basically, the tests sporadically fail to kill the `socat` process,
reporting it to not exist. in the log, you could also see the `socat`
existing with SIG15. so my guess is -- `socat` can get killed by the
environment (nix build pipeline, for instance), and would no longer
require a cleanup (won't be reparented to PID1).
so the mental shift is -- as long as `socat` is gone, the clean was
successful. the failure mode here would be incorrectly capturing
`socat`'s PID, or missing the `kill` command (right now, it comes from
`coreutils` package, so presumably it would always be available).
`extraCombinators` were accepting a raw flake input (named `jail-nix`
here) instead of an instatiated flake output (name `jail` here).
also added a test to ensure it works correctly (I run tests locally for
now)
- correct tool positioning -- explain intended use cases without getting
into too much detail
- some fact-checking -- shared proc and IPC namespaces claim is totall
bogus
- document the tools this flake is based on, and explain the exposure
surface for each
- remove some explanations that were relevant in a context of the old
flake version -- old version is not published and will not be
observable to the user, so it must not be mentioned
- more laid-back and grounded documentation style: the intended audience
are engineers like myself -- not an LLM, not an investor
tag: deslop
my assumption here is -- nix doesn't care about the newlines in its
config, so I would prefer it to cope with a double newline, as it
drastically simplifies the `NIX_CONFIG` handling:
- no obscure append guard
- no double escaped newlines
- shorter code lines in general
tag: deslop