Repository navigation
Expand file tree
/
Copy pathflake.nix
More file actions
193 lines (187 loc) · 7 KB
/
Copy pathflake.nix
File metadata and controls
193 lines (187 loc) · 7 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
{
description = "rbitcoin — pinned Nix builds for byte-identical release binaries";
# Track the current NixOS **stable/large** channel (Hydra-tested; cache.nixos.org).
# Advance deliberately with `nix flake update` every ~6 months or near channel EOL —
# not daily. Exact rev is frozen in flake.lock (never floating import <nixpkgs> {}).
# See docs/reproducible-builds.md § pin policy.
inputs.nixpkgs.url = "github:NixOS/nixpkgs/nixos-26.05";
# Layered cargo builds: deps derivation + app derivation (faster rebuilds).
# Crane ≥0.23 targets modern nixpkgs; keep in lockstep with the channel bump.
inputs.crane.url = "github:ipetkov/crane/v0.24.0";
outputs =
{
self,
nixpkgs,
crane,
}:
let
# Release packages + checks. Linux only, deliberately: the Nix path exists
# to produce fully static musl binaries, and Apple forbids a static
# libSystem link, so a Darwin `nix build` is store-rpath (not portable).
# Darwin/Windows ship from GHA instead — docs/reproducible-builds.md
# § Windows / Darwin snapshots.
systems = [
"x86_64-linux"
"aarch64-linux"
];
# Dev shells only pin *tool* versions; they build nothing that ships, so
# the static-link constraint above does not apply to them. Darwin is a
# required PR gate (ci.yml `macos`) over real Darwin-only store code
# (pool session, bulk_io, sorted_run), so those contributors get the same
# pinned rustc / LLVM / ast-grep as Linux.
devSystems = systems ++ [ "aarch64-darwin" ];
forAllSystems = nixpkgs.lib.genAttrs systems;
forAllDevSystems = nixpkgs.lib.genAttrs devSystems;
mkRbitcoin =
pkgs:
pkgs.callPackage ./nix/rbitcoin.nix {
craneLib = crane.mkLib pkgs;
};
in
{
nixosModules = {
default = self.nixosModules.rbitcoin;
rbitcoin = import ./nix/modules/rbitcoin.nix {
defaultPackage = system: self.packages.${system}.rbitcoin-musl;
};
};
packages = forAllSystems (
system:
let
pkgs = import nixpkgs {
inherit system;
# Disable impure overlays; pure evaluation for reproducibility.
config = { };
overlays = [ ];
};
# Optional dynamic glibc package (Nix-store linked; not portable off-store).
rbitcoin-glibc = mkRbitcoin pkgs;
# Primary / default: fully static musl — portable operator binary.
# callPackage under pkgsStatic so rustc's sysroot includes musl std;
# rbitcoin.nix scopes static link flags to the host target only.
rbitcoin-musl = mkRbitcoin pkgs.pkgsStatic;
in
{
default = rbitcoin-musl;
rbitcoin = rbitcoin-musl;
rbitcoin-node = rbitcoin-musl;
rbitcoin-cli = rbitcoin-musl;
rbitcoin-musl = rbitcoin-musl;
# Kept for store-native Nix environments / optional dual-platform repro.
rbitcoin-glibc = rbitcoin-glibc;
}
// nixpkgs.lib.optionalAttrs (system == "x86_64-linux") {
# Optional third platform: aarch64-linux cross from x86_64 (heavy toolchain).
rbitcoin-aarch64 =
let
pkgsAarch64 = import nixpkgs {
system = "x86_64-linux";
crossSystem = {
config = "aarch64-unknown-linux-gnu";
};
config = { };
overlays = [ ];
};
in
mkRbitcoin pkgsAarch64;
}
);
# Dev shell uses the **same pinned** nixpkgs (not floating <nixpkgs>).
devShells = forAllDevSystems (
system:
let
pkgs = import nixpkgs {
inherit system;
config = { };
overlays = [ ];
};
in
{
default = pkgs.mkShell {
packages = with pkgs; [
rustc
cargo
rustfmt
clippy
# Match rustc's LLVM major (nixos-26.05 → rustc 1.95 → LLVM 21).
llvmPackages.bintools
llvmPackages.llvm
cargo-llvm-cov
ast-grep
pkg-config
];
RUST_BACKTRACE = "1";
# Dev shell still denies warnings; release package uses its own RUSTFLAGS.
RUSTFLAGS = "-Dwarnings";
shellHook = ''
export LLVM_COV="${pkgs.llvmPackages.llvm}/bin/llvm-cov"
export LLVM_PROFDATA="${pkgs.llvmPackages.llvm}/bin/llvm-profdata"
# Host gnu debug (fmt/clippy/test). Coverage → target/cov; musl → nix/crane.
# Default is $PWD/target/dev, one directory per worktree. Set
# CARGO_TARGET_DIR only to a private directory this shell alone owns.
if [ -z "''${CARGO_TARGET_DIR:-}" ]; then
export CARGO_TARGET_DIR="$PWD/target/dev"
fi
echo "rbitcoin devShell: rustc=$(rustc --version) (pinned nixpkgs via flake) CARGO_TARGET_DIR=$CARGO_TARGET_DIR"
'';
};
}
// nixpkgs.lib.optionalAttrs (builtins.elem system systems) {
# Private Tor / i2pd / cjdns meshes for scripts/overlay-functional.
# Not the default shell: extra daemons, Linux-only (cjdns TUN).
overlayFunctional = pkgs.mkShell {
packages = with pkgs; [
rustc
cargo
rustfmt
clippy
llvmPackages.bintools
llvmPackages.llvm
pkg-config
python3
tor
i2pd
cjdns
iproute2
procps
iputils
];
RUST_BACKTRACE = "1";
RUSTFLAGS = "-Dwarnings";
shellHook = ''
export OVERLAY_IN_NIX=1
if [ -z "''${CARGO_TARGET_DIR:-}" ]; then
export CARGO_TARGET_DIR="$PWD/target/dev"
fi
echo "rbitcoin overlayFunctional: rustc=$(rustc --version) tor=$(tor --version | head -n1) CARGO_TARGET_DIR=$CARGO_TARGET_DIR"
'';
};
}
);
# `nix flake check` can validate the package builds on the current system.
checks = forAllSystems (
system:
let
pkgs = import nixpkgs {
inherit system;
config = { };
overlays = [ ];
};
in
{
rbitcoin = self.packages.${system}.rbitcoin-musl;
nixos-module-eval = import ./nix/tests/nixos-module-eval.nix {
inherit nixpkgs pkgs;
expectedPackage = self.packages.${system}.rbitcoin-musl;
module = self.nixosModules.rbitcoin;
};
}
// nixpkgs.lib.optionalAttrs (system == "x86_64-linux") {
nixos-module-runtime = import ./nix/tests/nixos-module-runtime.nix {
inherit pkgs;
module = self.nixosModules.rbitcoin;
};
}
);
};
}