TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Guix Reduces Bootstrap Seed by Half

284 pointsby stargraveover 5 years ago

8 comments

reacwebover 5 years ago
I do not understand. When I have started on linux, 25 floppies were enough for a full installation (including latex and X) on my big HD (120MB). How a striped down version of bash, coreutils&co and guile could require 120MB ?
评论 #21202516 未加载
评论 #21202843 未加载
评论 #21202478 未加载
评论 #21202246 未加载
评论 #21202415 未加载
yourapostasyover 5 years ago
Dayum...just how far do the turtles go? Even when they reach full source bootstrap, are they ruminating over concerns about the firmware&#x2F;BIOS? If <i>those</i> concerns are addressed with an equivalent bootstrap-seeded coreboot, then are there concerns with the silicon? I never even thought someone was taking this level of security seriously enough to actually put the effort into it, but I&#x27;m extremely glad to see they are. I can easily see high-security DevOps builds of secrets management stores driven by such a bootstrapped Guix to nearly indefinitely satisfy the provenance-type questions from the regulatory compliance teams I work with.
评论 #21203796 未加载
评论 #21203769 未加载
评论 #21202114 未加载
评论 #21202265 未加载
评论 #21203264 未加载
评论 #21201997 未加载
gglitchover 5 years ago
Neat - MES Scheme is apparently named after Alan Kay&#x27;s description of Lisp as the Maxwell&#x27;s equations of software.<p><a href="https:&#x2F;&#x2F;gitlab.com&#x2F;janneke&#x2F;mes" rel="nofollow">https:&#x2F;&#x2F;gitlab.com&#x2F;janneke&#x2F;mes</a>
评论 #21214579 未加载
archi42over 5 years ago
So the only trust anchor remaining are the kernel and the hardware. It seems an attacker has to build a kernel module that detects the bootstrapping process and injects the (self-replicating!) bad code while building the final gcc.<p>I like the work, but I still don&#x27;t think the kind of attack mitigated here is practical. OTOH it&#x27;s nice to have the option (if I was to build&#x2F;publish my own distribution I would use this as my trust anchor, plus some ancient hardware and Linux 2.4 CDs to build my own bootstrap environment; though as a random guy on the internet I am probably less trustable than e.g. the Debian people).
antoineMoPaover 5 years ago
Anyone using Guix in production? (Anyone using Guix?)
评论 #21203681 未加载
评论 #21206097 未加载
评论 #21208570 未加载
xvilkaover 5 years ago
I wonder if they target RISC-V platform too. Or OpenPOWER (the case of Raptor Engineering).
评论 #21203280 未加载
评论 #21214470 未加载
评论 #21207016 未加载
atianover 5 years ago
Yeah startups are gonna need another way of financing fast if seed amounts keep going down. If anything the startup age is over on the west coast.
评论 #21202219 未加载
m4r35n357over 5 years ago
Fascinating stuff!