Merge staging-next into staging

This commit is contained in:
nixpkgs-ci[bot]
2025-08-11 18:06:47 +00:00
committed by GitHub
88 changed files with 1043 additions and 389 deletions

View File

@@ -9,6 +9,9 @@ inputs:
merged-as-untrusted:
description: "Whether to checkout the merge commit in the ./untrusted folder."
type: boolean
pinnedFrom:
description: "Whether to checkout the pinned nixpkgs for CI and from where (trusted, untrusted)."
type: string
targetSha:
description: "The target commit SHA, previously collected."
type: string
@@ -83,13 +86,36 @@ runs:
# Would be great to do the checkouts in git worktrees of the existing spare checkout instead,
# but Nix is broken with them:
# https://github.com/NixOS/nix/issues/6073
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
ref: ${{ inputs.mergedSha || steps.commits.outputs.mergedSha }}
path: untrusted
- if: inputs.target-as-trusted && (inputs.targetSha || steps.commits.outputs.targetSha)
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
ref: ${{ inputs.targetSha || steps.commits.outputs.targetSha }}
path: trusted
- if: inputs.pinnedFrom
id: pinned
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
env:
PINNED_FROM: ${{ inputs.pinnedFrom }}
with:
script: |
const path = require('node:path')
const pinned = require(path.resolve(path.join(process.env.PINNED_FROM, 'ci', 'pinned.json')))
core.setOutput('pinnedSha', pinned.pins.nixpkgs.revision)
- if: steps.pinned.outputs.pinnedSha
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
ref: ${{ steps.pinned.outputs.pinnedSha }}
path: pinned
sparse-checkout: |
lib
maintainers
nixos/lib
pkgs

View File

@@ -27,7 +27,7 @@ jobs:
steps:
# Use a GitHub App to create the PR so that CI gets triggered
# The App is scoped to Repository > Contents and Pull Requests: write for Nixpkgs
- uses: actions/create-github-app-token@df432ceedc7162793a195dd1713ff69aefc7379e # v2.0.6
- uses: actions/create-github-app-token@0f859bf9e69e887678d5bbfbee594437cb440ffe # v2.1.0
id: app-token
with:
app-id: ${{ vars.NIXPKGS_CI_APP_ID }}
@@ -35,7 +35,7 @@ jobs:
permission-contents: write
permission-pull-requests: write
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
ref: ${{ github.event.pull_request.head.sha }}
token: ${{ steps.app-token.outputs.token }}

View File

@@ -26,26 +26,25 @@ jobs:
matrix:
include:
- runner: ubuntu-24.04
system: x86_64-linux
name: x86_64-linux
systems: x86_64-linux
builds: [shell, manual-nixos, lib-tests, tarball]
desc: shell, docs, lib, tarball
- runner: ubuntu-24.04-arm
system: aarch64-linux
name: aarch64-linux
systems: aarch64-linux
builds: [shell, manual-nixos, manual-nixpkgs, manual-nixpkgs-tests]
desc: shell, docs
- runner: macos-13
system: x86_64-darwin
builds: [shell]
desc: shell
- runner: macos-14
system: aarch64-darwin
name: darwin
systems: aarch64-darwin x86_64-darwin
builds: [shell]
desc: shell
name: '${{ matrix.system }}: ${{ matrix.desc }}'
name: '${{ matrix.name }}: ${{ matrix.desc }}'
runs-on: ${{ matrix.runner }}
timeout-minutes: 60
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
sparse-checkout: .github/actions
- name: Check if the PR can be merged and checkout the merge commit
@@ -53,9 +52,11 @@ jobs:
with:
mergedSha: ${{ inputs.mergedSha }}
merged-as-untrusted: true
pinnedFrom: untrusted
- uses: cachix/install-nix-action@f0fe604f8a612776892427721526b4c7cfb23aba # v31
- uses: cachix/install-nix-action@fc6e360bedc9ee72d75e701397f0bb30dce77568 # v31
with:
# Sandbox is disabled on MacOS by default.
extra_nix_config: sandbox = true
- uses: cachix/cachix-action@0fc020193b5a1fa3ac4575aa3a7d3aa6a35435ad # v16
@@ -64,31 +65,33 @@ jobs:
name: nixpkgs-ci
authToken: "${{ secrets.CACHIX_AUTH_TOKEN }}"
- run: nix-env --install -f pinned -A nix-build-uncached
- name: Build shell
if: contains(matrix.builds, 'shell')
run: nix-build untrusted/ci -A shell
run: echo "${{ matrix.systems }}" | xargs -n1 nix-build-uncached untrusted/ci --arg nixpkgs ./pinned -A shell --argstr system
- name: Build NixOS manual
if: |
contains(matrix.builds, 'manual-nixos') && !cancelled() &&
contains(fromJSON(inputs.baseBranch).type, 'primary')
run: nix-build untrusted/ci -A manual-nixos --argstr system ${{ matrix.system }} --out-link nixos-manual
run: nix-build-uncached untrusted/ci --arg nixpkgs ./pinned -A manual-nixos --out-link nixos-manual
- name: Build Nixpkgs manual
if: contains(matrix.builds, 'manual-nixpkgs') && !cancelled()
run: nix-build untrusted/ci -A manual-nixpkgs -A manual-nixpkgs-tests
run: nix-build-uncached untrusted/ci --arg nixpkgs ./pinned -A manual-nixpkgs -A manual-nixpkgs-tests
- name: Build Nixpkgs manual tests
if: contains(matrix.builds, 'manual-nixpkgs-tests') && !cancelled()
run: nix-build untrusted/ci -A manual-nixpkgs-tests
run: nix-build-uncached untrusted/ci --arg nixpkgs ./pinned -A manual-nixpkgs-tests
- name: Build lib tests
if: contains(matrix.builds, 'lib-tests') && !cancelled()
run: nix-build untrusted/ci -A lib-tests
run: nix-build-uncached untrusted/ci --arg nixpkgs ./pinned -A lib-tests
- name: Build tarball
if: contains(matrix.builds, 'tarball') && !cancelled()
run: nix-build untrusted/ci -A tarball
run: nix-build-uncached untrusted/ci --arg nixpkgs ./pinned -A tarball
- name: Upload NixOS manual
if: |
@@ -96,6 +99,5 @@ jobs:
contains(fromJSON(inputs.baseBranch).type, 'primary')
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: nixos-manual-${{ matrix.system }}
name: nixos-manual-${{ matrix.name }}
path: nixos-manual
if-no-files-found: error

View File

@@ -40,7 +40,7 @@ jobs:
runs-on: ubuntu-24.04-arm
timeout-minutes: 3
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
fetch-depth: 0
filter: tree:0

View File

@@ -51,7 +51,7 @@ jobs:
runs-on: ubuntu-24.04-arm
timeout-minutes: 5
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
sparse-checkout: .github/actions
- name: Check if the PR can be merged and checkout the merge and target commits
@@ -60,7 +60,7 @@ jobs:
merged-as-untrusted: true
target-as-trusted: true
- uses: cachix/install-nix-action@f0fe604f8a612776892427721526b4c7cfb23aba # v31
- uses: cachix/install-nix-action@fc6e360bedc9ee72d75e701397f0bb30dce77568 # v31
- uses: cachix/cachix-action@0fc020193b5a1fa3ac4575aa3a7d3aa6a35435ad # v16
with:
@@ -71,7 +71,7 @@ jobs:
- name: Build codeowners validator
run: nix-build trusted/ci -A codeownersValidator
- uses: actions/create-github-app-token@df432ceedc7162793a195dd1713ff69aefc7379e # v2.0.6
- uses: actions/create-github-app-token@0f859bf9e69e887678d5bbfbee594437cb440ffe # v2.1.0
if: github.event_name == 'pull_request_target' && vars.OWNER_RO_APP_ID
id: app-token
with:
@@ -109,18 +109,18 @@ jobs:
runs-on: ubuntu-24.04-arm
timeout-minutes: 5
steps:
- uses: cachix/install-nix-action@f0fe604f8a612776892427721526b4c7cfb23aba # v31
- uses: cachix/install-nix-action@fc6e360bedc9ee72d75e701397f0bb30dce77568 # v31
# Important: Because we use pull_request_target, this checks out the base branch of the PR, not the PR head.
# This is intentional, because we need to request the review of owners as declared in the base branch.
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
path: trusted
- name: Build review request package
run: nix-build trusted/ci -A requestReviews
- uses: actions/create-github-app-token@df432ceedc7162793a195dd1713ff69aefc7379e # v2.0.6
- uses: actions/create-github-app-token@0f859bf9e69e887678d5bbfbee594437cb440ffe # v2.1.0
if: github.event_name == 'pull_request_target' && vars.OWNER_APP_ID
id: app-token
with:

View File

@@ -36,7 +36,7 @@ jobs:
# Use a GitHub App to create the PR so that CI gets triggered
# The App is scoped to Repository > Contents and Pull Requests: write for Nixpkgs
# We only need Pull Requests: write here, but the app is also used for backports.
- uses: actions/create-github-app-token@df432ceedc7162793a195dd1713ff69aefc7379e # v2.0.6
- uses: actions/create-github-app-token@0f859bf9e69e887678d5bbfbee594437cb440ffe # v2.1.0
id: app-token
with:
app-id: ${{ vars.NIXPKGS_CI_APP_ID }}

View File

@@ -44,22 +44,24 @@ jobs:
sudo mkswap /swap
sudo swapon /swap
- name: Check out the PR at the test merge commit
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
ref: ${{ inputs.mergedSha }}
path: untrusted
sparse-checkout: .github/actions
- name: Check out the PR at the test merge commit
uses: ./.github/actions/get-merge-commit
with:
mergedSha: ${{ inputs.mergedSha }}
merged-as-untrusted: true
pinnedFrom: untrusted
- name: Install Nix
uses: cachix/install-nix-action@f0fe604f8a612776892427721526b4c7cfb23aba # v31
with:
extra_nix_config: sandbox = true
uses: cachix/install-nix-action@fc6e360bedc9ee72d75e701397f0bb30dce77568 # v31
- name: Evaluate the ${{ matrix.system }} output paths for all derivation attributes
env:
MATRIX_SYSTEM: ${{ matrix.system }}
run: |
nix-build untrusted/ci -A eval.singleSystem \
nix-build untrusted/ci --arg nixpkgs ./pinned -A eval.singleSystem \
--argstr evalSystem "$MATRIX_SYSTEM" \
--arg chunkSize 8000 \
--out-link merged
@@ -123,7 +125,7 @@ jobs:
GH_TOKEN: ${{ github.token }}
run: gh api /rate_limit | jq
- uses: actions/download-artifact@v4
- uses: actions/download-artifact@v5
if: steps.targetRunId.outputs.targetRunId
with:
run-id: ${{ steps.targetRunId.outputs.targetRunId }}
@@ -137,7 +139,7 @@ jobs:
env:
MATRIX_SYSTEM: ${{ matrix.system }}
run: |
nix-build untrusted/ci -A eval.diff \
nix-build untrusted/ci --arg nixpkgs ./pinned -A eval.diff \
--arg beforeDir ./target \
--arg afterDir "$(readlink ./merged)" \
--argstr evalSystem "$MATRIX_SYSTEM" \
@@ -158,27 +160,29 @@ jobs:
statuses: write
timeout-minutes: 5
steps:
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
sparse-checkout: .github/actions
- name: Check out the PR at the target commit
uses: ./.github/actions/get-merge-commit
with:
targetSha: ${{ inputs.targetSha }}
target-as-trusted: true
pinnedFrom: trusted
- name: Download output paths and eval stats for all systems
uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4.1.8
uses: actions/download-artifact@de96f4613b77ec03b5cf633e7c350c32bd3c5660 # v4.1.8
with:
pattern: diff-*
path: diff
merge-multiple: true
- name: Check out the PR at the target commit
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
ref: ${{ inputs.targetSha }}
path: trusted
- name: Install Nix
uses: cachix/install-nix-action@f0fe604f8a612776892427721526b4c7cfb23aba # v31
with:
extra_nix_config: sandbox = true
uses: cachix/install-nix-action@fc6e360bedc9ee72d75e701397f0bb30dce77568 # v31
- name: Combine all output paths and eval stats
run: |
nix-build trusted/ci -A eval.combine \
nix-build trusted/ci --arg nixpkgs ./pinned -A eval.combine \
--arg diffDir ./diff \
--out-link combined
@@ -191,7 +195,7 @@ jobs:
| jq --raw-input --slurp 'split("\n")[:-1]' > touched-files.json
# Use the target branch to get accurate maintainer info
nix-build trusted/ci -A eval.compare \
nix-build trusted/ci --arg nixpkgs ./pinned -A eval.compare \
--arg combinedDir "$(realpath ./combined)" \
--arg touchedFilesJson ./touched-files.json \
--argstr githubAuthorId "$AUTHOR_ID" \
@@ -241,7 +245,7 @@ jobs:
runs-on: ubuntu-24.04-arm
timeout-minutes: 10
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
sparse-checkout: .github/actions
- name: Check if the PR can be merged and checkout the merge commit
@@ -250,9 +254,7 @@ jobs:
merged-as-untrusted: true
- name: Install Nix
uses: cachix/install-nix-action@f0fe604f8a612776892427721526b4c7cfb23aba # v31
with:
extra_nix_config: sandbox = true
uses: cachix/install-nix-action@fc6e360bedc9ee72d75e701397f0bb30dce77568 # v31
- name: Ensure flake outputs on all systems still evaluate
run: nix flake check --all-systems --no-build ./untrusted

View File

@@ -40,7 +40,7 @@ jobs:
runs-on: ubuntu-24.04-arm
if: github.event_name != 'schedule' || github.repository_owner == 'NixOS'
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
sparse-checkout: |
ci/github-script
@@ -49,7 +49,7 @@ jobs:
run: npm install @actions/artifact bottleneck
# Use a GitHub App, because it has much higher rate limits: 12,500 instead of 5,000 req / hour.
- uses: actions/create-github-app-token@df432ceedc7162793a195dd1713ff69aefc7379e # v2.0.6
- uses: actions/create-github-app-token@0f859bf9e69e887678d5bbfbee594437cb440ffe # v2.1.0
if: vars.NIXPKGS_CI_APP_ID
id: app-token
with:

View File

@@ -21,7 +21,7 @@ jobs:
runs-on: ubuntu-24.04-arm
timeout-minutes: 10
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
sparse-checkout: .github/actions
- name: Check if the PR can be merged and checkout the merge commit
@@ -29,17 +29,16 @@ jobs:
with:
mergedSha: ${{ inputs.mergedSha }}
merged-as-untrusted: true
pinnedFrom: untrusted
- uses: cachix/install-nix-action@f0fe604f8a612776892427721526b4c7cfb23aba # v31
with:
extra_nix_config: sandbox = true
- uses: cachix/install-nix-action@fc6e360bedc9ee72d75e701397f0bb30dce77568 # v31
- name: Check that files are formatted
run: |
# Note that it's fine to run this on untrusted code because:
# - There's no secrets accessible here
# - The build is sandboxed
if ! nix-build untrusted/ci -A fmt.check; then
if ! nix-build untrusted/ci --arg nixpkgs ./pinned -A fmt.check; then
echo "Some files are not properly formatted"
echo "Please format them by going to the Nixpkgs root directory and running one of:"
echo " nix-shell --run treefmt"
@@ -54,7 +53,7 @@ jobs:
runs-on: ubuntu-24.04-arm
timeout-minutes: 10
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
sparse-checkout: .github/actions
- name: Check if the PR can be merged and checkout the merge commit
@@ -62,21 +61,20 @@ jobs:
with:
mergedSha: ${{ inputs.mergedSha }}
merged-as-untrusted: true
pinnedFrom: untrusted
- uses: cachix/install-nix-action@f0fe604f8a612776892427721526b4c7cfb23aba # v31
with:
extra_nix_config: sandbox = true
- uses: cachix/install-nix-action@fc6e360bedc9ee72d75e701397f0bb30dce77568 # v31
- name: Parse all nix files
run: |
# Tests multiple versions at once, let's make sure all of them run, so keep-going.
nix-build untrusted/ci -A parse --keep-going
nix-build untrusted/ci --arg nixpkgs ./pinned -A parse --keep-going
nixpkgs-vet:
runs-on: ubuntu-24.04-arm
timeout-minutes: 10
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
sparse-checkout: .github/actions
- name: Check if the PR can be merged and checkout merged and target commits
@@ -84,19 +82,18 @@ jobs:
with:
mergedSha: ${{ inputs.mergedSha }}
merged-as-untrusted: true
pinnedFrom: untrusted
targetSha: ${{ inputs.targetSha }}
target-as-trusted: true
- uses: cachix/install-nix-action@f0fe604f8a612776892427721526b4c7cfb23aba # v31
with:
extra_nix_config: sandbox = true
- uses: cachix/install-nix-action@fc6e360bedc9ee72d75e701397f0bb30dce77568 # v31
- name: Running nixpkgs-vet
env:
# Force terminal colors to be enabled. The library that `nixpkgs-vet` uses respects https://bixense.com/clicolors/
CLICOLOR_FORCE: 1
run: |
if nix-build untrusted/ci -A nixpkgs-vet --arg base "./trusted" --arg head "./untrusted"; then
if nix-build untrusted/ci --arg nixpkgs ./pinned -A nixpkgs-vet --arg base "./trusted" --arg head "./untrusted"; then
exit 0
else
exitCode=$?

View File

@@ -23,7 +23,7 @@ jobs:
steps:
# Use a GitHub App to create the PR so that CI gets triggered
# The App is scoped to Repository > Contents and Pull Requests: write for Nixpkgs
- uses: actions/create-github-app-token@df432ceedc7162793a195dd1713ff69aefc7379e # v2.0.6
- uses: actions/create-github-app-token@0f859bf9e69e887678d5bbfbee594437cb440ffe # v2.1.0
id: app-token
with:
app-id: ${{ vars.NIXPKGS_CI_APP_ID }}
@@ -31,7 +31,7 @@ jobs:
permission-contents: write
permission-pull-requests: write
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
- name: Find merge base between two branches
if: contains(inputs.from, ' ')

View File

@@ -29,7 +29,7 @@ jobs:
targetSha: ${{ steps.get-merge-commit.outputs.targetSha }}
systems: ${{ steps.systems.outputs.systems }}
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
sparse-checkout: |
.github/actions

View File

@@ -23,7 +23,7 @@ jobs:
outputs:
systems: ${{ steps.systems.outputs.systems }}
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
sparse-checkout: |
ci/supportedSystems.json

View File

@@ -30,22 +30,20 @@ jobs:
timeout-minutes: 20
steps:
- name: Check out the PR at the base commit
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
with:
path: trusted
sparse-checkout: ci
- name: Install Nix
uses: cachix/install-nix-action@f0fe604f8a612776892427721526b4c7cfb23aba # v31
with:
extra_nix_config: sandbox = true
uses: cachix/install-nix-action@fc6e360bedc9ee72d75e701397f0bb30dce77568 # v31
- name: Build the requestReviews derivation
run: nix-build trusted/ci -A requestReviews
# See ./codeowners-v2.yml, reuse the same App because we need the same permissions
# Can't use the token received from permissions above, because it can't get enough permissions
- uses: actions/create-github-app-token@df432ceedc7162793a195dd1713ff69aefc7379e # v2.0.6
- uses: actions/create-github-app-token@0f859bf9e69e887678d5bbfbee594437cb440ffe # v2.1.0
if: github.event_name == 'pull_request_target' && vars.OWNER_APP_ID
id: app-token
with:
@@ -98,7 +96,7 @@ jobs:
run: gh api /rate_limit | jq
- name: Download the comparison results
uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4.1.8
uses: actions/download-artifact@de96f4613b77ec03b5cf633e7c350c32bd3c5660 # v4.1.8
with:
run-id: ${{ steps.eval.outputs.run-id }}
github-token: ${{ github.token }}

View File

@@ -121,8 +121,8 @@ rec {
# CI jobs
lib-tests = import ../lib/tests/release.nix { inherit pkgs; };
manual-nixos = (import ../nixos/release.nix { }).manual.${system} or null;
manual-nixpkgs = (import ../doc { });
manual-nixpkgs-tests = (import ../doc { }).tests;
manual-nixpkgs = (import ../doc { inherit pkgs; });
manual-nixpkgs-tests = (import ../doc { inherit pkgs; }).tests;
nixpkgs-vet = pkgs.callPackage ./nixpkgs-vet.nix { };
parse = pkgs.lib.recurseIntoAttrs {
latest = pkgs.callPackage ./parse.nix { nix = pkgs.nixVersions.latest; };

View File

@@ -4186,12 +4186,6 @@
github = "carlthome";
githubId = 1595907;
};
carpinchomug = {
email = "aki.suda@protonmail.com";
github = "carpinchomug";
githubId = 101536256;
name = "Akiyoshi Suda";
};
cartr = {
email = "carter.sande@duodecima.technology";
github = "cartr";
@@ -23000,7 +22994,7 @@
seylerius = {
name = "Sable Seyler";
email = "sable@seyleri.us";
github = "seylerius";
github = "sableseyler";
githubId = 1145981;
keys = [ { fingerprint = "7246 B6E1 ABB9 9A48 4395 FD11 DC26 B921 A9E9 DBDE"; } ];
};
@@ -24521,6 +24515,12 @@
githubId = 332289;
name = "Rafał Łasocha";
};
sxmair = {
email = "sumairhasan99@gmail.com";
github = "sxmair";
githubId = 127287939;
name = "Syed Sumairul Hasan";
};
syberant = {
email = "sybrand@neuralcoding.com";
github = "syberant";

View File

@@ -170,6 +170,7 @@
- `services.gitea` supports sending notifications with sendmail again. To do this, activate the parameter `services.gitea.mailerUseSendmail` and configure SMTP server.
- `libvirt` now supports using `nftables` backend.
- The `virtualisation.libvirtd.firewallBackend` option can be used to configure the firewall backend used by libvirtd.
- `systemd.extraConfig` and `boot.initrd.systemd.extraConfig` was converted to RFC42-style `systemd.settings.Manager` and `boot.initrd.systemd.settings.Manager` respectively.
- `systemd.watchdog.runtimeTime` was renamed to `systemd.settings.Manager.RuntimeWatchdogSec`

View File

@@ -148,11 +148,11 @@ def main() -> None:
args.global_timeout,
debug=debugger,
) as driver:
if offset := args.dump_vsocks:
driver.dump_machine_ssh(offset)
if args.interactive:
history_dir = os.getcwd()
history_path = os.path.join(history_dir, ".nixos-test-history")
if offset := args.dump_vsocks:
driver.dump_machine_ssh(offset)
ptpython.ipython.embed(
user_ns=driver.test_symbols(),
history_filename=history_path,

View File

@@ -66,6 +66,36 @@ in
default = [ ];
description = "Extra command line arguments to be passed to the PCSC daemon.";
};
ignoreReaderNames = lib.mkOption {
type = lib.types.listOf (lib.types.strMatching "[^:]+");
default = [ ];
description = ''
List of reader name patterns for the PCSC daemon to ignore.
For more precise control, readers can be ignored through udev rules
(cf. {option}`services.udev.extraRules`) by setting the
`PCSCLITE_IGNORE` property, for example:
```
ACTION!="remove|unbind", SUBSYSTEM=="usb", ATTR{idVendor}=="20a0", ENV{PCSCLITE_IGNORE}="1"
```
'';
example = [
"Nitrokey"
"YubiKey"
];
};
extendReaderNames = lib.mkOption {
type = lib.types.nullOr lib.types.str;
default = null;
description = ''
String to append to every reader name. The special variable `$HOSTNAME`
will be expanded to the current host name.
'';
example = " $HOSTNAME";
};
};
config = lib.mkIf config.services.pcscd.enable {
@@ -79,7 +109,17 @@ in
systemd.sockets.pcscd.wantedBy = [ "sockets.target" ];
systemd.services.pcscd = {
environment.PCSCLITE_HP_DROPDIR = pluginEnv;
environment = {
PCSCLITE_HP_DROPDIR = pluginEnv;
PCSCLITE_FILTER_IGNORE_READER_NAMES = lib.mkIf (cfg.ignoreReaderNames) (
lib.concatStringsSep ":" cfg.ignoreReaderNames
);
PCSCLITE_FILTER_EXTEND_READER_NAMES = lib.mkIf (
cfg.extendReaderNames != null
) cfg.extendReaderNames;
};
# If the cfgFile is empty and not specified (in which case the default
# /etc/reader.conf is assumed), pcscd will happily start going through the

View File

@@ -58,23 +58,6 @@ let
Path to use for the pid file.
'';
};
template = lib.mkOption {
default = null;
type = with types; nullOr (listOf (attrsOf anything));
description =
let
upstreamDocs =
if flavour == "vault-agent" then
"https://developer.hashicorp.com/vault/docs/agent/template"
else
"https://github.com/hashicorp/consul-template/blob/main/docs/configuration.md#templates";
in
''
Template section of ${flavour}.
Refer to <${upstreamDocs}> for supported values.
'';
};
};
};

View File

@@ -31,6 +31,10 @@ let
''}
${cfg.qemu.verbatimConfig}
'';
networkConfigFile = pkgs.writeText "network.conf" ''
firewall_backend = "${cfg.firewallBackend}"
'';
dirName = "libvirt";
subDirs = list: [ dirName ] ++ map (e: "${dirName}/${e}") list;
@@ -385,6 +389,18 @@ in
Whether to configure OpenSSH to use the [SSH Proxy](https://libvirt.org/ssh-proxy.html).
'';
};
firewallBackend = mkOption {
type = types.enum [
"iptables"
"nftables"
];
default = if config.networking.nftables.enable then "nftables" else "iptables";
defaultText = lib.literalExpression "if config.networking.nftables.enable then \"nftables\" else \"iptables\"";
description = ''
The backend used to setup virtual network firewall rules.
'';
};
};
###### implementation
@@ -462,6 +478,9 @@ in
# Copy generated qemu config to libvirt directory
cp -f ${qemuConfigFile} /var/lib/${dirName}/qemu.conf
# Copy generated network config to libvirt directory
cp -f ${networkConfigFile} /var/lib/${dirName}/network.conf
# stable (not GC'able as in /nix/store) paths for using in <emulator> section of xml configs
for emulator in ${cfg.package}/libexec/libvirt_lxc ${cfg.qemu.package}/bin/qemu-kvm ${cfg.qemu.package}/bin/qemu-system-*; do
ln -s --force "$emulator" /run/${dirName}/nix-emulators/

View File

@@ -185,11 +185,9 @@ let
Refer to the
[Docker engine documentation](https://docs.docker.com/engine/network/#published-ports) for full details.
'';
example = literalExpression ''
[
"127.0.0.1:8080:9000"
]
'';
example = [
"127.0.0.1:8080:9000"
];
};
user = mkOption {
@@ -387,7 +385,9 @@ let
mkService =
name: container:
let
dependsOn = map (x: "${cfg.backend}-${x}.service") container.dependsOn;
dependsOn = lib.attrsets.mapAttrsToList (k: v: "${v.serviceName}.service") (
lib.attrsets.getAttrs container.dependsOn cfg.containers
);
escapedName = escapeShellArg name;
preStartScript = pkgs.writeShellApplication {
name = "pre-start";
@@ -539,7 +539,7 @@ let
Restart = "always";
}
// optionalAttrs (cfg.backend == "podman") {
Environment = "PODMAN_SYSTEMD_UNIT=podman-${name}.service";
Environment = "PODMAN_SYSTEMD_UNIT=%n";
Type = "notify";
NotifyAccess = "all";
Delegate = mkIf (container.podman.sdnotify == "healthy") true;

View File

@@ -9,6 +9,8 @@ let
inherit (import ../lib/testing-python.nix { inherit system pkgs; }) makeTest;
serviceName = "nginxtest"; # different on purpose to verify proper systemd unit generation
mkOCITest =
backend:
makeTest {
@@ -23,6 +25,7 @@ let
virtualisation.oci-containers = {
inherit backend;
containers.nginx = {
inherit serviceName;
image = "nginx-container";
imageStream = pkgs.dockerTools.examples.nginxStream;
ports = [ "8181:80" ];
@@ -39,7 +42,7 @@ let
# Stop systemd from killing remaining processes if ExecStop script
# doesn't work, so that proper stopping can be tested.
systemd.services."${backend}-nginx".serviceConfig.KillSignal = "SIGCONT";
systemd.services.${serviceName}.serviceConfig.KillSignal = "SIGCONT";
};
};
@@ -47,11 +50,11 @@ let
import json
start_all()
${backend}.wait_for_unit("${backend}-nginx.service")
${backend}.wait_for_unit("${serviceName}.service")
${backend}.wait_for_open_port(8181)
${backend}.wait_until_succeeds("curl -f http://localhost:8181 | grep Hello")
output = json.loads(${backend}.succeed("${backend} inspect nginx --format json").strip())[0]
${backend}.succeed("systemctl stop ${backend}-nginx.service", timeout=10)
${backend}.succeed("systemctl stop ${serviceName}.service", timeout=10)
assert output['HostConfig']['CapAdd'] == ["CAP_AUDIT_READ"]
assert output['HostConfig']['CapDrop'] == ${
if backend == "docker" then "[\"CAP_AUDIT_WRITE\"]" else "[]"
@@ -60,6 +63,9 @@ let
assert output['HostConfig']['Devices'] == [{'PathOnHost': '/dev/random', 'PathInContainer': '/dev/random', 'CgroupPermissions': '${
if backend == "docker" then "rwm" else ""
}'}]
''
+ lib.strings.optionalString (backend == "podman") ''
assert output['Config']['Labels']['PODMAN_SYSTEMD_UNIT'] == '${serviceName}.service'
'';
};

View File

@@ -0,0 +1,48 @@
{
# Basic
lib,
melpaBuild,
fetchFromGitHub,
# Updater
unstableGitUpdater,
}:
melpaBuild {
pname = "eaf-airshare";
version = "0-unstable-2023-07-11";
src = fetchFromGitHub {
owner = "emacs-eaf";
repo = "eaf-airshare";
rev = "71b4507ad5724babcf34da941a53c5a94bf7666a";
hash = "sha256-jpODlbg/luuCuDOayBqhVCF3vXww2FolYLniykeZr6E=";
};
files = ''
("*.el"
"*.py")
'';
passthru = {
updateScript = unstableGitUpdater { };
eafPythonDeps =
ps:
with ps;
[
qrcode
]
++ ps.qrcode.optional-dependencies.pil;
eafOtherDeps = [ ];
};
meta = {
description = "Share text by qr-code in Emacs";
homepage = "https://github.com/emacs-eaf/eaf-airshare";
license = lib.licenses.gpl3Only;
maintainers = with lib.maintainers; [
thattemperature
];
};
}

View File

@@ -411,8 +411,8 @@ let
mktplcRef = {
name = "vscode-neovim";
publisher = "asvetliakov";
version = "1.18.22";
hash = "sha256-nSRZGRhqRO52dx3QfSJZR5uVNVaxw0mcH/JBFyrUGKA=";
version = "1.18.23";
hash = "sha256-x8amgtsyWMtlV4lHgr0rfBAYzVMpQGzyBqMVTV8hs60=";
};
meta = {
changelog = "https://marketplace.visualstudio.com/items/asvetliakov.vscode-neovim/changelog";
@@ -1183,8 +1183,8 @@ let
mktplcRef = {
name = "vscode-database-client2";
publisher = "cweijan";
version = "8.3.6";
hash = "sha256-DHI5Cor6iYAB5RPMEOIoV5NX8sqkEwQI5hDwKF1m+oY=";
version = "8.3.7";
hash = "sha256-SqgCXR6LXy1lSc2fRhRsB7QSqKngRB4ypdPlXt3OOx4=";
};
meta = {
description = "Database Client For Visual Studio Code";
@@ -2033,8 +2033,8 @@ let
mktplcRef = {
publisher = "github";
name = "vscode-pull-request-github";
version = "0.114.3";
hash = "sha256-ZrutAYL0HphkSDh2BRA4wZUA/s1Uf6IvPWs4dfqfEDk=";
version = "0.116.0";
hash = "sha256-nkK5Mli1dz/zsSkE1YtLyOeokgUYrGqbwuniy3vPlWU=";
};
meta = {
license = lib.licenses.mit;
@@ -4580,8 +4580,8 @@ let
mktplcRef = {
name = "svelte-vscode";
publisher = "svelte";
version = "109.10.0";
hash = "sha256-Rpzcf0ioM7faDWG1xcEuz6GNzU1lHZsGxGgaKwC8SKk=";
version = "109.10.1";
hash = "sha256-nkQ+ianTCMGWKy5NfnuXSWcR7xi6+KkbMCK075nXluE=";
};
meta = {
changelog = "https://github.com/sveltejs/language-tools/releases";

View File

@@ -7,8 +7,8 @@ vscode-utils.buildVscodeMarketplaceExtension {
mktplcRef = {
name = "claude-dev";
publisher = "saoudrizwan";
version = "3.20.5";
hash = "sha256-sxByZXSNuxVrW4WWKvNCmR2SZ6tR5CDxGXdLyHoegwc=";
version = "3.23.0";
hash = "sha256-WIohL7kd6AGgSmstTkLjF0QL1WShQqBnUDyU5reiB/8=";
};
meta = {

