Skip to content

Include Nix store registration in disk images - #487

Draft
rahultee wants to merge 3 commits into
mainfrom
nix-store-registration-metadata
Draft

rahultee wants to merge 3 commits into
mainfrom
nix-store-registration-metadata

Conversation

@rahultee

@rahultee rahultee commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Why

The disk images contain the Nix store path files but discard the registration data required to populate a local Nix store database. This metadata prepares the images for goval #24086's immutable lower-store design without changing mount behavior or publishing a disk revision.

What changed

Both production and development squashfs images, plus the production and development disk-script image builders, now include a versioned registration artifact at /nix-lower-registration/v1/:

  • format-version is 1.
  • registration is the native closureInfo.registration stream accepted by nix-store --load-db.
  • store-paths is the sorted list of canonical closure paths.
  • SHA256SUMS records SHA-256 digests for each of those three artifact files.

The Nix registration stream carries paths, NAR hashes and sizes, deriver fields as supplied by closureInfo (currently empty), and references. nix-store --load-db imports those records as valid paths. This format does not carry signatures; the digests detect file mismatch/tampering but are not a signature or source-authenticity mechanism.

The goval consumer should reject missing or unknown versions, digest mismatches, absent physical store paths, and references outside the registered closure before importing registration into an empty scratch DB. For the planned local-overlay store, mount the lower read-only at /mnt/nix-lower/nix/store and configure its realStoreDir accordingly; retain /mnt/nix/store as the persistent upper. This PR does not make the lower writable, add GC/delete enforcement, enable the overlay, or publish/promote a disk revision.

Test plan

  • nix-instantiate --parse on the modified Nix expressions — passed.
  • nix fmt -- --check . — passed; 0 of 85 Nix files need formatting.
  • bash -n on the production bundle builder and extracted focused-check shell — passed.
  • git diff --check — passed.
  • nix build --no-link --print-build-logs .#checks.x86_64-linux.disk-image-registration-fixture — passed in the sandbox. The tiny bundle contains a real Nix store reference; both disk.raw and disk.sqsh were built via pkgs/bundle-image, extracted, and checked for metadata/path/reference closure, scratch DB import and path validity, and metadata/store tampering.
  • Full production/development check is available as nix build .#disk-image-registration-full (optional/heavy). Its earlier full-closure attempt resolved 4,921 paths (64.7 GiB estimated unpacked) and timed out after 300 seconds while fetching, before that derivation began.
  • bash scripts/ci_check.sh — timed out at 300 seconds during its final nix eval .#bundle step after the format check, grep check, nix eval .#modules --json, and nix develop ... --command echo Hello, world had passed. Running nix eval .#bundle separately also passed.

Rollout

No rollout action is required. The images gain additive metadata only; goval must separately consume the artifact and preserve the lower read-only. This PR does not authorize or ship a new disk revision.

  • This is fully backward and forward compatible

CI status at handoff: all eight checks for head c8b638e were pending on the latest query. A checks job failed on the prior head; log access returned HTTP 403, so no cause is claimed.
Deferred follow-up hardening: registration is not required for the first Snix-removal staging run. That run leaves PID1/nixmodules paths unregistered, matching legacy behavior. No disk revision is promoted by this PR.

~ written by ⠕ Replit

@rahultee
rahultee marked this pull request as ready for review September 24, 2026 21:31
@rahultee
rahultee requested a review from a team as a code owner September 24, 2026 21:31
@rahultee
rahultee requested review from vlinkz and removed request for a team September 24, 2026 21:31
@rahultee
rahultee marked this pull request as draft September 24, 2026 22:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant