n8n 2.32 replaced the sheetjs-CDN xlsx@0.20.2 tarball (which lacked an integrity checksum and had to be patched into pnpm-lock.yaml) with the regular npm package @e965/xlsx@0.20.3, which already carries an integrity field. The patchXlsxLockfile workaround is therefore obsolete and actively harmful: substituteInPlace --replace-fail no longer matches, making fetchPnpmDeps fail with a build error (not a hash mismatch), which left the fake-hash sentinel behind in n8n.nix on update. - overlays/mods/n8n.nix: remove xlsx workaround; bump to 2.32.6 with real src (sha256-wWm6...) and pnpmDeps (sha256-QzUJCF+...) hashes. - tests/n8n-overlay-test.nix: update expectations to 2.32.6; drop the obsolete checkXlsxIntegrityPatch. - overlays/mods/update.sh: use a literal SRI sentinel instead of lib.fakeHash (lib is not in scope inside the {prev}: overlay); add a snapshot-based EXIT trap that restores n8n.nix on any failure (error/SIGINT/SIGTERM/killed build) while preserving pre-existing working-tree edits; surface a clearer message when fetchPnpmDeps fails for a non-hash reason.
47 lines
1.7 KiB
Nix
47 lines
1.7 KiB
Nix
{prev}: let
|
|
# n8n >= 2.32 replaced the sheetjs-CDN `xlsx@0.20.2` tarball (which lacked an
|
|
# integrity checksum and had to be patched into pnpm-lock.yaml) with the
|
|
# regular npm package `@e965/xlsx@0.20.3`, which already carries an integrity
|
|
# field. The old lockfile-integrity workaround is therefore obsolete and has
|
|
# been removed.
|
|
in
|
|
prev.n8n.overrideAttrs (finalAttrs: previousAttrs: {
|
|
version = "2.32.6";
|
|
|
|
src = prev.fetchFromGitHub {
|
|
owner = "n8n-io";
|
|
repo = "n8n";
|
|
tag = "n8n@${finalAttrs.version}";
|
|
hash = "sha256-wWm6vGyJ2I2SBU38gRGaZG2FR5FBxH6V/sWQwn5B4Ac=";
|
|
};
|
|
|
|
pnpmDeps = prev.fetchPnpmDeps {
|
|
inherit (finalAttrs) pname version src;
|
|
pnpm = prev.pnpm_10;
|
|
fetcherVersion = 3;
|
|
hash = "sha256-QzUJCF+VIku9/HrmiUR9FNCU3MlYtyKOILZjFNXvN8U=";
|
|
};
|
|
|
|
preBuild =
|
|
(previousAttrs.preBuild or "")
|
|
+ ''
|
|
if [ ! -e node_modules/sass-embedded ] && [ -e node_modules/.pnpm/node_modules/sass-embedded ]; then
|
|
ln -s .pnpm/node_modules/sass-embedded node_modules/sass-embedded
|
|
fi
|
|
if [ ! -e node_modules/sqlite3 ] && [ -e node_modules/.pnpm/node_modules/sqlite3 ]; then
|
|
ln -s .pnpm/node_modules/sqlite3 node_modules/sqlite3
|
|
fi
|
|
'';
|
|
|
|
# Self-contained update script (./update.sh) — fetches latest stable
|
|
# release from n8n-io/n8n, recomputes both src and pnpmDeps hashes.
|
|
# The CI workflow in .gitea/workflows/nix-update.yml discovers and runs it.
|
|
passthru = (previousAttrs.passthru or {}) // {updateScript = ./update.sh;};
|
|
|
|
meta =
|
|
previousAttrs.meta
|
|
// {
|
|
changelog = "https://github.com/n8n-io/n8n/releases/tag/n8n@${finalAttrs.version}";
|
|
};
|
|
})
|