mirror of
https://github.com/lhns/steam-frame-nix.git
synced 2026-10-06 01:00:13 +02:00
Docs: lazy Nix removal, install --clone with the template's credentials
README: what --clone does for a private repository (the template's gh/store helpers, the gh auth login offer, keep those lines in your config, what gets cloned into and that re-running continues), the git/gh lines in the usage example, and that uninstall no longer waits for programs from the Nix store. docs/cleanup.md: the clone steps, the untouched-template marker, and the LazyUnmount= drop-in.
This commit is contained in:
1 parent
6f163141f5
commit
85523b63ad
3 files changed
+67
-35
No files matched your search
+36
-19
@@ -45,11 +45,28 @@ What `install.sh install` sets up is listed in the README under
|
||||
desktop can't reach it with its own environment) and uses the installed
|
||||
`home-manager` if there is one, else Home Manager's `master`.
|
||||
|
||||
`install --clone` takes SteamOS' `git`, else `nix run nixpkgs#git`. An
|
||||
existing directory is reused only if it is the top of a clone whose
|
||||
`origin` is the same repository: URLs are compared as lower-case
|
||||
host/path without `.git` (so `git@host:o/r`, `ssh://git@host/o/r` and
|
||||
`https://host/o/r.git` match), and with `--ref` it must be on that branch.
|
||||
`install --clone` takes SteamOS' `git`, else `nix run nixpkgs#git`, always
|
||||
with `GIT_TERMINAL_PROMPT=0`. Each step checks whether an earlier run did it
|
||||
(Nix works: not installed). The target directory is cloned into only when it
|
||||
is missing, empty or the untouched template: `create_config` writes the hash
|
||||
of the configuration's files (without `.git`) to
|
||||
`.git/steam-frame-nix-template`, and the template counts as untouched while
|
||||
the files still match and there is at most one commit. Anything else (the
|
||||
clone of an earlier run, a changed template, any other directory) is used
|
||||
as it is: no clone, `--ref` ignored, straight to the switch.
|
||||
|
||||
Into an empty target, the template comes first, but only without a Home
|
||||
Manager configuration (no `~/.config/home-manager`); with one, git clones
|
||||
with that configuration's helpers. The switch to the template is skipped
|
||||
when it is linked, Home Manager is installed and git has a credential
|
||||
helper. The clone goes to `.<dir>.clone.XXXXXX` next to the target (removed
|
||||
if it fails, the template stays), replaces the template (checked unchanged
|
||||
again), then Home Manager switches to it. A failed switch leaves the clone,
|
||||
so a rerun only switches. `gh auth login --hostname github.com
|
||||
--git-protocol https`, with the Home Manager profile's `gh`, is offered only
|
||||
for `https://github.com/` URLs and with a terminal. Tests: section G of
|
||||
`modules/cleanup/check.nix` (a logging git, a fake nix,
|
||||
`STEAM_FRAME_NIX_TTY` instead of `/dev/tty`).
|
||||
|
||||
`restart-check` (run by the session module's activation after
|
||||
`steamFrameUserServices`, and by `install` at its end) compares the
|
||||
@@ -60,17 +77,17 @@ with the debugger drop-in, looks for a listener on port 8087 in
|
||||
`/proc/net/tcp*`. Tests use `STEAM_FRAME_NIX_PROC` and
|
||||
`STEAM_FRAME_NIX_CGROUP` (section F of `modules/cleanup/check.nix`).
|
||||
|
||||
`uninstall` removes Nix with nix-installer, which fails when it can't
|
||||
unmount `/nix` (`systemctl stop nix.mount`). Before that it scans `/proc`
|
||||
for processes using `/nix`: their `exe`, `cwd`, `root` or an `fd` links into
|
||||
`/nix`, or `maps` names a file there (e.g. an app started before the
|
||||
uninstall that mapped Home Manager's `mime.cache`). Only the user's own
|
||||
processes are readable; the Nix daemon is nix-installer's to stop. Skipped:
|
||||
the script itself, its subshells (descendants) and its process group (the
|
||||
`curl | bash` pipeline). Its ancestors are listed with a hint to run
|
||||
`uninstall` from another terminal. Nothing is killed: it asks to close them
|
||||
and re-checks on Enter, or (`--yes`, no terminal) stops before Nix. A bash
|
||||
from the Nix store re-executes the script with `/usr/bin/bash` first, and
|
||||
nix-installer runs from a root-owned copy in `/tmp`. The check uses
|
||||
`STEAM_FRAME_NIX_PROC` as a fake `/proc` (section H of
|
||||
`modules/cleanup/check.nix`).
|
||||
`uninstall` removes Nix with nix-installer (from a root-owned copy in
|
||||
`/tmp`), whose `systemctl stop nix.mount` fails while a process uses `/nix`,
|
||||
and in the Steam session some always do until logout (e.g. Steam and
|
||||
xdg-desktop-portal, once they mapped a file from the store). So first a
|
||||
runtime drop-in, `/run/systemd/system/nix.mount.d/50-steam-frame-nix-lazy-unmount.conf`
|
||||
with `LazyUnmount=yes`, makes that stop detach `/nix` (`umount -l`): the
|
||||
programs keep their open files until they exit. The drop-in is removed
|
||||
afterwards. Before that, for information, it lists the processes whose
|
||||
`exe`, `cwd`, `root` or an `fd` links into `/nix`, or whose `maps` names a
|
||||
file there (only the user's own are readable), except the script itself,
|
||||
its subshells and its process group (the `curl | bash` pipeline). Tests:
|
||||
section H of `modules/cleanup/check.nix` (`STEAM_FRAME_NIX_PROC` as a fake
|
||||
`/proc`, `STEAM_FRAME_NIX_SYSTEM_RUNTIME` for the drop-in, a logging
|
||||
nix-installer).
|
||||
Reference in new issue
Block a user