From 9dfe94b8fc0a127a6ae8903f631fb6c156f06229 Mon Sep 17 00:00:00 2001 From: Nikhil Unni Date: Wed, 7 Oct 2026 20:23:43 -0700 Subject: [PATCH] fix(nix): the dev shell disables fortify hardening so jemalloc configures The cc-wrapper's fortify hardening adds -D_FORTIFY_SOURCE to every C compile. Debug builds compile C at -O0, so glibc emits "_FORTIFY_SOURCE requires compiling with optimization". jemalloc's configure probes use -Werror, so each probe fails and configure stops with "cannot determine return type of strerror_r". A native Linux `cargo build` of engram-host-agent inside `nix develop` failed every time. musl does not emit the warning, so the musl cross targets were not affected. The dev shell only makes development builds; CI and the images do not build inside it. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01UHxL6gj4o8EvxYpgtwEWaM --- flake.nix | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/flake.nix b/flake.nix index 964e7fe35..03eb2bfff 100644 --- a/flake.nix +++ b/flake.nix @@ -96,6 +96,15 @@ LIBCLANG_PATH = "${pkgs.llvmPackages.libclang.lib}/lib"; }; + # The cc-wrapper's fortify hardening adds -D_FORTIFY_SOURCE to every + # C compile. Debug builds compile C at -O0, so glibc then emits + # "_FORTIFY_SOURCE requires compiling with optimization". jemalloc's + # configure probes compile with -Werror, so every probe fails and + # configure stops ("cannot determine return type of strerror_r"). + # This shell only makes development builds; release images are + # built outside it. + hardeningDisable = [ "fortify" ]; + shellHook = '' # Insulate cargo from the host's rustup installation. #