Commit Graph

17451 Commits

Author SHA1 Message Date
Alyssa Ross
f104a8b928 Don't refer to public keys as secret keys in error
This constructor is used for public keys as well.

(cherry picked from commit 9cc550d652)
2024-09-23 22:03:20 +00:00
Robert Hensing
e873d00bda
Merge pull request #11463 from NixOS/mergify/bp/2.23-maintenance/pr-11321
replace backport github action with mergify (backport #11321)
2024-09-16 12:41:26 +02:00
Robert Hensing
337f12800b
Merge pull request #11483 from NixOS/mergify/bp/2.23-maintenance/pr-11473
Fix making the build directory kept by `keep-failed` readable (backport #11473)
2024-09-16 12:39:30 +02:00
Artturin
91a13171d3 Fix making the build directory kept by keep-failed readable
Caused by 1d3696f0fb

Without this fix the kept build directory is readable only by root

```
$ sudo ls -ld /comp-temp/nix-build-openssh-static-x86_64-unknown-linux-musl-9.8p1.drv-5
drwx------ root root 60 B Wed Sep 11 00:09:48 2024  /comp-temp/nix-build-openssh-static-x86_64-unknown-linux-musl-9.8p1.drv-5/

$ sudo ls -ld /comp-temp/nix-build-openssh-static-x86_64-unknown-linux-musl-9.8p1.drv-5/build
drwxr-xr-x nixbld1 nixbld 80 B Wed Sep 11 00:09:58 2024  /comp-temp/nix-build-openssh-static-x86_64-unknown-linux-musl-9.8p1.drv-5/build/
```

(cherry picked from commit ebebe626ff)
2024-09-11 12:55:16 +00:00
Eelco Dolstra
3de8fbaa4b
Merge pull request #11420 from NixOS/mergify/bp/2.23-maintenance/pr-10919
install-darwin: fix _nixbld uids for macOS sequoia (backport #10919)
2024-09-10 21:38:23 +02:00
Eelco Dolstra
45df48b410
Merge commit from fork
Backport NAR tests, fix duplicate name check
2024-09-10 12:42:55 +02:00
Eelco Dolstra
a0df929575 Fix test 2024-09-10 12:22:31 +02:00
Eelco Dolstra
78eb845950 Improve use-case-hack description slightly
(cherry picked from commit 5ca2f58798)
2024-09-10 10:01:39 +02:00
Eelco Dolstra
8ce0c82268 Typo
(cherry picked from commit 4cfa59fdb3)
2024-09-10 10:01:39 +02:00
Eelco Dolstra
b88d78f98d Test that deserializing regular files / symlinks is exclusive
(cherry picked from commit 52ba3cc5ea)
2024-09-10 10:01:39 +02:00
Eelco Dolstra
fd4f995963 Fix test on macOS
(cherry picked from commit 21dcbd7e83)
2024-09-10 10:00:58 +02:00
Eelco Dolstra
2a25c1d9b4 Test that deserializing NARs with names with equal Unicode normal forms fails on macOS
The test is based on the one by @puckipedia but with the file names
swapped to make them sorted.

(cherry picked from commit 7a765a6aaf)
2024-09-10 10:00:58 +02:00
Eelco Dolstra
b51c0915ee Detect NAR directory entries that collide with another path after case-hacking
The test was made by @puckipedia.

(cherry picked from commit 3557587381)
2024-09-10 09:58:20 +02:00
Eelco Dolstra
3ab521f8e0 More tests
(cherry picked from commit 77c090cdbd)
2024-09-10 09:58:05 +02:00
Eelco Dolstra
7358d217cf Test that nix-store --restore fails if the output already exists
This restores the behaviour from before the std::filesystem
refactorings.

(cherry picked from commit da1ad28912)
2024-09-10 09:57:50 +02:00
Eelco Dolstra
f9b3defe7f Add test case for NARs with duplicate directory entries
This test was made by @puckipedia.

(cherry picked from commit 83d5b32803)
2024-09-10 09:57:05 +02:00
Eelco Dolstra
49f21a860f NAR parser: Fix check for duplicate / incorrectly sorted entries
"prevName" was always empty because it was declared in the wrong scope.

(cherry picked from commit 495d32e1b8)
2024-09-10 09:56:51 +02:00
Jörg Thalheim
0c7cdde6e3 replace backport github action with mergify
The current backport action cannot automerge because
the github action bot does not trigger github CI actions.
Mergify instead does not have this limitation and can also
use a merge queue.

On top we have now a declarative configuration to allow
contributers to add new tests to required without having access
to the github org.

An example pull request and backport can be seen here:

https://github.com/Mic92/nix-1/pull/4

and here:

https://github.com/Mic92/nix-1/pull/5

To complete the setup the mergify app must be enabled for this repository.
It's already installed in the nixos organization for nixos-hardware and
other repositories.

(cherry picked from commit 80f20fa4cb)
2024-09-09 16:38:45 +00:00
Emily
4e5a997428 install-darwin: increment base UID by 1 (#15)
(cherry picked from commit 11cf29b15c)
2024-09-03 23:58:14 +00:00
Travis A. Everett
3726460c30 install-darwin: move nixbld gid to match first UID
(cherry picked from commit 75567423fb)
2024-09-03 23:58:14 +00:00
Travis A. Everett
d5dc377973 install-darwin: fix _nixbld uids for macOS sequoia
Starting in macOS 15 Sequoia, macOS daemon UIDs are encroaching on our
default UIDs of 301-332. This commit relocates our range up to avoid
clashing with the current UIDs of 301-304 and buy us a little time
while still leaving headroom for people installing more than 32 users.

(cherry picked from commit df36ff0d1e)
2024-09-03 23:58:13 +00:00
Robert Hensing
700d1355d3
Merge pull request #11333 from NixOS/backport-11329-to-2.23-maintenance
[Backport 2.23-maintenance] fix: check to see if there are any lines before
2024-08-19 16:27:24 +02:00
Tom Bereknyei
7cca0f3794 fix: check to see if there are any lines before
(cherry picked from commit 59db8fd62b)
2024-08-19 13:40:35 +00:00
tomberek
d02b2eb187
Merge pull request #11318 from NixOS/backport-11270-to-2.23-maintenance
[Backport 2.23-maintenance] libstore: fix port binding in __darwinAllowLocalNetworking sandbox
2024-08-17 02:56:20 -04:00
Andrew Marshall
8f439a2c3c libstore: fix port binding in __darwinAllowLocalNetworking sandbox
In d60c3f7f7c, this was changed to close a
hole in the sandbox. Unfortunately, this was too restrictive such that it
made local port binding fail, thus making derivations that needed
`__darwinAllowLocalNetworking` gain nearly nothing, and thus largely
fail (as the primary use for it is to enable port binding).

This unfortunately does mean that a sandboxed build process can, in
coordination with an actor outside the sandbox, escape the sandbox by
binding a port and connecting to it externally to send data. I do not
see a way around this with my experimentation and understanding of the
(quite undocumented) macOS sandbox profile API. Notably it seems not
possible to use the sandbox to do any of:

- Restrict the remote IP of inbound network requests
- Restrict the address being bound to

As such, the `(local ip "*:*")` here appears to be functionally no
different than `(local ip "localhost:*")` (however it *should* be
different than removing the filter entirely, as that would make it also
apply to non-IP networking). Doing `(allow network-inbound (require-all
(local ip "localhost:*") (remote ip "localhost:*")))` causes listening
to fail.

Note that `network-inbound` implies `network-bind`.

(cherry picked from commit 00f6db36fd)
2024-08-17 03:17:43 +00:00
Eelco Dolstra
9297d927c9
Merge pull request #11214 from NixOS/backport-11171-to-2.23-maintenance
[Backport 2.23-maintenance] Increase download buffer size and improve tarball import logging
2024-07-29 16:03:27 +02:00
Eelco Dolstra
dd0412d1b4 Show when we're unpacking an archive into the Git cache
This happens in parallel with the download (which starts later), so
you only see this message when the download has finished but the
import hasn't.

(cherry picked from commit 01839b525c)
2024-07-29 13:02:58 +00:00
Eelco Dolstra
c3e907af7d Warn if the download buffer is full
(cherry picked from commit f6a9a71b38)
2024-07-29 13:02:58 +00:00
Eelco Dolstra
78046450ab Add 'download-buffer-size' setting
We are piping curl downloads into `unpackTarfileToSink()`, but the
latter is typically slower than the former if you're on a fast
connection. So the download could appear unnecessarily slow. (There is
even a risk that if the Git import is *really* slow for whatever
reason, the TCP connection could time out.)

So let's make the download buffer bigger by default - 64 MiB is big
enough for the Nixpkgs tarball. Perhaps in the future, we could have
an unlimited buffer that spills data to disk beyond a certain
threshold, but that's probably overkill.

(cherry picked from commit 8ffea0a018)
2024-07-29 13:02:57 +00:00
Eelco Dolstra
7698e53b0b Log download durations
(cherry picked from commit caf4e98f0c)
2024-07-29 13:02:57 +00:00
Eelco Dolstra
051f3773db
Merge pull request #11194 from NixOS/backport-11086-to-2.23-maintenance
[Backport 2.23-maintenance] Eval cache: fix cache regressions
2024-07-26 18:26:25 +02:00
Lexi Mattick
77e4802ce2 Clean up cache for all commands
(cherry picked from commit 6c4470ec2a)
2024-07-26 15:59:36 +00:00
Lexi Mattick
6925a772d0 Eval cache: fix cache regressions
- Fix eval cache not being persisted in `nix develop` (since #10570)
- Don't attempt to commit cache transaction if there is no active transaction, which will spew errors in edge cases
- Drive-by: trivial typo fix

(cherry picked from commit e764ed31f6)
2024-07-26 15:59:36 +00:00
Eelco Dolstra
707a6c550f
Merge pull request #11128 from NixOS/backport-10852-to-2.23-maintenance
[Backport 2.23-maintenance] add call to `checkInterrupt` in a bunch of places
2024-07-17 18:28:29 +02:00
siddhantCodes
af8a1715e1 add call to checkInterrupt in a bunch of places
This brings back the old behaviour. We check for interrupts in places
that may iterate over wide directories.

