Unfortunately, as you mention, this seems to imply at best computing the
hash of the dependency graph of all possible nativeBuildInputs (in order
to not allow an untrusted user to insert a maliciously-built package
into the store), and at worst downloading/building the nativeBuildInputs
for every possible build blatform.