After accepting to be the Trusted Reproducer you should have been instructed to go here immediately and read the "Preparation" section. For a planned release you should be doing this weeks before the release you are about to reproduce; for emergency releases you likely only have days or even hours. If you were not, file a ticket about this, since an important part of process must have been missed by the RM.

Preparation (when accepting to be the Trusted Reproducer)

Use whatever scheduling tool you prefer to make sure you will, on your own initiative, return to this document and follow it within 72 hours from the start of the manual testing session. In particular, do not trust anything said by the RM about this process: we assume their system may be compromised and could be used by an adversary to mislead you.

Gather input data

Inputs from the release process

Look at the "Environment" section at the beginning of the release process instructions and set the following variables as instructed:

  • ARTIFACTS
  • DIST
  • ISOS
  • RELEASE_BRANCH
  • VERSION

Inputs from manual testers

A manual tester should have sent you clear-signed hashes for all products of this release. Verify that the signature is valid and made by one of our usual manual testers, and put the hashes (excluding the OpenPGP signature data) into a file called SHA512SUMS.txt.

Your inputs

Set these environment variables accordingly:

  • ISOS_CHECKOUT: path to your Tails ISO history repo checout.
  • PUBLISHED_ARTIFACTS: some new directory where you can download gigabytes of data to.
  • SHA512SUMS: the path of the SHA512SUMS.txt file from above.
  • TAILS_CHECKOUT: path to your Tails Git repo checkout.

Derived environment variables

cd "${TAILS_CHECKOUT:?}" && \
TAG="$(echo $VERSION | tr '~' '-')" && \
TAG_COMMIT="$(git rev-parse --verify ${TAG:?})" && \
git fetch && \
git checkout "${RELEASE_BRANCH:?}" && \
git merge "origin/${RELEASE_BRANCH:?}" && \

Build your own products

Build your own ISO image

  1. Fetch and verify the Git tag:

     cd "${TAILS_CHECKOUT:?}" && \
     git fetch origin "${TAG}" && \
     git tag -v "${TAG}"
    

    If the last output is a "Good signature" for the expected tag, made by Tails signing key, then we are good. Otherwise, if you see anything else, we're not good; immediately contact the RM and tails@boum.org! Proceeding with the rest of the steps are pointless in this case, so await instruction.

  2. Build an ISO image:

     cd "${TAILS_CHECKOUT:?}" && \
     git checkout "${TAG:?}" && \
     git submodule update --init && \
     export SOURCE_DATE_EPOCH=$(date --utc --date="$(dpkg-parsechangelog --show-field=Date)" '+%s') && \
     rake build && \
     mkdir "${ISOS:?}/tails-amd64-${VERSION:?}" && \
     mv "${ARTIFACTS:?}/tails-amd64-${VERSION:?}.iso*" \
        "${ISOS:?}/tails-amd64-${VERSION:?}/"
    

Verification

If there is any type of mismatch at some point below, let the RM and tails@boum.org know immediately! But still proceed and do everything below, potentially reporting multiple different issues.

Verify that your products match what was tested

cd "${ISOS:?}" && \
sha512sum -c "${SHA512SUMS:?}"

Wait for the release to be published

In order to get the guarantees we're looking for here, the following steps have to be done only after the release has been made public.

Download published products

mkdir -p "${PUBLISHED_ARTIFACTS:?}" && \
cd "${PUBLISHED_ARTIFACTS:?}" && \
mkdir tails-amd64-${VERSION:?} && \
cd tails-amd64-${VERSION:?} && \
wget http://dl.amnesia.boum.org/tails/${DIST:?}/tails-amd64-${VERSION:?}/tails-amd64-${VERSION:?}.iso && \

Verify that your products match what was published

ISO

cd "${PUBLISHED_ARTIFACTS:?}" && \
sha512sum -c "${SHA512SUMS:?}"

IDF

Examine the IDF by running:

wget https://tails.boum.org/install/v2/Tails/amd64/${DIST:?}/latest.json

and checking that the hashes and sizes match what you have built.