A modern, delicious implementation of the Nix package manager, focused on correctness, usability, and growth — and committed to doing right by its community
Find a file
jade e3b702fa22 Actually try making a userns before assuming they don't work
If unprivileged userns are *believed* to be disabled (such as with
"kernel.unprivileged_userns_clone = 0"), Lix would previously *give up*
on trying to use a user namespace before actually trying it, even if, in
cases such as unprivileged_userns_clone, it would actually be allowed
since Nix has CAP_SYS_ADMIN when running as daemon.

(see, e.g. 25d4709a4f)

We changed it to actually try it first, and then diagnose possible
causes, and also to be more loud about the whole thing, using warnings
instead of debugs. These warnings will only print on the first build run
by the daemon, which is, tbh, eh, shrug.

This is what led to us realizing that no-userns was a poorly exercised
condition.

Change-Id: I8e4f21afc89c574020dc7e89a560cc740ce6573a
2024-05-05 00:37:24 +00:00
.github remove Github workflow files 2024-04-28 02:56:19 -06:00
bench Add benchmarking scripts 2024-04-08 19:50:24 -07:00
clang-tidy
contrib
doc Merge "Revert "Revert "Merge pull request #6621 from Kha/nested-follows""" into main 2024-05-04 08:52:29 +00:00
lix-doc Format Nix code with nixfmt 2024-04-08 13:00:00 -07:00
m4
maintainers docs: don't compute rl-next.md during build 2024-04-09 02:09:36 +00:00
meson
misc Format Nix code with nixfmt 2024-04-08 13:00:00 -07:00
mk
nix-support binary tarball: include cacert in root paths 2024-04-12 07:04:37 -06:00
perl Format Nix code with nixfmt 2024-04-08 13:00:00 -07:00
scripts meson: correctly differentiate $profiledir and $sysconfdir/profile.d 2024-04-09 02:25:58 -06:00
src Actually try making a userns before assuming they don't work 2024-05-05 00:37:24 +00:00
tests Fix /etc/group having desynced IDs from the actual UID in the sandbox 2024-05-04 17:36:50 -07:00
.clang-format
.clang-tidy
.dir-locals.el
.editorconfig
.envrc
.gitignore docs: redo content generation for mdbook and manual 2024-04-11 13:32:06 +00:00
.version
boehmgc-coroutine-sp-fallback.diff
boehmgc-traceable_allocator-public.diff
configure.ac
CONTRIBUTING.md
COPYING
default.nix Format Nix code with nixfmt 2024-04-08 13:00:00 -07:00
docker.nix Format Nix code with nixfmt 2024-04-08 13:00:00 -07:00
flake.lock pre-commit: stop using the flake 2024-04-08 15:29:23 -07:00
flake.nix libstore/local-derivation-goal: prohibit creating setuid/setgid binaries 2024-05-03 16:29:06 +02:00
justfile justfile: allow passing args to meson compile 2024-04-25 14:26:38 +02:00
local.mk build: enable libstdc++ assertions 2024-04-08 15:40:12 -07:00
Makefile
Makefile.config.in
meson.build libstore/local-derivation-goal: prohibit creating setuid/setgid binaries 2024-05-03 16:29:06 +02:00
meson.options meson: correctly embed sandbox shell when asked 2024-04-18 16:15:58 -06:00
package.nix package: remove assert for libseccomp version 2024-05-04 11:25:29 +02:00
precompiled-headers.h
README.md
shell.nix
treefmt.toml Format Nix code with nixfmt 2024-04-08 13:00:00 -07:00

Nix

Open Collective supporters Test

Nix is a powerful package manager for Linux and other Unix systems that makes package management reliable and reproducible. Please refer to the Nix manual for more details.

Installation

On Linux and macOS the easiest way to install Nix is to run the following shell command (as a user other than root):

$ curl -L https://nixos.org/nix/install | sh

Information on additional installation methods is available on the Nix download page.

Building And Developing

See our Hacking guide in our manual for instruction on how to to set up a development environment and build Nix from source.

Additional Resources

License

Nix is released under the LGPL v2.1.