mirror of
https://relay.ngit.dev/npub15qydau2hjma6ngxkl2cyar74wzyjshvl65za5k5rl69264ar2exs5cyejr/ngit-grasp.git
synced 2026-10-05 15:08:24 +00:00
Tagged releases need installable artifacts whose source and embedded revision are pinned to the pushed tag, without requiring operators to have Rust or Nix on the deployment host. Add a Linux pkgsStatic output and a v* ngit-ci workflow that verifies the tag against Cargo package metadata, builds the x86_64 MUSL binary, creates a reproducible licensed archive and SHA256SUMS, and uploads both as release assets. Derive the Nix package version from Cargo.toml so release validation has one authoritative version. The first artifact target assumes x86_64 Linux and the existing tag-trigger environment provided by ngit-ci. Multi-architecture archives, OCI publication, release tagging, and the separate v3 metadata promotion are deliberately excluded. Validated with a staged-tree nix build .#static, static PIE and embedded-revision inspection, an archive/checksum round trip, nix flake check --no-build --no-write-lock-file, cargo metadata, and git diff --check.
118 lines
4.1 KiB
Nix
118 lines
4.1 KiB
Nix
{
|
|
description = "ngit-grasp - A GRASP implementation in Rust";
|
|
|
|
inputs = {
|
|
nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
|
|
rust-overlay.url = "github:oxalica/rust-overlay";
|
|
flake-utils.url = "github:numtide/flake-utils";
|
|
};
|
|
|
|
outputs = { self, nixpkgs, rust-overlay, flake-utils }:
|
|
let
|
|
sourceRevision =
|
|
if self ? rev then self.rev
|
|
else if self ? dirtyRev then self.dirtyRev
|
|
else "unknown";
|
|
ngitGraspVersion =
|
|
(builtins.fromTOML (builtins.readFile ./Cargo.toml)).package.version;
|
|
in
|
|
(flake-utils.lib.eachDefaultSystem (system:
|
|
let
|
|
overlays = [ (import rust-overlay) ];
|
|
pkgs = import nixpkgs { inherit system overlays; };
|
|
|
|
rustToolchain = pkgs.rust-bin.stable.latest.default.override {
|
|
extensions = [ "rust-src" "rust-analyzer" ];
|
|
};
|
|
in {
|
|
devShells.default = pkgs.mkShell {
|
|
# Single dev shell for the whole workspace (ngit-grasp + grasp-audit).
|
|
buildInputs = with pkgs; [ rustToolchain pkg-config openssl git gitlint ];
|
|
|
|
RUST_SRC_PATH = "${rustToolchain}/lib/rustlib/src/rust/library";
|
|
|
|
shellHook = ''
|
|
echo "🚀 ngit-grasp workspace development environment"
|
|
echo "Rust version: $(rustc --version)"
|
|
echo ""
|
|
echo "Quick commands:"
|
|
echo " cargo build - Build the whole workspace"
|
|
echo " cargo test - Run ngit-grasp tests"
|
|
echo " cargo run - Run the relay"
|
|
echo " cargo build -p grasp-audit - Build the audit tool"
|
|
echo " cargo test -p grasp-audit - Run grasp-audit unit tests"
|
|
echo ""
|
|
'';
|
|
};
|
|
|
|
# Both crates are members of a single workspace sharing one Cargo.lock.
|
|
packages = {
|
|
default = self.packages.${system}.ngit-grasp;
|
|
|
|
ngit-grasp = pkgs.rustPlatform.buildRustPackage {
|
|
pname = "ngit-grasp";
|
|
version = ngitGraspVersion;
|
|
src = ./.;
|
|
NGIT_BUILD_REVISION = sourceRevision;
|
|
cargoLock = {
|
|
lockFile = ./Cargo.lock;
|
|
};
|
|
|
|
# Only build/test the ngit-grasp package, not the whole workspace.
|
|
cargoBuildFlags = [ "-p" "ngit-grasp" ];
|
|
|
|
nativeBuildInputs = with pkgs; [ pkg-config git ];
|
|
|
|
buildInputs = with pkgs; [ openssl ];
|
|
|
|
# Run lib tests only; integration tests spawn a live relay and require
|
|
# network access not available in the Nix sandbox.
|
|
doCheck = true;
|
|
cargoTestFlags = [ "-p" "ngit-grasp" "--lib" ];
|
|
};
|
|
|
|
grasp-audit = pkgs.rustPlatform.buildRustPackage {
|
|
pname = "grasp-audit";
|
|
version = "0.2.0";
|
|
src = ./.;
|
|
cargoLock = {
|
|
lockFile = ./Cargo.lock;
|
|
};
|
|
|
|
cargoBuildFlags = [ "-p" "grasp-audit" ];
|
|
|
|
nativeBuildInputs = with pkgs; [ pkg-config git ];
|
|
|
|
buildInputs = with pkgs; [ openssl ];
|
|
|
|
# Audit tests require a running Nostr relay; skip in the sandbox.
|
|
doCheck = false;
|
|
};
|
|
} // pkgs.lib.optionalAttrs pkgs.stdenv.isLinux {
|
|
# Portable release binary used by the tag-triggered release workflow.
|
|
static = pkgs.pkgsStatic.rustPlatform.buildRustPackage {
|
|
pname = "ngit-grasp";
|
|
version = ngitGraspVersion;
|
|
src = ./.;
|
|
NGIT_BUILD_REVISION = sourceRevision;
|
|
cargoLock = {
|
|
lockFile = ./Cargo.lock;
|
|
};
|
|
|
|
cargoBuildFlags = [ "-p" "ngit-grasp" ];
|
|
nativeBuildInputs = with pkgs; [ pkg-config ];
|
|
buildInputs = with pkgs.pkgsStatic; [ openssl ];
|
|
|
|
doCheck = false;
|
|
};
|
|
};
|
|
})) // {
|
|
# NixOS module for deployment
|
|
nixosModules.default = { ... }: {
|
|
imports = [ ./nix/module.nix ];
|
|
_module.args.ngitGraspSourceRevision = sourceRevision;
|
|
};
|
|
nixosModules.ngit-grasp = self.nixosModules.default;
|
|
};
|
|
}
|