flake check kept failing on a cold store with "path '…-source' is not
valid" while evaluating Stylix's import-from-derivation in the
home-manager fontconfig text. Nix keeps flake-input sources in a git
cache and only materializes the -source store paths lazily; IFD readFile
needs them as real store paths. Works locally only because prior builds
already materialized them. Add a `nix flake archive` step that copies
every transitive input into the store before the check (and before the
eval matrix, which has the same need).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
flake check kept failing with "path '…-source' is not valid" while
evaluating the home-manager fontconfig text (Stylix/base16.nix do
import-from-derivation). Root cause: the installer pulled the latest Nix
(2.34), whose lazy-trees / git-cache behaviour doesn't materialise
flake-input source paths into the store, so the IFD reads can't find
them. Pin the install to 2.31.5 — the version that wrote flake.lock
locally and evaluates the flake cleanly all session.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
flake check evaluates the home-manager fontconfig text, which via
Stylix/base16.nix does import-from-derivation — eval must realize fetched
`-source` paths. The single-user Nix in the runner container can't set up
the build sandbox (no user namespaces), so realization failed with
"path '…-source' is not valid". Set sandbox = false for the runner
(safe in a throwaway CI container).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Empty group wasn't enough — this Nix version errors with "build users
group 'nixbld' has no members". Create the nixbld group plus 10 build
users (what a multi-user install does) before running the installer.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The single-user installer, running as root in the catthehacker container,
aborts because its bundled nix.conf sets build-users-group=nixbld and the
group doesn't exist ("the group 'nixbld' ... does not exist"). Pre-create
an empty nixbld group so config validation passes; single-user builds run
as root and never use it. Also set NIX_SSL_CERT_FILE at the job level
since we add nix to PATH without sourcing the installer profile that would
otherwise export it.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
act_runner v0.2.11 bundles an `act` that supports up to node20, but
DeterminateSystems/nix-installer-action@main moved to the node24 runtime,
so the job died with "runs.using ... got node24". Replace the JS action
with a plain single-user Nix install (--no-daemon, no systemd needed in
the catthehacker container) and set NIX_CONFIG at the job level so the
bare `nix flake check` still gets flakes. A run step has no node-runtime
coupling, so this won't break again when an action bumps its runtime.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Gitea only scans .gitea/workflows and .github/workflows; it does not scan
.forgejo/workflows (that path is Forgejo-only). The CI was therefore
dormant on a Gitea instance regardless of whether Actions was enabled.
git mv to .gitea/workflows/ (scanned by both Gitea and Forgejo). Updated
the live references in STRUCTURE.md (Gitea + act_runner), AGENT.md, and
today's ROADMAP entry; left the dated historical Shipped entries as the
changelog they are.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>