Hacker News

Favorites Setup
Nix wrote half of my debugger (fzakaria.com)
2026-10-09 Fri | 201 points by ingve | original
[−]Cyph0n · 2026-10-10 Sat 20:02 UTC · link
Dude, this is amazing stuff. Farid really is putting out banger after Nix banger haha. This sounds like a mini/less capable Antithesis runtime, but running on your machine.

Curious: how does Rewind deal with randomness?

[−]setheron · 2026-10-11 Sun 02:52 UTC · link
The kernel's RNG is seeded from a seed passed at boot.
[−]iwixon · 2026-10-11 Sun 04:07 UTC · link
I had the exact same thought about Antithesis while reading this. I wonder if this could be used for concurrency bug hunting by setting up preconditions and grinding until failure to capture a bug you’re looking for.
[−]tecoholic · 2026-10-10 Sat 22:20 UTC · link
Seeing Nix these days is such a whiplash experience. We have fully deterministic systems and then we have LLMs. God ;)
[−]bentcorner · 2026-10-10 Sat 22:28 UTC · link
I use an agent to author my nix config - personally I don't have the determination to have picked Nix up entirely on my own so I find it to be a godsend. I can code review config changes and keep it all in git - also makes it easy to pick up the entire config and deploy it on a different machine.
[−]weavie · 2026-10-10 Sat 22:37 UTC · link
Plus if it messes up, you can just roll back.
[−]tyromaniac · 2026-10-10 Sat 23:42 UTC · link
I don't vibe code my config but this is still my favorite part. If I had it working at some point, I can always get my full system back to there
[−]nemo1618 · 2026-10-10 Sat 22:48 UTC · link
LLMs can be deterministic too! People just don't bother because the applications of this aren't widely known yet. See https://lukechampine.com/repligraphs
[−]autkuc · 2026-10-10 Sat 23:51 UTC · link
I was just reading Michael Lynch's posts about Sia[0] and I came across this.

Its a very curious project, but don't you end up pinning repligraph usability on model weights? Since you take indeterminism out of the equation, a repligraph's notability is as significant as the producing model's weights, and since there is no dice rolls to be made, the eyeball problem:

> Our blind spots, while not perfectly correlated, have substantial overlap

is entirely replicated. Models that are diffused from one another can have the same blind spots, the same loose statistical reality that exists with humans. This is partially addressed in steering:

> A repligraph proves that a model generated some artifact. It does not prove that the model did a good job, or that the artifact is safe.

but I think the "Peer Review" solution is inadequate, and with some jailbreaking prompts' innocuous looks considered, "the attacker just needs to find one prompt" might be much easier than it appears.

Batching seems to be a huge economic turn off for proprietary model determinism, but I think its entirely viable for consumer models. Trustless evals are brilliant and should've been our reality. Nice project, good luck on your endeavor.

[0]: https://mtlynch.io/tags/sia/

[−]nemo1618 · 2026-10-11 Sun 06:26 UTC · link
Thank you for the kind words! It's funny how much staying power those blog posts have, haha. Michael has some arcane ability to consistently hit the front page of HN.

True, I expect models to be pretty correlated with each other as well. But you can at least attempt to quantify that correlation in a rigorous way, by running experiments (e.g. by pointing each model at a big project and comparing the sets of bugs they each find).

And yeah, the "double-edged sword" aspect of determinism is definitely the biggest bullet that you have to bite. For me, it's better than the alternative; without determinism, such jailbreaking attacks are still possible, just harder to detect. But I certainly would not want people to go around thinking "it's deterministic, therefore it's safe."

[−]jazzyjackson · 2026-10-10 Sat 23:42 UTC · link
The configuration can be sloppy and vibed, as long as it behaves the same every time nix retains its power :)
[−]pjmlp · 2026-10-11 Sun 06:21 UTC · link
Deterministic systems like tracing GCs, JIT compilers, PGO data, machine learning optimising passes that vary their output, depending on program behaviours?
[−]__MatrixMan__ · 2026-10-10 Sat 22:25 UTC · link
I find myself moving more and more non-build things into nix builds because I don't want to roll my own cache invalidation. Seems like this is yet another reason to do so.
[−]pmarreck · 2026-10-10 Sat 22:43 UTC · link
There is likely a mass of devs that is probably, hmmm, 10x the number of Nix devs from over a year ago, who know exactly what Nix offers and why it is cool, but couldn't be bothered to master it until AI came along and basically "solved the problem".

