Compare commits

..

4 Commits

Author SHA1 Message Date
Timothy J. Aveni 8dde1f6b82 Add Camino TypeScript package helper 2026-07-12 12:21:21 -07:00
Timothy J. Aveni e0874093f2 Drop perl from package prepare shell 2026-06-27 20:33:06 -07:00
Timothy J. Aveni 0b159fcb81 Add perl to package prepare shell 2026-06-27 20:31:20 -07:00
Timothy J. Aveni f33eee054f Initial commit
germanium cutoff
2026-05-24 15:25:38 -07:00
4 changed files with 14 additions and 140 deletions
-8
View File
@@ -1,8 +0,0 @@
{
"version": 1,
"sourceRepo": "https://gitea-external.egads.tutti.syntaxblitz.net/quixos/quixos",
"sourceCommit": "22bb3d02264980d74de65c34bbbcb81764dc65c0",
"sourcePath": "quixos-instance/quixos-nix-helpers",
"exportName": "quixos-nix-helpers",
"mirrorRemote": "https://gitea-external.egads.tutti.syntaxblitz.net/quixos/quixos-nix-helpers.git"
}
-17
View File
@@ -1,17 +0,0 @@
import fs from "node:fs";
import crypto from "node:crypto";
const [schemaPath, packageRevisionId, bindingOutput, generatorPath, output] = process.argv.slice(2);
if (!schemaPath || !packageRevisionId || !bindingOutput || !generatorPath || !output) throw new Error("Missing candidate check receipt inputs");
const canonical = (value) => Array.isArray(value) ? value.map(canonical) : value && typeof value === "object"
? Object.fromEntries(Object.entries(value).sort(([a], [b]) => a < b ? -1 : a > b ? 1 : 0).map(([key, entry]) => [key, canonical(entry)])) : value;
const hash = (value) => `sha256:${crypto.createHash("sha256").update(JSON.stringify(canonical(value))).digest("hex")}`;
const schema = JSON.parse(fs.readFileSync(schemaPath, "utf8"));
if (!schema.packages.some((entry) => entry.revisionId === packageRevisionId)) throw new Error("Checked binding schema lacks the package");
const generated = fs.readFileSync(bindingOutput, "utf8");
if (generated !== fs.readFileSync(".qx-checked-bindings", "utf8")) throw new Error("Build replaced candidate-generated bindings; its check is not evidence for this candidate");
const receipt = {
schemaVersion: 1, packageRevisionId, success: true, bindingSchema: schema,
bindingSchemaDigest: hash(schema), generatedDigest: hash(generated),
checkerDigest: hash({ generatorPath, compiler: JSON.parse(fs.readFileSync("node_modules/typescript/package.json", "utf8")), lock: fs.readFileSync("yarn.lock", "utf8") }),
};
fs.writeFileSync(output, `${JSON.stringify(receipt, null, 2)}\n`, { flag: "wx" });
-13
View File
@@ -1,13 +0,0 @@
# The caller has compiled this package and its exact recursive candidate graph.
# No credentials, mutable references, or workspace-wide unrelated schema enter
# the package derivation. Ordinary #server builds are not promotion evidence.
{ source, schema, generator, packageRevisionId, system ? builtins.currentSystem }:
let
package = builtins.getFlake ("path:" + source);
checked = package.quixosPackages.${system}.checkedServer or
(throw "Package ${packageRevisionId} lacks checkedServer. Upgrade its Nix helper and adopt generated implementation bindings before cutover.");
in checked {
inherit packageRevisionId;
schema = builtins.path { path = /. + schema; name = "candidate-package-bindings.json"; };
generator = builtins.storePath generator;
}
+14 -102
View File
@@ -510,20 +510,6 @@ EOF
''; '';
}; };
# Language-neutral, offline schema compilation. Snapshot directories must be
# fixed Nix inputs matching the resource lock's complete dependency closure.
mkQxBindingSchema = { pkgs, protocol, src, repository, commit, resources ? [ ] }:
let
snapshots = pkgs.writeText "qx-binding-snapshots.json" (builtins.toJSON { inherit resources; });
in pkgs.runCommand "qx-binding-schema.json" { } ''
${protocol}/bin/quixos-resource-compile \
--root ${src} --kind package \
--repository ${pkgs.lib.escapeShellArg repository} \
--commit ${pkgs.lib.escapeShellArg commit} \
--checkout-root "$TMPDIR/checkouts" \
--snapshot-map ${snapshots} --snapshot-only true --schema-out "$out" > /dev/null
'';
mkCaminoTsYarnNixifyFlake = mkCaminoTsYarnNixifyFlake =
{ {
inputs, inputs,
@@ -535,14 +521,8 @@ EOF
promptName ? null, promptName ? null,
nodejsAttr ? "nodejs_24", nodejsAttr ? "nodejs_24",
buildCommand ? "yarn build", buildCommand ? "yarn build",
sourcePortals ? { },
buildEnv ? { }, buildEnv ? { },
# An exact, compiler-produced BindingSchema JSON artifact and a backend.
# Other language helpers can consume the same schema with their own generator/runtime.
bindings ? null,
bindingOptions ? { },
# A dedicated entrypoint calling SDK serveMigration; never start the
# normal package server in the isolated migration execution boundary.
migrationEntrypoint ? null,
nativeBuildInputs ? [ ], nativeBuildInputs ? [ ],
devShellPackages ? [ ], devShellPackages ? [ ],
devShellHook ? "", devShellHook ? "",
@@ -551,8 +531,6 @@ EOF
}: }:
flake-utils.lib.eachDefaultSystem ( flake-utils.lib.eachDefaultSystem (
system: system:
let
outputsFor = candidateBindings:
let let
pkgs = import nixpkgs { inherit system; }; pkgs = import nixpkgs { inherit system; };
lib = pkgs.lib; lib = pkgs.lib;
@@ -583,29 +561,12 @@ EOF
attrs attrs
); );
bindingConfig = if candidateBindings != null then candidateBindings portalLinksFor = attrs:
else if bindings == null then null else callOption bindings; lib.concatStringsSep "\n" (
bindingSchema = if bindingConfig == null then null else bindingConfig.schema or (mkQxBindingSchema { lib.mapAttrsToList
inherit pkgs; (target: source: "ln -sfn ${source} ${lib.escapeShellArg target}")
protocol = bindingConfig.generator; attrs
src = packageRoot; );
inherit (bindingConfig) repository commit;
resources = bindingConfig.resources or [ ];
});
bindingOutput = if bindingConfig == null then "src/gen/qx.ts" else bindingConfig.output or "src/gen/qx.ts";
bindingOptionsFile = if bindingConfig == null then null else
pkgs.writeText "qx-typescript-options.json" (builtins.toJSON (bindingConfig.options or bindingOptions));
bindingCommand = if bindingConfig == null then "" else ''
mkdir -p ${lib.escapeShellArg (dirOf bindingOutput)}
${bindingConfig.generator}/bin/quixos-codegen-ts \
${lib.escapeShellArg (toString bindingSchema)} \
${lib.escapeShellArg bindingConfig.packageRevisionId} \
${lib.escapeShellArg bindingOutput} ${bindingOptionsFile}
'';
generateBindings = pkgs.writeShellApplication {
name = "qx-generate-bindings";
text = bindingCommand;
};
bundleConfig = if bundle == null then { } else bundle; bundleConfig = if bundle == null then { } else bundle;
bundleOutfile = bundleConfig.outfile or "server.mjs"; bundleOutfile = bundleConfig.outfile or "server.mjs";
@@ -613,14 +574,6 @@ EOF
bundleTarget = bundleConfig.target or "node24"; bundleTarget = bundleConfig.target or "node24";
bundleFormat = bundleConfig.format or "esm"; bundleFormat = bundleConfig.format or "esm";
bundleBanner = bundleConfig.banner or nodeRequireBanner; bundleBanner = bundleConfig.banner or nodeRequireBanner;
bundleAliases = bundleConfig.aliases or {
"@automerge/automerge" = "./node_modules/@automerge/automerge/dist/mjs/entrypoints/fullfat_base64.js";
};
bundleAliasArgs = lib.concatStringsSep " " (
lib.mapAttrsToList
(from: to: "--alias:${from}=${lib.escapeShellArg to}")
bundleAliases
);
nodeRequireBanner = "import { createRequire } from 'module';const require = createRequire(import.meta.url);"; nodeRequireBanner = "import { createRequire } from 'module';const require = createRequire(import.meta.url);";
bundleCommand = bundleCommand =
if bundle == null if bundle == null
@@ -631,7 +584,6 @@ EOF
--platform=${bundlePlatform} \ --platform=${bundlePlatform} \
--target=${bundleTarget} \ --target=${bundleTarget} \
--format=${bundleFormat} \ --format=${bundleFormat} \
${bundleAliasArgs} \
${lib.optionalString (bundleConfig.preserveSymlinks or true) "--preserve-symlinks \\"} ${lib.optionalString (bundleConfig.preserveSymlinks or true) "--preserve-symlinks \\"}
--banner:js=${lib.escapeShellArg bundleBanner} \ --banner:js=${lib.escapeShellArg bundleBanner} \
--outfile=${lib.escapeShellArg bundleOutfile} --outfile=${lib.escapeShellArg bundleOutfile}
@@ -643,22 +595,12 @@ EOF
installConfig.libexecName or (lib.strings.sanitizeDerivationName packageNameFinal); installConfig.libexecName or (lib.strings.sanitizeDerivationName packageNameFinal);
serverFile = installConfig.serverFile or bundleOutfile; serverFile = installConfig.serverFile or bundleOutfile;
descriptorPath = installConfig.descriptorPath or "descriptor.quixos-package.txtpb"; descriptorPath = installConfig.descriptorPath or "descriptor.quixos-package.txtpb";
