The package used to fetch the Agent-Field/furrow release asset and stage it for
go:embed, which is what `make build` does. Those bytes are a stock glibc build
that no Nix phase ever touched, so the copy codeaf writes out to
~/.codeaf/bin/furrow-0.1.0 cannot start here: NixOS answers "Could not start
dynamically linked executable" and names stub-ld. Every furrow verb the package
offers was dead with it.
Staging a rebuilt furrow was not an option. Upstream's fetcher hashes what it
stages against internal/furrowbin/pin.json and refuses anything else, and
patching the downloaded asset changes its hash. So this stages nothing, and
./furrow.nix builds the pinned version from source instead. The wrapped codeaf
passes it through CODEAF_FURROW, which internal/furrow reads before it looks at
the embedded copy, so the go binary carries no furrow at all (63 MB, was 67 MB)
and nothing unpatched is written to the state root.
furrow is Rust, not Go, and rusqlite bundles sqlite, hence the build time. Its
test suite wants a filesystem that supports user.* xattrs; the sandbox /tmp is
tmpfs and answers EOPNOTSUPP, which takes out the fixture of all 54 cli tests at
tests/cli.rs:48 and one lib test with it. The unit tests run, minus that one.
Verified with nix build .#codeaf: `codeaf --version` reports 0.7.1, the wrapper
sets CODEAF_FURROW to the store furrow, that furrow prints `furrow 0.1.0`
against store glibc, and it sits in the codeaf output's references so a gc
cannot pull it out from under the wrapper. Not verified on darwin, no builder.
Refs nix-overlay-bju
The lib suite failed in the Nix sandbox:
harness::sandbox::tests::test_internal_sandbox_exec_dev_null_and_dns
harness::sandbox::tests::test_internal_sandbox_cross_directory_rename
Failed to exec shell in sandbox: Permission denied (os error 13)
apply_landlock_linux() allow-lists FHS paths only, and Landlock matches
inodes rather than symlinked views, so nothing under /nix/store can be
executed once the ruleset is applied; /bin/sh here is a store path. The
build sandbox also drops the /usr, /lib, /run and /var rules, since those
paths do not exist there, and has no /etc/resolv.conf without network, so
neither test can pass however the package is written. 342 of 344 tests run,
all green.
The same denial applies at runtime: every shell tool call goes through
marmel --internal-sandbox-exec and fails on NixOS. Tracked as
nix-overlay-5ml. Upstream main still carries the FHS-only list.
CodeAF (Agent-Field/CodeAF) is a Go coding harness that ships one binary.
Pinned to v0.7.1; the flake's nixpkgs already carries go 1.26.7 and go.mod
asks for 1.26.5, so no extra nixpkgs input is needed.
Two things about this build are not obvious from the derivation:
- `make build` runs two host-side steps before compiling: `go generate
./internal/manual` packs the built-in manual into the pages.pack.gz and
chat.pack.gz that the codeaf_packed_manual tag embeds, and
internal/furrowbin/cmd/fetch stages the pinned Agent-Field/furrow release
into internal/furrowbin/cache for go:embed. Both are run in preBuild with
GOOS/GOARCH unset, the way the Makefile does it, so a cross build does not
try to run a target binary on the build machine. buildGoModule runs preBuild
in the vendoring derivation as well, before vendor/ exists and before the
dependencies are in reach, so the two steps are gated on vendor/.
- The furrow step gets its bytes from fetchurl and `-from`, the offline road
upstream documents. The fetcher still checks the sha256 in
internal/furrowbin/pin.json, so the hashes here duplicate a pin that is
already in the source; drop the furrow entirely and codeaf still builds and
falls back to looking for the binary on PATH.
Tests are off: the upstream suite is a make/CI matrix with network and timing
assumptions, not a `go test ./...` that fits buildGoModule.
Verified with nix build .#codeaf, `codeaf --version` reporting 0.7.1 and
`codeaf manual` listing the packed manual pages.
Refs nix-overlay-m5y
The 1.0.0 bump took a bogus tag. Graphify-Labs/graphify carries a
v1.0.0 branch from 2026-04-05 that sits 2126 commits behind v0.9.77,
still ships pyproject name graphifyy 0.1.10, and never reached PyPI,
where 0.9.77 is the latest release. nix-update picked it because it is
the highest semver tag available.
It also does not build here. Its pyproject hard-requires graspologic,
which pulls python-future, and nixpkgs disables that for Python >= 3.13
(this flake is on 3.14). Lowering the interpreter is no way out either:
python312 fails further down the chain on falcon and hyppo. 0.9.x ships
a networkx Louvain fallback for a missing Leiden backend; 1.0.0 imports
graspologic.partition.leiden unconditionally, so it is worse code even
if it did build.
Dependency corrections for the pinned source:
- datasketch dropped: upstream vendored MinHash into
graphify/_minhash.py, which also retires the pybloomfilter3
dontCheckPythonMetadata workaround in default.nix
- numpy added: graphify/_minhash.py imports it directly
Verified with nix build .#graphify (pythonImportsCheck passes) and
graphify --version reporting 0.9.77.
Refs nix-overlay-olq
Refresh every package pin so the overlay stops carrying versions upstream
has moved past, and repair the pins where an automated bump had produced a
version that no longer resolves:
- graphify 0.9.61 -> 1.0.0 and back to tag tracking: the branch-tracking
update script generated v0.9.77-unstable-<date> for a rev = "v${version}"
src, a tag that never existed
- radar 1.13.1 -> 1.16.2 (upstream retagged its releases as k8s-ui-v*)
- llama-cpp b9645 -> b11439
- hipengine 0.5.0 -> 0.6.1, traycer 1.3.0 -> 1.4.2, freetoken 0.1.2 -> 0.1.3
- awg-tool 0.4.0, freebuff 0.2.19, kubernetes-mcp-server 0.0.67,
marmel 0-unstable-2026-10-05, open-code-review 1.12.12,
ds4 0-unstable-2026-09-20
- version-string normalisation for the branch-tracked packages already at
their newest commit (g3, haivemind, shardr, skillsmcp)
Every changed src hash was re-fetched and verified. omniroute stays at
3.8.50: 3.8.51 changes its npm lockfile, so its npmDepsHash would have to
be recomputed before the bump is usable.
🤖 Generated with Codebuff
Co-Authored-By: Codebuff <noreply@codebuff.com>
Decentralized LLM repository (Go): content-addressed model store with
BitTorrent-based sync and OpenAI-compatible serving via llama-server.
Upstream has no tagged source releases, so the package is pinned to
main HEAD (fab7fa8) with a nix-update script targeting the branch.
Builds both shardr and shardhive binaries.
Upstream and the bundled OpenCode plugin invoke the tool as `ocr`, but the
Go build names the binary after its cmd/ directory (`opencodereview`), so
the CLI was missing from PATH under the name everything expects.
- packages/open-code-review/opencode-plugin.nix: builds the plugin TS file
plus runtime node_modules from the plugin's package-lock.json into
share/open-code-review/opencode (exposed as passthru.opencode-plugin,
same source rev as the CLI so versions stay locked)
- modules/open-code-review-hm.nix: homeManagerModules.default with
programs.open-code-review.{enable,opencode.enable} — symlinks the plugin
and node_modules into ~/.config/opencode/plugins/ and installs the CLI
- flake.nix: expose homeManagerModules.default
Note: upstream declares the plugin SDKs as devDependencies, so the
lockfile install must not use --omit=dev.
🤖 Generated with Codebuff
Co-Authored-By: Codebuff <noreply@codebuff.com>
Build alibaba/open-code-review v1.12.9 from source via buildGoModule
(CGO disabled, cmd/opencodereview subpackage, version ldflags).
🤖 Generated with Codebuff
Co-Authored-By: Codebuff <noreply@codebuff.com>
Pin Na1w/marmel to commit fd551ae. Upstream publishes no tags or
releases, so the version uses the shape nix-update generates for a
tagless repository, keeping `nix-update --version=branch=main` usable.
The test suite runs green (325 lib tests plus all integration suites)
with two accommodations, both documented in the derivation:
- Export SSL_CERT_FILE from nixpkgs cacert. rustls refuses to construct
a reqwest::Client without a system trust store, which failed 38 tests
with "No CA certificates were loaded from the system".
- Serialise the test harness. The lib suite shares process-global worker
registries and steer/abort buses, so manager-loop tests fail
nondeterministically on parallel threads: one unchanged derivation
produced 3 failures, then 1 failure, then 0 with --test-threads=1.
No test is skipped or filtered.
Annotated example configs are installed to share/doc/marmel/examples/.