View File

@@ -145,10 +145,7 @@ stdenv.mkDerivation (
};
meta = meta // {
description = ''
Wrapped variant of ${pname} which launches in a FHS compatible environment.
Should allow for easy usage of extensions without nix-specific modifications.
'';
description = "Wrapped variant of ${pname} which launches in a FHS compatible environment, should allow for easy usage of extensions without nix-specific modifications";
};
};
in
@@ -277,27 +274,28 @@ stdenv.mkDerivation (
ln -s "$out/Applications/${longName}.app/Contents/Resources/app/bin/${sourceExecutableName}" "$out/bin/${executableName}"
''
else
''
mkdir -p "$out/lib/${libraryName}" "$out/bin"
cp -r ./* "$out/lib/${libraryName}"
ln -s "$out/lib/${libraryName}/bin/${sourceExecutableName}" "$out/bin/${executableName}"
(
''
mkdir -p "$out/lib/${libraryName}" "$out/bin"
cp -r ./* "$out/lib/${libraryName}"
ln -s "$out/lib/${libraryName}/bin/${sourceExecutableName}" "$out/bin/${executableName}"
''
# These are named vscode.png, vscode-insiders.png, etc to match the name in upstream *.deb packages.
mkdir -p "$out/share/pixmaps"
cp "$out/lib/${libraryName}/resources/app/resources/linux/code.png" "$out/share/pixmaps/${iconName}.png"
''
+ ''
mkdir -p "$out/share/pixmaps"
cp "$out/lib/${libraryName}/resources/app/resources/linux/code.png" "$out/share/pixmaps/${iconName}.png"
''
)
# Override the previously determined VSCODE_PATH with the one we know to be correct
+ (lib.optionalString patchVSCodePath ''
# Override the previously determined VSCODE_PATH with the one we know to be correct
sed -i "/ELECTRON=/iVSCODE_PATH='$out/lib/${libraryName}'" "$out/bin/${executableName}"
grep -q "VSCODE_PATH='$out/lib/${libraryName}'" "$out/bin/${executableName}" # check if sed succeeded
'')
# Remove native encryption code, as it derives the key from the executable path which does not work for us.
# The credentials should be stored in a secure keychain already, so the benefit of this is questionable
# in the first place.
+ ''
# Remove native encryption code, as it derives the key from the executable path which does not work for us.
# The credentials should be stored in a secure keychain already, so the benefit of this is questionable
# in the first place.
rm -rf $out/lib/${libraryName}/resources/app/node_modules/vscode-encrypt
''
)
@@ -312,9 +310,11 @@ stdenv.mkDerivation (
lib.optionalString stdenv.hostPlatform.isLinux
"--prefix LD_LIBRARY_PATH : ${lib.makeLibraryPath [ libdbusmenu ]}"
}
# Add gio to PATH so that moving files to the trash works when not using a desktop environment
''
# Add gio to PATH so that moving files to the trash works when not using a desktop environment
+ ''
--prefix PATH : ${glib.bin}/bin
--add-flags "\''${NIXOS_OZONE_WL:+\''${WAYLAND_DISPLAY:+--ozone-platform-hint=auto --enable-features=WaylandWindowDecorations --enable-wayland-ime=true}}"
--add-flags "\''${NIXOS_OZONE_WL:+\''${WAYLAND_DISPLAY:+--ozone-platform-hint=auto --enable-features=WaylandWindowDecorations --enable-wayland-ime=true --wayland-text-input-version=3}}"
--add-flags ${lib.escapeShellArg commandLineArgs}
)
'';
@@ -322,22 +322,25 @@ stdenv.mkDerivation (
# See https://github.com/NixOS/nixpkgs/issues/49643#issuecomment-873853897
# linux only because of https://github.com/NixOS/nixpkgs/issues/138729
postPatch =
lib.optionalString stdenv.hostPlatform.isLinux ''
# this is a fix for "save as root" functionality
packed="resources/app/node_modules.asar"
unpacked="resources/app/node_modules"
asar extract "$packed" "$unpacked"
substituteInPlace $unpacked/@vscode/sudo-prompt/index.js \
--replace "/usr/bin/pkexec" "/run/wrappers/bin/pkexec" \
--replace "/bin/bash" "${bash}/bin/bash"
rm -rf "$packed"
# this is a fix for "save as root" functionality
lib.optionalString stdenv.hostPlatform.isLinux (
''
packed="resources/app/node_modules.asar"
unpacked="resources/app/node_modules"
asar extract "$packed" "$unpacked"
substituteInPlace $unpacked/@vscode/sudo-prompt/index.js \
--replace-fail "/usr/bin/pkexec" "/run/wrappers/bin/pkexec" \
--replace-fail "/bin/bash" "${bash}/bin/bash"
rm -rf "$packed"
''
# without this symlink loading JsChardet, the library that is used for auto encoding detection when files.autoGuessEncoding is true,
# fails to load with: electron/js2c/renderer_init: Error: Cannot find module 'jschardet'
# and the window immediately closes which renders VSCode unusable
# see https://github.com/NixOS/nixpkgs/issues/152939 for full log
ln -rs "$unpacked" "$packed"
''
+ ''
ln -rs "$unpacked" "$packed"
''
)
+ (
let
vscodeRipgrep =

View File

@@ -26,11 +26,11 @@ let
hash =
{
x86_64-linux = "sha256-Tl2/EIGvSZM5OrMBOHlFXGR1XkllJLBq7+noZZA+UAk=";
x86_64-darwin = "sha256-46l0YmqWtHkVbJtZfW6mdmBQFQ2bf2wxJXu0Gjnj+oU=";
aarch64-linux = "sha256-Q143KRaaXGZ8RlxBGecZMqfjo3896LlhCBFYhpdfd+0=";
aarch64-darwin = "sha256-m/QDmjO3oxklN/8hkLoa6Hm8zeUQ0s+iUyyqY5TrYMY=";
armv7l-linux = "sha256-zkE5tr6BLcATBJU2y+hqEGKhVI6oB0Pe8Vi14MYkWno=";
x86_64-linux = "sha256-8gOAcyG1gPLK7YLBMgdKJbyF32gbm7mFa4oXJPQIWUI=";
x86_64-darwin = "sha256-r9+PYN/1QFviNobsN/cmU7icXqoYYUXx7tVqqfsJgEw=";
aarch64-linux = "sha256-3O3tNOiF77W1uNX6XxiCMy8CCowCPyimPLaQ0m73Ej4=";
aarch64-darwin = "sha256-NpIC4KM+BUyzsjvgLjIMXkfgEvKqz67P0tNoMd0vsMA=";
armv7l-linux = "sha256-GIRyfhGMBALf/bvKAKIm6DgyL9o50CEgXhKFNegLfd4=";
}
.${system} or throwSystem;
@@ -41,7 +41,7 @@ callPackage ./generic.nix rec {
# Please backport all compatible updates to the stable release.
# This is important for the extension ecosystem.
version = "1.102.35058";
version = "1.103.05312";
pname = "vscodium";
executableName = "codium";

View File

@@ -1,11 +1,11 @@
{
"packageVersion": "141.0.2-1",
"packageVersion": "141.0.3-1",
"source": {
"rev": "141.0.2-1",
"hash": "sha256-M4RQcpIk4jjcSUFwMI5fPi7frMOEM4+FSpbqNiXxOVc="
"rev": "141.0.3-1",
"hash": "sha256-0SosHE51IkDyg37fHnlJKn7IbMwr1iSXHr5Wuv2WkPg="
},
"firefox": {
"version": "141.0.2",
"hash": "sha512-bRVSvGTZFeeEpdVgyLs1pTCPNevNJVKwJ/gPlQx/DGJ8ykaweWz24X2PUMgub3Cj7BFHHODgWHlPUAt7FeF7Qw=="
"version": "141.0.3",
"hash": "sha512-tmCwGIQMQaJUc0tIR6eR8an9L3Lb6oJepZcf0LMmmkPx9L4cz0pT94Cba5g5j04EoULlf4iC1lkLq2Nu91AC9g=="
}
}

View File

@@ -9,14 +9,14 @@ let
callPackage
(import ./generic.nix rec {
pname = "apptainer";
version = "1.4.1";
version = "1.4.2";
projectName = "apptainer";
src = fetchFromGitHub {
owner = "apptainer";
repo = "apptainer";
tag = "v${version}";
hash = "sha256-1deSlDNk8ZI/z1eWmslesXO0ypCoMxCJMdihFPCSPIc=";
hash = "sha256-xa35HhziEUzuNIKT1h/nOXjV5/UYkbFlJcZMApaIGfQ=";
};
# Override vendorHash with overrideAttrs.

View File

@@ -251,7 +251,7 @@ dotnetFromEnv'
local wrapperFlags=()
if (( ${#runtimeDeps[@]} > 0 )); then
local libraryPath=("${dotnetRuntimeDeps[@]/%//lib}")
local libraryPath=("${runtimeDeps[@]/%//lib}")
local OLDIFS="$IFS" IFS=':'
wrapperFlags+=("--suffix" "LD_LIBRARY_PATH" ":" "${libraryPath[*]}")
IFS="$OLDIFS"

View File

@@ -0,0 +1,58 @@
{
lib,
stdenv,
alsa-utils,
installShellFiles,
}:
stdenv.mkDerivation (finalAttrs: {
pname = "alsa-utils-nhlt";
inherit (alsa-utils) version src;
outputs = [
"out"
"man"
];
nativeBuildInputs = [ installShellFiles ];
# The configure script insists on various headers and libraries from
# alsa-lib and cannot be convinced to forego the respective checks. To
# avoid dependency on alsa-lib we therefore circumvent the usual build
# flow and compile the source directly.
dontConfigure = true;
postPatch = ''
# The aconfig.h header is normally generated by the configure script and
# even though included it is not actually used. Drop in an empty dummy
# header.
touch nhlt/aconfig.h
'';
buildPhase = ''
runHook preBuild
# Compile flags -g -O2 mirroring configure script.
$CC -g -O2 -o nhlt-dmic-info nhlt/nhlt-dmic-info.c
runHook postBuild
'';
installPhase = ''
runHook preInstall
installBin nhlt-dmic-info
installManPage nhlt/nhlt-dmic-info.1
runHook postInstall
'';
meta = {
description = "Tool to extract microphone array information from ACPI NHLT table";
homepage = "http://www.alsa-project.org/";
license = lib.licenses.gpl2Plus;
maintainers = with lib.maintainers; [ mvs ];
mainProgram = "nhlt-dmic-info";
platforms = lib.platforms.linux;
};
})

View File

@@ -11,11 +11,11 @@
stdenv.mkDerivation rec {
pname = "armadillo";
version = "14.6.1";
version = "14.6.2";
src = fetchurl {
url = "mirror://sourceforge/arma/armadillo-${version}.tar.xz";
hash = "sha256-vsZ/No/GFnPEyelCnSATWkK6gKLH+FkrkS5fl+KJv8A=";
hash = "sha256-Sd23ZnCx0aFC92BjfmU+xbILpzDnYwovPCsT0yTDfgg=";
};
nativeBuildInputs = [ cmake ];

View File

@@ -902,8 +902,8 @@
},
{
"pname": "Microsoft.WindowsDesktop.App.Ref",
"version": "8.0.18",
"hash": "sha256-cuCPcAp4jRFR44Z7Ib9oFxzKTKEVD9zKchNlA6Z2OfA="
"version": "8.0.19",
"hash": "sha256-rbNLx37nzGSoBNXyL1TadcKtI3SUAZ9x8e6NUMYU6hI="
},
{
"pname": "Mono.Cecil",

View File

@@ -46,14 +46,14 @@ stdenvNoCC.mkDerivation (
}
rec {
pname = "Avalonia";
version = "11.3.2";
version = "11.3.3";
src = fetchFromGitHub {
owner = "AvaloniaUI";
repo = "Avalonia";
tag = version;
fetchSubmodules = true;
hash = "sha256-b7K8h2hqkLnXj3YIaRKUqlbWsDNhfWCEqH1W8K0lP6g=";
hash = "sha256-+u0VCUqGT6D84GdApkThJB295nHIZInRtPFWr9UOsFk=";
};
patches = [

View File

@@ -7,16 +7,16 @@
buildGoModule rec {
pname = "civo";
version = "1.4.1";
version = "1.4.2";
src = fetchFromGitHub {
owner = "civo";
repo = "cli";
rev = "v${version}";
hash = "sha256-KwzQnjLmss8udSCKncoASZlO+G9ch7pZp6Iql+YV1nQ=";
hash = "sha256-U//qnxLD4DR6hIUJBIYtkbUkXVmIiHxLfTeza+bTYL4=";
};
vendorHash = "sha256-jW1pJ/UmeFsIEVvrwxcQuWwPQFHYkJBFnxGei41pz2U=";
vendorHash = "sha256-TsaGXDUTvTsfDIBhM9+JwL2swEw/qSivn3NTA0tWkZw=";
nativeBuildInputs = [ installShellFiles ];

View File

@@ -8,13 +8,13 @@
buildGoModule rec {
pname = "croc";
version = "10.2.3";
version = "10.2.4";
src = fetchFromGitHub {
owner = "schollz";
repo = "croc";
rev = "v${version}";
hash = "sha256-PuU60Ybiz/6ajJ67lntyq3e3ZPuxNKmM5iCPTRkldrs=";
hash = "sha256-iC2Yki8RN+csvNvIQP65bAIN1Q0KR5DUIiZqEVZqG+o=";
};
vendorHash = "sha256-bFn2C5py2STLz8YBlnyK2XDBlgoBnXujeBizN9cDTI0=";

View File

@@ -92,12 +92,12 @@ let
'';
in
stdenv.mkDerivation rec {
version = "5.2.0";
version = "5.2.1";
pname = "darktable";
src = fetchurl {
url = "https://github.com/darktable-org/darktable/releases/download/release-${version}/darktable-${version}.tar.xz";
hash = "sha256-U6Rs1G73EYSFxKv0q0B8GBY5u4Y0JD7A7R98HoKZvsY=";
hash = "sha256-AvGqmuk5See8VMNO61/5LCuH+V0lR4Zd9VxgRnVk7hE=";
};
nativeBuildInputs = [

View File

@@ -12,7 +12,7 @@
nixosTests,
}:
let
version = "4.13.2";
version = "4.13.3";
frontend = buildNpmPackage {
pname = "dependency-track-frontend";
@@ -25,7 +25,7 @@ let
owner = "DependencyTrack";
repo = "frontend";
rev = version;
hash = "sha256-HshphdOvJMRdMWYNc+nOkoFGA9Rr+N7+Gs8THBZjKTM=";
hash = "sha256-I6vR4FCVxyoNlj/iPopEJn98jsJWt4rGZZXS+iPDcmI=";
};
installPhase = ''
@@ -33,7 +33,7 @@ let
cp -R ./dist $out/
'';
npmDepsHash = "sha256-u5yVJlW9LhptyHQddd1RCBgU/xNdSNX5FAmSEj6n7Ng=";
npmDepsHash = "sha256-t+FPHb+OzavTUXjNw75EuFOuHmv8fQYqRQrUnF2zDXw=";
forceGitDeps = true;
makeCacheWritable = true;
@@ -50,7 +50,7 @@ maven.buildMavenPackage rec {
owner = "DependencyTrack";
repo = "dependency-track";
rev = version;
hash = "sha256-4A34lt6M0M1+HPGFFqH/Ik07FBNz6pI0XYiW9rIVsOk=";
hash = "sha256-9kkWb1YfUANoVAb9mnLkmVswE4f+YdEtd5aPEP+TRFo=";
};
patches = [
@@ -65,7 +65,7 @@ maven.buildMavenPackage rec {
'';
mvnJdk = jre_headless;
mvnHash = "sha256-V0EhfPN8htR4v/KQpQ9tec6dAe/FOxBCp8cUZqL7mFo=";
mvnHash = "sha256-jsS8/xfvoowzcym3cxv9L5rYSr8YezPEQaUofs7yxUI=";
manualMvnArtifacts = [ "com.coderplus.maven.plugins:copy-rename-maven-plugin:1.0.1" ];
buildOffline = true;

View File

@@ -1,3 +1,3 @@
{
"yarn_offline_cache_hash": "sha256-M0K26W917xtv2KxyATI2pCsyDo8ybjiFqLHPlXY9c8g="
"yarn_offline_cache_hash": "sha256-sHvkDzOoRo9Lz4ynNX5vrejOwKBVIzJeVqJzs8M39vA="
}

View File

@@ -1,6 +1,6 @@
{
"name": "draupnir",
"version": "2.5.0",
"version": "2.5.1",
"description": "A moderation tool for Matrix",
"main": "lib/index.js",
"repository": "https://github.com/the-draupnir-project/Draupnir.git",
@@ -52,7 +52,7 @@
"@sentry/node": "^7.17.2",
"@sinclair/typebox": "0.34.13",
"@the-draupnir-project/interface-manager": "4.1.0",
"@the-draupnir-project/matrix-basic-types": "1.3.0",
"@the-draupnir-project/matrix-basic-types": "1.4.0",
"@the-draupnir-project/mps-interface-adaptor": "^0.4.1",
"better-sqlite3": "^9.4.3",
"body-parser": "^1.20.2",
@@ -63,15 +63,15 @@
"jsdom": "^24.0.0",
"matrix-appservice-bridge": "^10.3.1",
"matrix-bot-sdk": "npm:@vector-im/matrix-bot-sdk@^0.7.1-element.6",
"matrix-protection-suite": "npm:@gnuxie/matrix-protection-suite@3.7.1",
"matrix-protection-suite-for-matrix-bot-sdk": "npm:@gnuxie/matrix-protection-suite-for-matrix-bot-sdk@3.6.6",
"matrix-protection-suite": "npm:@gnuxie/matrix-protection-suite@3.8.0",
"matrix-protection-suite-for-matrix-bot-sdk": "npm:@gnuxie/matrix-protection-suite-for-matrix-bot-sdk@3.8.0",
"pg": "^8.8.0",
"yaml": "^2.3.2"
},
"overrides": {
"matrix-bot-sdk": "$@vector-im/matrix-bot-sdk",
"@vector-im/matrix-bot-sdk": "npm:@vector-im/matrix-bot-sdk@^0.7.1-element.6",
"@the-draupnir-project/matrix-basic-types": "@the-draupnir-project/matrix-basic-types@1.2.0",
"@the-draupnir-project/matrix-basic-types": "$the-draupnir-project/matrix-basic-types",
"matrix-protection-suite": "$matrix-protection-suite"
},
"engines": {

View File

@@ -22,13 +22,13 @@ let
in
mkYarnPackage rec {
pname = "draupnir";
version = "2.5.0";
version = "2.5.1";
src = fetchFromGitHub {
owner = "the-draupnir-project";
repo = "Draupnir";
tag = "v${version}";
hash = "sha256-au0qYS646MAXyfQTk6gJem3geTecgDwzZl+87/6VE5A=";
hash = "sha256-fk9V5ZOnu9gHL7GnZ2eTCon/dINTTkWffRdMRj9AjPk=";
};
nativeBuildInputs = [

View File

@@ -11,14 +11,14 @@
stdenv.mkDerivation (finalAttrs: {
pname = "feedbackd-device-themes";
version = "0.8.4";
version = "0.8.5";
src = fetchFromGitLab {
domain = "gitlab.freedesktop.org";
owner = "agx";
repo = "feedbackd-device-themes";
rev = "v${finalAttrs.version}";
hash = "sha256-eLR1BnPpIdo6udQsLcLn4hK2TTRYUIh5vwAg+rdMLKU=";
hash = "sha256-Uj6EEE8EQeHG2Z3tMc7UmTlr6td5YhOBAdWpFnFSKE4=";
};
nativeBuildInputs = [

View File

@@ -27,7 +27,7 @@
stdenv.mkDerivation (finalAttrs: {
pname = "feedbackd";
version = "0.8.3";
version = "0.8.4";
outputs = [
"out"
@@ -40,7 +40,7 @@ stdenv.mkDerivation (finalAttrs: {
owner = "agx";
repo = "feedbackd";
rev = "v${finalAttrs.version}";
hash = "sha256-ypKD9n9dC+0J+HFtL43mCky/ZXu4bgejYzw7nHHPAm4=";
hash = "sha256-9UBrexS7zNxFUB/K1I5ZO78OjGAshCAABZQyc0lBLlQ=";
};
depsBuildBuild = [

View File

@@ -65,12 +65,12 @@
let
sources = {
x86_64-linux = fetchurl {
url = "https://sf3-cn.feishucdn.com/obj/ee-appcenter/91e64286/Feishu-linux_x64-7.42.17.deb";
sha256 = "sha256-Rsq+xQAyi7I1WcnkXzhPEgbUyfXU9XPVKIuv6Z9H5VA=";
url = "https://sf3-cn.feishucdn.com/obj/ee-appcenter/fc10b1c0/Feishu-linux_x64-7.46.11.deb";
sha256 = "sha256-xcTSyRoRGlXn++KRmXtqNBI6diY00v0UUZe3RxCewFk=";
};
aarch64-linux = fetchurl {
url = "https://sf3-cn.feishucdn.com/obj/ee-appcenter/49127814/Feishu-linux_arm64-7.42.17.deb";
sha256 = "sha256-UykQk8R8EDsHmRGy9BfDXhEZFlYT16bAkRuLXFZJDHw=";
url = "https://sf3-cn.feishucdn.com/obj/ee-appcenter/ccc36dfd/Feishu-linux_arm64-7.46.11.deb";
sha256 = "sha256-pOA1WAhkIFn4H9sZye6ges2U5DvDDmLAOllD5qAklmg=";
};
};
@@ -133,7 +133,7 @@ let
];
in
stdenv.mkDerivation {
version = "7.42.17";
version = "7.46.11";
pname = "feishu";
src =

View File

@@ -28,13 +28,13 @@ let
in
rustPlatform.buildRustPackage (finalAttrs: {
pname = "fishnet";
version = "2.9.5";
version = "2.10.0";
src = fetchFromGitHub {
owner = "lichess-org";
repo = "fishnet";
tag = "v${finalAttrs.version}";
hash = "sha256-+JkqxO7wwYZHwWRMboKGe8uo/F223efR+9pIsAIoFpU=";
hash = "sha256-BtOPLqfE6SjCr8/HS5oev1j3R26+wkWw051gZwDyCM0=";
fetchSubmodules = true;
};
@@ -45,7 +45,7 @@ rustPlatform.buildRustPackage (finalAttrs: {
cp -v '${nnueSmall}' 'Fairy-Stockfish/src/${nnueSmallFile}'
'';
cargoHash = "sha256-WjBrv4GApT7LTnexLDhY7Zni5kLtvUzaGs2YuA3UiHE=";
cargoHash = "sha256-1Pk9vXo1ivE8H6ctS8PEsCEv/EKFxFtgnmrvik6Gwug=";
nativeInstallCheckInputs = [
versionCheckHook

View File

@@ -9,16 +9,16 @@
buildGoModule (finalAttrs: {
pname = "geminicommit";
version = "0.4.1";
version = "0.5.0";
src = fetchFromGitHub {
owner = "tfkhdyt";
repo = "geminicommit";
tag = "v${finalAttrs.version}";
hash = "sha256-QUI5JI1udOo3IOXegoes3pwwgSfxXIjxXIPsA5SuAJo=";
hash = "sha256-wUqu6/j9AyD/THblX0w+Wt43FK//WammB6c425pTwbc=";
};
vendorHash = "sha256-AFm+1RQ6sMSe+kY/cw1Ly/8WEj2/yk0nJQiEJzV6jKg=";
vendorHash = "sha256-4aVUD16zhzWvgD90gttmoDRoKKb0dRgDdH1HMfgd3LU=";
nativeBuildInputs = [
installShellFiles
@@ -29,8 +29,8 @@ buildGoModule (finalAttrs: {
cmd = finalAttrs.meta.mainProgram;
goDefaultCmd = finalAttrs.pname;
in
# The official github released binary is renamed since v0.4.1,
# see: https://github.com/tfkhdyt/geminicommit/releases/tag/v0.4.1
# The official github released binary is renamed since v0.5.0,
# see: https://github.com/tfkhdyt/geminicommit/releases/tag/v0.5.0
# Here we link the old name (which is also the `go build` default name)
# for backward compatibility:
''

View File

@@ -17,6 +17,14 @@ stdenvNoCC.mkDerivation (finalAttrs: {
sourceRoot = ".";
# otherwise fails to unpack with:
# ERROR: Dangerous link path was ignored : Ghostty.app/Contents/Resources/terminfo/67/ghostty : ../78/xterm-ghostty
unpackPhase = lib.optionalString stdenvNoCC.hostPlatform.isDarwin ''
runHook preUnpack
7zz -snld x $src
runHook postUnpack
'';
nativeBuildInputs = [
_7zz
makeBinaryWrapper

View File

@@ -151,6 +151,8 @@ buildDotnetModule (finalAttrs: {
disabledTests = [
"GitHub.Runner.Common.Tests.Listener.SelfUpdaterL0.TestSelfUpdateAsync"
"GitHub.Runner.Common.Tests.ProcessInvokerL0.OomScoreAdjIsInherited"
# intermittently failing
"GitHub.Runner.Common.Tests.ProcessExtensionL0.SuccessReadProcessEnv"
]
++ map (x: "GitHub.Runner.Common.Tests.Listener.SelfUpdaterL0.TestSelfUpdateAsync_${x}") [
"Cancel_CloneHashTask_WhenNotNeeded"
@@ -208,12 +210,10 @@ buildDotnetModule (finalAttrs: {
"GitHub.Runner.Common.Tests.Worker.StepHostL0.DetermineNode20RuntimeVersionInAlpineContainerAsync"
]
++ lib.optionals finalAttrs.DOTNET_SYSTEM_GLOBALIZATION_INVARIANT [
"GitHub.Runner.Common.Tests.ProcessExtensionL0.SuccessReadProcessEnv"
"GitHub.Runner.Common.Tests.Util.StringUtilL0.FormatUsesInvariantCulture"
"GitHub.Runner.Common.Tests.Worker.VariablesL0.Constructor_SetsOrdinalIgnoreCaseComparer"
"GitHub.Runner.Common.Tests.Worker.WorkerL0.DispatchCancellation"
"GitHub.Runner.Common.Tests.Worker.WorkerL0.DispatchRunNewJob"
"GitHub.Runner.Common.Tests.ProcessExtensionL0.SuccessReadProcessEnv"
];
testProjectFile = [ "src/Test/Test.csproj" ];

View File

@@ -24,11 +24,11 @@
stdenv.mkDerivation (finalAttrs: {
pname = "glycin-loaders";
version = "1.2.2";
version = "1.2.3";
src = fetchurl {
url = "mirror://gnome/sources/glycin/${lib.versions.majorMinor finalAttrs.version}/glycin-${finalAttrs.version}.tar.xz";
hash = "sha256-SrRG1YsQx2KDInplSHuLvbdLpQCentIwRfz6i6P7KGE=";
hash = "sha256-OAqv4r+07KDEW0JmDr/0SWANAKQ7YJ1bHIP3lfXI+zw=";
};
patches = [

View File

@@ -75,11 +75,11 @@
stdenv.mkDerivation (finalAttrs: {
pname = "gnome-control-center";
version = "48.3";
version = "48.4";
src = fetchurl {
url = "mirror://gnome/sources/gnome-control-center/${lib.versions.major finalAttrs.version}/gnome-control-center-${finalAttrs.version}.tar.xz";
hash = "sha256-wGmCRaZCC63Qd8Fv+yGIYORXzXMAYScY6r+aukciK64=";
hash = "sha256-KiDu5uBcjTrdru+lJNzh7p+Ip32Djj/R7e88DC5GetI=";
};
patches = [

View File

@@ -30,11 +30,11 @@
stdenv.mkDerivation (finalAttrs: {
pname = "gnome-maps";
version = "48.4";
version = "48.6";
src = fetchurl {
url = "mirror://gnome/sources/gnome-maps/${lib.versions.major finalAttrs.version}/gnome-maps-${finalAttrs.version}.tar.xz";
hash = "sha256-rocWuLCz/r0+0iwX6QYuuA9tbSXFBQHATUIwuXzuRco=";
hash = "sha256-OtqaMVUXWlGdQV8Ll9D+129PS+uLYCEqAXaXoyy+gaY=";
};
doCheck = !stdenv.hostPlatform.isDarwin;

View File

@@ -32,7 +32,7 @@
stdenv.mkDerivation (finalAttrs: {
pname = "gnome-online-accounts";
version = "3.54.4";
version = "3.54.5";
outputs = [
"out"
@@ -45,7 +45,7 @@ stdenv.mkDerivation (finalAttrs: {
src = fetchurl {
url = "mirror://gnome/sources/gnome-online-accounts/${lib.versions.majorMinor finalAttrs.version}/gnome-online-accounts-${finalAttrs.version}.tar.xz";
hash = "sha256-VXOZQ+dH3LSIXqYHpMJ2fYAC9xKV4a/+pi6jb20c9ZM=";
hash = "sha256-6PEntTIpWimRLRwAc0kx35r/pOv8RK0N5cKWw9J9LJU=";
};
mesonFlags = [

View File

@@ -69,7 +69,7 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "gnome-shell";
version = "48.3";
version = "48.4";
outputs = [
"out"
@@ -78,7 +78,7 @@ stdenv.mkDerivation (finalAttrs: {
src = fetchurl {
url = "mirror://gnome/sources/gnome-shell/${lib.versions.major finalAttrs.version}/gnome-shell-${finalAttrs.version}.tar.xz";
hash = "sha256-+wID/HSFk/FOUXMmGOHwQlJf1xl2Sg/bDuP2/kE6mys=";
hash = "sha256-QOLtdLRTZ/DKOPv6oKtHCGjSNZHQPcQNCr1v930jtwc=";
};
patches = [

View File

@@ -48,11 +48,11 @@ in
stdenv.mkDerivation (finalAttrs: {
pname = "gnome-software";
version = "48.3";
version = "48.4";
src = fetchurl {
url = "mirror://gnome/sources/gnome-software/${lib.versions.major finalAttrs.version}/gnome-software-${finalAttrs.version}.tar.xz";
hash = "sha256-Emlx6LwADdwgAXjI+sj3EU7tQt5KTiASugaz/+cH4jo=";
hash = "sha256-nNEwvGLNCLY6Ii6yZmG8xxfnXVjuGzwYgMTRt2zNJjs=";
};
patches = [

View File

@@ -0,0 +1,97 @@
{
lib,
stdenv,
fetchFromGitHub,
cmake,
ninja,
python3,
validatePkgConfig,
versionCheckHook,
testers,
nix-update-script,
enableCmdline ? !stdenv.hostPlatform.isNone,
enableMath ? false,
}:
stdenv.mkDerivation (finalAttrs: {
pname = "jerryscript";
version = "3.0.0";
outputs = [
"out"
"lib"
"dev"
];
src = fetchFromGitHub {
owner = "jerryscript-project";
repo = "jerryscript";
tag = "v${finalAttrs.version}";
hash = "sha256-Evu4qLlwg3Sf9w/ojtZMNxGJEtopHgKnwqlpf115zD4=";
};
nativeBuildInputs = [
cmake
ninja
];
cmakeFlags = [
(lib.cmakeBool "JERRY_CMDLINE" enableCmdline)
(lib.cmakeBool "JERRY_MATH" enableMath)
(lib.cmakeBool "BUILD_SHARED_LIBS" (!stdenv.hostPlatform.isStatic))
];
nativeCheckInputs = [
python3
];
doCheck = true;
checkPhase = ''
runHook preCheck
pushd ../
python3 tools/run-tests.py --unittests
popd
runHook postCheck
'';
# Uses a custom lib variable that ignores what nixpkgs's cmake setupHook specifies.
postInstall = ''
mkdir -p "$lib/lib"
mv "$out/lib/"*.so "$lib/lib"
'';
nativeInstallCheckInputs = [
validatePkgConfig
versionCheckHook
];
doInstallCheck = true;
postInstallCheck = ''
echo 'print("Hello" + " " + "World!")' | \
"$out/bin/jerry" - | \
cmp - <(echo "Hello World!")
'';
passthru = {
tests.pkg-config = testers.hasPkgConfigModules {
package = finalAttrs.finalPackage;
versionCheck = true;
};
updateScript = nix-update-script { };
};
meta = {
description = "Lightweight JavaScript engine for resource-constrained devices";
homepage = "https://jerryscript.net/";
downloadPage = "https://github.com/jerryscript-project/jerryscript/";
changelog = "https://github.com/jerryscript-project/jerryscript/releases/tag/v${finalAttrs.version}";
license = lib.licenses.asl20;
mainProgram = "jerry";
pkgConfigModules = [
"libjerry-core"
"libjerry-ext"
"libjerry-port"
];
maintainers = with lib.maintainers; [ RossSmyth ];
};
})

View File

@@ -10,7 +10,7 @@
let
pname = "jetbrains-toolbox";
version = "2.7.0.48109";
version = "2.8.0.51430";
updateScript = ./update.sh;
@@ -55,10 +55,10 @@ let
aarch64 = "-arm64";
};
hash = selectSystem {
x86_64-linux = "sha256-ZEtkWKKX4XAd8LujuVVy+lFcgqhhxkEh6F75vl2hRgs=";
aarch64-linux = "sha256-qAftn6bx8JUtym37PNFsxnyt3twSxWsewKA/XDU/WeY=";
x86_64-darwin = "sha256-OVg4qDhoHN2eV3grPjM33fzXxw1tI4rA+T/3vDGuLHc=";
aarch64-darwin = "sha256-/MjoMH06m4aXesKr2VKoiDlhyWlA5MIlYJdqjBcxTnA=";
x86_64-linux = "sha256-f/pAYcITnJUDvWmIdYsgMdVwN5Je3V1SWdSyoyLMUuc=";
aarch64-linux = "sha256-ocASvocUeQtZlrxwHqImk6rLk/XvxreaRIPwnb8ZWuc=";
x86_64-darwin = "sha256-u/7ebU3oj8ZPnLRS0AiTMZHcTh5dCJmDLkjESOE9TyI=";
aarch64-darwin = "sha256-gHbtrvWyTsiOBJIHR5uqyj1C/nBB6KANivM3lezkauQ=";
};
in
selectKernel {

View File

@@ -0,0 +1,53 @@
{
stdenv,
fetchzip,
lib,
makeWrapper,
jre,
stripJavaArchivesHook,
versionCheckHook,
}:
stdenv.mkDerivation (finalAttrs: {
pname = "jib-cli";
version = "0.13.0";
src = fetchzip {
url = "https://github.com/GoogleContainerTools/jib/releases/download/v${finalAttrs.version}-cli/jib-jre-${finalAttrs.version}.zip";
hash = "sha256-3/wKpwVHVBU86GJfR4YGM5ba8pOOfLL+fKU7zwwU+Qc=";
};
nativeBuildInputs = [
makeWrapper
stripJavaArchivesHook
];
nativeInstallCheckInputs = [ versionCheckHook ];
buildInputs = [ jre ];
dontBuild = true;
doInstallCheck = true;
versionCheckProgram = "${placeholder "out"}/bin/jib";
installPhase = ''
runHook preInstall
mkdir -p $out
cp -r lib $out/
jarPaths=$(find $out/lib -name '*.jar' | tr '\n' ':' | sed 's/:$//')
makeWrapper ${jre}/bin/java $out/bin/jib \
--add-flags "-cp \"$jarPaths\" com.google.cloud.tools.jib.cli.JibCli"
runHook postInstall
'';
meta = {
description = "Container image builder for Java using Jib CLI";
homepage = "https://github.com/GoogleContainerTools/jib";
license = lib.licenses.asl20;
maintainers = with lib.maintainers; [
sxmair
];
mainProgram = "jib";
sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ];
};
})

View File

@@ -8,11 +8,11 @@
let
pname = "ledger-live-desktop";
version = "2.122.1";
version = "2.124.0";
src = fetchurl {
url = "https://download.live.ledger.com/${pname}-${version}-linux-x86_64.AppImage";
hash = "sha256-Cy74WFxNX5cJhkx3FmiIgCLoWFos2BXntl6mEeK6MQ8=";
hash = "sha256-aB9WFfGSdrIaBpOL7qqomfCqYIIsTeCch2fkta4M9RM=";
};
appimageContents = appimageTools.extractType2 {

View File

@@ -33,6 +33,6 @@ stdenv.mkDerivation rec {
mainProgram = "gen-ctl-io";
homepage = "https://github.com/NanoComp/libctl";
license = licenses.gpl2Only;
maintainers = with maintainers; [ carpinchomug ];
maintainers = [ ];
};
}

View File

@@ -24,14 +24,14 @@
}:
stdenv.mkDerivation (finalAttrs: {
pname = "libglycin";
version = "1.2.2";
version = "1.2.3";
src = fetchFromGitLab {
domain = "gitlab.gnome.org";
owner = "GNOME";
repo = "glycin";
tag = finalAttrs.version;
hash = "sha256-K+cR+0a/zRpOvMsX1ZljjJYYOXbHkyDGE9Q9vY1qJBg=";
hash = "sha256-O7Z7kzC0BU7FAF1UZC6LbXVIXPDertsAUNYwHAjkzPI=";
};
nativeBuildInputs = [
@@ -49,7 +49,7 @@ stdenv.mkDerivation (finalAttrs: {
cargoDeps = rustPlatform.fetchCargoVendor {
inherit (finalAttrs) pname version src;
hash = "sha256-zGDmmRbaR2boaf9lLzvW/H7xgMo9uHTmlC0oNupLUos=";
hash = "sha256-g2tsQ6q+sUxn3itu3IgZ5EGtDorPzhaO5B1hlEW5xzs=";
};
buildInputs = [

View File

@@ -63,13 +63,13 @@ rustPlatform.buildRustPackage (finalAttrs: {
postPatch = ''
substituteInPlace crates/config/src/sections/http.rs \
--replace ./frontend/dist/ "$out/share/$pname/assets/"
--replace-fail ./share/assets/ "$out/share/$pname/assets/"
substituteInPlace crates/config/src/sections/templates.rs \
--replace ./share/templates/ "$out/share/$pname/templates/" \
--replace ./share/translations/ "$out/share/$pname/translations/" \
--replace ./share/manifest.json "$out/share/$pname/assets/manifest.json"
--replace-fail ./share/templates/ "$out/share/$pname/templates/" \
--replace-fail ./share/translations/ "$out/share/$pname/translations/" \
--replace-fail ./share/manifest.json "$out/share/$pname/assets/manifest.json"
substituteInPlace crates/config/src/sections/policy.rs \
--replace ./share/policy.wasm "$out/share/$pname/policy.wasm"
--replace-fail ./share/policy.wasm "$out/share/$pname/policy.wasm"
'';
preBuild = ''
@@ -77,9 +77,10 @@ rustPlatform.buildRustPackage (finalAttrs: {
(cd "$npmRoot" && npm run build)
'';
# Adopted from https://github.com/element-hq/matrix-authentication-service/blob/main/Dockerfile
# Adapted from https://github.com/element-hq/matrix-authentication-service/blob/v0.20.0/.github/workflows/build.yaml#L75-L84
postInstall = ''
install -Dm444 -t "$out/share/$pname" "policies/policy.wasm"
install -Dm444 -t "$out/share/$pname" "$npmRoot/dist/manifest.json"
install -Dm444 -t "$out/share/$pname/assets" "$npmRoot/dist/"*
cp -r templates "$out/share/$pname/templates"
cp -r translations "$out/share/$pname/translations"

View File

@@ -30,6 +30,8 @@ buildGoModule rec {
"list-deduplicated-blocks"
"listblocks"
"mark-blocks"
"splitblocks"
"tenant-injector"
"undelete-blocks"
]);

View File

@@ -39,7 +39,7 @@ rustPlatform.buildRustPackage (finalAttrs: {
];
buildInputs = lib.optionals enableNixImport [
nixVersions.nix_2_24
nixVersions.nix_2_28
boost
];

View File

@@ -17,13 +17,13 @@
}:
stdenv.mkDerivation (finalAttrs: {
pname = "nugget-doom";
version = "4.3.0";
version = "4.4.0";
src = fetchFromGitHub {
owner = "MrAlaux";
repo = "Nugget-Doom";
tag = "nugget-doom-${finalAttrs.version}";
hash = "sha256-T85UwCl75/RPOscfcRVlF3HhjlDVM2+W1L002UGNLZU=";
hash = "sha256-Egk4Tx0qFC++r/Bubr1N+lxAfjyDkRmrZKwf09ZD+Kk=";
};
nativeBuildInputs = [
@@ -53,7 +53,7 @@ stdenv.mkDerivation (finalAttrs: {
meta = {
description = "Doom source port forked from Woof! with additional features";
homepage = "https://github.com/MrAlaux/Nugget-Doom";
changelog = "https://github.com/fabiangreffrath/woof/blob/${finalAttrs.src.rev}/CHANGELOG.md";
changelog = "https://github.com/MrAlaux/Nugget-Doom/blob/${finalAttrs.src.rev}/CHANGELOG.md";
license = lib.licenses.gpl2Plus;
maintainers = with lib.maintainers; [ bandithedoge ];
mainProgram = "nugget-doom";

View File

@@ -1,6 +1,6 @@
source 'https://rubygems.org'
gem 'oxidized', '0.33.0'
gem 'oxidized-web', '0.16.0'
gem 'oxidized', '0.34.3'
gem 'oxidized-web', '0.17.1'
gem 'oxidized-script', '0.7.0'
gem 'psych', '~> 5.0'

View File

@@ -2,11 +2,10 @@ GEM
remote: https://rubygems.org/
specs:
asetus (0.4.0)
base64 (0.2.0)
base64 (0.3.0)
bcrypt_pbkdf (1.1.1)
bcrypt_pbkdf (1.1.1-arm64-darwin)
bcrypt_pbkdf (1.1.1-x86_64-darwin)
charlock_holmes (0.7.9)
concurrent-ruby (1.3.5)
date (3.4.1)
ed25519 (1.4.0)
emk-sinatra-url-for (0.2.1)
@@ -16,10 +15,10 @@ GEM
thor
tilt
htmlentities (4.3.4)
json (2.12.0)
json (2.13.2)
logger (1.7.0)
multi_json (1.15.0)
mustermann (3.0.3)
multi_json (1.17.0)
mustermann (3.0.4)
ruby2_keywords (~> 0.0.1)
net-ftp (0.3.8)
net-protocol
@@ -32,8 +31,7 @@ GEM
net-ssh (7.3.0)
net-telnet (0.2.0)
nio4r (2.7.4)
ostruct (0.6.1)
oxidized (0.33.0)
oxidized (0.34.3)
asetus (~> 0.4)
bcrypt_pbkdf (~> 1.0)
ed25519 (~> 1.2)
@@ -42,30 +40,31 @@ GEM
net-scp (~> 4.1)
net-ssh (~> 7.3)
net-telnet (~> 0.2)
ostruct (~> 0.6)
psych (~> 5.0)
rugged (~> 1.6)
semantic_logger (~> 4.17.0)
slop (~> 4.6)
syslog (~> 0.3.0)
syslog_protocol (~> 0.9.2)
oxidized-script (0.7.0)
oxidized (~> 0.29)
slop (~> 4.6)
oxidized-web (0.16.0)
charlock_holmes (~> 0.7.5)
oxidized-web (0.17.1)
charlock_holmes (>= 0.7.5, < 0.8.0)
emk-sinatra-url-for (~> 0.2)
haml (~> 6.0)
htmlentities (~> 4.3)
json (~> 2.3)
ostruct (~> 0.6)
oxidized (~> 0.31)
puma (>= 3.11.4)
sinatra (>= 1.4.6)
sinatra-contrib (>= 1.4.6)
haml (>= 6.0.0, < 6.4.0)
htmlentities (>= 4.3.0, < 4.4.0)
json (>= 2.3.0, < 2.14.0)
oxidized (~> 0.34.1)
puma (~> 6.6.0)
sinatra (~> 4.1.1)
sinatra-contrib (~> 4.1.1)
psych (5.2.6)
date
stringio
puma (6.6.0)
puma (6.6.1)
nio4r (~> 2.0)
rack (3.1.14)
rack (3.2.0)
rack-protection (4.1.1)
base64 (>= 0.1.0)
logger (>= 1.6.0)
@@ -75,6 +74,8 @@ GEM
rack (>= 3.0.0)
ruby2_keywords (0.0.5)
rugged (1.9.0)
semantic_logger (4.17.0)
concurrent-ruby (~> 1.0)
sinatra (4.1.1)
logger (>= 1.6.0)
mustermann (~> 3.0)
@@ -90,24 +91,24 @@ GEM
tilt (~> 2.0)
slop (4.10.1)
stringio (3.1.7)
temple (0.10.3)
thor (1.3.2)
tilt (2.6.0)
syslog (0.3.0)
logger
syslog_protocol (0.9.2)
temple (0.10.4)
thor (1.4.0)
tilt (2.6.1)
time (0.4.1)
date
timeout (0.4.3)
PLATFORMS
arm64-darwin
ruby
x86_64-darwin
x86_64-linux
DEPENDENCIES
oxidized (= 0.33.0)
oxidized (= 0.34.3)
oxidized-script (= 0.7.0)
oxidized-web (= 0.16.0)
oxidized-web (= 0.17.1)
psych (~> 5.0)
BUNDLED WITH
2.5.22
2.6.6

