r/NixOS • • 3d ago

Why does NixOS rebuild DaVinci Resolve after every flake update?

Post image

I use NixOS Unstable mostly for all stuff, but DaVinci Resolve is coming from NixOS Stable just to fix this issue. But after Nix Flake Update it still rebuilds everything. Any way to prevent that?

Here's my config - https://github.com/SeniorMatt/nixos

44 Upvotes

29 comments sorted by

57

u/segv 3d ago

It's unfree and therefore not cached by hydra. If any of the inputs used in the build change, the resolver tries to build it - since it has no cached archive available, it builds it from source.

2

u/Creepy_Reindeer2149 3d ago

What is the rationale for unfree packages not being cached? How much is legal vs philosophical?

20

u/segv 3d ago edited 3d ago

I'm no authority in the matter, but I suppose it's mostly legal. You can stick to any philosophy you like, but at the end of the day it is your infrastructure hosting somebody else's copyrightednon-copyleft material.

Edit: non-copyleft is a better word, but still doesn't capture every nuance of the situation

8

u/dastarruer 3d ago

Legally I don’t think they can host builds of proprietary software without prior approval, so the compromise is to build it on the user’s machine instead.

1

u/xplosm 3d ago

Legal issues when distributing binaries outside of approved channels by the owners of the IP.

1

u/Nico_Weio 2d ago

The other comment explains it nicely, I just want to stress that none of this is set in stone: https://github.com/NixOS/nixpkgs/issues/83884

11

u/IronChe 3d ago

You build from source each time, targeting the latest commit I guess. Similar thing happens for Aseprite. While I am not familiar with the exact publication model/licensing of the DaVinciResolve, for Aseprite, the software is open-source, but prebuilt binaries cannot be distributed. In other words, it is free to use only if you can build it yourself. I checked DaVinci site and it looks like you need to "register" to download for free. It would make sense then that they do not allow prebuilt binaries to be distributed as well.

11

u/IronChe 3d ago

Oh, sorry, you asked how to fix it rebuilding after each flake update. You can freeze your nixpkgs versions to target a specific release, e.g.
```nix inputs = { #base packages nixpkgs.url = "github:NixOS/nixpkgs/nixpkgs-unstable"; nixpkgs-stable.url = "github:nixos/nixpkgs/nixos-25.11";

#frozen nixpkgs for aseprite so that it does not rebuild when I update
nixpkgs-aseprite.url = "github:NixOS/nixpkgs/da39501c8d0a093136854eddcd6927c8a8bb0d8f"; # 2026.09.09

```

8

u/snowman-london 3d ago

You can always create your own cachix cache as well. One of the ways to speed this up is to create a workflow in gh ( or any platform you are using ) and run a nightly build for this and push this into cachix. This will solve the problem of rebuilding this locally. I do that for a lot. Let GH build for you.

2

u/adamkex 3d ago

Is there a guide (or similar) on how to do this?

5

u/duck1123 3d ago

Here is my config to set up a service to watch my builds and push them up to my caches. (cachix and a self-hosted attic) Hope this at least points you in the right direction.

https://github.com/duck1123/dotfiles/blob/master/modules%2Fnixos%2Fnix-attic.nix

1

u/adamkex 3d ago

Thank you

3

u/snowman-london 3d ago

There you go "Ask and it will be delivered" I do it a bit differently, but hey there are so many ways to do this and it looks elegant and well done. This will save you a lot of time.

1

u/reduX179 3d ago edited 3d ago

You don't even need another server you can use GitHub releases as cachix alternative you don't have to make asset of each drv instead make a cumulative chunk and save their offset in index file and make some local proxy which translates offset to real data  it has limit of 2gb and whole cache can be splitted into chunks.

1

u/snowman-london 2d ago

That sound like a interesting solution. Please explain!

1

u/reduX179 2d ago edited 2d ago

https://github.com/divyam234/nix-cache

You can fork and include this in your dotfiles you have to change only hardcoded public and you forked repo with mine.Also change workflow add your derivations acc to your machines

Currently what I do whenever my dotfiles flake.lock is updated it dispatches the event to cache repo and it then auto builds

I have multiple machine with diff arch if you have only x86 you can remove arm64 pipeline for workflow.

1

u/snowman-london 2d ago

Nice I will def try this. Thanks.

4

u/cfx_4188 3d ago

Unfortunately, this is a property of proprietary packages in NixOS. I also spend a whole hour reassembling one heavy package.

2

u/vcunat 3d ago

In practice, stable rebuilds everything once in a few weeks. Currently that's roughly bi-weekly cycle of staging-next-26.05 iterations.

3

u/vcunat 3d ago

I forgot to add the primary reason: some security fixes cause huge rebuilds, and they tend to be relatively frequent nowadays.

1

u/Krutonium 3d ago

Oddly one of the few positives of AI. Things in general are getting more secure in the race to secure against people using AI to break stuff.

1

u/vcunat 2d ago

I'm not sure if it's positive yet. Attacks are simpler than they used to be. Making a project secure against that takes more (human) effort than it used to, I think.

1

u/Objective-Stranger99 3d ago

I am also on the unstable channel with DaVinci Resolve installed, and it only rebuilds when a new version is released once every few months, even though I update my flakes every day and rebuild.

1

u/MuffinGamez 3d ago

it would be nice if hydra had some exceptions for building unfree packages. i dont really see why its not done or binary packages are repackaged (which is what arch/aur does a lot)

1

u/Spra991 3d ago edited 2d ago

NixOS Stable isnt very stable, it changes constantly and requires tens of GB of updates, if any one of those hit the davinci package, that gets rebuild a well. If you want it to not change, pin it to a specific revision, i.e. add ?rev=... to the URL.

You can also do it inline for individual packages without a flake input:, e.g.

(builtins.getFlake ("github:NixOS/nixpkgs?rev=1c3fe55ad329cbcb28471bb30f05c9827f724c77")).legacyPackages.${system}.
ffmpeg

1

u/akaiggy 3d ago

This is good motivation for setting up a remote builder

1

u/RogueProtocol37 2d ago

It's very easy to setup a local Nix cache server using Harmonia

services.harmonia.cache = {
enable = true;
signKeyPaths = [ /sign/key/path ];
settings = {
  bind = "[::]:5000";
  workers = 4;
  };
};

networking.firewall.allowedTCPPorts = [ 5000 ];    

And add it to your Nix caches:

_: {
   nix = {
settings.substituters = [
  "http://localhost:5000"
];
settings.trusted-public-keys = [
  "cache.local-1:xyzzzzxxxzzszsszsssssssxxx"
    ];
  };
}

Then you only need to build once until there are real changes from you or the upstream

(You can check out Harmonia's github repo to figure out how to deal with the sign key and the public key)