#!/usr/bin/env bash # Resolve ryan.zen.extensions into extensions.lock.json via AMO's v5 API. # # lock.sh [--missing] # # is the evaluated home-manager config, e.g. # ~/.config/home-manager#homeConfigurations.ryan.config # ~/.config/nix#darwinConfigurations..config.home-manager.users.ryan # # Default: re-resolve everything (unpinned entries move to AMO's current version). # --missing: keep existing entries that still satisfy the spec; resolve the rest. # # Only ryan.zen.extensions.*.{id,version} is evaluated, which never touches the # lock, so this works when the lock is empty or stale. # Needs: nix (>= 2.19 for `nix hash convert`), curl, jq. set -euo pipefail attr="${1:?usage: lock.sh [--missing]}" mode="${2:-all}" here="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" lockfile="$here/extensions.lock.json" api="https://addons.mozilla.org/api/v5/addons/addon" spec="$(nix eval --json "$attr.ryan.zen.extensions" \ --apply 'es: builtins.mapAttrs (_: e: { inherit (e) id version; }) (builtins.removeAttrs es (builtins.filter (n: !es.${n}.enable) (builtins.attrNames es)))')" old="$(cat "$lockfile" 2>/dev/null || echo '{}')" new='{}' uri() { jq -rn --arg s "$1" '$s|@uri'; } for name in $(jq -r 'keys[]' <<<"$spec"); do id="$(jq -r --arg n "$name" '.[$n].id' <<<"$spec")" want="$(jq -r --arg n "$name" '.[$n].version // empty' <<<"$spec")" if [ "$mode" = "--missing" ]; then keep="$(jq -c --arg n "$name" --arg id "$id" --arg v "$want" \ '.[$n] | select(. != null and .id == $id and ($v == "" or .version == $v))' <<<"$old")" if [ -n "$keep" ]; then new="$(jq --arg n "$name" --argjson e "$keep" '.[$n] = $e' <<<"$new")" continue fi fi if [ -n "$want" ]; then v="$(curl -fsSL "$api/$(uri "$id")/versions/$(uri "$want")/")" else v="$(curl -fsSL "$api/$(uri "$id")/" | jq '.current_version')" fi version="$(jq -r '.version' <<<"$v")" url="$(jq -r '.file.url' <<<"$v")" algo_hex="$(jq -r '.file.hash' <<<"$v")" # "sha256:" [ "${algo_hex%%:*}" = sha256 ] || { echo "$name: unexpected hash $algo_hex" >&2; exit 1; } hash="$(nix hash convert --hash-algo sha256 --to sri "${algo_hex#sha256:}")" echo "$name ($id) -> $version" >&2 new="$(jq --arg n "$name" --arg id "$id" --arg ver "$version" --arg url "$url" --arg h "$hash" \ '.[$n] = {id: $id, version: $ver, url: $url, hash: $h}' <<<"$new")" done jq -S . <<<"$new" > "$lockfile.tmp" && mv "$lockfile.tmp" "$lockfile"