Farid Zakaria

4 min read

DEFCON34 wrap-up


I recently came back from DEFCON34 and the nix.vegas community. The talks I gave are now online if you are interested in watching them. 🙌

Many thanks to all the organizers of DEFCON34 and nix.vegas. This is our, the Nix community and mine specifically, second year at DEFCON34 and it was a blast. To be honest, I barely interacted with the rest of DEFCON because I was so busy with the Nix community. The talks, the hallway conversations, and the in-chance encounters were all amazing.

One particular story, was that Carl Dong happen to be walking by the Nix Vegas village as I was giving my talk on Guix by Nix. He was a Bitcoin core developer and was one of the contributors responsible for the Bitcoin Core reproducible builds project that leverges Guix.11He was pleasantly surprised and happy to hear that Nix also has reproducible builds that start from stage0

Kismet.

§What is nix.vegas?

For those that don’t know: nix.vegas is the Nix community that runs within DEF CON in Las Vegas, hosted by the SoCal NixOS User Group and Distractions, Inc. This was its second year: DEF CON 33 ran under the banner “Rebuild the World”, and this year’s theme was “Escape Your Fate”.

The full playlist is on YouTube.

Note If the sound is a bit off or weird, this year DEF CON experimented with “silent” talks. Each talk was broadcasted and attendees had to wear headphones to listen. It was a bit weird giving talks to a quiet room. 🤷

§Relocatable Nix Binaries

Summary: Nix’s absolute /nix/store paths buy us reproducibility, but costs us the ability to put the store anywhere else. You can change the store prefix today, but it changes the hash of every single derivation in the closure down to bash, so you get to rebuild the world before you get to run hello.

How can we circumvent this?

The talk walks through $ORIGIN in RUNPATH and upstreaming support in the Linux kernel via a eBPF-based binfmt_misc solution.

Further reading: Linux kernel will support $ORIGIN, sort of.

§Guix by Nix

Summary: What was meant to be a lightning talk on guix-transfer and GuixPkgs but went a little over. This is our project on rewriting Guix derivations into Nix derivations so that every Guix package becomes buildable by Nix. This lets us include their source-bootstrapped JDK for instance, which nixpkgs does not have.

Further reading: Guix by Nix and GuixPkgs: every Guix package, as a Nix flake

§How to piss off your Nix friends

Summary: This talk is a bit of a rant, but it is given in good faith with a dose of humor. The core claim is that we optimize Nix and nixpkgs for social comfort and broad appeal, and we pay for it in technical ambition.

Further reading: How to piss off your Nix friends.

Looking forward to next year. Three talks in two days was a little ambitious, but I would do it again.

Everything lives on my talks page alongside their slides and the rest of my talks.