My Experience with Nix on OS X
mpscholten.de
mpscholten.de
It's very important for us to get such feedback. This allows us to improve and move forward.
In Nix defense I think it's not worth comparing stability yet, although that is the most important aspect for users.
What matters currently is how many smart people grasp the idea why we're fundamentally better by architecturing the language and packaging problem itself and any help we get to move us forward.
For fair comparison you should note that we have ~800 contributors, probably more than 90% are on Linux. Meanwhile Homebrew packages have almost 6000 contributors.
We have recently added 4 macs to our build farm at http://hydra.nixos.org/machines, but we desperately need more developers that care. Not 6000, just a few more.
My main complaint with Nix itself was that Vim was built without python support so Youcompleteme didn't work and it wasn't obvious how to recompile it to have python support, but the experience was nice enough that I'll give it another go later on.
But, comparing Nix on the simple operations is like reviewing a sports car after only driving it in a school zone. There is so much more that Nix provides that homebrew doesn't even come close to.
Nix has made managing of my servers way easier then anything I have tried before and I have no intentions of changing away any time soon.
I immediately ran into a showstopper bug that they've had for some time now. Apparently, they've focused on NixOS and the CA certificate configuration is borked on other platforms. This means Git, Curl and anything else that tries to use the standard OS certificate store will fail certificate validation. I know it's only one issue, but it was pernicious enough for me to nuke my Nix install and move onto something else.
At the moment, the best I can find for OS X is Rudix. The selection of available software is pathetic compared to Homebrew and Nix, but a lot of the core stuff is there and it's all packaged as a .pkg, which makes it really easy to cleanly erase installed software.
Apologies for hijacking a Nix thread, but I'd love your views on our OS X binary package sets[0]. We currently ship over 14,000 pre-built signed packages, all self-contained under /opt/pkg, and easy to search/install/remove using pkgin which has a familiar feel to anyone used to apt-get/yum/etc.
The packages are continuously built from pkgsrc trunk so should be reasonably up-to-date, and we try to be responsive when users need newer versions or packages built with different options.
So far the feedback has been positive, but I'd love to see more use-cases so we can improve the experience for everybody. Thanks.
In theory, but there's no package uninstaller and OS X installer packages are neither pure nor idempotent.
While you can remove the files installed by one, there's no straightforward or platform-provided way to undo the changes made by their (generally unknowable) install scripts.
Incidentally, Apple shipped an Xcode uninstaller; written in perl, it used lsbom and pkgutil to collect and subsequently remove the files owned by all the com.apple.dt packages complement the system-owned files or files installed by other packages.
I'm genuinely curious, I don't really use homebrew either since most of the stuff I need is already installed.
It basically boils down to one thing: isolation.
Everything you use will be described by Nix, no system libraries or commands. The only think you rely on is the kernel of the host.
Not only is my environment almost exactly the same from development to CI to deployment but I can actually copy the program exactly as it was built between them (assuming compatible kernel and architecture). For example when I push to my master branch CI automatically runs a build, tests the code with the exact versions of the libraries it will be using in production then uploads them to a binary cache (which is essentially the nix equivalent of a package server), Now I can just install the program on my production servers and it will use the exact versions of the libraries that I tested it with with almost no reliance on the underlying system.
It's like docker but simpler and more elegant.
If a passionate mac advocate wanted to take on the responsibility of setting up & running a CI machine and hooking it up to the github PRs, I can only imagine it being a good thing...
Now Travis doing this is interesting because last time people looked there was no hosting for OS X that wasn't ridiculously expensive, so we've literally had people donate Mac Minis.
At the moment that's broken (the 10.9 SDK is installed in 10.11, then links against some 10.11 libraries, which is blocking mplayer). I don't have the knowledge to fix it.
homebrew and fink have had the same problem (deciding when to link against system libraries and when to try to rebuild) -- hopefully nix will get over this hurdle.
Apple doesn't help this -- they want you to just install xcode and the most recent SDK and nothing else.
I'm tempted by the "1-environment" idea but homebrew has done such an excellent job in comparison to fink/port, I';; stay loyal. Also wondering if those two projects couldn't profit from some code sharing?
EDIT: completed sentence
Better CI + critical mass of maintainers (and that's just a few more) is all we need now.
[1]: https://github.com/PureDarwin/PureDarwin
[2]: https://www.macstadium.com/ (thanks!)
I totally agree that nix is the future of package management.
Also Guix switch challenge is incredible from a security perspective: https://www.gnu.org/software/guix/manual/html_node/Invoking-...
Nix should take those things back. Overall, it's a great package manager.
To go further, being different is almost always a bad idea. People are used to how current stuff works; you need a really good reason not to provide the same interface.
It is weird mostly due to exposure to other tools. IIRC nix started out over 10 years ago, well before apt or yum became very widely used.
I looked at the web-site and didn't find it clear what it does that Homebrew doesn't, other than being cross-platform (although I recently started using Linuxbrew which has made Homebrew cross-platform-ish for me).
{
packageOverrides = pkgs: with pkgs; rec {
all = buildEnv {
name = "all";
paths = [
vim
fish
gitAndTools.gitFull
];
};
};
}
This is the Nix package collection. You can install this package with `nix-env -i all`. What does it do? Install vim, install fish, install git. Not much, and easily doable in Homebrew in much fewer keystrokes.Now imagine you decided that you don't like vim and want to go with emacs. You change the paths to `paths = [ emacs fish gitAndTools.gitFull ]`. Run `nix-env -i all` again. What does it do now? It uninstall vim and install emacs.
Now that you decided you don't like emacs after all and want to go back to vim. You can just run `nix-env --rollback` and it will happily rollback the change it made to the filesystem made by latest nix-env call, as in, restoring vim at where you expect it to be.
This is the declarative nature of Nix. You declare the state you want the package to be (or the whole system, in case of NixOS) and Nix will figure out how to get to that state. default.nix can also do a lot more things, for example, adding custom packages, overriding versions, changing build flags and much more.
Let's say one day you need to clone the whole setup to other machine, you only need to copy this default.nix and run `nix-env -i all` on that machine and everything is reproduced in the way you expected. This default.nix can also be per-project, allowing collaborators to share the same packages (and custom packages).
If a package system is well designed, having the package for vim on my system shouldn't be doing any harm even if I'm not currently using it, so the system you are describing isn't really any better than just having a list of packages I want installed in a text file.
Using Vim isn't the best example (why would someone want multiple Vim?) but the same apply to languages as well. For example if I want to use Python 3.2, but there are handful of utilities that require 3.3+. I can just install 3.2 to my profile and install those utilities with 3.5 without actually exposing 3.5 to my profile.
I don't know if it is "the future", but it has features that would be very welcome in other package managers.
Perhaps, if they clean it up significantly, I think that nix's principles are very sound, but the implementation isn't: it's fine when you are using it as a simple package manager but as soon as you want to do something a bit complex (say building gcc with a different kernel version) you're on your own:
1) half of the documentation makes reference to configuration files which aren't in my version of nix??
2) there is no real mail/news forum for support/help: no IRC isn't enough.
I thought Gentoo was cool in the early 2000s when I didn't do sysadmin work for my job. I'm not waiting an hour or two to install a package anymore.
I'm sure this will improve when more precompiled packages are released for OSX when it is more popular.