-
Notifications
You must be signed in to change notification settings - Fork 9
Expand file tree
/
Copy pathflake.nix
More file actions
638 lines (602 loc) · 26.7 KB
/
Copy pathflake.nix
File metadata and controls
638 lines (602 loc) · 26.7 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
{
description = "tau";
inputs = {
nixpkgs.url = "github:NixOS/nixpkgs/nixpkgs-unstable";
flake-utils.url = "github:numtide/flake-utils";
flakebox = {
url = "github:dpc/flakebox?rev=105902c66930a9e6a874d27ea8430e8f8db864d7";
inputs.nixpkgs.follows = "nixpkgs";
};
dpc-public-skills = {
url = "git+https://radicle.dpc.pw/z2HR882B4c4mTdAgdt4SozpdeTuMf.git";
inputs.nixpkgs.follows = "nixpkgs";
};
tau-ext-rostra.url = "git+https://radicle.dpc.pw/z4LrrRivcgNjJii5wzbjTvA8ttt6o.git?ref=main";
tau-ext-slack.url = "git+https://radicle.dpc.pw/z3NJhEtKWCbHPa28wDQSYJ8eEfBjg.git?ref=master";
tau-ext-telegram.url = "git+https://radicle.dpc.pw/z3sPdSePnxtBvP9pTLwUwVgpMU68r.git?ref=main";
tau-ext-zulip.url = "git+https://radicle.dpc.pw/z2LFTBWK7VpAwC3Bpxohkh91aqXd.git?ref=main";
tau-ext-pim.url = "git+https://radicle.dpc.pw/z4FCuiVzFns5iTquhsYCntZyVWCqi.git?ref=main";
tau-ext-swarm.url = "git+https://radicle.dpc.pw/z38my9x3Rmn6VYtDMiLKgjK3tRv8o.git?ref=master";
tau-ext-xmpp.url = "git+https://radicle.dpc.pw/zpN6uwkd6ok9qRAX5yZaF7w8xzDd.git?ref=master";
selfci = {
url = "git+https://radicle.dpc.pw/z2tDzYbAXxTQEKTGFVwiJPajkbeDU.git";
inputs.nixpkgs.follows = "nixpkgs";
inputs.flake-utils.follows = "flake-utils";
# TODO: temporarily broken because of wild 0.9.0 hackery
# inputs.flakebox.follows = "flakebox";
};
};
outputs =
{
self,
nixpkgs,
flake-utils,
flakebox,
dpc-public-skills,
tau-ext-pim,
tau-ext-rostra,
tau-ext-slack,
tau-ext-swarm,
tau-ext-telegram,
tau-ext-xmpp,
tau-ext-zulip,
selfci,
...
}@inputs:
flake-utils.lib.eachDefaultSystem (
system:
let
nixpkgsPkgs = nixpkgs.legacyPackages.${system};
# TODO: get rid of custom stuff
# pkgs = nixpkgs.legacyPackages.${system};
pkgs = import nixpkgs {
inherit system;
overlays = [
flakebox.overlays.default
];
};
projectName = "tau";
cargoCrap = pkgs.callPackage ./nix/pkgs/cargo-crap.nix { };
selfciPkg = selfci.packages.${system}.default;
selfciMq = selfci.packages.${system}.mq;
flakeboxLib = flakebox.lib.mkLib pkgs {
config = {
# Tau's cargo-crap derivations use a locally pinned package and
# project-specific CI gates rather than Flakebox's integration.
cargo-crap.enable = false;
github.ci.buildOutputs = [
".#ci.workspace"
".#ci.workspaceDocs"
];
just.importPaths = [ "justfile.custom.just" ];
just.rules.watch.enable = false;
rootDir.".envrc".text = pkgs.lib.mkForce ''
use flake
source_env_if_exists .envrc.local
'';
toolchain.components = [
"rustc"
"cargo"
"clippy"
"rust-analyzer"
"rust-src"
"llvm-tools"
];
};
};
buildPaths = [
".cargo-crap.toml"
"Cargo.toml"
"Cargo.lock"
".config/nextest.toml"
".agents/skills"
"config"
"crates"
];
cargoManifest = builtins.fromTOML (builtins.readFile ./Cargo.toml);
releaseProfile = cargoManifest.profile.release;
