From 713e04f2e07d5fee0b777990f468026082c075aa Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Thu, 13 Aug 2026 23:08:55 +0200 Subject: [PATCH 1/2] fetchRepoProject: enble strictDeps, enable structuredAttrs --- pkgs/build-support/fetchrepoproject/default.nix | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pkgs/build-support/fetchrepoproject/default.nix b/pkgs/build-support/fetchrepoproject/default.nix index 5f10c7eebf45..55750b4f0b82 100644 --- a/pkgs/build-support/fetchrepoproject/default.nix +++ b/pkgs/build-support/fetchrepoproject/default.nix @@ -80,7 +80,10 @@ lib.fetchers.withNormalizedHash { } ( cacert ]; - GIT_SSL_CAINFO = "${cacert}/etc/ssl/certs/ca-bundle.crt"; + strictDeps = true; + __structuredAttrs = true; + + env.GIT_SSL_CAINFO = "${cacert}/etc/ssl/certs/ca-bundle.crt"; buildCommand = '' # Path must be absolute (e.g. for GnuPG: ~/.repoconfig/gnupg/pubring.kbx) From 3d83b9c80cded46f14ca3a927d4983e335b1b524 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Thu, 1 Oct 2026 15:47:10 +0200 Subject: [PATCH 2/2] fetchRepoProject: do less work at eval time Inherit variables so they are available in the builder and treat the structured arrays as actual arrays on the bash side. This also requires that we don't have empty flags in the flag lists, so use optional instead of optionalString. --- .../fetchrepoproject/default.nix | 31 ++++++++++--------- 1 file changed, 16 insertions(+), 15 deletions(-) diff --git a/pkgs/build-support/fetchrepoproject/default.nix b/pkgs/build-support/fetchrepoproject/default.nix index 55750b4f0b82..9d3005b92078 100644 --- a/pkgs/build-support/fetchrepoproject/default.nix +++ b/pkgs/build-support/fetchrepoproject/default.nix @@ -30,23 +30,22 @@ lib.fetchers.withNormalizedHash { } ( concatMapStringsSep concatStringsSep fetchers - optionalString + optional ; - extraRepoInitFlags = [ - (optionalString (repoRepoURL != "") "--repo-url=${repoRepoURL}") - (optionalString (repoRepoRev != "") "--repo-branch=${repoRepoRev}") - (optionalString (referenceDir != "") "--reference=${referenceDir}") - (optionalString (manifestName != "") "--manifest-name=${manifestName}") - ]; + extraRepoInitFlags = + optional (repoRepoURL != "") "--repo-url=${repoRepoURL}" + ++ optional (repoRepoRev != "") "--repo-branch=${repoRepoRev}" + ++ optional (referenceDir != "") "--reference=${referenceDir}" + ++ optional (manifestName != "") "--manifest-name=${manifestName}"; repoInitFlags = [ "--manifest-url=${manifest}" "--manifest-branch=${rev}" "--depth=1" - (optionalString createMirror "--mirror") - (optionalString useArchive "--archive") ] + ++ optional createMirror "--mirror" + ++ optional useArchive "--archive" ++ extraRepoInitFlags; local_manifests = copyPathsToStore localManifests; @@ -85,6 +84,8 @@ lib.fetchers.withNormalizedHash { } ( env.GIT_SSL_CAINFO = "${cacert}/etc/ssl/certs/ca-bundle.crt"; + inherit repoInitFlags createMirror local_manifests; + buildCommand = '' # Path must be absolute (e.g. for GnuPG: ~/.repoconfig/gnupg/pubring.kbx) export HOME="$(pwd)" @@ -93,23 +94,23 @@ lib.fetchers.withNormalizedHash { } ( cd $out mkdir .repo - ${optionalString (local_manifests != [ ]) '' + if [ "''${#local_manifests[@]}" -gt 0 ]; then mkdir .repo/local_manifests - for local_manifest in ${concatMapStringsSep " " toString local_manifests}; do + for local_manifest in "''${local_manifests[@]}"; do cp $local_manifest .repo/local_manifests/$(stripHash $local_manifest) done - ''} + fi - repo init ${concatStringsSep " " repoInitFlags} + repo init "''${repoInitFlags[@]}" repo sync --jobs=$NIX_BUILD_CORES --current-branch # TODO: The git-index files (and probably the files in .repo as well) have # different contents each time and will therefore change the final hash # (i.e. creating a mirror probably won't work). - ${optionalString (!createMirror) '' + if [ -z "$createMirror" ]; then rm -rf .repo find -type d -name '.git' -prune -exec rm -rf {} + - ''} + fi ''; } )