From d99bb06862c06d21eb0aa20a2df3c19d6ff94d65 Mon Sep 17 00:00:00 2001 From: Hermes Agent Date: Fri, 25 Sep 2026 12:19:08 -0500 Subject: [PATCH] fix(nix/desktop): compile node-pty against electron.headers MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The desktop derivation compiled node-pty against a hand-pinned fetchurl of Electron's node headers, whose URL is templated off electron.version but whose sha256 is hardcoded. Every nixpkgs electron bump swaps the tarball out from under that pinned hash, failing the fixed-output derivation at build time — and only there, never in the networked Docker/npm ci paths. Use nixpkgs' own electron.headers derivation instead. It is version-locked to the electron package, so it tracks every bump automatically with no hand-pinned hash to go stale, needs no network, and is already the --nodedir layout (so the manual fetch + tar extraction both go away). Same pattern as signal-desktop, github-desktop, session-desktop, rstudio in nixpkgs. Fixes #61443 Co-authored-by: ak2k <19240940+ak2k@users.noreply.github.com> --- nix/desktop.nix | 19 +++++++++---------- 1 file changed, 9 insertions(+), 10 deletions(-) diff --git a/nix/desktop.nix b/nix/desktop.nix index 7d065daac4..ffbf9bcebd 100644 --- a/nix/desktop.nix +++ b/nix/desktop.nix @@ -41,11 +41,6 @@ let extraRunFlags = lib.concatMapStrings (line: " \\\n --run ${lib.escapeShellArg line}") extraRun; - electronHeaders = pkgs.fetchurl { - url = "https://artifacts.electronjs.org/headers/dist/v${electron.version}/node-v${electron.version}-headers.tar.gz"; - sha256 = "sha256-f8bSbLRmtbP93CJAvEBs+sHWDZ1xP2bcpLhC1EnOmZU="; - }; - # node-pty ships no Electron-tagged prebuild we can trust to match this # exact nixpkgs electron version, so it's always compiled from source # against Electron's own headers (not whatever Node ran `npm`). @@ -87,17 +82,21 @@ let patchShebangs . - # The native provider runs before compilation. Use the headers for - # the exact Electron runtime shipped by this derivation, offline. - mkdir -p "$TMPDIR/electron-headers" - tar -xzf ${electronHeaders} -C "$TMPDIR/electron-headers" --strip-components=1 + # The native provider runs before compilation. Compile node-pty against + # the exact Electron runtime this derivation ships (the nixpkgs + # `electron`). Its headers come from nixpkgs' own `electron.headers` + # derivation — version-locked to `electron`, so it tracks every bump + # automatically with no hand-pinned hash to go stale, needs no network + # (node-gyp's --disturl path can't run in the sandbox), and is already + # the --nodedir layout. Same pattern as signal-desktop / github-desktop / + # session-desktop / rstudio in nixpkgs. ${lib.getExe hermesNpmLib.node-gyp} rebuild \ --directory=node_modules/node-pty \ --build-from-source \ --runtime=electron \ --target=${electron.version} \ --arch=${targetArch} \ - --nodedir="$TMPDIR/electron-headers" \ + --nodedir=${electron.headers} \ --disturl="" \ --offline