Skip to content

Switch rootcell to nixpkgs-weekly and fix Lima first-switch compatibility#68

Merged
jimpudar merged 1 commit into
mainfrom
jmp/fix-rootcell-firewall-repro
May 23, 2026
Merged

Switch rootcell to nixpkgs-weekly and fix Lima first-switch compatibility#68
jimpudar merged 1 commit into
mainfrom
jmp/fix-rootcell-firewall-repro

Conversation

@jimpudar
Copy link
Copy Markdown
Collaborator

Summary

  • Move the flake to Determinate’s nixpkgs-weekly and use the repo’s plain p.lima host tools
  • Add a Lima version preflight so old limactl fails fast before .ssh.overVsock provisioning starts
  • Keep Rootcell guests on classic dbus-daemon to avoid the first nixos-rebuild switch hanging during a broker migration from the nixos-lima base image
  • Update the README and provider docs to describe the Lima version requirement

Testing

  • bun run lint
  • bun run typecheck
  • bun run test
  • nix eval --raw .#packages.aarch64-darwin.lima.version
  • nix eval --raw .#packages.x86_64-darwin.lima.version
  • nix shell .#hostTools --command limactl --version
  • Full macos-lima-user-v2 integration smoke passed, including fresh firewall and agent VM provisioning over VSOCK and egress-policy validation

@jimpudar jimpudar merged commit 7437a65 into main May 23, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant