c08c444a39
CI / check (push) Has been cancelled
The lib suite failed in the Nix sandbox:
harness::sandbox::tests::test_internal_sandbox_exec_dev_null_and_dns
harness::sandbox::tests::test_internal_sandbox_cross_directory_rename
Failed to exec shell in sandbox: Permission denied (os error 13)
apply_landlock_linux() allow-lists FHS paths only, and Landlock matches
inodes rather than symlinked views, so nothing under /nix/store can be
executed once the ruleset is applied; /bin/sh here is a store path. The
build sandbox also drops the /usr, /lib, /run and /var rules, since those
paths do not exist there, and has no /etc/resolv.conf without network, so
neither test can pass however the package is written. 342 of 344 tests run,
all green.
The same denial applies at runtime: every shell tool call goes through
marmel --internal-sandbox-exec and fails on NixOS. Tracked as
nix-overlay-5ml. Upstream main still carries the FHS-only list.
94 lines
3.7 KiB
Nix
94 lines
3.7 KiB
Nix
{
|
|
lib,
|
|
rustPlatform,
|
|
fetchFromGitHub,
|
|
cacert,
|
|
}:
|
|
|
|
rustPlatform.buildRustPackage rec {
|
|
pname = "marmel";
|
|
# Upstream publishes no git tags, so this is pinned to the 1.0.0 release
|
|
# commit ("1.0.0 (#6)").
|
|
version = "1.0.0";
|
|
|
|
src = fetchFromGitHub {
|
|
owner = "Na1w";
|
|
repo = "marmel";
|
|
rev = "d6627d7cf3bf509d1e6db0d9d78736116e92e82a";
|
|
hash = "sha256-UlrSp/n3og0GAQXzISsB24OfK3qOUPE7jYOkEbZ2neI=";
|
|
};
|
|
|
|
cargoHash = "sha256-etqW3xcxkiNfkiPxl/Emt5pQCkNnoIhHFkX0Zqfs4rc=";
|
|
|
|
nativeCheckInputs = [ cacert ];
|
|
|
|
# The test suite builds `reqwest::Client`s, and rustls rejects construction
|
|
# outright when no system trust store is found ("No CA certificates were
|
|
# loaded from the system"). The sandbox has no /etc/ssl, so point the tests
|
|
# at nixpkgs' bundle. Build-time only; the installed binary still uses the
|
|
# host's trust store at runtime.
|
|
preCheck = ''
|
|
export SSL_CERT_FILE=${cacert}/etc/ssl/certs/ca-bundle.crt
|
|
'';
|
|
|
|
# Serialise the test harness. The lib suite shares process-global worker
|
|
# registries and steer/abort buses (src/orchestrator/workers.rs,
|
|
# src/orchestrator/bus.rs, src/orchestrator/preemption.rs), so the
|
|
# manager-loop tests fail nondeterministically when the harness runs them on
|
|
# parallel threads: rebuilding one unchanged derivation yielded 3 failures,
|
|
# then 1 failure, then 0 with serial threads. Drop this flag once upstream
|
|
# makes that state per-instance.
|
|
#
|
|
# The two sandbox-exec tests are skipped. They re-exec `sh` through
|
|
# `marmel --internal-sandbox-exec`, and apply_landlock_linux() allow-lists
|
|
# FHS paths only (/usr, /bin, /lib, /opt, /etc, /var) plus /tmp. Landlock
|
|
# matches inodes rather than symlinked views, and every binary on NixOS
|
|
# resolves into the store (`/bin/sh` is
|
|
# /nix/store/<hash>-bash-interactive-5.3p9/bin/bash), so the exec is denied:
|
|
# "Failed to exec shell in sandbox: Permission denied (os error 13)". Checked
|
|
# against this build on a NixOS host, where the same command succeeds once
|
|
# the workspace root is `/` and therefore covers /nix/store. Inside the build
|
|
# sandbox the tests are doubly impossible: /usr, /lib, /run and /var do not
|
|
# exist, so the `if let Ok(fd)` guards silently drop those rules, and
|
|
# /etc/resolv.conf is absent because the sandbox has no network. 342 of 344
|
|
# tests still run. Upstream main still carries the FHS-only list; drop these
|
|
# skips if that ever gains /nix/store.
|
|
cargoTestFlags = [
|
|
"--"
|
|
"--test-threads=1"
|
|
"--skip"
|
|
"harness::sandbox::tests::test_internal_sandbox_exec_dev_null_and_dns"
|
|
"--skip"
|
|
"harness::sandbox::tests::test_internal_sandbox_cross_directory_rename"
|
|
];
|
|
|
|
# Role prompts are embedded with `include_str!`, so the binary needs no
|
|
# runtime data files. The annotated example configs are the de-facto
|
|
# first-run documentation, since a backend URL and model are mandatory.
|
|
postInstall = ''
|
|
install -Dm644 marmel.toml.example $out/share/doc/${pname}/examples/marmel.toml.example
|
|
install -Dm644 marmel.toml.cloud $out/share/doc/${pname}/examples/marmel.toml.cloud
|
|
'';
|
|
|
|
passthru = {
|
|
category = "AI Coding Agents";
|
|
updateScript = [
|
|
"nix-update"
|
|
"--flake"
|
|
".#marmel"
|
|
"--version=branch=main"
|
|
];
|
|
};
|
|
|
|
meta = {
|
|
description = "Autonomous agentic coding assistant with Manager + specialist subagent orchestration over any OpenAI-compatible LLM backend";
|
|
homepage = "https://github.com/Na1w/marmel";
|
|
# Upstream README states MIT, but the repository ships no LICENSE file and
|
|
# Cargo.toml has no license field.
|
|
license = lib.licenses.mit;
|
|
sourceProvenance = with lib.sourceTypes; [ fromSource ];
|
|
mainProgram = "marmel";
|
|
platforms = lib.platforms.unix;
|
|
};
|
|
}
|