diff --git a/lib/default.nix b/lib/default.nix index 751738a98965..56baba8708c5 100644 --- a/lib/default.nix +++ b/lib/default.nix @@ -89,6 +89,14 @@ let # domain-specific fetchers = callLibs ./fetchers.nix; + services = callLibs ./services/lib.nix; + importService = self.modules.importApply ./services/service.nix; + + # Modules that are not specific to a module class + genericModules = { + meta-maintainers = ./modules/generic/meta-maintainers.nix; + assertions = ./modules/generic/assertions.nix; + }; # Eval-time filesystem handling path = callLibs ./path; diff --git a/lib/modules/generic/assertions.nix b/lib/modules/generic/assertions.nix new file mode 100644 index 000000000000..2f455d51cbc1 --- /dev/null +++ b/lib/modules/generic/assertions.nix @@ -0,0 +1,39 @@ +{ lib, ... }: +{ + _class = null; # not specific to NixOS + + options = { + + assertions = lib.mkOption { + type = lib.types.listOf lib.types.unspecified; + internal = true; + default = [ ]; + example = [ + { + assertion = false; + message = "you can't enable this for that reason"; + } + ]; + description = '' + This option allows modules to express conditions that must + hold for the evaluation of the system configuration to + succeed, along with associated error messages for the user. + ''; + }; + + warnings = lib.mkOption { + internal = true; + default = [ ]; + type = lib.types.listOf lib.types.str; + example = [ "The `foo' service is deprecated and will go away soon!" ]; + description = '' + This option allows modules to show warnings to users during + the evaluation of the system configuration. + ''; + }; + + }; + # impl of assertions is in + # - + # - +} diff --git a/lib/modules/generic/meta-maintainers.nix b/lib/modules/generic/meta-maintainers.nix new file mode 100644 index 000000000000..4c8e0bf5fb5b --- /dev/null +++ b/lib/modules/generic/meta-maintainers.nix @@ -0,0 +1,59 @@ +# Test: +# ../../../modules/generic/meta-maintainers/test.nix +{ lib, ... }: +let + inherit (lib) + mkOption + types + ; + + # The resulting value of this type shows where all values were defined + sourceList = types.listOf types.raw // { + merge = loc: defs: lib.listToAttrs (lib.map ({ file, value }: lib.nameValuePair file value) defs); + }; +in +{ + _class = null; # not specific to NixOS + options = { + meta = { + maintainers = mkOption { + type = + let + allMaintainers = lib.attrValues lib.maintainers; + in + lib.types.addCheck sourceList (lib.all (v: lib.elem v allMaintainers)) + // { + description = "list of lib.maintainers"; + }; + default = [ ]; + example = lib.literalExpression "[ lib.maintainers.alice lib.maintainers.bob ]"; + description = '' + List of maintainers of each module. + This option should be defined at most once per module. + + The option value is not a list of maintainers, but an attribute set that maps module file names to lists of maintainers. + ''; + }; + teams = mkOption { + type = + let + allTeams = lib.attrValues lib.teams; + in + lib.types.addCheck sourceList (lib.all (v: lib.elem v allTeams)) + // { + description = "list of lib.teams"; + }; + default = [ ]; + example = lib.literalExpression "[ lib.teams.acme lib.teams.haskell ]"; + description = '' + List of team maintainers of each module. + This option should be defined at most once per module. + ''; + }; + }; + }; + meta.maintainers = with lib.maintainers; [ + pierron + roberth + ]; +} diff --git a/lib/services/lib.nix b/lib/services/lib.nix index 02587b6bc810..7c235e066802 100644 --- a/lib/services/lib.nix +++ b/lib/services/lib.nix @@ -50,10 +50,10 @@ rec { # darwin/modules/services/system.nix { lib, config, pkgs, ... }: let - portable-lib = import { inherit lib; }; - - modularServiceConfiguration = portable-lib.configure { + modularServiceConfiguration = lib.services.configure { serviceManagerPkgs = pkgs; + # To load a different portable service base, set `baseModules` instead: + # baseModules = [ (lib.importService { inherit pkgs; }) ]; extraRootModules = [ ./launchd-service.nix # launchd-specific options (plist generation, etc.) ]; @@ -82,18 +82,27 @@ rec { `serviceManagerPkgs` : 1\. A Nixpkgs instance used for built-in logic such as converting - `configData..text` to a store path. + `configData..text` to a store path. Required unless `baseModules` + is set. + + `baseModules` + + : 2\. Modules that replace the portable service base. They are loaded + into the "root" service submodule and must handle propagation to + sub-`services` themselves. Defaults to the portable service base of + this Nixpkgs. Set it to supply a different one, for example a + `service.nix` pinned from another Nixpkgs. `extraRootModules` - : 2\. Modules to be loaded into the "root" service submodule, but not + : 3\. Modules to be loaded into the "root" service submodule, but not into its sub-`services`. That's the modules' own responsibility. Typically contains service-manager-specific option modules (e.g. systemd unit options, launchd plist options). `extraRootSpecialArgs` - : 3\. Fixed module arguments provided alongside `extraRootModules`. + : 4\. Fixed module arguments provided alongside `extraRootModules`. # Output @@ -103,17 +112,15 @@ rec { */ configure = { - serviceManagerPkgs, + serviceManagerPkgs ? throw "lib.services.configure: `serviceManagerPkgs` is required unless `baseModules` is set", + baseModules ? [ (lib.importService { pkgs = serviceManagerPkgs; }) ], extraRootModules ? [ ], extraRootSpecialArgs ? { }, }: let - modules = [ - (lib.modules.importApply ./service.nix { pkgs = serviceManagerPkgs; }) - ]; serviceSubmodule = types.submoduleWith { class = "service"; - modules = modules ++ extraRootModules; + modules = baseModules ++ extraRootModules; specialArgs = extraRootSpecialArgs; }; in diff --git a/lib/services/service.nix b/lib/services/service.nix index 20d74e1793b2..b344075e4c33 100644 --- a/lib/services/service.nix +++ b/lib/services/service.nix @@ -42,8 +42,8 @@ in # https://nixos.org/manual/nixos/unstable/#modular-services _class = "service"; imports = [ - ../../modules/generic/meta-maintainers.nix - ../../nixos/modules/misc/assertions.nix + ../modules/generic/meta-maintainers.nix + ../modules/generic/assertions.nix (lib.modules.importApply ./config-data.nix { inherit pkgs; }) ]; options = { diff --git a/lib/services/test.nix b/lib/services/test.nix index 0b08026c335d..624e34ff855e 100644 --- a/lib/services/test.nix +++ b/lib/services/test.nix @@ -5,13 +5,7 @@ let inherit (lib) mkOption types; - portable-lib = import ./lib.nix { inherit lib; }; - - configured = portable-lib.configure { - serviceManagerPkgs = throw "do not use pkgs in this test"; - extraRootModules = [ ]; - extraRootSpecialArgs = { }; - }; + portable-lib = lib.services; dummyPkg = name: @@ -21,6 +15,17 @@ let builder = "/bin/false"; }; + configured = portable-lib.configure { + # `coreutils` is the only package the portable layer legitimately needs, to derive + # `process.reloadCommand` from `process.reloadSignal`. Anything else reaching for + # `pkgs` fails on the missing attribute. + serviceManagerPkgs = { + coreutils = dummyPkg "coreutils"; + }; + extraRootModules = [ ]; + extraRootSpecialArgs = { }; + }; + exampleConfig = { services = { service1 = { @@ -48,6 +53,7 @@ let (dummyPkg "cowsay.sh") "world" ]; + reloadCommand = "${dummyPkg "cowsay.sh"} reload"; }; }; service3 = { @@ -65,6 +71,7 @@ let )) "!" ]; + reloadSignal = "HUP"; }; assertions = [ { @@ -148,13 +155,15 @@ let # Every service carries some assertions that hold; only the violated ones are of interest here. failures = lib.filter (a: !a.assertion); + # The goal of this test is to perform and check a complete evaluation of all options. + # Only filter out values that are truly infeasible to check, such as function values. filterEval = config: lib.optionalAttrs (config ? process) { inherit (config) warnings; assertions = failures config.assertions; - # Only `argv` is relevant here; `process` also carries the reload options. - process = { inherit (config.process) argv; }; + # `flagFormat` is a function and cannot be compared; the rest of `process` is checked. + process = { inherit (config.process) argv reloadCommand reloadSignal; }; } // { services = lib.mapAttrs (k: filterEval) config.services; @@ -170,6 +179,8 @@ let "/usr/bin/echo" "hello" ]; + reloadCommand = null; + reloadSignal = null; }; services = { }; assertions = [ @@ -188,6 +199,8 @@ let "${dummyPkg "cowsay.sh"}" "world" ]; + reloadCommand = "${dummyPkg "cowsay.sh"} reload"; + reloadSignal = null; }; services = { }; assertions = [ ]; @@ -196,6 +209,8 @@ let service3 = { process = { argv = [ "/bin/false" ]; + reloadCommand = null; + reloadSignal = null; }; services.exclacow = { process = { @@ -203,6 +218,8 @@ let "${dummyPkg "cowsay-ng"}/bin/cowsay" "!" ]; + reloadCommand = "${dummyPkg "coreutils"}/bin/kill -HUP $MAINPID"; + reloadSignal = "HUP"; }; services = { }; assertions = [ @@ -228,6 +245,8 @@ let "--name" "example" ]; + reloadCommand = null; + reloadSignal = null; }; services = { }; assertions = [ ]; @@ -241,6 +260,8 @@ let "--quiet=false" "--verbose=true" ]; + reloadCommand = null; + reloadSignal = null; }; services = { }; assertions = [ ]; @@ -255,6 +276,8 @@ let "--host" "b" ]; + reloadCommand = null; + reloadSignal = null; }; services = { }; assertions = [ ]; @@ -270,6 +293,8 @@ let "a" "TRAILING" ]; + reloadCommand = null; + reloadSignal = null; }; services = { }; assertions = [ ]; diff --git a/maintainers/maintainer-list.nix b/maintainers/maintainer-list.nix index c1fa2d95c8c0..f4fa72e205a9 100644 --- a/maintainers/maintainer-list.nix +++ b/maintainers/maintainer-list.nix @@ -15939,6 +15939,13 @@ github = "langsjo"; githubId = 104687438; }; + larry0x = { + name = "Larry Engineer"; + email = "nixpkgs@larry.engineer"; + github = "larry0x"; + githubId = 26318510; + keys = [ { fingerprint = "BF1C 46E2 93BB 3CC3 7155 56ED 5E02 19E0 2D70 E4E2"; } ]; + }; larsr = { email = "Lars.Rasmusson@gmail.com"; github = "larsr"; @@ -19281,6 +19288,11 @@ githubId = 85857; name = "Martin Milata"; }; + mmkamron = { + name = "Kamron Mirsamatov"; + github = "mmkamron"; + githubId = 30682234; + }; mmkaram = { name = "Mahdy Karam"; github = "mmkaram"; diff --git a/modules/generic/meta-maintainers.nix b/modules/generic/meta-maintainers.nix index ce37dae03db6..0c99929eea1a 100644 --- a/modules/generic/meta-maintainers.nix +++ b/modules/generic/meta-maintainers.nix @@ -1,59 +1,7 @@ # Test: # ./meta-maintainers/test.nix -{ lib, ... }: -let - inherit (lib) - mkOption - types - ; - - # The resulting value of this type shows where all values were defined - sourceList = types.listOf types.raw // { - merge = loc: defs: lib.listToAttrs (lib.map ({ file, value }: lib.nameValuePair file value) defs); - }; -in { - _class = null; # not specific to NixOS - options = { - meta = { - maintainers = mkOption { - type = - let - allMaintainers = lib.attrValues lib.maintainers; - in - lib.types.addCheck sourceList (lib.all (v: lib.elem v allMaintainers)) - // { - description = "list of lib.maintainers"; - }; - default = [ ]; - example = lib.literalExpression "[ lib.maintainers.alice lib.maintainers.bob ]"; - description = '' - List of maintainers of each module. - This option should be defined at most once per module. - - The option value is not a list of maintainers, but an attribute set that maps module file names to lists of maintainers. - ''; - }; - teams = mkOption { - type = - let - allTeams = lib.attrValues lib.teams; - in - lib.types.addCheck sourceList (lib.all (v: lib.elem v allTeams)) - // { - description = "list of lib.teams"; - }; - default = [ ]; - example = lib.literalExpression "[ lib.teams.acme lib.teams.haskell ]"; - description = '' - List of team maintainers of each module. - This option should be defined at most once per module. - ''; - }; - }; - }; - meta.maintainers = with lib.maintainers; [ - pierron - roberth - ]; + # Not `lib.genericModules.meta-maintainers`: the `lib` module argument may come + # from a different Nixpkgs version than this file. + imports = [ ../../lib/modules/generic/meta-maintainers.nix ]; } diff --git a/modules/generic/meta-maintainers/test.nix b/modules/generic/meta-maintainers/test.nix index a9859a6ee2dc..aff61454f4c6 100644 --- a/modules/generic/meta-maintainers/test.nix +++ b/modules/generic/meta-maintainers/test.nix @@ -37,7 +37,7 @@ rec { test = assert example.config.meta.maintainers == { - ${toString ../meta-maintainers.nix} = [ + ${toString ../../../lib/modules/generic/meta-maintainers.nix} = [ lib.maintainers.pierron lib.maintainers.roberth ]; diff --git a/nixos/doc/manual/default.nix b/nixos/doc/manual/default.nix index 78f44ad9ad74..e9ecc6c02bff 100644 --- a/nixos/doc/manual/default.nix +++ b/nixos/doc/manual/default.nix @@ -25,7 +25,6 @@ let escapeShellArg concatMapStringsSep sourceFilesBySuffices - modules ; common = import ./common.nix; @@ -134,7 +133,7 @@ let inherit (evalModules { modules = [ - (modules.importApply ../../../lib/services/service.nix { + (pkgs.lib.importService { pkgs = throw "nixos docs / portableServiceOptions: Do not reference pkgs in docs"; }) ]; diff --git a/nixos/doc/manual/release-notes/rl-2611.section.md b/nixos/doc/manual/release-notes/rl-2611.section.md index 2bfdc1e6b150..6776415f31da 100644 --- a/nixos/doc/manual/release-notes/rl-2611.section.md +++ b/nixos/doc/manual/release-notes/rl-2611.section.md @@ -56,6 +56,8 @@ - [snowflake-prometheus-exporter](https://github.com/grafana/snowflake-prometheus-exporter), a Prometheus exporter for Snowflake metrics. Available as [services.prometheus.exporters.snowflake](#opt-services.prometheus.exporters.snowflake.enable). +- [Pumpkin](https://pumpkinmc.org/), a Minecraft server implementation written entirely in Rust, focused on performance and configurability. Available as [services.pumpkin](#opt-services.pumpkin.enable). + - [feishin](https://github.com/jeffvli/feishin), a modern self-hosted music player. Available as [services.feishin](#opt-services.feishin.enable). - [CastSponsorSkip](https://github.com/gabe565/CastSponsorSkip/), skips YouTube sponsorships (and sometimes ads) on all local Google Cast devices. diff --git a/nixos/modules/misc/assertions.nix b/nixos/modules/misc/assertions.nix index e3adc2dcac46..d009ed2520b9 100644 --- a/nixos/modules/misc/assertions.nix +++ b/nixos/modules/misc/assertions.nix @@ -1,38 +1,5 @@ -{ lib, ... }: { - - options = { - - assertions = lib.mkOption { - type = lib.types.listOf lib.types.unspecified; - internal = true; - default = [ ]; - example = [ - { - assertion = false; - message = "you can't enable this for that reason"; - } - ]; - description = '' - This option allows modules to express conditions that must - hold for the evaluation of the system configuration to - succeed, along with associated error messages for the user. - ''; - }; - - warnings = lib.mkOption { - internal = true; - default = [ ]; - type = lib.types.listOf lib.types.str; - example = [ "The `foo' service is deprecated and will go away soon!" ]; - description = '' - This option allows modules to show warnings to users during - the evaluation of the system configuration. - ''; - }; - - }; - # impl of assertions is in - # - - # - + # Not `lib.genericModules.assertions`: the `lib` module argument may come from a + # different Nixpkgs version than this file. + imports = [ ../../../lib/modules/generic/assertions.nix ]; } diff --git a/nixos/modules/misc/documentation.nix b/nixos/modules/misc/documentation.nix index 3fd6e126cc1c..d0017d57e868 100644 --- a/nixos/modules/misc/documentation.nix +++ b/nixos/modules/misc/documentation.nix @@ -116,9 +116,7 @@ let && (t == "file" -> hasSuffix ".nix" n) ); prefixRegex = - "^" - + lib.strings.escapeRegex (toString pkgs.path) - + "($|/(modules|nixos|lib/services)($|/.*)|/lib)"; + "^" + lib.strings.escapeRegex (toString pkgs.path) + "($|/(modules|nixos|lib)($|/.*))"; filteredModules = builtins.path { name = "source"; inherit (pkgs) path; @@ -132,7 +130,10 @@ let in pkgs.runCommand "lazy-options.json" rec { - libPath = filter (pkgs.path + "/lib"); + # `lib` shares the `filteredModules` tree, so that `declarations` pointing + # into it are stripped by the `extraSources` of `../../doc/manual`, just + # like the ones pointing into `modules` and `nixos`. + libPath = filteredModules + "/lib"; pkgsLibPath = filter (pkgs.path + "/pkgs/pkgs-lib"); nixosPath = filteredModules + "/nixos"; env.NIX_ABORT_ON_WARN = warningsAreErrors; @@ -142,7 +143,6 @@ let + " ]"; disallowedReferences = [ filteredModules - libPath pkgsLibPath ]; __structuredAttrs = true; diff --git a/nixos/modules/misc/documentation/modular-services.nix b/nixos/modules/misc/documentation/modular-services.nix index 7fab6c1b456b..639e11ab6292 100644 --- a/nixos/modules/misc/documentation/modular-services.nix +++ b/nixos/modules/misc/documentation/modular-services.nix @@ -24,6 +24,7 @@ let "" = fakeSubmodule pkgs.autopush-rs.services.autoendpoint; "" = fakeSubmodule pkgs.ghostunnel.services.default; + "" = fakeSubmodule pkgs.git-pages.services.default; "" = fakeSubmodule pkgs.ktls-utils.services.default; "" = fakeSubmodule pkgs.php.services.default; "" = fakeSubmodule pkgs.snid.services.default; diff --git a/nixos/modules/module-list.nix b/nixos/modules/module-list.nix index e6c3e69b0955..e9931a91a6b2 100644 --- a/nixos/modules/module-list.nix +++ b/nixos/modules/module-list.nix @@ -671,6 +671,7 @@ ./services/games/minecraft-server.nix ./services/games/minetest-server.nix ./services/games/openarena.nix + ./services/games/pumpkin.nix ./services/games/quake3-server.nix ./services/games/teeworlds.nix ./services/games/terraria.nix diff --git a/nixos/modules/services/games/pumpkin.nix b/nixos/modules/services/games/pumpkin.nix new file mode 100644 index 000000000000..115ef8a3ca8e --- /dev/null +++ b/nixos/modules/services/games/pumpkin.nix @@ -0,0 +1,922 @@ +{ + config, + lib, + pkgs, + ... +}: +let + cfg = config.services.pumpkin; + + settingsFormat = pkgs.formats.toml { }; + jsonFormat = pkgs.formats.json { }; + + hasSecret = path: settings: (lib.attrByPath path null settings) != null; + + filterNulls = + v: if lib.isAttrs v then lib.mapAttrs (_: filterNulls) (lib.filterAttrs (_: x: x != null) v) else v; + + settingsWithoutSecrets = filterNulls ( + cfg.settings + // { + networking = cfg.settings.networking // { + rcon = + (builtins.removeAttrs cfg.settings.networking.rcon [ "passwordFile" ]) + // lib.optionalAttrs (cfg.settings.networking.rcon.passwordFile != null) { + password = "@PUMPKIN_RCON_PASSWORD@"; + }; + proxy = cfg.settings.networking.proxy // { + velocity = + (builtins.removeAttrs cfg.settings.networking.proxy.velocity [ "secretFile" ]) + // lib.optionalAttrs (cfg.settings.networking.proxy.velocity.secretFile != null) { + secret = "@PUMPKIN_VELOCITY_SECRET@"; + }; + }; + }; + } + ); + + configFile = settingsFormat.generate "pumpkin.toml" settingsWithoutSecrets; + + whitelistFile = jsonFormat.generate "whitelist.json" cfg.whitelist.entries; +in +{ + meta.maintainers = with lib.maintainers; [ + DerGrumpf + jk + ]; + + options.services.pumpkin = { + enable = lib.mkEnableOption "Pumpkin, a Minecraft server written in Rust"; + + package = lib.mkPackageOption pkgs "pumpkin" { }; + + openFirewall = lib.mkOption { + type = lib.types.bool; + default = false; + description = '' + Whether to open the firewall for the ports enabled under + {option}`services.pumpkin.settings.networking`. + ''; + example = true; + }; + + dataDir = lib.mkOption { + type = lib.types.path; + default = "/var/lib/pumpkin"; + description = '' + Directory holding Pumpkin's state (config, worlds, logs, etc.). + If this is a subdirectory of `/var/lib`, it is managed automatically + via systemd's `StateDirectory`; otherwise you are responsible for + ensuring the directory exists with the correct permissions. + ''; + example = "/srv/pumpkin"; + }; + + whitelist.entries = lib.mkOption { + type = lib.types.listOf ( + lib.types.submodule { + options = { + uuid = lib.mkOption { + type = lib.types.str; + description = "The player's UUID, in dashed form."; + }; + name = lib.mkOption { + type = lib.types.str; + description = "The player's username."; + }; + }; + } + ); + default = [ ]; + description = '' + Initial whitelist entries. Written to `whitelist.json` only if + that file doesn't already exist, since it's normally managed at + runtime via in-game/console `/whitelist` commands; changes made + this way are not overwritten by later rebuilds. + ''; + example = [ + { + uuid = "069a79f4-44e9-4726-a5be-fca90e38aaf5"; + name = "Notch"; + } + ]; + }; + + settings = lib.mkOption { + description = '' + Structured configuration written to `pumpkin.toml`, following + [RFC 42](https://github.com/NixOS/rfcs/blob/master/rfcs/0042-config-option.md). + Any field not covered by a typed option below can still be set via + this freeform `settings` attrset. See upstream's default generated + `pumpkin.toml` and the `pumpkin-config` crate source for the full + field list. + + ::: {.warning} + Do not set `networking.rcon.password` or + `networking.proxy.velocity.secret` here — they would end up + world-readable in the Nix store. Use + {option}`services.pumpkin.settings.networking.rcon.passwordFile` and + {option}`services.pumpkin.settings.networking.proxy.velocity.secretFile` + instead; setting either password/secret directly is rejected at + eval time. + ::: + ''; + default = { }; + example = lib.literalExpression '' + { + seed = "1785537519969227430"; + server_links.custom.discord = "https://discord.gg/example"; + } + ''; + type = lib.types.submodule { + freeformType = settingsFormat.type; + + options = { + default_difficulty = lib.mkOption { + type = lib.types.enum [ + "Peaceful" + "Easy" + "Normal" + "Hard" + ]; + default = "Normal"; + description = "Default game difficulty."; + example = "Hard"; + }; + op_permission_level = lib.mkOption { + type = lib.types.enum [ + 0 + 2 + 3 + 4 + ]; + default = 4; + description = '' + Permission level assigned to players by the /op command. Note: + upstream's deserializer currently rejects the value `1` due to a + missing match arm — only 0, 2, 3, and 4 are accepted. + ''; + }; + allow_nether = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether the Nether dimension is enabled."; + }; + allow_end = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether the End dimension is enabled."; + }; + hardcore = lib.mkOption { + type = lib.types.bool; + default = false; + description = "Whether the server runs in hardcore mode."; + example = true; + }; + tps = lib.mkOption { + type = lib.types.float; + default = 20.0; + description = "Server ticks per second."; + }; + default_gamemode = lib.mkOption { + type = lib.types.enum [ + "Survival" + "Creative" + "Adventure" + "Spectator" + ]; + default = "Survival"; + description = "Default gamemode assigned to new players."; + example = "Creative"; + }; + force_gamemode = lib.mkOption { + type = lib.types.bool; + default = false; + description = "Whether to force the default gamemode on every join."; + example = true; + }; + scrub_ips = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether to remove IP addresses from logs."; + }; + use_favicon = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether to serve a favicon to clients."; + }; + favicon_path = lib.mkOption { + type = lib.types.nullOr lib.types.str; + default = null; + description = "Path to an optional server favicon."; + example = "favicon.png"; + }; + default_level_name = lib.mkOption { + type = lib.types.str; + default = "world"; + description = "Name of the default level/world folder."; + }; + allow_chat_reports = lib.mkOption { + type = lib.types.bool; + default = false; + description = "Whether players can send signed chat reports."; + example = true; + }; + seed = lib.mkOption { + type = lib.types.nullOr lib.types.str; + default = null; + description = "Seed string for world generation."; + example = "11238910"; + }; + + white_list = lib.mkOption { + type = lib.types.bool; + default = false; + description = "Whether the whitelist is active."; + }; + enforce_whitelist = lib.mkOption { + type = lib.types.bool; + default = false; + description = "Whether to kick already-connected players who aren't whitelisted."; + }; + + logging = { + enabled = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether Pumpkin's internal logging is enabled."; + }; + threads = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether to include thread names in log output."; + }; + color = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether to colorize log output."; + }; + timestamp = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether to include timestamps in log output."; + }; + file = lib.mkOption { + type = lib.types.str; + default = "latest.log"; + description = "Log file name, relative to the state directory."; + example = "pumpkin.log"; + }; + }; + + resource_pack = { + java = { + enabled = lib.mkOption { + type = lib.types.bool; + default = false; + description = "Whether to require a Java Edition resource pack."; + example = true; + }; + url = lib.mkOption { + type = lib.types.str; + default = ""; + description = "URL of the resource pack."; + example = "https://example.com/resourcepack.zip"; + }; + sha1 = lib.mkOption { + type = lib.types.str; + default = ""; + description = "SHA-1 hash of the resource pack."; + example = "da39a3ee5e6b4b0d3255bfef95601890afd80709"; + }; + prompt_message = lib.mkOption { + type = lib.types.str; + default = ""; + description = "Message shown to players when prompted to accept the pack."; + example = "Please accept the resource pack to join."; + }; + force = lib.mkOption { + type = lib.types.bool; + default = false; + description = "Whether to disconnect players who decline the pack."; + }; + }; + bedrock = { + enabled = lib.mkOption { + type = lib.types.bool; + default = false; + description = "Whether to require a Bedrock Edition resource pack."; + example = true; + }; + force = lib.mkOption { + type = lib.types.bool; + default = false; + description = "Whether to disconnect players who decline the pack."; + }; + packs = lib.mkOption { + type = lib.types.listOf (lib.types.either lib.types.str (lib.types.attrsOf settingsFormat.type)); + default = [ ]; + description = '' + Array of Bedrock resource pack definitions. Entries may be bare + strings (e.g. a UUID or path) or tables (e.g. attrsets with + name/uuid/version keys), since upstream does not document the + entry shape in more detail. + ''; + example = [ "016d3a32-11f0-4a3f-8b52-8f1c3f1e5b0a" ]; + }; + }; + }; + + world = { + lighting = lib.mkOption { + type = lib.types.enum [ + "default" + "full" + "dark" + ]; + default = "default"; + description = "Lighting engine mode."; + example = "full"; + }; + autosave_ticks = lib.mkOption { + type = lib.types.ints.unsigned; + default = 6000; + description = "Ticks between automatic world saves (0 disables autosave)."; + example = 12000; + }; + chunk = { + type = lib.mkOption { + type = lib.types.enum [ + "anvil" + "linear" + "pump" + ]; + default = "anvil"; + description = '' + Chunk/world storage format. `anvil` is the modern Vanilla format; + `linear` is the more compact third-party format; `pump` is + Pumpkin's own optimized format. Only `anvil` uses + `write_in_place`/`compression` — they're ignored for the other two. + ''; + example = "linear"; + }; + write_in_place = lib.mkOption { + type = lib.types.bool; + default = false; + description = "Whether to write chunk data in place (anvil only)."; + }; + compression = { + algorithm = lib.mkOption { + type = lib.types.enum [ + "GZip" + "ZLib" + "LZ4" + "Custom" + ]; + default = "LZ4"; + description = "Chunk compression algorithm (anvil only)."; + example = "ZLib"; + }; + level = lib.mkOption { + type = lib.types.ints.unsigned; + default = 6; + description = "Chunk compression level (anvil only)."; + example = 9; + }; + }; + }; + }; + + networking = { + query = { + enabled = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether to accept GameSpy4 query connections."; + }; + address = lib.mkOption { + type = lib.types.str; + default = "0.0.0.0:25565"; + description = "Address:port to bind the query listener to."; + }; + }; + + rcon = { + enabled = lib.mkOption { + type = lib.types.bool; + default = false; + description = "Whether to accept RCON connections."; + }; + address = lib.mkOption { + type = lib.types.str; + default = "0.0.0.0:25575"; + description = "Address:port to bind the RCON listener to."; + }; + max_connections = lib.mkOption { + type = lib.types.ints.unsigned; + default = 10; + description = "Maximum number of simultaneous RCON connections."; + example = 20; + }; + logging = { + logged_successfully = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether to log successful RCON logins."; + }; + wrong_password = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether to log failed RCON login attempts."; + }; + commands = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether to log commands run over RCON."; + }; + quit = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether to log RCON client disconnects."; + }; + }; + passwordFile = lib.mkOption { + type = lib.types.nullOr lib.types.path; + default = null; + description = '' + Path to a file containing the RCON password. Loaded securely + at service start via systemd's `LoadCredential` and substituted + into the generated `pumpkin.toml` in place of a placeholder + string, using `replace-secret`; never placed in the Nix store. + Compatible with sops-nix and agenix. Does not enable RCON on + its own — set + {option}`services.pumpkin.settings.networking.rcon.enabled` + as well. + ''; + example = "/run/secrets/pumpkin-rcon-password"; + }; + }; + + proxy = { + enabled = lib.mkOption { + type = lib.types.bool; + default = false; + description = "Whether to enable proxy (Velocity/BungeeCord) support."; + example = true; + }; + velocity = { + enabled = lib.mkOption { + type = lib.types.bool; + default = false; + description = "Whether to enable the Velocity modern forwarding protocol."; + example = true; + }; + secretFile = lib.mkOption { + type = lib.types.nullOr lib.types.path; + default = null; + description = '' + Path to a file containing the Velocity forwarding secret. Loaded + securely at service start via systemd's `LoadCredential` and + substituted into the generated `pumpkin.toml` in place of a + placeholder string, using `replace-secret`; never placed in the + Nix store. + ''; + example = "/run/secrets/pumpkin-velocity-secret"; + }; + }; + bungeecord.enabled = lib.mkOption { + type = lib.types.bool; + default = false; + description = "Whether to enable BungeeCord IP forwarding."; + example = true; + }; + }; + + lan_broadcast.enabled = lib.mkOption { + type = lib.types.bool; + default = false; + description = "Whether to broadcast the server on the local network."; + example = true; + }; + + java = { + enabled = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether to accept Java Edition connections."; + }; + address = lib.mkOption { + type = lib.types.str; + default = "0.0.0.0:25565"; + description = "Address:port to bind the Java listener to."; + }; + compression = { + enabled = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether to compress packets."; + }; + threshold = lib.mkOption { + type = lib.types.ints.unsigned; + default = 256; + description = "Minimum packet size (in bytes) before compression is applied."; + example = 512; + }; + level = lib.mkOption { + type = lib.types.ints.unsigned; + default = 4; + description = "Compression level."; + example = 5; + }; + }; + authentication = { + enabled = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether to require Mojang authentication for Java clients."; + }; + connect_timeout = lib.mkOption { + type = lib.types.ints.unsigned; + default = 5000; + description = "Timeout (ms) for connecting to the authentication server."; + }; + read_timeout = lib.mkOption { + type = lib.types.ints.unsigned; + default = 5000; + description = "Timeout (ms) for reading from the authentication server."; + }; + prevent_proxy_connections = lib.mkOption { + type = lib.types.bool; + default = false; + description = "Whether to reject connections proxied through another server."; + }; + player_profile = { + allow_banned_players = lib.mkOption { + type = lib.types.bool; + default = false; + description = "Whether to allow players Mojang has banned."; + }; + allowed_actions = lib.mkOption { + type = lib.types.listOf ( + lib.types.enum [ + "FORCED_NAME_CHANGE" + "USING_BANNED_SKIN" + ] + ); + default = [ + "FORCED_NAME_CHANGE" + "USING_BANNED_SKIN" + ]; + description = "Which flagged-profile actions are still permitted to join."; + }; + }; + textures = { + enabled = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether to fetch player skins/capes/elytras."; + }; + allowed_url_schemes = lib.mkOption { + type = lib.types.listOf ( + lib.types.enum [ + "http" + "https" + ] + ); + default = [ + "http" + "https" + ]; + description = "URL schemes allowed for texture URLs."; + }; + allowed_url_domains = lib.mkOption { + type = lib.types.listOf lib.types.str; + default = [ + ".minecraft.net" + ".mojang.com" + ]; + description = "Domains allowed to serve textures."; + example = [ ".mydomain.example" ]; + }; + types = { + skin = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether to load skin textures."; + }; + cape = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether to load cape textures."; + }; + elytra = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether to load elytra textures."; + }; + }; + }; + }; + }; + + bedrock = { + enabled = lib.mkOption { + type = lib.types.bool; + default = false; + description = "Whether to accept Bedrock Edition connections."; + }; + address = lib.mkOption { + type = lib.types.str; + default = "0.0.0.0:19132"; + description = "Address:port to bind the Bedrock listener to."; + }; + compression = { + enabled = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether to compress packets."; + }; + threshold = lib.mkOption { + type = lib.types.ints.unsigned; + default = 256; + description = "Minimum packet size (in bytes) before compression is applied."; + example = 512; + }; + level = lib.mkOption { + type = lib.types.ints.unsigned; + default = 4; + description = "Compression level."; + example = 5; + }; + }; + authentication = { + enabled = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether to require Xbox Live authentication for Bedrock clients."; + }; + connect_timeout = lib.mkOption { + type = lib.types.ints.unsigned; + default = 5000; + description = "Timeout (ms) for connecting to the authentication server."; + }; + read_timeout = lib.mkOption { + type = lib.types.ints.unsigned; + default = 5000; + description = "Timeout (ms) for reading from the authentication server."; + }; + }; + }; + }; + + commands = { + use_console = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether the server console accepts commands."; + }; + use_tty = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether to use a TTY for the console."; + }; + log_console = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether to log console command usage."; + }; + broadcast_console_to_ops = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether to broadcast console commands to operators."; + }; + default_op_level = lib.mkOption { + type = lib.types.ints.between 0 4; + default = 0; + description = "Default operator permission level assigned via the console."; + example = 4; + }; + }; + + chat.format = lib.mkOption { + type = lib.types.str; + default = "<{DISPLAYNAME}> {MESSAGE}"; + description = "Chat message format template."; + example = "[{DISPLAYNAME}]: {MESSAGE}"; + }; + + pvp = { + enabled = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether player-vs-player combat is allowed."; + }; + hurt_animation = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether to show the hurt animation on PvP damage."; + }; + protect_creative = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether creative-mode players are protected from PvP damage."; + }; + knockback = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether PvP hits apply knockback."; + }; + swing = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether to show the attack swing animation."; + }; + }; + + server_links = { + enabled = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether to advertise server links to clients."; + }; + bug_report = lib.mkOption { + type = lib.types.str; + default = "https://github.com/Pumpkin-MC/Pumpkin/issues"; + description = "Bug report link."; + }; + support = lib.mkOption { + type = lib.types.str; + default = ""; + description = "Support link."; + example = "https://example.com/support"; + }; + status = lib.mkOption { + type = lib.types.str; + default = ""; + description = "Status page link."; + example = "https://status.example.com"; + }; + feedback = lib.mkOption { + type = lib.types.str; + default = ""; + description = "Feedback link."; + example = "https://example.com/feedback"; + }; + community = lib.mkOption { + type = lib.types.str; + default = ""; + description = "Community link."; + example = "https://discord.gg/example"; + }; + website = lib.mkOption { + type = lib.types.str; + default = ""; + description = "Website link."; + example = "https://example.com"; + }; + forums = lib.mkOption { + type = lib.types.str; + default = ""; + description = "Forums link."; + example = "https://forums.example.com"; + }; + news = lib.mkOption { + type = lib.types.str; + default = ""; + description = "News link."; + example = "https://example.com/news"; + }; + announcements = lib.mkOption { + type = lib.types.str; + default = ""; + description = "Announcements link."; + example = "https://example.com/announcements"; + }; + # server_links.custom is intentionally left to the freeform part + # of `settings`, since its shape is user-defined key/value pairs. + }; + + player_data = { + save_player_data = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether to persist player data."; + }; + save_player_cron_interval = lib.mkOption { + type = lib.types.ints.unsigned; + default = 300; + description = "Interval, in seconds, between player data saves."; + example = 600; + }; + }; + + fun.april_fools = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether to enable April Fools' Day easter eggs."; + }; + + recipe.send_recipes = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether to send the recipe book to clients."; + }; + + plugins.blocked_permissions = lib.mkOption { + type = lib.types.listOf lib.types.str; + default = [ ]; + description = "Permissions plugins are blocked from granting."; + example = [ "pumpkin.admin" ]; + }; + + advancement.save_advancements = lib.mkOption { + type = lib.types.bool; + default = true; + description = "Whether to persist player advancement progress."; + }; + }; + }; + }; + }; + + config = lib.mkIf cfg.enable { + assertions = [ + { + assertion = !(hasSecret [ "networking" "rcon" "password" ] cfg.settings); + message = "services.pumpkin: `settings.networking.rcon.password` is not allowed (world-readable in the Nix store). Use `settings.networking.rcon.passwordFile` instead."; + } + { + assertion = !(hasSecret [ "networking" "proxy" "velocity" "secret" ] cfg.settings); + message = "services.pumpkin: `settings.networking.proxy.velocity.secret` is not allowed (world-readable in the Nix store). Use `settings.networking.proxy.velocity.secretFile` instead."; + } + ]; + + systemd.services.pumpkin = { + description = "Pumpkin Minecraft Server"; + wantedBy = [ "multi-user.target" ]; + after = [ "network-online.target" ]; + wants = [ "network-online.target" ]; + + preStart = '' + install -m600 ${configFile} "${cfg.dataDir}/pumpkin.toml" + '' + + lib.optionalString (cfg.settings.networking.rcon.passwordFile != null) '' + ${lib.getExe pkgs.replace-secret} '@PUMPKIN_RCON_PASSWORD@' \ + "$CREDENTIALS_DIRECTORY/rcon-password" "${cfg.dataDir}/pumpkin.toml" + '' + + lib.optionalString (cfg.settings.networking.proxy.velocity.secretFile != null) '' + ${lib.getExe pkgs.replace-secret} '@PUMPKIN_VELOCITY_SECRET@' \ + "$CREDENTIALS_DIRECTORY/velocity-secret" "${cfg.dataDir}/pumpkin.toml" + '' + + lib.optionalString (cfg.whitelist.entries != [ ]) '' + if [ ! -e "${cfg.dataDir}/whitelist.json" ]; then + install -m600 ${whitelistFile} "${cfg.dataDir}/whitelist.json" + fi + ''; + + serviceConfig = lib.mkMerge [ + (lib.mkIf (lib.hasPrefix "/var/lib/" cfg.dataDir) { + StateDirectory = lib.last (lib.splitString "/" cfg.dataDir); + }) + { + ExecStart = lib.getExe cfg.package; + LoadCredential = + lib.optional ( + cfg.settings.networking.rcon.passwordFile != null + ) "rcon-password:${cfg.settings.networking.rcon.passwordFile}" + ++ lib.optional ( + cfg.settings.networking.proxy.velocity.secretFile != null + ) "velocity-secret:${cfg.settings.networking.proxy.velocity.secretFile}"; + Restart = "on-failure"; + RestartSec = 5; + StartLimitIntervalSec = 120; + StartLimitBurst = 5; + TimeoutStopSec = 120; + LimitNOFILE = 65536; + + DynamicUser = true; + WorkingDirectory = cfg.dataDir; + + NoNewPrivileges = true; + PrivateTmp = true; + ProtectSystem = "strict"; + ProtectHome = true; + CapabilityBoundingSet = ""; + } + ]; + }; + + networking.firewall = lib.mkIf cfg.openFirewall { + allowedTCPPorts = + lib.optional cfg.settings.networking.java.enabled ( + lib.toInt (lib.last (lib.splitString ":" cfg.settings.networking.java.address)) + ) + ++ lib.optional ( + cfg.settings.networking.rcon.enabled || cfg.settings.networking.rcon.passwordFile != null + ) (lib.toInt (lib.last (lib.splitString ":" cfg.settings.networking.rcon.address))); + allowedUDPPorts = lib.optional cfg.settings.networking.bedrock.enabled ( + lib.toInt (lib.last (lib.splitString ":" cfg.settings.networking.bedrock.address)) + ); + }; + }; +} diff --git a/nixos/modules/services/networking/netbird.nix b/nixos/modules/services/networking/netbird.nix index baba9801ecd5..d2fe3de9db97 100644 --- a/nixos/modules/services/networking/netbird.nix +++ b/nixos/modules/services/networking/netbird.nix @@ -339,7 +339,7 @@ in mkdir -p "$out/share/applications" substitute ${cfg.ui.package}/share/applications/netbird.desktop \ "$out/share/applications/${mkBin "netbird"}.desktop" \ - --replace-fail 'Name=Netbird' "Name=NetBird @ ${client.service.name}" \ + --replace-fail 'Name=NetBird' "Name=NetBird @ ${client.service.name}" \ --replace-fail 'Icon=netbird' "Icon=${cfg.ui.package}/share/icons/hicolor/256x256/apps/netbird.png" \ --replace-fail 'netbird-ui' "${mkBin "netbird-ui"}" '') diff --git a/nixos/modules/system/service/systemd/system.nix b/nixos/modules/system/service/systemd/system.nix index b1ae25b85118..b0b49b98e500 100644 --- a/nixos/modules/system/service/systemd/system.nix +++ b/nixos/modules/system/service/systemd/system.nix @@ -15,7 +15,7 @@ let mapAttrsToList ; - portable-lib = import ../../../../../lib/services/lib.nix { inherit lib; }; + portable-lib = lib.services; dash = before: after: diff --git a/nixos/modules/virtualisation/openvswitch.nix b/nixos/modules/virtualisation/openvswitch.nix index 4e75d1677955..085de6b61c7f 100644 --- a/nixos/modules/virtualisation/openvswitch.nix +++ b/nixos/modules/virtualisation/openvswitch.nix @@ -64,9 +64,22 @@ in boot.extraModulePackages = [ cfg.package ]; + systemd.sockets.ovsdb = { + description = "Open_vSwitch Database Socket"; + wantedBy = [ "sockets.target" ]; + before = [ "ovsdb.service" ]; + socketConfig = { + ListenStream = "${runDir}/db.sock"; + Service = "ovsdb.service"; + SocketMode = "0770"; + }; + }; + systemd.services.ovsdb = { description = "Open_vSwitch Database Server"; wantedBy = [ "multi-user.target" ]; + requires = [ "ovsdb.socket" ]; + after = [ "ovsdb.socket" ]; path = [ cfg.package ]; restartTriggers = [ db @@ -95,7 +108,7 @@ in serviceConfig = { ExecStart = '' ${cfg.package}/bin/ovsdb-server \ - --remote=punix:${runDir}/db.sock \ + --remote=pfd:3 \ --private-key=db:Open_vSwitch,SSL,private_key \ --certificate=db:Open_vSwitch,SSL,certificate \ --bootstrap-ca-cert=db:Open_vSwitch,SSL,ca_cert \ @@ -105,6 +118,7 @@ in /var/db/openvswitch/conf.db ''; Restart = "always"; + RestartMode = "direct"; RestartSec = 3; PIDFile = "/run/openvswitch/ovsdb.pid"; # Use service type 'forking' to correctly determine when ovsdb-server is ready. @@ -118,8 +132,8 @@ in systemd.services.ovs-vswitchd = { description = "Open_vSwitch Daemon"; wantedBy = [ "multi-user.target" ]; - bindsTo = [ "ovsdb.service" ]; - after = [ "ovsdb.service" ]; + requires = [ "ovsdb.socket" ]; + after = [ "ovsdb.socket" ]; path = [ cfg.package ]; serviceConfig = { ExecStart = '' @@ -131,6 +145,7 @@ in # Use service type 'forking' to correctly determine when vswitchd is ready. Type = "forking"; Restart = "always"; + RestartMode = "direct"; RestartSec = 3; }; }; diff --git a/nixos/tests/all-tests.nix b/nixos/tests/all-tests.nix index f7aa55cc7b47..375c9bc60bc0 100644 --- a/nixos/tests/all-tests.nix +++ b/nixos/tests/all-tests.nix @@ -697,6 +697,7 @@ in geth = runTest ./geth.nix; ghostunnel = runTest ./ghostunnel.nix; ghostunnel-modular = runTest ./ghostunnel-modular.nix; + git-pages-modular = runTest ./git-pages.nix; gitdaemon = runTest ./gitdaemon.nix; gitea = import ./gitea.nix { inherit pkgs runTest; @@ -1501,6 +1502,7 @@ in pufferpanel = runTest ./pufferpanel.nix; pulseaudio = discoverTests (import ./pulseaudio.nix); pulseaudio-tcp = runTest ./pulseaudio-tcp.nix; + pumpkin = runTest ./pumpkin.nix; pykms = runTest ./pykms.nix; qbit-manage = runTest ./qbit-manage.nix; qbittorrent = runTest ./qbittorrent.nix; diff --git a/nixos/tests/git-pages.nix b/nixos/tests/git-pages.nix new file mode 100644 index 000000000000..c7e19b7cf846 --- /dev/null +++ b/nixos/tests/git-pages.nix @@ -0,0 +1,65 @@ +{ pkgs, ... }: +{ + name = "git-pages-modular-service"; + + nodes.machine = { pkgs, ... }: { + environment.systemPackages = [ pkgs.curl ]; + + system.services.git-pages = { + imports = [ pkgs.git-pages.services.default ]; + git-pages = { + settings.server = { + pages = "tcp/:3000"; + caddy = "tcp/:3001"; + metrics = "tcp/:3002"; + }; + }; + systemd.service.environment.PAGES_INSECURE = "1"; + }; + + services.caddy = { + enable = true; + configFile = pkgs.writeText "Caddyfile" '' + { + admin off + persist_config off + auto_https disable_redirects + on_demand_tls { + permission http http://localhost:3001 + } + } + https://, http:// { + tls { + on_demand + } + reverse_proxy http://localhost:3000 + } + ''; + }; + + networking.firewall.allowedTCPPorts = [ 80 ]; + }; + + testScript = + let + testSite = pkgs.runCommand "git-pages-testsite.tar" { } '' + echo It works! > index.html + tar cvf $out index.html + ''; + in + '' + start_all() + + machine.wait_for_unit("caddy.service") + machine.wait_for_open_port(80) + machine.wait_for_unit("git-pages.service") + machine.wait_for_open_port(3001) + machine.wait_for_open_port(3002) + machine.fail("curl -f http://localhost/.git-pages/health") + machine.succeed("curl -f http://localhost/ -X PUT --data-binary @${testSite} --header 'Content-Type: application/x-tar'") + machine.wait_until_succeeds("test -f /var/lib/git-pages/data/site/localhost/.index") + machine.succeed("curl -f http://localhost/.git-pages/health") + machine.succeed("curl -f http://localhost/ | grep -F 'It works!'") + machine.succeed("curl -f http://localhost:3002/metrics") + ''; +} diff --git a/nixos/tests/openvswitch.nix b/nixos/tests/openvswitch.nix index cd725ccb4071..a6296c2a36a2 100644 --- a/nixos/tests/openvswitch.nix +++ b/nixos/tests/openvswitch.nix @@ -58,5 +58,27 @@ node1.wait_until_succeeds("ping -c1 10.0.0.2", timeout=30) node2.wait_until_succeeds("ping -c1 10.0.0.1", timeout=30) + + with subtest("Restarting ovsdb preserves OpenFlow flows"): + ovs_ofctl = "ovs-ofctl -O OpenFlow13" + marker_cookie = "0x5eed" + + def check_marker_flow(): + node1.succeed( + f"{ovs_ofctl} dump-flows vs0 | grep -q 'cookie={marker_cookie}'" + ) + + node1.succeed( + f"{ovs_ofctl} add-flow vs0 " + f"'cookie={marker_cookie},priority=100,ip,nw_src=192.0.2.1,actions=drop'" + ) + check_marker_flow() + + node1.succeed("systemctl restart ovsdb.service") + node1.wait_for_unit("ovsdb.service") + node1.wait_for_unit("ovs-vswitchd.service") + node1.wait_for_unit("vs0-netdev.service") + + check_marker_flow() ''; } diff --git a/nixos/tests/pumpkin.nix b/nixos/tests/pumpkin.nix new file mode 100644 index 000000000000..a6760ea36ad5 --- /dev/null +++ b/nixos/tests/pumpkin.nix @@ -0,0 +1,46 @@ +{ lib, pkgs, ... }: +let + seed = "2151901553968352745"; + rcon-pass = "foobar"; + rcon-port = 25575; +in +{ + name = "pumpkin"; + + containers.machine = { + environment.systemPackages = [ pkgs.mcrcon ]; + + systemd.tmpfiles.rules = [ + "f /root/rcon-password 0400 root root - ${rcon-pass}" + ]; + + services.pumpkin = { + enable = true; + settings = { + inherit seed; + bedrock.enabled = false; + networking.rcon = { + enabled = true; + address = "0.0.0.0:${toString rcon-port}"; + passwordFile = "/root/rcon-password"; + }; + }; + }; + }; + + testScript = '' + machine.wait_for_unit("pumpkin") + machine.wait_for_open_port(25565) + machine.wait_for_open_port(${toString rcon-port}) + assert "${seed}" in machine.succeed( + "mcrcon -H localhost -P ${toString rcon-port} -p '${rcon-pass}' -c 'seed'" + ) + machine.systemctl("stop pumpkin") + machine.wait_until_fails("systemctl is-active --quiet pumpkin") + ''; + + meta.maintainers = with lib.maintainers; [ + DerGrumpf + jk + ]; +} diff --git a/pkgs/applications/editors/vscode/extensions/anthropic.claude-code/default.nix b/pkgs/applications/editors/vscode/extensions/anthropic.claude-code/default.nix index 9891cbfe859b..167499bddc58 100644 --- a/pkgs/applications/editors/vscode/extensions/anthropic.claude-code/default.nix +++ b/pkgs/applications/editors/vscode/extensions/anthropic.claude-code/default.nix @@ -21,22 +21,22 @@ vscode-utils.buildVscodeMarketplaceExtension (finalAttrs: { sources = { "x86_64-linux" = { arch = "linux-x64"; - hash = "sha256-eIJB3cp3HeD5DGcr/mp4kjkY/gMFp9oam8cGKeKSOMc="; + hash = "sha256-muoSfcisO8jaCTAmFsdQFQn6gJJLW/ziTrnuD9wMCSM="; }; "aarch64-linux" = { arch = "linux-arm64"; - hash = "sha256-SG5Mj3qd0VUOErXUtHiAHaPCWmDoCCNSnNoQBa4cBCw="; + hash = "sha256-YlMnG09gsk9qTymjchJVmVC1pt/cSyIwh5vmvA/O55Y="; }; "aarch64-darwin" = { arch = "darwin-arm64"; - hash = "sha256-gOOI6PqNdET7phteeqZ9ejcXTpstipMSGVTGxyf+od0="; + hash = "sha256-0bcaZ4v2Wq2Y3Krfh2zbasf/S/wvyF1VJfz1qAHOQ7U="; }; }; in { name = "claude-code"; publisher = "anthropic"; - version = "2.1.258"; + version = "2.1.260"; } // sources.${stdenvNoCC.hostPlatform.system} or (throw "Unsupported system ${stdenvNoCC.hostPlatform.system}"); diff --git a/pkgs/applications/editors/vscode/vscode.nix b/pkgs/applications/editors/vscode/vscode.nix index 433433dfb4ec..0ace47f3fef3 100644 --- a/pkgs/applications/editors/vscode/vscode.nix +++ b/pkgs/applications/editors/vscode/vscode.nix @@ -34,16 +34,16 @@ let hash = { - x86_64-linux = "sha256-Rw8oHp118DsblX844ZNYAUDeOx2cm6bbE+e/MK6tTgA="; - aarch64-linux = "sha256-nWe+3yRHB96FEFVNFGJz0WNQGCl8b2ynkqXjeGiFZmI="; - aarch64-darwin = "sha256-yaORecVLW5rdAwdhPkxm9ENnJFbGLUP9aJU/iqEOdDI="; - armv7l-linux = "sha256-eI3yRcCXK0MPSjAuBuaK1JHMx/pMoUIotgqFOR1bCWs="; + x86_64-linux = "sha256-m0pU8NSb6qQT7aE30AxlQaY5MA1HnvysVmrRNBlAkhg="; + aarch64-linux = "sha256-KqwVTsRSgX6Ix7RSsRDyzbqtAK97zwXvc0OJE2ThDEQ="; + aarch64-darwin = "sha256-vRWhsmzRC6hJAPe9MPIdUe7yaIKOHhWorB+X+ZYgu+U="; + armv7l-linux = "sha256-orlhTC2qojDvMM/McSGmzwYTP5G4or9p/L0mtDu/HIA="; } .${system} or throwSystem; # Please backport all compatible updates to the stable release. # This is important for the extension ecosystem. - version = "1.135.0"; + version = "1.136.1"; # The update server (update.code.visualstudio.com) expects the version path # segment in X.Y.Z form, so we normalize X.Y to X.Y.0 (e.g. "1.110" → "1.110.0"). @@ -51,7 +51,7 @@ let downloadVersion = lib.versions.pad 3 version; # This is used for VS Code - Remote SSH test - rev = "08d4889f9ec4a1685d257b9b95de036c8e1ce1e5"; + rev = "a44adf7f53e00964ab890f9f8758a334f1fc15bc"; in buildVscode { pname = "vscode" + lib.optionalString isInsiders "-insiders"; @@ -84,7 +84,7 @@ buildVscode { src = fetchurl { name = "vscode-server-${rev}.tar.gz"; url = "https://update.code.visualstudio.com/commit:${rev}/server-linux-x64/stable"; - hash = "sha256-GqqUokBmyMhFiwwEP+IQqxrr+wfjgXtTLIudsQWOIYc="; + hash = "sha256-MYihsWaHogWVchb/NTndLrGeARcpVVOoi+8FOxIYhHU="; }; stdenv = stdenvNoCC; }; diff --git a/pkgs/build-support/trivial-builders/default.nix b/pkgs/build-support/trivial-builders/default.nix index 4f4b6a9e5911..27cb83cfc6f6 100644 --- a/pkgs/build-support/trivial-builders/default.nix +++ b/pkgs/build-support/trivial-builders/default.nix @@ -374,27 +374,33 @@ rec { # TODO: deduplicate with documentation in doc/build-helpers/trivial-build-helpers.chapter.md # see also https://github.com/NixOS/nixpkgs/pull/249721 # See https://nixos.org/manual/nixpkgs/unstable/#trivial-builder-concatText - /* + /** concat a list of files to the nix store. The contents of files are added to the file in the store. - Example: + See also the `concatText` helper function below. - # Writes my-file to /nix/store/ + # Examples + + Writes `my-file` to `/nix/store/`: + + ```nix concatTextFile { name = "my-file"; files = [ drv1 "${drv2}/path/to/file" ]; } + ``` - See also the `concatText` helper function below. + Writes executable `my-file` to `/nix/store//bin/my-file`: - # Writes executable my-file to /nix/store//bin/my-file + ```nix concatTextFile { name = "my-file"; files = [ drv1 "${drv2}/path/to/file" ]; executable = true; destination = "/bin/my-file"; } + ``` */ concatTextFile = { @@ -432,25 +438,32 @@ rec { # TODO: deduplicate with documentation in doc/build-helpers/trivial-build-helpers.chapter.md # see also https://github.com/NixOS/nixpkgs/pull/249721 # See https://nixos.org/manual/nixpkgs/unstable/#trivial-builder-concatText - /* + /** Writes a text file to nix store with no optional parameters available. - Example: + # Example - # Writes contents of files to /nix/store/ + Writes contents of files to `/nix/store/`: + + ```nix concatText "my-file" [ file1 file2 ] + ``` */ concatText = name: files: concatTextFile { inherit name files; }; # TODO: deduplicate with documentation in doc/build-helpers/trivial-build-helpers.chapter.md # see also https://github.com/NixOS/nixpkgs/pull/249721 # See https://nixos.org/manual/nixpkgs/unstable/#trivial-builder-concatText - /* - Writes a text file to nix store with and mark it as executable. + /** + Writes a text file to nix store and marks it as executable. - Example: - # Writes contents of files to /nix/store/ + # Example + + Writes contents of files to `/nix/store/`: + + ```nix concatScript "my-file" [ file1 file2 ] + ``` */ concatScript = name: files: @@ -459,11 +472,10 @@ rec { executable = true; }; - /* - TODO: Deduplicate this documentation. - More docs in doc/build-helpers/trivial-build-helpers.chapter.md - See https://nixos.org/manual/nixpkgs/unstable/#trivial-builder-symlinkJoin - + # TODO: Deduplicate this documentation. + # More docs in doc/build-helpers/trivial-build-helpers.chapter.md + # See https://nixos.org/manual/nixpkgs/unstable/#trivial-builder-symlinkJoin + /** Create a forest of symlinks to the files in `paths`. This creates a single derivation that replicates the directory structure @@ -471,16 +483,23 @@ rec { BEWARE: it may not "work right" when the passed paths contain symlinks to directories. - Example: + # Examples - # adds symlinks of hello to current build. + Adds symlinks of hello to the current build: + + ```nix symlinkJoin { name = "myhello"; paths = [ pkgs.hello ]; } + ``` - # adds symlinks of hello and stack to current build and prints "links added" + Adds symlinks of hello and stack to the current build and prints "links added": + + ```nix symlinkJoin { name = "myexample"; paths = [ pkgs.hello pkgs.stack ]; postBuild = "echo links added"; } + ``` This creates a derivation with a directory structure like the following: + ``` /nix/store/sglsr5g079a5235hy29da3mq3hv8sjmm-myexample |-- bin | |-- hello -> /nix/store/qy93dp4a3rqyn2mz63fbxjg228hffwyw-hello-2.10/bin/hello @@ -493,39 +512,43 @@ rec { | `-- vendor_completions.d | `-- stack.fish -> /nix/store/6lzdpxshx78281vy056lbk553ijsdr44-stack-2.1.3.1/share/fish/vendor_completions.d/stack.fish ... + ``` To create a directory structure from a specific subdirectory of input `paths` instead of their full trees, you can either append the subdirectory path to each input path, or use the `stripPrefix` argument to remove the common prefix during linking. - Example: + Creates symlinks of tmpfiles.d rules from multiple packages: - # create symlinks of tmpfiles.d rules from multiple packages + ```nix symlinkJoin { name = "tmpfiles.d"; paths = [ pkgs.lvm2 pkgs.nix ]; stripPrefix = "/lib/tmpfiles.d"; } + ``` This creates a derivation with a directory structure like the following: + ``` /nix/store/m5s775yicb763hfa133jwml5hwmwzv14-tmpfiles.d |-- lvm2.conf -> /nix/store/k6js0l5f0zpvrhay49579fj939j77p2w-lvm2-2.03.29/lib/tmpfiles.d/lvm2.conf `-- nix-daemon.conf -> /nix/store/z4v2s3s3y79fmabhps5hakb3c5dwaj5a-nix-1.33.7/lib/tmpfiles.d/nix-daemon.conf + ``` By default, packages that don't contain the specified subdirectory are silently skipped. Set `failOnMissing = true` to make the build fail if any input package is missing the subdirectory - (this is the default behavior when not using stripPrefix). + (this is the default behavior when not using `stripPrefix`). - symlinkJoin and linkFarm are similar functions, but they output + `symlinkJoin` and `linkFarm` are similar functions, but they output derivations with different structure. - symlinkJoin is used to create a derivation with a familiar directory - structure (top-level bin/, share/, etc), but with all actual files being symlinks to + `symlinkJoin` is used to create a derivation with a familiar directory + structure (top-level `bin/`, `share/`, etc), but with all actual files being symlinks to the files in the input derivations. - symlinkJoin is used many places in nixpkgs to create a single derivation + `symlinkJoin` is used many places in nixpkgs to create a single derivation that appears to contain binaries, libraries, documentation, etc from multiple input derivations. - linkFarm is instead used to create a simple derivation with symlinks to - other derivations. A derivation created with linkFarm is often used in CI + `linkFarm` is instead used to create a simple derivation with symlinks to + other derivations. A derivation created with `linkFarm` is often used in CI as a easy way to build multiple derivations at once. */ symlinkJoin = lib.extendMkDerivation { @@ -603,33 +626,41 @@ rec { }; }; - # TODO: move linkFarm docs to the Nixpkgs manual - /* + /** Quickly create a set of symlinks to derivations. This creates a simple derivation with symlinks to all inputs. - entries can be a list of attribute sets like + `entries` can be a list of attribute sets like + ```nix [ { name = "name" ; path = "/nix/store/..."; } ] + ``` or an attribute set name -> path like: + ```nix { name = "/nix/store/..."; other = "/nix/store/..."; } + ``` - Example: + # Example - # Symlinks hello and stack paths in store to current $out/hello-test and - # $out/foobar. + Symlinks hello and stack paths in store to the current `$out/hello-test` and + `$out/foobar`: + + ```nix linkFarm "myexample" [ { name = "hello-test"; path = pkgs.hello; } { name = "foobar"; path = pkgs.stack; } ] + ``` This creates a derivation with a directory structure like the following: + ``` /nix/store/qc5728m4sa344mbks99r3q05mymwm4rw-myexample |-- foobar -> /nix/store/6lzdpxshx78281vy056lbk553ijsdr44-stack-2.1.3.1 `-- hello-test -> /nix/store/qy93dp4a3rqyn2mz63fbxjg228hffwyw-hello-2.10 + ``` - See the note on symlinkJoin for the difference between linkFarm and symlinkJoin. + See the note on `symlinkJoin` for the difference between `linkFarm` and `symlinkJoin`. */ linkFarm = name: entries: @@ -676,25 +707,29 @@ rec { ${lib.concatStrings linkCommands} ''; - # TODO: move linkFarmFromDrvs docs to the Nixpkgs manual - /* - Easily create a linkFarm from a set of derivations. + /** + Easily create a `linkFarm` from a set of derivations. - This calls linkFarm with a list of entries created from the list of input + This calls `linkFarm` with a list of entries created from the list of input derivations. It turns each input derivation into an attribute set - like { name = drv.name ; path = drv }, and passes this to linkFarm. + like `{ name = drv.name ; path = drv }`, and passes this to `linkFarm`. - Example: + # Example - # Symlinks the hello, gcc, and ghc derivations in $out + Symlinks the hello, gcc, and ghc derivations in `$out`: + + ```nix linkFarmFromDrvs "myexample" [ pkgs.hello pkgs.gcc pkgs.ghc ] + ``` This creates a derivation with a directory structure like the following: + ``` /nix/store/m3s6wkjy9c3wy830201bqsb91nk2yj8c-myexample |-- gcc-wrapper-9.2.0 -> /nix/store/fqhjxf9ii4w4gqcsx59fyw2vvj91486a-gcc-wrapper-9.2.0 |-- ghc-8.6.5 -> /nix/store/gnf3s07bglhbbk4y6m76sbh42siym0s6-ghc-8.6.5 `-- hello-2.10 -> /nix/store/k0ll91c4npk4lg8lqhx00glg2m735g74-hello-2.10 + ``` */ linkFarmFromDrvs = name: drvs: @@ -706,8 +741,7 @@ rec { in linkFarm name (map mkEntryFromDrv drvs); - # TODO: move onlyBin docs to the Nixpkgs manual - /* + /** Produce a derivation that links to the target derivation's `/bin`, and *only* `/bin`. @@ -819,8 +853,7 @@ rec { sort ./references >$out ''; - # TODO: move writeStringReferencesToFile docs to the Nixpkgs manual - /* + /** Extract a string's references to derivations and paths (its context) and write them to a text file, removing the input string itself from the dependency graph. This is useful when you want to @@ -988,27 +1021,27 @@ rec { inheritFunctionArgs = false; }; - # TODO: move copyPathToStore docs to the Nixpkgs manual - /* + /** Copy a path to the Nix store. Nix automatically copies files to the store before stringifying paths. - If you need the store path of a file, ${copyPathToStore } can be - shortened to ${}. + If you need the store path of a file, `${copyPathToStore }` can be + shortened to `${}`. */ copyPathToStore = builtins.filterSource (p: t: true); - # TODO: move copyPathsToStore docs to the Nixpkgs manual - # Copy a list of paths to the Nix store. + /** + Copy a list of paths to the Nix store. + */ copyPathsToStore = map copyPathToStore; - # TODO: move applyPatches docs to the Nixpkgs manual - /* + /** Applies a list of patches to a source directory. - Example: + # Example - # Patching nixpkgs: + Patching nixpkgs: + ```nix applyPatches { src = pkgs.path; patches = [ @@ -1018,6 +1051,7 @@ rec { }) ]; } + ``` */ applyPatches = lib.extendMkDerivation { constructDrv = stdenvNoCC.mkDerivation; @@ -1080,16 +1114,18 @@ rec { }; }; - # TODO: move docs to Nixpkgs manual - # An immutable file in the store with a length of 0 bytes. + /** + An immutable file in the store with a length of 0 bytes. + */ emptyFile = runCommand "empty-file" { outputHash = "sha256-d6xi4mKdjkX2JFicDIv5niSzpyI0m/Hnm8GGAIU04kY="; outputHashMode = "recursive"; preferLocalBuild = true; } "touch $out"; - # TODO: move docs to Nixpkgs manual - # An immutable empty directory in the store. + /** + An immutable empty directory in the store. + */ emptyDirectory = runCommand "empty-directory" { outputHashAlgo = "sha256"; outputHashMode = "recursive"; diff --git a/pkgs/by-name/bi/bitcoin-knots/package.nix b/pkgs/by-name/bi/bitcoin-knots/package.nix index 1c6a88d022de..88147db00769 100644 --- a/pkgs/by-name/bi/bitcoin-knots/package.nix +++ b/pkgs/by-name/bi/bitcoin-knots/package.nix @@ -36,12 +36,12 @@ stdenv.mkDerivation (finalAttrs: { pname = if withGui then "bitcoin-knots" else "bitcoind-knots"; - version = "29.3.knots20260508"; + version = "29.4.1.knots20260508"; src = fetchurl { url = "https://bitcoinknots.org/files/29.x/${finalAttrs.version}/bitcoin-${finalAttrs.version}.tar.gz"; # hash retrieved from signed SHA256SUMS - hash = "sha256-jjrr2sqzL29rZdkMmKGIlSVToSpXfgtY0TUlv9Wd1jA="; + hash = "sha256-2kPox5C+2djEMtB6ECcQhFN9vWHeO6D3vUn5Wa3Lm48="; }; nativeBuildInputs = [ @@ -86,18 +86,18 @@ stdenv.mkDerivation (finalAttrs: { publicKeys = fetchFromGitHub { owner = "bitcoinknots"; repo = "guix.sigs"; - rev = "15113e2fe61b31354a6bcc3fddd17f759ce20c4a"; - sha256 = "sha256-snbs2j88k9CBdv8+s3GaFoIXyJRVWlKoxiKA8R6ek9Y="; + rev = "5d1879a10e22934294944eebc2f5f925a29b5ebc"; + sha256 = "sha256-5xZSk7BnZI8FOiAgONsHqDBztuKpyBHJVp8VpcXhJlo="; }; checksums = fetchurl { url = "https://bitcoinknots.org/files/${majorVersion}.x/${finalAttrs.version}/SHA256SUMS"; - hash = "sha256-vFfeObwXowk143DSv9WZ++u+KA0fuHexFU1NizrCiV4="; + hash = "sha256-r6vDK1Vu7pjVaJVlDoakOaIwMv5ZsyHPx0YULecAxnI="; }; signatures = fetchurl { url = "https://bitcoinknots.org/files/${majorVersion}.x/${finalAttrs.version}/SHA256SUMS.asc"; - hash = "sha256-8pVhrITphjs7rnJZrmxAU92GVgkjVPlkA54ne9iwiIs="; + hash = "sha256-2qInQ7g/YpXBgmHz7UtDf8Jherr2O1fIr+atVWBJVK4="; }; verifyBuilderKeys = @@ -149,7 +149,6 @@ stdenv.mkDerivation (finalAttrs: { # building with db48 (for legacy wallet support) is broken on Darwin (lib.cmakeBool "WITH_BDB" (withWallet && !stdenv.hostPlatform.isDarwin)) (lib.cmakeBool "WITH_USDT" enableTracing) - (lib.cmakeFeature "RDTS_CONSENT" "RUNTIME_WARN") ] ++ lib.optionals (!finalAttrs.finalPackage.doCheck) [ (lib.cmakeBool "BUILD_TESTS" false) diff --git a/pkgs/by-name/ch/chisel/package.nix b/pkgs/by-name/ch/chisel/package.nix index 449a45ded6ef..53070cea637b 100644 --- a/pkgs/by-name/ch/chisel/package.nix +++ b/pkgs/by-name/ch/chisel/package.nix @@ -6,13 +6,13 @@ buildGoModule (finalAttrs: { pname = "chisel"; - version = "1.12.0"; + version = "1.12.1"; src = fetchFromGitHub { owner = "jpillora"; repo = "chisel"; tag = "v${finalAttrs.version}"; - hash = "sha256-jB326ReuNObOW5BD0SlKMWIDiVGi9xuGbk1DlYTQWUw="; + hash = "sha256-ze/rGtUonSCC/6vo809xwlrEsIdNwn2e0g+l968TzN8="; }; vendorHash = "sha256-5YQDDK8tD8UZk8Jw+lG/AlKc1jW5gd8BQfMgGz+kZew="; diff --git a/pkgs/by-name/cl/claude-code/manifest.zst.json b/pkgs/by-name/cl/claude-code/manifest.zst.json index 03311f1c91a4..50ea0492882e 100644 --- a/pkgs/by-name/cl/claude-code/manifest.zst.json +++ b/pkgs/by-name/cl/claude-code/manifest.zst.json @@ -1,62 +1,60 @@ { - "version": "2.1.258", + "version": "2.1.260", "manifestSignatureEnforcement": "flag", - "commit": "b3cd543a1f6fcdf4d8fabc0f5e5538d2ee7f38e1", - "buildDate": "2026-09-01T22:04:05Z", + "commit": "e51f681183f733dbe9a81bf35921c786ee26dbc6", + "buildDate": "2026-09-03T19:52:17Z", "platforms": { "darwin-arm64": { "binary": "claude.zst", - "checksum": "ee83f6743e0e5f60ec1456ea813851c625051241f7bc55d607faafe44cf4bc82", - "size": 65811873, + "checksum": "90c8e9f337f7461b7582862f35ce22f89ad13b8d529c150f2969e8fa6d3bf020", + "size": 65758751, "bundle": { - "checksum": "412f0b36da7cff5b20e7d856c939b449449583ee0971e9217c54972d1dfb4df3", - "size": 65814874 + "checksum": "7639b52c3ff28116f770e198ffb9760f9ecd44632a7c2a0ff0200c4dcf1dd038", + "size": 65759778 } }, "darwin-x64": { "binary": "claude.zst", - "checksum": "160aa9a06afcb80c293ecd4e42ea62adb67e471bed6b9a813504f26b96978034", - "size": 69876596, + "checksum": "6f85206e0365f2edbcaff94058802d627d5c48d585d5630cf71e5fe1515f3e00", + "size": 69805574, "bundle": { - "checksum": "575203804ea01ddd3c12226c7c9cdcd068f1d039c732e22916297d438944510c", - "size": 69878203 + "checksum": "e81267bb7ff923e2b5d2b61dbe6e0767e2783dd88e306e0a1f308b8477cab96f", + "size": 69807328 } }, "linux-arm64": { "binary": "claude.zst", - "checksum": "31768a9f65e58e48a3cacf7fce069bb6d7bd707cdb49874af2cb19b9d05af671", - "size": 75035372 + "checksum": "cfd17d6812c2bd7c2e9c4bc028786e5619db2962a17ac10b77667a3ff1148877", + "size": 74961889 }, "linux-x64": { "binary": "claude.zst", - "checksum": "88207a58aee5a82e47db834ce81111200ad8fae9ea9abe2ff1ff9773d6a2100a", - "size": 75670149 + "checksum": "ad1c0b3f2de334f4bcb4a783c275b1af7a5945c0c955a9c7352cf4fa0666a7ec", + "size": 75589735 }, "linux-arm64-musl": { "binary": "claude.zst", - "checksum": "6658622d769ad18dfbc1e70ea0056e34e88e258b15769e9c63c6c444cb83625a", - "size": 73516216 + "checksum": "b483ac78a8f2169a744703f273ed24b302baf8b671c92897a7611f107f6c3920", + "size": 73440071 }, "linux-x64-musl": { "binary": "claude.zst", - "checksum": "d357e596364fb922923e5db2b3877d3d7ba4a1b9d2f44f44879efa103bf459a0", - "size": 74188445 + "checksum": "0d4231f3bafbc88f26899e54c246638659feccfb7e8be7b0d02078b58bdd4039", + "size": 74103087 }, "win32-x64": { "binary": "claude.exe.zst", - "checksum": "94c7203fbeaa42f67dba3e7aabc544b1356dcec76bf830693948e99f4e4f21bc", - "size": 78074015 + "checksum": "664d2c6ca08afcd030100ddaddb80c5764bc517a4df407d819e6839bcc5edca8", + "size": 78005064 }, "win32-arm64": { "binary": "claude.exe.zst", - "checksum": "28eb7de6beb1adc3bc628426eada6aabd9592d42b66174cc419f64cb208f0127", - "size": 74810598 + "checksum": "f38cd767f8aef8c0eec1a09bf1f636bf9c6b8589d133c80be54a3ec9798a0f18", + "size": 74742830 } }, "sdkCompat": { "testedWrapperVersions": [ - "0.3.217", - "0.3.218", "0.3.219", "0.3.220", "0.3.221", diff --git a/pkgs/by-name/ex/exploitdb/package.nix b/pkgs/by-name/ex/exploitdb/package.nix index 7d3ad556f54b..77f39c5274f7 100644 --- a/pkgs/by-name/ex/exploitdb/package.nix +++ b/pkgs/by-name/ex/exploitdb/package.nix @@ -6,13 +6,13 @@ }: stdenv.mkDerivation (finalAttrs: { pname = "exploitdb"; - version = "2026-09-02"; + version = "2026-09-03"; src = fetchFromGitLab { owner = "exploit-database"; repo = "exploitdb"; tag = finalAttrs.version; - hash = "sha256-kpDDkmKCoSJhinL5V9r0L5d8z3j+/nBr2wRMzogdJQI="; + hash = "sha256-xlCeoBzd5+p/++0JGYYy+eHWiC+41rce1gzcJycHskg="; }; nativeBuildInputs = [ makeWrapper ]; diff --git a/pkgs/by-name/gi/git-pages/package.nix b/pkgs/by-name/gi/git-pages/package.nix index 311f34df1061..d51fd4513585 100644 --- a/pkgs/by-name/gi/git-pages/package.nix +++ b/pkgs/by-name/gi/git-pages/package.nix @@ -2,8 +2,12 @@ lib, buildGoModule, fetchFromCodeberg, + fetchpatch, nix-update-script, versionCheckHook, + formats, + coreutils, + nixosTests, }: buildGoModule (finalAttrs: { @@ -18,6 +22,16 @@ buildGoModule (finalAttrs: { hash = "sha256-4yQ3RRJbOfMaqjJJ6CRRN7TuaYY8ScLXxMZPd4tWPwk="; }; + patches = [ + # bugfix to avoid creating parent directory on start + # remove when https://codeberg.org/git-pages/git-pages/pulls/258 is available in the release + (fetchpatch { + name = "mkdirall-parent-dir-create.patch"; + url = "https://codeberg.org/git-pages/git-pages/commit/507e57edbcfc0ec933a877bf26b1756ca0a61870.patch"; + hash = "sha256-1CjU4yGmDOmYsxo3U44Cg2xLJkrmUOX5ZXTycdLs6OE="; + }) + ]; + subPackages = [ "." ]; vendorHash = "sha256-NNIkzgRki2rtCVUnnhT44rEBcMZYiJPmsXySpxiHYR0="; @@ -31,7 +45,16 @@ buildGoModule (finalAttrs: { nativeInstallCheckInputs = [ versionCheckHook ]; versionCheckProgramArg = "-version"; - passthru.updateScript = nix-update-script { }; + passthru = { + tests = { inherit (nixosTests) git-pages-modular; }; + updateScript = nix-update-script { }; + services.default = { + imports = [ + (lib.modules.importApply ./service.nix { inherit formats coreutils; }) + ]; + git-pages.package = finalAttrs.finalPackage; + }; + }; meta = { description = "Scalable static site server for Git forges (like GitHub Pages or Netlify"; diff --git a/pkgs/by-name/gi/git-pages/service.nix b/pkgs/by-name/gi/git-pages/service.nix new file mode 100644 index 000000000000..61c8b645d0ad --- /dev/null +++ b/pkgs/by-name/gi/git-pages/service.nix @@ -0,0 +1,116 @@ +# Non-module dependencies (`importApply`) +{ formats, coreutils }: + +{ + config, + lib, + options, + name, + ... +}: +let + cfg = config.git-pages; + settingsFormat = formats.toml { }; + configFile = "git-pages.toml"; + configOutPath = config.configData.${configFile}.path; +in +{ + _class = "service"; + + meta.maintainers = with lib.maintainers; [ + dtomvan + phanirithvij + ]; + + options.git-pages = { + package = lib.mkOption { + description = "Package to use for git-pages"; + defaultText = "The git-pages package that provided this module."; + type = lib.types.package; + }; + + secretFile = lib.mkOption { + description = '' + File that contains secrets for the git-pages config. + If values in this file are set, any options specified take priority over the options set in + {option}`git-pages.settings`. + + ::: {.note} + See the [git-pages documentation](https://git-pages.org/running-a-server/#configuration) on + secrets and environment variables. + ::: + ''; + default = null; + type = lib.types.nullOr lib.types.str; + }; + settings = lib.mkOption { + type = settingsFormat.type; + description = '' + Settings to set in config.toml. + + ::: {.note} + See the [git-pages documentation](https://git-pages.org/running-a-server/#configuration) on configuring the server. + ::: + ''; + default = { }; + }; + }; + + config = { + git-pages.settings.storage.fs.root = lib.mkDefault "/var/lib/${name}/data"; + + process.argv = [ + (lib.getExe cfg.package) + "-config" + configOutPath + ]; + + configData."${configFile}".source = settingsFormat.generate configFile cfg.settings; + } + // lib.optionalAttrs (options ? systemd) { + systemd.service = { + description = "Forge-agnostic static site server"; + documentation = [ "https://git-pages.org/running-a-server/" ]; + + after = [ "network.target" ]; + wants = [ "network.target" ]; + wantedBy = [ "multi-user.target" ]; + restartTriggers = [ config.configData."${configFile}".source ]; + + serviceConfig = { + Restart = "always"; + + StateDirectory = name; + WorkingDirectory = "%S/${name}"; + BindReadOnlyPaths = [ configOutPath ]; + + LoadCredential = lib.optional (cfg.secretFile != null) "secrets.toml:${cfg.secretFile}"; + + User = name; + DynamicUser = true; + + # systemd service hardening + ProtectHome = true; + MemoryDenyWriteExecute = true; + PrivateDevices = true; + PrivateTmp = true; + ProtectSystem = "strict"; + ProtectControlGroups = true; + RestrictSUIDSGID = true; + RestrictRealtime = true; + RestrictAddressFamilies = "AF_INET AF_INET6 AF_UNIX"; + RestrictNamespaces = true; + LockPersonality = true; + ProtectKernelLogs = true; + ProtectKernelTunables = true; + ProtectHostname = true; + ProtectKernelModules = true; + PrivateUsers = true; + ProtectClock = true; + SystemCallArchitectures = "native"; + SystemCallErrorNumber = "EPERM"; + SystemCallFilter = "@system-service"; + }; + }; + }; +} diff --git a/pkgs/by-name/gl/gleam/package.nix b/pkgs/by-name/gl/gleam/package.nix index 5bf606a2ebf3..432b248bd0a2 100644 --- a/pkgs/by-name/gl/gleam/package.nix +++ b/pkgs/by-name/gl/gleam/package.nix @@ -30,13 +30,15 @@ rustPlatform.buildRustPackage (finalAttrs: { nativeBuildInputs = [ pkg-config - beamPackages.erlang ]; nativeCheckInputs = [ # used by several tests git + # erlang runtime is used for integration tests + beamPackages.erlang + # js runtimes used for integration tests nodejs bun diff --git a/pkgs/by-name/jj/jj-starship/package.nix b/pkgs/by-name/jj/jj-starship/package.nix index 39904a3f8263..eb92cce2c54c 100644 --- a/pkgs/by-name/jj/jj-starship/package.nix +++ b/pkgs/by-name/jj/jj-starship/package.nix @@ -14,16 +14,16 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "jj-starship"; - version = "0.7.1"; + version = "0.7.3"; src = fetchFromGitHub { owner = "dmmulroy"; repo = "jj-starship"; tag = "v${finalAttrs.version}"; - hash = "sha256-NLds7i1ZmscicaNLmkZCWmc7A+367BXxGioRd4yYof8="; + hash = "sha256-oI/6zLVvQWJt3+LtVLfv5eCia/Bwmb88NJaY0lpEz1c="; }; - cargoHash = "sha256-i7x/y+BkKH+Xj1bU4RRe9fcteabB+4uAgJuW3x5/jv4="; + cargoHash = "sha256-GuZnQOzX24Z9PhEKPYHr44UPCSxem81EWMgGW/ixk2c="; buildNoDefaultFeatures = !withGit; diff --git a/pkgs/by-name/jp/jprq/package.nix b/pkgs/by-name/jp/jprq/package.nix new file mode 100644 index 000000000000..075a283e4873 --- /dev/null +++ b/pkgs/by-name/jp/jprq/package.nix @@ -0,0 +1,36 @@ +{ + lib, + buildGoModule, + fetchFromGitHub, +}: +buildGoModule rec { + pname = "jprq"; + version = "2.4"; + + __structuredAttrs = true; + + src = fetchFromGitHub { + owner = "azimjohn"; + repo = "jprq"; + tag = version; + hash = "sha256-aOsknEmNXSOKwmCQtm5mibrw9VKpb7uOdOZsivYsz+g="; + }; + + vendorHash = "sha256-aK+7ca16jzvKEDEWjCiud52vHciy1ZUwlSxKjd6rc+U="; + + subPackages = [ + "cli" + ]; + + postInstall = '' + mv $out/bin/cli $out/bin/jprq + ''; + + meta = { + description = "Free and open tool for exposing local servers to public network"; + homepage = "https://jprq.io"; + license = lib.licenses.bsd3; + maintainers = with lib.maintainers; [ mmkamron ]; + mainProgram = "jprq"; + }; +} diff --git a/pkgs/by-name/ju/just-lsp/package.nix b/pkgs/by-name/ju/just-lsp/package.nix index e150fbb3a946..c3b19a7d8c8b 100644 --- a/pkgs/by-name/ju/just-lsp/package.nix +++ b/pkgs/by-name/ju/just-lsp/package.nix @@ -8,7 +8,7 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "just-lsp"; - version = "0.6.2"; + version = "0.7.1"; __structuredAttrs = true; @@ -16,10 +16,10 @@ rustPlatform.buildRustPackage (finalAttrs: { owner = "terror"; repo = "just-lsp"; tag = finalAttrs.version; - hash = "sha256-B9ydV1q73auAVVaW9FyYmgyPncX9OXlE4w1IPst9buU="; + hash = "sha256-MQzXXsosKyFBRJBXB8Om9Su5aZDGSnW8rGdLfvuCo6U="; }; - cargoHash = "sha256-vUILbwu5/EQFG/8GCr3tQtmipGrVVwzgoV1oyDHWx0o="; + cargoHash = "sha256-D52hr/h2+/GTp95ZZJWxh6wXLa6FU/xVlP/2M8A6KL8="; nativeInstallCheckInputs = [ versionCheckHook diff --git a/pkgs/by-name/kn/knot-dns/package.nix b/pkgs/by-name/kn/knot-dns/package.nix index 637860fb10a4..dae8d40455bd 100644 --- a/pkgs/by-name/kn/knot-dns/package.nix +++ b/pkgs/by-name/kn/knot-dns/package.nix @@ -34,11 +34,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "knot-dns"; - version = "3.5.7"; + version = "3.5.8"; src = fetchurl { url = "https://knot-dns.nic.cz/release/knot-${finalAttrs.version}.tar.xz"; - sha256 = "0e363e9160895e2b83d02b0a7488c3a566b605b92edac85d03be3ebce94b8214"; + sha256 = "4197c902feccf32475b254c7ddaa1ac123700e3895f50b80103ffeb8352a2807"; }; outputs = [ diff --git a/pkgs/by-name/ls/lstk/package.nix b/pkgs/by-name/ls/lstk/package.nix index dbadb23a21de..1ed8dd890ba8 100644 --- a/pkgs/by-name/ls/lstk/package.nix +++ b/pkgs/by-name/ls/lstk/package.nix @@ -7,7 +7,7 @@ }: buildGoModule (finalAttrs: { pname = "lstk"; - version = "0.22.1"; + version = "0.22.2"; __structuredAttrs = true; @@ -15,10 +15,10 @@ buildGoModule (finalAttrs: { owner = "localstack"; repo = "lstk"; tag = "v${finalAttrs.version}"; - sha256 = "sha256-SavoRL6MP4owejL+BX1VgsBMLsuNdCw3rj2n+Il/+IU="; + sha256 = "sha256-Yy3LmKih91bXsa2wbBgGGNP6VhYBSD/3FFeU6WN15ek="; }; - vendorHash = "sha256-AvNFx3kMin6r788PCRdZ7qU3dUpJ/OILoY6hgvIXz+w="; + vendorHash = "sha256-wA59wFUoNW4NqAUI2MAGyF2g4vhX4++vlSAqwuXK4U4="; excludedPackages = "test/integration"; diff --git a/pkgs/by-name/ma/mate-utils/package.nix b/pkgs/by-name/ma/mate-utils/package.nix index 53a4f62c9cdc..54442e7ad4bc 100644 --- a/pkgs/by-name/ma/mate-utils/package.nix +++ b/pkgs/by-name/ma/mate-utils/package.nix @@ -28,7 +28,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "mate-utils"; - version = "1.28.1"; + version = "1.28.3"; outputs = [ "out" "man" @@ -39,7 +39,7 @@ stdenv.mkDerivation (finalAttrs: { repo = "mate-utils"; tag = "v${finalAttrs.version}"; fetchSubmodules = true; - hash = "sha256-0G25g4vpfufbvUYjCRJVBv9r5t/gnkDzWGKTf8N5MFQ="; + hash = "sha256-3MeR6Fm2w+AY9PHVTd5FoTygNGBLgFYFWoTBeKYEHA8="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/ma/matrix-authentication-service/package.nix b/pkgs/by-name/ma/matrix-authentication-service/package.nix index 11ecefbbc67c..3e3e5d109555 100644 --- a/pkgs/by-name/ma/matrix-authentication-service/package.nix +++ b/pkgs/by-name/ma/matrix-authentication-service/package.nix @@ -21,21 +21,21 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "matrix-authentication-service"; - version = "1.23.0"; + version = "1.24.0"; src = fetchFromGitHub { owner = "element-hq"; repo = "matrix-authentication-service"; tag = "v${finalAttrs.version}"; - hash = "sha256-DnaVIMp+pRRsNlyBZiTiqXajOgGFBT38sNLmC+IF8pU="; + hash = "sha256-LWGnfM7os9GT6fa/Vk1wAEp9m1L5rEL7tSPmgEKMNfQ="; }; - cargoHash = "sha256-3fBikvSbPTiIYXk7TQKoQ/YqjF5ZCoN0xQRSqCmHF9Q="; + cargoHash = "sha256-jAJuRwhc+0IAikLyqctHuCQcS61iNj7iKWHJdRAqsAk="; pnpmDeps = fetchPnpmDeps { inherit (finalAttrs) pname version src; fetcherVersion = 4; - hash = "sha256-8dPqsa1/D4q7hdntV1AmbRxQyZgAf7Q/z+etj+R/jIE="; + hash = "sha256-DxEjMhYqZGbnobQ/F0WFXq7qaxSkWDcoZ0kmWJsdxEQ="; }; pnpmRoot = "frontend"; diff --git a/pkgs/by-name/ne/netbird-dashboard/package.nix b/pkgs/by-name/ne/netbird-dashboard/package.nix index bce7be1501d0..afd3ed653c1d 100644 --- a/pkgs/by-name/ne/netbird-dashboard/package.nix +++ b/pkgs/by-name/ne/netbird-dashboard/package.nix @@ -6,16 +6,16 @@ buildNpmPackage rec { pname = "netbird-dashboard"; - version = "2.91.1"; + version = "2.92.0"; src = fetchFromGitHub { owner = "netbirdio"; repo = "dashboard"; rev = "v${version}"; - hash = "sha256-TA+H1v4Xd56UcJtNLZrTOPjvOuwBmkmX2UpbLsBJA+A="; + hash = "sha256-ZE+Flbtb9/opOIbjoFsNdl2oWx9yBOUxgA+Iu6zJC/E="; }; - npmDepsHash = "sha256-KWEVpESs71ng9uGbgP1xHihFhRONDE81wx6y3O4BoAY="; + npmDepsHash = "sha256-75Sc4MMW2HOCqfIngQbigVyzjHwNMeOhZumrm28K1o8="; npmFlags = [ "--legacy-peer-deps" ]; installPhase = '' diff --git a/pkgs/by-name/ne/netbird/package.nix b/pkgs/by-name/ne/netbird/package.nix index 23edf5f03fdc..96bbb0395f14 100644 --- a/pkgs/by-name/ne/netbird/package.nix +++ b/pkgs/by-name/ne/netbird/package.nix @@ -78,7 +78,7 @@ let in buildGoModule (finalAttrs: { pname = "netbird-${componentName}"; - version = "0.77.1"; + version = "0.78.1"; __structuredAttrs = true; @@ -86,7 +86,7 @@ buildGoModule (finalAttrs: { owner = "netbirdio"; repo = "netbird"; tag = "v${finalAttrs.version}"; - hash = "sha256-uGyo2J/3berl6yBCs+Qy0mXKMZNRM8o6gclBeiDxon8="; + hash = "sha256-YWLorAu71hG5BJLXsZwtQf86o51KCn2/1wI1DRg/aCg="; }; overrideModAttrs = final: prev: { @@ -100,7 +100,7 @@ buildGoModule (finalAttrs: { }; proxyVendor = true; - vendorHash = "sha256-IGCfMhcrZqHye83zcJuDf1Hyv7X4rKybxWOiyxGuYtY="; + vendorHash = "sha256-E8NeS88Ab5sumDxyH54y3GIWcXQQzRT0UXO+xwcQpUU="; nativeBuildInputs = [ installShellFiles diff --git a/pkgs/by-name/no/noctalia-greeter/package.nix b/pkgs/by-name/no/noctalia-greeter/package.nix index f86af8324e9b..22ce1b6a3a00 100644 --- a/pkgs/by-name/no/noctalia-greeter/package.nix +++ b/pkgs/by-name/no/noctalia-greeter/package.nix @@ -25,6 +25,7 @@ wayland-protocols, wlroots_0_20, + versionCheckHook, nix-update-script, }: @@ -68,6 +69,12 @@ stdenv.mkDerivation (finalAttrs: { wlroots_0_20 ]; + doInstallCheck = stdenv.buildPlatform.canExecute stdenv.hostPlatform; + versionCheckProgram = "${placeholder "out"}/bin/noctalia-greeter"; + nativeInstallCheckInputs = [ + versionCheckHook + ]; + passthru.updateScript = nix-update-script { }; meta = { diff --git a/pkgs/by-name/no/noctalia/package.nix b/pkgs/by-name/no/noctalia/package.nix index 435496116d29..5fbe2c1a5da0 100644 --- a/pkgs/by-name/no/noctalia/package.nix +++ b/pkgs/by-name/no/noctalia/package.nix @@ -12,6 +12,7 @@ makeBinaryWrapper, autoAddDriverRunpath, installShellFiles, + versionCheckHook, # libraries cairo, @@ -137,6 +138,12 @@ stdenv.mkDerivation (finalAttrs: { gitMinimal ]; + doInstallCheck = stdenv.buildPlatform.canExecute stdenv.hostPlatform; + + nativeInstallCheckInputs = [ + versionCheckHook + ]; + passthru.updateScript = nix-update-script { }; meta = { diff --git a/pkgs/by-name/om/omnictl/package.nix b/pkgs/by-name/om/omnictl/package.nix index 50c692755526..a512ba947c8a 100644 --- a/pkgs/by-name/om/omnictl/package.nix +++ b/pkgs/by-name/om/omnictl/package.nix @@ -8,16 +8,16 @@ buildGoModule rec { pname = "omnictl"; - version = "1.10.5"; + version = "1.10.6"; src = fetchFromGitHub { owner = "siderolabs"; repo = "omni"; rev = "v${version}"; - hash = "sha256-UV106G6B2ygT83zUe5C8HrS1/TLixZtmyI4OGqqAUfY="; + hash = "sha256-3Fm7WM8ge7rz9h/UlvULrG8yzol8e/i+3FSvRBf/g+k="; }; - vendorHash = "sha256-02wymmQpzojZej+v5lhZ3SDXwVq3l6Wr64fIKp8L6vk="; + vendorHash = "sha256-JZmRdWwZ2s5Ot+GopWg1jgCKruE+z6rltGch/DApuoI="; ldflags = [ "-s" diff --git a/pkgs/by-name/op/open-interpreter/package.nix b/pkgs/by-name/op/open-interpreter/package.nix index 27144414650b..66e5b2430a0a 100644 --- a/pkgs/by-name/op/open-interpreter/package.nix +++ b/pkgs/by-name/op/open-interpreter/package.nix @@ -66,7 +66,10 @@ stdenv.mkDerivation rec { description = "The open-source terminal agent built for low-cost models"; homepage = "https://github.com/openinterpreter/openinterpreter"; license = licenses.asl20; - maintainers = with maintainers; [ _2hexed ]; + maintainers = with maintainers; [ + _2hexed + happysalada + ]; platforms = [ "x86_64-linux" "aarch64-linux" diff --git a/pkgs/by-name/op/openvswitch/package.nix b/pkgs/by-name/op/openvswitch/package.nix index 74222ad18979..db5aca0d872c 100644 --- a/pkgs/by-name/op/openvswitch/package.nix +++ b/pkgs/by-name/op/openvswitch/package.nix @@ -24,19 +24,20 @@ python3, sphinxHook, tcpdump, + unbound, util-linux, which, }: stdenv.mkDerivation (finalAttrs: { pname = if withDPDK then "openvswitch-dpdk" else "openvswitch"; - version = "3.7.1"; + version = "4.0.0"; src = fetchFromGitHub { owner = "openvswitch"; repo = "ovs"; tag = "v${finalAttrs.version}"; - hash = "sha256-3FQjV4BZZpn7Loiu9Xm30cCqzkU1HgJ3sAc+I6D8OvQ="; + hash = "sha256-+WjpNJkM3AztBY1gPO6RdujGi86GDTjskJyDK16/9Dc="; }; outputs = [ @@ -74,6 +75,7 @@ stdenv.mkDerivation (finalAttrs: { perl procps python3 + unbound util-linux which ] @@ -108,13 +110,9 @@ stdenv.mkDerivation (finalAttrs: { installShellCompletion utilities/ovs-vsctl-bashcomp.bash mkdir -p $tools/{bin,share/openvswitch/scripts} - mv $out/share/openvswitch/bugtool-plugins $tools/share/openvswitch - mv $out/share/openvswitch/scripts/ovs-{bugtool*,check-dead-ifs,monitor-ipsec,vtep} $tools/share/openvswitch/scripts + mv $out/share/openvswitch/scripts/ovs-{check-dead-ifs,monitor-ipsec,vtep} $tools/share/openvswitch/scripts mv $out/share/openvswitch/scripts/usdt $tools/share/openvswitch/scripts - mv $out/bin/ovs-{bugtool,dpctl-top,l3ping,parse-backtrace,pcap,tcpdump,tcpundump,test,vlan-test} $tools/bin - - wrapProgram $tools/bin/ovs-l3ping \ - --prefix PYTHONPATH : $out/share/openvswitch/python + mv $out/bin/ovs-{dpctl-top,pcap,tcpdump,tcpundump} $tools/bin wrapProgram $tools/bin/ovs-tcpdump \ --prefix PATH : ${lib.makeBinPath [ tcpdump ]} \ @@ -126,6 +124,9 @@ stdenv.mkDerivation (finalAttrs: { export TESTSUITEFLAGS="-j$NIX_BUILD_CORES" export RECHECK=yes + # Nix sandbox has no /etc/resolv.conf + export OVS_RESOLV_CONF=/dev/null + patchShebangs tests/ ''; @@ -138,7 +139,10 @@ stdenv.mkDerivation (finalAttrs: { pyparsing pytest setuptools - ]); + tftpy + ]) + # pyftpdlib depends on pysendfile extension, which cannot be static + ++ lib.optionals (!stdenv.hostPlatform.isStatic) [ python3.pkgs.pyftpdlib ]; passthru = { tests = { diff --git a/pkgs/by-name/pe/perfetto-sdk/package.nix b/pkgs/by-name/pe/perfetto-sdk/package.nix new file mode 100644 index 000000000000..30ffc38d2a3b --- /dev/null +++ b/pkgs/by-name/pe/perfetto-sdk/package.nix @@ -0,0 +1,7 @@ +{ + perfetto, + ... +}@args: + +# Alias to perfetto.sdk to improve discoverability +(perfetto.override (removeAttrs args [ "perfetto" ])).sdk diff --git a/pkgs/by-name/pe/perfetto/package.nix b/pkgs/by-name/pe/perfetto/package.nix index 9cb320f68788..dbc6e506f0d7 100644 --- a/pkgs/by-name/pe/perfetto/package.nix +++ b/pkgs/by-name/pe/perfetto/package.nix @@ -239,6 +239,10 @@ stdenv.mkDerivation (finalAttrs: { runHook postInstall ''; + passthru = { + inherit (finalAttrs.passthru) updateScript tests; + }; + meta = { inherit (finalAttrs.meta) homepage diff --git a/pkgs/by-name/pr/prek/package.nix b/pkgs/by-name/pr/prek/package.nix index 99bde6cb2329..9bd9a6177e1d 100644 --- a/pkgs/by-name/pr/prek/package.nix +++ b/pkgs/by-name/pr/prek/package.nix @@ -10,17 +10,17 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "prek"; - version = "0.4.14"; + version = "0.5.2"; __structuredAttrs = true; src = fetchFromGitHub { owner = "j178"; repo = "prek"; tag = "v${finalAttrs.version}"; - hash = "sha256-Zu7EGt/4GoUK02NkuCJbUBiluhHGMB/hLr/FL4oEY20="; + hash = "sha256-8LvrsmHTvlJ/1xrVsO/81zZBOVv6nyJ1rKeF8DCrTf8="; }; - cargoHash = "sha256-s+l7xMf+TiEi5TgrQqP7c4SczdnFFRFpFOOVdBXAmwM="; + cargoHash = "sha256-COOU7CelDvnMKxBbAPiNvo+E+GnrS+tXiyqPBdUYBMk="; nativeBuildInputs = [ installShellFiles diff --git a/pkgs/by-name/pu/pumpkin/package.nix b/pkgs/by-name/pu/pumpkin/package.nix new file mode 100644 index 000000000000..ce0c0fae11a8 --- /dev/null +++ b/pkgs/by-name/pu/pumpkin/package.nix @@ -0,0 +1,49 @@ +{ + lib, + rustPlatform, + fetchFromGitHub, + nix-update-script, + nixosTests, +}: + +rustPlatform.buildRustPackage (finalAttrs: { + pname = "pumpkin"; + version = "0.1.0-unstable-2026-07-25"; + __structuredAttrs = true; + + src = fetchFromGitHub { + owner = "Pumpkin-MC"; + repo = "Pumpkin"; + rev = "0dfaf5d213e9bc281defa8315945160eddbc7f47"; + hash = "sha256-b2Ws2zUPouJWFDEeqr3zJ+l0G4BQNg+pYo21LBQDSzk="; + fetchSubmodules = true; + }; + + cargoHash = "sha256-xLFfb6ufSw6M6GIMcfvGfVYwN8kccK4+ufwHjdrLJxI="; + + cargoBuildFlags = [ + "--package" + "pumpkin" + ]; + + doCheck = true; + + passthru = { + updateScript = nix-update-script { extraArgs = [ "--version=branch" ]; }; + tests = { + nixos = nixosTests.pumpkin; + }; + }; + + meta = { + description = "Minecraft server built entirely in Rust, focused on performance, compatibility and configurability"; + homepage = "https://pumpkinmc.org/"; + license = lib.licenses.gpl3Only; + maintainers = with lib.maintainers; [ + DerGrumpf + jk + ]; + mainProgram = "pumpkin"; + platforms = lib.platforms.unix; + }; +}) diff --git a/pkgs/by-name/qo/qownnotes-tui/package.nix b/pkgs/by-name/qo/qownnotes-tui/package.nix index e976ec041131..224362fe6f6b 100644 --- a/pkgs/by-name/qo/qownnotes-tui/package.nix +++ b/pkgs/by-name/qo/qownnotes-tui/package.nix @@ -10,7 +10,7 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "qownnotes-tui"; - version = "0.6.0"; + version = "0.8.0"; __structuredAttrs = true; @@ -18,10 +18,10 @@ rustPlatform.buildRustPackage (finalAttrs: { owner = "qownnotes"; repo = "qownnotes-tui"; tag = "v${finalAttrs.version}"; - hash = "sha256-TqqqXpUYWIkcQVMHxapCveASmMHYjCHchmYUEDZg7qY="; + hash = "sha256-62EXnkooEAzczrIBNj8G6i/SLBbjotMUtZ86rNbNe7o="; }; - cargoHash = "sha256-fjSHZ2Xg1uv5Nl1oBBTE+5YsD749ITHUZG8grqrnNDU="; + cargoHash = "sha256-c4mZD7w2KSvWeYvAt+ISbCpPOuG1VwTS8xcOht3rdLM="; strictDeps = true; diff --git a/pkgs/by-name/rt/rtk/package.nix b/pkgs/by-name/rt/rtk/package.nix index a7e0a0c7aaae..d2661d1230ff 100644 --- a/pkgs/by-name/rt/rtk/package.nix +++ b/pkgs/by-name/rt/rtk/package.nix @@ -13,17 +13,17 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "rtk"; - version = "0.45.0"; + version = "0.47.0"; __structuredAttrs = true; src = fetchFromGitHub { owner = "rtk-ai"; repo = "rtk"; tag = "v${finalAttrs.version}"; - hash = "sha256-weAyHM0nWLrM8JRbbXIfjUsHtAep3DOFyTO+M3BZ/iU="; + hash = "sha256-qYVkFLS6G4Tf1NmD9B3kJkyb47XREoVE65EqBtbzzjs="; }; - cargoHash = "sha256-tgW6il/xLxt/xwhUBJ4MNVnk0JSZ7iFjJaEobj5+H4o="; + cargoHash = "sha256-2lwLPia3v7xagKsrCpayixZMmOqX15qrjsVP8/RQCXE="; nativeBuildInputs = [ makeWrapper diff --git a/pkgs/by-name/tt/ttnn-visualizer/package.nix b/pkgs/by-name/tt/ttnn-visualizer/package.nix new file mode 100644 index 000000000000..561cfeea4bf6 --- /dev/null +++ b/pkgs/by-name/tt/ttnn-visualizer/package.nix @@ -0,0 +1,163 @@ +{ + lib, + fetchFromGitHub, + fetchPnpmDeps, + nodejs_24, + pnpmConfigHook, + pnpm_11, + python3, + stdenvNoCC, + writeShellScriptBin, +}: + +let + version = "0.88.0"; + + patchNodeEngine = '' + substituteInPlace package.json \ + --replace-fail '"node": "24.15.0"' '"node": ">=24.15.0"' + substituteInPlace pnpm-workspace.yaml \ + --replace-fail 'engineStrict: true' 'engineStrict: false' + ''; + + ps = python3.pkgs; + src = fetchFromGitHub { + owner = "tenstorrent"; + repo = "ttnn-visualizer"; + tag = "v${version}"; + hash = "sha256-9ohL+xjiu56gasor8+eKsJPWhoDVD1zxFw60QYbWsHQ="; + }; + + frontendSource = stdenvNoCC.mkDerivation (finalAttrs: { + pname = "ttnn-visualizer-frontend-source"; + inherit version; + inherit src; + + pnpmDeps = fetchPnpmDeps { + inherit (finalAttrs) src pname version; + pnpm = pnpm_11; + fetcherVersion = 4; + hash = "sha256-25yC1PR8o3zppmIsK1fkYsB9K2XBUVLHk5+qJlHJfLI="; + postPatch = patchNodeEngine; + }; + + nativeBuildInputs = [ + nodejs_24 + pnpm_11 + pnpmConfigHook + ]; + + env = { + CI = "true"; + npm_config_yes = "true"; + pnpm_config_confirm_modules_purge = "false"; + }; + + postPatch = '' + ${patchNodeEngine} + + ${python3}/bin/python - <<'PY' + import json + from pathlib import Path + + package_json = Path("package.json") + data = json.loads(package_json.read_text()) + scripts = data.get("scripts", {}) + scripts.pop("prepare", None) + data["scripts"] = scripts + package_json.write_text(json.dumps(data, indent=2) + "\n") + PY + ''; + + buildPhase = '' + runHook preBuild + pnpm build + runHook postBuild + ''; + + installPhase = '' + runHook preInstall + mkdir -p "$out" + cp -r . "$out/" + runHook postInstall + ''; + }); + + ttnnVisualizer = ps.buildPythonPackage (finalAttrs: { + pname = "ttnn-visualizer"; + inherit version; + pyproject = true; + src = frontendSource; + + build-system = [ + ps.setuptools + ps.wheel + ]; + + postPatch = '' + substituteInPlace pyproject.toml \ + --replace-fail 'setuptools==78.1.1' 'setuptools' + ''; + + propagatedBuildInputs = [ + ps.alembic + ps.build + ps.flask + ps.flask-cors + ps.flask-socketio + ps.flask-sqlalchemy + ps.flask-static-digest + ps.gevent + ps.gunicorn + ps.orjson + ps.pandas + ps.pydantic + ps.pydantic-core + ps.python-dotenv + ps.pyyaml + ps.tt-perf-report + ps.uvicorn + ps.zstd + ]; + + pythonRelaxDeps = [ + "flask-cors" + "flask-socketio" + "flask" + "gevent" + "gunicorn" + "pandas" + "pydantic" + "pydantic-core" + "pyyaml" + "setuptools" + "uvicorn" + "zstd" + ]; + + pythonImportsCheck = [ "ttnn_visualizer" ]; + }); + + pythonEnv = python3.withPackages (ps: [ + ttnnVisualizer + ps.gunicorn + ps.gevent + ]); +in +(writeShellScriptBin "ttnn-visualizer" '' + export FLASK_ENV=production + export PATH="${lib.makeBinPath [ pythonEnv ]}:$PATH" + exec ${pythonEnv}/bin/python -m ttnn_visualizer.app "$@" +'').overrideAttrs + (_: { + strictDeps = true; + __structuredAttrs = true; + meta = { + description = "Tool for visualizing and analyzing TT-NN model execution"; + homepage = "https://github.com/tenstorrent/ttnn-visualizer"; + license = lib.licenses.asl20; + mainProgram = "ttnn-visualizer"; + maintainers = with lib.maintainers; [ mert-kurttutan ]; + platforms = lib.platforms.linux; + }; + }) diff --git a/pkgs/by-name/us/user-scanner/package.nix b/pkgs/by-name/us/user-scanner/package.nix index b6f78e13bb94..272fc0a16ada 100644 --- a/pkgs/by-name/us/user-scanner/package.nix +++ b/pkgs/by-name/us/user-scanner/package.nix @@ -8,7 +8,7 @@ python3Packages.buildPythonApplication (finalAttrs: { pname = "user-scanner"; - version = "1.4.3.1"; + version = "1.5.1"; pyproject = true; __structuredAttrs = true; @@ -17,7 +17,7 @@ python3Packages.buildPythonApplication (finalAttrs: { owner = "kaifcodec"; repo = "user-scanner"; tag = "v${finalAttrs.version}"; - hash = "sha256-7A4XxxUHyvEcZcAgGWzg79B/X0ePAdIt7yPM+nGsZGc="; + hash = "sha256-lBVKCIpvdYRz80BoaSbFcizs2tLEWankcLeOqu9u4iM="; }; build-system = with python3Packages; [ flit-core ]; @@ -26,6 +26,7 @@ python3Packages.buildPythonApplication (finalAttrs: { colorama curl-cffi httpx + mcp socksio ]; diff --git a/pkgs/by-name/we/wechat/package.nix b/pkgs/by-name/we/wechat/package.nix index a09398e05dd0..1251c2597f43 100644 --- a/pkgs/by-name/we/wechat/package.nix +++ b/pkgs/by-name/we/wechat/package.nix @@ -15,7 +15,10 @@ let downloadPage = "https://linux.weixin.qq.com/en"; license = lib.licenses.unfree; sourceProvenance = [ lib.sourceTypes.binaryNativeCode ]; - maintainers = with lib.maintainers; [ prince213 ]; + maintainers = with lib.maintainers; [ + larry0x + prince213 + ]; mainProgram = "wechat"; platforms = [ "aarch64-darwin" @@ -28,31 +31,31 @@ let # https://dldir1.qq.com/weixin/mac/mac-release.xml aarch64-darwin = let - version = "4.1.8.106-37335"; + version = "4.1.13.59-269627"; version' = lib.replaceString "-" "_" version; in { inherit version; src = fetchurl { url = "https://dldir1v6.qq.com/weixin/Universal/Mac/xWeChatMac_universal_${version'}.dmg"; - hash = "sha256-lygjqWbNqh9fCnhbyfEhnRdKdfQ9MOwPv5unqwJJsvE="; + hash = "sha256-45zrtADGKikIfN+BQRMR74Pnmr4VHfXShamWEnOTdOk="; }; }; # use https://web.archive.org/save to archive the Linux versions # add `if_` at the end of timestamps to avoid toolbar insertion # for a more complicated guide, see https://en.wikipedia.org/wiki/Help:Using_the_Wayback_Machine aarch64-linux = { - version = "4.1.1.4"; + version = "4.1.1.8"; src = fetchurl { - url = "https://web.archive.org/web/20260311102559if_/https://dldir1v6.qq.com/weixin/Universal/Linux/WeChatLinux_arm64.AppImage"; - hash = "sha256-YlWJxT62tXDaNwYVpsPMC5elFH8fsbI1HjTQn6ePiPo="; + url = "https://web.archive.org/web/20260818044444if_/https://dldir1v6.qq.com/weixin/Universal/Linux/WeChatLinux_arm64.AppImage"; + hash = "sha256-RLHhac3wSS1C9rx3GsA07Tp1EzxSf2LLBMyPtrECnUY="; }; }; x86_64-linux = { - version = "4.1.1.4"; + version = "4.1.1.8"; src = fetchurl { - url = "https://web.archive.org/web/20260311102439if_/https://dldir1v6.qq.com/weixin/Universal/Linux/WeChatLinux_x86_64.AppImage"; - hash = "sha256-XxAvFnlljqurGPDgRr+DnuCKbdVvgXBPh02DLHY3Oz8="; + url = "https://web.archive.org/web/20260818044436if_/https://dldir1v6.qq.com/weixin/Universal/Linux/WeChatLinux_x86_64.AppImage"; + hash = "sha256-RX26ArkbAxzdRBLu4HT7v/udnQax5Q/Bgi00hw4RSZA="; }; }; }; diff --git a/pkgs/by-name/xm/xmpp-bridge/package.nix b/pkgs/by-name/xm/xmpp-bridge/package.nix deleted file mode 100644 index 14dc4375de6c..000000000000 --- a/pkgs/by-name/xm/xmpp-bridge/package.nix +++ /dev/null @@ -1,51 +0,0 @@ -{ - lib, - fetchFromGitHub, - stdenv, - pkg-config, - libstrophe, - installShellFiles, -}: - -stdenv.mkDerivation (finalAttrs: { - pname = "xmpp-bridge"; - version = "0.6.0"; - - src = fetchFromGitHub { - owner = "majewsky"; - repo = "xmpp-bridge"; - rev = "v${finalAttrs.version}"; - hash = "sha256-JXhVi2AiV/PmWPfoQJl/N92GAZQ9UxReAiCkiDxgdFY="; - }; - - nativeBuildInputs = [ - installShellFiles - pkg-config - ]; - - buildInputs = [ - libstrophe - ]; - - strictDeps = true; - - # Makefile is hardcoded to install to /usr, install manually - installPhase = '' - runHook preInstall - - install -D -m 0755 build/xmpp-bridge "$out/bin/xmpp-bridge" - installManPage xmpp-bridge.1 - - runHook postInstall - ''; - - meta = { - description = "Connect command-line programs to XMPP"; - homepage = "https://github.com/majewsky/xmpp-bridge"; - license = lib.licenses.gpl3Plus; - mainProgram = "xmpp-bridge"; - maintainers = with lib.maintainers; [ gigahawk ]; - platforms = lib.platforms.unix; - broken = stdenv.hostPlatform.isDarwin; - }; -}) diff --git a/pkgs/development/python-modules/alibabacloud-sls20201230/default.nix b/pkgs/development/python-modules/alibabacloud-sls20201230/default.nix index ae7345c28dd2..e5c1de9db03e 100644 --- a/pkgs/development/python-modules/alibabacloud-sls20201230/default.nix +++ b/pkgs/development/python-modules/alibabacloud-sls20201230/default.nix @@ -10,7 +10,7 @@ buildPythonPackage (finalAttrs: { pname = "alibabacloud-sls20201230"; - version = "5.14.0"; + version = "5.15.0"; pyproject = true; __structuredAttrs = true; @@ -18,7 +18,7 @@ buildPythonPackage (finalAttrs: { src = fetchPypi { pname = "alibabacloud_sls20201230"; inherit (finalAttrs) version; - hash = "sha256-tySehsqxNdVfTHan9603srbIuwOQDx6FLAB6S3Cc1YQ="; + hash = "sha256-z2r5kjqJmlRZNeV44Mfa7F2Mss2GpR7viP5u219kVdw="; }; build-system = [ setuptools ]; diff --git a/pkgs/development/python-modules/boto3-stubs/default.nix b/pkgs/development/python-modules/boto3-stubs/default.nix index 7c083a97530c..8ce2c0087e09 100644 --- a/pkgs/development/python-modules/boto3-stubs/default.nix +++ b/pkgs/development/python-modules/boto3-stubs/default.nix @@ -358,13 +358,13 @@ buildPythonPackage (finalAttrs: { pname = "boto3-stubs"; - version = "1.43.87"; + version = "1.43.88"; pyproject = true; src = fetchPypi { pname = "boto3_stubs"; inherit (finalAttrs) version; - hash = "sha256-keMOAPVVlVjuiyCYP/qs4j5IEAEIUC1tlkuQ14bf88A="; + hash = "sha256-YZ5Jv4PThB7BuLD5VVaMS1Pf/OWKuA08QDjYy/LXkCk="; }; build-system = [ setuptools ]; diff --git a/pkgs/development/python-modules/claude-agent-sdk/default.nix b/pkgs/development/python-modules/claude-agent-sdk/default.nix index 66ab7113747a..b180aa7d02d5 100644 --- a/pkgs/development/python-modules/claude-agent-sdk/default.nix +++ b/pkgs/development/python-modules/claude-agent-sdk/default.nix @@ -14,14 +14,14 @@ buildPythonPackage (finalAttrs: { pname = "claude-agent-sdk"; - version = "0.2.149"; + version = "0.2.152"; pyproject = true; src = fetchFromGitHub { owner = "anthropics"; repo = "claude-agent-sdk-python"; tag = "v${finalAttrs.version}"; - hash = "sha256-3QOFqWl8k6hoToMfIz11a3uF+rb6XZqBnzaKlqxRtOk="; + hash = "sha256-h3LjBolK1hpcATNX45ftYZBTKWQtSF34o78E6fRab2M="; }; build-system = [ hatchling ]; diff --git a/pkgs/development/python-modules/credsweeper/default.nix b/pkgs/development/python-modules/credsweeper/default.nix index 33ff64e031c8..214b701f206b 100644 --- a/pkgs/development/python-modules/credsweeper/default.nix +++ b/pkgs/development/python-modules/credsweeper/default.nix @@ -44,7 +44,7 @@ buildPythonPackage (finalAttrs: { pname = "credsweeper"; - version = "1.18.1"; + version = "1.18.2"; pyproject = true; __structuredAttrs = true; @@ -53,7 +53,7 @@ buildPythonPackage (finalAttrs: { owner = "Samsung"; repo = "CredSweeper"; tag = "v${finalAttrs.version}"; - hash = "sha256-ktaCNgM0FJCdreIqhzYc21CjpLmp7vIbs9E5Q6yvWjc="; + hash = "sha256-JurMfb4CZGDUDmjkd+dKngoOnv9u2VU8rAst2HijZh0="; }; build-system = [ hatchling ]; diff --git a/pkgs/development/python-modules/cyclopts/default.nix b/pkgs/development/python-modules/cyclopts/default.nix index 9c0da004b787..2f31add226c5 100644 --- a/pkgs/development/python-modules/cyclopts/default.nix +++ b/pkgs/development/python-modules/cyclopts/default.nix @@ -28,14 +28,14 @@ buildPythonPackage (finalAttrs: { pname = "cyclopts"; - version = "4.23.3"; + version = "4.24.0"; pyproject = true; src = fetchFromGitHub { owner = "BrianPugh"; repo = "cyclopts"; tag = "v${finalAttrs.version}"; - hash = "sha256-oNZlmEgiNJ714QklZ3U7XwuYGjAfOx6F7J5GsK0qON8="; + hash = "sha256-2+UcktWF5/E+fcGRmxTz6ef3oT9vUixC5jLNn4QQFMM="; }; pythonRelaxDeps = [ "rich-rst" ]; diff --git a/pkgs/development/python-modules/iamdata/default.nix b/pkgs/development/python-modules/iamdata/default.nix index 350b92c53500..2433a0a6a7bf 100644 --- a/pkgs/development/python-modules/iamdata/default.nix +++ b/pkgs/development/python-modules/iamdata/default.nix @@ -8,14 +8,14 @@ buildPythonPackage (finalAttrs: { pname = "iamdata"; - version = "0.1.202609031"; + version = "0.1.202609041"; pyproject = true; src = fetchFromGitHub { owner = "cloud-copilot"; repo = "iam-data-python"; tag = "v${finalAttrs.version}"; - hash = "sha256-bcoZunL72CNZB/xP55o5I8/S5ZZrYmgLHiSIzaXFOio="; + hash = "sha256-O+jk2r0KFCK56MuRa33XmrIEHKvgyr2SnQo4byRVMoc="; }; __darwinAllowLocalNetworking = true; diff --git a/pkgs/development/python-modules/mypy-boto3/default.nix b/pkgs/development/python-modules/mypy-boto3/default.nix index c576b05179d3..bae6c4510994 100644 --- a/pkgs/development/python-modules/mypy-boto3/default.nix +++ b/pkgs/development/python-modules/mypy-boto3/default.nix @@ -335,8 +335,8 @@ in "sha256-3JYcWKFk0dKJg/qn+EBvxeAO5xh5PXCU3dTEWDr1oXI="; mypy-boto3-connect = - buildMypyBoto3Package "connect" "1.43.84" - "sha256-ydNsiq5TJMyLouSgRMvmuYtQVY1IPFKtQ45awtaOpkg="; + buildMypyBoto3Package "connect" "1.43.88" + "sha256-nwCOd292NPwPsLsrHRg29a2MRO+Hh8h2H5WK1xb9CdU="; mypy-boto3-connect-contact-lens = buildMypyBoto3Package "connect-contact-lens" "1.43.79" @@ -423,8 +423,8 @@ in "sha256-67KqkSc8oUjKhuvQW6glmb211JZd+xkF03Mt8FISE8k="; mypy-boto3-drs = - buildMypyBoto3Package "drs" "1.43.73" - "sha256-qFlhBteatF0GN4ri990RBfLD05dT9IVNBN1mNX77wJw="; + buildMypyBoto3Package "drs" "1.43.88" + "sha256-NiIdpQFSOXIehaU3CHmbAXKQtN987CKXS8rALs5Yd84="; mypy-boto3-ds = buildMypyBoto3Package "ds" "1.43.0" @@ -459,16 +459,16 @@ in "sha256-02BUkAFhr9sT8ohkJJFPYNni0O9/UI/G0GUee/Kx5Dw="; mypy-boto3-ecs = - buildMypyBoto3Package "ecs" "1.43.83" - "sha256-zv9tbfBPI2OWAR3NHyllDRDsoqrQY35kSW/4jZcKXL4="; + buildMypyBoto3Package "ecs" "1.43.88" + "sha256-ISRYYfs2nEW/dt9uqkVz7ZPshfO6VjZDfw/iDP7hqlQ="; mypy-boto3-efs = buildMypyBoto3Package "efs" "1.43.23" "sha256-11KpPRxGId76g/I4jXwMQ55kwGEQVsasgvMUXsiLbM4="; mypy-boto3-eks = - buildMypyBoto3Package "eks" "1.43.80" - "sha256-pnWwk+ZoYbSqaWUt11IILs9dyGoRL+G4mrRwgUgQMw0="; + buildMypyBoto3Package "eks" "1.43.88" + "sha256-SqRuidD6RQLjGow/AXhpvYiM5+tkBBDBT6F9nAhHs6I="; mypy-boto3-elastic-inference = buildMypyBoto3Package "elastic-inference" "1.36.0" @@ -491,8 +491,8 @@ in "sha256-ft2sKNwhMdRhms/ZXOetpR/gnB3YNYGsbQWQySagk2E="; mypy-boto3-elbv2 = - buildMypyBoto3Package "elbv2" "1.43.54" - "sha256-ca2dDyh5WqJKkLCLcOv4Mhymlwy+WlEkvrhcOlYcXi0="; + buildMypyBoto3Package "elbv2" "1.43.88" + "sha256-gwGI01weMHiIFmvWL7AM4Dva6Qu2k0o1jADy71MvKcQ="; mypy-boto3-emr = buildMypyBoto3Package "emr" "1.43.50" @@ -590,8 +590,8 @@ in "sha256-+DDeD9YWo98meLZU2Mzu5AE0S7HFg6kfxeUWUh9XcQA="; mypy-boto3-guardduty = - buildMypyBoto3Package "guardduty" "1.43.86" - "sha256-TZggEBYh+bqQ5EH+LZzzCjnVbB+s+rL2KHPLvUNmhCg="; + buildMypyBoto3Package "guardduty" "1.43.88" + "sha256-UjHoeDHvr2QKwUQ2NEMoE38Lxa/vAiUNmJqp1XaVP5Q="; mypy-boto3-health = buildMypyBoto3Package "health" "1.43.0" @@ -1318,8 +1318,8 @@ in "sha256-rMrmybKplGKYPFr1cIQaHRs/bwcKFYlFWCQRe7PxXOk="; mypy-boto3-stepfunctions = - buildMypyBoto3Package "stepfunctions" "1.43.7" - "sha256-vu4gaGfa504vH0UFXiynyAA/UCzQxbMd14QSl1jmHk4="; + buildMypyBoto3Package "stepfunctions" "1.43.88" + "sha256-CfFmSJQ5iH8LIwDpEBzUacftP5N8cyE7M/YNxcp6SrA="; mypy-boto3-storagegateway = buildMypyBoto3Package "storagegateway" "1.43.0" @@ -1362,12 +1362,12 @@ in "sha256-fc0e8DEx/b6M3kPB4Y07qqqMayg2BGSQ69gkuhcrl9Y="; mypy-boto3-transcribe = - buildMypyBoto3Package "transcribe" "1.43.20" - "sha256-zk62JmlBT6nmRYoTZ3j7ThgbqjqTv0UOK3A+vZZlkRE="; + buildMypyBoto3Package "transcribe" "1.43.88" + "sha256-j0jjna9RrTHQRzwwJ8tR82161XXYRc2CJKWYzninfGA="; mypy-boto3-transfer = - buildMypyBoto3Package "transfer" "1.43.0" - "sha256-tC7uaKRyBaeJRefCknpR+CHWyTmV3DxuauCaAj37hV0="; + buildMypyBoto3Package "transfer" "1.43.88" + "sha256-19TDWG2CxiHrVgT9TrnEFLYU/PhjtxkOmGfeQi2KG8k="; mypy-boto3-translate = buildMypyBoto3Package "translate" "1.43.0" diff --git a/pkgs/development/python-modules/netio/default.nix b/pkgs/development/python-modules/netio/default.nix index 9b04bf2e6595..369cb6d3df88 100644 --- a/pkgs/development/python-modules/netio/default.nix +++ b/pkgs/development/python-modules/netio/default.nix @@ -7,25 +7,23 @@ requests, }: -buildPythonPackage rec { +buildPythonPackage (finalAttrs: { pname = "netio"; - version = "1.0.13"; + version = "2.0.1"; pyproject = true; src = fetchFromGitHub { owner = "netioproducts"; repo = "PyNetio"; - tag = "v${version}"; - hash = "sha256-s/X2WGhQXYsbo+ZPpkVSF/vclaThYYNHu0UY0yCnfPA="; + tag = "v${finalAttrs.version}"; + hash = "sha256-OmYSa8boZPAqw1PXc3BmLAxGiNgnAYiXbHTk5QF/5b8="; }; - nativeBuildInputs = [ - poetry-core - ]; - pythonRelaxDeps = [ "pyopenssl" ]; - propagatedBuildInputs = [ + build-system = [ poetry-core ]; + + dependencies = [ requests pyopenssl ]; @@ -37,10 +35,10 @@ buildPythonPackage rec { meta = { description = "Module for interacting with NETIO devices"; - mainProgram = "Netio"; homepage = "https://github.com/netioproducts/PyNetio"; - changelog = "https://github.com/netioproducts/PyNetio/blob/v${version}/CHANGELOG.md"; + changelog = "https://github.com/netioproducts/PyNetio/blob/v${finalAttrs.src.tag}/CHANGELOG.md"; license = lib.licenses.mit; maintainers = with lib.maintainers; [ fab ]; + mainProgram = "Netio"; }; -} +}) diff --git a/pkgs/development/python-modules/publicsuffixlist/default.nix b/pkgs/development/python-modules/publicsuffixlist/default.nix index 9d5f5dc00a7a..4943437a4adb 100644 --- a/pkgs/development/python-modules/publicsuffixlist/default.nix +++ b/pkgs/development/python-modules/publicsuffixlist/default.nix @@ -11,12 +11,12 @@ buildPythonPackage (finalAttrs: { pname = "publicsuffixlist"; - version = "1.0.2.20260902"; + version = "1.0.2.20260903"; pyproject = true; src = fetchPypi { inherit (finalAttrs) pname version; - hash = "sha256-3ldVc/T1/r+dACpKmWR8jJxRNxiQat7A74bnueLrB6c="; + hash = "sha256-zAj1xclqZgnxo907ZRxtd+KKkCeM8pslLP7sybAEi5o="; }; postPatch = '' diff --git a/pkgs/development/python-modules/pysnmp-pyasn1/default.nix b/pkgs/development/python-modules/pysnmp-pyasn1/default.nix index 2014d670066f..3a179b0045df 100644 --- a/pkgs/development/python-modules/pysnmp-pyasn1/default.nix +++ b/pkgs/development/python-modules/pysnmp-pyasn1/default.nix @@ -2,23 +2,23 @@ lib, buildPythonPackage, fetchFromGitHub, - poetry-core, + hatchling, pytestCheckHook, }: -buildPythonPackage rec { +buildPythonPackage (finalAttrs: { pname = "pysnmp-pyasn1"; - version = "1.1.3"; + version = "1.2.0"; pyproject = true; src = fetchFromGitHub { owner = "pysnmp"; repo = "pyasn1"; - tag = "v${version}"; - hash = "sha256-W74aWMqGlat+aZfhbP1cTKRz7SomHdGwfK5yJwxgyqI="; + tag = "v${finalAttrs.version}"; + hash = "sha256-o+YVlLs0xIKOcpFANGlSSpbK3YGBDDNOdlYvH1OliYM="; }; - nativeBuildInputs = [ poetry-core ]; + nativeBuildInputs = [ hatchling ]; nativeCheckInputs = [ pytestCheckHook ]; @@ -27,8 +27,8 @@ buildPythonPackage rec { meta = { description = "Python ASN.1 encoder and decoder"; homepage = "https://github.com/pysnmp/pyasn1"; - changelog = "https://github.com/pysnmp/pyasn1/releases/tag/v${version}"; + changelog = "https://github.com/pysnmp/pyasn1/releases/tag/${finalAttrs.src.tag}"; license = lib.licenses.bsd2; maintainers = with lib.maintainers; [ fab ]; }; -} +}) diff --git a/pkgs/development/python-modules/shacl2code/default.nix b/pkgs/development/python-modules/shacl2code/default.nix index 748be754897e..fcf68d7533ba 100644 --- a/pkgs/development/python-modules/shacl2code/default.nix +++ b/pkgs/development/python-modules/shacl2code/default.nix @@ -18,7 +18,7 @@ buildPythonPackage (finalAttrs: { pname = "shacl2code"; - version = "1.2.0"; + version = "1.3.2"; pyproject = true; __structuredAttrs = true; @@ -27,7 +27,7 @@ buildPythonPackage (finalAttrs: { owner = "JPEWdev"; repo = "shacl2code"; tag = "v${finalAttrs.version}"; - hash = "sha256-YGZLvJRoA0sMjTvYYChZMWtERjXLWgHe1WgzNEG9xGc="; + hash = "sha256-N6coxDngvaDOSZaETT7amjJQtQeorMVfa1qTM45H3gY="; }; build-system = [ hatchling ]; diff --git a/pkgs/development/python-modules/slack-sdk/default.nix b/pkgs/development/python-modules/slack-sdk/default.nix index f9bc7f2c38fb..4039fc1fe2f1 100644 --- a/pkgs/development/python-modules/slack-sdk/default.nix +++ b/pkgs/development/python-modules/slack-sdk/default.nix @@ -18,14 +18,14 @@ buildPythonPackage (finalAttrs: { pname = "slack-sdk"; - version = "3.44.0"; + version = "3.44.1"; pyproject = true; src = fetchFromGitHub { owner = "slackapi"; repo = "python-slack-sdk"; tag = "v${finalAttrs.version}"; - hash = "sha256-Bl3ozOiHtlEHBYwNdpP6w7PDXiRWJECimDB7Z95oDwA="; + hash = "sha256-fQJxh5AMu3/a7k6U6GS7uxJF1o27d/GgO1Lm35wX3rU="; }; build-system = [ setuptools ]; diff --git a/pkgs/development/python-modules/tencentcloud-sdk-python/default.nix b/pkgs/development/python-modules/tencentcloud-sdk-python/default.nix index 7db30cae8e1a..9b5aaa2d918f 100644 --- a/pkgs/development/python-modules/tencentcloud-sdk-python/default.nix +++ b/pkgs/development/python-modules/tencentcloud-sdk-python/default.nix @@ -9,14 +9,14 @@ buildPythonPackage (finalAttrs: { pname = "tencentcloud-sdk-python"; - version = "3.1.168"; + version = "3.1.169"; pyproject = true; src = fetchFromGitHub { owner = "TencentCloud"; repo = "tencentcloud-sdk-python"; tag = finalAttrs.version; - hash = "sha256-GykS29RD/LRlJud9U+JUl/E+MyQoFW+ee7ylAnPNz5g="; + hash = "sha256-6YDmEABE4Z/aKksyBaJPeSCfGyFNV0L8OnzSPXlpGew="; }; build-system = [ setuptools ]; diff --git a/pkgs/development/python-modules/xformers/default.nix b/pkgs/development/python-modules/xformers/default.nix index 87f624dc0806..d46224e0502b 100644 --- a/pkgs/development/python-modules/xformers/default.nix +++ b/pkgs/development/python-modules/xformers/default.nix @@ -3,6 +3,7 @@ stdenv, buildPythonPackage, fetchFromGitHub, + fetchpatch, # build-system torch, @@ -51,6 +52,16 @@ buildPythonPackage.override { stdenv = effectiveStdenv; } (finalAttrs: { hash = "sha256-UqpRHLN0INpW6sA8DbQCSeL8uhS+IoW60UPVUIh1NY0="; }; + patches = [ + # Fix `IndexError: list assignment index out of range` with torch >= 2.13 + # https://github.com/facebookresearch/xformers/commit/f06b9a7b0db97a78913ca8dc1652468a0527dc80 + (fetchpatch { + name = "xformers-fix-tests-pytorch-2.13.patch"; + url = "https://github.com/facebookresearch/xformers/commit/f06b9a7b0db97a78913ca8dc1652468a0527dc80.patch"; + hash = "sha256-QE3hmwXI3yJBgRWOHKoDUaEsFO+vuqV+DTMW7sjuURU="; + }) + ]; + # ModuleNotFoundError: No module named 'xformers.components' postPatch = '' touch xformers/components/__init__.py diff --git a/pkgs/os-specific/linux/ddcci/0001-Use-sysfs_emit-and-field-width-specifier.patch b/pkgs/os-specific/linux/ddcci/0001-Use-sysfs_emit-and-field-width-specifier.patch new file mode 100644 index 000000000000..8a9b72b66626 --- /dev/null +++ b/pkgs/os-specific/linux/ddcci/0001-Use-sysfs_emit-and-field-width-specifier.patch @@ -0,0 +1,285 @@ +From 9510aa4aebf32678884f55ae251e54012a354ed1 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Alice=20=E2=9C=A8=F0=9F=8C=99=20Luna?= +Date: Sat, 22 Aug 2026 16:26:42 +0200 +Subject: [PATCH] Use sysfs_emit and field width specifier '*' + +This fixes the build due to strncpy being removed from the kernel 7.2 +and also makes the code more readable, +since the handling of buffer overflows id done by sysfs_emit. + +Note that the documentation about reading attributes says: + +> New implementations of show() methods should only use sysfs_emit() +> or sysfs_emit_at() when formatting the value to be returned to user space. + +See: https://docs.kernel.org/filesystems/sysfs.html#reading-writing-attribute-data +from kernel 7.2.0, last revised 16 August 2011. + +This change also uses the field width specifier '*' for add_uevent_var calls. +--- + ddcci/ddcci.c | 153 +++++++++++++++++--------------------------------- + 1 file changed, 50 insertions(+), 103 deletions(-) + +diff --git a/ddcci/ddcci.c b/ddcci/ddcci.c +index 6b41eab..76a1cd3 100644 +--- a/ddcci/ddcci.c ++++ b/ddcci/ddcci.c +@@ -735,154 +735,101 @@ static ssize_t ddcci_attr_capabilities_show(struct device *dev, + char *buf) + { + struct ddcci_device *device = ddcci_verify_device(dev); +- ssize_t ret = -ENOENT; +- size_t len; + + if (likely(device != NULL)) { +- len = device->capabilities_len; +- if (unlikely(len > PAGE_SIZE)) +- len = PAGE_SIZE; +- if (len == 0) { +- ret = len; +- } else { +- memcpy(buf, device->capabilities, len); +- if (likely(len < PAGE_SIZE)) { +- buf[len] = '\n'; +- ret = len+1; +- } +- } +- } ++ if (device->capabilities_len == 0) ++ return 0; + +- return ret; ++ return sysfs_emit(buf, "%.*s\n", (int)device->capabilities_len, device->capabilities); ++ } ++ return -ENOENT; + } + + static ssize_t ddcci_attr_prot_show(struct device *dev, + struct device_attribute *attr, char *buf) + { + struct ddcci_device *device = ddcci_verify_device(dev); +- ssize_t ret = -ENOENT; +- size_t len; + + if (likely(device != NULL)) { +- len = strnlen(device->prot, sizeof(device->prot)); +- strncpy(buf, device->prot, PAGE_SIZE); +- if (len == 0) { +- ret = len; +- } else if (likely(len < PAGE_SIZE)) { +- buf[len] = '\n'; +- ret = len+1; +- } else { +- ret = PAGE_SIZE; +- } ++ if (device->prot[0] == '\0') ++ return 0; ++ ++ return sysfs_emit(buf, "%.*s\n", (int)sizeof(device->prot), device->prot); + } +- return ret; ++ return -ENOENT; + } + + static ssize_t ddcci_attr_type_show(struct device *dev, + struct device_attribute *attr, char *buf) + { + struct ddcci_device *device = ddcci_verify_device(dev); +- ssize_t ret = -ENOENT; +- size_t len; + + if (likely(device != NULL)) { +- len = strnlen(device->type, sizeof(device->type)); +- strncpy(buf, device->type, PAGE_SIZE); +- if (len == 0) { +- ret = len; +- } else if (likely(len < PAGE_SIZE)) { +- buf[len] = '\n'; +- ret = len+1; +- } else { +- ret = PAGE_SIZE; +- } ++ if (device->type[0] == '\0') ++ return 0; ++ ++ return sysfs_emit(buf, "%.*s\n", (int)sizeof(device->type), device->type); + } +- return ret; ++ return -ENOENT; + } + + static ssize_t ddcci_attr_model_show(struct device *dev, + struct device_attribute *attr, char *buf) + { + struct ddcci_device *device = ddcci_verify_device(dev); +- ssize_t ret = -ENOENT; +- size_t len; + + if (likely(device != NULL)) { +- len = strnlen(device->model, sizeof(device->model)); +- strncpy(buf, device->model, PAGE_SIZE); +- if (len == 0) { +- ret = len; +- } else if (likely(len < PAGE_SIZE)) { +- buf[len] = '\n'; +- ret = len+1; +- } else { +- ret = PAGE_SIZE; +- } ++ if (device->model[0] == '\0') ++ return 0; ++ ++ return sysfs_emit(buf, "%.*s\n", (int)sizeof(device->model), device->model); + } +- return ret; ++ return -ENOENT; + } + + static ssize_t ddcci_attr_vendor_show(struct device *dev, + struct device_attribute *attr, char *buf) + { + struct ddcci_device *device = ddcci_verify_device(dev); +- ssize_t ret = -ENOENT; +- size_t len; + + if (likely(device != NULL)) { +- len = strnlen(device->vendor, sizeof(device->vendor)); +- strncpy(buf, device->vendor, PAGE_SIZE); +- if (len == 0) { +- ret = len; +- } else if (likely(len < PAGE_SIZE)) { +- buf[len] = '\n'; +- ret = len+1; +- } else { +- ret = PAGE_SIZE; +- } ++ if (device->vendor[0] == '\0') ++ return 0; ++ ++ return sysfs_emit(buf, "%.*s\n", (int)sizeof(device->vendor), device->vendor); + } +- return ret; ++ return -ENOENT; + } + + static ssize_t ddcci_attr_module_show(struct device *dev, + struct device_attribute *attr, char *buf) + { + struct ddcci_device *device = ddcci_verify_device(dev); +- ssize_t ret = -ENOENT; +- size_t len; + + if (likely(device != NULL)) { +- len = strnlen(device->module, sizeof(device->module)); +- strncpy(buf, device->module, PAGE_SIZE); +- if (len == 0) { +- ret = len; +- } else if (likely(len < PAGE_SIZE)) { +- buf[len] = '\n'; +- ret = len+1; +- } else { +- ret = PAGE_SIZE; +- } ++ if (device->module[0] == '\0') ++ return 0; ++ ++ return sysfs_emit(buf, "%.*s\n", (int)sizeof(device->module), device->module); + } +- return ret; ++ return -ENOENT; + } + + static ssize_t ddcci_attr_serial_show(struct device *dev, + struct device_attribute *attr, char *buf) + { + struct ddcci_device *device = ddcci_verify_device(dev); +- ssize_t ret = -ENOENT; + + if (likely(device != NULL)) +- ret = scnprintf(buf, PAGE_SIZE, "%d\n", device->device_number); ++ return sysfs_emit(buf, "%d\n", device->device_number); + +- return ret; ++ return -ENOENT; + } + + static ssize_t ddcci_attr_modalias_show(struct device *dev, + struct device_attribute *attr, char *buf) + { + struct ddcci_device *device = ddcci_verify_device(dev); +- ssize_t ret = -ENOENT; + char model[ARRAY_SIZE(device->model)]; + char vendor[ARRAY_SIZE(device->model)]; + char module[ARRAY_SIZE(device->model)]; +@@ -895,16 +842,16 @@ static ssize_t ddcci_attr_modalias_show(struct device *dev, + ddcci_modalias_clean(vendor, sizeof(vendor), '_'); + ddcci_modalias_clean(module, sizeof(module), '_'); + +- ret = scnprintf(buf, PAGE_SIZE, "%s%s-%s-%s-%s-%s\n", ++ return sysfs_emit(buf, "%s%.*s-%.*s-%.*s-%.*s-%.*s\n", + DDCCI_MODULE_PREFIX, +- device->prot, +- device->type, +- model, +- vendor, +- module ++ (int)sizeof(device->prot), device->prot, ++ (int)sizeof(device->type), device->type, ++ (int)sizeof(model), model, ++ (int)sizeof(vendor), vendor, ++ (int)sizeof(module), module + ); + } +- return ret; ++ return -ENOENT; + } + + static DEVICE_ATTR(capabilities, S_IRUGO, ddcci_attr_capabilities_show, NULL); +@@ -945,33 +892,33 @@ static int ddcci_device_uevent(CSTRUCT device *dev, struct kobj_uevent_env *env) + ddcci_modalias_clean(vendor, sizeof(vendor), '_'); + ddcci_modalias_clean(module, sizeof(module), '_'); + +- if (add_uevent_var(env, "MODALIAS=%s%s-%s-%s-%s-%s", ++ if (add_uevent_var(env, "MODALIAS=%s%.*s-%.*s-%.*s-%.*s-%.*s", + DDCCI_MODULE_PREFIX, +- device->prot, +- device->type, +- model, +- vendor, +- module ++ (int)sizeof(device->prot), device->prot, ++ (int)sizeof(device->type), device->type, ++ (int)sizeof(model), model, ++ (int)sizeof(vendor), vendor, ++ (int)sizeof(module), module + )) + return -ENOMEM; + + if (device->prot[0]) +- if (add_uevent_var(env, "DDCCI_PROT=%s", device->prot)) ++ if (add_uevent_var(env, "DDCCI_PROT=%.*s", (int)sizeof(device->prot), device->prot)) + return -ENOMEM; + + if (device->type[0]) +- if (add_uevent_var(env, "DDCCI_TYPE=%s", device->type)) ++ if (add_uevent_var(env, "DDCCI_TYPE=%.*s", (int)sizeof(device->type), device->type)) + return -ENOMEM; + + if (device->model[0]) +- if (add_uevent_var(env, "DDCCI_MODEL=%s", device->model)) ++ if (add_uevent_var(env, "DDCCI_MODEL=%.*s", (int)sizeof(device->model), device->model)) + return -ENOMEM; + + if (device->vendor[0]) { +- if (add_uevent_var(env, "DDCCI_VENDOR=%s", device->vendor)) ++ if (add_uevent_var(env, "DDCCI_VENDOR=%.*s", (int)sizeof(device->vendor), device->vendor)) + return -ENOMEM; + +- if (add_uevent_var(env, "DDCCI_MODULE=%s", device->module)) ++ if (add_uevent_var(env, "DDCCI_MODULE=%.*s", (int)sizeof(device->module), device->module)) + return -ENOMEM; + + if (add_uevent_var(env, "DDCCI_UNIQ=%d", device->device_number)) +-- +2.54.0 + diff --git a/pkgs/os-specific/linux/ddcci/default.nix b/pkgs/os-specific/linux/ddcci/default.nix index fbef48622ac2..40754474d793 100644 --- a/pkgs/os-specific/linux/ddcci/default.nix +++ b/pkgs/os-specific/linux/ddcci/default.nix @@ -31,6 +31,10 @@ stdenv.mkDerivation rec { --replace depmod \# ''; + patches = [ + ./0001-Use-sysfs_emit-and-field-width-specifier.patch + ]; + makeFlags = kernelModuleMakeFlags ++ [ "KDIR=${kernel.dev}/lib/modules/${kernel.modDirVersion}/build" "KVER=${kernel.modDirVersion}" diff --git a/pkgs/servers/http/nginx/module-aliases.nix b/pkgs/servers/http/nginx/module-aliases.nix index 9ddc1e7c1997..e0c2018765b3 100644 --- a/pkgs/servers/http/nginx/module-aliases.nix +++ b/pkgs/servers/http/nginx/module-aliases.nix @@ -3,6 +3,7 @@ self: { # keep-sorted start case=no numeric=yes block=yes + auth-a2aclr = throw "auth-a2aclr was removed because its upstream is unmaintained and its pinned arpa2common dependency no longer builds"; # Added 2026-09-02 fastcgi-cache-purge = throw "fastcgi-cache-purge was renamed to cache-purge"; fluentd = throw "fluentd was removed due to lack of maintenance"; # Added 2026-08-02 http_proxy_connect_module_v24 = throw "http_proxy_connect_module_v24 was removed because it was not compatible with any supported nginx version"; # Added 2026-07-29 diff --git a/pkgs/servers/http/nginx/modules/auth-a2aclr/package.nix b/pkgs/servers/http/nginx/modules/auth-a2aclr/package.nix deleted file mode 100644 index 69ce5288d03c..000000000000 --- a/pkgs/servers/http/nginx/modules/auth-a2aclr/package.nix +++ /dev/null @@ -1,39 +0,0 @@ -{ - fetchFromGitLab, - lib, - mkNginxPlugin, - arpa2common, -}: - -mkNginxPlugin (finalAttrs: { - pname = "auth-a2aclr"; - version = "0-unstable-2020-08-03"; - - src = fetchFromGitLab { - owner = "arpa2"; - repo = "nginx-auth-a2aclr"; - rev = "bbabf9480bb2b40ac581551883a18dfa6522dd63"; - hash = "sha256-h2LgMhreCgod+H/bNQzY9BvqG9ezkwikwWB3T6gHH04="; - }; - - buildInputs = [ - (arpa2common.overrideAttrs (old: rec { - version = "0.7.1"; - - src = fetchFromGitLab { - owner = "arpa2"; - repo = "arpa2common"; - rev = "v${version}"; - hash = "sha256-8zVsAlGtmya9EK4OkGUMu2FKJRn2Q3bg2QWGjqcii64="; - }; - })) - ]; - - meta = { - broken = true; # overridden arpa2common package fails to build - description = "Integrate ARPA2 Resource ACLs into nginx"; - homepage = "https://gitlab.com/arpa2/nginx-auth-a2aclr"; - license = lib.licenses.isc; - maintainers = [ ]; - }; -}) diff --git a/pkgs/top-level/aliases.nix b/pkgs/top-level/aliases.nix index a8744aaec129..c32920c8febd 100644 --- a/pkgs/top-level/aliases.nix +++ b/pkgs/top-level/aliases.nix @@ -2766,6 +2766,7 @@ mapAliases { xmonad_log_applet = warnAlias "'xmonad_log_applet' has been renamed to 'xmonad-log-applet'" xmonad-log-applet; # Added 2026-07-27 xmonad_log_applet_mate = warnAlias "'xmonad_log_applet_mate' has been renamed to 'xmonad-log-applet-mate'" xmonad-log-applet-mate; # Added 2026-07-27 xmonad_log_applet_xfce = warnAlias "'xmonad_log_applet_xfce' has been renamed to 'xmonad-log-applet-xfce'" xmonad-log-applet-xfce; # Added 2026-07-27 + xmpp-bridge = throw "'xmpp-bridge' has been removed as it is unmaintained upstream."; # Added 2026-09-04 xneur = throw "'xneur' has been removed as it is unmaintained and depends on pcre, which is deprecated"; # Added 2026-06-06 xo = throw "Use 'dbtpl' instead of 'xo'"; # Added 2025-09-28 xonsh-unwrapped = throw "'xonsh-unwrapped' has been renamed to/replaced by 'python3Packages.xonsh'"; # Converted to throw 2025-10-27