From 31a68c07febce8a2ed0ff76a5cf3cfa184b6b701 Mon Sep 17 00:00:00 2001 From: Victor Hooi Date: Wed, 30 Sep 2026 04:48:07 +1000 Subject: [PATCH] lix: fix build on darwin 97bf56b78d97 ("lix: link with -z,noexecstack") sets NIX_LDFLAGS to "-z,noexecstack" on every platform. cc-wrapper prefixes each word of NIX_LDFLAGS with -Wl, so clang hands `-z noexecstack` to the linker, and Apple's ld64 has no -z option. Meson's compiler sanity check then fails to link, and every Lix in lixPackageSets fails to build on aarch64-darwin: https://hydra.nixos.org/build/347153371 Mach-O does not need the flag: ld64 leaves stacks non-executable unless -allow_stack_execute is passed. lib.optionalString keeps the value unchanged on ELF platforms, so no Linux derivation changes. Assisted-by: Claude Code (Claude Opus 5.5) --- pkgs/tools/package-management/lix/common-lix.nix | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/pkgs/tools/package-management/lix/common-lix.nix b/pkgs/tools/package-management/lix/common-lix.nix index 95249b3a591a..6f4d41a9928f 100644 --- a/pkgs/tools/package-management/lix/common-lix.nix +++ b/pkgs/tools/package-management/lix/common-lix.nix @@ -291,7 +291,9 @@ stdenv.mkDerivation (finalAttrs: { # Defense-in-depth: never inherit an executable stack from a dependency. # It does happen: https://github.com/NixOS/nixpkgs/issues/567777. - NIX_LDFLAGS = "-z,noexecstack"; + # ELF only: Apple's ld64 rejects `-z`, and Mach-O stacks are already + # non-executable unless linked with `-allow_stack_execute`. + NIX_LDFLAGS = lib.optionalString stdenv.hostPlatform.isElf "-z,noexecstack"; }; propagatedBuildInputs = [