From 769a075d52a637f5119089e45420a6dbffabe75d Mon Sep 17 00:00:00 2001 From: Thierry Delafontaine Date: Sat, 8 Aug 2026 10:12:43 +0000 Subject: [PATCH 1/3] opencode{,-desktop}: 1.18.13 -> 1.18.16 https://github.com/anomalyco/opencode/releases/tag/v1.18.16 https://github.com/anomalyco/opencode/releases/tag/v1.18.15 https://github.com/anomalyco/opencode/releases/tag/v1.18.14 --- pkgs/by-name/op/opencode/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/op/opencode/package.nix b/pkgs/by-name/op/opencode/package.nix index bd6ee5800f8f..7dd8b36be663 100644 --- a/pkgs/by-name/op/opencode/package.nix +++ b/pkgs/by-name/op/opencode/package.nix @@ -16,7 +16,7 @@ stdenvNoCC.mkDerivation (finalAttrs: { pname = "opencode"; - version = "1.18.13"; + version = "1.18.16"; __structuredAttrs = true; strictDeps = true; @@ -25,7 +25,7 @@ stdenvNoCC.mkDerivation (finalAttrs: { owner = "anomalyco"; repo = "opencode"; tag = "v${finalAttrs.version}"; - hash = "sha256-xjzxTsMN4dMax3rL+2+4og0E7LovwYFvpU7Ea2sh6tM="; + hash = "sha256-AP2W443Zk/X8j6BWfMgAEbR4BQiJgnPpr1OG6JWIprE="; }; node_modules = stdenvNoCC.mkDerivation { @@ -85,7 +85,7 @@ stdenvNoCC.mkDerivation (finalAttrs: { # NOTE: Required else we get errors that our fixed-output derivation references store paths dontFixup = true; - outputHash = "sha256-gb1vgLGiK56A9Xtg71d2J9ct8TJAjDg1A7cOUx0v3cA="; + outputHash = "sha256-GBLs3nXtfSeXb4jXxSNM8ElMa/e/EB4sZn3c2inHnco="; outputHashAlgo = "sha256"; outputHashMode = "recursive"; }; From a79533a592b202694dedaa5cfdd218f1f0303e61 Mon Sep 17 00:00:00 2001 From: Thierry Delafontaine Date: Sat, 8 Aug 2026 13:02:47 +0200 Subject: [PATCH 2/3] opencode: resign the darwin binary Resolves #550300 --- pkgs/by-name/op/opencode/package.nix | 49 +++++++++++++++++++--------- 1 file changed, 34 insertions(+), 15 deletions(-) diff --git a/pkgs/by-name/op/opencode/package.nix b/pkgs/by-name/op/opencode/package.nix index 7dd8b36be663..374e8df72507 100644 --- a/pkgs/by-name/op/opencode/package.nix +++ b/pkgs/by-name/op/opencode/package.nix @@ -1,7 +1,8 @@ { lib, - stdenvNoCC, + stdenv, bun, + darwin, fetchFromGitHub, makeBinaryWrapper, models-dev, @@ -14,7 +15,7 @@ writableTmpDirAsHomeHook, }: -stdenvNoCC.mkDerivation (finalAttrs: { +stdenv.mkDerivation (finalAttrs: { pname = "opencode"; version = "1.18.16"; @@ -28,7 +29,7 @@ stdenvNoCC.mkDerivation (finalAttrs: { hash = "sha256-AP2W443Zk/X8j6BWfMgAEbR4BQiJgnPpr1OG6JWIprE="; }; - node_modules = stdenvNoCC.mkDerivation { + node_modules = stdenv.mkDerivation { pname = "${finalAttrs.pname}-node_modules"; inherit (finalAttrs) version src; @@ -96,14 +97,26 @@ stdenvNoCC.mkDerivation (finalAttrs: { installShellFiles makeBinaryWrapper writableTmpDirAsHomeHook + ] + ++ lib.optionals stdenv.hostPlatform.isDarwin [ + darwin.sigtool ]; - postPatch = '' - # NOTE: Relax Bun version check to be a warning instead of an error - substituteInPlace packages/script/src/index.ts \ - --replace-fail 'throw new Error(`This script requires bun@''${expectedBunVersionRange}' \ - 'console.warn(`Warning: This script requires bun@''${expectedBunVersionRange}' - ''; + postPatch = + # Relax Bun version check to be a warning instead of an error + '' + substituteInPlace packages/script/src/index.ts \ + --replace-fail \ + 'throw new Error(`This script requires bun@''${expectedBunVersionRange}' \ + 'console.warn(`Warning: This script requires bun@''${expectedBunVersionRange}' + '' + # Skip smoke test + + '' + substituteInPlace packages/opencode/script/build.ts \ + --replace-fail \ + 'if (item.os === process.platform && item.arch === process.arch && !item.abi)' \ + 'if (false)' + ''; configurePhase = '' runHook preConfigure @@ -143,7 +156,7 @@ stdenvNoCC.mkDerivation (finalAttrs: { [ ripgrep ] - ++ lib.optionals stdenvNoCC.hostPlatform.isDarwin [ + ++ lib.optionals stdenv.hostPlatform.isDarwin [ sysctl ] ) @@ -158,11 +171,17 @@ stdenvNoCC.mkDerivation (finalAttrs: { runHook postInstall ''; - postInstall = lib.optionalString (stdenvNoCC.buildPlatform.canExecute stdenvNoCC.hostPlatform) '' - installShellCompletion --cmd opencode \ - --bash <($out/bin/opencode completion) \ - --zsh <(SHELL=/bin/zsh $out/bin/opencode completion) - ''; + postInstall = + lib.optionalString stdenv.hostPlatform.isDarwin '' + codesign --force --sign - $out/bin/.opencode-wrapped + '' + + lib.optionalString (stdenv.buildPlatform.canExecute stdenv.hostPlatform) '' + installShellCompletion --cmd opencode \ + --bash <($out/bin/opencode completion) \ + --zsh <(SHELL=/bin/zsh $out/bin/opencode completion) + ''; + + dontStrip = true; nativeInstallCheckInputs = [ versionCheckHook From da99d514c7ba67b606410836d2563c1be683c464 Mon Sep 17 00:00:00 2001 From: Thierry Delafontaine Date: Tue, 11 Aug 2026 10:28:03 +0200 Subject: [PATCH 3/3] opencode: restructure derivation --- pkgs/by-name/op/opencode/package.nix | 151 ++++++++++++++------------- 1 file changed, 77 insertions(+), 74 deletions(-) diff --git a/pkgs/by-name/op/opencode/package.nix b/pkgs/by-name/op/opencode/package.nix index 374e8df72507..55967add1ab0 100644 --- a/pkgs/by-name/op/opencode/package.nix +++ b/pkgs/by-name/op/opencode/package.nix @@ -14,7 +14,71 @@ versionCheckHook, writableTmpDirAsHomeHook, }: +let + node_modules = + finalAttrs: + stdenv.mkDerivation { + pname = "${finalAttrs.pname}-node_modules"; + inherit (finalAttrs) version src; + impureEnvVars = lib.fetchers.proxyImpureEnvVars ++ [ + "GIT_PROXY_COMMAND" + "SOCKS_SERVER" + ]; + + nativeBuildInputs = [ + bun + writableTmpDirAsHomeHook + ]; + + dontConfigure = true; + + buildPhase = '' + runHook preBuild + + export BUN_INSTALL_CACHE_DIR=$(mktemp -d) + bun install \ + --cpu="*" \ + --frozen-lockfile \ + --filter ./ \ + --filter ./packages/app \ + --filter ./packages/desktop \ + --filter ./packages/opencode \ + --filter ./packages/shared \ + --ignore-scripts \ + --no-progress \ + --os="*" + + bun --bun ./nix/scripts/canonicalize-node-modules.ts + bun --bun ./nix/scripts/normalize-bun-binaries.ts + + runHook postBuild + ''; + + installPhase = '' + runHook preInstall + + mkdir -p $out + find . -type d -name node_modules -exec cp -R --parents {} $out \; + + # opencode targets only Linux and Darwin (see meta.platforms), so the + # Windows executables that "bun install --os=*" fetches are never + # executed. Dropping them keeps the output reproducible on hosts whose + # security