radrootsd

JSON-RPC bridge for Radroots event publishing
git clone https://radroots.dev/git/radrootsd.git
Log | Files | Refs | README | LICENSE

commit 048ea5445aa2a56f2862a11a41fc0fd83aa8e4e4
parent 70de1195c050823a05ec79b3526adcbed728a6f7
Author: triesap <tyson@radroots.org>
Date:   Mon,  7 Sep 2026 02:39:03 +0000

feat(nix): build governed radrootsd outputs

- Replace checkout wrappers with a real Crane-built radrootsd package.
- Expose one package, check, and application on the two governed systems.
- Remove development-shell, module, OCI, and excluded-system outputs.
- Lock shared Nix tooling to the qualified Lib input and test the boundary.

Diffstat:
MREADME | 7+++++--
Mflake.lock | 120+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++------
Mflake.nix | 248+++++++++++++++++++++++++++++--------------------------------------------------
Mtests/package_boundary.rs | 34++++++++++++++++++++++++++++++++++
4 files changed, 242 insertions(+), 167 deletions(-)

diff --git a/README b/README @@ -28,8 +28,11 @@ scripts/verify-supply-chain.sh The boundary command byte-compares the root-only public API against its reviewed baseline and rejects forbidden repository roots or credential material. The supply-chain command checks the locked dependency, license, -advisory, and immutable public-source policy. Nix and OCI are deferred and -unclaimed through RCLD-RSHR-170. +advisory, and immutable public-source policy. + +The standalone flake exposes exactly one real `radrootsd` package, check, and +application for `aarch64-darwin` and `x86_64-linux`. It exposes no checkout +wrapper, development shell, NixOS module, OCI artifact, or other system. ## Copyright diff --git a/flake.lock b/flake.lock @@ -1,12 +1,71 @@ { "nodes": { + "crane": { + "locked": { + "lastModified": 1766774972, + "narHash": "sha256-8qxEFpj4dVmIuPn9j9z6NTbU+hrcGjBOvaxTzre5HmM=", + "owner": "ipetkov", + "repo": "crane", + "rev": "01bc1d404a51a0a07e9d8759cd50a7903e218c82", + "type": "github" + }, + "original": { + "owner": "ipetkov", + "repo": "crane", + "rev": "01bc1d404a51a0a07e9d8759cd50a7903e218c82", + "type": "github" + } + }, + "flake-parts": { + "inputs": { + "nixpkgs-lib": "nixpkgs-lib" + }, + "locked": { + "lastModified": 1772408722, + "narHash": "sha256-rHuJtdcOjK7rAHpHphUb1iCvgkU3GpfvicLMwwnfMT0=", + "owner": "hercules-ci", + "repo": "flake-parts", + "rev": "f20dc5d9b8027381c474144ecabc9034d6a839a3", + "type": "github" + }, + "original": { + "owner": "hercules-ci", + "repo": "flake-parts", + "type": "github" + } + }, + "lib": { + "inputs": { + "crane": [ + "crane" + ], + "flake-parts": "flake-parts", + "nixpkgs": "nixpkgs", + "rust-overlay": "rust-overlay", + "treefmt-nix": "treefmt-nix" + }, + "locked": { + "lastModified": 1788739124, + "narHash": "sha256-Aw8qbU1DrtxSYJKg0js6kexnKgVGFCjR34bgq+ZVAVo=", + "owner": "radrootslabs", + "repo": "lib", + "rev": "055096853fca95e15d0f813d33a14aca13be3881", + "type": "github" + }, + "original": { + "owner": "radrootslabs", + "repo": "lib", + "rev": "055096853fca95e15d0f813d33a14aca13be3881", + "type": "github" + } + }, "nixpkgs": { "locked": { - "lastModified": 1774799055, - "narHash": "sha256-Tsq9BCz0q47ej1uFF39m4tuhcwru/ls6vCCJzutEpaw=", + "lastModified": 1773222311, + "narHash": "sha256-BHoB/XpbqoZkVYZCfXJXfkR+GXFqwb/4zbWnOr2cRcU=", "owner": "NixOS", "repo": "nixpkgs", - "rev": "107cba9eb4a8d8c9f8e9e61266d78d340867913a", + "rev": "0590cd39f728e129122770c029970378a79d076a", "type": "github" }, "original": { @@ -16,24 +75,48 @@ "type": "github" } }, + "nixpkgs-lib": { + "locked": { + "lastModified": 1772328832, + "narHash": "sha256-e+/T/pmEkLP6BHhYjx6GmwP5ivonQQn0bJdH9YrRB+Q=", + "owner": "nix-community", + "repo": "nixpkgs.lib", + "rev": "c185c7a5e5dd8f9add5b2f8ebeff00888b070742", + "type": "github" + }, + "original": { + "owner": "nix-community", + "repo": "nixpkgs.lib", + "type": "github" + } + }, "root": { "inputs": { - "nixpkgs": "nixpkgs", - "rust-overlay": "rust-overlay" + "crane": "crane", + "lib": "lib", + "nixpkgs": [ + "lib", + "nixpkgs" + ], + "rust-overlay": [ + "lib", + "rust-overlay" + ] } }, "rust-overlay": { "inputs": { "nixpkgs": [ + "lib", "nixpkgs" ] }, "locked": { - "lastModified": 1784350408, - "narHash": "sha256-OstzLWL5t7Xe14xEC6GIMJCp0PrYNTSA0El7GG2av88=", + "lastModified": 1785131767, + "narHash": "sha256-VNbQv2P0zgaNh96mT4LrnX7hdXgiC5nBH+uvyrrVX7U=", "owner": "oxalica", "repo": "rust-overlay", - "rev": "3c38e1e1ba9c8d7030f7b5a801398ea7d8a6fdc0", + "rev": "c67ce00525464a710971351c183ce67acb6ca827", "type": "github" }, "original": { @@ -41,6 +124,27 @@ "repo": "rust-overlay", "type": "github" } + }, + "treefmt-nix": { + "inputs": { + "nixpkgs": [ + "lib", + "nixpkgs" + ] + }, + "locked": { + "lastModified": 1773297127, + "narHash": "sha256-6E/yhXP7Oy/NbXtf1ktzmU8SdVqJQ09HC/48ebEGBpk=", + "owner": "numtide", + "repo": "treefmt-nix", + "rev": "71b125cd05fbfd78cab3e070b73544abe24c5016", + "type": "github" + }, + "original": { + "owner": "numtide", + "repo": "treefmt-nix", + "type": "github" + } } }, "root": "root", diff --git a/flake.nix b/flake.nix @@ -1,174 +1,108 @@ { - description = "radrootsd"; + description = "Radroots public runtime daemon"; inputs = { - nixpkgs.url = "github:NixOS/nixpkgs/nixos-25.11"; - rust-overlay = { - url = "github:oxalica/rust-overlay"; - inputs.nixpkgs.follows = "nixpkgs"; + # Crane 0.23+ currently asks nixpkgs' Cargo vendor helper to fetch + # semver-build-metadata crate versions through the crates.io API. That + # endpoint rejects the literal `+`; the immutable v0.22.0 input avoids + # that upstream fetch defect while preserving the same locked sources. + crane.url = "github:ipetkov/crane/01bc1d404a51a0a07e9d8759cd50a7903e218c82"; + lib = { + url = "github:radrootslabs/lib/055096853fca95e15d0f813d33a14aca13be3881"; + inputs.crane.follows = "crane"; }; + nixpkgs.follows = "lib/nixpkgs"; + rust-overlay.follows = "lib/rust-overlay"; }; outputs = - { nixpkgs, rust-overlay, ... }: + { + crane, + lib, + nixpkgs, + rust-overlay, + ... + }: let - systems = [ - "aarch64-darwin" - "aarch64-linux" - "x86_64-darwin" - "x86_64-linux" - ]; + systems = lib.lib.supportedSystems; forAllSystems = - f: - nixpkgs.lib.genAttrs systems ( - system: - let - pkgs = import nixpkgs { - inherit system; - overlays = [ rust-overlay.overlays.default ]; - }; - rustToolchain = pkgs.rust-bin.fromRustupToolchainFile ./rust-toolchain.toml; - basePackages = - [ - pkgs.git - rustToolchain - pkgs.clang - pkgs.llvmPackages.libclang - pkgs.libsodium - pkgs.openssl - pkgs.pkg-config - pkgs.sqlite - ] - ++ pkgs.lib.optionals pkgs.stdenv.isDarwin [ - pkgs.darwin.libiconv - ]; - libraryPath = pkgs.lib.makeLibraryPath basePackages; - includePath = pkgs.lib.makeSearchPathOutput "dev" "include" basePackages; - llvmToolsBin = "${pkgs.llvmPackages.llvm}/bin"; - darwinLdFlags = pkgs.lib.optionalString pkgs.stdenv.isDarwin "-L${pkgs.darwin.libiconv}/lib"; - darwinRustFlags = pkgs.lib.optionalString pkgs.stdenv.isDarwin "-L native=${pkgs.darwin.libiconv}/lib"; - coveragePackages = basePackages ++ [ - pkgs.llvmPackages.llvm - ]; - mkApp = - name: - { - runtimeInputs ? basePackages, - text, - }: - let - script = pkgs.writeShellApplication { - inherit name; - inherit runtimeInputs; - text = '' - set -euo pipefail - repo_root="$(git rev-parse --show-toplevel)" - cd "$repo_root" - export LIBCLANG_PATH="${pkgs.llvmPackages.libclang.lib}/lib" - export LIBRARY_PATH="${libraryPath}:''${LIBRARY_PATH:-}" - export DYLD_FALLBACK_LIBRARY_PATH="${libraryPath}:''${DYLD_FALLBACK_LIBRARY_PATH:-}" - export LDFLAGS="${darwinLdFlags} ''${LDFLAGS:-}" - export NIX_LDFLAGS="${darwinLdFlags} ''${NIX_LDFLAGS:-}" - export RUSTFLAGS="${darwinRustFlags} ''${RUSTFLAGS:-}" - export CPATH="${includePath}:''${CPATH:-}" - ${text} - ''; - }; - in - { - type = "app"; - program = "${script}/bin/${name}"; - }; - in - f { - inherit - basePackages - coveragePackages - darwinLdFlags - darwinRustFlags - includePath - libraryPath - llvmToolsBin - mkApp - pkgs - rustToolchain - ; - } + function: + builtins.listToAttrs ( + map (system: { + name = system; + value = function system; + }) systems ); - in - { - apps = forAllSystems ( - { - coveragePackages, - llvmToolsBin, - mkApp, - ... - }: - rec { - default = check; - check = mkApp "check" { - text = '' - cargo metadata --format-version 1 --no-deps - cargo check - ''; + daemonOutputs = + system: + let + pkgs = import nixpkgs { + inherit system; + overlays = [ rust-overlay.overlays.default ]; }; - coverage-report = mkApp "coverage-report" { - runtimeInputs = coveragePackages; - text = '' - export PATH="$HOME/.cargo/bin:$PATH" - cargo +nightly llvm-cov --version >/dev/null 2>&1 || { - echo "cargo +nightly llvm-cov must be available to run coverage-report" >&2 - exit 1 - } - export LLVM_COV="${llvmToolsBin}/llvm-cov" - export LLVM_PROFDATA="${llvmToolsBin}/llvm-profdata" - mkdir -p target/coverage - cargo +nightly llvm-cov clean --workspace - cargo +nightly llvm-cov --workspace --all-features --branch --no-report - cargo +nightly llvm-cov report --json --summary-only --output-path target/coverage/summary.json - cargo +nightly llvm-cov report --lcov --output-path target/coverage/lcov.info - cargo +nightly llvm-cov report --summary-only - echo "coverage summary: target/coverage/summary.json" - echo "coverage lcov: target/coverage/lcov.info" - ''; + helpers = lib.lib.mkServiceHelpers system; + toolchain = helpers.mkToolchain { + rustToolchainFile = ./rust-toolchain.toml; }; - fmt = mkApp "fmt" { - text = '' - cargo fmt --all --check - ''; + nativeInputs = helpers.mkNativeInputs { }; + craneLib = (crane.mkLib pkgs).overrideToolchain toolchain; + source = pkgs.lib.cleanSourceWith { + src = ./.; + filter = + path: type: + craneLib.filterCargoSources path type + || baseNameOf path == "README"; + name = "radrootsd-source"; }; - test = mkApp "test" { - text = '' - cargo test - ''; + commonArgs = { + src = source; + cargoLock = ./Cargo.lock; + strictDeps = true; + nativeBuildInputs = nativeInputs.nativeBuildInputs; + buildInputs = nativeInputs.buildInputs; + env = nativeInputs.environment; + doCheck = false; }; - } - ); - - devShells = forAllSystems ( - { - basePackages, - darwinLdFlags, - darwinRustFlags, - includePath, - libraryPath, - pkgs, - ... - }: - { - default = pkgs.mkShell { - packages = basePackages; - shellHook = '' - export LIBCLANG_PATH="${pkgs.llvmPackages.libclang.lib}/lib" - export LIBRARY_PATH="${libraryPath}:''${LIBRARY_PATH:-}" - export DYLD_FALLBACK_LIBRARY_PATH="${libraryPath}:''${DYLD_FALLBACK_LIBRARY_PATH:-}" - export LDFLAGS="${darwinLdFlags} ''${LDFLAGS:-}" - export NIX_LDFLAGS="${darwinLdFlags} ''${NIX_LDFLAGS:-}" - export RUSTFLAGS="${darwinRustFlags} ''${RUSTFLAGS:-}" - export CPATH="${includePath}:''${CPATH:-}" - ''; + cargoArtifacts = craneLib.buildDepsOnly commonArgs; + package = craneLib.buildPackage ( + commonArgs + // { + inherit cargoArtifacts; + pname = "radrootsd"; + version = "0.1.0"; + CARGO_PROFILE = "release"; + cargoExtraArgs = "--locked --package radrootsd --bin radrootsd"; + } + ); + check = craneLib.mkCargoDerivation ( + commonArgs + // { + inherit cargoArtifacts; + pname = "radrootsd-check"; + version = "1"; + buildPhaseCargoCommand = "cargo check --locked --package radrootsd --all-targets"; + installPhaseCommand = "mkdir -p $out"; + } + ); + app = { + type = "app"; + program = "${package}/bin/radrootsd"; + meta.description = "Run the built radrootsd daemon"; }; - } - ); + in + { + inherit app check package; + }; + in + { + packages = forAllSystems (system: { + default = (daemonOutputs system).package; + }); + checks = forAllSystems (system: { + default = (daemonOutputs system).check; + }); + apps = forAllSystems (system: { + default = (daemonOutputs system).app; + }); }; } diff --git a/tests/package_boundary.rs b/tests/package_boundary.rs @@ -2,6 +2,7 @@ const ROOT: &str = include_str!("../src/lib.rs"); const PUBLIC_API: &str = include_str!("../contracts/api_baselines/radrootsd.txt"); +const FLAKE: &str = include_str!("../flake.nix"); #[test] fn implementation_modules_are_private_and_api_is_owned() { @@ -29,3 +30,36 @@ fn public_error_is_redacted_and_source_free() { } assert!(!PUBLIC_API.contains("std::io::Error")); } + +#[test] +fn nix_outputs_are_real_owned_and_exactly_bounded() { + for required in [ + "github:radrootslabs/lib/055096853fca95e15d0f813d33a14aca13be3881", + "systems = lib.lib.supportedSystems", + "craneLib.buildPackage", + "craneLib.mkCargoDerivation", + "program = \"${package}/bin/radrootsd\"", + "default = (daemonOutputs system).package", + "default = (daemonOutputs system).check", + "default = (daemonOutputs system).app", + ] { + assert!( + FLAKE.contains(required), + "missing governed Nix source: {required}" + ); + } + for forbidden in [ + "writeShellApplication", + "git rev-parse", + "repo_root", + "devShells", + "nixosModules", + "aarch64-linux", + "x86_64-darwin", + ] { + assert!( + !FLAKE.contains(forbidden), + "forbidden Nix surface is present: {forbidden}" + ); + } +}