Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add reproducible timestamps in archives #4546

Open
wants to merge 2 commits into
base: main
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -86,6 +86,16 @@ public class CustomBundleMojo extends AbstractMojo {
@Parameter
private MavenArchiveConfiguration archive = new MavenArchiveConfiguration();

/**
* Timestamp for reproducible output archive entries, either formatted as ISO
* 8601 extended offset date-time (e.g. in UTC such as '2011-12-03T10:15:30Z' or
* with an offset '2019-10-05T20:37:42+06:00'), or as an int representing
* seconds since the epoch (like <a href=
* "https://reproducible-builds.org/docs/source-date-epoch/">SOURCE_DATE_EPOCH</a>).
*/
@Parameter(defaultValue = "${project.build.outputTimestamp}")
private String outputTimestamp;

@Component(role = Archiver.class, hint = "jar")
private JarArchiver jarArchiver;

Expand All @@ -100,6 +110,9 @@ public void execute() throws MojoExecutionException, MojoFailureException {
archiver.setArchiver(jarArchiver);
archiver.setOutputFile(outputJarFile);

// configure for Reproducible Builds based on outputTimestamp value
archiver.configureReproducibleBuild(outputTimestamp);

try {
archiver.getArchiver().setManifest(updateManifest());

Expand Down
5 changes: 5 additions & 0 deletions tycho-gpg-plugin/pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -64,6 +64,11 @@
<artifactId>tycho-core</artifactId>
<version>${project.version}</version>
</dependency>

<dependency>
<groupId>org.apache.maven</groupId>
<artifactId>maven-archiver</artifactId>
</dependency>
</dependencies>

<build>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -11,9 +11,11 @@

import java.io.File;
import java.io.IOException;
import java.nio.file.attribute.FileTime;
import java.util.Arrays;
import java.util.List;

import org.apache.maven.archiver.MavenArchiver;
import org.apache.maven.plugin.MojoExecutionException;
import org.apache.maven.plugin.MojoFailureException;
import org.apache.maven.plugins.annotations.Component;
Expand Down Expand Up @@ -137,6 +139,15 @@ enum PGPKeyBehavior {
@Parameter
private List<String> forceSignature;

/**
* Timestamp for reproducible output archive entries, either formatted as ISO 8601 extended
* offset date-time (e.g. in UTC such as '2011-12-03T10:15:30Z' or with an offset
* '2019-10-05T20:37:42+06:00'), or as an int representing seconds since the epoch (like
* <a href="https://reproducible-builds.org/docs/source-date-epoch/">SOURCE_DATE_EPOCH</a>).
*/
@Parameter(defaultValue = "${project.build.outputTimestamp}")
private String outputTimestamp;

@Component(role = UnArchiver.class, hint = "zip")
private ZipUnArchiver zipUnArchiver;

Expand Down Expand Up @@ -208,6 +219,10 @@ public void doExecute() throws MojoExecutionException, MojoFailureException {
}
}

// configure for Reproducible Builds based on outputTimestamp value
MavenArchiver.parseBuildOutputTimestamp(outputTimestamp).map(FileTime::from)
.ifPresent(modifiedTime -> xzArchiver.configureReproducibleBuild(modifiedTime));

xzArchiver.setDestFile(artifactsXmlXz);
xzArchiver.addFile(artifactsXml, artifactsXml.getName());
xzArchiver.createArchive();
Expand Down
93 changes: 93 additions & 0 deletions tycho-its/projects/reproducible-archive-timestamps/pom.xml
Original file line number Diff line number Diff line change
@@ -0,0 +1,93 @@
<?xml version="1.0" encoding="UTF-8"?>
<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 https://maven.apache.org/maven-v4_0_0.xsd">
<modelVersion>4.0.0</modelVersion>

<groupId>reproducible.archive.timestamps</groupId>
<artifactId>reproducible.archive.timestamps.parent</artifactId>
<version>1.0.0</version>
<packaging>pom</packaging>

<modules>
<module>reproducible.bundle</module>
<module>reproducible.bundle.feature</module>
<module>reproducible.iu</module>
<module>reproducible.repository</module>
</modules>

<properties>
<project.build.outputTimestamp>2023-01-01T00:00:00Z</project.build.outputTimestamp>
<target-platform>http://download.eclipse.org/releases/latest</target-platform>
</properties>

<repositories>
<repository>
<id>repo</id>
<layout>p2</layout>
<url>${target-platform}</url>
</repository>
</repositories>

<build>
<plugins>
<plugin>
<groupId>org.eclipse.tycho</groupId>
<artifactId>tycho-maven-plugin</artifactId>
<version>${tycho-version}</version>
<extensions>true</extensions>
</plugin>

<plugin>
<groupId>org.eclipse.tycho</groupId>
<artifactId>target-platform-configuration</artifactId>
<version>${tycho-version}</version>
<configuration>
<environments>
<environment>
<os>linux</os>
<ws>gtk</ws>
<arch>x86</arch>
</environment>
</environments>
</configuration>
</plugin>

<plugin>
<groupId>org.eclipse.tycho</groupId>
<artifactId>tycho-packaging-plugin</artifactId>
<version>${tycho-version}</version>
</plugin>

<plugin>
<groupId>org.eclipse.tycho</groupId>
<artifactId>tycho-source-plugin</artifactId>
<version>${tycho-version}</version>
<executions>
<execution>
<id>plugin-source</id>
<goals>
<goal>plugin-source</goal>
<goal>feature-source</goal>
</goals>
</execution>
</executions>
</plugin>

<plugin>
<groupId>org.eclipse.tycho</groupId>
<artifactId>tycho-p2-plugin</artifactId>
<version>${tycho-version}</version>
<executions>
<execution>
<id>attach-p2-metadata</id>
<phase>package</phase>
<goals>
<goal>p2-metadata</goal>
</goals>
</execution>
</executions>
</plugin>
</plugins>
</build>

</project>
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
bin.includes = feature.xml
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
<?xml version="1.0" encoding="UTF-8"?>
<feature
id="reproducible.bundle.feature"
label="Feature"
version="1.0.0">

<plugin
id="reproducible.bundle"
download-size="0"
install-size="0"
version="0.0.0"
unpack="false"/>

</feature>
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
<?xml version="1.0" encoding="UTF-8"?>
<project>
<modelVersion>4.0.0</modelVersion>

<parent>
<groupId>reproducible.archive.timestamps</groupId>
<artifactId>reproducible.archive.timestamps.parent</artifactId>
<version>1.0.0</version>
</parent>

<artifactId>reproducible.bundle.feature</artifactId>
<packaging>eclipse-feature</packaging>
</project>
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
Manifest-Version: 1.0
Bundle-ManifestVersion: 2
Bundle-Name: Reproducible-bundle
Bundle-SymbolicName: reproducible.bundle
Bundle-Version: 1.0.0
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
source.. = src/
output.. = bin/
bin.includes = META-INF/,\
.
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
Manifest-Version: 1.0
Bundle-ManifestVersion: 2
Bundle-Name: Reproducible-bundle
Bundle-SymbolicName: reproducible.bundle.attached
Bundle-Version: 1.0.0
Original file line number Diff line number Diff line change
@@ -0,0 +1,44 @@
<?xml version="1.0" encoding="UTF-8"?>
<project>
<modelVersion>4.0.0</modelVersion>

<parent>
<groupId>reproducible.archive.timestamps</groupId>
<artifactId>reproducible.archive.timestamps.parent</artifactId>
<version>1.0.0</version>
</parent>

<artifactId>reproducible.bundle</artifactId>
<packaging>eclipse-plugin</packaging>

<build>
<plugins>
<plugin>
<groupId>org.eclipse.tycho.extras</groupId>
<artifactId>tycho-custom-bundle-plugin</artifactId>
<version>${tycho-version}</version>
<executions>
<execution>
<id>attached</id>
<phase>package</phase>
<goals>
<goal>custom-bundle</goal>
</goals>
<configuration>
<bundleLocation>${project.basedir}/custom</bundleLocation>
<classifier>attached</classifier>
<fileSets>
<fileSet>
<directory>${project.build.outputDirectory}</directory>
<includes>
<include>**/*.class</include>
</includes>
</fileSet>
</fileSets>
</configuration>
</execution>
</executions>
</plugin>
</plugins>
</build>
</project>
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
package reproducible.bundle;

public class PublicClass
{

}
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
<?xml version='1.0' encoding='UTF-8'?>
<unit id='reproducible.iu' version='1.0.0' singleton='false'>
<update id='reproducible.iu' range='[0.0.0,1.0.0)' severity='0'/>
<properties>
<property name='org.eclipse.equinox.p2.name' value='Root files for my product'/>
</properties>
<touchpoint id='org.eclipse.equinox.p2.native' version='1.0.0'/>
<touchpointData>
<instructions>
<instruction key='install'>
unzip(source:@artifact, target:${installFolder});
</instruction>
<instruction key='uninstall'>
cleanupzip(source:@artifact, target:${installFolder});
</instruction>
</instructions>
</touchpointData>
</unit>
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
<?xml version="1.0" encoding="UTF-8"?>
<project>
<modelVersion>4.0.0</modelVersion>

<parent>
<groupId>reproducible.archive.timestamps</groupId>
<artifactId>reproducible.archive.timestamps.parent</artifactId>
<version>1.0.0</version>
</parent>

<artifactId>reproducible.iu</artifactId>
<packaging>p2-installable-unit</packaging>
</project>
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
requires.0.namespace=org.eclipse.equinox.p2.iu
requires.0.name=reproducible.iu
requires.0.range=[$version$,$version$]
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
<?xml version="1.0" encoding="UTF-8"?>
<?pde version="3.5"?>

<product name="Main Product" uid="main.product.id" id="product.branding" application="product.bundle.application" version="1.0.0" useFeatures="false" includeLaunchers="false">

<configIni use="default">
</configIni>

<launcherArgs>
</launcherArgs>

<plugins>
<plugin id="org.eclipse.core.runtime"/>
</plugins>


</product>
Original file line number Diff line number Diff line change
@@ -0,0 +1,60 @@
<?xml version="1.0" encoding="UTF-8"?>
<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 https://maven.apache.org/maven-v4_0_0.xsd">
<modelVersion>4.0.0</modelVersion>

<parent>
<groupId>reproducible.archive.timestamps</groupId>
<artifactId>reproducible.archive.timestamps.parent</artifactId>
<version>1.0.0</version>
</parent>

<artifactId>reproducible.repository</artifactId>
<packaging>eclipse-repository</packaging>

<build>
<plugins>
<plugin>
<groupId>org.eclipse.tycho</groupId>
<artifactId>tycho-p2-repository-plugin</artifactId>
<version>${tycho-version}</version>
<executions>
<execution>
<id>assemble-maven-repository</id>
<phase>verify</phase>
<goals>
<goal>assemble-maven-repository</goal>
</goals>
</execution>
</executions>
</plugin>
<plugin>
<groupId>org.eclipse.tycho</groupId>
<artifactId>tycho-p2-director-plugin</artifactId>
<version>${tycho-version}</version>
<executions>
<execution>
<id>materialize-products</id>
<goals>
<goal>materialize-products</goal>
</goals>
</execution>
<execution>
<id>archive-products</id>
<goals>
<goal>archive-products</goal>
</goals>
</execution>
</executions>
<configuration>
<formats>
<linux>zip</linux>
<mac>zip</mac>
<windows>zip</windows>
</formats>
</configuration>
</plugin>
</plugins>
</build>

</project>
Loading