all messages for Guix-related lists mirrored at yhetil.org
 help / color / mirror / code / Atom feed
From: Andreas Enge <andreas@enge.fr>
To: Andy Wingo <wingo@igalia.com>
Cc: guix-devel@gnu.org
Subject: Re: Yet another Hydra mirror: hydra-mirror.marusich.info
Date: Tue, 8 Mar 2016 10:57:33 +0100	[thread overview]
Message-ID: <20160308095733.GA15199@solar> (raw)
In-Reply-To: <87oaap49y6.fsf@igalia.com>

On Tue, Mar 08, 2016 at 10:04:33AM +0100, Andy Wingo wrote:
> Right now hydra.gnu.org is in this weird situation where people who use
> it have to trust it, modulo "guix challenge" of course.  But really all
> we have to trust is the mapping from the derivation (like the "foo"
> package) to a hash of the build results; the actual build result could
> be transferred from anywhere with no trust issues at all, provided that
> we verify the hash.  (Do I understand the situation correctly?)

Yes, if I understand you correctly :-)  Clearly, we need to trust someone;
it is hydra.gnu.org (or more precisely, a machine in its build farm) that
creates the mapping from a derivation to a build result. So we cannot do
without trusting it. The signature that hydra provides serves two purposes:
it creates the hash and adds this trust value.

> Anyway
> it would be very interesting to be able to distribute the build products
> using more scalable channels without having to trust more people.

This is the case for the web caches, which distribute the signature of
hydra.gnu.org with the packages. Actually, any distribution process would do,
a DHT or any kind of store.

Andreas

  reply	other threads:[~2016-03-08  9:57 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2016-03-08  6:37 Yet another Hydra mirror: hydra-mirror.marusich.info Chris Marusich
2016-03-08  9:04 ` Andy Wingo
2016-03-08  9:57   ` Andreas Enge [this message]
2016-03-09 12:37     ` Ludovic Courtès
2016-03-08  9:13 ` Ludovic Courtès
2016-03-09  8:27   ` Chris Marusich
2016-03-09 12:42     ` Ludovic Courtès
2016-03-11  4:08       ` Chris Marusich
2016-03-11 14:47         ` Ludovic Courtès
2016-04-06 13:43 ` Nils Gillmann
2016-04-07  4:56   ` Chris Marusich

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20160308095733.GA15199@solar \
    --to=andreas@enge.fr \
    --cc=guix-devel@gnu.org \
    --cc=wingo@igalia.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
Code repositories for project(s) associated with this external index

	https://git.savannah.gnu.org/cgit/guix.git

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.