about summary refs log tree commit diff
path: root/tvix/cli/default.nix
diff options
context:
space:
mode:
authorFlorian Klink <flokli@flokli.de>2024-07-07T14·16+0300
committerclbot <clbot@tvl.fyi>2024-07-07T15·11+0000
commitd17c3d96b61a38b8a1900ca3b08bafff8e863cd2 (patch)
tree15faeaa4efedfb9c6fdfc0841c32711c7ed7e9fd /tvix/cli/default.nix
parent89d204d295345af6b64b2c5d515cfcf02828abf5 (diff)
refactor(tvix): point SSL_CERT_FILE to /dev/null r/8357
reqwest wants to be able to read a file of trust roots when constructed,
but as it doesn't actually do any HTTPS connections inside the nix
build, an empty list of trust roots is totally sufficient.

Thankfully /dev/null provides such a file.

Change-Id: I9bd1619b2c9f8ff2a6640d2ac410d4de5b20c2ea
Reviewed-on: https://cl.tvl.fyi/c/depot/+/11961
Autosubmit: flokli <flokli@flokli.de>
Tested-by: BuildkiteCI
Reviewed-by: aspen <root@gws.fyi>
Diffstat (limited to 'tvix/cli/default.nix')
-rw-r--r--tvix/cli/default.nix6
1 files changed, 3 insertions, 3 deletions
diff --git a/tvix/cli/default.nix b/tvix/cli/default.nix
index 3ed7a7ccfaec..90394f6d28c7 100644
--- a/tvix/cli/default.nix
+++ b/tvix/cli/default.nix
@@ -3,7 +3,7 @@
 (depot.tvix.crates.workspaceMembers.tvix-cli.build.override {
   runTests = true;
   testPreRun = ''
-    export SSL_CERT_FILE=${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt;
+    export SSL_CERT_FILE=/dev/null
   '';
 }).overrideAttrs (finalAttrs: previousAttrs:
 
@@ -30,7 +30,7 @@ let
   mkExprBenchmark = { expr, description }:
     let name = "tvix-cli-benchmark-${description}"; in
     (pkgs.runCommand name { } ''
-      export SSL_CERT_FILE=${pkgs.cacert.out}/etc/ssl/certs/ca-bundle.crt
+      export SSL_CERT_FILE=/dev/null
       ${lib.escapeShellArgs [
         "${pkgs.time}/bin/time"
         "--format" "${benchmark-gnutime-format-string description}"
@@ -54,7 +54,7 @@ let
       name = "tvix-eval-test-${builtins.replaceStrings [".drv"] ["-drv"] attrpath}";
     in
     (pkgs.runCommand name { } ''
-      export SSL_CERT_FILE=${pkgs.cacert.out}/etc/ssl/certs/ca-bundle.crt
+      export SSL_CERT_FILE=/dev/null
       TVIX_OUTPUT=$(${tvix-cli}/bin/tvix -E '(import ${pkgs.path} {}).${attrpath}')
       EXPECTED='${/* the verbatim expected Tvix output: */ "=> \"${builtins.unsafeDiscardStringContext expectedPath}\" :: string"}'