# Selfci captures and replays Nix build logs verbatim. Keep every nextest
# lane plain and non-interactive so terminal detection cannot add progress
# frames or ANSI escapes to those persistent logs.
nextestReporterArgs = "--color never --show-progress none --status-level none --no-input-handler";
# Nextest otherwise detects host CPUs independently of the Nix build
# budget. Zero/unset budgets retain its normal CPU-count selection.
nextestBuildBudget = ''
export NEXTEST_TEST_THREADS="''${NIX_BUILD_CORES:-num-cpus}"
if [ "$NEXTEST_TEST_THREADS" = 0 ]; then
export NEXTEST_TEST_THREADS=num-cpus
fi
echo "Nextest test concurrency: $NEXTEST_TEST_THREADS"
'';
buildSrc =
# The universal release binary needs parallel LLVM optimization. This
# evaluation guard prevents normal release builds from silently
# returning to the multi-minute fat-LTO/one-CGU configuration.
assert releaseProfile.lto == "thin";
assert releaseProfile.codegen-units == 16;
flakeboxLib.source.fromPaths {
root = ./.;
paths = buildPaths;
filter = flakeboxLib.source.filters.excludeDirectoriesNamed [ "specs" ];
};
# Placeholders are 40 / 16 raw bytes that the binary embeds via
# a `static [u8; N]` in `crates/tau-harness/src/version.rs`.
# The strings below MUST byte-for-byte match those statics, and
# the substituted values MUST be the same length so `bbe` can
# patch them in place without shifting any file offsets.
#
# Why the unique `__TAU_BUILD…` prefix: short, "ASCII-table-ish"
# placeholders (e.g. `0123456`) collide with natural byte runs
# in the binary (base64 alphabets, hex digit tables) and bbe
# would silently corrupt them.
tauBuildRevisionPlaceholder = "__TAU_BUILD_GIT_REVISION_PLACEHOLDER____";
tauBuildDatePlaceholder = "__TAU_BUILD_DATE";
tauBuildRevision =
if (self ? rev) && (builtins.stringLength self.rev == 40) then
self.rev
else if (self ? dirtyRev) && (builtins.stringLength self.dirtyRev == 46) then
builtins.substring 0 40 self.dirtyRev
else if (self ? dirtyRev) && (builtins.stringLength self.dirtyRev == 40) then
self.dirtyRev
else
tauBuildRevisionPlaceholder;
tauBuildDirty = self ? dirtyRev;
tauBuildRevisionDisplay =
if tauBuildRevision == tauBuildRevisionPlaceholder then
"unknown"
else
"${builtins.substring 0 7 tauBuildRevision}${pkgs.lib.optionalString tauBuildDirty "-modified"}";
tauBuildDate =
if self ? lastModifiedDate then
"${builtins.substring 0 4 self.lastModifiedDate}-${builtins.substring 4 2 self.lastModifiedDate}-${
builtins.substring 6 2 self.lastModifiedDate
} ${builtins.substring 8 2 self.lastModifiedDate}:${builtins.substring 10 2 self.lastModifiedDate}"
else
tauBuildDatePlaceholder;
tauPackage = nixpkgsPkgs.callPackage ./nix/pkgs/tau.nix {
buildRevision = tauBuildRevision;
buildDate = tauBuildDate;
buildDirty = tauBuildDirty;
};
tauDirtyPackage = nixpkgsPkgs.callPackage ./nix/pkgs/tau.nix {
buildRevision = "0123456789abcdef0123456789abcdef01234567";
buildDate = "1970-01-01 00:00";
buildDirty = true;
};
replaceTauBuildInfo =
package:
pkgs.stdenv.mkDerivation {
pname = projectName;
version = package.version;
dontUnpack = true;
dontStrip = true;
nativeBuildInputs = [ pkgs.bbe ];
# `bbe` itself silently no-ops when its pattern isn't found,
# which is exactly how the previous LTO-eats-the-placeholder
# bug shipped. Track per-placeholder hit counts and require
# at least one substitution across all executables; also
# assert no placeholder bytes remain after patching.
installPhase = ''
cp -a ${package} $out
chmod -R u+w $out
revision_hits=0
date_hits=0
for path in $(${pkgs.findutils}/bin/find $out -type f -executable); do
had_revision=0
had_date=0
if grep -aqF '${tauBuildRevisionPlaceholder}' "$path"; then
had_revision=1
fi
if grep -aqF '${tauBuildDatePlaceholder}' "$path"; then
had_date=1
fi
${pkgs.bbe}/bin/bbe \
-e 's/${tauBuildRevisionPlaceholder}/${tauBuildRevision}/' \
-e 's/${tauBuildDatePlaceholder}/${tauBuildDate}/' \
"$path" -o ./tmp
cat ./tmp > "$path"
if [ "$had_revision" = 1 ]; then
if grep -aqF '${tauBuildRevisionPlaceholder}' "$path"; then
echo "error: revision placeholder still present in $path after bbe" >&2
exit 1
fi
revision_hits=$((revision_hits + 1))
fi
if [ "$had_date" = 1 ]; then
if grep -aqF '${tauBuildDatePlaceholder}' "$path"; then
echo "error: date placeholder still present in $path after bbe" >&2
exit 1
fi
date_hits=$((date_hits + 1))
fi
done
if [ "$revision_hits" = 0 ]; then
echo "error: revision placeholder '${tauBuildRevisionPlaceholder}' not found in any executable under $out" >&2
echo " (likely the compiler optimized it out — check crates/tau-harness/src/version.rs)" >&2
exit 1
fi
if [ "$date_hits" = 0 ]; then
echo "error: date placeholder '${tauBuildDatePlaceholder}' not found in any executable under $out" >&2
echo " (likely the compiler optimized it out — check crates/tau-harness/src/version.rs)" >&2
exit 1
fi
${pkgs.lib.optionalString pkgs.stdenv.hostPlatform.isLinux ''
# Wild keeps x86_64 Linux links for this large binary fast. Fail
# rather than allowing a shared build override to disable it again.
if ${pkgs.binutils}/bin/readelf --file-header "$out/bin/tau" |
grep -qF 'Advanced Micro Devices X86-64'
then
if ! ${pkgs.binutils}/bin/readelf --string-dump .comment "$out/bin/tau" |
grep -qF 'Linker: Wild '
then
echo "error: x86_64 Linux $out/bin/tau was not linked with Wild" >&2
exit 1
fi
fi
''}
'';
};
multiBuild = (flakeboxLib.craneMultiBuild { }) (
craneLib':
let
craneLib = craneLib'.overrideArgs {
pname = projectName;
src = buildSrc;
nativeBuildInputs = [ ];
env.RUSTDOCFLAGS = "-D warnings";
env.SSL_CERT_FILE = "${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt";
};
workspaceBuildCommand = "cargo build --profile $CARGO_PROFILE --locked --workspace --all-targets";
workspaceDocsCommand = "cargo doc --profile $CARGO_PROFILE --workspace --locked --no-deps";
in
rec {
# Docs compute ordinary dependencies in check mode, so retain both
# normal-build and check-mode dependency artifacts.
workspaceDeps = craneLib.buildDepsOnly {
pname = "${projectName}-workspace";
buildPhaseCargoCommand = ''
${workspaceBuildCommand}
cargo check --profile $CARGO_PROFILE --workspace --locked
'';
cargoBuildCommand = "dontuse";
cargoCheckCommand = "dontuse";
doCheck = false;
};
# This artifact-producing build is the only workspace gate that
# tests consume. Docs and Clippy remain required terminal gates.
workspace = craneLib.mkCargoDerivation {
pname = "${projectName}-workspace";
cargoArtifacts = workspaceDeps;
buildPhaseCargoCommand = workspaceBuildCommand;
doCheck = false;
};
workspaceDocs = craneLib.mkCargoDerivation {
pname = "${projectName}-workspace-docs";
cargoArtifacts = workspaceDeps;
buildPhaseCargoCommand = workspaceDocsCommand;
doCheck = false;
doInstallCargoArtifacts = false;
};
tests = craneLib.cargoNextest {
cargoArtifacts = workspace;
cargoNextestExtraArgs = "--workspace ${nextestReporterArgs}";
# PTY E2E fixtures execute the candidate universal binary for
# their UI and component subprocesses. Nextest does not require
# that executable, so fail if the workspace artifact omitted it
# rather than accidentally running a PATH binary.
preCheck = ''
${nextestBuildBudget}
test -x "$PWD/target/$CARGO_PROFILE/tau"
'';
# This terminal gate has no downstream Cargo consumer. Exporting
# its target directory would recompress about 3 GiB after every run.
doInstallCargoArtifacts = false;
nativeBuildInputs = [
pkgs.ripgrep
pkgs.util-linux
];
postCheck = ''
# Public provider cassettes are a wire-compatibility gate.
export TAU_VCR=replay-only
export TAU_VCR_DIR="$PWD/crates/tau-provider-codex/fixtures/provider-vcr"
export TAU_CURATED_VCR_LANE=1
cargo nextest run --locked \
--workspace \
--cargo-profile $CARGO_PROFILE \
--no-tests=fail \
${nextestReporterArgs} \
-E 'package(dpc-tau-provider-codex) & test(/curated_provider_vcr_replay_only_lane/)'
unset TAU_VCR TAU_VCR_DIR TAU_CURATED_VCR_LANE
# Poison every ambient startup transport. The fixture must ignore
# them (including runtime settings reloads and secret discovery)
# and still prove its exact extension allowlist.
export TAU_ENABLE_EXTENSIONS=core-shell
export TAU_EXTENSION_CLI_OVERRIDES='["EnableAll"]'
export TAU_ROLE_CLI_OVERRIDES='["DisableAll"]'
export TAU_HARNESS_CONFIG_OVERRIDES='[{"key":"agents.default_role","raw_value":"missing"}]'
export TAU_STARTUP_ROLE=missing
env 'TAU_SECRET_BAD@=poison' cargo nextest run --locked \
--workspace \
--cargo-profile $CARGO_PROFILE \
--no-tests=fail \
${nextestReporterArgs} \
-E 'package(dpc-tau-e2e-tests) & (binary(deterministic_provider) | binary(cancellation_liveness))'
if test "$(uname -s)" = Linux; then
# Run the exact workspace-built candidate against a
# fixture-owned loopback HTTP/SSE server. Check before
# exporting: without the path, the E2E tests skip.
test -x "$PWD/target/$CARGO_PROFILE/tau-ext-provider-builtin"
export TAU_E2E_PROVIDER_BUILTIN_BIN="$PWD/target/$CARGO_PROFILE/tau-ext-provider-builtin"
# The provider's documented additive-CA input accepts only
# certificate PEM blocks. Nix's source bundle also carries
# NSS trust labels, so derive the narrow fixture input here.
export TAU_E2E_PROVIDER_CA_BUNDLE="$TMPDIR/provider-builtin-e2e-ca.pem"
sed -n '/^-----BEGIN CERTIFICATE-----$/,/^-----END CERTIFICATE-----$/p' \
"${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt" \
> "$TAU_E2E_PROVIDER_CA_BUNDLE"
test -s "$TAU_E2E_PROVIDER_CA_BUNDLE"
env 'TAU_SECRET_BAD@=poison' cargo nextest run --locked \
--workspace \
--cargo-profile $CARGO_PROFILE \
--no-tests=fail \
${nextestReporterArgs} \
-E 'package(dpc-tau-e2e-tests) & binary(provider_builtin_retry)'
unset TAU_E2E_PROVIDER_BUILTIN_BIN TAU_E2E_PROVIDER_CA_BUNDLE
fi
# The PTY gate must spawn the exact workspace-built universal
# binary from this Cargo profile, not a user PATH entry.
export TAU_E2E_TAU_BIN="$PWD/target/$CARGO_PROFILE/tau"
test -x "$TAU_E2E_TAU_BIN"
env 'TAU_SECRET_BAD@=poison' cargo nextest run --locked \
--workspace \
--cargo-profile $CARGO_PROFILE \
--no-tests=fail \
${nextestReporterArgs} \
-E 'package(dpc-tau-e2e-tests) & (binary(core_resume) | binary(core_shell_resume))'
'';
};
clippy = craneLib.cargoClippy {
cargoArtifacts = workspaceDeps;
cargoClippyExtraArgs = "-- -D warnings -D clippy::debug_assert_with_mut_call";
