!lheuhImcToQZYTQTuI:nixos.org

Nix on macOS

1163 Members
“There are still many issues with the Darwin platform but most of it is quite usable.” — http://yves.gnu-darwin.org188 Servers

Load older messages


SenderMessageTime
16 Nov 2025
@weethet:catgirl.cloudWeetHet
nix-run> exporting https://tangled.org/@weethet.bsky.social/nix-run (rev 73d7bf6b58848fb8f42e3a69816e0847f041c689) into /nix/store/m4m951648wmipxgwrgsml9gzjwfpfhm7-nix-run-73d7bf6
nix-run> Initialized empty Git repository in /nix/store/m4m951648wmipxgwrgsml9gzjwfpfhm7-nix-run-73d7bf6/.git/
nix-run> fatal: unable to access 'https://tangled.org/@weethet.bsky.social/nix-run/': Could not resolve host: tangled.org (Could not contact DNS servers)
nix-run> fatal: unable to access 'https://tangled.org/@weethet.bsky.social/nix-run/': Could not resolve host: tangled.org (Could not contact DNS servers)
nix-run> fatal: unable to access 'https://tangled.org/@weethet.bsky.social/nix-run/': Could not resolve host: tangled.org (Could not contact DNS servers)
nix-run> Unable to checkout 73d7bf6b58848fb8f42e3a69816e0847f041c689 from https://tangled.org/@weethet.bsky.social/nix-run.
19:46:28
@weethet:catgirl.cloudWeetHet Works with relaxed because it disables sandbox for FODs entirely 19:47:01
@winter:catgirl.cloudWinter probably because of c-ares? cc Randy Eckenrode 19:47:47
@weethet:catgirl.cloudWeetHetI don't have IPv6 though19:48:07
@winter:catgirl.cloudWintertbh i don’t know anyone who uses darwin w/ sandbox=true, sandbox=relaxed is more usable for Reasons19:48:11
@winter:catgirl.cloudWinterjust CCing him because he looked at c-ares stuff yesterday even if it’s probably not the same issue19:48:29
@weethet:catgirl.cloudWeetHet I'm using sandbox = true for the last year 19:48:32
@weethet:catgirl.cloudWeetHet * I'm using sandbox = true for the last ~year 19:48:44
@winter:catgirl.cloudWinteryou’ve never run into a drv with a sandboxProfile?19:48:51
@samasaur:matrix.orgsamasaur iirc there are fairly fundamental darwin deps that fail with the sandbox enabled, so i think sandbox = true only works when you get those from cache.nixos.org 19:49:31
@weethet:catgirl.cloudWeetHetI use true by default and pass relaxed if needed19:49:47
@samasaur:matrix.orgsamasaurah drat I was really hoping using terminal.app would fix this :(19:52:07
@samasaur:matrix.orgsamasaur it's Really Weird that home-manager switch is removing terminal.app from the list of programs with app management permissions... 19:52:31
@samasaur:matrix.orgsamasaur ah and what i meant by "first time using copying instead of linking" is that home-manager recently changed to copying applications into ~/Applications/Home Manager Apps instead of symlinking them there (following a nix-darwin PR), and the app management check only runs if you are copying 19:53:38
@weethet:catgirl.cloudWeetHetRealistically we should probably make bootstrap work with sandbox = true at one point19:57:03
@weethet:catgirl.cloudWeetHetI would really like if hydra was running with sandbox = true19:57:14
@samasaur:matrix.orgsamasauroh yeah i def agree19:57:23
@samasaur:matrix.orgsamasaurunfortunately there are many goals like that and only so much time19:57:36
@weethet:catgirl.cloudWeetHet26.05 maybe?19:57:44
@weethet:catgirl.cloudWeetHetI mean this is kinda fundamental19:57:52
@weethet:catgirl.cloudWeetHetMaybe we can even add a way to wrap packages to run in their own sandboxes so we can deliver pre-sandboxed executables20:01:03
@weethet:catgirl.cloudWeetHetWhy am I building fish...20:04:07
@weethet:catgirl.cloudWeetHetYou know what, I'll pass on updating nixpkgs rn let's wait a bit for this stuff to be fixed20:04:26
@samasaur:matrix.orgsamasauryeah fish is broken rn20:24:28
@samasaur:matrix.orgsamasaurkeeping me from updating as well :(20:24:35
@samasaur:matrix.orgsamasaurand it's some transitive issues from python not resolving argv0? i believe it was posted in this room20:25:10
@reckenrode:matrix.orgRandy EckenrodeMy PR only addressed the link-local issue. I didn’t look at other issues. The question I’d have is if there’s anything unusual about the DNS config. It’s also possible using private APIs to get the system’s DNS server needs a sandbox exemption.20:42:37
@reckenrode:matrix.orgRandy Eckenrode c-ares uses private APIs because iOS doesn’t have /etc/resolv.conf, and they want to use the same code path on both platforms. How that gets past App Store review, I have no idea. 20:44:35
@weethet:catgirl.cloudWeetHetI'm not using anything different from the default macOS DNS settings20:44:38
@weethet:catgirl.cloudWeetHetAnd it worked before on unstable20:44:52

Show newer messages


Back to Room ListRoom Version: 6