Question for the beautiful people out there who main guixsd: did guix's whole reproducible builds thing prevent the xz backdoor? I heard it was only present in binaries from the maintainer, so #guix should be immune right?

@aeva it was only (fully) present in _source tarballs_ from maintainer (but not in the repo), so that depends on where guix was getting its sources from.

Follow

@aeva

Also, its activation conditions were pretty strict (both at build time as well as at runtime), so there's a good chance it wouldn't enable itself there even if the malicious sources were used.

Sign in to participate in the conversation
Qoto Mastodon

QOTO: Question Others to Teach Ourselves
An inclusive, Academic Freedom, instance
All cultures welcome.
Hate speech and harassment strictly forbidden.