /bin/bash +I: Setting pbuilder2's GECOS to second user,second room,second work-phone,second home-phone,second other +I: user script /srv/workspace/pbuilder/2931246/tmp/hooks/D01_modify_environment finished +I: user script /srv/workspace/pbuilder/2931246/tmp/hooks/D02_print_environment starting I: set - BUILDDIR='/build/reproducible-path' - BUILDUSERGECOS='first user,first room,first work-phone,first home-phone,first other' - BUILDUSERNAME='pbuilder1' - BUILD_ARCH='arm64' - DEBIAN_FRONTEND='noninteractive' + BASH=/bin/sh + BASHOPTS=checkwinsize:cmdhist:complete_fullquote:extquote:force_fignore:globasciiranges:globskipdots:hostcomplete:interactive_comments:patsub_replacement:progcomp:promptvars:sourcepath + BASH_ALIASES=() + BASH_ARGC=() + BASH_ARGV=() + BASH_CMDS=() + BASH_LINENO=([0]="12" [1]="0") + BASH_LOADABLES_PATH=/usr/local/lib/bash:/usr/lib/bash:/opt/local/lib/bash:/usr/pkg/lib/bash:/opt/pkg/lib/bash:. + BASH_SOURCE=([0]="/tmp/hooks/D02_print_environment" [1]="/tmp/hooks/D02_print_environment") + BASH_VERSINFO=([0]="5" [1]="2" [2]="37" [3]="1" [4]="release" [5]="aarch64-unknown-linux-gnu") + BASH_VERSION='5.2.37(1)-release' + BUILDDIR=/build/reproducible-path + BUILDUSERGECOS='second user,second room,second work-phone,second home-phone,second other' + BUILDUSERNAME=pbuilder2 + BUILD_ARCH=arm64 + DEBIAN_FRONTEND=noninteractive DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=12 ' - DISTRIBUTION='trixie' - HOME='/root' - HOST_ARCH='arm64' + DIRSTACK=() + DISTRIBUTION=trixie + EUID=0 + FUNCNAME=([0]="Echo" [1]="main") + GROUPS=() + HOME=/root + HOSTNAME=i-capture-the-hostname + HOSTTYPE=aarch64 + HOST_ARCH=arm64 IFS=' ' - INVOCATION_ID='f9b63e721fd74e7da5296c64bcafdbac' - LANG='C' - LANGUAGE='en_US:en' - LC_ALL='C' - MAIL='/var/mail/root' - OPTIND='1' - PATH='/usr/sbin:/usr/bin:/sbin:/bin:/usr/games' - PBCURRENTCOMMANDLINEOPERATION='build' - PBUILDER_OPERATION='build' - PBUILDER_PKGDATADIR='/usr/share/pbuilder' - PBUILDER_PKGLIBDIR='/usr/lib/pbuilder' - PBUILDER_SYSCONFDIR='/etc' - PPID='725686' - PS1='# ' - PS2='> ' + INVOCATION_ID=ce5c57aadf0c4ea6a3382f4848c3b73b + LANG=C + LANGUAGE=nl_BE:nl + LC_ALL=C + MACHTYPE=aarch64-unknown-linux-gnu + MAIL=/var/mail/root + OPTERR=1 + OPTIND=1 + OSTYPE=linux-gnu + PATH=/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path + PBCURRENTCOMMANDLINEOPERATION=build + PBUILDER_OPERATION=build + PBUILDER_PKGDATADIR=/usr/share/pbuilder + PBUILDER_PKGLIBDIR=/usr/lib/pbuilder + PBUILDER_SYSCONFDIR=/etc + PIPESTATUS=([0]="0") + POSIXLY_CORRECT=y + PPID=2931246 PS4='+ ' - PWD='/' - SHELL='/bin/bash' - SHLVL='2' - SUDO_COMMAND='/usr/bin/timeout -k 18.1h 18h /usr/bin/ionice -c 3 /usr/bin/nice /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.hdLVcN2p/pbuilderrc_ss43 --distribution trixie --hookdir /etc/pbuilder/first-build-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/trixie-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.hdLVcN2p/b1 --logfile b1/build.log golang-github-sigstore-sigstore_1.8.12-1.dsc' - SUDO_GID='109' - SUDO_UID='104' - SUDO_USER='jenkins' - TERM='unknown' - TZ='/usr/share/zoneinfo/Etc/GMT+12' - USER='root' - _='/usr/bin/systemd-run' - http_proxy='http://192.168.101.4:3128' + PWD=/ + SHELL=/bin/bash + SHELLOPTS=braceexpand:errexit:hashall:interactive-comments:posix + SHLVL=3 + SUDO_COMMAND='/usr/bin/timeout -k 24.1h 24h /usr/bin/ionice -c 3 /usr/bin/nice -n 11 /usr/bin/unshare --uts -- /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.hdLVcN2p/pbuilderrc_NO45 --distribution trixie --hookdir /etc/pbuilder/rebuild-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/trixie-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.hdLVcN2p/b2 --logfile b2/build.log golang-github-sigstore-sigstore_1.8.12-1.dsc' + SUDO_GID=109 + SUDO_UID=104 + SUDO_USER=jenkins + TERM=unknown + TZ=/usr/share/zoneinfo/Etc/GMT-14 + UID=0 + USER=root + _='I: set' + http_proxy=http://192.168.101.4:3128 I: uname -a - Linux codethink03-arm64 6.1.0-32-cloud-arm64 #1 SMP Debian 6.1.129-1 (2025-03-06) aarch64 GNU/Linux + Linux i-capture-the-hostname 6.1.0-32-cloud-arm64 #1 SMP Debian 6.1.129-1 (2025-03-06) aarch64 GNU/Linux I: ls -l /bin - lrwxrwxrwx 1 root root 7 Mar 4 2025 /bin -> usr/bin -I: user script /srv/workspace/pbuilder/725686/tmp/hooks/D02_print_environment finished + lrwxrwxrwx 1 root root 7 Mar 4 11:20 /bin -> usr/bin +I: user script /srv/workspace/pbuilder/2931246/tmp/hooks/D02_print_environment finished -> Attempting to satisfy build-dependencies -> Creating pbuilder-satisfydepends-dummy package Package: pbuilder-satisfydepends-dummy @@ -630,7 +662,7 @@ Get: 472 http://deb.debian.org/debian trixie/main arm64 golang-github-skratchdot-open-golang-dev all 0.0~git20160302.0.75fb7ed-2.1 [4156 B] Get: 473 http://deb.debian.org/debian trixie/main arm64 golang-github-theupdateframework-go-tuf-dev all 2.0.2+0.7.0-1 [200 kB] Get: 474 http://deb.debian.org/debian trixie/main arm64 golang-github-sigstore-sigstore-dev all 1.8.12-1 [94.2 kB] -Fetched 230 MB in 2s (129 MB/s) +Fetched 230 MB in 1s (177 MB/s) Preconfiguring packages ... Selecting previously unselected package golang-golang-x-sys-dev. (Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 19917 files and directories currently installed.) @@ -2152,8 +2184,8 @@ Setting up tzdata (2025a-2) ... Current default time zone: 'Etc/UTC' -Local time is now: Sat Apr 18 11:14:02 UTC 2026. -Universal Time is now: Sat Apr 18 11:14:02 UTC 2026. +Local time is now: Sun Mar 16 04:54:25 UTC 2025. +Universal Time is now: Sun Mar 16 04:54:25 UTC 2025. Run 'dpkg-reconfigure tzdata' if you wish to change it. Setting up golang-github-coreos-go-semver-dev (0.3.0-1) ... @@ -2547,7 +2579,11 @@ Building tag database... -> Finished parsing the build-deps I: Building the package -I: Running cd /build/reproducible-path/golang-github-sigstore-sigstore-1.8.12/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-genchanges -S > ../golang-github-sigstore-sigstore_1.8.12-1_source.changes +I: user script /srv/workspace/pbuilder/2931246/tmp/hooks/A99_set_merged_usr starting +Not re-configuring usrmerge for trixie +I: user script /srv/workspace/pbuilder/2931246/tmp/hooks/A99_set_merged_usr finished +hostname: Name or service not known +I: Running cd /build/reproducible-path/golang-github-sigstore-sigstore-1.8.12/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-genchanges -S > ../golang-github-sigstore-sigstore_1.8.12-1_source.changes dpkg-buildpackage: info: source package golang-github-sigstore-sigstore dpkg-buildpackage: info: source version 1.8.12-1 dpkg-buildpackage: info: source distribution unstable @@ -2575,33 +2611,33 @@ make[1]: Leaving directory '/build/reproducible-path/golang-github-sigstore-sigstore-1.8.12' dh_auto_build -O--builddirectory=_build -O--buildsystem=golang cd _build && go install -trimpath -v -p 12 github.com/sigstore/sigstore/pkg/cryptoutils github.com/sigstore/sigstore/pkg/fulcioroots github.com/sigstore/sigstore/pkg/oauth github.com/sigstore/sigstore/pkg/oauth/internal github.com/sigstore/sigstore/pkg/oauth/oidc github.com/sigstore/sigstore/pkg/oauthflow github.com/sigstore/sigstore/pkg/signature github.com/sigstore/sigstore/pkg/signature/dsse github.com/sigstore/sigstore/pkg/signature/kms github.com/sigstore/sigstore/pkg/signature/kms/aws github.com/sigstore/sigstore/pkg/signature/kms/fake github.com/sigstore/sigstore/pkg/signature/options github.com/sigstore/sigstore/pkg/signature/payload github.com/sigstore/sigstore/pkg/signature/ssh github.com/sigstore/sigstore/pkg/tuf github.com/sigstore/sigstore/test -internal/msan -internal/goexperiment +internal/profilerecord +internal/unsafeheader +internal/goos internal/coverage/rtcov +internal/godebugs +internal/goexperiment internal/goarch -internal/goos +internal/msan internal/byteorder internal/asan -internal/profilerecord -internal/unsafeheader -internal/godebugs -internal/runtime/math -internal/cpu internal/runtime/syscall math/bits unicode -internal/chacha8rand +internal/cpu unicode/utf8 crypto/internal/fips140/alias -crypto/internal/fips140deps/byteorder -sync/atomic -internal/abi internal/itoa +internal/runtime/math +internal/abi cmp +sync/atomic +internal/chacha8rand crypto/internal/fips140/subtle +crypto/internal/fips140deps/byteorder crypto/internal/boring/sig -math unicode/utf16 +math vendor/golang.org/x/crypto/cryptobyte/asn1 internal/nettrace encoding @@ -2611,22 +2647,22 @@ log/internal container/list vendor/golang.org/x/crypto/internal/alias +github.com/aws/aws-sdk-go-v2/internal/sdkio internal/bytealg internal/runtime/atomic internal/runtime/sys crypto/internal/fips140deps/cpu -github.com/aws/aws-sdk-go-v2/internal/sdkio internal/runtime/exithook -internal/stringslite internal/race -internal/runtime/maps +internal/stringslite internal/sync +internal/runtime/maps runtime internal/reflectlite +sync iter crypto/subtle weak -sync slices maps internal/bisect @@ -2634,29 +2670,29 @@ internal/singleflight unique runtime/cgo -errors sort +errors internal/godebug io strconv -bytes -vendor/golang.org/x/net/dns/dnsmessage -math/rand/v2 -path -crypto/internal/fips140deps/godebug -strings internal/oserror +path +math/rand/v2 +vendor/golang.org/x/net/dns/dnsmessage +syscall +bytes hash +crypto/internal/fips140deps/godebug crypto -syscall -reflect -net/netip math/rand -github.com/aws/smithy-go/transport/http/internal/io -hash/crc32 +strings +crypto/internal/randutil golang.org/x/crypto/blowfish +net/netip +reflect +hash/crc32 +github.com/aws/smithy-go/transport/http/internal/io container/heap -crypto/internal/randutil vendor/golang.org/x/text/transform github.com/syndtr/goleveldb/leveldb/comparer github.com/aws/smithy-go/io @@ -2666,167 +2702,167 @@ github.com/theupdateframework/go-tuf/v0/internal/roles bufio net/http/internal/ascii +net/http/internal/testcert +github.com/aws/aws-sdk-go-v2/internal/strings +time +internal/syscall/unix +internal/syscall/execenv crypto/internal/fips140/sha256 crypto/internal/fips140/sha3 crypto/internal/fips140/sha512 crypto/tls/internal/fips140tls -net/http/internal/testcert -github.com/aws/aws-sdk-go-v2/internal/strings crypto/sha3 -crypto/internal/fips140/hmac crypto/internal/fips140hash +crypto/internal/fips140/hmac +regexp crypto/internal/fips140/check crypto/internal/fips140/aes crypto/internal/fips140/nistec/fiat crypto/internal/fips140/edwards25519/field -crypto/internal/fips140/bigmod crypto/internal/fips140/hkdf crypto/internal/fips140/tls12 -regexp +crypto/internal/fips140/bigmod crypto/internal/fips140/tls13 -crypto/internal/fips140/edwards25519 -internal/syscall/unix -time -internal/syscall/execenv -crypto/internal/fips140/nistec io/fs internal/poll +github.com/aws/smithy-go/ptr context +crypto/internal/fips140/edwards25519 github.com/aws/aws-sdk-go-v2/internal/timeconv -github.com/aws/smithy-go/ptr -internal/fmtsort -encoding/binary -github.com/aws/aws-sdk-go-v2/internal/sdk -github.com/aws/smithy-go/context internal/filepathlite embed +github.com/aws/aws-sdk-go-v2/internal/sdk +github.com/aws/smithy-go/context os -encoding/base64 -golang.org/x/crypto/internal/poly1305 -vendor/golang.org/x/crypto/internal/poly1305 -github.com/golang/snappy -golang.org/x/sys/unix -golang.org/x/crypto/nacl/secretbox -encoding/pem -crypto/internal/sysrand -fmt +crypto/internal/fips140/nistec +internal/fmtsort +encoding/binary path/filepath golang.org/x/sys/cpu io/ioutil -net +fmt +crypto/internal/sysrand internal/sysinfo crypto/internal/entropy crypto/internal/fips140/drbg crypto/internal/fips140/aes/gcm crypto/internal/fips140only -crypto/internal/fips140/ecdh -crypto/internal/fips140/ecdsa -crypto/internal/fips140/ed25519 crypto/internal/fips140/rsa -os/exec crypto/internal/fips140/mlkem -golang.org/x/crypto/sha3 +crypto/internal/fips140/ed25519 +os/exec +crypto/internal/fips140/ecdh +crypto/internal/fips140/ecdsa crypto/md5 crypto/rc4 +encoding/base64 +golang.org/x/crypto/internal/poly1305 +golang.org/x/sys/unix +golang.org/x/crypto/sha3 +golang.org/x/crypto/nacl/secretbox +encoding/pem crypto/cipher +vendor/golang.org/x/crypto/internal/poly1305 +github.com/golang/snappy +net crypto/internal/boring crypto/des +github.com/skratchdot/open-golang/open vendor/golang.org/x/crypto/chacha20 golang.org/x/crypto/chacha20 -math/big encoding/hex -github.com/opencontainers/go-digest +net/url encoding/json crypto/ecdh -net/url +math/big crypto/sha512 crypto/sha1 crypto/aes crypto/sha256 crypto/hmac +github.com/opencontainers/go-digest github.com/theupdateframework/go-tuf/v0/internal/fsutil log golang.org/x/crypto/pbkdf2 compress/flate +vendor/golang.org/x/crypto/chacha20poly1305 vendor/golang.org/x/text/unicode/norm vendor/golang.org/x/net/http2/hpack golang.org/x/crypto/scrypt -vendor/golang.org/x/crypto/chacha20poly1305 mime mime/quotedprintable net/http/internal github.com/syndtr/goleveldb/leveldb/util github.com/syndtr/goleveldb/leveldb/storage -flag vendor/golang.org/x/text/unicode/bidi -github.com/syndtr/goleveldb/leveldb/cache -github.com/syndtr/goleveldb/leveldb/filter +flag runtime/debug compress/gzip -golang.org/x/term -github.com/syndtr/goleveldb/leveldb/opt +github.com/syndtr/goleveldb/leveldb/cache +github.com/syndtr/goleveldb/leveldb/filter runtime/trace +github.com/syndtr/goleveldb/leveldb/opt text/template/parse -gopkg.in/square/go-jose.v2/json vendor/golang.org/x/text/secure/bidirule +gopkg.in/square/go-jose.v2/json github.com/pkg/browser +testing database/sql/driver github.com/go-jose/go-jose/v3/json -github.com/skratchdot/open-golang/open -github.com/syndtr/goleveldb/leveldb/errors -testing golang.org/x/crypto/curve25519 +github.com/syndtr/goleveldb/leveldb/errors golang.org/x/crypto/ssh/internal/bcrypt_pbkdf +github.com/aws/aws-sdk-go-v2/internal/sync/singleflight github.com/syndtr/goleveldb/leveldb/iterator github.com/syndtr/goleveldb/leveldb/journal -github.com/aws/aws-sdk-go-v2/internal/sync/singleflight +github.com/secure-systems-lab/go-securesystemslib/cjson github.com/aws/smithy-go/internal/sync/singleflight github.com/aws/smithy-go/logging -github.com/secure-systems-lab/go-securesystemslib/cjson +github.com/aws/smithy-go/middleware +vendor/golang.org/x/net/idna github.com/aws/smithy-go github.com/syndtr/goleveldb/leveldb/memdb +github.com/theupdateframework/go-tuf/v0/data github.com/syndtr/goleveldb/leveldb/table -github.com/aws/smithy-go/middleware -vendor/golang.org/x/net/idna -github.com/aws/aws-sdk-go-v2/aws/ratelimit github.com/aws/smithy-go/auth -github.com/theupdateframework/go-tuf/v0/data -github.com/aws/aws-sdk-go-v2/feature/ec2/imds/internal/config -os/user -github.com/aws/aws-sdk-go-v2/aws/protocol/restjson github.com/theupdateframework/go-tuf/v0/util crypto/elliptic crypto/internal/boring/bbig encoding/asn1 crypto/rand crypto/dsa +text/template crypto/ed25519 crypto/rsa github.com/secure-systems-lab/go-securesystemslib/encrypted crypto/internal/hpke github.com/syndtr/goleveldb/leveldb -text/template +golang.org/x/term golang.org/x/crypto/ed25519 github.com/segmentio/ksuid github.com/aws/aws-sdk-go-v2/internal/rand github.com/aws/smithy-go/time github.com/aws/smithy-go/rand github.com/aws/aws-sdk-go-v2/aws/middleware/private/metrics +github.com/sigstore/sigstore/pkg/signature/options +github.com/aws/aws-sdk-go-v2/aws/ratelimit github.com/aws/aws-sdk-go-v2/internal/context +github.com/aws/aws-sdk-go-v2/feature/ec2/imds/internal/config +os/user +github.com/aws/aws-sdk-go-v2/aws/protocol/restjson +vendor/golang.org/x/crypto/cryptobyte +crypto/x509/pkix +github.com/aws/aws-sdk-go-v2/internal/middleware github.com/aws/smithy-go/document github.com/aws/smithy-go/encoding -github.com/aws/smithy-go/encoding/json -github.com/aws/aws-sdk-go-v2/internal/middleware -github.com/sigstore/sigstore/pkg/signature/options encoding/xml +github.com/aws/aws-sdk-go-v2/internal/ini +golang.org/x/sync/singleflight +github.com/aws/smithy-go/encoding/json github.com/aws/aws-sdk-go-v2/service/sso/types github.com/aws/aws-sdk-go-v2/service/ssooidc/types github.com/aws/aws-sdk-go-v2/service/sts/types -github.com/aws/aws-sdk-go-v2/internal/ini github.com/aws/aws-sdk-go-v2/service/kms/types -vendor/golang.org/x/crypto/cryptobyte -crypto/x509/pkix -golang.org/x/sync/singleflight github.com/jellydator/ttlcache crypto/ecdsa github.com/sigstore/sigstore/pkg/oauth @@ -2837,25 +2873,25 @@ github.com/aws/aws-sdk-go-v2/internal/shareddefaults crypto/x509 github.com/google/go-containerregistry/pkg/name -net/textproto vendor/golang.org/x/net/http/httpproxy +net/textproto github.com/sigstore/sigstore/pkg/signature/payload vendor/golang.org/x/net/http/httpguts mime/multipart github.com/sigstore/sigstore/pkg/cryptoutils github.com/theupdateframework/go-tuf/v0/pkg/keys +gopkg.in/square/go-jose.v2 github.com/go-jose/go-jose/v3 -crypto/tls