Revert "staging-nixos merge for 2026-06-19"
This commit is contained in:
@@ -10,7 +10,6 @@
|
||||
|
||||
<!-- To avoid merge conflicts, consider adding your item at an arbitrary place in the list instead. -->
|
||||
|
||||
- Paths under `/etc/xdg/` from packages in `environment.systemPackages` are no longer linked into the global `/etc/` by default. Modules depending on such directories must declare them explicitly using `environment.pathsToLink`.
|
||||
- `databricks-cli` has been updated from `0.290.2` to `1.x.x`, the first major release. OAuth tokens for interactive logins (`auth_type = databricks-cli`) are now stored in the OS-native secure store by default (Secret Service on Linux) instead of `~/.databricks/token-cache.json`; cached tokens from older versions are not migrated, so run `databricks auth login` once per profile after upgrading. To keep the previous file-backed storage, set `DATABRICKS_AUTH_STORAGE=plaintext` or add `auth_storage = plaintext` under `[__settings__]` in `~/.databrickscfg`. Additionally, the `vector_search_endpoints` DABs resource renamed `min_qps` to `target_qps` (and the `vector-search-endpoints` command renamed `--min-qps` to `--target-qps`). See the [upstream changelog](https://github.com/databricks/cli/blob/main/CHANGELOG.md) for details.
|
||||
|
||||
- `hurl` has been updated to `8.x.x` which has some breaking changes. See [upstream changelog](https://github.com/Orange-OpenSource/hurl/releases/tag/8.0.0) for details.
|
||||
|
||||
@@ -187,6 +187,7 @@ in
|
||||
|
||||
environment.pathsToLink = [
|
||||
"/bin"
|
||||
"/etc/xdg"
|
||||
"/etc/gtk-2.0"
|
||||
"/etc/gtk-3.0"
|
||||
"/lib" # FIXME: remove and update debug-info.nix
|
||||
|
||||
@@ -22,6 +22,8 @@
|
||||
};
|
||||
|
||||
config = {
|
||||
# FIXME this does not actually work because "/etc/xdg" is linked
|
||||
# unconditionally in `nixos/modules/config/system-path.nix`
|
||||
environment.pathsToLink = lib.mkIf config.xdg.autostart.install [
|
||||
"/etc/xdg/autostart"
|
||||
];
|
||||
|
||||
@@ -763,7 +763,6 @@ in
|
||||
];
|
||||
};
|
||||
serviceConfig.Type = "oneshot";
|
||||
serviceConfig.EnvironmentFile = "-/etc/switch-root.conf";
|
||||
description = "NixOS Activation";
|
||||
|
||||
script = # bash
|
||||
@@ -771,14 +770,6 @@ in
|
||||
set -uo pipefail
|
||||
export PATH="/bin:${cfg.package.util-linux}/bin"
|
||||
|
||||
# A non-NixOS closure (e.g. init=/bin/sh) has no prepare-root;
|
||||
# initrd-find-nixos-closure records this as a non-empty NEW_INIT.
|
||||
# Skip activation and let initrd-switch-root hand over to it directly.
|
||||
if [ -n "''${NEW_INIT:-}" ]; then
|
||||
echo "$NEW_INIT is not a NixOS system - not activating"
|
||||
exit 0
|
||||
fi
|
||||
|
||||
closure="$(realpath /nixos-closure)"
|
||||
|
||||
# Initialize the system
|
||||
|
||||
@@ -71,10 +71,6 @@
|
||||
RequiresMountsFor = [
|
||||
"/sysroot/nix/store"
|
||||
];
|
||||
# find-etc only creates this symlink for a NixOS init. For a
|
||||
# non-NixOS init= (e.g. init=/bin/sh) it is absent, so skip the
|
||||
# mount instead of failing the whole initrd.
|
||||
ConditionPathExists = "/etc-metadata-image";
|
||||
};
|
||||
requires = [
|
||||
config.boot.initrd.systemd.services.initrd-find-etc.name
|
||||
@@ -127,8 +123,6 @@
|
||||
"/run/nixos-etc-metadata"
|
||||
];
|
||||
DefaultDependencies = false;
|
||||
# Skip for a non-NixOS init=, see the metadata mount above.
|
||||
ConditionPathExists = "/etc-basedir";
|
||||
};
|
||||
}
|
||||
];
|
||||
@@ -146,8 +140,6 @@
|
||||
# before the overlay is mounted.
|
||||
"/run/nixos-etc-metadata"
|
||||
];
|
||||
# Skip for a non-NixOS init=, see the metadata mount above.
|
||||
ConditionPathExists = "/etc-metadata-image";
|
||||
};
|
||||
serviceConfig = {
|
||||
Type = "oneshot";
|
||||
|
||||
@@ -1645,7 +1645,6 @@ in
|
||||
"i686-linux"
|
||||
] ./initrd-network-openvpn { systemdStage1 = true; };
|
||||
systemd-initrd-networkd-ssh = runTest ./systemd-initrd-networkd-ssh.nix;
|
||||
systemd-initrd-non-nixos = runTest ./systemd-initrd-non-nixos.nix;
|
||||
systemd-initrd-shutdown = runTest {
|
||||
imports = [ ./systemd-shutdown.nix ];
|
||||
_module.args.systemdStage1 = true;
|
||||
|
||||
@@ -1,68 +0,0 @@
|
||||
{ lib, pkgs, ... }:
|
||||
let
|
||||
marker = "REACHED NON-NIXOS INIT AS PID 1";
|
||||
|
||||
# A non-NixOS init (no prepare-root). We use a store path, not literal
|
||||
# /bin/sh: a fresh disk has no /bin/sh yet (it is created by the activation a
|
||||
# non-NixOS init skips), while the store is always mounted; init=/bin/sh works
|
||||
# the same on a real system. Writes a marker, then stays alive so PID 1 lives.
|
||||
nonNixosInit = pkgs.writeShellScriptBin "non-nixos" ''
|
||||
echo "${marker}" > /dev/console
|
||||
exec ${pkgs.coreutils}/bin/sleep infinity
|
||||
'';
|
||||
|
||||
common = {
|
||||
boot.initrd.systemd.enable = true;
|
||||
|
||||
virtualisation = {
|
||||
# tmpfs root, like real non-NixOS closure init= microvm consumers.
|
||||
diskImage = null;
|
||||
|
||||
graphics = false;
|
||||
};
|
||||
|
||||
# Speed up wait_for_console.
|
||||
boot.consoleLogLevel = lib.mkForce 3;
|
||||
boot.initrd.systemd.managerEnvironment.SYSTEMD_LOG_LEVEL = "warning";
|
||||
|
||||
# switch-root needs an os-release on the target root. A real system has one
|
||||
# on disk; our fresh tmpfs does not, so create it.
|
||||
boot.initrd.systemd.tmpfiles.settings."10-os-release"."/sysroot/etc/os-release".f = {
|
||||
mode = "0644";
|
||||
argument = "ID=test-non-nixos";
|
||||
};
|
||||
};
|
||||
in
|
||||
{
|
||||
name = "systemd-initrd-non-nixos";
|
||||
|
||||
nodes = {
|
||||
bashActivation = common;
|
||||
|
||||
nixosInit = {
|
||||
imports = [ common ];
|
||||
system.nixos-init.enable = true;
|
||||
system.etc.overlay.enable = true;
|
||||
services.userborn.enable = true;
|
||||
};
|
||||
};
|
||||
|
||||
testScript = ''
|
||||
import os
|
||||
|
||||
# The last init= on the cmdline wins; QEMU_KERNEL_PARAMS is appended after
|
||||
# the default one, so this boots our non-NixOS init.
|
||||
os.environ["QEMU_KERNEL_PARAMS"] = "init=${lib.getExe nonNixosInit}"
|
||||
|
||||
start_all()
|
||||
|
||||
# If a code path does not skip the non-NixOS init, switch-root is blocked and
|
||||
# the machine drops to emergency mode: the marker never appears and the wait
|
||||
# times out.
|
||||
with subtest("bash initrd-nixos-activation skips a non-NixOS init"):
|
||||
bashActivation.wait_for_console_text("${marker}", timeout=300)
|
||||
|
||||
with subtest("nixos-init switches to a non-NixOS init directly"):
|
||||
nixosInit.wait_for_console_text("${marker}", timeout=300)
|
||||
'';
|
||||
}
|
||||
@@ -3,7 +3,7 @@ use std::{os::unix, path::Path};
|
||||
use anyhow::{Context, Result};
|
||||
|
||||
use crate::config::Config;
|
||||
use crate::{SYSROOT_PATH, find_init_in_prefix, resolve_in_prefix, verify_init_is_nixos};
|
||||
use crate::{SYSROOT_PATH, find_toplevel_in_prefix, resolve_in_prefix};
|
||||
|
||||
/// Entrypoint for the `find-etc` binary.
|
||||
///
|
||||
@@ -12,20 +12,7 @@ use crate::{SYSROOT_PATH, find_init_in_prefix, resolve_in_prefix, verify_init_is
|
||||
/// This avoids needing a reference to the toplevel embedded in the initrd and thus reduces the
|
||||
/// need to re-build it.
|
||||
pub fn find_etc() -> Result<()> {
|
||||
let init_in_sysroot =
|
||||
find_init_in_prefix(SYSROOT_PATH).context("Failed to find init in sysroot")?;
|
||||
|
||||
// A non-NixOS init= (e.g. init=/bin/sh) has no etc metadata image. Skip
|
||||
// without creating the symlinks: the etc-overlay mounts are gated on them
|
||||
// and so skip too, and initrd-init switches root to the init directly.
|
||||
let Ok(toplevel) = verify_init_is_nixos(SYSROOT_PATH, &init_in_sysroot) else {
|
||||
log::info!(
|
||||
"{} is not a NixOS system - not setting up the etc overlay.",
|
||||
init_in_sysroot.display()
|
||||
);
|
||||
return Ok(());
|
||||
};
|
||||
|
||||
let toplevel = find_toplevel_in_prefix(SYSROOT_PATH)?;
|
||||
let config = Config::from_toplevel(&toplevel, SYSROOT_PATH)?;
|
||||
|
||||
let basedir = config
|
||||
|
||||
@@ -27,6 +27,16 @@ pub use crate::{
|
||||
|
||||
pub const SYSROOT_PATH: &str = "/sysroot";
|
||||
|
||||
/// Find the path to the toplevel closure of the system in a prefix.
|
||||
///
|
||||
/// Uses the `init=` parameter on the kernel command-line.
|
||||
///
|
||||
/// Returns the relative path of the init to the prefix, e.g. without the `/sysroot` prefix.
|
||||
pub fn find_toplevel_in_prefix(prefix: &str) -> Result<PathBuf> {
|
||||
let init_in_sysroot = find_init_in_prefix(prefix)?;
|
||||
verify_init_is_nixos(prefix, init_in_sysroot)
|
||||
}
|
||||
|
||||
/// Verify that an init path is inside a `NixOS` toplevel directory.
|
||||
///
|
||||
/// If the path is verified, returns the path to the toplevel.
|
||||
@@ -77,16 +87,20 @@ pub fn find_init_in_prefix(prefix: &str) -> Result<PathBuf> {
|
||||
}
|
||||
|
||||
/// Extract the value of the `init` parameter from the given kernel `cmdline`.
|
||||
///
|
||||
/// If `init=` appears multiple times the last one wins, matching the kernel.
|
||||
/// This is what makes appending `init=/bin/sh` at the boot prompt work even
|
||||
/// though the boot entry already has an `init=`.
|
||||
fn extract_init(cmdline: &str) -> Result<PathBuf> {
|
||||
let init = cmdline
|
||||
let init_params: Vec<&str> = cmdline
|
||||
.split_ascii_whitespace()
|
||||
.filter_map(|p| p.strip_prefix("init="))
|
||||
.next_back()
|
||||
.with_context(|| format!("No init= parameter on kernel cmdline: {cmdline}"))?;
|
||||
.filter(|p| p.starts_with("init="))
|
||||
.collect();
|
||||
|
||||
if init_params.len() != 1 {
|
||||
bail!("Expected exactly one init param on kernel cmdline: {cmdline}")
|
||||
}
|
||||
|
||||
let init = init_params
|
||||
.first()
|
||||
.and_then(|s| s.split('=').next_back())
|
||||
.context("Failed to extract init path from kernel cmdline: {cmdline}")?;
|
||||
|
||||
Ok(PathBuf::from(init))
|
||||
}
|
||||
@@ -115,25 +129,4 @@ mod tests {
|
||||
|
||||
Ok(())
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn test_extract_init_single() {
|
||||
assert_eq!(
|
||||
extract_init("root=fstab init=/nix/store/xxx-nixos/init quiet").unwrap(),
|
||||
PathBuf::from("/nix/store/xxx-nixos/init")
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn test_extract_init_last_wins() {
|
||||
assert_eq!(
|
||||
extract_init("init=/nix/store/xxx-nixos/init init=/bin/sh").unwrap(),
|
||||
PathBuf::from("/bin/sh")
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn test_extract_init_missing() {
|
||||
assert!(extract_init("root=fstab quiet").is_err());
|
||||
}
|
||||
}
|
||||
|
||||
@@ -11,11 +11,11 @@
|
||||
|
||||
stdenv.mkDerivation (finalAttrs: {
|
||||
pname = "strace";
|
||||
version = "7.1";
|
||||
version = "7.0";
|
||||
|
||||
src = fetchurl {
|
||||
url = "https://strace.io/files/${finalAttrs.version}/strace-${finalAttrs.version}.tar.xz";
|
||||
hash = "sha256-gXQ+zypbRBhrL1A4r9yL7aflxwrtFbT7+8xuns4kSQ8=";
|
||||
hash = "sha256-bJJBm+Py7FYLMXKKRlIhfFmGTIZCunsbN3GxsBOtB0s=";
|
||||
};
|
||||
|
||||
separateDebugInfo = true;
|
||||
|
||||
@@ -5,43 +5,43 @@
|
||||
"lts": false
|
||||
},
|
||||
"6.1": {
|
||||
"version": "6.1.176",
|
||||
"hash": "sha256:1xj4ms4gd8ghd0l0dzsyi762dgpdrmqhc3f0arrp7sa0p8npf6da",
|
||||
"version": "6.1.175",
|
||||
"hash": "sha256:11fapr04y96p9ja6mfzm7bcd3zb4dzyw6qrh7c11bss9wjlq9s9p",
|
||||
"lts": true
|
||||
},
|
||||
"5.15": {
|
||||
"version": "5.15.210",
|
||||
"hash": "sha256:008a55av0x9fa3fspcz43sycik143gqxg2agcalrax2yw5ma82wi",
|
||||
"version": "5.15.209",
|
||||
"hash": "sha256:1d0yhbpqlkr1znahky15dfavr6dzb3wb8c15k9qqvkf2xb3pfv9l",
|
||||
"lts": true
|
||||
},
|
||||
"5.10": {
|
||||
"version": "5.10.259",
|
||||
"hash": "sha256:02dn8rf9p0afkl8kbdv28ijq974zfnv8zdsqcqbmapjm19c8wpma",
|
||||
"version": "5.10.258",
|
||||
"hash": "sha256:1rdldzb3g33v6zvcmxafqpkjgqpp4n5qlxwb77wfd5jpzhgcnz4y",
|
||||
"lts": true
|
||||
},
|
||||
"6.6": {
|
||||
"version": "6.6.143",
|
||||
"hash": "sha256:0ci9b6kjp7r2xwqifs2963l9ihk2rllk4zpl2kgzbny0r66izkns",
|
||||
"version": "6.6.142",
|
||||
"hash": "sha256:0w1bdzp9x1sqcr9xlk7dvylhs7kycghjabfgd3iv49ydfmx61xmj",
|
||||
"lts": true
|
||||
},
|
||||
"6.12": {
|
||||
"version": "6.12.94",
|
||||
"hash": "sha256:1ln83ljmc7wr1nrjjq1hp1m1vx54j7i6i15m3hqb73a1p4ra5679",
|
||||
"version": "6.12.93",
|
||||
"hash": "sha256:18sg154hqw8l98pfim2hjm1y604h5dwn9gj3gyncas8bgjl4h9j9",
|
||||
"lts": true
|
||||
},
|
||||
"6.18": {
|
||||
"version": "6.18.36",
|
||||
"hash": "sha256:0kn4r43lnd5nb5c298b30030qyaxv05s7k40n9si1j3iyk4qdazv",
|
||||
"version": "6.18.35",
|
||||
"hash": "sha256:0dpjprjzc4w44kw49jcgx1ffrm6gxn2gsnsz3hhmw4hr4a9h51pp",
|
||||
"lts": true
|
||||
},
|
||||
"7.0": {
|
||||
"version": "7.0.13",
|
||||
"hash": "sha256:04wrz38ldls7pv1yxa1m7p2hqn1731l93xnz93fs7b0nyz8fv09w",
|
||||
"version": "7.0.12",
|
||||
"hash": "sha256:1nk5lans9qg1avmmcwyadfps43d3hyjz9a5gjyvsc77w3sjckvap",
|
||||
"lts": false
|
||||
},
|
||||
"7.1": {
|
||||
"version": "7.1.1",
|
||||
"hash": "sha256:0z8x6wafxzc5vkim9jh8wpycdkk9y5bpxgsirmdpyznw84szl5aj",
|
||||
"version": "7.1",
|
||||
"hash": "sha256:18344l5fv3hgsqjrjr3dgg96lll7f294qq11lg40sydygxwl87v9",
|
||||
"lts": false
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user