From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp2 ([2001:41d0:2:4a6f::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms11 with LMTPS id 6Ht6ErvQSF/rLQAA0tVLHw (envelope-from ) for ; Fri, 28 Aug 2020 09:39:07 +0000 Received: from aspmx1.migadu.com ([2001:41d0:2:4a6f::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp2 with LMTPS id cEVLDrvQSF8rJAAAB5/wlQ (envelope-from ) for ; Fri, 28 Aug 2020 09:39:07 +0000 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id D3B159401AE for ; Fri, 28 Aug 2020 09:39:06 +0000 (UTC) Received: from localhost ([::1]:37874 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1kBaqf-0007Y7-Ix for larch@yhetil.org; Fri, 28 Aug 2020 05:39:05 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:49160) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1kBaqX-0007X4-Ct for guix-devel@gnu.org; Fri, 28 Aug 2020 05:38:57 -0400 Received: from mail3-relais-sop.national.inria.fr ([192.134.164.104]:16354) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1kBaqU-00062V-VC for guix-devel@gnu.org; Fri, 28 Aug 2020 05:38:56 -0400 X-IronPort-AV: E=Sophos;i="5.76,359,1592863200"; d="scan'208";a="357509845" Received: from unknown (HELO ribbon) ([193.50.110.227]) by mail3-relais-sop.national.inria.fr with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 28 Aug 2020 11:38:49 +0200 From: =?utf-8?Q?Ludovic_Court=C3=A8s?= To: Subject: Dealing with foreign distros without nscd X-URL: http://www.fdn.fr/~lcourtes/ X-Revolutionary-Date: 11 Fructidor an 228 de la =?utf-8?Q?R=C3=A9volution?= X-PGP-Key-ID: 0x090B11993D9AEBB5 X-PGP-Key: http://www.fdn.fr/~lcourtes/ludovic.asc X-PGP-Fingerprint: 3CE4 6455 8A84 FDC6 9DB4 0CFB 090B 1199 3D9A EBB5 X-OS: x86_64-pc-linux-gnu Date: Fri, 28 Aug 2020 11:38:49 +0200 Message-ID: <87blivrtxy.fsf@inria.fr> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/26.3 (gnu/linux) MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Received-SPF: pass client-ip=192.134.164.104; envelope-from=ludovic.courtes@inria.fr; helo=mail3-relais-sop.national.inria.fr X-detected-operating-system: by eggs.gnu.org: First seen = 2020/08/28 05:38:50 X-ACL-Warn: Detected OS = ??? X-Spam_score_int: -68 X-Spam_score: -6.9 X-Spam_bar: ------ X-Spam_report: (-6.9 / 5.0 requ) BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: guix-devel@gnu.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+larch=yhetil.org@gnu.org Sender: "Guix-devel" X-Scanner: scn0 Authentication-Results: aspmx1.migadu.com; dkim=none; dmarc=none; spf=pass (aspmx1.migadu.com: domain of guix-devel-bounces@gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=guix-devel-bounces@gnu.org X-Spam-Score: 0.49 X-TUID: IrKsi79JBi8+ Hello Guix! One of the most important pieces of advice we give to use Guix on foreign distros is to make sure the distro runs nscd, so we don=E2=80=99t e= nd up dlopening NSS modules in Guix-produced programs: https://guix.gnu.org/manual/en/html_node/Application-Setup.html#Name-Serv= ice-Switch A situation where this is not possible is HPC clusters: you would like to run packs there, but you=E2=80=99re not root and cannot spawn nscd, and = those machines typically use a Red Hat derivative with =E2=80=98sssd=E2=80=99: --8<---------------cut here---------------start------------->8--- $ grep sss /etc/nsswitch.conf passwd: files sss shadow: files sss group: files sss services: files sss netgroup: files sss automount: files sss --8<---------------cut here---------------end--------------->8--- If you try to run binaries from =E2=80=98guix pack=E2=80=99 there, they=E2= =80=99ll fail to find libnss_sss.so, and so user name lookups etc. (e.g., getpw(3)) will fail. The workaround I found is to add =E2=80=98sssd=E2=80=99 to the pack, like s= o: guix pack -RR -S /lib=3Dlib -S /bin=3Dbin sssd guile That way, on the other machine, you can set LD_LIBRARY_PATH such that Guix=E2=80=99 libnss_sss.so gets loaded: tar xf /path/to/pack.tgz LD_LIBRARY_PATH=3D$PWD/lib ./bin/guile -c '(pk (getpw (getuid)))' It works! However, if people have ideas of less arcane workarounds, I=E2= =80=99m interested. For the record, I pushed one commit that fixes =E2=80=98sssd=E2=80=99=C2=B9= and another one to have LD_LIBRARY_PATH honored when using GUIX_EXECUTION_ENGINE=3Dfakechroot=C2=B2. Ludo=E2=80=99. =C2=B9 https://git.savannah.gnu.org/cgit/guix.git/commit/?id=3D8df6900dffa9= e1c74ac3f64877f067974eee0eeb =C2=B2 https://git.savannah.gnu.org/cgit/guix.git/commit/?id=3D28dce8f02db3= 8a41e59ecdf3786baa6f732636ff