From b9481444f41c876118bcd4251c94c10fe6d1bae3 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 21 Nov 2024 14:09:00 +0000 Subject: [PATCH 1/6] git-lfs: 3.5.1 -> 3.6.0 (cherry picked from commit 1c537cf04ac89ffb85f45963d114d5463eae90e2) --- pkgs/applications/version-management/git-lfs/default.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/applications/version-management/git-lfs/default.nix b/pkgs/applications/version-management/git-lfs/default.nix index b62466e85b12..eb6b52c2809a 100644 --- a/pkgs/applications/version-management/git-lfs/default.nix +++ b/pkgs/applications/version-management/git-lfs/default.nix @@ -12,16 +12,16 @@ buildGoModule rec { pname = "git-lfs"; - version = "3.5.1"; + version = "3.6.0"; src = fetchFromGitHub { owner = "git-lfs"; repo = "git-lfs"; rev = "v${version}"; - hash = "sha256-xSLXbAvIoY3c341qi89pTrjBZdXh/bPrweJD2O2gkjY="; + hash = "sha256-PpNdbvtDAZDT43yyEkUvnhfUTAMM+mYImb3dVbAVPic="; }; - vendorHash = "sha256-N8HB2qwBxjzfNucftHxmX2W9srCx62pjmkCWzwiCj/I="; + vendorHash = "sha256-JT0r/hs7ZRtsYh4aXy+v8BjwiLvRJ10e4yRirqmWVW0="; nativeBuildInputs = [ asciidoctor From 6d864b07647c77b910484dc4983f54ec7baafa08 Mon Sep 17 00:00:00 2001 From: Gaetan Lepage Date: Wed, 4 Dec 2024 15:55:15 +0100 Subject: [PATCH 2/6] git-lfs: minor improvements (cherry picked from commit 719b30aeb3c06744480f754f7ad5109d1de46c08) --- .../version-management/git-lfs/default.nix | 24 ++++++++++++------- 1 file changed, 15 insertions(+), 9 deletions(-) diff --git a/pkgs/applications/version-management/git-lfs/default.nix b/pkgs/applications/version-management/git-lfs/default.nix index eb6b52c2809a..7b2e8381155e 100644 --- a/pkgs/applications/version-management/git-lfs/default.nix +++ b/pkgs/applications/version-management/git-lfs/default.nix @@ -1,13 +1,13 @@ { lib, + stdenv, buildGoModule, fetchFromGitHub, asciidoctor, installShellFiles, git, - testers, - git-lfs, - stdenv, + versionCheckHook, + nix-update-script, }: buildGoModule rec { @@ -17,7 +17,7 @@ buildGoModule rec { src = fetchFromGitHub { owner = "git-lfs"; repo = "git-lfs"; - rev = "v${version}"; + rev = "refs/tags/v${version}"; hash = "sha256-PpNdbvtDAZDT43yyEkUvnhfUTAMM+mYImb3dVbAVPic="; }; @@ -61,16 +61,22 @@ buildGoModule rec { --zsh <($out/bin/git-lfs completion zsh) ''; - passthru.tests.version = testers.testVersion { - package = git-lfs; + nativeInstallCheckInputs = [ + versionCheckHook + ]; + versionCheckProgramArg = [ "--version" ]; + doInstallCheck = true; + + passthru = { + updateScript = nix-update-script { }; }; - meta = with lib; { + meta = { description = "Git extension for versioning large files"; homepage = "https://git-lfs.github.com/"; changelog = "https://github.com/git-lfs/git-lfs/raw/v${version}/CHANGELOG.md"; - license = licenses.mit; - maintainers = with maintainers; [ twey ]; + license = lib.licenses.mit; + maintainers = with lib.maintainers; [ twey ]; mainProgram = "git-lfs"; }; } From b9c14c52dc4c90dd961c004086ebdef6f1f1c421 Mon Sep 17 00:00:00 2001 From: Gaetan Lepage Date: Wed, 4 Dec 2024 16:19:04 +0100 Subject: [PATCH 3/6] git-lfs: disable network tests on darwin (cherry picked from commit cc006aed5e75d43ca4b463f679fa2594764f553b) --- .../version-management/git-lfs/default.nix | 33 +++++++++++++++++++ 1 file changed, 33 insertions(+) diff --git a/pkgs/applications/version-management/git-lfs/default.nix b/pkgs/applications/version-management/git-lfs/default.nix index 7b2e8381155e..da5fa88179cc 100644 --- a/pkgs/applications/version-management/git-lfs/default.nix +++ b/pkgs/applications/version-management/git-lfs/default.nix @@ -50,6 +50,37 @@ buildGoModule rec { unset subPackages ''; + checkFlags = lib.optionals stdenv.hostPlatform.isDarwin ( + let + # Fail in the sandbox with network-related errors. + # Enabling __darwinAllowLocalNetworking is not enough. + skippedTests = [ + "TestAPIBatch" + "TestAPIBatchOnlyBasic" + "TestAuthErrWithBody" + "TestAuthErrWithoutBody" + "TestCertFromSSLCAInfoConfig" + "TestCertFromSSLCAInfoEnv" + "TestCertFromSSLCAInfoEnvWithSchannelBackend" + "TestCertFromSSLCAPathConfig" + "TestCertFromSSLCAPathEnv" + "TestClientRedirect" + "TestClientRedirectReauthenticate" + "TestDoAPIRequestWithAuth" + "TestDoWithAuthApprove" + "TestDoWithAuthNoRetry" + "TestDoWithAuthReject" + "TestFatalWithBody" + "TestFatalWithoutBody" + "TestHttp2" + "TestHttpVersion" + "TestWithNonFatal500WithBody" + "TestWithNonFatal500WithoutBody" + ]; + in + [ "-skip=^${builtins.concatStringsSep "$|^" skippedTests}$" ] + ); + postInstall = '' installManPage man/man*/* @@ -71,6 +102,8 @@ buildGoModule rec { updateScript = nix-update-script { }; }; + __darwinAllowLocalNetworking = true; + meta = { description = "Git extension for versioning large files"; homepage = "https://git-lfs.github.com/"; From e06a51767295a73a9b7f36f9f3d4f6c714fc5b0e Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Wed, 25 Jun 2025 00:03:56 -0400 Subject: [PATCH 4/6] git-lfs: migrate fetchgit `rev = "refs/tags/..."` to `tag` Not a cherry-pick, as the filename changed and the commit is a treewide. But identical to the diff for this file from 0cd04d30366f52fe9dd7664fb7decf4b93b1d789. --- pkgs/applications/version-management/git-lfs/default.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/applications/version-management/git-lfs/default.nix b/pkgs/applications/version-management/git-lfs/default.nix index da5fa88179cc..cecabf2a76e1 100644 --- a/pkgs/applications/version-management/git-lfs/default.nix +++ b/pkgs/applications/version-management/git-lfs/default.nix @@ -17,7 +17,7 @@ buildGoModule rec { src = fetchFromGitHub { owner = "git-lfs"; repo = "git-lfs"; - rev = "refs/tags/v${version}"; + tag = "v${version}"; hash = "sha256-PpNdbvtDAZDT43yyEkUvnhfUTAMM+mYImb3dVbAVPic="; }; From 8176237e26cda0328d79329be6247e4c88d6ef7b Mon Sep 17 00:00:00 2001 From: Thomas Gerbet Date: Tue, 14 Jan 2025 20:35:31 +0100 Subject: [PATCH 5/6] git-lfs: 3.6.0 -> 3.6.1 Fixes CVE-2024-53263 Changes: https://github.com/git-lfs/git-lfs/releases/tag/v3.6.1 (cherry picked from commit 8ab70837ff5b7406c9e57a5e81b22fc8d8b08330) --- pkgs/applications/version-management/git-lfs/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/version-management/git-lfs/default.nix b/pkgs/applications/version-management/git-lfs/default.nix index cecabf2a76e1..8df608c614fe 100644 --- a/pkgs/applications/version-management/git-lfs/default.nix +++ b/pkgs/applications/version-management/git-lfs/default.nix @@ -12,13 +12,13 @@ buildGoModule rec { pname = "git-lfs"; - version = "3.6.0"; + version = "3.6.1"; src = fetchFromGitHub { owner = "git-lfs"; repo = "git-lfs"; tag = "v${version}"; - hash = "sha256-PpNdbvtDAZDT43yyEkUvnhfUTAMM+mYImb3dVbAVPic="; + hash = "sha256-zZ9VYWVV+8G3gojj1m74syvsYM1mX0YT4hKnpkdMAQk="; }; vendorHash = "sha256-JT0r/hs7ZRtsYh4aXy+v8BjwiLvRJ10e4yRirqmWVW0="; From 252c5e148456498621b3997a3ef930d213159900 Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Wed, 25 Jun 2025 00:08:38 -0400 Subject: [PATCH 6/6] git-lfs: use a string for versionCheckProgramArg where possible Not a cherry-pick, as the filename changed and the commit is a treewide. But identical to the diff for this file from bfe27cf81c881138fcaa0329b3ad51832558dcab. --- pkgs/applications/version-management/git-lfs/default.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/applications/version-management/git-lfs/default.nix b/pkgs/applications/version-management/git-lfs/default.nix index 8df608c614fe..42d7b2b17abc 100644 --- a/pkgs/applications/version-management/git-lfs/default.nix +++ b/pkgs/applications/version-management/git-lfs/default.nix @@ -95,7 +95,7 @@ buildGoModule rec { nativeInstallCheckInputs = [ versionCheckHook ]; - versionCheckProgramArg = [ "--version" ]; + versionCheckProgramArg = "--version"; doInstallCheck = true; passthru = {