commit 048ea5445aa2a56f2862a11a41fc0fd83aa8e4e4
parent 70de1195c050823a05ec79b3526adcbed728a6f7
Author: triesap <tyson@radroots.org>
Date: Mon, 7 Sep 2026 02:39:03 +0000
feat(nix): build governed radrootsd outputs
- Replace checkout wrappers with a real Crane-built radrootsd package.
- Expose one package, check, and application on the two governed systems.
- Remove development-shell, module, OCI, and excluded-system outputs.
- Lock shared Nix tooling to the qualified Lib input and test the boundary.
Diffstat:
| M | README | | | 7 | +++++-- |
| M | flake.lock | | | 120 | +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++------ |
| M | flake.nix | | | 248 | +++++++++++++++++++++++++++++-------------------------------------------------- |
| M | tests/package_boundary.rs | | | 34 | ++++++++++++++++++++++++++++++++++ |
4 files changed, 242 insertions(+), 167 deletions(-)
diff --git a/README b/README
@@ -28,8 +28,11 @@ scripts/verify-supply-chain.sh
The boundary command byte-compares the root-only public API against its
reviewed baseline and rejects forbidden repository roots or credential
material. The supply-chain command checks the locked dependency, license,
-advisory, and immutable public-source policy. Nix and OCI are deferred and
-unclaimed through RCLD-RSHR-170.
+advisory, and immutable public-source policy.
+
+The standalone flake exposes exactly one real `radrootsd` package, check, and
+application for `aarch64-darwin` and `x86_64-linux`. It exposes no checkout
+wrapper, development shell, NixOS module, OCI artifact, or other system.
## Copyright
diff --git a/flake.lock b/flake.lock
@@ -1,12 +1,71 @@
{
"nodes": {
+ "crane": {
+ "locked": {
+ "lastModified": 1766774972,
+ "narHash": "sha256-8qxEFpj4dVmIuPn9j9z6NTbU+hrcGjBOvaxTzre5HmM=",
+ "owner": "ipetkov",
+ "repo": "crane",
+ "rev": "01bc1d404a51a0a07e9d8759cd50a7903e218c82",
+ "type": "github"
+ },
+ "original": {
+ "owner": "ipetkov",
+ "repo": "crane",
+ "rev": "01bc1d404a51a0a07e9d8759cd50a7903e218c82",
+ "type": "github"
+ }
+ },
+ "flake-parts": {
+ "inputs": {
+ "nixpkgs-lib": "nixpkgs-lib"
+ },
+ "locked": {
+ "lastModified": 1772408722,
+ "narHash": "sha256-rHuJtdcOjK7rAHpHphUb1iCvgkU3GpfvicLMwwnfMT0=",
+ "owner": "hercules-ci",
+ "repo": "flake-parts",
+ "rev": "f20dc5d9b8027381c474144ecabc9034d6a839a3",
+ "type": "github"
+ },
+ "original": {
+ "owner": "hercules-ci",
+ "repo": "flake-parts",
+ "type": "github"
+ }
+ },
+ "lib": {
+ "inputs": {
+ "crane": [
+ "crane"
+ ],
+ "flake-parts": "flake-parts",
+ "nixpkgs": "nixpkgs",
+ "rust-overlay": "rust-overlay",
+ "treefmt-nix": "treefmt-nix"
+ },
+ "locked": {
+ "lastModified": 1788739124,
+ "narHash": "sha256-Aw8qbU1DrtxSYJKg0js6kexnKgVGFCjR34bgq+ZVAVo=",
+ "owner": "radrootslabs",
+ "repo": "lib",
+ "rev": "055096853fca95e15d0f813d33a14aca13be3881",
+ "type": "github"
+ },
+ "original": {
+ "owner": "radrootslabs",
+ "repo": "lib",
+ "rev": "055096853fca95e15d0f813d33a14aca13be3881",
+ "type": "github"
+ }
+ },
"nixpkgs": {
"locked": {
- "lastModified": 1774799055,
- "narHash": "sha256-Tsq9BCz0q47ej1uFF39m4tuhcwru/ls6vCCJzutEpaw=",
+ "lastModified": 1773222311,
+ "narHash": "sha256-BHoB/XpbqoZkVYZCfXJXfkR+GXFqwb/4zbWnOr2cRcU=",
"owner": "NixOS",
"repo": "nixpkgs",
- "rev": "107cba9eb4a8d8c9f8e9e61266d78d340867913a",
+ "rev": "0590cd39f728e129122770c029970378a79d076a",
"type": "github"
},
"original": {
@@ -16,24 +75,48 @@
"type": "github"
}
},
+ "nixpkgs-lib": {
+ "locked": {
+ "lastModified": 1772328832,
+ "narHash": "sha256-e+/T/pmEkLP6BHhYjx6GmwP5ivonQQn0bJdH9YrRB+Q=",
+ "owner": "nix-community",
+ "repo": "nixpkgs.lib",
+ "rev": "c185c7a5e5dd8f9add5b2f8ebeff00888b070742",
+ "type": "github"
+ },
+ "original": {
+ "owner": "nix-community",
+ "repo": "nixpkgs.lib",
+ "type": "github"
+ }
+ },
"root": {
"inputs": {
- "nixpkgs": "nixpkgs",
- "rust-overlay": "rust-overlay"
+ "crane": "crane",
+ "lib": "lib",
+ "nixpkgs": [
+ "lib",
+ "nixpkgs"
+ ],
+ "rust-overlay": [
+ "lib",
+ "rust-overlay"
+ ]
}
},
"rust-overlay": {
"inputs": {
"nixpkgs": [
+ "lib",
"nixpkgs"
]
},
"locked": {
- "lastModified": 1784350408,
- "narHash": "sha256-OstzLWL5t7Xe14xEC6GIMJCp0PrYNTSA0El7GG2av88=",
+ "lastModified": 1785131767,
+ "narHash": "sha256-VNbQv2P0zgaNh96mT4LrnX7hdXgiC5nBH+uvyrrVX7U=",
"owner": "oxalica",
"repo": "rust-overlay",
- "rev": "3c38e1e1ba9c8d7030f7b5a801398ea7d8a6fdc0",
+ "rev": "c67ce00525464a710971351c183ce67acb6ca827",
"type": "github"
},
"original": {
@@ -41,6 +124,27 @@
"repo": "rust-overlay",
"type": "github"
}
+ },
+ "treefmt-nix": {
+ "inputs": {
+ "nixpkgs": [
+ "lib",
+ "nixpkgs"
+ ]
+ },
+ "locked": {
+ "lastModified": 1773297127,
+ "narHash": "sha256-6E/yhXP7Oy/NbXtf1ktzmU8SdVqJQ09HC/48ebEGBpk=",
+ "owner": "numtide",
+ "repo": "treefmt-nix",
+ "rev": "71b125cd05fbfd78cab3e070b73544abe24c5016",
+ "type": "github"
+ },
+ "original": {
+ "owner": "numtide",
+ "repo": "treefmt-nix",
+ "type": "github"
+ }
}
},
"root": "root",
diff --git a/flake.nix b/flake.nix
@@ -1,174 +1,108 @@
{
- description = "radrootsd";
+ description = "Radroots public runtime daemon";
inputs = {
- nixpkgs.url = "github:NixOS/nixpkgs/nixos-25.11";
- rust-overlay = {
- url = "github:oxalica/rust-overlay";
- inputs.nixpkgs.follows = "nixpkgs";
+ # Crane 0.23+ currently asks nixpkgs' Cargo vendor helper to fetch
+ # semver-build-metadata crate versions through the crates.io API. That
+ # endpoint rejects the literal `+`; the immutable v0.22.0 input avoids
+ # that upstream fetch defect while preserving the same locked sources.
+ crane.url = "github:ipetkov/crane/01bc1d404a51a0a07e9d8759cd50a7903e218c82";
+ lib = {
+ url = "github:radrootslabs/lib/055096853fca95e15d0f813d33a14aca13be3881";
+ inputs.crane.follows = "crane";
};
+ nixpkgs.follows = "lib/nixpkgs";
+ rust-overlay.follows = "lib/rust-overlay";
};
outputs =
- { nixpkgs, rust-overlay, ... }:
+ {
+ crane,
+ lib,
+ nixpkgs,
+ rust-overlay,
+ ...
+ }:
let
- systems = [
- "aarch64-darwin"
- "aarch64-linux"
- "x86_64-darwin"
- "x86_64-linux"
- ];
+ systems = lib.lib.supportedSystems;
forAllSystems =
- f:
- nixpkgs.lib.genAttrs systems (
- system:
- let
- pkgs = import nixpkgs {
- inherit system;
- overlays = [ rust-overlay.overlays.default ];
- };
- rustToolchain = pkgs.rust-bin.fromRustupToolchainFile ./rust-toolchain.toml;
- basePackages =
- [
- pkgs.git
- rustToolchain
- pkgs.clang
- pkgs.llvmPackages.libclang
- pkgs.libsodium
- pkgs.openssl
- pkgs.pkg-config
- pkgs.sqlite
- ]
- ++ pkgs.lib.optionals pkgs.stdenv.isDarwin [
- pkgs.darwin.libiconv
- ];
- libraryPath = pkgs.lib.makeLibraryPath basePackages;
- includePath = pkgs.lib.makeSearchPathOutput "dev" "include" basePackages;
- llvmToolsBin = "${pkgs.llvmPackages.llvm}/bin";
- darwinLdFlags = pkgs.lib.optionalString pkgs.stdenv.isDarwin "-L${pkgs.darwin.libiconv}/lib";
- darwinRustFlags = pkgs.lib.optionalString pkgs.stdenv.isDarwin "-L native=${pkgs.darwin.libiconv}/lib";
- coveragePackages = basePackages ++ [
- pkgs.llvmPackages.llvm
- ];
- mkApp =
- name:
- {
- runtimeInputs ? basePackages,
- text,
- }:
- let
- script = pkgs.writeShellApplication {
- inherit name;
- inherit runtimeInputs;
- text = ''
- set -euo pipefail
- repo_root="$(git rev-parse --show-toplevel)"
- cd "$repo_root"
- export LIBCLANG_PATH="${pkgs.llvmPackages.libclang.lib}/lib"
- export LIBRARY_PATH="${libraryPath}:''${LIBRARY_PATH:-}"
- export DYLD_FALLBACK_LIBRARY_PATH="${libraryPath}:''${DYLD_FALLBACK_LIBRARY_PATH:-}"
- export LDFLAGS="${darwinLdFlags} ''${LDFLAGS:-}"
- export NIX_LDFLAGS="${darwinLdFlags} ''${NIX_LDFLAGS:-}"
- export RUSTFLAGS="${darwinRustFlags} ''${RUSTFLAGS:-}"
- export CPATH="${includePath}:''${CPATH:-}"
- ${text}
- '';
- };
- in
- {
- type = "app";
- program = "${script}/bin/${name}";
- };
- in
- f {
- inherit
- basePackages
- coveragePackages
- darwinLdFlags
- darwinRustFlags
- includePath
- libraryPath
- llvmToolsBin
- mkApp
- pkgs
- rustToolchain
- ;
- }
+ function:
+ builtins.listToAttrs (
+ map (system: {
+ name = system;
+ value = function system;
+ }) systems
);
- in
- {
- apps = forAllSystems (
- {
- coveragePackages,
- llvmToolsBin,
- mkApp,
- ...
- }:
- rec {
- default = check;
- check = mkApp "check" {
- text = ''
- cargo metadata --format-version 1 --no-deps
- cargo check
- '';
+ daemonOutputs =
+ system:
+ let
+ pkgs = import nixpkgs {
+ inherit system;
+ overlays = [ rust-overlay.overlays.default ];
};
- coverage-report = mkApp "coverage-report" {
- runtimeInputs = coveragePackages;
- text = ''
- export PATH="$HOME/.cargo/bin:$PATH"
- cargo +nightly llvm-cov --version >/dev/null 2>&1 || {
- echo "cargo +nightly llvm-cov must be available to run coverage-report" >&2
- exit 1
- }
- export LLVM_COV="${llvmToolsBin}/llvm-cov"
- export LLVM_PROFDATA="${llvmToolsBin}/llvm-profdata"
- mkdir -p target/coverage
- cargo +nightly llvm-cov clean --workspace
- cargo +nightly llvm-cov --workspace --all-features --branch --no-report
- cargo +nightly llvm-cov report --json --summary-only --output-path target/coverage/summary.json
- cargo +nightly llvm-cov report --lcov --output-path target/coverage/lcov.info
- cargo +nightly llvm-cov report --summary-only
- echo "coverage summary: target/coverage/summary.json"
- echo "coverage lcov: target/coverage/lcov.info"
- '';
+ helpers = lib.lib.mkServiceHelpers system;
+ toolchain = helpers.mkToolchain {
+ rustToolchainFile = ./rust-toolchain.toml;
};
- fmt = mkApp "fmt" {
- text = ''
- cargo fmt --all --check
- '';
+ nativeInputs = helpers.mkNativeInputs { };
+ craneLib = (crane.mkLib pkgs).overrideToolchain toolchain;
+ source = pkgs.lib.cleanSourceWith {
+ src = ./.;
+ filter =
+ path: type:
+ craneLib.filterCargoSources path type
+ || baseNameOf path == "README";
+ name = "radrootsd-source";
};
- test = mkApp "test" {
- text = ''
- cargo test
- '';
+ commonArgs = {
+ src = source;
+ cargoLock = ./Cargo.lock;
+ strictDeps = true;
+ nativeBuildInputs = nativeInputs.nativeBuildInputs;
+ buildInputs = nativeInputs.buildInputs;
+ env = nativeInputs.environment;
+ doCheck = false;
};
- }
- );
-
- devShells = forAllSystems (
- {
- basePackages,
- darwinLdFlags,
- darwinRustFlags,
- includePath,
- libraryPath,
- pkgs,
- ...
- }:
- {
- default = pkgs.mkShell {
- packages = basePackages;
- shellHook = ''
- export LIBCLANG_PATH="${pkgs.llvmPackages.libclang.lib}/lib"
- export LIBRARY_PATH="${libraryPath}:''${LIBRARY_PATH:-}"
- export DYLD_FALLBACK_LIBRARY_PATH="${libraryPath}:''${DYLD_FALLBACK_LIBRARY_PATH:-}"
- export LDFLAGS="${darwinLdFlags} ''${LDFLAGS:-}"
- export NIX_LDFLAGS="${darwinLdFlags} ''${NIX_LDFLAGS:-}"
- export RUSTFLAGS="${darwinRustFlags} ''${RUSTFLAGS:-}"
- export CPATH="${includePath}:''${CPATH:-}"
- '';
+ cargoArtifacts = craneLib.buildDepsOnly commonArgs;
+ package = craneLib.buildPackage (
+ commonArgs
+ // {
+ inherit cargoArtifacts;
+ pname = "radrootsd";
+ version = "0.1.0";
+ CARGO_PROFILE = "release";
+ cargoExtraArgs = "--locked --package radrootsd --bin radrootsd";
+ }
+ );
+ check = craneLib.mkCargoDerivation (
+ commonArgs
+ // {
+ inherit cargoArtifacts;
+ pname = "radrootsd-check";
+ version = "1";
+ buildPhaseCargoCommand = "cargo check --locked --package radrootsd --all-targets";
+ installPhaseCommand = "mkdir -p $out";
+ }
+ );
+ app = {
+ type = "app";
+ program = "${package}/bin/radrootsd";
+ meta.description = "Run the built radrootsd daemon";
};
- }
- );
+ in
+ {
+ inherit app check package;
+ };
+ in
+ {
+ packages = forAllSystems (system: {
+ default = (daemonOutputs system).package;
+ });
+ checks = forAllSystems (system: {
+ default = (daemonOutputs system).check;
+ });
+ apps = forAllSystems (system: {
+ default = (daemonOutputs system).app;
+ });
};
}
diff --git a/tests/package_boundary.rs b/tests/package_boundary.rs
@@ -2,6 +2,7 @@
const ROOT: &str = include_str!("../src/lib.rs");
const PUBLIC_API: &str = include_str!("../contracts/api_baselines/radrootsd.txt");
+const FLAKE: &str = include_str!("../flake.nix");
#[test]
fn implementation_modules_are_private_and_api_is_owned() {
@@ -29,3 +30,36 @@ fn public_error_is_redacted_and_source_free() {
}
assert!(!PUBLIC_API.contains("std::io::Error"));
}
+
+#[test]
+fn nix_outputs_are_real_owned_and_exactly_bounded() {
+ for required in [
+ "github:radrootslabs/lib/055096853fca95e15d0f813d33a14aca13be3881",
+ "systems = lib.lib.supportedSystems",
+ "craneLib.buildPackage",
+ "craneLib.mkCargoDerivation",
+ "program = \"${package}/bin/radrootsd\"",
+ "default = (daemonOutputs system).package",
+ "default = (daemonOutputs system).check",
+ "default = (daemonOutputs system).app",
+ ] {
+ assert!(
+ FLAKE.contains(required),
+ "missing governed Nix source: {required}"
+ );
+ }
+ for forbidden in [
+ "writeShellApplication",
+ "git rev-parse",
+ "repo_root",
+ "devShells",
+ "nixosModules",
+ "aarch64-linux",
+ "x86_64-darwin",
+ ] {
+ assert!(
+ !FLAKE.contains(forbidden),
+ "forbidden Nix surface is present: {forbidden}"
+ );
+ }
+}