diff --git a/modules/home/package-sets/ai.nix b/modules/home/package-sets/ai.nix index 4bf385a..22b546e 100644 --- a/modules/home/package-sets/ai.nix +++ b/modules/home/package-sets/ai.nix @@ -12,7 +12,7 @@ in home.packages = [ inputs.ngp-nur.packages.${system}.opencode-v2 inputs.claude-code.packages.${system}.claude-code - (import ../../../overlays/codex.nix { pkgs = unstable; }) + unstable.codex hunkPackages.hunk ]; } diff --git a/overlays/codex.nix b/overlays/codex.nix index 244bad5..9108b10 100644 --- a/overlays/codex.nix +++ b/overlays/codex.nix @@ -2,22 +2,53 @@ pkgs, codex ? pkgs.codex, }: +let + v8Version = "150.4.0"; + v8Target = pkgs.stdenv.hostPlatform.rust.rustcTarget; + v8Release = "https://github.com/openai/codex/releases/download/rusty-v8-v${v8Version}"; + v8Archive = pkgs.fetchurl { + url = "${v8Release}/librusty_v8_ptrcomp_sandbox_release_${v8Target}.a.gz"; + hash = + { + x86_64-linux = "sha256-o1x10fJuapg4haRbM0kKTr5U8FBQVosyuJz7QhswtYM="; + aarch64-linux = "sha256-0VF+7UBUaFNwKbAF1f6ZfsdNXI01H5FrOm3yC30oEbo="; + x86_64-darwin = "sha256-4Nm7ZOizoDTCkwyDly8/NXYCERSDQvoEB7OCUO8zCFY="; + aarch64-darwin = "sha256-AK27SHmISMd1UEQcaGc6XoUpuOG3PqvN7iMss5tA9KE="; + } + .${pkgs.stdenv.hostPlatform.system}; + }; + v8Binding = pkgs.fetchurl { + url = "${v8Release}/src_binding_ptrcomp_sandbox_release_${v8Target}.rs"; + hash = + { + x86_64-linux = "sha256-dyeCauR5vbZF6Acjn7EtH44uI956bPFvXuWSaQ0dhQY="; + aarch64-linux = "sha256-dyeCauR5vbZF6Acjn7EtH44uI956bPFvXuWSaQ0dhQY="; + x86_64-darwin = "sha256-ylrfDPicmnCtRgrnNkiy/om3SqETs8t/dXtqArdYOU8="; + aarch64-darwin = "sha256-ylrfDPicmnCtRgrnNkiy/om3SqETs8t/dXtqArdYOU8="; + } + .${pkgs.stdenv.hostPlatform.system}; + }; +in codex.overrideAttrs ( finalAttrs: prevAttrs: { - version = "0.146.1"; + version = "0.147.0"; src = pkgs.fetchFromGitHub { owner = "openai"; repo = "codex"; tag = "rust-v${finalAttrs.version}"; - hash = "sha256-aXK/hUz61STkD8xcVqvBzP1RYDu+kw7v1ufVZHyzN84="; + hash = "sha256-NKeOxp9vLcx7tpghqhpS3ocPqUDP2PircNwkJNpHBPo="; }; cargoDeps = pkgs.rustPlatform.fetchCargoVendor { inherit (finalAttrs) src; sourceRoot = "${finalAttrs.src.name}/codex-rs"; - hash = "sha256-N9jbH/cgAyu2QxneSnpkdaF0MgV3ZtDmN9q6rr9u+hE="; + hash = "sha256-MJuM2QLxvL+r/Gw8QXLjtsLS25QGVCqcqU5GJssSoQ4="; }; env = prevAttrs.env + // { + RUSTY_V8_ARCHIVE = v8Archive; + RUSTY_V8_SRC_BINDING_PATH = v8Binding; + } // pkgs.lib.optionalAttrs pkgs.stdenv.hostPlatform.isDarwin { # Keep the aarch64-darwin text segment within ld64's +/-128MB branch range. CARGO_PROFILE_RELEASE_OPT_LEVEL = "s"; diff --git a/overlays/lmstudio.nix b/overlays/lmstudio.nix index 091ee9d..563c9d2 100644 --- a/overlays/lmstudio.nix +++ b/overlays/lmstudio.nix @@ -2,7 +2,7 @@ lib, appimageTools, fetchurl, - lmstudioVersion ? "0.4.20-1", + lmstudioVersion ? "0.4.21-2", }: let pname = "lmstudio"; @@ -10,7 +10,7 @@ let src = fetchurl { url = "https://installers.lmstudio.ai/linux/x64/${version}/LM-Studio-${version}-x64.AppImage"; - hash = "sha256-bhyeeXOuiS7vk01wZhLJIMBLJBZYYRCNWIMliAHGSu0="; + hash = "sha256-EBQ3bYnWaMOBTNIOKxRqB2FGdg3tHvB7lo+2HFje01U="; }; appimageContents = appimageTools.extractType2 { inherit pname version src; }; diff --git a/overlays/nixery.nix b/overlays/nixery.nix index dbe0e51..8d7d0b0 100644 --- a/overlays/nixery.nix +++ b/overlays/nixery.nix @@ -1,12 +1,12 @@ final: prev: let - rev = "d020e8bdff866f6102bc319d6d55a1c59bce72fd"; + rev = "324aebb6550ab78c2bbe6e36ec50acf9c020a844"; src = prev.fetchgit { url = "https://code.tvl.fyi/depot.git:/tools/nixery.git"; inherit rev; - hash = "sha256-Wog0rbERDMNm6kcWHZm2H8uZsr1eUcCgSljbiStvJpE="; + hash = "sha256-5BiKdN5VRxQEvHopG+aMDD5FW1Q0UouPabFjBsMe1gQ="; }; depotStub = { diff --git a/overlays/scripts/update-codex-overlay b/overlays/scripts/update-codex-overlay index 53868af..28f4947 100755 --- a/overlays/scripts/update-codex-overlay +++ b/overlays/scripts/update-codex-overlay @@ -15,6 +15,7 @@ require sort name=codex file=overlays/codex.nix current="$(sed -nE 's/^[[:space:]]*version = "([^"]+)";/\1/p' "$file")" +current_v8="$(sed -nE 's/^[[:space:]]*v8Version = "([^"]+)";/\1/p' "$file")" latest="$(github_latest_stable_version openai codex rust-v)" if [[ -z "$latest" ]]; then @@ -33,9 +34,38 @@ if [[ "$mode" == check ]]; then exit 1 fi +mapfile -t old_archive_hashes < <(sed -nE 's/^[[:space:]]*(x86_64-linux|aarch64-linux|x86_64-darwin|aarch64-darwin) = "([^"]+)";/\2/p' "$file" | sed -n '1,4p') +mapfile -t old_binding_hashes < <(sed -nE 's/^[[:space:]]*(x86_64-linux|aarch64-linux|x86_64-darwin|aarch64-darwin) = "([^"]+)";/\2/p' "$file" | sed -n '5,8p') old_src_hash="$(sed -nE 's/^[[:space:]]*hash = "([^"]+)";/\1/p' "$file" | sed -n '1p')" old_cargo_hash="$(sed -nE 's/^[[:space:]]*hash = "([^"]+)";/\1/p' "$file" | sed -n '2p')" new_src_hash="$(prefetch_url_hash "https://github.com/openai/codex/archive/refs/tags/rust-v$latest.tar.gz" true)" +new_v8="$( + curl -fsSL "https://raw.githubusercontent.com/openai/codex/rust-v$latest/codex-rs/Cargo.lock" \ + | awk '$0 == "name = \"v8\"" { found = 1; next } found && /^version = / { gsub(/[\" ]/, "", $3); print $3; exit }' +)" + +if [[ -z "$new_v8" ]]; then + echo "$name: could not determine the rusty_v8 version" >&2 + exit 1 +fi + +v8_assets="$(curl -fsSL "https://api.github.com/repos/openai/codex/releases/tags/rusty-v8-v$new_v8")" +systems=(x86_64-linux aarch64-linux x86_64-darwin aarch64-darwin) +targets=(x86_64-unknown-linux-gnu aarch64-unknown-linux-gnu x86_64-apple-darwin aarch64-apple-darwin) +new_archive_hashes=() +new_binding_hashes=() +for target in "${targets[@]}"; do + archive="librusty_v8_ptrcomp_sandbox_release_${target}.a.gz" + binding="src_binding_ptrcomp_sandbox_release_${target}.rs" + archive_digest="$(jq -r --arg asset "$archive" '.assets[] | select(.name == $asset) | .digest' <<<"$v8_assets")" + binding_digest="$(jq -r --arg asset "$binding" '.assets[] | select(.name == $asset) | .digest' <<<"$v8_assets")" + if [[ -z "$archive_digest" || -z "$binding_digest" ]]; then + echo "$name: missing rusty_v8 assets for $target" >&2 + exit 1 + fi + new_archive_hashes+=("$(nix hash convert --hash-algo sha256 --to sri "${archive_digest#sha256:}")") + new_binding_hashes+=("$(nix hash convert --hash-algo sha256 --to sri "${binding_digest#sha256:}")") +done expr=$(cat <