fix(nix): build bcrypt's native binding again under pnpm 10
0d8c436 (nodejs_20/pnpm_9 -> nodejs_24/pnpm_10) shipped a package with
no compiled bcrypt, and nsecbunkerd has been crashlooping on aio-demo
ever since: dist/daemon/index.js requires bcrypt at load, the store path
has only binding.gyp and the C++ sources under bcrypt@5.1.1, and the
daemon dies instantly with
Cannot find module '.../bcrypt/lib/binding/napi-v3/bcrypt_lib.node'
buildPhase re-runs `pnpm install --force --offline` specifically to fire
bcrypt's node-gyp postinstall, because configHook installs with
--ignore-scripts. pnpm 10 changed that contract: it refuses to run *any*
dependency lifecycle script unless the package is allow-listed, and it
skips them silently — the install still reports success. So the bump
turned that line into a no-op, the build kept passing, and the failure
only surfaced at boot on the deployed host.
Pass --config.dangerouslyAllowAllBuilds=true to restore the pnpm 9
semantics this build has always relied on. We run inside the nix sandbox
against a store-seeded offline cache, so "all builds" is the same closed
set of scripts pnpm 9 already ran.
Add an installCheckPhase that requires bcrypt from the *installed* $out
tree, the same way the daemon does. This failure mode is invisible at
build time and fatal at boot, so it has to break the build instead of
the host.
Verified against the nixpkgs the deploy uses (da5ad661):
lib/binding/napi-v3/bcrypt_lib.node is produced, installCheck prints
"bcrypt native binding loads OK", and the daemon reaches
"nsecBunker ready to serve requests." pnpmDeps hash is unchanged.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QBjd9Rw4ct134JH3CnLVaw
This commit is contained in:
parent
0d8c436f66
commit
d2ec84a18e
1 changed files with 31 additions and 1 deletions
32
package.nix
32
package.nix
|
|
@ -80,7 +80,21 @@ stdenv.mkDerivation (finalAttrs: {
|
|||
# configHook ran with --ignore-scripts; re-run install to trigger
|
||||
# native-module postinstall (bcrypt). --offline keeps it inside the
|
||||
# store seeded by configHook.
|
||||
pnpm install --force --offline --frozen-lockfile --reporter=append-only
|
||||
#
|
||||
# `dangerouslyAllowAllBuilds` is load-bearing under pnpm 10: unlike
|
||||
# pnpm 9, pnpm 10 refuses to run *any* dependency lifecycle script
|
||||
# unless the package is allow-listed (`onlyBuiltDependencies` /
|
||||
# `pnpm approve-builds`), and it skips them **silently** — the install
|
||||
# still reports success. Without this, bcrypt's node-gyp postinstall
|
||||
# never runs, `lib/binding/napi-v3/bcrypt_lib.node` is never produced,
|
||||
# and the daemon dies at boot with MODULE_NOT_FOUND. That is exactly
|
||||
# what shipped in 0d8c436 (the nodejs_20/pnpm_9 -> nodejs_24/pnpm_10
|
||||
# bump) and took down nsecbunkerd on aio-demo. The flag restores the
|
||||
# pnpm 9 semantics this build has always relied on; we are inside the
|
||||
# nix sandbox against a store-seeded offline cache, so "all builds"
|
||||
# is the same closed set of scripts pnpm 9 ran.
|
||||
pnpm install --force --offline --frozen-lockfile --reporter=append-only \
|
||||
--config.dangerouslyAllowAllBuilds=true
|
||||
|
||||
pnpm prisma generate
|
||||
pnpm build
|
||||
|
|
@ -132,6 +146,22 @@ stdenv.mkDerivation (finalAttrs: {
|
|||
runHook postInstall
|
||||
'';
|
||||
|
||||
doInstallCheck = true;
|
||||
|
||||
# The bcrypt failure mode is silent at build time and fatal at boot, so
|
||||
# assert the native binding loads from the *installed* tree exactly the
|
||||
# way `dist/daemon/index.js` loads it. A build that can't require bcrypt
|
||||
# must fail here rather than on the deployed host.
|
||||
installCheckPhase = ''
|
||||
runHook preInstallCheck
|
||||
|
||||
${lib.getExe nodejs_24} -e \
|
||||
"require('$out/share/nsecbunkerd/node_modules/bcrypt'); \
|
||||
console.log('bcrypt native binding loads OK')"
|
||||
|
||||
runHook postInstallCheck
|
||||
'';
|
||||
|
||||
passthru = {
|
||||
inherit prisma-engines;
|
||||
};
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue