From af7b05d708fb92e939a626cede1fed8c0b909431 Mon Sep 17 00:00:00 2001 From: LewdLeah Date: Sun, 27 Sep 2026 15:27:34 -0400 Subject: [PATCH 1/4] fix(get-platform): NixOS gets Debian engines like any other glibc distro Closes #29150 Signed-off-by: LewdLeah --- packages/fetch-engine/src/download.ts | 14 ++------ .../src/__tests__/getPlatform.test.ts | 34 +++++++++++++++++++ .../src/__tests__/getSSLVersion.test.ts | 21 +++++++++++- .../src/__tests__/parseDistro.test.ts | 17 ++++++++++ packages/get-platform/src/binaryTargets.ts | 2 -- packages/get-platform/src/getPlatform.ts | 21 ++++++++---- 6 files changed, 88 insertions(+), 21 deletions(-) diff --git a/packages/fetch-engine/src/download.ts b/packages/fetch-engine/src/download.ts index a87c53f568e4..4f4c0b41e500 100644 --- a/packages/fetch-engine/src/download.ts +++ b/packages/fetch-engine/src/download.ts @@ -14,7 +14,7 @@ import { BinaryType } from './BinaryType' import { chmodPlusX } from './chmodPlusX' import { cleanupCache } from './cleanupCache' import { downloadZip } from './downloadZip' -import { allEngineEnvVarsSet, getBinaryEnvVarPath } from './env' +import { getBinaryEnvVarPath } from './env' import { getHash } from './getHash' import { getBar } from './log' import { getCacheDir, getDownloadUrl, overwriteFile } from './utils' @@ -73,17 +73,9 @@ export async function download(options: DownloadOptions): Promise { } // get platform - const { binaryTarget, ...os } = await getPlatformInfo() + const { binaryTarget } = await getPlatformInfo() - if (os.targetDistro && ['nixos'].includes(os.targetDistro) && !allEngineEnvVarsSet(Object.keys(options.binaries))) { - console.error( - `${yellow('Warning')} Precompiled engine files are not available for ${ - os.targetDistro - }, please provide the paths via environment variables, see https://pris.ly/d/custom-engines`, - ) - } else if ( - ['freebsd11', 'freebsd12', 'freebsd13', 'freebsd14', 'freebsd15', 'openbsd', 'netbsd'].includes(binaryTarget) - ) { + if (['freebsd11', 'freebsd12', 'freebsd13', 'freebsd14', 'freebsd15', 'openbsd', 'netbsd'].includes(binaryTarget)) { console.error( `${yellow( 'Warning', diff --git a/packages/get-platform/src/__tests__/getPlatform.test.ts b/packages/get-platform/src/__tests__/getPlatform.test.ts index 47fc45927e6a..0d6a7682df0b 100644 --- a/packages/get-platform/src/__tests__/getPlatform.test.ts +++ b/packages/get-platform/src/__tests__/getPlatform.test.ts @@ -155,6 +155,40 @@ describe('getBinaryTargetForCurrentPlatformInternal', () => { expect(ctx.mocked['console.error'].mock.calls.join('\n')).toMatchInlineSnapshot(`""`) }) + it('nixos (nixos), amd64 (x86_64), openssl-3.0.x', () => { + expect( + getBinaryTargetForCurrentPlatformInternal({ + platform, + libssl: '3.0.x', + arch: 'x64', + archFromUname: 'x86_64', + familyDistro: 'nixos', + originalDistro: 'nixos', + targetDistro: 'debian', + }), + ).toBe('debian-openssl-3.0.x') + expect(ctx.mocked['console.log'].mock.calls.join('\n')).toMatchInlineSnapshot(`""`) + expect(ctx.mocked['console.warn'].mock.calls.join('\n')).toMatchInlineSnapshot(`""`) + expect(ctx.mocked['console.error'].mock.calls.join('\n')).toMatchInlineSnapshot(`""`) + }) + + it('nixos (nixos), arm64 (aarch64), openssl-3.0.x', () => { + expect( + getBinaryTargetForCurrentPlatformInternal({ + platform, + libssl: '3.0.x', + arch: 'arm64', + archFromUname: 'aarch64', + familyDistro: 'nixos', + originalDistro: 'nixos', + targetDistro: 