!9IQChSjwSHXPPWTa:lix.systems

Lix

1104 Members
Lix user channel. Feel free to discuss on-topic issues here and give each other help. For matrix.to links to the rest of the Lix channels, see: https://wiki.lix.systems/books/lix-organisation/page/matrix-rooms295 Servers

Load older messages


SenderMessageTime
28 Nov 2025
@522_:catgirl.cloud522 it/its ⛯ΘΔ i do think for machine resolution of versions you don't need semver, you only need a major version that you can bump (which, yeah, you can use branches for that) 11:52:07
@522_:catgirl.cloud522 it/its ⛯ΘΔmost of semver is for humans reading it11:52:29
@toonn:matrix.orgtoonn It's also humans writing it so it's not infallible. API inspection would be pretty cool. 12:15:54
@goldstein:tty5.devgoldstein API inspection for Nix is hard because of laziness
you don’t know which subexprs you can even touch to inspect
12:26:12
@goldstein:tty5.devgoldsteinand also any behind a lambda is ~completely opaque I think12:26:36
@toonn:matrix.orgtoonn It's hard in any language TBH. 13:44:53
@david:lenfesty.cadavidHrm, `nix upgrade-nix` is failing with permissions issues on trying to open `/nix/var/nix/profiles/default.lock`22:53:10
@david:lenfesty.cadavidHaving trouble finding a fix/workaround, anyone have suggestions?22:53:27
@david:lenfesty.cadavid"ask for help so you can solve it yourself" works yet again22:59:56
@david:lenfesty.cadavid`sudo nix` could not find `nix` but if I sourced the profile from a root shell upgrade-nix worked fine23:07:44
@david:lenfesty.cadavidStill maybe a potential issue but idk. Specifically it failed while trying to uninstall the old version of Lix (for reference, 1.93 -> 1.94)23:08:32
29 Nov 2025
@raitobezarius:matrix.orgraitobezarius
In reply to @david:lenfesty.ca
Still maybe a potential issue but idk. Specifically it failed while trying to uninstall the old version of Lix (for reference, 1.93 -> 1.94)
Can you open an issue? Thanks!
00:08:59
@conformally:matrix.org@conformally:matrix.org left the room.11:41:40
@arianvp:matrix.orgArianI think I found some weird daemon protocol incompatibility between nix and lix12:39:02
@arianvp:matrix.orgArian

% nix flake check --eval-store auto --store ssh-ng://altra --system aarch64-linux

error: cannot build missing derivation '/nix/store/s131lvrb3pqysw22nl0lmq8sbdflpwfc-vm-test-run-spire-join-token.drv'

from a 2.24.12 evaluator to a 1.94 remote builder.

I’m pretty certain this used to work on 1.93

12:39:54
@arianvp:matrix.orgArianBut this is probably in the “we dont care” territory. lemme try with lix and lix12:41:47
@raitobezarius:matrix.orgraitobezariusI wouldn't want to try hard to debug an issue that could be not on our side12:44:36
@raitobezarius:matrix.orgraitobezariusIf you have more data and/or a reproducer, feel free to throw an issue at me, no promise tho12:44:57
@raitobezarius:matrix.orgraitobezariusIf it's a Lix/Lix issue, of course, this is prioritized12:45:07
30 Nov 2025
@sofiedotcafe:matrix.orgSofie 🏳️‍⚧️ (she/her)Redacted or Malformed Event12:07:36
@sofiedotcafe:matrix.orgSofie 🏳️‍⚧️ (she/her)https://burnthewhich.github.io/shbangenv/shbangenv.html12:09:16
@sofiedotcafe:matrix.orgSofie 🏳️‍⚧️ (she/her)lmfao, what12:09:20
@sofiedotcafe:matrix.orgSofie 🏳️‍⚧️ (she/her)it is far more portable(as in, works on non FHS systems like NixOS);and I don't really believe it could even cause vurnerbalities12:10:40
@sofiedotcafe:matrix.orgSofie 🏳️‍⚧️ (she/her) * 12:10:50
@sofiedotcafe:matrix.orgSofie 🏳️‍⚧️ (she/her) * 12:11:01
@522_:catgirl.cloud522 it/its ⛯ΘΔ i mean i guess if you consider "an attacker can put a malicious bash in your path" to be a vulnerability 12:13:14
@522_:catgirl.cloud522 it/its ⛯ΘΔ(but also they can put malicious "every other tool you use" in your path so)12:13:25
@522_:catgirl.cloud522 it/its ⛯ΘΔif your PATH is fucked then you are so very utterly fucked12:14:05
@aloisw:julia0815.dealoisw I suppose this is what they mean by "The nexus of the security vulnerability is that using #!/usr/bin/env ensures that the script itself is unable to sanitize the environment before relying upon it." But does any script actually do that? 12:25:03
@arianvp:matrix.orgArian
In reply to @sofiedotcafe:matrix.org
it is far more portable(as in, works on non FHS systems like NixOS);and I don't really believe it could even cause vurnerbalities
so /usr/bin/env bash is more portable than. /bin/bash. but less portable than /bin/sh is the thesis. but idk wtf the point is they’re trying to make
12:28:25

Show newer messages


Back to Room ListRoom Version: 10