From 6f216d0e5479b1d77094fa16cb5ef6082859da04 Mon Sep 17 00:00:00 2001 From: Johannes Kirschbauer Date: Tue, 1 Apr 2025 10:27:06 +0200 Subject: [PATCH 1/9] ci/compare: nix stats comparison Displays stats table in the step-summary if there are no added/removed packages (cherry picked from commit 0d584f7c8fe87a8ddd8ce013b8b19b47fc3834aa) --- ci/eval/compare/default.nix | 50 ++++++++++++++++++++++++++++++++++--- ci/eval/default.nix | 2 ++ 2 files changed, 48 insertions(+), 4 deletions(-) diff --git a/ci/eval/compare/default.nix b/ci/eval/compare/default.nix index 9b71c6656914..c6711687ae9c 100644 --- a/ci/eval/compare/default.nix +++ b/ci/eval/compare/default.nix @@ -3,6 +3,7 @@ jq, runCommand, writeText, + python3, ... }: { @@ -123,18 +124,59 @@ let in runCommand "compare" { - nativeBuildInputs = [ jq ]; + nativeBuildInputs = [ + jq + (python3.withPackages ( + ps: with ps; [ + numpy + pandas + scipy + ] + )) + + ]; maintainers = builtins.toJSON maintainers; passAsFile = [ "maintainers" ]; + env = { + BEFORE_DIR = "${beforeResultDir}"; + AFTER_DIR = "${afterResultDir}"; + }; } '' mkdir $out cp ${changed-paths} $out/changed-paths.json - jq -r -f ${./generate-step-summary.jq} < ${changed-paths} > $out/step-summary.md + + if jq -e '(.attrdiff.added | length == 0) and (.attrdiff.removed | length == 0)' "${changed-paths}" > /dev/null; then + # Chunks have changed between revisions + # We cannot generate a performance comparison + { + echo + echo "# Performance comparison" + echo + echo "This compares the performance of this branch against its pull request base branch (e.g., 'master')" + echo + echo "For further help please refer to: [ci/README.md](https://github.com/NixOS/nixpkgs/blob/master/ci/README.md)" + echo + } >> $out/step-summary.md + + python3 ${./cmp-stats.py} >> $out/step-summary.md + + else + # Package chunks are the same in both revisions + # We can use the to generate a performance comparison + { + echo + echo "# Performance Comparison" + echo + echo "Performance stats were skipped because the package sets differ between the two revisions." + echo + echo "For further help please refer to: [ci/README.md](https://github.com/NixOS/nixpkgs/blob/master/ci/README.md)" + } >> $out/step-summary.md + fi + + jq -r -f ${./generate-step-summary.jq} < ${changed-paths} >> $out/step-summary.md cp "$maintainersPath" "$out/maintainers.json" - - # TODO: Compare eval stats '' diff --git a/ci/eval/default.nix b/ci/eval/default.nix index 8537084b1bd5..639e75ec4211 100644 --- a/ci/eval/default.nix +++ b/ci/eval/default.nix @@ -9,6 +9,7 @@ nixVersions, jq, sta, + python3, }: let @@ -270,6 +271,7 @@ let runCommand writeText supportedSystems + python3 ; }; From 2cbf86884a8a57034d50b5c43867795c7e5ce4c0 Mon Sep 17 00:00:00 2001 From: Tristan Ross Date: Wed, 13 Nov 2024 19:35:50 -0800 Subject: [PATCH 2/9] widevine-cdm: move to by-name (cherry picked from commit 447999e1ae0f6e9db4a8694a7105bdec49573e69) --- .../widevine-cdm.nix => by-name/wi/widevine-cdm/package.nix} | 0 pkgs/top-level/all-packages.nix | 2 -- 2 files changed, 2 deletions(-) rename pkgs/{applications/networking/browsers/misc/widevine-cdm.nix => by-name/wi/widevine-cdm/package.nix} (100%) diff --git a/pkgs/applications/networking/browsers/misc/widevine-cdm.nix b/pkgs/by-name/wi/widevine-cdm/package.nix similarity index 100% rename from pkgs/applications/networking/browsers/misc/widevine-cdm.nix rename to pkgs/by-name/wi/widevine-cdm/package.nix diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 21bd77e5e152..f5357cbe12eb 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -21158,8 +21158,6 @@ with pkgs; aitrack = libsForQt5.callPackage ../applications/misc/aitrack { }; - widevine-cdm = callPackage ../applications/networking/browsers/misc/widevine-cdm.nix { }; - tidal-dl = python3Packages.callPackage ../tools/audio/tidal-dl { }; tubekit = callPackage ../applications/networking/cluster/tubekit/wrapper.nix { }; From 74c3bb1f9b3e74b6c56e61f338ac8d452a9c4cdd Mon Sep 17 00:00:00 2001 From: Tristan Ross Date: Wed, 13 Nov 2024 19:49:14 -0800 Subject: [PATCH 3/9] widevine-cdm: add aarch64-linux (cherry picked from commit 4910bf15877f16aa3db7140c748920ee63aa3ad6) --- .../by-name/wi/widevine-cdm/aarch64-linux.nix | 49 +++++++++++++++++++ pkgs/by-name/wi/widevine-cdm/meta.nix | 12 +++++ pkgs/by-name/wi/widevine-cdm/package.nix | 36 +------------- pkgs/by-name/wi/widevine-cdm/x86_64-linux.nix | 28 +++++++++++ 4 files changed, 91 insertions(+), 34 deletions(-) create mode 100644 pkgs/by-name/wi/widevine-cdm/aarch64-linux.nix create mode 100644 pkgs/by-name/wi/widevine-cdm/meta.nix create mode 100644 pkgs/by-name/wi/widevine-cdm/x86_64-linux.nix diff --git a/pkgs/by-name/wi/widevine-cdm/aarch64-linux.nix b/pkgs/by-name/wi/widevine-cdm/aarch64-linux.nix new file mode 100644 index 000000000000..f8ce102acdda --- /dev/null +++ b/pkgs/by-name/wi/widevine-cdm/aarch64-linux.nix @@ -0,0 +1,49 @@ +{ + lib, + stdenv, + fetchurl, + fetchFromGitHub, + squashfsTools, + python3, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "widevine-cdm"; + version = "${finalAttrs.lacrosVersion}-${builtins.substring 0 7 finalAttrs.widevineInstaller.rev}"; + lacrosVersion = "120.0.6098.0"; + + widevineInstaller = fetchFromGitHub { + owner = "AsahiLinux"; + repo = "widevine-installer"; + rev = "7a3928fe1342fb07d96f61c2b094e3287588958b"; + sha256 = "sha256-XI1y4pVNpXS+jqFs0KyVMrxcULOJ5rADsgvwfLF6e0Y="; + }; + + src = fetchurl { + url = "https://commondatastorage.googleapis.com/chromeos-localmirror/distfiles/chromeos-lacros-arm64-squash-zstd-${finalAttrs.lacrosVersion}"; + hash = "sha256-OKV8w5da9oZ1oSGbADVPCIkP9Y0MVLaQ3PXS3ZBLFXY="; + }; + + nativeBuildInputs = [ + squashfsTools + python3 + ]; + + unpackPhase = '' + unsquashfs -q $src 'WidevineCdm/*' + python3 $widevineInstaller/widevine_fixup.py squashfs-root/WidevineCdm/_platform_specific/cros_arm64/libwidevinecdm.so libwidevinecdm.so + cp squashfs-root/WidevineCdm/manifest.json . + cp squashfs-root/WidevineCdm/LICENSE LICENSE.txt + ''; + + # Accoring to widevine-installer: "Hack because Chromium hardcodes a check for this right now..." + postInstall = '' + install -vD manifest.json "$out/share/google/chrome/WidevineCdm/manifest.json" + install -vD LICENSE.txt "$out/share/google/chrome/WidevineCdm/License.txt" + install -vD libwidevinecdm.so "$out/share/google/chrome/WidevineCdm/_platform_specific/linux_arm64/libwidevinecdm.so" + mkdir -p "$out/share/google/chrome/WidevineCdm/_platform_specific/linux_x64" + touch "$out/share/google/chrome/WidevineCdm/_platform_specific/linux_x64/libwidevinecdm.so" + ''; + + meta = import ./meta.nix lib; +}) diff --git a/pkgs/by-name/wi/widevine-cdm/meta.nix b/pkgs/by-name/wi/widevine-cdm/meta.nix new file mode 100644 index 000000000000..0361d3ee1da5 --- /dev/null +++ b/pkgs/by-name/wi/widevine-cdm/meta.nix @@ -0,0 +1,12 @@ +lib: { + description = "Widevine CDM"; + homepage = "https://www.widevine.com"; + sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ]; + license = lib.licenses.unfree; + maintainers = with lib.maintainers; [ jlamur ]; + platforms = lib.map (lib.removeSuffix ".nix") ( + lib.filter (name: name != "meta.nix" && name != "package.nix") ( + builtins.attrNames (builtins.readDir ./.) + ) + ); +} diff --git a/pkgs/by-name/wi/widevine-cdm/package.nix b/pkgs/by-name/wi/widevine-cdm/package.nix index a5e7bc2f1b40..f4e0d12fbe49 100644 --- a/pkgs/by-name/wi/widevine-cdm/package.nix +++ b/pkgs/by-name/wi/widevine-cdm/package.nix @@ -1,35 +1,3 @@ -{ - lib, - stdenv, - fetchzip, -}: +{ stdenv, callPackage }: -stdenv.mkDerivation rec { - pname = "widevine-cdm"; - version = "4.10.2830.0"; - - src = fetchzip { - url = "https://dl.google.com/widevine-cdm/${version}-linux-x64.zip"; - hash = "sha256-XDnsan1ulnIK87Owedb2s9XWLzk1K2viGGQe9LN/kcE="; - stripRoot = false; - }; - - installPhase = '' - runHook preInstall - - install -vD manifest.json $out/share/google/chrome/WidevineCdm/manifest.json - install -vD LICENSE.txt $out/share/google/chrome/WidevineCdm/LICENSE.txt - install -vD libwidevinecdm.so $out/share/google/chrome/WidevineCdm/_platform_specific/linux_x64/libwidevinecdm.so - - runHook postInstall - ''; - - meta = with lib; { - description = "Widevine CDM"; - homepage = "https://www.widevine.com"; - sourceProvenance = with sourceTypes; [ binaryNativeCode ]; - license = licenses.unfree; - maintainers = with maintainers; [ jlamur ]; - platforms = [ "x86_64-linux" ]; - }; -} +callPackage (./. + "/${stdenv.hostPlatform.system}.nix") { inherit stdenv; } diff --git a/pkgs/by-name/wi/widevine-cdm/x86_64-linux.nix b/pkgs/by-name/wi/widevine-cdm/x86_64-linux.nix new file mode 100644 index 000000000000..07432c73527f --- /dev/null +++ b/pkgs/by-name/wi/widevine-cdm/x86_64-linux.nix @@ -0,0 +1,28 @@ +{ + lib, + stdenv, + fetchzip, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "widevine-cdm"; + version = "4.10.2830.0"; + + src = fetchzip { + url = "https://dl.google.com/widevine-cdm/${finalAttrs.version}-linux-x64.zip"; + hash = "sha256-XDnsan1ulnIK87Owedb2s9XWLzk1K2viGGQe9LN/kcE="; + stripRoot = false; + }; + + installPhase = '' + runHook preInstall + + install -vD manifest.json $out/share/google/chrome/WidevineCdm/manifest.json + install -vD LICENSE.txt $out/share/google/chrome/WidevineCdm/LICENSE.txt + install -vD libwidevinecdm.so $out/share/google/chrome/WidevineCdm/_platform_specific/linux_x64/libwidevinecdm.so + + runHook postInstall + ''; + + meta = import ./meta.nix lib; +}) From a3c295824a4412eef7ee2fe22ef3d78384ea0969 Mon Sep 17 00:00:00 2001 From: Tristan Ross Date: Fri, 14 Feb 2025 12:55:22 -0800 Subject: [PATCH 4/9] widevine-cdm: fix eval outside unsupported platforms (cherry picked from commit db9bc910a059df8f7effbf1a59e4124c70d1daed) --- pkgs/by-name/wi/widevine-cdm/package.nix | 14 ++++++++++++-- 1 file changed, 12 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/wi/widevine-cdm/package.nix b/pkgs/by-name/wi/widevine-cdm/package.nix index f4e0d12fbe49..bae718940d20 100644 --- a/pkgs/by-name/wi/widevine-cdm/package.nix +++ b/pkgs/by-name/wi/widevine-cdm/package.nix @@ -1,3 +1,13 @@ -{ stdenv, callPackage }: +{ + lib, + stdenv, + callPackage, +}: -callPackage (./. + "/${stdenv.hostPlatform.system}.nix") { inherit stdenv; } +let + targets = lib.genAttrs [ + "aarch64-linux" + "x86_64-linux" + ] (name: ./. + "/${name}.nix"); +in +callPackage (targets."${stdenv.hostPlatform.system}" or targets.x86_64-linux) { inherit stdenv; } From 1e4455556bbbe3532e230d7769be576237a77e26 Mon Sep 17 00:00:00 2001 From: fmbearmf <77757734+fmbearmf@users.noreply.github.com> Date: Tue, 6 May 2025 22:25:49 -0700 Subject: [PATCH 5/9] widevine-cdm: 4.10.2830.0 -> 4.10.2891.0 (cherry picked from commit 5040abe52791fc093448415bf486ce353eb61a95) --- pkgs/by-name/wi/widevine-cdm/x86_64-linux.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/wi/widevine-cdm/x86_64-linux.nix b/pkgs/by-name/wi/widevine-cdm/x86_64-linux.nix index 07432c73527f..00c1b625c32d 100644 --- a/pkgs/by-name/wi/widevine-cdm/x86_64-linux.nix +++ b/pkgs/by-name/wi/widevine-cdm/x86_64-linux.nix @@ -6,11 +6,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "widevine-cdm"; - version = "4.10.2830.0"; + version = "4.10.2891.0"; src = fetchzip { url = "https://dl.google.com/widevine-cdm/${finalAttrs.version}-linux-x64.zip"; - hash = "sha256-XDnsan1ulnIK87Owedb2s9XWLzk1K2viGGQe9LN/kcE="; + hash = "sha256-ZO6FmqJUnB9VEJ7caJt58ym8eB3/fDATri3iOWCULRI="; stripRoot = false; }; From a89ab840508514ebe7285328ccd57c793406eeb8 Mon Sep 17 00:00:00 2001 From: Wolfgang Walther Date: Fri, 9 May 2025 20:56:58 +0200 Subject: [PATCH 6/9] workflows/editorconfig: drop and move to treefmt We already have treefmt running for nixfmt, so it's easy to just add another formatter to it. This gives a much better UX, because all formatting errors are reported through the same channel. It also saves us one CI job, which takes most of the time to just set up the machine, clone the repo and download Nix - while doing a minimum of actual work. Total execution time for treefmt is ~10% slower: - 38s only nixfmt - 43s nixfmt + editorconfig-checker (cherry picked from commit ba4fe10465e752d701e44bb8c5a8fc670b3845a1) --- ...{check-nix-format.yml => check-format.yml} | 11 ++-- .github/workflows/editorconfig-v2.yml | 52 ------------------- ci/OWNERS | 2 +- ci/default.nix | 7 +++ 4 files changed, 12 insertions(+), 60 deletions(-) rename .github/workflows/{check-nix-format.yml => check-format.yml} (80%) delete mode 100644 .github/workflows/editorconfig-v2.yml diff --git a/.github/workflows/check-nix-format.yml b/.github/workflows/check-format.yml similarity index 80% rename from .github/workflows/check-nix-format.yml rename to .github/workflows/check-format.yml index 8c35196e4944..ca3da602575b 100644 --- a/.github/workflows/check-nix-format.yml +++ b/.github/workflows/check-format.yml @@ -1,7 +1,4 @@ -# NOTE: Formatting with the RFC-style nixfmt command is not yet stable. -# See https://github.com/NixOS/rfcs/pull/166. - -name: Check that Nix files are formatted +name: Check that files are formatted on: pull_request_target: @@ -14,7 +11,7 @@ jobs: uses: ./.github/workflows/get-merge-commit.yml nixos: - name: nixfmt-check + name: fmt-check runs-on: ubuntu-24.04 needs: get-merge-commit if: needs.get-merge-commit.outputs.mergedSha @@ -27,13 +24,13 @@ jobs: with: extra_nix_config: sandbox = true - - name: Check that Nix files are formatted + - name: Check that files are formatted run: | # Note that it's fine to run this on untrusted code because: # - There's no secrets accessible here # - The build is sandboxed if ! nix-build ci -A fmt.check; then - echo "Some Nix files are not properly formatted" + echo "Some files are not properly formatted" echo "Please format them by going to the Nixpkgs root directory and running one of:" echo " nix-shell --run treefmt" echo " nix develop --command treefmt" diff --git a/.github/workflows/editorconfig-v2.yml b/.github/workflows/editorconfig-v2.yml deleted file mode 100644 index 68d780f2190f..000000000000 --- a/.github/workflows/editorconfig-v2.yml +++ /dev/null @@ -1,52 +0,0 @@ -name: "Checking EditorConfig v2" - -on: - pull_request_target: - -permissions: {} - -jobs: - get-merge-commit: - uses: ./.github/workflows/get-merge-commit.yml - - tests: - name: editorconfig-check - runs-on: ubuntu-24.04 - needs: get-merge-commit - if: "needs.get-merge-commit.outputs.mergedSha && !contains(github.event.pull_request.title, '[skip treewide]')" - steps: - - name: Get list of changed files from PR - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - run: | - gh api \ - repos/${{ github.repository }}/pulls/${{ github.event.number }}/files --paginate \ - | jq '.[] | select(.status != "removed") | .filename' \ - > "$HOME/changed_files" - - - name: print list of changed files - run: | - cat "$HOME/changed_files" - - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - with: - ref: ${{ needs.get-merge-commit.outputs.mergedSha }} - - - name: Get Nixpkgs revision for editorconfig-checker - run: | - # Pin to a commit from nixpkgs-unstable to avoid building from e.g. staging. - # This should not be a URL, because it would allow PRs to run arbitrary code in CI! - rev=$(jq -r .rev ci/pinned-nixpkgs.json) - echo "url=https://github.com/NixOS/nixpkgs/archive/$rev.tar.gz" >> "$GITHUB_ENV" - - - uses: cachix/install-nix-action@526118121621777ccd86f79b04685a9319637641 # v31 - with: - nix_path: nixpkgs=${{ env.url }} - - - name: Checking EditorConfig - run: | - < "$HOME/changed_files" nix-shell -p editorconfig-checker --run 'xargs -r editorconfig-checker -disable-indent-size' - - - if: ${{ failure() }} - run: | - echo "::error :: Hey! It looks like your changes don't follow our editorconfig settings. Read https://editorconfig.org/#download to configure your editor so you never see this error again." diff --git a/ci/OWNERS b/ci/OWNERS index 5dbe009276a1..5dcc5941eab5 100644 --- a/ci/OWNERS +++ b/ci/OWNERS @@ -15,7 +15,7 @@ # CI /.github/workflows @NixOS/Security @Mic92 @zowoq @infinisil -/.github/workflows/check-nix-format.yml @infinisil +/.github/workflows/check-format.yml @infinisil /.github/workflows/nixpkgs-vet.yml @infinisil @philiptaron /.github/workflows/codeowners-v2.yml @infinisil /ci @infinisil @philiptaron @NixOS/Security diff --git a/ci/default.nix b/ci/default.nix index 67f59d61bfd4..59fb1b48574c 100644 --- a/ci/default.nix +++ b/ci/default.nix @@ -48,6 +48,13 @@ let # the default formatter for Nix code. # See https://github.com/NixOS/nixfmt programs.nixfmt.enable = true; + + settings.formatter.editorconfig-checker = { + command = "${pkgs.lib.getExe pkgs.editorconfig-checker}"; + options = [ "-disable-indent-size" ]; + includes = [ "*" ]; + priority = 1; + }; }; fs = pkgs.lib.fileset; nixFilesSrc = fs.toSource { From 6591df26df5d1a1c1ef17a2c7938cfef07e0c850 Mon Sep 17 00:00:00 2001 From: Wolfgang Walther Date: Fri, 9 May 2025 21:54:12 +0200 Subject: [PATCH 7/9] workflows/keep-sorted: drop and move to treefmt Same reasoning as the commit before, but keep-sorted has even less overhead than editorconfig-checker. Benchmark has it at 1 second per run. (cherry picked from commit 1cb7a384e022733ba8c1387a9aef9ad382c86394) --- .github/workflows/keep-sorted.yml | 41 ------------------------------- ci/default.nix | 2 ++ 2 files changed, 2 insertions(+), 41 deletions(-) delete mode 100644 .github/workflows/keep-sorted.yml diff --git a/.github/workflows/keep-sorted.yml b/.github/workflows/keep-sorted.yml deleted file mode 100644 index ec2237f52bd9..000000000000 --- a/.github/workflows/keep-sorted.yml +++ /dev/null @@ -1,41 +0,0 @@ -name: Check that files are sorted - -on: - pull_request_target: - types: [opened, synchronize, reopened] - -permissions: {} - -jobs: - get-merge-commit: - uses: ./.github/workflows/get-merge-commit.yml - - nixos: - name: keep-sorted - runs-on: ubuntu-24.04 - needs: get-merge-commit - if: "needs.get-merge-commit.outputs.mergedSha && !contains(github.event.pull_request.title, '[skip treewide]')" - steps: - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - with: - ref: ${{ needs.get-merge-commit.outputs.mergedSha }} - - - name: Get Nixpkgs revision for keep-sorted - run: | - # Pin to a commit from nixpkgs-unstable to avoid e.g. building nixfmt from staging. - # This should not be a URL, because it would allow PRs to run arbitrary code in CI! - rev=$(jq -r .rev ci/pinned-nixpkgs.json) - echo "url=https://github.com/NixOS/nixpkgs/archive/$rev.tar.gz" >> "$GITHUB_ENV" - - - uses: cachix/install-nix-action@526118121621777ccd86f79b04685a9319637641 # v31 - with: - extra_nix_config: sandbox = true - nix_path: nixpkgs=${{ env.url }} - - - name: Install keep-sorted - run: "nix-env -f '' -iAP keep-sorted jq" - - - name: Check that Nix files are sorted - shell: bash - run: | - git ls-files | xargs keep-sorted --mode lint | jq --raw-output '.[] | "Please make sure any new entries in \(.path) are sorted alphabetically."' diff --git a/ci/default.nix b/ci/default.nix index 59fb1b48574c..9d0fff7d119a 100644 --- a/ci/default.nix +++ b/ci/default.nix @@ -44,6 +44,8 @@ let # By default it's info, which is too noisy since we have many unmatched files settings.on-unmatched = "debug"; + programs.keep-sorted.enable = true; + # This uses nixfmt-rfc-style underneath, # the default formatter for Nix code. # See https://github.com/NixOS/nixfmt From b793f5ffc003e6624df23fd99c03b0c3474108cd Mon Sep 17 00:00:00 2001 From: Winter Date: Thu, 8 May 2025 03:23:13 -0400 Subject: [PATCH 8/9] fetchurl: don't prefer hashed mirrors by default Right now, when building any FOD that uses `fetchurl` (which is the majority of ours), `tarballs.nixos.org` will always be contacted before the actual URL. Given that `tarballs.nixos.org` mainly hosts the bootstrap tools, which already explicitly set it as the host to pull from, it doesn't make much sense to force every other `fetchurl` invocation to first reach out to `tarballs.nixos.org`. (cherry picked from commit 40d5f4e0a0d9f45abaab7324963c69960c5c2327) --- pkgs/build-support/fetchurl/default.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/build-support/fetchurl/default.nix b/pkgs/build-support/fetchurl/default.nix index e4a70743334b..88b3eb172141 100644 --- a/pkgs/build-support/fetchurl/default.nix +++ b/pkgs/build-support/fetchurl/default.nix @@ -215,7 +215,7 @@ stdenvNoCC.mkDerivation ( # If set, prefer the content-addressable mirrors # (http://tarballs.nixos.org) over the original URLs. - preferHashedMirrors = true; + preferHashedMirrors = false; # New-style output content requirements. inherit (hash_) outputHashAlgo outputHash; From 72778c43a5b08da724628d4daf558b4b61b3a046 Mon Sep 17 00:00:00 2001 From: Wolfgang Walther Date: Fri, 9 May 2025 21:59:49 +0200 Subject: [PATCH 9/9] workflows/check-nixf-tidy: drop The workflow has been disabled for 9 months. Except for the Eval workflow, this is the most complex, yet unused, workflow. As discussed in #332695, this needs a proper wrapper first. Chances are high, that once a good CLI tool is available, the workflow would be implemented entirely different: We could easily run it via treefmt as well, so that we get the same results locally as in CI. (cherry picked from commit 60450491f9f3ff10a0d0f4e597091d3c13f7ca4a) --- .github/workflows/check-nixf-tidy.yml | 132 -------------------------- 1 file changed, 132 deletions(-) delete mode 100644 .github/workflows/check-nixf-tidy.yml diff --git a/.github/workflows/check-nixf-tidy.yml b/.github/workflows/check-nixf-tidy.yml deleted file mode 100644 index 1bb43c746bc5..000000000000 --- a/.github/workflows/check-nixf-tidy.yml +++ /dev/null @@ -1,132 +0,0 @@ -name: Check changed Nix files with nixf-tidy (experimental) - -on: - pull_request_target: - types: [opened, synchronize, reopened, edited] - -permissions: {} - -jobs: - nixos: - name: exp-nixf-tidy-check - runs-on: ubuntu-24.04 - if: "!contains(github.event.pull_request.title, '[skip treewide]')" - steps: - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - with: - ref: refs/pull/${{ github.event.pull_request.number }}/merge - # Fetches the merge commit and its parents - fetch-depth: 2 - - - name: Checking out target branch - run: | - target=$(mktemp -d) - targetRev=$(git rev-parse HEAD^1) - git worktree add "$target" "$targetRev" - echo "targetRev=$targetRev" >> "$GITHUB_ENV" - echo "target=$target" >> "$GITHUB_ENV" - - - name: Get Nixpkgs revision for nixf - run: | - # pin to a commit from nixpkgs-unstable to avoid e.g. building nixf - # from staging - # This should not be a URL, because it would allow PRs to run arbitrary code in CI! - rev=$(jq -r .rev ci/pinned-nixpkgs.json) - echo "url=https://github.com/NixOS/nixpkgs/archive/$rev.tar.gz" >> "$GITHUB_ENV" - - - uses: cachix/install-nix-action@526118121621777ccd86f79b04685a9319637641 # v31 - with: - extra_nix_config: sandbox = true - nix_path: nixpkgs=${{ env.url }} - - - name: Install nixf and jq - # provided jq is incompatible with our expression - run: "nix-env -f '' -iAP nixf jq" - - - name: Check that Nix files pass nixf-tidy - run: | - # Filtering error messages we don't like - nixf_wrapper(){ - nixf-tidy --variable-lookup < "$1" | jq -r ' - [ - "sema-escaping-with" - ] - as $ignored_errors|[.[]|select(.sname as $s|$ignored_errors|index($s)|not)] - ' - } - - failedFiles=() - - # Don't report errors to file overview - # to avoid duplicates when editing title and description - if [[ "${{ github.event.action }}" == 'edited' ]] && [[ -z "${{ github.event.edited.changes.base }}" ]]; then - DONT_REPORT_ERROR=1 - else - DONT_REPORT_ERROR= - fi - # TODO: Make this more parallel - - # Loop through all Nix files touched by the PR - while readarray -d '' -n 2 entry && (( ${#entry[@]} != 0 )); do - type=${entry[0]} - file=${entry[1]} - case $type in - A*) - source="" - dest=$file - ;; - M*) - source=$file - dest=$file - ;; - C*|R*) - source=$file - read -r -d '' dest - ;; - *) - echo "Ignoring file $file with type $type" - continue - esac - - if [[ -n "$source" ]] && [[ "$(nixf_wrapper ${{ env.target }}/"$source")" != '[]' ]] 2>/dev/null; then - echo "Ignoring file $file because it doesn't pass nixf-tidy in the target commit" - echo # insert blank line - else - nixf_report="$(nixf_wrapper "$dest")" - if [[ "$nixf_report" != '[]' ]]; then - echo "$dest doesn't pass nixf-tidy. Reported by nixf-tidy:" - errors=$(echo "$nixf_report" | jq -r --arg dest "$dest" ' - def getLCur: "line=" + (.line+1|tostring) + ",col=" + (.column|tostring); - def getRCur: "endLine=" + (.line+1|tostring) + ",endColumn=" + (.column|tostring); - def getRange: "file=\($dest)," + (.lCur|getLCur) + "," + (.rCur|getRCur); - def getBody: . as $top|(.range|getRange) + ",title="+ .sname + "::" + - (.message|sub("{}" ; ($top.args.[]|tostring))); - def getNote: "\n::notice " + (.|getBody); - def getMessage: "::error " + (.|getBody) + (if (.notes|length)>0 then - ([.notes.[]|getNote]|add) else "" end); - .[]|getMessage - ') - if [[ -z "$DONT_REPORT_ERROR" ]]; then - echo "$errors" - else - # just print in plain text - echo "${errors/::/}" - echo # add one empty line - fi - failedFiles+=("$dest") - fi - fi - done < <(git diff -z --name-status ${{ env.targetRev }} -- '*.nix') - - if [[ -n "$DONT_REPORT_ERROR" ]]; then - echo "Edited the PR but didn't change the base branch, only the description/title." - echo "Not reporting errors again to avoid duplication." - echo # add one empty line - fi - - if (( "${#failedFiles[@]}" > 0 )); then - echo "Some new/changed Nix files don't pass nixf-tidy." - echo "See ${{ github.event.pull_request.html_url }}/files for reported errors." - echo "If you believe this is a false positive, ping @Aleksanaa and @inclyc in this PR." - exit 1 - fi