One thing missing from this is a trust framework where cache writers would sign their compiled code. There could also be a verification layer.
One thing missing from this is a trust framework where cache writers would sign their compiled code. There could also be a verification layer.
Building big sharable package systems is indeed a second half of the problem. Figuring out how to make the system have the hashy goodness AND be usefully collaborative with async swarms of people working independently and yet sharing work: tricky. We're trying to do it, though!
We have our first few packages now published, here: https://catalog.warpsys.org/
You can also see _how_ we build things, because we publish the full rebuild instructions with each release: for example, here's how we packaged our bash: https://catalog.warpsys.org/warpsys.org/bash/_replays/zM5K3V...
I'm in #warpforge on matrix with some collaborators if anyone's interested in joining us for a chat and some hacking :)
gittup[1] implements part of this idea, but without the distributed bit. bazel[2] implements the distributed bit (minus trust), but not the distro bit. What's really lacking is momentum around the idea to get a sufficient number of people behind it.
[1]: https://github.com/gittup/gittup [2]: https://bazel.build/
Besides the global cache for the whole distro, you can also set up caches for other software. For example, if you build your projects with Nix, you can have a cache for your projects (so that new contributors won't need to recompile everything from scratch). That's the premise behind https://www.cachix.org/
The only difference is that Nix caches aren't fine grained like ccache and sccache