Skip to content

harmonia-ci: let's make the deamon build stuff. - #849

Draft
Mic92 wants to merge 4 commits into
mainfrom
harmonia-ci
Draft

Mic92 wants to merge 4 commits into
mainfrom
harmonia-ci

Conversation

@Mic92

@Mic92 Mic92 commented Feb 22, 2026

Copy link
Copy Markdown
Member

No description provided.

@coderabbitai

coderabbitai Bot commented Feb 22, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: d7c02821-04e0-453a-a8e2-9ce293095709

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Mic92
Mic92 force-pushed the harmonia-ci branch 3 times, most recently from 5b966bb to e08601e Compare February 22, 2026 10:59
@Mic92 Mic92 changed the title harmonia-ci: let's make the deaemon build stuff. harmonia-ci: let's make the deamon build stuff. Feb 22, 2026
@Mic92
Mic92 force-pushed the harmonia-ci branch 3 times, most recently from 8785d4d to 94b6593 Compare February 22, 2026 11:17
@codecov

codecov Bot commented Feb 22, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 73.45662% with 976 lines in your changes missing coverage. Please review.
✅ Project coverage is 66.25%. Comparing base (48da606) to head (dfdfd99).
⚠️ Report is 1 commits behind head on main.

Files with missing lines Patch % Lines
harmonia-daemon/src/handler.rs 55.65% 191 Missing and 17 partials ⚠️
harmonia-daemon/src/build.rs 79.97% 114 Missing and 31 partials ⚠️
harmonia-daemon/src/linux_sandbox.rs 70.42% 113 Missing and 5 partials ⚠️
harmonia-daemon/src/export_references_graph.rs 76.33% 104 Missing and 7 partials ⚠️
harmonia-daemon/src/darwin_sandbox.rs 54.92% 94 Missing and 2 partials ⚠️
harmonia-daemon/src/main.rs 0.00% 51 Missing ⚠️
harmonia-daemon/src/builtins/buildenv.rs 62.40% 40 Missing and 10 partials ⚠️
harmonia-daemon/src/builtins/unpack_channel.rs 72.99% 29 Missing and 8 partials ⚠️
harmonia-daemon/src/builtins/fetchurl.rs 69.23% 27 Missing and 5 partials ⚠️
harmonia-daemon/src/config.rs 0.00% 30 Missing ⚠️
... and 12 more
Additional details and impacted files
@@            Coverage Diff             @@
##             main     #849      +/-   ##
==========================================
+ Coverage   64.58%   66.25%   +1.66%     
==========================================
  Files         146      162      +16     
  Lines       16822    20415    +3593     
  Branches    16822    20415    +3593     
==========================================
+ Hits        10865    13526    +2661     
- Misses       5304     6123     +819     
- Partials      653      766     +113     
Flag Coverage Δ
aarch64-darwin 66.64% <75.70%> (+1.93%) ⬆️
x86_64-linux 66.17% <75.66%> (+2.12%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@github-actions

Copy link
Copy Markdown
Contributor

🐰 Bencher Report

Branchharmonia-ci
Testbedgithub-actions

⚠️ WARNING: No Threshold found!

Without a Threshold, no Alerts will ever be generated.

Click here to create a new Threshold
For more information, see the Threshold documentation.
To only post results if a Threshold exists, set the --ci-only-thresholds flag.

Click to view all benchmark results
BenchmarkLatencymilliseconds (ms)
closure/download📈 view plot
⚠️ NO THRESHOLD
1,878.00 ms
http/concurrent_16📈 view plot
⚠️ NO THRESHOLD
473.51 ms
http/concurrent_4📈 view plot
⚠️ NO THRESHOLD
534.47 ms
http/sequential📈 view plot
⚠️ NO THRESHOLD
1,110.70 ms
🐰 View full continuous benchmarking report in Bencher

@DerDennisOP

DerDennisOP commented Apr 30, 2026 •

Copy link
Copy Markdown
Contributor

What about Gradient? https://github.com/wavelens/gradient ? Isn't this basically the same thing you are trying, but more mature?

We talked at the 38c3 and you we're like: "Another Nix CI system 🙄 , just use build-bot."

But I happy to migrate to harmonia daemon sandboxes once done ❤️

@Mic92

Mic92 commented May 1, 2026 •

Copy link
Copy Markdown
Member Author

What about Gradient? https://github.com/wavelens/gradient ? Isn't this basically the same thing you are trying, but more mature?

We talked at the 38c3 and you we're like: "Another Nix CI system 🙄 , just use build-bot."

But I happy to migrate to harmonia daemon sandboxes once done ❤️

I haven't looked your CI. Yeah. I might do the sandbox first after all. Also these days I am leaning towards stuff like NATS for really large build farms (> 1000 nodes).

@DerDennisOP

DerDennisOP commented May 9, 2026 •

Copy link
Copy Markdown
Contributor

I haven't looked your CI. Yeah. I might do the sandbox first after all. Also these days I am leaning towards stuff like NATS for really large build farms (> 1000 nodes).

That's should also be the goal for gradient, but imo Gradient is far away from hitting that kind of performance level. While Database queries are beeing improved and the custom protocol is modified to be able to handle many builders every day, it isn't a trivial task at all.

Mic92 and others added 4 commits August 5, 2026 01:34
Add design documents under docs/architecture/ci/ that describe the
planned standalone daemon for CI: build protocol, scheduler/database
shape, sandbox/security model, signing/upload, forge integration,
HA, GC, and the webui surface. PLAN.md tracks the in-progress
sandbox migration. LICENSE and harmonia-daemon/README catch up to
the harmonia-nar -> harmonia-file-nar rename.

Co-authored-by: Amaan Qureshi <git@amaanq.com>
Stand up the process-isolation layer the daemon will use to run
builders: a Sandbox trait with NoSandbox, LinuxSandbox (CLONE_NEWUSER /
CLONE_NEWMOUNT user-namespace runner), and a darwin_sandbox using
sandbox-exec.  build_users introduces file-locked UID allocation
(auto_user_lock on Linux when root, simple_user_lock for a configured
build-users-group on macOS), with supplementary GIDs from the group and
guards against self-UID and system-UID collisions.  pathlocks and
canonicalize cover store-path locking and the canonicalisation pass
that Nix runs on a builder's output before hashing.  The harmonia-daemon
config and NixOS module gain matching sandbox / buildUsersGroup options;
when the sandbox is off the NixOS unit re-enables the standard systemd
hardening that was previously unconditional.

Co-authored-by: Amaan Qureshi <git@amaanq.com>
Add the three builtin builders the standalone daemon will dispatch to
in place of executing a real builder.  buildenv assembles the
`buildEnv` output by walking the input drvs and rejecting malformed
manifests instead of silently producing an empty output.  fetchurl
implements `builtin:fetchurl` with the same hashing and ca-rewriting
semantics as Nix.  unpack_channel implements `builtin:unpack-channel`
by extracting a tarball through libarchive (via compress-tools-rs);
nix/packages.nix and the dev shell gain pkg-config + libarchive so the
crate links, and the cargo build switches to the mold linker on ELF.

Co-authored-by: Amaan Qureshi <git@amaanq.com>
…d tests

Wire harmonia-daemon up as a real builder.  build.rs (the executor)
walks a Derivation, dispatches builtin builders or spawns a sandboxed
child, drains stdout+stderr into bzip2-compressed build logs, enforces
the timeout via the process group, validates impureHostDeps against
allowed prefixes, sets NIX_OUTPUT_CHECKED / impureEnvVars for fixed-
output derivations, wires exportReferencesGraph and output constraints,
and cleans up partial outputs on any failed build.  passAsFile and
structuredAttrs are written to the build environment in the same shape
Nix uses.  scheduler.rs adds a DAG-aware build scheduler with bounded
concurrency.  export_references_graph.rs computes the closure graph
the builder hands to Nix-compatible drvs.

handler.rs gains query_missing for standalone-daemon clients, an
on-the-fly hashing NAR import path, and propagates repair removal
errors instead of swallowing them; nar_size == 0 is documented as the
"unknown" sentinel.  main.rs initialises tracing-subscriber, applies
the SandboxConfig, and preserves mount flags when remounting the store
writable.  Cargo manifests pull in the deps (bytes/bzip2/compress-tools/
libc/nix/tokio process/tracing-subscriber/...) and lib.rs publishes
the new modules.

Tests cover add_to_store_nar, build_derivation (1.4k lines of behaviour
coverage: fixed-output env, impure host deps, builtin dispatch,
timeouts using a shell busy-loop, partial-output cleanup, ...) and
query_missing.  TestStore provides shared fixture wiring across the
suite.  Three NixOS VM tests (tests/cache.nix, daemon-cache.nix,
privileged-sandbox.nix) exercise the daemon end-to-end through its
socket, including a real privileged-sandbox build that checks the
builder's credentials.

Co-authored-by: Amaan Qureshi <git@amaanq.com>
@Mic92

Mic92 commented Aug 19, 2026

Copy link
Copy Markdown
Member Author

The sandbox I am using in https://github.com/Mic92/tribuchet/
is now in a good shape (at least the Linux version, the macOS version hasn't seen much real-world testing yet). So I might start porting that over.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants