3 ms·
> NixOS itself still also has problems. The configuration / state for a program is scattered between /etc /nix/store ~ ~/.config /var instead of being in a cent
by someplaceguy 3y ago
> NixOS itself still also has problems. The configuration / state for a program is scattered between /etc /nix/store ~ ~/.config /var instead of being in a centralized place.
Those are features, not bugs... There are reasons for all of those existing and for why you wouldn't want everything in a centralized place.
- charcircuit 3y agoThe same could be said about having /bin /lib /usr/bin /usr/sbin /usr/lib /usr/local/bin /usr/local/lib ... yet these were all merged into /nix/store. NixOS's handling of state is poor. Even ignoring the problem of it all being spread out it is not uncommon for secrets to make it into /nix/store which is world readable.
- mongol 3y agoSecrets handling is indeed an issue, you can shoot yourself in the foot if you are not careful. If you are careful you can avoid it though and it is not neccessarily difficult. It is certainly is one aspect of NixOS that requires care and can be improved. But to me, it is not so bad as to avoid it. The advantages outweigh the disadvantages with a wide margin
- someplaceguy 3y agoWell, good luck convincing anyone to merge all config and mutable state into the same place (that should be fun, especially the user-specific config/state) :) > NixOS's handling of state is poor. Even ignoring the problem of it all being spread out it is not uncommon for secrets to make it into /nix/store which is world readable. The secrets handling is a well-known issue and easy to avoid when you're familiar with Nix. Although yes, it can be a problem when people are not aware of it. And I disagree with NixOS's handling of state being poor. Apart from this "secrets" problem you mentioned, it's not worse than other Linux-based operating systems and in fact it can be argued that it's significantly better. Just the fact that /nix/store is mounted read-only is, on its own, already a huge improvement over letting users and applications installing and modifying the system in an ad-hoc fashion (good luck when you upgrade your system!). Not to mention all the other advantages of /nix/store (such as user-installed applications, no package or library conflicts even if you install multiple versions of them, etc). And as another example, the `stateVersion` feature is something that also makes upgrades a lot more reliable, and I know of no other operating system that has a similar feature. Atomic configuration changes, booting into specific configurations, and system-wide configuration roll-backs (configurations which also include changes in package versions or even entire OS upgrades), also makes upgrades and configuration changes easy to try / fix if anything goes wrong. No other widely-used operating system has such a reliable configuration change mechanism, as far as I know. But, you know, if you have other ideas of how things can be improved (apart from your idea of merging user and system-wide state into the same place, which I think makes no sense), I would definitely appreciate to hear it!
- charcircuit 3y ago>Well, good luck convincing anyone to merge all config and mutable state into the same place It will need to happen sooner or later once distros realize that security is important. >it's not worse than other Linux-based operating systems I was not talking in relative terms. NixOS made steps in the right direction, but there is still much more that can be done.
- someplaceguy 3y agoIf you can think of a concrete and detailed, workable proposal, maybe you could write up a NixOS RFC and send a PR for discussion (or post something on the discourse community website?). Who knows, maybe something can be fleshed out and improvements come out of it...
- charcircuit 3y agoThanks for the suggestion, ut I don't currently have time to design this. If I did I personally think there are other usability issues that I would prioritized fixing instead of trying to push the technology forward.