3 ms·
> Reviews are done on what, you have someone reviewing clang code? Binutils? There aren't random developers pushing commits to these codebases: these are used
by TacticalCoder 2y ago
> Reviews are done on what, you have someone reviewing clang code? Binutils?
There aren't random developers pushing commits to these codebases: these are used by virtually every Linux distro out there (OK, maybe not the Kubernetes one that ships only 12 binaries, forgot its name).
It seems obvious to me that GP is talking about protection against rogue distro maintainers, not fundamental packages being backdoored.
You're basically saying: "GP's work is pointless because Linus could insert a backdoor in the Linux kernel".
In addition to that determinism and 100% reproducibility brings another gigantic benefit: should a backdoor ever be found in clang or one of the binutils tool, it's going to be 100% reproducible. And that is a big thing: being able to reproduce a backdoor is a godsend for security.
- lrvick 1y ago> OK, maybe not the Kubernetes one that ships only 12 binaries, forgot its name You are likely thinking of Talos Linux, which incidentally also builds itself with stagex.