{ lib, rustPlatform, fetchFromGitHub, cacert, }: rustPlatform.buildRustPackage rec { pname = "marmel"; # Upstream publishes no git tags, so this is pinned to the 1.0.0 release # commit ("1.0.0 (#6)"). version = "1.0.0"; src = fetchFromGitHub { owner = "Na1w"; repo = "marmel"; rev = "d6627d7cf3bf509d1e6db0d9d78736116e92e82a"; hash = "sha256-UlrSp/n3og0GAQXzISsB24OfK3qOUPE7jYOkEbZ2neI="; }; cargoHash = "sha256-etqW3xcxkiNfkiPxl/Emt5pQCkNnoIhHFkX0Zqfs4rc="; nativeCheckInputs = [ cacert ]; # The test suite builds `reqwest::Client`s, and rustls rejects construction # outright when no system trust store is found ("No CA certificates were # loaded from the system"). The sandbox has no /etc/ssl, so point the tests # at nixpkgs' bundle. Build-time only; the installed binary still uses the # host's trust store at runtime. preCheck = '' export SSL_CERT_FILE=${cacert}/etc/ssl/certs/ca-bundle.crt ''; # Serialise the test harness. The lib suite shares process-global worker # registries and steer/abort buses (src/orchestrator/workers.rs, # src/orchestrator/bus.rs, src/orchestrator/preemption.rs), so the # manager-loop tests fail nondeterministically when the harness runs them on # parallel threads: rebuilding one unchanged derivation yielded 3 failures, # then 1 failure, then 0 with serial threads. Drop this flag once upstream # makes that state per-instance. # # The two sandbox-exec tests are skipped. They re-exec `sh` through # `marmel --internal-sandbox-exec`, and apply_landlock_linux() allow-lists # FHS paths only (/usr, /bin, /lib, /opt, /etc, /var) plus /tmp. Landlock # matches inodes rather than symlinked views, and every binary on NixOS # resolves into the store (`/bin/sh` is # /nix/store/-bash-interactive-5.3p9/bin/bash), so the exec is denied: # "Failed to exec shell in sandbox: Permission denied (os error 13)". Checked # against this build on a NixOS host, where the same command succeeds once # the workspace root is `/` and therefore covers /nix/store. Inside the build # sandbox the tests are doubly impossible: /usr, /lib, /run and /var do not # exist, so the `if let Ok(fd)` guards silently drop those rules, and # /etc/resolv.conf is absent because the sandbox has no network. 342 of 344 # tests still run. Upstream main still carries the FHS-only list; drop these # skips if that ever gains /nix/store. cargoTestFlags = [ "--" "--test-threads=1" "--skip" "harness::sandbox::tests::test_internal_sandbox_exec_dev_null_and_dns" "--skip" "harness::sandbox::tests::test_internal_sandbox_cross_directory_rename" ]; # Role prompts are embedded with `include_str!`, so the binary needs no # runtime data files. The annotated example configs are the de-facto # first-run documentation, since a backend URL and model are mandatory. postInstall = '' install -Dm644 marmel.toml.example $out/share/doc/${pname}/examples/marmel.toml.example install -Dm644 marmel.toml.cloud $out/share/doc/${pname}/examples/marmel.toml.cloud ''; passthru = { category = "AI Coding Agents"; updateScript = [ "nix-update" "--flake" ".#marmel" "--version=branch=main" ]; }; meta = { description = "Autonomous agentic coding assistant with Manager + specialist subagent orchestration over any OpenAI-compatible LLM backend"; homepage = "https://github.com/Na1w/marmel"; # Upstream README states MIT, but the repository ships no LICENSE file and # Cargo.toml has no license field. license = lib.licenses.mit; sourceProvenance = with lib.sourceTypes; [ fromSource ]; mainProgram = "marmel"; platforms = lib.platforms.unix; }; }