Go to file
Nikita Karetnikov e9c6c58418 substitute-binary: Support the Signature field of a narinfo file.
* guix/scripts/substitute-binary.scm (<narinfo>): Add the 'signature'
  and 'contents' fields.
  (narinfo-signature->canonical-sexp): New function.
  (narinfo-maker): Add the 'signature' argument and use it.
  (assert-valid-signature): New function.
  (read-narinfo): Support the Signature field.
  (write-narinfo): Use 'narinfo-contents'.
  (%allow-unauthenticated-substitutes?): New variable.
* guix/base64.scm, tests/base64.scm, tests/substitute-binary.scm: New files.
* Makefile.am (SCM_TESTS): Add tests/base64.scm and
  tests/substitute-binary.scm.
  (MODULES): Add guix/base64.scm.
* test-env.in: Set 'GUIX_ALLOW_UNAUTHENTICATED_SUBSTITUTES'.
2014-03-30 12:02:10 +02:00
build-aux check-available-binaries: Make sure substitutes are enabled. 2014-03-25 20:45:13 +01:00
doc offload: Allow build machines to specify a port number. 2014-03-13 21:58:04 +01:00
gnu gnu: ed: Upgrade to 1.10. 2014-03-29 23:15:27 +01:00
guix substitute-binary: Support the Signature field of a narinfo file. 2014-03-30 12:02:10 +02:00
m4 Add 'guix offload' as a daemon build hook. 2014-01-24 00:01:50 +01:00
nix daemon: Clear $NIX_SUBSTITUTERS when passed '--no-substitutes'. 2014-03-27 23:56:47 +01:00
nix-upstream@24cb65efc3 Update 'nix-upstream' sub-module. 2014-03-22 22:57:10 +01:00
po ui: Handle SRFI-35 '&message' conditions. 2014-02-21 23:49:52 +01:00
scripts guix: Add missing call to 'bindtextdomain'. 2013-10-12 22:29:31 +02:00
srfi Update SRFI-64 to the latest upstream version. 2014-02-24 16:30:08 -05:00
tests substitute-binary: Support the Signature field of a narinfo file. 2014-03-30 12:02:10 +02:00
.dir-locals.el utils: Add 'call-with-decompressed-port' and 'call-with-compressed-output-port'. 2014-03-24 22:15:29 +01:00
.gitignore Update .gitignore for Guile 2.0.9 bootstrap binaries. 2014-02-16 16:40:08 -05:00
.gitmodules build: Add Nix as a sub-module. 2012-12-03 23:05:11 +01:00
AUTHORS Add Manolis to 'AUTHORS'. 2014-02-16 19:53:59 +01:00
COPYING Add the usual top-level files. 2012-06-03 23:46:56 +02:00
ChangeLog build: Generate a ChangeLog file upon "make dist". 2013-05-12 16:35:17 +02:00
HACKING doc: Update packaging guidelines. 2014-03-10 23:43:31 +01:00
Makefile.am substitute-binary: Support the Signature field of a narinfo file. 2014-03-30 12:02:10 +02:00
NEWS Update 'NEWS'. 2013-12-11 13:06:19 +01:00
README doc: Improve "Installing Guix from Guix" section. 2013-11-16 21:56:44 +01:00
ROADMAP doc: Update 'ROADMAP'. 2014-01-03 18:19:58 +01:00
THANKS Thank Niels. 2014-01-03 16:51:30 +01:00
TODO Update 'TODO'. 2013-12-22 01:11:12 +01:00
bootstrap build: Have `bootstrap' run all the necessary steps. 2012-12-13 23:46:33 +01:00
config-daemon.ac Add 'guix offload' as a daemon build hook. 2014-01-24 00:01:50 +01:00
configure.ac Change the default store file name to /gnu/store. 2014-03-09 22:09:58 +01:00
daemon.am build: Change state and log directories to $localstatedir/.../guix. 2014-03-09 22:10:01 +01:00
doc.am build: Build the bootstrap-graph.{png,eps,pdf} under $(top_srcdir). 2013-10-18 22:05:39 +02:00
gnu-system.am gnu: Add mc 2014-03-26 10:50:01 -05:00
guix.scm Update license headers. 2013-01-06 00:47:50 +01:00
pre-inst-env.in build: Set 'NIX_LIBEXEC_DIR' in 'pre-inst-env'. 2014-01-26 15:53:56 +01:00
release.nix release.nix: Revert back to before unchroot experiments. 2013-05-12 15:18:17 +02:00
test-env.in substitute-binary: Support the Signature field of a narinfo file. 2014-03-30 12:02:10 +02:00

README

This file contains ambiguous Unicode characters!

This file contains ambiguous Unicode characters that may be confused with others in your current locale. If your use case is intentional and legitimate, you can safely ignore this warning. Use the Escape button to highlight these characters.

-*- mode: org -*-

[[http://www.gnu.org/software/guix/][GNU Guix]] (IPA: /ɡiːks/) is a purely functional package manager, and
associated free software distribution, for the [[http://www.gnu.org/gnu/gnu.html][GNU system]].  In addition
to standard package management features, Guix supports transactional
upgrades and roll-backs, unprivileged package management, per-user
profiles, and garbage collection.

It provides [[http://www.gnu.org/software/guile/][Guile]] Scheme APIs, including a high-level embedded
domain-specific languages (EDSLs) to describe how packages are to be
built and composed.

A user-land free software distribution for GNU/Linux comes as part of
Guix.

Guix is based on the [[http://nixos.org/nix/][Nix]] package manager.


* Requirements

GNU Guix currently depends on the following packages:

  - [[http://gnu.org/software/guile/][GNU Guile 2.0.x]], version 2.0.5 or later
  - [[http://gnupg.org/][GNU libgcrypt]]

Unless `--disable-daemon' was passed, the following packages are needed:

  - [[http://sqlite.org/][SQLite 3]]
  - [[http://www.bzip.org][libbz2]]
  - [[http://gcc.gnu.org][GCC's g++]]

When `--disable-daemon' was passed, you instead need the following:

  - [[http://nixos.org/nix/][Nix]]

* Installation

See the manual for the installation instructions, either by running

  info -f doc/guix.info "(guix) Installation"

or by checking the [[http://www.gnu.org/software/guix/manual/guix.html#Installation][web copy of the manual]].

For information on installation from a Git checkout, please see the HACKING
file.

* Installing Guix from Guix

You can re-build and re-install Guix using a system that already runs Guix.
To do so:

  - Install the dependencies (see 'Requirements' above) and build tools using
    Guix:

      guix package --install={autoconf,automake,bzip2,gcc,binutils,ld-wrapper,glibc,gettext,guile,libgcrypt,pkg-config,sqlite}

  - set the environment variables that Guix recommends you to set during the
    package installation process:
      ACLOCAL_PATH, CPATH, LIBRARY_PATH, PKG_CONFIG_PATH

  - set the PATH environment variable to refer to the profile:
      PATH=$HOME/.guix-profile/bin:$PATH

  - re-run the configure script passing it the option
    `--with-libgcrypt-prefix=$HOME/.guix-profile/'

  - run "make" and "make install"

* How It Works

Guix does the high-level preparation of a /derivation/.  A derivation is
the promise of a build; it is stored as a text file under
=/nix/store/xxx.drv=.  The (guix derivations) module provides the
`derivation' primitive, as well as higher-level wrappers such as
`build-expression->derivation'.

Guix does remote procedure calls (RPCs) to the Guix or Nix daemon (the
=guix-daemon= or =nix-daemon= command), which in turn performs builds
and accesses to the Nix store on its behalf.  The RPCs are implemented
in the (guix store) module.

* Installing Guix as non-root

The Guix daemon allows software builds to be performed under alternate
user accounts, which are normally created specifically for this
purpose.  For instance, you may have a pool of accounts in the
=guixbuild= group, and then you can instruct =guix-daemon= to use them
like this:

  $ guix-daemon --build-users-group=guixbuild

However, unless it is run as root, =guix-daemon= cannot switch users.
In that case, it falls back to using a setuid-root helper program call
=nix-setuid-helper=.  That program is not setuid-root by default when
you install it; instead you should run a command along these lines
(assuming Guix is installed under /usr/local):

  # chown root.root /usr/local/libexec/nix-setuid-helper
  # chmod 4755 /usr/local/libexec/nix-setuid-helper

* Contact

GNU Guix is hosted at https://savannah.gnu.org/projects/guix/.

Please email <bug-guix@gnu.org> for bug reports or questions regarding
Guix and its distribution; email <gnu-system-discuss@gnu.org> for
general issues regarding the GNU system.

Join #guix on irc.freenode.net.

* Guix & Nix

GNU Guix is based on [[http://nixos.org/nix/][the Nix package manager]].  It implements the same
package deployment paradigm, and in fact it reuses some of its code.
Yet, different engineering decisions were made for Guix, as described
below.

Nix is really two things: a package build tool, implemented by a library
and daemon, and a special-purpose programming language.  GNU Guix relies
on the former, but uses Scheme as a replacement for the latter.

Using Scheme instead of a specific language allows us to get all the
features and tooling that come with Guile (compiler, debugger, REPL,
Unicode, libraries, etc.)  And it means that we have a general-purpose
language, on top of which we can have embedded domain-specific languages
(EDSLs), such as the one used to define packages.  This broadens what
can be done in package recipes themselves, and what can be done around them.

Technically, Guix makes remote procedure calls to the nix-worker
daemon to perform operations on the store.  At the lowest level, Nix
“derivations” represent promises of a build, stored in .drv files in
the store.  Guix produces such derivations, which are then interpreted
by the daemon to perform the build.  Thus, Guix derivations can use
derivations produced by Nix (and vice versa).

With Nix and the [[http://nixos.org/nixpkgs][Nixpkgs]] distribution, package composition happens at
the Nix language level, but builders are usually written in Bash.
Conversely, Guix encourages the use of Scheme for both package
composition and builders.  Likewise, the core functionality of Nix is
written in C++ and Perl; Guix relies on some of the original C++ code,
but exposes all the API as Scheme.

* Related software

  - [[http://nixos.org][Nix, Nixpkgs, and NixOS]], functional package manager and associated
    software distribution, are the inspiration of Guix
  - [[http://www.gnu.org/software/stow/][GNU Stow]] builds around the idea of one directory per prefix, and a
    symlink tree to create user environments
  - [[http://www.pvv.ntnu.no/~arnej/store/storedoc_6.html][STORE]] shares the same idea
  - [[https://live.gnome.org/OSTree/][GNOME's OSTree]] allows bootable system images to be built from a
    specified set of packages
  - The [[http://www.gnu.org/s/gsrc/][GNU Source Release Collection]] (GSRC) is a user-land software
    distribution; unlike Guix, it relies on core tools available on the
    host system