Repository navigation
Conversation
Assisted-by: Replit
Assisted-by: Replit
Assisted-by: Replit
rahultee
marked this pull request as ready for review
September 24, 2026 21:31
rahultee
marked this pull request as draft
September 24, 2026 22:03
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The disk images contain the Nix store path files but discard the registration data required to populate a local Nix store database. This metadata prepares the images for goval #24086's immutable lower-store design without changing mount behavior or publishing a disk revision.
What changed
Both production and development squashfs images, plus the production and development
disk-scriptimage builders, now include a versioned registration artifact at/nix-lower-registration/v1/:format-versionis1.registrationis the nativeclosureInfo.registrationstream accepted bynix-store --load-db.store-pathsis the sorted list of canonical closure paths.SHA256SUMSrecords SHA-256 digests for each of those three artifact files.The Nix registration stream carries paths, NAR hashes and sizes, deriver fields as supplied by
closureInfo(currently empty), and references.nix-store --load-dbimports those records as valid paths. This format does not carry signatures; the digests detect file mismatch/tampering but are not a signature or source-authenticity mechanism.The goval consumer should reject missing or unknown versions, digest mismatches, absent physical store paths, and references outside the registered closure before importing
registrationinto an empty scratch DB. For the planned local-overlay store, mount the lower read-only at/mnt/nix-lower/nix/storeand configure itsrealStoreDiraccordingly; retain/mnt/nix/storeas the persistent upper. This PR does not make the lower writable, add GC/delete enforcement, enable the overlay, or publish/promote a disk revision.Test plan
nix-instantiate --parseon the modified Nix expressions — passed.nix fmt -- --check .— passed; 0 of 85 Nix files need formatting.bash -non the production bundle builder and extracted focused-check shell — passed.git diff --check— passed.nix build --no-link --print-build-logs .#checks.x86_64-linux.disk-image-registration-fixture— passed in the sandbox. The tiny bundle contains a real Nix store reference; bothdisk.rawanddisk.sqshwere built viapkgs/bundle-image, extracted, and checked for metadata/path/reference closure, scratch DB import and path validity, and metadata/store tampering.nix build .#disk-image-registration-full(optional/heavy). Its earlier full-closure attempt resolved 4,921 paths (64.7 GiB estimated unpacked) and timed out after 300 seconds while fetching, before that derivation began.bash scripts/ci_check.sh— timed out at 300 seconds during its finalnix eval .#bundlestep after the format check, grep check,nix eval .#modules --json, andnix develop ... --command echo Hello, worldhad passed. Runningnix eval .#bundleseparately also passed.Rollout
No rollout action is required. The images gain additive metadata only; goval must separately consume the artifact and preserve the lower read-only. This PR does not authorize or ship a new disk revision.
CI status at handoff: all eight checks for head c8b638e were pending on the latest query. A checks job failed on the prior head; log access returned HTTP 403, so no cause is claimed.
Deferred follow-up hardening: registration is not required for the first Snix-removal staging run. That run leaves PID1/nixmodules paths unregistered, matching legacy behavior. No disk revision is promoted by this PR.
~ written by ⠕ Replit