aboutsummaryrefslogtreecommitdiff
-*- mode: org; coding: utf-8; -*-

#+TITLE: Tentative GNU Guix Road Map

Copyright © 2012, 2013, 2014, 2015 Ludovic Courtès <ludo@gnu.org>

  Copying and distribution of this file, with or without modification,
  are permitted in any medium without royalty provided the copyright
  notice and this notice are preserved.

The goals of the GNU Guix project are two-fold:

  - to build a purely functional package manager, based on Nix and
    Guile;

  - to use it to build a practical 100% free software distribution of
    GNU/Linux and possibly other GNU variants, with a focus on the
    promotion and tight integration of GNU components–the GNU system.

Since its inception, the project has gone a long way towards that goal.  Below
is a list of items we want for version "1.0" of the Guix System Distribution.
There will be a few 0.x releases by then to give the new features more
exposure and testing.

You're welcome to discuss this road map on guix-devel@gnu.org or #guix on
the Libera Chat IRC network!

* Features scheduled for 1.0

  - larger & more robust build farm
    + we need a powerful, dedicated front-end
    + armhf-linux build machine
    + leave Hydra in favor of 'guix publish' + custom code?
  - more OS features
    + LVM support
    + encrypted root
    + configurable name service switch
    + whole-system unit tests, using VMs
  - more service definitions
    + mcron, postfix(?), wicd(?), etc.
  - better 'guix system'
    + 'reconfigure' should be able to restart non-essential services
    + support for '--list-generations' and '--delete-generations'
  - better 'guix pull'
    + using Git to fetch the source instead of re-downloading everything
    + build more quickly
    + install new .mo files and new manual
    + authentication of the Guix source: use signed commits?
  - simplified, purely declarative service list in 'operating-system'
    + it should be possible to inspect the service instance declarations and
      settings
  - GUIs
    + integrate guix-web?
    + guile-ncurses installer?
  - 'guix publish'?

