test-macos-app-sandbox uses the system-provided codesign binary
(/usr/bin/codesign) to apply entitlements to an app bundle. This fails
in the sandbox as /usr/bin/codesign is not accessible. Patch the test to
instead use the codesign binary from sigtool. The test was updated to
pass the executable path to codesign as sigtool can't handle the bundle
path.
Format all Nix files using the officially approved formatter,
making the CI check introduced in the previous commit succeed:
nix-build ci -A fmt.check
This is the next step of the of the [implementation](https://github.com/NixOS/nixfmt/issues/153)
of the accepted [RFC 166](https://github.com/NixOS/rfcs/pull/166).
This commit will lead to merge conflicts for a number of PRs,
up to an estimated ~1100 (~33%) among the PRs with activity in the past 2
months, but that should be lower than what it would be without the previous
[partial treewide format](https://github.com/NixOS/nixpkgs/pull/322537).
Merge conflicts caused by this commit can now automatically be resolved while rebasing using the
[auto-rebase script](8616af08d9/maintainers/scripts/auto-rebase).
If you run into any problems regarding any of this, please reach out to the
[formatting team](https://nixos.org/community/teams/formatting/) by
pinging @NixOS/nix-formatting.
This was tested x86_64-linux -> x86_64-freebsd. It works by injecting
the tools that would otherwise be run at build time for the same
executables extracted from a native build.
Without this, there are multiple issues:
a) It will fail to start building since there are naming conflicts
between the "host" (build system) and "normal" (host system) object
files. This is resolved with a patch from buildroot.
b) It will then still fail to build since it will still try to build the
"host" objects, with a host compiler, but it will use the
configuration flags for the "target" OS. This is resolved by
importing the executables that would otherwise be run on the build
system from the intermediate stage of a native build, saved in a new
"dev" output. We also fake the "host" compiler as a tool which simply
touches its outputs.
c) Finally, there is a clang bug which causes a static assert that
something is trivially copyable to fire as a false positive. We
remove this check with a patch from rubyjs.