diff --git a/.github/workflows/backport.yml b/.github/workflows/backport.yml
index 5805401b08c7..ba5c06452664 100644
--- a/.github/workflows/backport.yml
+++ b/.github/workflows/backport.yml
@@ -39,6 +39,8 @@ jobs:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
ref: ${{ github.event.pull_request.head.sha }}
+ # Avoid materializing full nixpkgs tree
+ sparse-checkout: .
token: ${{ steps.app-token.outputs.token }}
persist-credentials: true
diff --git a/doc/release-notes/rl-2611.section.md b/doc/release-notes/rl-2611.section.md
index 24941676a336..f6d4cabc93c4 100644
--- a/doc/release-notes/rl-2611.section.md
+++ b/doc/release-notes/rl-2611.section.md
@@ -16,6 +16,8 @@
+nixpkgs.url = "https://channels.nixos.org/nixos-26.05/nixexprs.tar.zst";
```
+- `sing-box` now supports NaïveProxy outbounds.
+
## Backward Incompatibilities {#sec-nixpkgs-release-26.11-incompatibilities}
diff --git a/maintainers/maintainer-list.nix b/maintainers/maintainer-list.nix
index 2a041719c32e..4b90c38188dc 100644
--- a/maintainers/maintainer-list.nix
+++ b/maintainers/maintainer-list.nix
@@ -18938,6 +18938,11 @@
githubId = 45770;
name = "Mitsuhiro Nakamura";
};
+ mnixry = {
+ github = "mnixry";
+ githubId = 32300164;
+ name = "Mix";
+ };
MNThomson = {
github = "MNThomson";
githubId = 73045936;
diff --git a/nixos/doc/manual/release-notes/rl-2611.section.md b/nixos/doc/manual/release-notes/rl-2611.section.md
index 034b4a9dfd62..9aeec853c539 100644
--- a/nixos/doc/manual/release-notes/rl-2611.section.md
+++ b/nixos/doc/manual/release-notes/rl-2611.section.md
@@ -18,6 +18,8 @@
+nixpkgs.url = "https://channels.nixos.org/nixos-26.05/nixexprs.tar.zst";
```
+- `sing-box` now supports NaïveProxy outbounds.
+
## New Modules {#sec-release-26.11-new-modules}
diff --git a/nixos/modules/services/web-apps/jirafeau.nix b/nixos/modules/services/web-apps/jirafeau.nix
index c1accf047c10..3ebb9beab22e 100644
--- a/nixos/modules/services/web-apps/jirafeau.nix
+++ b/nixos/modules/services/web-apps/jirafeau.nix
@@ -52,7 +52,7 @@ in
'';
description =
let
- documentationLink = "https://gitlab.com/mojo42/Jirafeau/-/blob/${cfg.package.version}/lib/config.original.php";
+ documentationLink = "https://gitlab.com/jirafeau/Jirafeau/-/blob/${cfg.package.version}/lib/config.original.php";
in
''
Jirefeau configuration. Refer to <${documentationLink}> for supported
diff --git a/nixos/modules/system/boot/loader/limine/limine-install.py b/nixos/modules/system/boot/loader/limine/limine-install.py
index dacf4a339d0e..ba6cd4fc8356 100644
--- a/nixos/modules/system/boot/loader/limine/limine-install.py
+++ b/nixos/modules/system/boot/loader/limine/limine-install.py
@@ -1,4 +1,4 @@
-#!@python3@/bin/python3 -B
+#!@python3@/bin/python3 -BP
from dataclasses import dataclass
from typing import Any, Dict, List, Optional, Tuple
diff --git a/nixos/modules/system/service/systemd/service.nix b/nixos/modules/system/service/systemd/service.nix
index e7fa338ff97b..76814d419931 100644
--- a/nixos/modules/system/service/systemd/service.nix
+++ b/nixos/modules/system/service/systemd/service.nix
@@ -118,18 +118,20 @@ in
Main command line for systemd's ExecReload with systemd's specifier and
environment variable substitution enabled.
- This option sets the primary ExecRestart entry. Additional ExecReload entries
- can be added via `systemd.service.serviceConfig.ExecReload` with `lib.mkBefore`
- or `lib.mkAfter`.
+ This option sets the primary ExecReload entry, and is the way to extend the
+ command line derived from {option}`process.reloadCommand`.
This option allows you to use systemd specifiers like `%n` (unit name),
`%i` (instance), `%t` (runtime directory), and environment variables using
`''${VAR}` syntax in your command line.
- By default, it is set to {option}`process.reloadCommand` when specified, or an
- empty string otherwise. Because {option}`process.reloadCommand` is already a
- command line (not an argument list), it is used verbatim so that references
- like `$MAINPID` are preserved.
+ By default, it is set to {option}`process.reloadCommand`. Because
+ {option}`process.reloadCommand` is already a command line (not an argument
+ list), it is used verbatim so that references like `$MAINPID` are preserved.
+
+ When {option}`process.reloadCommand` is unset, this option is `null` and no
+ `ExecReload` is emitted; a service may then set
+ `systemd.service.serviceConfig.ExecReload` itself.
To extend {option}`process.reloadCommand` with systemd specifiers, you can append
to the command line:
@@ -147,7 +149,7 @@ in
for available specifiers like `%n`, `%i`, `%t`.
'';
type = types.nullOr types.str;
- default = if config.process.reloadCommand != null then config.process.reloadCommand else "";
+ default = config.process.reloadCommand;
defaultText = lib.literalExpression "config.process.reloadCommand";
};
@@ -208,7 +210,7 @@ in
# TODO description;
wantedBy = lib.mkDefault [ "multi-user.target" ];
serviceConfig = {
- ExecReload = config.systemd.mainExecReload;
+ ExecReload = lib.mkIf (config.systemd.mainExecReload != null) config.systemd.mainExecReload;
Type = lib.mkDefault (if config.notificationProtocol.systemd then "notify" else "simple");
Restart = lib.mkDefault "always";
RestartSec = lib.mkDefault "5";
diff --git a/nixos/tests/freescout/integration.nix b/nixos/tests/freescout/integration.nix
index 57d28f032c3a..c3226f8488a9 100644
--- a/nixos/tests/freescout/integration.nix
+++ b/nixos/tests/freescout/integration.nix
@@ -26,7 +26,6 @@ let
...
}:
{
- virtualisation.memorySize = 1024;
environment.systemPackages = with pkgs; [
curl
sendInitial
@@ -99,7 +98,7 @@ let
};
};
- mkNode =
+ mkContainer =
dbType:
{ config, pkgs, ... }:
{
@@ -118,14 +117,14 @@ in
e1mo
];
- nodes = {
+ containers = {
# This may lead to duplicate tests, but ensures that
# it's always tested on the current default version
# even if the tests are not updated
- freescout_pgsql = mkNode "pgsql";
+ freescout-pgsql = mkContainer "pgsql";
# Same as the freescout_pgsql_default node
- freescout_mysql = mkNode "mysql";
+ freescout-mysql = mkContainer "mysql";
};
testScript = ''
@@ -151,7 +150,7 @@ in
machine.wait_for_unit("freescout-setup")
with subtest("Login works"):
- machine.succeed("/var/lib/freescout/artisan freescout:create-user --role=admin --firstName=Xenia --lastName=TheFox --email xenia@${freescoutDomain} --no-interaction --password=foo | grep 'User created with id'")
+ machine.succeed("/var/lib/freescout/artisan -- freescout:create-user --role=admin --firstName=Xenia --lastName=TheFox --email xenia@${freescoutDomain} --no-interaction --password=foo | grep 'User created with id'")
token=machine.succeed("curl -fsSL --cookie-jar cjar 'http://${freescoutDomain}/login' | grep -Po '(?<= name=\"_token\" value=\")(\\w+)(?=\")'").strip()
data=f"email=xenia%40${freescoutDomain}&password=foo&_token={token}&remember=on"
machine.succeed(f"curl -sSfX POST --cookie-jar cjar --cookie cjar --data-raw '{data}' 'http://${freescoutDomain}/login' | grep 'Redirecting to'")
diff --git a/nixos/tests/freescout/upgrade.nix b/nixos/tests/freescout/upgrade.nix
index 397788710bf1..0cfb9f703b8a 100644
--- a/nixos/tests/freescout/upgrade.nix
+++ b/nixos/tests/freescout/upgrade.nix
@@ -73,7 +73,7 @@ in
with subtest("Create user and log in"):
# Create uesr
- machine.succeed("/var/lib/freescout/artisan freescout:create-user --role=admin --firstName=Xenia --lastName=TheFox --email xenia@${freescoutDomain} --no-interaction --password=foo | grep 'User created with id'")
+ machine.succeed("/var/lib/freescout/artisan -- freescout:create-user --role=admin --firstName=Xenia --lastName=TheFox --email xenia@${freescoutDomain} --no-interaction --password=foo | grep 'User created with id'")
# Obtain CSRF token
token=machine.succeed("curl -fsSL --cookie-jar cjar 'http://${freescoutDomain}/login' | grep -Po '(?<= name=\"_token\" value=\")(\w+)(?=\")'").strip()
# Actually log in
diff --git a/nixos/tests/installed-tests/xdg-desktop-portal.nix b/nixos/tests/installed-tests/xdg-desktop-portal.nix
index a85203fe3eda..dabc2fb306e0 100644
--- a/nixos/tests/installed-tests/xdg-desktop-portal.nix
+++ b/nixos/tests/installed-tests/xdg-desktop-portal.nix
@@ -22,6 +22,7 @@ makeInstalledTest {
environment.systemPackages = with pkgs; [
umockdev
wireless-regdb
+ bubblewrap
];
services.geoclue2 = {
enable = true;
diff --git a/nixos/tests/jirafeau.nix b/nixos/tests/jirafeau.nix
index ebbd637a13ec..b723b1652c1a 100644
--- a/nixos/tests/jirafeau.nix
+++ b/nixos/tests/jirafeau.nix
@@ -18,5 +18,20 @@
machine.wait_for_unit("nginx.service")
machine.wait_for_open_port(80)
machine.succeed("curl -sSfL http://localhost/ | grep 'Jirafeau'")
+
+ machine.succeed("printf '%s' '' > /tmp/preview.svg")
+ link = machine.succeed(
+ "curl --fail --silent --show-error "
+ "-F time=month -F 'file=@/tmp/preview.svg;type=image' "
+ "http://localhost/script.php"
+ ).splitlines()[0]
+ headers = machine.succeed(
+ f"curl --fail --silent --show-error --dump-header - "
+ f"--output /tmp/preview-response 'http://localhost/f.php?h={link}&p=1'"
+ )
+ header_lines = {line.lower() for line in headers.splitlines()}
+ assert "x-content-type-options: nosniff" in header_lines
+ assert "content-type: image" in header_lines
+ machine.succeed("cmp /tmp/preview.svg /tmp/preview-response")
'';
}
diff --git a/nixos/tests/kanidm-provisioning.nix b/nixos/tests/kanidm-provisioning.nix
index 133bd0d10cb2..78b0ff5ad05c 100644
--- a/nixos/tests/kanidm-provisioning.nix
+++ b/nixos/tests/kanidm-provisioning.nix
@@ -18,7 +18,7 @@ in
name = "kanidm-provisioning-${kanidmPackage.version}";
meta.maintainers = with pkgs.lib.maintainers; [ oddlama ];
- _module.args.kanidmPackage = pkgs.lib.mkDefault pkgs.kanidmWithSecretProvisioning_1_10;
+ _module.args.kanidmPackage = pkgs.lib.mkDefault pkgs.kanidmWithSecretProvisioning_1_11;
nodes.provision =
{ pkgs, lib, ... }:
diff --git a/nixos/tests/kanidm.nix b/nixos/tests/kanidm.nix
index 1d17d84908cf..3eaa6d0ab5bf 100644
--- a/nixos/tests/kanidm.nix
+++ b/nixos/tests/kanidm.nix
@@ -22,7 +22,7 @@ in
oddlama
];
- _module.args.kanidmPackage = pkgs.lib.mkDefault pkgs.kanidm_1_10;
+ _module.args.kanidmPackage = pkgs.lib.mkDefault pkgs.kanidm_1_11;
nodes.server =
{ pkgs, ... }:
diff --git a/nixos/tests/nextcloud/default.nix b/nixos/tests/nextcloud/default.nix
index 2cb226e353da..6c7ef18068e7 100644
--- a/nixos/tests/nextcloud/default.nix
+++ b/nixos/tests/nextcloud/default.nix
@@ -136,6 +136,8 @@ let
map callNextcloudTest (
[
./basic.nix
+ ./home-bindmount.nix
+ ./home-mount.nix
./with-declarative-redis-and-secrets.nix
./with-mysql-and-memcached.nix
./with-postgresql-and-redis.nix
diff --git a/nixos/tests/nextcloud/home-bindmount.nix b/nixos/tests/nextcloud/home-bindmount.nix
new file mode 100644
index 000000000000..a48882544508
--- /dev/null
+++ b/nixos/tests/nextcloud/home-bindmount.nix
@@ -0,0 +1,68 @@
+{
+ name,
+ pkgs,
+ testBase,
+ system,
+ ...
+}:
+
+with import ../../lib/testing-python.nix { inherit system pkgs; };
+runTest (
+ { lib, ... }:
+ {
+ inherit name;
+ meta.maintainers = lib.teams.nextcloud.members;
+
+ imports = [ testBase ];
+
+ nodes.nextcloud = { pkgs, ... }: {
+ # Make sure that inside our tmpfs mount an actual directory for Nextcloud exists.
+ boot.initrd.systemd.tmpfiles.settings."nextcloud"."/sysroot/mnt/nextcloud".d = { };
+
+ boot.initrd.systemd.mounts = [
+ # Create a mocked /mnt/nextcloud. Only a tmpfs here, but in reality this could e.g.
+ # be the mount of a larger disk.
+ {
+ unitConfig.DefaultDependencies = "no";
+ conflicts = [ "umount.target" ];
+ wantedBy = [ "initrd.target" ];
+ before = [ "systemd-tmpfiles-setup-sysroot.service" ];
+ options = "x-initrd.mount";
+ where = "/sysroot/mnt";
+ what = "tmpfs";
+ type = "tmpfs";
+ }
+ # Bind some directory to /var/lib/nextcloud, the place that the Nextcloud module expects
+ # by default.
+ {
+ conflicts = [ "umount.target" ];
+ wantedBy = [ "initrd.target" ];
+ before = [ "systemd-tmpfiles-setup-sysroot.service" ];
+ options = "x-initrd.mount,bind";
+ where = "/sysroot/var/lib/nextcloud";
+ what = "/sysroot/mnt/nextcloud";
+ type = "none";
+ }
+ ];
+ environment.systemPackages = [
+ pkgs.util-linux
+ ];
+ services.nextcloud = {
+ config.dbtype = "sqlite";
+ };
+ };
+
+ test-helpers.init = ''
+ import json
+ mnts = json.loads(nextcloud.succeed("findmnt /var/lib/nextcloud -J"))["filesystems"]
+ t.assertEqual(1, len(mnts))
+ mnt = mnts[0]
+ t.assertEqual("tmpfs[/nextcloud]", mnt["source"])
+ t.assertEqual("/var/lib/nextcloud", mnt["target"])
+ '';
+
+ test-helpers.extraTests = ''
+ nextcloud.succeed("test -d /mnt/nextcloud/data/root")
+ '';
+ }
+)
diff --git a/nixos/tests/nextcloud/home-mount.nix b/nixos/tests/nextcloud/home-mount.nix
new file mode 100644
index 000000000000..a79f2fdd97b3
--- /dev/null
+++ b/nixos/tests/nextcloud/home-mount.nix
@@ -0,0 +1,32 @@
+{
+ name,
+ pkgs,
+ testBase,
+ system,
+ ...
+}:
+
+with import ../../lib/testing-python.nix { inherit system pkgs; };
+runTest (
+ { config, lib, ... }:
+ {
+ inherit name;
+ meta.maintainers = lib.teams.nextcloud.members;
+
+ imports = [ testBase ];
+
+ nodes.nextcloud = { pkgs, ... }: {
+ system.activationScripts.nc-mock-mount = {
+ deps = [ "users" ];
+ text = ''
+ ${pkgs.coreutils}/bin/mkdir -p /mnt
+ ${pkgs.util-linux}/bin/mount -t tmpfs tmpfs /mnt
+ '';
+ };
+ services.nextcloud = {
+ config.dbtype = "sqlite";
+ home = "/mnt/nextcloud";
+ };
+ };
+ }
+)
diff --git a/nixos/tests/system-services-compliance.nix b/nixos/tests/system-services-compliance.nix
index add3593fd3a8..433a2fb7c629 100644
--- a/nixos/tests/system-services-compliance.nix
+++ b/nixos/tests/system-services-compliance.nix
@@ -81,6 +81,16 @@ let
process.reloadSignal = "HUP";
};
}).config.systemd.services;
+
+ # A service setting `ExecReload` through the systemd escape hatch, without
+ # any `process.reloadCommand` of its own.
+ ownExecReloadUnits =
+ (evalSystemServices {
+ service = {
+ process.argv = [ "${coreutils}/bin/true" ];
+ systemd.service.serviceConfig.ExecReload = "${coreutils}/bin/kill -USR2 $MAINPID";
+ };
+ }).config.systemd.services;
in
{
testDefaultType = {
@@ -97,6 +107,19 @@ let
expr = reloadUnits.service.serviceConfig.ExecReload;
expected = "${coreutils}/bin/kill -HUP $MAINPID";
};
+
+ # Without a reload command, the framework must not define `ExecReload` at
+ # all, so that it neither conflicts with a service-provided definition nor
+ # renders a bare `ExecReload=` line.
+ testNoReloadExecReloadUnset = {
+ expr = defaultUnits.service.serviceConfig ? ExecReload;
+ expected = false;
+ };
+
+ testServiceOwnExecReload = {
+ expr = ownExecReloadUnits.service.serviceConfig.ExecReload;
+ expected = "${coreutils}/bin/kill -USR2 $MAINPID";
+ };
};
systemdEval = pkgs.stdenvNoCC.mkDerivation (finalAttrs: {
diff --git a/pkgs/applications/networking/browsers/brave/packages/brave-origin.nix b/pkgs/applications/networking/browsers/brave/packages/brave-origin.nix
index 8af08a9f7eeb..326f78ee7bad 100644
--- a/pkgs/applications/networking/browsers/brave/packages/brave-origin.nix
+++ b/pkgs/applications/networking/browsers/brave/packages/brave-origin.nix
@@ -1,21 +1,21 @@
# Expression generated by update.sh; do not edit it by hand!
rec {
pname = "brave-origin";
- version = "1.92.144";
+ version = "1.93.129";
flavor = "origin";
archives = {
aarch64-linux = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-origin_${version}_arm64.deb";
- hash = "sha256-zqjpiBMogYhtuEhIlPlK8J2j9hzfd1M8RYlT/c74Na8=";
+ hash = "sha256-29NLuWH3TAUGkiiY00J+e+IGaqfIZ/g2vLI1aDXacVw=";
};
x86_64-linux = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-origin_${version}_amd64.deb";
- hash = "sha256-KF5WXF7GJPLCcEQyASEVfNrYyFJRXBSyWVPPAZPCa/E=";
+ hash = "sha256-F5d660t4t52L27gt8SF9n/54lmK+CeqZeqlbS84wjvU=";
};
aarch64-darwin = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-origin-v${version}-darwin-arm64.zip";
- hash = "sha256-kkP8cBRnC34+SjC9EvkpKcDYP3cxW7sdJgni0+zXwbk=";
+ hash = "sha256-H+UHhEPMBT/wki30DBic1jSpXI8jlddYruEs9TU0Mx8=";
};
};
}
diff --git a/pkgs/applications/networking/browsers/brave/packages/brave.nix b/pkgs/applications/networking/browsers/brave/packages/brave.nix
index c50a2fc89fcc..055bca8d9ae0 100644
--- a/pkgs/applications/networking/browsers/brave/packages/brave.nix
+++ b/pkgs/applications/networking/browsers/brave/packages/brave.nix
@@ -1,20 +1,20 @@
# Expression generated by update.sh; do not edit it by hand!
rec {
pname = "brave";
- version = "1.92.144";
+ version = "1.93.129";
archives = {
aarch64-linux = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-browser_${version}_arm64.deb";
- hash = "sha256-Z9uUJRaMx+P35oXtvAnjHyOQOXt8mW5oyyEtnD754x8=";
+ hash = "sha256-pO6vTzTv7OKcP5uJwlcc+vUdg/0Lm2Q6apnEhjRxasM=";
};
x86_64-linux = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-browser_${version}_amd64.deb";
- hash = "sha256-no/KD+3EB6CqvVWEmDB/8k2rv1wau469FBXMNWN7z6k=";
+ hash = "sha256-fOyneo8kzoGqldT6nYRzFqgy1+WhKGhcSkJQTCd4w6k=";
};
aarch64-darwin = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-v${version}-darwin-arm64.zip";
- hash = "sha256-YidWCVGP36wn1goAulSbVrKFoHI1NA/pLtfPjIXBO48=";
+ hash = "sha256-phHj7wAZKhRsqYrApNONbjM3RQBra893cDUq6e2lBrs=";
};
};
}
diff --git a/pkgs/build-support/node/prefetch-npm-deps/default.nix b/pkgs/build-support/node/prefetch-npm-deps/default.nix
index eb73907343de..2875c9291dec 100644
--- a/pkgs/build-support/node/prefetch-npm-deps/default.nix
+++ b/pkgs/build-support/node/prefetch-npm-deps/default.nix
@@ -300,8 +300,19 @@
NIX_NPM_REGISTRY_OVERRIDES = npmRegistryOverridesString;
# Fetcher version controls which features are enabled in prefetch-npm-deps
- # Version 2+ enables packument fetching for workspace support
- NPM_FETCHER_VERSION = toString fetcherVersion;
+ NPM_FETCHER_VERSION =
+ let
+ # Increment when we introduce a new version.
+ validFetcherVersions = [
+ 1 # Initial version
+ 2 # enables packument fetching for workspace support
+ ];
+ in
+ assert lib.assertMsg (lib.elem fetcherVersion validFetcherVersions)
+ "fetchNpmDeps: fetcher version must be one of: ${
+ lib.concatMapStringsSep ", " toString validFetcherVersions
+ }.";
+ (toString fetcherVersion);
SSL_CERT_FILE =
if
diff --git a/pkgs/by-name/_1/_1password-gui/sources.json b/pkgs/by-name/_1/_1password-gui/sources.json
index 7ab8898f017c..bf65e03c8848 100644
--- a/pkgs/by-name/_1/_1password-gui/sources.json
+++ b/pkgs/by-name/_1/_1password-gui/sources.json
@@ -29,28 +29,28 @@
},
"beta": {
"linux": {
- "version": "8.12.26-31.BETA",
+ "version": "8.12.32-26.BETA",
"sources": {
"x86_64": {
- "url": "https://downloads.1password.com/linux/tar/beta/x86_64/1password-8.12.26-31.BETA.x64.tar.gz",
- "hash": "sha256-jlBvt2QEOgoisC1u8WY7cEXuCgk3wKcgQ1owu02rEio="
+ "url": "https://downloads.1password.com/linux/tar/beta/x86_64/1password-8.12.32-26.BETA.x64.tar.gz",
+ "hash": "sha256-9LtsORe/o1+SxBfeGCFf6hiO1uwuBWyIjHVs2jW0FNo="
},
"aarch64": {
- "url": "https://downloads.1password.com/linux/tar/beta/aarch64/1password-8.12.26-31.BETA.arm64.tar.gz",
- "hash": "sha256-jCI5G9xGdXChGW8388BMpMfyYwxzNxYNoV2sYBj8eV4="
+ "url": "https://downloads.1password.com/linux/tar/beta/aarch64/1password-8.12.32-26.BETA.arm64.tar.gz",
+ "hash": "sha256-zyTyqTEIq4mXttyy5VCai9oBgTNo8tsmtqU+PuZOtGA="
}
}
},
"darwin": {
- "version": "8.12.26-31.BETA",
+ "version": "8.12.32-26.BETA",
"sources": {
"x86_64": {
- "url": "https://downloads.1password.com/mac/1Password-8.12.26-31.BETA-x86_64.zip",
- "hash": "sha256-TBNhnCrKVZD1CVeBZ3dZ0TVeldrRotUpXEycFnvPfZo="
+ "url": "https://downloads.1password.com/mac/1Password-8.12.32-26.BETA-x86_64.zip",
+ "hash": "sha256-PhqdUmd7EjYiYbzxuzs4Z4v2TD0S6SJPaKLvinCxcqE="
},
"aarch64": {
- "url": "https://downloads.1password.com/mac/1Password-8.12.26-31.BETA-aarch64.zip",
- "hash": "sha256-8+H9+Z7/uqlnMP2eUm7z493S6ZCEV0a5Sorw3AGTDCc="
+ "url": "https://downloads.1password.com/mac/1Password-8.12.32-26.BETA-aarch64.zip",
+ "hash": "sha256-eVkVAGQRRWv4vMnGJt+4ETAdnU6/slLXlTJgXxhNRzc="
}
}
}
diff --git a/pkgs/by-name/al/all-the-package-names/package.nix b/pkgs/by-name/al/all-the-package-names/package.nix
index fe35b7eb856f..305f8ddac1c8 100644
--- a/pkgs/by-name/al/all-the-package-names/package.nix
+++ b/pkgs/by-name/al/all-the-package-names/package.nix
@@ -7,16 +7,16 @@
buildNpmPackage rec {
pname = "all-the-package-names";
- version = "2.0.2511";
+ version = "2.0.2520";
src = fetchFromGitHub {
owner = "nice-registry";
repo = "all-the-package-names";
tag = "v${version}";
- hash = "sha256-KnEvFnPXQZ+XhNyweWIE0mjM4vqcqXcJKuus/dFq5f0=";
+ hash = "sha256-cJwYVEeiry7lmhcuE8ABrCB59MH8GZBqF34FvHUOX6M=";
};
- npmDepsHash = "sha256-Xw/SXRpQkPd+EcemeHO89tC9amDiVV/RD/1H0H8rax0=";
+ npmDepsHash = "sha256-B7UDkGEYVTmf/gny4o9YqgNuU1Zz+y6Fg2st7Khy2fo=";
passthru.updateScript = nix-update-script { };
diff --git a/pkgs/by-name/an/ani-cli/package.nix b/pkgs/by-name/an/ani-cli/package.nix
index d53722be88dd..3df8eff5aec4 100644
--- a/pkgs/by-name/an/ani-cli/package.nix
+++ b/pkgs/by-name/an/ani-cli/package.nix
@@ -28,13 +28,13 @@ in
stdenvNoCC.mkDerivation (finalAttrs: {
pname = "ani-cli";
- version = "4.14";
+ version = "5.0";
src = fetchFromGitHub {
owner = "pystardust";
repo = "ani-cli";
tag = "v${finalAttrs.version}";
- hash = "sha256-OyCKDN89sBz59+3JncMDyNOq8UMqqjara+A0Owo3oko=";
+ hash = "sha256-rRQESi0Skoyf1jy/dRRK6ooKRPQhkak107kk5ulwZYI=";
};
nativeBuildInputs = [ makeWrapper ];
diff --git a/pkgs/by-name/be/bendsql/package.nix b/pkgs/by-name/be/bendsql/package.nix
new file mode 100644
index 000000000000..47afd7653c68
--- /dev/null
+++ b/pkgs/by-name/be/bendsql/package.nix
@@ -0,0 +1,60 @@
+{
+ lib,
+ rustPlatform,
+ fetchCrate,
+ pkg-config,
+ sqlite,
+ versionCheckHook,
+ nix-update-script,
+ testers,
+}:
+
+rustPlatform.buildRustPackage (finalAttrs: {
+ __structuredAttrs = true;
+
+ pname = "bendsql";
+ version = "0.34.2";
+
+ src = fetchCrate {
+ inherit (finalAttrs) pname version;
+ hash = "sha256-TSHUts54DfgWMTHuCUzjRdDVx6QXpOm+5Lhli6rlnqQ=";
+ };
+
+ cargoHash = "sha256-ST2ybXxXMd5MRFaITEoFRw0/yx+dOkff6vVm3mW87A4=";
+
+ nativeBuildInputs = [ pkg-config ];
+
+ buildInputs = [ sqlite ];
+
+ env = {
+ BENDSQL_BUILD_INFO = "nixpkgs";
+ LIBSQLITE3_SYS_USE_PKG_CONFIG = "1";
+ };
+
+ postPatch = ''
+ substituteInPlace build.rs \
+ --replace-fail "BuildBuilder::default().build_timestamp(true).build()?" \
+ "BuildBuilder::default().build_timestamp(false).build()?"
+ '';
+
+ doInstallCheck = true;
+ nativeInstallCheckInputs = [ versionCheckHook ];
+ versionCheckProgramArg = "--version";
+
+ passthru = {
+ tests.version = testers.testVersion {
+ package = finalAttrs.finalPackage;
+ command = "bendsql --version";
+ };
+ updateScript = nix-update-script { };
+ };
+
+ meta = {
+ description = "Native command-line client for Databend";
+ mainProgram = "bendsql";
+ homepage = "https://github.com/databendlabs/bendsql";
+ changelog = "https://github.com/databendlabs/bendsql/releases/tag/v${finalAttrs.version}";
+ license = lib.licenses.asl20;
+ maintainers = with lib.maintainers; [ mnixry ];
+ };
+})
diff --git a/pkgs/by-name/bi/bitwarden-desktop/package.nix b/pkgs/by-name/bi/bitwarden-desktop/package.nix
index d1dccec7b1ff..4422068fd053 100644
--- a/pkgs/by-name/bi/bitwarden-desktop/package.nix
+++ b/pkgs/by-name/bi/bitwarden-desktop/package.nix
@@ -73,8 +73,8 @@ buildNpmPackage (finalAttrs: {
];
npmWorkspace = "apps/desktop";
- npmDepsFetcherVersion = 3;
- npmDepsHash = "sha256-8wjt5wnJG4S4EeGWGxbo6Bwt76GIqrSiwqwwwQ17Y5Y=";
+ npmDepsFetcherVersion = 2;
+ npmDepsHash = "sha256-WRxlvkgWboO0ukUHgjC5CrfgfwnmUfDXI4r5dx9CKww=";
cargoDeps = rustPlatform.fetchCargoVendor {
inherit (finalAttrs)
diff --git a/pkgs/by-name/bo/bootmac/package.nix b/pkgs/by-name/bo/bootmac/package.nix
new file mode 100644
index 000000000000..776aed9967ec
--- /dev/null
+++ b/pkgs/by-name/bo/bootmac/package.nix
@@ -0,0 +1,67 @@
+{
+ lib,
+ stdenv,
+ fetchFromGitLab,
+ meson,
+ ninja,
+ makeWrapper,
+ gawk,
+ bluez,
+ util-linux,
+ gnugrep,
+ gnused,
+ coreutils,
+ iproute2,
+ udevCheckHook,
+}:
+stdenv.mkDerivation (finalAttrs: {
+ name = "bootmac";
+ version = "0.7.1";
+ __structuredAttrs = true;
+ strictDeps = true;
+
+ src = fetchFromGitLab {
+ domain = "gitlab.postmarketos.org";
+ owner = "postmarketOS";
+ repo = "bootmac";
+ rev = "v${finalAttrs.version}";
+ hash = "sha256-GWvZUC8LKPpOWt1oCr93JHg5+W+0CCiYT63VhpSH1ko=";
+ };
+
+ nativeBuildInputs = [
+ meson
+ ninja
+ makeWrapper
+ udevCheckHook
+ ];
+
+ mesonFlags = [ "-Dsystemd_units=true" ];
+
+ postInstall = ''
+ wrapProgram $out/bin/bootmac \
+ --prefix PATH : ${
+ lib.makeBinPath [
+ gawk
+ bluez
+ util-linux
+ gnugrep
+ gnused
+ coreutils
+ iproute2
+ ]
+ }
+
+ substituteInPlace \
+ $out/lib/systemd/system/bootmac@.service \
+ $out/lib/udev/rules.d/90-bootmac-{bluetooth,wifi}.rules \
+ --replace-fail /usr/bin/bootmac $out/bin/bootmac
+ '';
+
+ meta = {
+ description = "Configure the MAC addresses of WLAN and Bluetooth interfaces at boot";
+ mainProgram = "bootmac";
+ license = lib.licenses.gpl3;
+ maintainers = with lib.maintainers; [ matthewcroughan ];
+ platforms = bluez.meta.platforms;
+ };
+})
diff --git a/pkgs/by-name/ca/catgirldownloader/package.nix b/pkgs/by-name/ca/catgirldownloader/package.nix
new file mode 100644
index 000000000000..9c9a542d9c5e
--- /dev/null
+++ b/pkgs/by-name/ca/catgirldownloader/package.nix
@@ -0,0 +1,56 @@
+{
+ lib,
+ fetchFromGitHub,
+ python3Packages,
+ gtk4,
+ libadwaita,
+ gobject-introspection,
+ wrapGAppsHook4,
+ meson,
+ ninja,
+ pkg-config,
+ gettext,
+ desktop-file-utils,
+}:
+python3Packages.buildPythonApplication (finalAttrs: {
+ pname = "catgirldownloader";
+ version = "0.5";
+
+ __structuredAttrs = true;
+ pyproject = false;
+
+ src = fetchFromGitHub {
+ owner = "NyarchLinux";
+ repo = "CatgirlDownloader";
+ tag = finalAttrs.version;
+ hash = "sha256-+RyQOgqPZN3AnVdd5mtgppQ/z51VIEeEsiW2RFTnVbk=";
+ };
+
+ nativeBuildInputs = [
+ meson
+ ninja
+ pkg-config
+ desktop-file-utils
+ gettext
+ gobject-introspection
+ wrapGAppsHook4
+ ];
+
+ buildInputs = [
+ gtk4
+ libadwaita
+ ];
+
+ dependencies = with python3Packages; [
+ pygobject3
+ requests
+ ];
+
+ meta = {
+ description = "A GTK4 application that downloads images of catgirl and waifus from multiple sources";
+ homepage = "https://github.com/NyarchLinux/CatgirlDownloader";
+ license = lib.licenses.gpl3Only;
+ maintainers = with lib.maintainers; [ yarn ];
+ platforms = lib.platforms.linux;
+ };
+})
diff --git a/pkgs/by-name/cr/cronet-go/build-naive.patch b/pkgs/by-name/cr/cronet-go/build-naive.patch
new file mode 100644
index 000000000000..0de12a17befe
--- /dev/null
+++ b/pkgs/by-name/cr/cronet-go/build-naive.patch
@@ -0,0 +1,51 @@
+--- a/cmd/build-naive/cmd_build.go
++++ b/cmd/build-naive/cmd_build.go
+@@ -211,7 +211,7 @@ func runGetClang(t Target) {
+ }
+
+ func buildTarget(t Target) {
+- runGetClang(t)
++ // runGetClang(t)
+
+ outputDirectory := getOutputDirectory(t)
+
+@@ -244,16 +244,15 @@ func buildTarget(t Target) {
+ "optimize_for_size=true",
+ fmt.Sprintf("target_os=\"%s\"", t.OS),
+ fmt.Sprintf("target_cpu=\"%s\"", t.CPU),
++ "clang_base_path=\"@clang_base_path@\"",
++ "clang_use_chrome_plugins=false",
+ }
+
+ switch t.OS {
+ case "mac":
+ args = append(args, "use_sysroot=false")
+ case "linux":
+- // Sysroot is handled by get-clang.sh, use the naiveproxy path
+- sysrootPath := getSysrootPath(t)
+- sysrootDirectory := strings.TrimPrefix(sysrootPath, srcRoot+string(filepath.Separator))
+- args = append(args, "use_sysroot=true", fmt.Sprintf("target_sysroot=\"//%s\"", sysrootDirectory))
++ args = append(args, "use_sysroot=false")
+ if t.CPU == "x64" {
+ args = append(args, "use_cfi_icall=false", "is_cfi=false")
+ }
+@@ -316,7 +315,7 @@ func buildTarget(t Target) {
+
+ gnArgs := strings.Join(args, " ")
+
+- gnPath := filepath.Join(srcRoot, "gn", "out", "gn")
++ gnPath := "@gn@"
+ if runtime.GOOS == "windows" {
+ gnPath += ".exe"
+ }
+--- a/cmd/build-naive/cmd_package.go
++++ b/cmd/build-naive/cmd_package.go
+@@ -386,7 +386,7 @@ const Version = "%s"
+ // This allows the package to compile in purego mode (user must provide .so/.dylib)
+ generatePuregoStubFile(targetDirectory, packageName, chromiumVersion)
+
+- runCommand(targetDirectory, "go", "mod", "tidy")
++ // runCommand(targetDirectory, "go", "mod", "tidy")
+
+ log.Printf("Generated submodule lib/%s", directoryName)
+ }
diff --git a/pkgs/by-name/cr/cronet-go/cflags.patch b/pkgs/by-name/cr/cronet-go/cflags.patch
new file mode 100644
index 000000000000..d7f0ba76ed5b
--- /dev/null
+++ b/pkgs/by-name/cr/cronet-go/cflags.patch
@@ -0,0 +1,40 @@
+--- a/naiveproxy/src/build/config/compiler/BUILD.gn
++++ b/naiveproxy/src/build/config/compiler/BUILD.gn
+@@ -631,9 +631,9 @@
+ # The performance improvement does not seem worth the risk. See
+ # https://crbug.com/484082200 for background and https://crrev.com/c/7593035
+ # for discussion.
+- if (!is_wasm && !is_apple) {
+- cflags += [ "-fno-lifetime-dse" ]
+- }
++ # if (!is_wasm && !is_apple) {
++ # cflags += [ "-fno-lifetime-dse" ]
++ # }
+
+ # TODO(hans): Remove this once Clang generates better optimized debug info
+ # by default. https://crbug.com/765793
+@@ -1950,13 +1950,13 @@
+ # sanitizer) is enabled, they then do expensive debug like operations. We
+ # want to suppress this behaviour since we want to keep performance costs
+ # as low as possible while having these checks.
+- "-fsanitize-ignore-for-ubsan-feature=array-bounds",
++ # "-fsanitize-ignore-for-ubsan-feature=array-bounds",
+
+ # Because we've enabled array-bounds sanitizing we also want to suppress
+ # the related warning about "unsafe-buffer-usage-in-static-sized-array",
+ # since we know that the array bounds sanitizing will catch any out-of-
+ # bounds accesses.
+- "-Wno-unsafe-buffer-usage-in-static-sized-array",
++ # "-Wno-unsafe-buffer-usage-in-static-sized-array",
+ ]
+ }
+ }
+@@ -1974,7 +1974,7 @@
+ # sanitizer) is enabled, they then do expensive debug like operations. We
+ # want to suppress this behaviour since we want to keep performance costs
+ # as low as possible while having these checks.
+- "-fsanitize-ignore-for-ubsan-feature=return",
++ # "-fsanitize-ignore-for-ubsan-feature=return",
+ ]
+ }
+ }
diff --git a/pkgs/by-name/cr/cronet-go/libresolv.patch b/pkgs/by-name/cr/cronet-go/libresolv.patch
new file mode 100644
index 000000000000..2ecab176f017
--- /dev/null
+++ b/pkgs/by-name/cr/cronet-go/libresolv.patch
@@ -0,0 +1,11 @@
+--- a/naiveproxy/src/build/config/mac/BUILD.gn
++++ b/naiveproxy/src/build/config/mac/BUILD.gn
+@@ -14,7 +14,7 @@ import("//build/toolchain/siso.gni")
+ # is applied to all targets. It is here to separate out the logic.
+ config("compiler") {
+ # These flags are shared between the C compiler and linker.
+- common_mac_flags = []
++ common_mac_flags = [ "-I@libresolv@/include" ]
+
+ # CPU architecture.
+ _archs_mapping_os = archs_mapping[current_os]
diff --git a/pkgs/by-name/cr/cronet-go/package.nix b/pkgs/by-name/cr/cronet-go/package.nix
new file mode 100644
index 000000000000..ffdbf1e7b9eb
--- /dev/null
+++ b/pkgs/by-name/cr/cronet-go/package.nix
@@ -0,0 +1,101 @@
+{
+ apple-sdk_15,
+ buildGoModule,
+ buildPackages,
+ darwin,
+ fetchFromGitHub,
+ gn,
+ lib,
+ ninja,
+ python3,
+ replaceVars,
+ stdenvNoCC,
+ symlinkJoin,
+ xcbuild,
+}:
+let
+ llvmCcAndBintools = symlinkJoin {
+ name = "llvmCcAndBintools";
+ paths = [
+ buildPackages.rustc.llvmPackages.llvm
+ buildPackages.rustc.llvmPackages.stdenv.cc
+ ];
+ };
+in
+stdenvNoCC.mkDerivation (finalAttrs: {
+ pname = "cronet-go";
+ version = "148.0.7778.96-1-unstable-2026-07-12";
+
+ # nixpkgs-update: no auto update
+ src = fetchFromGitHub {
+ owner = "SagerNet";
+ repo = "cronet-go";
+ rev = "617d38f41f935b46a68f550d9add2e38abb3f168";
+ fetchSubmodules = true;
+ hash = "sha256-UK7mv0TuhJX4y64DhH49t5mgZFGhMx4Viy/chulKD4s=";
+ };
+
+ patches = [
+ ./cflags.patch
+ ]
+ ++ lib.optional stdenvNoCC.hostPlatform.isDarwin (
+ replaceVars ./libresolv.patch {
+ libresolv = lib.getInclude darwin.libresolv;
+ }
+ );
+
+ nativeBuildInputs = [
+ buildPackages.rustc.llvmPackages.bintools
+ ninja
+ python3
+ ]
+ ++ lib.optional stdenvNoCC.hostPlatform.isDarwin xcbuild;
+
+ buildInputs = lib.optional stdenvNoCC.hostPlatform.isDarwin apple-sdk_15;
+
+ buildPhase = ''
+ runHook preBuild
+
+ ${lib.getExe finalAttrs.passthru.build-naive} build
+ ${lib.getExe finalAttrs.passthru.build-naive} package --local
+ ${lib.getExe finalAttrs.passthru.build-naive} package
+
+ runHook postBuild
+ '';
+
+ installPhase = ''
+ runHook preInstall
+
+ mkdir -p $out
+ cp -r lib include include_cgo.go $out/
+
+ runHook postInstall
+ '';
+
+ passthru = {
+ build-naive = buildGoModule {
+ pname = finalAttrs.pname + "-build-naive";
+ inherit (finalAttrs) version src;
+ vendorHash = "sha256-pyeE+JPuRQEjNzrF+o9jslBcBM1vruuL+I/DCIa2BG0=";
+ patches = [
+ (replaceVars ./build-naive.patch {
+ gn = lib.getExe gn;
+ clang_base_path = llvmCcAndBintools;
+ })
+ ];
+ subPackages = [ "cmd/build-naive" ];
+ meta.mainProgram = "build-naive";
+ };
+ };
+
+ strictDeps = true;
+ __structuredAttrs = true;
+
+ meta = {
+ description = "Go bindings for naiveproxy";
+ homepage = "https://github.com/SagerNet/cronet-go";
+ license = lib.licenses.gpl3Plus;
+ maintainers = with lib.maintainers; [ prince213 ];
+ platforms = lib.platforms.darwin ++ lib.platforms.linux;
+ };
+})
diff --git a/pkgs/by-name/ev/evcc/package.nix b/pkgs/by-name/ev/evcc/package.nix
index 99dd9ce7c447..8eb9abbf547c 100644
--- a/pkgs/by-name/ev/evcc/package.nix
+++ b/pkgs/by-name/ev/evcc/package.nix
@@ -17,13 +17,13 @@
}:
let
- version = "0.313.0";
+ version = "0.313.1";
src = fetchFromGitHub {
owner = "evcc-io";
repo = "evcc";
tag = version;
- hash = "sha256-VDLEgkbBgyAuVAVrd0D3i07mwN1OBJfwOCXdi3gc/aw=";
+ hash = "sha256-P/NEP+gGS3Wni9j09NVujmdDYaAz7ntOtrPFZNKy/Bo=";
};
vendorHash = "sha256-QJsdBqa/JHaBig4bRtU3LqlYwh/BHnP3vg8YM3reuDY=";
diff --git a/pkgs/by-name/ex/exo/package.nix b/pkgs/by-name/ex/exo/package.nix
index 080fc9d3c42d..f9321d6d3a52 100644
--- a/pkgs/by-name/ex/exo/package.nix
+++ b/pkgs/by-name/ex/exo/package.nix
@@ -61,7 +61,7 @@ let
__structuredAttrs = true;
sourceRoot = "${finalAttrs.src.name}/dashboard";
- npmDepsFetcherVersion = 3;
+ npmDepsFetcherVersion = 2;
npmDeps = fetchNpmDeps {
inherit (finalAttrs)
@@ -70,8 +70,8 @@ let
src
sourceRoot
;
- fetcherVersion = 3;
- hash = "sha256-gBWJP0dF2zDEWLYxfKYQSn9O5hVRkcviDv9oP267pQQ=";
+ fetcherVersion = 2;
+ hash = "sha256-d/+54lpNe0tXrC+Mrhpc1cdXOMjYblE0QByIdiaDgU0=";
};
});
in
diff --git a/pkgs/by-name/fr/freescout/package.nix b/pkgs/by-name/fr/freescout/package.nix
index 24442006c851..b3fc3c7abb0f 100644
--- a/pkgs/by-name/fr/freescout/package.nix
+++ b/pkgs/by-name/fr/freescout/package.nix
@@ -7,13 +7,13 @@
stdenv.mkDerivation (finalAttrs: {
preferLocalBuild = true;
pname = "freescout";
- version = "1.8.230";
+ version = "1.8.232";
src = fetchFromGitHub {
owner = "freescout-help-desk";
repo = "freescout";
tag = finalAttrs.version;
- hash = "sha256-QAMZj1tUSaErLTJR8IfzatNw5G8lznA4mNa+a4Bd5rQ=";
+ hash = "sha256-dqUKfj9Y/CoU4hC8rq7XejVswaEOiZtFG6rsSGgljfY=";
};
patches = [
@@ -46,7 +46,7 @@ stdenv.mkDerivation (finalAttrs: {
runHook postInstall
'';
- passthru.tests = lib.attrValues nixosTests.freescout;
+ passthru.tests = nixosTests.freescout;
# Because freescout is searching for some folders only relative to it's own source location, we need to have the symlinks to the actual locations in here
dontCheckForBrokenSymlinks = true;
diff --git a/pkgs/by-name/ga/gammu/package.nix b/pkgs/by-name/ga/gammu/package.nix
index 005e5237a58c..f2377b596b40 100644
--- a/pkgs/by-name/ga/gammu/package.nix
+++ b/pkgs/by-name/ga/gammu/package.nix
@@ -24,7 +24,7 @@
stdenv.mkDerivation (finalAttrs: {
pname = "gammu";
- version = "1.43.2";
+ version = "1.43.3";
__structuredAttrs = true;
@@ -32,7 +32,7 @@ stdenv.mkDerivation (finalAttrs: {
owner = "gammu";
repo = "gammu";
rev = finalAttrs.version;
- sha256 = "sha256-+mZBELwFUEL4S3IUIIa83TaNIYQxjQE1TvWhXTcIfYc=";
+ sha256 = "sha256-qmpbAiu0aIjawdKTNClMa3yFSdakOlh/dY5gAY04K3M=";
};
patches = [
diff --git a/pkgs/by-name/gh/ghui/package.nix b/pkgs/by-name/gh/ghui/package.nix
index bd4b30d000d5..418b8253b7a6 100644
--- a/pkgs/by-name/gh/ghui/package.nix
+++ b/pkgs/by-name/gh/ghui/package.nix
@@ -31,8 +31,8 @@ buildNpmPackage (finalAttrs: {
cp ${./package-lock.json} package-lock.json
'';
- npmDepsHash = "sha256-pg+USHnvcxaXG/floNItLXNFJOPvuDltQCcN1qT/nng=";
- npmDepsFetcherVersion = 3;
+ npmDepsHash = "sha256-JxyG7qMJS7zchxLIxYCmsFajUVW4fONnqgeq2iKlt4A=";
+ npmDepsFetcherVersion = 2;
nativeBuildInputs = [ bun ];
diff --git a/pkgs/by-name/gl/glitchtip/frontend.nix b/pkgs/by-name/gl/glitchtip/frontend.nix
index 86c37d73d166..e3b4406c9d5f 100644
--- a/pkgs/by-name/gl/glitchtip/frontend.nix
+++ b/pkgs/by-name/gl/glitchtip/frontend.nix
@@ -21,11 +21,12 @@ buildNpmPackage (finalAttrs: {
nodejs = nodejs_22;
+ npmDepsFetcherVersion = 2;
npmDeps = fetchNpmDeps {
name = "${finalAttrs.pname}-${finalAttrs.version}-npm-deps";
inherit (finalAttrs) src;
- npmDepsFetcherVersion = 3;
- hash = "sha256-V9aRKoJ6+BN/q7NS21eZBopzkWje8sOGGL1AgO4cUM0=";
+ fetcherVersion = 2;
+ hash = "sha256-xobZg0Hc+Yi9+q6kMwuKtBb4pjdYNS4T9VdFy5hARlw=";
};
postPatch = ''
diff --git a/pkgs/by-name/go/goaccess/package.nix b/pkgs/by-name/go/goaccess/package.nix
index ad32acf68b3c..dc2ee4b52ccd 100644
--- a/pkgs/by-name/go/goaccess/package.nix
+++ b/pkgs/by-name/go/goaccess/package.nix
@@ -12,13 +12,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "goaccess";
- version = "1.10.2";
+ version = "1.11";
src = fetchFromGitHub {
owner = "allinurl";
repo = "goaccess";
tag = "v${finalAttrs.version}";
- hash = "sha256-n0+Z3kkjMCjPN0Cb0R1QGSzzXH3S9kjDchy9ay6109s=";
+ hash = "sha256-9Z57T0MPs3ytwi32fMF67j8h7ml20cw4Hf+/DEg5AQY=";
};
nativeBuildInputs = [ autoreconfHook ];
diff --git a/pkgs/by-name/h2/h2o/package.nix b/pkgs/by-name/h2/h2o/package.nix
index 50191ac86634..7a5f1ccc7612 100644
--- a/pkgs/by-name/h2/h2o/package.nix
+++ b/pkgs/by-name/h2/h2o/package.nix
@@ -27,13 +27,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "h2o";
- version = "2.3.0-rolling-2026-06-29";
+ version = "2.3.0-rolling-2026-07-31";
src = fetchFromGitHub {
owner = "h2o";
repo = "h2o";
- rev = "edd7a120bfc4af11ac0cbebce2a43cc1f93f9af1";
- hash = "sha256-WQy+v4zpwzgbMxT43+Nd33+YPynyZIwqzVTaknqjCmE=";
+ rev = "ba16320ad18c2bb2e28478ce9e37b9a57a5c98f6";
+ hash = "sha256-MmfypvlLJ3NeZ1Nyeyzo1mXxICllQPBwwseOo+rC1Ig=";
};
outputs = [
@@ -71,9 +71,9 @@ stdenv.mkDerivation (finalAttrs: {
++ lib.optional withZstandard zstd;
cmakeFlags = [
- "-DWITH_BROTLI=${if withBrotli then "ON" else "OFF"}"
- "-DWITH_MRUBY=${if withMruby then "ON" else "OFF"}"
- "-DWITH_ZSTD=${if withZstandard then "ON" else "OFF"}"
+ (lib.cmakeBool "WITH_BROTLI" withBrotli)
+ (lib.cmakeBool "WITH_MRUBY" withMruby)
+ (lib.cmakeBool "WITH_ZSTD" withZstandard)
];
postInstall = ''
diff --git a/pkgs/by-name/ji/jirafeau/package.nix b/pkgs/by-name/ji/jirafeau/package.nix
index d590bc92c420..52a016b95774 100644
--- a/pkgs/by-name/ji/jirafeau/package.nix
+++ b/pkgs/by-name/ji/jirafeau/package.nix
@@ -14,13 +14,13 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "jirafeau";
- version = "4.4.0";
+ version = "4.7.2";
src = fetchFromGitLab {
- owner = "mojo42";
+ owner = "jirafeau";
repo = "Jirafeau";
rev = finalAttrs.version;
- hash = "sha256-jJ2r8XTtAzawTVo2A2pDwy7Z6KHeyBkgXXaCPY0w/rg=";
+ hash = "sha256-zCmSdlHkYQVQXBeVk8AUPoC0UBxz3hWIdM2tGmnLTrw=";
};
installPhase = ''
@@ -34,7 +34,7 @@ stdenv.mkDerivation (finalAttrs: {
meta = {
description = "Website permitting upload of a file in a simple way and giving a unique link to it";
license = lib.licenses.agpl3Plus;
- homepage = "https://gitlab.com/mojo42/Jirafeau";
+ homepage = "https://gitlab.com/jirafeau/Jirafeau";
platforms = lib.platforms.all;
maintainers = [ ];
};
diff --git a/pkgs/by-name/ka/kazumi/git-hashes.json b/pkgs/by-name/ka/kazumi/git-hashes.json
index a3a5b15cdb07..500fc50fd9cc 100644
--- a/pkgs/by-name/ka/kazumi/git-hashes.json
+++ b/pkgs/by-name/ka/kazumi/git-hashes.json
@@ -2,14 +2,14 @@
"audio_service_mpris": "sha256-IVv1ioBpiK0VbnOFqnc9NbNn3Z+l9VN2clpCQjckBRo=",
"audio_service_win": "sha256-OZq2waTr0WLJ6uki/VLdUBdDdui25PvXnMNFohs7gjs=",
"desktop_webview_window": "sha256-KWON5aTPlVVrLidmnfpV+syWPYEngChOvkN7miIFjvE=",
- "media_kit": "sha256-cKV7ST1egNdXLcsNTUcK7Xh/II72bl8cR3fJuf3/AyM=",
- "media_kit_libs_android_video": "sha256-cKV7ST1egNdXLcsNTUcK7Xh/II72bl8cR3fJuf3/AyM=",
- "media_kit_libs_ios_video": "sha256-cKV7ST1egNdXLcsNTUcK7Xh/II72bl8cR3fJuf3/AyM=",
- "media_kit_libs_linux": "sha256-cKV7ST1egNdXLcsNTUcK7Xh/II72bl8cR3fJuf3/AyM=",
- "media_kit_libs_macos_video": "sha256-cKV7ST1egNdXLcsNTUcK7Xh/II72bl8cR3fJuf3/AyM=",
- "media_kit_libs_ohos": "sha256-cKV7ST1egNdXLcsNTUcK7Xh/II72bl8cR3fJuf3/AyM=",
- "media_kit_libs_video": "sha256-cKV7ST1egNdXLcsNTUcK7Xh/II72bl8cR3fJuf3/AyM=",
- "media_kit_libs_windows_video": "sha256-cKV7ST1egNdXLcsNTUcK7Xh/II72bl8cR3fJuf3/AyM=",
- "media_kit_video": "sha256-cKV7ST1egNdXLcsNTUcK7Xh/II72bl8cR3fJuf3/AyM=",
+ "media_kit": "sha256-nM6WJalSotWWvpEvDxaNXynEIMNh2yj5MSn7lLLcJsA=",
+ "media_kit_libs_android_video": "sha256-nM6WJalSotWWvpEvDxaNXynEIMNh2yj5MSn7lLLcJsA=",
+ "media_kit_libs_ios_video": "sha256-nM6WJalSotWWvpEvDxaNXynEIMNh2yj5MSn7lLLcJsA=",
+ "media_kit_libs_linux": "sha256-nM6WJalSotWWvpEvDxaNXynEIMNh2yj5MSn7lLLcJsA=",
+ "media_kit_libs_macos_video": "sha256-nM6WJalSotWWvpEvDxaNXynEIMNh2yj5MSn7lLLcJsA=",
+ "media_kit_libs_ohos": "sha256-nM6WJalSotWWvpEvDxaNXynEIMNh2yj5MSn7lLLcJsA=",
+ "media_kit_libs_video": "sha256-nM6WJalSotWWvpEvDxaNXynEIMNh2yj5MSn7lLLcJsA=",
+ "media_kit_libs_windows_video": "sha256-nM6WJalSotWWvpEvDxaNXynEIMNh2yj5MSn7lLLcJsA=",
+ "media_kit_video": "sha256-nM6WJalSotWWvpEvDxaNXynEIMNh2yj5MSn7lLLcJsA=",
"webview_windows": "sha256-afBTwbam9YA0xvIYMtiJe+CKi8GWit1HqDR3J72r2o0="
}
diff --git a/pkgs/by-name/ka/kazumi/package.nix b/pkgs/by-name/ka/kazumi/package.nix
index dd2628868ad3..b5efafdf28f5 100644
--- a/pkgs/by-name/ka/kazumi/package.nix
+++ b/pkgs/by-name/ka/kazumi/package.nix
@@ -20,13 +20,13 @@
}:
let
- version = "2.2.3";
+ version = "2.2.6";
src = fetchFromGitHub {
owner = "Predidit";
repo = "Kazumi";
tag = version;
- hash = "sha256-CAc7KaTSYKy3UxLei8GPhDYbJURshChZoUhmFetBEuw=";
+ hash = "sha256-a2N9ucF+KNHmQ7hnL9GPOLYM4S9DEFlQ0I9mzLM5eEU=";
};
in
flutter.buildFlutterApplication {
diff --git a/pkgs/by-name/ka/kazumi/pubspec.lock.json b/pkgs/by-name/ka/kazumi/pubspec.lock.json
index d42d66e269c7..061ac7342793 100644
--- a/pkgs/by-name/ka/kazumi/pubspec.lock.json
+++ b/pkgs/by-name/ka/kazumi/pubspec.lock.json
@@ -262,16 +262,6 @@
"source": "hosted",
"version": "0.3.1"
},
- "card_settings_ui": {
- "dependency": "direct main",
- "description": {
- "name": "card_settings_ui",
- "sha256": "73670e4685d44fed8e9669e813153801825eea6f7a2845665e3a5a8631761e6c",
- "url": "https://pub.dev"
- },
- "source": "hosted",
- "version": "2.0.1"
- },
"characters": {
"dependency": "transitive",
"description": {
@@ -1211,8 +1201,8 @@
"dependency": "direct main",
"description": {
"path": "media_kit",
- "ref": "b11ec8050d1f07ca117022f2da3260281676346f",
- "resolved-ref": "b11ec8050d1f07ca117022f2da3260281676346f",
+ "ref": "e3d51713f085068da32fb502ee65885547042661",
+ "resolved-ref": "e3d51713f085068da32fb502ee65885547042661",
"url": "https://github.com/Predidit/media-kit.git"
},
"source": "git",
@@ -1222,8 +1212,8 @@
"dependency": "direct overridden",
"description": {
"path": "libs/android/media_kit_libs_android_video",
- "ref": "b11ec8050d1f07ca117022f2da3260281676346f",
- "resolved-ref": "b11ec8050d1f07ca117022f2da3260281676346f",
+ "ref": "e3d51713f085068da32fb502ee65885547042661",
+ "resolved-ref": "e3d51713f085068da32fb502ee65885547042661",
"url": "https://github.com/Predidit/media-kit.git"
},
"source": "git",
@@ -1233,8 +1223,8 @@
"dependency": "direct overridden",
"description": {
"path": "libs/ios/media_kit_libs_ios_video",
- "ref": "b11ec8050d1f07ca117022f2da3260281676346f",
- "resolved-ref": "b11ec8050d1f07ca117022f2da3260281676346f",
+ "ref": "e3d51713f085068da32fb502ee65885547042661",
+ "resolved-ref": "e3d51713f085068da32fb502ee65885547042661",
"url": "https://github.com/Predidit/media-kit.git"
},
"source": "git",
@@ -1244,8 +1234,8 @@
"dependency": "direct overridden",
"description": {
"path": "libs/linux/media_kit_libs_linux",
- "ref": "b11ec8050d1f07ca117022f2da3260281676346f",
- "resolved-ref": "b11ec8050d1f07ca117022f2da3260281676346f",
+ "ref": "e3d51713f085068da32fb502ee65885547042661",
+ "resolved-ref": "e3d51713f085068da32fb502ee65885547042661",
"url": "https://github.com/Predidit/media-kit.git"
},
"source": "git",
@@ -1255,8 +1245,8 @@
"dependency": "direct overridden",
"description": {
"path": "libs/macos/media_kit_libs_macos_video",
- "ref": "b11ec8050d1f07ca117022f2da3260281676346f",
- "resolved-ref": "b11ec8050d1f07ca117022f2da3260281676346f",
+ "ref": "e3d51713f085068da32fb502ee65885547042661",
+ "resolved-ref": "e3d51713f085068da32fb502ee65885547042661",
"url": "https://github.com/Predidit/media-kit.git"
},
"source": "git",
@@ -1266,8 +1256,8 @@
"dependency": "direct overridden",
"description": {
"path": "libs/ohos/media_kit_libs_ohos",
- "ref": "b11ec8050d1f07ca117022f2da3260281676346f",
- "resolved-ref": "b11ec8050d1f07ca117022f2da3260281676346f",
+ "ref": "e3d51713f085068da32fb502ee65885547042661",
+ "resolved-ref": "e3d51713f085068da32fb502ee65885547042661",
"url": "https://github.com/Predidit/media-kit.git"
},
"source": "git",
@@ -1277,8 +1267,8 @@
"dependency": "direct main",
"description": {
"path": "libs/universal/media_kit_libs_video",
- "ref": "b11ec8050d1f07ca117022f2da3260281676346f",
- "resolved-ref": "b11ec8050d1f07ca117022f2da3260281676346f",
+ "ref": "e3d51713f085068da32fb502ee65885547042661",
+ "resolved-ref": "e3d51713f085068da32fb502ee65885547042661",
"url": "https://github.com/Predidit/media-kit.git"
},
"source": "git",
@@ -1288,8 +1278,8 @@
"dependency": "direct overridden",
"description": {
"path": "libs/windows/media_kit_libs_windows_video",
- "ref": "b11ec8050d1f07ca117022f2da3260281676346f",
- "resolved-ref": "b11ec8050d1f07ca117022f2da3260281676346f",
+ "ref": "e3d51713f085068da32fb502ee65885547042661",
+ "resolved-ref": "e3d51713f085068da32fb502ee65885547042661",
"url": "https://github.com/Predidit/media-kit.git"
},
"source": "git",
@@ -1299,8 +1289,8 @@
"dependency": "direct main",
"description": {
"path": "media_kit_video",
- "ref": "b11ec8050d1f07ca117022f2da3260281676346f",
- "resolved-ref": "b11ec8050d1f07ca117022f2da3260281676346f",
+ "ref": "e3d51713f085068da32fb502ee65885547042661",
+ "resolved-ref": "e3d51713f085068da32fb502ee65885547042661",
"url": "https://github.com/Predidit/media-kit.git"
},
"source": "git",
@@ -2446,6 +2436,6 @@
},
"sdks": {
"dart": ">=3.11.0 <4.0.0",
- "flutter": ">=3.44.7"
+ "flutter": ">=3.44.8"
}
}
diff --git a/pkgs/by-name/li/lib60870/package.nix b/pkgs/by-name/li/lib60870/package.nix
index 0878ce66cec0..953c0d10f406 100644
--- a/pkgs/by-name/li/lib60870/package.nix
+++ b/pkgs/by-name/li/lib60870/package.nix
@@ -9,20 +9,21 @@
stdenv.mkDerivation (finalAttrs: {
pname = "lib60870";
- version = "2.3.6";
+ version = "2.4.1";
src = fetchFromGitHub {
owner = "mz-automation";
repo = "lib60870";
rev = "v${finalAttrs.version}";
- hash = "sha256-9VqLl1pDmi8TauBA8uCyymzsYd3w4b5AKtqH7XW80N4=";
+ hash = "sha256-WXEe+G7ib9XNAZSsNl/RZcFHXpIbCMKNfPLnxZzz09E=";
};
sourceRoot = "${finalAttrs.src.name}/lib60870-C";
postPatch = ''
+ # Keep system mbedTLS support enabled without vendored mbedTLS sources.
substituteInPlace CMakeLists.txt \
- --replace-fail "cmake_minimum_required(VERSION 3.0)" "cmake_minimum_required(VERSION 3.10)"
+ --replace-fail "if(MBEDTLS_DIR)" "if(MBEDTLS_DIR OR WITH_MBEDTLS3)"
''
+ lib.optionalString stdenv.hostPlatform.isDarwin ''
substituteInPlace src/CMakeLists.txt \
diff --git a/pkgs/by-name/li/libmodsecurity/package.nix b/pkgs/by-name/li/libmodsecurity/package.nix
index 5224f7f6e81b..6baec57daee1 100644
--- a/pkgs/by-name/li/libmodsecurity/package.nix
+++ b/pkgs/by-name/li/libmodsecurity/package.nix
@@ -20,13 +20,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "libmodsecurity";
- version = "3.0.15";
+ version = "3.0.16";
src = fetchFromGitHub {
owner = "owasp-modsecurity";
repo = "ModSecurity";
rev = "v${finalAttrs.version}";
- hash = "sha256-gI874wkqy8VuwxUmIgb8d7fULJUQ+rKBBF492NtuRMY=";
+ hash = "sha256-KkUZ52IQ8kZPP4znvNX2kDCbYFBesmvV5i1tVgHFct8=";
fetchSubmodules = true;
};
@@ -63,7 +63,7 @@ stdenv.mkDerivation (finalAttrs: {
];
postPatch = ''
- # https://github.com/owasp-modsecurity/ModSecurity/blob/v3.0.15/build.sh#L6-L25
+ # https://github.com/owasp-modsecurity/ModSecurity/blob/v3.0.16/build.sh#L6-L25
echo "noinst_HEADERS = \\" > ./src/headers.mk
ls -1 ./src/ \
actions/*.h \
diff --git a/pkgs/by-name/li/libtrace/package.nix b/pkgs/by-name/li/libtrace/package.nix
index 53e63fa75f5a..5f84f49fffb7 100644
--- a/pkgs/by-name/li/libtrace/package.nix
+++ b/pkgs/by-name/li/libtrace/package.nix
@@ -16,13 +16,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "libtrace";
- version = "4.0.32-2";
+ version = "4.0.34-1";
src = fetchFromGitHub {
owner = "LibtraceTeam";
repo = "libtrace";
tag = finalAttrs.version;
- hash = "sha256-cqRhTNSXvNlZW63baxqcqVJJEVe8SeunTPdJ623kIvo=";
+ hash = "sha256-vVhLUc2IddslHmXtzduYs4MLwWA+vYE/q5qpZIORdbY=";
};
strictDeps = true;
diff --git a/pkgs/by-name/li/libvncserver/package.nix b/pkgs/by-name/li/libvncserver/package.nix
index 1cc1489c93d9..d6e56f6003bd 100644
--- a/pkgs/by-name/li/libvncserver/package.nix
+++ b/pkgs/by-name/li/libvncserver/package.nix
@@ -41,6 +41,18 @@ stdenv.mkDerivation (finalAttrs: {
url = "https://github.com/LibVNC/libvncserver/commit/e64fa928170f22a2e21b5bbd6d46c8f8e7dd7a96.patch";
hash = "sha256-AAZ3H34+nLqQggb/sNSx2gIGK96m4zatHX3wpyjNLOA=";
})
+
+ (fetchpatch {
+ name = "CVE-2026-32854.patch";
+ url = "https://github.com/LibVNC/libvncserver/commit/dc78dee51a7e270e537a541a17befdf2073f5314.patch";
+ hash = "sha256-CgVfvsrgZWnjIzu/0UegoAuCqO7WHhCDVvhH8Yk1cXo=";
+ })
+
+ (fetchpatch {
+ name = "CVE-2026-32853.patch";
+ url = "https://github.com/LibVNC/libvncserver/commit/009008e2f4d5a54dd71f422070df3af7b3dbc931.patch";
+ hash = "sha256-ZgpiIS7KoRzDmVLQ0J86wTFFykCBVMt6bZwJsFvIO74=";
+ })
];
nativeBuildInputs = [
diff --git a/pkgs/by-name/ma/mark/package.nix b/pkgs/by-name/ma/mark/package.nix
index 9da7683e1c8b..25b1951bffa8 100644
--- a/pkgs/by-name/ma/mark/package.nix
+++ b/pkgs/by-name/ma/mark/package.nix
@@ -1,23 +1,24 @@
{
lib,
+ stdenv,
buildGoModule,
fetchFromGitHub,
+ iana-etc,
+ libredirect,
}:
-# Tests with go 1.24 do not work. For now
-# https://github.com/kovetskiy/mark/pull/581#issuecomment-2797872996
buildGoModule (finalAttrs: {
pname = "mark";
- version = "16.6.0";
+ version = "16.8.9";
src = fetchFromGitHub {
owner = "kovetskiy";
repo = "mark";
rev = "v${finalAttrs.version}";
- sha256 = "sha256-kpWY+8r6ILHmZr1VWO+4rj8tLqzyucsDNPnoPaF1IkU=";
+ sha256 = "sha256-tIixIAgMooDONu1ZcU0tTFM0DR+j2R4gcO9s1tA0x9I=";
};
- vendorHash = "sha256-vJn/bFhbnDY0OfuD9swvt/X5Pb0nWpaoHc1iwWCVwpg=";
+ vendorHash = "sha256-DR3ma5pliR7C1gJ+b2gbWEIEEb+QaH7hSSc9mroA5Tc=";
ldflags = [
"-s"
@@ -25,18 +26,35 @@ buildGoModule (finalAttrs: {
"-X main.version=${finalAttrs.version}"
];
+ nativeCheckInputs = lib.optionals stdenv.hostPlatform.isDarwin [ libredirect.hook ];
+
+ # goldmark-katex pulls in modernc.org/libc, whose vendored netdb package reads
+ # /etc/protocols and /etc/services during package init. It falls back to a
+ # built-in table when they do not exist, but panics when they exist and are
+ # unreadable, which is what the Darwin sandbox produces.
+ preCheck = lib.optionalString stdenv.hostPlatform.isDarwin ''
+ export NIX_REDIRECTS=/etc/protocols=${iana-etc}/etc/protocols:/etc/services=${iana-etc}/etc/services
+ '';
+
checkFlags =
let
skippedTests = [
# Expects to be able to launch google-chrome
"TestExtractMermaidImage"
"TestExtractD2Image/example"
+ "TestAttachmentFilenameAttributeIsEscaped"
+ "TestDiagramWithoutTitleHasNoCaption"
+ "TestDiagramWithTitleKeepsCaption"
];
in
[
"-skip=^${builtins.concatStringsSep "$|^" skippedTests}$"
];
+ # confluence/api_test.go serves a mock Confluence API over httptest, which
+ # binds a localhost listener.
+ __darwinAllowLocalNetworking = true;
+
meta = {
description = "Tool for syncing your markdown documentation with Atlassian Confluence pages";
mainProgram = "mark";
diff --git a/pkgs/by-name/ms/msm-modem/package.nix b/pkgs/by-name/ms/msm-modem/package.nix
new file mode 100644
index 000000000000..1b7466e28c70
--- /dev/null
+++ b/pkgs/by-name/ms/msm-modem/package.nix
@@ -0,0 +1,59 @@
+{
+ lib,
+ stdenv,
+ fetchFromGitLab,
+ meson,
+ ninja,
+ nix-update-script,
+ makeWrapper,
+ gnugrep,
+ gawk,
+ libqmi,
+}:
+
+stdenv.mkDerivation (finalAttrs: {
+ pname = "msm-modem";
+ version = "13";
+ __structuredAttrs = true;
+ strictDeps = true;
+
+ src = fetchFromGitLab {
+ domain = "gitlab.postmarketos.org";
+ owner = "postmarketOS";
+ repo = "msm-modem";
+ tag = finalAttrs.version;
+ hash = "sha256-kKDqYrd7yI3beS7kMVN+xqTBfNC4NTUgch2t/rDM9LE=";
+ };
+
+ nativeBuildInputs = [
+ meson
+ ninja
+ makeWrapper
+ ];
+
+ mesonFlags = [
+ "-Ddownstream=false"
+ "-Dopenrc=false"
+ ];
+
+ postInstall = ''
+ wrapProgram $out/libexec/msm-modem-uim-selection \
+ --prefix PATH : ${
+ lib.makeBinPath [
+ libqmi
+ gawk
+ gnugrep
+ ]
+ }
+ '';
+
+ passthru.updateScript = nix-update-script { };
+
+ meta = {
+ description = "Common support for Qualcomm MSM modems";
+ homepage = "https://gitlab.postmarketos.org/postmarketOS/msm-modem";
+ license = lib.licenses.gpl3Only;
+ maintainers = with lib.maintainers; [ matthewcroughan ];
+ platforms = lib.platforms.linux;
+ };
+})
diff --git a/pkgs/by-name/ne/necesse-server/package.nix b/pkgs/by-name/ne/necesse-server/package.nix
index 88e7c558b6e1..ef6f85fcc8ac 100644
--- a/pkgs/by-name/ne/necesse-server/package.nix
+++ b/pkgs/by-name/ne/necesse-server/package.nix
@@ -6,7 +6,7 @@
}:
let
- version = "1.2.0-23522718";
+ version = "1.3.1-24494674";
urlVersion = lib.replaceStrings [ "." ] [ "-" ] version;
in
@@ -16,7 +16,7 @@ stdenvNoCC.mkDerivation {
src = fetchzip {
url = "https://necesse.pwn.sh/server/necesse-server-linux64-${urlVersion}.zip";
- hash = "sha256-PIguTYULddLKj6PpoSvX3gNSvqrS7oRTOPuwoA0/XOc=";
+ hash = "sha256-A2mWnIIRGNfbxg7aZDwEk7QvuDUUpr2ARIddasTlvFM=";
};
# removing packaged jre since we use our own
diff --git a/pkgs/by-name/pa/panoply/package.nix b/pkgs/by-name/pa/panoply/package.nix
index 060fff5c39c5..b795b3200c78 100644
--- a/pkgs/by-name/pa/panoply/package.nix
+++ b/pkgs/by-name/pa/panoply/package.nix
@@ -8,11 +8,11 @@
stdenvNoCC.mkDerivation rec {
pname = "panoply";
- version = "5.10.0";
+ version = "5.10.1";
src = fetchurl {
url = "https://www.giss.nasa.gov/tools/panoply/download/PanoplyJ-${version}.tgz";
- hash = "sha256-xPeBNjOY8BMs3zw0coUhYqaEcyYc9BtO2ETwDOv2H5Q=";
+ hash = "sha256-xSvzYD7Bk3SC0WUhQVKRhkCZTiB1vAATM7qSGw9U7Lo=";
};
nativeBuildInputs = [ makeWrapper ];
diff --git a/pkgs/by-name/ph/photoqt/package.nix b/pkgs/by-name/ph/photoqt/package.nix
index 514d8260e860..e9ab6fae7f63 100644
--- a/pkgs/by-name/ph/photoqt/package.nix
+++ b/pkgs/by-name/ph/photoqt/package.nix
@@ -17,11 +17,11 @@
stdenv.mkDerivation (finalAttrs: {
pname = "photoqt";
- version = "5.4";
+ version = "5.4.1";
src = fetchurl {
url = "https://photoqt.org/downloads/source/photoqt-${finalAttrs.version}.tar.gz";
- hash = "sha256-Gifem+gVPmpF7uhiD2atejtFmOVuu7t2ZLKHMNS5yvY=";
+ hash = "sha256-vCihM84yDfDbz77qigIFQH/LIarH6IHKS3QdFPLZ8Lc=";
};
nativeBuildInputs = [
diff --git a/pkgs/by-name/pi/pike/package.nix b/pkgs/by-name/pi/pike/package.nix
index fa4ae9329258..1a89fdd100cd 100644
--- a/pkgs/by-name/pi/pike/package.nix
+++ b/pkgs/by-name/pi/pike/package.nix
@@ -113,7 +113,7 @@ let
mpl20
];
maintainers = with lib.maintainers; [ siraben ];
- platforms = with lib.platforms; unix ++ windows;
+ platforms = [ "x86_64-linux" ];
mainProgram = "pike";
};
});
@@ -208,7 +208,8 @@ stdenv.mkDerivation (finalAttrs: {
mpl20
];
maintainers = with lib.maintainers; [ siraben ];
- platforms = with lib.platforms; unix ++ windows;
+ # Bootstrap binary is only available for x86_64-linux
+ platforms = [ "x86_64-linux" ];
mainProgram = "pike";
};
})
diff --git a/pkgs/by-name/qw/qwen-code/package.nix b/pkgs/by-name/qw/qwen-code/package.nix
index 50a1d4e02c9c..a4e253da3cb3 100644
--- a/pkgs/by-name/qw/qwen-code/package.nix
+++ b/pkgs/by-name/qw/qwen-code/package.nix
@@ -23,8 +23,8 @@ buildNpmPackage (finalAttrs: {
hash = "sha256-XWhQ5GlAGW0WAyiPwBULLz1yQps2IdjVkusQ0a88tCs=";
};
- npmDepsFetcherVersion = 3;
- npmDepsHash = "sha256-dRc+hTk5ELw0rJhT71heFnLjTmjN1UpIOHUMXKt4YwU=";
+ npmDepsFetcherVersion = 2;
+ npmDepsHash = "sha256-2vr8Yspm6CCVnO6Jf8B3wiL6X+Tp6hZZEPr+WC/Dcak=";
# npm 11 incompatible with fetchNpmDeps
# https://github.com/NixOS/nixpkgs/issues/474535
diff --git a/pkgs/by-name/ru/rustfs/package.nix b/pkgs/by-name/ru/rustfs/package.nix
index 4dd7a96ffd58..326eb00351d6 100644
--- a/pkgs/by-name/ru/rustfs/package.nix
+++ b/pkgs/by-name/ru/rustfs/package.nix
@@ -51,14 +51,14 @@ let
in
rustPlatform.buildRustPackage rec {
pname = "rustfs";
- version = "1.0.0-beta.11";
+ version = "1.0.0-beta.12";
__structuredAttrs = true;
src = fetchFromGitHub {
owner = "rustfs";
repo = "rustfs";
tag = version;
- hash = "sha256-arwTgRwUr7/mgobtxnkhxD1mu4LrrEqKnrewacpc6ro=";
+ hash = "sha256-u5DhPg0e42IvP5lNyLVh2kBQLEYQz3J5crnTs8mfFms=";
};
postPatch = ''
@@ -66,7 +66,7 @@ rustPlatform.buildRustPackage rec {
cp -rL ${console} ./rustfs/static
'';
- cargoHash = "sha256-cMOPQ70hGFJEdYkrizgrwJOfga9UvqJRPdQbX/Whhuk=";
+ cargoHash = "sha256-5QpSWlGN0zV6BW6joRyP+Ly6QEVTkHTJUSBBnyYx+EQ=";
nativeBuildInputs = [
protobuf
diff --git a/pkgs/by-name/sd/sdl_gamecontrollerdb/package.nix b/pkgs/by-name/sd/sdl_gamecontrollerdb/package.nix
index cb4953993819..7394df312177 100644
--- a/pkgs/by-name/sd/sdl_gamecontrollerdb/package.nix
+++ b/pkgs/by-name/sd/sdl_gamecontrollerdb/package.nix
@@ -7,13 +7,13 @@
stdenvNoCC.mkDerivation (finalAttrs: {
pname = "sdl_gamecontrollerdb";
- version = "0-unstable-2026-07-23";
+ version = "0-unstable-2026-07-31";
src = fetchFromGitHub {
owner = "mdqinc";
repo = "SDL_GameControllerDB";
- rev = "fa9c1fb9df83bdabb9f699eadac66adc9759b14d";
- hash = "sha256-t8fTiPT0g08QbPJGnlppJEe64ZHGNyV8fv0Za471DD8=";
+ rev = "92580540a27913da37a34cfcc006f973d471c081";
+ hash = "sha256-awINI/AItJ/ReuFWiuH6NTA9RrgAWXe/M3wIWk9ytlA=";
};
dontBuild = true;
diff --git a/pkgs/by-name/se/secp256k1-jdk/package.nix b/pkgs/by-name/se/secp256k1-jdk/package.nix
index 1acb5d832481..13324af60281 100644
--- a/pkgs/by-name/se/secp256k1-jdk/package.nix
+++ b/pkgs/by-name/se/secp256k1-jdk/package.nix
@@ -3,6 +3,7 @@
fetchFromGitHub,
maven,
jdk25,
+ nix-update-script,
}:
maven.buildMavenPackage (finalAttrs: {
@@ -12,7 +13,7 @@ maven.buildMavenPackage (finalAttrs: {
src = fetchFromGitHub {
owner = "bitcoinj";
repo = "secp256k1-jdk";
- rev = "v${finalAttrs.version}";
+ tag = "v${finalAttrs.version}";
hash = "sha256-F2e4NDPEU7ZAu4+fvEd4BRbE2JwCvUiMeXHTMDXbIJE=";
};
@@ -44,6 +45,8 @@ maven.buildMavenPackage (finalAttrs: {
runHook postInstall
'';
+ passthru.updateScript = nix-update-script { };
+
meta = {
changelog = "https://github.com/bitcoinj/secp256k1-jdk/blob/master/CHANGELOG.adoc";
description = "Java library providing Elliptic Curve Cryptography on curve secp256k1";
diff --git a/pkgs/by-name/sg/sgdboop/package.nix b/pkgs/by-name/sg/sgdboop/package.nix
index c6530e63ab2e..318a4929d93f 100644
--- a/pkgs/by-name/sg/sgdboop/package.nix
+++ b/pkgs/by-name/sg/sgdboop/package.nix
@@ -9,27 +9,28 @@
}:
stdenv.mkDerivation (finalAttrs: {
pname = "sgdboop";
- version = "1.3.2";
+ version = "1.4.2";
src = fetchFromGitHub {
owner = "SteamGridDB";
repo = "SGDBoop";
tag = "v${finalAttrs.version}";
- hash = "sha256-/pXZMq80fb7Z+619ACnu/ZYWpouh59PIiruWY7l2cnQ=";
+ hash = "sha256-17LfPmqvSrXvIcKfjTrpopAIzue62TXw/yXXmAQOeR0=";
};
- makeFlags = [
- # The flatpak install just copies things to /app - otherwise wants to do things with XDG
- "FLATPAK_ID=fake"
- ];
+ installPhase = ''
+ runHook preInstall
- postPatch = ''
- substituteInPlace Makefile \
- --replace-fail "/app/" "$out/"
- '';
+ install -Dm755 SGDBoop \
+ $out/bin/SGDBoop
- postInstall = ''
- rm -r "$out/share/metainfo"
+ install -Dm644 res/linux/com.steamgriddb.SGDBoop.desktop \
+ $out/share/applications/com.steamgriddb.SGDBoop.desktop
+
+ install -Dm444 res/com.steamgriddb.SGDBoop.svg \
+ $out/share/icons/hicolor/scalable/apps/com.steamgriddb.SGDBoop.svg
+
+ runHook postInstall
'';
nativeBuildInputs = [
diff --git a/pkgs/by-name/si/sing-box/cronet-go.patch b/pkgs/by-name/si/sing-box/cronet-go.patch
new file mode 100644
index 000000000000..b50ab0e12c2b
--- /dev/null
+++ b/pkgs/by-name/si/sing-box/cronet-go.patch
@@ -0,0 +1,27 @@
+--- a/internal/cronet/loader_unix.go
++++ b/internal/cronet/loader_unix.go
+@@ -68,10 +68,11 @@
+ }
+
+ var searchPaths []string
+- executablePath, err := os.Executable()
+- if err == nil {
+- searchPaths = append(searchPaths, filepath.Dir(executablePath))
+- }
++ // executablePath, err := os.Executable()
++ // if err == nil {
++ // searchPaths = append(searchPaths, filepath.Dir(executablePath))
++ // }
++ searchPaths = append(searchPaths, "@out@/lib")
+
+ if ldPath := os.Getenv("LD_LIBRARY_PATH"); ldPath != "" {
+ paths := filepath.SplitList(ldPath)
+@@ -85,7 +86,7 @@
+ }
+ }
+
+- searchPaths = append(searchPaths, "/usr/local/lib", "/usr/lib")
++ // searchPaths = append(searchPaths, "/usr/local/lib", "/usr/lib")
+
+ for _, searchPath := range searchPaths {
+ fullPath := filepath.Join(searchPath, libName)
diff --git a/pkgs/by-name/si/sing-box/package.nix b/pkgs/by-name/si/sing-box/package.nix
index 467f0ae8be37..42960d0db491 100644
--- a/pkgs/by-name/si/sing-box/package.nix
+++ b/pkgs/by-name/si/sing-box/package.nix
@@ -1,17 +1,28 @@
{
lib,
buildGoModule,
- fetchFromGitHub,
- installShellFiles,
+ buildPackages,
coreutils,
- nix-update-script,
+ cronet-go,
+ fetchFromGitHub,
+ go,
+ installShellFiles,
nixosTests,
-}:
+ stdenvNoCC,
+ withStaticCronet ? true,
+ withNaiveOutbound ? true,
+}:
+assert lib.assertMsg (
+ withNaiveOutbound -> !withStaticCronet -> stdenvNoCC.hostPlatform.isLinux
+) "Dynamic linking to cronet-go is only available on Linux.";
buildGoModule (finalAttrs: {
pname = "sing-box";
version = "1.13.15";
+ __structuredAttrs = true;
+
+ # nixpkgs-update: no auto update
src = fetchFromGitHub {
owner = "SagerNet";
repo = "sing-box";
@@ -34,15 +45,28 @@ buildGoModule (finalAttrs: {
"with_ocm"
"badlinkname"
"tfogo_checklinkname0"
- ];
+ ]
+ ++ lib.optional withNaiveOutbound "with_naive_outbound"
+ ++ lib.optional (withNaiveOutbound && !withStaticCronet) "with_purego";
subPackages = [
"cmd/sing-box"
];
- env.CGO_ENABLED = 0;
+ env = {
+ CGO_ENABLED = 0;
+ }
+ // lib.optionalAttrs (withNaiveOutbound && withStaticCronet) {
+ CGO_ENABLED = 1;
+ CGO_LDFLAGS = "-fuse-ld=lld";
+ };
- nativeBuildInputs = [ installShellFiles ];
+ nativeBuildInputs = [
+ installShellFiles
+ ]
+ ++ lib.optional (withNaiveOutbound && withStaticCronet) buildPackages.rustc.llvmPackages.bintools;
+
+ buildInputs = lib.optional (withNaiveOutbound && withStaticCronet) cronet-go;
ldflags = [
"-X=github.com/sagernet/sing-box/constant.Version=${finalAttrs.version}"
@@ -50,6 +74,17 @@ buildGoModule (finalAttrs: {
"-checklinkname=0"
];
+ postConfigure = lib.optionalString withNaiveOutbound ''
+ pushd vendor/github.com/sagernet/cronet-go
+ chmod -R u+w .
+ cp -r ${cronet-go}/ .
+ # for !withStaticCronet
+ patch -p1 < ${./cronet-go.patch}
+ substituteInPlace internal/cronet/loader_unix.go \
+ --subst-var out
+ popd
+ '';
+
postInstall = ''
installShellCompletion release/completions/sing-box.{bash,fish,zsh}
@@ -60,10 +95,12 @@ buildGoModule (finalAttrs: {
install -Dm444 release/config/sing-box.rules $out/share/polkit-1/rules.d/sing-box.rules
install -Dm444 release/config/sing-box-split-dns.xml $out/share/dbus-1/system.d/sing-box-split-dns.conf
+ ''
+ + lib.optionalString (withNaiveOutbound && !withStaticCronet) ''
+ ln -s "${cronet-go}/lib/${go.GOOS}_${go.GOARCH}/libcronet.so" "$out/lib/"
'';
passthru = {
- updateScript = nix-update-script { };
tests = { inherit (nixosTests) sing-box; };
};
diff --git a/pkgs/by-name/sn/snyk/package.nix b/pkgs/by-name/sn/snyk/package.nix
index 81bdd8ba7795..0d8a102d3ab3 100644
--- a/pkgs/by-name/sn/snyk/package.nix
+++ b/pkgs/by-name/sn/snyk/package.nix
@@ -24,9 +24,9 @@ buildNpmPackage (finalAttrs: {
'';
};
- npmDepsFetcherVersion = 3;
+ npmDepsFetcherVersion = 2;
- npmDepsHash = "sha256-AmJNFEw7IF9PjgeRma6vp3I7a60ZkekfRkPXJtjVIik=";
+ npmDepsHash = "sha256-e7C2ZG7SH9xjfU07lX8rzPeox6k2Fdz7AowOduLxvvs=";
nodejs = nodejs_24;
diff --git a/pkgs/by-name/ti/tinyproxy/package.nix b/pkgs/by-name/ti/tinyproxy/package.nix
index 035c3194b91e..bb07a0bf0a4d 100644
--- a/pkgs/by-name/ti/tinyproxy/package.nix
+++ b/pkgs/by-name/ti/tinyproxy/package.nix
@@ -2,7 +2,7 @@
lib,
stdenv,
fetchFromGitHub,
- fetchpatch2,
+ fetchpatch,
autoreconfHook,
perl,
nixosTests,
@@ -22,10 +22,26 @@ stdenv.mkDerivation (finalAttrs: {
patches = [
# Fix case-sensitive matching of "chunked" (CVE-2026-31842)
- (fetchpatch2 {
+ (fetchpatch {
name = "fix-chunked-case-sensitivity.patch";
url = "https://github.com/tinyproxy/tinyproxy/commit/879bf844abffa0bf5fae6aff0c73179024dd9f98.patch";
- hash = "sha256-Nav3nXyxdoM/tIvfyPJHEYEjAtrRrJlvkMXzsQCZan4=";
+ hash = "sha256-kU9Vqf2YtnKNJU4eQlau/ijtXkGPS/n+YSeficfu7JM=";
+ })
+ # Remove when updating to the first upstream release containing these fixes.
+ (fetchpatch {
+ name = "CVE-2026-54387.patch";
+ url = "https://github.com/tinyproxy/tinyproxy/commit/623bfc093df009296f0b85d40bc677ef9d5c09bb.patch";
+ hash = "sha256-BSnK3XkBFW43cnD937RKr7FJzQT90BxJkILXz/QPZo8=";
+ })
+ (fetchpatch {
+ name = "CVE-2026-54388.patch";
+ url = "https://github.com/tinyproxy/tinyproxy/commit/364cdb67e0ea00a8e4a7037e2693e0711e816adb.patch";
+ hash = "sha256-+Z/Rj/zNldfOPVzWUlFHa37LEfSh/PtXOaN8z++ONJQ=";
+ })
+ (fetchpatch {
+ name = "CVE-2026-55202.patch";
+ url = "https://github.com/tinyproxy/tinyproxy/commit/09312a185ae25cc486b4ff5987638a7917a48bce.patch";
+ hash = "sha256-kwYk5E95KQK42ebLV0nHB706VynDnjHB/5eENKO7Eaw=";
})
];
diff --git a/pkgs/by-name/va/vaultwarden/webvault.nix b/pkgs/by-name/va/vaultwarden/webvault.nix
index 55a2c15e16ab..c62c3087533d 100644
--- a/pkgs/by-name/va/vaultwarden/webvault.nix
+++ b/pkgs/by-name/va/vaultwarden/webvault.nix
@@ -19,8 +19,8 @@ buildNpmPackage rec {
hash = "sha256-Uz0wPdhTVy2yOlKWAy5phr+30NmFaIPQQh5bsiWCDLA=";
};
- npmDepsFetcherVersion = 3;
- npmDepsHash = "sha256-PaDxqVsq00QIKDmhDhsEbKdM4QXfXn28PgpOyZjB60k=";
+ npmDepsFetcherVersion = 2;
+ npmDepsHash = "sha256-SkzEM54nMFqiYUqIRTbp3+yaZEJMgjFkjRLT5NZTN94=";
nativeBuildInputs = [
python3
diff --git a/pkgs/by-name/xd/xdg-desktop-portal/package.nix b/pkgs/by-name/xd/xdg-desktop-portal/package.nix
index 680c0e283a3c..04cf5343259d 100644
--- a/pkgs/by-name/xd/xdg-desktop-portal/package.nix
+++ b/pkgs/by-name/xd/xdg-desktop-portal/package.nix
@@ -39,13 +39,20 @@ let
domain = "gitlab.gnome.org";
owner = "GNOME";
repo = "libglnx";
- rev = "ccea836b799256420788c463a638ded0636b1632";
- hash = "sha256-H8Bg9QCSkt/aBOaHLyHYC2ei6OU7UpcLq8zLurkYOuA=";
+ rev = "ff64d52116ae74f0d25e24f089db28921ea171ff";
+ hash = "sha256-U6+vIU/wxnGGg07FJElQijbV0+jUswdG/lfzhw4wQy0=";
+ };
+ gvdbSrc = fetchFromGitLab {
+ domain = "gitlab.gnome.org";
+ owner = "GNOME";
+ repo = "gvdb";
+ rev = "c6f2359cc1d00f16e0a0e2527fa0bc1882b8b5ab";
+ hash = "sha256-FQPctq+fj6du0sBawaJxtO0PRO0KIHHhdA2jh24Yacw=";
};
in
stdenv.mkDerivation (finalAttrs: {
pname = "xdg-desktop-portal";
- version = "1.20.4";
+ version = "1.22.1";
outputs = [
"out"
@@ -57,7 +64,7 @@ stdenv.mkDerivation (finalAttrs: {
owner = "flatpak";
repo = "xdg-desktop-portal";
tag = finalAttrs.version;
- hash = "sha256-wLQgJsVicOb8G7M5Qwd+t90UgNYTD04bZ5Ki85Alr1w=";
+ hash = "sha256-GYPc5gFw3vMiDbrw5h6xeU7wupfyWeWq/Vl+vVrX8h0=";
};
patches = [
@@ -74,9 +81,6 @@ stdenv.mkDerivation (finalAttrs: {
# Allow installing installed tests to a separate output.
./installed-tests-path.patch
-
- # test tries to read /proc/cmdline, which is not intended to be accessible in the sandbox
- ./trash-test.patch
];
nativeBuildInputs = [
@@ -128,6 +132,7 @@ stdenv.mkDerivation (finalAttrs: {
ps.dbus-python
]))
umockdev
+ bubblewrap
];
checkInputs = [ umockdev ];
@@ -151,8 +156,9 @@ stdenv.mkDerivation (finalAttrs: {
doCheck = true;
postPatch = ''
- mkdir -p subprojects/libglnx
+ mkdir -p subprojects/{libglnx,gvdb}
cp -r ${libglnxSrc}/* subprojects/libglnx/
+ cp -r ${gvdbSrc}/* subprojects/gvdb/
# until/unless bubblewrap ships a pkg-config file, meson has no way to find it when cross-compiling.
substituteInPlace meson.build \
diff --git a/pkgs/by-name/xd/xdg-desktop-portal/trash-test.patch b/pkgs/by-name/xd/xdg-desktop-portal/trash-test.patch
deleted file mode 100644
index 23991fd87020..000000000000
--- a/pkgs/by-name/xd/xdg-desktop-portal/trash-test.patch
+++ /dev/null
@@ -1,18 +0,0 @@
-diff --git a/tests/test_trash.py b/tests/test_trash.py
-index 2637256..e89d45c 100644
---- a/tests/test_trash.py
-+++ b/tests/test_trash.py
-@@ -13,13 +13,6 @@ class TestTrash:
- def test_version(self, portals, dbus_con):
- xdp.check_version(dbus_con, "Trash", 1)
-
-- def test_trash_file_fails(self, portals, dbus_con):
-- trash_intf = xdp.get_portal_iface(dbus_con, "Trash")
-- with open("/proc/cmdline") as fd:
-- result = trash_intf.TrashFile(fd.fileno())
--
-- assert result == 0
--
- def test_trash_file(self, portals, dbus_con):
- trash_intf = xdp.get_portal_iface(dbus_con, "Trash")
-
diff --git a/pkgs/by-name/zi/zigbee2mqtt/package.nix b/pkgs/by-name/zi/zigbee2mqtt/package.nix
index ddf527f7b93e..c73b8df14224 100644
--- a/pkgs/by-name/zi/zigbee2mqtt/package.nix
+++ b/pkgs/by-name/zi/zigbee2mqtt/package.nix
@@ -14,20 +14,20 @@
}:
stdenv.mkDerivation (finalAttrs: {
pname = "zigbee2mqtt";
- version = "2.12.1";
+ version = "2.13.0";
src = fetchFromGitHub {
owner = "Koenkk";
repo = "zigbee2mqtt";
tag = finalAttrs.version;
- hash = "sha256-DTL27AcPmAI5XEEHb2S74LYWm4f6kUASsTmQeGftDzM=";
+ hash = "sha256-JSmJXjEF0dQ1sWyXvtLmN9gfAg3PjXWPOlb7xCxz8RI=";
};
pnpmDeps = fetchPnpmDeps {
inherit (finalAttrs) pname version src;
pnpm = pnpm_10;
fetcherVersion = 4;
- hash = "sha256-RI6tz8pyqYg/L6wSc0Rt5ZqHT8aktReyVjNgISPqKRQ=";
+ hash = "sha256-5S3VnPxR7P4dwXcFQSjNbTJ5KOWteb4ZBpTy7gtoY4I=";
};
nativeBuildInputs = [
diff --git a/pkgs/development/python-modules/fastapi-pagination/default.nix b/pkgs/development/python-modules/fastapi-pagination/default.nix
index 705adb2284cb..abe23ecaffd7 100644
--- a/pkgs/development/python-modules/fastapi-pagination/default.nix
+++ b/pkgs/development/python-modules/fastapi-pagination/default.nix
@@ -14,7 +14,7 @@
buildPythonPackage (finalAttrs: {
pname = "fastapi-pagination";
- version = "0.15.15";
+ version = "0.15.16";
pyproject = true;
__structuredAttrs = true;
@@ -22,7 +22,7 @@ buildPythonPackage (finalAttrs: {
owner = "uriyyo";
repo = "fastapi-pagination";
tag = finalAttrs.version;
- hash = "sha256-G6qF57MWlrZ4Poc+M2YtpKqquhOR/Zh4TnFmL2qZ1Uk=";
+ hash = "sha256-hsJbtR11Ej7lh8rqndnp47XdM67IypyT6cheMfskmio=";
};
build-system = [
diff --git a/pkgs/servers/home-assistant/custom-components/elegoo_printer/package.nix b/pkgs/servers/home-assistant/custom-components/elegoo_printer/package.nix
index 998fabdbe762..3fc648b431ba 100644
--- a/pkgs/servers/home-assistant/custom-components/elegoo_printer/package.nix
+++ b/pkgs/servers/home-assistant/custom-components/elegoo_printer/package.nix
@@ -19,13 +19,13 @@
buildHomeAssistantComponent rec {
owner = "danielcherubini";
domain = "elegoo_printer";
- version = "2.11.0";
+ version = "2.12.0";
src = fetchFromGitHub {
owner = "danielcherubini";
repo = "elegoo-homeassistant";
tag = "v${version}";
- hash = "sha256-UrmgWCY1U52LCt2O/HXOwbcIzTYX/TrnGxvW2S0iB7M=";
+ hash = "sha256-aeptx8CFKD+22H8Bw19rDUuHkET3vINN3NpGuherc8Y=";
};
dependencies = [
diff --git a/pkgs/servers/home-assistant/custom-components/powercalc/package.nix b/pkgs/servers/home-assistant/custom-components/powercalc/package.nix
index 7c632fe29365..8049c1740095 100644
--- a/pkgs/servers/home-assistant/custom-components/powercalc/package.nix
+++ b/pkgs/servers/home-assistant/custom-components/powercalc/package.nix
@@ -17,13 +17,13 @@
buildHomeAssistantComponent rec {
owner = "bramstroker";
domain = "powercalc";
- version = "1.23.0";
+ version = "1.23.2";
src = fetchFromGitHub {
inherit owner;
repo = "homeassistant-powercalc";
tag = "v${version}";
- hash = "sha256-WmbmKYcGwuny6Z2WLNZOACNs1jjKKlL9Dwvvd0Q2ass=";
+ hash = "sha256-JOZLVQhT3MhYbq6wuS7PM6H5fKVvf1ZhAYR5LZoRWAA=";
};
dependencies = [ numpy ];
diff --git a/pkgs/servers/http/nginx/modules/aliases.nix b/pkgs/servers/http/nginx/modules/aliases.nix
index 6d2c8b0a279d..9ddc1e7c1997 100644
--- a/pkgs/servers/http/nginx/modules/aliases.nix
+++ b/pkgs/servers/http/nginx/modules/aliases.nix
@@ -4,11 +4,14 @@ self: {
# keep-sorted start case=no numeric=yes block=yes
fastcgi-cache-purge = throw "fastcgi-cache-purge was renamed to cache-purge";
+ fluentd = throw "fluentd was removed due to lack of maintenance"; # Added 2026-08-02
http_proxy_connect_module_v24 = throw "http_proxy_connect_module_v24 was removed because it was not compatible with any supported nginx version"; # Added 2026-07-29
http_proxy_connect_module_v25 = throw "http_proxy_connect_module_v25 was removed because it was not compatible with any supported nginx version"; # Added 2026-07-29
modsecurity-nginx = self.modsecurity;
+ naxsi = throw "naxsi was removed because the build was broken & the repo is archived"; # Added 2026-08-02
ngx_aws_auth = throw "ngx_aws_auth was renamed to aws-auth";
opentracing = throw "opentracing-cpp was removed because opentracing as been archived upstream"; # Added 2025-10-19
+ pagespeed = throw "pagespeed was removed because the upstream repo is archived & the build was broken"; # Added 2026-08-02
statsd = throw "statsd was removed because its upstream source vanished"; # Added 2026-07-28
# keep-sorted end
}
diff --git a/pkgs/servers/http/nginx/modules/aws-auth/package.nix b/pkgs/servers/http/nginx/modules/aws-auth/package.nix
index 5499a506a3b8..5de4483c87c4 100644
--- a/pkgs/servers/http/nginx/modules/aws-auth/package.nix
+++ b/pkgs/servers/http/nginx/modules/aws-auth/package.nix
@@ -20,5 +20,6 @@ mkNginxPlugin (finalAttrs: {
homepage = "https://github.com/anomalizer/ngx_aws_auth";
license = lib.licenses.bsd2;
maintainers = [ ];
+ broken = true;
};
})
diff --git a/pkgs/servers/http/nginx/modules/cache-purge/package.nix b/pkgs/servers/http/nginx/modules/cache-purge/package.nix
index 8e2211d8b05d..5da23ae14be2 100644
--- a/pkgs/servers/http/nginx/modules/cache-purge/package.nix
+++ b/pkgs/servers/http/nginx/modules/cache-purge/package.nix
@@ -6,13 +6,13 @@
mkNginxPlugin (finalAttrs: {
pname = "cache-purge";
- version = "2.5.1";
+ version = "3.0.2";
src = fetchFromGitHub {
owner = "nginx-modules";
repo = "ngx_cache_purge";
tag = finalAttrs.version;
- hash = "sha256-jVm8E4u1NkjtBoGdRzUDo6l27XPDFoCrNUf2asaXRG0=";
+ hash = "sha256-kjZbHXaDCh4EHK59XuIISZ0xcgd2c+plwrXvqB+2S1E=";
};
meta = {
diff --git a/pkgs/servers/http/nginx/modules/develkit/package.nix b/pkgs/servers/http/nginx/modules/develkit/package.nix
index cb2fceae3cdf..827d6eb791c3 100644
--- a/pkgs/servers/http/nginx/modules/develkit/package.nix
+++ b/pkgs/servers/http/nginx/modules/develkit/package.nix
@@ -6,13 +6,13 @@
mkNginxPlugin (finalAttrs: {
pname = "develkit";
- version = "0.3.3";
+ version = "0.3.4";
src = fetchFromGitHub {
owner = "vision5";
repo = "ngx_devel_kit";
tag = "v${finalAttrs.version}";
- hash = "sha256-/RQUVHwIdNqm3UemQ/oNs2ksg8beziA4Pxejd5Yg0Pg=";
+ hash = "sha256-SXQ5KC8X9nKLbntXjEziCqJVeiX+lnBKruAVVVcexaM=";
};
meta = {
diff --git a/pkgs/servers/http/nginx/modules/fancyindex/package.nix b/pkgs/servers/http/nginx/modules/fancyindex/package.nix
index e91359568288..b8be79fe85b9 100644
--- a/pkgs/servers/http/nginx/modules/fancyindex/package.nix
+++ b/pkgs/servers/http/nginx/modules/fancyindex/package.nix
@@ -6,13 +6,13 @@
mkNginxPlugin (finalAttrs: {
pname = "fancyindex";
- version = "0.5.2";
+ version = "0.6.0";
src = fetchFromGitHub {
owner = "aperezdc";
repo = "ngx-fancyindex";
tag = "v${finalAttrs.version}";
- hash = "sha256-70bEZ5EVM3jjY5b9azXYBvJnFDoqgGXu0F7JcWkhWVk=";
+ hash = "sha256-97HCAm3hcgrwyOvBEwC+vcVkuuzedgHC67+w8OK2bEQ=";
};
meta = {
diff --git a/pkgs/servers/http/nginx/modules/fluentd/package.nix b/pkgs/servers/http/nginx/modules/fluentd/package.nix
deleted file mode 100644
index 57cd3676de7c..000000000000
--- a/pkgs/servers/http/nginx/modules/fluentd/package.nix
+++ /dev/null
@@ -1,24 +0,0 @@
-{
- fetchFromGitHub,
- lib,
- mkNginxPlugin,
-}:
-
-mkNginxPlugin (finalAttrs: {
- pname = "fluentd";
- version = "0.3-unstable-2014-03-28";
-
- src = fetchFromGitHub {
- owner = "fluent";
- repo = "nginx-fluentd-module";
- rev = "8af234043059c857be27879bc547c141eafd5c13";
- hash = "sha256-tf+jrac1QGOEwQnmDPmMMvM/Tg1TXTmKysBwndovi/k=";
- };
-
- meta = {
- description = "Fluentd data collector";
- homepage = "https://github.com/fluent/nginx-fluentd-module";
- license = lib.licenses.asl20;
- maintainers = [ ];
- };
-})
diff --git a/pkgs/servers/http/nginx/modules/lua-upstream/package.nix b/pkgs/servers/http/nginx/modules/lua-upstream/package.nix
index 5d2eaa351c44..02e24a2dae9d 100644
--- a/pkgs/servers/http/nginx/modules/lua-upstream/package.nix
+++ b/pkgs/servers/http/nginx/modules/lua-upstream/package.nix
@@ -26,5 +26,6 @@ mkNginxPlugin (finalAttrs: {
homepage = "https://github.com/openresty/lua-upstream-nginx-module";
license = lib.licenses.bsd2;
maintainers = [ ];
+ broken = true; # Build against nginx fails
};
})
diff --git a/pkgs/servers/http/nginx/modules/naxsi/package.nix b/pkgs/servers/http/nginx/modules/naxsi/package.nix
deleted file mode 100644
index c1af28a7d076..000000000000
--- a/pkgs/servers/http/nginx/modules/naxsi/package.nix
+++ /dev/null
@@ -1,26 +0,0 @@
-{
- fetchFromGitHub,
- lib,
- mkNginxPlugin,
-}:
-
-mkNginxPlugin (finalAttrs: {
- pname = "naxsi";
- version = "1.0-unstable-2020-09-10";
-
- src = fetchFromGitHub {
- owner = "nbs-system";
- repo = "naxsi";
- rev = "95ac520eed2ea04098a76305fd0ad7e9158840b7";
- sha256 = "0b5pnqkgg18kbw5rf2ifiq7lsx5rqmpqsql6hx5ycxjzxj6acfb3";
- };
-
- sourceRoot = "${finalAttrs.src.name}/naxsi_src";
-
- meta = {
- description = "Open-source, high performance, low rules maintenance WAF";
- homepage = "https://github.com/nbs-system/naxsi";
- license = lib.licenses.gpl3;
- maintainers = [ ];
- };
-})
diff --git a/pkgs/servers/http/nginx/modules/njs/package.nix b/pkgs/servers/http/nginx/modules/njs/package.nix
index a6b3af2f36ff..c275ae255845 100644
--- a/pkgs/servers/http/nginx/modules/njs/package.nix
+++ b/pkgs/servers/http/nginx/modules/njs/package.nix
@@ -9,13 +9,13 @@
mkNginxPlugin (finalAttrs: {
pname = "njs";
- version = "0.9.4";
+ version = "1.0.0";
src = fetchFromGitHub {
owner = "nginx";
repo = "njs";
tag = finalAttrs.version;
- hash = "sha256-Ee55QKaeZ0mYGKUroKr/AYGoOCakEonU483qkhmZdzU=";
+ hash = "sha256-svZvAVcIm13SVf4O5rgZOigJ8IKuaPQrnZenkZaDluQ=";
};
preConfigure = ''
diff --git a/pkgs/servers/http/nginx/modules/pagespeed/package.nix b/pkgs/servers/http/nginx/modules/pagespeed/package.nix
deleted file mode 100644
index 696bdfdde986..000000000000
--- a/pkgs/servers/http/nginx/modules/pagespeed/package.nix
+++ /dev/null
@@ -1,51 +0,0 @@
-{
- fetchFromGitHub,
- lib,
- libuuid,
- mkNginxPlugin,
- psol,
- runCommand,
- zlib,
-}:
-
-mkNginxPlugin (finalAttrs: {
- pname = "pagespeed";
- version = psol.version;
-
- src =
- let
- moduleSrc = fetchFromGitHub {
- owner = "apache";
- repo = "incubator-pagespeed-ngx";
- rev = "v${psol.version}-stable";
- sha256 = "0ry7vmkb2bx0sspl1kgjlrzzz6lbz07313ks2lr80rrdm2zb16wp";
- };
- in
- runCommand "ngx_pagespeed"
- {
- meta = {
- description = "PageSpeed module for Nginx";
- homepage = "https://developers.google.com/speed/pagespeed/module/";
- license = lib.licenses.asl20;
- };
- }
- ''
- cp -r "${moduleSrc}" "$out"
- chmod -R +w "$out"
- ln -s "${psol}" "$out/psol"
- '';
-
- buildInputs = [
- zlib
- libuuid
- ]; # psol deps
-
- allowMemoryWriteExecute = true;
-
- meta = {
- description = "Automatic PageSpeed optimization";
- homepage = "https://github.com/apache/incubator-pagespeed-ngx";
- license = lib.licenses.asl20;
- maintainers = [ ];
- };
-})
diff --git a/pkgs/servers/http/nginx/modules/push-stream/package.nix b/pkgs/servers/http/nginx/modules/push-stream/package.nix
index 8d9df1b59130..49ec6a5c661f 100644
--- a/pkgs/servers/http/nginx/modules/push-stream/package.nix
+++ b/pkgs/servers/http/nginx/modules/push-stream/package.nix
@@ -20,5 +20,6 @@ mkNginxPlugin (finalAttrs: {
homepage = "https://github.com/wandenberg/nginx-push-stream-module";
license = lib.licenses.gpl3;
maintainers = [ ];
+ broken = true;
};
})
diff --git a/pkgs/servers/http/nginx/modules/video-thumbextractor/package.nix b/pkgs/servers/http/nginx/modules/video-thumbextractor/package.nix
index 54070a0ea7e0..90e4822ab46a 100644
--- a/pkgs/servers/http/nginx/modules/video-thumbextractor/package.nix
+++ b/pkgs/servers/http/nginx/modules/video-thumbextractor/package.nix
@@ -27,5 +27,6 @@ mkNginxPlugin (finalAttrs: {
homepage = "https://github.com/wandenberg/nginx-video-thumbextractor-module";
license = lib.licenses.gpl3;
maintainers = [ ];
+ broken = true;
};
})
diff --git a/pkgs/servers/http/nginx/modules/vts/package.nix b/pkgs/servers/http/nginx/modules/vts/package.nix
index fffb783fd6fe..10858b0cb7ca 100644
--- a/pkgs/servers/http/nginx/modules/vts/package.nix
+++ b/pkgs/servers/http/nginx/modules/vts/package.nix
@@ -6,13 +6,13 @@
mkNginxPlugin (finalAttrs: {
pname = "vts";
- version = "0.2.2";
+ version = "0.2.6";
src = fetchFromGitHub {
owner = "vozlt";
repo = "nginx-module-vts";
tag = "v${finalAttrs.version}";
- hash = "sha256-ReTmYGVSOwtnYDMkQDMWwxw09vT4iHYfYZvgd8iBotk=";
+ hash = "sha256-3u4igVGBVsv+GNi3CSduZL6ZaOmdPoItUPA4+wmRw5Y=";
};
meta = {
diff --git a/pkgs/servers/kanidm/1_10.nix b/pkgs/servers/kanidm/1_10.nix
index 543296dd86f3..7601a72038eb 100644
--- a/pkgs/servers/kanidm/1_10.nix
+++ b/pkgs/servers/kanidm/1_10.nix
@@ -2,4 +2,5 @@ import ./generic.nix {
version = "1.10.5";
hash = "sha256-mNdG5iPtnhwvy9PABaRPV6KQfvD+/ZKH2hC6Hfo0y48=";
cargoHash = "sha256-UE/jZaX/mEJUHBqsk2o0rBcocpoFg5XWAmVk4smm5mc=";
+ eolDate = "2026-08-31";
}
diff --git a/pkgs/servers/kanidm/1_11.nix b/pkgs/servers/kanidm/1_11.nix
new file mode 100644
index 000000000000..c06b30750207
--- /dev/null
+++ b/pkgs/servers/kanidm/1_11.nix
@@ -0,0 +1,5 @@
+import ./generic.nix {
+ version = "1.11.0";
+ hash = "sha256-3dcJxJx8UFebW6WMdVTH6kfsNBed+55JFwHWVhZulOU=";
+ cargoHash = "sha256-qOs/uSs3iaiTGsqydpNbZ6KSLNE+k+5bM7k3ijRzNT0=";
+}
diff --git a/pkgs/servers/kanidm/generic.nix b/pkgs/servers/kanidm/generic.nix
index fcd8c3e543a9..9c5ee6266aa0 100644
--- a/pkgs/servers/kanidm/generic.nix
+++ b/pkgs/servers/kanidm/generic.nix
@@ -91,14 +91,23 @@ rustPlatform.buildRustPackage (finalAttrs: {
// lib.optionalAttrs (lib.versionAtLeast finalAttrs.version "1.9") {
server_migration_path = "/etc/kanidm/migrations.d";
};
+ # lower required rust-version in Cargo.toml to allow backporting
+ rustVersion =
+ if lib.versionAtLeast finalAttrs.version "1.11" then
+ {
+ from = "1.96";
+ to = "1.95";
+ }
+ else
+ null;
in
''
cp ${format profile} libs/profiles/${finalAttrs.env.KANIDM_BUILD_PROFILE}.toml
substituteInPlace libs/profiles/${finalAttrs.env.KANIDM_BUILD_PROFILE}.toml --replace-fail '@htmx_ui_pkg_path@' "$out/ui/hpkg"
''
- + lib.optionalString (lib.versionAtLeast finalAttrs.version "1.9") ''
+ + lib.optionalString (rustVersion != null) ''
substituteInPlace Cargo.toml \
- --replace-fail 'rust-version = "1.93"' 'rust-version = "1.91"'
+ --replace-fail 'rust-version = "${rustVersion.from}"' 'rust-version = "${rustVersion.to}"'
'';
nativeBuildInputs = [
diff --git a/pkgs/servers/kanidm/provision-patches/1_11/oauth2-basic-secret-modify.patch b/pkgs/servers/kanidm/provision-patches/1_11/oauth2-basic-secret-modify.patch
new file mode 100644
index 000000000000..5101273d30d1
--- /dev/null
+++ b/pkgs/servers/kanidm/provision-patches/1_11/oauth2-basic-secret-modify.patch
@@ -0,0 +1,159 @@
+From 5b97267c49def10f5a4b7bb372963261c0f4b08d Mon Sep 17 00:00:00 2001
+From: oddlama
+Date: Fri, 1 May 2026 15:01:05 +0200
+Subject: [PATCH 1/2] oauth2 basic secret modify
+
+---
+ server/core/src/actors/v1_write.rs | 42 +++++++++++++++++++++++++++++
+ server/core/src/https/v1.rs | 6 ++++-
+ server/core/src/https/v1_oauth2.rs | 29 ++++++++++++++++++++
+ server/lib/src/server/migrations.rs | 16 +++++++++++
+ 4 files changed, 92 insertions(+), 1 deletion(-)
+
+diff --git a/server/core/src/actors/v1_write.rs b/server/core/src/actors/v1_write.rs
+index 977292ae9..bf79c42a1 100644
+--- a/server/core/src/actors/v1_write.rs
++++ b/server/core/src/actors/v1_write.rs
+@@ -326,6 +326,48 @@ impl QueryServerWriteV1 {
+ .and_then(|_| idms_prox_write.commit().map(|_| ()))
+ }
+
++ #[instrument(
++ level = "info",
++ skip_all,
++ fields(uuid = ?eventid)
++ )]
++ pub async fn handle_oauth2_basic_secret_write(
++ &self,
++ client_auth_info: ClientAuthInfo,
++ filter: Filter,
++ new_secret: String,
++ eventid: Uuid,
++ ) -> Result<(), OperationError> {
++ // Given a protoEntry, turn this into a modification set.
++ let ct = duration_from_epoch_now();
++ let mut idms_prox_write = self.idms.proxy_write(ct).await?;
++ let ident = idms_prox_write
++ .validate_client_auth_info_to_ident(client_auth_info, ct)
++ .map_err(|e| {
++ admin_error!(err = ?e, "Invalid identity");
++ e
++ })?;
++
++ let modlist = ModifyList::new_purge_and_set(
++ Attribute::OAuth2RsBasicSecret,
++ Value::SecretValue(new_secret),
++ );
++
++ let mdf =
++ ModifyEvent::from_internal_parts(ident, &modlist, &filter, &idms_prox_write.qs_write)
++ .map_err(|e| {
++ admin_error!(err = ?e, "Failed to begin modify during handle_oauth2_basic_secret_write");
++ e
++ })?;
++
++ trace!(?mdf, "Begin modify event");
++
++ idms_prox_write
++ .qs_write
++ .modify(&mdf)
++ .and_then(|_| idms_prox_write.commit())
++ }
++
+ #[instrument(
+ level = "info",
+ skip_all,
+diff --git a/server/core/src/https/v1.rs b/server/core/src/https/v1.rs
+index ba3ea2827..489ce0002 100644
+--- a/server/core/src/https/v1.rs
++++ b/server/core/src/https/v1.rs
+@@ -10,7 +10,7 @@ use axum::extract::{Path, State};
+ use axum::http::{HeaderMap, HeaderValue};
+ use axum::middleware::from_fn;
+ use axum::response::{IntoResponse, Response};
+-use axum::routing::{delete, get, post, put};
++use axum::routing::{delete, get, post, put, patch};
+ use axum::{Extension, Json, Router};
+ use axum_extra::extract::cookie::{Cookie, CookieJar, SameSite};
+ use compact_jwt::{Jwk, Jws, JwsSigner};
+@@ -3156,6 +3156,10 @@ pub(crate) fn route_setup(state: ServerState) -> Router {
+ "/v1/oauth2/{rs_name}/_basic_secret",
+ get(super::v1_oauth2::oauth2_id_get_basic_secret),
+ )
++ .route(
++ "/v1/oauth2/{rs_name}/_basic_secret",
++ patch(super::v1_oauth2::oauth2_id_patch_basic_secret),
++ )
+ .route(
+ "/v1/oauth2/{rs_name}/_scopemap/{group}",
+ post(super::v1_oauth2::oauth2_id_scopemap_post)
+diff --git a/server/core/src/https/v1_oauth2.rs b/server/core/src/https/v1_oauth2.rs
+index fdc3647b4..ed4709d27 100644
+--- a/server/core/src/https/v1_oauth2.rs
++++ b/server/core/src/https/v1_oauth2.rs
+@@ -149,6 +149,35 @@ pub(crate) async fn oauth2_id_get_basic_secret(
+ .map_err(WebError::from)
+ }
+
++#[utoipa::path(
++ patch,
++ path = "/v1/oauth2/{rs_name}/_basic_secret",
++ request_body=ProtoEntry,
++ responses(
++ DefaultApiResponse,
++ ),
++ security(("token_jwt" = [])),
++ tag = "v1/oauth2",
++ operation_id = "oauth2_id_patch_basic_secret"
++)]
++/// Overwrite the basic secret for a given OAuth2 Resource Server.
++#[instrument(level = "info", skip(state, new_secret))]
++pub(crate) async fn oauth2_id_patch_basic_secret(
++ State(state): State,
++ Extension(kopid): Extension,
++ VerifiedClientInformation(client_auth_info): VerifiedClientInformation,
++ Path(rs_name): Path,
++ Json(new_secret): Json,
++) -> Result, WebError> {
++ let filter = oauth2_id(&rs_name);
++ state
++ .qe_w_ref
++ .handle_oauth2_basic_secret_write(client_auth_info, filter, new_secret, kopid.eventid)
++ .await
++ .map(Json::from)
++ .map_err(WebError::from)
++}
++
+ #[utoipa::path(
+ patch,
+ path = "/v1/oauth2/{rs_name}",
+diff --git a/server/lib/src/server/migrations.rs b/server/lib/src/server/migrations.rs
+index b3effb95b..5c6a56d24 100644
+--- a/server/lib/src/server/migrations.rs
++++ b/server/lib/src/server/migrations.rs
+@@ -220,6 +220,22 @@ impl QueryServer {
+ reload_required = true;
+ };
+
++ // secret provisioning: allow idm_admin to modify OAuth2RsBasicSecret.
++ write_txn.internal_modify_uuid(
++ UUID_IDM_ACP_OAUTH2_MANAGE_V1,
++ &ModifyList::new_append(
++ Attribute::AcpCreateAttr,
++ Attribute::OAuth2RsBasicSecret.into(),
++ ),
++ )?;
++ write_txn.internal_modify_uuid(
++ UUID_IDM_ACP_OAUTH2_MANAGE_V1,
++ &ModifyList::new_append(
++ Attribute::AcpModifyPresentAttr,
++ Attribute::OAuth2RsBasicSecret.into(),
++ ),
++ )?;
++
+ // Execute whatever operations we have batched up and ready to go. This is needed
+ // to preserve ordering of the operations - if we reloaded after a remigrate then
+ // we would have skipped the patch level fix which needs to have occurred *first*.
+--
+2.53.0
+
diff --git a/pkgs/servers/kanidm/provision-patches/1_11/recover-account.patch b/pkgs/servers/kanidm/provision-patches/1_11/recover-account.patch
new file mode 100644
index 000000000000..a462c14d5d1c
--- /dev/null
+++ b/pkgs/servers/kanidm/provision-patches/1_11/recover-account.patch
@@ -0,0 +1,128 @@
+From e8cd69afcee9d8d37233fa998cf9d1fa124ae90d Mon Sep 17 00:00:00 2001
+From: oddlama
+Date: Fri, 1 May 2026 15:01:14 +0200
+Subject: [PATCH 2/2] recover account
+
+---
+ server/core/src/actors/internal.rs | 5 +++--
+ server/core/src/admin.rs | 6 +++---
+ server/daemon/src/main.rs | 24 +++++++++++++++++++++++-
+ server/daemon/src/opt.rs | 7 +++++++
+ 4 files changed, 36 insertions(+), 6 deletions(-)
+
+diff --git a/server/core/src/actors/internal.rs b/server/core/src/actors/internal.rs
+index deed7350d..f4e9e486a 100644
+--- a/server/core/src/actors/internal.rs
++++ b/server/core/src/actors/internal.rs
+@@ -189,17 +189,18 @@ impl QueryServerWriteV1 {
+
+ #[instrument(
+ level = "info",
+- skip(self, eventid),
++ skip(self, password, eventid),
+ fields(uuid = ?eventid)
+ )]
+ pub(crate) async fn handle_admin_recover_account(
+ &self,
+ name: String,
++ password: Option,
+ eventid: Uuid,
+ ) -> Result {
+ let ct = duration_from_epoch_now();
+ let mut idms_prox_write = self.idms.proxy_write(ct).await?;
+- let pw = idms_prox_write.recover_account(name.as_str(), None)?;
++ let pw = idms_prox_write.recover_account(name.as_str(), password.as_deref())?;
+
+ idms_prox_write.commit().map(|()| pw)
+ }
+diff --git a/server/core/src/admin.rs b/server/core/src/admin.rs
+index 6a13dcaab..6b1070113 100644
+--- a/server/core/src/admin.rs
++++ b/server/core/src/admin.rs
+@@ -27,7 +27,7 @@ const REPL_CTRL_TIMEOUT: Duration = Duration::from_secs(15);
+
+ #[derive(Serialize, Deserialize, Debug)]
+ pub enum AdminTaskRequest {
+- RecoverAccount { name: String },
++ RecoverAccount { name: String, password: Option },
+ DisableAccount { name: String },
+ ShowReplicationCertificate,
+ ShowReplicationCertificateMetadata,
+@@ -416,8 +416,8 @@ async fn handle_client(
+
+ let resp = async {
+ match req {
+- AdminTaskRequest::RecoverAccount { name } => {
+- match server_rw.handle_admin_recover_account(name, eventid).await {
++ AdminTaskRequest::RecoverAccount { name, password } => {
++ match server_rw.handle_admin_recover_account(name, password, eventid).await {
+ Ok(password) => AdminTaskResponse::RecoverAccount { password },
+ Err(e) => {
+ error!(err = ?e, "error during recover-account");
+diff --git a/server/daemon/src/main.rs b/server/daemon/src/main.rs
+index 13653a5cb..ae560f9ce 100644
+--- a/server/daemon/src/main.rs
++++ b/server/daemon/src/main.rs
+@@ -380,11 +380,32 @@ fn check_file_ownership(opt: &KanidmdParser) -> Result<(), ExitCode> {
+
+ async fn scripting_command(cmd: ScriptingCommand, config: Configuration) -> ExitCode {
+ match cmd {
+- ScriptingCommand::RecoverAccount { name } => {
++ ScriptingCommand::RecoverAccount { name, from_environment } => {
++ let password = if from_environment {
++ match std::env::var("KANIDM_RECOVER_ACCOUNT_PASSWORD_FILE") {
++ Ok(path) => match tokio::fs::read_to_string(&path).await {
++ Ok(contents) => Some(contents),
++ Err(e) => {
++ error!("Failed to read password file '{}': {}", path, e);
++ return ExitCode::FAILURE;
++ }
++ },
++ Err(_) => match std::env::var("KANIDM_RECOVER_ACCOUNT_PASSWORD") {
++ Ok(val) => Some(val),
++ Err(_) => {
++ error!("Neither KANIDM_RECOVER_ACCOUNT_PASSWORD_FILE nor KANIDM_RECOVER_ACCOUNT_PASSWORD was set");
++ return ExitCode::FAILURE;
++ }
++ }
++ }
++ } else {
++ None
++ };
+ submit_admin_req_json(
+ config.adminbindpath.as_str(),
+ AdminTaskRequest::RecoverAccount {
+ name: name.to_owned(),
++ password,
+ },
+ )
+ .await;
+@@ -1008,6 +1029,7 @@ async fn kanidm_main(config: Configuration, opt: KanidmdParser) -> ExitCode {
+ config.adminbindpath.as_str(),
+ AdminTaskRequest::RecoverAccount {
+ name: name.to_owned(),
++ password: None,
+ },
+ )
+ .await;
+diff --git a/server/daemon/src/opt.rs b/server/daemon/src/opt.rs
+index 524ba3134..fa3d70f44 100644
+--- a/server/daemon/src/opt.rs
++++ b/server/daemon/src/opt.rs
+@@ -128,6 +128,13 @@ enum ScriptingCommand {
+ #[clap(value_parser)]
+ /// The account name to recover credentials for.
+ name: String,
++ /// Use a password given via an environment variable.
++ /// - `KANIDM_RECOVER_ACCOUNT_PASSWORD_FILE` takes precedence and reads the desired
++ /// password from the given file
++ /// - `KANIDM_RECOVER_ACCOUNT_PASSWORD` directly takes a
++ /// password - beware that this will leave the password in the environment
++ #[clap(long = "from-environment")]
++ from_environment: bool,
+ },
+ /// Backup
+ Backup {
+--
+2.53.0
+
diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix
index 648fa88bff55..506c38f1bc91 100644
--- a/pkgs/top-level/all-packages.nix
+++ b/pkgs/top-level/all-packages.nix
@@ -7378,17 +7378,23 @@ with pkgs;
kanidm_1_10 = callPackage ../servers/kanidm/1_10.nix {
kanidmWithSecretProvisioning = kanidmWithSecretProvisioning_1_10;
};
+ kanidm_1_11 = callPackage ../servers/kanidm/1_11.nix {
+ kanidmWithSecretProvisioning = kanidmWithSecretProvisioning_1_11;
+ };
kanidmWithSecretProvisioning_1_8 = kanidm_1_8.override { enableSecretProvisioning = true; };
kanidmWithSecretProvisioning_1_9 = kanidm_1_9.override { enableSecretProvisioning = true; };
kanidmWithSecretProvisioning_1_10 = kanidm_1_10.override { enableSecretProvisioning = true; };
+ kanidmWithSecretProvisioning_1_11 = kanidm_1_11.override { enableSecretProvisioning = true; };
})
kanidm_1_8
kanidm_1_9
kanidm_1_10
+ kanidm_1_11
kanidmWithSecretProvisioning_1_8
kanidmWithSecretProvisioning_1_9
kanidmWithSecretProvisioning_1_10
+ kanidmWithSecretProvisioning_1_11
;
lemmy-server = callPackage ../servers/web-apps/lemmy/server.nix { };
diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix
index aed44234b45b..7c52ed9443bc 100644
--- a/pkgs/top-level/perl-packages.nix
+++ b/pkgs/top-level/perl-packages.nix
@@ -8987,8 +8987,21 @@ with self;
url = "mirror://cpan/authors/id/S/SB/SBECK/Date-Manip-6.98.tar.gz";
hash = "sha256-rP2KYFGbpM0YHIpnqD1/ApxtmrTosCEtxH5B1iEP2kk=";
};
+ # Remove when updating to the first release containing both CVE fixes.
+ patches = [
+ (fetchpatch {
+ name = "CVE-2026-60074.patch";
+ url = "https://security.metacpan.org/patches/D/Date-Manip/6.99/CVE-2026-60074-r1.patch";
+ hash = "sha256-leXFfzLyy0yBpBXgT3u3ZyFaIbsbJSFzVkdam9hb3+0=";
+ })
+ (fetchpatch {
+ name = "CVE-2026-60075.patch";
+ url = "https://security.metacpan.org/patches/D/Date-Manip/6.99/CVE-2026-60075-r1.patch";
+ hash = "sha256-vMsOrUhrfn8efKRzfJ+jaypOHER8MlUIob5u88n/TAw=";
+ })
+ ];
# for some reason, parsing /etc/localtime does not work anymore - make sure that the fallback "/bin/date +%Z" will work
- patchPhase = ''
+ postPatch = ''
sed -i "s#/bin/date#${pkgs.coreutils}/bin/date#" lib/Date/Manip/TZ.pm
'';
doCheck = !stdenv.hostPlatform.isi686; # build freezes during tests on i686