No description
Find a file
Alyssa Ross bac38f3c49 fix(3p/nix): Fix long paths permanently breaking GC
Suppose I have a path /nix/store/[hash]-[name]/a/a/a/a/a/[...]/a,
long enough that everything after "/nix/store/" is longer than 4096
(MAX_PATH) bytes.

Nix will happily allow such a path to be inserted into the store,
because it doesn't look at all the nested structure.  It just cares
about the /nix/store/[hash]-[name] part.  But, when the path is deleted,
we encounter a problem.  Nix will move the path to /nix/store/trash, but
then when it's trying to recursively delete the trash directory, it will
at some point try to unlink
/nix/store/trash/[hash]-[name]/a/a/a/a/a/[...]/a.  This will fail,
because the path is too long.  After this has failed, any store deletion
operation will never work again, because Nix needs to delete the trash
directory before recreating it to move new things to it.  (I assume this
is because otherwise a path being deleted could already exist in the
trash, and then moving it would fail.)

This means that if I can trick somebody into just fetching a tarball
containing a path of the right length, they won't be able to delete
store paths or garbage collect ever again, until the offending path is
manually removed from /nix/store/trash.  (And even fixing this manually
is quite difficult if you don't understand the issue, because the
absolute path that Nix says it failed to remove is also too long for
rm(1).)

This patch fixes the issue by making Nix's recursive delete operation
use unlinkat(2).  This function takes a relative path and a directory
file descriptor.  We ensure that the relative path is always just the
name of the directory entry, and therefore its length will never exceed
255 bytes.  This means that it will never even come close to AX_PATH,
and Nix will therefore be able to handle removing arbitrarily deep
directory hierachies.

Since the directory file descriptor is used for recursion after being
used in readDirectory, I made a variant of readDirectory that takes an
already open directory stream, to avoid the directory being opened
multiple times.  As we have seen from this issue, the less we have to
interact with paths, the better, and so it's good to reuse file
descriptors where possible.

I left _deletePath as succeeding even if the parent directory doesn't
exist, even though that feels wrong to me, because without that early
return, the linux-sandbox test failed.

Reported-by: Alyssa Ross <hi@alyssa.is>
Thanks-to: Puck Meerburg <puck@puckipedia.com>
Tested-by: Puck Meerburg <puck@puckipedia.com>
Reviewed-by: Puck Meerburg <puck@puckipedia.com>
(cherry picked from commit c05e20daa1abb3446e378331697938b78af2b3d7)
2020-05-24 00:12:38 +01:00
bin feat(bin): Add ninja & meson CLI tools 2020-05-17 02:49:13 +01:00
docs docs: Update review address to depot@tazj.in 2019-12-20 21:29:16 +00:00
fun chore: Update from Clang 9 to Clang 10 for all projects 2020-05-22 18:29:47 +01:00
lisp/dns chore: Rename pkgs->depot in all Nix file headers 2020-02-21 13:54:53 +00:00
net chore(net/stomp_erl): Remove erlang.mk 2019-12-21 03:05:51 +00:00
nix docs(nix/yants): Mention Yants subtree split in README 2020-05-16 12:37:12 +01:00
ops feat(ops/nixos/nugget): Install rr and hyperfine 2020-05-23 20:37:26 +01:00
overrides refactor: emacsPackagesNg -> emacsPackages 2020-03-08 23:20:03 +00:00
presentations chore: Rename pkgs->depot in all Nix file headers 2020-02-21 13:54:53 +00:00
third_party fix(3p/nix): Fix long paths permanently breaking GC 2020-05-24 00:12:38 +01:00
tools fix(tools/emacs): Use explicit includes 2020-05-22 19:05:39 +01:00
web chore(web/tvl): Remove direct link to TVL Meet from website 2020-05-17 00:35:37 +01:00
.envrc refactor(ops/kms_pass): Pin encrypted secrets into Nix store 2019-12-23 13:26:09 +01:00
.git-blame-ignore-revs chore: Add an ignoreRevsFile for git blame 2020-05-19 22:18:53 +01:00
.gitignore Squashed 'third_party/git/' changes from 5fa0f5238b..ef7aa56f96 2020-05-22 17:46:45 +01:00
.rgignore chore: Only exclude //third_party/git from ripgrep 2020-05-17 23:58:22 +01:00
ci-builds.nix feat(ci-builds): Build //third_party/nix in CI 2020-05-17 23:59:23 +01:00
default.nix refactor: Pass the depot as an argument named 'depot' 2020-02-21 12:45:43 +00:00
LICENSE chore: Keep project root under MIT license 2019-06-28 22:56:48 +01:00
README.md Squashed 'third_party/git/' changes from 5fa0f5238b..ef7aa56f96 2020-05-22 17:46:45 +01:00

depot

builds.sr.ht status

This repository is the monorepo for my personal tools and infrastructure. Everything in here is built using Nix with an automatic attribute-set layout that mirrors the filesystem layout of the repository (this might feel familiar to users of Bazel).

This repository used to be hosted on GitHub, but for a variety of reasons I have decided to take over the management of personal infrastructure - of which this repository is a core component.

If you've ended up here and have no idea who I am, feel free to follow me on Twitter.

Highlights

Tools

  • tools/emacs contains my personal Emacs configuration (packages & config)
  • fun/aoc2019 contains solutions for a handful of Advent of Code 2019 challenges, before I ran out of interest
  • tools/blog_cli contains my tool for writing new blog posts and storing them in the DNS zone
  • tools/cheddar contains a source code and Markdown rendering tool that is integrated with my cgit instance to render files in various views
  • ops/kms_pass.nix is a tiny tool that emulates the user-interface of pass, but actually uses Google Cloud KMS for secret decryption
  • ops/kontemplate contains my Kubernetes resource templating tool (with which the services in this repository are deployed!)
  • ops/besadii contains a tool that runs as the git post-receive-hook on my git server to trigger builds on sourcehut.

Packages / Libraries

  • nix/buildGo implements a Nix library that can build Go software in the style of Bazel's rules_go. Go programs in this repository are built using this library.
  • nix/buildLisp implements a Nix library that can build Common Lisp software. Currently only SBCL is supported. Lisp programs in this repository are built using this library.
  • tools/emacs-pkgs contains various Emacs libraries that my Emacs setup uses, for example:
    • dottime.el provides dottime in the Emacs modeline
    • nix-util.el provides editing utilities for Nix files
    • term-switcher.el is an ivy-function for switching between vterm buffers
  • net/alcoholic_jwt contains an easy-to-use JWT-validation library for Rust
  • net/crimp contains a high-level HTTP client using cURL for Rust

Services

Services in this repository are deployed on a Google Kubernetes Engine cluster using Nixery.

  • web/blog and web/homepage contain my blog and website setup (serving at tazj.in)
  • web/cgit-taz contains a slightly patched version of cgit that serves my git web interface at git.tazj.in
  • ops/journaldriver contains a small Rust daemon that can forward logs from journald to Stackdriver Logging

Miscellaneous

Presentations I've given in the past are in the presentations folder, these cover a variety of topics and some of them have links to recordings.

There's a few fun things in the fun/ folder, often with context given in the README. Check out my list of the best tools for example.

Contributing

If you'd like to contribute to any of the tools in here, please check out the contribution guidelines.