!lymvtcwDJ7ZA9Npq:lix.systems

Lix Development

416 Members
(Technical) development of Lix, the package manager, a Nix implementation. Please be mindful of ongoing technical conversations in this channel.139 Servers

Load older messages


SenderMessageTime
29 Jul 2025
@emilazy:matrix.orgemilyoh wait16:38:49
@emilazy:matrix.orgemily /btar 16:38:51
@emilazy:matrix.orgemilylol16:38:52
@emilazy:matrix.orgemilyso16:39:02
@emilazy:matrix.orgemily $TMPDIR ends with a / normally on macOS 16:39:08
@emilazy:matrix.orgemily e.g. /var/folders/1v/jtp_4pzx7xq371f8j_xdnrvm0000gn/T/ 16:39:15
@emilazy:matrix.orgemily /nix/var/nix/builds/nix-build-libarchive-3.8.1.drv-6/b does not 16:39:28
@emilazy:matrix.orgemilydo we want to work around that when things concatenate without the slash or just say it's an upstream bug?16:39:41
@emilazy:matrix.orgemily (I mean it is an upstream bug) 16:39:45
@emilazy:matrix.orgemilyok, I just fixed it upstream16:59:47
@emilazy:matrix.orgemily previously the $TMPDIR would have been /private/tmp/nix-build-libarchive-3.8.1.drv-6 16:59:58
@emilazy:matrix.orgemily which would result in libarchive creating a file like /private/tmp/nix-build-libarchive-3.8.1.drv-6tar.md.CvYd75, which is fine because the permissions are less locked down. comedy 17:00:17
@raitobezarius:matrix.orgraitobezarius
In reply to @emilazy:matrix.org
(I mean it is an upstream bug)
what is upstream here
17:04:45
@emilazy:matrix.orgemily libarchive 17:04:53
@raitobezarius:matrix.orgraitobezariusah ok17:04:56
@emilazy:matrix.orgemilyand maybe anything else similarly dumb17:04:59
@emilazy:matrix.orgemilyit's not worth worrying about I think17:05:06
@emilazy:matrix.orgemilygiven it would cause issues on Linux too (it was in a macOS-only code path in this case), and was already behaving wrong pre-CVE-fixes17:05:29
@emilazy:matrix.orgemily FWIW something seems screwy about Unix sockets in /tmp in the Darwin sandbox even after fixes: https://github.com/NixOS/nixpkgs/pull/429415 17:30:12
@emilazy:matrix.orgemilybut I'm not sure exactly what/how17:30:21
@emilazy:matrix.orgemilyand it may be an okay regression because we should really be closing that off anyway…17:30:32
@raitobezarius:matrix.orgraitobezariusi cannot understand what is screwy17:31:21
@raitobezarius:matrix.orgraitobezariuswhat behavior do you see17:31:27
@raitobezarius:matrix.orgraitobezariusah you're not exactly sure neither17:31:38
@emilazy:matrix.orgemily bind fails on /tmp/blah 17:34:40
@emilazy:matrix.orgemily I don't know, libuv regularly breaks in the Darwin sandbox, so maybe it wasn't related to the CVE stuff 17:35:07
@emilazy:matrix.orgemilybut it seems suspicious (but I can't figure out why it'd have become screwier)17:35:18
@emilazy:matrix.orgemilyRedacted or Malformed Event19:02:32
@emilazy:matrix.orgemilyRedacted or Malformed Event19:02:45
@emilazy:matrix.orgemilyRedacted or Malformed Event19:03:03

Show newer messages


Back to Room ListRoom Version: 10