Commit Graph
18843 Commits
Author SHA1 Message Date
eldritch horrors ef8a6cc5f5 libutil: add tryGetHome that doesn't throw on errors
Change-Id: Ib5bcb277e39093b303fe4a66a8903a7c5692f305
2026-01-27 17:13:07 +01:00
Raito Bezarius e083a68a9f libstore/linux: forbid xattrs syscalls
xattrs are revealing some unfortunate brittleness in real world
derivations that are getting -EINVAL errors while executing their test
code.

The reason for this is that Linux checks [1] UID delegations for xattrs
writes.

In the Lix sandbox, except if you enabled a uid-range feature, you have
exactly 3 UIDs: root, nixbld and nobody.

If your test code makes use of UIDs which have not been delegated, you
will receive an EINVAL on your operation. Test code is not resilient
with respect to the number of available UIDs in their namespace.

To avoid further issues for end users who are running into spurious
derivation build failures, we forbid xattrs again for now.

For more information about the plans, please consult or chime in [2].

Fixes #1105. Reopens #838. Fixes #1103.

[1]: https://elixir.bootlin.com/linux/v6.18.6/source/fs/posix_acl.c#L257
[2]: https://zulip.lix.systems/#narrow/channel/9-Store/topic/disablement.20of.20xattrs/with/5295

Change-Id: I864066b34cd8319d2271fac1b179cb4f950d836e
Signed-off-by: Raito Bezarius <raito@lix.systems>
2026-01-26 18:54:51 +00:00
eldritch horrors cfabc37828 libstore: add unix:// uri protocol argument
Change-Id: I7fc27926aa1d89e2190b1deb0252ad33f2b364a5
2026-01-26 18:17:07 +00:00
eldritch horrors bdc220b8ec libstore: allow for multiple daemon sockets with preference
this will let us configure more than one socket to connect/bind to,
which in turn lets us use posix acls on sockets for access control.
we will also need something like this for the final rpc transition.

Change-Id: I9c39f14906e9bf809055ab5c94bf687745b4f69e
2026-01-26 18:17:07 +00:00
eldritch horrors f4458b8e46 libstore: simplify netrc, cafile loading for builtin builders
Change-Id: I8370a1434729c7ff2e44ddbaf173d7068e8ace9f
2026-01-25 19:47:24 +01:00
eldritch horrors 99d674b785 libstore: despecialize sandbox launching
now that builtin builders are regular executables we no longer need to
treat them specially during sandbox launch itself, only while we build
the command line and environment for the sandboxed process. we are not
far from being able to extract platform-dependent sandbox launch code,
ideally moving all of it into (much more replaceable) libexec helpers.

Change-Id: I9b7041314683c56cd70eec9b1b4eae6de228883f
2026-01-25 19:43:13 +01:00
eldritch horrors 049c7b3369 libstore: move the builtin builders to our new executable
this means that builtinFetchurl runs in a real process now, and thus we
no longer need its workarounds for running in a forked process. forking
dropped the signal handler thread and broke the curl state via sharing,
neither of which happens any more now. we can run fetchurl builtins and
their actions straight from the main thread of our builder now, and the
temporary files and settings overrides we did are now also unnecessary.

Change-Id: I738171bc120ffcd541b7ff1424fed7924c2cdc1d
2026-01-25 19:31:38 +01:00
eldritch horrors 58c3ee4c8e builtin-builder: remove unescapeNul that snuck back in
fuck

Change-Id: I5d203fc36c4a2eb2aefde9208d6cefd3619cdf03
2026-01-25 19:30:10 +01:00
eldritch horrors 5abf26a19f add a builtin-builder command for ... builtin builders
this will let us migrate the fork+do_stuff combo of builtin builders we
have today to fork+exec of this new command. we use a subcommand rather
than a simple libexec helper because we would like to avoid linking all
of lix into the simple libexec helpers if possible. this is only hookup
for the builders, none of the buiders are migrated here to ease review.

Change-Id: I9358f1f3fee6ca640c81a7bd865128ae0d0e35a5
2026-01-25 17:26:39 +00:00
eldritch horrors c50a3a426f libutil: add simple NUL escaping/unescaping functions
Change-Id: Ia4cc7b8f1058439f312066422eebfaff1c2c0c6c
2026-01-25 17:29:32 +01:00
eldritch horrors ed6a1e58ea libstore: don't call builtin builders with derivations
call them with their individual parameters instead. this will make it
much easier to turn them into executables we can exec in the sandbox.

Change-Id: Ib49cf44715b2a480fecadabd21216c69cd730ef5
2026-01-25 15:34:59 +01:00
eldritch horrors 21e8347bb6 libstore: make netrc/cafile child args plain strings again
not having the optionals set when the builder runs (e.g. because FOD
hashes were not configured correctly) could cause assertion failures
in the builder process. while this should usually not happen we *do*
want to print a useful error message here instead of a crash report.

Change-Id: I81fb1d45fcbf660d0d9a7f0c0a12c38379ecd4c6
2026-01-25 15:34:59 +01:00
rootile 2f7644c420 tests/functional2: fix wrong usage of env var
Change-Id: I37580e0d74e26e064261c98a1162fbd9e23a9d46
2026-01-23 16:15:55 +01:00
Rebecca Turnerandrootile cb34b56fea tests/functional2: Fix Python LSP by adjusting imports
See: cl/4840

When importing Python modules, we include `functional2` in the module
path, like this:

    from functional2.testlib.fixtures.env import ManagedEnv

This means that python expects to see a file like
`functional2/testlib/fixtures/env.py`. We run `pytest` from `tests/` in
the `justfile` and have `tests/functional2/__init__.py` so `pytest` in
`meson` is able to find these imports.

However, language servers generally consider the `pyproject.toml` to be
the project root, so (e.g.) `pyright` is unable to follow any of the
`functional2` imports, leading to lots of spurious errors.

In cl/4840 I moved `tests/functional2/pyproject.toml` to
`tests/pyproject.toml`, which worked but was considered aesthetically
unappealing.

This diff is much larger but it's a more elegant solution.

Change-Id: I2983c7b87f88f59a4e3521451a9f5acd6a6a6964
2026-01-23 15:06:51 +01:00
eldritch horrors 0453be06b6 libutil: remove unused RunOptions::{chdir, createSession}
Change-Id: Ib2b9f5c094233661a01ad8cea30a44e11931c941
2026-01-22 16:59:39 +01:00
eldritch horrors b5a25f0fb6 libstore: move build hook launching to libexec helper
like diff hooks before the build hooks also use runProgram features that
aren't present in posix_spawn. just like diff hooks we do not expect the
build hook processes to be so fast that launch overhead matters somehow.

Change-Id: If3c33dbd7d2ac20c95886e06d24feda312946c78
2026-01-22 16:59:37 +01:00
eldritch horrors a7f4a675b6 libutil: remove Pid::setSeparatePG
use a wrapper type instead. whether something should be treated as a
single process or a group is a type decision more than a runtime one

Change-Id: I966e998c19e74be64ddd72ab11af809d001f61b5
2026-01-22 16:57:26 +01:00
eldritch horrors 0b03ae1a13 libutil: remove unused Pid::{killSignal, setKillSignal}
Change-Id: Ic7cceef2d82a98cf8fe23260603b1262c097cad4
2026-01-22 15:23:38 +00:00
eldritch horrors 5351518c75 libstore: add a diff hook helper libexec binary
diff hooks use uid/gid switch functionality that is otherwise only
needed for linux sandbox setup and unsupported by posix_spawn. not
doing these switches inside lix core code may let us move to using
posix_spawn for most process launching in the future, and for diff
hooks the added overhead of a wrapper program really does not hurt
at all. diff hooks are expected to be expensive in terms of output
size, process launch overhead is not likely to even be noticeable.

Change-Id: Ifa4b3eedef237632db3eb88d10e6469acae01f9e
2026-01-22 15:23:38 +00:00
eldritch horrors d7b0d322f7 libstore: make diff-hooks work for non-root users
it's kind of weird to not allow diff-hooks in single user mode unless
that user is root. maybe that's why we have no tests for them? we can
at least add a test that diff hooks are run at all when we expect it.

Change-Id: I54d623b5416acda1c205cc062b0f3a33c9f4aaa7
2026-01-22 15:23:38 +00:00
eldritch horrors 36168de584 libutil: remove {Process,Run}Options::dieWithParent
nothing except the linux sandbox actually *needs* this for correctness.
the linux sandbox only uses it to ensure that builder uids are freed up
when the sandbox is torn down, and even *then* it only works as we need
it to with PID namespaces enabled since the parent death signals is not
inherited across fork, but when pid1 of a pid namespace dies the kernel
also kills all namespace members. in all other cases this flag does not
help us that much because it actively prevents child processes cleaning
up after themselves, possibly leaving more trash around than otherwise.

Change-Id: I9ae0a9e91833a91d1011375dda402ac6c0a7ef6f
2026-01-22 15:23:38 +00:00
Raito BezariusandNiko Klanecek 728d2bfee7 contrib/plugins: add mTLS binary cache store plugin
Adds an example plugin implementing an mTLS-enabled binary cache store
(https+mtls:// scheme) using client certificates for authentication.

Darwin fix: don't link liblix* into plugins (host resolves symbols at
runtime via dynamic_lookup). Explicitly link curl so it binds to
Nix-store libcurl, not /usr/lib/libcurl. This prevents the plugin's
curl_easy_setopt calls from operating on the wrong libcurl instance.

Test portability: BSD sed -i wrapper, OpenSSL -sha256 for cert signing,
redirect test server output to log file.

Change-Id: I652b987d3ac45e31df50ff4ba1f523294438c2b6
2026-01-21 22:50:35 +00:00
eldritch horrors 7068cbf010 libstore: extract env and args rewriting from child
this really doesn't have to be here, it doesn't help very much. doing it
in the parent is cheap enough to not care and sandbox setup is not async
yet *anyway*, so we would not even notice if the old way was any faster.

Change-Id: I5a3a99af0fa5928e9a42f9c6589d98ff38b8c775
2026-01-21 15:59:30 +01:00
eldritch horrors 6da0389d0f libstore: move netrc/ca init outside of the build child process
this will make it easier to turn build sandbox processes into helpers.
the point they were at was effectivly unsandboxed except for a few fds
that were redirected by commonExecveingChildInit, which only made logs
of any errors that much harder to convey from the child to the parent.

Change-Id: I67006eb33e1e13311bb8d14e6a0c3d5e6baf0c13
2026-01-21 15:59:30 +01:00
eldritch horrors 5ba9a3961c libstore: move setupSyscallFilter to linux platform bits
setting them that little bit later really doesn't hurt us at all.

Change-Id: I6b50fbe0b58d037de729748cb4f87dd628bd111b
2026-01-21 15:59:30 +01:00
eldritch horrors 95c65ce637 libstore: move setPersonality to linux platform
it doesn't do anything anywhere else, and personality setup is not a
critical operation (all it does is change which arch uname returns).

Change-Id: I39d7fcc4916e6882e49191d2294f9b7ee0dbbcd0
2026-01-21 15:59:30 +01:00
eldritch horrors 6edbef7338 libstore: move some macos-specific bits to platform
Change-Id: I9236ffb8e098d09215067b872b5da5e210557815
2026-01-21 15:59:30 +01:00
eldritch horrors c39488d2a4 libstore: move some linux-specific child setup to platform code
best viewed with --color-moved --color-moved-ws=all

Change-Id: I3738f07fd0b39498abf253967906270dc0b215f4
2026-01-21 15:59:30 +01:00
eldritch horrors 113c6fd618 libstore: reformat bits of LocalDerivationGoal
mathbb overbar sigh

Change-Id: I9b5361ba03ff11a89773f7da2262d38fbf39b7af
2026-01-21 15:59:30 +01:00
eldritch horrors 3937eb9ecc libstore: open builder log pty in parent
there's no need to do it in the fork, we're not changing security
domains before opening the pty anyway. we do change who owns this
pty device, but since we change it via chown we can just *not* do
that before we have an open fd to the pty. in practice this isn't
even necessary because the daemon runs as root, but if we ever do
run the daemon as an unprivileged user we'd need this to be split

Change-Id: I35264ab2954c7ba2c9c24c927366d64acada6772
2026-01-21 15:59:30 +01:00
eldritch horrors 697a86c4af libutil/libstore: move namespace support checks to libexec
this also requires moving namespace support information into Worker and
out of function-scope static variables, otherwise we can't use async IO
for the libexec helper output. we could set the fd to blocking for just
one CL and extract the Worker changes into another that the reverts the
blocking fd usage, but that seems not warranted for the scope of these.

Change-Id: I6996fab1ae74693d50cefb6a6a9c21d61dada1d9
2026-01-20 22:42:53 +00:00
eldritch horrors be27e9696b libutil: move unix chdir+bind/connect to libexec
Change-Id: Ie07ece701454153d3d5c6c34e5613c0d1d5fae03
2026-01-20 22:42:53 +00:00
Justin ! 41a68f206f treewide: print* -> format* for functions not printing
Those functions have been recently refactored to return a formatted
`string` or take an `std::ostream` and only do the formatting have been
renamed to match what they're actually doing.

Change-Id: I3fe32fbe8723c2d93226370b8dd297f16a6a6964
2026-01-20 22:31:59 +00:00
eldritch horrors 761f8ab6eb libutil: fix libexec helper args span calculation
fucking hate C

Change-Id: I678c9eda32911ce7ea5e76c4274b71e45e7f3790
2026-01-20 19:16:00 +01:00
eldritch horrors 8039d69818 libutil: move killUser innards to libexec
Change-Id: Iddd3099c31c91b18c946f7ba2db79c221e7686fe
2026-01-20 16:43:23 +01:00
eldritch horrors d9187b4ee0 libmain: run pagers with a libexec helper
this is mostly a test and example for the libexec helper infrastructure,
but it also lets us simplify pager launching until we we can more easily
handle executable-not-found errors the launch fallbacks would cause when
using runProgram2 instead of fork. ideally we'd use `posix_spawn` later.

fixes #1104

Change-Id: Ia33cc12e8a9d60ffad6f5c055bb1b8b596810e64
2026-01-20 14:02:12 +00:00
eldritch horrors 9921615410 libutil: add libexec helper infrastructure
the new libexec directory is not available as a setting like other
directories (e.g. binDir) are since we consider libexec helpers to
be very internal. repointing them is like repointing a .so file we
dynamically link to; it can work, but needs much more preparation.

Change-Id: I40e64be0b32276f2864c0f2eb0b998d4c8ce7c88
2026-01-20 13:53:44 +00:00
eldritch horrors 9b334faa81 meson: use escaping functions for config.h defines
Change-Id: If7677d8040e0da0b72fc9498f2c920a0f1bb25f7
2026-01-20 13:53:44 +00:00
Pol Dellaiera 7009944370 chore: replace edolstra/flake-compat with lix-project/flake-compat
Change-Id: Ia7409ecb2f61d1ff6c8c4031025226e8549b22b6
2026-01-20 12:31:41 +00:00
Commentator2.0 eca222c7ca tests/functional2: migrate dump-db.sh
Change-Id: Ife8ff62add37f50867f55a5eaa26f7a68fad1c78
2026-01-20 10:08:36 +00:00
Commentator2.0 cdd8508bc9 tests/functional2: Provide a shortcut to clear a store
Change-Id: Ic28fb8a81ef95a1b83fa8099f5337e89f630f8e1
2026-01-20 10:08:14 +00:00
eldritch horrors d5bdc1c240 tests: remove outdated comment in test-session
we *are* using runProgram2, just not its builtin stdout stream.

Change-Id: I1766a9e443f539979f1f780a6d32294d103fb10f
2026-01-19 20:31:30 +00:00
eldritch horrors e2991e1245 libstore: use runProgram2 to launch build hooks
we don't need the full sandbox setup helpers for this: mount namespaces
do not need to be kept, loggers are not needed, and redirections can be
done by runProgram2. once the build hook is removed we will not run the
communication bits from a different process anyway, this prepares that.

Change-Id: I95d28f7c2c25e43ccd82b448d270403ce4f28852
2026-01-19 19:46:29 +00:00
eldritch horrors f2432be62d libstore: use runProgram2 for ssh connections
we do not need explict redirection management now, and dieWithParent
doesn't need an override either. we'd much prefer to kill ssh if the
process in charge exits; even ssh multiplexers are not fazed by this

Change-Id: I81e28b7605df73c887878ea4716228c7ad0f5c6f
2026-01-19 19:45:28 +00:00
eldritch horrors 39869c8b35 libutil: add setsid support to runProgram2
Change-Id: I9c023f2497cab12f1a7bfafd0baa82ffb5912d3e
2026-01-19 19:28:46 +01:00
eldritch horrors 6c7a80e449 libutil: reformat runProgram2
yeah. sorry about that.

Change-Id: I33d55d0014a53346a5c0ce07091a086374172b30
2026-01-19 19:28:46 +01:00
eldritch horrors a28dc8f77f tests: use runProgram2 for repl tests
the redirections the tests did were once not possible with runProgram2,
but they have been for a while now. we should use them instead of fork.

Change-Id: Ia422c8941ed04a9403dee68bfe938d68952253da
2026-01-19 19:28:46 +01:00
eldritch horrors 1719d60531 libutil: return pid object from RunningProgram::release
returning the pid as a pid_t instead of as a Pid raii wrapper is only
convenient for daemon use (where it'll eventually go away). using the
released pid correctly in other places is harder without the wrapper.

Change-Id: Ib42a2f357d2f0849beabd015b321bfff31334eda
2026-01-19 19:28:46 +01:00
Tom Hubrecht 7d764670c8 nix/path-info: Don't print missing paths as no fetch can be done
Fixes #323

Let's now all go an a little rant about spaghetti code...

The result of this code is that the missing paths are not printed
anymore. The basic issue was that the parent class of this command is
StorePathsCommand, which inherits from BuiltPathsCommand, and their
purpose is to work on path that are clearly in the store, building them
if needed (and ofc telling the user about what's missing), the sequance
of calls is:

- BuiltPathsCommand::run(ref<Store> store, Installables && installables)
- Installable::toBuiltPaths( *getEvaluator()->begin(aio()),
getEvalStore(), store, realiseMode, operateOn, installables);
  where operateOn is Output by default, realiseMode is Derivation, so
the only thing that can be built are the derivations for the required
installables
- Installable::build(state, evalStore, store, mode, installables)
- Installable::build2(state, evalStore, store, mode, installables,
bMode)

And that final call has the following:

```
    switch (mode) {

    case Realise::Nothing:
    case Realise::Derivation:
        state.aio.blockOn(printMissing(store, pathsToBuild, lvlError));
```

So there were two options, hack a new spaghetti in the existing
spaghetti code, or condense all those calls that are actually useless in
our case because they mostly transform a list of installables into a map
from installables to their BuiltPath which are then iterated to retrieve
the final outputs, whereas it is possible to directly get the required
paths in a much more efficient manner and without printing unrequired
stuff through a multitude of intertwined function calls by simply
replacing one method that was previously inherited from the grandparent
class

Change-Id: I1d2baaef5a099cd98b63b5346f2613914c6cd2ac
2026-01-18 20:25:39 +00:00
eldritch horrors 54180f4c35 libmain: remove RunPager
it's no longer needed now that withPager exists. also fix a
logger-never-resumed bug that never showed up in the world.

Change-Id: I7311a50896f5291364320ec4c88506dc3bb11d4c
2026-01-18 19:17:14 +00:00