Lots of progress for Debian's reproducible builds
lwn.net
lwn.net
http://meetings-archive.debian.net/pub/debian-meetings/2015/...
Sorry, I didn't realise it had been posted before.
The big push for reproducible builds came in the wake of the Snowden evidence that the NSA was specifically and systematically attacking the machines of system administrators in order to gain access to the machines they controlled. Debian and Tor developers should logically be even bigger attack targets.
Let's say you had a bug, and are trying to see when it was introduced.
Something like the compilation time printed in a log at startup you don't really care about, the versions of each part of your build chain and all dependencies are where your focus will be. This is easier to achieve.
Unless the compilation time is the source of the bug :)
If you could reproduce that environment easily and instantly, you wouldn't need Docker since you'd just reproduce it every time.
Even if, hypothetically, it were trivial for NixOS to obtain perfect reproducibility, that doesn't necessarily help with making Debian reproducible in a backwards-compatible way.
https://reproducible.debian.net/index_issues.html
Almost none of those things are debian specific - they're things like "the timestamp of when this was built is put in the documentation" or "the kernel version is put in the binary".
Issues of those types would affect any OS and build system, and are would impact any system, even one with source purity goals like NixOS and similar.
I only found this issue on the Tor tracker, and apparently NixOS does not produce reproducible builds in the same way as intended by Debian: https://trac.torproject.org/projects/tor/ticket/12520
I hope this is the case, as I believe that one thing that holds Linux/BSD back from further refinement is the workload involved to maintain packages.
The XDG App effort to produce standardized runtimes and isolated applications is probably what you're looking for, but it is completely orthogonal to reproducible builds as runtimes for XDG App can be built in a multitude of ways, eg. with pre-built distribution packages (reproducible or not).
They even try to link mutt to a particular version of gpg, which is a bit extreme as mutt calls gpg via shell so the interface between both is really really loose.
That said I really like nix.
Yes they still use dynamic linking in the technical sense, as the libs are not folded into the resulting binary.
But they miss the spirit (or raison d'etre if you will) of dynamic linking by making hashing part of the linker requirements.
Its something that seems to crop up more and more in the Linux world these days.