The previous commit broke CI on main here, and the mechanism is worth recording.
Measured, by asking each cache for the path that failed in keystore-module
(the same class of path fails in every Rust-building repo):
logos-co.cachix.org 200 <- present
cache.nix.logos.co/public 404
cache.nix.logos.co/ci 404
cache.nixos.org 404
The failing path is a fixed-output fetch of a crates.io tarball
(crate-alloy-eip7928-0.3.4.tar.gz). With Cachix in the substituters CI never
performed that fetch -- it downloaded the finished path. Dropping Cachix
therefore did not merely cost cache hits: it made CI attempt the fetch for the
first time, and it fails there in ~7 minutes, taking cargo-vendor-dir and the
whole module with it.
The crate itself is healthy: that URL returns 20373 bytes hashing to
407510740da5..., exactly the expected outputHash. So this is not a yanked crate
or a stale hash -- it is an untested assumption ("CI can fetch from crates.io")
that Cachix had been hiding.
Cachix therefore stays as a READ-ONLY substituter until Attic has the paths. It
is credential-free (the cache is public) and nothing publishes to it any more:
pushes go to Attic, public on main and ci elsewhere. Drop these two lines once
Attic is seeded -- and expect that first uncached build to exercise the fetch
path for real.
The Attic side is confirmed working in the failing runs themselves: they
substituted python3-env and doctest from cache.nix.logos.co/public, and the push
step correctly skipped, since these repos have no public-cache environment yet.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
logos-evm-eth-rpc-module
A Logos core module (Rust, rust-first cdylib): a proxyable, fail-closed
Ethereum JSON-RPC client for the Logos multi-chain EVM wallet.
It stores configuration per chain (endpoint + proxy policy), so callers route
by chainId alone. Every outbound request is built through a single fail-closed
chokepoint (src/proxy.rs): if a chain is configured with proxyRequired and no
usable proxy, the request is refused rather than sent in the clear. Uses
reqwest with rustls-tls + socks (socks5h:// resolves DNS through the
proxy — Tor-ready).
Contract (EthRpcModule)
Config: set_chain_config(chainId, {endpoint, proxy?, proxyRequired?, timeoutSecs?}),
get_chain_config, remove_chain_config, list_chains. Calls keyed by chainId:
verify_chain_id, block_number, get_balance, call, get_transaction_count,
gas_price, fee_history, estimate_gas, send_raw_transaction,
get_transaction_receipt, get_transaction_by_hash, raw_rpc.
Build & test
cd rust-lib && cargo test --no-default-features # rpc + proxy cores (mock node + fail-closed)
nix build .#install # -> result/modules/eth_rpc_module/
src/proxy.rsis an inlined copy of the canonicallogos-evm-net-proxycrate (the module builder only stages a module'srust-lib, so a sibling path dep isn't visible in the nix sandbox). Keep the two in sync.