!9IQChSjwSHXPPWTa:lix.systems

Lix

1194 Members
Lix user channel. Feel free to discuss on-topic issues here and give each other help. For matrix.to links to the rest of the Lix channels, see: https://wiki.lix.systems/books/lix-organisation/page/matrix-rooms329 Servers

Load older messages


SenderMessageTime
4 Jun 2026
@raitobezarius:matrix.orgraitobezariusAlso in the case of signing, you could extend derivations to output modulo you can verify a signature over a public key btw21:23:44
@raitobezarius:matrix.orgraitobezarius
In reply to @baloo_:matrix.org
That's not a terrible idea. No clue how to lookup the peer from the daemon but I can look into that
I didn't say the RPC exist ofc
21:23:55
@raitobezarius:matrix.orgraitobezariusNote there's a chain on building up capnp equivalent of the current proto, you can throw some Get identity or something there21:24:21
@raitobezarius:matrix.orgraitobezariusAn alternative is to give cryptographic identity to each derivation built-in but that's a big source of irreproducibilith ig21:24:57
@baloo_:matrix.orgbaloocould be a challenge response with the daemon too21:25:49
@raitobezarius:matrix.orgraitobezarius
In reply to @baloo_:matrix.org
could be a challenge response with the daemon too
Many possibilities
21:26:40
@raitobezarius:matrix.orgraitobezariusI want to explore this seriously but I always run into emergencies for now ^^'21:27:01
@baloo_:matrix.orgbalooyeahhh ... same boat21:28:04
5 Jun 2026
@baloo_:matrix.orgbaloo

Don’t know if pid is the way, maybe uid, they should be translated when they cross the namespace.

Depends on the story of the Liz sandbox and whether there is uid reuse.

03:33:30
@baloo_:matrix.orgbaloo * Don’t know if pid is the way, maybe uid, they should be translated when they cross the namespace.
Depends on the story of the Lix sandbox and whether there is uid reuse.
03:33:38
@raitobezarius:matrix.orgraitobezariusI said pidfd on purpose :p09:02:09
@emilazy:matrix.orgemilyfyi I am actively working on a prod-ready solution for this that doesn't involve Nix-level changes (and maintains all the nice properties you'd want), stay tuned (~next couple weeks) :)10:58:41
@emilazy:matrix.orgemily(good timing!)10:58:53
@emilazy:matrix.orgemily(and attestation is solved fwiw)10:59:35
@emilazy:matrix.orgemilyhappy to ping once I have something ready for looking at11:02:30
@thewholeworldisburning123:rougebordeaux.xyzkiffeuse4life67 changed their profile picture.14:17:36
@baloo_:matrix.orgbaloolet me know if you want reviews or tests16:14:32
@zimward:zimward.moezimward changed their display name from zimward to zimward @GPN24.19:36:56
6 Jun 2026
@geoffrey:frogeye.frGeoffrey Frogeye

I figured it out: it's actually not related to pasta, but just the sandbox. It's preventing glibc's getaddrinfo from connecting to the nscd service, so it falls back to using its internal nss system, which parses /etc/resolv.conf manually and just ignores ndots, assuming a high value I guess. It's only an issue since curl 8.20.0 landed in nixpkgs, specifically since they added a 50 ms delay to Happy Eyeballs, which I guess now gives a chance to the searched "github.com.frogeye.fr" to be resolved.

So not a Lix issue, probably not a curl issue (it just makes more connections try to use IPv6 where they wouldn't before, which is a good thing), maybe a glibc issue (why nss ignores ndots while in the same codebase nscd uses it is beyond me), and there's also something about NixOS's networking.domain documentation lying about not configuring itself for DNS resolution purposes. I don't really know where to report/document this so I'll just put it here. For me I just disabled the search option entierely with networking.resolvconf.extraConfig = ''nosearch_keys='static' '';

19:13:10
@raitobezarius:matrix.orgraitobezariusThis is so cursed19:20:17
@raitobezarius:matrix.orgraitobezariusThanks for debugging so far19:20:25
@maralorn:maralorn.demaralornI am trying to fix the build finished detection in nom and it is surprisingly difficult.19:30:05
@maralorn:maralorn.demaralornDoes this bug still exist? https://git.lix.systems/lix-project/lix/issues/1819:30:16
@maralorn:maralorn.demaralornBecause I am trying to reproduce the issue on my system without installing a newer lix version globally.19:30:38
@maralorn:maralorn.demaralornSo I thought running my test suite as root would be a quick workaround for debugging. 😄19:31:01
@raitobezarius:matrix.orgraitobezariusYes you need to do NIX_REMOTE=local20:10:21
@raitobezarius:matrix.orgraitobezariusBut this bug has not been fully fixed20:10:27
7 Jun 2026
@define9293:matrix.orgdefine9293 joined the room.05:27:55
@crystallinefire:chat.solarpunk.moeCRYSTL ⬡ changed their profile picture.05:36:14
@crystallinefire:chat.solarpunk.moeCRYSTL ⬡ changed their display name from CRYSTL ⬡ to SUSTL ⬡.05:36:24

Show newer messages


Back to Room ListRoom Version: 10