Re: [RFC] Reproducible Builds Support
| From: | Jordi Boggiano | Date: | Fri, 15 Dec 2017 10:13:45 +0000 |
| Subject: | Re: [RFC] Reproducible Builds Support | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-101356@lists.php.net to get a copy of this message | ||
On 2017-12-14 10:02 AM, Jelle van der Waa wrote:
I have had similar issues with Phar files when I tried to make Composer builds reproducible. The cause is that the Phar extension uses the current unix timestamp as filemtime for all files in the table of content (at least when using addFromString), so every time you build the TOC is different and hence the signature at the end also is. I built a tool to fix this which just overwrites the TOC timestamps with whatever you want and then updates the signature.. If it helps, you can find it there: https://github.com/Seldaek/phar-utils Example usage in Composer: https://github.com/composer/composer/blob/84f5a1a7e8293978a718663dfac399e83f093e9e/src/Composer/Compiler.php#L161-L164 I guess an alternative fix would be for someone to actually fix the Phar extension so addFromString has a filemtime parameter you can pass the desired mtime to. I have not checked whether addFile suffers from the same issue or not, but possibly it needs to be fixed to read the mtime from the file you add. Best, Jordi -- Jordi Boggiano @seldaek - http://seld.beThanks for the information, I'll see if I can do some more digging.The last issue is phar.phar being non-reproducible of which I am not sure what the issue would be. I'm not sure how the binary data in the phar.phar is generated.Phars are liketarsthat are also valid PHP files. This means there are probably modification times, etc, set in there. Not sure what else would need to be changed.