From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp1 ([2001:41d0:2:4a6f::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms11 with LMTPS id aEZjIMNZh18QSAAA0tVLHw (envelope-from ) for ; Wed, 14 Oct 2020 20:04:19 +0000 Received: from aspmx1.migadu.com ([2001:41d0:2:4a6f::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp1 with LMTPS id sAgwHMNZh1/7AgAAbx9fmQ (envelope-from ) for ; Wed, 14 Oct 2020 20:04:19 +0000 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id 2B6579402A0 for ; Wed, 14 Oct 2020 20:04:19 +0000 (UTC) Received: from localhost ([::1]:58854 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1kSn0T-0005Vc-SZ for larch@yhetil.org; Wed, 14 Oct 2020 16:04:17 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:49410) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1kSn0A-0005Tl-UA for guix-devel@gnu.org; Wed, 14 Oct 2020 16:03:58 -0400 Received: from mail-qt1-x834.google.com ([2607:f8b0:4864:20::834]:39389) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1kSn09-0006oZ-7s for guix-devel@gnu.org; Wed, 14 Oct 2020 16:03:58 -0400 Received: by mail-qt1-x834.google.com with SMTP id c13so218455qtx.6 for ; Wed, 14 Oct 2020 13:03:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to; bh=/8VF/klcpJmWiSqv7tLr6nL5O8ITNBdkAC87lCJ/pKk=; b=O48rR0t1itmXInc4S5PFjOjuvMPtRX8RrjE5cH0wjXya4sQrONhNPlhvteJuFv0LIg gezoPj5aIZ+ttgGGOgPef0AtwibIV+/GCxW9Ya+19sx7DxUvL8NEuhom7ZsOFpzh1QrR PS5177eqj21QWBPes1Rh5/fuUr7fxszIu1LljiDFzwwnujLsHmCMdyOUrAW9FKG1i0eo STpcdQZQWacOfL5z7fu/QXVH+BB8l/kNAx81XImUpnWfxG3QW0dSMejEQb+g47R7UOtE lqlk1rm1p2e8Osn6cxBZ53ty0/CJ0hVP4avrxyDopSShZXI2NLzypAU9Oyt8BwOqLKej Gp9A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to; bh=/8VF/klcpJmWiSqv7tLr6nL5O8ITNBdkAC87lCJ/pKk=; b=ktYcOMHN/curuGeH6KmOPMwGguuPy+4YIwS4ezfQsnB80orftwft8G0B1dPmK+MoKL 5syc8x7el3IJIeKttUVWhMafRzEqBZHPLjaqZsrqaPD+bERSc3I23YEnXCcFHRgKrEHw e/t7dTUu+WxV57IUiIF3rklHII3bKTq88imKAzlJgVLOP1QFmNIajlDXvRCq4ODAqPws e3UP5C3yowOD00Q907zVynqeJ73CELx3j7z2oY6D+uCjkDjyEc6M/98SiZLlg8GtfLis 245+it7CAuukeKbhsLf+XrSRj8qlAHaTY72ihgvRd3JQtkuRk67wuYukrzVJGTz46ekQ mq2Q== X-Gm-Message-State: AOAM531szk64uj2dtlxQ8JR19nC/V4cQ/3vY5bCCCkgFYFfrlf4iuQDF 6n9SiwQVm21HALnM3o+kVTQiilRWE5tkHpGY4anP/x4CHhI= X-Google-Smtp-Source: ABdhPJyCplQD84Cvl1Ab612ZPL+L0r/nStxOVN6eEKxXKiTegdFFlbKS8E5QHEaWvgOtqazvwWittxQovFMZBB72onc= X-Received: by 2002:ac8:4295:: with SMTP id o21mr814364qtl.313.1602705835963; Wed, 14 Oct 2020 13:03:55 -0700 (PDT) MIME-Version: 1.0 References: <86blh5jb9w.fsf@gmail.com> <87362g65i4.fsf@dismail.de> In-Reply-To: <87362g65i4.fsf@dismail.de> From: zimoun Date: Wed, 14 Oct 2020 22:03:44 +0200 Message-ID: Subject: Re: Diverse Double-Compiling, --with-c-toolchain and trusting trust To: zimoun , Guix Devel Content-Type: text/plain; charset="UTF-8" Received-SPF: pass client-ip=2607:f8b0:4864:20::834; envelope-from=zimon.toutoune@gmail.com; helo=mail-qt1-x834.google.com X-detected-operating-system: by eggs.gnu.org: No matching host in p0f cache. That's all we know. X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: guix-devel@gnu.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+larch=yhetil.org@gnu.org Sender: "Guix-devel" X-Scanner: scn0 Authentication-Results: aspmx1.migadu.com; dkim=pass header.d=gmail.com header.s=20161025 header.b=O48rR0t1; dmarc=pass (policy=none) header.from=gmail.com; spf=pass (aspmx1.migadu.com: domain of guix-devel-bounces@gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=guix-devel-bounces@gnu.org X-Spam-Score: -1.71 X-TUID: VgJ2CaScr/kj Dear, On Wed, 14 Oct 2020 at 20:12, Joshua Branson wrote: > This reminds me of the reflections on trusting trust: Hehe! The Diverse Double-Compiling (DDC) is a countermeasure against Trusting Trust attack. :-) If you are interested by the topic, one entry point is one of this links: 1: 2: 3: > If you get something like this working, and you'd like some help > assembling it into a blog post, please let me know! Thanks for the offer. I will keep it in mind. All the best, simon