# Clippy consumes prebuilt dependencies but is a terminal gate;
# do not export its post-check target directory.
doInstallCargoArtifacts = false;
};
workspaceDepsCcov = craneLib.buildDepsOnly {
pname = "${projectName}-workspace-ccov";
buildPhaseCargoCommand = ''
source <(cargo llvm-cov show-env --export-prefix)
cargo build --locked --workspace --all-targets --profile $CARGO_PROFILE
'';
cargoBuildCommand = "dontuse";
cargoCheckCommand = "dontuse";
nativeBuildInputs = [ pkgs.cargo-llvm-cov ];
doCheck = false;
};
workspaceCcov = craneLib.buildWorkspace {
pname = "${projectName}-workspace-ccov";
cargoArtifacts = workspaceDepsCcov;
buildPhaseCargoCommand = ''
source <(cargo llvm-cov show-env --export-prefix)
cargo build --locked --workspace --all-targets --profile $CARGO_PROFILE
'';
nativeBuildInputs = [ pkgs.cargo-llvm-cov ];
doCheck = false;
};
testsCcov = craneLib.mkCargoDerivation {
pname = "${projectName}-tests-ccov";
cargoArtifacts = workspaceCcov;
buildPhaseCargoCommand = ''
${nextestBuildBudget}
source <(cargo llvm-cov show-env --export-prefix)
cargo nextest run --locked --workspace --all-targets --profile coverage --cargo-profile $CARGO_PROFILE ${nextestReporterArgs}
mkdir -p $out
cargo llvm-cov report --profile $CARGO_PROFILE --lcov --output-path $out/lcov.info
test -s $out/lcov.info
'';
doInstallCargoArtifacts = false;
nativeBuildInputs = [
pkgs.cargo-llvm-cov
pkgs.cargo-nextest
pkgs.ripgrep
pkgs.util-linux
];
doCheck = false;
};
# cargo-crap reads source and explicit LCOV only. Keep cargoArtifacts
# explicitly null below: enhanced Crane may otherwise infer and unpack
# compiled artifacts which none of these derivations consume.
crapReport = craneLib.mkCargoDerivation {
pname = "${projectName}-cargo-crap-ccov-report";
cargoArtifacts = null;
buildPhaseCargoCommand = ''
test -s ${testsCcov}/lcov.info
mkdir -p $out
${cargoCrap}/bin/cargo-crap \
--workspace \
--lcov ${testsCcov}/lcov.info \
--threshold 30 \
--top 100 \
--min 50 \
--format markdown \
--output $out/cargo-crap.md
cp ${testsCcov}/lcov.info $out/lcov.info
'';
doInstallCargoArtifacts = false;
nativeBuildInputs = [ cargoCrap ];
doCheck = false;
};
# Duplicate detection is a separate, coverage-free inventory. Exclude
# test-only source files under src/ in addition to Cargo's top-level
# tests/ exclusion; neither invocation changes the blocking CRAP gate.
crapDuplicates = craneLib.mkCargoDerivation {
pname = "${projectName}-cargo-crap-duplicates";
cargoArtifacts = null;
buildPhaseCargoCommand = ''
mkdir -p $out
args=(
--workspace
--duplicates
--exclude '**/tests/**'
--exclude '**/tests.rs'
--exclude '**/*_tests.rs'
--top 0
)
${cargoCrap}/bin/cargo-crap "''${args[@]}" \
--format human --output $out/duplicates.txt
${cargoCrap}/bin/cargo-crap "''${args[@]}" \
--format json --output $out/duplicates.json
# Workspace locations are absolute; /build/source disappears
# after Nix finishes. Make both reports navigable from repo root.
sed -i "s|$PWD/||g" $out/duplicates.txt $out/duplicates.json
'';
doInstallCargoArtifacts = false;
nativeBuildInputs = [ cargoCrap ];
doCheck = false;
};
crapAbsolute = craneLib.mkCargoDerivation {
pname = "${projectName}-cargo-crap-ccov-absolute";
cargoArtifacts = null;
buildPhaseCargoCommand = ''
test -s ${testsCcov}/lcov.info
${cargoCrap}/bin/cargo-crap \
--workspace \
--lcov ${testsCcov}/lcov.info \
--min 100 \
--format github \
--fail-above
mkdir -p $out
cp ${testsCcov}/lcov.info $out/lcov.info
'';
doInstallCargoArtifacts = false;
nativeBuildInputs = [ cargoCrap ];
doCheck = false;
};
crap = pkgs.runCommand "${projectName}-cargo-crap-ccov" { } ''
mkdir -p $out
ln -s ${crapAbsolute} $out/absolute
cp ${crapAbsolute}/lcov.info $out/lcov.info
'';
tauDeps = craneLib.buildDepsOnly {
cargoExtraArgs = "-p dpc-tau";
};
tau = replaceTauBuildInfo (
craneLib.buildPackage (
{
cargoArtifacts = tauDeps;
cargoExtraArgs = "-p dpc-tau";
