This was not the case in 2023 for Arch Linux[1] back when the post was originally published, and is also not the case for Debian[2] since 2024.
Also container native and soon to be LLVM native.
It is our best answer so far to the ROTT paper.
Also live-bootstrap, stage0, mrustc, mes, and so many amazing projects whose combined efforts all helped finally make probably trustworthy toolchains a thing.
Discussion at the time: https://news.ycombinator.com/item?id=38020792
With careful planning though, with the ability to rootkit any linux kernel it compiles that in turn hot-patches any gcc compilations and so on, with the ability to re-route system calls to hide itself... it could be very very hard to detect.
Even moreso if such was deployed in a couple target CI/CD systems.
bootstrappable builds are the only path to prove such an attack did not happen.