From 9dd5558b06dbdacbf635a3dd36dce1b1a7ee3a89 Mon Sep 17 00:00:00 2001 From: Thierry Delafontaine Date: Fri, 10 Apr 2026 22:16:24 +0000 Subject: [PATCH 01/71] bun: 1.3.11 -> 1.3.13 https://bun.sh/blog/bun-v1.3.12 https://bun.sh/blog/bun-v1.3.13 --- pkgs/by-name/bu/bun/package.nix | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/by-name/bu/bun/package.nix b/pkgs/by-name/bu/bun/package.nix index 0baa565112f7..3ca623f770e5 100644 --- a/pkgs/by-name/bu/bun/package.nix +++ b/pkgs/by-name/bu/bun/package.nix @@ -17,7 +17,7 @@ }: stdenvNoCC.mkDerivation (finalAttrs: { - version = "1.3.11"; + version = "1.3.13"; pname = "bun"; src = @@ -81,19 +81,19 @@ stdenvNoCC.mkDerivation (finalAttrs: { sources = { "aarch64-darwin" = fetchurl { url = "https://github.com/oven-sh/bun/releases/download/bun-v${finalAttrs.version}/bun-darwin-aarch64.zip"; - hash = "sha256-b1o0Z+2crsR5W/eM1HZQfZ+HDH1XuGyUX8szgSZ3L/w="; + hash = "sha256-VGfj9l26Umuf6pjwzOBO+vwMY+Fpcz7Ce4dqOtMtoZA="; }; "aarch64-linux" = fetchurl { url = "https://github.com/oven-sh/bun/releases/download/bun-v${finalAttrs.version}/bun-linux-aarch64.zip"; - hash = "sha256-0TlE2hKlPsx0v2pyC9HQTEVVwDjf5CI2U1anvkdpH98="; + hash = "sha256-cLrkGzkIsKEg4eWMXIrzDnSvrjuNEbDT/djnh937SyI="; }; "x86_64-darwin" = fetchurl { url = "https://github.com/oven-sh/bun/releases/download/bun-v${finalAttrs.version}/bun-darwin-x64-baseline.zip"; - hash = "sha256-+2c5sIv1RVDtqnyCTNWy3KRbagav70CEQwh6YxBfb40="; + hash = "sha256-qYumpIDyL9qbNDYmuQak4mqlNhi/hdK8WSjs8rpF8O0="; }; "x86_64-linux" = fetchurl { url = "https://github.com/oven-sh/bun/releases/download/bun-v${finalAttrs.version}/bun-linux-x64.zip"; - hash = "sha256-hhG6k1r4hvBabzh0ChUWAybBXl1dB63vlmEwtEk2B+0="; + hash = "sha256-ecB3H6i5LDOq5B4VoODTB+qZ0OLwAxfHHGxTI3p44lo="; }; }; updateScript = writeShellScript "update-bun" '' From ecbfb55dcc993cda2d6dcdf8cde68acabc79a975 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Mon, 13 Apr 2026 16:13:59 +0200 Subject: [PATCH 02/71] xfce4-session: enable strictDeps --- pkgs/by-name/xf/xfce4-session/package.nix | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/xf/xfce4-session/package.nix b/pkgs/by-name/xf/xfce4-session/package.nix index 01de6eb316e4..453da3ff08ab 100644 --- a/pkgs/by-name/xf/xfce4-session/package.nix +++ b/pkgs/by-name/xf/xfce4-session/package.nix @@ -7,6 +7,7 @@ xfce4-dev-tools, wrapGAppsHook3, polkit, + bashNonInteractive, xfce4-exo, libxfce4util, libxfce4ui, @@ -37,9 +38,11 @@ stdenv.mkDerivation (finalAttrs: { pkg-config xfce4-dev-tools wrapGAppsHook3 + iceauth ]; buildInputs = [ + bashNonInteractive xfce4-exo gtk3 gtk-layer-shell @@ -50,9 +53,10 @@ stdenv.mkDerivation (finalAttrs: { libwnck xfconf polkit - iceauth ]; + strictDeps = true; + configureFlags = [ "--enable-maintainer-mode" "--with-xsession-prefix=${placeholder "out"}" From 21fd76392df2db992eb6b817d9fb1bf1e5784a85 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 27 Apr 2026 15:24:51 +0000 Subject: [PATCH 03/71] ente-web: 1.3.32 -> 1.3.36 --- pkgs/by-name/en/ente-web/package.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/en/ente-web/package.nix b/pkgs/by-name/en/ente-web/package.nix index e6b77b8d8679..7ba48dbf8d3f 100644 --- a/pkgs/by-name/en/ente-web/package.nix +++ b/pkgs/by-name/en/ente-web/package.nix @@ -27,7 +27,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "ente-web-${enteApp}"; - version = "1.3.32"; + version = "1.3.36"; src = fetchFromGitHub { owner = "ente-io"; @@ -38,7 +38,7 @@ stdenv.mkDerivation (finalAttrs: { ]; tag = "photos-v${finalAttrs.version}"; fetchSubmodules = true; - hash = "sha256-Lwa45QqqyvFgHJ4IiJm2tJy5CdPI5XO3wCzXTeNCTq4="; + hash = "sha256-o75r8LFgG3BT3IIPiD9x6gY3fRDoxJ3ZTBPAYr3hLWI="; }; sourceRoot = "${finalAttrs.src.name}/web"; @@ -50,13 +50,13 @@ stdenv.mkDerivation (finalAttrs: { sourceRoot cargoRoot ; - hash = "sha256-/FkAxi9KpW/Z6sdo7gfxvCmaAe0JzjubScrcGjbLD88="; + hash = "sha256-NYPxaVYEaJVcsRX6wLVJd+/UUJrNel0zTPYGdEv8a+U="; }; cargoRoot = "packages/wasm"; offlineCache = fetchYarnDeps { yarnLock = "${finalAttrs.src}/web/yarn.lock"; - hash = "sha256-bWOwIa7SD0z2StoUg9HlQGTBq2xXltLgQ2ft8umjg/Y="; + hash = "sha256-eGu+s8g0nGijYfjo8RkT5/iBfbwk5cBMacbe/gO03NI="; }; nativeBuildInputs = [ From efc7009dd0ef120dfa8126485aceb5262ea5191a Mon Sep 17 00:00:00 2001 From: myul <52401682+mtul0729@users.noreply.github.com> Date: Wed, 29 Apr 2026 00:21:00 +0800 Subject: [PATCH 04/71] bitwarden-desktop: build desktop_napi with --release --- pkgs/by-name/bi/bitwarden-desktop/package.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/by-name/bi/bitwarden-desktop/package.nix b/pkgs/by-name/bi/bitwarden-desktop/package.nix index 926bfdde293d..1409c8e06c67 100644 --- a/pkgs/by-name/bi/bitwarden-desktop/package.nix +++ b/pkgs/by-name/bi/bitwarden-desktop/package.nix @@ -134,7 +134,7 @@ buildNpmPackage' rec { patchShebangs apps/desktop/node_modules pushd apps/desktop/desktop_native/napi - npm run build + npm run build -- --release popd pushd apps/desktop/desktop_native/proxy From 6325e7ff1406f7af435042429601dc29d74cbebe Mon Sep 17 00:00:00 2001 From: Eman Resu <78693624+quatquatt@users.noreply.github.com> Date: Sun, 26 Apr 2026 15:04:05 -0400 Subject: [PATCH 05/71] lib.extendDerivation: inline variables --- lib/customisation.nix | 8 ++------ 1 file changed, 2 insertions(+), 6 deletions(-) diff --git a/lib/customisation.nix b/lib/customisation.nix index ce00e364ba76..1a2815098420 100644 --- a/lib/customisation.nix +++ b/lib/customisation.nix @@ -409,12 +409,10 @@ rec { extendDerivation = condition: passthru: drv: let - outputs = drv.outputs or [ "out" ]; - commonAttrs = drv // (listToAttrs outputsList) // { all = map (x: x.value) outputsList; } // passthru; - outputToAttrListElement = outputName: { + outputsList = map (outputName: { name = outputName; value = commonAttrs @@ -436,9 +434,7 @@ rec { # TODO: also add overrideAttrs when overrideAttrs is not custom, e.g. when not splicing. overrideAttrs = f: (passthru.overrideAttrs f).${outputName}; }; - }; - - outputsList = map outputToAttrListElement outputs; + }) (drv.outputs or [ "out" ]); in commonAttrs // { From 8ccea3bf6cc28d7754f2dd7d4028b96ee0c5212c Mon Sep 17 00:00:00 2001 From: Eman Resu <78693624+quatquatt@users.noreply.github.com> Date: Sun, 26 Apr 2026 15:11:21 -0400 Subject: [PATCH 06/71] lib.extendDerivation: avoid optionalAttrs merge --- lib/customisation.nix | 36 ++++++++++++++++-------------------- 1 file changed, 16 insertions(+), 20 deletions(-) diff --git a/lib/customisation.nix b/lib/customisation.nix index 1a2815098420..d6a1eb8d9bab 100644 --- a/lib/customisation.nix +++ b/lib/customisation.nix @@ -414,26 +414,22 @@ rec { outputsList = map (outputName: { name = outputName; - value = - commonAttrs - // { - inherit (drv.${outputName}) type outputName; - outputSpecified = true; - drvPath = - assert condition; - drv.${outputName}.drvPath; - outPath = - assert condition; - drv.${outputName}.outPath; - } - // - # TODO: give the derivation control over the outputs. - # `overrideAttrs` may not be the only attribute that needs - # updating when switching outputs. - optionalAttrs (passthru ? overrideAttrs) { - # TODO: also add overrideAttrs when overrideAttrs is not custom, e.g. when not splicing. - overrideAttrs = f: (passthru.overrideAttrs f).${outputName}; - }; + value = commonAttrs // { + inherit (drv.${outputName}) type outputName; + outputSpecified = true; + drvPath = + assert condition; + drv.${outputName}.drvPath; + outPath = + assert condition; + drv.${outputName}.outPath; + # TODO: give the derivation control over the outputs. + # `overrideAttrs` may not be the only attribute that needs + # updating when switching outputs. + # TODO: also add overrideAttrs when overrideAttrs is not custom, e.g. when not splicing. + ${if passthru ? overrideAttrs then "overrideAttrs" else null} = + f: (passthru.overrideAttrs f).${outputName}; + }; }) (drv.outputs or [ "out" ]); in commonAttrs From 1e022acbf5861841e47e8fbac78fb483dc488e94 Mon Sep 17 00:00:00 2001 From: Eman Resu <78693624+quatquatt@users.noreply.github.com> Date: Sun, 26 Apr 2026 15:41:33 -0400 Subject: [PATCH 07/71] lib.makeOverridable: inline several variables --- lib/customisation.nix | 30 +++++++++++++++--------------- 1 file changed, 15 insertions(+), 15 deletions(-) diff --git a/lib/customisation.nix b/lib/customisation.nix index d6a1eb8d9bab..fdaf80c9b6b8 100644 --- a/lib/customisation.nix +++ b/lib/customisation.nix @@ -159,28 +159,28 @@ rec { # When f is a callable attribute set, # it may contain its own `f.override` and additional attributes. # This helper function recovers those attributes and decorate the overrider. - recoverMetadata = + decorate = + f': if isAttrs f then - fDecorated: - # Preserve additional attributes for f - f - // fDecorated - # Decorate f.override if presented - // lib.optionalAttrs (f ? override) { - override = fdrv: makeOverridable (f.override fdrv); - } + ( + fDecorated: + # Preserve additional attributes for f + f + // fDecorated + # Decorate f.override if presented + // lib.optionalAttrs (f ? override) { + override = fdrv: makeOverridable (f.override fdrv); + } + ) + (mirrorArgs f') else - id; - decorate = f': recoverMetadata (mirrorArgs f'); + mirrorArgs f'; in decorate ( origArgs: let result = f origArgs; - # Changes the original arguments with (potentially a function that returns) a set of new attributes - overrideWith = newArgs: origArgs // (if isFunction newArgs then newArgs origArgs else newArgs); - # Re-call the function but with different arguments overrideArgs = mirrorArgs ( /** @@ -190,7 +190,7 @@ rec { This function was provided by `lib.makeOverridable`. */ - newArgs: makeOverridable f (overrideWith newArgs) + newArgs: makeOverridable f (origArgs // (if isFunction newArgs then newArgs origArgs else newArgs)) ); # Change the result of the function call by applying g to it overrideResult = g: makeOverridable (mirrorArgs (args: g (f args))) origArgs; From c33811716d42e163f76f6d2b5cbe0c1c5777e40a Mon Sep 17 00:00:00 2001 From: Eman Resu <78693624+quatquatt@users.noreply.github.com> Date: Mon, 27 Apr 2026 11:06:55 -0400 Subject: [PATCH 08/71] lib.makeOverridable: avoid optionalAttrs merge --- lib/customisation.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/lib/customisation.nix b/lib/customisation.nix index fdaf80c9b6b8..f20298cb8808 100644 --- a/lib/customisation.nix +++ b/lib/customisation.nix @@ -168,8 +168,8 @@ rec { f // fDecorated # Decorate f.override if presented - // lib.optionalAttrs (f ? override) { - override = fdrv: makeOverridable (f.override fdrv); + // { + ${if f ? override then "override" else null} = fdrv: makeOverridable (f.override fdrv); } ) (mirrorArgs f') From cb1edb818340d88e7bd33f061dfa59e058199e89 Mon Sep 17 00:00:00 2001 From: Eman Resu <78693624+quatquatt@users.noreply.github.com> Date: Mon, 27 Apr 2026 11:32:52 -0400 Subject: [PATCH 09/71] lib.makeOverridable: inline helper function into its usages Also perform some manual beta reductions. --- lib/customisation.nix | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) diff --git a/lib/customisation.nix b/lib/customisation.nix index f20298cb8808..95f1d5ebf69e 100644 --- a/lib/customisation.nix +++ b/lib/customisation.nix @@ -192,14 +192,12 @@ rec { */ newArgs: makeOverridable f (origArgs // (if isFunction newArgs then newArgs origArgs else newArgs)) ); - # Change the result of the function call by applying g to it - overrideResult = g: makeOverridable (mirrorArgs (args: g (f args))) origArgs; in if isAttrs result then result // { override = overrideArgs; - overrideDerivation = fdrv: overrideResult (x: overrideDerivation x fdrv); + overrideDerivation = fdrv: makeOverridable (mirrorArgs (args: overrideDerivation (f args) fdrv)) origArgs; ${if result ? overrideAttrs then "overrideAttrs" else null} = /** Override the attributes that were passed to `mkDerivation` in order to generate this derivation. @@ -211,7 +209,7 @@ rec { */ # NOTE: part of the above documentation had to be duplicated in `mkDerivation`'s `overrideAttrs`. # design/tech debt issue: https://github.com/NixOS/nixpkgs/issues/273815 - fdrv: overrideResult (x: x.overrideAttrs fdrv); + fdrv: makeOverridable (mirrorArgs (args: (f args).overrideAttrs fdrv)) origArgs; } else if isFunction result then # Transform the result into a functor while propagating its arguments From 32271580219a89a34906a12f6171df17053726dd Mon Sep 17 00:00:00 2001 From: Eman Resu <78693624+quatquatt@users.noreply.github.com> Date: Mon, 27 Apr 2026 18:42:16 -0400 Subject: [PATCH 10/71] lib.meta.availableOn: move negation outside loop Also exit early without meta.badPlatforms. This is a very hot function thanks to its usage in stdenv check-meta. --- lib/meta.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/meta.nix b/lib/meta.nix index 3341caf0e0fb..ba0870c1a94d 100644 --- a/lib/meta.nix +++ b/lib/meta.nix @@ -368,7 +368,7 @@ rec { availableOn = platform: pkg: ((!pkg ? meta.platforms) || any (platformMatch platform) pkg.meta.platforms) - && all (elem: !platformMatch platform elem) (pkg.meta.badPlatforms or [ ]); + && ((!pkg ? meta.badPlatforms) || !(any (platformMatch platform) pkg.meta.badPlatforms)); /** Mapping of SPDX ID to the attributes in lib.licenses. From 57b321c19098f311478c037842433cfed8358fd4 Mon Sep 17 00:00:00 2001 From: Eman Resu <78693624+quatquatt@users.noreply.github.com> Date: Mon, 27 Apr 2026 18:52:06 -0400 Subject: [PATCH 11/71] stdenv/check-meta: inline negation of availableOn --- pkgs/stdenv/generic/check-meta.nix | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/pkgs/stdenv/generic/check-meta.nix b/pkgs/stdenv/generic/check-meta.nix index e651e012d34e..5ec1e77e1f90 100644 --- a/pkgs/stdenv/generic/check-meta.nix +++ b/pkgs/stdenv/generic/check-meta.nix @@ -37,7 +37,7 @@ let ; inherit (lib.meta) - availableOn + platformMatch cpeFullVersionWithVendor ; @@ -122,7 +122,14 @@ let isMarkedBroken = attrs: attrs.meta.broken or false; - hasUnsupportedPlatform = pkg: !(availableOn hostPlatform pkg); + # Logical inversion of meta.availableOn for hostPlatform + hasUnsupportedPlatform = + let + anyHostPlatform = any (platformMatch hostPlatform); + in + pkg: + pkg ? meta.platforms && !(anyHostPlatform pkg.meta.platforms) + || pkg ? meta.badPlatforms && anyHostPlatform pkg.meta.badPlatforms; isMarkedInsecure = attrs: (attrs.meta.knownVulnerabilities or [ ]) != [ ]; From 7c145d032046cb1e2ebfa3e179e854391f49cc86 Mon Sep 17 00:00:00 2001 From: Eman Resu <78693624+quatquatt@users.noreply.github.com> Date: Tue, 28 Apr 2026 07:28:26 -0400 Subject: [PATCH 12/71] stdenv/check-meta: check condition before typechecking --- pkgs/stdenv/generic/check-meta.nix | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/pkgs/stdenv/generic/check-meta.nix b/pkgs/stdenv/generic/check-meta.nix index 5ec1e77e1f90..d2c6c74b293e 100644 --- a/pkgs/stdenv/generic/check-meta.nix +++ b/pkgs/stdenv/generic/check-meta.nix @@ -388,10 +388,11 @@ let identifiers = attrs; }; - metaInvalid = if config.checkMeta then meta: !metaType.verify meta else meta: false; + checkMeta = config.checkMeta; + metaInvalid = meta: !metaType.verify meta; checkOutputsToInstall = - if config.checkMeta then + if checkMeta then attrs: let actualOutputs = attrs.outputs or [ "out" ]; @@ -412,7 +413,7 @@ let attrs: # Check meta attribute types first, to make sure it is always called even when there are other issues # Note that this is not a full type check and functions below still need to by careful about their inputs! - if metaInvalid (attrs.meta or { }) then + if checkMeta && metaInvalid (attrs.meta or { }) then { reason = "unknown-meta"; msg = "has an invalid meta attrset:${ From 1d12e66bc2bd4f7074051c4138e08aea89052ef2 Mon Sep 17 00:00:00 2001 From: Eman Resu <78693624+quatquatt@users.noreply.github.com> Date: Tue, 28 Apr 2026 08:07:23 -0400 Subject: [PATCH 13/71] stdenv/check-meta: check config before checking meta outputs --- pkgs/stdenv/generic/check-meta.nix | 15 ++++++--------- 1 file changed, 6 insertions(+), 9 deletions(-) diff --git a/pkgs/stdenv/generic/check-meta.nix b/pkgs/stdenv/generic/check-meta.nix index d2c6c74b293e..d219cf47e28b 100644 --- a/pkgs/stdenv/generic/check-meta.nix +++ b/pkgs/stdenv/generic/check-meta.nix @@ -392,14 +392,11 @@ let metaInvalid = meta: !metaType.verify meta; checkOutputsToInstall = - if checkMeta then - attrs: - let - actualOutputs = attrs.outputs or [ "out" ]; - in - any (output: !elem output actualOutputs) (attrs.meta.outputsToInstall or [ ]) - else - attrs: false; + attrs: + let + actualOutputs = attrs.outputs or [ "out" ]; + in + any (output: !elem output actualOutputs) (attrs.meta.outputsToInstall or [ ]); # Check if a derivation is valid, that is whether it passes checks for # e.g brokenness or license. @@ -423,7 +420,7 @@ let } # --- Put checks that cannot be ignored here --- - else if checkOutputsToInstall attrs then + else if checkMeta && checkOutputsToInstall attrs then { reason = "broken-outputs"; msg = "has invalid meta.outputsToInstall"; From 1be6d007b897797a7d2081dc00ad168434eb5a1f Mon Sep 17 00:00:00 2001 From: Eman Resu <78693624+quatquatt@users.noreply.github.com> Date: Tue, 28 Apr 2026 11:22:39 -0400 Subject: [PATCH 14/71] stdenv/check-meta: check that allowlist/blocklist nonempty first --- pkgs/stdenv/generic/check-meta.nix | 28 ++++++++++++---------------- 1 file changed, 12 insertions(+), 16 deletions(-) diff --git a/pkgs/stdenv/generic/check-meta.nix b/pkgs/stdenv/generic/check-meta.nix index d219cf47e28b..08fe10117cbf 100644 --- a/pkgs/stdenv/generic/check-meta.nix +++ b/pkgs/stdenv/generic/check-meta.nix @@ -81,20 +81,16 @@ let hasListedLicense = assert areLicenseListsValid; - list: - if list == [ ] then - attrs: false - else - attrs: - attrs ? meta.license - && ( - if isList attrs.meta.license then - any (l: elem l list) attrs.meta.license - else if attrs.meta.license ? "licenseType" then - lib.licenses.containsLicenses list attrs.meta.license - else - elem attrs.meta.license list - ); + list: attrs: + attrs ? meta.license + && ( + if isList attrs.meta.license then + any (l: elem l list) attrs.meta.license + else if attrs.meta.license ? "licenseType" then + lib.licenses.containsLicenses list attrs.meta.license + else + elem attrs.meta.license list + ); hasAllowlistedLicense = hasListedLicense allowlist; @@ -428,13 +424,13 @@ let } # --- Put checks that can be ignored here --- - else if hasDeniedUnfreeLicense attrs && !(hasAllowlistedLicense attrs) then + else if hasDeniedUnfreeLicense attrs && !(allowlist != [ ] && hasAllowlistedLicense attrs) then { reason = "unfree"; msg = "has an unfree license (‘${showLicense attrs.meta.license}’)"; remediation = remediate_allowlist "Unfree" (remediate_predicate "allowUnfreePredicate" attrs); } - else if hasBlocklistedLicense attrs then + else if blocklist != [ ] && hasBlocklistedLicense attrs then { reason = "blocklisted"; msg = "has a blocklisted license (‘${showLicense attrs.meta.license}’)"; From 3a7b504487cf8f30900f1f62a98a1ac760bc7cae Mon Sep 17 00:00:00 2001 From: Eman Resu <78693624+quatquatt@users.noreply.github.com> Date: Tue, 28 Apr 2026 08:20:29 -0400 Subject: [PATCH 15/71] stdenv/check-meta: check that sources allowed first --- pkgs/stdenv/generic/check-meta.nix | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/pkgs/stdenv/generic/check-meta.nix b/pkgs/stdenv/generic/check-meta.nix index 08fe10117cbf..31bda9690f69 100644 --- a/pkgs/stdenv/generic/check-meta.nix +++ b/pkgs/stdenv/generic/check-meta.nix @@ -181,7 +181,6 @@ let attrs: attrs ? meta.sourceProvenance && any (t: !t.isSource) attrs.meta.sourceProvenance - && !allowNonSource && !allowNonSourcePredicate attrs; showLicenseOrSourceType = @@ -436,7 +435,7 @@ let msg = "has a blocklisted license (‘${showLicense attrs.meta.license}’)"; remediation = ""; } - else if hasDeniedNonSourceProvenance attrs then + else if !allowNonSource && hasDeniedNonSourceProvenance attrs then { reason = "non-source"; msg = "contains elements not built from source (‘${showSourceType attrs.meta.sourceProvenance}’)"; From 4084a18fb16e211666544fd223dcbba48b17f4d7 Mon Sep 17 00:00:00 2001 From: Eman Resu <78693624+quatquatt@users.noreply.github.com> Date: Tue, 28 Apr 2026 08:29:10 -0400 Subject: [PATCH 16/71] stdenv/check-meta: exit early if no meta defined --- pkgs/stdenv/generic/check-meta.nix | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pkgs/stdenv/generic/check-meta.nix b/pkgs/stdenv/generic/check-meta.nix index 31bda9690f69..e3990a8eb0ab 100644 --- a/pkgs/stdenv/generic/check-meta.nix +++ b/pkgs/stdenv/generic/check-meta.nix @@ -403,9 +403,12 @@ let # Along with a boolean flag for each reason checkValidity = attrs: + if !attrs ? meta then + null + else # Check meta attribute types first, to make sure it is always called even when there are other issues # Note that this is not a full type check and functions below still need to by careful about their inputs! - if checkMeta && metaInvalid (attrs.meta or { }) then + if checkMeta && metaInvalid attrs.meta then { reason = "unknown-meta"; msg = "has an invalid meta attrset:${ From fe037eedc6eee0d521012f2460641ccd6cac45b4 Mon Sep 17 00:00:00 2001 From: Eman Resu <78693624+quatquatt@users.noreply.github.com> Date: Tue, 28 Apr 2026 11:39:21 -0400 Subject: [PATCH 17/71] stdenv/check-meta: inline verify call --- pkgs/stdenv/generic/check-meta.nix | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/pkgs/stdenv/generic/check-meta.nix b/pkgs/stdenv/generic/check-meta.nix index e3990a8eb0ab..67144ac147e6 100644 --- a/pkgs/stdenv/generic/check-meta.nix +++ b/pkgs/stdenv/generic/check-meta.nix @@ -384,7 +384,6 @@ let }; checkMeta = config.checkMeta; - metaInvalid = meta: !metaType.verify meta; checkOutputsToInstall = attrs: @@ -408,7 +407,7 @@ let else # Check meta attribute types first, to make sure it is always called even when there are other issues # Note that this is not a full type check and functions below still need to by careful about their inputs! - if checkMeta && metaInvalid attrs.meta then + if checkMeta && !metaType.verify attrs.meta then { reason = "unknown-meta"; msg = "has an invalid meta attrset:${ From 5a18a22ae09c94a7720917169d65822ff4f08860 Mon Sep 17 00:00:00 2001 From: whoomee Date: Thu, 30 Apr 2026 12:10:36 +0200 Subject: [PATCH 18/71] .gitattributes: update lock file attributes Mark additional lock files as generated (Rust, Ruby, PHP, and others). Remove node-packages.nix as it isn't used in Nix anymore. --- .gitattributes | 23 +++++++++++++++++++++-- 1 file changed, 21 insertions(+), 2 deletions(-) diff --git a/.gitattributes b/.gitattributes index 6f006049e92d..d67974e66b69 100644 --- a/.gitattributes +++ b/.gitattributes @@ -1,7 +1,26 @@ -**/deps.nix linguist-generated +# node/js lock files +**/package-lock.json linguist-generated +**/yarn.nix linguist-generated +**/yarn.lock linguist-generated + +# Rust lock files +**/Cargo.lock linguist-generated +pkgs/build-support/rust/**/Cargo.lock -linguist-generated + +# NuGet, Gradle and others **/deps.json linguist-generated + +# Ruby lock files +**/gemset.nix linguist-generated +**/Gemfile.lock linguist-generated + +# PHP lock files +**/composer.lock linguist-generated + +# various package managers and tools +**/deps.nix linguist-generated **/deps.toml linguist-generated -**/node-packages.nix linguist-generated + pkgs/applications/editors/emacs-modes/*-generated.nix linguist-generated pkgs/development/r-modules/*-packages.nix linguist-generated From c1e048eebcd138b22941726be3968fea70df7b88 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Fri, 1 May 2026 08:30:03 -0700 Subject: [PATCH 19/71] rnote: 0.14.1 -> 0.14.2 Diff: https://github.com/flxzt/rnote/compare/v0.14.1...v0.14.2 Changelog: https://github.com/flxzt/rnote/releases/tag/v0.14.2 --- pkgs/by-name/rn/rnote/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/rn/rnote/package.nix b/pkgs/by-name/rn/rnote/package.nix index 497ec619e3ef..33ec119668be 100644 --- a/pkgs/by-name/rn/rnote/package.nix +++ b/pkgs/by-name/rn/rnote/package.nix @@ -26,18 +26,18 @@ stdenv.mkDerivation (finalAttrs: { pname = "rnote"; - version = "0.14.1"; + version = "0.14.2"; src = fetchFromGitHub { owner = "flxzt"; repo = "rnote"; tag = "v${finalAttrs.version}"; - hash = "sha256-uOfFZuxxU8StirS5E/Tm8Lg58u8s4USgA9BeEUKw3xE="; + hash = "sha256-uuLoc1nWlb3Xm/WSrvjCit1G8kUZA3+HIW8akFXPGi4="; }; cargoDeps = rustPlatform.fetchCargoVendor { inherit (finalAttrs) pname version src; - hash = "sha256-N3mh/hGQ/Pu01uGL5e8BZvrrEm3u7cnJHSqt5FHynKQ="; + hash = "sha256-eDKyA8LaH+nvDcCG74ucWYSJc8qLmps1xz3WPHoOJ0w="; }; nativeBuildInputs = [ From 222ed18540ff853dcf8df329fc0f247e7252a8c5 Mon Sep 17 00:00:00 2001 From: sternenseemann Date: Fri, 1 May 2026 18:09:28 +0200 Subject: [PATCH 20/71] nixos/lib/systemd-lib: make unitNameType work with e.g. Rust regex The unitNameType regex currently makes the Tvix CI (and likely Snix in the future) fail since "sysroot-nix-.ro\\x2dstore.mount" will fail the check since it doesn't interpret the single backslash as part of the bracket expression. POSIX doesn't require escaping the backslash in bracket exprs: > The special characters '.', '*', '[', and '\\' ( , , > , and , respectively) shall lose their > special meaning within a bracket expression. However, Rust uses the backslash for escaping in bracket exprs, so it also needs to be escaped: > [\[\]] Escaping in character classes (matching [ or ]) Making the Regex work with both POSIX-like regexes and Rust's regex syntax is possible in this case, so let's do it. --- nixos/lib/systemd-lib.nix | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/nixos/lib/systemd-lib.nix b/nixos/lib/systemd-lib.nix index 13c529d53619..5c974f41dda5 100644 --- a/nixos/lib/systemd-lib.nix +++ b/nixos/lib/systemd-lib.nix @@ -67,7 +67,9 @@ rec { mkPathSafeName = replaceStrings [ "@" ":" "\\" "[" "]" ] [ "-" "-" "-" "" "" ]; # a type for options that take a unit name - unitNameType = types.strMatching "[a-zA-Z0-9@%:_.\\-]+[.](service|socket|device|mount|automount|swap|target|path|timer|scope|slice)"; + # note: redundantly escaping backslash in the bracket expression makes the regex + # slightly more portable even though POSIX doesn't require it. + unitNameType = types.strMatching "[a-zA-Z0-9@%:_.\\\\-]+[.](service|socket|device|mount|automount|swap|target|path|timer|scope|slice)"; makeUnit = name: unit: From 69aaea60901fe2e5c072766ba8070e0c5416ecb7 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Fri, 1 May 2026 10:07:59 -0700 Subject: [PATCH 21/71] python3Packages.miniaudio: 1.70 -> 1.71 Diff: https://github.com/irmen/pyminiaudio/compare/v1.70...v1.71 Changelog: https://github.com/irmen/pyminiaudio/releases/tag/v1.71 --- pkgs/development/python-modules/miniaudio/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/miniaudio/default.nix b/pkgs/development/python-modules/miniaudio/default.nix index da1056999e26..10df66a9d826 100644 --- a/pkgs/development/python-modules/miniaudio/default.nix +++ b/pkgs/development/python-modules/miniaudio/default.nix @@ -9,14 +9,14 @@ buildPythonPackage rec { pname = "miniaudio"; - version = "1.70"; + version = "1.71"; pyproject = true; src = fetchFromGitHub { owner = "irmen"; repo = "pyminiaudio"; tag = "v${version}"; - hash = "sha256-7i1ORJJwdd/an5IsW/xO1puI/LJJ5WDEdaE8DU4/laQ="; + hash = "sha256-fBdRricV0eqQknOQInB3cj8reZGKS9hrJTMF1ILASpY="; }; # TODO: Properly unvendor miniaudio c library From f6da786dba308dd4259aadd3aa4476300bd47089 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sandro=20J=C3=A4ckel?= Date: Sat, 2 May 2026 01:02:16 +0200 Subject: [PATCH 22/71] rclone: 1.73.5 -> 1.74.0 Diff: https://github.com/rclone/rclone/compare/v1.73.5...v1.74.0 Changelog: https://github.com/rclone/rclone/blob/v1.74.0/docs/content/changelog.md --- pkgs/by-name/rc/rclone/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/rc/rclone/package.nix b/pkgs/by-name/rc/rclone/package.nix index 156c8dd63a10..a1d682295f3a 100644 --- a/pkgs/by-name/rc/rclone/package.nix +++ b/pkgs/by-name/rc/rclone/package.nix @@ -17,7 +17,7 @@ buildGoModule (finalAttrs: { pname = "rclone"; - version = "1.73.5"; + version = "1.74.0"; outputs = [ "out" @@ -28,10 +28,10 @@ buildGoModule (finalAttrs: { owner = "rclone"; repo = "rclone"; tag = "v${finalAttrs.version}"; - hash = "sha256-9oWxL6VHPOl0IJgc7uBWfDkJlUBMvqsEQR8kVH37DZo="; + hash = "sha256-nYtUPC7qaX0mvg4AtCIkDT6v7y0zZPn02XnR7lNhtio="; }; - vendorHash = "sha256-ZEkZbP2r9PFAURkJNR1829VgaL1GXq72mt5Hnz5++kY="; + vendorHash = "sha256-fRUHQ0cTggHn6rJY4QiFgFBdQYAQ/cD0feUTstp2jMg="; subPackages = [ "." ]; From 9f0c0964c6730756829fa794725284ee0c5c085c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sandro=20J=C3=A4ckel?= Date: Sat, 2 May 2026 01:11:38 +0200 Subject: [PATCH 23/71] golangci-lint: 2.11.4 -> 2.12.1 Diff: https://github.com/golangci/golangci-lint/compare/v2.11.4...v2.12.1 Changelog: https://github.com/golangci/golangci-lint/blob/v2.12.1/CHANGELOG.md --- pkgs/by-name/go/golangci-lint/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/go/golangci-lint/package.nix b/pkgs/by-name/go/golangci-lint/package.nix index 33e2eee4fb1c..aa453d09e74e 100644 --- a/pkgs/by-name/go/golangci-lint/package.nix +++ b/pkgs/by-name/go/golangci-lint/package.nix @@ -14,16 +14,16 @@ buildGo126Module (finalAttrs: { pname = "golangci-lint"; - version = "2.11.4"; + version = "2.12.1"; src = fetchFromGitHub { owner = "golangci"; repo = "golangci-lint"; tag = "v${finalAttrs.version}"; - hash = "sha256-B19aLvfNRY9TOYw/71f2vpNUuSIz8OI4dL0ijGezsas="; + hash = "sha256-dMXjfMPdqOPJDC7t6+X4GgfmSf/9ThOuUdp4JgVSmmI="; }; - vendorHash = "sha256-xuoj4+U4tB5gpABKq4Dbp2cxnljxdYoBbO8A7DqPM5E="; + vendorHash = "sha256-qTvBE+c1frDZj3NOy0VKYVbsdxEunun67QrKTye5Rx8="; subPackages = [ "cmd/golangci-lint" ]; From cd0b0d5405837eb77d8ed17b80c319052cfd2011 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 2 May 2026 02:54:48 +0000 Subject: [PATCH 24/71] python3Packages.django-hijack: 3.7.7 -> 3.7.8 --- pkgs/development/python-modules/django-hijack/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/django-hijack/default.nix b/pkgs/development/python-modules/django-hijack/default.nix index 97871ee76ce2..bfcff439a251 100644 --- a/pkgs/development/python-modules/django-hijack/default.nix +++ b/pkgs/development/python-modules/django-hijack/default.nix @@ -19,14 +19,14 @@ buildPythonPackage rec { pname = "django-hijack"; - version = "3.7.7"; + version = "3.7.8"; pyproject = true; src = fetchFromGitHub { owner = "django-hijack"; repo = "django-hijack"; tag = version; - hash = "sha256-qPghlZpzhFZZhmJUJSXjDvE9zB3QFVk1BTu9z0KEa/g="; + hash = "sha256-91ziHv39GmXrbswqOyVHmSv11LqKNT318/8mx5iIdHg="; }; build-system = [ From d56bf96128c942b63a099e74c9f1797ac1d348b6 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Fri, 1 May 2026 20:56:59 -0700 Subject: [PATCH 25/71] abcmidi: 2026.02.24 -> 2026.04.26 Diff: https://github.com/sshlien/abcmidi/compare/2026.02.24...2026.04.26 --- pkgs/by-name/ab/abcmidi/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ab/abcmidi/package.nix b/pkgs/by-name/ab/abcmidi/package.nix index 6d5dd308d444..326184e817ec 100644 --- a/pkgs/by-name/ab/abcmidi/package.nix +++ b/pkgs/by-name/ab/abcmidi/package.nix @@ -6,13 +6,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "abcmidi"; - version = "2026.02.24"; + version = "2026.04.26"; src = fetchFromGitHub { owner = "sshlien"; repo = "abcmidi"; tag = finalAttrs.version; - hash = "sha256-Hy0ICuMK4pCaJn/36QwkCfEI5kgmkWyr9V4RhMpGQes="; + hash = "sha256-d3mzAMFohBppduP25FUWmmQFFCo5lnP5LFLcoVFwjn0="; }; # TODO: remove once https://github.com/sshlien/abcmidi/pull/15 merged From 4718fb4a8e438231e00fe83b8d689230bf2cd8b3 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Fri, 1 May 2026 21:42:09 -0700 Subject: [PATCH 26/71] python3Packages.datastar-py: init at 1.0.0 --- .../python-modules/datastar-py/default.nix | 40 +++++++++++++++++++ pkgs/top-level/python-packages.nix | 2 + 2 files changed, 42 insertions(+) create mode 100644 pkgs/development/python-modules/datastar-py/default.nix diff --git a/pkgs/development/python-modules/datastar-py/default.nix b/pkgs/development/python-modules/datastar-py/default.nix new file mode 100644 index 000000000000..64e1d6648e37 --- /dev/null +++ b/pkgs/development/python-modules/datastar-py/default.nix @@ -0,0 +1,40 @@ +{ + buildPythonPackage, + fetchFromGitHub, + hatchling, + lib, + pytestCheckHook, +}: + +buildPythonPackage (finalAttrs: { + pname = "datastar-py"; + version = "1.0.0"; + pyproject = true; + + src = fetchFromGitHub { + owner = "starfederation"; + repo = "datastar-python"; + tag = "v${finalAttrs.version}"; + hash = "sha256-79pdSzHwkF8JX3rF5PIEvx//rKRvX3H1B2382Wfbm9U="; + }; + + build-system = [ hatchling ]; + + pythonImportsCheck = [ "datastar_py" ]; + + nativeCheckInputs = [ + pytestCheckHook + ]; + + # tests were only added after 1.0.0 + # TODO enable after update + doCheck = false; + + meta = { + changelog = "https://github.com/starfederation/datastar-python/releases/tag/${finalAttrs.src.tag}"; + description = "Helper functions and classes for the Datastar library"; + homepage = "https://github.com/starfederation/datastar-python"; + license = lib.licenses.mit; + maintainers = [ lib.maintainers.dotlambda ]; + }; +}) diff --git a/pkgs/top-level/python-packages.nix b/pkgs/top-level/python-packages.nix index aff8d37062ab..9277d2c8ec76 100644 --- a/pkgs/top-level/python-packages.nix +++ b/pkgs/top-level/python-packages.nix @@ -3650,6 +3650,8 @@ self: super: with self; { datasketch = callPackage ../development/python-modules/datasketch { }; + datastar-py = callPackage ../development/python-modules/datastar-py { }; + datauri = callPackage ../development/python-modules/datauri { }; datefinder = callPackage ../development/python-modules/datefinder { }; From bb642659a85ef0f3dca21f7fb0788a20e4c0cfb9 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Fri, 1 May 2026 21:33:50 -0700 Subject: [PATCH 27/71] spotdl: 4.4.3 -> 4.4.4 Diff: https://github.com/spotDL/spotify-downloader/compare/v4.4.3...v4.4.4 Changelog: https://github.com/spotDL/spotify-downloader/releases/tag/v4.4.4 --- pkgs/by-name/sp/spotdl/package.nix | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/sp/spotdl/package.nix b/pkgs/by-name/sp/spotdl/package.nix index f371f96ab698..7abb861e6d2e 100644 --- a/pkgs/by-name/sp/spotdl/package.nix +++ b/pkgs/by-name/sp/spotdl/package.nix @@ -8,14 +8,14 @@ python3Packages.buildPythonApplication (finalAttrs: { pname = "spotdl"; - version = "4.4.3"; + version = "4.4.4"; pyproject = true; src = fetchFromGitHub { owner = "spotDL"; repo = "spotify-downloader"; tag = "v${finalAttrs.version}"; - hash = "sha256-opbbcYjsR+xuo2uQ7Ic/2+BfkiwdEe1xD/whRonDBWo="; + hash = "sha256-GKkkYA1Z6YsthIKE8Hf/vKRHU7kPCKabOh28i/JSSOc="; }; build-system = with python3Packages; [ hatchling ]; @@ -26,11 +26,14 @@ python3Packages.buildPythonApplication (finalAttrs: { with python3Packages; [ beautifulsoup4 + datastar-py fastapi + jinja2 mutagen platformdirs pydantic pykakasi + python-multipart python-slugify pytube rapidfuzz From 0ba12358445bd4a7b23c3e57f24d2cbd9b8640be Mon Sep 17 00:00:00 2001 From: "Can H. Tartanoglu" Date: Thu, 16 Apr 2026 21:23:26 +0200 Subject: [PATCH 28/71] codex-acp: 0.9.2 -> 0.12.0 --- pkgs/by-name/co/codex-acp/hashes.json | 8 - pkgs/by-name/co/codex-acp/package.nix | 69 ++++---- pkgs/by-name/co/codex-acp/update.py | 216 -------------------------- 3 files changed, 35 insertions(+), 258 deletions(-) delete mode 100644 pkgs/by-name/co/codex-acp/hashes.json delete mode 100755 pkgs/by-name/co/codex-acp/update.py diff --git a/pkgs/by-name/co/codex-acp/hashes.json b/pkgs/by-name/co/codex-acp/hashes.json deleted file mode 100644 index c816627693e9..000000000000 --- a/pkgs/by-name/co/codex-acp/hashes.json +++ /dev/null @@ -1,8 +0,0 @@ -{ - "version": "0.9.4", - "hash": "sha256-sVmy7t1+z88WmYuupVmUA3GYA2kkv3nY7Z3Ic99f5UY=", - "cargoHash": "sha256-Ik6pewc6f+cmVKiqVj1g0h7cIxLhE6xOd9p/ySo/EPg=", - "codexRev": "c34b30a3c128bb75fcec27ef838c93c99b92fc61", - "codexSrcHash": "sha256-SnJHiecKNCHhkiMpbsEwpUarpKLpxn1JOHLHy2vgRog=", - "nodeVersionHash": "sha256-q/bOpgF6/0K3MDKXAC+bi1Rb/vCHNhKZpNDbhyYH+oc=" -} diff --git a/pkgs/by-name/co/codex-acp/package.nix b/pkgs/by-name/co/codex-acp/package.nix index 7d2b617c86f9..7345807cca2b 100644 --- a/pkgs/by-name/co/codex-acp/package.nix +++ b/pkgs/by-name/co/codex-acp/package.nix @@ -7,53 +7,56 @@ pkg-config, openssl, libcap, + librusty_v8 ? fetchurl { + name = "librusty_v8-146.4.0"; + url = "https://github.com/denoland/rusty_v8/releases/download/v146.4.0/librusty_v8_release_${stdenv.hostPlatform.rust.rustcTarget}.a.gz"; + hash = + { + x86_64-linux = "sha256-5ktNmeSuKTouhGJEqJuAF4uhA4LBP7WRwfppaPUpEVM="; + aarch64-linux = "sha256-2/FlsHyBvbBUvARrQ9I+afz3vMGkwbW0d2mDpxBi7Ng="; + x86_64-darwin = "sha256-YwzSQPG77NsHFBfcGDh6uBz2fFScHFFaC0/Pnrpke7c="; + aarch64-darwin = "sha256-v+LJvjKlbChUbw+WWCXuaPv2BkBfMQzE4XtEilaM+Yo="; + } + .${stdenv.hostPlatform.system}; + meta = { + version = "146.4.0"; + sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ]; + }; + }, }: let - versionData = builtins.fromJSON (builtins.readFile ./hashes.json); - inherit (versionData) - version - hash - cargoHash - codexRev - codexSrcHash - nodeVersionHash - ; - - # codex-core uses include_str!("../../../../node-version.txt"), so we need - # to place node-version.txt at the vendored workspace root. - nodeVersionFile = fetchurl { - url = "https://raw.githubusercontent.com/zed-industries/codex/${codexRev}/codex-rs/node-version.txt"; - hash = nodeVersionHash; - }; - - # codex-linux-sandbox compiles a patched bubblewrap source tree from - # codex-rs/vendor/bubblewrap. Cargo vendoring flattens workspace layout, - # so this directory must be provided explicitly. + # codex-acp 0.12.0 pins openai/codex rust-v0.124.0 in Cargo.lock. + codexRev = "e9fb49366c93a1478ec71cc41ecee415a197d036"; codexSrc = fetchFromGitHub { - owner = "zed-industries"; + owner = "openai"; repo = "codex"; rev = codexRev; - hash = codexSrcHash; + hash = "sha256-YFnzzwCm9/b30qLDMbkf/rEizuTjeqdCgoBZeS0wNBo="; }; in -rustPlatform.buildRustPackage { +rustPlatform.buildRustPackage (finalAttrs: { pname = "codex-acp"; - inherit version; + version = "0.12.0"; src = fetchFromGitHub { owner = "zed-industries"; repo = "codex-acp"; - rev = "v${version}"; - inherit hash; + tag = "v${finalAttrs.version}"; + hash = "sha256-qPqg95FpXHBtyHBJtrfJUwu9GokfmOJgKgqLKQ48u+8="; }; - inherit cargoHash; + cargoHash = "sha256-/BZ82qiTy/mPwhf5v5CFrNSB6AxCRFdmHB72L0+KjJw="; - preBuild = '' - cp ${nodeVersionFile} "$NIX_BUILD_TOP/codex-acp-${version}-vendor/node-version.txt" + # fetchCargoVendor only keeps the individual git crate subtrees, so restore + # the workspace-root file that codex-core includes via ../../../../node-version.txt. + postPatch = '' + cp ${codexSrc}/codex-rs/node-version.txt "$cargoDepsCopy/source-git-0/node-version.txt" ''; - env = lib.optionalAttrs stdenv.hostPlatform.isLinux { + env = { + RUSTY_V8_ARCHIVE = librusty_v8; + } + // lib.optionalAttrs stdenv.hostPlatform.isLinux { CODEX_BWRAP_SOURCE_DIR = "${codexSrc}/codex-rs/vendor/bubblewrap"; }; @@ -70,16 +73,14 @@ rustPlatform.buildRustPackage { doCheck = false; - passthru.updateScript = ./update.py; - meta = { description = "An ACP-compatible coding agent powered by Codex"; homepage = "https://github.com/zed-industries/codex-acp"; - changelog = "https://github.com/zed-industries/codex-acp/releases/tag/v${version}"; + changelog = "https://github.com/zed-industries/codex-acp/releases/tag/v${finalAttrs.version}"; license = lib.licenses.asl20; maintainers = with lib.maintainers; [ tlvince ]; platforms = lib.platforms.unix; sourceProvenance = with lib.sourceTypes; [ fromSource ]; mainProgram = "codex-acp"; }; -} +}) diff --git a/pkgs/by-name/co/codex-acp/update.py b/pkgs/by-name/co/codex-acp/update.py deleted file mode 100755 index 38ef25c5ab45..000000000000 --- a/pkgs/by-name/co/codex-acp/update.py +++ /dev/null @@ -1,216 +0,0 @@ -#!/usr/bin/env nix-shell -#!nix-shell -I nixpkgs=./. -i python3 -p python3 nix cacert - -"""Update script for codex-acp package. - -codex-acp depends on crates from zed-industries/codex via a git dependency. -To keep the Nix expression up to date, we need to: -- update codex-acp source hash, -- extract the pinned codex git revision from Cargo.lock, -- refresh node-version.txt hash for that codex revision, -- refresh codex source hash for vendored bubblewrap on Linux, -- recompute cargoHash. -""" - -from __future__ import annotations - -import json -import os -import re -import subprocess -import tarfile -import tempfile -import urllib.request -from pathlib import Path - -SCRIPT_DIR = Path(__file__).resolve().parent -NIXPKGS_ROOT = SCRIPT_DIR.parents[4] -HASHES_FILE = SCRIPT_DIR / "hashes.json" - -OWNER = "zed-industries" -REPO = "codex-acp" -DUMMY_CARGO_HASH = "sha256-AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=" -ANSI_ESCAPE_RE = re.compile(r"\x1b\[[0-9;]*m") - - -def run(cmd: list[str], cwd: Path | None = None) -> str: - result = subprocess.run( - cmd, - cwd=str(cwd) if cwd else None, - check=False, - capture_output=True, - text=True, - ) - if result.returncode != 0: - output = result.stderr.strip() or result.stdout.strip() - msg = f"Command failed ({result.returncode}): {' '.join(cmd)}" - if output: - msg = f"{msg}\n{output}" - raise RuntimeError(msg) - return result.stdout.strip() - - -def github_request(url: str) -> dict: - headers = { - "Accept": "application/vnd.github+json", - } - token = os.environ.get("GITHUB_TOKEN") - if token: - headers["Authorization"] = f"Bearer {token}" - - req = urllib.request.Request(url, headers=headers) - with urllib.request.urlopen(req) as response: - return json.loads(response.read().decode("utf-8")) - - -def fetch_latest_release(owner: str, repo: str) -> str: - data = github_request(f"https://api.github.com/repos/{owner}/{repo}/releases/latest") - tag_name = data["tag_name"] - return tag_name[1:] if tag_name.startswith("v") else tag_name - - -def version_key(version: str) -> tuple[int, ...]: - parts = re.findall(r"\d+", version) - return tuple(int(part) for part in parts) - - -def should_update(current: str, latest: str) -> bool: - return version_key(latest) > version_key(current) - - -def load_hashes(path: Path) -> dict[str, str]: - with path.open() as f: - return json.load(f) - - -def save_hashes(path: Path, data: dict[str, str]) -> None: - with path.open("w") as f: - json.dump(data, f, indent=2) - f.write("\n") - - -def prefetch_sri(url: str, *, unpack: bool = False) -> str: - cmd = ["nix-prefetch-url", "--type", "sha256"] - if unpack: - cmd.append("--unpack") - cmd.append(url) - - raw_hash = run(cmd, cwd=NIXPKGS_ROOT) - return run( - [ - "nix", - "--extra-experimental-features", - "nix-command", - "hash", - "to-sri", - "--type", - "sha256", - raw_hash, - ], - cwd=NIXPKGS_ROOT, - ) - - -def extract_codex_rev_from_tarball(tag: str) -> str: - """Extract zed-industries/codex git revision from codex-acp Cargo.lock.""" - url = f"https://github.com/{OWNER}/{REPO}/archive/refs/tags/{tag}.tar.gz" - - with tempfile.TemporaryDirectory() as tmpdir: - tarball_path = Path(tmpdir) / "source.tar.gz" - urllib.request.urlretrieve(url, tarball_path) - - with tarfile.open(tarball_path, "r:gz") as tar: - for member in tar.getmembers(): - if not member.name.endswith("Cargo.lock"): - continue - cargo_lock = tar.extractfile(member) - if cargo_lock is None: - continue - - content = cargo_lock.read().decode("utf-8") - match = re.search(r"zed-industries/codex\?branch=acp#([a-f0-9]+)", content) - if match: - return match.group(1) - - raise RuntimeError("Could not extract codex git revision from Cargo.lock") - - -def calculate_dependency_hash(attr_path: str) -> str: - result = subprocess.run( - ["nix-build", "--no-out-link", "-A", attr_path], - cwd=str(NIXPKGS_ROOT), - check=False, - capture_output=True, - text=True, - ) - output = ANSI_ESCAPE_RE.sub("", f"{result.stdout}\n{result.stderr}") - - match = re.search(r"got:\s*(sha256-[A-Za-z0-9+/=]+)", output) - if match: - return match.group(1) - - if result.returncode == 0: - raise RuntimeError("nix-build unexpectedly succeeded with placeholder cargoHash") - - raise RuntimeError("Failed to parse cargoHash from nix-build output") - - -def main() -> None: - data = load_hashes(HASHES_FILE) - current = data["version"] - latest = fetch_latest_release(OWNER, REPO) - - print(f"Current: {current}, Latest: {latest}") - - if not should_update(current, latest): - print("Already up to date") - return - - tag = f"v{latest}" - print(f"Updating codex-acp to {latest}...") - - source_url = f"https://github.com/{OWNER}/{REPO}/archive/refs/tags/{tag}.tar.gz" - print("Calculating source hash...") - source_hash = prefetch_sri(source_url, unpack=True) - print(f" hash: {source_hash}") - - print("Extracting codex git revision from Cargo.lock...") - codex_rev = extract_codex_rev_from_tarball(tag) - print(f" codexRev: {codex_rev}") - - codex_src_url = f"https://github.com/zed-industries/codex/archive/{codex_rev}.tar.gz" - print("Calculating codex source hash...") - codex_src_hash = prefetch_sri(codex_src_url, unpack=True) - print(f" codexSrcHash: {codex_src_hash}") - - node_version_url = ( - f"https://raw.githubusercontent.com/zed-industries/codex/{codex_rev}/" - "codex-rs/node-version.txt" - ) - print("Calculating node-version.txt hash...") - node_version_hash = prefetch_sri(node_version_url, unpack=False) - print(f" nodeVersionHash: {node_version_hash}") - - data = { - "version": latest, - "hash": source_hash, - "cargoHash": DUMMY_CARGO_HASH, - "codexRev": codex_rev, - "codexSrcHash": codex_src_hash, - "nodeVersionHash": node_version_hash, - } - save_hashes(HASHES_FILE, data) - - print("Calculating cargoHash...") - attr_path = os.environ.get("UPDATE_NIX_ATTR_PATH", "codex-acp") - cargo_hash = calculate_dependency_hash(attr_path) - print(f" cargoHash: {cargo_hash}") - - data["cargoHash"] = cargo_hash - save_hashes(HASHES_FILE, data) - - print(f"Updated to {latest}") - - -if __name__ == "__main__": - main() From ca6ef2340673e28801635fadecf1ce46df8cca68 Mon Sep 17 00:00:00 2001 From: "Can H. Tartanoglu" Date: Mon, 20 Apr 2026 15:46:11 +0200 Subject: [PATCH 29/71] codex-acp: add update script --- pkgs/by-name/co/codex-acp/librusty_v8.nix | 23 +++ pkgs/by-name/co/codex-acp/package.nix | 24 +-- pkgs/by-name/co/codex-acp/update.sh | 188 ++++++++++++++++++++++ 3 files changed, 217 insertions(+), 18 deletions(-) create mode 100644 pkgs/by-name/co/codex-acp/librusty_v8.nix create mode 100755 pkgs/by-name/co/codex-acp/update.sh diff --git a/pkgs/by-name/co/codex-acp/librusty_v8.nix b/pkgs/by-name/co/codex-acp/librusty_v8.nix new file mode 100644 index 000000000000..59bd883a617a --- /dev/null +++ b/pkgs/by-name/co/codex-acp/librusty_v8.nix @@ -0,0 +1,23 @@ +# auto-generated file -- DO NOT EDIT! +{ + lib, + stdenv, + fetchurl, +}: + +fetchurl { + name = "librusty_v8-146.4.0"; + url = "https://github.com/denoland/rusty_v8/releases/download/v146.4.0/librusty_v8_release_${stdenv.hostPlatform.rust.rustcTarget}.a.gz"; + hash = + { + x86_64-linux = "sha256-5ktNmeSuKTouhGJEqJuAF4uhA4LBP7WRwfppaPUpEVM="; + aarch64-linux = "sha256-2/FlsHyBvbBUvARrQ9I+afz3vMGkwbW0d2mDpxBi7Ng="; + x86_64-darwin = "sha256-YwzSQPG77NsHFBfcGDh6uBz2fFScHFFaC0/Pnrpke7c="; + aarch64-darwin = "sha256-v+LJvjKlbChUbw+WWCXuaPv2BkBfMQzE4XtEilaM+Yo="; + } + .${stdenv.hostPlatform.system}; + meta = { + version = "146.4.0"; + sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ]; + }; +} diff --git a/pkgs/by-name/co/codex-acp/package.nix b/pkgs/by-name/co/codex-acp/package.nix index 7345807cca2b..6be13b9b7ba0 100644 --- a/pkgs/by-name/co/codex-acp/package.nix +++ b/pkgs/by-name/co/codex-acp/package.nix @@ -1,37 +1,23 @@ { lib, stdenv, + callPackage, fetchFromGitHub, - fetchurl, rustPlatform, pkg-config, openssl, libcap, - librusty_v8 ? fetchurl { - name = "librusty_v8-146.4.0"; - url = "https://github.com/denoland/rusty_v8/releases/download/v146.4.0/librusty_v8_release_${stdenv.hostPlatform.rust.rustcTarget}.a.gz"; - hash = - { - x86_64-linux = "sha256-5ktNmeSuKTouhGJEqJuAF4uhA4LBP7WRwfppaPUpEVM="; - aarch64-linux = "sha256-2/FlsHyBvbBUvARrQ9I+afz3vMGkwbW0d2mDpxBi7Ng="; - x86_64-darwin = "sha256-YwzSQPG77NsHFBfcGDh6uBz2fFScHFFaC0/Pnrpke7c="; - aarch64-darwin = "sha256-v+LJvjKlbChUbw+WWCXuaPv2BkBfMQzE4XtEilaM+Yo="; - } - .${stdenv.hostPlatform.system}; - meta = { - version = "146.4.0"; - sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ]; - }; - }, + librusty_v8 ? callPackage ./librusty_v8.nix { }, }: let # codex-acp 0.12.0 pins openai/codex rust-v0.124.0 in Cargo.lock. codexRev = "e9fb49366c93a1478ec71cc41ecee415a197d036"; + codexHash = "sha256-YFnzzwCm9/b30qLDMbkf/rEizuTjeqdCgoBZeS0wNBo="; codexSrc = fetchFromGitHub { owner = "openai"; repo = "codex"; rev = codexRev; - hash = "sha256-YFnzzwCm9/b30qLDMbkf/rEizuTjeqdCgoBZeS0wNBo="; + hash = codexHash; }; in rustPlatform.buildRustPackage (finalAttrs: { @@ -73,6 +59,8 @@ rustPlatform.buildRustPackage (finalAttrs: { doCheck = false; + passthru.updateScript = ./update.sh; + meta = { description = "An ACP-compatible coding agent powered by Codex"; homepage = "https://github.com/zed-industries/codex-acp"; diff --git a/pkgs/by-name/co/codex-acp/update.sh b/pkgs/by-name/co/codex-acp/update.sh new file mode 100755 index 000000000000..c22f6bae1863 --- /dev/null +++ b/pkgs/by-name/co/codex-acp/update.sh @@ -0,0 +1,188 @@ +#!/usr/bin/env nix-shell +#!nix-shell -i bash -p bash cacert common-updater-scripts coreutils curl gnutar jq nix nix-update python3 + +set -euo pipefail + +PACKAGE_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" +NIXPKGS_ROOT="$(realpath "$PACKAGE_DIR/../../../..")" +PACKAGE_NIX="$PACKAGE_DIR/package.nix" +LIBRUSTY_V8_NIX="$PACKAGE_DIR/librusty_v8.nix" +ATTR_PATH="${UPDATE_NIX_ATTR_PATH:-codex-acp}" +OWNER="zed-industries" +REPO="codex-acp" + +github_api_get() { + local url="$1" + + if [[ -n "${GITHUB_TOKEN:-}" ]]; then + curl --fail --silent --show-error \ + -H "Accept: application/vnd.github+json" \ + -H "Authorization: Bearer ${GITHUB_TOKEN}" \ + "$url" + else + curl --fail --silent --show-error \ + -H "Accept: application/vnd.github+json" \ + "$url" + fi +} + +normalize_version() { + local version="$1" + echo "${version#v}" +} + +prefetch_sri() { + local url="$1" + local unpack="${2:-false}" + local raw_hash + local args=(--type sha256) + + if [[ "$unpack" == "true" ]]; then + args+=(--unpack) + fi + + raw_hash="$(nix-prefetch-url "${args[@]}" "$url")" + nix hash convert --to sri --hash-algo sha256 "$raw_hash" +} + +parse_release_metadata() { + local cargo_lock="$1" + + python3 - "$cargo_lock" <<'PY' +import pathlib +import re +import sys + +text = pathlib.Path(sys.argv[1]).read_text() + +codex_match = re.search( + r'git\+https://github\.com/openai/codex\?tag=([^#"]+)#([0-9a-f]+)', + text, +) +if codex_match is None: + raise SystemExit("Could not find pinned openai/codex dependency in Cargo.lock") + +v8_match = re.search(r'\[\[package\]\]\nname = "v8"\nversion = "([^"]+)"', text) +if v8_match is None: + raise SystemExit('Could not find v8 package version in Cargo.lock') + +print(codex_match.group(1)) +print(codex_match.group(2)) +print(v8_match.group(1)) +PY +} + +update_codex_pins() { + python3 - "$PACKAGE_NIX" <<'PY' +import os +import pathlib +import re +import sys + +path = pathlib.Path(sys.argv[1]) +text = path.read_text() + +patterns = [ + ( + r'codexRev = "[0-9a-f]+";', + f'codexRev = "{os.environ["CODEX_REV"]}";', + "codexRev", + ), + ( + r'codexHash = "sha256-[^"]+";', + f'codexHash = "{os.environ["CODEX_HASH"]}";', + "codexHash", + ), +] + +for pattern, replacement, label in patterns: + text, count = re.subn(pattern, replacement, text, count=1) + if count != 1: + raise SystemExit(f"Failed to update {label} in {path}") + +path.write_text(text) +PY +} + +write_librusty_v8_nix() { + cat >"$LIBRUSTY_V8_NIX" < Date: Thu, 30 Apr 2026 10:44:00 +0200 Subject: [PATCH 30/71] codex-acp: address review feedback --- pkgs/by-name/co/codex-acp/librusty_v8.nix | 3 +- pkgs/by-name/co/codex-acp/package.nix | 3 +- pkgs/by-name/co/codex-acp/update.sh | 126 ++++++++++++---------- 3 files changed, 72 insertions(+), 60 deletions(-) diff --git a/pkgs/by-name/co/codex-acp/librusty_v8.nix b/pkgs/by-name/co/codex-acp/librusty_v8.nix index 59bd883a617a..c2f00c5fe62e 100644 --- a/pkgs/by-name/co/codex-acp/librusty_v8.nix +++ b/pkgs/by-name/co/codex-acp/librusty_v8.nix @@ -15,7 +15,8 @@ fetchurl { x86_64-darwin = "sha256-YwzSQPG77NsHFBfcGDh6uBz2fFScHFFaC0/Pnrpke7c="; aarch64-darwin = "sha256-v+LJvjKlbChUbw+WWCXuaPv2BkBfMQzE4XtEilaM+Yo="; } - .${stdenv.hostPlatform.system}; + .${stdenv.hostPlatform.system} + or (throw "librusty_v8 146.4.0 is not available for ${stdenv.hostPlatform.system}"); meta = { version = "146.4.0"; sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ]; diff --git a/pkgs/by-name/co/codex-acp/package.nix b/pkgs/by-name/co/codex-acp/package.nix index 6be13b9b7ba0..04b17ef411ac 100644 --- a/pkgs/by-name/co/codex-acp/package.nix +++ b/pkgs/by-name/co/codex-acp/package.nix @@ -7,6 +7,7 @@ pkg-config, openssl, libcap, + bubblewrap, librusty_v8 ? callPackage ./librusty_v8.nix { }, }: let @@ -43,7 +44,7 @@ rustPlatform.buildRustPackage (finalAttrs: { RUSTY_V8_ARCHIVE = librusty_v8; } // lib.optionalAttrs stdenv.hostPlatform.isLinux { - CODEX_BWRAP_SOURCE_DIR = "${codexSrc}/codex-rs/vendor/bubblewrap"; + CODEX_BWRAP_SOURCE_DIR = "${bubblewrap.src}"; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/co/codex-acp/update.sh b/pkgs/by-name/co/codex-acp/update.sh index c22f6bae1863..401c252abe13 100755 --- a/pkgs/by-name/co/codex-acp/update.sh +++ b/pkgs/by-name/co/codex-acp/update.sh @@ -1,5 +1,5 @@ #!/usr/bin/env nix-shell -#!nix-shell -i bash -p bash cacert common-updater-scripts coreutils curl gnutar jq nix nix-update python3 +#!nix-shell -i bash -p bash cacert common-updater-scripts coreutils curl gnutar jq nix-update set -euo pipefail @@ -7,23 +7,24 @@ PACKAGE_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" NIXPKGS_ROOT="$(realpath "$PACKAGE_DIR/../../../..")" PACKAGE_NIX="$PACKAGE_DIR/package.nix" LIBRUSTY_V8_NIX="$PACKAGE_DIR/librusty_v8.nix" -ATTR_PATH="${UPDATE_NIX_ATTR_PATH:-codex-acp}" +ATTR_PATH=codex-acp OWNER="zed-industries" REPO="codex-acp" github_api_get() { local url="$1" + local curl_args=( + --fail + --silent + --show-error + -H "Accept: application/vnd.github+json" + ) if [[ -n "${GITHUB_TOKEN:-}" ]]; then - curl --fail --silent --show-error \ - -H "Accept: application/vnd.github+json" \ - -H "Authorization: Bearer ${GITHUB_TOKEN}" \ - "$url" - else - curl --fail --silent --show-error \ - -H "Accept: application/vnd.github+json" \ - "$url" + curl_args+=(-H "Authorization: Bearer ${GITHUB_TOKEN}") fi + + curl "${curl_args[@]}" "$url" } normalize_version() { @@ -47,61 +48,69 @@ prefetch_sri() { parse_release_metadata() { local cargo_lock="$1" + local codex_metadata codex_tag codex_rev v8_version - python3 - "$cargo_lock" <<'PY' -import pathlib -import re -import sys + codex_metadata="$( + sed -nE 's|.*git\+https://github\.com/openai/codex\?tag=([^#"]+)#([0-9a-f]+).*|\1 \2|p' "$cargo_lock" \ + | head -n1 + )" + if [[ -z "$codex_metadata" ]]; then + echo "Could not find pinned openai/codex dependency in Cargo.lock" >&2 + return 1 + fi + read -r codex_tag codex_rev <<<"$codex_metadata" + if [[ -z "$codex_tag" || -z "$codex_rev" ]]; then + echo "Could not parse pinned openai/codex dependency in Cargo.lock" >&2 + return 1 + fi -text = pathlib.Path(sys.argv[1]).read_text() + v8_version="$( + awk ' + /^\[\[package\]\]$/ { in_pkg = 1; is_v8 = 0; next } + in_pkg && /^name = "v8"$/ { is_v8 = 1; next } + in_pkg && is_v8 && /^version = "/ { + gsub(/^version = "/, "") + gsub(/"$/, "") + print + exit + } + ' "$cargo_lock" + )" + if [[ -z "$v8_version" ]]; then + echo "Could not find v8 package version in Cargo.lock" >&2 + return 1 + fi -codex_match = re.search( - r'git\+https://github\.com/openai/codex\?tag=([^#"]+)#([0-9a-f]+)', - text, -) -if codex_match is None: - raise SystemExit("Could not find pinned openai/codex dependency in Cargo.lock") - -v8_match = re.search(r'\[\[package\]\]\nname = "v8"\nversion = "([^"]+)"', text) -if v8_match is None: - raise SystemExit('Could not find v8 package version in Cargo.lock') - -print(codex_match.group(1)) -print(codex_match.group(2)) -print(v8_match.group(1)) -PY + printf '%s\n%s\n%s\n' "$codex_tag" "$codex_rev" "$v8_version" } update_codex_pins() { - python3 - "$PACKAGE_NIX" <<'PY' -import os -import pathlib -import re -import sys + local tmp + tmp="$(mktemp)" -path = pathlib.Path(sys.argv[1]) -text = path.read_text() + awk -v codex_rev="$CODEX_REV" -v codex_hash="$CODEX_HASH" ' + /codexRev = "[0-9a-f]+";/ { + rev_count++ + sub(/codexRev = "[0-9a-f]+";/, "codexRev = \"" codex_rev "\";") + } + /codexHash = "sha256-[^"]+";/ { + hash_count++ + sub(/codexHash = "sha256-[^"]+";/, "codexHash = \"" codex_hash "\";") + } + { print } + END { + if (rev_count != 1) { + print "Failed to update codexRev in package.nix" > "/dev/stderr" + exit 1 + } + if (hash_count != 1) { + print "Failed to update codexHash in package.nix" > "/dev/stderr" + exit 1 + } + } + ' "$PACKAGE_NIX" >"$tmp" -patterns = [ - ( - r'codexRev = "[0-9a-f]+";', - f'codexRev = "{os.environ["CODEX_REV"]}";', - "codexRev", - ), - ( - r'codexHash = "sha256-[^"]+";', - f'codexHash = "{os.environ["CODEX_HASH"]}";', - "codexHash", - ), -] - -for pattern, replacement, label in patterns: - text, count = re.subn(pattern, replacement, text, count=1) - if count != 1: - raise SystemExit(f"Failed to update {label} in {path}") - -path.write_text(text) -PY + mv "$tmp" "$PACKAGE_NIX" } write_librusty_v8_nix() { @@ -123,7 +132,8 @@ fetchurl { x86_64-darwin = "${V8_HASH_X86_64_DARWIN}"; aarch64-darwin = "${V8_HASH_AARCH64_DARWIN}"; } - .\${stdenv.hostPlatform.system}; + .\${stdenv.hostPlatform.system} + or (throw "librusty_v8 ${V8_VERSION} is not available for \${stdenv.hostPlatform.system}"); meta = { version = "${V8_VERSION}"; sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ]; From 032a22de03c6a89d4e643a03d4c7d47d14b38a46 Mon Sep 17 00:00:00 2001 From: eljamm Date: Sat, 2 May 2026 08:01:08 +0200 Subject: [PATCH 31/71] gnunet{-gtk,-messenger-cli}, libgnunetchat: fix 404 changelogs and switch to new repository, since the old one isn't a valid git repo anymore: ``` $ git clone https://git.gnunet.org/gnunet/libgnunetchat.git Cloning into 'libgnunetchat'... fatal: repository 'https://git.gnunet.org/gnunet/libgnunetchat.git/' not found ``` --- pkgs/by-name/gn/gnunet-gtk/package.nix | 2 +- pkgs/by-name/gn/gnunet-messenger-cli/package.nix | 4 ++-- pkgs/by-name/gn/gnunet/package.nix | 2 +- pkgs/by-name/li/libgnunetchat/package.nix | 6 +++--- 4 files changed, 7 insertions(+), 7 deletions(-) diff --git a/pkgs/by-name/gn/gnunet-gtk/package.nix b/pkgs/by-name/gn/gnunet-gtk/package.nix index 75b61bb055e3..d0266865963b 100644 --- a/pkgs/by-name/gn/gnunet-gtk/package.nix +++ b/pkgs/by-name/gn/gnunet-gtk/package.nix @@ -50,7 +50,7 @@ stdenv.mkDerivation (finalAttrs: { meta = gnunet.meta // { description = "GNUnet GTK User Interface"; - homepage = "https://git.gnunet.org/gnunet-gtk.git"; + homepage = "https://git-www.taler.net/gnunet-gtk.git"; # https://www.gnunet.org/en/news/2025-09-0.25.0.html broken = true; }; diff --git a/pkgs/by-name/gn/gnunet-messenger-cli/package.nix b/pkgs/by-name/gn/gnunet-messenger-cli/package.nix index 9db6de9f2a34..0187ec9a7f79 100644 --- a/pkgs/by-name/gn/gnunet-messenger-cli/package.nix +++ b/pkgs/by-name/gn/gnunet-messenger-cli/package.nix @@ -17,7 +17,7 @@ stdenv.mkDerivation (finalAttrs: { version = "0.3.1"; src = fetchgit { - url = "https://git.gnunet.org/messenger-cli.git"; + url = "https://git-www.taler.net/messenger-cli.git"; tag = "v${finalAttrs.version}"; hash = "sha256-8Iby3IZXEZJ1dqVV62xDzXx/qq7JKhVtn6ZLb697ZSw="; }; @@ -46,7 +46,7 @@ stdenv.mkDerivation (finalAttrs: { meta = { description = "Decentralized, privacy-preserving networking framework for secure peer-to-peer communication"; - homepage = "https://git.gnunet.org/messenger-cli.git"; + homepage = "https://git-www.taler.net/messenger-cli.git"; license = lib.licenses.gpl3Plus; platforms = lib.platforms.all; teams = with lib.teams; [ ngi ]; diff --git a/pkgs/by-name/gn/gnunet/package.nix b/pkgs/by-name/gn/gnunet/package.nix index b447e54faf7b..a72841ffdb1f 100644 --- a/pkgs/by-name/gn/gnunet/package.nix +++ b/pkgs/by-name/gn/gnunet/package.nix @@ -127,7 +127,7 @@ stdenv.mkDerivation (finalAttrs: { maintainers = with lib.maintainers; [ pstn ]; teams = with lib.teams; [ ngi ]; platforms = lib.platforms.unix; - changelog = "https://git.gnunet.org/gnunet.git/tree/ChangeLog?h=v${finalAttrs.version}"; + changelog = "https://git-www.taler.net/gnunet.git/tree/NEWS/?h=v${finalAttrs.version}"; # meson: "Can not run test applications in this cross environment." (for dane_verify_crt_raw) broken = !stdenv.buildPlatform.canExecute stdenv.hostPlatform; }; diff --git a/pkgs/by-name/li/libgnunetchat/package.nix b/pkgs/by-name/li/libgnunetchat/package.nix index 87d51bb9ac44..7b6f1ad7529f 100644 --- a/pkgs/by-name/li/libgnunetchat/package.nix +++ b/pkgs/by-name/li/libgnunetchat/package.nix @@ -20,7 +20,7 @@ stdenv.mkDerivation (finalAttrs: { version = "0.6.1"; src = fetchgit { - url = "https://git.gnunet.org/libgnunetchat.git"; + url = "https://git-www.taler.net/libgnunetchat.git"; tag = "v${finalAttrs.version}"; hash = "sha256-FKFoIuGGPcYVRBrsqn1rnodRVCLAjLKlgZOs9v4H+8w="; }; @@ -58,8 +58,8 @@ stdenv.mkDerivation (finalAttrs: { meta = { pkgConfigModules = [ "gnunetchat" ]; description = "Library for secure, decentralized chat using GNUnet network services"; - homepage = "https://git.gnunet.org/libgnunetchat.git"; - changelog = "https://git.gnunet.org/libgnunetchat.git/plain/ChangeLog?h=v${finalAttrs.version}"; + homepage = "https://git-www.taler.net/libgnunetchat.git"; + changelog = "https://git-www.taler.net/libgnunetchat.git/plain/ChangeLog?h=v${finalAttrs.version}"; license = lib.licenses.gpl3Plus; platforms = lib.platforms.all; teams = with lib.teams; [ ngi ]; From fbacd040e101b5951b579d43158f6e1b79c5ce2e Mon Sep 17 00:00:00 2001 From: eljamm Date: Sat, 2 May 2026 08:24:07 +0200 Subject: [PATCH 32/71] libeufin, taldir, taler-*: switch to new git repository since the old one isn't valid anymore. --- pkgs/by-name/li/libeufin/package.nix | 4 ++-- pkgs/by-name/ta/taldir/package.nix | 4 ++-- pkgs/by-name/ta/taler-challenger/package.nix | 6 +++--- pkgs/by-name/ta/taler-depolymerization/package.nix | 4 ++-- pkgs/by-name/ta/taler-exchange/package.nix | 4 ++-- pkgs/by-name/ta/taler-mdb/package.nix | 4 ++-- pkgs/by-name/ta/taler-merchant/package.nix | 4 ++-- pkgs/by-name/ta/taler-sync/package.nix | 4 ++-- pkgs/by-name/ta/taler-twister/package.nix | 4 ++-- 9 files changed, 19 insertions(+), 19 deletions(-) diff --git a/pkgs/by-name/li/libeufin/package.nix b/pkgs/by-name/li/libeufin/package.nix index d8e8a691615d..07f0344163ea 100644 --- a/pkgs/by-name/li/libeufin/package.nix +++ b/pkgs/by-name/li/libeufin/package.nix @@ -19,7 +19,7 @@ stdenv.mkDerivation (finalAttrs: { version = "1.3.0"; src = fetchgit { - url = "https://git.taler.net/libeufin.git/"; + url = "https://git-www.taler.net/libeufin.git/"; tag = "v${finalAttrs.version}"; hash = "sha256-bt1NBoiN52CX2Itg8lQ/b0V/MZulBTaD8luNlH4Mwss="; fetchSubmodules = true; @@ -116,7 +116,7 @@ stdenv.mkDerivation (finalAttrs: { doCheck = false; meta = { - homepage = "https://git.taler.net/libeufin.git/"; + homepage = "https://git-www.taler.net/libeufin.git"; description = "Integration and sandbox testing for FinTech APIs and data formats"; license = lib.licenses.agpl3Plus; maintainers = with lib.maintainers; [ atemu ]; diff --git a/pkgs/by-name/ta/taldir/package.nix b/pkgs/by-name/ta/taldir/package.nix index d0cbcbf21a0f..7d9a680887cd 100644 --- a/pkgs/by-name/ta/taldir/package.nix +++ b/pkgs/by-name/ta/taldir/package.nix @@ -9,7 +9,7 @@ buildGoModule (finalAttrs: { version = "1.0.5"; src = fetchgit { - url = "https://git.taler.net/taldir.git"; + url = "https://git-www.taler.net/taldir.git"; tag = "v${finalAttrs.version}"; hash = "sha256-ZKNkMV0IV6E+yCQeabGXpIQclx1S4YEgFn4whGXTaks="; }; @@ -40,7 +40,7 @@ buildGoModule (finalAttrs: { doCheck = false; meta = { - homepage = "https://git.taler.net/taldir.git"; + homepage = "https://git-www.taler.net/taldir.git"; description = "Directory service to resolve wallet mailboxes by messenger addresses"; teams = with lib.teams; [ ngi ]; # themadbit will maintain after being added to maintainers diff --git a/pkgs/by-name/ta/taler-challenger/package.nix b/pkgs/by-name/ta/taler-challenger/package.nix index 76763371fe9b..26fa4ddc4bda 100644 --- a/pkgs/by-name/ta/taler-challenger/package.nix +++ b/pkgs/by-name/ta/taler-challenger/package.nix @@ -24,12 +24,12 @@ stdenv.mkDerivation (finalAttrs: { version = "1.3.0"; src = fetchgit { - url = "https://git.taler.net/challenger.git"; + url = "https://git-www.taler.net/challenger.git"; tag = "v${finalAttrs.version}"; hash = "sha256-oomrqpA/V2sNTRzFbHS7rnZdTIs8w+SRYsa9AYDFn5o="; }; - # https://git.taler.net/challenger.git/tree/bootstrap + # https://git-www.taler.net/challenger.git/tree/bootstrap preAutoreconf = '' # Generate Makefile.am in contrib/ pushd contrib @@ -73,7 +73,7 @@ stdenv.mkDerivation (finalAttrs: { meta = { description = "OAuth 2.0-based authentication service that validates user can receive messages at a certain address"; - homepage = "https://git.taler.net/challenger.git"; + homepage = "https://git-www.taler.net/challenger.git"; license = lib.licenses.agpl3Plus; maintainers = with lib.maintainers; [ wegank ]; teams = with lib.teams; [ ngi ]; diff --git a/pkgs/by-name/ta/taler-depolymerization/package.nix b/pkgs/by-name/ta/taler-depolymerization/package.nix index 91cbbf61c864..b75005de1989 100644 --- a/pkgs/by-name/ta/taler-depolymerization/package.nix +++ b/pkgs/by-name/ta/taler-depolymerization/package.nix @@ -8,7 +8,7 @@ rustPlatform.buildRustPackage { version = "0-unstable-2024-06-17"; src = fetchgit { - url = "https://git.taler.net/depolymerization.git/"; + url = "https://git-www.taler.net/depolymerization.git"; rev = "a0d27ac3bba22d4934ca9f7b244b0d9e45bb484f"; hash = "sha256-HmQ/DPq/O6aODWms/bSsCVgBF7z246xxfYxiHrAkgYw="; }; @@ -35,7 +35,7 @@ rustPlatform.buildRustPackage { meta = { description = "Wire gateway for Bitcoin/Ethereum"; - homepage = "https://git.taler.net/depolymerization.git/"; + homepage = "https://git-www.taler.net/depolymerization.git/"; license = lib.licenses.agpl3Only; teams = [ lib.teams.ngi ]; }; diff --git a/pkgs/by-name/ta/taler-exchange/package.nix b/pkgs/by-name/ta/taler-exchange/package.nix index 2fe055b21bdf..bfbaee281870 100644 --- a/pkgs/by-name/ta/taler-exchange/package.nix +++ b/pkgs/by-name/ta/taler-exchange/package.nix @@ -28,7 +28,7 @@ stdenv.mkDerivation (finalAttrs: { version = "1.3.0"; src = fetchgit { - url = "https://git.taler.net/exchange.git"; + url = "https://git-www.taler.net/exchange.git"; tag = "v${finalAttrs.version}"; fetchSubmodules = true; hash = "sha256-FePuJUEa01E2jlAOdHryzkFwXqNcU+AkMKs1pamNJn8="; @@ -133,7 +133,7 @@ stdenv.mkDerivation (finalAttrs: { payment system. ''; homepage = "https://taler.net/"; - changelog = "https://git.taler.net/exchange.git/tree/ChangeLog"; + changelog = "https://git-www.taler.net/exchange.git/tree/ChangeLog?h=v${finalAttrs.version}"; license = lib.licenses.agpl3Plus; maintainers = with lib.maintainers; [ astro ]; teams = with lib.teams; [ ngi ]; diff --git a/pkgs/by-name/ta/taler-mdb/package.nix b/pkgs/by-name/ta/taler-mdb/package.nix index 3bd77d459d27..8f8074c20a30 100644 --- a/pkgs/by-name/ta/taler-mdb/package.nix +++ b/pkgs/by-name/ta/taler-mdb/package.nix @@ -20,7 +20,7 @@ stdenv.mkDerivation (finalAttrs: { version = "1.3.0"; src = fetchgit { - url = "https://git.taler.net/taler-mdb.git"; + url = "https://git-www.taler.net/taler-mdb.git"; tag = "v${finalAttrs.version}"; fetchSubmodules = true; hash = "sha256-bslsC/m75kt8JoIQPp53u64SxghwZloOHehctphpNwI="; @@ -47,7 +47,7 @@ stdenv.mkDerivation (finalAttrs: { doCheck = true; meta = { - homepage = "https://git.taler.net/taler-mdb.git"; + homepage = "https://git-www.taler.net/taler-mdb.git"; description = "Sales integration with the Multi-Drop-Bus of Snack machines, NFC readers and QR code display"; license = lib.licenses.agpl3Plus; teams = with lib.teams; [ ngi ]; diff --git a/pkgs/by-name/ta/taler-merchant/package.nix b/pkgs/by-name/ta/taler-merchant/package.nix index 79dcf63af244..1e407829e186 100644 --- a/pkgs/by-name/ta/taler-merchant/package.nix +++ b/pkgs/by-name/ta/taler-merchant/package.nix @@ -22,7 +22,7 @@ stdenv.mkDerivation (finalAttrs: { version = "1.3.0"; src = fetchgit { - url = "https://git.taler.net/merchant.git"; + url = "https://git-www.taler.net/merchant.git"; tag = "v${finalAttrs.version}"; fetchSubmodules = true; hash = "sha256-nrXokwZ0IFXAH3B12/FDAhhyE6JAiiJ59cuWLwLM684="; @@ -113,7 +113,7 @@ stdenv.mkDerivation (finalAttrs: { to know the customer's physical address. ''; homepage = "https://taler.net/"; - changelog = "https://git.taler.net/merchant.git/tree/ChangeLog"; + changelog = "https://git-www.taler.net/merchant.git/tree/ChangeLog?h=v${finalAttrs.version}"; license = lib.licenses.agpl3Plus; maintainers = with lib.maintainers; [ astro ]; teams = with lib.teams; [ ngi ]; diff --git a/pkgs/by-name/ta/taler-sync/package.nix b/pkgs/by-name/ta/taler-sync/package.nix index a935bba2b9f6..bbe43f6cb84b 100644 --- a/pkgs/by-name/ta/taler-sync/package.nix +++ b/pkgs/by-name/ta/taler-sync/package.nix @@ -22,7 +22,7 @@ stdenv.mkDerivation (finalAttrs: { version = "1.3.0"; src = fetchgit { - url = "https://git.taler.net/sync.git"; + url = "https://git-www.taler.net/sync.git"; tag = "v${finalAttrs.version}"; hash = "sha256-1m26ORKsN0GHJWQ/5gtMO3x1ng+GsZK9Y80413vF5pI="; }; @@ -55,7 +55,7 @@ stdenv.mkDerivation (finalAttrs: { meta = { description = "Backup and synchronization service"; - homepage = "https://git.taler.net/sync.git"; + homepage = "https://git-www.taler.net/sync.git"; license = lib.licenses.agpl3Plus; maintainers = with lib.maintainers; [ wegank ]; teams = with lib.teams; [ ngi ]; diff --git a/pkgs/by-name/ta/taler-twister/package.nix b/pkgs/by-name/ta/taler-twister/package.nix index 91156eb33cb5..aa6deebf8cd2 100644 --- a/pkgs/by-name/ta/taler-twister/package.nix +++ b/pkgs/by-name/ta/taler-twister/package.nix @@ -17,7 +17,7 @@ stdenv.mkDerivation (finalAttrs: { version = "1.0.0"; src = fetchgit { - url = "https://git.taler.net/twister.git"; + url = "https://git-www.taler.net/twister.git"; tag = "v${finalAttrs.version}"; hash = "sha256-ir+kU9bCWwhqR88hmNHB5cm1DXOQowI5y6GdhWpX/L0="; }; @@ -39,7 +39,7 @@ stdenv.mkDerivation (finalAttrs: { doInstallCheck = true; meta = { - homepage = "https://git.taler.net/twister.git"; + homepage = "https://git-www.taler.net/twister.git"; description = "Fault injector for HTTP traffic"; teams = with lib.teams; [ ngi ]; maintainers = [ ]; From b5202e459ab6129d8333bb8feab2597d34a02499 Mon Sep 17 00:00:00 2001 From: Bobby Rong Date: Sat, 2 May 2026 19:06:08 +0800 Subject: [PATCH 33/71] pantheon.switchboard-plug-about: 8.2.2 -> 8.2.3 https://github.com/elementary/settings-system/compare/8.2.2...8.2.3 --- .../pantheon/apps/switchboard-plugs/about/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/desktops/pantheon/apps/switchboard-plugs/about/default.nix b/pkgs/desktops/pantheon/apps/switchboard-plugs/about/default.nix index d8f9cada18f5..40c81e4b6e41 100644 --- a/pkgs/desktops/pantheon/apps/switchboard-plugs/about/default.nix +++ b/pkgs/desktops/pantheon/apps/switchboard-plugs/about/default.nix @@ -28,13 +28,13 @@ stdenv.mkDerivation rec { pname = "switchboard-plug-about"; - version = "8.2.2"; + version = "8.2.3"; src = fetchFromGitHub { owner = "elementary"; repo = "settings-system"; tag = version; - hash = "sha256-SPFCBsk4tVR+5Q6uuDG/fTIn+4TXdeAobfQxkmxMiW0="; + hash = "sha256-skuMgLZTkJEWrmDGwSuCivsJrvKIUYT2YISYj7/BVe4="; }; nativeBuildInputs = [ From bbd34105fe60ad3e4bb9ab1df4a28563b8f71690 Mon Sep 17 00:00:00 2001 From: 0xferrous <0xferrous@proton.me> Date: Sat, 2 May 2026 15:34:19 +0000 Subject: [PATCH 34/71] maintainers: add 0xferrous --- maintainers/maintainer-list.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/maintainers/maintainer-list.nix b/maintainers/maintainer-list.nix index bd3a40644c0e..08d33e3b90c6 100644 --- a/maintainers/maintainer-list.nix +++ b/maintainers/maintainer-list.nix @@ -145,6 +145,12 @@ githubId = 67933444; keys = [ { fingerprint = "B39E B98E 8860 DAFB 0567 0073 A614 B7D2 5134 987A"; } ]; }; + _0xferrous = { + email = "0xferrous@proton.me"; + github = "0xferrous"; + githubId = 213212767; + name = "0xferrous"; + }; _0xgsvs = { email = "venkat.subrahmanyam.34@gmail.com"; name = "0xgsvs"; From 02b085bb9418bf1b5e38f7abd030b7a5531b5f30 Mon Sep 17 00:00:00 2001 From: 0xferrous <0xferrous@proton.me> Date: Sat, 2 May 2026 15:34:29 +0000 Subject: [PATCH 35/71] tree-sitter-grammars.tree-sitter-plank: init at 0.1.0 --- .../tr/tree-sitter/grammars/grammar-sources.nix | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/pkgs/by-name/tr/tree-sitter/grammars/grammar-sources.nix b/pkgs/by-name/tr/tree-sitter/grammars/grammar-sources.nix index e58fe78ffd87..3590b69dbba0 100644 --- a/pkgs/by-name/tr/tree-sitter/grammars/grammar-sources.nix +++ b/pkgs/by-name/tr/tree-sitter/grammars/grammar-sources.nix @@ -2000,6 +2000,19 @@ }; }; + plank = { + version = "0.1.0"; + url = "github:plankevm/plank-monorepo"; + hash = "sha256-B2UmV5i2ELlmzyrR8iFIOQcSpHeRQl4I6lxakMskolg="; + location = "plank-tree-sitter"; + meta = { + license = lib.licenses.mit; + maintainers = with lib.maintainers; [ + _0xferrous + ]; + }; + }; + po = { version = "0-unstable-2024-04-20"; url = "github:erasin/tree-sitter-po"; From f7fe61fc34d95a714c4878e6f18858c032bba9dc Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 2 May 2026 16:23:07 +0000 Subject: [PATCH 36/71] python3Packages.pyintesishome: 1.8.5 -> 1.8.7 --- pkgs/development/python-modules/pyintesishome/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/pyintesishome/default.nix b/pkgs/development/python-modules/pyintesishome/default.nix index 218cf2870c53..96ef3a1f9c93 100644 --- a/pkgs/development/python-modules/pyintesishome/default.nix +++ b/pkgs/development/python-modules/pyintesishome/default.nix @@ -7,14 +7,14 @@ buildPythonPackage rec { pname = "pyintesishome"; - version = "1.8.5"; + version = "1.8.7"; format = "setuptools"; src = fetchFromGitHub { owner = "jnimmo"; repo = "pyIntesisHome"; tag = version; - hash = "sha256-QgIvIn8I5EtJSNj1FdOI+DPgG7/y2ToQ62dhk7flieo="; + hash = "sha256-TwZAuu/mnChZwhZ5uGPiQ23curCiqTKWNgDrvwpgojc="; }; propagatedBuildInputs = [ aiohttp ]; From 435191101e1b298f543d845bd6e75ca2c4394366 Mon Sep 17 00:00:00 2001 From: Alexis Hildebrandt Date: Sat, 2 May 2026 09:40:09 +0200 Subject: [PATCH 37/71] zensical: 0.0.31 -> 0.0.39 --- pkgs/by-name/ze/zensical/package.nix | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ze/zensical/package.nix b/pkgs/by-name/ze/zensical/package.nix index f6ac57056cc8..4712b614b36e 100644 --- a/pkgs/by-name/ze/zensical/package.nix +++ b/pkgs/by-name/ze/zensical/package.nix @@ -8,7 +8,7 @@ python3Packages.buildPythonApplication (finalAttrs: { pname = "zensical"; - version = "0.0.31"; + version = "0.0.39"; pyproject = true; # We fetch from PyPi, because GitHub repo does not contain all sources. @@ -16,12 +16,12 @@ python3Packages.buildPythonApplication (finalAttrs: { # We could combine sources, but then nix-update won't work. src = fetchPypi { inherit (finalAttrs) pname version; - hash = "sha256-nBLwe95wxL/bE9bK4b7fjRgGTSV6boESihUlArKKj8M="; + hash = "sha256-KocTxUNirbCIHpsFFLWtmmljJHVmmd7bVfocvzzMDto="; }; cargoDeps = rustPlatform.fetchCargoVendor { inherit (finalAttrs) pname version src; - hash = "sha256-5lsL42TYg7AsnCxzLcg/KEewcTKLBKvRMJtu+fBkgeY="; + hash = "sha256-dsmb65a/dDQJXxPqM2re1w9NkomuL4JtJm0c09rN4BI="; }; nativeBuildInputs = with rustPlatform; [ @@ -36,6 +36,7 @@ python3Packages.buildPythonApplication (finalAttrs: { pygments pymdown-extensions pyyaml + tomli ]; nativeCheckInputs = [ versionCheckHook ]; From d7c03e3a489f2b8fae3bd25fd5aae966b19fc499 Mon Sep 17 00:00:00 2001 From: miampf Date: Fri, 1 May 2026 10:38:35 +0200 Subject: [PATCH 38/71] azure-cli-extensions.confcom: update maintainer --- pkgs/by-name/az/azure-cli/extensions-manual.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/by-name/az/azure-cli/extensions-manual.nix b/pkgs/by-name/az/azure-cli/extensions-manual.nix index 343cd12664af..a0255abdd3c1 100644 --- a/pkgs/by-name/az/azure-cli/extensions-manual.nix +++ b/pkgs/by-name/az/azure-cli/extensions-manual.nix @@ -192,7 +192,7 @@ chmod +x $out/${python3.sitePackages}/azext_confcom/bin/genpolicy-linux ''; meta = { - maintainers = with lib.maintainers; [ miampf ]; + maintainers = [ ]; platforms = lib.platforms.linux; # confcom is linux only }; }; From 961f3acb9fda006d504a19f3cf137cc559c72724 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Sat, 2 May 2026 11:29:57 -0700 Subject: [PATCH 39/71] python3Packages.rocketchat-api: 3.6.0 -> 3.6.1 Diff: https://github.com/jadolg/rocketchat_API/compare/3.6.0...3.6.1 Changelog: https://github.com/jadolg/rocketchat_API/releases/tag/3.6.1 --- pkgs/development/python-modules/rocketchat-api/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/rocketchat-api/default.nix b/pkgs/development/python-modules/rocketchat-api/default.nix index f3ebbed7d38e..067c560eb7bf 100644 --- a/pkgs/development/python-modules/rocketchat-api/default.nix +++ b/pkgs/development/python-modules/rocketchat-api/default.nix @@ -10,14 +10,14 @@ buildPythonPackage rec { pname = "rocketchat-api"; - version = "3.6.0"; + version = "3.6.1"; pyproject = true; src = fetchFromGitHub { owner = "jadolg"; repo = "rocketchat_API"; tag = version; - hash = "sha256-GYk3ZMAothllMxFhSFc2p4nX0wQOaWtltcrXpwK6lzE="; + hash = "sha256-KatsV5MbZ7akD/nsNLEIwPecsaa9W8PplGCppe5rcZI="; }; build-system = [ From 26bd7c1218d57b54c0c6fa19dc79270588c02618 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 2 May 2026 19:44:33 +0000 Subject: [PATCH 40/71] python3Packages.tesla-fleet-api: 1.4.6 -> 1.4.7 --- pkgs/development/python-modules/tesla-fleet-api/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/tesla-fleet-api/default.nix b/pkgs/development/python-modules/tesla-fleet-api/default.nix index 5c18c04d7166..68369780e2fd 100644 --- a/pkgs/development/python-modules/tesla-fleet-api/default.nix +++ b/pkgs/development/python-modules/tesla-fleet-api/default.nix @@ -15,14 +15,14 @@ buildPythonPackage rec { pname = "tesla-fleet-api"; - version = "1.4.6"; + version = "1.4.7"; pyproject = true; src = fetchFromGitHub { owner = "Teslemetry"; repo = "python-tesla-fleet-api"; tag = "v${version}"; - hash = "sha256-2LCpwVf10dsgZlouvu3Spr0geK8uDpEXKOI1l6sZqmM="; + hash = "sha256-704vqQwT50j/F1Mk8VMJ9VSOUfu+pHmxYQySs4UlFls="; }; build-system = [ setuptools ]; From b86bf12f81af8c31f3cf115ed1dbbeacfab7f70e Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Sat, 2 May 2026 14:52:08 -0700 Subject: [PATCH 41/71] python3Packages.insteon-frontend-home-assistant: 0.6.1 -> 0.6.2 Changelog: https://github.com/pyinsteon/insteon-panel/releases/tag/0.6.2 --- .../insteon-frontend-home-assistant/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/insteon-frontend-home-assistant/default.nix b/pkgs/development/python-modules/insteon-frontend-home-assistant/default.nix index c466b2a2ee58..cab0f335319d 100644 --- a/pkgs/development/python-modules/insteon-frontend-home-assistant/default.nix +++ b/pkgs/development/python-modules/insteon-frontend-home-assistant/default.nix @@ -7,13 +7,13 @@ buildPythonPackage rec { pname = "insteon-frontend-home-assistant"; - version = "0.6.1"; + version = "0.6.2"; pyproject = true; src = fetchPypi { pname = "insteon_frontend_home_assistant"; inherit version; - hash = "sha256-r6xXEZFAGgXByl+urpXfzhuCedBPjqkwT8Q0sEHQA2w="; + hash = "sha256-p5hL8LE8h/4ytHft/v23uzv7YwR9UBDVru8n7WeY99Q="; }; nativeBuildInputs = [ setuptools ]; From 0f18e852b2ab4697aa7101a33bd1357d7b3620c9 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Sat, 2 May 2026 15:07:23 -0700 Subject: [PATCH 42/71] pytr: 0.4.7 -> 0.4.9 Diff: https://github.com/pytr-org/pytr/compare/v0.4.7...v0.4.9 Changelog: https://github.com/pytr-org/pytr/releases/tag/v0.4.9 --- pkgs/by-name/py/pytr/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/py/pytr/package.nix b/pkgs/by-name/py/pytr/package.nix index 7adb5efa55e6..49c905775d6a 100644 --- a/pkgs/by-name/py/pytr/package.nix +++ b/pkgs/by-name/py/pytr/package.nix @@ -9,14 +9,14 @@ python3Packages.buildPythonApplication rec { pname = "pytr"; - version = "0.4.7"; + version = "0.4.9"; pyproject = true; src = fetchFromGitHub { owner = "pytr-org"; repo = "pytr"; tag = "v${version}"; - hash = "sha256-+GIjNtlg9q125jf8p5AyE1F+lT0mfqQaSJbusp0kRmo="; + hash = "sha256-W6OtXK9c8NV8wIhvaym2tAg6UNJtCEPk1mt5VB0+Rkg="; }; build-system = with python3Packages; [ @@ -30,9 +30,9 @@ python3Packages.buildPythonApplication rec { coloredlogs cryptography curl-cffi - ecdsa packaging pathvalidate + playwright pygments requests-futures shtab From 636fc13366919d6441b26a14ed7a4395e835e0b1 Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Sun, 5 Apr 2026 12:14:17 -0400 Subject: [PATCH 43/71] {ci,workflows}: allow multiple blocking reviews --- .github/workflows/check.yml | 37 +++++- .github/workflows/eval.yml | 14 +++ .github/workflows/pull-request-target.yml | 22 ++++ ci/github-script/check-target-branch.js | 10 +- ci/github-script/manual-file-edits.js | 26 ++++- ci/github-script/prepare.js | 16 ++- ci/github-script/reviews.js | 130 +++++++++++++++------- 7 files changed, 192 insertions(+), 63 deletions(-) diff --git a/.github/workflows/check.yml b/.github/workflows/check.yml index fa16aec65997..99e83c2c151f 100644 --- a/.github/workflows/check.yml +++ b/.github/workflows/check.yml @@ -16,6 +16,14 @@ on: required: true type: string secrets: + # Can be provided in pull requests because the job it is used in does + # not evaluate untrusted code. + NIXPKGS_COMMIT_CHECK_APP_PRIVATE_KEY: + required: false + # Can be provided in pull requests because the job it is used in does + # not evaluate untrusted code. + NIXPKGS_MANUAL_EDIT_CHECK_APP_PRIVATE_KEY: + required: false # Should only be provided in the merge queue, not in pull requests, # where we're evaluating untrusted code. CACHIX_AUTH_TOKEN_GHA: @@ -45,9 +53,19 @@ jobs: - name: Install dependencies run: npm install bottleneck@2.19.5 + # It's fine to reuse this app in the 'pull-request-target / prepare' job, + # because that job has to run before this one. + - uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1 + if: github.event_name != 'pull_request' && vars.NIXPKGS_COMMIT_CHECK_CLIENT_ID + id: app-token + with: + client-id: ${{ vars.NIXPKGS_COMMIT_CHECK_CLIENT_ID }} + private-key: ${{ secrets.NIXPKGS_COMMIT_CHECK_APP_PRIVATE_KEY }} + permission-pull-requests: write + - name: Log current API rate limits env: - GH_TOKEN: ${{ github.token }} + GH_TOKEN: ${{ steps.app-token.outputs.token || github.token }} run: gh api /rate_limit | jq - name: Check commits @@ -56,6 +74,7 @@ jobs: env: TARGETS_STABLE: ${{ fromJSON(inputs.baseBranch).stable && !contains(fromJSON(inputs.headBranch).type, 'development') }} with: + github-token: ${{ steps.app-token.outputs.token || github.token }} script: | const targetsStable = JSON.parse(process.env.TARGETS_STABLE) require('./trusted/ci/github-script/commits.js')({ @@ -68,7 +87,7 @@ jobs: - name: Log current API rate limits env: - GH_TOKEN: ${{ github.token }} + GH_TOKEN: ${{ steps.app-token.outputs.token || github.token }} run: gh api /rate_limit | jq manual-file-edits: @@ -85,25 +104,35 @@ jobs: sparse-checkout: | ci/github-script + - uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1 + if: github.event_name != 'pull_request' && vars.NIXPKGS_MANUAL_EDIT_CHECK_CLIENT_ID + id: app-token + with: + client-id: ${{ vars.NIXPKGS_MANUAL_EDIT_CHECK_CLIENT_ID }} + private-key: ${{ secrets.NIXPKGS_MANUAL_EDIT_CHECK_APP_PRIVATE_KEY }} + permission-pull-requests: write + - name: Log current API rate limits env: - GH_TOKEN: ${{ github.token }} + GH_TOKEN: ${{ steps.app-token.outputs.token || github.token }} run: gh api /rate_limit | jq - name: Discourage manual edits to certain files uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 with: + github-token: ${{ steps.app-token.outputs.token || github.token }} script: | require('./trusted/ci/github-script/manual-file-edits.js')({ github, context, core, + dry: context.eventName == 'pull_request', repoPath: 'trusted', }) - name: Log current API rate limits env: - GH_TOKEN: ${{ github.token }} + GH_TOKEN: ${{ steps.app-token.outputs.token || github.token }} run: gh api /rate_limit | jq owners: diff --git a/.github/workflows/eval.yml b/.github/workflows/eval.yml index 4939fa5ec329..a8dcaf29456f 100644 --- a/.github/workflows/eval.yml +++ b/.github/workflows/eval.yml @@ -23,6 +23,10 @@ on: default: false type: boolean secrets: + # Can be provided in pull requests because the job it is used in does + # not evaluate untrusted code. + NIXPKGS_BRANCH_CHECK_APP_PRIVATE_KEY: + required: false # Should only be provided in the merge queue, not in pull requests, # where we're evaluating untrusted code. CACHIX_AUTH_TOKEN_GHA: @@ -349,10 +353,20 @@ jobs: description, target_url }) + + - uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1 + if: github.event_name == 'pull_request_target' && vars.NIXPKGS_BRANCH_CHECK_CLIENT_ID + id: app-token + with: + client-id: ${{ vars.NIXPKGS_BRANCH_CHECK_CLIENT_ID }} + private-key: ${{ secrets.NIXPKGS_BRANCH_CHECK_APP_PRIVATE_KEY }} + permission-pull-requests: write + - name: Request changes if PR is against an inappropriate branch if: ${{ github.event_name == 'pull_request_target' }} uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 with: + github-token: ${{ steps.app-token.outputs.token || github.token }} script: | require('./nixpkgs/trusted/ci/github-script/check-target-branch.js')({ github, diff --git a/.github/workflows/pull-request-target.yml b/.github/workflows/pull-request-target.yml index 190ce2510a3e..02d07344eee8 100644 --- a/.github/workflows/pull-request-target.yml +++ b/.github/workflows/pull-request-target.yml @@ -10,6 +10,12 @@ on: secrets: NIXPKGS_CI_APP_PRIVATE_KEY: required: true + NIXPKGS_BRANCH_CHECK_APP_PRIVATE_KEY: + required: false + NIXPKGS_COMMIT_CHECK_APP_PRIVATE_KEY: + required: false + NIXPKGS_MANUAL_EDIT_CHECK_APP_PRIVATE_KEY: + required: false concurrency: group: pr-${{ github.workflow }}-${{ github.event_name }}-${{ github.event.pull_request.number || github.run_id }} @@ -36,6 +42,17 @@ jobs: sparse-checkout-cone-mode: true # default, for clarity sparse-checkout: | ci/github-script + + # It's fine to reuse this app in the 'check / commits' job, + # because this job has to run before that one. + - uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1 + if: vars.NIXPKGS_COMMIT_CHECK_CLIENT_ID + id: app-token + with: + client-id: ${{ vars.NIXPKGS_COMMIT_CHECK_CLIENT_ID }} + private-key: ${{ secrets.NIXPKGS_COMMIT_CHECK_APP_PRIVATE_KEY }} + permission-pull-requests: write + - id: prepare uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 with: @@ -60,6 +77,9 @@ jobs: permissions: # cherry-picks pull-requests: write + secrets: + NIXPKGS_COMMIT_CHECK_APP_PRIVATE_KEY: ${{ secrets.NIXPKGS_COMMIT_CHECK_APP_PRIVATE_KEY }} + NIXPKGS_MANUAL_EDIT_CHECK_APP_PRIVATE_KEY: ${{ secrets.NIXPKGS_MANUAL_EDIT_CHECK_APP_PRIVATE_KEY }} with: baseBranch: ${{ needs.prepare.outputs.baseBranch }} headBranch: ${{ needs.prepare.outputs.headBranch }} @@ -82,6 +102,8 @@ jobs: # compare pull-requests: write statuses: write + secrets: + NIXPKGS_BRANCH_CHECK_APP_PRIVATE_KEY: ${{ secrets.NIXPKGS_BRANCH_CHECK_APP_PRIVATE_KEY }} with: artifact-prefix: ${{ inputs.artifact-prefix }} mergedSha: ${{ needs.prepare.outputs.mergedSha }} diff --git a/ci/github-script/check-target-branch.js b/ci/github-script/check-target-branch.js index 9b47a946b889..a31520c02fc6 100644 --- a/ci/github-script/check-target-branch.js +++ b/ci/github-script/check-target-branch.js @@ -151,11 +151,9 @@ async function checkTargetBranch({ github, context, core, dry }) { core, dry, body, - event: 'COMMENT', + event: 'REQUEST_CHANGES', reviewKey, }) - - throw new Error('This PR is against the wrong branch.') } else if (rebuildsAllTests && !isExemptKernelUpdate) { let branchText if (base === 'master' && maxRebuildCount >= 500) { @@ -179,11 +177,9 @@ async function checkTargetBranch({ github, context, core, dry }) { core, dry, body, - event: 'COMMENT', + event: 'REQUEST_CHANGES', reviewKey, }) - - throw new Error('This PR is against the wrong branch.') } else if ( maxRebuildCount >= 500 && !isExemptKernelUpdate && @@ -204,7 +200,7 @@ async function checkTargetBranch({ github, context, core, dry }) { core, dry, body, - event: 'COMMENT', + event: 'REQUEST_CHANGES', reviewKey, }) } else { diff --git a/ci/github-script/manual-file-edits.js b/ci/github-script/manual-file-edits.js index e40d6decbb7d..84235d44752c 100644 --- a/ci/github-script/manual-file-edits.js +++ b/ci/github-script/manual-file-edits.js @@ -7,9 +7,13 @@ const { getCommitDetailsForPR } = require('./get-pr-commit-details') * context: import('@actions/github/lib/context').Context, * core: import('@actions/core'), * repoPath?: string, + * dry: boolean, * }} CheckManualFileEditsProps */ -async function checkManualFileEdits({ github, context, core, repoPath }) { +async function checkManualFileEdits({ github, context, core, repoPath, dry }) { + const { dismissReviews, postReview } = require('./reviews.js') + const reviewKey = 'manual-file-edits' + const pull_number = context.payload.pull_request?.number if (!pull_number) { core.info('This is not a pull request. Skipping checks.') @@ -35,8 +39,13 @@ async function checkManualFileEdits({ github, context, core, repoPath }) { changedPaths.includes('maintainers/github-teams.json'), ) ) { - core.setFailed( - [ + postReview({ + github, + context, + core, + dry, + event: 'REQUEST_CHANGES', + body: [ 'maintainers/github-teams.json is supposed to accurately reflect the state of the teams in GitHub.\n', 'Therefore, it should not be edited manually.\n', 'All changes to teams listed in maintainers/github-teams.json should be performed in GitHub by a team maintainer.\n', @@ -48,7 +57,16 @@ async function checkManualFileEdits({ github, context, core, repoPath }) { (prev, curr) => prev + (!prev || prev.endsWith('\n') ? '' : ' ') + curr, '', ), - ) + reviewKey, + }) + } else { + dismissReviews({ + github, + context, + core, + dry, + reviewKey, + }) } } diff --git a/ci/github-script/prepare.js b/ci/github-script/prepare.js index dfe2d93f3d69..d4d69eb71692 100644 --- a/ci/github-script/prepare.js +++ b/ci/github-script/prepare.js @@ -172,14 +172,20 @@ module.exports = async ({ github, context, core, dry }) => { ' ```', ].join('\n') - await postReview({ github, context, core, dry, body, reviewKey }) - - throw new Error(`The PR contains commits from a different base.`) + await postReview({ + github, + context, + core, + dry, + body, + event: 'REQUEST_CHANGES', + reviewKey, + }) } + } else { + await dismissReviews({ github, context, core, dry, reviewKey }) } - await dismissReviews({ github, context, core, dry, reviewKey }) - let mergedSha, targetSha if (prInfo.mergeable) { diff --git a/ci/github-script/reviews.js b/ci/github-script/reviews.js index 7041fdae1f10..80e250cfa7c3 100644 --- a/ci/github-script/reviews.js +++ b/ci/github-script/reviews.js @@ -5,10 +5,28 @@ const eventToState = { REQUEST_CHANGES: 'CHANGES_REQUESTED', } +// Use substring checks in order to allow testing in forks +// Usernames must also end in "[bot]" +const reviewUsers = [ + 'github-actions', + 'nixpkgs-ci', + 'branch-check', + 'commit-check', + 'manual-edit', +] + +/** + * @typedef {InstanceType} GitHub + * @typedef {typeof import('@actions/github').context} Context + * + * @typedef {Awaited>['data'][number]} Review + * @typedef {Review & { user: NonNullable }} ReviewWithNonNullUser + */ + /** * @param {{ - * github: InstanceType, - * context: import('@actions/github/lib/context').Context, + * github: GitHub, + * context: Context, * core: import('@actions/core'), * dry: boolean, * reviewKey?: string, @@ -25,18 +43,32 @@ async function dismissReviews({ github, context, core, dry, reviewKey }) { return } - const reviews = ( - await github.paginate(github.rest.pulls.listReviews, { - ...context.repo, - pull_number, - }) - ).filter( - (review) => - review.user?.login === 'github-actions[bot]' && - review.state !== 'DISMISSED', + const allReviews = await github.paginate(github.rest.pulls.listReviews, { + ...context.repo, + pull_number, + }) + + const reviews = /** @type {ReviewWithNonNullUser[]} */ ( + allReviews.filter( + (review) => + review.user && + review.state !== 'DISMISSED' && + review.user.login.endsWith('[bot]') && + reviewUsers.some((substr) => review.user?.login.includes(substr)), + ) ) - const changesRequestedReviews = reviews.filter( - (review) => review.state === 'CHANGES_REQUESTED', + + const reviewsByUser = reviews.reduce( + (prev, curr) => { + if (!(curr.user.login in prev)) { + prev[curr.user.login] = [] + } + + prev[curr.user.login].push(curr) + + return prev + }, + /** @type {Record } */ ({}), ) const commentRegex = new RegExp( @@ -50,8 +82,8 @@ async function dismissReviews({ github, context, core, dry, reviewKey }) { ) let reviewsToMinimize = reviews - let /** @type {typeof reviews} */ reviewsToDismiss = [] - let /** @type {typeof reviews} */ reviewsToResolve = [] + const /** @type {ReviewWithNonNullUser[]} */ reviewsToDismiss = [] + const /** @type {ReviewWithNonNullUser[]} */ reviewsToResolve = [] if (reviewKey && reviews.every((review) => commentRegex.test(review.body))) { reviewsToMinimize = reviews.filter((review) => @@ -59,29 +91,39 @@ async function dismissReviews({ github, context, core, dry, reviewKey }) { ) } - // If we want to dismiss all reviews with the key reviewKey, - // but there are other requested changes from CI, we can't dismiss, - // because then the other requested changes will be dismissed too. - if ( - changesRequestedReviews.every( - (review) => - commentResolvedRegex.test(review.body) || - (reviewKey && reviewKeyRegex.test(review.body)) || - // If we are called by check-commits and the review body is clearly - // from `commits.js`, then we can safely dismiss the review. - // This helps with pre-existing reviews (before the comments were added). - (reviewKey && - reviewKey === 'check-commits' && - review.body.includes('PR / Check / cherry-pick')), - ) - ) { - reviewsToDismiss = changesRequestedReviews - } else if (reviewsToMinimize.length) { - reviewsToResolve = reviewsToMinimize.filter( - (review) => - review.state === 'CHANGES_REQUESTED' && - !commentResolvedRegex.test(review.body), - ) + for (const reviewsForUser of Object.values(reviewsByUser)) { + // Make sure that we don't dismiss all reviews by a user if they + // have any reviews we don't want to dismiss. + if ( + reviewsForUser.every( + (review) => + commentResolvedRegex.test(review.body) || + (reviewKey && reviewKeyRegex.test(review.body)) || + // If we are called by check-commits and the review body is clearly + // from `commits.js`, then we can safely dismiss the review. + // This helps with pre-existing reviews (before the comments were added). + (reviewKey && + reviewKey === 'check-commits' && + review.body.includes('PR / Check / cherry-pick')), + ) + ) { + reviewsToDismiss.push( + ...reviewsForUser.filter( + (review) => review.state === 'CHANGES_REQUESTED', + ), + ) + } else { + reviewsToResolve.push( + ...reviewsForUser.filter( + (review) => + review.state === 'CHANGES_REQUESTED' && + !commentResolvedRegex.test(review.body) && + reviewsToMinimize.some( + (toMinimize) => toMinimize.node_id === review.node_id, + ), + ), + ) + } } await Promise.all([ @@ -121,8 +163,8 @@ async function dismissReviews({ github, context, core, dry, reviewKey }) { /** * @param {{ - * github: InstanceType, - * context: import('@actions/github/lib/context').Context + * github: GitHub, + * context: Context, * core: import('@actions/core'), * dry: boolean, * body: string, @@ -158,11 +200,13 @@ async function postReview({ }) ).filter( (review) => - review.user?.login === 'github-actions[bot]' && - review.state !== 'DISMISSED', + review.user && + review.state !== 'DISMISSED' && + review.user.login.endsWith('[bot]') && + reviewUsers.some((substr) => review.user?.login.includes(substr)), ) - /** @type {null | typeof reviews[number]} */ + /** @type {null | Review} */ let pendingReview const matchingReviews = reviews.filter((review) => reviewKeyRegex.test(review.body), From b53019057afd1e8c474d7ac1e84ce40a2addd6d8 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 3 May 2026 10:37:44 +0000 Subject: [PATCH 44/71] c2patool: 0.26.50 -> 0.26.55 --- pkgs/by-name/c2/c2patool/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/c2/c2patool/package.nix b/pkgs/by-name/c2/c2patool/package.nix index 9c9ac59711a5..185dc7932140 100644 --- a/pkgs/by-name/c2/c2patool/package.nix +++ b/pkgs/by-name/c2/c2patool/package.nix @@ -10,16 +10,16 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "c2patool"; - version = "0.26.50"; + version = "0.26.55"; src = fetchFromGitHub { owner = "contentauth"; repo = "c2pa-rs"; tag = "c2patool-v${finalAttrs.version}"; - hash = "sha256-4I+q+6gz+xNz+lhxyC14hZ8yyYG4qzT8TtkLxl8Y71g="; + hash = "sha256-QsBS5J35R4/e6JzuurPo0WzHfDunu7mkdrBFLlY165g="; }; - cargoHash = "sha256-Fp+EuxrPx817wjzzq8+f6vBzBe5vyhkXGRsaEqTa/Jo="; + cargoHash = "sha256-3rRSFHtQVzXeK+k+A5XW+cMvrxamkxDy57PO6SG6E8E="; # use the non-vendored openssl env.OPENSSL_NO_VENDOR = 1; From e8ab5cf41f2e966fd717050012f0ce2281bde244 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Sun, 3 May 2026 13:59:19 +0200 Subject: [PATCH 45/71] python3Packages.soxr: 1.0.0 -> 1.1.0 https://github.com/dofuuz/python-soxr/releases/tag/v1.1.0 --- pkgs/development/python-modules/soxr/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/soxr/default.nix b/pkgs/development/python-modules/soxr/default.nix index 17973333df6b..d4343e3bfa5a 100644 --- a/pkgs/development/python-modules/soxr/default.nix +++ b/pkgs/development/python-modules/soxr/default.nix @@ -23,14 +23,14 @@ buildPythonPackage rec { pname = "soxr"; - version = "1.0.0"; + version = "1.1.0"; pyproject = true; src = fetchFromGitHub { owner = "dofuuz"; repo = "python-soxr"; tag = "v${version}"; - hash = "sha256-8NVQD1LamIRe77bKEs8YqHXeXifdMJpQUedmeiBRHSI="; + hash = "sha256-XdSInR0ogbcku6yvMkGEEIxu2nlqa0mffBtd+ifvzoU="; }; patches = [ ./cmake-nanobind.patch ]; From df268eb420bcc356de685d8b7901b9ca42e052ad Mon Sep 17 00:00:00 2001 From: Eman Resu <78693624+quatquatt@users.noreply.github.com> Date: Tue, 28 Apr 2026 11:43:15 -0400 Subject: [PATCH 46/71] stdenv/check-meta: move negation outside loop, avoid primop if undefined --- pkgs/stdenv/generic/check-meta.nix | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/pkgs/stdenv/generic/check-meta.nix b/pkgs/stdenv/generic/check-meta.nix index 67144ac147e6..e9923aa995c9 100644 --- a/pkgs/stdenv/generic/check-meta.nix +++ b/pkgs/stdenv/generic/check-meta.nix @@ -387,10 +387,13 @@ let checkOutputsToInstall = attrs: - let - actualOutputs = attrs.outputs or [ "out" ]; - in - any (output: !elem output actualOutputs) (attrs.meta.outputsToInstall or [ ]); + attrs.meta ? outputsToInstall + && ( + let + actualOutputs = attrs.outputs or [ "out" ]; + in + !all (output: elem output actualOutputs) attrs.meta.outputsToInstall + ); # Check if a derivation is valid, that is whether it passes checks for # e.g brokenness or license. From 4da12f050a2163b7f5a24c092deb9b8882e07576 Mon Sep 17 00:00:00 2001 From: Eman Resu <78693624+quatquatt@users.noreply.github.com> Date: Tue, 28 Apr 2026 12:49:17 -0400 Subject: [PATCH 47/71] stdenv/check-meta: call containsLicenses early with list --- pkgs/stdenv/generic/check-meta.nix | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/pkgs/stdenv/generic/check-meta.nix b/pkgs/stdenv/generic/check-meta.nix index e9923aa995c9..404debbf1b06 100644 --- a/pkgs/stdenv/generic/check-meta.nix +++ b/pkgs/stdenv/generic/check-meta.nix @@ -81,13 +81,17 @@ let hasListedLicense = assert areLicenseListsValid; - list: attrs: + list: + let + containsListLicenses = lib.licenses.containsLicenses list; + in + attrs: attrs ? meta.license && ( if isList attrs.meta.license then any (l: elem l list) attrs.meta.license else if attrs.meta.license ? "licenseType" then - lib.licenses.containsLicenses list attrs.meta.license + containsListLicenses attrs.meta.license else elem attrs.meta.license list ); From b58843343280f817c6d797c00b07ebc6422d85bc Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Sun, 3 May 2026 14:11:50 +0200 Subject: [PATCH 48/71] python3Packages.requests-cache: fix optional-dependencies The optional-dependencies are accessible via passthru only. --- pkgs/development/python-modules/requests-cache/default.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/development/python-modules/requests-cache/default.nix b/pkgs/development/python-modules/requests-cache/default.nix index 92d46c37db03..3be91dbea9cd 100644 --- a/pkgs/development/python-modules/requests-cache/default.nix +++ b/pkgs/development/python-modules/requests-cache/default.nix @@ -64,7 +64,7 @@ buildPythonPackage (finalAttrs: { orjson ujson ] - ++ lib.concatAttrValues (lib.removeAttrs finalAttrs.optional-dependencies [ "all" ]); + ++ lib.concatAttrValues (lib.removeAttrs finalAttrs.passthru.optional-dependencies [ "all" ]); }; nativeCheckInputs = [ From a72cd26ceb15e1f9091a72f3edef41dcf28e3589 Mon Sep 17 00:00:00 2001 From: Eman Resu <78693624+quatquatt@users.noreply.github.com> Date: Mon, 27 Apr 2026 12:48:31 -0400 Subject: [PATCH 49/71] lib.makeOverridable: avoid some function calls --- lib/customisation.nix | 114 ++++++++++++++++++++---------------------- 1 file changed, 55 insertions(+), 59 deletions(-) diff --git a/lib/customisation.nix b/lib/customisation.nix index 95f1d5ebf69e..b2fa2cdebf33 100644 --- a/lib/customisation.nix +++ b/lib/customisation.nix @@ -155,71 +155,67 @@ rec { let # Creates a functor with the same arguments as f mirrorArgs = mirrorFunctionArgs f; - # Recover overrider and additional attributes for f - # When f is a callable attribute set, - # it may contain its own `f.override` and additional attributes. - # This helper function recovers those attributes and decorate the overrider. - decorate = - f': - if isAttrs f then - ( - fDecorated: - # Preserve additional attributes for f - f - // fDecorated - # Decorate f.override if presented - // { - ${if f ? override then "override" else null} = fdrv: makeOverridable (f.override fdrv); - } - ) - (mirrorArgs f') - else - mirrorArgs f'; - in - decorate ( - origArgs: - let - result = f origArgs; - # Re-call the function but with different arguments - overrideArgs = mirrorArgs ( - /** - Change the arguments with which a certain function is called. + f' = + origArgs: + let + result = f origArgs; - In some cases, you may find a list of possible attributes to pass in this function's `__functionArgs` attribute, but it will not be complete for an original function like `args@{foo, ...}: ...`, which accepts arbitrary attributes. - - This function was provided by `lib.makeOverridable`. - */ - newArgs: makeOverridable f (origArgs // (if isFunction newArgs then newArgs origArgs else newArgs)) - ); - in - if isAttrs result then - result - // { - override = overrideArgs; - overrideDerivation = fdrv: makeOverridable (mirrorArgs (args: overrideDerivation (f args) fdrv)) origArgs; - ${if result ? overrideAttrs then "overrideAttrs" else null} = + # Re-call the function but with different arguments + overrideArgs = mirrorArgs ( /** - Override the attributes that were passed to `mkDerivation` in order to generate this derivation. + Change the arguments with which a certain function is called. - This function is provided by `lib.makeOverridable`, and indirectly by `callPackage` among others, in order to make the combination of `override` and `overrideAttrs` work. - Specifically, it re-adds the `override` attribute to the result of `overrideAttrs`. + In some cases, you may find a list of possible attributes to pass in this function's `__functionArgs` attribute, but it will not be complete for an original function like `args@{foo, ...}: ...`, which accepts arbitrary attributes. - The real implementation of `overrideAttrs` is provided by `stdenv.mkDerivation`. + This function was provided by `lib.makeOverridable`. */ - # NOTE: part of the above documentation had to be duplicated in `mkDerivation`'s `overrideAttrs`. - # design/tech debt issue: https://github.com/NixOS/nixpkgs/issues/273815 - fdrv: makeOverridable (mirrorArgs (args: (f args).overrideAttrs fdrv)) origArgs; - } - else if isFunction result then - # Transform the result into a functor while propagating its arguments - setFunctionArgs result (functionArgs result) - // { - override = overrideArgs; - } - else - result - ); + newArgs: makeOverridable f (origArgs // (if isFunction newArgs then newArgs origArgs else newArgs)) + ); + in + if isAttrs result then + result + // { + override = overrideArgs; + overrideDerivation = + fdrv: makeOverridable (mirrorArgs (args: overrideDerivation (f args) fdrv)) origArgs; + ${if result ? overrideAttrs then "overrideAttrs" else null} = + /** + Override the attributes that were passed to `mkDerivation` in order to generate this derivation. + + This function is provided by `lib.makeOverridable`, and indirectly by `callPackage` among others, in order to make the combination of `override` and `overrideAttrs` work. + Specifically, it re-adds the `override` attribute to the result of `overrideAttrs`. + + The real implementation of `overrideAttrs` is provided by `stdenv.mkDerivation`. + */ + # NOTE: part of the above documentation had to be duplicated in `mkDerivation`'s `overrideAttrs`. + # design/tech debt issue: https://github.com/NixOS/nixpkgs/issues/273815 + fdrv: makeOverridable (mirrorArgs (args: (f args).overrideAttrs fdrv)) origArgs; + } + else if isFunction result then + # Transform the result into a functor while propagating its arguments + setFunctionArgs result (functionArgs result) + // { + override = overrideArgs; + } + else + result; + in + # Recover overrider and additional attributes for f + # When f is a callable attribute set, + # it may contain its own `f.override` and additional attributes. + # This recovers those attributes and decorates the overrider. + if isAttrs f then + # Preserve additional attributes for f + f + // (mirrorArgs f') + # Decorate f.override if presented + // { + ${if f ? override then "override" else null} = fdrv: makeOverridable (f.override fdrv); + } + + else + mirrorArgs f'; /** Call the package function in the file `fn` with the required From 6a07020e3c1734ff6f069a8f4ff33e6a2a0aefae Mon Sep 17 00:00:00 2001 From: Eman Resu <78693624+quatquatt@users.noreply.github.com> Date: Mon, 27 Apr 2026 12:02:43 -0400 Subject: [PATCH 50/71] lib.overrideDerivation: rewrite to not be utterly ridiculous Why are we running a `flip` on arguments we can control? Why are we using `or` on one line only to use a full if/else on the next line? Why are we merging with {}, and why have we been doing it for three years? THese are the questions I ask myself. --- lib/customisation.nix | 16 +++++++--------- 1 file changed, 7 insertions(+), 9 deletions(-) diff --git a/lib/customisation.nix b/lib/customisation.nix index b2fa2cdebf33..4fbbfec41dff 100644 --- a/lib/customisation.nix +++ b/lib/customisation.nix @@ -20,7 +20,6 @@ let take length filterAttrs - flip head pipe isDerivation @@ -98,19 +97,18 @@ rec { */ overrideDerivation = drv: f: - let - newDrv = derivation (drv.drvAttrs // (f drv)); - in - flip (extendDerivation (seq drv.drvPath true)) newDrv ( + (extendDerivation (seq drv.drvPath true)) ( { meta = drv.meta or { }; - passthru = if drv ? passthru then drv.passthru else { }; + passthru = drv.passthru or { }; } // (drv.passthru or { }) - // optionalAttrs (drv ? __spliced) { - __spliced = { } // (mapAttrs (_: sDrv: overrideDerivation sDrv f) drv.__spliced); + // { + ${if drv ? __spliced then "__spliced" else null} = mapAttrs ( + _: sDrv: overrideDerivation sDrv f + ) drv.__spliced; } - ); + ) (derivation (drv.drvAttrs // (f drv))); /** `makeOverridable` takes a function from attribute set to attribute set and From caab17b274c0bf5b1763315132af91a80b106582 Mon Sep 17 00:00:00 2001 From: Eman Resu <78693624+quatquatt@users.noreply.github.com> Date: Sun, 26 Apr 2026 16:00:20 -0400 Subject: [PATCH 51/71] lib.callPackageWith: move error message variables out of happy path --- lib/customisation.nix | 90 +++++++++++++++++++++---------------------- 1 file changed, 43 insertions(+), 47 deletions(-) diff --git a/lib/customisation.nix b/lib/customisation.nix index 4fbbfec41dff..2cce885dde6f 100644 --- a/lib/customisation.nix +++ b/lib/customisation.nix @@ -264,6 +264,40 @@ rec { ``` */ callPackageWith = + let + makeErrorMessage = + autoArgs: fn: args: fargs: arg: + let + # Get a list of suggested argument names for a given missing one + getSuggestions = + arg: + pipe (autoArgs // args) [ + attrNames + # Only use ones that are at most 2 edits away. While mork would work, + # levenshteinAtMost is only fast for 2 or less. + (filter (levenshteinAtMost 2 arg)) + # Put strings with shorter distance first + (sortOn (levenshtein arg)) + # Only take the first couple results + (take 3) + # Quote all entries + (map (x: "\"" + x + "\"")) + ]; + + prettySuggestions = + suggestions: + if suggestions == [ ] then + "" + else if length suggestions == 1 then + ", did you mean ${elemAt suggestions 0}?" + else + ", did you mean ${concatStringsSep ", " (lib.init suggestions)} or ${lib.last suggestions}?"; + + loc = unsafeGetAttrPos arg fargs; + loc' = if loc != null then loc.file + ":" + toString loc.line else ""; + in + "lib.customisation.callPackageWith: Function called without required argument \"${arg}\" at ${loc'}${prettySuggestions (getSuggestions arg)}"; + in autoArgs: fn: args: let f = if isFunction fn then fn else import fn; @@ -277,58 +311,20 @@ rec { # wouldn't be passed to it missingArgs = # Filter out arguments that have a default value - ( - filterAttrs (name: value: !value) - # Filter out arguments that would be passed - (removeAttrs fargs (attrNames allArgs)) - ); - - # Get a list of suggested argument names for a given missing one - getSuggestions = - arg: - pipe (autoArgs // args) [ - attrNames - # Only use ones that are at most 2 edits away. While mork would work, - # levenshteinAtMost is only fast for 2 or less. - (filter (levenshteinAtMost 2 arg)) - # Put strings with shorter distance first - (sortOn (levenshtein arg)) - # Only take the first couple results - (take 3) - # Quote all entries - (map (x: "\"" + x + "\"")) - ]; - - prettySuggestions = - suggestions: - if suggestions == [ ] then - "" - else if length suggestions == 1 then - ", did you mean ${elemAt suggestions 0}?" - else - ", did you mean ${concatStringsSep ", " (lib.init suggestions)} or ${lib.last suggestions}?"; - - errorForArg = - arg: - let - loc = unsafeGetAttrPos arg fargs; - loc' = if loc != null then loc.file + ":" + toString loc.line else ""; - in - "Function called without required argument \"${arg}\" at " - + "${loc'}${prettySuggestions (getSuggestions arg)}"; - - # Only show the error for the first missing argument - error = errorForArg (head (attrNames missingArgs)); + filterAttrs (name: value: !value) + # Filter out arguments that would be passed + (removeAttrs fargs (attrNames allArgs)); in if missingArgs == { } then makeOverridable f allArgs - # This needs to be an abort so it can't be caught with `builtins.tryEval`, - # which is used by nix-env and ofborg to filter out packages that don't evaluate. - # This way we're forced to fix such errors in Nixpkgs, - # which is especially relevant with allowAliases = false else - abort "lib.customisation.callPackageWith: ${error}"; + # Only show the error for the first missing argument + # This needs to be an abort so it can't be caught with `builtins.tryEval`, + # which is used by nix-env and ofborg to filter out packages that don't evaluate. + # This way we're forced to fix such errors in Nixpkgs, + # which is especially relevant with allowAliases = false + abort (makeErrorMessage autoArgs fn args fargs (head (attrNames missingArgs))); /** Like `callPackage`, but for a function that returns an attribute From 54cbe35bf9b3513d5789c76a9be9a448bed24d2c Mon Sep 17 00:00:00 2001 From: Eman Resu <78693624+quatquatt@users.noreply.github.com> Date: Thu, 30 Apr 2026 10:33:31 -0400 Subject: [PATCH 52/71] lib.callPackageWith: use custom version of filterAttrs Avoids a double-negation and passing the name every time. --- lib/customisation.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/lib/customisation.nix b/lib/customisation.nix index 2cce885dde6f..9ce5f1eece3e 100644 --- a/lib/customisation.nix +++ b/lib/customisation.nix @@ -19,7 +19,6 @@ let sortOn take length - filterAttrs head pipe isDerivation @@ -265,6 +264,7 @@ rec { */ callPackageWith = let + filterTrueAttrs = set: removeAttrs set (filter (name: set.${name}) (attrNames set)); makeErrorMessage = autoArgs: fn: args: fargs: arg: let @@ -311,7 +311,7 @@ rec { # wouldn't be passed to it missingArgs = # Filter out arguments that have a default value - filterAttrs (name: value: !value) + filterTrueAttrs # Filter out arguments that would be passed (removeAttrs fargs (attrNames allArgs)); From efd9c79a80ce8e4596bd60f72537f2c65a87b6fe Mon Sep 17 00:00:00 2001 From: Eman Resu <78693624+quatquatt@users.noreply.github.com> Date: Thu, 30 Apr 2026 14:12:28 -0400 Subject: [PATCH 53/71] lib.callPackageWith: filter names instead of attributes --- lib/customisation.nix | 11 +++++------ 1 file changed, 5 insertions(+), 6 deletions(-) diff --git a/lib/customisation.nix b/lib/customisation.nix index 9ce5f1eece3e..2801dafd59f2 100644 --- a/lib/customisation.nix +++ b/lib/customisation.nix @@ -264,7 +264,6 @@ rec { */ callPackageWith = let - filterTrueAttrs = set: removeAttrs set (filter (name: set.${name}) (attrNames set)); makeErrorMessage = autoArgs: fn: args: fargs: arg: let @@ -309,14 +308,14 @@ rec { # a list of argument names that the function requires, but # wouldn't be passed to it - missingArgs = + missingNames = # Filter out arguments that have a default value - filterTrueAttrs + filter (name: !fargs.${name}) # Filter out arguments that would be passed - (removeAttrs fargs (attrNames allArgs)); + (attrNames (removeAttrs fargs (attrNames allArgs))); in - if missingArgs == { } then + if missingNames == [ ] then makeOverridable f allArgs else # Only show the error for the first missing argument @@ -324,7 +323,7 @@ rec { # which is used by nix-env and ofborg to filter out packages that don't evaluate. # This way we're forced to fix such errors in Nixpkgs, # which is especially relevant with allowAliases = false - abort (makeErrorMessage autoArgs fn args fargs (head (attrNames missingArgs))); + abort (makeErrorMessage autoArgs fn args fargs (head missingNames)); /** Like `callPackage`, but for a function that returns an attribute From 0b29c3289edeb4730cb4b067edf03361cd8c9654 Mon Sep 17 00:00:00 2001 From: Eman Resu <78693624+quatquatt@users.noreply.github.com> Date: Fri, 1 May 2026 10:55:14 -0400 Subject: [PATCH 54/71] lib.callPackageWith: check if args are already empty before handling defaults --- lib/customisation.nix | 24 ++++++++++++++---------- 1 file changed, 14 insertions(+), 10 deletions(-) diff --git a/lib/customisation.nix b/lib/customisation.nix index 2801dafd59f2..e9e88aff7cb5 100644 --- a/lib/customisation.nix +++ b/lib/customisation.nix @@ -6,6 +6,8 @@ let unsafeGetAttrPos ; inherit (lib) + all + attrValues functionArgs isFunction mirrorFunctionArgs @@ -265,8 +267,14 @@ rec { callPackageWith = let makeErrorMessage = - autoArgs: fn: args: fargs: arg: + autoArgs: fn: args: fargs: unpassedArgs: let + # The first missing arg + arg = head ( + # Filter out the default args. We did a similar computation in the + # happy path, but we're okay recomputing it in an error case + filter (name: !fargs.${name}) (attrNames unpassedArgs) + ); # Get a list of suggested argument names for a given missing one getSuggestions = arg: @@ -306,16 +314,12 @@ rec { # This includes automatic ones and ones passed explicitly allArgs = intersectAttrs fargs autoArgs // args; - # a list of argument names that the function requires, but - # wouldn't be passed to it - missingNames = - # Filter out arguments that have a default value - filter (name: !fargs.${name}) - # Filter out arguments that would be passed - (attrNames (removeAttrs fargs (attrNames allArgs))); + # arguments that weren't passed automatically to the function + unpassedArgs = removeAttrs fargs (attrNames allArgs); in - if missingNames == [ ] then + # if nonempty, check if the function has defaults for those other args + if unpassedArgs == { } || all (value: value) (attrValues unpassedArgs) then makeOverridable f allArgs else # Only show the error for the first missing argument @@ -323,7 +327,7 @@ rec { # which is used by nix-env and ofborg to filter out packages that don't evaluate. # This way we're forced to fix such errors in Nixpkgs, # which is especially relevant with allowAliases = false - abort (makeErrorMessage autoArgs fn args fargs (head missingNames)); + abort (makeErrorMessage autoArgs fn args fargs unpassedArgs); /** Like `callPackage`, but for a function that returns an attribute From b17f9963c5cf1f40e22f1739d365206ae64eeadd Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Thu, 30 Apr 2026 09:07:52 +0200 Subject: [PATCH 55/71] python3Packages.claude-agent-sdk: 0.1.68 -> 0.1.71 Diff: https://github.com/anthropics/claude-agent-sdk-python/compare/v0.1.68...v0.1.71 Changelog: https://github.com/anthropics/claude-agent-sdk-python/blob/v0.1.71/CHANGELOG.md --- pkgs/development/python-modules/claude-agent-sdk/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/claude-agent-sdk/default.nix b/pkgs/development/python-modules/claude-agent-sdk/default.nix index 17da75bd68f7..754842d5e6a5 100644 --- a/pkgs/development/python-modules/claude-agent-sdk/default.nix +++ b/pkgs/development/python-modules/claude-agent-sdk/default.nix @@ -13,14 +13,14 @@ buildPythonPackage (finalAttrs: { pname = "claude-agent-sdk"; - version = "0.1.68"; + version = "0.1.71"; pyproject = true; src = fetchFromGitHub { owner = "anthropics"; repo = "claude-agent-sdk-python"; tag = "v${finalAttrs.version}"; - hash = "sha256-m42AYi9OkII9NOSNV9D9M7GMamh2Qncpz21s7BS1E70="; + hash = "sha256-C/oJ2/iSTgN+IQpX2V5EC47sqwrhYcVorAm3X43eqCw="; }; build-system = [ hatchling ]; From 63e174d99d3a14bb77d94bec1bb5e9b647651c02 Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Sun, 3 May 2026 14:25:36 +0200 Subject: [PATCH 56/71] python3Packages.claude-agent-sdk: 0.1.71 -> 0.1.72 Diff: https://github.com/anthropics/claude-agent-sdk-python/compare/v0.1.71...v0.1.72 Changelog: https://github.com/anthropics/claude-agent-sdk-python/blob/v0.1.72/CHANGELOG.md --- pkgs/development/python-modules/claude-agent-sdk/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/claude-agent-sdk/default.nix b/pkgs/development/python-modules/claude-agent-sdk/default.nix index 754842d5e6a5..64e121f02c6a 100644 --- a/pkgs/development/python-modules/claude-agent-sdk/default.nix +++ b/pkgs/development/python-modules/claude-agent-sdk/default.nix @@ -13,14 +13,14 @@ buildPythonPackage (finalAttrs: { pname = "claude-agent-sdk"; - version = "0.1.71"; + version = "0.1.72"; pyproject = true; src = fetchFromGitHub { owner = "anthropics"; repo = "claude-agent-sdk-python"; tag = "v${finalAttrs.version}"; - hash = "sha256-C/oJ2/iSTgN+IQpX2V5EC47sqwrhYcVorAm3X43eqCw="; + hash = "sha256-F8V1BUC0jeGWWFBS1GE931bycm0xJlAmoH1kPpxkk9o="; }; build-system = [ hatchling ]; From a585591aa391172ae52fdfa79a7c527c03d6a89b Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 3 May 2026 12:30:26 +0000 Subject: [PATCH 57/71] sqlmap: 1.10.3 -> 1.10.5 --- pkgs/development/python-modules/sqlmap/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/sqlmap/default.nix b/pkgs/development/python-modules/sqlmap/default.nix index a7587c290b82..be7951219592 100644 --- a/pkgs/development/python-modules/sqlmap/default.nix +++ b/pkgs/development/python-modules/sqlmap/default.nix @@ -9,12 +9,12 @@ buildPythonPackage (finalAttrs: { pname = "sqlmap"; - version = "1.10.3"; + version = "1.10.5"; pyproject = true; src = fetchPypi { inherit (finalAttrs) pname version; - hash = "sha256-PRZvDidyvwjJ7oXU9Mu6eObHm08wWCjjHx6BPjP/Dlg="; + hash = "sha256-LS4K7+3KyxjVoFKeNteRypSa7Yr6RAHiL/eviY8YajE="; }; postPatch = '' From af8a3925844248b5b033824c36030bfe3a669f76 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 3 May 2026 12:57:33 +0000 Subject: [PATCH 58/71] python3Packages.knx-frontend: 2026.4.22.141111 -> 2026.4.30.60856 --- pkgs/development/python-modules/knx-frontend/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/knx-frontend/default.nix b/pkgs/development/python-modules/knx-frontend/default.nix index 077e173e6c86..9bb21e466955 100644 --- a/pkgs/development/python-modules/knx-frontend/default.nix +++ b/pkgs/development/python-modules/knx-frontend/default.nix @@ -7,14 +7,14 @@ buildPythonPackage rec { pname = "knx-frontend"; - version = "2026.4.22.141111"; + version = "2026.4.30.60856"; pyproject = true; # TODO: source build, uses yarn.lock src = fetchPypi { pname = "knx_frontend"; inherit version; - hash = "sha256-2gzQETX2YayiahCGw9sSS6mCo5DmApBZB54ISQBm43M="; + hash = "sha256-ZviZoQY0ZlIgiiEKwsOpTRVoi8F1JPE1RqD8Nzozpr4="; }; build-system = [ setuptools ]; From 16939eba9a911d2c1a07e3bc28f773365ec89382 Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Sun, 3 May 2026 14:32:14 +0200 Subject: [PATCH 59/71] python3Packages.pyintesishome: modernize --- .../python-modules/pyintesishome/default.nix | 17 ++++++++++------- 1 file changed, 10 insertions(+), 7 deletions(-) diff --git a/pkgs/development/python-modules/pyintesishome/default.nix b/pkgs/development/python-modules/pyintesishome/default.nix index 96ef3a1f9c93..afccc4be5f55 100644 --- a/pkgs/development/python-modules/pyintesishome/default.nix +++ b/pkgs/development/python-modules/pyintesishome/default.nix @@ -3,21 +3,24 @@ aiohttp, buildPythonPackage, fetchFromGitHub, + setuptools, }: -buildPythonPackage rec { +buildPythonPackage (finalAttrs: { pname = "pyintesishome"; version = "1.8.7"; - format = "setuptools"; + pyproject = true; src = fetchFromGitHub { owner = "jnimmo"; repo = "pyIntesisHome"; - tag = version; + tag = finalAttrs.version; hash = "sha256-TwZAuu/mnChZwhZ5uGPiQ23curCiqTKWNgDrvwpgojc="; }; - propagatedBuildInputs = [ aiohttp ]; + build-system = [ setuptools ]; + + dependencies = [ aiohttp ]; # Project has no tests doCheck = false; @@ -27,8 +30,8 @@ buildPythonPackage rec { meta = { description = "Python interface for IntesisHome devices"; homepage = "https://github.com/jnimmo/pyIntesisHome"; - changelog = "https://github.com/jnimmo/pyIntesisHome/releases/tag/${version}"; - license = with lib.licenses; [ mit ]; + changelog = "https://github.com/jnimmo/pyIntesisHome/releases/tag/${finalAttrs.src.tag}"; + license = lib.licenses.mit; maintainers = with lib.maintainers; [ fab ]; }; -} +}) From d2ee4b566987668a6add5dabaec630fe1c27f5c4 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 3 May 2026 13:08:55 +0000 Subject: [PATCH 60/71] wxmaxima: 26.01.0 -> 26.05.0 --- pkgs/by-name/wx/wxmaxima/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/wx/wxmaxima/package.nix b/pkgs/by-name/wx/wxmaxima/package.nix index f22dc9cba856..2defc671f091 100644 --- a/pkgs/by-name/wx/wxmaxima/package.nix +++ b/pkgs/by-name/wx/wxmaxima/package.nix @@ -13,13 +13,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "wxmaxima"; - version = "26.01.0"; + version = "26.05.0"; src = fetchFromGitHub { owner = "wxMaxima-developers"; repo = "wxmaxima"; rev = "Version-${finalAttrs.version}"; - hash = "sha256-RoFOmBro8Oo6P3gglaz8ofkrhwxnwy6Rf0po3jOY5D4="; + hash = "sha256-/O57UjejHb9lDYiLs9jdtmt/S7CTHY0tlq07fAxh5TM="; }; buildInputs = [ From 1c3eaed6b1d5d3399ee7a6f6d273011040bd25b3 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Na=C3=AFm=20Camille=20Favier?= Date: Sun, 3 May 2026 15:14:01 +0200 Subject: [PATCH 61/71] nixos/profiles/base: add explicit support for ext filesystems ext filesystems are only supported unconditionally if the systemd initrd is NOT used. Since the systemd initrd was recently enabled by default, the default ISO image configuration is now missing support for ext filesystems, which means that one cannot e.g. boot into a live ISO image and run `fsck.ext4`. This commit adds ext2, ext3 and ext4 as explicitly supported file systems in the base profile, which ensures that the associated tools are always available. --- nixos/modules/profiles/base.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/nixos/modules/profiles/base.nix b/nixos/modules/profiles/base.nix index fffc53c8e551..b7dd6477984e 100644 --- a/nixos/modules/profiles/base.nix +++ b/nixos/modules/profiles/base.nix @@ -53,6 +53,9 @@ # Include support for various filesystems and tools to create / manipulate them. boot.supportedFilesystems = lib.mkMerge [ [ + "ext2" + "ext3" + "ext4" "btrfs" "cifs" "f2fs" From f1e83d38920b3e8885f5fe5b4ed82d2f8bab1145 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 3 May 2026 13:31:27 +0000 Subject: [PATCH 62/71] mcp-gateway: 2.9.1 -> 2.11.0 --- pkgs/by-name/mc/mcp-gateway/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/mc/mcp-gateway/package.nix b/pkgs/by-name/mc/mcp-gateway/package.nix index dd91c1b45f13..13947edaca2a 100644 --- a/pkgs/by-name/mc/mcp-gateway/package.nix +++ b/pkgs/by-name/mc/mcp-gateway/package.nix @@ -7,16 +7,16 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "mcp-gateway"; - version = "2.9.1"; + version = "2.11.0"; src = fetchFromGitHub { owner = "MikkoParkkola"; repo = "mcp-gateway"; tag = "v${finalAttrs.version}"; - hash = "sha256-jPggWHX/Qz3sMh3P791D9WRMsppy3xRfUXd3jAcef5M="; + hash = "sha256-7IALz7hOnCeKtiEm8b3M7v5oy4hw173viyhNeqQIhTI="; }; - cargoHash = "sha256-TLjiI6mgWRkxZEifbyLzZpHj+486RYoGY2GOXsh/1Bs="; + cargoHash = "sha256-B5HRETFryzLqQhdIqRFj0apZS0wMggW2MHE2VsbB22Y="; nativeInstallCheckInputs = [ versionCheckHook From d6d32e1a005051e1595412aa9416dcf983e45168 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 3 May 2026 13:36:35 +0000 Subject: [PATCH 63/71] mympd: 25.0.1 -> 25.0.2 --- pkgs/by-name/my/mympd/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/my/mympd/package.nix b/pkgs/by-name/my/mympd/package.nix index b3f9e005a037..9d5e5ff1d1f9 100644 --- a/pkgs/by-name/my/mympd/package.nix +++ b/pkgs/by-name/my/mympd/package.nix @@ -18,13 +18,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "mympd"; - version = "25.0.1"; + version = "25.0.2"; src = fetchFromGitHub { owner = "jcorporation"; repo = "myMPD"; rev = "v${finalAttrs.version}"; - sha256 = "sha256-qi+VzDe91yEQzNEcUSuhcuxF76FmBsVkmb5LCB+yjP0="; + sha256 = "sha256-DF2+n6yiMOhHIS271YKzsEX0EZ7UXAtojVv48m7GSmQ="; }; nativeBuildInputs = [ From ef7c1bdbc3fe60b4f99ae8d5411f0cd025f4b28b Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 3 May 2026 13:50:45 +0000 Subject: [PATCH 64/71] havn: 0.3.6 -> 0.3.7 --- pkgs/by-name/ha/havn/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ha/havn/package.nix b/pkgs/by-name/ha/havn/package.nix index 589d72cb43b8..731ac2e94f52 100644 --- a/pkgs/by-name/ha/havn/package.nix +++ b/pkgs/by-name/ha/havn/package.nix @@ -6,16 +6,16 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "havn"; - version = "0.3.6"; + version = "0.3.7"; src = fetchFromGitHub { owner = "mrjackwills"; repo = "havn"; tag = "v${finalAttrs.version}"; - hash = "sha256-eQyWaAPDnfAXvqOVNI9luZIdLMSj1P779yiWOhZ5dsg="; + hash = "sha256-9xMrzRfnUA8GG+u255oBhdUWL7NACVtj50QwZuMM4yg="; }; - cargoHash = "sha256-pnXPIEVzAn6ovNo7+3BNzFptleOPFDklSU/e44roahs="; + cargoHash = "sha256-Fu+AU46AY/96uwKqDQcQ9inp2VZAZnq0YxR8N6wcQ2M="; checkFlags = [ # Skip tests that require network access From 9c0878efceab645197da67fc094c04c89e58e7f2 Mon Sep 17 00:00:00 2001 From: Christopher Crouse Date: Sun, 3 May 2026 16:38:59 +0200 Subject: [PATCH 65/71] pantheon-tweaks: 2.5.1 -> 2.5.2 --- pkgs/by-name/pa/pantheon-tweaks/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/pa/pantheon-tweaks/package.nix b/pkgs/by-name/pa/pantheon-tweaks/package.nix index e9caad91be84..dd25125b706d 100644 --- a/pkgs/by-name/pa/pantheon-tweaks/package.nix +++ b/pkgs/by-name/pa/pantheon-tweaks/package.nix @@ -17,13 +17,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "pantheon-tweaks"; - version = "2.5.1"; + version = "2.5.2"; src = fetchFromGitHub { owner = "pantheon-tweaks"; repo = "pantheon-tweaks"; rev = finalAttrs.version; - hash = "sha256-haiKElDv6lvZeROpiCc2n3I0Ho/l6HjUhu/yBISsT2E="; + hash = "sha256-C6QgGjNjkgJ1qCNNe5gkwjzMfBosxjDIdVyIokCRkbE="; }; nativeBuildInputs = [ From d2e22243954141a6680fc7eb4c631dcec19e2d9f Mon Sep 17 00:00:00 2001 From: Sebastian August Snoer Date: Sun, 3 May 2026 12:24:15 +0200 Subject: [PATCH 66/71] vimPlugins.run-nvim: init at 2.0.0 --- pkgs/applications/editors/vim/plugins/generated.nix | 13 +++++++++++++ pkgs/applications/editors/vim/plugins/overrides.nix | 12 ++++++++++++ .../editors/vim/plugins/vim-plugin-names | 1 + 3 files changed, 26 insertions(+) diff --git a/pkgs/applications/editors/vim/plugins/generated.nix b/pkgs/applications/editors/vim/plugins/generated.nix index 335435b85d9a..17a92f2c1640 100644 --- a/pkgs/applications/editors/vim/plugins/generated.nix +++ b/pkgs/applications/editors/vim/plugins/generated.nix @@ -15539,6 +15539,19 @@ final: prev: { meta.hydraPlatforms = [ ]; }; + run-nvim = buildVimPlugin { + pname = "run.nvim"; + version = "2.0.0"; + src = fetchgit { + url = "https://codeberg.org/ssnoer/run.nvim"; + tag = "v2.0.0"; + hash = "sha256-MTxhhcD6lHLJCfwaivKF9reeUrMog/8I2kJarNWz5Kk="; + }; + meta.homepage = "https://codeberg.org/ssnoer/run.nvim"; + meta.license = lib.licenses.unfree; + meta.hydraPlatforms = [ ]; + }; + runner-nvim = buildVimPlugin { pname = "runner-nvim"; version = "0-unstable-2026-02-11"; diff --git a/pkgs/applications/editors/vim/plugins/overrides.nix b/pkgs/applications/editors/vim/plugins/overrides.nix index 6a9830ab6808..4093605bc22a 100644 --- a/pkgs/applications/editors/vim/plugins/overrides.nix +++ b/pkgs/applications/editors/vim/plugins/overrides.nix @@ -3899,6 +3899,18 @@ assertNoAdditions { }; }); + run-nvim = super.run-nvim.overrideAttrs { + dependencies = [ + self.telescope-nvim + ]; + + checkInputs = [ + # Transitive depedency of telescope.nvim + # Issue: https://github.com/NixOS/nixpkgs/issues/394939 + self.plenary-nvim + ]; + }; + rust-tools-nvim = super.rust-tools-nvim.overrideAttrs { dependencies = [ self.nvim-lspconfig ]; }; diff --git a/pkgs/applications/editors/vim/plugins/vim-plugin-names b/pkgs/applications/editors/vim/plugins/vim-plugin-names index e13118523ecf..312dbb311486 100644 --- a/pkgs/applications/editors/vim/plugins/vim-plugin-names +++ b/pkgs/applications/editors/vim/plugins/vim-plugin-names @@ -1108,6 +1108,7 @@ https://github.com/rose-pine/neovim/,main,rose-pine https://github.com/seblyng/roslyn.nvim/,, https://github.com/keith/rspec.vim/,, https://github.com/ccarpita/rtorrent-syntax-file/,, +https://codeberg.org/ssnoer/run.nvim,, https://github.com/TheLazyCat00/runner-nvim/,, https://github.com/simrat39/rust-tools.nvim/,, https://github.com/rust-lang/rust.vim/,, From 29bd4475ae607ac6b3dbe534d5f34c44b038111e Mon Sep 17 00:00:00 2001 From: Thomas Butter Date: Tue, 21 Apr 2026 05:53:17 +0000 Subject: [PATCH 67/71] mystmd: 1.3.18 -> 1.8.3 --- pkgs/by-name/my/mystmd/package.nix | 92 +++++++++++++++++++++++++----- 1 file changed, 79 insertions(+), 13 deletions(-) diff --git a/pkgs/by-name/my/mystmd/package.nix b/pkgs/by-name/my/mystmd/package.nix index 3a956e647590..9092d64aa386 100644 --- a/pkgs/by-name/my/mystmd/package.nix +++ b/pkgs/by-name/my/mystmd/package.nix @@ -1,30 +1,96 @@ { + bun, lib, - buildNpmPackage, fetchFromGitHub, mystmd, + nodejs, + stdenv, testers, nix-update-script, + writableTmpDirAsHomeHook, }: - -buildNpmPackage rec { +stdenv.mkDerivation (finalAttrs: { pname = "mystmd"; - version = "1.3.18"; + version = "1.8.3"; + + strictDeps = true; + __structuredAttrs = true; src = fetchFromGitHub { owner = "jupyter-book"; repo = "mystmd"; - rev = "mystmd@${version}"; - hash = "sha256-20Cxs4ib7xRn4UC9ShiQ+KnyrTCmW/vII7QN9BObY78="; + tag = "mystmd@${finalAttrs.version}"; + hash = "sha256-OmREjNDgmq5+nidBZh4DUy9bMtDeHMrGWZEqKo5TUrQ="; }; - npmDepsHash = "sha256-dcjOxEYTG/EnBRu+RE7cpSEvNmG32QsDDYzItaNTpa0="; + node_modules = stdenv.mkDerivation { + inherit (finalAttrs) src version; + pname = "${finalAttrs.pname}-node_modules"; - dontNpmInstall = true; + nativeBuildInputs = [ + bun + nodejs + writableTmpDirAsHomeHook + ]; + + dontConfigure = true; + dontFixup = true; + + buildPhase = '' + runHook preBuild + export BUN_INSTALL_CACHE_DIR=$(mktemp -d) + bun install --no-progress --frozen-lockfile --no-cache + + runHook postBuild + ''; + + installPhase = '' + runHook preInstall + + mkdir -p $out/node_modules + cp -R ./node_modules $out + + runHook postInstall + ''; + + outputHash = + { + x86_64-linux = "sha256-4EQkvsoji9M4VCrdwyHm+ncd4XFjgAf34Kt+YeM3qjs="; + aarch64-linux = "sha256-xm4T1BL3AyRsYOERz4LhG4ZJQkSMzspoA+l60OND3E0="; + x86_64-darwin = "sha256-L+zY9O5ridMvZEhGH0R56P3XiDlYF3UrFZwmOYlqxYY="; + aarch64-darwin = "sha256-ZUx+jF7IcEbUCnUUeW0uOFgEpO9UIJpP3/VpUJ5ulAM="; + } + .${stdenv.hostPlatform.system} or (throw "unsupported system ${stdenv.hostPlatform.system}"); + + outputHashAlgo = "sha256"; + outputHashMode = "recursive"; + }; + + nativeBuildInputs = [ + bun + nodejs + ]; + + buildInputs = [ + nodejs + ]; + + buildPhase = '' + runHook preBuild + + cp -R ${finalAttrs.node_modules}/node_modules . + patchShebangs node_modules + bun run build + + runHook postBuild + ''; installPhase = '' runHook preInstall + mkdir -p $out/lib + cp -r node_modules $out/lib/ + cp -r packages $out/lib/ install -D packages/mystmd/dist/myst.cjs $out/bin/myst runHook postInstall @@ -32,8 +98,8 @@ buildNpmPackage rec { passthru = { tests.version = testers.testVersion { - package = mystmd; - version = "v${version}"; + package = finalAttrs.finalPackage; + version = "v${finalAttrs.version}"; }; updateScript = nix-update-script { }; }; @@ -41,9 +107,9 @@ buildNpmPackage rec { meta = { description = "Command line tools for working with MyST Markdown"; homepage = "https://github.com/jupyter-book/mystmd"; - changelog = "https://github.com/jupyter-book/mystmd/blob/${src.rev}/packages/myst-cli/CHANGELOG.md"; + changelog = "https://github.com/jupyter-book/mystmd/blob/${finalAttrs.src.rev}/packages/myst-cli/CHANGELOG.md"; license = lib.licenses.mit; - maintainers = [ ]; + maintainers = with lib.maintainers; [ tbutter ]; mainProgram = "myst"; }; -} +}) From 2e733c9abfe237a75b15b38c23042e322918dcd5 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Sun, 3 May 2026 15:19:24 +0200 Subject: [PATCH 68/71] vaultwarden: 1.35.8 -> 1.36.0 https://github.com/dani-garcia/vaultwarden/releases/tag/1.36.0 Fixes: - GHSA-pfp2-jhgq-6hg5 - GHSA-w6h6-8r66-hcv7 - GHSA-hxqh-ff5p-wfr3 - GHSA-j4j8-gpvj-7fqr - GHSA-6x5c-84vm-5j56 - GHSA-72vh-x5jq-m82g --- pkgs/by-name/va/vaultwarden/package.nix | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) diff --git a/pkgs/by-name/va/vaultwarden/package.nix b/pkgs/by-name/va/vaultwarden/package.nix index 2e27f7c11164..7d46003d9eed 100644 --- a/pkgs/by-name/va/vaultwarden/package.nix +++ b/pkgs/by-name/va/vaultwarden/package.nix @@ -8,9 +8,10 @@ pkg-config, openssl, libiconv, - dbBackend ? "sqlite", + dbBackend ? "sqlite_system", libmysqlclient, libpq, + sqlite, }: let @@ -19,16 +20,16 @@ in rustPlatform.buildRustPackage (finalAttrs: { pname = "vaultwarden"; - version = "1.35.8"; + version = "1.36.0"; src = fetchFromGitHub { owner = "dani-garcia"; repo = "vaultwarden"; tag = finalAttrs.version; - hash = "sha256-bEPwH0+b4cQTh1hNiiX2qvTNeRxxShm2JXNKNfn4xm8="; + hash = "sha256-jc2f7Ia2c+U1cQBXmyzfQAgFMFoAPexLejs6/FKaN9I="; }; - cargoHash = "sha256-gcE3qfSVCk08haADyqOff4R0ekd9Q6RB59LUtow9Yi4="; + cargoHash = "sha256-sjWBM9SsI/7AQ8SuFiTR19l8kqp3rhy64Uh/1TatH6A="; # used for "Server Installed" version in admin panel env.VW_VERSION = finalAttrs.version; @@ -41,7 +42,8 @@ rustPlatform.buildRustPackage (finalAttrs: { libiconv ] ++ lib.optional (dbBackend == "mysql") libmysqlclient - ++ lib.optional (dbBackend == "postgresql") libpq; + ++ lib.optional (dbBackend == "postgresql") libpq + ++ lib.optional (dbBackend == "sqlite_system") sqlite; buildFeatures = dbBackend; From 9711ace54523b15f791c4d60c6a4ae4981688088 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sandro=20J=C3=A4ckel?