3 ms·
> For example you could have a /nix/state that had a directory for each program. NixOS already has that. It's called `/var/lib`. > Each program could have its
by someplaceguy 3y ago
> For example you could have a /nix/state that had a directory for each program.
NixOS already has that. It's called `/var/lib`.
> Each program could have its own global and user specific state it could manage from within its directory.
The user-specific state is (and should be) in each user's home directory, not scattered around in a bunch of system-wide directories, one for each application...
That's not just for convenience, but also for security (and privacy) reasons.
I'd be interested to know who gets to manage the user-specific state in your proposal. Does each app have it's own per-user directory for each user? i.e. if you have 1000 apps and 10 users, do you need exactly 10,000 user-specific directories? And if not, who gets to create these directories and when are they created/removed?
To be honest, it sounds like you're not aware of all the complexities and implications / consequences of what you're proposing, i.e. it sounds like you didn't think this through. But on the off-chance I'm wrong, I'd be happy to be proven so.
- charcircuit 3y ago>The user-specific state is (and should be) in each user's home directory, not scattered around in a bunch of system-wide directories, one for each application... I disagree with this because state is owned by the program so it would make the most sense for it to live in the directory for the program. A user can tell the program that they want to modify the state, but ultimately the program has total ownership of its state. The program should not be leaching into user's home directory to read and write files and should be restricted to directories it owns. >I'd be interested to know who gets to manage the user-specific state in your proposal. One way to do it would be for the program to manage it. >Does each app have it's own per-user directory for each user? It could choose. >if you have 1000 apps and 10 users, do you need exactly 10,000 user-specific directories? This is unrealistic. On the want majority of computers an app will only be run by 1 user. Focusing on handling multiple users is a more special case and is a distraction from the point I'm trying to make.
- someplaceguy 3y ago> One way to do it would be for the program to manage it. Really? So a program can access (and modify!) the state of all of its users? Do you realize how easy it would be to trick my Firefox instance into reading (and even modifying) the state of another user, and even running other code on behalf of another user, given that it would have privileges to do so? If I understand correctly your proposal, you basically just converted almost every single application bug into a privilege escalation bug. Not to mention that how do you even define what the same "app" is? Is Firefox 28 the same app as Firefox 45? And if so, can a user install his own Firefox (like you currently can on NixOS and even other OSes)? Also, how would you backup all of your own per-user state, given that every app can decide to manage it differently (i.e. storing it in different files and/or directories inside their own per-app directory, or perhaps even in a single per-app database which you wouldn't have access to). Look, I'm not trying to grill you, I just think you haven't thought this through (but again, I'm happy to be proven wrong). > This is unrealistic. On the want majority of computers an app will only be run by 1 user. Focusing on handling multiple users is a more special case and is a distraction from the point I'm trying to make. What does this even mean? We're talking about user-specific state. So there's different state for each user, which means there are multiple users, by definition! So how is focusing on multiple users a distraction? It's the whole point... As I mentioned, on NixOS, the system-wide mutable state is already stored on /var/lib/<app>, which is what you are (redundantly) proposing. So we're just arguing about how to handle user-specific state, nothing else.
- charcircuit 3y ago>Really? So a program can access (and modify!) the state of all of its users? I never said that. The same binary can be run by multiple users and the user running it affects what files it can read and write. >Not to mention that how do you even define what the same "app" is? The user has an idea on what the same app is. Unfortunately Nix does not properly understand this concept. >Also, how would you backup all of your own per-user state, given that every app can decide to manage it differently You could back up the entire state visible to the user. >What does this even mean? Having a single set of state for each program would be good enough for most users. >As I mentioned, on NixOS, the system-wide mutable state is already stored on /var/lib/<app>, which is what you are (redundantly) proposing. That is one place. Some programs don't use it. It's not a centralized place of state for every program.