Dear Michael,

Unfortunately I have to protest when you make a statement like this:

On Mon, Jul 06, 2026 at 04:03:56PM +0000, Michael Ackermann via Tinycc-devel 
wrote:
> Long story short, tinycc is a crucial component to accomplish the only known
> complete(!) system bootstrap which exists today, that is live-bootstrap for 
> x86_32 "only".

A complete Posix-like system, i.e. including its kernel, utility programs
and compilers, created as a reproducible binary, without reliance on
_any_ specific binary blobs, is available since several years ago from
the VSOBFS project.

You know this.

Please do not let your enthusiasm about the tinycc's role in bootstrapping
replace a healthy respect to the facts.

Please also note:

"Bootstrapping" is hardly relevant for practical security.

There are unfortunately much more important problems, like trust in
supply chains or source code with hidden backdoors.

A potentially trustable compiler (the stated purpose of "bootstrapping")
does not help there.

The "bootstrapping" projects live because they look cool, inspire
learning and because it is tempting to see them as security means,
which they actually are not.

Regards
/tccm

_______________________________________________
Tinycc-devel mailing list
[email protected]
https://lists.nongnu.org/mailman/listinfo/tinycc-devel

Reply via email to