Files
millerson-overlay.nix/packages/marmel/package.nix
T
alex c08c444a39
CI / check (push) Has been cancelled
fix(marmel): skip the two Landlock sandbox-exec tests
The lib suite failed in the Nix sandbox:

    harness::sandbox::tests::test_internal_sandbox_exec_dev_null_and_dns
    harness::sandbox::tests::test_internal_sandbox_cross_directory_rename
    Failed to exec shell in sandbox: Permission denied (os error 13)

apply_landlock_linux() allow-lists FHS paths only, and Landlock matches
inodes rather than symlinked views, so nothing under /nix/store can be
executed once the ruleset is applied; /bin/sh here is a store path. The
build sandbox also drops the /usr, /lib, /run and /var rules, since those
paths do not exist there, and has no /etc/resolv.conf without network, so
neither test can pass however the package is written. 342 of 344 tests run,
all green.

The same denial applies at runtime: every shell tool call goes through
marmel --internal-sandbox-exec and fails on NixOS. Tracked as
nix-overlay-5ml. Upstream main still carries the FHS-only list.
2026-10-06 22:31:40 +03:00

94 lines
3.7 KiB
Nix

{
lib,
rustPlatform,
fetchFromGitHub,
cacert,
}:
rustPlatform.buildRustPackage rec {
pname = "marmel";
# Upstream publishes no git tags, so this is pinned to the 1.0.0 release
# commit ("1.0.0 (#6)").
version = "1.0.0";
src = fetchFromGitHub {
owner = "Na1w";
repo = "marmel";
rev = "d6627d7cf3bf509d1e6db0d9d78736116e92e82a";
hash = "sha256-UlrSp/n3og0GAQXzISsB24OfK3qOUPE7jYOkEbZ2neI=";
};
cargoHash = "sha256-etqW3xcxkiNfkiPxl/Emt5pQCkNnoIhHFkX0Zqfs4rc=";
nativeCheckInputs = [ cacert ];
# The test suite builds `reqwest::Client`s, and rustls rejects construction
# outright when no system trust store is found ("No CA certificates were
# loaded from the system"). The sandbox has no /etc/ssl, so point the tests
# at nixpkgs' bundle. Build-time only; the installed binary still uses the
# host's trust store at runtime.
preCheck = ''
export SSL_CERT_FILE=${cacert}/etc/ssl/certs/ca-bundle.crt
'';
# Serialise the test harness. The lib suite shares process-global worker
# registries and steer/abort buses (src/orchestrator/workers.rs,
# src/orchestrator/bus.rs, src/orchestrator/preemption.rs), so the
# manager-loop tests fail nondeterministically when the harness runs them on
# parallel threads: rebuilding one unchanged derivation yielded 3 failures,
# then 1 failure, then 0 with serial threads. Drop this flag once upstream
# makes that state per-instance.
#
# The two sandbox-exec tests are skipped. They re-exec `sh` through
# `marmel --internal-sandbox-exec`, and apply_landlock_linux() allow-lists
# FHS paths only (/usr, /bin, /lib, /opt, /etc, /var) plus /tmp. Landlock
# matches inodes rather than symlinked views, and every binary on NixOS
# resolves into the store (`/bin/sh` is
# /nix/store/<hash>-bash-interactive-5.3p9/bin/bash), so the exec is denied:
# "Failed to exec shell in sandbox: Permission denied (os error 13)". Checked
# against this build on a NixOS host, where the same command succeeds once
# the workspace root is `/` and therefore covers /nix/store. Inside the build
# sandbox the tests are doubly impossible: /usr, /lib, /run and /var do not
# exist, so the `if let Ok(fd)` guards silently drop those rules, and
# /etc/resolv.conf is absent because the sandbox has no network. 342 of 344
# tests still run. Upstream main still carries the FHS-only list; drop these
# skips if that ever gains /nix/store.
cargoTestFlags = [
"--"
"--test-threads=1"
"--skip"
"harness::sandbox::tests::test_internal_sandbox_exec_dev_null_and_dns"
"--skip"
"harness::sandbox::tests::test_internal_sandbox_cross_directory_rename"
];
# Role prompts are embedded with `include_str!`, so the binary needs no
# runtime data files. The annotated example configs are the de-facto
# first-run documentation, since a backend URL and model are mandatory.
postInstall = ''
install -Dm644 marmel.toml.example $out/share/doc/${pname}/examples/marmel.toml.example
install -Dm644 marmel.toml.cloud $out/share/doc/${pname}/examples/marmel.toml.cloud
'';
passthru = {
category = "AI Coding Agents";
updateScript = [
"nix-update"
"--flake"
".#marmel"
"--version=branch=main"
];
};
meta = {
description = "Autonomous agentic coding assistant with Manager + specialist subagent orchestration over any OpenAI-compatible LLM backend";
homepage = "https://github.com/Na1w/marmel";
# Upstream README states MIT, but the repository ships no LICENSE file and
# Cargo.toml has no license field.
license = lib.licenses.mit;
sourceProvenance = with lib.sourceTypes; [ fromSource ];
mainProgram = "marmel";
platforms = lib.platforms.unix;
};
}