blog

SEAN K.H. LIAO

Arch Linux Reproducible Builds

Reason I don't use Gentoo / Linux from Scratch: I don't want to build everything from source (on my puny xps 13). But have you ever wondered if the prebuilr binary packages you get through the repos are actually what they claim to be?

Reproducible Builds is an effort to change that, making build artifacts byte-for-byte identical and accountable. Arch Linux is in there, and here, with tooling like repro and rebuilderd to make it easier for end users to automate verifications.

Verifying means taking the distributed package, getting the sources, and building it yourself to compare the results.

It's all still alpha quality software, features are missing and may be buggy. I run / ran rebuilderd for [core] at some point.

notes

as of the time of writing: