Compare commits

10 Commits

Author SHA1 Message Date
alex 0813f55762 fix(kyojin): Isolate JIT and runtime toolchains
CI / check (push) Has been cancelled
Allow a pinned JIT SDK without rebuilding PyTorch or the extension.
Keep runtime device bitcode unchanged: exporting TheRock bitcode into
the serving process crashes CLR 7.2 on a basic tensor operation.

Disable unsupported expandable segments and check all five HIP kernel
modules, with an optional GPU matmul and module-loading regression test.
2026-10-08 17:17:56 +03:00
alex 4c24610aae fix(kyojin): serve wrappers get a C compiler, hipcc and the JIT sources
CI / check (push) Has been cancelled
env.sh assumes a distro box: a system cc for Triton's runtime C builds, a hipcc
for the JIT HIP kernels and the repo root on PYTHONPATH. The wrappers now export
all three (, ,  for the amdgcn bitcode,
PYTHONPATH=${src}/gr for gr_mix_hip).

The wheel ships only the files pyproject lists, so the .hip kernel sources, the
qsa_proof marker gating the QSA prefill kernel, the dense-GEMM tuning seed and
gr/ never reached site-packages: kernels fell back to Triton and every start
re-tuned dense GEMM for 7 minutes.

Verified on the Strix Halo box: server READY, start-up 713 s -> 103 s, warm-up
418 s -> 4 s, 584-token prompt served over /v1/chat/completions with no
'unavailable' fallbacks.
2026-10-08 15:57:52 +03:00
alex e061d3c170 feat(kyojin): add Kyojin ExLlamaV3 engine for AMD Strix Halo
CI / check (push) Has been cancelled
Kyojin (Yamz-Labs/kyojin) is a fork of ExLlamaV3 that runs 100 GB-class
EXL3 MoE packs on one 128 GB Ryzen AI Max box. It ships a torch C++
extension that torch's cpp_extension cross-compiles to HIP, and upstream
supports gfx1151 only, so the kernels are built for gfx1151 alone and
the package is marked Linux-only. Pinned to the v1.3 release.

The extension must be compiled against a ROCm build of torch. The flake's
nixos-unstable carries torch 2.13, whose ROCm build fails in nixpkgs (the
CK SDPA configure step runs a script through /bin/bash) and has no binary
on the cache, so the build would compile PyTorch from source and die.
python3Packages.torchWithRocm from the already pinned nixpkgs-torch211
input gives torch 2.11 with ROCm 7.2.2, gfx1151 in its target list and a
cached binary, so default.nix builds through that input the way freetoken
does.

nixpkgs splits the single devel tree the AMD wheels ship, so two
symlinkJoins stand in for it: one as ROCM_HOME (hipcc, headers, amdgcn
bitcode) and one handed to setup.py as EXL3_ROCM_DEV_INCLUDE, which wants
hipsparse/, rocsparse/, rocrand/, thrust/ and pybind11 (nixpkgs torch no
longer exports pybind11 headers). hipsolver is in there because torch's
own HIPContextLight.h includes it.

setup.py gets one patch in postPatch. It imports exllamav3 to reach
build_config, that runs the package __init__, which imports ext.py, which
JIT-compiles the entire extension whenever no precompiled exllamav3_ext is
importable, meaning every wheel build, into a $HOME the sandbox does not
grant. Registering a stub package keeps the two leaf modules importable
without that detour.

doCheck = false: tests/ drives a real gfx1151 GPU and the published
packs. Inference on a card is not verified here, this builder has no
/dev/kfd, so the wheel-only LD_PRELOAD workaround for torch's bundled HSA
runtime is untested. It should not be needed, the store torch links the
store rocm-runtime.

Verified with nix build .#kyojin at v1.3: exllamav3_ext loads, torch
reports hip 7.2.53211, the closure holds one torch (ROCm), and
kyojin-serve-qwen plus kyojin-serve-glm print their usage.

Refs nix-overlay-du9
2026-10-07 16:14:09 +03:00
alex ff1fecc0ed fix(codeaf): build furrow from source and hand it over in CODEAF_FURROW
CI / check (push) Has been cancelled
The package used to fetch the Agent-Field/furrow release asset and stage it for
go:embed, which is what `make build` does. Those bytes are a stock glibc build
that no Nix phase ever touched, so the copy codeaf writes out to
~/.codeaf/bin/furrow-0.1.0 cannot start here: NixOS answers "Could not start
dynamically linked executable" and names stub-ld. Every furrow verb the package
offers was dead with it.

Staging a rebuilt furrow was not an option. Upstream's fetcher hashes what it
stages against internal/furrowbin/pin.json and refuses anything else, and
patching the downloaded asset changes its hash. So this stages nothing, and
./furrow.nix builds the pinned version from source instead. The wrapped codeaf
passes it through CODEAF_FURROW, which internal/furrow reads before it looks at
the embedded copy, so the go binary carries no furrow at all (63 MB, was 67 MB)
and nothing unpatched is written to the state root.

furrow is Rust, not Go, and rusqlite bundles sqlite, hence the build time. Its
test suite wants a filesystem that supports user.* xattrs; the sandbox /tmp is
tmpfs and answers EOPNOTSUPP, which takes out the fixture of all 54 cli tests at
tests/cli.rs:48 and one lib test with it. The unit tests run, minus that one.

Verified with nix build .#codeaf: `codeaf --version` reports 0.7.1, the wrapper
sets CODEAF_FURROW to the store furrow, that furrow prints `furrow 0.1.0`
against store glibc, and it sits in the codeaf output's references so a gc
cannot pull it out from under the wrapper. Not verified on darwin, no builder.

Refs nix-overlay-bju
2026-10-07 11:33:48 +03:00
alex c08c444a39 fix(marmel): skip the two Landlock sandbox-exec tests
CI / check (push) Has been cancelled
The lib suite failed in the Nix sandbox:

    harness::sandbox::tests::test_internal_sandbox_exec_dev_null_and_dns
    harness::sandbox::tests::test_internal_sandbox_cross_directory_rename
    Failed to exec shell in sandbox: Permission denied (os error 13)

apply_landlock_linux() allow-lists FHS paths only, and Landlock matches
inodes rather than symlinked views, so nothing under /nix/store can be
executed once the ruleset is applied; /bin/sh here is a store path. The
build sandbox also drops the /usr, /lib, /run and /var rules, since those
paths do not exist there, and has no /etc/resolv.conf without network, so
neither test can pass however the package is written. 342 of 344 tests run,
all green.

The same denial applies at runtime: every shell tool call goes through
marmel --internal-sandbox-exec and fails on NixOS. Tracked as
nix-overlay-5ml. Upstream main still carries the FHS-only list.
2026-10-06 22:31:40 +03:00
alex 03337bc545 feat(codeaf): add CodeAF coding agent package
CI / check (push) Has been cancelled
CodeAF (Agent-Field/CodeAF) is a Go coding harness that ships one binary.
Pinned to v0.7.1; the flake's nixpkgs already carries go 1.26.7 and go.mod
asks for 1.26.5, so no extra nixpkgs input is needed.

Two things about this build are not obvious from the derivation:

- `make build` runs two host-side steps before compiling: `go generate
  ./internal/manual` packs the built-in manual into the pages.pack.gz and
  chat.pack.gz that the codeaf_packed_manual tag embeds, and
  internal/furrowbin/cmd/fetch stages the pinned Agent-Field/furrow release
  into internal/furrowbin/cache for go:embed. Both are run in preBuild with
  GOOS/GOARCH unset, the way the Makefile does it, so a cross build does not
  try to run a target binary on the build machine. buildGoModule runs preBuild
  in the vendoring derivation as well, before vendor/ exists and before the
  dependencies are in reach, so the two steps are gated on vendor/.
- The furrow step gets its bytes from fetchurl and `-from`, the offline road
  upstream documents. The fetcher still checks the sha256 in
  internal/furrowbin/pin.json, so the hashes here duplicate a pin that is
  already in the source; drop the furrow entirely and codeaf still builds and
  falls back to looking for the binary on PATH.

Tests are off: the upstream suite is a make/CI matrix with network and timing
assumptions, not a `go test ./...` that fits buildGoModule.

Verified with nix build .#codeaf, `codeaf --version` reporting 0.7.1 and
`codeaf manual` listing the packed manual pages.

Refs nix-overlay-m5y
2026-10-06 21:45:16 +03:00
alex dcbde330e4 fix(graphify): roll pin back to v0.9.77
CI / check (push) Has been cancelled
The 1.0.0 bump took a bogus tag. Graphify-Labs/graphify carries a
v1.0.0 branch from 2026-04-05 that sits 2126 commits behind v0.9.77,
still ships pyproject name graphifyy 0.1.10, and never reached PyPI,
where 0.9.77 is the latest release. nix-update picked it because it is
the highest semver tag available.

It also does not build here. Its pyproject hard-requires graspologic,
which pulls python-future, and nixpkgs disables that for Python >= 3.13
(this flake is on 3.14). Lowering the interpreter is no way out either:
python312 fails further down the chain on falcon and hyppo. 0.9.x ships
a networkx Louvain fallback for a missing Leiden backend; 1.0.0 imports
graspologic.partition.leiden unconditionally, so it is worse code even
if it did build.

Dependency corrections for the pinned source:
- datasketch dropped: upstream vendored MinHash into
  graphify/_minhash.py, which also retires the pybloomfilter3
  dontCheckPythonMetadata workaround in default.nix
- numpy added: graphify/_minhash.py imports it directly

Verified with nix build .#graphify (pythonImportsCheck passes) and
graphify --version reporting 0.9.77.

Refs nix-overlay-olq
2026-10-06 19:50:01 +03:00
alex 029d84940d chore(marmel): bump to 1.0.0
Pin upstream release commit d6627d7c ("1.0.0 (#6)"), update src hash.
Cargo.lock is byte-identical to the previous pin, so cargoHash is unchanged.
2026-10-06 19:20:49 +03:00
alex aa2c0995b2 docs(readme): track llama.cpp b11439 in the package table
CI / check (push) Has been cancelled
The table still advertised b9645 after the pin moved, so the README
contradicted the package it documents.

🤖 Generated with Codebuff
Co-Authored-By: Codebuff <noreply@codebuff.com>
2026-10-06 16:49:50 +03:00
alex 6013b17aad chore(packages): bump pins to current upstream releases
Refresh every package pin so the overlay stops carrying versions upstream
has moved past, and repair the pins where an automated bump had produced a
version that no longer resolves:

- graphify 0.9.61 -> 1.0.0 and back to tag tracking: the branch-tracking
  update script generated v0.9.77-unstable-<date> for a rev = "v${version}"
  src, a tag that never existed
- radar 1.13.1 -> 1.16.2 (upstream retagged its releases as k8s-ui-v*)
- llama-cpp b9645 -> b11439
- hipengine 0.5.0 -> 0.6.1, traycer 1.3.0 -> 1.4.2, freetoken 0.1.2 -> 0.1.3
- awg-tool 0.4.0, freebuff 0.2.19, kubernetes-mcp-server 0.0.67,
  marmel 0-unstable-2026-10-05, open-code-review 1.12.12,
  ds4 0-unstable-2026-09-20
- version-string normalisation for the branch-tracked packages already at
  their newest commit (g3, haivemind, shardr, skillsmcp)

Every changed src hash was re-fetched and verified. omniroute stays at
3.8.50: 3.8.51 changes its npm lockfile, so its npmDepsHash would have to
be recomputed before the bump is usable.

🤖 Generated with Codebuff
Co-Authored-By: Codebuff <noreply@codebuff.com>
2026-10-06 16:46:26 +03:00
24 changed files with 565 additions and 64 deletions
+29 -1
View File
@@ -14,6 +14,7 @@ A custom Nix overlay and flake providing additional packages not found in upstre
|---------|-------------|----------|
| `awg-tool` | CLI for AmneziaWG self-hosting — generates 1.0/1.5/2.0/3.0 obfuscation parameters, exports .conf and vpn:// configs, installs servers over SSH | Networking |
| `aionui` | Free, open-source, Cowork app with AI Agents | AI Coding Agents |
| `codeaf` | Coding harness and software factory for open models: hand work off, then watch every project from one terminal | AI Coding Agents |
| `container-use` | Containerized environments for coding agents | AI Coding Agents |
| `desloppify` | Multi-language codebase health scanner and technical debt tracker for AI agents | AI Coding Agents |
| `ds4` | DeepSeek 4 Flash and PRO local inference engine for ROCm (Strix Halo) | AI Inference |
@@ -30,7 +31,8 @@ A custom Nix overlay and flake providing additional packages not found in upstre
| `shardr` | Decentralized LLM repository: content-addressed model store, BitTorrent-based sync, OpenAI-compatible serving via llama-server | AI Inference |
| `skillsmcp` | MCP server that exposes Agent Skills to AI agents via the Model Context Protocol | MCP Servers |
| `kubernetes-mcp-server` | Model Context Protocol (MCP) server for Kubernetes and OpenShift | MCP Servers |
| `llama-cpp` | llama.cpp pinned to build b9645, built for Strix Halo (gfx1151) with ROCm + Vulkan backends | AI Inference |
| `kyojin` | ExLlamaV3-based inference engine with speculative decoding for 100 GB-class MoE packs on one 128 GB AMD Strix Halo (gfx1151, ROCm 7) | AI Inference |
| `llama-cpp` | llama.cpp pinned to build b11439, built for Strix Halo (gfx1151) with ROCm + Vulkan backends | AI Inference |
| `loop` | Corporate messenger for your team | Communication |
| `radar` | Modern Kubernetes visibility — topology, event timeline, service traffic, resource browsing, Helm management, and GitOps support | Kubernetes |
| `omniroute` | Unified AI router with 160+ providers, auto fallback, MCP/A2A, OpenAI-compatible APIs | AI LLM Gateway |
@@ -93,6 +95,30 @@ nix run git+https://git.millerson.name/alex/millerson-overlay.nix.git#mcp-gatewa
nix profile install git+https://git.millerson.name/alex/millerson-overlay.nix.git#mcp-gateway
```
### Kyojin JIT Toolchain
Kyojin's serving wrappers use the packaged ROCm compiler by default. Supply a
pinned SDK to compile HIP JIT kernels with another compiler without rebuilding
PyTorch or the HIP extension:
```nix
kyojin.override { jitRocmSdk = myJitSdk; }
```
The SDK must provide `bin/hipcc` and matching `amdgcn/bitcode`. Its compiler
wrapper must set `HIP_DEVICE_LIB_PATH` to that bitcode **in the compiler
subprocess only**, along with any required `ROCM_PATH` and Nix C++ toolchain
flags. Keep the compiler wrapper's real path inside the SDK prefix so upstream's
compiler provenance check recognizes it.
The serving process keeps PyTorch's ROCm device libraries. Setting TheRock's
Clang 23 bitcode globally makes the ROCm 7.2 runtime crash on a basic PyTorch
matrix multiplication. The serving wrappers also disable unsupported expandable
allocator segments. `nix build .#kyojin.tests.jit` checks compilation of five HIP
kernel modules without requiring a GPU; `packages/kyojin/check-jit.py --gpu`, run
with the package's Python environment and serving variables, additionally checks
PyTorch matrix multiplication and module loading through its existing HIP runtime.
### nftablesbuilder Runtime Notes
`nftablesbuilder` is a web interface for managing nftables. It consists of a
@@ -185,6 +211,7 @@ nix-overlay/
├── packages/ # Package definitions
│ ├── awg-tool/ # AmneziaWG parameter generation and SSH deployment CLI
│ ├── aionui/ # AionUi - AI Cowork desktop app
│ ├── codeaf/ # Coding harness and software factory for open models
│ ├── container-use/ # Containerized environments for coding agents
│ ├── default/ # Meta-package listing all packages
│ ├── desloppify/ # Codebase health scanner for AI agents
@@ -197,6 +224,7 @@ nix-overlay/
│ ├── haivemind/ # Multi-model AI consensus runner
│ ├── hipengine/ # ROCm-native LLM inference engine for AMD GPUs
│ ├── kubernetes-mcp-server/ # MCP server for Kubernetes and OpenShift
│ ├── kyojin/ # ExLlamaV3-based inference engine for Strix Halo (gfx1151)
│ ├── loop/ # Corporate messenger for your team
│ ├── mcp-gateway/ # MCP protocol gateway
│ ├── omniroute/ # Unified AI router with 160+ providers
+3 -3
View File
@@ -8,13 +8,13 @@
rustPlatform.buildRustPackage rec {
pname = "awg-tool";
version = "0.3.0";
version = "0.4.0";
src = fetchFromGitHub {
owner = "Vadim-Khristenko";
repo = "awg-containers-and-tools";
rev = "v${version}";
hash = "sha256-IRi2LPTDLT6qfuolCUHSJWaXTg5pt/kqVlosxqCMQDs=";
hash = "sha256-ggQjlHxNY3uXdLkE3CsSjsijFQScaJyCMhaXwASARSg=";
};
# awg-core builds ssh2 with vendored-openssl, which compiles libssh2
@@ -24,7 +24,7 @@ rustPlatform.buildRustPackage rec {
perl
];
cargoHash = "sha256-7sDpdjvA3kAHtwQ2qmpRPQywmyQBXZzM2ClfLKbGoKc=";
cargoHash = "sha256-2Vh9DXn6qdUT6wiITDID09j1iqpTHkZt/mpjAlYFA60=";
# Upstream tests exercise Docker/SSH targets; unit tests are already
# covered by the upstream CI before a release is cut.
+9
View File
@@ -0,0 +1,9 @@
{
pkgs,
...
}:
pkgs.callPackage ./package.nix {
# Not a package of its own: codeaf is the only consumer, and codeaf is the one
# that knows which furrow version it pinned. See ./furrow.nix.
furrow = pkgs.callPackage ./furrow.nix { };
}
+54
View File
@@ -0,0 +1,54 @@
{
lib,
rustPlatform,
fetchFromGitHub,
}:
# furrow is the copy-on-write workspace snapper codeaf drives. codeaf ships a
# copy of it inside the go binary: the release asset from GitHub, glibc-dynamic
# and untouched by anything in this build, so the file codeaf writes out to
# ~/.codeaf/bin/furrow-<version> cannot start here — NixOS answers "Could not
# start dynamically linked executable" and names stub-ld. Building furrow here
# instead gives the same version as an ordinary Nix binary, and codeaf is told
# to use it through CODEAF_FURROW, which internal/furrow reads before it ever
# looks at the embedded copy. See ./package.nix.
#
# The version here has to be the one codeaf pinned in
# internal/furrowbin/pin.json: the decoders in codeaf were written for that
# furrow. Bump the two together.
rustPlatform.buildRustPackage rec {
pname = "furrow";
version = "0.1.0";
src = fetchFromGitHub {
owner = "Agent-Field";
repo = "furrow";
rev = "v${version}";
hash = "sha256-xknfvnBDFxDYeBE1yAjXl1Fx3VDHrNSUhXEWQO3PK6s=";
};
cargoHash = "sha256-FGtrKtWFPcT3R8nF5OQFlmIiKSuZ8aiHfj76bBvga5A=";
# Only the unit tests run here. Every cli integration test builds a fixture
# whose first step is `xattr::set(…, "user.furrow-test", …)`, and the sandbox
# /tmp is a tmpfs that answers EOPNOTSUPP for user.* xattrs, so all 54 of them
# die in setup — same reason forks_files_links_modes_and_xattrs is skipped, in
# the one lib test that touches an xattr. Upstream's CI runs the whole suite on
# a filesystem that supports them.
cargoTestFlags = [ "--lib" ];
checkFlags = [
"--skip"
"forks_files_links_modes_and_xattrs"
];
meta = with lib; {
description = "Local-first working-state snapshots for agentic development";
homepage = "https://github.com/Agent-Field/furrow";
changelog = "https://github.com/Agent-Field/furrow/releases/tag/v${version}";
license = licenses.asl20;
# Thirteen source files use std::os::unix with no windows guards, so the
# upstream release has no windows asset either.
platforms = platforms.unix;
mainProgram = "furrow";
};
}
+94
View File
@@ -0,0 +1,94 @@
{
lib,
buildGoModule,
fetchFromGitHub,
makeWrapper,
furrow,
}:
# codeaf carries a furrow inside itself: internal/furrowbin embeds whatever is
# staged in internal/furrowbin/cache and, on first use, writes it out to
# ~/.codeaf/bin/furrow-<version>. Upstream stages the GitHub release asset there,
# whose bytes are someone else's glibc-dynamic build that no Nix phase ever
# touched, so the file that lands in the state root cannot start here. Staging a
# rebuilt furrow is not an option either: upstream's fetcher re-checks the sha256
# named in internal/furrowbin/pin.json and would refuse one. So this build stages
# nothing, and hands over ./furrow.nix through CODEAF_FURROW instead, which
# internal/furrow reads before it looks at the embedded copy at all. Nothing of
# furrow's ends up in the codeaf binary; without that variable codeaf looks for
# furrow on PATH, the way a plain `go build` does.
#
# A codeaf run without this wrapper is not the same program: it has no furrow
# unless one is on PATH.
buildGoModule rec {
pname = "codeaf";
version = "0.7.1";
src = fetchFromGitHub {
owner = "Agent-Field";
repo = "CodeAF";
rev = "v${version}";
hash = "sha256-F4rRDNrTCF8/cj6g0KM41+gNdzvTWw5Vj2N0OJp+vCc=";
};
vendorHash = "sha256-eIocnhp3uGk+wG0kprRie0Csms+Deqxy3K3HuI1vJyM=";
env.CGO_ENABLED = 0;
nativeBuildInputs = [ makeWrapper ];
# The shipped binary carries the packed manual rather than the raw Markdown.
tags = [ "codeaf_packed_manual" ];
subPackages = [ "cmd/codeaf" ];
# Upstream's own suite is a CI matrix (make test / make check) with network
# and timing assumptions; it is not buildGoModule-shaped.
doCheck = false;
# `make build` runs a host-side step before compiling: packing the manual into
# what the codeaf_packed_manual tag embeds. It is built for the build machine
# even when codeaf targets another platform, hence the unset GOOS/GOARCH. The
# vendoring derivation runs preBuild too, before vendor/ exists, and this step
# needs the vendored dependencies, so it waits for it. Upstream's other step,
# staging the furrow release, is deliberately not run: see ./furrow.nix.
preBuild = ''
if [ -d vendor ]; then
env -u GOOS -u GOARCH go generate ./internal/manual
fi
'';
postInstall = ''
wrapProgram $out/bin/codeaf --set CODEAF_FURROW ${furrow}/bin/furrow
'';
ldflags = [
"-s"
"-w"
"-X github.com/Agent-Field/codeaf/internal/buildinfo.rev=${version}"
"-X github.com/Agent-Field/codeaf/internal/buildinfo.dirty=false"
];
passthru = {
inherit furrow;
category = "AI Coding Agents";
updateScript = [
"nix-update"
"--flake"
".#codeaf"
# furrow.nix is not a flake output, so nix-update never touches it: bump it
# by hand alongside the version codeaf pins in internal/furrowbin/pin.json.
];
};
meta = with lib; {
description = "Coding harness and software factory for open models: hand off work and watch every project from one terminal";
homepage = "https://github.com/Agent-Field/CodeAF";
changelog = "https://github.com/Agent-Field/CodeAF/blob/v${version}/CHANGELOG.md";
license = licenses.asl20;
# Runs the furrow built from source by ./furrow.nix, not the release asset
# upstream would have embedded.
mainProgram = "codeaf";
platforms = platforms.linux ++ platforms.darwin;
};
}
+3 -3
View File
@@ -9,13 +9,13 @@
stdenv.mkDerivation {
pname = "ds4";
version = "0-unstable-2026-09-12";
version = "0-unstable-2026-09-20";
src = fetchFromGitHub {
owner = "antirez";
repo = "ds4";
rev = "bd66c402070042bf0a79ad6ece8242de4c93680c";
hash = "sha256-F/MKv3/0Oj8DLa+q6jMtv0wFDgUvii+Xo2f1dPBDg6A=";
rev = "0aaea5a238fb41a35106a551e73c8409dfb751ac";
hash = "sha256-Bo/td1HwVjw6bwz3BDwTP+ZSudkVFCo2aIVK4axvmXg=";
};
nativeBuildInputs = [
+4 -4
View File
@@ -9,11 +9,11 @@
}:
let
version = "0.0.174";
version = "0.2.19";
freebuffSrc = fetchurl {
url = "https://registry.npmjs.org/freebuff/-/freebuff-${version}.tgz";
hash = "sha256-o767MqjDbhiu+Zy3Jc/43kBNIgLVLEgqC7D3GwtU0hg=";
hash = "sha256-vIypYxwCuA/PKpldhwuFVNqwtm4UXZM6xInKZ5A+u9w=";
};
pkgTar = fetchurl {
@@ -48,14 +48,14 @@ let
binarySrc = fetchurl {
url = "https://github.com/CodebuffAI/codebuff-community/releases/download/freebuff-v${version}/freebuff-linux-x64.tar.gz";
hash = "sha256-W/+lPhdHxq0a5TWY/JodAuP2hLpCGlLU7E8SoNe+OYA=";
hash = "sha256-8EfFlhc6k0fEDws3w4kw1rIPQr5RXZHtekjxwouWW7Q=";
};
in
stdenv.mkDerivation rec {
pname = "freebuff";
version = "0.0.174";
version = "0.2.19";
src = freebuffSrc;
+2 -2
View File
@@ -81,14 +81,14 @@ let
in
py.buildPythonApplication (finalAttrs: {
pname = "freetoken";
version = "0.1.2";
version = "0.1.3";
pyproject = true;
src = fetchFromGitHub {
owner = "FlashML-org";
repo = "FreeToken";
tag = "v${finalAttrs.version}";
hash = "sha256-0MhuubuTjNvtQZxisC2cg1dJeR+A6wZ901H5FRv+l+c=";
hash = "sha256-59itjnwDr4P7I/ZLIbkNw9/8CCPvTP7yNWl9ogBnZ3o=";
};
# setup.py imports torch.utils.cpp_extension at build time and compiles two
+1 -1
View File
@@ -16,7 +16,7 @@ rustPlatform.buildRustPackage rec {
# Upstream has no git tags or releases; pin main and let nix-update
# track the branch. Version shape matches nix-update --version=branch=main
# for a tagless repository (package version is 0.1.0 upstream).
version = "0.1.0-unstable-2026-09-06";
version = "0-unstable-2026-09-06";
src = fetchFromGitHub {
owner = "dhanji";
+1 -15
View File
@@ -2,18 +2,4 @@
pkgs,
...
}:
# nixpkgs' pybloomfilter3 0.7.3 (a datasketch dependency) ships sdist metadata
# that still says 0.7.2, which makes pythonMetadataCheckPhase fail even though
# the build succeeds. Skip only that check.
let
python = pkgs.python3.override {
packageOverrides = self: super: {
pybloomfilter3 = super.pybloomfilter3.overridePythonAttrs (_: {
dontCheckPythonMetadata = true;
});
};
};
in
python.pkgs.callPackage ./package.nix {
python3Packages = python.pkgs;
}
pkgs.callPackage ./package.nix { }
+8 -5
View File
@@ -6,14 +6,18 @@
python3Packages.buildPythonApplication rec {
pname = "graphify";
version = "0.9.61";
version = "0.9.77";
pyproject = true;
# Do not bump to the v1.0.0 tag: it is a stale branch 2126 commits behind
# v0.9.77 (tagged 2026-04-05, pyproject still says graphifyy 0.1.10) and was
# never published to PyPI, where 0.9.77 is the latest release. nix-update
# picks v1.0.0 as the highest tag, so check PyPI before taking its result.
src = fetchFromGitHub {
owner = "safishamsi";
owner = "Graphify-Labs";
repo = "graphify";
rev = "v${version}";
hash = "sha256-9AEbHmqqZv/fBioUMNv60KAb/FpvWpwC6QhGSdBxISs=";
hash = "sha256-CvJ6GoV1nSzFGfLQbzKSHDUNOuOPQZaYOf/idcSHkPw=";
};
build-system = with python3Packages; [
@@ -24,7 +28,7 @@ python3Packages.buildPythonApplication rec {
# Missing grammars will be downloaded by tree-sitter at runtime on demand.
dependencies = with python3Packages; [
networkx
datasketch
numpy
rapidfuzz
tree-sitter
tree-sitter-python
@@ -77,7 +81,6 @@ python3Packages.buildPythonApplication rec {
"nix-update"
"--flake"
".#graphify"
"--version=branch=main"
];
};
+1 -1
View File
@@ -6,7 +6,7 @@
python3Packages.buildPythonApplication rec {
pname = "haivemind";
version = "0.1.0";
version = "0-unstable-2026-07-01";
pyproject = true;
src = fetchFromGitHub {
+2 -2
View File
@@ -6,14 +6,14 @@
python3Packages.buildPythonApplication rec {
pname = "hipengine";
version = "0.5.0";
version = "0.6.1";
pyproject = true;
src = fetchFromGitHub {
owner = "shisa-ai";
repo = "hipEngine";
rev = "v${version}";
hash = "sha256-xjVpdr2avDKA2IoXA9W5Q/c6cT+G/BxrTDzjP5Tm+3Y=";
hash = "sha256-7FQZuExTTqcMKZkCRzLC5nYLpGytswhEsBTUliQqoTI=";
};
build-system = with python3Packages; [
+3 -3
View File
@@ -6,16 +6,16 @@
buildGoModule rec {
pname = "kubernetes-mcp-server";
version = "0.0.66";
version = "0.0.67";
src = fetchFromGitHub {
owner = "containers";
repo = "kubernetes-mcp-server";
rev = "v${version}";
hash = "sha256-vnJxSCfnpvOZJXQpKrCAW4QKt5R2PJDYQevA7O1uXZg=";
hash = "sha256-rejF9JsszB3ZirZhoK1VDbCH/P0Xzmh4TJw5j+okj+M=";
};
vendorHash = "sha256-gbqoT4X+wVOEktHm7jaAH9vHrUBrYgR8OjyFz1ljP6k=";
vendorHash = "sha256-TSB2jAWh2PlDHpvzA/rrBbjaR8sgyjivDO0vsbcuvgg=";
env.CGO_ENABLED = 0;
+46
View File
@@ -0,0 +1,46 @@
"""Compile Kyojin's JIT kernels; --gpu also loads them through torch's HIP runtime."""
import ctypes
import importlib
import os
from pathlib import Path
import sys
from exllamav3.util import hip_compiler
from exllamav3.util.hip_lib import load_hip_runtime
sdk = Path(os.environ["EXL3_ROCM_SDK"])
assert Path(hip_compiler.hipcc()) == sdk / "bin/hipcc"
assert Path(os.environ["HIP_DEVICE_LIB_PATH"]).is_dir()
assert (sdk / "amdgcn/bitcode").is_dir()
if os.environ.get("KYOJIN_REQUIRE_SDK") == "1":
assert hip_compiler.warning() is None, hip_compiler.warning()
print(hip_compiler.describe(), flush=True)
lib = None
if "--gpu" in sys.argv:
import torch
# Also exercise the runtime bitcode path: merely loading a HIP module
# does not catch incompatible device libraries in CLR/COMGR.
x = torch.ones((32, 32), device="cuda", dtype=torch.float32)
assert torch.equal(x @ x, torch.full_like(x, 32))
torch.cuda.synchronize()
lib = load_hip_runtime()
lib.hipModuleLoad.argtypes = [ctypes.POINTER(ctypes.c_void_p), ctypes.c_char_p]
lib.hipModuleUnload.argtypes = [ctypes.c_void_p]
for module, function, args in [
("gr_mix_hip", "compile_hsaco", ()),
("exllamav3.modules.attention_fn.qsa_prefill_hip", "compile_hsaco", ()),
("exllamav3.modules.ple_fn.ple_hip", "compile_hsaco", ()),
("exllamav3.vendor.fla.hip.gdn_fused_h_hip", "_compile", ("", "gfx1151")),
("exllamav3.vendor.fla.hip.kda_fused_h_hip", "_compile", ("", "gfx1151")),
]:
path = Path(getattr(importlib.import_module(module), function)(*args))
# HIP accepts ELF, offload bundles, and compressed offload bundles (CCOB).
assert path.read_bytes().startswith((b"\x7fELF", b"__CLANG_OFFLOAD_BUNDLE__", b"CCOB")), path
if lib is not None:
handle = ctypes.c_void_p()
assert lib.hipModuleLoad(ctypes.byref(handle), os.fsencode(path)) == 0, path
assert lib.hipModuleUnload(handle) == 0, path
print(f"OK: {module}", flush=True)
+13
View File
@@ -0,0 +1,13 @@
{
pkgs,
inputs,
jitRocmSdk ? null,
...
}:
# The HIP extension has to be compiled against a ROCm build of PyTorch, and the
# only ROCm torch in this flake with a cached binary is the one from the pinned
# nixpkgs-torch211 input (2.11 + ROCm 7.2, python 3.13). Current nixos-unstable
# ships torch 2.13, whose ROCm build fails to configure in nixpkgs and is not
# on cache.nixos.org.
inputs.nixpkgs-torch211.legacyPackages.${pkgs.stdenv.hostPlatform.system}.callPackage ./package.nix
{ inherit jitRocmSdk; }
+251
View File
@@ -0,0 +1,251 @@
{
lib,
stdenv,
pkgs,
python3,
fetchFromGitHub,
makeWrapper,
rocmPackages,
# Override only the serving toolchain; torch and the extension keep their ROCm.
jitRocmSdk ? null,
}:
let
py = python3.pkgs;
# Kyojin is the Yamz fork of ExLlamaV3: a Python package plus a C++ extension
# that torch's cpp_extension cross-compiles to HIP code objects. Upstream
# only supports AMD Strix Halo, so the kernels are built for gfx1151 alone.
rocmArch = "gfx1151";
version = "1.3";
src = fetchFromGitHub {
owner = "Yamz-Labs";
repo = "kyojin";
rev = "v${version}";
hash = "sha256-/DPoqW/iaLXRAH8XF5RdE+K5YS4jZT6Sic6QeCDQMlU=";
};
# setup.py passes EXL3_ROCM_DEV_INCLUDE as -I to every translation unit. The
# AMD wheels ship one devel tree holding hipsparse/ and thrust/; nixpkgs
# splits them per package, so join the include dirs. torch's public HIP
# headers also pull hipsolver/, and it no longer vendors pybind11.
rocmDevInclude = pkgs.symlinkJoin {
name = "kyojin-rocm-dev-include";
paths = map lib.getDev (
[ py.pybind11 ]
++ [
rocmPackages.clr
rocmPackages.hipblas
rocmPackages.hipblaslt
rocmPackages.hipcub
rocmPackages.hipfft
rocmPackages.hiprand
rocmPackages.hipsparse
rocmPackages.hipsolver
rocmPackages.rocblas
rocmPackages.rocprim
rocmPackages.rocrand
rocmPackages.rocsolver
rocmPackages.rocsparse
rocmPackages.rocthrust
]
);
};
# torch's HIP path in cpp_extension expects one ROCM_HOME holding bin/hipcc,
# the headers and the amdgcn bitcode; nixpkgs ships them separately.
rocmToolkit = pkgs.symlinkJoin {
name = "kyojin-rocm-toolkit";
paths = [
rocmPackages."rocm-core"
rocmPackages."rocm-runtime"
rocmPackages."rocm-device-libs"
rocmPackages."rocm-comgr"
rocmPackages.clr
(lib.getBin rocmPackages.hipcc)
rocmPackages.rocblas
rocmPackages.hipblas
rocmPackages.hipblas-common
rocmPackages.hipblaslt
rocmPackages.hipsparse
rocmPackages.hipsolver
rocmPackages.hiprand
rocmPackages.rocrand
rocmPackages.hipfft
rocmPackages.rocsparse
rocmPackages.rocsolver
rocmPackages.rocthrust
rocmPackages.rocprim
rocmPackages.hipcub
];
# The setup hooks of the joined packages would rewrite build flags; the
# compiler only needs the files.
postBuild = ''
rm -rf $out/nix-support
'';
};
# The library: exllamav3 plus the compiled exllamav3_ext module.
library = py.buildPythonPackage {
inherit src version;
pname = "kyojin";
format = "pyproject";
build-system = with py; [
setuptools
wheel
];
nativeBuildInputs = [
py.ninja
rocmPackages."rocm-runtime"
];
buildInputs = [ (lib.getBin rocmPackages.hipcc) ];
propagatedBuildInputs = with py; [
aiohttp
huggingface-hub
jinja2
llguidance
marisa-trie
numpy
pillow
pydantic
pyyaml
rich
safetensors
tokenizers
torchWithRocm
typing-extensions
];
env = {
PYTORCH_ROCM_ARCH = rocmArch;
ROCM_PATH = "${rocmToolkit}";
ROCM_HOME = "${rocmToolkit}";
HIP_PATH = "${rocmToolkit}";
HIPCC = "${rocmToolkit}/bin/hipcc";
HIP_DEVICE_LIB_PATH = "${rocmPackages."rocm-device-libs"}/amdgcn/bitcode";
# Upstream build scripts look these up to find the ROCm devel tree.
EXL3_ROCM_SDK = "${rocmToolkit}";
EXL3_ROCM_DEV_INCLUDE = "${rocmDevInclude}/include";
# Default defines of upstream build.sh (tools/strix_halo/rebuild.sh).
EXL3_HIP_DEFINES = "EXL3_HIP_STG_PAD";
};
