Compare commits

..

5 Commits

Author SHA1 Message Date
alex 5d46cbde3f bd: update sync.remote
CI / check (push) Has been cancelled
2026-09-14 12:31:44 +03:00
alex 3ee46a6824 chore(beads): File marmel racy-test and nix build .#packages follow-ups 2026-09-14 12:31:39 +03:00
alex d74788a4cb feat(packages): Add marmel autonomous coding agent
Pin Na1w/marmel to commit fd551ae. Upstream publishes no tags or
releases, so the version uses the shape nix-update generates for a
tagless repository, keeping `nix-update --version=branch=main` usable.

The test suite runs green (325 lib tests plus all integration suites)
with two accommodations, both documented in the derivation:

- Export SSL_CERT_FILE from nixpkgs cacert. rustls refuses to construct
  a reqwest::Client without a system trust store, which failed 38 tests
  with "No CA certificates were loaded from the system".
- Serialise the test harness. The lib suite shares process-global worker
  registries and steer/abort buses, so manager-loop tests fail
  nondeterministically on parallel threads: one unchanged derivation
  produced 3 failures, then 1 failure, then 0 with --test-threads=1.
  No test is skipped or filtered.

Annotated example configs are installed to share/doc/marmel/examples/.
Role prompts are embedded via include_str!, so there is no runtime data
directory. Upstream README states MIT but ships no LICENSE file and no
Cargo.toml license field.
2026-09-14 12:31:39 +03:00
alex 4ec88a70ed chore(beads): close flake.lock refresh task 2026-09-14 01:18:53 +03:00
alex 3f868775af chore(flake): refresh nixpkgs inputs to 2026-09-11
Bump nixpkgs and nixpkgs-latest from 2026-05/2026-08 to current
nixos-unstable (2026-09-11); both inputs now resolve to the same rev.
Re-validated every package against the new inputs.

Fallout fixed:
- freetoken: upstream pins torch>=2.11,<2.12 and triton==3.6.0, but the new
  nixpkgs only ships torch 2.13 / triton 3.7. Add a nixpkgs-torch211 input
  pinned at the previous revision and build freetoken against it, keeping
  the CUDA 12.9 / torch 2.11 stack unchanged.
- graphify: nixpkgs' pybloomfilter3 0.7.3 ships sdist metadata that still
  says 0.7.2, tripping pythonMetadataCheckPhase; skip that check only.

All 22 packages build and `nix flake check --no-build` passes.
2026-09-14 01:18:49 +03:00
9 changed files with 135 additions and 8 deletions
+2
View File
@@ -52,3 +52,5 @@
# - linear.api-key # - linear.api-key
# - github.org # - github.org
# - github.repo # - github.repo
sync.remote: "git+ssh://git@git.millerson.name:22002/alex/millerson-overlay.nix.git"
+2
View File
@@ -1,3 +1,5 @@
{"_type":"issue","id":"nix-overlay-4g1","title":"Add marmel package","description":"Package Na1w/marmel (binary: marmel, cargo crate: marmennill), an autonomous agentic coding assistant.\n\nDecisions from grilling session:\n- attr/pname/mainProgram = marmel\n- version = unstable-2026-09-13 (tagless upstream; matches nix-update --version=branch=main output shape)\n- rev = fd551ae3198d427b0f0df3429f88764c49095b23, updateScript = nix-update --version=branch=main\n- license = mit (upstream README claims MIT; no LICENSE file, no Cargo.toml license field)\n- platforms = unix\n- category = AI Coding Agents\n- doCheck = true, triage sandbox-hostile PTY/Landlock tests by name; fall back to doCheck=false with comment only if suite is unsandboxable\n- install annotated example configs to share/doc/marmel/examples/\n- verification: nix build .#marmel, nix run .#marmel -- --help, nix eval version, nix flake check, nix build .#packages, README table row\n\nKnown build risk: aws-lc-sys (via rustls-platform-verifier) is a CMake/NASM C build; add only the build inputs the build actually demands.","status":"open","priority":2,"issue_type":"task","owner":"alex@millerson.name","created_at":"2026-09-14T08:56:39Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-09-14T08:56:39Z","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-89n","title":"Refresh flake.lock nixpkgs inputs","description":"Update nixpkgs and nixpkgs-latest flake inputs (pinned 2026-05 and 2026-08) to current nixos-unstable, then re-validate package builds.","status":"closed","priority":2,"issue_type":"task","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-09-13T18:40:17Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-09-13T22:18:53Z","started_at":"2026-09-13T18:40:18Z","closed_at":"2026-09-13T22:18:53Z","close_reason":"nixpkgs/nixpkgs-latest bumped to 2026-09-11, freetoken pinned to nixpkgs-torch211, all 22 packages build and flake check passes.","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-cfk","title":"Update all packages to latest upstream versions","description":"Bump every package in packages/ to its latest available upstream version, refresh hashes (src, cargoHash, vendorHash, npm deps, bun2nix, appimage, etc.), verify builds, and update README. Packages: aionui, awg-tool, container-use, desloppify, ds4, freebuff, freetoken, graphify, haivemind, hipengine, kubernetes-mcp-server, llama-cpp, loop, mcp-gateway, nftables-analyzer, nftablesbuilder, omniroute, radar, relay-free-llm, skillsmcp, stakpak, traycer.","status":"closed","priority":2,"issue_type":"task","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-09-13T13:59:31Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-09-13T18:06:08Z","started_at":"2026-09-13T13:59:35Z","closed_at":"2026-09-13T18:06:08Z","close_reason":"All packages bumped to latest upstream; treefmt clean and nix flake check --no-build passes.","dependency_count":0,"dependent_count":0,"comment_count":0} {"_type":"issue","id":"nix-overlay-cfk","title":"Update all packages to latest upstream versions","description":"Bump every package in packages/ to its latest available upstream version, refresh hashes (src, cargoHash, vendorHash, npm deps, bun2nix, appimage, etc.), verify builds, and update README. Packages: aionui, awg-tool, container-use, desloppify, ds4, freebuff, freetoken, graphify, haivemind, hipengine, kubernetes-mcp-server, llama-cpp, loop, mcp-gateway, nftables-analyzer, nftablesbuilder, omniroute, radar, relay-free-llm, skillsmcp, stakpak, traycer.","status":"closed","priority":2,"issue_type":"task","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-09-13T13:59:31Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-09-13T18:06:08Z","started_at":"2026-09-13T13:59:35Z","closed_at":"2026-09-13T18:06:08Z","close_reason":"All packages bumped to latest upstream; treefmt clean and nix flake check --no-build passes.","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-05o","title":"Add llama-cpp package (build 9645) to overlay","description":"Port the pinned llama.cpp b9645 derivation from nixos-config/modules/llm-engine.nix into packages/llama-cpp/ (default.nix + package.nix). ROCm + Vulkan enabled, znver5 CPU flags, strix-halo gfx1151 orientation. Must build via nix build .#llama-cpp.","status":"closed","priority":2,"issue_type":"feature","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-09-13T09:22:26Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-09-13T10:33:35Z","started_at":"2026-09-13T09:22:28Z","closed_at":"2026-09-13T10:33:35Z","close_reason":"llama-cpp b9645 packaged in packages/llama-cpp, built and smoke-tested on gfx1151 (ROCm + Vulkan)","dependency_count":0,"dependent_count":0,"comment_count":0} {"_type":"issue","id":"nix-overlay-05o","title":"Add llama-cpp package (build 9645) to overlay","description":"Port the pinned llama.cpp b9645 derivation from nixos-config/modules/llm-engine.nix into packages/llama-cpp/ (default.nix + package.nix). ROCm + Vulkan enabled, znver5 CPU flags, strix-halo gfx1151 orientation. Must build via nix build .#llama-cpp.","status":"closed","priority":2,"issue_type":"feature","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-09-13T09:22:26Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-09-13T10:33:35Z","started_at":"2026-09-13T09:22:28Z","closed_at":"2026-09-13T10:33:35Z","close_reason":"llama-cpp b9645 packaged in packages/llama-cpp, built and smoke-tested on gfx1151 (ROCm + Vulkan)","dependency_count":0,"dependent_count":0,"comment_count":0}
{"_type":"issue","id":"nix-overlay-6y6","title":"Add Loop corporate messenger package","description":"Add Loop - Corporate messenger for your team. Distributed as x86-64 binary from https://artifacts.wilix.dev/repository/loop-files/loop-6.0.3/loop-desktop-6.0.3-linux-x64.tar.gz","status":"closed","priority":2,"issue_type":"feature","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-05-29T16:41:37Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-05-29T16:51:32Z","started_at":"2026-05-29T16:42:02Z","closed_at":"2026-05-29T16:51:32Z","close_reason":"Closed","dependency_count":0,"dependent_count":0,"comment_count":0} {"_type":"issue","id":"nix-overlay-6y6","title":"Add Loop corporate messenger package","description":"Add Loop - Corporate messenger for your team. Distributed as x86-64 binary from https://artifacts.wilix.dev/repository/loop-files/loop-6.0.3/loop-desktop-6.0.3-linux-x64.tar.gz","status":"closed","priority":2,"issue_type":"feature","assignee":"Alexander Miroshnichenko","owner":"alex@millerson.name","created_at":"2026-05-29T16:41:37Z","created_by":"Alexander Miroshnichenko","updated_at":"2026-05-29T16:51:32Z","started_at":"2026-05-29T16:42:02Z","closed_at":"2026-05-29T16:51:32Z","close_reason":"Closed","dependency_count":0,"dependent_count":0,"comment_count":0}
+1
View File
@@ -22,6 +22,7 @@ A custom Nix overlay and flake providing additional packages not found in upstre
| `graphify` | Turn any folder of code, docs, papers, images, or videos into a queryable knowledge graph | AI Coding Agents | | `graphify` | Turn any folder of code, docs, papers, images, or videos into a queryable knowledge graph | AI Coding Agents |
| `haivemind` | Multi-model AI consensus, aggregation, and fusion runner for popular AI CLIs | AI Coding Agents | | `haivemind` | Multi-model AI consensus, aggregation, and fusion runner for popular AI CLIs | AI Coding Agents |
| `hipengine` | ROCm-native local LLM inference engine with torch-free runtime for AMD RDNA GPUs | AI Inference | | `hipengine` | ROCm-native local LLM inference engine with torch-free runtime for AMD RDNA GPUs | AI Inference |
| `marmel` | Autonomous agentic coding assistant with Manager + specialist subagent orchestration over any OpenAI-compatible LLM backend | AI Coding Agents |
| `mcp-gateway` | Universal Model Context Protocol gateway that sits between AI client and MCP tools/servers | MCP Servers | | `mcp-gateway` | Universal Model Context Protocol gateway that sits between AI client and MCP tools/servers | MCP Servers |
| `nftables-analyzer` | Analyze nftables firewall rules and evaluate traffic queries | Networking | | `nftables-analyzer` | Analyze nftables firewall rules and evaluate traffic queries | Networking |
| `nftablesbuilder` | Web interface to manage nftables rules with drag-and-drop rule creation | Networking | | `nftablesbuilder` | Web interface to manage nftables rules with drag-and-drop rule creation | Networking |
Generated
+23 -6
View File
@@ -75,11 +75,11 @@
}, },
"nixpkgs": { "nixpkgs": {
"locked": { "locked": {
"lastModified": 1777954456, "lastModified": 1789149629,
"narHash": "sha256-hGdgeU2Nk87RAuZyYjyDjFL6LK7dAZN5RE9+hrDTkDU=", "narHash": "sha256-H6GwaZzZf+4npqv0tph94w9tZddSjFjmQrVsW0z78uk=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "549bd84d6279f9852cae6225e372cc67fb91a4c1", "rev": "eaad089433ca2bb662274377d33df3d0e51ef28b",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -91,11 +91,11 @@
}, },
"nixpkgs-latest": { "nixpkgs-latest": {
"locked": { "locked": {
"lastModified": 1785967620, "lastModified": 1789149629,
"narHash": "sha256-IItrdb7Puk05RqOBWZYFC5X6Wl1sJmCfh5MWVHw5iMM=", "narHash": "sha256-H6GwaZzZf+4npqv0tph94w9tZddSjFjmQrVsW0z78uk=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "b7c2ada94fe99c15b0dbcf4d11fd7850b957a436", "rev": "eaad089433ca2bb662274377d33df3d0e51ef28b",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -105,6 +105,22 @@
"type": "github" "type": "github"
} }
}, },
"nixpkgs-torch211": {
"locked": {
"lastModified": 1777954456,
"narHash": "sha256-hGdgeU2Nk87RAuZyYjyDjFL6LK7dAZN5RE9+hrDTkDU=",
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "549bd84d6279f9852cae6225e372cc67fb91a4c1",
"type": "github"
},
"original": {
"owner": "NixOS",
"repo": "nixpkgs",
"rev": "549bd84d6279f9852cae6225e372cc67fb91a4c1",
"type": "github"
}
},
"root": { "root": {
"inputs": { "inputs": {
"blueprint": "blueprint", "blueprint": "blueprint",
@@ -112,6 +128,7 @@
"flake-parts": "flake-parts", "flake-parts": "flake-parts",
"nixpkgs": "nixpkgs", "nixpkgs": "nixpkgs",
"nixpkgs-latest": "nixpkgs-latest", "nixpkgs-latest": "nixpkgs-latest",
"nixpkgs-torch211": "nixpkgs-torch211",
"systems": "systems", "systems": "systems",
"treefmt-nix": "treefmt-nix" "treefmt-nix": "treefmt-nix"
} }
+5
View File
@@ -6,6 +6,11 @@
# Newer nixpkgs whose toolchains are required by some packages: # Newer nixpkgs whose toolchains are required by some packages:
# rustc >= 1.95 (mcp-gateway >= 3.4.0), go >= 1.26.3 (kubernetes-mcp-server >= 0.0.66). # rustc >= 1.95 (mcp-gateway >= 3.4.0), go >= 1.26.3 (kubernetes-mcp-server >= 0.0.66).
nixpkgs-latest.url = "github:NixOS/nixpkgs/nixos-unstable"; nixpkgs-latest.url = "github:NixOS/nixpkgs/nixos-unstable";
# freetoken pins torch>=2.11,<2.12 and triton==3.6.0; current
# nixos-unstable only ships torch 2.13 / triton 3.7. Keep the previous
# nixpkgs revision for freetoken so its CUDA 12.9 / torch 2.11 stack is
# unchanged.
nixpkgs-torch211.url = "github:NixOS/nixpkgs/549bd84d6279f9852cae6225e372cc67fb91a4c1";
systems.url = "github:nix-systems/default"; systems.url = "github:nix-systems/default";
blueprint = { blueprint = {
url = "github:numtide/blueprint"; url = "github:numtide/blueprint";
+6 -1
View File
@@ -1,5 +1,10 @@
{ {
pkgs, pkgs,
inputs,
... ...
}: }:
pkgs.callPackage ./package.nix { } # freetoken pins torch>=2.11,<2.12 and triton==3.6.0, but current
# nixos-unstable ships torch 2.13 + triton 3.7 and no older torch. Build it
# with the pinned nixpkgs-torch211 revision (CUDA 12.9 / torch-bin 2.11).
inputs.nixpkgs-torch211.legacyPackages.${pkgs.stdenv.hostPlatform.system}.callPackage ./package.nix
{ }
+15 -1
View File
@@ -2,4 +2,18 @@
pkgs, pkgs,
... ...
}: }:
pkgs.callPackage ./package.nix { } # nixpkgs' pybloomfilter3 0.7.3 (a datasketch dependency) ships sdist metadata
# that still says 0.7.2, which makes pythonMetadataCheckPhase fail even though
# the build succeeds. Skip only that check.
let
python = pkgs.python3.override {
packageOverrides = self: super: {
pybloomfilter3 = super.pybloomfilter3.overridePythonAttrs (_: {
dontCheckPythonMetadata = true;
});
};
};
in
python.pkgs.callPackage ./package.nix {
python3Packages = python.pkgs;
}
+5
View File
@@ -0,0 +1,5 @@
{
pkgs,
...
}:
pkgs.callPackage ./package.nix { }
+76
View File
@@ -0,0 +1,76 @@
{
lib,
rustPlatform,
fetchFromGitHub,
cacert,
}:
rustPlatform.buildRustPackage rec {
pname = "marmel";
# Upstream publishes no git tags or releases, so this is pinned to a commit.
# The version shape matches what `nix-update --version=branch=main` generates
# for a tagless repository.
version = "unstable-2026-09-13";
src = fetchFromGitHub {
owner = "Na1w";
repo = "marmel";
rev = "fd551ae3198d427b0f0df3429f88764c49095b23";
hash = "sha256-nghvUF0EdqTGWT6GMG5oW1iK76r9vgvYeUj98hNraIo=";
};
cargoHash = "sha256-sUSsxcj4m4uJ28RKdJWKsb+MlVW6GkWjZdhKPFKlE/Y=";
nativeCheckInputs = [ cacert ];
# The test suite builds `reqwest::Client`s, and rustls rejects construction
# outright when no system trust store is found ("No CA certificates were
# loaded from the system"). The sandbox has no /etc/ssl, so point the tests
# at nixpkgs' bundle. Build-time only; the installed binary still uses the
# host's trust store at runtime.
preCheck = ''
export SSL_CERT_FILE=${cacert}/etc/ssl/certs/ca-bundle.crt
'';
# Serialise the test harness. The lib suite shares process-global worker
# registries and steer/abort buses (src/orchestrator/workers.rs,
# src/orchestrator/bus.rs, src/orchestrator/preemption.rs), so the
# manager-loop tests fail nondeterministically when the harness runs them on
# parallel threads: rebuilding one unchanged derivation yielded 3 failures,
# then 1 failure, then 0 with serial threads. All 325 tests still run — none
# are skipped or filtered. Drop this flag once upstream makes that state
# per-instance.
cargoTestFlags = [
"--"
"--test-threads=1"
];
# Role prompts are embedded with `include_str!`, so the binary needs no
# runtime data files. The annotated example configs are the de-facto
# first-run documentation, since a backend URL and model are mandatory.
postInstall = ''
install -Dm644 marmel.toml.example $out/share/doc/${pname}/examples/marmel.toml.example
install -Dm644 marmel.toml.cloud $out/share/doc/${pname}/examples/marmel.toml.cloud
'';
passthru = {
category = "AI Coding Agents";
updateScript = [
"nix-update"
"--flake"
".#marmel"
"--version=branch=main"
];
};
meta = {
description = "Autonomous agentic coding assistant with Manager + specialist subagent orchestration over any OpenAI-compatible LLM backend";
homepage = "https://github.com/Na1w/marmel";
# Upstream README states MIT, but the repository ships no LICENSE file and
# Cargo.toml has no license field.
license = lib.licenses.mit;
sourceProvenance = with lib.sourceTypes; [ fromSource ];
mainProgram = "marmel";
platforms = lib.platforms.unix;
};
}