Working towards a source-based bootstrapping path to a GNU+Linux system
bootstrappable.org
bootstrappable.org
This is important, even if you don't intend to run GNU Guix itself. I care about building GNU userland for embedded targets, and even with a build system like Yocto, which builds specific versions of the entire host userland, you can get errors due to eg. an older gnu m4 not being buildable with a modern glibc. Thus, you end up essentially requiring developers to build inside a container.
This is paving the way for having everything required to build a piece of software just checked into the git repository. If you want to change it, you just commit it like everything else.
was a project to boot the Linux kernel directly from source code using a C compiler as part of the boot process.
https://github.com/fosslinux/live-bootstrap/blob/master/part...
All that said, I am not an expert so would like to learn more. Can somebody let me know why one cannot just take the assembly version of an existing compiler and carefully review its code to be happy with it and then build everything from that verified compiler? Why does it need so many steps?
GCC 4.7 is the last version that can be built from source using only a C compiler. GCC has long included the C++ compiler inside, but didn’t require one to build until 4.8.
Because your current OS to load the assembly code may have been poisoned to present you with a sanitized version on the compiler.
I'm 50/50 on whether someone at some point hasn't executed a successful Trusting Trust attack (see Ken Thompson). With modern machines that have megabytes of binary blobs, different co-processors that have access to the RAM while they can't be reprogrammed to be on the user's side, and techniques that can actually tell when sensitive operations are happening, such attacks are becoming more feasible.