Latest commit

History

1,382 Commits

Folders and files

NameName
Last commit message
Last commit date

nixception

LicenseTest

nixception turns ordinary build-tool actions into Nix builds, using the Nix store as a content-addressed cache. It's a server that speaks the Remote Execution API (REAPI) and translates each remote action it receives — a single gcc invocation sent by recc, a Bazel rule — into a Nix derivation, and builds it through the recursive-nix daemon. Cached results live in the Nix store, so any action is built at most once across all consumers.

 recc / bazel ──REAPI──▶ nixception server ──recursive-nix──▶ /nix/store
(compiler/rule) (NixStore + (CAS + action
NixScheduler + cache)
NixWorker)

Because the Nix store is content-addressed, identical actions are built once and reused across runs and across projects. The win is a shared, reproducible, deduplicated cache for fine-grained build actions (individual compiles, Bazel rules) — not just whole packages.

nixception is built on top of NativeLink, an efficient, high-performance build cache and remote execution system. See Relationship to NativeLink below for how the two projects and their licenses relate.

Status: experimental. Interfaces (server topology, setup hook contract, derivation encoding) are still moving.

How it works

The nixception binary (src/bin/nixception.rs) is a NativeLink server assembled from a custom topology:

  • Exposes a REAPI gRPC endpoint on 0.0.0.0:50051 with the CAS, AC (action cache), Execution, Capabilities and ByteStream services.
  • Backs them with a NixStore — the Nix store used directly as the content-addressed store — and a NixScheduler.

The translation logic lives in nativelink-scheduler/src/:

  • nix_scheduler.rs — receives actions and manages a connection pool to the Nix daemon to avoid per-action overhead and daemon-connection deadlocks.
  • nix_worker.rs — the heart of the translation. For each action it scans every input for /nix/store/... references to discover the action's real store dependencies, prepares a derivation that runs the action's command through a small bash runner, realises it via recursive-nix, and collects the outputs back to the client.
  • nix_stats.rs — lock-free timing statistics per cost center (scanning, preparation, upload, execution, collection), printed on shutdown.

Because every action is realised as a derivation from inside a Nix build, the server relies on recursive-nix: the ability of a build to talk back to the Nix daemon (via /build/.nix-socket) and realise further derivations.

Building

The flake uses git submodules (vendor/). On Nix ≥ 2.27 they're picked up automatically:

nix build
./result/bin/nixception

On older Nix, pass the submodules flag explicitly:

nix build ".?submodules=1#"

A development shell with the pinned Rust toolchain is available through nix develop, and plain cargo build --release --bin nixception works inside it.

Using it in a Nix build

The intended consumer interface is a nixpkgs setup hook (tools/nixception-hook.nix + tools/nixception-setup-hook.sh). Added to nativeBuildInputs, it starts the server before configurePhase and tears it down when the build exits:

nativeBuildInputs=[nixceptionHook];

The consuming derivation needs requiredSystemFeatures = [ "recursive-nix" ]. Useful environment variables:

  • NIXCEPTION_VERBOSE=1 — stream timestamped server output to stderr (by default the log is kept quiet and dumped only on failure).
  • NIXCEPTION_STATS_FILE — where the server writes its timing summary.
  • NIXCEPTION_LOG — log level / filter (same syntax as RUST_LOG); honored if set.
  • NIXCEPTION_EXTRA_SANDBOX_PATHS — colon-separated /nix/store/… paths to make available inside every reapi-action sandbox (e.g. a compiler toolchain). The runner itself carries no toolset of its own, so any tool the executed command needs — even a shell or coreutils — must come through this or already be discoverable as a /nix/store/… reference in the action's own command/environment/inputs.

Relationship to NativeLink & licensing

nixception is a friendly fork of NativeLink by Trace Machina, Inc. and the NativeLink authors. All credit for the underlying build-cache and remote-execution infrastructure — the stores, schedulers, services and the REAPI implementation this project is assembled from — belongs to them. If you need a production-grade build cache or remote execution at scale, use NativeLink; this project serves a different, Nix-specific niche.

Licensing

  • This repository is licensed under the Apache License 2.0. It's based on the last Apache-2.0 licensed commit of upstream NativeLink; the upstream copyright notices are preserved in the source headers, and attribution notices are collected in NOTICE.
  • Upstream NativeLink has since moved to dual licensing under the Functional Source License 1.1 with an Apache 2.0 future grant (FSL-1.1-Apache-2.0): each upstream release converts to Apache 2.0 two years after its publication.
  • Consequently, nixception tracks upstream with a lag of two years: an upstream change is only incorporated here once its FSL grace period has lapsed and it's available under Apache 2.0. Until then, this repository only carries the Apache-licensed base plus the nixception-specific work developed here.
  • The vendored nix-compat crate (from the tvix project) is GPL-3.0 and is statically linked into the nixception executable, so binary distributions of nixception are governed by the GPLv3 even though the code in this repository is Apache 2.0. See NOTICE for details.

Contributing

See CONTRIBUTING.md. Security reports: see SECURITY.md.

