[prev in list] [next in list] [prev in thread] [next in thread] 

List:       nix-dev
Subject:    Re: [Nix-dev] help with patch for screen locking
From:       zimbatm <zimbatm () zimbatm ! com>
Date:       2017-02-07 20:05:05
Message-ID: CANEP-f6rjaqNvZ34Zc3PKGkTu8MUf7cHdURc2ECkRrTErHQAyA () mail ! gmail ! com
[Download RAW message or body]

[Attachment #2 (multipart/alternative)]


Regarding the suid bit, why don't we let the program decide what suid
should be applied to it's programs?
https://github.com/NixOS/nixpkgs/pull/22532

On Tue, 7 Feb 2017 at 19:38 <david@zarel.net> wrote:

> On 2017-02-07 19:50, Tomasz Czy=C5=BC wrote:
> > David,
> >
> > I assume you are not talking about
> > https://github.com/NixOS/nixpkgs/issues/16485 [2]?
>
> In fact I'm talking about https://github.com/NixOS/nixpkgs/issues/16845
> :-) my mistake
>
> > Usually I'm using this kind of stuff as part of user session/desktop
> > environment.
>
> Exactly, the actual screenlocker would be installed as a system package,
> I thought it was okay because I noticed something like that was already
> present in xfce.nix, but maybe we can adapt xfce4-session to accept a
> new build input and change it so that it calls the screenlocker in the
> nix store instead of calling the system package.
>
> With regards to slock: maybe we can ask the user to explicitly enable
> the suid like we do when a user tries to install a non-free package?
> _______________________________________________
> nix-dev mailing list
> nix-dev@lists.science.uu.nl
> http://lists.science.uu.nl/mailman/listinfo/nix-dev
>

[Attachment #5 (text/html)]

<div dir="ltr">Regarding the suid bit, why don&#39;t we let the program decide what \
suid should be applied to it&#39;s programs?  <a \
href="https://github.com/NixOS/nixpkgs/pull/22532">https://github.com/NixOS/nixpkgs/pull/22532</a></div><br><div \
class="gmail_quote"><div dir="ltr">On Tue, 7 Feb 2017 at 19:38 &lt;<a \
href="mailto:david@zarel.net">david@zarel.net</a>&gt; wrote:<br></div><blockquote \
class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc \
solid;padding-left:1ex">On 2017-02-07 19:50, Tomasz Czyż wrote:<br \
class="gmail_msg"> &gt; David,<br class="gmail_msg">
&gt;<br class="gmail_msg">
&gt; I assume you are not talking about<br class="gmail_msg">
&gt; <a href="https://github.com/NixOS/nixpkgs/issues/16485" rel="noreferrer" \
class="gmail_msg" target="_blank">https://github.com/NixOS/nixpkgs/issues/16485</a> \
[2]?<br class="gmail_msg"> <br class="gmail_msg">
In fact I&#39;m talking about <a href="https://github.com/NixOS/nixpkgs/issues/16845" \
rel="noreferrer" class="gmail_msg" \
target="_blank">https://github.com/NixOS/nixpkgs/issues/16845</a><br \
class="gmail_msg"> :-) my mistake<br class="gmail_msg">
<br class="gmail_msg">
&gt; Usually I&#39;m using this kind of stuff as part of user session/desktop<br \
class="gmail_msg"> &gt; environment.<br class="gmail_msg">
<br class="gmail_msg">
Exactly, the actual screenlocker would be installed as a system package,<br \
class="gmail_msg"> I thought it was okay because I noticed something like that was \
already<br class="gmail_msg"> present in xfce.nix, but maybe we can adapt \
xfce4-session to accept a<br class="gmail_msg"> new build input and change it so that \
it calls the screenlocker in the<br class="gmail_msg"> nix store instead of calling \
the system package.<br class="gmail_msg"> <br class="gmail_msg">
With regards to slock: maybe we can ask the user to explicitly enable<br \
class="gmail_msg"> the suid like we do when a user tries to install a non-free \
package?<br class="gmail_msg"> _______________________________________________<br \
class="gmail_msg"> nix-dev mailing list<br class="gmail_msg">
<a href="mailto:nix-dev@lists.science.uu.nl" class="gmail_msg" \
target="_blank">nix-dev@lists.science.uu.nl</a><br class="gmail_msg"> <a \
href="http://lists.science.uu.nl/mailman/listinfo/nix-dev" rel="noreferrer" \
class="gmail_msg" target="_blank">http://lists.science.uu.nl/mailman/listinfo/nix-dev</a><br \
class="gmail_msg"> </blockquote></div>



_______________________________________________
nix-dev mailing list
nix-dev@lists.science.uu.nl
http://lists.science.uu.nl/mailman/listinfo/nix-dev


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic