!LemuOOvbWqRXodtSsw:nixos.org

NixOS Reproducible Builds

543 Members
Report: https://reproducible.nixos.org Project progress: https://github.com/orgs/NixOS/projects/30121 Servers

Load older messages


SenderMessageTime
10 May 2023
@davidak:matrix.orgdavidak
In reply to @raitobezarius:matrix.org
hash collection infra might be already in an issue

Trustix could provide that, but the project is not actively developed anymore. It would be great if someone could take over maintainership.

room: https://matrix.to/#/!tCEqPTBHfrsSDeIuFP:trustix.dev?via=matrix.org&via=nixos.dev&via=chir.rs

20:43:36
@raitobezarius:matrix.orgraitobezariusI did repeat this a lot of times indeed :)20:43:47
@davidak:matrix.orgdavidakare there other efforts?20:43:53
@raitobezarius:matrix.orgraitobezariusSecurity team discussed it20:44:02
@raitobezarius:matrix.orgraitobezarius(hash collection infra)20:44:06
@raitobezarius:matrix.orgraitobezariusNothing more to the best of my knowledge20:44:14
11 May 2023
@asymmetric:matrix.dapp.org.uk@asymmetric:matrix.dapp.org.uk joined the room.08:37:12
@julienmalka:matrix.orgJulien joined the room.17:13:07
@julienmalka:matrix.orgJulienI may be interested in relaunching the effort to have trustix be a thing, but I don't have the bandwith to do that only on my own17:14:31
@raitobezarius:matrix.orgraitobezariusWould you be interesting into getting that hash collection infra first?17:14:58
@raitobezarius:matrix.orgraitobezariusThen we can build Trustix on the top of that IMHO17:15:02
@julienmalka:matrix.orgJulienI would need to read more on what you mean by "hash collection infra"17:15:30
@raitobezarius:matrix.orgraitobezariusGo to Security Discussion17:15:39
@raitobezarius:matrix.orgraitobezariusThere's a bit of discussion there17:15:44
@raitobezarius:matrix.orgraitobezariusExpanding what it is17:15:50
@julienmalka:matrix.orgJulienBut yes, it fits my research interests to help nix get better in terms of software supply chain security17:16:00
@julienmalka:matrix.orgJulien
In reply to @raitobezarius:matrix.org
Go to Security Discussion
Sure, but each time I join a new matrix channel I get a little bit more sick
17:16:35
@raitobezarius:matrix.orgraitobezariusdon't worry I will do a RFC for IRC17:16:44
@julienmalka:matrix.orgJulienWhere should I sign ?17:17:06
@julienmalka:matrix.orgJulienAh yes, the "hash collection infra" looks like something I had in mind actually 17:19:08
@julienmalka:matrix.orgJulienWell I'd be ready to work on that kind of solution and could probably even have that be part of my PhD when I start it17:20:22
@raitobezarius:matrix.orgraitobezariusstop giving hope to this channel's people17:20:55
@davidak:matrix.orgdavidak
In reply to @raitobezarius:matrix.org
Would you be interesting into getting that hash collection infra first?

i think trustix has hash collection infra, but no one knows if and how it works (except adisbladis who is unresponsive to the questions)

https://github.com/nix-community/trustix/issues/90

19:36:58
@davidak:matrix.orgdavidaki have collected thousands of hashes on my computer from reviewing PRs and would like to share them, so we can get a broader picture of unreproducible packages19:41:11
@raitobezarius:matrix.orgraitobezariusSomeone needs to investigate this properly19:53:20
@raitobezarius:matrix.orgraitobezariusOr ping adisbladis on appropriate channels19:53:32
@davidak:matrix.orgdavidaki pinged him multiple times in the official room and he has seen it according to matrix20:01:57
@raitobezarius:matrix.orgraitobezariusI know20:02:39
@davidak:matrix.orgdavidakso someone else would have to dig into the code20:02:40
@raitobezarius:matrix.orgraitobezariusThat's why I said "appropriate channels" ;)20:02:50

Show newer messages


Back to Room ListRoom Version: 6