diff --git a/nix/mkAtmApp.nix b/nix/mkAtmApp.nix index 527d259..3e1102d 100644 --- a/nix/mkAtmApp.nix +++ b/nix/mkAtmApp.nix @@ -190,6 +190,33 @@ pkgs.stdenv.mkDerivation (finalAttrs: { copy_pnpm_pkg "@serialport/$parser" "$out/node_modules/@serialport/$parser" done + # ── Strip node-gyp build detritus ────────────────────────────────── + # node-gyp leaves its scaffolding beside the compiled addons, and several + # of those files embed absolute /nix/store paths to the BUILD toolchain: + # build/node_gyp_bins/python3 an ELF copy of python3 with an RPATH + # build/config.gypi python3 + nodejs + npm paths + # build/Release/.deps/**.o.d pcsclite.dev include paths + # Nix scans $out for store hashes, so each becomes a RUNTIME reference and + # drags python311 + nodejs + npm + pcsclite.dev (~212MB of closure) onto + # every ATM. Nothing reads them at runtime — only build/Release/*.node is + # loaded, via `bindings` / `node-gyp-build`. Keep the addons, drop the + # scaffolding. obj.target/*.node is node-gyp's pre-copy of the same addon; + # the loaded one at build/Release/*.node is untouched. + find $out/node_modules -type d \ + \( -name node_gyp_bins -o -name .deps -o -name obj.target -o -name obj \) \ + -prune -exec rm -rf {} + + find $out/node_modules -path '*/build/*' -type f \ + \( -name config.gypi -o -name '*.mk' -o -name Makefile \ + -o -name binding.Makefile -o -name '*.a' -o -name '*.o' \) -delete + + # pnpm/node-gyp rewrote these CLI helpers' shebangs to the build nodejs, + # which alone retains the full nodejs (not the slim one Electron needs). + # They are build-time utilities — the runtime entry of each package + # (index.js) carries no shebang — so point them at PATH instead of + # deleting files a package might still require. + find $out/node_modules -type f -name '*.js' \ + -exec sed -i '1s|^#!/nix/store/[^ ]*/bin/node$|#!/usr/bin/env node|' {} + + runHook postInstall '';