diff --git a/docker.nix b/docker.nix index a9489e5b0..60490469f 100644 --- a/docker.nix +++ b/docker.nix @@ -62,38 +62,37 @@ let ++ autoLayered ++ extraPkgs; - users = - { + users = { - root = { - uid = 0; - shell = "${pkgs.bashInteractive}/bin/bash"; - home = "/root"; - gid = 0; - groups = [ "root" ]; - description = "System administrator"; - }; + root = { + uid = 0; + shell = "${pkgs.bashInteractive}/bin/bash"; + home = "/root"; + gid = 0; + groups = [ "root" ]; + description = "System administrator"; + }; - nobody = { - uid = 65534; - shell = "${pkgs.shadow}/bin/nologin"; - home = "/var/empty"; - gid = 65534; - groups = [ "nobody" ]; - description = "Unprivileged account (don't use!)"; + nobody = { + uid = 65534; + shell = "${pkgs.shadow}/bin/nologin"; + home = "/var/empty"; + gid = 65534; + groups = [ "nobody" ]; + description = "Unprivileged account (don't use!)"; + }; + } + // lib.listToAttrs ( + map (n: { + name = "nixbld${toString n}"; + value = { + uid = 30000 + n; + gid = 30000; + groups = [ "nixbld" ]; + description = "Nix build user ${toString n}"; }; - } - // lib.listToAttrs ( - map (n: { - name = "nixbld${toString n}"; - value = { - uid = 30000 + n; - gid = 30000; - groups = [ "nixbld" ]; - description = "Nix build user ${toString n}"; - }; - }) (lib.lists.range 1 32) - ); + }) (lib.lists.range 1 32) + ); groups = { root.gid = 0; @@ -361,7 +360,8 @@ let "org.opencontainers.image.version" = pkgs.nix.version; "org.opencontainers.image.description" = "Minimal Lix container image, with some batteries included."; - } // lib.optionalAttrs (lixRevision != null) { "org.opencontainers.image.revision" = lixRevision; }; + } + // lib.optionalAttrs (lixRevision != null) { "org.opencontainers.image.revision" = lixRevision; }; }; meta = { diff --git a/flake.lock b/flake.lock index 2e6701d2b..848ce9d57 100644 --- a/flake.lock +++ b/flake.lock @@ -108,11 +108,11 @@ }, "nixpkgs_2": { "locked": { - "lastModified": 1749522908, - "narHash": "sha256-eWANkhWXFL1MmaxzsZ9bhLCNT8OVs7CC+OXaSDGlA8A=", + "lastModified": 1757198069, + "narHash": "sha256-m3VUcOD4rTs8J7S+3dOjWMrAjw6RcITC3XYQ98zhEFs=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "e5cb99555c45a13dcc5f1317462238530b0066b7", + "rev": "0747026fc57ecb9c28901c7f7a2b5dc40e8af43c", "type": "github" }, "original": { diff --git a/flake.nix b/flake.nix index a73399a8d..62cca4dd3 100644 --- a/flake.nix +++ b/flake.nix @@ -171,8 +171,13 @@ { nixStable = prev.nix; - # Nix 2.18 has been removed from Nixpkgs ≥ 25.05, so we need to reintroduce it ourselves for our tests. nixVersions = prev.nixVersions // { + nix_2_3 = prev.nixVersions.nix_2_3.overrideAttrs (old: { + meta = old.meta // { + knownVulnerabilities = [ ]; + }; + }); + # Nix 2.18 has been removed from Nixpkgs ≥ 25.05, so we need to reintroduce it ourselves for our tests. nix_2_18 = nix_2_18.outputs.packages.${currentStdenv.hostPlatform.system}.default; }; @@ -366,15 +371,16 @@ in pkgs.symlinkJoin { name = "nixpkgs-lib-tests"; - paths = - [ testWithNix ] - # NOTE: nixpkgs 25.05 is being ... *creative*, and requires this dance to override - # the evaluator used for the test. it will break again in the future, don't worry. - ++ lib.optionals pkgs.stdenv.isLinux [ - ((pkgs.callPackage "${nixpkgs}/ci/eval" { nixVersions.latest = nix; }).attrpathsSuperset { - evalSystem = system; - }) - ]; + paths = [ + testWithNix + ] + # NOTE: nixpkgs 25.05 is being ... *creative*, and requires this dance to override + # the evaluator used for the test. it will break again in the future, don't worry. + ++ lib.optionals pkgs.stdenv.isLinux [ + ((pkgs.callPackage "${nixpkgs}/ci/eval" { inherit nix; }).attrpathsSuperset { + evalSystem = system; + }) + ]; } ); */ diff --git a/misc/capnproto.nix b/misc/capnproto.nix index 4d09a2892..a3f807dc0 100644 --- a/misc/capnproto.nix +++ b/misc/capnproto.nix @@ -39,7 +39,8 @@ stdenv.mkDerivation rec { propagatedBuildInputs = [ openssl zlib - ] ++ lib.optional (stdenv.cc.isClang && stdenv.targetPlatform.isStatic) empty-libgcc_eh; + ] + ++ lib.optional (stdenv.cc.isClang && stdenv.targetPlatform.isStatic) empty-libgcc_eh; # FIXME: separate the binaries from the stuff that user systems actually use # This runs into a terrible UX issue in Lix and I just don't want to debug it diff --git a/package.nix b/package.nix index 211a44cae..998a51865 100644 --- a/package.nix +++ b/package.nix @@ -200,12 +200,13 @@ stdenv.mkDerivation (finalAttrs: { ); }; - outputs = - [ "out" ] - ++ lib.optionals (!finalAttrs.dontBuild) [ - "dev" - "doc" - ]; + outputs = [ + "out" + ] + ++ lib.optionals (!finalAttrs.dontBuild) [ + "dev" + "doc" + ]; dontBuild = lintInsteadOfBuild; @@ -241,81 +242,79 @@ stdenv.mkDerivation (finalAttrs: { # We only include CMake so that Meson can locate toml11, which only ships CMake dependency metadata. dontUseCmakeConfigure = true; - nativeBuildInputs = - [ - # python3.withPackages does not splice properly, see https://github.com/NixOS/nixpkgs/issues/305858 - (python3.pythonOnBuildForHost.withPackages (p: [ - p.pytest - p.pytest-xdist - p.python-frontmatter - ])) - meson - ninja - cmake - rustc - capnproto-lix - ] - ++ [ - (lib.getBin lowdown-unsandboxed) - mdbook - mdbook-linkcheck - ] - ++ [ - pkg-config + nativeBuildInputs = [ + # python3.withPackages does not splice properly, see https://github.com/NixOS/nixpkgs/issues/305858 + (python3.pythonOnBuildForHost.withPackages (p: [ + p.pytest + p.pytest-xdist + p.python-frontmatter + ])) + meson + ninja + cmake + rustc + capnproto-lix + ] + ++ [ + (lib.getBin lowdown-unsandboxed) + mdbook + mdbook-linkcheck + ] + ++ [ + pkg-config - # Tests - git - mercurial - jq - lsof - ] - ++ lib.optional hostPlatform.isLinux util-linuxMinimal - ++ lib.optional (!officialRelease && buildUnreleasedNotes) build-release-notes - ++ lib.optional internalApiDocs doxygen - ++ lib.optionals lintInsteadOfBuild [ - # required for a wrapped clang-tidy - llvmPackages.clang-tools - # load-bearing order (just as below); the actual stdenv wrapped clang - # needs to precede the unwrapped clang in PATH such that calling `clang` - # can compile things. - stdenv.cc - # required for run-clang-tidy - llvmPackages.clang-unwrapped - ]; + # Tests + git + mercurial + jq + lsof + ] + ++ lib.optional hostPlatform.isLinux util-linuxMinimal + ++ lib.optional (!officialRelease && buildUnreleasedNotes) build-release-notes + ++ lib.optional internalApiDocs doxygen + ++ lib.optionals lintInsteadOfBuild [ + # required for a wrapped clang-tidy + llvmPackages.clang-tools + # load-bearing order (just as below); the actual stdenv wrapped clang + # needs to precede the unwrapped clang in PATH such that calling `clang` + # can compile things. + stdenv.cc + # required for run-clang-tidy + llvmPackages.clang-unwrapped + ]; - buildInputs = - [ - curl - bzip2 - xz - brotli - editline-lix - openssl - sqlite - libarchive - boost - lowdown - libsodium - toml11 - pegtl - capnproto-lix - ] - ++ lib.optionals hostPlatform.isLinux [ - libseccomp - busybox-sandbox-shell - passt-lix - ] - ++ lib.optionals ( - stdenv.hostPlatform.isDarwin && lib.versionOlder stdenv.hostPlatform.darwinSdkVersion "11.0" - ) [ apple-sdk_11 ] - ++ lib.optional internalApiDocs rapidcheck - ++ lib.optional hostPlatform.isx86_64 libcpuid - # There have been issues building these dependencies - ++ lib.optional (hostPlatform.canExecute buildPlatform) aws-sdk-cpp-nix - ++ lib.optionals (finalAttrs.dontBuild) maybePropagatedInputs - # I am so sorry. This is because checkInputs are required to pass - # configure, but we don't actually want to *run* the checks here. - ++ lib.optionals lintInsteadOfBuild finalAttrs.checkInputs; + buildInputs = [ + curl + bzip2 + xz + brotli + editline-lix + openssl + sqlite + libarchive + boost + lowdown + libsodium + toml11 + pegtl + capnproto-lix + ] + ++ lib.optionals hostPlatform.isLinux [ + libseccomp + busybox-sandbox-shell + passt-lix + ] + ++ lib.optionals ( + stdenv.hostPlatform.isDarwin && lib.versionOlder stdenv.hostPlatform.darwinSdkVersion "11.0" + ) [ apple-sdk_11 ] + ++ lib.optional internalApiDocs rapidcheck + ++ lib.optional hostPlatform.isx86_64 libcpuid + # There have been issues building these dependencies + ++ lib.optional (hostPlatform.canExecute buildPlatform) aws-sdk-cpp-nix + ++ lib.optionals (finalAttrs.dontBuild) maybePropagatedInputs + # I am so sorry. This is because checkInputs are required to pass + # configure, but we don't actually want to *run* the checks here. + ++ lib.optionals lintInsteadOfBuild finalAttrs.checkInputs; checkInputs = [ gtest diff --git a/perl/default.nix b/perl/default.nix index ed2584c7f..20ecc162c 100644 --- a/perl/default.nix +++ b/perl/default.nix @@ -35,19 +35,18 @@ perl.pkgs.toPerlModule ( ninja ]; - buildInputs = - [ - nix - curl - bzip2 - xz - perl - boost - perlPackages.DBI - perlPackages.DBDSQLite - ] - ++ lib.optional (stdenv.isLinux || stdenv.isDarwin) libsodium - ++ lib.optional stdenv.isDarwin darwin.apple_sdk.frameworks.Security; + buildInputs = [ + nix + curl + bzip2 + xz + perl + boost + perlPackages.DBI + perlPackages.DBDSQLite + ] + ++ lib.optional (stdenv.isLinux || stdenv.isDarwin) libsodium + ++ lib.optional stdenv.isDarwin darwin.apple_sdk.frameworks.Security; # Nixpkgs' Meson hook likes to set this to "plain". mesonBuildType = "debugoptimized"; diff --git a/tests/nixos/remote-builds-ssh-ng.nix b/tests/nixos/remote-builds-ssh-ng.nix index ec12f9066..ba757312f 100644 --- a/tests/nixos/remote-builds-ssh-ng.nix +++ b/tests/nixos/remote-builds-ssh-ng.nix @@ -48,6 +48,7 @@ in imports = [ test.config.builders.config ]; services.openssh.enable = true; virtualisation.writableStore = true; + virtualisation.additionalPaths = [ config.system.build.extraUtils ]; nix.settings.sandbox = true; nix.settings.substituters = lib.mkForce [ ]; };