* Features for later

  - complete GNU/Hurd port
  - use content-based addressing when downloading substitutes to reduce
    bandwidth requirements
    + design nar v2 format where file contents are replaced by their hashes
    + leverage /gnu/store/.links
  - binary origin tracking
    + keep signatures in sqlite.db
    + preserve signatures upon import/export
  - peer-to-peer distribution of updates (GNUnet?)
  - more deterministic builds
    + identify & fix sources of non-determinism in builds
    + strengthen guix-daemon containers to further increase reproducibility
    + trusting-trust: bootstrap with different tool chains
    + fixed-point: re-bootstrap until fixed point is reached
    + distributed validation: compare contents of store items with others
      * resist a hydra.gnu.org compromise
  - reproducible containers: mix of 'guix environment' and 'guix system vm'
  - execute code with least privilege
    + build containers like guix-daemon does
    + provide a Plash-like interface in Bash
  - daemon rewritten in Guile
  - more shepherd integration
    + monitor network interfaces and start/stop events based on that
    + include a DHCP client written in Scheme
pan>gnu: openssl: Update to 1.1.1k [security fixes]....Fixes CVE-2021-3450 and CVE-2021-3449. * gnu/packages/tls.scm (openssl/fixed): Update to 1.1.1k. Léo Le Bouter 2021-03-14gnu: OpenSSL: Refer to the version number in a more robust way....* gnu/packages/tls.scm (openssl)[arguments]: Replace use of VERSION with (PACKAGE-VERSION THIS-PACKAGE). (openssl/fixed): Adjust accordingly. Leo Famulari 2021-03-13gnu: gnutls: Fix CVE-2021-20231 and CVE-2021-20232....* gnu/packages/patches/gnutls-CVE-2021-20231.patch, gnu/packages/patches/gnutls-CVE-2021-20232.patch: New files. * gnu/local.mk (dist_patch_DATA): Add them. * gnu/packages/tls.scm (gnutls)[replacement]: New field. (gnutls/fixed): New variable. (guile2.2-gnutls): Use package/inherit. Mark H Weaver 2021-03-12gnu: Add s2n....* gnu/packages/tls.scm (s2n): New variable. Signed-off-by: Ludovic Courtès <ludo@gnu.org> Greg Hogan 2021-03-12gnu: OpenSSL: Fix version number in build configuration....Fixes <https://bugs.gnu.org/47108>. This is a followup to commit 4a8b529ce15ddc69a9dd701e450fc85a0ed65910. * gnu/packages/tls.scm (openssl/fixed)[arguments]: New field. Leo Famulari 2021-03-11gnu: certbot, python-acme: Update to 1.13.0....* gnu/packages/tls.scm (python-acme): Update to 1.13.0. [native-inputs]: Remove python-mock. [propagated-inputs]: Remove python-six. (certbot): Update to 1.13.0. [propagated-inputs]: Remove python-six. [arguments]: Remove 'build-documentation' phase. Leo Famulari 2021-03-11gnu: openssl: Update to 1.1.1j [security fixes]....* gnu/packages/tls.scm (openssl/fixed): New variable. (openssl)[replacement]: Graft. Léo Le Bouter 2021-03-03gnu: certbot, python-acme: Update to 1.12.0....* gnu/packages/tls.scm (python-acme): Update to 1.12.0. (certbot): Update to 1.12.0. [arguments]: Replace the 'build-documentation' phase. Leo Famulari 2021-01-10Merge branch 'master' into stagingEfraim Flashner 2021-01-03gnu: libressl: Update to 3.1.5 [security fix]....* gnu/packages/tls.scm (libressl): Update to 3.1.5. Tobias Geerinckx-Rice 2020-12-29Merge branch 'master' into ungraftingMarius Bakke 2020-12-21gnu: certbot, python-acme: Update to 1.10.1....* gnu/packages/tls.scm (certbot, python-acme): Update to 1.10.1. Leo Famulari 2020-12-21Merge branch 'master' into ungraftingMarius Bakke 2020-12-20gnu: p11-kit: Fix source hash....(Obviously) the tarball wasn't updated in place, and the .sig did check out, but I forgot to commit it because I'm a bit of an idiot. * gnu/packages/tls.scm (p11-kit)[source]: Update hash. Tobias Geerinckx-Rice 2020-12-20gnu: p11-kit: Update to 0.23.22....* gnu/packages/tls.scm (p11-kit): Update to 0.23.22. Tobias Geerinckx-Rice 2020-12-19gnu: dehydrated: Update to 0.7.0....* gnu/packages/tls.scm (dehydrated): Update to 0.7.0. Tobias Geerinckx-Rice 2020-12-08gnu: OpenSSL: Update to 1.1.1i [fixes CVE-2020-1971]....* gnu/packages/tls.scm (openssl)[replacement]: Update replacement to 1.1.1i (openssl-1.1.1g): Replace with ... (openssl-1.1.1i): ... new variable. Leo Famulari 2020-12-08gnu: OpenSSL: Update to 1.1.1i [fixes CVE-2020-1971]....* gnu/packages/tls.scm (openssl): Update to 1.1.1i. Marius Bakke 2020-12-08gnu: openssl: Update to 1.1.1g and remove replacement....* gnu/packages/tls.scm (openssl): Update to 1.1.1g. [replacement]: Remove. (openssl-1.1.1g): Remove. Ludovic Courtès 2020-12-08gnu: gnutls: Update to 3.6.15 and remove replacement....* gnu/packages/tls.scm (gnutls): Update to 3.6.15. [source]: Add "gnutls-cross.patch". [replacement]: Remove. [native-inputs]: Add GUILE-3.0 when (%current-target-system) is true. (gnutls/fixed): Remove. * gnu/packages/package-management.scm (guix)[propagated-inputs]: Remove reference to 'gnutls/fixed'. * gnu/packages/tls.scm (gnutls/dane): Inherit from gnutls. * gnu/packages/vpn.scm (openconnect)[propagated-inputs]: Remove gnutls/fixed, add gnutls. Co-authored-by: Efraim Flashner <efraim@flashner.co.il> Ludovic Courtès 2020-12-03gnu: gnutls-dane: Inherit from newer GnuTLS....Fixes <https://bugs.gnu.org/44914>. * gnu/packages/tls.scm (gnutls/dane): Inherit from GNUTLS/FIXED instead of GNUTLS. Marius Bakke 2020-12-03gnu: GnuTLS: Update replacement to 3.6.15 [fixes CVE-2020-24659]....* gnu/packages/tls.scm (gnutls-3.6.14): Rename to ... (gnutls/fixed): ... this. Update to 3.6.15. (gnutls): Adjust for renamed replacement. * gnu/packages/package-management.scm (guix)[propagated-inputs]: Likewise. * gnu/packages/vpn.scm (openconnect)[propagated-inputs]: Likewise. Marius Bakke 2020-11-21gnu: openssl: Fix cross compiling for powerpc targets....* gnu/packages/tls.scm (openssl)[arguments]: Add cross compile target cases for powerpc64le-linux, powerpc64-linux and powerpc-linux. Efraim Flashner 2020-11-08gnu: openssl: Fix indentation....* gnu/packages/tls.scm (openssl): Fix indentation of package definition. Efraim Flashner 2020-11-08gnu: openssl: Fix cross compiling for mips64el-linux....* gnu/packages/tls.scm (openssl)[arguments]: When cross compiling add case for mips64el-linux. Efraim Flashner 2020-10-21gnu: certbot, python-acme: Update to 1.8.0....* gnu/packages/tls.scm (certbot, python-acme): Update 1.8.0. Leo Famulari 2020-10-16gnu: libressl: Update to 3.1.4....* gnu/packages/tls.scm (libressl): Update to 3.1.4. Tobias Geerinckx-Rice