Source-only uploads

Summary

Since circa August 2014, the Debian archive accepts source-only uploads and since August 2015, arch:all packages are built on the buildds. NEW uploads and uploads with NEW binaries currently cannot be source-only. Please bear in mind that this is only supported in stretch and later.

Rationale

Historically, the uploads of packages required them to be built on the developer's machine. The binary, arch-specific packages would be taken as-it-is by the archive after the upload (along with all binary packages, which are architecture agnostic). This means in particular that when you install an amd64 package it is very likely the exact version that was compiled by the maintainer.

There are a few problems with this approach:

Source-only uploads address these issues by essentially having a central authority to compile all code. However, the disadvantage is that if the archive is compromised then every package is compromised. This is true, but it is true even now for more than 90% packages that are built by the archive.

A complementary project is ReproducibleBuilds which aims to make builds fully, bit-per-bit, reproducible. In the future one can imagine that packages are built both by the developer and the archive, the results are tested for equality and the package is only accepted if they match. All this work is about distributing trust and detecting problems early.

How to make a source-only upload

The dpkg-buildpackage program accepts the --changes-option=-S flag which builds the packages as always, but the final .changes file will contain only the source code. You can then use dput to upload the .changes file (see this thread). Example:

$ cd nghttp2
$ dpkg-buildpackage --changes-option=-S
$ cd ..
$ ls *nghttp2*.*
libnghttp2-doc_1.3.4-1_all.deb  nghttp2_1.3.4-1_amd64.changes  nghttp2_1.3.4-1.dsc
nghttp2_1.3.4-1_amd64.build     nghttp2_1.3.4-1.debian.tar.xz  nghttp2_1.3.4.orig.tar.bz2
$ egrep '^ \S{32} ' nghttp2_1.3.4-1_amd64.changes 
 01c9325805a6fe7fc444c890cf43e0fa 2008 httpd optional nghttp2_1.3.4-1.dsc
 cce2f954f27981191e539f43066e939a 1504585 httpd optional nghttp2_1.3.4.orig.tar.bz2
 e0be575279e76a872eac15708374499e 10060 httpd optional nghttp2_1.3.4-1.debian.tar.xz

You can also use the -S flag which only creates the source-only upload (the package is not even built in this case). Please make sure that the package builds properly before.

git-buildpackage support

You should not build packages to upload directly with dpkg-buildpackage. Use pbuilder or sbuild!

If you are using git-buildpackage without pbuilder or sbuild, it will happily accept -S or --changes-option=-S switch:

gbp buildpackage --changes-option=-S

This also works with --git-pbuilder too in jessie and below.

If you are using --git-pbuilder in stretch or later, you should use --git-pbuilder-options=--source-only-changes:

gbp buildpackage --git-pbuilder --git-pbuilder-options=--source-only-changes

This will give a binary .changes file and a source-only .changes file. Alternatively, you can set SOURCE_ONLY_CHANGES=yes in your pbuilderrc and avoid needing to give the option on the command-line.

When using git-buildpackage with sbuild (≥ 0.70.0-1), specify --source-only-changes in order to get both a binary .changes file and a source-only .changes file, e.g.:

gbp buildpackage --git-builder='sbuild --source-only-changes -v -As --dist=unstable'

This can also be hardcoded in the configuration file, see sbuild.conf for details:

$source_only_changes = 1;

Sources