GNU bug report logs - #44447
gnu: pwsafe: Reset timestamps in zip archives

Please note: This is a static page, with minimal formatting, updated once a day.
Click here to see this page with the latest information and nicer formatting.

Package: guix-patches; Reported by: Tim Gesthuizen <tim.gesthuizen@HIDDEN>; Keywords: patch; dated Wed, 4 Nov 2020 16:22:01 UTC; Maintainer for guix-patches is guix-patches@HIDDEN.
Added tag(s) patch. Request was from zimoun <zimon.toutoune@HIDDEN> to control <at> debbugs.gnu.org. Full text available.

Message received at submit <at> debbugs.gnu.org:


Received: (at submit) by debbugs.gnu.org; 4 Nov 2020 16:21:18 +0000
From debbugs-submit-bounces <at> debbugs.gnu.org Wed Nov 04 11:21:18 2020
Received: from localhost ([127.0.0.1]:50376 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces <at> debbugs.gnu.org>)
	id 1kaLXC-0006ef-6F
	for submit <at> debbugs.gnu.org; Wed, 04 Nov 2020 11:21:18 -0500
Received: from lists.gnu.org ([209.51.188.17]:52424)
 by debbugs.gnu.org with esmtp (Exim 4.84_2)
 (envelope-from <tim.gesthuizen@HIDDEN>) id 1kaLX9-0006eU-Kj
 for submit <at> debbugs.gnu.org; Wed, 04 Nov 2020 11:21:17 -0500
Received: from eggs.gnu.org ([2001:470:142:3::10]:46286)
 by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)
 (Exim 4.90_1) (envelope-from <tim.gesthuizen@HIDDEN>)
 id 1kaLX9-0006Ci-CX
 for guix-patches@HIDDEN; Wed, 04 Nov 2020 11:21:15 -0500
Received: from sonic303-20.consmr.mail.ir2.yahoo.com ([77.238.178.201]:45392)
 by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128)
 (Exim 4.90_1) (envelope-from <tim.gesthuizen@HIDDEN>)
 id 1kaLX3-0007sD-1h
 for guix-patches@HIDDEN; Wed, 04 Nov 2020 11:21:15 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.de; s=s2048;
 t=1604506863; bh=ATZ4Q59xSxRjOPRlf3cpT8lVvPumFb7bPe0+G7LKOzA=;
 h=From:To:Subject:Date:References:From:Subject;
 b=U3TJWXMNeMQp5dq4XjNTl9+LGdZAfaOr5R7CKNy8ju8gfA7F9GDx9OQ2MaOa4NQzGVqTmYs+yPkdWtccB2t1gKszAY5H8um8o/dtBMP52IgjvkvbEfsokGZJm1/RFbf84mp0JRW2iGI4W2L5JzglPA5C2wdWEiFBbEecIg3p7rL2yIrJI1UMlWvX1E9nrAB0yGwlNLQ3TW0JRTYr+6U/+hXlcdx4XVzVdM+rWHB08ljI8A7ZjsU/RUsvl2K/0oLl8ZgWcTWGVcy7PhJqMNGVQi6L9cIOkSrLjQM0WdhdHmL9qgbmNLsYufum1uc8BPgskFytqioSRuwAyJaE+lldQg==
X-SONIC-DKIM-SIGN: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048;
