Perfectly Reproducible, Verified Go Toolchains
1–6 of 6 posts
Re: Perfectly Reproducible, Verified Go Toolchains
#2Re: Perfectly Reproducible, Verified Go Toolchains
#3"Now we can diff the Go toolchain we’ve created on our Mac with the Go toolchain that Ubuntu ships:" [..]
"We’ve successfully reproduced the Ubuntu package’s executables" [..]
"Note in particular that we’ve reconstructed the toolchain binaries bit-for-bit: they do not show up in the diff at all. That is, we proved that the Ubuntu Go binaries correspond exactly to the upstream Go sources."
Also, for your own programs:
"For Go programs that don’t need cgo, a reproducible build is as simple as compiling with CGO_ENABLED=0 go build -trimpath. Disabling cgo removes the host C toolchain as a relevant input, and -trimpath removes the current directory"
Re: Perfectly Reproducible, Verified Go Toolchains
#4Features like this take a lot of effort and aren't very visible, but are very much appreciated. Thanks to everyone who worked on this!
Re: Perfectly Reproducible, Verified Go Toolchains
#5So, as much as I appreciate what Russ Cox is doing in general, how to just switch it off?
Re: Perfectly Reproducible, Verified Go Toolchains
#6Great for CI maybe... not so much on the traveller's dev laptop where you want to be quick and often operate on a broken internet link. So, as much as I appreciate what Russ Cox is doing in general, how to just switch it off?
I couldn't see any mention of needing an internet link.