From mboxrd@z Thu Jan 1 00:00:00 1970 From: Giovanni Biscuolo Subject: Re: CDN performance Date: Wed, 19 Dec 2018 13:40:19 +0100 Message-ID: <87imzpd70s.fsf@roquette.mug.biscuolo.net> References: <20181203154335.10366-1-ludo@gnu.org> <87tvju6145.fsf@gnu.org> <87ftv7l6gy.fsf@gmail.com> <871s6qzo6m.fsf_-_@gnu.org> <87y38tx365.fsf@gmail.com> <878t0thfp9.fsf@roquette.mug.biscuolo.net> <874lbfd0sd.fsf@netris.org> Mime-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:58030) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1gZb9W-00008U-F3 for guix-devel@gnu.org; Wed, 19 Dec 2018 07:40:43 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1gZb9Q-0005Fw-Mq for guix-devel@gnu.org; Wed, 19 Dec 2018 07:40:42 -0500 Received: from ns13.heimat.it ([46.4.214.66]:44534) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1gZb9J-000562-TD for guix-devel@gnu.org; Wed, 19 Dec 2018 07:40:30 -0500 In-Reply-To: <874lbfd0sd.fsf@netris.org> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Mark H Weaver Cc: guix-devel@gnu.org, 33600@debbugs.gnu.org --=-=-= Content-Type: text/plain Content-Transfer-Encoding: quoted-printable Hi Mark, sorry for the late reply Mark H Weaver writes: > Giovanni Biscuolo writes: >> with a solid infrastructure of "scientifically" trustable build farms, >> there are no reasons not to trust substitutes servers (this implies >> working towards 100% reproducibility of GuixSD) > > What does "scientifically trustable" mean? I'm still not able to elaborate on that (working on it, a sort of self-research-hack project) but I'm referencing to this message related to reduced bootstrap tarballs: https://lists.gnu.org/archive/html/guix-devel/2018-11/msg00347.html and the related reply by Jeremiah (unfortunately cannot find it in archives, Message-ID: <877eh81tm4.fsf@ITSx01.pdp10.guru>) in particular Jeremiah replied this: =2D-8<---------------cut here---------------start------------->8--- > so, if I don't get it wrong, every skilled engineer will be able to > build an "almost analogic" (zero bit of software preloaded) computing > machine ad use stage0/mes [1] as the "metre" [2] to calibrate all other > computing machines (thanks to reproducible builds)? well, I haven't thought of it in those terms but yes I guess that is one of the properties of the plan. =2D-8<---------------cut here---------------end--------------->8--- and =2D-8<---------------cut here---------------start------------->8--- > so, having the scientific proof that binary conforms to source, there > will be noo need to trust (the untrastable) Well, that is what someone else could do with it but not a direct goal of the work. =2D-8<---------------cut here---------------end--------------->8--- maybe a more correct definition of the above "scientific proof" should be "mathematical proof" I lack the theoretical basis to be more precise now, sorry :-S a marketing-like campaign sould be "no more trusting trust" best regards Giovanni =2D-=20 Giovanni Biscuolo Xelera IT Infrastructures --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERcxjuFJYydVfNLI5030Op87MORIFAlwaPDMACgkQ030Op87M ORLmMhAA3wY2DoFzwN39wWQuqUV4PKTMl9B+9hWl6MjL7J4tPsBWkgXn1QvjOF11 Fs7aX3kZ3swDhcfXR6DL9zj8ZmZplp0AqbLVuB+31Nvyy3kjFiW38XWlv65z7XCi 9AxXHndI3IxMEbVXk0v8Vjo7R4fj9n9tmV1Vw6nnv/n3FcAusrZRF9fH0lQrd/Su 8tL/30CLuLNBJWj5xxrV6HRmvki4Jdn8G/IqNAAj0mFS2XN0zYCNf+NlmXkd/Gmj hTMpxiWRtJiGXCQEzElPZjiOw/Ce48oCqjvsCsQa5a5JY2gLp7LM8tWA/Uqo5NrC 5kuCL6Oe/izl2tex9pOMKO/wVct0bCTPLNjOJUQaUIS13V4H7yf8VhwK6Nq2KV+K wdqKmegWvaDO1jXuHBRbW8L1HXxD1YvUUrn7rXVd/DTGPeltyI38wDG6Z3L33Sli gelYo3ZC7Ia3ZtER/75sCKXqUSzBSPGbzztC6W6AsUtun8S9ofk3N5lZx4M3dssL VHb2QZtLIlkU5OMWhaKrz+szM1SQGMBYD0xoe9t3qZgUrdq78M1Yeo+qFOd3vWbA 2g7CWAx8ah9sPAC5MZiojF2OqMhRCuYSUJ/ene0ukQgr10+lY3ZunOx6bNFyJQiR NpQQFbwCfYfPCtlibrv2+QGxG38MI65WMnu+Kyc74eJTR0HtqWE= =RMw8 -----END PGP SIGNATURE----- --=-=-=--