= Date: Sun, 3 May 2026 16:56:34 +0200 Subject: [PATCH 69/71] vaultwarden.webvault: 2026.3.1+0 -> 2026.4.1+0 --- pkgs/by-name/va/vaultwarden/webvault.nix | 15 ++++++++++++--- 1 file changed, 12 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/va/vaultwarden/webvault.nix b/pkgs/by-name/va/vaultwarden/webvault.nix index 208efdd0f7c1..61bb7542da8e 100644 --- a/pkgs/by-name/va/vaultwarden/webvault.nix +++ b/pkgs/by-name/va/vaultwarden/webvault.nix @@ -10,16 +10,25 @@ buildNpmPackage rec { pname = "vaultwarden-webvault"; - version = "2026.3.1+0"; + version = "2026.4.1+0"; src = fetchFromGitHub { owner = "vaultwarden"; repo = "vw_web_builds"; tag = "v${version}"; - hash = "sha256-nUhSoqf655eOs+rKqAZB0XzPD6ePL6CIxVAnB5dmJAs="; + hash = "sha256-CIKhdCQwx1zS8rkOtZoG9WDxtweSmrCNL6HfZXi+mM8="; }; - npmDepsHash = "sha256-dlYN2aiv6XbDXQVstfI6XIe+X5Q1lqs62eNalGTGx7k="; + # Upstream lockfile is out of sync for @napi-rs/cli (spec 3.5.1, resolved + # 3.2.0), which makes offline `npm ci` hit the registry. The desktop + # workspace is unused here. https://github.com/bitwarden/clients/pull/20480 + postPatch = '' + substituteInPlace package-lock.json \ + --replace-fail '"@napi-rs/cli": "3.5.1"' '"@napi-rs/cli": "3.2.0"' + ''; + + npmDepsFetcherVersion = 2; + npmDepsHash = "sha256-NBhII5HySIkv0bCeWjH6MknX5NMp11Gwno7RnfCKgjc="; nativeBuildInputs = [ python3 From cd2e5a371bce6f240cec8b9a156a923b454014fd Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Sun, 3 May 2026 13:21:39 -0400 Subject: [PATCH 70/71] Revert "{ci,workflows}: allow multiple blocking reviews" --- .github/workflows/check.yml | 37 +----- .github/workflows/eval.yml | 14 --- .github/workflows/pull-request-target.yml | 22 ---- ci/github-script/check-target-branch.js | 10 +- ci/github-script/manual-file-edits.js | 26 +---- ci/github-script/prepare.js | 16 +-- ci/github-script/reviews.js | 130 +++++++--------------- 7 files changed, 63 insertions(+), 192 deletions(-) diff --git a/.github/workflows/check.yml b/.github/workflows/check.yml index 99e83c2c151f..fa16aec65997 100644 --- a/.github/workflows/check.yml +++ b/.github/workflows/check.yml @@ -16,14 +16,6 @@ on: required: true type: string secrets: - # Can be provided in pull requests because the job it is used in does - # not evaluate untrusted code. - NIXPKGS_COMMIT_CHECK_APP_PRIVATE_KEY: - required: false - # Can be provided in pull requests because the job it is used in does - # not evaluate untrusted code. - NIXPKGS_MANUAL_EDIT_CHECK_APP_PRIVATE_KEY: - required: false # Should only be provided in the merge queue, not in pull requests, # where we're evaluating untrusted code. CACHIX_AUTH_TOKEN_GHA: @@ -53,19 +45,9 @@ jobs: - name: Install dependencies run: npm install bottleneck@2.19.5 - # It's fine to reuse this app in the 'pull-request-target / prepare' job, - # because that job has to run before this one. - - uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1 - if: github.event_name != 'pull_request' && vars.NIXPKGS_COMMIT_CHECK_CLIENT_ID - id: app-token - with: - client-id: ${{ vars.NIXPKGS_COMMIT_CHECK_CLIENT_ID }} - private-key: ${{ secrets.NIXPKGS_COMMIT_CHECK_APP_PRIVATE_KEY }} - permission-pull-requests: write - - name: Log current API rate limits env: - GH_TOKEN: ${{ steps.app-token.outputs.token || github.token }} + GH_TOKEN: ${{ github.token }} run: gh api /rate_limit | jq - name: Check commits @@ -74,7 +56,6 @@ jobs: env: TARGETS_STABLE: ${{ fromJSON(inputs.baseBranch).stable && !contains(fromJSON(inputs.headBranch).type, 'development') }} with: - github-token: ${{ steps.app-token.outputs.token || github.token }} script: | const targetsStable = JSON.parse(process.env.TARGETS_STABLE) require('./trusted/ci/github-script/commits.js')({ @@ -87,7 +68,7 @@ jobs: - name: Log current API rate limits env: - GH_TOKEN: ${{ steps.app-token.outputs.token || github.token }} + GH_TOKEN: ${{ github.token }} run: gh api /rate_limit | jq manual-file-edits: @@ -104,35 +85,25 @@ jobs: sparse-checkout: | ci/github-script - - uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1 - if: github.event_name != 'pull_request' && vars.NIXPKGS_MANUAL_EDIT_CHECK_CLIENT_ID - id: app-token - with: - client-id: ${{ vars.NIXPKGS_MANUAL_EDIT_CHECK_CLIENT_ID }} - private-key: ${{ secrets.NIXPKGS_MANUAL_EDIT_CHECK_APP_PRIVATE_KEY }} - permission-pull-requests: write - - name: Log current API rate limits env: - GH_TOKEN: ${{ steps.app-token.outputs.token || github.token }} + GH_TOKEN: ${{ github.token }} run: gh api /rate_limit | jq - name: Discourage manual edits to certain files uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 with: - github-token: ${{ steps.app-token.outputs.token || github.token }} script: | require('./trusted/ci/github-script/manual-file-edits.js')({ github, context, core, - dry: context.eventName == 'pull_request', repoPath: 'trusted', }) - name: Log current API rate limits env: - GH_TOKEN: ${{ steps.app-token.outputs.token || github.token }} + GH_TOKEN: ${{ github.token }} run: gh api /rate_limit | jq owners: diff --git a/.github/workflows/eval.yml b/.github/workflows/eval.yml index a8dcaf29456f..4939fa5ec329 100644 --- a/.github/workflows/eval.yml +++ b/.github/workflows/eval.yml @@ -23,10 +23,6 @@ on: default: false type: boolean secrets: - # Can be provided in pull requests because the job it is used in does - # not evaluate untrusted code. - NIXPKGS_BRANCH_CHECK_APP_PRIVATE_KEY: - required: false # Should only be provided in the merge queue, not in pull requests, # where we're evaluating untrusted code. CACHIX_AUTH_TOKEN_GHA: @@ -353,20 +349,10 @@ jobs: description, target_url }) - - - uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1 - if: github.event_name == 'pull_request_target' && vars.NIXPKGS_BRANCH_CHECK_CLIENT_ID - id: app-token - with: - client-id: ${{ vars.NIXPKGS_BRANCH_CHECK_CLIENT_ID }} - private-key: ${{ secrets.NIXPKGS_BRANCH_CHECK_APP_PRIVATE_KEY }} - permission-pull-requests: write - - name: Request changes if PR is against an inappropriate branch if: ${{ github.event_name == 'pull_request_target' }} uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 with: - github-token: ${{ steps.app-token.outputs.token || github.token }} script: | require('./nixpkgs/trusted/ci/github-script/check-target-branch.js')({ github, diff --git a/.github/workflows/pull-request-target.yml b/.github/workflows/pull-request-target.yml index 02d07344eee8..190ce2510a3e 100644 --- a/.github/workflows/pull-request-target.yml +++ b/.github/workflows/pull-request-target.yml @@ -10,12 +10,6 @@ on: secrets: NIXPKGS_CI_APP_PRIVATE_KEY: required: true - NIXPKGS_BRANCH_CHECK_APP_PRIVATE_KEY: - required: false - NIXPKGS_COMMIT_CHECK_APP_PRIVATE_KEY: - required: false - NIXPKGS_MANUAL_EDIT_CHECK_APP_PRIVATE_KEY: - required: false concurrency: group: pr-${{ github.workflow }}-${{ github.event_name }}-${{ github.event.pull_request.number || github.run_id }} @@ -42,17 +36,6 @@ jobs: sparse-checkout-cone-mode: true # default, for clarity sparse-checkout: | ci/github-script - - # It's fine to reuse this app in the 'check / commits' job, - # because this job has to run before that one. - - uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1 - if: vars.NIXPKGS_COMMIT_CHECK_CLIENT_ID - id: app-token - with: - client-id: ${{ vars.NIXPKGS_COMMIT_CHECK_CLIENT_ID }} - private-key: ${{ secrets.NIXPKGS_COMMIT_CHECK_APP_PRIVATE_KEY }} - permission-pull-requests: write - - id: prepare uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 with: @@ -77,9 +60,6 @@ jobs: permissions: # cherry-picks pull-requests: write - secrets: - NIXPKGS_COMMIT_CHECK_APP_PRIVATE_KEY: ${{ secrets.NIXPKGS_COMMIT_CHECK_APP_PRIVATE_KEY }} - NIXPKGS_MANUAL_EDIT_CHECK_APP_PRIVATE_KEY: ${{ secrets.NIXPKGS_MANUAL_EDIT_CHECK_APP_PRIVATE_KEY }} with: baseBranch: ${{ needs.prepare.outputs.baseBranch }} headBranch: ${{ needs.prepare.outputs.headBranch }} @@ -102,8 +82,6 @@ jobs: # compare pull-requests: write statuses: write - secrets: - NIXPKGS_BRANCH_CHECK_APP_PRIVATE_KEY: ${{ secrets.NIXPKGS_BRANCH_CHECK_APP_PRIVATE_KEY }} with: artifact-prefix: ${{ inputs.artifact-prefix }} mergedSha: ${{ needs.prepare.outputs.mergedSha }} diff --git a/ci/github-script/check-target-branch.js b/ci/github-script/check-target-branch.js index a31520c02fc6..9b47a946b889 100644 --- a/ci/github-script/check-target-branch.js +++ b/ci/github-script/check-target-branch.js @@ -151,9 +151,11 @@ async function checkTargetBranch({ github, context, core, dry }) { core, dry, body, - event: 'REQUEST_CHANGES', + event: 'COMMENT', reviewKey, }) + + throw new Error('This PR is against the wrong branch.') } else if (rebuildsAllTests && !isExemptKernelUpdate) { let branchText if (base === 'master' && maxRebuildCount >= 500) { @@ -177,9 +179,11 @@ async function checkTargetBranch({ github, context, core, dry }) { core, dry, body, - event: 'REQUEST_CHANGES', + event: 'COMMENT', reviewKey, }) + + throw new Error('This PR is against the wrong branch.') } else if ( maxRebuildCount >= 500 && !isExemptKernelUpdate && @@ -200,7 +204,7 @@ async function checkTargetBranch({ github, context, core, dry }) { core, dry, body, - event: 'REQUEST_CHANGES', + event: 'COMMENT', reviewKey, }) } else { diff --git a/ci/github-script/manual-file-edits.js b/ci/github-script/manual-file-edits.js index 84235d44752c..e40d6decbb7d 100644 --- a/ci/github-script/manual-file-edits.js +++ b/ci/github-script/manual-file-edits.js @@ -7,13 +7,9 @@ const { getCommitDetailsForPR } = require('./get-pr-commit-details') * context: import('@actions/github/lib/context').Context, * core: import('@actions/core'), * repoPath?: string, - * dry: boolean, * }} CheckManualFileEditsProps */ -async function checkManualFileEdits({ github, context, core, repoPath, dry }) { - const { dismissReviews, postReview } = require('./reviews.js') - const reviewKey = 'manual-file-edits' - +async function checkManualFileEdits({ github, context, core, repoPath }) { const pull_number = context.payload.pull_request?.number if (!pull_number) { core.info('This is not a pull request. Skipping checks.') @@ -39,13 +35,8 @@ async function checkManualFileEdits({ github, context, core, repoPath, dry }) { changedPaths.includes('maintainers/github-teams.json'), ) ) { - postReview({ - github, - context, - core, - dry, - event: 'REQUEST_CHANGES', - body: [ + core.setFailed( + [ 'maintainers/github-teams.json is supposed to accurately reflect the state of the teams in GitHub.\n', 'Therefore, it should not be edited manually.\n', 'All changes to teams listed in maintainers/github-teams.json should be performed in GitHub by a team maintainer.\n', @@ -57,16 +48,7 @@ async function checkManualFileEdits({ github, context, core, repoPath, dry }) { (prev, curr) => prev + (!prev || prev.endsWith('\n') ? '' : ' ') + curr, '', ), - reviewKey, - }) - } else { - dismissReviews({ - github, - context, - core, - dry, - reviewKey, - }) + ) } } diff --git a/ci/github-script/prepare.js b/ci/github-script/prepare.js index d4d69eb71692..dfe2d93f3d69 100644 --- a/ci/github-script/prepare.js +++ b/ci/github-script/prepare.js @@ -172,20 +172,14 @@ module.exports = async ({ github, context, core, dry }) => { ' ```', ].join('\n') - await postReview({ - github, - context, - core, - dry, - body, - event: 'REQUEST_CHANGES', - reviewKey, - }) + await postReview({ github, context, core, dry, body, reviewKey }) + + throw new Error(`The PR contains commits from a different base.`) } - } else { - await dismissReviews({ github, context, core, dry, reviewKey }) } + await dismissReviews({ github, context, core, dry, reviewKey }) + let mergedSha, targetSha if (prInfo.mergeable) { diff --git a/ci/github-script/reviews.js b/ci/github-script/reviews.js index 80e250cfa7c3..7041fdae1f10 100644 --- a/ci/github-script/reviews.js +++ b/ci/github-script/reviews.js @@ -5,28 +5,10 @@ const eventToState = { REQUEST_CHANGES: 'CHANGES_REQUESTED', } -// Use substring checks in order to allow testing in forks -// Usernames must also end in "[bot]" -const reviewUsers = [ - 'github-actions', - 'nixpkgs-ci', - 'branch-check', - 'commit-check', - 'manual-edit', -] - -/** - * @typedef {InstanceType} GitHub - * @typedef {typeof import('@actions/github').context} Context - * - * @typedef {Awaited>['data'][number]} Review - * @typedef {Review & { user: NonNullable }} ReviewWithNonNullUser - */ - /** * @param {{ - * github: GitHub, - * context: Context, + * github: InstanceType, + * context: import('@actions/github/lib/context').Context, * core: import('@actions/core'), * dry: boolean, * reviewKey?: string, @@ -43,32 +25,18 @@ async function dismissReviews({ github, context, core, dry, reviewKey }) { return } - const allReviews = await github.paginate(github.rest.pulls.listReviews, { - ...context.repo, - pull_number, - }) - - const reviews = /** @type {ReviewWithNonNullUser[]} */ ( - allReviews.filter( - (review) => - review.user && - review.state !== 'DISMISSED' && - review.user.login.endsWith('[bot]') && - reviewUsers.some((substr) => review.user?.login.includes(substr)), - ) + const reviews = ( + await github.paginate(github.rest.pulls.listReviews, { + ...context.repo, + pull_number, + }) + ).filter( + (review) => + review.user?.login === 'github-actions[bot]' && + review.state !== 'DISMISSED', ) - - const reviewsByUser = reviews.reduce( - (prev, curr) => { - if (!(curr.user.login in prev)) { - prev[curr.user.login] = [] - } - - prev[curr.user.login].push(curr) - - return prev - }, - /** @type {Record } */ ({}), + const changesRequestedReviews = reviews.filter( + (review) => review.state === 'CHANGES_REQUESTED', ) const commentRegex = new RegExp( @@ -82,8 +50,8 @@ async function dismissReviews({ github, context, core, dry, reviewKey }) { ) let reviewsToMinimize = reviews - const /** @type {ReviewWithNonNullUser[]} */ reviewsToDismiss = [] - const /** @type {ReviewWithNonNullUser[]} */ reviewsToResolve = [] + let /** @type {typeof reviews} */ reviewsToDismiss = [] + let /** @type {typeof reviews} */ reviewsToResolve = [] if (reviewKey && reviews.every((review) => commentRegex.test(review.body))) { reviewsToMinimize = reviews.filter((review) => @@ -91,39 +59,29 @@ async function dismissReviews({ github, context, core, dry, reviewKey }) { ) } - for (const reviewsForUser of Object.values(reviewsByUser)) { - // Make sure that we don't dismiss all reviews by a user if they - // have any reviews we don't want to dismiss. - if ( - reviewsForUser.every( - (review) => - commentResolvedRegex.test(review.body) || - (reviewKey && reviewKeyRegex.test(review.body)) || - // If we are called by check-commits and the review body is clearly - // from `commits.js`, then we can safely dismiss the review. - // This helps with pre-existing reviews (before the comments were added). - (reviewKey && - reviewKey === 'check-commits' && - review.body.includes('PR / Check / cherry-pick')), - ) - ) { - reviewsToDismiss.push( - ...reviewsForUser.filter( - (review) => review.state === 'CHANGES_REQUESTED', - ), - ) - } else { - reviewsToResolve.push( - ...reviewsForUser.filter( - (review) => - review.state === 'CHANGES_REQUESTED' && - !commentResolvedRegex.test(review.body) && - reviewsToMinimize.some( - (toMinimize) => toMinimize.node_id === review.node_id, - ), - ), - ) - } + // If we want to dismiss all reviews with the key reviewKey, + // but there are other requested changes from CI, we can't dismiss, + // because then the other requested changes will be dismissed too. + if ( + changesRequestedReviews.every( + (review) => + commentResolvedRegex.test(review.body) || + (reviewKey && reviewKeyRegex.test(review.body)) || + // If we are called by check-commits and the review body is clearly + // from `commits.js`, then we can safely dismiss the review. + // This helps with pre-existing reviews (before the comments were added). + (reviewKey && + reviewKey === 'check-commits' && + review.body.includes('PR / Check / cherry-pick')), + ) + ) { + reviewsToDismiss = changesRequestedReviews + } else if (reviewsToMinimize.length) { + reviewsToResolve = reviewsToMinimize.filter( + (review) => + review.state === 'CHANGES_REQUESTED' && + !commentResolvedRegex.test(review.body), + ) } await Promise.all([ @@ -163,8 +121,8 @@ async function dismissReviews({ github, context, core, dry, reviewKey }) { /** * @param {{ - * github: GitHub, - * context: Context, + * github: InstanceType, + * context: import('@actions/github/lib/context').Context * core: import('@actions/core'), * dry: boolean, * body: string, @@ -200,13 +158,11 @@ async function postReview({ }) ).filter( (review) => - review.user && - review.state !== 'DISMISSED' && - review.user.login.endsWith('[bot]') && - reviewUsers.some((substr) => review.user?.login.includes(substr)), + review.user?.login === 'github-actions[bot]' && + review.state !== 'DISMISSED', ) - /** @type {null | Review} */ + /** @type {null | typeof reviews[number]} */ let pendingReview const matchingReviews = reviews.filter((review) => reviewKeyRegex.test(review.body), From 352de38344eaf7ea89599222fc255e2138121c0c Mon Sep 17 00:00:00 2001 From: Pol Dellaiera Date: Sun, 3 May 2026 19:36:00 +0200 Subject: [PATCH 71/71] nixfmt-rs: 0.2.0 -> 0.3.0 Diff: https://github.com/Mic92/nixfmt-rs/compare/0.2.0...0.3.0 Changelog: https://github.com/Mic92/nixfmt-rs/releases/tag/0.3.0 --- pkgs/by-name/ni/nixfmt-rs/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ni/nixfmt-rs/package.nix b/pkgs/by-name/ni/nixfmt-rs/package.nix index abd00f80a874..abfdb282e14a 100644 --- a/pkgs/by-name/ni/nixfmt-rs/package.nix +++ b/pkgs/by-name/ni/nixfmt-rs/package.nix @@ -12,7 +12,7 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "nixfmt-rs"; - version = "0.2.0"; + version = "0.3.0"; __structuredAttrs = true; strictDeps = true; @@ -21,10 +21,10 @@ rustPlatform.buildRustPackage (finalAttrs: { owner = "Mic92"; repo = "nixfmt-rs"; tag = finalAttrs.version; - hash = "sha256-eBVi22+EGMYWv2t/seoPqou8PuABxVcsWTFcrNYP6So="; + hash = "sha256-H4APJn0NGaD2LrkjcJ7io+fu3aKoO0Cn2BJk731YlqQ="; }; - cargoHash = "sha256-fadjOtfB8bFuhTN9mAmi2A526boW7Aje39IBjdxszok="; + cargoHash = "sha256-gJq6PxA6WaWObHnIL7jsKQBOSHQj31kzlrM95OY27ro="; nativeBuildInputs = [ installShellFiles