@bkhl All the source code except for recent patches would be in the upstream, but you don't have the exact source that went into the particular binary package.
NixOS, Debian, SuSE, Alma, Rocky, Oracle, they are pretty much reproducible -- you can take the exact source pile for this exact package version and in 90%+ of the cases with NixOS and Debian you can even bit for bit get the exact same binary package file.
RHEL has subscription terms that actively prevent this.