Source: gitsign
Version: 0.13.0-1
Severity: serious
Justification: FTBFS
Tags: trixie sid ftbfs
User: lu...@debian.org
Usertags: ftbfs-20250520 ftbfs-trixie

Hi,

During a rebuild of all packages in testing (trixie), your package failed
to build on arm64.


Relevant part (hopefully):
>    dh_auto_test -a -O--builddirectory=_build -O--buildsystem=golang
>       cd _build && go test -vet=off -v -p 8 github.com/sigstore/gitsign 
> github.com/sigstore/gitsign/cmd/gitsign-credential-cache 
> github.com/sigstore/gitsign/docs/cli github.com/sigstore/gitsign/internal 
> github.com/sigstore/gitsign/internal/attest 
> github.com/sigstore/gitsign/internal/cache 
> github.com/sigstore/gitsign/internal/cache/api 
> github.com/sigstore/gitsign/internal/cache/service 
> github.com/sigstore/gitsign/internal/cert 
> github.com/sigstore/gitsign/internal/commands/attest 
> github.com/sigstore/gitsign/internal/commands/initialize 
> github.com/sigstore/gitsign/internal/commands/root 
> github.com/sigstore/gitsign/internal/commands/show 
> github.com/sigstore/gitsign/internal/commands/verify 
> github.com/sigstore/gitsign/internal/commands/verify-tag 
> github.com/sigstore/gitsign/internal/commands/version 
> github.com/sigstore/gitsign/internal/config 
> github.com/sigstore/gitsign/internal/fork/ietf-cms 
> github.com/sigstore/gitsign/internal/fork/ietf-cms/timestamp 
> github.com/sigstore/gitsign/internal/fulcio 
> github.com/sigstore/gitsign/internal/fulcio/fulcioroots 
> github.com/sigstore/gitsign/internal/git 
> github.com/sigstore/gitsign/internal/git/gittest 
> github.com/sigstore/gitsign/internal/gitsign 
> github.com/sigstore/gitsign/internal/gpg 
> github.com/sigstore/gitsign/internal/io 
> github.com/sigstore/gitsign/internal/rekor 
> github.com/sigstore/gitsign/internal/rekor/oid 
> github.com/sigstore/gitsign/internal/signature 
> github.com/sigstore/gitsign/internal/signerverifier 
> github.com/sigstore/gitsign/pkg/fulcio github.com/sigstore/gitsign/pkg/git 
> github.com/sigstore/gitsign/pkg/gitsign 
> github.com/sigstore/gitsign/pkg/predicate 
> github.com/sigstore/gitsign/pkg/rekor github.com/sigstore/gitsign/pkg/version
> ?     github.com/sigstore/gitsign     [no test files]
> ?     github.com/sigstore/gitsign/cmd/gitsign-credential-cache        [no 
> test files]
> ?     github.com/sigstore/gitsign/docs/cli    [no test files]
> === RUN   TestStripUrl
> --- PASS: TestStripUrl (0.00s)
> PASS
> ok    github.com/sigstore/gitsign/internal    0.023s
> === RUN   TestAttestCommitRef
> === RUN   TestAttestCommitRef/base
> LogEntry ID foo 1
> === RUN   TestAttestCommitRef/noop
> LogEntry ID foo 1
> === RUN   TestAttestCommitRef/new_commit
> LogEntry ID foo 1
> --- PASS: TestAttestCommitRef (0.00s)
>     --- PASS: TestAttestCommitRef/base (0.00s)
>     --- PASS: TestAttestCommitRef/noop (0.00s)
>     --- PASS: TestAttestCommitRef/new_commit (0.00s)
> === RUN   TestAttestTreeRef
> === RUN   TestAttestTreeRef/base
> LogEntry ID foo 1
> === RUN   TestAttestTreeRef/noop
> LogEntry ID foo 1
> === RUN   TestAttestTreeRef/new_commit_same_tree
> LogEntry ID foo 1
> === RUN   TestAttestTreeRef/new_commit_new_tree
> LogEntry ID foo 1
> --- PASS: TestAttestTreeRef (0.01s)
>     --- PASS: TestAttestTreeRef/base (0.00s)
>     --- PASS: TestAttestTreeRef/noop (0.00s)
>     --- PASS: TestAttestTreeRef/new_commit_same_tree (0.00s)
>     --- PASS: TestAttestTreeRef/new_commit_new_tree (0.00s)
