Gentoo Archives: gentoo-dev

From: Zac Medico <zmedico@g.o>
To: gentoo-dev@l.g.o, Michael Orlitzky <mjo@g.o>
Subject: Re: [gentoo-dev] [PATCH] install-qa-check.d: Support QA{,_STRICT}_INSTALL_PATHS variables (bug 670902)
Date: Mon, 12 Nov 2018 23:47:25
Message-Id: 8b5289cf-2829-33b3-9d01-9461a3066b3e@gentoo.org
In Reply to: Re: [gentoo-dev] [PATCH] install-qa-check.d: Support QA{,_STRICT}_INSTALL_PATHS variables (bug 670902) by Michael Orlitzky
1 On 11/12/18 2:34 PM, Michael Orlitzky wrote:
2 > On 11/12/2018 04:06 PM, Zac Medico wrote:
3 >> On 11/12/18 12:57 PM, Michael Orlitzky wrote:
4 >>> On 11/12/2018 03:33 PM, Zac Medico wrote:
5 >>>>
6 >>>> QA_INSTALL_PATHS=( /nix )
7 >>>
8 >>> That really, really, really doesn't belong there.
9 >>
10 >> I'm open to suggestions for alternatives. Ideas?
11 >>
12 >
13 > /var/lib/nix?
14 >
15 > The idea being, to put it in the right place by default, and let people
16 > override it with EXTRA_ECONF if they really want to download random
17 > binaries from strangers and run them.
18
19 I recommend to add /nix to the whitelist because this is the default
20 location for all operating systems, as shown consistently throughout the
21 installation instructions found at
22 https://nixos.org/nix/manual/#chap-installation.
23
24 The nix manual also has this explicit warning in the "Building Nix from
25 Source" section found at https://nixos.org/nix/manual/#sec-building-source:
26
27 > Warning: It is best not to change the Nix store from its default,
28 since doing
29 > so makes it impossible to use pre-built binaries from the standard Nixpkgs
30 > channels — that is, all packages will need to be built from source.
31 --
32 Thanks,
33 Zac

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies