From cab5f67c3415d59e37791491c69b889956a4c8cb Mon Sep 17 00:00:00 2001 From: Eelco Dolstra Date: Tue, 10 Feb 2026 21:42:11 +0100 Subject: [PATCH 1/2] Always record BuildProvenance This contains useful info (such as the build host) even if we don't know where the .drv file came from. --- src/libstore/unix/build/derivation-builder.cc | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/libstore/unix/build/derivation-builder.cc b/src/libstore/unix/build/derivation-builder.cc index bb18f2109429..833e05f8fb26 100644 --- a/src/libstore/unix/build/derivation-builder.cc +++ b/src/libstore/unix/build/derivation-builder.cc @@ -1867,7 +1867,7 @@ SingleDrvOutputs DerivationBuilderImpl::registerOutputs() newInfo.deriver = drvPath; newInfo.ultimate = true; - if (drvProvenance) + if (experimentalFeatureSettings.isEnabled(Xp::Provenance)) newInfo.provenance = std::make_shared(drvPath, outputName, settings.getHostName(), drvProvenance); store.signPathInfo(newInfo); From 0d6c3123d6e68057d7cbfd060ad30aa40dce897d Mon Sep 17 00:00:00 2001 From: Eelco Dolstra Date: Tue, 10 Feb 2026 21:51:33 +0100 Subject: [PATCH 2/2] Add 'system' field to BuildProvenance This makes it possible to see what system type a store path is built for. This information previously wasn't readily available from the Nix database or binary cache. --- src/libstore/include/nix/store/provenance.hh | 7 +++++++ src/libstore/provenance.cc | 7 ++++++- src/libstore/unix/build/derivation-builder.cc | 4 ++-- src/nix/provenance-show.md | 2 +- src/nix/provenance.cc | 5 +++-- tests/functional/flakes/provenance.sh | 4 +++- 6 files changed, 22 insertions(+), 7 deletions(-) diff --git a/src/libstore/include/nix/store/provenance.hh b/src/libstore/include/nix/store/provenance.hh index 602a5bf3381c..f742888b362a 100644 --- a/src/libstore/include/nix/store/provenance.hh +++ b/src/libstore/include/nix/store/provenance.hh @@ -23,6 +23,11 @@ struct BuildProvenance : Provenance */ std::optional buildHost; + /** + * The system type of the derivation. + */ + std::string system; + /** * The provenance of the derivation, if known. */ @@ -34,10 +39,12 @@ struct BuildProvenance : Provenance const StorePath & drvPath, const OutputName & output, std::optional buildHost, + std::string system, std::shared_ptr next) : drvPath(drvPath) , output(output) , buildHost(std::move(buildHost)) + , system(std::move(system)) , next(std::move(next)) { } diff --git a/src/libstore/provenance.cc b/src/libstore/provenance.cc index 4a5bcf31ebd2..0fa38658d769 100644 --- a/src/libstore/provenance.cc +++ b/src/libstore/provenance.cc @@ -10,6 +10,7 @@ nlohmann::json BuildProvenance::to_json() const {"drv", drvPath.to_string()}, {"output", output}, {"buildHost", buildHost}, + {"system", system}, {"next", next ? next->to_json() : nlohmann::json(nullptr)}, }; } @@ -23,7 +24,11 @@ Provenance::Register registerBuildProvenance("build", [](nlohmann::json json) { if (auto p = optionalValueAt(obj, "buildHost")) buildHost = p->get>(); auto buildProv = make_ref( - StorePath(getString(valueAt(obj, "drv"))), getString(valueAt(obj, "output")), buildHost, next); + StorePath(getString(valueAt(obj, "drv"))), + getString(valueAt(obj, "output")), + buildHost, + getString(valueAt(obj, "system")), + next); return buildProv; }); diff --git a/src/libstore/unix/build/derivation-builder.cc b/src/libstore/unix/build/derivation-builder.cc index 833e05f8fb26..f7218df13698 100644 --- a/src/libstore/unix/build/derivation-builder.cc +++ b/src/libstore/unix/build/derivation-builder.cc @@ -1868,8 +1868,8 @@ SingleDrvOutputs DerivationBuilderImpl::registerOutputs() newInfo.deriver = drvPath; newInfo.ultimate = true; if (experimentalFeatureSettings.isEnabled(Xp::Provenance)) - newInfo.provenance = - std::make_shared(drvPath, outputName, settings.getHostName(), drvProvenance); + newInfo.provenance = std::make_shared( + drvPath, outputName, settings.getHostName(), drv.platform, drvProvenance); store.signPathInfo(newInfo); finish(newInfo.path); diff --git a/src/nix/provenance-show.md b/src/nix/provenance-show.md index b57f009db0f2..95675430cdf1 100644 --- a/src/nix/provenance-show.md +++ b/src/nix/provenance-show.md @@ -8,7 +8,7 @@ R""( # nix provenance show /run/current-system /nix/store/k145bdxhdb89i4fkvgdisdz1yh2wiymm-nixos-system-machine-25.05.20251210.d2b1213 ← copied from cache.flakehub.com - ← built from derivation /nix/store/w3p3xkminq61hs00kihd34w1dglpj5s9-nixos-system-machine-25.05.20251210.d2b1213.drv (output out) on build-machine + ← built from derivation /nix/store/w3p3xkminq61hs00kihd34w1dglpj5s9-nixos-system-machine-25.05.20251210.d2b1213.drv (output out) on build-machine for x86_64-linux ← instantiated from flake output github:my-org/my-repo/6b03eb949597fe96d536e956a2c14da9901dbd21?dir=machine#nixosConfigurations.machine.config.system.build.toplevel ``` diff --git a/src/nix/provenance.cc b/src/nix/provenance.cc index 803bc9676ccf..205ac76de23c 100644 --- a/src/nix/provenance.cc +++ b/src/nix/provenance.cc @@ -58,10 +58,11 @@ struct CmdProvenanceShow : StorePathsCommand } else if (auto build = std::dynamic_pointer_cast(provenance)) { logger->cout( "← built from derivation " ANSI_BOLD "%s" ANSI_NORMAL " (output " ANSI_BOLD "%s" ANSI_NORMAL - ") on " ANSI_BOLD "%s" ANSI_NORMAL, + ") on " ANSI_BOLD "%s" ANSI_NORMAL " for " ANSI_BOLD "%s" ANSI_NORMAL, store.printStorePath(build->drvPath), build->output, - build->buildHost.value_or("unknown host").c_str()); + build->buildHost.value_or("unknown host").c_str(), + build->system); provenance = build->next; } else if (auto flake = std::dynamic_pointer_cast(provenance)) { // Collapse subpath/tree provenance into the flake provenance for legibility. diff --git a/tests/functional/flakes/provenance.sh b/tests/functional/flakes/provenance.sh index af4e3767220a..20026f41d227 100644 --- a/tests/functional/flakes/provenance.sh +++ b/tests/functional/flakes/provenance.sh @@ -40,6 +40,7 @@ builder=$(nix eval --raw "$flake1Dir#packages.$system.default._builder") "type": "flake" }, "output": "out", + "system": "$system", "type": "build" } EOF @@ -115,6 +116,7 @@ nix copy --from "file://$binaryCache" "$outPath" --no-check-sigs "type": "flake" }, "output": "out", + "system": "$system", "type": "build" }, "type": "copied" @@ -126,7 +128,7 @@ EOF [[ $(nix provenance show "$outPath") = $(cat <