This includes a bunch of fixes against glibc >= 2.28 by @pbogdan, thanks
a lot :-)
While I haven't tested this by bootstrapping a NixOps Hetzner machine
(this is what nixpart0 is used for), I'm merging this anyway, since the
worst that could happen is that it's still broken.
I've build this on x86_64-linux but didn't extensively test it.