Skip to content

Recognize Determinate Secure Packages as supported Nixpkgs inputs - #236

Merged
lucperkins merged 7 commits into
mainfrom
lucperkins/dsp-2596-dsp-inputs
Sep 23, 2026
Merged

lucperkins merged 7 commits into
mainfrom
lucperkins/dsp-2596-dsp-inputs

Conversation

@lucperkins

@lucperkins lucperkins commented Aug 10, 2026 •

Copy link
Copy Markdown
Member

An issue that has recently emerged is that if you're using "Nixpkgs" as one of our Determinate Secure Packages variants (secure-packages-*) then Flake Checker won't recognize those as Nixpkgs inputs. This PR updates FC's machinery to handle those.

Testing

  • tests/flake.clean.8.lock covers the FlakeHub form and is expected to be clean.
  • tests/flake.dirty.2.lock pulls the same flake from GitHub and is still expected to produce both issues, since Secure Packages only comes from FlakeHub.
  • Unit tests in src/secure_packages.rs cover the name matching and both URL forms, including near misses (right name/wrong org, right host/wrong flake).

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • Added support for recognizing Determinate Secure Packages hosted on FlakeHub, including standard and pinned package URLs.
    • Secure Packages dependencies now bypass supported-reference and owner checks while continuing to receive outdated-version checks.
    • Added validation for supported hosts, owners, and package naming conventions.
  • Bug Fixes

    • Improved handling of GitHub-form Secure Packages references in lockfiles.
  • Release

    • Updated the package version to 0.2.15.

lucperkins and others added 2 commits August 10, 2026 17:19
Determinate Secure Packages flakes are re-exported Nixpkgs variants
published on FlakeHub under the DeterminateSystems org, which means they'd
otherwise get flagged for using an unsupported Git ref and for having a
non-upstream owner.

Exempt them from both checks when the input is a FlakeHub tarball for
DeterminateSystems/secure-packages*. Matching on the name prefix rather
than an explicit list means new channels work without a release. The age
check still applies, since Secure Packages flakes receive a continuous
stream of security updates.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Aug 10, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 0dd968d8-0bd3-4bbe-bda6-686d0e590170

📥 Commits

Reviewing files that changed from the base of the PR and between 51607ef and 3775ab6.

⛔ Files ignored due to path filters (2)
  • Cargo.lock is excluded by !**/*.lock
  • tests/flake.dirty.2.lock is excluded by !**/*.lock
📒 Files selected for processing (1)
  • src/secure_packages.rs
🚧 Files skipped from review as they are similar to previous changes (1)
  • src/secure_packages.rs

Included review availability: 1 review is currently available. Your included PR review attempts over the past 7 days set your current allowance at 2 reviews per hour.


📝 Walkthrough

Walkthrough

The package recognizes Determinate Secure Packages flakes hosted on FlakeHub. Qualifying tarball dependencies bypass supported-reference and owner checks while remaining subject to outdated checks. Tests cover valid, invalid, clean-lock, and dirty-lock cases.

Changes

Secure Packages support

Layer / File(s) Summary
Secure Packages URL recognition
src/main.rs, src/secure_packages.rs
The new module validates Secure Packages owners, names, standard FlakeHub URLs, and pinned FlakeHub URLs. Table-driven tests cover accepted and rejected inputs.
Dependency validation exemptions
src/flake.rs, Cargo.toml
Tarball matching checks original and locked URLs. Secure Packages dependencies skip supported-reference and owner validation but retain age validation. The package version is updated to 0.2.15.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Sequence Diagram(s)

sequenceDiagram
  participant FlakeLock
  participant FlakeChecker
  participant SecurePackages
  FlakeLock->>FlakeChecker: provide original and locked tarball URLs
  FlakeChecker->>SecurePackages: classify tarball URLs
  SecurePackages-->>FlakeChecker: return Secure Packages status
  FlakeChecker-->>FlakeLock: apply reference, owner, and age checks
Loading

Merge Risk: ⚪ Minimal · up to d4d4f

This PR adds recognition for Determinate Secure Packages Nixpkgs inputs and updates related tests; no actionable merge-blocking risk remains beyond normal checks and review.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 60.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 5 functions across 1 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: recognizing Determinate Secure Packages as supported Nixpkgs inputs.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch lucperkins/dsp-2596-dsp-inputs

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🧹 Nitpick comments (1)
src/flake.rs (1)

90-109: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Make Secure Packages classification affect an observable validation decision.

At Line 97, secure_packages can be true only for Node::Tarball. That branch returns None for both git_ref and owner at Line 101. The checks at Lines 107 and 133 therefore do not execute for a classified URL. For Node::Repo, secure_packages is always false at Line 95.

The new fixtures do not test the exemption. The clean tarball already bypasses both checks. The GitHub fixture remains flagged because every repository node sets secure_packages to false.

Confirm the intended policy. Then either remove this no-op state, or apply URL classification at a validation decision that can produce an observable exemption. Add an integration test for the selected behavior and for retained Outdated reporting.

Also applies to: 135-135, 209-209, 265-282

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@src/flake.rs` around lines 90 - 109, Confirm the intended Secure Packages
policy, then update the validation flow around the node classification and the
checks near the ref/owner and age validations so secure-package URL
classification produces an observable exemption rather than a no-op; otherwise
remove the unused secure_packages state. Add integration coverage for the
selected exemption behavior and ensure Outdated reporting remains unchanged.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@README.md`:
- Around line 43-53: Update the validation flow in the `secure_packages`
handling within the `Node::Tarball` logic so recognized DeterminateSystems
Secure Packages flakes bypass the unsupported Git ref and non-upstream owner
checks even when `git_ref` and `owner` are `None`; preserve the age check, and
retain the documented README exemption and version bump.
- Line 51: Update the Secure Packages example in the README to use the
documented FIPS distribution name secure-packages-rolling-fips, or explicitly
identify secure-packages-26.05-fips as a future naming example while retaining
the other valid examples.

---

Nitpick comments:
In `@src/flake.rs`:
- Around line 90-109: Confirm the intended Secure Packages policy, then update
the validation flow around the node classification and the checks near the
ref/owner and age validations so secure-package URL classification produces an
observable exemption rather than a no-op; otherwise remove the unused
secure_packages state. Add integration coverage for the selected exemption
behavior and ensure Outdated reporting remains unchanged.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 5255a56c-b0ea-459a-8f57-3395a1bb207d

📥 Commits

Reviewing files that changed from the base of the PR and between 3117400 and 51607ef.

⛔ Files ignored due to path filters (3)
  • Cargo.lock is excluded by !**/*.lock
  • tests/flake.clean.8.lock is excluded by !**/*.lock
  • tests/flake.dirty.2.lock is excluded by !**/*.lock
📒 Files selected for processing (5)
  • Cargo.toml
  • README.md
  • src/flake.rs
  • src/main.rs
  • src/secure_packages.rs

Comment thread README.md Outdated
Comment thread README.md Outdated
lucperkins and others added 4 commits August 10, 2026 17:23
The FIPS distribution is secure-packages-rolling-fips; there's no
secure-packages-26.05-fips.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Both FIPS distributions exist: secure-packages-rolling-fips and
secure-packages-26.05-fips.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@lucperkins
lucperkins requested review from Naxdy and cole-h August 31, 2026 16:30
@lucperkins
lucperkins merged commit cddc8af into main Sep 23, 2026
15 checks passed
@lucperkins
lucperkins deleted the lucperkins/dsp-2596-dsp-inputs branch September 23, 2026 18:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants