Diff of the two buildlogs: -- --- b1/build.log 2025-08-20 12:34:36.810347044 +0000 +++ b2/build.log 2025-08-20 12:37:00.390516551 +0000 @@ -1,6 +1,6 @@ I: pbuilder: network access will be disabled during build -I: Current time: Wed Aug 20 00:32:19 -12 2025 -I: pbuilder-time-stamp: 1755693139 +I: Current time: Wed Sep 23 08:57:38 +14 2026 +I: pbuilder-time-stamp: 1790103458 I: Building the build Environment I: extracting base tarball [/var/cache/pbuilder/unstable-reproducible-base.tgz] I: copying local configuration @@ -25,53 +25,85 @@ dpkg-source: info: applying disable-tests-that-download.patch I: Not using root during the build. I: Installing the build-deps -I: user script /srv/workspace/pbuilder/2558516/tmp/hooks/D02_print_environment starting +I: user script /srv/workspace/pbuilder/1998787/tmp/hooks/D01_modify_environment starting +debug: Running on codethink03-arm64. +I: Changing host+domainname to test build reproducibility +I: Adding a custom variable just for the fun of it... +I: Changing /bin/sh to bash +'/bin/sh' -> '/bin/bash' +lrwxrwxrwx 1 root root 9 Sep 22 18:57 /bin/sh -> /bin/bash +I: Setting pbuilder2's login shell to /bin/bash +I: Setting pbuilder2's GECOS to second user,second room,second work-phone,second home-phone,second other +I: user script /srv/workspace/pbuilder/1998787/tmp/hooks/D01_modify_environment finished +I: user script /srv/workspace/pbuilder/1998787/tmp/hooks/D02_print_environment starting I: set - BUILDDIR='/build/reproducible-path' - BUILDUSERGECOS='first user,first room,first work-phone,first home-phone,first other' - BUILDUSERNAME='pbuilder1' - BUILD_ARCH='arm64' - DEBIAN_FRONTEND='noninteractive' + BASH=/bin/sh + BASHOPTS=checkwinsize:cmdhist:complete_fullquote:extquote:force_fignore:globasciiranges:globskipdots:hostcomplete:interactive_comments:patsub_replacement:progcomp:promptvars:sourcepath + BASH_ALIASES=() + BASH_ARGC=() + BASH_ARGV=() + BASH_CMDS=() + BASH_LINENO=([0]="12" [1]="0") + BASH_LOADABLES_PATH=/usr/local/lib/bash:/usr/lib/bash:/opt/local/lib/bash:/usr/pkg/lib/bash:/opt/pkg/lib/bash:. + BASH_SOURCE=([0]="/tmp/hooks/D02_print_environment" [1]="/tmp/hooks/D02_print_environment") + BASH_VERSINFO=([0]="5" [1]="2" [2]="37" [3]="1" [4]="release" [5]="aarch64-unknown-linux-gnu") + BASH_VERSION='5.2.37(1)-release' + BUILDDIR=/build/reproducible-path + BUILDUSERGECOS='second user,second room,second work-phone,second home-phone,second other' + BUILDUSERNAME=pbuilder2 + BUILD_ARCH=arm64 + DEBIAN_FRONTEND=noninteractive DEB_BUILD_OPTIONS='buildinfo=+all reproducible=+all parallel=12 ' - DISTRIBUTION='unstable' - HOME='/root' - HOST_ARCH='arm64' + DIRSTACK=() + DISTRIBUTION=unstable + EUID=0 + FUNCNAME=([0]="Echo" [1]="main") + GROUPS=() + HOME=/root + HOSTNAME=i-capture-the-hostname + HOSTTYPE=aarch64 + HOST_ARCH=arm64 IFS=' ' - INVOCATION_ID='8b2e46ebf4b34d9f987be4c5302e971c' - LANG='C' - LANGUAGE='en_US:en' - LC_ALL='C' - MAIL='/var/mail/root' - OPTIND='1' - PATH='/usr/sbin:/usr/bin:/sbin:/bin:/usr/games' - PBCURRENTCOMMANDLINEOPERATION='build' - PBUILDER_OPERATION='build' - PBUILDER_PKGDATADIR='/usr/share/pbuilder' - PBUILDER_PKGLIBDIR='/usr/lib/pbuilder' - PBUILDER_SYSCONFDIR='/etc' - PPID='2558516' - PS1='# ' - PS2='> ' + INVOCATION_ID=29a2e454c3ab4e49ab14c39dd2cb0bf7 + LANG=C + LANGUAGE=nl_BE:nl + LC_ALL=C + MACHTYPE=aarch64-unknown-linux-gnu + MAIL=/var/mail/root + OPTERR=1 + OPTIND=1 + OSTYPE=linux-gnu + PATH=/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path + PBCURRENTCOMMANDLINEOPERATION=build + PBUILDER_OPERATION=build + PBUILDER_PKGDATADIR=/usr/share/pbuilder + PBUILDER_PKGLIBDIR=/usr/lib/pbuilder + PBUILDER_SYSCONFDIR=/etc + PIPESTATUS=([0]="0") + POSIXLY_CORRECT=y + PPID=1998787 PS4='+ ' - PWD='/' - SHELL='/bin/bash' - SHLVL='2' - SUDO_COMMAND='/usr/bin/timeout -k 18.1h 18h /usr/bin/ionice -c 3 /usr/bin/nice /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.z5AJwcxL/pbuilderrc_HRm8 --distribution unstable --hookdir /etc/pbuilder/first-build-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/unstable-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.z5AJwcxL/b1 --logfile b1/build.log golang-github-sigstore-sigstore_1.9.5-1.dsc' - SUDO_GID='109' - SUDO_HOME='/var/lib/jenkins' - SUDO_UID='104' - SUDO_USER='jenkins' - TERM='unknown' - TZ='/usr/share/zoneinfo/Etc/GMT+12' - USER='root' - _='/usr/bin/systemd-run' - http_proxy='http://192.168.101.4:3128' + PWD=/ + SHELL=/bin/bash + SHELLOPTS=braceexpand:errexit:hashall:interactive-comments:posix + SHLVL=3 + SUDO_COMMAND='/usr/bin/timeout -k 24.1h 24h /usr/bin/ionice -c 3 /usr/bin/nice -n 11 /usr/bin/unshare --uts -- /usr/sbin/pbuilder --build --configfile /srv/reproducible-results/rbuild-debian/r-b-build.z5AJwcxL/pbuilderrc_JV5F --distribution unstable --hookdir /etc/pbuilder/rebuild-hooks --debbuildopts -b --basetgz /var/cache/pbuilder/unstable-reproducible-base.tgz --buildresult /srv/reproducible-results/rbuild-debian/r-b-build.z5AJwcxL/b2 --logfile b2/build.log golang-github-sigstore-sigstore_1.9.5-1.dsc' + SUDO_GID=109 + SUDO_HOME=/var/lib/jenkins + SUDO_UID=104 + SUDO_USER=jenkins + TERM=unknown + TZ=/usr/share/zoneinfo/Etc/GMT-14 + UID=0 + USER=root + _='I: set' + http_proxy=http://192.168.101.4:3128 I: uname -a - Linux codethink04-arm64 6.12.41+deb13-cloud-arm64 #1 SMP Debian 6.12.41-1 (2025-08-12) aarch64 GNU/Linux + Linux i-capture-the-hostname 6.12.41+deb13-cloud-arm64 #1 SMP Debian 6.12.41-1 (2025-08-12) aarch64 GNU/Linux I: ls -l /bin - lrwxrwxrwx 1 root root 7 Aug 10 12:30 /bin -> usr/bin -I: user script /srv/workspace/pbuilder/2558516/tmp/hooks/D02_print_environment finished + lrwxrwxrwx 1 root root 7 Aug 10 2025 /bin -> usr/bin +I: user script /srv/workspace/pbuilder/1998787/tmp/hooks/D02_print_environment finished -> Attempting to satisfy build-dependencies -> Creating pbuilder-satisfydepends-dummy package Package: pbuilder-satisfydepends-dummy @@ -640,7 +672,7 @@ Get: 479 http://deb.debian.org/debian unstable/main arm64 golang-github-theupdateframework-go-tuf-dev all 2.0.2+0.7.0-1 [200 kB] Get: 480 http://deb.debian.org/debian unstable/main arm64 golang-github-tink-crypto-tink-go-dev all 2.4.0-1 [2021 kB] Get: 481 http://deb.debian.org/debian unstable/main arm64 golang-github-sigstore-sigstore-dev all 1.9.5-1 [112 kB] -Fetched 224 MB in 2s (107 MB/s) +Fetched 224 MB in 1s (214 MB/s) Preconfiguring packages ... Selecting previously unselected package golang-golang-x-sys-dev. (Reading database ... (Reading database ... 5% (Reading database ... 10% (Reading database ... 15% (Reading database ... 20% (Reading database ... 25% (Reading database ... 30% (Reading database ... 35% (Reading database ... 40% (Reading database ... 45% (Reading database ... 50% (Reading database ... 55% (Reading database ... 60% (Reading database ... 65% (Reading database ... 70% (Reading database ... 75% (Reading database ... 80% (Reading database ... 85% (Reading database ... 90% (Reading database ... 