Commit Graph

2676 Commits

Author SHA1 Message Date
Eelco Dolstra
0b2dffefea Factor out NarCache from RemoteFSAccessor
Use

```
git show --color-moved --patience --color-moved-ws=ignore-all-space
```

to review and see that this is mostly code motion.

Co-Authored-By: John Ericson <John.Ericson@Obsidian.Systems>
2026-01-21 19:15:51 -05:00
Eelco Dolstra
44dce7a3d1 Merge pull request #15029 from amaanq/signature-type-core
libutil: add `Signature` struct for typed signatures
2026-01-21 21:17:01 +00:00
Amaan Qureshi
12ef043655 libutil: add Signature struct for typed signatures
Introduce a new `Signature` struct that represents a cryptographic
signature
along with the key name that produced it. This provides:

- Structured representation instead of colon-separated strings
- Type-safe parsing with `Signature::parse()`
- Serialization with `to_string()`
- JSON serialization/deserialization
- Batch parsing with `parseMany<Container>()`
- Batch serialization with `toStrings()`

This is scaffolding for future changes that will use this type
throughout the codebase.
2026-01-21 11:51:46 -05:00
Sergei Zimmerman
6dd89b5a2a libutil: Add PathFmt wrapped type for formatting fs::path, fix all double-quoting issues
This will once and for all get rid of all double-quoting issues. On windows the quoting
is doubly bad because it escaped all \ to \\, which is very bad for error messages. In
order to prevent future regression std::filesystem::path formatting now must use a special
type PathFmt (like Magenta). In the future we could even change how we render filesystem paths.
2026-01-21 06:06:19 +03:00
Sergei Zimmerman
73beff89cb libutil: Fix mingw build 2026-01-21 04:54:54 +03:00
John Ericson
017a247e63 Merge pull request #15025 from cole-h/cole-h/push-qmyswwomnsnl
libutil: add missing tracking URLs for external-builders and blake3-h…
2026-01-20 16:17:30 +00:00
Eelco Dolstra
4a267f720e Merge pull request #14998 from NixOS/fix-remote-store-nar-from-path
libstore: Do not mark connections as bad when RemoteStore::narFromPath is called as a coroutine
2026-01-20 16:08:07 +00:00
Cole Helbling
c398dd7cbd libutil: add missing tracking URLs for external-builders and blake3-hashes 2026-01-20 07:32:26 -08:00
John Ericson
67a99db5be Merge pull request #15020 from xokdvium/more-enum-compression
Use CompressionAlgo enum throughout
2026-01-20 04:50:56 +00:00
John Ericson
a59bc630aa Merge pull request #15015 from NixOS/catch-system-error
Catch `SystemError` in portable code
2026-01-20 04:41:29 +00:00
Sergei Zimmerman
6ba067831a Use CompressionAlgo throughout
Instead of the stringly typed code we should use an enum class, this is
more clear and less error-prone. Also adds settings implementations for
CompressionAlgo and std::optional<CompressionAlgo>. The first is used
for NAR compression, since we never accepted empty strings there:

error: unknown compression method ''

The other one is used for optional .narinfo, .ls, and log/ compression.
Those treated empty strings as compression being disabled. The same exact
semantics is kept.

This has the benefit of improving error messages for incorrect values:

error: option 'compression' has invalid value 'bz'
       Did you mean one of br, xz or lz4?
2026-01-20 04:35:16 +03:00
Sergei Zimmerman
556974f33b libutil: Remove unused overload of unpackTarfile 2026-01-20 01:32:43 +03:00
Sergei Zimmerman
9e496f9af2 libutil: Make Pid destructor more robust
Without this we can abort by throwing an exception in the destructor:

[24/635/2958 copied (3.8/26.0 GiB)] copying path '/nix/store/ncd2iic2nwxwhqsf4gp9sdybkwnwz20b-ruby3.3-mini_portile2-2.8.9' from 'ssh-ng://localhost:22'

Nix crashed. This is a bug. Please report this at https://github.com/NixOS/nix/issues with the following information included:

Exception: nix::Interrupted: error: interrupted by the user
Stack trace:
 0# 0x00000000004AFFE9 in result/bin/nix
 1# 0x00007F946290A1AA in /nix/store/cf1a53iqg6ncnygl698c4v0l8qam5a2q-gcc-14.3.0-lib/lib/libstdc++.so.6
 2# __cxa_call_terminate in /nix/store/cf1a53iqg6ncnygl698c4v0l8qam5a2q-gcc-14.3.0-lib/lib/libstdc++.so.6
 3# __gxx_personality_v0 in /nix/store/cf1a53iqg6ncnygl698c4v0l8qam5a2q-gcc-14.3.0-lib/lib/libstdc++.so.6
 4# 0x00007F946283FA19 in /nix/store/cf1a53iqg6ncnygl698c4v0l8qam5a2q-gcc-14.3.0-lib/lib/libgcc_s.so.1
 5# _Unwind_RaiseException in /nix/store/cf1a53iqg6ncnygl698c4v0l8qam5a2q-gcc-14.3.0-lib/lib/libgcc_s.so.1
 6# __cxa_throw in /nix/store/cf1a53iqg6ncnygl698c4v0l8qam5a2q-gcc-14.3.0-lib/lib/libstdc++.so.6
 7# 0x00007F94635D82D0 in /nix/store/9wrnk0nizdwba4sy9lg3h0xd30pg1x5a-nix-util-2.34.0pre/lib/libnixutil.so.2.34.0
 8# nix::Pid::wait() in /nix/store/9wrnk0nizdwba4sy9lg3h0xd30pg1x5a-nix-util-2.34.0pre/lib/libnixutil.so.2.34.0
 9# nix::Pid::~Pid() in /nix/store/9wrnk0nizdwba4sy9lg3h0xd30pg1x5a-nix-util-2.34.0pre/lib/libnixutil.so.2.34.0
2026-01-19 22:28:37 +03:00
Sergei Zimmerman
726e924bd7 libstore: Do not mark connections as bad when RemoteStore::narFromPath is called as a coroutine
forced_unwind is thrown by Boost.Context when destroying the coroutine.
This lead to us resetting the remote connection for each narFromPath
with the ssh-ng:// store, so copying was very slow.
2026-01-19 22:28:34 +03:00
John Ericson
a32c139379 Catch SystemError in portable code
This will ensure this catching works on Windows too, not just Unix.
2026-01-18 18:53:45 -05:00
Sergei Zimmerman
4db68c28c1 treewide: Add missing overrides of streaming readFile, make readFile non-virtual
This makes all addToStore operations that use these source accessors
constant memory regardless of file sizes. Also make the other overload
altogether and relegate it to the base class as a non-virtual method to
avoid such mistakes.
2026-01-19 01:15:26 +03:00
Sergei Zimmerman
6ba468805b libutil: Factor out copyFdRange
This factors out the helper function from seekableGetNarBytes into copyFdRange
and adds some more sanity checks for offset/length truncation/wrapping at that
API boundary where we work with NAR-style offsets and convert to native off_t.
2026-01-19 01:15:23 +03:00
Sergei Zimmerman
656e1fc659 nar-accessor: Fix thread safety of seekableGetNarBytes, use Sink
Instead of mutating the file pointer we can instead safely do
preads. That makes the local-nar-info cache once again thread safe
without the overhead of reopening the file that we used to have prior
to b9b6defca6 which broke the thread safety
by persisting the file descriptor.
2026-01-19 00:51:57 +03:00
Sergei Zimmerman
054de385d8 Merge pull request #15011 from trofi/lixnu-openat-sysno
libutil: fix `linux` build on fresh `glibc` and `gcc`
2026-01-17 17:16:43 +00:00
Sergei Trofimovich
3256aba6a2 libutil: fix linux build on fresh glibc and gcc
Without the change the build fails for me as:

    ../unix/file-descriptor.cc:404:70: error: 'RESOLVE_BENEATH' was not declared in this scope
      404 |         dirFd, path.rel_c_str(), flags, static_cast<uint64_t>(mode), RESOLVE_BENEATH | RESOLVE_NO_SYMLINKS);
          |                                                                      ^~~~~~~~~~~~~~~

This happens for 2 reasons:
1. `__NR_openat2` constant was not pulled in from the according headers
   and as a result `<linux/openat2.h>` was not included.
2. `define HAVE_OPENAT2 0` build is broken: refers to missing
   `RESOLVE_BENEATH` normally pulled in from `<linux/openat2.h>`

This changes fixes both.
2026-01-17 13:01:22 +00:00
Sergei Zimmerman
af7c7b6723 Merge pull request #14973 from NixOS/windows-known-folders
Use known folders for nix data on windows
2026-01-16 23:58:17 +00:00
Sergei Zimmerman
5d2938520c Use known folders for nix data on windows
This is the usual conventions on windows.

See https://learn.microsoft.com/en-us/windows/win32/shell/knownfolderid and
https://github.com/adrg/xdg for examples of the mapping of XDG paths to Windows
known folders.

Additionally, on Windows, this allows us to dispense with a hard-coded
default for `nixConfDir`, which is both nice (fewer compile-time
configuration options) and necessary, because we don't know what drive
the `ProgramData` directory will live on.

Tested on wine.

Co-Authored-By: John Ericson <John.Ericson@Obsidian.Systems>
2026-01-17 02:12:41 +03:00
John Ericson
1e1d9f28ba Merge pull request #14754 from NixOS/structured-attrs-cleanup
Clean up structured attrs parsing using JSON utils
2026-01-16 22:13:18 +00:00
John Ericson
54c62782f5 Move environmentVariablesCategory to libcmd
It does not belong in libutil.
2026-01-16 16:01:04 -05:00
John Ericson
ce28cb32e9 BinaryCacheStore: Avoid recreating NAR listing
We already have it, so let's just use it!
2026-01-13 14:01:25 -05:00
John Ericson
3d18d73003 Remove redundant NarAccessor::nar 2026-01-13 13:32:29 -05:00
John Ericson
8089af3bb0 Better type for NarMemberConstructor::regular
This makes some invariants clearer and more local.
2026-01-13 13:12:15 -05:00
John Ericson
b49ea8b246 Factor out parseNarListing, move to nar-listing.{cc,hh}
Now we have less of a maze of implementation structs.

Review with
```
git show --color-moved --patience --color-moved-ws=ignore-all-space
```
2026-01-13 13:10:04 -05:00
John Ericson
af821ba647 Split out nar-listing.{cc,hh}
I like the separation of concerns from NAR accessing.
2026-01-13 12:10:54 -05:00
Eelco Dolstra
1b1c949d0c Merge pull request #14981 from roberth/fix-git-relative-url-crash
`fixGitURL`: fix crash for "relative" `file:` paths and reject unsupported SCP URLs
2026-01-13 12:59:59 +00:00
John Ericson
4991defc44 Make reading in a nar listing all well typed
We can get rid of `NarMember`, because it is just `NarListing` in
disguise! The use of `std::variant` makes clear that certain stat fields
we don't care about in the non-regular-file case too.
2026-01-13 01:33:53 -05:00
Sergei Zimmerman
66fefcd795 libutil: Better implementation of createAnonymousTempFile on windows 2026-01-13 01:28:17 +03:00
Sergei Zimmerman
fd0bcd97e8 libutil: Include std::error_code in the base class SystemError 2026-01-13 00:50:42 +03:00
John Ericson
aaccb73916 ptrToOwned should be in the nix namespace 2026-01-12 16:14:21 -05:00
Robert Hensing
3b028edbf7 fixGitURL: fix crash for relative paths and reject unsupported SCP URLs
Relative paths (e.g., "relative/repo") would crash in renderAuthorityAndPath()
because an empty authority was set, violating RFC 3986 section 3.3 which
requires paths to start with "/" when an authority is present.

Fix by only setting authority for absolute paths:
- Absolute paths: file:///path (empty authority)
- Relative paths: file:path (no authority)

Also reject SCP-like URLs without a user (e.g., "github.com:path") with a
clear error message, since proper support requires careful implementation,
which is not something I can do right now.
2026-01-12 13:03:57 +01:00
Sergei Zimmerman
920c5ceb0c Merge pull request #14961 from NixOS/readdir-nonexistent-fix
libutil/union-source-accessor: Barf on non-existent directories
2026-01-11 18:15:22 +00:00
John Ericson
25998fcd1e Merge pull request #14970 from NixOS/more-openfile-readonly
Use openFileReadonly in more places
2026-01-11 00:07:15 +00:00
Sergei Zimmerman
f8a92564f7 More std::filesystem::path for nix {cat,ls}
Also fixes a double quoting issue I accidentally introduced ccdd1f1c65
in seekableGetNarBytes.
2026-01-11 01:44:16 +03:00
Sergei Zimmerman
2ae4121c1d libutil/file-system: Use openFileReadonly in more places 2026-01-11 01:44:15 +03:00
Sergei Zimmerman
08887caa1a libutil: RestoreRegularFile is an FdSink
It correctly models the is-a relation. This will be useful for doing a dynamic_cast in
downstream code that wants to copy from a file descriptor to a file descriptor.
2026-01-10 16:31:05 +03:00
Sergei Zimmerman
ccdd1f1c65 libstore: Fix mingw build
This also adds a utility for opening a file descriptor from a path in readonly mode.
Previous commit helps a bit with error handling, since now we just throw a NativeSysError.
2026-01-09 21:06:34 +03:00
Sergei Zimmerman
b7fd471f84 libutil: Inline windows-error.hh into error.hh
This way each consumer of NativeSysError doesn't have to
also conditionally include the windows-error.hh, which is very cumbersome.
And we can't include windows-error.hh in error.hh because of a circular import.
2026-01-09 20:59:35 +03:00
Sergei Zimmerman
4ab2cdacfc libutil/union-source-accessor: Barf on non-existent directories
Previously builtins.readDir would return an empty attribute set
instead of barfing on non-existent paths. This is a regression from
2.32 for impure eval.
2026-01-09 20:19:32 +03:00
Sergei Zimmerman
b474e8d249 Merge pull request #14935 from NixOS/delete-path-fchmod
libutil: Implement unix::fchmodatTryNoFollow, use in deletePath
2026-01-07 13:12:18 +00:00
Sergei Zimmerman
9a63752317 libutil: Implement unix::fchmodatTryNoFollow
Using fchmodat after a fstatat in deletePath has a slight TOCTOU
window. We can plug it by using fchmodat (the libc wrapper with
AT_SYMLINK_NOFOLLOW), but it tries fchmodat2 and falls back to the
O_PATH trick while failing when procfs isn't mounted. We can do a bit
better than that and also cache whether syscalls are unsupported to
avoid the repeated context switching that glibc would impose.

Also tests the fallback path. It's only for kernels older than 6.6 and
when procfs isn't accessible that we fall back to the racy fchmodat
without AT_SYMLINK_NOFOLLOW.

What previously used to be:

openat(AT_FDCWD, "/tmp/store-race/nix/var/nix/builds", O_RDONLY) = 11
newfstatat(11, "nix-2704212-84654554", {st_mode=S_IFDIR|000, st_size=3, ...}, AT_SYMLINK_NOFOLLOW) = 0
fchmodat(11, "nix-2704212-84654554", 040700) = 0

Is now a TOCTOU-free sequence of syscalls:

openat(AT_FDCWD, "/tmp/store-race/nix/var/nix/builds", O_RDONLY) = 11
newfstatat(11, "nix-2704953-1733606057", {st_mode=S_IFDIR|000, st_size=3, ...}, AT_SYMLINK_NOFOLLOW) = 0
fchmodat2(11, "nix-2704953-1733606057", 040700, AT_SYMLINK_NOFOLLOW) = 0

Or if the fchmodat2 is not supported:

openat(11, "nix-2705443-3010460784", O_RDONLY|O_NOFOLLOW|O_CLOEXEC|O_PATH) = 12
fstat(12, {st_mode=S_IFDIR|000, st_size=3, ...}) = 0
chmod("/proc/self/fd/12", 040700)       = 0
openat(11, "nix-2705443-3010460784", O_RDONLY|O_NOFOLLOW|O_DIRECTORY) = 12

This prevents a potentially arbitrary chmod that follows symlinks,
though the race window is very small. Also in the case that fchmodat2
isn't supported we could instead open the /proc/self/fd/N path instead
of using openat, but that's pretty much equivalent. We only care
about ensuring that the thing we chmodded wasn't a symlink since
fchmodat follows symlinks and the support for AT_SYMLINK_NOFOLLOW
in libc for that is pretty spotty on Linux. E.g. glibc fails if the
AT_SYMLINK_NOFOLLOW is specified and procfs isn't available even on
regular files. The patch also includes a test that uses a user namespace
on Linux to test this exact scenario (though it's rather exotic).
2026-01-07 14:59:05 +03:00
Graham Christensen
05df7d716a Auto-replace actually existing store path hashes 2026-01-06 17:26:20 +01:00
Artemis Tosini
357a45253c Fix creation of cgroups
A commit in #14800 broke tests around creating cgroups due to incorrect
path handling logic.
(See https://hydra.nixos.org/build/318367985/nixlog/11)

Fix that logic and represent cgroups as CanonPath.

Co-authored-by: John Ericson <John.Ericson@Obsidian.Systems>
Co-authored-by: Sergei Zimmerman <sergei@zimmerman.foo>
2026-01-05 19:48:08 +00:00
John Ericson
fef2e2e314 Merge pull request #14800 from obsidiansystems/std-file-system-path-in-builder
Use `std::filesystem::path` in `DerivationBuilder`
2026-01-04 22:39:09 +00:00
Sergei Zimmerman
f129bbb9e9 libutil: Fix on freebsd
Also remove the redundant ifdef. I forgot to add the necessary includes
while moving the code around.
2026-01-01 16:25:41 +03:00
John Ericson
04c0e3432a Use std::filesystem::path in DerivationBuilder
Since it is currently unix-only, we can use `.native()` not `.string()`
for perf, and we don't have to worry about platform-specific
conversions.
2025-12-30 14:39:54 -05:00