Are you saying that NixOS allows packages to cheat? That seems like a serious flaw.
If there's one thing worse than a non-purely-functional system, then it must be a system that claims to be purely-functional but turns out to be non-functional.
Are you saying that NixOS allows packages to cheat? That seems like a serious flaw.
If there's one thing worse than a non-purely-functional system, then it must be a system that claims to be purely-functional but turns out to be non-functional.
Namely there is:
- Making the Nix store writable. Normally it's mounted read-only, and only the Nix daemon can write finished deterministic builds there. Often wanted by users who haven't learned how to handle Nix packages, as they just want to change some file in the store.
- Disabling the sandbox. Usually all builds are done in a sandbox which doesn't have network access, read access only to the Nix store and write access only to only the destination directory in the Nix store (with some exceptions), which gives strong reproducability guarantees.
nix-env -i firefox
This does create an immutable copy of Firefox in the Nix store, but it's not reproducible in the sense that the profile state isn't captured in a Nix expression.