pin nixpkgs to align with app packages
4 files changed,  +215, -49
M Justfile
+5, -2
 1@@ -320,7 +320,8 @@ _pin-host-key HOST IP KEY:
 2     echo "known_hosts: pinned {{ HOST }} ({{ IP }})"
 3 
 4 # Run after `just update-nixpkgs` in sovrn and moods. Fails unless both lock
 5-# the same revision; the fleet then pins it and re-locks both projects.
 6+# the same revision; the fleet then pins it (flake and devenv) and re-locks
 7+# both projects.
 8 # Move the fleet's nixpkgs to the revision sovrn and moods lock.
 9 sync-nixpkgs:
10     #!/usr/bin/env bash
11@@ -329,6 +330,8 @@ sync-nixpkgs:
12     moods="$(jq -r .nodes.nixpkgs.locked.rev ~/projects/moods/flake.lock)"
13     [ "$sovrn" = "$moods" ] || { echo "sovrn locks $sovrn, moods locks $moods: bump them to the same revision first" >&2; exit 1; }
14     sed -i "s|nixpkgs\\.url = \"github:NixOS/nixpkgs/[0-9a-f]*\";|nixpkgs.url = \"github:NixOS/nixpkgs/$sovrn\";|" flake.nix
15+    sed -i "s|url: github:NixOS/nixpkgs/[0-9a-f]*$|url: github:NixOS/nixpkgs/$sovrn|" devenv.yaml
16     nix flake update nixpkgs sovrn moods
17+    devenv update nixpkgs
18     just eval >/dev/null
19-    echo "nixpkgs -> $sovrn (fleet, sovrn, moods); commit flake.nix and flake.lock"
20+    echo "nixpkgs -> $sovrn (fleet, devenv, sovrn, moods); commit flake.nix, flake.lock, devenv.yaml and devenv.lock"
M devenv.lock
+170, -17
  1@@ -1,5 +1,24 @@
  2 {
  3   "nodes": {
  4+    "bug": {
  5+      "inputs": {
  6+        "flake-utils": "flake-utils",
  7+        "nixpkgs": "nixpkgs"
  8+      },
  9+      "locked": {
 10+        "lastModified": 1789299135,
 11+        "narHash": "sha256-eU2EKLWUG7+LOdd6xlLELcXaK9yGyS4Hi1NWWuJPyj0=",
 12+        "ref": "refs/heads/main",
 13+        "rev": "c150b552f4b084877dd7386a5543934d7ad0c7e9",
 14+        "revCount": 12,
 15+        "type": "git",
 16+        "url": "https://git.kilimanjaro.io/bug"
 17+      },
 18+      "original": {
 19+        "type": "git",
 20+        "url": "https://git.kilimanjaro.io/bug"
 21+      }
 22+    },
 23     "devenv": {
 24       "locked": {
 25         "dir": "src/modules",
 26@@ -17,46 +36,180 @@
 27         "type": "github"
 28       }
 29     },
 30-    "nixpkgs": {
 31+    "flake-utils": {
 32       "inputs": {
 33-        "nixpkgs-src": "nixpkgs-src"
 34+        "systems": "systems"
 35       },
 36       "locked": {
 37-        "lastModified": 1789506231,
 38-        "narHash": "sha256-vNkJbtmqyBfFhn/HnzQo4ROuoyYWuy/allqTfJb4kMY=",
 39-        "owner": "cachix",
 40-        "repo": "devenv-nixpkgs",
 41-        "rev": "c2f38fe7f9e04d9aadd354d380f2bd40531d9737",
 42+        "lastModified": 1731533236,
 43+        "narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
 44+        "owner": "numtide",
 45+        "repo": "flake-utils",
 46+        "rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
 47         "type": "github"
 48       },
 49       "original": {
 50-        "owner": "cachix",
 51-        "ref": "rolling",
 52-        "repo": "devenv-nixpkgs",
 53+        "owner": "numtide",
 54+        "repo": "flake-utils",
 55+        "type": "github"
 56+      }
 57+    },
 58+    "flake-utils_2": {
 59+      "inputs": {
 60+        "systems": "systems_2"
 61+      },
 62+      "locked": {
 63+        "lastModified": 1731533236,
 64+        "narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
 65+        "owner": "numtide",
 66+        "repo": "flake-utils",
 67+        "rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
 68+        "type": "github"
 69+      },
 70+      "original": {
 71+        "owner": "numtide",
 72+        "repo": "flake-utils",
 73+        "type": "github"
 74+      }
 75+    },
 76+    "local-code-review": {
 77+      "inputs": {
 78+        "nixpkgs": "nixpkgs_2"
 79+      },
 80+      "locked": {
 81+        "lastModified": 1790664642,
 82+        "narHash": "sha256-Pl7zVsnoxxrbrg/up/5Ue2a9ajtROQptM4AOuo7AYts=",
 83+        "ref": "refs/heads/main",
 84+        "rev": "95ae244a839007c6aa89fa5230be193d878ee56e",
 85+        "revCount": 17,
 86+        "type": "git",
 87+        "url": "https://git.kilimanjaro.io/local-code-review"
 88+      },
 89+      "original": {
 90+        "type": "git",
 91+        "url": "https://git.kilimanjaro.io/local-code-review"
 92+      }
 93+    },
 94+    "nixpkgs": {
 95+      "locked": {
 96+        "lastModified": 1789149629,
 97+        "narHash": "sha256-H6GwaZzZf+4npqv0tph94w9tZddSjFjmQrVsW0z78uk=",
 98+        "owner": "NixOS",
 99+        "repo": "nixpkgs",
100+        "rev": "eaad089433ca2bb662274377d33df3d0e51ef28b",
101+        "type": "github"
102+      },
103+      "original": {
104+        "owner": "NixOS",
105+        "ref": "nixos-unstable",
106+        "repo": "nixpkgs",
107         "type": "github"
108       }
109     },
110-    "nixpkgs-src": {
111-      "flake": false,
112+    "nixpkgs_2": {
113       "locked": {
114-        "lastModified": 1789370336,
115-        "narHash": "sha256-6RSEDHIWQtesQKWSu5qRai8L2h4KgCgMEfJHstW99G4=",
116+        "lastModified": 1790323409,
117+        "narHash": "sha256-VVTPf+Hyd5ebpjBMHmrLMSBIeW6ls48Bqtosj7CNKLA=",
118         "owner": "NixOS",
119         "repo": "nixpkgs",
120-        "rev": "c7def046b9a883d46974757852106483d741586f",
121+        "rev": "e94cb152ed51bd6e24eb4a41f1460252beb52cd2",
122         "type": "github"
123       },
124       "original": {
125         "owner": "NixOS",
126-        "ref": "nixpkgs-unstable",
127+        "ref": "nixos-unstable",
128+        "repo": "nixpkgs",
129+        "type": "github"
130+      }
131+    },
132+    "nixpkgs_3": {
133+      "locked": {
134+        "lastModified": 1790578696,
135+        "narHash": "sha256-ZoxIApko70jCdbH3l20HWXOBaT2HZd87orzd2yJ9dVE=",
136+        "owner": "NixOS",
137+        "repo": "nixpkgs",
138+        "rev": "7a0f122f5090cf4c2ade2a13a0e229d4e19ba71f",
139+        "type": "github"
140+      },
141+      "original": {
142+        "owner": "NixOS",
143+        "repo": "nixpkgs",
144+        "rev": "7a0f122f5090cf4c2ade2a13a0e229d4e19ba71f",
145+        "type": "github"
146+      }
147+    },
148+    "nixpkgs_4": {
149+      "locked": {
150+        "lastModified": 1790578696,
151+        "narHash": "sha256-ZoxIApko70jCdbH3l20HWXOBaT2HZd87orzd2yJ9dVE=",
152+        "owner": "NixOS",
153+        "repo": "nixpkgs",
154+        "rev": "7a0f122f5090cf4c2ade2a13a0e229d4e19ba71f",
155+        "type": "github"
156+      },
157+      "original": {
158+        "owner": "NixOS",
159+        "ref": "nixos-unstable",
160         "repo": "nixpkgs",
161         "type": "github"
162       }
163     },
164     "root": {
165       "inputs": {
166+        "bug": "bug",
167         "devenv": "devenv",
168-        "nixpkgs": "nixpkgs"
169+        "local-code-review": "local-code-review",
170+        "nixpkgs": "nixpkgs_3",
171+        "secrets": "secrets"
172+      }
173+    },
174+    "secrets": {
175+      "inputs": {
176+        "flake-utils": "flake-utils_2",
177+        "nixpkgs": "nixpkgs_4"
178+      },
179+      "locked": {
180+        "lastModified": 1790680131,
181+        "narHash": "sha256-p3xPff0d3O4T8AW0Zbv7sZDZcJk61f5LEHRKcSTRF58=",
182+        "ref": "refs/heads/main",
183+        "rev": "96a2b2da934d769c76c19073e89e19e231964868",
184+        "revCount": 1,
185+        "type": "git",
186+        "url": "https://git.kilimanjaro.io/secrets"
187+      },
188+      "original": {
189+        "type": "git",
190+        "url": "https://git.kilimanjaro.io/secrets"
191+      }
192+    },
193+    "systems": {
194+      "locked": {
195+        "lastModified": 1681028828,
196+        "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
197+        "owner": "nix-systems",
198+        "repo": "default",
199+        "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
200+        "type": "github"
201+      },
202+      "original": {
203+        "owner": "nix-systems",
204+        "repo": "default",
205+        "type": "github"
206+      }
207+    },
208+    "systems_2": {
209+      "locked": {
210+        "lastModified": 1681028828,
211+        "narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
212+        "owner": "nix-systems",
213+        "repo": "default",
214+        "rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
215+        "type": "github"
216+      },
217+      "original": {
218+        "owner": "nix-systems",
219+        "repo": "default",
220+        "type": "github"
221       }
222     }
223   },
M devenv.nix
+29, -28
 1@@ -20,9 +20,10 @@
 2     pkgs.curl
 3     pkgs.jq
 4 
 5-    # go toolchain
 6-    pkgs.go
 7-    pkgs.golangci-lint
 8+    # custom dev tools
 9+    inputs.bug.packages.${pkgs.system}.bug
10+    inputs.local-code-review.packages.${pkgs.system}.default
11+    inputs.secrets.packages.${pkgs.system}.default
12 
13     # atproto
14     pkgs.atproto-goat
15@@ -39,32 +40,32 @@
16 
17 
18   enterShell = ''
19-    export SOVRN_DATA_DIR="${config.devenv.root}/data/dev"
20-
21-    # Configure bash with fish-like features
22-    bind 'set completion-ignore-case on'  # Case-insensitive completion
23-    bind 'set show-all-if-ambiguous on'   # Show all completions on first tab
24-    bind 'set menu-complete-display-prefix on'
25-    bind 'TAB:menu-complete'              # Tab cycles through completions
26-    bind '\e[A:history-search-backward'   # Up arrow searches history
27-    bind '\e[B:history-search-forward'    # Down arrow searches history
28-    bind 'set colored-completion-prefix on'  # Color the completion prefix
29-    bind 'set colored-stats on'           # Color the completion stats
30-
31-    # Enable bash-completion if available
32-    if [ -f ${pkgs.bash-completion}/etc/profile.d/bash_completion.sh ]; then
33-      source ${pkgs.bash-completion}/etc/profile.d/bash_completion.sh
34+    # Interactive shells only: `devenv shell -- <cmd>` has no line editing,
35+    # and bind warns there.
36+    if [[ $- == *i* ]]; then
37+      # Configure bash with fish-like features
38+      bind 'set completion-ignore-case on'  # Case-insensitive completion
39+      bind 'set show-all-if-ambiguous on'   # Show all completions on first tab
40+      bind 'set menu-complete-display-prefix on'
41+      bind 'TAB:menu-complete'              # Tab cycles through completions
42+      bind '"\e[A":history-search-backward' # Up arrow searches history
43+      bind '"\e[B":history-search-forward'  # Down arrow searches history
44+      bind 'set colored-completion-prefix on'  # Color the completion prefix
45+      bind 'set colored-stats on'           # Color the completion stats
46+
47+      # Enable bash-completion if available
48+      if [ -f ${pkgs.bash-completion}/etc/profile.d/bash_completion.sh ]; then
49+        source ${pkgs.bash-completion}/etc/profile.d/bash_completion.sh
50+      fi
51+
52+      # Better directory navigation
53+      shopt -s autocd 2>/dev/null          # Type directory name to cd
54+      shopt -s dirspell 2>/dev/null        # Correct spelling of dir names
55+      shopt -s cdspell 2>/dev/null         # Correct spelling of cd args
56+
57+      # Enable ** globbing for recursive directory matching
58+      shopt -s globstar 2>/dev/null
59     fi
60-
61-    # Better directory navigation
62-    shopt -s autocd 2>/dev/null          # Type directory name to cd
63-    shopt -s dirspell 2>/dev/null        # Correct spelling of dir names
64-    shopt -s cdspell 2>/dev/null         # Correct spelling of cd args
65-
66-    # Enable ** globbing for recursive directory matching
67-    shopt -s globstar 2>/dev/null
68-
69-    # Use correct hcloud context
70   '';
71   # https://devenv.sh/tasks/
72   # tasks = {
M devenv.yaml
+11, -2
 1@@ -1,8 +1,17 @@
 2 # yaml-language-server: $schema=https://devenv.sh/devenv.schema.json
 3 inputs:
 4+  # The fleet's shared revision (flake.nix), which sovrn and moods also lock,
 5+  # so all three dev shells share store paths. Bumped with the others by
 6+  # `just sync-nixpkgs`, never by hand.
 7   nixpkgs:
 8-    url: github:cachix/devenv-nixpkgs/rolling
 9-
10+    url: github:NixOS/nixpkgs/7a0f122f5090cf4c2ade2a13a0e229d4e19ba71f
11+  bug:
12+    url: git+https://git.kilimanjaro.io/bug
13+  local-code-review:
14+    url: git+https://git.kilimanjaro.io/local-code-review
15+  secrets:
16+    url: git+https://git.kilimanjaro.io/secrets
17+reload: false
18 # If you're using non-OSS software, you can set allow_unfree to true.
19 # allow_unfree: true
20