3 ms·
I don't understand the conjunction of the following two phrases in the article: > * Nix goes a step further by disallowing package* > * builds to access the in
by frabbit 6y ago
I don't understand the conjunction of the following two phrases in the article:
> * Nix goes a step further by disallowing package*
> * builds to access the internet. This allows Nix*
> * packages to be a lot more reproducible;*
and
> * The src attribute tells Nix where the source *
> * code of the package is stored. Sometimes this*
> * can be a URL to a compressed archive on the*
> * internet,
- tridentlead 6y agoThe idea is that as long as the downloaded source file matches the hash all inputs are deterministic and so is the build overall.
- scintill76 6y agoRight. More specifically, Nix itself can download files in this way, but the build scripts (in this case, the mkdir & cp part) are not allowed access so that the build is deterministic.
- takeda 6y agoFirst paragraph talks about build. The build by default happens in sandbox, with many things disabled to force reproducibility. It sometimes makes things annoying, for example there was one Ruby package that was downloading a file during build, so whomever was making a derivation needed to download it in advance) The second paragraph talks about fetching sources which nix does before build starts, each source is required to be provided with hash, this ensures that it is an identical file that author of the derivation used.