Symptoms & scope
- Evaluation reports access forbidden in pure evaluation mode.
- Configuration references a personal home file or /var data at evaluation time.
Relevant environment
Pure flake evaluation; path literals, readFile and host-local data are not interchangeable with runtime path strings.
Recognizable messages (synthetic examples)
error: access to absolute path '/home/example/wallpaper.png' is forbidden in pure evaluation mode (use '--impure' to override)Inspect expression purpose before adding an impurity override.
Possible causes
These are possible explanations, not a confirmed diagnosis. Several independent faults can coexist.
- A source file outside the flake tree may be read using an absolute path or builtins.readFile.
- A runtime path may accidentally be expressed as a Nix path value, causing evaluation-time access instead of passing a string.
Diagnose safely
Run one command at a time in the relevant session. Read the explanation first. Uppercase placeholders need your own values; tools and privileges vary by distribution. These commands are displayed here and never executed by the website.
Check 1
Use the actual configuration checkout; rg reads matching lines without evaluating Nix.
rg -n 'builtins\.readFile|builtins\.getEnv|/home/|/var/' /etc/nixosInterpret the result: Compare the denied path with its expression and option type. A runtime string may be valid where copying source data is not.
Check 2
Run in the flake checkout; inspect whether the file belongs to an explicit input.
rg -n 'inputs|url|path:|readFile' flake.nixInterpret the result: A file absent from declared inputs is not made reproducible merely because it exists on this host.
Evidence-guided next steps
Declare nonsecret source data as an input
If the file is build-time source, place it in the tracked flake tree or use an explicit pinned input. Reference it relative to that source so another machine can evaluate the same configuration.
Precautions: Source files normally enter the world-readable Nix store. Keep secrets out and preserve source filtering.
Recovery / rollback: Restore previous source layout, references and lock file; retain any moved original file until the new layout is verified.
Did this solution help you?
Keep runtime resources as runtime paths
If the option expects a runtime filename such as an EnvironmentFile, use its documented string form and provision the file outside the store. If impurity is intentional for local experimentation, confine --impure to that explicit evaluation and document the dependency.
Precautions: A string only helps if the option really opens it at runtime. --impure does not keep secrets out of build outputs automatically.
Recovery / rollback: Restore the old expression and runtime-file configuration; revoke any exposed secret before further use if it was copied to the store.
Did this solution help you?
References & review
This guide was prepared from primary project or distribution sources and reviewed on the date shown. This is an editorial source check, not evidence that a fix was reproduced on your hardware. Diagnostic log examples are synthetic fixtures. Version-dependent details must be checked against your installed release.
- Nix eval — pure and impure evaluation (project or distribution documentation)
- Official NixOS Wiki — flake source boundaries (project or distribution documentation)