diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index d85714111..5f54eb843 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -336,14 +336,15 @@ jobs: needs: changes if: needs.changes.outputs.nix == 'true' runs-on: ubuntu-22.04 + continue-on-error: true steps: - uses: actions/checkout@v5 - name: Install Nix uses: DeterminateSystems/nix-installer-action@ef8a148080ab6020fd15196c2084a2eea5ff2d25 # v22 - - name: Validate pnpm dependency hash - run: nix build .#dbx-pnpm-deps --no-link --print-build-logs + - name: Validate Nix dependency closures + run: nix build .#dbx-pnpm-deps .#dbx-cargo-deps --no-link --print-build-logs changes: runs-on: ubuntu-22.04 @@ -404,11 +405,15 @@ jobs: - '.github/scripts/bump-agent-versions.test.mjs' - '.github/workflows/agents-release.yml' nix: - # This fast check validates only the fixed-output pnpm dependency closure. + # These advisory checks validate the pnpm and Cargo dependency closures. - 'package.json' - 'packages/**/package.json' - 'pnpm-lock.yaml' - 'pnpm-workspace.yaml' + - 'Cargo.toml' + - 'Cargo.lock' + - 'crates/**/Cargo.toml' + - 'src-tauri/Cargo.toml' - 'flake.nix' - 'flake.lock' - '.github/workflows/ci.yml' diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 28cc368fe..4b9a82d0b 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -41,6 +41,7 @@ jobs: nix-packaging: runs-on: ubuntu-22.04 + continue-on-error: true steps: - uses: actions/checkout@v5 @@ -636,8 +637,9 @@ jobs: --clobber publish: - # Keep the release as a draft until every platform and the Nix package pass. - needs: [cleanup-release-signatures, docker-manifest, jdbc-plugin, nix-packaging, static-browser] + # Keep the release as a draft until every release-blocking platform job passes. + # Nix packaging is advisory and runs independently from publication. + needs: [cleanup-release-signatures, docker-manifest, jdbc-plugin, static-browser] runs-on: ubuntu-latest steps: - name: Publish draft release diff --git a/flake.lock b/flake.lock index cf4bd6c79..7441f024c 100644 --- a/flake.lock +++ b/flake.lock @@ -1,5 +1,20 @@ { "nodes": { + "crane": { + "locked": { + "lastModified": 1785284101, + "narHash": "sha256-ghcXEpYEM4a7pbEkoqbn8c0ptJJqgGzuFiG3T6W5g4I=", + "owner": "ipetkov", + "repo": "crane", + "rev": "756d6d07c3818ea95d1e2cdac63fa7d02fe3e61b", + "type": "github" + }, + "original": { + "owner": "ipetkov", + "repo": "crane", + "type": "github" + } + }, "flake-utils": { "inputs": { "systems": "systems" @@ -36,6 +51,7 @@ }, "root": { "inputs": { + "crane": "crane", "flake-utils": "flake-utils", "nixpkgs": "nixpkgs", "rust-overlay": "rust-overlay" diff --git a/flake.nix b/flake.nix index 0cb3458f2..9dc62e74a 100644 --- a/flake.nix +++ b/flake.nix @@ -4,6 +4,7 @@ inputs = { nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable"; flake-utils.url = "github:numtide/flake-utils"; + crane.url = "github:ipetkov/crane"; rust-overlay = { url = "github:oxalica/rust-overlay"; inputs.nixpkgs.follows = "nixpkgs"; @@ -15,6 +16,7 @@ self, nixpkgs, flake-utils, + crane, rust-overlay, }: flake-utils.lib.eachDefaultSystem ( @@ -33,6 +35,14 @@ "rustfmt" ]; }; + baseCraneLib = (crane.mkLib pkgs).overrideToolchain rustToolchain; + craneLib = baseCraneLib.appendCrateRegistries [ + (baseCraneLib.registryFromDownloadUrl { + indexUrl = "https://github.com/rust-lang/crates.io-index"; + dl = "https://static.crates.io/crates"; + fetchurlExtraArgs.curlOpts = "--retry 20 --retry-all-errors --retry-delay 1"; + }) + ]; # ------------------------------------------------------------------ # # Linux-only system libraries required by Tauri / WebKit2GTK # @@ -154,13 +164,17 @@ # without compiling the frontend and Rust desktop application. packages.dbx-pnpm-deps = self.packages.${system}.dbx-desktop.pnpmDeps; + # Fast dependency target used by CI to validate Cargo vendoring without + # compiling the frontend and Rust desktop application. + packages.dbx-cargo-deps = self.packages.${system}.dbx-desktop.cargoVendorDir; + # ------------------------------------------------------------------ # # packages.dbx-desktop — Tauri desktop application # # Build with: nix build .#dbx-desktop # # # # Two-phase build strategy: # # 1. pnpm.fetchDeps → vendor all npm/pnpm deps offline # - # 2. importCargoLock → vendor all Cargo deps offline # + # 2. Crane vendoring → vendor all Cargo deps offline # # 3. pnpm build → compile Vue/TypeScript frontend # # 4. cargo build -p dbx → compile Tauri Rust backend # # # @@ -187,12 +201,18 @@ }; # ── Step 2: vendor Cargo dependencies ───────────────────────────── # - cargoDeps = pkgs.rustPlatform.importCargoLock { - lockFile = ./Cargo.lock; + cargoVendorDir = craneLib.vendorCargoDeps { + cargoLock = ./Cargo.lock; + # Pin Git checkouts by their complete Cargo source identity. Unlike + # package-name/version keys, these remain stable when a package + # version inside the same checkout changes. outputHashes = { - "tokio-postgres-0.7.18" = "sha256-HRbYVSD7iIwG3m1tOGoIZy0xAZwALWIpTtakVSYPIYI="; - "mysql-common-derive-0.32.2" = "sha256-8lWgsdTuLTgOmzP7tXmA9LnomOE0wjxXsCBw9NEMt2o="; - "mysql_async-0.37.0" = "sha256-tMFvmypIBh1GHg3cLFWmLf6N1wrwKPlzx2G/MHwtlFM="; + "git+https://github.com/t8y2/rust_mysql_common.git?rev=77085e91e5081309d585153e3b656ce33bc1fe74#77085e91e5081309d585153e3b656ce33bc1fe74" = + "sha256-8lWgsdTuLTgOmzP7tXmA9LnomOE0wjxXsCBw9NEMt2o="; + "git+https://github.com/t8y2/mysql_async.git?rev=2be6e392eb9b06d20dcd2d8ed8eae748d413c9ec#2be6e392eb9b06d20dcd2d8ed8eae748d413c9ec" = + "sha256-tMFvmypIBh1GHg3cLFWmLf6N1wrwKPlzx2G/MHwtlFM="; + "git+https://github.com/t8y2/tokio-postgres-gaussdb.git?rev=115f9fef10f0fc3669b5337955e4eb461fc349a6#115f9fef10f0fc3669b5337955e4eb461fc349a6" = + "sha256-HRbYVSD7iIwG3m1tOGoIZy0xAZwALWIpTtakVSYPIYI="; }; }; @@ -207,7 +227,8 @@ pkgs.jq # used by preConfigure to strip packageManager pkgs.cargo-tauri # tauri CLI — needed to properly embed frontend assets # Hooks that wire up the vendored deps automatically: - pkgs.rustPlatform.cargoSetupHook # sets CARGO_HOME to cargoDeps + craneLib.configureCargoCommonVarsHook + craneLib.configureCargoVendoredDepsHook pkgs.pnpmConfigHook # sets up pnpm offline store pkgs.desktop-file-utils # for `desktop-file-validate` pkgs.copyDesktopItems # installs desktopItem into share/applications