Compare commits
	
		
			15 Commits
		
	
	
		
			v6
			...
			install_ur
		
	
	| Author | SHA1 | Date | |
|---|---|---|---|
|  | afb82faed7 | ||
|  | ebed63b0a2 | ||
|  | 5c21a08208 | ||
|  | 9affe1ce81 | ||
|  | ef735e86b9 | ||
|  | 4856b67e4a | ||
|  | 6e3de2b50b | ||
|  | d8ecc134bc | ||
|  | dba72516a1 | ||
|  | df989ac1d6 | ||
|  | a5f8eada85 | ||
|  | f57eb6b95e | ||
|  | 033d472283 | ||
|  | 39c9ce7c86 | ||
|  | 8b315ca141 | 
| @@ -17,8 +17,8 @@ jobs: | |||||||
|   tests: |   tests: | ||||||
|     runs-on: ubuntu-latest |     runs-on: ubuntu-latest | ||||||
|     steps: |     steps: | ||||||
|     - uses: actions/checkout@v1 |     - uses: actions/checkout@v2 | ||||||
|     - uses: cachix/install-nix-action@v3 |     - uses: cachix/install-nix-action@v7 | ||||||
|     - run: nix-build |     - run: nix-build | ||||||
| ``` | ``` | ||||||
|  |  | ||||||
|   | |||||||
| @@ -1,6 +1,9 @@ | |||||||
| name: 'Install Nix' | name: 'Install Nix' | ||||||
| description: 'Installs Nix on GitHub Actions for the supported platforms: Linux and macOS.' | description: 'Installs Nix on GitHub Actions for the supported platforms: Linux and macOS.' | ||||||
| author: 'Domen Kožar' | author: 'Domen Kožar' | ||||||
|  | inputs: | ||||||
|  |   install_url: | ||||||
|  |     description: 'Installation URL that will contain a script to install Nix' | ||||||
| branding: | branding: | ||||||
|   color: 'blue' |   color: 'blue' | ||||||
|   icon: 'sun' |   icon: 'sun' | ||||||
|   | |||||||
							
								
								
									
										102
									
								
								lib/create-darwin-volume.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										102
									
								
								lib/create-darwin-volume.sh
									
									
									
									
									
										Executable file
									
								
							| @@ -0,0 +1,102 @@ | |||||||
|  | #!/usr/bin/env bash | ||||||
|  | set -e | ||||||
|  |  | ||||||
|  | root_disks() { | ||||||
|  |     diskutil list -plist / | ||||||
|  | } | ||||||
|  |  | ||||||
|  | apfs_volumes_for() { | ||||||
|  |     disk=$1 | ||||||
|  |     diskutil apfs list -plist "$disk" | ||||||
|  | } | ||||||
|  |  | ||||||
|  | disk_identifier() { | ||||||
|  |     xpath "/plist/dict/key[text()='WholeDisks']/following-sibling::array[1]/string/text()" 2>/dev/null | ||||||
|  | } | ||||||
|  |  | ||||||
|  | volume_get() { | ||||||
|  |     key=$1 i=$2 | ||||||
|  |     xpath "/plist/dict/array/dict/key[text()='Volumes']/following-sibling::array/dict[$i]/key[text()='$key']/following-sibling::string[1]/text()" 2> /dev/null | ||||||
|  | } | ||||||
|  |  | ||||||
|  | find_nix_volume() { | ||||||
|  |     disk=$1 | ||||||
|  |     i=1 | ||||||
|  |     volumes=$(apfs_volumes_for "$disk") | ||||||
|  |     while true; do | ||||||
|  |         name=$(echo "$volumes" | volume_get "Name" "$i") | ||||||
|  |         if [ -z "$name" ]; then | ||||||
|  |             break | ||||||
|  |         fi | ||||||
|  |         case "$name" in | ||||||
|  |             [Nn]ix*) | ||||||
|  |                 echo "$name" | ||||||
|  |                 break | ||||||
|  |                 ;; | ||||||
|  |         esac | ||||||
|  |         i=$((i+1)) | ||||||
|  |     done | ||||||
|  | } | ||||||
|  |  | ||||||
|  | test_fstab() { | ||||||
|  |     grep -q "/nix" /etc/fstab 2>/dev/null | ||||||
|  | } | ||||||
|  |  | ||||||
|  | test_synthetic_conf() { | ||||||
|  |     grep -q "^nix" /etc/synthetic.conf 2>/dev/null | ||||||
|  | } | ||||||
|  |  | ||||||
|  | test_nix() { | ||||||
|  |     test -d "/nix" | ||||||
|  | } | ||||||
|  |  | ||||||
|  | main() { | ||||||
|  |     ( | ||||||
|  |         echo "" | ||||||
|  |         echo "     ------------------------------------------------------------------ " | ||||||
|  |         echo "    | This installer will create a volume for the nix store and        |" | ||||||
|  |         echo "    | configure it to mount at /nix.  Follow these steps to uninstall. |" | ||||||
|  |         echo "     ------------------------------------------------------------------ " | ||||||
|  |         echo "" | ||||||
|  |         echo "  1. Remove the entry from fstab using 'sudo vifs'" | ||||||
|  |         echo "  2. Destroy the data volume using 'diskutil apfs deleteVolume'" | ||||||
|  |         echo "  3. Delete /etc/synthetic.conf" | ||||||
|  |         echo "" | ||||||
|  |     ) >&2 | ||||||
|  |  | ||||||
|  |     if [ -L "/nix" ]; then | ||||||
|  |         echo "error: /nix is a symlink, please remove it or edit synthetic.conf (requires reboot)" >&2 | ||||||
|  |         echo "  /nix -> $(readlink "/nix")" >&2 | ||||||
|  |         exit 2 | ||||||
|  |     fi | ||||||
|  |  | ||||||
|  |     if ! test_synthetic_conf; then | ||||||
|  |         echo "Configuring /etc/synthetic.conf..." >&2 | ||||||
|  |         echo nix | sudo tee /etc/synthetic.conf | ||||||
|  |         /System/Library/Filesystems/apfs.fs/Contents/Resources/apfs.util -B | ||||||
|  |     fi | ||||||
|  |  | ||||||
|  |     if ! test_nix; then | ||||||
|  |         echo "Creating mountpoint for /nix..." >&2 | ||||||
|  |         sudo mkdir /nix | ||||||
|  |     fi | ||||||
|  |  | ||||||
|  |     disk=$(root_disks | disk_identifier) | ||||||
|  |     volume=$(find_nix_volume "$disk") | ||||||
|  |     if [ -z "$volume" ]; then | ||||||
|  |         echo "Creating a Nix Store volume..." >&2 | ||||||
|  |         sudo diskutil apfs addVolume "$disk" APFS 'Nix Store' -mountpoint /nix | ||||||
|  |         volume="Nix Store" | ||||||
|  |     else | ||||||
|  |         echo "Using existing '$volume' volume" >&2 | ||||||
|  |     fi | ||||||
|  |  | ||||||
|  |     if ! test_fstab; then | ||||||
|  |         echo "Configuring /etc/fstab..." >&2 | ||||||
|  |         label=$(echo "$volume" | sed 's/ /\\040/g') | ||||||
|  |         printf "\$a\nLABEL=%s /nix apfs rw\n.\nwq\n" "$label" | EDITOR=ed sudo vifs | ||||||
|  |         sudo defaults write /Library/Preferences/SystemConfiguration/autodiskmount AutomountDisksWithoutUserLogin -bool true | ||||||
|  |     fi | ||||||
|  | } | ||||||
|  |  | ||||||
|  | main "$@" | ||||||
							
								
								
									
										48
									
								
								lib/install-nix.sh
									
									
									
									
									
										Executable file
									
								
							
							
						
						
									
										48
									
								
								lib/install-nix.sh
									
									
									
									
									
										Executable file
									
								
							| @@ -0,0 +1,48 @@ | |||||||
|  | #!/usr/bin/env bash | ||||||
|  | set -euo pipefail | ||||||
|  |  | ||||||
|  | export here=$(dirname "${BASH_SOURCE[0]}") | ||||||
|  |  | ||||||
|  | nixConf() { | ||||||
|  |   sudo mkdir -p /etc/nix | ||||||
|  |   # Workaround a segfault: https://github.com/NixOS/nix/issues/2733 | ||||||
|  |   sudo sh -c 'echo http2 = false >> /etc/nix/nix.conf' | ||||||
|  |   # Set jobs to number of cores | ||||||
|  |   sudo sh -c 'echo max-jobs = auto >> /etc/nix/nix.conf' | ||||||
|  |   # Allow binary caches for runner user | ||||||
|  |   sudo sh -c 'echo trusted-users = root runner >> /etc/nix/nix.conf' | ||||||
|  | } | ||||||
|  |  | ||||||
|  | if [[ $OSTYPE =~ darwin ]]; then | ||||||
|  |   # Catalina workaround https://github.com/NixOS/nix/issues/2925 | ||||||
|  |   $here/create-darwin-volume.sh | ||||||
|  |  | ||||||
|  |   # Disable spotlight indexing of /nix to speed up performance | ||||||
|  |   sudo mdutil -i off /nix | ||||||
|  | fi | ||||||
|  |  | ||||||
|  | nixConf | ||||||
|  |  | ||||||
|  | # Needed due to multi-user being too defensive | ||||||
|  | export ALLOW_PREEXISTING_INSTALLATION=1 | ||||||
|  |  | ||||||
|  | sh <(curl -L ${INPUT_INSTALL_URL:-https://nixos.org/nix/install}) --daemon | ||||||
|  |  | ||||||
|  | # write nix.conf again as installation overwrites it | ||||||
|  | nixConf | ||||||
|  |  | ||||||
|  | # macOS needs certificates hints | ||||||
|  | if [[ $OSTYPE =~ darwin ]]; then | ||||||
|  |   cert_file=/nix/var/nix/profiles/default/etc/ssl/certs/ca-bundle.crt | ||||||
|  |   echo "::set-env name=NIX_SSL_CERT_FILE::$cert_file" | ||||||
|  |   export NIX_SSL_CERT_FILE=$cert_file | ||||||
|  |   sudo launchctl setenv NIX_SSL_CERT_FILE "$cert_file" | ||||||
|  | fi | ||||||
|  |  | ||||||
|  | # Reload the daemon to pick up changes | ||||||
|  | sudo pkill -HUP nix-daemon | ||||||
|  |  | ||||||
|  | # Set paths | ||||||
|  | echo "::add-path::/nix/var/nix/profiles/per-user/runner/profile/bin" | ||||||
|  | echo "::add-path::/nix/var/nix/profiles/default/bin" | ||||||
|  | echo "::set-env name=NIX_PATH::/nix/var/nix/profiles/per-user/root/channels" | ||||||
							
								
								
									
										79
									
								
								lib/main.js
									
									
									
									
									
								
							
							
						
						
									
										79
									
								
								lib/main.js
									
									
									
									
									
