Add Nix flake support with source build, prebuilt, and desktop outputs - #5
Draft
levonk wants to merge 18 commits into
Draft
Add Nix flake support with source build, prebuilt, and desktop outputs#5levonk wants to merge 18 commits into
levonk wants to merge 18 commits into
Conversation
…skills-lock.json)
Member
|
Hi @levonk thanks for contributing! |
levonk
added a commit
to levonk/acryl
that referenced
this pull request
Sep 2, 2026
…D hash Four fixes for the CI failures on PR acryldev#5: 1. Rebase onto upstream/main (was 11 commits behind — caused the "Typecheck, test, and build" failure on a test already fixed on main) 2. Add use-flakehub: false to magic-nix-cache-action (the action defaults to use-flakehub: true, which attempts FlakeHub OIDC auth and breaks CI for orgs without a FlakeHub account — root cause of the "Unable to authenticate to FlakeHub" error) 3. Add timeout-minutes: 20 to the build job (was missing — GitHub's default max is 6h, caused the aarch64-darwin job to hang) 4. Update fetchPnpmDeps hash (stale after rebase picked up new upstream pnpm-lock.yaml changes)
levonk
force-pushed
the
feature/nix-flake-support
branch
from
September 2, 2026 20:30
aa04fae to
cfa8b92
Compare
levonk
marked this pull request as draft
September 2, 2026 23:08
levonk
marked this pull request as ready for review
September 3, 2026 03:02
Member
|
Resolved the conflict against current The resolution preserves both branches' development-log entries. I ran the repository suite in the merged worktree: 806 ACRYL tests and 274 Market tests passed. The five refreshed GitHub checks are now running; I will use those as the final merge gate. |
.devin/, agent/, skills-lock.json, and /.agents/ (untracked scaffolding) are machine-local agent artifacts, not project config. Move them out of the shared .gitignore; keep them ignored via .git/info/exclude on each machine instead.
Add Nix flake support targeting the acryl-tui terminal client. The flake uses nixpkgs' modern PNPM hooks (fetchPnpmDeps, pnpmConfigHook) with pnpm_11 and fetcherVersion 4. Key design decisions: - Targets acryl-tui (not the Electron desktop app) as the default package, exposing the `acryl` binary via `nix run .#acryl` - Uses nixpkgs-26.05-darwin legacy pin for x86_64-darwin (Intel macOS), since nixpkgs-unstable dropped support after 26.05 - Forces nodeLinker: hoisted in pnpm-workspace.yaml during the build to flatten node_modules (pnpm 11 moved this setting from .npmrc) - Builds only the TUI dependency chain (acryl-control -> acryl-harness-runtime -> acryl-tui) instead of the full workspace - Sets dontStrip and dontFixup to avoid slow strip/fixup phases on thousands of JS files in node_modules - ESBUILD_BINARY_PATH points to nixpkgs esbuild to avoid the postinstall binary download (skipped by --ignore-scripts) Also adds: - devbox.json for reproducible development environment - .github/workflows/nix.yml for CI across all 4 supported systems - /result and /result-* to .gitignore
Document the implementation commit d6d2e46 which added Nix flake support for building acryl-tui.
Add `packages.${system}.acryl-desktop` to the flake, building the
Electron desktop app alongside the existing TUI output.
Key decisions:
- Uses nixpkgs electron (43.1.0) as the runtime instead of the npm
electron package (which downloads a platform binary via postinstall,
blocked by --ignore-scripts in the Nix sandbox)
- Creates a CJS shim at node_modules/electron/index.js that exports
the nixpkgs electron path, replacing the real npm package
- Skips the generate-* build scripts (they use sharp for image
processing) since build/ assets are already tracked in git
- Builds the full dependency chain: acryl-control ->
acryl-harness-runtime -> dsh-community-market ->
acryl-development-canvas -> acryl-desktop
- Refactors shared derivation attrs (pnpmDeps, preConfigure, etc.)
into commonDerivationAttrs to avoid duplication between TUI and
desktop derivations
Both outputs verified:
nix run .#acryl -- --help
nix run .#acryl-desktop -- --help
Document implementation commit 397f91034cb6a6444c6dccf6f33d06e8b10bf43b which added the Electron desktop app as a separate Nix package output.
- SHA-pin all GitHub Actions to 40-char commit SHAs (checkout@v5, nix-installer-action@v22, magic-nix-cache-action@v14) instead of mutable @v4/@main refs — prevents supply-chain attacks - Add if: github.event_name != 'pull_request' guard on nix run steps to prevent PR-controlled code from reaching GITHUB_TOKEN/OIDC - Add path filtering to nix.yml (flake.nix, flake.lock, **/*.nix, pnpm-lock.yaml, etc.) so CI only fires when Nix files change - Add nix run .#default -- --help test to CI - Add act to devbox.json packages (required for local CI validation) - Remove invalid nixpkgs.commit field from devbox.json (devbox 0.18 ignores it; was set to channel name not 40-char hash) - Add .devbox/ to .gitignore (devbox generated artifacts) - Add Nix (Flake) and Devbox install sections to README.md, README.en.md, and README.zh.md - Update bilingual-docs hash record in README.i18n.yaml devbox.lock cannot be generated on x86_64-darwin due to devbox 0.18 hardcoding a nixpkgs commit that dropped x86_64-darwin support; generate on aarch64-darwin or Linux.
devbox 0.18 ignores the nixpkgs.commit field for regular package-name resolution and hardcodes nixpkgs 26.11, which dropped x86_64-darwin. Work around this by referencing every package as a flake URL pointing at the nixpkgs-26.05-darwin commit (f6107e5) — flake-based references bypass devbox's package index, and nixpkgs.commit controls the shell infrastructure (mkShell). This works on all platforms: x86_64-darwin, aarch64-darwin, and Linux. Generate and commit devbox.lock for reproducible environments.
Use per-package platform scoping: clean package names (nodejs_22, pnpm_11, esbuild, act) for normal platforms (Linux, aarch64-darwin), and flake URL references to nixpkgs-26.05-darwin only for x86_64-darwin. The nixpkgs.commit field is set to the 26.05-darwin pin for the shell infrastructure (mkShell), which devbox 0.18 honors when all active packages on a platform are flake-based. On normal platforms, packages resolve from nixpkgs-unstable via devbox's index — the same behavior as before. On x86_64-darwin, the flake URL references bypass devbox's hardcoded nixpkgs 26.11 (which dropped x86_64-darwin) and pull from 26.05-darwin instead. The lock file records both resolution paths. Linux/aarch64-darwin entries will be populated when a user on that platform runs devbox install.
Replace all github:levonk/acryl references with github:acryldev/acryl in flake.nix (homepage meta), README.md, README.en.md, README.zh.md, and DEVELOPMENT-LOG.md commit links. Update bilingual-docs hash record.
Add packages.<system>.prebuilt — fetches the prebuilt CLI tarball from GitHub releases (v0.1.19). Each tarball bundles its own Node runtime and native addons (node-pty, koffi, sharp), so no from-source build is needed for the prebuilt path. Uses autoPatchelfHook on Linux for glibc linking. The default output remains #acryl (from-source build), following Nix convention. #prebuilt is an optional fast path for users who want the exact release binary. Add CI steps to build and test #prebuilt on all 4 platforms. Update READMEs to document the #prebuilt output.
…D hash Four fixes for the CI failures on PR acryldev#5: 1. Rebase onto upstream/main (was 11 commits behind — caused the "Typecheck, test, and build" failure on a test already fixed on main) 2. Add use-flakehub: false to magic-nix-cache-action (the action defaults to use-flakehub: true, which attempts FlakeHub OIDC auth and breaks CI for orgs without a FlakeHub account — root cause of the "Unable to authenticate to FlakeHub" error) 3. Add timeout-minutes: 20 to the build job (was missing — GitHub's default max is 6h, caused the aarch64-darwin job to hang) 4. Update fetchPnpmDeps hash (stale after rebase picked up new upstream pnpm-lock.yaml changes)
The preConfigure hook checked `if ! grep -q "nodeLinker"` and only inserted `nodeLinker: hoisted` when the key was absent. But pnpm-workspace.yaml already had `nodeLinker: isolated`, so the sed never ran. The isolated linker creates a .pnpm/ virtual store with symlinks that break when copied to the Nix store, leaving node_modules/ with only 3 entries (the workspace packages) and no registry dependencies like @deepseek-ai/dsh-llm. Replace the value when the key exists, instead of only inserting when missing. After this fix, node_modules/ has 648 packages and all four outputs (default, acryl, prebuilt, acryl-desktop) pass smoke tests.
The prebuilt release tarball bundles both glibc-linked and musl-linked native koffi addons (musl_x64/koffi.node alongside linux_x64/koffi.node). autoPatchelfHook was only finding glibc (stdenv.cc.cc.lib), so it failed with "could not satisfy dependency libc.musl-x86_64.so.1" on Linux. Add pkgs.musl to buildInputs so autoPatchelf can patch both variants.
The magic-nix-cache v14 static binary for arm64-darwin fails on the macos-14 runner with: dyld: Symbol not found: __ZNSt13exception_ptr31__from_native_exception_pointerEPv Expected in: /usr/lib/libc++.1.dylib This is a DeterminateSystems binary incompatibility — the binary was built against a newer libc++ than the runner ships. The build itself never starts; the job hangs for 20 minutes then gets cancelled. Make the cache action Linux-only. Darwin builds work without it, just slower (no cache acceleration). The flake and builds are unaffected.
levonk
marked this pull request as draft
September 9, 2026 23:31
levonk
force-pushed
the
feature/nix-flake-support
branch
from
September 9, 2026 23:31
19fa777 to
b3309f3
Compare
6 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
flake.nixwith#acryl(TUI from source, also#default),#prebuilt(prebuilt CLI release tarball, v0.1.36),#acryl-desktop(Electron from source), anddevShells.default#prebuiltis conditionally exposed only on platforms with a release asset (x86_64-linux, aarch64-linux, aarch64-darwin). v0.1.36 does not ship a darwin-x64 CLI tarball, so#prebuiltis not available onx86_64-darwin— use#defaultor#acrylthere.devbox.json+devbox.lockfor reproducible development environments.github/workflows/nix.yml— CI builds all outputs on x86_64-linux, aarch64-linux, aarch64-darwin, and x86_64-darwin usingmacos-26/macos-26-intelrunners.github/workflows/nix-release.yml— daily hash automation that detects whenflake.nixlags behind the latest GitHub release, prefetches new SRI hashes, and opens a PR.gitignorewith/result,/result-*, and.devbox/Platform scope
The project's CI matrix is Linux-only, but the project ships release binaries for all four Nix target systems (x86_64-linux, aarch64-linux, aarch64-darwin, x86_64-darwin). This flake supports all four systems. The
detect-platform-scope.shnixify detection script reportslinux_onlybecause it inspects.github/workflows/CI matrices, but the release assets cover all four platforms. This override is noted here per the nixify skill's requirement.Supported systems
x86_64-linux— source build + prebuiltaarch64-linux— source build + prebuiltaarch64-darwin— source build + prebuiltx86_64-darwin— source build only (vianixpkgs-26.05-darwinlegacy pin; no prebuilt tarball available for this platform)Relationship to nixpkgs
This project is not currently in nixpkgs. If there is interest in adding it, the flake's
#acrylsource build derivation could serve as the basis for a nixpkgs package expression.Test plan
nix flake check --no-buildpasses on all systemsnix build .#acrylsucceeds on all systemsnix build .#acryl-desktopsucceeds on all systemsnix build .#prebuiltsucceeds on x86_64-linux, aarch64-linux, aarch64-darwinnix run .#acryl -- --helpworksnix run .#prebuilt -- --helpworks (where available)nix run .#acryl-desktop -- --helpworks