!LemuOOvbWqRXodtSsw:nixos.org

NixOS Reproducible Builds

553 Members
Report: https://reproducible.nixos.org Project progress: https://github.com/orgs/NixOS/projects/30128 Servers

Load older messages


SenderMessageTime
26 May 2021
@andi:kack.itandi-but otherwise looked good :D10:50:21
@gytis-ivaskevicius:matrix.orgGytis Ivaskevicius:D10:51:12
@gytis-ivaskevicius:matrix.orgGytis Ivaskeviciusnice10:51:13
@andi:kack.itandi-So if you want to redo the Go bootstrap ping me for a review. I'd be very happy about it.10:52:16
@gytis-ivaskevicius:matrix.orgGytis IvaskeviciusIll think about it. Currently i got quite a bit on my hands10:53:36
@andi:kack.itandi-Another exercise related to bootstrapping that I would love to do: build a bootstrap tarball on x86_64-linux with nixpkgs, then substitute our bootstrap tarball with the equivalent files from a debian/fedora/... and rebuild that bootstrap tarball. Ideally the results should be identialca.10:54:06
@andi:kack.itandi- * Another exercise related to bootstrapping that I would love to do: build a bootstrap tarball on x86_64-linux with nixpkgs, then substitute our bootstrap tarball with the equivalent files from a debian/fedora/... and rebuild that bootstrap tarball. Ideally the results should be identialcal10:54:09
@gytis-ivaskevicius:matrix.orgGytis IvaskeviciusOh, actually thats pretty smart10:54:44
@andi:kack.itandi-If they are not we can see why and rule out those impurities. Once we can show that you can bootstrap nixpkgs from another distros sources (e.g. Guix MES bootstrapped toolchain) we have a bit more "trust" into those files.10:55:46
@linus.heckemann:matrix.mayflower.deLinux Hackermanthat's basically https://www.schneier.com/blog/archives/2006/01/countering_trus.html right?10:57:35
@andi:kack.itandi-perhaps a gentoo stage1 tarball would be a good starting point as those already exist10:57:39
@gytis-ivaskevicius:matrix.orgGytis Ivaskeviciuswell, currently its not going to be reproducible for sure11:00:07
@andi:kack.itandi-Well because our GCC isn't but otherwise?11:01:34
@andi:kack.itandi-Actually the slower GCC should be reproducible so not sure waht might be the issue11:02:44
@gytis-ivaskevicius:matrix.orgGytis IvaskeviciusDue to the issue that i sent earlier which is basically gcc/glibc and im not sure about all bin utils and stuff11:02:59
@gytis-ivaskevicius:matrix.orgGytis Ivaskeviciusshell/utils might be screwed as well.Not sure tho11:03:46
@andi:kack.itandi-But once we can reproduce the tarballs (even cross distro?) it might be a good idea to do "one final" toolchain rotation, no?11:04:03
@andi:kack.itandi-So that we have a clean slate from which we can start.11:04:13
@gytis-ivaskevicius:matrix.orgGytis Ivaskeviciusyou basically mean extra stdenv stage?11:04:34
@gytis-ivaskevicius:matrix.orgGytis Ivaskeviciusif so - boom https://github.com/NixOS/nixpkgs/issues/12346711:05:05
@andi:kack.itandi-No, lets say we put in the effort to fix your said impurties and then go the extra mile to show that we can now reproduce the tarball based on a) the previousy nixpkgs see and b) another distros toolchain we could then do one "final" swap of the bootstrap seeds. That would let us start from a well defined bootstrap seed instead of the wild mixture it is now.11:05:51
@andi:kack.itandi-And from there on we only add newer compiler versions to the bootstrap (until in 20y we decide that the 30d bootstrap time is getting too long and cut the chain)11:06:25
@synthetica:matrix.orgSynthetica"Grandpa, why do I still need to compile GCC versions 6 through 84"11:09:20
@toonn:matrix.orgtoonn Why make the chain longer? 11:14:18
@toonn:matrix.orgtoonn It's only as trustworthy as the seed anyway so you might as well trim it down as much as possible at each step. 11:14:44
@andi:kack.itandi-the point is you only want to show that the seed is trustworthy once11:15:27
@andi:kack.itandi-and then never again11:15:29
@andi:kack.itandi-I am thinking more towards that cross-distro bootstrap.. if we can pull that off it would be nice to have that attestation as part of the regular bootstrap. Build stdenv using debian, fedora, nixpkgs bootstrap and they must all match the same output otherwise the nixpkgs stdenv build fails.11:16:39
@toonn:matrix.orgtoonn Yeah, so you build the seed bootstrap. Next time you slap a new GCC on top of that. Next time you peel it away to slap an even newer GCC on top of it. Keep doing this until the bootstrap can't build a version, then and only then keep the bootstrap+previous-GCC, wash, rinse and repeat. 11:16:55
@andi:kack.itandi-Not sure I follow.11:18:50

Show newer messages


Back to Room ListRoom Version: 6