From de11c51abef3bc644abadbe4db6679fbab965366 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 10 Aug 2026 14:45:26 +0000 Subject: [PATCH 001/140] rapidcheck: 0-unstable-2023-12-14 -> 0-unstable-2026-08-06 --- pkgs/by-name/ra/rapidcheck/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ra/rapidcheck/package.nix b/pkgs/by-name/ra/rapidcheck/package.nix index 880630fa6bd6..9a7830a18f4e 100644 --- a/pkgs/by-name/ra/rapidcheck/package.nix +++ b/pkgs/by-name/ra/rapidcheck/package.nix @@ -9,13 +9,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "rapidcheck"; - version = "0-unstable-2023-12-14"; + version = "0-unstable-2026-08-06"; src = fetchFromGitHub { owner = "emil-e"; repo = "rapidcheck"; - rev = "ff6af6fc683159deb51c543b065eba14dfcf329b"; - hash = "sha256-Ixz5RpY0n8Un/Pv4XoTfbs40+70iyMbkQUjDqoLaWOg="; + rev = "6e8dadfdafa3a74eabb52ead87f8787f72eccd0b"; + hash = "sha256-AOHG06EVsOOdvyOohP5hsFuEe7yfXuvkEgFHQUVUs0w="; }; outputs = [ From b9d6aebf85f0e2212e3c1a0ef852bd498e1b9e05 Mon Sep 17 00:00:00 2001 From: Nick Cao Date: Thu, 6 Aug 2026 13:03:08 -0400 Subject: [PATCH 002/140] telegram-desktop.tg_owt: 0-unstable-2026-04-09 -> 0-unstable-2026-08-03 Diff: https://github.com/desktop-app/tg_owt/compare/89df288dd6ba5b2ec95b3c5eaf1e7e0c3a870fc4...19d51d3c19632a63fdbe17c62f10332d978cb940 --- .../instant-messengers/telegram/telegram-desktop/tg_owt.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/applications/networking/instant-messengers/telegram/telegram-desktop/tg_owt.nix b/pkgs/applications/networking/instant-messengers/telegram/telegram-desktop/tg_owt.nix index 73038a5e3242..48752b669300 100644 --- a/pkgs/applications/networking/instant-messengers/telegram/telegram-desktop/tg_owt.nix +++ b/pkgs/applications/networking/instant-messengers/telegram/telegram-desktop/tg_owt.nix @@ -33,13 +33,13 @@ stdenv.mkDerivation { pname = "tg_owt"; - version = "0-unstable-2026-04-09"; + version = "0-unstable-2026-08-03"; src = fetchFromGitHub { owner = "desktop-app"; repo = "tg_owt"; - rev = "89df288dd6ba5b2ec95b3c5eaf1e7e0c3a870fc4"; - hash = "sha256-wdO3AACCEN3IDYWt5a+f7zrcPFoqz+c7vLpo6LZk29w="; + rev = "19d51d3c19632a63fdbe17c62f10332d978cb940"; + hash = "sha256-Cb1XWnryZEKTyvhBeOsYX5KZG88zUOAlSRhfyIh06g4="; fetchSubmodules = true; }; From cebce1bc4b1c747a601320edc3e80f5b8ef9905e Mon Sep 17 00:00:00 2001 From: Nick Cao Date: Thu, 6 Aug 2026 13:01:29 -0400 Subject: [PATCH 003/140] telegram-desktop: 7.0.2 -> 7.0.9 Diff: https://github.com/telegramdesktop/tdesktop/compare/v7.0.2...v7.0.9 Changelog: https://github.com/telegramdesktop/tdesktop/releases/tag/v7.0.9 --- .../telegram/telegram-desktop/unwrapped.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/networking/instant-messengers/telegram/telegram-desktop/unwrapped.nix b/pkgs/applications/networking/instant-messengers/telegram/telegram-desktop/unwrapped.nix index e744ee618380..dbe653a7fb0a 100644 --- a/pkgs/applications/networking/instant-messengers/telegram/telegram-desktop/unwrapped.nix +++ b/pkgs/applications/networking/instant-messengers/telegram/telegram-desktop/unwrapped.nix @@ -46,14 +46,14 @@ stdenv.mkDerivation (finalAttrs: { pname = "telegram-desktop-unwrapped"; - version = "7.0.2"; + version = "7.0.9"; src = fetchFromGitHub { owner = "telegramdesktop"; repo = "tdesktop"; rev = "v${finalAttrs.version}"; fetchSubmodules = true; - hash = "sha256-G/A5J2m1sXHD50zDmMD9ehnorAGRjnQ+YGMv6DEiJcQ="; + hash = "sha256-zpGfubIZtTmLjAgxYGcMy2N3Xlf9NOppcxsMSUS/KEA="; }; nativeBuildInputs = [ From 6dd92175515cf16dc8652565dce1ff1855c197a6 Mon Sep 17 00:00:00 2001 From: Nick Cao Date: Thu, 6 Aug 2026 13:03:59 -0400 Subject: [PATCH 004/140] _64gram: 1.2.5 -> 1.2.6 Diff: https://github.com/TDesktop-x64/tdesktop/compare/v1.2.5...v1.2.6 Changelog: https://github.com/TDesktop-x64/tdesktop/releases/tag/v1.2.6 --- pkgs/by-name/_6/_64gram/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/_6/_64gram/package.nix b/pkgs/by-name/_6/_64gram/package.nix index c87d829cb39d..8471eae19165 100644 --- a/pkgs/by-name/_6/_64gram/package.nix +++ b/pkgs/by-name/_6/_64gram/package.nix @@ -10,13 +10,13 @@ telegram-desktop.override { inherit withWebkit; unwrapped = telegram-desktop.unwrapped.overrideAttrs (old: rec { pname = "64gram-unwrapped"; - version = "1.2.5"; + version = "1.2.6"; src = fetchFromGitHub { owner = "TDesktop-x64"; repo = "tdesktop"; tag = "v${version}"; - hash = "sha256-CcYcdSgeVEbGKOzim+Q/gIxMIfDGaSStF4cLLttA+SM="; + hash = "sha256-BMNoAYwvkh4L81/cI/AeyXQjCqiygjiXpOOOgBUmhPY="; fetchSubmodules = true; }; From b33844c3f24cfa1e40308b4b9275a1bbbf840602 Mon Sep 17 00:00:00 2001 From: Nick Cao Date: Tue, 11 Aug 2026 18:58:53 -0400 Subject: [PATCH 005/140] _64gram: 1.2.6 -> 1.2.7 Diff: https://github.com/TDesktop-x64/tdesktop/compare/v1.2.6...v1.2.7 Changelog: https://github.com/TDesktop-x64/tdesktop/releases/tag/v1.2.7 --- pkgs/by-name/_6/_64gram/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/_6/_64gram/package.nix b/pkgs/by-name/_6/_64gram/package.nix index 8471eae19165..f84ed1e536a1 100644 --- a/pkgs/by-name/_6/_64gram/package.nix +++ b/pkgs/by-name/_6/_64gram/package.nix @@ -10,13 +10,13 @@ telegram-desktop.override { inherit withWebkit; unwrapped = telegram-desktop.unwrapped.overrideAttrs (old: rec { pname = "64gram-unwrapped"; - version = "1.2.6"; + version = "1.2.7"; src = fetchFromGitHub { owner = "TDesktop-x64"; repo = "tdesktop"; tag = "v${version}"; - hash = "sha256-BMNoAYwvkh4L81/cI/AeyXQjCqiygjiXpOOOgBUmhPY="; + hash = "sha256-5Ovx/71wf0SV4RUwEmIvf1Q686AZ5WPxn9WlgklAMf4="; fetchSubmodules = true; }; From 6c35b72eb621b3d4cb068f866fb82e560c50f06a Mon Sep 17 00:00:00 2001 From: Nick Cao Date: Thu, 6 Aug 2026 13:05:04 -0400 Subject: [PATCH 006/140] materialgram: 6.7.7.1 -> 7.0.5.1 Diff: https://github.com/kukuruzka165/materialgram/compare/v6.7.7.1...v7.0.5.1 Changelog: https://github.com/kukuruzka165/materialgram/releases/tag/v7.0.5.1 --- pkgs/by-name/ma/materialgram/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ma/materialgram/package.nix b/pkgs/by-name/ma/materialgram/package.nix index d63199543aac..36642598b45d 100644 --- a/pkgs/by-name/ma/materialgram/package.nix +++ b/pkgs/by-name/ma/materialgram/package.nix @@ -11,12 +11,12 @@ telegram-desktop.override { unwrapped = telegram-desktop.unwrapped.overrideAttrs ( finalAttrs: previousAttrs: { pname = "materialgram-unwrapped"; - version = "6.7.7.1"; + version = "7.0.5.1"; src = fetchFromGitHub { owner = "kukuruzka165"; repo = "materialgram"; - hash = "sha256-Cy0ooQZOhfE+QBaRDblKXhmqYsKJ0TfeHsfJaVLVn8o="; + hash = "sha256-OE7TbxFEYzTM2IB7HMokR3a+tsrg4n4cbHmRXPITykI="; tag = "v${finalAttrs.version}"; fetchSubmodules = true; }; From 497aaf86df1757e24b1641b8e4e14c8f24a716f0 Mon Sep 17 00:00:00 2001 From: Nick Cao Date: Thu, 6 Aug 2026 13:06:05 -0400 Subject: [PATCH 007/140] telegram-desktop: build with default ffmpeg --- .../telegram/telegram-desktop/unwrapped.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/networking/instant-messengers/telegram/telegram-desktop/unwrapped.nix b/pkgs/applications/networking/instant-messengers/telegram/telegram-desktop/unwrapped.nix index dbe653a7fb0a..9a63c2fa457a 100644 --- a/pkgs/applications/networking/instant-messengers/telegram/telegram-desktop/unwrapped.nix +++ b/pkgs/applications/networking/instant-messengers/telegram/telegram-desktop/unwrapped.nix @@ -16,7 +16,7 @@ kcoreaddons, lz4, xxhash, - ffmpeg_6, + ffmpeg, protobuf, openal-soft, minizip-ng-compat, @@ -72,7 +72,7 @@ stdenv.mkDerivation (finalAttrs: { qtsvg lz4 xxhash - ffmpeg_6 + ffmpeg openal-soft minizip-ng-compat range-v3 From 66104fad19feabe258052c64bf345b45f9746a8c Mon Sep 17 00:00:00 2001 From: Nick Cao Date: Tue, 11 Aug 2026 19:00:47 -0400 Subject: [PATCH 008/140] telegram-desktop: use system libfido2 --- .../instant-messengers/telegram/telegram-desktop/unwrapped.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/applications/networking/instant-messengers/telegram/telegram-desktop/unwrapped.nix b/pkgs/applications/networking/instant-messengers/telegram/telegram-desktop/unwrapped.nix index 9a63c2fa457a..55d16f978c84 100644 --- a/pkgs/applications/networking/instant-messengers/telegram/telegram-desktop/unwrapped.nix +++ b/pkgs/applications/networking/instant-messengers/telegram/telegram-desktop/unwrapped.nix @@ -29,6 +29,7 @@ boost, ada, cmark-gfm, + libfido2, libavif, libheif, libjxl, @@ -83,6 +84,7 @@ stdenv.mkDerivation (finalAttrs: { boost ada cmark-gfm + libfido2 (tdlib.override { tde2eOnly = true; }) ] ++ lib.optionals stdenv.hostPlatform.isLinux [ From 5280777ebaaac11421eebf801a564a3cba31a696 Mon Sep 17 00:00:00 2001 From: hustlerone Date: Sat, 17 Jan 2026 19:30:22 +0100 Subject: [PATCH 009/140] grub2: 2.12 -> 2.14 Co-Authored-By: OPNA2608 Co-Authored-By: azban --- nixos/tests/grub/basic.nix | 2 +- .../gr/grub2/add-hidden-menu-entries.patch | 114 +++- .../gr/grub2/bootstrap-po-downloads.patch | 13 + pkgs/by-name/gr/grub2/package.nix | 610 +++--------------- 4 files changed, 191 insertions(+), 548 deletions(-) create mode 100644 pkgs/by-name/gr/grub2/bootstrap-po-downloads.patch diff --git a/nixos/tests/grub/basic.nix b/nixos/tests/grub/basic.nix index 4221eec73049..697681b1dc45 100644 --- a/nixos/tests/grub/basic.nix +++ b/nixos/tests/grub/basic.nix @@ -49,7 +49,7 @@ grub_select_all_configurations() with subtest("Invalid credentials are rejected"): grub_login_as("wronguser", "wrongsecret") - machine.wait_for_console_text("error: access denied.") + machine.wait_for_console_text("access denied") grub_select_all_configurations() with subtest("Valid credentials are accepted"): diff --git a/pkgs/by-name/gr/grub2/add-hidden-menu-entries.patch b/pkgs/by-name/gr/grub2/add-hidden-menu-entries.patch index 836a9853708f..3c3189693d3a 100644 --- a/pkgs/by-name/gr/grub2/add-hidden-menu-entries.patch +++ b/pkgs/by-name/gr/grub2/add-hidden-menu-entries.patch @@ -1,42 +1,86 @@ +From dc1b837925f7c2ee6663cf34bbd982e0b368d811 Mon Sep 17 00:00:00 2001 +From: hustlerone +Date: Sun, 18 Jan 2026 11:57:36 +0100 +Subject: [PATCH] Add hidden menu entries + +Merge conflicts manually resolved. + +https://lists.gnu.org/archive/html/grub-devel/2016-04/msg00089.html +https://marc.info/?l=grub-devel&m=146193404929072&w=2 + +Vendored in: +https://build.opensuse.org/projects/openSUSE:Factory/packages/grub2/files/grub2-Add-hidden-menu-entries.patch?expand=1 +--- + grub-core/commands/blsuki.c | 4 ++-- + grub-core/commands/legacycfg.c | 4 ++-- + grub-core/commands/menuentry.c | 22 +++++++++++++++++----- + grub-core/normal/menu.c | 30 ++++++++++++++++++++++++++---- + grub-core/normal/menu_text.c | 6 +++++- + include/grub/menu.h | 2 ++ + include/grub/normal.h | 2 +- + 7 files changed, 55 insertions(+), 15 deletions(-) + +diff --git a/grub-core/commands/blsuki.c b/grub-core/commands/blsuki.c +index 4133d3111..26055f91f 100644 +--- a/grub-core/commands/blsuki.c ++++ b/grub-core/commands/blsuki.c +@@ -1022,7 +1022,7 @@ bls_create_entry (grub_blsuki_entry_t *entry) + linux_cmd, initrd_cmd ? initrd_cmd : "", + dt_cmd ? dt_cmd : ""); + +- grub_normal_add_menu_entry (argc, argv, classes, id, users, hotkey, NULL, src, 0, entry); ++ grub_normal_add_menu_entry (argc, argv, classes, id, users, hotkey, NULL, src, 0, entry, 0); + + finish: + grub_free (linux_cmd); +@@ -1088,7 +1088,7 @@ uki_create_entry (grub_blsuki_entry_t *entry) + (options != NULL) ? " " : "", + (options != NULL) ? options : ""); + +- grub_normal_add_menu_entry (1, argv, NULL, id, NULL, NULL, NULL, src, 0, entry); ++ grub_normal_add_menu_entry (1, argv, NULL, id, NULL, NULL, NULL, src, 0, entry, 0); + + finish: + grub_free (argv); diff --git a/grub-core/commands/legacycfg.c b/grub-core/commands/legacycfg.c -index e9e9d94ef..54e08a1b4 100644 +index 7d9f9eb3c..bb5b7b3ad 100644 --- a/grub-core/commands/legacycfg.c +++ b/grub-core/commands/legacycfg.c @@ -143,7 +143,7 @@ legacy_file (const char *filename) args[0] = oldname; grub_normal_add_menu_entry (1, args, NULL, NULL, "legacy", NULL, NULL, -- entrysrc, 0); -+ entrysrc, 0, 0); +- entrysrc, 0, NULL); ++ entrysrc, 0, NULL, 0); grub_free (args); entrysrc[0] = 0; grub_free (oldname); -@@ -205,7 +205,7 @@ legacy_file (const char *filename) +@@ -204,7 +204,7 @@ legacy_file (const char *filename) } args[0] = entryname; grub_normal_add_menu_entry (1, args, NULL, NULL, NULL, -- NULL, NULL, entrysrc, 0); -+ NULL, NULL, entrysrc, 0, 0); +- NULL, NULL, entrysrc, 0, NULL); ++ NULL, NULL, entrysrc, 0, NULL, 0); grub_free (args); } diff --git a/grub-core/commands/menuentry.c b/grub-core/commands/menuentry.c -index 720e6d8ea..50632ccce 100644 +index 5e1318f17..288189b8d 100644 --- a/grub-core/commands/menuentry.c +++ b/grub-core/commands/menuentry.c @@ -78,7 +78,7 @@ grub_normal_add_menu_entry (int argc, const char **args, char **classes, const char *id, const char *users, const char *hotkey, const char *prefix, const char *sourcecode, -- int submenu) -+ int submenu, int hidden) +- int submenu, grub_blsuki_entry_t *blsuki) ++ int submenu, grub_blsuki_entry_t *blsuki, int hidden) { int menu_hotkey = 0; char **menu_args = NULL; -@@ -188,8 +188,11 @@ grub_normal_add_menu_entry (int argc, const char **args, - (*last)->args = menu_args; +@@ -189,8 +189,11 @@ grub_normal_add_menu_entry (int argc, const char **args, (*last)->sourcecode = menu_sourcecode; (*last)->submenu = submenu; + (*last)->blsuki = blsuki; + (*last)->hidden = hidden; + + if (!hidden) @@ -46,27 +90,28 @@ index 720e6d8ea..50632ccce 100644 return GRUB_ERR_NONE; fail: -@@ -286,7 +289,8 @@ grub_cmd_menuentry (grub_extcmd_context_t ctxt, int argc, char **args) - users, +@@ -291,7 +294,8 @@ grub_cmd_menuentry (grub_extcmd_context_t ctxt, int argc, char **args) ctxt->state[2].arg, 0, ctxt->state[3].arg, -- ctxt->extcmd->cmd->name[0] == 's'); -+ ctxt->extcmd->cmd->name[0] == 's', + ctxt->extcmd->cmd->name[0] == 's', +- NULL); ++ NULL, + ctxt->extcmd->cmd->name[0] == 'h'); src = args[argc - 1]; args[argc - 1] = NULL; -@@ -303,7 +307,8 @@ grub_cmd_menuentry (grub_extcmd_context_t ctxt, int argc, char **args) +@@ -308,7 +312,9 @@ grub_cmd_menuentry (grub_extcmd_context_t ctxt, int argc, char **args) ctxt->state[0].args, ctxt->state[4].arg, users, ctxt->state[2].arg, prefix, src + 1, -- ctxt->extcmd->cmd->name[0] == 's'); +- ctxt->extcmd->cmd->name[0] == 's', NULL); + ctxt->extcmd->cmd->name[0] == 's', ++ NULL, + ctxt->extcmd->cmd->name[0] == 'h'); src[len - 1] = ch; args[argc - 1] = src; -@@ -311,7 +316,7 @@ grub_cmd_menuentry (grub_extcmd_context_t ctxt, int argc, char **args) +@@ -316,7 +322,7 @@ grub_cmd_menuentry (grub_extcmd_context_t ctxt, int argc, char **args) return r; } @@ -75,7 +120,7 @@ index 720e6d8ea..50632ccce 100644 void grub_menu_init (void) -@@ -327,6 +332,12 @@ grub_menu_init (void) +@@ -332,6 +338,12 @@ grub_menu_init (void) | GRUB_COMMAND_FLAG_EXTRACTOR, N_("BLOCK"), N_("Define a submenu."), options); @@ -89,10 +134,10 @@ index 720e6d8ea..50632ccce 100644 void diff --git a/grub-core/normal/menu.c b/grub-core/normal/menu.c -index 6a90e091f..4236f55bc 100644 +index b946c834d..483a3505c 100644 --- a/grub-core/normal/menu.c +++ b/grub-core/normal/menu.c -@@ -37,6 +37,8 @@ +@@ -38,6 +38,8 @@ entry failing to boot. */ #define DEFAULT_ENTRY_ERROR_DELAY_MS 2500 @@ -101,7 +146,7 @@ index 6a90e091f..4236f55bc 100644 grub_err_t (*grub_gfxmenu_try_hook) (int entry, grub_menu_t menu, int nested) = NULL; -@@ -80,8 +82,20 @@ grub_menu_get_entry (grub_menu_t menu, int no) +@@ -81,8 +83,20 @@ grub_menu_get_entry (grub_menu_t menu, int no) { grub_menu_entry_t e; @@ -124,7 +169,7 @@ index 6a90e091f..4236f55bc 100644 return e; } -@@ -93,10 +107,10 @@ get_entry_index_by_hotkey (grub_menu_t menu, int hotkey) +@@ -94,10 +108,10 @@ get_entry_index_by_hotkey (grub_menu_t menu, int hotkey) grub_menu_entry_t entry; int i; @@ -137,7 +182,7 @@ index 6a90e091f..4236f55bc 100644 return -1; } -@@ -509,6 +523,10 @@ get_entry_number (grub_menu_t menu, const char *name) +@@ -510,6 +524,10 @@ get_entry_number (grub_menu_t menu, const char *name) grub_menu_entry_t e = menu->entry_list; int i; @@ -148,7 +193,7 @@ index 6a90e091f..4236f55bc 100644 grub_errno = GRUB_ERR_NONE; for (i = 0; e; i++) -@@ -520,6 +538,10 @@ get_entry_number (grub_menu_t menu, const char *name) +@@ -521,6 +539,10 @@ get_entry_number (grub_menu_t menu, const char *name) break; } e = e->next; @@ -160,10 +205,10 @@ index 6a90e091f..4236f55bc 100644 if (! e) diff --git a/grub-core/normal/menu_text.c b/grub-core/normal/menu_text.c -index b1321eb26..d2e46cac8 100644 +index 9c383e64a..e55bafa6c 100644 --- a/grub-core/normal/menu_text.c +++ b/grub-core/normal/menu_text.c -@@ -289,7 +289,11 @@ print_entries (grub_menu_t menu, const struct menu_viewer_data *data) +@@ -292,7 +292,11 @@ print_entries (grub_menu_t menu, const struct menu_viewer_data *data) print_entry (data->geo.first_entry_y + i, data->offset == i, e, data); if (e) @@ -177,10 +222,10 @@ index b1321eb26..d2e46cac8 100644 grub_term_gotoxy (data->term, diff --git a/include/grub/menu.h b/include/grub/menu.h -index ee2b5e910..eb8a86ba9 100644 +index 8d06e8400..f7a302081 100644 --- a/include/grub/menu.h +++ b/include/grub/menu.h -@@ -58,6 +58,8 @@ struct grub_menu_entry +@@ -72,6 +72,8 @@ struct grub_menu_entry int submenu; @@ -188,17 +233,20 @@ index ee2b5e910..eb8a86ba9 100644 + /* The next element. */ struct grub_menu_entry *next; - }; + diff --git a/include/grub/normal.h b/include/grub/normal.h -index 218cbabcc..bcb412466 100644 +index d0150e3c2..4c1fe8ec1 100644 --- a/include/grub/normal.h +++ b/include/grub/normal.h @@ -145,7 +145,7 @@ grub_normal_add_menu_entry (int argc, const char **args, char **classes, const char *id, const char *users, const char *hotkey, const char *prefix, const char *sourcecode, -- int submenu); -+ int submenu, int hidden); +- int submenu, grub_blsuki_entry_t *blsuki); ++ int submenu, grub_blsuki_entry_t *blsuki, int hidden); grub_err_t grub_normal_set_password (const char *user, const char *password); +-- +2.51.2 + diff --git a/pkgs/by-name/gr/grub2/bootstrap-po-downloads.patch b/pkgs/by-name/gr/grub2/bootstrap-po-downloads.patch new file mode 100644 index 000000000000..521f44fb308a --- /dev/null +++ b/pkgs/by-name/gr/grub2/bootstrap-po-downloads.patch @@ -0,0 +1,13 @@ +diff --git a/bootstrap b/bootstrap +index dc9fb4383..5d0e90a92 100755 +--- a/bootstrap ++++ b/bootstrap +@@ -931,7 +931,7 @@ update_po_files() { + # Usually contains *.s1 checksum files. + ref_po_dir="$po_dir/.reference" + +- test -d $ref_po_dir || mkdir $ref_po_dir || return ++ test -d $ref_po_dir && return || mkdir $ref_po_dir + download_po_files $ref_po_dir $domain \ + && ls "$ref_po_dir"/*.po 2>/dev/null | + sed 's|.*/||; s|\.po$||' > "$po_dir/LINGUAS" || return diff --git a/pkgs/by-name/gr/grub2/package.nix b/pkgs/by-name/gr/grub2/package.nix index 0c8a57992686..0333b5c44a69 100644 --- a/pkgs/by-name/gr/grub2/package.nix +++ b/pkgs/by-name/gr/grub2/package.nix @@ -1,12 +1,15 @@ { lib, stdenv, + fetchurl, fetchgit, flex, bison, python3, autoconf, + autoconf-archive, automake, + autoreconfHook, libtool, bash, gettext, @@ -23,6 +26,7 @@ buildPackages, nixosTests, fuse3, # only needed for grub-mount + xz, # for xz compression support. Usually counterproductive, so don't try to force compression in your GRUB install. runtimeShell, zfs ? null, efiSupport ? false, @@ -30,7 +34,8 @@ zfsSupport ? false, xenSupport ? false, xenPvhSupport ? false, - kbdcompSupport ? false, + corebootSupport ? false, + kbdcompSupport ? corebootSupport, ckbcomp, }: @@ -81,7 +86,7 @@ let gnulib = fetchgit { url = "https://git.savannah.gnu.org/git/gnulib.git"; - # NOTE: keep in sync with bootstrap.conf! + # NOTE: get $GNULIB_REVISION from bootstrap.conf! rev = "9f48fb992a3d7e96610c4ce8be969cff2d61a01b"; hash = "sha256-mzbF66SNqcSlI+xmjpKpNMwzi13yEWoc1Fl7p4snTto="; }; @@ -90,9 +95,12 @@ let # but those translations are not versioned/stable. For that reason # we take them from the nearest release tarball instead: locales = fetchzip { - url = "https://ftp.gnu.org/gnu/grub/grub-2.12.tar.gz"; - hash = "sha256-IoRiJHNQ58y0UhCAD0CrpFiI8Mz1upzAtyh5K4Njh/w="; + url = "https://ftp.gnu.org/gnu/grub/grub-${version}.tar.gz"; + hash = "sha256-NUlE6l8Ul3i1Si9mZgND6lnvFqc74EGptHV2iCtu+As="; }; + + # This is the variable that sets the GRUB release. + version = "2.14"; in assert zfsSupport -> zfs != null; @@ -103,485 +111,57 @@ assert lib.asserts.assertMsg ( ieee1275Support xenSupport xenPvhSupport + corebootSupport ] ) <= 1 # (0 == pc) ) "Only <= 1 of grub2's platform-related *Support options may be enabled at the same time"; stdenv.mkDerivation rec { pname = "grub"; - version = "2.12"; + inherit version; src = fetchgit { url = "https://git.savannah.gnu.org/git/grub.git"; tag = "grub-${version}"; - hash = "sha256-lathsBb2f7urh8R86ihpTdwo3h1hAHnRiHd5gCLVpBc="; + hash = "sha256-Gkpde5CeJOQ+0p5WGwXZ2P881jxrWkuFw3Fh4lul/so="; }; patches = [ ./fix-bash-completion.patch ./add-hidden-menu-entries.patch + ./bootstrap-po-downloads.patch - # https://lists.gnu.org/archive/html/grub-devel/2025-02/msg00024.html - (fetchpatch { - name = "01_implement_grub_strlcpy.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=ea703528a8581a2ea7e0bad424a70fdf0aec7d8f"; - hash = "sha256-MSMgu1vMG83HRImUUsTyA1YQaIhgEreGGPd+ZDWSI2I="; - }) - (fetchpatch { - name = "02_CVE-2024-45781.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=c1a291b01f4f1dcd6a22b61f1c81a45a966d16ba"; - hash = "sha256-q8ErK+cQzaqwSuhLRFL3AfYBkpgJq1IQmadnlmlz2yw="; - }) - (fetchpatch { - name = "03_CVE-2024-45782_CVE-2024-56737.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=417547c10410b714e43f08f74137c24015f8f4c3"; - hash = "sha256-mRinw27WZ2d1grzyzFGO18yXx72UVBM6Lf5cR8XJfs8="; - }) - (fetchpatch { - name = "04_fs_tar_initialize_name_in_grub_cpio_find_file.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=2c8ac08c99466c0697f704242363fc687f492a0d"; - hash = "sha256-EMGF0B+Fw6tSmllWUJAp1ynzWk+w2C/XM1LmXSReHWg="; - }) - (fetchpatch { - name = "05_CVE-2024-45780.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=0087bc6902182fe5cedce2d034c75a79cf6dd4f3"; - hash = "sha256-IlW5i4EJVoUYPu9/lb0LeytTpzltQuu5fpkFPQNIhls="; - }) - (fetchpatch { - name = "06_fs_f2fs_grub_errno_mount_fails.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=563436258cde64da6b974880abff1bf0959f4da3"; - hash = "sha256-Iu0RPyB+pAnqMT+MTX+TrJbYJsvYPn7jbMgE1jcLh/Q="; - }) - (fetchpatch { - name = "07_CVE-2024-45783.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=f7c070a2e28dfab7137db0739fb8db1dc02d8898"; - hash = "sha256-V1wh2dPeTazmad61jFtOjhq2MdoD+txPWY/AfwwyTZM="; - }) - (fetchpatch { - name = "08_fs_iso9660_grub_errno_mount_fails.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=965db5970811d18069b34f28f5f31ddadde90a97"; - hash = "sha256-6eN1AvZwXkJOQVcjgymy/E7QiAxzL/d0W3KlAZRqUzI="; - }) - (fetchpatch { - name = "09_fs_iso9660_fix_invalid_free.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=1443833a9535a5873f7de3798cf4d8389f366611"; - hash = "sha256-Gt5yMy5Vg9zrDggj3o/TLNt2vT9/6IuHg4Se2p8e8pI="; - }) - (fetchpatch { - name = "10_fs_jfs_fix_oob_read_jfs_getent.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=66175696f3a385b14bdf1ebcda7755834bd2d5fb"; - hash = "sha256-ETbzbc5gvf55sTLjmJOXXC9VH3qcP1Gv5seR/U9NRiY="; - }) - (fetchpatch { - name = "11_fs_jfs_fix_oob_read_caused_by_invalid_dir_slot_index.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=ab09fd0531f3523ac0ef833404526c98c08248f7"; - hash = "sha256-wE6niiIx4BdN800/Eegb6IbBRoMFpXq9kPvatwhWNXY="; - }) - (fetchpatch { - name = "12_fs_jfs_use_full_40_bits_offset_and_address_for_data_extent.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=bd999310fe67f35a66de3bfa2836da91589d04ef"; - hash = "sha256-fbC4oTEIoGWJASzJI5RXfoanrMLTfjFOI51LCUU7Ctg="; - }) - (fetchpatch { - name = "13_fs_jfs_inconsistent_signed_unsigned_types_usage.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=edd995a26ec98654d907a9436a296c2d82bc4b28"; - hash = "sha256-aa1G1vi4bPZejfKEqZokAZTzY9Ea2lyxTrP4drDV9tk="; - }) - (fetchpatch { - name = "14_fs_ext2_fix_out-of-bounds_read_for_inline_extent.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=7e2f750f0a795c4d64ec7dc7591edac8da2e978c"; - hash = "sha256-PtPqZHMU2fy7btRRaaswLyHizplxnygCzDfcg5ievOQ="; - }) - (fetchpatch { - name = "15_fs_ntfs_fix_out-of-bounds_read.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=aff26318783a135562b904ff09e2359893885732"; - hash = "sha256-znN6lkAB9aAhTGKR1038DzOz5nzuTp+7ylHVqRM7HeI="; - }) - (fetchpatch { - name = "16_fs_ntfs_track_the_end_of_the_MFT_attribute_buffer.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=237a71184a32d1ef7732f5f49ed6a89c5fe1c99a"; - hash = "sha256-0I/g0qHkWY6PArPn1UaYRhCrrh9bHknADh34v5eSjjM="; - }) - (fetchpatch { - name = "17_fs_ntfs_use_a_helper_function_to_access_attributes.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=048777bc29043403d077d41a81d0183767b8bc71"; - hash = "sha256-Mm49MSLqCq143r8ruLJm1QoyCoLtOlCBfqoAPwPlv8E="; - }) - # Patch 18 (067b6d225d482280abad03944f04e30abcbdafa1) has been removed because it causes regressions - # https://lists.gnu.org/archive/html/grub-devel/2025-03/msg00067.html - (fetchpatch { - name = "19_fs_xfs_fix_out-of-bounds_read.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=6ccc77b59d16578b10eaf8a4fe85c20b229f0d8a"; - hash = "sha256-FvTzFvfEi3oyxPC/dUHreyzzeVCskaUlYUjpKY/l0DE="; - }) - (fetchpatch { - name = "20_fs_xfs_ensuring_failing_to_mount_sets_a_grub_errno.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=d1d6b7ea58aa5a80a4c4d0666b49460056c8ef0a"; - hash = "sha256-SLdXMmYHq/gRmWrjRrOu5ZYFod84EllUL6hk+gnr3kg="; - }) - (fetchpatch { - name = "21_kern_file_ensure_file_data_is_set.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=a7910687294b29288ac649e71b47493c93294f17"; - hash = "sha256-DabZK9eSToEmSA9dEwtEN+URiVyS9qf6e2Y2UiMuy8Q="; - }) - (fetchpatch { - name = "22_kern_file_implement_filesystem_reference_counting.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=16f196874fbe360a1b3c66064ec15adadf94c57b"; - excludes = [ "grub-core/fs/erofs.c" ]; # Does not exist on 2.12 - hash = "sha256-yGU//1tPaxi+xFKZrsbUAnvgFpwtrIMG+8cPbSud4+U="; - }) - (fetchpatch { - name = "23_prerequisite_1_key_protector_add_key_protectors_framework.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=5d260302da672258444b01239803c8f4d753e3f3"; - hash = "sha256-5aFHzc5qXBNLEc6yzI17AH6J7EYogcXdLxk//1QgumY="; - }) - (fetchpatch { - name = "23_prerequisite_2_disk_cryptodisk_allow_user_to_retry_failed_passphrase.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=386b59ddb42fa3f86ddfe557113b25c8fa16f88c"; - hash = "sha256-e1kGQB7wGWvEb2bY3xIpZxE1uzTt9JOKi05jXyUm+bI="; - }) - (fetchpatch { - name = "23_prerequisite_3_cryptodisk_support_key_protectors.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=ad0c52784a375cecaa8715d7deadcf5d65baf173"; - hash = "sha256-+YIvUYA3fLiOFFsXDrQjqjWFluzLa7N1tv0lwq8BqCs="; - }) - (fetchpatch { - name = "23_prerequisite_4_cryptodisk_fallback_to_passphrase.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=6abf8af3c54abc04c4ec71c75d10fcfbc190e181"; - hash = "sha256-eMu9rW4iJucDAsTQMJD1XE6dDIcUmn02cGqIaqBbO3o="; - }) - (fetchpatch { - name = "23_prerequisite_5_cryptodisk_wipe_out_the_cached_keys_from_protectors.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=b35480b48e6f9506d8b7ad8a3b5206d29c24ea95"; - hash = "sha256-5L6Rr+X5Z+Ip91z8cpLcatDW1vyEoZa1icL2oMXPXuI="; - }) - (fetchpatch { - name = "23_prerequisite_6_cli_lock_add_build_option_to_block_command_line_interface.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=bb65d81fe320e4b20d0a9b32232a7546eb275ecc"; - hash = "sha256-HxXgtvEhtaIjXbOcxJHNpD9/NVOv3uXPnue7cagEMu8="; - }) - (fetchpatch { - name = "23_CVE-2024-49504.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=13febd78db3cd85dcba67d8ad03ad4d42815f11e"; - hash = "sha256-GejDL9IKbmbSUmp8F1NuvBcFAp2/W04jxmOatI5dKn8="; - }) - (fetchpatch { - name = "24_disk_loopback_reference_tracking_for_the_loopback.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=67f70f70a36b6e87a65f928fe1e840a12eafb7ae"; - hash = "sha256-sWBnSF3rAuY1A/IIK1Pc+BqTvyK3j7+lLEhvImtBQMA="; - }) - (fetchpatch { - name = "25_kern_disk_limit_recursion_depth.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=18212f0648b6de7d71d4c8f41eb4d8b78b3a299b"; - hash = "sha256-HiVzXUNs45Fxh4DSqO8wAxSBM7CaYU/bix0PVBcIHGw="; - }) - (fetchpatch { - name = "26_kern_partition_limit_recursion_in_part_iterate.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=8a7103fddfd6664f41081f3bb88eebbf2871da2a"; - hash = "sha256-Nw1VFRVww1VSDSBkRrnTGeaA2PKCitugM12XH6X/2YI="; - }) - (fetchpatch { - name = "27_script_execute_limit_the_recursion_depth.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=d8a937ccae5c6d86dc4375698afca5cefdcd01e1"; - hash = "sha256-YOAdPMZ2iBNMzIwAXFkkyTMKh4ptZUQ0J3v9EjnRlbo="; - }) - (fetchpatch { - name = "28_net_unregister_net_default_ip_and_net_default_mac_variables_hooks_on_unload.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=a1dd8e59da26f1a9608381d3a1a6c0f465282b1d"; - hash = "sha256-7fqdkhFqLECzhz1OLavkHrE9ktDAEmx9ZxZayNr/Eo4="; - }) - (fetchpatch { - name = "29_net_remove_variables_hooks_when_interface_is_unregisted.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=aa8b4d7facef7b75a2703274b1b9d4e0e734c401"; - hash = "sha256-m3VLDbJlwchV5meEpU4LJrDxBtA80qvYcVMJinHLnac="; - }) - (fetchpatch { - name = "30_CVE-2025-0624.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=5eef88152833062a3f7e017535372d64ac8ef7e1"; - hash = "sha256-DvhzHnenAmO9SZpi4kU+0GhyKZB4q4xQYuNJgEhJmn0="; - }) - (fetchpatch { - name = "31_net_tftp_fix_stack_buffer_overflow_in_tftp_open.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=0707accab1b9be5d3645d4700dde3f99209f9367"; - hash = "sha256-16NrpWFSE4jFT2uxmJg16jChw8HiGRTol25XQXNQ5l4="; - }) - (fetchpatch { - name = "32_CVE-2024-45774.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=2c34af908ebf4856051ed29e46d88abd2b20387f"; - hash = "sha256-OWmF+fp2TmetQjV4EWMcESW8u52Okkb5C5IPLfczyv4="; - }) - (fetchpatch { - name = "33_kern_dl_fix_for_an_integer_overflow_in_grub_dl_ref.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=500e5fdd82ca40412b0b73f5e5dda38e4a3af96d"; - hash = "sha256-FNqOWo+oZ4/1sCbTi2uaeKchUxwAKXtbzhScezm0yxk="; - }) - # Patch 34 (https://git.savannah.gnu.org/cgit/grub.git/patch/?id=d72208423dcabf9eb4a3bcb17b6b31888396bd49) - # is skipped, grub_dl_set_mem_attrs() does not exist on 2.12 - (fetchpatch { - name = "35_kern_dl_check_for_the_SHF_INFO_LINK_flag_in_grub_dl_relocate_symbols.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=98ad84328dcabfa603dcf5bd217570aa6b4bdd99"; - hash = "sha256-Zi4Pj2NbodL0VhhO5MWhvErb8xmA7Li0ur0MxpgQjzg="; - }) - (fetchpatch { - name = "36_CVE-2024-45775.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=05be856a8c3aae41f5df90cab7796ab7ee34b872"; - hash = "sha256-T6DO8iuImQTP7hPaCAHMtFnheQoCkZ6w+kfNolLPmrY="; - }) - (fetchpatch { - name = "37_commands_ls_fix_NULL_dereference.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=0bf56bce47489c059e50e61a3db7f682d8c44b56"; - hash = "sha256-h5okwqv4ZFahP3ANUbsk1fiSV4pwEnxUExeBgQ4tiTI="; - }) - (fetchpatch { - name = "38_CVE-2025-0622.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=2123c5bca7e21fbeb0263df4597ddd7054700726"; - hash = "sha256-tFE7VgImGZWDICyvHbrI1hqW6/XohgdTmk21MzljMGw="; - }) - (fetchpatch { - name = "39_CVE-2025-0622.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=9c16197734ada8d0838407eebe081117799bfe67"; - hash = "sha256-tTeuEvadKbXVuY0m0dKtTr11Lpb3yQi4zk0bpwrMOeA="; - }) - (fetchpatch { - name = "40_CVE-2025-0622.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=7580addfc8c94cedb0cdfd7a1fd65b539215e637"; - hash = "sha256-khRLpWqE7hzzoqssVkGFMjAv09T+uHn13Q9pCpogMms="; - }) - (fetchpatch { - name = "41_CVE-2024-45776.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=09bd6eb58b0f71ec273916070fa1e2de16897a91"; - hash = "sha256-yrl/6XUdKQg/MLe8KFuFoRRbQSyOhDmyvnWBV+sr3EY="; - }) - (fetchpatch { - name = "42_CVE-2024-45777.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=b970a5ed967816bbca8225994cd0ee2557bad515"; - hash = "sha256-Vl5Emw3O3Ba2hD1GCWune4PGduDDPO0gM5u+zx/OwKo="; - }) - (fetchpatch { - name = "43_CVE-2025-0690.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=dad8f502974ed9ad0a70ae6820d17b4b142558fc"; - hash = "sha256-DeWOncndX2VM8w1lb5fd5wHAZrI+ChB5Pj9XbUIfDWY="; - }) - (fetchpatch { - name = "44_commands_test_stack_overflow_due_to_unlimited_recursion_depth.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=c68b7d23628a19da67ebe2e06f84165ee04961af"; - hash = "sha256-aputM9KqkB/cK8hBiU9VXbu0LpLNlNCMVIeE9h2pMgY="; - }) - (fetchpatch { - name = "45_CVE-2025-1118.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=34824806ac6302f91e8cabaa41308eaced25725f"; - hash = "sha256-PKQs+fCwj4a9p4hbMqAT3tFNoAOw4xnbKmCwjPUgEOc="; - }) - (fetchpatch { - name = "46_commands_memrw_disable_memory_reading_in_lockdown_mode.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=340e4d058f584534f4b90b7dbea2b64a9f8c418c"; - hash = "sha256-NiMIUnfRreDBw+k4yxUzoRNMFL8pkJhVtkINVgmv5XA="; - }) - (fetchpatch { - name = "47_commands_hexdump_disable_memory_reading_in_lockdown_mode.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=5f31164aed51f498957cdd6ed733ec71a8592c99"; - hash = "sha256-NA7QjxZ9FP+WwiOveqLkbZqsF7hULIyaVS3gNaSUXJE="; - }) - (fetchpatch { - name = "48_CVE-2024-45778_CVE-2024-45779.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=26db6605036bd9e5b16d9068a8cc75be63b8b630"; - hash = "sha256-1+ImwkF/qsejWs2lpyO6xbcqVo2NJGv32gjrP8mEPnI="; - }) - (fetchpatch { - name = "49_CVE-2025-0677_CVE-2025-0684_CVE-2025-0685_CVE-2025-0686_CVE-2025-0689.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=c4bc55da28543d2522a939ba4ee0acde45f2fa74"; - hash = "sha256-qrlErSImMX8eXJHkXjOe5GZ6lWOya5SVpNoiqyEM1lE="; - }) - (fetchpatch { - name = "50_disk_use_safe_math_macros_to_prevent_overflows.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=c407724dad6c3e2fc1571e57adbda71cc03f82aa"; - hash = "sha256-kkAjxXvCdzwqh+oWtEF3qSPiUX9cGWO6eSFVeo7WJzQ="; - }) - (fetchpatch { - name = "51_disk_prevent_overflows_when_allocating_memory_for_arrays.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=d8151f98331ee4d15fcca59edffa59246d8fc15f"; - hash = "sha256-2U+gMLigOCCg3P1GB615xQ0B9PDA6j92tt1ba3Tqg+E="; - }) - (fetchpatch { - name = "52_disk_check_if_returned_pointer_for_allocated_memory_is_NULL.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=33bd6b5ac5c77b346769ab5284262f94e695e464"; - hash = "sha256-+BaJRskWP/YVEdvIxMvEydjQx2LpLlGphRtZjiOUxJ0="; - }) - (fetchpatch { - name = "53_disk_ieee1275_ofdisk_call_grub_ieee1275_close_when_grub_malloc_fails.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=fbaddcca541805c333f0fc792b82772594e73753"; - hash = "sha256-9sGA41HlB/8rtT/fMfkDo4ZJMXBSr+EyN92l/0gDfl4="; - }) - (fetchpatch { - name = "54_fs_use_safe_math_macros_to_prevent_overflows.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=6608163b08a7a8be4b0ab2a5cd4593bba07fe2b7"; - excludes = [ "grub-core/fs/erofs.c" ]; # Does not exist on 2.12 - hash = "sha256-mW4MH5VH5pDxCaFhNh/4mEcYloga56p8vCi7X4kSaek="; - }) - (fetchpatch { - name = "55_CVE-2025-0678_CVE-2025-1125.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=84bc0a9a68835952ae69165c11709811dae7634e"; - hash = "sha256-rCliqM2+k7rTGNpdHFkg3pHvuISjoG0MQr6/8lIvwK4="; - }) - (fetchpatch { - name = "56_fs_prevent_overflows_when_assigning_returned_values_from_read_number.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=cde9f7f338f8f5771777f0e7dfc423ddf952ad31"; - hash = "sha256-dN3HJXNIYtaUZL0LhLabC4VKK6CVC8km9UTw/ln/6ys="; - }) - (fetchpatch { - name = "57_fs_zfs_use_safe_math_macros_to_prevent_overflows.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=88e491a0f744c6b19b6d4caa300a576ba56db7c9"; - hash = "sha256-taSuKyCf9+TiQZcF26yMWpDDQqCfTdRuZTqB9aEz3aA="; - }) - (fetchpatch { - name = "58_fs_zfs_prevent_overflows_when_allocating_memory_for_arrays.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=7f38e32c7ebeaebb79e2c71e3c7d5ea367d3a39c"; - hash = "sha256-E5VmP7I4TAEXxTz3j7mi/uIr9kOSzMoPHAYAbyu56Xk="; - }) - (fetchpatch { - name = "59_fs_zfs_check_if_returned_pointer_for_allocated_memory_is_NULL.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=13065f69dae0eeb60813809026de5bd021051892"; - hash = "sha256-1W//rHUspDS+utdNc069J8lX1ONfoBKiJYnUt46C/D0="; - }) - (fetchpatch { - name = "60_fs_zfs_add_missing_NULL_check_after_grub_strdup_call.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=dd6a4c8d10e02ca5056681e75795041a343636e4"; - hash = "sha256-iFLEkz5G6aQ8FXGuY7/wgN4d4o0+sUxWMKYIFcQ/H+o="; - }) - (fetchpatch { - name = "61_net_use_safe_math_macros_to_prevent_overflows.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=4beeff8a31c4fb4071d2225533cfa316b5a58391"; - hash = "sha256-/gs5ZhplQ1h7PWw0p+b5+0OxmRcvDRKWHj39ezhivcg="; - }) - (fetchpatch { - name = "62_net_prevent_overflows_when_allocating_memory_for_arrays.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=dee2c14fd66bc497cdc74c69fde8c9b84637c8eb"; - hash = "sha256-cO02tCGEeQhQF0TmgtNOgUwRLnNgmxhEefo1gtSlFOk="; - }) - (fetchpatch { - name = "63_net_check_if_returned_pointer_for_allocated_memory_is_NULL.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=1c06ec900591d1fab6fbacf80dc010541d0a5ec8"; - hash = "sha256-oSRhWWVraitoVDqGlFOVzdCkaNqFGOHLjJu75CSc388="; - }) - (fetchpatch { - name = "64_fs_sfs_check_if_allocated_memory_is_NULL.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=e3c578a56f9294e286b6028ca7c1def997a17b15"; - hash = "sha256-7tvFbmjWmWmmRykQjMvZV6IYlhSS8oNR7YfaO5XXAfU="; - }) - (fetchpatch { - name = "65_script_execute_fix_potential_underflow_and_NULL.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=d13b6e8ebd10b4eb16698a002aa40258cf6e6f0e"; - hash = "sha256-paMWaAIImzxtufUrVF5v4T4KnlDAJIPhdaHznu5CyZ8="; - }) - (fetchpatch { - name = "66_osdep_unix_getroot_fix_potential_underflow.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=66733f7c7dae889861ea3ef3ec0710811486019e"; - hash = "sha256-/14HC1kcW7Sy9WfJQFfC+YnvS/GNTMP+Uy6Dxd3zkwc="; - }) - (fetchpatch { - name = "67_misc_ensure_consistent_overflow_error_messages.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=f8795cde217e21539c2f236bcbb1a4bf521086b3"; - hash = "sha256-4X7wr1Tg16xDE9FO6NTlgkfLV5zFKmajeaOspIqcCuI="; - }) - (fetchpatch { - name = "68_bus_usb_ehci_define_GRUB_EHCI_TOGGLE_as_grub_uint32_t.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=9907d9c2723304b42cf6da74f1cc6c4601391956"; - hash = "sha256-D8xaI8g7ffGGmZqqeS8wxWIFLUWUBfmHwMVOHkYTc2I="; - }) - (fetchpatch { - name = "69_normal_menu_use_safe_math_to_avoid_an_integer_overflow.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=5b36a5210e21bee2624f8acc36aefd8f10266adb"; - hash = "sha256-UourmM0Zlaj4o+SnYi5AtjfNujDOt+2ez2XH/uWyiaM="; - }) - (fetchpatch { - name = "70_kern_partition_add_sanity_check_after_grub_strtoul_call.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=8e6e87e7923ca2ae880021cb42a35cc9bb4c8fe2"; - hash = "sha256-4keMUu6ZDKmuSQlFnldV15dDGUibsnSvoEWhLsqWieI="; - }) - (fetchpatch { - name = "71_kern_misc_add_sanity_check_after_grub_strtoul_call.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=a8d6b06331a75d75b46f3dd6cc6fcd40dcf604b7"; - hash = "sha256-2Mpe1sqyuoUPyMAKGZTNzG/ig3G3K8w0gia7lc508Rg="; - }) - (fetchpatch { - name = "72_loader_i386_linux_cast_left_shift_to_grub_uint32_t.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=490a6ab71cebd96fae7a1ceb9067484f5ccbec2a"; - hash = "sha256-e49OC1EBaX0/nWTTXT5xE5apTJPQV0myP5Ohxn9Wwa8="; - }) - (fetchpatch { - name = "73_loader_i386_bsd_use_safe_math_to_avoid_underflow.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=4dc6166571645780c459dde2cdc1b001a5ec844c"; - hash = "sha256-e8X+oBvejcFNOY1Tp/f6QqCDwrgK7f9u1F8SdO/dhy4="; - }) - (fetchpatch { - # Fixes 7e2f750f0a (security patch 14/73) - name = "fs_ext2_rework_out-of-bounds_read_for_inline_and_external_extents.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=348cd416a3574348f4255bf2b04ec95938990997"; - hash = "sha256-WBLYQxv8si2tvdPAvbm0/4NNqYWBMJpFV4GC0HhN/kE="; - }) - (fetchpatch { - name = "CVE-2025-4382.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=c448f511e74cb7c776b314fcb7943f98d3f22b6d"; - hash = "sha256-64gMhCEW0aYHt46crX/qN/3Hj8MgvWLazgQlVXqe8LE="; - }) - # https://lists.gnu.org/archive/html/grub-devel/2025-11/msg00155.html - (fetchpatch { - name = "1_commands_test_fix_error_in_recursion_depth_calculation.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=cc9d621dd06bfa12eac511b37b4ceda5bd2f8246"; - hash = "sha256-GpLpqTKr2ke/YaxnZIO1Kh9wpde44h2mvwcODcAL/nk="; - }) - (fetchpatch { - name = "2_CVE-2025-54771.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=c4fb4cbc941981894a00ba8e75d634a41967a27f"; - hash = "sha256-yWowlAMVXdfIyC+BiB00IZvTwIybvaPhxAyz0MPjQuY="; - }) - (fetchpatch { - name = "3_CVE-2025-54770.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=10e58a14db20e17d1b6a39abe38df01fef98e29d"; - hash = "sha256-1ROc5n7sApw7aGr+y8gygFqVkifLdgOD3RPaW9b8aQQ="; - }) - (fetchpatch { - name = "4_CVE-2025-61662.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=8ed78fd9f0852ab218cc1f991c38e5a229e43807"; - hash = "sha256-mG+vcZHbF4duY2YoYAzPBQRHfWvp5Fvgtm0XBk7JqqM="; - }) - (fetchpatch { - name = "5_CVE-2025-61663_CVE-2025-61664.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=05d3698b8b03eccc49e53491bbd75dba15f40917"; - hash = "sha256-kgtXhZmAQpassEf8+RzqkghAzLrCcRoRMMnfunF/0J8="; - }) - (fetchpatch { - name = "6_tests_lib_functional_test_unregister_commands_on_module_unload.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=9df1e693e70c5a274b6d60dc76efe2694b89c2fc"; - hash = "sha256-UzyYkpP7vivx2jzxi7BMP9h9OB2yraswrMW4g9UWsbI="; - }) - (fetchpatch { - name = "7_CVE-2025-61661.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=549a9cc372fd0b96a4ccdfad0e12140476cc62a3"; - hash = "sha256-2mlDoVXY7Upwx4QBeAMOHUtoUlyx1MDDmabnrwK1gEY="; - }) - (fetchpatch { - name = "8_commands_usbtest_ensure_string_length_is_sufficient_in_usb_string_processing.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=7debdce1e98907e65223a4b4c53a41345ac45e53"; - hash = "sha256-2ALvrmwxvpjQYjGNrQ0gyGotpk0kgmYlJXMF1xXrnEw="; - }) - # Required to apply the GCC-15 patch - (fetchpatch { - name = "gnulib_Add_patch_to_allow_GRUB_w_GCC-15_compile_0_1.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=bba7dd7363402157034e9c94ee3d9ea82e37861d"; - hash = "sha256-KO9rE/9xRkIGi/Y6jv1gVPiAJZUejwaUW6kIWthPUhw="; - }) - # Required to apply the GCC-11 patch - (fetchpatch { - name = "gnulib_Add_patch_to_allow_GRUB_w_GCC-15_compile_0_2.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=db506b3b83640ab166a782e1ca47c47836afddcd"; - hash = "sha256-4ucCu+9OZ8NoicLF9hCgUpX4xgJk4Gzu6F3P4zl9J3U="; - }) - # Required to build grub 2.12 with GCC 15 - (fetchpatch { - name = "gnulib_Add_patch_to_allow_GRUB_w_GCC-15_compile_1_2.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=ac1512b872af8567b408518a7efa01607a0219ae"; - hash = "sha256-deyp6Yatlgv86bYMt7WcWhKg8J6StDPUEy4UPHqJYIc="; + /* + Restore gfxterm_menu (and cmdline_cat). The NixOS installer uses it. + + I want to mention that dead code gets automatically removed by the bootstrapper. + This would include files like `grub-core/tests/gfxterm_menu.c`. + + Luckily for us, it doesn't have to be this way. We can re-run `autogen.sh`. + */ + (fetchpatch { + name = "03_restore_gfxterm_menu.patch"; + url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=ca2a91f43bf6e1df23a07c295534f871ddf2d401"; + revert = true; + hash = "sha256-nFOoIyJqORY3I/mFGB9rcdpsnUcoUwfsQ7F+TQr4Aps="; + }) + + /* + The commit that we're reverting below breaks the `kernel.img` payload that's generated at runtime. + + If we don't do this, we can't install GRUB. + */ + (fetchpatch { + name = "01_fix_kernel-img_load_offset.patch"; + url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=1a5417f39a0ccefcdd5440f2a67f84d2d2e26960"; + revert = true; + hash = "sha256-mHaVrzGs7uqYqSSAHOw1qgZSHLWG3CmVcZWrSLvVOy8="; + }) + (fetchpatch { + name = "00_fix_kernel-img_load_offset.patch"; + url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=ac042f3f58d33ce9cd5ff61750f06da1a1d7b0eb"; + revert = true; + hash = "sha256-uYlS4r0frL62H35Bts+W9l4MOHCcoBGOhbCQtxU363s="; }) # Required to build grub2_efi with GCC 16, or fails with "error: 'regparm' # attribute ignored [-Werror=attributes]" @@ -592,16 +172,27 @@ stdenv.mkDerivation rec { }) ]; - postPatch = - if kbdcompSupport then - '' - sed -i util/grub-kbdcomp.in -e 's@\bckbcomp\b@${ckbcomp}/bin/ckbcomp@' - '' - else - '' - echo '#! ${runtimeShell}' > util/grub-kbdcomp.in - echo 'echo "Compile grub2 with { kbdcompSupport = true; } to enable support for this command."' >> util/grub-kbdcomp.in - ''; + postPatch = '' + ${ + if kbdcompSupport then + '' + sed -i util/grub-kbdcomp.in -e 's@\bckbcomp\b@${ckbcomp}/bin/ckbcomp@' + '' + else + '' + echo '#! ${runtimeShell}' > util/grub-kbdcomp.in + echo 'echo "Compile grub2 with { kbdcompSupport = true; } to enable support for this command."' >> util/grub-kbdcomp.in + '' + } + + GNULIB_REVISION=$(. bootstrap.conf; echo $GNULIB_REVISION) + if [ "$GNULIB_REVISION" != ${gnulib.rev} ]; then + echo "This version of GRUB requires a different gnulib revision!" + echo "We have: ${gnulib.rev}" + echo "GRUB needs: $GNULIB_REVISION" + exit 1 + fi + ''; depsBuildBuild = [ buildPackages.stdenv.cc @@ -615,6 +206,7 @@ stdenv.mkDerivation rec { gettext freetype autoconf + autoconf-archive automake help2man ]; @@ -624,6 +216,7 @@ stdenv.mkDerivation rec { freetype lvm2 fuse3 + xz libtool bash ] @@ -637,36 +230,28 @@ stdenv.mkDerivation rec { separateDebugInfo = !xenSupport; preConfigure = '' - for i in "tests/util/"*.in - do - sed -i "$i" -e's|/bin/bash|${stdenv.shell}|g' - done + for i in "tests/util/"*.in + do + sed -i "$i" -e's|/bin/bash|${stdenv.shell}|g' + done - # Apparently, the QEMU executable is no longer called - # `qemu-system-i386', even on i386. - # - # In addition, use `-nodefaults' to avoid errors like: - # - # chardev: opening backend "stdio" failed - # qemu: could not open serial device 'stdio': Invalid argument - # - # See . - sed -i "tests/util/grub-shell.in" \ - -e's/qemu-system-i386/qemu-system-x86_64 -nodefaults/g' - - unset CPP # setting CPP intereferes with dependency calculation + # Apparently, the QEMU executable is no longer called + # `qemu-system-i386', even on i386. + # + # In addition, use `-nodefaults' to avoid errors like: + # + # chardev: opening backend "stdio" failed + # qemu: could not open serial device 'stdio': Invalid argument + # + # See . + sed -i "tests/util/grub-shell.in" \ + -e's/qemu-system-i386/qemu-system-x86_64 -nodefaults/g' patchShebangs . - GNULIB_REVISION=$(. bootstrap.conf; echo $GNULIB_REVISION) - if [ "$GNULIB_REVISION" != ${gnulib.rev} ]; then - echo "This version of GRUB requires a different gnulib revision!" - echo "We have: ${gnulib.rev}" - echo "GRUB needs: $GNULIB_REVISION" - exit 1 - fi - cp -f --no-preserve=mode ${locales}/po/LINGUAS ${locales}/po/*.po po + mkdir po/.reference + cp -f --no-preserve=mode ${locales}/po/*.po po/.reference ./bootstrap --no-git --gnulib-srcdir=${gnulib} @@ -679,13 +264,6 @@ stdenv.mkDerivation rec { ) ''; - postConfigure = '' - # make sure .po files are up to date to workaround - # parallel `msgmerge --update` on autogenerated .po files: - # https://github.com/NixOS/nixpkgs/pull/248747#issuecomment-1676301670 - make dist - ''; - configureFlags = [ "--enable-grub-mount" # dep of os-prober ] @@ -718,6 +296,10 @@ stdenv.mkDerivation rec { ++ lib.optionals xenPvhSupport [ "--with-platform=xen_pvh" "--target=${xenPvhSystemsBuild.${stdenv.hostPlatform.system}.target}" + ] + ++ lib.optionals corebootSupport [ + "--with-platform=coreboot" + "--enable-boot-time" # Log boot times. Might be useful for debugging loading issues. ]; # save target that grub is compiled for @@ -733,11 +315,11 @@ stdenv.mkDerivation rec { enableParallelBuilding = true; postInstall = '' - # Avoid a runtime reference to gcc - sed -i $out/lib/grub/*/modinfo.sh -e "/grub_target_cppflags=/ s|'.*'|' '|" - # just adding bash to buildInputs wasn't enough to fix the shebang - substituteInPlace $out/lib/grub/*/modinfo.sh \ - --replace ${buildPackages.bash} "/usr/bin/bash" + ## Although usually referencing store paths is a bad idea, the reference to `gcc` inside grub_target_cppflags seems to be completely harmless. + # + ## I am still unsure about the functionality of modinfo.sh, but from what I can tell, it's just metadata. + + patchShebangs $out/lib/grub/*/modinfo.sh ''; passthru.tests = { From b064a48442474145159c318ceea3ab73ec01d52b Mon Sep 17 00:00:00 2001 From: hustlerone Date: Mon, 1 Jun 2026 11:58:25 +0200 Subject: [PATCH 010/140] grub2: use stable savannah repositories When rebuild cache on a custom cache builder it appears impossible to load sources/packages from git.savannah.gnu.org. Using stable savannah repositories instead Co-authored-by: fomichevmi <59839128+fomichevmi@users.noreply.github.com> --- pkgs/by-name/gr/grub2/package.nix | 88 ++++++++++++++++--------------- 1 file changed, 46 insertions(+), 42 deletions(-) diff --git a/pkgs/by-name/gr/grub2/package.nix b/pkgs/by-name/gr/grub2/package.nix index 0333b5c44a69..269162d2273e 100644 --- a/pkgs/by-name/gr/grub2/package.nix +++ b/pkgs/by-name/gr/grub2/package.nix @@ -85,7 +85,7 @@ let inPCSystems = lib.any (system: stdenv.hostPlatform.system == system) (lib.attrNames pcSystems); gnulib = fetchgit { - url = "https://git.savannah.gnu.org/git/gnulib.git"; + url = "https://https.git.savannah.gnu.org/git/gnulib.git"; # NOTE: get $GNULIB_REVISION from bootstrap.conf! rev = "9f48fb992a3d7e96610c4ce8be969cff2d61a01b"; hash = "sha256-mzbF66SNqcSlI+xmjpKpNMwzi13yEWoc1Fl7p4snTto="; @@ -121,56 +121,60 @@ stdenv.mkDerivation rec { inherit version; src = fetchgit { - url = "https://git.savannah.gnu.org/git/grub.git"; + url = "https://https.git.savannah.gnu.org/git/grub.git"; tag = "grub-${version}"; hash = "sha256-Gkpde5CeJOQ+0p5WGwXZ2P881jxrWkuFw3Fh4lul/so="; }; - patches = [ - ./fix-bash-completion.patch - ./add-hidden-menu-entries.patch - ./bootstrap-po-downloads.patch + patches = + let + grubPatch = commit: "https://cgit.git.savannah.gnu.org/cgit/grub.git/patch/?id=${commit}"; + in + [ + ./fix-bash-completion.patch + ./add-hidden-menu-entries.patch + ./bootstrap-po-downloads.patch - /* - Restore gfxterm_menu (and cmdline_cat). The NixOS installer uses it. + /* + Restore gfxterm_menu (and cmdline_cat). The NixOS installer uses it. - I want to mention that dead code gets automatically removed by the bootstrapper. - This would include files like `grub-core/tests/gfxterm_menu.c`. + I want to mention that dead code gets automatically removed by the bootstrapper. + This would include files like `grub-core/tests/gfxterm_menu.c`. - Luckily for us, it doesn't have to be this way. We can re-run `autogen.sh`. - */ - (fetchpatch { - name = "03_restore_gfxterm_menu.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=ca2a91f43bf6e1df23a07c295534f871ddf2d401"; - revert = true; - hash = "sha256-nFOoIyJqORY3I/mFGB9rcdpsnUcoUwfsQ7F+TQr4Aps="; - }) + Luckily for us, it doesn't have to be this way. We can re-run `autogen.sh`. + */ + (fetchpatch { + name = "03_restore_gfxterm_menu.patch"; + url = grubPatch "ca2a91f43bf6e1df23a07c295534f871ddf2d401"; + revert = true; + hash = "sha256-nFOoIyJqORY3I/mFGB9rcdpsnUcoUwfsQ7F+TQr4Aps="; + }) - /* - The commit that we're reverting below breaks the `kernel.img` payload that's generated at runtime. + /* + The commit that we're reverting below breaks the `kernel.img` payload that's generated at runtime. - If we don't do this, we can't install GRUB. - */ - (fetchpatch { - name = "01_fix_kernel-img_load_offset.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=1a5417f39a0ccefcdd5440f2a67f84d2d2e26960"; - revert = true; - hash = "sha256-mHaVrzGs7uqYqSSAHOw1qgZSHLWG3CmVcZWrSLvVOy8="; - }) - (fetchpatch { - name = "00_fix_kernel-img_load_offset.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=ac042f3f58d33ce9cd5ff61750f06da1a1d7b0eb"; - revert = true; - hash = "sha256-uYlS4r0frL62H35Bts+W9l4MOHCcoBGOhbCQtxU363s="; - }) - # Required to build grub2_efi with GCC 16, or fails with "error: 'regparm' - # attribute ignored [-Werror=attributes]" - (fetchpatch { - name = "gcc16_make_regparm_attribute_more_conditional.patch"; - url = "https://git.savannah.gnu.org/cgit/grub.git/patch/?id=9922ed133c2c754ec9f37198da2b3e3e8a4fd5ff"; - hash = "sha256-V2vffDxL/qQ14YN5scc3CFPBFBWvkh57dc5/hWd/6F4="; - }) - ]; + If we don't do this, we can't install GRUB. + */ + (fetchpatch { + name = "01_fix_kernel-img_load_offset.patch"; + url = grubPatch "1a5417f39a0ccefcdd5440f2a67f84d2d2e26960"; + revert = true; + hash = "sha256-mHaVrzGs7uqYqSSAHOw1qgZSHLWG3CmVcZWrSLvVOy8="; + }) + (fetchpatch { + name = "00_fix_kernel-img_load_offset.patch"; + url = grubPatch "ac042f3f58d33ce9cd5ff61750f06da1a1d7b0eb"; + revert = true; + hash = "sha256-uYlS4r0frL62H35Bts+W9l4MOHCcoBGOhbCQtxU363s="; + }) + + # Required to build grub2_efi with GCC 16, or fails with "error: 'regparm' attribute ignored [-Werror=attributes]" + (fetchpatch { + name = "gcc16_make_regparm_attribute_more_conditional.patch"; + url = grubPatch "9922ed133c2c754ec9f37198da2b3e3e8a4fd5ff"; + hash = "sha256-V2vffDxL/qQ14YN5scc3CFPBFBWvkh57dc5/hWd/6F4="; + }) + ]; postPatch = '' ${ From 0e1587fa4414f4672f432509d810b3b6f6e84b9b Mon Sep 17 00:00:00 2001 From: hustlerone Date: Mon, 27 Jul 2026 16:04:58 +0200 Subject: [PATCH 011/140] grub2: use freedesktop repository --- nixos/modules/installer/cd-dvd/iso-image.nix | 1 - pkgs/by-name/gr/grub2/package.nix | 41 ++++++++------------ 2 files changed, 17 insertions(+), 25 deletions(-) diff --git a/nixos/modules/installer/cd-dvd/iso-image.nix b/nixos/modules/installer/cd-dvd/iso-image.nix index 59e6c3be2d99..e73fa287c45b 100644 --- a/nixos/modules/installer/cd-dvd/iso-image.nix +++ b/nixos/modules/installer/cd-dvd/iso-image.nix @@ -371,7 +371,6 @@ let "gfxmenu" "gfxterm" "gfxterm_background" - "gfxterm_menu" "test" "loadenv" "all_video" diff --git a/pkgs/by-name/gr/grub2/package.nix b/pkgs/by-name/gr/grub2/package.nix index 269162d2273e..9ff99c2e6385 100644 --- a/pkgs/by-name/gr/grub2/package.nix +++ b/pkgs/by-name/gr/grub2/package.nix @@ -121,14 +121,14 @@ stdenv.mkDerivation rec { inherit version; src = fetchgit { - url = "https://https.git.savannah.gnu.org/git/grub.git"; + url = "https://gitlab.freedesktop.org/gnu-grub/grub.git"; tag = "grub-${version}"; hash = "sha256-Gkpde5CeJOQ+0p5WGwXZ2P881jxrWkuFw3Fh4lul/so="; }; patches = let - grubPatch = commit: "https://cgit.git.savannah.gnu.org/cgit/grub.git/patch/?id=${commit}"; + grubPatch = commit: "https://gitlab.freedesktop.org/gnu-grub/grub/-/commit/${commit}.patch"; in [ ./fix-bash-completion.patch @@ -136,18 +136,14 @@ stdenv.mkDerivation rec { ./bootstrap-po-downloads.patch /* - Restore gfxterm_menu (and cmdline_cat). The NixOS installer uses it. - - I want to mention that dead code gets automatically removed by the bootstrapper. - This would include files like `grub-core/tests/gfxterm_menu.c`. - - Luckily for us, it doesn't have to be this way. We can re-run `autogen.sh`. + Fix parallel `msgmerge` race on de.po. + See https://gitlab.freedesktop.org/gnu-grub/grub/-/work_items/18 + See https://github.com/NixOS/nixpkgs/pull/248747#issuecomment-1676301670 */ (fetchpatch { - name = "03_restore_gfxterm_menu.patch"; - url = grubPatch "ca2a91f43bf6e1df23a07c295534f871ddf2d401"; - revert = true; - hash = "sha256-nFOoIyJqORY3I/mFGB9rcdpsnUcoUwfsQ7F+TQr4Aps="; + name = "02_fix_msmerge.patch"; + url = grubPatch "c2a215245e2e7d61da4f41945222bd761679ae11"; + hash = "sha256-vBCDej/5DVX1NQMR05kNunxbmfyKywyYQtu4tg3Q2Cs="; }) /* @@ -157,15 +153,8 @@ stdenv.mkDerivation rec { */ (fetchpatch { name = "01_fix_kernel-img_load_offset.patch"; - url = grubPatch "1a5417f39a0ccefcdd5440f2a67f84d2d2e26960"; - revert = true; - hash = "sha256-mHaVrzGs7uqYqSSAHOw1qgZSHLWG3CmVcZWrSLvVOy8="; - }) - (fetchpatch { - name = "00_fix_kernel-img_load_offset.patch"; - url = grubPatch "ac042f3f58d33ce9cd5ff61750f06da1a1d7b0eb"; - revert = true; - hash = "sha256-uYlS4r0frL62H35Bts+W9l4MOHCcoBGOhbCQtxU363s="; + url = grubPatch "1dc2986c7e8480d955f87d276d31400116a21fac"; + hash = "sha256-T1V7Rklc7RNsKTwk2gLoWHxoXUlCM0/mxcnymqUcyRg="; }) # Required to build grub2_efi with GCC 16, or fails with "error: 'regparm' attribute ignored [-Werror=attributes]" @@ -234,6 +223,9 @@ stdenv.mkDerivation rec { separateDebugInfo = !xenSupport; preConfigure = '' + # Trust me, it's NEVER missing. + substituteInPlace configure.ac --replace-fail 'm4_ifndef([AX_CHECK_LINK_FLAG], [m4_fatal([autoconf-archive is missing. You must install it to generate the configure script.])])' ' ' + for i in "tests/util/"*.in do sed -i "$i" -e's|/bin/bash|${stdenv.shell}|g' @@ -312,6 +304,8 @@ stdenv.mkDerivation rec { "${efiSystemsInstall.${stdenv.hostPlatform.system}.target}-efi" else if ieee1275Support then "${ieee1275SystemsBuild.${stdenv.hostPlatform.system}.target}-ieee1275" + else if corebootSupport then + "i386" else lib.optionalString inPCSystems "${pcSystems.${stdenv.hostPlatform.system}.target}-pc"; @@ -319,11 +313,10 @@ stdenv.mkDerivation rec { enableParallelBuilding = true; postInstall = '' - ## Although usually referencing store paths is a bad idea, the reference to `gcc` inside grub_target_cppflags seems to be completely harmless. - # - ## I am still unsure about the functionality of modinfo.sh, but from what I can tell, it's just metadata. + # We have to do this or else closure size balloons up patchShebangs $out/lib/grub/*/modinfo.sh + sed -i $out/lib/grub/*/modinfo.sh -e "/grub_target_cppflags=/ s|'.*'|' '|" ''; passthru.tests = { From 929801ec3bdad0f963668f628cb58d0b0665552f Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 18 Aug 2026 01:23:15 +0000 Subject: [PATCH 012/140] os-prober: 1.84 -> 1.85 --- pkgs/by-name/os/os-prober/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/os/os-prober/package.nix b/pkgs/by-name/os/os-prober/package.nix index f96434477975..5cbc555ad8fa 100644 --- a/pkgs/by-name/os/os-prober/package.nix +++ b/pkgs/by-name/os/os-prober/package.nix @@ -16,14 +16,14 @@ }: stdenv.mkDerivation (finalAttrs: { - version = "1.84"; + version = "1.85"; pname = "os-prober"; src = fetchFromGitLab { domain = "salsa.debian.org"; owner = "installer-team"; repo = "os-prober"; rev = finalAttrs.version; - sha256 = "sha256-91UTiwg4qIi+aCzAto7tCd5WZFjI15XxR1/hZQ0fUa4="; + sha256 = "sha256-JK1+xzbl1EyHZ4E6pmQ5NDbtivZvFySHX+JkWodxyl4="; }; nativeBuildInputs = [ makeWrapper ]; From 5bf6dfb0e7182e928cb21a53a8dc10afddda02f0 Mon Sep 17 00:00:00 2001 From: Guillaume Girol Date: Thu, 20 Aug 2026 12:00:00 +0000 Subject: [PATCH 013/140] nixosTests.os-prober: fix --- nixos/tests/os-prober.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/nixos/tests/os-prober.nix b/nixos/tests/os-prober.nix index 1c26d7423a86..c1cb71dc75e4 100644 --- a/nixos/tests/os-prober.nix +++ b/nixos/tests/os-prober.nix @@ -99,9 +99,11 @@ import ./make-test-python.nix ( desktop-file-utils docbook5 docbook_xsl_ns + hello kbd.dev kmod.dev libarchive.dev + libcap-text-verifier libxml2.bin libxslt.bin nixos-artwork.wallpapers.simple-dark-gray-bottom @@ -112,6 +114,7 @@ import ./make-test-python.nix ( perlPackages.JSON perlPackages.ListCompare perlPackages.XMLLibXML + # make-options-doc/default.nix (python3.withPackages (p: [ p.mistune ])) shared-mime-info sudo From eac3b505ee1fe1eb3301bb2bab5a0be62a49488c Mon Sep 17 00:00:00 2001 From: Tom Fitzhenry Date: Tue, 18 Aug 2026 05:06:13 +0000 Subject: [PATCH 014/140] grub2: fix grubTarget and restrict platforms for coreboot builds --- pkgs/by-name/gr/grub2/package.nix | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/gr/grub2/package.nix b/pkgs/by-name/gr/grub2/package.nix index 9ff99c2e6385..d3b898d77e03 100644 --- a/pkgs/by-name/gr/grub2/package.nix +++ b/pkgs/by-name/gr/grub2/package.nix @@ -45,6 +45,11 @@ let x86_64-linux.target = "i386"; }; + corebootSystemsBuild = { + i686-linux.target = "i386"; + x86_64-linux.target = "i386"; + }; + efiSystemsBuild = { i686-linux.target = "i386"; x86_64-linux.target = "x86_64"; @@ -295,6 +300,7 @@ stdenv.mkDerivation rec { ] ++ lib.optionals corebootSupport [ "--with-platform=coreboot" + "--target=${corebootSystemsBuild.${stdenv.hostPlatform.system}.target}" "--enable-boot-time" # Log boot times. Might be useful for debugging loading issues. ]; @@ -305,7 +311,7 @@ stdenv.mkDerivation rec { else if ieee1275Support then "${ieee1275SystemsBuild.${stdenv.hostPlatform.system}.target}-ieee1275" else if corebootSupport then - "i386" + "${corebootSystemsBuild.${stdenv.hostPlatform.system}.target}-coreboot" else lib.optionalString inPCSystems "${pcSystems.${stdenv.hostPlatform.system}.target}-pc"; @@ -354,6 +360,8 @@ stdenv.mkDerivation rec { lib.attrNames xenSystemsBuild else if xenPvhSupport then lib.attrNames xenPvhSystemsBuild + else if corebootSupport then + lib.attrNames corebootSystemsBuild else lib.platforms.gnu ++ lib.platforms.linux; From 05be4476d9e4120d55df27cc7f90e6507dcd4b8b Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Sat, 22 Aug 2026 13:43:54 +0200 Subject: [PATCH 015/140] dpkg: enable strictDeps --- pkgs/by-name/dp/dpkg/package.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkgs/by-name/dp/dpkg/package.nix b/pkgs/by-name/dp/dpkg/package.nix index e6aecac386cd..c838c4294c20 100644 --- a/pkgs/by-name/dp/dpkg/package.nix +++ b/pkgs/by-name/dp/dpkg/package.nix @@ -16,6 +16,7 @@ diffutils, versionCheckHook, glibc, + bashNonInteractive, }: stdenv.mkDerivation (finalAttrs: { @@ -113,7 +114,9 @@ stdenv.mkDerivation (finalAttrs: { xz zstd libmd + bashNonInteractive ]; + nativeBuildInputs = [ makeWrapper perl @@ -121,6 +124,8 @@ stdenv.mkDerivation (finalAttrs: { pkg-config ]; + strictDeps = true; + postInstall = '' for i in $out/bin/*; do if head -n 1 $i | grep -q perl; then From ee06a4a96fd6268c500ce2c226f89c2df3ebc823 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Sat, 22 Aug 2026 13:44:04 +0200 Subject: [PATCH 016/140] dpkg: enable structuredAttrs --- pkgs/by-name/dp/dpkg/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/dp/dpkg/package.nix b/pkgs/by-name/dp/dpkg/package.nix index c838c4294c20..6d370bbb7f06 100644 --- a/pkgs/by-name/dp/dpkg/package.nix +++ b/pkgs/by-name/dp/dpkg/package.nix @@ -143,6 +143,8 @@ stdenv.mkDerivation (finalAttrs: { setupHook = ./setup-hook.sh; + __structuredAttrs = true; + meta = { description = "Debian package manager"; homepage = "https://wiki.debian.org/Teams/Dpkg"; From 50383adbd00d78b20e7cae3a44042e1b67796a68 Mon Sep 17 00:00:00 2001 From: Felix Stupp Date: Sat, 22 Aug 2026 17:44:54 +0000 Subject: [PATCH 017/140] nixos/nix: declare .settings.experimental-features for documentation and for ensured mergeability --- nixos/modules/config/nix.nix | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/nixos/modules/config/nix.nix b/nixos/modules/config/nix.nix index 671d0f7865e1..db9e70bb9c3f 100644 --- a/nixos/modules/config/nix.nix +++ b/nixos/modules/config/nix.nix @@ -252,6 +252,16 @@ in ''; }; + experimental-features = mkOption { + type = with types; listOf str; + default = [ ]; + example = [ "ca-derivations" ]; + description = '' + List of experimental features to enable in Nix. + See for available features. + ''; + }; + sandbox = mkOption { type = types.either types.bool (types.enum [ "relaxed" ]); default = true; From 337890d592b17fc939ad72c14c097077d7f01ca9 Mon Sep 17 00:00:00 2001 From: Jamie Magee Date: Mon, 24 Aug 2026 22:22:32 -0700 Subject: [PATCH 018/140] nixos/journald: migrate to RFC 42-style settings Co-authored-by: Grimmauld --- .../administration/systemd-state.section.md | 2 +- nixos/modules/services/logging/rsyslogd.nix | 2 + nixos/modules/services/logging/syslog-ng.nix | 2 + .../modules/system/boot/systemd/journald.nix | 166 ++++++------------ .../modules/testing/test-instrumentation.nix | 10 +- nixos/tests/rsyslogd.nix | 7 +- nixos/tests/systemd-journal.nix | 6 +- nixos/tests/systemd.nix | 2 +- 8 files changed, 71 insertions(+), 126 deletions(-) diff --git a/nixos/doc/manual/administration/systemd-state.section.md b/nixos/doc/manual/administration/systemd-state.section.md index 84f074871a65..473b8232d687 100644 --- a/nixos/doc/manual/administration/systemd-state.section.md +++ b/nixos/doc/manual/administration/systemd-state.section.md @@ -47,6 +47,6 @@ form to `/var/log/journal/{machine-id}`; if (locally) persisting the entire log is desired, it is recommended to make all of `/var/log/journal` persistent. If not, one can set `Storage=volatile` in {manpage}`journald.conf(5)` -([`services.journald.storage = "volatile";`](#opt-services.journald.storage)), +([`services.journald.settings.Journal.Storage = "volatile";`](#opt-services.journald.settings.Journal)), which disables journal persistence and causes it to be written to `/run/log/journal`. diff --git a/nixos/modules/services/logging/rsyslogd.nix b/nixos/modules/services/logging/rsyslogd.nix index 01a94c549dfc..492ff3779b3f 100644 --- a/nixos/modules/services/logging/rsyslogd.nix +++ b/nixos/modules/services/logging/rsyslogd.nix @@ -84,6 +84,8 @@ in config = lib.mkIf cfg.enable { + services.journald.settings.Journal.ForwardToSyslog = lib.mkOptionDefault true; + environment.systemPackages = [ pkgs.rsyslog ]; systemd.services.syslog = { diff --git a/nixos/modules/services/logging/syslog-ng.nix b/nixos/modules/services/logging/syslog-ng.nix index 6b3e7c3e599d..b0bdc4871f8e 100644 --- a/nixos/modules/services/logging/syslog-ng.nix +++ b/nixos/modules/services/logging/syslog-ng.nix @@ -77,6 +77,8 @@ in }; config = lib.mkIf cfg.enable { + services.journald.settings.Journal.ForwardToSyslog = lib.mkOptionDefault true; + systemd.services.syslog-ng = { description = "syslog-ng daemon"; wantedBy = [ "multi-user.target" ]; diff --git a/nixos/modules/system/boot/systemd/journald.nix b/nixos/modules/system/boot/systemd/journald.nix index 4fa91c66d6b1..b7659b5e2871 100644 --- a/nixos/modules/system/boot/systemd/journald.nix +++ b/nixos/modules/system/boot/systemd/journald.nix @@ -1,7 +1,6 @@ { config, lib, - pkgs, utils, ... }: @@ -10,111 +9,65 @@ let in { imports = [ + (lib.mkRenamedOptionModule + [ "services" "journald" "storage" ] + [ "services" "journald" "settings" "Journal" "Storage" ] + ) + (lib.mkRenamedOptionModule + [ "services" "journald" "rateLimitInterval" ] + [ "services" "journald" "settings" "Journal" "RateLimitIntervalSec" ] + ) + (lib.mkRenamedOptionModule + [ "services" "journald" "rateLimitBurst" ] + [ "services" "journald" "settings" "Journal" "RateLimitBurst" ] + ) + (lib.mkRenamedOptionModule + [ "services" "journald" "forwardToSyslog" ] + [ "services" "journald" "settings" "Journal" "ForwardToSyslog" ] + ) + (lib.mkRemovedOptionModule + [ + "services" + "journald" + "console" + ] + "Use services.journald.settings.Journal.ForwardToConsole and services.journald.settings.Journal.TTYPath instead." + ) + (lib.mkRenamedOptionModule + [ "services" "journald" "audit" ] + [ "services" "journald" "settings" "Journal" "Audit" ] + ) + (lib.mkRemovedOptionModule [ + "services" + "journald" + "extraConfig" + ] "Use services.journald.settings.Journal instead.") ]; options = { - services.journald.console = lib.mkOption { - default = ""; - type = lib.types.str; - description = "If non-empty, write log messages to the specified TTY device."; - }; - - services.journald.rateLimitInterval = lib.mkOption { - default = "30s"; - type = lib.types.str; + services.journald.settings.Journal = lib.mkOption { + default = { }; + example = { + Storage = "volatile"; + ForwardToConsole = true; + TTYPath = "/dev/tty12"; + }; description = '' - Configures the rate limiting interval that is applied to all - messages generated on the system. This rate limiting is applied - per-service, so that two services which log do not interfere with - each other's limit. The value may be specified in the following - units: s, min, h, ms, us. To turn off any kind of rate limiting, - set either value to 0. - - See {option}`services.journald.rateLimitBurst` for important - considerations when setting this value. - ''; - }; - - services.journald.storage = lib.mkOption { - default = "persistent"; - type = lib.types.enum [ - "persistent" - "volatile" - "auto" - "none" - ]; - description = '' - Controls where to store journal data. See - {manpage}`journald.conf(5)` for further information. - ''; - }; - - services.journald.rateLimitBurst = lib.mkOption { - default = 10000; - type = lib.types.int; - description = '' - Configures the rate limiting burst limit (number of messages per - interval) that is applied to all messages generated on the system. - This rate limiting is applied per-service, so that two services - which log do not interfere with each other's limit. - - Note that the effective rate limit is multiplied by a factor derived - from the available free disk space for the journal as described on - {manpage}`journald.conf(5)`. - - Note that the total amount of logs stored is limited by journald settings - such as `SystemMaxUse`, which defaults to 10% the file system size - (capped at max 4GB), and `SystemKeepFree`, which defaults to 15% of the - file system size. - - It is thus recommended to compute what period of time that you will be - able to store logs for when an application logs at full burst rate. - With default settings for log lines that are 100 Bytes long, this can - amount to just a few hours. - ''; - }; - - services.journald.audit = lib.mkOption { - default = "keep"; - type = lib.types.oneOf [ - lib.types.bool - (lib.types.enum [ "keep" ]) - ]; - description = '' - If enabled systemd-journald will turn on auditing on start-up. - If disabled it will turn it off. If unset it will neither enable nor disable it, leaving the previous state unchanged. - - NixOS defaults to leaving this unset as enabling audit without auditd running leads to spamming /dev/kmesg with random messages - and if you enable auditd then auditd is responsible for turning auditing on. - - If you want to have audit logs in journald and do not mind audit logs also ending up in /dev/kmesg you can set this option to true. - - If you want to for some ununderstandable reason disable auditing if auditd enabled it then you can set this option to false. - It is of NixOS' opinion that setting this to false is definitely the wrong thing to do - but it's an option. - ''; - }; - - services.journald.extraConfig = lib.mkOption { - default = ""; - type = lib.types.lines; - example = "Storage=volatile"; - description = '' - Extra config options for systemd-journald. See {manpage}`journald.conf(5)` - for available options. - ''; - }; - - services.journald.forwardToSyslog = lib.mkOption { - default = config.services.rsyslogd.enable || config.services.syslog-ng.enable; - defaultText = lib.literalExpression "services.rsyslogd.enable || services.syslog-ng.enable"; - type = lib.types.bool; - description = '' - Whether to forward log messages to syslog. + Options for the systemd journal service. See {manpage}`journald.conf(5)` + man page for available options. ''; + type = lib.types.submodule { + freeformType = lib.types.attrsOf utils.systemdUtils.unitOptions.unitOption; + }; }; }; config = { + services.journald.settings.Journal = { + # "keep" isn't systemd's default since v258, so set it explicitly. + Audit = lib.mkOptionDefault "keep"; + }; + systemd.additionalUpstreamSystemUnits = [ "systemd-journald.socket" "systemd-journald@.socket" @@ -136,23 +89,8 @@ in "sockets.target" ]; - environment.etc = { - "systemd/journald.conf".text = '' - [Journal] - Storage=${cfg.storage} - RateLimitInterval=${cfg.rateLimitInterval} - RateLimitBurst=${toString cfg.rateLimitBurst} - ${lib.optionalString (cfg.console != "") '' - ForwardToConsole=yes - TTYPath=${cfg.console} - ''} - ${lib.optionalString (cfg.forwardToSyslog) '' - ForwardToSyslog=yes - ''} - Audit=${utils.systemdUtils.lib.toOption cfg.audit} - ${cfg.extraConfig} - ''; - }; + environment.etc."systemd/journald.conf".text = + utils.systemdUtils.lib.settingsToSections cfg.settings; users.groups.systemd-journal.gid = config.ids.gids.systemd-journal; diff --git a/nixos/modules/testing/test-instrumentation.nix b/nixos/modules/testing/test-instrumentation.nix index 3a24c9272a6b..47890479a4c9 100644 --- a/nixos/modules/testing/test-instrumentation.nix +++ b/nixos/modules/testing/test-instrumentation.nix @@ -233,11 +233,11 @@ in environment.systemPackages = [ pkgs.xwininfo ]; # Log everything to the serial console. - services.journald.extraConfig = '' - ForwardToConsole=yes - TTYPath=/dev/${qemu-common.qemuSerialDevice} - MaxLevelConsole=debug - ''; + services.journald.settings.Journal = { + ForwardToConsole = true; + TTYPath = "/dev/${qemu-common.qemuSerialDevice}"; + MaxLevelConsole = "debug"; + }; systemd.settings.Manager = managerSettings; systemd.user.settings.Manager = { diff --git a/nixos/tests/rsyslogd.nix b/nixos/tests/rsyslogd.nix index 99703f18d6a7..0702698d6c6e 100644 --- a/nixos/tests/rsyslogd.nix +++ b/nixos/tests/rsyslogd.nix @@ -13,10 +13,11 @@ with pkgs.lib; meta.maintainers = [ pkgs.lib.maintainers.aanderse ]; nodes.machine = - { config, pkgs, ... }: + { lib, ... }: { services.rsyslogd.enable = true; - services.journald.forwardToSyslog = false; + # Verify that the module's option default remains overridable by downstream defaults. + services.journald.settings.Journal.ForwardToSyslog = lib.mkDefault false; }; # ensure rsyslogd isn't receiving messages from journald if explicitly disabled @@ -31,7 +32,7 @@ with pkgs.lib; meta.maintainers = [ pkgs.lib.maintainers.aanderse ]; nodes.machine = - { config, pkgs, ... }: + { ... }: { services.rsyslogd.enable = true; }; diff --git a/nixos/tests/systemd-journal.nix b/nixos/tests/systemd-journal.nix index e2867de95f64..64a8374f11d0 100644 --- a/nixos/tests/systemd-journal.nix +++ b/nixos/tests/systemd-journal.nix @@ -1,4 +1,4 @@ -{ pkgs, ... }: +{ lib, pkgs, ... }: { name = "systemd-journal"; @@ -14,7 +14,8 @@ security.audit.enable = true; }; nodes.journaldAudit = { - services.journald.audit = true; + # Verify that the module's option default remains overridable by downstream defaults. + services.journald.settings.Journal.Audit = lib.mkDefault true; security.audit.enable = true; }; nodes.containerCheck = { @@ -45,6 +46,7 @@ with subtest("journald audit"): journaldAudit.wait_for_unit("multi-user.target") + journaldAudit.succeed("grep -Fx 'Audit=true' /etc/systemd/journald.conf") # logs should end up in the journald journaldAudit.succeed("journalctl _TRANSPORT=audit --grep 'unit=systemd-journald'") diff --git a/nixos/tests/systemd.nix b/nixos/tests/systemd.nix index b04b288e8939..22ec4d68898a 100644 --- a/nixos/tests/systemd.nix +++ b/nixos/tests/systemd.nix @@ -35,7 +35,7 @@ KExecWatchdogSec = "5min"; }; systemd.user.settings.Manager.DefaultEnvironment = "\"XXX_USER=bar\""; - services.journald.extraConfig = "Storage=volatile"; + services.journald.settings.Journal.Storage = "volatile"; test-support.displayManager.auto.user = "alice"; systemd.shutdownRamfs.contents."/etc/systemd/system-shutdown/test".source = From 4b9b0e6ee7e5008a55126e084a4495d863f0958c Mon Sep 17 00:00:00 2001 From: r4v3n6101 Date: Tue, 25 Aug 2026 22:25:42 +0300 Subject: [PATCH 019/140] darkplaces: add darwin support --- pkgs/by-name/da/darkplaces/package.nix | 29 ++++++++++++++++++-------- 1 file changed, 20 insertions(+), 9 deletions(-) diff --git a/pkgs/by-name/da/darkplaces/package.nix b/pkgs/by-name/da/darkplaces/package.nix index 66181890271c..b6c7c21f6ed7 100644 --- a/pkgs/by-name/da/darkplaces/package.nix +++ b/pkgs/by-name/da/darkplaces/package.nix @@ -23,8 +23,13 @@ stdenv.mkDerivation { zlib libjpeg SDL2 - libx11 - ]; + ] + ++ lib.optionals stdenv.hostPlatform.isLinux [ libx11 ]; + + postPatch = lib.optionalString stdenv.hostPlatform.isDarwin '' + substituteInPlace makefile.inc \ + --replace-fail '$(SDLCONFIG_STATICLIBS)' '$(SDLCONFIG_LIBS)' + ''; buildFlags = [ "release" ]; @@ -38,12 +43,18 @@ stdenv.mkDerivation { runHook postInstall ''; - postFixup = '' - patchelf \ - --add-needed ${libvorbis}/lib/libvorbisfile.so \ - --add-needed ${libvorbis}/lib/libvorbis.so \ - $out/bin/darkplaces - ''; + postFixup = + lib.optionalString stdenv.hostPlatform.isLinux '' + patchelf \ + --add-needed ${libvorbis}/lib/libvorbisfile.so \ + --add-needed ${libvorbis}/lib/libvorbis.so \ + $out/bin/darkplaces + '' + + lib.optionalString stdenv.hostPlatform.isDarwin '' + ${stdenv.cc.targetPrefix}install_name_tool \ + -add_rpath ${lib.getLib libvorbis}/lib \ + $out/bin/darkplaces + ''; meta = { homepage = "https://www.icculus.org/twilight/darkplaces/"; @@ -56,6 +67,6 @@ stdenv.mkDerivation { ''; maintainers = with lib.maintainers; [ necrophcodr ]; license = lib.licenses.gpl2Plus; - platforms = lib.platforms.linux; + platforms = lib.platforms.linux ++ lib.platforms.darwin; }; } From 2452ba690cfa131ce5bb55b2974b99a01ac94709 Mon Sep 17 00:00:00 2001 From: Ihar Hrachyshka Date: Tue, 25 Aug 2026 23:04:29 -0400 Subject: [PATCH 020/140] firefox/wrapper: add appDataDir argument This is immediately helpful on MacOS 27+ where access to default datadir is now restricted to apps that are signed by Mozilla. Moving datadir to a new location implies a completely new profile will be created, unless users migrate their datadirs from the default location to the new one. Nixpkgs derivation cannot execute this migration for the users, nor it includes any tools to help with it. For this reason, users on 27+ will have to explicitly opt-in their firefox to use a new location, potentially also migrating their existing datadir beforehand. I expect Home Manager programs.firefox module to allow to set the argument to: ${cfg.home.homeDirectory}/Library/Application Support/org.nixos.firefox Other package consumers are advised to use the same directory for portability reasons. Fixes #535123 --- pkgs/applications/networking/browsers/firefox/wrapper.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/pkgs/applications/networking/browsers/firefox/wrapper.nix b/pkgs/applications/networking/browsers/firefox/wrapper.nix index 5976eb00cb86..2083d60b3656 100644 --- a/pkgs/applications/networking/browsers/firefox/wrapper.nix +++ b/pkgs/applications/networking/browsers/firefox/wrapper.nix @@ -71,6 +71,7 @@ let pkcs11Modules ? [ ], useGlvnd ? (!isDarwin), cfg ? config.${applicationName} or { }, + appDataDir ? null, ## Following options are needed for extra prefs & policies # For more information about anti tracking (german website) @@ -334,6 +335,11 @@ let "MOZ_ALLOW_DOWNGRADE" "1" ] + ++ lib.optionals (appDataDir != null) [ + "--set" + "MOZ_APP_DATA" + appDataDir + ] ++ lib.optionals (!isDarwin) [ "--suffix" "GTK_PATH" From 704cb65f3b542f23da3a70d5f2017d9fc9120b0b Mon Sep 17 00:00:00 2001 From: Ihar Hrachyshka Date: Tue, 25 Aug 2026 23:26:13 -0400 Subject: [PATCH 021/140] doc/rl-2611: mention Firefox appDataDir wrapper argument --- doc/release-notes/rl-2611.section.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/doc/release-notes/rl-2611.section.md b/doc/release-notes/rl-2611.section.md index cadc135ca33b..4474ca49d95c 100644 --- a/doc/release-notes/rl-2611.section.md +++ b/doc/release-notes/rl-2611.section.md @@ -185,6 +185,8 @@ They were missing before because Ceph omitted logs when this directory was missing. Ceph logs can grow large, so you may want to configure rotation of these logs. +- Firefox wrapper now accepts an optional `appDataDir` argument, which sets `MOZ_APP_DATA` to relocate Firefox application data. This is especially useful on macOS 27 and later, where wrapped Firefox applications may be denied access to profiles in traditional application data directory. + ## Nixpkgs Library {#sec-nixpkgs-release-26.11-lib} From 2434f97ee57768fd6c953d409b33927196947136 Mon Sep 17 00:00:00 2001 From: Jan Tojnar Date: Wed, 26 Aug 2026 09:11:34 +0200 Subject: [PATCH 022/140] nixos/selfoss: Allow overriding php-fpm pool user --- nixos/modules/services/web-apps/selfoss.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/nixos/modules/services/web-apps/selfoss.nix b/nixos/modules/services/web-apps/selfoss.nix index 6c1d4a0f46e5..acb7892b6fa9 100644 --- a/nixos/modules/services/web-apps/selfoss.nix +++ b/nixos/modules/services/web-apps/selfoss.nix @@ -123,7 +123,7 @@ in config = mkIf cfg.enable { services.phpfpm.pools = mkIf (cfg.pool == "${poolName}") { ${poolName} = { - user = config.services.nginx.user; + user = mkDefault config.services.nginx.user; settings = mapAttrs (name: mkDefault) { "listen.owner" = config.services.nginx.user; "listen.group" = config.services.nginx.group; From e72b010254c1db149aa9aede9bc98a0f562199fb Mon Sep 17 00:00:00 2001 From: Jan Tojnar Date: Wed, 26 Aug 2026 10:07:18 +0200 Subject: [PATCH 023/140] nixos/selfoss: Avoid `with` expression --- nixos/modules/services/web-apps/selfoss.nix | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/nixos/modules/services/web-apps/selfoss.nix b/nixos/modules/services/web-apps/selfoss.nix index acb7892b6fa9..38acd58883bf 100644 --- a/nixos/modules/services/web-apps/selfoss.nix +++ b/nixos/modules/services/web-apps/selfoss.nix @@ -4,8 +4,17 @@ pkgs, ... }: -with lib; + let + inherit (lib) + mapAttrs + mkDefault + mkEnableOption + mkIf + mkOption + types + ; + cfg = config.services.selfoss; poolName = "selfoss_pool"; From 9e122a71ee69f2c1bb89e5783c9944af33c1aaf5 Mon Sep 17 00:00:00 2001 From: Jan Tojnar Date: Wed, 26 Aug 2026 10:27:03 +0200 Subject: [PATCH 024/140] nixos/selfoss: Port to RFC42-style settings --- .../manual/release-notes/rl-2611.section.md | 9 + nixos/modules/services/web-apps/selfoss.nix | 189 +++++++++++------- 2 files changed, 124 insertions(+), 74 deletions(-) diff --git a/nixos/doc/manual/release-notes/rl-2611.section.md b/nixos/doc/manual/release-notes/rl-2611.section.md index deb30bbdc45c..527a890104aa 100644 --- a/nixos/doc/manual/release-notes/rl-2611.section.md +++ b/nixos/doc/manual/release-notes/rl-2611.section.md @@ -209,6 +209,15 @@ - The papra NixOS module is now hardening the systemd unit by default. If this breaks any of the configured directories, please reconfigure them through `services.papra.environment` to enable sandbox passthrough. +- `services.selfoss.extraConfig` and `services.selfoss.database` have been removed in favor of the structured [](#opt-services.selfoss.settings) option. When moving the `database` options to `settings`, you should also switch to the upstream naming: + + - `type` → [`db_type`](#opt-services.selfoss.settings.db_type) + - `host` → [`db_host`](#opt-services.selfoss.settings.db_host) + - `name` → [`db_database`](#opt-services.selfoss.settings.db_database) + - `username` → [`db_user`](#opt-services.selfoss.settings.db_user) + - `password` → [`db_password`](#opt-services.selfoss.settings.db_password) + - `port` → [`db_port`](#opt-services.selfoss.settings.db_port) + - `slskd` has been updated to v0.25.0, which renames the `global` option to `transfers`. Please review the [changelog](https://github.com/slskd/slskd/releases#release-0.25.0). - [firefox-syncserver.database.type](#opt-services.firefox-syncserver.database.type) no longer defaults to `"mysql"`. You must now explicitly choose between `"mysql"` and `"postgresql"`. New deployments should prefer PostgreSQL. diff --git a/nixos/modules/services/web-apps/selfoss.nix b/nixos/modules/services/web-apps/selfoss.nix index 38acd58883bf..88e088024c1c 100644 --- a/nixos/modules/services/web-apps/selfoss.nix +++ b/nixos/modules/services/web-apps/selfoss.nix @@ -21,25 +21,58 @@ let dataDir = "/var/lib/selfoss"; - selfoss-config = - let - db_type = cfg.database.type; - default_port = if (db_type == "mysql") then 3306 else 5342; - in - pkgs.writeText "selfoss-config.ini" '' - [globals] - ${lib.optionalString (db_type != "sqlite") '' - db_type=${db_type} - db_host=${cfg.database.host} - db_database=${cfg.database.name} - db_username=${cfg.database.user} - db_password=${cfg.database.password} - db_port=${toString (if (cfg.database.port != null) then cfg.database.port else default_port)} - ''} - ${cfg.extraConfig} - ''; + settingsFormat = pkgs.formats.iniWithGlobalSection { + mkKeyValue = lib.generators.mkKeyValueDefault { + mkValueString = + v: + if v == null then + "" + else if v == true then + "1" + else if v == false then + "0" + else + lib.generators.mkValueStringDefault { } v; + } "="; + }; + + selfoss-config = settingsFormat.generate "config.ini" { globalSection = cfg.settings; }; in { + imports = [ + (lib.mkRenamedOptionModule + [ "services" "selfoss" "database" "type" ] + [ "services" "selfoss" "settings" "db_type" ] + ) + (lib.mkRenamedOptionModule + [ "services" "selfoss" "database" "host" ] + [ "services" "selfoss" "settings" "db_host" ] + ) + (lib.mkRenamedOptionModule + [ "services" "selfoss" "database" "name" ] + [ "services" "selfoss" "settings" "db_database" ] + ) + (lib.mkRenamedOptionModule + [ "services" "selfoss" "database" "username" ] + [ "services" "selfoss" "settings" "db_user" ] + ) + (lib.mkRenamedOptionModule + [ "services" "selfoss" "database" "password" ] + [ "services" "selfoss" "settings" "db_password" ] + ) + (lib.mkRenamedOptionModule + [ "services" "selfoss" "database" "port" ] + [ "services" "selfoss" "settings" "db_port" ] + ) + (lib.mkRemovedOptionModule [ "services" "selfoss" "extraConfig" ] '' + Use services.selfoss.settings instead. + + This is part of the general move to use structured settings instead of raw + text for config as introduced by RFC0042: + https://github.com/NixOS/rfcs/blob/master/rfcs/0042-config-option.md + '') + ]; + options = { services.selfoss = { enable = mkEnableOption "selfoss"; @@ -63,67 +96,75 @@ in ''; }; - database = { - type = mkOption { - type = types.enum [ - "pgsql" - "mysql" - "sqlite" - ]; - default = "sqlite"; - description = '' - Database to store feeds. Supported are sqlite, pgsql and mysql. - ''; + settings = lib.mkOption { + type = lib.types.submodule { + # Only single level of config supported + freeformType = types.attrsOf settingsFormat.lib.types.atom; + + options = { + db_type = mkOption { + type = types.enum [ + "pgsql" + "mysql" + "sqlite" + ]; + default = "sqlite"; + description = '' + Database to store feeds. Supported are sqlite, pgsql and mysql. + ''; + }; + + db_host = mkOption { + type = types.str; + default = "localhost"; + description = '' + Host of the database (has no effect if type is "sqlite"). + ''; + }; + + db_database = mkOption { + type = types.str; + default = "tt_rss"; + description = '' + Name of the existing database (has no effect if type is "sqlite"). + ''; + }; + + db_user = mkOption { + type = types.str; + default = "tt_rss"; + description = '' + The database user. The user must exist and has access to + the specified database (has no effect if type is "sqlite"). + ''; + }; + + db_password = mkOption { + type = types.nullOr types.str; + default = null; + description = '' + The database user's password (has no effect if type is "sqlite"). + ''; + }; + + db_port = mkOption { + type = types.nullOr types.port; + default = null; + description = '' + The database's port. If not set, the default ports will be + provided (5432 and 3306 for pgsql and mysql respectively) + (has no effect if type is "sqlite"). + ''; + }; + }; }; - host = mkOption { - type = types.str; - default = "localhost"; - description = '' - Host of the database (has no effect if type is "sqlite"). - ''; - }; + default = { }; - name = mkOption { - type = types.str; - default = "tt_rss"; - description = '' - Name of the existing database (has no effect if type is "sqlite"). - ''; - }; - - user = mkOption { - type = types.str; - default = "tt_rss"; - description = '' - The database user. The user must exist and has access to - the specified database (has no effect if type is "sqlite"). - ''; - }; - - password = mkOption { - type = types.nullOr types.str; - default = null; - description = '' - The database user's password (has no effect if type is "sqlite"). - ''; - }; - - port = mkOption { - type = types.nullOr types.port; - default = null; - description = '' - The database's port. If not set, the default ports will be - provided (5432 and 3306 for pgsql and mysql respectively) - (has no effect if type is "sqlite"). - ''; - }; - }; - extraConfig = mkOption { - type = types.lines; - default = ""; description = '' - Extra configuration added to config.ini + Configuration for selfoss, see + + for supported values. ''; }; }; From 0b1b70d4fe793329d54ea5c661d911d7d5fa86f3 Mon Sep 17 00:00:00 2001 From: Jost Alemann Date: Thu, 27 Aug 2026 19:12:19 +0200 Subject: [PATCH 025/140] ruff: 0.16.4 -> 0.16.5 Changelog: https://github.com/astral-sh/ruff/releases/tag/0.16.5 Diff: https://github.com/astral-sh/ruff/compare/0.16.4...0.16.5 --- pkgs/by-name/ru/ruff/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ru/ruff/package.nix b/pkgs/by-name/ru/ruff/package.nix index 731f8fcbda6a..b9bec9e6ea83 100644 --- a/pkgs/by-name/ru/ruff/package.nix +++ b/pkgs/by-name/ru/ruff/package.nix @@ -16,7 +16,7 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "ruff"; - version = "0.16.4"; + version = "0.16.5"; __structuredAttrs = true; @@ -24,12 +24,12 @@ rustPlatform.buildRustPackage (finalAttrs: { owner = "astral-sh"; repo = "ruff"; tag = finalAttrs.version; - hash = "sha256-x6fIeDT8J0RVFzNEMm5QfOxcnGImJsJCMUMC+5mDPBI="; + hash = "sha256-M9sZjXxW9ig2Wfk8fDafgxsbV/QHM4ESUsONRHJEonE="; }; cargoBuildFlags = [ "--package=ruff" ]; - cargoHash = "sha256-kwnSLBK4H/RPUY+Nb08quRe3q9Ke5Sgmdf588b2QfUs="; + cargoHash = "sha256-6jY6JbKnlfij+Hao6KSGmiSirQNsBg4zlhk58dV2xcw="; nativeBuildInputs = [ installShellFiles ]; From 5167191691ecee9ed1db5b0f765d312a264012aa Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 27 Aug 2026 21:11:53 +0000 Subject: [PATCH 026/140] home-assistant-custom-components.localthings: 0.22.0 -> 0.24.0 --- .../home-assistant/custom-components/localthings/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/home-assistant/custom-components/localthings/package.nix b/pkgs/servers/home-assistant/custom-components/localthings/package.nix index 40aa0fa468fc..e9f6da454062 100644 --- a/pkgs/servers/home-assistant/custom-components/localthings/package.nix +++ b/pkgs/servers/home-assistant/custom-components/localthings/package.nix @@ -12,13 +12,13 @@ buildHomeAssistantComponent (finalAttrs: { owner = "mbillow"; domain = "localthings"; - version = "0.22.0"; + version = "0.24.0"; src = fetchFromGitHub { owner = "mbillow"; repo = "localthings"; tag = "v${finalAttrs.version}"; - hash = "sha256-fgpSB+/4FXiRmOdYPheLyKkcBa/Ltp902fUQIeOOBog="; + hash = "sha256-Qu+mVPUW3P6kghwEfvKGIABEHdgOO9+EATbX5Fqzk28="; }; dependencies = [ From c770124c9e2586beb6080468a43a5878a5d2e196 Mon Sep 17 00:00:00 2001 From: zowoq <59103226+zowoq@users.noreply.github.com> Date: Fri, 28 Aug 2026 21:51:01 +1000 Subject: [PATCH 027/140] grub2: use gnu mirror for locales URL --- pkgs/by-name/gr/grub2/package.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/by-name/gr/grub2/package.nix b/pkgs/by-name/gr/grub2/package.nix index 86a4890b0f4f..392a6ed6e794 100644 --- a/pkgs/by-name/gr/grub2/package.nix +++ b/pkgs/by-name/gr/grub2/package.nix @@ -100,7 +100,7 @@ let # but those translations are not versioned/stable. For that reason # we take them from the nearest release tarball instead: locales = fetchzip { - url = "https://ftp.gnu.org/gnu/grub/grub-${version}.tar.gz"; + url = "mirror://gnu/grub/grub-${version}.tar.gz"; hash = "sha256-NUlE6l8Ul3i1Si9mZgND6lnvFqc74EGptHV2iCtu+As="; }; From 2778556b64f9dcdfc6bab4c1106d4fdc0701df2b Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 28 Aug 2026 15:16:16 +0000 Subject: [PATCH 028/140] age-plugin-fido2prf: 0.3.0 -> 0.3.1 --- pkgs/by-name/ag/age-plugin-fido2prf/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ag/age-plugin-fido2prf/package.nix b/pkgs/by-name/ag/age-plugin-fido2prf/package.nix index 0665af9265d1..d2c9428f6b81 100644 --- a/pkgs/by-name/ag/age-plugin-fido2prf/package.nix +++ b/pkgs/by-name/ag/age-plugin-fido2prf/package.nix @@ -7,13 +7,13 @@ }: buildGoModule (finalAttrs: { pname = "age-plugin-fido2prf"; - version = "0.3.0"; + version = "0.3.1"; src = fetchFromGitHub { owner = "FiloSottile"; repo = "typage"; tag = "v${finalAttrs.version}"; - hash = "sha256-JGEn1xIzfLyoCWd/aRRG08Z/OoviEyZF+tGEfcj9DXw="; + hash = "sha256-vwE4u7xMHe0pGY/18ZbIAnoMyFyWlIbVbpQH4ZIbgZ8="; }; srcRoot = "${finalAttrs.src}/fido2prf/cmd/age-plugin-fido2prf"; From 6498e2e306332ec08253ebcabc590b16c4c48d6d Mon Sep 17 00:00:00 2001 From: Thiago Kenji Okada Date: Sat, 29 Aug 2026 15:58:44 +0100 Subject: [PATCH 029/140] nixos-rebuild-ng: create custom profile directory on set_profile() Fix #557687, and also make Profile model pure instead of having side-effects. --- .../src/nixos_rebuild/models.py | 1 - .../nixos-rebuild-ng/src/nixos_rebuild/nix.py | 9 +++++++ .../nixos-rebuild-ng/src/tests/test_main.py | 26 ++++++++++++++++--- .../nixos-rebuild-ng/src/tests/test_models.py | 5 +--- .../ni/nixos-rebuild-ng/src/tests/test_nix.py | 26 +++++++++++++++++++ 5 files changed, 59 insertions(+), 8 deletions(-) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py index ec84383e5f16..ad0aa384d02c 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py @@ -212,5 +212,4 @@ class Profile: return cls(name, Path("/nix/var/nix/profiles/system")) case _: path = Path("/nix/var/nix/profiles/system-profiles") / name - path.parent.mkdir(mode=0o755, parents=True, exist_ok=True) return cls(name, path) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py index eb59898b8561..bf3bb9046d28 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py @@ -690,6 +690,15 @@ def set_profile( ).strip() raise NixOSRebuildError(msg) + # Using custom profile, the target profile directory may not exist so we + # need to create it first + if profile.name != "system": + run_wrapper( + ["mkdir", "-p", profile.path.parent], + remote=target_host, + elevate=elevate, + ) + run_wrapper( ["nix-env", "-p", profile.path, "--set", path_to_config], remote=target_host, diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py index 221067f0bc08..bacfd86ef934 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_main.py @@ -610,7 +610,7 @@ def test_execute_nix_switch_flake(mock_run: Mock, tmp_path: Path) -> None: @patch("subprocess.run", autospec=True) @patch("uuid.uuid4", autospec=True) @patch(get_qualified_name(nr.services.cleanup_ssh), autospec=True) -def test_execute_nix_switch_build_target_host( +def test_execute_nix_switch_build_target_host_custom_profile( mock_cleanup_ssh: Mock, mock_uuid4: Mock, mock_run: Mock, @@ -654,10 +654,12 @@ def test_execute_nix_switch_build_target_host( "nixos-config=./configuration.nix", "-I", "nixpkgs=$HOME/.nix-defexpr/channels/pinned_nixpkgs", + "--profile-name", + "custom-profile", ] ) - assert mock_run.call_count == 12 + assert mock_run.call_count == 13 mock_run.assert_has_calls( [ call( @@ -791,6 +793,24 @@ def test_execute_nix_switch_build_target_host( check=True, **DEFAULT_RUN_KWARGS, ), + call( + [ + "ssh", + *nr.process.SSH_DEFAULT_OPTS, + "user@target-host", + "--", + "sudo", + "/bin/sh", + "-c", + """'exec /usr/bin/env -i PATH="${PATH-}" "$@"'""", + "sh", + "mkdir", + "-p", + "/nix/var/nix/profiles/system-profiles", + ], + check=True, + **DEFAULT_RUN_KWARGS, + ), call( [ "ssh", @@ -804,7 +824,7 @@ def test_execute_nix_switch_build_target_host( "sh", "nix-env", "-p", - "/nix/var/nix/profiles/system", + "/nix/var/nix/profiles/system-profiles/custom-profile", "--set", str(config_path), ], diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py index fa9a41f93a42..2be7e0af7c6d 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py @@ -205,19 +205,16 @@ def test_flake_from_arg( ) == m.Flake("/path/to", 'nixosConfigurations."remote-hostname"') -@patch("pathlib.Path.mkdir", autospec=True) -def test_profile_from_arg(mock_mkdir: Mock) -> None: +def test_profile_from_arg() -> None: assert m.Profile.from_arg("system") == m.Profile( "system", Path("/nix/var/nix/profiles/system"), ) - mock_mkdir.assert_not_called() assert m.Profile.from_arg("something") == m.Profile( "something", Path("/nix/var/nix/profiles/system-profiles/something"), ) - mock_mkdir.assert_called_once() def test_grouped_nix_args_flake_build_flags() -> None: diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py index 7917764a6f72..51b4cde3bfe0 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_nix.py @@ -749,6 +749,32 @@ def test_set_profile(mock_run: Mock) -> None: elevate=e.NO_ELEVATOR, ) + mock_run.reset_mock() + target_host = m.Remote("user@localhost", [], "ssh") + + n.set_profile( + m.Profile("something", profile_path), + config_path, + target_host=target_host, + elevate=e.NO_ELEVATOR, + ) + + mock_run.assert_has_calls( + [ + call( + ["mkdir", "-p", profile_path.parent], + remote=target_host, + elevate=e.NO_ELEVATOR, + ), + call( + ["nix-env", "-p", profile_path, "--set", config_path], + remote=target_host, + elevate=e.NO_ELEVATOR, + ), + ] + ) + + mock_run.reset_mock() mock_run.return_value = CompletedProcess([], 1) with pytest.raises(m.NixOSRebuildError) as exc: From 2420dbadd28a10346c35f5894c8a757a6abe7e84 Mon Sep 17 00:00:00 2001 From: Thiago Kenji Okada Date: Sat, 29 Aug 2026 16:00:06 +0100 Subject: [PATCH 030/140] nixos-rebuild-ng: refactor Profile model --- .../src/nixos_rebuild/models.py | 18 ++++++++++++------ .../nixos-rebuild-ng/src/nixos_rebuild/nix.py | 6 +++--- .../nixos-rebuild-ng/src/tests/test_models.py | 5 +++++ 3 files changed, 20 insertions(+), 9 deletions(-) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py index ad0aa384d02c..56aecb868bb6 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/models.py @@ -205,11 +205,17 @@ class Profile: name: str path: Path + @classmethod + def _is_custom_name(cls, name: str) -> bool: + return name != "system" + @classmethod def from_arg(cls, name: str) -> Self: - match name: - case "system": - return cls(name, Path("/nix/var/nix/profiles/system")) - case _: - path = Path("/nix/var/nix/profiles/system-profiles") / name - return cls(name, path) + if cls._is_custom_name(name): + path = Path("/nix/var/nix/profiles/system-profiles") / name + return cls(name, path) + else: + return cls(name, Path("/nix/var/nix/profiles/system")) + + def is_custom(self) -> bool: + return self._is_custom_name(self.name) diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py index bf3bb9046d28..40cd1ad9e345 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/nixos_rebuild/nix.py @@ -690,9 +690,9 @@ def set_profile( ).strip() raise NixOSRebuildError(msg) - # Using custom profile, the target profile directory may not exist so we - # need to create it first - if profile.name != "system": + if profile.is_custom(): + # Using custom profile, the target profile directory may not exist yet, + # so we need to create it first run_wrapper( ["mkdir", "-p", profile.path.parent], remote=target_host, diff --git a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py index 2be7e0af7c6d..b2bd2702cd6a 100644 --- a/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py +++ b/pkgs/by-name/ni/nixos-rebuild-ng/src/tests/test_models.py @@ -217,6 +217,11 @@ def test_profile_from_arg() -> None: ) +def test_profile_is_custom() -> None: + assert not m.Profile("system", Path()).is_custom() + assert m.Profile("something", Path()).is_custom() + + def test_grouped_nix_args_flake_build_flags() -> None: """Test that flake_build_flags excludes evaluation-only flags.""" from argparse import Namespace From cc5a6df10e79b66e0b4ec51b6001b5e43a32b6c0 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Gutyina=20Gerg=C5=91?= Date: Wed, 26 Aug 2026 21:45:01 +0000 Subject: [PATCH 031/140] pnpm_11: 11.22.0 -> 11.25.0 --- pkgs/development/tools/pnpm/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/tools/pnpm/default.nix b/pkgs/development/tools/pnpm/default.nix index b8a5e914c232..a2fe016c0a22 100644 --- a/pkgs/development/tools/pnpm/default.nix +++ b/pkgs/development/tools/pnpm/default.nix @@ -45,8 +45,8 @@ let hash = "sha256-zLXEecqxsAYhMlv+fUyaioAx56Ul1ySeJ17L7IGwjbI="; }; "11" = { - version = "11.22.0"; - hash = "sha256-V6l+byOj+v/AMVOk74x3CgVSYSuGQK6+Ob/dV1TQ69w="; + version = "11.25.0"; + hash = "sha256-M90HSPJ+eRbE8ci2lDRhmD40U7BrvaYxKmKAEwtIgeU="; }; }; From 8c3b3138b2ea5db1426fc3a34c23429419621cb7 Mon Sep 17 00:00:00 2001 From: rorosen Date: Sun, 30 Aug 2026 19:14:32 +0200 Subject: [PATCH 032/140] k3s_1_33: drop EOL, see https://kubernetes.io/releases/1.33/ --- .../cluster/k3s/1_33/chart-versions.nix | 10 ------- .../cluster/k3s/1_33/images-versions.json | 26 ------------------- .../networking/cluster/k3s/1_33/versions.nix | 21 --------------- .../networking/cluster/k3s/default.nix | 2 -- pkgs/top-level/aliases.nix | 1 + pkgs/top-level/all-packages.nix | 1 - 6 files changed, 1 insertion(+), 60 deletions(-) delete mode 100644 pkgs/applications/networking/cluster/k3s/1_33/chart-versions.nix delete mode 100644 pkgs/applications/networking/cluster/k3s/1_33/images-versions.json delete mode 100644 pkgs/applications/networking/cluster/k3s/1_33/versions.nix diff --git a/pkgs/applications/networking/cluster/k3s/1_33/chart-versions.nix b/pkgs/applications/networking/cluster/k3s/1_33/chart-versions.nix deleted file mode 100644 index d9f782df1b61..000000000000 --- a/pkgs/applications/networking/cluster/k3s/1_33/chart-versions.nix +++ /dev/null @@ -1,10 +0,0 @@ -{ - traefik-crd = { - url = "https://k3s.io/k3s-charts/assets/traefik-crd/traefik-crd-40.1.4+up40.1.0.tgz"; - sha256 = "0g79q6rb3n3i2v1qw3j5259pjfb9y1g4m9r9wpqrijhrsj2qjn6d"; - }; - traefik = { - url = "https://k3s.io/k3s-charts/assets/traefik/traefik-40.1.4+up40.1.0.tgz"; - sha256 = "0rvp9ch1rda4iv79hjc6236ldqv9xvzsfrqixbzz3ffmrppczsx9"; - }; -} diff --git a/pkgs/applications/networking/cluster/k3s/1_33/images-versions.json b/pkgs/applications/networking/cluster/k3s/1_33/images-versions.json deleted file mode 100644 index f183ab128fa6..000000000000 --- a/pkgs/applications/networking/cluster/k3s/1_33/images-versions.json +++ /dev/null @@ -1,26 +0,0 @@ -{ - "airgap-images-amd64-tar-gz": { - "url": "https://github.com/k3s-io/k3s/releases/download/v1.33.13%2Bk3s2/k3s-airgap-images-amd64.tar.gz", - "sha256": "49f2d99717503e1f9db527baedf7b4b3d0463f1ed3d4544940a234561c5651ba" - }, - "airgap-images-amd64-tar-zst": { - "url": "https://github.com/k3s-io/k3s/releases/download/v1.33.13%2Bk3s2/k3s-airgap-images-amd64.tar.zst", - "sha256": "7e59087b6a72e00db45a3bcb4f144114b13eb72dc8947c2b7908a0e1482b42b3" - }, - "airgap-images-arm-tar-gz": { - "url": "https://github.com/k3s-io/k3s/releases/download/v1.33.13%2Bk3s2/k3s-airgap-images-arm.tar.gz", - "sha256": "91e2deca0b39119d02c03495520542977712641ec142a81af0ad1fa1cbf4f362" - }, - "airgap-images-arm-tar-zst": { - "url": "https://github.com/k3s-io/k3s/releases/download/v1.33.13%2Bk3s2/k3s-airgap-images-arm.tar.zst", - "sha256": "b94244483badd6793f2e8d93de9d3125d4faf4a10b10047f289bee1e30bb1f44" - }, - "airgap-images-arm64-tar-gz": { - "url": "https://github.com/k3s-io/k3s/releases/download/v1.33.13%2Bk3s2/k3s-airgap-images-arm64.tar.gz", - "sha256": "35bbd4e5201c8c6a48776822b8e46d7067cff1875f86c3bde5de3bda37757584" - }, - "airgap-images-arm64-tar-zst": { - "url": "https://github.com/k3s-io/k3s/releases/download/v1.33.13%2Bk3s2/k3s-airgap-images-arm64.tar.zst", - "sha256": "47bc05eb1b21f0f76530a927ec5e1c5c2dec457f0190bf423e7be1d49348b5e6" - } -} diff --git a/pkgs/applications/networking/cluster/k3s/1_33/versions.nix b/pkgs/applications/networking/cluster/k3s/1_33/versions.nix deleted file mode 100644 index 00b7fc83a4bb..000000000000 --- a/pkgs/applications/networking/cluster/k3s/1_33/versions.nix +++ /dev/null @@ -1,21 +0,0 @@ -{ - k3sVersion = "1.33.13+k3s2"; - k3sCommit = "875e930d812e17f955cfb3a4817ad33cce3c6822"; - k3sRepoSha256 = "1hk3z4s2hhzdha894aai4jpl8nc5mkqb2sf7hywi8b11h8ckhv8n"; - k3sVendorHash = "sha256-jsGm6y94Kqd4SIDy00A5QpBylHIuTuirEbChpEKo2R8="; - chartVersions = import ./chart-versions.nix; - imagesVersions = builtins.fromJSON (builtins.readFile ./images-versions.json); - k3sRootVersion = "0.15.2"; - k3sRootSha256 = "0yxq2jqqb7flm4rs9dl7fqxba3mmwkmjbc8rx7pgai4qa1lzyigy"; - k3sCNIVersion = "1.9.1-k3s1"; - k3sCNISha256 = "1ggaz0p1c2k94car9d89a05smz3zx32sxn197b1l5kmjcnzdwadh"; - containerdVersion = "2.2.5-k3s1.33"; - containerdSha256 = "1al4zsyh3pz379ia0awhrlz7nyl2abyy0ayw0gl4gr6xjp7jsp1s"; - containerdPackage = "github.com/k3s-io/containerd/v2"; - criCtlVersion = "1.33.0-k3s2"; - flannelVersion = "v0.28.4"; - flannelPluginVersion = "v1.9.0-flannel1"; - kubeRouterVersion = "v2.6.3-k3s1"; - criDockerdVersion = "v0.3.19-k3s2"; - helmJobVersion = "v0.13.3-build20260727"; -} diff --git a/pkgs/applications/networking/cluster/k3s/default.nix b/pkgs/applications/networking/cluster/k3s/default.nix index fafe11745677..5722b7d8dd99 100644 --- a/pkgs/applications/networking/cluster/k3s/default.nix +++ b/pkgs/applications/networking/cluster/k3s/default.nix @@ -12,8 +12,6 @@ let extraArgs = removeAttrs args [ "callPackage" ]; in { - k3s_1_33 = common (import ./1_33/versions.nix) extraArgs; - k3s_1_34 = (common (import ./1_34/versions.nix) extraArgs).overrideAttrs { patches = [ ./go_runc_require.patch ]; }; diff --git a/pkgs/top-level/aliases.nix b/pkgs/top-level/aliases.nix index 8165b2de64f1..e3fc99c02c12 100644 --- a/pkgs/top-level/aliases.nix +++ b/pkgs/top-level/aliases.nix @@ -1208,6 +1208,7 @@ mapAliases { k3s_1_30 = throw "'k3s_1_30' has been removed from nixpkgs as it has reached end of life"; # Added 2025-09-01 k3s_1_31 = throw "'k3s_1_31' has been removed from nixpkgs as it has reached end of life"; # Added 2025-12-08 k3s_1_32 = throw "'k3s_1_32' has been removed from nixpkgs as it has reached end of life"; # Added 2026-03-31 + k3s_1_33 = throw "'k3s_1_33' has been removed from nixpkgs as it has reached end of life"; # Added 2026-08-30 k4dirstat = throw "'k4dirstat' has been removed due to outdated KF5 dependencies; consider using 'qdirstat' instead."; # Added 2026-05-01 kaffeine = throw "'kaffeine' has been removed due to outdated KF5 dependencies."; # Added 2026-05-01 kak-lsp = throw "'kak-lsp' has been renamed to/replaced by 'kakoune-lsp'"; # Converted to throw 2025-10-27 diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index fc4fc4613be1..061bbd7bf8b2 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -8789,7 +8789,6 @@ with pkgs; jackmix_jack1 = jackmix.override { jack = jack1; }; inherit (callPackage ../applications/networking/cluster/k3s { }) - k3s_1_33 k3s_1_34 k3s_1_35 k3s_1_36 From 34a13c1a3be160c0ce1eee4e3fe17cae4bc9de7a Mon Sep 17 00:00:00 2001 From: rorosen Date: Sun, 30 Aug 2026 21:25:39 +0200 Subject: [PATCH 033/140] k3s: enable structuredAttrs for all versions --- pkgs/applications/networking/cluster/k3s/builder.nix | 1 + pkgs/applications/networking/cluster/k3s/default.nix | 1 - 2 files changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/applications/networking/cluster/k3s/builder.nix b/pkgs/applications/networking/cluster/k3s/builder.nix index c6c5f758dfc8..9ca056a19d54 100644 --- a/pkgs/applications/networking/cluster/k3s/builder.nix +++ b/pkgs/applications/networking/cluster/k3s/builder.nix @@ -377,6 +377,7 @@ buildGoModule (finalAttrs: { pname = "k3s"; version = k3sVersion; pos = builtins.unsafeGetAttrPos "k3sVersion" attrs; + __structuredAttrs = true; tags = [ "libsqlite3" diff --git a/pkgs/applications/networking/cluster/k3s/default.nix b/pkgs/applications/networking/cluster/k3s/default.nix index 5722b7d8dd99..5a772f320760 100644 --- a/pkgs/applications/networking/cluster/k3s/default.nix +++ b/pkgs/applications/networking/cluster/k3s/default.nix @@ -21,7 +21,6 @@ in }; k3s_1_36 = (common (import ./1_36/versions.nix) extraArgs).overrideAttrs { - __structuredAttrs = true; patches = [ ./go_runc_require.patch ]; }; } From 3f485e99aff21d8da69ba60778d43e458056d41e Mon Sep 17 00:00:00 2001 From: rorosen Date: Sun, 30 Aug 2026 21:27:34 +0200 Subject: [PATCH 034/140] k3s: remove patch to require opencontainers/runc This patch is not needed anymore. Additionally, refactors default.nix slightly. --- .../networking/cluster/k3s/default.nix | 16 ++++------------ .../cluster/k3s/go_runc_require.patch | 18 ------------------ 2 files changed, 4 insertions(+), 30 deletions(-) delete mode 100644 pkgs/applications/networking/cluster/k3s/go_runc_require.patch diff --git a/pkgs/applications/networking/cluster/k3s/default.nix b/pkgs/applications/networking/cluster/k3s/default.nix index 5a772f320760..9b8933ef3e99 100644 --- a/pkgs/applications/networking/cluster/k3s/default.nix +++ b/pkgs/applications/networking/cluster/k3s/default.nix @@ -2,7 +2,7 @@ let k3s_builder = import ./builder.nix lib; - common = opts: callPackage (k3s_builder opts); + forVersions = versions: callPackage (k3s_builder (import versions)) extraArgs; # extraArgs is the extra arguments passed in by the caller to propagate downward. # This is to allow all-packages.nix to do: # @@ -12,15 +12,7 @@ let extraArgs = removeAttrs args [ "callPackage" ]; in { - k3s_1_34 = (common (import ./1_34/versions.nix) extraArgs).overrideAttrs { - patches = [ ./go_runc_require.patch ]; - }; - - k3s_1_35 = (common (import ./1_35/versions.nix) extraArgs).overrideAttrs { - patches = [ ./go_runc_require.patch ]; - }; - - k3s_1_36 = (common (import ./1_36/versions.nix) extraArgs).overrideAttrs { - patches = [ ./go_runc_require.patch ]; - }; + k3s_1_34 = forVersions ./1_34/versions.nix; + k3s_1_35 = forVersions ./1_35/versions.nix; + k3s_1_36 = forVersions ./1_36/versions.nix; } diff --git a/pkgs/applications/networking/cluster/k3s/go_runc_require.patch b/pkgs/applications/networking/cluster/k3s/go_runc_require.patch deleted file mode 100644 index 8d8d5912afd1..000000000000 --- a/pkgs/applications/networking/cluster/k3s/go_runc_require.patch +++ /dev/null @@ -1,18 +0,0 @@ -# Adds explicit require of opencontainers/runc to go.mod before version.sh is called and -# removes it afterwards so that later build commands don't complain about inconsistent -# vendoring. -diff --git a/scripts/package-cli b/scripts/package-cli -index a15d754926..bc450dbe4e 100755 ---- a/scripts/package-cli -+++ b/scripts/package-cli -@@ -3,7 +3,10 @@ set -e -x - - cd $(dirname $0)/.. - -+runc_require=$(grep "github.com/opencontainers/runc" go.mod | awk -F '=> ' '{print $2}' | xargs -0 printf 'require %s') -+echo "$runc_require" >> go.mod - . ./scripts/version.sh -+sed -i '$d' go.mod - - GO=${GO-go} - From 087ef34a8becb62aa8c23daeaefe684a9b458560 Mon Sep 17 00:00:00 2001 From: rorosen Date: Sun, 30 Aug 2026 18:45:26 +0200 Subject: [PATCH 035/140] k3s_1_34: 1.34.10+k3s1 -> 1.34.11+k3s1 Attention: This release upgrades Traefik chart to v40.x which includes a breaking change for the ingress-nginx migration: the provider name changes from kubernetesIngressNginx to kubernetesIngressNGINX. Check https://github.com/traefik/traefik-helm-chart/releases/tag/v40.0.0 for more details https://github.com/k3s-io/k3s/releases/tag/v1.34.11%2Bk3s1 --- .../cluster/k3s/1_34/images-versions.json | 24 +++++++++---------- .../networking/cluster/k3s/1_34/versions.nix | 12 +++++----- 2 files changed, 18 insertions(+), 18 deletions(-) diff --git a/pkgs/applications/networking/cluster/k3s/1_34/images-versions.json b/pkgs/applications/networking/cluster/k3s/1_34/images-versions.json index affe7822e17e..5bc57d772387 100644 --- a/pkgs/applications/networking/cluster/k3s/1_34/images-versions.json +++ b/pkgs/applications/networking/cluster/k3s/1_34/images-versions.json @@ -1,26 +1,26 @@ { "airgap-images-amd64-tar-gz": { - "url": "https://github.com/k3s-io/k3s/releases/download/v1.34.10%2Bk3s1/k3s-airgap-images-amd64.tar.gz", - "sha256": "e972a78ff6ba5a83ea80c36ac986e687ee2ce4181e0fe6104f98a48467094297" + "url": "https://github.com/k3s-io/k3s/releases/download/v1.34.11%2Bk3s1/k3s-airgap-images-amd64.tar.gz", + "sha256": "8347931329bd188ecfa7782e7c0b9509813a29f5b6481c7b1ab54238aef1cf1f" }, "airgap-images-amd64-tar-zst": { - "url": "https://github.com/k3s-io/k3s/releases/download/v1.34.10%2Bk3s1/k3s-airgap-images-amd64.tar.zst", - "sha256": "7e59087b6a72e00db45a3bcb4f144114b13eb72dc8947c2b7908a0e1482b42b3" + "url": "https://github.com/k3s-io/k3s/releases/download/v1.34.11%2Bk3s1/k3s-airgap-images-amd64.tar.zst", + "sha256": "807160da9a1b3ec86183a777241a6fe948d27fd6fdf3b88d0da39fa3b1ceeddc" }, "airgap-images-arm-tar-gz": { - "url": "https://github.com/k3s-io/k3s/releases/download/v1.34.10%2Bk3s1/k3s-airgap-images-arm.tar.gz", - "sha256": "718b9bf069aff3ffc9c3dd769abc30decf301ae90d06e47f33ed48e4957b9b3b" + "url": "https://github.com/k3s-io/k3s/releases/download/v1.34.11%2Bk3s1/k3s-airgap-images-arm.tar.gz", + "sha256": "c6c996e5aefd1ffb02f2fd089c29d26ae2b5a24e1c81b32f330e93612d1c38de" }, "airgap-images-arm-tar-zst": { - "url": "https://github.com/k3s-io/k3s/releases/download/v1.34.10%2Bk3s1/k3s-airgap-images-arm.tar.zst", - "sha256": "d24b30ad5536998219611cdb7ee20d2c821a9acb69fb3852dd892a1e082edf44" + "url": "https://github.com/k3s-io/k3s/releases/download/v1.34.11%2Bk3s1/k3s-airgap-images-arm.tar.zst", + "sha256": "57133711ae21010fd197fb666c631d7ac7c5a3f40533038b9a9d9e51ea066e5f" }, "airgap-images-arm64-tar-gz": { - "url": "https://github.com/k3s-io/k3s/releases/download/v1.34.10%2Bk3s1/k3s-airgap-images-arm64.tar.gz", - "sha256": "3040602c860a1827d11b6db19307e586300a271b2f5a7781909de47f32df4ea2" + "url": "https://github.com/k3s-io/k3s/releases/download/v1.34.11%2Bk3s1/k3s-airgap-images-arm64.tar.gz", + "sha256": "1f812132104de93d30d8d1f317e11cb263a8e44f9ef1abba07cf3eb178b8113e" }, "airgap-images-arm64-tar-zst": { - "url": "https://github.com/k3s-io/k3s/releases/download/v1.34.10%2Bk3s1/k3s-airgap-images-arm64.tar.zst", - "sha256": "dc1a8c0d10a40f2d0dc1d53c5c42f2b4e00a996b1573227bcbf2855c644d3025" + "url": "https://github.com/k3s-io/k3s/releases/download/v1.34.11%2Bk3s1/k3s-airgap-images-arm64.tar.zst", + "sha256": "18c53139e7ad39009057d5c52ec5501aeea1ada235986e43c7357a3863ff3fdd" } } diff --git a/pkgs/applications/networking/cluster/k3s/1_34/versions.nix b/pkgs/applications/networking/cluster/k3s/1_34/versions.nix index 464581ab7cf2..bee4de84a654 100644 --- a/pkgs/applications/networking/cluster/k3s/1_34/versions.nix +++ b/pkgs/applications/networking/cluster/k3s/1_34/versions.nix @@ -1,16 +1,16 @@ { - k3sVersion = "1.34.10+k3s1"; - k3sCommit = "39a4509ed98145d4f1eb8e15a8ca8362ca018afa"; - k3sRepoSha256 = "1r0far01pxbjvlrz7pjmx11k1hmvwr6xmkdcpf9iph64qlnwr4s3"; - k3sVendorHash = "sha256-ypwsQOkbda18/YLqM4v88RH4aKAxsagiocukYFnQHSw="; + k3sVersion = "1.34.11+k3s1"; + k3sCommit = "9312658016b9e33288b528da68bf88e37e6aeecf"; + k3sRepoSha256 = "0mk2i1ir93amv9aq37mmnzyj1zzq6nvgg81vfnw4da4ln5kvj878"; + k3sVendorHash = "sha256-QcGSnYXlG/+PFD+XGeVoCI/bh91YdW8sPUi4B0gFSC0="; chartVersions = import ./chart-versions.nix; imagesVersions = builtins.fromJSON (builtins.readFile ./images-versions.json); k3sRootVersion = "0.15.2"; k3sRootSha256 = "0yxq2jqqb7flm4rs9dl7fqxba3mmwkmjbc8rx7pgai4qa1lzyigy"; k3sCNIVersion = "1.9.1-k3s1"; k3sCNISha256 = "1ggaz0p1c2k94car9d89a05smz3zx32sxn197b1l5kmjcnzdwadh"; - containerdVersion = "2.2.5-k3s2"; - containerdSha256 = "1i9vkmf3gg34d9hjq15c00frhqxs9cba03zwg7qqq34gkb4qhjch"; + containerdVersion = "2.2.7-k3s1"; + containerdSha256 = "0zn64g6fzv8knan550ydbkgkaxa8qi2l8dw38w9g3hm8lv43nqyv"; containerdPackage = "github.com/k3s-io/containerd/v2"; criCtlVersion = "1.34.0-k3s2"; flannelVersion = "v0.28.4"; From 4bbf5fc812c9de99a394a0276743a9498c7cf6e5 Mon Sep 17 00:00:00 2001 From: rorosen Date: Sun, 30 Aug 2026 19:06:31 +0200 Subject: [PATCH 036/140] k3s_1_35: 1.35.7+k3s1 -> 1.35.8+k3s1 Attention: This release upgrades Traefik chart to v40.x which includes a breaking change for the ingress-nginx migration: the provider name changes from kubernetesIngressNginx to kubernetesIngressNGINX. Check https://github.com/traefik/traefik-helm-chart/releases/tag/v40.0.0 for more details https://github.com/k3s-io/k3s/releases/tag/v1.35.8%2Bk3s1 --- .../cluster/k3s/1_35/images-versions.json | 24 +++++++++---------- .../networking/cluster/k3s/1_35/versions.nix | 12 +++++----- 2 files changed, 18 insertions(+), 18 deletions(-) diff --git a/pkgs/applications/networking/cluster/k3s/1_35/images-versions.json b/pkgs/applications/networking/cluster/k3s/1_35/images-versions.json index d58cdb9b168a..d54f579310e1 100644 --- a/pkgs/applications/networking/cluster/k3s/1_35/images-versions.json +++ b/pkgs/applications/networking/cluster/k3s/1_35/images-versions.json @@ -1,26 +1,26 @@ { "airgap-images-amd64-tar-gz": { - "url": "https://github.com/k3s-io/k3s/releases/download/v1.35.7%2Bk3s1/k3s-airgap-images-amd64.tar.gz", - "sha256": "c109b42bce8de6f258be41f3f83393ff2693b7ede95bce0e80a1ff394b590507" + "url": "https://github.com/k3s-io/k3s/releases/download/v1.35.8%2Bk3s1/k3s-airgap-images-amd64.tar.gz", + "sha256": "a2893ea3234e01facd06cdb2ca879b65348fccf6b43be20501d72a949ece45f7" }, "airgap-images-amd64-tar-zst": { - "url": "https://github.com/k3s-io/k3s/releases/download/v1.35.7%2Bk3s1/k3s-airgap-images-amd64.tar.zst", - "sha256": "d28bbfef8a86b740e8235b6b2cfa6e29ecb0da457a55275d788a18d09142ee1f" + "url": "https://github.com/k3s-io/k3s/releases/download/v1.35.8%2Bk3s1/k3s-airgap-images-amd64.tar.zst", + "sha256": "807160da9a1b3ec86183a777241a6fe948d27fd6fdf3b88d0da39fa3b1ceeddc" }, "airgap-images-arm-tar-gz": { - "url": "https://github.com/k3s-io/k3s/releases/download/v1.35.7%2Bk3s1/k3s-airgap-images-arm.tar.gz", - "sha256": "589150e3493a5cd29bf7b8b57f9e3f7968c1b2d1f79e8a072352d63abb59e978" + "url": "https://github.com/k3s-io/k3s/releases/download/v1.35.8%2Bk3s1/k3s-airgap-images-arm.tar.gz", + "sha256": "08118b95556457b8a191357b329a42298d485b4597f720c14c5625d256f1e656" }, "airgap-images-arm-tar-zst": { - "url": "https://github.com/k3s-io/k3s/releases/download/v1.35.7%2Bk3s1/k3s-airgap-images-arm.tar.zst", - "sha256": "c6d57e5fb17ba142464bc8db9debfa701f560b4defa70c2e06981bf52cb9e26b" + "url": "https://github.com/k3s-io/k3s/releases/download/v1.35.8%2Bk3s1/k3s-airgap-images-arm.tar.zst", + "sha256": "3f502e7d64a87b5b5afc5ed8ed27febb73e090d81a5b7df9db51cfd5a7a144a1" }, "airgap-images-arm64-tar-gz": { - "url": "https://github.com/k3s-io/k3s/releases/download/v1.35.7%2Bk3s1/k3s-airgap-images-arm64.tar.gz", - "sha256": "b686b4c09dc335535889d5630ae5b0283d421d40af1029b271938cfd3b358f11" + "url": "https://github.com/k3s-io/k3s/releases/download/v1.35.8%2Bk3s1/k3s-airgap-images-arm64.tar.gz", + "sha256": "23d82e394d9ad41ea2912afaf0a6ead69bacede819c12678ba5dec22d16784da" }, "airgap-images-arm64-tar-zst": { - "url": "https://github.com/k3s-io/k3s/releases/download/v1.35.7%2Bk3s1/k3s-airgap-images-arm64.tar.zst", - "sha256": "47bc05eb1b21f0f76530a927ec5e1c5c2dec457f0190bf423e7be1d49348b5e6" + "url": "https://github.com/k3s-io/k3s/releases/download/v1.35.8%2Bk3s1/k3s-airgap-images-arm64.tar.zst", + "sha256": "18c53139e7ad39009057d5c52ec5501aeea1ada235986e43c7357a3863ff3fdd" } } diff --git a/pkgs/applications/networking/cluster/k3s/1_35/versions.nix b/pkgs/applications/networking/cluster/k3s/1_35/versions.nix index 3ccce4040e6a..ce3cb92a1f25 100644 --- a/pkgs/applications/networking/cluster/k3s/1_35/versions.nix +++ b/pkgs/applications/networking/cluster/k3s/1_35/versions.nix @@ -1,16 +1,16 @@ { - k3sVersion = "1.35.7+k3s1"; - k3sCommit = "cd43afc7151132bac92feacd3e4d2127ea1e70d0"; - k3sRepoSha256 = "1m9kwz8i1sqjgmc71qknmr87c9g8z7r2wl9440r32lfzxq8a6g1b"; - k3sVendorHash = "sha256-0MVOVrRWZ/xyTaRq5Nw5ogxIGZLArDVA1wiHmiwKqFA="; + k3sVersion = "1.35.8+k3s1"; + k3sCommit = "e952d68a5a5f8953c4549cf8fb557f3eae417107"; + k3sRepoSha256 = "07kpi9kl8pw4fyba474dap5hiskxays8qa8mf4qz6ai4wqapzg5c"; + k3sVendorHash = "sha256-2u9D2HLhiryOi8bwu5Tbv162WEoRbFfgePW7AeefuG8="; chartVersions = import ./chart-versions.nix; imagesVersions = builtins.fromJSON (builtins.readFile ./images-versions.json); k3sRootVersion = "0.15.2"; k3sRootSha256 = "0yxq2jqqb7flm4rs9dl7fqxba3mmwkmjbc8rx7pgai4qa1lzyigy"; k3sCNIVersion = "1.9.1-k3s1"; k3sCNISha256 = "1ggaz0p1c2k94car9d89a05smz3zx32sxn197b1l5kmjcnzdwadh"; - containerdVersion = "2.2.5-k3s2"; - containerdSha256 = "1i9vkmf3gg34d9hjq15c00frhqxs9cba03zwg7qqq34gkb4qhjch"; + containerdVersion = "2.2.7-k3s1"; + containerdSha256 = "0zn64g6fzv8knan550ydbkgkaxa8qi2l8dw38w9g3hm8lv43nqyv"; containerdPackage = "github.com/k3s-io/containerd/v2"; criCtlVersion = "1.35.0-k3s2"; flannelVersion = "v0.28.4"; From 69d6bd80b9e1bb390b590401b80bbba4a086b0c6 Mon Sep 17 00:00:00 2001 From: rorosen Date: Sun, 30 Aug 2026 21:31:16 +0200 Subject: [PATCH 037/140] k3s_1_36: 1.36.3+k3s1 -> 1.36.4+k3s1 Attention: This release upgrades Traefik chart to v40.x which includes a breaking change for the ingress-nginx migration: the provider name changes from kubernetesIngressNginx to kubernetesIngressNGINX. Check https://github.com/traefik/traefik-helm-chart/releases/tag/v40.0.0 for more details https://github.com/k3s-io/k3s/releases/tag/v1.36.4%2Bk3s1 --- .../cluster/k3s/1_36/images-versions.json | 24 +++++++++---------- .../networking/cluster/k3s/1_36/versions.nix | 12 +++++----- 2 files changed, 18 insertions(+), 18 deletions(-) diff --git a/pkgs/applications/networking/cluster/k3s/1_36/images-versions.json b/pkgs/applications/networking/cluster/k3s/1_36/images-versions.json index 2fd4b7681648..f9bfef30d60d 100644 --- a/pkgs/applications/networking/cluster/k3s/1_36/images-versions.json +++ b/pkgs/applications/networking/cluster/k3s/1_36/images-versions.json @@ -1,26 +1,26 @@ { "airgap-images-amd64-tar-gz": { - "url": "https://github.com/k3s-io/k3s/releases/download/v1.36.3%2Bk3s1/k3s-airgap-images-amd64.tar.gz", - "sha256": "e09e718f931ef094294781d3c35e58b84e2170acd5cc2edae075a20f58d1f89d" + "url": "https://github.com/k3s-io/k3s/releases/download/v1.36.4%2Bk3s1/k3s-airgap-images-amd64.tar.gz", + "sha256": "a5a6c970a992ce6ed5801b5fd090aa7edde354a786eb0e7d75b162d0b22901dd" }, "airgap-images-amd64-tar-zst": { - "url": "https://github.com/k3s-io/k3s/releases/download/v1.36.3%2Bk3s1/k3s-airgap-images-amd64.tar.zst", - "sha256": "a197d79e979cc3f4fa9bca8f500bd70092b25c1b5ebda68b35a25f792abd42b0" + "url": "https://github.com/k3s-io/k3s/releases/download/v1.36.4%2Bk3s1/k3s-airgap-images-amd64.tar.zst", + "sha256": "9024613e2d468c51ba0e5ba21898604c41339354449fb3338cc6a7931189eb6a" }, "airgap-images-arm-tar-gz": { - "url": "https://github.com/k3s-io/k3s/releases/download/v1.36.3%2Bk3s1/k3s-airgap-images-arm.tar.gz", - "sha256": "5e6b25d6cd2f6f25e663edf94a450e560a80b7a207c3d9f4d4646b688cceee5b" + "url": "https://github.com/k3s-io/k3s/releases/download/v1.36.4%2Bk3s1/k3s-airgap-images-arm.tar.gz", + "sha256": "519824fd8ab0096959164c319de4e28abb4677c1e6a10a2fd0bb8922c73e16d1" }, "airgap-images-arm-tar-zst": { - "url": "https://github.com/k3s-io/k3s/releases/download/v1.36.3%2Bk3s1/k3s-airgap-images-arm.tar.zst", - "sha256": "b94244483badd6793f2e8d93de9d3125d4faf4a10b10047f289bee1e30bb1f44" + "url": "https://github.com/k3s-io/k3s/releases/download/v1.36.4%2Bk3s1/k3s-airgap-images-arm.tar.zst", + "sha256": "31a0be5131bb87286209fa0ea2c91e73fda57aee622e162f5f0e54b6e53f8ce5" }, "airgap-images-arm64-tar-gz": { - "url": "https://github.com/k3s-io/k3s/releases/download/v1.36.3%2Bk3s1/k3s-airgap-images-arm64.tar.gz", - "sha256": "75fc0f7a1f8a9babf00e4a6bd5fadfb6657a3af1289fe3611eaf56f01e5ce735" + "url": "https://github.com/k3s-io/k3s/releases/download/v1.36.4%2Bk3s1/k3s-airgap-images-arm64.tar.gz", + "sha256": "5b66fde4e29681c09980d64bc77544769210abf8dcbd19dc210427ed12e0e8f8" }, "airgap-images-arm64-tar-zst": { - "url": "https://github.com/k3s-io/k3s/releases/download/v1.36.3%2Bk3s1/k3s-airgap-images-arm64.tar.zst", - "sha256": "856feb047453cd697c2bc4dcf20127448554c8366be992a211558a13d830a038" + "url": "https://github.com/k3s-io/k3s/releases/download/v1.36.4%2Bk3s1/k3s-airgap-images-arm64.tar.zst", + "sha256": "9d3c4c2197bcf857ca17633aa393bad683cc982ddd408620f93036a3cca953b5" } } diff --git a/pkgs/applications/networking/cluster/k3s/1_36/versions.nix b/pkgs/applications/networking/cluster/k3s/1_36/versions.nix index 35ac31d3f09f..a9afa6110624 100644 --- a/pkgs/applications/networking/cluster/k3s/1_36/versions.nix +++ b/pkgs/applications/networking/cluster/k3s/1_36/versions.nix @@ -1,16 +1,16 @@ { - k3sVersion = "1.36.3+k3s1"; - k3sCommit = "5aed4d7beddeb3e67120da477c876ac9efd70318"; - k3sRepoSha256 = "0y5lc93f5pdvgm3mmk87mh50z7iway4cz99nskfh1600zfhia2s6"; - k3sVendorHash = "sha256-pxYh1AJVZL8Xx23Nairoi5bSNNSVs+EqJbXF7ISN3wg="; + k3sVersion = "1.36.4+k3s1"; + k3sCommit = "4dedb15be78017a8ddd5b9e81acd44f3481078ed"; + k3sRepoSha256 = "07ynarjmjqybfyq30kaa08nx9rw5h83nifir050mplqjwb10mrk5"; + k3sVendorHash = "sha256-naO/9O5aLGNf7FwQvsvSb/eG0eCBFc/Um3yfH2fP+8Y="; chartVersions = import ./chart-versions.nix; imagesVersions = builtins.fromJSON (builtins.readFile ./images-versions.json); k3sRootVersion = "0.15.2"; k3sRootSha256 = "0yxq2jqqb7flm4rs9dl7fqxba3mmwkmjbc8rx7pgai4qa1lzyigy"; k3sCNIVersion = "1.9.1-k3s1"; k3sCNISha256 = "1ggaz0p1c2k94car9d89a05smz3zx32sxn197b1l5kmjcnzdwadh"; - containerdVersion = "2.3.2-k3s2"; - containerdSha256 = "1jzhkh0zg1s2922fkr4r5v1680apafkjqba8ic6br8nc8bk7j4xq"; + containerdVersion = "2.3.4-k3s1.36"; + containerdSha256 = "0mlazx89616j90s73953spi4ahcas8w9kb51a7qf02pa9isyz5vi"; containerdPackage = "github.com/k3s-io/containerd/v2"; criCtlVersion = "1.36.0-k3s1"; flannelVersion = "v0.28.4"; From a906f9e6860c798e690722f08182e1c071dcc278 Mon Sep 17 00:00:00 2001 From: Darren Rambaud <225436867+debtquity@users.noreply.github.com> Date: Mon, 31 Aug 2026 02:49:18 -0500 Subject: [PATCH 038/140] replibyte: fix `aarch64-darwin` build * both `--defsym` and `__rust_probestack=0` are unknown/invalid options during link on darwin systems using clang Resolves: #558280 --- pkgs/by-name/re/replibyte/package.nix | 13 ++++++++++++- 1 file changed, 12 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/re/replibyte/package.nix b/pkgs/by-name/re/replibyte/package.nix index ac985daae032..124dd6fdb1c6 100644 --- a/pkgs/by-name/re/replibyte/package.nix +++ b/pkgs/by-name/re/replibyte/package.nix @@ -1,5 +1,6 @@ { lib, + stdenv, rustPlatform, fetchFromGitHub, pkg-config, @@ -29,7 +30,17 @@ rustPlatform.buildRustPackage (finalAttrs: { # Fix undefined reference to `__rust_probestack` from wasmer_vm. # Define it as a no-op since it's only needed for stack overflow detection. - env.RUSTFLAGS = "-C link-arg=-Wl,--defsym,__rust_probestack=0"; + env.RUSTFLAGS = + let + linkArgs = [ + "-Wl" + ] + ++ lib.optionals stdenv.hostPlatform.isLinux [ + "--defsym" + "__rust_probestack=0" + ]; + in + "-C link-arg=${builtins.concatStringsSep "," linkArgs}"; cargoBuildFlags = [ "--all-features" ]; From c4d0fc08a479907e56e38c2b8ba00487d3d9495e Mon Sep 17 00:00:00 2001 From: nitinbhat972 Date: Mon, 31 Aug 2026 16:29:09 +0530 Subject: [PATCH 039/140] cwal: 0.9.0 -> 0.10.0 - migrate build from cmake to nob (CMakeLists removed upstream) - remove cmake from nativeBuildInputs, use cc nob.c -o nob && ./nob build - patch INSTALL_DIR to $out and use nob install --- pkgs/by-name/cw/cwal/package.nix | 29 +++++++++++++++++++++++------ 1 file changed, 23 insertions(+), 6 deletions(-) diff --git a/pkgs/by-name/cw/cwal/package.nix b/pkgs/by-name/cw/cwal/package.nix index 0bf13b9a0e1c..75e7bb72d197 100644 --- a/pkgs/by-name/cw/cwal/package.nix +++ b/pkgs/by-name/cw/cwal/package.nix @@ -2,8 +2,7 @@ lib, stdenv, fetchFromGitHub, - cmake, - pkg-config, + pkgconf, imagemagick, libimagequant, luajit, @@ -12,20 +11,19 @@ stdenv.mkDerivation (finalAttrs: { pname = "cwal"; - version = "0.9.0"; + version = "0.10.0"; src = fetchFromGitHub { owner = "nitinbhat972"; repo = "cwal"; rev = "v${finalAttrs.version}"; - hash = "sha256-RDtYBgqTG3Ycn1D6QtaHGZVXKxw8UqhzssxXA4temYo="; + hash = "sha256-hQ2N/lSUp1FduYG0tPOVP68QeOQyi7luEkys3A697LU="; }; strictDeps = true; nativeBuildInputs = [ - cmake - pkg-config + pkgconf makeBinaryWrapper ]; @@ -35,6 +33,25 @@ stdenv.mkDerivation (finalAttrs: { luajit ]; + postPatch = '' + substituteInPlace config.h \ + --replace-fail '#define INSTALL_DIR "/usr"' \ + "#define INSTALL_DIR \"$out\"" + ''; + + buildPhase = '' + runHook preBuild + cc nob.c -o nob + ./nob build + runHook postBuild + ''; + + installPhase = '' + runHook preInstall + ./nob install + runHook postInstall + ''; + postFixup = '' wrapProgram $out/bin/cwal \ --prefix XDG_DATA_DIRS : $out/share From 6ea306ead64da8e798dba815cc169663176ed82c Mon Sep 17 00:00:00 2001 From: Weijia Wang <9713184+wegank@users.noreply.github.com> Date: Mon, 31 Aug 2026 14:26:57 +0200 Subject: [PATCH 040/140] python3Packages.{pyqt6-,}qscintilla: use top-level callPackage Assisted-by: Claude Code (Claude Opus 5) --- .../python-modules/qscintilla/default.nix | 39 ++++++++++++------- pkgs/top-level/python-packages.nix | 8 ++-- 2 files changed, 27 insertions(+), 20 deletions(-) diff --git a/pkgs/development/python-modules/qscintilla/default.nix b/pkgs/development/python-modules/qscintilla/default.nix index 4e757881f66a..64e10176c298 100644 --- a/pkgs/development/python-modules/qscintilla/default.nix +++ b/pkgs/development/python-modules/qscintilla/default.nix @@ -2,25 +2,34 @@ lib, stdenv, - pythonPackages, - qmake, - qscintilla, - qtbase, - qtmacextras ? null, + buildPythonPackage, + isPy3k, + python, + pyqt-builder, + pyqt5, + pyqt6, + setuptools, + sip, + + libsForQt5, + qt6Packages, + + useQt6 ? true, }: let - qtVersion = lib.versions.major qtbase.version; - pyQtPackage = pythonPackages."pyqt${qtVersion}"; + qtPackages = if useQt6 then qt6Packages else libsForQt5; - inherit (pythonPackages) - isPy3k - python - sip - pyqt-builder + inherit (qtPackages) + qmake + qscintilla + qtbase ; + + qtVersion = lib.versions.major qtbase.version; + pyQtPackage = if useQt6 then pyqt6 else pyqt5; in -pythonPackages.buildPythonPackage { +buildPythonPackage { # Matches the `name` declared in Python/pyproject-qt${qtVersion}.toml upstream, # which is inconsistent between Qt5 ("QScintilla") and Qt6 ("PyQt6-QScintilla"). pname = if qtVersion == "5" then "qscintilla" else "pyqt${qtVersion}-qscintilla"; @@ -35,7 +44,7 @@ pythonPackages.buildPythonPackage { qmake pyqt-builder qscintilla - pythonPackages.setuptools + setuptools ]; buildInputs = [ qtbase ]; @@ -43,7 +52,7 @@ pythonPackages.buildPythonPackage { propagatedBuildInputs = [ pyQtPackage ] - ++ lib.optionals stdenv.hostPlatform.isDarwin [ qtmacextras ]; + ++ lib.optionals (stdenv.hostPlatform.isDarwin && !useQt6) [ libsForQt5.qtmacextras ]; dontWrapQtApps = true; diff --git a/pkgs/top-level/python-packages.nix b/pkgs/top-level/python-packages.nix index 5915aeeab4ef..d6a849caae8a 100644 --- a/pkgs/top-level/python-packages.nix +++ b/pkgs/top-level/python-packages.nix @@ -15833,9 +15833,7 @@ self: super: with self; { inherit (pkgs) mesa; }; - pyqt6-qscintilla = pkgs.qt6Packages.callPackage ../development/python-modules/qscintilla { - pythonPackages = self; - }; + pyqt6-qscintilla = callPackage ../development/python-modules/qscintilla { }; pyqt6-sip = callPackage ../development/python-modules/pyqt/pyqt6-sip.nix { inherit (pkgs) mesa; @@ -17589,8 +17587,8 @@ self: super: with self; { qreactor = callPackage ../development/python-modules/qreactor { }; - qscintilla = pkgs.libsForQt5.callPackage ../development/python-modules/qscintilla { - pythonPackages = self; + qscintilla = callPackage ../development/python-modules/qscintilla { + useQt6 = false; }; qstylizer = callPackage ../development/python-modules/qstylizer { }; From a369bb4954e0477056cb432db738258284444f4f Mon Sep 17 00:00:00 2001 From: nitinbhat972 Date: Mon, 31 Aug 2026 18:19:45 +0530 Subject: [PATCH 041/140] cwal: 0.10.0 -> 0.10.1 --- pkgs/by-name/cw/cwal/package.nix | 11 ++--------- 1 file changed, 2 insertions(+), 9 deletions(-) diff --git a/pkgs/by-name/cw/cwal/package.nix b/pkgs/by-name/cw/cwal/package.nix index 75e7bb72d197..4b1e32eb7fbe 100644 --- a/pkgs/by-name/cw/cwal/package.nix +++ b/pkgs/by-name/cw/cwal/package.nix @@ -6,25 +6,23 @@ imagemagick, libimagequant, luajit, - makeBinaryWrapper, }: stdenv.mkDerivation (finalAttrs: { pname = "cwal"; - version = "0.10.0"; + version = "0.10.1"; src = fetchFromGitHub { owner = "nitinbhat972"; repo = "cwal"; rev = "v${finalAttrs.version}"; - hash = "sha256-hQ2N/lSUp1FduYG0tPOVP68QeOQyi7luEkys3A697LU="; + hash = "sha256-n9v2EiW1wRMsYoNk+m20qQao52vvmD6NDM8Z/oEyjbU="; }; strictDeps = true; nativeBuildInputs = [ pkgconf - makeBinaryWrapper ]; buildInputs = [ @@ -52,11 +50,6 @@ stdenv.mkDerivation (finalAttrs: { runHook postInstall ''; - postFixup = '' - wrapProgram $out/bin/cwal \ - --prefix XDG_DATA_DIRS : $out/share - ''; - meta = { description = "Blazing-fast pywal-like color palette generator written in C"; homepage = "https://github.com/nitinbhat972/cwal"; From b03ae3bded84ef543af3b722ad0ea09d847907e0 Mon Sep 17 00:00:00 2001 From: "Adam C. Stephens" Date: Mon, 31 Aug 2026 10:32:47 -0400 Subject: [PATCH 042/140] victoriametrics: 1.150.0 -> 1.151.0 Changelog: https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.151.0 --- pkgs/by-name/vi/victoriametrics/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/vi/victoriametrics/package.nix b/pkgs/by-name/vi/victoriametrics/package.nix index f0361b1f915c..c03666eef1af 100644 --- a/pkgs/by-name/vi/victoriametrics/package.nix +++ b/pkgs/by-name/vi/victoriametrics/package.nix @@ -14,13 +14,13 @@ buildGoModule (finalAttrs: { pname = "VictoriaMetrics"; - version = "1.150.0"; + version = "1.151.0"; src = fetchFromGitHub { owner = "VictoriaMetrics"; repo = "VictoriaMetrics"; tag = "v${finalAttrs.version}"; - hash = "sha256-fY8rfWuMk46sNiS+IhQYINxoasmHhUJzBKI2ocROZR8="; + hash = "sha256-LMilqB2enkzZr3zLcwnDLojtFV/lcOsXA9EhjiFarqE="; }; vendorHash = null; From 8def184688d68da75e1134e63414bb3273eb7ab0 Mon Sep 17 00:00:00 2001 From: coolcuber Date: Mon, 31 Aug 2026 17:04:08 -0400 Subject: [PATCH 043/140] hash_extender: fix version, modernize --- pkgs/by-name/ha/hash_extender/package.nix | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ha/hash_extender/package.nix b/pkgs/by-name/ha/hash_extender/package.nix index af192e02f956..c88185bcac1e 100644 --- a/pkgs/by-name/ha/hash_extender/package.nix +++ b/pkgs/by-name/ha/hash_extender/package.nix @@ -8,13 +8,16 @@ stdenv.mkDerivation { pname = "hash_extender"; - version = "unstable-2020-03-24"; + version = "0-unstable-2020-03-24"; + + strictDeps = true; + __structuredAttrs = true; src = fetchFromGitHub { owner = "iagox86"; repo = "hash_extender"; rev = "cb8aaee49f93e9c0d2f03eb3cafb429c9eed723d"; - sha256 = "1fj118566hr1wv03az2w0iqknazsqqkak0mvlcvwpgr6midjqi9b"; + hash = "sha256-K0UsW6wmv8s3o7uCqSbG+is7cQRcfDXA5iFDYwoKQbo="; }; patches = [ From 52687a57845d319be7ac0c43b079d37510870e11 Mon Sep 17 00:00:00 2001 From: Jost Alemann Date: Mon, 31 Aug 2026 20:07:12 +0200 Subject: [PATCH 044/140] ty: 0.0.75 -> 0.0.77 Changelog: https://github.com/astral-sh/ty/releases/tag/0.0.77 Diff: https://github.com/astral-sh/ty/compare/0.0.75...0.0.77 Skipping another seemingly flaky test --- pkgs/by-name/ty/ty/package.nix | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ty/ty/package.nix b/pkgs/by-name/ty/ty/package.nix index 4fffcf5b083b..8c0b34999a3e 100644 --- a/pkgs/by-name/ty/ty/package.nix +++ b/pkgs/by-name/ty/ty/package.nix @@ -17,7 +17,7 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "ty"; - version = "0.0.75"; + version = "0.0.77"; __structuredAttrs = true; src = fetchFromGitHub { @@ -25,7 +25,7 @@ rustPlatform.buildRustPackage (finalAttrs: { repo = "ty"; tag = finalAttrs.version; fetchSubmodules = true; - hash = "sha256-hzEgbimysGMH+bQoKmTOWZl8DgaW/G1QUkI5T18UMp4="; + hash = "sha256-xg62mzRpDSgkehwbxCC3EHKk9xG9UhX0WhPL2aqAZP4="; }; # For Darwin platforms, remove the integration test for file notifications, @@ -39,7 +39,7 @@ rustPlatform.buildRustPackage (finalAttrs: { cargoBuildFlags = [ "--package=ty" ]; - cargoHash = "sha256-TSvfiHsXyn1MLUwfi+9ZxWH5AqKhkPPU297lL5nL7fI="; + cargoHash = "sha256-TsspMKOxq5rh6dNWev297FQYi27n2ncQ1gUx9469WwY="; nativeBuildInputs = [ installShellFiles ]; buildInputs = [ rust-jemalloc-sys ]; @@ -72,6 +72,10 @@ rustPlatform.buildRustPackage (finalAttrs: { # flaky: unmatched assertion: revealed: Literal[1] "--skip=mdtest::generics/pep695/functions.md" + + # flaky: https://github.com/astral-sh/ty/issues/1540 + # fails with: Indexed project files contains '/build/.tmpOzGFH2/project/bar/baz.py' which was not expected. + "--skip=unix::symlink_inside_project" ]; nativeInstallCheckInputs = [ versionCheckHook ]; From 32d69257d4dfca43faac512bfe84179d59f23b52 Mon Sep 17 00:00:00 2001 From: Roman Maksimovich Date: Tue, 1 Sep 2026 13:16:30 +0800 Subject: [PATCH 045/140] pshash: 0.1.16.0 -> 0.1.20.2 --- pkgs/by-name/ps/pshash/package.nix | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ps/pshash/package.nix b/pkgs/by-name/ps/pshash/package.nix index 8f7579fe23d1..5055f26c7ea1 100644 --- a/pkgs/by-name/ps/pshash/package.nix +++ b/pkgs/by-name/ps/pshash/package.nix @@ -5,12 +5,12 @@ }: haskellPackages.mkDerivation rec { pname = "pshash"; - version = "0.1.16.0"; + version = "0.1.20.2"; src = fetchFromGitHub { owner = "thornoar"; repo = "pshash"; tag = "v${version}"; - hash = "sha256-3Qe52Hto3Z96b5q9TLz7XB7BzMfdNBd4p8V6dknH6VM="; + hash = "sha256-MQPOvVGWD2PeMf84asYlM5toEKJjOzGDrHKyqJTeSgg="; }; postPatch = '' @@ -31,6 +31,7 @@ haskellPackages.mkDerivation rec { base containers directory + random ]; license = lib.licenses.mit; From d43115bef1d6957dab5eab4a239b0b107a352acd Mon Sep 17 00:00:00 2001 From: "Dr. Jonathan Berrisch" Date: Tue, 1 Sep 2026 15:17:13 +0200 Subject: [PATCH 046/140] nixos/nixosTests.firewall-nftables: fix race condition Replaces grep -qF by grep -F. grep -q can close the pipe before switch-to-configuration is done writing, which panics it (SIGPIPE is ignored, so println!() fails instead). Also moves the connections test after the reload check as it stops the service. Once stopped `switch-to-configuration-ng` only picks up the service reload by a timing-dependent fallback (wait for D-Bus activity to settle, then re-check which units became newly active). Under CI load, that wait can finish before the unit is actually restarted. So the test becomes flaky. Moving the reload-check before the connections test ensures that the service is still active so `switch-to-configuration-ng` reliably picks up the reload. --- nixos/tests/firewall.nix | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/nixos/tests/firewall.nix b/nixos/tests/firewall.nix index 5c2e94fccac4..1aaddc0eb469 100644 --- a/nixos/tests/firewall.nix +++ b/nixos/tests/firewall.nix @@ -121,13 +121,13 @@ walled.succeed("${reset}") attacker.fail("curl --fail --connect-timeout 2 http://walled/ >&2") + # Check whether activation of a new configuration reloads the firewall. + walled.succeed( + "/run/booted-system/specialisation/different-config/bin/switch-to-configuration test 2>&1 | grep -F ${unit}.service" + ) + # If we stop the firewall, then connections should succeed. walled.stop_job("${unit}") attacker.succeed("curl -v http://walled/ >&2") - - # Check whether activation of a new configuration reloads the firewall. - walled.succeed( - "/run/booted-system/specialisation/different-config/bin/switch-to-configuration test 2>&1 | grep -qF ${unit}.service" - ) ''; } From 35bc343dfedbc8fc6bcfbaa762def2b1208448e1 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 1 Sep 2026 13:25:25 +0000 Subject: [PATCH 047/140] prometheus-snowflake-exporter: 0-unstable-2026-07-02 -> latest-unstable-2026-08-26 --- pkgs/by-name/pr/prometheus-snowflake-exporter/package.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/pr/prometheus-snowflake-exporter/package.nix b/pkgs/by-name/pr/prometheus-snowflake-exporter/package.nix index 85f2e0152755..a5ef45a5913a 100644 --- a/pkgs/by-name/pr/prometheus-snowflake-exporter/package.nix +++ b/pkgs/by-name/pr/prometheus-snowflake-exporter/package.nix @@ -10,18 +10,18 @@ buildGoModule (finalAttrs: { pname = "prometheus-snowflake-exporter"; # No tagged release upstream (only a moving `latest` tag), so pin the commit and # use nixpkgs' unstable versioning. Bump the date + rev on update. - version = "0-unstable-2026-07-02"; + version = "latest-unstable-2026-08-26"; __structuredAttrs = true; src = fetchFromGitHub { owner = "grafana"; repo = "snowflake-prometheus-exporter"; - rev = "d9447d3401aa81b26c091775606c502bf8e2d7cd"; - hash = "sha256-3yaZ2kk2k5ivUNgRNazYjA38zY4dvsTOrkvftQpCW5A="; + rev = "744f67a6217d27d96ea664868cd19fa19595b45c"; + hash = "sha256-UdMU4Z6dOzsMEuctQJBlkI/MxsCrZ4O092F0HSUTgLc="; }; - vendorHash = "sha256-HvlZ5g1LqAoXuFuidmHCMTeFfivqUR2ryAh0hQayxnc="; + vendorHash = "sha256-QQKTxRBlx6v5gFOpQccYvMkRzwtjYaemheE3CMyA7W8="; ldflags = [ "-s" From 0956f7848d14761ea47994e4bf54cbe79c071db8 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 1 Sep 2026 13:40:20 +0000 Subject: [PATCH 048/140] daktari: 0.0.350 -> 0.0.353 --- pkgs/by-name/da/daktari/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/da/daktari/package.nix b/pkgs/by-name/da/daktari/package.nix index 5b4db545a25a..57df71b2be52 100644 --- a/pkgs/by-name/da/daktari/package.nix +++ b/pkgs/by-name/da/daktari/package.nix @@ -7,7 +7,7 @@ python3Packages.buildPythonApplication (finalAttrs: { pname = "daktari"; - version = "0.0.350"; + version = "0.0.353"; pyproject = true; __structuredAttrs = true; @@ -15,7 +15,7 @@ python3Packages.buildPythonApplication (finalAttrs: { owner = "genio-learn"; repo = "daktari"; tag = "v${finalAttrs.version}"; - hash = "sha256-JpLY+s88UcNgpy6K7+ZmLUCDlxqNtbuW3wIz8phy7Ag="; + hash = "sha256-gVch0gfuUd6/33z6KK7hTHOjG0rPaBThruqMLHf+2PA="; }; patches = [ ./optional-pyclip.patch ]; From 7d9ee47930b91a2e122a7b75ffe8b987e364f9a6 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 1 Sep 2026 13:58:06 +0000 Subject: [PATCH 049/140] vscode-extensions.tsandall.opa: 0.24.1 -> 0.25.0 --- pkgs/applications/editors/vscode/extensions/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/editors/vscode/extensions/default.nix b/pkgs/applications/editors/vscode/extensions/default.nix index c7fbbe452865..433c1ff638c0 100644 --- a/pkgs/applications/editors/vscode/extensions/default.nix +++ b/pkgs/applications/editors/vscode/extensions/default.nix @@ -4885,8 +4885,8 @@ let mktplcRef = { name = "opa"; publisher = "tsandall"; - version = "0.24.1"; - hash = "sha256-wNlZM9/2K32W4vYPKzLiBCTqhV+SqgZzXGRxKoHoIaM="; + version = "0.25.0"; + hash = "sha256-d+INOMEc4ZO3T3326GxQW3PP/UflOwmEPfQOm2weVRY="; }; meta = { changelog = "https://github.com/open-policy-agent/vscode-opa/blob/master/CHANGELOG.md"; From 03192a1ad238d5093b25938d24ba419e310e215a Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 1 Sep 2026 14:18:25 +0000 Subject: [PATCH 050/140] gobgp: 4.8.0 -> 4.9.0 --- pkgs/by-name/go/gobgp/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/go/gobgp/package.nix b/pkgs/by-name/go/gobgp/package.nix index 6d26953e8377..7f974cda8684 100644 --- a/pkgs/by-name/go/gobgp/package.nix +++ b/pkgs/by-name/go/gobgp/package.nix @@ -6,13 +6,13 @@ buildGoModule (finalAttrs: { pname = "gobgp"; - version = "4.8.0"; + version = "4.9.0"; src = fetchFromGitHub { owner = "osrg"; repo = "gobgp"; rev = "v${finalAttrs.version}"; - sha256 = "sha256-nU/HjHi0nKQy8SelwKSHneRjaRVNfvif4dljhPpUZrI="; + sha256 = "sha256-52eJtAQfDF76vvLQMxnttPgXppaumZcZ/toOoLeYBu8="; }; vendorHash = "sha256-9r8LZlCF4sr8VTyJfDktjhk32afc8ep7GXtqxUnAleE="; From 954ce6f12b87d13349acae5bf22cb06155e5cdb4 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 1 Sep 2026 14:18:38 +0000 Subject: [PATCH 051/140] gobgpd: 4.8.0 -> 4.9.0 --- pkgs/by-name/go/gobgpd/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/go/gobgpd/package.nix b/pkgs/by-name/go/gobgpd/package.nix index f6eb0a287a49..eb64b2546b46 100644 --- a/pkgs/by-name/go/gobgpd/package.nix +++ b/pkgs/by-name/go/gobgpd/package.nix @@ -7,13 +7,13 @@ buildGoModule (finalAttrs: { pname = "gobgpd"; - version = "4.8.0"; + version = "4.9.0"; src = fetchFromGitHub { owner = "osrg"; repo = "gobgp"; tag = "v${finalAttrs.version}"; - hash = "sha256-nU/HjHi0nKQy8SelwKSHneRjaRVNfvif4dljhPpUZrI="; + hash = "sha256-52eJtAQfDF76vvLQMxnttPgXppaumZcZ/toOoLeYBu8="; }; vendorHash = "sha256-9r8LZlCF4sr8VTyJfDktjhk32afc8ep7GXtqxUnAleE="; From 6773e4b401138fd0f5c519582953d3f45195f30b Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 1 Sep 2026 14:49:19 +0000 Subject: [PATCH 052/140] ergo: 6.0.4 -> 6.0.5 --- pkgs/by-name/er/ergo/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/er/ergo/package.nix b/pkgs/by-name/er/ergo/package.nix index 27c2cf09dcdc..aa29ccc07cc1 100644 --- a/pkgs/by-name/er/ergo/package.nix +++ b/pkgs/by-name/er/ergo/package.nix @@ -9,11 +9,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "ergo"; - version = "6.0.4"; + version = "6.0.5"; src = fetchurl { url = "https://github.com/ergoplatform/ergo/releases/download/v${finalAttrs.version}/ergo-${finalAttrs.version}.jar"; - sha256 = "sha256-PeFQiRx+oE9cbNSPjVPU5/q7Ib+ZnFoXiattnszXT4c="; + sha256 = "sha256-Kn4peMsJU47WeA2FrjqjnB7M4Q5eWm4Nw82KsIeFFYg="; }; nativeBuildInputs = [ makeWrapper ]; From 58e6137f99c79b3a18ebaf00681b8f5262944c5d Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 1 Sep 2026 15:47:18 +0000 Subject: [PATCH 053/140] python3Packages.django-treenode: 0.24.0 -> 0.25.0 --- pkgs/development/python-modules/django-treenode/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/django-treenode/default.nix b/pkgs/development/python-modules/django-treenode/default.nix index e7959e3fce35..b4ba4e79728b 100644 --- a/pkgs/development/python-modules/django-treenode/default.nix +++ b/pkgs/development/python-modules/django-treenode/default.nix @@ -8,14 +8,14 @@ buildPythonPackage rec { pname = "django-treenode"; - version = "0.24.0"; + version = "0.25.0"; pyproject = true; src = fetchFromGitHub { owner = "fabiocaccamo"; repo = "django-treenode"; tag = version; - hash = "sha256-ZdoFUYgPbfS7ORqd1kVh+XpJetZZ4alEkaVu5jqw5II="; + hash = "sha256-MsMNKptwxBNHgW+0juIkJCD8qdXvXzorwL/DnL+FqgQ="; }; build-system = [ From e0dfb2e9dad0ba54507869d9aa62fcac5fe94cd4 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 1 Sep 2026 17:16:52 +0000 Subject: [PATCH 054/140] vscode-extensions.uloco.theme-bluloco-light: 3.7.5 -> 3.10.0 --- pkgs/applications/editors/vscode/extensions/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/editors/vscode/extensions/default.nix b/pkgs/applications/editors/vscode/extensions/default.nix index c7fbbe452865..9d30118bfe17 100644 --- a/pkgs/applications/editors/vscode/extensions/default.nix +++ b/pkgs/applications/editors/vscode/extensions/default.nix @@ -4978,8 +4978,8 @@ let mktplcRef = { name = "theme-bluloco-light"; publisher = "uloco"; - version = "3.7.5"; - sha256 = "sha256-MDrw0JWioLyg+H0XOCpULsmtM/y7RfV9ruDtskRiT3A="; + version = "3.10.0"; + sha256 = "sha256-dweX1i8nn8qSleeGyhnrzSUXkhA13IXcGwwdkV7WsCI="; }; postInstall = '' rm -r $out/share/vscode/extensions/uloco.theme-bluloco-light/screenshots From 014de2b27b24aa7bad5fbd80dadd99eb12f0d8f1 Mon Sep 17 00:00:00 2001 From: Jost Alemann Date: Tue, 1 Sep 2026 20:12:13 +0200 Subject: [PATCH 055/140] ashell: 0.9.0 -> 0.10.0 Changelog: https://github.com/MalpenZibo/ashell/releases/tag/0.10.0 Diff: https://github.com/MalpenZibo/ashell/compare/0.9.0...0.10.0 --- pkgs/by-name/as/ashell/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/as/ashell/package.nix b/pkgs/by-name/as/ashell/package.nix index 4beac74e9bd9..3247a134ad30 100644 --- a/pkgs/by-name/as/ashell/package.nix +++ b/pkgs/by-name/as/ashell/package.nix @@ -15,16 +15,16 @@ }: rustPlatform.buildRustPackage (finalAttrs: { pname = "ashell"; - version = "0.9.0"; + version = "0.10.0"; src = fetchFromGitHub { owner = "MalpenZibo"; repo = "ashell"; tag = finalAttrs.version; - hash = "sha256-QRNEc2HNqA1tZk/jW/MXDwXda58yNlkw86SCTjH1/1w="; + hash = "sha256-1ci09G9qQCAmYnERtd1Pm2hZPEL0AMuYF7B9AlnnfbE="; }; - cargoHash = "sha256-bLZcRASBGV9Y/QlDVBdOl2ElZDLI1KUAh5MlOsjmlKs="; + cargoHash = "sha256-yuj74sMsL1c0vLEb0iyXTJYUw0rH7bJdxJRVVpPCkf0="; nativeBuildInputs = [ pkg-config From b685ce38aea205a7a419760ae2046b5f6f8b3780 Mon Sep 17 00:00:00 2001 From: Chris Moultrie <821688+tebriel@users.noreply.github.com> Date: Tue, 1 Sep 2026 15:06:54 -0400 Subject: [PATCH 056/140] github-copilot-app: fix build on darwin due to multiple targets --- pkgs/by-name/gi/github-copilot-app/package.nix | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/gi/github-copilot-app/package.nix b/pkgs/by-name/gi/github-copilot-app/package.nix index 15afb0f50d6b..ebbb836e59a0 100644 --- a/pkgs/by-name/gi/github-copilot-app/package.nix +++ b/pkgs/by-name/gi/github-copilot-app/package.nix @@ -95,7 +95,8 @@ stdenv.mkDerivation { cp -r *.app $out/Applications/ mkdir -p $out/bin - ln -s "$out/Applications/"*.app/Contents/MacOS/* $out/bin/github-copilot-app + ln -s "$out/Applications/"*.app/Contents/MacOS/git-credential-copilot "$out"/bin/git-credential-copilot + ln -s "$out/Applications/"*.app/Contents/MacOS/github "$out"/bin/github-copilot-app '' else '' From ad3e7f672a2e7ff3033423991fd430199e2dd96e Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 1 Sep 2026 19:15:29 +0000 Subject: [PATCH 057/140] xq-xml: 1.5.0 -> 1.5.1 --- pkgs/by-name/xq/xq-xml/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/xq/xq-xml/package.nix b/pkgs/by-name/xq/xq-xml/package.nix index fcb2c2c6a8c7..ada1f81880b8 100644 --- a/pkgs/by-name/xq/xq-xml/package.nix +++ b/pkgs/by-name/xq/xq-xml/package.nix @@ -8,16 +8,16 @@ buildGoModule (finalAttrs: { pname = "xq"; - version = "1.5.0"; + version = "1.5.1"; src = fetchFromGitHub { owner = "sibprogrammer"; repo = "xq"; tag = "v${finalAttrs.version}"; - hash = "sha256-LjY+BQUrqjBZD3//4CULMiIbOfJXVB394ac1yT5DPaU="; + hash = "sha256-cDZdQ0gmyx3h64l+HlPKj9AJVyKR5EGFPaNU+4xX0pw="; }; - vendorHash = "sha256-ILlqmZwC0azNfvC3f5wSV96X7GPy969YUiIYOrFxJmU="; + vendorHash = "sha256-ZYZgac2AW7Yjy3wYjh+VXK5Ng7+CBZebn4bUX2lt2sc="; ldflags = [ "-s" From 31c6a5de9fadffc1bee0a26601198930e5fe7a09 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 1 Sep 2026 19:27:29 +0000 Subject: [PATCH 058/140] vscode-extensions.zaaack.markdown-editor: 0.1.19 -> 0.1.20 --- pkgs/applications/editors/vscode/extensions/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/editors/vscode/extensions/default.nix b/pkgs/applications/editors/vscode/extensions/default.nix index c7fbbe452865..0b1a2d94e0bc 100644 --- a/pkgs/applications/editors/vscode/extensions/default.nix +++ b/pkgs/applications/editors/vscode/extensions/default.nix @@ -5552,8 +5552,8 @@ let mktplcRef = { name = "markdown-editor"; publisher = "zaaack"; - version = "0.1.19"; - hash = "sha256-W0lL0JMNyEszyJa6I7RbXYLu4cU9DQUh0ZEAOd6eshI="; + version = "0.1.20"; + hash = "sha256-YewK36OeKWgTU/iFRVZHYjF2+ke6TXb6HIggRZt1/nk="; }; meta = { description = "Visual Studio Code extension for WYSIWYG markdown editing"; From 6461a4a578fe0d5e7421112bea7d7a2e6f30f95d Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 1 Sep 2026 20:03:09 +0000 Subject: [PATCH 059/140] proton-pass-cli: 2.3.2 -> 2.3.3 --- pkgs/by-name/pr/proton-pass-cli/package.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/pr/proton-pass-cli/package.nix b/pkgs/by-name/pr/proton-pass-cli/package.nix index 16eb82a64463..f39fae72d43e 100644 --- a/pkgs/by-name/pr/proton-pass-cli/package.nix +++ b/pkgs/by-name/pr/proton-pass-cli/package.nix @@ -15,7 +15,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "proton-pass-cli"; - version = "2.3.2"; + version = "2.3.3"; __structuredAttrs = true; strictDeps = true; @@ -57,15 +57,15 @@ stdenv.mkDerivation (finalAttrs: { sources = { "aarch64-darwin" = fetchurl { url = "https://proton.me/download/pass-cli/${finalAttrs.version}/pass-cli-macos-aarch64"; - hash = "sha256-+/ierVv7KGbZmdaHDmOnmW3rg/UQAhlDoWCwYw5RbEI="; + hash = "sha256-MoFYesnFCuLxYEunXp0dObbeuyIbZabMVvZNYm7ePbw="; }; "aarch64-linux" = fetchurl { url = "https://proton.me/download/pass-cli/${finalAttrs.version}/pass-cli-linux-aarch64"; - hash = "sha256-tgEzTMePTdsSVwjG1kuLUJ5agqM3u4vq0Lwvht2cq/8="; + hash = "sha256-nD6F4Q07tjH/43fwY9mWucyaVF0wlxvO31kQ4W0DVCs="; }; "x86_64-linux" = fetchurl { url = "https://proton.me/download/pass-cli/${finalAttrs.version}/pass-cli-linux-x86_64"; - hash = "sha256-+VxrObRdlrZw8knMu1awazoX1FeTV9LQTErGTk/77/c="; + hash = "sha256-tbSaiz/Qr4gwwMGXnyjqDJDM7Oc/WQI6i8qCRdS2jak="; }; }; updateScript = writeShellScript "update-proton-pass-cli" '' From 3bb569713e3a2793bdeae114de2a47153803b27a Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 1 Sep 2026 22:53:44 +0000 Subject: [PATCH 060/140] jawiki-all-titles-in-ns0: 0-unstable-2026-08-01 -> 0-unstable-2026-09-01 --- pkgs/by-name/ja/jawiki-all-titles-in-ns0/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ja/jawiki-all-titles-in-ns0/package.nix b/pkgs/by-name/ja/jawiki-all-titles-in-ns0/package.nix index c478b1d44dec..357480ea6462 100644 --- a/pkgs/by-name/ja/jawiki-all-titles-in-ns0/package.nix +++ b/pkgs/by-name/ja/jawiki-all-titles-in-ns0/package.nix @@ -7,13 +7,13 @@ stdenvNoCC.mkDerivation { pname = "jawiki-all-titles-in-ns0"; - version = "0-unstable-2026-08-01"; + version = "0-unstable-2026-09-01"; src = fetchFromGitHub { owner = "musjj"; repo = "jawiki-archive"; - rev = "9d043ec108e2bd63a0f5971826e14b9888d18399"; - hash = "sha256-rCPD/Y82dvAiCVt2XmX1WwcujIpacCU/Pcyn4zUWg0I="; + rev = "5c0d3d609a19361e9ebbe24702da11c8285e278d"; + hash = "sha256-D4dqdc0xeKPcy0MmfKcK6GEngQOmLg/2H6TuWGyS0i8="; }; installPhase = '' From 38199720743beb2e184852a6041708e2c3c3bc45 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 00:25:45 +0000 Subject: [PATCH 061/140] docuum: 0.27.0 -> 0.27.1 --- pkgs/by-name/do/docuum/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/do/docuum/package.nix b/pkgs/by-name/do/docuum/package.nix index 5d956f2ebda5..d6d61d9c1c14 100644 --- a/pkgs/by-name/do/docuum/package.nix +++ b/pkgs/by-name/do/docuum/package.nix @@ -8,16 +8,16 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "docuum"; - version = "0.27.0"; + version = "0.27.1"; src = fetchFromGitHub { owner = "stepchowfun"; repo = "docuum"; tag = "v${finalAttrs.version}"; - hash = "sha256-Avd+37mY9E28kfqRI8W3Lx5O/RrxuHFwBnXZqqdrkNQ="; + hash = "sha256-yy2mZx2eFgEpYVvO0Dgvf42b2rK+xMiIiF5tFz+1tV0="; }; - cargoHash = "sha256-VrCtfE4WvTlKeLsJVm73kNvo3lH90nt+imG2Yqse8K0="; + cargoHash = "sha256-GVjVX942kAUWZuR7k4Yu1GS9DbSr9HMoM/rfdUVXX5o="; checkFlags = [ # fails, no idea why From 3355bf46e052d380fb1ecf770650689dccf4129b Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 00:28:29 +0000 Subject: [PATCH 062/140] speakeasy-cli: 1.795.1 -> 1.796.2 --- pkgs/by-name/sp/speakeasy-cli/package.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/sp/speakeasy-cli/package.nix b/pkgs/by-name/sp/speakeasy-cli/package.nix index 9409cd5ae2fb..91eaf79de0e7 100644 --- a/pkgs/by-name/sp/speakeasy-cli/package.nix +++ b/pkgs/by-name/sp/speakeasy-cli/package.nix @@ -11,7 +11,7 @@ }: stdenv.mkDerivation (finalAttrs: { pname = "speakeasy-cli"; - version = "1.795.1"; + version = "1.796.2"; sourceRoot = "."; src = @@ -33,15 +33,15 @@ stdenv.mkDerivation (finalAttrs: { sources = { "x86_64-linux" = fetchurl { url = "https://github.com/speakeasy-api/speakeasy/releases/download/v${finalAttrs.version}/speakeasy_linux_amd64.zip"; - hash = "sha256-oKLhpMFjWjso7e7hdCdRiXltYVOVLkPvYVESUGsGy9E="; + hash = "sha256-5LAlRh0CDzs8eSsxLY8nK2ZazVl9rLZONWywlTOKwTs="; }; "aarch64-darwin" = fetchurl { url = "https://github.com/speakeasy-api/speakeasy/releases/download/v${finalAttrs.version}/speakeasy_darwin_arm64.zip"; - hash = "sha256-T73N3y/OGjEmlU6ehKfid6uxL6wD5bTpInLSM06OZbM="; + hash = "sha256-uVVX/6L3ehLnF/rZ9EmIrFhrulvzKxOI5ryBWqN7LtA="; }; "aarch64-linux" = fetchurl { url = "https://github.com/speakeasy-api/speakeasy/releases/download/v${finalAttrs.version}/speakeasy_linux_arm64.zip"; - hash = "sha256-8mhwxAiB3OKJfmL60K0SdLNAhQgx+iBG/1lynGdczTM="; + hash = "sha256-n0C/wnGMcn90ECcPqwffMY94UUgdYyR1Wpn+Qj8vtY0="; }; }; updateScript = writeShellScript "update-speakeasy" '' From 612d7a5f57454e7dc4831465f938936f610aefc6 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 00:38:43 +0000 Subject: [PATCH 063/140] lcrq: 0.3.1 -> 0.4.0 --- pkgs/by-name/lc/lcrq/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/lc/lcrq/package.nix b/pkgs/by-name/lc/lcrq/package.nix index 981b7a915f89..af635a242168 100644 --- a/pkgs/by-name/lc/lcrq/package.nix +++ b/pkgs/by-name/lc/lcrq/package.nix @@ -5,13 +5,13 @@ }: stdenv.mkDerivation (finalAttrs: { pname = "lcrq"; - version = "0.3.1"; + version = "0.4.0"; src = fetchFromCodeberg { owner = "librecast"; repo = "lcrq"; rev = "v${finalAttrs.version}"; - hash = "sha256-hNH5SdvKhNPUJWs7vpPECcBsRyNdHQF+Ot3LmyX2V3c="; + hash = "sha256-1kKWg+GN+WrYx7RTjTLqfGt9qcqeh9vc/TyfZMKsH7A="; }; installFlags = [ "PREFIX=$(out)" ]; From 50407268e0df5abd229f64b0dbdc648cf1289333 Mon Sep 17 00:00:00 2001 From: whispers Date: Tue, 1 Sep 2026 23:56:24 -0400 Subject: [PATCH 064/140] libsoup_3: move to by-name --- .../libsoup/3.x.nix => by-name/li/libsoup_3/package.nix} | 0 pkgs/top-level/all-packages.nix | 2 -- 2 files changed, 2 deletions(-) rename pkgs/{development/libraries/libsoup/3.x.nix => by-name/li/libsoup_3/package.nix} (100%) diff --git a/pkgs/development/libraries/libsoup/3.x.nix b/pkgs/by-name/li/libsoup_3/package.nix similarity index 100% rename from pkgs/development/libraries/libsoup/3.x.nix rename to pkgs/by-name/li/libsoup_3/package.nix diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 0b3c7c74cdff..7a1549c03480 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -6050,8 +6050,6 @@ with pkgs; libsigcxx30 = callPackage ../development/libraries/libsigcxx/3.0.nix { }; - libsoup_3 = callPackage ../development/libraries/libsoup/3.x.nix { }; - libtorrent-rasterbar = libtorrent-rasterbar-2_0_x; libubox-nossl = libubox.override { with_ustream_ssl = false; }; From b68e0286a62124e858935ac44d36f3b782ad4008 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 05:22:26 +0000 Subject: [PATCH 065/140] okms-cli: 0.4.4 -> 0.5.0 --- pkgs/by-name/ok/okms-cli/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ok/okms-cli/package.nix b/pkgs/by-name/ok/okms-cli/package.nix index cf12c1008ebd..4ded50ddd191 100644 --- a/pkgs/by-name/ok/okms-cli/package.nix +++ b/pkgs/by-name/ok/okms-cli/package.nix @@ -8,16 +8,16 @@ buildGoModule (finalAttrs: { pname = "okms-cli"; - version = "0.4.4"; + version = "0.5.0"; src = fetchFromGitHub { owner = "ovh"; repo = "okms-cli"; tag = "v${finalAttrs.version}"; - hash = "sha256-S3A3X1Inrnqf4+Sz7e6mqL+vzrz2huIfvNSV6cV5NIU="; + hash = "sha256-mAHhmEB2N4TcW1axzNHtsOOc9mlUJS66CZprKIsrFyg="; }; - vendorHash = "sha256-GJG6cZ1FIWUNjDvcuOav7gPrgaKsfEI7U9lkPq+2H7E="; + vendorHash = "sha256-/VKa35URUY4K60aN+9saFyzCgCUb0xDDTa8eSXofOtk="; ldflags = [ "-s" From 50cc2aa2154235b94fa17e8d45737efff4b8c65b Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 05:34:15 +0000 Subject: [PATCH 066/140] kubernetes-helmPlugins.helm-schema: 2.5.0 -> 2.6.0 --- .../networking/cluster/helm/plugins/helm-schema.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/applications/networking/cluster/helm/plugins/helm-schema.nix b/pkgs/applications/networking/cluster/helm/plugins/helm-schema.nix index 1219302378c5..c5b0a618c4aa 100644 --- a/pkgs/applications/networking/cluster/helm/plugins/helm-schema.nix +++ b/pkgs/applications/networking/cluster/helm/plugins/helm-schema.nix @@ -8,16 +8,16 @@ buildGoModule (finalAttrs: { pname = "helm-schema"; - version = "2.5.0"; + version = "2.6.0"; src = fetchFromGitHub { owner = "losisin"; repo = "helm-values-schema-json"; tag = "v${finalAttrs.version}"; - hash = "sha256-GryjtwHUchH/69iLKavvJF9BE/E9g3LtgW9SBGXenU0="; + hash = "sha256-DTxVVf8p9IHYPIC5TevnvvLWTQx2VIy3WNPXSczTkSs="; }; - vendorHash = "sha256-FFxPgTjg88GX5J+23O7A4WerqzWwM6YS9FlT13arWMQ="; + vendorHash = "sha256-XSaTTzSoKnwoiZu/FqHYOas6dMtr5C4+F5jy4FX1ot8="; ldflags = [ "-s" From 9735ee12245764e5491338d53a2bbffe036b685d Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 06:07:46 +0000 Subject: [PATCH 067/140] graphify: 0.9.48 -> 0.9.53 --- pkgs/by-name/gr/graphify/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/gr/graphify/package.nix b/pkgs/by-name/gr/graphify/package.nix index 8e44e286cbf1..1ffaa444f2a7 100644 --- a/pkgs/by-name/gr/graphify/package.nix +++ b/pkgs/by-name/gr/graphify/package.nix @@ -8,14 +8,14 @@ python3Packages.buildPythonApplication rec { __structuredAttrs = true; pname = "graphify"; - version = "0.9.48"; + version = "0.9.53"; pyproject = true; src = fetchFromGitHub { owner = "Graphify-Labs"; repo = "graphify"; tag = "v${version}"; - hash = "sha256-gcQ8isXZQu/VQkK74vAaOKnbNdsxiez+TSZdRUxEMiA="; + hash = "sha256-1G8PuSxYM70nMf8glJARA9vVMI8Ue7zqfAxgXi18lPM="; }; build-system = [ From c168e716184984fe03e04054cc52a6e5720fce76 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 06:38:26 +0000 Subject: [PATCH 068/140] oxker: 0.13.3 -> 0.13.4 --- pkgs/by-name/ox/oxker/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ox/oxker/package.nix b/pkgs/by-name/ox/oxker/package.nix index f05fc246f815..2f0a763c5679 100644 --- a/pkgs/by-name/ox/oxker/package.nix +++ b/pkgs/by-name/ox/oxker/package.nix @@ -10,14 +10,14 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "oxker"; - version = "0.13.3"; + version = "0.13.4"; src = fetchCrate { inherit (finalAttrs) pname version; - hash = "sha256-F/5QkEA4/UFFM3FEiqyBFZQWiIhQokT4VjL5SaKrDIA="; + hash = "sha256-W2swVJd/rygvt/q3YqqI1bVMmuitre4k9Zwl9JYZZbs="; }; - cargoHash = "sha256-v0EOUIEaAUtcNlkBhFQ1Q/quYdG6+18MT2nnjZ/ApbM="; + cargoHash = "sha256-pJAnR0P5/vA9HbljbC3XhQbpiSeq3oBDCCaMuwfzLZ4="; # See https://github.com/mrjackwills/oxker/issues/73 checkFlags = lib.optionals stdenv.hostPlatform.isDarwin [ From 69430c6fc4121e2e739b1527e9a33a4870f7a547 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 07:36:14 +0000 Subject: [PATCH 069/140] oidc-agent: 5.3.6 -> 5.3.8 --- pkgs/by-name/oi/oidc-agent/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/oi/oidc-agent/package.nix b/pkgs/by-name/oi/oidc-agent/package.nix index e28f1d15e98b..2f721f059b71 100644 --- a/pkgs/by-name/oi/oidc-agent/package.nix +++ b/pkgs/by-name/oi/oidc-agent/package.nix @@ -15,13 +15,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "oidc-agent"; - version = "5.3.6"; + version = "5.3.8"; src = fetchFromGitHub { owner = "indigo-dc"; repo = "oidc-agent"; tag = "v${finalAttrs.version}"; - hash = "sha256-GY0YsZJUUDBx1+ivE+h7tRG32qTeAcI7mmh6+zK+1KA="; + hash = "sha256-n88PQgFqsYiFwngaz1LGicVszoiepafshZa5/DiNw3I="; }; nativeBuildInputs = [ From 85520792633ff205aab7906edd26666989cc5278 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 08:12:36 +0000 Subject: [PATCH 070/140] matrix-alertmanager-receiver: 2026.8.5 -> 2026.8.26 --- pkgs/by-name/ma/matrix-alertmanager-receiver/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ma/matrix-alertmanager-receiver/package.nix b/pkgs/by-name/ma/matrix-alertmanager-receiver/package.nix index e27bcda375e1..8f484dc1e881 100644 --- a/pkgs/by-name/ma/matrix-alertmanager-receiver/package.nix +++ b/pkgs/by-name/ma/matrix-alertmanager-receiver/package.nix @@ -8,17 +8,17 @@ buildGoModule (finalAttrs: { pname = "matrix-alertmanager-receiver"; - version = "2026.8.5"; + version = "2026.8.26"; __structuredAttrs = true; src = fetchFromGitHub { owner = "metio"; repo = "matrix-alertmanager-receiver"; tag = finalAttrs.version; - hash = "sha256-0Kh446DWt9UcAuFF0DjMxlNCb+kZOCHs+oCG+BPgsi8="; + hash = "sha256-Qlg3IvfTQ0lzPN+m4usRT5SW4IFWXkvG4PRGIhwukcs="; }; - vendorHash = "sha256-+6qW0W2cSTMOPJznhGy8sAH8O1GucrwVL/uRj8qUYLQ="; + vendorHash = "sha256-AJ5st9AHf2laZI1hdGa0oFsPA8ulSSUFnSyeNttqem0="; env.CGO_ENABLED = "0"; From ccec07874d9d120541943fb02cbdc2e742c3c3ab Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 09:31:49 +0000 Subject: [PATCH 071/140] python3Packages.aioghost: 0.4.24 -> 0.4.26 --- pkgs/development/python-modules/aioghost/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/aioghost/default.nix b/pkgs/development/python-modules/aioghost/default.nix index aa41231e2194..095c126d5c1c 100644 --- a/pkgs/development/python-modules/aioghost/default.nix +++ b/pkgs/development/python-modules/aioghost/default.nix @@ -13,14 +13,14 @@ buildPythonPackage (finalAttrs: { pname = "aioghost"; - version = "0.4.24"; + version = "0.4.26"; pyproject = true; src = fetchFromGitHub { owner = "TryGhost"; repo = "aioghost"; tag = "v${finalAttrs.version}"; - hash = "sha256-5yQ2JL24BJ97xJKJlxod0BNT6gKTsdkFz+s8sM4plBc="; + hash = "sha256-Y3Dy+Gtb1u2x286bxScMYVn4D1B0TBCltD8ddeziYic="; }; build-system = [ hatchling ]; From e3b4dbb51298d09925ae596619d99818ad79730f Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 09:38:33 +0000 Subject: [PATCH 072/140] libvgm: 0-unstable-2026-08-18 -> 0-unstable-2026-08-27 --- pkgs/by-name/li/libvgm/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/li/libvgm/package.nix b/pkgs/by-name/li/libvgm/package.nix index 9501dc43dc98..cf88c595f1d3 100644 --- a/pkgs/by-name/li/libvgm/package.nix +++ b/pkgs/by-name/li/libvgm/package.nix @@ -38,13 +38,13 @@ assert enableTools -> enableAudio && enableEmulation && enableLibplayer; stdenv.mkDerivation (finalAttrs: { pname = "libvgm"; - version = "0-unstable-2026-08-18"; + version = "0-unstable-2026-08-27"; src = fetchFromGitHub { owner = "ValleyBell"; repo = "libvgm"; - rev = "d4a07d0111527bf5130d0814505a1243136f3962"; - hash = "sha256-t0/7uorfT+nusRGOv58XNXwZruwyKld7IC+l1q6Ewn8="; + rev = "e41ca80220cbcbaac0e7d77bf57c689a395c5f97"; + hash = "sha256-r2bE8cmSxDab4kOu/8KJHqcICKTmv2uSMvIOaOHuaFc="; }; outputs = [ From cf6a014d171b2eccc2efc2587ac526ea1051858d Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Tue, 1 Sep 2026 01:31:27 +0200 Subject: [PATCH 073/140] buildMozillaMach, firefox: apply RFC169 terminology This also deduplicates the arguments for the signing requirement and addon sideloading by moving them into the inner build function. --- doc/release-notes/rl-2611.section.md | 10 + .../browsers/firefox-bin/default.nix | 4 +- .../firefox/packages/firefox-devedition.nix | 8 +- .../networking/browsers/firefox/wrapper.nix | 36 +-- .../mailreaders/thunderbird-bin/default.nix | 2 +- .../mailreaders/thunderbird/packages.nix | 8 +- .../build-mozilla-mach/default.nix | 224 +++++++++--------- .../fi/firefoxpwa-unwrapped/package.nix | 12 +- .../fl/floorp-bin-unwrapped/package.nix | 4 +- .../li/librewolf-bin-unwrapped/package.nix | 4 +- .../li/librewolf-unwrapped/package.nix | 7 +- 11 files changed, 163 insertions(+), 156 deletions(-) diff --git a/doc/release-notes/rl-2611.section.md b/doc/release-notes/rl-2611.section.md index 6261560ecec6..2503b2df2a00 100644 --- a/doc/release-notes/rl-2611.section.md +++ b/doc/release-notes/rl-2611.section.md @@ -146,6 +146,16 @@ - `pnpm_10` was upgraded to version 10.34.1+, which introduced stricter integrity checks. If you encounter `ERR_PNPM_MISSING_TARBALL_INTEGRITY`, you can fall back to the older `pnpm_10_34_0`. +- `buildMozillaMach` is now using `enable` and `with` + terminology from RFC 169 and the `wrapFirefox` and `wrapThunderbird` functions + check for these new attribute names on the passed package. + The `privacySupport` function argument has been replaced by multiple + granular options corresponding to individual features: `enableDataReporting`, + `enableLocation`, `enableWebRTC`. + The `requireSigning` and `allowAddonSideload` function arguments moved from + the outer to the inner function and were renamed to `enableAddonSigning` and + `enableAddonSideload`, respectively. + - `fetchPnpmDeps`' `fetcherVersion = 1` and `fetcherVersion = 2` have been removed, as announced in the 26.05 release. Packages still using them now throw an evaluation error and must migrate to `fetcherVersion = 3` (or later) diff --git a/pkgs/applications/networking/browsers/firefox-bin/default.nix b/pkgs/applications/networking/browsers/firefox-bin/default.nix index 88d59af1aa81..07423c272088 100644 --- a/pkgs/applications/networking/browsers/firefox-bin/default.nix +++ b/pkgs/applications/networking/browsers/firefox-bin/default.nix @@ -130,8 +130,8 @@ stdenv.mkDerivation { passthru = { inherit applicationName binaryName; libName = "firefox-bin-${version}"; - ffmpegSupport = true; - gssSupport = true; + withFFmpeg = true; + withGSSAPI = true; gtk3 = gtk3; # update with: diff --git a/pkgs/applications/networking/browsers/firefox/packages/firefox-devedition.nix b/pkgs/applications/networking/browsers/firefox/packages/firefox-devedition.nix index 449995dd3620..f0a973193222 100644 --- a/pkgs/applications/networking/browsers/firefox/packages/firefox-devedition.nix +++ b/pkgs/applications/networking/browsers/firefox/packages/firefox-devedition.nix @@ -7,12 +7,11 @@ buildMozillaMach, }: -buildMozillaMach rec { +(buildMozillaMach rec { pname = "firefox-devedition"; binaryName = "firefox-devedition"; version = "155.0b5"; applicationName = "Firefox Developer Edition"; - requireSigning = false; branding = "browser/branding/aurora"; src = fetchurl { url = "mirror://mozilla/devedition/releases/${version}/source/firefox-${version}.source.tar.xz"; @@ -52,4 +51,7 @@ buildMozillaMach rec { versionSuffix = "b[0-9]*"; baseUrl = "https://archive.mozilla.org/pub/devedition/releases/"; }; -} +}).override + { + enableAddonSigning = false; + } diff --git a/pkgs/applications/networking/browsers/firefox/wrapper.nix b/pkgs/applications/networking/browsers/firefox/wrapper.nix index f59895902aec..ff22fb46edea 100644 --- a/pkgs/applications/networking/browsers/firefox/wrapper.nix +++ b/pkgs/applications/networking/browsers/firefox/wrapper.nix @@ -69,7 +69,7 @@ let wmClass ? applicationName, nativeMessagingHosts ? [ ], pkcs11Modules ? [ ], - useGlvnd ? (!isDarwin), + withGlvnd ? (!isDarwin), cfg ? config.${applicationName} or { }, ## Following options are needed for extra prefs & policies @@ -88,20 +88,20 @@ let }: let - ffmpegSupport = browser.ffmpegSupport or false; + withFFmpeg = browser.withFFmpeg or false; # Firefox dlopens libavcodec by hardcoded soname, so each ffmpeg major needs # explicit browser support; keep versioned pins here (never the ffmpeg alias) # and add a tier when a release gains the next ABI. # libavcodec 62: 146 (bug 1962139), uplifted to ESR 140.10.2 (bug 2036244). # libavcodec 63: 154 (bug 2057577), uplifted to ESR 153.1 (bug 2057577). ffmpegPackage = if lib.versionAtLeast browser.version "153.1" then ffmpeg_9 else ffmpeg_8; - gssSupport = browser.gssSupport or false; - alsaSupport = browser.alsaSupport or false; - pipewireSupport = browser.pipewireSupport or false; - sndioSupport = browser.sndioSupport or false; - jackSupport = browser.jackSupport or false; + withGSSAPI = browser.withGSSAPI or false; + withALSA = browser.withALSA or false; + withPipewire = browser.withPipewire or false; + withSndio = browser.withSndio or false; + withJACK = browser.withJACK or false; # PCSC-Lite daemon (services.pcscd) also must be enabled for firefox to access smartcards - smartcardSupport = cfg.smartcardSupport or false; + withPCSC = cfg.smartcardSupport or false; allNativeMessagingHosts = map lib.getBin (lib.unique nativeMessagingHosts); @@ -119,10 +119,10 @@ let ] ++ lib.optional (cfg.speechSynthesisSupport or true) speechd-minimal ) - ++ lib.optional pipewireSupport pipewire - ++ lib.optional ffmpegSupport ffmpegPackage - ++ lib.optional gssSupport libkrb5 - ++ lib.optional useGlvnd libglvnd + ++ lib.optional withPipewire pipewire + ++ lib.optional withFFmpeg ffmpegPackage + ++ lib.optional withGSSAPI libkrb5 + ++ lib.optional withGlvnd libglvnd ++ lib.optionals (cfg.enableQuakeLive or false) [ stdenv.cc libx11 @@ -134,10 +134,10 @@ let zlib ] ++ lib.optional (config.pulseaudio or (!isDarwin)) libpulseaudio - ++ lib.optional alsaSupport alsa-lib - ++ lib.optional sndioSupport sndio - ++ lib.optional jackSupport libjack2 - ++ lib.optional smartcardSupport opensc + ++ lib.optional withALSA alsa-lib + ++ lib.optional withSndio sndio + ++ lib.optional withJACK libjack2 + ++ lib.optional withPCSC opensc ++ pkcs11Modules ++ lib.optionals (!isDarwin) gtk_modules; gtk_modules = lib.optionals (!isDarwin) [ libcanberra-gtk3 ]; @@ -161,7 +161,7 @@ let extensions = if nameArray != (lib.unique nameArray) then throw "Firefox addon name needs to be unique" - else if browser.requireSigning || !browser.allowAddonSideload then + else if browser.enableAddonSigning || !browser.enableAddonSideload then throw "Nix addons are only supported with signature enforcement disabled and addon sideloading enabled (eg. LibreWolf)" else map ( @@ -195,7 +195,7 @@ let Install = lib.foldr (e: ret: ret ++ [ "${e.outPath}/${e.extid}.xpi" ]) [ ] extensions; }; } - // lib.optionalAttrs smartcardSupport { + // lib.optionalAttrs withPCSC { SecurityDevices = { "OpenSC PKCS#11 Module" = "opensc-pkcs11.so"; }; diff --git a/pkgs/applications/networking/mailreaders/thunderbird-bin/default.nix b/pkgs/applications/networking/mailreaders/thunderbird-bin/default.nix index 004c91f93cfc..a0403dccbbeb 100644 --- a/pkgs/applications/networking/mailreaders/thunderbird-bin/default.nix +++ b/pkgs/applications/networking/mailreaders/thunderbird-bin/default.nix @@ -106,7 +106,7 @@ let gtk3 ; binaryName = "thunderbird"; - gssSupport = true; + withGSSAPI = true; }; in diff --git a/pkgs/applications/networking/mailreaders/thunderbird/packages.nix b/pkgs/applications/networking/mailreaders/thunderbird/packages.nix index 7a168b5b012c..64668c52acf0 100644 --- a/pkgs/applications/networking/mailreaders/thunderbird/packages.nix +++ b/pkgs/applications/networking/mailreaders/thunderbird/packages.nix @@ -69,14 +69,14 @@ let }).override ( { - geolocationSupport = false; - webrtcSupport = false; + enableLocation = false; + enableWebRTC = false; - pgoSupport = false; # console.warn: feeds: "downloadFeed: network connection unavailable" + enablePGO = false; # console.warn: feeds: "downloadFeed: network connection unavailable" } // lib.optionalAttrs (lib.versionAtLeast version "149") { # https://bugzilla.mozilla.org/show_bug.cgi?id=2025767 - crashreporterSupport = false; + enableCrashReporter = false; } ); diff --git a/pkgs/build-support/build-mozilla-mach/default.nix b/pkgs/build-support/build-mozilla-mach/default.nix index 1132b07930e3..57ea2447247c 100644 --- a/pkgs/build-support/build-mozilla-mach/default.nix +++ b/pkgs/build-support/build-mozilla-mach/default.nix @@ -8,8 +8,6 @@ application ? "browser", applicationName ? "Firefox", branding ? null, - requireSigning ? true, - allowAddonSideload ? false, src, unpackPhase ? null, extraPatches ? [ ], @@ -24,12 +22,8 @@ }: let - # Rename the variables to prevent infinite recursion - requireSigningDefault = requireSigning; - allowAddonSideloadDefault = allowAddonSideload; - # Specifying --(dis|en)able-elf-hack on a platform for which it's not implemented will give `--disable-elf-hack is not available in this configuration` - # This is declared here because it's used in the default value of elfhackSupport + # This is declared here because it's used in the default value of enableElfhack isElfhackPlatform = stdenv: stdenv.hostPlatform.isElf @@ -50,11 +44,13 @@ in # build time autoconf, + buildPackages, cargo, dump_syms, makeBinaryWrapper, mimalloc, nodejs, + overrideCC, perl, pkg-config, pkgsCross, # wasm32 rlbox @@ -115,80 +111,73 @@ in cups, rsync, # used when preparing .app directory - # optionals - - ## addon signing/sideloading - requireSigning ? requireSigningDefault, - allowAddonSideload ? allowAddonSideloadDefault, - - ## debugging - - debugBuild ? false, - - # On 32bit platforms, we disable adding "-g" for easier linking. - enableDebugSymbols ? !stdenv.hostPlatform.is32bit, - - ## optional libraries - - alsaSupport ? stdenv.hostPlatform.isLinux, + # optional dependencies + withALSA ? stdenv.hostPlatform.isLinux, alsa-lib, - ffmpegSupport ? true, - gssSupport ? true, + withFFmpeg ? true, + withGSSAPI ? true, libkrb5, - jackSupport ? stdenv.hostPlatform.isLinux, + withJACK ? stdenv.hostPlatform.isLinux, libjack2, - jemallocSupport ? !stdenv.hostPlatform.isMusl, + withJemalloc ? !stdenv.hostPlatform.isMusl, jemalloc, - ltoSupport ? ( + withPipewire ? withWayland && enableWebRTC, + withPulseaudio ? stdenv.hostPlatform.isLinux, + libpulseaudio, + withSndio ? stdenv.hostPlatform.isLinux, + sndio, + withWayland ? !stdenv.hostPlatform.isDarwin, + libxkbcommon, + libdrm, + + # Build configuration + + ## Addon signing/sideloading + enableAddonSigning ? true, + enableAddonSideload ? false, + + ## Optimizations + enableElfhack ? + isElfhackPlatform stdenv && !(stdenv.hostPlatform.isMusl && stdenv.hostPlatform.isAarch64), + enableLTO ? ( (stdenv.hostPlatform.isLinux || stdenv.hostPlatform.isDarwin) && stdenv.hostPlatform.is64bit && !stdenv.hostPlatform.isRiscV ), - overrideCC, - buildPackages, - # PGO merges profile data with a 32-bit llvm-profdata, which runs out of - # address space on the huge libxul profile, so disable it on 32-bit. - pgoSupport ? ( + enablePGO ? ( stdenv.hostPlatform.isLinux && stdenv.hostPlatform == stdenv.buildPlatform + # PGO merges profile data with a 32-bit llvm-profdata, which runs out of + # address space on the huge libxul profile, so disable it on 32-bit. && stdenv.hostPlatform.is64bit ), xvfb-run, - elfhackSupport ? - isElfhackPlatform stdenv && !(stdenv.hostPlatform.isMusl && stdenv.hostPlatform.isAarch64), - pipewireSupport ? waylandSupport && webrtcSupport, - pulseaudioSupport ? stdenv.hostPlatform.isLinux, - libpulseaudio, - sndioSupport ? stdenv.hostPlatform.isLinux, - sndio, - waylandSupport ? !stdenv.hostPlatform.isDarwin, - libxkbcommon, - libdrm, - ## privacy-related options + ## Debugging + enableDebug ? false, - privacySupport ? false, + ## On 32bit platforms, we disable adding "-g" for easier linking. + enableDebugSymbols ? !stdenv.hostPlatform.is32bit, - # WARNING: NEVER set any of the options below to `true` by default. - # Set to `!privacySupport` or `false`. + ## Privacy knobs + enableDataReporting ? true, + enableLocation ? true, + enableWebRTC ? true, + enableNeckoWiFi ? enableLocation, - crashreporterSupport ? - !privacySupport + ## Crash reporting + ## https://crash-stats.mozilla.org/search/?distribution_id=%3Dnixos + enableCrashReporter ? + enableDataReporting && !stdenv.hostPlatform.isLoongArch64 && !stdenv.hostPlatform.isRiscV && !stdenv.hostPlatform.isMusl, curl, - geolocationSupport ? !privacySupport, - webrtcSupport ? !privacySupport, - # digital rights management - - # This flag controls whether Firefox will show the nagbar, that allows - # users at runtime the choice to enable Widevine CDM support when a site - # requests it. - # Controlling the nagbar and widevine CDM at runtime is possible by setting - # `browser.eme.ui.enabled` and `media.gmp-widevinecdm.enabled` accordingly - drmSupport ? true, + ## DRM / Encrypted Media Extensions + # Build time toggle to control whether the DRM nagbar will appear + # (browser.eme.ui.enabled), when sites require it to playback media. + enableEMENagbar ? true, # As stated by Sylvestre Ledru (@sylvestre) on Nov 22, 2017 at # https://github.com/NixOS/nixpkgs/issues/31843#issuecomment-346372756 we @@ -213,10 +202,10 @@ in assert stdenv.cc.libc or null != null; assert - pipewireSupport - -> !waylandSupport || !webrtcSupport - -> throw "${pname}: pipewireSupport requires both wayland and webrtc support."; -assert elfhackSupport -> isElfhackPlatform stdenv; + withPipewire + -> !withWayland || !enableWebRTC + -> throw "${pname}: Pipewire support depends on Wayland and WebRTC support."; +assert enableElfhack -> isElfhackPlatform stdenv; let inherit (lib) enableFeature; @@ -238,7 +227,7 @@ let # LTO requires LLVM bintools including ld.lld and llvm-ar. buildStdenv = overrideCC llvmPackages.stdenv ( llvmPackages.stdenv.cc.override { - bintools = if ltoSupport then buildPackages.rustc.llvmPackages.bintools else stdenv.cc.bintools; + bintools = if enableLTO then buildPackages.rustc.llvmPackages.bintools else stdenv.cc.bintools; } ); @@ -273,7 +262,7 @@ let ); defaultPrefs = - if geolocationSupport then + if enableLocation then { "geo.provider.network.url" = { value = "https://api.beacondb.net/v1/geolocate"; @@ -284,7 +273,7 @@ let { "geo.provider.use_geoclue" = { value = false; - reason = "Geolocation support has been disabled through the `geolocationSupport` package attribute."; + reason = "Geolocation support has been disabled through the `enableLocation` package attribute."; }; }; @@ -301,7 +290,7 @@ let if stdenv.hostPlatform.isDarwin then "cairo-cocoa" else - "cairo-gtk3${lib.optionalString waylandSupport "-wayland"}"; + "cairo-gtk3${lib.optionalString withWayland "-wayland"}"; in @@ -324,10 +313,10 @@ buildStdenv.mkDerivation { outputs = [ "out" ] - ++ lib.optionals crashreporterSupport [ "symbols" ]; + ++ lib.optionals enableCrashReporter [ "symbols" ]; # Add another configure-build-profiling run before the final configure phase if we build with pgo - preConfigurePhases = lib.optionals pgoSupport [ + preConfigurePhases = lib.optionals enablePGO [ "configurePhase" "buildPhase" "profilingPhase" @@ -393,11 +382,11 @@ buildStdenv.mkDerivation { ] ++ lib.optionals stdenv.hostPlatform.isDarwin [ rsync ] ++ lib.optionals stdenv.hostPlatform.isx86 [ nasm ] - ++ lib.optionals crashreporterSupport [ + ++ lib.optionals enableCrashReporter [ dump_syms patchelf ] - ++ lib.optionals pgoSupport [ xvfb-run ] + ++ lib.optionals enablePGO [ xvfb-run ] ++ extraNativeBuildInputs; setOutputFlags = false; # `./mach configure` doesn't understand `--*dir=` flags. @@ -430,7 +419,7 @@ buildStdenv.mkDerivation { export WASM_CC=${pkgsCross.wasm32-wasip1.stdenv.cc}/bin/${pkgsCross.wasm32-wasip1.stdenv.cc.targetPrefix}cc export WASM_CXX=${pkgsCross.wasm32-wasip1.stdenv.cc}/bin/${pkgsCross.wasm32-wasip1.stdenv.cc.targetPrefix}c++ '' - + lib.optionalString pgoSupport '' + + lib.optionalString enablePGO '' if [ -e "$TMPDIR/merged.profdata" ]; then echo "Configuring with profiling data" for i in "''${!configureFlagsArray[@]}"; do @@ -464,7 +453,7 @@ buildStdenv.mkDerivation { + lib.optionalString (enableOfficialBranding && !stdenv.hostPlatform.is32bit) '' export MOZILLA_OFFICIAL=1 '' - + lib.optionalString (!requireSigning) '' + + lib.optionalString (!enableAddonSigning) '' export MOZ_REQUIRE_SIGNING= '' + lib.optionalString stdenv.hostPlatform.isMusl '' @@ -491,13 +480,13 @@ buildStdenv.mkDerivation { "--target=${buildStdenv.hostPlatform.config}" ] # LTO is done using clang and lld. - ++ lib.optionals ltoSupport [ + ++ lib.optionals enableLTO [ "--enable-lto=cross,full" # Cross-Language LTO "--enable-linker=lld" ] - ++ lib.optional (isElfhackPlatform stdenv) (enableFeature elfhackSupport "elf-hack") - ++ lib.optional (!drmSupport) "--disable-eme" - ++ lib.optional allowAddonSideload "--allow-addon-sideload" + ++ lib.optional (isElfhackPlatform stdenv) (enableFeature enableElfhack "elf-hack") + ++ lib.optional (!enableEMENagbar) "--disable-eme" + ++ lib.optional enableAddonSideload "--allow-addon-sideload" ++ lib.optionals (!stdenv.hostPlatform.isDarwin) [ # MacOS builds use bundled versions of libraries: https://bugzilla.mozilla.org/show_bug.cgi?id=1776255 "--enable-system-pixman" @@ -514,27 +503,28 @@ buildStdenv.mkDerivation { "--with-system-zlib" # These options are not available on MacOS, even --disable-* - (enableFeature alsaSupport "alsa") - (enableFeature jackSupport "jack") - (enableFeature pulseaudioSupport "pulseaudio") - (enableFeature sndioSupport "sndio") + (enableFeature withALSA "alsa") + (enableFeature withJACK "jack") + (enableFeature withPulseaudio "pulseaudio") + (enableFeature withSndio "sndio") ] ++ lib.optionals (!buildStdenv.hostPlatform.isDarwin && lib.versionAtLeast version "141") [ "--with-onnx-runtime=${lib.getLib onnxruntime}/lib" ] ++ [ - (enableFeature crashreporterSupport "crashreporter") - (enableFeature ffmpegSupport "ffmpeg") - (enableFeature geolocationSupport "necko-wifi") - (enableFeature gssSupport "negotiateauth") - (enableFeature jemallocSupport "jemalloc") - (enableFeature webrtcSupport "webrtc") + (enableFeature withFFmpeg "ffmpeg") + (enableFeature withGSSAPI "negotiateauth") + (enableFeature withJemalloc "jemalloc") - (enableFeature debugBuild "debug") - (if debugBuild then "--enable-profiling" else "--enable-optimize") + (enableFeature enableCrashReporter "crashreporter") + (enableFeature enableNeckoWiFi "necko-wifi") + (enableFeature enableWebRTC "webrtc") + + (enableFeature enableDebug "debug") + (if enableDebug then "--enable-profiling" else "--enable-optimize") # --enable-release adds -ffunction-sections & LTO that require a big amount # of RAM, and the 32-bit memory space cannot handle that linking - (enableFeature (!debugBuild && !stdenv.hostPlatform.is32bit) "release") + (enableFeature (!enableDebug && !stdenv.hostPlatform.is32bit) "release") (enableFeature enableDebugSymbols "debug-symbols") ] ++ lib.optionals enableDebugSymbols [ @@ -597,20 +587,20 @@ buildStdenv.mkDerivation { zlib (if (lib.versionAtLeast version "144") then nss_latest else nss_esr) ] - ++ lib.optional alsaSupport alsa-lib - ++ lib.optional jackSupport libjack2 - ++ lib.optional pulseaudioSupport libpulseaudio # only headers are needed - ++ lib.optional sndioSupport sndio - ++ lib.optionals waylandSupport [ + ++ lib.optional withALSA alsa-lib + ++ lib.optional withJACK libjack2 + ++ lib.optional withPulseaudio libpulseaudio # only headers are needed + ++ lib.optional withSndio sndio + ++ lib.optionals withWayland [ libxkbcommon libdrm ] )) - ++ lib.optional gssSupport libkrb5 - ++ lib.optional jemallocSupport jemalloc + ++ lib.optional withGSSAPI libkrb5 + ++ lib.optional withJemalloc jemalloc ++ extraBuildInputs; - profilingPhase = lib.optionalString pgoSupport '' + profilingPhase = lib.optionalString enablePGO '' # Avoid compressing the instrumented build with high levels of compression export MOZ_PKG_FORMAT=TAR @@ -663,7 +653,7 @@ buildStdenv.mkDerivation { # Generate build symbols once after the final build # https://firefox-source-docs.mozilla.org/crash-reporting/uploading_symbol.html preInstall = - lib.optionalString crashreporterSupport '' + lib.optionalString enableCrashReporter '' ./mach buildsymbols mkdir -p $symbols/ cp objdir/dist/*.crashreporter-symbols.zip $symbols/ @@ -697,7 +687,7 @@ buildStdenv.mkDerivation { cd .. ''; - postFixup = lib.optionalString (crashreporterSupport && buildStdenv.hostPlatform.isLinux) '' + postFixup = lib.optionalString (enableCrashReporter && buildStdenv.hostPlatform.isLinux) '' patchelf --add-rpath "${lib.makeLibraryPath [ curl ]}" $out/lib/${binaryName}/crashreporter ''; @@ -715,21 +705,25 @@ buildStdenv.mkDerivation { ''; passthru = { - inherit applicationName; - inherit application extraPatches; - inherit updateScript; - inherit alsaSupport; - inherit binaryName; - inherit requireSigning allowAddonSideload; - inherit jackSupport; - inherit pipewireSupport; - inherit sndioSupport; - inherit nspr; - inherit ffmpegSupport; - inherit gssSupport; - inherit tests; - inherit gtk3; - inherit wasiSysRoot; + inherit + application + applicationName + binaryName + enableAddonSideload + enableAddonSigning + extraPatches + gtk3 + nspr + tests + updateScript + wasiSysRoot + withALSA + withFFmpeg + withGSSAPI + withJACK + withPipewire + withSndio + ; version = packageVersion; } // extraPassthru; diff --git a/pkgs/by-name/fi/firefoxpwa-unwrapped/package.nix b/pkgs/by-name/fi/firefoxpwa-unwrapped/package.nix index 352795aa199e..29438dd2bf95 100644 --- a/pkgs/by-name/fi/firefoxpwa-unwrapped/package.nix +++ b/pkgs/by-name/fi/firefoxpwa-unwrapped/package.nix @@ -99,12 +99,12 @@ rustPlatform.buildRustPackage rec { # wrapped similarly to `firefoxRuntime`, and these passthru variables are # read when `wrapFirefox` wraps this derivation too. inherit (firefoxRuntime) - ffmpegSupport - gssSupport - alsaSupport - pipewireSupport - sndioSupport - jackSupport + withALSA + withFFmpeg + withGSSAPI + withJACK + withPipewire + withSndio ; }; diff --git a/pkgs/by-name/fl/floorp-bin-unwrapped/package.nix b/pkgs/by-name/fl/floorp-bin-unwrapped/package.nix index 239e5cbbc80b..bc45d19ea164 100644 --- a/pkgs/by-name/fl/floorp-bin-unwrapped/package.nix +++ b/pkgs/by-name/fl/floorp-bin-unwrapped/package.nix @@ -113,8 +113,8 @@ stdenv.mkDerivation (finalAttrs: { inherit binaryName; applicationName = "Floorp"; libName = "floorp-bin-${finalAttrs.version}"; - ffmpegSupport = true; - gssSupport = true; + withFFmpeg = true; + withGSSAPI = true; gtk3 = gtk3; updateScript = ./update.sh; }; diff --git a/pkgs/by-name/li/librewolf-bin-unwrapped/package.nix b/pkgs/by-name/li/librewolf-bin-unwrapped/package.nix index e6e69af03db0..f134e082b967 100644 --- a/pkgs/by-name/li/librewolf-bin-unwrapped/package.nix +++ b/pkgs/by-name/li/librewolf-bin-unwrapped/package.nix @@ -96,8 +96,8 @@ stdenv.mkDerivation { inherit binaryName; applicationName = "LibreWolf"; libName = "librewolf-bin-${version}"; - ffmpegSupport = true; - gssSupport = true; + withFFmpeg = true; + withGSSAPI = true; gtk3 = gtk3; updateScript = ./update.sh; }; diff --git a/pkgs/by-name/li/librewolf-unwrapped/package.nix b/pkgs/by-name/li/librewolf-unwrapped/package.nix index 86076f9126aa..8f19e763a723 100644 --- a/pkgs/by-name/li/librewolf-unwrapped/package.nix +++ b/pkgs/by-name/li/librewolf-unwrapped/package.nix @@ -15,8 +15,6 @@ in binaryName = "librewolf"; version = librewolf-src.packageVersion; src = librewolf-src.firefox; - requireSigning = false; - allowAddonSideload = true; branding = "browser/branding/librewolf"; inherit (librewolf-src) extraConfigureFlags @@ -52,7 +50,10 @@ in }; }).override { - crashreporterSupport = false; + enableAddonSigning = false; + enableAddonSideload = true; + + enableCrashReporter = false; # This will set `MOZILLA_OFFICIAL=1`, which is set by the mozconfig upstream, but has to # be set manually in our case. # This will not override the branding as `branding` is already set to the official From aeb2237f2455507e675f3de130f57b94160a543e Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 11:18:39 +0000 Subject: [PATCH 074/140] buildstream: 2.7.0 -> 2.8.0 --- pkgs/by-name/bu/buildstream/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/bu/buildstream/package.nix b/pkgs/by-name/bu/buildstream/package.nix index 55fe57411dfd..350f92829371 100644 --- a/pkgs/by-name/bu/buildstream/package.nix +++ b/pkgs/by-name/bu/buildstream/package.nix @@ -24,14 +24,14 @@ python3Packages.buildPythonApplication (finalAttrs: { pname = "buildstream"; - version = "2.7.0"; + version = "2.8.0"; pyproject = true; src = fetchFromGitHub { owner = "apache"; repo = "buildstream"; tag = finalAttrs.version; - hash = "sha256-eHZmimuwOo3ZHZw5QF94B6wkso1+QbZIcgpDgsw1hiM="; + hash = "sha256-TS1er7lWoaMaVnfT1GAApt2qxxyTrl0o354v6rIpgCA="; }; build-system = with python3Packages; [ From 6b2bb874240906c9134ca4fe0f56eccdce985d44 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 11:32:04 +0000 Subject: [PATCH 075/140] proto: 0.61.0 -> 0.61.2 --- pkgs/by-name/pr/proto/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/pr/proto/package.nix b/pkgs/by-name/pr/proto/package.nix index c290aae47187..96c9a3629c89 100644 --- a/pkgs/by-name/pr/proto/package.nix +++ b/pkgs/by-name/pr/proto/package.nix @@ -11,16 +11,16 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "proto"; - version = "0.61.0"; + version = "0.61.2"; src = fetchFromGitHub { owner = "moonrepo"; repo = "proto"; rev = "v${finalAttrs.version}"; - hash = "sha256-g2465xAxDaPJzprKTcrI9XLp07dX9t64X+KYzqjERb4="; + hash = "sha256-y7utg4vGz7QE2cSwuXQMiz4CFZXFZideoNL1K6ZfFYc="; }; - cargoHash = "sha256-ujAmzUDSAXMRKE+hxl80VOVBULYDNRsqYqlOp60ZE4o="; + cargoHash = "sha256-epmvqbupsK2PK99ko+7p5RwkGFC25BcOAQ2CGvhtH1c="; buildInputs = lib.optionals stdenv.hostPlatform.isDarwin [ libiconv From b8a5d38f55ec3b6dce868a66f3fae2eae90f3f94 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 11:50:39 +0000 Subject: [PATCH 076/140] firebase-tools: 15.28.1 -> 15.28.2 --- pkgs/by-name/fi/firebase-tools/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/fi/firebase-tools/package.nix b/pkgs/by-name/fi/firebase-tools/package.nix index 1b67d10fff07..6fd7a9f2983c 100644 --- a/pkgs/by-name/fi/firebase-tools/package.nix +++ b/pkgs/by-name/fi/firebase-tools/package.nix @@ -11,17 +11,17 @@ buildNpmPackage rec { pname = "firebase-tools"; - version = "15.28.1"; + version = "15.28.2"; nodejs = nodejs_22; src = fetchFromGitHub { owner = "firebase"; repo = "firebase-tools"; tag = "v${version}"; - hash = "sha256-Dls7xLkHnvLGQnw72RoOYw8iz2axHNBBKdzVwWpfWHE="; + hash = "sha256-19cIgkZ0luZYYx+9Cs077b5Q+sLxf+4ahwWO6hspxDw="; }; - npmDepsHash = "sha256-u8zhpnd2avSXiIZi6rj8y6JI9ngqTxIhlPR+Xor3ka8="; + npmDepsHash = "sha256-ZcI4Do4NcTIhJx1o/Hb9fZysv7WyGMLOUKMb4SUbeTY="; # No more package-lock.json in upstream src postPatch = '' From ef04d95fef2a3986724fb8ad71b064d90c7f0ee4 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 1 Sep 2026 18:50:25 +0000 Subject: [PATCH 077/140] audacity: 3.7.8 -> 3.7.9 --- pkgs/by-name/au/audacity/package.nix | 9 +++------ 1 file changed, 3 insertions(+), 6 deletions(-) diff --git a/pkgs/by-name/au/audacity/package.nix b/pkgs/by-name/au/audacity/package.nix index ff0bd1ae1e67..9b096104c63d 100644 --- a/pkgs/by-name/au/audacity/package.nix +++ b/pkgs/by-name/au/audacity/package.nix @@ -31,7 +31,7 @@ libid3tag, libopus, libuuid, - ffmpeg_8, + ffmpeg, soundtouch, portaudio, # given up fighting their portaudio.patch? portmidi, @@ -58,18 +58,15 @@ # TODO # 1. detach sbsms -let - ffmpeg = ffmpeg_8; -in stdenv.mkDerivation (finalAttrs: { pname = "audacity"; - version = "3.7.8"; + version = "3.7.9"; src = fetchFromGitHub { owner = "audacity"; repo = "audacity"; rev = "Audacity-${finalAttrs.version}"; - hash = "sha256-Vp3Nx3LuNu5fqeLF6dvZ9/hhkoUCu0eCAdIEDtS1IwU="; + hash = "sha256-q/5LPL76GPEFGRxTZcuxmLuq15fwbw2Mak/q2RObghk="; }; patches = [ From abc5127fdbb4e3a9ea36e61c4f8dd727d888cc8d Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 12:09:38 +0000 Subject: [PATCH 078/140] python3Packages.azure-keyvault-certificates: 4.11.1 -> 4.11.2 --- .../python-modules/azure-keyvault-certificates/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/azure-keyvault-certificates/default.nix b/pkgs/development/python-modules/azure-keyvault-certificates/default.nix index 69838c92c21f..b8ef6b88fc71 100644 --- a/pkgs/development/python-modules/azure-keyvault-certificates/default.nix +++ b/pkgs/development/python-modules/azure-keyvault-certificates/default.nix @@ -11,13 +11,13 @@ buildPythonPackage rec { pname = "azure-keyvault-certificates"; - version = "4.11.1"; + version = "4.11.2"; pyproject = true; src = fetchPypi { pname = "azure_keyvault_certificates"; inherit version; - hash = "sha256-c02aZfqg8r1FueFi0xesrexxBWk06/S7/gWLI9dL0HM="; + hash = "sha256-H7wd8a4bm1tJpbWRX4JuwLFmLs/ukJzHV601IIOYv70="; }; nativeBuildInputs = [ setuptools ]; From e7f5510514f3be37200116931607e4fb43d6bf6c Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 12:11:29 +0000 Subject: [PATCH 079/140] python3Packages.netutils: 1.18.0 -> 1.19.1 --- pkgs/development/python-modules/netutils/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/netutils/default.nix b/pkgs/development/python-modules/netutils/default.nix index 87fc5dbf828d..029426afdf68 100644 --- a/pkgs/development/python-modules/netutils/default.nix +++ b/pkgs/development/python-modules/netutils/default.nix @@ -14,14 +14,14 @@ buildPythonPackage (finalAttrs: { pname = "netutils"; - version = "1.18.0"; + version = "1.19.1"; pyproject = true; src = fetchFromGitHub { owner = "networktocode"; repo = "netutils"; tag = "v${finalAttrs.version}"; - hash = "sha256-1pfuuvJ3ze2MYW9IX3oCDZ/VRvuytdl3ZnMQOTjOEOs="; + hash = "sha256-5BtrtlwY/V8hFUxUOri8v8j4hd6hF2c7ZWvQEmKdTjM="; }; build-system = [ poetry-core ]; From 623e27fbc6751d941b6f13db98a8230c4e387abe Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 12:27:08 +0000 Subject: [PATCH 080/140] zapret2: 1.0.4 -> 1.0.5 --- pkgs/by-name/za/zapret2/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/za/zapret2/package.nix b/pkgs/by-name/za/zapret2/package.nix index ef985f84db1e..7a93f3302e10 100644 --- a/pkgs/by-name/za/zapret2/package.nix +++ b/pkgs/by-name/za/zapret2/package.nix @@ -21,7 +21,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "zapret2"; - version = "1.0.4"; + version = "1.0.5"; outputs = [ "out" @@ -35,7 +35,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "bol-van"; repo = "zapret2"; tag = "v${finalAttrs.version}"; - hash = "sha256-C3TOpbqt805N/aiHO/G9VocwGjOGvxobi/Sfi7ZX38k="; + hash = "sha256-hoDUASf2xcpqNaoEGp4HduVbBIVvIo3CuwUJ9tgZ19c="; leaveDotGit = true; postFetch = '' cd "$out" From 16f60b25519f324437d48ad7e6236f05f09fa081 Mon Sep 17 00:00:00 2001 From: Gaetan Lepage Date: Wed, 2 Sep 2026 12:38:21 +0000 Subject: [PATCH 081/140] gpu-viewer: 3.35 -> 4.00 Diff: https://github.com/arunsivaramanneo/gpu-viewer/compare/v3.35...v4.00 Changelog: https://github.com/arunsivaramanneo/GPU-Viewer/releases/tag/v4.00 --- pkgs/by-name/gp/gpu-viewer/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/gp/gpu-viewer/package.nix b/pkgs/by-name/gp/gpu-viewer/package.nix index f0b4663a0796..36e55bcfe0ab 100644 --- a/pkgs/by-name/gp/gpu-viewer/package.nix +++ b/pkgs/by-name/gp/gpu-viewer/package.nix @@ -29,7 +29,7 @@ python3Packages.buildPythonApplication (finalAttrs: { pname = "gpu-viewer"; - version = "3.35"; + version = "4.00"; pyproject = false; __structuredAttrs = true; @@ -37,7 +37,7 @@ python3Packages.buildPythonApplication (finalAttrs: { owner = "arunsivaramanneo"; repo = "gpu-viewer"; tag = "v${finalAttrs.version}"; - hash = "sha256-W8BPtHbOwLZ95bY6ZmAaKS87fh+gOWZIhxjWKqiavag="; + hash = "sha256-zSPXOWdd962DvwqYiit9wGT6vDxvgkQz91852+h4d7Q="; }; nativeBuildInputs = [ From 6ebef31c5f712c99fe56d5d64fc4c7203b9cbfaf Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 13:01:07 +0000 Subject: [PATCH 082/140] sonar: 0.4.0 -> 0.4.1 --- pkgs/by-name/so/sonar/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/so/sonar/package.nix b/pkgs/by-name/so/sonar/package.nix index 1d564007953d..f91650c36ae2 100644 --- a/pkgs/by-name/so/sonar/package.nix +++ b/pkgs/by-name/so/sonar/package.nix @@ -8,13 +8,13 @@ buildGoModule (finalAttrs: { __structuredAttrs = true; pname = "sonar"; - version = "0.4.0"; + version = "0.4.1"; src = fetchFromGitHub { owner = "raskrebs"; repo = "sonar"; tag = "v${finalAttrs.version}"; - hash = "sha256-rHc7uYk0Js/hvWntI/Kt4Wq6Pod4T1DnTjAeUDa0fv0="; + hash = "sha256-CQtr+22B2a1svX3KnDdGDXQRA1gyYI0uGF8DodvCfPE="; }; vendorHash = "sha256-komX1AmHt2NoF1x6xsNa2RFkfVzOXfYEMPhT0zwMxjw="; From 3cac7a1eba427d468dec648465092833c3cc654f Mon Sep 17 00:00:00 2001 From: zowoq <59103226+zowoq@users.noreply.github.com> Date: Wed, 2 Sep 2026 13:13:25 +0000 Subject: [PATCH 083/140] linux_7_2: 7.2.2 -> 7.2.3 --- pkgs/os-specific/linux/kernel/kernels-org.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/kernels-org.json b/pkgs/os-specific/linux/kernel/kernels-org.json index 68637ab7b8fc..84ffdc12b75f 100644 --- a/pkgs/os-specific/linux/kernel/kernels-org.json +++ b/pkgs/os-specific/linux/kernel/kernels-org.json @@ -40,8 +40,8 @@ "lts": false }, "7.2": { - "version": "7.2.2", - "hash": "sha256:10qd3kllldrw6gbp0wfziy94bgjr98svzzqci3z3xi4q9zhpq3kx", + "version": "7.2.3", + "hash": "sha256:00yd1rar9dxgdfx1003c9m5bs90bv6da7j2117pwcgmiwzl5k8lb", "lts": false } } From 092eec8edc834bb5f441dad7df3d2676e748156f Mon Sep 17 00:00:00 2001 From: zowoq <59103226+zowoq@users.noreply.github.com> Date: Wed, 2 Sep 2026 13:13:28 +0000 Subject: [PATCH 084/140] linux_7_1: 7.1.12 -> 7.1.13 --- pkgs/os-specific/linux/kernel/kernels-org.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/kernels-org.json b/pkgs/os-specific/linux/kernel/kernels-org.json index 84ffdc12b75f..d06d22e0c3b2 100644 --- a/pkgs/os-specific/linux/kernel/kernels-org.json +++ b/pkgs/os-specific/linux/kernel/kernels-org.json @@ -35,8 +35,8 @@ "lts": true }, "7.1": { - "version": "7.1.12", - "hash": "sha256:1qaskd7g2pzh32lvfb18qh29hfy3mh2flglh1d9cvr17xnrid5rq", + "version": "7.1.13", + "hash": "sha256:1mqshj3ldn0md1c0am35skznnq5vmz3fvrr0cqmwwp6bzpx9akb1", "lts": false }, "7.2": { From ab787beb39ad78b63dcb8b9c18f4f540b7a5990f Mon Sep 17 00:00:00 2001 From: zowoq <59103226+zowoq@users.noreply.github.com> Date: Wed, 2 Sep 2026 13:13:30 +0000 Subject: [PATCH 085/140] linux_6_18: 6.18.48 -> 6.18.49 --- pkgs/os-specific/linux/kernel/kernels-org.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/kernels-org.json b/pkgs/os-specific/linux/kernel/kernels-org.json index d06d22e0c3b2..5e09fd764d5c 100644 --- a/pkgs/os-specific/linux/kernel/kernels-org.json +++ b/pkgs/os-specific/linux/kernel/kernels-org.json @@ -30,8 +30,8 @@ "lts": true }, "6.18": { - "version": "6.18.48", - "hash": "sha256:137wqvcfl8drb4n51hqc2pw4kg0hl5j7fi8wdgy0hmsb1aqsvgay", + "version": "6.18.49", + "hash": "sha256:14c1l9hbqcjlzfl7bssa43yqsg26sycp5plx4wfnzshz24rnz0mf", "lts": true }, "7.1": { From 975a8ce770df85cf2ba0efb24baf6914ab543cce Mon Sep 17 00:00:00 2001 From: zowoq <59103226+zowoq@users.noreply.github.com> Date: Wed, 2 Sep 2026 13:13:32 +0000 Subject: [PATCH 086/140] linux_6_12: 6.12.107 -> 6.12.108 --- pkgs/os-specific/linux/kernel/kernels-org.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/kernels-org.json b/pkgs/os-specific/linux/kernel/kernels-org.json index 5e09fd764d5c..be2c1c842701 100644 --- a/pkgs/os-specific/linux/kernel/kernels-org.json +++ b/pkgs/os-specific/linux/kernel/kernels-org.json @@ -25,8 +25,8 @@ "lts": true }, "6.12": { - "version": "6.12.107", - "hash": "sha256:0yih5s4xbp1hlyfha49z2j3l9x7i5ij335jfl6f6sbfy7yzcby55", + "version": "6.12.108", + "hash": "sha256:1bxsykj1w8slrn837z05ax8r9d5kkgk5kbjzbngmrm921lhfmlg1", "lts": true }, "6.18": { From ceea471ea9ebdd04e3cc86a89ba957c2ecf006b8 Mon Sep 17 00:00:00 2001 From: zowoq <59103226+zowoq@users.noreply.github.com> Date: Wed, 2 Sep 2026 13:13:35 +0000 Subject: [PATCH 087/140] linux_6_6: 6.6.155 -> 6.6.156 --- pkgs/os-specific/linux/kernel/kernels-org.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/kernels-org.json b/pkgs/os-specific/linux/kernel/kernels-org.json index be2c1c842701..2e1065a06a40 100644 --- a/pkgs/os-specific/linux/kernel/kernels-org.json +++ b/pkgs/os-specific/linux/kernel/kernels-org.json @@ -20,8 +20,8 @@ "lts": true }, "6.6": { - "version": "6.6.155", - "hash": "sha256:10j9cm0jrjjwm8gy8h8nkyj8x3pfhaicj29125qb069c7wkajrsf", + "version": "6.6.156", + "hash": "sha256:07a1dyaxmcv289r0n4agna2li2rfsjdld8279cs18jmg9r52dqmf", "lts": true }, "6.12": { From 767ad7e2568e83fb8ad3041392033fdb1f434a64 Mon Sep 17 00:00:00 2001 From: zowoq <59103226+zowoq@users.noreply.github.com> Date: Wed, 2 Sep 2026 13:13:37 +0000 Subject: [PATCH 088/140] linux_6_1: 6.1.186 -> 6.1.187 --- pkgs/os-specific/linux/kernel/kernels-org.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/kernels-org.json b/pkgs/os-specific/linux/kernel/kernels-org.json index 2e1065a06a40..8b1d7d287733 100644 --- a/pkgs/os-specific/linux/kernel/kernels-org.json +++ b/pkgs/os-specific/linux/kernel/kernels-org.json @@ -5,8 +5,8 @@ "lts": false }, "6.1": { - "version": "6.1.186", - "hash": "sha256:0vi3yqvass80jgjw2yc2iz7p4wfqlih2gvjhzxd20j14pwmw7vgf", + "version": "6.1.187", + "hash": "sha256:0av4fcw3hv4pfql85s2rirxj7hkdr2kdasj219kwl257xa57jvhv", "lts": true }, "5.15": { From a903074785ce385bd1ab2de415f8b2df992bbbd1 Mon Sep 17 00:00:00 2001 From: zowoq <59103226+zowoq@users.noreply.github.com> Date: Wed, 2 Sep 2026 13:13:39 +0000 Subject: [PATCH 089/140] linux_5_15: 5.15.219 -> 5.15.220 --- pkgs/os-specific/linux/kernel/kernels-org.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/kernels-org.json b/pkgs/os-specific/linux/kernel/kernels-org.json index 8b1d7d287733..587a6b98e96e 100644 --- a/pkgs/os-specific/linux/kernel/kernels-org.json +++ b/pkgs/os-specific/linux/kernel/kernels-org.json @@ -10,8 +10,8 @@ "lts": true }, "5.15": { - "version": "5.15.219", - "hash": "sha256:192ws3mf4hvhawdl6amg7a7q7d68v2ijgjsy1cbq2vy2iiwlyjnh", + "version": "5.15.220", + "hash": "sha256:08v7mbwvfgy9vv60j2ssdks4ss218p27rkwwrmjch2hj0ljrkcmm", "lts": true }, "5.10": { From 90e2512eecad7592cba35f54aa26203f98c536b3 Mon Sep 17 00:00:00 2001 From: zowoq <59103226+zowoq@users.noreply.github.com> Date: Wed, 2 Sep 2026 13:13:41 +0000 Subject: [PATCH 090/140] linux_5_10: 5.10.268 -> 5.10.269 --- pkgs/os-specific/linux/kernel/kernels-org.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/kernels-org.json b/pkgs/os-specific/linux/kernel/kernels-org.json index 587a6b98e96e..84c349595f0a 100644 --- a/pkgs/os-specific/linux/kernel/kernels-org.json +++ b/pkgs/os-specific/linux/kernel/kernels-org.json @@ -15,8 +15,8 @@ "lts": true }, "5.10": { - "version": "5.10.268", - "hash": "sha256:0fi6a8gbj60ankrx8gcjswv52k93xcjajcb6jihkwx63vfm4s5kv", + "version": "5.10.269", + "hash": "sha256:1sf6iikwr9rikdi097xplz7yw1jj4cx6ldng7gzp8rj0360icnlw", "lts": true }, "6.6": { From 1265f5c7e1a577ebdf473e002db6a0c106c1ab1e Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 13:21:07 +0000 Subject: [PATCH 091/140] supercronic: 0.2.48 -> 0.2.49 --- pkgs/by-name/su/supercronic/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/su/supercronic/package.nix b/pkgs/by-name/su/supercronic/package.nix index 39abc955861a..a74c5e590315 100644 --- a/pkgs/by-name/su/supercronic/package.nix +++ b/pkgs/by-name/su/supercronic/package.nix @@ -9,16 +9,16 @@ buildGoModule (finalAttrs: { pname = "supercronic"; - version = "0.2.48"; + version = "0.2.49"; src = fetchFromGitHub { owner = "aptible"; repo = "supercronic"; rev = "v${finalAttrs.version}"; - hash = "sha256-29VJSC4bdmarniKe9rZVX0+8BTt9tYCbLetXCfx/oec="; + hash = "sha256-vjlsww/YEbG/HJaExH86kyciuTNs6583CFIFf2S8Rzk="; }; - vendorHash = "sha256-v03ui07OuOGmeaCyW3VrKmtFDpRSanuMAYWNSqojhro="; + vendorHash = "sha256-qsxNAMTHEPtLuedEOAnE+BI65uo4iL620mGz0aveFQc="; excludedPackages = [ "cronexpr/cronexpr" ]; From 02469fb2fbae14b506067c3faa3ddb3e161e012c Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 13:32:15 +0000 Subject: [PATCH 092/140] pandera: 0.33.0 -> 0.33.1 --- pkgs/development/python-modules/pandera/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/pandera/default.nix b/pkgs/development/python-modules/pandera/default.nix index 790904b129d5..e130e0b03d05 100644 --- a/pkgs/development/python-modules/pandera/default.nix +++ b/pkgs/development/python-modules/pandera/default.nix @@ -49,7 +49,7 @@ buildPythonPackage (finalAttrs: { pname = "pandera"; - version = "0.33.0"; + version = "0.33.1"; pyproject = true; __structuredAttrs = true; @@ -57,7 +57,7 @@ buildPythonPackage (finalAttrs: { owner = "unionai-oss"; repo = "pandera"; tag = "v${finalAttrs.version}"; - hash = "sha256-QW+od2owqkErtz8fZc+LFVtsVAdMZFtUnR+9eaAXPK4="; + hash = "sha256-5sM/iEbv1+ojqwL/E9cVQxJW3u1dlzMQ6iAiKAjV+DI="; }; build-system = [ From 47f64cac394b84ea4e830a55145d4b649f9b3fd9 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 13:58:21 +0000 Subject: [PATCH 093/140] orbvis: 0.3.3 -> 0.3.4 --- pkgs/by-name/or/orbvis/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/or/orbvis/package.nix b/pkgs/by-name/or/orbvis/package.nix index 6099bb5b8ba5..f845b69b8511 100644 --- a/pkgs/by-name/or/orbvis/package.nix +++ b/pkgs/by-name/or/orbvis/package.nix @@ -14,13 +14,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "orbvis"; - version = "0.3.3"; + version = "0.3.4"; src = fetchFromGitHub { owner = "wojciech-graj"; repo = "orbvis"; tag = "v${finalAttrs.version}"; - hash = "sha256-U19kslgAULBBFozK5KUtew6KRsFeJ4+h8bL9cXmnzso="; + hash = "sha256-e41CDv86zz+x5LF2JDZuxzgIvhHBM0s2XHoQMHfMRAg="; }; nativeBuildInputs = [ From ba59fc921a5fca07bba3f9d08991050ecdddb1a4 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 14:08:33 +0000 Subject: [PATCH 094/140] terraform-providers.auth0_auth0: 1.55.0 -> 1.56.0 --- .../networking/cluster/terraform-providers/providers.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/applications/networking/cluster/terraform-providers/providers.json b/pkgs/applications/networking/cluster/terraform-providers/providers.json index b8240f9bc969..af65c4efc194 100644 --- a/pkgs/applications/networking/cluster/terraform-providers/providers.json +++ b/pkgs/applications/networking/cluster/terraform-providers/providers.json @@ -82,13 +82,13 @@ "vendorHash": "sha256-L9IGENsL8Kibq5O/JOgCxLRUxgS7q9G/NovC/Q7tw48=" }, "auth0_auth0": { - "hash": "sha256-SpGTMAFEiJVGpXYAIigJQditDvs8sU2Bz57ohanccAM=", + "hash": "sha256-t/AdooXhTpu4UXE8u6cvdVPL4HFUQQWOSAjw1RXFs8c=", "homepage": "https://registry.terraform.io/providers/auth0/auth0", "owner": "auth0", "repo": "terraform-provider-auth0", - "rev": "v1.55.0", + "rev": "v1.56.0", "spdx": "MPL-2.0", - "vendorHash": "sha256-ajl7q+9oA+NA5eqAXA5yjej03qdI5nimRNQW6GoGOq4=" + "vendorHash": "sha256-ydki+y2A6g94xNGVr7xZkBB/grEbOOD4LRwYGAmzLsc=" }, "aviatrixsystems_aviatrix": { "hash": "sha256-46djOfAj/5kfeoKLQHbeKefzdGbmlBATR+uN/IaAn8I=", From e2196583c007573d5696659e5a88b122a8e0873f Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 14:31:34 +0000 Subject: [PATCH 095/140] terraform-providers.vpsfreecz_vpsadmin: 1.3.0 -> 1.5.0 --- .../networking/cluster/terraform-providers/providers.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/applications/networking/cluster/terraform-providers/providers.json b/pkgs/applications/networking/cluster/terraform-providers/providers.json index b8240f9bc969..f863242ed2eb 100644 --- a/pkgs/applications/networking/cluster/terraform-providers/providers.json +++ b/pkgs/applications/networking/cluster/terraform-providers/providers.json @@ -1490,13 +1490,13 @@ "vendorHash": "sha256-GRnVhGpVgFI83Lg34Zv1xgV5Kp8ioKTFV5uaqS80ATg=" }, "vpsfreecz_vpsadmin": { - "hash": "sha256-T+az9OH9/ZMSJewZpC9VLSXOZ5N/wz00VRnl9Ab4aeI=", + "hash": "sha256-1r2SqoRWJJhQej8D3LXHOEXT5RSxE4t6s7QuiNoIqpg=", "homepage": "https://registry.terraform.io/providers/vpsfreecz/vpsadmin", "owner": "vpsfreecz", "repo": "terraform-provider-vpsadmin", - "rev": "v1.3.0", + "rev": "v1.5.0", "spdx": "MPL-2.0", - "vendorHash": "sha256-98lrEH7j4Fl0oSEoL75e0h+8ySLacPK2k0OehY3jqhA=" + "vendorHash": "sha256-fbFpENa1/8Qs6RnTUMi0LDATho8+WuKhj4i8S/dG3Yg=" }, "vultr_vultr": { "hash": "sha256-hK4/Pzj0UtWDLQS3cRMC73ZRr20HCWqI+jUlTUHcHaw=", From 3f3c3b1b4de12617f7d0db26c9768185e2a49a98 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 14:32:56 +0000 Subject: [PATCH 096/140] goose: 3.27.3 -> 3.28.0 --- pkgs/by-name/go/goose/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/go/goose/package.nix b/pkgs/by-name/go/goose/package.nix index f58da1fbc62d..630cd5bd8bdf 100644 --- a/pkgs/by-name/go/goose/package.nix +++ b/pkgs/by-name/go/goose/package.nix @@ -7,17 +7,17 @@ buildGoModule (finalAttrs: { pname = "goose"; - version = "3.27.3"; + version = "3.28.0"; src = fetchFromGitHub { owner = "pressly"; repo = "goose"; rev = "v${finalAttrs.version}"; - hash = "sha256-CSS0OtC4/EeQD7PGin64U0Fag2z490RQ7CKNBRyp8f8="; + hash = "sha256-V7kpDIJOyWB0O6uGQmxO1lgfdUYXIGJ3ycmXGu20H94="; }; proxyVendor = true; - vendorHash = "sha256-opO6G9Fdyt27GlWyaB/6J1xhm3wTgH9Xc/FYcLcqBVs="; + vendorHash = "sha256-phtM6ClEwszIE7TQVXJbRLvSk0uSbng6h/pQsjHmjGU="; # skipping: end-to-end tests require a docker daemon postPatch = '' From 48cc27cb09de573f7137a2035855b07c9680a4ff Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 15:31:25 +0000 Subject: [PATCH 097/140] prometheus-statsd-exporter: 0.28.0 -> 0.31.0 --- pkgs/by-name/pr/prometheus-statsd-exporter/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/pr/prometheus-statsd-exporter/package.nix b/pkgs/by-name/pr/prometheus-statsd-exporter/package.nix index d57e78b68df7..a1a6826cfd30 100644 --- a/pkgs/by-name/pr/prometheus-statsd-exporter/package.nix +++ b/pkgs/by-name/pr/prometheus-statsd-exporter/package.nix @@ -6,13 +6,13 @@ buildGoModule rec { pname = "statsd_exporter"; - version = "0.28.0"; + version = "0.31.0"; src = fetchFromGitHub { owner = "prometheus"; repo = "statsd_exporter"; rev = "v${version}"; - hash = "sha256-h58yD+jmvUCvYsJqNcBSR1f+5YgDyMbLDd3I0HW9/kA="; + hash = "sha256-6t2j8jzvxhtSPzo0QBFqggMiZk/vcKRiWeRhV8jZqjk="; }; ldflags = @@ -29,7 +29,7 @@ buildGoModule rec { "-X ${t}.BuildDate=unknown" ]; - vendorHash = "sha256-QKDvoctvvdijQ+ZlClqTyJZfDzqAIikAwOQds9+NQIc="; + vendorHash = "sha256-iMRqQ77KbOaxSneMRm1ihcqqprxcw/azeyOOyR4Fu0Q="; meta = { description = "Receives StatsD-style metrics and exports them to Prometheus"; From bcb11b587887af15abd1d3bab748c3b47a0f45d9 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 15:40:47 +0000 Subject: [PATCH 098/140] balena-compose-parser: 0.3.0 -> 0.4.0 --- pkgs/by-name/ba/balena-compose-parser/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ba/balena-compose-parser/package.nix b/pkgs/by-name/ba/balena-compose-parser/package.nix index db1048f21518..211ab2b2b193 100644 --- a/pkgs/by-name/ba/balena-compose-parser/package.nix +++ b/pkgs/by-name/ba/balena-compose-parser/package.nix @@ -6,13 +6,13 @@ buildGoModule rec { __structuredAttrs = true; pname = "balena-compose-parser"; - version = "0.3.0"; + version = "0.4.0"; src = fetchFromGitHub { owner = "balena-io-modules"; repo = "balena-compose-parser"; rev = "v${version}"; - hash = "sha256-VOFSdcygi3YlRlV48zV1fGtRgFSio2KBZCs25iqBmLY="; + hash = "sha256-fEvLu2xZlYoILM4DThiSQHG2gbGOB5IQVgmwcLKsKwo="; }; modRoot = "lib"; From 8bd1fa478dc05512b6399b57eefbaed846108d4f Mon Sep 17 00:00:00 2001 From: Dustin Sweigart Date: Mon, 13 Jul 2026 10:06:06 -0400 Subject: [PATCH 099/140] nixos/step-ca: add extraArgs option for additional step-ca CLI flags --- nixos/modules/services/security/step-ca.nix | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/nixos/modules/services/security/step-ca.nix b/nixos/modules/services/security/step-ca.nix index d92900b7220b..1fb880d067cd 100644 --- a/nixos/modules/services/security/step-ca.nix +++ b/nixos/modules/services/security/step-ca.nix @@ -54,6 +54,15 @@ in ::: ''; }; + extraArgs = lib.mkOption { + type = lib.types.listOf lib.types.str; + default = [ ]; + example = [ + "--resolver=10.1.2.3:53" + "--quiet" + ]; + description = "Ad-hoc command-line arguments passed to the service at startup."; + }; intermediatePasswordFile = lib.mkOption { type = lib.types.nullOr lib.types.externalPath; default = null; @@ -114,6 +123,7 @@ in + lib.optionalString ( cfg.intermediatePasswordFile != null ) " --password-file \${CREDENTIALS_DIRECTORY}/intermediate_password" + + lib.optionalString (cfg.extraArgs != [ ]) " ${lib.escapeShellArgs cfg.extraArgs}" ) ]; From 5ae2545bac7ae3ccb119eca4a753d6e4236d0f0e Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 17:12:39 +0000 Subject: [PATCH 100/140] xdg-desktop-portal-generic: 0.5.0 -> 0.6.1 --- pkgs/by-name/xd/xdg-desktop-portal-generic/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/xd/xdg-desktop-portal-generic/package.nix b/pkgs/by-name/xd/xdg-desktop-portal-generic/package.nix index a2f604b84519..2ffed1bf60d2 100644 --- a/pkgs/by-name/xd/xdg-desktop-portal-generic/package.nix +++ b/pkgs/by-name/xd/xdg-desktop-portal-generic/package.nix @@ -11,13 +11,13 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "xdg-desktop-portal-generic"; - version = "0.5.0"; + version = "0.6.1"; src = fetchFromGitHub { owner = "lamco-admin"; repo = "xdg-desktop-portal-generic"; rev = "v${finalAttrs.version}"; - hash = "sha256-Owx4GnsVzu16Md0ARQLwkjFN5bCurhS216nguA95EDg="; + hash = "sha256-Y7fdAbge1wG8lE0BUBSNGEbz3it2cZ8o80ayUEdFt8M="; }; __structuredAttrs = true; @@ -31,7 +31,7 @@ rustPlatform.buildRustPackage (finalAttrs: { --replace-fail '/usr/libexec/' '${placeholder "out"}/libexec/' ''; - cargoHash = "sha256-m/OdKQNX4ufUBIBg5+dZyr46X9ovgKXMLa5AvdbOQ5Q="; + cargoHash = "sha256-3t2w37jqU9iLRZWldnuNZkqE4jreMe+OVl7f3ZHyGXc="; nativeBuildInputs = [ pkg-config From 7a2148e931419f75f67620349d377ddf32462cda Mon Sep 17 00:00:00 2001 From: lucasew Date: Wed, 2 Sep 2026 14:26:56 -0300 Subject: [PATCH 101/140] trilium-server: fix aarch64-linux build 0.105.0 added rm of the unused musl better-sqlite3 prebuild so autoPatchelfHook would not try to patch it. The path was hardcoded to linuxmusl-x64.node. The arm64 tarball ships linuxmusl-arm64.node instead, so the build died in installPhase. Remove any linuxmusl-*.node prebuild. Resolves #559163 Assisted-by: Grok Build (xAI Grok 4.6) --- pkgs/by-name/tr/trilium-server/package.nix | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/tr/trilium-server/package.nix b/pkgs/by-name/tr/trilium-server/package.nix index e25982d43b7d..0485ece28e54 100644 --- a/pkgs/by-name/tr/trilium-server/package.nix +++ b/pkgs/by-name/tr/trilium-server/package.nix @@ -46,7 +46,8 @@ stdenv.mkDerivation { cp -r ./* "$out/share/trilium-server/" - rm $out/share/trilium-server/node_modules/better-sqlite3/prebuilds/linuxmusl-x64.node + # Unused musl prebuilds confuse autoPatchelfHook (glibc-only). + rm -f "$out/share/trilium-server/node_modules/better-sqlite3/prebuilds"/linuxmusl-*.node makeWrapper "$out/share/trilium-server/node/bin/node" "$out/bin/trilium-server" \ --chdir "$out/share/trilium-server" \ From 8a52ddab40d0765d19b0cdf611d08df8d2d66a7c Mon Sep 17 00:00:00 2001 From: jopejoe1 Date: Wed, 2 Sep 2026 18:04:35 +0000 Subject: [PATCH 102/140] firefox-beta-unwrapped: 155.0b5 -> 156.0b2 --- .../networking/browsers/firefox/packages/firefox-beta.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/networking/browsers/firefox/packages/firefox-beta.nix b/pkgs/applications/networking/browsers/firefox/packages/firefox-beta.nix index 8a03e06626a9..20f7f74a25af 100644 --- a/pkgs/applications/networking/browsers/firefox/packages/firefox-beta.nix +++ b/pkgs/applications/networking/browsers/firefox/packages/firefox-beta.nix @@ -10,11 +10,11 @@ buildMozillaMach rec { pname = "firefox-beta"; binaryName = "firefox-beta"; - version = "155.0b5"; + version = "156.0b2"; applicationName = "Firefox Beta"; src = fetchurl { url = "mirror://mozilla/firefox/releases/${version}/source/firefox-${version}.source.tar.xz"; - sha512 = "30b4b84c80057a992e763b8f967c65f46308324fd41c0307c9302e262e6428c379861ccd9ce52dde15d0dc3f4410b95a8c047ea7e5af9d90e60e7bb57ee59137"; + sha512 = "5b685f8b947af0b519c59a308fba6a41f9481df68b7fb6f4b395707653c3ef1822817d2f867d663081cd2d61c8fd4537f46b8002da84b5efa9b8a57ae9491164"; }; meta = { From 2e9ba061138d7d404fb5f71f5cc2d59799e4f386 Mon Sep 17 00:00:00 2001 From: jopejoe1 Date: Wed, 2 Sep 2026 18:04:43 +0000 Subject: [PATCH 103/140] firefox-devedition-unwrapped: 155.0b5 -> 156.0b2 --- .../browsers/firefox/packages/firefox-devedition.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/networking/browsers/firefox/packages/firefox-devedition.nix b/pkgs/applications/networking/browsers/firefox/packages/firefox-devedition.nix index 449995dd3620..f214b36faab1 100644 --- a/pkgs/applications/networking/browsers/firefox/packages/firefox-devedition.nix +++ b/pkgs/applications/networking/browsers/firefox/packages/firefox-devedition.nix @@ -10,13 +10,13 @@ buildMozillaMach rec { pname = "firefox-devedition"; binaryName = "firefox-devedition"; - version = "155.0b5"; + version = "156.0b2"; applicationName = "Firefox Developer Edition"; requireSigning = false; branding = "browser/branding/aurora"; src = fetchurl { url = "mirror://mozilla/devedition/releases/${version}/source/firefox-${version}.source.tar.xz"; - sha512 = "8e9ccc65a8cd6640171d4891fe8d01435cd524cee8164a5829429df827bcc2b49c3b7e6a092aaf5bfa48140d7f40f6c9cb371af48a7321132ea6ee5da0af08e3"; + sha512 = "683326ff4367f9b807c4c5b93f100970258ada9838da2c597358105a99ff4aa7e33269fe67d6c68d466e2f539d2bea3015457109516af19e1785588ce43426b5"; }; # buildMozillaMach sets MOZ_APP_REMOTINGNAME during configuration, but From dcceb1bb27c9bf659f7606616896881991302e63 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 18:05:21 +0000 Subject: [PATCH 104/140] frame-media-converter: 0.33.0 -> 0.33.1 --- pkgs/by-name/fr/frame-media-converter/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/fr/frame-media-converter/package.nix b/pkgs/by-name/fr/frame-media-converter/package.nix index a5e308a12ae7..634fac621ba7 100644 --- a/pkgs/by-name/fr/frame-media-converter/package.nix +++ b/pkgs/by-name/fr/frame-media-converter/package.nix @@ -25,7 +25,7 @@ let in rustPlatform.buildRustPackage (finalAttrs: { pname = "frame-media-converter"; - version = "0.33.0"; + version = "0.33.1"; __structuredAttrs = true; @@ -33,10 +33,10 @@ rustPlatform.buildRustPackage (finalAttrs: { owner = "66HEX"; repo = "frame"; tag = finalAttrs.version; - hash = "sha256-Nz1ct+Hkc1f7llXT925gBwAivfz1QCpTJW1WzjratTI="; + hash = "sha256-oUJ6yiSZGrpdKra22H/nyLjDh9f6p9gOA9TeXjlDuRY="; }; - cargoHash = "sha256-n1HlMAYHrHwZN+nxA5dgTghcrNaYKL3LLtphcc2Ty7U="; + cargoHash = "sha256-Rq2/CWxKN7HmmFtmt26CMfVwmwc4Wl2wnbvB9inVsHw="; cargoBuildFlags = cargoFlags; cargoTestFlags = cargoFlags; From ebeee09735bbf4527d46570fef6c9f00549bceee Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Wed, 2 Sep 2026 20:08:01 +0200 Subject: [PATCH 105/140] python3Packages.alibabacloud-ecs20140526: 7.10.0 -> 7.11.1 --- .../python-modules/alibabacloud-ecs20140526/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/alibabacloud-ecs20140526/default.nix b/pkgs/development/python-modules/alibabacloud-ecs20140526/default.nix index 777b98d5f535..bdb0236d0680 100644 --- a/pkgs/development/python-modules/alibabacloud-ecs20140526/default.nix +++ b/pkgs/development/python-modules/alibabacloud-ecs20140526/default.nix @@ -9,7 +9,7 @@ buildPythonPackage (finalAttrs: { pname = "alibabacloud-ecs20140526"; - version = "7.10.0"; + version = "7.11.1"; pyproject = true; __structuredAttrs = true; @@ -17,7 +17,7 @@ buildPythonPackage (finalAttrs: { src = fetchPypi { pname = "alibabacloud_ecs20140526"; inherit (finalAttrs) version; - hash = "sha256-1X48Rz1Fd9ggw7f4eqGJMGJAxtgQ/qF/8hKS9p3gKkk="; + hash = "sha256-q9vqFRjbyed8RldEEXGGJe6wlDL/XN6K1LsdPr1zcEU="; }; build-system = [ setuptools ]; From 7fc354c812f3aeb1a207ae0400ec60e928a0d7bd Mon Sep 17 00:00:00 2001 From: Pol Dellaiera Date: Wed, 2 Sep 2026 19:59:34 +0200 Subject: [PATCH 106/140] python3Packages.lxmf: 1.1.0 -> 1.1.1 --- pkgs/development/python-modules/lxmf/default.nix | 15 +++++++-------- 1 file changed, 7 insertions(+), 8 deletions(-) diff --git a/pkgs/development/python-modules/lxmf/default.nix b/pkgs/development/python-modules/lxmf/default.nix index 4dd76bdccc70..cd15b5ec0e08 100644 --- a/pkgs/development/python-modules/lxmf/default.nix +++ b/pkgs/development/python-modules/lxmf/default.nix @@ -1,7 +1,7 @@ { lib, buildPythonPackage, - fetchFromGitHub, + fetchPypi, # rns optionally depends on lxmf but we can't have two versions of rns in a closure propagateRns ? false, qrcode, @@ -12,15 +12,14 @@ buildPythonPackage (finalAttrs: { pname = "lxmf"; - version = "1.1.0"; + version = "1.1.1"; pyproject = true; __structuredAttrs = true; - src = fetchFromGitHub { - owner = "markqvist"; - repo = "lxmf"; - tag = finalAttrs.version; - hash = "sha256-XiBBf9eqW7BWCcRJzgQ0SrItoF9hr33u9nK6VBkSM9Y="; + src = fetchPypi { + inherit (finalAttrs) version; + pname = "lxmf"; + hash = "sha256-8vfqF9eT/MMsq4JugejpgkQE0CXR/HGxQ74yQtReal4="; }; build-system = [ setuptools ]; @@ -45,7 +44,7 @@ buildPythonPackage (finalAttrs: { meta = { description = "Lightweight Extensible Message Format for Reticulum"; homepage = "https://github.com/markqvist/lxmf"; - changelog = "https://github.com/markqvist/LXMF/releases/tag/${finalAttrs.src.tag}"; + changelog = "https://github.com/markqvist/LXMF/releases/tag/${finalAttrs.version}"; license = lib.licenses.reticulum; maintainers = with lib.maintainers; [ drupol From 350650cd7191041a5d2d6531819f7a7a18a65aa2 Mon Sep 17 00:00:00 2001 From: Pol Dellaiera Date: Wed, 2 Sep 2026 18:58:41 +0200 Subject: [PATCH 107/140] python3Packages.nomadnet: 1.2.8 -> 1.2.9 --- pkgs/development/python-modules/nomadnet/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/nomadnet/default.nix b/pkgs/development/python-modules/nomadnet/default.nix index 43aebc2a797f..6c3077d7240c 100644 --- a/pkgs/development/python-modules/nomadnet/default.nix +++ b/pkgs/development/python-modules/nomadnet/default.nix @@ -12,14 +12,14 @@ buildPythonPackage (finalAttrs: { pname = "nomadnet"; - version = "1.2.8"; + version = "1.2.9"; pyproject = true; __structuredAttrs = true; src = fetchPypi { inherit (finalAttrs) version pname; - hash = "sha256-6RQsbUIruRc2r+br62GArjRQTst7xrR5R1YFVvjroeE="; + hash = "sha256-3ySYwQuBf/A/WI3nlywZTEZ7yAszbMLVPVOwkXBY5ls="; }; build-system = [ setuptools ]; From 4bb4ff35346554cf8d0728210711bdc538a7a6cd Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Wed, 2 Sep 2026 20:08:34 +0200 Subject: [PATCH 108/140] python3Packages.alibabacloud-sas20181203: 9.3.3 -> 10.1.0 --- .../python-modules/alibabacloud-sas20181203/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/alibabacloud-sas20181203/default.nix b/pkgs/development/python-modules/alibabacloud-sas20181203/default.nix index 11585202a1db..65c60c4feb3b 100644 --- a/pkgs/development/python-modules/alibabacloud-sas20181203/default.nix +++ b/pkgs/development/python-modules/alibabacloud-sas20181203/default.nix @@ -9,7 +9,7 @@ buildPythonPackage (finalAttrs: { pname = "alibabacloud-sas20181203"; - version = "9.3.3"; + version = "10.1.0"; pyproject = true; __structuredAttrs = true; @@ -17,7 +17,7 @@ buildPythonPackage (finalAttrs: { src = fetchPypi { pname = "alibabacloud_sas20181203"; inherit (finalAttrs) version; - hash = "sha256-Y1xDWiGmjuDkcgF6c031fe5xBO4tA8xUH9DIXBN2oRw="; + hash = "sha256-P2S5K15GHzXHgP9krkx51aI2xVwehttmdYL8BN88vQs="; }; build-system = [ setuptools ]; From e0fce8034884c23395748d2d185ba11f9efc0fb9 Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Wed, 2 Sep 2026 20:08:53 +0200 Subject: [PATCH 109/140] python3Packages.alibabacloud-vpc20160428: 7.1.6 -> 7.2.0 --- .../python-modules/alibabacloud-vpc20160428/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/alibabacloud-vpc20160428/default.nix b/pkgs/development/python-modules/alibabacloud-vpc20160428/default.nix index d8b6dce29b62..6dc483cd634a 100644 --- a/pkgs/development/python-modules/alibabacloud-vpc20160428/default.nix +++ b/pkgs/development/python-modules/alibabacloud-vpc20160428/default.nix @@ -9,7 +9,7 @@ buildPythonPackage (finalAttrs: { pname = "alibabacloud-vpc20160428"; - version = "7.1.6"; + version = "7.2.0"; pyproject = true; __structuredAttrs = true; @@ -17,7 +17,7 @@ buildPythonPackage (finalAttrs: { src = fetchPypi { pname = "alibabacloud_vpc20160428"; inherit (finalAttrs) version; - hash = "sha256-EJE/0D1EJdDK6A7FpJo72m/QmkzFwRDUHE90vb6AmYA="; + hash = "sha256-7z9ISKULT4/Cjssv7S6jt/qeXXbNNuYCqgwciMethvo="; }; build-system = [ setuptools ]; From 4b7aded8f7996032721e0dd481e1d6daed485e57 Mon Sep 17 00:00:00 2001 From: eljamm Date: Wed, 2 Sep 2026 18:08:58 +0000 Subject: [PATCH 110/140] linux_xanmod: 6.18.47 -> 6.18.49 - Changelog: https://dl.xanmod.org/changelog/6.18/ChangeLog-6.18.49-xanmod1.gz - Diff: https://gitlab.com/xanmod/linux/-/compare/6.18.47-xanmod1..6.18.49-xanmod1?from_project_id=51590166 --- pkgs/os-specific/linux/kernel/xanmod-kernels.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/xanmod-kernels.nix b/pkgs/os-specific/linux/kernel/xanmod-kernels.nix index 524f23d39352..1e55fb70ac4e 100644 --- a/pkgs/os-specific/linux/kernel/xanmod-kernels.nix +++ b/pkgs/os-specific/linux/kernel/xanmod-kernels.nix @@ -15,8 +15,8 @@ let variants = { # ./update-xanmod.sh lts lts = { - version = "6.18.47"; - hash = "sha256-FdC/RgaV7p3asZp2skiJKJ4JCx5TI+L4eZxOx2+Pdz0="; + version = "6.18.49"; + hash = "sha256-4kjRCVsj/nE4gfRg8KgagojPFiAVNa9zmAqls9Le6mI="; isLTS = true; }; # ./update-xanmod.sh main From 91a8ff572fd67e1ab521ce8013a94c0735af527d Mon Sep 17 00:00:00 2001 From: Jost Alemann Date: Wed, 2 Sep 2026 20:06:20 +0200 Subject: [PATCH 111/140] foot: 1.27.0 -> 1.28.0 Changelog: https://codeberg.org/dnkl/foot/releases/tag/1.28.0 Diff: https://codeberg.org/dnkl/foot/compare/1.27.0...1.28.0 --- pkgs/by-name/fo/foot/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/fo/foot/package.nix b/pkgs/by-name/fo/foot/package.nix index 2f18f121c896..581df7b8ad00 100644 --- a/pkgs/by-name/fo/foot/package.nix +++ b/pkgs/by-name/fo/foot/package.nix @@ -27,7 +27,7 @@ }: let - version = "1.27.0"; + version = "1.28.0"; # build stimuli file for PGO build and the script to generate it # independently of the foot's build, so we can cache the result @@ -40,7 +40,7 @@ let src = fetchurl { url = "https://codeberg.org/dnkl/foot/raw/tag/${version}/scripts/generate-alt-random-writes.py"; - hash = "sha256-d7oE3hSStET9Bz8PcmRHSZ+ga+7lrL3/oJdx7phNei8="; + hash = "sha256-RUCG4EK9+aXe+EKvFYv6/JzQBglGZHyaEpr63v8akW4="; }; dontUnpack = true; @@ -103,7 +103,7 @@ stdenv.mkDerivation { owner = "dnkl"; repo = "foot"; tag = version; - hash = "sha256-jbE44SpMqDhOOT2o4Wh7UCdXn6bBqxOMskCHHTzEKmU="; + hash = "sha256-CZlbQut5jM8/dWuLlJPDaLBykV7K5l/caB3DLQ94mG8="; }; separateDebugInfo = true; From ac76c1207784eee8bc6a262d78fb91a18414a80a Mon Sep 17 00:00:00 2001 From: jopejoe1 Date: Wed, 2 Sep 2026 18:05:44 +0000 Subject: [PATCH 112/140] python313Packages.gftools: 0.9.999 -> 0.9991 --- pkgs/development/python-modules/gftools/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/gftools/default.nix b/pkgs/development/python-modules/gftools/default.nix index e13b7af1b60e..97b29cc21b3a 100644 --- a/pkgs/development/python-modules/gftools/default.nix +++ b/pkgs/development/python-modules/gftools/default.nix @@ -58,14 +58,14 @@ let in buildPythonPackage rec { pname = "gftools"; - version = "0.9.999"; + version = "0.9991"; pyproject = true; src = fetchFromGitHub { owner = "googlefonts"; repo = "gftools"; tag = "v${version}"; - hash = "sha256-jKd/i0qXzPJNOxzO2Ds3BxP2RDoelNhKutqeaz/yQww="; + hash = "sha256-660/sU9aSt1y3iljss82SJT8QTMnVMjjJECIgHA9xso="; }; postPatch = '' From 03932f3c17db4499e868cff3fd4fa8722603e848 Mon Sep 17 00:00:00 2001 From: jopejoe1 Date: Wed, 2 Sep 2026 18:05:36 +0000 Subject: [PATCH 113/140] python313Packages.gflanguages: 0.7.10 -> 0.7.11 --- pkgs/development/python-modules/gflanguages/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/gflanguages/default.nix b/pkgs/development/python-modules/gflanguages/default.nix index 8367305b78f9..a5f86b4840cc 100644 --- a/pkgs/development/python-modules/gflanguages/default.nix +++ b/pkgs/development/python-modules/gflanguages/default.nix @@ -14,14 +14,14 @@ buildPythonPackage (finalAttrs: { pname = "gflanguages"; - version = "0.7.10"; + version = "0.7.11"; pyproject = true; src = fetchFromGitHub { owner = "googlefonts"; repo = "lang"; tag = "v${finalAttrs.version}"; - hash = "sha256-N7hFJ9qvb+i8j7NKGtJivFnrCKBE4tsvBAclrFBGFiw="; + hash = "sha256-skybvMeSP+F3Bz3PJEB7ZIEVhLdwBc8+VemDcC+1FZc="; }; # Relax the dependency on protobuf 3. Other packages in the Google Fonts From 979bde13787e092dc58c2f147e90024022296ea8 Mon Sep 17 00:00:00 2001 From: eljamm Date: Wed, 2 Sep 2026 18:11:06 +0000 Subject: [PATCH 114/140] linux_xanmod_latest: 7.1.11 -> 7.1.13 - Changelog: https://dl.xanmod.org/changelog/7.1/ChangeLog-7.1.13-xanmod1.gz - Diff: https://gitlab.com/xanmod/linux/-/compare/7.1.11-xanmod1..7.1.13-xanmod1?from_project_id=51590166 --- pkgs/os-specific/linux/kernel/xanmod-kernels.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/xanmod-kernels.nix b/pkgs/os-specific/linux/kernel/xanmod-kernels.nix index 1e55fb70ac4e..532c6641863a 100644 --- a/pkgs/os-specific/linux/kernel/xanmod-kernels.nix +++ b/pkgs/os-specific/linux/kernel/xanmod-kernels.nix @@ -21,8 +21,8 @@ let }; # ./update-xanmod.sh main main = { - version = "7.1.11"; - hash = "sha256-Ao0TJVW4PyMHe9HXDRbnFYlz/ikrgNAMiA3K3LAwFeM="; + version = "7.1.13"; + hash = "sha256-6ENhT+sf/e0xd2e0r3adcept7fasxz8SCgrpgzEhxU8="; }; }; From 14b4e9abf85117eae055a691220f24490c32e567 Mon Sep 17 00:00:00 2001 From: jopejoe1 Date: Wed, 2 Sep 2026 18:05:02 +0000 Subject: [PATCH 115/140] discord: update various discord-canary: 1.0.1766 -> 1.0.1794 discord-development: 1.0.1010 -> 1.0.1010 discord-ptb: 1.0.211 -> 1.0.212 discord: 1.0.155 -> 1.0.156 pkgsCross.aarch64-darwin.discord-canary: 0.0.1294 -> 0.0.1306 pkgsCross.aarch64-darwin.discord-development: 1.0.1021 -> 1.0.1021 pkgsCross.aarch64-darwin.discord-ptb: 0.0.256 -> 0.0.257 pkgsCross.aarch64-darwin.discord: 0.0.409 -> 0.0.410 --- .../instant-messengers/discord/sources.json | 518 +++++++++--------- 1 file changed, 259 insertions(+), 259 deletions(-) diff --git a/pkgs/applications/networking/instant-messengers/discord/sources.json b/pkgs/applications/networking/instant-messengers/discord/sources.json index 8754e998d57c..864cac3c3607 100644 --- a/pkgs/applications/networking/instant-messengers/discord/sources.json +++ b/pkgs/applications/networking/instant-messengers/discord/sources.json @@ -1,83 +1,78 @@ { "linux-canary": { "distro": { - "hash": "sha256-4j3ii6uD9f0tV71mU8XFFxWch7LiWCwclnkHa5NGj+4=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/linux/x64/1.0.1766/full.distro" + "hash": "sha256-UHlT587DCEDz7YSxN57S3mZ+4R2bi8/Aqvf62QuibEY=", + "url": "https://canary.dl2.discordapp.net/distro/app/canary/linux/x64/1.0.1794/full.distro" }, "kind": "distro", "modules": { - "discord_arborium": { - "hash": "sha256-I6JRlVELq5Mldcaz+lKMt0izsNSfWdw/e5JPqBGLOzE=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/linux/x64/1.0.1766/discord_arborium/1/full.distro", - "version": 1 - }, "discord_cloudsync": { - "hash": "sha256-ZulqlXaIFr+Ds20ON02HZLn45JFqq9POuYoFV1t0eZI=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/linux/x64/1.0.1766/discord_cloudsync/1/full.distro", + "hash": "sha256-/gA7pLPkyWAMQc2gNgq9L14W9hu3Bi5rPtCyWZGghqQ=", + "url": "https://canary.dl2.discordapp.net/distro/app/canary/linux/x64/1.0.1794/discord_cloudsync/1/full.distro", "version": 1 }, "discord_desktop_core": { - "hash": "sha256-H7mcz7tm2FQXrmbfLz9n1bxbuAMNAnGK9iWEbMoVoew=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/linux/x64/1.0.1766/discord_desktop_core/1/full.distro", + "hash": "sha256-/iCoCP3vNeAVXRK3smZdf8XrQNYanejlcjZ9fcddbHg=", + "url": "https://canary.dl2.discordapp.net/distro/app/canary/linux/x64/1.0.1794/discord_desktop_core/1/full.distro", "version": 1 }, "discord_dispatch": { - "hash": "sha256-XTmNR20AqtrpWiwOy0vMrUy0K2bDG7P27a80hbvWS58=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/linux/x64/1.0.1766/discord_dispatch/1/full.distro", + "hash": "sha256-KjrgWGgTHuNOqm2NnOiDATyAgngaGSktATe5OnV3Cjg=", + "url": "https://canary.dl2.discordapp.net/distro/app/canary/linux/x64/1.0.1794/discord_dispatch/1/full.distro", "version": 1 }, "discord_erlpack": { - "hash": "sha256-zH6H8EchYRXbK7HgG6F09Oiieep6JyTw1+r2nRmtQ6Q=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/linux/x64/1.0.1766/discord_erlpack/1/full.distro", + "hash": "sha256-eLse+k1w07/mGh0h3beXGZtsCz7NuP6qSQH6hJcNspM=", + "url": "https://canary.dl2.discordapp.net/distro/app/canary/linux/x64/1.0.1794/discord_erlpack/1/full.distro", "version": 1 }, "discord_game_utils": { - "hash": "sha256-3H3KVkC/t6UdxTQEUtKg9rfk1xKaWf0MDerUm5yO3/Y=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/linux/x64/1.0.1766/discord_game_utils/1/full.distro", + "hash": "sha256-JPacuW/LhaFGftu3tR3C4AKU+6nnJuc4N99CnvJskf8=", + "url": "https://canary.dl2.discordapp.net/distro/app/canary/linux/x64/1.0.1794/discord_game_utils/1/full.distro", "version": 1 }, "discord_krisp": { - "hash": "sha256-w8XATCZyCv1FeoRBweo7+wL9NAX2jD8JNKiF1ED7T1w=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/linux/x64/1.0.1766/discord_krisp/1/full.distro", + "hash": "sha256-xYryuPZXFp9nvDQ4l8qFANh16CcO+ZNCEUc0/UXrBzE=", + "url": "https://canary.dl2.discordapp.net/distro/app/canary/linux/x64/1.0.1794/discord_krisp/1/full.distro", "version": 1 }, "discord_modules": { - "hash": "sha256-Qd4gefF0GDNmZpwtIuuOdGRxRn7b+l88N7lbsRebe9U=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/linux/x64/1.0.1766/discord_modules/1/full.distro", + "hash": "sha256-KCAWR5Eoib/RkO3MVn8oHh6WBTfTMA2fMLMjMCrRiZs=", + "url": "https://canary.dl2.discordapp.net/distro/app/canary/linux/x64/1.0.1794/discord_modules/1/full.distro", "version": 1 }, "discord_rpc": { - "hash": "sha256-XxkRTULSxx7o8PNwCtz4FeZ9vowa8EHr7DNryvG/vMk=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/linux/x64/1.0.1766/discord_rpc/1/full.distro", + "hash": "sha256-uYcDMwefWLdUzCjpN6b0h5pN95UKZs6gwgwA3uiPmb4=", + "url": "https://canary.dl2.discordapp.net/distro/app/canary/linux/x64/1.0.1794/discord_rpc/1/full.distro", "version": 1 }, "discord_spellcheck": { - "hash": "sha256-mFEZg/Z33mdj4dIwJNfj7pCj/xcLoCTch/t2pssl45c=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/linux/x64/1.0.1766/discord_spellcheck/1/full.distro", + "hash": "sha256-xSOog8VBcJBhbfzWXUlMMHWYfQ+Mkx0O5/IGu72zTvY=", + "url": "https://canary.dl2.discordapp.net/distro/app/canary/linux/x64/1.0.1794/discord_spellcheck/1/full.distro", "version": 1 }, "discord_sysimg": { - "hash": "sha256-O5XrO1uL6zNHbIh6XUXQP3e/ZcAd46Z4s26+ihzWfBU=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/linux/x64/1.0.1766/discord_sysimg/1/full.distro", + "hash": "sha256-UTNNk4RY6fk9GnTxNyhBI3XLmA38oSsdKVpLl3VqtjU=", + "url": "https://canary.dl2.discordapp.net/distro/app/canary/linux/x64/1.0.1794/discord_sysimg/1/full.distro", "version": 1 }, "discord_utils": { - "hash": "sha256-aN53SHC3x1YKzd3pmmQX7lWu6iVRC7kN9BxViPSSNV8=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/linux/x64/1.0.1766/discord_utils/1/full.distro", + "hash": "sha256-CbAcjtjZdENZcjcrEOLP/SOdi9Yay4/J4re0UguvO40=", + "url": "https://canary.dl2.discordapp.net/distro/app/canary/linux/x64/1.0.1794/discord_utils/1/full.distro", "version": 1 }, "discord_voice": { - "hash": "sha256-pbzNmysNg7tWzbpQSqGr8OBWdaGSR8/pi5A15y2oZno=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/linux/x64/1.0.1766/discord_voice/1/full.distro", + "hash": "sha256-Ev6sh9hjfjdZ+5ZmXKW4QXFdGwQAozXP4/F6P6BYISI=", + "url": "https://canary.dl2.discordapp.net/distro/app/canary/linux/x64/1.0.1794/discord_voice/1/full.distro", "version": 1 }, "discord_zstd": { - "hash": "sha256-E+ai701mLhnEdSAO+9dR0KEWZuVEJvCzmrRjPB0ST0I=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/linux/x64/1.0.1766/discord_zstd/1/full.distro", + "hash": "sha256-1Sfz6Wymr9T3mIwdRb4e6KYNl/iI2eDoiK+DDsGUty8=", + "url": "https://canary.dl2.discordapp.net/distro/app/canary/linux/x64/1.0.1794/discord_zstd/1/full.distro", "version": 1 } }, - "version": "1.0.1766" + "version": "1.0.1794" }, "linux-development": { "distro": { @@ -161,253 +156,253 @@ }, "linux-ptb": { "distro": { - "hash": "sha256-9eq0gqGesGYXCLsztSt9mf0laH/OuLhjCuOKRL8Xnp4=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/linux/x64/1.0.211/full.distro" + "hash": "sha256-4LjSOiwKk82VvmxYEKGJnp0yz5pNbdJ3mDOgnK3+GCs=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/linux/x64/1.0.212/full.distro" }, "kind": "distro", "modules": { "discord_arborium": { - "hash": "sha256-w4mPCev2fCDBLeozW24Aps/m+5kWAyVtYD55868lQzA=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/linux/x64/1.0.211/discord_arborium/1/full.distro", + "hash": "sha256-1Oh0s1LoS/IqGUfP5ZLYdVGPXZVzK/hRNRa6qelYqFc=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/linux/x64/1.0.212/discord_arborium/1/full.distro", "version": 1 }, "discord_cloudsync": { - "hash": "sha256-BXIIi69tGkND16aykVut6cE8B/WiVe6/9mpPBBxVZ1s=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/linux/x64/1.0.211/discord_cloudsync/1/full.distro", + "hash": "sha256-Tv21h/Zx3cCz3JiCuM/NN8VwZti+KGTqscmDZRsGC2Y=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/linux/x64/1.0.212/discord_cloudsync/1/full.distro", "version": 1 }, "discord_desktop_core": { - "hash": "sha256-gB3j55jhG/qh13itZ79Oiio2Ys7i61k5d4NIj9+a4d8=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/linux/x64/1.0.211/discord_desktop_core/1/full.distro", + "hash": "sha256-bfZVCO3uEWlHJa5IhENPpArW1j75wICaRe7BS2FyDN0=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/linux/x64/1.0.212/discord_desktop_core/1/full.distro", "version": 1 }, "discord_dispatch": { - "hash": "sha256-OcokUI/f0Ra6JBC7xJ3+Icv0yyZlD7g1As7c718f3AY=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/linux/x64/1.0.211/discord_dispatch/1/full.distro", + "hash": "sha256-C/o9W9HQM27j7Yd9EL/gPqZ4Qwh1PnWeh1hfdwWwnQE=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/linux/x64/1.0.212/discord_dispatch/1/full.distro", "version": 1 }, "discord_erlpack": { - "hash": "sha256-z9pwZyP59qIDZeojVaNgJohsu4SNstQliXvuIJjTWU0=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/linux/x64/1.0.211/discord_erlpack/1/full.distro", + "hash": "sha256-tGXulf3fiJh/rYWAVkc3X0BEfYmJ7B+bpco1jdGshiM=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/linux/x64/1.0.212/discord_erlpack/1/full.distro", "version": 1 }, "discord_game_utils": { - "hash": "sha256-pBvHJOJ8LqV1yDY/AKhxl9+5CBuGDdZxNECQ+mzPPcA=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/linux/x64/1.0.211/discord_game_utils/1/full.distro", + "hash": "sha256-HteWjRWb7cGjTVx4KR9s6usA742cp09NbTeHF91tCys=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/linux/x64/1.0.212/discord_game_utils/1/full.distro", "version": 1 }, "discord_krisp": { - "hash": "sha256-302w/9D93ESPY3ij6vbOeig32nikoWDD8t8YoCPGWEc=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/linux/x64/1.0.211/discord_krisp/1/full.distro", + "hash": "sha256-ntr0p+Mjam+JDwFWTgrFhbmesXPg0CzkajBM/D4pZPw=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/linux/x64/1.0.212/discord_krisp/1/full.distro", "version": 1 }, "discord_modules": { - "hash": "sha256-zDsZa17X3GIIGeNG6JBuTTyXqtqD2NiZRrmcL67oSj4=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/linux/x64/1.0.211/discord_modules/1/full.distro", + "hash": "sha256-YC00gpi63MLWWQG52neNOcrE0CLmLPo1f2qtqOQyCNI=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/linux/x64/1.0.212/discord_modules/1/full.distro", "version": 1 }, "discord_rpc": { - "hash": "sha256-ndZwouBJpQHNDIWfuC/xvM2+fIIwrUutLAQwj+fNyXY=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/linux/x64/1.0.211/discord_rpc/1/full.distro", + "hash": "sha256-+e6mv8np0+rcHbql4cBW2gymQPAceLC+1EX/fHOWf0k=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/linux/x64/1.0.212/discord_rpc/1/full.distro", "version": 1 }, "discord_spellcheck": { - "hash": "sha256-se40Ubw07Fwg7VBIkvgfIzBIbpdWyOEAHHk+SrAk9Dk=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/linux/x64/1.0.211/discord_spellcheck/1/full.distro", + "hash": "sha256-KxWS1m9gD5+hZHqbLmjZV8nmvRJflVITugyvj14aZjM=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/linux/x64/1.0.212/discord_spellcheck/1/full.distro", "version": 1 }, "discord_sysimg": { - "hash": "sha256-kbJsxsqrjoVajWCUDAywNQlEVHQ6Iyl6FjltvGenAPg=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/linux/x64/1.0.211/discord_sysimg/1/full.distro", + "hash": "sha256-g8mckNZNTCZDD8m1WnWx3vtsqZ1B/Ou0qGMf5F0bgX8=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/linux/x64/1.0.212/discord_sysimg/1/full.distro", "version": 1 }, "discord_utils": { - "hash": "sha256-l32yxA7h01KsBvc5wambNoyxiACacprLdJXnM5c0bxU=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/linux/x64/1.0.211/discord_utils/1/full.distro", + "hash": "sha256-/OKjhFGVQ/U3O/YvNkc+xrPNJGBAkmctgUjLiK2cOcY=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/linux/x64/1.0.212/discord_utils/1/full.distro", "version": 1 }, "discord_voice": { - "hash": "sha256-vuX/J5+Br2lC+rsEnAWlrYivkAF7HKb3FG+xBO3HxOI=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/linux/x64/1.0.211/discord_voice/1/full.distro", + "hash": "sha256-EgEXB1pXz5RTXtUPNwkDfuSP001luOYqFIH/TiIWGB4=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/linux/x64/1.0.212/discord_voice/1/full.distro", "version": 1 }, "discord_zstd": { - "hash": "sha256-ZZ1cKzbxPKyu7Ku+T6iQ9Qrs9tFA++Yebpu02v9IkMg=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/linux/x64/1.0.211/discord_zstd/1/full.distro", + "hash": "sha256-ivgN/iLzXIXdV0KTzZMakkgWj7mDvlAZ06RjLWvB1qQ=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/linux/x64/1.0.212/discord_zstd/1/full.distro", "version": 1 } }, - "version": "1.0.211" + "version": "1.0.212" }, "linux-stable": { "distro": { - "hash": "sha256-8gWwie6ns9oLR+YcN5Yo0Ml9cozrM6Ybg7IXg3hEir0=", - "url": "https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/1.0.155/full.distro" + "hash": "sha256-vvQ7e7rsk85mPCbNeb00d3OCUWUzUkFNYVctPYvBGRE=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/1.0.156/full.distro" }, "kind": "distro", "modules": { "discord_arborium": { - "hash": "sha256-W0u/dID213JCOtMxvINaGPRXRMfOkbqWxw2LYJM03N4=", - "url": "https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/1.0.155/discord_arborium/1/full.distro", + "hash": "sha256-JUA2EDfYcRaVnU4zzhOKZ8Q0X8YafPhKJcUd0J+MztU=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/1.0.156/discord_arborium/1/full.distro", "version": 1 }, "discord_cloudsync": { - "hash": "sha256-kCFreXY3IBuMZ7FtqVSv4IAMzQYBNV4qplQZx9PlQlU=", - "url": "https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/1.0.155/discord_cloudsync/1/full.distro", + "hash": "sha256-J+lGNUKZJ+DtbQ8pXLUuw07T6MH7fyzblKr6fQ9bb2s=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/1.0.156/discord_cloudsync/1/full.distro", "version": 1 }, "discord_desktop_core": { - "hash": "sha256-s7WzMCq0J6XacDErIvMfmIlt9McK00dNshz+w7VJ0wo=", - "url": "https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/1.0.155/discord_desktop_core/1/full.distro", + "hash": "sha256-21p4kuV4dJUvxNVWgYsVIxkyYohak7NxgscIYdlD0a0=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/1.0.156/discord_desktop_core/1/full.distro", "version": 1 }, "discord_dispatch": { - "hash": "sha256-PHjwOQ71MsbPTDSGGljPd9m4D471ImQp3a8obW7lod8=", - "url": "https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/1.0.155/discord_dispatch/1/full.distro", + "hash": "sha256-P5FQFCzWsgrDNu7OoyI1mjStfBP5nM6C45fu42MoYv4=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/1.0.156/discord_dispatch/1/full.distro", "version": 1 }, "discord_erlpack": { - "hash": "sha256-vtd9yB9mK6twH74dgC7NuT2rVCr5ucjSv+11yCOF0Gs=", - "url": "https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/1.0.155/discord_erlpack/1/full.distro", + "hash": "sha256-nfgYCt0rHjlZUedu40sRThxp1TEdfB+9TXz31RFZ60k=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/1.0.156/discord_erlpack/1/full.distro", "version": 1 }, "discord_game_utils": { - "hash": "sha256-H3FM1Ml97v9MkGVCgYUW+mz2JOd9CZP/Dgzvu2rGOuE=", - "url": "https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/1.0.155/discord_game_utils/1/full.distro", + "hash": "sha256-gAB1QY8QjHl6xogqQr1uxgYuuywQV+VcqMB5cAC0vNc=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/1.0.156/discord_game_utils/1/full.distro", "version": 1 }, "discord_krisp": { - "hash": "sha256-lCOK9yjqa1yLcSOdhILgW/kr1ZJjqxAdbo93/FnyNnk=", - "url": "https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/1.0.155/discord_krisp/1/full.distro", + "hash": "sha256-bmMDt2FshcCZA3eDZ+uVmxzCqgkTI81Zc6Wrrw3ZK/0=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/1.0.156/discord_krisp/1/full.distro", "version": 1 }, "discord_modules": { - "hash": "sha256-OC2VIUOXaiGcoqV8NOzW55z3DpRpdqfTBdni3wNyvlA=", - "url": "https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/1.0.155/discord_modules/1/full.distro", + "hash": "sha256-YVhJEFMOo8AmGFpET5sdTdLiRLO407t5Z6KCixKEjGk=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/1.0.156/discord_modules/1/full.distro", "version": 1 }, "discord_rpc": { - "hash": "sha256-GS/nOO/ec43OgYN744Gao4IHYWBPpznA1stk/BmPEqQ=", - "url": "https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/1.0.155/discord_rpc/1/full.distro", + "hash": "sha256-Av9sjzLybZV9OD5WEteV0sHRDzNp8LiBUOb1V63oZv8=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/1.0.156/discord_rpc/1/full.distro", "version": 1 }, "discord_spellcheck": { - "hash": "sha256-oBGlUOrQ2/cW5EbTcTe31wvfm5V14gyBoStucMXDJqU=", - "url": "https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/1.0.155/discord_spellcheck/1/full.distro", - "version": 1 - }, - "discord_utils": { - "hash": "sha256-BOb01yg0+O3/k5CX0TKVaz8598HqcQp09R4vA60e87s=", - "url": "https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/1.0.155/discord_utils/1/full.distro", - "version": 1 - }, - "discord_voice": { - "hash": "sha256-ib2a5g6Pr6YR+RUWYm4u929yTgWUMtMaETwMNaEal7M=", - "url": "https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/1.0.155/discord_voice/1/full.distro", - "version": 1 - }, - "discord_zstd": { - "hash": "sha256-QNYSCSoJJVKeV3w+AS6AbaVcTnIs6gMX1nek0tn/eoA=", - "url": "https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/1.0.155/discord_zstd/1/full.distro", - "version": 1 - } - }, - "version": "1.0.155" - }, - "osx-canary": { - "distro": { - "hash": "sha256-g2G2hLwYUiQBDHUiWKGH7BK153qnRZvySwzktOio8SI=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1294/full.distro" - }, - "kind": "distro", - "modules": { - "discord_arborium": { - "hash": "sha256-KNEcVAc7z4n9yPSi3LT+sZe3iq4J7QtH66OAJ473nqM=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1294/discord_arborium/1/full.distro", - "version": 1 - }, - "discord_cloudsync": { - "hash": "sha256-0iKZk1fyyN5te8AUaC3H1gsOr/BGxhMwionpCgkna4A=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1294/discord_cloudsync/1/full.distro", - "version": 1 - }, - "discord_desktop_core": { - "hash": "sha256-K4O77jQCWBh2nYjFhwlJCHzxmmuadouv3pqLN0q8c9s=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1294/discord_desktop_core/1/full.distro", - "version": 1 - }, - "discord_dispatch": { - "hash": "sha256-6T4HWFZpkGQcpwfVWMaw4sTpibG4wo1HLk8ZcmtBfvM=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1294/discord_dispatch/1/full.distro", - "version": 1 - }, - "discord_erlpack": { - "hash": "sha256-MNX10Hk1nzEq000t15Msg8hzmGCkby7z/I6b9LuR5Sk=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1294/discord_erlpack/1/full.distro", - "version": 1 - }, - "discord_game_utils": { - "hash": "sha256-6znm3uE1Fl7ItuT/1OVRxP21kSYaDXkTIl1SNadWSSQ=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1294/discord_game_utils/1/full.distro", - "version": 1 - }, - "discord_intents": { - "hash": "sha256-titG9Z0eXKm2QnWm1xdPljUF7s3VBwM3kZN0Mwc730E=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1294/discord_intents/1/full.distro", - "version": 1 - }, - "discord_krisp": { - "hash": "sha256-9v2+nnjkQeI7RLt2+Q05zfGaKvchoCxRFciJFT5VrDc=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1294/discord_krisp/1/full.distro", - "version": 1 - }, - "discord_modules": { - "hash": "sha256-LAc5uFvYdg5ruzmd2Msh3c7eegChFoIBXj8X7JYJVqs=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1294/discord_modules/1/full.distro", - "version": 1 - }, - "discord_notifications": { - "hash": "sha256-mxQb3Em0wDma8EXTN4cULjvW31JwVxDzQ3ne9FcKbC4=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1294/discord_notifications/1/full.distro", - "version": 1 - }, - "discord_rpc": { - "hash": "sha256-DXSY6qhtxW0S3rE9w5/KO85bsU7JP2ldx5tOoTwoptM=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1294/discord_rpc/1/full.distro", - "version": 1 - }, - "discord_spellcheck": { - "hash": "sha256-X5BitbmM9HnEex2DsRN3t56tLBRtkyeeY7rZ9QgoNdU=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1294/discord_spellcheck/1/full.distro", + "hash": "sha256-O0p451X8HYslCd9QWJ/SbjQ+tIs3otCfxzBPmZjM6LI=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/1.0.156/discord_spellcheck/1/full.distro", "version": 1 }, "discord_sysimg": { - "hash": "sha256-SHpivOq+XZeEiU9EAfD2YMeIo10DvWDmzU0C0cm3wuQ=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1294/discord_sysimg/1/full.distro", + "hash": "sha256-9HxsiEhAPIpTRPoYYvsyakWJT6GaT+3/L1dvtxNZNhA=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/1.0.156/discord_sysimg/1/full.distro", "version": 1 }, "discord_utils": { - "hash": "sha256-MVLPSCP3AxDs3DNFuwyYjlZHyA4cVErANFCMTzorGWk=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1294/discord_utils/3/full.distro", - "version": 3 + "hash": "sha256-qsB1dfte6qoD+nT0rZ+mJnn6L0p6OSeGVMWQobc9WM4=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/1.0.156/discord_utils/1/full.distro", + "version": 1 }, "discord_voice": { - "hash": "sha256-mfoo7ZBsU/fRkHGxKk0j/i0qj2PnBnzdTSt8pI0t53s=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1294/discord_voice/2/full.distro", - "version": 2 - }, - "discord_webauthn": { - "hash": "sha256-kCeElNUwLB1yFrHTqP6W+S6/F5npRiYo5uH6M31uNxo=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1294/discord_webauthn/1/full.distro", + "hash": "sha256-icxv/ISGtR5d7ZdQaFzrspulK8KRYZfMzxzatX7/xhI=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/1.0.156/discord_voice/1/full.distro", "version": 1 }, "discord_zstd": { - "hash": "sha256-15edfIf+s9zPaYWYw7SPsUGXXFJK9LMGK6LzaDvSiyE=", - "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1294/discord_zstd/1/full.distro", + "hash": "sha256-tndzE1U8DA+K4XGbX9jII7zrSiybG1qAqSzCwypSYYo=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/linux/x64/1.0.156/discord_zstd/1/full.distro", "version": 1 } }, - "version": "0.0.1294" + "version": "1.0.156" + }, + "osx-canary": { + "distro": { + "hash": "sha256-SjRGJwvd+IOkCqrG6akvvlFFpDV4gQozf4mPinKrZQE=", + "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1306/full.distro" + }, + "kind": "distro", + "modules": { + "discord_cloudsync": { + "hash": "sha256-uynrrQxSvQjnGsS2V+CpiRfBCpNzAVgo94nySxMWrGw=", + "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1306/discord_cloudsync/1/full.distro", + "version": 1 + }, + "discord_desktop_core": { + "hash": "sha256-7tAXBdi+OXZaXl8+camk2IHEwzqrUpHjcc8QYI3oals=", + "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1306/discord_desktop_core/1/full.distro", + "version": 1 + }, + "discord_dispatch": { + "hash": "sha256-Kd3fZYacc9H2MfOfHIgdDu56HCeRYF60dG6234Uin2c=", + "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1306/discord_dispatch/1/full.distro", + "version": 1 + }, + "discord_erlpack": { + "hash": "sha256-/JAAcJ/bDJaUllVn+0aAErWysh//dSPrT64uGe5THVU=", + "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1306/discord_erlpack/1/full.distro", + "version": 1 + }, + "discord_game_utils": { + "hash": "sha256-4x+ZNH831aCeuNVK2RLiAfaYolFcPSXFcnk/Y/19/Nc=", + "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1306/discord_game_utils/1/full.distro", + "version": 1 + }, + "discord_intents": { + "hash": "sha256-1RzkNxAlvdLr7vpW2sIj+dE/6gkauXbgmyU6ZfROxvk=", + "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1306/discord_intents/1/full.distro", + "version": 1 + }, + "discord_krisp": { + "hash": "sha256-WY5x578AvlwSUC/tV0j+SZItOCiHqzNZDfV4TfK52XM=", + "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1306/discord_krisp/1/full.distro", + "version": 1 + }, + "discord_modules": { + "hash": "sha256-tOTaUzDS5EEJpxCT+2eMaELyqrpBpyg4VVAR2qoKpqs=", + "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1306/discord_modules/1/full.distro", + "version": 1 + }, + "discord_notifications": { + "hash": "sha256-wgywWGbwb4ZOxAbvP1zwGmXYY7YcWVZZ/3oHPTi6+ns=", + "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1306/discord_notifications/1/full.distro", + "version": 1 + }, + "discord_rpc": { + "hash": "sha256-76+PQX58ftimpJWWaasvVUz5csbR+mKL0DTcUYAYuHs=", + "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1306/discord_rpc/1/full.distro", + "version": 1 + }, + "discord_spellcheck": { + "hash": "sha256-An1SBmKEPI8pRip6g/YZW6dGsLpx0TIvS+QCkI1YnWs=", + "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1306/discord_spellcheck/1/full.distro", + "version": 1 + }, + "discord_sysimg": { + "hash": "sha256-9MJv02Fk+ega0kbbLL7/s420Mx149sJFWvkkU66yJuY=", + "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1306/discord_sysimg/1/full.distro", + "version": 1 + }, + "discord_utils": { + "hash": "sha256-ptioApBU8h3ryIan7db5A77Tf87MTqRRNSVZhiUeUcA=", + "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1306/discord_utils/1/full.distro", + "version": 1 + }, + "discord_voice": { + "hash": "sha256-pVs09tpg7jTKfm54N1uaRf731Du9vpB7q8UFUHorpWU=", + "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1306/discord_voice/1/full.distro", + "version": 1 + }, + "discord_webauthn": { + "hash": "sha256-op6K8vlmdjXxsZ2+23CSuZGmdvS7tb7gCq5eRrD1r6g=", + "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1306/discord_webauthn/1/full.distro", + "version": 1 + }, + "discord_zstd": { + "hash": "sha256-bibBKtu5xxBdtk5lfJAMtrjVMz/YMjzFTjHu2xoTNSc=", + "url": "https://canary.dl2.discordapp.net/distro/app/canary/osx/universal/0.0.1306/discord_zstd/1/full.distro", + "version": 1 + } + }, + "version": "0.0.1306" }, "osx-development": { "distro": { @@ -506,187 +501,192 @@ }, "osx-ptb": { "distro": { - "hash": "sha256-mTArbvIvLjOSGpb35GO17K8lnCqAHd6fDdxpzwFKmg4=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.256/full.distro" + "hash": "sha256-0itWlg4uO9n251oeACGHfgId6sV9WwWXib+xTpLlKdg=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.257/full.distro" }, "kind": "distro", "modules": { "discord_arborium": { - "hash": "sha256-eySEVa1AmxNMG8P1cqxLFftrQjyzWrN8QInF8rUh53Q=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.256/discord_arborium/1/full.distro", + "hash": "sha256-nxM1iYpiUhF5out+DCCJGaiPr/WuQDYXxHHnOVG542U=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.257/discord_arborium/1/full.distro", "version": 1 }, "discord_cloudsync": { - "hash": "sha256-7/60p+KD/WIxA0ErfHUrSPXGxVTmyNiC9Kcu6WUAPsQ=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.256/discord_cloudsync/1/full.distro", + "hash": "sha256-+XUuoUmKHd0paaXCm64M/6GbI6oox3auQrHo2QB7IqY=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.257/discord_cloudsync/1/full.distro", "version": 1 }, "discord_desktop_core": { - "hash": "sha256-xtxh0mvHKtAtohJptt/89DhEVpC1UbWloVnhvK3kmO4=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.256/discord_desktop_core/1/full.distro", + "hash": "sha256-+n+arWUqZyDX9pTRYd90uuo//JXqMo6L3mIymSkrUTY=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.257/discord_desktop_core/1/full.distro", "version": 1 }, "discord_dispatch": { - "hash": "sha256-wi67HEYdj+bL+Zs+PrNkaMSfzjyGR0eMi0smyyvJoig=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.256/discord_dispatch/1/full.distro", + "hash": "sha256-7nuF4fhgJx0B7s73dnGddPr1gLpnaVksRYpKQmqf5Qk=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.257/discord_dispatch/1/full.distro", "version": 1 }, "discord_erlpack": { - "hash": "sha256-rhf2TnRJaz3uqFq2tu8JCIbUFdBHJFQWupn2BvreeiM=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.256/discord_erlpack/1/full.distro", + "hash": "sha256-YP5XoJ4gdPJwRVP9Poj0G+Rv+ZrWE1O8TQ211LfD6tI=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.257/discord_erlpack/1/full.distro", "version": 1 }, "discord_game_utils": { - "hash": "sha256-3GlzC6GHnC+hb6YMWNcA9ly7g8vKMuMf48Xv04tpMMw=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.256/discord_game_utils/1/full.distro", + "hash": "sha256-QOggWiTw6TK9mj7mnn5EvoI6Ai/QuF6R6c16vJQQwMA=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.257/discord_game_utils/1/full.distro", "version": 1 }, "discord_intents": { - "hash": "sha256-6cDb4uNVlpVTiqww03+74raqkOAbWgI0jS5xG0lgO0g=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.256/discord_intents/1/full.distro", + "hash": "sha256-n+LHKnwc/eDih0rCT11BCMNMG0Nb9LluIxkZ/qdLxYs=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.257/discord_intents/1/full.distro", "version": 1 }, "discord_krisp": { - "hash": "sha256-jx0nK45QkHhkl9DMB81qwJw6GceFu8KPBcQVMvJKRXI=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.256/discord_krisp/1/full.distro", + "hash": "sha256-hnPCYcyTRyXrq/HaQn7HoFlKF13VSvSwTRn3lrzYAxw=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.257/discord_krisp/1/full.distro", "version": 1 }, "discord_modules": { - "hash": "sha256-kELcckM97k084WfqVyFaJb9Nmdp1UOsXvL8vfeyzDck=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.256/discord_modules/1/full.distro", + "hash": "sha256-l5X0AeddEKdXzc8z3SkiIEeu0aF9pz7SlRN2+jgvJsQ=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.257/discord_modules/1/full.distro", "version": 1 }, "discord_notifications": { - "hash": "sha256-lVlDGN+qYKOPKUgHZ20b5b36T0GNj2KyHzRQZclJ6w8=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.256/discord_notifications/1/full.distro", + "hash": "sha256-1Hl6kvliMkmATrqPLUazkTkVhjXxuYufjV/wbg8WMsM=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.257/discord_notifications/1/full.distro", "version": 1 }, "discord_rpc": { - "hash": "sha256-gwqGxzJPCBIoYTftUIUiTi7D1qtsdxDJgCIqM8MRifo=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.256/discord_rpc/1/full.distro", + "hash": "sha256-pZtk1ilJRl6/UnKV70ON4X1gEewdwUHN8l0VjiGb1QU=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.257/discord_rpc/1/full.distro", "version": 1 }, "discord_spellcheck": { - "hash": "sha256-SeglC/2Wp8DdSt7EAdxdEB4kfx7pAZdelv7OQYb0fz4=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.256/discord_spellcheck/1/full.distro", + "hash": "sha256-wPa9fIcrPk1yln0/dbhdJzJO93Y7G9x+L61mpGmu9Uk=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.257/discord_spellcheck/1/full.distro", "version": 1 }, "discord_sysimg": { - "hash": "sha256-PDaNTbEZxg4W8HteDJ1QSgUcpizvnRRLGkYp3YNiSkY=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.256/discord_sysimg/1/full.distro", + "hash": "sha256-at2pxdYqY4h7I0vmmpJN+nuSi3b85qZvngfYVwjD7q0=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.257/discord_sysimg/1/full.distro", "version": 1 }, "discord_utils": { - "hash": "sha256-zGNUOs+uWSAgAht56Oe6y5xgEhtaSKOLwVmNC0L6t6Y=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.256/discord_utils/1/full.distro", + "hash": "sha256-83pMGx2wlw5gCqcZPKwqUqztF6EnJzHSNExi/LaUsn0=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.257/discord_utils/1/full.distro", "version": 1 }, "discord_voice": { - "hash": "sha256-pF3ki+YCVyrD/dL9aPCgylc7gs21MppkZOHROEiDm+w=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.256/discord_voice/1/full.distro", + "hash": "sha256-bR4oAeMkBEi4miW27/I6YD7wjcQWOaLZJMsEcA5GttM=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.257/discord_voice/1/full.distro", "version": 1 }, "discord_webauthn": { - "hash": "sha256-z+rVhzu+CL8nu9FfyQESkDbJBWVGHz03j/EGBc1f1vI=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.256/discord_webauthn/1/full.distro", + "hash": "sha256-JAhcJogkRO6w5lgDau3lQs7R9yvuw2J3e5yNeZkeOCc=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.257/discord_webauthn/1/full.distro", "version": 1 }, "discord_zstd": { - "hash": "sha256-5cNp0u8jlQYI9LBIbi3pmL7jm43tgD3EVq3bamPZSxE=", - "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.256/discord_zstd/1/full.distro", + "hash": "sha256-YuztgnEkhGX5bUhqRTt4CNj3Cr/TKWFs9GFrnLHccXs=", + "url": "https://ptb.dl2.discordapp.net/distro/app/ptb/osx/universal/0.0.257/discord_zstd/1/full.distro", "version": 1 } }, - "version": "0.0.256" + "version": "0.0.257" }, "osx-stable": { "distro": { - "hash": "sha256-KfWALYNAd/FX+LQRMIyCt69MY6J5jRS7gFg4jCl4fSY=", - "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.409/full.distro" + "hash": "sha256-J2gIsqC0Kzn+G9FaLqkO5xCr4g5VhIyydPHRKt13eMk=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.410/full.distro" }, "kind": "distro", "modules": { "discord_arborium": { - "hash": "sha256-53S9PggFNCKdfQ0sYl6Mn5R5Kngg2/T6eElq9C+DN08=", - "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.409/discord_arborium/1/full.distro", + "hash": "sha256-1qA8sYKihOt3wymjEVgRTPhX2jSVtthc8KX4w54t+qE=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.410/discord_arborium/1/full.distro", "version": 1 }, "discord_cloudsync": { - "hash": "sha256-/ySgAAJ0n2TWB/wbvB7OihFxRrC7NyTjQ1H4TqvWZ84=", - "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.409/discord_cloudsync/1/full.distro", + "hash": "sha256-VH8rFK6asP+2lGPiC4NbNY4t20dx7qwGmlp7Mj8iVTE=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.410/discord_cloudsync/1/full.distro", "version": 1 }, "discord_desktop_core": { - "hash": "sha256-szNLjknsUqkkxLPpyJjEfxT46AUjM4g+DTMoPgrxBm0=", - "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.409/discord_desktop_core/1/full.distro", + "hash": "sha256-ZJKB5FeNJ7Z9+tuSxK9zcFG4826VFUMTrT6XHFi36YM=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.410/discord_desktop_core/1/full.distro", "version": 1 }, "discord_dispatch": { - "hash": "sha256-UoWIZ1Uc0Q6YXSTzulJSWNjgdRyTiX54R05UTh8fTiE=", - "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.409/discord_dispatch/1/full.distro", + "hash": "sha256-D7R3j/sZpwel0WBwshGHqM/HMIWwA1vW2gxUCDpUZKU=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.410/discord_dispatch/1/full.distro", "version": 1 }, "discord_erlpack": { - "hash": "sha256-xlWB+o/sjHFLZVMFke9RCQt65lBVn/pUT8jNUUkfSyI=", - "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.409/discord_erlpack/1/full.distro", + "hash": "sha256-kSKDbwiqhXVcGWtOqW184yO6uKeACyCAxgEKTOoqGOI=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.410/discord_erlpack/1/full.distro", "version": 1 }, "discord_game_utils": { - "hash": "sha256-Hqs0td1l6gWvdNcn0WA/DfADlZq+OT0+HlgUXiyvwEk=", - "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.409/discord_game_utils/1/full.distro", + "hash": "sha256-jz65aXMzEct+HT1Shs1ziyaksbFIWyAY8YjWZTvt6jI=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.410/discord_game_utils/1/full.distro", "version": 1 }, "discord_intents": { - "hash": "sha256-jKNBNIlXutv2ex6MuO8kmwkx7kcQ2uaIt0f/ogw4Vws=", - "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.409/discord_intents/1/full.distro", + "hash": "sha256-nU9TvJqrH6+ROZsF3WD+L/ZvuIqIuGbfejQe0C0XypY=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.410/discord_intents/1/full.distro", "version": 1 }, "discord_krisp": { - "hash": "sha256-7OizZzIYAlP4CmZ1kcpFc52ijT6abHYJ4KvQAhaG/J0=", - "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.409/discord_krisp/1/full.distro", + "hash": "sha256-Jm1/RTUsXrvwntxWZKblkRzlwsVGVegzo9uqyjBH98Q=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.410/discord_krisp/1/full.distro", "version": 1 }, "discord_modules": { - "hash": "sha256-l3obGjd4nK7DQtwoml6PvzmQnYaRu36xAEUjd0TKmIs=", - "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.409/discord_modules/1/full.distro", + "hash": "sha256-7Nsbay4MP424IAtpQCcgEmSeSxVphOFUJuY/Dytb1LY=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.410/discord_modules/1/full.distro", "version": 1 }, "discord_notifications": { - "hash": "sha256-8XfxczmmMq5w4HRLQnCjxjFV0fQgDwaEkcezXGd7gNU=", - "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.409/discord_notifications/1/full.distro", + "hash": "sha256-4m4DjudjLxua1KUwjKN+DouU8JYxsa7wvTvbCTEkzKU=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.410/discord_notifications/1/full.distro", "version": 1 }, "discord_rpc": { - "hash": "sha256-1n+gO1c4SZrV2jOD2SVMCQYnHU8e5ErrB0eJEv8hvus=", - "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.409/discord_rpc/1/full.distro", + "hash": "sha256-kv8Qh9F3PmCru7DKmvsJiq+4/LoYAOtpiE9SCpPBMbc=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.410/discord_rpc/1/full.distro", "version": 1 }, "discord_spellcheck": { - "hash": "sha256-QPZOJTNAU5rShPeV4SU2P9eBmDEbLZHEwThyXdRPsLg=", - "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.409/discord_spellcheck/1/full.distro", + "hash": "sha256-dzieOT9NurZjWKaetEY5Z1DWXe/Axq7eLtPNyT3ATbk=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.410/discord_spellcheck/1/full.distro", + "version": 1 + }, + "discord_sysimg": { + "hash": "sha256-ruKew+1lZZO9FpvVkJp2U/X4/l5EaTAjuQqZZP+u2wU=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.410/discord_sysimg/1/full.distro", "version": 1 }, "discord_utils": { - "hash": "sha256-PMv/psANJnI+yhGwsibWDdLGdlUQC8/Rh0h5nmNQfJY=", - "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.409/discord_utils/1/full.distro", + "hash": "sha256-M6Hd5ehiB7j/VLRRzP/UoO5AK7UdCO8iWdlM+5cps3E=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.410/discord_utils/1/full.distro", "version": 1 }, "discord_voice": { - "hash": "sha256-GtnSgoFM1aGBLLLwaB/81iRhuQvuuNuvNehO3k/UP7c=", - "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.409/discord_voice/1/full.distro", + "hash": "sha256-eHBSpQfP+oDcbctuDhPeNkAT75bfk+IVhe212D2jCTI=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.410/discord_voice/1/full.distro", "version": 1 }, "discord_webauthn": { - "hash": "sha256-r0WinKYXuJtY0YWn2GHoFrUID1mwBGRMVVJOMLFGSOs=", - "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.409/discord_webauthn/1/full.distro", + "hash": "sha256-Wlqq/elXIb8m8mZF3P6xWG1mViqrUieBmd83mS9V7Rg=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.410/discord_webauthn/1/full.distro", "version": 1 }, "discord_zstd": { - "hash": "sha256-pBA8Iyv1S7wePlvdNI4lj4MfY2Z8MPtiVaf6EBi8rY0=", - "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.409/discord_zstd/1/full.distro", + "hash": "sha256-+OkUUomOUW6uj1/6cMZmi6dmEkR4HPDkjm1dJ5gSnTY=", + "url": "https://stable.dl2.discordapp.net/distro/app/stable/osx/universal/0.0.410/discord_zstd/1/full.distro", "version": 1 } }, - "version": "0.0.409" + "version": "0.0.410" } } From 5775f79df26751d1d5296da38d2bc1ded5b9bd7a Mon Sep 17 00:00:00 2001 From: Pol Dellaiera Date: Wed, 2 Sep 2026 20:22:10 +0200 Subject: [PATCH 116/140] python3Packages.nomadnet: 1.2.9 -> 1.3.0 --- pkgs/development/python-modules/nomadnet/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/nomadnet/default.nix b/pkgs/development/python-modules/nomadnet/default.nix index 6c3077d7240c..99c550151d97 100644 --- a/pkgs/development/python-modules/nomadnet/default.nix +++ b/pkgs/development/python-modules/nomadnet/default.nix @@ -12,14 +12,14 @@ buildPythonPackage (finalAttrs: { pname = "nomadnet"; - version = "1.2.9"; + version = "1.3.0"; pyproject = true; __structuredAttrs = true; src = fetchPypi { inherit (finalAttrs) version pname; - hash = "sha256-3ySYwQuBf/A/WI3nlywZTEZ7yAszbMLVPVOwkXBY5ls="; + hash = "sha256-WbF57unbpvNabzsBgCWJGEodvtuSGUhpPPpw42GTGx4="; }; build-system = [ setuptools ]; From 2711f4344872fafd5e135cfc2d873185f8df5217 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 18:28:03 +0000 Subject: [PATCH 117/140] zenith: 0.15.0 -> 0.15.1 --- pkgs/by-name/ze/zenith/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ze/zenith/package.nix b/pkgs/by-name/ze/zenith/package.nix index ab062dcb4c43..36d70c8620b5 100644 --- a/pkgs/by-name/ze/zenith/package.nix +++ b/pkgs/by-name/ze/zenith/package.nix @@ -8,13 +8,13 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "zenith"; - version = "0.15.0"; + version = "0.15.1"; src = fetchFromGitHub { owner = "bvaisvil"; repo = "zenith"; rev = finalAttrs.version; - hash = "sha256-NOQ+LqymP1VQ80up6XR7kBYRfWey82wbDbGkf1NsQhc="; + hash = "sha256-kxxavotpejDcWgsP06BmhpCe46tsu8EIPuao9i3RUpg="; }; # remove cargo config so it can find the linker on aarch64-linux @@ -22,7 +22,7 @@ rustPlatform.buildRustPackage (finalAttrs: { rm .cargo/config.toml ''; - cargoHash = "sha256-OABHxLLysx/atZBWCMJCcypugzs5OFtRp2KW3dkp2DE="; + cargoHash = "sha256-9c1c+DnGLyUpmevEn6H+9oD+aclvYAONaMutyQa7Fbc="; nativeBuildInputs = [ rustPlatform.bindgenHook ] ++ lib.optional nvidiaSupport makeWrapper; From 8c2c5136bb9b4d29fc0063b302b44a0dc66d5927 Mon Sep 17 00:00:00 2001 From: Tom Hunze Date: Wed, 2 Sep 2026 20:33:12 +0200 Subject: [PATCH 118/140] react-native-debugger: drop This package has seen no upstream changes since July 2023 [1] and vendors Electron version 25, which has been EOL since December 2023 [2] and ships with the EOL Chromium version 114 [3]. [1] https://github.com/jhen0409/react-native-debugger [2] https://endoflife.date/electron [3] https://www.electronjs.org/blog/electron-25-0#stack-changes --- .../re/react-native-debugger/package.nix | 134 ------------------ pkgs/top-level/aliases.nix | 1 + 2 files changed, 1 insertion(+), 134 deletions(-) delete mode 100644 pkgs/by-name/re/react-native-debugger/package.nix diff --git a/pkgs/by-name/re/react-native-debugger/package.nix b/pkgs/by-name/re/react-native-debugger/package.nix deleted file mode 100644 index 21d016e33798..000000000000 --- a/pkgs/by-name/re/react-native-debugger/package.nix +++ /dev/null @@ -1,134 +0,0 @@ -{ - lib, - stdenv, - fetchurl, - unzip, - cairo, - libxtst, - libxscrnsaver, - libxrender, - libxrandr, - libxi, - libxfixes, - libxext, - libxdamage, - libxcursor, - libxcomposite, - libx11, - libxcb, - gdk-pixbuf, - fontconfig, - pango, - atk, - at-spi2-atk, - at-spi2-core, - gtk3, - glib, - freetype, - dbus, - nss, - nspr, - alsa-lib, - cups, - expat, - udev, - makeDesktopItem, - libdrm, - libxkbcommon, - libgbm, - makeWrapper, -}: - -let - rpath = lib.makeLibraryPath [ - cairo - stdenv.cc.cc - gdk-pixbuf - fontconfig - pango - atk - gtk3 - glib - freetype - dbus - nss - nspr - alsa-lib - cups - expat - udev - at-spi2-atk - at-spi2-core - libdrm - libxkbcommon - libgbm - - libx11 - libxcursor - libxtst - libxcb - libxext - libxi - libxdamage - libxrandr - libxcomposite - libxfixes - libxrender - libxscrnsaver - ]; -in -stdenv.mkDerivation (finalAttrs: { - pname = "react-native-debugger"; - version = "0.14.0"; - src = fetchurl { - url = "https://github.com/jhen0409/react-native-debugger/releases/download/v${finalAttrs.version}/rn-debugger-linux-x64.zip"; - sha256 = "sha256-RioBe0MAR47M84aavFaTJikGsJtcZDak8Tkg3WtX2l0="; - }; - - nativeBuildInputs = [ - makeWrapper - unzip - ]; - buildCommand = '' - shopt -s extglob - mkdir -p $out - unzip $src -d $out - - mkdir $out/{lib,bin,share} - mv $out/{libEGL,libGLESv2,libvk_swiftshader,libffmpeg}.so $out/lib - mv $out/!(lib|share|bin) $out/share - - patchelf \ - --set-interpreter $(cat $NIX_CC/nix-support/dynamic-linker) \ - --set-rpath ${rpath}:$out/lib \ - $out/share/react-native-debugger - - wrapProgram $out/share/react-native-debugger \ - --add-flags --no-sandbox - - ln -s $out/share/react-native-debugger $out/bin/react-native-debugger - - install -Dm644 "${finalAttrs.desktopItem}/share/applications/"* \ - -t $out/share/applications/ - ''; - - desktopItem = makeDesktopItem { - name = "rndebugger"; - exec = "react-native-debugger"; - desktopName = "React Native Debugger"; - genericName = "React Native Debugger"; - categories = [ - "Development" - "Debugger" - ]; - }; - - meta = { - homepage = "https://github.com/jhen0409/react-native-debugger"; - sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ]; - license = lib.licenses.mit; - description = "Standalone app based on official debugger of React Native, and includes React Inspector / Redux DevTools"; - mainProgram = "react-native-debugger"; - maintainers = [ ]; - }; -}) diff --git a/pkgs/top-level/aliases.nix b/pkgs/top-level/aliases.nix index 93259ca12a60..18ce59699193 100644 --- a/pkgs/top-level/aliases.nix +++ b/pkgs/top-level/aliases.nix @@ -2163,6 +2163,7 @@ mapAliases { rapidjson-unstable = throw "'rapidjson-unstable' has been renamed to/replaced by 'rapidjson'"; # Converted to throw 2025-10-27 rar2fs = throw "'rar2fs' has been removed as it is unmaintained, and depends on the unmaintained fuse2 library"; # Added 2026-05-19 raycast-beta = throw "'raycast-beta' has been removed because Raycast 2.0 is out of beta. Use 'raycast' instead."; # Added 2026-08-24 + react-native-debugger = throw "'react-native-debugger' has been removed as it was unmaintained upstream and vendoring an EOL version of Electron"; # Added 2026-09-02 react-static = throw "'react-static' has been removed due to lack of maintenance upstream"; # Added 2025-11-04 recurseIntoAttrs = warnAlias "'recurseIntoAttrs' has been removed from pkgs, use `lib.recurseIntoAttrs` instead" lib.recurseIntoAttrs; # Added 2025-10-30 redict = throw "'redict' has been removed due to lack of nixpkgs maintenance and a slow upstream development pace. Consider using 'valkey'."; # Added 2025-10-16 From 48a72b33f593b7f6ffe08d96d2cd1258c26a52e5 Mon Sep 17 00:00:00 2001 From: bleetube Date: Wed, 2 Sep 2026 12:02:35 -0700 Subject: [PATCH 119/140] lnd: 0.21.2-beta -> 0.21.3-beta --- pkgs/by-name/ln/lnd/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ln/lnd/package.nix b/pkgs/by-name/ln/lnd/package.nix index e975e1d11aff..b86528c0c924 100644 --- a/pkgs/by-name/ln/lnd/package.nix +++ b/pkgs/by-name/ln/lnd/package.nix @@ -23,16 +23,16 @@ buildGoModule (finalAttrs: { pname = "lnd"; - version = "0.21.2-beta"; + version = "0.21.3-beta"; src = fetchFromGitHub { owner = "lightningnetwork"; repo = "lnd"; rev = "v${finalAttrs.version}"; - hash = "sha256-8HSKntW0cLkJi4You8gJgXaUoQoevl2zY+mji3fprJI="; + hash = "sha256-sz0BSf6QnxGQxLw/8fPNsg9/v742JNMCs+lTWa6lPD0="; }; - vendorHash = "sha256-YdrgmzTbxrsW/smmxFBiHQ1jB+cxNgNxPAsrPPS61AU="; + vendorHash = "sha256-/TKQLgVCgBF6DLnaXUJCVvOmOXZ3sJUGbyKQGsBi1dE="; subPackages = [ "cmd/lncli" From 1a10a8ac909c2f3a25f5690f88e0288d20cb9125 Mon Sep 17 00:00:00 2001 From: bleetube Date: Wed, 2 Sep 2026 12:04:55 -0700 Subject: [PATCH 120/140] lnd: remove bleetube as maintainer --- pkgs/by-name/ln/lnd/package.nix | 1 - 1 file changed, 1 deletion(-) diff --git a/pkgs/by-name/ln/lnd/package.nix b/pkgs/by-name/ln/lnd/package.nix index b86528c0c924..fc9a13f49daf 100644 --- a/pkgs/by-name/ln/lnd/package.nix +++ b/pkgs/by-name/ln/lnd/package.nix @@ -48,7 +48,6 @@ buildGoModule (finalAttrs: { homepage = "https://github.com/lightningnetwork/lnd"; license = lib.licenses.mit; maintainers = with lib.maintainers; [ - bleetube cypherpunk2140 prusnak ]; From 839408f5bd5fcbd4f73d887043eda4f4771a577c Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 19:16:22 +0000 Subject: [PATCH 121/140] regclient: 0.11.5 -> 0.11.6 --- pkgs/by-name/re/regclient/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/re/regclient/package.nix b/pkgs/by-name/re/regclient/package.nix index cb5ad5dbda68..cf0e04d4f834 100644 --- a/pkgs/by-name/re/regclient/package.nix +++ b/pkgs/by-name/re/regclient/package.nix @@ -19,15 +19,15 @@ in buildGoModule (finalAttrs: { pname = "regclient"; - version = "0.11.5"; + version = "0.11.6"; src = fetchFromGitHub { owner = "regclient"; repo = "regclient"; tag = "v${finalAttrs.version}"; - sha256 = "sha256-tJBnNtuN9BIlGvHekrvziyBu5gFPzbID/09eAoM5VUc="; + sha256 = "sha256-GBRqblUXSUVbpI/sQ8UIc/XaRQHZE+S43i/S3zc3vgo="; }; - vendorHash = "sha256-jpXy3ZWj+JoDKU2r7FanKR8nQGIQPAL9GW4g//e5xZs="; + vendorHash = "sha256-XU6y15/6VEbV323jKWw2534huQjTxn/qmsyN+qszQxA="; outputs = [ "out" ] ++ bins; From 44900b88906b01dc6a8874c4c091c3f724c241dc Mon Sep 17 00:00:00 2001 From: Pol Dellaiera Date: Wed, 2 Sep 2026 18:20:48 +0200 Subject: [PATCH 122/140] pedantix: 1.1.0 -> 1.2.1 Diff: https://github.com/Swarsel/pedantix/compare/v1.1.0...v1.2.1 Changelog: https://github.com/Swarsel/pedantix/releases/tag/v1.2.1 --- pkgs/by-name/pe/pedantix/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/pe/pedantix/package.nix b/pkgs/by-name/pe/pedantix/package.nix index bc2d6ff37d30..1d17344d7674 100644 --- a/pkgs/by-name/pe/pedantix/package.nix +++ b/pkgs/by-name/pe/pedantix/package.nix @@ -8,17 +8,17 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "pedantix"; - version = "1.1.0"; + version = "1.2.1"; __structuredAttrs = true; src = fetchFromGitHub { owner = "Swarsel"; repo = "pedantix"; tag = "v${finalAttrs.version}"; - hash = "sha256-6NwpoqHkMMnqDkoJGbjZ47PUx+M4yYDcN5HiTKscw7E="; + hash = "sha256-WqCiIOFaVZ6+pVBF+fIZlOEb4N+cHCJZBPQ8Rj2OEh0="; }; - cargoHash = "sha256-6U9rnWTVsO1DPp1cEBkRLHjJKcbgNEqXSvzWUC8tWZQ="; + cargoHash = "sha256-ay4rANqOby+/VM+JWbXcd0JQCcZuv8TjZv3d9vcFgfI="; doInstallCheck = true; nativeInstallCheckInputs = [ versionCheckHook ]; From 7daf2ffe557f3fcb062d00251efb676e112f96da Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 19:41:32 +0000 Subject: [PATCH 123/140] okteto: 3.22.0 -> 3.23.0 --- pkgs/by-name/ok/okteto/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ok/okteto/package.nix b/pkgs/by-name/ok/okteto/package.nix index 085ec29445aa..13ba7d35d145 100644 --- a/pkgs/by-name/ok/okteto/package.nix +++ b/pkgs/by-name/ok/okteto/package.nix @@ -10,16 +10,16 @@ buildGoModule (finalAttrs: { pname = "okteto"; - version = "3.22.0"; + version = "3.23.0"; src = fetchFromGitHub { owner = "okteto"; repo = "okteto"; tag = finalAttrs.version; - hash = "sha256-PuJag9/qQG23mU+TE1LboYF+/1od5nVmgXpAaTJKlIg="; + hash = "sha256-P5dHpv2CEoJYr4rj3hQbavlsNNBRBIx4mzE3KhtLTXg="; }; - vendorHash = "sha256-zEdhWfbZv088CXN2+3FQdCPcz3lJOf5iJPeublmVJyM="; + vendorHash = "sha256-/ZC5p5TAJOD8Wx1MDaI2NMPIL2QLfCeP0+XzdK346vI="; postPatch = '' # Disable some tests that need file system & network access. From b0f180915645e02286cf758802f6b853dd1f3739 Mon Sep 17 00:00:00 2001 From: Pol Dellaiera Date: Wed, 2 Sep 2026 21:43:59 +0200 Subject: [PATCH 124/140] mago: 1.47.4 -> 1.47.5 Diff: https://github.com/carthage-software/mago/compare/1.47.4...1.47.5 Changelog: https://github.com/carthage-software/mago/releases/tag/1.47.5 --- pkgs/by-name/ma/mago/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ma/mago/package.nix b/pkgs/by-name/ma/mago/package.nix index 0005026fb61c..2eafa7f86b22 100644 --- a/pkgs/by-name/ma/mago/package.nix +++ b/pkgs/by-name/ma/mago/package.nix @@ -11,17 +11,17 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "mago"; - version = "1.47.4"; + version = "1.47.5"; src = fetchFromGitHub { owner = "carthage-software"; repo = "mago"; tag = finalAttrs.version; - hash = "sha256-Qi1Bz5u/ZDupJz/9ueAwCnJ1hUWIpx1B32dGzcp87Fo="; + hash = "sha256-IUz1BrwJnx+VXq89YbuN6kR7CzCZzkTOG1pQQ9+NpA4="; forceFetchGit = true; # Does not download all files otherwise }; - cargoHash = "sha256-iw9ipn86SjXCdmC5W2naJvaSpYCYb6uNPkKVtA/ZMd4="; + cargoHash = "sha256-r9YgTFIBa3HoKEpDH3SLqmXLLd5HNPCznf/mo1si2rw="; env = { # Get openssl-sys to use pkg-config From 6961a8499068095ea56933326f95299a28306ba4 Mon Sep 17 00:00:00 2001 From: Ross Smyth <18294397+RossSmyth@users.noreply.github.com> Date: Wed, 2 Sep 2026 15:32:59 -0400 Subject: [PATCH 125/140] popcorntime: Mark insecure --- pkgs/by-name/po/popcorntime/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/po/popcorntime/package.nix b/pkgs/by-name/po/popcorntime/package.nix index 3c108c50e007..b32d14d030ad 100644 --- a/pkgs/by-name/po/popcorntime/package.nix +++ b/pkgs/by-name/po/popcorntime/package.nix @@ -102,5 +102,8 @@ stdenv.mkDerivation rec { license = lib.licenses.gpl3; maintainers = with lib.maintainers; [ onny ]; mainProgram = "popcorntime"; + knownVulnerabilities = [ + "Uses vendored Electron 6, EOL on May 18, 2020 with many CVEs" + ]; }; } From 846d50377cca4acc94a1ad9e8ee5a7b0cdbdf518 Mon Sep 17 00:00:00 2001 From: Ross Smyth <18294397+RossSmyth@users.noreply.github.com> Date: Wed, 2 Sep 2026 15:37:23 -0400 Subject: [PATCH 126/140] keeweb: mark insecure due to EOL electron --- pkgs/by-name/ke/keeweb/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/ke/keeweb/package.nix b/pkgs/by-name/ke/keeweb/package.nix index e83b9b6863fa..81a5e2511523 100644 --- a/pkgs/by-name/ke/keeweb/package.nix +++ b/pkgs/by-name/ke/keeweb/package.nix @@ -76,6 +76,9 @@ let license = lib.licenses.mit; maintainers = with lib.maintainers; [ sikmir ]; platforms = builtins.attrNames srcs; + knownVulnerabilities = [ + "Uses Electron 12, EOL on November 16 2012. Has many known CVEs" + ]; }; in if stdenv.hostPlatform.isDarwin then From ed3691fc32945aea055fd2437a10cd84165d0a2f Mon Sep 17 00:00:00 2001 From: Ross Smyth <18294397+RossSmyth@users.noreply.github.com> Date: Wed, 2 Sep 2026 15:39:25 -0400 Subject: [PATCH 127/140] keybase-gui: mark insecure due to EOL Electron --- pkgs/by-name/ke/keybase-gui/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/ke/keybase-gui/package.nix b/pkgs/by-name/ke/keybase-gui/package.nix index df4bffcfc302..37f9754616a2 100644 --- a/pkgs/by-name/ke/keybase-gui/package.nix +++ b/pkgs/by-name/ke/keybase-gui/package.nix @@ -163,5 +163,8 @@ stdenv.mkDerivation (finalAttrs: { ]; sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ]; license = lib.licenses.bsd3; + knownVulnerabilities = [ + "Uses Electron 28, EOL on 05 Dec 2023. Has many known CVEs" + ]; }; }) From 35e74831d475dab80cef9a8a7bdb1eb67db50454 Mon Sep 17 00:00:00 2001 From: Ross Smyth <18294397+RossSmyth@users.noreply.github.com> Date: Wed, 2 Sep 2026 15:43:03 -0400 Subject: [PATCH 128/140] inav-configurator: mark as insecure due to EOL Electron --- pkgs/by-name/in/inav-configurator/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/in/inav-configurator/package.nix b/pkgs/by-name/in/inav-configurator/package.nix index ffb5ad7d11e6..a3aaae2f6837 100644 --- a/pkgs/by-name/in/inav-configurator/package.nix +++ b/pkgs/by-name/in/inav-configurator/package.nix @@ -79,5 +79,8 @@ stdenv.mkDerivation rec { wucke13 ]; platforms = lib.platforms.linux; + knownVulnerabilities = [ + "Uses Electron 38.7.2, EOL on 28-Jan-2026, with several known CVEs." + ]; }; } From 71fcd865933414f3c150901a49ce551334b80d3d Mon Sep 17 00:00:00 2001 From: Ross Smyth <18294397+RossSmyth@users.noreply.github.com> Date: Wed, 2 Sep 2026 15:44:51 -0400 Subject: [PATCH 129/140] hakuneko: mark as insecure --- pkgs/by-name/ha/hakuneko/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/ha/hakuneko/package.nix b/pkgs/by-name/ha/hakuneko/package.nix index 93a534d2d5b2..bab7e86d7799 100644 --- a/pkgs/by-name/ha/hakuneko/package.nix +++ b/pkgs/by-name/ha/hakuneko/package.nix @@ -101,5 +101,8 @@ stdenv.mkDerivation (finalAttrs: { "i686-linux" ]; mainProgram = "hakuneko"; + knownVulnerabilities = [ + "Uses Electron 6.1.7, which was EOL on February 25, 2020, with many known CVEs" + ]; }; }) From aac96db68db96bfff4a3d95651659f0a551aa11c Mon Sep 17 00:00:00 2001 From: Ross Smyth <18294397+RossSmyth@users.noreply.github.com> Date: Wed, 2 Sep 2026 15:46:49 -0400 Subject: [PATCH 130/140] cypress: mark as insecure --- pkgs/by-name/cy/cypress/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/cy/cypress/package.nix b/pkgs/by-name/cy/cypress/package.nix index 9d614b677e0b..48de7545df25 100644 --- a/pkgs/by-name/cy/cypress/package.nix +++ b/pkgs/by-name/cy/cypress/package.nix @@ -127,5 +127,8 @@ stdenv.mkDerivation rec { Crafter jonhermansen ]; + knownVulnerabilities = [ + "Uses Electron 37.6.0, EOL on October 4, 2025, Several CVEs known." + ]; }; } From 668b046c5f142956e727c6e53430677b783bdf3a Mon Sep 17 00:00:00 2001 From: Ross Smyth <18294397+RossSmyth@users.noreply.github.com> Date: Wed, 2 Sep 2026 15:49:20 -0400 Subject: [PATCH 131/140] beekeeper-studio: mark as insecure due to EOL Electron --- pkgs/by-name/be/beekeeper-studio/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/be/beekeeper-studio/package.nix b/pkgs/by-name/be/beekeeper-studio/package.nix index 03a43ee33dc8..38081a914692 100644 --- a/pkgs/by-name/be/beekeeper-studio/package.nix +++ b/pkgs/by-name/be/beekeeper-studio/package.nix @@ -159,5 +159,8 @@ stdenv.mkDerivation (finalAttrs: { "x86_64-linux" "aarch64-darwin" ]; + knownVulnerabilities = [ + "Uses Electron 39.8.1, which was EOL on March 13 2026, with several known CVEs" + ]; }; }) From 5a2bb406835bde2d078dc3277f560c239099b8dc Mon Sep 17 00:00:00 2001 From: Ross Smyth <18294397+RossSmyth@users.noreply.github.com> Date: Wed, 2 Sep 2026 15:34:44 -0400 Subject: [PATCH 132/140] pencil: Mark insecure due to EOL Electron --- pkgs/by-name/pe/pencil/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/pe/pencil/package.nix b/pkgs/by-name/pe/pencil/package.nix index 917bbaa7a9ed..b68c4797c766 100644 --- a/pkgs/by-name/pe/pencil/package.nix +++ b/pkgs/by-name/pe/pencil/package.nix @@ -146,5 +146,8 @@ stdenv.mkDerivation (finalAttrs: { mrVanDalo ]; platforms = lib.platforms.linux; + knownVulnerabilities = [ + "Uses Electron 6, EOL in May 2020 with many CVEs" + ]; }; }) From 0b07d1e13f785b676d51ddc71cf0c38e28c96490 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 20:05:00 +0000 Subject: [PATCH 133/140] home-assistant-custom-components.blitzortung: 1.7.0 -> 1.7.1 --- .../home-assistant/custom-components/blitzortung/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/home-assistant/custom-components/blitzortung/package.nix b/pkgs/servers/home-assistant/custom-components/blitzortung/package.nix index 5600f7edd3fd..3bfaf6033e3d 100644 --- a/pkgs/servers/home-assistant/custom-components/blitzortung/package.nix +++ b/pkgs/servers/home-assistant/custom-components/blitzortung/package.nix @@ -10,13 +10,13 @@ buildHomeAssistantComponent (finalAttrs: { owner = "mrk-its"; domain = "blitzortung"; - version = "1.7.0"; + version = "1.7.1"; src = fetchFromGitHub { owner = "mrk-its"; repo = "homeassistant-blitzortung"; tag = "v${finalAttrs.version}"; - hash = "sha256-8/KIPOmQdaaSFFrjliBBNjboPx8ewzG9/W/grBuex6s="; + hash = "sha256-CjO1SeArDYMZyHDNxGGhS26leUEgrpRYiXEWKYdeA7o="; }; dependencies = [ From d050eb1e8dab9c53178e57effaec79c78249f5fe Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 20:05:53 +0000 Subject: [PATCH 134/140] libdigidocpp: 4.5.0 -> 4.5.1 --- pkgs/by-name/li/libdigidocpp/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/li/libdigidocpp/package.nix b/pkgs/by-name/li/libdigidocpp/package.nix index 0f9d6d7b4fa5..8ca53895155d 100644 --- a/pkgs/by-name/li/libdigidocpp/package.nix +++ b/pkgs/by-name/li/libdigidocpp/package.nix @@ -16,14 +16,14 @@ }: stdenv.mkDerivation (finalAttrs: { - version = "4.5.0"; + version = "4.5.1"; pname = "libdigidocpp"; src = fetchFromGitHub { owner = "open-eid"; repo = "libdigidocpp"; tag = "v${finalAttrs.version}"; - hash = "sha256-/RCRYF3G7/0J6oHT4mfapI4tlYLdWlQ2HTVqJGuDm3A="; + hash = "sha256-LT2JQwrliec3/tttu0SehhOnO+IL+IOLyk9L1tLsuuw="; }; nativeBuildInputs = [ From eb02530ac93905716982b33571637deeff8c0d85 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 2 Sep 2026 21:14:06 +0000 Subject: [PATCH 135/140] dokuwiki: 2026-07-14b -> 2026-07-14c --- pkgs/by-name/do/dokuwiki/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/do/dokuwiki/package.nix b/pkgs/by-name/do/dokuwiki/package.nix index e6b1e614063f..3059ee06e05a 100644 --- a/pkgs/by-name/do/dokuwiki/package.nix +++ b/pkgs/by-name/do/dokuwiki/package.nix @@ -9,13 +9,13 @@ stdenv.mkDerivation rec { pname = "dokuwiki"; - version = "2026-07-14b"; + version = "2026-07-14c"; src = fetchFromGitHub { owner = "dokuwiki"; repo = "dokuwiki"; rev = "release-${version}"; - sha256 = "sha256-w/uVk60gdr4PhUMOHHYl+X87Hx9pojYqJo5sZXLUX6o="; + sha256 = "sha256-84kMuFTWYo6Cjd6qpkZsLZoECIP9IzSrc9dX1uKMp0M="; }; preload = writeText "preload.php" '' From 3d0d76207d79575f5cd2cc5f41cef6ed9dce519b Mon Sep 17 00:00:00 2001 From: whispers Date: Tue, 1 Sep 2026 23:56:24 -0400 Subject: [PATCH 136/140] unqlite: rec -> finalAttrs, move to by-name --- .../unqlite/default.nix => by-name/un/unqlite/package.nix} | 7 ++++--- pkgs/top-level/all-packages.nix | 2 -- 2 files changed, 4 insertions(+), 5 deletions(-) rename pkgs/{development/libraries/unqlite/default.nix => by-name/un/unqlite/package.nix} (93%) diff --git a/pkgs/development/libraries/unqlite/default.nix b/pkgs/by-name/un/unqlite/package.nix similarity index 93% rename from pkgs/development/libraries/unqlite/default.nix rename to pkgs/by-name/un/unqlite/package.nix index 8b368b6e6c8f..de260d78c20d 100644 --- a/pkgs/development/libraries/unqlite/default.nix +++ b/pkgs/by-name/un/unqlite/package.nix @@ -5,14 +5,14 @@ cmake, }: -stdenv.mkDerivation rec { +stdenv.mkDerivation (finalAttrs: { pname = "unqlite"; version = "1.2.1"; src = fetchFromGitHub { owner = "symisc"; repo = "unqlite"; - tag = version; + tag = finalAttrs.version; hash = "sha256-HXhI+IEnBBsWzI+EriGqqkJmeyOF+Y/NJzu4rMd0eY0="; }; @@ -38,5 +38,6 @@ stdenv.mkDerivation rec { ''; maintainers = [ ]; license = lib.licenses.bsd2; + priority = 10; }; -} +}) diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 0b3c7c74cdff..e23ecf3ddd68 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -6646,8 +6646,6 @@ with pkgs; sqlite = lowPrio (callPackage ../development/libraries/sqlite { }); - unqlite = lowPrio (callPackage ../development/libraries/unqlite { }); - inherit (callPackage ../development/libraries/sqlite/tools.nix { }) From d1173f76d8fb2f202e9e1cfdb89dc5998bf597d9 Mon Sep 17 00:00:00 2001 From: networkException Date: Thu, 3 Sep 2026 00:02:17 +0200 Subject: [PATCH 137/140] ungoogled-chromium: 152.0.7977.64-1 -> 152.0.7977.75-1 https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html This update includes 26 security fixes. CVEs: CVE-2026-84353 CVE-2026-84352 CVE-2026-84354 CVE-2026-84359 CVE-2026-84357 CVE-2026-84324 CVE-2026-84349 CVE-2026-84326 CVE-2026-84333 CVE-2026-84351 CVE-2026-84325 CVE-2026-84328 CVE-2026-84347 CVE-2026-84323 CVE-2026-84355 CVE-2026-84358 CVE-2026-84332 CVE-2026-84330 CVE-2026-84334 CVE-2026-84348 CVE-2026-84335 CVE-2026-84327 CVE-2026-84329 CVE-2026-84356 CVE-2026-84350 CVE-2026-84331 --- .../networking/browsers/chromium/info.json | 22 +++++++++---------- 1 file changed, 11 insertions(+), 11 deletions(-) diff --git a/pkgs/applications/networking/browsers/chromium/info.json b/pkgs/applications/networking/browsers/chromium/info.json index 884eeaa06645..67aa9f0afe9a 100644 --- a/pkgs/applications/networking/browsers/chromium/info.json +++ b/pkgs/applications/networking/browsers/chromium/info.json @@ -853,7 +853,7 @@ } }, "ungoogled-chromium": { - "version": "152.0.7977.64", + "version": "152.0.7977.75", "deps": { "depot_tools": { "rev": "38c391feba5fb96812f9028da12413ffc39df394", @@ -865,16 +865,16 @@ "hash": "sha256-ovLx6KaORdXqnWgbsGEty10k2CHuCmTk3yEqy5//ovk=" }, "ungoogled-patches": { - "rev": "152.0.7977.64-1", - "hash": "sha256-9esE3TgtKiwwFL5pu87aEQznelMVtNXBslggYAJTEbc=" + "rev": "152.0.7977.75-1", + "hash": "sha256-HXWnJfk0SxC8sRcgtFdGBOOeiV7kEQD2YXQFBwMsU1s=" }, "npmHash": "sha256-pF0JtwFpPC4/fodbhSJnQKkczA9WlDg4VqEAy9aDVLg=" }, "DEPS": { "src": { "url": "https://chromium.googlesource.com/chromium/src.git", - "rev": "506c834ecceaa943c5f41e6cfe7f68acb5c45346", - "hash": "sha256-KEr9nzF55+c8Rvvay3SZjcWMDWVGTyv1f5Pjv3ckl3E=", + "rev": "4999cc1efed37c4d91dc4ce6ec4b0a50e2a9a8cb", + "hash": "sha256-RXykREnCulCwk8zkk8OAd62TM4qel6j4uhyaaYzgolY=", "recompress": true }, "src/third_party/clang-format/script": { @@ -989,8 +989,8 @@ }, "src/third_party/dawn": { "url": "https://dawn.googlesource.com/dawn.git", - "rev": "571752c9cb3ed36a3194854374984427794c4dda", - "hash": "sha256-YMgRmVMXo1Ra5M034zij/ik/1aHpb3veK4VWsKHIwhI=" + "rev": "ab8827bc57b176eeaa89f71324130c02d4d41145", + "hash": "sha256-Xd1FsdIBO6hzNECnNnXR0306woHl5/L+5WZ/pxTlYfA=" }, "src/third_party/dawn/third_party/glfw3/src": { "url": "https://chromium.googlesource.com/external/github.com/glfw/glfw", @@ -1124,8 +1124,8 @@ }, "src/third_party/devtools-frontend/src": { "url": "https://chromium.googlesource.com/devtools/devtools-frontend", - "rev": "941348cf79c423892e1c7c219091a7103d18a68b", - "hash": "sha256-/b+NCAr1jRJd/Uq4Cf5aO/yTdNP00ImIWuSJ4aP+TEw=" + "rev": "04db1f5240b636511ec4e9058a78f8274a7f65ee", + "hash": "sha256-vZxKC/QD2dHNnVm9OZI1Bo0Jdnn+AJhFpXYSXXF7JsA=" }, "src/third_party/dom_distiller_js/dist": { "url": "https://chromium.googlesource.com/chromium/dom-distiller/dist.git", @@ -1694,8 +1694,8 @@ }, "src/v8": { "url": "https://chromium.googlesource.com/v8/v8.git", - "rev": "6aacaf6256a069ee455142333b7d38cad1c8d6e0", - "hash": "sha256-1NX4HP/BIJ6bWxoF42K89X8ADHuHjA5akkOL/WkIeME=" + "rev": "3de6ffffbfdcf265e9f11a5c9d1cfb4d486d7550", + "hash": "sha256-ZHEmeSe8r226gjazm91GYqlfbM9a5yi8KnFv4iAWFKE=" }, "src/agents/shared": { "url": "https://chromium.googlesource.com/chromium/agents.git", From 5848d3b16821cadff61d453a5577baf217a1a5e0 Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Thu, 3 Sep 2026 00:02:50 +0200 Subject: [PATCH 138/140] python3Packages.androidtvremote2: 0.3.1 -> 0.3.2 Diff: https://github.com/tronikos/androidtvremote2/compare/v0.3.1...v0.3.2 Changelog: https://github.com/tronikos/androidtvremote2/releases/tag/v0.3.2 --- pkgs/development/python-modules/androidtvremote2/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/androidtvremote2/default.nix b/pkgs/development/python-modules/androidtvremote2/default.nix index 1ca07612292a..fdccc81750b5 100644 --- a/pkgs/development/python-modules/androidtvremote2/default.nix +++ b/pkgs/development/python-modules/androidtvremote2/default.nix @@ -10,14 +10,14 @@ buildPythonPackage (finalAttrs: { pname = "androidtvremote2"; - version = "0.3.1"; + version = "0.3.2"; pyproject = true; src = fetchFromGitHub { owner = "tronikos"; repo = "androidtvremote2"; tag = "v${finalAttrs.version}"; - hash = "sha256-W+L1yQ7FAoKIlYtlM7gfPv8Tco/9hCDDUQQ16xg+++s="; + hash = "sha256-zyM9s8gtL0lBGd2hkANZRNsG7BEZv+c7Agexpk80OT0="; }; build-system = [ setuptools ]; From 3e7bea1366833aa46f54401eb6cb597c9486382b Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Thu, 3 Sep 2026 00:04:59 +0200 Subject: [PATCH 139/140] python3Packages.censys: 2.2.19 -> 2.3.0 Changelog: https://github.com/censys/censys-python/releases/tag/v2.3.0 --- .../python-modules/censys/default.nix | 20 ++++++------------- 1 file changed, 6 insertions(+), 14 deletions(-) diff --git a/pkgs/development/python-modules/censys/default.nix b/pkgs/development/python-modules/censys/default.nix index 5b098bfb3ea1..7583c0fc92bc 100644 --- a/pkgs/development/python-modules/censys/default.nix +++ b/pkgs/development/python-modules/censys/default.nix @@ -4,15 +4,14 @@ backoff, buildPythonPackage, fetchFromGitHub, + hatchling, importlib-metadata, parameterized, - poetry-core, - pytest-mock, pytest-cov-stub, + pytest-mock, pytestCheckHook, - pythonAtLeast, - requests, requests-mock, + requests, responses, rich, writableTmpDirAsHomeHook, @@ -20,17 +19,17 @@ buildPythonPackage rec { pname = "censys"; - version = "2.2.19"; + version = "2.3.0"; pyproject = true; src = fetchFromGitHub { owner = "censys"; repo = "censys-python"; tag = "v${version}"; - hash = "sha256-3eQtGCIKtjpDWfyrIEPZnA6xLMNl0cg61wh0nuwNwh4="; + hash = "sha256-GBFsAVecUN49vousqnB6enqRsAg1aBrjaA/Q7XXnOUE="; }; - build-system = [ poetry-core ]; + build-system = [ hatchling ]; dependencies = [ argcomplete @@ -55,13 +54,6 @@ buildPythonPackage rec { mkdir -p $HOME ''; - disabledTests = lib.optionals (pythonAtLeast "3.14") [ - # argparse usage prefix uses the actual prog (python3.14 -m pytest) instead of sys.argv[0] - "test_default_help" - "test_help" - "test_search_help" - ]; - pythonImportsCheck = [ "censys" ]; meta = { From 0cbb100863f41c15b8b6548f431c1a480ca573e6 Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Thu, 3 Sep 2026 00:07:31 +0200 Subject: [PATCH 140/140] python3Packages.censys: migrate to finalAttrs --- pkgs/development/python-modules/censys/default.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/development/python-modules/censys/default.nix b/pkgs/development/python-modules/censys/default.nix index 7583c0fc92bc..2a3672bd77e7 100644 --- a/pkgs/development/python-modules/censys/default.nix +++ b/pkgs/development/python-modules/censys/default.nix @@ -17,7 +17,7 @@ writableTmpDirAsHomeHook, }: -buildPythonPackage rec { +buildPythonPackage (finalAttrs: { pname = "censys"; version = "2.3.0"; pyproject = true; @@ -25,7 +25,7 @@ buildPythonPackage rec { src = fetchFromGitHub { owner = "censys"; repo = "censys-python"; - tag = "v${version}"; + tag = "v${finalAttrs.version}"; hash = "sha256-GBFsAVecUN49vousqnB6enqRsAg1aBrjaA/Q7XXnOUE="; }; @@ -59,9 +59,9 @@ buildPythonPackage rec { meta = { description = "Python API wrapper for the Censys Search Engine (censys.io)"; homepage = "https://github.com/censys/censys-python"; - changelog = "https://github.com/censys/censys-python/releases/tag/${src.tag}"; + changelog = "https://github.com/censys/censys-python/releases/tag/v${finalAttrs.src.tag}"; license = lib.licenses.asl20; maintainers = with lib.maintainers; [ fab ]; mainProgram = "censys"; }; -} +})