• Stars
    star
    243
  • Rank 161,285 (Top 4 %)
  • Language
    Rust
  • License
    MIT License
  • Created over 5 years ago
  • Updated 12 months ago

Reviews

There are no reviews yet. Be the first to send feedback to the community and the maintainers!

Repository Details

Install & Run nix without root permissions [maintainer=@Mic92]

nix-user-chroot

Build Status

Maintainance status: unmaintained. I currently do not have any use for the tool and therefore do not activly fix bugs or add features. I don't expect many regressions over time as kernel APIs are stable but new use cases might break with it. If you are a user having issues with it, you may also try out if nix-portable solves your use case. If you have recommendations from one over the other please, feel free to make a pull request to update this description.

Rust rewrite of lethalman's version to clarify the license situation. This forks also makes it possible to use the nix sandbox!

Run and install nix as user without root permissions. Nix-user-chroot requires user namespaces to perform its task (available since linux 3.8). Note that this is not available for unprivileged users in some Linux distributions such as Red Hat Linux, CentOS when using the stock kernel. It should be available in Ubuntu, Debian and Arch Linux.

Check if your kernel supports user namespaces for unprivileged users

$ unshare --user --pid echo YES
YES

The output should be YES. If the command is absent, an alternative is to check the kernel compile options:

$ zgrep CONFIG_USER_NS /proc/config.gz
CONFIG_USER_NS=y

On some systems, like Debian or Ubuntu, the kernel configuration is in a different place, so instead use:

$ grep CONFIG_USER_NS /boot/config-$(uname -r)
CONFIG_USER_NS=y

You can also try reading /proc/sys/kernel/unprivileged_userns_clone. This flag should be present, and set to 1:

$ cat /proc/sys/kernel/unprivileged_userns_clone
1

On Debian or Arch-based system this feature might be disabled by default. However they provide a sysctl switch to enable it at runtime.

Note that there may be security implications to enabling user namespaces.

On RedHat / CentOS 7.4 user namespaces are disabled by default, but can be enabled by:

  1. Adding namespace.unpriv_enable=1 to the kernel boot parameters via grubby
  2. echo "user.max_user_namespaces=15076" >> /etc/sysctl.conf to increase the number of allowed namespaces above the default 0.

For more details, see the RedHat Documentation

Download static binaries

Checkout the latest release and download the binary matching your architecture.

Install with cargo

$ cargo install nix-user-chroot

Build from source

$ git clone https://github.com/nix-community/nix-user-chroot
$ cd nix-user-chroot
$ cargo build --release

If you use rustup, you can also build a statically linked version:

$ rustup target add x86_64-unknown-linux-musl
$ cargo build --release --target=x86_64-unknown-linux-musl

Installation

This will download and extract latest nix binary tarball from the chroot:

$ mkdir -m 0755 ~/.nix
$ nix-user-chroot ~/.nix bash -c "curl -L https://nixos.org/nix/install | bash"

The installation described here will not work on NixOS this way, because you start with an empty nix store and miss therefore tools like bash and coreutils. You won't need nix-user-chroot on NixOS anyway since you can get similar functionality using nix run --store ~/.nix nixpkgs.bash nixpkgs.coreutils:

Usage

After installation you can always get into the nix user chroot using:

$ nix-user-chroot ~/.nix bash -l

You are in a user chroot where / is owned by your user, hence also /nix is owned by your user. Everything else is bind mounted from the real root.

The nix config is not in /etc/nix but in /nix/etc/nix, so that you can modify it. This is done with the NIX_CONF_DIR, which you can override at any time.

Libraries and applications from Nixpkgs with OpenGL or CUDA support need to load libraries from /run/opengl-driver/lib. For convenience, nix-user-chroot will bind mount /nix/var/nix/opengl-driver/lib (if it exists) to this location. You will still need to link the system libraries here, as their original locations are distro-dependent. For example, for CUDA support on Ubuntu 20.04:

$ mkdir -p /nix/var/nix/opengl-driver/lib
$ ln -s /usr/lib/x86_64-linux-gnu/libcuda.so.1 /nix/var/nix/opengl-driver/lib

If this directory didn't exist when you first entered the nix user chroot, you will need to reenter for /run/opengl-driver/lib to be mounted.

Wishlist

These are features the author would like to see, let me know, if you want to work on this:

Add an --install flag:

Instead of

$ mkdir -m 0755 ~/.nix
$ nix-user-chroot ~/.nix bash -c "curl -L https://nixos.org/nix/install | bash"

it should just be:

$ nix-user-chroot --install

This assumes we just install to $XDG_DATA_HOME or $HOME/.data/nix by default.

Add a setuid version

Since not all linux distributions allow user namespaces by default, we will need packages for those that install setuid binaries to achieve the same.

Similar projects

nix-portable

More Repositories

1

home-manager

Manage a user environment using Nix [maintainer=@rycee]
Nix
6,023
star
2

awesome-nix

😎 A curated list of the best resources in the Nix community [maintainer=@cyntheticfox]
2,546
star
3

nixos-generators

Collection of image builders [maintainer=@Lassulus]
Nix
1,338
star
4

NixOS-WSL

NixOS on WSL(2) [maintainer=@nzbr]
Nix
1,236
star
5

disko

Declarative disk partitioning and formatting using nix [maintainer=@Lassulus]
Nix
1,232
star
6

nix-direnv

A fast, persistent use_nix/use_flake implementation for direnv [maintainer=@Mic92 / @bbenne10]
Nix
1,170
star
7

nixvim

Configure Neovim with Nix! [maintainer=@pta2002, @traxys, @GaetanLepage]
Nix
1,060
star
8

nix-on-droid

Nix-enabled environment for your Android device. [maintainers=@t184256,@Gerschtli]
Nix
1,038
star
9

nixos-anywhere

install nixos everywhere via ssh [maintainer=@numtide]
Shell
1,029
star
10

NUR

Nix User Repository: User contributed nix packages [maintainer=@Mic92]
Python
882
star
11

impermanence

Modules to help you handle persistent state on systems with ephemeral root storage [maintainer=@talyz]
Nix
882
star
12

dream2nix

Simplified nix packaging for various programming language ecosystems [maintainer=@DavHau]
Nix
839
star
13

comma

Comma runs software without installing it. [maintainers=@Artturin,@burke,@DavHau]
Rust
831
star
14

rnix-lsp

WIP Language Server for Nix! [maintainer=@aaronjanse]
Rust
701
star
15

lanzaboote

Secure Boot for NixOS [maintainers=@blitz @raitobezarius @nikstur]
Rust
696
star
16

poetry2nix

Convert poetry projects to nix automagically [maintainer=@adisbladis]
Nix
693
star
17

nix-init

Generate Nix packages from URLs with hash prefetching, dependency inference, license detection, and more [maintainer=@figsoda]
Rust
692
star
18

nix-index

Quickly locate nix packages with specific files [maintainers=@bennofs @figsoda @raitobezarius]
Rust
681
star
19

naersk

Build Rust projects in Nix - no configuration, no code generation, no IFD, sandbox friendly.
Nix
643
star
20

nixd

Nix language server, based on nix libraries [maintainer=@inclyc]
C++
619
star
21

nixGL

A wrapper tool for nix OpenGL application [maintainer=@guibou]
Nix
611
star
22

lorri

Your project’s nix-env [maintainer=@Profpatsch,@nyarly]
Rust
576
star
23

robotnix

Build Android (AOSP) using Nix [maintainer=@danielfullmer,@Atemu]
Nix
558
star
24

fenix

Rust toolchains and rust-analyzer nightly for Nix [maintainer=@figsoda]
Nix
547
star
25

nixpkgs-fmt

Nix code formatter for nixpkgs [maintainer=@zimbatm]
Rust
503
star
26

nixpkgs-wayland

Automated, pre-built packages for Wayland (sway/wlroots) tools for NixOS. [maintainers=@colemickens, @Artturin]
Nix
467
star
27

emacs-overlay

Bleeding edge emacs overlay [maintainer=@adisbladis]
Nix
451
star
28

vulnix

Vulnerability (CVE) scanner for Nix/NixOS.
Python
378
star
29

nurl

Generate Nix fetcher calls from repository URLs [maintainer=@figsoda]
Rust
360
star
30

