OpenWrt is reproducible!
How we got there and what we learned


Denver Gingerich

Linux Plumbers Conference 2026

Wednesday 7 October 2026

https://ossguy.com/talks/20261007_lpc/

why make OpenWrt reproducible?

one (of many) metric for code quality

requires a level of code understanding

demonstrates that this understanding exists

security

compliance

for a community distro, benchmark to be proud of

upstream-first approach means we solve at the root

why wasn't it reproducible?

timestamps

vendor-/target-specific firmware image format quirks

kernel modules, esp. if used on few targets

(support hash-based module integrity checking!)

build env - categories

build env - examples

beyond the build env (Managing variance)

is OpenWrt reproducible?

many years of opkg history

>1 decade on reproducibility (slides) (video)

early work: Reproducible OpenWrt

at last!

but wait...

time to change everything

for the better!

apk (Alpine Package Keeper)

a very pleasant package format

from shell scripts to C

main apk-tools fixes: file ordering, SOURCE_DATE_EPOCH

beyond Alpine: using v3 indexes already

let's not forget the tool itself

other challenges

keen readers noticed inconsistent /init - now fixed

teaching diffoscope even more formats,
for human-readable output

defaults is a hexdump diff; nice but...

lots of vendor-specific partitioning :(

thanks to OpenWrt, now supported by diffoscope!

current status (images graph)

https://rebuilder-01.infra.openwrt.org/

firmware images graph

current status (images examples)

https://rebuilder-01.infra.openwrt.org/

images examples - MediaTek

current status (packages graph)

https://rebuilder-01.infra.openwrt.org/

packages graph

current status (packages examples)

https://rebuilder-01.infra.openwrt.org/

packages examples - MediaTek

verifying the results

https://github.com/aparcar/openwrt-rebuilder

builds exactly what the buildbots build

more on why

https://reproducible-builds.org/

which problems do reproducible builds solve?

how about your build system?

QR code linking to SFC Sustainer page

https://ossguy.com/talks/20261007_lpc/

become a Sustainer:

https://sfconservancy.org/sustainer/

Presentation and slides are: Copyright © 2023-2026 Denver Gingerich, and are licensed under the Creative Commons Attribution-Share Alike 4.0 International License. Slide Source available.