From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:470:142:3::10]:57185) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1iBJJR-0006Ug-1N for guix-patches@gnu.org; Fri, 20 Sep 2019 09:51:07 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1iBJJP-0002CM-Fv for guix-patches@gnu.org; Fri, 20 Sep 2019 09:51:04 -0400 Received: from debbugs.gnu.org ([209.51.188.43]:48167) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1iBJJO-0002Bq-1q for guix-patches@gnu.org; Fri, 20 Sep 2019 09:51:02 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1iBJJN-0007XA-UA for guix-patches@gnu.org; Fri, 20 Sep 2019 09:51:01 -0400 Subject: [bug#37466] [PATCH 2/4] gnu: Add heads. Resent-Message-ID: Date: Fri, 20 Sep 2019 15:49:54 +0200 From: Danny Milosavljevic Message-ID: <20190920154954.35713605@scratchpost.org> In-Reply-To: <20190920140529.234c55ad@alma-ubu> References: <20190920010248.28082-1-dannym@scratchpost.org> <20190920073149.2933-1-dannym@scratchpost.org> <20190920073149.2933-2-dannym@scratchpost.org> <20190920140529.234c55ad@alma-ubu> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; boundary="Sig_/8tCO2BHUY_NKWCIgzpFV7HU"; protocol="application/pgp-signature" List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+kyle=kyleam.com@gnu.org Sender: "Guix-patches" To: =?UTF-8?Q?Bj=C3=B6rn_?= =?UTF-8?Q?H=C3=B6fling?= Cc: 37466@debbugs.gnu.org --Sig_/8tCO2BHUY_NKWCIgzpFV7HU Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable Hi Bj=C3=B6rn, On Fri, 20 Sep 2019 14:05:29 +0200 Bj=C3=B6rn H=C3=B6fling wrote: > That's the non-free kernel, right? Right. > Besides that neither DNS nor Google knows that host. Hmm, you're right, but it worked for me. Doesn't work now. Using "www" is probably better anyhow (and works). > In general, this long list of source-files looks a bit strange: I think > all/most of these packages are already a Guix package, where > the source code is (more or less) verified to be FSDG-compatible, > possibly with a snipped. Now this package is just getting a huge list of > unreviewed source tarballs in. Hm. >=20 > Could we at least somehow reference the source package from Guix? Well, heads provides an initrd and they want reproducible builds for it for security purposes--that's the main reason they build a "cross" compiler too: To have the compiler produce verifiable executables. So basically if we change the version or anything, the hashes won't match any more and any person going along their installation guide should abort the installation--because heads has presumably been tampered with. Not sure what to do about it. Maybe at least linux-libre produces bitwise identical outputs to Linux for what they care about. I'll try it. --Sig_/8tCO2BHUY_NKWCIgzpFV7HU Content-Type: application/pgp-signature Content-Description: OpenPGP digital signature -----BEGIN PGP SIGNATURE----- iQEzBAEBCAAdFiEEds7GsXJ0tGXALbPZ5xo1VCwwuqUFAl2E2QIACgkQ5xo1VCww uqVHzAf/RqxETW1BnnaY0oqKiqDlOsU8lMhebn4DblVj0wWQc/Frk8V4X8ysD5g9 BPN7SORWfm5DSY9Bp0lEuj5pY93yCHNaIWSduGLLZ7ypQYz/9jAgM4agDY5B2AW+ V00Byfas5tRpvosxEMjOTDaM4hh0Lr8+llKnJCI6vJjdI3DXClpwfRQ7xmNzAadU w8QEBj2iZC2NWkf56dv4sm23M8weHZMjhXOBIKfmG/P72Tr4libp8nhCe62En6if 02h9jEkdMlVcTQziQ6oxhEqoRDLQLxDGkUh+zdd+KcLPhHULrE230hRE1DZhpAqh 75lahkQNWeiEHz8upkVXgQvQcBnN0Q== =VP1E -----END PGP SIGNATURE----- --Sig_/8tCO2BHUY_NKWCIgzpFV7HU--