macOS marvels - #16109
Merged
Merged
macOS marvels#16109
Conversation
Contributor
Author
|
I've just read the new AI guidelines and will adjust the commits to have the requisite trailers. |
PhilipTaronQ
force-pushed
the
macos-marvels
branch
from
July 7, 2026 00:03
b37a495 to
5fec1da
Compare
Contributor
Author
|
I'm now in conformance. |
`sandbox_init_with_parameters` -- the only sandbox symbol Nix uses -- is exported by libSystem (via the re-exported `libsystem_sandbox`) on all supported macOS versions. Note that `libsandbox` **doesn't even export it**. That library carries only the `sandbox_compile_*` / `sandbox_apply*` / `sandbox_*_params` APIs, none of which Nix calls. The explicit link dates from f733553, when nixpkgs builds used the `darwin.apple_sdk.libs.sandbox` stubs; that pattern was dropped in 20b532e. Worse, `libsandbox` ships only as a system dylib (that is, a SDK .tbd) -- no static variant exists anywhere -- so requiring it breaks two build setups: * `-Dprefer_static=true` (no static libsandbox to find) * bare Apple clang, whose `-print-search-dirs` does not reveal the SDK to meson's `find_library` directory scan. What's the solution? Drop the `find_library` entirely and rely on libSystem. Easy enough. Assisted-by: Claude Code (various models)
`vars.sh` tests `$NIX_STORE` bare while running under `set -u`, which aborts every functional test before it starts unless NIX_STORE is set. That environment variable is always set inside nix builds and dev shells, which is why CI never sees this, but running the suite on a bare machine (e.g. a stock macOS runner) fails immediately. Simple enough fix: do the normal shell guard. Assisted-by: Claude Code (various models)
The sandbox profile language comments with ';'. The '#' line here was tolerated by libsandbox's compiler through macOS 15, but macOS 26 rejects it as an "illegal sharp expression", failing sandbox initialization for the test derivation. Assisted-by: Claude Code (various models)
664532c removed the fake stdenv's 'mimic behavior of stdenv' loop that exported per-output variables for __structuredAttrs shells. Since then, nothing sets a plain `$out` in a structured-attrs dev shell: develop.cc uses the outputs associative array only for path rewrites, and associative arrays cannot cross `execve` into `nix develop -c` children. The same commit had to adjust the `print-dev-env` assertion from `.variables.out` to `.variables.outputs.value.out`, but *it left `structured-attrs.sh`'s `nix develop ... -c bash -c 'test -n "$out"'` untouched*! As a consequence, that assertion has passed vacuously ever since, because `MixEnvironment::setEnviron()` merges the caller's environment and CI runs the suite inside nix builds ... where `$out` is already set. Sad. On any environment without an ambient `$out` the test fails. That's how I ran into it. What's the fix? Restore the export loop in the fake setup, in the same form as real nixpkgs `setup.sh` (`export "$name=${outputs[$name]}"`). With the caller's `$out` removed, and the assert that `$out` is the rewritten output path (`<cwd>/outputs/out`) rather than merely non-empty, the validation is validation indeed. No vacuity! Assisted-by: Claude Code (various models)
PhilipTaronQ
force-pushed
the
macos-marvels
branch
from
September 26, 2026 11:50
5fec1da to
ef5726a
Compare
Contributor
|
@PhilipTaronQ, this is now just test fixes and should be good to review right? |
Ericson2314
approved these changes
Sep 28, 2026
Member
|
@xokdvium we talked about it at NixCon. This is small bug fixes and test fixes; nothing I would call a real behavior change. |
Contributor
Author
Yes, and build script fixes. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
I'm working on making Nix's bootstrap path real for macOS -- compiling outside of Nix, using the GHA xcode toolchain. I ran into the four issues that are highlighted in these commits while doing so. None are super high priority, but they're all blockers in their way.
AI Disclosure
This is all done with Claude Fable 5 and Opus 5.5 assistance.
Context
Each commit stands alone and can be reviewed by itself.