It's possible to put a path into the store in pure mode by pretending
it's locked like this:
$ echo 'lalala' > testfile
$ nix eval --expr '(builtins.fetchTree { path = "/home/ma27/testfile"; rev = "0000000000000000000000000000000000000000"; type = "path"; })'
{ lastModified = 1723656303; lastModifiedDate = "20240814172503"; narHash = "sha256-hOMY06A0ohaaCLwnhpZIMoAqi/8kG2vk30NRiqi0dfc="; outPath = "/nix/store/lhfz259iipmv9ky995rml8018jvriynh-source"; rev = "0000000000000000000000000000000000000000"; shortRev = "0000000"; }
$ cat /nix/store/lhfz259iipmv9ky995rml8018jvriynh-source
lalala
There was a fix in CppNix[1], but Puck noted that it's breaking
backwards-compatibility because
> [...] a github fetch with a fully specified rev is no longer considered "locked"
> this is for "purity" reasons, but it breaks any existing flake.nix files
I tried a way smaller correctness fix here:
* Each scheme can denote whether a `rev` is enough to consider itself
locked.
* If a `rev` is given and the scheme is OK with just a `rev` to be
locked, the input is marked as locked.
For `path` this is not the case anymore, i.e. it requires a NAR hash to
be locked down.
[1] https://github.com/nixos/nix/commit/071dd2b3a4e6c0b2106f1b6f14ec26e153d97446
Change-Id: Ibbbf4733c82bcfa1c24dfe099a896d8aaecd81cc
97 lines
3.6 KiB
Bash
97 lines
3.6 KiB
Bash
source common.sh
|
|
|
|
requireGit
|
|
|
|
clearStore
|
|
|
|
testFetchTreeError() {
|
|
rawFetchTreeArg="${1?fetchTree arg missing}"
|
|
messageSubstring="${2?messageSubstring missing}"
|
|
|
|
output="$(nix eval --impure --raw --expr "(builtins.fetchTree $rawFetchTreeArg).outPath" 2>&1)" && status=0 || status=$?
|
|
grepQuiet "$messageSubstring" <<<"$output"
|
|
test "$status" -ne 0
|
|
}
|
|
|
|
# github/gitlab/sourcehut fetcher input validation
|
|
for provider in github gitlab sourcehut; do
|
|
# ref/rev validation
|
|
testFetchTreeError \
|
|
"{ type = \"$provider\"; owner = \"foo\"; repo = \"bar\"; ref = \",\"; }" \
|
|
"URL '$provider:foo/bar' contains an invalid branch/tag name"
|
|
|
|
testFetchTreeError \
|
|
"\"$provider://host/foo/bar/,\"" \
|
|
"URL '$provider:foo/bar', ',' is not a commit hash or a branch/tag name"
|
|
|
|
testFetchTreeError \
|
|
"\"$provider://host/foo/bar/f16d8f43dd0998cdb315a2cccf2e4d10027e7ca4?rev=abc\"" \
|
|
"URL '$provider://host/foo/bar/f16d8f43dd0998cdb315a2cccf2e4d10027e7ca4?rev=abc' already contains a ref or rev"
|
|
|
|
testFetchTreeError \
|
|
"\"$provider://host/foo/bar/ref?ref=ref2\"" \
|
|
"URL '$provider://host/foo/bar/ref?ref=ref2' already contains a ref or rev"
|
|
|
|
# host validation
|
|
testFetchTreeError \
|
|
"{ type = \"$provider\"; owner = \"foo\"; repo = \"bar\"; host = \"git_hub.com\"; }" \
|
|
"URL '$provider:foo/bar' contains an invalid instance host"
|
|
|
|
testFetchTreeError \
|
|
"\"$provider://host/foo/bar/ref?host=git_hub.com\"" \
|
|
"URL '$provider:foo/bar' contains an invalid instance host"
|
|
|
|
# invalid attributes
|
|
testFetchTreeError \
|
|
"{ type = \"$provider\"; owner = \"foo\"; repo = \"bar\"; wrong = true; }" \
|
|
"unsupported input attribute 'wrong'"
|
|
|
|
testFetchTreeError \
|
|
"\"$provider://host/foo/bar/ref?wrong=1\"" \
|
|
"unsupported input attribute 'wrong'"
|
|
done
|
|
|
|
# unsupported attributes w/ tarball fetcher
|
|
testFetchTreeError \
|
|
"\"https://host/foo?wrong=1\"" \
|
|
"unsupported tarball input attribute 'wrong'. If you wanted to fetch a tarball with a query parameter, please use '{ type = \"tarball\"; url = \"...\"; }"
|
|
|
|
# test for unsupported attributes / validation in git fetcher
|
|
testFetchTreeError \
|
|
"\"git+https://github.com/owner/repo?invalid=1\"" \
|
|
"unsupported Git input attribute 'invalid'"
|
|
|
|
testFetchTreeError \
|
|
"\"git+https://github.com/owner/repo?url=foo\"" \
|
|
"URL 'git+https://github.com/owner/repo?url=foo' must not override url via query param!"
|
|
|
|
testFetchTreeError \
|
|
"\"git+https://github.com/owner/repo?ref=foo.lock\"" \
|
|
"invalid Git branch/tag name 'foo.lock'"
|
|
|
|
testFetchTreeError \
|
|
"{ type = \"git\"; url =\"https://github.com/owner/repo\"; ref = \"foo.lock\"; }" \
|
|
"invalid Git branch/tag name 'foo.lock'"
|
|
|
|
# same for mercurial
|
|
testFetchTreeError \
|
|
"\"hg+https://forge.tld/owner/repo?invalid=1\"" \
|
|
"unsupported Mercurial input attribute 'invalid'"
|
|
|
|
testFetchTreeError \
|
|
"{ type = \"hg\"; url = \"https://forge.tld/owner/repo\"; invalid = 1; }" \
|
|
"unsupported Mercurial input attribute 'invalid'"
|
|
|
|
testFetchTreeError \
|
|
"\"hg+https://forge.tld/owner/repo?ref=,\"" \
|
|
"invalid Mercurial branch/tag name ','"
|
|
|
|
testFetchTreeError \
|
|
"{ type = \"hg\"; url = \"https://forge.tld/owner/repo\"; ref = \",\"; }" \
|
|
"invalid Mercurial branch/tag name ','"
|
|
|
|
echo 'hello lix' > testfile
|
|
output="$(nix eval --expr '(builtins.fetchTree { path = "'"$(pwd)"'/testfile"; rev = "0000000000000000000000000000000000000000"; type = "path"; })' 2>&1)" && status=0 || status=$?
|
|
[ "$status" -eq 1 ]
|
|
grepQuiet "error: in pure evaluation mode, 'fetchTree' requires a locked input" <<<"$output"
|