From da1641ac89500a42942e32257242c06aa562f1b2 Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Wed, 19 Aug 2026 17:58:24 +0200 Subject: [PATCH 1/8] tools: improve nix-changes coverage Signed-off-by: Antoine du Hamel --- .github/workflows/nix-changes.yml | 37 ++++------------ tools/nix/list-requesites.sh | 70 +++++++++++++++++++++++++++++++ 2 files changed, 77 insertions(+), 30 deletions(-) create mode 100755 tools/nix/list-requesites.sh diff --git a/.github/workflows/nix-changes.yml b/.github/workflows/nix-changes.yml index 84c4337bab19..9000d7ea556d 100644 --- a/.github/workflows/nix-changes.yml +++ b/.github/workflows/nix-changes.yml @@ -11,10 +11,12 @@ on: - v[0-9]+.x paths: - '**.nix' + - tools/nix/list-requesites.sh - .github/workflows/nix-changes.yml pull_request: paths: - '**.nix' + - tools/nix/list-requesites.sh - .github/workflows/nix-changes.yml types: [opened, synchronize, reopened, ready_for_review] @@ -47,7 +49,9 @@ jobs: with: fetch-depth: 2 persist-credentials: false - sparse-checkout: '*.nix' + sparse-checkout: | + ./tools/nix/list-requesites.sh + '*.nix' sparse-checkout-cone-mode: false - uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0 @@ -60,39 +64,12 @@ jobs: name: nodejs - name: Compute requisites after change - shell: bash # See https://docs.github.com/en/actions/writing-workflows/workflow-syntax-for-github-actions#exit-codes-and-error-action-preference, we want the pipefail option. - run: | - nix-store --query --references "$( - nix-instantiate -I "nixpkgs=./tools/nix/pkgs.nix" shell.nix \ - --arg devTools " - (import ./tools/nix/devTools.nix {}) - ++ builtins.attrValues ( - { inherit (import {}) nixfmt-tree sccache; } - // import ./tools/nix/openssl-matrix.nix {} - // import ./tools/nix/pkcs11.nix {} - )")" \ - | xargs nix-store --realise \ - | xargs nix-store --query --requisites \ - | sort -k1.45 \ - > requisites-${{ matrix.system }}-after.list + run: ./tools/nix/list-requesites.sh > requisites-${{ matrix.system }}-after.list - name: Compute requisites before change - shell: bash # See https://docs.github.com/en/actions/writing-workflows/workflow-syntax-for-github-actions#exit-codes-and-error-action-preference, we want the pipefail option. run: | git reset HEAD^ --hard - nix-store --query --references "$( - nix-instantiate -I "nixpkgs=./tools/nix/pkgs.nix" shell.nix \ - --arg devTools " - (import ./tools/nix/devTools.nix {}) - ++ builtins.attrValues ( - { inherit (import {}) nixfmt-tree sccache; } - // import ./tools/nix/openssl-matrix.nix {} - // import ./tools/nix/pkcs11.nix {} - )")" \ - | xargs nix-store --realise \ - | xargs nix-store --query --requisites \ - | sort -k1.45 \ - > requisites-${{ matrix.system }}-before.list + ./tools/nix/list-requesites.sh > requisites-${{ matrix.system }}-before.list - name: Output diff run: | diff --git a/tools/nix/list-requesites.sh b/tools/nix/list-requesites.sh new file mode 100755 index 000000000000..41d260e6334c --- /dev/null +++ b/tools/nix/list-requesites.sh @@ -0,0 +1,70 @@ +#!/bin/sh + +set -ex + +OPTIONAL_FLAGS=$(nix-instantiate \ + --eval --strict --json -E ' + builtins.filter + (n: builtins.match "with[A-Z].+" n != null) + (builtins.attrNames (builtins.functionArgs (import ./shell.nix))) + ' | jq -r 'map("--arg \(.) true") | join(" ")') + +PIPEFAIL="$(mktemp)" + +cleanup () { + EXIT_CODE=$? + rm "$PIPEFAIL" + exit $EXIT_CODE +} + +trap cleanup INT TERM EXIT + +{ + # shellcheck disable=SC2086 + nix-instantiate -I "nixpkgs=./tools/nix/pkgs.nix" shell.nix \ + $OPTIONAL_FLAGS \ + --arg sharedLibDeps '{ + # Using an empty set as some build dependencies are required only in the absence of shared deps (e.g. Cargo). + # We pass the shared deps as devTools below so they are still accounted for. + }' \ + --arg pkcs11 'import ./tools/nix/pkcs11.nix { + # Passing an import call rather than "true" to workaround sharedLibDeps being empty. + }' \ + --arg devTools ' + let + pkgs = import { }; + sharedLibDepsFn = import ./tools/nix/sharedLibDeps.nix; + in + (import ./tools/nix/devTools.nix { }) + ++ pkgs.lib.flatten ( + with (pkgs.callPackage ./tools/nix/v8.nix { }); + [ + # We do not want to build V8 here, but still want to list its requisites. + buildInputs + nativeBuildInputs + propagatedBuildInputs + propagatedNativeBuildInputs + (pkgs.callPackage ./tools/nix/non-v8-deps-mock.nix { }) + ] + ) + ++ builtins.attrValues ( + { + # Additional packages we are using across the codebase + inherit (pkgs) nixfmt-tree sccache; + } + // import ./tools/nix/openssl-matrix.nix { } + // sharedLibDepsFn ( + pkgs.lib.filterAttrs (n: v: builtins.match "with[A-Z].+" n != null) ( + builtins.functionArgs sharedLibDepsFn + ) + ) + )' || echo > "$PIPEFAIL" +} | { + xargs nix-store --query --references || echo > "$PIPEFAIL" +} | { + xargs nix-store --realise || echo > "$PIPEFAIL" +} | { + xargs nix-store --query --requisites || echo > "$PIPEFAIL" +} | { + sort -k1.45 || echo > "$PIPEFAIL" +} && [ ! -s "$PIPEFAIL" ] From 000c3b9ca1a1f975ebd9b3b73998bc1b14d90a65 Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Wed, 19 Aug 2026 18:30:26 +0200 Subject: [PATCH 2/8] fixup! tools: improve nix-changes coverage --- .github/workflows/nix-changes.yml | 12 +++++++----- tools/nix/{list-requesites.sh => list-requisites.sh} | 0 2 files changed, 7 insertions(+), 5 deletions(-) rename tools/nix/{list-requesites.sh => list-requisites.sh} (100%) diff --git a/.github/workflows/nix-changes.yml b/.github/workflows/nix-changes.yml index 9000d7ea556d..a17be0ee511a 100644 --- a/.github/workflows/nix-changes.yml +++ b/.github/workflows/nix-changes.yml @@ -11,12 +11,12 @@ on: - v[0-9]+.x paths: - '**.nix' - - tools/nix/list-requesites.sh + - tools/nix/list-requisites.sh - .github/workflows/nix-changes.yml pull_request: paths: - '**.nix' - - tools/nix/list-requesites.sh + - tools/nix/list-requisites.sh - .github/workflows/nix-changes.yml types: [opened, synchronize, reopened, ready_for_review] @@ -50,7 +50,7 @@ jobs: fetch-depth: 2 persist-credentials: false sparse-checkout: | - ./tools/nix/list-requesites.sh + ./tools/nix/list-requisites.sh '*.nix' sparse-checkout-cone-mode: false @@ -64,12 +64,14 @@ jobs: name: nodejs - name: Compute requisites after change - run: ./tools/nix/list-requesites.sh > requisites-${{ matrix.system }}-after.list + run: ./tools/nix/list-requisites.sh > requisites-${{ matrix.system }}-after.list - name: Compute requisites before change run: | git reset HEAD^ --hard - ./tools/nix/list-requesites.sh > requisites-${{ matrix.system }}-before.list + # TODO(aduh95): remove this once list-requisites.sh has reached `main` + [ -f tools/nix/list-requisites.sh ] || git checkout FETCH_HEAD -- tools/nix/list-requisites.sh + ./tools/nix/list-requisites.sh > requisites-${{ matrix.system }}-before.list - name: Output diff run: | diff --git a/tools/nix/list-requesites.sh b/tools/nix/list-requisites.sh similarity index 100% rename from tools/nix/list-requesites.sh rename to tools/nix/list-requisites.sh From 2d7e6fc9782f284010415d94cb88c964ec7d31f9 Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Wed, 19 Aug 2026 18:32:52 +0200 Subject: [PATCH 3/8] fixup! tools: improve nix-changes coverage --- .github/workflows/nix-changes.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.github/workflows/nix-changes.yml b/.github/workflows/nix-changes.yml index a17be0ee511a..15a8b56daa53 100644 --- a/.github/workflows/nix-changes.yml +++ b/.github/workflows/nix-changes.yml @@ -54,6 +54,8 @@ jobs: '*.nix' sparse-checkout-cone-mode: false + - run: ls; ls tools/nix + - uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0 with: extra_nix_config: sandbox = true From 1320a131bc7e638dc92e6142cb2e01caf15a79b3 Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Wed, 19 Aug 2026 18:34:14 +0200 Subject: [PATCH 4/8] fixup! tools: improve nix-changes coverage --- .github/workflows/nix-changes.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/nix-changes.yml b/.github/workflows/nix-changes.yml index 15a8b56daa53..c3ffac4808d6 100644 --- a/.github/workflows/nix-changes.yml +++ b/.github/workflows/nix-changes.yml @@ -50,7 +50,7 @@ jobs: fetch-depth: 2 persist-credentials: false sparse-checkout: | - ./tools/nix/list-requisites.sh + tools/nix/list-requisites.sh '*.nix' sparse-checkout-cone-mode: false From 72c94769d0180bea50ca58993237bda8c5e56cd7 Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Wed, 19 Aug 2026 18:35:41 +0200 Subject: [PATCH 5/8] fixup! tools: improve nix-changes coverage --- .github/workflows/nix-changes.yml | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/.github/workflows/nix-changes.yml b/.github/workflows/nix-changes.yml index c3ffac4808d6..545d2ccc8d1f 100644 --- a/.github/workflows/nix-changes.yml +++ b/.github/workflows/nix-changes.yml @@ -50,12 +50,10 @@ jobs: fetch-depth: 2 persist-credentials: false sparse-checkout: | + *.nix tools/nix/list-requisites.sh - '*.nix' sparse-checkout-cone-mode: false - - run: ls; ls tools/nix - - uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0 with: extra_nix_config: sandbox = true From fa9a024744ebe33502a34e167c291e73af826442 Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Wed, 19 Aug 2026 18:42:59 +0200 Subject: [PATCH 6/8] fixup! tools: improve nix-changes coverage --- .github/workflows/build-tarball.yml | 2 ++ .github/workflows/coverage-windows.yml | 2 ++ .github/workflows/test-linux.yml | 2 ++ .github/workflows/test-macos.yml | 2 ++ .github/workflows/test-shared.yml | 4 ++-- 5 files changed, 10 insertions(+), 2 deletions(-) diff --git a/.github/workflows/build-tarball.yml b/.github/workflows/build-tarball.yml index ab0698e11b74..248e64bab776 100644 --- a/.github/workflows/build-tarball.yml +++ b/.github/workflows/build-tarball.yml @@ -23,6 +23,7 @@ on: - tools/eslint-rules/** - tools/eslint/** - tools/lint-md/** + - tools/nix/** - typings/** - vcbuild.bat - .** @@ -52,6 +53,7 @@ on: - tools/eslint-rules/** - tools/eslint/** - tools/lint-md/** + - tools/nix/** - typings/** - vcbuild.bat - .** diff --git a/.github/workflows/coverage-windows.yml b/.github/workflows/coverage-windows.yml index 59329670e6c2..d0236cd7d609 100644 --- a/.github/workflows/coverage-windows.yml +++ b/.github/workflows/coverage-windows.yml @@ -23,6 +23,7 @@ on: - tools/eslint-rules/** - tools/eslint/** - tools/lint-md/** + - tools/nix/** - typings/** - .** - '!.github/workflows/coverage-windows.yml' @@ -49,6 +50,7 @@ on: - tools/eslint-rules/** - tools/eslint/** - tools/lint-md/** + - tools/nix/** - typings/** - .** - '!.github/workflows/coverage-windows.yml' diff --git a/.github/workflows/test-linux.yml b/.github/workflows/test-linux.yml index 40762503f685..7681a176139d 100644 --- a/.github/workflows/test-linux.yml +++ b/.github/workflows/test-linux.yml @@ -9,6 +9,7 @@ on: - tools/actions/** - tools/clang-format/** - tools/dep_updaters/** + - tools/nix/** - test/internet/** - '**.nix' - .github/** @@ -27,6 +28,7 @@ on: - tools/actions/** - tools/clang-format/** - tools/dep_updaters/** + - tools/nix/** - test/internet/** - '**.nix' - .github/** diff --git a/.github/workflows/test-macos.yml b/.github/workflows/test-macos.yml index e87e83505d6d..c53bcde2851c 100644 --- a/.github/workflows/test-macos.yml +++ b/.github/workflows/test-macos.yml @@ -23,6 +23,7 @@ on: - tools/eslint-rules/** - tools/eslint/** - tools/lint-md/** + - tools/nix/** - typings/** - vcbuild.bat - .** @@ -53,6 +54,7 @@ on: - tools/eslint-rules/** - tools/eslint/** - tools/lint-md/** + - tools/nix/** - typings/** - vcbuild.bat - .** diff --git a/.github/workflows/test-shared.yml b/.github/workflows/test-shared.yml index 284372317359..c18b41edab54 100644 --- a/.github/workflows/test-shared.yml +++ b/.github/workflows/test-shared.yml @@ -41,7 +41,7 @@ on: - test/internet/** - tools/** - '!tools/gyp/**' - - '!tools/nix/**' + - '!tools/nix/**.nix' - '!tools/v8/**' - '!tools/v8_gypfiles/**' - typings/** @@ -93,7 +93,7 @@ on: - test/internet/** - tools/** - '!tools/gyp/**' - - '!tools/nix/**' + - '!tools/nix/**.nix' - '!tools/v8/**' - '!tools/v8_gypfiles/**' - typings/** From 2029e3cc34d69574538f506883ee0de66948dd62 Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Thu, 20 Aug 2026 01:10:27 +0200 Subject: [PATCH 7/8] fixup! tools: improve nix-changes coverage --- .github/workflows/nix-changes.yml | 8 ++++---- .github/workflows/test-shared.yml | 6 ++++-- tools/nix/list-requisites.sh | 29 ++++++++--------------------- 3 files changed, 16 insertions(+), 27 deletions(-) diff --git a/.github/workflows/nix-changes.yml b/.github/workflows/nix-changes.yml index 545d2ccc8d1f..ed25798152e3 100644 --- a/.github/workflows/nix-changes.yml +++ b/.github/workflows/nix-changes.yml @@ -11,12 +11,12 @@ on: - v[0-9]+.x paths: - '**.nix' - - tools/nix/list-requisites.sh + - tools/nix/** - .github/workflows/nix-changes.yml pull_request: paths: - '**.nix' - - tools/nix/list-requisites.sh + - tools/nix/** - .github/workflows/nix-changes.yml types: [opened, synchronize, reopened, ready_for_review] @@ -50,8 +50,8 @@ jobs: fetch-depth: 2 persist-credentials: false sparse-checkout: | - *.nix - tools/nix/list-requisites.sh + shell.nix + tools/nix/ sparse-checkout-cone-mode: false - uses: cachix/install-nix-action@630ae543ea3a38a9a4166f03376c02c50f408342 # v31.11.0 diff --git a/.github/workflows/test-shared.yml b/.github/workflows/test-shared.yml index c18b41edab54..8a04fe4d74fc 100644 --- a/.github/workflows/test-shared.yml +++ b/.github/workflows/test-shared.yml @@ -41,9 +41,10 @@ on: - test/internet/** - tools/** - '!tools/gyp/**' - - '!tools/nix/**.nix' + - '!tools/nix/**' - '!tools/v8/**' - '!tools/v8_gypfiles/**' + - tools/nix/list-requisites.sh - typings/** - vcbuild.bat - .** @@ -93,9 +94,10 @@ on: - test/internet/** - tools/** - '!tools/gyp/**' - - '!tools/nix/**.nix' + - '!tools/nix/**' - '!tools/v8/**' - '!tools/v8_gypfiles/**' + - tools/nix/list-requisites.sh - typings/** - vcbuild.bat - .** diff --git a/tools/nix/list-requisites.sh b/tools/nix/list-requisites.sh index 41d260e6334c..c54002d2448a 100755 --- a/tools/nix/list-requisites.sh +++ b/tools/nix/list-requisites.sh @@ -9,17 +9,7 @@ OPTIONAL_FLAGS=$(nix-instantiate \ (builtins.attrNames (builtins.functionArgs (import ./shell.nix))) ' | jq -r 'map("--arg \(.) true") | join(" ")') -PIPEFAIL="$(mktemp)" - -cleanup () { - EXIT_CODE=$? - rm "$PIPEFAIL" - exit $EXIT_CODE -} - -trap cleanup INT TERM EXIT - -{ +DRV=$( # shellcheck disable=SC2086 nix-instantiate -I "nixpkgs=./tools/nix/pkgs.nix" shell.nix \ $OPTIONAL_FLAGS \ @@ -58,13 +48,10 @@ trap cleanup INT TERM EXIT builtins.functionArgs sharedLibDepsFn ) ) - )' || echo > "$PIPEFAIL" -} | { - xargs nix-store --query --references || echo > "$PIPEFAIL" -} | { - xargs nix-store --realise || echo > "$PIPEFAIL" -} | { - xargs nix-store --query --requisites || echo > "$PIPEFAIL" -} | { - sort -k1.45 || echo > "$PIPEFAIL" -} && [ ! -s "$PIPEFAIL" ] + )' +) +REFS=$(nix-store --query --references "$DRV") +STORE_PATHS=$(echo "$REFS" | xargs nix-store --realise) +REQUISITES=$(echo "$STORE_PATHS" | xargs nix-store --query --requisites) + +echo "$REQUISITES" | sort -k1.45 From d09f06ad86ef2f97d78629dfc03f69d38ebc74af Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Thu, 20 Aug 2026 01:32:55 +0200 Subject: [PATCH 8/8] fixup! tools: improve nix-changes coverage --- tools/nix/list-requisites.sh | 19 ++++++++++++------- 1 file changed, 12 insertions(+), 7 deletions(-) diff --git a/tools/nix/list-requisites.sh b/tools/nix/list-requisites.sh index c54002d2448a..92aa91794326 100755 --- a/tools/nix/list-requisites.sh +++ b/tools/nix/list-requisites.sh @@ -2,14 +2,19 @@ set -ex -OPTIONAL_FLAGS=$(nix-instantiate \ - --eval --strict --json -E ' - builtins.filter - (n: builtins.match "with[A-Z].+" n != null) - (builtins.attrNames (builtins.functionArgs (import ./shell.nix))) - ' | jq -r 'map("--arg \(.) true") | join(" ")') +BASE_DIR=$(cd "$(dirname "$0")/../.." && pwd) + +OPTIONAL_FLAGS=$(nix-instantiate -I "nixpkgs=$BASE_DIR/tools/nix/pkgs.nix" --eval --strict --raw -E " + (import {}).lib.concatMapStrings + (n: ''--arg \${n} true '') + (builtins.filter + (n: builtins.match ''with[A-Z].+'' n != null) + (builtins.attrNames (builtins.functionArgs (import $BASE_DIR/shell.nix)))) + " +) DRV=$( + cd "$BASE_DIR" # shellcheck disable=SC2086 nix-instantiate -I "nixpkgs=./tools/nix/pkgs.nix" shell.nix \ $OPTIONAL_FLAGS \ @@ -54,4 +59,4 @@ REFS=$(nix-store --query --references "$DRV") STORE_PATHS=$(echo "$REFS" | xargs nix-store --realise) REQUISITES=$(echo "$STORE_PATHS" | xargs nix-store --query --requisites) -echo "$REQUISITES" | sort -k1.45 +echo "$REQUISITES" | sort -k1.45 | uniq