Running an independent Arch Linux rebuilder
lists.reproducible-builds.org
lists.reproducible-builds.org
https://linderud.dev/blog/reproducible-arch-linux-packages/
EDIT: I did self-discover I did submit the article when I wrote it. Just forgot. Oh well :)
Not just is there obvious malware, but also are there obvious vulnerabilities, is the person that wrote it of good nature / located in a country where they’re safe from nation state pressure, is there a lot of history behind the app.
Obviously this is too much work for any individual and requires a chain of trust. I believe fedora and Ubuntu at the very least audit to some extent but I’ve never seen any doco.
I know Arch has: https://wiki.archlinux.org/index.php/Arch_Security_Team
but I'd be really interested to hear that the official packages have obvious malware.
Their documentation has some really good pointers at common issues and how to solve them: https://reproducible-builds.org/docs/
And the diffoscope tool is very useful for debugging.
[0] I believe other projects had similar things going on but the Debian one became the main to serve as an umbrella.
[0] https://wiki.archlinux.org/index.php/Rebuilderd
[1] https://wiki.archlinux.org/index.php/Rebuilderd#Syncing_pack...
take for example the aur package for MS fonts; https://aur.archlinux.org/packages/ttf-ms-fonts/
all it does is download a ton of microsoft corefont executables to unpack.
another example would be the proprietary driver packages, like the nvidia ones.
point still stands, aur does distribute executables once in awhile.
The AUR doesn't distribute those executables; it distributes the instructions for the user (or some software working on behalf of the user) to go fetch the executables themselves. This is an important distinction, because the official Arch repositories _do_ distribute executables, directly to the user.
Since end users build AUR packages themselves, there is nothing distributed, and nothing to verify.
Reproducible builds are for artifacts that are... built. Plenty of AUR recipes download blobs and explode them, but the resulting xz package isn't actually hosted in the AUR.
A tool like rebuilderd would only be relevant to the AUR in the case that somebody is publishing generated AUR packages to a repo for others to install without building them directly, and then you'd like to verify those.
Yes. AUR is excluded from reproducible builds because it only provides build scripts and not actual packages. There is nothing to reproduce. One surely could make a repo and compare results, but it would frankly be a bit futile considering the general package quality there.
https://github.com/archlinux/rebuilder https://github.com/archlinux/signstar
> a large number of builds are not reproducible yet
https://wiki.archlinux.org/index.php/DeveloperWiki:Reproduci...
It's still very much a work in progress.