these 4 derivations will be built: /nix/store/1s05iq45g85pw7fcnzm7glfi3yrah6hh-format-meson.drv /nix/store/hywfyv7aa51anhfbbjhf7rq146ws5n35-check-merge-conflicts.drv /nix/store/h72f2lxzv1dykdysar5dxip7g9yirmig-pre-commit-config.json.drv /nix/store/gndvkiwsys5qaxahhxs5qvybb82svwp9-pre-commit-run.drv these 11 paths will be fetched (12.2 MiB download, 35.3 MiB unpacked): /nix/store/sdm1k3b5d5gy5szf3ialbd6kxplz332w-pre-commit-4.5.1 /nix/store/7mqd83wz5k6zkn0crhwykb4nhx7r2sbw-python3.14-cfgv-3.5.0 /nix/store/mf4sbsxfzpaz6hzssrrhcnw0gifjfvg5-python3.14-distlib-0.4.0 /nix/store/6nrsyrxg0fwpgb091mfbav038sxgkrcw-python3.14-filelock-3.29.7 /nix/store/gdapza9z66z1nmydyw6ksha11yr8dyrr-python3.14-identify-2.6.19 /nix/store/ina7p30pnnzsvq0ljs2kii3ij21k9ip5-python3.14-nodeenv-1.10.0 /nix/store/jaj2x0j6sl7rc064bwvk9ycaszmwks1n-python3.14-pre-commit-hooks-6.0.0 /nix/store/zhqj1rncyr712dbfcyjix04s7864pa14-python3.14-python-discovery-1.4.2 /nix/store/iwqi5xbxblar62cnxfygn99bw3zim59w-python3.14-ukkonen-1.1.0 /nix/store/8rr4fbkl29ycxvx6g3ngsiy84202x51w-python3.14-virtualenv-21.6.1 /nix/store/znrza96d6d54gc2j4imn19pa17vlh1bm-zizmor-1.30.0 building '/nix/store/hywfyv7aa51anhfbbjhf7rq146ws5n35-check-merge-conflicts.drv' building '/nix/store/1s05iq45g85pw7fcnzm7glfi3yrah6hh-format-meson.drv' check-merge-conflicts> tribuchet: building on eliza format-meson> tribuchet: building on eliza Failed to find a machine for remote build! derivation: h72f2lxzv1dykdysar5dxip7g9yirmig-pre-commit-config.json.drv required (system, features): (aarch64-linux, []) 1 available machines: (systems, maxjobs, supportedFeatures, mandatoryFeatures) ([aarch64-darwin, x86_64-darwin], 8, [big-parallel, recursive-nix], []) building '/nix/store/h72f2lxzv1dykdysar5dxip7g9yirmig-pre-commit-config.json.drv' pre-commit-config.json> tribuchet: building on eliza pre-commit-config.json> Sourcing pytest-check-hook pre-commit-config.json> Using pytestCheckPhase Failed to find a machine for remote build! derivation: gndvkiwsys5qaxahhxs5qvybb82svwp9-pre-commit-run.drv required (system, features): (aarch64-linux, []) 1 available machines: (systems, maxjobs, supportedFeatures, mandatoryFeatures) ([aarch64-darwin, x86_64-darwin], 8, [big-parallel, recursive-nix], []) building '/nix/store/gndvkiwsys5qaxahhxs5qvybb82svwp9-pre-commit-run.drv' pre-commit-run> tribuchet: building on eliza pre-commit-run> Sourcing pytest-check-hook pre-commit-run> Using pytestCheckPhase pre-commit-run> Running phase: unpackPhase pre-commit-run> unpacking source archive /nix/store/4w6c2k1h0pd7dsjynz3nnfczsm9rmhdb-source pre-commit-run> source root is source pre-commit-run> Running phase: patchPhase pre-commit-run> Running phase: updateAutotoolsGnuConfigScriptsPhase pre-commit-run> Running phase: configurePhase pre-commit-run> no configure script, doing nothing pre-commit-run> Running phase: buildPhase pre-commit-run> Running: $ pre-commit run --all-files pre-commit-run> check-merge-conflicts....................................................Passed pre-commit-run> check-merge-conflicts-2..................................................Passed pre-commit-run> clang-format.............................................................Failed pre-commit-run> - hook id: clang-format pre-commit-run> - files were modified by this hook pre-commit-run> meson-format.............................................................Passed pre-commit-run> nixfmt...................................................................Passed pre-commit-run> shellcheck...............................................................Passed pre-commit-run> zizmor...................................................................Failed pre-commit-run> - hook id: zizmor pre-commit-run> - exit code: 12 pre-commit-run> pre-commit-run> INFO zizmor: 🌈 zizmor v1.30.0 pre-commit-run> WARN audit: zizmor: zizmor is running in offline mode by default; some audits and auto-fixes will not be available. see https://docs.zizmor.sh/usage/#operating-modes for details pre-commit-run> INFO audit: zizmor: 🌈 completed .github/workflows/backport.yml pre-commit-run> INFO audit: zizmor: 🌈 completed .github/workflows/ci.yml pre-commit-run> INFO audit: zizmor: 🌈 completed .github/workflows/labels.yml pre-commit-run> INFO audit: zizmor: 🌈 completed .github/workflows/upload-release.yml pre-commit-run> help[self-repository]: use GitHub's dedicated self-repository syntax pre-commit-run> --> .github/workflows/ci.yml:32:13 pre-commit-run> | pre-commit-run> 32 | - uses: ./.github/actions/install-nix-action pre-commit-run> | - ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ use '$/...' instead of './...' pre-commit-run> | _______| pre-commit-run> | | pre-commit-run> 33 | | with: pre-commit-run> 34 | | dogfood: ${{ github.event_name == 'workflow_dispatch' && inputs.dogfood || github.event_name != 'workflow_dispatch' }} pre-commit-run> 35 | | extra_nix_config: pre-commit-run> 36 | | experimental-features = nix-command flakes pre-commit-run> 37 | | github_token: ${{ secrets.GITHUB_TOKEN }} pre-commit-run> 38 | | use_cache: false pre-commit-run> | |________________________- this step pre-commit-run> | pre-commit-run> = note: audit confidence → High pre-commit-run> = note: this finding has an auto-fix pre-commit-run> = help: audit documentation → https://docs.zizmor.sh/audits/#self-repository pre-commit-run> pre-commit-run> help[self-repository]: use GitHub's dedicated self-repository syntax pre-commit-run> --> .github/workflows/ci.yml:48:15 pre-commit-run> | pre-commit-run> 48 | - uses: ./.github/actions/install-nix-action pre-commit-run> | - ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ use '$/...' instead of './...' pre-commit-run> | _________| pre-commit-run> | | pre-commit-run> 49 | | with: pre-commit-run> 50 | | dogfood: ${{ github.event_name == 'workflow_dispatch' && inputs.dogfood || github.event_name != 'workflow_dispatch' }} pre-commit-run> 51 | | extra_nix_config: experimental-features = nix-command flakes pre-commit-run> 52 | | github_token: ${{ secrets.GITHUB_TOKEN }} pre-commit-run> | |___________________________________________________- this step pre-commit-run> | pre-commit-run> = note: audit confidence → High pre-commit-run> = note: this finding has an auto-fix pre-commit-run> = help: audit documentation → https://docs.zizmor.sh/audits/#self-repository pre-commit-run> pre-commit-run> help[self-repository]: use GitHub's dedicated self-repository syntax pre-commit-run> --> .github/workflows/ci.yml:98:13 pre-commit-run> | pre-commit-run> 98 | - uses: ./.github/actions/install-nix-action pre-commit-run> | - ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ use '$/...' instead of './...' pre-commit-run> | _______| pre-commit-run> | | pre-commit-run> 99 | | with: pre-commit-run> 100 | | github_token: ${{ secrets.GITHUB_TOKEN }} pre-commit-run> 101 | | dogfood: ${{ github.event_name == 'workflow_dispatch' && inputs.dogfood || github.event_name != 'workflow_dispatch' }} pre-commit-run> ... | pre-commit-run> 104 | | # Since ubuntu 22.30, unprivileged usernamespaces are no longer allowed to map to the root user: pre-commit-run> 105 | | # https://ubuntu.com/blog/ubuntu-23-10-restricted-unprivileged-user-namespaces pre-commit-run> | |__________________________________________________________________________________- this step pre-commit-run> | pre-commit-run> = note: audit confidence → High pre-commit-run> = note: this finding has an auto-fix pre-commit-run> = help: audit documentation → https://docs.zizmor.sh/audits/#self-repository pre-commit-run> pre-commit-run> help[self-repository]: use GitHub's dedicated self-repository syntax pre-commit-run> --> .github/workflows/ci.yml:156:13 pre-commit-run> | pre-commit-run> 156 | - uses: ./.github/actions/install-nix-action pre-commit-run> | - ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ use '$/...' instead of './...' pre-commit-run> | _______| pre-commit-run> | | pre-commit-run> 157 | | with: pre-commit-run> 158 | | github_token: ${{ secrets.GITHUB_TOKEN }} pre-commit-run> 159 | | dogfood: ${{ github.event_name == 'workflow_dispatch' && inputs.dogfood || github.event_name != 'workflow_dispatch' }} pre-commit-run> | |______________________________________________________________________________________________________________________________- this step pre-commit-run> | pre-commit-run> = note: audit confidence → High pre-commit-run> = note: this finding has an auto-fix pre-commit-run> = help: audit documentation → https://docs.zizmor.sh/audits/#self-repository pre-commit-run> pre-commit-run> help[self-repository]: use GitHub's dedicated self-repository syntax pre-commit-run> --> .github/workflows/ci.yml:232:13 pre-commit-run> | pre-commit-run> 232 | - uses: ./.github/actions/install-nix-action pre-commit-run> | - ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ use '$/...' instead of './...' pre-commit-run> | _______| pre-commit-run> | | pre-commit-run> 233 | | with: pre-commit-run> 234 | | github_token: ${{ secrets.GITHUB_TOKEN }} pre-commit-run> 235 | | dogfood: ${{ github.event_name == 'workflow_dispatch' && inputs.dogfood || github.event_name != 'workflow_dispatch' }} pre-commit-run> 236 | | extra_nix_config: "sandbox = true" pre-commit-run> | |__________________________________________- this step pre-commit-run> | pre-commit-run> = note: audit confidence → High pre-commit-run> = note: this finding has an auto-fix pre-commit-run> = help: audit documentation → https://docs.zizmor.sh/audits/#self-repository pre-commit-run> pre-commit-run> help[self-repository]: use GitHub's dedicated self-repository syntax pre-commit-run> --> .github/workflows/ci.yml:292:13 pre-commit-run> | pre-commit-run> 292 | - uses: ./.github/actions/install-nix-action pre-commit-run> | - ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ use '$/...' instead of './...' pre-commit-run> | _______| pre-commit-run> | | pre-commit-run> 293 | | with: pre-commit-run> 294 | | github_token: ${{ secrets.GITHUB_TOKEN }} pre-commit-run> 295 | | dogfood: ${{ github.event_name == 'workflow_dispatch' && inputs.dogfood || github.event_name != 'workflow_dispatch' }} pre-commit-run> 296 | | extra_nix_config: | pre-commit-run> 297 | | experimental-features = flakes nix-command ca-derivations impure-derivations pre-commit-run> 298 | | max-jobs = 1 pre-commit-run> | |______________________- this step pre-commit-run> | pre-commit-run> = note: audit confidence → High pre-commit-run> = note: this finding has an auto-fix pre-commit-run> = help: audit documentation → https://docs.zizmor.sh/audits/#self-repository pre-commit-run> pre-commit-run> help[self-repository]: use GitHub's dedicated self-repository syntax pre-commit-run> --> .github/workflows/upload-release.yml:26:15 pre-commit-run> | pre-commit-run> 26 | - uses: ./.github/actions/install-nix-action pre-commit-run> | - ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ use '$/...' instead of './...' pre-commit-run> | _________| pre-commit-run> | | pre-commit-run> 27 | | with: pre-commit-run> 28 | | dogfood: false # Use stable version pre-commit-run> 29 | | use_cache: false # Don't want any cache injection shenanigans pre-commit-run> 30 | | extra_nix_config: | pre-commit-run> 31 | | experimental-features = nix-command flakes pre-commit-run> | |______________________________________________________- this step pre-commit-run> | pre-commit-run> = note: audit confidence → High pre-commit-run> = note: this finding has an auto-fix pre-commit-run> = help: audit documentation → https://docs.zizmor.sh/audits/#self-repository pre-commit-run> pre-commit-run> 35 findings (3 ignored, 25 suppressed, 7 safe fixes): 0 informational, 7 low, 0 medium, 0 high pre-commit-run> pre-commit-run> diff --git a/src/libstore/build/derivation-building-goal.cc b/src/libstore/build/derivation-building-goal.cc pre-commit-run> index 5792cec..92d8e69 100644 pre-commit-run> --- a/src/libstore/build/derivation-building-goal.cc pre-commit-run> +++ b/src/libstore/build/derivation-building-goal.cc pre-commit-run> @@ -1069,8 +1069,7 @@ Goal::Co DerivationBuildingGoal::buildLocally( pre-commit-run> || settings.extraPlatforms.get().count(drv->platform) || drv->isBuiltin(); pre-commit-run> auto required = drvOptions.getRequiredSystemFeatures(*drv); pre-commit-run> auto & available = worker.store.config.systemFeatures.get(); pre-commit-run> - bool featuresOk = pre-commit-run> - std::ranges::all_of(required, [&](const std::string & f) { return available.count(f); }); pre-commit-run> + bool featuresOk = std::ranges::all_of(required, [&](const std::string & f) { return available.count(f); }); pre-commit-run> if (worker.settings.maxBuildJobs.get() != 0 && platformOk && featuresOk) { pre-commit-run> debug( pre-commit-run> "external builder declined '%s'; falling back to a local build", error: Cannot build '/nix/store/gndvkiwsys5qaxahhxs5qvybb82svwp9-pre-commit-run.drv'. Reason: builder failed with exit code 1. Output paths: /nix/store/d6iz0l0s2rwkz9rdrsnqcpfczy6a9xr3-pre-commit-run Last 25 log lines: > 29 | | use_cache: false # Don't want any cache injection shenanigans > 30 | | extra_nix_config: | > 31 | | experimental-features = nix-command flakes > | |______________________________________________________- this step > | > = note: audit confidence → High > = note: this finding has an auto-fix > = help: audit documentation → https://docs.zizmor.sh/audits/#self-repository > > 35 findings (3 ignored, 25 suppressed, 7 safe fixes): 0 informational, 7 low, 0 medium, 0 high > > diff --git a/src/libstore/build/derivation-building-goal.cc b/src/libstore/build/derivation-building-goal.cc > index 5792cec..92d8e69 100644 > --- a/src/libstore/build/derivation-building-goal.cc > +++ b/src/libstore/build/derivation-building-goal.cc > @@ -1069,8 +1069,7 @@ Goal::Co DerivationBuildingGoal::buildLocally( > || settings.extraPlatforms.get().count(drv->platform) || drv->isBuiltin(); > auto required = drvOptions.getRequiredSystemFeatures(*drv); > auto & available = worker.store.config.systemFeatures.get(); > - bool featuresOk = > - std::ranges::all_of(required, [&](const std::string & f) { return available.count(f); }); > + bool featuresOk = std::ranges::all_of(required, [&](const std::string & f) { return available.count(f); }); > if (worker.settings.maxBuildJobs.get() != 0 && platformOk && featuresOk) { > debug( > "external builder declined '%s'; falling back to a local build", For full logs, run: nix log /nix/store/gndvkiwsys5qaxahhxs5qvybb82svwp9-pre-commit-run.drv