* fix(cmake): one LogosModule.cmake, the union of the two that had diverged
There were two copies — here and in logos-plugin-qt — and the received wisdom
that "the builder's shadows the backend's" is wrong. Selection is BY MODULE
CLASS, and each copy was missing what the other had:
mkLogosModule.nix:79 tests the BUILDER root, always true, so CORE
modules take this copy;
buildCppPlugin.nix:191 tests the MODULE'S OWN src, almost never true, so
every ui_qml module falls through to the backend's.
This copy had no REP_FILE, no logos_replica_factory, no LogosViewPluginBase — a
core module passing REP_FILE had it silently swallowed into
MODULE_UNPARSED_ARGUMENTS. The backend's had no generated_code/*.cpp glob, no
metadata.json configure_file, no LOGOS_API_STYLE and no Rust static-lib block.
Merged as a strict union, 721 -> 888 lines. logos_find_qt stays a macro(): the
function() form is the older one, and the macro IS the mingw fix. The four
LogosView*.in templates come along because the replica-factory function
resolves them as siblings through CMAKE_CURRENT_FUNCTION_LIST_DIR.
Prerequisite for relocating the view-plugin templates, not a cleanup — that
move cannot be reasoned about while two files disagree about what a view module
even is.
Verified: a core module (test_basic_module_cpp) and a ui_qml module
(test_fullapi_ui) both build through this copy, and all five of the builder's
own checks pass, including rust-native-dep, which is what exercises the
LOGOS_MODULE_RUST_STATIC_LIBS block the merge carried.
NOTE this de-duplicates nothing yet: buildCppPlugin.nix still routes ui_qml at
the backend's copy, so every in-tree REP_FILE consumer still compiles against
logos-plugin-qt's. Flipping that routing, and having the backend re-export this
file, is the follow-up.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix(qml): resolve interface_dependencies in the QML pipeline
buildCppPlugin.nix never resolved interface_dependencies, so a ui_qml module's
interfaces reached the generator only through cpp-generator's own re-read of
metadata.json — invisible to the plugin backend, and silently skipping any entry
with an `input:` (a cross-repo interface), which can only be resolved to a path
by the builder.
Now resolved and passed as interfaceDeps, exactly as mkLogosModule.nix does for
core modules. Needed because the qt consumer wrappers are now emitted per
dependency and per interface by the backend, which has to be told what they are.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* feat: retire interface "provider"; throw instead of generating nothing
Drops providerCodegen and the PROVIDER_HEADER plumbing in LogosModule.cmake.
autoCodegen ends in a catch-all `else ""`, so simply deleting the branch would
make `interface: "provider"` mean "generate no glue at all": the module builds
green and is then un-callable from every consumer, with nothing in the log to
say why. It throws instead, naming the replacement.
tests/test-module-pre-configure.nix covers exactly that: a mutation control
confirms the suite fails with `expected expression to throw, but it succeeded
with ""` when the throw is removed. 258 -> 265 tests.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* feat: parse and validate metadata.json#host_services (C2)
A closed set — token_registry, token_delivery, dynamic_calls — parsed and
VALIDATED, unlike the older `capabilities` field, which parseMetadata.nix never
reads. A security decision must not ride on a key nothing looks at, which is why
this is a new field rather than a new meaning for that one.
Two tiers, and the distinction is the point:
* token_registry / token_delivery are TRUST-ROOT — a module holding them can
enumerate the token store or hand authority to an arbitrary target — so they
are additionally restricted to a hardcoded allowlist of module names
(capability_module). Hardcoded rather than configurable: an allowlist a
module could extend from its own metadata would not be an allowlist.
* dynamic_calls is elevated but NOT name-restricted, because a third-party
module that genuinely forwards untyped calls (a webview shell) has to be
able to ask for it.
An unknown service name is refused OUTRIGHT rather than filtered out: it means
the module believes it holds a privilege that does not exist, and silently
dropping the entry hides that from whoever wrote it. Same reasoning as
lp_grant_host_services, which rejects an unknown name wholesale and leaves the
existing grant untouched.
The declaration is advisory. Authority is the host's grant, pushed into the
module's own image over the module-impl C ABI.
265 -> 273 tests. The allowlist case carries a mutation control: with the
trust-root check removed the suite fails with `expected expression to throw, but
it succeeded with ... "name":"sneaky_module","host_services":["token_registry"]`,
so the test genuinely guards the boundary rather than restating it. Includes the
bypass attempt of mixing a permitted service in with a restricted one.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: emit cdylib glue with logos-qt-host-generator, not qt-sdk's stale copy
B1 relocated the cdylib Qt-plugin glue generator to logos-plugin-qt (the Qt
plugin BACKEND owns the glue; the SDK does not), but universalCodegen and
cdylibCodegen still called `logos-qt-generator` from logos-qt-sdk, which ships
an OLDER copy of the same emitter. Both copies compile and both emit working
glue, so nothing failed — the builds simply used stale glue.
That is not theoretical. It is why the Phase C host-services grant never
reached a module: the new glue reads the `hostServices` property and forwards
it across the C ABI, the old one does not, and every build stayed green while
capability_module refused every requestModule for want of a grant that was
delivered to its process and then dropped on the floor.
Measured: `hostServices` appears 4 times in logos-plugin-qt's copy and 0 times
in logos-qt-sdk's. After the switch the built capability_module plugin
references logos_module_grant_host_services twice (the export plus the glue's
call) where it previously referenced it once.
Threads the plugin-qt FLAKE (not its lib — the generator is a package of it)
from flake.nix through lib/default.nix into buildCppPlugin, mkLogosModule and
mkLogosModuleTests, and puts logos-qt-host-generator on PATH everywhere
logos-qt-generator already was. `--backend ui` still uses qt-sdk's generator:
the view backend has not moved.
logos-test-modules ipc-tests: FAIL -> PASS, which is the end-to-end proof that
a universal capability_module now mints tokens under a host-granted privilege.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: thread logos-plugin-qt through the ui_qml build path too
mkLogosQmlModule imports buildCppPlugin at its OWN call site, separate from
lib/default.nix's, and that one was left unwired — so every ui_qml module with a
C++ backend hit `logos-plugin-qt = null` and failed to evaluate.
Caught by the regression batch: logos-accounts-ui went from building to FAIL
while all five test-modules checks passed, which is the shape of a defect in one
module CLASS rather than in the generator switch itself.
logos-accounts-ui builds again.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* test: pin the cdylib glue to the maintained generator
The existing assertion ("universal still emits the cdylib Qt glue") checked for
the string `logos-qt-generator` and so failed the moment the builder switched to
`logos-qt-host-generator` — the test doing its job. Retargeted at the invariant
that actually matters (`--backend cdylib` is still emitted) and extended into a
drift guard:
* both codegen paths MUST name logos-qt-host-generator
* neither may fall back to `logos-qt-generator ` (trailing space, so it cannot
match the host generator; `--backend ui` still legitimately uses qt-sdk's)
Worth the four assertions because the failure they catch is invisible: both
copies of the emitter compile and both produce loadable glue, so reverting to
qt-sdk's would emit stale glue and stay green — which is precisely how the
host-services grant went undelivered for a whole phase.
265 -> 277 tests.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* test(fixtures): declare universal authoring where the fixture already claimed it
The `core-universal-module` fixture is named "universal", is described as a
"Universal interface module fixture (mirrors logos-accounts-module pattern)",
and sits under a test section headed "Universal interface core module" -- but
it carried no `interface` key at all, so parseMetadata resolved it to
"legacy". The fixture was not testing the thing its name claims. The real
logos-accounts-module is `interface: universal`.
Declare `interface: universal` on the three `type: core` fixtures whose
legacy-ness was incidental, and pin the value so it cannot silently regress:
core-universal-module mirrors logos-accounts-module (universal)
core-module mirrors the minimal template (universal)
extlib-module mirrors the external-lib template and the real
vendor-extlib core modules (storage/wallet/libp2p/
blockchain) -- all universal
No `type: core` module in the workspace is still legacy-authored.
The other four legacy fixtures are LEFT legacy on purpose, and are now pinned
with an assertion + the evidence, so the coverage is deliberate instead of
accidental:
ui-qml-backend-module mirrors logos-package-manager-ui, which is STILL
legacy; the universal ui_qml shape is already covered
on disk by the ui-qml-backend TEMPLATE
qml-module QML-only: no C++ backend to derive a contract from;
module-with-deps mkLogosQmlModule never reads `interface`, and
universal+ui_qml routes to uiCodegen which demands a
.rep neither fixture has
ui-module `type: ui` has no template and one real instance
(logos-basecamp), which is legacy
These are metadata-parse fixtures only -- none of the three edited fixtures
contains any C++, so this is a metadata-shape correction, not a code port.
No fixture in this repo held a hand-written Qt plugin to migrate.
Verified: all 5 checks run BY NAME (default, qml-integration, rust-native-dep,
static-extlib, test-framework-integration) pass before and after. `default`
goes 277 -> 284 assertions, exactly the 7 added. qml-integration,
static-extlib and test-framework-integration produce byte-identical store
paths to baseline. rust-native-dep's path changes only because mkLogosModule
embeds the builder's own flake source (its fixture src is byte-identical:
xa6m5ci38fc5adcbi0hfyqvgzrmyr3j9) -- attributed by rebuilding with the change
stashed. Positive control: reverting core-universal-module to legacy makes
`default` FAIL on the new assertion, so it bites.
NOT verified: no plugin is built from any edited fixture (they are metadata
only), so there is no `lm methods` surface to diff -- the method-surface check
does not apply here. Nothing downstream of this repo was rebuilt.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* feat: hand buildHeaders the qt generator, so a contract can drive the wrapper
`contractLidl` already reached buildHeaders on every call — the qt backend just
declined to read it outside cross-compilation. What was missing was the tool:
logos-qt-generator went into buildPlugin's extraNativeBuildInputs and nowhere
near buildHeaders, so the contract-driven branch could not have run even if it
had been selected.
Passing it is the whole change on this side. `logosQtGenerator` is already the
BUILD-platform binary (buildSystemFor), which is what a cross build needs from
a pure tool role, and the backend puts only the generator its selected emitter
actually uses on PATH — so an lp variant and a contract-less module keep the
derivation they had.
Deliberately NOT passed to moduleIncludeLp: logos-qt-generator has no lp
backend. The lp wrapper still comes from logos-cpp-generator's lp emitter,
which is not the legacy Qt one and is not what this migration is about.
buildCppPlugin — the ui_qml pipeline — is left on the legacy path and now says
why. It computes no `lidl` output for the module it builds, so it has no
contract to hand over; and it costs nothing today, because mkLogosQmlModule
reads `moduleLib` and never `moduleInclude`, so that derivation is never
realised. A ui_qml module is a leaf and nothing consumes its client wrapper.
Fixing it therefore starts with giving that pipeline a contract, not with
adding a flag here.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* feat: link the Qt host runtime from logos-qt-host, not logos-qt-sdk
The Qt host runtime -- LogosAPI, LogosAPIProvider, LogosProviderBase and the
legacy PluginInterface -- moved out of logos-qt-sdk into logos-plugin-qt, where
it ships as the `logos-qt-host` CMake package. LogosModule.cmake now takes it
from LOGOS_QT_HOST_ROOT and links logos-qt-host::logos_qt_host; mkLogosModule,
buildCppPlugin, mkLogosModuleTests and the module dev shell all pass that root.
logos-qt-sdk is NOT dropped. It stays required for the Qt-typed headers that
were never part of the host runtime -- logos_qt_lp_bridge.h and logos_qt_wire.h,
which the generated Qt consumer wrappers #include by name, and
logos_ui_plugin_context.h -- and for the logos-qt-generator that emits them. Its
include dirs are kept, but AFTER the host runtime's, so the host headers win the
five names the two roots share.
mkLogosModuleTests now also passes -DLOGOS_QT_HOST_ROOT to logos-test-framework,
whose LogosTest.cmake already prefers it and falls back to LOGOS_QT_SDK_ROOT.
logos-plugin-qt's logos-protocol input gains a `follows` (as logos-qt-sdk's
already had). Building logos-qt-host makes that input load-bearing for the first
time, and a second logos-protocol on the link line would mean a second
TokenManager singleton.
Nothing here fails open. A LOGOS_QT_HOST_ROOT with no runtime under it is a
FATAL_ERROR rather than a fall-through to logos-qt-sdk; a host package that
resolves without defining its target is a FATAL_ERROR rather than a plugin
linked without a runtime; and the legacy logos-qt-sdk fallback, which stays
available while other consumers migrate, announces itself in the configure log.
The new `qt-host-repoint` check pins all four selection paths plus both guards.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* feat(b2b): probe logos-qt-sdk by a header it owns, and drop the qt-sdk fallback
Two changes, both forced by logos-qt-sdk no longer forwarding the host runtime's
headers.
The presence probe tested ${LOGOS_QT_SDK_ROOT}/cpp/logos_api.h or
include/cpp/logos_api.h. Neither exists any more: the host split moved
logos_api.h out of qt-sdk's cpp/, and the forwarder that kept it in include/cpp/
is gone. A correct root would have been reported as "logos-qt-sdk not found"
while CMake was looking straight at it. It now probes logos_qt_wire.h, which
this SDK does own -- along with logos_qt_lp_bridge.h and
logos_ui_plugin_context.h, the only reason the root is still required at all.
(The source branch was already dead on arrival: qt-sdk's cpp/ has held no
logos_api.h since B1, so LOGOS_QT_SDK_IS_SOURCE could never be TRUE.)
The legacy fallback -- no LOGOS_QT_HOST_ROOT means take the host runtime from
logos-qt-sdk's forwarding package -- is deleted. Its premise is false now, and
what it would do instead is worse than failing: find_package(logos-qt-sdk)
still succeeds and its INTERFACE target still chains logos-qt-host, so the
build would work by accident through one more hop while the include path it set
up (${LOGOS_QT_SDK_ROOT}/include{,/cpp,/core}) contained none of the headers it
was chosen for. LOGOS_QT_HOST_ROOT is now the one source, and its absence is a
FATAL_ERROR that says so.
test-qt-host-repoint.nix follows: its test 3 asserted the fallback happened and
was announced; it now asserts the fallback is gone -- a build with no
LOGOS_QT_HOST_ROOT aborts even with a good logos-qt-sdk root present. Test 3b is
new and pins the probe fix directly: that same run must NOT say "logos-qt-sdk
not found", and a qt-sdk root scaffolded the way the real prefix now looks
(logos_qt_wire.h, no logos_api.h) is still found.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* feat: LogosModule.cmake is this repo's, and every module type now gets it
logos-plugin-qt shipped a second copy of cmake/LogosModule.cmake, and which
one a module configured with was decided by its TYPE:
buildCppPlugin.nix set LOGOS_MODULE_BUILDER_ROOT only when the MODULE's own
repo carried a cmake/LogosModule.cmake. No module does, so every ui_qml
plugin fell through to the value logos-plugin-qt's lib/default.nix sets --
its own root -- while mkLogosModule's core path used this repo's copy.
Both compiled, so the two drifted with nothing to say so: this copy carried
A1's union (the generated_code/*.cpp glob, LOGOS_API_STYLE, the metadata
configure_file, Go/Rust static-lib linking, the external-library FATAL_ERRORs,
logos_find_qt as a Windows-safe macro) while plugin-qt's had B2b's addition of
logos_qt_arg_decode.{cpp,h} to the host-runtime source list -- which
qt_provider_object.cpp's dispatch needs, and whose absence is a link error, not
a configure error. That file is ported here.
Routing: both nix entry points now pass LOGOS_MODULE_BUILDER_ROOT
unconditionally, so a ui_qml plugin and a core module configure with the same
file. The old module-local branch is gone with it -- an unconditional value is
what makes "there is one copy" a property of the code rather than of what
happens to be on disk -- and a missing file now throws instead of falling back
to something that quietly configures differently.
logos_module() prints the file it came from, so a future fork shows up in any
configure log rather than after a phase of debugging.
Verified: counter, counter_qml, logos-storage-ui, logos-package-manager-ui,
test_fullapi_ui, logos-accounts-ui, logos-blockchain-ui, logos-wallet-ui and
logos-evm-wallet-ui (ui_qml) plus test_basic_module_cpp and capability_module
(core) all build, and their configure logs name this file. Checks by name:
default, qml-integration, qt-host-repoint, static-extlib OK; rust-native-dep
and test-framework-integration fail identically at the pre-change baseline
(this repo's own lock pins a logos-protocol without TokenManager::forIdentity,
so logos-qt-host will not compile from it -- green in the workspace closure).
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* feat: read the view templates from their owner, and check the ABI they declare
Two changes, one theme: nothing in this build should be able to pick a second
copy of a file without saying so.
1. cmake/LogosView*.in are deleted. They now live once, in logos-plugin-qt's
cmake/, and _logos_module_add_replica_factory takes the directory from
LOGOS_VIEW_TEMPLATE_DIR (cache variable, then environment) instead of
probing for a sibling of this .cmake file.
The sibling probe is what made the duplication possible: it meant the
templates had to sit next to LogosModule.cmake, but logos-plugin-qt's
rep-file-plugin fixture instantiates them too and cannot depend on this
repo, so it kept a byte-identical copy. logos-plugin-qt is the only place
both consumers can read one copy from; see its cmake/README.md.
There is no fallback. An unset variable, or a directory missing any of the
four templates, is a FATAL_ERROR naming what it wanted.
2. A new `view-interface-abi` check, in CI.
LogosViewPlugin and LogosViewReplicaFactory are declared TWICE and always
will be: module side in logos-plugin-qt's templates, host side in
logos-view-module-runtime's headers. They cannot share a header — a module
plugin has to compile against Qt alone, and logos-view-module-runtime
depends on logos-plugin-qt, so the include could only point the wrong way.
They bind at runtime through the IID string, and a mismatch there is silent
the whole way: both sides compile, the plugin loads, qobject_cast returns
nullptr, the view is blank.
Until now the only thing holding those two in agreement was a comment
asking a human to keep them in sync — which had already rotted (it pointed
at src/, the headers are in include/) and prevented none of the five
duplicate-source defects in this refactor.
This repo depends on logos-plugin-qt AND on logos-view-module-runtime, and
is the only one that does, so the comparison lives here. tests/
view-interface-abi.py extracts the IID and the ordered pure-virtual list
from both sides and fails on any difference — including a class rename,
which would otherwise turn the comparison into a vacuous pass.
Proven by mutation: adding an argument to enableRemoting on the module side,
bumping the IID on the host side, and renaming the host-side class each turn
the check red with a specific message; reverting each turns it green.
Note: like the already-red rust-native-dep and test-framework-integration
checks, view-interface-abi does not evaluate until this repo's logos-plugin-qt
pin advances past the commit that adds packages.<sys>.logos-view-templates. It
says exactly that, and names logos-plugin-qt as the input to move.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix(view-abi): check the class that actually binds at runtime, and let it run
The guard had two independent faults; either one alone made it decorative.
1. IT DID NOT CATCH WHAT IT NAMED. The script read `#define <Name>_iid` and
the `virtual ...;` list inside `class <Name>`. Both of those are the
abstract shape. The runtime binding is declared on the CONCRETE class the
template also contains — @LOGOS_FACTORY_CLASS@, with Q_OBJECT,
Q_PLUGIN_METADATA and Q_INTERFACES — and that class was never inspected.
Two mutations that both reach production were run against it and it stayed
green on both:
Q_PLUGIN_METADATA(IID LogosViewReplicaFactory_iid)
-> Q_PLUGIN_METADATA(IID "logos.view.replica_factory/2.0")
Q_INTERFACES(LogosViewReplicaFactory) deleted
It now parses every class in the file, finds the ones deriving from the
interface, and requires: at least one exists (so a dropped base class or a
rename cannot make the comparison vacuous); a QObject-derived one has
Q_OBJECT; a QObject-derived one names the interface in Q_INTERFACES; and
any Q_PLUGIN_METADATA IID resolves to the IID the HOST casts on.
Two more windows were open and are now closed: the argument of
Q_DECLARE_INTERFACE was only checked for EXISTENCE, though it is the string
qobject_cast compares and need not be the #define — it is now resolved
through the file's #defines and compared both across sides and against that
side's own #define; and the interface's own base list, which is its vtable
layout, was not compared at all.
Proven by mutation, 12 cases, each reverted to green afterwards: the 2
above, plus a changed Q_DECLARE_INTERFACE IID, a dropped interface base, a
renamed interface, a dropped Q_OBJECT, a base added to the interface, a
*ViewPluginBase that stops implementing LogosViewPlugin, the 2 the old
guard already caught (regression), and 2 null controls — a comment edit and
a reflowed declaration — which must stay GREEN and do.
The nix wrapper also sets `set -o pipefail` explicitly and folds stderr
into $out. `... | tee $out` takes tee's exit status; that it worked at all
depended on stdenv happening to set pipefail, which is not a thing a guard
should rest on.
2. IT COULD NOT EXECUTE. With no overrides — the CI condition — the check
EVAL-THREW: this flake pinned logos-plugin-qt at b8b9b414, which predates
packages.<sys>.logos-view-templates. So the step was unconditionally red
from the day it landed, camouflaged by test-framework-integration being red
beside it for the same stale pin.
Both logos-plugin-qt and logos-plugin-core (the same repo, selected per
module type — a split pin gives core and ui modules two different
LogosModule.cmake and two Qt host runtimes) now name rev fcf5a29 in the
URL, not just in the lock, so `nix flake update` cannot walk them back onto
a master that still lacks those outputs.
That bump fixes the EVAL failure for all three affected checks.
view-interface-abi is now GREEN with no overrides. rust-native-dep and
test-framework-integration now evaluate and build, and fail later on an
unrelated pre-existing problem: logos-qt-host does not compile against the
pinned logos-protocol, whose TokenManager has no forIdentity /
isolateIdentity. That is the same failure logos-plugin-qt's own #qt-host
check has at fcf5a29 with its own lock and no overrides, so it is not
introduced here and cannot be fixed here.
CI: qt-host-repoint is added — it is hermetic and it existed without ever
being listed. rust-native-dep is deliberately still not listed, with the
reason recorded next to it.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix(view-abi): follow bases transitively, or the guard watches an empty window
Implementor detection matched only the immediate base clause, so one level of
indirection skipped every concrete-class check — and the "no implementors"
backstop did not fire either, because the helper base still counted as an
implementor in its own right.
That is not a hypothetical shape. lidl_gen_ui.cpp emits every real ui_qml
plugin deriving from LogosViewPlugin INDIRECTLY, via <Rep>ViewPluginBase, so
for that half of the pair the window this guard exists to watch was empty in
production.
Resolve each class's transitive base set through the other classes in the file
before testing membership, and make the QObject check transitive with it. The
two mutations that escaped — an indirect base with the IID bumped to /2.0, and
an indirect base with Q_INTERFACES deleted — now fail, each naming its own
cause; indirection alone stays green and reports both implementors.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* chore(deps): bump the B3/B4 stack, and rev-pin the inputs update cannot reach
Moves every input this builder shares with the SDK codegen stack onto the
revisions that stack has actually pushed:
logos-protocol 03842db -> c8bab12 feat/per-client-token-store
logos-cpp-sdk e3744fb -> a04b278 feat/sdk-codegen-b3-d11
logos-qt-sdk c6be61d -> 8a06b87 feat/sdk-codegen-b3-d11
logos-plugin-qt fcf5a29 -> cc24fa1 feat/b4-qt-host-windows-target
logos-plugin-core fcf5a29 -> cc24fa1 same rev, per the type split
logos-view-module-runtime 471dd56 -> 5510acd feat/sdk-codegen-b4-qt-host
logos-standalone-app 288fec2 -> 39f4f2b feat/sdk-codegen-b4-qt-host
logos-test-framework eb1600c -> c382ab1 feat/sdk-codegen-b4-test-framework
Every one of those is a BRANCH TIP, not master. Six of them were plain
`github:logos-co/<repo>` urls, so `nix flake update` would have relocked them
onto master and the bump would silently not have happened -- the update
succeeds, the lock changes, and the rev is still wrong. They are rev-pinned
here for the same reason logos-plugin-qt already was. Each is a fast-forward
from its own master (03842db, e3744fb, c6be61d, 8846fc5, 471dd56, 288fec2 and
eb1600c are ancestors of their targets), so pinning gives up nothing; drop the
revs as the branches land.
logos-plugin-qt/-core go to cc24fa1, the tip of feat/b4-qt-host-windows-target,
NOT to the sibling feat/b4-qt-host-windows-target-8ccb1fc. The sibling
re-baselines onto 8ccb1fc and drops the LogosModule.cmake repoint and the
view-templates commit, so its flake exposes no packages.<sys>.logos-view-templates
and `view-interface-abi` would hit its own throw instead of running. cc24fa1
carries the old fcf5a29 pin's content under rebased shas (4c581a6/e4ea357/fcf5a29
are fe780a6/34704d1/3d7e3e6 there).
logos-test-framework's pin is the least obvious and the one worth keeping: this
branch teaches mkLogosModuleTests to pass -DLOGOS_QT_HOST_ROOT, and it is
LogosTest.cmake on c382ab1 that prefers it -- master's copy knows only
LOGOS_QT_SDK_ROOT, so a master lock links the unit tests against the wrong
runtime root without failing.
The follows keep one logos-protocol on the link line: root, logos-plugin-qt,
logos-plugin-core, logos-qt-sdk and logos-cpp-sdk all resolve to c8bab12.
All seven checks build on aarch64-darwin: default, qml-integration,
qt-host-repoint, rust-native-dep, static-extlib, test-framework-integration,
view-interface-abi.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* feat(metadata): codegen.consumer_api_style, gated on how the image gets tokens
Lets a module declare its CONSUMER type surface independently of its provider
packaging. A cdylib-packaged module can now hold Qt-typed dependency wrappers —
the combination that was previously inexpressible, and the only reason
`interface: "provider"` and `--provider-header` are still alive.
The enabling codegen landed first (logos-cpp-sdk 620f2e1, logos-qt-sdk 6b88630):
a default-constructible Qt umbrella and a consumer binding that takes an
explicit origin instead of a LogosAPI. An earlier attempt at this key FAILED
because it was added without that codegen, so its only reachable outcome was a
compile error inside generated code. It is meaningful now.
── The predicate ───────────────────────────────────────────────────────────
packagedAsCdylib = interface == "cdylib"
|| (interface == "universal" && type != "ui_qml")
character-for-character what modulePreConfigure.autoCodegen branches on when it
decides to emit the module-impl C ABI, so the two cannot drift.
The distinction is NOT "this image has no LogosAPI" — a cdylib module's plugin
does contain one, in the Qt glue that receives tokens. What separates the two
worlds is where the image's own TokenManager is FILLED:
cdylib-packaged : logos_module_accept_token -> lp_token_save, same image.
An origin-bound wrapper's null sync hook costs nothing.
Qt plugin : only LpBridge::syncTokens, installed exclusively by
forTarget(api, …). An origin-bound wrapper there would be
silently unauthenticated — the exact defect syncTokens
exists for.
Measured with `nm -gU`, not argued: `logos_module_accept_token` is defined in
exactly the shapes the predicate calls true, across six real plugins.
`universal` + `ui_qml` is the trap — it looks cdylib-shaped but uiCodegen emits
only view glue, so it is a Qt object holding a LogosAPI. Excluded.
`--binding origin` is not selectable from metadata at all: it is derived as
`isQt && packagedAsCdylib` in the backend, an AND no key can reach from the
wrong side. What a key CAN express wrongly is the mirror move — `lp` on a Qt
plugin — unsafe for the identical reason, and refused at eval naming the key.
Verified additive on seven modules spanning legacy/core, universal/core,
universal/ui_qml and QML-only: `diff -r` clean, narHash identical where
comparable, and `test_qml_only` byte-identical by store path. Note compiled
modules cannot share a store path across any builder edit, since mkLogosModule
bakes LOGOS_MODULE_BUILDER_ROOT — narHash is the honest comparison.
Three mutation controls, each failing loudly: removing the eval throw, nulling
the backend's own assertion, and dropping the packagedAsCdylib conjunct from
`originBound` — the last being the one that pins the token-mirror hazard rather
than just the lp refusal.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* chore(deps): take the backend that honours consumer_api_style
08ae7ac added the metadata key but this repo still pinned logos-plugin-qt at
cc24fa1c, which predates 2d25069's `originBound` derivation. Both backend
inputs resolved there, so the key parsed and validated and then reached a
backend that ignored it: a module asking for Qt-typed consumers still got
lp-typed wrappers, and failed to compile with a type mismatch 20 errors deep
rather than anything naming the key.
Both `logos-plugin-qt` and `logos-plugin-core` move — they are two inputs onto
the same repo, selected by module type, and a split pin would give core and ui
modules different backends.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* chore(deps): take the SDKs that carry the origin-bound consumer codegen
The backend pin (723244b) was necessary but not sufficient. consumer_api_style
= "qt" on a cdylib emits `new LogosModules()` against the Qt umbrella, which is
default-constructible only from logos-cpp-sdk 620f2e1; and the wrapper it
constructs binds through LpBridge::forOrigin, which arrives with logos-qt-sdk
aca2951. Pinned at a04b278 / 8a06b87 the key resolved, reached a backend that
honoured it, and then failed at
no matching constructor for initialization of 'LogosModules'
in generated code — three pin levels away from anything naming the feature.
Recording the chain, because it took four bumps to find: a module's consumer
surface is decided by test-modules -> module-builder -> {plugin-qt, cpp-sdk,
qt-sdk}, and every level has to move together. Each intermediate state built
something; none of them built the right thing.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* feat: refuse a core module that ships a plugin with no interface
`interface` defaults to "legacy", and legacy generates no glue. For a CONSUMER
that is correct: a ui_qml view plugin is never loaded by liblogos, and a fixture
that only builds tests has nothing to expose. For a module that ships a plugin
liblogos loads and other modules call, it is the silent form of exactly what the
`provider` branch already throws for — the module builds green and is
un-callable from every consumer, with the first symptom arriving at runtime in a
different process.
`main` is the discriminator, and measurement is why. `type` alone cannot do it:
of the modules that reach autoCodegen with no interface, the ten ui_qml ones are
consumers and test_framework_module is core but ships no plugin at all — it has
no plugin source, only calculator.{h,cpp}, and exists to drive mkLogosModuleTests.
Gating on `type == "core"` would have thrown for it. A provider ships a plugin,
so it names one in `main`; that fixture's `main` was vestigial and is dropped
here, which is also the honest description of what it always was.
Both directions checked, not just the quiet one: with the vestigial `main` put
back, test-framework-integration fails to evaluate with this message; with it
dropped, the same attribute evaluates and the check builds. The workspace still
evaluates on aarch64-darwin (624 packages) and x86_64-windows (386).
Depends on logos-test-modules retiring test_ipc_module, which was the last
module this would have thrown for.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix(metadata): drop `dynamic_calls`, which broke the grants it sat beside
`dynamic_calls` was listed as a host service and is not one. It gated nothing
and could not: the by-name path is ungated at every layer, so any module could
always make dynamic calls without asking.
What the declaration actually did was break the asking module. `hostServiceBit`
(logos_protocol.cpp:109-111) recognises exactly `token_registry` and
`token_delivery`; `lp_grant_host_services` returns LP_ERR_INVALID_ARG on the
first entry it does not recognise (:695-702), which fails the WHOLE grant. So a
module asking for `dynamic_calls` alongside a real service silently lost the
real one — the opposite of the "ADVISORY … an ungranted module gets
LP_ERR_UNSUPPORTED" the comment here promised.
Removed from `known` rather than made inert, so asking is now a build error
instead of a silent downgrade. No module in the tree declares it.
The supported surface for by-name calls is LogosModules::dynamic(target) plus
LpClient::getMethods(), added in logos-cpp-sdk alongside this. Neither needs a
grant, which is the whole point.
Two tests move with it. The "accepted for any module" case becomes an
assertThrows. The "allowlist is not bypassed by mixing in a permitted service"
case loses its premise — both remaining services are trust-root, so there is no
"permitted for anyone" name left to mix, and keeping the old form would have
passed for the wrong reason (unknown name, not the allowlist). It now pins that
asking for BOTH trust-root services does not slip past.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* ci: use logos-co/setup-nix-cache-action for Nix setup and caching
Replaces the per-repo installer + cachix pair with the shared action, which
installs Nix with the Logos Attic cache (cache.nix.logos.co) preconfigured and
publishes what the job builds — master to the public cache, every other ref to
ci.
Each converted job also gains
environment: ${{ github.ref == 'refs/heads/master' && 'public-cache' || '' }}
because ATTIC_TOKEN_PUBLIC only exists inside that environment. Without it the
secret resolves empty on master and publishing is silently skipped — the job
still passes, so the omission would not show up as a failure.
The action installs Nix itself on every runner, macOS included. That is a
deliberate reversal of the workaround these files carried: the comments here
said cachix/install-nix-action collides with the runner's pre-existing _nixbld
users (eDSRecordAlreadyExists), so DeterminateSystems' installer was used
instead. It no longer reproduces — logos-delivery-module has already been
converted the plain way and its `build-and-test (macos-latest)` leg passes.
Keeping the workaround would have meant a second installer plus a duplicated
substituter/key block in ten files, guarding against something two green runs
say does not happen. If it ever recurs it fails loudly at install, which is
recoverable; the silent-skip above is the failure mode worth engineering
against.
One property is deliberately NOT carried over: the old cachix step ran with
`continue-on-error: true` so a failed cache push could not fail a job whose
tests passed. The action exposes no equivalent, and adding one here would also
swallow genuine setup failures now that the same step installs Nix rather than
only publishing at the end.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* docs: align guides and skills with the universal codegen pipeline
The docs/ set, the authoring skills and the CMakeLists template still told
authors to write `interface: "provider"` classes with LOGOS_METHOD, or claimed
the builder runs `logos-cpp-generator --from-header` to emit the Qt glue. The
universal path is three steps — `--header-to-lidl` to derive the contract, then
`logos-qt-host-generator --backend cdylib` for the plugin glue, then
`logos-cpp-generator --lidl --backend cdylib` for the C-ABI exports — and
`--from-header` drives the separate `interface: "cdylib"` authoring path.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* feat: take the view templates from logos-view-module
The LogosView*.in templates moved out of logos-plugin-qt, which is now limited
to making a cdylib loadable by logos-module-loader-qt. Add logos-view-module as
an input and read them from there.
- view-interface-abi now reads logos-view-module's logos-view-templates and
diffs it against logos-view-module-runtime's host headers. The throw fallback
named logos-plugin-qt and told the reader to bump that pin; it names
logos-view-module now.
