Uninstall: wait until nothing uses /nix before removing Nix

nix-installer uninstall failed at `systemctl stop nix.mount` ("Job
failed") while programs started from the Nix store still ran: a terminal
session's tools, or apps that mapped Home Manager's mime.cache.

- Before nix-installer runs, after Home Manager is gone, uninstall scans
  /proc for the user's processes whose exe, cwd, root, an fd or a mapped
  file is in /nix, and lists them by name and PID (the shells it was
  started from included; itself, its subshells and its curl | bash
  pipeline skipped). Close them and press Enter to re-check, or abort;
  with --yes or without a terminal it stops: "close these or reboot, then
  run uninstall again". Nothing is killed (replaces the old kill prompt).
- nix-installer runs from a copy outside /nix.
- cleanup check H: a fake /proc (STEAM_FRAME_NIX_PROC) with programs from
  the store stops before Nix; without them Nix is removed.
This commit is contained in:
Pierre Kisters committed 2026-10-01 18:14:19 +02:00
1 parent da01b7e5ac
commit 3acacc6388
5 files changed
+153 -47

No files matched your search

+15
View File
@@ -44,3 +44,18 @@ What `install.sh install` sets up is listed in the README under
`systemctl --user` against the outer session's user manager (the nested
desktop can't reach it with its own environment) and uses the installed
`home-manager` if there is one, else Home Manager's `master`.
`uninstall` removes Nix with nix-installer, which fails when it can't
unmount `/nix` (`systemctl stop nix.mount`). Before that it scans `/proc`
for processes using `/nix`: their `exe`, `cwd`, `root` or an `fd` links into
`/nix`, or `maps` names a file there (e.g. an app started before the
uninstall that mapped Home Manager's `mime.cache`). Only the user's own
processes are readable; the Nix daemon is nix-installer's to stop. Skipped:
the script itself, its subshells (descendants) and its process group (the
`curl | bash` pipeline). Its ancestors are listed with a hint to run
`uninstall` from another terminal. Nothing is killed: it asks to close them
and re-checks on Enter, or (`--yes`, no terminal) stops before Nix. A bash
from the Nix store re-executes the script with `/usr/bin/bash` first, and
nix-installer runs from a copy outside `/nix`. The check uses
`STEAM_FRAME_NIX_PROC` as a fake `/proc` (section H of
`modules/cleanup/check.nix`).