Add Nix flake support with source build, prebuilt, and desktop outputs - #5
Conversation
|
Hi @levonk thanks for contributing! |
…D hash Four fixes for the CI failures on PR acryldev#5: 1. Rebase onto upstream/main (was 11 commits behind — caused the "Typecheck, test, and build" failure on a test already fixed on main) 2. Add use-flakehub: false to magic-nix-cache-action (the action defaults to use-flakehub: true, which attempts FlakeHub OIDC auth and breaks CI for orgs without a FlakeHub account — root cause of the "Unable to authenticate to FlakeHub" error) 3. Add timeout-minutes: 20 to the build job (was missing — GitHub's default max is 6h, caused the aarch64-darwin job to hang) 4. Update fetchPnpmDeps hash (stale after rebase picked up new upstream pnpm-lock.yaml changes)
aa04fae to
cfa8b92
Compare
|
Resolved the conflict against current The resolution preserves both branches' development-log entries. I ran the repository suite in the merged worktree: 806 ACRYL tests and 274 Market tests passed. The five refreshed GitHub checks are now running; I will use those as the final merge gate. |
…D hash Four fixes for the CI failures on PR acryldev#5: 1. Rebase onto upstream/main (was 11 commits behind — caused the "Typecheck, test, and build" failure on a test already fixed on main) 2. Add use-flakehub: false to magic-nix-cache-action (the action defaults to use-flakehub: true, which attempts FlakeHub OIDC auth and breaks CI for orgs without a FlakeHub account — root cause of the "Unable to authenticate to FlakeHub" error) 3. Add timeout-minutes: 20 to the build job (was missing — GitHub's default max is 6h, caused the aarch64-darwin job to hang) 4. Update fetchPnpmDeps hash (stale after rebase picked up new upstream pnpm-lock.yaml changes)
19fa777 to
b3309f3
Compare
|
Thanks for the substantial work here - reviewed the flake end to end. This is real packaging engineering: the fetchPnpmDeps v4 usage, the documented nodeLinker override, the ESBUILD_BINARY_PATH substitution, autoPatchelf + musl handling for koffi, SHA-pinned actions with PR guards - all correct. The README.i18n.yaml hash-record update was a nice touch too. Three blockers before merge:
Would love one fully green 4-system run on the branch before merging. Happy to review the follow-up. |
…D hash Four fixes for the CI failures on PR acryldev#5: 1. Rebase onto upstream/main (was 11 commits behind — caused the "Typecheck, test, and build" failure on a test already fixed on main) 2. Add use-flakehub: false to magic-nix-cache-action (the action defaults to use-flakehub: true, which attempts FlakeHub OIDC auth and breaks CI for orgs without a FlakeHub account — root cause of the "Unable to authenticate to FlakeHub" error) 3. Add timeout-minutes: 20 to the build job (was missing — GitHub's default max is 6h, caused the aarch64-darwin job to hang) 4. Update fetchPnpmDeps hash (stale after rebase picked up new upstream pnpm-lock.yaml changes)
b3309f3 to
fe21243
Compare
…D hash Four fixes for the CI failures on PR acryldev#5: 1. Rebase onto upstream/main (was 11 commits behind — caused the "Typecheck, test, and build" failure on a test already fixed on main) 2. Add use-flakehub: false to magic-nix-cache-action (the action defaults to use-flakehub: true, which attempts FlakeHub OIDC auth and breaks CI for orgs without a FlakeHub account — root cause of the "Unable to authenticate to FlakeHub" error) 3. Add timeout-minutes: 20 to the build job (was missing — GitHub's default max is 6h, caused the aarch64-darwin job to hang) 4. Update fetchPnpmDeps hash (stale after rebase picked up new upstream pnpm-lock.yaml changes)
7d21d18 to
e6868a4
Compare
…D hash Four fixes for the CI failures on PR acryldev#5: 1. Rebase onto upstream/main (was 11 commits behind — caused the "Typecheck, test, and build" failure on a test already fixed on main) 2. Add use-flakehub: false to magic-nix-cache-action (the action defaults to use-flakehub: true, which attempts FlakeHub OIDC auth and breaks CI for orgs without a FlakeHub account — root cause of the "Unable to authenticate to FlakeHub" error) 3. Add timeout-minutes: 20 to the build job (was missing — GitHub's default max is 6h, caused the aarch64-darwin job to hang) 4. Update fetchPnpmDeps hash (stale after rebase picked up new upstream pnpm-lock.yaml changes)
e6868a4 to
6cb9194
Compare
…D hash Four fixes for the CI failures on PR acryldev#5: 1. Rebase onto upstream/main (was 11 commits behind — caused the "Typecheck, test, and build" failure on a test already fixed on main) 2. Add use-flakehub: false to magic-nix-cache-action (the action defaults to use-flakehub: true, which attempts FlakeHub OIDC auth and breaks CI for orgs without a FlakeHub account — root cause of the "Unable to authenticate to FlakeHub" error) 3. Add timeout-minutes: 20 to the build job (was missing — GitHub's default max is 6h, caused the aarch64-darwin job to hang) 4. Update fetchPnpmDeps hash (stale after rebase picked up new upstream pnpm-lock.yaml changes)
804a930 to
0ba0402
Compare
…D hash Four fixes for the CI failures on PR acryldev#5: 1. Rebase onto upstream/main (was 11 commits behind — caused the "Typecheck, test, and build" failure on a test already fixed on main) 2. Add use-flakehub: false to magic-nix-cache-action (the action defaults to use-flakehub: true, which attempts FlakeHub OIDC auth and breaks CI for orgs without a FlakeHub account — root cause of the "Unable to authenticate to FlakeHub" error) 3. Add timeout-minutes: 20 to the build job (was missing — GitHub's default max is 6h, caused the aarch64-darwin job to hang) 4. Update fetchPnpmDeps hash (stale after rebase picked up new upstream pnpm-lock.yaml changes)
0ba0402 to
5369acf
Compare
…D hash Four fixes for the CI failures on PR acryldev#5: 1. Rebase onto upstream/main (was 11 commits behind — caused the "Typecheck, test, and build" failure on a test already fixed on main) 2. Add use-flakehub: false to magic-nix-cache-action (the action defaults to use-flakehub: true, which attempts FlakeHub OIDC auth and breaks CI for orgs without a FlakeHub account — root cause of the "Unable to authenticate to FlakeHub" error) 3. Add timeout-minutes: 20 to the build job (was missing — GitHub's default max is 6h, caused the aarch64-darwin job to hang) 4. Update fetchPnpmDeps hash (stale after rebase picked up new upstream pnpm-lock.yaml changes)
5369acf to
47b5c79
Compare
|
@levonk please ensure CI/CD is green |
|
All three blockers addressed — CI is now fully green and the branch is mergeable.
Also re-recorded the bilingual blob hashes for the merged README pair, and refreshed the RFC-0004 i18n record that was stale on main itself. Green run: |
devbox 0.18 ignores the nixpkgs.commit field for regular package-name resolution and hardcodes nixpkgs 26.11, which dropped x86_64-darwin. Work around this by referencing every package as a flake URL pointing at the nixpkgs-26.05-darwin commit (f6107e5) — flake-based references bypass devbox's package index, and nixpkgs.commit controls the shell infrastructure (mkShell). This works on all platforms: x86_64-darwin, aarch64-darwin, and Linux. Generate and commit devbox.lock for reproducible environments.
Use per-package platform scoping: clean package names (nodejs_22, pnpm_11, esbuild, act) for normal platforms (Linux, aarch64-darwin), and flake URL references to nixpkgs-26.05-darwin only for x86_64-darwin. The nixpkgs.commit field is set to the 26.05-darwin pin for the shell infrastructure (mkShell), which devbox 0.18 honors when all active packages on a platform are flake-based. On normal platforms, packages resolve from nixpkgs-unstable via devbox's index — the same behavior as before. On x86_64-darwin, the flake URL references bypass devbox's hardcoded nixpkgs 26.11 (which dropped x86_64-darwin) and pull from 26.05-darwin instead. The lock file records both resolution paths. Linux/aarch64-darwin entries will be populated when a user on that platform runs devbox install.
Replace all github:levonk/acryl references with github:acryldev/acryl in flake.nix (homepage meta), README.md, README.en.md, README.zh.md, and DEVELOPMENT-LOG.md commit links. Update bilingual-docs hash record.
Add packages.<system>.prebuilt — fetches the prebuilt CLI tarball from GitHub releases (v0.1.19). Each tarball bundles its own Node runtime and native addons (node-pty, koffi, sharp), so no from-source build is needed for the prebuilt path. Uses autoPatchelfHook on Linux for glibc linking. The default output remains #acryl (from-source build), following Nix convention. #prebuilt is an optional fast path for users who want the exact release binary. Add CI steps to build and test #prebuilt on all 4 platforms. Update READMEs to document the #prebuilt output.
…D hash Four fixes for the CI failures on PR acryldev#5: 1. Rebase onto upstream/main (was 11 commits behind — caused the "Typecheck, test, and build" failure on a test already fixed on main) 2. Add use-flakehub: false to magic-nix-cache-action (the action defaults to use-flakehub: true, which attempts FlakeHub OIDC auth and breaks CI for orgs without a FlakeHub account — root cause of the "Unable to authenticate to FlakeHub" error) 3. Add timeout-minutes: 20 to the build job (was missing — GitHub's default max is 6h, caused the aarch64-darwin job to hang) 4. Update fetchPnpmDeps hash (stale after rebase picked up new upstream pnpm-lock.yaml changes)
The preConfigure hook checked `if ! grep -q "nodeLinker"` and only inserted `nodeLinker: hoisted` when the key was absent. But pnpm-workspace.yaml already had `nodeLinker: isolated`, so the sed never ran. The isolated linker creates a .pnpm/ virtual store with symlinks that break when copied to the Nix store, leaving node_modules/ with only 3 entries (the workspace packages) and no registry dependencies like @deepseek-ai/dsh-llm. Replace the value when the key exists, instead of only inserting when missing. After this fix, node_modules/ has 648 packages and all four outputs (default, acryl, prebuilt, acryl-desktop) pass smoke tests.
The prebuilt release tarball bundles both glibc-linked and musl-linked native koffi addons (musl_x64/koffi.node alongside linux_x64/koffi.node). autoPatchelfHook was only finding glibc (stdenv.cc.cc.lib), so it failed with "could not satisfy dependency libc.musl-x86_64.so.1" on Linux. Add pkgs.musl to buildInputs so autoPatchelf can patch both variants.
The magic-nix-cache v14 static binary for arm64-darwin fails on the macos-14 runner with: dyld: Symbol not found: __ZNSt13exception_ptr31__from_native_exception_pointerEPv Expected in: /usr/lib/libc++.1.dylib This is a DeterminateSystems binary incompatibility — the binary was built against a newer libc++ than the runner ships. The build itself never starts; the job hangs for 20 minutes then gets cancelled. Make the cache action Linux-only. Darwin builds work without it, just slower (no cache acceleration). The flake and builds are unaffected.
…ntel macOS runners The macos-13 runner can no longer bootstrap Determinate Nix (DeterminateSystems/nix-src#224), so the x86_64-darwin CI job fails before building anything. Keep the derivation in flake.nix for local Intel builders; restore the job via a Rosetta cross-build from macos-14 when feasible.
… runner Nixify skill compliance fixes after rebasing on upstream/main: 1. Update prebuilt version from v0.1.19 to v0.1.36 (latest release). Refresh all three per-platform SRI hashes by prefetching the new release assets. Remove x86_64-darwin from prebuiltAssets because v0.1.36 does not ship a darwin-x64 CLI tarball. 2. Make #prebuilt conditional via optionalAttrs so it is only exposed on platforms with a release asset (x86_64-linux, aarch64-linux, aarch64-darwin). On x86_64-darwin, nix run .#prebuilt correctly errors "package not available" instead of failing with a missing attribute error. 3. Add .github/workflows/nix-release.yml — daily hash automation workflow (scheduled lag-check template, required by nixify Step 16 for prebuilt tarball flakes). Detects when flake.nix lags behind the latest GitHub release, prefetches new SRI hashes, and opens a PR. Uses GITHUB_TOKEN (releases are created with GITHUB_TOKEN via softprops/action-gh-release, so release: published would never fire). 4. Update aarch64-darwin CI runner from macos-14 to macos-26 (nixify Step 16: always use the newest runner).
- Bump the Nix tag-pinning example from v0.1.19 to v0.1.36 in all three READMEs (README.md, README.en.md, README.zh.md). - Note that #prebuilt is available on x86_64-linux, aarch64-linux, and aarch64-darwin only (v0.1.36 does not ship a darwin-x64 CLI tarball). - Re-record the bilingual-docs blob hashes in README.i18n.yaml.
Add a development-log entry for the v0.1.36 prebuilt bump, the new nix-release.yml hash automation workflow, the macos-26 runner update, and the rebase onto upstream/main 0822873. Re-point the two earlier Nix entries (acryl-desktop output and acryl-tui flake support) at their rebased commit hashes.
The rebase onto upstream/main 227c3f9 pulled in a new pnpm-lock.yaml (7869 lines changed) which invalidated the fetchPnpmDeps hash. Updated to sha256-gqs/PgXIBj8+YsH/z/qIPa68XVNO7hu4eDxvShYkyxI= as reported by the aarch64-darwin CI failure.
Main reorganized workspace packages from the root into apps/, runtime/, plugins/, distribution/, and examples/ directories. The flake's build and install phases still referenced the old flat paths (acryl-cli/lib, acryl-control/lib, etc.). - Update all source paths in build and install phases to use the new directory structure (apps/acryl-cli, runtime/acryl-control, plugins/dsh-community-market, apps/acryl-desktop). - Add dsh-community-market to the CLI (#default) build chain — main added a /market command to acryl-cli that imports dsh-community-market, so it must be built before acryl-cli. - Remove acryl-development-canvas from the desktop build chain — the package no longer exists in the workspace. - Split installWorkspacePackage into srcDir (workspace path) and pkgName (node_modules name) since they now differ. Add an extraDirs parameter to copy non-compiled runtime assets (dsh-community-market reads JSON schemas from docs/schemas/ at runtime via readFileSync relative to lib/).
acryl-cli now imports dsh-community-market (added by the /market command), but the CI workflow's 'Build workspace type providers' step only built acryl-control and acryl-harness-runtime. The typecheck step then fails with TS2307 for dsh-community-market. This is a pre-existing issue on main — it was hidden because main's CI fails earlier at the bilingual-docs gate before reaching typecheck.
…staller The job was dropped after the Determinate installer failed on the deprecated macos-13 image. The actual constraint is narrower: Determinate stopped shipping Intel *host* builds in Nov 2025 (DeterminateSystems/nix-src#224), but GitHub still provides Intel runners and upstream Nix installs fine on them. Run the leg on macos-26-intel (the current Intel label, GA Feb 2026) using cachix/install-nix-action with flakes enabled explicitly; other legs keep the Determinate installer.
…ambiguity in findLiveEntry
df933bd to
873a09e
Compare
|
Thank you @levonk! Great contribution — the Nix flake support is solid. I rebased and fixed the CI issues (plugin-lifecycle test and typecheck provider builds). |
Summary
flake.nixwith#acryl(TUI from source, also#default),#prebuilt(prebuilt CLI release tarball, v0.1.36),#acryl-desktop(Electron from source), anddevShells.default#prebuiltis conditionally exposed only on platforms with a release asset (x86_64-linux, aarch64-linux, aarch64-darwin). v0.1.36 does not ship a darwin-x64 CLI tarball, so#prebuiltis not available onx86_64-darwin— use#defaultor#acrylthere.devbox.json+devbox.lockfor reproducible development environments.github/workflows/nix.yml— CI builds all outputs on x86_64-linux, aarch64-linux, aarch64-darwin, and x86_64-darwin usingmacos-26/macos-26-intelrunners.github/workflows/nix-release.yml— daily hash automation that detects whenflake.nixlags behind the latest GitHub release, prefetches new SRI hashes, and opens a PR.gitignorewith/result,/result-*, and.devbox/Platform scope
The project's CI matrix is Linux-only, but the project ships release binaries for all four Nix target systems (x86_64-linux, aarch64-linux, aarch64-darwin, x86_64-darwin). This flake supports all four systems. The
detect-platform-scope.shnixify detection script reportslinux_onlybecause it inspects.github/workflows/CI matrices, but the release assets cover all four platforms. This override is noted here per the nixify skill's requirement.Supported systems
x86_64-linux— source build + prebuiltaarch64-linux— source build + prebuiltaarch64-darwin— source build + prebuiltx86_64-darwin— source build only (vianixpkgs-26.05-darwinlegacy pin; no prebuilt tarball available for this platform)Relationship to nixpkgs
This project is not currently in nixpkgs. If there is interest in adding it, the flake's
#acrylsource build derivation could serve as the basis for a nixpkgs package expression.Test plan
nix flake check --no-buildpasses on all systemsnix build .#acrylsucceeds on all systemsnix build .#acryl-desktopsucceeds on all systemsnix build .#prebuiltsucceeds on x86_64-linux, aarch64-linux, aarch64-darwinnix run .#acryl -- --helpworksnix run .#prebuilt -- --helpworks (where available)nix run .#acryl-desktop -- --helpworks