(cherry picked from commit 8f1a26667e)
2024-07-17 16:02:07 +00:00
Eelco Dolstra
180dfa44b2 Bump version 2024-07-08 12:36:05 +02:00
Robert Hensing
f1deb42176
Merge pull request #11052 from NixOS/backport-11051-to-2.23-maintenance
[Backport 2.23-maintenance] src/nix/prefetch: fix prefetch containing current directory instead o…
2024-07-05 23:00:08 +02:00
Jörg Thalheim
d58592469d Update src/nix/prefetch.cc
Co-authored-by: Eelco Dolstra <edolstra@gmail.com>
(cherry picked from commit 05381c0b30)
2024-07-05 18:33:21 +00:00
Jörg Thalheim
73f3179954 src/nix/prefetch: fix prefetch containing current directory instead of tarball
When --unpack was used the nix would add the current directory to the
nix store instead of the content of unpacked.
The reason for this is that std::distance already consumes the iterator.
To fix this we re-instantiate the directory iterator in case the
directory only contains a single entry.

(cherry picked from commit 8cea1fbd97)
2024-07-05 18:33:21 +00:00
Eelco Dolstra
df877f4522 Bump version 2024-07-05 19:40:34 +02:00
Eelco Dolstra
39735546f1
Merge pull request #11045 from NixOS/backport-11031-to-2.23-maintenance
[Backport 2.23-maintenance] libstore: fix sandboxed builds on macOS
2024-07-05 17:43:30 +02:00
Emily
b74f140866 libstore: fix sandboxed builds on macOS
The recent fix for CVE-2024-38531 broke the sandbox on macOS
completely. As it’s not practical to use `chroot(2)` on
macOS, the build takes place in the main filesystem tree, and the
world‐unreadable wrapper directory prevents the build from accessing
its `$TMPDIR` at all.

The macOS sandbox probably shouldn’t be treated as any kind of a
security boundary in its current state, but this specific vulnerability
wasn’t possible to exploit on macOS anyway, as creating `set{u,g}id`
binaries is blocked by sandbox policy.

Locking down the build sandbox further may be a good idea in future,
but it already has significant compatibility issues. For now, restore
the previous status quo on macOS.

Thanks to @alois31 for helping me come to a better understanding of
the vulnerability.

Fixes: 1d3696f0fb
Closes: #11002
(cherry picked from commit af2e1142b1)
2024-07-05 15:09:04 +00:00
Emily
639c2ffc9d libstore: clean up the build directory properly
After the fix for CVE-2024-38531, this was only removing the nested
build directory, rather than the top‐level temporary directory.

Fixes: 1d3696f0fb
(cherry picked from commit 76e4adfaac)
2024-07-05 15:09:04 +00:00
Eelco Dolstra
a5c2e1ef44
Merge pull request #11042 from NixOS/backport-11020-to-2.23-maintenance
[Backport 2.23-maintenance] Tarball fetcher: Fix fetchToStore() and eval caching
2024-07-05 16:55:08 +02:00
Eelco Dolstra
b91c7cf077 Tarball fetcher: Include revCount/lastModified in the fingerprint
This can influence the evaluation result so they should be included in
the fingerprint.

(cherry picked from commit 5b4102c3b2)
2024-07-05 14:30:29 +00:00
Eelco Dolstra
e38f45b19f nix flake metadata: Show flake fingerprint
This is useful for testing/debugging and maybe for sharing eval caches
(since it tells you what file in ~/.cache/nix/eval-cache-v5 to copy).

(cherry picked from commit 1ff186fc6e)
2024-07-05 14:30:29 +00:00
Eelco Dolstra
241c539f6f Tarball fetcher: Fix fetchToStore() and eval caching
(cherry picked from commit 9d95c228ee)
2024-07-05 14:30:29 +00:00
Robert Hensing
50a71b69b0
Merge pull request #11032 from NixOS/backport-11009-to-2.23-maintenance
[Backport 2.23-maintenance] Installer tests
2024-07-03 20:55:28 +02:00
Robert Hensing
49ae3b4166 installerScriptForGHA: aarch64-darwin
GitHub Actions seems to have magically switched architectures
without changing their identifiers.
See 2813ee66cb/README.md (available-images)
Maybe they have more complete documentation elsewhere, but it
seems to be incapable of selecting a runner based on architecture.

(cherry picked from commit df3e92ff96)
2024-07-03 18:22:47 +00:00
Robert Hensing
6d6ddbf36c
Merge pull request #11029 from NixOS/backport-11022-to-2.23-maintenance
[Backport 2.23-maintenance] Use proper struct sockpeercred for SO_PEERCRED for OpenBSD
2024-07-03 19:59:33 +02:00