So I'd expect AI to rapidly accelerate Nix adoption. Hopefully, because it is amazing.

[−]p1necone · 2026-10-10 Sat 23:19 UTC · link
Yeah I tried to daily drive Nix at one point pre AI and the ergonomics were just not a good match for me - perhaps I should try it again.
[−]pmarreck · 2026-10-11 Sun 05:06 UTC · link
I promise you that it will be worth it. Try again.
[−]californical · 2026-10-11 Sun 07:36 UTC · link
It really depends on the person, for me I have my own setup script that works on both Mac and Linux, installing all of my core software using whichever method is best for each system, I basically have a csv with columns of “program” “install command Linux” and “install command Mac” and it just works.

Then all of my dotfiles are backed up, with any important other config, in a big gig repo. And all of my documents/photos/etc live on a separate hard drive which gets backed up to the cloud.

All of that to say, with the right setup nix is mostly unnecessary, and honestly the benefit of not using it is that I can wipe my system anytime and restart it with just my usual important programs ready to go. Any mess made along the way gets purged automatically in every fresh install

[−]pavo-etc · 2026-10-10 Sat 23:21 UTC · link
This is exactly me and I've fallen in love with nix
[−]cedws · 2026-10-11 Sun 00:04 UTC · link
Me too. I’ve known about Nix for a long time but resisted the idea of learning a new language just to manage my system. In retrospect, it would have been worth it, but now I don’t have to.
[−]pmarreck · 2026-10-11 Sun 05:05 UTC · link
And I understand because it took me TEN YEARS to come around.

I worked with a very forward-thinking functional programmer around 2012 and even back then she was raving about it. And of course, people thought she was a raving lunatic.

I give her credit to this day. It took me having one too many problems caused by NOT using Nix, to cause me to finally dive in.

And there's no going back. Which is what happens with the best technologies.

[−]nine_k · 2026-10-11 Sun 00:24 UTC · link
Nix is amazing in many ways, but its discoverability and transparency are sometimes very poor. Its module system is anything but lean and straightforward.

I say this as a daily user of Nix.

[−]mamcx · 2026-10-11 Sun 00:58 UTC · link
Is mainly the language. Is not just weird like APL , that insanely make sense. is weird.
[−]jeremyjh · 2026-10-11 Sun 01:27 UTC · link
I don’t find it weird compared to other functional languages.
[−]Shish2k · 2026-10-11 Sun 08:13 UTC · link
That's not the compliment that you think it is...

(I say this as somebody who deeply loves the concepts in most functional languages, and loves the concepts in nix, but recognises that the developer-experience of both is about as pleasant as reading somebody else's code-golfed perl)

[−]nine_k · 2026-10-11 Sun 05:30 UTC · link
I don't find Nix the language particularly weird. But pick an arbitrary .nix file, see a bunch of stuff passed to the derivation, and try to find out whence it comes, and what types / attributes are expected there. The only definitely working solution I know is a full-text search over the file tree.

Now compare it even to Haskell, to say nothing about e.g. Typescript.

[−]0x457 · 2026-10-11 Sun 00:38 UTC · link
Yeah, even you understand nix and make packages it was still a PITA to use sometimes. If something isn't in nixpkgs or you need a different version, it might be as easy as writting 20 lines of nix, or 2000.

Now you can just send this to agent "port dis <repo link>" and 20 minutes later you get a working package, or 20 working packages what were required for that package to work.

Fixing stuff also easy, just today for some reason my machine wouldn't wake up monitors after sleeping them, a few minutes later claude fixed my configuration. Making QuickShell things with it also easy. For years I've avoide all GUIs for networkmanager and bluetooth on linux because they all looked awful and unusable, now QuickShell things made just for me, exactly the way I wanted.

[−]Nihmie · 2026-10-11 Sun 01:16 UTC · link
Before AI, there was virtually no documentation, and there are so many ways to do any single thing that it makes it brutal to figure out what any given configuration was trying to do.

Is `nix` amazing though? Eh... if it were implemented better, it could be amazing. It's like python virtual environments or `pyproject.toml` for general software. It solves a real problem, but it does so by introducing a possibly even bigger problem.

[−]pmarreck · 2026-10-11 Sun 05:07 UTC · link
No.

it's more like, it definitively solves a problem forever, like nothing else.

It's like when you have immutable data and it permanently solves a class of problems that can result from mutable data.

It's sort of like that.

[−]jeremyjh · 2026-10-11 Sun 01:25 UTC · link
I think that ratio is possible, and certainly I’m counted among those numbers. However, it is not so much the case that I longed to use Nix and agents made it more feasible. What happened is that I wanted an agent to manage my machine’s configuration without giving it much access.

It’s not the only thing that agents have changed for me - I also went back to using neovim and tmux; partly because of how I use remote development servers but also because now I can get my setup working perfectly for me without a lot of hassle.

Open source and code managing all the things has always been a great idea but now it feels crazy to do anything else.

[−]POiNTx · 2026-10-11 Sun 01:36 UTC · link
I've been using nix before you could use AI to write ok code with it and it was a struggle knowing how to configure nix sometimes. Especially when dealing with less popular software which happens from time to time. Still stuck to it as I've felt that once it was working it was pretty amazing. But using Claude with nix is super cool. It's really good and I don't care much about the quality of my nix config at this point, it's just for me and I just want my computer to do what I want it to do and Claude can figure it out most of the time.
[−]skydhash · 2026-10-11 Sun 02:17 UTC · link
I tried using various configurations tools and to this day, unless it’s needed for a project, my strategy is “don’t bother”. When I use a program for a while, I backup the config somewhere and perhaps write a few notes, but my daily setup vary enough and last enough that I wouldn’t replicate it.

My mac setup hasn’t been replaced since 2021 or something, and it was copied from my old mac. I have a dotfiles git repo, which I drag around and have multiple branches for my daily driver. For temp setup, I just copy files and edit.

[−]unshavedyak · 2026-10-11 Sun 02:21 UTC · link
Heck i used Claude when it sucked just to ask it questions. It was wrong on 50% of the questions back then but it still was easier than randomly searching for the solutions. Claude helped unblock me when i got stuck on obtuse nix errors, foreign compilation issues, etc.

These days it's magical, but it was even a huge boon when it was barely functional. Nix just had a way of leaving me super confused and stranded.

[−]pjmlp · 2026-10-11 Sun 06:18 UTC · link
I still cannot be bothered, even after reading this article.
[−]troupo · 2026-10-11 Sun 07:54 UTC · link
I find this take baffling.

"We have this system that is so amazing that... it requires a paid subscription to an LLM provider or a $5000 GPU for most people to understand and configure".

When instead Nix could've focused on releasing flakes 10 years ago with probably the same effect. And fix issues like this: https://news.ycombinator.com/item?id=50040083

[−]clivedup · 2026-10-11 Sun 09:02 UTC · link
And yet, it matches reality.

Flake stabilisation probably hasn't gotten any easier/more likely by LLMs, but it does make it quicker for people to pickup technology.

Technology sometimes has that odd effect. (And it will apply to different technologies in different contexts at different rates.)

[−]jeltz · 2026-10-11 Sun 10:58 UTC · link
Yes, this just confirms nämy view that Nix, as it is right now, is bad.
[−]riedel · 2026-10-11 Sun 10:12 UTC · link
I love the combination.

I use devenv (yet another nix flake dev environments) and opencode.

It is quite a synergy : my nix usage profits from the agent and the agent profits from being able to install just anything.

I even vibecoded a plugin for personal use that runs all bash tool calls through devenv and uses the supplied nix lsp package:

https://github.com/riedel/opencode-devenv

[−]riedel · 2026-10-11 Sun 10:26 UTC · link
Also being able to use wsl on my windows based work laptop added a lot to nixos affordance : https://nix-community.github.io/NixOS-WSL/install.html
[−]iwannakms · 2026-10-10 Sat 23:16 UTC · link
I'd love to become a Nix user one day. I tried to write a rather complex flake one day; it ended up with Nix (nix command) deleting itself: I immediately lost trust with it.
[−]iwannakms · 2026-10-10 Sat 23:19 UTC · link
Also Nix first tries to find a derivation in a remote cache and sets a very long timeout, so when you have a limited connection (e. g. a corporate limited network setup), it's painful.
[−]tracnar · 2026-10-11 Sun 08:00 UTC · link
I believe the default at least changed so it should be better now!
[−]stuxnet79 · 2026-10-11 Sun 03:03 UTC · link
This sounds like a total nightmare. I am very interested in Nix and was strongly considering setting it up on my new travel laptop as a daily driver but stories like these give me pause. I would love to get a more detailed explanation of what happened here. Either way I am past the phase where I'm comfortable or patient enough to beta test software so Debian / Ubuntu it is for me.
[−]chickensong · 2026-10-11 Sun 06:58 UTC · link
Nix daily driver for years here. I don't know what they did to screw up their system like that, but it's unusual IME. Normally you can just reboot and load the previous profile. Even in the absolute worst case, as long as you have your config, you could boot the installer and then load your config and your system comes back exactly as it was. It's definitely not beta software.

FWIW, I used Debian more than anything over decades, and also have little patience when it comes to unstable computers. NixOS is a breath of fresh air and has reinvigorated my love of Linux. I haven't found it less stable than Debian, and also have a higher degree of confidence when making changes. It has its quirks, but ultimately I've found it a joy to use, and I'm never going back to a distro that doesn't have similar capabilities.

If you boot default Debian and apt install a handful of packages from the primary channel, it probably doesn't matter much, but if you enjoy even a modest amount of customizing, NixOS really shines. From one Linux user to another, I encourage you to try it! I have no affiliation, just an old head stoked on Nix.

[−]saagarjha · 2026-10-10 Sat 23:35 UTC · link
I kind of confused what nix has to do with this considering it seems to basically be reimplementing rr?
[−]peter_d_sherman · 2026-10-11 Sun 02:30 UTC · link
The following page explains how Rewind VM works:

https://rewindvm.dev/#how

...of which the following are most important:

2. Run deterministically

One vCPU on stock KVM, so code in the VM runs on the real CPU. The VM's kernel carries a small Rewind platform: interrupts arrive only when the VM hands control to Rewind, time moves only then, and the timestamp counter and hardware RNG are hidden. A step is one of those handoffs.

3. Keep keyframes

Every quarter second of wall time, Rewind snapshots the machine using KVM's dirty-page [aka Memory Pages that have been written to since the last snapshot] log. Pages go into a content-addressed store (BLAKE3, zstd), so a page shared by keyframes, runs and forks is stored once."

Now, that's some brilliant engineering right there!

While I like the product name "Rewind VM" (and yes, that's what it allows the user to do!), it could just as easily be called "Deterministic VM" and that name would have been wholly appropriate, as well!

Future OS and VM engineers should study Rewind VM. Those are some great engineering ideas there, and determinism, or at least optional determinism, should it be desired, when it is desired -- is the one thing that is completely non-existent in most OS's, most VM's, and most other program runtime environments...

Anyway, a great article on using Rewind VM (never knew about it before this article!) with Nix builds.

[−]firemelt · 2026-10-11 Sun 04:24 UTC · link
so this is like redux but for the whole VM?
[−]troupo · 2026-10-11 Sun 08:01 UTC · link
Are you tooting your own horn?

There could be great ideas in Rewind VM, but the page is littered with Claude-ish which is immediately off-putting.

[−]fxtentacle · 2026-10-11 Sun 08:58 UTC · link
"What is this superpower, and why is nobody else using it?"

The "Undo" time-travelling debugger for C/C++ has been around for 20+ years. So I guess the answer is simply that most people chase shiny new things instead of using established, reliable, and, hence, boring tools.