Make workspace authoring converge through immutable Nix candidates

Coordinate registered resource edits bottom-up into retained exact remote sources.
Use one Nix-owned source graph for provisional checking, template publication,
explicit baseline upgrades and host activation; retain independent runtime pins.

Add scoped contract inspection, historical recovery, derived worklists, crash-safe
locks, named dependency adoption and plain-QX structural editing. Repair TODO
ownership and template instantiation, and document the supported agent workflow.

Validated with protocol and command suites, real jj/Nix convergence and cache
checks, TS/React installed-command acceptance, and fresh TODO first-edit acceptance.
No live deployment or public publication performed. Props projection generation
and a one-command rich feature generator remain explicitly outside this delivery.
This commit is contained in:
Timothy J. Aveni
2026-09-14 10:26:11 -07:00
parent fae4e48f72
commit 01ca965c7f
29 changed files with 1103 additions and 75 deletions
+77
View File
@@ -0,0 +1,77 @@
# All source trees and recursive locks are fetched by Nix at exact retained
# revisions. No authoring-directory overlay or externally assembled schema.
{ repository, commit, kind, generator, contractOnly ? false, system ? builtins.currentSystem }:
let
pkgs = import (/. + "@nixpkgs@") { inherit system; };
protocol = builtins.storePath generator;
sourceKey = source: "${source.kind}:${source.repository}@${source.commit}";
fetch = source: builtins.fetchGit {
url = source.repository;
rev = source.commit;
ref = "refs/tags/quixos-reachability/${source.commit}";
shallow = true;
};
load = ancestors: source:
if builtins.elem (sourceKey source) ancestors then
throw "Source dependency cycle at ${sourceKey source}"
else if builtins.length ancestors >= 100 then
throw "Source dependency depth exceeds 100"
else let
directory = fetch source;
lockFile = pkgs.runCommand "qx-source-lock.json" { } ''
${protocol}/bin/quixos-lock-check ${directory}/quixos.lock > "$out"
'';
lock = builtins.fromJSON (builtins.readFile lockFile);
children = map (entry: load (ancestors ++ [ (sourceKey source) ]) (entry.source // { inherit (entry) kind; })) lock.resources;
in source // { inherit directory children; };
root = load [ ] { inherit kind repository commit; };
flatten = node: [ node ] ++ pkgs.lib.concatMap flatten node.children;
nodes = builtins.attrValues (builtins.listToAttrs (map (node: {
name = sourceKey node; value = node;
}) (flatten root)));
snapshots = pkgs.writeText "qx-nix-source-graph.json" (builtins.toJSON {
resources = map (node: { inherit (node) kind repository commit directory; })
(builtins.filter (node: node.kind != "workspace") nodes);
});
compile = node: pkgs.runCommand "qx-${node.kind}-contract" { } ''
mkdir -p "$out"
${if node.kind == "workspace" then ''
${protocol}/bin/quixos-workspace-compile --root ${node.directory} \
--source-root-commit ${pkgs.lib.escapeShellArg node.commit} \
--checkout-root "$TMPDIR/checkouts" --snapshot-map ${snapshots} \
--graph-out "$out/graph.json" > "$out/candidate.json"
'' else ''
${protocol}/bin/quixos-resource-compile --root ${node.directory} \
--kind ${node.kind} --repository ${pkgs.lib.escapeShellArg node.repository} \
--commit ${pkgs.lib.escapeShellArg node.commit} \
--checkout-root "$TMPDIR/checkouts" --snapshot-map ${snapshots} --snapshot-only true \
--graph-out "$out/graph.json" --schema-out "$out/bindings.json" > "$out/candidate.json"
''}
'';
contract = compile root;
checkPackage = node: let
compiled = compile node;
candidate = builtins.fromJSON (builtins.readFile "${compiled}/candidate.json");
package = builtins.getFlake ("git+${node.repository}?rev=${node.commit}&ref=refs/tags/quixos-reachability/${node.commit}");
checked = package.quixosPackages.${system}.checkedServer or
(throw "Package ${node.repository} lacks checkedServer; use the supported package scaffold.");
artifact = checked {
schema = "${compiled}/bindings.json";
generator = protocol;
packageRevisionId = candidate.revision.revisionId;
};
in { packageRevisionId = candidate.revision.revisionId; artifactPath = artifact; };
checks = if contractOnly then [ ] else map checkPackage (builtins.filter (node: node.kind == "package") nodes);
manifest = pkgs.writeText "qx-candidate-checks.json" (builtins.toJSON checks);
in pkgs.runCommand (if contractOnly then "qx-contract" else "qx-checked-candidate") { } ''
mkdir -p "$out"
cp ${contract}/candidate.json "$out/candidate.json"
cp ${contract}/graph.json "$out/graph.json"
cp ${manifest} "$out/checks.json"
${pkgs.lib.optionalString (kind != "workspace") ''cp ${contract}/bindings.json "$out/bindings.json"''}
${pkgs.lib.optionalString (kind == "package") ''
${protocol}/bin/quixos-codegen-ts ${contract}/bindings.json \
${pkgs.lib.escapeShellArg (builtins.fromJSON (builtins.readFile "${contract}/candidate.json")).revision.revisionId} \
"$out/bindings.ts" ${pkgs.lib.optionalString (builtins.pathExists (root.directory + "/bindings.json")) (toString root.directory + "/bindings.json")}
''}
''