With `waitForNixStore = false` an agent is started through a launcher
script so that macOS lists it under its own name in System Settings >
Login Items & Extensions. Two properties of that launcher were fixed and
unreachable from configuration: its base name (the agent's attribute name)
and its interpreter (`/bin/sh`).
Both matter on macOS. The name is what "Allow in the Background" shows, so
a fleet-wide prefix such as `nix-` makes every Home Manager agent
recognisable next to third-party items. The interpreter is the binary the
system attributes the agent's process to; a store-resident shell attributes
it to the launcher itself rather than to Apple's `/bin/sh`, which changes
how the privacy prompts for folders like `~/Downloads` apply. Users who
need either property today have to vendor this module.
`launcher.name` (default: the attribute name, as before) and
`launcher.shell` (default: `/bin/sh`, as before) make both configurable
without changing any existing agent.
By default agents are started via /bin/sh with /bin/wait4path, which
makes every Home Manager agent show up as "sh" in System Settings >
Login Items & Extensions. Allow opting out per agent, in which case
the command is exec'd through a launcher script named after the agent
so it is displayed under its own name.
When an agent's launchd.agents.<name>.domain is changed from gui to
user (or the agent is newly installed on a headless macOS system
where the gui/<UID> domain never existed), bootoutAgent attempts to
unload the agent from the old domain first. On such systems, this
fails with: Boot-out failed: 125: Domain does not support specified
action.
The bootoutAgent function only treated "No such process" as a
non-fatal condition (return 2). This change adds the domain-not-exist
error to the same handling path: the agent wasn't running in a domain
that doesn't exist, so we can safely skip the boot-out and proceed
with bootstrap into the new domain.
User-domain agents need the Background session type to bootstrap into user/501, and activation should fail rather than silently unloading services when launchctl bootstrap fails.
On Darwin, launchd may attempt to start agents before the Nix store is
mounted and available. This leads to failures when the agent's executable
or arguments reside in the Nix store.
This change wraps the agent's command in a shell script that uses
/bin/wait4path to ensure /nix/store is ready before executing the
original program. It also ensures that ProgramArguments are correctly
escaped and concatenated.
This patch updates all usage of toPlist such that it escapes any strings
in the final output.
The motication for this change is to avoid confusion when end-users of
home-manager's APIs are not aware that the option values they set end up
being passed un-escaped to XML files.
BREAKING CHANGE: Consumers doing manual escaping will now be doubly escaped.
Co-authored-by: Linnnus <linnnus@users.noreply.github.com>