Improvements:
1. Turn the nix value into an attrset so that every inhibitor has a name
that we can match between generations
2. Write the attrset to a file as JSON
3. When checking, we load the JSON files from both the current and the
new generation into a jq pipeline and match up the keys.
We output a dict with a value for every key that is present in both
generations with a different value.
4. Build in error handling for different corner cases (missing files,
non-JSON content)
9bfd0d688d changed this line from
`substituteInPlace` to `sed`, but in the case of cross compilation
that would use the host's `sed`, which isn't necessarily executable by
the build machine.
Two improvements:
* use `writeShellApplication` (which uses `passAsFile` instead of
passing the activation script as an env var into the derivation.
We disable shellcheck and the bash options that this builder
usually adds to avoid issues with out-of-tree activation scripts.
* use `sed` instead of `substituteInPlace`, since the substitute
functions load the file content into a shell variable
This avoids issues when the activation is too long to fit in a shell variable.
Before this commit, a very large activation script, would cause build
failures because of different limits on the file content size, e.g.
```
➜ nix build -f . nixosTests.restartByActivationScript.nodes.machine.system.build.toplevel -vL
this derivation will be built:
/nix/store/xw6anpfjyamnycjg58cmj01sz3ididyl-nixos-system-machine-test.drv
building '/nix/store/xw6anpfjyamnycjg58cmj01sz3ididyl-nixos-system-machine-test.drv'...
nixos-system-machine-test> error: executing '/nix/store/rlq03x4cwf8zn73hxaxnx0zn5q9kifls-bash-5.3p3/bin/bash': Argument list too long
error: builder for '/nix/store/xw6anpfjyamnycjg58cmj01sz3ididyl-nixos-system-machine-test.drv' failed with exit code 1;
last 1 log lines:
> error: executing '/nix/store/rlq03x4cwf8zn73hxaxnx0zn5q9kifls-bash-5.3p3/bin/bash': Argument list too long
For full logs, run:
nix log /nix/store/xw6anpfjyamnycjg58cmj01sz3ididyl-nixos-system-machine-test.drv
```
This commit introduces "switch inhibitors" which are derivations that
prevent a switch of a system to a new configuration if those derivations
don't have the same hash in both configurations.
This means that we can for instance add the systemd and dbus derivations
such that users will be instructed to reboot their system when those
derivations have changed instead of switching.
This feature should be used sparingly, but it can make NixOS more robust
by avoiding users switching to a configuration that can make their
system unstable (like major updates of systemd, or new versions of dbus
since the dbus and dbus-broker daemons cannot be restarted).
The user can still force the switch by setting an env var.
Provide indirection for ExecStart to enable control over systemd
specifier and variable substitution, while escaping process.argv
by default for literal arguments.
input_leds is commonly wanted, but not strictly needed, for luks. It
provides caps lock key LED functionlaity for most keyboards, which is
useful when inputing a password to unlock a LUKS filesystem.
crytpd is a helper module which *may* be compiled based on architecture
and/or crypto algorithms which are supported (built) in the kernel.
Since not all kernels need cryptd to do LUKS-based encryption, move
cryptd to cryptoModules which can be configured based on the built
kernel.
This module made the assumption that `e2fsprogs` will always be
available in `system.fsPackages`, whereas on my system with tmpfs as
root+btrfs setup, e2fsprogs is not added to `fsPackages`, causing zram-generator
failed to find mkfs.ext4.
Related log:
```
systemd-makefs[555]: mkfs binary for ext4 is not available.
```
Shuffle:
The definitions are now combined into a single option. Since they have
no interdependencies, that's ok, but you may notice this trivial change
by a changed hash, and analyzing with nix-diff.
Deprecation:
Use the option `system.systemBuilderCommands` instead.
Until now, both options are set to true as default. But the systemd-journal-gatewayd
service defaults them to false. To match the origin behaviour, the defaults have been
changed.