3 ms·
Good thing. NetBSD has fully reproductible build since 2017. https://blog.netbsd.org/tnf/entry/netbsd_fully_reproducible_builds https://blog.netbsd.org/tnf/entr
by jaypatelani 5mo ago
Good thing. NetBSD has fully reproductible build since 2017. https://blog.netbsd.org/tnf/entry/netbsd_fully_reproducible_builds https://blog.netbsd.org/tnf/entry/netbsd_fully_reproducible_...
- idoubtit 5mo agoAs pointed in your link, NetBSD achieved this with some help from Debian. If I understand correctly, it's not that NetBSD tried harder, it's that their problem was easier: fewer packages which change less (they still use CVS, "stability" is an understatement!). BTW, most Debian packages have reproducible builds. Those which have not (I'd say 5%) are shown in orange in the graph there: https://wiki.debian.org/ReproducibleBuilds https://wiki.debian.org/ReproducibleBuilds
- kakwa_ 5mo agoAlso, the *BSD are structured somewhat differently to a Linux distro. It's not like the Linux world where you have distinct projects like the Kernel, GNU, OpenSSL, and then it's the distributions job to assemble everything. In the BSD projects, the scope is developing and distributing an entire base system, i.e., the kernel but also the libc, the shell/all posix utilities, and a few third parties like OpenSSH (which are usually "softforked"). It's quite visible in the sources, it's a lot more than just a kernel: https://github.com/NetBSD/src https://github.com/NetBSD/src Additional packages you could get from pkg_in/pkgsrc (NetBSD), pkg-ng/ports (FreeBSD) or pkg_add (OpenBSD) are clearly distinct from the base system, installed in a dedicated subtree (/usr/src in NetBSD, /usr/local/ OpenBSD/FreeBSD), and provided in a best effort manner. The reproducible build target was almost certainly only for the base system, which is a few percent of what Debian tries to achieve, and on which NetBSD has a tighter control over (developer + distributor instead of downstream assembler+distributor). A reproducible base system is useful, but given how quickly you typically need to install packages from pkgsrc, it's not quite enough.
- mmooss 5mo ago> it's not that NetBSD tried harder, it's that their problem was easier: fewer packages which change less Maybe that's trying harder on design rather than trying to remedy the consequences later.
- lrvick 5mo agoWhile we are bragging, stagex was the first to hit 100% full source bootstrapped deterministic and hermetic builds last year and the first to make multiple signed reproductions by different maintainers on their own hardware mandatory for every release. Debian has come along way, but when Debian says reproducible they mean they grab third party binaries to build theirs. When we say reproducible we mean 100% bootstrapped from source code all the way through the entire software supply chain. We think that distinction matters. https://stagex.tools https://stagex.tools
- PunchyHamster 5mo agoThat distro has smaller codebase than Debian Installer.
- nrvn 5mo agoThis! Unfortunately, the term “reproducible” can be interpreted in many ways because there is no strict and complete definition. People and projects bend it to their liking. Your approach is correct. https://www.bootstrappable.org/ https://www.bootstrappable.org/
- deleted 5mo ago[deleted]
- deknos 5mo agonewcomers will always have it much easier. also guix i think also reached this. also, stagex and others probably profited QUITE A LOT from the debian efforts, because they started to go upstream and talking to developers.. just arch linux profited from debian maintainers a decade before that an debian people asking upstream to improve...
- lrvick 5mo agoGuix did a full source bootstrap first, credit where well due, but it does not apply to their whole tree. E.g haskell is bootstrapped with a binary, qemu includes binary firmware blobs, etc. Guix is not fully bootstrapped or reproducible. To your point though, the incomplete efforts of many other distros absolutely accelerated us.