endpoint agents scan the store, and removes the vulnerable + # bundled 7za.exe that will be quarantined. + find $out -type f -name '*.exe' -delete + + runHook postInstall + ''; + + # NOTE: Required else we get errors that our fixed-output derivation references store paths + dontFixup = true; + + outputHash = "sha256-GBLs3nXtfSeXb4jXxSNM8ElMa/e/EB4sZn3c2inHnco="; + outputHashAlgo = "sha256"; + outputHashMode = "recursive"; + }; +in stdenv.mkDerivation (finalAttrs: { pname = "opencode"; version = "1.18.16"; @@ -29,79 +93,6 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-AP2W443Zk/X8j6BWfMgAEbR4BQiJgnPpr1OG6JWIprE="; }; - node_modules = stdenv.mkDerivation { - pname = "${finalAttrs.pname}-node_modules"; - inherit (finalAttrs) version src; - - impureEnvVars = lib.fetchers.proxyImpureEnvVars ++ [ - "GIT_PROXY_COMMAND" - "SOCKS_SERVER" - ]; - - nativeBuildInputs = [ - bun - writableTmpDirAsHomeHook - ]; - - dontConfigure = true; - - buildPhase = '' - runHook preBuild - - export BUN_INSTALL_CACHE_DIR=$(mktemp -d) - bun install \ - --cpu="*" \ - --frozen-lockfile \ - --filter ./ \ - --filter ./packages/app \ - --filter ./packages/desktop \ - --filter ./packages/opencode \ - --filter ./packages/shared \ - --ignore-scripts \ - --no-progress \ - --os="*" - - bun --bun ./nix/scripts/canonicalize-node-modules.ts - bun --bun ./nix/scripts/normalize-bun-binaries.ts - - runHook postBuild - ''; - - installPhase = '' - runHook preInstall - - mkdir -p $out - find . -type d -name node_modules -exec cp -R --parents {} $out \; - - # opencode targets only Linux and Darwin (see meta.platforms), so the - # Windows executables that "bun install --os=*" fetches are never - # executed. Dropping them keeps the output reproducible on hosts whose - # security endpoint agents scan the store, and removes the vulnerable - # bundled 7za.exe that will be quarantined. - find $out -type f -name '*.exe' -delete - - runHook postInstall - ''; - - # NOTE: Required else we get errors that our fixed-output derivation references store paths - dontFixup = true; - - outputHash = "sha256-GBLs3nXtfSeXb4jXxSNM8ElMa/e/EB4sZn3c2inHnco="; - outputHashAlgo = "sha256"; - outputHashMode = "recursive"; - }; - - nativeBuildInputs = [ - bun - nodejs - installShellFiles - makeBinaryWrapper - writableTmpDirAsHomeHook - ] - ++ lib.optionals stdenv.hostPlatform.isDarwin [ - darwin.sigtool - ]; - postPatch = # Relax Bun version check to be a warning instead of an error '' @@ -118,10 +109,21 @@ stdenv.mkDerivation (finalAttrs: { 'if (false)' ''; + nativeBuildInputs = [ + bun + nodejs + installShellFiles + makeBinaryWrapper + writableTmpDirAsHomeHook + ] + ++ lib.optionals stdenv.hostPlatform.isDarwin [ + darwin.sigtool + ]; + configurePhase = '' runHook preConfigure - cp -R ${finalAttrs.node_modules}/. . + cp -R ${finalAttrs.passthru.node_modules}/. . patchShebangs node_modules patchShebangs packages/*/node_modules @@ -200,6 +202,7 @@ stdenv.mkDerivation (finalAttrs: { theme = "${finalAttrs.finalPackage}/share/theme.json"; tui = "${finalAttrs.finalPackage}/share/tui.json"; }; + node_modules = node_modules finalAttrs; updateScript = nix-update-script { extraArgs = [ "--subpackage"