guix-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Yet another Hydra mirror: hydra-mirror.marusich.info


From: Andreas Enge
Subject: Re: Yet another Hydra mirror: hydra-mirror.marusich.info
Date: Tue, 8 Mar 2016 10:57:33 +0100
User-agent: Mutt/1.5.24 (2015-08-30)

On Tue, Mar 08, 2016 at 10:04:33AM +0100, Andy Wingo wrote:
> Right now hydra.gnu.org is in this weird situation where people who use
> it have to trust it, modulo "guix challenge" of course.  But really all
> we have to trust is the mapping from the derivation (like the "foo"
> package) to a hash of the build results; the actual build result could
> be transferred from anywhere with no trust issues at all, provided that
> we verify the hash.  (Do I understand the situation correctly?)

Yes, if I understand you correctly :-)  Clearly, we need to trust someone;
it is hydra.gnu.org (or more precisely, a machine in its build farm) that
creates the mapping from a derivation to a build result. So we cannot do
without trusting it. The signature that hydra provides serves two purposes:
it creates the hash and adds this trust value.

> Anyway
> it would be very interesting to be able to distribute the build products
> using more scalable channels without having to trust more people.

This is the case for the web caches, which distribute the signature of
hydra.gnu.org with the packages. Actually, any distribution process would do,
a DHT or any kind of store.

Andreas




reply via email to

[Prev in Thread] Current Thread [Next in Thread]