guix-patches
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[bug#37466] [PATCH 2/4] gnu: Add heads.


From: Danny Milosavljevic
Subject: [bug#37466] [PATCH 2/4] gnu: Add heads.
Date: Fri, 20 Sep 2019 15:49:54 +0200

Hi Björn,

On Fri, 20 Sep 2019 14:05:29 +0200
Björn Höfling <address@hidden> wrote:

> That's the non-free kernel, right?

Right.

> Besides that neither DNS nor Google knows that host.

Hmm, you're right, but it worked for me.  Doesn't work now.
Using "www" is probably better anyhow (and works).

> In general, this long list of source-files looks a bit strange: I think
> all/most of these packages are already a Guix package, where
> the source code is (more or less) verified to be FSDG-compatible,
> possibly with a snipped. Now this package is just getting a huge list of
> unreviewed source tarballs in. Hm.
> 
> Could we at least somehow reference the source package from Guix?

Well, heads provides an initrd and they want reproducible builds for it for
security purposes--that's the main reason they build a "cross" compiler too:
To have the compiler produce verifiable executables.

So basically if we change the version or anything, the hashes won't match
any more and any person going along their installation guide should
abort the installation--because heads has presumably been tampered with.

Not sure what to do about it.

Maybe at least linux-libre produces bitwise identical outputs to Linux
for what they care about.  I'll try it.

Attachment: pgp6UiYAioa7d.pgp
Description: OpenPGP digital signature


reply via email to

[Prev in Thread] Current Thread [Next in Thread]