								
							| @@ -8,70 +8,23 @@ var __awaiter = (this && this.__awaiter) || function (thisArg, _arguments, P, ge | |||||||
|         step((generator = generator.apply(thisArg, _arguments || [])).next()); |         step((generator = generator.apply(thisArg, _arguments || [])).next()); | ||||||
|     }); |     }); | ||||||
| }; | }; | ||||||
| var __importStar = (this && this.__importStar) || function (mod) { |  | ||||||
|     if (mod && mod.__esModule) return mod; |  | ||||||
|     var result = {}; |  | ||||||
|     if (mod != null) for (var k in mod) if (Object.hasOwnProperty.call(mod, k)) result[k] = mod[k]; |  | ||||||
|     result["default"] = mod; |  | ||||||
|     return result; |  | ||||||
| }; |  | ||||||
| Object.defineProperty(exports, "__esModule", { value: true }); | Object.defineProperty(exports, "__esModule", { value: true }); | ||||||
| const core = __importStar(require("@actions/core")); | const child_process_1 = require("child_process"); | ||||||
| const exec = __importStar(require("@actions/exec")); | const process_1 = require("process"); | ||||||
| const tc = __importStar(require("@actions/tool-cache")); | const net_1 = require("net"); | ||||||
| const os_1 = require("os"); | function awaitSocket() { | ||||||
| function nixConf() { |  | ||||||
|     return __awaiter(this, void 0, void 0, function* () { |     return __awaiter(this, void 0, void 0, function* () { | ||||||
|         // Workaround a segfault: https://github.com/NixOS/nix/issues/2733 |         const daemonSocket = net_1.createConnection({ path: '/nix/var/nix/daemon-socket/socket' }); | ||||||
|         yield exec.exec("sudo", ["mkdir", "-p", "/etc/nix"]); |         daemonSocket.on('error', () => __awaiter(this, void 0, void 0, function* () { | ||||||
|         yield exec.exec("sudo", ["sh", "-c", "echo http2 = false >> /etc/nix/nix.conf"]); |             console.log('Waiting for daemon socket to be available, reconnecting...'); | ||||||
|         // Set jobs to number of cores |             yield new Promise(resolve => setTimeout(resolve, 500)); | ||||||
|         yield exec.exec("sudo", ["sh", "-c", "echo max-jobs = auto >> /etc/nix/nix.conf"]); |             yield awaitSocket(); | ||||||
|         // Allow binary caches for runner user |         })); | ||||||
|         yield exec.exec("sudo", ["sh", "-c", "echo trusted-users = root runner >> /etc/nix/nix.conf"]); |         daemonSocket.on('connect', () => { | ||||||
|  |             process_1.exit(0); | ||||||
|  |         }); | ||||||
|     }); |     }); | ||||||
| } | } | ||||||
| function run() { | child_process_1.execFileSync(`${__dirname}/install-nix.sh`, { stdio: 'inherit' }); | ||||||
|     return __awaiter(this, void 0, void 0, function* () { | // nc doesn't work correctly on macOS :( | ||||||
|         try { | awaitSocket(); | ||||||
|             const PATH = process.env.PATH; |  | ||||||
|             const INSTALL_PATH = '/opt/nix'; |  | ||||||
|             yield nixConf(); |  | ||||||
|             // Catalina workaround https://github.com/NixOS/nix/issues/2925 |  | ||||||
|             if (os_1.type() == "Darwin") { |  | ||||||
|                 yield exec.exec("sudo", ["sh", "-c", `echo \"nix\t${INSTALL_PATH}\"  >> /etc/synthetic.conf`]); |  | ||||||
|                 yield exec.exec("sudo", ["sh", "-c", `mkdir -m 0755 ${INSTALL_PATH} && chown runner ${INSTALL_PATH}`]); |  | ||||||
|                 yield exec.exec("/System/Library/Filesystems/apfs.fs/Contents/Resources/apfs.util", ["-B"]); |  | ||||||
|                 // Needed for sudo to pass NIX_IGNORE_SYMLINK_STORE |  | ||||||
|                 yield exec.exec("sudo", ["sh", "-c", "echo 'Defaults env_keep += NIX_IGNORE_SYMLINK_STORE'  >> /etc/sudoers"]); |  | ||||||
|                 core.exportVariable('NIX_IGNORE_SYMLINK_STORE', "1"); |  | ||||||
|                 // Needed for nix-daemon installation |  | ||||||
|                 yield exec.exec("sudo", ["launchctl", "setenv", "NIX_IGNORE_SYMLINK_STORE", "1"]); |  | ||||||
|             } |  | ||||||
|             // Needed due to multi-user being too defensive |  | ||||||
|             core.exportVariable('ALLOW_PREEXISTING_INSTALLATION', "1"); |  | ||||||
|             // TODO: retry due to all the things that go wrong |  | ||||||
|             const nixInstall = yield tc.downloadTool('https://nixos.org/nix/install'); |  | ||||||
|             yield exec.exec("sh", [nixInstall, "--daemon"]); |  | ||||||
|             // write nix.conf again as installation overwrites it, reload the daemon to pick up changes |  | ||||||
|             yield nixConf(); |  | ||||||
|             yield exec.exec("sudo", ["pkill", "-HUP", "nix-daemon"]); |  | ||||||
|             // setup env |  | ||||||
|             core.exportVariable('PATH', `${PATH}:/nix/var/nix/profiles/default/bin:/nix/var/nix/profiles/per-user/runner/profile/bin`); |  | ||||||
|             core.exportVariable('NIX_PATH', `/nix/var/nix/profiles/per-user/root/channels`); |  | ||||||
|             if (os_1.type() == "Darwin") { |  | ||||||
|                 // macOS needs certificates hints |  | ||||||
|                 core.exportVariable('NIX_SSL_CERT_FILE', '/nix/var/nix/profiles/default/etc/ssl/certs/ca-bundle.crt'); |  | ||||||
|                 // TODO: nc doesn't work correctly on macOS :( |  | ||||||
|                 //await exec.exec("sh", ["-c", "while ! nc -zU /nix/var/nix/daemon-socket/socket; do sleep 0.5; done"]); |  | ||||||
|                 // macOS needs time to reload the daemon :( |  | ||||||
|                 yield exec.exec("sleep", ["10"]); |  | ||||||
|             } |  | ||||||
|         } |  | ||||||
|         catch (error) { |  | ||||||
|             core.setFailed(`Action failed with error: ${error}`); |  | ||||||
|             throw (error); |  | ||||||
|         } |  | ||||||
|     }); |  | ||||||
| } |  | ||||||
| run(); |  | ||||||
|   | |||||||
| @@ -1,8 +0,0 @@ | |||||||
| "use strict"; |  | ||||||
| Object.defineProperty(exports, "__esModule", { value: true }); |  | ||||||
| function extrasperse(elem, array) { |  | ||||||
|     const init = []; |  | ||||||
|     return array.reduce((r, a) => r.concat(elem, a), init); |  | ||||||
| } |  | ||||||
| exports.extrasperse = extrasperse; |  | ||||||
| ; |  | ||||||
							
