logoalt Hacker News

imoverclocked • yesterday at 6:39 PM • 2 replies • view on HN

There are classes of virus that are hard to detect. One is a compiler virus that passes itself from compiler to compiler. You only get rid of the vector by bootstrapping from 0.


Replies

Aissen • yesterday at 7:01 PM

No, you can do bootstrapping and save binaries for reuse with hash verification. Android did that for its Rust toolchain: https://cs.android.com/android/platform/superproject/main/+/...

Bootstrapping at every build does not save you from the threat you think it does.

➕ show 1 reply
duped • yesterday at 7:06 PM

Sure but that's a compiler bootstrapping problem. It doesn't answer the question: why do you need to bootstrap the toolchain to build the distro? You can reuse a trusted toolchain that's been safely bootstrapped .

➕ show 1 reply