Your message dated Sun, 28 Dec 2025 22:19:13 +0000
with message-id <[email protected]>
and subject line Bug#1122824: fixed in golang-github-google-go-attestation
0.6.0-1
has caused the Debian Bug report #1122824,
regarding golang-github-google-go-attestation: please make the build
reproducible
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1122824: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1122824
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: golang-github-google-go-attestation
Version: 0.5.1-2
Severity: wishlist
Tags: patch
User: [email protected]
Usertags: nocheck
X-Debbugs-Cc: [email protected]
Hi,
Whilst working on the Reproducible Builds effort [0], we noticed that
golang-github-google-go-attestation could not be built reproducibly.
This is because the call to remove some tests were essentially in the
wrong debian/rules target. Whilst it they were in execute_before_dh_auto_test,
this target is not called if the tests are skipped — meaning that if the tests
_aren't_ run, then the package contains those files.
Patch attached that moves these deletions to execute_after_dh_auto_build
which is always run.
[0] https://reproducible-builds.org/
Regards,
--
,''`.
: :' : Chris Lamb
`. `'` [email protected] / chris-lamb.co.uk
`-
--- a/debian/rules 2025-12-12 11:51:34.578343520 -0800
--- b/debian/rules 2025-12-12 11:55:20.343494389 -0800
@@ -7,7 +7,7 @@
%:
dh $@ --builddirectory=_build --buildsystem=golang
-execute_before_dh_auto_test:
+execute_after_dh_auto_build:
#
src/github.com/google/go-attestation/attest/attest_simulated_tpm20_test.go:29:2:
cannot find package "github.com/google/go-tpm-tools/simulator" in any of:
rm -fv
_build/src/github.com/google/go-attestation/attest/attest_simulated_tpm20_test.go
# src/github.com/google/go-attestation/attest/application_key_test.go:38:14:
undefined: setupSimulatedTPM
--- End Message ---
--- Begin Message ---
Source: golang-github-google-go-attestation
Source-Version: 0.6.0-1
Done: Simon Josefsson <[email protected]>
We believe that the bug you reported is fixed in the latest version of
golang-github-google-go-attestation, which is due to be installed in the Debian
FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Simon Josefsson <[email protected]> (supplier of updated
golang-github-google-go-attestation package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sun, 28 Dec 2025 22:35:08 +0100
Source: golang-github-google-go-attestation
Architecture: source
Version: 0.6.0-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Go Packaging Team <[email protected]>
Changed-By: Simon Josefsson <[email protected]>
Closes: 1122824
Changes:
golang-github-google-go-attestation (0.6.0-1) unstable; urgency=medium
.
[ Simon Josefsson ]
* New upstream version 0.6.0
* Drop B-D/D on golang-github-google-go-tspi-dev
* Standards-Version: 4.7.3
* Improve d/copyright
* Add B-D/D on golang-github-google-go-cmp-dev
* Fix dh_auto_test
* Drop DH_GOLANG_EXCLUDES
* Improve Salsa CI
* Improve d/copyright
.
[ Chris Lamb ]
* Fix reproducibility (Closes: #1122824)
Checksums-Sha1:
fd5513c601846a12a70be87f6fedbeedd702b18a 2780
golang-github-google-go-attestation_0.6.0-1.dsc
e47f2acae61554a34ddf0cb276399ffb5ec96205 221328
golang-github-google-go-attestation_0.6.0.orig.tar.xz
71c85eca2f7726a4fde66b3769177738c3a46836 3960
golang-github-google-go-attestation_0.6.0-1.debian.tar.xz
4b002ab35ac7785a7c730020be05b9aedc7f9467 570492
golang-github-google-go-attestation_0.6.0-1.git.tar.xz
b3d45c192b2cbaf503565b026278cc5cbd327cc6 17247
golang-github-google-go-attestation_0.6.0-1_source.buildinfo
Checksums-Sha256:
745723d1efe597bfcbdf792534f6a4c85325e94e8489c5a881a0f3844d434930 2780
golang-github-google-go-attestation_0.6.0-1.dsc
8a508366446613ead86a2c43b0e62af071f1d99648d6700aac93abe672c51685 221328
golang-github-google-go-attestation_0.6.0.orig.tar.xz
6f1ae5e98d110f74edbb5bfdda688c56b78c5436acb413eef2f0b5d41cea88dd 3960
golang-github-google-go-attestation_0.6.0-1.debian.tar.xz
0ab3ee3d24d0a545e5b5a2052b2acbb5d7736b6ec65fb788e6e19b13899a5836 570492
golang-github-google-go-attestation_0.6.0-1.git.tar.xz
355a47bdd560f2a709a068aa470582586f5514ed47c92796d0d4df2669f4e9b9 17247
golang-github-google-go-attestation_0.6.0-1_source.buildinfo
Files:
68ef4e24db7a66839524dd2a89a12c94 2780 golang optional
golang-github-google-go-attestation_0.6.0-1.dsc
c17417180e3c2756c1ca25dea0ea19fd 221328 golang optional
golang-github-google-go-attestation_0.6.0.orig.tar.xz
0bc8067232b5b4c20a855e6f06bf5a30 3960 golang optional
golang-github-google-go-attestation_0.6.0-1.debian.tar.xz
aaba7b5eb6069032e6e75c9539d3de77 570492 golang optional
golang-github-google-go-attestation_0.6.0-1.git.tar.xz
81c952fdf92430532fdd48b6c4af0da8 17247 golang optional
golang-github-google-go-attestation_0.6.0-1_source.buildinfo
Git-Tag-Info: tag=fdede05eb43504d2a1c29e3239845b4c236e5f3b
fp=a3cc9c870b9d310abad4cf2f51722b08fe4745a2
Git-Tag-Tagger: Simon Josefsson <[email protected]>
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmlRqDgACgkQYG0ITkaD
wHnbnBAAzrRg1UGjsxiDLdZULJI157SBkA5e1wpqKC1uQ4gD+HsZfcG9SMhSRVc7
mCclc9g7AXUxJw4BYI38+UR5afvAu01ikf8LjL+gcbU1gjDPAvTcJJEEOD/OZUM6
CT0GlPukfcz4yQhcguIzHN2FPWWJ1WF+mKjBkcukv08HwjaG+w+Z+eLCBk03fIj6
eEAKuIVEET2oWWAvPj/xpkoE67IC0MaJusWi1aoFGBq5iT5J1Tv/KAV1ErAlLrLR
Vs3obLigXZa0AgFyMqsetMNAaQ9Ng/emdTmD3dtOIOTsrNnUms4KsWKVXzLkXH3t
Uz8UoWanJrdQDiUU3p/8ETj6qgdKIMnAKE4Ki/Dn03ynZLhMhx93SVILCqvWB0So
QyZ0Iw8dEdMpMo2ExG/yq1CfkVejMS1t2vOzI7MgfjYBnTNac5S5oHj5C0k8t4QW
d6m67jKA4VWTjohV6hFEylEMCuruw6qX/JHW/GHds3X/suY+wCswK0hJ5ldUuHEG
+/sE3LfnPHFPYNWEv/aUDkALOQIxDUIlwX7cyUI2iLEDx+3nNUhVfCiCGbp3AV/4
+GsEAbFt0EqZA2WdV9cPLBroyaL4SJXO4agaijITH1xpB8hdwNG+GwiSCWQTHTqo
VxF43jgYqa/V7esqupSCf+5QRp3wyGCyukLnBOk+5Z+5nd1/Ebk=
=nc07
-----END PGP SIGNATURE-----
pgpTpxI3qMbKt.pgp
Description: PGP signature
--- End Message ---