feat: introduced nix packaging and path-based binary resolution

- Add comprehensive Nix flake definitions, derivations, modules, and CI workflows.
- Update tests and executables to resolve binaries from PATH rather than absolute paths.
- Ensure byte reproducibility and zeroed timestamps in embedded dashboard archives.
- Add handling for Nix-managed installations in CLI update checks.
This commit is contained in:
can1357
2026-08-13 03:52:47 +02:00
parent 2e492a3076
commit b60bef961c
33 changed files with 3515 additions and 89 deletions
@@ -53,10 +53,6 @@ if (
}
const transformersVersion = transformersManifest.version;
function shouldAdhocSignDarwinBinary(crossBuild: CrossBuild | null): boolean {
return process.platform === "darwin" && !crossBuild;
}
async function runCommand(
command: string[],
env: NodeJS.ProcessEnv = Bun.env,
@@ -76,6 +72,7 @@ async function runCommand(
async function main(): Promise<void> {
const crossBuild = resolveCrossBuild(Bun.env.CROSS_TARGET);
const shouldAdhocSign = process.platform === "darwin" && !crossBuild && Bun.env.BUN_NO_CODESIGN_MACHO_BINARY !== "1";
const outName = crossBuild ? `omp-${crossBuild.id}` : "omp";
const outputPath = path.join(packageDir, "dist", outName);
// Generate inside the try so the finally always restores the empty checked-in
@@ -99,10 +96,11 @@ async function main(): Promise<void> {
outfile: outputPath,
transformersVersion,
target: crossBuild?.target,
skipBuiltinCodesign: shouldAdhocSignDarwinBinary(crossBuild),
executablePath: Bun.env.BUN_COMPILE_EXECUTABLE_PATH || undefined,
skipBuiltinCodesign: shouldAdhocSign,
});
if (shouldAdhocSignDarwinBinary(crossBuild)) {
if (shouldAdhocSign) {
await runCommand(["codesign", "--force", "--sign", "-", outputPath]);
}
} finally {
@@ -16,6 +16,8 @@ export interface CodingAgentCompileOptions {
readonly transformersVersion: string;
/** Optional cross-compilation runtime target. */
readonly target?: Bun.Build.CompileTarget;
/** Optional unmodified Bun executable used as the standalone runtime template. */
readonly executablePath?: string;
/** Match release builds that minify identifiers while retaining names. */
readonly minifyIdentifiers?: boolean;
/** Disable Bun's built-in Darwin signing before the caller re-signs. */
@@ -47,7 +49,11 @@ export async function compileCodingAgent(options: CodingAgentCompileOptions): Pr
},
plugins: [await createLegacyPiVirtualModulePlugin()],
compile: {
...(options.target ? { target: options.target } : {}),
...(options.executablePath
? { executablePath: options.executablePath }
: options.target
? { target: options.target }
: {}),
outfile: options.outfile,
autoloadBunfig: false,
autoloadDotenv: false,