diff --git a/doc/release-notes/rl-2511.section.md b/doc/release-notes/rl-2511.section.md
index baa6daea1584..8522948accd4 100644
--- a/doc/release-notes/rl-2511.section.md
+++ b/doc/release-notes/rl-2511.section.md
@@ -318,6 +318,13 @@ and [release notes for v18](https://goteleport.com/docs/changelog/#1800-070325).
- `zig_0_12` has been removed.
+- The `services.yggdrasil` module has been refactored with the following breaking changes:
+ - The `services.yggdrasil.configFile` option has been removed. Configuration should now be specified directly via `services.yggdrasil.settings`.
+ - The `services.yggdrasil.persistentKeys` option has been removed. To maintain persistent keys and IPv6 addresses across reboots, use `services.yggdrasil.settings.PrivateKeyPath` to securely load your private key from a file via systemd credentials. The private key must be in PEM format (PKCS #8).
+ - Storing `PrivateKey` directly in `settings` is now explicitly forbidden to prevent keys from being stored world-readable in the Nix store.
+ - If you previously used `configFile`, migrate your configuration to the `settings` option and extract the private key to a separate file referenced by `PrivateKeyPath`.
+ - If you previously used `persistentKeys`, convert your keys to PEM format and store them in a secure location accessible only to root, then reference them via `PrivateKeyPath`.
+
- `zigbee2mqtt` was updated to version 2.x, which contains breaking changes. See the [discussion](https://github.com/Koenkk/zigbee2mqtt/discussions/24198) for further information.
## Other Notable Changes {#sec-nixpkgs-release-25.11-notable-changes}
diff --git a/nixos/doc/manual/release-notes/rl-2605.section.md b/nixos/doc/manual/release-notes/rl-2605.section.md
index 9d4f926dc718..ed4c83085e79 100644
--- a/nixos/doc/manual/release-notes/rl-2605.section.md
+++ b/nixos/doc/manual/release-notes/rl-2605.section.md
@@ -63,6 +63,8 @@ of pulling the upstream container image from Docker Hub. If you want the old beh
- Ethercalc and its associated module have been removed, as the package is unmaintained and cannot be installed from source with npm now.
+- `services.cgit` before always had the git-http-backend and its "export all" setting enabled, which sidestepped any access control configured in cgit's settings. Now you have to make a decision and either enable or disable `services.cgit.gitHttpBackend.checkExportOkFiles` (or disable the git-http-backend).
+
- The Bash implementation of the `nixos-rebuild` program is removed. All switchable systems now use the Python rewrite. Any prior usage of `system.rebuild.enableNg` must now be removed. If you have any outstanding issues with the new implementation, please open an issue on GitHub.
- The `networking.wireless` module has been security hardened: the `wpa_supplicant` daemon now runs under an unprivileged user with restricted access to the system.
diff --git a/nixos/modules/security/rtkit.nix b/nixos/modules/security/rtkit.nix
index f2cd256468da..61e4f8666fe7 100644
--- a/nixos/modules/security/rtkit.nix
+++ b/nixos/modules/security/rtkit.nix
@@ -1,6 +1,3 @@
-# A module for ‘rtkit’, a DBus system service that hands out realtime
-# scheduling priority to processes that ask for it.
-
{
config,
lib,
@@ -8,20 +5,13 @@
utils,
...
}:
-
-with lib;
-
let
cfg = config.security.rtkit;
- package = pkgs.rtkit;
-
in
{
-
- options = {
-
- security.rtkit.enable = mkOption {
- type = types.bool;
+ options.security.rtkit = {
+ enable = lib.mkOption {
+ type = lib.types.bool;
default = false;
description = ''
Whether to enable the RealtimeKit system service, which hands
@@ -31,8 +21,10 @@ in
'';
};
- security.rtkit.args = mkOption {
- type = types.listOf types.str;
+ package = lib.mkPackageOption pkgs "rtkit" { };
+
+ args = lib.mkOption {
+ type = lib.types.listOf lib.types.str;
default = [ ];
description = ''
Command-line options for `rtkit-daemon`.
@@ -42,25 +34,23 @@ in
"--max-realtime-priority=28"
];
};
-
};
- config = mkIf cfg.enable {
-
+ config = lib.mkIf cfg.enable {
security.polkit.enable = true;
# To make polkit pickup rtkit policies
- environment.systemPackages = [ package ];
+ environment.systemPackages = [ cfg.package ];
- services.dbus.packages = [ package ];
+ services.dbus.packages = [ cfg.package ];
- systemd.packages = [ package ];
+ systemd.packages = [ cfg.package ];
systemd.services.rtkit-daemon = {
serviceConfig = {
ExecStart = [
"" # Resets command from upstream unit.
- "${package}/libexec/rtkit-daemon ${utils.escapeSystemdExecArgs cfg.args}"
+ "${cfg.package}/libexec/rtkit-daemon ${utils.escapeSystemdExecArgs cfg.args}"
];
# Needs to verify the user of the processes.
@@ -104,7 +94,7 @@ in
description = "RealtimeKit daemon";
};
users.groups.rtkit = { };
-
};
+ meta = { inherit (pkgs.rtkit.meta) maintainers; };
}
diff --git a/nixos/modules/services/networking/cgit.nix b/nixos/modules/services/networking/cgit.nix
index c9abf022932f..63d247a9e068 100644
--- a/nixos/modules/services/networking/cgit.nix
+++ b/nixos/modules/services/networking/cgit.nix
@@ -193,6 +193,32 @@ in
type = lib.types.str;
default = "cgit";
};
+
+ gitHttpBackend.enable = lib.mkOption {
+ description = ''
+ Whether to bypass cgit and use git-http-backend for HTTP clones.
+ While this enables HTTP clones to use the more efficient smart protocol,
+ it does not support access control via cgit's settings (e.g. the `ignore` repository setting).
+
+ If you want to disallow access to some repositories with this backend,
+ enable `checkExportOkFiles` and set `strict-export = "git-daemon-export-ok"` in `settings`.
+ '';
+ type = lib.types.bool;
+ default = true;
+ };
+
+ gitHttpBackend.checkExportOkFiles = lib.mkOption {
+ description = ''
+ Whether git-http-backend should only export repositories that contain a `git-daemon-export-ok` file.
+
+ When the backend is enabled and the check is disabled all repositories can be cloned
+ irrespective of cgit's settings (e.g. the `ignore` repository setting).
+
+ When enabled you must also configure `strict-export = "git-daemon-export-ok"`
+ in `settings` to make cgit check for the same files.
+ '';
+ type = lib.types.bool;
+ };
};
}
)
@@ -201,10 +227,30 @@ in
};
config = lib.mkIf (lib.any (cfg: cfg.enable) (lib.attrValues cfgs)) {
- assertions = lib.mapAttrsToList (vhost: cfg: {
- assertion = !cfg.enable || (cfg.scanPath == null) != (cfg.repos == { });
- message = "Exactly one of services.cgit.${vhost}.scanPath or services.cgit.${vhost}.repos must be set.";
- }) cfgs;
+ assertions = lib.flatten (
+ lib.mapAttrsToList (vhost: cfg: [
+ {
+ assertion = !cfg.enable || (cfg.scanPath == null) != (cfg.repos == { });
+ message = "Misconfigured services.cgit.${vhost}: Exactly one of scanPath or repos must be set.";
+ }
+ {
+ assertion =
+ !cfg.enable
+ || !cfg.gitHttpBackend.enable
+ || !cfg.gitHttpBackend.checkExportOkFiles
+ || cfg.settings.strict-export == "git-daemon-export-ok";
+ message = "Misconfigured services.cgit.${vhost}: When gitHttpBackend.checkExportOkFiles is true then settings.strict-export must be \"git-daemon-export-ok\".";
+ }
+ {
+ assertion =
+ !cfg.enable
+ || !cfg.gitHttpBackend.enable
+ || cfg.settings.strict-export == null
+ || cfg.gitHttpBackend.checkExportOkFiles;
+ message = "Misconfigured services.cgit.${vhost}: settings.strict-export is set but the gitHttpBackend is enabled and checkExportOkFiles is false.";
+ }
+ ]) cfgs
+ );
users = lib.mkMerge (
lib.flip lib.mapAttrsToList cfgs (
@@ -259,16 +305,20 @@ in
alias = lib.mkDefault "${cfg.package}/cgit/${fileName}";
}
))
- // {
+ // lib.optionalAttrs cfg.gitHttpBackend.enable {
"~ ${regexLocation cfg}/.+/(info/refs|git-upload-pack)" = {
fastcgiParams = rec {
SCRIPT_FILENAME = "${pkgs.git}/libexec/git-core/git-http-backend";
- GIT_HTTP_EXPORT_ALL = "1";
GIT_PROJECT_ROOT = gitProjectRoot name cfg;
HOME = GIT_PROJECT_ROOT;
+ }
+ // lib.optionalAttrs (!cfg.gitHttpBackend.checkExportOkFiles) {
+ GIT_HTTP_EXPORT_ALL = "1";
};
extraConfig = mkFastcgiPass name cfg;
};
+ }
+ // {
"${stripLocation cfg}/" = {
fastcgiParams = {
SCRIPT_FILENAME = "${cfg.package}/cgit/cgit.cgi";
diff --git a/nixos/modules/services/networking/yggdrasil.nix b/nixos/modules/services/networking/yggdrasil.nix
index 5d1ecd7f4797..3f2f0277f59a 100644
--- a/nixos/modules/services/networking/yggdrasil.nix
+++ b/nixos/modules/services/networking/yggdrasil.nix
@@ -13,14 +13,47 @@ let
bool
listOf
str
+ attrs
+ submodule
;
- keysPath = "/var/lib/yggdrasil/keys.json";
-
cfg = config.services.yggdrasil;
- settingsProvided = cfg.settings != { };
- configFileProvided = cfg.configFile != null;
- format = pkgs.formats.json { };
+ # Paths for persistent keys
+ stateDir = "/var/lib/yggdrasil";
+ persistentKeyPath = "${stateDir}/private.pem";
+ legacyKeysPath = "${stateDir}/keys.json";
+
+ # Determine which key path to use:
+ # 1. If PrivateKeyPath is explicitly set, use that
+ # 2. If persistentKeys is enabled, use the auto-generated key path
+ effectiveKeyPath =
+ if cfg.settings.PrivateKeyPath != null then
+ cfg.settings.PrivateKeyPath
+ else if cfg.persistentKeys then
+ persistentKeyPath
+ else
+ null;
+
+ # Build base configuration with systemd credential path override
+ baseSettings =
+ cfg.settings
+ // (
+ if effectiveKeyPath != null then
+ {
+ PrivateKeyPath = "/private-key";
+ }
+ else
+ { }
+ );
+
+ # Remove null values that yggdrasil doesn't expect
+ cleanSettings = lib.filterAttrs (n: v: v != null) baseSettings;
+
+ # Generate configuration file from user settings
+ configFile = pkgs.writeTextFile {
+ name = "yggdrasil.conf";
+ text = builtins.toJSON cleanSettings;
+ };
in
{
imports = [
@@ -35,7 +68,59 @@ in
enable = lib.mkEnableOption "the yggdrasil system service";
settings = mkOption {
- type = format.type;
+ type = submodule {
+ freeformType = attrs;
+ options = {
+ PrivateKeyPath = mkOption {
+ type = nullOr path;
+ default = null;
+ example = "/run/secrets/yggdrasil-private-key";
+ description = ''
+ Path to the private key file on the host system.
+ When specified, the key will be loaded via systemd credentials
+ for secure access by the yggdrasil service.
+
+ Warning: Do not put private keys directly in the Nix store
+ as they would be world-readable!
+ '';
+ };
+
+ Peers = mkOption {
+ type = listOf str;
+ default = [ ];
+ example = [
+ "tcp://aa.bb.cc.dd:eeeee"
+ "tcp://[aaaa:bbbb:cccc:dddd::eeee]:fffff"
+ ];
+ description = ''
+ List of outbound peer connection strings.
+ Connection strings can contain options, see the yggdrasil documentation.
+ '';
+ };
+
+ Listen = mkOption {
+ type = listOf str;
+ default = [ ];
+ example = [
+ "tcp://0.0.0.0:xxxxx"
+ "tls://[::]:yyyyy"
+ ];
+ description = ''
+ Listen addresses for incoming connections.
+ You need listeners to accept incoming peerings from non-local nodes.
+ '';
+ };
+
+ AllowedPublicKeys = mkOption {
+ type = listOf str;
+ default = [ ];
+ description = ''
+ List of peer public keys to allow incoming peering connections from.
+ If left empty, all connections are allowed by default.
+ '';
+ };
+ };
+ };
default = { };
example = {
Peers = [
@@ -45,47 +130,35 @@ in
Listen = [
"tcp://0.0.0.0:xxxxx"
];
+ PrivateKeyPath = "/run/secrets/yggdrasil-key";
+ IfName = "ygg0";
+ IfMTU = 65535;
};
description = ''
- Configuration for yggdrasil, as a Nix attribute set.
+ Configuration for yggdrasil, as a structured Nix attribute set.
- Warning: this is stored in the WORLD-READABLE Nix store!
- Therefore, it is not appropriate for private keys. If you
- wish to specify the keys, use {option}`configFile`.
+ If you specify settings here, they will be used as persistent
+ configuration and Yggdrasil will retain the same configuration
+ (including IPv6 address if keys are provided) across restarts.
- If the {option}`persistentKeys` is enabled then the
- keys that are generated during activation will override
- those in {option}`settings` or
- {option}`configFile`.
-
- If no keys are specified then ephemeral keys are generated
+ If no settings are specified, ephemeral keys are generated
and the Yggdrasil interface will have a random IPv6 address
- each time the service is started. This is the default.
+ each time the service is started.
- If both {option}`configFile` and {option}`settings`
- are supplied, they will be combined, with values from
- {option}`configFile` taking precedence.
+ Use {option}`settings.PrivateKeyPath` to securely load private
+ keys from files owned by root via systemd credentials.
+
+ The most important options have dedicated NixOS options above.
+ You can also specify any other yggdrasil configuration option directly.
+
+ For a complete list of available options, see:
+ https://yggdrasil-network.github.io/configurationref.html
You can use the command `nix-shell -p yggdrasil --run "yggdrasil -genconf"`
to generate default configuration values with documentation.
'';
};
- configFile = mkOption {
- type = nullOr path;
- default = null;
- example = "/run/keys/yggdrasil.conf";
- description = ''
- A file which contains JSON or HJSON configuration for yggdrasil. See
- the {option}`settings` option for more information.
-
- Note: This file must not be larger than 1 MB because it is passed to
- the yggdrasil process via systemd‘s LoadCredential mechanism. For
- details, see and `man 5
- systemd.exec`.
- '';
- };
-
group = mkOption {
type = nullOr str;
default = null;
@@ -101,7 +174,7 @@ in
NixOS firewall blocks link-local communication, so in order to make
incoming local peering work you will also need to configure
`MulticastInterfaces` in your Yggdrasil configuration
- ({option}`settings` or {option}`configFile`). You will then have to
+ ({option}`settings`). You will then have to
add the ports that you configure there to your firewall configuration
({option}`networking.firewall.allowedTCPPorts` or
{option}`networking.firewall.interfaces..allowedTCPPorts`).
@@ -125,9 +198,18 @@ in
package = lib.mkPackageOption pkgs "yggdrasil" { };
persistentKeys = lib.mkEnableOption ''
- persistent keys. If enabled then keys will be generated once and Yggdrasil
- will retain the same IPv6 address when the service is
- restarted. Keys are stored at ${keysPath}
+ automatic generation and persistence of keys.
+ If enabled, a private key will be generated on first startup and stored
+ at ${persistentKeyPath}. This ensures the Yggdrasil node retains the same
+ IPv6 address across reboots.
+
+ If you have existing keys from a previous installation (in the old
+ keys.json format at ${legacyKeysPath}), they will be automatically
+ migrated to the new PEM format on first startup.
+
+ Note: This option is mutually exclusive with {option}`settings.PrivateKeyPath`.
+ If you want to use externally managed keys, use {option}`settings.PrivateKeyPath`
+ instead
'';
extraArgs = mkOption {
@@ -146,7 +228,6 @@ in
config = mkIf cfg.enable (
let
binYggdrasil = "${cfg.package}/bin/yggdrasil";
- binHjson = "${pkgs.hjson-go}/bin/hjson-cli";
in
{
assertions = [
@@ -154,67 +235,93 @@ in
assertion = config.networking.enableIPv6;
message = "networking.enableIPv6 must be true for yggdrasil to work";
}
+ {
+ assertion = !(cfg.settings ? PrivateKey);
+ message = ''
+ services.yggdrasil.settings.PrivateKey is not supported because it
+ would be stored in the world-readable Nix store.
+ Use services.yggdrasil.settings.PrivateKeyPath instead to securely load the private key from a file.
+ '';
+ }
+ {
+ assertion = !(cfg.persistentKeys && cfg.settings.PrivateKeyPath != null);
+ message = ''
+ services.yggdrasil.persistentKeys and services.yggdrasil.settings.PrivateKeyPath
+ are mutually exclusive. Use only one of them.
+ '';
+ }
];
- # This needs to be a separate service. The yggdrasil service fails if
- # this is put into its preStart.
+ # One-shot service to generate or migrate persistent keys
systemd.services.yggdrasil-persistent-keys = lib.mkIf cfg.persistentKeys {
+ description = "Generate or migrate Yggdrasil persistent keys";
wantedBy = [ "multi-user.target" ];
before = [ "yggdrasil.service" ];
- serviceConfig.Type = "oneshot";
- serviceConfig.RemainAfterExit = true;
+ serviceConfig = {
+ Type = "oneshot";
+ RemainAfterExit = true;
+ };
+ path = [
+ cfg.package
+ pkgs.jq
+ ];
script = ''
- if [ ! -e ${keysPath} ]
- then
- mkdir --mode=700 -p ${builtins.dirOf keysPath}
- ${binYggdrasil} -genconf -json \
- | ${pkgs.jq}/bin/jq \
- 'to_entries|map(select(.key|endswith("Key")))|from_entries' \
- > ${keysPath}
+ set -euo pipefail
+
+ # Create state directory with secure permissions
+ mkdir -p ${stateDir}
+ chmod 700 ${stateDir}
+
+ # If new format key already exists, nothing to do
+ if [ -f ${persistentKeyPath} ]; then
+ echo "Persistent key already exists at ${persistentKeyPath}"
+ exit 0
fi
+
+ # Check for legacy keys.json and migrate if found
+ if [ -f ${legacyKeysPath} ]; then
+ echo "Found legacy keys at ${legacyKeysPath}, migrating to PEM format..."
+
+ # Extract the PrivateKey from the legacy JSON format
+ PRIVATE_KEY_HEX=$(jq -r '.PrivateKey' ${legacyKeysPath})
+
+ if [ -n "$PRIVATE_KEY_HEX" ] && [ "$PRIVATE_KEY_HEX" != "null" ]; then
+ # Use yggdrasil's built-in -exportkey flag to convert to PEM format
+ # Create a minimal config with just the private key
+ echo "{\"PrivateKey\": \"$PRIVATE_KEY_HEX\"}" | yggdrasil -useconf -exportkey > ${persistentKeyPath}
+ chmod 600 ${persistentKeyPath}
+
+ echo "Successfully migrated legacy keys to ${persistentKeyPath}"
+ echo "You may remove the legacy file ${legacyKeysPath} after verifying the migration"
+ exit 0
+ fi
+ fi
+
+ # No existing keys found, generate new ones using yggdrasil
+ echo "Generating new persistent key at ${persistentKeyPath}..."
+ yggdrasil -genconf | yggdrasil -useconf -exportkey > ${persistentKeyPath}
+ chmod 600 ${persistentKeyPath}
+ echo "Successfully generated new persistent key"
'';
};
systemd.services.yggdrasil = {
description = "Yggdrasil Network Service";
- after = [ "network-pre.target" ];
+ after = [
+ "network-pre.target"
+ ]
+ ++ lib.optional cfg.persistentKeys "yggdrasil-persistent-keys.service";
wants = [ "network.target" ];
before = [ "network.target" ];
wantedBy = [ "multi-user.target" ];
- # This script first prepares the config file, then it starts Yggdrasil.
- # The preparation could also be done in ExecStartPre/preStart but only
- # systemd versions >= v252 support reading credentials in ExecStartPre. As
- # of February 2023, systemd v252 is not yet in the stable branch of NixOS.
- #
- # This could be changed in the future once systemd version v252 has
- # reached NixOS but it does not have to be. Config file preparation is
- # fast enough, it does not need elevated privileges, and `set -euo
- # pipefail` should make sure that the service is not started if the
- # preparation fails. Therefore, it is not necessary to move the
- # preparation to ExecStartPre.
- script = ''
- set -euo pipefail
-
- # prepare config file
- ${
- (
- if settingsProvided || configFileProvided || cfg.persistentKeys then
- "echo "
-
- + (lib.optionalString settingsProvided "'${builtins.toJSON cfg.settings}'")
- + (lib.optionalString configFileProvided "$(${binHjson} -c \"$CREDENTIALS_DIRECTORY/yggdrasil.conf\")")
- + (lib.optionalString cfg.persistentKeys "$(cat ${keysPath})")
- + " | ${pkgs.jq}/bin/jq -s add | ${binYggdrasil} -normaliseconf -useconf"
- else
- "${binYggdrasil} -genconf"
- )
- + " > /run/yggdrasil/yggdrasil.conf"
- }
-
- # start yggdrasil
- exec ${binYggdrasil} -useconffile /run/yggdrasil/yggdrasil.conf ${lib.strings.escapeShellArgs cfg.extraArgs}
- '';
+ script =
+ if cfg.settings != { } || cfg.persistentKeys then
+ # Use user settings or persistent keys configuration
+ "exec ${binYggdrasil} -useconffile ${configFile} ${lib.strings.escapeShellArgs cfg.extraArgs}"
+ else
+ # Generate and use ephemeral config
+ "exec ${binYggdrasil} -genconf | ${binYggdrasil} -useconf ${lib.strings.escapeShellArgs cfg.extraArgs}";
serviceConfig = {
ExecReload = "${pkgs.coreutils}/bin/kill -HUP $MAINPID";
@@ -224,8 +331,8 @@ in
StateDirectory = "yggdrasil";
RuntimeDirectory = "yggdrasil";
RuntimeDirectoryMode = "0750";
- BindReadOnlyPaths = lib.optional cfg.persistentKeys keysPath;
- LoadCredential = mkIf configFileProvided "yggdrasil.conf:${cfg.configFile}";
+ BindReadOnlyPaths = lib.optional (effectiveKeyPath != null) "%d/private-key:/private-key";
+ LoadCredential = lib.optional (effectiveKeyPath != null) "private-key:${effectiveKeyPath}";
AmbientCapabilities = "CAP_NET_ADMIN CAP_NET_BIND_SERVICE";
CapabilityBoundingSet = "CAP_NET_ADMIN CAP_NET_BIND_SERVICE";
@@ -265,6 +372,7 @@ in
maintainers = with lib.maintainers; [
gazally
nagy
+ pinpox
];
};
}
diff --git a/nixos/modules/virtualisation/qemu-vm.nix b/nixos/modules/virtualisation/qemu-vm.nix
index 18d0a9937152..abded7525062 100644
--- a/nixos/modules/virtualisation/qemu-vm.nix
+++ b/nixos/modules/virtualisation/qemu-vm.nix
@@ -1143,6 +1143,85 @@ in
'';
};
+ virtualisation.credentials = mkOption {
+ description = ''
+ Credentials to pass to the VM using systemd's credential system.
+
+ See {manpage}`systemd.exec(5)` , {manpage}`systemd-creds(1)` and https://systemd.io/CREDENTIALS/ for more
+ information about systemd credentials.
+ '';
+ default = { };
+ example = {
+ database-password = {
+ text = "my-secret-password";
+ };
+ ssl-cert = {
+ source = "./cert.pem";
+ };
+ binary-key = {
+ mechanism = "fw_cfg";
+ source = "./private.der";
+ };
+ config-file = {
+ mechanism = "smbios";
+ text = ''
+ [database]
+ host=localhost
+ port=5432
+ '';
+ };
+ };
+ type = types.attrsOf (
+ lib.types.submodule (
+ {
+ name,
+ options,
+ config,
+ ...
+ }:
+ {
+ options = {
+ mechanism = lib.mkOption {
+ type = lib.types.enum [
+ "fw_cfg"
+ "smbios"
+ ];
+ default = if pkgs.stdenv.hostPlatform.isx86 then "smbios" else "fw_cfg";
+ defaultText = lib.literalExpression ''if pkgs.stdenv.hostPlatform.isx86 then "smbios" else "fw_cfg"'';
+ description = ''
+ The mechanism used to pass the credential to the VM.
+ '';
+ };
+ source = lib.mkOption {
+ type = lib.types.nullOr (lib.types.pathWith { });
+ default = null;
+ description = ''
+ Source file on the host containing the credential data.
+ '';
+ };
+ text = lib.mkOption {
+ default = null;
+ type = lib.types.nullOr lib.types.str;
+ description = ''
+ Text content of the credential.
+
+ For binary data or when the credential content should come from
+ an existing file, use `source` instead.
+
+ ::: {.warning}
+ The text here is stored in the host's nix store as a file.
+ :::
+ '';
+ };
+ };
+ config.source = lib.mkIf (config.text != null) (
+ lib.mkDerivedConfig options.text (pkgs.writeText name)
+ );
+ }
+ )
+ );
+ };
+
};
config = {
@@ -1331,6 +1410,14 @@ in
"-global"
"driver=cfi.pflash01,property=secure,value=on"
])
+ (lib.mapAttrsToList (
+ name: cred:
+ if cred.mechanism == "fw_cfg" then
+ "-fw_cfg name=opt/io.systemd.credentials/${name},file=${cred.source}"
+ # smbios - must use base64 encoding (SMBIOS can't handle null bytes)
+ else
+ "-smbios type=11,path=<(echo 'io.systemd.credential.binary:${name}='; base64 -w0 '${cred.source}')"
+ ) cfg.credentials)
];
virtualisation.qemu.drives = mkMerge [
diff --git a/nixos/tests/all-tests.nix b/nixos/tests/all-tests.nix
index be7df9027bb4..59e67971f083 100644
--- a/nixos/tests/all-tests.nix
+++ b/nixos/tests/all-tests.nix
@@ -1313,6 +1313,14 @@ in
pyload = runTest ./pyload.nix;
qbittorrent = runTest ./qbittorrent.nix;
qboot = handleTestOn [ "x86_64-linux" "i686-linux" ] ./qboot.nix { };
+ qemu-vm-credentials-fwcfg = runTest {
+ imports = [ ./qemu-vm-credentials.nix ];
+ _module.args.mechanism = "fw_cfg";
+ };
+ qemu-vm-credentials-smbios = runTestOn [ "x86_64-linux" ] {
+ imports = [ ./qemu-vm-credentials.nix ];
+ _module.args.mechanism = "smbios";
+ };
qemu-vm-external-disk-image = runTest ./qemu-vm-external-disk-image.nix;
qemu-vm-restrictnetwork = handleTest ./qemu-vm-restrictnetwork.nix { };
qemu-vm-store = runTest ./qemu-vm-store.nix;
diff --git a/nixos/tests/cgit.nix b/nixos/tests/cgit.nix
index 2c48e6bde47d..a7839e24c4a4 100644
--- a/nixos/tests/cgit.nix
+++ b/nixos/tests/cgit.nix
@@ -39,6 +39,23 @@ in
":date.txt"
];
};
+ gitHttpBackend.checkExportOkFiles = false;
+ };
+ services.cgit."check.localhost" = {
+ enable = true;
+ scanPath = "/tmp/git";
+ settings = {
+ strict-export = "git-daemon-export-ok";
+ };
+ gitHttpBackend.checkExportOkFiles = true;
+ };
+ services.cgit."no-git-http-backend.localhost" = {
+ enable = true;
+ scanPath = "/tmp/git";
+ settings = {
+ strict-export = "git-daemon-export-ok";
+ };
+ gitHttpBackend.enable = false;
};
environment.systemPackages = [ pkgs.git ];
@@ -107,5 +124,25 @@ in
server.fail(
"curl -fsS 'http://localhost/%28c%29git/some-repo/about/' | grep -F 'cgit NixOS Test at'"
)
+
+ # EXPORT_ALL is not set with checkExportOkFiles = true
+ server.succeed("touch /tmp/git/some-repo/git-daemon-export-ok")
+ server.succeed(
+ "git clone http://check.localhost/some-repo $(mktemp -d)"
+ )
+ server.succeed("rm /tmp/git/some-repo/git-daemon-export-ok")
+ server.fail(
+ "git clone http://check.localhost/some-repo $(mktemp -d)"
+ )
+
+ # Disabling the git-http-backend-works
+ server.succeed("touch /tmp/git/some-repo/git-daemon-export-ok")
+ server.succeed(
+ "git clone http://no-git-http-backend.localhost/some-repo $(mktemp -d)"
+ )
+ server.succeed("rm /tmp/git/some-repo/git-daemon-export-ok")
+ server.fail(
+ "git clone http://no-git-http-backend.localhost/some-repo $(mktemp -d)"
+ )
'';
}
diff --git a/nixos/tests/qemu-vm-credentials.nix b/nixos/tests/qemu-vm-credentials.nix
new file mode 100644
index 000000000000..9ee2d270d8f0
--- /dev/null
+++ b/nixos/tests/qemu-vm-credentials.nix
@@ -0,0 +1,83 @@
+{
+ lib,
+ pkgs,
+ mechanism,
+ ...
+}:
+
+let
+ secret = ''
+ foo
+ bar
+ baz
+ '';
+ secret-file = "bar";
+in
+
+{
+ name = "qemu-vm-credentials-${mechanism}";
+
+ meta.maintainers = with lib.maintainers; [ arianvp ];
+
+ nodes = {
+ machine = {
+ virtualisation.credentials = {
+ secret = {
+ inherit mechanism;
+ text = secret;
+ };
+ secret-default-mechanism = {
+ text = "default-mechanism";
+ };
+ secret-file-nix-store = {
+ inherit mechanism;
+ source = pkgs.writeText "secret-file-nix-store" secret-file;
+ };
+ secret-file-host = {
+ inherit mechanism;
+ source = "./secret-file-host";
+ };
+ secret-file-host-binary = {
+ inherit mechanism;
+ source = "./secret-file-host-binary";
+ };
+ };
+ };
+ };
+
+ testScript = ''
+ import base64
+ secret_file_host = "baz"
+ # Binary data with null bytes, high bytes, and all sorts of problematic characters
+ secret_file_host_binary = bytes([
+ 0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, # null and control chars
+ 0x08, 0x09, 0x0A, 0x0B, 0x0C, 0x0D, 0x0E, 0x0F,
+ 0xDE, 0xAD, 0xBE, 0xEF, # classic binary pattern
+ 0xFF, 0xFE, 0xFD, 0xFC, # high bytes
+ 0x00, 0x00, 0x00, 0x00, # multiple nulls
+ 0x80, 0x81, 0x82, 0x83, # more high bytes
+ ])
+
+ with open(machine.state_dir / "secret-file-host", "w") as f:
+ f.write(secret_file_host)
+ with open(machine.state_dir / "secret-file-host-binary", "wb") as f2:
+ f2.write(secret_file_host_binary)
+
+
+ # Test text credential
+ t.assertEqual(machine.succeed("systemd-creds --system cat secret").strip(), "foo\nbar\nbaz")
+
+ t.assertEqual(machine.succeed("systemd-creds --system cat secret-default-mechanism").strip(), "default-mechanism")
+
+ # Test credential from nix store
+ t.assertEqual(machine.succeed("systemd-creds --system cat secret-file-nix-store").strip(), "${secret-file}")
+
+ # Test credential from host file
+ t.assertEqual(machine.succeed("systemd-creds --system cat secret-file-host").strip(), secret_file_host)
+
+ # Test binary credential - verify exact binary content
+ result = machine.succeed("systemd-creds --system cat secret-file-host-binary --transcode=base64").strip()
+ expected = base64.b64encode(secret_file_host_binary).decode('ascii')
+ t.assertEqual(result, expected, f"Binary credential mismatch: got {result}, expected {expected}")
+ '';
+}
diff --git a/nixos/tests/systemd-initrd-credentials.nix b/nixos/tests/systemd-initrd-credentials.nix
index 50893d2cec78..7904ddc58476 100644
--- a/nixos/tests/systemd-initrd-credentials.nix
+++ b/nixos/tests/systemd-initrd-credentials.nix
@@ -1,32 +1,31 @@
-{ lib, pkgs, ... }:
{
name = "systemd-initrd-credentials";
- nodes.machine =
- { pkgs, ... }:
- {
- virtualisation = {
- qemu.options = [
- "-smbios type=11,value=io.systemd.credential:cred-smbios=secret-smbios"
- ];
- };
+ nodes.machine = {
+ testing.initrdBackdoor = true;
- boot.initrd.availableKernelModules = [ "dmi_sysfs" ];
-
- boot.kernelParams = [ "systemd.set_credential=cred-cmdline:secret-cmdline" ];
-
- boot.initrd.systemd = {
- enable = true;
- };
+ virtualisation.credentials.cred-test.text = "secret-test";
+ virtualisation.credentials.cred-test-fw_cfg = {
+ mechanism = "fw_cfg";
+ text = "secret-fw_cfg";
};
+ boot.initrd.availableKernelModules = [
+ "dmi_sysfs"
+ "qemu_fw_cfg"
+ ];
+
+ boot.kernelParams = [ "systemd.set_credential=cred-cmdline:secret-cmdline" ];
+
+ boot.initrd.systemd.enable = true;
+ };
+
testScript = ''
- machine.wait_for_unit("multi-user.target")
+ machine.wait_for_unit("initrd.target")
- # Check credential passed via kernel command line
- assert "secret-cmdline" in machine.succeed("systemd-creds --system cat cred-cmdline")
+ t.assertIn("secret-cmdline", machine.succeed("systemd-creds --system cat cred-cmdline"))
+ t.assertIn("secret-test", machine.succeed("systemd-creds --system cat cred-test"))
+ t.assertIn("secret-fw_cfg", machine.succeed("systemd-creds --system cat cred-test-fw_cfg"))
- # Check credential passed via SMBIOS
- assert "secret-smbios" in machine.succeed("systemd-creds --system cat cred-smbios")
'';
}
diff --git a/nixos/tests/yggdrasil.nix b/nixos/tests/yggdrasil.nix
index e4b15a841cf4..01a9c4cf1d8a 100644
--- a/nixos/tests/yggdrasil.nix
+++ b/nixos/tests/yggdrasil.nix
@@ -4,6 +4,16 @@ let
PublicKey = "3e91ec9e861960d86e1ce88051f97c435bdf2859640ab681dfa906eb45ad5182";
PrivateKey = "a867f9e078e4ce58d310cf5acd4622d759e2a21df07e1d6fc380a2a26489480d3e91ec9e861960d86e1ce88051f97c435bdf2859640ab681dfa906eb45ad5182";
};
+ # Frank has a legacy keys.json that should be migrated
+ # This is the same key as Alice but in the old hex format
+ frankIp6 = aliceIp6; # Should get same IP after migration
+ frankLegacyKeys = {
+ # The old format stored PrivateKey as 128 hex chars (64 bytes = seed + pubkey)
+ # This corresponds to Alice's key
+ PrivateKey =
+ "a867f9e078e4ce58d310cf5acd4622d759e2a21df07e1d6fc380a2a264894809" + aliceKeys.PublicKey;
+ PublicKey = aliceKeys.PublicKey;
+ };
bobIp6 = "202:a483:73a4:9f2d:a559:4a19:bc9:8458";
bobPrefix = "302:a483:73a4:9f2d";
bobConfig = {
@@ -153,6 +163,62 @@ in
persistentKeys = true;
};
};
+
+ # Eve uses persistentKeys for automatic key generation.
+ eve =
+ { ... }:
+ {
+ networking.firewall.allowedTCPPorts = [ 43211 ];
+ services.yggdrasil = {
+ enable = true;
+ persistentKeys = true;
+ openMulticastPort = true;
+ settings = {
+ IfName = "ygg0";
+ MulticastInterfaces = [
+ {
+ Regex = ".*";
+ Beacon = true;
+ Listen = true;
+ Port = 43211;
+ }
+ ];
+ };
+ };
+ };
+
+ # Frank tests migration from legacy keys.json format
+ frank =
+ { pkgs, ... }:
+ {
+ networking.firewall.allowedTCPPorts = [ 43212 ];
+
+ # Pre-populate the legacy keys.json file before the service starts
+ system.activationScripts.yggdrasil-legacy-keys = ''
+ mkdir -p /var/lib/yggdrasil
+ cat > /var/lib/yggdrasil/keys.json << 'EOF'
+ ${builtins.toJSON frankLegacyKeys}
+ EOF
+ chmod 600 /var/lib/yggdrasil/keys.json
+ '';
+
+ services.yggdrasil = {
+ enable = true;
+ persistentKeys = true;
+ openMulticastPort = true;
+ settings = {
+ IfName = "ygg0";
+ MulticastInterfaces = [
+ {
+ Regex = ".*";
+ Beacon = true;
+ Listen = true;
+ Port = 43212;
+ }
+ ];
+ };
+ };
+ };
};
testScript = ''
@@ -164,13 +230,38 @@ in
bob.start()
carol.start()
+ eve.start()
+ frank.start()
bob.wait_for_unit("default.target")
carol.wait_for_unit("yggdrasil.service")
+ # Eve uses persistentKeys - verify the key generation service ran
+ eve.wait_for_unit("yggdrasil-persistent-keys.service")
+ eve.wait_for_unit("yggdrasil.service")
+ eve.succeed("test -f /var/lib/yggdrasil/private.pem")
+ eve.succeed("grep -q 'BEGIN PRIVATE KEY' /var/lib/yggdrasil/private.pem")
+
+ # Frank tests migration from legacy keys.json format
+ frank.wait_for_unit("yggdrasil-persistent-keys.service")
+ frank.wait_for_unit("yggdrasil.service")
+ # Verify migration happened: private.pem should exist
+ frank.succeed("test -f /var/lib/yggdrasil/private.pem")
+ frank.succeed("grep -q 'BEGIN PRIVATE KEY' /var/lib/yggdrasil/private.pem")
+ # Legacy file should still exist (not deleted, user should verify and remove)
+ frank.succeed("test -f /var/lib/yggdrasil/keys.json")
+
ip_addr_show = "ip -o -6 addr show dev ygg0 scope global"
carol.wait_until_succeeds(f"[ `{ip_addr_show} | grep -v tentative | wc -l` -ge 1 ]")
carol_ip6 = re.split(" +|/", carol.succeed(ip_addr_show))[3]
+ eve.wait_until_succeeds(f"[ `{ip_addr_show} | grep -v tentative | wc -l` -ge 1 ]")
+ eve_ip6 = re.split(" +|/", eve.succeed(ip_addr_show))[3]
+
+ # Verify Frank got the expected IP after migration (same key as Alice = same IP)
+ frank.wait_until_succeeds(f"[ `{ip_addr_show} | grep -v tentative | wc -l` -ge 1 ]")
+ frank_ip6 = re.split(" +|/", frank.succeed(ip_addr_show))[3]
+ assert frank_ip6 == "${frankIp6}", f"Frank's IP {frank_ip6} doesn't match expected ${frankIp6} after migration"
+
# If Alice can talk to Carol, then Bob's outbound peering and Carol's
# local peering have succeeded and everybody is connected.
alice.wait_until_succeeds(f"ping -c 1 {carol_ip6}")
@@ -186,6 +277,10 @@ in
carol.fail("journalctl -u dhcpcd | grep ygg0")
+ # Eve should be able to communicate with the network via multicast peering
+ eve.wait_until_succeeds(f"ping -c 1 {carol_ip6}")
+ carol.wait_until_succeeds(f"ping -c 1 {eve_ip6}")
+
alice.wait_for_unit("httpd.service")
carol.succeed("curl --fail -g http://[${aliceIp6}]")
carol.succeed("curl --fail -g http://[${danIp6}]")
diff --git a/pkgs/applications/emulators/wine/base.nix b/pkgs/applications/emulators/wine/base.nix
index 4343843d42a8..6ec634d47d82 100644
--- a/pkgs/applications/emulators/wine/base.nix
+++ b/pkgs/applications/emulators/wine/base.nix
@@ -221,6 +221,7 @@ stdenv.mkDerivation (
)
)
);
+ env.NIX_CFLAGS_COMPILE = lib.optionalString (wineRelease == "yabridge") "-std=gnu17";
# Don't shrink the ELF RPATHs in order to keep the extra RPATH
# elements specified above.
diff --git a/pkgs/by-name/am/amd-debug-tools/package.nix b/pkgs/by-name/am/amd-debug-tools/package.nix
new file mode 100644
index 000000000000..d31c9f3cdc91
--- /dev/null
+++ b/pkgs/by-name/am/amd-debug-tools/package.nix
@@ -0,0 +1,63 @@
+{
+ acpica-tools,
+ ethtool,
+ fetchgit,
+ lib,
+ libdisplay-info,
+ python3Packages,
+}:
+
+python3Packages.buildPythonApplication rec {
+ pname = "amd-debug-tools";
+ version = "0.2.10";
+ pyproject = true;
+
+ src = fetchgit {
+ url = "https://git.kernel.org/pub/scm/linux/kernel/git/superm1/amd-debug-tools.git";
+ rev = version;
+ hash = "sha256-tbykQ8tc6YKHjKEHA9Ml7Z7MjDQzMGXtTwMG9buiovg=";
+ };
+
+ build-system = with python3Packages; [
+ setuptools
+ setuptools-scm
+ ];
+
+ dependencies = with python3Packages; [
+ dbus-fast
+ jinja2
+ matplotlib
+ packaging
+ pandas
+ pyudev
+ seaborn
+ tabulate
+ ];
+
+ # Not available in nixpkgs as of 2025-11-15.
+ pythonRemoveDeps = [
+ "cysystemd"
+ ];
+
+ makeWrapperArgs = [
+ "--prefix PATH : ${
+ lib.makeBinPath [
+ acpica-tools
+ ethtool
+ libdisplay-info
+ ]
+ }"
+ ];
+
+ # Tests require hardware-specific features
+ doCheck = false;
+
+ meta = {
+ description = "Debug tools for AMD systems";
+ homepage = "https://git.kernel.org/pub/scm/linux/kernel/git/superm1/amd-debug-tools.git/";
+ license = lib.licenses.mit;
+ maintainers = with lib.maintainers; [ samuela ];
+ platforms = lib.platforms.linux;
+ mainProgram = "amd-s2idle";
+ };
+}
diff --git a/pkgs/by-name/an/angband/package.nix b/pkgs/by-name/an/angband/package.nix
index 13065d826779..470e8491151b 100644
--- a/pkgs/by-name/an/angband/package.nix
+++ b/pkgs/by-name/an/angband/package.nix
@@ -13,13 +13,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "angband";
- version = "4.2.5";
+ version = "4.2.6";
src = fetchFromGitHub {
owner = "angband";
repo = "angband";
rev = finalAttrs.version;
- hash = "sha256-XH2FUTJJaH5TqV2UD1CKKAXE4CRAb6zfg1UQ79a15k0=";
+ hash = "sha256-lx2EfE3ylcH1vLAHwNT1me1l4e4Jspkw4YJIAOlu/0E=";
};
nativeBuildInputs = [ autoreconfHook ];
diff --git a/pkgs/by-name/av/avalonia/package.nix b/pkgs/by-name/av/avalonia/package.nix
index bf3cdef4efb5..4b39631b3371 100644
--- a/pkgs/by-name/av/avalonia/package.nix
+++ b/pkgs/by-name/av/avalonia/package.nix
@@ -46,14 +46,14 @@ stdenvNoCC.mkDerivation (
}
rec {
pname = "Avalonia";
- version = "11.3.7";
+ version = "11.3.9";
src = fetchFromGitHub {
owner = "AvaloniaUI";
repo = "Avalonia";
tag = version;
fetchSubmodules = true;
- hash = "sha256-ZzMb8GGdEQsn4me3AewRJsBxGJ6M/dZ+mlQOYY3xaKs=";
+ hash = "sha256-qvkQKlz9GQayAxCPITYJbCk+w4d9xJNo+P1I9J1SYho=";
};
patches = [
diff --git a/pkgs/by-name/be/beszel/package.nix b/pkgs/by-name/be/beszel/package.nix
index f6948cf2fcd6..6403a68c4775 100644
--- a/pkgs/by-name/be/beszel/package.nix
+++ b/pkgs/by-name/be/beszel/package.nix
@@ -8,13 +8,13 @@
}:
buildGoModule rec {
pname = "beszel";
- version = "0.16.1";
+ version = "0.17.0";
src = fetchFromGitHub {
owner = "henrygd";
repo = "beszel";
tag = "v${version}";
- hash = "sha256-fPVjJfMaTSPolB6l2t1b2CjSaX3Gc4/0Nruy4OY9RAc=";
+ hash = "sha256-MY/rsWdIiYsqcw6gqDkfA8A/Ied3OSHfJI3KUBxoRKc=";
};
webui = buildNpmPackage {
@@ -48,10 +48,10 @@ buildGoModule rec {
sourceRoot = "${src.name}/internal/site";
- npmDepsHash = "sha256-YVYHNAf0JdTpqUYq5JosuzWLOsZkbX2okNPj5JQTOto=";
+ npmDepsHash = "sha256-1au4kSxyjdwFExIoUBSPf/At0jQsfbzlEXuigygBTRM=";
};
- vendorHash = "sha256-fXiCddu7DE6NLNJkYupQsAK0xMBoL0K5T7Ig0IuIbD4=";
+ vendorHash = "sha256-gfQU3jGwTGmMJIy9KTjk/Ncwpk886vMo4CJvm5Y5xpA=";
preBuild = ''
mkdir -p internal/site/dist
diff --git a/pkgs/by-name/bl/blobby/package.nix b/pkgs/by-name/bl/blobby/package.nix
index e61cc1d52f35..ceb650d1daba 100644
--- a/pkgs/by-name/bl/blobby/package.nix
+++ b/pkgs/by-name/bl/blobby/package.nix
@@ -1,7 +1,7 @@
{
lib,
stdenv,
- fetchurl,
+ fetchFromGitHub,
SDL2,
SDL2_image,
libGLU,
@@ -17,11 +17,13 @@
stdenv.mkDerivation {
pname = "blobby-volley";
- version = "1.1.1";
+ version = "1.1.1-unstable-2025-07-26";
- src = fetchurl {
- url = "mirror://sourceforge/blobby/Blobby%20Volley%202%20%28Linux%29/1.1.1/blobby2-linux-1.1.1.tar.gz";
- sha256 = "sha256-NX7lE+adO1D2f8Bj1Ky3lZpf6Il3gX8KqxTMxw2yFLo=";
+ src = fetchFromGitHub {
+ owner = "danielknobe";
+ repo = "blobbyvolley2";
+ rev = "9bc797f0fade4766f2d98f8cf4db0a8a7b82a950";
+ sha256 = "sha256-0e1YOwHX2x/snkyH1qeQowJr1YGdExstUoCBOhG1kBU=";
};
nativeBuildInputs = [
@@ -39,10 +41,6 @@ stdenv.mkDerivation {
zlib
];
- preConfigure = ''
- sed -e '1i#include ' -i src/NetworkMessage.cpp
- '';
-
inherit unzip;
postInstall = ''
diff --git a/pkgs/by-name/br/broadcom-bt-firmware/package.nix b/pkgs/by-name/br/broadcom-bt-firmware/package.nix
index 2824fd6330f4..dc53849c9a13 100644
--- a/pkgs/by-name/br/broadcom-bt-firmware/package.nix
+++ b/pkgs/by-name/br/broadcom-bt-firmware/package.nix
@@ -48,5 +48,6 @@ stdenvNoCC.mkDerivation rec {
license = lib.licenses.unfree;
platforms = lib.platforms.linux;
maintainers = with lib.maintainers; [ zraexy ];
+ sourceProvenance = with lib.sourceTypes; [ binaryFirmware ];
};
}
diff --git a/pkgs/by-name/cl/clapper-enhancers/package.nix b/pkgs/by-name/cl/clapper-enhancers/package.nix
index 39802f3b87fc..96bba08885a2 100644
--- a/pkgs/by-name/cl/clapper-enhancers/package.nix
+++ b/pkgs/by-name/cl/clapper-enhancers/package.nix
@@ -9,6 +9,8 @@
libpeas2,
json-glib,
libsoup_3,
+ libmicrodns,
+ sqlite,
glib,
clapper-unwrapped,
gst_all_1,
@@ -17,13 +19,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "clapper-enhancers";
- version = "0.8.3";
+ version = "0.10.0";
src = fetchFromGitHub {
owner = "Rafostar";
repo = "clapper-enhancers";
tag = finalAttrs.version;
- hash = "sha256-uj0ZZrS2Y896EDWeBsU3Q3S2kFdEg5FQkBOcI97FFWc=";
+ hash = "sha256-9ix58RlJKpNXq7L6hRBySaNA9umxcg52tJmqyv1x1Wg=";
};
nativeBuildInputs = [
@@ -39,6 +41,8 @@ stdenv.mkDerivation (finalAttrs: {
libpeas2
json-glib
libsoup_3
+ libmicrodns # for feature "control-hub"
+ sqlite # for feature "recall"
glib
clapper-unwrapped
gst_all_1.gstreamer
diff --git a/pkgs/by-name/cl/clapper-unwrapped/package.nix b/pkgs/by-name/cl/clapper-unwrapped/package.nix
index c5bc14eea542..5e10fd2d4077 100644
--- a/pkgs/by-name/cl/clapper-unwrapped/package.nix
+++ b/pkgs/by-name/cl/clapper-unwrapped/package.nix
@@ -18,11 +18,12 @@
libmicrodns,
glib-networking,
libpeas2,
+ graphviz,
}:
stdenv.mkDerivation (finalAttrs: {
pname = "clapper-unwrapped";
- version = "0.8.0";
+ version = "0.10.0";
outputs = [
"out"
@@ -34,7 +35,7 @@ stdenv.mkDerivation (finalAttrs: {
owner = "Rafostar";
repo = "clapper";
tag = finalAttrs.version;
- hash = "sha256-Yb2fWsdd8jhxkGWKanLn7CAuF4MjyQ27XTrO8ja3hfs=";
+ hash = "sha256-WU004/ea3H0eBYd6XPDsEQaoAuShvZzOu3QOweFvdIo=";
};
nativeBuildInputs = [
@@ -62,6 +63,7 @@ stdenv.mkDerivation (finalAttrs: {
libsoup_3
libmicrodns
libpeas2
+ graphviz # for feature "pipeline-preview"
];
postPatch = ''
diff --git a/pkgs/by-name/dp/dprint/package.nix b/pkgs/by-name/dp/dprint/package.nix
index dbea0403ed51..ea88b2dca244 100644
--- a/pkgs/by-name/dp/dprint/package.nix
+++ b/pkgs/by-name/dp/dprint/package.nix
@@ -12,7 +12,7 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "dprint";
- version = "0.51.0";
+ version = "0.51.1";
# Prefer repository rather than crate here
# - They have Cargo.lock in the repository
@@ -21,10 +21,10 @@ rustPlatform.buildRustPackage (finalAttrs: {
owner = "dprint";
repo = "dprint";
tag = finalAttrs.version;
- hash = "sha256-ulOIlRuajUbnow8KelnSeHUTxR7A9HC2LWj3aQZsn4A=";
+ hash = "sha256-jj9SsVWCw2Fzoj1ome2rJ9bADFgREUdQf0jfOpt8PkU=";
};
- cargoHash = "sha256-/rQoVXrULwgGAEkMROqwASKRcNKwljS7nC35Ve3yk3U=";
+ cargoHash = "sha256-zjk2LrljubzfNk20y4XTcnqiQQsBlc2aRwAhH8wpv3Q=";
nativeBuildInputs = [ installShellFiles ];
diff --git a/pkgs/by-name/fi/files-cli/package.nix b/pkgs/by-name/fi/files-cli/package.nix
index 9005fed6ae7e..ff83bd43eea0 100644
--- a/pkgs/by-name/fi/files-cli/package.nix
+++ b/pkgs/by-name/fi/files-cli/package.nix
@@ -8,16 +8,16 @@
buildGoModule rec {
pname = "files-cli";
- version = "2.15.177";
+ version = "2.15.178";
src = fetchFromGitHub {
repo = "files-cli";
owner = "files-com";
rev = "v${version}";
- hash = "sha256-czc6CZL28Gws7h6CjGg0Ml2+X2GjIGBykbZL0qe66us=";
+ hash = "sha256-03dADzK1LgD3IqYdDqUtZO1yOIya85cefA1cd0/70qQ=";
};
- vendorHash = "sha256-PsPaRbC9j4zfLfdS6LodkSxmJNt9K9Ig1XpLBmR3SMQ=";
+ vendorHash = "sha256-5ONoYzrULR2Z3x/EPwkBgxOm78XBdlCosWSKhZYlKco=";
ldflags = [
"-s"
diff --git a/pkgs/by-name/fu/furtherance/package.nix b/pkgs/by-name/fu/furtherance/package.nix
index 112f4107ebd2..a712f87b009c 100644
--- a/pkgs/by-name/fu/furtherance/package.nix
+++ b/pkgs/by-name/fu/furtherance/package.nix
@@ -13,16 +13,16 @@
}:
rustPlatform.buildRustPackage (finalAttrs: {
pname = "furtherance";
- version = "25.3.0";
+ version = "26.1.0";
src = fetchFromGitHub {
owner = "unobserved-io";
repo = "Furtherance";
rev = finalAttrs.version;
- hash = "sha256-LyGO+fbsu16Us0+sK0T6HlGq7EwZWSetd+gCIKKEbkk=";
+ hash = "sha256-EwOLTq82NNuRMUCFSKryl6fBtXxhNps+tzOo3Uhe3yA=";
};
- cargoHash = "sha256-j/5O40k12rl/gmRc1obo9ImdkZ0Mdrke2PCf6tFCWIo=";
+ cargoHash = "sha256-iJW7tnGnwdp494ylJyNEuC80SIV8wRu8ygd5lcul2KA=";
nativeBuildInputs = [
pkg-config
diff --git a/pkgs/by-name/gc/gcli/package.nix b/pkgs/by-name/gc/gcli/package.nix
index 65dbcb1e2419..ce68dfada20c 100644
--- a/pkgs/by-name/gc/gcli/package.nix
+++ b/pkgs/by-name/gc/gcli/package.nix
@@ -11,13 +11,13 @@
stdenv.mkDerivation rec {
pname = "gcli";
- version = "2.9.1";
+ version = "2.10.0";
src = fetchFromGitHub {
owner = "herrhotzenplotz";
repo = "gcli";
rev = "v${version}";
- hash = "sha256-Y6wAGg32ZnPAoFB9uzkPyeSAWATHpkBvNASZQ8S+SYc=";
+ hash = "sha256-2L6/ZYxRY2xrTxr/oD02xCRqdk7VWrPlFwr8wU8C2x8=";
};
nativeBuildInputs = [
diff --git a/pkgs/by-name/gf/gfxreconstruct/package.nix b/pkgs/by-name/gf/gfxreconstruct/package.nix
index b04642602e79..05d97039f45e 100644
--- a/pkgs/by-name/gf/gfxreconstruct/package.nix
+++ b/pkgs/by-name/gf/gfxreconstruct/package.nix
@@ -18,24 +18,16 @@
stdenv.mkDerivation rec {
pname = "gfxreconstruct";
- version = "1.0.4";
+ version = "1.0.4-unstable-2025-10-30";
src = fetchFromGitHub {
owner = "LunarG";
repo = "gfxreconstruct";
- tag = "v${version}";
- hash = "sha256-MuCdJoBFxKwDCOCltlU3oBS9elFS6F251dHjHcIb4Jg=";
+ rev = "4f1fa3aa9870b00404e6597283b2032a885303b3";
+ hash = "sha256-HwGmtkVQJirKikb37A/dQeEr3AWmqJMfBj46UKsS5m8=";
fetchSubmodules = true;
};
- cmakeFlags = [
- # The CMakeLists.txt is actually 3.10 compatible, but it specifies 3.5 as `CMAKE_VERSION_MINIMUM`
- "-DCMAKE_POLICY_VERSION_MINIMUM=3.10"
- ];
-
- # Workaround for "error: ... class std::__cxx11::wstring_convert' is deprecated [-Werror=deprecated-declarations]"
- env.NIX_CFLAGS_COMPILE = "-Wno-error=deprecated-declarations";
-
buildInputs = [
libX11
libxcb
@@ -72,6 +64,9 @@ stdenv.mkDerivation rec {
--prefix VK_ADD_LAYER_PATH : "$out/share/vulkan/explicit_layer.d"
wrapProgram $out/bin/gfxrecon-replay \
--prefix LD_LIBRARY_PATH : ${lib.makeLibraryPath [ vulkan-loader ]}
+
+ # Remove unrelated files that got installed
+ rm -r $out/lib/{cmake,pkgconfig}
'';
meta = {
diff --git a/pkgs/by-name/gp/gpupad/package.nix b/pkgs/by-name/gp/gpupad/package.nix
index 25c740910bf0..69ec7e4756b7 100644
--- a/pkgs/by-name/gp/gpupad/package.nix
+++ b/pkgs/by-name/gp/gpupad/package.nix
@@ -2,6 +2,7 @@
lib,
stdenv,
fetchFromGitHub,
+ fetchpatch,
cmake,
glslang,
@@ -29,6 +30,12 @@ stdenv.mkDerivation (finalAttrs: {
patches = [
# the current version of glslang no longer separates its libs into sublibs
./glslang-use-combined-lib.patch
+
+ (fetchpatch {
+ name = "add-missing-inline.patch";
+ url = "https://github.com/houmain/gpupad/commit/52fcb3619e5e2698a8c11a97668670a5cd0531a8.patch";
+ hash = "sha256-FnC5uKickZVPVr+y1Thvtk+Xi38V0AHBYGU+x64EXrA=";
+ })
];
strictDeps = true;
diff --git a/pkgs/by-name/hu/hugo/package.nix b/pkgs/by-name/hu/hugo/package.nix
index 79717445184d..ce64e7075190 100644
--- a/pkgs/by-name/hu/hugo/package.nix
+++ b/pkgs/by-name/hu/hugo/package.nix
@@ -11,16 +11,16 @@
buildGoModule (finalAttrs: {
pname = "hugo";
- version = "0.153.3";
+ version = "0.154.2";
src = fetchFromGitHub {
owner = "gohugoio";
repo = "hugo";
tag = "v${finalAttrs.version}";
- hash = "sha256-EJYBIElh1akj8/cYzd/5hUNJtmFK/BxgWTg5jo2/xS4=";
+ hash = "sha256-DVNuVhybpi9LOSciCftEVzWdMYsnQKREKFlalB4QMX8=";
};
- vendorHash = "sha256-cTrqnZdRCLthZCpXqbfIS1quySyB2lWxbxP/4k2nASQ=";
+ vendorHash = "sha256-7hI2FblqJQYhoWX2K+J+/HIY8CzQ+tBZmForS6gEnoE=";
checkFlags =
let
diff --git a/pkgs/by-name/io/iosevka/package.nix b/pkgs/by-name/io/iosevka/package.nix
index 2ce274806b4a..97cea1edc3c0 100644
--- a/pkgs/by-name/io/iosevka/package.nix
+++ b/pkgs/by-name/io/iosevka/package.nix
@@ -58,16 +58,16 @@ assert (extraParameters != null) -> set != null;
buildNpmPackage rec {
pname = "Iosevka${toString set}";
- version = "33.3.6";
+ version = "34.0.0";
src = fetchFromGitHub {
owner = "be5invis";
repo = "iosevka";
rev = "v${version}";
- hash = "sha256-/Bex4N+3xnYwteO85UaqrIKL5qGnYgSJYO9ET/WEUjM=";
+ hash = "sha256-fASlzL/7pVDIs5wCkEUJaU0r0Gy5YGZ9kxiAskZHWcI=";
};
- npmDepsHash = "sha256-6TTcXFf9z3ebL4l+++0DS26BJVnwzIi7hU2R1H0DF44=";
+ npmDepsHash = "sha256-uujfgTv2QEhywQNmglZusgikGEZvVtWL/lYFq6Q1VFc=";
nativeBuildInputs = [
remarshal
diff --git a/pkgs/by-name/je/jetbrains-runner/package.nix b/pkgs/by-name/je/jetbrains-runner/package.nix
index c5caba3c2a16..d2b399fd0cf2 100644
--- a/pkgs/by-name/je/jetbrains-runner/package.nix
+++ b/pkgs/by-name/je/jetbrains-runner/package.nix
@@ -8,13 +8,13 @@
}:
stdenv.mkDerivation rec {
pname = "jetbrains-runner";
- version = "3.0.6";
+ version = "3.0.7";
src = fetchFromGitHub {
owner = "alex1701c";
repo = "JetBrainsRunner";
tag = version;
- hash = "sha256-Jw86JFaaJ5kGB4dnOInAcdGsLmE4XO7O8/aBaV1zcNU=";
+ hash = "sha256-TaueSAxGiKiPVT26DSy1mzwsw2vBUK3D//vtOLtw2KQ=";
fetchSubmodules = true;
};
diff --git a/pkgs/by-name/li/libcosmicAppHook/package.nix b/pkgs/by-name/li/libcosmicAppHook/package.nix
index 416ec8029da3..976b14013620 100644
--- a/pkgs/by-name/li/libcosmicAppHook/package.nix
+++ b/pkgs/by-name/li/libcosmicAppHook/package.nix
@@ -57,7 +57,7 @@ makeSetupHook {
lib.makeSearchPath "share" (
lib.optionals includeSettings [ fallbackThemes ] ++ [ targetPackages.cosmic-icons or cosmic-icons ]
);
- cargoLinkerVar = targetPackages.stdenv.hostPlatform.rust.cargoEnvVarTarget;
+ cargoLinkerVar = stdenv.targetPlatform.rust.cargoEnvVarTarget;
# force linking for all libraries that may be dlopen'd by libcosmic/iced apps
cargoLinkLibs = lib.escapeShellArgs (
[
diff --git a/pkgs/by-name/mi/mitra/package.nix b/pkgs/by-name/mi/mitra/package.nix
index 52c86feb8c44..060c10fb3c59 100644
--- a/pkgs/by-name/mi/mitra/package.nix
+++ b/pkgs/by-name/mi/mitra/package.nix
@@ -6,17 +6,17 @@
rustPlatform.buildRustPackage rec {
pname = "mitra";
- version = "4.15.0";
+ version = "4.16.0";
src = fetchFromGitea {
domain = "codeberg.org";
owner = "silverpill";
repo = "mitra";
rev = "v${version}";
- hash = "sha256-zEJ+fGOY69F/gF7ZFyWigAxTXP6sZMvFo7sgy36wVFk=";
+ hash = "sha256-Z3vJ2myo2fzBbH8P+JYzK9W4rlV4UaoySY/MMLhOvI4=";
};
- cargoHash = "sha256-DQAqvh17AWQt3gSRzQlP5ZL3L1Euqsl+bXoiJBGkdqo=";
+ cargoHash = "sha256-YWOGJtOu84WLKDqwhLIxYlYXetkn9YnW17U5MF/VFM8=";
# require running database
doCheck = false;
diff --git a/pkgs/by-name/mk/mktoc/package.nix b/pkgs/by-name/mk/mktoc/package.nix
index 9b1c53afaeb9..d0d064fba9f5 100644
--- a/pkgs/by-name/mk/mktoc/package.nix
+++ b/pkgs/by-name/mk/mktoc/package.nix
@@ -7,16 +7,16 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "mktoc";
- version = "5.0.0";
+ version = "5.1.1";
src = fetchFromGitHub {
owner = "KevinGimbel";
repo = "mktoc";
rev = "v${finalAttrs.version}";
- hash = "sha256-QiV0lPM5rRAVH+a15f3G8quoa26I8jHEvbtfTQU5FKM=";
+ hash = "sha256-EyQrfLpeWacAEpVnaz4alEF/IAjSH/4HsTsdJldOJxg=";
};
- cargoHash = "sha256-Ny9g1TQUSGOBocFtzmxfFZp5K8t7z3JlEMHBTi69bLU=";
+ cargoHash = "sha256-yTTJ0gxmQhn40eI+Elzvv/t0WLivI0TV8B/LS6KLg14=";
nativeInstallCheckInputs = [
versionCheckHook
diff --git a/pkgs/by-name/mp/mpfr/package.nix b/pkgs/by-name/mp/mpfr/package.nix
index 7dc402720c8a..91199418e254 100644
--- a/pkgs/by-name/mp/mpfr/package.nix
+++ b/pkgs/by-name/mp/mpfr/package.nix
@@ -50,7 +50,8 @@ stdenv.mkDerivation rec {
# Without this, the `tget_set_d128` test experiences a link
# error due to missing `__dpd_trunctdkf`.
"--disable-decimal-float"
- ];
+ ]
+ ++ lib.optional stdenv.hostPlatform.isPE "LDFLAGS=-Wl,-no-undefined";
doCheck = true; # not cross;
diff --git a/pkgs/by-name/pl/pluto/package.nix b/pkgs/by-name/pl/pluto/package.nix
index 953e562e88e5..977f2ffa09c7 100644
--- a/pkgs/by-name/pl/pluto/package.nix
+++ b/pkgs/by-name/pl/pluto/package.nix
@@ -6,16 +6,16 @@
buildGoModule rec {
pname = "pluto";
- version = "5.22.6";
+ version = "5.22.7";
src = fetchFromGitHub {
owner = "FairwindsOps";
repo = "pluto";
rev = "v${version}";
- hash = "sha256-6Xi+EWQvFYtdiVywhSB4Lmzsc6Z1nE8UWO8vBteVOnE=";
+ hash = "sha256-lB8xMkKCnQYMtwvYXbCwSsh30nbpQ/2Pl8dHA1R3bQg=";
};
- vendorHash = "sha256-59mRVfQ2rduTvIJE1l/j3K+PY3OEMfNpjjYg3hqNUhs=";
+ vendorHash = "sha256-PVax9C1tSlB8AVhJbRx4l5kvOrPfWd4O8jQ2lXoamls=";
ldflags = [
"-w"
diff --git a/pkgs/by-name/pr/prmers/package.nix b/pkgs/by-name/pr/prmers/package.nix
index c6baf240dd69..d3953a863329 100644
--- a/pkgs/by-name/pr/prmers/package.nix
+++ b/pkgs/by-name/pr/prmers/package.nix
@@ -12,13 +12,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "prmers";
- version = "4.15.71-alpha";
+ version = "4.15.77-alpha";
src = fetchFromGitHub {
owner = "cherubrock-seb";
repo = "PrMers";
tag = "v${finalAttrs.version}";
- hash = "sha256-2/bRdH/k9btUhXWoDBQ4gKQsUjuUKtfcy9eyzfJShPI=";
+ hash = "sha256-TQsW1QY5MxHRJkG5b0rtVmOOC2fuw1jFhLpEH/q1kBg=";
};
enableParallelBuilding = true;
diff --git a/pkgs/by-name/qo/qoi/add-install-target-and-pc-module.patch b/pkgs/by-name/qo/qoi/add-install-target-and-pc-module.patch
new file mode 100644
index 000000000000..f910080d3074
--- /dev/null
+++ b/pkgs/by-name/qo/qoi/add-install-target-and-pc-module.patch
@@ -0,0 +1,65 @@
+diff --git a/.gitignore b/.gitignore
+index 9234e61..f137e88 100644
+--- a/.gitignore
++++ b/.gitignore
+@@ -3,3 +3,4 @@ stb_image.h
+ stb_image_write.h
+ qoibench
+ qoiconv
++qoi.pc
+diff --git a/Makefile b/Makefile
+index fb4b4d8..4660180 100644
+--- a/Makefile
++++ b/Makefile
+@@ -7,6 +7,11 @@ LFLAGS_CONV ?= $(LDFLAGS)
+ TARGET_BENCH ?= qoibench
+ TARGET_CONV ?= qoiconv
+
++PREFIX ?= /usr/local
++BINDIR ?= $(PREFIX)/bin
++INCLUDEDIR ?= $(PREFIX)/include
++LIBDIR ?= $(PREFIX)/lib
++
+ all: $(TARGET_BENCH) $(TARGET_CONV)
+
+ bench: $(TARGET_BENCH)
+@@ -17,6 +22,24 @@ conv: $(TARGET_CONV)
+ $(TARGET_CONV):$(TARGET_CONV).c qoi.h
+ $(CC) $(CFLAGS_CONV) $(CFLAGS) $(TARGET_CONV).c -o $(TARGET_CONV) $(LFLAGS_CONV)
+
++qoi.pc: qoi.pc.in
++ sed < qoi.pc.in > qoi.pc \
++ -e 's|@PREFIX@|$(PREFIX)|g' \
++ -e 's|@INCLUDEDIR@|$(INCLUDEDIR:$(PREFIX)%=$${prefix}%)|g'
++
++.PHONY: install
++install: install-tools install-header
++
++.PHONY: install-tools
++install-tools: all
++ install -Dm 755 $(TARGET_CONV) $(DESTDIR)$(BINDIR)/$(TARGET_CONV)
++ install -Dm 755 $(TARGET_BENCH) $(DESTDIR)$(BINDIR)/$(TARGET_BENCH)
++
++.PHONY: install-header
++install-header: qoi.h qoi.pc
++ install -Dm 644 qoi.h $(DESTDIR)$(INCLUDEDIR)/qoi.h
++ install -Dm 644 qoi.pc $(DESTDIR)$(LIBDIR)/pkgconfig/qoi.pc
++
+ .PHONY: clean
+ clean:
+ $(RM) $(TARGET_BENCH) $(TARGET_CONV)
+diff --git a/qoi.pc.in b/qoi.pc.in
+new file mode 100755
+index 0000000..dd83a36
+--- /dev/null
++++ b/qoi.pc.in
+@@ -0,0 +1,9 @@
++prefix=@PREFIX@
++includedir=@INCLUDEDIR@
++
++Name: qoi
++Description: The "Quite OK Image Format" for fast, lossless image compression
++Version: 0
++URL: https://qoiformat.org/
++License: MIT
++Cflags: -I${includedir}
diff --git a/pkgs/by-name/qo/qoi/package.nix b/pkgs/by-name/qo/qoi/package.nix
index a95fd712eb1d..e3fb2e90107f 100644
--- a/pkgs/by-name/qo/qoi/package.nix
+++ b/pkgs/by-name/qo/qoi/package.nix
@@ -1,49 +1,52 @@
{
fetchFromGitHub,
lib,
+ libpng,
+ nix-update-script,
stb,
stdenv,
+ testers,
}:
stdenv.mkDerivation (finalAttrs: {
pname = "qoi";
- version = "0-unstable-2023-08-10"; # no upstream version yet.
+ version = "0-unstable-2025-11-13"; # no upstream version yet.
src = fetchFromGitHub {
owner = "phoboslab";
repo = "qoi";
- rev = "19b3b4087b66963a3699ee45f05ec9ef205d7c0e";
- hash = "sha256-E1hMtjMuDS2zma2s5hlHby/sroRGhtyZm9gLQ+VztsM=";
+ rev = "44b233a95eda82fbd2e39a269199b73af0f4c4c3";
+ hash = "sha256-W5JG9Nz4NI2KZmUEtxEiGH7oxfAzEIaUyXTbSB25hZw=";
};
+ patches = [
+ # https://github.com/phoboslab/qoi/pull/322
+ ./add-install-target-and-pc-module.patch
+ ];
+
outputs = [
"out"
"dev"
];
- nativeBuildInputs = [ stb ];
+ strictDeps = true;
+ enableParalleBuilding = true;
- buildPhase = ''
- runHook preBuild
+ buildInputs = [ libpng ];
- make CFLAGS_CONV="-I${stb}/include/stb -O3" qoiconv
+ # Don't bloat the header-only output with binaries
+ propagatedBuildOutputs = [ ];
- runHook postBuild
- '';
+ makeFlags = [
+ "CFLAGS=-I${lib.getDev stb}/include/stb"
+ "PREFIX=${placeholder "dev"}"
+ "BINDIR=${placeholder "out"}/bin"
+ ];
- installPhase = ''
- runHook preInstall
-
- # Conversion utility for images->qoi. Not usually needed for development.
- mkdir -p ${placeholder "out"}/bin
- install qoiconv ${placeholder "out"}/bin
-
- # The actual single-header implementation. Nothing to compile, just install.
- mkdir -p ${placeholder "dev"}/include/
- install qoi.h ${placeholder "dev"}/include
-
- runHook postInstall
- '';
+ passthru = {
+ tests.pkg-config = testers.hasPkgConfigModules { package = finalAttrs.finalPackage; };
+ updateScript = nix-update-script { extraArgs = [ "--version=branch" ]; };
+ };
meta = {
description = "'Quite OK Image Format' for fast, lossless image compression";
@@ -52,5 +55,6 @@ stdenv.mkDerivation (finalAttrs: {
license = lib.licenses.mit;
maintainers = with lib.maintainers; [ hzeller ];
platforms = lib.platforms.all;
+ pkgConfigModules = [ "qoi" ];
};
})
diff --git a/pkgs/applications/networking/instant-messengers/quaternion/default.nix b/pkgs/by-name/qu/quaternion/package.nix
similarity index 51%
rename from pkgs/applications/networking/instant-messengers/quaternion/default.nix
rename to pkgs/by-name/qu/quaternion/package.nix
index e275452c9b9e..209c96528916 100644
--- a/pkgs/applications/networking/instant-messengers/quaternion/default.nix
+++ b/pkgs/by-name/qu/quaternion/package.nix
@@ -3,56 +3,40 @@
lib,
fetchFromGitHub,
cmake,
- wrapQtAppsHook,
- qtbase,
- qtquickcontrols2 ? null, # only a separate package on qt5
- qtkeychain,
- qtmultimedia,
- qttools,
- libquotient,
+ qt6,
libsecret,
olm,
+ kdePackages,
}:
-let
- inherit (lib) cmakeBool;
-
-in
stdenv.mkDerivation (finalAttrs: {
pname = "quaternion";
- version = "0.0.96.1";
+ version = "0.0.97.1";
src = fetchFromGitHub {
owner = "quotient-im";
repo = "Quaternion";
- rev = finalAttrs.version;
- hash = "sha256-lRCSEb/ldVnEv6z0moU4P5rf0ssKb9Bw+4QEssLjuwI=";
+ tag = finalAttrs.version;
+ hash = "sha256-Dn4E3mTqcNK88PNraL+qR1gREob5j7s3Qf8XAaTNSJg=";
};
buildInputs = [
- libquotient
+ kdePackages.libquotient
libsecret
olm
- qtbase
- qtkeychain
- qtmultimedia
- qtquickcontrols2
+ qt6.qtbase
+ kdePackages.qtkeychain
+ qt6.qtmultimedia
];
nativeBuildInputs = [
cmake
- qttools
- wrapQtAppsHook
+ qt6.qttools
+ qt6.wrapQtAppsHook
];
- # qt6 needs UTF
env.LANG = "C.UTF-8";
- cmakeFlags = [
- # drop this from 0.0.97 onwards as it will be qt6 only
- (cmakeBool "BUILD_WITH_QT6" ((lib.versions.major qtbase.version) == "6"))
- ];
-
postInstall =
if stdenv.hostPlatform.isDarwin then
''
@@ -62,8 +46,8 @@ stdenv.mkDerivation (finalAttrs: {
''
else
''
- substituteInPlace $out/share/applications/com.github.quaternion.desktop \
- --replace 'Exec=quaternion' "Exec=$out/bin/quaternion"
+ substituteInPlace $out/share/applications/io.github.quotient_im.Quaternion.desktop \
+ --replace-fail 'Exec=quaternion' "Exec=$out/bin/quaternion"
'';
meta = {
@@ -72,6 +56,5 @@ stdenv.mkDerivation (finalAttrs: {
homepage = "https://matrix.org/ecosystem/clients/quaternion/";
license = lib.licenses.gpl3;
maintainers = with lib.maintainers; [ peterhoeg ];
- inherit (qtbase.meta) platforms;
};
})
diff --git a/pkgs/by-name/rt/rtkit/meson-actual-use-systemd_systemunitdir.patch b/pkgs/by-name/rt/rtkit/meson-actual-use-systemd_systemunitdir.patch
deleted file mode 100644
index fa1ca26088ce..000000000000
--- a/pkgs/by-name/rt/rtkit/meson-actual-use-systemd_systemunitdir.patch
+++ /dev/null
@@ -1,22 +0,0 @@
-From 7d62095b94f8df3891c984a1535026d2658bb177 Mon Sep 17 00:00:00 2001
-From: Edmund Wu
-Date: Sat, 11 Apr 2020 16:59:35 -0400
-Subject: [PATCH] meson: actually use systemd_systemunitdir
-
----
- meson.build | 2 +-
- 1 file changed, 1 insertion(+), 1 deletion(-)
-
-diff --git a/meson.build b/meson.build
-index 02e6c73..ba5ba1e 100644
---- a/meson.build
-+++ b/meson.build
-@@ -58,7 +58,7 @@ if policydir == ''
- policydir = get_option('datadir') / 'polkit-1' / 'actions'
- endif
-
--systemunitdir = ''
-+systemunitdir = get_option('systemd_systemunitdir')
- if systemunitdir == '' and systemd_dep.found()
- systemunitdir = systemd_dep.get_pkgconfig_variable(
- 'systemdsystemunitdir',
diff --git a/pkgs/by-name/rt/rtkit/meson-fix-librt-find_library-check.patch b/pkgs/by-name/rt/rtkit/meson-fix-librt-find_library-check.patch
deleted file mode 100644
index 54992e84ca66..000000000000
--- a/pkgs/by-name/rt/rtkit/meson-fix-librt-find_library-check.patch
+++ /dev/null
@@ -1,22 +0,0 @@
-From 98f70edd8f534c371cb4308b9720739c5178918d Mon Sep 17 00:00:00 2001
-From: Felipe Sateler
-Date: Sat, 11 Apr 2020 10:59:21 -0400
-Subject: [PATCH] meson: fix librt find_library check
-
----
- meson.build | 2 +-
- 1 file changed, 1 insertion(+), 1 deletion(-)
-
-diff --git a/meson.build b/meson.build
-index 02e6c73..49da472 100644
---- a/meson.build
-+++ b/meson.build
-@@ -22,7 +22,7 @@ polkit_dep = dependency('polkit-gobject-1', required: false)
- systemd_dep = dependency('systemd', required: false)
- thread_dep = dependency('threads')
-
--librt_dep = cc.find_library('z')
-+librt_dep = cc.find_library('rt')
- cc.check_header('sched.h', dependencies: librt_dep)
- cc.has_function('sched_setscheduler', dependencies: librt_dep)
-
diff --git a/pkgs/by-name/rt/rtkit/package.nix b/pkgs/by-name/rt/rtkit/package.nix
index 350f6ccdd18a..4d3b47ce87d8 100644
--- a/pkgs/by-name/rt/rtkit/package.nix
+++ b/pkgs/by-name/rt/rtkit/package.nix
@@ -1,7 +1,7 @@
{
lib,
stdenv,
- fetchFromGitHub,
+ fetchFromGitLab,
meson,
ninja,
pkg-config,
@@ -10,23 +10,28 @@
libcap,
polkit,
systemd,
+ fetchpatch,
+ nix-update-script,
}:
-stdenv.mkDerivation {
+stdenv.mkDerivation (finalAttrs: {
pname = "rtkit";
- version = "0.13";
+ version = "0.14";
- src = fetchFromGitHub {
- owner = "heftig";
+ src = fetchFromGitLab {
+ domain = "gitlab.freedesktop.org";
+ owner = "pipewire";
repo = "rtkit";
- rev = "c295fa849f52b487be6433e69e08b46251950399";
- sha256 = "0yfsgi3pvg6dkizrww1jxpkvcbhzyw9110n1dypmzq0c5hlzjxcd";
+ tag = "v${finalAttrs.version}";
+ hash = "sha256-y952SHbUWIjg1BKqenHABVWm0S5d/sBac1zRp9BpXB8=";
};
patches = [
- ./meson-actual-use-systemd_systemunitdir.patch
- ./meson-fix-librt-find_library-check.patch
- ./rtkit-daemon-dont-log-debug-messages-by-default.patch
+ # Let us override the `sysusersdir` path
+ (fetchpatch {
+ url = "https://gitlab.freedesktop.org/pipewire/rtkit/-/commit/621fdc3f2c037781dc279760cfbff64974fdbe77.patch";
+ hash = "sha256-Ffdi6dfZmdBpClpJkPNISmEoeUkIufrObz5g7RSPqLw=";
+ })
];
nativeBuildInputs = [
@@ -35,6 +40,7 @@ stdenv.mkDerivation {
pkg-config
unixtools.xxd
];
+
buildInputs = [
dbus
libcap
@@ -43,23 +49,26 @@ stdenv.mkDerivation {
];
mesonFlags = [
- "-Dinstalled_tests=false"
-
- "-Ddbus_systemservicedir=${placeholder "out"}/share/dbus-1/system-services"
- "-Ddbus_interfacedir=${placeholder "out"}/share/dbus-1/interfaces"
- "-Ddbus_rulesdir=${placeholder "out"}/etc/dbus-1/system.d"
- "-Dpolkit_actiondir=${placeholder "out"}/share/polkit-1/actions"
- "-Dsystemd_systemunitdir=${placeholder "out"}/etc/systemd/system"
+ (lib.mesonBool "installed_tests" false)
+ (lib.mesonOption "dbus_systemservicedir" "${placeholder "out"}/share/dbus-1/system-services")
+ (lib.mesonOption "dbus_interfacedir" "${placeholder "out"}/share/dbus-1/interfaces")
+ (lib.mesonOption "dbus_rulesdir" "${placeholder "out"}/etc/dbus-1/system.d")
+ (lib.mesonOption "polkit_actiondir" "${placeholder "out"}/share/polkit-1/actions")
+ (lib.mesonOption "systemd_systemunitdir" "${placeholder "out"}/etc/systemd/system")
+ (lib.mesonOption "systemd_sysusersdir" "${placeholder "out"}/lib/sysusers.d")
];
+ passthru.updateScript = nix-update-script { };
+
meta = {
- homepage = "https://github.com/heftig/rtkit";
+ homepage = "https://gitlab.freedesktop.org/pipewire/rtkit";
description = "Daemon that hands out real-time priority to processes";
mainProgram = "rtkitctl";
license = with lib.licenses; [
- gpl3
- bsd0
- ]; # lib is bsd license
+ gpl3Plus
+ mit
+ ];
platforms = lib.platforms.linux;
+ maintainers = [ lib.maintainers.Gliczy ];
};
-}
+})
diff --git a/pkgs/by-name/rt/rtkit/rtkit-daemon-dont-log-debug-messages-by-default.patch b/pkgs/by-name/rt/rtkit/rtkit-daemon-dont-log-debug-messages-by-default.patch
deleted file mode 100644
index 667d80ab6915..000000000000
--- a/pkgs/by-name/rt/rtkit/rtkit-daemon-dont-log-debug-messages-by-default.patch
+++ /dev/null
@@ -1,73 +0,0 @@
-From 4880b9c67628a781bdb183dcdc69f12cb829817d Mon Sep 17 00:00:00 2001
-From: Jean Delvare
-Date: Sat, 15 Apr 2023 11:53:27 +0200
-Subject: [PATCH] rtkit-daemon: Don't log debug messages by default
-
-The rtkit-daemon service is a lot more verbose than other services
-when it doesn't have anything to do. Stop logging the debug messages
-by default to avoid flooding the system log.
-
-This addresses issue #22.
----
- rtkit-daemon.c | 13 +++++++++++++
- 1 file changed, 13 insertions(+)
-
-diff --git a/rtkit-daemon.c b/rtkit-daemon.c
-index 17122fa..0c5d814 100644
---- a/rtkit-daemon.c
-+++ b/rtkit-daemon.c
-@@ -154,6 +154,9 @@ static bool canary_demote_unknown = FALSE;
- /* Log to stderr? */
- static bool log_stderr = FALSE;
-
-+/* Also log debugging messages? */
-+static bool log_debug = FALSE;
-+
- /* Scheduling policy to use */
- static int sched_policy = SCHED_RR;
-
-@@ -1876,6 +1879,7 @@ enum {
- ARG_CANARY_DEMOTE_UNKNOWN,
- ARG_CANARY_REFUSE_SEC,
- ARG_STDERR,
-+ ARG_DEBUG,
- ARG_INTROSPECT
- };
-
-@@ -1905,6 +1909,7 @@ static const struct option long_options[] = {
- { "canary-demote-unknown", no_argument, 0, ARG_CANARY_DEMOTE_UNKNOWN },
- { "canary-refuse-sec", required_argument, 0, ARG_CANARY_REFUSE_SEC },
- { "stderr", no_argument, 0, ARG_STDERR },
-+ { "debug", no_argument, 0, ARG_DEBUG },
- { "introspect", no_argument, 0, ARG_INTROSPECT },
- { NULL, 0, 0, 0}
- };
-@@ -1933,6 +1938,7 @@ static void show_help(const char *exe) {
- " --version Show version\n\n"
- "OPTIONS:\n"
- " --stderr Log to STDERR in addition to syslog\n"
-+ " --debug Also log debugging mssages\n"
- " --user-name=USER Run daemon as user (%s)\n\n"
- " --scheduling-policy=(RR|FIFO) Choose scheduling policy (%s)\n"
- " --our-realtime-priority=[%i..%i] Realtime priority for the daemon (%u)\n"
-@@ -2222,6 +2228,10 @@ static int parse_command_line(int argc, char *argv[], int *ret) {
- log_stderr = TRUE;
- break;
-
-+ case ARG_DEBUG:
-+ log_debug = TRUE;
-+ break;
-+
- case ARG_INTROSPECT:
- fputs(introspect_xml, stdout);
- *ret = 0;
-@@ -2251,6 +2261,9 @@ static int parse_command_line(int argc, char *argv[], int *ret) {
- return -1;
- }
-
-+ if (!log_debug)
-+ setlogmask(LOG_UPTO(LOG_INFO));
-+
- assert(our_realtime_priority >= (unsigned) sched_get_priority_min(sched_policy));
- assert(our_realtime_priority <= (unsigned) sched_get_priority_max(sched_policy));
-
diff --git a/pkgs/by-name/sc/scaleway-cli/package.nix b/pkgs/by-name/sc/scaleway-cli/package.nix
index a291ac296c5a..33d3d5da63b0 100644
--- a/pkgs/by-name/sc/scaleway-cli/package.nix
+++ b/pkgs/by-name/sc/scaleway-cli/package.nix
@@ -10,16 +10,16 @@
buildGoModule (finalAttrs: {
pname = "scaleway-cli";
- version = "2.48.0";
+ version = "2.49.0";
src = fetchFromGitHub {
owner = "scaleway";
repo = "scaleway-cli";
tag = "v${finalAttrs.version}";
- hash = "sha256-ME5kza09t/FQaQcXlyMyjaZb3A7Bpbw1vdHjATWpas4=";
+ hash = "sha256-l9SEM9SNLt2K4QsrYkLA+eZQTe5nXl/Ds2v84qltwTE=";
};
- vendorHash = "sha256-Z7AAoHRo22y6WaknOWCSopyo+JWo1ITivF+53RHh2gs=";
+ vendorHash = "sha256-4k90jyi3IPtL4maFGEiQmrQnC8tQOa8X8JJiUulh9y0=";
env.CGO_ENABLED = 0;
diff --git a/pkgs/by-name/sd/sdl_gamecontrollerdb/package.nix b/pkgs/by-name/sd/sdl_gamecontrollerdb/package.nix
index 7df4f9173bcf..05b56efa62cb 100644
--- a/pkgs/by-name/sd/sdl_gamecontrollerdb/package.nix
+++ b/pkgs/by-name/sd/sdl_gamecontrollerdb/package.nix
@@ -7,13 +7,13 @@
stdenvNoCC.mkDerivation (finalAttrs: {
pname = "sdl_gamecontrollerdb";
- version = "0-unstable-2025-12-26";
+ version = "0-unstable-2025-12-30";
src = fetchFromGitHub {
owner = "mdqinc";
repo = "SDL_GameControllerDB";
- rev = "547fb8019f8cf7c443244b918c5be05c9e5a53f3";
- hash = "sha256-mPVnxDuivh+jBf25jPo3wA/CHAgGkzAb2ybbRLmdE/o=";
+ rev = "01de5cf46ff3679b5378ec7dae365791e632b76a";
+ hash = "sha256-O04ruUxYYUCtuP7JAdB4IFFV9Uh4Hhy+fE8Iuai01pY=";
};
dontBuild = true;
diff --git a/pkgs/by-name/se/send/package.nix b/pkgs/by-name/se/send/package.nix
index 3778bdcff011..245eee19b821 100644
--- a/pkgs/by-name/se/send/package.nix
+++ b/pkgs/by-name/se/send/package.nix
@@ -17,6 +17,8 @@ buildNpmPackage rec {
hash = "sha256-tfntox8Sw3xzlCOJgY/LThThm+mptYY5BquYDjzHonQ=";
};
+ nodejs = nodejs_20;
+
npmDepsHash = "sha256-ZVegUECrwkn/DlAwqx5VDmcwEIJV/jAAV99Dq29Tm2w=";
nativeBuildInputs = [
@@ -37,7 +39,7 @@ buildNpmPackage rec {
cp -r dist $out/lib/node_modules/send/
ln -s $out/lib/node_modules/send/dist/version.json $out/lib/node_modules/send/version.json
- makeWrapper ${lib.getExe nodejs_20} $out/bin/send \
+ makeWrapper ${lib.getExe nodejs} $out/bin/send \
--add-flags $out/lib/node_modules/send/server/bin/prod.js \
--set "NODE_ENV" "production"
'';
diff --git a/pkgs/by-name/sg/sgt-puzzles/package.nix b/pkgs/by-name/sg/sgt-puzzles/package.nix
index f9813627dcaf..7a56dee66356 100644
--- a/pkgs/by-name/sg/sgt-puzzles/package.nix
+++ b/pkgs/by-name/sg/sgt-puzzles/package.nix
@@ -18,11 +18,11 @@
stdenv.mkDerivation (finalAttrs: {
pname = "sgt-puzzles";
- version = "20251127.a4f68b6";
+ version = "20251220.ecb576f";
src = fetchurl {
url = "http://www.chiark.greenend.org.uk/~sgtatham/puzzles/puzzles-${finalAttrs.version}.tar.gz";
- hash = "sha256-NaRLonSMOKZaZjttBDnM2VV1oa21rLDISvSyV8F9tQ0=";
+ hash = "sha256-hgh3q9qACtlcfOkH2anesQKYREuwcLfiucUMg+p5xWs=";
};
sgt-puzzles-menu = fetchurl {
diff --git a/pkgs/by-name/sh/shutter/package.nix b/pkgs/by-name/sh/shutter/package.nix
index 00c9fdf1c01b..8486719d875b 100644
--- a/pkgs/by-name/sh/shutter/package.nix
+++ b/pkgs/by-name/sh/shutter/package.nix
@@ -16,61 +16,61 @@
let
perlModules = with perlPackages; [
- ImageMagick
Cairo
+ CairoGObject
+ CarpAlways
+ commonsense
+ EncodeLocale
FileBaseDir
- FileWhich
FileCopyRecursive
- XMLSimple
- XMLTwig
- XMLParser
- SortNaturally
- LocaleGettext
- ProcProcessTable
- X11Protocol
- ProcSimple
- ImageExifTool
- JSON
- JSONMaybeXS
- NetOAuth
- PathClass
- LWP
- LWPProtocolHttps
- NetDBus
- TryTiny
- WWWMechanize
- HTTPMessage
- HTTPDate
+ FileWhich
+ Glib
+ GlibObjectIntrospection
+ GooCanvas2
+ GooCanvas2CairoTypes
+ Gtk3
+ Gtk3ImageView
HTMLForm
HTMLParser
HTMLTagset
HTTPCookies
- EncodeLocale
- URI
- CarpAlways
- GlibObjectIntrospection
+ HTTPDate
+ HTTPMessage
+ ImageExifTool
+ ImageMagick
+ JSON
+ JSONMaybeXS
+ LocaleGettext
+ LWP
+ LWPProtocolHttps
+ Moo
+ NetDBus
NumberBytesHuman
- CairoGObject
- Readonly
- Gtk3ImageView
- Gtk3
- Glib
Pango
- GooCanvas2
- GooCanvas2CairoTypes
- commonsense
+ PathClass
+ ProcProcessTable
+ ProcSimple
+ Readonly
+ SortNaturally
+ SubQuote
+ TryTiny
TypesSerialiser
+ URI
+ X11Protocol
+ XMLParser
+ XMLSimple
+ XMLTwig
];
in
stdenv.mkDerivation rec {
pname = "shutter";
- version = "0.99.2";
+ version = "0.99.6";
src = fetchFromGitHub {
owner = "shutter-project";
repo = "shutter";
rev = "v${version}";
- sha256 = "sha256-o95skSr6rszh0wsHQTpu1GjqCDmde7aygIP+i4XQW9A=";
+ sha256 = "sha256-2wRPmTpFfgU8xW9Fyn1+TMowcKm3pukT1ck06IWPiGo=";
};
nativeBuildInputs = [ wrapGAppsHook3 ];
diff --git a/pkgs/by-name/so/solc/package.nix b/pkgs/by-name/so/solc/package.nix
index 141795a126a2..cbab1ff2a437 100644
--- a/pkgs/by-name/so/solc/package.nix
+++ b/pkgs/by-name/so/solc/package.nix
@@ -25,9 +25,9 @@ assert cvc4Support -> cvc4 != null && cln != null && gmp != null;
let
pname = "solc";
- version = "0.8.28";
- linuxHash = "sha256-kosJ10stylGK5NUtsnMM7I+OfhR40TXPQDvnggOFLLc=";
- darwinHash = "sha256-gVFbDlPeqiZtVJVFzKrApalubU6CAcd/ZzsscQl22eo=";
+ version = "0.8.33";
+ linuxHash = "sha256-sWCV0GOUW5GPNX1flk+UOrdwoHZHnx4MsZMGDDBxx6M=";
+ darwinHash = "sha256-gyQoBZHOOY1+JyKEa8EOzxd5sToyjvl7aHySzZxwgBo=";
nativeInstallCheckInputs = [
versionCheckHook
@@ -64,15 +64,6 @@ let
hash = linuxHash;
};
- # Fix build with GCC 14
- # Submitted upstream: https://github.com/ethereum/solidity/pull/15685
- postPatch = ''
- substituteInPlace test/yulPhaser/Chromosome.cpp \
- --replace-fail \
- "BOOST_TEST(abs" \
- "BOOST_TEST(fabs"
- '';
-
cmakeFlags = [
"-DBoost_USE_STATIC_LIBS=OFF"
diff --git a/pkgs/by-name/su/suricata/bpf_stubs_workaround.patch b/pkgs/by-name/su/suricata/bpf_stubs_workaround.patch
index d4e8c95fea22..d8997542fc1c 100644
--- a/pkgs/by-name/su/suricata/bpf_stubs_workaround.patch
+++ b/pkgs/by-name/su/suricata/bpf_stubs_workaround.patch
@@ -1,19 +1,11 @@
-*** suricata-5.0.0/ebpf/Makefile.in 2019-10-16 22:39:13.174649416 +0200
---- suricata-5.0.0/ebpf/Makefile.in.fixed 2019-10-16 22:38:41.822201802 +0200
-***************
-*** 527,533 ****
- @BUILD_EBPF_TRUE@$(BPF_TARGETS): %.bpf: %.c
- # From C-code to LLVM-IR format suffix .ll (clang -S -emit-llvm)
- @BUILD_EBPF_TRUE@ ${CLANG} -Wall $(BPF_CFLAGS) -O2 \
-! @BUILD_EBPF_TRUE@ -I/usr/include/$(build_cpu)-$(build_os)/ \
- @BUILD_EBPF_TRUE@ -D__KERNEL__ -D__ASM_SYSREG_H \
- @BUILD_EBPF_TRUE@ -target bpf -S -emit-llvm $< -o ${@:.bpf=.ll}
- # From LLVM-IR to BPF-bytecode in ELF-obj file
---- 527,533 ----
- @BUILD_EBPF_TRUE@$(BPF_TARGETS): %.bpf: %.c
- # From C-code to LLVM-IR format suffix .ll (clang -S -emit-llvm)
- @BUILD_EBPF_TRUE@ ${CLANG} -Wall $(BPF_CFLAGS) -O2 \
-! @BUILD_EBPF_TRUE@ -idirafter ../bpf_stubs_workaround \
- @BUILD_EBPF_TRUE@ -D__KERNEL__ -D__ASM_SYSREG_H \
- @BUILD_EBPF_TRUE@ -target bpf -S -emit-llvm $< -o ${@:.bpf=.ll}
- # From LLVM-IR to BPF-bytecode in ELF-obj file
+--- a/ebpf/Makefile.in
++++ b/ebpf/Makefile.in
+@@ -530,7 +530,7 @@
+ @BUILD_EBPF_TRUE@$(BPF_TARGETS): %.bpf: %.c
+ # From C-code to LLVM-IR format suffix .ll (clang -S -emit-llvm)
+ @BUILD_EBPF_TRUE@ ${CLANG} -Wall $(BPF_CFLAGS) -O2 -g \
+-@BUILD_EBPF_TRUE@ -I/usr/include/$(build_cpu)-$(build_os)/ \
++@BUILD_EBPF_TRUE@ -idirafter ../bpf_stubs_workaround \
+ @BUILD_EBPF_TRUE@ -D__KERNEL__ -D__ASM_SYSREG_H \
+ @BUILD_EBPF_TRUE@ -target bpf -S -emit-llvm $< -o ${@:.bpf=.ll}
+ # From LLVM-IR to BPF-bytecode in ELF-obj file
diff --git a/pkgs/by-name/su/suricata/package.nix b/pkgs/by-name/su/suricata/package.nix
index c6df3153bb46..77f070b2a9ca 100644
--- a/pkgs/by-name/su/suricata/package.nix
+++ b/pkgs/by-name/su/suricata/package.nix
@@ -5,7 +5,6 @@
clang,
llvm,
pkg-config,
- makeWrapper,
elfutils,
file,
jansson,
@@ -39,17 +38,21 @@ let
in
stdenv.mkDerivation rec {
pname = "suricata";
- version = "7.0.10";
+ version = "8.0.2";
src = fetchurl {
url = "https://www.openinfosecfoundation.org/download/${pname}-${version}.tar.gz";
- hash = "sha256-GX+SXqcBvctKFaygJLBlRrACZ0zZWLWJWPKaW7IU11k=";
+ hash = "sha256-nUUMosrb4QGZPpkDOmI0nSvanf2QpqzBvLbMbbdutVE=";
};
+ patches = lib.optionals stdenv.hostPlatform.is64bit [
+ # Provide empty gnu/stubs-32.h for eBPF build
+ ./bpf_stubs_workaround.patch
+ ];
+
nativeBuildInputs = [
clang
llvm
- makeWrapper
pkg-config
]
++ lib.optionals rustSupport [
@@ -90,14 +93,7 @@ stdenv.mkDerivation rec {
enableParallelBuilding = true;
- patches = lib.optional stdenv.hostPlatform.is64bit ./bpf_stubs_workaround.patch;
-
postPatch = ''
- substituteInPlace ./configure \
- --replace "/usr/bin/file" "${file}/bin/file"
- substituteInPlace ./libhtp/configure \
- --replace "/usr/bin/file" "${file}/bin/file"
-
mkdir -p bpf_stubs_workaround/gnu
touch bpf_stubs_workaround/gnu/stubs-32.h
'';
@@ -116,6 +112,7 @@ stdenv.mkDerivation rec {
"--enable-python"
"--enable-unix-socket"
"--localstatedir=/var"
+ "--runstatedir=/run"
"--sysconfdir=/etc"
"--with-libhs-includes=${lib.getDev vectorscan}/include/hs"
"--with-libhs-libraries=${lib.getLib vectorscan}/lib"
@@ -142,17 +139,8 @@ stdenv.mkDerivation rec {
doCheck = true;
installFlags = [
- "e_datadir=\${TMPDIR}"
- "e_localstatedir=\${TMPDIR}"
- "e_logdir=\${TMPDIR}"
- "e_logcertsdir=\${TMPDIR}"
- "e_logfilesdir=\${TMPDIR}"
- "e_rundir=\${TMPDIR}"
- "e_sysconfdir=\${out}/etc/suricata"
- "e_sysconfrulesdir=\${out}/etc/suricata/rules"
- "localstatedir=\${TMPDIR}"
- "runstatedir=\${TMPDIR}"
- "sysconfdir=\${out}/etc"
+ "DESTDIR=\${out}"
+ "prefix=/"
];
installTargets = [
@@ -161,10 +149,8 @@ stdenv.mkDerivation rec {
];
postInstall = ''
- wrapProgram "$out/bin/suricatasc" \
- --prefix PYTHONPATH : $PYTHONPATH:$(toPythonPath "$out")
substituteInPlace "$out/etc/suricata/suricata.yaml" \
- --replace "/etc/suricata" "$out/etc/suricata"
+ --replace-fail "/etc/suricata" "${placeholder "out"}/etc/suricata"
'';
passthru.tests = { inherit (nixosTests) suricata; };
diff --git a/pkgs/by-name/vi/vicinae/package.nix b/pkgs/by-name/vi/vicinae/package.nix
index 5214f5c0c7b4..df8ccc62d2b3 100644
--- a/pkgs/by-name/vi/vicinae/package.nix
+++ b/pkgs/by-name/vi/vicinae/package.nix
@@ -22,13 +22,13 @@
}:
gcc15Stdenv.mkDerivation (finalAttrs: {
pname = "vicinae";
- version = "0.17.3";
+ version = "0.18.0";
src = fetchFromGitHub {
owner = "vicinaehq";
repo = "vicinae";
tag = "v${finalAttrs.version}";
- hash = "sha256-EzvASqrcGZqWyESuYNKRnH17s5hBJK2woIrS6iD6nOs=";
+ hash = "sha256-ApMcDKe+6uYb2M+UL8SWW8M1S5bmT8EI5uOChLxzWqs=";
};
apiDeps = fetchNpmDeps {
diff --git a/pkgs/by-name/xi/xinetd/package.nix b/pkgs/by-name/xi/xinetd/package.nix
index 9deff58cf1d2..8dfcea649641 100644
--- a/pkgs/by-name/xi/xinetd/package.nix
+++ b/pkgs/by-name/xi/xinetd/package.nix
@@ -19,6 +19,8 @@ stdenv.mkDerivation (finalAttrs: {
pkg-config
];
+ env.NIX_CFLAGS_COMPILE = "-std=gnu17";
+
buildInputs = [
libtirpc
];
diff --git a/pkgs/by-name/xp/xpilot-ng/package.nix b/pkgs/by-name/xp/xpilot-ng/package.nix
index b5e54059c896..2e28be64ee9a 100644
--- a/pkgs/by-name/xp/xpilot-ng/package.nix
+++ b/pkgs/by-name/xp/xpilot-ng/package.nix
@@ -38,6 +38,7 @@ stdenv.mkDerivation (finalAttrs: {
patches = [
./xpilot-ng-gcc-14-fix.patch
./xpilot-ng-sdl-window-fix.patch
+ ./xpilot-ng-gcc-15-fix.patch
];
meta = {
diff --git a/pkgs/by-name/xp/xpilot-ng/xpilot-ng-gcc-15-fix.patch b/pkgs/by-name/xp/xpilot-ng/xpilot-ng-gcc-15-fix.patch
new file mode 100644
index 000000000000..6b502be65e48
--- /dev/null
+++ b/pkgs/by-name/xp/xpilot-ng/xpilot-ng-gcc-15-fix.patch
@@ -0,0 +1,13 @@
+Only in xpilot-ng-4.7.3/src/server: .suibotdef.c.swp
+diff -r -U3 xpilot-ng-4.7.3.orig/src/server/suibotdef.c xpilot-ng-4.7.3/src/server/suibotdef.c
+--- xpilot-ng-4.7.3.orig/src/server/suibotdef.c 2026-01-03 16:26:37.070168944 +0100
++++ xpilot-ng-4.7.3/src/server/suibotdef.c 2026-01-03 16:27:31.970201518 +0100
+@@ -372,7 +372,7 @@
+ } object_proximity_t;
+
+
+-static bool Get_object_proximity();
++static bool Get_object_proximity(player_t *pl, object_t *shot, double sqmaxdist,int maxtime, object_proximity_t *object_proximity);
+ static bool Get_object_proximity(player_t *pl, object_t *shot, double sqmaxdist,int maxtime, object_proximity_t *object_proximity){
+ /* get square of closest distance between player and object
+ * compare with sqmaxdist and maxtime and return sqdistance and time
diff --git a/pkgs/by-name/zo/zoom-us/package.nix b/pkgs/by-name/zo/zoom-us/package.nix
