Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This seems to me like a necessary complement to the efforts around making packages build reproducibly.

It has long been accepted that if a piece of software requires a non-Free compiler to build it, then that piece of software is de facto non-Free too. Taking that to its logical extreme, a piece of software isn't Free unless it can be built by a compiler whose recursive sequence of meta-compilers leads back to a minimal, audited binary seed.

Fortunately, once this has been done once (or multiple times independently, producing the same results), all future compilations and software can potentially enjoy the benefits of the process.



Assuming that you can trust the computers it's running on.


This is basically the argument made in "Reflections on Trusting Trust", the Turing Award Lecture of Ken Thompson.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: