Repository navigation
ci: stop mounting /etc/ssl/certs into the Nix sandbox - #166
Merged
Merged
Conversation
Since #159 turned the sandbox on, no fixed-output derivation can start. Nix mounts ssl-cert-file at /etc/ssl/certs/ca-certificates.crt for each of them, and extra-sandbox-paths has already mounted the host's /etc/ssl/certs, which holds that file, so creating the mount point fails: error: creating regular file "…/etc/ssl/certs/ca-certificates.crt": File exists No pull request has shown it, because the crate downloads they needed all came from Cachix. The dependency bump in #164 is the first to need new ones. The cold canary, which builds every crate download without Cachix, would fail on Monday: its last green run predates #159, and built them unsandboxed. Drop the extra sandbox path from both. The crate downloads still get the CA bundle through ssl-cert-file, and nothing else in the sandbox has a network to need one. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Since #159 turned the Nix sandbox on, no fixed-output derivation can start in CI. That includes every crate download:
How it happens:
ssl-cert-fileat/etc/ssl/certs/ca-certificates.crtfor each fixed-output derivation.extra-sandbox-paths = /etc/ssl/certsmounts the host directory first. That directory already holds the file.O_CREAT | O_EXCL, so that step fails.Why no pull request caught it:
This drops it from
ci.ymlandnix-canary.yml. The crate downloads still get the CA bundle throughssl-cert-file, and nothing else in the sandbox has a network to need one. No test or trycmd case reads/etc/ssl.Type of Change
Related Issues & Upstream References
How Has This Been Tested?
nix fmt(no changes), andactionlinton both workflows.O_EXCL.File exists.download-base64-0.23.1that failed on build(deps): Automatic dependency updates for 2026-10-06 #164.Contributor Checklist
dev(unless this is a release PR targetingmain)cargo clippy --all-targetspasses with no warningscargo nextest run(orcargo test) passescargo fmt --check/nix fmtpasses🤖 Generated with Claude Code