!lheuhImcToQZYTQTuI:nixos.org

Nix on macOS

1154 Members
“There are still many issues with the Darwin platform but most of it is quite usable.” — http://yves.gnu-darwin.org184 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
2 Dec 2025
@niklaskorz:matrix.orgniklaskorzcppnix added it over a year ago18:30:02
@weethet:catgirl.cloudWeetHetOh okay so Lix just hasn't picked it up18:30:16
@niklaskorz:matrix.orgniklaskorzhttps://git.lix.systems/lix-project/lix/issues/69118:30:26
@niklaskorz:matrix.orgniklaskorz

that sandbox change got (relatively soft-) rejected here because it's an effectively deprecated feature on macOS that allows random communication between derivations. you might be able to find it, someone filed a bug requesting said port.

18:30:30
@niklaskorz:matrix.orgniklaskorzso according to that thread: contributions welcome18:32:32
@weethet:catgirl.cloudWeetHetDamn okay I need to backport the ipc cleanup18:32:47
@weethet:catgirl.cloudWeetHetSure I guess18:32:50
@reckenrode:matrix.orgRandy EckenrodeAllowing communication between derivations seems problematic. Can’t Postgres just include a sandbox profile with what it needs?18:36:13
@reckenrode:matrix.orgRandy EckenrodeJust went and checked the CVEs from earlier. Those were about being able to inject into a build. This seems more like everybody being able to interfere with each other like if they had access to localhost.18:43:59
@reckenrode:matrix.orgRandy EckenrodeDoes upstream Nix tie it to whether local networking is allowed?18:44:18
@reckenrode:matrix.orgRandy EckenrodeThe upstream Nix patch just seems to be about cleaning up IPC objects.18:47:20
@weethet:catgirl.cloudWeetHetUsing relaxed is weird18:49:09
@weethet:catgirl.cloudWeetHet I'm gonna put it behind __darwinAllowSysvIPC 18:49:56
@weethet:catgirl.cloudWeetHet * I'm gonna put it behind __darwinAllowSysVIPC 18:56:20
@emilazy:matrix.orgemilyplease don't19:08:40

Show newer messages


Back to Room ListRoom Version: 6