NixOS & Configuration

Pure evaluation rejects a host-local file

A flake reads a path outside its declared inputs and pure evaluation rejects it. Distinguish build-time source data from runtime filesystem paths.

On this page
  1. Symptoms & scope
  2. Possible causes
  3. Diagnose safely
  4. Evidence-guided next steps
  5. References & review
  6. Related problems

Symptoms & scope

  • Evaluation reports access forbidden in pure evaluation mode.
  • Configuration references a personal home file or /var data at evaluation time.

Relevant environment

Pure flake evaluation; path literals, readFile and host-local data are not interchangeable with runtime path strings.

Recognizable messages (synthetic examples)
error: access to absolute path '/home/example/wallpaper.png' is forbidden in pure evaluation mode (use '--impure' to override)

Inspect expression purpose before adding an impurity override.

Possible causes

These are possible explanations, not a confirmed diagnosis. Several independent faults can coexist.

  • A source file outside the flake tree may be read using an absolute path or builtins.readFile.
  • A runtime path may accidentally be expressed as a Nix path value, causing evaluation-time access instead of passing a string.

Diagnose safely

Run one command at a time in the relevant session. Read the explanation first. Uppercase placeholders need your own values; tools and privileges vary by distribution. These commands are displayed here and never executed by the website.

Check 1

Use the actual configuration checkout; rg reads matching lines without evaluating Nix.

rg -n 'builtins\.readFile|builtins\.getEnv|/home/|/var/' /etc/nixos

Interpret the result: Compare the denied path with its expression and option type. A runtime string may be valid where copying source data is not.

Check 2

Run in the flake checkout; inspect whether the file belongs to an explicit input.

rg -n 'inputs|url|path:|readFile' flake.nix

Interpret the result: A file absent from declared inputs is not made reproducible merely because it exists on this host.

Evidence-guided next steps

Declare nonsecret source data as an input

If the file is build-time source, place it in the tracked flake tree or use an explicit pinned input. Reference it relative to that source so another machine can evaluate the same configuration.

Precautions: Source files normally enter the world-readable Nix store. Keep secrets out and preserve source filtering.

Recovery / rollback: Restore previous source layout, references and lock file; retain any moved original file until the new layout is verified.

Did this solution help you?

Share this solution#

Keep runtime resources as runtime paths

If the option expects a runtime filename such as an EnvironmentFile, use its documented string form and provision the file outside the store. If impurity is intentional for local experimentation, confine --impure to that explicit evaluation and document the dependency.

Precautions: A string only helps if the option really opens it at runtime. --impure does not keep secrets out of build outputs automatically.

Recovery / rollback: Restore the old expression and runtime-file configuration; revoke any exposed secret before further use if it was copied to the store.

Did this solution help you?

Share this solution#

References & review

This guide was prepared from primary project or distribution sources and reviewed on the date shown. This is an editorial source check, not evidence that a fix was reproduced on your hardware. Diagnostic log examples are synthetic fixtures. Version-dependent details must be checked against your installed release.