fix(nix): build bcrypt's native binding again under pnpm 10 — unbreaks nsecbunkerd on aio-demo #54
1 changed files with 50 additions and 2 deletions
52
package.nix
52
package.nix
|
|
@ -9,6 +9,9 @@
|
||||||
# 7.x in nixpkgs which doesn't ship libquery_engine.node, so we'd fail
|
# 7.x in nixpkgs which doesn't ship libquery_engine.node, so we'd fail
|
||||||
# at postinstall.
|
# at postinstall.
|
||||||
prisma-engines_6,
|
prisma-engines_6,
|
||||||
|
bash,
|
||||||
|
coreutils,
|
||||||
|
gnused,
|
||||||
openssl,
|
openssl,
|
||||||
sqlite,
|
sqlite,
|
||||||
python311,
|
python311,
|
||||||
|
|
@ -80,7 +83,21 @@ stdenv.mkDerivation (finalAttrs: {
|
||||||
# configHook ran with --ignore-scripts; re-run install to trigger
|
# configHook ran with --ignore-scripts; re-run install to trigger
|
||||||
# native-module postinstall (bcrypt). --offline keeps it inside the
|
# native-module postinstall (bcrypt). --offline keeps it inside the
|
||||||
# store seeded by configHook.
|
# store seeded by configHook.
|
||||||
pnpm install --force --offline --frozen-lockfile --reporter=append-only
|
#
|
||||||
|
# `dangerouslyAllowAllBuilds` is load-bearing under pnpm 10: unlike
|
||||||
|
# pnpm 9, pnpm 10 refuses to run *any* dependency lifecycle script
|
||||||
|
# unless the package is allow-listed (`onlyBuiltDependencies` /
|
||||||
|
# `pnpm approve-builds`), and it skips them **silently** — the install
|
||||||
|
# still reports success. Without this, bcrypt's node-gyp postinstall
|
||||||
|
# never runs, `lib/binding/napi-v3/bcrypt_lib.node` is never produced,
|
||||||
|
# and the daemon dies at boot with MODULE_NOT_FOUND. That is exactly
|
||||||
|
# what shipped in 0d8c436 (the nodejs_20/pnpm_9 -> nodejs_24/pnpm_10
|
||||||
|
# bump) and took down nsecbunkerd on aio-demo. The flag restores the
|
||||||
|
# pnpm 9 semantics this build has always relied on; we are inside the
|
||||||
|
# nix sandbox against a store-seeded offline cache, so "all builds"
|
||||||
|
# is the same closed set of scripts pnpm 9 ran.
|
||||||
|
pnpm install --force --offline --frozen-lockfile --reporter=append-only \
|
||||||
|
--config.dangerouslyAllowAllBuilds=true
|
||||||
|
|
||||||
pnpm prisma generate
|
pnpm prisma generate
|
||||||
pnpm build
|
pnpm build
|
||||||
|
|
@ -117,7 +134,22 @@ stdenv.mkDerivation (finalAttrs: {
|
||||||
makeWrapper ${lib.getExe nodejs_24} $out/bin/nsecbunkerd \
|
makeWrapper ${lib.getExe nodejs_24} $out/bin/nsecbunkerd \
|
||||||
--add-flags $out/share/nsecbunkerd/scripts/start.js \
|
--add-flags $out/share/nsecbunkerd/scripts/start.js \
|
||||||
--set NODE_ENV production \
|
--set NODE_ENV production \
|
||||||
--prefix PATH : ${lib.makeBinPath [ openssl nodejs_24 ]} \
|
--prefix PATH : ${
|
||||||
|
lib.makeBinPath [
|
||||||
|
openssl
|
||||||
|
nodejs_24
|
||||||
|
# scripts/start.js shells out to `npm run prisma:migrate`, and
|
||||||
|
# npm needs a shell to spawn at all. The pnpm-generated
|
||||||
|
# `node_modules/.bin/prisma` shim is itself a /bin/sh script
|
||||||
|
# that resolves its basedir with `dirname` + `sed`. Ship all
|
||||||
|
# three so the launcher works under any caller's environment
|
||||||
|
# (the systemd unit's PATH, docker compose, a bare shell)
|
||||||
|
# rather than depending on what the caller happens to export.
|
||||||
|
bash
|
||||||
|
coreutils
|
||||||
|
gnused
|
||||||
|
]
|
||||||
|
} \
|
||||||
${
|
${
|
||||||
lib.concatStringsSep " \\\n " (
|
lib.concatStringsSep " \\\n " (
|
||||||
lib.mapAttrsToList (n: v: "--set ${n} ${lib.escapeShellArg v}") prismaEnv
|
lib.mapAttrsToList (n: v: "--set ${n} ${lib.escapeShellArg v}") prismaEnv
|
||||||
|
|
@ -132,6 +164,22 @@ stdenv.mkDerivation (finalAttrs: {
|
||||||
runHook postInstall
|
runHook postInstall
|
||||||
'';
|
'';
|
||||||
|
|
||||||
|
doInstallCheck = true;
|
||||||
|
|
||||||
|
# The bcrypt failure mode is silent at build time and fatal at boot, so
|
||||||
|
# assert the native binding loads from the *installed* tree exactly the
|
||||||
|
# way `dist/daemon/index.js` loads it. A build that can't require bcrypt
|
||||||
|
# must fail here rather than on the deployed host.
|
||||||
|
installCheckPhase = ''
|
||||||
|
runHook preInstallCheck
|
||||||
|
|
||||||
|
${lib.getExe nodejs_24} -e \
|
||||||
|
"require('$out/share/nsecbunkerd/node_modules/bcrypt'); \
|
||||||
|
console.log('bcrypt native binding loads OK')"
|
||||||
|
|
||||||
|
runHook postInstallCheck
|
||||||
|
'';
|
||||||
|
|
||||||
passthru = {
|
passthru = {
|
||||||
inherit prisma-engines;
|
inherit prisma-engines;
|
||||||
};
|
};
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue