From 90e401e6e6aac7748706b7bed4678f320583a94a Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 17 Feb 2025 17:11:30 +0000 Subject: [PATCH 01/18] tomcat9: 9.0.98 -> 9.0.100 (cherry picked from commit 6dd52fd0866f53efe69acaf2ee87c1894f1e4277) --- pkgs/servers/http/tomcat/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/http/tomcat/default.nix b/pkgs/servers/http/tomcat/default.nix index 5645edcb8461..51642f07448c 100644 --- a/pkgs/servers/http/tomcat/default.nix +++ b/pkgs/servers/http/tomcat/default.nix @@ -60,8 +60,8 @@ let in { tomcat9 = common { - version = "9.0.98"; - hash = "sha256-HZoRBMLiNaW6/26cqOKL49hkgD+vxHj1wTwq5qXtPW8="; + version = "9.0.100"; + hash = "sha256-ElMVjEWjGoFotBQ2USrMIpLpSjRosb2OTQp6edzB9f8="; }; tomcat10 = common { From 24fe4a37d22ab1a8792cd5758e0f5c089cbc6d9c Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 15 Mar 2025 16:52:39 +0000 Subject: [PATCH 02/18] tomcat9: 9.0.100 -> 9.0.102 (cherry picked from commit 22a4dec340522facc00633f5707c9a9b61dc5d36) --- pkgs/servers/http/tomcat/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/http/tomcat/default.nix b/pkgs/servers/http/tomcat/default.nix index 51642f07448c..3330f87bb6d5 100644 --- a/pkgs/servers/http/tomcat/default.nix +++ b/pkgs/servers/http/tomcat/default.nix @@ -60,8 +60,8 @@ let in { tomcat9 = common { - version = "9.0.100"; - hash = "sha256-ElMVjEWjGoFotBQ2USrMIpLpSjRosb2OTQp6edzB9f8="; + version = "9.0.102"; + hash = "sha256-I+CjsW1ToSHIyGsOpOaWfRpKtonM9kkM4J6uV6w5R4c="; }; tomcat10 = common { From 90ebb92961f9b39f29236897b3d3dff2ff8ee6b9 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 15 Mar 2025 13:53:06 +0000 Subject: [PATCH 03/18] tomcat10: 10.1.34 -> 10.1.39 (cherry picked from commit baaf8e7cc8ad2062464d1864a0b2965385f25cd6) --- pkgs/servers/http/tomcat/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/http/tomcat/default.nix b/pkgs/servers/http/tomcat/default.nix index 3330f87bb6d5..8c8b59764984 100644 --- a/pkgs/servers/http/tomcat/default.nix +++ b/pkgs/servers/http/tomcat/default.nix @@ -65,8 +65,8 @@ in }; tomcat10 = common { - version = "10.1.34"; - hash = "sha256-95lUE4C//ytnTO/YbFN20tfVZrOi58RXnStJHejsbDY="; + version = "10.1.39"; + hash = "sha256-AM7ck/AzfNjJi9nCFppuYifVaNx7oLsaRHUrM7VPzuU="; }; tomcat11 = common { From 1ed1eff49d2f6f58db0e1a4d927bd2ad9dcf046f Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 16 Apr 2025 00:28:02 +0000 Subject: [PATCH 04/18] tomcat10: 10.1.39 -> 10.1.40 (cherry picked from commit 615bd295ad0038eb346f87a09c8f7557968ee436) --- pkgs/servers/http/tomcat/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/http/tomcat/default.nix b/pkgs/servers/http/tomcat/default.nix index 8c8b59764984..e791b34f8cd1 100644 --- a/pkgs/servers/http/tomcat/default.nix +++ b/pkgs/servers/http/tomcat/default.nix @@ -65,8 +65,8 @@ in }; tomcat10 = common { - version = "10.1.39"; - hash = "sha256-AM7ck/AzfNjJi9nCFppuYifVaNx7oLsaRHUrM7VPzuU="; + version = "10.1.40"; + hash = "sha256-JfHmB/F+4vqZ4ynuwjtjk6ueE5CSnGzcsx90lXa5TY4="; }; tomcat11 = common { From 5596ed026c62cdd949bd3f4433642350d4dffaec Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 16 Apr 2025 02:21:16 +0000 Subject: [PATCH 05/18] tomcat9: 9.0.102 -> 9.0.104 (cherry picked from commit 4fd25226bc970444d8e9ef976d97e58a14ab0b09) --- pkgs/servers/http/tomcat/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/http/tomcat/default.nix b/pkgs/servers/http/tomcat/default.nix index e791b34f8cd1..4adc5932d7c3 100644 --- a/pkgs/servers/http/tomcat/default.nix +++ b/pkgs/servers/http/tomcat/default.nix @@ -60,8 +60,8 @@ let in { tomcat9 = common { - version = "9.0.102"; - hash = "sha256-I+CjsW1ToSHIyGsOpOaWfRpKtonM9kkM4J6uV6w5R4c="; + version = "9.0.104"; + hash = "sha256-+hl1HI+BspTd40atk1F73thPQIhcRC4KcTDamCoiq64="; }; tomcat10 = common { From b560c127f4df919fb26c85125d8c230ac2d5c194 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 13 Mar 2025 22:06:23 +0000 Subject: [PATCH 06/18] tomcat: 11.0.2 -> 11.0.5 (cherry picked from commit 226aa70ab7542f40e10bdb8a9e41d5aa366f576a) --- pkgs/servers/http/tomcat/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/http/tomcat/default.nix b/pkgs/servers/http/tomcat/default.nix index 4adc5932d7c3..b84542d98f04 100644 --- a/pkgs/servers/http/tomcat/default.nix +++ b/pkgs/servers/http/tomcat/default.nix @@ -70,7 +70,7 @@ in }; tomcat11 = common { - version = "11.0.2"; - hash = "sha256-wbMaaYnTCnNEwaNlXadGec6fm0iicehkZHoUHeO3jLg="; + version = "11.0.5"; + hash = "sha256-sGH67p46AUjYOK2DSayDZMtUoo9x1pQuWOfF4a3hHa4="; }; } From 92b884a42059d31ded1965bc89967d1263e98c93 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 14 Apr 2025 21:29:13 +0000 Subject: [PATCH 07/18] tomcat: 11.0.5 -> 11.0.6 (cherry picked from commit 59ce228cf96c01f08ebeb5338ac8ec2660adeb30) --- pkgs/servers/http/tomcat/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/http/tomcat/default.nix b/pkgs/servers/http/tomcat/default.nix index b84542d98f04..35241d54e39e 100644 --- a/pkgs/servers/http/tomcat/default.nix +++ b/pkgs/servers/http/tomcat/default.nix @@ -70,7 +70,7 @@ in }; tomcat11 = common { - version = "11.0.5"; - hash = "sha256-sGH67p46AUjYOK2DSayDZMtUoo9x1pQuWOfF4a3hHa4="; + version = "11.0.6"; + hash = "sha256-hkRY9ka/k40/61dzRWGZgZuR1SZw5NckuYZsz9R2HO8="; }; } From 96dae1a8a70ed4971e03e11268b402df80f2a416 Mon Sep 17 00:00:00 2001 From: Leona Maroni Date: Wed, 7 May 2025 22:27:02 +0200 Subject: [PATCH 08/18] nixos/gitlab: add activeRecord key files GitLab 17.11 started using rails activeRecord encryption for some values. Introduce new key files. For the future there should also be an option to set multiple activeRecord keys for rotation. (manual backport from a95a530883f1c7cd408b823bba87ea17093301ea with diff behavior) --- nixos/modules/services/misc/gitlab.nix | 64 +++++++++++++++++++++++++- 1 file changed, 63 insertions(+), 1 deletion(-) diff --git a/nixos/modules/services/misc/gitlab.nix b/nixos/modules/services/misc/gitlab.nix index 103308c09fb7..0358460e446b 100644 --- a/nixos/modules/services/misc/gitlab.nix +++ b/nixos/modules/services/misc/gitlab.nix @@ -913,6 +913,44 @@ in ''; }; + secrets.activeRecordPrimaryKeyFile = mkOption { + type = with types; nullOr path; + default = null; + description = '' + A file containing the secret used to encrypt some rails data + in the DB. This should not be the same as `services.gitlab.secrets.activeRecordDeterministicKeyFile`! + Make sure the secret is at ideally 32 characters and all random, + no regular words or you'll be exposed to dictionary attacks. + This should be a string, not a nix path, since nix paths are + copied into the world-readable nix store. + ''; + }; + + secrets.activeRecordDeterministicKeyFile = mkOption { + type = with types; nullOr path; + default = null; + description = '' + A file containing the secret used to encrypt some rails data in a deterministic way + in the DB. This should not be the same as `services.gitlab.secrets.activeRecordPrimaryKeyFile`! + Make sure the secret is at ideally 32 characters and all random, + no regular words or you'll be exposed to dictionary attacks. + This should be a string, not a nix path, since nix paths are + copied into the world-readable nix store. + ''; + }; + + secrets.activeRecordSaltFile = mkOption { + type = with types; nullOr path; + default = null; + description = '' + A file containing the salt for active record encryption in the DB. + Make sure the secret is at ideally 32 characters and all random, + no regular words or you'll be exposed to dictionary attacks. + This should be a string, not a nix path, since nix paths are + copied into the world-readable nix store. + ''; + }; + extraShellConfig = mkOption { type = types.attrs; default = { }; @@ -1155,6 +1193,15 @@ in GitLab instances created or updated between versions [15.11.0, 15.11.2] have an incorrect database schema. Check the upstream documentation for a workaround: https://docs.gitlab.com/ee/update/versions/gitlab_16_changes.html#undefined-column-error-upgrading-to-162-or-later'' ) + (mkIf (cfg.secrets.activeRecordPrimaryKeyFile == null) + "services.gitlab.secrets.activeRecordPrimaryKeyFile is null. Please set this key file to make this secret stable and avoid decryption errors." + ) + (mkIf (cfg.secrets.activeRecordDeterministicKeyFile == null) + "services.gitlab.secrets.activeRecordDeterministicKeyFile is null. Please set this key file to make this secret stable and avoid decryption errors." + ) + (mkIf (cfg.secrets.activeRecordSaltFile == null) + "services.gitlab.secrets.activeRecordSaltFile is null. Please set this key file to make this secret stable and avoid decryption errors." + ) ]; assertions = [ @@ -1487,10 +1534,25 @@ in otp="$(<'${cfg.secrets.otpFile}')" jws="$(<'${cfg.secrets.jwsFile}')" export secret db otp jws + ${lib.optionalString (cfg.secrets.activeRecordPrimaryKeyFile != null) '' + arprimary="$(<'${cfg.secrets.activeRecordPrimaryKeyFile}')" + export arprimary + ''} + ${lib.optionalString (cfg.secrets.activeRecordDeterministicKeyFile != null) '' + ardeterministic="$(<'${cfg.secrets.activeRecordDeterministicKeyFile}')" + export ardeterminstic + ''} + ${lib.optionalString (cfg.secrets.activeRecordSaltFile != null) '' + arsalt="$(<'${cfg.secrets.activeRecordSaltFile}')" + export arsalt + ''} jq -n '{production: {secret_key_base: $ENV.secret, otp_key_base: $ENV.otp, db_key_base: $ENV.db, - openid_connect_signing_key: $ENV.jws}}' \ + openid_connect_signing_key: $ENV.jws, + active_record_encryption_primary_key: $ENV.arprimary, + active_record_encryption_deterministic_key: $ENV.ardeterministic, + active_record_encryption_key_derivation_salt: $ENV.arsalt}}' \ > '${cfg.statePath}/config/secrets.yml' ) From 9f489aca6f585ec3982a2c8f7845ff05992adb84 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 8 May 2025 22:43:13 +0000 Subject: [PATCH 09/18] thunderbird: 128.9.2esr -> 128.10.0esr (cherry picked from commit 87c270109c93bb6a1694d877a8e6415464646c25) --- .../networking/mailreaders/thunderbird/packages.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/networking/mailreaders/thunderbird/packages.nix b/pkgs/applications/networking/mailreaders/thunderbird/packages.nix index 0110ba593612..c72fc1e034c2 100644 --- a/pkgs/applications/networking/mailreaders/thunderbird/packages.nix +++ b/pkgs/applications/networking/mailreaders/thunderbird/packages.nix @@ -93,8 +93,8 @@ rec { thunderbird-esr = thunderbird-128; thunderbird-128 = common { - version = "128.9.2esr"; - sha512 = "3c8df53304611c1a7f8c02d50cfa1017f4d64c50a93fd6603ce0766cbb5d63c7bc5e0276f155c35817c3efa49f683c05583ddf24257bf8c25f585b67fd732cb5"; + version = "128.10.0esr"; + sha512 = "b02582ea4fa0297a06d30eda1555bbf3ed79ae7a35a8993f2a70b0ec84af28a4d084cd7ebe1c73676e689ff9366e779cc5ef67a197638949bf232a40b740d1b6"; updateScript = callPackage ./update.nix { attrPath = "thunderbirdPackages.thunderbird-128"; From f21545387a8ff8cd2feb0be29233b778c831680a Mon Sep 17 00:00:00 2001 From: Winter Date: Sun, 11 May 2025 13:46:33 -0400 Subject: [PATCH 10/18] sta: unbreak on darwin Builds and runs just fine. (cherry picked from commit fa417a2bc0a18d2bd859a87c973f228d9491c61a) --- pkgs/by-name/st/sta/package.nix | 1 - 1 file changed, 1 deletion(-) diff --git a/pkgs/by-name/st/sta/package.nix b/pkgs/by-name/st/sta/package.nix index 64cbc1d4745a..c7487086bef6 100644 --- a/pkgs/by-name/st/sta/package.nix +++ b/pkgs/by-name/st/sta/package.nix @@ -31,7 +31,6 @@ stdenv.mkDerivation { homepage = "https://github.com/simonccarter/sta"; maintainers = [ ]; platforms = platforms.all; - badPlatforms = platforms.darwin; mainProgram = "sta"; }; } From fcb56b6c7a83eed2e53ed5cd34592cb9ad4d46b0 Mon Sep 17 00:00:00 2001 From: Winter Date: Sun, 11 May 2025 21:11:10 -0400 Subject: [PATCH 11/18] sta: enable tests (cherry picked from commit c4f6f75afc6932a12e5e6605bc24afb4199e1315) --- pkgs/by-name/st/sta/package.nix | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) diff --git a/pkgs/by-name/st/sta/package.nix b/pkgs/by-name/st/sta/package.nix index c7487086bef6..b0b00a3d4e64 100644 --- a/pkgs/by-name/st/sta/package.nix +++ b/pkgs/by-name/st/sta/package.nix @@ -3,6 +3,7 @@ lib, fetchFromGitHub, autoreconfHook, + cxxtest, }: stdenv.mkDerivation { @@ -18,6 +19,24 @@ stdenv.mkDerivation { nativeBuildInputs = [ autoreconfHook ]; + doCheck = true; + nativeCheckInputs = [ cxxtest ]; + checkInputs = [ cxxtest ]; + + checkPhase = '' + runHook preCheck + + pushd test + + cxxtestgen --error-printer --have-std -o tests.cpp sta_test_1.h sta_test_2.h + ${stdenv.cc.targetPrefix}c++ -o tester tests.cpp + ./tester + + popd + + runHook postCheck + ''; + meta = with lib; { description = "Simple statistics from the command line interface (CLI), fast"; longDescription = '' From 75b2e3a6543da8742b1d9168c8f897c4bfb25630 Mon Sep 17 00:00:00 2001 From: Winter Date: Sun, 11 May 2025 21:11:46 -0400 Subject: [PATCH 12/18] sta: enable strictDeps (cherry picked from commit baf6ebeba5f60942d667662e7f481638fc390fac) --- pkgs/by-name/st/sta/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/st/sta/package.nix b/pkgs/by-name/st/sta/package.nix index b0b00a3d4e64..a24b87d9ff7d 100644 --- a/pkgs/by-name/st/sta/package.nix +++ b/pkgs/by-name/st/sta/package.nix @@ -17,6 +17,8 @@ stdenv.mkDerivation { sha256 = "sha256-AiygCfBze7J1Emy6mc27Dim34eLR7VId9wodUZapIL4="; }; + strictDeps = true; + nativeBuildInputs = [ autoreconfHook ]; doCheck = true; From d0b81c69c33e238c6695c93ed7f50c8bbc39ca6d Mon Sep 17 00:00:00 2001 From: Pol Dellaiera Date: Mon, 12 May 2025 15:10:44 +0200 Subject: [PATCH 13/18] vscode-extensions.amazonwebservices.amazon-q-vscode: init at 1.66.0 (cherry picked from commit 2d1675a0d63feee5d83f59f03075bb873bcf19a2) --- .../default.nix | 22 +++++++++++++++++++ .../editors/vscode/extensions/default.nix | 2 ++ 2 files changed, 24 insertions(+) create mode 100644 pkgs/applications/editors/vscode/extensions/amazonwebservices.amazon-q-vscode/default.nix diff --git a/pkgs/applications/editors/vscode/extensions/amazonwebservices.amazon-q-vscode/default.nix b/pkgs/applications/editors/vscode/extensions/amazonwebservices.amazon-q-vscode/default.nix new file mode 100644 index 000000000000..306df8c3cb55 --- /dev/null +++ b/pkgs/applications/editors/vscode/extensions/amazonwebservices.amazon-q-vscode/default.nix @@ -0,0 +1,22 @@ +{ + lib, + vscode-utils, +}: + +vscode-utils.buildVscodeMarketplaceExtension (finalAttrs: { + mktplcRef = { + name = "amazon-q-vscode"; + publisher = "AmazonWebServices"; + version = "1.66.0"; + hash = "sha256-EnNwlSmJWBcSfFCayxJS94qVUqgQlbX0RLCB4jJsn+4="; + }; + + meta = { + changelog = "https://github.com/aws/aws-toolkit-vscode/releases/tag/amazonq%2Fv${finalAttrs.version}"; + description = "Amazon Q, CodeCatalyst, Local Lambda debug, SAM/CFN syntax, ECS Terminal, AWS resources"; + downloadPage = "https://marketplace.visualstudio.com/items?itemName=AmazonWebServices.amazon-q-vscode"; + homepage = "https://github.com/aws/aws-toolkit-vscode"; + license = lib.licenses.asl20; + maintainers = with lib.maintainers; [ drupol ]; + }; +}) diff --git a/pkgs/applications/editors/vscode/extensions/default.nix b/pkgs/applications/editors/vscode/extensions/default.nix index b3efaee028c4..744d390a455a 100644 --- a/pkgs/applications/editors/vscode/extensions/default.nix +++ b/pkgs/applications/editors/vscode/extensions/default.nix @@ -253,6 +253,8 @@ let }; }; + amazonwebservices.amazon-q-vscode = callPackage ./amazonwebservices.amazon-q-vscode { }; + angular.ng-template = buildVscodeMarketplaceExtension { mktplcRef = { name = "ng-template"; From 406954bfa85e5021156f660aa568d5c128d22b23 Mon Sep 17 00:00:00 2001 From: Wolfgang Walther Date: Sun, 11 May 2025 20:55:26 +0200 Subject: [PATCH 14/18] workflows/eval: load supportedSystems from JSON file This is a refactor to prepare the next commit. It doesn't do much on its own, but is separated for ease of review. (cherry picked from commit 456a4697b1bbafb6c85c0632ad1fca1d6aa0c24a) --- .github/workflows/eval.yml | 7 ++----- .github/workflows/get-merge-commit.yml | 10 +++++++++- ci/eval/README.md | 2 +- ci/eval/default.nix | 7 ++----- ci/supportedSystems.json | 6 ++++++ ci/supportedSystems.nix | 6 ------ pkgs/top-level/release-haskell.nix | 2 +- pkgs/top-level/release-outpaths.nix | 2 +- pkgs/top-level/release.nix | 2 +- 9 files changed, 23 insertions(+), 21 deletions(-) create mode 100644 ci/supportedSystems.json delete mode 100644 ci/supportedSystems.nix diff --git a/.github/workflows/eval.yml b/.github/workflows/eval.yml index 8cc523d1bef3..95130ec85d6b 100644 --- a/.github/workflows/eval.yml +++ b/.github/workflows/eval.yml @@ -26,7 +26,6 @@ jobs: if: needs.get-merge-commit.outputs.mergedSha outputs: targetSha: ${{ steps.targetSha.outputs.targetSha }} - systems: ${{ steps.systems.outputs.systems }} steps: - name: Check out the PR at the test merge commit uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 @@ -47,11 +46,9 @@ jobs: with: extra_nix_config: sandbox = true - - name: Evaluate the list of all attributes and get the systems matrix - id: systems + - name: Evaluate the list of all attributes run: | nix-build nixpkgs/ci -A eval.attrpathsSuperset - echo "systems=$(> "$GITHUB_OUTPUT" - name: Upload the list of all attributes uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 @@ -66,7 +63,7 @@ jobs: strategy: fail-fast: false matrix: - system: ${{ fromJSON(needs.attrs.outputs.systems) }} + system: ${{ fromJSON(needs.get-merge-commit.outputs.systems) }} steps: - name: Enable swap run: | diff --git a/.github/workflows/get-merge-commit.yml b/.github/workflows/get-merge-commit.yml index cb38438cae3b..7ce1d53b0249 100644 --- a/.github/workflows/get-merge-commit.yml +++ b/.github/workflows/get-merge-commit.yml @@ -6,6 +6,9 @@ on: mergedSha: description: "The merge commit SHA" value: ${{ jobs.resolve-merge-commit.outputs.mergedSha }} + systems: + description: "The supported systems" + value: ${{ jobs.resolve-merge-commit.outputs.systems }} permissions: {} @@ -14,6 +17,7 @@ jobs: runs-on: ubuntu-24.04-arm outputs: mergedSha: ${{ steps.merged.outputs.mergedSha }} + systems: ${{ steps.systems.outputs.systems }} steps: - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: @@ -40,4 +44,8 @@ jobs: fi ;; esac - rm -rf base + + - name: Load supported systems + id: systems + run: | + echo "systems=$(jq -c > "$GITHUB_OUTPUT" diff --git a/ci/eval/README.md b/ci/eval/README.md index 0436a028ed69..011f3dd74ed0 100644 --- a/ci/eval/README.md +++ b/ci/eval/README.md @@ -11,7 +11,7 @@ nix-build ci -A eval.full \ --arg evalSystems '["x86_64-linux" "aarch64-darwin"]' ``` -- `--max-jobs`: The maximum number of derivations to run at the same time. Only each [supported system](../supportedSystems.nix) gets a separate derivation, so it doesn't make sense to set this higher than that number. +- `--max-jobs`: The maximum number of derivations to run at the same time. Only each [supported system](../supportedSystems.json) gets a separate derivation, so it doesn't make sense to set this higher than that number. - `--cores`: The number of cores to use for each job. Recommended to set this to the amount of cores on your system divided by `--max-jobs`. - `chunkSize`: The number of attributes that are evaluated simultaneously on a single core. Lowering this decreases memory usage at the cost of increased evaluation time. If this is too high, there won't be enough chunks to process them in parallel, and will also increase evaluation time. - `evalSystems`: The set of systems for which `nixpkgs` should be evaluated. Defaults to the four official platforms (`x86_64-linux`, `aarch64-linux`, `x86_64-darwin` and `aarch64-darwin`). diff --git a/ci/eval/default.nix b/ci/eval/default.nix index 639e75ec4211..99445e953183 100644 --- a/ci/eval/default.nix +++ b/ci/eval/default.nix @@ -26,14 +26,14 @@ let "nixos" "pkgs" ".version" - "ci/supportedSystems.nix" + "ci/supportedSystems.json" ] ); }; nix = nixVersions.nix_2_24; - supportedSystems = import ../supportedSystems.nix; + supportedSystems = builtins.fromJSON (builtins.readFile ../supportedSystems.json); attrpathsSuperset = runCommand "attrpaths-superset.json" @@ -43,8 +43,6 @@ let nix time ]; - env.supportedSystems = builtins.toJSON supportedSystems; - passAsFile = [ "supportedSystems" ]; } '' export NIX_STATE_DIR=$(mktemp -d) @@ -58,7 +56,6 @@ let --option restrict-eval true \ --option allow-import-from-derivation false \ --arg enableWarnings false > $out/paths.json - mv "$supportedSystemsPath" $out/systems.json ''; singleSystem = diff --git a/ci/supportedSystems.json b/ci/supportedSystems.json new file mode 100644 index 000000000000..44c18f1abf0e --- /dev/null +++ b/ci/supportedSystems.json @@ -0,0 +1,6 @@ +[ + "aarch64-linux", + "aarch64-darwin", + "x86_64-linux", + "x86_64-darwin" +] diff --git a/ci/supportedSystems.nix b/ci/supportedSystems.nix deleted file mode 100644 index 471f84b92fc2..000000000000 --- a/ci/supportedSystems.nix +++ /dev/null @@ -1,6 +0,0 @@ -[ - "aarch64-linux" - "aarch64-darwin" - "x86_64-linux" - "x86_64-darwin" -] diff --git a/pkgs/top-level/release-haskell.nix b/pkgs/top-level/release-haskell.nix index 91f22faba8b2..7c949a0e640b 100644 --- a/pkgs/top-level/release-haskell.nix +++ b/pkgs/top-level/release-haskell.nix @@ -10,7 +10,7 @@ $ hydra-eval-jobs -I . pkgs/top-level/release-haskell.nix */ { - supportedSystems ? import ../../ci/supportedSystems.nix, + supportedSystems ? builtins.fromJSON (builtins.readFile ../../ci/supportedSystems.json), }: let diff --git a/pkgs/top-level/release-outpaths.nix b/pkgs/top-level/release-outpaths.nix index e6caabec04e9..8ca14fc95007 100644 --- a/pkgs/top-level/release-outpaths.nix +++ b/pkgs/top-level/release-outpaths.nix @@ -13,7 +13,7 @@ attrNamesOnly ? false, # Set this to `null` to build for builtins.currentSystem only - systems ? import ../../ci/supportedSystems.nix, + systems ? builtins.fromJSON (builtins.readFile ../../ci/supportedSystems.json), }: let lib = import (path + "/lib"); diff --git a/pkgs/top-level/release.nix b/pkgs/top-level/release.nix index 25031e6dd3ab..e7e703cfbc09 100644 --- a/pkgs/top-level/release.nix +++ b/pkgs/top-level/release.nix @@ -19,7 +19,7 @@ system ? builtins.currentSystem, officialRelease ? false, # The platform doubles for which we build Nixpkgs. - supportedSystems ? import ../../ci/supportedSystems.nix, + supportedSystems ? builtins.fromJSON (builtins.readFile ../../ci/supportedSystems.json), # The platform triples for which we build bootstrap tools. bootstrapConfigs ? [ "aarch64-apple-darwin" From cce93e81a46b4941d3e43235a5a5b50c2da2828c Mon Sep 17 00:00:00 2001 From: Wolfgang Walther Date: Sun, 11 May 2025 21:28:40 +0200 Subject: [PATCH 15/18] workflows/get-merge-commit: return targetSha We can fetch the targetSha directly with the mergedSha from the API. This avoids a checkout with fetch-depth: 2 for a small performance improvement. (cherry picked from commit 962836d4d0bdad936e973194a8935363f34a2678) --- .github/workflows/eval.yml | 20 +++++--------------- .github/workflows/get-merge-commit.yml | 10 +++++++--- ci/README.md | 4 ++-- ci/get-merge-commit.sh | 5 ++++- 4 files changed, 18 insertions(+), 21 deletions(-) diff --git a/.github/workflows/eval.yml b/.github/workflows/eval.yml index 95130ec85d6b..024e7b823b62 100644 --- a/.github/workflows/eval.yml +++ b/.github/workflows/eval.yml @@ -24,23 +24,13 @@ jobs: runs-on: ubuntu-24.04-arm needs: get-merge-commit if: needs.get-merge-commit.outputs.mergedSha - outputs: - targetSha: ${{ steps.targetSha.outputs.targetSha }} steps: - name: Check out the PR at the test merge commit uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: ref: ${{ needs.get-merge-commit.outputs.mergedSha }} - fetch-depth: 2 path: nixpkgs - - name: Determine target commit - if: github.event_name == 'pull_request_target' - id: targetSha - run: | - targetSha=$(git -C nixpkgs rev-parse HEAD^1) - echo "targetSha=$targetSha" >> "$GITHUB_OUTPUT" - - name: Install Nix uses: cachix/install-nix-action@526118121621777ccd86f79b04685a9319637641 # v31 with: @@ -143,7 +133,7 @@ jobs: path: prResult/* - name: Get target run id - if: needs.attrs.outputs.targetSha + if: needs.get-merge-commit.outputs.targetSha id: targetRunId run: | # Get the latest eval.yml workflow run for the PR's target commit @@ -172,7 +162,7 @@ jobs: echo "targetRunId=$runId" >> "$GITHUB_OUTPUT" env: REPOSITORY: ${{ github.repository }} - TARGET_SHA: ${{ needs.attrs.outputs.targetSha }} + TARGET_SHA: ${{ needs.get-merge-commit.outputs.targetSha }} GH_TOKEN: ${{ github.token }} - uses: actions/download-artifact@v4 @@ -186,8 +176,8 @@ jobs: - name: Compare against the target branch if: steps.targetRunId.outputs.targetRunId run: | - git -C nixpkgs worktree add ../target ${{ needs.attrs.outputs.targetSha }} - git -C nixpkgs diff --name-only ${{ needs.attrs.outputs.targetSha }} \ + git -C nixpkgs worktree add ../target ${{ needs.get-merge-commit.outputs.targetSha }} + git -C nixpkgs diff --name-only ${{ needs.get-merge-commit.outputs.targetSha }} \ | jq --raw-input --slurp 'split("\n")[:-1]' > touched-files.json # Use the target branch to get accurate maintainer info @@ -241,7 +231,7 @@ jobs: - name: Check out Nixpkgs at the base commit uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: - ref: ${{ needs.attrs.outputs.targetSha }} + ref: ${{ needs.get-merge-commit.outputs.targetSha }} path: base sparse-checkout: ci diff --git a/.github/workflows/get-merge-commit.yml b/.github/workflows/get-merge-commit.yml index 7ce1d53b0249..7d8dd03fbf66 100644 --- a/.github/workflows/get-merge-commit.yml +++ b/.github/workflows/get-merge-commit.yml @@ -6,6 +6,9 @@ on: mergedSha: description: "The merge commit SHA" value: ${{ jobs.resolve-merge-commit.outputs.mergedSha }} + targetSha: + description: "The target commit SHA" + value: ${{ jobs.resolve-merge-commit.outputs.targetSha }} systems: description: "The supported systems" value: ${{ jobs.resolve-merge-commit.outputs.systems }} @@ -17,6 +20,7 @@ jobs: runs-on: ubuntu-24.04-arm outputs: mergedSha: ${{ steps.merged.outputs.mergedSha }} + targetSha: ${{ steps.merged.outputs.targetSha }} systems: ${{ steps.systems.outputs.systems }} steps: - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 @@ -35,9 +39,9 @@ jobs: echo "mergedSha=${{ github.sha }}" >> "$GITHUB_OUTPUT" ;; pull_request_target) - if mergedSha=$(base/ci/get-merge-commit.sh ${{ github.repository }} ${{ github.event.number }}); then - echo "Checking the merge commit $mergedSha" - echo "mergedSha=$mergedSha" >> "$GITHUB_OUTPUT" + if commits=$(base/ci/get-merge-commit.sh ${{ github.repository }} ${{ github.event.number }}); then + echo "Checking the commits:\n$commits" + echo "$commits" >> "$GITHUB_OUTPUT" else # Skipping so that no notifications are sent echo "Skipping the rest..." diff --git a/ci/README.md b/ci/README.md index a1b327de4e5d..6ef665e8b099 100644 --- a/ci/README.md +++ b/ci/README.md @@ -44,14 +44,14 @@ Why not just build the tooling right from the PRs Nixpkgs version? ## `get-merge-commit.sh GITHUB_REPO PR_NUMBER` Check whether a PR is mergeable and return the test merge commit as -[computed by GitHub](https://docs.github.com/en/rest/guides/using-the-rest-api-to-interact-with-your-git-database?apiVersion=2022-11-28#checking-mergeability-of-pull-requests). +[computed by GitHub](https://docs.github.com/en/rest/guides/using-the-rest-api-to-interact-with-your-git-database?apiVersion=2022-11-28#checking-mergeability-of-pull-requests) and its parent. Arguments: - `GITHUB_REPO`: The repository of the PR, e.g. `NixOS/nixpkgs` - `PR_NUMBER`: The PR number, e.g. `1234` Exit codes: -- 0: The PR can be merged, the test merge commit hash is returned on stdout +- 0: The PR can be merged, the hashes of the test merge commit and the target commit are returned on stdout - 1: The PR cannot be merged because it's not open anymore - 2: The PR cannot be merged because it has a merge conflict - 3: The merge commit isn't being computed, GitHub is likely having internal issues, unknown if the PR is mergeable diff --git a/ci/get-merge-commit.sh b/ci/get-merge-commit.sh index c62bb56dd993..c233f7f91691 100755 --- a/ci/get-merge-commit.sh +++ b/ci/get-merge-commit.sh @@ -55,7 +55,10 @@ done if [[ "$mergeable" == "true" ]]; then log "The PR can be merged" - jq -r .merge_commit_sha <<< "$prInfo" + mergedSha="$(jq -r .merge_commit_sha <<< "$prInfo")" + echo "mergedSha=$mergedSha" + targetSha="$(gh api "/repos/$repo/commits/$mergedSha" --jq '.parents[0].sha')" + echo "targetSha=$targetSha" else log "The PR has a merge conflict" exit 2 From 3ac0b4a479a3b46b421582028c43b8c2f5f6f987 Mon Sep 17 00:00:00 2001 From: Wolfgang Walther Date: Sun, 11 May 2025 19:49:54 +0200 Subject: [PATCH 16/18] workflows/eval: remove attrs step Previously, the attrs step consisted of: - 7s queue time - 1m 15s run time Only 25s of this were spent preparing the attr paths. A bit more than a minute was just spent for queuing, checking out the repo, downloading nix, downloading dependencies, uploading the artifacts - and then downloading them again in the next step. All of that can be avoided if we collect the attrs as part of the outpaths job. By running the attrs step as part of each outpaths step the attrpaths will be collected 4x, but: - We save a minute for each eval run to complete. - We save a full job, giving us more free runners and *possibly* less queue times for other jobs in the repo. - We reduce complexity in the workflow file. (cherry picked from commit af6faf876022f53031aee0bf9fdb6aa1b0842995) --- .github/workflows/eval.yml | 40 +++----------------------------------- ci/eval/default.nix | 3 +-- 2 files changed, 4 insertions(+), 39 deletions(-) diff --git a/.github/workflows/eval.yml b/.github/workflows/eval.yml index 024e7b823b62..c887638ab9b8 100644 --- a/.github/workflows/eval.yml +++ b/.github/workflows/eval.yml @@ -19,37 +19,10 @@ jobs: get-merge-commit: uses: ./.github/workflows/get-merge-commit.yml - attrs: - name: Attributes - runs-on: ubuntu-24.04-arm - needs: get-merge-commit - if: needs.get-merge-commit.outputs.mergedSha - steps: - - name: Check out the PR at the test merge commit - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - with: - ref: ${{ needs.get-merge-commit.outputs.mergedSha }} - path: nixpkgs - - - name: Install Nix - uses: cachix/install-nix-action@526118121621777ccd86f79b04685a9319637641 # v31 - with: - extra_nix_config: sandbox = true - - - name: Evaluate the list of all attributes - run: | - nix-build nixpkgs/ci -A eval.attrpathsSuperset - - - name: Upload the list of all attributes - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 - with: - name: paths - path: result/* - outpaths: name: Outpaths runs-on: ubuntu-24.04-arm - needs: [ attrs, get-merge-commit ] + needs: [ get-merge-commit ] strategy: fail-fast: false matrix: @@ -62,12 +35,6 @@ jobs: sudo mkswap /swap sudo swapon /swap - - name: Download the list of all attributes - uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4.1.8 - with: - name: paths - path: paths - - name: Check out the PR at the test merge commit uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 with: @@ -85,7 +52,6 @@ jobs: run: | nix-build nixpkgs/ci -A eval.singleSystem \ --argstr evalSystem "$MATRIX_SYSTEM" \ - --arg attrpathFile ./paths/paths.json \ --arg chunkSize 10000 # If it uses too much memory, slightly decrease chunkSize @@ -98,7 +64,7 @@ jobs: process: name: Process runs-on: ubuntu-24.04-arm - needs: [ outpaths, attrs, get-merge-commit ] + needs: [ outpaths, get-merge-commit ] outputs: targetRunId: ${{ steps.targetRunId.outputs.targetRunId }} steps: @@ -200,7 +166,7 @@ jobs: tag: name: Tag runs-on: ubuntu-24.04-arm - needs: [ attrs, process ] + needs: [ process ] if: needs.process.outputs.targetRunId permissions: pull-requests: write diff --git a/ci/eval/default.nix b/ci/eval/default.nix index 99445e953183..e3f035e18d56 100644 --- a/ci/eval/default.nix +++ b/ci/eval/default.nix @@ -65,7 +65,7 @@ let # because `--argstr system` would only be passed to the ci/default.nix file! evalSystem, # The path to the `paths.json` file from `attrpathsSuperset` - attrpathFile, + attrpathFile ? "${attrpathsSuperset}/paths.json", # The number of attributes per chunk, see ./README.md for more info. chunkSize, checkMeta ? true, @@ -286,7 +286,6 @@ let name = evalSystem; path = singleSystem { inherit quickTest evalSystem chunkSize; - attrpathFile = attrpathsSuperset + "/paths.json"; }; }) evalSystems ); From 2c21052647cc731afc815668bd750dfb0946a870 Mon Sep 17 00:00:00 2001 From: Alyssa Ross Date: Sun, 11 May 2025 19:52:06 +0200 Subject: [PATCH 17/18] btrfs-progs.meta.mainProgram: init (cherry picked from commit fddf18a8fc616cf8f706ae58b95489ce87588faf) --- pkgs/by-name/bt/btrfs-progs/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/bt/btrfs-progs/package.nix b/pkgs/by-name/bt/btrfs-progs/package.nix index 560d5f1cfcd3..a4ce7d4c9cb8 100644 --- a/pkgs/by-name/bt/btrfs-progs/package.nix +++ b/pkgs/by-name/bt/btrfs-progs/package.nix @@ -96,6 +96,7 @@ stdenv.mkDerivation rec { homepage = "https://btrfs.readthedocs.io/en/latest/"; changelog = "https://github.com/kdave/btrfs-progs/raw/v${version}/CHANGES"; license = licenses.gpl2Only; + mainProgram = "btrfs"; maintainers = with maintainers; [ raskin ]; platforms = platforms.linux; }; From 06308ec8d5ad9723dbe26d13e0eba1f94933dbbc Mon Sep 17 00:00:00 2001 From: Winter Date: Mon, 12 May 2025 17:58:07 -0400 Subject: [PATCH 18/18] OWNERS: remove ehmry User was banned [0], so do this to stop the CI from failing. [0]: https://github.com/NixOS/moderation/commit/06298268253d22c7a4612c6d82c976fff699bddc (cherry picked from commit 940c27de00491c11276347af1c8c09c276fafcb4) --- ci/OWNERS | 9 ++------- 1 file changed, 2 insertions(+), 7 deletions(-) diff --git a/ci/OWNERS b/ci/OWNERS index 5dcc5941eab5..980151acfe70 100644 --- a/ci/OWNERS +++ b/ci/OWNERS @@ -275,8 +275,8 @@ pkgs/development/python-modules/buildcatrust/ @ajs124 @lukegb @mweinelt /nixos/modules/services/web-servers/nginx/ @raitobezarius # Dhall -/pkgs/development/dhall-modules @Gabriella439 @Profpatsch @ehmry -/pkgs/development/interpreters/dhall @Gabriella439 @Profpatsch @ehmry +/pkgs/development/dhall-modules @Gabriella439 @Profpatsch +/pkgs/development/interpreters/dhall @Gabriella439 @Profpatsch # Idris /pkgs/development/idris-modules @Infinisil @@ -347,11 +347,6 @@ pkgs/development/python-modules/buildcatrust/ @ajs124 @lukegb @mweinelt # Xfce /doc/hooks/xfce4-dev-tools.section.md @NixOS/xfce -# nim -/doc/languages-frameworks/nim.section.md @ehmry -/pkgs/build-support/build-nim-package.nix @ehmry -/pkgs/top-level/nim-overrides.nix @ehmry - # terraform providers /pkgs/applications/networking/cluster/terraform-providers @zowoq