Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
29 changes: 29 additions & 0 deletions flake.nix
Original file line number Diff line number Diff line change
Expand Up @@ -654,6 +654,7 @@
crm
dcal
fleet-status
land
local-ai-monthly
# `nix build .#local-models-prune` — the ONLY verb on this fleet
# that deletes a working copy. Exposed so the guard suite can be
Expand Down Expand Up @@ -2623,6 +2624,34 @@
touch "$out"
'';

# land (CNA-M07): the landing tool that carries a working lane into the
# notes repository. The suite builds its own fixture lane in $TMPDIR --
# nested .git, symlink, 3-byte file, excluded glob, sparse file over the
# 95 MiB ceiling -- and drives copy/verify/diff over it. rsync is in the
# build inputs so the diff cross-check is exercised here and not only on
# a host that happens to have it; the sparse file costs no store space.
# What is pinned: a packet's row count equals `find -type f`, a flipped
# byte or a stray file FAILS verify, the sources are byte-identical
# afterwards, and the secret guard aborts before writing anything while
# printing the file's name and never the matched value.
land =
pkgs.runCommand "land"
{
nativeBuildInputs = [
pkgs.python3
pkgs.rsync
];
}
''
set -euo pipefail
export HOME="$TMPDIR/home"
export PYTHONDONTWRITEBYTECODE=1
export LAND_PY=${pkgs.land}/share/land/land.py
mkdir -p "$HOME"
python3 -m unittest discover -s ${./tests/land} -p 'test_*.py' -v
touch "$out"
'';

# seats: one capacity oracle across every seat on this box. Hermetic —
# SEATS_NO_NETWORK=1 and a home tree the test builds itself, because
# every fact the program reports is relative to now and a checked-in
Expand Down
5 changes: 5 additions & 0 deletions overlays/default.nix
Original file line number Diff line number Diff line change
Expand Up @@ -121,4 +121,9 @@ final: prev: {
# Huion Note X10 offline-note extractor over BLE, pinned by commit, thin
# strokes. Only hosts/client/huion.nix consumes it. See pkgs/huion-notes.nix.
huion-notes = final.callPackage ../pkgs/huion-notes.nix { };

# land (CNA-M07): copy-then-verify for preservation packets — manifest,
# README, sha256 over every row. Used by the nightly ~/today sweep and by
# every one-time landing lane. Stdlib Python; see pkgs/land.
land = final.callPackage ../pkgs/land { };
}
44 changes: 44 additions & 0 deletions pkgs/land/default.nix
Original file line number Diff line number Diff line change
@@ -0,0 +1,44 @@
{
lib,
stdenvNoCC,
python3,
makeWrapper,
rsync,
coreutils,
}:
# land (CNA-M07): copy-then-verify for preservation packets. One stdlib Python
# file, one entry point. `land copy` writes a packet (the tree plus
# preservation-<date>.json and README.md), `land verify` recomputes every hash
# and count in it, `land diff` proves a source and its copy are the same bytes
# before anybody removes a source.
#
# rsync is a SECOND OPINION, never the authority: a packet legitimately differs
# from its source in two recorded ways (the dot-git rename and the exclusions),
# so `land diff` always hashes and only adds the rsync -rn --checksum pass when
# neither applies. Suffix, not prefix, on PATH — the host's own rsync is fine,
# this one only guarantees the command exists.
stdenvNoCC.mkDerivation {
pname = "land";
version = "1";
src = ./.;
nativeBuildInputs = [ makeWrapper ];
dontBuild = true;
installPhase = ''
runHook preInstall
install -Dm0644 land.py $out/share/land/land.py
makeWrapper ${python3.interpreter} $out/bin/land \
--add-flags "$out/share/land/land.py" \
--argv0 land \
--suffix PATH : ${
lib.makeBinPath [
rsync
coreutils
]
}
runHook postInstall
'';
meta = {
description = "Copy-then-verify landing tool for preservation packets: manifest, README, hashes";
mainProgram = "land";
};
}
Loading