extraFiles = installConfig.extraFiles or [ ];
installExtraFile = file:
let
source = toString file.source;
target = file.target or (baseNameOf source);
mode = file.mode or "0644";
in ''
install -Dm${toString mode} ${lib.escapeShellArg source} "$out/libexec/${serverLibexecName}/${target}"
'';
installServerPhase = installServerPhase =
if installServer == null if installServer == null
then null then null
else '' else ''
runHook preInstall runHook preInstall
install -Dm755 ${lib.escapeShellArg serverFile} "$out/libexec/${serverLibexecName}/${serverFile}" install -Dm755 ${lib.escapeShellArg serverFile} "$out/libexec/${serverLibexecName}/${serverFile}"
${lib.concatMapStringsSep "\n" installExtraFile extraFiles}
mkdir -p "$out/bin" mkdir -p "$out/bin"
cat > "$out/bin/${serverBin}" <<EOF cat > "$out/bin/${serverBin}" <<EOF
#!${pkgs.runtimeShell} #!${pkgs.runtimeShell}
@@ -668,17 +610,6 @@ EOF
${lib.optionalString (installConfig ? descriptorPath && descriptorPath != null) '' ${lib.optionalString (installConfig ? descriptorPath && descriptorPath != null) ''
cp ${lib.escapeShellArg descriptorPath} "$out/${descriptorPath}" cp ${lib.escapeShellArg descriptorPath} "$out/${descriptorPath}"
''} ''}
${lib.optionalString (bindingConfig != null) ''
install -m 0444 quixos-check.json "$out/quixos-check.json"
''}
${lib.optionalString (migrationEntrypoint != null) ''
install -Dm444 migration.mjs "$out/libexec/${serverLibexecName}/migration.mjs"
cat > "$out/bin/migrate" <<EOF
#!${pkgs.runtimeShell}
exec ${nodejs}/bin/node --max-old-space-size=256 "$out/libexec/${serverLibexecName}/migration.mjs" "\$@"
EOF
chmod +x "$out/bin/migrate"
''}
runHook postInstall runHook postInstall
''; '';
@@ -687,26 +618,16 @@ EOF
overrideAttrs = old: { overrideAttrs = old: {
nativeBuildInputs = nativeBuildInputs =
(old.nativeBuildInputs or [ ]) (old.nativeBuildInputs or [ ])
++ lib.optional (bundle != null || migrationEntrypoint != null) pkgs.esbuild ++ lib.optional (bundle != null) pkgs.esbuild
++ callOption nativeBuildInputs; ++ callOption nativeBuildInputs;
preConfigure = (old.preConfigure or "") + ''
${portalLinksFor (callOption sourcePortals)}
'';
buildPhase = '' buildPhase = ''
runHook preBuild runHook preBuild
${exportsFor (callOption buildEnv)} ${exportsFor (callOption buildEnv)}
${bindingCommand}
${lib.optionalString (bindingConfig != null) "yarn exec tsc --noEmit"}
${lib.optionalString (bindingConfig != null) "cp ${lib.escapeShellArg bindingOutput} .qx-checked-bindings"}
${buildCommand} ${buildCommand}
${lib.optionalString (bindingConfig != null) ''
yarn exec tsc --noEmit
node ${./check-receipt.mjs} ${lib.escapeShellArg (toString bindingSchema)} \
${lib.escapeShellArg bindingConfig.packageRevisionId} ${lib.escapeShellArg bindingOutput} \
${lib.escapeShellArg (toString bindingConfig.generator)} quixos-check.json
''}
${bundleCommand} ${bundleCommand}
${lib.optionalString (migrationEntrypoint != null) ''
esbuild ${lib.escapeShellArg migrationEntrypoint} --bundle --platform=node --target=node24 --format=esm \
${bundleAliasArgs} --preserve-symlinks --banner:js=${lib.escapeShellArg nodeRequireBanner} --outfile=migration.mjs
''}
runHook postBuild runHook postBuild
''; '';
} // lib.optionalAttrs (installServerPhase != null) { } // lib.optionalAttrs (installServerPhase != null) {
@@ -741,19 +662,11 @@ EOF
devShells.default = pkgs.mkShell { devShells.default = pkgs.mkShell {
packages = [ packages = [
nodejs nodejs
project.yarn-freestanding pkgs.yarn-berry_4
] ++ lib.optional (bindingConfig != null) generateBindings ++ callOption devShellPackages; ] ++ callOption devShellPackages;
# Explicit command keeps shell entry free of source mutations.
shellHook = devShellHookBase + callOption devShellHook; shellHook = devShellHookBase + callOption devShellHook;
}; };
} // maybeServerOutputs; } // maybeServerOutputs
in (outputsFor null) // {
# The workspace supplies a compiler-produced schema for the exact
# candidate graph. Standalone builds may use checked-in authoring types,
# but only this build path regenerates and witnesses candidate contracts.
quixosPackages.checkedServer = { schema, generator, packageRevisionId }:
(outputsFor { inherit schema generator packageRevisionId; }).packages.server;
}
); );
in in
{ {
@@ -762,6 +675,5 @@ in
mkTsPackageServer mkTsPackageServer
mkSchemaSupport mkSchemaSupport
mkCaminoSourcePackage mkCaminoSourcePackage
mkQxBindingSchema
mkCaminoTsYarnNixifyFlake; mkCaminoTsYarnNixifyFlake;
} }