!lheuhImcToQZYTQTuI:nixos.org

Nix on macOS

1230 Members
“There are still many issues with the Darwin platform but most of it is quite usable.” — http://yves.gnu-darwin.org205 Servers

Load older messages


SenderMessageTime
12 Jun 2026
@weethet:catgirl.cloudWeetHet* You won't be able to rebuild these bit for bit 11:50:44
@weethet:catgirl.cloudWeetHetNixOS can get a certificate, or?11:50:58
@benjaminsparks:chat.alugha.appBen Sparksbit for bit reproducibility is an extremely high target11:51:05
@weethet:catgirl.cloudWeetHetIt's 100$?11:51:06
@reckenrode:matrix.orgRandy Eckenrode We don’t have a way to do that safely, so it would have to be done separately and provided as binaries (which I think is what WeetHet is getting at). 11:51:18
@weethet:catgirl.cloudWeetHetYeah that's basically my idea11:51:35
@weethet:catgirl.cloudWeetHetStill better than using binaries provided by apple11:52:00
@reckenrode:matrix.orgRandy EckenrodeI don’t think we’d want to sign a bunch of binaries like that. If there’s a problem, Apple could revoke the certificate and break everything.11:52:11
@reckenrode:matrix.orgRandy EckenrodeProbably the way to go is a cert we install, but we still don’t have a way to safely manage signing.11:52:44
@reckenrode:matrix.orgRandy EckenrodeThe issue is if you can make Nix sign arbitrary code, it undermines the security model behind entitlements.11:53:10
@weethet:catgirl.cloudWeetHetThe derivations that are signed this way would need to be approved by darwin-core?11:54:15
@k900:0upti.meK900 Doesn't Apple require additional verification for those certs anyway? 11:55:06
@weethet:catgirl.cloudWeetHetPreferably this should be done together with requiring mandatory commit signing for everyone in nixpkgs so no one could just update a random file and fake a signature11:55:36
@weethet:catgirl.cloudWeetHet* Preferably this should be done together with requiring mandatory commit signing for everyone in nixpkgs so no one could just update a random file and fake the author11:55:42
@k900:0upti.meK900That is never happening11:56:36
@reckenrode:matrix.orgRandy EckenrodeIf we did it separately. I’m thinking more generally like a signing service (akin to suid wrappers), which has been proposed and rejected for that reason.11:56:44
@weethet:catgirl.cloudWeetHetI don't see why a separate subset of such packages can't exist11:57:12
@weethet:catgirl.cloudWeetHetWe would at least be able to distribute debug server finally11:57:23
@reckenrode:matrix.orgRandy EckenrodeNo. The verification is if you sell on the app store. They need a D&B number IIRC.11:57:26
@reckenrode:matrix.orgRandy Eckenrode I could build debugserver and sign it with my certificate, but I would rather not be that one block at the bottom of the tower in that XKCD comic. 11:58:39
@weethet:catgirl.cloudWeetHetThe certificate should be procured by the nixos foundation 11:59:25
@weethet:catgirl.cloudWeetHetIMHO11:59:28
@reckenrode:matrix.orgRandy EckenrodeSome entitlements work with ad hoc signatures. We should enable those if we can.12:00:18
@weethet:catgirl.cloudWeetHetBtw have you seen macOS 27?12:00:57
@weethet:catgirl.cloudWeetHetI hate the reverted sidebars12:01:03
@weethet:catgirl.cloudWeetHetIf you make a new design language at least stick to it instead of just mixing the old one together with the new one12:01:40
@weethet:catgirl.cloudWeetHetLike now we have liquid glass buttons on top of acrylic surfaces12:02:34
@weethet:catgirl.cloudWeetHetWhich just looks horrible12:02:42
@weethet:catgirl.cloudWeetHetOh, and the sidebars still behave like they are above the window surface, so some objects can go behind them even though they aren't visually12:07:23
@niklaskorz:matrix.orgniklaskorzI like that they reverted the sidebars, generally without the design fixes in 27 I'd have ditched macOS for good when Sequoia reaches EOL12:58:02

Show newer messages


Back to Room ListRoom Version: 6