-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathsources.pin
More file actions
134 lines (131 loc) · 8.45 KB
/
Copy pathsources.pin
File metadata and controls
134 lines (131 loc) · 8.45 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
# The source set scripts/build-pacman-static links a static pacman from.
#
# Every line here is an input to a binary this repository publishes as a release
# asset, so each one is pinned by content. Policy 10 pins by commit hash and
# names a content hash as the equivalent for a non-git artefact: pacman is a git
# checkout at a commit, everything else is a tarball at a sha256.
#
# ⛔ Nothing here is fetched at image build time. The Dockerfile does not read
# this file. It is read by scripts/build-pacman-static, which runs in its own
# workflow and produces release assets.
#
# Field format, one record per line, whitespace separated:
#
# zig VERSION HOST-TRIPLE URL SHA256
# source NAME VERSION URL SHA256
# pacman COMMIT URL
# describe VALUE
# tag NAME TAG-OBJECT-SHA
# signer FINGERPRINT NAME
# keyserver URL
#
# ⛔ The build fails on a sha256 that does not match. It does not warn and
# continue, and it does not re-fetch from somewhere else.
#
# To re-derive any line:
# curl -sSfL --connect-timeout 20 --max-time 300 -o f URL && sha256sum f
#
# Recorded 2026-08-28. Every hash below was measured by fetching the URL beside
# it on that date, not copied from an upstream checksum file.
#---------------------------------------------------------------------------#
# The toolchain.
#
# zig is the C compiler, the linker, the archiver and the musl libc source, in
# one download. It cross compiles to every architecture below from one host, so
# there is no per architecture toolchain to build, cache or relocate.
#
# ⚠ A mussel or crosstool-NG toolchain bakes its --prefix in at configure time
# and cannot be moved, so a cached toolchain artefact only works if every runner
# unpacks it at the identical absolute path. zig has no such constraint: the
# tree is relocatable and the same one serves all eight targets.
#
# ⚠ Two host triples are pinned because the build matrix can run on either.
#---------------------------------------------------------------------------#
zig 0.16.0 x86_64-linux https://ziglang.org/download/0.16.0/zig-x86_64-linux-0.16.0.tar.xz 70e49664a74374b48b51e6f3fdfbf437f6395d42509050588bd49abe52ba3d00
zig 0.16.0 aarch64-linux https://ziglang.org/download/0.16.0/zig-aarch64-linux-0.16.0.tar.xz ea4b09bfb22ec6f6c6ceac57ab63efb6b46e17ab08d21f69f3a48b38e1534f17
#---------------------------------------------------------------------------#
# The static dependency stack, in the order it is built.
#
# ⛔ Eleven libraries, not thirteen. Both reference recipes also link brotli and
# nghttp2, which are curl content encoding and HTTP/2. Neither is needed to
# fetch a package from an Arch mirror, and both cost: brotli selects a code
# model attribute on a compiler version test rather than a target test and does
# not compile for loongarch64 under clang, and an OpenSSL built with brotli puts
# an object needing the brotli encoder inside libcrypto, which then makes curl's
# configure report that OpenSSL is missing. Leaving both out removes two build
# failures and no capability this binary needs.
#
# ⚠ What that costs is written down rather than hidden: the binary negotiates
# HTTP/1.1 and does not accept a br content encoding. scripts/build-pacman-static
# records curl's feature and protocol lists in the evidence file, so the
# difference is a measurement rather than a claim.
#
# ⚠ OpenSSL is the 3.5 long term support line, not the newest release. 3.6 and
# 4.0 both published on the same day as 3.5.8 and all four are the same
# coordinated fix, so newest buys nothing here and costs a major version.
#---------------------------------------------------------------------------#
source zlib 1.3.2 https://github.com/madler/zlib/releases/download/v1.3.2/zlib-1.3.2.tar.gz bb329a0a2cd0274d05519d61c667c062e06990d72e125ee2dfa8de64f0119d16
source xz 5.8.3 https://github.com/tukaani-project/xz/releases/download/v5.8.3/xz-5.8.3.tar.gz 3d3a1b973af218114f4f889bbaa2f4c037deaae0c8e815eec381c3d546b974a0
source bzip2 1.0.8 https://sourceware.org/pub/bzip2/bzip2-1.0.8.tar.gz ab5a03176ee106d3f0fa90e381da478ddae405918153cca248e682cd0c4a2269
source zstd 1.5.7 https://github.com/facebook/zstd/releases/download/v1.5.7/zstd-1.5.7.tar.gz eb33e51f49a15e023950cd7825ca74a4a2b43db8354825ac24fc1b7ee09e6fa3
source openssl 3.5.8 https://github.com/openssl/openssl/releases/download/openssl-3.5.8/openssl-3.5.8.tar.gz a8f84a39918ec6415ce765d9b429d313ba97b8143169c172e734b9514464f5b2
source libarchive 3.8.9 https://github.com/libarchive/libarchive/releases/download/v3.8.9/libarchive-3.8.9.tar.gz f5a6539059cf5e597dbeda37bfa4874b1e8dea063c8d93bf85a2b44af90a5bd4
source curl 8.21.0 https://github.com/curl/curl/releases/download/curl-8_21_0/curl-8.21.0.tar.gz d9b327997999045a24cda50f3983e69e51c516bd8be6ef9842fc7f99135e33bb
source libgpg-error 1.61 https://gnupg.org/ftp/gcrypt/libgpg-error/libgpg-error-1.61.tar.bz2 7a85413f2bc354f4f8aa832b718af122e48965e9e0eb9012ee659c13c6385c93
source libassuan 3.0.2 https://gnupg.org/ftp/gcrypt/libassuan/libassuan-3.0.2.tar.bz2 d2931cdad266e633510f9970e1a2f346055e351bb19f9b78912475b8074c36f6
source gpgme 2.1.2 https://gnupg.org/ftp/gcrypt/gpgme/gpgme-2.1.2.tar.bz2 0687a95b299871c4141f507c0f740de6b429c9ac067d0fa4e062e3264df5fb77
source libseccomp 2.6.1 https://github.com/seccomp/libseccomp/releases/download/v2.6.1/libseccomp-2.6.1.tar.gz 501f66c667225d53791b97e1d7cf85ab764c297d04881f60f38f451c4b0ee1be
#---------------------------------------------------------------------------#
# pacman itself.
#
# ⭐ The commit is the one every port of this repository already publishes. The
# anchor tag family is <arch>-7.1.0.r9.g54d9411-<pkgrel>, and g54d9411 is this
# commit abbreviated, so the static binary and the image's own pacman are built
# from the same source. tests/static/85-pacman-static-pin.sh asserts the two
# strings agree inside this repository, and freshness-pacman-static.yml measures
# the pin against live upstream.
#
# ⛔ A commit, not the v7.1.0 tag, and the difference is not cosmetic. v7.1.0 is
# an annotated tag object 208ff2b57e49f2851ce7bca5ac9090c6cb8aa746 pointing at
# commit 5683f8477a0afcc6b331766175a83445b2dcfe89, which is nine commits behind
# what Arch ships. Pinning the tag would build a pacman that is not the one in
# any published image.
#
# ⚠ The signed tag is checked as well as the commit, which is the one place this
# recipe takes both halves of the choice policy 10 describes. The commit is what
# decides the checkout; the signature is what says upstream published that
# history under a release manager's key.
#
# ⛔ What the tag proves and what it does not, because the two are different and
# the difference is easy to overstate. v7.1.0 is an annotated tag object whose
# target is 5683f8477a0afcc6b331766175a83445b2dcfe89, and the pinned build commit
# is nine commits later. So the signature says a release manager published the
# 7.1.0 release point. ⚠ It does not say anyone signed the nine commits after
# it. Those are covered by the commit hash and by nothing else.
#
# ⛔ The tag object's own sha is pinned, not just its name. A tag name can be
# moved and re-pushed; an object sha cannot. Policy 10 names dereferencing the
# tag object as the step that gets this right.
#
# ⛔ scripts/build-pacman-static fetches the tag, imports the signers by
# fingerprint from the keyserver below, and requires a VALIDSIG naming one of
# them. It never continues on a failure and it never skips. Taking a build
# without it needs PACMAN_TAG_VERIFY=skip, which is a named, deliberate act and
# is recorded in the evidence file. ⚠ Two keyservers are pinned rather than one,
# so a single outage does not stop a release. Neither is trusted: what each
# returns is checked against the fingerprint before it is used.
#
# ⚠ The fingerprint decides who a key belongs to, and the name beside it is a
# label for a reader. ⛔ The two names below were swapped until 2026-08-29, and
# nothing noticed because nothing read these lines. Re-derived on that date by
# importing each fingerprint and reading its uid:
# gpg --keyserver hkps://keyserver.ubuntu.com --recv-keys <fingerprint>
# gpg --list-keys --with-colons <fingerprint>
#---------------------------------------------------------------------------#
pacman 54d94116164b0b2202c6061c4a59c6f3e70820d8 https://gitlab.archlinux.org/pacman/pacman.git
describe 7.1.0.r9.g54d9411
tag v7.1.0 208ff2b57e49f2851ce7bca5ac9090c6cb8aa746
signer 6645B0A8C7005E78DB1D7864F99FFE0FEAE999BD Allan McRae
signer B8151B117037781095514CA7BBDFFC92306B1121 Andrew Gregory
keyserver hkps://keyserver.ubuntu.com
keyserver hkps://keys.openpgp.org