The clippy check's comment described `-D warnings -A clippy::pedantic` — the `-A` half dropping pedantic from the CI gate — but the args were only `-D warnings`, so pedantic was hard-denied contrary to the doc. Operator call: pedantic should be gated. Encode that as the single source of truth: set the workspace lint `pedantic = deny` (errors locally and in CI), and rewrite the checks.nix comment to match. Args unchanged; `-D warnings` still gates rustc + non-pedantic clippy warnings. No new failures — the tree was already pedantic-clean under CI's `-D warnings`, which denied pedantic.
95 lines
4.2 KiB
Nix
95 lines
4.2 KiB
Nix
# Flake checks: formatting, the clippy gate, the workspace test run,
|
|
# the nix-options docs eval, and the hivectl CLI-reference freshness
|
|
# check. Imported per system from flake.nix.
|
|
{
|
|
pkgs,
|
|
craneLib,
|
|
rust,
|
|
self,
|
|
system,
|
|
treefmt-eval,
|
|
}:
|
|
let
|
|
inherit (rust) cleanSrc cargoArtifacts nativeBuildInputs;
|
|
in
|
|
{
|
|
formatting = treefmt-eval.config.build.check self;
|
|
|
|
# Clippy via crane's first-class `cargoClippy` builder. Reuses the
|
|
# shared `cargoArtifacts` (deps already built) and runs
|
|
# `cargo clippy --workspace --all-targets` directly.
|
|
#
|
|
# `-D warnings` makes every rustc/clippy warning a hard CI gate.
|
|
# Pedantic is gated too, deliberately: the workspace lint table
|
|
# (Cargo.toml) sets `pedantic = deny`, so pedantic lints are errors
|
|
# both locally and here. We want that — a toolchain bump that adds a
|
|
# new pedantic lint reds the build until the code is updated, rather
|
|
# than sliding in unnoticed. (The lint table allows a few noisy
|
|
# pedantic lints explicitly, e.g. `must_use_candidate`; those keep
|
|
# their allow via higher priority.)
|
|
clippy = craneLib.cargoClippy {
|
|
src = cleanSrc;
|
|
inherit cargoArtifacts nativeBuildInputs;
|
|
pname = "hyperhive-workspace";
|
|
version = "0.1.0";
|
|
cargoClippyExtraArgs = "--workspace --all-targets -- -D warnings";
|
|
};
|
|
|
|
# `cargo test --workspace` lifted out of the package builds so the
|
|
# `hyperhive-assets` dep (which `hive-agent::prompt::tests`
|
|
# needs via `HIVE_ASSETS_DIR` to assert against the actual
|
|
# production prompt template) is scoped to this one check
|
|
# instead of bleeding into the binary derivations' input
|
|
# hash. Net: editing `hive-agent/prompts/system.md` still
|
|
# rebuilds this test check (correct — the tests assert
|
|
# against its wording), but `packages.default` and the
|
|
# per-container toplevels stay fully cached.
|
|
cargo-test = craneLib.cargoTest {
|
|
src = cleanSrc;
|
|
inherit cargoArtifacts nativeBuildInputs;
|
|
pname = "hyperhive-workspace";
|
|
version = "0.1.0";
|
|
cargoTestExtraArgs = "--workspace";
|
|
HIVE_ASSETS_DIR = "${self.packages.${system}.assets}/share/hyperhive";
|
|
};
|
|
|
|
# Nix options docs evaluation. Cheap: pulls in `nixosOptionsDoc` +
|
|
# the host module's stub eval, no rust or frontend deps. CI fails
|
|
# fast if a module change breaks option declarations or the doc
|
|
# rendering. Reuses the `packages.<system>.docs` derivation so the
|
|
# per-system eval of nix/docs/default.nix happens once.
|
|
inherit (self.packages.${system}) docs;
|
|
|
|
# Frontend build. Builds the `hyperhive-frontend` npm package, whose
|
|
# fixed-output npm-deps derivation pins `npmDepsHash`
|
|
# (nix/packages/frontend.nix). No other check exercises that FOD:
|
|
# `cargo-test` forces `.#assets`, but `assets` carries no frontend
|
|
# dependency, so without this check a stale `npmDepsHash` after a
|
|
# `package-lock.json` bump that forgets to recompute it sails through
|
|
# every PR and only breaks when the host toplevel is built on deploy.
|
|
# Reusing the already-defined `packages.<system>.frontend` derivation
|
|
# makes such a hash mismatch a red PR instead of a red main.
|
|
inherit (self.packages.${system}) frontend;
|
|
|
|
# `hivectl` CLI reference freshness check. The committed
|
|
# markdown at `docs/tools/hivectl-cli.md` is the rendered
|
|
# output of the hidden `hivectl markdown-docs` subcommand
|
|
# (clap-markdown walks the binary's own command tree). This
|
|
# check regenerates it from the built binary and fails if the
|
|
# committed copy drifted — so a verb / flag / help-string edit
|
|
# that forgets to refresh the doc is caught in CI. Reuses the
|
|
# already-built `packages.<system>.default` (no extra compile).
|
|
# Regenerate locally with:
|
|
# nix build .#default
|
|
# ./result/bin/hivectl markdown-docs > docs/tools/hivectl-cli.md
|
|
hivectl-docs = pkgs.runCommand "hivectl-docs-fresh" { nativeBuildInputs = [ pkgs.diffutils ]; } ''
|
|
${self.packages.${system}.default}/bin/hivectl markdown-docs > generated.md
|
|
if ! diff -u ${../docs/tools/hivectl-cli.md} generated.md; then
|
|
echo "" >&2
|
|
echo "ERROR: docs/tools/hivectl-cli.md is out of date — regenerate it:" >&2
|
|
echo " nix build .#default && ./result/bin/hivectl markdown-docs > docs/tools/hivectl-cli.md" >&2
|
|
exit 1
|
|
fi
|
|
touch "$out"
|
|
'';
|
|
}
|