unofficial mirror of guix-devel@gnu.org 
 help / color / mirror / code / Atom feed
* Install FAQ: Only build the non-deterministic packages?
@ 2016-09-16 17:11 carlo von lynX
  2016-09-17 23:35 ` Leo Famulari
  2017-01-12 23:58 ` carlo von lynX
  0 siblings, 2 replies; 7+ messages in thread
From: carlo von lynX @ 2016-09-16 17:11 UTC (permalink / raw)
  To: guix-devel

Hello everyone!

Some questions I couldn't resolve from manuals and searches:

I haven't figured out if there is a way to know which packages
are reproducible. I would like to configure my guix to only
fetch binaries that a sufficient number of people agree on to
be deterministic - and for a start it doesn't even have to be
all digital signatures and stuff: would be enough if the
process is known to be deterministic, so the package definition
carries the checksums for the appropriate binary package with
it. I doubt an attacker would dare to mess with that, at least
not now.

I just checked git://git.debian.org/git/reproducible/notes.git
but there are only 118 packages saying "deterministic: True".
What happened to the plan of making that database multi-distro?
I also read about the "Reproducible Build Summit" and I am glad
Lunar is still on course.

I also saw https://debbugs.gnu.org/cgi/bugreport.cgi?bug=22883
about trustable "guix pull". Is it still the case that the
update of package definitions is happening over unsecured http?
Concerning git consistency, isn't it enough to run git fsck so
that a mitm intervention would sooner or later be detected?

And concluding, do you know if Nix is in any better or worse 
condition regarding reproducibility and security of the tool-
chain than Guix? Does nix-pull have the same problem?

Best regards and keep up the good work!

P.S. I'm working with ng0, trying to make a trustworthy system
image for GNUnet/secushare installations. Guix is a top notch
candidate for dissemination. Even if I hate guile and emacs.


-- 
  E-mail is public! Talk to me in private using encryption:
         http://loupsycedyglgamf.onion/LynX/
          irc://loupsycedyglgamf.onion:67/lynX
         https://psyced.org:34443/LynX/

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2017-01-20 15:55 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2016-09-16 17:11 Install FAQ: Only build the non-deterministic packages? carlo von lynX
2016-09-17 23:35 ` Leo Famulari
2016-09-19 11:06   ` ng0
2016-09-19 21:47     ` Leo Famulari
2017-01-12 23:58 ` carlo von lynX
2017-01-13 13:14   ` Ludovic Courtès
2017-01-20 15:55     ` carlo von lynX

Code repositories for project(s) associated with this public inbox

	https://git.savannah.gnu.org/cgit/guix.git

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).