Compare commits
1 Commits
Author | SHA1 | Date | |
---|---|---|---|
08403cd828 |
4
.github/workflows/test.yml
vendored
4
.github/workflows/test.yml
vendored
@ -17,8 +17,4 @@ jobs:
|
|||||||
- run: yarn test
|
- run: yarn test
|
||||||
- name: Install Nix
|
- name: Install Nix
|
||||||
uses: ./
|
uses: ./
|
||||||
- run: nix-env -iA cachix -f https://github.com/NixOS/nixpkgs/tarball/ab5863afada3c1b50fc43bf774b75ea71b287cde
|
|
||||||
- run: cat /etc/nix/nix.conf
|
|
||||||
# cachix should be available and be able to configure a cache
|
|
||||||
- run: cachix use cachix
|
|
||||||
- run: nix-build test.nix
|
- run: nix-build test.nix
|
47
lib/main.js
47
lib/main.js
@ -20,52 +20,35 @@ const core = __importStar(require("@actions/core"));
|
|||||||
const exec = __importStar(require("@actions/exec"));
|
const exec = __importStar(require("@actions/exec"));
|
||||||
const tc = __importStar(require("@actions/tool-cache"));
|
const tc = __importStar(require("@actions/tool-cache"));
|
||||||
const os_1 = require("os");
|
const os_1 = require("os");
|
||||||
function nixConf() {
|
const fs_1 = require("fs");
|
||||||
return __awaiter(this, void 0, void 0, function* () {
|
|
||||||
// Workaround a segfault: https://github.com/NixOS/nix/issues/2733
|
|
||||||
yield exec.exec("sudo", ["mkdir", "-p", "/etc/nix"]);
|
|
||||||
yield exec.exec("sudo", ["sh", "-c", "echo http2 = false >> /etc/nix/nix.conf"]);
|
|
||||||
// Set jobs to number of cores
|
|
||||||
yield exec.exec("sudo", ["sh", "-c", "echo max-jobs = auto >> /etc/nix/nix.conf"]);
|
|
||||||
// Allow binary caches for runner user
|
|
||||||
yield exec.exec("sudo", ["sh", "-c", "echo trusted-users = root runner >> /etc/nix/nix.conf"]);
|
|
||||||
});
|
|
||||||
}
|
|
||||||
function run() {
|
function run() {
|
||||||
return __awaiter(this, void 0, void 0, function* () {
|
return __awaiter(this, void 0, void 0, function* () {
|
||||||
try {
|
try {
|
||||||
|
const home = os_1.homedir();
|
||||||
|
const { username } = os_1.userInfo();
|
||||||
const PATH = process.env.PATH;
|
const PATH = process.env.PATH;
|
||||||
const INSTALL_PATH = '/opt/nix';
|
const INSTALL_PATH = '/opt/nix';
|
||||||
yield nixConf();
|
const CERTS_PATH = home + '/.nix-profile/etc/ssl/certs/ca-bundle.crt';
|
||||||
|
// Workaround a segfault: https://github.com/NixOS/nix/issues/2733
|
||||||
|
yield exec.exec("sudo", ["mkdir", "-p", "/etc/nix"]);
|
||||||
|
yield exec.exec("sudo", ["sh", "-c", "echo http2 = false >> /etc/nix/nix.conf"]);
|
||||||
|
// Set jobs to number of cores
|
||||||
|
yield exec.exec("sudo", ["sh", "-c", "echo max-jobs = auto >> /etc/nix/nix.conf"]);
|
||||||
// Catalina workaround https://github.com/NixOS/nix/issues/2925
|
// Catalina workaround https://github.com/NixOS/nix/issues/2925
|
||||||
if (os_1.type() == "Darwin") {
|
if (os_1.type() == "Darwin") {
|
||||||
yield exec.exec("sudo", ["sh", "-c", `echo \"nix\t${INSTALL_PATH}\" >> /etc/synthetic.conf`]);
|
yield exec.exec("sudo", ["sh", "-c", `echo \"nix\t${INSTALL_PATH}\" >> /etc/synthetic.conf`]);
|
||||||
yield exec.exec("sudo", ["sh", "-c", `mkdir -m 0755 ${INSTALL_PATH} && chown runner ${INSTALL_PATH}`]);
|
yield exec.exec("sudo", ["sh", "-c", `mkdir -m 0755 ${INSTALL_PATH} && chown runner ${INSTALL_PATH}`]);
|
||||||
yield exec.exec("/System/Library/Filesystems/apfs.fs/Contents/Resources/apfs.util", ["-B"]);
|
yield exec.exec("/System/Library/Filesystems/apfs.fs/Contents/Resources/apfs.util", ["-B"]);
|
||||||
// Needed for sudo to pass NIX_IGNORE_SYMLINK_STORE
|
|
||||||
yield exec.exec("sudo", ["sh", "-c", "echo 'Defaults env_keep += NIX_IGNORE_SYMLINK_STORE' >> /etc/sudoers"]);
|
|
||||||
core.exportVariable('NIX_IGNORE_SYMLINK_STORE', "1");
|
core.exportVariable('NIX_IGNORE_SYMLINK_STORE', "1");
|
||||||
// Needed for nix-daemon installation
|
|
||||||
yield exec.exec("sudo", ["launchctl", "setenv", "NIX_IGNORE_SYMLINK_STORE", "1"]);
|
|
||||||
}
|
}
|
||||||
// Needed due to multi-user being too defensive
|
|
||||||
core.exportVariable('ALLOW_PREEXISTING_INSTALLATION', "1");
|
|
||||||
// TODO: retry due to all the things that go wrong
|
// TODO: retry due to all the things that go wrong
|
||||||
const nixInstall = yield tc.downloadTool('https://nixos.org/nix/install');
|
const nixInstall = yield tc.downloadTool('https://nixos.org/nix/install');
|
||||||
yield exec.exec("sh", [nixInstall, "--daemon"]);
|
yield exec.exec("sh", [nixInstall]);
|
||||||
// write nix.conf again as installation overwrites it, reload the daemon to pick up changes
|
core.exportVariable('PATH', `${PATH}:${home}/.nix-profile/bin`);
|
||||||
yield nixConf();
|
core.exportVariable('NIX_PATH', `/nix/var/nix/profiles/per-user/${username}/channels`);
|
||||||
yield exec.exec("sudo", ["pkill", "-HUP", "nix-daemon"]);
|
// macOS needs certificates hints
|
||||||
// setup env
|
if (fs_1.existsSync(CERTS_PATH)) {
|
||||||
core.exportVariable('PATH', `${PATH}:/nix/var/nix/profiles/default/bin:/nix/var/nix/profiles/per-user/runner/profile/bin`);
|
core.exportVariable('NIX_SSL_CERT_FILE', CERTS_PATH);
|
||||||
core.exportVariable('NIX_PATH', `/nix/var/nix/profiles/per-user/root/channels`);
|
|
||||||
if (os_1.type() == "Darwin") {
|
|
||||||
// macOS needs certificates hints
|
|
||||||
core.exportVariable('NIX_SSL_CERT_FILE', '/nix/var/nix/profiles/default/etc/ssl/certs/ca-bundle.crt');
|
|
||||||
// TODO: nc doesn't work correctly on macOS :(
|
|
||||||
//await exec.exec("sh", ["-c", "while ! nc -zU /nix/var/nix/daemon-socket/socket; do sleep 0.5; done"]);
|
|
||||||
// macOS needs time to reload the daemon :(
|
|
||||||
yield exec.exec("sleep", ["10"]);
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
catch (error) {
|
catch (error) {
|
||||||
|
54
src/main.ts
54
src/main.ts
@ -1,9 +1,17 @@
|
|||||||
import * as core from '@actions/core';
|
import * as core from '@actions/core';
|
||||||
import * as exec from '@actions/exec';
|
import * as exec from '@actions/exec';
|
||||||
import * as tc from '@actions/tool-cache';
|
import * as tc from '@actions/tool-cache';
|
||||||
import {type} from 'os';
|
import {homedir, userInfo, type} from 'os';
|
||||||
|
import {existsSync} from 'fs';
|
||||||
|
|
||||||
|
async function run() {
|
||||||
|
try {
|
||||||
|
const home = homedir();
|
||||||
|
const {username} = userInfo();
|
||||||
|
const PATH = process.env.PATH;
|
||||||
|
const INSTALL_PATH = '/opt/nix';
|
||||||
|
const CERTS_PATH = home + '/.nix-profile/etc/ssl/certs/ca-bundle.crt';
|
||||||
|
|
||||||
async function nixConf() {
|
|
||||||
// Workaround a segfault: https://github.com/NixOS/nix/issues/2733
|
// Workaround a segfault: https://github.com/NixOS/nix/issues/2733
|
||||||
await exec.exec("sudo", ["mkdir", "-p", "/etc/nix"]);
|
await exec.exec("sudo", ["mkdir", "-p", "/etc/nix"]);
|
||||||
await exec.exec("sudo", ["sh", "-c", "echo http2 = false >> /etc/nix/nix.conf"]);
|
await exec.exec("sudo", ["sh", "-c", "echo http2 = false >> /etc/nix/nix.conf"]);
|
||||||
@ -11,54 +19,24 @@ async function nixConf() {
|
|||||||
// Set jobs to number of cores
|
// Set jobs to number of cores
|
||||||
await exec.exec("sudo", ["sh", "-c", "echo max-jobs = auto >> /etc/nix/nix.conf"]);
|
await exec.exec("sudo", ["sh", "-c", "echo max-jobs = auto >> /etc/nix/nix.conf"]);
|
||||||
|
|
||||||
// Allow binary caches for runner user
|
|
||||||
await exec.exec("sudo", ["sh", "-c", "echo trusted-users = root runner >> /etc/nix/nix.conf"]);
|
|
||||||
}
|
|
||||||
|
|
||||||
async function run() {
|
|
||||||
try {
|
|
||||||
const PATH = process.env.PATH;
|
|
||||||
const INSTALL_PATH = '/opt/nix';
|
|
||||||
|
|
||||||
await nixConf();
|
|
||||||
|
|
||||||
// Catalina workaround https://github.com/NixOS/nix/issues/2925
|
// Catalina workaround https://github.com/NixOS/nix/issues/2925
|
||||||
if (type() == "Darwin") {
|
if (type() == "Darwin") {
|
||||||
await exec.exec("sudo", ["sh", "-c", `echo \"nix\t${INSTALL_PATH}\" >> /etc/synthetic.conf`]);
|
await exec.exec("sudo", ["sh", "-c", `echo \"nix\t${INSTALL_PATH}\" >> /etc/synthetic.conf`]);
|
||||||
await exec.exec("sudo", ["sh", "-c", `mkdir -m 0755 ${INSTALL_PATH} && chown runner ${INSTALL_PATH}`]);
|
await exec.exec("sudo", ["sh", "-c", `mkdir -m 0755 ${INSTALL_PATH} && chown runner ${INSTALL_PATH}`]);
|
||||||
await exec.exec("/System/Library/Filesystems/apfs.fs/Contents/Resources/apfs.util", ["-B"]);
|
await exec.exec("/System/Library/Filesystems/apfs.fs/Contents/Resources/apfs.util", ["-B"]);
|
||||||
|
|
||||||
// Needed for sudo to pass NIX_IGNORE_SYMLINK_STORE
|
|
||||||
await exec.exec("sudo", ["sh", "-c", "echo 'Defaults env_keep += NIX_IGNORE_SYMLINK_STORE' >> /etc/sudoers"]);
|
|
||||||
core.exportVariable('NIX_IGNORE_SYMLINK_STORE', "1");
|
core.exportVariable('NIX_IGNORE_SYMLINK_STORE', "1");
|
||||||
// Needed for nix-daemon installation
|
|
||||||
await exec.exec("sudo", ["launchctl", "setenv", "NIX_IGNORE_SYMLINK_STORE", "1"]);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// Needed due to multi-user being too defensive
|
|
||||||
core.exportVariable('ALLOW_PREEXISTING_INSTALLATION', "1");
|
|
||||||
|
|
||||||
// TODO: retry due to all the things that go wrong
|
// TODO: retry due to all the things that go wrong
|
||||||
const nixInstall = await tc.downloadTool('https://nixos.org/nix/install');
|
const nixInstall = await tc.downloadTool('https://nixos.org/nix/install');
|
||||||
await exec.exec("sh", [nixInstall, "--daemon"]);
|
await exec.exec("sh", [nixInstall]);
|
||||||
|
core.exportVariable('PATH', `${PATH}:${home}/.nix-profile/bin`)
|
||||||
|
core.exportVariable('NIX_PATH', `/nix/var/nix/profiles/per-user/${username}/channels`)
|
||||||
|
|
||||||
// write nix.conf again as installation overwrites it, reload the daemon to pick up changes
|
// macOS needs certificates hints
|
||||||
await nixConf();
|
if (existsSync(CERTS_PATH)) {
|
||||||
await exec.exec("sudo", ["pkill", "-HUP", "nix-daemon"]);
|
core.exportVariable('NIX_SSL_CERT_FILE', CERTS_PATH);
|
||||||
|
|
||||||
// setup env
|
|
||||||
core.exportVariable('PATH', `${PATH}:/nix/var/nix/profiles/default/bin:/nix/var/nix/profiles/per-user/runner/profile/bin`)
|
|
||||||
core.exportVariable('NIX_PATH', `/nix/var/nix/profiles/per-user/root/channels`)
|
|
||||||
if (type() == "Darwin") {
|
|
||||||
// macOS needs certificates hints
|
|
||||||
core.exportVariable('NIX_SSL_CERT_FILE', '/nix/var/nix/profiles/default/etc/ssl/certs/ca-bundle.crt');
|
|
||||||
|
|
||||||
// TODO: nc doesn't work correctly on macOS :(
|
|
||||||
//await exec.exec("sh", ["-c", "while ! nc -zU /nix/var/nix/daemon-socket/socket; do sleep 0.5; done"]);
|
|
||||||
// macOS needs time to reload the daemon :(
|
|
||||||
await exec.exec("sleep", ["10"]);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
core.setFailed(`Action failed with error: ${error}`);
|
core.setFailed(`Action failed with error: ${error}`);
|
||||||
throw(error);
|
throw(error);
|
||||||
|
Reference in New Issue
Block a user