Role prompts are embedded via include_str!, so there is no runtime data
directory. Upstream README states MIT but ships no LICENSE file and no
Cargo.toml license field.
Bump nixpkgs and nixpkgs-latest from 2026-05/2026-08 to current
nixos-unstable (2026-09-11); both inputs now resolve to the same rev.
Re-validated every package against the new inputs.
Fallout fixed:
- freetoken: upstream pins torch>=2.11,<2.12 and triton==3.6.0, but the new
nixpkgs only ships torch 2.13 / triton 3.7. Add a nixpkgs-torch211 input
pinned at the previous revision and build freetoken against it, keeping
the CUDA 12.9 / torch 2.11 stack unchanged.
- graphify: nixpkgs' pybloomfilter3 0.7.3 ships sdist metadata that still
says 0.7.2, tripping pythonMetadataCheckPhase; skip that check only.
All 22 packages build and `nix flake check --no-build` passes.
Pin upstream llama.cpp b9645 and build it against the nixpkgs-latest
input (the flake's pinned nixpkgs only carries the pre-tools/ui b8983).
ROCm deps come from rocmPackages.gfx1151, so clr/rocBLAS/hipBLAS are
built for gfx1151 only; clr's own build is arch-independent, so its
store path stays substitutable. Vulkan on, CPU variants with znver5 /
AVX-512, web UI and npm toolchain dropped.
Ported from nixos-config's llm-engine.nix with two fixes: npmConfigHook
hard-fails when npmDeps is null, so nodejs and the hook are stripped
from nativeBuildInputs, and CMAKE_HIP_FLAGS is appended to
cmakeFlagsArray because the cmake hook word-splits plain cmakeFlags.
Verified on the Radeon 8060S (gfx1151): llama-bench loads both ROCm and
Vulkan backends and completes pp16/tg8 runs.
Package FreeToken (FlashML-org/FreeToken) — edge-native MoE serving
engine with OpenAI/Anthropic-compatible APIs, serving the `ft` CLI.
- torch-bin 2.11 (CUDA 12.9 wheel build) satisfies the torch>=2.11,<2.12
pin; extensions link the same cudaPackages.cuda_cudart via a synthetic
CUDA_HOME (cudart headers + nvcc crt/ headers, no nvcc needed).
- flashlib==0.3.0 vendored from the PyPI wheel (Triton-only; freetoken
never imports the CuTeDSL GEMM backends, so nvidia-cutlass-dsl is
omitted via pythonRemoveDeps).
- apache-tvm-ffi overridden to the pinned 0.1.13.post3 with a vendored
cython 3.3.0 (build needs >=3.2.8, nixpkgs has 3.2.4); pytest skipped
(upstream runs pytest-xdist with GPU tests).
- Unfree (CUDA EULA) is self-scoped: the package re-imports nixpkgs with
config.allowUnfree so no flake-level or user config change is needed.
- Optional accel extras (flashinfer/sglang-kernel) and the kernel-cache
wheel are not packaged; runtime falls back to pure-Triton kernels.
- Verified: nix build .#freetoken, ft --version, python imports check,
extension RPATHs.
App.query_one searches the app's default screen (_default), but #chat-log/#health-bar/etc. live on the pushed MainScreen. Every HaivemindApp handler failed with NoMatches at runtime. Hold a reference to the MainScreen instance and query it directly so widget lookup no longer depends on which screen is active.
Upstream haivemind_tui.py started the engine synchronously in HaivemindApp.on_mount while MainScreen mounts asynchronously, causing ProbeStart handler to query #chat-log on the default screen (NoMatches). Move the start_run trigger into MainScreen.on_mount so it runs only once the screen is active.
Rust CLI for AmneziaWG self-hosting from Vadim-Khristenko/awg-containers-and-tools: generates 1.0/1.5/2.0/3.0 obfuscation parameters, exports .conf and vpn:// configs, installs servers over SSH.
Traycer is an open-source AI orchestration desktop app (Electron).
Packaged from the upstream AppImage via appimageTools.wrapType2,
matching the existing loop package pattern.
Web interface to manage nftables rules with drag-and-drop rule creation.
Upstream source is incomplete (missing settings crate, no GUI build
tooling), so the package builds the Rust workspace from the pinned
commit with a patched-in settings crate (schema recovered from official
release artifacts) and reuses the prebuilt GUI from the hash-pinned
release tarball on nftablesbuilder.eu.
Add antirez/ds4 — DeepSeek V4 Flash/PRO local inference engine built
with the ROCm strix-halo target for AMD Radeon 8060S (gfx1151).
Wires up all 8 ROCm transitive dependencies (clr, hipblas, hipblas-common,
hipblaslt, hipcub, rocblas, rocprim, rocwmma) via explicit include/lib paths.
Add OmniRoute v3.8.28 - a unified AI router aggregating 160+ providers
with auto fallback, MCP/A2A support, and OpenAI-compatible APIs.
Uses a hybrid approach: GitHub source for dependency resolution via
fetchNpmDeps, combined with pre-built dist/ from the npm tarball to
avoid the complex Next.js build in the Nix sandbox.
Add RelayFreeLLM, a RESTful API gateway that routes prompts to multiple
AI providers (Gemini, Cerebras, Groq, Mistral, etc.) with failover and
intent-based routing. Includes local cerebras-cloud-sdk build since it is
not yet in nixpkgs.
- Delete packages/goose-cli/ (librusty_v8 pre-built binary dependency)
- Remove global nixpkgs.config.allowUnfree from flake.nix
(goose-cli was the only package requiring unfree binaries)
- Add .claude/ to .gitignore
- Update README.md and AGENTS.md to remove all goose-cli references
- Use appimageTools.extractType2 to access embedded assets
- Install loop-desktop.desktop and rewrite Exec=AppRun → Exec=loop
- Copy hicolor icons (16–1024px) from AppImage tree
Revert the --ozone-platform=x11 flag since the user prefers native
Wayland. The flag was added to work around a zxdg_exporter_v1
Wayland protocol crash in Electron, but forcing X11 is not
acceptable for Wayland users. Keep --no-sandbox for NixOS store
compatibility.
- Add --ozone-platform=x11 to wrapper to fix Wayland crash
(zxdg_exporter_v1 protocol error causing SIGTRAP on Wayland)
- Add --no-sandbox since chrome-sandbox lacks SUID on NixOS
- Add LD_LIBRARY_PATH to wrapper so Electron GPU process finds bundled libEGL.so.1
- Add glib.bin to buildInputs and wrap gsettings into PATH
- Create versioned symlinks for bundled libEGL.so and libGLESv2.so
- Clean up formatting in package inputs
Replace full node_modules copy with production-only FOD (mirrors
the upstream Dockerfile pattern), reducing package output from
~6.9 GB to ~1.3 GB.
Hoist @sentry/node to top-level node_modules so Electron's
require() resolution can find it. Bun nests transitive deps
inside .bun/ but Electron resolves from the realpath, requiring
the dependency to be accessible from the walked-up directory
chain.
Build AionUi from source using bun for dependency fetching and
electron-vite for TypeScript compilation. Native addons
(better-sqlite3, sharp) are compiled against nixpkgs node-gyp.
The package uses a fixed-output derivation for bun install,
electron-vite for the build, and wraps the result with nixpkgs
electron for a fully self-contained runtime.
Also includes desktop entry and icon generation.
Remove unnecessary copy to ~/.config/manicode/. The patched ELF
binary and tree-sitter.wasm stay in the nix store alongside a minimal
JS launcher that spawns the engine with terminal cleanup handling.
- Download and extract the engine binary from codebuff.com releases
- Use patchelf to set correct glibc interpreter path
- Create wrapper launcher that copies patched binary to user config
- Pre-fetch all npm dependencies (no network needed in sandbox)
- Set dontStrip/dontPatchelf to prevent fixupPhase corruption
Add freebuff v0.0.85 from npm registry — a pure JS CLI tool for
AI-assisted coding. Pre-fetches all transitive npm dependencies to
work within the Nix sandbox (no network access during build).
Version was showing as "dev" instead of "v1.5.14" because ldflags
targeted the wrong variable. Changed from internal/version.Current
to main.version which is the variable actually used by cmd/explorer.
Replace fetchurl + prebuilt binary with buildGoModule + buildNpmPackage
to compile radar natively from source. Frontend (React/Vite) is built
as a separate derivation, then embedded into the Go binary via go:embed.
Also patches the npm lockfile to add missing resolved URLs for
workspace packages that lacked them, enabling proper dependency fetching.
Closes nix-overlay-qlc