git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Git generated tarballs and Debian

From
brian m. carlson <sandals@crustytoothpaste.net>
Date
Apr 28, 2026, 10:25 UTC
Message-ID
<afCLFJX86yEPKKfk@fruit.crustytoothpaste.net>
In-Reply-To
<9030b26d-02ed-4452-b212-a69a4ff21e2d@hogyros.de>
On 2026-04-28 at 08:40:05, Simon Richter wrote:
Show 12 quoted lines
> Hi,
> 
> in Debian, we're shipping "original" tarballs for each software package, and
> the Debian specific changes in a separate file.
> 
> Historically, this users could do a bitwise comparison of the original
> tarball and the one in Debian to verify that these were unchanged.
> 
> With git, some authors have stopped releasing official tarballs, so we're
> using git-archive a lot -- but this is reproducible only by accident. GitHub
> also prepares some release tarballs that may or not be bitwise identical to
> what git archive produces.

I'll just note that we don't make any guarantees that `git archive` produces identical output across versions. Incorrectly making that assumption broke kernel.org when we changed the format in the past.

Also, if you use `export-subst`, then it's possible to emit short object IDs, which can differ in length depending on how many objects are in the repository. It's also possible to use zlib or pigz instead of gzip to produce tarballs, in which case the compressed data will also differ.

I had intended to create and emit a standard, reproducible format for `git archive`, but never got around to finishing that. Perhaps I'll try to pick it up at some point; I expect it will be easier to implement now that we have Rust support in the tree.

When I was one of the maintainer of Git LFS, we intentionally produced source tarballs specifically to emit bit-for-bit identical artifacts.

-- 
brian m. carlson (they/them)
Toronto, Ontario, CA
Previous: Simon RichterNext: Simon Richter
Message 2 of 6 in “Git generated tarballs and Debian”
  1. Simon RichterApr 28, 2026
  2. brian m. carlsonApr 28, 2026
  3. Simon RichterApr 28, 2026
  4. Theodore TsoApr 28, 2026
  5. brian m. carlsonApr 28, 2026
  6. Jeff KingApr 29, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.