Skip to content

Pipeline for Nix - #2209

Open
chinyeungli wants to merge 112 commits into
mainfrom
1938_pipeline_for_nix
Open

chinyeungli wants to merge 112 commits into
mainfrom
1938_pipeline_for_nix

Conversation

@chinyeungli

@chinyeungli chinyeungli commented Aug 18, 2026 •

Copy link
Copy Markdown
Contributor

Issues

Changes

This PR creates a dedicated pipeline for Nix packages.

Requirements

  • This pipeline only works on packages that found in the official nixpkgs.
  • It takes a single Nix PURL as an input (i.e. pkg:nix/nixpkgs/...)
  • A 'version' or a 'commit' qualifier is required in the input PURL as this is needed to fetch the correct source and binary for deployment to development mapping scan.
  • It also requires the input PURL to have a "system" qualifier to resolve system-specific binaries.
  • Docker is required. The code use docker to build sources by applying patches/configs that's defined in the upstream .nix files.
  • If the PURL has no output qualifier, the pipeline tries debug first (dwarf symbols are needed for D2D mapping) and falls back to out. If the PURL specifies an output, only that one is used.

Summary

  • The code will get metadata from https://search.devbox.sh and find and fetch the binary package from https://cache.nixos.org/
  • If a Nix package cannot be found in https://cache.nixos.org/ and a commit hash is provided, the code will try to fetch and build the source from https://github.com/NixOS/nixpkgs and patch the sources using the exact configuration defined in the upstream .nix files.
  • The pipeline will check if there is any license mismatch between the codebase and the declared license from the detected packages

Notes for deployment to development mapping

As Nix is not tied to a single programming language ecosystem, this pipeline executes all currently supported D2D steps across multiple languages.

Handling Missing Debug Symbols:

For pkg:nix/nixpkgs/SDL_mixer@1.2.12?system=x86_64-linux , as seen in https://search.devbox.sh/v2/pkg?name=SDL_mixer , there is no debug build found under the "outputs" section. Therefore, even the ELF binary is not stripped:
Screenshot 2026-08-18 140703

there is no dwarf symbols collected and no development to deployment mapping can be performed

Screenshot 2026-08-18 140719

Template File Mapping (.in files):

For pkg:nix/nixpkgs/openssl@3.6.0?out=debug&system=x86_64-linux, following are some of the dwarf symbols collected:

include/openssl/asn1.h
include/openssl/asn1t.h

However, these exact header files do not exist in the source codebase; they are generated from GNU Autoconf template files. To complete the mapping, the code has been updated to map to the corresponding .in template files:
Screenshot 2026-08-18 135225

Source-Only Scans:
For pkg:nix/nixpkgs/haskellPackages.aasam@0.2.0.0?system=x86_64-linux&commit=a3ae4cdd64f675cf2580affecdee01c401b43638 , this package does not exist on https://search.devbox.sh/, so no binary can be fetched, and the local Nix build fails because the package declares dependencies incompatible with the GHC version in this nixpkgs commit. The pipeline still fetches the patched source tree and runs the license scan; only the D2D mapping is skipped.:
Screenshot 2026-08-18 141322

Design notes

  • Custom Nix image: Built on first use with zstd, xz, bzip2, and gzip installed. Without this, nix-shell -p fetches the decompressors on every extraction, which hits the CDN's rate limit.
  • Local nixpkgs cache: A bare git clone of nixpkgs lives on the host. Each scan shallow-fetches its commit and creates a temporary worktree, bind-mounted into the container read-only. Avoids GitHub rate limits.
  • Concurrent scans: RQ runs each scan in its own worker process. File locks serialize image builds, git operations, and GC.
  • Nix store GC: The nix-eval-cache volume is pruned with nix-collect-garbage --delete-older-than 12h, at most once every 3 hours, so disk usage stays bounded.

Notes

Because the pipeline relies on a Linux-based Docker container (nixos/nix) to build sources, providing a PURL for a non-Linux system (e.g., darwin) triggers a system barrier warning.
When this happens, the pipeline safely falls back to evaluating the source using the container's native Linux environment. The extracted source tree will contain Linux-specific patches rather than macOS patches. The impact on the d2d mapping is expected to be minimal, though a small number of files may remain unmapped due to missing OS-specific structural patches.

Checklist

  • I have read the contributing guidelines
  • I have linked an existing issue above
  • I have added unit tests covering the new code
  • I have reviewed and understood every line of this PR

chinyeungli and others added 30 commits March 13, 2026 13:19
 - Get the input and extract content into the from/ codebase.
 - Build the source and place the built files into the to/ codebase.
 - Run scans.
 - Identify sources in from/ that are used in the build.

Signed-off-by: Chin Yeung Li <tli@nexb.com>
…ses detected in the codebase #1767

 * Introduce new "LICENSE_ISSUE" tag
 * License deduplication/simplification is not working well; work in progress

Signed-off-by: Chin Yeung Li <tli@nexb.com>
This commit is for testing purpose and is definitely not ready.

Signed-off-by: Chin Yeung Li <tli@nexb.com>
Signed-off-by: tdruez <tdruez@aboutcode.org>
Signed-off-by: tdruez <tdruez@aboutcode.org>
Signed-off-by: Chin Yeung Li <tli@nexb.com>
Signed-off-by: Chin Yeung Li <tli@nexb.com>
 * Use Docker for building instead of Cargo
 * Accept only one PURL as input
 * Use the .rlib found in .d files for D2D mapping
 * Remove unnecessary code

Signed-off-by: Chin Yeung Li <tli@nexb.com>
 * Add comparison logic
 * Add tests
 * Update extra_data fields
 * Better code organization
 * etc..

Signed-off-by: Chin Yeung Li <tli@nexb.com>
Signed-off-by: tdruez <tdruez@aboutcode.org>
Signed-off-by: tdruez <tdruez@aboutcode.org>
Signed-off-by: Rishabh Rohil <rishabhrohil024@gmail.com>
Signed-off-by: Rishabh Rohil <rishabhrohil024@gmail.com>
Signed-off-by: tdruez <tdruez@aboutcode.org>
Signed-off-by: tdruez <tdruez@aboutcode.org>
Signed-off-by: tdruez <tdruez@aboutcode.org>
Signed-off-by: OmAnand857 <allansmith2561@gmail.com>
Signed-off-by: tdruez <tdruez@aboutcode.org>
Signed-off-by: Aayush Kumar <code@aayushk.dev>
Signed-off-by: tdruez <tdruez@aboutcode.org>
Signed-off-by: tdruez <tdruez@aboutcode.org>
tdruez and others added 12 commits September 4, 2026 06:11
Signed-off-by: tdruez <tdruez@aboutcode.org>
Signed-off-by: Chin Yeung <tli@nexb.com>
Signed-off-by: Chin Yeung Li <tli@nexb.com>
Signed-off-by: Chin Yeung Li <tli@nexb.com>
 * Build the package binary from source using Docker if binary cannot be found in cache.nixos.org
 * Enhance logging

Signed-off-by: Chin Yeung Li <tli@nexb.com>
 * Add `.resolve()` to resolve file system path

Signed-off-by: Chin Yeung Li <tli@nexb.com>
* Many D2D steps look for resources without a status. However, the earlier
  scanning step flags all resources as "scanned". To prevent D2D steps from
  skipping these resources, we clear the status of all `to` resources

Signed-off-by: Chin Yeung Li <tli@nexb.com>
Signed-off-by: Chin Yeung Li <tli@nexb.com>
Signed-off-by: Chin Yeung Li <tli@nexb.com>
* Fully extract the codebase for D2D
* Update the "from" resource handling to support resources with status
* Refactor `extract_nar_archive()`
* Prevent permission issues during extraction

Signed-off-by: Chin Yeung Li <tli@nexb.com>
Signed-off-by: Chin Yeung Li <tli@nexb.com>
Signed-off-by: Chin Yeung Li <tli@nexb.com>

@Shriprasad-P Shriprasad-P left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review

PR: Pipeline for Nix

Touched: Dockerfile, docker-compose.yml, docs/built-in-pipelines.rst, pyproject.toml, scanpipe/pipelines/__init__.py, scanpipe/pipelines/scan_nix_package.py

  • Addresses a concrete correctness/reliability issue based on the title and diff.
  • Diff is fairly large (+1973/-22); a short summary of risk areas from the author would help reviewers.

Commenting as a drive-by reviewer after reading the diff. Happy to look again if maintainers want a deeper pass on a specific file.

ziadhany and others added 14 commits September 28, 2026 13:27
Signed-off-by: ziad hany <ziadhany2016@gmail.com>
Signed-off-by: ziad hany <ziadhany2016@gmail.com>
Signed-off-by: Chin Yeung Li <tli@nexb.com>
Signed-off-by: Chin Yeung Li <tli@nexb.com>
Signed-off-by: Chin Yeung Li <tli@nexb.com>
- Introduce a local cache directory for the custom Nix image, bare git repo, and worktrees.
- Add file locks to safely support concurrent scans.
- Pre-install compression tools (`zstd`, `xz`, etc.) in a custom Docker image to prevent CDN rate-limiting and extraction timeouts.
- Implement Nix store garbage collection handling to prevent unlimited disk space usage.
- Improve error handling and add automatic retries for Docker Desktop startup races.

Signed-off-by: Chin Yeung Li <tli@nexb.com>
Signed-off-by: Chin Yeung Li <tli@nexb.com>
Signed-off-by: ziad hany <ziadhany2016@gmail.com>
Signed-off-by: ziad hany <ziadhany2016@gmail.com>
Signed-off-by: ziad hany <ziadhany2016@gmail.com>
Signed-off-by: ziad hany <ziadhany2016@gmail.com>
Signed-off-by: Tushar Goel <tushar.goel.dav@gmail.com>
Signed-off-by: ziad hany <ziadhany2016@gmail.com>
Co-authored-by: ziad hany <ziadhany2016@gmail.com>
Signed-off-by: ziad hany <ziadhany2016@gmail.com>
Signed-off-by: Chin Yeung <tli@nexb.com>
@chinyeungli
chinyeungli requested a review from tdruez September 28, 2026 06:16
Signed-off-by: Chin Yeung Li <tli@nexb.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

nixpkgs-clarity: Design and implement Scancode pipeline for single nixpkg