diff --git a/.github/workflows/build-tarball.yml b/.github/workflows/build-tarball.yml index ab0698e11b74..248e64bab776 100644 --- a/.github/workflows/build-tarball.yml +++ b/.github/workflows/build-tarball.yml @@ -23,6 +23,7 @@ on: - tools/eslint-rules/** - tools/eslint/** - tools/lint-md/** + - tools/nix/** - typings/** - vcbuild.bat - .** @@ -52,6 +53,7 @@ on: - tools/eslint-rules/** - tools/eslint/** - tools/lint-md/** + - tools/nix/** - typings/** - vcbuild.bat - .** diff --git a/.github/workflows/coverage-windows.yml b/.github/workflows/coverage-windows.yml index 59329670e6c2..d0236cd7d609 100644 --- a/.github/workflows/coverage-windows.yml +++ b/.github/workflows/coverage-windows.yml @@ -23,6 +23,7 @@ on: - tools/eslint-rules/** - tools/eslint/** - tools/lint-md/** + - tools/nix/** - typings/** - .** - '!.github/workflows/coverage-windows.yml' @@ -49,6 +50,7 @@ on: - tools/eslint-rules/** - tools/eslint/** - tools/lint-md/** + - tools/nix/** - typings/** - .** - '!.github/workflows/coverage-windows.yml' diff --git a/.github/workflows/nix-changes.yml b/.github/workflows/nix-changes.yml index 84c4337bab19..ed25798152e3 100644 --- a/.github/workflows/nix-changes.yml +++ b/.github/workflows/nix-changes.yml @@ -11,10 +11,12 @@ on: - v[0-9]+.x paths: - '**.nix' + - tools/nix/** - .github/workflows/nix-changes.yml pull_request: paths: - '**.nix' + - tools/nix/** - .github/workflows/nix-changes.yml types: [opened, synchronize, reopened, ready_for_review] @@ -47,7 +49,9 @@ jobs: with: fetch-depth: 2 persist-credentials: false - sparse-checkout: '*.nix' + sparse-checkout: | + shell.nix + tools/nix/ sparse-checkout-cone-mode: false - uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0 @@ -60,39 +64,14 @@ jobs: name: nodejs - name: Compute requisites after change - shell: bash # See https://docs.github.com/en/actions/writing-workflows/workflow-syntax-for-github-actions#exit-codes-and-error-action-preference, we want the pipefail option. - run: | - nix-store --query --references "$( - nix-instantiate -I "nixpkgs=./tools/nix/pkgs.nix" shell.nix \ - --arg devTools " - (import ./tools/nix/devTools.nix {}) - ++ builtins.attrValues ( - { inherit (import {}) nixfmt-tree sccache; } - // import ./tools/nix/openssl-matrix.nix {} - // import ./tools/nix/pkcs11.nix {} - )")" \ - | xargs nix-store --realise \ - | xargs nix-store --query --requisites \ - | sort -k1.45 \ - > requisites-${{ matrix.system }}-after.list + run: ./tools/nix/list-requisites.sh > requisites-${{ matrix.system }}-after.list - name: Compute requisites before change - shell: bash # See https://docs.github.com/en/actions/writing-workflows/workflow-syntax-for-github-actions#exit-codes-and-error-action-preference, we want the pipefail option. run: | git reset HEAD^ --hard - nix-store --query --references "$( - nix-instantiate -I "nixpkgs=./tools/nix/pkgs.nix" shell.nix \ - --arg devTools " - (import ./tools/nix/devTools.nix {}) - ++ builtins.attrValues ( - { inherit (import {}) nixfmt-tree sccache; } - // import ./tools/nix/openssl-matrix.nix {} - // import ./tools/nix/pkcs11.nix {} - )")" \ - | xargs nix-store --realise \ - | xargs nix-store --query --requisites \ - | sort -k1.45 \ - > requisites-${{ matrix.system }}-before.list + # TODO(aduh95): remove this once list-requisites.sh has reached `main` + [ -f tools/nix/list-requisites.sh ] || git checkout FETCH_HEAD -- tools/nix/list-requisites.sh + ./tools/nix/list-requisites.sh > requisites-${{ matrix.system }}-before.list - name: Output diff run: | diff --git a/.github/workflows/test-linux.yml b/.github/workflows/test-linux.yml index 40762503f685..7681a176139d 100644 --- a/.github/workflows/test-linux.yml +++ b/.github/workflows/test-linux.yml @@ -9,6 +9,7 @@ on: - tools/actions/** - tools/clang-format/** - tools/dep_updaters/** + - tools/nix/** - test/internet/** - '**.nix' - .github/** @@ -27,6 +28,7 @@ on: - tools/actions/** - tools/clang-format/** - tools/dep_updaters/** + - tools/nix/** - test/internet/** - '**.nix' - .github/** diff --git a/.github/workflows/test-macos.yml b/.github/workflows/test-macos.yml index e87e83505d6d..c53bcde2851c 100644 --- a/.github/workflows/test-macos.yml +++ b/.github/workflows/test-macos.yml @@ -23,6 +23,7 @@ on: - tools/eslint-rules/** - tools/eslint/** - tools/lint-md/** + - tools/nix/** - typings/** - vcbuild.bat - .** @@ -53,6 +54,7 @@ on: - tools/eslint-rules/** - tools/eslint/** - tools/lint-md/** + - tools/nix/** - typings/** - vcbuild.bat - .** diff --git a/.github/workflows/test-shared.yml b/.github/workflows/test-shared.yml index 284372317359..8a04fe4d74fc 100644 --- a/.github/workflows/test-shared.yml +++ b/.github/workflows/test-shared.yml @@ -44,6 +44,7 @@ on: - '!tools/nix/**' - '!tools/v8/**' - '!tools/v8_gypfiles/**' + - tools/nix/list-requisites.sh - typings/** - vcbuild.bat - .** @@ -96,6 +97,7 @@ on: - '!tools/nix/**' - '!tools/v8/**' - '!tools/v8_gypfiles/**' + - tools/nix/list-requisites.sh - typings/** - vcbuild.bat - .** diff --git a/tools/nix/list-requisites.sh b/tools/nix/list-requisites.sh new file mode 100755 index 000000000000..92aa91794326 --- /dev/null +++ b/tools/nix/list-requisites.sh @@ -0,0 +1,62 @@ +#!/bin/sh + +set -ex + +BASE_DIR=$(cd "$(dirname "$0")/../.." && pwd) + +OPTIONAL_FLAGS=$(nix-instantiate -I "nixpkgs=$BASE_DIR/tools/nix/pkgs.nix" --eval --strict --raw -E " + (import {}).lib.concatMapStrings + (n: ''--arg \${n} true '') + (builtins.filter + (n: builtins.match ''with[A-Z].+'' n != null) + (builtins.attrNames (builtins.functionArgs (import $BASE_DIR/shell.nix)))) + " +) + +DRV=$( + cd "$BASE_DIR" + # shellcheck disable=SC2086 + nix-instantiate -I "nixpkgs=./tools/nix/pkgs.nix" shell.nix \ + $OPTIONAL_FLAGS \ + --arg sharedLibDeps '{ + # Using an empty set as some build dependencies are required only in the absence of shared deps (e.g. Cargo). + # We pass the shared deps as devTools below so they are still accounted for. + }' \ + --arg pkcs11 'import ./tools/nix/pkcs11.nix { + # Passing an import call rather than "true" to workaround sharedLibDeps being empty. + }' \ + --arg devTools ' + let + pkgs = import { }; + sharedLibDepsFn = import ./tools/nix/sharedLibDeps.nix; + in + (import ./tools/nix/devTools.nix { }) + ++ pkgs.lib.flatten ( + with (pkgs.callPackage ./tools/nix/v8.nix { }); + [ + # We do not want to build V8 here, but still want to list its requisites. + buildInputs + nativeBuildInputs + propagatedBuildInputs + propagatedNativeBuildInputs + (pkgs.callPackage ./tools/nix/non-v8-deps-mock.nix { }) + ] + ) + ++ builtins.attrValues ( + { + # Additional packages we are using across the codebase + inherit (pkgs) nixfmt-tree sccache; + } + // import ./tools/nix/openssl-matrix.nix { } + // sharedLibDepsFn ( + pkgs.lib.filterAttrs (n: v: builtins.match "with[A-Z].+" n != null) ( + builtins.functionArgs sharedLibDepsFn + ) + ) + )' +) +REFS=$(nix-store --query --references "$DRV") +STORE_PATHS=$(echo "$REFS" | xargs nix-store --realise) +REQUISITES=$(echo "$STORE_PATHS" | xargs nix-store --query --requisites) + +echo "$REQUISITES" | sort -k1.45 | uniq