Sign in

Martin Schwaighofer

@mschwaig.bsky.social
117 followers 71 following 192 posts

Proving the link between source code and running systems with Nix. ❄ A solid foundation for supply chain security: doi.org/10.1145/3689944.3696169

PostsRepliesMedia
Reposted by Martin Schwaighofer
The C Programming Language @c-official.bsky.social · 21/03/2026
The great thing about C is that if your code compiles, it's correct
1123946
Martin Schwaighofer @mschwaig.bsky.social · 02/11/2025
the #nixos SC election ends in about two hours
010
Martin Schwaighofer @mschwaig.bsky.social · 18/09/2025
Tragically, being overly sensitive to temperature readings from the community creates an incentive in the community towards being loud and dramatic.
020
Martin Schwaighofer @mschwaig.bsky.social · 18/09/2025
All of the SC looking out into the community for feedback to determine what they should do seems like underutilizing the power they were elected to wield. It empowers the vocal minority in a similar way that not having formal leadership at all does.
120
Martin Schwaighofer @mschwaig.bsky.social · 18/09/2025
To me, one nice aspect of an executive-style role and with the current-size committee is that the executive can embody the need to make a decision one way or the other, with the SC hopefully reflecting a wide but reasonable range of opinions in the community to them.
110
Martin Schwaighofer @mschwaig.bsky.social · 17/09/2025
The main idea is delegating power to one person and revoking it if they actually do something that doesn't have the required support in the SC. That seems like something the constitution maybe already allows for, not sure.
120
Martin Schwaighofer @mschwaig.bsky.social · 17/09/2025
It's a bold proposal, but I imagine that would be one way of addressing some of the issues you pointed out without changing the constitution.
230
Martin Schwaighofer @mschwaig.bsky.social · 17/09/2025
Do you think it would make sense for the SC to select an executive amongst themselves that can lead BDFL-style as long as they have broad support within the SC?
130
Martin Schwaighofer @mschwaig.bsky.social · 05/08/2025
Maybe they'll add an s to the end for each subsequent release. They could even rebrand gpt-2 and gpt-1 as os and o.
020
Martin Schwaighofer @mschwaig.bsky.social · 25/07/2025
You can use fetchgit to fetch the repo and lib.fileset to do the filtering.
020
Martin Schwaighofer @mschwaig.bsky.social · 11/07/2025
You're right. I was looking at this kind of in the wrong way. 😅
020
Martin Schwaighofer @mschwaig.bsky.social · 11/07/2025
Oh, you probably mean just taking snapshots, not rolling back to them? 😅
110
Martin Schwaighofer @mschwaig.bsky.social · 11/07/2025
It sounds like that would lead to having inconsistent data / a 'split view' of your data whenever a rollback happens. Is this useful in some applications anyways?
110
Martin Schwaighofer @mschwaig.bsky.social · 04/07/2025
They are called Genki Instruments, the product the showed at the time is a Ring called Wave you can use to control stuff.
000
Martin Schwaighofer @mschwaig.bsky.social · 04/07/2025
Not 100 % what you asked I think, but Olí had a great talk at NixCon 2024 about how the firmware of the product his company builds for live music performance is built with nix: youtu.be/Nfn_srkKans
youtu.be
NixCon2024 Deterministic Firmware with Nix
YouTube video by NixCon
100
Martin Schwaighofer @mschwaig.bsky.social · 29/05/2025
Virtual Boy 2 😄
000
Martin Schwaighofer @mschwaig.bsky.social · 15/05/2025
Schiff 🚢
010
Martin Schwaighofer @mschwaig.bsky.social · 09/05/2025
Though that's not the only cool kind of verification I'd like to implement. For now I'm still working on the basics, and I'll work my way up to the really crazy parts. 🤪😅
020
Martin Schwaighofer @mschwaig.bsky.social · 09/05/2025
I started implementing a policy engine for trust model verification with the datafrog library now, so when someone wants to trust key A and key B only when they agree (reproducibility) that will be possible. 🐸
120
Martin Schwaighofer @mschwaig.bsky.social · 09/05/2025
Actually I even forked snix, so that I could port my upstream placeholder implementation to Rust and put it there, because that made sense to me. 😅👍
The GitHub UI showing a fork of the snix repository under my git username: mschwaig.

