# Copyright 2025-2026 Gentoo Authors # Distributed under the terms of the GNU General Public License v2 EAPI=8 # NOTE: This package uses a pre-built crate tarball instead of listing individual # crates in CRATES="". This approach is required because: # 1. Codex has 800+ crate dependencies, which triggers Portage QA warnings: # "QA Notice: This package uses a very large number of CRATES. Please provide # a crate tarball instead and fetch it via SRC_URI." # 2. Stricter ebuild QA checks (e.g., in CI pipelines) fail with too many crates. # # The crate tarball is auto-generated by GitHub Actions at: # https://github.com/gentoo-zh-drafts/codex/ # Workflow source code for auditing: # https://github.com/gentoo-zh-drafts/codex/blob/crate-dist/.github/workflows/crates.yml # This allows anyone to review and verify the crate packaging process. CRATES=" " declare -A GIT_CRATES=( [appcontainer_common]='https://github.com/microsoft/mxc;6cd3d58f05d3447e67109cfb75e042803b843ca4;mxc-%commit%/src/backends/appcontainer/common' [crossterm]='https://github.com/openai-oss-forks/crossterm;efa177859fd9623d57b9fe7ae9bf491ae1ac6ec4;crossterm-%commit%' [h3]='https://github.com/hyperium/h3;e07e69412876f7e26f026bd75a48b2704d8c8283;h3-%commit%/h3' [h3-quinn]='https://github.com/hyperium/h3;e07e69412876f7e26f026bd75a48b2704d8c8283;h3-%commit%/h3-quinn' [learning_mode_windows]='https://github.com/microsoft/mxc;6cd3d58f05d3447e67109cfb75e042803b843ca4;mxc-%commit%/src/backends/learning_mode/windows' [nucleo-matcher]='https://github.com/helix-editor/nucleo;4253de9faabb4e5c6d81d946a5e35a90f87347ee;nucleo-%commit%/matcher' [nucleo]='https://github.com/helix-editor/nucleo;4253de9faabb4e5c6d81d946a5e35a90f87347ee;nucleo-%commit%' [runfiles]='https://github.com/dzbarsky/rules_rust;b56cbaa8465e74127f1ea216f813cd377295ad81;rules_rust-%commit%/rust/runfiles' [tokio-tungstenite]='https://github.com/openai-oss-forks/tokio-tungstenite;0e5b2d73aa18dd9f0a50ee9ff199d5aef7594186;tokio-tungstenite-%commit%' [tungstenite]='https://github.com/openai-oss-forks/tungstenite-rs;4fffad30fe373adbdcffab9545e9e9bf4f2fc19f;tungstenite-rs-%commit%' [wxc_common]='https://github.com/microsoft/mxc;6cd3d58f05d3447e67109cfb75e042803b843ca4;mxc-%commit%/src/core/wxc_common' ) RUST_MIN_VER="1.95.0" # python3 .github/scripts/rusty_v8_bazel.py resolved-v8-crate-version RUSTY_V8_TAG="150.4.0" inherit cargo check-reqs toolchain-funcs CHECKREQS_MEMORY="15G" CHECKREQS_DISK_BUILD="20G" DESCRIPTION="Codex CLI - OpenAI's AI-powered coding agent" HOMEPAGE="https://github.com/openai/codex" # The crate tarball URL uses ${PV} so it auto-updates when bumping versions. # This tarball is generated by: https://github.com/gentoo-zh-drafts/codex/ # See .github/workflows/crates.yml for the generation process. SRC_URI=" https://github.com/openai/${PN}/archive/rust-v${PV}.tar.gz -> ${P}.tar.gz https://github.com/gentoo-zh-drafts/codex/releases/download/rust-v${PV}/codex-rust-v${PV}-crates.tar.xz amd64? ( https://github.com/openai/codex/releases/download/rusty-v8-v${RUSTY_V8_TAG}/librusty_v8_release_x86_64-unknown-linux-musl.a.gz -> rusty_v8_${RUSTY_V8_TAG}_librusty_v8_release_x86_64-unknown-linux-musl.a.gz https://github.com/openai/codex/releases/download/rusty-v8-v${RUSTY_V8_TAG}/src_binding_release_x86_64-unknown-linux-musl.rs -> rusty_v8_${RUSTY_V8_TAG}_src_binding_release_x86_64-unknown-linux-musl.rs ) arm64? ( https://github.com/openai/codex/releases/download/rusty-v8-v${RUSTY_V8_TAG}/librusty_v8_release_aarch64-unknown-linux-musl.a.gz -> rusty_v8_${RUSTY_V8_TAG}_librusty_v8_release_aarch64-unknown-linux-musl.a.gz https://github.com/openai/codex/releases/download/rusty-v8-v${RUSTY_V8_TAG}/src_binding_release_aarch64-unknown-linux-musl.rs -> rusty_v8_${RUSTY_V8_TAG}_src_binding_release_aarch64-unknown-linux-musl.rs ) ${CARGO_CRATE_URIS} " S="${WORKDIR}/${PN}-rust-v${PV}/codex-rs" PATCHES=( "${FILESDIR}/${PN}-0.156.0-recursion-limit.patch" "${FILESDIR}/${PN}-0.157.1-btrfs-socket-mounts.patch" ) LICENSE="Apache-2.0" # Dependent crate licenses LICENSE+=" Apache-2.0 Apache-2.0-with-LLVM-exceptions BSD-2 BSD Boost-1.0 CC0-1.0 CDLA-Permissive-2.0 ISC MIT MPL-2.0 Unicode-3.0 ZLIB " SLOT="0" KEYWORDS="~amd64 ~arm64" # Tests fail due to ring crate conflicts with system OpenSSL RESTRICT="test" DEPEND=" dev-libs/openssl:= sys-apps/dbus " RDEPEND="${DEPEND} >=sys-apps/bubblewrap-0.11.2 sys-apps/ripgrep !dev-util/codex-bin " BDEPEND="virtual/pkgconfig" # rust does not use *FLAGS from make.conf, silence portage warning QA_FLAGS_IGNORED="usr/libexec/${PN}/bin/*" pkg_pretend() { check-reqs_pkg_pretend } pkg_setup() { check-reqs_pkg_setup rust_pkg_setup if tc-is-lto; then export CARGO_PROFILE_RELEASE_LTO=thin else export CARGO_PROFILE_RELEASE_LTO=false fi } gen_git_crate_dir() { # https://github.com/gentoo/gentoo/blob/b09dd88412fe2d5eee5a8891e08bfa2d67848da3/eclass/cargo.eclass#L442 IFS=';' read -r crate_uri commit crate_dir <<<"${GIT_CRATES[$1]}" echo "${WORKDIR}/${crate_dir//%commit%/${commit}}" } src_prepare() { default # Fix tokio-tungstenite's git dependency on tungstenite sed -i '/^\[dependencies\.tungstenite\]/,/^$/{ s|git = "https://github.com/openai-oss-forks/tungstenite-rs"|path = "'"$(gen_git_crate_dir tungstenite)"'"| /^rev = /d }' "$(gen_git_crate_dir tokio-tungstenite)/Cargo.toml" || die # Remove the [patch.crates-io] section and add path-based patches sed -i '/^\[patch\.crates-io\]/,/^$/d' "${S}/Cargo.toml" || die sed -i '/^\[patch\."ssh:\/\/git@github\.com/,/^$/d' "${S}/Cargo.toml" || die # Add new patch section with local paths cat >> "${S}/Cargo.toml" <<-EOF || die [patch.crates-io] crossterm = { path = "$(gen_git_crate_dir crossterm)" } tokio-tungstenite = { path = "$(gen_git_crate_dir tokio-tungstenite)" } tungstenite = { path = "$(gen_git_crate_dir tungstenite)" } EOF } src_compile() { local rusty_v8_triple use amd64 && rusty_v8_triple=x86_64-unknown-linux-musl use arm64 && rusty_v8_triple=aarch64-unknown-linux-musl # codex-core trait resolution overflows rustc's default 8MiB stack export RUST_MIN_STACK=16777216 RUSTY_V8_ARCHIVE="${DISTDIR}/rusty_v8_${RUSTY_V8_TAG}_librusty_v8_release_${rusty_v8_triple}.a.gz" \ RUSTY_V8_SRC_BINDING_PATH="${DISTDIR}/rusty_v8_${RUSTY_V8_TAG}_src_binding_release_${rusty_v8_triple}.rs" \ cargo_src_compile \ --bin codex \ --bin codex-code-mode-host } src_install() { local package_dir="/usr/libexec/${PN}" local target use amd64 && target=x86_64-unknown-linux-gnu use arm64 && target=aarch64-unknown-linux-gnu use elibc_musl && target=${target%-gnu}-musl # The shared daemon requires the complete upstream package layout. Keep # system dependencies in Portage: executable wrappers survive the daemon's # package copy, which deliberately rejects symlinks outside the package. exeinto "${package_dir}/bin" doexe "$(cargo_target_dir)/codex" "$(cargo_target_dir)/codex-code-mode-host" dosym -r "${package_dir}/bin/codex" /usr/bin/codex dosym -r "${package_dir}/bin/codex-code-mode-host" /usr/bin/codex-code-mode-host printf '#!/bin/sh\nexec "%s/usr/bin/rg" "$@"\n' "${EPREFIX}" > "${T}/rg" || die exeinto "${package_dir}/codex-path" doexe "${T}/rg" printf '#!/bin/sh\nexec "%s/usr/bin/bwrap" "$@"\n' "${EPREFIX}" > "${T}/bwrap" || die exeinto "${package_dir}/codex-resources" doexe "${T}/bwrap" # Build metadata makes this a pinned local daemon package. Without it, # Codex silently auto-updates the daemon to an unpatched upstream binary. cat > "${T}/codex-package.json" <<-EOF || die { "layoutVersion": 1, "version": "${PV}+gentoo.${PR}", "target": "${target}", "variant": "codex", "entrypoint": "bin/codex" } EOF insinto "${package_dir}" doins "${T}/codex-package.json" einstalldocs } pkg_postinst() { elog "Codex uses a complete, locally patched runtime package." elog "After upgrading, refresh an existing daemon from this package with:" elog " codex app-server daemon update --from-cli --yes" elog "This restarts its running sessions; finish active work first." elog "Keep the previous tested overlay ebuild until its replacement passes" elog "daemon startup, sandbox execution and local-file editing checks." }