public inbox for gentoo-dev@lists.gentoo.org
 help / color / mirror / Atom feed
From: Zac Medico <zmedico@gentoo.org>
To: gentoo-dev@lists.gentoo.org, Michael Orlitzky <mjo@gentoo.org>
Subject: Re: [gentoo-dev] [PATCH] install-qa-check.d: Support QA{,_STRICT}_INSTALL_PATHS variables (bug 670902)
Date: Mon, 12 Nov 2018 15:47:25 -0800	[thread overview]
Message-ID: <8b5289cf-2829-33b3-9d01-9461a3066b3e@gentoo.org> (raw)
In-Reply-To: <f32f85d3-28e9-dd06-a256-716488eca166@gentoo.org>


[-- Attachment #1.1: Type: text/plain, Size: 1199 bytes --]

On 11/12/18 2:34 PM, Michael Orlitzky wrote:
> On 11/12/2018 04:06 PM, Zac Medico wrote:
>> On 11/12/18 12:57 PM, Michael Orlitzky wrote:
>>> On 11/12/2018 03:33 PM, Zac Medico wrote:
>>>>
>>>> QA_INSTALL_PATHS=( /nix )
>>>
>>> That really, really, really doesn't belong there.
>>
>> I'm open to suggestions for alternatives. Ideas?
>>
> 
> /var/lib/nix?
> 
> The idea being, to put it in the right place by default, and let people
> override it with EXTRA_ECONF if they really want to download random
> binaries from strangers and run them.

I recommend to add /nix to the whitelist because this is the default
location for all operating systems, as shown consistently throughout the
installation instructions found at
https://nixos.org/nix/manual/#chap-installation.

The nix manual also has this explicit warning in the "Building Nix from
Source" section found at https://nixos.org/nix/manual/#sec-building-source:

> Warning: It is best not to change the Nix store from its default,
since doing
> so makes it impossible to use pre-built binaries from the standard Nixpkgs
> channels — that is, all packages will need to be built from source.
-- 
Thanks,
Zac


[-- Attachment #2: OpenPGP digital signature --]
[-- Type: application/pgp-signature, Size: 981 bytes --]

  reply	other threads:[~2018-11-12 23:47 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2018-11-12 20:33 [gentoo-dev] [PATCH] install-qa-check.d: Support QA{,_STRICT}_INSTALL_PATHS variables (bug 670902) Zac Medico
2018-11-12 20:57 ` Michael Orlitzky
2018-11-12 21:06   ` Zac Medico
2018-11-12 22:34     ` Michael Orlitzky
2018-11-12 23:47       ` Zac Medico [this message]
2018-11-13  5:44         ` Michael Orlitzky
2018-11-13  6:21           ` Zac Medico
2018-11-13  6:57             ` Michael Orlitzky
2018-11-13 21:21               ` William Hubbs

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=8b5289cf-2829-33b3-9d01-9461a3066b3e@gentoo.org \
    --to=zmedico@gentoo.org \
    --cc=gentoo-dev@lists.gentoo.org \
    --cc=mjo@gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox