git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Git generated tarballs and Debian

From
Theodore Tso <tytso@mit.edu>
Date
Apr 28, 2026, 11:50 UTC
Message-ID
<20260428115017.GA71700@macsyma-wired.lan>
In-Reply-To
<afCLFJX86yEPKKfk@fruit.crustytoothpaste.net>
On Tue, Apr 28, 2026 at 10:25:24AM +0000, brian m. carlson wrote:
Show 9 quoted lines
> 
> I'll just note that we don't make any guarantees that `git archive`
> produces identical output across versions.  Incorrectly making that
> assumption broke kernel.org when we changed the format in the past.
> 
> Also, if you use `export-subst`, then it's possible to emit short object
> IDs, which can differ in length depending on how many objects are in the
> repository.  It's also possible to use zlib or pigz instead of gzip to
> produce tarballs, in which case the compressed data will also differ.

This is what I've been using to try get reproducible tarballs for e2fprogs:

git archive --prefix=e2fsprogs-${ver}/ ${commit} | gzip -9n > $fn
,,, where $commit is a signed git tag.

I know that in the past, using --format=tgz has broken based on different compression parameters used by git (and whether it used an external or internal compressor). I also know that if $commit is a tree-id, this can result in the timestamps being not reproduible. I also don't use export-subst.

There is also the difference in the prefix used by github and gitlab, but that's arguably not git's fault.

What other gotchas are there? How is this likely to be inconsistent in the future? How much work is there to provide that guarantee in the future?

   	    	    	 	      	  - Ted

P.S. Although I use pristine-tar in Debian because I didn't want to count on git-archive being reproducible. But it would be lovely if I could make that guarantee starting on a particular git version.

Previous: Simon RichterNext: brian m. carlson
Message 4 of 6 in “Git generated tarballs and Debian”
  1. Simon RichterApr 28, 2026
  2. brian m. carlsonApr 28, 2026
  3. Simon RichterApr 28, 2026
  4. Theodore TsoApr 28, 2026
  5. brian m. carlsonApr 28, 2026
  6. Jeff KingApr 29, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.