summary refs log tree commit diff
path: root/pkgs/tools/security/fido2luks
diff options
context:
space:
mode:
authorBenjamin Hipple <bhipple@protonmail.com>2020-01-12 11:21:23 -0500
committerBenjamin Hipple <bhipple@protonmail.com>2020-02-10 10:17:29 -0500
commit2115a2037cb8337ccb09798c175733f1fc747ee3 (patch)
treeae36678ae1dfb15b8c9cd74229cb369a60ae7fe8 /pkgs/tools/security/fido2luks
parentd9eb897edd8dfb7c65d8069197e3db5eeb537d69 (diff)
downloadnixpkgs-2115a2037cb8337ccb09798c175733f1fc747ee3.tar
nixpkgs-2115a2037cb8337ccb09798c175733f1fc747ee3.tar.gz
nixpkgs-2115a2037cb8337ccb09798c175733f1fc747ee3.tar.bz2
nixpkgs-2115a2037cb8337ccb09798c175733f1fc747ee3.tar.lz
nixpkgs-2115a2037cb8337ccb09798c175733f1fc747ee3.tar.xz
nixpkgs-2115a2037cb8337ccb09798c175733f1fc747ee3.tar.zst
nixpkgs-2115a2037cb8337ccb09798c175733f1fc747ee3.zip
fetchcargo: use flat tar.gz file for vendored src instead of recursive hash dir
This has several advantages:

1. It takes up less space on disk in-between builds in the nix store.
2. It uses less space in the binary cache for vendor derivation packages.
3. It uses less network traffic downloading from the binary cache.
4. It plays nicely with hashed mirrors like tarballs.nixos.org, which only
   substitute --flat hashes on single files (not recursive directory hashes).
5. It's consistent with how simple `fetchurl` src derivations work.
6. It provides a stronger abstraction between input src-package and output
   package, e.g., it's harder to accidentally depend on the src derivation at
   runtime by referencing something like `${src}/etc/index.html`. Likewise, in
   the store it's harder to get confused with something that is just there as a
   build-time dependency vs. a runtime dependency, since the build-time
   src dependencies are tarred up.

Disadvantages are:
1. It takes slightly longer to untar at the start of a build.

As currently implemented, this attaches the compacted vendor.tar.gz feature as a
rider on `verifyCargoDeps`, since both of them are relatively newly implemented
behavior that change the `cargoSha256`.

If this PR is accepted, I will push forward the remaining rust packages with a
series of treewide PRs to update the `cargoSha256`s.
Diffstat (limited to 'pkgs/tools/security/fido2luks')
-rw-r--r--pkgs/tools/security/fido2luks/default.nix4
1 files changed, 2 insertions, 2 deletions
diff --git a/pkgs/tools/security/fido2luks/default.nix b/pkgs/tools/security/fido2luks/default.nix
index 4682a09acf5..ea911e46734 100644
--- a/pkgs/tools/security/fido2luks/default.nix
+++ b/pkgs/tools/security/fido2luks/default.nix
@@ -19,8 +19,8 @@ rustPlatform.buildRustPackage rec {
   buildInputs = [ cryptsetup ];
   nativeBuildInputs = [ pkg-config ];
 
-  cargoSha256 = "1i37k4ih6118z3wip2qh4jqk7ja2z0v1w8dri1lwqwlciqw17zi9";
-  verifyCargoDeps = true;
+  cargoSha256 = "0rp4f6xnwmvf3pv6h0qwsg01jrndf77yn67675ac39kxzmrzfy2f";
+  legacyCargoFetcher = false;
 
   meta = with stdenv.lib; {
     description = "Decrypt your LUKS partition using a FIDO2 compatible authenticator";