Does this sound right? I’m trying to figure out where uncontrollable randomness would come in during a compile phase, and coming up blank.
Does this sound right? I’m trying to figure out where uncontrollable randomness would come in during a compile phase, and coming up blank.
I have not followed the progress recently, but https://reproducible-builds.org/ is a starting point if you are interested.
There is a sane path forward for reproducibility on bare metal, no custom emulation is needed.
Both your causes seem trivially fixable here - the QEMU builds could have a standard system clock time they start with, and an ‘unsorted’ file listing made in a deterministic OS environment will keep the same file order, no?
By comparison the rb.org site says you need to start with stripping all that stuff out of your build process, for the reasons you refer to.
You'd be amazed about the amount of indeterminsim lurking in the guts of depencies all the way into libc and os ... Like locale, fs
Deterministic replay with QEMU is a "power tool" in the larger picture of these efforts.
So it'd be good for cases where you otherwise wouldn't be able to provide any verifiability. But for software, it's still not as good as eliminating non-determinism completely.
E.G. There could be malicious code hidden in the free RAM.