 t=1604506863; bh=+KbKg6WUUKvAbevwVkCZffJTIrLvwmYuV8jb0Opic7Y=;
 h=From:To:Subject:Date;
 b=Ud3PqtT9yYGhuxdGXWw5NjyJu7o/eYv2+v2XT4NxRgguVqNIYIIjYKl03OrAtxP9HhvVANrDRUp1uhTnSrVB1TQgHReXmfxiOFmPdjzNNX0vVxaU2K6+lLRsRzTpfY7z08ddKPOIP7/jHYLb5jYTTHP1PWYNwgfwP/ctlz5ohd6YINX0+7hEuJTDtiAJdK4TOHYhf6XDah3xtbeuPqKWP8EYhdFb/T7UjSTGVPvhvJL/fuj5LVxkPBwvBxOXfJADV17QaH0keqd/fuHJpTzD+URgjT1klr6SZvnzcPo1r4y5emCkpTrEcBF/BTGAN13DbNicUm2kNcXKrzTFOFt65g==
X-YMail-OSG: XYBeU5wVM1mgwuYIwS.UEEE.eQe9jqdYh1Gh2b64_BoHpuM9TTFH_RNOIr95T_i
 wAK.9JVtWqV_OIS3WhhhIFNwSYl4yfHKDbDz6UY_GFKqFm7QudThdjiANxAgx3mCJvKEU2SJpUrq
 nRGjJ0PsTt9fvWnUwoWjPLaxld6saHW8Xl5D5IVNWKGmGLjurY2DCiFV7S2Sj.Kh2jYJoDu8uwdR
 jvMT0yJTNNMYibNeG9LXvbTtfIZIXGxBkqC3XladMnWhsyOiITU7Y9zJnEnKgJSOtt2MZxPTkYPI
 .8KYH9WPkSZs8gIDzJA7zyI6DPjd_G3k0Qbid_cTLsiTpXc.Mm55mHDI8iQDeYdLuLH3iA2ghsl4
 t_KCm0dE7z6lNpicVflLsLVfxEZfCD5noOqQ8MGMPwbc.aMFBrULf6HR8UAcJi4PEwYFXZSSyuzD
 9kdyPi4AJsOiUR5eKplhNixodNUfBxiC6zriKyxEPMfNMskHEn0S8EoaZVy.sCUabpfhqn4IKwqd
 BlvwMfjUhZ3SpzcoFmlw3u1qyqGohBXg4.K8saIfdffmJuocj_mHTPn86E7IpR9fn2dTYPhchpov
 rnCQb2qaYKqcFToMUiLDo7vFgFUJ2ld_SjiuWrgH3M10n4SIf8ii_JkYd6R_N_O7qgNue51zFQ5F
 k.yKkB1Y0YyNloKbKMZoicoSarDqDLXiDH1MgevFl3jf9Viks7x01ma5CAv92ULB.2oQwmYg6izu
 3XhBFcrJS4RmxaLa9e8i6nfrF6P1JMJF4usKjLgKLtZXGU4cLnkqwojxNQlDdhOk_HoOGdglLuwz
 LU5sKgV5dKJZFhEf_sI5wV8g_QeiQvDwsLF6tSIJo_XUevAXzSJyJvYBHs0HCjozEZbiFDsHW7rS
 .J8FClglBCiH1pOsSFD0ODbTANTOtB9SeGhHtgpSX3djm9dKMkW0Dwnqky1ufQ_Om9XjnD6eVjCw
 Rz7KQKybJVgmUwfIxdy7lGdpCT_b8pjTTQFAJTm.jAh41zrCb_WTawYLixVCJhkE__L9jzLSRmG5
 TiFnuIiJvPukkIySgRXyj5p9w0vvdk2Ki.bpYPBtD76UymfMY7kaWwEp72OSmxRNGL3O7eOZ5hJd
 NzgMi_M_u0CggUkZScQYoc1OBwcXkBkVkhe9RigEcjMDKHNq82g36qzUX.sT5rYytBpWCzskf7pM
 KPvUDVylaWRaWHPz_eh__7HCTCEUhxG.UJB4rIV79zZGfcdMwsaCq.BQM3rtKG3jv6Jir6vMOqx8
 5SDJG4InC9hSuOh7OIeMj5PHvUZjDw0wg5yVIiMgcMKBX9hRLrnrZv6W1J0QSTe3B.3ekFCuQl6v
 jaB7MHhhNyW1OMBqfSmspJjnalYNlYpkk9eNTQwqNRbrvwckJdvIUFC3GJydAmteMLad9sqPZYw3
 9wpqditP.BprYRobhozb5kjdeYu5GWPQNPwk1hMlJjhMmeGY_qDizugw__5vseU2c0KjDL0jpXzl
 IdCO0E0Q191af5XDbEuggZ9AEJbWmrSA0SlDtG_JJEZOoL9gvfY_kLyTc1bNdpyRAMBlhGRrtU_B
 bPthdKfXa_zYoRVOJowQA.uKpqQi6Xps3WcdmIaOSycEb4.w3FUzsjCE8JkI9mjlj4zq2iKO6Nju
 qW6dweaBI2gGQ41NxHg5Rt24LaMQ1v1Td9yEFGSuq_HAx.Wn.53v0T2F2pE8Wk6Gd3iffHzFN4J_
 r5FkkjqK2VblOELYu225C2gRU58tZRhn86.a7beOa1WdYGeoZSGfYkbDZJCJnd9ltuxmtdRD9DWZ
 1IPQiy1SepVFxtG1at66UEqhsrhZRVJlEObWGBAZPlBEtAO0PMKam0OE4CWcBR4IRxnkNwLEYnWg
 xsoJfVCQca1lsy80XdHEOOryfkyZmIKWrKRzcqR.3AnpHEhyqtF.cm7y3gsiK3fpN_EEOZWIwm8r
 lCAvtKg2PJcZF_DXjujsrCdi_BDoFkOj0dq0vKqNhvaCT5N9r1n_qJ1YXqcnD.jNmbffAhTe4eP5
 C91_VUgC6VKinRbaCO.0z.JYAF8rzok9h3AoEZvcCDOY2iKfny9EINrj1MywiPR.OUaLq1HfCs85
 nLOrK.bbdqSKZkG9VnTa8PlxJkkLbUrX61lliqvvj2K2LRRA9Vvl3XmyIzsXpodBOSO1Z77pWYYE
 hNyVZbkaa03rQRXYQiOJEg2u.u6qMiih0kS60JH2lNhDQlrDwOwnsOE8WYnpyCm81YSHJ8H2WGHw
 UM067ITHeXjqCzg.nOvFcaOcFwUpU_lehaPhABcnQyuDtvgcW4n9yCVboHeXEDnL8lf_A1CejAgG
 9KtlAaIJKMhYRWgC_UQd3.eSZtL6h4Yo80UifuNwqsIAedyuWPxCHWvszp7PbMw--
Received: from sonic.gate.mail.ne1.yahoo.com by
 sonic303.consmr.mail.ir2.yahoo.com with HTTP; Wed, 4 Nov 2020 16:21:03 +0000
Received: by smtp403.mail.ir2.yahoo.com (VZM Hermes SMTP Server) with ESMTPA
 ID 5857bf937b1182a90476713c1fab461d; 
 Wed, 04 Nov 2020 16:21:02 +0000 (UTC)
User-agent: mu4e 1.4.13; emacs 27.1
From: Tim Gesthuizen <tim.gesthuizen@HIDDEN>
To: guix-patches@HIDDEN
Subject: gnu: pwsafe: Reset timestamps in zip archives
Date: Wed, 04 Nov 2020 17:20:57 +0100
Message-ID: <87k0v1w0t2.fsf@HIDDEN>
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="=-=-="
References: <87k0v1w0t2.fsf.ref@HIDDEN>
X-Mailer: WebService/1.1.16944
 mail.backend.jedi.jws.acl:role.jedi.acl.token.atz.jws.hermes.yahoo
 Apache-HttpAsyncClient/4.1.4 (Java/11.0.7)
Content-Length: 9173
Received-SPF: pass client-ip=77.238.178.201;
 envelope-from=tim.gesthuizen@HIDDEN;
 helo=sonic303-20.consmr.mail.ir2.yahoo.com
X-detected-operating-system: by eggs.gnu.org: First seen = 2020/11/04 11:21:03
X-ACL-Warn: Detected OS   = Linux 3.11 and newer [fuzzy]
X-Spam_score_int: -20
X-Spam_score: -2.1
X-Spam_bar: --
X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1,
 DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001,
 RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001,
 SPF_PASS=-0.001 autolearn=ham autolearn_force=no
X-Spam_action: no action
X-Spam-Score: -1.6 (-)
X-Debbugs-Envelope-To: submit
X-BeenThere: debbugs-submit <at> debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit <at> debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces <at> debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces <at> debbugs.gnu.org>
X-Spam-Score: -2.6 (--)

--=-=-=
Content-Type: text/plain

Hi,
I had a look at the old discussion and made a second attempt at fixing
the timestamps in the zip files. I wrote a version in C that does the
this back then but was unsuitable for usage in Guix.
Ludo created a draft for directly reading the zip files and zeroing the
time stamps in Scheme as a response.
But he also mentioned that Debians strip-nondeterminism probobaly
already does what we want.
So I took the this route for solving our problems.
strip-nondeterminism is written in Perl. I don't have any experience
with Perl, so probably my package definitions need some cleanup.
In addition, the tests for strip-nondeterminism fail. Yet using it makes
the build of pwsafe deterministic.
The strip-nondeterminism executable will also fail to run without
changes to the environment when run from a profile.
I am also not sure whether debian.scm is the right file for it.

So the patches below are probably more of a draft and it would be really
nice if someone with Perl experience could tweak them.
As there is a very similar problem with jar files in ant-build-system it
might be benefitial to port this approach to it, but I am not sure about
that.

Tim.


--=-=-=
Content-Type: text/x-patch; charset=utf-8
Content-Disposition: inline; filename=0001-gnu-Add-perl-sub-override.patch
Content-Transfer-Encoding: quoted-printable

From a2b4a41aef84e168366952b5f3b99d4f4ff463d6 Mon Sep 17 00:00:00 2001
From: Tim Gesthuizen <tim.gesthuizen@HIDDEN>
Date: Wed, 4 Nov 2020 16:09:00 +0100
Subject: [PATCH 1/3] gnu: Add perl-sub-override

* gnu/packages/perl.scm (perl-sub-override): New variable.
---
 gnu/packages/perl.scm | 21 +++++++++++++++++++++
 1 file changed, 21 insertions(+)

diff --git a/gnu/packages/perl.scm b/gnu/packages/perl.scm
index ad84d63785..936a605d43 100644
--- a/gnu/packages/perl.scm
+++ b/gnu/packages/perl.scm
@@ -28,6 +28,7 @@
 ;;; Copyright =C2=A9 2020 Paul Garlick <pgarlick@HIDDEN=
m>
 ;;; Copyright =C2=A9 2020 Nicolas Goaziou <mail@HIDDEN>
 ;;; Copyright =C2=A9 2020 Malte Frank Gerdes <malte.f.gerdes@HIDDEN>
+;;; Copyright =C2=A9 2020 Tim Gesthuizen <tim.gesthuizen@HIDDEN>
 ;;;
 ;;; This file is part of GNU Guix.
 ;;;
@@ -9209,6 +9210,26 @@ specification is omitted in the name, then the curre=
nt package is used.  The
 return value is the sub.")
     (license (package-license perl))))
=20
+(define-public perl-sub-override
+  (package
+    (name "perl-sub-override")
+    (version "0.09")
+    (source
+     (origin
+       (method url-fetch)
+       (uri (string-append
+             "https://cpan.metacpan.org/authors/id/O/OV/OVID/Sub-Override-"
+             version ".tar.gz"))
+       (sha256
+        (base32
+         "1d955qn44brkcfif3gi0q2vvvqahny6rax0vr068x5i9yz0ng6lk"))))
+    (native-inputs `(("perl-test-fatal" ,perl-test-fatal)))
+    (build-system perl-build-system)
+    (home-page "https://metacpan.org/release/Sub-Override")
+    (synopsis "Override a sub")
+    (description "Sub::Override aids in overriding subroutines.")
+    (license (package-license perl))))
+
 (define-public perl-sub-quote
   (package
     (name "perl-sub-quote")
--=20
2.29.1


--=-=-=
Content-Type: text/x-patch
Content-Disposition: inline;
 filename=0002-gnu-Add-strip-nondeterminism.patch

From 3c22713d1234e6014d5959e31b621151defab5de Mon Sep 17 00:00:00 2001
From: Tim Gesthuizen <tim.gesthuizen@HIDDEN>
Date: Wed, 4 Nov 2020 16:09:42 +0100
Subject: [PATCH 2/3] gnu: Add strip-nondeterminism

* gnu/packages/debian.scm (strip-nondeterminism): New variable.
---
 gnu/packages/debian.scm | 33 ++++++++++++++++++++++++++++++++-
 1 file changed, 32 insertions(+), 1 deletion(-)

diff --git a/gnu/packages/debian.scm b/gnu/packages/debian.scm
index 52e7ec223a..e710de066f 100644
--- a/gnu/packages/debian.scm
+++ b/gnu/packages/debian.scm
@@ -25,13 +25,15 @@
   #:use-module (guix packages)
   #:use-module (guix build-system gnu)
   #:use-module (guix build-system trivial)
+  #:use-module (guix build-system perl)
   #:use-module (gnu packages autotools)
   #:use-module (gnu packages base)
   #:use-module (gnu packages compression)
   #:use-module (gnu packages gettext)
   #:use-module (gnu packages gnupg)
   #:use-module (gnu packages wget)
-  #:use-module (gnu packages perl))
+  #:use-module (gnu packages perl)
+  #:use-module (gnu packages perl-compression))
 
 (define-public debian-archive-keyring
   (package
@@ -275,3 +277,32 @@ debian/copyright for more information.")))))
 selectively mirror Debian and Ubuntu GNU/Linux distributions or any
 other apt sources typically provided by open source developers.")
       (license license:gpl2))))
+
+(define-public strip-nondeterminism
+  (package
+    (name "strip-nondeterminism")
+    (version "1.9.0")
+    (source
+     (origin
+       (method git-fetch)
+       (uri
+        (git-reference
+         (url "https://salsa.debian.org/reproducible-builds/strip-nondeterminism")
+         (commit version)))
+       (file-name (git-file-name name version))
+       (sha256
+        (base32
+         "0hk8kdkdjpmsl93l09ihlcl8kxibk429a30w81ir085arwqpakzx"))))
+    (build-system perl-build-system)
+    (propagated-inputs
+     `(("perl-archive-zip" ,perl-archive-zip)
+       ("perl-sub-override" ,perl-sub-override)))
+    (arguments `(#:tests? #f))
+    (home-page "https://salsa.debian.org/reproducible-builds/strip-nondeterminism")
+    (synopsis "Strips non deterministic parts off of zip and jar archives")
+    (description "File::StripNondeterminism is a Perl module for stripping
+bits of nondeterministic information, such as timestamps and file system
+order, from files such as gzipped files, ZIP archives, and Jar files.  It can
+be used as a post-processing step to make a build reproducible, when the build
+process itself cannot be made deterministic.")
+    (license license:gpl3+)))
-- 
2.29.1


