From 2356d4e708e3a4ad4cb3cd6bb196d2fef78af3d8 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 8 Jul 2026 16:40:18 +0000 Subject: [PATCH 01/71] libmodsecurity: 3.0.15 -> 3.0.16 --- pkgs/by-name/li/libmodsecurity/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/li/libmodsecurity/package.nix b/pkgs/by-name/li/libmodsecurity/package.nix index 5224f7f6e81b..6baec57daee1 100644 --- a/pkgs/by-name/li/libmodsecurity/package.nix +++ b/pkgs/by-name/li/libmodsecurity/package.nix @@ -20,13 +20,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "libmodsecurity"; - version = "3.0.15"; + version = "3.0.16"; src = fetchFromGitHub { owner = "owasp-modsecurity"; repo = "ModSecurity"; rev = "v${finalAttrs.version}"; - hash = "sha256-gI874wkqy8VuwxUmIgb8d7fULJUQ+rKBBF492NtuRMY="; + hash = "sha256-KkUZ52IQ8kZPP4znvNX2kDCbYFBesmvV5i1tVgHFct8="; fetchSubmodules = true; }; @@ -63,7 +63,7 @@ stdenv.mkDerivation (finalAttrs: { ]; postPatch = '' - # https://github.com/owasp-modsecurity/ModSecurity/blob/v3.0.15/build.sh#L6-L25 + # https://github.com/owasp-modsecurity/ModSecurity/blob/v3.0.16/build.sh#L6-L25 echo "noinst_HEADERS = \\" > ./src/headers.mk ls -1 ./src/ \ actions/*.h \ From b804fa464fe6b6a4b427c58ec9b57c1a12a11279 Mon Sep 17 00:00:00 2001 From: Marie Ramlow Date: Thu, 4 Jun 2026 11:56:27 +0200 Subject: [PATCH 02/71] xdg-desktop-portal: 1.20.4 -> 1.22.1 --- .../installed-tests/xdg-desktop-portal.nix | 1 + .../by-name/xd/xdg-desktop-portal/package.nix | 22 ++++++++++++------- .../xd/xdg-desktop-portal/trash-test.patch | 18 --------------- 3 files changed, 15 insertions(+), 26 deletions(-) delete mode 100644 pkgs/by-name/xd/xdg-desktop-portal/trash-test.patch diff --git a/nixos/tests/installed-tests/xdg-desktop-portal.nix b/nixos/tests/installed-tests/xdg-desktop-portal.nix index a85203fe3eda..dabc2fb306e0 100644 --- a/nixos/tests/installed-tests/xdg-desktop-portal.nix +++ b/nixos/tests/installed-tests/xdg-desktop-portal.nix @@ -22,6 +22,7 @@ makeInstalledTest { environment.systemPackages = with pkgs; [ umockdev wireless-regdb + bubblewrap ]; services.geoclue2 = { enable = true; diff --git a/pkgs/by-name/xd/xdg-desktop-portal/package.nix b/pkgs/by-name/xd/xdg-desktop-portal/package.nix index 32c369a0e4a6..0cb5231b568a 100644 --- a/pkgs/by-name/xd/xdg-desktop-portal/package.nix +++ b/pkgs/by-name/xd/xdg-desktop-portal/package.nix @@ -40,13 +40,20 @@ let domain = "gitlab.gnome.org"; owner = "GNOME"; repo = "libglnx"; - rev = "ccea836b799256420788c463a638ded0636b1632"; - hash = "sha256-H8Bg9QCSkt/aBOaHLyHYC2ei6OU7UpcLq8zLurkYOuA="; + rev = "ff64d52116ae74f0d25e24f089db28921ea171ff"; + hash = "sha256-U6+vIU/wxnGGg07FJElQijbV0+jUswdG/lfzhw4wQy0="; + }; + gvdbSrc = fetchFromGitLab { + domain = "gitlab.gnome.org"; + owner = "GNOME"; + repo = "gvdb"; + rev = "c6f2359cc1d00f16e0a0e2527fa0bc1882b8b5ab"; + hash = "sha256-FQPctq+fj6du0sBawaJxtO0PRO0KIHHhdA2jh24Yacw="; }; in stdenv.mkDerivation (finalAttrs: { pname = "xdg-desktop-portal"; - version = "1.20.4"; + version = "1.22.1"; outputs = [ "out" @@ -58,7 +65,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "flatpak"; repo = "xdg-desktop-portal"; tag = finalAttrs.version; - hash = "sha256-wLQgJsVicOb8G7M5Qwd+t90UgNYTD04bZ5Ki85Alr1w="; + hash = "sha256-GYPc5gFw3vMiDbrw5h6xeU7wupfyWeWq/Vl+vVrX8h0="; }; patches = [ @@ -75,9 +82,6 @@ stdenv.mkDerivation (finalAttrs: { # Allow installing installed tests to a separate output. ./installed-tests-path.patch - - # test tries to read /proc/cmdline, which is not intended to be accessible in the sandbox - ./trash-test.patch ]; nativeBuildInputs = [ @@ -129,6 +133,7 @@ stdenv.mkDerivation (finalAttrs: { ps.dbus-python ])) umockdev + bubblewrap ]; checkInputs = [ umockdev ]; @@ -152,8 +157,9 @@ stdenv.mkDerivation (finalAttrs: { doCheck = true; postPatch = '' - mkdir -p subprojects/libglnx + mkdir -p subprojects/{libglnx,gvdb} cp -r ${libglnxSrc}/* subprojects/libglnx/ + cp -r ${gvdbSrc}/* subprojects/gvdb/ # until/unless bubblewrap ships a pkg-config file, meson has no way to find it when cross-compiling. substituteInPlace meson.build \ diff --git a/pkgs/by-name/xd/xdg-desktop-portal/trash-test.patch b/pkgs/by-name/xd/xdg-desktop-portal/trash-test.patch deleted file mode 100644 index 23991fd87020..000000000000 --- a/pkgs/by-name/xd/xdg-desktop-portal/trash-test.patch +++ /dev/null @@ -1,18 +0,0 @@ -diff --git a/tests/test_trash.py b/tests/test_trash.py -index 2637256..e89d45c 100644 ---- a/tests/test_trash.py -+++ b/tests/test_trash.py -@@ -13,13 +13,6 @@ class TestTrash: - def test_version(self, portals, dbus_con): - xdp.check_version(dbus_con, "Trash", 1) - -- def test_trash_file_fails(self, portals, dbus_con): -- trash_intf = xdp.get_portal_iface(dbus_con, "Trash") -- with open("/proc/cmdline") as fd: -- result = trash_intf.TrashFile(fd.fileno()) -- -- assert result == 0 -- - def test_trash_file(self, portals, dbus_con): - trash_intf = xdp.get_portal_iface(dbus_con, "Trash") - From 83c10e57dcd85d88194ea9f3a96f37f19340e05a Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 25 Jul 2026 20:33:36 +0000 Subject: [PATCH 03/71] gammu: 1.43.2 -> 1.43.3 --- pkgs/by-name/ga/gammu/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ga/gammu/package.nix b/pkgs/by-name/ga/gammu/package.nix index 005e5237a58c..f2377b596b40 100644 --- a/pkgs/by-name/ga/gammu/package.nix +++ b/pkgs/by-name/ga/gammu/package.nix @@ -24,7 +24,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "gammu"; - version = "1.43.2"; + version = "1.43.3"; __structuredAttrs = true; @@ -32,7 +32,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "gammu"; repo = "gammu"; rev = finalAttrs.version; - sha256 = "sha256-+mZBELwFUEL4S3IUIIa83TaNIYQxjQE1TvWhXTcIfYc="; + sha256 = "sha256-qmpbAiu0aIjawdKTNClMa3yFSdakOlh/dY5gAY04K3M="; }; patches = [ From 44bfa48ab50ed97c09e4f674dcc755075c573a3f Mon Sep 17 00:00:00 2001 From: Gerhard Schwanzer Date: Sun, 26 Jul 2026 09:56:22 +0200 Subject: [PATCH 04/71] jirafeau: 4.4.0 -> 4.7.2 https://gitlab.com/jirafeau/Jirafeau/-/blob/4.7.2/CHANGELOG.md Update to the continued official project namespace. This release contains the fix for CVE-2026-1466; extend the NixOS test with the vulnerable preview contract. Assisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol) --- nixos/modules/services/web-apps/jirafeau.nix | 2 +- nixos/tests/jirafeau.nix | 15 +++++++++++++++ pkgs/by-name/ji/jirafeau/package.nix | 8 ++++---- 3 files changed, 20 insertions(+), 5 deletions(-) diff --git a/nixos/modules/services/web-apps/jirafeau.nix b/nixos/modules/services/web-apps/jirafeau.nix index c1accf047c10..3ebb9beab22e 100644 --- a/nixos/modules/services/web-apps/jirafeau.nix +++ b/nixos/modules/services/web-apps/jirafeau.nix @@ -52,7 +52,7 @@ in ''; description = let - documentationLink = "https://gitlab.com/mojo42/Jirafeau/-/blob/${cfg.package.version}/lib/config.original.php"; + documentationLink = "https://gitlab.com/jirafeau/Jirafeau/-/blob/${cfg.package.version}/lib/config.original.php"; in '' Jirefeau configuration. Refer to <${documentationLink}> for supported diff --git a/nixos/tests/jirafeau.nix b/nixos/tests/jirafeau.nix index ebbd637a13ec..b723b1652c1a 100644 --- a/nixos/tests/jirafeau.nix +++ b/nixos/tests/jirafeau.nix @@ -18,5 +18,20 @@ machine.wait_for_unit("nginx.service") machine.wait_for_open_port(80) machine.succeed("curl -sSfL http://localhost/ | grep 'Jirafeau'") + + machine.succeed("printf '%s' '' > /tmp/preview.svg") + link = machine.succeed( + "curl --fail --silent --show-error " + "-F time=month -F 'file=@/tmp/preview.svg;type=image' " + "http://localhost/script.php" + ).splitlines()[0] + headers = machine.succeed( + f"curl --fail --silent --show-error --dump-header - " + f"--output /tmp/preview-response 'http://localhost/f.php?h={link}&p=1'" + ) + header_lines = {line.lower() for line in headers.splitlines()} + assert "x-content-type-options: nosniff" in header_lines + assert "content-type: image" in header_lines + machine.succeed("cmp /tmp/preview.svg /tmp/preview-response") ''; } diff --git a/pkgs/by-name/ji/jirafeau/package.nix b/pkgs/by-name/ji/jirafeau/package.nix index d590bc92c420..52a016b95774 100644 --- a/pkgs/by-name/ji/jirafeau/package.nix +++ b/pkgs/by-name/ji/jirafeau/package.nix @@ -14,13 +14,13 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "jirafeau"; - version = "4.4.0"; + version = "4.7.2"; src = fetchFromGitLab { - owner = "mojo42"; + owner = "jirafeau"; repo = "Jirafeau"; rev = finalAttrs.version; - hash = "sha256-jJ2r8XTtAzawTVo2A2pDwy7Z6KHeyBkgXXaCPY0w/rg="; + hash = "sha256-zCmSdlHkYQVQXBeVk8AUPoC0UBxz3hWIdM2tGmnLTrw="; }; installPhase = '' @@ -34,7 +34,7 @@ stdenv.mkDerivation (finalAttrs: { meta = { description = "Website permitting upload of a file in a simple way and giving a unique link to it"; license = lib.licenses.agpl3Plus; - homepage = "https://gitlab.com/mojo42/Jirafeau"; + homepage = "https://gitlab.com/jirafeau/Jirafeau"; platforms = lib.platforms.all; maintainers = [ ]; }; From 2cd494ee4e0b6f0b4bb9e7f05df557a0ba06786d Mon Sep 17 00:00:00 2001 From: Gerhard Schwanzer Date: Sun, 26 Jul 2026 10:59:06 +0200 Subject: [PATCH 05/71] libvncserver: backport CVE-2026-32853 and CVE-2026-32854 fixes Backport the complete upstream bounds checks for UltraZip decoding and malformed HTTP proxy requests. https://github.com/LibVNC/libvncserver/security/advisories/GHSA-87q7-v983-qwcj https://github.com/LibVNC/libvncserver/security/advisories/GHSA-xjp8-4qqv-5x4x Assisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol) --- pkgs/by-name/li/libvncserver/package.nix | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/pkgs/by-name/li/libvncserver/package.nix b/pkgs/by-name/li/libvncserver/package.nix index 1cc1489c93d9..d6e56f6003bd 100644 --- a/pkgs/by-name/li/libvncserver/package.nix +++ b/pkgs/by-name/li/libvncserver/package.nix @@ -41,6 +41,18 @@ stdenv.mkDerivation (finalAttrs: { url = "https://github.com/LibVNC/libvncserver/commit/e64fa928170f22a2e21b5bbd6d46c8f8e7dd7a96.patch"; hash = "sha256-AAZ3H34+nLqQggb/sNSx2gIGK96m4zatHX3wpyjNLOA="; }) + + (fetchpatch { + name = "CVE-2026-32854.patch"; + url = "https://github.com/LibVNC/libvncserver/commit/dc78dee51a7e270e537a541a17befdf2073f5314.patch"; + hash = "sha256-CgVfvsrgZWnjIzu/0UegoAuCqO7WHhCDVvhH8Yk1cXo="; + }) + + (fetchpatch { + name = "CVE-2026-32853.patch"; + url = "https://github.com/LibVNC/libvncserver/commit/009008e2f4d5a54dd71f422070df3af7b3dbc931.patch"; + hash = "sha256-ZgpiIS7KoRzDmVLQ0J86wTFFykCBVMt6bZwJsFvIO74="; + }) ]; nativeBuildInputs = [ From 573b0af3f7d4918ad3bd1def2014c14fd1af36b3 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 28 Jul 2026 23:47:59 +0000 Subject: [PATCH 06/71] libtrace: 4.0.32-2 -> 4.0.34-1 --- pkgs/by-name/li/libtrace/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/li/libtrace/package.nix b/pkgs/by-name/li/libtrace/package.nix index 53e63fa75f5a..5f84f49fffb7 100644 --- a/pkgs/by-name/li/libtrace/package.nix +++ b/pkgs/by-name/li/libtrace/package.nix @@ -16,13 +16,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "libtrace"; - version = "4.0.32-2"; + version = "4.0.34-1"; src = fetchFromGitHub { owner = "LibtraceTeam"; repo = "libtrace"; tag = finalAttrs.version; - hash = "sha256-cqRhTNSXvNlZW63baxqcqVJJEVe8SeunTPdJ623kIvo="; + hash = "sha256-vVhLUc2IddslHmXtzduYs4MLwWA+vYE/q5qpZIORdbY="; }; strictDeps = true; From 42cd904020cc5e6bd579da13452700db81e18102 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 29 Jul 2026 17:14:39 +0000 Subject: [PATCH 07/71] python3Packages.fastapi-pagination: 0.15.15 -> 0.15.16 --- .../development/python-modules/fastapi-pagination/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/fastapi-pagination/default.nix b/pkgs/development/python-modules/fastapi-pagination/default.nix index 705adb2284cb..abe23ecaffd7 100644 --- a/pkgs/development/python-modules/fastapi-pagination/default.nix +++ b/pkgs/development/python-modules/fastapi-pagination/default.nix @@ -14,7 +14,7 @@ buildPythonPackage (finalAttrs: { pname = "fastapi-pagination"; - version = "0.15.15"; + version = "0.15.16"; pyproject = true; __structuredAttrs = true; @@ -22,7 +22,7 @@ buildPythonPackage (finalAttrs: { owner = "uriyyo"; repo = "fastapi-pagination"; tag = finalAttrs.version; - hash = "sha256-G6qF57MWlrZ4Poc+M2YtpKqquhOR/Zh4TnFmL2qZ1Uk="; + hash = "sha256-hsJbtR11Ej7lh8rqndnp47XdM67IypyT6cheMfskmio="; }; build-system = [ From 830255b283cd4ba6a4a81b74891cedc40763d7c1 Mon Sep 17 00:00:00 2001 From: Ihar Hrachyshka Date: Thu, 30 Jul 2026 19:52:12 -0400 Subject: [PATCH 08/71] .github: avoid full checkout on backport The backport action should work with a sparse tree, so materializing all files is just wasteful. Since total time allocated for backport jobs is just 3 mins, sometimes a slow worktree checkout consumes a good chunk of it and pushes the job to timeout, resulting in missed backport. See for example: https://github.com/NixOS/nixpkgs/actions/runs/30587897004/job/91023481883 --- .github/workflows/backport.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.github/workflows/backport.yml b/.github/workflows/backport.yml index 5805401b08c7..ba5c06452664 100644 --- a/.github/workflows/backport.yml +++ b/.github/workflows/backport.yml @@ -39,6 +39,8 @@ jobs: - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 with: ref: ${{ github.event.pull_request.head.sha }} + # Avoid materializing full nixpkgs tree + sparse-checkout: . token: ${{ steps.app-token.outputs.token }} persist-credentials: true From 9364f8ea48005a8b703237b0f945a9dd38d6a6fa Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 31 Jul 2026 12:36:23 +0000 Subject: [PATCH 09/71] photoqt: 5.4 -> 5.4.1 --- pkgs/by-name/ph/photoqt/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ph/photoqt/package.nix b/pkgs/by-name/ph/photoqt/package.nix index 514d8260e860..e9ab6fae7f63 100644 --- a/pkgs/by-name/ph/photoqt/package.nix +++ b/pkgs/by-name/ph/photoqt/package.nix @@ -17,11 +17,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "photoqt"; - version = "5.4"; + version = "5.4.1"; src = fetchurl { url = "https://photoqt.org/downloads/source/photoqt-${finalAttrs.version}.tar.gz"; - hash = "sha256-Gifem+gVPmpF7uhiD2atejtFmOVuu7t2ZLKHMNS5yvY="; + hash = "sha256-vCihM84yDfDbz77qigIFQH/LIarH6IHKS3QdFPLZ8Lc="; }; nativeBuildInputs = [ From f4f31d3197b1cd9650c76bc71ec255c0ff10fbe5 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=C2=B7=F0=90=91=91=F0=90=91=B4=F0=90=91=95=F0=90=91=91?= =?UTF-8?q?=F0=90=91=A9=F0=90=91=A4?= Date: Sun, 26 Jul 2026 10:58:08 -0700 Subject: [PATCH 10/71] =?UTF-8?q?h2o:=202.3.0-rolling-2026-06-29=20?= =?UTF-8?q?=E2=86=92=202.3.0-rolling-2026-07-21?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- pkgs/by-name/h2/h2o/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/h2/h2o/package.nix b/pkgs/by-name/h2/h2o/package.nix index 50191ac86634..43e8b2fdba73 100644 --- a/pkgs/by-name/h2/h2o/package.nix +++ b/pkgs/by-name/h2/h2o/package.nix @@ -27,13 +27,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "h2o"; - version = "2.3.0-rolling-2026-06-29"; + version = "2.3.0-rolling-2026-07-21"; src = fetchFromGitHub { owner = "h2o"; repo = "h2o"; - rev = "edd7a120bfc4af11ac0cbebce2a43cc1f93f9af1"; - hash = "sha256-WQy+v4zpwzgbMxT43+Nd33+YPynyZIwqzVTaknqjCmE="; + rev = "3a5d2cb898bdb54795f060be7aba478912f65bb0"; + hash = "sha256-2S3u7qeC2D/nY7nEvE6scUw9aktGbMg0u5f350LhHVo="; }; outputs = [ From 1411f34b511d7d0c671141b2b6c0b2c8c0135850 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=C2=B7=F0=90=91=91=F0=90=91=B4=F0=90=91=95=F0=90=91=91?= =?UTF-8?q?=F0=90=91=A9=F0=90=91=A4?= Date: Sun, 26 Jul 2026 11:06:20 -0700 Subject: [PATCH 11/71] h2o: use cmake helpers from lib --- pkgs/by-name/h2/h2o/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/h2/h2o/package.nix b/pkgs/by-name/h2/h2o/package.nix index 43e8b2fdba73..6199daa9a934 100644 --- a/pkgs/by-name/h2/h2o/package.nix +++ b/pkgs/by-name/h2/h2o/package.nix @@ -71,9 +71,9 @@ stdenv.mkDerivation (finalAttrs: { ++ lib.optional withZstandard zstd; cmakeFlags = [ - "-DWITH_BROTLI=${if withBrotli then "ON" else "OFF"}" - "-DWITH_MRUBY=${if withMruby then "ON" else "OFF"}" - "-DWITH_ZSTD=${if withZstandard then "ON" else "OFF"}" + (lib.cmakeBool "WITH_BROTLI" withBrotli) + (lib.cmakeBool "WITH_MRUBY" withMruby) + (lib.cmakeBool "WITH_ZSTD" withZstandard) ]; postInstall = '' From 9dc345f4b69738f65ff92c632cd1979b2dc6c1be Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=C2=B7=F0=90=91=91=F0=90=91=B4=F0=90=91=95=F0=90=91=91?= =?UTF-8?q?=F0=90=91=A9=F0=90=91=A4?= Date: Fri, 31 Jul 2026 08:15:49 -0700 Subject: [PATCH 12/71] =?UTF-8?q?h2o:=202.3.0-rolling-2026-07-21=20?= =?UTF-8?q?=E2=86=92=202.3.0-rolling-2026-07-31?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- pkgs/by-name/h2/h2o/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/h2/h2o/package.nix b/pkgs/by-name/h2/h2o/package.nix index 6199daa9a934..7a5f1ccc7612 100644 --- a/pkgs/by-name/h2/h2o/package.nix +++ b/pkgs/by-name/h2/h2o/package.nix @@ -27,13 +27,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "h2o"; - version = "2.3.0-rolling-2026-07-21"; + version = "2.3.0-rolling-2026-07-31"; src = fetchFromGitHub { owner = "h2o"; repo = "h2o"; - rev = "3a5d2cb898bdb54795f060be7aba478912f65bb0"; - hash = "sha256-2S3u7qeC2D/nY7nEvE6scUw9aktGbMg0u5f350LhHVo="; + rev = "ba16320ad18c2bb2e28478ce9e37b9a57a5c98f6"; + hash = "sha256-MmfypvlLJ3NeZ1Nyeyzo1mXxICllQPBwwseOo+rC1Ig="; }; outputs = [ From ba4712332440067ab7d7e09500cb0d387e6ce028 Mon Sep 17 00:00:00 2001 From: Mix <32300164+mnixry@users.noreply.github.com> Date: Tue, 14 Jul 2026 00:58:11 +0800 Subject: [PATCH 13/71] maintainers: add mnixry --- maintainers/maintainer-list.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/maintainers/maintainer-list.nix b/maintainers/maintainer-list.nix index 6501b3cbcadc..696cf760818f 100644 --- a/maintainers/maintainer-list.nix +++ b/maintainers/maintainer-list.nix @@ -18912,6 +18912,11 @@ githubId = 45770; name = "Mitsuhiro Nakamura"; }; + mnixry = { + github = "mnixry"; + githubId = 32300164; + name = "Mix"; + }; MNThomson = { github = "MNThomson"; githubId = 73045936; From 4e45f75b8e30b4b177976b5be5b9ddb3e874dea7 Mon Sep 17 00:00:00 2001 From: Mix <32300164+mnixry@users.noreply.github.com> Date: Tue, 14 Jul 2026 00:59:18 +0800 Subject: [PATCH 14/71] bendsql: init at 0.34.2 Assisted-by: OpenAI Codex (GPT-5.5) --- pkgs/by-name/be/bendsql/package.nix | 60 +++++++++++++++++++++++++++++ 1 file changed, 60 insertions(+) create mode 100644 pkgs/by-name/be/bendsql/package.nix diff --git a/pkgs/by-name/be/bendsql/package.nix b/pkgs/by-name/be/bendsql/package.nix new file mode 100644 index 000000000000..47afd7653c68 --- /dev/null +++ b/pkgs/by-name/be/bendsql/package.nix @@ -0,0 +1,60 @@ +{ + lib, + rustPlatform, + fetchCrate, + pkg-config, + sqlite, + versionCheckHook, + nix-update-script, + testers, +}: + +rustPlatform.buildRustPackage (finalAttrs: { + __structuredAttrs = true; + + pname = "bendsql"; + version = "0.34.2"; + + src = fetchCrate { + inherit (finalAttrs) pname version; + hash = "sha256-TSHUts54DfgWMTHuCUzjRdDVx6QXpOm+5Lhli6rlnqQ="; + }; + + cargoHash = "sha256-ST2ybXxXMd5MRFaITEoFRw0/yx+dOkff6vVm3mW87A4="; + + nativeBuildInputs = [ pkg-config ]; + + buildInputs = [ sqlite ]; + + env = { + BENDSQL_BUILD_INFO = "nixpkgs"; + LIBSQLITE3_SYS_USE_PKG_CONFIG = "1"; + }; + + postPatch = '' + substituteInPlace build.rs \ + --replace-fail "BuildBuilder::default().build_timestamp(true).build()?" \ + "BuildBuilder::default().build_timestamp(false).build()?" + ''; + + doInstallCheck = true; + nativeInstallCheckInputs = [ versionCheckHook ]; + versionCheckProgramArg = "--version"; + + passthru = { + tests.version = testers.testVersion { + package = finalAttrs.finalPackage; + command = "bendsql --version"; + }; + updateScript = nix-update-script { }; + }; + + meta = { + description = "Native command-line client for Databend"; + mainProgram = "bendsql"; + homepage = "https://github.com/databendlabs/bendsql"; + changelog = "https://github.com/databendlabs/bendsql/releases/tag/v${finalAttrs.version}"; + license = lib.licenses.asl20; + maintainers = with lib.maintainers; [ mnixry ]; + }; +}) From 80a6477dd85030cc7664cdeb8957bc305b29543a Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 1 Aug 2026 10:24:09 +0000 Subject: [PATCH 15/71] necesse-server: 1.2.0-23522718 -> 1.3.1-24494674 --- pkgs/by-name/ne/necesse-server/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ne/necesse-server/package.nix b/pkgs/by-name/ne/necesse-server/package.nix index 88e7c558b6e1..ef6f85fcc8ac 100644 --- a/pkgs/by-name/ne/necesse-server/package.nix +++ b/pkgs/by-name/ne/necesse-server/package.nix @@ -6,7 +6,7 @@ }: let - version = "1.2.0-23522718"; + version = "1.3.1-24494674"; urlVersion = lib.replaceStrings [ "." ] [ "-" ] version; in @@ -16,7 +16,7 @@ stdenvNoCC.mkDerivation { src = fetchzip { url = "https://necesse.pwn.sh/server/necesse-server-linux64-${urlVersion}.zip"; - hash = "sha256-PIguTYULddLKj6PpoSvX3gNSvqrS7oRTOPuwoA0/XOc="; + hash = "sha256-A2mWnIIRGNfbxg7aZDwEk7QvuDUUpr2ARIddasTlvFM="; }; # removing packaged jre since we use our own From f0063617f10be428b11e8110a1a3ddea6a89aa09 Mon Sep 17 00:00:00 2001 From: Marcel Date: Thu, 30 Jul 2026 17:18:46 +0200 Subject: [PATCH 16/71] rustfs: 1.0.0-beta.11 -> 1.0.0-beta.12 Diff: https://github.com/rustfs/rustfs/compare/1.0.0-beta.11...1.0.0-beta.12 --- pkgs/by-name/ru/rustfs/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ru/rustfs/package.nix b/pkgs/by-name/ru/rustfs/package.nix index 4dd7a96ffd58..326eb00351d6 100644 --- a/pkgs/by-name/ru/rustfs/package.nix +++ b/pkgs/by-name/ru/rustfs/package.nix @@ -51,14 +51,14 @@ let in rustPlatform.buildRustPackage rec { pname = "rustfs"; - version = "1.0.0-beta.11"; + version = "1.0.0-beta.12"; __structuredAttrs = true; src = fetchFromGitHub { owner = "rustfs"; repo = "rustfs"; tag = version; - hash = "sha256-arwTgRwUr7/mgobtxnkhxD1mu4LrrEqKnrewacpc6ro="; + hash = "sha256-u5DhPg0e42IvP5lNyLVh2kBQLEYQz3J5crnTs8mfFms="; }; postPatch = '' @@ -66,7 +66,7 @@ rustPlatform.buildRustPackage rec { cp -rL ${console} ./rustfs/static ''; - cargoHash = "sha256-cMOPQ70hGFJEdYkrizgrwJOfga9UvqJRPdQbX/Whhuk="; + cargoHash = "sha256-5QpSWlGN0zV6BW6joRyP+Ly6QEVTkHTJUSBBnyYx+EQ="; nativeBuildInputs = [ protobuf From 4d53f69eb7681739a0811914d7f47addd6fac7ff Mon Sep 17 00:00:00 2001 From: Gerhard Schwanzer Date: Fri, 31 Jul 2026 07:56:01 +0200 Subject: [PATCH 17/71] tinyproxy: fix CVE-2026-54387, CVE-2026-54388 and CVE-2026-55202 Apply upstream fixes for ambiguous HTTP request framing and inconsistent stathost authentication and routing. No upstream release containing these fixes is available. Assisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol) --- pkgs/by-name/ti/tinyproxy/package.nix | 22 +++++++++++++++++++--- 1 file changed, 19 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ti/tinyproxy/package.nix b/pkgs/by-name/ti/tinyproxy/package.nix index 035c3194b91e..bb07a0bf0a4d 100644 --- a/pkgs/by-name/ti/tinyproxy/package.nix +++ b/pkgs/by-name/ti/tinyproxy/package.nix @@ -2,7 +2,7 @@ lib, stdenv, fetchFromGitHub, - fetchpatch2, + fetchpatch, autoreconfHook, perl, nixosTests, @@ -22,10 +22,26 @@ stdenv.mkDerivation (finalAttrs: { patches = [ # Fix case-sensitive matching of "chunked" (CVE-2026-31842) - (fetchpatch2 { + (fetchpatch { name = "fix-chunked-case-sensitivity.patch"; url = "https://github.com/tinyproxy/tinyproxy/commit/879bf844abffa0bf5fae6aff0c73179024dd9f98.patch"; - hash = "sha256-Nav3nXyxdoM/tIvfyPJHEYEjAtrRrJlvkMXzsQCZan4="; + hash = "sha256-kU9Vqf2YtnKNJU4eQlau/ijtXkGPS/n+YSeficfu7JM="; + }) + # Remove when updating to the first upstream release containing these fixes. + (fetchpatch { + name = "CVE-2026-54387.patch"; + url = "https://github.com/tinyproxy/tinyproxy/commit/623bfc093df009296f0b85d40bc677ef9d5c09bb.patch"; + hash = "sha256-BSnK3XkBFW43cnD937RKr7FJzQT90BxJkILXz/QPZo8="; + }) + (fetchpatch { + name = "CVE-2026-54388.patch"; + url = "https://github.com/tinyproxy/tinyproxy/commit/364cdb67e0ea00a8e4a7037e2693e0711e816adb.patch"; + hash = "sha256-+Z/Rj/zNldfOPVzWUlFHa37LEfSh/PtXOaN8z++ONJQ="; + }) + (fetchpatch { + name = "CVE-2026-55202.patch"; + url = "https://github.com/tinyproxy/tinyproxy/commit/09312a185ae25cc486b4ff5987638a7917a48bce.patch"; + hash = "sha256-kwYk5E95KQK42ebLV0nHB706VynDnjHB/5eENKO7Eaw="; }) ]; From 2341bac55174264ce72f661504ea88c3c6af5f62 Mon Sep 17 00:00:00 2001 From: Steven Allen Date: Sat, 1 Aug 2026 09:36:48 -0700 Subject: [PATCH 18/71] brave, brave-origin: 1.92.144 -> 1.93.129 Changelog: https://community.brave.app/t/release-channel-1-93-129/656295 --- .../networking/browsers/brave/packages/brave-origin.nix | 8 ++++---- .../networking/browsers/brave/packages/brave.nix | 8 ++++---- 2 files changed, 8 insertions(+), 8 deletions(-) diff --git a/pkgs/applications/networking/browsers/brave/packages/brave-origin.nix b/pkgs/applications/networking/browsers/brave/packages/brave-origin.nix index 8af08a9f7eeb..326f78ee7bad 100644 --- a/pkgs/applications/networking/browsers/brave/packages/brave-origin.nix +++ b/pkgs/applications/networking/browsers/brave/packages/brave-origin.nix @@ -1,21 +1,21 @@ # Expression generated by update.sh; do not edit it by hand! rec { pname = "brave-origin"; - version = "1.92.144"; + version = "1.93.129"; flavor = "origin"; archives = { aarch64-linux = { url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-origin_${version}_arm64.deb"; - hash = "sha256-zqjpiBMogYhtuEhIlPlK8J2j9hzfd1M8RYlT/c74Na8="; + hash = "sha256-29NLuWH3TAUGkiiY00J+e+IGaqfIZ/g2vLI1aDXacVw="; }; x86_64-linux = { url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-origin_${version}_amd64.deb"; - hash = "sha256-KF5WXF7GJPLCcEQyASEVfNrYyFJRXBSyWVPPAZPCa/E="; + hash = "sha256-F5d660t4t52L27gt8SF9n/54lmK+CeqZeqlbS84wjvU="; }; aarch64-darwin = { url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-origin-v${version}-darwin-arm64.zip"; - hash = "sha256-kkP8cBRnC34+SjC9EvkpKcDYP3cxW7sdJgni0+zXwbk="; + hash = "sha256-H+UHhEPMBT/wki30DBic1jSpXI8jlddYruEs9TU0Mx8="; }; }; } diff --git a/pkgs/applications/networking/browsers/brave/packages/brave.nix b/pkgs/applications/networking/browsers/brave/packages/brave.nix index c50a2fc89fcc..055bca8d9ae0 100644 --- a/pkgs/applications/networking/browsers/brave/packages/brave.nix +++ b/pkgs/applications/networking/browsers/brave/packages/brave.nix @@ -1,20 +1,20 @@ # Expression generated by update.sh; do not edit it by hand! rec { pname = "brave"; - version = "1.92.144"; + version = "1.93.129"; archives = { aarch64-linux = { url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-browser_${version}_arm64.deb"; - hash = "sha256-Z9uUJRaMx+P35oXtvAnjHyOQOXt8mW5oyyEtnD754x8="; + hash = "sha256-pO6vTzTv7OKcP5uJwlcc+vUdg/0Lm2Q6apnEhjRxasM="; }; x86_64-linux = { url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-browser_${version}_amd64.deb"; - hash = "sha256-no/KD+3EB6CqvVWEmDB/8k2rv1wau469FBXMNWN7z6k="; + hash = "sha256-fOyneo8kzoGqldT6nYRzFqgy1+WhKGhcSkJQTCd4w6k="; }; aarch64-darwin = { url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-v${version}-darwin-arm64.zip"; - hash = "sha256-YidWCVGP36wn1goAulSbVrKFoHI1NA/pLtfPjIXBO48="; + hash = "sha256-phHj7wAZKhRsqYrApNONbjM3RQBra893cDUq6e2lBrs="; }; }; } From 8401cfc7a166bf6ff79f321bceccea2b61162f53 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 1 Aug 2026 19:55:56 +0000 Subject: [PATCH 19/71] ani-cli: 4.14 -> 5.0 --- pkgs/by-name/an/ani-cli/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/an/ani-cli/package.nix b/pkgs/by-name/an/ani-cli/package.nix index d53722be88dd..3df8eff5aec4 100644 --- a/pkgs/by-name/an/ani-cli/package.nix +++ b/pkgs/by-name/an/ani-cli/package.nix @@ -28,13 +28,13 @@ in stdenvNoCC.mkDerivation (finalAttrs: { pname = "ani-cli"; - version = "4.14"; + version = "5.0"; src = fetchFromGitHub { owner = "pystardust"; repo = "ani-cli"; tag = "v${finalAttrs.version}"; - hash = "sha256-OyCKDN89sBz59+3JncMDyNOq8UMqqjara+A0Owo3oko="; + hash = "sha256-rRQESi0Skoyf1jy/dRRK6ooKRPQhkak107kk5ulwZYI="; }; nativeBuildInputs = [ makeWrapper ]; From 4c482de9b9f18ee7e8486624cd22ba6e3de90be7 Mon Sep 17 00:00:00 2001 From: Marie Ramlow Date: Sat, 1 Aug 2026 21:17:37 +0200 Subject: [PATCH 20/71] bitwarden-desktop: use npmDepsFetcherVersion 2 There is no version 3 yet, hashes will break in the future if we add a new version. --- pkgs/by-name/bi/bitwarden-desktop/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/bi/bitwarden-desktop/package.nix b/pkgs/by-name/bi/bitwarden-desktop/package.nix index d1dccec7b1ff..4422068fd053 100644 --- a/pkgs/by-name/bi/bitwarden-desktop/package.nix +++ b/pkgs/by-name/bi/bitwarden-desktop/package.nix @@ -73,8 +73,8 @@ buildNpmPackage (finalAttrs: { ]; npmWorkspace = "apps/desktop"; - npmDepsFetcherVersion = 3; - npmDepsHash = "sha256-8wjt5wnJG4S4EeGWGxbo6Bwt76GIqrSiwqwwwQ17Y5Y="; + npmDepsFetcherVersion = 2; + npmDepsHash = "sha256-WRxlvkgWboO0ukUHgjC5CrfgfwnmUfDXI4r5dx9CKww="; cargoDeps = rustPlatform.fetchCargoVendor { inherit (finalAttrs) From c97d2b5476b90cb8217927612d97d2f66f11c15f Mon Sep 17 00:00:00 2001 From: Marie Ramlow Date: Sat, 1 Aug 2026 21:17:37 +0200 Subject: [PATCH 21/71] exo: use npmDepsFetcherVersion 2 There is no version 3 yet, hashes will break in the future if we add a new version. --- pkgs/by-name/ex/exo/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ex/exo/package.nix b/pkgs/by-name/ex/exo/package.nix index d8acacd3973a..7ecfe0f4644e 100644 --- a/pkgs/by-name/ex/exo/package.nix +++ b/pkgs/by-name/ex/exo/package.nix @@ -56,7 +56,7 @@ let inherit src version; sourceRoot = "${finalAttrs.src.name}/dashboard"; - npmDepsFetcherVersion = 3; + npmDepsFetcherVersion = 2; npmDeps = fetchNpmDeps { inherit (finalAttrs) @@ -65,8 +65,8 @@ let src sourceRoot ; - fetcherVersion = 3; - hash = "sha256-gBWJP0dF2zDEWLYxfKYQSn9O5hVRkcviDv9oP267pQQ="; + fetcherVersion = 2; + hash = "sha256-d/+54lpNe0tXrC+Mrhpc1cdXOMjYblE0QByIdiaDgU0="; }; }); in From cf8c0c8fc9f579c62c38694279395b51ac4e406c Mon Sep 17 00:00:00 2001 From: Marie Ramlow Date: Sat, 1 Aug 2026 21:17:37 +0200 Subject: [PATCH 22/71] ghui: use npmDepsFetcherVersion 2 There is no version 3 yet, hashes will break in the future if we add a new version. --- pkgs/by-name/gh/ghui/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/gh/ghui/package.nix b/pkgs/by-name/gh/ghui/package.nix index bd4b30d000d5..418b8253b7a6 100644 --- a/pkgs/by-name/gh/ghui/package.nix +++ b/pkgs/by-name/gh/ghui/package.nix @@ -31,8 +31,8 @@ buildNpmPackage (finalAttrs: { cp ${./package-lock.json} package-lock.json ''; - npmDepsHash = "sha256-pg+USHnvcxaXG/floNItLXNFJOPvuDltQCcN1qT/nng="; - npmDepsFetcherVersion = 3; + npmDepsHash = "sha256-JxyG7qMJS7zchxLIxYCmsFajUVW4fONnqgeq2iKlt4A="; + npmDepsFetcherVersion = 2; nativeBuildInputs = [ bun ]; From d3edf45a0723454799c6a090b1903186ddb26b69 Mon Sep 17 00:00:00 2001 From: Marie Ramlow Date: Sat, 1 Aug 2026 21:17:37 +0200 Subject: [PATCH 23/71] glitchtip: use npmDepsFetcherVersion 2 There is no version 3 yet, hashes will break in the future if we add a new version. --- pkgs/by-name/gl/glitchtip/frontend.nix | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/gl/glitchtip/frontend.nix b/pkgs/by-name/gl/glitchtip/frontend.nix index 86c37d73d166..e3b4406c9d5f 100644 --- a/pkgs/by-name/gl/glitchtip/frontend.nix +++ b/pkgs/by-name/gl/glitchtip/frontend.nix @@ -21,11 +21,12 @@ buildNpmPackage (finalAttrs: { nodejs = nodejs_22; + npmDepsFetcherVersion = 2; npmDeps = fetchNpmDeps { name = "${finalAttrs.pname}-${finalAttrs.version}-npm-deps"; inherit (finalAttrs) src; - npmDepsFetcherVersion = 3; - hash = "sha256-V9aRKoJ6+BN/q7NS21eZBopzkWje8sOGGL1AgO4cUM0="; + fetcherVersion = 2; + hash = "sha256-xobZg0Hc+Yi9+q6kMwuKtBb4pjdYNS4T9VdFy5hARlw="; }; postPatch = '' From 780b418f01fa0664f380fbde52bbcdf9a5f9a792 Mon Sep 17 00:00:00 2001 From: Marie Ramlow Date: Sat, 1 Aug 2026 21:17:37 +0200 Subject: [PATCH 24/71] qwen-code: use npmDepsFetcherVersion 2 There is no version 3 yet, hashes will break in the future if we add a new version. --- pkgs/by-name/qw/qwen-code/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/qw/qwen-code/package.nix b/pkgs/by-name/qw/qwen-code/package.nix index 50a1d4e02c9c..a4e253da3cb3 100644 --- a/pkgs/by-name/qw/qwen-code/package.nix +++ b/pkgs/by-name/qw/qwen-code/package.nix @@ -23,8 +23,8 @@ buildNpmPackage (finalAttrs: { hash = "sha256-XWhQ5GlAGW0WAyiPwBULLz1yQps2IdjVkusQ0a88tCs="; }; - npmDepsFetcherVersion = 3; - npmDepsHash = "sha256-dRc+hTk5ELw0rJhT71heFnLjTmjN1UpIOHUMXKt4YwU="; + npmDepsFetcherVersion = 2; + npmDepsHash = "sha256-2vr8Yspm6CCVnO6Jf8B3wiL6X+Tp6hZZEPr+WC/Dcak="; # npm 11 incompatible with fetchNpmDeps # https://github.com/NixOS/nixpkgs/issues/474535 From 9e6b82223843022cb9575f66a1a3d0c198db0d2b Mon Sep 17 00:00:00 2001 From: Marie Ramlow Date: Sat, 1 Aug 2026 21:17:37 +0200 Subject: [PATCH 25/71] snyk: use npmDepsFetcherVersion 2 There is no version 3 yet, hashes will break in the future if we add a new version. --- pkgs/by-name/sn/snyk/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/sn/snyk/package.nix b/pkgs/by-name/sn/snyk/package.nix index 81bdd8ba7795..0d8a102d3ab3 100644 --- a/pkgs/by-name/sn/snyk/package.nix +++ b/pkgs/by-name/sn/snyk/package.nix @@ -24,9 +24,9 @@ buildNpmPackage (finalAttrs: { ''; }; - npmDepsFetcherVersion = 3; + npmDepsFetcherVersion = 2; - npmDepsHash = "sha256-AmJNFEw7IF9PjgeRma6vp3I7a60ZkekfRkPXJtjVIik="; + npmDepsHash = "sha256-e7C2ZG7SH9xjfU07lX8rzPeox6k2Fdz7AowOduLxvvs="; nodejs = nodejs_24; From ac8a2ab1a8fd71babdee1368a82fae59bfc3aacc Mon Sep 17 00:00:00 2001 From: Marie Ramlow Date: Sat, 1 Aug 2026 21:17:37 +0200 Subject: [PATCH 26/71] vaultwarden: use npmDepsFetcherVersion 2 There is no version 3 yet, hashes will break in the future if we add a new version. --- pkgs/by-name/va/vaultwarden/webvault.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/va/vaultwarden/webvault.nix b/pkgs/by-name/va/vaultwarden/webvault.nix index 55a2c15e16ab..c62c3087533d 100644 --- a/pkgs/by-name/va/vaultwarden/webvault.nix +++ b/pkgs/by-name/va/vaultwarden/webvault.nix @@ -19,8 +19,8 @@ buildNpmPackage rec { hash = "sha256-Uz0wPdhTVy2yOlKWAy5phr+30NmFaIPQQh5bsiWCDLA="; }; - npmDepsFetcherVersion = 3; - npmDepsHash = "sha256-PaDxqVsq00QIKDmhDhsEbKdM4QXfXn28PgpOyZjB60k="; + npmDepsFetcherVersion = 2; + npmDepsHash = "sha256-SkzEM54nMFqiYUqIRTbp3+yaZEJMgjFkjRLT5NZTN94="; nativeBuildInputs = [ python3 From 1d387153a7899fc828d7524a80963dcd8c551d73 Mon Sep 17 00:00:00 2001 From: cinereal Date: Sat, 1 Aug 2026 13:00:25 +0200 Subject: [PATCH 27/71] modular-services: fix description on mainExecReload the description in question turned out correct for `mainExecStart`, not for `mainExecReload` Assisted-by: Claude:claude-opus-5 Signed-off-by: cinereal --- nixos/modules/system/service/systemd/service.nix | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/nixos/modules/system/service/systemd/service.nix b/nixos/modules/system/service/systemd/service.nix index e7fa338ff97b..9deb732e2a61 100644 --- a/nixos/modules/system/service/systemd/service.nix +++ b/nixos/modules/system/service/systemd/service.nix @@ -118,9 +118,8 @@ in Main command line for systemd's ExecReload with systemd's specifier and environment variable substitution enabled. - This option sets the primary ExecRestart entry. Additional ExecReload entries - can be added via `systemd.service.serviceConfig.ExecReload` with `lib.mkBefore` - or `lib.mkAfter`. + This option sets the primary ExecReload entry, and is the way to extend the + command line derived from {option}`process.reloadCommand`. This option allows you to use systemd specifiers like `%n` (unit name), `%i` (instance), `%t` (runtime directory), and environment variables using From 1f0df078bc29bc2d405b60105641c8ec671abc1d Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Sun, 2 Aug 2026 00:00:59 +0200 Subject: [PATCH 28/71] freescout: fix passthru.tests This must be an attrset, not a list. --- pkgs/by-name/fr/freescout/package.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/by-name/fr/freescout/package.nix b/pkgs/by-name/fr/freescout/package.nix index 24442006c851..330273012aee 100644 --- a/pkgs/by-name/fr/freescout/package.nix +++ b/pkgs/by-name/fr/freescout/package.nix @@ -46,7 +46,7 @@ stdenv.mkDerivation (finalAttrs: { runHook postInstall ''; - passthru.tests = lib.attrValues nixosTests.freescout; + passthru.tests = nixosTests.freescout; # Because freescout is searching for some folders only relative to it's own source location, we need to have the symlinks to the actual locations in here dontCheckForBrokenSymlinks = true; From fb6d49e15e3ce6d36f4f7a942ef5a6a53dca6b44 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Sun, 2 Aug 2026 00:04:51 +0200 Subject: [PATCH 29/71] freescout: 1.8.230 -> 1.8.232 https://github.com/freescout-help-desk/freescout/releases/tag/1.8.231 https://github.com/freescout-help-desk/freescout/releases/tag/1.8.232 Fixes: CVE-2026-59882, CVE-2026-45294, CVE-2026-45294 --- pkgs/by-name/fr/freescout/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/fr/freescout/package.nix b/pkgs/by-name/fr/freescout/package.nix index 330273012aee..b3fc3c7abb0f 100644 --- a/pkgs/by-name/fr/freescout/package.nix +++ b/pkgs/by-name/fr/freescout/package.nix @@ -7,13 +7,13 @@ stdenv.mkDerivation (finalAttrs: { preferLocalBuild = true; pname = "freescout"; - version = "1.8.230"; + version = "1.8.232"; src = fetchFromGitHub { owner = "freescout-help-desk"; repo = "freescout"; tag = finalAttrs.version; - hash = "sha256-QAMZj1tUSaErLTJR8IfzatNw5G8lznA4mNa+a4Bd5rQ="; + hash = "sha256-dqUKfj9Y/CoU4hC8rq7XejVswaEOiZtFG6rsSGgljfY="; }; patches = [ From 7a73234dc9a5b60d9509ddc2ee3a7db09d83ab6e Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Sun, 2 Aug 2026 00:17:33 +0200 Subject: [PATCH 30/71] nixosTests.freescout: fix string splitting in artisan call --- nixos/tests/freescout/integration.nix | 2 +- nixos/tests/freescout/upgrade.nix | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/nixos/tests/freescout/integration.nix b/nixos/tests/freescout/integration.nix index 57d28f032c3a..bc29d95badc0 100644 --- a/nixos/tests/freescout/integration.nix +++ b/nixos/tests/freescout/integration.nix @@ -151,7 +151,7 @@ in machine.wait_for_unit("freescout-setup") with subtest("Login works"): - machine.succeed("/var/lib/freescout/artisan freescout:create-user --role=admin --firstName=Xenia --lastName=TheFox --email xenia@${freescoutDomain} --no-interaction --password=foo | grep 'User created with id'") + machine.succeed("/var/lib/freescout/artisan -- freescout:create-user --role=admin --firstName=Xenia --lastName=TheFox --email xenia@${freescoutDomain} --no-interaction --password=foo | grep 'User created with id'") token=machine.succeed("curl -fsSL --cookie-jar cjar 'http://${freescoutDomain}/login' | grep -Po '(?<= name=\"_token\" value=\")(\\w+)(?=\")'").strip() data=f"email=xenia%40${freescoutDomain}&password=foo&_token={token}&remember=on" machine.succeed(f"curl -sSfX POST --cookie-jar cjar --cookie cjar --data-raw '{data}' 'http://${freescoutDomain}/login' | grep 'Redirecting to'") diff --git a/nixos/tests/freescout/upgrade.nix b/nixos/tests/freescout/upgrade.nix index 397788710bf1..0cfb9f703b8a 100644 --- a/nixos/tests/freescout/upgrade.nix +++ b/nixos/tests/freescout/upgrade.nix @@ -73,7 +73,7 @@ in with subtest("Create user and log in"): # Create uesr - machine.succeed("/var/lib/freescout/artisan freescout:create-user --role=admin --firstName=Xenia --lastName=TheFox --email xenia@${freescoutDomain} --no-interaction --password=foo | grep 'User created with id'") + machine.succeed("/var/lib/freescout/artisan -- freescout:create-user --role=admin --firstName=Xenia --lastName=TheFox --email xenia@${freescoutDomain} --no-interaction --password=foo | grep 'User created with id'") # Obtain CSRF token token=machine.succeed("curl -fsSL --cookie-jar cjar 'http://${freescoutDomain}/login' | grep -Po '(?<= name=\"_token\" value=\")(\w+)(?=\")'").strip() # Actually log in From 64027c4fdbc29b5edbe20b622fd8f97ad7340da9 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Sun, 2 Aug 2026 00:17:50 +0200 Subject: [PATCH 31/71] nixosTests.freescout.integration: run in nspawn --- nixos/tests/freescout/integration.nix | 9 ++++----- 1 file changed, 4 insertions(+), 5 deletions(-) diff --git a/nixos/tests/freescout/integration.nix b/nixos/tests/freescout/integration.nix index bc29d95badc0..c3226f8488a9 100644 --- a/nixos/tests/freescout/integration.nix +++ b/nixos/tests/freescout/integration.nix @@ -26,7 +26,6 @@ let ... }: { - virtualisation.memorySize = 1024; environment.systemPackages = with pkgs; [ curl sendInitial @@ -99,7 +98,7 @@ let }; }; - mkNode = + mkContainer = dbType: { config, pkgs, ... }: { @@ -118,14 +117,14 @@ in e1mo ]; - nodes = { + containers = { # This may lead to duplicate tests, but ensures that # it's always tested on the current default version # even if the tests are not updated - freescout_pgsql = mkNode "pgsql"; + freescout-pgsql = mkContainer "pgsql"; # Same as the freescout_pgsql_default node - freescout_mysql = mkNode "mysql"; + freescout-mysql = mkContainer "mysql"; }; testScript = '' From 350b7cf07b06ec666d1ef2d889ee8f17aba14e45 Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Sun, 2 Aug 2026 00:28:12 +0200 Subject: [PATCH 32/71] goaccess: 1.10.2 -> 1.11 Diff: https://github.com/allinurl/goaccess/compare/v1.10.2...v1.11 Changelog: https://github.com/allinurl/goaccess/raw/v1.11/ChangeLog --- pkgs/by-name/go/goaccess/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/go/goaccess/package.nix b/pkgs/by-name/go/goaccess/package.nix index ad32acf68b3c..dc2ee4b52ccd 100644 --- a/pkgs/by-name/go/goaccess/package.nix +++ b/pkgs/by-name/go/goaccess/package.nix @@ -12,13 +12,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "goaccess"; - version = "1.10.2"; + version = "1.11"; src = fetchFromGitHub { owner = "allinurl"; repo = "goaccess"; tag = "v${finalAttrs.version}"; - hash = "sha256-n0+Z3kkjMCjPN0Cb0R1QGSzzXH3S9kjDchy9ay6109s="; + hash = "sha256-9Z57T0MPs3ytwi32fMF67j8h7ml20cw4Hf+/DEg5AQY="; }; nativeBuildInputs = [ autoreconfHook ]; From 1309adc7f34a903769edfe175ae7d95544b13073 Mon Sep 17 00:00:00 2001 From: cinereal Date: Sat, 1 Aug 2026 13:01:47 +0200 Subject: [PATCH 33/71] modular-services: only emit `ExecReload` when there is a reload command `systemd.mainExecReload` fell back to `""` when `process.reloadCommand` was unset, while `systemd.services."".serviceConfig.ExecReload` was defined unconditionally. `serviceConfig` entries use `unitOption`, which concatenates definitions only when one of them is a list; two plain strings go through `mergeEqualOption` instead. So any service setting `ExecReload` through the systemd escape hatch failed to evaluate, as in `nixosTests.php85.fpm-modular`. The `""` fallback was also rendered as a bare `ExecReload=` line in every unit without a reload command, since `attrsToSection` does not filter empty strings. Default `systemd.mainExecReload` to `process.reloadCommand` itself, which makes its existing `defaultText` accurate, and guard the definition with `lib.mkIf`, so the framework leaves `ExecReload` undefined unless there really is a reload command. Assisted-by: Claude:claude-opus-5 Signed-off-by: cinereal --- .../system/service/systemd/service.nix | 15 +++++++----- nixos/tests/system-services-compliance.nix | 23 +++++++++++++++++++ 2 files changed, 32 insertions(+), 6 deletions(-) diff --git a/nixos/modules/system/service/systemd/service.nix b/nixos/modules/system/service/systemd/service.nix index 9deb732e2a61..76814d419931 100644 --- a/nixos/modules/system/service/systemd/service.nix +++ b/nixos/modules/system/service/systemd/service.nix @@ -125,10 +125,13 @@ in `%i` (instance), `%t` (runtime directory), and environment variables using `''${VAR}` syntax in your command line. - By default, it is set to {option}`process.reloadCommand` when specified, or an - empty string otherwise. Because {option}`process.reloadCommand` is already a - command line (not an argument list), it is used verbatim so that references - like `$MAINPID` are preserved. + By default, it is set to {option}`process.reloadCommand`. Because + {option}`process.reloadCommand` is already a command line (not an argument + list), it is used verbatim so that references like `$MAINPID` are preserved. + + When {option}`process.reloadCommand` is unset, this option is `null` and no + `ExecReload` is emitted; a service may then set + `systemd.service.serviceConfig.ExecReload` itself. To extend {option}`process.reloadCommand` with systemd specifiers, you can append to the command line: @@ -146,7 +149,7 @@ in for available specifiers like `%n`, `%i`, `%t`. ''; type = types.nullOr types.str; - default = if config.process.reloadCommand != null then config.process.reloadCommand else ""; + default = config.process.reloadCommand; defaultText = lib.literalExpression "config.process.reloadCommand"; }; @@ -207,7 +210,7 @@ in # TODO description; wantedBy = lib.mkDefault [ "multi-user.target" ]; serviceConfig = { - ExecReload = config.systemd.mainExecReload; + ExecReload = lib.mkIf (config.systemd.mainExecReload != null) config.systemd.mainExecReload; Type = lib.mkDefault (if config.notificationProtocol.systemd then "notify" else "simple"); Restart = lib.mkDefault "always"; RestartSec = lib.mkDefault "5"; diff --git a/nixos/tests/system-services-compliance.nix b/nixos/tests/system-services-compliance.nix index add3593fd3a8..433a2fb7c629 100644 --- a/nixos/tests/system-services-compliance.nix +++ b/nixos/tests/system-services-compliance.nix @@ -81,6 +81,16 @@ let process.reloadSignal = "HUP"; }; }).config.systemd.services; + + # A service setting `ExecReload` through the systemd escape hatch, without + # any `process.reloadCommand` of its own. + ownExecReloadUnits = + (evalSystemServices { + service = { + process.argv = [ "${coreutils}/bin/true" ]; + systemd.service.serviceConfig.ExecReload = "${coreutils}/bin/kill -USR2 $MAINPID"; + }; + }).config.systemd.services; in { testDefaultType = { @@ -97,6 +107,19 @@ let expr = reloadUnits.service.serviceConfig.ExecReload; expected = "${coreutils}/bin/kill -HUP $MAINPID"; }; + + # Without a reload command, the framework must not define `ExecReload` at + # all, so that it neither conflicts with a service-provided definition nor + # renders a bare `ExecReload=` line. + testNoReloadExecReloadUnset = { + expr = defaultUnits.service.serviceConfig ? ExecReload; + expected = false; + }; + + testServiceOwnExecReload = { + expr = ownExecReloadUnits.service.serviceConfig.ExecReload; + expected = "${coreutils}/bin/kill -USR2 $MAINPID"; + }; }; systemdEval = pkgs.stdenvNoCC.mkDerivation (finalAttrs: { From b306f58e91aa81116d5b1e8ba677b28b878db5e4 Mon Sep 17 00:00:00 2001 From: Fazzi Date: Mon, 27 Jul 2026 18:01:02 +0100 Subject: [PATCH 34/71] sgdboop: 1.3.2 -> 1.4.2 --- pkgs/by-name/sg/sgdboop/package.nix | 25 +++++++++++++------------ 1 file changed, 13 insertions(+), 12 deletions(-) diff --git a/pkgs/by-name/sg/sgdboop/package.nix b/pkgs/by-name/sg/sgdboop/package.nix index c6530e63ab2e..318a4929d93f 100644 --- a/pkgs/by-name/sg/sgdboop/package.nix +++ b/pkgs/by-name/sg/sgdboop/package.nix @@ -9,27 +9,28 @@ }: stdenv.mkDerivation (finalAttrs: { pname = "sgdboop"; - version = "1.3.2"; + version = "1.4.2"; src = fetchFromGitHub { owner = "SteamGridDB"; repo = "SGDBoop"; tag = "v${finalAttrs.version}"; - hash = "sha256-/pXZMq80fb7Z+619ACnu/ZYWpouh59PIiruWY7l2cnQ="; + hash = "sha256-17LfPmqvSrXvIcKfjTrpopAIzue62TXw/yXXmAQOeR0="; }; - makeFlags = [ - # The flatpak install just copies things to /app - otherwise wants to do things with XDG - "FLATPAK_ID=fake" - ]; + installPhase = '' + runHook preInstall - postPatch = '' - substituteInPlace Makefile \ - --replace-fail "/app/" "$out/" - ''; + install -Dm755 SGDBoop \ + $out/bin/SGDBoop - postInstall = '' - rm -r "$out/share/metainfo" + install -Dm644 res/linux/com.steamgriddb.SGDBoop.desktop \ + $out/share/applications/com.steamgriddb.SGDBoop.desktop + + install -Dm444 res/com.steamgriddb.SGDBoop.svg \ + $out/share/icons/hicolor/scalable/apps/com.steamgriddb.SGDBoop.svg + + runHook postInstall ''; nativeBuildInputs = [ From 726b971e891919d3c8788ec84fd9abeb94c79477 Mon Sep 17 00:00:00 2001 From: Sizhe Zhao Date: Sun, 1 Mar 2026 20:25:53 +0800 Subject: [PATCH 35/71] cronet-go: init at 148.0.7778.96-1-unstable-2026-07-12 --- pkgs/by-name/cr/cronet-go/build-naive.patch | 51 ++++++++++ pkgs/by-name/cr/cronet-go/cflags.patch | 40 ++++++++ pkgs/by-name/cr/cronet-go/libresolv.patch | 11 +++ pkgs/by-name/cr/cronet-go/package.nix | 101 ++++++++++++++++++++ 4 files changed, 203 insertions(+) create mode 100644 pkgs/by-name/cr/cronet-go/build-naive.patch create mode 100644 pkgs/by-name/cr/cronet-go/cflags.patch create mode 100644 pkgs/by-name/cr/cronet-go/libresolv.patch create mode 100644 pkgs/by-name/cr/cronet-go/package.nix diff --git a/pkgs/by-name/cr/cronet-go/build-naive.patch b/pkgs/by-name/cr/cronet-go/build-naive.patch new file mode 100644 index 000000000000..0de12a17befe --- /dev/null +++ b/pkgs/by-name/cr/cronet-go/build-naive.patch @@ -0,0 +1,51 @@ +--- a/cmd/build-naive/cmd_build.go ++++ b/cmd/build-naive/cmd_build.go +@@ -211,7 +211,7 @@ func runGetClang(t Target) { + } + + func buildTarget(t Target) { +- runGetClang(t) ++ // runGetClang(t) + + outputDirectory := getOutputDirectory(t) + +@@ -244,16 +244,15 @@ func buildTarget(t Target) { + "optimize_for_size=true", + fmt.Sprintf("target_os=\"%s\"", t.OS), + fmt.Sprintf("target_cpu=\"%s\"", t.CPU), ++ "clang_base_path=\"@clang_base_path@\"", ++ "clang_use_chrome_plugins=false", + } + + switch t.OS { + case "mac": + args = append(args, "use_sysroot=false") + case "linux": +- // Sysroot is handled by get-clang.sh, use the naiveproxy path +- sysrootPath := getSysrootPath(t) +- sysrootDirectory := strings.TrimPrefix(sysrootPath, srcRoot+string(filepath.Separator)) +- args = append(args, "use_sysroot=true", fmt.Sprintf("target_sysroot=\"//%s\"", sysrootDirectory)) ++ args = append(args, "use_sysroot=false") + if t.CPU == "x64" { + args = append(args, "use_cfi_icall=false", "is_cfi=false") + } +@@ -316,7 +315,7 @@ func buildTarget(t Target) { + + gnArgs := strings.Join(args, " ") + +- gnPath := filepath.Join(srcRoot, "gn", "out", "gn") ++ gnPath := "@gn@" + if runtime.GOOS == "windows" { + gnPath += ".exe" + } +--- a/cmd/build-naive/cmd_package.go ++++ b/cmd/build-naive/cmd_package.go +@@ -386,7 +386,7 @@ const Version = "%s" + // This allows the package to compile in purego mode (user must provide .so/.dylib) + generatePuregoStubFile(targetDirectory, packageName, chromiumVersion) + +- runCommand(targetDirectory, "go", "mod", "tidy") ++ // runCommand(targetDirectory, "go", "mod", "tidy") + + log.Printf("Generated submodule lib/%s", directoryName) + } diff --git a/pkgs/by-name/cr/cronet-go/cflags.patch b/pkgs/by-name/cr/cronet-go/cflags.patch new file mode 100644 index 000000000000..d7f0ba76ed5b --- /dev/null +++ b/pkgs/by-name/cr/cronet-go/cflags.patch @@ -0,0 +1,40 @@ +--- a/naiveproxy/src/build/config/compiler/BUILD.gn ++++ b/naiveproxy/src/build/config/compiler/BUILD.gn +@@ -631,9 +631,9 @@ + # The performance improvement does not seem worth the risk. See + # https://crbug.com/484082200 for background and https://crrev.com/c/7593035 + # for discussion. +- if (!is_wasm && !is_apple) { +- cflags += [ "-fno-lifetime-dse" ] +- } ++ # if (!is_wasm && !is_apple) { ++ # cflags += [ "-fno-lifetime-dse" ] ++ # } + + # TODO(hans): Remove this once Clang generates better optimized debug info + # by default. https://crbug.com/765793 +@@ -1950,13 +1950,13 @@ + # sanitizer) is enabled, they then do expensive debug like operations. We + # want to suppress this behaviour since we want to keep performance costs + # as low as possible while having these checks. +- "-fsanitize-ignore-for-ubsan-feature=array-bounds", ++ # "-fsanitize-ignore-for-ubsan-feature=array-bounds", + + # Because we've enabled array-bounds sanitizing we also want to suppress + # the related warning about "unsafe-buffer-usage-in-static-sized-array", + # since we know that the array bounds sanitizing will catch any out-of- + # bounds accesses. +- "-Wno-unsafe-buffer-usage-in-static-sized-array", ++ # "-Wno-unsafe-buffer-usage-in-static-sized-array", + ] + } + } +@@ -1974,7 +1974,7 @@ + # sanitizer) is enabled, they then do expensive debug like operations. We + # want to suppress this behaviour since we want to keep performance costs + # as low as possible while having these checks. +- "-fsanitize-ignore-for-ubsan-feature=return", ++ # "-fsanitize-ignore-for-ubsan-feature=return", + ] + } + } diff --git a/pkgs/by-name/cr/cronet-go/libresolv.patch b/pkgs/by-name/cr/cronet-go/libresolv.patch new file mode 100644 index 000000000000..2ecab176f017 --- /dev/null +++ b/pkgs/by-name/cr/cronet-go/libresolv.patch @@ -0,0 +1,11 @@ +--- a/naiveproxy/src/build/config/mac/BUILD.gn ++++ b/naiveproxy/src/build/config/mac/BUILD.gn +@@ -14,7 +14,7 @@ import("//build/toolchain/siso.gni") + # is applied to all targets. It is here to separate out the logic. + config("compiler") { + # These flags are shared between the C compiler and linker. +- common_mac_flags = [] ++ common_mac_flags = [ "-I@libresolv@/include" ] + + # CPU architecture. + _archs_mapping_os = archs_mapping[current_os] diff --git a/pkgs/by-name/cr/cronet-go/package.nix b/pkgs/by-name/cr/cronet-go/package.nix new file mode 100644 index 000000000000..ffdbf1e7b9eb --- /dev/null +++ b/pkgs/by-name/cr/cronet-go/package.nix @@ -0,0 +1,101 @@ +{ + apple-sdk_15, + buildGoModule, + buildPackages, + darwin, + fetchFromGitHub, + gn, + lib, + ninja, + python3, + replaceVars, + stdenvNoCC, + symlinkJoin, + xcbuild, +}: +let + llvmCcAndBintools = symlinkJoin { + name = "llvmCcAndBintools"; + paths = [ + buildPackages.rustc.llvmPackages.llvm + buildPackages.rustc.llvmPackages.stdenv.cc + ]; + }; +in +stdenvNoCC.mkDerivation (finalAttrs: { + pname = "cronet-go"; + version = "148.0.7778.96-1-unstable-2026-07-12"; + + # nixpkgs-update: no auto update + src = fetchFromGitHub { + owner = "SagerNet"; + repo = "cronet-go"; + rev = "617d38f41f935b46a68f550d9add2e38abb3f168"; + fetchSubmodules = true; + hash = "sha256-UK7mv0TuhJX4y64DhH49t5mgZFGhMx4Viy/chulKD4s="; + }; + + patches = [ + ./cflags.patch + ] + ++ lib.optional stdenvNoCC.hostPlatform.isDarwin ( + replaceVars ./libresolv.patch { + libresolv = lib.getInclude darwin.libresolv; + } + ); + + nativeBuildInputs = [ + buildPackages.rustc.llvmPackages.bintools + ninja + python3 + ] + ++ lib.optional stdenvNoCC.hostPlatform.isDarwin xcbuild; + + buildInputs = lib.optional stdenvNoCC.hostPlatform.isDarwin apple-sdk_15; + + buildPhase = '' + runHook preBuild + + ${lib.getExe finalAttrs.passthru.build-naive} build + ${lib.getExe finalAttrs.passthru.build-naive} package --local + ${lib.getExe finalAttrs.passthru.build-naive} package + + runHook postBuild + ''; + + installPhase = '' + runHook preInstall + + mkdir -p $out + cp -r lib include include_cgo.go $out/ + + runHook postInstall + ''; + + passthru = { + build-naive = buildGoModule { + pname = finalAttrs.pname + "-build-naive"; + inherit (finalAttrs) version src; + vendorHash = "sha256-pyeE+JPuRQEjNzrF+o9jslBcBM1vruuL+I/DCIa2BG0="; + patches = [ + (replaceVars ./build-naive.patch { + gn = lib.getExe gn; + clang_base_path = llvmCcAndBintools; + }) + ]; + subPackages = [ "cmd/build-naive" ]; + meta.mainProgram = "build-naive"; + }; + }; + + strictDeps = true; + __structuredAttrs = true; + + meta = { + description = "Go bindings for naiveproxy"; + homepage = "https://github.com/SagerNet/cronet-go"; + license = lib.licenses.gpl3Plus; + maintainers = with lib.maintainers; [ prince213 ]; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + }; +}) From e99be1b21f7e78caf6d3853f94f650f52752e1bd Mon Sep 17 00:00:00 2001 From: Sizhe Zhao Date: Sun, 1 Mar 2026 21:02:29 +0800 Subject: [PATCH 36/71] sing-box: support naive outbound --- pkgs/by-name/si/sing-box/cronet-go.patch | 27 ++++++++++++ pkgs/by-name/si/sing-box/package.nix | 53 ++++++++++++++++++++---- 2 files changed, 72 insertions(+), 8 deletions(-) create mode 100644 pkgs/by-name/si/sing-box/cronet-go.patch diff --git a/pkgs/by-name/si/sing-box/cronet-go.patch b/pkgs/by-name/si/sing-box/cronet-go.patch new file mode 100644 index 000000000000..b50ab0e12c2b --- /dev/null +++ b/pkgs/by-name/si/sing-box/cronet-go.patch @@ -0,0 +1,27 @@ +--- a/internal/cronet/loader_unix.go ++++ b/internal/cronet/loader_unix.go +@@ -68,10 +68,11 @@ + } + + var searchPaths []string +- executablePath, err := os.Executable() +- if err == nil { +- searchPaths = append(searchPaths, filepath.Dir(executablePath)) +- } ++ // executablePath, err := os.Executable() ++ // if err == nil { ++ // searchPaths = append(searchPaths, filepath.Dir(executablePath)) ++ // } ++ searchPaths = append(searchPaths, "@out@/lib") + + if ldPath := os.Getenv("LD_LIBRARY_PATH"); ldPath != "" { + paths := filepath.SplitList(ldPath) +@@ -85,7 +86,7 @@ + } + } + +- searchPaths = append(searchPaths, "/usr/local/lib", "/usr/lib") ++ // searchPaths = append(searchPaths, "/usr/local/lib", "/usr/lib") + + for _, searchPath := range searchPaths { + fullPath := filepath.Join(searchPath, libName) diff --git a/pkgs/by-name/si/sing-box/package.nix b/pkgs/by-name/si/sing-box/package.nix index 467f0ae8be37..42960d0db491 100644 --- a/pkgs/by-name/si/sing-box/package.nix +++ b/pkgs/by-name/si/sing-box/package.nix @@ -1,17 +1,28 @@ { lib, buildGoModule, - fetchFromGitHub, - installShellFiles, + buildPackages, coreutils, - nix-update-script, + cronet-go, + fetchFromGitHub, + go, + installShellFiles, nixosTests, -}: + stdenvNoCC, + withStaticCronet ? true, + withNaiveOutbound ? true, +}: +assert lib.assertMsg ( + withNaiveOutbound -> !withStaticCronet -> stdenvNoCC.hostPlatform.isLinux +) "Dynamic linking to cronet-go is only available on Linux."; buildGoModule (finalAttrs: { pname = "sing-box"; version = "1.13.15"; + __structuredAttrs = true; + + # nixpkgs-update: no auto update src = fetchFromGitHub { owner = "SagerNet"; repo = "sing-box"; @@ -34,15 +45,28 @@ buildGoModule (finalAttrs: { "with_ocm" "badlinkname" "tfogo_checklinkname0" - ]; + ] + ++ lib.optional withNaiveOutbound "with_naive_outbound" + ++ lib.optional (withNaiveOutbound && !withStaticCronet) "with_purego"; subPackages = [ "cmd/sing-box" ]; - env.CGO_ENABLED = 0; + env = { + CGO_ENABLED = 0; + } + // lib.optionalAttrs (withNaiveOutbound && withStaticCronet) { + CGO_ENABLED = 1; + CGO_LDFLAGS = "-fuse-ld=lld"; + }; - nativeBuildInputs = [ installShellFiles ]; + nativeBuildInputs = [ + installShellFiles + ] + ++ lib.optional (withNaiveOutbound && withStaticCronet) buildPackages.rustc.llvmPackages.bintools; + + buildInputs = lib.optional (withNaiveOutbound && withStaticCronet) cronet-go; ldflags = [ "-X=github.com/sagernet/sing-box/constant.Version=${finalAttrs.version}" @@ -50,6 +74,17 @@ buildGoModule (finalAttrs: { "-checklinkname=0" ]; + postConfigure = lib.optionalString withNaiveOutbound '' + pushd vendor/github.com/sagernet/cronet-go + chmod -R u+w . + cp -r ${cronet-go}/ . + # for !withStaticCronet + patch -p1 < ${./cronet-go.patch} + substituteInPlace internal/cronet/loader_unix.go \ + --subst-var out + popd + ''; + postInstall = '' installShellCompletion release/completions/sing-box.{bash,fish,zsh} @@ -60,10 +95,12 @@ buildGoModule (finalAttrs: { install -Dm444 release/config/sing-box.rules $out/share/polkit-1/rules.d/sing-box.rules install -Dm444 release/config/sing-box-split-dns.xml $out/share/dbus-1/system.d/sing-box-split-dns.conf + '' + + lib.optionalString (withNaiveOutbound && !withStaticCronet) '' + ln -s "${cronet-go}/lib/${go.GOOS}_${go.GOARCH}/libcronet.so" "$out/lib/" ''; passthru = { - updateScript = nix-update-script { }; tests = { inherit (nixosTests) sing-box; }; }; From 5ebe7da9ffb840c6e2f9981cc5212dca5b5434dc Mon Sep 17 00:00:00 2001 From: Sizhe Zhao Date: Sun, 24 May 2026 22:58:38 +0800 Subject: [PATCH 37/71] doc/rl-2611: add sing-box naive outbound --- doc/release-notes/rl-2611.section.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/doc/release-notes/rl-2611.section.md b/doc/release-notes/rl-2611.section.md index 24941676a336..f6d4cabc93c4 100644 --- a/doc/release-notes/rl-2611.section.md +++ b/doc/release-notes/rl-2611.section.md @@ -16,6 +16,8 @@ +nixpkgs.url = "https://channels.nixos.org/nixos-26.05/nixexprs.tar.zst"; ``` +- `sing-box` now supports NaïveProxy outbounds. + ## Backward Incompatibilities {#sec-nixpkgs-release-26.11-incompatibilities} From 32db8d6e993b9021d60c51f8166f3268a63f6891 Mon Sep 17 00:00:00 2001 From: Sizhe Zhao Date: Sun, 24 May 2026 22:59:50 +0800 Subject: [PATCH 38/71] nixos/doc/rl-2611: add sing-box naive outbound --- nixos/doc/manual/release-notes/rl-2611.section.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/nixos/doc/manual/release-notes/rl-2611.section.md b/nixos/doc/manual/release-notes/rl-2611.section.md index 034b4a9dfd62..9aeec853c539 100644 --- a/nixos/doc/manual/release-notes/rl-2611.section.md +++ b/nixos/doc/manual/release-notes/rl-2611.section.md @@ -18,6 +18,8 @@ +nixpkgs.url = "https://channels.nixos.org/nixos-26.05/nixexprs.tar.zst"; ``` +- `sing-box` now supports NaïveProxy outbounds. + ## New Modules {#sec-release-26.11-new-modules} From 6f2ec629d6934aa8c3e452a8bcfc6701d8522b64 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 2 Aug 2026 04:59:45 +0000 Subject: [PATCH 39/71] home-assistant-custom-components.elegoo_printer: 2.11.0 -> 2.12.0 --- .../custom-components/elegoo_printer/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/home-assistant/custom-components/elegoo_printer/package.nix b/pkgs/servers/home-assistant/custom-components/elegoo_printer/package.nix index 998fabdbe762..3fc648b431ba 100644 --- a/pkgs/servers/home-assistant/custom-components/elegoo_printer/package.nix +++ b/pkgs/servers/home-assistant/custom-components/elegoo_printer/package.nix @@ -19,13 +19,13 @@ buildHomeAssistantComponent rec { owner = "danielcherubini"; domain = "elegoo_printer"; - version = "2.11.0"; + version = "2.12.0"; src = fetchFromGitHub { owner = "danielcherubini"; repo = "elegoo-homeassistant"; tag = "v${version}"; - hash = "sha256-UrmgWCY1U52LCt2O/HXOwbcIzTYX/TrnGxvW2S0iB7M="; + hash = "sha256-aeptx8CFKD+22H8Bw19rDUuHkET3vINN3NpGuherc8Y="; }; dependencies = [ From b208bae1f7b9961abddb56bf74b1af177272c242 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 2 Aug 2026 05:35:42 +0000 Subject: [PATCH 40/71] sdl_gamecontrollerdb: 0-unstable-2026-07-23 -> 0-unstable-2026-07-31 --- pkgs/by-name/sd/sdl_gamecontrollerdb/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/sd/sdl_gamecontrollerdb/package.nix b/pkgs/by-name/sd/sdl_gamecontrollerdb/package.nix index cb4953993819..7394df312177 100644 --- a/pkgs/by-name/sd/sdl_gamecontrollerdb/package.nix +++ b/pkgs/by-name/sd/sdl_gamecontrollerdb/package.nix @@ -7,13 +7,13 @@ stdenvNoCC.mkDerivation (finalAttrs: { pname = "sdl_gamecontrollerdb"; - version = "0-unstable-2026-07-23"; + version = "0-unstable-2026-07-31"; src = fetchFromGitHub { owner = "mdqinc"; repo = "SDL_GameControllerDB"; - rev = "fa9c1fb9df83bdabb9f699eadac66adc9759b14d"; - hash = "sha256-t8fTiPT0g08QbPJGnlppJEe64ZHGNyV8fv0Za471DD8="; + rev = "92580540a27913da37a34cfcc006f973d471c081"; + hash = "sha256-awINI/AItJ/ReuFWiuH6NTA9RrgAWXe/M3wIWk9ytlA="; }; dontBuild = true; From 5e0e35c6dd85f29474c565d9feb1f62506d06ed9 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 2 Aug 2026 06:26:14 +0000 Subject: [PATCH 41/71] home-assistant-custom-components.powercalc: 1.23.0 -> 1.23.2 --- .../home-assistant/custom-components/powercalc/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/home-assistant/custom-components/powercalc/package.nix b/pkgs/servers/home-assistant/custom-components/powercalc/package.nix index 7c632fe29365..8049c1740095 100644 --- a/pkgs/servers/home-assistant/custom-components/powercalc/package.nix +++ b/pkgs/servers/home-assistant/custom-components/powercalc/package.nix @@ -17,13 +17,13 @@ buildHomeAssistantComponent rec { owner = "bramstroker"; domain = "powercalc"; - version = "1.23.0"; + version = "1.23.2"; src = fetchFromGitHub { inherit owner; repo = "homeassistant-powercalc"; tag = "v${version}"; - hash = "sha256-WmbmKYcGwuny6Z2WLNZOACNs1jjKKlL9Dwvvd0Q2ass="; + hash = "sha256-JOZLVQhT3MhYbq6wuS7PM6H5fKVvf1ZhAYR5LZoRWAA="; }; dependencies = [ numpy ]; From c321a2d68d2856cc46e98275d12b90052ac6c762 Mon Sep 17 00:00:00 2001 From: Gerhard Schwanzer Date: Sun, 2 Aug 2026 08:33:42 +0200 Subject: [PATCH 42/71] lib60870: 2.3.6 -> 2.4.1 https://redirect.github.com/mz-automation/lib60870/releases/tag/v2.4.1 Assisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol) --- pkgs/by-name/li/lib60870/package.nix | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/li/lib60870/package.nix b/pkgs/by-name/li/lib60870/package.nix index 0878ce66cec0..953c0d10f406 100644 --- a/pkgs/by-name/li/lib60870/package.nix +++ b/pkgs/by-name/li/lib60870/package.nix @@ -9,20 +9,21 @@ stdenv.mkDerivation (finalAttrs: { pname = "lib60870"; - version = "2.3.6"; + version = "2.4.1"; src = fetchFromGitHub { owner = "mz-automation"; repo = "lib60870"; rev = "v${finalAttrs.version}"; - hash = "sha256-9VqLl1pDmi8TauBA8uCyymzsYd3w4b5AKtqH7XW80N4="; + hash = "sha256-WXEe+G7ib9XNAZSsNl/RZcFHXpIbCMKNfPLnxZzz09E="; }; sourceRoot = "${finalAttrs.src.name}/lib60870-C"; postPatch = '' + # Keep system mbedTLS support enabled without vendored mbedTLS sources. substituteInPlace CMakeLists.txt \ - --replace-fail "cmake_minimum_required(VERSION 3.0)" "cmake_minimum_required(VERSION 3.10)" + --replace-fail "if(MBEDTLS_DIR)" "if(MBEDTLS_DIR OR WITH_MBEDTLS3)" '' + lib.optionalString stdenv.hostPlatform.isDarwin '' substituteInPlace src/CMakeLists.txt \ From 0b7688d3e00c60914ff06062133e25d0f332702e Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Sun, 2 Aug 2026 12:05:55 +0200 Subject: [PATCH 43/71] nginxModules.pagespeed: remove Repo was archived last year & build is broken. --- pkgs/servers/http/nginx/modules/aliases.nix | 1 + .../http/nginx/modules/pagespeed/package.nix | 51 ------------------- 2 files changed, 1 insertion(+), 51 deletions(-) delete mode 100644 pkgs/servers/http/nginx/modules/pagespeed/package.nix diff --git a/pkgs/servers/http/nginx/modules/aliases.nix b/pkgs/servers/http/nginx/modules/aliases.nix index 6d2c8b0a279d..9ca7a2fbc71f 100644 --- a/pkgs/servers/http/nginx/modules/aliases.nix +++ b/pkgs/servers/http/nginx/modules/aliases.nix @@ -9,6 +9,7 @@ self: { modsecurity-nginx = self.modsecurity; ngx_aws_auth = throw "ngx_aws_auth was renamed to aws-auth"; opentracing = throw "opentracing-cpp was removed because opentracing as been archived upstream"; # Added 2025-10-19 + pagespeed = throw "pagespeed was removed because the upstream repo is archived & the build was broken"; # Added 2026-08-02 statsd = throw "statsd was removed because its upstream source vanished"; # Added 2026-07-28 # keep-sorted end } diff --git a/pkgs/servers/http/nginx/modules/pagespeed/package.nix b/pkgs/servers/http/nginx/modules/pagespeed/package.nix deleted file mode 100644 index 696bdfdde986..000000000000 --- a/pkgs/servers/http/nginx/modules/pagespeed/package.nix +++ /dev/null @@ -1,51 +0,0 @@ -{ - fetchFromGitHub, - lib, - libuuid, - mkNginxPlugin, - psol, - runCommand, - zlib, -}: - -mkNginxPlugin (finalAttrs: { - pname = "pagespeed"; - version = psol.version; - - src = - let - moduleSrc = fetchFromGitHub { - owner = "apache"; - repo = "incubator-pagespeed-ngx"; - rev = "v${psol.version}-stable"; - sha256 = "0ry7vmkb2bx0sspl1kgjlrzzz6lbz07313ks2lr80rrdm2zb16wp"; - }; - in - runCommand "ngx_pagespeed" - { - meta = { - description = "PageSpeed module for Nginx"; - homepage = "https://developers.google.com/speed/pagespeed/module/"; - license = lib.licenses.asl20; - }; - } - '' - cp -r "${moduleSrc}" "$out" - chmod -R +w "$out" - ln -s "${psol}" "$out/psol" - ''; - - buildInputs = [ - zlib - libuuid - ]; # psol deps - - allowMemoryWriteExecute = true; - - meta = { - description = "Automatic PageSpeed optimization"; - homepage = "https://github.com/apache/incubator-pagespeed-ngx"; - license = lib.licenses.asl20; - maintainers = [ ]; - }; -}) From 9525c348d4c1ec01784ac3ed0b16f53400877121 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Sun, 2 Aug 2026 12:06:21 +0200 Subject: [PATCH 44/71] nginxModules.fluentd: remove Broken for a while, not updated since 2014 and repo hasn't seen activity for 7 years. --- pkgs/servers/http/nginx/modules/aliases.nix | 1 + .../http/nginx/modules/fluentd/package.nix | 24 ------------------- 2 files changed, 1 insertion(+), 24 deletions(-) delete mode 100644 pkgs/servers/http/nginx/modules/fluentd/package.nix diff --git a/pkgs/servers/http/nginx/modules/aliases.nix b/pkgs/servers/http/nginx/modules/aliases.nix index 9ca7a2fbc71f..3e49ec7e95a0 100644 --- a/pkgs/servers/http/nginx/modules/aliases.nix +++ b/pkgs/servers/http/nginx/modules/aliases.nix @@ -4,6 +4,7 @@ self: { # keep-sorted start case=no numeric=yes block=yes fastcgi-cache-purge = throw "fastcgi-cache-purge was renamed to cache-purge"; + fluentd = throw "fluentd was removed due to lack of maintenance"; # Added 2026-08-02 http_proxy_connect_module_v24 = throw "http_proxy_connect_module_v24 was removed because it was not compatible with any supported nginx version"; # Added 2026-07-29 http_proxy_connect_module_v25 = throw "http_proxy_connect_module_v25 was removed because it was not compatible with any supported nginx version"; # Added 2026-07-29 modsecurity-nginx = self.modsecurity; diff --git a/pkgs/servers/http/nginx/modules/fluentd/package.nix b/pkgs/servers/http/nginx/modules/fluentd/package.nix deleted file mode 100644 index 57cd3676de7c..000000000000 --- a/pkgs/servers/http/nginx/modules/fluentd/package.nix +++ /dev/null @@ -1,24 +0,0 @@ -{ - fetchFromGitHub, - lib, - mkNginxPlugin, -}: - -mkNginxPlugin (finalAttrs: { - pname = "fluentd"; - version = "0.3-unstable-2014-03-28"; - - src = fetchFromGitHub { - owner = "fluent"; - repo = "nginx-fluentd-module"; - rev = "8af234043059c857be27879bc547c141eafd5c13"; - hash = "sha256-tf+jrac1QGOEwQnmDPmMMvM/Tg1TXTmKysBwndovi/k="; - }; - - meta = { - description = "Fluentd data collector"; - homepage = "https://github.com/fluent/nginx-fluentd-module"; - license = lib.licenses.asl20; - maintainers = [ ]; - }; -}) From 84261cd0c2ff34daaecdb3b497118e4b16bc23a9 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Sun, 2 Aug 2026 12:08:20 +0200 Subject: [PATCH 45/71] nginxModules.naxsi: remove Build broken & repo archived. --- pkgs/servers/http/nginx/modules/aliases.nix | 1 + .../http/nginx/modules/naxsi/package.nix | 26 ------------------- 2 files changed, 1 insertion(+), 26 deletions(-) delete mode 100644 pkgs/servers/http/nginx/modules/naxsi/package.nix diff --git a/pkgs/servers/http/nginx/modules/aliases.nix b/pkgs/servers/http/nginx/modules/aliases.nix index 3e49ec7e95a0..9ddc1e7c1997 100644 --- a/pkgs/servers/http/nginx/modules/aliases.nix +++ b/pkgs/servers/http/nginx/modules/aliases.nix @@ -8,6 +8,7 @@ self: { http_proxy_connect_module_v24 = throw "http_proxy_connect_module_v24 was removed because it was not compatible with any supported nginx version"; # Added 2026-07-29 http_proxy_connect_module_v25 = throw "http_proxy_connect_module_v25 was removed because it was not compatible with any supported nginx version"; # Added 2026-07-29 modsecurity-nginx = self.modsecurity; + naxsi = throw "naxsi was removed because the build was broken & the repo is archived"; # Added 2026-08-02 ngx_aws_auth = throw "ngx_aws_auth was renamed to aws-auth"; opentracing = throw "opentracing-cpp was removed because opentracing as been archived upstream"; # Added 2025-10-19 pagespeed = throw "pagespeed was removed because the upstream repo is archived & the build was broken"; # Added 2026-08-02 diff --git a/pkgs/servers/http/nginx/modules/naxsi/package.nix b/pkgs/servers/http/nginx/modules/naxsi/package.nix deleted file mode 100644 index c1af28a7d076..000000000000 --- a/pkgs/servers/http/nginx/modules/naxsi/package.nix +++ /dev/null @@ -1,26 +0,0 @@ -{ - fetchFromGitHub, - lib, - mkNginxPlugin, -}: - -mkNginxPlugin (finalAttrs: { - pname = "naxsi"; - version = "1.0-unstable-2020-09-10"; - - src = fetchFromGitHub { - owner = "nbs-system"; - repo = "naxsi"; - rev = "95ac520eed2ea04098a76305fd0ad7e9158840b7"; - sha256 = "0b5pnqkgg18kbw5rf2ifiq7lsx5rqmpqsql6hx5ycxjzxj6acfb3"; - }; - - sourceRoot = "${finalAttrs.src.name}/naxsi_src"; - - meta = { - description = "Open-source, high performance, low rules maintenance WAF"; - homepage = "https://github.com/nbs-system/naxsi"; - license = lib.licenses.gpl3; - maintainers = [ ]; - }; -}) From 553fb879c3f8d84396b45e1b322924086356173e Mon Sep 17 00:00:00 2001 From: Marie Ramlow Date: Sat, 1 Aug 2026 21:23:02 +0200 Subject: [PATCH 46/71] fetchNpmDeps: assert fetcherVersion is not higher than latest version If we introduce version 3, current packages that use the non-existent version 3 will get their hashes broken. Prevent stupid LLMs from introducing more trouble when hallucinating more non-existent versions. --- .../node/prefetch-npm-deps/default.nix | 15 +++++++++++++-- 1 file changed, 13 insertions(+), 2 deletions(-) diff --git a/pkgs/build-support/node/prefetch-npm-deps/default.nix b/pkgs/build-support/node/prefetch-npm-deps/default.nix index eb73907343de..2875c9291dec 100644 --- a/pkgs/build-support/node/prefetch-npm-deps/default.nix +++ b/pkgs/build-support/node/prefetch-npm-deps/default.nix @@ -300,8 +300,19 @@ NIX_NPM_REGISTRY_OVERRIDES = npmRegistryOverridesString; # Fetcher version controls which features are enabled in prefetch-npm-deps - # Version 2+ enables packument fetching for workspace support - NPM_FETCHER_VERSION = toString fetcherVersion; + NPM_FETCHER_VERSION = + let + # Increment when we introduce a new version. + validFetcherVersions = [ + 1 # Initial version + 2 # enables packument fetching for workspace support + ]; + in + assert lib.assertMsg (lib.elem fetcherVersion validFetcherVersions) + "fetchNpmDeps: fetcher version must be one of: ${ + lib.concatMapStringsSep ", " toString validFetcherVersions + }."; + (toString fetcherVersion); SSL_CERT_FILE = if From c2d890f46320fd8ce5f6c84bb2b426c719a7ecb8 Mon Sep 17 00:00:00 2001 From: Tom Herbers Date: Sun, 2 Aug 2026 08:42:19 +0200 Subject: [PATCH 47/71] kanidm_1_11: init at 1.11.0 Changelog: https://github.com/kanidm/kanidm/releases/tag/v1.11.0 --- nixos/tests/kanidm-provisioning.nix | 2 +- nixos/tests/kanidm.nix | 2 +- pkgs/servers/kanidm/1_10.nix | 1 + pkgs/servers/kanidm/1_11.nix | 5 + pkgs/servers/kanidm/generic.nix | 13 +- .../1_11/oauth2-basic-secret-modify.patch | 159 ++++++++++++++++++ .../1_11/recover-account.patch | 128 ++++++++++++++ pkgs/top-level/all-packages.nix | 6 + 8 files changed, 312 insertions(+), 4 deletions(-) create mode 100644 pkgs/servers/kanidm/1_11.nix create mode 100644 pkgs/servers/kanidm/provision-patches/1_11/oauth2-basic-secret-modify.patch create mode 100644 pkgs/servers/kanidm/provision-patches/1_11/recover-account.patch diff --git a/nixos/tests/kanidm-provisioning.nix b/nixos/tests/kanidm-provisioning.nix index 133bd0d10cb2..78b0ff5ad05c 100644 --- a/nixos/tests/kanidm-provisioning.nix +++ b/nixos/tests/kanidm-provisioning.nix @@ -18,7 +18,7 @@ in name = "kanidm-provisioning-${kanidmPackage.version}"; meta.maintainers = with pkgs.lib.maintainers; [ oddlama ]; - _module.args.kanidmPackage = pkgs.lib.mkDefault pkgs.kanidmWithSecretProvisioning_1_10; + _module.args.kanidmPackage = pkgs.lib.mkDefault pkgs.kanidmWithSecretProvisioning_1_11; nodes.provision = { pkgs, lib, ... }: diff --git a/nixos/tests/kanidm.nix b/nixos/tests/kanidm.nix index 1d17d84908cf..3eaa6d0ab5bf 100644 --- a/nixos/tests/kanidm.nix +++ b/nixos/tests/kanidm.nix @@ -22,7 +22,7 @@ in oddlama ]; - _module.args.kanidmPackage = pkgs.lib.mkDefault pkgs.kanidm_1_10; + _module.args.kanidmPackage = pkgs.lib.mkDefault pkgs.kanidm_1_11; nodes.server = { pkgs, ... }: diff --git a/pkgs/servers/kanidm/1_10.nix b/pkgs/servers/kanidm/1_10.nix index 543296dd86f3..7601a72038eb 100644 --- a/pkgs/servers/kanidm/1_10.nix +++ b/pkgs/servers/kanidm/1_10.nix @@ -2,4 +2,5 @@ import ./generic.nix { version = "1.10.5"; hash = "sha256-mNdG5iPtnhwvy9PABaRPV6KQfvD+/ZKH2hC6Hfo0y48="; cargoHash = "sha256-UE/jZaX/mEJUHBqsk2o0rBcocpoFg5XWAmVk4smm5mc="; + eolDate = "2026-08-31"; } diff --git a/pkgs/servers/kanidm/1_11.nix b/pkgs/servers/kanidm/1_11.nix new file mode 100644 index 000000000000..c06b30750207 --- /dev/null +++ b/pkgs/servers/kanidm/1_11.nix @@ -0,0 +1,5 @@ +import ./generic.nix { + version = "1.11.0"; + hash = "sha256-3dcJxJx8UFebW6WMdVTH6kfsNBed+55JFwHWVhZulOU="; + cargoHash = "sha256-qOs/uSs3iaiTGsqydpNbZ6KSLNE+k+5bM7k3ijRzNT0="; +} diff --git a/pkgs/servers/kanidm/generic.nix b/pkgs/servers/kanidm/generic.nix index fcd8c3e543a9..9c5ee6266aa0 100644 --- a/pkgs/servers/kanidm/generic.nix +++ b/pkgs/servers/kanidm/generic.nix @@ -91,14 +91,23 @@ rustPlatform.buildRustPackage (finalAttrs: { // lib.optionalAttrs (lib.versionAtLeast finalAttrs.version "1.9") { server_migration_path = "/etc/kanidm/migrations.d"; }; + # lower required rust-version in Cargo.toml to allow backporting + rustVersion = + if lib.versionAtLeast finalAttrs.version "1.11" then + { + from = "1.96"; + to = "1.95"; + } + else + null; in '' cp ${format profile} libs/profiles/${finalAttrs.env.KANIDM_BUILD_PROFILE}.toml substituteInPlace libs/profiles/${finalAttrs.env.KANIDM_BUILD_PROFILE}.toml --replace-fail '@htmx_ui_pkg_path@' "$out/ui/hpkg" '' - + lib.optionalString (lib.versionAtLeast finalAttrs.version "1.9") '' + + lib.optionalString (rustVersion != null) '' substituteInPlace Cargo.toml \ - --replace-fail 'rust-version = "1.93"' 'rust-version = "1.91"' + --replace-fail 'rust-version = "${rustVersion.from}"' 'rust-version = "${rustVersion.to}"' ''; nativeBuildInputs = [ diff --git a/pkgs/servers/kanidm/provision-patches/1_11/oauth2-basic-secret-modify.patch b/pkgs/servers/kanidm/provision-patches/1_11/oauth2-basic-secret-modify.patch new file mode 100644 index 000000000000..5101273d30d1 --- /dev/null +++ b/pkgs/servers/kanidm/provision-patches/1_11/oauth2-basic-secret-modify.patch @@ -0,0 +1,159 @@ +From 5b97267c49def10f5a4b7bb372963261c0f4b08d Mon Sep 17 00:00:00 2001 +From: oddlama +Date: Fri, 1 May 2026 15:01:05 +0200 +Subject: [PATCH 1/2] oauth2 basic secret modify + +--- + server/core/src/actors/v1_write.rs | 42 +++++++++++++++++++++++++++++ + server/core/src/https/v1.rs | 6 ++++- + server/core/src/https/v1_oauth2.rs | 29 ++++++++++++++++++++ + server/lib/src/server/migrations.rs | 16 +++++++++++ + 4 files changed, 92 insertions(+), 1 deletion(-) + +diff --git a/server/core/src/actors/v1_write.rs b/server/core/src/actors/v1_write.rs +index 977292ae9..bf79c42a1 100644 +--- a/server/core/src/actors/v1_write.rs ++++ b/server/core/src/actors/v1_write.rs +@@ -326,6 +326,48 @@ impl QueryServerWriteV1 { + .and_then(|_| idms_prox_write.commit().map(|_| ())) + } + ++ #[instrument( ++ level = "info", ++ skip_all, ++ fields(uuid = ?eventid) ++ )] ++ pub async fn handle_oauth2_basic_secret_write( ++ &self, ++ client_auth_info: ClientAuthInfo, ++ filter: Filter, ++ new_secret: String, ++ eventid: Uuid, ++ ) -> Result<(), OperationError> { ++ // Given a protoEntry, turn this into a modification set. ++ let ct = duration_from_epoch_now(); ++ let mut idms_prox_write = self.idms.proxy_write(ct).await?; ++ let ident = idms_prox_write ++ .validate_client_auth_info_to_ident(client_auth_info, ct) ++ .map_err(|e| { ++ admin_error!(err = ?e, "Invalid identity"); ++ e ++ })?; ++ ++ let modlist = ModifyList::new_purge_and_set( ++ Attribute::OAuth2RsBasicSecret, ++ Value::SecretValue(new_secret), ++ ); ++ ++ let mdf = ++ ModifyEvent::from_internal_parts(ident, &modlist, &filter, &idms_prox_write.qs_write) ++ .map_err(|e| { ++ admin_error!(err = ?e, "Failed to begin modify during handle_oauth2_basic_secret_write"); ++ e ++ })?; ++ ++ trace!(?mdf, "Begin modify event"); ++ ++ idms_prox_write ++ .qs_write ++ .modify(&mdf) ++ .and_then(|_| idms_prox_write.commit()) ++ } ++ + #[instrument( + level = "info", + skip_all, +diff --git a/server/core/src/https/v1.rs b/server/core/src/https/v1.rs +index ba3ea2827..489ce0002 100644 +--- a/server/core/src/https/v1.rs ++++ b/server/core/src/https/v1.rs +@@ -10,7 +10,7 @@ use axum::extract::{Path, State}; + use axum::http::{HeaderMap, HeaderValue}; + use axum::middleware::from_fn; + use axum::response::{IntoResponse, Response}; +-use axum::routing::{delete, get, post, put}; ++use axum::routing::{delete, get, post, put, patch}; + use axum::{Extension, Json, Router}; + use axum_extra::extract::cookie::{Cookie, CookieJar, SameSite}; + use compact_jwt::{Jwk, Jws, JwsSigner}; +@@ -3156,6 +3156,10 @@ pub(crate) fn route_setup(state: ServerState) -> Router { + "/v1/oauth2/{rs_name}/_basic_secret", + get(super::v1_oauth2::oauth2_id_get_basic_secret), + ) ++ .route( ++ "/v1/oauth2/{rs_name}/_basic_secret", ++ patch(super::v1_oauth2::oauth2_id_patch_basic_secret), ++ ) + .route( + "/v1/oauth2/{rs_name}/_scopemap/{group}", + post(super::v1_oauth2::oauth2_id_scopemap_post) +diff --git a/server/core/src/https/v1_oauth2.rs b/server/core/src/https/v1_oauth2.rs +index fdc3647b4..ed4709d27 100644 +--- a/server/core/src/https/v1_oauth2.rs ++++ b/server/core/src/https/v1_oauth2.rs +@@ -149,6 +149,35 @@ pub(crate) async fn oauth2_id_get_basic_secret( + .map_err(WebError::from) + } + ++#[utoipa::path( ++ patch, ++ path = "/v1/oauth2/{rs_name}/_basic_secret", ++ request_body=ProtoEntry, ++ responses( ++ DefaultApiResponse, ++ ), ++ security(("token_jwt" = [])), ++ tag = "v1/oauth2", ++ operation_id = "oauth2_id_patch_basic_secret" ++)] ++/// Overwrite the basic secret for a given OAuth2 Resource Server. ++#[instrument(level = "info", skip(state, new_secret))] ++pub(crate) async fn oauth2_id_patch_basic_secret( ++ State(state): State, ++ Extension(kopid): Extension, ++ VerifiedClientInformation(client_auth_info): VerifiedClientInformation, ++ Path(rs_name): Path, ++ Json(new_secret): Json, ++) -> Result, WebError> { ++ let filter = oauth2_id(&rs_name); ++ state ++ .qe_w_ref ++ .handle_oauth2_basic_secret_write(client_auth_info, filter, new_secret, kopid.eventid) ++ .await ++ .map(Json::from) ++ .map_err(WebError::from) ++} ++ + #[utoipa::path( + patch, + path = "/v1/oauth2/{rs_name}", +diff --git a/server/lib/src/server/migrations.rs b/server/lib/src/server/migrations.rs +index b3effb95b..5c6a56d24 100644 +--- a/server/lib/src/server/migrations.rs ++++ b/server/lib/src/server/migrations.rs +@@ -220,6 +220,22 @@ impl QueryServer { + reload_required = true; + }; + ++ // secret provisioning: allow idm_admin to modify OAuth2RsBasicSecret. ++ write_txn.internal_modify_uuid( ++ UUID_IDM_ACP_OAUTH2_MANAGE_V1, ++ &ModifyList::new_append( ++ Attribute::AcpCreateAttr, ++ Attribute::OAuth2RsBasicSecret.into(), ++ ), ++ )?; ++ write_txn.internal_modify_uuid( ++ UUID_IDM_ACP_OAUTH2_MANAGE_V1, ++ &ModifyList::new_append( ++ Attribute::AcpModifyPresentAttr, ++ Attribute::OAuth2RsBasicSecret.into(), ++ ), ++ )?; ++ + // Execute whatever operations we have batched up and ready to go. This is needed + // to preserve ordering of the operations - if we reloaded after a remigrate then + // we would have skipped the patch level fix which needs to have occurred *first*. +-- +2.53.0 + diff --git a/pkgs/servers/kanidm/provision-patches/1_11/recover-account.patch b/pkgs/servers/kanidm/provision-patches/1_11/recover-account.patch new file mode 100644 index 000000000000..a462c14d5d1c --- /dev/null +++ b/pkgs/servers/kanidm/provision-patches/1_11/recover-account.patch @@ -0,0 +1,128 @@ +From e8cd69afcee9d8d37233fa998cf9d1fa124ae90d Mon Sep 17 00:00:00 2001 +From: oddlama +Date: Fri, 1 May 2026 15:01:14 +0200 +Subject: [PATCH 2/2] recover account + +--- + server/core/src/actors/internal.rs | 5 +++-- + server/core/src/admin.rs | 6 +++--- + server/daemon/src/main.rs | 24 +++++++++++++++++++++++- + server/daemon/src/opt.rs | 7 +++++++ + 4 files changed, 36 insertions(+), 6 deletions(-) + +diff --git a/server/core/src/actors/internal.rs b/server/core/src/actors/internal.rs +index deed7350d..f4e9e486a 100644 +--- a/server/core/src/actors/internal.rs ++++ b/server/core/src/actors/internal.rs +@@ -189,17 +189,18 @@ impl QueryServerWriteV1 { + + #[instrument( + level = "info", +- skip(self, eventid), ++ skip(self, password, eventid), + fields(uuid = ?eventid) + )] + pub(crate) async fn handle_admin_recover_account( + &self, + name: String, ++ password: Option, + eventid: Uuid, + ) -> Result { + let ct = duration_from_epoch_now(); + let mut idms_prox_write = self.idms.proxy_write(ct).await?; +- let pw = idms_prox_write.recover_account(name.as_str(), None)?; ++ let pw = idms_prox_write.recover_account(name.as_str(), password.as_deref())?; + + idms_prox_write.commit().map(|()| pw) + } +diff --git a/server/core/src/admin.rs b/server/core/src/admin.rs +index 6a13dcaab..6b1070113 100644 +--- a/server/core/src/admin.rs ++++ b/server/core/src/admin.rs +@@ -27,7 +27,7 @@ const REPL_CTRL_TIMEOUT: Duration = Duration::from_secs(15); + + #[derive(Serialize, Deserialize, Debug)] + pub enum AdminTaskRequest { +- RecoverAccount { name: String }, ++ RecoverAccount { name: String, password: Option }, + DisableAccount { name: String }, + ShowReplicationCertificate, + ShowReplicationCertificateMetadata, +@@ -416,8 +416,8 @@ async fn handle_client( + + let resp = async { + match req { +- AdminTaskRequest::RecoverAccount { name } => { +- match server_rw.handle_admin_recover_account(name, eventid).await { ++ AdminTaskRequest::RecoverAccount { name, password } => { ++ match server_rw.handle_admin_recover_account(name, password, eventid).await { + Ok(password) => AdminTaskResponse::RecoverAccount { password }, + Err(e) => { + error!(err = ?e, "error during recover-account"); +diff --git a/server/daemon/src/main.rs b/server/daemon/src/main.rs +index 13653a5cb..ae560f9ce 100644 +--- a/server/daemon/src/main.rs ++++ b/server/daemon/src/main.rs +@@ -380,11 +380,32 @@ fn check_file_ownership(opt: &KanidmdParser) -> Result<(), ExitCode> { + + async fn scripting_command(cmd: ScriptingCommand, config: Configuration) -> ExitCode { + match cmd { +- ScriptingCommand::RecoverAccount { name } => { ++ ScriptingCommand::RecoverAccount { name, from_environment } => { ++ let password = if from_environment { ++ match std::env::var("KANIDM_RECOVER_ACCOUNT_PASSWORD_FILE") { ++ Ok(path) => match tokio::fs::read_to_string(&path).await { ++ Ok(contents) => Some(contents), ++ Err(e) => { ++ error!("Failed to read password file '{}': {}", path, e); ++ return ExitCode::FAILURE; ++ } ++ }, ++ Err(_) => match std::env::var("KANIDM_RECOVER_ACCOUNT_PASSWORD") { ++ Ok(val) => Some(val), ++ Err(_) => { ++ error!("Neither KANIDM_RECOVER_ACCOUNT_PASSWORD_FILE nor KANIDM_RECOVER_ACCOUNT_PASSWORD was set"); ++ return ExitCode::FAILURE; ++ } ++ } ++ } ++ } else { ++ None ++ }; + submit_admin_req_json( + config.adminbindpath.as_str(), + AdminTaskRequest::RecoverAccount { + name: name.to_owned(), ++ password, + }, + ) + .await; +@@ -1008,6 +1029,7 @@ async fn kanidm_main(config: Configuration, opt: KanidmdParser) -> ExitCode { + config.adminbindpath.as_str(), + AdminTaskRequest::RecoverAccount { + name: name.to_owned(), ++ password: None, + }, + ) + .await; +diff --git a/server/daemon/src/opt.rs b/server/daemon/src/opt.rs +index 524ba3134..fa3d70f44 100644 +--- a/server/daemon/src/opt.rs ++++ b/server/daemon/src/opt.rs +@@ -128,6 +128,13 @@ enum ScriptingCommand { + #[clap(value_parser)] + /// The account name to recover credentials for. + name: String, ++ /// Use a password given via an environment variable. ++ /// - `KANIDM_RECOVER_ACCOUNT_PASSWORD_FILE` takes precedence and reads the desired ++ /// password from the given file ++ /// - `KANIDM_RECOVER_ACCOUNT_PASSWORD` directly takes a ++ /// password - beware that this will leave the password in the environment ++ #[clap(long = "from-environment")] ++ from_environment: bool, + }, + /// Backup + Backup { +-- +2.53.0 + diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index fbd50102e4eb..7580fa54e47a 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -7378,17 +7378,23 @@ with pkgs; kanidm_1_10 = callPackage ../servers/kanidm/1_10.nix { kanidmWithSecretProvisioning = kanidmWithSecretProvisioning_1_10; }; + kanidm_1_11 = callPackage ../servers/kanidm/1_11.nix { + kanidmWithSecretProvisioning = kanidmWithSecretProvisioning_1_11; + }; kanidmWithSecretProvisioning_1_8 = kanidm_1_8.override { enableSecretProvisioning = true; }; kanidmWithSecretProvisioning_1_9 = kanidm_1_9.override { enableSecretProvisioning = true; }; kanidmWithSecretProvisioning_1_10 = kanidm_1_10.override { enableSecretProvisioning = true; }; + kanidmWithSecretProvisioning_1_11 = kanidm_1_11.override { enableSecretProvisioning = true; }; }) kanidm_1_8 kanidm_1_9 kanidm_1_10 + kanidm_1_11 kanidmWithSecretProvisioning_1_8 kanidmWithSecretProvisioning_1_9 kanidmWithSecretProvisioning_1_10 + kanidmWithSecretProvisioning_1_11 ; lemmy-server = callPackage ../servers/web-apps/lemmy/server.nix { }; From 6cd3e717ef7308ab7759a6b0d042e45387cedc97 Mon Sep 17 00:00:00 2001 From: yaaaarn Date: Sun, 2 Aug 2026 13:23:36 +0100 Subject: [PATCH 48/71] catgirldownloader: init at 0.5 --- pkgs/by-name/ca/catgirldownloader/package.nix | 56 +++++++++++++++++++ 1 file changed, 56 insertions(+) create mode 100644 pkgs/by-name/ca/catgirldownloader/package.nix diff --git a/pkgs/by-name/ca/catgirldownloader/package.nix b/pkgs/by-name/ca/catgirldownloader/package.nix new file mode 100644 index 000000000000..9c9a542d9c5e --- /dev/null +++ b/pkgs/by-name/ca/catgirldownloader/package.nix @@ -0,0 +1,56 @@ +{ + lib, + fetchFromGitHub, + python3Packages, + gtk4, + libadwaita, + gobject-introspection, + wrapGAppsHook4, + meson, + ninja, + pkg-config, + gettext, + desktop-file-utils, +}: +python3Packages.buildPythonApplication (finalAttrs: { + pname = "catgirldownloader"; + version = "0.5"; + + __structuredAttrs = true; + pyproject = false; + + src = fetchFromGitHub { + owner = "NyarchLinux"; + repo = "CatgirlDownloader"; + tag = finalAttrs.version; + hash = "sha256-+RyQOgqPZN3AnVdd5mtgppQ/z51VIEeEsiW2RFTnVbk="; + }; + + nativeBuildInputs = [ + meson + ninja + pkg-config + desktop-file-utils + gettext + gobject-introspection + wrapGAppsHook4 + ]; + + buildInputs = [ + gtk4 + libadwaita + ]; + + dependencies = with python3Packages; [ + pygobject3 + requests + ]; + + meta = { + description = "A GTK4 application that downloads images of catgirl and waifus from multiple sources"; + homepage = "https://github.com/NyarchLinux/CatgirlDownloader"; + license = lib.licenses.gpl3Only; + maintainers = with lib.maintainers; [ yarn ]; + platforms = lib.platforms.linux; + }; +}) From 764a4ebdf25b051f3e937840e1c60526c9f0a0ea Mon Sep 17 00:00:00 2001 From: Morgan Jones Date: Sun, 2 Aug 2026 05:24:15 -0700 Subject: [PATCH 49/71] nixos/limine: don't read all of /nix/store during installation The installer being placed directly at (e.g.) /nix/store/272h8d4df6by64ycl3s01bixrcaq5a9a-limine-install.py causes Python to search the script's directory for imports if -P is not added, so add -P to avoid Python automatically adding /nix/store to the script's sys.path. From the python manpage: > -P: Don't automatically prepend a potentially unsafe path to sys.path > such as the current directory, the script's directory or an empty string. > See also the PYTHONSAFEPATH environment variable. --- nixos/modules/system/boot/loader/limine/limine-install.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/nixos/modules/system/boot/loader/limine/limine-install.py b/nixos/modules/system/boot/loader/limine/limine-install.py index dacf4a339d0e..ba6cd4fc8356 100644 --- a/nixos/modules/system/boot/loader/limine/limine-install.py +++ b/nixos/modules/system/boot/loader/limine/limine-install.py @@ -1,4 +1,4 @@ -#!@python3@/bin/python3 -B +#!@python3@/bin/python3 -BP from dataclasses import dataclass from typing import Any, Dict, List, Optional, Tuple From d1b0abbadf97279b258a35becfc8166408906aff Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 2 Aug 2026 12:41:13 +0000 Subject: [PATCH 50/71] _1password-gui-beta: 8.12.26-31.BETA -> 8.12.32-26.BETA --- pkgs/by-name/_1/_1password-gui/sources.json | 20 ++++++++++---------- 1 file changed, 10 insertions(+), 10 deletions(-) diff --git a/pkgs/by-name/_1/_1password-gui/sources.json b/pkgs/by-name/_1/_1password-gui/sources.json index 7ab8898f017c..bf65e03c8848 100644 --- a/pkgs/by-name/_1/_1password-gui/sources.json +++ b/pkgs/by-name/_1/_1password-gui/sources.json @@ -29,28 +29,28 @@ }, "beta": { "linux": { - "version": "8.12.26-31.BETA", + "version": "8.12.32-26.BETA", "sources": { "x86_64": { - "url": "https://downloads.1password.com/linux/tar/beta/x86_64/1password-8.12.26-31.BETA.x64.tar.gz", - "hash": "sha256-jlBvt2QEOgoisC1u8WY7cEXuCgk3wKcgQ1owu02rEio=" + "url": "https://downloads.1password.com/linux/tar/beta/x86_64/1password-8.12.32-26.BETA.x64.tar.gz", + "hash": "sha256-9LtsORe/o1+SxBfeGCFf6hiO1uwuBWyIjHVs2jW0FNo=" }, "aarch64": { - "url": "https://downloads.1password.com/linux/tar/beta/aarch64/1password-8.12.26-31.BETA.arm64.tar.gz", - "hash": "sha256-jCI5G9xGdXChGW8388BMpMfyYwxzNxYNoV2sYBj8eV4=" + "url": "https://downloads.1password.com/linux/tar/beta/aarch64/1password-8.12.32-26.BETA.arm64.tar.gz", + "hash": "sha256-zyTyqTEIq4mXttyy5VCai9oBgTNo8tsmtqU+PuZOtGA=" } } }, "darwin": { - "version": "8.12.26-31.BETA", + "version": "8.12.32-26.BETA", "sources": { "x86_64": { - "url": "https://downloads.1password.com/mac/1Password-8.12.26-31.BETA-x86_64.zip", - "hash": "sha256-TBNhnCrKVZD1CVeBZ3dZ0TVeldrRotUpXEycFnvPfZo=" + "url": "https://downloads.1password.com/mac/1Password-8.12.32-26.BETA-x86_64.zip", + "hash": "sha256-PhqdUmd7EjYiYbzxuzs4Z4v2TD0S6SJPaKLvinCxcqE=" }, "aarch64": { - "url": "https://downloads.1password.com/mac/1Password-8.12.26-31.BETA-aarch64.zip", - "hash": "sha256-8+H9+Z7/uqlnMP2eUm7z493S6ZCEV0a5Sorw3AGTDCc=" + "url": "https://downloads.1password.com/mac/1Password-8.12.32-26.BETA-aarch64.zip", + "hash": "sha256-eVkVAGQRRWv4vMnGJt+4ETAdnU6/slLXlTJgXxhNRzc=" } } } From 9b7ecae5a1700c3465584f53c93421de6b008d3f Mon Sep 17 00:00:00 2001 From: Vlad Petrov Date: Wed, 29 Jul 2026 20:30:47 +0300 Subject: [PATCH 51/71] mark: 16.6.0 -> 16.8.9 Co-authored-by: Nikolay Korotkiy --- pkgs/by-name/ma/mark/package.nix | 28 +++++++++++++++++++++++----- 1 file changed, 23 insertions(+), 5 deletions(-) diff --git a/pkgs/by-name/ma/mark/package.nix b/pkgs/by-name/ma/mark/package.nix index 9da7683e1c8b..25b1951bffa8 100644 --- a/pkgs/by-name/ma/mark/package.nix +++ b/pkgs/by-name/ma/mark/package.nix @@ -1,23 +1,24 @@ { lib, + stdenv, buildGoModule, fetchFromGitHub, + iana-etc, + libredirect, }: -# Tests with go 1.24 do not work. For now -# https://github.com/kovetskiy/mark/pull/581#issuecomment-2797872996 buildGoModule (finalAttrs: { pname = "mark"; - version = "16.6.0"; + version = "16.8.9"; src = fetchFromGitHub { owner = "kovetskiy"; repo = "mark"; rev = "v${finalAttrs.version}"; - sha256 = "sha256-kpWY+8r6ILHmZr1VWO+4rj8tLqzyucsDNPnoPaF1IkU="; + sha256 = "sha256-tIixIAgMooDONu1ZcU0tTFM0DR+j2R4gcO9s1tA0x9I="; }; - vendorHash = "sha256-vJn/bFhbnDY0OfuD9swvt/X5Pb0nWpaoHc1iwWCVwpg="; + vendorHash = "sha256-DR3ma5pliR7C1gJ+b2gbWEIEEb+QaH7hSSc9mroA5Tc="; ldflags = [ "-s" @@ -25,18 +26,35 @@ buildGoModule (finalAttrs: { "-X main.version=${finalAttrs.version}" ]; + nativeCheckInputs = lib.optionals stdenv.hostPlatform.isDarwin [ libredirect.hook ]; + + # goldmark-katex pulls in modernc.org/libc, whose vendored netdb package reads + # /etc/protocols and /etc/services during package init. It falls back to a + # built-in table when they do not exist, but panics when they exist and are + # unreadable, which is what the Darwin sandbox produces. + preCheck = lib.optionalString stdenv.hostPlatform.isDarwin '' + export NIX_REDIRECTS=/etc/protocols=${iana-etc}/etc/protocols:/etc/services=${iana-etc}/etc/services + ''; + checkFlags = let skippedTests = [ # Expects to be able to launch google-chrome "TestExtractMermaidImage" "TestExtractD2Image/example" + "TestAttachmentFilenameAttributeIsEscaped" + "TestDiagramWithoutTitleHasNoCaption" + "TestDiagramWithTitleKeepsCaption" ]; in [ "-skip=^${builtins.concatStringsSep "$|^" skippedTests}$" ]; + # confluence/api_test.go serves a mock Confluence API over httptest, which + # binds a localhost listener. + __darwinAllowLocalNetworking = true; + meta = { description = "Tool for syncing your markdown documentation with Atlassian Confluence pages"; mainProgram = "mark"; From 7e09d3726c5850ddb11930780212eb14776e704e Mon Sep 17 00:00:00 2001 From: Gerhard Schwanzer Date: Sun, 2 Aug 2026 14:43:29 +0200 Subject: [PATCH 52/71] perlPackages.DateManip: fix CVE-2026-60074 and CVE-2026-60075 Apply CPAN Security's complete fixes for rejecting non-ASCII numeric date fields and bounding parser input before expensive regular expressions run. Move the existing date fallback substitution to postPatch so the standard patch phase applies the security patches first. Assisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol) --- pkgs/top-level/perl-packages.nix | 15 ++++++++++++++- 1 file changed, 14 insertions(+), 1 deletion(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index aed44234b45b..7c52ed9443bc 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -8987,8 +8987,21 @@ with self; url = "mirror://cpan/authors/id/S/SB/SBECK/Date-Manip-6.98.tar.gz"; hash = "sha256-rP2KYFGbpM0YHIpnqD1/ApxtmrTosCEtxH5B1iEP2kk="; }; + # Remove when updating to the first release containing both CVE fixes. + patches = [ + (fetchpatch { + name = "CVE-2026-60074.patch"; + url = "https://security.metacpan.org/patches/D/Date-Manip/6.99/CVE-2026-60074-r1.patch"; + hash = "sha256-leXFfzLyy0yBpBXgT3u3ZyFaIbsbJSFzVkdam9hb3+0="; + }) + (fetchpatch { + name = "CVE-2026-60075.patch"; + url = "https://security.metacpan.org/patches/D/Date-Manip/6.99/CVE-2026-60075-r1.patch"; + hash = "sha256-vMsOrUhrfn8efKRzfJ+jaypOHER8MlUIob5u88n/TAw="; + }) + ]; # for some reason, parsing /etc/localtime does not work anymore - make sure that the fallback "/bin/date +%Z" will work - patchPhase = '' + postPatch = '' sed -i "s#/bin/date#${pkgs.coreutils}/bin/date#" lib/Date/Manip/TZ.pm ''; doCheck = !stdenv.hostPlatform.isi686; # build freezes during tests on i686 From 205fb105e846a6182084052e3b42a3af7eb9a246 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 2 Aug 2026 12:45:34 +0000 Subject: [PATCH 53/71] panoply: 5.10.0 -> 5.10.1 --- pkgs/by-name/pa/panoply/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/pa/panoply/package.nix b/pkgs/by-name/pa/panoply/package.nix index 060fff5c39c5..b795b3200c78 100644 --- a/pkgs/by-name/pa/panoply/package.nix +++ b/pkgs/by-name/pa/panoply/package.nix @@ -8,11 +8,11 @@ stdenvNoCC.mkDerivation rec { pname = "panoply"; - version = "5.10.0"; + version = "5.10.1"; src = fetchurl { url = "https://www.giss.nasa.gov/tools/panoply/download/PanoplyJ-${version}.tgz"; - hash = "sha256-xPeBNjOY8BMs3zw0coUhYqaEcyYc9BtO2ETwDOv2H5Q="; + hash = "sha256-xSvzYD7Bk3SC0WUhQVKRhkCZTiB1vAATM7qSGw9U7Lo="; }; nativeBuildInputs = [ makeWrapper ]; From bdb1f1c194eaa65129ecd7b1fd5cfde7c9a4a832 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Sun, 2 Aug 2026 15:49:28 +0200 Subject: [PATCH 54/71] zigbee2mqtt: 2.12.1 -> 2.13.0 https://github.com/Koenkk/zigbee2mqtt/releases/tag/2.13.0 --- pkgs/by-name/zi/zigbee2mqtt/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/zi/zigbee2mqtt/package.nix b/pkgs/by-name/zi/zigbee2mqtt/package.nix index ddf527f7b93e..c73b8df14224 100644 --- a/pkgs/by-name/zi/zigbee2mqtt/package.nix +++ b/pkgs/by-name/zi/zigbee2mqtt/package.nix @@ -14,20 +14,20 @@ }: stdenv.mkDerivation (finalAttrs: { pname = "zigbee2mqtt"; - version = "2.12.1"; + version = "2.13.0"; src = fetchFromGitHub { owner = "Koenkk"; repo = "zigbee2mqtt"; tag = finalAttrs.version; - hash = "sha256-DTL27AcPmAI5XEEHb2S74LYWm4f6kUASsTmQeGftDzM="; + hash = "sha256-JSmJXjEF0dQ1sWyXvtLmN9gfAg3PjXWPOlb7xCxz8RI="; }; pnpmDeps = fetchPnpmDeps { inherit (finalAttrs) pname version src; pnpm = pnpm_10; fetcherVersion = 4; - hash = "sha256-RI6tz8pyqYg/L6wSc0Rt5ZqHT8aktReyVjNgISPqKRQ="; + hash = "sha256-5S3VnPxR7P4dwXcFQSjNbTJ5KOWteb4ZBpTy7gtoY4I="; }; nativeBuildInputs = [ From f3dced00971eef97a88b53ea0a55bd69aacc07bc Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 2 Aug 2026 13:53:28 +0000 Subject: [PATCH 55/71] nginxModules.njs: 0.9.4 -> 1.0.0 --- pkgs/servers/http/nginx/modules/njs/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/http/nginx/modules/njs/package.nix b/pkgs/servers/http/nginx/modules/njs/package.nix index a6b3af2f36ff..c275ae255845 100644 --- a/pkgs/servers/http/nginx/modules/njs/package.nix +++ b/pkgs/servers/http/nginx/modules/njs/package.nix @@ -9,13 +9,13 @@ mkNginxPlugin (finalAttrs: { pname = "njs"; - version = "0.9.4"; + version = "1.0.0"; src = fetchFromGitHub { owner = "nginx"; repo = "njs"; tag = finalAttrs.version; - hash = "sha256-Ee55QKaeZ0mYGKUroKr/AYGoOCakEonU483qkhmZdzU="; + hash = "sha256-svZvAVcIm13SVf4O5rgZOigJ8IKuaPQrnZenkZaDluQ="; }; preConfigure = '' From b0067f4d586d08ac7f8b07eb2f8354dd113b502c Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 2 Aug 2026 13:55:01 +0000 Subject: [PATCH 56/71] nginxModules.develkit: 0.3.3 -> 0.3.4 --- pkgs/servers/http/nginx/modules/develkit/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/http/nginx/modules/develkit/package.nix b/pkgs/servers/http/nginx/modules/develkit/package.nix index cb2fceae3cdf..827d6eb791c3 100644 --- a/pkgs/servers/http/nginx/modules/develkit/package.nix +++ b/pkgs/servers/http/nginx/modules/develkit/package.nix @@ -6,13 +6,13 @@ mkNginxPlugin (finalAttrs: { pname = "develkit"; - version = "0.3.3"; + version = "0.3.4"; src = fetchFromGitHub { owner = "vision5"; repo = "ngx_devel_kit"; tag = "v${finalAttrs.version}"; - hash = "sha256-/RQUVHwIdNqm3UemQ/oNs2ksg8beziA4Pxejd5Yg0Pg="; + hash = "sha256-SXQ5KC8X9nKLbntXjEziCqJVeiX+lnBKruAVVVcexaM="; }; meta = { From 04a3452b944657d5e4ffe1fe3001b27924d580aa Mon Sep 17 00:00:00 2001 From: matthewcroughan Date: Sun, 2 Aug 2026 14:58:04 +0100 Subject: [PATCH 57/71] msm-modem: init at 13 --- pkgs/by-name/ms/msm-modem/package.nix | 59 +++++++++++++++++++++++++++ 1 file changed, 59 insertions(+) create mode 100644 pkgs/by-name/ms/msm-modem/package.nix diff --git a/pkgs/by-name/ms/msm-modem/package.nix b/pkgs/by-name/ms/msm-modem/package.nix new file mode 100644 index 000000000000..1b7466e28c70 --- /dev/null +++ b/pkgs/by-name/ms/msm-modem/package.nix @@ -0,0 +1,59 @@ +{ + lib, + stdenv, + fetchFromGitLab, + meson, + ninja, + nix-update-script, + makeWrapper, + gnugrep, + gawk, + libqmi, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "msm-modem"; + version = "13"; + __structuredAttrs = true; + strictDeps = true; + + src = fetchFromGitLab { + domain = "gitlab.postmarketos.org"; + owner = "postmarketOS"; + repo = "msm-modem"; + tag = finalAttrs.version; + hash = "sha256-kKDqYrd7yI3beS7kMVN+xqTBfNC4NTUgch2t/rDM9LE="; + }; + + nativeBuildInputs = [ + meson + ninja + makeWrapper + ]; + + mesonFlags = [ + "-Ddownstream=false" + "-Dopenrc=false" + ]; + + postInstall = '' + wrapProgram $out/libexec/msm-modem-uim-selection \ + --prefix PATH : ${ + lib.makeBinPath [ + libqmi + gawk + gnugrep + ] + } + ''; + + passthru.updateScript = nix-update-script { }; + + meta = { + description = "Common support for Qualcomm MSM modems"; + homepage = "https://gitlab.postmarketos.org/postmarketOS/msm-modem"; + license = lib.licenses.gpl3Only; + maintainers = with lib.maintainers; [ matthewcroughan ]; + platforms = lib.platforms.linux; + }; +}) From e56288309931f810588d0f63768fd004675d3373 Mon Sep 17 00:00:00 2001 From: matthewcroughan Date: Sun, 2 Aug 2026 14:44:11 +0100 Subject: [PATCH 58/71] bootmac: init at 0.7.1 --- pkgs/by-name/bo/bootmac/package.nix | 67 +++++++++++++++++++++++++++++ 1 file changed, 67 insertions(+) create mode 100644 pkgs/by-name/bo/bootmac/package.nix diff --git a/pkgs/by-name/bo/bootmac/package.nix b/pkgs/by-name/bo/bootmac/package.nix new file mode 100644 index 000000000000..776aed9967ec --- /dev/null +++ b/pkgs/by-name/bo/bootmac/package.nix @@ -0,0 +1,67 @@ +{ + lib, + stdenv, + fetchFromGitLab, + meson, + ninja, + makeWrapper, + gawk, + bluez, + util-linux, + gnugrep, + gnused, + coreutils, + iproute2, + udevCheckHook, +}: +stdenv.mkDerivation (finalAttrs: { + name = "bootmac"; + version = "0.7.1"; + __structuredAttrs = true; + strictDeps = true; + + src = fetchFromGitLab { + domain = "gitlab.postmarketos.org"; + owner = "postmarketOS"; + repo = "bootmac"; + rev = "v${finalAttrs.version}"; + hash = "sha256-GWvZUC8LKPpOWt1oCr93JHg5+W+0CCiYT63VhpSH1ko="; + }; + + nativeBuildInputs = [ + meson + ninja + makeWrapper + udevCheckHook + ]; + + mesonFlags = [ "-Dsystemd_units=true" ]; + + postInstall = '' + wrapProgram $out/bin/bootmac \ + --prefix PATH : ${ + lib.makeBinPath [ + gawk + bluez + util-linux + gnugrep + gnused + coreutils + iproute2 + ] + } + + substituteInPlace \ + $out/lib/systemd/system/bootmac@.service \ + $out/lib/udev/rules.d/90-bootmac-{bluetooth,wifi}.rules \ + --replace-fail /usr/bin/bootmac $out/bin/bootmac + ''; + + meta = { + description = "Configure the MAC addresses of WLAN and Bluetooth interfaces at boot"; + mainProgram = "bootmac"; + license = lib.licenses.gpl3; + maintainers = with lib.maintainers; [ matthewcroughan ]; + platforms = bluez.meta.platforms; + }; +}) From 74cc0a6c9d734b6bbe47c45d92713bd417296772 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 2 Aug 2026 14:04:46 +0000 Subject: [PATCH 59/71] nginxModules.vts: 0.2.2 -> 0.2.6 --- pkgs/servers/http/nginx/modules/vts/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/http/nginx/modules/vts/package.nix b/pkgs/servers/http/nginx/modules/vts/package.nix index fffb783fd6fe..10858b0cb7ca 100644 --- a/pkgs/servers/http/nginx/modules/vts/package.nix +++ b/pkgs/servers/http/nginx/modules/vts/package.nix @@ -6,13 +6,13 @@ mkNginxPlugin (finalAttrs: { pname = "vts"; - version = "0.2.2"; + version = "0.2.6"; src = fetchFromGitHub { owner = "vozlt"; repo = "nginx-module-vts"; tag = "v${finalAttrs.version}"; - hash = "sha256-ReTmYGVSOwtnYDMkQDMWwxw09vT4iHYfYZvgd8iBotk="; + hash = "sha256-3u4igVGBVsv+GNi3CSduZL6ZaOmdPoItUPA4+wmRw5Y="; }; meta = { From 9c511e822ddcaf01f0a634b86d7f2fab52f80b60 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 2 Aug 2026 14:05:54 +0000 Subject: [PATCH 60/71] nginxModules.cache-purge: 2.5.1 -> 3.0.2 --- pkgs/servers/http/nginx/modules/cache-purge/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/http/nginx/modules/cache-purge/package.nix b/pkgs/servers/http/nginx/modules/cache-purge/package.nix index 8e2211d8b05d..5da23ae14be2 100644 --- a/pkgs/servers/http/nginx/modules/cache-purge/package.nix +++ b/pkgs/servers/http/nginx/modules/cache-purge/package.nix @@ -6,13 +6,13 @@ mkNginxPlugin (finalAttrs: { pname = "cache-purge"; - version = "2.5.1"; + version = "3.0.2"; src = fetchFromGitHub { owner = "nginx-modules"; repo = "ngx_cache_purge"; tag = finalAttrs.version; - hash = "sha256-jVm8E4u1NkjtBoGdRzUDo6l27XPDFoCrNUf2asaXRG0="; + hash = "sha256-kjZbHXaDCh4EHK59XuIISZ0xcgd2c+plwrXvqB+2S1E="; }; meta = { From b5a373cb2f831dd88f29e63359245da097082fac Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 2 Aug 2026 14:06:34 +0000 Subject: [PATCH 61/71] nginxModules.fancyindex: 0.5.2 -> 0.6.0 --- pkgs/servers/http/nginx/modules/fancyindex/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/http/nginx/modules/fancyindex/package.nix b/pkgs/servers/http/nginx/modules/fancyindex/package.nix index e91359568288..b8be79fe85b9 100644 --- a/pkgs/servers/http/nginx/modules/fancyindex/package.nix +++ b/pkgs/servers/http/nginx/modules/fancyindex/package.nix @@ -6,13 +6,13 @@ mkNginxPlugin (finalAttrs: { pname = "fancyindex"; - version = "0.5.2"; + version = "0.6.0"; src = fetchFromGitHub { owner = "aperezdc"; repo = "ngx-fancyindex"; tag = "v${finalAttrs.version}"; - hash = "sha256-70bEZ5EVM3jjY5b9azXYBvJnFDoqgGXu0F7JcWkhWVk="; + hash = "sha256-97HCAm3hcgrwyOvBEwC+vcVkuuzedgHC67+w8OK2bEQ="; }; meta = { From 6ed597fc7979c8cb6c7ae07c640afd885d2cfa7f Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 2 Aug 2026 14:27:18 +0000 Subject: [PATCH 62/71] all-the-package-names: 2.0.2511 -> 2.0.2520 --- pkgs/by-name/al/all-the-package-names/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/al/all-the-package-names/package.nix b/pkgs/by-name/al/all-the-package-names/package.nix index fe35b7eb856f..305f8ddac1c8 100644 --- a/pkgs/by-name/al/all-the-package-names/package.nix +++ b/pkgs/by-name/al/all-the-package-names/package.nix @@ -7,16 +7,16 @@ buildNpmPackage rec { pname = "all-the-package-names"; - version = "2.0.2511"; + version = "2.0.2520"; src = fetchFromGitHub { owner = "nice-registry"; repo = "all-the-package-names"; tag = "v${version}"; - hash = "sha256-KnEvFnPXQZ+XhNyweWIE0mjM4vqcqXcJKuus/dFq5f0="; + hash = "sha256-cJwYVEeiry7lmhcuE8ABrCB59MH8GZBqF34FvHUOX6M="; }; - npmDepsHash = "sha256-Xw/SXRpQkPd+EcemeHO89tC9amDiVV/RD/1H0H8rax0="; + npmDepsHash = "sha256-B7UDkGEYVTmf/gny4o9YqgNuU1Zz+y6Fg2st7Khy2fo="; passthru.updateScript = nix-update-script { }; From c504cb466e947f8549dc4c861b54b4aabaddbf94 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Sun, 2 Aug 2026 16:56:55 +0200 Subject: [PATCH 63/71] evcc: 0.313.0 -> 0.313.1 https://github.com/evcc-io/evcc/releases/tag/0.313.1 --- pkgs/by-name/ev/evcc/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ev/evcc/package.nix b/pkgs/by-name/ev/evcc/package.nix index 99dd9ce7c447..8eb9abbf547c 100644 --- a/pkgs/by-name/ev/evcc/package.nix +++ b/pkgs/by-name/ev/evcc/package.nix @@ -17,13 +17,13 @@ }: let - version = "0.313.0"; + version = "0.313.1"; src = fetchFromGitHub { owner = "evcc-io"; repo = "evcc"; tag = version; - hash = "sha256-VDLEgkbBgyAuVAVrd0D3i07mwN1OBJfwOCXdi3gc/aw="; + hash = "sha256-P/NEP+gGS3Wni9j09NVujmdDYaAz7ntOtrPFZNKy/Bo="; }; vendorHash = "sha256-QJsdBqa/JHaBig4bRtU3LqlYwh/BHnP3vg8YM3reuDY="; From f06bc88ebb8ed29aee58f0d45987e88adb61734c Mon Sep 17 00:00:00 2001 From: Sean Gilligan Date: Sun, 2 Aug 2026 08:30:17 -0700 Subject: [PATCH 64/71] secp256k1-jdk: add nix-update-script Add nix-update-script. Also change `rev` to `tag` in `fetchFromGitHub`. --- pkgs/by-name/se/secp256k1-jdk/package.nix | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/se/secp256k1-jdk/package.nix b/pkgs/by-name/se/secp256k1-jdk/package.nix index 1acb5d832481..13324af60281 100644 --- a/pkgs/by-name/se/secp256k1-jdk/package.nix +++ b/pkgs/by-name/se/secp256k1-jdk/package.nix @@ -3,6 +3,7 @@ fetchFromGitHub, maven, jdk25, + nix-update-script, }: maven.buildMavenPackage (finalAttrs: { @@ -12,7 +13,7 @@ maven.buildMavenPackage (finalAttrs: { src = fetchFromGitHub { owner = "bitcoinj"; repo = "secp256k1-jdk"; - rev = "v${finalAttrs.version}"; + tag = "v${finalAttrs.version}"; hash = "sha256-F2e4NDPEU7ZAu4+fvEd4BRbE2JwCvUiMeXHTMDXbIJE="; }; @@ -44,6 +45,8 @@ maven.buildMavenPackage (finalAttrs: { runHook postInstall ''; + passthru.updateScript = nix-update-script { }; + meta = { changelog = "https://github.com/bitcoinj/secp256k1-jdk/blob/master/CHANGELOG.adoc"; description = "Java library providing Elliptic Curve Cryptography on curve secp256k1"; From e5a2cc86eb4ec3faa564f7e208bc0faaab20ec8e Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 2 Aug 2026 16:12:37 +0000 Subject: [PATCH 65/71] kazumi: 2.2.3 -> 2.2.6 --- pkgs/by-name/ka/kazumi/git-hashes.json | 18 ++++----- pkgs/by-name/ka/kazumi/package.nix | 4 +- pkgs/by-name/ka/kazumi/pubspec.lock.json | 48 ++++++++++-------------- 3 files changed, 30 insertions(+), 40 deletions(-) diff --git a/pkgs/by-name/ka/kazumi/git-hashes.json b/pkgs/by-name/ka/kazumi/git-hashes.json index a3a5b15cdb07..500fc50fd9cc 100644 --- a/pkgs/by-name/ka/kazumi/git-hashes.json +++ b/pkgs/by-name/ka/kazumi/git-hashes.json @@ -2,14 +2,14 @@ "audio_service_mpris": "sha256-IVv1ioBpiK0VbnOFqnc9NbNn3Z+l9VN2clpCQjckBRo=", "audio_service_win": "sha256-OZq2waTr0WLJ6uki/VLdUBdDdui25PvXnMNFohs7gjs=", "desktop_webview_window": "sha256-KWON5aTPlVVrLidmnfpV+syWPYEngChOvkN7miIFjvE=", - "media_kit": "sha256-cKV7ST1egNdXLcsNTUcK7Xh/II72bl8cR3fJuf3/AyM=", - "media_kit_libs_android_video": "sha256-cKV7ST1egNdXLcsNTUcK7Xh/II72bl8cR3fJuf3/AyM=", - "media_kit_libs_ios_video": "sha256-cKV7ST1egNdXLcsNTUcK7Xh/II72bl8cR3fJuf3/AyM=", - "media_kit_libs_linux": "sha256-cKV7ST1egNdXLcsNTUcK7Xh/II72bl8cR3fJuf3/AyM=", - "media_kit_libs_macos_video": "sha256-cKV7ST1egNdXLcsNTUcK7Xh/II72bl8cR3fJuf3/AyM=", - "media_kit_libs_ohos": "sha256-cKV7ST1egNdXLcsNTUcK7Xh/II72bl8cR3fJuf3/AyM=", - "media_kit_libs_video": "sha256-cKV7ST1egNdXLcsNTUcK7Xh/II72bl8cR3fJuf3/AyM=", - "media_kit_libs_windows_video": "sha256-cKV7ST1egNdXLcsNTUcK7Xh/II72bl8cR3fJuf3/AyM=", - "media_kit_video": "sha256-cKV7ST1egNdXLcsNTUcK7Xh/II72bl8cR3fJuf3/AyM=", + "media_kit": "sha256-nM6WJalSotWWvpEvDxaNXynEIMNh2yj5MSn7lLLcJsA=", + "media_kit_libs_android_video": "sha256-nM6WJalSotWWvpEvDxaNXynEIMNh2yj5MSn7lLLcJsA=", + "media_kit_libs_ios_video": "sha256-nM6WJalSotWWvpEvDxaNXynEIMNh2yj5MSn7lLLcJsA=", + "media_kit_libs_linux": "sha256-nM6WJalSotWWvpEvDxaNXynEIMNh2yj5MSn7lLLcJsA=", + "media_kit_libs_macos_video": "sha256-nM6WJalSotWWvpEvDxaNXynEIMNh2yj5MSn7lLLcJsA=", + "media_kit_libs_ohos": "sha256-nM6WJalSotWWvpEvDxaNXynEIMNh2yj5MSn7lLLcJsA=", + "media_kit_libs_video": "sha256-nM6WJalSotWWvpEvDxaNXynEIMNh2yj5MSn7lLLcJsA=", + "media_kit_libs_windows_video": "sha256-nM6WJalSotWWvpEvDxaNXynEIMNh2yj5MSn7lLLcJsA=", + "media_kit_video": "sha256-nM6WJalSotWWvpEvDxaNXynEIMNh2yj5MSn7lLLcJsA=", "webview_windows": "sha256-afBTwbam9YA0xvIYMtiJe+CKi8GWit1HqDR3J72r2o0=" } diff --git a/pkgs/by-name/ka/kazumi/package.nix b/pkgs/by-name/ka/kazumi/package.nix index dd2628868ad3..b5efafdf28f5 100644 --- a/pkgs/by-name/ka/kazumi/package.nix +++ b/pkgs/by-name/ka/kazumi/package.nix @@ -20,13 +20,13 @@ }: let - version = "2.2.3"; + version = "2.2.6"; src = fetchFromGitHub { owner = "Predidit"; repo = "Kazumi"; tag = version; - hash = "sha256-CAc7KaTSYKy3UxLei8GPhDYbJURshChZoUhmFetBEuw="; + hash = "sha256-a2N9ucF+KNHmQ7hnL9GPOLYM4S9DEFlQ0I9mzLM5eEU="; }; in flutter.buildFlutterApplication { diff --git a/pkgs/by-name/ka/kazumi/pubspec.lock.json b/pkgs/by-name/ka/kazumi/pubspec.lock.json index d42d66e269c7..061ac7342793 100644 --- a/pkgs/by-name/ka/kazumi/pubspec.lock.json +++ b/pkgs/by-name/ka/kazumi/pubspec.lock.json @@ -262,16 +262,6 @@ "source": "hosted", "version": "0.3.1" }, - "card_settings_ui": { - "dependency": "direct main", - "description": { - "name": "card_settings_ui", - "sha256": "73670e4685d44fed8e9669e813153801825eea6f7a2845665e3a5a8631761e6c", - "url": "https://pub.dev" - }, - "source": "hosted", - "version": "2.0.1" - }, "characters": { "dependency": "transitive", "description": { @@ -1211,8 +1201,8 @@ "dependency": "direct main", "description": { "path": "media_kit", - "ref": "b11ec8050d1f07ca117022f2da3260281676346f", - "resolved-ref": "b11ec8050d1f07ca117022f2da3260281676346f", + "ref": "e3d51713f085068da32fb502ee65885547042661", + "resolved-ref": "e3d51713f085068da32fb502ee65885547042661", "url": "https://github.com/Predidit/media-kit.git" }, "source": "git", @@ -1222,8 +1212,8 @@ "dependency": "direct overridden", "description": { "path": "libs/android/media_kit_libs_android_video", - "ref": "b11ec8050d1f07ca117022f2da3260281676346f", - "resolved-ref": "b11ec8050d1f07ca117022f2da3260281676346f", + "ref": "e3d51713f085068da32fb502ee65885547042661", + "resolved-ref": "e3d51713f085068da32fb502ee65885547042661", "url": "https://github.com/Predidit/media-kit.git" }, "source": "git", @@ -1233,8 +1223,8 @@ "dependency": "direct overridden", "description": { "path": "libs/ios/media_kit_libs_ios_video", - "ref": "b11ec8050d1f07ca117022f2da3260281676346f", - "resolved-ref": "b11ec8050d1f07ca117022f2da3260281676346f", + "ref": "e3d51713f085068da32fb502ee65885547042661", + "resolved-ref": "e3d51713f085068da32fb502ee65885547042661", "url": "https://github.com/Predidit/media-kit.git" }, "source": "git", @@ -1244,8 +1234,8 @@ "dependency": "direct overridden", "description": { "path": "libs/linux/media_kit_libs_linux", - "ref": "b11ec8050d1f07ca117022f2da3260281676346f", - "resolved-ref": "b11ec8050d1f07ca117022f2da3260281676346f", + "ref": "e3d51713f085068da32fb502ee65885547042661", + "resolved-ref": "e3d51713f085068da32fb502ee65885547042661", "url": "https://github.com/Predidit/media-kit.git" }, "source": "git", @@ -1255,8 +1245,8 @@ "dependency": "direct overridden", "description": { "path": "libs/macos/media_kit_libs_macos_video", - "ref": "b11ec8050d1f07ca117022f2da3260281676346f", - "resolved-ref": "b11ec8050d1f07ca117022f2da3260281676346f", + "ref": "e3d51713f085068da32fb502ee65885547042661", + "resolved-ref": "e3d51713f085068da32fb502ee65885547042661", "url": "https://github.com/Predidit/media-kit.git" }, "source": "git", @@ -1266,8 +1256,8 @@ "dependency": "direct overridden", "description": { "path": "libs/ohos/media_kit_libs_ohos", - "ref": "b11ec8050d1f07ca117022f2da3260281676346f", - "resolved-ref": "b11ec8050d1f07ca117022f2da3260281676346f", + "ref": "e3d51713f085068da32fb502ee65885547042661", + "resolved-ref": "e3d51713f085068da32fb502ee65885547042661", "url": "https://github.com/Predidit/media-kit.git" }, "source": "git", @@ -1277,8 +1267,8 @@ "dependency": "direct main", "description": { "path": "libs/universal/media_kit_libs_video", - "ref": "b11ec8050d1f07ca117022f2da3260281676346f", - "resolved-ref": "b11ec8050d1f07ca117022f2da3260281676346f", + "ref": "e3d51713f085068da32fb502ee65885547042661", + "resolved-ref": "e3d51713f085068da32fb502ee65885547042661", "url": "https://github.com/Predidit/media-kit.git" }, "source": "git", @@ -1288,8 +1278,8 @@ "dependency": "direct overridden", "description": { "path": "libs/windows/media_kit_libs_windows_video", - "ref": "b11ec8050d1f07ca117022f2da3260281676346f", - "resolved-ref": "b11ec8050d1f07ca117022f2da3260281676346f", + "ref": "e3d51713f085068da32fb502ee65885547042661", + "resolved-ref": "e3d51713f085068da32fb502ee65885547042661", "url": "https://github.com/Predidit/media-kit.git" }, "source": "git", @@ -1299,8 +1289,8 @@ "dependency": "direct main", "description": { "path": "media_kit_video", - "ref": "b11ec8050d1f07ca117022f2da3260281676346f", - "resolved-ref": "b11ec8050d1f07ca117022f2da3260281676346f", + "ref": "e3d51713f085068da32fb502ee65885547042661", + "resolved-ref": "e3d51713f085068da32fb502ee65885547042661", "url": "https://github.com/Predidit/media-kit.git" }, "source": "git", @@ -2446,6 +2436,6 @@ }, "sdks": { "dart": ">=3.11.0 <4.0.0", - "flutter": ">=3.44.7" + "flutter": ">=3.44.8" } } From aa39d2aaa79eafddbd5b68429c44917c9ff29f32 Mon Sep 17 00:00:00 2001 From: Ben Siraphob Date: Fri, 10 Apr 2026 21:42:18 -0700 Subject: [PATCH 66/71] pike: restrict to x86_64-linux --- pkgs/by-name/pi/pike/package.nix | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/pi/pike/package.nix b/pkgs/by-name/pi/pike/package.nix index fa4ae9329258..1a89fdd100cd 100644 --- a/pkgs/by-name/pi/pike/package.nix +++ b/pkgs/by-name/pi/pike/package.nix @@ -113,7 +113,7 @@ let mpl20 ]; maintainers = with lib.maintainers; [ siraben ]; - platforms = with lib.platforms; unix ++ windows; + platforms = [ "x86_64-linux" ]; mainProgram = "pike"; }; }); @@ -208,7 +208,8 @@ stdenv.mkDerivation (finalAttrs: { mpl20 ]; maintainers = with lib.maintainers; [ siraben ]; - platforms = with lib.platforms; unix ++ windows; + # Bootstrap binary is only available for x86_64-linux + platforms = [ "x86_64-linux" ]; mainProgram = "pike"; }; }) From bd6a0be6fdad4b32682126bfbc5192e42de3fd5b Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Sun, 2 Aug 2026 12:10:12 +0200 Subject: [PATCH 67/71] nginxModules.lua-upstream: mark as broken Active, but broken on our side. If somebody cares, they should step up as maintainer. --- pkgs/servers/http/nginx/modules/lua-upstream/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/servers/http/nginx/modules/lua-upstream/package.nix b/pkgs/servers/http/nginx/modules/lua-upstream/package.nix index 5d2eaa351c44..02e24a2dae9d 100644 --- a/pkgs/servers/http/nginx/modules/lua-upstream/package.nix +++ b/pkgs/servers/http/nginx/modules/lua-upstream/package.nix @@ -26,5 +26,6 @@ mkNginxPlugin (finalAttrs: { homepage = "https://github.com/openresty/lua-upstream-nginx-module"; license = lib.licenses.bsd2; maintainers = [ ]; + broken = true; # Build against nginx fails }; }) From 25988867542449ea009e00fc51553a2090b4c732 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Sun, 2 Aug 2026 12:11:42 +0200 Subject: [PATCH 68/71] nginxModules.aws-auth: mark as broken --- pkgs/servers/http/nginx/modules/aws-auth/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/servers/http/nginx/modules/aws-auth/package.nix b/pkgs/servers/http/nginx/modules/aws-auth/package.nix index 5499a506a3b8..5de4483c87c4 100644 --- a/pkgs/servers/http/nginx/modules/aws-auth/package.nix +++ b/pkgs/servers/http/nginx/modules/aws-auth/package.nix @@ -20,5 +20,6 @@ mkNginxPlugin (finalAttrs: { homepage = "https://github.com/anomalizer/ngx_aws_auth"; license = lib.licenses.bsd2; maintainers = [ ]; + broken = true; }; }) From 436ee95f2c7f845e917ee91daa6b0ed3d7b41593 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Sun, 2 Aug 2026 12:12:05 +0200 Subject: [PATCH 69/71] nginxModules.push-stream: mark as broken --- pkgs/servers/http/nginx/modules/push-stream/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/servers/http/nginx/modules/push-stream/package.nix b/pkgs/servers/http/nginx/modules/push-stream/package.nix index 8d9df1b59130..49ec6a5c661f 100644 --- a/pkgs/servers/http/nginx/modules/push-stream/package.nix +++ b/pkgs/servers/http/nginx/modules/push-stream/package.nix @@ -20,5 +20,6 @@ mkNginxPlugin (finalAttrs: { homepage = "https://github.com/wandenberg/nginx-push-stream-module"; license = lib.licenses.gpl3; maintainers = [ ]; + broken = true; }; }) From 3dd00f8ea070ecfb124277b5a9172a46184d68aa Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Sun, 2 Aug 2026 12:12:23 +0200 Subject: [PATCH 70/71] nginxModules.video-thumbextractor: mark as broken --- pkgs/servers/http/nginx/modules/video-thumbextractor/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/servers/http/nginx/modules/video-thumbextractor/package.nix b/pkgs/servers/http/nginx/modules/video-thumbextractor/package.nix index 54070a0ea7e0..90e4822ab46a 100644 --- a/pkgs/servers/http/nginx/modules/video-thumbextractor/package.nix +++ b/pkgs/servers/http/nginx/modules/video-thumbextractor/package.nix @@ -27,5 +27,6 @@ mkNginxPlugin (finalAttrs: { homepage = "https://github.com/wandenberg/nginx-video-thumbextractor-module"; license = lib.licenses.gpl3; maintainers = [ ]; + broken = true; }; }) From ef3a9736aa216af5ecb0c9119ee7c284bc0b568c Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Sun, 2 Aug 2026 14:26:37 +0200 Subject: [PATCH 71/71] nixos/nextcloud: add test verifying that bind-mounts and special places of /var/lib/nextcloud are OK This is a regular source for confusion and had no test-coverage so far, so adding two tests that * Make sure Nextcloud running in a different location (tmpfs mount here as mock for the mount of a different disk). * A bind-mount of Nextcloud from a disk-mount to /var/lib/nextcloud can be created. --- nixos/tests/nextcloud/default.nix | 2 + nixos/tests/nextcloud/home-bindmount.nix | 68 ++++++++++++++++++++++++ nixos/tests/nextcloud/home-mount.nix | 32 +++++++++++ 3 files changed, 102 insertions(+) create mode 100644 nixos/tests/nextcloud/home-bindmount.nix create mode 100644 nixos/tests/nextcloud/home-mount.nix diff --git a/nixos/tests/nextcloud/default.nix b/nixos/tests/nextcloud/default.nix index 2cb226e353da..6c7ef18068e7 100644 --- a/nixos/tests/nextcloud/default.nix +++ b/nixos/tests/nextcloud/default.nix @@ -136,6 +136,8 @@ let map callNextcloudTest ( [ ./basic.nix + ./home-bindmount.nix + ./home-mount.nix ./with-declarative-redis-and-secrets.nix ./with-mysql-and-memcached.nix ./with-postgresql-and-redis.nix diff --git a/nixos/tests/nextcloud/home-bindmount.nix b/nixos/tests/nextcloud/home-bindmount.nix new file mode 100644 index 000000000000..a48882544508 --- /dev/null +++ b/nixos/tests/nextcloud/home-bindmount.nix @@ -0,0 +1,68 @@ +{ + name, + pkgs, + testBase, + system, + ... +}: + +with import ../../lib/testing-python.nix { inherit system pkgs; }; +runTest ( + { lib, ... }: + { + inherit name; + meta.maintainers = lib.teams.nextcloud.members; + + imports = [ testBase ]; + + nodes.nextcloud = { pkgs, ... }: { + # Make sure that inside our tmpfs mount an actual directory for Nextcloud exists. + boot.initrd.systemd.tmpfiles.settings."nextcloud"."/sysroot/mnt/nextcloud".d = { }; + + boot.initrd.systemd.mounts = [ + # Create a mocked /mnt/nextcloud. Only a tmpfs here, but in reality this could e.g. + # be the mount of a larger disk. + { + unitConfig.DefaultDependencies = "no"; + conflicts = [ "umount.target" ]; + wantedBy = [ "initrd.target" ]; + before = [ "systemd-tmpfiles-setup-sysroot.service" ]; + options = "x-initrd.mount"; + where = "/sysroot/mnt"; + what = "tmpfs"; + type = "tmpfs"; + } + # Bind some directory to /var/lib/nextcloud, the place that the Nextcloud module expects + # by default. + { + conflicts = [ "umount.target" ]; + wantedBy = [ "initrd.target" ]; + before = [ "systemd-tmpfiles-setup-sysroot.service" ]; + options = "x-initrd.mount,bind"; + where = "/sysroot/var/lib/nextcloud"; + what = "/sysroot/mnt/nextcloud"; + type = "none"; + } + ]; + environment.systemPackages = [ + pkgs.util-linux + ]; + services.nextcloud = { + config.dbtype = "sqlite"; + }; + }; + + test-helpers.init = '' + import json + mnts = json.loads(nextcloud.succeed("findmnt /var/lib/nextcloud -J"))["filesystems"] + t.assertEqual(1, len(mnts)) + mnt = mnts[0] + t.assertEqual("tmpfs[/nextcloud]", mnt["source"]) + t.assertEqual("/var/lib/nextcloud", mnt["target"]) + ''; + + test-helpers.extraTests = '' + nextcloud.succeed("test -d /mnt/nextcloud/data/root") + ''; + } +) diff --git a/nixos/tests/nextcloud/home-mount.nix b/nixos/tests/nextcloud/home-mount.nix new file mode 100644 index 000000000000..a79f2fdd97b3 --- /dev/null +++ b/nixos/tests/nextcloud/home-mount.nix @@ -0,0 +1,32 @@ +{ + name, + pkgs, + testBase, + system, + ... +}: + +with import ../../lib/testing-python.nix { inherit system pkgs; }; +runTest ( + { config, lib, ... }: + { + inherit name; + meta.maintainers = lib.teams.nextcloud.members; + + imports = [ testBase ]; + + nodes.nextcloud = { pkgs, ... }: { + system.activationScripts.nc-mock-mount = { + deps = [ "users" ]; + text = '' + ${pkgs.coreutils}/bin/mkdir -p /mnt + ${pkgs.util-linux}/bin/mount -t tmpfs tmpfs /mnt + ''; + }; + services.nextcloud = { + config.dbtype = "sqlite"; + home = "/mnt/nextcloud"; + }; + }; + } +)