Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion packaging/binary-tarball.nix
Original file line number Diff line number Diff line change
Expand Up @@ -80,10 +80,11 @@ runCommand "nix-binary-tarball-${version}" env ''
fn=$out/$dir.tar.xz
mkdir -p $out/nix-support
echo "file binary-dist $fn" >> $out/nix-support/hydra-build-products
# Store mtime is 1 second into the epoch.
tar cf - \
--sort=name \
--owner=0 --group=0 --mode=u+rw,uga+r \
--mtime='1970-01-01' \
--mtime='@1' \
--absolute-names \
--hard-dereference \
--transform "s,$TMPDIR/install,$dir/install," \
Expand Down
3 changes: 2 additions & 1 deletion packaging/rust-installer/tarball.nix
Original file line number Diff line number Diff line change
Expand Up @@ -36,10 +36,11 @@ runCommand "nix-installer-tarball-${nix.version}"
cp ${installerClosureInfo}/registration $TMPDIR/reginfo
# Store mtime is 1 second into the epoch.
tar cf - \
--sort=name \
--owner=0 --group=0 --mode=u+rw,uga+r \
--mtime='1970-01-01' \
--mtime='@1' \
--absolute-names \
--hard-dereference \
--transform "s,$TMPDIR/reginfo,$dir/.reginfo," \
Expand Down
4 changes: 4 additions & 0 deletions scripts/install-nix-from-tarball.sh
Original file line number Diff line number Diff line change
Expand Up @@ -194,6 +194,10 @@ for i in $(cd "$self/store" >/dev/null && echo ./*); do
mv "$i_tmp" "$dest/store/$i"
chmod -w "$dest/store/$i"
fi
# BusyBox tar is bad at preserving mtime because it doesn't seem to do the correct
# thing of doing a final fixup pass for fixing parent directory permissions and doesn't
# handle symlinks at all. So we can set the correct mtime here.
find "$dest/store/$i" -depth -exec touch -hmd "@1" {} +
Comment on lines +197 to +200

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@fgaz this issue affects alpine fwiw.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the heads-up. What does an incorrect mtime break?

done
echo "" >&2

Expand Down
81 changes: 49 additions & 32 deletions tests/installer/default.nix
Original file line number Diff line number Diff line change
Expand Up @@ -5,18 +5,39 @@
}:

let
commonCheck = ''
export NIX_CONFIG="substituters = "
installScripts = {
nix-env --version
nix --extra-experimental-features nix-command store info
nix-store --verify --check-contents
nix store verify --all --extra-experimental-features nix-command --no-trust
nix-channel --add file://$HOME/channel myChannel
nix-channel --update
[[ $(nix-instantiate --eval --expr 'builtins.readFile <myChannel/someFile>') = '"someContent"' ]]
bad_mtime=$( find /nix/store/ -mindepth 1 ! -path /nix/store/.links \
-exec sh -c '[ "$(stat -c %Y "{}")" -ne 1 ]' \; -print -quit )
if [ -n "$bad_mtime" ]; then
echo "bad filesystem object mtime after install:"
stat "$bad_mtime"
exit 1
fi
'';

installCases = {
install-default = {
script = ''
install = ''
tar -xf ./nix.tar.xz
mv ./nix-* nix
./nix/install --no-channel-add
'';
};

install-both-profile-links = {
script = ''
install = ''
tar -xf ./nix.tar.xz
mv ./nix-* nix
ln -s $HOME/.local/state/nix/profiles/a-profile $HOME/.nix-profile
Expand All @@ -27,15 +48,15 @@ let
};

install-force-no-daemon = {
script = ''
install = ''
tar -xf ./nix.tar.xz
mv ./nix-* nix
./nix/install --no-daemon --no-channel-add
'';
};

install-force-daemon = {
script = ''
install = ''
tar -xf ./nix.tar.xz
mv ./nix-* nix
./nix/install --daemon --no-channel-add
Expand All @@ -58,7 +79,12 @@ let
disableSELinux = "sudo setenforce 0";

images = {
"ubuntu-22-04" = {
# Images are named such that the DrvName logic that extracts the derivation
# name for logs doesn't treat the everything after the `-` as the version.
# That's accomplished by adding `v` after the dash. This makes logs more
# legible.

"ubuntu-v22_04" = {
"x86_64-linux" = {
image = import <nix/fetchurl.nix> {
url = "https://cloud-images.ubuntu.com/releases/jammy/release-20260913/ubuntu-22.04-server-cloudimg-amd64-disk-kvm.img";
Expand All @@ -67,7 +93,7 @@ let
};
};

"ubuntu-24-04" = {
"ubuntu-v24_04" = {
"x86_64-linux" = {
image = import <nix/fetchurl.nix> {
url = "https://cloud-images.ubuntu.com/releases/noble/release-20260911/ubuntu-24.04-server-cloudimg-amd64.img";
Expand All @@ -76,7 +102,7 @@ let
};
};

"fedora-44" = {
"fedora-v44" = {
"x86_64-linux" = {
image = import <nix/fetchurl.nix> {
url = "https://download.fedoraproject.org/pub/fedora/linux/releases/44/Cloud/x86_64/images/Fedora-Cloud-Base-Generic-44-1.7.x86_64.qcow2";
Expand All @@ -86,7 +112,7 @@ let
};
};

"rocky-8" = {
"rocky-v8" = {
"x86_64-linux" = {
image = import <nix/fetchurl.nix> {
url = "https://dl.rockylinux.org/pub/rocky/8/images/x86_64/Rocky-8-GenericCloud-Base-8.10-20240528.0.x86_64.qcow2";
Expand All @@ -96,7 +122,7 @@ let
};
};

"rocky-9" = {
"rocky-v9" = {
"x86_64-linux" = {
image = import <nix/fetchurl.nix> {
url = "https://dl.rockylinux.org/pub/rocky/9/images/x86_64/Rocky-9-GenericCloud-Base-9.8-20260525.0.x86_64.qcow2";
Expand All @@ -108,7 +134,7 @@ let
};
};

"rocky-10" = {
"rocky-v10" = {
"x86_64-linux" = {
image = import <nix/fetchurl.nix> {
url = "https://dl.rockylinux.org/pub/rocky/10/images/x86_64/Rocky-10-GenericCloud-Base-10.2-20260525.0.x86_64.qcow2";
Expand All @@ -121,17 +147,17 @@ let
};

# Docs on cloud-init quirks: https://gitlab.alpinelinux.org/alpine/aports/-/blob/master/community/cloud-init/README.Alpine?ref_type=heads
"alpine-3-23" = {
"alpine-v3_23" = {
"x86_64-linux" = {
image = import <nix/fetchurl.nix> {
url = "https://dl-cdn.alpinelinux.org/alpine/v3.23/releases/cloud/alpine-3.23.6-x86_64-bios-cloudinit-r0.qcow2";
hash = "sha512-+F0E0lvjkmC273NNkY1+X2lpdf7uuuMuQtkBL6dmnWBX8gEZ0bq2fihWJIttnJaCTcaEMpT5IoSGrZ4IvBfVpg==";
};
shell = "/bin/sh";
postBoot = "touch ~/.profile";
installScripts = {
installCases = {
# Multi-user installer doesn't support non-bash shells or OpenRC.
inherit (installScripts) install-default install-both-profile-links install-force-no-daemon;
inherit (installCases) install-default install-both-profile-links install-force-no-daemon;
};
};
};
Expand All @@ -145,6 +171,7 @@ let
}:
let
image = images.${imageName}.${system};
test = installCases.${testName};
in
with nixpkgsFor.${system}.native;
runCommand "installer-test-${imageName}-${testName}"
Expand All @@ -156,7 +183,8 @@ let
];
image = image.image;
postBoot = image.postBoot or "";
installScript = installScripts.${testName}.script;
installScript = test.install;
checkScript = commonCheck + (test.check or "");
binaryTarball = binaryTarballs.${system};
}
''
Expand Down Expand Up @@ -221,15 +249,15 @@ let
if [[ -n $postBoot ]]; then
echo "Running post-boot commands..."
$ssh "set -ex; $postBoot"
$ssh "set -eux; $postBoot"
fi
echo "Copying installer..."
scp -P $ssh_port $ssh_opts $binaryTarball/nix-*.tar.xz user@localhost:nix.tar.xz
echo "Running installer..."
$ssh <<EOF
set -eux;
set -eux
# TODO: The installer should probably autodetect instead of requiring manually specifying this.
if command -v sudo; then
Expand All @@ -241,24 +269,13 @@ let
$installScript
EOF
echo "Copying the mock channel"
ssh -p $ssh_port $ssh_opts user@localhost "mkdir channel"
scp -P $ssh_port $ssh_opts ${mockChannel pkgs}/channel/nixexprs.tar.bz2 user@localhost:channel/
echo "Copying the mock channel..."
scp -r -P $ssh_port $ssh_opts ${mockChannel pkgs}/channel user@localhost:./
echo "Testing Nix installation..."
$ssh <<EOF
set -eux
nix-env --version
nix --extra-experimental-features nix-command store info
out=\$(nix-build --no-substitute -E 'derivation { name = "foo"; system = "${system}"; builder = "/bin/sh"; args = ["-c" "echo foobar > \$out"]; }')
[ "\$(cat \$out)" = foobar ]
export NIX_CONFIG="substituters = "
\$(which nix-channel) --add file://\$HOME/channel myChannel
\$(which nix-channel) --update
[[ \$(nix-instantiate --eval --expr 'builtins.readFile <myChannel/someFile>') = '"someContent"' ]]
$checkScript
EOF
echo "Done!"
Expand All @@ -271,7 +288,7 @@ builtins.mapAttrs (
imageName: imageForSystems:
lib.concatMapAttrs (system: image: {
${system} = builtins.mapAttrs (testName: test: makeTest { inherit imageName testName system; }) (
image.installScripts or installScripts
image.installCases or installCases
);
}) imageForSystems
) images
Loading