From ede8af8191d2bc9ff5c59b6a26d7b84e79b9ea94 Mon Sep 17 00:00:00 2001 From: Ayaz Salikhov Date: Thu, 8 Oct 2026 12:34:06 +0000 Subject: [PATCH] refactor: Group binaries in subdirectories (#8535) Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --- .github/actions/build-deps/action.yml | 2 +- .github/workflows/build-nix-images.yml | 6 ++-- .github/workflows/build-packaging-images.yml | 4 +-- .github/workflows/on-pr.yml | 3 +- .github/workflows/on-trigger.yml | 3 +- .../workflows/reusable-build-test-config.yml | 10 +++---- .github/workflows/upload-conan-deps.yml | 2 +- .../packaging-tools.sh} | 0 .../sanitizer-libs.sh} | 0 bin/{ => nix}/check-build-context-runtime.sh | 2 +- bin/{ => nix}/check-nix-store-refs.sh | 2 +- bin/{ => nix}/default-loader-path.sh | 0 cmake/PatchNixBinary.cmake | 4 +-- conanfile.py | 2 +- docs/build/nix.md | 12 ++++---- docs/build/nix_troubleshooting.md | 6 ++-- nix/docker/Dockerfile | 6 ++-- nix/docker/README.md | 29 ++++++++++--------- nix/docker/test_files/cpp/compile-sources.sh | 2 +- nix/docker/test_files/rust/compile-sources.sh | 2 +- package/README.md | 2 +- package/images/packaging/Dockerfile | 2 +- 22 files changed, 50 insertions(+), 51 deletions(-) rename bin/{install-packaging-tools.sh => install/packaging-tools.sh} (100%) rename bin/{install-sanitizer-libs.sh => install/sanitizer-libs.sh} (100%) rename bin/{ => nix}/check-build-context-runtime.sh (97%) rename bin/{ => nix}/check-nix-store-refs.sh (98%) rename bin/{ => nix}/default-loader-path.sh (100%) diff --git a/.github/actions/build-deps/action.yml b/.github/actions/build-deps/action.yml index 49eb7329d3..d38544b489 100644 --- a/.github/actions/build-deps/action.yml +++ b/.github/actions/build-deps/action.yml @@ -52,4 +52,4 @@ runs: - name: Check build-context packages for Nix store dependencies (Linux) if: ${{ runner.os == 'Linux' }} shell: bash - run: ./bin/check-build-context-runtime.sh "${RUNNER_TEMP}/conan-graph.json" + run: ./bin/nix/check-build-context-runtime.sh "${RUNNER_TEMP}/conan-graph.json" diff --git a/.github/workflows/build-nix-images.yml b/.github/workflows/build-nix-images.yml index 7b4d2895a7..2da025ef3e 100644 --- a/.github/workflows/build-nix-images.yml +++ b/.github/workflows/build-nix-images.yml @@ -12,7 +12,7 @@ on: - "!nix/docker/README.md" - "!nix/devshell.nix" - "!nix/check-tools/**" - - "bin/default-loader-path.sh" + - "bin/nix/default-loader-path.sh" pull_request: paths: - ".github/workflows/build-nix-images.yml" @@ -24,8 +24,8 @@ on: - "!nix/devshell.nix" - "!nix/check-tools/**" - "bin/check-tools.sh" - - "bin/default-loader-path.sh" - - "bin/install-sanitizer-libs.sh" + - "bin/nix/default-loader-path.sh" + - "bin/install/sanitizer-libs.sh" workflow_dispatch: concurrency: diff --git a/.github/workflows/build-packaging-images.yml b/.github/workflows/build-packaging-images.yml index 829a26831f..3c1f010564 100644 --- a/.github/workflows/build-packaging-images.yml +++ b/.github/workflows/build-packaging-images.yml @@ -5,12 +5,12 @@ on: branches: - develop paths: - - "bin/install-packaging-tools.sh" + - "bin/install/packaging-tools.sh" - "package/images/packaging/**" pull_request: paths: - ".github/workflows/build-packaging-images.yml" - - "bin/install-packaging-tools.sh" + - "bin/install/packaging-tools.sh" - "package/images/packaging/**" workflow_dispatch: diff --git a/.github/workflows/on-pr.yml b/.github/workflows/on-pr.yml index 69051d5977..9421f7f2e2 100644 --- a/.github/workflows/on-pr.yml +++ b/.github/workflows/on-pr.yml @@ -93,9 +93,8 @@ jobs: .github/workflows/reusable-upload-recipe.yml .clang-tidy .codecov.yml - bin/check-nix-store-refs.sh bin/check-tools.sh - bin/default-loader-path.sh + bin/nix/** cfg/** cmake/** conan/** diff --git a/.github/workflows/on-trigger.yml b/.github/workflows/on-trigger.yml index 062f735d57..771d74f56d 100644 --- a/.github/workflows/on-trigger.yml +++ b/.github/workflows/on-trigger.yml @@ -31,9 +31,8 @@ on: - ".github/workflows/reusable-upload-recipe.yml" - ".clang-tidy" - ".codecov.yml" - - "bin/check-nix-store-refs.sh" - "bin/check-tools.sh" - - "bin/default-loader-path.sh" + - "bin/nix/**" - "cfg/**" - "cmake/**" - "conan/**" diff --git a/.github/workflows/reusable-build-test-config.yml b/.github/workflows/reusable-build-test-config.yml index 9cfeee8407..103e848734 100644 --- a/.github/workflows/reusable-build-test-config.yml +++ b/.github/workflows/reusable-build-test-config.yml @@ -257,20 +257,20 @@ jobs: # cache included, since what it holds is what gets uploaded and reused. - name: Check the build output for Nix store references (Nix toolchain) if: ${{ inputs.toolchain == 'nix' }} - run: ./bin/check-nix-store-refs.sh "${BUILD_DIR}" + run: ./bin/nix/check-nix-store-refs.sh "${BUILD_DIR}" - name: Check the Conan cache for Nix store references (Nix toolchain) if: ${{ inputs.toolchain == 'nix' }} - run: ./bin/check-nix-store-refs.sh "${CONAN_HOME}" + run: ./bin/nix/check-nix-store-refs.sh "${CONAN_HOME}" # Only what PatchNixBinary.cmake retargets: the toolchain in the Linux # images always references the store. Same condition it uses. - name: Check for Nix store references (Linux) if: ${{ runner.os == 'Linux' && env.SANITIZERS_ENABLED == 'false' }} run: | - ./bin/check-nix-store-refs.sh "${BUILD_DIR}/xrpld" - ./bin/check-nix-store-refs.sh "${BUILD_DIR}/xrpl_tests" - ./bin/check-nix-store-refs.sh "${BUILD_DIR}/xrpld_tests" + ./bin/nix/check-nix-store-refs.sh "${BUILD_DIR}/xrpld" + ./bin/nix/check-nix-store-refs.sh "${BUILD_DIR}/xrpl_tests" + ./bin/nix/check-nix-store-refs.sh "${BUILD_DIR}/xrpld_tests" - name: Show ccache statistics if: ${{ inputs.ccache_enabled }} diff --git a/.github/workflows/upload-conan-deps.yml b/.github/workflows/upload-conan-deps.yml index 526b647429..ff8360d999 100644 --- a/.github/workflows/upload-conan-deps.yml +++ b/.github/workflows/upload-conan-deps.yml @@ -115,7 +115,7 @@ jobs: - name: Check the Conan cache for Nix store references (Nix toolchain) if: ${{ matrix.toolchain == 'nix' }} - run: ./bin/check-nix-store-refs.sh "${CONAN_HOME}" + run: ./bin/nix/check-nix-store-refs.sh "${CONAN_HOME}" - name: Log into Conan remote if: ${{ github.repository == 'XRPLF/rippled' && (github.event_name == 'push' || github.event_name == 'workflow_dispatch') }} diff --git a/bin/install-packaging-tools.sh b/bin/install/packaging-tools.sh similarity index 100% rename from bin/install-packaging-tools.sh rename to bin/install/packaging-tools.sh diff --git a/bin/install-sanitizer-libs.sh b/bin/install/sanitizer-libs.sh similarity index 100% rename from bin/install-sanitizer-libs.sh rename to bin/install/sanitizer-libs.sh diff --git a/bin/check-build-context-runtime.sh b/bin/nix/check-build-context-runtime.sh similarity index 97% rename from bin/check-build-context-runtime.sh rename to bin/nix/check-build-context-runtime.sh index ecf923f599..8a6311fabc 100755 --- a/bin/check-build-context-runtime.sh +++ b/bin/nix/check-build-context-runtime.sh @@ -11,7 +11,7 @@ # update moves the GCC runtime to a new store path, so a cached binary has to # get by with the pinned glibc alone. See docs/build/nix.md. # -# Usage: bin/check-build-context-runtime.sh +# Usage: bin/nix/check-build-context-runtime.sh # is the output of `conan install --format=json`. set -euo pipefail diff --git a/bin/check-nix-store-refs.sh b/bin/nix/check-nix-store-refs.sh similarity index 98% rename from bin/check-nix-store-refs.sh rename to bin/nix/check-nix-store-refs.sh index 70413df75e..d600393f5e 100755 --- a/bin/check-nix-store-refs.sh +++ b/bin/nix/check-nix-store-refs.sh @@ -10,7 +10,7 @@ # alone; the scripts in a Conan cache are all git hook samples and autotools # scratch, 36 false positives to 0 real. # -# Usage: bin/check-nix-store-refs.sh +# Usage: bin/nix/check-nix-store-refs.sh set -euo pipefail diff --git a/bin/default-loader-path.sh b/bin/nix/default-loader-path.sh similarity index 100% rename from bin/default-loader-path.sh rename to bin/nix/default-loader-path.sh diff --git a/cmake/PatchNixBinary.cmake b/cmake/PatchNixBinary.cmake index 05d923b74e..593a19caa6 100644 --- a/cmake/PatchNixBinary.cmake +++ b/cmake/PatchNixBinary.cmake @@ -17,7 +17,7 @@ (runtime libraries resolved through the rpath) are skipped too. Everywhere else `patch_nix_binary` is a no-op. - The default loader is resolved by bin/default-loader-path.sh. + The default loader is resolved by bin/nix/default-loader-path.sh. #]===================================================================] include_guard(GLOBAL) @@ -25,7 +25,7 @@ include_guard(GLOBAL) include(CompilationEnv) # Resolves the system default ELF loader path for the current architecture. -set(_loader_path_script "${CMAKE_SOURCE_DIR}/bin/default-loader-path.sh") +set(_loader_path_script "${CMAKE_SOURCE_DIR}/bin/nix/default-loader-path.sh") if( is_linux diff --git a/conanfile.py b/conanfile.py index ad8ddc7be3..039155c254 100644 --- a/conanfile.py +++ b/conanfile.py @@ -154,7 +154,7 @@ class Xrpl(ConanFile): self.requires("xxhash/0.8.3", transitive_headers=True) exports_sources = ( - "bin/default-loader-path.sh", + "bin/nix/default-loader-path.sh", "CMakeLists.txt", "cfg/*", "cmake/*", diff --git a/docs/build/nix.md b/docs/build/nix.md index c33c8a87ad..b6de134f6f 100644 --- a/docs/build/nix.md +++ b/docs/build/nix.md @@ -183,14 +183,14 @@ at link or run time. > configuration CI covers, and no dependency binaries are published for it. This is checked rather than assumed. -[`bin/check-nix-store-refs.sh`](../../bin/check-nix-store-refs.sh) takes one file -or directory and fails if a binary under it resolves a store path at run time. +[`bin/nix/check-nix-store-refs.sh`](../../bin/nix/check-nix-store-refs.sh) takes one +file or directory and fails if a binary under it resolves a store path at run time. CI runs it over the build output and the Conan cache, and again in the upload job before anything is published. You can run it yourself: ```bash -bin/check-nix-store-refs.sh build -bin/check-nix-store-refs.sh ~/.conan2-nix +bin/nix/check-nix-store-refs.sh build +bin/nix/check-nix-store-refs.sh ~/.conan2-nix ``` It works on Linux too, but asserts something narrower there: the toolchain always @@ -204,7 +204,7 @@ instrument them. CI checks that they load nothing from the store but glibc, from the graph `conan install --format=json` writes: ```bash -bin/check-build-context-runtime.sh graph.json +bin/nix/check-build-context-runtime.sh graph.json ``` Only the binaries [`PatchNixBinary.cmake`](../../cmake/PatchNixBinary.cmake) @@ -212,7 +212,7 @@ retargets to the system loader have to be fully clean, and those are what CI checks: ```bash -bin/check-nix-store-refs.sh build/xrpld +bin/nix/check-nix-store-refs.sh build/xrpld ``` ### The libresolv stub diff --git a/docs/build/nix_troubleshooting.md b/docs/build/nix_troubleshooting.md index 49088ab6b4..597fc69def 100644 --- a/docs/build/nix_troubleshooting.md +++ b/docs/build/nix_troubleshooting.md @@ -178,11 +178,11 @@ A binary stops starting after a `nix flake update`, or after dyld[57271]: Library not loaded: /nix/store/…-libresolv-93/lib/libresolv.9.dylib ``` -[`bin/check-nix-store-refs.sh`](../../bin/check-nix-store-refs.sh) finds the same -thing without having to run anything, and names the file: +[`bin/nix/check-nix-store-refs.sh`](../../bin/nix/check-nix-store-refs.sh) finds the +same thing without having to run anything, and names the file: ``` -$ bin/check-nix-store-refs.sh ~/.conan2-nix +$ bin/nix/check-nix-store-refs.sh ~/.conan2-nix ::error file=/Users/you/.conan2-nix/p/b/c-area24ded30c388c/p/bin/adig::references the Nix store at run time /Users/you/.conan2-nix/p/b/c-area24ded30c388c/p/bin/adig /nix/store/p4lp3xq4imd1qzqh08x8vcq2zfhi7rca-libresolv-93/lib/libresolv.9.dylib diff --git a/nix/docker/Dockerfile b/nix/docker/Dockerfile index 7eae693ad2..b10be7755b 100644 --- a/nix/docker/Dockerfile +++ b/nix/docker/Dockerfile @@ -60,10 +60,10 @@ ENV GIT_SSL_CAINFO="/nix/ci-env/etc/ssl/certs/ca-bundle.crt" # Externally-built dynamically-linked ELF binaries hard-code the loader path # (e.g. /lib64/ld-linux-x86-64.so.2) in their PT_INTERP header. Install it # from the Nix store when the base image doesn't already provide one. -COPY bin/default-loader-path.sh /tmp/loader-path.sh +COPY bin/nix/default-loader-path.sh /usr/local/bin/default-loader-path.sh RUN <