Commit Graph
18309 Commits
Author SHA1 Message Date
Maximilian Bosch 2175d007e5 libstore/path-tree: allow passing a custom accessor
If none is given, we fall back to whatever accessor we get from the
store.

To display which paths actually contain the references leading to
e.g. a cycle or triggering a disallowedRequisites error, we'd
potentially have to look into the chroot from the previously finished
build. This behavior should not be part of the local accessor by
default, but part of a "special" accessor. This change allows using such
an accessor for `genGraphString()`.

Now that we inject the accessor from the outside, we have to mock it
anyways in the tests. Hence, this also adds a testcase for the
precise=True case.

Change-Id: I58465fb944776c2b0262ba054d1f296ed2ae3406
2025-08-23 18:36:49 +02:00
Maximilian Bosch 312e90f4b6 tests: add small testcase for output cycle detection
Change-Id: I186937dfbca4d051e5ad860239720816429a0a8e
2025-08-23 16:23:35 +02:00
Maximilian Bosch f7871fcb57 libutil/topo-sort: return std::variant<std::vector<T>, Cycle>
The variant has on the left-hand side the topologically sorted vector
and the right-hand side is a pair showing the path and its parent that
represent a cycle in the graph making the sort impossible.

The goal is to implement #551 which needs to throw an error if the
topo-sort fails. However, the error-message is supposed to contain a
graph of store-paths and the API to generate this is inherently async.

Now, catching the exception and re-throwing another one is impossible
since `co_await` is forbidden in `catch`-blocks and adding another
topoSort variant that allows an async `makeError` also seems odd. Hence,
I decided to alter the data-structure in use a bit for this use-case.
One out of two uses of the function are affected after all.

Change-Id: I70a987f470437df8beb3b1cc203ff88701d0aa1b
2025-08-23 16:23:35 +02:00
eldritch horrors be438c62e1 nix/eval: remove --write-to
it's broken, can write arbitrary file paths when run as root, and only
supports strings and recursive sets of strings. this was only used for
manpage generation in a build system that has not woken up since 1976.

fixes #974
fixes #227

Change-Id: I4f18599685a3077c15ddc02c759558f986c8c6e4
2025-08-23 10:39:30 +00:00
Alois Wohlschlager 0f50bc452e libutil: make backoffTimeouts inline
Commit 5dc847b47b introduced it as a non-inline
function with definition in the header, which can result in linker errors like
the following:

    /build/source/build/lix/libutil/backoff.hh:36: multiple definition of `nix::backoffTimeouts(unsigned int, std::chrono::duration<long, std::ratio<1l, 1000l> >, std::chrono::duration<long, std::ratio<1l, 1000l> >, std::chrono::duration<long, std::ratio<1l, 1000l> >)'; tests/unit/liblixutil-tests.p/libutil_backoff.cc.o:/nix/store/eeeeeeeeeeeeeeeeeeeeeeeeeeeeeeee-gtest-static-x86_64-unknown-linux-musl-1.17.0-dev/include/gtest/gtest-printers.h:1223: first defined here

This error was observed during trying to bump `lixPackageSets.git` in nixpkgs.
I am not sure why it can't be observed in the in-tree `nixStatic` package but
the definition is wrong in any case.

Change-Id: I6a6a6964e218a03ca2a2e8eddbb72d44e06e904e
2025-08-23 11:23:15 +02:00
Maximilian Bosch 5dc847b47b libstore: exponential backoff for downloads
Closes #932

`connect-timeout` gets replaced by an exponential backoff for the
download timeout where the initial value is controlled by the setting
`initial-connect-timeout`.

Per iteration, the upper limit of the timeout is increased set to

    timeout := min(max_connect_timeout, initial_connect_timeout * 2^i)

I decided to move the entire timeout / tracking of attempts into its own
class to not make the filetransfer implementation more complex. Also,
that allows us to write unit-tests for it.

Setting `--download-attempts` to `0` is forbidden now and an exception
will be thrown. For `--offline` we set it to `1`, the behavior is
equivalent to what it was before: whether the max tries were exceeded is
only checked after the first download exception got thrown, i.e. there's
still one attempt being made.

The end-result - with timeouts being caused by a wrongly set proxy -
looks like this:

    $ env HTTPS_PROXY=1.1.1.1 nix store ping --store https://example.com
    warning: error: unable to download 'https://example.com/nix-cache-info': Connection timed out after 5006 milliseconds (curl error code=28); retrying in 422ms ms (attempt 1/5)
    warning: error: unable to download 'https://example.com/nix-cache-info': Connection timed out after 10010 milliseconds (curl error code=28); retrying in 1003ms ms (attempt 2/5)
    warning: error: unable to download 'https://example.com/nix-cache-info': Connection timed out after 20020 milliseconds (curl error code=28); retrying in 2018ms ms (attempt 3/5)
    warning: error: unable to download 'https://example.com/nix-cache-info': Connection timed out after 40007 milliseconds (curl error code=28); retrying in 4087ms ms (attempt 4/5)
    error: unable to download 'https://example.com/nix-cache-info': Connection timed out after 80074 milliseconds (curl error code=28)

Change-Id: I9e8d08d78275bcf60080d663febc9e075243d36b
2025-08-22 16:19:46 +02:00
Commentator2.0andCommentator2.0 7553d0a983 tests/functional2/lang: don't throw unused file errors on invalid configurations
Currenlty, when a test group is invalid already, we also throw unsued
file errors.
This leads to clutter as more often than not, the unused files are
caused by an invalid configuration, making the debug stack bigger
without reason.

With this commit the behavior is changed to only error about unused
files, when no other configuration issues were found

Change-Id: I92a819753f13b8ed5a07dae53ecaee5d84b5ce64
2025-08-22 07:50:20 +02:00
Commentator2.0andCommentator2.0 0a3e43590c tests/functional2: improve files ux
Currenlty one is required to always write the bulky `mark.parametrize`
with indirect and things

This commit adds a custom decorator for usage of files, which hides the
parametrization complexity from the user.

Change-Id: I526e016d12006669dc302dfc5af619735399c503
2025-08-22 07:50:20 +02:00
Jade Lovelace a84355a813 perl: passthru perl
Required for compat with CppNix derivation.

Fixes: https://git.lix.systems/lix-project/lix/issues/971
Change-Id: I6c38545b7a34b22843fc9acfbb042259cd824d84
2025-08-22 01:51:47 +00:00
Raito Bezarius ac9721a92e Revert "libutil: add makeTempSiblingPath helper"
Revert submission 3850

Reason for revert: caused multiple regressions noticed in https://git.lix.systems/lix-project/lix/issues/975 and https://git.lix.systems/lix-project/lix/issues/966 (suspected).

Root cause analysis has not been done yet and this breaks Lix on Darwin on HEAD.

Reverted changes: /q/submissionid:3850

Change-Id: Ifc8ccc212ec73f51958b20c9419c81d723f87b0d
2025-08-21 14:37:46 +00:00
Raito Bezarius 1fdaa6888a Revert "libstore: use makeTempSiblingPath in replaceValidPath"
Revert submission 3850

Reason for revert: caused multiple regressions noticed in https://git.lix.systems/lix-project/lix/issues/975 and https://git.lix.systems/lix-project/lix/issues/966 (suspected).

Root cause analysis has not been done yet and this breaks Lix on Darwin on HEAD.

Reverted changes: /q/submissionid:3850

Change-Id: I23f659664bcb1f38ea8cd053279d3275f33e001c
2025-08-21 14:37:46 +00:00
Raito Bezarius 7622d28dd4 Revert "libutil: extract Base32 helpers from Hash"
Revert submission 3850

Reason for revert: caused multiple regressions noticed in https://git.lix.systems/lix-project/lix/issues/975 and https://git.lix.systems/lix-project/lix/issues/966 (suspected).

Root cause analysis has not been done yet and this breaks Lix on Darwin on HEAD.

Reverted changes: /q/submissionid:3850

Change-Id: I2dae7147030c883a57be8a8c205e492e16425a23
2025-08-21 14:37:46 +00:00
Raito Bezarius 28bcc7fb24 Revert "libutil: use OS‐provided entropy for temporary filenames"
Revert submission 3850

Reason for revert: caused multiple regressions noticed in https://git.lix.systems/lix-project/lix/issues/975 and https://git.lix.systems/lix-project/lix/issues/966 (suspected).

Root cause analysis has not been done yet and this breaks Lix on Darwin on HEAD.

Reverted changes: /q/submissionid:3850

Change-Id: Icdbb89bbf031581250fbda3c9ab9095e7af10ec1
2025-08-21 14:37:46 +00:00
Raito Bezarius 7c03f42759 Revert "libstore: simplify makeTemp{,Sibling}Path callers"
Revert submission 3850

Reason for revert: caused multiple regressions noticed in https://git.lix.systems/lix-project/lix/issues/975 and https://git.lix.systems/lix-project/lix/issues/966 (suspected).

Root cause analysis has not been done yet and this breaks Lix on Darwin on HEAD.

Reverted changes: /q/submissionid:3850

Change-Id: I410046be0ed84e84d1530748d29383489e36c72c
2025-08-21 14:37:46 +00:00
Raito Bezarius ca3328dac0 Revert "libstore: use makeTemp{,Sibling}Path more"
Revert submission 3850

Reason for revert: caused multiple regressions noticed in https://git.lix.systems/lix-project/lix/issues/975 and https://git.lix.systems/lix-project/lix/issues/966 (suspected).

Root cause analysis has not been done yet and this breaks Lix on Darwin on HEAD.

Reverted changes: /q/submissionid:3850

Change-Id: I22a7e48239783bfee53734f65d4e723a7690c3f5
2025-08-21 14:37:46 +00:00
Raito Bezarius 805aeffece Revert "libstore: simplify fallback build directory logic"
Revert submission 3850

Reason for revert: caused multiple regressions noticed in https://git.lix.systems/lix-project/lix/issues/975 and https://git.lix.systems/lix-project/lix/issues/966 (suspected).

Root cause analysis has not been done yet and this breaks Lix on Darwin on HEAD.

Reverted changes: /q/submissionid:3850

Change-Id: Id6db066f3f5c454b258157bc12e0f26020de94a7
2025-08-21 14:37:46 +00:00
Raito Bezarius bde4a50740 Revert "libutil: use makeTempPath in createTempSubdir"
Revert submission 3850

Reason for revert: caused multiple regressions noticed in https://git.lix.systems/lix-project/lix/issues/975 and https://git.lix.systems/lix-project/lix/issues/966 (suspected).

Root cause analysis has not been done yet and this breaks Lix on Darwin on HEAD.

Reverted changes: /q/submissionid:3850

Change-Id: I22d2c315bd8b1eed536c08f2d5b368331907f994
2025-08-21 14:37:46 +00:00
Raito Bezarius e3ff4e0365 Revert "libstore: simplify createTempDir interface"
Revert submission 3850

Reason for revert: caused multiple regressions noticed in https://git.lix.systems/lix-project/lix/issues/975 and https://git.lix.systems/lix-project/lix/issues/966 (suspected).

Root cause analysis has not been done yet and this breaks Lix on Darwin on HEAD.

Reverted changes: /q/submissionid:3850

Change-Id: I76930bdc1fb51edb5b0c591272ecb6f69085f197
2025-08-21 14:37:46 +00:00
Raito Bezarius e7253d0621 Revert "libstore: make temporary path prefixes optional"
Revert submission 3850

Reason for revert: caused multiple regressions noticed in https://git.lix.systems/lix-project/lix/issues/975 and https://git.lix.systems/lix-project/lix/issues/966 (suspected).

Root cause analysis has not been done yet and this breaks Lix on Darwin on HEAD.

Reverted changes: /q/submissionid:3850

Change-Id: Ib4d3179cbfa8e9f861d7416fe08f7d7e3a7d55e2
2025-08-21 14:37:46 +00:00
Raito Bezarius c9cbbc4f63 Revert "tests: remove obsolete code to create custom build direc..."
Revert submission 3850

Reason for revert: caused multiple regressions noticed in https://git.lix.systems/lix-project/lix/issues/975 and https://git.lix.systems/lix-project/lix/issues/966 (suspected).

Root cause analysis has not been done yet and this breaks Lix on Darwin on HEAD.

Reverted changes: /q/submissionid:3850

Change-Id: I56f871786760eb9f54c02773f0617de9878c1382
2025-08-21 14:37:46 +00:00
Raito Bezarius 9cabe56fcd Revert "libstore: don’t include derivation names in build direct..."
Revert submission 3850

Reason for revert: caused multiple regressions noticed in https://git.lix.systems/lix-project/lix/issues/975 and https://git.lix.systems/lix-project/lix/issues/966 (suspected).

Root cause analysis has not been done yet and this breaks Lix on Darwin on HEAD.

Reverted changes: /q/submissionid:3850

Change-Id: Iee4c3f071238fa58e0e92f0bcc5584ded4a9d71f
2025-08-21 14:37:46 +00:00
Jade Lovelace 61955d0a40 libexpr: hyperlink attr names to their definition locations
Concept: what if you could, in your fancy terminal, in the year of our
lord 2025, just click on the attrs you're looking at to go to where
they're defined. Currently we only expose this info as
builtins.unsafeGetAttrPos, which is inconvenient as it's not
discoverable to users.

By putting it in this more visible yet invisible spot, it's more likely
to be more useful to more people.

In the current state, this is not the most useful ever due to stuff like
https://github.com/neovim/neovim/discussions/35097. However, it can be
expanded by perhaps adding something like the url format setting ripgrep
has.

Change-Id: I3947f97d5c2056d59099af468d7b855486438227
2025-08-20 20:55:54 +00:00
Alois Wohlschlager c82af241f5 packaging: fix static build
Normally `pkgsStatic` adds ` -static` to `NIX_CFLAGS_COMPILE`. Due to a bug
this did not apply with `__structuredAttrs`. As the fix [1] has not been
backported yet, put it in the package manually.

[1] https://github.com/NixOS/nixpkgs/pull/428430

Fixes: https://git.lix.systems/lix-project/lix/issues/962

Change-Id: I6a6a6964c6a33f486ba3df3be16f715ad1b060c3
2025-08-20 18:31:52 +02:00
Alois Wohlschlager 010dae39d3 capnproto: fix platform offset
Backport of https://github.com/NixOS/nixpkgs/commit/8b0263aba578e2fa611a528bedcfc5cf4d5a687c .

Change-Id: I6a6a6964917df3610cd728c696ecdcd8ea6e61a4
2025-08-20 18:25:57 +02:00
eldritch horrors 001c70d2ba libstore: mark all non-local stores as thread-unsafe
this pretty much only impacts store verification via the nix3 cli. no
other thread pools are left, and the verification pool may *actually*
be important for throughput since verification involves much hashing.

Change-Id: I32152e6169a82a1268a790e333f21a0430ede7f4
2025-08-19 13:08:53 +00:00
eldritch horrors 3cecd2306b nix/sigs: remove sign pool
signing is very cheap, it's only the store access that is expensive.
http binary caches parallelize async accesses extremely well though.

Change-Id: Ifdbf398bd328ba16ec4e8caba3f5f99a6cf3e046
2025-08-19 13:08:53 +00:00
eldritch horrors d63edddeb0 libstore: remove debug info upload pool
Change-Id: Ife5f69ddaeb82f002f4dfe05347fe700d201df72
2025-08-19 13:08:53 +00:00
eldritch horrors 13509ef773 libstore: rewrite debug info upload with generators
Change-Id: I1b0424c3b8aed5a90d1ca3d61b11cc5a1bf92cf0
2025-08-19 13:08:53 +00:00
eldritch horrors c917f4ec78 nix/sigs: remove CopySigs thread pool
we don't have benchmarks for this one, but a 10x improvement seems likely.

Change-Id: I76f4e9c9ebff86fd7d451ed7e125ab309011457e
2025-08-19 13:08:53 +00:00
eldritch horrors 20f84eb6bf libstore: remove queryValidPaths thread pool
this is used by nix-env and copyPaths, which in turn is used to upload
to binary caches. for a large path set we have seen 10x a improvement.

Change-Id: Ieadd0e66180e5ceecefaf944a5bb2f0523374954
2025-08-19 13:08:53 +00:00
eldritch horrors 5fc6ab2e50 libutil: make generator iterators adl-visible
lets us use generators in algorithms that use adl iterator access

Change-Id: I05b06f070e370ef21c693e61979d07d9b7206a9f
2025-08-19 13:08:53 +00:00
eldritch horrors 5a30005e2f libutil: remove unused runAsyncInNewThread
Change-Id: I55d161201737fc6b7dbfb0a387b253939dfe5784
2025-08-19 13:08:53 +00:00
sternenseemann e339480592 Test build with lowdown < 1.4 in CI
Change-Id: I486dec6f2d91580d21712c1f4f18462aa02473b3
2025-08-19 10:45:40 +00:00
Commentator2.0 d8b1fb7799 tests/functional2/lang: replace toml with tomllib
currenlty we use the external package `toml`, this just adds an
unnessecary dependency, as python ships its own toml as `tomllib`

Change-Id: Ia63fa7558973e853ada20cbfa21d897d700444f8
2025-08-18 20:08:09 +02:00
WeetHet 1f47ecef4e libstore/build: adjust setupConfiguredCertificateAuthority
Always use tmpDir on darwin. Call setupConfiguredCertificateAuthority even if useChroot = 1 on non-linux.
Even though macOS builds are not executed in a chroot, enabling the sandbox
sets `useChroot = 1`. Basically, useChroot is set when the sandbox is enabled,
not really when a chroot build is executed

Change-Id: I8d4c1e617abcc05dfabd998a8ce94bb11587f9d1
2025-08-18 13:08:42 +00:00
Emily ce6dcf18d6 libstore: don’t include derivation names in build directories
They have variable size, which is bad for #913.

Change-Id: I6a6a6964a84804dee281ade48e6517419a6143fa
2025-08-18 09:27:31 +00:00
Emily 246f0eed82 tests: remove obsolete code to create custom build directories
We now do in fact do this and decide this.

Change-Id: I6a6a69643af2449370df001f8be787eba889b857
2025-08-18 09:27:31 +00:00
Emily 6aedc0ee70 libstore: make temporary path prefixes optional
This is not the same thing as passing an empty string, because it
avoids the `-` separator.

Change-Id: I6a6a69646aa76953078a08c606e8f82c9ec03e8e
2025-08-18 09:27:31 +00:00
Emily 0173d0dde4 libstore: simplify createTempDir interface
We always use the default temporary directory, because
`createUniqueDir` has an interface nice enough to use directly for
the few bespoke uses.

Change-Id: I6a6a6964c15c31bb3e131fbe1db1837987a6d6dc
2025-08-18 09:27:31 +00:00
Emily 2a17164865 libutil: use makeTempPath in createTempSubdir
This makes the paths more nondeterministic, but more reliably unique,
and lets us remove the retry loop.

Note that this adds random entropy to the build directory visible
inside derivations on Darwin and unsandboxed Linux. It was already
non‐deterministic in the presence of concurrent builds and similar,
but now we can reliably expect it to be different every time. On the
whole I think that’s a good thing, as it is impossible to ensure
a single consistent build directory and derivation outputs should
not depend on it.

Package reproducibility isn’t great on Darwin to begin with,
though, and the reproducibility bugs this will turn up in packages
will be more urgent to fix than when the build directory was mostly
consistent. A quick survey of my local store shows that many C, C++,
and Rust binaries contain build directory references, likely due to
use of `__FILE__` and its equivalents; non‐binary offenders include:

* Install logs included in the Rust and Cargo bootstrap compilers
* Example errors in the Rust documentation referencing build paths
* Configuration information installed with CPython itself
* Python 2 metadata from resholve’s closure
* Cython metadata
* Generated headers in Facebook libraries referencing source paths
* Generated CMake files in Facebook libraries referencing source paths

I haven’t built that much in this store since the last GC, so this is
probably only a small sample of the problems across the tree. These are
all instances of <https://reproducible-builds.org/docs/build-path/>,
though, and should probably just be treated as general reproducibility
bugs outside of contexts like the Linux sandbox where we can normalize
them away entirely.

I have implemented away build directory paths for C/C++, applied some
additional fixes for non‐`__FILE__`‐related issues in binaries
from ATF and LLVM, and fixed the derivation bug causing the CPython
3 issue, and will work on upstreaming these changes. Rust is working
on the problem upstream, with some temporary workarounds we can
potentially apply in Nixpkgs for now. The rest will require some
distributed effort.

Change-Id: I6a6a69648f74d85c6fca86cc52f38fd957e4f9ad
2025-08-18 09:27:31 +00:00
Emily 267d9e100c libstore: simplify fallback build directory logic
This does change the behaviour when the global temporary directory
does not exist, but other uses of the global temporary directory are
already broken in that circumstance, and it should be fixed centrally
if the use case is considered desirable. The logic was not present
before the recent churn around build directories – it was added now
that Lix is taking ownership of the build directory in the store –
so this should not be a meaningful regression.

Change-Id: I6a6a69648054ae201b3ce36d11e49c93793fdb0e
2025-08-18 09:27:31 +00:00
Emily cad304420f libstore: use makeTemp{,Sibling}Path more
Change-Id: I6a6a69641f9c9d3ab339d25d061dad6cd1f8416d
2025-08-18 09:27:31 +00:00
Emily 24ccf500d1 libstore: simplify makeTemp{,Sibling}Path callers
There is now no risk of race conditions on a system with a functioning
entropy source, and the bespoke prefixes are either redundant to the
default or unnecessary.

Change-Id: I6a6a69648a3b8060333e97269ea8b72499614559
2025-08-18 09:27:31 +00:00
Emily 03beb9a1d3 libutil: use OS‐provided entropy for temporary filenames
Relax the constraints on keeping the exact same filename format to
provide a more robust source of entropy with a simpler interface
(as previously suggested by eldritch horrors). Using 128 bits of
OS‐provided entropy ensures global uniqueness and allows us to
skip any thought of gracefully handling the case where these files
already exist.

My microbenchmark that repeatedly constructed paths like this and
printed them out showed that this takes about 1.23× the time of
the previous implementation, both taking on the order of a couple
microseconds for one iteration. Since everything that uses it is doing
things more expensive than printing to standard output, the actual
performance delta is likely to be lost in the noise. If it somehow
becomes a bottleneck, it can be optimized without sacrificing the
guarantees by reading from the system RNG only to seed a thread‐local
CSPRNG like [ChaCha8Rand], but I think that’s very unlikely.

We also tweak the recommended way of creating a temporary file inside
a directory in anticipation of later changes, and rename the `suffix`
parameter to `prefix` (it’s a prefix to the random characters and
a suffix to the root, but this way is more consistent).

[ChaCha8Rand]: https://c2sp.org/chacha8rand

Change-Id: I5bd7badf1392243f485935c4a016c1f833cb16d3
2025-08-18 09:27:31 +00:00
Emily 76baa4c50d libutil: extract Base32 helpers from Hash
Change-Id: I6a6a6964f95aecf152090a3bf82b5ec287a21481
2025-08-18 09:27:31 +00:00
Emily a42cb1c43d libstore: use makeTempSiblingPath in replaceValidPath
Change-Id: I6a6a69643732c1bb4942425ae1f179a411412fd5
2025-08-18 09:27:31 +00:00
Emily e2d85579d8 libutil: add makeTempSiblingPath helper
The prospective callers of this should probably be doing something
smarter or more abstracted to begin with, but this is useful as an
incremental improvement for call sites with existing `makeTempPath`
logic in the face of filename length limits.

Change-Id: I6a6a6964374f47abbf0ec10aa8d945c4e50a43af
2025-08-18 09:27:31 +00:00
eldritch horrors 3de996f521 libexpr: stringviewify some more APIs
notably this also includes the symbol table because it stores real
strings that are referenced by eval values, and an upcoming change
will make it impossible to share those strings with value strings.

Change-Id: I20a3644db8aa0850efe29630e0b73d424cb2aa56
2025-08-17 14:55:13 +02:00
eldritch horrors 8208c6ebb7 libexpr: don't read Value::string.s directly
Change-Id: I0f224459fcbff8bc53c3668bc6ea52881c453fd0
2025-08-17 12:11:19 +00:00
Emily 27f7075f4d libexpr: remove the parse-toml-timestamps experimental feature
See [my comment] on the Nix PR to restore the previous behaviour
for why I believe we should remove this for the next release. The PR
should still be backported to stable releases to avoid making breaking
changes to their semantics.

[my comment]: <https://github.com/NixOS/nix/pull/13741#issuecomment-3180851635>

Fixing this across supported Lix versions is required for Nixpkgs to
update toml11, which is a blocker for the CMake 4 update.

Change-Id: I6a6a69642e6b6cb13a9fccc0778e9158b53102d5
2025-08-16 14:27:13 +01:00