# setup.py pulls the extension source list and the arch helper with
# `from exllamav3...import ...`, which runs the package __init__ and
# therefore exllamav3/ext.py. That module JIT-compiles the extension when no
# precompiled exllamav3_ext is importable, i.e. during every wheel build
# (and it wants a writable $HOME for it). Register an empty `exllamav3`
# package first so only the two leaf modules are imported, and load
# build_config without the package wrapper.
postPatch = ''
sed -i '1i import sys as _sys, types as _types; _exl3_pkg = _types.ModuleType("exllamav3"); _exl3_pkg.__path__ = ["exllamav3"]; _sys.modules.setdefault("exllamav3", _exl3_pkg)' setup.py
sed -i 's|^from exllamav3\.exllamav3_ext\.build_config import get_sources as _get_sources$|import sys as _exl3_sys; _exl3_sys.path.insert(0, "exllamav3/exllamav3_ext"); from build_config import get_sources as _get_sources; _exl3_sys.path.pop(0)|' setup.py
grep -q 'from build_config import' setup.py
# Upstream serves these from the checkout (pip install -e .); the wheel only
# packages what pyproject lists, and three things are read out of the
# installed package at run time: the .hip sources the JIT kernels compile,
# the qsa_proof marker gating the QSA prefill kernel, and the dense-GEMM
# tuning seed (without it every start re-tunes for ~7 minutes).
sed -i 's|^ "exllamav3_ext/\*\*/\*",$|&\n "**/*.hip",\n "**/*.ok",\n "model/dense_gemm_tune_seed.txt",|' pyproject.toml
grep -q '"\*\*/\*.hip"' pyproject.toml
'';
# tests/ needs a real gfx1151 GPU and the published model packs.
doCheck = false;
meta = with lib; {
description = "Inference engine for 100 GB-class EXL3 MoE models on AMD Strix Halo (gfx1151, ROCm 7)";
homepage = "https://github.com/Yamz-Labs/kyojin";
changelog = "https://github.com/Yamz-Labs/kyojin/releases";
license = licenses.mit;
sourceProvenance = with sourceTypes; [ fromSource ];
# HIP code objects are gfx1151-only and ROCm is Linux-only.
platforms = platforms.linux;
};
};
python = py.python.withPackages (_: [ library ]);
jitSdk = if jitRocmSdk == null then rocmToolkit else jitRocmSdk;
in
stdenv.mkDerivation {
inherit src version;
pname = "kyojin";
# Only the wrappers are installed here: the serve scripts are plain scripts,
# they import their siblings by path, and the module itself is in `library`.
#
# Upstream `tools/strix_halo/env.sh` is sourced before serving, and on a
# distro box that brings a system `cc` (the AMD Triton backend compiles a
# CPython glue module at runtime, and again per kernel launcher) plus a hipcc
# for the JIT HIP kernels (qsa prefill, gdn, kda, ple). Nix gives the wrapper
# neither, so export them here instead: Triton takes the compiler from $CC,
# exllamav3 finds hipcc under $EXL3_ROCM_SDK, and hipclang only finds the
# amdgcn bitcode through $HIP_DEVICE_LIB_PATH (hipcc's own DEVICE_LIB_PATH is
# not enough for a --genco call). The ROCm paths stay out of LD_LIBRARY_PATH
# (upstream Trap 1/5: a second libhsa segfaults torch), and PYTHONPATH gets
# `gr/`: upstream env.sh puts the repo root there so `import gr_mix_hip` (the
# hand-written gated-residual WMMA kernel the server asks for with
# EXL3_GR_HIP=1) resolves, and it is not part of the wheel either.
dontConfigure = true;
dontBuild = true;
nativeBuildInputs = [ makeWrapper ];
installPhase = ''
runHook preInstall
mkdir -p $out/bin
for model in glm mimo qwen; do
makeWrapper ${python}/bin/python $out/bin/kyojin-serve-$model \
--set PYTORCH_ROCM_ARCH ${rocmArch} \
--set CC ${stdenv.cc}/bin/cc \
--set EXL3_ROCM_SDK ${jitSdk} \
--set HIP_DEVICE_LIB_PATH ${rocmPackages."rocm-device-libs"}/amdgcn/bitcode \
--set EXL3_EXPANDABLE_SEGMENTS 0 \
--prefix PATH : ${lib.makeBinPath [ stdenv.cc ]} \
--prefix PYTHONPATH : ${src}/gr \
--add-flags "${src}/tools/$model/serve.py"
done
runHook postInstall
'';
passthru = {
inherit python rocmArch;
pythonPackage = library;
jitRocmSdk = jitSdk;
tests.jit =
pkgs.runCommand "kyojin-jit-check"
{
EXL3_ROCM_SDK = jitSdk;
# CLR/COMGR also reads this variable. Newer bitcode crashes torch
# matmul; a custom hipcc must select its own bitcode in its subprocess.
HIP_DEVICE_LIB_PATH = "${rocmPackages."rocm-device-libs"}/amdgcn/bitcode";
EXL3_EXPANDABLE_SEGMENTS = "0";
PYTHONPATH = "${src}/gr";
KYOJIN_REQUIRE_SDK = lib.boolToString (jitRocmSdk != null);
}
''
export HOME="$TMPDIR"
${python}/bin/python ${./check-jit.py}
touch "$out"
'';
category = "AI Inference";
updateScript = [
"nix-update"
"--flake"
".#kyojin"
];
};
meta = library.meta // {
mainProgram = "kyojin-serve-qwen";
};
}
+2 -2
View File
@@ -18,7 +18,7 @@ let
# Upstream release tag. Bump with:
# nix flake prefetch github:ggml-org/llama.cpp/b<NNNN>
# then update buildNumber and the src hash.
buildNumber = "9645";
buildNumber = "11439";
# HIP flags from the llm-engine.nix bring-up config. The -I paths for
# hipBLASLt/rocWMMA are dropped because this tag's HIP backend links
@@ -51,7 +51,7 @@ in
repo = "llama.cpp";
tag = "b${buildNumber}";
# Tarball hash (this tag has no submodules).
hash = "sha256-ntRwfI2/yVqi3QjQfO0ZajMFSD8r/6XPiuy0X2BhwVk=";
hash = "sha256-9KUkThRm+kvYOguP08JOPtjQjtDsDqgh1e50NdR0V5I=";
};
# The embedded web UI is disabled via cmakeFlags, so none of the npm
+27 -10
View File
@@ -7,19 +7,18 @@
rustPlatform.buildRustPackage rec {
pname = "marmel";
# Upstream publishes no git tags or releases, so this is pinned to a commit.
# The version shape matches what `nix-update --version=branch=main` generates
# for a tagless repository.
version = "unstable-2026-09-13";
# Upstream publishes no git tags, so this is pinned to the 1.0.0 release
# commit ("1.0.0 (#6)").
version = "1.0.0";
src = fetchFromGitHub {
owner = "Na1w";
repo = "marmel";
rev = "fd551ae3198d427b0f0df3429f88764c49095b23";
hash = "sha256-nghvUF0EdqTGWT6GMG5oW1iK76r9vgvYeUj98hNraIo=";
rev = "d6627d7cf3bf509d1e6db0d9d78736116e92e82a";
hash = "sha256-UlrSp/n3og0GAQXzISsB24OfK3qOUPE7jYOkEbZ2neI=";
};
cargoHash = "sha256-sUSsxcj4m4uJ28RKdJWKsb+MlVW6GkWjZdhKPFKlE/Y=";
cargoHash = "sha256-etqW3xcxkiNfkiPxl/Emt5pQCkNnoIhHFkX0Zqfs4rc=";
nativeCheckInputs = [ cacert ];
@@ -37,12 +36,30 @@ rustPlatform.buildRustPackage rec {
# src/orchestrator/bus.rs, src/orchestrator/preemption.rs), so the
# manager-loop tests fail nondeterministically when the harness runs them on
# parallel threads: rebuilding one unchanged derivation yielded 3 failures,
# then 1 failure, then 0 with serial threads. All 325 tests still run — none
# are skipped or filtered. Drop this flag once upstream makes that state
# per-instance.
# then 1 failure, then 0 with serial threads. Drop this flag once upstream
# makes that state per-instance.
#
# The two sandbox-exec tests are skipped. They re-exec `sh` through
# `marmel --internal-sandbox-exec`, and apply_landlock_linux() allow-lists
# FHS paths only (/usr, /bin, /lib, /opt, /etc, /var) plus /tmp. Landlock
# matches inodes rather than symlinked views, and every binary on NixOS
# resolves into the store (`/bin/sh` is
# /nix/store/<hash>-bash-interactive-5.3p9/bin/bash), so the exec is denied:
# "Failed to exec shell in sandbox: Permission denied (os error 13)". Checked
# against this build on a NixOS host, where the same command succeeds once
# the workspace root is `/` and therefore covers /nix/store. Inside the build
# sandbox the tests are doubly impossible: /usr, /lib, /run and /var do not
# exist, so the `if let Ok(fd)` guards silently drop those rules, and
# /etc/resolv.conf is absent because the sandbox has no network. 342 of 344
# tests still run. Upstream main still carries the FHS-only list; drop these
# skips if that ever gains /nix/store.
cargoTestFlags = [
"--"
"--test-threads=1"
"--skip"
"harness::sandbox::tests::test_internal_sandbox_exec_dev_null_and_dns"
"--skip"
"harness::sandbox::tests::test_internal_sandbox_cross_directory_rename"
];
# Role prompts are embedded with `include_str!`, so the binary needs no
+2 -2
View File
@@ -7,13 +7,13 @@
buildGoModule rec {
pname = "open-code-review";
version = "1.12.9";
version = "1.12.12";
src = fetchFromGitHub {
owner = "alibaba";
repo = "open-code-review";
rev = "v${version}";
hash = "sha256-g/l4Ezv1YJYjRNI2DU5WgkaPvYp+/SC3yL+HEl/8kFI=";
hash = "sha256-U8C1LdO+6QQKDStitCDVypdNq5IkRgBlPbH4udpXLRM=";
};
vendorHash = "sha256-f5Ty22wicf1J8+RKnHYcEO7flWn9gkWQODlfunn23EA=";
+6 -6
View File
@@ -6,13 +6,13 @@
}:
let
version = "1.13.1";
version = "1.16.2";
src = fetchFromGitHub {
owner = "skyhook-io";
repo = "radar";
rev = "v${version}";
hash = "sha256-jRcX7wv+uHxH2hoYSoLEjcVnuRGAnrTt4tbwZozDb7Y=";
rev = "k8s-ui-v${version}";
hash = "sha256-OrG628fEXVRwH3W4EBUBeqzFUyp12m3Xt4qTC5r5kVE=";
};
# Build the frontend as a separate derivation.
@@ -26,7 +26,7 @@ let
# Upstream lockfile ships complete resolved/integrity fields for all
# packages since v1.9.x, so no lockfile patching is needed anymore.
npmDepsHash = "sha256-TuSBPGktl6s1adHWbP81+TOEZufo5y2gwiUnfiaLoOc=";
npmDepsHash = "sha256-1wznZuUbDKQlqJZpuNU+s7l24OY9981ak66HroXUtLk=";
npmDepsFetcherVersion = 2;
makeCacheWritable = true;
@@ -54,7 +54,7 @@ buildGoModule {
pname = "radar";
inherit version src;
vendorHash = "sha256-sFlj1sE+ciXQauReWm3mLQZK21lqTaU4cAj06flpx30=";
vendorHash = "sha256-4xkFqa0hWN57bjfA0bgO8mcCsk3iVW45F8RJQnS2nm0=";
# Copy pre-built frontend assets before Go compilation for go:embed
preBuild = ''
@@ -91,7 +91,7 @@ buildGoModule {
meta = with lib; {
description = "Modern Kubernetes visibility — topology, event timeline, service traffic, resource browsing, Helm management, and GitOps support";
homepage = "https://github.com/skyhook-io/radar";
changelog = "https://github.com/skyhook-io/radar/releases/tag/v${version}";
changelog = "https://github.com/skyhook-io/radar/releases/tag/k8s-ui-v${version}";
license = licenses.asl20;
mainProgram = "radar";
platforms = platforms.linux;
+1 -1
View File
@@ -8,7 +8,7 @@ buildGoModule rec {
pname = "shardr";
# Pinned to a commit: upstream has no tagged source releases, only
# prebuilt "shardr-runner" bundles.
version = "0.1.0+unstable";
version = "0-unstable-2026-10-02";
src = fetchFromGitHub {
owner = "Cyb3rDudu";
+1 -1
View File
@@ -8,7 +8,7 @@ python3Packages.buildPythonApplication {
pname = "skillsmcp";
# Pinned to a commit rather than a release tag because upstream
# has not yet published a tagged release containing all features.
version = "0.2.0+unstable";
version = "0-unstable-2026-04-08";
pyproject = true;
src = fetchFromGitHub {
+2 -2
View File
@@ -5,10 +5,10 @@
}:
let
version = "1.3.0";
version = "1.4.2";
src = fetchurl {
url = "https://github.com/traycerai/traycer/releases/download/desktop-v${version}/traycer-desktop-linux-x86_64.AppImage";
hash = "sha256-iDpbpDpd0OeRGTKwUVRYiIpRSltnAIb59W+yIfH8HFU=";
hash = "sha256-OIJ2e+BAomg3Fq7zaxlVi5o8hpDECaVUYsPpLiYib1I=";
};
appimageContents = appimageTools.extractType2 {
pname = "traycer";