!lheuhImcToQZYTQTuI:nixos.org

Nix on macOS

1161 Members
“There are still many issues with the Darwin platform but most of it is quite usable.” — http://yves.gnu-darwin.org188 Servers

Load older messages


SenderMessageTime
16 Nov 2025
@weethet:catgirl.cloudWeetHetI don't have IPv6 though19:48:07
@winter:catgirl.cloudWintertbh i don’t know anyone who uses darwin w/ sandbox=true, sandbox=relaxed is more usable for Reasons19:48:11
@winter:catgirl.cloudWinterjust CCing him because he looked at c-ares stuff yesterday even if it’s probably not the same issue19:48:29
@weethet:catgirl.cloudWeetHet I'm using sandbox = true for the last year 19:48:32
@weethet:catgirl.cloudWeetHet * I'm using sandbox = true for the last ~year 19:48:44
@winter:catgirl.cloudWinteryou’ve never run into a drv with a sandboxProfile?19:48:51
@samasaur:matrix.orgsamasaur iirc there are fairly fundamental darwin deps that fail with the sandbox enabled, so i think sandbox = true only works when you get those from cache.nixos.org 19:49:31
@weethet:catgirl.cloudWeetHetI use true by default and pass relaxed if needed19:49:47
@samasaur:matrix.orgsamasaurah drat I was really hoping using terminal.app would fix this :(19:52:07
@samasaur:matrix.orgsamasaur it's Really Weird that home-manager switch is removing terminal.app from the list of programs with app management permissions... 19:52:31
@samasaur:matrix.orgsamasaur ah and what i meant by "first time using copying instead of linking" is that home-manager recently changed to copying applications into ~/Applications/Home Manager Apps instead of symlinking them there (following a nix-darwin PR), and the app management check only runs if you are copying 19:53:38
@weethet:catgirl.cloudWeetHetRealistically we should probably make bootstrap work with sandbox = true at one point19:57:03
@weethet:catgirl.cloudWeetHetI would really like if hydra was running with sandbox = true19:57:14
@samasaur:matrix.orgsamasauroh yeah i def agree19:57:23
@samasaur:matrix.orgsamasaurunfortunately there are many goals like that and only so much time19:57:36
@weethet:catgirl.cloudWeetHet26.05 maybe?19:57:44
@weethet:catgirl.cloudWeetHetI mean this is kinda fundamental19:57:52
@weethet:catgirl.cloudWeetHetMaybe we can even add a way to wrap packages to run in their own sandboxes so we can deliver pre-sandboxed executables20:01:03
@weethet:catgirl.cloudWeetHetWhy am I building fish...20:04:07
@weethet:catgirl.cloudWeetHetYou know what, I'll pass on updating nixpkgs rn let's wait a bit for this stuff to be fixed20:04:26
@samasaur:matrix.orgsamasauryeah fish is broken rn20:24:28
@samasaur:matrix.orgsamasaurkeeping me from updating as well :(20:24:35
@samasaur:matrix.orgsamasaurand it's some transitive issues from python not resolving argv0? i believe it was posted in this room20:25:10
@reckenrode:matrix.orgRandy EckenrodeMy PR only addressed the link-local issue. I didn’t look at other issues. The question I’d have is if there’s anything unusual about the DNS config. It’s also possible using private APIs to get the system’s DNS server needs a sandbox exemption.20:42:37
@reckenrode:matrix.orgRandy Eckenrode c-ares uses private APIs because iOS doesn’t have /etc/resolv.conf, and they want to use the same code path on both platforms. How that gets past App Store review, I have no idea. 20:44:35
@weethet:catgirl.cloudWeetHetI'm not using anything different from the default macOS DNS settings20:44:38
@weethet:catgirl.cloudWeetHetAnd it worked before on unstable20:44:52
@weethet:catgirl.cloudWeetHetAnd if I rollback to the 25.11pre889916.ffcdcf99d65c it works fine20:45:17
@reckenrode:matrix.orgRandy EckenrodeIt’s almost certainly https://github.com/NixOS/nixpkgs/pull/451579.20:45:42
@weethet:catgirl.cloudWeetHetDamn. Any ideas on why and how to fix this?20:47:39

Show newer messages


Back to Room ListRoom Version: 6