home.social

#guixsystem — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #guixsystem, aggregated by home.social.

fetched live
  1. @nen Mietin, jaksaisinko vielä tänään kokeilla #GuixSystem'iä. Viimeksi kun kokeilin, koneessa oli #IntelARC-näytönohjain ja näyttö meni sekaisin. (Guix on #GNU-brändätty, joten näyttöajureissa saa tyytyä siihen, mitä binaarimöykyittä saa.)

  2. 🛡️🪲 Managerul de pachete GNU Guix a fost lovit de patru vulnerabilități de securitate 🚀💻

    GNU Guix, managerul de pachete tranzacțional și avansat din ecosistemul GNU — apreciat la nivel global pentru abordarea sa puristă în privința libertății software, configurarea declarativă și reproductibilitatea absolută a build-urilor — se confruntă cu o provocare serioasă de securitate. Comunitatea de dezvoltatori a confirmat oficial descoperirea a patru vulnerabilități în logica sa de funcționare, forțând emiterea unor patch-uri de urgență.

    Deoarece GNU Guix folosește un demon de fundal cu privilegii ridicate (guix-daemon) pentru a compila și izola pachetele destinate utilizatorilor, aceste breșe reprezintă un risc considerabil pentru integritatea sistemelor afectate.

    Iată detaliile principale despre problemele identificate:

    🔹 Breșe la nivelul privilegiilor și izolării (Sandbox Escape):
    Vulnerabilitățile identificate vizează în mod special mecanismul de sandbox (mediul izolat) pe care Guix îl folosește în timpul compilării pachetelor din surse.

    Riscul: Anumite erori logice în gestionarea permisiunilor și a directoarelor temporare de build puteau permite unui pachet malițios să „evadeze” din containerul său izolat. Odată evadat, codul atacatorului ar fi putut interfața cu fișierele critice ale sistemului gazdă sau ar fi putut obține o escaladare neautorizată a privilegiilor până la nivelul de root.

    🔹 Manipularea reproducerii pachetelor (Build Poisoning):
    Una dintre cele mai mari calități ale GNU Guix este reproductibilitatea (același cod sursă generează bit cu bit același binar). Breșele raportate introduceau un risc de „otrăvire” a procesului de build local, permițând unui utilizator local neautorizat sau unui script malițios să modifice rezultatul compilării altor pachete de pe mașină, alterând binarul final fără ca administratorul să observe imediat.

    🔹 Remedierea și corecturile aplicate:
    Echipa GNU Guix a reacționat cu promptitudine imediat ce detaliile tehnice au fost verificate. A fost lansată o actualizare care modifică modul în care guix-daemon gestionează variabilele de mediu, legăturile simbolice (symlinks) și montarea directoarelor în sandbox, închizând complet portițele de evadare folosite în scenariile de atac testate.

    ⚠️ Acțiune obligatorie pentru utilizatori: Dacă rulezi GNU Guix ca manager de pachete independent pe o altă distribuție sau dacă folosești sistemul de operare complet Guix System, este critic să îți actualizezi demonul de sistem imediat.

    Pentru a securiza mașina, utilizatorii trebuie să ruleze comanda de actualizare a profilelor și, extrem de important, să repornească serviciul de fundal:

    Bash
    guix pull
    sudo systemctl restart guix-daemon
    Prin această intervenție rapidă, comunitatea demonstrează din nou că transparența totală a codului open-source și auditurile de securitate riguroase sunt cele mai bune mecanisme de protecție împotriva defectelor inevitabile de programare.

    #GNUGuix #GuixSystem #GNULinux #Cybersecurity #PackageManager #SandboxEscape #PrivilegeEscalation #OpenSource #TechNews

  3. tl;dr Staying on Debian Stable

    So it's been an interesting summer of experiment. I've been on #Debian Stable for ages and loved it from the beginning. I've dabbled for the first time this summer in #Fedora (easiest and safest #AsahiLinux install on a discarded Macbook). And I finally got time (and lots of help! thanks!) to try out #Guix #GuixSystem as a distro.

    Impressed with Fedora, rock solid. As a GNOME user it would take awhile to notice it wasn't Debian. I bet people alias apt=dnf. But it made me realize: the update pace on Fedora vexed me.

    Debian "Stable" doesn't mean Debian doesn't crash. Debian Stable means Debian doesn't CHANGE.

    And when I finally got my caveman skull (partially, crudely) around the Guix/Nix paradigm, I realized it was just Arch with extra steps. I yearn for the mathematical formality of a declarative Lispy config. It may not have been worth the extra complexity and learning curve, but it definitely was not worth leaving the Stable lifestyle. I do love to tinker, but I love to have a simple familiar boring system. I guess more.

    What drew me to Guix in the first place was the promise of reproducible portability: it is very important that the Stack of Laptops all behave the same. But I have in fact enjoyed this very thing for years, with a bash script. If you've read this far, could you just validate me here? Tell me you approve of my imperative setup? 😆

  4. Well, scratch that, problem was in contents of /etc/resolve.conf not being generated for new version. Why I don't know ha ha ha , simple fix go into previous generation, copy settings, go back to new generation copypasta those settings into new gens etc/resolve.conf, think about how to do it properly next time. The game continues #GuixSystem #guix

  5. Looks like Guix may be going slop-free. That would be cool, if it happens. They're pretty extreme about their dedication to Free Software, you'd think it would be an obvious step to take. codeberg.org/guix/guix-consens

    #GuixSystem #Linux

  6. Tackling WordPress on Guix continues! In Part 2 The GNU Guy makes more progress setting up WordPress on Guix System — perfect for self-hosters and Guix learners. Practical steps, tips and demos to follow. #WordPress #Guix #GuixSystem #GNU #FreeSoftware #SelfHost #Linux #Tutorial #Education #English
    peertube.vesdia.eu/videos/watc

  7. Äh, olisi kiva saada harvemmin käytettyyn #matkakannettava'an (kohta 11 vuotta vanha Asus Zenbook ultrakannettava) jokin h-i-t-a-a-s-t-i päivittyvä vakaa käyttis. #Debian13 siinä oli, se on ookoo(hko). Kokeilin #RockyLinux 10.1:tä, ookoo mutta #RHEL'in pakettivarastoista puuttuu minulle oleellisia ohjelmia. #GuixSystem ei edes asennu, koska langaton verkkokortti vaatisi suljettua koodia. #openSUSEKalpa asentuu mutta pääsee vain komentoriville. #linux #bsd #floss #atkjuttuja

  8. #IntelArc asettaa todella ankaria rajoituksia sille, mitä vapaata järjestelmää kokeilukoneelle kannattaa yrittää. Kaikki #BSD:t #FreeBSD:tä myöten ovat joko kieltäytyneet pääsemästä graafiseen tilaan tai buutanneet itsensä yrittäessään; Linuxeistakin #GuixSystem'issä oli näytönpiirto-ongelmia ja lopulta #Kwin lakkasi käynnistymästä (eli työpöydälle pääsi mutta ikkunoilla ei ollut reunoja ja ne olivat vain kiinteä alue näytön vasemmassa yläkulmassa). #linux #floss #atkjuttuja

  9. So proud and happy!
    Don't forget to donate.
    The 1.5.0 version is now available!
    #guix #OS #GuixSystem #new_releases #gnu #foss #freesoftware
    :bongoCat:

    Read it for more informations:

    guix.gnu.org/en/blog/2026/gnu-

  10. Vapaa #kokeilukone ja #vapaaherra'na päiviään viettävä (ja hammashuolensa hetkeksi taka-alalle painava) herrasmies… mitäs sitä tekisi? No #Arch voisi väistyä, kokeiluun vaikkapa #GuixSystem tai #Gentoo. Jälkimmäistä en ole koskaan vielä jaksanut asentaa, tahtoo puuduttaa ajatuskin siitä, että koko ajan pitää olla toinen kone vierellä näyttämässä asennusohjeita. #NixOS tuli jo kokeiltua, joten olisiko Guixin vuoro? #atkjuttuja #linux #bsd #floss

  11. So #GuixSystem (i.e., the OS) has a service to provide a build VM to sandbox the #Guix build process, and this made me think, it could be handy to provide a service for creating #Trisquel or #Parabola VMs as a base, effectively extending the Guix functionality set with the Debian & Arch Linux package archives

  12. This is the end of this experiment with #Guix and #GuixSystem

    I really like the ideas behind Guix, and learned a lot by reading its documentation and playing with it. But I will put it back on a shelf for now, because what I need is a system for daily use which gets out of the way. At my current skill level with it, and in its current state, we're not quite there yet.

    I'm keeping my configuration files and a fresh installation iso, so I can get going more quickly next time I feel like trying it again.

    After a few days of testing, it turns out #FedoraSilverblue is going to fit the bill nicely. It shares some ideas with Guix (immutability, rollbacks, in general better isolation between OS and apps), and everything I need seems to be available and working out of the box.
    It's running smoothly on this 10-year old Intel Nuc, so will also be fine on a 10-year old MacBook Pro (with slightly higher specs) whenever I'm ready to make the switch.

    This other thread is what prompted me to try and find a more future-proof OS: fediscience.org/@Guillawme/113

  13. First time I have time to play with #Guix and #GuixSystem since the previous post... The spring semester is getting very busy very fast, leaving little time for this experiment.

    Today `guix pull` really made the computer break a sweat, big time. This is telling me that, as cool as Guix is, and as much as I like the ideas it embodies, maybe I am not quite yet ready to make it my main OS. On the other hand, with today's update several CLI apps I was missing are now available. Really cool to see more things entering the package collection!

    I still want to contribute some package definitions, but at the current rates at which I learn and guix improves, these might well be contributed by others by the time I figure out how to make them build* or how to send my contributions**.

    *: with some I got stuck, see for example codeberg.org/guix-science/guix

    **: I wish the main guix channel was on a forge like Codeberg, it would be so much easier to contribute.

  14. A bit frustrated with #Guix and #GuixSystem lately... Can't get 'emacs --daemon' to work reliably. I have a shepherd user service that starts and stops cleanly. But 'emacsclient' can never bring up a graphical window despite being run from a graphical session.

    But somewhat surprisingly, setting up a wifi printer was easier than I expected. Seeing the CUPS printer test page made my evening yesterday! (small things, eh?). I still need to move this to the system configuration file, since this initial test was done through the CUPS web interface.
    The scanner on this same device worked with zero configuration, over the wifi too. Getting this to work was one of the main potential roadblocks to ditching macOS. I don't scan or print often, but when I need to it's for important things. And it's too inconvenient to scramble to find a scanner/printer at work or at a library, so it's got to work at home.

  15. Lately I've had less free time to play with #Guix and #GuixSystem (no longer on vacation), so I haven't written to this thread. Recent progress is like two steps forward, one back. Still progress.

    I made my configuration files public here: codeberg.org/Guillawme/guix-co
    It's a work in progress. If something is obviously wrong I'd like to know, so don't hesitate to tell me, whoever is reading this.

    Thanks to Guix I resurrected my old #Emacs config, and it's been very fun!
    I started it in June 2015 while procrastinating on my PhD thesis... which I wrote more efficiently, of course, once I had an Emacs config I liked. 🙃 I abandoned it in 2019 to switch to doom-emacs. Doom never felt like home, it's somebody else's config after all. It also looks too much like an operating system. I quit doom when it started doing native compilation of elisp files by default: each update would make the computer break a sweat. At this point I also had "config burn-out" (not bankruptcy, it was still manageable, but I was tired of it). Some parts of Emacs never worked well on a Mac, which made it frustrating. I settled on helix, which is excellent! I love its approach of "good defaults" and "everything built-in".

    Now I realize how much the Emacs experience is better in GuixSystem. Certain things are still a pain to set up (emacs --daemon, anyone?), but I am hopeful that once done it will function forever thanks to Guix.

  16. My adventures on #GuixSystem: I have learned two lessons in the last few days:
    (1) Don't use ext4 for your root drive in #Guix - you will run out of inodes. That is a bad thing, and has required me learn how to properly use btrfs with subvols etc. This necessitated several attempts to make a working install! Then:
    (2) Don't put /tmp on tmpfs, even with 32Gb of memory. If you have any complexity in your setup, you will run out of space before the build completes. This is also bad. Remounting /tmp elsewhere doesn't seem to be possible, or at least easy. I made a very simple configuration which did build, but wouldn't boot. Earlier generations also didn't boot. So now I am going through the install process yet again.
    To be clear - this is OK - it's a test machine, a learning opportunity, and I have time. There are some odd things in the installation process I don't understand, so I want to clarify these as well.
    I think I might make it an #hpr episode when I finally know enough!