Skip to content

macOS marvels - #16109

Merged
Ericson2314 merged 4 commits into
NixOS:masterfrom
PhilipTaronQ:macos-marvels
Sep 28, 2026
Merged

Ericson2314 merged 4 commits into
NixOS:masterfrom
PhilipTaronQ:macos-marvels

Conversation

@PhilipTaronQ

@PhilipTaronQ PhilipTaronQ commented Jul 6, 2026 •

Copy link
Copy Markdown
Contributor

Motivation

I'm working on making Nix's bootstrap path real for macOS -- compiling outside of Nix, using the GHA xcode toolchain. I ran into the four issues that are highlighted in these commits while doing so. None are super high priority, but they're all blockers in their way.

AI Disclosure

This is all done with Claude Fable 5 and Opus 5.5 assistance.

Context

Each commit stands alone and can be reviewed by itself.

@github-actions github-actions Bot added the with-tests Issues related to testing. PRs with tests have some priority label Jul 6, 2026
@PhilipTaronQ

Copy link
Copy Markdown
Contributor Author

I've just read the new AI guidelines and will adjust the commits to have the requisite trailers.

@PhilipTaronQ

Copy link
Copy Markdown
Contributor Author

I'm now in conformance.

`sandbox_init_with_parameters` -- the only sandbox symbol Nix uses -- is exported by libSystem (via the re-exported `libsystem_sandbox`) on all supported macOS versions.

Note that `libsandbox` **doesn't even export it**. That library carries only the `sandbox_compile_*` / `sandbox_apply*` / `sandbox_*_params` APIs, none of which Nix calls.

The explicit link dates from f733553, when nixpkgs builds used the `darwin.apple_sdk.libs.sandbox` stubs; that pattern was dropped in 20b532e.

Worse, `libsandbox` ships only as a system dylib (that is, a SDK .tbd) -- no static variant exists anywhere -- so requiring it breaks two build setups:

 * `-Dprefer_static=true` (no static libsandbox to find)
 * bare Apple clang, whose `-print-search-dirs` does not reveal the SDK to meson's `find_library` directory scan.

What's the solution? Drop the `find_library` entirely and rely on libSystem. Easy enough.

Assisted-by: Claude Code (various models)
`vars.sh` tests `$NIX_STORE` bare while running under `set -u`, which aborts every functional test before it starts unless NIX_STORE is set.

That environment variable is always set inside nix builds and dev shells, which is why CI never sees this, but running the suite on a bare machine (e.g. a stock macOS runner) fails immediately.

Simple enough fix: do the normal shell guard.

Assisted-by: Claude Code (various models)
The sandbox profile language comments with ';'. The '#' line here was
tolerated by libsandbox's compiler through macOS 15, but macOS 26
rejects it as an "illegal sharp expression", failing sandbox
initialization for the test derivation.

Assisted-by: Claude Code (various models)
664532c removed the fake stdenv's 'mimic behavior of stdenv' loop that exported per-output variables for __structuredAttrs shells.

Since then, nothing sets a plain `$out` in a structured-attrs dev shell: develop.cc uses the outputs associative array only for path rewrites, and associative arrays cannot cross `execve` into `nix develop -c` children.

The same commit had to adjust the `print-dev-env` assertion from `.variables.out` to `.variables.outputs.value.out`, but *it left `structured-attrs.sh`'s `nix develop ... -c bash -c 'test -n "$out"'` untouched*!

As a consequence, that assertion has passed vacuously ever since, because `MixEnvironment::setEnviron()` merges the caller's environment and CI runs the suite inside nix builds ... where `$out` is already set. Sad.

On any environment without an ambient `$out` the test fails. That's how I ran into it.

What's the fix?  Restore the export loop in the fake setup, in the same form as real nixpkgs `setup.sh` (`export "$name=${outputs[$name]}"`).

With the caller's `$out` removed, and the assert that `$out` is the rewritten output path (`<cwd>/outputs/out`) rather than merely non-empty, the validation is validation indeed. No vacuity!

Assisted-by: Claude Code (various models)
@xokdvium

Copy link
Copy Markdown
Contributor

@PhilipTaronQ, this is now just test fixes and should be good to review right?

@Ericson2314
Ericson2314 added this pull request to the merge queue Sep 28, 2026
Merged via the queue into NixOS:master with commit 92962c5 Sep 28, 2026
17 checks passed
@Ericson2314

Copy link
Copy Markdown
Member

@xokdvium we talked about it at NixCon. This is small bug fixes and test fixes; nothing I would call a real behavior change.

@PhilipTaronQ

Copy link
Copy Markdown
Contributor Author

@PhilipTaronQ, this is now just test fixes and should be good to review right?

Yes, and build script fixes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

with-tests Issues related to testing. PRs with tests have some priority

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants