Answer to the Core Questions
1. Pinning channels per machine
Yes. When each host is locked to a specific channel revision, the derivations it builds are deterministic and share the same set of package inputs. This eliminates the classic “old‑channel + new‑channel” collision that produces identical store paths for the same package name. In practice, a pinned machine will never attempt to build a derivation that conflicts with a package from another revision, so the risk of an output‑path conflict drops dramatically.
2. Pre‑swap validation step
nixos‑rebuild switch already performs a full build before updating /run/current-system. The only place a conflict can surface is during the build. A lightweight pre‑swap check can be added by running nix-store --verify on the newly built generation. If nix-store reports a duplicate or orphaned path, the switch is aborted before the atomic symlink change.
3. Emulating a gradual rollout with flakes
Flakes give you a reproducible, per‑machine build configuration. By using nixos-rebuild test on a subset of hosts and keeping the channel pinned, you can verify that the new system generation builds cleanly before a global switch. The atomicity guarantee is preserved because the symlink update still happens in a single step; only the decision to run switch is staged.
Why the Conflict Happens
Output path conflicts arise when two derivations resolve to the same /nix/store path. Common causes are:
- Mixing channel revisions (e.g., a package built from 24.05 collides with one from 24.11).
- Manual symlinks or orphaned store entries that masquerade as a derivation output.
- Packaging bugs that rename an output without updating its hash.
Practical Troubleshooting Steps
Identify the offending path: Run nix-store --verify and note any duplicate output or broken symlink messages.
Pin the channel: sudo nix-channel --add https://nixos.org/channels/nixos-24.05 nixos and sudo nix-channel --update.
Clean stale entries: sudo nix-collect-garbage -d (after verifying you have backups).
Test the new generation: nixos-rebuild test to build without switching.
Validate the store: nix-store --verify /nix/store/-* on the new paths.
Switch if clean: nixos-rebuild switch.
Optional Wrapper Script for Pre‑Swap Validation
#!/usr/bin/env bash
set -e
# Build the new generation
nixos-rebuild build
# Verify the store for the new generation
nix-store --verify > /tmp/nix-verify.log || {
echo "Store verification failed – aborting switch."
exit 1
}
# If verification succeeded, perform the atomic switch
nixos-rebuild switch
What We Still Need to Know
To tailor the recommendation further, please provide the exact output path that Nix reports as conflicting during your last nixos-rebuild switch attempt. Knowing the path allows us to determine whether the conflict stems from a channel mix, a stale symlink, or a packaging bug.