From mboxrd@z Thu Jan 1 00:00:00 1970 From: Giovanni Biscuolo Subject: Re: Preparing the reduced bootstrap tarballs Date: Mon, 19 Nov 2018 19:54:43 +0100 Message-ID: <87muq428zw.fsf@roquette.mug.biscuolo.net> References: <87d0r322zy.fsf@ITSx01.pdp10.guru> Mime-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:45016) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1gOohB-0006zH-MT for guix-devel@gnu.org; Mon, 19 Nov 2018 13:54:54 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1gOoh6-00050x-MH for guix-devel@gnu.org; Mon, 19 Nov 2018 13:54:53 -0500 Received: from ns13.heimat.it ([46.4.214.66]:47620) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1gOoh6-0004zi-GF for guix-devel@gnu.org; Mon, 19 Nov 2018 13:54:48 -0500 In-Reply-To: <87d0r322zy.fsf@ITSx01.pdp10.guru> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Jeremiah@pdp10.guru, guix-devel@gnu.org --=-=-= Content-Type: text/plain Content-Transfer-Encoding: quoted-printable Hi Jeremiah, Jeremiah@pdp10.guru writes: [...] > and once I finally complete stage0; you would also have the blueprints > for making the virtual machine in hardware, so, if I don't get it wrong, every skilled engineer will be able to build an "almost analogic" (zero bit of software preloaded) computing machine ad use stage0/mes [1] as the "metre" [2] to calibrate all other computing machines (thanks to reproducible builds)? > hand toggle in the bits for the hex0-monitor the first bit of code have to be "manually" introduced in the machine, right? for the lazyer like me, what about a punched card? :-)=20 > and have absolute proof that no trusting trust or Nexus > Intruder Class attacks have occurred in the creation of the binaries. I didn't know about Nexus Intruder attacks: could you please give me some links to the relevant bibliography? > Every issue anyone is willing to bring, I will publicly address until > all bootstrap roots (even on arbitrary hardware) lead to the proof that > these binaries are perfectly reproducible and that they only behave in > the manner explicitly specified by the standards to which they > conform. so, having the scientific proof that binary conforms to source, there will be noo need to trust (the untrastable) thank you! Ciao Giovanni [2] I still have not fully understood the relationship between stage0 and mes [1] https://en.m.wikipedia.org/wiki/Metre =2D-=20 Giovanni Biscuolo Xelera IT Infrastructures --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERcxjuFJYydVfNLI5030Op87MORIFAlvzBvMACgkQ030Op87M ORKjzRAAudIEOy/B22dOdOhT+xroL3RYiat9I+f9h+jZgm21K5/49biBILDrqU20 a/YWzmCVDo1d/Wq37FXkYWqMKSpBrEcNc6DhlbPZ/1Hom35e7IdisRCBLsliMt66 6Y+a1QBNz1acWrM0NXhWyyBZWW1oA0OLTSU+sA2EP/+wwRcz3iLKiKpEv09Kg/4j jL8kNu+MIGlLRJFPwzIi6Wqdh0pNUu1osN8q8xJDEukOX93hNXBA+tPs6v/AycCi fbnGNmE3l970QgKLcxcrvXT4wbkTccA180p1sHnF6D73FFsSWnEAZP57bMbk1rjd YYS+XIdth/gDmaOyzCNKz5K+6XRxdkwxCFwKP4ElFjUdElhWRouc529GvbIWBImm /99eehAwiTUFewgGjTtoXSgKnqtjFGIxXJXoznHa7lN/U+tyAnhl5O4SgAkymYwF Xd1hvI1KLFNJD8T/b15IlIr4H1/86tAxUJ6tBu4j4aqwR3NCyhWjBiTF/lmq/4pw f1AE+HO3WS1eTab/NCpRrerMl8tTNZ1vchJ7KnXrHD/Ackdpj52G+YLGhffpRGw5 Z0r6fnWeywRuEA1uu6vBZPkI9A8NbYos14NoGR1YgRNU0l7Ub2uNwuhn7aaKHZPP chJRvk6a9G8fMcabCSrakO5F1cS8x3G2DBT5+NKcJyEvSoh9T6k= =xTdL -----END PGP SIGNATURE----- --=-=-=--