These problems can also cascade, if component A embeds the hash of another component B, e.g. to verify that it's been given a correct version. If that hash comes from an unreproducible upstream, and building it ourselves gives a different hash, then we'll need to alter component A to use that new hash. That, in turn, changes the hash of component A, which might be referenced in some other component C, and so on.
Look at windows. Even if you fix the compiler and linker, you still non-reproducibility by design, the PE header contains a timestamp.
People also like to stick non-reproducible stuff into builds directly, like timestamps.
Compilers don't have any reason to lay down data in a specific order, so if they are threaded in the backend they just don't.
IDL tools might stick in the timestamp of when a file was generated, for convenience.
and on and on and on.
Once you make the sensible choice to include build time in the result you've broken reproducibility. Fixing this means tracking down every package that does this and removing the timestamp.
If one has reproducible builds, wouldn't a commit/tag from the version control system also do the job of traceability and reproducibility ?
Thing is just that host + build time is what was traditionally used. There's no single commit you could use in cvs.
Would be nice if there was. I think this is the root of issues such as firmware with the same password/cryto keys across a whole product family instead of unique ones.