1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
|
# One job, because the flake is the build.
#
# This used to be a kaniko pipeline whose only purpose was to publish the
# container image buck2's remote executor pulled; nothing about it ran the
# build. `nix flake check` runs fmt, clippy, the test suite and all three
# shared objects, and it pins what it runs with.
#
# The publish step is in the same job for the same reason: a second job would
# get a cold nix store and rebuild everything it was about to upload. The
# branch check is a shell `if` rather than a second job's `rules:` because
# there is nothing to gate but the last two commands.
stages: [check]
check:
stage: check
image: nixos/nix:latest
variables:
# The flake is fetched from the checkout, so the runner needs the git tree
# rather than a shallow single commit.
GIT_DEPTH: "0"
before_script:
- echo "experimental-features = nix-command flakes" >> /etc/nix/nix.conf
script:
- nix flake check -L
# The store paths are read-only symlink farms; the runner uploads plain
# files, so dereference them into a tree it can zip.
- nix build -L --no-link --print-out-paths .#libs .#android > /tmp/outs
- mkdir -p artifacts && xargs -a /tmp/outs -I{} cp -rL {}/. artifacts/
# Tarballs rooted at lib/ and include/, so a consumer's `flake = false`
# input resolves to ${input}/lib/libjoltmoq.so with nothing in between.
# One per target: the desktop objects carry a RUNPATH into the builder's
# /nix/store and are only usable from nix, the Android ones link nothing
# but the NDK sysroot and are what an APK actually packages.
- |
set -eu
if [ "$CI_COMMIT_BRANCH" = "$CI_DEFAULT_BRANCH" ]; then
tar czf x86_64-linux.tar.gz -C artifacts include lib/libvidya.so lib/libjolttui.so lib/libjoltmoq.so
tar czf android-arm64-v8a.tar.gz -C artifacts include lib/arm64-v8a
base="$CI_API_V4_URL/projects/$CI_PROJECT_ID/packages/generic/jolt-native/$CI_COMMIT_SHA"
nix shell nixpkgs#curl -c sh -eu -c '
for f in x86_64-linux.tar.gz android-arm64-v8a.tar.gz; do
curl --fail-with-body --header "JOB-TOKEN: $CI_JOB_TOKEN" \
--upload-file "$f" "$1/$f"
done
' sh "$base"
fi
artifacts:
name: "jolt-native-$CI_COMMIT_SHORT_SHA"
paths: [artifacts/]
expire_in: 1 week
rules:
- if: $CI_PIPELINE_SOURCE == "merge_request_event"
- if: $CI_COMMIT_BRANCH == $CI_DEFAULT_BRANCH
|