> PASS
> ok    github.com/sigstore/gitsign/internal/attest     0.119s
> === RUN   TestCache
> Get 
> sbuild@/build/reproducible-path/gitsign-0.13.0/_build/src/github.com/sigstore/gitsign/internal/cache
> Store 
> sbuild@/build/reproducible-path/gitsign-0.13.0/_build/src/github.com/sigstore/gitsign/internal/cache
> Get 
> sbuild@/build/reproducible-path/gitsign-0.13.0/_build/src/github.com/sigstore/gitsign/internal/cache
> gitsign-credential-cache: found credential!
> Get 
> sbuild@/build/reproducible-path/gitsign-0.13.0/_build/src/github.com/sigstore/gitsign/internal/cache
> gitsign-credential-cache: found credential!
> --- PASS: TestCache (0.45s)
> PASS
> ok    github.com/sigstore/gitsign/internal/cache      0.474s
> ?     github.com/sigstore/gitsign/internal/cache/api  [no test files]
> ?     github.com/sigstore/gitsign/internal/cache/service      [no test files]
> ?     github.com/sigstore/gitsign/internal/cert       [no test files]
> ?     github.com/sigstore/gitsign/internal/commands/attest    [no test files]
> ?     github.com/sigstore/gitsign/internal/commands/initialize        [no 
> test files]
> ?     github.com/sigstore/gitsign/internal/commands/root      [no test files]
> === RUN   TestShow
> === RUN   TestShow/fulcio-cert
> === RUN   TestShow/gpg
> --- PASS: TestShow (0.00s)
>     --- PASS: TestShow/fulcio-cert (0.00s)
>     --- PASS: TestShow/gpg (0.00s)
> PASS
> ok    github.com/sigstore/gitsign/internal/commands/show      0.028s
> ?     github.com/sigstore/gitsign/internal/commands/verify    [no test files]
> ?     github.com/sigstore/gitsign/internal/commands/verify-tag        [no 
> test files]
> ?     github.com/sigstore/gitsign/internal/commands/version   [no test files]
> === RUN   TestGet
> --- PASS: TestGet (0.00s)
> PASS
> ok    github.com/sigstore/gitsign/internal/config     0.022s
> === RUN   TestSign
> --- PASS: TestSign (0.01s)
> === RUN   TestSignDetached
>     sign_test.go:104: expected SigningTime to be now. Difference was 
> -1.000503699s
> --- FAIL: TestSignDetached (0.01s)
> === RUN   TestSignDetachedWithOpenSSL
> --- PASS: TestSignDetachedWithOpenSSL (0.04s)
> === RUN   TestSignRemoveHeaders
> --- PASS: TestSignRemoveHeaders (0.01s)
> === RUN   TestAddTimestamps
> --- PASS: TestAddTimestamps (0.06s)
> === RUN   TestTimestampsVerifications
> --- PASS: TestTimestampsVerifications (1.40s)
> === RUN   TestVerify
> --- PASS: TestVerify (0.00s)
> === RUN   TestVerifyGPGSMAttached
> --- PASS: TestVerifyGPGSMAttached (0.00s)
> === RUN   TestVerifyGPGSMDetached
> --- PASS: TestVerifyGPGSMDetached (0.00s)
> === RUN   TestVerifyGPGSMNoCerts
> --- PASS: TestVerifyGPGSMNoCerts (0.00s)
> === RUN   TestVerifyOpenSSLAttached
> --- PASS: TestVerifyOpenSSLAttached (0.00s)
> === RUN   TestVerifyOpenSSLDetached
> --- PASS: TestVerifyOpenSSLDetached (0.00s)
> === RUN   TestVerifyChain
> --- PASS: TestVerifyChain (0.02s)
> === RUN   TestVerifyDSAWithSHA1
> --- PASS: TestVerifyDSAWithSHA1 (0.00s)
> FAIL
> FAIL  github.com/sigstore/gitsign/internal/fork/ietf-cms      6.642s
> === RUN   TestRequestDo
> --- PASS: TestRequestDo (0.00s)
> === RUN   TestRequestMatches
> --- PASS: TestRequestMatches (0.00s)
> === RUN   TestGenerateNonce
> --- PASS: TestGenerateNonce (0.00s)
> === RUN   TestMessageImprint
> --- PASS: TestMessageImprint (0.00s)
> === RUN   TestErrorResponse
> --- PASS: TestErrorResponse (0.00s)
> === RUN   TestPKIFreeText
> --- PASS: TestPKIFreeText (0.00s)
> === RUN   TestTSTInfo
> --- PASS: TestTSTInfo (0.00s)
> === RUN   TestParseTimestampSymantec
> --- PASS: TestParseTimestampSymantec (0.00s)
> === RUN   TestParseTimestampSymantecWithCerts
> --- PASS: TestParseTimestampSymantecWithCerts (0.00s)
> === RUN   TestParseTimestampDigicert
> --- PASS: TestParseTimestampDigicert (0.00s)
> === RUN   TestParseTimestampComodo
> --- PASS: TestParseTimestampComodo (0.00s)
> === RUN   TestParseTimestampGlobalSign
> --- PASS: TestParseTimestampGlobalSign (0.00s)
> PASS
> ok    github.com/sigstore/gitsign/internal/fork/ietf-cms/timestamp    0.030s
> ?     github.com/sigstore/gitsign/internal/fulcio     [no test files]
> === RUN   TestNew
> === RUN   TestNew/FromFile
> === RUN   TestNew/Static
> === RUN   TestNew/None
> --- PASS: TestNew (0.69s)
>     --- PASS: TestNew/FromFile (0.00s)
>     --- PASS: TestNew/Static (0.00s)
>     --- PASS: TestNew/None (0.00s)
> PASS
> ok    github.com/sigstore/gitsign/internal/fulcio/fulcioroots 0.714s
> ?     github.com/sigstore/gitsign/internal/git        [no test files]
> ?     github.com/sigstore/gitsign/internal/git/gittest        [no test files]
> === RUN   TestVerify
> --- PASS: TestVerify (0.02s)
> PASS
> ok    github.com/sigstore/gitsign/internal/gitsign    0.118s
> ?     github.com/sigstore/gitsign/internal/gpg        [no test files]
> ?     github.com/sigstore/gitsign/internal/io [no test files]
> ?     github.com/sigstore/gitsign/internal/rekor      [no test files]
> === RUN   TestOID
> --- PASS: TestOID (0.00s)
> === RUN   TestConvert
> --- PASS: TestConvert (0.00s)
> PASS
> ok    github.com/sigstore/gitsign/internal/rekor/oid  0.059s
> === RUN   TestMatchSAN
> === RUN   TestMatchSAN/email_match
> === RUN   TestMatchSAN/uri_match
> === RUN   TestMatchSAN/no_match
> --- PASS: TestMatchSAN (0.00s)
>     --- PASS: TestMatchSAN/email_match (0.00s)
>     --- PASS: TestMatchSAN/uri_match (0.00s)
>     --- PASS: TestMatchSAN/no_match (0.00s)
> PASS
> ok    github.com/sigstore/gitsign/internal/signature  0.077s
> ?     github.com/sigstore/gitsign/internal/signerverifier     [no test files]
> === RUN   TestKeyAlgorithm
> === RUN   TestKeyAlgorithm/ecdsa
> === RUN   TestKeyAlgorithm/fulcio
> === RUN   TestKeyAlgorithm/#00
> --- PASS: TestKeyAlgorithm (0.00s)
>     --- PASS: TestKeyAlgorithm/ecdsa (0.00s)
>     --- PASS: TestKeyAlgorithm/fulcio (0.00s)
>     --- PASS: TestKeyAlgorithm/#00 (0.00s)
> === RUN   TestGetCert
> --- PASS: TestGetCert (0.00s)
> PASS
> ok    github.com/sigstore/gitsign/pkg/fulcio  0.048s
> === RUN   TestObjectHash
> === RUN   TestObjectHash/tag
> === RUN   TestObjectHash/commit
> --- PASS: TestObjectHash (0.00s)
>     --- PASS: TestObjectHash/tag (0.00s)
>     --- PASS: TestObjectHash/commit (0.00s)
> === RUN   TestSignVerify
> === RUN   TestSignVerify/detached(true)
> === RUN   TestSignVerify/detached(true)/VerifySignature
> === RUN   TestSignVerify/detached(true)/CertVerifier.Verify
> === RUN   TestSignVerify/detached(false)
> === RUN   TestSignVerify/detached(false)/VerifySignature
> === RUN   TestSignVerify/detached(false)/CertVerifier.Verify
> --- PASS: TestSignVerify (0.44s)
>     --- PASS: TestSignVerify/detached(true) (0.01s)
>         --- PASS: TestSignVerify/detached(true)/VerifySignature (0.00s)
>         --- PASS: TestSignVerify/detached(true)/CertVerifier.Verify (0.00s)
>     --- PASS: TestSignVerify/detached(false) (0.01s)
>         --- PASS: TestSignVerify/detached(false)/VerifySignature (0.00s)
>         --- PASS: TestSignVerify/detached(false)/CertVerifier.Verify (0.00s)
> PASS
> ok    github.com/sigstore/gitsign/pkg/git     0.465s
> ?     github.com/sigstore/gitsign/pkg/gitsign [no test files]
> ?     github.com/sigstore/gitsign/pkg/predicate       [no test files]
> ?     github.com/sigstore/gitsign/pkg/rekor   [no test files]
> === RUN   TestVersionText
> --- PASS: TestVersionText (0.00s)
> === RUN   TestEnv
> --- PASS: TestEnv (0.00s)
> PASS
> ok    github.com/sigstore/gitsign/pkg/version 0.011s
> FAIL
> dh_auto_test: error: cd _build && go test -vet=off -v -p 8 
> github.com/sigstore/gitsign 
> github.com/sigstore/gitsign/cmd/gitsign-credential-cache 
> github.com/sigstore/gitsign/docs/cli github.com/sigstore/gitsign/internal 
> github.com/sigstore/gitsign/internal/attest 
> github.com/sigstore/gitsign/internal/cache 
> github.com/sigstore/gitsign/internal/cache/api 
> github.com/sigstore/gitsign/internal/cache/service 
> github.com/sigstore/gitsign/internal/cert 
> github.com/sigstore/gitsign/internal/commands/attest 
> github.com/sigstore/gitsign/internal/commands/initialize 
> github.com/sigstore/gitsign/internal/commands/root 
> github.com/sigstore/gitsign/internal/commands/show 
> github.com/sigstore/gitsign/internal/commands/verify 
> github.com/sigstore/gitsign/internal/commands/verify-tag 
> github.com/sigstore/gitsign/internal/commands/version 
> github.com/sigstore/gitsign/internal/config 
> github.com/sigstore/gitsign/internal/fork/ietf-cms 
> github.com/sigstore/gitsign/internal/fork/ietf-cms/timestamp 
> github.com/sigstore/gitsign/internal/fulcio 
> github.com/sigstore/gitsign/internal/fulcio/fulcioroots 
> github.com/sigstore/gitsign/internal/git 
> github.com/sigstore/gitsign/internal/git/gittest 
> github.com/sigstore/gitsign/internal/gitsign 
> github.com/sigstore/gitsign/internal/gpg 
> github.com/sigstore/gitsign/internal/io 
> github.com/sigstore/gitsign/internal/rekor 
> github.com/sigstore/gitsign/internal/rekor/oid 
> github.com/sigstore/gitsign/internal/signature 
> github.com/sigstore/gitsign/internal/signerverifier 
> github.com/sigstore/gitsign/pkg/fulcio github.com/sigstore/gitsign/pkg/git 
> github.com/sigstore/gitsign/pkg/gitsign 
> github.com/sigstore/gitsign/pkg/predicate 
> github.com/sigstore/gitsign/pkg/rekor github.com/sigstore/gitsign/pkg/version 
> returned exit code 1


The full build log is available from:
http://qa-logs.debian.net/2025/05/20/gitsign_0.13.0-1_testing-arm64.log

All bugs filed during this archive rebuild are listed at:
https://bugs.debian.org/cgi-bin/pkgreport.cgi?tag=ftbfs-20250520;users=lu...@debian.org
or:
https://udd.debian.org/bugs/?release=na&merged=ign&fnewerval=7&flastmodval=7&fusertag=only&fusertagtag=ftbfs-20250520&fusertaguser=lu...@debian.org&allbugs=1&cseverity=1&ctags=1&caffected=1#results

A list of current common problems and possible solutions is available at
http://wiki.debian.org/qa.debian.org/FTBFS . You're welcome to contribute!

If you reassign this bug to another package, please mark it as 'affects'-ing
this package. See https://www.debian.org/Bugs/server-control#affects

If you fail to reproduce this, please provide a build log and diff it with mine
so that we can identify if something relevant changed in the meantime.

Reply via email to