--=-=-=
Content-Type: text/x-patch
Content-Disposition: inline;
 filename=0003-gnu-pwsafe-Reset-timestamps-in-in-zip-archives.patch

From 95ce6fe3180f78c38b85853ad9689d191ed25e0c Mon Sep 17 00:00:00 2001
From: Tim Gesthuizen <tim.gesthuizen@HIDDEN>
Date: Wed, 4 Nov 2020 16:10:20 +0100
Subject: [PATCH 3/3] gnu: pwsafe: Reset timestamps in in zip archives

* gnu/packages/password-utils.scm (pwsafe):
  [native-inputs] Add strip-nondeterminism.
  [arguments]: Add a new phase resetting timestamps in zip archives and adapt
  modules for it.
---
 gnu/packages/password-utils.scm | 20 ++++++++++++++++++--
 1 file changed, 18 insertions(+), 2 deletions(-)

diff --git a/gnu/packages/password-utils.scm b/gnu/packages/password-utils.scm
index c1bd212f09..85c2248a20 100644
--- a/gnu/packages/password-utils.scm
+++ b/gnu/packages/password-utils.scm
@@ -64,6 +64,7 @@
   #:use-module (gnu packages crypto)
   #:use-module (gnu packages cryptsetup)
   #:use-module (gnu packages curl)
+  #:use-module (gnu packages debian)
   #:use-module (gnu packages docbook)
   #:use-module (gnu packages file)
   #:use-module (gnu packages freedesktop)
@@ -227,6 +228,7 @@ algorithms AES or Twofish.")
      `(("gettext" ,gettext-minimal)
        ("gtest" ,googletest)
        ("perl" ,perl)
+       ("strip-nondeterminism" ,strip-nondeterminism)
        ("zip" ,zip)))
     (inputs `(("curl" ,curl)
               ("file" ,file)
@@ -237,7 +239,10 @@ algorithms AES or Twofish.")
               ("qrencode" ,qrencode)
               ("wxwidgets" ,wxwidgets)
               ("xerces-c" ,xerces-c)))
-    (arguments '(#:configure-flags (list "-DNO_GTEST=YES")
+    (arguments `(#:configure-flags (list "-DNO_GTEST=YES")
+                 #:modules ((guix build cmake-build-system)
+                            (guix build utils)
+                            (ice-9 ftw))
                  #:phases (modify-phases %standard-phases
                             (add-after 'unpack 'add-gtest
                               (lambda* (#:key inputs #:allow-other-keys)
@@ -247,7 +252,18 @@ algorithms AES or Twofish.")
                                   (display "find_package(GTest)
 add_subdirectory(src/test)\n" cmake-port)
                                   (close cmake-port)
-                                  #t))))))
+                                  #t)))
+                            (add-after 'build 'patch-zips
+                              (lambda* (#:key inputs #:allow-other-keys)
+                                (ftw (getcwd)
+                                     (lambda (filename statinfo flag)
+                                       (when (and (eq? flag 'regular)
+                                                  (string-suffix? ".zip" filename))
+                                         (chmod filename #o644)
+                                         (invoke "strip-nondeterminism"
+                                                 "-v" filename))
+                                       #t))
+                                #t)))))
     (synopsis "Password safe with automatic input and key generation")
     (description "pwsafe is a password manager originally designed by Bruce
 Schneier.  It offers a simple UI to manage passwords for different services.
-- 
2.29.1


--=-=-=--




Acknowledgement sent to Tim Gesthuizen <tim.gesthuizen@HIDDEN>:
New bug report received and forwarded. Copy sent to guix-patches@HIDDEN. Full text available.
Report forwarded to guix-patches@HIDDEN:
bug#44447; Package guix-patches. Full text available.
Please note: This is a static page, with minimal formatting, updated once a day.
Click here to see this page with the latest information and nicer formatting.
Last modified: Thu, 10 Jun 2021 11:45:01 UTC

GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997 nCipher Corporation Ltd, 1994-97 Ian Jackson.