Commit Graph

22531 Commits

Author SHA1 Message Date
John Ericson
ce28cb32e9 BinaryCacheStore: Avoid recreating NAR listing
We already have it, so let's just use it!
2026-01-13 14:01:25 -05:00
John Ericson
3d18d73003 Remove redundant NarAccessor::nar 2026-01-13 13:32:29 -05:00
John Ericson
8089af3bb0 Better type for NarMemberConstructor::regular
This makes some invariants clearer and more local.
2026-01-13 13:12:15 -05:00
John Ericson
b49ea8b246 Factor out parseNarListing, move to nar-listing.{cc,hh}
Now we have less of a maze of implementation structs.

Review with
```
git show --color-moved --patience --color-moved-ws=ignore-all-space
```
2026-01-13 13:10:04 -05:00
John Ericson
af821ba647 Split out nar-listing.{cc,hh}
I like the separation of concerns from NAR accessing.
2026-01-13 12:10:54 -05:00
Eelco Dolstra
1b1c949d0c Merge pull request #14981 from roberth/fix-git-relative-url-crash
`fixGitURL`: fix crash for "relative" `file:` paths and reject unsupported SCP URLs
2026-01-13 12:59:59 +00:00
Eelco Dolstra
53e942bfcc Merge pull request #14983 from roberth/fetchTree-relative-file
fetchTree: reject relative `file:` paths for tarballs
2026-01-13 12:46:08 +00:00
Jörg Thalheim
1bddbff3a6 Merge pull request #14986 from NixOS/nar-cache-cleanup
Two NAR accessor / listing cleanups
2026-01-13 07:31:29 +00:00
John Ericson
4991defc44 Make reading in a nar listing all well typed
We can get rid of `NarMember`, because it is just `NarListing` in
disguise! The use of `std::variant` makes clear that certain stat fields
we don't care about in the non-regular-file case too.
2026-01-13 01:33:53 -05:00
John Ericson
8f829e478f Inline RemoteFSAccessor::makeCacheFile into lambda
It's just easier to avoid headers.
2026-01-13 01:33:53 -05:00
John Ericson
7ac5a61208 Merge pull request #14948 from NixOS/ca-nar-cache
RemoteFSAccessor: Make the local NAR cache content-addressed
2026-01-13 04:56:31 +00:00
John Ericson
2af5792cc2 Inline RemoteFSAccessor::addToCache
It was not pulling its weight. (Only used once, optional paths are
confusing, we already have an `if` / branch fit-for-purpose.)
2026-01-12 23:09:45 -05:00
Eelco Dolstra
e251ffdd46 RemoteFSAccessor: Make the local NAR cache content-addressed
Use double-indirection for better NAR accessor caching

Co-authored-by: John Ericson <John.Ericson@Obsidian.Systems>
2026-01-12 23:00:20 -05:00
John Ericson
a8087ebf52 Merge pull request #14984 from NixOS/more-windows-fixes
More windows fixes
2026-01-12 23:19:38 +00:00
Sergei Zimmerman
66fefcd795 libutil: Better implementation of createAnonymousTempFile on windows 2026-01-13 01:28:17 +03:00
Sergei Zimmerman
1ea3a841bb libstore/local-binary-cache-store: Use portable error_code in getFile 2026-01-13 00:56:03 +03:00
Sergei Zimmerman
fd0bcd97e8 libutil: Include std::error_code in the base class SystemError 2026-01-13 00:50:42 +03:00
Robert Hensing
b19bfc6373 fetchTree: improve relative path error wording
Avoid implying that relative paths could work if a base directory
were defined. The file: scheme fundamentally does not support them.
2026-01-12 20:16:26 +01:00
Robert Hensing
3b028edbf7 fixGitURL: fix crash for relative paths and reject unsupported SCP URLs
Relative paths (e.g., "relative/repo") would crash in renderAuthorityAndPath()
because an empty authority was set, violating RFC 3986 section 3.3 which
requires paths to start with "/" when an authority is present.

Fix by only setting authority for absolute paths:
- Absolute paths: file:///path (empty authority)
- Relative paths: file:path (no authority)

Also reject SCP-like URLs without a user (e.g., "github.com:path") with a
clear error message, since proper support requires careful implementation,
which is not something I can do right now.
2026-01-12 13:03:57 +01:00
Robert Hensing
23a7178eb4 fetchTree: reject relative file: paths for tarballs
Relative paths like `file:./foo.tar.gz` have never worked for tarballs
because curl rejects relative file: URLs. Previously this resulted in
cryptic curl errors. Now we reject them early with a clear message
explaining that relative paths are not supported because there is no
defined base directory to resolve them against.

See https://github.com/NixOS/nix/issues/12281
2026-01-12 03:31:42 +01:00
John Ericson
252aff5c8f Merge pull request #14971 from obsidiansystems/misc-builder-fixes
Misc builder fixes
2026-01-11 21:02:14 +00:00
Sergei Zimmerman
920c5ceb0c Merge pull request #14961 from NixOS/readdir-nonexistent-fix
libutil/union-source-accessor: Barf on non-existent directories
2026-01-11 18:15:22 +00:00
John Ericson
de76cb681d Make sure we reliably call Worker::childTerminated
When a goal with an active child process is destroyed (e.g., during
failure cascades without `--keep-going`), the child process gets killed
but `childTerminated` was never called. This left stale entries in the
worker's `children` list.

Fix this by ensuring `childTerminated` is called from destructors:

- `DerivationBuilderImpl::killChild` now calls `childTerminated` via
  the `miscMethods` callback.

- `HookInstance` gains an `onKillChild` callback that is invoked from
  its destructor when killing the process. `buildWithHook` sets this
  callback to call `childTerminated`.

To make these calls safe from destructors (where the goal object may be
partially destroyed), add a new overload of `Worker::childTerminated`
that takes an explicit `JobCategory` parameter instead of calling the
virtual method `Goal::jobCategory`. The original overload still exists
for convenience for normal (non-destructor) call sites.
2026-01-10 20:24:05 -05:00
John Ericson
d19bfb0045 Avoid short circuiting in Worker::removeGoal
We have to call into both branches no matter what.
2026-01-10 20:23:50 -05:00
John Ericson
160822858a Merge pull request #14788 from NixOS/coroutine-child-output
Way more RAII for `DerivationBuildingGoal`
2026-01-11 00:09:53 +00:00
John Ericson
25998fcd1e Merge pull request #14970 from NixOS/more-openfile-readonly
Use openFileReadonly in more places
2026-01-11 00:07:15 +00:00
John Ericson
7ba09399cc Merge pull request #14968 from NixOS/fs-sink-restore-regular-file-fd
libutil: RestoreRegularFile is an FdSink
2026-01-11 00:05:20 +00:00
Sergei Zimmerman
f8a92564f7 More std::filesystem::path for nix {cat,ls}
Also fixes a double quoting issue I accidentally introduced ccdd1f1c65
in seekableGetNarBytes.
2026-01-11 01:44:16 +03:00
Sergei Zimmerman
2ae4121c1d libutil/file-system: Use openFileReadonly in more places 2026-01-11 01:44:15 +03:00
John Ericson
38c755f168 Merge pull request #14966 from drupol/push-ozvunuqvxrvw
chore: replace `edolstra/flake-compat` with `NixOS/flake-compat`
2026-01-10 15:59:07 +00:00
Sergei Zimmerman
08887caa1a libutil: RestoreRegularFile is an FdSink
It correctly models the is-a relation. This will be useful for doing a dynamic_cast in
downstream code that wants to copy from a file descriptor to a file descriptor.
2026-01-10 16:31:05 +03:00
Pol Dellaiera
8d588ad471 chore: replace edolstra/flake-compat with NixOS/flake-compat 2026-01-10 10:10:55 +01:00
Sergei Zimmerman
6970efe2e1 Merge pull request #14962 from NixOS/fix-mingw
Fix mingw build (once again), add openFileReadonly and clean up error.hh to include WinError
2026-01-10 00:39:46 +00:00
Sergei Zimmerman
3b95b7c9aa Merge pull request #14963 from corngood/test-leak
libflake-tests: fix leak in nix_api_store_test.nix_api_load_flake_with_flags
2026-01-09 23:44:30 +00:00
David McFarland
4289e2f9e6 libflake-tests: fix leak in nix_api_store_test.nix_api_load_flake_with_flags 2026-01-09 16:51:15 -04:00
Eelco Dolstra
d1dc2d53b1 Merge pull request #14960 from NixOS/path-cleanup
PathInputScheme::getAccessor(): Drop unnecessary call to queryPathInfo()
2026-01-09 18:47:03 +00:00
Sergei Zimmerman
ccdd1f1c65 libstore: Fix mingw build
This also adds a utility for opening a file descriptor from a path in readonly mode.
Previous commit helps a bit with error handling, since now we just throw a NativeSysError.
2026-01-09 21:06:34 +03:00
Sergei Zimmerman
b7fd471f84 libutil: Inline windows-error.hh into error.hh
This way each consumer of NativeSysError doesn't have to
also conditionally include the windows-error.hh, which is very cumbersome.
And we can't include windows-error.hh in error.hh because of a circular import.
2026-01-09 20:59:35 +03:00
Sergei Zimmerman
4ab2cdacfc libutil/union-source-accessor: Barf on non-existent directories
Previously builtins.readDir would return an empty attribute set
instead of barfing on non-existent paths. This is a regression from
2.32 for impure eval.
2026-01-09 20:19:32 +03:00
Eelco Dolstra
21534baa89 PathInputScheme::getAccessor(): Drop unnecessary call to queryPathInfo() 2026-01-09 15:33:24 +01:00
Eelco Dolstra
477aa250d4 Merge pull request #14959 from NixOS/git-repo-tests
Move {init,create}GitRepo to tests/functional/common/functions.sh
2026-01-09 14:24:21 +00:00
Eelco Dolstra
2417ee4732 Move {init,create}GitRepo to tests/functional/common/functions.sh 2026-01-09 14:57:21 +01:00
John Ericson
36a6247a0b Merge pull request #14953 from corngood/cygwin-symlink-test
libutil-tests: fix openFileEnsureBeneathNoSymlinks.works on cygwin
2026-01-09 03:55:52 +00:00
David McFarland
ac24ef84fa libutil-tests: fix openFileEnsureBeneathNoSymlinks.works on cygwin 2026-01-08 18:59:46 -04:00
John Ericson
5a65b1f131 Merge pull request #14947 from NixOS/local-nar-cache
BinaryCacheStoreConfig: Change localNarCache to std::filesystem::path
2026-01-07 20:56:29 +00:00
Eelco Dolstra
24da83853a BinaryCacheStoreConfig: Change localNarCache to std::filesystem::path 2026-01-07 21:15:19 +01:00
Eelco Dolstra
6f7190bdae Merge pull request #14946 from NixOS/fix-structured-attrs-test
Fix structured-attrs test failure in dev shell
2026-01-07 18:36:52 +00:00
Eelco Dolstra
7ce871ee86 Fix structured-attrs test failure in dev shell
Fixes "error: cannot create symlink '.../tests/functional/result';
already exists".
2026-01-07 18:00:27 +01:00
Sergei Zimmerman
b474e8d249 Merge pull request #14935 from NixOS/delete-path-fchmod
libutil: Implement unix::fchmodatTryNoFollow, use in deletePath
2026-01-07 13:12:18 +00:00
Sergei Zimmerman
9a63752317 libutil: Implement unix::fchmodatTryNoFollow
Using fchmodat after a fstatat in deletePath has a slight TOCTOU
window. We can plug it by using fchmodat (the libc wrapper with
AT_SYMLINK_NOFOLLOW), but it tries fchmodat2 and falls back to the
O_PATH trick while failing when procfs isn't mounted. We can do a bit
better than that and also cache whether syscalls are unsupported to
avoid the repeated context switching that glibc would impose.

Also tests the fallback path. It's only for kernels older than 6.6 and
when procfs isn't accessible that we fall back to the racy fchmodat
without AT_SYMLINK_NOFOLLOW.

What previously used to be:

openat(AT_FDCWD, "/tmp/store-race/nix/var/nix/builds", O_RDONLY) = 11
newfstatat(11, "nix-2704212-84654554", {st_mode=S_IFDIR|000, st_size=3, ...}, AT_SYMLINK_NOFOLLOW) = 0
fchmodat(11, "nix-2704212-84654554", 040700) = 0

Is now a TOCTOU-free sequence of syscalls:

openat(AT_FDCWD, "/tmp/store-race/nix/var/nix/builds", O_RDONLY) = 11
newfstatat(11, "nix-2704953-1733606057", {st_mode=S_IFDIR|000, st_size=3, ...}, AT_SYMLINK_NOFOLLOW) = 0
fchmodat2(11, "nix-2704953-1733606057", 040700, AT_SYMLINK_NOFOLLOW) = 0

Or if the fchmodat2 is not supported:

openat(11, "nix-2705443-3010460784", O_RDONLY|O_NOFOLLOW|O_CLOEXEC|O_PATH) = 12
fstat(12, {st_mode=S_IFDIR|000, st_size=3, ...}) = 0
chmod("/proc/self/fd/12", 040700)       = 0
openat(11, "nix-2705443-3010460784", O_RDONLY|O_NOFOLLOW|O_DIRECTORY) = 12

This prevents a potentially arbitrary chmod that follows symlinks,
though the race window is very small. Also in the case that fchmodat2
isn't supported we could instead open the /proc/self/fd/N path instead
of using openat, but that's pretty much equivalent. We only care
about ensuring that the thing we chmodded wasn't a symlink since
fchmodat follows symlinks and the support for AT_SYMLINK_NOFOLLOW
in libc for that is pretty spotty on Linux. E.g. glibc fails if the
AT_SYMLINK_NOFOLLOW is specified and procfs isn't available even on
regular files. The patch also includes a test that uses a user namespace
on Linux to test this exact scenario (though it's rather exotic).
2026-01-07 14:59:05 +03:00