diff --git a/.github/workflows/nix.yml b/.github/workflows/nix.yml new file mode 100644 index 0000000..f79807f --- /dev/null +++ b/.github/workflows/nix.yml @@ -0,0 +1,66 @@ +name: nix + +on: + push: + branches: + - main + paths: + - flake.nix + - flake.lock + - .nix/** + - Cargo.toml + - Cargo.lock + - .github/workflows/nix.yml + pull_request: + branches: + - main + paths: + - flake.nix + - flake.lock + - .nix/** + - Cargo.toml + - Cargo.lock + - .github/workflows/nix.yml + workflow_dispatch: + +permissions: + contents: read + +concurrency: + group: nix-${{ github.ref }} + cancel-in-progress: true + +jobs: + nix: + runs-on: ubuntu-latest + timeout-minutes: 60 + steps: + - uses: actions/checkout@v6 + + - uses: cachix/install-nix-action@v31 + + # skia-bindings' build script does NOT validate the archive passed via + # SKIA_BINARIES_URL (upstream `// TODO: verify key`), so a stale pin + # builds successfully against outdated skia binaries instead of failing. + # Enforce the version match explicitly. + - name: Check skia-binaries pins match Cargo.lock + run: | + crate_version=$(grep -A1 'name = "skia-bindings"' Cargo.lock | sed -n 's/^version = "\(.*\)"/\1/p') + test -n "$crate_version" || { echo "::error::skia-bindings not found in Cargo.lock"; exit 1; } + grep -oE 'https://github.com/rust-skia/skia-binaries/releases/download/[^"]+' flake.nix | while read -r url; do + tag=$(echo "$url" | cut -d/ -f8) + if [ "$tag" != "$crate_version" ]; then + echo "::error::flake.nix pins skia-binaries $tag but Cargo.lock has skia-bindings $crate_version: $url" + exit 1 + fi + done + echo "All skia-binaries pins match skia-bindings $crate_version" + + - name: Verify all pinned flake inputs (all platforms) + run: nix flake archive + + - name: Evaluate flake outputs for all systems + run: nix flake check --all-systems --no-build + + - name: Build packages (x86_64-linux) + run: nix build .#vykar .#vykar-server .#vykar-gui --print-build-logs