								
								
									
										80
									
								
								src/main.ts
									
									
									
									
									
								
							
							
						
						
									
										80
									
								
								src/main.ts
									
									
									
									
									
								
							| @@ -1,68 +1,20 @@ | |||||||
| import * as core from '@actions/core'; | import { execFileSync } from 'child_process'; | ||||||
| import * as exec from '@actions/exec'; | import { exit } from 'process'; | ||||||
| import * as tc from '@actions/tool-cache'; | import { createConnection } from 'net'; | ||||||
| import {type} from 'os'; |  | ||||||
|  |  | ||||||
| async function nixConf() { | async function awaitSocket() { | ||||||
|     // Workaround a segfault: https://github.com/NixOS/nix/issues/2733 |   const daemonSocket = createConnection({ path: '/nix/var/nix/daemon-socket/socket' }); | ||||||
|     await exec.exec("sudo", ["mkdir", "-p", "/etc/nix"]); |   daemonSocket.on('error', async () => { | ||||||
|     await exec.exec("sudo", ["sh", "-c", "echo http2 = false >> /etc/nix/nix.conf"]); |     console.log('Waiting for daemon socket to be available, reconnecting...'); | ||||||
|  |     await new Promise(resolve => setTimeout(resolve, 500)); | ||||||
|     // Set jobs to number of cores |     await awaitSocket(); | ||||||
|     await exec.exec("sudo", ["sh", "-c", "echo max-jobs = auto >> /etc/nix/nix.conf"]); |   }); | ||||||
|  |   daemonSocket.on('connect', () => { | ||||||
|     // Allow binary caches for runner user |     exit(0); | ||||||
|     await exec.exec("sudo", ["sh", "-c", "echo trusted-users = root runner >> /etc/nix/nix.conf"]); |   }); | ||||||
| } | } | ||||||
|  |  | ||||||
| async function run() { | execFileSync(`${__dirname}/install-nix.sh`, { stdio: 'inherit' }); | ||||||
|   try { |  | ||||||
|     const PATH = process.env.PATH;   |  | ||||||
|     const INSTALL_PATH = '/opt/nix'; |  | ||||||
|  |  | ||||||
|     await nixConf(); | // nc doesn't work correctly on macOS :( | ||||||
|  | awaitSocket(); | ||||||
|     // Catalina workaround https://github.com/NixOS/nix/issues/2925 |  | ||||||
|     if (type() == "Darwin") { |  | ||||||
|       await exec.exec("sudo", ["sh", "-c", `echo \"nix\t${INSTALL_PATH}\"  >> /etc/synthetic.conf`]); |  | ||||||
|       await exec.exec("sudo", ["sh", "-c", `mkdir -m 0755 ${INSTALL_PATH} && chown runner ${INSTALL_PATH}`]); |  | ||||||
|       await exec.exec("/System/Library/Filesystems/apfs.fs/Contents/Resources/apfs.util", ["-B"]); |  | ||||||
|  |  | ||||||
|       // Needed for sudo to pass NIX_IGNORE_SYMLINK_STORE |  | ||||||
|       await exec.exec("sudo", ["sh", "-c", "echo 'Defaults env_keep += NIX_IGNORE_SYMLINK_STORE'  >> /etc/sudoers"]); |  | ||||||
|       core.exportVariable('NIX_IGNORE_SYMLINK_STORE', "1"); |  | ||||||
|       // Needed for nix-daemon installation |  | ||||||
|       await exec.exec("sudo", ["launchctl", "setenv", "NIX_IGNORE_SYMLINK_STORE", "1"]); |  | ||||||
|     } |  | ||||||
|  |  | ||||||
|     // Needed due to multi-user being too defensive |  | ||||||
|     core.exportVariable('ALLOW_PREEXISTING_INSTALLATION', "1");  |  | ||||||
|  |  | ||||||
|     // TODO: retry due to all the things that go wrong |  | ||||||
|     const nixInstall = await tc.downloadTool('https://nixos.org/nix/install'); |  | ||||||
|     await exec.exec("sh", [nixInstall, "--daemon"]); |  | ||||||
|  |  | ||||||
|     // write nix.conf again as installation overwrites it, reload the daemon to pick up changes |  | ||||||
|     await nixConf(); |  | ||||||
|     await exec.exec("sudo", ["pkill", "-HUP", "nix-daemon"]); |  | ||||||
|  |  | ||||||
|     // setup env |  | ||||||
|     core.exportVariable('PATH', `${PATH}:/nix/var/nix/profiles/default/bin:/nix/var/nix/profiles/per-user/runner/profile/bin`) |  | ||||||
|     core.exportVariable('NIX_PATH', `/nix/var/nix/profiles/per-user/root/channels`) |  | ||||||
|     if (type() == "Darwin") { |  | ||||||
|       // macOS needs certificates hints |  | ||||||
|       core.exportVariable('NIX_SSL_CERT_FILE', '/nix/var/nix/profiles/default/etc/ssl/certs/ca-bundle.crt'); |  | ||||||
|  |  | ||||||
|       // TODO: nc doesn't work correctly on macOS :( |  | ||||||
|       //await exec.exec("sh", ["-c", "while ! nc -zU /nix/var/nix/daemon-socket/socket; do sleep 0.5; done"]); |  | ||||||
|       // macOS needs time to reload the daemon :( |  | ||||||
|       await exec.exec("sleep", ["10"]); |  | ||||||
|     } |  | ||||||
|  |  | ||||||
|   } catch (error) { |  | ||||||
|     core.setFailed(`Action failed with error: ${error}`); |  | ||||||
|     throw(error); |  | ||||||
|   }  |  | ||||||
| } |  | ||||||
|  |  | ||||||
| run(); |  | ||||||
		Reference in New Issue
	
	Block a user