!VRULIdgoKmKPzJZzjj:nixos.org

Nix Hackers

940 Members
For people hacking on the Nix package manager itself195 Servers

Load older messages


SenderMessageTime
10 Apr 2026
@ebeem:matrix.orgebeem-sama changed their profile picture.13:57:04
@jonzuky:matrix.orgJon Zuk joined the room.20:57:29
13 Apr 2026
@tiktorchic18:matrix.orgTikTorchic18 joined the room.01:10:58
@alesya-h:nixos.devAlesya changed their display name from Alesya Huzik to Alesya.01:47:21
@juhp:matrix.orgJens Petersen What is the easiest way to know what is in a new nix minor release?
One should check the commits 2.34.5..2.34.6?
07:51:25
@juhp:matrix.orgJens Petersen * What is the easiest way to know what is in a new nix minor release?
One should check the commits eg 2.34.5..2.34.6?
07:51:42
@juhp:matrix.orgJens PetersenOkay I guess it is just a single fix this time07:53:39
@xokdvium:matrix.orgSergei Zimmerman (xokdvium)
In reply to @juhp:matrix.org
What is the easiest way to know what is in a new nix minor release?
One should check the commits eg 2.34.5..2.34.6?
For major stuff we do try to have release notes, but minor bug fixes sometimes just get yeeted
07:53:59
@juhp:matrix.orgJens PetersenOkay07:54:38
@tanja:catgirl.cloudTanja (she/her) removed their profile picture.14:18:42
@niksnut:matrix.orgniksnut👍️ on moving the perl bindings out of the nix repo15:44:08
@Ericson2314:matrix.orgJohn EricsonOK thanks Eelco15:45:43
@niksnut:matrix.orgniksnutbut uhm, I thought the whole thing was being rewritten in perl?15:52:56
@niksnut:matrix.orgniksnut*rust15:52:59
@hexa:lossy.networkhexaI don't think the web bits have been touched yet15:53:49
@niksnut:matrix.orgniksnuttoo bad15:54:28
@niksnut:matrix.orgniksnutI'd much rather see the perl stuff replaced than the C++ stuff15:54:38
14 Apr 2026
@nik.singh710:matrix.orgSemi changed their profile picture.00:26:04
@nik.singh710:matrix.orgSemi changed their display name from Nikhil Singh to Semi.00:27:42
@43d734m34:matrix.orgeyepatch joined the room.15:58:25
15 Apr 2026
@98765abc:mozilla.org@98765abc:mozilla.org left the room.06:49:32
16 Apr 2026
@perchun:matrix.orgPerchun Pak [don't randomly ping] changed their display name from Perchun Pak [don't ping; dm instead] to Perchun Pak [don't randomly ping; dm instead].17:07:34
@perchun:matrix.orgPerchun Pak [don't randomly ping] changed their display name from Perchun Pak [don't randomly ping; dm instead] to Perchun Pak [don't randomly ping].17:16:13
17 Apr 2026
@c4lliope:matrix.orgc4lliope set a profile picture.08:36:44
@c4lliope:matrix.orgc4lliope changed their profile picture.08:41:40
18 Apr 2026
@voxel:quamquam.orgvoxel ⚡️ joined the room.16:56:41
@voxel:quamquam.orgvoxel ⚡️ Eelco: I wanted to say thank you for creating nix, btw. I'm building something huge on it - already working large parts of it. I'm building the next gen package distribution 17:00:50
@voxel:quamquam.orgvoxel ⚡️ * Eelco: I wanted to say thank you for creating nix, btw. I'm building something huge on it - already working large parts of it. I'm building the next gen package distribution on it. Walrus / Sui / Nix / IKA and the stuff I'm building. I'm very confident that with this system, we can prevent dependency chain attacks and many other problems :) 17:01:50
@voxel:quamquam.orgvoxel ⚡️Super exciting times for fully decentralized, bulletproof systems. Especially using IKA with its mpc-2pc (multi party computation - 2 party) - ground breaking crypto that allows us the have the signing key split in a way that a contract needs to properly evaluate and you have to sign the second part. Part of my workflow system is building a smart contract that evaluates to true when multiple parties build the same artifact, checked the source code with all dependencies against malware loaders or other bad code like unicode malware (glassworm), .... By using SUI frozen objects I can guarantee that releases can't ever be manipulated afterwards. Walrus blobs also can't be manipulated and quilt encoding allows us to nicely cache and re-consolidate unused storage. We (me and chatgpt 5.4 pro) are currently discussing/designing an optimized data structure to start with. I already have git on SUI/Walrus backend I'm polishing currently, before I publish it in testnet. Hosting nixpkgs sources on this should cost ~4$ / year on storage. Very curious what commits will cost on mainnet :) The cool thing is, that release tags can be frozen and therefore never ever be changed. Like the axios hack in the last weeks where a maleware on the developer machine overwrote the release tag and added malware dependency. I fear the day github gets hacked and half the CI they provide get compromised compilers that build a sleeping worm that goes haywire after some month.17:30:58
@voxel:quamquam.orgvoxel ⚡️The workflow engine I have built already creates signed digest files of all build outputs and has native nix build step. I want to combine this build artifacts then with a LSM module to allow super secure systems that only run code that got signed by this chain. the linux current xattr based system does not work due nix store compression, but with a LSM (maybe ebpf) and a small daemon this will work.18:16:03

Show newer messages


Back to Room ListRoom Version: 6