ea4cd375f8
The fake Internet (bubblewrap + slirp4netns + MITM proxy + upload-pack shim, 883 lines across dev-sandbox.sh, stage2-run.sh, proxy.py, ssh-shim.sh, openssl.cnf, install-update-e2e.sh) existed to isolate install.sh's network. The GIT_CONFIG_GLOBAL insteadOf redirect the windows driver introduced does the same job with a gitconfig file and works on any OS, so: * install-e2e-run.yml now runs tests/install/installer-script-e2e.sh directly on the bare runner - no sandbox deps, no userns sysctls - and takes a runner input; * the macos matrix calls the SAME workflow on macos-latest, deleting install-e2e-macos-run.yml: installer-script -> installer-script / hermes-update flip from grey to live, app-update pairs stay TODO inside the shared gate; * install.sh is no longer curl'd through a fake CA - each leg runs the copy from the ref a user of that version actually executed; * scripts/dev-sandbox.sh becomes the minimal isolation sandbox from ab6b9492f (separate HERMES_HOME / Electron userData / app name, same CLI surface: --persistent, --from, --delete), keeping its .hermes-sandbox dir name so gitignore and docs hold; * nix/sandbox.nix drops the bwrap/proxy closure and keeps only the Electron runtime LD_LIBRARY_PATH the desktop app needs. Verified: nix build .#sandbox + smoke run (isolated HERMES_HOME created, ephemeral cleanup), shellcheck/bash -n on both scripts, actionlint on all three workflows, and the new driver ran the full v0.20.2 -> HEAD hermes-update pass locally before this commit.
76 lines
1.1 KiB
Nix
76 lines
1.1 KiB
Nix
{
|
|
# Electron needs its native runtime libraries on LD_LIBRARY_PATH when the
|
|
# sandboxed command launches the desktop app (`sandbox hermes desktop`,
|
|
# `sandbox npm run dev`); nothing else in the sandbox is nix-specific.
|
|
alsa-lib,
|
|
at-spi2-atk,
|
|
atk,
|
|
cairo,
|
|
cups,
|
|
dbus,
|
|
expat,
|
|
fontconfig,
|
|
freetype,
|
|
glib,
|
|
gtk3,
|
|
libdrm,
|
|
libgbm,
|
|
libxkbcommon,
|
|
mesa,
|
|
nspr,
|
|
nss,
|
|
pango,
|
|
systemd,
|
|
libX11,
|
|
libXcomposite,
|
|
libXdamage,
|
|
libXext,
|
|
libXfixes,
|
|
libXrandr,
|
|
libXrender,
|
|
libXtst,
|
|
libxcb,
|
|
|
|
writeShellApplication,
|
|
lib,
|
|
}:
|
|
let
|
|
electronRuntime = [
|
|
alsa-lib
|
|
at-spi2-atk
|
|
atk
|
|
cairo
|
|
cups
|
|
dbus
|
|
expat
|
|
fontconfig
|
|
freetype
|
|
glib
|
|
gtk3
|
|
libdrm
|
|
libgbm
|
|
libxkbcommon
|
|
mesa
|
|
nspr
|
|
nss
|
|
pango
|
|
systemd
|
|
libX11
|
|
libXcomposite
|
|
libXdamage
|
|
libXext
|
|
libXfixes
|
|
libXrandr
|
|
libXrender
|
|
libXtst
|
|
libxcb
|
|
];
|
|
in
|
|
writeShellApplication {
|
|
name = "sandbox";
|
|
text = ''
|
|
export LD_LIBRARY_PATH=${lib.makeLibraryPath electronRuntime}''${LD_LIBRARY_PATH:+:$LD_LIBRARY_PATH}
|
|
exec ${../scripts/dev-sandbox.sh} "$@"
|
|
'';
|
|
}
|