commit cbd72bcc435094cc38401dd6cb99161bb600aaa3
parent 4904035864f5b45e831d352548a17104f537bcc9
Author: triesap <tyson@radroots.org>
Date: Fri, 21 Aug 2026 22:55:49 +0000
build: bind Lib flake source data
Add the exact non-flake Lib input required by the final service source-lock contract without evaluating or qualifying Nix.
Diffstat:
3 files changed, 58 insertions(+), 0 deletions(-)
diff --git a/flake.lock b/flake.lock
@@ -1,5 +1,21 @@
{
"nodes": {
+ "lib": {
+ "locked": {
+ "lastModified": 1787301679,
+ "narHash": "sha256-WOcgJuKhM9aP55yTuTM63uBf+/IroeBu26zy+lMkvpE=",
+ "owner": "radrootslabs",
+ "repo": "lib",
+ "rev": "b44119fbac5985be8127ad1bf56d2950e6399427",
+ "type": "github"
+ },
+ "original": {
+ "owner": "radrootslabs",
+ "repo": "lib",
+ "rev": "b44119fbac5985be8127ad1bf56d2950e6399427",
+ "type": "github"
+ }
+ },
"nixpkgs": {
"locked": {
"lastModified": 1774799055,
@@ -18,6 +34,7 @@
},
"root": {
"inputs": {
+ "lib": "lib",
"nixpkgs": "nixpkgs",
"rust-overlay": "rust-overlay"
}
diff --git a/flake.nix b/flake.nix
@@ -2,6 +2,10 @@
description = "myc";
inputs = {
+ lib = {
+ url = "github:radrootslabs/lib/b44119fbac5985be8127ad1bf56d2950e6399427";
+ flake = false;
+ };
nixpkgs.url = "github:NixOS/nixpkgs/nixos-25.11";
rust-overlay = {
url = "github:oxalica/rust-overlay";
diff --git a/tests/services_hardening_native_release.rs b/tests/services_hardening_native_release.rs
@@ -7,6 +7,8 @@ use serde_json::json;
const CONTRACT: &str = include_str!("../contracts/services_hardening/native_release.v1.json");
const MANIFEST: &str = include_str!("../Cargo.toml");
const LOCK: &str = include_str!("../Cargo.lock");
+const FLAKE: &str = include_str!("../flake.nix");
+const FLAKE_LOCK: &str = include_str!("../flake.lock");
const LIB_REVISION: &str = "b44119fbac5985be8127ad1bf56d2950e6399427";
const LIB_REPOSITORY: &str = "https://github.com/radrootslabs/lib";
@@ -181,6 +183,41 @@ fn every_radroots_dependency_is_exactly_source_locked() {
assert_eq!(sources.len(), 1);
let source = sources.into_iter().next().expect("Lib source");
assert!(source.contains(&format!("?rev={LIB_REVISION}#{LIB_REVISION}")));
+
+ for required in [
+ "lib = {",
+ "github:radrootslabs/lib/b44119fbac5985be8127ad1bf56d2950e6399427",
+ "flake = false;",
+ ] {
+ assert!(
+ FLAKE.contains(required),
+ "flake source data is missing `{required}`"
+ );
+ }
+ let flake_lock: serde_json::Value =
+ serde_json::from_str(FLAKE_LOCK).expect("flake source lock");
+ assert_eq!(flake_lock["version"], 7);
+ assert_eq!(flake_lock["root"], "root");
+ assert_eq!(flake_lock["nodes"]["root"]["inputs"]["lib"], "lib");
+ assert_eq!(
+ flake_lock["nodes"]["lib"],
+ json!({
+ "locked": {
+ "lastModified": 1787301679_u64,
+ "narHash": "sha256-WOcgJuKhM9aP55yTuTM63uBf+/IroeBu26zy+lMkvpE=",
+ "owner": "radrootslabs",
+ "repo": "lib",
+ "rev": LIB_REVISION,
+ "type": "github"
+ },
+ "original": {
+ "owner": "radrootslabs",
+ "repo": "lib",
+ "rev": LIB_REVISION,
+ "type": "github"
+ }
+ })
+ );
}
#[test]