index 70eb83ab4d32..433fd2acb869 100644
--- a/pkgs/by-name/zo/zoom-us/package.nix
+++ b/pkgs/by-name/zo/zoom-us/package.nix
@@ -54,25 +54,25 @@ let
# Zoom versions are released at different times per platform and often with different versions.
# We write them on three lines like this (rather than using {}) so that the updater script can
# find where to edit them.
- versions.aarch64-darwin = "6.7.0.71075";
- versions.x86_64-darwin = "6.7.0.71075";
+ versions.aarch64-darwin = "6.7.2.72191";
+ versions.x86_64-darwin = "6.7.2.72191";
# This is the fallback version so that evaluation can produce a meaningful result.
- versions.x86_64-linux = "6.7.0.6313";
+ versions.x86_64-linux = "6.7.2.6498";
srcs = {
aarch64-darwin = fetchurl {
url = "https://zoom.us/client/${versions.aarch64-darwin}/zoomusInstallerFull.pkg?archType=arm64";
name = "zoomusInstallerFull.pkg";
- hash = "sha256-Jj6Ikxk7W77sv6g6yYR9ttTRF3kooQgVJnExNaU5aAA=";
+ hash = "sha256-v4maXehUE0KSmZO2OI/d2qVyeTnGvkaWaQzul/yde80=";
};
x86_64-darwin = fetchurl {
url = "https://zoom.us/client/${versions.x86_64-darwin}/zoomusInstallerFull.pkg";
- hash = "sha256-OaF3cbJZcXKKPkvdfjMuL1Va944N/TOAlqCLdA1fl64=";
+ hash = "sha256-6hDDzxzZMisPPyrIQ6XIhipVbid4a/X2gaV4DYIfz3w=";
};
x86_64-linux = fetchurl {
url = "https://zoom.us/client/${versions.x86_64-linux}/zoom_x86_64.pkg.tar.xz";
- hash = "sha256-Bm5LEGmGN0iUwzKdVzicxfx6K3g9FGevvR/gUIBaPj8=";
+ hash = "sha256-fvZMKjzQFkIKl3TUOMYHR75SDHShkKjk59ps55o9Qks=";
};
};
diff --git a/pkgs/development/libraries/gmp/6.x.nix b/pkgs/development/libraries/gmp/6.x.nix
index 541bab687537..e55838d4216b 100644
--- a/pkgs/development/libraries/gmp/6.x.nix
+++ b/pkgs/development/libraries/gmp/6.x.nix
@@ -69,7 +69,7 @@ let
++ optional (stdenv.hostPlatform.isDarwin && stdenv.hostPlatform.is64bit) "ABI=64"
# to build a .dll on windows, we need --disable-static + --enable-shared
# see https://gmplib.org/manual/Notes-for-Particular-Systems.html
- ++ optional (!withStatic && stdenv.hostPlatform.isWindows) "--disable-static --enable-shared"
+ ++ optional (!withStatic && stdenv.hostPlatform.isPE) "--disable-static --enable-shared"
++ optional (stdenv.hostPlatform.isDarwin && stdenv.hostPlatform.isAarch64) "--disable-assembly";
doCheck = true; # not cross;
diff --git a/pkgs/development/python-modules/beancount/default.nix b/pkgs/development/python-modules/beancount/default.nix
index 91afb6fe23ab..cc2b0bafc2dc 100644
--- a/pkgs/development/python-modules/beancount/default.nix
+++ b/pkgs/development/python-modules/beancount/default.nix
@@ -5,6 +5,7 @@
buildPythonPackage,
click,
fetchFromGitHub,
+ fetchpatch2,
flex,
gnupg,
meson,
@@ -26,6 +27,19 @@ buildPythonPackage rec {
hash = "sha256-XWTgaBvB4/SONL44afvprZwJUVrkoda5XLGNxad0kec=";
};
+ patches = [
+ (fetchpatch2 {
+ name = "accept-date-range-error-message-from-py3.14";
+ url = "https://salsa.debian.org/python-team/packages/beancount/-/raw/debian/sid/debian/patches/0003-Accept-date-range-error-message-from-py3.14.patch";
+ hash = "sha256-wqMTGSi4Gn5VADjV4MjZhFNWB3ThUhxvLYK7sentScQ=";
+ })
+ (fetchpatch2 {
+ name = "skip-ref-count-test-with-py3.14";
+ url = "https://salsa.debian.org/python-team/packages/beancount/-/raw/debian/sid/debian/patches/0004-Skip-refcount-test-with-py3.14.patch";
+ hash = "sha256-6P9xe15WBGaWpVYB2HfGfFHLMMmGkfnDwdjdktlSNxk=";
+ })
+ ];
+
build-system = [
meson
meson-python
diff --git a/pkgs/servers/home-assistant/default.nix b/pkgs/servers/home-assistant/default.nix
index a7972e6e6d9a..bd13da4c6956 100644
--- a/pkgs/servers/home-assistant/default.nix
+++ b/pkgs/servers/home-assistant/default.nix
@@ -95,6 +95,16 @@ let
];
});
+ google-genai = super.google-genai.overridePythonAttrs rec {
+ version = "1.38.0";
+ src = fetchFromGitHub {
+ owner = "googleapis";
+ repo = "python-genai";
+ tag = "v${version}";
+ hash = "sha256-gJaLEpNKHl6n1MvQDIUW7ynsHYH2eEPGsYso5jSysNg=";
+ };
+ };
+
gspread = super.gspread.overridePythonAttrs (oldAttrs: rec {
version = "5.12.4";
src = fetchFromGitHub {
diff --git a/pkgs/tools/archivers/gnutar/default.nix b/pkgs/tools/archivers/gnutar/default.nix
index 02eae53b58e0..1ddcfb22f04b 100644
--- a/pkgs/tools/archivers/gnutar/default.nix
+++ b/pkgs/tools/archivers/gnutar/default.nix
@@ -5,6 +5,7 @@
autoreconfHook,
updateAutotoolsGnuConfigScriptsHook,
libintl,
+ gettext,
aclSupport ? lib.meta.availableOn stdenv.hostPlatform acl,
acl,
}:
@@ -46,7 +47,13 @@ stdenv.mkDerivation rec {
# "_libintl_textdomain", referenced from:
# _main in tar.o
# ld: symbol(s) not found for architecture x86_64
- buildInputs = lib.optional aclSupport acl ++ lib.optional stdenv.hostPlatform.isDarwin libintl;
+ buildInputs =
+ lib.optional aclSupport acl
+ ++ lib.optional stdenv.hostPlatform.isDarwin libintl
+ # gettext gets pulled in via autoreconfHook because strictDeps is not set,
+ # and is linked against. Without this, it doesn't end up in HOST_PATH.
+ # TODO: enable strictDeps, and either make this dependency explicit, or remove it
+ ++ lib.optional stdenv.hostPlatform.isCygwin gettext;
# May have some issues with root compilation because the bootstrap tool
# cannot be used as a login shell for now.
@@ -54,14 +61,6 @@ stdenv.mkDerivation rec {
stdenv.hostPlatform.system == "armv7l-linux" || stdenv.hostPlatform.isSunOS
) "1";
- preConfigure =
- if stdenv.hostPlatform.isCygwin then
- ''
- sed -i gnu/fpending.h -e 's,include ,,'
- ''
- else
- null;
-
doCheck = false; # fails
doInstallCheck = false; # fails
diff --git a/pkgs/tools/compression/gzip/default.nix b/pkgs/tools/compression/gzip/default.nix
index 0e756eab0113..85b452f2260b 100644
--- a/pkgs/tools/compression/gzip/default.nix
+++ b/pkgs/tools/compression/gzip/default.nix
@@ -62,6 +62,12 @@ stdenv.mkDerivation (finalAttrs: {
sed -i '1{;/#!\/bin\/sh/aPATH="'$out'/bin:$PATH"
}' $out/bin/*
''
+ # avoid wrapping the actual executable on cygwin because changing the
+ # extension will break dll linking
+ + lib.optionalString stdenv.hostPlatform.isCygwin ''
+ mv $out/bin/{,.}gzip.exe
+ ln -s .gzip.exe $out/bin/gzip
+ ''
# run gzip with "-n" when $GZIP_NO_TIMESTAMPS (set by stdenv's setup.sh) is set to stop gzip from adding timestamps
# to archive headers: https://github.com/NixOS/nixpkgs/issues/86348
# if changing so that there's no longer a .gzip-wrapped then update copy in make-bootstrap-tools.nix
diff --git a/pkgs/tools/security/web-eid-app/default.nix b/pkgs/tools/security/web-eid-app/default.nix
index 0d8df0f677a6..dae430bbadb3 100644
--- a/pkgs/tools/security/web-eid-app/default.nix
+++ b/pkgs/tools/security/web-eid-app/default.nix
@@ -1,23 +1,24 @@
{
lib,
- mkDerivation,
+ stdenv,
fetchFromGitHub,
cmake,
gtest,
pcsclite,
pkg-config,
qttools,
+ wrapQtAppsHook,
}:
-mkDerivation rec {
+stdenv.mkDerivation rec {
pname = "web-eid-app";
- version = "2.6.0";
+ version = "2.8.0";
src = fetchFromGitHub {
owner = "web-eid";
repo = "web-eid-app";
rev = "v${version}";
- hash = "sha256-UqHT85zuoT/ISFP2qgG2J1518eGEvm5L96ntZ/lx9BE=";
+ hash = "sha256-J0ZUE22zHAYST4GttfBMXQ4ibO7bGuO2ZMBJdO0GsMw=";
fetchSubmodules = true;
};
@@ -25,6 +26,7 @@ mkDerivation rec {
cmake
pkg-config
qttools
+ wrapQtAppsHook
];
buildInputs = [
@@ -43,6 +45,7 @@ mkDerivation rec {
mode.
'';
homepage = "https://github.com/web-eid/web-eid-app";
+ changelog = "https://github.com/web-eid/web-eid-app/releases/tag/${src.rev}";
license = lib.licenses.mit;
maintainers = [ lib.maintainers.flokli ];
platforms = lib.platforms.linux;
diff --git a/pkgs/top-level/aliases.nix b/pkgs/top-level/aliases.nix
index 894042f7d9ab..274d6d29b018 100644
--- a/pkgs/top-level/aliases.nix
+++ b/pkgs/top-level/aliases.nix
@@ -1415,6 +1415,7 @@ mapAliases {
qtile-unwrapped = throw "'qtile-unwrapped' has been renamed to/replaced by 'python3.pkgs.qtile'"; # Converted to throw 2025-10-27
quantum-espresso-mpi = throw "'quantum-espresso-mpi' has been renamed to/replaced by 'quantum-espresso'"; # Converted to throw 2025-10-27
quaternion-qt5 = throw "'quaternion-qt5' has been removed as quaternion dropped Qt5 support with v0.0.97.1"; # Added 2025-05-24
+ quaternion-qt6 = warnAlias "'quaternion-qt6 has been renamed to quaternion"; # Added 2025-12-31
qubes-core-vchan-xen = throw "'qubes-core-vchan-xen' has been removed because it has been marked as broken since at least November 2024."; # Added 2025-10-11
quicksynergy = throw "'quicksynergy' has been removed due to lack of maintenance upstream. Consider using 'deskflow' instead."; # Added 2025-06-18
quictls = throw "'quictls' has been removed. QUIC support is now available in `openssl`.";
diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix
index cc13466d8197..46b0d16d3947 100644
--- a/pkgs/top-level/all-packages.nix
+++ b/pkgs/top-level/all-packages.nix
@@ -1670,11 +1670,6 @@ with pkgs;
charles5
;
- quaternion-qt6 =
- qt6Packages.callPackage ../applications/networking/instant-messengers/quaternion
- { };
- quaternion = quaternion-qt6;
-
tensor = libsForQt5.callPackage ../applications/networking/instant-messengers/tensor { };
libtensorflow = python3.pkgs.tensorflow-build.libtensorflow;
@@ -4010,7 +4005,7 @@ with pkgs;
# https://github.com/NixOS/nixpkgs/issues/227327
wafHook = waf.hook;
- web-eid-app = libsForQt5.callPackage ../tools/security/web-eid-app { };
+ web-eid-app = qt6Packages.callPackage ../tools/security/web-eid-app { };
wio = callPackage ../by-name/wi/wio/package.nix {
wlroots = wlroots_0_19;
diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix
index d842e1237650..968612bf3171 100644
--- a/pkgs/top-level/perl-packages.nix
+++ b/pkgs/top-level/perl-packages.nix
@@ -8827,10 +8827,10 @@ with self;
DateManip = buildPerlPackage {
pname = "Date-Manip";
- version = "6.92";
+ version = "6.98";
src = fetchurl {
- url = "mirror://cpan/authors/id/S/SB/SBECK/Date-Manip-6.92.tar.gz";
- hash = "sha256-q5Yr05ygnsb8/n5aaRKvcbDB9vA+TtK+9uRHHJ02ehM=";
+ url = "mirror://cpan/authors/id/S/SB/SBECK/Date-Manip-6.98.tar.gz";
+ hash = "sha256-rP2KYFGbpM0YHIpnqD1/ApxtmrTosCEtxH5B1iEP2kk=";
};
# for some reason, parsing /etc/localtime does not work anymore - make sure that the fallback "/bin/date +%Z" will work
patchPhase = ''