Merge pull request #13183 from NousResearch/fix/nix

fix/nix
This commit is contained in:
ethernet
2026-04-20 17:10:52 -04:00
committed by GitHub
5 changed files with 39 additions and 25 deletions

8
.github/actions/nix-setup/action.yml vendored Normal file
View File

@@ -0,0 +1,8 @@
name: 'Setup Nix'
description: 'Install Nix with DeterminateSystems and enable magic-nix-cache'
runs:
using: composite
steps:
- uses: DeterminateSystems/nix-installer-action@ef8a148080ab6020fd15196c2084a2eea5ff2d25 # v22
- uses: DeterminateSystems/magic-nix-cache-action@565684385bcd71bad329742eefe8d12f2e765b39 # v13

View File

@@ -2,14 +2,6 @@ name: Nix Lockfile Check
on: on:
pull_request: pull_request:
paths:
- 'ui-tui/package.json'
- 'ui-tui/package-lock.json'
- 'web/package.json'
- 'web/package-lock.json'
- 'nix/tui.nix'
- 'nix/web.nix'
- 'nix/lib.nix'
workflow_dispatch: workflow_dispatch:
permissions: permissions:
@@ -27,7 +19,7 @@ jobs:
steps: steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
- uses: nixbuild/nix-quick-install-action@63ca48f939ee3b8d835f4126562537df0fee5b91 # v30 - uses: ./.github/actions/nix-setup
- name: Resolve head SHA - name: Resolve head SHA
id: sha id: sha

View File

@@ -98,7 +98,7 @@ jobs:
token: ${{ secrets.GITHUB_TOKEN }} token: ${{ secrets.GITHUB_TOKEN }}
fetch-depth: 0 fetch-depth: 0
- uses: nixbuild/nix-quick-install-action@63ca48f939ee3b8d835f4126562537df0fee5b91 # v30 - uses: ./.github/actions/nix-setup
- name: Apply lockfile hashes - name: Apply lockfile hashes
id: apply id: apply

View File

@@ -4,15 +4,6 @@ on:
push: push:
branches: [main] branches: [main]
pull_request: pull_request:
paths:
- 'flake.nix'
- 'flake.lock'
- 'nix/**'
- 'pyproject.toml'
- 'uv.lock'
- 'hermes_cli/**'
- 'run_agent.py'
- 'acp_adapter/**'
permissions: permissions:
contents: read contents: read
@@ -29,9 +20,8 @@ jobs:
runs-on: ${{ matrix.os }} runs-on: ${{ matrix.os }}
timeout-minutes: 30 timeout-minutes: 30
steps: steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
- uses: DeterminateSystems/nix-installer-action@ef8a148080ab6020fd15196c2084a2eea5ff2d25 # v22 - uses: ./.github/actions/nix-setup
- uses: DeterminateSystems/magic-nix-cache-action@565684385bcd71bad329742eefe8d12f2e765b39 # v13
- name: Check flake - name: Check flake
if: runner.os == 'Linux' if: runner.os == 'Linux'
run: nix flake check --print-build-logs run: nix flake check --print-build-logs

View File

@@ -2,17 +2,23 @@
{ pkgs, npm-lockfile-fix }: { pkgs, npm-lockfile-fix }:
{ {
# Returns a buildNpmPackage-compatible attrs set that provides: # Returns a buildNpmPackage-compatible attrs set that provides:
# patchPhase — strips trailing NUL newline from lockfile # patchPhase — ensures lockfile has exactly one trailing newline
# nativeBuildInputs — [ updateLockfileScript ] (list, prepend with ++ for more) # nativeBuildInputs — [ updateLockfileScript ] (list, prepend with ++ for more)
# passthru.devShellHook — stamp-checked npm install + hash auto-update # passthru.devShellHook — stamp-checked npm install + hash auto-update
# passthru.npmLockfile — metadata for mkFixLockfiles # passthru.npmLockfile — metadata for mkFixLockfiles
# #
# NOTE: npmConfigHook runs `diff` between the source lockfile and the
# npm-deps cache lockfile. fetchNpmDeps preserves whatever trailing
# newlines the lockfile has. The patchPhase normalizes to exactly one
# trailing newline so both sides always match.
#
# Usage: # Usage:
# npm = hermesNpmLib.mkNpmPassthru { folder = "ui-tui"; attr = "tui"; pname = "hermes-tui"; }; # npm = hermesNpmLib.mkNpmPassthru { folder = "ui-tui"; attr = "tui"; pname = "hermes-tui"; };
# pkgs.buildNpmPackage (npm // { ... } # or: # pkgs.buildNpmPackage (npm // { ... } # or:
# pkgs.buildNpmPackage ({ ... } // npm) # pkgs.buildNpmPackage ({ ... } // npm)
mkNpmPassthru = mkNpmPassthru =
{ folder, # repo-relative folder with package.json, e.g. "ui-tui" {
folder, # repo-relative folder with package.json, e.g. "ui-tui"
attr, # flake package attr, e.g. "tui" attr, # flake package attr, e.g. "tui"
pname, # e.g. "hermes-tui" pname, # e.g. "hermes-tui"
nixFile ? "nix/${attr}.nix", # defaults to nix/<attr>.nix nixFile ? "nix/${attr}.nix", # defaults to nix/<attr>.nix
@@ -20,7 +26,25 @@
{ {
patchPhase = '' patchPhase = ''
runHook prePatch runHook prePatch
sed -i -z 's/\n$//' package-lock.json # Normalize trailing newlines so source and npm-deps always match,
# regardless of what fetchNpmDeps preserves.
sed -i -z 's/\n*$/\n/' package-lock.json
# Make npmConfigHook's byte-for-byte diff newline-agnostic by
# replacing its hardcoded /nix/store/.../diff with a wrapper that
# normalizes trailing newlines on both sides before comparing.
mkdir -p "$TMPDIR/bin"
cat > "$TMPDIR/bin/diff" << DIFFWRAP
#!/bin/sh
f1=\$(mktemp) && sed -z 's/\n*$/\n/' "\$1" > "\$f1"
f2=\$(mktemp) && sed -z 's/\n*$/\n/' "\$2" > "\$f2"
${pkgs.diffutils}/bin/diff "\$f1" "\$f2" && rc=0 || rc=\$?
rm -f "\$f1" "\$f2"
exit \$rc
DIFFWRAP
chmod +x "$TMPDIR/bin/diff"
export PATH="$TMPDIR/bin:$PATH"
runHook postPatch runHook postPatch
''; '';