mirror of
https://github.com/akitaonrails/ai-memory.git
synced 2026-10-02 03:24:46 +08:00
build(nix): pin flake inputs and verify the flake in CI
Two gaps in the packaging as submitted. Inputs floated: `github:NixOS/nixpkgs/nixos-unstable` resolves to whatever that branch points at today, so two people — or the same person a week apart — could get different builds from identical source. A flake's whole value is reproducibility. Normally `flake.lock` pins this; the tree has no lock, and a contributor without Nix installed cannot generate one, so the revisions are pinned in `inputs` directly instead. Same determinism, no tooling required to keep it honest. Nothing executed it: ai-memory has no other Nix coverage, so `flake.nix` was source no job ran. It could break through a dependency bump, a toolchain change, or a new build script and stay green forever, and the first person to notice would be a NixOS user. Adds a `nix` workflow that runs `nix build` and then executes `./result/bin/ai-memory --version`, so a package that builds but cannot run still fails. It is scoped to changes in flake.nix / Cargo.lock / Cargo.toml / rust-toolchain.toml plus a weekly schedule and manual dispatch, rather than every pull request: a full release build under Nix costs more wall-clock than the rest of the matrix combined and almost no PR can affect it. Refs #405 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
3c92ed77c6
commit
100424bccd
@@ -0,0 +1,55 @@
|
||||
name: nix
|
||||
|
||||
# Builds the flake so the Nix packaging cannot rot unnoticed.
|
||||
#
|
||||
# ai-memory does not otherwise test on Nix, so without this job `flake.nix`
|
||||
# is source nobody executes: it can break through a dependency bump, a
|
||||
# toolchain change, or a new build script and stay green because no other
|
||||
# job touches it.
|
||||
#
|
||||
# Deliberately NOT run on every pull request — a full release build under
|
||||
# Nix costs far more wall-clock than the rest of the matrix combined, and
|
||||
# most PRs cannot affect it. It runs when an input to the Nix build
|
||||
# actually changes, on a weekly schedule to catch upstream drift, and on
|
||||
# demand.
|
||||
on:
|
||||
push:
|
||||
branches: [main]
|
||||
paths:
|
||||
- 'flake.nix'
|
||||
- 'Cargo.lock'
|
||||
- 'Cargo.toml'
|
||||
- 'rust-toolchain.toml'
|
||||
- '.github/workflows/nix.yml'
|
||||
pull_request:
|
||||
paths:
|
||||
- 'flake.nix'
|
||||
- 'Cargo.lock'
|
||||
- 'Cargo.toml'
|
||||
- 'rust-toolchain.toml'
|
||||
- '.github/workflows/nix.yml'
|
||||
schedule:
|
||||
# Mondays 05:17 UTC. Off the hour so it does not pile onto the
|
||||
# top-of-hour scheduling spike.
|
||||
- cron: '17 5 * * 1'
|
||||
workflow_dispatch:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
build:
|
||||
name: nix build
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- uses: cachix/install-nix-action@13d8dd58da0234aa297dedd986986ccb8e7f3e24 # v31.11.1
|
||||
with:
|
||||
extra_nix_config: |
|
||||
experimental-features = nix-command flakes
|
||||
# `nix flake check` would also evaluate every output; the build is the
|
||||
# claim worth verifying, and it is the expensive half anyway.
|
||||
- run: nix build --print-build-logs
|
||||
# The binary is what the flake promises. Run it, so a package that
|
||||
# builds but cannot execute still fails.
|
||||
- run: ./result/bin/ai-memory --version
|
||||
+5
-1
@@ -26,7 +26,11 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
|
||||
no system-library hunting). The flake skips the packaging test suite
|
||||
because those tests exercise the Docker-wrapper shell script and need
|
||||
`docker`/`podman` on PATH; the rest of the workspace tests can be run via
|
||||
`nix develop -c cargo test --workspace`. ([#405])
|
||||
`nix develop -c cargo test --workspace`. Flake inputs are pinned to
|
||||
explicit revisions rather than floating branches, so the build is
|
||||
reproducible, and a `nix` CI job builds the flake and runs the resulting
|
||||
binary whenever a Nix build input changes plus weekly, so the packaging
|
||||
cannot rot unnoticed. ([#405])
|
||||
- New `strip_root_combinators` config flag (env `AI_MEMORY_STRIP_ROOT_COMBINATORS`,
|
||||
or `strip_root_combinators = true` in config.toml) strips root-level
|
||||
`anyOf`/`oneOf`/`allOf` from MCP tool input schemas on every `tools/list`.
|
||||
|
||||
@@ -22,11 +22,22 @@
|
||||
{
|
||||
description = "Long-term memory for AI coding agents";
|
||||
|
||||
# Inputs are pinned to explicit revisions rather than floating branches.
|
||||
#
|
||||
# A flake's value is reproducibility, and `github:NixOS/nixpkgs/nixos-unstable`
|
||||
# resolves to whatever that branch points at today, so two people — or the
|
||||
# same person a week apart — can get different builds from identical source.
|
||||
# Normally `flake.lock` handles this; pinning here achieves the same
|
||||
# determinism and keeps the tree honest for contributors who do not have
|
||||
# Nix installed and so cannot regenerate a lock.
|
||||
#
|
||||
# To update: bump these revisions deliberately, in their own commit, and
|
||||
# let the `nix` CI job prove the result still builds.
|
||||
inputs = {
|
||||
nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable";
|
||||
flake-utils.url = "github:numtide/flake-utils";
|
||||
nixpkgs.url = "github:NixOS/nixpkgs/0ae2bc1419c3f345984c2629e72e7a631820fa4d";
|
||||
flake-utils.url = "github:numtide/flake-utils/11707dc2f618dd54ca8739b309ec4fc024de578b";
|
||||
rust-overlay = {
|
||||
url = "github:oxalica/rust-overlay";
|
||||
url = "github:oxalica/rust-overlay/99607a06c2ea1290cd3258c11d1416dde9201f94";
|
||||
inputs.nixpkgs.follows = "nixpkgs";
|
||||
};
|
||||
};
|
||||
|
||||
Reference in New Issue
Block a user