Fellas, I have 2 months before my next major commitment, my j*b. Wish me luck as I attempt to fully internalize the workings of #nixOS, #nix the language, and nix the pacman. I'd set up a #systemd #nspawnd #container for regular linux work. (I'd like other suggestions on this). My current plans:

- #flakes/'modern' practices
- dotfile integration (not using #homemanager)
- use #bitwarden integration somehow natively and bridging between bitwarden store cloned locally and #linux keystore (not even sure what I mean here)
- #secureboot that unseals the encrypted root partition keys from the TPM and auto-decrypts my root
- #nixpak as much
- package my scripts to be proper packages/flakes/modules/whatever for better integration
- #snix/ #lix?
- #dhall config instead?

Give more suggestions/tips

RE: https://mathstodon.xyz/@xameer/116555844234700032

maybe its happening on my system
as #lix has made some commits in view of some #infosec threat recently

An integer overflow vulnerability has been reported and mitigated by the #Lix project as part of a security coordination with the CppNix project.

https://lix.systems/blog/2026-05-05-lix-unsigned-integer-overflow/

All releases are available, installers were published, Nixpkgs small channels contains the fixes, patches are available. We recommend you upgrade at the earliest if you are at risk (see the additional guidance section).

#Nix #NixOS #security

An exploitable integer overflow in Lix (CVE-2026-44028)

Security researchers have found a security issue in Lix. This issue has been assigned CVE-2026-44028. Important note : The issues are different between Lix and CppNix but it seems there was confusion in MITRE who emitted the CVE and copied the wrong information which should have gone into the CppNix CVE, we are trying to update the CVE metadata.

Lix
Coroutine stack-to-heap overflow via unbounded recursion in NAR directory parser

https://github.com/NixOS/nix/security/advisories/GHSA-vh5x-56v6-4368

#Nix #Lix

#NoCVE atm
Coroutine stack-to-heap overflow via unbounded recursion in NAR directory parser

### Impact Unbounded recursion in the NAR (Nix Archive) parser could lead to a stack-to-heap overflow when the parser is run on a coroutine stack. The stack was allocated without a guard page, w...

GitHub

Whenever I can, I always add the option

--log-format multiline-with-logs

to my #nix commands just to get that maximum verbosity and scroll through history in case of failure.

Ps: #lix recently added an option to nix.conf to make it a default behavior. 😀 

log-format =
https://lix.systems/blog/2026-03-25-lix-2.95-release/

Announcing Lix 2.95 “Kakigōri”

We at the Lix team are proud to announce our sixth major release, version 2.95 “Kakigōri”. This release focuses on long-awaited bugfixes, quality-of-life improvements, documentation, performance improvements and continued integration of Lix with the Cap’n’Proto remote procedure call runtime to replace the previous bespoke implementation.

Lix

Digital sovereignty: the french government accelerates the reduction of its extra-European dependencies (#GAFAMdetox) - Links - #NixOS Discourse
https://discourse.nixos.org/t/digital-sovereignty-the-french-government-accelerates-the-reduction-of-its-extra-european-dependencies-gafamdetox/77071

Very cool. 😎

There is also a mention that this uses #Lix by default.

Digital sovereignty: the french government accelerates the reduction of its extra-European dependencies (#GAFAMdetox)

numerique.gouv.fr Adieu Windows : Sécurix et Bureautix, le Linux de l'État aux noms d'irréductibles Gaulois — Frandroid France plans to replace Windows with a hardened configuration built on NixOS. : NixOS

NixOS Discourse

my #lixcon2026 talk about build system yuri has been released: https://media.ccc.de/v/lixcon-2026-2-nix-and-buck2-from-enemies-to-lovers-with-snowydeer

slides: https://jade.fyi/lixcon2026

we build #nix store paths entirely outside of nix using deps from nix, then re-import them (with correct deps!) into nix once built. this powers writing a docker image in 6 lines of code without devs touching nix language at all.

you can use a new parameter in #lix 2.95's CLI to import store paths built by other build systems like we're doing, using `nix store add-path --references-list-json`.
happy yuri!

Nix and buck2: from enemies to lovers with snowydeer

media.ccc.de

Just watching the #lixcon talks, and the current talk just talked about "Botanix", does someone know where to find it? I might have missed where he said it's still unpublished?

#lix

Andel de fantasía, abril do 2026 - BiosBardia

Inés Mosquera. Esta listaxe céntrase en recomendacións de literatura infantil e xuvenil. Avalíanse unicamente obras publicadas durante os últimos doce meses. A lista publícase cada dous meses. Non se inclúen obras publicadas por Aira. A trompeta do cisne, de E.B. White. Tradución de Estela Villar Nogueira. Sushi Books O recoñecido escritor E. B. White é autor das coñecidas obras infantís…

BiosBardia

@nixpkgssecuritychanges This will not affect you if you us #Lix instead

#nix #nixos