Compare commits

29 Commits

Author SHA1 Message Date
alex 0813f55762 fix(kyojin): Isolate JIT and runtime toolchains
CI / check (push) Has been cancelled
Allow a pinned JIT SDK without rebuilding PyTorch or the extension.
Keep runtime device bitcode unchanged: exporting TheRock bitcode into
the serving process crashes CLR 7.2 on a basic tensor operation.

Disable unsupported expandable segments and check all five HIP kernel
modules, with an optional GPU matmul and module-loading regression test.
2026-10-08 17:17:56 +03:00
alex 4c24610aae fix(kyojin): serve wrappers get a C compiler, hipcc and the JIT sources
CI / check (push) Has been cancelled
env.sh assumes a distro box: a system cc for Triton's runtime C builds, a hipcc
for the JIT HIP kernels and the repo root on PYTHONPATH. The wrappers now export
all three (, ,  for the amdgcn bitcode,
PYTHONPATH=${src}/gr for gr_mix_hip).

The wheel ships only the files pyproject lists, so the .hip kernel sources, the
qsa_proof marker gating the QSA prefill kernel, the dense-GEMM tuning seed and
gr/ never reached site-packages: kernels fell back to Triton and every start
re-tuned dense GEMM for 7 minutes.

Verified on the Strix Halo box: server READY, start-up 713 s -> 103 s, warm-up
418 s -> 4 s, 584-token prompt served over /v1/chat/completions with no
'unavailable' fallbacks.
2026-10-08 15:57:52 +03:00
alex e061d3c170 feat(kyojin): add Kyojin ExLlamaV3 engine for AMD Strix Halo
CI / check (push) Has been cancelled
Kyojin (Yamz-Labs/kyojin) is a fork of ExLlamaV3 that runs 100 GB-class
EXL3 MoE packs on one 128 GB Ryzen AI Max box. It ships a torch C++
extension that torch's cpp_extension cross-compiles to HIP, and upstream
supports gfx1151 only, so the kernels are built for gfx1151 alone and
the package is marked Linux-only. Pinned to the v1.3 release.

The extension must be compiled against a ROCm build of torch. The flake's
nixos-unstable carries torch 2.13, whose ROCm build fails in nixpkgs (the
CK SDPA configure step runs a script through /bin/bash) and has no binary
on the cache, so the build would compile PyTorch from source and die.
python3Packages.torchWithRocm from the already pinned nixpkgs-torch211
input gives torch 2.11 with ROCm 7.2.2, gfx1151 in its target list and a
cached binary, so default.nix builds through that input the way freetoken
does.

nixpkgs splits the single devel tree the AMD wheels ship, so two
symlinkJoins stand in for it: one as ROCM_HOME (hipcc, headers, amdgcn
bitcode) and one handed to setup.py as EXL3_ROCM_DEV_INCLUDE, which wants
hipsparse/, rocsparse/, rocrand/, thrust/ and pybind11 (nixpkgs torch no
longer exports pybind11 headers). hipsolver is in there because torch's
own HIPContextLight.h includes it.

setup.py gets one patch in postPatch. It imports exllamav3 to reach
build_config, that runs the package __init__, which imports ext.py, which
JIT-compiles the entire extension whenever no precompiled exllamav3_ext is
importable, meaning every wheel build, into a $HOME the sandbox does not
grant. Registering a stub package keeps the two leaf modules importable
without that detour.

doCheck = false: tests/ drives a real gfx1151 GPU and the published
packs. Inference on a card is not verified here, this builder has no
/dev/kfd, so the wheel-only LD_PRELOAD workaround for torch's bundled HSA
runtime is untested. It should not be needed, the store torch links the
store rocm-runtime.

Verified with nix build .#kyojin at v1.3: exllamav3_ext loads, torch
reports hip 7.2.53211, the closure holds one torch (ROCm), and
kyojin-serve-qwen plus kyojin-serve-glm print their usage.

Refs nix-overlay-du9
2026-10-07 16:14:09 +03:00
alex ff1fecc0ed fix(codeaf): build furrow from source and hand it over in CODEAF_FURROW
CI / check (push) Has been cancelled
The package used to fetch the Agent-Field/furrow release asset and stage it for
go:embed, which is what `make build` does. Those bytes are a stock glibc build
that no Nix phase ever touched, so the copy codeaf writes out to
~/.codeaf/bin/furrow-0.1.0 cannot start here: NixOS answers "Could not start
dynamically linked executable" and names stub-ld. Every furrow verb the package
offers was dead with it.

Staging a rebuilt furrow was not an option. Upstream's fetcher hashes what it
stages against internal/furrowbin/pin.json and refuses anything else, and
patching the downloaded asset changes its hash. So this stages nothing, and
./furrow.nix builds the pinned version from source instead. The wrapped codeaf
passes it through CODEAF_FURROW, which internal/furrow reads before it looks at
the embedded copy, so the go binary carries no furrow at all (63 MB, was 67 MB)
and nothing unpatched is written to the state root.

furrow is Rust, not Go, and rusqlite bundles sqlite, hence the build time. Its
test suite wants a filesystem that supports user.* xattrs; the sandbox /tmp is
tmpfs and answers EOPNOTSUPP, which takes out the fixture of all 54 cli tests at
tests/cli.rs:48 and one lib test with it. The unit tests run, minus that one.

Verified with nix build .#codeaf: `codeaf --version` reports 0.7.1, the wrapper
sets CODEAF_FURROW to the store furrow, that furrow prints `furrow 0.1.0`
against store glibc, and it sits in the codeaf output's references so a gc
cannot pull it out from under the wrapper. Not verified on darwin, no builder.

Refs nix-overlay-bju
2026-10-07 11:33:48 +03:00
alex c08c444a39 fix(marmel): skip the two Landlock sandbox-exec tests
CI / check (push) Has been cancelled
The lib suite failed in the Nix sandbox:

    harness::sandbox::tests::test_internal_sandbox_exec_dev_null_and_dns
    harness::sandbox::tests::test_internal_sandbox_cross_directory_rename
    Failed to exec shell in sandbox: Permission denied (os error 13)

apply_landlock_linux() allow-lists FHS paths only, and Landlock matches
inodes rather than symlinked views, so nothing under /nix/store can be
executed once the ruleset is applied; /bin/sh here is a store path. The
build sandbox also drops the /usr, /lib, /run and /var rules, since those
paths do not exist there, and has no /etc/resolv.conf without network, so
neither test can pass however the package is written. 342 of 344 tests run,
all green.

The same denial applies at runtime: every shell tool call goes through
marmel --internal-sandbox-exec and fails on NixOS. Tracked as
nix-overlay-5ml. Upstream main still carries the FHS-only list.
2026-10-06 22:31:40 +03:00
alex 03337bc545 feat(codeaf): add CodeAF coding agent package
CI / check (push) Has been cancelled
CodeAF (Agent-Field/CodeAF) is a Go coding harness that ships one binary.
Pinned to v0.7.1; the flake's nixpkgs already carries go 1.26.7 and go.mod
asks for 1.26.5, so no extra nixpkgs input is needed.

Two things about this build are not obvious from the derivation:

- `make build` runs two host-side steps before compiling: `go generate
  ./internal/manual` packs the built-in manual into the pages.pack.gz and
  chat.pack.gz that the codeaf_packed_manual tag embeds, and
  internal/furrowbin/cmd/fetch stages the pinned Agent-Field/furrow release
  into internal/furrowbin/cache for go:embed. Both are run in preBuild with
  GOOS/GOARCH unset, the way the Makefile does it, so a cross build does not
  try to run a target binary on the build machine. buildGoModule runs preBuild
  in the vendoring derivation as well, before vendor/ exists and before the
  dependencies are in reach, so the two steps are gated on vendor/.
- The furrow step gets its bytes from fetchurl and `-from`, the offline road
  upstream documents. The fetcher still checks the sha256 in
  internal/furrowbin/pin.json, so the hashes here duplicate a pin that is
  already in the source; drop the furrow entirely and codeaf still builds and
  falls back to looking for the binary on PATH.

Tests are off: the upstream suite is a make/CI matrix with network and timing
assumptions, not a `go test ./...` that fits buildGoModule.

Verified with nix build .#codeaf, `codeaf --version` reporting 0.7.1 and
`codeaf manual` listing the packed manual pages.

Refs nix-overlay-m5y
2026-10-06 21:45:16 +03:00
alex dcbde330e4 fix(graphify): roll pin back to v0.9.77
CI / check (push) Has been cancelled
The 1.0.0 bump took a bogus tag. Graphify-Labs/graphify carries a
v1.0.0 branch from 2026-04-05 that sits 2126 commits behind v0.9.77,
still ships pyproject name graphifyy 0.1.10, and never reached PyPI,
where 0.9.77 is the latest release. nix-update picked it because it is
the highest semver tag available.

It also does not build here. Its pyproject hard-requires graspologic,
which pulls python-future, and nixpkgs disables that for Python >= 3.13
(this flake is on 3.14). Lowering the interpreter is no way out either:
python312 fails further down the chain on falcon and hyppo. 0.9.x ships
a networkx Louvain fallback for a missing Leiden backend; 1.0.0 imports
graspologic.partition.leiden unconditionally, so it is worse code even
if it did build.

Dependency corrections for the pinned source:
- datasketch dropped: upstream vendored MinHash into
  graphify/_minhash.py, which also retires the pybloomfilter3
  dontCheckPythonMetadata workaround in default.nix
- numpy added: graphify/_minhash.py imports it directly

Verified with nix build .#graphify (pythonImportsCheck passes) and
graphify --version reporting 0.9.77.

Refs nix-overlay-olq
2026-10-06 19:50:01 +03:00
alex 029d84940d chore(marmel): bump to 1.0.0
Pin upstream release commit d6627d7c ("1.0.0 (#6)"), update src hash.
Cargo.lock is byte-identical to the previous pin, so cargoHash is unchanged.
2026-10-06 19:20:49 +03:00
alex aa2c0995b2 docs(readme): track llama.cpp b11439 in the package table
CI / check (push) Has been cancelled
The table still advertised b9645 after the pin moved, so the README
contradicted the package it documents.

🤖 Generated with Codebuff
Co-Authored-By: Codebuff <noreply@codebuff.com>
2026-10-06 16:49:50 +03:00
alex 6013b17aad chore(packages): bump pins to current upstream releases
Refresh every package pin so the overlay stops carrying versions upstream
has moved past, and repair the pins where an automated bump had produced a
version that no longer resolves:

- graphify 0.9.61 -> 1.0.0 and back to tag tracking: the branch-tracking
  update script generated v0.9.77-unstable-<date> for a rev = "v${version}"
  src, a tag that never existed
- radar 1.13.1 -> 1.16.2 (upstream retagged its releases as k8s-ui-v*)
- llama-cpp b9645 -> b11439
- hipengine 0.5.0 -> 0.6.1, traycer 1.3.0 -> 1.4.2, freetoken 0.1.2 -> 0.1.3
- awg-tool 0.4.0, freebuff 0.2.19, kubernetes-mcp-server 0.0.67,
  marmel 0-unstable-2026-10-05, open-code-review 1.12.12,
  ds4 0-unstable-2026-09-20
- version-string normalisation for the branch-tracked packages already at
  their newest commit (g3, haivemind, shardr, skillsmcp)

Every changed src hash was re-fetched and verified. omniroute stays at
3.8.50: 3.8.51 changes its npm lockfile, so its npmDepsHash would have to
be recomputed before the bump is usable.

🤖 Generated with Codebuff
Co-Authored-By: Codebuff <noreply@codebuff.com>
2026-10-06 16:46:26 +03:00
alex 4fe8f68e9b feat(shardr): Add shardr package to the overlay
CI / check (push) Has been cancelled
Decentralized LLM repository (Go): content-addressed model store with
BitTorrent-based sync and OpenAI-compatible serving via llama-server.
Upstream has no tagged source releases, so the package is pinned to
main HEAD (fab7fa8) with a nix-update script targeting the branch.
Builds both shardr and shardhive binaries.
2026-10-04 19:54:11 +03:00
alex c5c3696df7 chore(git): ignore .beads.gate.lock runtime artifact
CI / check (push) Has been cancelled
bd creates an empty 0600 lock at the repo root; it was staged by accident
and has never been tracked.
2026-10-02 09:33:01 +03:00
alex b7e19f7381 chore(agents): drop CLAUDE.md duplicate of AGENTS.md
AGENTS.md holds the full agent workflow rules; the CLAUDE.md copy only
duplicated the beads integration block. Update the serena core memory so
it points at the one remaining file.
2026-10-02 09:32:57 +03:00
alex 864447de71 chore(agents): point Matt Pocock skills at the beads issue tracker
CI / check (push) Has been cancelled
The engineering skills (to-tickets, triage, spec, wayfinder) need to know
where issues live for this repo. It is not the Gitea forge remote; it is
bd/beads, which AGENTS.md already mandates for all task tracking.

Adds docs/agents/issue-tracker.md (bd commands and wayfinding mapping),
docs/agents/triage-labels.md (five canonical roles kept as-is, applied
with bd tag / bd label add), docs/agents/domain.md (single-context
layout: CONTEXT.md plus docs/adr/ at the root), and an 'Agent skills'
index block in AGENTS.md. The pre-existing staged deletion of CLAUDE.md
is left out of this commit and stays in the index.
2026-10-02 09:26:40 +03:00
alex 704b8e577a feat(open-code-review): expose ocr alias for the CLI binary
CI / check (push) Has been cancelled
Upstream and the bundled OpenCode plugin invoke the tool as `ocr`, but the
Go build names the binary after its cmd/ directory (`opencodereview`), so
the CLI was missing from PATH under the name everything expects.
2026-09-28 15:30:31 +03:00
alex b6becd5e01 feat: bundle opencode plugin as open-code-review passthru + HM module
CI / check (push) Has been cancelled
- packages/open-code-review/opencode-plugin.nix: builds the plugin TS file
  plus runtime node_modules from the plugin's package-lock.json into
  share/open-code-review/opencode (exposed as passthru.opencode-plugin,
  same source rev as the CLI so versions stay locked)
- modules/open-code-review-hm.nix: homeManagerModules.default with
  programs.open-code-review.{enable,opencode.enable} — symlinks the plugin
  and node_modules into ~/.config/opencode/plugins/ and installs the CLI
- flake.nix: expose homeManagerModules.default

Note: upstream declares the plugin SDKs as devDependencies, so the
lockfile install must not use --omit=dev.

🤖 Generated with Codebuff
Co-Authored-By: Codebuff <noreply@codebuff.com>
2026-09-26 11:35:09 +03:00
alex 308494febe feat: add open-code-review package (alibaba AI code review CLI)
CI / check (push) Has been cancelled
Build alibaba/open-code-review v1.12.9 from source via buildGoModule
(CGO disabled, cmd/opencodereview subpackage, version ldflags).

🤖 Generated with Codebuff
Co-Authored-By: Codebuff <noreply@codebuff.com>
2026-09-26 10:24:25 +03:00
alex a150408a5a Add Serena configuration and project memories
CI / check (push) Has been cancelled
(Set up Serena IDE integration with a Nix language server and create a
memory graph documenting package conventions, core structure, tech
stack, and task completion workflows.)
2026-09-23 14:54:50 +03:00
alex c437841a86 feat(packages): add g3
CI / check (push) Has been cancelled
Pinned commit: upstream has no tags. Ships g3 and g3-studio.

Closes nix-overlay-ikz
2026-09-23 14:52:31 +03:00
alex 5f848a82a3 chore(beads): Export marmel follow-ups and close marmel package task
CI / check (push) Has been cancelled
2026-09-14 12:32:44 +03:00
alex 5d46cbde3f bd: update sync.remote
CI / check (push) Has been cancelled
2026-09-14 12:31:44 +03:00
alex 3ee46a6824 chore(beads): File marmel racy-test and nix build .#packages follow-ups 2026-09-14 12:31:39 +03:00
alex d74788a4cb feat(packages): Add marmel autonomous coding agent
Pin Na1w/marmel to commit fd551ae. Upstream publishes no tags or
releases, so the version uses the shape nix-update generates for a
tagless repository, keeping `nix-update --version=branch=main` usable.

The test suite runs green (325 lib tests plus all integration suites)
with two accommodations, both documented in the derivation:

- Export SSL_CERT_FILE from nixpkgs cacert. rustls refuses to construct
  a reqwest::Client without a system trust store, which failed 38 tests
  with "No CA certificates were loaded from the system".
- Serialise the test harness. The lib suite shares process-global worker
  registries and steer/abort buses, so manager-loop tests fail
  nondeterministically on parallel threads: one unchanged derivation
  produced 3 failures, then 1 failure, then 0 with --test-threads=1.
  No test is skipped or filtered.

Annotated example configs are installed to share/doc/marmel/examples/.
Role prompts are embedded via include_str!, so there is no runtime data
directory. Upstream README states MIT but ships no LICENSE file and no
Cargo.toml license field.
2026-09-14 12:31:39 +03:00
alex 4ec88a70ed chore(beads): close flake.lock refresh task 2026-09-14 01:18:53 +03:00
alex 3f868775af chore(flake): refresh nixpkgs inputs to 2026-09-11
Bump nixpkgs and nixpkgs-latest from 2026-05/2026-08 to current
nixos-unstable (2026-09-11); both inputs now resolve to the same rev.
Re-validated every package against the new inputs.

Fallout fixed:
- freetoken: upstream pins torch>=2.11,<2.12 and triton==3.6.0, but the new
  nixpkgs only ships torch 2.13 / triton 3.7. Add a nixpkgs-torch211 input
  pinned at the previous revision and build freetoken against it, keeping
  the CUDA 12.9 / torch 2.11 stack unchanged.
- graphify: nixpkgs' pybloomfilter3 0.7.3 ships sdist metadata that still
  says 0.7.2, tripping pythonMetadataCheckPhase; skip that check only.

All 22 packages build and `nix flake check --no-build` passes.
2026-09-14 01:18:49 +03:00
alex b5dfa1b08d chore(beads): close package-update task and record llama-cpp follow-up
CI / check (push) Has been cancelled
2026-09-13 21:17:57 +03:00
alex b9e759a2c1 chore(packages): bump packages to latest upstream versions
Update every package to its newest upstream release/commit:
- aionui 2.1.50 -> 2.2.2
- awg-tool 0.2.2 -> 0.3.0
- ds4 -> 0-unstable-2026-09-12
- freebuff 0.0.142 -> 0.0.174
- graphify 0.9.35 -> 0.9.61
- hipengine 0.3.0 -> 0.5.0
- mcp-gateway 3.4.0 -> 3.5.1
- omniroute 3.8.49 -> 3.8.50
- radar 1.9.1 -> 1.13.1
- relay-free-llm -> 0-unstable-2026-08-31
- traycer 1.1.10 -> 1.3.0

Refresh all source/dependency hashes (src, cargoHash, vendorHash,
npmDepsHash, bun FODs) and keep treefmt clean.

Packaging fixes required by the bumps:
- graphify: relax the setuptools>=83 build-backend pin (nixpkgs ships
  setuptools 80.x; the PEP 639 metadata needs only >=77).
- hipengine: add a llguidance 1.8.0 override (nixpkgs ships 1.7.x).
- omniroute: use npmDepsFetcherVersion 2; the v1 fetcher drops packages
  whose lockfile entries lack resolved URLs, breaking npm's cache check.
- radar: fix a frontend npmDepsHash/vendorHash swap from nix-update.

Packages already at latest are untouched: container-use, desloppify,
freetoken, kubernetes-mcp-server, loop, nftables-analyzer,
nftablesbuilder, stakpak, haivemind, skillsmcp. llama-cpp stays pinned
at b9645 and is tracked separately (manual HIP flag re-validation).
2026-09-13 21:06:04 +03:00
alex f9a45d14af chore(beads): close llama-cpp package issue
CI / check (push) Has been cancelled
2026-09-13 13:38:07 +03:00
alex 73f782d523 feat(packages): add llama-cpp b9645 for Strix Halo (ROCm + Vulkan)
Pin upstream llama.cpp b9645 and build it against the nixpkgs-latest
input (the flake's pinned nixpkgs only carries the pre-tools/ui b8983).
ROCm deps come from rocmPackages.gfx1151, so clr/rocBLAS/hipBLAS are
built for gfx1151 only; clr's own build is arch-independent, so its
store path stays substitutable. Vulkan on, CPU variants with znver5 /
AVX-512, web UI and npm toolchain dropped.

Ported from nixos-config's llm-engine.nix with two fixes: npmConfigHook
hard-fails when npmDeps is null, so nodejs and the hook are stripped
from nativeBuildInputs, and CMAKE_HIP_FLAGS is appended to
cmakeFlagsArray because the cmake hook word-splits plain cmakeFlags.

Verified on the Radeon 8060S (gfx1151): llama-bench loads both ROCm and
Vulkan backends and completes pp16/tg8 runs.
2026-09-13 13:33:30 +03:00
56 changed files with 1768 additions and 154 deletions
+2
View File
@@ -52,3 +52,5 @@
# - linear.api-key
# - github.org
# - github.repo
sync.remote: "git+ssh://git@git.millerson.name:22002/alex/millerson-overlay.nix.git"
+20 -12
View File
@@ -1,12 +1,20 @@
{"_type":"issue","id":"nix-overlay-dv3","title":"Fix Config screen crash on F2","description":"F2 opens ConfigScreen then Textual raises InvalidSelectValueError because _refresh_aggregator_dropdown assigns Select.BLANK, resolved as False, instead of clearing selection.\\n\\nAcceptance: Config screen opens with saved consensus configuration; regression covers no selected aggregator; targeted tests pass.","status":"closed","priority":1,"issue_type":"bug","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-08-20T11:34:03Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-08-20T11:37:47Z","started_at":"2026-08-20T11:34:07Z","closed_at":"2026-08-20T11:37:47Z","close_reason":"Replaced invalid Select.BLANK handling; built haivemind and verified ConfigScreen headlessly.","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-a9m","title":"Fix haivemind startup after MainScreen mount","description":"Restore deferred engine startup while preserving MainScreen widget lookup fix.","status":"closed","priority":1,"issue_type":"bug","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-08-20T11:20:36Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-08-20T11:21:43Z","started_at":"2026-08-20T11:20:43Z","closed_at":"2026-08-20T11:21:43Z","close_reason":"Restored engine startup after MainScreen mount and verified package build.","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-q2m","title":"Add FreeToken package (FlashML-org/FreeToken)","description":"Package https://github.com/FlashML-org/FreeToken into the overlay following the standard packages/\u0026lt;name\u0026gt;/{default.nix,package.nix} pattern. Must build via nix build, README updated, category set.","notes":"Build in progress. Resolved: tvm-ffi 0.1.13.post3 builds (cython 3.3.0 vendored, dontUsePytestCheck due to xdist addopts), flashlib wheel + pythonRemoveDeps, freetoken pythonRelaxDeps gguf/modelscope. Remaining: torch-bin CUDA closure (nccl done; libnvshmem source build ~hours), then freetoken extensions. Note: torch-bin 2.11 = +cu128 PyPI wheel autoPatchelf'd to nixpkgs cuda12.9 libs.","status":"closed","priority":2,"issue_type":"feature","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-08-30T06:40:20Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-08-30T17:51:10Z","started_at":"2026-08-30T06:40:34Z","closed_at":"2026-08-30T17:51:10Z","close_reason":"freetoken 0.1.2 packaged: builds via nix build .#freetoken, ft CLI verified (ft --version), imports checked, RPATHs correct (cudart 12.9 + torch-bin libs). Docs in README + meta.longDescription.","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-q00","title":"Add haivemind package","description":"Package https://github.com/dev-boz/haivemind in the Nix overlay, document it, validate the build, and complete repository workflow.","status":"closed","priority":2,"issue_type":"task","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-08-08T16:32:37Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-08-08T16:36:41Z","started_at":"2026-08-08T16:33:00Z","closed_at":"2026-08-08T16:36:41Z","close_reason":"Closed","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-67e","title":"Add traycer package","description":"Add new package for traycer from https://github.com/traycerai/traycer. Steps: research repo build system, create packages/traycer/, stage with git add, test nix build, update README.","status":"closed","priority":2,"issue_type":"task","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-08-07T08:59:25Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-08-07T09:22:07Z","started_at":"2026-08-07T09:00:29Z","closed_at":"2026-08-07T09:22:07Z","close_reason":"Traycer package added, built, pushed","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-2gf","title":"Update all packages to latest versions","description":"## Why\\nUser request: update every package in the overlay to its latest upstream version.\\n\\n## What\\nBump version + src hash (and cargoHash for Rust) in each packages/\u003cname\u003e/package.nix, update README table if needed, verify builds.\\n\\n## Acceptance\\n- Every package builds with nix build .#\u003cname\u003e\\n- README reflects new versions\\n- Changes committed and pushed","notes":"All packages updated and built successfully. Commit 1f3f0f468bdd on local main. PUSH BLOCKED: git.millerson.name:22002 and DoltHub unreachable from this network (SSH connect timeout). Re-run git push + bd dolt push when network is back, then close.","status":"closed","priority":2,"issue_type":"task","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-08-07T07:22:50Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-08-07T13:17:34Z","started_at":"2026-08-07T07:22:55Z","closed_at":"2026-08-07T13:17:34Z","close_reason":"All packages updated to latest versions, verified building, pushed to origin","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-9xs","title":"Update all packages to latest versions","description":"Update every package in packages/ to its latest upstream version, refresh source hashes and cargoHashes, verify builds, update README.","status":"in_progress","priority":2,"issue_type":"task","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-08-07T05:45:16Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-08-07T05:45:22Z","started_at":"2026-08-07T05:45:22Z","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-f8c","title":"Add nftablesbuilder package","description":"Package NftablesBuilder (github.com/AiseBouma/NftablesBuilder) web interface to manage nftables. Upstream source is incomplete (missing settings crate, no GUI build tooling, no Cargo.lock) so: patch in authored settings crate (schema from release artifacts), build Rust workspace from pinned commit, reuse built GUI assets from hash-pinned release tarball.","status":"closed","priority":2,"issue_type":"task","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-08-07T04:58:22Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-08-07T05:38:40Z","started_at":"2026-08-07T04:58:25Z","closed_at":"2026-08-07T05:38:40Z","close_reason":"Package added, builds green, committed","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-bjd","title":"Add nftables-analyzer CLI package","description":"Add python3Packages.buildPythonApplication derivation for reinaldosaraiva/nftables-analyzer (CLI only). Pin to main commit 5fc78d0c9ce173e3baa80a5655bcadb1b2f78493 (no tags upstream). sourceRoot=source/backend, hatchling build system. Category: Networking. Frontend excluded - upstream repo missing frontend/src/lib modules.","status":"closed","priority":2,"issue_type":"task","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-08-07T04:48:07Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-08-07T04:50:25Z","started_at":"2026-08-07T04:48:10Z","closed_at":"2026-08-07T04:50:25Z","close_reason":"Package added, built, smoke-tested, committed","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-5gg","title":"freetoken: optional accel extras and kernel-cache wheel","description":"Follow-ups for the freetoken package: (1) package flashinfer[cu12] and sglang-kernel 0.4.5 (accel extra) so the native fast path is available instead of the Triton fallback; (2) package the freetoken-kernel-cache companion wheel (prebuilt TVM FFI kernels, built via scripts/build-release-wheels.sh) so TVM JIT kernel compilation (nvcc at runtime) can be avoided. Both blocked on suitable PyPI/CUDA packaging work in nixpkgs (flashinfer exists in nixpkgs but needs cu12 variant). Priority: backlog.","status":"open","priority":3,"issue_type":"task","owner":"alex@millerson.name","created_at":"2026-08-30T17:58:57Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-08-30T17:58:57Z","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-vhq","title":"Note missing Dolt remote in AGENTS.md","description":"## Why\\nAgents running bd dolt push see 'No remote is configured - skipping' and may mistake it for a failure (blocking session close). Document that this is expected: no Dolt remote is set up, beads state is versioned locally in .beads/ and committed via git.\\n\\n## What\\nAdd a short note in the Beads Issue Tracker / Session Completion section of AGENTS.md.\\n\\n## Acceptance\\n- AGENTS.md explains the expected bd dolt push output and that git push is the actual sync mechanism","status":"closed","priority":3,"issue_type":"task","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-08-07T13:18:33Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-08-07T13:19:26Z","started_at":"2026-08-07T13:18:51Z","closed_at":"2026-08-07T13:19:26Z","close_reason":"AGENTS.md updated and pushed","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"memory","key":"python-packaging-in-this-overlay-torch-bin-cuda","value":"python packaging in this overlay: torch-bin (CUDA) propagates triton-bin — always use py.torch-bin AND py.triton-bin together (python-packages.nix maps torch-bin = callPackage { triton = self.triton-bin; }) or you get duplicate triton in closure. Unfree CUDA deps: self-scope with 'import pkgs.path { config.allowUnfree = true; }' inside package.nix — no flake-level or user config changes needed. cuda_cudart include lacks crt/ headers — they live in cudaPackages.cuda_nvcc/include/crt; merge into a synthetic CUDA_HOME. pythonRuntimeDepsCheck enforces version constraints (not just names) — use pythonRelaxDeps/pythonRemoveDeps."}
{"_type":"issue","id":"nix-overlay-4g1","title":"Add marmel package","description":"Package Na1w/marmel (binary: marmel, cargo crate: marmennill), an autonomous agentic coding assistant.\n\nDecisions from grilling session:\n- attr/pname/mainProgram = marmel\n- version = unstable-2026-09-13 (tagless upstream; matches nix-update --version=branch=main output shape)\n- rev = fd551ae3198d427b0f0df3429f88764c49095b23, updateScript = nix-update --version=branch=main\n- license = mit (upstream README claims MIT; no LICENSE file, no Cargo.toml license field)\n- platforms = unix\n- category = AI Coding Agents\n- doCheck = true, triage sandbox-hostile PTY/Landlock tests by name; fall back to doCheck=false with comment only if suite is unsandboxable\n- install annotated example configs to share/doc/marmel/examples/\n- verification: nix build .#marmel, nix run .#marmel -- --help, nix eval version, nix flake check, nix build .#packages, README table row\n\nKnown build risk: aws-lc-sys (via rustls-platform-verifier) is a CMake/NASM C build; add only the build inputs the build actually demands.","status":"closed","priority":2,"issue_type":"task","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-09-14T08:56:39Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-09-14T09:32:05Z","started_at":"2026-09-14T08:56:49Z","closed_at":"2026-09-14T09:32:05Z","close_reason":"marmel packaged and pushed: nix build green with 325 tests, --help smoke test passes, flake check passes with unfree allowed, launcher list includes marmel. Follow-ups filed as nix-overlay-d2r (racy upstream tests) and nix-overlay-05n (nix build .#packages broken).","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-89n","title":"Refresh flake.lock nixpkgs inputs","description":"Update nixpkgs and nixpkgs-latest flake inputs (pinned 2026-05 and 2026-08) to current nixos-unstable, then re-validate package builds.","status":"closed","priority":2,"issue_type":"task","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-09-13T18:40:17Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-09-13T22:18:53Z","started_at":"2026-09-13T18:40:18Z","closed_at":"2026-09-13T22:18:53Z","close_reason":"nixpkgs/nixpkgs-latest bumped to 2026-09-11, freetoken pinned to nixpkgs-torch211, all 22 packages build and flake check passes.","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-cfk","title":"Update all packages to latest upstream versions","description":"Bump every package in packages/ to its latest available upstream version, refresh hashes (src, cargoHash, vendorHash, npm deps, bun2nix, appimage, etc.), verify builds, and update README. Packages: aionui, awg-tool, container-use, desloppify, ds4, freebuff, freetoken, graphify, haivemind, hipengine, kubernetes-mcp-server, llama-cpp, loop, mcp-gateway, nftables-analyzer, nftablesbuilder, omniroute, radar, relay-free-llm, skillsmcp, stakpak, traycer.","status":"closed","priority":2,"issue_type":"task","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-09-13T13:59:31Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-09-13T18:06:08Z","started_at":"2026-09-13T13:59:35Z","closed_at":"2026-09-13T18:06:08Z","close_reason":"All packages bumped to latest upstream; treefmt clean and nix flake check --no-build passes.","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-05o","title":"Add llama-cpp package (build 9645) to overlay","description":"Port the pinned llama.cpp b9645 derivation from nixos-config/modules/llm-engine.nix into packages/llama-cpp/ (default.nix + package.nix). ROCm + Vulkan enabled, znver5 CPU flags, strix-halo gfx1151 orientation. Must build via nix build .#llama-cpp.","status":"closed","priority":2,"issue_type":"feature","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-09-13T09:22:26Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-09-13T10:33:35Z","started_at":"2026-09-13T09:22:28Z","closed_at":"2026-09-13T10:33:35Z","close_reason":"llama-cpp b9645 packaged in packages/llama-cpp, built and smoke-tested on gfx1151 (ROCm + Vulkan)","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-6y6","title":"Add Loop corporate messenger package","description":"Add Loop - Corporate messenger for your team. Distributed as x86-64 binary from https://artifacts.wilix.dev/repository/loop-files/loop-6.0.3/loop-desktop-6.0.3-linux-x64.tar.gz","status":"closed","priority":2,"issue_type":"feature","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-05-29T16:41:37Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-05-29T16:51:32Z","started_at":"2026-05-29T16:42:02Z","closed_at":"2026-05-29T16:51:32Z","close_reason":"Closed","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-cdt","title":"radar-1.6.1","description":"update package radar to v1.6.1","status":"closed","priority":2,"issue_type":"task","owner":"alex@millerson.name","created_at":"2026-05-17T12:41:54Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-05-17T13:03:38Z","closed_at":"2026-05-17T13:03:38Z","close_reason":"Closed","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-27z","title":"freebuff","description":"В данный nixos overlay репозиторй необходимо добавить новый пакет https://www.npmjs.com/package/freebuff .\nИспользуй mcp: nixos, karpathy-guidelines и Sequential Thinking для планирования шаг за шагом задачи. Управление тасками используй beads. Разбей задачу на подзадачи, используя beads с указанием parent task.\n\nRequired Skills\ncaveman,karpathy-guidelines,nix,nix-flakes","status":"closed","priority":2,"issue_type":"feature","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-05-11T16:11:44Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-05-11T17:03:53Z","started_at":"2026-05-11T16:17:34Z","closed_at":"2026-05-11T17:03:53Z","close_reason":"Closed","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-qlc.5","title":"Update package metadata and updateScript","description":"Remove binaryNativeCode sourceProvenance, update meta, adjust updateScript for source build","status":"closed","priority":2,"issue_type":"task","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-05-11T13:51:22Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-05-11T15:01:06Z","started_at":"2026-05-11T14:59:33Z","closed_at":"2026-05-11T15:01:06Z","close_reason":"Closed","dependencies":[{"issue_id":"nix-overlay-qlc.5","depends_on_id":"nix-overlay-qlc","type":"parent-child","created_at":"2026-05-11T16:51:21Z","created_by":"Alexander Miroshnichenko","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-qlc.4","title":"Test build and verify functionality","description":"Build radar from source and verify it runs correctly","status":"closed","priority":2,"issue_type":"task","owner":"alex@millerson.name","created_at":"2026-05-11T13:51:11Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-05-11T14:59:55Z","closed_at":"2026-05-11T14:59:55Z","close_reason":"Closed","dependencies":[{"issue_id":"nix-overlay-qlc.4","depends_on_id":"nix-overlay-qlc","type":"parent-child","created_at":"2026-05-11T16:51:10Z","created_by":"Alexander Miroshnichenko","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-qlc.3","title":"Handle go:embed frontend assets","description":"Ensure frontend assets are copied to internal/static/dist before Go build so go:embed works correctly","status":"closed","priority":2,"issue_type":"task","owner":"alex@millerson.name","created_at":"2026-05-11T13:51:02Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-05-11T14:59:55Z","closed_at":"2026-05-11T14:59:55Z","close_reason":"Closed","dependencies":[{"issue_id":"nix-overlay-qlc.3","depends_on_id":"nix-overlay-qlc","type":"parent-child","created_at":"2026-05-11T16:51:02Z","created_by":"Alexander Miroshnichenko","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-qlc.2","title":"Configure npm dependencies for frontend build","description":"Set up npmDependencies hash for the Vite/React frontend build within buildGoModule","status":"closed","priority":2,"issue_type":"task","owner":"alex@millerson.name","created_at":"2026-05-11T13:50:53Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-05-11T14:59:55Z","closed_at":"2026-05-11T14:59:55Z","close_reason":"Closed","dependencies":[{"issue_id":"nix-overlay-qlc.2","depends_on_id":"nix-overlay-qlc","type":"parent-child","created_at":"2026-05-11T16:50:52Z","created_by":"Alexander Miroshnichenko","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-qlc.1","title":"Update radar default.nix to use buildGoModule","description":"Change package.nix from stdenv.mkDerivation with fetchurl to buildGoModule pattern","status":"closed","priority":2,"issue_type":"task","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-05-11T13:50:42Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-05-11T14:59:55Z","started_at":"2026-05-11T13:51:49Z","closed_at":"2026-05-11T14:59:55Z","close_reason":"Closed","dependencies":[{"issue_id":"nix-overlay-qlc.1","depends_on_id":"nix-overlay-qlc","type":"parent-child","created_at":"2026-05-11T16:50:41Z","created_by":"Alexander Miroshnichenko","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-qlc","title":"Rebuild radar package from source instead of prebuilt binary","description":"Current radar package uses prebuilt binary from GitHub releases. Need to rebuild from source using nix native tooling (buildGoModule + npm for frontend). Build pipeline: 1) npm run build for frontend, 2) copy assets to internal/static/dist, 3) CGO_ENABLED=0 go build with embedded assets.","status":"closed","priority":2,"issue_type":"task","owner":"alex@millerson.name","created_at":"2026-05-11T13:50:27Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-09-14T12:29:23Z","closed_at":"2026-05-11T15:01:06Z","close_reason":"Closed","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-y8r","title":"nix-overlay-2lr-3 · Approach 3: ручной npm cache + buildGoModule [parent:nix-overlay-2lr]","notes":"BLOCKED: fetchNpmDeps v2 не загружает workspace-scoped пакеты (@vitejs/plugin-react ENOTCACHED) даже с makeCacheWritable=true. Все 3 подхода заблокированы одним ограничением — fetchNpmDeps v2 не поддерживает npm workspaces корректно, вопреки release notes.","status":"closed","priority":2,"issue_type":"task","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-05-11T09:38:34Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-05-11T11:14:40Z","started_at":"2026-05-11T10:23:41Z","closed_at":"2026-05-11T11:14:40Z","dependencies":[{"issue_id":"nix-overlay-y8r","depends_on_id":"nix-overlay-2lr","type":"parent-child","created_at":"2026-05-11T12:42:18Z","created_by":"Alexander Miroshnichenko","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-dcx","title":"nix-overlay-2lr-2 · Approach 2: bun2nix генерация пакетов [parent:nix-overlay-2lr]","notes":"Skipping bun2nix — требует staging branch, неочевидная поддержка npm lockfiles. Проще перейти к Approach 3 (ручной stdenv.mkDerivation с nodejs/npm).","status":"closed","priority":2,"issue_type":"task","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-05-11T09:38:06Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-05-11T10:23:18Z","started_at":"2026-05-11T10:21:04Z","closed_at":"2026-05-11T10:23:18Z","dependencies":[{"issue_id":"nix-overlay-dcx","depends_on_id":"nix-overlay-2lr","type":"parent-child","created_at":"2026-05-11T12:42:12Z","created_by":"Alexander Miroshnichenko","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-3ik","title":"nix-overlay-2lr-1 · Approach 1: buildNpmPackage + buildGoModule с npmDepsFetcherVersion=2 [parent:nix-overlay-2lr]","notes":"fetchNpmDeps v2 не resolves workspace-scoped packages (@vitejs/plugin-react ENOTCACHED). Approach blocked — same issue as previous attempt. Moving to Approach 2 (bun2nix).","status":"closed","priority":2,"issue_type":"task","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-05-11T09:37:43Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-05-11T10:20:38Z","started_at":"2026-05-11T09:39:05Z","closed_at":"2026-05-11T10:20:38Z","dependencies":[{"issue_id":"nix-overlay-3ik","depends_on_id":"nix-overlay-2lr","type":"parent-child","created_at":"2026-05-11T12:41:54Z","created_by":"Alexander Miroshnichenko","metadata":"{}"}],"dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-2lr","title":"radar","description":"Используй karpathy-guidelines и Sequential Thinking для планирования шаг за шагом добавления нового пакета https://github.com/skyhook-io/radar.git в данный NIXOS overlay-репозиторий. Разбей задачу на подзадачи, используя beads. В написании кода используй mcp: nixos, refContext и context7.\n\n\n\n## Required Skills\ncaveman,karpathy-guidelines,nix,nix-flakes","notes":"Все 3 подхода провалены. fetchNpmDeps v2 НЕ работает с npm workspaces вопреки release notes - ENOTCACHED для workspace-scoped пакетов (@vitejs/plugin-react). Ручной сбор node_modules без npm ci слишком сложен (требует reimplement fetchNpmDeps). Текущее решение: pre-built binary из GitHub Releases. Нужно дождаться исправления fetchNpmDeps v2 в nixpkgs или upstream поддержки standalone lockfile для web/.","status":"closed","priority":2,"issue_type":"feature","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-05-10T19:28:56Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-09-14T12:29:23Z","started_at":"2026-05-10T19:30:31Z","closed_at":"2026-05-11T11:24:40Z","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-05n","title":"nix build .#packages is broken (and CI dead-line masked by || true)","description":"nix build .#packages fails with: expected flake output attribute 'packages' to be a derivation or path but found a set (system-keyed set from blueprint).\n\n.github/workflows/ci.yml hides this with 'nix build .#packages || true', so the CI build step never actually builds anything.\n\nLikely fix: iterate packages.x86_64-linux.\u003cname\u003e, e.g. nix build .#packages.x86_64-linux.default plus per-package evaluation, or use 'nix build .#packages.x86_64-linux.*'-style invocation if supported.\n\nAlso: 'nix flake check' fails on HEAD because packages/desloppify is unfreeRedistributable (Refusing to evaluate package 'desloppify-1.0' ... unfree license). CI runs nix flake check, so that step is red unless NIXPKGS_ALLOW_UNFREE=1 is set.","status":"open","priority":3,"issue_type":"bug","owner":"alex@millerson.name","created_at":"2026-09-14T09:29:25Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-09-14T09:29:25Z","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-d2r","title":"Report racy test isolation upstream in Na1w/marmel","description":"The lib test suite of Na1w/marmel shares process-global state (src/orchestrator/workers.rs ACTIVE_WORKERS/WORKER_CONTEXT_TOKENS/RECENT_COMPLETED_WORKERS, src/orchestrator/bus.rs GLOBAL_CANCELLATION_TOKEN, src/orchestrator/preemption.rs ACTIVE_STREAMS) so manager-loop tests fail nondeterministically under the default parallel test harness.\n\nEvidence: one unchanged nix derivation produced 3 failures (102/101/201 results vs expected 3/2/3), then 1 failure, then 0 with --test-threads=1.\n\nImpact: packages/marmel works around it with cargoTestFlags = [\"--\" \"--test-threads=1\"] and a comment. Worth reporting upstream so the workaround can be dropped.","status":"open","priority":3,"issue_type":"task","owner":"alex@millerson.name","created_at":"2026-09-14T09:29:25Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-09-14T09:29:25Z","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-k38","title":"Bump llama-cpp pin b9645 -\u003e b10944","description":"packages/llama-cpp pins ggml-org/llama.cpp to b9645 and intentionally removes passthru.updateScript. Upstream latest is b10944. The nixpkgs llama-cpp skeleton and custom HIP/cmake flags (gfx1151 Strix Halo) target b9645; a bump needs re-validating flags (e.g. hipBLASLt/rocWMMA/unified-memory) and a full ROCm rebuild. Do manually per the comment in package.nix.","status":"open","priority":3,"issue_type":"task","owner":"alex@millerson.name","created_at":"2026-09-13T18:05:55Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-09-13T18:05:55Z","dependency_count":0,"dependent_count":0,"comment_count":0}
+1
View File
@@ -11,3 +11,4 @@ result-*
*.db
.beads-credential-key
logs/
.beads.gate.lock
+2
View File
@@ -0,0 +1,2 @@
/cache
/project.local.yml
+23
View File
@@ -0,0 +1,23 @@
# nix-overlay — package conventions
## Directory pattern (every package)
`packages/<name>/default.nix` (wrapper, receives blueprint args) + `packages/<name>/package.nix` (the derivation, `pkgs.callPackage`-style argsets).
Wrapper variants:
- Plain: `{ pkgs, ... }: pkgs.callPackage ./package.nix { }`
- Needs blueprint extras: pass `perSystem`, `inputs`, etc. through explicitly.
- Alternate nixpkgs (freetoken): wrapper ignores `pkgs` for the derivation and calls `inputs.nixpkgs-torch211.legacyPackages.${pkgs.stdenv.hostPlatform.system}.callPackage ./package.nix { }`.
## Derivedivation requirements
- Use `stdenv.mkDerivation rec { pname; version; }` or `rustPlatform.buildRustPackage` (Rust: `cargoHash`; Go/Python equivalents as needed).
- `meta.description` required (feeds the default meta-package listing).
- `meta.mainProgram` set for CLI-providing packages.
- Organizational attrs via `passthru`: `category` (e.g. "AI Coding Agents"), `hideFromDocs = true` to exclude from docs listing.
- No `with pkgs;` at top level of Nix files (scope issues).
- No hardcoded system paths/system assumptions.
## Adding a package (sequence)
mkdir → package.nix → default.nix wrapper → `git add packages/<name>/` (required for blueprint discovery) → `nix build .#<name>` → update README Available Packages table → commit (conventional-commit format).
## Naming
- Package dir name = flake output attr name (kebab-case).
+30
View File
@@ -0,0 +1,30 @@
# nix-overlay — core
Nix flake overlay (numtide/blueprint-based) exposing extra packages for Nix/NixOS.
Repo: `git+https://git.millerson.name/alex/millerson-overlay.nix.git`
## Source map
- `flake.nix` — inputs + outputs; blueprint drives perSystem outputs; overlays/modules added manually on top.
- `overlays/default.nix` — binary-cache-friendly: maps blueprint's pre-built `packages` under namespace `millerson-nix-overlay`.
- `overlays/shared-nixpkgs.nix` — builds `packages/` tree against consumer's `final` via `mkPackagesFor`; shares deps, cache only hits on matching nixpkgs rev.
- `packages/<name>/default.nix` + `package.nix` — every package follows this wrapper/derivation split. See `mem:conventions` for patterns.
- `packages/default/` — meta-package; generates name\tdesc list from `perSystem.self`, filtering `passthru.hideFromDocs`.
- `packages/flake-inputs/` — dummy derivation referencing all flake inputs so they get cached. `hideFromDocs = true`.
- `treefmt.toml` — nixfmt for `*.nix`, flake.lock excluded.
- `AGENTS.md` — agent workflow rules (beads tracking, mandatory skills, caveman comms).
## Project-wide invariants
- All overlay packages live under the single attrset `millerson-nix-overlay` (not top-level attrs).
- Blueprint discovers packages from the **git index**, not the working dir: new `packages/<name>/` must be `git add`-ed before `nix build .#<name>` sees it.
- Three nixpkgs inputs; some packages deliberately build against non-default ones. See pins in `mem:tech_stack`.
- Everything under `packages/` uses `pkgs.callPackage ./package.nix { }` wrapper pattern; `default.nix` receives blueprint args (pkgs, perSystem, inputs, ...).
## Task workflow (from AGENTS.md, enforced)
Runnable commands (build/format/update/bd/push): `mem:suggested_commands`. Exact done-checklist: `mem:task_completion`.
- ALL task tracking via `bd` (beads): `bd ready`, `bd update <id> --claim`, `bd close <id>`. NEVER TodoWrite/markdown TODOs.
- `bd prime` before starting work; `bd remember` for persistent knowledge (no MEMORY.md files).
- Session not complete until `git push` succeeds (`bd dolt push` skipping with "No remote is configured" is expected, not a failure).
- Commits use conventional-commit format.
- For nixpkgs/option lookups use the `nix` skill; for flake/devShell ops the `nix-flakes` skill; comms in caveman mode.
+33
View File
@@ -0,0 +1,33 @@
# Memory Maintenance
## Discovery Model
- Core principle: progressive discovery through references, building a graph of memories.
- Initially, agents are provided with the list of all memories (names only).
- Agents should read `mem:core` as the top-level entry point (graph root).
This memory should contain references to other memories covering major project domains.
The referenced memories shall, in turn, shall contain references to even more specific memories, and so on.
The depth of the graph shall depend on the project complexity.
- Use topics/folders to group related memories in order to make the content structure explicit.
Folders can mirror project structure (e.g. modules like frontend/backend) or topics like debugging, architecture, etc.
- Memory references must use a mem: prefix inside backticks, e.g. `mem:frontend/core`.
The surrounding text should clearly indicate when to read the memory/which content to expect.
The text should provide more precise guidance than the memory name alone,
i.e. avoid a reference like "frontend debugging: `mem:frontend/debugging` and instead make clear which aspects of frontend debugging are covered.
- Memories themselves should not contain information about when to read them; this is the responsibility of the referring memory.
## Style
Dense agent notes, not prose docs. Prefer invariants, terse bullets.
Avoid obvious context, rationale, and examples unless they prevent likely mistakes.
Keep guidance durable and generalizable, not task-local.
## Add/update threshold
Add or update memories only with stable, non-obvious project conventions that avoid complex rediscovery in the future.
Do not add: quick-read facts; generic language/framework knowledge; one-off task notes; volatile line-level details; behavior likely to change soon.
## Maintenance Actions
- Renaming memories: References are updated automatically if handled via Serena's memory rename tool.
- Checking for stale memories (e.g. after deletion): Call `serena memories check` for a report.
+34
View File
@@ -0,0 +1,34 @@
# nix-overlay — commands
All run from repo root (`nix-overlay/`).
## Build / run
- `nix build .#<package>` — build one package (must be `git add`-ed first if new; blueprint reads git index).
- `nix run .#<package>` — run a package CLI (needs `meta.mainProgram`).
- `nix build .#default` — build the meta-package (package listing).
- `nix flake show` — inspect flake outputs (also index-limited).
- `nix flake check` — full check incl. formatting.
- `nix develop` — dev shell from blueprint.
## Format
- `nix fmt` (treefmt → nixfmt on *.nix). Same as `nix flake check`'s format gate.
## Package updates
- `nix-update <package>` — bump version + hashes (cargoHash etc.).
- `nix-update <package> --version <v>` — specific version.
- `nix-update skillsmcp --version=branch=main` — for commit-pinned pkgs; or `--commit <sha>`.
## Beads (mandatory task tracking)
- `bd prime` — session context, run before any work.
- `bd ready` / `bd show <id>` / `bd update <id> --claim` / `bd close <id>`.
- `bd remember` — persistent knowledge instead of MEMORY.md.
- `bd dolt push` — prints "No remote is configured — skipping." (expected; exit 0).
## Session completion push
```
git pull --rebase && bd dolt push && git push
git status # must show "up to date with origin"
```
## Serena
- `serena memories check` — verify memory references after edits/deletes.
+11
View File
@@ -0,0 +1,11 @@
# nix-overlay — task completion
Done when ALL of these pass/hold:
1. Build passes: `nix build .#<package>` (or `nix flake check` for cross-cutting changes). Never leave a package committed that doesn't build.
2. Formatting: `nix fmt` clean (nixfmt; `flake.lock` excluded).
3. New package is staged (`git add packages/<name>/`) before build — blueprint index requirement.
4. README.md Available Packages table updated if package added/changed visibly.
5. Commit: conventional commit format (use conventional-commit / caveman-commit skill). No work left uncommitted.
6. Beads: work claimed via `bd update <id> --claim` before, `bd close <id>` after.
7. Pushed: `git pull --rebase && bd dolt push && git push` then `git status` shows "up to date with origin". `bd dolt push` skip message is expected, not a failure. Do not stop before push succeeds.
+11
View File
@@ -0,0 +1,11 @@
# nix-overlay — tech stack
- Language: Nix. Build system: Nix flake via `numtide/blueprint` (with `flake-parts`, `systems` for multi-system).
- Formatting: `treefmt-nix` → `nixfmt` on `*.nix` (`flake.lock` excluded in `treefmt.toml`).
- Multi-input nixpkgs setup (flake.nix) — pins matter, do not "unify" them:
- `nixpkgs` = nixos-unstable (default; blueprint follows it).
- `nixpkgs-latest` = nixos-unstable — needed by packages requiring newer toolchains: rustc >= 1.95 (mcp-gateway >= 3.4.0), go >= 1.26.3 (kubernetes-mcp-server >= 0.0.66).
- `nixpkgs-torch211` = pinned rev `549bd84d6279f9852cae6225e372cc67fb91a4c1` — freetoken pins torch>=2.11,<2.12 / triton==3.6.0; nixos-unstable ships torch 2.13/triton 3.7, so freetoken builds via `inputs.nixpkgs-torch211.legacyPackages.${system}.callPackage` (see `packages/freetoken/default.nix`).
- `bun2nix` pinned to branch `staging-2.1.0` until catalog support (bun2nix#86) lands on default branch (TODO #4001).
- Package kinds in `packages/`: mostly Rust (rustPlatform.buildRustPackage), Go, Python/torch, Node/bun; each self-contained in its own dir.
- `flake.lock` managed only via `nix flake update` — never hand-edited.
+169
View File
@@ -0,0 +1,169 @@
# the name by which the project can be referenced within Serena/when chatting with the LLM.
project_name: "nix-overlay"
# list of language servers to start when using the LSP backend; choose from:
# ada al angular ansible bash
# bsl clojure cpp cpp_ccls crystal
# csharp csharp_omnisharp cue dart deno
# elixir elm erlang fortran fsharp
# gdscript gleam go groovy haskell
# haxe hlsl html java json
# julia kotlin latex lean4 lua
# luau markdown matlab msl nextflow
# nix ocaml pascal perl php
# php_phpactor php_phpantom powershell python python_basedpyright
# python_jedi python_pyrefly python_ty qml r
# rego ruby ruby_solargraph rust scala
# scss solidity svelte swift systemverilog
# terraform toml typescript typescript_vts vue
# wolfram yaml zig
# (This list may be outdated; generated with scripts/print_language_list.py;
# For the current list, see values of the LanguageServerId enum here:
# https://github.com/oraios/serena/blob/main/src/solidlsp/ls_config.py)
# For some languages, there are several alternative language servers, e.g. csharp_omnisharp, ruby_solargraph.)
# Note:
# - For C, use cpp
# - For JavaScript, use typescript
# - For Angular projects, use angular (subsumes typescript+html; requires `npm install` in the project root)
# - For Svelte projects, use svelte (subsumes typescript/javascript for .svelte projects; requires npm)
# - For Deno projects, use deno (serves the same .ts/.js files as typescript; requires the deno CLI on PATH)
# - For SCSS / Sass / plain CSS, use scss (some-sass-language-server handles all three)
# - For Free Pascal/Lazarus, use pascal
# Special requirements:
# Some language servers require additional setup/installations.
# See here for details: https://oraios.github.io/serena/01-about/020_programming-languages.html#language-servers
# When using multiple language servers, the first language server that supports a given file will be used for that file.
# The first language server is the default language and the respective language server will be used as a fallback.
# Note that when using the JetBrains backend, language servers are not used and this list is correspondingly ignored.
language_servers:
- nix
# the encoding used by text files in the project
# For a list of possible encodings, see https://docs.python.org/3.11/library/codecs.html#standard-encodings
encoding: "utf-8"
# optional shell command to run before the language backend (LSP or JetBrains) is initialised.
# the command runs in the project root directory and is only executed if the project is trusted
# (see trusted_project_path_patterns in the global configuration).
# serena waits for the command to exit: a non-zero exit code is logged as an error but does not
# abort activation. a per-project timeout (activation_command_timeout, default 180s) is the safety
# backstop for non-terminating commands; on expiry the process is killed and activation continues.
# example: activation_command: "npx nx run-many -t build"
activation_command:
# maximum time in seconds to wait for activation_command to complete before killing it (default 180s).
# must be a positive number.
activation_command_timeout: 180.0
# line ending convention to use when writing source files.
# Possible values: unset (use global setting), "lf", "crlf", or "native" (platform default)
# This does not affect Serena's own files (e.g. memories and configuration files), which always use native line endings.
line_ending:
# The language backend to use for this project.
# If not set, the global setting from serena_config.yml is used.
# Valid values: LSP, JetBrains
# Note: the backend is fixed at startup. If a project with a different backend
# is activated post-init, an error will be returned.
language_backend:
# whether to use project's .gitignore files to ignore files
ignore_all_files_in_gitignore: true
# advanced configuration option allowing to configure language server-specific options.
# Maps the language key to the options.
# The settings are considered only if the project is trusted (see global configuration to define trusted projects).
# See https://oraios.github.io/serena/02-usage/050_configuration.html#language-server-specific-settings
ls_specific_settings: {}
# list of workspace folder paths (LSP backend only).
# These folders will be used to build up Serena's symbol index.
# Paths must be within the project root and should thus be relative to the project root.
# Furthermore, the paths should not be filtered by ignore settings.
# Default setting: The entire project root folder (".") is considered.
# In (large) monorepos, this can be used to index only subfolders of the project root, e.g.
# ls_workspace_folders:
# - "./subproject1"
# - "./subproject2"
ls_workspace_folders:
- "."
# list of additional workspace folder paths for cross-package reference support.
# Paths can be absolute or relative to the project root.
# Each folder is registered as an LSP workspace folder, enabling language servers to discover
# symbols and references across package boundaries, but these folders are not indexed by Serena,
# i.e. the respective symbols will not be found using Serena's symbol search tools.
# Example:
# additional_workspace_folders:
# - ../sibling-package
# - ../shared-lib
ls_additional_workspace_folders: []
# list of additional paths to ignore in this project.
# Same syntax as gitignore, so you can use * and **.
# Important: quote patterns that start with `*`, otherwise YAML treats them as aliases.
# Example:
# ignored_paths:
# - "examples/**"
# - ".worktrees/**"
# - "**/bin/**"
# - "**/obj/**"
# Note: global ignored_paths from serena_config.yml are also applied additively.
ignored_paths: []
# whether the project is in read-only mode
# If set to true, all editing tools will be disabled and attempts to use them will result in an error
# Added on 2025-04-18
read_only: false
# list of tool names to exclude.
# This extends the existing exclusions (e.g. from the global configuration)
# Find the list of tools here: https://oraios.github.io/serena/01-about/035_tools.html
excluded_tools: []
# list of tools to include that would otherwise be disabled (particularly optional tools that are disabled by default).
# This extends the existing inclusions (e.g. from the global configuration).
# Find the list of tools here: https://oraios.github.io/serena/01-about/035_tools.html
included_optional_tools: []
# fixed set of tools to use as the base tool set (if non-empty), replacing Serena's default set of tools.
# This cannot be combined with non-empty excluded_tools or included_optional_tools.
# Find the list of tools here: https://oraios.github.io/serena/01-about/035_tools.html
fixed_tools: []
# list of mode names that are to be activated by default, overriding the setting in the global configuration.
# The full set of modes to be activated is base_modes (from global config) + default_modes + added_modes.
# If the setting is undefined/empty, the default_modes from the global configuration (serena_config.yml) apply.
# Otherwise, this overrides the setting from the global configuration (serena_config.yml).
# Therefore, you can set this to [] if you do not want the default modes defined in the global config to apply
# for this project.
# This setting can, in turn, be overridden by CLI parameters (--mode).
# See https://oraios.github.io/serena/02-usage/050_configuration.html#modes
default_modes:
# list of mode names to be activated additionally for this project, e.g. ["query-projects"]
# The full set of modes to be activated is base_modes (from global config) + default_modes + added_modes.
# See https://oraios.github.io/serena/02-usage/050_configuration.html#modes
added_modes:
# initial prompt for the project. It will always be given to the LLM upon activating the project
# (contrary to the memories, which are loaded on demand).
initial_prompt: ""
# time budget (seconds) per tool call for the retrieval of additional symbol information
# such as docstrings or parameter information.
# This overrides the corresponding setting in the global configuration; see the documentation there.
# If null or missing, use the setting from the global configuration.
symbol_info_budget:
# list of regex patterns which, when matched, mark a memory entry as read‑only.
# Extends the list from the global configuration, merging the two lists.
read_only_memory_patterns: []
# list of regex patterns for memories to completely ignore.
# Matching memories will not appear in list_memories or activate_project output
# and cannot be accessed via read_memory or write_memory.
# To access ignored memory files, use the read_file tool on the raw file path.
# Extends the list from the global configuration, merging the two lists.
# Example: ["_archive/.*", "_episodes/.*"]
ignored_memory_patterns: []
+14
View File
@@ -375,6 +375,20 @@ git add packages/my-tool README.md
bd close <id> # Mark task as complete
```
## Agent skills
### Issue tracker
Issues live in the beads database (`.beads/`, driven by the `bd` CLI), synced through `git push`. The Gitea remote is not the issue tracker. See `docs/agents/issue-tracker.md`.
### Triage labels
The five canonical triage roles keep their default names, applied as `bd` labels. See `docs/agents/triage-labels.md`.
### Domain docs
Single-context layout: `CONTEXT.md` plus `docs/adr/` at the repo root. See `docs/agents/domain.md`.
<!-- BEGIN BEADS INTEGRATION v:1 profile:minimal hash:ca08a54f -->
## Beads Issue Tracker
-69
View File
@@ -1,69 +0,0 @@
# Project Instructions for AI Agents
This file provides instructions and context for AI coding agents working on this project.
<!-- BEGIN BEADS INTEGRATION v:1 profile:minimal hash:ca08a54f -->
## Beads Issue Tracker
This project uses **bd (beads)** for issue tracking. Run `bd prime` to see full workflow context and commands.
### Quick Reference
```bash
bd ready # Find available work
bd show <id> # View issue details
bd update <id> --claim # Claim work
bd close <id> # Complete work
```
### Rules
- Use `bd` for ALL task tracking — do NOT use TodoWrite, TaskCreate, or markdown TODO lists
- Run `bd prime` for detailed command reference and session close protocol
- Use `bd remember` for persistent knowledge — do NOT use MEMORY.md files
## Session Completion
**When ending a work session**, you MUST complete ALL steps below. Work is NOT complete until `git push` succeeds.
**MANDATORY WORKFLOW:**
1. **File issues for remaining work** - Create issues for anything that needs follow-up
2. **Run quality gates** (if code changed) - Tests, linters, builds
3. **Update issue status** - Close finished work, update in-progress items
4. **PUSH TO REMOTE** - This is MANDATORY:
```bash
git pull --rebase
bd dolt push
git push
git status # MUST show "up to date with origin"
```
5. **Clean up** - Clear stashes, prune remote branches
6. **Verify** - All changes committed AND pushed
7. **Hand off** - Provide context for next session
**CRITICAL RULES:**
- Work is NOT complete until `git push` succeeds
- NEVER stop before pushing - that leaves work stranded locally
- NEVER say "ready to push when you are" - YOU must push
- If push fails, resolve and retry until it succeeds
<!-- END BEADS INTEGRATION -->
## Build & Test
_Add your build and test commands here_
```bash
# Example:
# npm install
# npm test
```
## Architecture Overview
_Add a brief overview of your project architecture_
## Conventions & Patterns
_Add your project-specific conventions here_
+70
View File
@@ -14,22 +14,29 @@ A custom Nix overlay and flake providing additional packages not found in upstre
|---------|-------------|----------|
| `awg-tool` | CLI for AmneziaWG self-hosting — generates 1.0/1.5/2.0/3.0 obfuscation parameters, exports .conf and vpn:// configs, installs servers over SSH | Networking |
| `aionui` | Free, open-source, Cowork app with AI Agents | AI Coding Agents |
| `codeaf` | Coding harness and software factory for open models: hand work off, then watch every project from one terminal | AI Coding Agents |
| `container-use` | Containerized environments for coding agents | AI Coding Agents |
| `desloppify` | Multi-language codebase health scanner and technical debt tracker for AI agents | AI Coding Agents |
| `ds4` | DeepSeek 4 Flash and PRO local inference engine for ROCm (Strix Halo) | AI Inference |
| `freebuff` | The world's strongest free coding agent | AI Coding Agents |
| `freetoken` | Local MoE-offload LLM inference runtime with OpenAI- and Anthropic-compatible APIs | AI Inference |
| `graphify` | Turn any folder of code, docs, papers, images, or videos into a queryable knowledge graph | AI Coding Agents |
| `g3` | AI coding agent that writes code and executes commands, with multi-provider LLM support, context compaction, and desktop automation | AI Coding Agents |
| `haivemind` | Multi-model AI consensus, aggregation, and fusion runner for popular AI CLIs | AI Coding Agents |
| `hipengine` | ROCm-native local LLM inference engine with torch-free runtime for AMD RDNA GPUs | AI Inference |
| `marmel` | Autonomous agentic coding assistant with Manager + specialist subagent orchestration over any OpenAI-compatible LLM backend | AI Coding Agents |
| `mcp-gateway` | Universal Model Context Protocol gateway that sits between AI client and MCP tools/servers | MCP Servers |
| `nftables-analyzer` | Analyze nftables firewall rules and evaluate traffic queries | Networking |
| `nftablesbuilder` | Web interface to manage nftables rules with drag-and-drop rule creation | Networking |
| `shardr` | Decentralized LLM repository: content-addressed model store, BitTorrent-based sync, OpenAI-compatible serving via llama-server | AI Inference |
| `skillsmcp` | MCP server that exposes Agent Skills to AI agents via the Model Context Protocol | MCP Servers |
| `kubernetes-mcp-server` | Model Context Protocol (MCP) server for Kubernetes and OpenShift | MCP Servers |
| `kyojin` | ExLlamaV3-based inference engine with speculative decoding for 100 GB-class MoE packs on one 128 GB AMD Strix Halo (gfx1151, ROCm 7) | AI Inference |
| `llama-cpp` | llama.cpp pinned to build b11439, built for Strix Halo (gfx1151) with ROCm + Vulkan backends | AI Inference |
| `loop` | Corporate messenger for your team | Communication |
| `radar` | Modern Kubernetes visibility — topology, event timeline, service traffic, resource browsing, Helm management, and GitOps support | Kubernetes |
| `omniroute` | Unified AI router with 160+ providers, auto fallback, MCP/A2A, OpenAI-compatible APIs | AI LLM Gateway |
| `open-code-review` | AI-powered code review CLI combining deterministic pipelines with an LLM agent for line-level review comments | AI Coding Agents |
| `relay-free-llm` | RESTful API to route user prompts to various AI model providers with automatic failover and intent-based routing | AI LLM Gateway |
| `stakpak` | DevOps AI agent that generates infrastructure code, debugs Kubernetes, configures CI/CD, and automates deployments | AI Agents |
| `traycer` | Open-source AI orchestration app for agentic coding | AI Coding Agents |
@@ -88,6 +95,30 @@ nix run git+https://git.millerson.name/alex/millerson-overlay.nix.git#mcp-gatewa
nix profile install git+https://git.millerson.name/alex/millerson-overlay.nix.git#mcp-gateway
```
### Kyojin JIT Toolchain
Kyojin's serving wrappers use the packaged ROCm compiler by default. Supply a
pinned SDK to compile HIP JIT kernels with another compiler without rebuilding
PyTorch or the HIP extension:
```nix
kyojin.override { jitRocmSdk = myJitSdk; }
```
The SDK must provide `bin/hipcc` and matching `amdgcn/bitcode`. Its compiler
wrapper must set `HIP_DEVICE_LIB_PATH` to that bitcode **in the compiler
subprocess only**, along with any required `ROCM_PATH` and Nix C++ toolchain
flags. Keep the compiler wrapper's real path inside the SDK prefix so upstream's
compiler provenance check recognizes it.
The serving process keeps PyTorch's ROCm device libraries. Setting TheRock's
Clang 23 bitcode globally makes the ROCm 7.2 runtime crash on a basic PyTorch
matrix multiplication. The serving wrappers also disable unsupported expandable
allocator segments. `nix build .#kyojin.tests.jit` checks compilation of five HIP
kernel modules without requiring a GPU; `packages/kyojin/check-jit.py --gpu`, run
with the package's Python environment and serving variables, additionally checks
PyTorch matrix multiplication and module loading through its existing HIP runtime.
### nftablesbuilder Runtime Notes
`nftablesbuilder` is a web interface for managing nftables. It consists of a
@@ -112,6 +143,41 @@ nftablesbuilder.eu (served with a self-signed certificate, hence the
`curlOpts = "-k"` in the derivation); the source repository is missing the
`settings` crate, which this overlay patches in.
### OpenCodeReview OpenCode Plugin (Home Manager)
The `open-code-review` package bundles its OpenCode plugin (the plugin file
plus runtime `node_modules`) as `passthru.opencode-plugin`, built from the
same source revision as the CLI. A Home Manager module symlinks it into
`~/.config/opencode/plugins/` and puts the `ocr` CLI on PATH:
```nix
inputs.millerson-nix-overlay.url = "git+https://git.millerson.name/alex/millerson-overlay.nix.git";
inputs.home-manager.url = "github:nix-community/home-manager";
```
```nix
# in your home-manager configuration
imports = [ millerson-nix-overlay.homeManagerModules.default ];
programs.open-code-review = {
enable = true;
opencode.enable = true; # symlink plugin into ~/.config/opencode
};
```
Without Home Manager, symlink manually:
```bash
plugin=$(nix build --print-out-paths \
git+https://git.millerson.name/alex/millerson-overlay.nix.git#open-code-review.passthru.opencode-plugin)
mkdir -p ~/.config/opencode/plugins
ln -sf $plugin/share/open-code-review/opencode/open-code-review.ts ~/.config/opencode/plugins/
ln -sfn $plugin/share/open-code-review/opencode/node_modules ~/.config/opencode/plugins/node_modules
```
Note: the `node_modules` symlink is shared across everything in the plugins
directory; other manually-installed plugins with conflicting npm dependencies
cannot coexist with it.
## Development
@@ -145,6 +211,7 @@ nix-overlay/
├── packages/ # Package definitions
│ ├── awg-tool/ # AmneziaWG parameter generation and SSH deployment CLI
│ ├── aionui/ # AionUi - AI Cowork desktop app
│ ├── codeaf/ # Coding harness and software factory for open models
│ ├── container-use/ # Containerized environments for coding agents
│ ├── default/ # Meta-package listing all packages
│ ├── desloppify/ # Codebase health scanner for AI agents
@@ -153,12 +220,15 @@ nix-overlay/
│ ├── freebuff/ # Free coding agent (Codebuff)
│ ├── freetoken/ # Local MoE inference runtime (NVIDIA CUDA)
│ ├── graphify/ # Knowledge graph generator for code folders
│ ├── g3/ # AI coding agent (g3 + g3-studio)
│ ├── haivemind/ # Multi-model AI consensus runner
│ ├── hipengine/ # ROCm-native LLM inference engine for AMD GPUs
│ ├── kubernetes-mcp-server/ # MCP server for Kubernetes and OpenShift
│ ├── kyojin/ # ExLlamaV3-based inference engine for Strix Halo (gfx1151)
│ ├── loop/ # Corporate messenger for your team
│ ├── mcp-gateway/ # MCP protocol gateway
│ ├── omniroute/ # Unified AI router with 160+ providers
│ ├── open-code-review/ # AI code review CLI (deterministic + LLM agent)
│ ├── radar/ # Kubernetes UI (topology, timeline, Helm, GitOps)
│ ├── relay-free-llm/ # AI model provider routing gateway
│ ├── skillsmcp/ # MCP server for Agent Skills
+55
View File
@@ -0,0 +1,55 @@
# Domain Docs
How the engineering skills should consume this repo's domain documentation when exploring the codebase.
## Before exploring, read these
- **`CONTEXT.md`** at the repo root, or
- **`CONTEXT-MAP.md`** at the repo root if it exists — it points at one `CONTEXT.md` per context. Read each one relevant to the topic.
- **`docs/adr/`** — read ADRs that touch the area you're about to work in. In multi-context repos, also check `src/<context>/docs/adr/` for context-scoped decisions.
If any of these files don't exist, **proceed silently**. Don't flag their absence; don't suggest creating them upfront. The `/domain-modeling` skill (reached via `/grill-with-docs` and `/improve-codebase-architecture`) creates them lazily when terms or decisions actually get resolved.
## File structure
Single-context repo (most repos):
```
/
├── CONTEXT.md
├── docs/adr/
│ ├── 0001-two-overlay-strategies.md
│ └── 0002-package-discovery-via-git-index.md
├── packages/
├── overlays/
└── modules/
```
This repo uses the single-context layout. There is no `CONTEXT-MAP.md` and no per-directory `CONTEXT.md` files; the whole overlay is one domain.
Multi-context repo (presence of `CONTEXT-MAP.md` at the root):
```
/
├── CONTEXT-MAP.md
├── docs/adr/ ← system-wide decisions
└── src/
├── ordering/
│ ├── CONTEXT.md
│ └── docs/adr/ ← context-specific decisions
└── billing/
├── CONTEXT.md
└── docs/adr/
```
## Use the glossary's vocabulary
When your output names a domain concept (in an issue title, a refactor proposal, a hypothesis, a test name), use the term as defined in `CONTEXT.md`. Don't drift to synonyms the glossary explicitly avoids.
If the concept you need isn't in the glossary yet, that's a signal — either you're inventing language the project doesn't use (reconsider) or there's a real gap (note it for `/domain-modeling`).
## Flag ADR conflicts
If your output contradicts an existing ADR, surface it explicitly rather than silently overriding:
> _Contradicts ADR-0007 (event-sourced orders) — but worth reopening because…_
+63
View File
@@ -0,0 +1,63 @@
# Issue tracker: bd (beads)
Issues and specs for this repo live in the beads database at `.beads/`. The source of truth is `.beads/issues.jsonl`, managed through the `bd` CLI (v1.3.0). beads state is versioned in the repo and synced with `git push`; there is no separate Dolt remote.
The forge remote (`git.millerson.name`, self-hosted Gitea) is not the issue tracker. Do not open Gitea, GitHub, or GitLab issues for work in this repo.
## Core commands
```bash
bd ready # open issues with no active blockers
bd show <id> # full issue detail
bd list # list issues
bd search "<text>" # text search
bd create "title" -d "description" -p 2 -l label1,label2
bd q "quick capture" # create and print only the id
bd update <id> --claim # claim before starting work
bd close <id> --reason "..."
bd reopen <id>
bd comment <id> "..." # conversation history
bd note <id> "..." # append a note
bd tag <id> <label> # shorthand for: bd update <id> --add-label <label>
bd label add <id> <label>
bd label remove <id> <label>
bd status # database overview
```
Issue ids look like `nix-overlay-4g1`. New work must be claimed with `bd update <id> --claim` before it starts.
## When a skill says "publish to the issue tracker"
Run `bd create`. Use one issue per ticket. Put the full body in `--description` (markdown is fine). Add labels per `triage-labels.md`. For a multi-part spec, create a parent issue and link children with `--deps`.
## When a skill says "fetch the relevant ticket"
Run `bd show <id>` and read the description plus comments (`bd show <id> --include-comments --json` when full comment bodies are needed). The user normally passes the issue id directly.
## Dependencies
`bd create --deps 'blocked-by:nix-overlay-4g1,discovered-from:nix-overlay-2a3'`
Bare ids, `depends-on:` and `blocked-by:` all make the new issue depend on the target. `blocks:` reverses the direction. `bd link`, `bd dep`, and `bd children` manage the graph after creation. `bd ready` already excludes anything with an unresolved blocker, so a ticket is unblocked when every issue that blocks it is closed.
## Wayfinding operations
Used by `/wayfinder`. The map is a parent bead; the children are its sub-issues.
- **Map**: a bead created for the effort. Its description holds the Notes / Decisions-so-far / Fog body.
- **Child ticket**: a bead linked to the map with `--deps depends-on:<map-id>`. The question goes in the description. Record the ticket type as a label (`research`, `prototype`, `grilling`, `task`).
- **Blocking**: a `blocked-by:<id>` dependency on the blocking bead.
- **Frontier**: `bd ready` output, restricted to children of the map (`bd children <map-id> --ready` or filter `bd ready` by parent). Lowest priority number, then oldest, wins.
- **Claim**: `bd update <id> --claim` before any work starts.
- **Resolve**: append the answer with `bd note <id> "..."` or `bd comment`, then `bd close <id> --reason "<answer gist>"`, then add a context pointer (gist plus issue id) to the map's Decisions-so-far with `bd note <map-id> "..."`.
## Session end
Work is not complete until pushed. The project workflow requires:
```bash
git pull --rebase
bd dolt push # prints "No remote is configured - skipping." here; expected, not a failure
git push
git status # must show up to date with origin
```
+30
View File
@@ -0,0 +1,30 @@
# Triage Labels
The skills speak in terms of five canonical triage roles. This file maps those roles to the actual label strings used in this repo's issue tracker.
| Label in mattpocock/skills | Label in our tracker | Meaning |
| -------------------------- | -------------------- | ---------------------------------------- |
| `needs-triage` | `needs-triage` | Maintainer needs to evaluate this issue |
| `needs-info` | `needs-info` | Waiting on reporter for more information |
| `ready-for-agent` | `ready-for-agent` | Fully specified, ready for an AFK agent |
| `ready-for-human` | `ready-for-human` | Requires human implementation |
| `wontfix` | `wontfix` | Will not be actioned |
When a skill mentions a role (for example "apply the AFK-ready triage label"), use the corresponding label string from this table.
Edit the right-hand column to match whatever vocabulary you actually use.
## Applying labels with bd
Labels are bd labels, not forge labels:
```bash
bd tag <issue-id> ready-for-agent
bd label add <issue-id> needs-triage
bd label remove <issue-id> needs-triage
bd label list <issue-id>
```
On creation: `bd create "title" -l ready-for-agent`.
A ticket has at most one triage role label. When a ticket moves to a new role, remove the old label and add the new one in the same step rather than stacking role labels.
Generated
+23 -6
View File
@@ -75,11 +75,11 @@
},
"nixpkgs": {
"locked": {
"lastModified": 1777954456,
"narHash": "sha256-hGdgeU2Nk87RAuZyYjyDjFL6LK7dAZN5RE9+hrDTkDU=",
"lastModified": 1789149629,
"narHash": "sha256-H6GwaZzZf+4npqv0tph94w9tZddSjFjmQrVsW0z78uk=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "549bd84d6279f9852cae6225e372cc67fb91a4c1",
"rev": "eaad089433ca2bb662274377d33df3d0e51ef28b",
"type": "github"
},
"original": {
@@ -91,11 +91,11 @@
},
"nixpkgs-latest": {
"locked": {
"lastModified": 1785967620,
"narHash": "sha256-IItrdb7Puk05RqOBWZYFC5X6Wl1sJmCfh5MWVHw5iMM=",
"lastModified": 1789149629,
"narHash": "sha256-H6GwaZzZf+4npqv0tph94w9tZddSjFjmQrVsW0z78uk=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "b7c2ada94fe99c15b0dbcf4d11fd7850b957a436",
"rev": "eaad089433ca2bb662274377d33df3d0e51ef28b",
"type": "github"
},
"original": {
@@ -105,6 +105,22 @@
"type": "github"
}
},
"nixpkgs-torch211": {
"locked": {
"lastModified": 1777954456,
"narHash": "sha256-hGdgeU2Nk87RAuZyYjyDjFL6LK7dAZN5RE9+hrDTkDU=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "549bd84d6279f9852cae6225e372cc67fb91a4c1",
"type": "github"
},
"original": {
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "549bd84d6279f9852cae6225e372cc67fb91a4c1",
"type": "github"
}
},
"root": {
"inputs": {
"blueprint": "blueprint",
@@ -112,6 +128,7 @@
"flake-parts": "flake-parts",
"nixpkgs": "nixpkgs",
"nixpkgs-latest": "nixpkgs-latest",
"nixpkgs-torch211": "nixpkgs-torch211",
"systems": "systems",
"treefmt-nix": "treefmt-nix"
}
+9
View File
@@ -6,6 +6,11 @@
# Newer nixpkgs whose toolchains are required by some packages:
# rustc >= 1.95 (mcp-gateway >= 3.4.0), go >= 1.26.3 (kubernetes-mcp-server >= 0.0.66).
nixpkgs-latest.url = "github:NixOS/nixpkgs/nixos-unstable";
# freetoken pins torch>=2.11,<2.12 and triton==3.6.0; current
# nixos-unstable only ships torch 2.13 / triton 3.7. Keep the previous
# nixpkgs revision for freetoken so its CUDA 12.9 / torch 2.11 stack is
# unchanged.
nixpkgs-torch211.url = "github:NixOS/nixpkgs/549bd84d6279f9852cae6225e372cc67fb91a4c1";
systems.url = "github:nix-systems/default";
blueprint = {
url = "github:numtide/blueprint";
@@ -52,5 +57,9 @@
nixosModules.default = {
nixpkgs.overlays = [ self.overlays.default ];
};
homeManagerModules.default = {
imports = [ ./modules/open-code-review-hm.nix ];
};
};
}
+50
View File
@@ -0,0 +1,50 @@
# Home Manager module: installs the OpenCode plugin for OpenCodeReview.
#
# Creates symlinks under ~/.config/opencode/plugins/ for the plugin file and
# its runtime node_modules, and puts the matching `ocr` CLI on PATH.
#
# Note: the node_modules symlink is shared by everything in the plugins
# directory. Plugins installed by other means that need conflicting npm
# dependencies cannot coexist with this one.
{
config,
lib,
pkgs,
...
}:
let
cfg = config.programs.open-code-review;
in
{
options.programs.open-code-review = {
enable = lib.mkEnableOption "OpenCodeReview AI code review CLI and its OpenCode plugin";
package = lib.mkOption {
type = lib.types.package;
default = pkgs.open-code-review;
defaultText = lib.literalExpression "pkgs.open-code-review";
description = "The open-code-review package to use.";
};
opencode = {
enable = lib.mkEnableOption "symlink the bundled OpenCode plugin into ~/.config/opencode";
};
};
config = lib.mkIf cfg.enable (lib.mkMerge [
{
home.packages = [ cfg.package ];
}
(lib.mkIf cfg.opencode.enable {
# The plugin resolves its imports Node-style: node_modules next to the
# plugin file, or in any parent directory (via the file's realpath).
# Linking both the file and node_modules covers either resolution.
xdg.configFile."opencode/plugins/open-code-review.ts".source =
"${cfg.package.passthru.opencode-plugin}/share/open-code-review/opencode/open-code-review.ts";
xdg.configFile."opencode/plugins/node_modules".source =
"${cfg.package.passthru.opencode-plugin}/share/open-code-review/opencode/node_modules";
})
]);
}
+4 -4
View File
@@ -15,13 +15,13 @@
}:
let
version = "2.1.50";
version = "2.2.2";
src = fetchFromGitHub {
owner = "iOfficeAI";
repo = "AionUi";
rev = "v${version}";
hash = "sha256-NsKygGMRN5pQXyKaehVW/sC2tyd4KmrYmiQrr5ZGeNY=";
hash = "sha256-HyDzlUOg0OAGNhNveG/5Ba2UbgoR4VTQsbUGUzGmKd4=";
};
# FOD 1: All dependencies (dev + prod) for the build phase.
@@ -34,7 +34,7 @@ let
];
outputHashAlgo = "sha256";
outputHashMode = "recursive";
outputHash = "sha256-EeDapBXeiU/70N92ka1dmrKUMEDN65FON8VPVPsBfro=";
outputHash = "sha256-+vLK5f1rhcXAhHz0v1LkMbcBjBLFCHVTWbdamZIjOwY=";
dontPatchShebangs = true;
dontFixup = true;
SSL_CERT_FILE = "${cacert}/etc/ssl/certs/ca-bundle.crt";
@@ -63,7 +63,7 @@ let
];
outputHashAlgo = "sha256";
outputHashMode = "recursive";
outputHash = "sha256-L2UV+OsHfoQTsc1s+tBrJZtnoiCcB2mlnsAHbplTggc=";
outputHash = "sha256-CzVH9zQsssdkCX/BpUxQw1wnJQKzLYWWXZt3sn7eBFI=";
dontPatchShebangs = true;
dontFixup = true;
SSL_CERT_FILE = "${cacert}/etc/ssl/certs/ca-bundle.crt";
+3 -3
View File
@@ -8,13 +8,13 @@
rustPlatform.buildRustPackage rec {
pname = "awg-tool";
version = "0.2.2";
version = "0.4.0";
src = fetchFromGitHub {
owner = "Vadim-Khristenko";
repo = "awg-containers-and-tools";
rev = "v${version}";
hash = "sha256-z4LG+z60uqsfkRyt7Dc8Fc5GMfpiF7G0N9PXnzTUJms=";
hash = "sha256-ggQjlHxNY3uXdLkE3CsSjsijFQScaJyCMhaXwASARSg=";
};
# awg-core builds ssh2 with vendored-openssl, which compiles libssh2
@@ -24,7 +24,7 @@ rustPlatform.buildRustPackage rec {
perl
];
cargoHash = "sha256-Nb5tmwvhzKAldHai7yxtYapjbZmai0ujBX9c6nRGZk0=";
cargoHash = "sha256-2Vh9DXn6qdUT6wiITDID09j1iqpTHkZt/mpjAlYFA60=";
# Upstream tests exercise Docker/SSH targets; unit tests are already
# covered by the upstream CI before a release is cut.
+9
View File
@@ -0,0 +1,9 @@
{
pkgs,
...
}:
pkgs.callPackage ./package.nix {
# Not a package of its own: codeaf is the only consumer, and codeaf is the one
# that knows which furrow version it pinned. See ./furrow.nix.
furrow = pkgs.callPackage ./furrow.nix { };
}
+54
View File
@@ -0,0 +1,54 @@
{
lib,
rustPlatform,
fetchFromGitHub,
}:
# furrow is the copy-on-write workspace snapper codeaf drives. codeaf ships a
# copy of it inside the go binary: the release asset from GitHub, glibc-dynamic
# and untouched by anything in this build, so the file codeaf writes out to
# ~/.codeaf/bin/furrow-<version> cannot start here — NixOS answers "Could not
# start dynamically linked executable" and names stub-ld. Building furrow here
# instead gives the same version as an ordinary Nix binary, and codeaf is told
# to use it through CODEAF_FURROW, which internal/furrow reads before it ever
# looks at the embedded copy. See ./package.nix.
#
# The version here has to be the one codeaf pinned in
# internal/furrowbin/pin.json: the decoders in codeaf were written for that
# furrow. Bump the two together.
rustPlatform.buildRustPackage rec {
pname = "furrow";
version = "0.1.0";
src = fetchFromGitHub {
owner = "Agent-Field";
repo = "furrow";
rev = "v${version}";
hash = "sha256-xknfvnBDFxDYeBE1yAjXl1Fx3VDHrNSUhXEWQO3PK6s=";
};
cargoHash = "sha256-FGtrKtWFPcT3R8nF5OQFlmIiKSuZ8aiHfj76bBvga5A=";
# Only the unit tests run here. Every cli integration test builds a fixture
# whose first step is `xattr::set(…, "user.furrow-test", …)`, and the sandbox
# /tmp is a tmpfs that answers EOPNOTSUPP for user.* xattrs, so all 54 of them
# die in setup — same reason forks_files_links_modes_and_xattrs is skipped, in
# the one lib test that touches an xattr. Upstream's CI runs the whole suite on
# a filesystem that supports them.
cargoTestFlags = [ "--lib" ];
checkFlags = [
"--skip"
"forks_files_links_modes_and_xattrs"
];
meta = with lib; {
description = "Local-first working-state snapshots for agentic development";
homepage = "https://github.com/Agent-Field/furrow";
changelog = "https://github.com/Agent-Field/furrow/releases/tag/v${version}";
license = licenses.asl20;
# Thirteen source files use std::os::unix with no windows guards, so the
# upstream release has no windows asset either.
platforms = platforms.unix;
mainProgram = "furrow";
};
}
+94
View File
@@ -0,0 +1,94 @@
{
lib,
buildGoModule,
fetchFromGitHub,
makeWrapper,
furrow,
}:
# codeaf carries a furrow inside itself: internal/furrowbin embeds whatever is
# staged in internal/furrowbin/cache and, on first use, writes it out to
# ~/.codeaf/bin/furrow-<version>. Upstream stages the GitHub release asset there,
# whose bytes are someone else's glibc-dynamic build that no Nix phase ever
# touched, so the file that lands in the state root cannot start here. Staging a
# rebuilt furrow is not an option either: upstream's fetcher re-checks the sha256
# named in internal/furrowbin/pin.json and would refuse one. So this build stages
# nothing, and hands over ./furrow.nix through CODEAF_FURROW instead, which
# internal/furrow reads before it looks at the embedded copy at all. Nothing of
# furrow's ends up in the codeaf binary; without that variable codeaf looks for
# furrow on PATH, the way a plain `go build` does.
#
# A codeaf run without this wrapper is not the same program: it has no furrow
# unless one is on PATH.
buildGoModule rec {
pname = "codeaf";
version = "0.7.1";
src = fetchFromGitHub {
owner = "Agent-Field";
repo = "CodeAF";
rev = "v${version}";
hash = "sha256-F4rRDNrTCF8/cj6g0KM41+gNdzvTWw5Vj2N0OJp+vCc=";
};
vendorHash = "sha256-eIocnhp3uGk+wG0kprRie0Csms+Deqxy3K3HuI1vJyM=";
env.CGO_ENABLED = 0;
nativeBuildInputs = [ makeWrapper ];
# The shipped binary carries the packed manual rather than the raw Markdown.
tags = [ "codeaf_packed_manual" ];
subPackages = [ "cmd/codeaf" ];
# Upstream's own suite is a CI matrix (make test / make check) with network
# and timing assumptions; it is not buildGoModule-shaped.
doCheck = false;
# `make build` runs a host-side step before compiling: packing the manual into
# what the codeaf_packed_manual tag embeds. It is built for the build machine
# even when codeaf targets another platform, hence the unset GOOS/GOARCH. The
# vendoring derivation runs preBuild too, before vendor/ exists, and this step
# needs the vendored dependencies, so it waits for it. Upstream's other step,
# staging the furrow release, is deliberately not run: see ./furrow.nix.
preBuild = ''
if [ -d vendor ]; then
env -u GOOS -u GOARCH go generate ./internal/manual
fi
'';
postInstall = ''
wrapProgram $out/bin/codeaf --set CODEAF_FURROW ${furrow}/bin/furrow
'';
ldflags = [
"-s"
"-w"
"-X github.com/Agent-Field/codeaf/internal/buildinfo.rev=${version}"
"-X github.com/Agent-Field/codeaf/internal/buildinfo.dirty=false"
];
passthru = {
inherit furrow;
category = "AI Coding Agents";
updateScript = [
"nix-update"
"--flake"
".#codeaf"
# furrow.nix is not a flake output, so nix-update never touches it: bump it
# by hand alongside the version codeaf pins in internal/furrowbin/pin.json.
];
};
meta = with lib; {
description = "Coding harness and software factory for open models: hand off work and watch every project from one terminal";
homepage = "https://github.com/Agent-Field/CodeAF";
changelog = "https://github.com/Agent-Field/CodeAF/blob/v${version}/CHANGELOG.md";
license = licenses.asl20;
# Runs the furrow built from source by ./furrow.nix, not the release asset
# upstream would have embedded.
mainProgram = "codeaf";
platforms = platforms.linux ++ platforms.darwin;
};
}
+1 -2
View File
@@ -1,2 +1 @@
{ pkgs, ... }:
pkgs.callPackage ./package.nix { }
{ pkgs, ... }: pkgs.callPackage ./package.nix { }
+3 -3
View File
@@ -9,13 +9,13 @@
stdenv.mkDerivation {
pname = "ds4";
version = "0-unstable-2026-08-05";
version = "0-unstable-2026-09-20";
src = fetchFromGitHub {
owner = "antirez";
repo = "ds4";
rev = "b0309611041655f4e45671cfd9c9886aff161406";
hash = "sha256-yBPQqX8oI9fElGiXfz72iWwIS8ZQpK4Bl9TWLZSa6JU=";
rev = "0aaea5a238fb41a35106a551e73c8409dfb751ac";
hash = "sha256-Bo/td1HwVjw6bwz3BDwTP+ZSudkVFCo2aIVK4axvmXg=";
};
nativeBuildInputs = [
+4 -4
View File
@@ -9,11 +9,11 @@
}:
let
version = "0.0.142";
version = "0.2.19";
freebuffSrc = fetchurl {
url = "https://registry.npmjs.org/freebuff/-/freebuff-${version}.tgz";
hash = "sha256-8DSNy/wJqLzp7mu2xsPBlMv69aBMIBNVva3SAaV13Tw=";
hash = "sha256-vIypYxwCuA/PKpldhwuFVNqwtm4UXZM6xInKZ5A+u9w=";
};
pkgTar = fetchurl {
@@ -48,14 +48,14 @@ let
binarySrc = fetchurl {
url = "https://github.com/CodebuffAI/codebuff-community/releases/download/freebuff-v${version}/freebuff-linux-x64.tar.gz";
hash = "sha256-SuV5djfrvRZZ59p+dUyiux+OmEMOxscuIU5/YDGWHYI=";
hash = "sha256-8EfFlhc6k0fEDws3w4kw1rIPQr5RXZHtekjxwouWW7Q=";
};
in
stdenv.mkDerivation rec {
pname = "freebuff";
version = "0.0.142";
version = "0.2.19";
src = freebuffSrc;
+6 -1
View File
@@ -1,5 +1,10 @@
{
pkgs,
inputs,
...
}:
pkgs.callPackage ./package.nix { }
# freetoken pins torch>=2.11,<2.12 and triton==3.6.0, but current
# nixos-unstable ships torch 2.13 + triton 3.7 and no older torch. Build it
# with the pinned nixpkgs-torch211 revision (CUDA 12.9 / torch-bin 2.11).
inputs.nixpkgs-torch211.legacyPackages.${pkgs.stdenv.hostPlatform.system}.callPackage ./package.nix
{ }
+2 -2
View File
@@ -81,14 +81,14 @@ let
in
py.buildPythonApplication (finalAttrs: {
pname = "freetoken";
version = "0.1.2";
version = "0.1.3";
pyproject = true;
src = fetchFromGitHub {
owner = "FlashML-org";
repo = "FreeToken";
tag = "v${finalAttrs.version}";
hash = "sha256-0MhuubuTjNvtQZxisC2cg1dJeR+A6wZ901H5FRv+l+c=";
hash = "sha256-59itjnwDr4P7I/ZLIbkNw9/8CCPvTP7yNWl9ogBnZ3o=";
};
# setup.py imports torch.utils.cpp_extension at build time and compiles two
+5
View File
@@ -0,0 +1,5 @@
{
pkgs,
...
}:
pkgs.callPackage ./package.nix { }
+95
View File
@@ -0,0 +1,95 @@
{
lib,
stdenv,
rustPlatform,
fetchFromGitHub,
pkg-config,
openssl,
cmake,
libx11,
libxtst,
llvmPackages,
}:
rustPlatform.buildRustPackage rec {
pname = "g3";
# Upstream has no git tags or releases; pin main and let nix-update
# track the branch. Version shape matches nix-update --version=branch=main
# for a tagless repository (package version is 0.1.0 upstream).
version = "0-unstable-2026-09-06";
src = fetchFromGitHub {
owner = "dhanji";
repo = "g3";
rev = "9793144520d290a9ea621a06cf7d8322e6fa4a35";
hash = "sha256-s4QlOah7ffoFjiTw2nO/SbCbvIRxr4HB/3pOpQpGWRM=";
};
# Cargo.lock has a git dependency (tree-sitter-haskell); cargoHash /
# fetchCargoVendor covers registry + git sources.
cargoHash = "sha256-6dvN4//NNuo9s5QzTcrxYiNkxP0Ivysg6f1F9soFrL4=";
nativeBuildInputs = [
pkg-config
cmake
# llama-cpp-sys-2 runs bindgen, which needs libclang.
llvmPackages.libclang
];
buildInputs = [
openssl
libx11
libxtst
];
# bindgen (via llama-cpp-sys-2) needs libclang and the C library headers.
env = {
LIBCLANG_PATH = "${llvmPackages.libclang.lib}/lib";
BINDGEN_EXTRA_CLANG_ARGS = "-isystem ${lib.getDev stdenv.cc.libc}/include";
};
# Root package only builds/installs its own bins; studio is a sibling
# workspace member. Match upstream install.sh: ship g3 and studio
# (renamed to g3-studio).
cargoBuildFlags = [
"-p"
"g3"
"-p"
"studio"
];
cargoInstallFlags = [
"-p"
"g3"
"-p"
"studio"
];
# Provider and computer-control tests need network, LLM credentials, and a
# display; not runnable in the Nix sandbox.
doCheck = false;
# Upstream install.sh names the companion workspace manager g3-studio.
postInstall = ''
mv "$out/bin/studio" "$out/bin/g3-studio"
'';
passthru = {
category = "AI Coding Agents";
updateScript = [
"nix-update"
"--flake"
".#g3"
"--version=branch=main"
];
};
meta = with lib; {
description = "AI coding agent that writes code and executes commands, with multi-provider LLM support, context compaction, and desktop automation";
homepage = "https://github.com/dhanji/g3";
# Cargo.toml declares MIT; the repository ships no LICENSE file.
license = licenses.mit;
sourceProvenance = with sourceTypes; [ fromSource ];
mainProgram = "g3";
platforms = platforms.unix;
};
}
+11 -5
View File
@@ -6,14 +6,18 @@
python3Packages.buildPythonApplication rec {
pname = "graphify";
version = "0.9.35";
version = "0.9.77";
pyproject = true;
# Do not bump to the v1.0.0 tag: it is a stale branch 2126 commits behind
# v0.9.77 (tagged 2026-04-05, pyproject still says graphifyy 0.1.10) and was
# never published to PyPI, where 0.9.77 is the latest release. nix-update
# picks v1.0.0 as the highest tag, so check PyPI before taking its result.
src = fetchFromGitHub {
owner = "safishamsi";
owner = "Graphify-Labs";
repo = "graphify";
rev = "v${version}";
hash = "sha256-HESowqiR5c6WaeiNj1WDSYBzrrcpZQwqaKwQxroePD8=";
hash = "sha256-CvJ6GoV1nSzFGfLQbzKSHDUNOuOPQZaYOf/idcSHkPw=";
};
build-system = with python3Packages; [
@@ -24,7 +28,7 @@ python3Packages.buildPythonApplication rec {
# Missing grammars will be downloaded by tree-sitter at runtime on demand.
dependencies = with python3Packages; [
networkx
datasketch
numpy
rapidfuzz
tree-sitter
tree-sitter-python
@@ -40,6 +44,9 @@ python3Packages.buildPythonApplication rec {
# either `>` (versioned) or `"` (bare) via alternation. This also avoids
# prefix collisions (e.g. tree-sitter-c vs tree-sitter-c-sharp).
postPatch = ''
# relax the build-backend pin: nixpkgs' setuptools is older than 83, but
# the PEP 639 license metadata graphify relies on needs only >=77.
sed -i 's/setuptools>=83\.[0-9.]*/setuptools/' pyproject.toml
sed -i \
-e '/tree-sitter-typescript>\|tree-sitter-typescript"/d' \
-e '/tree-sitter-go>\|tree-sitter-go"/d' \
@@ -74,7 +81,6 @@ python3Packages.buildPythonApplication rec {
"nix-update"
"--flake"
".#graphify"
"--version=branch=main"
];
};
+1 -1
View File
@@ -6,7 +6,7 @@
python3Packages.buildPythonApplication rec {
pname = "haivemind";
version = "0.1.0";
version = "0-unstable-2026-07-01";
pyproject = true;
src = fetchFromGitHub {
+30 -2
View File
@@ -1,2 +1,30 @@
{ pkgs, ... }:
pkgs.callPackage ./package.nix { }
{
pkgs,
...
}:
# hipEngine >= 0.5.0 requires llguidance >= 1.8,<2; nixpkgs only provides
# 1.7.x. Override nixpkgs' llguidance to 1.8.0 and hand the resulting
# interpreter/package set to the package.
let
python = pkgs.python3.override {
packageOverrides = self: super: {
llguidance = super.llguidance.overridePythonAttrs (old: rec {
version = "1.8.0";
src = pkgs.fetchFromGitHub {
owner = "guidance-ai";
repo = "llguidance";
tag = "v${version}";
hash = "sha256-/rHTefKTq5ch38NqbcLYTXBJwkW+WzG5OFvignDIie4=";
};
cargoDeps = pkgs.rustPlatform.fetchCargoVendor {
pname = "llguidance";
inherit src version;
hash = "sha256-aa9R+6xgFVGAD3snHbkPRF5jMYwC3DFNjXcUtaOzDbU=";
};
});
};
};
in
python.pkgs.callPackage ./package.nix {
python3Packages = python.pkgs;
}
+3 -2
View File
@@ -6,14 +6,14 @@
python3Packages.buildPythonApplication rec {
pname = "hipengine";
version = "0.3.0";
version = "0.6.1";
pyproject = true;
src = fetchFromGitHub {
owner = "shisa-ai";
repo = "hipEngine";
rev = "v${version}";
hash = "sha256-lnYsXTxke5LLMbHOt6i2FM8IrnHCimC/va1fJL5G4PQ=";
hash = "sha256-7FQZuExTTqcMKZkCRzLC5nYLpGytswhEsBTUliQqoTI=";
};
build-system = with python3Packages; [
@@ -23,6 +23,7 @@ python3Packages.buildPythonApplication rec {
dependencies = with python3Packages; [
fastapi
jinja2
llguidance
numpy
safetensors
tokenizers
+3 -3
View File
@@ -6,16 +6,16 @@
buildGoModule rec {
pname = "kubernetes-mcp-server";
version = "0.0.66";
version = "0.0.67";
src = fetchFromGitHub {
owner = "containers";
repo = "kubernetes-mcp-server";
rev = "v${version}";
hash = "sha256-vnJxSCfnpvOZJXQpKrCAW4QKt5R2PJDYQevA7O1uXZg=";
hash = "sha256-rejF9JsszB3ZirZhoK1VDbCH/P0Xzmh4TJw5j+okj+M=";
};
vendorHash = "sha256-gbqoT4X+wVOEktHm7jaAH9vHrUBrYgR8OjyFz1ljP6k=";
vendorHash = "sha256-TSB2jAWh2PlDHpvzA/rrBbjaR8sgyjivDO0vsbcuvgg=";
env.CGO_ENABLED = 0;
+46
View File
@@ -0,0 +1,46 @@
"""Compile Kyojin's JIT kernels; --gpu also loads them through torch's HIP runtime."""
import ctypes
import importlib
import os
from pathlib import Path
import sys
from exllamav3.util import hip_compiler
from exllamav3.util.hip_lib import load_hip_runtime
sdk = Path(os.environ["EXL3_ROCM_SDK"])
assert Path(hip_compiler.hipcc()) == sdk / "bin/hipcc"
assert Path(os.environ["HIP_DEVICE_LIB_PATH"]).is_dir()
assert (sdk / "amdgcn/bitcode").is_dir()
if os.environ.get("KYOJIN_REQUIRE_SDK") == "1":
assert hip_compiler.warning() is None, hip_compiler.warning()
print(hip_compiler.describe(), flush=True)
lib = None
if "--gpu" in sys.argv:
import torch
# Also exercise the runtime bitcode path: merely loading a HIP module
# does not catch incompatible device libraries in CLR/COMGR.
x = torch.ones((32, 32), device="cuda", dtype=torch.float32)
assert torch.equal(x @ x, torch.full_like(x, 32))
torch.cuda.synchronize()
lib = load_hip_runtime()
lib.hipModuleLoad.argtypes = [ctypes.POINTER(ctypes.c_void_p), ctypes.c_char_p]
lib.hipModuleUnload.argtypes = [ctypes.c_void_p]
for module, function, args in [
("gr_mix_hip", "compile_hsaco", ()),
("exllamav3.modules.attention_fn.qsa_prefill_hip", "compile_hsaco", ()),
("exllamav3.modules.ple_fn.ple_hip", "compile_hsaco", ()),
("exllamav3.vendor.fla.hip.gdn_fused_h_hip", "_compile", ("", "gfx1151")),
("exllamav3.vendor.fla.hip.kda_fused_h_hip", "_compile", ("", "gfx1151")),
]:
path = Path(getattr(importlib.import_module(module), function)(*args))
# HIP accepts ELF, offload bundles, and compressed offload bundles (CCOB).
assert path.read_bytes().startswith((b"\x7fELF", b"__CLANG_OFFLOAD_BUNDLE__", b"CCOB")), path
if lib is not None:
handle = ctypes.c_void_p()
assert lib.hipModuleLoad(ctypes.byref(handle), os.fsencode(path)) == 0, path
assert lib.hipModuleUnload(handle) == 0, path
print(f"OK: {module}", flush=True)
+13
View File
@@ -0,0 +1,13 @@
{
pkgs,
inputs,
jitRocmSdk ? null,
...
}:
# The HIP extension has to be compiled against a ROCm build of PyTorch, and the
# only ROCm torch in this flake with a cached binary is the one from the pinned
# nixpkgs-torch211 input (2.11 + ROCm 7.2, python 3.13). Current nixos-unstable
# ships torch 2.13, whose ROCm build fails to configure in nixpkgs and is not
# on cache.nixos.org.
inputs.nixpkgs-torch211.legacyPackages.${pkgs.stdenv.hostPlatform.system}.callPackage ./package.nix
{ inherit jitRocmSdk; }
+251
View File
@@ -0,0 +1,251 @@
{
lib,
stdenv,
pkgs,
python3,
fetchFromGitHub,
makeWrapper,
rocmPackages,
# Override only the serving toolchain; torch and the extension keep their ROCm.
jitRocmSdk ? null,
}:
let
py = python3.pkgs;
# Kyojin is the Yamz fork of ExLlamaV3: a Python package plus a C++ extension
# that torch's cpp_extension cross-compiles to HIP code objects. Upstream
# only supports AMD Strix Halo, so the kernels are built for gfx1151 alone.
rocmArch = "gfx1151";
version = "1.3";
src = fetchFromGitHub {
owner = "Yamz-Labs";
repo = "kyojin";
rev = "v${version}";
hash = "sha256-/DPoqW/iaLXRAH8XF5RdE+K5YS4jZT6Sic6QeCDQMlU=";
};
# setup.py passes EXL3_ROCM_DEV_INCLUDE as -I to every translation unit. The
# AMD wheels ship one devel tree holding hipsparse/ and thrust/; nixpkgs
# splits them per package, so join the include dirs. torch's public HIP
# headers also pull hipsolver/, and it no longer vendors pybind11.
rocmDevInclude = pkgs.symlinkJoin {
name = "kyojin-rocm-dev-include";
paths = map lib.getDev (
[ py.pybind11 ]
++ [
rocmPackages.clr
rocmPackages.hipblas
rocmPackages.hipblaslt
rocmPackages.hipcub
rocmPackages.hipfft
rocmPackages.hiprand
rocmPackages.hipsparse
rocmPackages.hipsolver
rocmPackages.rocblas
rocmPackages.rocprim
rocmPackages.rocrand
rocmPackages.rocsolver
rocmPackages.rocsparse
rocmPackages.rocthrust
]
);
};
# torch's HIP path in cpp_extension expects one ROCM_HOME holding bin/hipcc,
# the headers and the amdgcn bitcode; nixpkgs ships them separately.
rocmToolkit = pkgs.symlinkJoin {
name = "kyojin-rocm-toolkit";
paths = [
rocmPackages."rocm-core"
rocmPackages."rocm-runtime"
rocmPackages."rocm-device-libs"
rocmPackages."rocm-comgr"
rocmPackages.clr
(lib.getBin rocmPackages.hipcc)
rocmPackages.rocblas
rocmPackages.hipblas
rocmPackages.hipblas-common
rocmPackages.hipblaslt
rocmPackages.hipsparse
rocmPackages.hipsolver
rocmPackages.hiprand
rocmPackages.rocrand
rocmPackages.hipfft
rocmPackages.rocsparse
rocmPackages.rocsolver
rocmPackages.rocthrust
rocmPackages.rocprim
rocmPackages.hipcub
];
# The setup hooks of the joined packages would rewrite build flags; the
# compiler only needs the files.
postBuild = ''
rm -rf $out/nix-support
'';
};
# The library: exllamav3 plus the compiled exllamav3_ext module.
library = py.buildPythonPackage {
inherit src version;
pname = "kyojin";
format = "pyproject";
build-system = with py; [
setuptools
wheel
];
nativeBuildInputs = [
py.ninja
rocmPackages."rocm-runtime"
];
buildInputs = [ (lib.getBin rocmPackages.hipcc) ];
propagatedBuildInputs = with py; [
aiohttp
huggingface-hub
jinja2
llguidance
marisa-trie
numpy
pillow
pydantic
pyyaml
rich
safetensors
tokenizers
torchWithRocm
typing-extensions
];
env = {
PYTORCH_ROCM_ARCH = rocmArch;
ROCM_PATH = "${rocmToolkit}";
ROCM_HOME = "${rocmToolkit}";
HIP_PATH = "${rocmToolkit}";
HIPCC = "${rocmToolkit}/bin/hipcc";
HIP_DEVICE_LIB_PATH = "${rocmPackages."rocm-device-libs"}/amdgcn/bitcode";
# Upstream build scripts look these up to find the ROCm devel tree.
EXL3_ROCM_SDK = "${rocmToolkit}";
EXL3_ROCM_DEV_INCLUDE = "${rocmDevInclude}/include";
# Default defines of upstream build.sh (tools/strix_halo/rebuild.sh).
EXL3_HIP_DEFINES = "EXL3_HIP_STG_PAD";
};
# setup.py pulls the extension source list and the arch helper with
# `from exllamav3...import ...`, which runs the package __init__ and
# therefore exllamav3/ext.py. That module JIT-compiles the extension when no
# precompiled exllamav3_ext is importable, i.e. during every wheel build
# (and it wants a writable $HOME for it). Register an empty `exllamav3`
# package first so only the two leaf modules are imported, and load
# build_config without the package wrapper.
postPatch = ''
sed -i '1i import sys as _sys, types as _types; _exl3_pkg = _types.ModuleType("exllamav3"); _exl3_pkg.__path__ = ["exllamav3"]; _sys.modules.setdefault("exllamav3", _exl3_pkg)' setup.py
sed -i 's|^from exllamav3\.exllamav3_ext\.build_config import get_sources as _get_sources$|import sys as _exl3_sys; _exl3_sys.path.insert(0, "exllamav3/exllamav3_ext"); from build_config import get_sources as _get_sources; _exl3_sys.path.pop(0)|' setup.py
grep -q 'from build_config import' setup.py
# Upstream serves these from the checkout (pip install -e .); the wheel only
# packages what pyproject lists, and three things are read out of the
# installed package at run time: the .hip sources the JIT kernels compile,
# the qsa_proof marker gating the QSA prefill kernel, and the dense-GEMM
# tuning seed (without it every start re-tunes for ~7 minutes).
sed -i 's|^ "exllamav3_ext/\*\*/\*",$|&\n "**/*.hip",\n "**/*.ok",\n "model/dense_gemm_tune_seed.txt",|' pyproject.toml
grep -q '"\*\*/\*.hip"' pyproject.toml
'';
# tests/ needs a real gfx1151 GPU and the published model packs.
doCheck = false;
meta = with lib; {
description = "Inference engine for 100 GB-class EXL3 MoE models on AMD Strix Halo (gfx1151, ROCm 7)";
homepage = "https://github.com/Yamz-Labs/kyojin";
changelog = "https://github.com/Yamz-Labs/kyojin/releases";
license = licenses.mit;
sourceProvenance = with sourceTypes; [ fromSource ];
# HIP code objects are gfx1151-only and ROCm is Linux-only.
platforms = platforms.linux;
};
};
python = py.python.withPackages (_: [ library ]);
jitSdk = if jitRocmSdk == null then rocmToolkit else jitRocmSdk;
in
stdenv.mkDerivation {
inherit src version;
pname = "kyojin";
# Only the wrappers are installed here: the serve scripts are plain scripts,
# they import their siblings by path, and the module itself is in `library`.
#
# Upstream `tools/strix_halo/env.sh` is sourced before serving, and on a
# distro box that brings a system `cc` (the AMD Triton backend compiles a
# CPython glue module at runtime, and again per kernel launcher) plus a hipcc
# for the JIT HIP kernels (qsa prefill, gdn, kda, ple). Nix gives the wrapper
# neither, so export them here instead: Triton takes the compiler from $CC,
# exllamav3 finds hipcc under $EXL3_ROCM_SDK, and hipclang only finds the
# amdgcn bitcode through $HIP_DEVICE_LIB_PATH (hipcc's own DEVICE_LIB_PATH is
# not enough for a --genco call). The ROCm paths stay out of LD_LIBRARY_PATH
# (upstream Trap 1/5: a second libhsa segfaults torch), and PYTHONPATH gets
# `gr/`: upstream env.sh puts the repo root there so `import gr_mix_hip` (the
# hand-written gated-residual WMMA kernel the server asks for with
# EXL3_GR_HIP=1) resolves, and it is not part of the wheel either.
dontConfigure = true;
dontBuild = true;
nativeBuildInputs = [ makeWrapper ];
installPhase = ''
runHook preInstall
mkdir -p $out/bin
for model in glm mimo qwen; do
makeWrapper ${python}/bin/python $out/bin/kyojin-serve-$model \
--set PYTORCH_ROCM_ARCH ${rocmArch} \
--set CC ${stdenv.cc}/bin/cc \
--set EXL3_ROCM_SDK ${jitSdk} \
--set HIP_DEVICE_LIB_PATH ${rocmPackages."rocm-device-libs"}/amdgcn/bitcode \
--set EXL3_EXPANDABLE_SEGMENTS 0 \
--prefix PATH : ${lib.makeBinPath [ stdenv.cc ]} \
--prefix PYTHONPATH : ${src}/gr \
--add-flags "${src}/tools/$model/serve.py"
done
runHook postInstall
'';
passthru = {
inherit python rocmArch;
pythonPackage = library;
jitRocmSdk = jitSdk;
tests.jit =
pkgs.runCommand "kyojin-jit-check"
{
EXL3_ROCM_SDK = jitSdk;
# CLR/COMGR also reads this variable. Newer bitcode crashes torch
# matmul; a custom hipcc must select its own bitcode in its subprocess.
HIP_DEVICE_LIB_PATH = "${rocmPackages."rocm-device-libs"}/amdgcn/bitcode";
EXL3_EXPANDABLE_SEGMENTS = "0";
PYTHONPATH = "${src}/gr";
KYOJIN_REQUIRE_SDK = lib.boolToString (jitRocmSdk != null);
}
''
export HOME="$TMPDIR"
${python}/bin/python ${./check-jit.py}
touch "$out"
'';
category = "AI Inference";
updateScript = [
"nix-update"
"--flake"
".#kyojin"
];
};
meta = library.meta // {
mainProgram = "kyojin-serve-qwen";
};
}
+17
View File
@@ -0,0 +1,17 @@
{
pkgs,
inputs,
...
}:
# llama.cpp b9645 is newer than the flake's pinned nixpkgs (llama-cpp b8983,
# pre-tools/ui) and needs its UI/ROCm layout, so build against the
# nixpkgs-latest input — same pattern as mcp-gateway/kubernetes-mcp-server.
let
latestPkgs = inputs.nixpkgs-latest.legacyPackages.${pkgs.stdenv.hostPlatform.system};
in
latestPkgs.callPackage ./package.nix {
# Strix Halo: build the ROCm dependencies (clr, rocBLAS, hipBLAS) for gfx1151
# only instead of every supported arch. clr's own build is arch-independent,
# so its store path is unchanged and stays substitutable.
rocmPackages = latestPkgs.rocmPackages.gfx1151;
}
+117
View File
@@ -0,0 +1,117 @@
{
lib,
# Build skeleton: nixpkgs' own llama-cpp derivation (b-tag layout, cmake/npm
# plumbing), retargeted at the pinned tag below.
llama-cpp,
fetchFromGitHub,
rocmPackages,
# nixpkgs-latest's nodejs/npm hooks: referenced only to strip them from
# nativeBuildInputs (the npm/web UI build is disabled below).
nodejs_latest,
npmHooks,
# Strix Halo (Radeon 8060S). clr/rocBLAS/hipBLAS come prefixed for this arch
# by the scoped rocmPackages in ./default.nix.
rocmGpuTargets ? [ "gfx1151" ],
}:
let
# Upstream release tag. Bump with:
# nix flake prefetch github:ggml-org/llama.cpp/b<NNNN>
# then update buildNumber and the src hash.
buildNumber = "11439";
# HIP flags from the llm-engine.nix bring-up config. The -I paths for
# hipBLASLt/rocWMMA are dropped because this tag's HIP backend links
# hipBLAS/rocBLAS only; GGML_HIPBLASLT and GGML_CUDA_ENABLE_UNIFIED_MEMORY
# are also unused by b9645 (cmake warns and ignores them).
hipFlags = lib.concatStringsSep " " [
"-mllvm"
"-amdgpu-early-inline-all=true"
"-mllvm"
"-amdgpu-function-calls=false"
"-mprefer-vector-width=512"
"-famd-opt"
"-mllvm"
"-inline-threshold=600"
"-mllvm"
"-unroll-threshold=150"
];
in
(llama-cpp.override {
inherit rocmPackages rocmGpuTargets;
rocmSupport = true;
vulkanSupport = true;
cudaSupport = false;
}).overrideAttrs
(old: {
version = buildNumber;
src = fetchFromGitHub {
owner = "ggml-org";
repo = "llama.cpp";
tag = "b${buildNumber}";
# Tarball hash (this tag has no submodules).
hash = "sha256-9KUkThRm+kvYOguP08JOPtjQjtDsDqgh1e50NdR0V5I=";
};
# The embedded web UI is disabled via cmakeFlags, so none of the npm
# machinery is needed: no dependency tree, and npmConfigHook hard-fails
# when npmDeps is null, so it (and nodejs) must come off the inputs.
npmDeps = null;
npmRoot = null;
npmDepsHash = null;
nativeBuildInputs = builtins.filter (x: x != nodejs_latest && x != npmHooks.npmConfigHook) (
old.nativeBuildInputs or [ ]
);
# The release tarball has no .git; upstream wants the build id in COMMIT.
postPatch = ''
echo ${buildNumber} > COMMIT
'';
# Replaces the base derivation's npm build step. CMAKE_HIP_FLAGS holds
# several space-separated flags, so it must be appended as an array element:
# plain cmakeFlags scalars are word-split by the cmake hook.
preConfigure = ''
prependToVar cmakeFlags "-DLLAMA_BUILD_COMMIT:STRING=$(cat COMMIT)"
cmakeFlagsArray+=("-DCMAKE_HIP_FLAGS=${hipFlags}")
'';
cmakeFlags =
builtins.filter (f: !(builtins.isString f && builtins.match ".*LLAMA_BUILD_NUMBER.*" f != null)) (
old.cmakeFlags or [ ]
)
++ [
"-DCMAKE_C_FLAGS=-march=znver5"
"-DCMAKE_CXX_FLAGS=-march=znver5"
"-DGGML_CPU=ON"
"-DGGML_AVX=ON"
"-DGGML_AVX_VNNI=ON"
"-DGGML_AVX2=ON"
"-DGGML_BMI2=ON"
"-DGGML_AVX512=ON"
"-DGGML_AVX512_VNNI=ON"
"-DGGML_AVX512_VBMI=ON"
"-DGGML_AVX512_BF16=ON"
"-DGGML_FMA=ON"
"-DGGML_F16C=ON"
"-DHIP_PLATFORM=amd"
"-DGGML_CUDA_FORCE_CUBLAS=OFF"
"-DGGML_HIPBLASLT=ON"
"-DGGML_HIP_NO_VMM=ON"
"-DGGML_HIP_GRAPHS=ON"
"-DGGML_CUDA_ENABLE_UNIFIED_MEMORY=ON"
"-DGGML_HIP_ROCWMMA_FATTN=OFF"
"-DGGML_HIP_MMQ_MFMA=ON"
"-DGGML_CUDA_FA_ALL_QUANTS=ON"
"-DCMAKE_BUILD_TYPE=Release"
"-DLLAMA_BUILD_NUMBER:STRING=${buildNumber}"
(lib.cmakeBool "LLAMA_BUILD_UI" false)
(lib.cmakeBool "LLAMA_USE_PREBUILT_UI" false)
];
# The base's update script tracks nixpkgs' llama-cpp attr, not this pin.
passthru = builtins.removeAttrs (old.passthru or { }) [ "updateScript" ] // {
category = "AI Inference";
};
})
+1 -2
View File
@@ -1,2 +1 @@
{ pkgs, ... }:
pkgs.callPackage ./package.nix { }
{ pkgs, ... }: pkgs.callPackage ./package.nix { }
+5
View File
@@ -0,0 +1,5 @@
{
pkgs,
...
}:
pkgs.callPackage ./package.nix { }
+93
View File
@@ -0,0 +1,93 @@
{
lib,
rustPlatform,
fetchFromGitHub,
cacert,
}:
rustPlatform.buildRustPackage rec {
pname = "marmel";
# Upstream publishes no git tags, so this is pinned to the 1.0.0 release
# commit ("1.0.0 (#6)").
version = "1.0.0";
src = fetchFromGitHub {
owner = "Na1w";
repo = "marmel";
rev = "d6627d7cf3bf509d1e6db0d9d78736116e92e82a";
hash = "sha256-UlrSp/n3og0GAQXzISsB24OfK3qOUPE7jYOkEbZ2neI=";
};
cargoHash = "sha256-etqW3xcxkiNfkiPxl/Emt5pQCkNnoIhHFkX0Zqfs4rc=";
nativeCheckInputs = [ cacert ];
# The test suite builds `reqwest::Client`s, and rustls rejects construction
# outright when no system trust store is found ("No CA certificates were
# loaded from the system"). The sandbox has no /etc/ssl, so point the tests
# at nixpkgs' bundle. Build-time only; the installed binary still uses the
# host's trust store at runtime.
preCheck = ''
export SSL_CERT_FILE=${cacert}/etc/ssl/certs/ca-bundle.crt
'';
# Serialise the test harness. The lib suite shares process-global worker
# registries and steer/abort buses (src/orchestrator/workers.rs,
# src/orchestrator/bus.rs, src/orchestrator/preemption.rs), so the
# manager-loop tests fail nondeterministically when the harness runs them on
# parallel threads: rebuilding one unchanged derivation yielded 3 failures,
# then 1 failure, then 0 with serial threads. Drop this flag once upstream
# makes that state per-instance.
#
# The two sandbox-exec tests are skipped. They re-exec `sh` through
# `marmel --internal-sandbox-exec`, and apply_landlock_linux() allow-lists
# FHS paths only (/usr, /bin, /lib, /opt, /etc, /var) plus /tmp. Landlock
# matches inodes rather than symlinked views, and every binary on NixOS
# resolves into the store (`/bin/sh` is
# /nix/store/<hash>-bash-interactive-5.3p9/bin/bash), so the exec is denied:
# "Failed to exec shell in sandbox: Permission denied (os error 13)". Checked
# against this build on a NixOS host, where the same command succeeds once
# the workspace root is `/` and therefore covers /nix/store. Inside the build
# sandbox the tests are doubly impossible: /usr, /lib, /run and /var do not
# exist, so the `if let Ok(fd)` guards silently drop those rules, and
# /etc/resolv.conf is absent because the sandbox has no network. 342 of 344
# tests still run. Upstream main still carries the FHS-only list; drop these
# skips if that ever gains /nix/store.
cargoTestFlags = [
"--"
"--test-threads=1"
"--skip"
"harness::sandbox::tests::test_internal_sandbox_exec_dev_null_and_dns"
"--skip"
"harness::sandbox::tests::test_internal_sandbox_cross_directory_rename"
];
# Role prompts are embedded with `include_str!`, so the binary needs no
# runtime data files. The annotated example configs are the de-facto
# first-run documentation, since a backend URL and model are mandatory.
postInstall = ''
install -Dm644 marmel.toml.example $out/share/doc/${pname}/examples/marmel.toml.example
install -Dm644 marmel.toml.cloud $out/share/doc/${pname}/examples/marmel.toml.cloud
'';
passthru = {
category = "AI Coding Agents";
updateScript = [
"nix-update"
"--flake"
".#marmel"
"--version=branch=main"
];
};
meta = {
description = "Autonomous agentic coding assistant with Manager + specialist subagent orchestration over any OpenAI-compatible LLM backend";
homepage = "https://github.com/Na1w/marmel";
# Upstream README states MIT, but the repository ships no LICENSE file and
# Cargo.toml has no license field.
license = lib.licenses.mit;
sourceProvenance = with lib.sourceTypes; [ fromSource ];
mainProgram = "marmel";
platforms = lib.platforms.unix;
};
}
+17 -17
View File
@@ -8,16 +8,16 @@
rustPlatform.buildRustPackage rec {
pname = "mcp-gateway";
version = "3.4.0";
version = "3.5.1";
src = fetchFromGitHub {
owner = "MikkoParkkola";
repo = "mcp-gateway";
rev = "v${version}";
hash = "sha256-shn2cv463SnegamsMu6NmfylnNaFzGJLoL2H7QhETY8=";
hash = "sha256-fcH2einyG9bNNLKZPomAlfGonNw0rw+TuwlYw38531E=";
};
cargoHash = "sha256-XuOYuYapb2l7RHQIgLDfcDPtSdMDpEgti8Ud5ssuGC8=";
cargoHash = "sha256-3QI7s5IpxbW9nvnk3X3xuUopNQJZftANN5BtbQNhKrY=";
nativeBuildInputs = [ pkg-config ];
@@ -28,22 +28,22 @@ rustPlatform.buildRustPackage rec {
doCheck = false;
postInstall = ''
mkdir -p $out/lib/systemd/user
cat > $out/lib/systemd/user/mcp-gateway.service << EOF
[Unit]
Description=MCP Gateway
After=network-online.target
Wants=network-online.target
mkdir -p $out/lib/systemd/user
cat > $out/lib/systemd/user/mcp-gateway.service << EOF
[Unit]
Description=MCP Gateway
After=network-online.target
Wants=network-online.target
[Service]
Type=simple
ExecStart=$out/bin/mcp-gateway --config %h/.config/mcp-gateway/gateway.yaml serve
Restart=on-failure
RestartSec=5
[Service]
Type=simple
ExecStart=$out/bin/mcp-gateway --config %h/.config/mcp-gateway/gateway.yaml serve
Restart=on-failure
RestartSec=5
[Install]
WantedBy=default.target
EOF
[Install]
WantedBy=default.target
EOF
'';
passthru.category = "MCP Servers";
+8 -4
View File
@@ -8,10 +8,10 @@
}:
let
version = "3.8.49";
version = "3.8.50";
npmTarball = fetchurl {
url = "https://registry.npmjs.org/omniroute/-/omniroute-${version}.tgz";
hash = "sha256-fcGsAxOdv1ZSwt24eHJu97lyRATKBw8rYeFvGTRhxYs=";
hash = "sha256-c4xYrx+q6MV+tkOpOdEZH41+CD2Sle9haH0r/wSHjCk=";
};
in
@@ -23,12 +23,16 @@ buildNpmPackage (finalAttrs: {
owner = "diegosouzapw";
repo = "OmniRoute";
rev = "v${finalAttrs.version}";
hash = "sha256-nRLziV4NWPoa0ev57DV7jmAvLpL/1MP1EMZO2/drrTU=";
hash = "sha256-+2FMc9wrvPtQS3+mGsBVvKrd5RprYe/r/GJvjAVMBpc=";
};
nodejs = nodejs_22;
npmDepsHash = "sha256-R0u93MLUUWC8xFgq4S0Aj/7wg4pygTKwxP/eWkWMgCw=";
# Upstream's package-lock omits `resolved` URLs for some entries, which the
# v1 fetcher drops from the cache (npm then fails with ENOTCACHED).
npmDepsFetcherVersion = 2;
npmDepsHash = "sha256-wa5vQMYugA8E7lXOh4lgNH7JNbKOinNaW6Zk8Mw2e8k=";
# Skip Next.js build (requires network for Google Fonts).
# Pre-built dist/ is copied from the npm tarball in preConfigure.
+5
View File
@@ -0,0 +1,5 @@
{
pkgs,
...
}:
pkgs.callPackage ./package.nix { }
@@ -0,0 +1,92 @@
# OpenCode plugin for OpenCodeReview, built from the same source revision as
# the CLI (see package.nix). Ships the plugin TypeScript file plus the runtime
# node_modules resolved from the plugin's package-lock.json, so OpenCode can
# import `@opencode-ai/plugin` (v1.x) and `@opencode/plugin` (v2.x) without a
# network install.
{
lib,
stdenv,
nodejs,
fetchNpmDeps,
src,
version,
}:
let
pluginDir = "plugins/open-code-review/opencode";
lockfileCopy = ''
cp ${pluginDir}/package-lock.json ./package-lock.json
chmod +w package-lock.json
'';
npmDeps = fetchNpmDeps {
name = "open-code-review-opencode-plugin-npm-deps";
inherit src;
postPatch = lockfileCopy;
hash = "sha256-s5BO+JJJ9qZkKRTDmWyfBFVKB9GEeqObzyJ1lkORQo0=";
};
in
stdenv.mkDerivation {
pname = "open-code-review-opencode-plugin";
inherit version src;
# The lockfile lives in plugins/open-code-review/opencode/, but fetchNpmDeps
# and npm ci expect it at the package root.
postPatch = lockfileCopy;
# Exposed as an env var; used as the offline npm cache in installPhase.
inherit npmDeps;
# No build steps needed: the plugin is a single .ts file that OpenCode's
# runtime transpiles on the fly; only node_modules is materialized.
dontBuild = true;
dontConfigure = true;
nativeBuildInputs = [ nodejs ];
# OpenCode resolves plugin imports Node-style: node_modules next to the
# plugin file, or in any parent directory (resolved via the file's realpath).
# Install both the plugin file and node_modules so the plugin works whether
# users symlink the file only, the plugin dir, or point OpenCode at the
# store path directly.
installPhase = ''
runHook preInstall
pushd ${pluginDir}
# NOTE: upstream's package.json declares the plugin SDKs as
# devDependencies, so --omit=dev must NOT be used — it would install
# nothing. The full lockfile install is required.
npm ci \
--ignore-scripts \
--no-audit \
--no-fund \
--no-progress \
--loglevel=error \
--offline \
--cache "$npmDeps"
pluginOut=$out/share/open-code-review/opencode
mkdir -p "$pluginOut"
cp open-code-review.ts "$pluginOut/"
cp -r node_modules "$pluginOut/"
popd
runHook postInstall
'';
passthru = {
# The plugin speaks the CLI's JSON protocol; use it with a matching CLI
# version (both are built from the same source revision here).
forCli = "open-code-review";
};
meta = with lib; {
description = "OpenCode plugin exposing OpenCodeReview as native tools and slash commands";
homepage = "https://github.com/alibaba/open-code-review";
changelog = "https://github.com/alibaba/open-code-review/releases/tag/v${version}";
license = licenses.asl20;
platforms = platforms.all;
};
}
+63
View File
@@ -0,0 +1,63 @@
{
lib,
buildGoModule,
fetchFromGitHub,
callPackage,
}:
buildGoModule rec {
pname = "open-code-review";
version = "1.12.12";
src = fetchFromGitHub {
owner = "alibaba";
repo = "open-code-review";
rev = "v${version}";
hash = "sha256-U8C1LdO+6QQKDStitCDVypdNq5IkRgBlPbH4udpXLRM=";
};
vendorHash = "sha256-f5Ty22wicf1J8+RKnHYcEO7flWn9gkWQODlfunn23EA=";
env.CGO_ENABLED = 0;
subPackages = [ "cmd/opencodereview" ];
doCheck = false;
# Upstream (and the bundled OpenCode plugin) invokes the CLI as `ocr`, but the
# Go build names the binary after its cmd/ directory.
postInstall = ''
ln -s $out/bin/opencodereview $out/bin/ocr
'';
ldflags = [
"-s"
"-w"
"-X main.Version=v${version}"
"-X main.GitCommit=v${version}"
"-X main.BuildDate=1970-01-01T00:00:00Z"
];
passthru = {
category = "Code Review";
# OpenCode plugin built from the same source revision as the CLI.
opencode-plugin = callPackage ./opencode-plugin.nix {
inherit src version;
};
updateScript = [
"nix-update"
"--flake"
".#open-code-review"
];
};
meta = with lib; {
description = "AI-powered code review CLI combining deterministic pipelines with an LLM agent";
homepage = "https://github.com/alibaba/open-code-review";
changelog = "https://github.com/alibaba/open-code-review/releases/tag/v${version}";
license = licenses.asl20;
sourceProvenance = with sourceTypes; [ fromSource ];
mainProgram = "opencodereview";
platforms = platforms.all;
};
}
+6 -6
View File
@@ -6,13 +6,13 @@
}:
let
version = "1.9.1";
version = "1.16.2";
src = fetchFromGitHub {
owner = "skyhook-io";
repo = "radar";
rev = "v${version}";
hash = "sha256-VZLzmxW86yMtYILhmKswkj57KD4Z+8ILwHKiO53YMWE=";
rev = "k8s-ui-v${version}";
hash = "sha256-OrG628fEXVRwH3W4EBUBeqzFUyp12m3Xt4qTC5r5kVE=";
};
# Build the frontend as a separate derivation.
@@ -26,7 +26,7 @@ let
# Upstream lockfile ships complete resolved/integrity fields for all
# packages since v1.9.x, so no lockfile patching is needed anymore.
npmDepsHash = "sha256-9xS5ChQ1xBix/n9N8vyBsHlHYmYXsibTK5J+X6mRgM4=";
npmDepsHash = "sha256-1wznZuUbDKQlqJZpuNU+s7l24OY9981ak66HroXUtLk=";
npmDepsFetcherVersion = 2;
makeCacheWritable = true;
@@ -54,7 +54,7 @@ buildGoModule {
pname = "radar";
inherit version src;
vendorHash = "sha256-d26tlh+Twv9GFX6NmR25Q9OpP/pUL2T4grdncQHYSg4=";
vendorHash = "sha256-4xkFqa0hWN57bjfA0bgO8mcCsk3iVW45F8RJQnS2nm0=";
# Copy pre-built frontend assets before Go compilation for go:embed
preBuild = ''
@@ -91,7 +91,7 @@ buildGoModule {
meta = with lib; {
description = "Modern Kubernetes visibility — topology, event timeline, service traffic, resource browsing, Helm management, and GitOps support";
homepage = "https://github.com/skyhook-io/radar";
changelog = "https://github.com/skyhook-io/radar/releases/tag/v${version}";
changelog = "https://github.com/skyhook-io/radar/releases/tag/k8s-ui-v${version}";
license = licenses.asl20;
mainProgram = "radar";
platforms = platforms.linux;
+3 -3
View File
@@ -59,14 +59,14 @@ let
in
python3Packages.buildPythonApplication {
pname = "relay-free-llm";
version = "0.1.0+unstable";
version = "0-unstable-2026-08-31";
format = "other";
src = fetchFromGitHub {
owner = "msmarkgu";
repo = "RelayFreeLLM";
rev = "96e6c48a552755bf250c3155b14176916c69d8d8";
hash = "sha256-SNux6hVOij+2kYFH/gUQQj8QLfxGzjcdakkZ48AIWPU=";
rev = "9a1aabe1905ac1d6b3d48ac492089a0ea9668388";
hash = "sha256-DjHaskOW28g9BEI1TbMwuDgcEH4++VEMmXUzpqZ9KMc=";
};
nativeBuildInputs = [ makeWrapper ];
+2
View File
@@ -0,0 +1,2 @@
{ pkgs, ... }:
pkgs.callPackage ./package.nix { }
+48
View File
@@ -0,0 +1,48 @@
{
lib,
buildGoModule,
fetchFromGitHub,
}:
buildGoModule rec {
pname = "shardr";
# Pinned to a commit: upstream has no tagged source releases, only
# prebuilt "shardr-runner" bundles.
version = "0-unstable-2026-10-02";
src = fetchFromGitHub {
owner = "Cyb3rDudu";
repo = "shardr";
rev = "fab7fa89bc8164181c5bcebd1f23a74825d11de1";
hash = "sha256-bbNvTU3rSlKD7Wr+Q+WGKKtIVUq6uzmv93uZq0gzO2U=";
};
vendorHash = "sha256-wI7oVOFEKDK2hr7MmJ/QY9Mqwgk6t24cBe8HSM/zpVo=";
subPackages = [
"cmd/shardr"
"cmd/shardhive"
];
# Upstream tests assume a llama-server binary and a live shardhive socket.
doCheck = false;
passthru = {
category = "AI Inference";
updateScript = [
"nix-update"
"--flake"
".#shardr"
"--version=branch=main"
];
};
meta = {
description = "Decentralized LLM repository with sync-based distribution over a BitTorrent peer network";
homepage = "https://github.com/Cyb3rDudu/shardr";
changelog = "https://github.com/Cyb3rDudu/shardr/releases";
license = lib.licenses.asl20;
maintainers = [ ];
mainProgram = "shardr";
};
}
+1 -1
View File
@@ -8,7 +8,7 @@ python3Packages.buildPythonApplication {
pname = "skillsmcp";
# Pinned to a commit rather than a release tag because upstream
# has not yet published a tagged release containing all features.
version = "0.2.0+unstable";
version = "0-unstable-2026-04-08";
pyproject = true;
src = fetchFromGitHub {
+2 -2
View File
@@ -5,10 +5,10 @@
}:
let
version = "1.1.10";
version = "1.4.2";
src = fetchurl {
url = "https://github.com/traycerai/traycer/releases/download/desktop-v${version}/traycer-desktop-linux-x86_64.AppImage";
hash = "sha256-+aSlqX1RCpbKuV0j7xEBMQDAq/IzpvCC5XZ/psQJcjY=";
hash = "sha256-OIJ2e+BAomg3Fq7zaxlVi5o8hpDECaVUYsPpLiYib1I=";
};
appimageContents = appimageTools.extractType2 {
pname = "traycer";