95% (Reading database ... 100% (Reading database ... 19969 files and directories currently installed.) @@ -2183,8 +2215,8 @@ Setting up tzdata (2025b-5) ... Current default time zone: 'Etc/UTC' -Local time is now: Wed Aug 20 12:33:20 UTC 2025. -Universal Time is now: Wed Aug 20 12:33:20 UTC 2025. +Local time is now: Tue Sep 22 18:58:38 UTC 2026. +Universal Time is now: Tue Sep 22 18:58:38 UTC 2026. Run 'dpkg-reconfigure tzdata' if you wish to change it. Setting up golang-github-coreos-go-semver-dev (0.3.0-1) ... @@ -2585,7 +2617,11 @@ Building tag database... -> Finished parsing the build-deps I: Building the package -I: Running cd /build/reproducible-path/golang-github-sigstore-sigstore-1.9.5/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games" HOME="/nonexistent/first-build" dpkg-genchanges -S > ../golang-github-sigstore-sigstore_1.9.5-1_source.changes +I: user script /srv/workspace/pbuilder/1998787/tmp/hooks/A99_set_merged_usr starting +Not re-configuring usrmerge for unstable +I: user script /srv/workspace/pbuilder/1998787/tmp/hooks/A99_set_merged_usr finished +hostname: Name or service not known +I: Running cd /build/reproducible-path/golang-github-sigstore-sigstore-1.9.5/ && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-buildpackage -us -uc -b && env PATH="/usr/sbin:/usr/bin:/sbin:/bin:/usr/games:/i/capture/the/path" HOME="/nonexistent/second-build" dpkg-genchanges -S > ../golang-github-sigstore-sigstore_1.9.5-1_source.changes dpkg-buildpackage: info: source package golang-github-sigstore-sigstore dpkg-buildpackage: info: source version 1.9.5-1 dpkg-buildpackage: info: source distribution unstable @@ -2613,46 +2649,46 @@ make[1]: Leaving directory '/build/reproducible-path/golang-github-sigstore-sigstore-1.9.5' dh_auto_build -O--builddirectory=_build -O--buildsystem=golang cd _build && go install -trimpath -v -p 12 github.com/sigstore/sigstore/pkg/cryptoutils github.com/sigstore/sigstore/pkg/fulcioroots github.com/sigstore/sigstore/pkg/oauth github.com/sigstore/sigstore/pkg/oauth/internal github.com/sigstore/sigstore/pkg/oauth/oidc github.com/sigstore/sigstore/pkg/oauthflow github.com/sigstore/sigstore/pkg/signature github.com/sigstore/sigstore/pkg/signature/dsse github.com/sigstore/sigstore/pkg/signature/kms github.com/sigstore/sigstore/pkg/signature/kms/aws github.com/sigstore/sigstore/pkg/signature/kms/cliplugin github.com/sigstore/sigstore/pkg/signature/kms/cliplugin/common github.com/sigstore/sigstore/pkg/signature/kms/cliplugin/encoding github.com/sigstore/sigstore/pkg/signature/kms/cliplugin/handler github.com/sigstore/sigstore/pkg/signature/kms/cliplugin/internal/signerverifier github.com/sigstore/sigstore/pkg/signature/kms/fake github.com/sigstore/sigstore/pkg/signature/options github.com/sigstore/sigstore/pkg/signature/payload github.com/sigstore/sigstore/pkg/signature/ssh github.com/sigstore/sigstore/pkg/signature/tink github.com/sigstore/sigstore/pkg/tuf github.com/sigstore/sigstore/test -internal/goarch -internal/goexperiment -internal/godebugs -internal/unsafeheader -internal/byteorder -internal/coverage/rtcov -internal/profilerecord -internal/abi internal/msan +internal/profilerecord +internal/unsafeheader +internal/godebugs +internal/goexperiment internal/asan -internal/runtime/syscall -internal/cpu +internal/coverage/rtcov +internal/goarch internal/goos -internal/runtime/math -sync/atomic +internal/byteorder math/bits unicode +sync/atomic unicode/utf8 +internal/runtime/syscall +internal/cpu crypto/internal/fips140/alias internal/itoa -internal/chacha8rand -crypto/internal/fips140deps/byteorder cmp -crypto/internal/fips140/subtle +internal/abi +internal/runtime/math crypto/internal/boring/sig +crypto/internal/fips140/subtle unicode/utf16 +internal/chacha8rand +crypto/internal/fips140deps/byteorder vendor/golang.org/x/crypto/cryptobyte/asn1 internal/nettrace +math encoding golang.org/x/crypto/internal/alias -internal/bytealg -internal/runtime/atomic -crypto/internal/fips140deps/cpu -internal/runtime/sys -math -google.golang.org/protobuf/internal/flags golang.org/x/crypto/salsa20/salsa +google.golang.org/protobuf/internal/flags google.golang.org/protobuf/internal/set -github.com/theupdateframework/go-tuf/v0/internal/sets log/internal +github.com/theupdateframework/go-tuf/v0/internal/sets +internal/bytealg +internal/runtime/atomic +internal/runtime/sys +crypto/internal/fips140deps/cpu container/list vendor/golang.org/x/crypto/internal/alias github.com/aws/aws-sdk-go-v2/internal/sdkio @@ -2667,336 +2703,336 @@ internal/sync internal/runtime/maps runtime +internal/reflectlite weak -iter crypto/subtle sync -internal/reflectlite -slices +iter maps +slices +errors +sort +internal/oserror +path +math/rand/v2 +vendor/golang.org/x/net/dns/dnsmessage +strconv internal/bisect -internal/testlog internal/singleflight unique +internal/testlog +io google.golang.org/protobuf/internal/pragma +syscall runtime/cgo -sort -errors -io -vendor/golang.org/x/net/dns/dnsmessage internal/godebug -container/heap -path -internal/oserror -strconv -math/rand/v2 bytes hash strings -github.com/aws/smithy-go/transport/http/internal/io -syscall -hash/fnv -hash/crc32 +crypto crypto/internal/randutil -math/rand +github.com/aws/smithy-go/transport/http/internal/io crypto/internal/fips140deps/godebug -reflect +container/heap net/netip -golang.org/x/crypto/blowfish -crypto -vendor/golang.org/x/text/transform -github.com/syndtr/goleveldb/leveldb/comparer -github.com/aws/smithy-go/io +reflect +math/rand +hash/fnv crypto/internal/fips140 +regexp/syntax +bufio crypto/internal/impl +hash/crc32 github.com/theupdateframework/go-tuf/v0/internal/roles -regexp/syntax +crypto/internal/fips140/sha256 +crypto/internal/fips140/sha3 +crypto/internal/fips140/sha512 +crypto/tls/internal/fips140tls +vendor/golang.org/x/text/transform net/http/internal/ascii -bufio +github.com/syndtr/goleveldb/leveldb/comparer net/http/internal/testcert +golang.org/x/crypto/blowfish +internal/syscall/unix +time +internal/syscall/execenv +github.com/aws/smithy-go/io github.com/aws/aws-sdk-go-v2/internal/strings -crypto/internal/fips140/sha3 -crypto/tls/internal/fips140tls -crypto/internal/fips140/sha256 -crypto/internal/fips140/sha512 -crypto/sha3 crypto/internal/fips140/hmac -crypto/internal/fips140hash +crypto/sha3 crypto/internal/fips140/check +crypto/internal/fips140hash crypto/internal/fips140/nistec/fiat -crypto/internal/fips140/hkdf +crypto/internal/fips140/aes crypto/internal/fips140/edwards25519/field -crypto/internal/fips140/tls12 crypto/internal/fips140/bigmod -crypto/internal/fips140/aes +crypto/internal/fips140/hkdf +crypto/internal/fips140/tls12 crypto/internal/fips140/tls13 -time -internal/syscall/execenv -internal/syscall/unix -crypto/internal/fips140/edwards25519 regexp +crypto/internal/fips140/edwards25519 io/fs internal/poll +context github.com/sigstore/sigstore/pkg/signature/kms/cliplugin/common -github.com/aws/aws-sdk-go-v2/internal/timeconv