}
// pkgs.lib.optionalAttrs (craneLib.cargoProfile == "release") {
# Keep the final command, wall time, and peak RSS visible in
# release logs without changing dev/CI profile semantics.
cargoBuildCommand = "${pkgs.time}/bin/time -v cargo build --release --locked";
nativeBuildInputs = [ pkgs.time ];
}
)
);
}
);
site = pkgs.runCommand "tau-agent-site" { } ''
mkdir -p $out/share/tau-agent-site
cp -r ${./site}/* $out/share/tau-agent-site/
'';
release-archives =
pkgs.runCommand "${projectName}-release-archives"
{
nativeBuildInputs = [
pkgs.gnutar
pkgs.gzip
];
}
''
mkdir -p $out
archive_dir=${projectName}-${multiBuild.x86_64-linux.release.tau.version}-x86_64-unknown-linux-gnu
mkdir -p "$archive_dir"
cp ${multiBuild.x86_64-linux.release.tau}/bin/tau "$archive_dir/tau"
chmod 755 "$archive_dir/tau"
tar --sort=name \
--mtime='@1' \
--owner=0 \
--group=0 \
--numeric-owner \
-czf $out/$archive_dir.tar.gz \
"$archive_dir"
archive_dir=${projectName}-${multiBuild.aarch64-linux.release.tau.version}-aarch64-unknown-linux-gnu
mkdir -p "$archive_dir"
cp ${multiBuild.aarch64-linux.release.tau}/bin/tau "$archive_dir/tau"
chmod 755 "$archive_dir/tau"
tar --sort=name \
--mtime='@1' \
--owner=0 \
--group=0 \
--numeric-owner \
-czf $out/$archive_dir.tar.gz \
"$archive_dir"
'';
in
{
packages = {
default = tauPackage;
tau = tauPackage;
site = site;
"cargo-crap" = cargoCrap;
inherit (tau-ext-pim.packages.${system}) tau-ext-pim;
inherit (tau-ext-rostra.packages.${system}) tau-ext-rostra;
inherit (tau-ext-slack.packages.${system}) tau-ext-slack;
inherit (tau-ext-swarm.packages.${system}) tau-ext-swarm;
inherit (tau-ext-telegram.packages.${system})
tau-ext-telegram
tau-telegram-gateway
;
inherit (tau-ext-xmpp.packages.${system}) tau-ext-xmpp;
inherit (tau-ext-zulip.packages.${system}) tau-ext-zulip;
}
// pkgs.lib.optionalAttrs pkgs.stdenv.hostPlatform.isLinux {
inherit release-archives;
};
ci = {
inherit (multiBuild.ci)
workspace
workspaceDocs
clippy
tests
workspaceCcov
testsCcov
crapReport
crapDuplicates
crapAbsolute
crap
;
};
checks = {
tau-version = tauPackage.passthru.tests.version;
tau-provenance = pkgs.runCommand "tau-package-provenance" { nativeBuildInputs = [ tauPackage ]; } ''
tau --version | grep -qF '(${tauBuildRevisionDisplay},'
touch "$out"
'';
tau-dirty-provenance =
pkgs.runCommand "tau-package-dirty-provenance" { nativeBuildInputs = [ tauDirtyPackage ]; }
''
tau --version | grep -qF 'tau ${tauDirtyPackage.version} (0123456-modified, 1970-01-01 00:00)'
touch "$out"
'';
};
legacyPackages = multiBuild;
devShells = flakeboxLib.mkShells {
channel = "stable";
NEXTEST_SHOW_PROGRESS = "none";
NEXTEST_STATUS_LEVEL = "none";
packages = [
cargoCrap
selfciMq
pkgs.cargo-nextest
pkgs.taplo
selfciPkg
];
shellHook = ''
${dpc-public-skills.packages.${system}.install}/bin/install-dpc-public-skills
'';
};
}
);
}