Skip to content

ci: stop mounting /etc/ssl/certs into the Nix sandbox - #166

Merged
fxrdhan merged 1 commit into
devfrom
claude/fix-nix-fod-sandbox
Oct 6, 2026
Merged

fxrdhan merged 1 commit into
devfrom
claude/fix-nix-fod-sandbox

Conversation

@fxrdhan

@fxrdhan fxrdhan commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

Summary

Since #159 turned the Nix sandbox on, no fixed-output derivation can start in CI. That includes every crate download:

error: creating regular file "/nix/store/…-download-base64-0.23.1.drv.chroot/root/etc/ssl/certs/ca-certificates.crt": File exists

How it happens:

  • Nix mounts ssl-cert-file at /etc/ssl/certs/ca-certificates.crt for each fixed-output derivation.
  • extra-sandbox-paths = /etc/ssl/certs mounts the host directory first. That directory already holds the file.
  • Nix creates the mount point with O_CREAT | O_EXCL, so that step fails.

Why no pull request caught it:

This drops it from ci.yml and nix-canary.yml. The crate downloads still get the CA bundle through ssl-cert-file, and nothing else in the sandbox has a network to need one. No test or trycmd case reads /etc/ssl.

Type of Change

  • 🐛 Bug fix (non-breaking change fixing an issue)
  • ✨ New feature (non-breaking change adding functionality)
  • ⚡ Performance improvement
  • ♻️ Code refactor / clean-up
  • 💥 Breaking change (fix or feature that would cause existing functionality to change)
  • 📝 Documentation / Man pages / Completions
  • 🔧 Build / CI / Dependencies

Related Issues & Upstream References

How Has This Been Tested?

  • Testing commands executed:
  • Platforms verified: Linux (the Nix jobs). This pull request's own Nix job takes its crate downloads from Cachix, so it does not exercise the fix; the two runs above do.

Contributor Checklist

  • Base branch is set to dev (unless this is a release PR targeting main)
  • My commits follow Conventional Commits format
  • Tests covering the changes have been added/updated
  • cargo clippy --all-targets passes with no warnings
  • cargo nextest run (or cargo test) passes
  • cargo fmt --check / nix fmt passes
  • License headers (SPDX / REUSE) are properly preserved/added

🤖 Generated with Claude Code

Since #159 turned the sandbox on, no fixed-output derivation can start.
Nix mounts ssl-cert-file at /etc/ssl/certs/ca-certificates.crt for each
of them, and extra-sandbox-paths has already mounted the host's
/etc/ssl/certs, which holds that file, so creating the mount point
fails:

    error: creating regular file "…/etc/ssl/certs/ca-certificates.crt": File exists

No pull request has shown it, because the crate downloads they needed
all came from Cachix. The dependency bump in #164 is the first to need
new ones. The cold canary, which builds every crate download without
Cachix, would fail on Monday: its last green run predates #159, and
built them unsandboxed.

Drop the extra sandbox path from both. The crate downloads still get
the CA bundle through ssl-cert-file, and nothing else in the sandbox
has a network to need one.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@fxrdhan
fxrdhan merged commit 0f303f5 into dev Oct 6, 2026
18 checks passed
@fxrdhan
fxrdhan deleted the claude/fix-nix-fod-sandbox branch October 6, 2026 07:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant