• 4 Posts
  • 294 Comments
Joined 10 months ago
cake
Cake day: October 18th, 2025

help-circle


  • Thank you, you reassured me quite a bit. I’ll have a good read of the manual.

    It is not really a build server, it’s a compute server. I’ll have users installing hundreds of different software packages, most of them using incompatible libraries and thus I was thinking of using Nix. Alternatives would be LMOD, which however requires the administrator to install very single piece of software, which… We don’t really have a dedicated system administrator and I don’t really want to go through the compilation instructions of every single piece of software we use. Alternatively everyone could compile their own software or install it through something like conda, but that eats up a lot of storage space since every library would be duplicated across users.


  • Hello, thank you for the in depth explanation! I am not very familiar with nix, and yes I’m talking about the package manager. I have installed NixOs recently to toy around with it and see whether it could be a good solution to certain problems we have. I have determined that NixOs itself is not mature enough for what we need, but I do see value in the nix package manager that other solutions do not offer.

    Regarding the 4 points you raise

    1. I’m not too worried about hash squatting, I guess there’s no way around it, but other ways of managing packages have way worse flaws than that.
    2. I do want my users to be able to build packages. In most cases I imagine we’ll use pre built packages, but often packages available are not optimized for certain architectures.
    3. How does the nix sandbox work? Just so I know what I’m working with. Do you know where I can read about it?
    4. Does root actively run installed packages at any point? If that is the case I’d be a bit wary to use nix for this purpose.

  • Thank you for the clear explanation. This is good enough for me I guess then. What I am most afraid is not really a colleague building a malicious package on purpose, but rather them installing something which is then run as root and gets access to the whole system. I understand packages are built by unprivileged users, but in the end they are owned by root.

    What I wonder is whether in the way it is possible that something is run as root without someone specifically deciding it should be.


  • Thank you for the explanation. Yes, I’m talking about the nix package manager, not about the operating system.

    As far as I understand packages are built by less privileges users, but libraries and binaries are owned by the root user in the nix store.

    https://nix.dev/manual/nix/2.34/installation/multi-user.html

    What I wonder is wheter this could lead to root executing untrusted code. I will have several users installing packages and I can not trust that they will check every package. Thus I’d like to know whether I can trust the system to be resilient without careful attention.









  • I use fedora with wayland and use teams at work. The non official desktop program is completely unusable.

    What I end up doing when I have a call is open it both in Firefox and chrome and check which one works first. I’ll open it on my phone as well in case neither works. Sometimes it works, sometimes it does not.

    I found that audio does not work if you connect headphones after the browser was started.

    In general my solution is to push to use jitsi anytime I can.






  • I guess it can have its uses, but it would definitely not replace a mobile phone for me. It may be good in an office where you get your calls by the computer and indeed for internet connection on a laptop, but it will not replace the ease of going somewhere and calling your friend to say “I’m in the square, I don’t see you let’s meet at this bar”.