package.el with ELPA mirrors vs straight.el commit pinning for air-gapped reproducibility
0 reputation · 07 Jul 2023, 02:29 UTC
Deterministic Configuration on Isolated Workstations
Maintaining a reproducible Emacs environment on an air-gapped workstation requires a strategy for package management that ensures a cold start results in the exact same byte-code and feature set across different machine images.
Using the built-in package.el with local ELPA mirrors provides a minimal bootstrap process and integrates with package-quickstart to cache autoloads for faster startup. However, package versions typically float based on the mirror's current state, which can introduce variance during fresh deployments.
Alternatively, straight.el allows pinning packages to specific git commits or using a lockfile. This ensures deterministic content and enables offline use after the initial clone, though it introduces a third-party dependency and a more complex bootstrap phase.
There is uncertainty regarding how native-compiled .eln caches interact with these two methods. Specifically, it is unclear if package-quickstart invalidation triggers a full recompilation of native-compiled files or if stale artifacts persist after a package version update in Emacs 28+.
- Does
package.elprovide a documented mechanism to pin specific versions across mirrors to match the determinism ofstraight.el? - How does the native-compilation cache handle invalidation when switching between pinned commits in
straight.elversus versioned tarballs inpackage.el?