fix(nix): build bcrypt's native binding again under pnpm 10 — unbreaks nsecbunkerd on aio-demo #54

Merged
padreug merged 2 commits from fix/pnpm10-bcrypt-native-build into dev 2026-09-05 19:00:02 +00:00
Showing only changes of commit e05e184785 - Show all commits

fix(nix): give the launcher a shell and coreutils/gnused on PATH
Some checks failed
Docker image / build-and-push-image (push) Has been cancelled

scripts/start.js shells out to `npm run prisma:migrate`, but the wrapper
only put nodejs and openssl on PATH, so npm could not spawn a shell at
all and every boot logged

  npm error syscall spawn sh
  npm error enoent spawn sh ENOENT

This was never fatal — the systemd unit's ExecStartPre already applies
migrations — but it is pure noise in the journal and it made the real
bcrypt crash harder to spot.

A shell alone is not enough: pnpm's generated node_modules/.bin/prisma
is itself a /bin/sh script that resolves its basedir with `dirname` and
`sed`. Ship bash, coreutils and gnused so the launcher stands on its own
under any caller's environment — the systemd unit's PATH, docker
compose, or a bare shell — rather than depending on what the caller
happens to export.

Verified: with PATH set to /nonexistent, the wrapper now applies all 25
migrations and starts the daemon cleanly.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QBjd9Rw4ct134JH3CnLVaw
Padreug 2026-09-05 20:58:26 +02:00

View file

@ -9,6 +9,9 @@
# 7.x in nixpkgs which doesn't ship libquery_engine.node, so we'd fail # 7.x in nixpkgs which doesn't ship libquery_engine.node, so we'd fail
# at postinstall. # at postinstall.
prisma-engines_6, prisma-engines_6,
bash,
coreutils,
gnused,
openssl, openssl,
sqlite, sqlite,
python311, python311,
@ -131,7 +134,22 @@ stdenv.mkDerivation (finalAttrs: {
makeWrapper ${lib.getExe nodejs_24} $out/bin/nsecbunkerd \ makeWrapper ${lib.getExe nodejs_24} $out/bin/nsecbunkerd \
--add-flags $out/share/nsecbunkerd/scripts/start.js \ --add-flags $out/share/nsecbunkerd/scripts/start.js \
--set NODE_ENV production \ --set NODE_ENV production \
--prefix PATH : ${lib.makeBinPath [ openssl nodejs_24 ]} \ --prefix PATH : ${
lib.makeBinPath [
openssl
nodejs_24
# scripts/start.js shells out to `npm run prisma:migrate`, and
# npm needs a shell to spawn at all. The pnpm-generated
# `node_modules/.bin/prisma` shim is itself a /bin/sh script
# that resolves its basedir with `dirname` + `sed`. Ship all
# three so the launcher works under any caller's environment
# (the systemd unit's PATH, docker compose, a bare shell)
# rather than depending on what the caller happens to export.
bash
coreutils
gnused
]
} \
${ ${
lib.concatStringsSep " \\\n " ( lib.concatStringsSep " \\\n " (
lib.mapAttrsToList (n: v: "--set ${n} ${lib.escapeShellArg v}") prismaEnv lib.mapAttrsToList (n: v: "--set ${n} ${lib.escapeShellArg v}") prismaEnv