Files
millerson-overlay.nix/packages/codeaf/package.nix
T
alex ff1fecc0ed
CI / check (push) Has been cancelled
fix(codeaf): build furrow from source and hand it over in CODEAF_FURROW
The package used to fetch the Agent-Field/furrow release asset and stage it for
go:embed, which is what `make build` does. Those bytes are a stock glibc build
that no Nix phase ever touched, so the copy codeaf writes out to
~/.codeaf/bin/furrow-0.1.0 cannot start here: NixOS answers "Could not start
dynamically linked executable" and names stub-ld. Every furrow verb the package
offers was dead with it.

Staging a rebuilt furrow was not an option. Upstream's fetcher hashes what it
stages against internal/furrowbin/pin.json and refuses anything else, and
patching the downloaded asset changes its hash. So this stages nothing, and
./furrow.nix builds the pinned version from source instead. The wrapped codeaf
passes it through CODEAF_FURROW, which internal/furrow reads before it looks at
the embedded copy, so the go binary carries no furrow at all (63 MB, was 67 MB)
and nothing unpatched is written to the state root.

furrow is Rust, not Go, and rusqlite bundles sqlite, hence the build time. Its
test suite wants a filesystem that supports user.* xattrs; the sandbox /tmp is
tmpfs and answers EOPNOTSUPP, which takes out the fixture of all 54 cli tests at
tests/cli.rs:48 and one lib test with it. The unit tests run, minus that one.

Verified with nix build .#codeaf: `codeaf --version` reports 0.7.1, the wrapper
sets CODEAF_FURROW to the store furrow, that furrow prints `furrow 0.1.0`
against store glibc, and it sits in the codeaf output's references so a gc
cannot pull it out from under the wrapper. Not verified on darwin, no builder.

Refs nix-overlay-bju
2026-10-07 11:33:48 +03:00

95 lines
3.3 KiB
Nix

{
lib,
buildGoModule,
fetchFromGitHub,
makeWrapper,
furrow,
}:
# codeaf carries a furrow inside itself: internal/furrowbin embeds whatever is
# staged in internal/furrowbin/cache and, on first use, writes it out to
# ~/.codeaf/bin/furrow-<version>. Upstream stages the GitHub release asset there,
# whose bytes are someone else's glibc-dynamic build that no Nix phase ever
# touched, so the file that lands in the state root cannot start here. Staging a
# rebuilt furrow is not an option either: upstream's fetcher re-checks the sha256
# named in internal/furrowbin/pin.json and would refuse one. So this build stages
# nothing, and hands over ./furrow.nix through CODEAF_FURROW instead, which
# internal/furrow reads before it looks at the embedded copy at all. Nothing of
# furrow's ends up in the codeaf binary; without that variable codeaf looks for
# furrow on PATH, the way a plain `go build` does.
#
# A codeaf run without this wrapper is not the same program: it has no furrow
# unless one is on PATH.
buildGoModule rec {
pname = "codeaf";
version = "0.7.1";
src = fetchFromGitHub {
owner = "Agent-Field";
repo = "CodeAF";
rev = "v${version}";
hash = "sha256-F4rRDNrTCF8/cj6g0KM41+gNdzvTWw5Vj2N0OJp+vCc=";
};
vendorHash = "sha256-eIocnhp3uGk+wG0kprRie0Csms+Deqxy3K3HuI1vJyM=";
env.CGO_ENABLED = 0;
nativeBuildInputs = [ makeWrapper ];
# The shipped binary carries the packed manual rather than the raw Markdown.
tags = [ "codeaf_packed_manual" ];
subPackages = [ "cmd/codeaf" ];
# Upstream's own suite is a CI matrix (make test / make check) with network
# and timing assumptions; it is not buildGoModule-shaped.
doCheck = false;
# `make build` runs a host-side step before compiling: packing the manual into
# what the codeaf_packed_manual tag embeds. It is built for the build machine
# even when codeaf targets another platform, hence the unset GOOS/GOARCH. The
# vendoring derivation runs preBuild too, before vendor/ exists, and this step
# needs the vendored dependencies, so it waits for it. Upstream's other step,
# staging the furrow release, is deliberately not run: see ./furrow.nix.
preBuild = ''
if [ -d vendor ]; then
env -u GOOS -u GOARCH go generate ./internal/manual
fi
'';
postInstall = ''
wrapProgram $out/bin/codeaf --set CODEAF_FURROW ${furrow}/bin/furrow
'';
ldflags = [
"-s"
"-w"
"-X github.com/Agent-Field/codeaf/internal/buildinfo.rev=${version}"
"-X github.com/Agent-Field/codeaf/internal/buildinfo.dirty=false"
];
passthru = {
inherit furrow;
category = "AI Coding Agents";
updateScript = [
"nix-update"
"--flake"
".#codeaf"
# furrow.nix is not a flake output, so nix-update never touches it: bump it
# by hand alongside the version codeaf pins in internal/furrowbin/pin.json.
];
};
meta = with lib; {
description = "Coding harness and software factory for open models: hand off work and watch every project from one terminal";
homepage = "https://github.com/Agent-Field/CodeAF";
changelog = "https://github.com/Agent-Field/CodeAF/blob/v${version}/CHANGELOG.md";
license = licenses.asl20;
# Runs the furrow built from source by ./furrow.nix, not the release asset
# upstream would have embedded.
mainProgram = "codeaf";
platforms = platforms.linux ++ platforms.darwin;
};
}