plugin: Make archives reproducible

Rebuilding a plugin with unchanged contents and version can produce
a JAR with different bytes because packaging uses the current time
for ZIP timestamps. Downstream builds then see a changed input and
recompile or rerun tests even though the plugin itself has not changed.

Use fixed ZIP timestamps and a stable member order so packaging the
same inputs produces the same archive. Keep the plugin-version file as
an input, but stop stamping the packaging action itself. Changes to the
plugin version still update the manifest and invalidate the archive;
unrelated workspace-status changes no longer invalidate packaging.

Release-Notes: skip
Change-Id: I7707b34bc9d45817f25da0a2bf20afa6fde7d162
diff --git a/gerrit_plugin.bzl b/gerrit_plugin.bzl
index 3d76788..3917ec9 100644
--- a/gerrit_plugin.bzl
+++ b/gerrit_plugin.bzl
@@ -216,7 +216,6 @@
     ])
     genrule2(
         name = name + target_suffix,
-        stamp = 1,
         srcs = ["%s__non_stamped_deploy.jar" % name],
         cmd = " && ".join([
             "TZ=UTC",
@@ -227,8 +226,8 @@
             "unzip -qo $$ROOT/$< -x " + EXCLUDES + " 2>/dev/null",
             copy_license_cmd,
             "echo \"Implementation-Version: $$GEN_VERSION\nGerrit-ApiVersion: $$API_VERSION\n$$(cat META-INF/MANIFEST.MF)\" > META-INF/MANIFEST.MF",
-            "find . -exec touch '{}' ';'",
-            "zip -Xqr $$ROOT/$@ .",
+            "find . -exec touch -t 198001010000 '{}' ';'",
+            "find . -mindepth 1 -print | LC_ALL=C sort | zip -Xq $$ROOT/$@ -@",
         ]),
         tools = [
             ":%s__gen_stamp_info" % name,