Files
hermes-agent/nix/pythonLock.nix
ethernet 712734436e fix(pm): make bootstrap and bundle ownership explicit
Finish bootstrap uv before PM replaces its store entry. Keep failure
receipts stdlib-only and align the cryptography requirement and override
with the locked version.

Let bundle builders declare launch paths and update ownership. Remove
payload discovery, Store probing, and the unused develop command.
Derive Nix Python from the PM lock and share its provenance stamp.

Document setup, activation, optional dependencies, and distribution
ownership. Targeted Windows tests, relocated runtime launches, Electron
bundling, and bilingual docs builds pass. Native Nix and signed-package
acceptance remain CI gates.
2026-09-08 00:24:51 -04:00

41 lines
1.2 KiB
Nix

# Nix uses the Python family pinned by PM, not a second version constant.
{
lib,
pkgs,
}:
let
pythonFamily =
lockfile:
let
version = (builtins.fromJSON (builtins.readFile lockfile)).packages.python.version;
parts = builtins.match "([0-9]+)\\.([0-9]+)(\\..*)?" version;
in
if parts == null then
throw "packages.python.version '${version}' is not a Python <major>.<minor> version — cannot derive the Nix interpreter from it"
else
builtins.elemAt parts 0 + "." + builtins.elemAt parts 1;
# Select pkgs.python3NN by family ("3.14" -> pkgs.python314). A missing
# lookup throws; there is no default interpreter to fall back to.
selectPython =
family: packageSet:
let
name = "python" + lib.replaceStrings [ "." ] [ "" ] family;
interp = packageSet.${name} or null;
in
if interp == null then
throw "package set does not provide ${name}, but pm/lock.json pins Python ${family} — update the nixpkgs input; Nix will not silently substitute another Python"
else
interp;
lockfile = ../pm/lock.json;
family = pythonFamily lockfile;
in
{
inherit pythonFamily selectPython;
inherit family;
interpreter = selectPython family pkgs;
}