Skip to content

fix: make check-flake-file cacheable across unrelated commits - #138

Merged
sini merged 2 commits into
mainfrom
check-flake-file-cacheable
Sep 27, 2026
Merged

sini merged 2 commits into
mainfrom
check-flake-file-cacheable

Conversation

@sini

@sini sini commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Closes #137.

check-flake-file interpolated the whole of self (diff -u ${top.inputs.self}/flake.nix …), so its derivation hash changed on every commit, including ones that only touch a README. A derivation whose hash has never been seen cannot be substituted from any cache, so CI rebuilds it every time and has to fetch its build inputs again (bash, stdenv, diffutils, flake-formatted, nix-auto-follow, …: 75 paths in dev/). The check's output is an empty file with no references, so a cache filled from outputs never holds those inputs. That is the repeated download reported in #137.

This is also why swapping runCommandLocal for runCommand alone made no difference: the hash was still new on each commit.

Changes:

  • The check and its check-hooks now receive a copy of the flake root containing only the files in the new option flake-file.check-files (default [ "flake.nix" "flake.lock" ]). Commits that change other files leave the check's hash unchanged.
  • runCommandLocal → runCommand with preferLocalBuild = true. It still builds locally rather than asking remote builders (the intent of feat: preferLocalBuild #110), but with allowSubstitutes left at its default, the now-stable output can come from a binary cache.
  • Docs: the option is listed in the options reference, and the hooks guide explains how to widen it.
  • Docs: the hooks guide and options reference described an exec string field that hooks never had. They now document program, with examples checked against the dev flake.

Behaviour change for custom check-hooks: hooks used to receive the full flake source. A hook that reads other files must now list them in flake-file.check-files. If it doesn't, it fails with a missing file rather than passing silently.

treefmt-check has the same shape but formats the whole tree, so it will always depend on every file. flake-file can't fix it. Caching it needs the check's build-time closure to be kept in the CI cache.

Validation

Measured on the dev/ flake with Nix 2.34.8:

scenario before after
commit touching only README.md check-flake-file.drv hash changes hash unchanged
hand-edited flake.nix check fails check fails with the diff
hook reading gen/x.txt via check-files n/a file present in the root, hook passes
  • cd dev && nix flake check passes on a clean checkout of the branch.
  • nix-shell ./dev/bootstrap-tests.nix --run test-all passes.

check-flake-file interpolated the whole of `self`, so its derivation
hash changed on every commit. A never-seen hash cannot be substituted,
so CI had to rebuild it each time, and fetch its build inputs again.

The check and its hooks now see a copy of the flake root that holds only
`flake-file.check-files` (default: flake.nix and flake.lock). It is also
built with runCommand + preferLocalBuild instead of runCommandLocal, so
the now-stable output can be substituted from a binary cache.

Closes #137
The hooks guide and options reference described an `exec` string that the
hook submodule never had. Hooks take `program`, a function from pkgs to a
derivation with meta.mainProgram. Write hooks run it from the flake root;
check hooks receive the flake root path as their first argument.

@drupol drupol left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

😍❤️

@sini
sini merged commit de3e0fc into main Sep 27, 2026
12 checks passed
@sini
sini deleted the check-flake-file-cacheable branch September 27, 2026 05:02
drupol added a commit to drupol/nixpkgs that referenced this pull request Sep 27, 2026
drupol added a commit to drupol/nixpkgs that referenced this pull request Sep 27, 2026
drupol added a commit to drupol/nixpkgs that referenced this pull request Sep 27, 2026
drupol added a commit to drupol/nixpkgs that referenced this pull request Sep 27, 2026
drupol added a commit to drupol/nixpkgs that referenced this pull request Sep 27, 2026
drupol added a commit to drupol/nixpkgs that referenced this pull request Sep 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Why runCommandLocal for check-flake-file ?

2 participants