Skip to content

Add native EROFS OCI full-bundle producer - #488

Open
rahultee wants to merge 3 commits into
mainfrom
feat/native-erofs-bundle
Open

rahultee wants to merge 3 commits into
mainfrom
feat/native-erofs-bundle

Conversation

@rahultee

@rahultee rahultee commented Oct 5, 2026 •

Copy link
Copy Markdown

Why

Add an OCI image for the full nixmodules bundle, so it can be distributed without a shared disk. Keep the same module paths and contents.

What changed

  • Add bundle-oci, an OCI layout containing one uncompressed EROFS layer.
  • Build it directly from the same bundle and complete dependency closure used by the existing disk builder. No disk-image conversion.
  • Include /etc/nixmodules metadata and preserve store paths, file contents, links, permissions, and UID/GID 11000.
  • Keep existing disk outputs, per-module OCI outputs, and dependency pins unchanged.
  • Embed source URL, full Git revision, output name, and commit-based UTC creation time during the build. Local sources without a clean revision omit that annotation.
  • Add bundle-oci.copyTo, a small Skopeo wrapper that preserves digests and accepts authentication and digest-file options. No publishing-time image rewriting.
  • Add a small test fixture to CI and usage instructions to the README.

Test plan

Passed locally:

  • Nix formatting and whitespace checks.
  • Provenance, deterministic layout generation, local-source metadata handling, and a real OCI-to-OCI copyTo with --authfile and --digestfile. Every blob and the manifest digest stayed unchanged. The wrapper closure retains the exact image.
  • The EROFS layer is byte-identical before and after the provenance change.
  • A real EROFS fixture built with the pinned nixpkgs source. Checks cover OCI hashes and descriptors, the full dependency closure, metadata, contents, permissions, ownership, symlinks, and hardlinks.
  • Import, unpack, and mount of that fixture with an isolated containerd 2.3 instance. A chrooted process running as UID/GID 11000 could read the files and follow their links.

The normal flake checks did not finish while fetching and evaluating historical module inputs. The separate small fixture passed. The full production bundle, registry publication, containerd 2.1-specific integration, and DAX behavior were not tested here. See the PR checks for current CI status.

Rollout

This PR only adds a build output. It does not publish an image or change any running workload. Consumers must support native EROFS layers, with the EROFS unpack tools and differ configured.

Safe to revert: the existing disk and per-module OCI outputs are unchanged.

  • This is fully backward and forward compatible

~ written by ⠕ Replit

@rahultee
rahultee marked this pull request as ready for review October 6, 2026 00:02
@rahultee
rahultee requested a review from a team as a code owner October 6, 2026 00:02
@rahultee
rahultee requested review from airportyh and vlinkz and removed request for a team October 6, 2026 00:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant