Repository navigation
distutils is not reproducible #78214
Description
Activity
Follow up of bpo-29708: OpenSUSE uses a downstream patch for distutils to fix https://bugzilla.opensuse.org/show_bug.cgi?id=1049186: distutils-reproducible-compile.patch. I converted the patch as a PR: PR 8057.
Naoki INADA wrote:
"""
Currently, marshal uses refcnt to determine using w_ref or not. Some immutable objects (especially, long and str) can be cached and reused. It may affects refcnt when byte compiling.I think we should use more deterministic way instead of refcnt. Maybe, count all constants in the module before marshal, like we did in compiling function for co_consts and co_names.
As a bonus, it may reduce resource usage too by merging constants over functions.
(e.g. ('self',) co_varnames and (None,) co_consts)
"""
#8057 (comment)Serhiy Storchaka added:
"""
I think we need to understand the issue better before committing changes. When found the source of unstability of file names, we can find other similar sources and make them stable too. For example if the source is listdir() or glob(), we can consider sorting results of all listdir() or glob() in distutils and related methods.On other side, if the problem is with reference counters in marshal, we can change the marshal module instead.
"""
#8057 (comment)- added3.8 (EOL)end of lifeend of lifestdlibStandard Library Python modules in the Lib/ directoryStandard Library Python modules in the Lib/ directory
on Jul 3, 2018 Copy of https://bugzilla.opensuse.org/show_bug.cgi?id=1049186 first message:
"""
e.g. python-simplejson has one-bit diffs in .pyc files
See
http://rb.zq1.de/compare.factory-20170713/python-simplejson-compare.outin python3-simplejson.rpm we get
-00004e50 68 6f 72 5f 5f da 07 64 65 63 69 6d 61 6c 72 0c |hor__..decimalr.|
+00004e50 68 6f 72 5f 5f 5a 07 64 65 63 69 6d 61 6c 72 0c |hor__Z.decimalr.|in python3-simplejson-test.rpm we get the opposite change
-00000580 72 13 00 00 00 5a 07 64 65 63 69 6d 61 6c 72 03 |r....Z.decimalr.|
+00000580 72 13 00 00 00 da 07 64 65 63 69 6d 61 6c 72 03 |r......decimalr.|and it seems to be related to filesystem ordering, since it built reproducibly
when using a filesystem with sorted readdir
using disorderfs via reproducible-faketools-filesys from
https://build.opensuse.org/package/show/home:bmwiedemann:reproducible/reproducible-faketools
"""
https://bugzilla.opensuse.org/show_bug.cgi?id=1049186#c0I agree that we should fix the underlying issue (marshal) rather than papering over it by sorting. In fact, we should have a test that compiles a bunch of pycs in a random orders and sees if they're the same or not.
Is this issue for only known marshal issue?
Or is this issue for all issues in distutils including unknowns?We should probably discuss the marshal issue in the preëxisting bpo-31377.
I'm not sure if "distutils is not reproducible" is a larger issue than "pyc compilation is not reproducible". This issue could be a meta issue for either.
Is this issue for only known marshal issue?
IMHO the order in which .pyc files are created on disk also matters. It changes the result of "os.listdir()": some application can rely on unsorted os.listdir(). sorted() seems simple and hardless compared to the benefit.
OK, I created sub issue for pyc.
unreproducible .pyc files are still one of the major headaches for my work on openSUSE reproducible builds.
There is also one aspect where i586 builds end up with different .pyc files than x86_64 builds. And then we randomly chose one of them for our "noarch" python module packages and hope they work everywhere (including on arm and s390 architectures).
So is someone working towards a concept that makes it is possible to create the same .pyc files anywhere?
Can I help something there?
Is there an ETA?There is also one aspect where i586 builds end up with different .pyc files than x86_64 builds. And then we randomly chose one of them for our "noarch" python module packages and hope they work everywhere (including on arm and s390 architectures).
They are functionally identical, despite not being bit-by-bit identical.
If they do not work everywhere, it's a very serious bug.So is someone working towards a concept that makes it is possible to create the same .pyc files anywhere?
No, it's a known issue no one is working on.
Can I help something there?
Maybe?
The two main culprits are in the marshal serialization algorithm: https://github.com/python/cpython/blob/master/Python/marshal.c
Specifically:- a heuristic depends on refcount (i.e. state of objects in the entire interpreter, rather than just relationships between serialized objects):
Line 304 in 33b671e
/* if it has only one reference, it definitely isn't shared */ - (frozen)sets are serialized in iteration order, which is unpredictable (and determinig a predictable order is not trivial):
Line 498 in 33b671e
else if (PyAnySet_CheckExact(v)) {
A solution will probably come with an unacceptable performance hit -- it's good to keep generating the .pyc files fast. Two options to overcome that come to mind:
- make reproducibility optional (which would make the testing more cumbersome)
- make an add-on tool to re-serialize an existing .pyc.
Reacted by Eric Snow- a heuristic depends on refcount (i.e. state of objects in the entire interpreter, rather than just relationships between serialized objects):
- added a commit that references this issue
on May 4, 2022 - added3.11only security fixesonly security fixesand removed3.8 (EOL)end of lifeend of life
on May 4, 2022 Thank you @methane -- we are now carrying your patch in python 3.10 in Debian: https://sources.debian.org/src/python3.10/3.10.4-4/debian/patches/gh-78214.diff/
@vstinner should this be closed now or will there be any other patches to Distutils before its removal?
A
- addedpendingThe issue will be closed if no feedback is providedThe issue will be closed if no feedback is provided
on Jun 7, 2022 I don't know the status of this issue, you should ask @methane who is more involved in this topic.
Ahh sorry, I will wait for @methane's opinion.
A
We have enough opening issues relating to reproducible pyc. So I agree to close this one.
- removedpendingThe issue will be closed if no feedback is providedThe issue will be closed if no feedback is provided
on Jun 9, 2022 - added a commit that references this issue
on Nov 28, 2024
Dependencies:
Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.
Show more details
GitHub fields:
bugs.python.org fields: