build: package with Nix and publish a static release artifact

packages.default builds natively and runs the suite: 357 tests pass in the
sandbox, including the 60 socket integration tests, which settles the open
question of whether they can bind in a Nix build. The sandbox's private
network namespace has loopback up and the tests take port 0, so there is
nothing to collide with.

packages.static is the published artifact, fully static against musl, so a
consumer needs neither autoPatchelfHook nor a matching glibc. There is no C
dependency anywhere in the tree, not even a TLS library, so unlike bunshin's
sqlite there is nothing to cross-provide. 2.3 MB stripped.

nixpkgs is pinned to unstable and deliberately not followed from a consumer:
every crate here declares rust-version 1.97 and nixos-25.11 ships 1.91.1, so
bucur's nixpkgs could not build this. It does not need to, since it fetches
the release asset.

wml is built in. It is opt-in upstream, and the bundled itsybitsy.toml names
it, so a default build refuses to boot the config shipped beside it.

apps.release-static publishes to Forgejo tagged by short rev, following
bunshin's. Note the asymmetry that bit bunshin: assets upload to
/releases/<id>/assets but download from /releases/download/<tag>/<name>.

THIRD_PARTY_NOTICES.md covers the static link closure, 73 crates across five
license families, plus the two vendored FIGlet fonts, which carry their terms
in the FIGfont comment header and which no crate scan can see. They are behind
the non-default figlet feature and so are not in this binary, but they are
redistributed with the source.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
randogoth 2026-10-06 08:46:04 +03:00
parent eebb33fde1
commit dffa42c304
3 changed files with 683 additions and 0 deletions

61
flake.lock generated Normal file
View file

@ -0,0 +1,61 @@
{
"nodes": {
"flake-utils": {
"inputs": {
"systems": "systems"
},
"locked": {
"lastModified": 1731533236,
"narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
"owner": "numtide",
"repo": "flake-utils",
"rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
"type": "github"
},
"original": {
"owner": "numtide",
"repo": "flake-utils",
"type": "github"
}
},
"nixpkgs": {
"locked": {
"lastModified": 1791179034,
"narHash": "sha256-Ni0LBydzaCi8oek12r4mVreuFHqYlM1eTD6SfiENKfw=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "494ce7fd23ff6a5dff39e1fb11e9b6f2ac74bf25",
"type": "github"
},
"original": {
"owner": "NixOS",
"ref": "nixos-unstable",
"repo": "nixpkgs",
"type": "github"
}
},
"root": {
"inputs": {
"flake-utils": "flake-utils",
"nixpkgs": "nixpkgs"
}
},
"systems": {
"locked": {
"lastModified": 1681028828,
"narHash": "sha256-Vy1rq5AaRuLzOxct8nz4T6wlgyUR7zLU309k9mBC768=",
"owner": "nix-systems",
"repo": "default",
"rev": "da67096a3b9bf56a91d16901293e51ba5b49a27e",
"type": "github"
},
"original": {
"owner": "nix-systems",
"repo": "default",
"type": "github"
}
}
},
"root": "root",
"version": 7
}