The description reads:
a development fork of https://git.snix.dev/snix/snix for laut

The license is MIT, and there are no stars or forks of it. Nothing else is visible besides a few buttons to navigate to Branches, Tags and Activity for the repo.
120
Martin Schwaighofer @mschwaig.bsky.social · 09/05/2025
I've started adding some rust code to laut. I even depend on sinx, the nix implementation written in rust, for nix32 encoding support.
The part of the GitHub UI that shows which portion of a repo is implemented in which language.

It shows 78.2 % Python, 14.2 % Nix and 7.6 % Rust.
150
Martin Schwaighofer @mschwaig.bsky.social · 07/05/2025
I get it. I think the middle ground of using Nix on another distro is probably nice for a lot of people who can't afford to chase after all of the small things that need effort to get working on NixOS. Why did you switch back? 😊
120
Martin Schwaighofer @mschwaig.bsky.social · 04/05/2025
Hi Wallfacer! 😊
010
Reposted by Martin Schwaighofer
mindflakes @mindflakes.bsky.social · 03/05/2025
Whenever my computer acts up I prepare a Computer Ant with a little expedition pack (headtorch, screwdriver, sandwiches, etc) and drop it into the USB port to go find the problem. It's never worked, not even once, but it's cute and distracting and that's what really matters
411715
Martin Schwaighofer @mschwaig.bsky.social · 04/05/2025
That's a bit scary. With ZFS I just kept a 1 GB reserved partition around to deal with how it behaves when it runs out of disk space. That was only necessary to give the nix db enough breathing room to successfully do GC.
000
Martin Schwaighofer @mschwaig.bsky.social · 29/04/2025
I ended up actually making a video about this now. If you are interested in Nix and Supply Chain Security, check it out: youtu.be/lqH2lVe8Isc EDIT: changed link to fix stereo audio
youtu.be
laut and the supply chain security best practices checklist
YouTube video by martin_builds_stuff
000
Martin Schwaighofer @mschwaig.bsky.social · 29/04/2025
Thanks, it's very nice of you to take the time to share your thoughts on this. 😊 Getting to 5 points probably isn't that easy actually, especially if you're not using Nix to do it. 😅 Let me know if you have any questions about laut.
000
Martin Schwaighofer @mschwaig.bsky.social · 25/04/2025
Thanks. 😁
010
Martin Schwaighofer @mschwaig.bsky.social · 25/04/2025
Thanks to the team at KTH in Stockholm, for your hard work on organizing this wonderful event. It is great that you are giving the supply chain security community this stage, which i think it desperately needs.
110
Martin Schwaighofer @mschwaig.bsky.social · 25/04/2025
In any case, when I get back to the studio at JKU I will try to make a short video about those individual checklist items, and not only if and how laut addresses them as part of its own development, buy also in terms of the vision that I have for what the project aims to provide to users eventually.
110
Martin Schwaighofer @mschwaig.bsky.social · 25/04/2025
Maybe it also shows that I am willing to go to great lengths in order to advertise my own project that I deeply believe in. Or it shows how most supply chain security professionals actually use a measured approach in terms of what they set up for their personal projects. I don't know. 😅
110
Martin Schwaighofer @mschwaig.bsky.social · 25/04/2025
I think it shows how hard it is to have a spotlight put onto what exactly you are doing in terms of supply chain security, especially in a room full of experts, even if you are yourself an expert, and when you have not checked all of the possible boxes yet, in terms of what others might expect.
110
Martin Schwaighofer @mschwaig.bsky.social · 25/04/2025
I won this nice hat today, for best practices in software supply chain security, for how I work on laut, at the Workshop on Supply Chain Security hosted by the CHAINS project at KTH. 🥳 I checked 5 out of 15 boxes on their self-assessment, and basically won by default because nobody else entered.
Me, a male human, in my bodily form, sitting in one of the window seats of an airliner, wearing a KTH hat and holding my filled-out best practices in software supply chain security self-assessment sheet, obscuring my lower face and chest.
310
Martin Schwaighofer @mschwaig.bsky.social · 24/04/2025
I think a lot of people and companies are getting frustrated with issues that stem from such limitations in these other tools and the huge effort required to manage them in various contexts, and are giving Nix a shot, in spite of its rough edges.
110
Martin Schwaighofer @mschwaig.bsky.social · 24/04/2025
If you have two things that are packaged in Nix, and you want to build or run a third thing that depends on both, conceptually that's easy to do in Nix. Nix makes things composable like that, tools like docker can't do that. Instead they force you to introduce, and then break a layer of isolation.
100
Martin Schwaighofer @mschwaig.bsky.social · 24/04/2025
I'm still scared of btrfs, because it was bad in 2018 or even earlier. Like the basic example people used to show off ZFS, where they use two small files as mirrored disks and have ZFS catch and fix it would not get caught in btrfs. I think. So, ... it better now and I can use it on my laptop? 😅
220
Martin Schwaighofer @mschwaig.bsky.social · 24/04/2025
Nobody: UDP: sessions never meant anything to me
000
Martin Schwaighofer @mschwaig.bsky.social · 23/04/2025
Thanks, you're right. The checkout action is real quick though, so I have no idea about the impact in those terms. 😅
000
Martin Schwaighofer @mschwaig.bsky.social · 23/04/2025
I use NixOS, with the arch wiki ... btw 😜
000
Martin Schwaighofer @mschwaig.bsky.social · 22/04/2025
That's really cool! Thanks for working on that stuff. 😅
010
Martin Schwaighofer @mschwaig.bsky.social · 22/04/2025
I consider them kind of a wart in the design as they are now. I wish they were less opaque.
010
Martin Schwaighofer @mschwaig.bsky.social · 22/04/2025
My guess is that it's because lots of people are starting to build their own derivations from scratch with the dynamic derivations experimental feature, and are running into them because of that.
100
Martin Schwaighofer @mschwaig.bsky.social · 22/04/2025
For almost 5 years I did not know they existed, until a few weeks ago. Now I run into them constantly. First I had to implement support for them myself for my project laut. Now it seems like a lot of people are running into them constantly.
220
Martin Schwaighofer @mschwaig.bsky.social · 22/04/2025
Oh god, those downstream placeholders again. 😂
100
Martin Schwaighofer @mschwaig.bsky.social · 21/04/2025
I'm curious to know what the problem was. I'm one of the users of that flag for my research, but I don't build full systems with it yet. 😊
110
Martin Schwaighofer @mschwaig.bsky.social · 17/04/2025
Sorry I had not heard about that UK court ruling. It was probably insensitive of me to ask that question in that context.
000
Martin Schwaighofer @mschwaig.bsky.social · 17/04/2025
Ok. Thanks for the reply, Gabby. Also thanks for being part of the Nix community in general, and for your work on the SC specifically.
100
Martin Schwaighofer @mschwaig.bsky.social · 17/04/2025
I think context matters. For example, i think it makes sense to treat issues that stem more from early upbringing and education differently from issues that center more around current lived experience.
000
Martin Schwaighofer @mschwaig.bsky.social · 17/04/2025
It seems like by going with feminism as an issue tied to 'immutable' biological features TERFs are always making that distinction, which I disagree with. On the other hand, personally right now, I also disagree with never making that distinction.
100
Martin Schwaighofer @mschwaig.bsky.social · 17/04/2025
Do you think we can and should sometimes make a distinction between women who were assigned female at birth and women who were socialized as boys in a respectful and sensible manner or not? 🤔
200