Lila: Decentralized Build Reproducibility Monitoring for the Functional Package Management Model
Julien Malka, Arnout Engelen

TL;DR
Lila is a decentralized system designed to monitor and assess build reproducibility at scale within the functional package management model, enhancing transparency and trust in software distribution.
Contribution
It introduces a decentralized reproducibility monitoring system tailored for the functional package management model, enabling distributed reporting and aggregation of build results.
Findings
Achieves scalable reproducibility monitoring for large software collections.
Facilitates distributed reporting and aggregation of build results.
Supports empirical studies of build reproducibility at scale.
Abstract
Ensuring the integrity of software build artifacts is an increasingly important concern for modern software engineering, driven by increasingly sophisticated attacks on build systems, distribution channels, and development infrastructures. Reproducible builds where binaries built independently from the same source code can be verified to be bit-for-bit identical to the distributed artifacts provide a principled foundation for transparency and trust in software distribution. Despite their potential, the large-scale adoption of reproducible builds faces two significant challenges: achieving high reproducibility rates across vast software collections and establishing reproducibility monitoring infrastructure that can operate at very large scale. While recent studies have shown that high reproducibility rates are achievable at scale …
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSecurity and Verification in Computing · Software Engineering Research · Advanced Malware Detection Techniques
