myc

Self-custodial remote signer for Radroots apps
git clone https://radroots.dev/git/myc.git
Log | Files | Refs | README | LICENSE

commit cbd72bcc435094cc38401dd6cb99161bb600aaa3
parent 4904035864f5b45e831d352548a17104f537bcc9
Author: triesap <tyson@radroots.org>
Date:   Fri, 21 Aug 2026 22:55:49 +0000

build: bind Lib flake source data

Add the exact non-flake Lib input required by the final service source-lock contract without evaluating or qualifying Nix.

Diffstat:
Mflake.lock | 17+++++++++++++++++
Mflake.nix | 4++++
Mtests/services_hardening_native_release.rs | 37+++++++++++++++++++++++++++++++++++++
3 files changed, 58 insertions(+), 0 deletions(-)

diff --git a/flake.lock b/flake.lock @@ -1,5 +1,21 @@ { "nodes": { + "lib": { + "locked": { + "lastModified": 1787301679, + "narHash": "sha256-WOcgJuKhM9aP55yTuTM63uBf+/IroeBu26zy+lMkvpE=", + "owner": "radrootslabs", + "repo": "lib", + "rev": "b44119fbac5985be8127ad1bf56d2950e6399427", + "type": "github" + }, + "original": { + "owner": "radrootslabs", + "repo": "lib", + "rev": "b44119fbac5985be8127ad1bf56d2950e6399427", + "type": "github" + } + }, "nixpkgs": { "locked": { "lastModified": 1774799055, @@ -18,6 +34,7 @@ }, "root": { "inputs": { + "lib": "lib", "nixpkgs": "nixpkgs", "rust-overlay": "rust-overlay" } diff --git a/flake.nix b/flake.nix @@ -2,6 +2,10 @@ description = "myc"; inputs = { + lib = { + url = "github:radrootslabs/lib/b44119fbac5985be8127ad1bf56d2950e6399427"; + flake = false; + }; nixpkgs.url = "github:NixOS/nixpkgs/nixos-25.11"; rust-overlay = { url = "github:oxalica/rust-overlay"; diff --git a/tests/services_hardening_native_release.rs b/tests/services_hardening_native_release.rs @@ -7,6 +7,8 @@ use serde_json::json; const CONTRACT: &str = include_str!("../contracts/services_hardening/native_release.v1.json"); const MANIFEST: &str = include_str!("../Cargo.toml"); const LOCK: &str = include_str!("../Cargo.lock"); +const FLAKE: &str = include_str!("../flake.nix"); +const FLAKE_LOCK: &str = include_str!("../flake.lock"); const LIB_REVISION: &str = "b44119fbac5985be8127ad1bf56d2950e6399427"; const LIB_REPOSITORY: &str = "https://github.com/radrootslabs/lib"; @@ -181,6 +183,41 @@ fn every_radroots_dependency_is_exactly_source_locked() { assert_eq!(sources.len(), 1); let source = sources.into_iter().next().expect("Lib source"); assert!(source.contains(&format!("?rev={LIB_REVISION}#{LIB_REVISION}"))); + + for required in [ + "lib = {", + "github:radrootslabs/lib/b44119fbac5985be8127ad1bf56d2950e6399427", + "flake = false;", + ] { + assert!( + FLAKE.contains(required), + "flake source data is missing `{required}`" + ); + } + let flake_lock: serde_json::Value = + serde_json::from_str(FLAKE_LOCK).expect("flake source lock"); + assert_eq!(flake_lock["version"], 7); + assert_eq!(flake_lock["root"], "root"); + assert_eq!(flake_lock["nodes"]["root"]["inputs"]["lib"], "lib"); + assert_eq!( + flake_lock["nodes"]["lib"], + json!({ + "locked": { + "lastModified": 1787301679_u64, + "narHash": "sha256-WOcgJuKhM9aP55yTuTM63uBf+/IroeBu26zy+lMkvpE=", + "owner": "radrootslabs", + "repo": "lib", + "rev": LIB_REVISION, + "type": "github" + }, + "original": { + "owner": "radrootslabs", + "repo": "lib", + "rev": LIB_REVISION, + "type": "github" + } + }) + ); } #[test]