3 ms·
>Opportunistic use of neighboring substitute servers is entirely safe, thanks to reproducible builds. How does this work? Just because the builds are reproduci
by catern 5y ago
>Opportunistic use of neighboring substitute servers is entirely safe, thanks to reproducible builds.
How does this work? Just because the builds are reproducible doesn't mean that the artifacts published by substitute servers are actually the outputs of the build process you expect.
- medstrom 5y agoIt is known what the SHA hash of the built artifact should be. https://guix.gnu.org/manual/en/html_node/Invoking-guix-challenge.html https://guix.gnu.org/manual/en/html_node/Invoking-guix-chall...
- catern 5y agoBut that SHA hash of the built artifact doesn't go in the package recipe. So how do I know what the SHA hash of the built artifact should be, if all I have is the Guix repo? I can always rebuild the artifacts myself using "challenge", but that defeats the purpose of using the substitute server...
- mbakke 5y agoIt means that if a server on your LAN advertises a substitute for a derivation that is bit-identical with one that is signed by an authorized substitute server (such as ci.guix.gnu.org), the build output will be downloaded from your network neighbor instead of over the internet. Of course this requires that ci.guix.gnu.org has already built the same derivation.
- catern 5y agoAh, thanks, makes sense! So it's just a bandwidth-saving device - still, sounds quite useful.
- medstrom 5y agoIt opens the door for more peer-to-peer distribution in the future. Imagine if every Guix system published their builds (as an opt-out setting). Then even if you modify a package's build options, a few other people might have made the exact same modification and you can download the built artifact from them.