[Flatpak]: Provide a Sources extension
Categories
(Core :: Widget: Gtk, enhancement)
Tracking
()
People
(Reporter: bbhtt.zn0i8, Unassigned)
References
(Blocks 1 open bug)
Details
User Agent: Mozilla/5.0 (X11; Linux x86_64; rv:143.0) Gecko/20100101 Firefox/143.0
Steps to reproduce:
Flatpak manifests built with flatpak-builder can generate a “Sources extension” for the built manifest on passing --bundle-sources.
This basically contains the raw sources that were specified in the manifest to build the app e.g. tarballs, debs, bare git mirrors etc.
The files inside a typical sources extension look like:
downloads/<sha 256 hash>/foobar.tar.xz
git/https_git_github_com_foobar_baz_git/<bare git repo>
manifest/foobar.patch
manifest/foobar.desktop
manifest/foobar.appdata.xml
Assuming these were used to build the app.
Since Firefox is not directly built using flatpak-builder, the easy way (passing --bundle-sources) to generate the sources extension cannot be used.
It can however produce its own Sources extension oob. Having the Sources extension would enable Flathub to run reproducibility checks for the published version of Firefox on Flathub.
So it'd be nice to have a sources extension. Basically in case of Firefox, it'd be creating a directory and putting the following files in them:
downloads/<sha 256 hash>/firefox-144.tar.xz
manifest/firefox.desktop
manifest/firefox.appdata.xml
Then running an ostree command to make that directory into a sources extension.
Actual results:
Missing sources extension:
flatpak remote-info flathub org.mozilla.firefox.Sources
error: Error searching remote flathub: Can't find ref org.mozilla.firefox.Sources
Expected results:
org.mozilla.firefox.Sources extension should be published to Flathub along with Firefox as laid out above.
Then running an ostree command to make that directory into a sources extension.
It'd be something like this (it should work in theory)
ostree commit --repo=repo --canonical-permissions --branch="runtime/org.mozilla.firefox.Sources/x86_64/stable" source_dir
Comment 2•1 year ago
|
||
The Bugbug bot thinks this bug should belong to the 'Core::Widget: Gtk' component, and is moving the bug to that component. Please correct in case you think the bot is wrong.
Comment 3•1 year ago
|
||
Having the Sources extension would enable Flathub to run reproducibility checks for the published version of Firefox on Flathub.
How does that work?
Basically it is a matter of taking the sources extension, rebuilding it independently and comparing org.mozilla.firefox that you are pushing to Flathub vs. the one independently built using diffoscope.
https://github.com/flathub-infra/flathub-repro-checker can automate that for most of the things on Flathub except direct uploads.
Comment 5•1 year ago
|
||
(In reply to bbhtt from comment #4)
Basically it is a matter of taking the sources extension, rebuilding it independently and comparing
org.mozilla.firefoxthat you are pushing to Flathub vs. the one independently built using diffoscope.
That still sounds very vague to me. How do I "take the sources extension", and how do I "rebuild it independently" so I can verify it contains the right things? Is this stuff documented somewhere?
Description
•