【文章标题】:Bootstrappable Builds: How and Why 可引导构建:方法与意义
【文章正文】: Bootstrappable builds: how and why 可引导构建:方法与意义
This article brought to you by LWN subscribers 本文由LWN订阅用户赞助呈现
Subscribers to LWN.net made this article — and everything that surrounds it — possible. If you appreciate our content, please buy a subscription and make the next set of articles possible. LWN.net的订阅者使这篇文章及其相关内容成为可能。如果您认可我们的内容,请购买订阅以支持后续文章创作。
This year’s edition of the Free and Open Source Software Yearly conference, better known as “FOSSY”, moved north to the beautiful (and enormous) campus of the University of British Columbia (UBC) in Vancouver, Canada from its home for the three previous editions: Portland, Oregon, in the US. There were many different types of talks at FOSSY, from deeply technical kernel-track topics, through talks on legal and community issues, to the “FOSS in Daily Life” talks. In the “Toolchains and Other Development Tools” track, Timothy Sample gave a presentation about bootstrappable builds, which is somewhat less well-known than its cousin, reproducible builds, though LWN did look at the topic just over two years ago. In short, a bootstrappable build is one that starts with a tiny program that can build another slightly larger program, which can build yet another, and so on, until the entirety of a modern Linux user space is built from a small seed. Ultimately, it results in code with a completely understood origin—unlike a typical Linux user space today. 今年的自由开源软件年度会议(简称FOSSY)从过去三届的举办地美国俄勒冈州波特兰市北迁至加拿大温哥华英属哥伦比亚大学(UBC)美丽而广阔的校园。FOSSY涵盖了多种类型的演讲,从深度的内核技术主题到法律与社区议题,再到”日常生活中的FOSS”专题。在”工具链与其他开发工具”专题中,Timothy Sample就”可引导构建”进行了演讲——这个概念虽不如其姊妹概念”可复现构建”知名,但LWN确实在两年前探讨过该主题。简而言之,可引导构建是指从一个能构建稍大程序的小程序开始,层层递进,最终从微小种子构建出完整的现代Linux用户空间。与当今典型的Linux用户空间不同,这种方式能产出完全可溯源的代码。
He began by asking attendees whether they had heard of bootstrappable builds and whether they were generally familiar with the idea; he seemed impressed that the majority knew the term and that roughly half of the audience knew more than that. He said that he embarked on the path toward bootstrappable builds almost ten years ago when he started using GNU Guix (which he pronounced “geeks”—surprising me). At that time, if you were using Guix, you were contributing to it, he said with a chuckle. Guix is a “functional package manager” that is similar to (and inspired by) Nix. 他首先询问与会者是否听说过可引导构建以及是否大致了解这个概念;当发现多数人知道这个术语且约半数听众有更深了解时,他显得颇为惊讶。他提到自己约十年前开始使用GNU Guix(他发音为”geeks”,这让我很意外)时,就踏上了可引导构建之路。当时若有人使用Guix,就相当于在为其做贡献,他笑着说道。Guix是一个”函数式包管理器”,与Nix类似(并受其启发)。
For both Guix and Nix, all of the software in the system is represented in a “derivation graph”, which describes how to build each of its programs. There are various inputs required in order to be able to build a particular program, which are specified in the graph. The way to build each of the inputs (and, of course, the inputs to the inputs and so on) is also represented in the graph. “There’s hundreds and hundreds of nodes in modern software, which is terrifyingly complex.” 对于Guix和Nix而言,系统中所有软件都体现在”派生图”中,该图描述了每个程序的构建方式。构建特定程序需要各种输入,这些都在图中被明确指定。图中还包含了每个输入(以及输入的输入等)的构建方式。“现代软件中有成百上千个节点,复杂程度令人咋舌。”
He gave the example of a Python program. It, obviously, requires Python in order to run, but Python is a C program, so a C compiler is needed. That C compiler is written in some language, so a compiler for that language will be needed. And so on. Guix collects all of that into the graph, which is an object that can be looked at and explored. “So you start wondering who compiles my compiler’s compiler compiler and where does it stop?” 他以Python程序为例:显然运行Python需要Python解释器,但Python本身是C程序,因此需要C编译器。而该C编译器又由某种语言编写,于是又需要该语言的编译器……如此循环。Guix将所有依赖关系整合进图中,形成可追溯的对象。“于是你开始思考:谁在编译我的编译器的编译器的编译器?这个链条止于何处?”
For a system like Debian, it stops at a C compiler binary that someone has uploaded to the repositories. For Guix, the original stopping point was a 250MB statically linked blob of GNU user-space programs. The answer to where all of that code came from is not entirely clear, of course, which was unsatisfying to Guix developers. That blob could be built reproducibly, which is good, Sample said, but does not solve the entire problem. 对于Debian这类系统,链条终止于某人上传到软件仓库的C编译器二进制文件。而Guix最初的终止点是一个250MB的GNU用户空间程序静态链接块。这些代码的确切来源并不完全清晰,这让Guix开发者感到不满。Sample表示,虽然该链接块可以复现构建(这很好),但并未彻底解决问题。
Bootstrappable 可引导性
The basic idea behind bootstrappable builds is to create a system that can be built without relying on pre-built artifacts. “Can we go from zero to the modern day without having to just assume the existence of these already-built-for-us artifacts?” The classic recipe for yogurt requires some yogurt to start the process, which is like how we normally build a C compiler today—we start with an existing C compiler binary. You might think about making sourdough bread with your grandmother’s starter brought over from the old country; “we’re basically making C compilers with Dennis Ritchie’s starter carried over from Bell Labs”. 可引导构建的基本理念是创建不依赖预构建产物的系统。“我们能否从零开始构建现代系统,而不必假设这些现成构建产物的存在?“就像制作酸奶需要引子,如今我们构建C编译器也始于现有的C编译器二进制文件。这让人想起用祖传酵母制作酸面包的场景:“我们本质上是用Dennis Ritchie从贝尔实验室传承的’引子’来制作C编译器”。
It is not just C, of course, as it is true for most languages. It is something of a point of pride for languages to “self host” by writing the compiler and other tools in the language itself. It is natural for the language developers to do that, because obviously their language is the best, but it leaves something of a chicken-and-egg problem behind. Bootstrappable builds is an effort to move beyond that and to build these tools “from scratch”. 当然这不仅限于C语言,大多数语言都是如此。语言开发者用该语言自身编写编译器和其他工具来实现”自托管”,这常被视为荣誉象征——毕竟他们自然认为自己的语言是最好的——但这留下了先有鸡还是先有蛋的问题。可引导构建正是为了突破这种局限,实现”从零开始”构建这些工具。
Reproducible builds allow people to “have more confidence that the binary you are using, which is actually executing on the computer, corresponds to the source code”. A user can receive a binary that purports to come from a set of source code files, but how can they be sure that it does? With a reproducible build, they can create the binary themselves and check to ensure that it is bit-for-bit the same as what they were given. 可复现构建让人们”更确信计算机上运行的二进制文件确实对应着源代码”。用户可能收到声称由某组源代码生成的二进制文件,但要如何验证真伪?通过可复现构建,他们可以自行生成二进制文件,并逐位核验是否与收到的文件完全一致。
Bootstrappable builds do exactly the same thing, but they handle a different failure mode. If a reproducible build fails to 可引导构建实现相同的目标,但针对不同的故障模式。如果可复现构建未能…