Remix.run Logo
▲ imoverclocked 2 hours ago

There are classes of virus that are hard to detect. One is a compiler virus that passes itself from compiler to compiler. You only get rid of the vector by bootstrapping from 0.

▲Aissen 2 hours ago | parent | next [-]

No, you can do bootstrapping and save binaries for reuse with hash verification. Android did that for its Rust toolchain: https://cs.android.com/android/platform/superproject/main/+/...

Bootstrapping at every build does not save you from the threat you think it does.

▲duped an hour ago | parent | prev [-]

Sure but that's a compiler bootstrapping problem. It doesn't answer the question: why do you need to bootstrap the toolchain to build the distro? You can reuse a trusted toolchain that's been safely bootstrapped .

▲lrvick an hour ago | parent [-]

Because no other trusted toolchains exist under a threat model that trusts no single person or computer. We -are- the trusted toolchain.