summaryrefslogtreecommitdiffstats
path: root/nixos/modules/system/activation/pre-switch-check.nix
blob: e80bec9eee9ace5671c29fbe905a4a283e42d7b5 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
{
  lib,
  config,
  pkgs,
  ...
}:
let
  preSwitchCheckScript = lib.concatLines (
    lib.mapAttrsToList (name: text: ''
      # pre-switch check ${name}
      #
      # Run with errexit in a subshell that is not part of an `if`/`||`
      # condition, so that `set -e` is actually honoured inside the
      # check body.
      set +e
      (
        set -e
        ${text}
      ) >&2
      _rc=$?
      set -e
      if [ "$_rc" -ne 0 ]; then
        echo "Pre-switch check '${name}' failed" >&2
        exit 1
      fi
    '') config.system.preSwitchChecks
  );
in
{
  options.system.preSwitchChecksScript = lib.mkOption {
    type = lib.types.pathInStore;
    internal = true;
    readOnly = true;
    default = lib.getExe (
      pkgs.writeShellApplication {
        name = "pre-switch-checks";
        text = preSwitchCheckScript;
      }
    );
  };

  options.system.preSwitchChecks = lib.mkOption {
    default = { };
    example = lib.literalExpression ''
      { failsEveryTime =
        '''
          false
        ''';
      }
    '';

    description = ''
      A set of shell script fragments that are executed before the switch to a
      new NixOS system configuration. A failure in any of these fragments will
      cause the switch to fail and exit early.
      The scripts receive the new configuration path and the action verb passed
      to switch-to-configuration, as the first and second positional arguments
      (meaning that you can access them using `$1` and `$2`, respectively).
    '';

    type = lib.types.attrsOf lib.types.str;
  };
}