!OqhvaDMJdKYUicLDiE:nixos.org

Nixpkgs Stdenv

197 Members
64 Servers

Load older messages


SenderMessageTime
20 Jun 2025
@emilazy:matrix.orgemily(the sandbox is off by default)18:01:28
@emilazy:matrix.orgemilybecause on Linux it is actually isolated, since Linux has network namespaces and builds run in a namespace with their own loopback interface and nothing else18:01:44
@aleksana:mozilla.orgaleksana 🏳️‍⚧️ (force me to bed after 18:00 UTC)
In reply to @emilazy:matrix.org
because on Linux it is actually isolated, since Linux has network namespaces and builds run in a namespace with their own loopback interface and nothing else
I know
18:02:08
@emilazy:matrix.orgemilyDarwin sadly lacks that functionality18:02:09
@aleksana:mozilla.orgaleksana 🏳️‍⚧️ (force me to bed after 18:00 UTC)But you'd make them know they are doing it wrong, rather than failing silently on some other cases18:02:35
@emilazy:matrix.orgemilyit's not really silent, is it? that's why we have CI/ofborg18:11:22
@emilazy:matrix.orgemilythere's no way to know whether something will build on a platform before something actually attempts the build18:11:37
@Ericson2314:matrix.orgJohn Ericsonhttps://pad.lassul.us/zvvXlsRCRVeXU48WWaCpDg22:35:16
@Ericson2314:matrix.orgJohn EricsonWe on the SC are thinking about this as a possible project to organize and fund on the foundation level22:35:51
@Ericson2314:matrix.orgJohn Ericsonwere curious what the Stdenv Team thinks about this22:36:08
@Ericson2314:matrix.orgJohn Ericson CC tomberek 22:36:11
@Ericson2314:matrix.orgJohn Ericsonto be clear, at this point, we're thinking more about the first step of a relocatable store22:36:42
@emilazy:matrix.orgemilyit was discussed here recently :)22:41:02
@emilazy:matrix.orgemilyhere22:41:16
@emilazy:matrix.orgemilyit's something I've thought about before, there are some tricky issues I outlined, I expect somewhat invasive patching across the tree would be necessary, but the initial hurdles are more writing loader code etc.22:41:52
@emilazy:matrix.orgemilyI think it would be feasible but hard (and some packages may never work)22:42:19
@emilazy:matrix.orgemily I see this came up as DT_INTERP in the doc. I think you can just solve the problem by avoiding the kernel's code for it as I outlined earlier. 22:43:02
@emilazy:matrix.orgemily IIRC #!/usr/bin/env -S is not portable wrt macOS so may not be a good solution for shebangs. 22:43:44
@emilazy:matrix.orgemilymight be workaroundable.22:43:58
@Ericson2314:matrix.orgJohn Ericsonoh my bad22:44:08
@Ericson2314:matrix.orgJohn EricsonI was scrolling around and didn't see it yet22:44:14
@Ericson2314:matrix.orgJohn Ericsonwith the static PIE?22:45:56
@Ericson2314:matrix.orgJohn Ericsonthat does sound nice22:46:14
@Ericson2314:matrix.orgJohn EricsonI'm hoping if we actually do it, we can petition POSIX to standardize more $ORIGIN22:46:42
@Ericson2314:matrix.orgJohn Ericsonso the cure gets better, longer term22:46:51
@emilazy:matrix.orgemily you just need loader code that resolves out the interp path and does exec. hopefully. unless that doesn't quite do the right thing in which case you need to load the interp into memory and jump into it, which would be awful 22:47:17
@emilazy:matrix.orgemilyanyway it's definitely prototypeable I think and I've toyed with the idea but it'd take a lot of time and not sure the appetite for the requisite patching would be there in Nixpkgs22:47:58
@Ericson2314:matrix.orgJohn EricsonI have to leave now, but perhaps the first thing to pay for is some sort of demo to gauge feasibility / unseamliness of hacks22:48:05
@Ericson2314:matrix.orgJohn Ericson

not sure the appetite for the requisite patching would be there in Nixpkgs

The hope for that is to gameify it a bit with "are we relocatable yet?" etc.

22:48:39
@Ericson2314:matrix.orgJohn EricsonI am more confident on that part, if the initial prototype works, and it takes less skill to do the patching using previously-invented techniques than come up with the techniques22:49:32

Show newer messages


Back to Room ListRoom Version: 9