'debian', + }), + ).toBe('linux-arm64-openssl-3.0.x') + expect(ctx.mocked['console.log'].mock.calls.join('\n')).toMatchInlineSnapshot(`""`) + expect(ctx.mocked['console.warn'].mock.calls.join('\n')).toMatchInlineSnapshot(`""`) + expect(ctx.mocked['console.error'].mock.calls.join('\n')).toMatchInlineSnapshot(`""`) + }) + it('unknown (unknown), amd64 (x86_64), openssl-3.0.x', () => { expect( getBinaryTargetForCurrentPlatformInternal({ diff --git a/packages/get-platform/src/__tests__/getSSLVersion.test.ts b/packages/get-platform/src/__tests__/getSSLVersion.test.ts index 1e70571474d5..9402c0888658 100644 --- a/packages/get-platform/src/__tests__/getSSLVersion.test.ts +++ b/packages/get-platform/src/__tests__/getSSLVersion.test.ts @@ -1,4 +1,4 @@ -import { describe, expect, it } from 'vitest' +import { afterEach, describe, expect, it, vi } from 'vitest' import { computeLibSSLSpecificPaths, getArchFromUname, getSSLVersion } from '../getPlatform' import { vitestContext } from '../test-utils/vitestContext' @@ -8,11 +8,30 @@ const describeIf = (condition: boolean) => (condition ? describe : describe.skip const ctx = vitestContext.new().assemble() describeIf(process.platform === 'linux')('computeLibSSLSpecificPaths', () => { + afterEach(() => { + vi.unstubAllEnvs() + }) + it('should not return an error', () => { const arch = 'x64' const archFromUname = 'x86_64' computeLibSSLSpecificPaths({ familyDistro: 'debian', arch, archFromUname }) }) + + it('reads nix-ld library path on nixos', () => { + vi.stubEnv('NIX_LD_LIBRARY_PATH', '/run/current-system/sw/share/nix-ld/lib:/nix/store/abc-openssl-3.0.x/lib') + vi.stubEnv('LD_LIBRARY_PATH', '') + expect(computeLibSSLSpecificPaths({ familyDistro: 'nixos', arch: 'x64', archFromUname: 'x86_64' })).toEqual([ + '/run/current-system/sw/share/nix-ld/lib', + '/nix/store/abc-openssl-3.0.x/lib', + ]) + }) + + it('returns no paths on nixos without nix-ld', () => { + vi.stubEnv('NIX_LD_LIBRARY_PATH', '') + vi.stubEnv('LD_LIBRARY_PATH', '') + expect(computeLibSSLSpecificPaths({ familyDistro: 'nixos', arch: 'x64', archFromUname: 'x86_64' })).toEqual([]) + }) }) describeIf(process.platform === 'linux')('getSSLVersion', () => { diff --git a/packages/get-platform/src/__tests__/parseDistro.test.ts b/packages/get-platform/src/__tests__/parseDistro.test.ts index 710e9ffae232..ac9d9d0710f6 100644 --- a/packages/get-platform/src/__tests__/parseDistro.test.ts +++ b/packages/get-platform/src/__tests__/parseDistro.test.ts @@ -224,6 +224,23 @@ ID_LIKE="opensuse suse" originalDistro: 'opensuse-tumbleweed', }, }, + { + name: 'nixos', + content: ` +NAME=NixOS +VERSION="26.05 (Yarara)" +ID=nixos +ID_LIKE="" +PRETTY_NAME="NixOS 26.05 (Yarara)" +VERSION_ID="26.05" +VERSION_CODENAME=yarara + `, + expect: { + targetDistro: 'debian', + familyDistro: 'nixos', + originalDistro: 'nixos', + }, + }, { name: 'unknown', content: ` diff --git a/packages/get-platform/src/binaryTargets.ts b/packages/get-platform/src/binaryTargets.ts index 8304ea603885..8dc703b2b091 100644 --- a/packages/get-platform/src/binaryTargets.ts +++ b/packages/get-platform/src/binaryTargets.ts @@ -18,7 +18,6 @@ export type BinaryTarget = | 'linux-musl-openssl-3.0.x' | 'linux-musl-arm64-openssl-1.1.x' | 'linux-musl-arm64-openssl-3.0.x' - | 'linux-nixos' | 'linux-static-x64' | 'linux-static-arm64' | 'windows' @@ -50,7 +49,6 @@ export const binaryTargets: BinaryTarget[] = [ 'linux-musl-openssl-3.0.x', 'linux-musl-arm64-openssl-1.1.x', 'linux-musl-arm64-openssl-3.0.x', - 'linux-nixos', 'linux-static-x64', 'linux-static-arm64', 'windows', diff --git a/packages/get-platform/src/getPlatform.ts b/packages/get-platform/src/getPlatform.ts index 3b152ba42e11..5cedf99ac8b1 100644 --- a/packages/get-platform/src/getPlatform.ts +++ b/packages/get-platform/src/getPlatform.ts @@ -38,7 +38,6 @@ export type DistroInfo = { | 'debian' | 'musl' | 'arm' - | 'nixos' | 'freebsd11' | 'freebsd12' | 'freebsd13' @@ -124,6 +123,7 @@ export function parseDistro(osReleaseInput: string): DistroInfo { * * Alpine Linux => ID=alpine => targetDistro=musl, familyDistro=alpine * Raspbian => ID=raspbian, ID_LIKE=debian => targetDistro=arm, familyDistro=debian + * NixOS => ID=nixos => targetDistro=debian, familyDistro=nixos * Debian => ID=debian => targetDistro=debian, familyDistro=debian * Distroless => ID=debian => targetDistro=debian, familyDistro=debian * Ubuntu => ID=ubuntu, ID_LIKE=debian => targetDistro=debian, familyDistro=debian @@ -157,9 +157,9 @@ export function parseDistro(osReleaseInput: string): DistroInfo { { id: 'nixos' }, ({ id: originalDistro }) => ({ - targetDistro: 'nixos', - originalDistro, + targetDistro: 'debian', familyDistro: 'nixos', + originalDistro, }) as const, ) .with( @@ -303,6 +303,17 @@ export function computeLibSSLSpecificPaths(args: ComputeLibSSLSpecificPathsParam debug('Trying platform-specific paths for "alpine"') return ['/lib', '/usr/lib'] }) + .with({ familyDistro: 'nixos' }, () => { + /* NixOS (nix-ld lists libraries for foreign binaries in NIX_LD_LIBRARY_PATH) */ + debug('Trying platform-specific paths for "nixos"') + return [ + ...new Set( + [process.env.NIX_LD_LIBRARY_PATH, process.env.LD_LIBRARY_PATH].flatMap((value) => + (value ?? '').split(':').filter(Boolean), + ), + ), + ] + }) .with({ familyDistro: 'debian' }, ({ archFromUname }) => { /* Linux Debian, Ubuntu, etc */ debug('Trying platform-specific paths for "debian" (and "ubuntu")') @@ -533,10 +544,6 @@ ${additionalMessage}`, return 'netbsd' } - if (platform === 'linux' && targetDistro === 'nixos') { - return 'linux-nixos' - } - if (platform === 'linux' && arch === 'arm64') { // 64 bit ARM (musl or glibc) const baseName = targetDistro === 'musl' ? 'linux-musl-arm64' : 'linux-arm64' From 58d60987aa2f793292f984db86fdf4068c162c21 Mon Sep 17 00:00:00 2001 From: LewdLeah Date: Sun, 27 Sep 2026 15:27:46 -0400 Subject: [PATCH 2/4] fix(get-platform): Alpine libssl arm never matched Signed-off-by: LewdLeah --- packages/get-platform/src/__tests__/getSSLVersion.test.ts | 7 +++++++ packages/get-platform/src/getPlatform.ts | 2 +- 2 files changed, 8 insertions(+), 1 deletion(-) diff --git a/packages/get-platform/src/__tests__/getSSLVersion.test.ts b/packages/get-platform/src/__tests__/getSSLVersion.test.ts index 9402c0888658..1850096678bf 100644 --- a/packages/get-platform/src/__tests__/getSSLVersion.test.ts +++ b/packages/get-platform/src/__tests__/getSSLVersion.test.ts @@ -18,6 +18,13 @@ describeIf(process.platform === 'linux')('computeLibSSLSpecificPaths', () => { computeLibSSLSpecificPaths({ familyDistro: 'debian', arch, archFromUname }) }) + it('returns alpine paths for alpine family', () => { + expect(computeLibSSLSpecificPaths({ familyDistro: 'alpine', arch: 'x64', archFromUname: 'x86_64' })).toEqual([ + '/lib', + '/usr/lib', + ]) + }) + it('reads nix-ld library path on nixos', () => { vi.stubEnv('NIX_LD_LIBRARY_PATH', '/run/current-system/sw/share/nix-ld/lib:/nix/store/abc-openssl-3.0.x/lib') vi.stubEnv('LD_LIBRARY_PATH', '') diff --git a/packages/get-platform/src/getPlatform.ts b/packages/get-platform/src/getPlatform.ts index 5cedf99ac8b1..31b59f0eb823 100644 --- a/packages/get-platform/src/getPlatform.ts +++ b/packages/get-platform/src/getPlatform.ts @@ -298,7 +298,7 @@ type ComputeLibSSLSpecificPathsParams = { export function computeLibSSLSpecificPaths(args: ComputeLibSSLSpecificPathsParams) { return match(args) - .with({ familyDistro: 'musl' }, () => { + .with({ familyDistro: 'alpine' }, () => { /* Linux Alpine */ debug('Trying platform-specific paths for "alpine"') return ['/lib', '/usr/lib'] From 2402966371e883e785316ee89043615e734965b5 Mon Sep 17 00:00:00 2001 From: LewdLeah Date: Sun, 27 Sep 2026 15:59:53 -0400 Subject: [PATCH 3/4] fix(get-platform): unreadable libssl dir no longer aborts detection Signed-off-by: LewdLeah --- packages/get-platform/src/__tests__/getSSLVersion.test.ts | 6 ++++++ packages/get-platform/src/getPlatform.ts | 7 ++----- 2 files changed, 8 insertions(+), 5 deletions(-) diff --git a/packages/get-platform/src/__tests__/getSSLVersion.test.ts b/packages/get-platform/src/__tests__/getSSLVersion.test.ts index 1850096678bf..508a1073abc3 100644 --- a/packages/get-platform/src/__tests__/getSSLVersion.test.ts +++ b/packages/get-platform/src/__tests__/getSSLVersion.test.ts @@ -64,6 +64,12 @@ describeIf(process.platform === 'linux')('getSSLVersion', () => { expect(strategy).not.toEqual(focusedStrategy) }) + it("falls back with a path that's not a dir", async () => { + ctx.fixture('libssl-specific-path/with-libssl-0') + const { strategy } = await getSSLVersion([`${ctx.tmpDir}/libssl.so.3`]) + expect(strategy).not.toEqual(focusedStrategy) + }) + it('selects the oldest libssl version, excluding libssl-0.x.x', async () => { ctx.fixture('libssl-specific-path/with-libssl-0') const { libssl, strategy } = await getSSLVersion([ctx.tmpDir]) diff --git a/packages/get-platform/src/getPlatform.ts b/packages/get-platform/src/getPlatform.ts index 31b59f0eb823..58d523816ef6 100644 --- a/packages/get-platform/src/getPlatform.ts +++ b/packages/get-platform/src/getPlatform.ts @@ -437,11 +437,8 @@ async function findLibSSL(directory: string) { try { const dirContents = await fs.readdir(directory) return dirContents.find((value) => value.startsWith('libssl.so.') && !value.startsWith('libssl.so.0')) - } catch (e) { - if (e.code === 'ENOENT') { - return undefined - } - throw e + } catch (_) { + return undefined } } From 6099c37f078b31b6aaa4708b830ff9b0db212d38 Mon Sep 17 00:00:00 2001 From: LewdLeah Date: Sun, 27 Sep 2026 16:17:48 -0400 Subject: [PATCH 4/4] fix(get-platform): schemas may still name linux-nixos Signed-off-by: LewdLeah --- packages/get-platform/src/binaryTargets.ts | 2 ++ 1 file changed, 2 insertions(+) diff --git a/packages/get-platform/src/binaryTargets.ts b/packages/get-platform/src/binaryTargets.ts index 8dc703b2b091..8304ea603885 100644 --- a/packages/get-platform/src/binaryTargets.ts +++ b/packages/get-platform/src/binaryTargets.ts @@ -18,6 +18,7 @@ export type BinaryTarget = | 'linux-musl-openssl-3.0.x' | 'linux-musl-arm64-openssl-1.1.x' | 'linux-musl-arm64-openssl-3.0.x' + | 'linux-nixos' | 'linux-static-x64' | 'linux-static-arm64' | 'windows' @@ -49,6 +50,7 @@ export const binaryTargets: BinaryTarget[] = [ 'linux-musl-openssl-3.0.x', 'linux-musl-arm64-openssl-1.1.x', 'linux-musl-arm64-openssl-3.0.x', + 'linux-nixos', 'linux-static-x64', 'linux-static-arm64', 'windows',