Commit Graph
18934 Commits
Author SHA1 Message Date
eldritch horrors c6931c4176 testing: migrate flakes/circular.sh
Change-Id: Ia9eb3631278957c449dd8791e9cf02cb47705a63
2026-02-17 13:53:26 +01:00
eldritch horrors 04988fa318 f2: add git and git_cmd fixtures for calling git
Change-Id: Icdc03c76164d0db503a2f6c90f2bcb2377d9ced5
2026-02-17 13:53:26 +01:00
eldritch horrors f31ece23da testing: migrate flakes/run.sh
Change-Id: Id953cd257c3831d67531ffa4a131607519361227
2026-02-17 13:53:25 +01:00
Max Siling f1ce35f53c libfetchers: produce a proper error when both ref and rev are set
Affects `github`, `gitlab` and `sourcehut` fetchers.
Previously this was an assertion, which crashed the evaluator
with SIGABRT.

Fixes: #1133
Change-Id: Ia9bb8dd29ac8b9c97bf048827f62c5076a6a6964
2026-02-16 14:25:40 +03:00
eldritch horrors 9520e663c8 libstore: send all changed settings to builtin-builder
this includes logger verbosity, which isn't a setting for some reason.

fixes #1111

Change-Id: Ib078205b41069628010273645e26baf33b1c6d14
2026-02-12 18:00:33 +00:00
eldritch horrors 6e3a7711ca libutil: allow retrieving all *changed* settings too
overridden-ness can be reset, and is usually reset such that setting
value taken from a config file are not considered as overriden. when
launching builtin builders we *do* want to send config file settings
changes to the builder, so we'll need one more getter method for it.

Change-Id: I861538a469121c77ebc1898a276439e6b756797d
2026-02-12 18:24:25 +01:00
eldritch horrors 9723dc2c89 testing: migrate nix-profile.sh test
Change-Id: Id7b4b1c36943123c9d5f538b05cd67408c1cb269
2026-02-11 20:46:18 +00:00
eldritch horrors bffbe73493 f2: remove unused build arguments
they're no longer used since non-diverted stores are the default now.

Change-Id: I277b819340c2b69e1fd06607e562221469b77926
2026-02-11 20:46:18 +00:00
eldritch horrors b34f136f10 f2: don't use diverted stores unless specifically requested
diverted stores are only necessary when the logical store paths of
objects matter for the test itself, such as for derivation hashes,
substitution from golden sample nars, or actual tests of the store
diversion functionality. all other tests can use undiverted stores
to run, especially since only linux can build in diverted a store.

Change-Id: I62f0907bdef9961609af22b610195fcec54c1e57
2026-02-11 20:46:18 +00:00
Raito Bezariusandeldritch horrors 505d0669dc libstore/build: fix starvation during substitution
When the destructor of PathSubstitutionGoal is run, this happens in a
sync context and can cause starvation of all ongoing IO w.r.t. to other
substitutions, including our own substitution.

While there's only a decompressor thread per stream, the other side of
the IO runs on the event loop.

In order to fix this, it is sufficient to remove the thread indirection
and inline the async code.

Fixes #1126. Great thanks to horrors' patience.

Co-authored-by: eldritch horrors <pennae@lix.systems>
Change-Id: I3eb37bc37d156f0f5528364e568fdaa2ced58011
Signed-off-by: Raito Bezarius <raito@lix.systems>
2026-02-11 14:18:00 +00:00
piegames ef2fd27467 deprecated-features/rec-set-dynamic-attrs: Downgrade to warning for now
Looks like too much stuff is breaking on this, so let's make it only a
warning for now to ease transition

Change-Id: I52d50ceb1fe1fbe9f4e28d0aabf3537f7e4d52d1
2026-02-11 12:24:35 +01:00
piegames ae4a000576 deprecated-features/broken-string-escape: Improve warning message
Explicitly catch common errors (trying to escape line breaks, badly
escaping interpolations) to provide better messages and user guidance
for these cases.

Change-Id: I3dd1b2ad3bca33be393e65be5e72f4fb9544a46a
2026-02-11 12:24:35 +01:00
rootile a2c91c000e f2: migrate build-delete.sh
Change-Id: I457620a33514477eccb449d4a6237a5ea43fe73d
2026-02-10 21:36:39 +00:00
rootile 45dfadeafa f2: move multiple-outputs.nix to global assets
Change-Id: I666af75a29727a6ea0c207e016d4723d19cbaa6f
2026-02-10 21:36:30 +00:00
eldritch horrors 51f1294bfc packaging: add asan libraries to closure-info if needed
devshells and asan build may fail to run builtins otherwise

Change-Id: Ia9a909671a00ff03822d9847aa086338a4763e86
2026-02-10 16:03:08 +01:00
eldritch horrors 95ac829cf3 libexec: unlazify launch-builder capnp message reading
StreamFdMessageReader reads message data *lazily*. if you don't access
all segments of the message before you close the underlying stream you
may find yourselv reading from something *very* different, and in this
case that something is The Void™. this causes reads to fail, writes on
the other side to fail to match, and finally our build launch to fail.
this does not lead to happy outcomes, so we will copy the full message
into a fresh new buffer *before* we try to access any of its contents.

fixes #1118

all-analysis-by: deprekated <kate@lix.systems>
Change-Id: I105540831fde855817194e9e539acf177f54a6f4
2026-02-09 17:30:05 +00:00
rootile a99b6f18c8 f2: migrate toString-path.sh
Change-Id: I862f532e94e385aa0f14c03e38e7e003c7bc83c3
2026-02-09 15:37:41 +01:00
rootile f761785099 tests/functional2/nix: refactor NixSettings
This is the long awaited refactor of the NixSettings.
It allows one to set, unset and update any and all settings with a neat
and easy-to-use interface

closes #846

Change-Id: Id4cfb5f853cc1168b506a1f6f405076f3a7cab65
2026-02-09 15:37:40 +01:00
eldritch horrors 2b4f1e076c build-remote: catch exceptions in Instance::build
this was just forgotten when the migration was done.

fixes #1083

Change-Id: I7a94edf304323b0c43e0a1cff39e5a52696c50e3
2026-02-09 11:43:56 +00:00
eldritch horrors 879b07fd3d libstore: treat more substituter failures as recoverable
if a substituter is entirely offline and cannot be queries at all we
should not be failing if other substituters are configured. likewise
if a substituter goes offline after querying but before we try using
it we should attempt to fetch that path from some other substituter.

ideally we'd treat all substituters as a single entity instead of as
one store each, then have that single entity take care of fallbacks,
retries, error reporting, etc. that requires larger rewrites though.

fixes #1061

Change-Id: I9d8fc0544ff380bf017256e8fcc82823dc634f10
2026-02-08 19:14:31 +00:00
eldritch horrors b983c15336 libutil: remove startProcess
it's only used by runProgram2, and runProgram2 can do something much better.

Change-Id: Idba563e1adbe3fd8ce07a0bb8ad4fc1b0cc057b9
2026-02-07 22:34:18 +01:00
eldritch horrors 6063ffead9 libutil: remove unused functions
Change-Id: I2b1c42460de50aff1f742856654c59fc4ce88e04
2026-02-07 20:23:33 +00:00
eldritch horrors 2cc49da1ec libmain: remove explicit std::cerr buffering
we don't use std::cerr often enough to want this, and since cerr flushes
after every operation anyway it never did anything useful to begin with.

Change-Id: Ia54be340826da5073e9a1786c463555f4f0e491c
2026-02-07 20:23:27 +00:00
eldritch horrors 909cbb0e40 libutil: improve runProgram2 log message
include argv0 if needed and program path at all times.

Change-Id: Icc5e28e32334e22f67fd58bd88784d4ddd5e583a
2026-02-07 20:34:49 +01:00
eldritch horrors 684aba046a libstore: *actually* always report launch-builder failures
kj exceptions get wrapped as Error instead of passed through as is.
luckily this also means that we can add context to them very easily

Change-Id: Icedab6c016f4434447dd38ba14138c102fc6149a
2026-02-06 15:55:53 +01:00
eldritch horrors ba4f4f917a libstore: always report launch-builder stderr on setup failures
Change-Id: Iac5d5ffe4df05714554766e591bc331405a8a108
2026-02-04 22:35:50 +00:00
eldritch horrors 8b73cbbb67 libstore: correctly initialize build request union members
oops. we have to use init* here, not get*. get returns a discarding
builder for something that was not inited previously, but the linux
cause worked anyway because the first member is created by default!

Change-Id: I40f8a12a04eef2f4e3a80d1537ac9b975490a027
2026-02-03 21:21:30 +01:00
eldritch horrors aa896041e0 libstore: asyncify build child setup completion wait
Change-Id: Ica70af2a1205830f1ca4bb48f42d09923cff2e58
2026-02-03 14:11:59 +00:00
eldritch horrors ac64c727b5 libstore: move build child launching to libexec
this allows us great flexibility in how children are launched (since the
actual launching is done by a separate executable), makes fork no longer
needed in the core codebase (outside of runProgram, anyway), and we even
get to use linux vfork to its full potential to decrease the launch cost
of sandboxes to a constant factor (previously it was O(#drvs + #deps) of
the build graph, which obviously goes to n² quickly if you are unlucky.)

Change-Id: I66e2d1b20242dc24d708666ef325fb8725bd9296
2026-02-03 14:11:33 +00:00
eldritch horrors 1079fe9884 libutil: kill process groups properly
we can have a ProcessGroup for a pid that *should* be a process group
but hasn't gotten around to setting its pgid yet. in such cases we do
want to be killing the thing anyway, not shoot into the void and hope
the right thing falls over. so far this has not been a problem due to
a mixture of just not having done this and being slow enough to work.

Change-Id: I4e0e54513252d8e18256b9286b819bfa957d70dc
2026-02-03 14:51:01 +01:00
eldritch horrors b8a9eaf1c8 libstore: don't use libutil as much for linux sandox setup
if we move this out of libstore and don't want to pull in all of libutil
with its myriad side effects std::filesystem is our best option, by far.
most notably we don't replace pathExists because std::filesystem::exists
behaves like `stat()` on symlinks, not like the `lstat()` as we require.

Change-Id: I1e488418dcabb33f2ebb73d8c3d1b43528aa51f1
2026-02-03 14:51:00 +01:00
eldritch horrors adf17a7b39 libstore: catch all exceptions in builder setup, not just lix errors
this lets us use std::filesystem and other apis to make builder setup easier.

Change-Id: Ie0303139171161887b610f845e2948fe07c143e0
2026-02-03 00:27:40 +01:00
eldritch horrors 8bd344718b libstore: transfer derivation build setup errors as strings
we will soon not have "proper" lix exceptions to report back any more.

Change-Id: I5061f289bcae64bf26d29cc9d0ec9af61315084e
2026-02-03 00:27:40 +01:00
eldritch horrors e575a3a930 libstore: reformat DarwinLocalDerivationGoal::execBuilder
it'll make diffing later a little bit easier.

Change-Id: I57b62fa0977648cf6948a07c1a103b0e1d6b6624
2026-02-03 00:27:40 +01:00
eldritch horrors 3d77ee8d94 libstore: move macos sandbox config to capnp
Change-Id: I0bc7c60329e0f24e15649c526386ba2466314b18
2026-02-02 19:30:52 +00:00
eldritch horrors 3896e265da libstore: move linux sandbox config to capnp
Change-Id: I3394353ed3f738976132c00973231af70dcffad4
2026-02-02 18:26:57 +01:00
eldritch horrors 0cc9d01ad0 libstore: move tmpDirInSandbox, enable-core-dumps, buildUser into capnp
since we're using tmpDirInSandbox as the working directory for the new
process we also rename it accordingly. buildUser likewise turns into a
different Credentials type because exposing user lock state seems odd.

Change-Id: Id4a1a6eb733f774c893f373b91c2a271a4b84185
2026-02-02 18:26:57 +01:00
eldritch horrors ac7a622b38 libstore: move builder/args/envs to capnp build request struct
Change-Id: If558e5b5ba9b195e31927ca5b5d0c2be743ce3f2
2026-02-02 18:26:56 +01:00
eldritch horrors ced825791a libstore: add capnp build request parameter struct to builders
there's nothing in here yet, we'll add that piece by piece.

Change-Id: Ib276d9e8281bb08013197db0f2bbfd8eec76b5ce
2026-02-02 18:26:56 +01:00
eldritch horrors f09ed729b5 libstore: generate darwin sandbox profile outside of sandbox process
Change-Id: I1a82e1dfa3709e1513d7acbdff50dc594cbc2323
2026-02-02 14:20:54 +00:00
eldritch horrors 9a31cc7da0 libutil, libstore: move closeExtraFDs to derivation goal
it's only used there.

Change-Id: I61ee47d37214c59c073cc9ed671ac1c82430227c
2026-02-02 14:20:54 +00:00
eldritch horrors 52590089df libutil, libstore: move bindPath to libstore linux platform bits
it's only used for linux sandbox setup, and can't be used elsewhere anyway.

Change-Id: I3560e141e5250cf9e72dc1576f87384a8e01f446
2026-02-02 14:20:54 +00:00
eldritch horrors dd54f45bc7 libstore: fix linux sandbox parent death signal handling
setting the signal is not enough, we must also check that the process we
expect to be parent to actually *is* our parent, not another process (eg
init if the daemon exited). we also have to set the death signal *after*
all set[ug]id calls, otherwise it will be cleared again by such changes.

Change-Id: I4e8c9102ea407576ed85b3203c8bb9bfb56762de
2026-02-02 14:20:54 +00:00
eldritch horrors 61e57329eb libstore: inline setupSyscallFilter
it's only used this once, and it accesses a (cached) global variable for
the filter. we want to move all sandbox setup state into a single object
soon, moving filter setup will make it a little bit easier to deal with.

Change-Id: I234d92d5ca044a16644b70bd303bfb7956c120f0
2026-02-02 14:20:54 +00:00
eldritch horrors ab6d8f513b libstore: always unmask all signals when launching build processes
when starting builders we want the inner processes to run with a blank
slate. if some signals are masked for any reason the builder processes
may attempt to send signals to each other that are never delivered; we
avoid this by unmasking all singals. since every build tree also has a
session and process group of its own we are not in danger of sending a
signal to a builder by accident from any source, so unmasking is okay.

Change-Id: I90720ed2bd44502ffb6d2bb848c05369809abeba
2026-02-02 14:20:54 +00:00
eldritch horrors 9ad8136825 libutil: always restore mounts from restoreProcessContext
daemons only need to restore the signal mask anyway, nothing else.

Change-Id: Id2a91f33ccf68f4d1af1bc526973a4bee066ff0b
2026-02-02 14:20:54 +00:00
eldritch horrors b908f9135c *: only increase stack size if evaluations are done
we don't need to mess with this rlimit for e.g. the daemon. increasing
the limit later should always be safe since we don't allocate (or map)
much before constructing the eval states that ultimately fill our heap
and could thus make stack expansion impossible after some time passes.

Change-Id: Ieafda537fbc99a6a7f83a093a981e7df947da437
2026-02-02 14:20:54 +00:00
eldritch horrors c20aaf6ca7 libstore: inline commonExecveingChildInit into single user
Change-Id: Ia389ec8c5e375b8386949c5fb031a52f27e76d37
2026-02-02 14:20:54 +00:00
eldritch horrors 1d227cbe07 libstore: extract capability raising into raiseAmbientCaps
this will be needed in other places in the future, and splitting it out
also clarifies the surrounding code. the keep-caps dance launchPasta is
doing doesn't have to be moved since it is only needed to allow setuid.

Change-Id: I6baaa138c2b1bca9626971ed3266c1a971a63acc
2026-02-02 14:20:54 +00:00
eldritch horrors 576ff2f598 update nixpkgs, pre-commit-hooks
the devshell no longer worked for us due to the recent deprecations :D
let's update pre-commit too because while it doesn't fail it does warn

Change-Id: Ic2060c82e4e97bb7a96cebd29097abefabdfe733
2026-02-02 15:08:49 +01:00