summaryrefslogtreecommitdiffstats
path: root/nixos/modules/installer/cd-dvd/channel.nix
blob: ce02bec09c6b017f191ad4ba198910aead18020c (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
# Provide an initial copy of the NixOS channel so that the user
# doesn't need to run "nix-channel --update" first.

{
  config,
  lib,
  pkgs,
  ...
}:

let
  # This is copied into the installer image, so it's important that it is filtered
  # to avoid including a large .git directory.
  # We also want the source name to be normalised to "source" to avoid depending on the
  # location of nixpkgs.
  # In the future we might want to expose the ISO image from the flake and use
  # `self.outPath` directly instead.
  nixpkgs = lib.cleanSource pkgs.path;

  # We need a copy of the Nix expressions for Nixpkgs and NixOS on the
  # CD.  These are installed into the "nixos" channel of the root
  # user, as expected by nixos-rebuild/nixos-install. FIXME: merge
  # with make-channel.nix.
  channelSources =
    pkgs.runCommand "nixos-${config.system.nixos.version}" { preferLocalBuild = true; }
      ''
        mkdir -p $out
        cp -prd ${nixpkgs.outPath} $out/nixos
        chmod -R u+w $out/nixos
        if [ ! -e $out/nixos/nixpkgs ]; then
          ln -s . $out/nixos/nixpkgs
        fi
        ${lib.optionalString (config.system.nixos.revision != null) ''
          echo -n ${config.system.nixos.revision} > $out/nixos/.git-revision
        ''}
        echo -n ${config.system.nixos.versionSuffix} > $out/nixos/.version-suffix
        echo ${config.system.nixos.versionSuffix} | sed -e s/pre// > $out/nixos/svn-revision
      '';
in

{
  options.system.installer.channel.enable =
    (lib.mkEnableOption "bundling NixOS/Nixpkgs channel in the installer")
    // {
      default = true;
    };
  config = lib.mkIf config.system.installer.channel.enable {
    # Pin the nixpkgs flake in the installer to our cleaned up nixpkgs source.
    # FIXME: this might be surprising and is really only needed for offline installations,
    # see discussion in https://github.com/NixOS/nixpkgs/pull/204178#issuecomment-1336289021
    nix.registry.nixpkgs.to = {
      type = "path";
      path = "${channelSources}/nixos";
    };

    # Provide the NixOS/Nixpkgs sources in /etc/nixos.  This is required
    # for nixos-install.  We use a systemd service rather than
    # boot.postBootCommands so that ordering relative to other
    # early-boot services (e.g. register-nix-paths in QEMU VMs) is
    # explicit.
    systemd.services.nix-channel-init = {
      description = "Initialize NixOS Channel";
      # Run early so the channel is available before regular services.
      # nix-env is invoked before nix-daemon.socket is up, so it
      # accesses the store directly (we are root).
      unitConfig.DefaultDependencies = false;
      wantedBy = [ "sysinit.target" ];
      before = [
        "sysinit.target"
        "shutdown.target"
        "nix-daemon.socket"
        "nix-daemon.service"
      ];
      after = [
        "local-fs.target"
        # In QEMU VMs the store DB is populated by register-nix-paths.
        # On real hardware this unit does not exist and the dependency
        # is silently ignored by systemd.
        "register-nix-paths.service"
      ];
      conflicts = [ "shutdown.target" ];
      restartIfChanged = false;
      serviceConfig = {
        Type = "oneshot";
        RemainAfterExit = true;
      };
      script = ''
        if ! [ -e /var/lib/nixos/did-channel-init ]; then
          echo "unpacking the NixOS/Nixpkgs sources..."
          mkdir -p /nix/var/nix/profiles/per-user/root
          ${lib.getExe' config.nix.package.out "nix-env"} -p /nix/var/nix/profiles/per-user/root/channels \
            -i ${channelSources} --quiet --option build-use-substitutes false \
            ${lib.optionalString config.boot.initrd.systemd.enable "--option sandbox false"} # There's an issue with pivot_root
          mkdir -m 0700 -p /root/.nix-defexpr
          ln -sfvT /nix/var/nix/profiles/per-user/root/channels /root/.nix-defexpr/channels
          mkdir -m 0755 -p /var/lib/nixos
          touch /var/lib/nixos/did-channel-init
        fi
      '';
    };
  };
}