os: add experimental reproducible Debian/mkosi backend#816
Conversation
|
Reproducibility/clean-build follow-up pushed as Verified with the exact full two-clean-build gate: The two Additional gates rerun successfully:
|
|
Post-push QEMU smoke test also passed the intended platform-independent portion on the final reproducible |
|
Added the missing SEV-SNP artifact chain in
Verification:
Rootfs size attribution versus |
|
Added the explicitly opt-in, development-only mkosi component cache in Security/audit boundary:
Cached component outputs: dstack Rust, container stack, Sysbox, nvattest, kernel source/build/stage, NVIDIA, ZFS, and TDX+SNP OVMF. Measured verification (
Usage: DSTACK_DEV_CACHE_DIR="$HOME/.cache/dstack/mkosi-dev" \
./os/mkosi/build.sh dev-image "$PWD/os/mkosi/build-dev" |
|
Follow-up |
|
Refactored the cache implementation in Structure now has three explicit layers:
In particular, Revalidated refactored HEAD:
|
|
Rootfs size parity is now pushed through Measured against the supplied Yocto 0.6.0 artifact: Retained changes:
Verification evidence:
|
Summary
os/image/assemble.shrelease pathValidation
./os/mkosi/build.sh lintdstack-0.6.0.tar.gzanddstack-0.6.0-uki.tar.gzswitch_root, and Debian systemdNotes
This remains experimental. Package contents are Debian rather than Yocto, while the external release contract and file/partition layout are shared with the Yocto backend.