github.com/aws/smithy-go/ptr -context -crypto/internal/fips140/nistec +github.com/aws/aws-sdk-go-v2/internal/timeconv github.com/aws/aws-sdk-go-v2/internal/sdk github.com/aws/smithy-go/context github.com/tink-crypto/tink-go/tink -internal/filepathlite embed +internal/filepathlite google.golang.org/protobuf/internal/editiondefaults os -internal/fmtsort +crypto/internal/fips140/nistec encoding/binary -encoding/base64 -golang.org/x/crypto/internal/poly1305 -vendor/golang.org/x/crypto/internal/poly1305 -github.com/golang/snappy -golang.org/x/sys/unix -github.com/tink-crypto/tink-go/internal/outputprefix -golang.org/x/crypto/nacl/secretbox -encoding/pem +internal/fmtsort crypto/internal/sysrand fmt path/filepath -google.golang.org/protobuf/internal/detrand -io/ioutil golang.org/x/sys/cpu +io/ioutil internal/sysinfo -net crypto/internal/entropy crypto/internal/fips140/drbg +crypto/internal/fips140/aes/gcm crypto/internal/fips140only crypto/internal/fips140/rsa -crypto/internal/fips140/mlkem -crypto/internal/fips140/ecdh crypto/internal/fips140/ed25519 -crypto/internal/fips140/ecdsa -crypto/internal/fips140/aes/gcm +crypto/internal/fips140/mlkem os/exec -golang.org/x/crypto/sha3 crypto/md5 crypto/rc4 +encoding/base64 +golang.org/x/crypto/internal/poly1305 +golang.org/x/sys/unix +crypto/internal/fips140/ecdh +crypto/internal/fips140/ecdsa +golang.org/x/crypto/nacl/secretbox +google.golang.org/protobuf/internal/detrand +encoding/pem +net +golang.org/x/crypto/sha3 +vendor/golang.org/x/crypto/internal/poly1305 +github.com/golang/snappy crypto/cipher +github.com/tink-crypto/tink-go/internal/outputprefix github.com/skratchdot/open-golang/open +crypto/internal/boring +crypto/des +vendor/golang.org/x/crypto/chacha20 +golang.org/x/crypto/chacha20 encoding/hex net/url +google.golang.org/protobuf/internal/errors +math/big encoding/json github.com/opencontainers/go-digest -math/big -google.golang.org/protobuf/internal/version -go/token -compress/flate -google.golang.org/protobuf/internal/errors -crypto/internal/boring -crypto/des -github.com/theupdateframework/go-tuf/v0/internal/fsutil -google.golang.org/protobuf/encoding/protowire crypto/ecdh crypto/sha512 crypto/sha1 crypto/aes crypto/sha256 crypto/hmac -log -google.golang.org/protobuf/reflect/protoreflect -vendor/golang.org/x/crypto/chacha20 +google.golang.org/protobuf/encoding/protowire +go/token +compress/flate +google.golang.org/protobuf/internal/version golang.org/x/crypto/pbkdf2 +google.golang.org/protobuf/reflect/protoreflect golang.org/x/crypto/scrypt +github.com/theupdateframework/go-tuf/v0/internal/fsutil +log +vendor/golang.org/x/crypto/chacha20poly1305 vendor/golang.org/x/text/unicode/norm vendor/golang.org/x/net/http2/hpack mime -vendor/golang.org/x/crypto/chacha20poly1305 mime/quotedprintable -compress/gzip -vendor/golang.org/x/text/unicode/bidi net/http/internal +vendor/golang.org/x/text/unicode/bidi github.com/syndtr/goleveldb/leveldb/util github.com/syndtr/goleveldb/leveldb/storage flag -runtime/debug +compress/gzip github.com/syndtr/goleveldb/leveldb/cache github.com/syndtr/goleveldb/leveldb/filter -runtime/trace -vendor/golang.org/x/text/secure/bidirule +runtime/debug google.golang.org/protobuf/internal/descfmt google.golang.org/protobuf/internal/descopts google.golang.org/protobuf/internal/strs google.golang.org/protobuf/internal/encoding/messageset google.golang.org/protobuf/internal/genid -google.golang.org/protobuf/internal/encoding/text google.golang.org/protobuf/internal/order +google.golang.org/protobuf/internal/encoding/text google.golang.org/protobuf/runtime/protoiface +github.com/syndtr/goleveldb/leveldb/opt google.golang.org/protobuf/reflect/protoregistry +runtime/trace +vendor/golang.org/x/text/secure/bidirule google.golang.org/protobuf/internal/protolazy -github.com/syndtr/goleveldb/leveldb/opt -vendor/golang.org/x/net/idna -testing text/template/parse -golang.org/x/term +testing gopkg.in/square/go-jose.v2/json github.com/syndtr/goleveldb/leveldb/errors +vendor/golang.org/x/net/idna github.com/pkg/browser github.com/syndtr/goleveldb/leveldb/iterator github.com/syndtr/goleveldb/leveldb/journal -google.golang.org/protobuf/internal/encoding/defval -database/sql/driver -google.golang.org/protobuf/proto crypto/elliptic crypto/internal/boring/bbig encoding/asn1 crypto/rand crypto/dsa +google.golang.org/protobuf/internal/encoding/defval +google.golang.org/protobuf/proto github.com/secure-systems-lab/go-securesystemslib/cjson -github.com/syndtr/goleveldb/leveldb/memdb crypto/ed25519 crypto/rsa github.com/secure-systems-lab/go-securesystemslib/encrypted github.com/theupdateframework/go-tuf/v0/data crypto/internal/hpke +github.com/syndtr/goleveldb/leveldb/memdb +github.com/theupdateframework/go-tuf/v0/util github.com/syndtr/goleveldb/leveldb/table +text/template golang.org/x/crypto/ed25519 -github.com/segmentio/ksuid +database/sql/driver github.com/go-jose/go-jose/json -github.com/theupdateframework/go-tuf/v0/util github.com/sigstore/sigstore/pkg/signature/options -golang.org/x/crypto/chacha20 -text/template -google.golang.org/protobuf/internal/filedesc vendor/golang.org/x/crypto/cryptobyte crypto/x509/pkix +google.golang.org/protobuf/internal/filedesc google.golang.org/protobuf/encoding/prototext +golang.org/x/term +github.com/segmentio/ksuid golang.org/x/crypto/curve25519 +crypto/ecdsa golang.org/x/crypto/ssh/internal/bcrypt_pbkdf github.com/aws/aws-sdk-go-v2/internal/rand github.com/aws/aws-sdk-go-v2/internal/sync/singleflight -github.com/syndtr/goleveldb/leveldb github.com/aws/smithy-go/internal/sync/singleflight +github.com/syndtr/goleveldb/leveldb github.com/aws/smithy-go/logging github.com/aws/smithy-go -github.com/aws/smithy-go/time github.com/aws/smithy-go/middleware +github.com/aws/smithy-go/time github.com/aws/smithy-go/rand github.com/aws/aws-sdk-go-v2/aws/ratelimit -github.com/aws/aws-sdk-go-v2/feature/ec2/imds/internal/config github.com/aws/smithy-go/auth +github.com/aws/aws-sdk-go-v2/feature/ec2/imds/internal/config os/user github.com/aws/aws-sdk-go-v2/aws/protocol/restjson github.com/aws/smithy-go/document -crypto/ecdsa github.com/aws/smithy-go/encoding github.com/aws/smithy-go/encoding/json encoding/xml +github.com/aws/aws-sdk-go-v2/internal/ini +golang.org/x/sync/singleflight github.com/aws/aws-sdk-go-v2/service/sso/types +gopkg.in/square/go-jose.v2/cipher +github.com/go-jose/go-jose/cipher github.com/aws/aws-sdk-go-v2/service/ssooidc/types -github.com/aws/aws-sdk-go-v2/service/sts/types github.com/aws/aws-sdk-go-v2/aws/middleware/private/metrics github.com/aws/aws-sdk-go-v2/internal/context -github.com/aws/aws-sdk-go-v2/internal/ini +github.com/sigstore/sigstore/pkg/oauth github.com/aws/aws-sdk-go-v2/service/kms/types -golang.org/x/sync/singleflight github.com/aws/aws-sdk-go-v2/internal/middleware +github.com/aws/aws-sdk-go-v2/service/sts/types +github.com/jellydator/ttlcache github.com/tink-crypto/tink-go/subtle/random google.golang.org/protobuf/internal/encoding/json -github.com/jellydator/ttlcache github.com/tink-crypto/tink-go/internal/signature/ecdsa github.com/tink-crypto/tink-go/secretdata golang.org/x/crypto/hkdf github.com/tink-crypto/tink-go/subtle -github.com/sigstore/sigstore/pkg/oauth -github.com/go-jose/go-jose/cipher github.com/tink-crypto/tink-go/signature/subtle -gopkg.in/square/go-jose.v2/cipher google.golang.org/protobuf/internal/encoding/tag google.golang.org/protobuf/encoding/protojson google.golang.org/protobuf/internal/impl github.com/aws/aws-sdk-go-v2/aws/protocol/xml github.com/aws/smithy-go/encoding/xml github.com/aws/aws-sdk-go-v2/internal/shareddefaults +vendor/golang.org/x/net/http/httpproxy github.com/google/go-containerregistry/pkg/name net/textproto crypto/x509 -vendor/golang.org/x/net/http/httpproxy -github.com/sigstore/sigstore/pkg/signature/payload vendor/golang.org/x/net/http/httpguts mime/multipart +github.com/sigstore/sigstore/pkg/signature/payload +github.com/sigstore/sigstore/pkg/cryptoutils github.com/theupdateframework/go-tuf/v0/pkg/keys gopkg.in/square/go-jose.v2 -github.com/sigstore/sigstore/pkg/cryptoutils -golang.org/x/crypto/ssh github.com/go-jose/go-jose -crypto/tls github.com/sigstore/sigstore/test +crypto/tls +golang.org/x/crypto/ssh github.com/theupdateframework/go-tuf/v0/internal/signer -github.com/theupdateframework/go-tuf/v0/sign github.com/theupdateframework/go-tuf/v0/verify +github.com/theupdateframework/go-tuf/v0/sign github.com/theupdateframework/go-tuf/v0/pkg/targets github.com/theupdateframework/go-tuf/v0 google.golang.org/protobuf/internal/filetype google.golang.org/protobuf/runtime/protoimpl google.golang.org/protobuf/types/known/timestamppb -github.com/tink-crypto/tink-go/proto/tink_go_proto -github.com/tink-crypto/tink-go/proto/common_go_proto github.com/tink-crypto/tink-go/proto/ed25519_go_proto google.golang.org/protobuf/types/descriptorpb +github.com/tink-crypto/tink-go/proto/tink_go_proto +github.com/tink-crypto/tink-go/proto/common_go_proto github.com/tink-crypto/tink-go/proto/ecdsa_go_proto -github.com/tink-crypto/tink-go/core/registry github.com/tink-crypto/tink-go/core/cryptofmt -github.com/tink-crypto/tink-go/internal/primitiveset -github.com/tink-crypto/tink-go/internal/protoserialization +github.com/tink-crypto/tink-go/core/registry github.com/tink-crypto/tink-go/internal/registryconfig github.com/tink-crypto/tink-go/internal/internalregistry +github.com/tink-crypto/tink-go/internal/protoserialization +github.com/tink-crypto/tink-go/internal/primitiveset github.com/tink-crypto/tink-go/keyset google.golang.org/genproto/googleapis/api/annotations -github.com/tink-crypto/tink-go/signature/ed25519 github.com/tink-crypto/tink-go/signature/ecdsa +github.com/tink-crypto/tink-go/signature/ed25519 +github.com/secure-systems-lab/go-securesystemslib/dsse github.com/sigstore/protobuf-specs/gen/pb-go/common/v1 github.com/sigstore/sigstore/pkg/signature/tink -github.com/secure-systems-lab/go-securesystemslib/dsse github.com/sigstore/sigstore/pkg/signature +net/http/httptrace +net/http github.com/sigstore/sigstore/pkg/signature/kms/cliplugin/encoding github.com/sigstore/sigstore/pkg/signature/kms/cliplugin/internal/signerverifier github.com/sigstore/sigstore/pkg/signature/dsse github.com/sigstore/sigstore/pkg/signature/ssh github.com/sigstore/sigstore/pkg/signature/kms/cliplugin github.com/sigstore/sigstore/pkg/signature/kms/cliplugin/handler -net/http/httptrace github.com/sigstore/sigstore/pkg/signature/kms -net/http github.com/sigstore/sigstore/pkg/signature/kms/fake -net/http/httptest github.com/theupdateframework/go-tuf/v0/client -github.com/aws/smithy-go/endpoints +net/http/httptest +golang.org/x/oauth2/internal net/http/httputil +github.com/aws/smithy-go/endpoints github.com/aws/smithy-go/encoding/httpbinding -golang.org/x/oauth2/internal golang.org/x/oauth2 github.com/theupdateframework/go-tuf/v0/client/leveldbstore github.com/aws/smithy-go/transport/http -github.com/coreos/go-oidc/v3/oidc -github.com/sigstore/sigstore/pkg/oauth/internal github.com/sigstore/sigstore/pkg/tuf +github.com/sigstore/sigstore/pkg/oauth/internal +github.com/coreos/go-oidc/v3/oidc github.com/sigstore/sigstore/pkg/oauth/oidc github.com/sigstore/sigstore/pkg/oauthflow -github.com/sigstore/sigstore/pkg/fulcioroots github.com/aws/smithy-go/auth/bearer +github.com/aws/aws-sdk-go-v2/internal/auth +github.com/aws/aws-sdk-go-v2/internal/endpoints/awsrulesfn github.com/aws/aws-sdk-go-v2/aws/protocol/query github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding -github.com/aws/aws-sdk-go-v2/internal/endpoints/awsrulesfn -github.com/aws/aws-sdk-go-v2/internal/auth github.com/aws/smithy-go/private/requestcompression +github.com/sigstore/sigstore/pkg/fulcioroots github.com/aws/aws-sdk-go-v2/aws github.com/aws/aws-sdk-go-v2/credentials github.com/aws/aws-sdk-go-v2/aws/middleware +github.com/aws/aws-sdk-go-v2/credentials/processcreds github.com/aws/aws-sdk-go-v2/aws/defaults -github.com/aws/aws-sdk-go-v2/internal/configsources github.com/aws/aws-sdk-go-v2/aws/signer/internal/v4 -github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 +github.com/aws/aws-sdk-go-v2/internal/configsources github.com/aws/aws-sdk-go-v2/internal/endpoints -github.com/aws/aws-sdk-go-v2/credentials/processcreds +github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 github.com/aws/aws-sdk-go-v2/service/sso/internal/endpoints github.com/aws/aws-sdk-go-v2/service/ssooidc/internal/endpoints github.com/aws/aws-sdk-go-v2/service/sts/internal/endpoints @@ -3006,10 +3042,10 @@ github.com/aws/aws-sdk-go-v2/aws/signer/v4 github.com/aws/aws-sdk-go-v2/internal/auth/smithy github.com/aws/aws-sdk-go-v2/service/internal/presigned-url -github.com/aws/aws-sdk-go-v2/credentials/endpointcreds/internal/client github.com/aws/aws-sdk-go-v2/feature/ec2/imds -github.com/aws/aws-sdk-go-v2/service/ssooidc +github.com/aws/aws-sdk-go-v2/credentials/endpointcreds/internal/client github.com/aws/aws-sdk-go-v2/service/sso +github.com/aws/aws-sdk-go-v2/service/ssooidc github.com/aws/aws-sdk-go-v2/service/sts github.com/aws/aws-sdk-go-v2/service/kms github.com/aws/aws-sdk-go-v2/credentials/endpointcreds @@ -3083,7 +3119,7 @@ === RUN TestMarshalCertificateToPEM/cert1 === RUN TestMarshalCertificateToPEM/cert2 === RUN TestMarshalCertificateToPEM/nil ---- PASS: TestMarshalCertificateToPEM (0.01s) +--- PASS: TestMarshalCertificateToPEM (0.00s) --- PASS: TestMarshalCertificateToPEM/cert1 (0.00s) --- PASS: TestMarshalCertificateToPEM/cert2 (0.00s) --- PASS: TestMarshalCertificateToPEM/nil (0.00s) @@ -3091,9 +3127,9 @@ === RUN TestMarshalCertificatesToPEM/one_cert === RUN TestMarshalCertificatesToPEM/two_certs === RUN TestMarshalCertificatesToPEM/nil_cert ---- PASS: TestMarshalCertificatesToPEM (0.01s) +--- PASS: TestMarshalCertificatesToPEM (0.00s) --- PASS: TestMarshalCertificatesToPEM/one_cert (0.00s) - --- PASS: TestMarshalCertificatesToPEM/two_certs (0.01s) + --- PASS: TestMarshalCertificatesToPEM/two_certs (0.00s) --- PASS: TestMarshalCertificatesToPEM/nil_cert (0.00s) === RUN TestCheckExpiration === RUN TestCheckExpiration/valid @@ -3122,7 +3158,7 @@ === RUN TestRSAPrivateKeyPEMRoundtrip === PAUSE TestRSAPrivateKeyPEMRoundtrip === RUN TestUnmarshalPEMToPrivateKey ---- PASS: TestUnmarshalPEMToPrivateKey (1.12s) +--- PASS: TestUnmarshalPEMToPrivateKey (1.69s) === RUN TestECDSAPublicKeyPEMRoundtrip === PAUSE TestECDSAPublicKeyPEMRoundtrip === RUN TestEd25519PublicKeyPEMRoundtrip @@ -3130,13 +3166,13 @@ === RUN TestRSAPublicKeyPEMRoundtrip === PAUSE TestRSAPublicKeyPEMRoundtrip === RUN TestSKIDRSA ---- PASS: TestSKIDRSA (0.15s) +--- PASS: TestSKIDRSA (0.62s) === RUN TestSKIDECDSA --- PASS: TestSKIDECDSA (0.00s) === RUN TestSKIDED25519 --- PASS: TestSKIDED25519 (0.00s) === RUN TestEqualKeys ---- PASS: TestEqualKeys (1.26s) +--- PASS: TestEqualKeys (0.97s) === RUN TestValidatePubKeyUnsupported --- PASS: TestValidatePubKeyUnsupported (0.00s) === RUN TestValidatePubKeyRsa @@ -3148,7 +3184,7 @@ === RUN TestValidatePubKeyEd25519 --- PASS: TestValidatePubKeyEd25519 (0.00s) === RUN TestUnmarshalPEMToPublicKey ---- PASS: TestUnmarshalPEMToPublicKey (1.60s) +--- PASS: TestUnmarshalPEMToPublicKey (1.06s) === RUN TestMarshalAndUnmarshalOtherNameSAN --- PASS: TestMarshalAndUnmarshalOtherNameSAN (0.00s) === RUN TestUnmarshalOtherNameSANFailures @@ -3164,39 +3200,39 @@ === PAUSE TestGeneratePEMEncodedRSAKeyPair/SkipPassword_func === CONT TestGeneratePEMEncodedRSAKeyPair/encrypted === CONT TestRSAPrivateKeyPEMRoundtrip +=== CONT TestGeneratePEMEncodedRSAKeyPair/SkipPassword_func +=== CONT TestGeneratePEMEncodedRSAKeyPair/nil_pass_func +=== CONT TestEd25519PrivateKeyPEMRoundtrip +--- PASS: TestEd25519PrivateKeyPEMRoundtrip (0.00s) +=== CONT TestECDSAPrivateKeyPEMRoundtrip +--- PASS: TestECDSAPrivateKeyPEMRoundtrip (0.00s) === CONT TestEd25519PublicKeyPEMRoundtrip +--- PASS: TestEd25519PublicKeyPEMRoundtrip (0.00s) === CONT TestRSAPublicKeyPEMRoundtrip === CONT TestGeneratePEMEncodedECDSAKeyPair === RUN TestGeneratePEMEncodedECDSAKeyPair/encrypted +=== CONT TestECDSAPublicKeyPEMRoundtrip === PAUSE TestGeneratePEMEncodedECDSAKeyPair/encrypted === RUN TestGeneratePEMEncodedECDSAKeyPair/nil_pass_func === PAUSE TestGeneratePEMEncodedECDSAKeyPair/nil_pass_func +--- PASS: TestECDSAPublicKeyPEMRoundtrip (0.00s) === RUN TestGeneratePEMEncodedECDSAKeyPair/SkipPassword_func === PAUSE TestGeneratePEMEncodedECDSAKeyPair/SkipPassword_func === CONT TestGeneratePEMEncodedECDSAKeyPair/encrypted -=== CONT TestGeneratePEMEncodedRSAKeyPair/SkipPassword_func ---- PASS: TestEd25519PublicKeyPEMRoundtrip (0.00s) -=== CONT TestECDSAPrivateKeyPEMRoundtrip -=== CONT TestECDSAPublicKeyPEMRoundtrip === CONT TestGeneratePEMEncodedECDSAKeyPair/nil_pass_func -=== CONT TestEd25519PrivateKeyPEMRoundtrip ---- PASS: TestECDSAPrivateKeyPEMRoundtrip (0.00s) -=== CONT TestGeneratePEMEncodedRSAKeyPair/nil_pass_func ---- PASS: TestEd25519PrivateKeyPEMRoundtrip (0.00s) ---- PASS: TestECDSAPublicKeyPEMRoundtrip (0.00s) === CONT TestGeneratePEMEncodedECDSAKeyPair/SkipPassword_func ---- PASS: TestRSAPrivateKeyPEMRoundtrip (0.26s) +--- PASS: TestRSAPrivateKeyPEMRoundtrip (0.36s) +--- PASS: TestRSAPublicKeyPEMRoundtrip (0.55s) --- PASS: TestGeneratePEMEncodedECDSAKeyPair (0.00s) --- PASS: TestGeneratePEMEncodedECDSAKeyPair/nil_pass_func (0.00s) --- PASS: TestGeneratePEMEncodedECDSAKeyPair/SkipPassword_func (0.00s) - --- PASS: TestGeneratePEMEncodedECDSAKeyPair/encrypted (0.53s) + --- PASS: TestGeneratePEMEncodedECDSAKeyPair/encrypted (0.59s) --- PASS: TestGeneratePEMEncodedRSAKeyPair (0.00s) - --- PASS: TestGeneratePEMEncodedRSAKeyPair/nil_pass_func (0.51s) - --- PASS: TestGeneratePEMEncodedRSAKeyPair/SkipPassword_func (0.86s) - --- PASS: TestGeneratePEMEncodedRSAKeyPair/encrypted (1.38s) ---- PASS: TestRSAPublicKeyPEMRoundtrip (1.57s) + --- PASS: TestGeneratePEMEncodedRSAKeyPair/SkipPassword_func (0.47s) + --- PASS: TestGeneratePEMEncodedRSAKeyPair/encrypted (0.90s) + --- PASS: TestGeneratePEMEncodedRSAKeyPair/nil_pass_func (1.04s) PASS -ok github.com/sigstore/sigstore/pkg/cryptoutils 5.750s +ok github.com/sigstore/sigstore/pkg/cryptoutils 5.420s ? github.com/sigstore/sigstore/pkg/fulcioroots [no test files] ? github.com/sigstore/sigstore/pkg/oauth [no test files] === RUN TestParseAccessTokenSuccessResponse @@ -3251,33 +3287,33 @@ --- PASS: TestStaticTokenGetter_GetIDToken/verified (0.00s) --- PASS: TestStaticTokenGetter_GetIDToken/spiffeid (0.00s) === RUN TestSubjectFromToken +=== RUN TestSubjectFromToken/Subject_as_subject === RUN TestSubjectFromToken/no_email_or_subject === RUN TestSubjectFromToken/Email_as_subject === RUN TestSubjectFromToken/String_email_verified_value === RUN TestSubjectFromToken/Email_not_verified === RUN TestSubjectFromToken/invalid_email_verified_property -=== RUN TestSubjectFromToken/Subject_as_subject --- PASS: TestSubjectFromToken (0.00s) + --- PASS: TestSubjectFromToken/Subject_as_subject (0.00s) --- PASS: TestSubjectFromToken/no_email_or_subject (0.00s) --- PASS: TestSubjectFromToken/Email_as_subject (0.00s) --- PASS: TestSubjectFromToken/String_email_verified_value (0.00s) --- PASS: TestSubjectFromToken/Email_not_verified (0.00s) --- PASS: TestSubjectFromToken/invalid_email_verified_property (0.00s) - --- PASS: TestSubjectFromToken/Subject_as_subject (0.00s) === RUN TestSubjectFromUnverifiedToken +=== RUN TestSubjectFromUnverifiedToken/Subject_as_subject === RUN TestSubjectFromUnverifiedToken/no_email_or_subject === RUN TestSubjectFromUnverifiedToken/Email_as_subject === RUN TestSubjectFromUnverifiedToken/String_email_verified_value === RUN TestSubjectFromUnverifiedToken/Email_not_verified === RUN TestSubjectFromUnverifiedToken/invalid_email_verified_property -=== RUN TestSubjectFromUnverifiedToken/Subject_as_subject --- PASS: TestSubjectFromUnverifiedToken (0.00s) + --- PASS: TestSubjectFromUnverifiedToken/Subject_as_subject (0.00s) --- PASS: TestSubjectFromUnverifiedToken/no_email_or_subject (0.00s) --- PASS: TestSubjectFromUnverifiedToken/Email_as_subject (0.00s) --- PASS: TestSubjectFromUnverifiedToken/String_email_verified_value (0.00s) --- PASS: TestSubjectFromUnverifiedToken/Email_not_verified (0.00s) --- PASS: TestSubjectFromUnverifiedToken/invalid_email_verified_property (0.00s) - --- PASS: TestSubjectFromUnverifiedToken/Subject_as_subject (0.00s) === RUN TestInteractiveFlow_IO === RUN TestInteractiveFlow_IO/default === RUN TestInteractiveFlow_IO/buffer @@ -3289,7 +3325,7 @@ === RUN TestGetAlgorithmDetails --- PASS: TestGetAlgorithmDetails (0.00s) === RUN TestAlgorithmRegistryConfig ---- PASS: TestAlgorithmRegistryConfig (1.97s) +--- PASS: TestAlgorithmRegistryConfig (16.36s) === RUN TestSignatureAlgorithmFlagRoundtrip --- PASS: TestSignatureAlgorithmFlagRoundtrip (0.00s) === RUN TestGetDefaultPublicKeyDetails @@ -3299,13 +3335,13 @@ === RUN TestGetDefaultPublicKeyDetails/ed25519 === RUN TestGetDefaultPublicKeyDetails/ed25519-ph === RUN TestGetDefaultPublicKeyDetails/rsa-2048-pss ---- PASS: TestGetDefaultPublicKeyDetails (0.91s) +--- PASS: TestGetDefaultPublicKeyDetails (0.47s) --- PASS: TestGetDefaultPublicKeyDetails/ecdsa-p256 (0.00s) --- PASS: TestGetDefaultPublicKeyDetails/ecdsa-p384 (0.00s) - --- PASS: TestGetDefaultPublicKeyDetails/rsa-2048 (0.50s) + --- PASS: TestGetDefaultPublicKeyDetails/rsa-2048 (0.11s) --- PASS: TestGetDefaultPublicKeyDetails/ed25519 (0.00s) --- PASS: TestGetDefaultPublicKeyDetails/ed25519-ph (0.00s) - --- PASS: TestGetDefaultPublicKeyDetails/rsa-2048-pss (0.41s) + --- PASS: TestGetDefaultPublicKeyDetails/rsa-2048-pss (0.36s) === RUN TestHashingAlgorithmMatches --- PASS: TestHashingAlgorithmMatches (0.00s) === RUN TestECDSASignerVerifier @@ -3343,9 +3379,9 @@ === RUN TestLoadDefaultSigner/ecdsa-p256 === RUN TestLoadDefaultSigner/ed25519 === RUN TestLoadDefaultSigner/ed25519-ph ---- PASS: TestLoadDefaultSigner (1.33s) - --- PASS: TestLoadDefaultSigner/rsa-2048 (0.98s) - --- PASS: TestLoadDefaultSigner/rsa-2048-pss (0.34s) +--- PASS: TestLoadDefaultSigner (1.21s) + --- PASS: TestLoadDefaultSigner/rsa-2048 (0.27s) + --- PASS: TestLoadDefaultSigner/rsa-2048-pss (0.95s) --- PASS: TestLoadDefaultSigner/ecdsa-p256 (0.00s) --- PASS: TestLoadDefaultSigner/ed25519 (0.00s) --- PASS: TestLoadDefaultSigner/ed25519-ph (0.00s) @@ -3359,36 +3395,36 @@ === RUN TestLoadDefaultSignerVerifier/ecdsa-p256 === RUN TestLoadDefaultSignerVerifier/ed25519 === RUN TestLoadDefaultSignerVerifier/ed25519-ph ---- PASS: TestLoadDefaultSignerVerifier (1.19s) - --- PASS: TestLoadDefaultSignerVerifier/rsa-2048 (0.99s) - --- PASS: TestLoadDefaultSignerVerifier/rsa-2048-pss (0.20s) +--- PASS: TestLoadDefaultSignerVerifier (0.55s) + --- PASS: TestLoadDefaultSignerVerifier/rsa-2048 (0.39s) + --- PASS: TestLoadDefaultSignerVerifier/rsa-2048-pss (0.15s) --- PASS: TestLoadDefaultSignerVerifier/ecdsa-p256 (0.00s) --- PASS: TestLoadDefaultSignerVerifier/ed25519 (0.00s) --- PASS: TestLoadDefaultSignerVerifier/ed25519-ph (0.00s) === RUN TestProviderRoundtrip === RUN TestProviderRoundtrip/ECDSA === RUN TestProviderRoundtrip/RSA ---- PASS: TestProviderRoundtrip (0.57s) +--- PASS: TestProviderRoundtrip (1.53s) --- PASS: TestProviderRoundtrip/ECDSA (0.00s) - --- PASS: TestProviderRoundtrip/RSA (0.01s) + --- PASS: TestProviderRoundtrip/RSA (0.00s) === RUN TestLoadUnsafeVerifier ---- PASS: TestLoadUnsafeVerifier (0.23s) +--- PASS: TestLoadUnsafeVerifier (0.19s) === RUN TestLoadVerifier ---- PASS: TestLoadVerifier (0.28s) +--- PASS: TestLoadVerifier (0.29s) === RUN TestLoadDefaultVerifier === RUN TestLoadDefaultVerifier/rsa-2048 === RUN TestLoadDefaultVerifier/rsa-2048-pss === RUN TestLoadDefaultVerifier/ecdsa-p256 === RUN TestLoadDefaultVerifier/ed25519 === RUN TestLoadDefaultVerifier/ed25519-ph ---- PASS: TestLoadDefaultVerifier (1.14s) - --- PASS: TestLoadDefaultVerifier/rsa-2048 (0.59s) - --- PASS: TestLoadDefaultVerifier/rsa-2048-pss (0.55s) +--- PASS: TestLoadDefaultVerifier (0.85s) + --- PASS: TestLoadDefaultVerifier/rsa-2048 (0.60s) + --- PASS: TestLoadDefaultVerifier/rsa-2048-pss (0.25s) --- PASS: TestLoadDefaultVerifier/ecdsa-p256 (0.00s) --- PASS: TestLoadDefaultVerifier/ed25519 (0.00s) --- PASS: TestLoadDefaultVerifier/ed25519-ph (0.00s) PASS -ok github.com/sigstore/sigstore/pkg/signature 7.758s +ok github.com/sigstore/sigstore/pkg/signature 21.598s === RUN TestImplementsDSSESigner --- PASS: TestImplementsDSSESigner (0.00s) === RUN TestImplementsDSSEVerifier @@ -3402,7 +3438,7 @@ === RUN TestInvalidSignature --- PASS: TestInvalidSignature (0.00s) PASS -ok github.com/sigstore/sigstore/pkg/signature/dsse 0.018s +ok github.com/sigstore/sigstore/pkg/signature/dsse 0.014s === RUN TestGet === PAUSE TestGet === CONT TestGet @@ -3416,15 +3452,15 @@ === PAUSE TestGet/successful_provider === CONT TestGet/cliplugin === CONT TestGet/file_path -=== CONT TestGet/registered_provider_error === CONT TestGet/successful_provider +=== CONT TestGet/registered_provider_error --- PASS: TestGet (0.00s) --- PASS: TestGet/cliplugin (0.00s) --- PASS: TestGet/file_path (0.00s) --- PASS: TestGet/successful_provider (0.00s) --- PASS: TestGet/registered_provider_error (0.00s) PASS -ok github.com/sigstore/sigstore/pkg/signature/kms 0.016s +ok github.com/sigstore/sigstore/pkg/signature/kms 0.013s === RUN TestParseReference === RUN TestParseReference/awskms:///1234abcd-12ab-34cd-56ef-1234567890ab === RUN TestParseReference/awskms:///mrk-1234abcd12ab34cd56ef1234567890ab @@ -3458,7 +3494,7 @@ --- PASS: TestParseReference/awskms:///1234abcd-12ab-YYYY-56ef-1234567890ab (0.00s) --- PASS: TestParseReference/awskms://1234abcd-12ab-34cd-56ef-1234567890ab (0.00s) PASS -ok github.com/sigstore/sigstore/pkg/signature/kms/aws 0.023s +ok github.com/sigstore/sigstore/pkg/signature/kms/aws 0.019s === RUN TestInvokePlugin === RUN TestInvokePlugin/success === RUN TestInvokePlugin/success:_expected_stdin @@ -3497,22 +3533,22 @@ === RUN TestPluginClient/CryptoSigner === PAUSE TestPluginClient/CryptoSigner === CONT TestPluginClient/DefaultAlgorithm -=== CONT TestPluginClient/SupportedAlgorithms === CONT TestPluginClient/SignMessage -=== CONT TestPluginClient/CreateKey +=== CONT TestPluginClient/SupportedAlgorithms === CONT TestPluginClient/PublicKey -=== CONT TestPluginClient/CryptoSigner === CONT TestPluginClient/VerifySignature +=== CONT TestPluginClient/CreateKey +=== CONT TestPluginClient/CryptoSigner --- PASS: TestPluginClient (0.00s) --- PASS: TestPluginClient/DefaultAlgorithm (0.00s) --- PASS: TestPluginClient/SupportedAlgorithms (0.00s) - --- PASS: TestPluginClient/CreateKey (0.00s) + --- PASS: TestPluginClient/SignMessage (0.00s) --- PASS: TestPluginClient/CryptoSigner (0.00s) --- PASS: TestPluginClient/PublicKey (0.00s) - --- PASS: TestPluginClient/SignMessage (0.00s) + --- PASS: TestPluginClient/CreateKey (0.00s) --- PASS: TestPluginClient/VerifySignature (0.00s) PASS -ok github.com/sigstore/sigstore/pkg/signature/kms/cliplugin 0.028s +ok github.com/sigstore/sigstore/pkg/signature/kms/cliplugin 0.021s === RUN TestPluginArgsJSON === PAUSE TestPluginArgsJSON === RUN TestPluginRespJSON @@ -3524,131 +3560,131 @@ === CONT TestHashFuncJSON === RUN TestHashFuncJSON/MD4 === PAUSE TestHashFuncJSON/MD4 -=== CONT TestPluginRespJSON -=== RUN TestPluginRespJSON/defaultAlgorithm === RUN TestHashFuncJSON/MD5 === PAUSE TestHashFuncJSON/MD5 -=== PAUSE TestPluginArgsJSON/defaultAlgorithm === RUN TestHashFuncJSON/SHA-1 === PAUSE TestHashFuncJSON/SHA-1 === RUN TestHashFuncJSON/SHA-224 === PAUSE TestHashFuncJSON/SHA-224 === RUN TestHashFuncJSON/SHA-256 +=== CONT TestPluginRespJSON +=== RUN TestPluginRespJSON/defaultAlgorithm +=== PAUSE TestPluginArgsJSON/defaultAlgorithm +=== PAUSE TestPluginRespJSON/defaultAlgorithm === RUN TestPluginArgsJSON/supportedAlgorithms -=== PAUSE TestHashFuncJSON/SHA-256 +=== RUN TestPluginRespJSON/supportedAlgorithms === PAUSE TestPluginArgsJSON/supportedAlgorithms -=== RUN TestHashFuncJSON/SHA-384 +=== PAUSE TestHashFuncJSON/SHA-256 === RUN TestPluginArgsJSON/createKey -=== PAUSE TestPluginArgsJSON/createKey -=== RUN TestPluginArgsJSON/publicKey -=== PAUSE TestHashFuncJSON/SHA-384 -=== PAUSE TestPluginArgsJSON/publicKey -=== PAUSE TestPluginRespJSON/defaultAlgorithm -=== RUN TestPluginRespJSON/supportedAlgorithms +=== RUN TestHashFuncJSON/SHA-384 === PAUSE TestPluginRespJSON/supportedAlgorithms === RUN TestPluginRespJSON/createKey +=== PAUSE TestHashFuncJSON/SHA-384 +=== PAUSE TestPluginRespJSON/createKey +=== RUN TestPluginRespJSON/publicKey +=== PAUSE TestPluginRespJSON/publicKey +=== PAUSE TestPluginArgsJSON/createKey +=== RUN TestPluginRespJSON/signMessage === RUN TestHashFuncJSON/SHA-512 +=== RUN TestPluginArgsJSON/publicKey +=== PAUSE TestPluginRespJSON/signMessage === PAUSE TestHashFuncJSON/SHA-512 -=== RUN TestHashFuncJSON/MD5+SHA1 -=== PAUSE TestHashFuncJSON/MD5+SHA1 +=== PAUSE TestPluginArgsJSON/publicKey === RUN TestPluginArgsJSON/signMessage +=== RUN TestHashFuncJSON/MD5+SHA1 === PAUSE TestPluginArgsJSON/signMessage +=== PAUSE TestHashFuncJSON/MD5+SHA1 === RUN TestPluginArgsJSON/verifySignature === PAUSE TestPluginArgsJSON/verifySignature -=== PAUSE TestPluginRespJSON/createKey -=== CONT TestPluginArgsJSON/publicKey -=== RUN TestPluginRespJSON/publicKey +=== CONT TestPluginArgsJSON/defaultAlgorithm +=== CONT TestPluginArgsJSON/signMessage +=== CONT TestPluginArgsJSON/createKey +=== CONT TestPluginArgsJSON/supportedAlgorithms +=== RUN TestPluginRespJSON/verifySignature +=== PAUSE TestPluginRespJSON/verifySignature === RUN TestHashFuncJSON/RIPEMD-160 -=== CONT TestPluginArgsJSON/verifySignature +=== CONT TestPluginRespJSON/defaultAlgorithm === PAUSE TestHashFuncJSON/RIPEMD-160 === RUN TestHashFuncJSON/SHA3-224 === PAUSE TestHashFuncJSON/SHA3-224 === RUN TestHashFuncJSON/SHA3-256 +=== CONT TestPluginArgsJSON/publicKey +=== CONT TestPluginRespJSON/signMessage +=== CONT TestPluginRespJSON/createKey +=== CONT TestPluginRespJSON/publicKey +=== CONT TestPluginArgsJSON/verifySignature === PAUSE TestHashFuncJSON/SHA3-256 -=== CONT TestPluginArgsJSON/defaultAlgorithm -=== PAUSE TestPluginRespJSON/publicKey -=== RUN TestPluginRespJSON/signMessage -=== CONT TestPluginArgsJSON/createKey -=== CONT TestPluginArgsJSON/supportedAlgorithms -=== CONT TestPluginArgsJSON/signMessage === RUN TestHashFuncJSON/SHA3-384 === PAUSE TestHashFuncJSON/SHA3-384 -=== PAUSE TestPluginRespJSON/signMessage -=== RUN TestPluginRespJSON/verifySignature -=== PAUSE TestPluginRespJSON/verifySignature === RUN TestHashFuncJSON/SHA3-512 -=== CONT TestPluginRespJSON/defaultAlgorithm === PAUSE TestHashFuncJSON/SHA3-512 -=== CONT TestPluginRespJSON/verifySignature === RUN TestHashFuncJSON/SHA-512/224 -=== CONT TestPluginRespJSON/createKey -=== CONT TestPluginRespJSON/signMessage === PAUSE TestHashFuncJSON/SHA-512/224 -=== CONT TestPluginRespJSON/supportedAlgorithms === RUN TestHashFuncJSON/SHA-512/256 === PAUSE TestHashFuncJSON/SHA-512/256 +=== CONT TestPluginRespJSON/verifySignature === RUN TestHashFuncJSON/BLAKE2s-256 -=== CONT TestPluginRespJSON/publicKey === PAUSE TestHashFuncJSON/BLAKE2s-256 +=== CONT TestPluginRespJSON/supportedAlgorithms === RUN TestHashFuncJSON/BLAKE2b-256 === PAUSE TestHashFuncJSON/BLAKE2b-256 === RUN TestHashFuncJSON/BLAKE2b-384 +--- PASS: TestPluginRespJSON (0.00s) + --- PASS: TestPluginRespJSON/defaultAlgorithm (0.00s) + --- PASS: TestPluginRespJSON/publicKey (0.00s) + --- PASS: TestPluginRespJSON/createKey (0.00s) + --- PASS: TestPluginRespJSON/verifySignature (0.00s) + --- PASS: TestPluginRespJSON/signMessage (0.00s) + --- PASS: TestPluginRespJSON/supportedAlgorithms (0.00s) === PAUSE TestHashFuncJSON/BLAKE2b-384 === RUN TestHashFuncJSON/BLAKE2b-512 === PAUSE TestHashFuncJSON/BLAKE2b-512 === CONT TestHashFuncJSON/MD4 === CONT TestHashFuncJSON/SHA3-256 -=== CONT TestHashFuncJSON/SHA3-224 -=== CONT TestHashFuncJSON/RIPEMD-160 -=== CONT TestHashFuncJSON/BLAKE2b-512 -=== CONT TestHashFuncJSON/MD5+SHA1 -=== CONT TestHashFuncJSON/BLAKE2b-384 --- PASS: TestPluginArgsJSON (0.00s) - --- PASS: TestPluginArgsJSON/verifySignature (0.00s) - --- PASS: TestPluginArgsJSON/defaultAlgorithm (0.00s) - --- PASS: TestPluginArgsJSON/publicKey (0.00s) - --- PASS: TestPluginArgsJSON/createKey (0.00s) --- PASS: TestPluginArgsJSON/signMessage (0.00s) --- PASS: TestPluginArgsJSON/supportedAlgorithms (0.00s) -=== CONT TestHashFuncJSON/SHA-512 + --- PASS: TestPluginArgsJSON/defaultAlgorithm (0.00s) + --- PASS: TestPluginArgsJSON/createKey (0.00s) + --- PASS: TestPluginArgsJSON/verifySignature (0.00s) + --- PASS: TestPluginArgsJSON/publicKey (0.00s) +=== CONT TestHashFuncJSON/MD5 +=== CONT TestHashFuncJSON/SHA3-224 === CONT TestHashFuncJSON/SHA-384 -=== CONT TestHashFuncJSON/SHA3-384 +=== CONT TestHashFuncJSON/MD5+SHA1 === CONT TestHashFuncJSON/SHA-256 === CONT TestHashFuncJSON/SHA-224 -=== CONT TestHashFuncJSON/SHA-1 -=== CONT TestHashFuncJSON/MD5 +=== CONT TestHashFuncJSON/BLAKE2s-256 +=== CONT TestHashFuncJSON/RIPEMD-160 === CONT TestHashFuncJSON/SHA-512/256 -=== CONT TestHashFuncJSON/SHA-512/224 +=== CONT TestHashFuncJSON/SHA-512 +=== CONT TestHashFuncJSON/BLAKE2b-384 === CONT TestHashFuncJSON/BLAKE2b-256 -=== CONT TestHashFuncJSON/BLAKE2s-256 +=== CONT TestHashFuncJSON/BLAKE2b-512 === CONT TestHashFuncJSON/SHA3-512 ---- PASS: TestPluginRespJSON (0.00s) - --- PASS: TestPluginRespJSON/defaultAlgorithm (0.00s) - --- PASS: TestPluginRespJSON/publicKey (0.00s) - --- PASS: TestPluginRespJSON/createKey (0.00s) - --- PASS: TestPluginRespJSON/verifySignature (0.00s) - --- PASS: TestPluginRespJSON/supportedAlgorithms (0.00s) - --- PASS: TestPluginRespJSON/signMessage (0.00s) +=== CONT TestHashFuncJSON/SHA-1 +=== CONT TestHashFuncJSON/SHA-512/224 +=== CONT TestHashFuncJSON/SHA3-384 --- PASS: TestHashFuncJSON (0.00s) --- PASS: TestHashFuncJSON/MD4 (0.00s) - --- PASS: TestHashFuncJSON/SHA3-224 (0.00s) + --- PASS: TestHashFuncJSON/MD5 (0.00s) --- PASS: TestHashFuncJSON/SHA3-256 (0.00s) - --- PASS: TestHashFuncJSON/RIPEMD-160 (0.00s) - --- PASS: TestHashFuncJSON/MD5+SHA1 (0.00s) - --- PASS: TestHashFuncJSON/BLAKE2b-512 (0.00s) - --- PASS: TestHashFuncJSON/BLAKE2b-384 (0.00s) - --- PASS: TestHashFuncJSON/SHA-512 (0.00s) - --- PASS: TestHashFuncJSON/SHA3-384 (0.00s) --- PASS: TestHashFuncJSON/SHA-384 (0.00s) + --- PASS: TestHashFuncJSON/SHA3-224 (0.00s) --- PASS: TestHashFuncJSON/SHA-256 (0.00s) + --- PASS: TestHashFuncJSON/MD5+SHA1 (0.00s) --- PASS: TestHashFuncJSON/SHA-224 (0.00s) - --- PASS: TestHashFuncJSON/SHA-1 (0.00s) - --- PASS: TestHashFuncJSON/MD5 (0.00s) + --- PASS: TestHashFuncJSON/BLAKE2s-256 (0.00s) --- PASS: TestHashFuncJSON/SHA-512/256 (0.00s) - --- PASS: TestHashFuncJSON/SHA-512/224 (0.00s) + --- PASS: TestHashFuncJSON/RIPEMD-160 (0.00s) + --- PASS: TestHashFuncJSON/SHA-512 (0.00s) + --- PASS: TestHashFuncJSON/BLAKE2b-384 (0.00s) --- PASS: TestHashFuncJSON/BLAKE2b-256 (0.00s) - --- PASS: TestHashFuncJSON/BLAKE2s-256 (0.00s) + --- PASS: TestHashFuncJSON/BLAKE2b-512 (0.00s) --- PASS: TestHashFuncJSON/SHA3-512 (0.00s) + --- PASS: TestHashFuncJSON/SHA-1 (0.00s) + --- PASS: TestHashFuncJSON/SHA-512/224 (0.00s) + --- PASS: TestHashFuncJSON/SHA3-384 (0.00s) PASS ok github.com/sigstore/sigstore/pkg/signature/kms/cliplugin/common 0.010s === RUN TestPackRPCOptions @@ -3674,25 +3710,25 @@ === CONT TestPackRPCOptions === CONT TestUnpackPublicKeyOptions === CONT TestPackVerifyOptions -=== CONT TestPackPublicKeyOptions -=== CONT TestUnpackMessageOptions ---- PASS: TestUnpackMessageOptions (0.00s) -=== CONT TestUnpackSignOptions === CONT TestPackMessageOptions ---- PASS: TestPackRPCOptions (0.00s) +--- PASS: TestPackMessageOptions (0.00s) +=== CONT TestUnpackRPCOptions --- PASS: TestUnpackPublicKeyOptions (0.00s) ---- PASS: TestPackPublicKeyOptions (0.00s) -=== CONT TestUnpackVerifyOptions +=== CONT TestUnpackSignOptions +--- PASS: TestUnpackRPCOptions (0.00s) +=== CONT TestPackPublicKeyOptions --- PASS: TestPackVerifyOptions (0.00s) ---- PASS: TestUnpackSignOptions (0.00s) +--- PASS: TestPackPublicKeyOptions (0.00s) === CONT TestPackSignOptions -=== CONT TestUnpackRPCOptions ---- PASS: TestPackMessageOptions (0.00s) ---- PASS: TestUnpackVerifyOptions (0.00s) +--- PASS: TestUnpackSignOptions (0.00s) +--- PASS: TestPackRPCOptions (0.00s) +=== CONT TestUnpackVerifyOptions --- PASS: TestPackSignOptions (0.00s) ---- PASS: TestUnpackRPCOptions (0.00s) +--- PASS: TestUnpackVerifyOptions (0.00s) +=== CONT TestUnpackMessageOptions +--- PASS: TestUnpackMessageOptions (0.00s) PASS -ok github.com/sigstore/sigstore/pkg/signature/kms/cliplugin/encoding 0.015s +ok github.com/sigstore/sigstore/pkg/signature/kms/cliplugin/encoding 0.018s ? github.com/sigstore/sigstore/pkg/signature/kms/cliplugin/handler [no test files] ? github.com/sigstore/sigstore/pkg/signature/kms/cliplugin/internal/signerverifier [no test files] === RUN TestFakeSigner @@ -3700,14 +3736,13 @@ === RUN TestFakeSignerWithPrivateKey --- PASS: TestFakeSignerWithPrivateKey (0.00s) PASS -ok github.com/sigstore/sigstore/pkg/signature/kms/fake 0.013s +ok github.com/sigstore/sigstore/pkg/signature/kms/fake 0.016s ? github.com/sigstore/sigstore/pkg/signature/options [no test files] === RUN TestMarshalCosign === PAUSE TestMarshalCosign === RUN TestUnmarshalCosign === PAUSE TestUnmarshalCosign === CONT TestMarshalCosign -=== CONT TestUnmarshalCosign === RUN TestMarshalCosign/no_claims === PAUSE TestMarshalCosign/no_claims === RUN TestMarshalCosign/standard_atomic_signature @@ -3717,29 +3752,30 @@ === RUN TestMarshalCosign/custom_identity === PAUSE TestMarshalCosign/custom_identity === CONT TestMarshalCosign/no_claims -=== CONT TestMarshalCosign/arbitrary_claims -=== CONT TestMarshalCosign/custom_identity +=== CONT TestUnmarshalCosign === RUN TestUnmarshalCosign/no_claims -=== CONT TestMarshalCosign/standard_atomic_signature === PAUSE TestUnmarshalCosign/no_claims === RUN TestUnmarshalCosign/arbitrary_claims ---- PASS: TestMarshalCosign (0.00s) - --- PASS: TestMarshalCosign/no_claims (0.00s) - --- PASS: TestMarshalCosign/standard_atomic_signature (0.00s) - --- PASS: TestMarshalCosign/arbitrary_claims (0.00s) - --- PASS: TestMarshalCosign/custom_identity (0.00s) === PAUSE TestUnmarshalCosign/arbitrary_claims === RUN TestUnmarshalCosign/unknown_type === PAUSE TestUnmarshalCosign/unknown_type === CONT TestUnmarshalCosign/no_claims -=== CONT TestUnmarshalCosign/unknown_type +=== CONT TestMarshalCosign/arbitrary_claims +=== CONT TestMarshalCosign/standard_atomic_signature +=== CONT TestMarshalCosign/custom_identity +--- PASS: TestMarshalCosign (0.00s) + --- PASS: TestMarshalCosign/no_claims (0.00s) + --- PASS: TestMarshalCosign/arbitrary_claims (0.00s) + --- PASS: TestMarshalCosign/standard_atomic_signature (0.00s) + --- PASS: TestMarshalCosign/custom_identity (0.00s) === CONT TestUnmarshalCosign/arbitrary_claims +=== CONT TestUnmarshalCosign/unknown_type --- PASS: TestUnmarshalCosign (0.00s) --- PASS: TestUnmarshalCosign/no_claims (0.00s) - --- PASS: TestUnmarshalCosign/unknown_type (0.00s) --- PASS: TestUnmarshalCosign/arbitrary_claims (0.00s) + --- PASS: TestUnmarshalCosign/unknown_type (0.00s) PASS -ok github.com/sigstore/sigstore/pkg/signature/payload 0.010s +ok github.com/sigstore/sigstore/pkg/signature/payload 0.011s === RUN TestFromOpenSSH sign_test.go:154: skip TestFromOpenSSH: missing ssh-keygen in PATH --- SKIP: TestFromOpenSSH (0.00s) @@ -3753,21 +3789,21 @@ --- PASS: TestRoundTrip/rsa (0.03s) --- PASS: TestRoundTrip/ed25519 (0.01s) PASS -ok github.com/sigstore/sigstore/pkg/signature/ssh 0.102s +ok github.com/sigstore/sigstore/pkg/signature/ssh 0.098s === RUN TestKeyHandleToSignerECDSA === RUN TestKeyHandleToSignerECDSA/ECDSA-P256-SHA256 === RUN TestKeyHandleToSignerECDSA/ECDSA-P384-SHA512 === RUN TestKeyHandleToSignerECDSA/ECDSA-P521-SHA512 ---- PASS: TestKeyHandleToSignerECDSA (0.08s) +--- PASS: TestKeyHandleToSignerECDSA (0.05s) --- PASS: TestKeyHandleToSignerECDSA/ECDSA-P256-SHA256 (0.00s) --- PASS: TestKeyHandleToSignerECDSA/ECDSA-P384-SHA512 (0.02s) - --- PASS: TestKeyHandleToSignerECDSA/ECDSA-P521-SHA512 (0.06s) + --- PASS: TestKeyHandleToSignerECDSA/ECDSA-P521-SHA512 (0.03s) === RUN TestKeyHandleToSignerED25519 --- PASS: TestKeyHandleToSignerED25519 (0.01s) === RUN TestKeyHandleToSignerFailsWithInvalidKeyType ---- PASS: TestKeyHandleToSignerFailsWithInvalidKeyType (1.09s) +--- PASS: TestKeyHandleToSignerFailsWithInvalidKeyType (1.91s) PASS -ok github.com/sigstore/sigstore/pkg/signature/tink 1.194s +ok github.com/sigstore/sigstore/pkg/signature/tink 1.972s === RUN TestMarshalStatusType --- PASS: TestMarshalStatusType (0.00s) === RUN TestMarshalInvalidStatusType @@ -3791,7 +3827,7 @@ PASS ok github.com/sigstore/sigstore/pkg/tuf 0.014s ? github.com/sigstore/sigstore/test [no test files] - rm -fr -- /tmp/dh-xdg-rundir-kjqTCD5u + rm -fr -- /tmp/dh-xdg-rundir-y1IkrSJp rm -rf /build/reproducible-path/golang-github-sigstore-sigstore-1.9.5/debian/tmp-home make[1]: Leaving directory '/build/reproducible-path/golang-github-sigstore-sigstore-1.9.5' create-stamp debian/debhelper-build-stamp @@ -3821,12 +3857,14 @@ dpkg-buildpackage: info: binary-only upload (no source included) dpkg-genchanges: info: including full source code in upload I: copying local configuration +I: user script /srv/workspace/pbuilder/1998787/tmp/hooks/B01_cleanup starting +I: user script /srv/workspace/pbuilder/1998787/tmp/hooks/B01_cleanup finished I: unmounting dev/ptmx filesystem I: unmounting dev/pts filesystem I: unmounting dev/shm filesystem I: unmounting proc filesystem I: unmounting sys filesystem I: cleaning the build env -I: removing directory /srv/workspace/pbuilder/2558516 and its subdirectories -I: Current time: Wed Aug 20 00:34:36 -12 2025 -I: pbuilder-time-stamp: 1755693276 +I: removing directory /srv/workspace/pbuilder/1998787 and its subdirectories +I: Current time: Wed Sep 23 08:59:59 +14 2026 +I: pbuilder-time-stamp: 1790103599