github.com/sigstore/sigstore/test golang.org/x/crypto/ssh -gopkg.in/square/go-jose.v2 +crypto/tls github.com/sigstore/sigstore/pkg/signature github.com/theupdateframework/go-tuf/v0/internal/signer -github.com/theupdateframework/go-tuf/v0/verify github.com/theupdateframework/go-tuf/v0/sign +github.com/theupdateframework/go-tuf/v0/verify github.com/theupdateframework/go-tuf/v0/pkg/targets -github.com/sigstore/sigstore/pkg/signature/kms github.com/theupdateframework/go-tuf/v0 +github.com/sigstore/sigstore/pkg/signature/kms github.com/sigstore/sigstore/pkg/signature/kms/fake github.com/secure-systems-lab/go-securesystemslib/dsse github.com/sigstore/sigstore/pkg/signature/ssh @@ -2870,19 +2906,19 @@ github.com/aws/smithy-go/endpoints golang.org/x/oauth2 github.com/theupdateframework/go-tuf/v0/client/leveldbstore -github.com/aws/smithy-go/transport/http github.com/sigstore/sigstore/pkg/oauth/internal github.com/coreos/go-oidc/v3/oidc +github.com/aws/smithy-go/transport/http github.com/sigstore/sigstore/pkg/tuf github.com/sigstore/sigstore/pkg/oauth/oidc github.com/sigstore/sigstore/pkg/oauthflow github.com/sigstore/sigstore/pkg/fulcioroots github.com/aws/smithy-go/auth/bearer github.com/aws/aws-sdk-go-v2/internal/auth -github.com/aws/aws-sdk-go-v2/internal/endpoints/awsrulesfn github.com/aws/aws-sdk-go-v2/aws/protocol/query -github.com/aws/smithy-go/private/requestcompression github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding +github.com/aws/smithy-go/private/requestcompression +github.com/aws/aws-sdk-go-v2/internal/endpoints/awsrulesfn github.com/aws/aws-sdk-go-v2/aws github.com/aws/aws-sdk-go-v2/aws/middleware github.com/aws/aws-sdk-go-v2/credentials @@ -2894,18 +2930,18 @@ github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 github.com/aws/aws-sdk-go-v2/service/sso/internal/endpoints github.com/aws/aws-sdk-go-v2/service/ssooidc/internal/endpoints -github.com/aws/aws-sdk-go-v2/service/sts/internal/endpoints github.com/aws/aws-sdk-go-v2/service/kms/internal/endpoints +github.com/aws/aws-sdk-go-v2/service/sts/internal/endpoints github.com/aws/aws-sdk-go-v2/aws/transport/http github.com/aws/aws-sdk-go-v2/aws/retry github.com/aws/aws-sdk-go-v2/aws/signer/v4 github.com/aws/aws-sdk-go-v2/internal/auth/smithy github.com/aws/aws-sdk-go-v2/service/internal/presigned-url github.com/aws/aws-sdk-go-v2/feature/ec2/imds +github.com/aws/aws-sdk-go-v2/credentials/endpointcreds/internal/client +github.com/aws/aws-sdk-go-v2/service/sso github.com/aws/aws-sdk-go-v2/service/ssooidc github.com/aws/aws-sdk-go-v2/service/sts -github.com/aws/aws-sdk-go-v2/service/sso -github.com/aws/aws-sdk-go-v2/credentials/endpointcreds/internal/client github.com/aws/aws-sdk-go-v2/service/kms github.com/aws/aws-sdk-go-v2/credentials/endpointcreds github.com/aws/aws-sdk-go-v2/credentials/ec2rolecreds @@ -2978,17 +3014,17 @@ === RUN TestMarshalCertificateToPEM/cert1 === RUN TestMarshalCertificateToPEM/cert2 === RUN TestMarshalCertificateToPEM/nil ---- PASS: TestMarshalCertificateToPEM (0.01s) - --- PASS: TestMarshalCertificateToPEM/cert1 (0.01s) +--- PASS: TestMarshalCertificateToPEM (0.00s) + --- PASS: TestMarshalCertificateToPEM/cert1 (0.00s) --- PASS: TestMarshalCertificateToPEM/cert2 (0.00s) --- PASS: TestMarshalCertificateToPEM/nil (0.00s) === RUN TestMarshalCertificatesToPEM === RUN TestMarshalCertificatesToPEM/one_cert === RUN TestMarshalCertificatesToPEM/two_certs === RUN TestMarshalCertificatesToPEM/nil_cert ---- PASS: TestMarshalCertificatesToPEM (0.01s) +--- PASS: TestMarshalCertificatesToPEM (0.00s) --- PASS: TestMarshalCertificatesToPEM/one_cert (0.00s) - --- PASS: TestMarshalCertificatesToPEM/two_certs (0.01s) + --- PASS: TestMarshalCertificatesToPEM/two_certs (0.00s) --- PASS: TestMarshalCertificatesToPEM/nil_cert (0.00s) === RUN TestCheckExpiration === RUN TestCheckExpiration/valid @@ -3017,7 +3053,7 @@ === RUN TestRSAPrivateKeyPEMRoundtrip === PAUSE TestRSAPrivateKeyPEMRoundtrip === RUN TestUnmarshalPEMToPrivateKey ---- PASS: TestUnmarshalPEMToPrivateKey (1.39s) +--- PASS: TestUnmarshalPEMToPrivateKey (1.16s) === RUN TestECDSAPublicKeyPEMRoundtrip === PAUSE TestECDSAPublicKeyPEMRoundtrip === RUN TestEd25519PublicKeyPEMRoundtrip @@ -3025,13 +3061,13 @@ === RUN TestRSAPublicKeyPEMRoundtrip === PAUSE TestRSAPublicKeyPEMRoundtrip === RUN TestSKIDRSA ---- PASS: TestSKIDRSA (0.61s) +--- PASS: TestSKIDRSA (0.76s) === RUN TestSKIDECDSA --- PASS: TestSKIDECDSA (0.00s) === RUN TestSKIDED25519 ---- PASS: TestSKIDED25519 (0.01s) +--- PASS: TestSKIDED25519 (0.00s) === RUN TestEqualKeys ---- PASS: TestEqualKeys (1.20s) +--- PASS: TestEqualKeys (1.94s) === RUN TestValidatePubKeyUnsupported --- PASS: TestValidatePubKeyUnsupported (0.00s) === RUN TestValidatePubKeyRsa @@ -3043,13 +3079,13 @@ === RUN TestValidatePubKeyEd25519 --- PASS: TestValidatePubKeyEd25519 (0.00s) === RUN TestUnmarshalPEMToPublicKey ---- PASS: TestUnmarshalPEMToPublicKey (2.59s) +--- PASS: TestUnmarshalPEMToPublicKey (1.79s) === RUN TestMarshalAndUnmarshalOtherNameSAN --- PASS: TestMarshalAndUnmarshalOtherNameSAN (0.00s) === RUN TestUnmarshalOtherNameSANFailures --- PASS: TestUnmarshalOtherNameSANFailures (0.00s) === RUN TestGetSubjectAltnernativeNames ---- PASS: TestGetSubjectAltnernativeNames (0.01s) +--- PASS: TestGetSubjectAltnernativeNames (0.00s) === CONT TestGeneratePEMEncodedRSAKeyPair === RUN TestGeneratePEMEncodedRSAKeyPair/encrypted === PAUSE TestGeneratePEMEncodedRSAKeyPair/encrypted @@ -3061,10 +3097,6 @@ === CONT TestEd25519PrivateKeyPEMRoundtrip --- PASS: TestEd25519PrivateKeyPEMRoundtrip (0.00s) === CONT TestRSAPublicKeyPEMRoundtrip -=== CONT TestECDSAPublicKeyPEMRoundtrip ---- PASS: TestECDSAPublicKeyPEMRoundtrip (0.00s) -=== CONT TestEd25519PublicKeyPEMRoundtrip ---- PASS: TestEd25519PublicKeyPEMRoundtrip (0.00s) === CONT TestGeneratePEMEncodedECDSAKeyPair === RUN TestGeneratePEMEncodedECDSAKeyPair/encrypted === PAUSE TestGeneratePEMEncodedECDSAKeyPair/encrypted @@ -3074,24 +3106,28 @@ === PAUSE TestGeneratePEMEncodedECDSAKeyPair/SkipPassword_func === CONT TestGeneratePEMEncodedECDSAKeyPair/encrypted === CONT TestGeneratePEMEncodedRSAKeyPair/SkipPassword_func -=== CONT TestECDSAPrivateKeyPEMRoundtrip === CONT TestGeneratePEMEncodedECDSAKeyPair/SkipPassword_func +=== CONT TestECDSAPrivateKeyPEMRoundtrip === CONT TestGeneratePEMEncodedECDSAKeyPair/nil_pass_func -=== CONT TestRSAPrivateKeyPEMRoundtrip ---- PASS: TestECDSAPrivateKeyPEMRoundtrip (0.00s) +=== CONT TestECDSAPublicKeyPEMRoundtrip +--- PASS: TestECDSAPublicKeyPEMRoundtrip (0.00s) +=== CONT TestEd25519PublicKeyPEMRoundtrip +--- PASS: TestEd25519PublicKeyPEMRoundtrip (0.00s) === CONT TestGeneratePEMEncodedRSAKeyPair/nil_pass_func ---- PASS: TestRSAPrivateKeyPEMRoundtrip (0.80s) +=== CONT TestRSAPrivateKeyPEMRoundtrip +--- PASS: TestECDSAPrivateKeyPEMRoundtrip (0.01s) +--- PASS: TestRSAPrivateKeyPEMRoundtrip (0.10s) +--- PASS: TestRSAPublicKeyPEMRoundtrip (0.44s) --- PASS: TestGeneratePEMEncodedECDSAKeyPair (0.00s) --- PASS: TestGeneratePEMEncodedECDSAKeyPair/SkipPassword_func (0.00s) --- PASS: TestGeneratePEMEncodedECDSAKeyPair/nil_pass_func (0.00s) - --- PASS: TestGeneratePEMEncodedECDSAKeyPair/encrypted (1.05s) + --- PASS: TestGeneratePEMEncodedECDSAKeyPair/encrypted (0.45s) --- PASS: TestGeneratePEMEncodedRSAKeyPair (0.00s) - --- PASS: TestGeneratePEMEncodedRSAKeyPair/SkipPassword_func (0.37s) - --- PASS: TestGeneratePEMEncodedRSAKeyPair/nil_pass_func (1.21s) - --- PASS: TestGeneratePEMEncodedRSAKeyPair/encrypted (1.73s) ---- PASS: TestRSAPublicKeyPEMRoundtrip (2.78s) + --- PASS: TestGeneratePEMEncodedRSAKeyPair/SkipPassword_func (0.57s) + --- PASS: TestGeneratePEMEncodedRSAKeyPair/nil_pass_func (0.69s) + --- PASS: TestGeneratePEMEncodedRSAKeyPair/encrypted (0.83s) PASS -ok github.com/sigstore/sigstore/pkg/cryptoutils 8.656s +ok github.com/sigstore/sigstore/pkg/cryptoutils 6.516s ? github.com/sigstore/sigstore/pkg/fulcioroots [no test files] ? github.com/sigstore/sigstore/pkg/oauth [no test files] === RUN TestParseAccessTokenSuccessResponse @@ -3100,7 +3136,7 @@ === RUN TestParseAccessTokenSuccessResponse/bad_json === RUN TestParseAccessTokenSuccessResponse/x-www-form-urlencoded === RUN TestParseAccessTokenSuccessResponse/expires_in_unparsable ---- PASS: TestParseAccessTokenSuccessResponse (0.02s) +--- PASS: TestParseAccessTokenSuccessResponse (0.00s) --- PASS: TestParseAccessTokenSuccessResponse/json (0.00s) --- PASS: TestParseAccessTokenSuccessResponse/json_no_access_token (0.00s) --- PASS: TestParseAccessTokenSuccessResponse/bad_json (0.00s) @@ -3115,14 +3151,14 @@ === RUN FuzzParseAccessTokenSuccess --- PASS: FuzzParseAccessTokenSuccess (0.00s) PASS -ok github.com/sigstore/sigstore/pkg/oauth/internal 0.063s +ok github.com/sigstore/sigstore/pkg/oauth/internal 0.047s ? github.com/sigstore/sigstore/pkg/oauth/oidc [no test files] === RUN TestClientCredentialsFlowTokenGetter_ccFlow client_credentials_test.go:36: got request: /.well-known/openid-configuration client_credentials_test.go:36: got request: /.well-known/openid-configuration client_credentials_test.go:36: got request: /token Token received! ---- PASS: TestClientCredentialsFlowTokenGetter_ccFlow (0.00s) +--- PASS: TestClientCredentialsFlowTokenGetter_ccFlow (0.01s) === RUN TestDeviceFlowTokenGetter_deviceFlow device_test.go:94: got request: /.well-known/openid-configuration device_test.go:94: got request: /.well-known/openid-configuration @@ -3139,7 +3175,7 @@ === RUN TestStaticTokenGetter_GetIDToken/not_verified === RUN TestStaticTokenGetter_GetIDToken/verified === RUN TestStaticTokenGetter_GetIDToken/spiffeid ---- PASS: TestStaticTokenGetter_GetIDToken (0.01s) +--- PASS: TestStaticTokenGetter_GetIDToken (0.00s) --- PASS: TestStaticTokenGetter_GetIDToken/no_email (0.00s) --- PASS: TestStaticTokenGetter_GetIDToken/no_verified (0.00s) --- PASS: TestStaticTokenGetter_GetIDToken/not_verified (0.00s) @@ -3160,19 +3196,19 @@ --- PASS: TestSubjectFromToken/String_email_verified_value (0.00s) --- PASS: TestSubjectFromToken/Email_not_verified (0.00s) === RUN TestSubjectFromUnverifiedToken -=== RUN TestSubjectFromUnverifiedToken/Email_not_verified === RUN TestSubjectFromUnverifiedToken/invalid_email_verified_property === RUN TestSubjectFromUnverifiedToken/Subject_as_subject === RUN TestSubjectFromUnverifiedToken/no_email_or_subject === RUN TestSubjectFromUnverifiedToken/Email_as_subject === RUN TestSubjectFromUnverifiedToken/String_email_verified_value +=== RUN TestSubjectFromUnverifiedToken/Email_not_verified --- PASS: TestSubjectFromUnverifiedToken (0.00s) - --- PASS: TestSubjectFromUnverifiedToken/Email_not_verified (0.00s) --- PASS: TestSubjectFromUnverifiedToken/invalid_email_verified_property (0.00s) --- PASS: TestSubjectFromUnverifiedToken/Subject_as_subject (0.00s) --- PASS: TestSubjectFromUnverifiedToken/no_email_or_subject (0.00s) --- PASS: TestSubjectFromUnverifiedToken/Email_as_subject (0.00s) --- PASS: TestSubjectFromUnverifiedToken/String_email_verified_value (0.00s) + --- PASS: TestSubjectFromUnverifiedToken/Email_not_verified (0.00s) === RUN TestInteractiveFlow_IO === RUN TestInteractiveFlow_IO/default === RUN TestInteractiveFlow_IO/buffer @@ -3180,9 +3216,9 @@ --- PASS: TestInteractiveFlow_IO/default (0.00s) --- PASS: TestInteractiveFlow_IO/buffer (0.00s) PASS -ok github.com/sigstore/sigstore/pkg/oauthflow 0.076s +ok github.com/sigstore/sigstore/pkg/oauthflow 0.047s === RUN TestECDSASignerVerifier ---- PASS: TestECDSASignerVerifier (0.01s) +--- PASS: TestECDSASignerVerifier (0.00s) === RUN TestECDSASignerVerifierUnsupportedHash --- PASS: TestECDSASignerVerifierUnsupportedHash (0.00s) === RUN TestECDSALoadVerifierWithoutKey @@ -3199,11 +3235,11 @@ === RUN TestED25519phVerifier --- PASS: TestED25519phVerifier (0.00s) === RUN TestRSAPKCS1v15SignerVerifier ---- PASS: TestRSAPKCS1v15SignerVerifier (0.08s) +--- PASS: TestRSAPKCS1v15SignerVerifier (0.04s) === RUN TestRSAPKCS1v15SignerVerifierUnsupportedHash --- PASS: TestRSAPKCS1v15SignerVerifierUnsupportedHash (0.00s) === RUN TestRSAPSSSignerVerifier ---- PASS: TestRSAPSSSignerVerifier (0.16s) +--- PASS: TestRSAPSSSignerVerifier (0.08s) === RUN TestRSAPSSSignerVerifierUnsupportedHash --- PASS: TestRSAPSSSignerVerifierUnsupportedHash (0.00s) === RUN TestLoadEd25519Signer @@ -3211,21 +3247,21 @@ === RUN TestLoadEd25519phSigner --- PASS: TestLoadEd25519phSigner (0.00s) === RUN TestLoadRSAPSSSignerVerifier ---- PASS: TestLoadRSAPSSSignerVerifier (0.01s) +--- PASS: TestLoadRSAPSSSignerVerifier (0.00s) === RUN TestConvertED25519ph ---- PASS: TestConvertED25519ph (0.01s) +--- PASS: TestConvertED25519ph (0.00s) === RUN TestProviderRoundtrip === RUN TestProviderRoundtrip/ECDSA === RUN TestProviderRoundtrip/RSA ---- PASS: TestProviderRoundtrip (0.83s) +--- PASS: TestProviderRoundtrip (0.24s) --- PASS: TestProviderRoundtrip/ECDSA (0.00s) - --- PASS: TestProviderRoundtrip/RSA (0.01s) + --- PASS: TestProviderRoundtrip/RSA (0.00s) === RUN TestLoadUnsafeVerifier ---- PASS: TestLoadUnsafeVerifier (0.90s) +--- PASS: TestLoadUnsafeVerifier (0.13s) === RUN TestLoadVerifier ---- PASS: TestLoadVerifier (1.30s) +--- PASS: TestLoadVerifier (0.90s) PASS -ok github.com/sigstore/sigstore/pkg/signature 3.356s +ok github.com/sigstore/sigstore/pkg/signature 1.424s === RUN TestImplementsDSSESigner --- PASS: TestImplementsDSSESigner (0.00s) === RUN TestImplementsDSSEVerifier @@ -3239,7 +3275,7 @@ === RUN TestInvalidSignature --- PASS: TestInvalidSignature (0.00s) PASS -ok github.com/sigstore/sigstore/pkg/signature/dsse 0.054s +ok github.com/sigstore/sigstore/pkg/signature/dsse 0.051s ? github.com/sigstore/sigstore/pkg/signature/kms [no test files] === RUN TestParseReference === RUN TestParseReference/awskms:///1234abcd-12ab-34cd-56ef-1234567890ab @@ -3274,13 +3310,13 @@ --- PASS: TestParseReference/awskms:///1234abcd-12ab-YYYY-56ef-1234567890ab (0.00s) --- PASS: TestParseReference/awskms://1234abcd-12ab-34cd-56ef-1234567890ab (0.00s) PASS -ok github.com/sigstore/sigstore/pkg/signature/kms/aws 0.024s +ok github.com/sigstore/sigstore/pkg/signature/kms/aws 0.023s === RUN TestFakeSigner --- PASS: TestFakeSigner (0.00s) === RUN TestFakeSignerWithPrivateKey --- PASS: TestFakeSignerWithPrivateKey (0.00s) PASS -ok github.com/sigstore/sigstore/pkg/signature/kms/fake 0.040s +ok github.com/sigstore/sigstore/pkg/signature/kms/fake 0.028s ? github.com/sigstore/sigstore/pkg/signature/options [no test files] === RUN TestMarshalCosign === PAUSE TestMarshalCosign @@ -3319,7 +3355,7 @@ --- PASS: TestUnmarshalCosign/unknown_type (0.00s) --- PASS: TestUnmarshalCosign/arbitrary_claims (0.00s) PASS -ok github.com/sigstore/sigstore/pkg/signature/payload 0.055s +ok github.com/sigstore/sigstore/pkg/signature/payload 0.035s === RUN TestFromOpenSSH sign_test.go:154: skip TestFromOpenSSH: missing ssh-keygen in PATH --- SKIP: TestFromOpenSSH (0.00s) @@ -3329,11 +3365,11 @@ === RUN TestRoundTrip === RUN TestRoundTrip/rsa === RUN TestRoundTrip/ed25519 ---- PASS: TestRoundTrip (0.14s) - --- PASS: TestRoundTrip/rsa (0.05s) +--- PASS: TestRoundTrip (0.07s) + --- PASS: TestRoundTrip/rsa (0.03s) --- PASS: TestRoundTrip/ed25519 (0.01s) PASS -ok github.com/sigstore/sigstore/pkg/signature/ssh 0.177s +ok github.com/sigstore/sigstore/pkg/signature/ssh 0.108s === RUN TestMarshalStatusType --- PASS: TestMarshalStatusType (0.00s) === RUN TestMarshalInvalidStatusType @@ -3355,9 +3391,9 @@ === RUN TestUnmarshalInvalidUsageType --- PASS: TestUnmarshalInvalidUsageType (0.00s) PASS -ok github.com/sigstore/sigstore/pkg/tuf 0.060s +ok github.com/sigstore/sigstore/pkg/tuf 0.008s ? github.com/sigstore/sigstore/test [no test files] - rm -fr -- /tmp/dh-xdg-rundir-0rCzj5O8 + rm -fr -- /tmp/dh-xdg-rundir-eJEmVGw2 rm -rf /build/reproducible-path/golang-github-sigstore-sigstore-1.8.12/debian/tmp-home make[1]: Leaving directory '/build/reproducible-path/golang-github-sigstore-sigstore-1.8.12' create-stamp debian/debhelper-build-stamp @@ -3387,12 +3423,14 @@ dpkg-buildpackage: info: binary-only upload (no source included) dpkg-genchanges: info: including full source code in upload I: copying local configuration +I: user script /srv/workspace/pbuilder/2931246/tmp/hooks/B01_cleanup starting +I: user script /srv/workspace/pbuilder/2931246/tmp/hooks/B01_cleanup finished I: unmounting dev/ptmx filesystem I: unmounting dev/pts filesystem I: unmounting dev/shm filesystem I: unmounting proc filesystem I: unmounting sys filesystem I: cleaning the build env -I: removing directory /srv/workspace/pbuilder/725686 and its subdirectories -I: Current time: Fri Apr 17 23:15:55 -12 2026 -I: pbuilder-time-stamp: 1776510955 +I: removing directory /srv/workspace/pbuilder/2931246 and its subdirectories +I: Current time: Sun Mar 16 18:55:45 +14 2025 +I: pbuilder-time-stamp: 1742100945