mirror of
https://github.com/getpaseo/paseo.git
synced 2026-07-29 12:01:31 +00:00
* fix: add missing resolved/integrity fields to package-lock.json npm omits resolved URLs and integrity hashes for workspace-local node_modules overrides. This breaks offline installers like Nix's npm ci. Add the missing fields for 25 workspace-hoisted packages. * feat: add Nix flake with package and NixOS module Add a Nix flake that builds the Paseo daemon (server + CLI) and provides a NixOS module for declarative deployment. Package (nix/package.nix): - Builds relay, server, and CLI workspaces - Skips onnxruntime-node install script (sandbox-incompatible) - Rebuilds only node-pty for native terminal support - Source filter excludes app/website/desktop workspaces NixOS module (nix/module.nix): - Systemd service with configurable user, port, listen address - allowedHosts for DNS rebinding protection - relay.enable to toggle remote access via app.paseo.sh - inheritUserEnvironment to expose user tools (git, ssh) to agents - openFirewall and extra environment variables ci: add Nix hash maintenance scripts and workflows scripts/fix-lockfile.mjs: Adds missing resolved/integrity fields to package-lock.json for workspace-local overrides. Idempotent, uses `npm view`. scripts/update-nix.sh: Runs fix-lockfile.mjs, prefetches deps, computes NAR hash, and updates npmDepsHash in nix/package.nix. Supports --check for CI. .github/workflows/nix-build.yml: Builds the Nix package on push/PR and verifies the lockfile and hash are up to date. .github/workflows/fix-nix-hash.yml: Auto-fixes lockfile signatures and Nix hash on dependabot PRs. fix: update npmDepsHash after upstream sync nix: allowlist workspace symlinks instead of blocklist Prevents build failures when upstream adds new workspace packages. * don't block PRs on nix failures * better document npm workaround * fix hash update script, and update hash * integrate with npm run build:daemon * ci: trigger nix build on highlight changes * fix(nix): update npmDepsHash --------- Co-authored-by: Mohamed Boudra <boudra.moha@gmail.com>
64 lines
1.9 KiB
Bash
Executable File
64 lines
1.9 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Fix workspace-local lockfile entries and update the Nix dependency hash.
|
|
# Requires: node, npm, nix
|
|
#
|
|
# Usage:
|
|
# ./scripts/update-nix.sh # fix lockfile + update hash
|
|
# ./scripts/update-nix.sh --check # verify everything is up to date (CI mode)
|
|
set -euo pipefail
|
|
|
|
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
|
|
ROOT_DIR="$(cd "$SCRIPT_DIR/.." && pwd)"
|
|
LOCK_FILE="$ROOT_DIR/package-lock.json"
|
|
PACKAGE_NIX="$ROOT_DIR/nix/package.nix"
|
|
|
|
CHECK_MODE=false
|
|
if [[ "${1:-}" == "--check" ]]; then
|
|
CHECK_MODE=true
|
|
fi
|
|
|
|
# 1. Fix lockfile (add resolved/integrity for workspace-local entries)
|
|
# Workaround for https://github.com/npm/cli/issues/4460
|
|
echo "Fixing lockfile..."
|
|
node "$SCRIPT_DIR/fix-lockfile.mjs" "$LOCK_FILE"
|
|
|
|
# 2. Prefetch deps and compute hash
|
|
echo "Prefetching npm dependencies..."
|
|
|
|
# Resolve prefetch-npm-deps from the same nixpkgs pinned in flake.lock
|
|
NIXPKGS_URL="$(node -p "
|
|
const l = JSON.parse(require('fs').readFileSync('$ROOT_DIR/flake.lock', 'utf8'));
|
|
const n = l.nodes.nixpkgs.locked;
|
|
'github:' + n.owner + '/' + n.repo + '/' + n.rev;
|
|
")"
|
|
|
|
STDERR_LOG="$(mktemp)"
|
|
trap "rm -f '$STDERR_LOG'" EXIT
|
|
|
|
if ! NEW_HASH="$(nix shell "${NIXPKGS_URL}#prefetch-npm-deps" -c prefetch-npm-deps "$LOCK_FILE" 2>"$STDERR_LOG")"; then
|
|
echo "ERROR: prefetch-npm-deps failed:" >&2
|
|
tail -20 "$STDERR_LOG" >&2
|
|
exit 1
|
|
fi
|
|
echo "Computed hash: $NEW_HASH"
|
|
|
|
# 3. Read current hash
|
|
CURRENT_HASH="$(grep 'npmDepsHash' "$PACKAGE_NIX" | sed 's/.*"\(.*\)".*/\1/')"
|
|
|
|
if [[ "$NEW_HASH" == "$CURRENT_HASH" ]]; then
|
|
echo "Hash is already up to date."
|
|
else
|
|
if $CHECK_MODE; then
|
|
echo "ERROR: npmDepsHash is stale."
|
|
echo " current: $CURRENT_HASH"
|
|
echo " correct: $NEW_HASH"
|
|
echo "Run ./scripts/update-nix.sh to fix."
|
|
exit 1
|
|
fi
|
|
|
|
echo "Updating npmDepsHash in nix/package.nix..."
|
|
sed -i.bak "s|npmDepsHash = \".*\"|npmDepsHash = \"$NEW_HASH\"|" "$PACKAGE_NIX"
|
|
rm -f "$PACKAGE_NIX.bak"
|
|
echo "Updated: $CURRENT_HASH -> $NEW_HASH"
|
|
fi
|