diff --git a/frontend/npm-deps-hash b/frontend/npm-deps-hash deleted file mode 100644 index fcb93e72..00000000 --- a/frontend/npm-deps-hash +++ /dev/null @@ -1 +0,0 @@ -sha256-8mYI9b1nuQ8YNFkW/ezJwO5Qw6NJTDG+kspYozs/5cI= \ No newline at end of file diff --git a/nix/checks.nix b/nix/checks.nix index e9e01878..ee4ca537 100644 --- a/nix/checks.nix +++ b/nix/checks.nix @@ -149,8 +149,10 @@ in version = "0.0.0"; src = ../frontend; - # See `nix/packages/frontend.nix`'s comment on the same line. - npmDepsHash = builtins.readFile ../frontend/npm-deps-hash; + # Same lockfile as `frontend`/`swarm-ui` above — recompute in + # lockstep with those two whenever `frontend/package-lock.json` + # changes (`prefetch-npm-deps frontend/package-lock.json`). + npmDepsHash = "sha256-8mYI9b1nuQ8YNFkW/ezJwO5Qw6NJTDG+kspYozs/5cI="; buildPhase = '' runHook preBuild diff --git a/nix/packages/frontend.nix b/nix/packages/frontend.nix index 406065bd..e97c24f0 100644 --- a/nix/packages/frontend.nix +++ b/nix/packages/frontend.nix @@ -35,15 +35,12 @@ buildNpmPackage { version = "0.0.0"; src = ../../frontend; - # Read from `../../frontend/npm-deps-hash`, the single source of - # truth `./swarm-ui.nix` and `../checks.nix`'s `swarm-ui-typecheck` - # also read — all three build from the one `frontend/package-lock.json`, - # so one file keeps them from drifting independently (this used to be - # a hardcoded copy per derivation, and only some of the three got - # updated the one time the lockfile changed). Regenerate with - # `prefetch-npm-deps frontend/package-lock.json` and overwrite the - # file whenever the lockfile changes. - npmDepsHash = builtins.readFile ../../frontend/npm-deps-hash; + # Computed from `frontend/package-lock.json` via + # prefetch-npm-deps frontend/package-lock.json + # Update whenever the lockfile changes. Recompute locally with the + # same command (`pkgs.prefetch-npm-deps`), or let the build fail + # and copy the actual hash from the error message. + npmDepsHash = "sha256-8mYI9b1nuQ8YNFkW/ezJwO5Qw6NJTDG+kspYozs/5cI="; # `npm run build` recurses into all workspaces (`--workspaces # --if-present`). The workspaces' build scripts each run their own diff --git a/nix/packages/swarm-ui.nix b/nix/packages/swarm-ui.nix index 6d750f43..3d2c0d23 100644 --- a/nix/packages/swarm-ui.nix +++ b/nix/packages/swarm-ui.nix @@ -19,12 +19,10 @@ # against authelia is figured out) has something to point at. # # Shares `frontend/package-lock.json` with `./frontend.nix` (same repo, -# same npm workspace root) — `npmDepsHash` is read from -# `../../frontend/npm-deps-hash`, the same file `./frontend.nix` and -# `../checks.nix`'s `swarm-ui-typecheck` read, so all three stay in -# lockstep automatically instead of needing 3 separate hand-edits. -# Scoped to build only the `swarm-ui` workspace (not the whole -# `npm run build --workspaces` frontend.nix runs) via an explicit +# same npm workspace root) — `npmDepsHash` must be updated in lockstep +# with that file's whenever the lockfile changes, since both hash the +# same file. Scoped to build only the `swarm-ui` workspace (not the +# whole `npm run build --workspaces` frontend.nix runs) via an explicit # `npm run build --workspace=…` buildPhase, so a dashboard/agent-only # change doesn't need to rebuild (or re-review the output of) this # derivation. @@ -34,8 +32,10 @@ buildNpmPackage { version = "0.0.0"; src = ../../frontend; - # See `./frontend.nix`'s comment on the same line. - npmDepsHash = builtins.readFile ../../frontend/npm-deps-hash; + # Recompute with `prefetch-npm-deps frontend/package-lock.json` + # whenever the lockfile changes — same value as `./frontend.nix`'s + # `npmDepsHash`, both hash the one shared lockfile. + npmDepsHash = "sha256-8mYI9b1nuQ8YNFkW/ezJwO5Qw6NJTDG+kspYozs/5cI="; buildPhase = '' runHook preBuild