this derivation will be built: /nix/store/spv1azmc6kdqjpqp8dxd9yvrivm2bvwh-pre-commit-run.drv building '/nix/store/spv1azmc6kdqjpqp8dxd9yvrivm2bvwh-pre-commit-run.drv' pre-commit-run> tribuchet: building on jamie pre-commit-run> Sourcing pytest-check-hook pre-commit-run> Using pytestCheckPhase pre-commit-run> Running phase: unpackPhase pre-commit-run> unpacking source archive /nix/store/fn7sdn468ajia73hkvavs90gdz8jfb35-source pre-commit-run> source root is source pre-commit-run> Running phase: patchPhase pre-commit-run> Running phase: updateAutotoolsGnuConfigScriptsPhase pre-commit-run> Running phase: configurePhase pre-commit-run> no configure script, doing nothing pre-commit-run> Running phase: buildPhase pre-commit-run> Running: $ pre-commit run --all-files pre-commit-run> check-merge-conflicts....................................................Passed pre-commit-run> check-merge-conflicts-2..................................................Passed pre-commit-run> clang-format.............................................................Failed pre-commit-run> - hook id: clang-format pre-commit-run> - files were modified by this hook pre-commit-run> meson-format.............................................................Passed pre-commit-run> nixfmt...................................................................Passed pre-commit-run> shellcheck...............................................................Passed pre-commit-run> zizmor...................................................................Failed pre-commit-run> - hook id: zizmor pre-commit-run> - exit code: 12 pre-commit-run> pre-commit-run> INFO zizmor: 🌈 zizmor v1.30.0 pre-commit-run> WARN audit: zizmor: zizmor is running in offline mode by default; some audits and auto-fixes will not be available. see https://docs.zizmor.sh/usage/#operating-modes for details pre-commit-run> INFO audit: zizmor: 🌈 completed .github/workflows/backport.yml pre-commit-run> INFO audit: zizmor: 🌈 completed .github/workflows/ci.yml pre-commit-run> INFO audit: zizmor: 🌈 completed .github/workflows/labels.yml pre-commit-run> INFO audit: zizmor: 🌈 completed .github/workflows/upload-release.yml pre-commit-run> help[self-repository]: use GitHub's dedicated self-repository syntax pre-commit-run> --> .github/workflows/ci.yml:32:13 pre-commit-run> | pre-commit-run> 32 | - uses: ./.github/actions/install-nix-action pre-commit-run> | - ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ use '$/...' instead of './...' pre-commit-run> | _______| pre-commit-run> | | pre-commit-run> 33 | | with: pre-commit-run> 34 | | dogfood: ${{ github.event_name == 'workflow_dispatch' && inputs.dogfood || github.event_name != 'workflow_dispatch' }} pre-commit-run> 35 | | extra_nix_config: pre-commit-run> 36 | | experimental-features = nix-command flakes pre-commit-run> 37 | | github_token: ${{ secrets.GITHUB_TOKEN }} pre-commit-run> 38 | | use_cache: false pre-commit-run> | |________________________- this step pre-commit-run> | pre-commit-run> = note: audit confidence → High pre-commit-run> = note: this finding has an auto-fix pre-commit-run> = help: audit documentation → https://docs.zizmor.sh/audits/#self-repository pre-commit-run> pre-commit-run> help[self-repository]: use GitHub's dedicated self-repository syntax pre-commit-run> --> .github/workflows/ci.yml:48:15 pre-commit-run> | pre-commit-run> 48 | - uses: ./.github/actions/install-nix-action pre-commit-run> | - ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ use '$/...' instead of './...' pre-commit-run> | _________| pre-commit-run> | | pre-commit-run> 49 | | with: pre-commit-run> 50 | | dogfood: ${{ github.event_name == 'workflow_dispatch' && inputs.dogfood || github.event_name != 'workflow_dispatch' }} pre-commit-run> 51 | | extra_nix_config: experimental-features = nix-command flakes pre-commit-run> 52 | | github_token: ${{ secrets.GITHUB_TOKEN }} pre-commit-run> | |___________________________________________________- this step pre-commit-run> | pre-commit-run> = note: audit confidence → High pre-commit-run> = note: this finding has an auto-fix pre-commit-run> = help: audit documentation → https://docs.zizmor.sh/audits/#self-repository pre-commit-run> pre-commit-run> help[self-repository]: use GitHub's dedicated self-repository syntax pre-commit-run> --> .github/workflows/ci.yml:98:13 pre-commit-run> | pre-commit-run> 98 | - uses: ./.github/actions/install-nix-action pre-commit-run> | - ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ use '$/...' instead of './...' pre-commit-run> | _______| pre-commit-run> | | pre-commit-run> 99 | | with: pre-commit-run> 100 | | github_token: ${{ secrets.GITHUB_TOKEN }} pre-commit-run> 101 | | dogfood: ${{ github.event_name == 'workflow_dispatch' && inputs.dogfood || github.event_name != 'workflow_dispatch' }} pre-commit-run> ... | pre-commit-run> 104 | | # Since ubuntu 22.30, unprivileged usernamespaces are no longer allowed to map to the root user: pre-commit-run> 105 | | # https://ubuntu.com/blog/ubuntu-23-10-restricted-unprivileged-user-namespaces pre-commit-run> | |__________________________________________________________________________________- this step pre-commit-run> | pre-commit-run> = note: audit confidence → High pre-commit-run> = note: this finding has an auto-fix pre-commit-run> = help: audit documentation → https://docs.zizmor.sh/audits/#self-repository pre-commit-run> pre-commit-run> help[self-repository]: use GitHub's dedicated self-repository syntax pre-commit-run> --> .github/workflows/ci.yml:156:13 pre-commit-run> | pre-commit-run> 156 | - uses: ./.github/actions/install-nix-action pre-commit-run> | - ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ use '$/...' instead of './...' pre-commit-run> | _______| pre-commit-run> | | pre-commit-run> 157 | | with: pre-commit-run> 158 | | github_token: ${{ secrets.GITHUB_TOKEN }} pre-commit-run> 159 | | dogfood: ${{ github.event_name == 'workflow_dispatch' && inputs.dogfood || github.event_name != 'workflow_dispatch' }} pre-commit-run> | |______________________________________________________________________________________________________________________________- this step pre-commit-run> | pre-commit-run> = note: audit confidence → High pre-commit-run> = note: this finding has an auto-fix pre-commit-run> = help: audit documentation → https://docs.zizmor.sh/audits/#self-repository pre-commit-run> pre-commit-run> help[self-repository]: use GitHub's dedicated self-repository syntax pre-commit-run> --> .github/workflows/ci.yml:232:13 pre-commit-run> | pre-commit-run> 232 | - uses: ./.github/actions/install-nix-action pre-commit-run> | - ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ use '$/...' instead of './...' pre-commit-run> | _______| pre-commit-run> | | pre-commit-run> 233 | | with: pre-commit-run> 234 | | github_token: ${{ secrets.GITHUB_TOKEN }} pre-commit-run> 235 | | dogfood: ${{ github.event_name == 'workflow_dispatch' && inputs.dogfood || github.event_name != 'workflow_dispatch' }} pre-commit-run> 236 | | extra_nix_config: "sandbox = true" pre-commit-run> | |__________________________________________- this step pre-commit-run> | pre-commit-run> = note: audit confidence → High pre-commit-run> = note: this finding has an auto-fix pre-commit-run> = help: audit documentation → https://docs.zizmor.sh/audits/#self-repository pre-commit-run> pre-commit-run> help[self-repository]: use GitHub's dedicated self-repository syntax pre-commit-run> --> .github/workflows/ci.yml:292:13 pre-commit-run> | pre-commit-run> 292 | - uses: ./.github/actions/install-nix-action pre-commit-run> | - ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ use '$/...' instead of './...' pre-commit-run> | _______| pre-commit-run> | | pre-commit-run> 293 | | with: pre-commit-run> 294 | | github_token: ${{ secrets.GITHUB_TOKEN }} pre-commit-run> 295 | | dogfood: ${{ github.event_name == 'workflow_dispatch' && inputs.dogfood || github.event_name != 'workflow_dispatch' }} pre-commit-run> 296 | | extra_nix_config: | pre-commit-run> 297 | | experimental-features = flakes nix-command ca-derivations impure-derivations pre-commit-run> 298 | | max-jobs = 1 pre-commit-run> | |______________________- this step pre-commit-run> | pre-commit-run> = note: audit confidence → High pre-commit-run> = note: this finding has an auto-fix pre-commit-run> = help: audit documentation → https://docs.zizmor.sh/audits/#self-repository pre-commit-run> pre-commit-run> help[self-repository]: use GitHub's dedicated self-repository syntax pre-commit-run> --> .github/workflows/upload-release.yml:26:15 pre-commit-run> | pre-commit-run> 26 | - uses: ./.github/actions/install-nix-action pre-commit-run> | - ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ use '$/...' instead of './...' pre-commit-run> | _________| pre-commit-run> | | pre-commit-run> 27 | | with: pre-commit-run> 28 | | dogfood: false # Use stable version pre-commit-run> 29 | | use_cache: false # Don't want any cache injection shenanigans pre-commit-run> 30 | | extra_nix_config: | pre-commit-run> 31 | | experimental-features = nix-command flakes pre-commit-run> | |______________________________________________________- this step pre-commit-run> | pre-commit-run> = note: audit confidence → High pre-commit-run> = note: this finding has an auto-fix pre-commit-run> = help: audit documentation → https://docs.zizmor.sh/audits/#self-repository pre-commit-run> pre-commit-run> 35 findings (3 ignored, 25 suppressed, 7 safe fixes): 0 informational, 7 low, 0 medium, 0 high pre-commit-run> pre-commit-run> diff --git a/src/libstore/build/derivation-building-goal.cc b/src/libstore/build/derivation-building-goal.cc pre-commit-run> index 5792cec..92d8e69 100644 pre-commit-run> --- a/src/libstore/build/derivation-building-goal.cc pre-commit-run> +++ b/src/libstore/build/derivation-building-goal.cc pre-commit-run> @@ -1069,8 +1069,7 @@ Goal::Co DerivationBuildingGoal::buildLocally( pre-commit-run> || settings.extraPlatforms.get().count(drv->platform) || drv->isBuiltin(); pre-commit-run> auto required = drvOptions.getRequiredSystemFeatures(*drv); pre-commit-run> auto & available = worker.store.config.systemFeatures.get(); pre-commit-run> - bool featuresOk = pre-commit-run> - std::ranges::all_of(required, [&](const std::string & f) { return available.count(f); }); pre-commit-run> + bool featuresOk = std::ranges::all_of(required, [&](const std::string & f) { return available.count(f); }); pre-commit-run> if (worker.settings.maxBuildJobs.get() != 0 && platformOk && featuresOk) { pre-commit-run> debug( pre-commit-run> "external builder declined '%s'; falling back to a local build", error: Cannot build '/nix/store/spv1azmc6kdqjpqp8dxd9yvrivm2bvwh-pre-commit-run.drv'. Reason: builder failed with exit code 1. Output paths: /nix/store/4l8zn1zkxlz2wmj596wcpgj24nh69wyd-pre-commit-run Last 25 log lines: > 29 | | use_cache: false # Don't want any cache injection shenanigans > 30 | | extra_nix_config: | > 31 | | experimental-features = nix-command flakes > | |______________________________________________________- this step > | > = note: audit confidence → High > = note: this finding has an auto-fix > = help: audit documentation → https://docs.zizmor.sh/audits/#self-repository > > 35 findings (3 ignored, 25 suppressed, 7 safe fixes): 0 informational, 7 low, 0 medium, 0 high > > diff --git a/src/libstore/build/derivation-building-goal.cc b/src/libstore/build/derivation-building-goal.cc > index 5792cec..92d8e69 100644 > --- a/src/libstore/build/derivation-building-goal.cc > +++ b/src/libstore/build/derivation-building-goal.cc > @@ -1069,8 +1069,7 @@ Goal::Co DerivationBuildingGoal::buildLocally( > || settings.extraPlatforms.get().count(drv->platform) || drv->isBuiltin(); > auto required = drvOptions.getRequiredSystemFeatures(*drv); > auto & available = worker.store.config.systemFeatures.get(); > - bool featuresOk = > - std::ranges::all_of(required, [&](const std::string & f) { return available.count(f); }); > + bool featuresOk = std::ranges::all_of(required, [&](const std::string & f) { return available.count(f); }); > if (worker.settings.maxBuildJobs.get() != 0 && platformOk && featuresOk) { > debug( > "external builder declined '%s'; falling back to a local build", For full logs, run: nix log /nix/store/spv1azmc6kdqjpqp8dxd9yvrivm2bvwh-pre-commit-run.drv