fix(codeaf): build furrow from source and hand it over in CODEAF_FURROW
CI / check (push) Has been cancelled

The package used to fetch the Agent-Field/furrow release asset and stage it for
go:embed, which is what `make build` does. Those bytes are a stock glibc build
that no Nix phase ever touched, so the copy codeaf writes out to
~/.codeaf/bin/furrow-0.1.0 cannot start here: NixOS answers "Could not start
dynamically linked executable" and names stub-ld. Every furrow verb the package
offers was dead with it.

Staging a rebuilt furrow was not an option. Upstream's fetcher hashes what it
stages against internal/furrowbin/pin.json and refuses anything else, and
patching the downloaded asset changes its hash. So this stages nothing, and
./furrow.nix builds the pinned version from source instead. The wrapped codeaf
passes it through CODEAF_FURROW, which internal/furrow reads before it looks at
the embedded copy, so the go binary carries no furrow at all (63 MB, was 67 MB)
and nothing unpatched is written to the state root.

furrow is Rust, not Go, and rusqlite bundles sqlite, hence the build time. Its
test suite wants a filesystem that supports user.* xattrs; the sandbox /tmp is
tmpfs and answers EOPNOTSUPP, which takes out the fixture of all 54 cli tests at
tests/cli.rs:48 and one lib test with it. The unit tests run, minus that one.

Verified with nix build .#codeaf: `codeaf --version` reports 0.7.1, the wrapper
sets CODEAF_FURROW to the store furrow, that furrow prints `furrow 0.1.0`
against store glibc, and it sits in the codeaf output's references so a gc
cannot pull it out from under the wrapper. Not verified on darwin, no builder.

Refs nix-overlay-bju
This commit is contained in:
2026-10-07 11:33:48 +03:00
parent c08c444a39
commit ff1fecc0ed
3 changed files with 92 additions and 58 deletions
+54
View File
@@ -0,0 +1,54 @@
{
lib,
rustPlatform,
fetchFromGitHub,
}:
# furrow is the copy-on-write workspace snapper codeaf drives. codeaf ships a
# copy of it inside the go binary: the release asset from GitHub, glibc-dynamic
# and untouched by anything in this build, so the file codeaf writes out to
# ~/.codeaf/bin/furrow-<version> cannot start here — NixOS answers "Could not
# start dynamically linked executable" and names stub-ld. Building furrow here
# instead gives the same version as an ordinary Nix binary, and codeaf is told
# to use it through CODEAF_FURROW, which internal/furrow reads before it ever
# looks at the embedded copy. See ./package.nix.
#
# The version here has to be the one codeaf pinned in
# internal/furrowbin/pin.json: the decoders in codeaf were written for that
# furrow. Bump the two together.
rustPlatform.buildRustPackage rec {
pname = "furrow";
version = "0.1.0";
src = fetchFromGitHub {
owner = "Agent-Field";
repo = "furrow";
rev = "v${version}";
hash = "sha256-xknfvnBDFxDYeBE1yAjXl1Fx3VDHrNSUhXEWQO3PK6s=";
};
cargoHash = "sha256-FGtrKtWFPcT3R8nF5OQFlmIiKSuZ8aiHfj76bBvga5A=";
# Only the unit tests run here. Every cli integration test builds a fixture
# whose first step is `xattr::set(…, "user.furrow-test", …)`, and the sandbox
# /tmp is a tmpfs that answers EOPNOTSUPP for user.* xattrs, so all 54 of them
# die in setup — same reason forks_files_links_modes_and_xattrs is skipped, in
# the one lib test that touches an xattr. Upstream's CI runs the whole suite on
# a filesystem that supports them.
cargoTestFlags = [ "--lib" ];
checkFlags = [
"--skip"
"forks_files_links_modes_and_xattrs"
];
meta = with lib; {
description = "Local-first working-state snapshots for agentic development";
homepage = "https://github.com/Agent-Field/furrow";
changelog = "https://github.com/Agent-Field/furrow/releases/tag/v${version}";
license = licenses.asl20;
# Thirteen source files use std::os::unix with no windows guards, so the
# upstream release has no windows asset either.
platforms = platforms.unix;
mainProgram = "furrow";
};
}