rnix-parser

A Nix parser written in Rust [maintainer=@oberblastmeister]
Nix
328
star
31

nixos-vscode-server

Visual Studio Code Server support in NixOS
Nix
316
star
32

crate2nix

rebuild only changed crates in CI with crate2nix and nix
Nix
311
star
33

terraform-nixos

A set of Terraform modules that are designed to deploy NixOS [maintainer=@adrian-gierakowski]
HCL
304
star
34

srvos

NixOS profiles for servers [maintainer=@numtide]
Nix
297
star
35

nixbox

NixOS Vagrant boxes [maintainer=@zimbatm]
HCL
276
star
36

neovim-nightly-overlay

[maintainer=@Kranzes]
Nix
267
star
37

vscode-nix-ide

Nix language support for VSCode editor [maintainer: @jnoortheen]
TypeScript
248
star
38

haumea

Filesystem-based module system for Nix [maintainer=@figsoda]
Nix
235
star
39

trustix

Trustix: Distributed trust and reproducibility tracking for binary caches [maintainer=@adisbladis]
Go
234
star
40

nix-zsh-completions

ZSH Completions for Nix
Shell
215
star
41

NixNG

A linux distribution based on Nix [maintainer=@MagicRB]
Nix
210
star
42

nix-index-database

Weekly updated nix-index database [maintainer=@Mic92]
Nix
205
star
43

noogle

https://noogle.dev - nix function exploring. [maintainer=@hsjobeki]
Nix
194
star
44

nix-melt

A ranger-like flake.lock viewer [maintainer=@figsoda]
Rust
190
star
45

pypi2nix

Abandoned! Generate Nix expressions for Python packages
Python
189
star
46

gomod2nix

Convert applications using Go modules to Nix expressions [maintainer=@adisbladis]
Nix
186
star
47

todomvc-nix

Example on how to nixify a project [maintainer=@Rizary]
Nix
160
star
48

flakelight

Framework for simplifying flake setup [maintainer=@accelbread]
Nix
159
star
49

nix-environments

Repository to maintain out-of-tree shell.nix files (maintainer=@mic92)
Nix
156
star
50

pip2nix

Freeze pip-installable packages into Nix expressions [maintainer=@datakurre]
Python
152
star
51

tree-sitter-nix

Nix grammar for tree-sitter [maintainer=@cstrahan]
JavaScript
148
star
52

docker-nixpkgs

docker images from nixpkgs [maintainer=@zimbatm]
Nix
137
star
53

linuxkit-nix

An easy to use Linux builder for macOS [maintainer=@nicknovitski]
Nix
133
star
54

nix-vscode-extensions

Nix expressions for VSCode and OpenVSX extensions [maintainers: @deemp, @AmeerTaweel]
Haskell
132
star
55

npmlock2nix

nixify npm based packages [maintainer=@andir]
Nix
125
star
56

yarn2nix

Generate nix expressions from a yarn.lock file [maintainer=???]
Nix
123
star
57

nixos-install-scripts

collection of one-shot scripts to install NixOS on various server hosters and other hardware. [maintainer=@happysalada]
Shell
122
star
58

nix-eval-jobs

Parallel nix evaluator with a streamable json output [maintainers @Mic92, @adisbladis]
C++
119
star
59

nixago

Generate configuration files using Nix [maintainer=@jmgilman]
Nix
118
star
60

nixdoc

Tool to generate documentation for Nix library functions [maintainer=@infinisil]
Nix
113
star
61

dns.nix

A Nix DSL for DNS zone files [maintainers=@raitobezarius @kirelagin @Tom-Hubrecht]
Nix
105
star
62

nix-unstable-installer

A place to host Nix unstable releases [maintainer=@lilyinstarlight]
Ruby
105
star
63

wiki

Nixos wiki [maintainer=@samueldr]
104
star
64

go-nix

Elements of Nix re-implemented as Go libraries [maintainer=@flokli]
Go
102
star
65

nixpkgs-lint

A fast semantic linter for Nix using tree-sitter 🌳 + ❄️. [maintainers=@Artturin,@siraben]
Rust
101
star
66

namaka

Snapshot testing for Nix based on haumea [maintainer=@figsoda]
Rust
96
star
67

nur-combined

A repository of NUR that combines all repositories [maintainer=@Mic92]
Nix
92
star
68

napalm

Support for building npm packages in Nix and lightweight npm registry [maintainer @jtojnar]
Nix
91
star
69

nixos-images

Automatically build (netboot) images for NixOS [maintainer=@Mic92]
Nix
90
star
70

nix-ld-rs

Run unpatched dynamic binaries on NixOS [maintainer=@zhaofengli @Mic92]
Rust
90
star
71

vgo2nix

Convert go.mod files to nixpkgs buildGoPackage compatible deps.nix files [maintainer=@adisbladis]
Nix
89
star
72

nixt

Simple unit-testing for Nix [maintainer=@Lord-Valen]
TypeScript
87
star
73

nur-packages-template

A template for NUR repositories: [maintainer=@fgaz]
Nix
84
star
74

pnpm2nix

Load pnpm lock files into nix :) [maintainer=@adisbladis]
Nix
82
star
75

mineflake

Declarative Minecraft server in NixOS [unmaintained]
Rust
75
star
76

infra

nix-community infrastructure [maintainer=@Mic92]
Nix
74
star
77

kde2nix

Provisional, experimental Plasma 6 (and friends) pre-release packaging [maintainer=@K900]
Nix
69
star
78

nix-data-science

Standard set of packages and overlays for data-scientists [maintainer=@tbenst]
Nix
69
star
79

pyproject.nix

A collection of Nix utilities to work with Python projects [maintainer=@adisbladis]
Nix
65
star
80

ethereum.nix

Nix packages and NixOS modules for the Ethereum ecosystem. [maintainers=@aldoborrero,@brianmcgee,@selfuryon]
Nix
65
star
81

setup.nix

Nixpkgs based build tools for declarative Python packages [maintainer=@datakurre]
Nix
64
star
82

nixpkgs.lib

nixpkgs lib for cheap instantiation [maintainer=@github-action] (with initial help from @blaggacao)
Nix
63
star
83

nix-installers

Nix installers for legacy distributions (rpm & deb & pacman) [maintainer=@adisbladis]
Nix
62
star
84

hydra-check

check hydra for the build status of a package [maintainer=@makefu,@Artturin]
Python
60
star
85

zon2nix

Convert the dependencies in `build.zig.zon` to a Nix expression [maintainer=@figsoda]
Zig
58
star
86

redoxpkgs

Cross-compile to Redox using Nix [maintainer=@aaronjanse]
Nix
51
star
87

nix-github-actions

A library to turn Nix Flake attribute sets into Github Actions matrices [maintainer=@adisbladis]
Nix
49
star
88

patsh

A command-line tool for patching shell scripts inspired by resholve [maintainer=@figsoda]
Rust
46
star
89

mavenix

Deterministic Maven builds using Nix [maintainer=@icetan]
Nix
45
star
90

nixpkgs-pytools

Tools for removing the tedious nature of creating nixpkgs derivations [maintainer=@costrouc]
Python
42
star
91

nix-unit

Unit testing for Nix code [maintainer=@adisbladis]
C++
41
star
92

docker-nix

Docker image for nix [maintainer=@zimbatm] [status=deprecated]
Dockerfile
38
star
93

nix-ts-mode

An Emacs major mode for editing Nix expressions, powered by tree-sitter.
Emacs Lisp
37
star
94

builtwithnix.org

Share the love of Nix [maintainer=@zimbatm]
HTML
37
star
95

nixpkgs-terraform-providers-bin

auto-updating terraform providers for nix [maintainer=@zimbatm]
Nix
35
star
96

nixops-libvirtd

NixOps libvirtd backend plugin [maintainer=@AmineChikhaoui]
Python
34
star
97

flake-nimble

Nimble packages Nix flake [maintainer=?]
Nix
33
star
98

authentik-nix

Nix flake with package, NixOS module and basic VM test for authentik. Trying to provide an alternative deployment mode to the officially supported docker-compose approach. Not affiliated with or officially supported by the authentik project [maintainer=@willibutz]
Nix
31
star
99

flake-firefox-nightly

this provides an auto-updating flake for firefox-nightly-bin from nixpkgs-mozilla [maintainer=@colemickens, @Artturin]
Nix
27
star
100

dreampkgs

A collection of software packages managed with dream2nix [maintainer=@DavHau]
Nix
26
star