- This repo supplies LOGOS_VIEW_TEMPLATE_DIR itself, since the backend no
longer does, via the extraCmakeFlags/extraEnv seams already carrying
LOGOS_CPP_SDK_ROOT and the other four roots. Both channels are load-bearing:
the cmake flag drives the nix build, the env var is what a dev shell resolves
when someone runs cmake by hand.
- Indexed through common.buildSystemFor, NOT the raw system: logos-view-module
publishes only the four native systems, while this repo's systems list adds
x86_64-windows, so a raw index would EVAL-fail the Windows leg.
- LogosModule.cmake's hard error named logos-plugin-qt as the caller that
passes the variable; it names this repo now.
The input is left on master rather than rev-pinned: the output does not exist
on any pushed branch yet, so view-interface-abi hits the throw until the move
lands and the pin can be set. Verified locally with
--override-input logos-view-module path:...
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* chore(deps): pin logos-view-module at the merged template move
logos-view-module#2 merged as 1f95a75, so packages.<sys>.logos-view-templates
now exists on its master and the input no longer has to sit unpinned.
Rev-pinned for the same reason logos-plugin-qt is: `nix flake update` must not
be able to walk this back to a commit without that output, which
view-interface-abi and every ui_qml plugin build need.
view-interface-abi now passes with NO --override-input, which is what the
unpinned state could not demonstrate.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* chore(deps): pin logos-standalone-app at the branch that absorbed master
The last pin on this branch that walked master backward. master's b960f44 had
bumped logos-standalone-app to e582e6c; this branch pinned 39f4f2b, which is on
feat/sdk-codegen-b4-qt-host only and does not contain it — so merging would
have reverted the hot-reload fix (#36) and the capability-bundling removal.
That branch has now absorbed master (logos-standalone-app b67eddd, `nix build
.#default` green) and this pins the result, exactly as logos-view-module-runtime
was handled in 8484fbb.
Every root input on this branch now CONTAINS master's rev: cpp-sdk, plugin-qt,
plugin-core, protocol, qt-sdk, test-framework, standalone-app and
view-module-runtime all check out as ancestors. Nothing walks master backward
any more.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* chore(deps): track master for every input whose PR has merged
logos-protocol (#59), logos-cpp-sdk (#138), logos-plugin-qt (#19) and
logos-qt-sdk (#33) have all landed, so the four rev pins bridging to them are
retired and each stale rationale is rewritten to name the PR that closed it.
logos-plugin-core moves in lockstep with logos-plugin-qt — it is the same repo
under a second input name, and a split pin would put two logos-qt-hosts in one
closure.
All four were SQUASH-merged, so `merge-base --is-ancestor <pin> master` is
correctly false while the content is in master. Every retirement was confirmed
against master's FILES via gh api, not ancestry.
The qt-sdk pin is worth a note: nothing makes logos-qt-sdk `follows` anywhere, so
one revision across consumers was upheld by hand-pinning the same rev — and it
had already drifted (this repo pinned aca2951 while logos-test-framework and
logos-basecamp pinned 8a06b870). Tracking master makes it structural.
Kept: logos-test-framework @ c382ab1 (master's LogosTest.cmake still knows only
LOGOS_QT_SDK_ROOT, not LOGOS_QT_HOST_ROOT — verified, 0 hits) and logos-rust-sdk
@ 0b4b8ed (no confirmed upstream merge).
All 7 checks build on aarch64-darwin and the flake evaluates on all 4 systems.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* chore(deps): retire four more pins, now that their PRs have merged
Takes this flake from five rev pins to one.
* logos-test-framework c382ab1 -> master. The pin existed because master's
cmake/LogosTest.cmake knew only LOGOS_QT_SDK_ROOT, so an unpinned input made
`test-framework-integration` link the unit tests against the wrong runtime
root. logos-test-framework#6 merged and master now has LOGOS_QT_HOST_ROOT
(6 references) — the exact gap the comment named.
* logos-standalone-app b67eddd -> master (13b81c9, #37). The host shell for
ui_qml `nix run` / integration tests carries the qt-host repoint, the
hot-reload fix (#36) and the capability-bundling removal on master now.
* logos-view-module-runtime 3ef779c -> master (b9a6778f, #25). Master no longer
rev-pins logos-plugin-qt itself, so both sides of the view ABI check are back
in step.
* logos-view-module 1f95a75 -> master. 1f95a75 IS that repo's master tip (the #2
merge), so this pin was already a no-op.
Every rationale is rewritten to name the PR that closed it rather than deleted.
All four upstreams were SQUASH-merged, so the old revs are not ancestors of the
new masters even though their content is in them; the retirements were confirmed
against master's FILES.
Relocked with an explicit --update-input per retired input, NOT a bare
`nix flake lock`: that does not re-resolve an input which is already locked, even
once its url stops carrying a rev, and it silently walked pins backward twice
earlier today. All eight now read master — view-module-runtime b9a6778f,
view-module 1f95a75f, standalone-app 13b81c9e, test-framework 5f75c941,
cpp-sdk 95d7b3a9, protocol f4407ff4, plugin-qt 9b2c64e5, qt-sdk 19c844f2.
logos-rust-sdk @0b4b8ed stays: no merged upstream confirmed for it.
All 7 checks build, including test-framework-integration — the one that would
actually catch a mislocked test-framework rather than compile around it.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* chore(deps): retire the last rev pin, logos-rust-sdk
This flake now pins nothing by rev.
0b4b8ed was kept on the grounds that no merged upstream could be confirmed for
it. That was wrong: it is an ANCESTOR of logos-rust-sdk's master (7c65d31), so it
was never waiting on anything — just behind. Unlike every other pin here it also
carried no stated reason; the comment beside it explains the `follows` that cuts
the rust-sdk -> module-builder test cycle, not the rev.
Master adds exactly two commits over it, neither touching what this builder
consumes (logos-lidl-gen and the SDK source the crate links):
671bcc6 chore(lidl-gen): delete the dead gen_provider example (#39)
7c65d31 ci: use logos-co/setup-nix-cache-action for Nix setup and caching (#40)
checks.rust-native-dep — the one that compiles a Rust module through lidl-gen —
rebuilds from source against rust-sdk master and passes, as do `default` and
view-interface-abi.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* chore(deps): take the rust-sdk that emits the 11th module-impl export
logos-rust-sdk#41 merged (52f0c6f), so its provider scaffold now emits
logos_module_grant_host_services — the one module-impl C ABI export it was
missing.
That is what broke this branch's cross-language doctests. Since ed50731 the
cdylib Qt glue comes from logos-plugin-qt's logos-qt-host-generator, and the
protocol bump turned on that glue's LOGOS_PROTOCOL_VERSION_MINOR >= 3 call to
the export. logos-protocol only declares it; each language backend owes the
definition, and logos-cpp-sdk had one where logos-rust-sdk did not. Every Rust
plugin therefore linked a call with no definition — not a link error on ELF, but
nixpkgs' -Wl,-z,now forces eager binding, so the module's host process aborted at
dlopen. It died AFTER the token exchange, so the runtime reported a successful
load and only the post-load registry snapshot showed the module gone, which is
why it looked like the dependency resolver dropping the Rust module.
doctests/cross-language-composition.test.yaml: 19 passed, 0 failed — including
the assertion that failed in CI (load-module cpp_frontdesk_module listing
rust_orchestrator_module) and every typed call across the boundary in both
directions. checks.rust-native-dep also builds.
Caveat: this was verified on macOS, which links plugins -undefined
dynamic_lookup and so never binds the symbol at all — that is exactly why the
bug was invisible there and fatal on Linux. What macOS proves is that nothing
regressed and the qt-sdk/cpp-sdk skew is gone; the ubuntu doc-tests are what
confirm the Rust modules now load.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* chore(deps): take the rust-sdk that calls grant_host_services publicly
logos-rust-sdk#42 merged (a3d0d71). #41 had emitted
`logos_rust_sdk::ffi::lp_grant_host_services(...)`, but `mod ffi` is private, so
every Rust module generated against protocol >= 0.3 failed to COMPILE with
error[E0603] — which is why this branch's doctests went from "the Rust module
does not load" to "Build it FAILED". #42 routes the call through a public
wrapper, matching how the crate already exposes save_token.
checks.rust-native-dep rebuilds a real Rust module through the generator against
a3d0d71 and passes, and doctests/cross-language-composition.test.yaml is 19
passed / 0 failed — including the load-module assertion that started this and
every typed call across the C++/Rust boundary in both directions.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
14 KiB
Nix API Reference
Complete reference for logos-module-builder Nix functions.
Overview
The logos-module-builder exposes its API via lib attribute:
logos-module-builder.lib.mkLogosModule { ... } # core + legacy UI widgets
logos-module-builder.lib.mkLogosQmlModule { ... } # ui_qml (QML view + optional C++ backend)
mkLogosModule
Builder for core C++ modules and legacy UI widget modules. For ui_qml modules (QML view with optional C++ backend), use mkLogosQmlModule instead.
Syntax
mkLogosModule {
src = ./.;
configFile = ./metadata.json;
# Optional
flakeInputs = inputs; # Pass all flake inputs — deps auto-resolved
externalLibInputs = { }; # For external C libs fetched as flake inputs
extraBuildInputs = [ ];
extraNativeBuildInputs = [ ];
configOverrides = { };
preConfigure = ""; # String or function: { externalLibs }: "..."
postInstall = "";
logosStandalone = null; # Override logos-standalone-app for `nix run`
}
Parameters
src (required)
Path to the module source directory.
src = ./.;
configFile (required)
Path to the metadata.json configuration file.
configFile = ./metadata.json;
flakeInputs (optional)
All flake inputs. The builder automatically filters this by dependencies in metadata.json to resolve module dependencies — you don't need to pass them individually.
outputs = inputs@{ logos-module-builder, ... }:
logos-module-builder.lib.mkLogosModule {
src = ./.;
configFile = ./metadata.json;
flakeInputs = inputs; # dependencies[] in metadata.json are resolved automatically from input names
};
externalLibInputs (optional)
Flake inputs for external C/C++ libraries. Keys must match library names in metadata.json's nix.external_libraries. For pre-built vendor libraries, use vendor_path in metadata.json instead — no externalLibInputs needed.
The builder auto-detects whether the resolved input is a Nix derivation (via lib.isDerivation). If it is, the derivation is used directly. If it's raw source, it's built with make / custom command. No flags needed in metadata.json.
Simple format — bare flake input, resolves to packages.${system}.default:
externalLibInputs = {
gowalletsdk = inputs.go-wallet-sdk;
};
Structured format — per-variant package mappings. When any entry uses this format, the builder produces both lib and lib-portable outputs, each linked against the corresponding external lib variant. The lgx output bundles lib and lgx-portable bundles lib-portable.
externalLibInputs = {
logos_pm = {
input = inputs.logos-package-manager;
packages = {
default = "lib"; # → input.packages.${system}.lib
portable = "lib-portable"; # → input.packages.${system}.lib-portable
};
};
};
extraBuildInputs (optional)
Additional Nix packages to add to buildInputs.
extraBuildInputs = with pkgs; [
openssl
libsodium
];
extraNativeBuildInputs (optional)
Additional Nix packages to add to nativeBuildInputs (build-time only).
extraNativeBuildInputs = with pkgs; [
rustc
cargo
];
configOverrides (optional)
Override values from metadata.json. Merged recursively.
configOverrides = {
version = "2.0.0";
nix_packages = {
build = [ "extra-package" ];
};
};
metadata.json: interface, codegen, and Go static libs (automatic)
The builder prepends steps before your preConfigure:
-
"interface": "universal"— derives everything fromsrc/<name>_impl.h(impl class derived from the module name, e.g.accounts_module→AccountsModuleImpl) in three steps:logos-cpp-generator --header-to-lidl→generated_code/<name>.lidl, the contract (also the events sidecar dependents' typed-event codegen reads)logos-qt-host-generator --lidl … --backend cdylib→<name>_cdylib_glue.{h,cpp}, the Qt pluginlogos_hostloadslogos-cpp-generator --lidl … --backend cdylib→<name>_module_impl.cpp,<name>_types.h(and<name>_events_cdylib.cppwhen the header declareslogos_events:), the Qt-free C-ABI wrapper around the impl class
(A single
logos-cpp-generator --from-header --backend qtcall used to do all of this;--backend qtno longer exists.)Optional overrides:
"interface": "universal", "codegen": { "impl_header": "src/custom_impl.h", "impl_class": "CustomImpl" }Method docs: a comment directly above a method's declaration becomes that method's
description, carried ingetMethods()and shown bylm methods,logoscore module-info, and Basecamp's Methods list:/// Processes the input and returns a result. QString doSomething(const QString& input); -
"interface": "universal"+"type": "ui_qml"(handled bymkLogosQmlModule) — for a C++ UI backend,"codegen": { "rep": "src/<name>.rep" }names the Qt Remote Objects view contract;repcruns on it and the*Backendclass derives the generated<RepClass>SimpleSource. The*Plugin/*Interfaceglue is still generated. -
External libraries —
logos-plugin-qtalready copies flake-built externals intolib/before your hook; you usually do not need tocpthem inpreConfigure. -
go_build: trueon annix.external_librariesentry — passes-DLOGOS_MODULE_GO_STATIC_LIBS=…to CMake soLogosModule.cmakelinks the static archive with whole-archive /-force_loadas needed.
LOGOS_MODULE_BUILDER_ROOT always points at this flake’s source — both entry points (mkLogosModule and buildCppPlugin) set it unconditionally, and evaluation throws if cmake/LogosModule.cmake is missing from it. That file is the only copy: logos-plugin-qt used to ship a second one, and because the override used to be conditional the two were selected by module type (every ui_qml plugin configured with the backend’s copy, every core module with this one). logos_module() echoes the file it was read from at configure time so a future fork is visible in the log.
preConfigure (optional)
Extra shell commands (or a function) appended after the automatic codegen / setup above.
String form — plain shell commands:
preConfigure = ''
echo "Running custom preConfigure"
./scripts/generate-something.sh
'';
Function form — receives { externalLibs } with resolved store paths keyed by library name:
preConfigure = { externalLibs }: ''
# Only when you need something beyond the defaults
echo "extra step using ${externalLibs.mylib}"
'';
postInstall (optional)
Shell commands to run after installation.
postInstall = ''
# Custom post-install
mkdir -p $out/share
cp extra-files/* $out/share/
'';
logosStandalone (optional)
Override the logos-standalone-app used for nix run. By default, logos-module-builder bundles logos-standalone-app internally and automatically wires up apps.default for UI modules ("type": "ui" or QML modules). You only need this parameter if you want to use a custom build of logos-standalone-app.
logosStandalone = my-custom-standalone-app;
Return Value
Returns an attribute set with:
{
packages = {
<system> = {
default = <combined package>;
<name>-lib = <library package>;
<name>-include = <headers package>;
lib = <library package>;
include = <headers package>;
lgx = <lgx package>; # always included
lgx-portable = <portable lgx>; # always included
install = <dev install package>; # always included
install-portable = <portable install package>; # always included
# Only when externalLibInputs uses structured format with variants:
<name>-lib-portable = <portable library package>;
lib-portable = <portable library package>;
};
};
devShells = {
<system> = {
default = <dev shell>;
};
};
apps = { ... }; # only for type="ui" (legacy widget modules)
config = <parsed config>;
metadataJson = <metadata.json content>;
}
Example
{
inputs = {
logos-module-builder.url = "github:logos-co/logos-module-builder";
waku_module.url = "github:logos-co/logos-waku-module"; # input name must match dependency name
};
outputs = inputs@{ logos-module-builder, ... }:
logos-module-builder.lib.mkLogosModule {
src = ./.;
configFile = ./metadata.json;
flakeInputs = inputs;
preConfigure = ''
echo "Building my module..."
'';
};
}
mkLogosQmlModule
Builder for ui_qml modules — QML view with an optional C++ backend. Validates that metadata.json has "type": "ui_qml" and a non-null "view" field. When "main" is declared, compiles the C++ backend via buildCppPlugin and bundles it alongside the QML view. When "main" is absent, produces a QML-only output (no compilation). Always wires apps.default.
Syntax
mkLogosQmlModule {
src = ./.;
configFile = ./metadata.json;
# Optional — same parameters as mkLogosModule
flakeInputs = inputs;
externalLibInputs = { };
extraBuildInputs = [ ];
extraNativeBuildInputs = [ ];
configOverrides = { };
preConfigure = "";
postInstall = "";
logosStandalone = null;
}
Return Value
{
packages = {
<system> = {
default = <combined plugin (if backend) + QML view>;
<name>-lib = <library package>; # only when backend present
lib = <library package>; # only when backend present
lgx = <lgx package>;
lgx-portable = <portable lgx>;
install = <dev install package>;
install-portable = <portable install package>;
};
};
devShells = {
<system> = {
default = <dev shell>;
};
};
apps = {
<system> = {
default = <logos-standalone-app runner>; # always present
};
};
config = <parsed config>;
metadataJson = <metadata.json content>;
}
Example (with backend)
{
inputs = {
logos-module-builder.url = "github:logos-co/logos-module-builder";
calc_module.url = "github:logos-co/logos-tutorial?dir=logos-calc-module";
};
outputs = inputs@{ logos-module-builder, ... }:
logos-module-builder.lib.mkLogosQmlModule {
src = ./.;
configFile = ./metadata.json; # type: ui_qml, main: "calc_ui_cpp_plugin", view: "qml/Main.qml"
flakeInputs = inputs;
};
}
Example (QML-only, no backend)
{
inputs = {
logos-module-builder.url = "github:logos-co/logos-module-builder";
};
outputs = inputs@{ logos-module-builder, ... }:
logos-module-builder.lib.mkLogosQmlModule {
src = ./.;
configFile = ./metadata.json; # type: ui_qml, view: "Main.qml" (no "main")
flakeInputs = inputs;
};
}
parseMetadata
Parse a metadata.json file.
parseModuleConfig
Parse JSON content and apply defaults.
let
config = logos-module-builder.lib.parseMetadata.parseModuleConfig
(builtins.readFile ./metadata.json);
in {
inherit (config) name version type category description;
inherit (config) dependencies nix_packages external_libraries cmake;
}
common
Utility functions.
systems
List of supported systems.
logos-module-builder.lib.common.systems
# [ "aarch64-darwin" "x86_64-darwin" "aarch64-linux" "x86_64-linux" ]
getLibExtension
Get library extension for platform.
logos-module-builder.lib.common.getLibExtension pkgs
# "dylib" on macOS, "so" on Linux
getPluginFilename
Get plugin filename for module.
logos-module-builder.lib.common.getPluginFilename pkgs "my_module"
# "my_module_plugin.dylib" or "my_module_plugin.so"
collectAllModuleDeps
Recursively resolve all module dependencies (direct + transitive) from flake inputs. Returns a flat attrset mapping module names to their LGX derivations. Used internally by mkStandaloneApp to bundle dependencies.
logos-module-builder.lib.common.collectAllModuleDeps system flakeInputs depNames
# { waku_module = <lgx derivation>; chat = <lgx derivation>; ... }
nameFormats
Convert module name to various formats.
logos-module-builder.lib.common.nameFormats "my_module"
# { snake = "my_module"; pascal = "MyModule"; camel = "myModule"; upper = "MY_MODULE"; }
Lower-level Builders
For advanced use cases, you can use some lower-level builders directly. Plugin compilation has been delegated to backends — mkModuleLib and mkModuleInclude no longer exist.
Plugin Backends
Plugin compilation is delegated to a backend (e.g. logos-plugin-qt). The active backends are exposed as uiBackend and coreBackend:
logos-module-builder.lib.uiBackend.buildPlugin { ... }
logos-module-builder.lib.uiBackend.buildHeaders { ... }
logos-module-builder.lib.coreBackend.buildPlugin { ... }
These are internal implementation details — most modules don't need to call them directly.
mkExternalLib
Build/resolve external libraries from flake inputs. Returns an attrset mapping library names to derivations. If a resolved input is already a Nix derivation (lib.isDerivation), it is used directly; otherwise the source is built with make / custom command.
logos-module-builder.lib.mkExternalLib.buildExternalLibs {
pkgs = ...;
config = ...;
externalInputs = { };
}
mkStandaloneApp
Build the apps.default entry for nix run.
logos-module-builder.lib.mkStandaloneApp {
pkgs = ...;
standalone = logos-standalone-app.packages.${system}.default;
plugin = self.packages.${system}.default;
metadataFile = ./metadata.json;
dirName = "logos-my-module-plugin-dir"; # optional
format = "qt-plugin"; # or "qml"
moduleDeps = { }; # resolved module deps (LGX packages)
}
version
Library version string.
logos-module-builder.lib.version
# "0.2.0"