fix(#1748): route all nix invocations through the host daemon (NIX_REMOTE=daemon)
Root contexts (systemd services running as root, PID 1) default to store=auto which resolves to the LOCAL nix store — bypassing the host daemon, its remote builders (muede-pc2), and any prebuilt derivation outputs already in the shared store. This causes spurious full rebuilds of agent toplevels that the host already built and cached. Two changes: harness-base.nix: - Add systemd.globalEnvironment.NIX_REMOTE = "daemon" — sets DefaultEnvironment in systemd.conf so every unit in the container inherits NIX_REMOTE=daemon. Non-root contexts already default to the daemon socket; this only matters for root services that would otherwise use the local store. - Add NIX_REMOTE = "daemon" to environment.variables so interactive shells also have it set (redundant with /etc/profile.d/nix-daemon.sh but explicit and profile-agnostic). hive-c0re.nix (hive-priv service): - Add NIX_REMOTE = "daemon" to the service environment. hive-priv runs as root and invokes nixos-container update + nix prebuild; these must route through the host daemon so they see the shared store and remote builders, not a private local store. The sandbox-fallback = true in harness-base.nix is kept as a belt- and-suspenders fallback but becomes a no-op for the common case once nix routes through the daemon (the daemon builds on the host where sandboxing works).
This commit is contained in:
parent
3e5ddbd2c0
commit
3a4b8d9873
2 changed files with 29 additions and 0 deletions
|
|
@ -1215,6 +1215,12 @@ in
|
|||
# errors out. Point HOME at the StateDirectory below (persistent,
|
||||
# so the cache survives across rebuilds).
|
||||
HOME = "/var/lib/hive-priv";
|
||||
# hive-priv runs as root. Root nix defaults to store=auto which
|
||||
# resolves to the LOCAL store — bypassing the host daemon, its
|
||||
# remote builders, and prebuilt derivation outputs. Force daemon
|
||||
# routing so nixos-container update and the nix prebuild see the
|
||||
# same store and substituters as every other build context.
|
||||
NIX_REMOTE = "daemon";
|
||||
};
|
||||
serviceConfig = {
|
||||
ExecStart = "${cfg.package}/bin/hive-priv";
|
||||
|
|
|
|||
Loading…
Reference in a new issue