lix: fix build on darwin

97bf56b78d ("lix: link with -z,noexecstack") sets NIX_LDFLAGS to
"-z,noexecstack" on every platform. cc-wrapper prefixes each word of
NIX_LDFLAGS with -Wl, so clang hands `-z noexecstack` to the linker, and
Apple's ld64 has no -z option. Meson's compiler sanity check then fails
to link, and every Lix in lixPackageSets fails to build on
aarch64-darwin: https://hydra.nixos.org/build/347153371

Mach-O does not need the flag: ld64 leaves stacks non-executable unless
-allow_stack_execute is passed. lib.optionalString keeps the value
unchanged on ELF platforms, so no Linux derivation changes.

Assisted-by: Claude Code (Claude Opus 5.5)
This commit is contained in:
Victor Hooi
2026-09-30 04:48:07 +10:00
parent 065c9d699b
commit 31a68c07fe

View File

@@ -291,7 +291,9 @@ stdenv.mkDerivation (finalAttrs: {
# Defense-in-depth: never inherit an executable stack from a dependency.
# It does happen: https://github.com/NixOS/nixpkgs/issues/567777.
NIX_LDFLAGS = "-z,noexecstack";
# ELF only: Apple's ld64 rejects `-z`, and Mach-O stacks are already
# non-executable unless linked with `-allow_stack_execute`.
NIX_LDFLAGS = lib.optionalString stdenv.hostPlatform.isElf "-z,noexecstack";
};
propagatedBuildInputs = [