About

NativeLink-based REAPI server that turns remote build actions into Nix derivations (Apache-2.0 release line)

Resources

Code of conduct

Contributing

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Latest commit

History

1,382 Commits

Folders and files

NameName
Last commit message
Last commit date

nixception

LicenseTest

nixception turns ordinary build-tool actions into Nix builds, using the Nix store as a content-addressed cache. It's a server that speaks the Remote Execution API (REAPI) and translates each remote action it receives — a single gcc invocation sent by recc, a Bazel rule — into a Nix derivation, and builds it through the recursive-nix daemon. Cached results live in the Nix store, so any action is built at most once across all consumers.

 recc / bazel ──REAPI──▶ nixception server ──recursive-nix──▶ /nix/store
(compiler/rule) (NixStore + (CAS + action
NixScheduler + cache)
NixWorker)

Because the Nix store is content-addressed, identical actions are built once and reused across runs and across projects. The win is a shared, reproducible, deduplicated cache for fine-grained build actions (individual compiles, Bazel rules) — not just whole packages.

nixception is built on top of NativeLink, an efficient, high-performance build cache and remote execution system. See Relationship to NativeLink below for how the two projects and their licenses relate.

Status: experimental. Interfaces (server topology, setup hook contract, derivation encoding) are still moving.

How it works

The nixception binary (src/bin/nixception.rs) is a NativeLink server assembled from a custom topology:

  • Exposes a REAPI gRPC endpoint on 0.0.0.0:50051 with the CAS, AC (action cache), Execution, Capabilities and ByteStream services.
  • Backs them with a NixStore — the Nix store used directly as the content-addressed store — and a NixScheduler.

The translation logic lives in nativelink-scheduler/src/:

  • nix_scheduler.rs — receives actions and manages a connection pool to the Nix daemon to avoid per-action overhead and daemon-connection deadlocks.
  • nix_worker.rs — the heart of the translation. For each action it scans every input for /nix/store/... references to discover the action's real store dependencies, prepares a derivation that runs the action's command through a small bash runner, realises it via recursive-nix, and collects the outputs back to the client.
  • nix_stats.rs — lock-free timing statistics per cost center (scanning, preparation, upload, execution, collection), printed on shutdown.

Because every action is realised as a derivation from inside a Nix build, the server relies on recursive-nix: the ability of a build to talk back to the Nix daemon (via /build/.nix-socket) and realise further derivations.

Building

The flake uses git submodules (vendor/). On Nix ≥ 2.27 they're picked up automatically:

nix build
./result/bin/nixception

On older Nix, pass the submodules flag explicitly:

nix build ".?submodules=1#"

A development shell with the pinned Rust toolchain is available through nix develop, and plain cargo build --release --bin nixception works inside it.

Using it in a Nix build

The intended consumer interface is a nixpkgs setup hook (tools/nixception-hook.nix + tools/nixception-setup-hook.sh). Added to nativeBuildInputs, it starts the server before configurePhase and tears it down when the build exits:

nativeBuildInputs=[nixceptionHook];

The consuming derivation needs requiredSystemFeatures = [ "recursive-nix" ]. Useful environment variables:

  • NIXCEPTION_VERBOSE=1 — stream timestamped server output to stderr (by default the log is kept quiet and dumped only on failure).
  • NIXCEPTION_STATS_FILE — where the server writes its timing summary.
  • NIXCEPTION_LOG — log level / filter (same syntax as RUST_LOG); honored if set.
  • NIXCEPTION_EXTRA_SANDBOX_PATHS — colon-separated /nix/store/… paths to make available inside every reapi-action sandbox (e.g. a compiler toolchain). The runner itself carries no toolset of its own, so any tool the executed command needs — even a shell or coreutils — must come through this or already be discoverable as a /nix/store/… reference in the action's own command/environment/inputs.

Relationship to NativeLink & licensing

nixception is a friendly fork of NativeLink by Trace Machina, Inc. and the NativeLink authors. All credit for the underlying build-cache and remote-execution infrastructure — the stores, schedulers, services and the REAPI implementation this project is assembled from — belongs to them. If you need a production-grade build cache or remote execution at scale, use NativeLink; this project serves a different, Nix-specific niche.

Licensing

  • This repository is licensed under the Apache License 2.0. It's based on the last Apache-2.0 licensed commit of upstream NativeLink; the upstream copyright notices are preserved in the source headers, and attribution notices are collected in NOTICE.
  • Upstream NativeLink has since moved to dual licensing under the Functional Source License 1.1 with an Apache 2.0 future grant (FSL-1.1-Apache-2.0): each upstream release converts to Apache 2.0 two years after its publication.
  • Consequently, nixception tracks upstream with a lag of two years: an upstream change is only incorporated here once its FSL grace period has lapsed and it's available under Apache 2.0. Until then, this repository only carries the Apache-licensed base plus the nixception-specific work developed here.
  • The vendored nix-compat crate (from the tvix project) is GPL-3.0 and is statically linked into the nixception executable, so binary distributions of nixception are governed by the GPLv3 even though the code in this repository is Apache 2.0. See NOTICE for details.

Contributing

See CONTRIBUTING.md. Security reports: see SECURITY.md.

About

NativeLink-based REAPI server that turns remote build actions into Nix derivations (Apache-2.0 release line)

Resources

Code of conduct

Contributing

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

1,382 Commits

Folders and files

NameName
Last commit message
Last commit date

nixception

LicenseTest

nixception turns ordinary build-tool actions into Nix builds, using the Nix store as a content-addressed cache. It's a server that speaks the Remote Execution API (REAPI) and translates each remote action it receives — a single gcc invocation sent by recc, a Bazel rule — into a Nix derivation, and builds it through the recursive-nix daemon. Cached results live in the Nix store, so any action is built at most once across all consumers.

 recc / bazel ──REAPI──▶ nixception server ──recursive-nix──▶ /nix/store
(compiler/rule) (NixStore + (CAS + action
NixScheduler + cache)
NixWorker)

Because the Nix store is content-addressed, identical actions are built once and reused across runs and across projects. The win is a shared, reproducible, deduplicated cache for fine-grained build actions (individual compiles, Bazel rules) — not just whole packages.

nixception is built on top of NativeLink, an efficient, high-performance build cache and remote execution system. See Relationship to NativeLink below for how the two projects and their licenses relate.

Status: experimental. Interfaces (server topology, setup hook contract, derivation encoding) are still moving.

How it works

The nixception binary (src/bin/nixception.rs) is a NativeLink server assembled from a custom topology:

  • Exposes a REAPI gRPC endpoint on 0.0.0.0:50051 with the CAS, AC (action cache), Execution, Capabilities and ByteStream services.
  • Backs them with a NixStore — the Nix store used directly as the content-addressed store — and a NixScheduler.

The translation logic lives in nativelink-scheduler/src/:

  • nix_scheduler.rs — receives actions and manages a connection pool to the Nix daemon to avoid per-action overhead and daemon-connection deadlocks.
  • nix_worker.rs — the heart of the translation. For each action it scans every input for /nix/store/... references to discover the action's real store dependencies, prepares a derivation that runs the action's command through a small bash runner, realises it via recursive-nix, and collects the outputs back to the client.
  • nix_stats.rs — lock-free timing statistics per cost center (scanning, preparation, upload, execution, collection), printed on shutdown.

Because every action is realised as a derivation from inside a Nix build, the server relies on recursive-nix: the ability of a build to talk back to the Nix daemon (via /build/.nix-socket) and realise further derivations.

Building

The flake uses git submodules (vendor/). On Nix ≥ 2.27 they're picked up automatically:

nix build
./result/bin/nixception

On older Nix, pass the submodules flag explicitly:

nix build ".?submodules=1#"

A development shell with the pinned Rust toolchain is available through nix develop, and plain cargo build --release --bin nixception works inside it.

Using it in a Nix build

The intended consumer interface is a nixpkgs setup hook (tools/nixception-hook.nix + tools/nixception-setup-hook.sh). Added to nativeBuildInputs, it starts the server before configurePhase and tears it down when the build exits:

nativeBuildInputs=[nixceptionHook];

The consuming derivation needs requiredSystemFeatures = [ "recursive-nix" ]. Useful environment variables:

  • NIXCEPTION_VERBOSE=1 — stream timestamped server output to stderr (by default the log is kept quiet and dumped only on failure).
  • NIXCEPTION_STATS_FILE — where the server writes its timing summary.
  • NIXCEPTION_LOG — log level / filter (same syntax as RUST_LOG); honored if set.
  • NIXCEPTION_EXTRA_SANDBOX_PATHS — colon-separated /nix/store/… paths to make available inside every reapi-action sandbox (e.g. a compiler toolchain). The runner itself carries no toolset of its own, so any tool the executed command needs — even a shell or coreutils — must come through this or already be discoverable as a /nix/store/… reference in the action's own command/environment/inputs.

Relationship to NativeLink & licensing

nixception is a friendly fork of NativeLink by Trace Machina, Inc. and the NativeLink authors. All credit for the underlying build-cache and remote-execution infrastructure — the stores, schedulers, services and the REAPI implementation this project is assembled from — belongs to them. If you need a production-grade build cache or remote execution at scale, use NativeLink; this project serves a different, Nix-specific niche.

Licensing

  • This repository is licensed under the Apache License 2.0. It's based on the last Apache-2.0 licensed commit of upstream NativeLink; the upstream copyright notices are preserved in the source headers, and attribution notices are collected in NOTICE.
  • Upstream NativeLink has since moved to dual licensing under the Functional Source License 1.1 with an Apache 2.0 future grant (FSL-1.1-Apache-2.0): each upstream release converts to Apache 2.0 two years after its publication.
  • Consequently, nixception tracks upstream with a lag of two years: an upstream change is only incorporated here once its FSL grace period has lapsed and it's available under Apache 2.0. Until then, this repository only carries the Apache-licensed base plus the nixception-specific work developed here.
  • The vendored nix-compat crate (from the tvix project) is GPL-3.0 and is statically linked into the nixception executable, so binary distributions of nixception are governed by the GPLv3 even though the code in this repository is Apache 2.0. See NOTICE for details.

Contributing

See CONTRIBUTING.md. Security reports: see SECURITY.md.

About

NativeLink-based REAPI server that turns remote build actions into Nix derivations (Apache-2.0 release line)

Resources

Code of conduct

Contributing

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

1,382 Commits

Folders and files

NameName
Last commit message
Last commit date

nixception

LicenseTest

nixception turns ordinary build-tool actions into Nix builds, using the Nix store as a content-addressed cache. It's a server that speaks the Remote Execution API (REAPI) and translates each remote action it receives — a single gcc invocation sent by recc, a Bazel rule — into a Nix derivation, and builds it through the recursive-nix daemon. Cached results live in the Nix store, so any action is built at most once across all consumers.

 recc / bazel ──REAPI──▶ nixception server ──recursive-nix──▶ /nix/store
(compiler/rule) (NixStore + (CAS + action
NixScheduler + cache)
NixWorker)

Because the Nix store is content-addressed, identical actions are built once and reused across runs and across projects. The win is a shared, reproducible, deduplicated cache for fine-grained build actions (individual compiles, Bazel rules) — not just whole packages.

nixception is built on top of NativeLink, an efficient, high-performance build cache and remote execution system. See Relationship to NativeLink below for how the two projects and their licenses relate.

Status: experimental. Interfaces (server topology, setup hook contract, derivation encoding) are still moving.

How it works

The nixception binary (src/bin/nixception.rs) is a NativeLink server assembled from a custom topology:

  • Exposes a REAPI gRPC endpoint on 0.0.0.0:50051 with the CAS, AC (action cache), Execution, Capabilities and ByteStream services.
  • Backs them with a NixStore — the Nix store used directly as the content-addressed store — and a NixScheduler.

The translation logic lives in nativelink-scheduler/src/:

  • nix_scheduler.rs — receives actions and manages a connection pool to the Nix daemon to avoid per-action overhead and daemon-connection deadlocks.
  • nix_worker.rs — the heart of the translation. For each action it scans every input for /nix/store/... references to discover the action's real store dependencies, prepares a derivation that runs the action's command through a small bash runner, realises it via recursive-nix, and collects the outputs back to the client.
  • nix_stats.rs — lock-free timing statistics per cost center (scanning, preparation, upload, execution, collection), printed on shutdown.

Because every action is realised as a derivation from inside a Nix build, the server relies on recursive-nix: the ability of a build to talk back to the Nix daemon (via /build/.nix-socket) and realise further derivations.

Building

The flake uses git submodules (vendor/). On Nix ≥ 2.27 they're picked up automatically:

nix build
./result/bin/nixception

On older Nix, pass the submodules flag explicitly:

nix build ".?submodules=1#"

A development shell with the pinned Rust toolchain is available through nix develop, and plain cargo build --release --bin nixception works inside it.

Using it in a Nix build

The intended consumer interface is a nixpkgs setup hook (tools/nixception-hook.nix + tools/nixception-setup-hook.sh). Added to nativeBuildInputs, it starts the server before configurePhase and tears it down when the build exits:

nativeBuildInputs=[nixceptionHook];

The consuming derivation needs requiredSystemFeatures = [ "recursive-nix" ]. Useful environment variables:

  • NIXCEPTION_VERBOSE=1 — stream timestamped server output to stderr (by default the log is kept quiet and dumped only on failure).
  • NIXCEPTION_STATS_FILE — where the server writes its timing summary.
  • NIXCEPTION_LOG — log level / filter (same syntax as RUST_LOG); honored if set.
  • NIXCEPTION_EXTRA_SANDBOX_PATHS — colon-separated /nix/store/… paths to make available inside every reapi-action sandbox (e.g. a compiler toolchain). The runner itself carries no toolset of its own, so any tool the executed command needs — even a shell or coreutils — must come through this or already be discoverable as a /nix/store/… reference in the action's own command/environment/inputs.

Relationship to NativeLink & licensing

nixception is a friendly fork of NativeLink by Trace Machina, Inc. and the NativeLink authors. All credit for the underlying build-cache and remote-execution infrastructure — the stores, schedulers, services and the REAPI implementation this project is assembled from — belongs to them. If you need a production-grade build cache or remote execution at scale, use NativeLink; this project serves a different, Nix-specific niche.

Licensing

  • This repository is licensed under the Apache License 2.0. It's based on the last Apache-2.0 licensed commit of upstream NativeLink; the upstream copyright notices are preserved in the source headers, and attribution notices are collected in NOTICE.
  • Upstream NativeLink has since moved to dual licensing under the Functional Source License 1.1 with an Apache 2.0 future grant (FSL-1.1-Apache-2.0): each upstream release converts to Apache 2.0 two years after its publication.
  • Consequently, nixception tracks upstream with a lag of two years: an upstream change is only incorporated here once its FSL grace period has lapsed and it's available under Apache 2.0. Until then, this repository only carries the Apache-licensed base plus the nixception-specific work developed here.
  • The vendored nix-compat crate (from the tvix project) is GPL-3.0 and is statically linked into the nixception executable, so binary distributions of nixception are governed by the GPLv3 even though the code in this repository is Apache 2.0. See NOTICE for details.

Contributing

See CONTRIBUTING.md. Security reports: see SECURITY.md.

About

NativeLink-based REAPI server that turns remote build actions into Nix derivations (Apache-2.0 release line)

Resources

Code of conduct

Contributing

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Latest commit

History

1,382 Commits

Folders and files

NameName
Last commit message
Last commit date

nixception

LicenseTest

nixception turns ordinary build-tool actions into Nix builds, using the Nix store as a content-addressed cache. It's a server that speaks the Remote Execution API (REAPI) and translates each remote action it receives — a single gcc invocation sent by recc, a Bazel rule — into a Nix derivation, and builds it through the recursive-nix daemon. Cached results live in the Nix store, so any action is built at most once across all consumers.

 recc / bazel ──REAPI──▶ nixception server ──recursive-nix──▶ /nix/store
(compiler/rule) (NixStore + (CAS + action
NixScheduler + cache)
NixWorker)

Because the Nix store is content-addressed, identical actions are built once and reused across runs and across projects. The win is a shared, reproducible, deduplicated cache for fine-grained build actions (individual compiles, Bazel rules) — not just whole packages.

nixception is built on top of NativeLink, an efficient, high-performance build cache and remote execution system. See Relationship to NativeLink below for how the two projects and their licenses relate.

Status: experimental. Interfaces (server topology, setup hook contract, derivation encoding) are still moving.

How it works

The nixception binary (src/bin/nixception.rs) is a NativeLink server assembled from a custom topology:

  • Exposes a REAPI gRPC endpoint on 0.0.0.0:50051 with the CAS, AC (action cache), Execution, Capabilities and ByteStream services.
  • Backs them with a NixStore — the Nix store used directly as the content-addressed store — and a NixScheduler.

The translation logic lives in nativelink-scheduler/src/:

  • nix_scheduler.rs — receives actions and manages a connection pool to the Nix daemon to avoid per-action overhead and daemon-connection deadlocks.
  • nix_worker.rs — the heart of the translation. For each action it scans every input for /nix/store/... references to discover the action's real store dependencies, prepares a derivation that runs the action's command through a small bash runner, realises it via recursive-nix, and collects the outputs back to the client.
  • nix_stats.rs — lock-free timing statistics per cost center (scanning, preparation, upload, execution, collection), printed on shutdown.

Because every action is realised as a derivation from inside a Nix build, the server relies on recursive-nix: the ability of a build to talk back to the Nix daemon (via /build/.nix-socket) and realise further derivations.

Building

The flake uses git submodules (vendor/). On Nix ≥ 2.27 they're picked up automatically:

nix build
./result/bin/nixception

On older Nix, pass the submodules flag explicitly:

nix build ".?submodules=1#"

A development shell with the pinned Rust toolchain is available through nix develop, and plain cargo build --release --bin nixception works inside it.

Using it in a Nix build

The intended consumer interface is a nixpkgs setup hook (tools/nixception-hook.nix + tools/nixception-setup-hook.sh). Added to nativeBuildInputs, it starts the server before configurePhase and tears it down when the build exits:

nativeBuildInputs=[nixceptionHook];

The consuming derivation needs requiredSystemFeatures = [ "recursive-nix" ]. Useful environment variables:

  • NIXCEPTION_VERBOSE=1 — stream timestamped server output to stderr (by default the log is kept quiet and dumped only on failure).
  • NIXCEPTION_STATS_FILE — where the server writes its timing summary.
  • NIXCEPTION_LOG — log level / filter (same syntax as RUST_LOG); honored if set.
  • NIXCEPTION_EXTRA_SANDBOX_PATHS — colon-separated /nix/store/… paths to make available inside every reapi-action sandbox (e.g. a compiler toolchain). The runner itself carries no toolset of its own, so any tool the executed command needs — even a shell or coreutils — must come through this or already be discoverable as a /nix/store/… reference in the action's own command/environment/inputs.

Relationship to NativeLink & licensing

nixception is a friendly fork of NativeLink by Trace Machina, Inc. and the NativeLink authors. All credit for the underlying build-cache and remote-execution infrastructure — the stores, schedulers, services and the REAPI implementation this project is assembled from — belongs to them. If you need a production-grade build cache or remote execution at scale, use NativeLink; this project serves a different, Nix-specific niche.

Licensing

  • This repository is licensed under the Apache License 2.0. It's based on the last Apache-2.0 licensed commit of upstream NativeLink; the upstream copyright notices are preserved in the source headers, and attribution notices are collected in NOTICE.
  • Upstream NativeLink has since moved to dual licensing under the Functional Source License 1.1 with an Apache 2.0 future grant (FSL-1.1-Apache-2.0): each upstream release converts to Apache 2.0 two years after its publication.
  • Consequently, nixception tracks upstream with a lag of two years: an upstream change is only incorporated here once its FSL grace period has lapsed and it's available under Apache 2.0. Until then, this repository only carries the Apache-licensed base plus the nixception-specific work developed here.
  • The vendored nix-compat crate (from the tvix project) is GPL-3.0 and is statically linked into the nixception executable, so binary distributions of nixception are governed by the GPLv3 even though the code in this repository is Apache 2.0. See NOTICE for details.

Contributing

See CONTRIBUTING.md. Security reports: see SECURITY.md.

About

NativeLink-based REAPI server that turns remote build actions into Nix derivations (Apache-2.0 release line)

Resources

Code of conduct

Contributing

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

1,382 Commits

Folders and files

NameName
Last commit message
Last commit date

nixception

LicenseTest

nixception turns ordinary build-tool actions into Nix builds, using the Nix store as a content-addressed cache. It's a server that speaks the Remote Execution API (REAPI) and translates each remote action it receives — a single gcc invocation sent by recc, a Bazel rule — into a Nix derivation, and builds it through the recursive-nix daemon. Cached results live in the Nix store, so any action is built at most once across all consumers.

 recc / bazel ──REAPI──▶ nixception server ──recursive-nix──▶ /nix/store
(compiler/rule) (NixStore + (CAS + action
NixScheduler + cache)
NixWorker)

Because the Nix store is content-addressed, identical actions are built once and reused across runs and across projects. The win is a shared, reproducible, deduplicated cache for fine-grained build actions (individual compiles, Bazel rules) — not just whole packages.

nixception is built on top of NativeLink, an efficient, high-performance build cache and remote execution system. See Relationship to NativeLink below for how the two projects and their licenses relate.

Status: experimental. Interfaces (server topology, setup hook contract, derivation encoding) are still moving.

How it works

The nixception binary (src/bin/nixception.rs) is a NativeLink server assembled from a custom topology:

  • Exposes a REAPI gRPC endpoint on 0.0.0.0:50051 with the CAS, AC (action cache), Execution, Capabilities and ByteStream services.
  • Backs them with a NixStore — the Nix store used directly as the content-addressed store — and a NixScheduler.

The translation logic lives in nativelink-scheduler/src/:

  • nix_scheduler.rs — receives actions and manages a connection pool to the Nix daemon to avoid per-action overhead and daemon-connection deadlocks.
  • nix_worker.rs — the heart of the translation. For each action it scans every input for /nix/store/... references to discover the action's real store dependencies, prepares a derivation that runs the action's command through a small bash runner, realises it via recursive-nix, and collects the outputs back to the client.
  • nix_stats.rs — lock-free timing statistics per cost center (scanning, preparation, upload, execution, collection), printed on shutdown.

Because every action is realised as a derivation from inside a Nix build, the server relies on recursive-nix: the ability of a build to talk back to the Nix daemon (via /build/.nix-socket) and realise further derivations.

Building

The flake uses git submodules (vendor/). On Nix ≥ 2.27 they're picked up automatically:

nix build
./result/bin/nixception

On older Nix, pass the submodules flag explicitly:

nix build ".?submodules=1#"

A development shell with the pinned Rust toolchain is available through nix develop, and plain cargo build --release --bin nixception works inside it.

Using it in a Nix build

The intended consumer interface is a nixpkgs setup hook (tools/nixception-hook.nix + tools/nixception-setup-hook.sh). Added to nativeBuildInputs, it starts the server before configurePhase and tears it down when the build exits:

nativeBuildInputs=[nixceptionHook];

The consuming derivation needs requiredSystemFeatures = [ "recursive-nix" ]. Useful environment variables:

  • NIXCEPTION_VERBOSE=1 — stream timestamped server output to stderr (by default the log is kept quiet and dumped only on failure).
  • NIXCEPTION_STATS_FILE — where the server writes its timing summary.
  • NIXCEPTION_LOG — log level / filter (same syntax as RUST_LOG); honored if set.
  • NIXCEPTION_EXTRA_SANDBOX_PATHS — colon-separated /nix/store/… paths to make available inside every reapi-action sandbox (e.g. a compiler toolchain). The runner itself carries no toolset of its own, so any tool the executed command needs — even a shell or coreutils — must come through this or already be discoverable as a /nix/store/… reference in the action's own command/environment/inputs.

Relationship to NativeLink & licensing

nixception is a friendly fork of NativeLink by Trace Machina, Inc. and the NativeLink authors. All credit for the underlying build-cache and remote-execution infrastructure — the stores, schedulers, services and the REAPI implementation this project is assembled from — belongs to them. If you need a production-grade build cache or remote execution at scale, use NativeLink; this project serves a different, Nix-specific niche.

Licensing

  • This repository is licensed under the Apache License 2.0. It's based on the last Apache-2.0 licensed commit of upstream NativeLink; the upstream copyright notices are preserved in the source headers, and attribution notices are collected in NOTICE.
  • Upstream NativeLink has since moved to dual licensing under the Functional Source License 1.1 with an Apache 2.0 future grant (FSL-1.1-Apache-2.0): each upstream release converts to Apache 2.0 two years after its publication.
  • Consequently, nixception tracks upstream with a lag of two years: an upstream change is only incorporated here once its FSL grace period has lapsed and it's available under Apache 2.0. Until then, this repository only carries the Apache-licensed base plus the nixception-specific work developed here.
  • The vendored nix-compat crate (from the tvix project) is GPL-3.0 and is statically linked into the nixception executable, so binary distributions of nixception are governed by the GPLv3 even though the code in this repository is Apache 2.0. See NOTICE for details.

Contributing

See CONTRIBUTING.md. Security reports: see SECURITY.md.

About

NativeLink-based REAPI server that turns remote build actions into Nix derivations (Apache-2.0 release line)

Resources

Code of conduct

Contributing

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

1,382 Commits

Folders and files

NameName
Last commit message
Last commit date

nixception

LicenseTest

nixception turns ordinary build-tool actions into Nix builds, using the Nix store as a content-addressed cache. It's a server that speaks the Remote Execution API (REAPI) and translates each remote action it receives — a single gcc invocation sent by recc, a Bazel rule — into a Nix derivation, and builds it through the recursive-nix daemon. Cached results live in the Nix store, so any action is built at most once across all consumers.

 recc / bazel ──REAPI──▶ nixception server ──recursive-nix──▶ /nix/store
(compiler/rule) (NixStore + (CAS + action
NixScheduler + cache)
NixWorker)

Because the Nix store is content-addressed, identical actions are built once and reused across runs and across projects. The win is a shared, reproducible, deduplicated cache for fine-grained build actions (individual compiles, Bazel rules) — not just whole packages.

nixception is built on top of NativeLink, an efficient, high-performance build cache and remote execution system. See Relationship to NativeLink below for how the two projects and their licenses relate.

Status: experimental. Interfaces (server topology, setup hook contract, derivation encoding) are still moving.

How it works

The nixception binary (src/bin/nixception.rs) is a NativeLink server assembled from a custom topology:

  • Exposes a REAPI gRPC endpoint on 0.0.0.0:50051 with the CAS, AC (action cache), Execution, Capabilities and ByteStream services.
  • Backs them with a NixStore — the Nix store used directly as the content-addressed store — and a NixScheduler.

The translation logic lives in nativelink-scheduler/src/:

  • nix_scheduler.rs — receives actions and manages a connection pool to the Nix daemon to avoid per-action overhead and daemon-connection deadlocks.
  • nix_worker.rs — the heart of the translation. For each action it scans every input for /nix/store/... references to discover the action's real store dependencies, prepares a derivation that runs the action's command through a small bash runner, realises it via recursive-nix, and collects the outputs back to the client.
  • nix_stats.rs — lock-free timing statistics per cost center (scanning, preparation, upload, execution, collection), printed on shutdown.

Because every action is realised as a derivation from inside a Nix build, the server relies on recursive-nix: the ability of a build to talk back to the Nix daemon (via /build/.nix-socket) and realise further derivations.

Building

The flake uses git submodules (vendor/). On Nix ≥ 2.27 they're picked up automatically:

nix build
./result/bin/nixception

On older Nix, pass the submodules flag explicitly:

nix build ".?submodules=1#"

A development shell with the pinned Rust toolchain is available through nix develop, and plain cargo build --release --bin nixception works inside it.

Using it in a Nix build

The intended consumer interface is a nixpkgs setup hook (tools/nixception-hook.nix + tools/nixception-setup-hook.sh). Added to nativeBuildInputs, it starts the server before configurePhase and tears it down when the build exits:

nativeBuildInputs=[nixceptionHook];

The consuming derivation needs requiredSystemFeatures = [ "recursive-nix" ]. Useful environment variables:

  • NIXCEPTION_VERBOSE=1 — stream timestamped server output to stderr (by default the log is kept quiet and dumped only on failure).
  • NIXCEPTION_STATS_FILE — where the server writes its timing summary.
  • NIXCEPTION_LOG — log level / filter (same syntax as RUST_LOG); honored if set.
  • NIXCEPTION_EXTRA_SANDBOX_PATHS — colon-separated /nix/store/… paths to make available inside every reapi-action sandbox (e.g. a compiler toolchain). The runner itself carries no toolset of its own, so any tool the executed command needs — even a shell or coreutils — must come through this or already be discoverable as a /nix/store/… reference in the action's own command/environment/inputs.

Relationship to NativeLink & licensing

nixception is a friendly fork of NativeLink by Trace Machina, Inc. and the NativeLink authors. All credit for the underlying build-cache and remote-execution infrastructure — the stores, schedulers, services and the REAPI implementation this project is assembled from — belongs to them. If you need a production-grade build cache or remote execution at scale, use NativeLink; this project serves a different, Nix-specific niche.

Licensing

  • This repository is licensed under the Apache License 2.0. It's based on the last Apache-2.0 licensed commit of upstream NativeLink; the upstream copyright notices are preserved in the source headers, and attribution notices are collected in NOTICE.
  • Upstream NativeLink has since moved to dual licensing under the Functional Source License 1.1 with an Apache 2.0 future grant (FSL-1.1-Apache-2.0): each upstream release converts to Apache 2.0 two years after its publication.
  • Consequently, nixception tracks upstream with a lag of two years: an upstream change is only incorporated here once its FSL grace period has lapsed and it's available under Apache 2.0. Until then, this repository only carries the Apache-licensed base plus the nixception-specific work developed here.
  • The vendored nix-compat crate (from the tvix project) is GPL-3.0 and is statically linked into the nixception executable, so binary distributions of nixception are governed by the GPLv3 even though the code in this repository is Apache 2.0. See NOTICE for details.

Contributing

See CONTRIBUTING.md. Security reports: see SECURITY.md.

About

NativeLink-based REAPI server that turns remote build actions into Nix derivations (Apache-2.0 release line)

Resources

Code of conduct

Contributing

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Latest commit

History

1,382 Commits

Folders and files

NameName
Last commit message
Last commit date

nixception

LicenseTest

nixception turns ordinary build-tool actions into Nix builds, using the Nix store as a content-addressed cache. It's a server that speaks the Remote Execution API (REAPI) and translates each remote action it receives — a single gcc invocation sent by recc, a Bazel rule — into a Nix derivation, and builds it through the recursive-nix daemon. Cached results live in the Nix store, so any action is built at most once across all consumers.

 recc / bazel ──REAPI──▶ nixception server ──recursive-nix──▶ /nix/store
(compiler/rule) (NixStore + (CAS + action
NixScheduler + cache)
NixWorker)

Because the Nix store is content-addressed, identical actions are built once and reused across runs and across projects. The win is a shared, reproducible, deduplicated cache for fine-grained build actions (individual compiles, Bazel rules) — not just whole packages.

nixception is built on top of NativeLink, an efficient, high-performance build cache and remote execution system. See Relationship to NativeLink below for how the two projects and their licenses relate.

Status: experimental. Interfaces (server topology, setup hook contract, derivation encoding) are still moving.

How it works

The nixception binary (src/bin/nixception.rs) is a NativeLink server assembled from a custom topology:

  • Exposes a REAPI gRPC endpoint on 0.0.0.0:50051 with the CAS, AC (action cache), Execution, Capabilities and ByteStream services.
  • Backs them with a NixStore — the Nix store used directly as the content-addressed store — and a NixScheduler.

The translation logic lives in nativelink-scheduler/src/:

  • nix_scheduler.rs — receives actions and manages a connection pool to the Nix daemon to avoid per-action overhead and daemon-connection deadlocks.
  • nix_worker.rs — the heart of the translation. For each action it scans every input for /nix/store/... references to discover the action's real store dependencies, prepares a derivation that runs the action's command through a small bash runner, realises it via recursive-nix, and collects the outputs back to the client.
  • nix_stats.rs — lock-free timing statistics per cost center (scanning, preparation, upload, execution, collection), printed on shutdown.

Because every action is realised as a derivation from inside a Nix build, the server relies on recursive-nix: the ability of a build to talk back to the Nix daemon (via /build/.nix-socket) and realise further derivations.

Building

The flake uses git submodules (vendor/). On Nix ≥ 2.27 they're picked up automatically:

nix build
./result/bin/nixception

On older Nix, pass the submodules flag explicitly:

nix build ".?submodules=1#"

A development shell with the pinned Rust toolchain is available through nix develop, and plain cargo build --release --bin nixception works inside it.

Using it in a Nix build

The intended consumer interface is a nixpkgs setup hook (tools/nixception-hook.nix + tools/nixception-setup-hook.sh). Added to nativeBuildInputs, it starts the server before configurePhase and tears it down when the build exits:

nativeBuildInputs=[nixceptionHook];

The consuming derivation needs requiredSystemFeatures = [ "recursive-nix" ]. Useful environment variables:

  • NIXCEPTION_VERBOSE=1 — stream timestamped server output to stderr (by default the log is kept quiet and dumped only on failure).
  • NIXCEPTION_STATS_FILE — where the server writes its timing summary.
  • NIXCEPTION_LOG — log level / filter (same syntax as RUST_LOG); honored if set.
  • NIXCEPTION_EXTRA_SANDBOX_PATHS — colon-separated /nix/store/… paths to make available inside every reapi-action sandbox (e.g. a compiler toolchain). The runner itself carries no toolset of its own, so any tool the executed command needs — even a shell or coreutils — must come through this or already be discoverable as a /nix/store/… reference in the action's own command/environment/inputs.

Relationship to NativeLink & licensing

nixception is a friendly fork of NativeLink by Trace Machina, Inc. and the NativeLink authors. All credit for the underlying build-cache and remote-execution infrastructure — the stores, schedulers, services and the REAPI implementation this project is assembled from — belongs to them. If you need a production-grade build cache or remote execution at scale, use NativeLink; this project serves a different, Nix-specific niche.

Licensing

  • This repository is licensed under the Apache License 2.0. It's based on the last Apache-2.0 licensed commit of upstream NativeLink; the upstream copyright notices are preserved in the source headers, and attribution notices are collected in NOTICE.
  • Upstream NativeLink has since moved to dual licensing under the Functional Source License 1.1 with an Apache 2.0 future grant (FSL-1.1-Apache-2.0): each upstream release converts to Apache 2.0 two years after its publication.
  • Consequently, nixception tracks upstream with a lag of two years: an upstream change is only incorporated here once its FSL grace period has lapsed and it's available under Apache 2.0. Until then, this repository only carries the Apache-licensed base plus the nixception-specific work developed here.
  • The vendored nix-compat crate (from the tvix project) is GPL-3.0 and is statically linked into the nixception executable, so binary distributions of nixception are governed by the GPLv3 even though the code in this repository is Apache 2.0. See NOTICE for details.

Contributing

See CONTRIBUTING.md. Security reports: see SECURITY.md.

About

NativeLink-based REAPI server that turns remote build actions into Nix derivations (Apache-2.0 release line)

Resources

Code of conduct

Contributing

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages