On 12/02/26 at 21:21 +0100, Marc Haber wrote: > On Thu, Feb 12, 2026 at 05:17:32PM +0100, Jonas Smedegaard wrote: > > It if was problematic, then I believe we have already a lot of broken > > packages in Debian - all those with "+ds" or "+dfsg" in the name but > > also with "orig" near the end of the name. Those are explicitly *not* > > bit-for-bit upstream-containerized-and-compressed originals. > > Yes, there are exceptions to the rule, but it is still the majorty of > packages that have the orig.tar.gz identical to upstream's relaease tarball.
Data about that, from https://debaudit.debian.net/orig-check/statistics uscan fails to download the current version for 22.87% of packages. uscan downloads an upstream tarball ... ... that is not identical for 4.25% of packages. ... that is bit-by-bit identical for 58.2% ... that is identical after some normalizations for 12.12% native packages: 2% Lucas