View File

@@ -14,10 +14,10 @@
platforms = [ ];
source = {
remotes = [ "https://rubygems.org" ];
sha256 = "01qml0yilb9basf7is2614skjp8384h2pycfx86cr8023arfj98g";
sha256 = "0yx9yn47a8lkfcjmigk79fykxvr80r4m1i35q82sxzynpbm7lcr7";
type = "gem";
};
version = "0.2.0";
version = "0.3.0";
};
bcrypt_pbkdf = {
groups = [ "default" ];
@@ -39,6 +39,16 @@
};
version = "0.7.9";
};
concurrent-ruby = {
groups = [ "default" ];
platforms = [ ];
source = {
remotes = [ "https://rubygems.org" ];
sha256 = "1ipbrgvf0pp6zxdk5ascp6i29aybz2bx9wdrlchjmpx6mhvkwfw1";
type = "gem";
};
version = "1.3.5";
};
date = {
groups = [ "default" ];
platforms = [ ];
@@ -100,10 +110,10 @@
platforms = [ ];
source = {
remotes = [ "https://rubygems.org" ];
sha256 = "0l0av82l1i5703fd5qnxr263zw21xmbpx737av3r9pjn0w0cw3xk";
sha256 = "0s5vklcy2fgdxa9c6da34jbfrqq7xs6mryjglqqb5iilshcg3q82";
type = "gem";
};
version = "2.12.0";
version = "2.13.2";
};
logger = {
groups = [ "default" ];
@@ -120,10 +130,10 @@
platforms = [ ];
source = {
remotes = [ "https://rubygems.org" ];
sha256 = "0pb1g1y3dsiahavspyzkdy39j4q377009f6ix0bh1ag4nqw43l0z";
sha256 = "06sabsvnw0x1aqdcswc6bqrqz6705548bfd8z22jxgxfjrn1yn3n";
type = "gem";
};
version = "1.15.0";
version = "1.17.0";
};
mustermann = {
dependencies = [ "ruby2_keywords" ];
@@ -131,10 +141,10 @@
platforms = [ ];
source = {
remotes = [ "https://rubygems.org" ];
sha256 = "123ycmq6pkivv29bqbv79jv2cs04xakzd0fz1lalgvfs5nxfky6i";
sha256 = "08ma2fmxlm6i7lih4mc3har2fzsbj1pl4hhva65kljf6nfvdryl5";
type = "gem";
};
version = "3.0.3";
version = "3.0.4";
};
net-ftp = {
dependencies = [
@@ -212,16 +222,6 @@
};
version = "2.7.4";
};
ostruct = {
groups = [ "default" ];
platforms = [ ];
source = {
remotes = [ "https://rubygems.org" ];
sha256 = "05xqijcf80sza5pnlp1c8whdaay8x5dc13214ngh790zrizgp8q9";
type = "gem";
};
version = "0.6.1";
};
oxidized = {
dependencies = [
"asetus"
@@ -232,19 +232,21 @@
"net-scp"
"net-ssh"
"net-telnet"
"ostruct"
"psych"
"rugged"
"semantic_logger"
"slop"
"syslog"
"syslog_protocol"
];
groups = [ "default" ];
platforms = [ ];
source = {
remotes = [ "https://rubygems.org" ];
sha256 = "02vprgsqaafrnkz9fhj27mv8ngir4h1g07zc6s6f7gja5awfwqzm";
sha256 = "16k60qxp2lw8l4ny21rk0m6vx3lipdhxp0lslmwn7gqi8wyw6ra8";
type = "gem";
};
version = "0.33.0";
version = "0.34.3";
};
oxidized-script = {
dependencies = [
@@ -267,7 +269,6 @@
"haml"
"htmlentities"
"json"
"ostruct"
"oxidized"
"puma"
"sinatra"
@@ -277,10 +278,10 @@
platforms = [ ];
source = {
remotes = [ "https://rubygems.org" ];
sha256 = "1w16ha8rdnqb9j7v9mjdgfh4p0fdmwfxfprs167267ag1mah4268";
sha256 = "1kcc7qlz3w530ssfnc7rgqhcwc4f4k3lbgayffwhnzl73s8mdld9";
type = "gem";
};
version = "0.16.0";
version = "0.17.1";
};
psych = {
dependencies = [
@@ -302,20 +303,20 @@
platforms = [ ];
source = {
remotes = [ "https://rubygems.org" ];
sha256 = "11xd3207k5rl6bz0qxhcb3zcr941rhx7ig2f19gxxmdk7s3hcp7j";
sha256 = "07pajhv7pqz82kcjc6017y4d0hwz5kp746cydpx1npd79r56xddr";
type = "gem";
};
version = "6.6.0";
version = "6.6.1";
};
rack = {
groups = [ "default" ];
platforms = [ ];
source = {
remotes = [ "https://rubygems.org" ];
sha256 = "0i2bjh42cmlkwxjrldqj8g5sfrasdp64xhfr25kvp4ziilm3qqc4";
sha256 = "04inzfa1psgl8mywgzaks31am1zh00lyc0mf3zb5jv399m8j3kbr";
type = "gem";
};
version = "3.1.14";
version = "3.2.0";
};
rack-protection = {
dependencies = [
@@ -366,6 +367,17 @@
};
version = "1.9.0";
};
semantic_logger = {
dependencies = [ "concurrent-ruby" ];
groups = [ "default" ];
platforms = [ ];
source = {
remotes = [ "https://rubygems.org" ];
sha256 = "1s9hs743a8wkqxwpfddsgwlf8ikc9y6n882gpli2xgkab7c60jy5";
type = "gem";
};
version = "4.17.0";
};
sinatra = {
dependencies = [
"logger"
@@ -421,35 +433,56 @@
};
version = "3.1.7";
};
syslog = {
dependencies = [ "logger" ];
groups = [ "default" ];
platforms = [ ];
source = {
remotes = [ "https://rubygems.org" ];
sha256 = "023lbh48fcn72gwyh1x52ycs1wx1bnhdajmv0qvkidmdsmxnxzjd";
type = "gem";
};
version = "0.3.0";
};
syslog_protocol = {
groups = [ "default" ];
platforms = [ ];
source = {
remotes = [ "https://rubygems.org" ];
sha256 = "1yb2cmbyj0zmb2yhkgnmghcngrkhcxs4g1svcmgfj90l2hs23nmc";
type = "gem";
};
version = "0.9.2";
};
temple = {
groups = [ "default" ];
platforms = [ ];
source = {
remotes = [ "https://rubygems.org" ];
sha256 = "0fwia5hvc1xz9w7vprzjnsym3v9j5l9ggdvy70jixbvpcpz4acfz";
sha256 = "0b7pzx45f1vg6f53midy70ndlmb0k4k03zp4nsq8l0q9dx5yk8dp";
type = "gem";
};
version = "0.10.3";
version = "0.10.4";
};
thor = {
groups = [ "default" ];
platforms = [ ];
source = {
remotes = [ "https://rubygems.org" ];
sha256 = "1nmymd86a0vb39pzj2cwv57avdrl6pl3lf5bsz58q594kqxjkw7f";
sha256 = "0gcarlmpfbmqnjvwfz44gdjhcmm634di7plcx2zdgwdhrhifhqw7";
type = "gem";
};
version = "1.3.2";
version = "1.4.0";
};
tilt = {
groups = [ "default" ];
platforms = [ ];
source = {
remotes = [ "https://rubygems.org" ];
sha256 = "0szpapi229v3scrvw1pgy0vpjm7z3qlf58m1198kxn70cs278g96";
sha256 = "0w27v04d7rnxjr3f65w1m7xyvr6ch6szjj2v5wv1wz6z5ax9pa9m";
type = "gem";
};
version = "2.6.0";
version = "2.6.1";
};
time = {
dependencies = [ "date" ];

View File

@@ -0,0 +1,108 @@
diff --git a/src/paperless/settings.py b/src/paperless/settings.py
index 3b69b2fc2..8549b9396 100644
--- a/src/paperless/settings.py
+++ b/src/paperless/settings.py
@@ -11,7 +11,6 @@ from typing import Final
from urllib.parse import urlparse
from celery.schedules import crontab
-from concurrent_log_handler.queue import setup_logging_queues
from django.utils.translation import gettext_lazy as _
from dotenv import load_dotenv
@@ -803,8 +802,6 @@ USE_TZ = True
# Logging #
###############################################################################
-setup_logging_queues()
-
LOGGING_DIR.mkdir(parents=True, exist_ok=True)
LOGROTATE_MAX_SIZE = os.getenv("PAPERLESS_LOGROTATE_MAX_SIZE", 1024 * 1024)
diff --git a/src/paperless_mail/mail.py b/src/paperless_mail/mail.py
index b62e37166..415a69163 100644
--- a/src/paperless_mail/mail.py
+++ b/src/paperless_mail/mail.py
@@ -29,7 +29,7 @@ from imap_tools import MailBoxUnencrypted
from imap_tools import MailMessage
from imap_tools import MailMessageFlags
from imap_tools import errors
-from imap_tools.mailbox import MailBoxTls
+from imap_tools.mailbox import MailBoxStartTls
from imap_tools.query import LogicOperator
from documents.data_models import ConsumableDocument
@@ -419,7 +419,7 @@ def get_mailbox(server, port, security) -> MailBox:
if security == MailAccount.ImapSecurity.NONE:
mailbox = MailBoxUnencrypted(server, port)
elif security == MailAccount.ImapSecurity.STARTTLS:
- mailbox = MailBoxTls(server, port, ssl_context=ssl_context)
+ mailbox = MailBoxStartTls(server, port, ssl_context=ssl_context)
elif security == MailAccount.ImapSecurity.SSL:
mailbox = MailBox(server, port, ssl_context=ssl_context)
else:
diff --git a/src/documents/serialisers.py b/src/documents/serialisers.py
index 5a1a6c6859a..95689b5124d 100644
--- a/src/documents/serialisers.py
+++ b/src/documents/serialisers.py
@@ -2038,6 +2038,24 @@ def validate(self, attrs):
return attrs
+ @staticmethod
+ def normalize_workflow_trigger_sources(trigger):
+ """
+ Convert sources to strings to handle django-multiselectfield v1.0 changes
+ """
+ if trigger and "sources" in trigger:
+ trigger["sources"] = [
+ str(s.value if hasattr(s, "value") else s) for s in trigger["sources"]
+ ]
+
+ def create(self, validated_data):
+ WorkflowTriggerSerializer.normalize_workflow_trigger_sources(validated_data)
+ return super().create(validated_data)
+
+ def update(self, instance, validated_data):
+ WorkflowTriggerSerializer.normalize_workflow_trigger_sources(validated_data)
+ return super().update(instance, validated_data)
+
class WorkflowActionEmailSerializer(serializers.ModelSerializer):
id = serializers.IntegerField(allow_null=True, required=False)
@@ -2202,6 +2220,8 @@ def update_triggers_and_actions(self, instance: Workflow, triggers, actions):
if triggers is not None and triggers is not serializers.empty:
for trigger in triggers:
filter_has_tags = trigger.pop("filter_has_tags", None)
+ # Convert sources to strings to handle django-multiselectfield v1.0 changes
+ WorkflowTriggerSerializer.normalize_workflow_trigger_sources(trigger)
trigger_instance, _ = WorkflowTrigger.objects.update_or_create(
id=trigger.get("id"),
defaults=trigger,
diff --git a/src/documents/tests/test_management_exporter.py b/src/documents/tests/test_management_exporter.py
index 68d20476593..7415467de79 100644
--- a/src/documents/tests/test_management_exporter.py
+++ b/src/documents/tests/test_management_exporter.py
@@ -123,7 +123,7 @@ def setUp(self) -> None:
self.trigger = WorkflowTrigger.objects.create(
type=WorkflowTrigger.WorkflowTriggerType.CONSUMPTION,
- sources=[1],
+ sources=[str(WorkflowTrigger.DocumentSourceChoices.CONSUME_FOLDER.value)],
filter_filename="*",
)
self.action = WorkflowAction.objects.create(assign_title="new title")
diff --git a/src/documents/tests/test_migration_workflows.py b/src/documents/tests/test_migration_workflows.py
index 9895188188a..60e429d68c2 100644
--- a/src/documents/tests/test_migration_workflows.py
+++ b/src/documents/tests/test_migration_workflows.py
@@ -104,7 +104,7 @@ def setUpBeforeMigration(self, apps):
trigger = WorkflowTrigger.objects.create(
type=0,
- sources=[DocumentSource.ConsumeFolder],
+ sources=[str(DocumentSource.ConsumeFolder)],
filter_path="*/path/*",
filter_filename="*file*",
)

View File

@@ -3,6 +3,7 @@
stdenv,
fetchFromGitHub,
fetchPypi,
fetchpatch,
node-gyp,
nodejs_20,
nixosTests,
@@ -144,6 +145,15 @@ python.pkgs.buildPythonApplication rec {
inherit version src;
# Manual partial backport of:
# - https://github.com/paperless-ngx/paperless-ngx/commit/9889c59d3daa8f4ac8ec2400c00ddc36a7ca63c9
# - https://github.com/paperless-ngx/paperless-ngx/pull/10538
# Fixes build with latest dependency versions.
# FIXME: remove in next update
patches = [
./dep-updates.patch
];
postPatch = ''
# pytest-xdist with to many threads makes the tests flaky
if (( $NIX_BUILD_CORES > 3)); then
@@ -162,7 +172,14 @@ python.pkgs.buildPythonApplication rec {
pythonRelaxDeps = [
"django-allauth"
"django-auditlog"
"django-guardian"
"django-multiselectfield"
"imap-tools"
"pathvalidate"
"redis"
"scikit-learn"
"tika-client"
];
dependencies =

View File

@@ -37,7 +37,7 @@
stdenv.mkDerivation (finalAttrs: {
pname = "papers";
version = "48.4";
version = "48.5";
outputs = [
"out"
@@ -47,7 +47,7 @@ stdenv.mkDerivation (finalAttrs: {
src = fetchurl {
url = "mirror://gnome/sources/papers/${lib.versions.major finalAttrs.version}/papers-${finalAttrs.version}.tar.xz";
hash = "sha256-8RqhxUSsIRJZ4jC0DIBK5kB3M5pXve+j2761f5Fm4/0=";
hash = "sha256-DMjXLHHT2KqxvhCuGUGkzZLNHip+gwq3aA4sgt+xnAs=";
};
cargoDeps = rustPlatform.fetchCargoVendor {
@@ -125,8 +125,8 @@ stdenv.mkDerivation (finalAttrs: {
'';
meta = with lib; {
homepage = "https://wiki.gnome.org/Apps/papers";
changelog = "https://gitlab.gnome.org/GNOME/Incubator/papers/-/blob/${finalAttrs.version}/NEWS?ref_type=tags";
homepage = "https://gitlab.gnome.org/GNOME/papers";
changelog = "https://gitlab.gnome.org/GNOME/papers/-/blob/${finalAttrs.version}/NEWS?ref_type=tags";
description = "GNOME's document viewer";
longDescription = ''

View File

@@ -12,19 +12,27 @@
upx,
zpaq,
zstd,
writableTmpDirAsHomeHook,
}:
stdenv.mkDerivation rec {
let
# peazip looks for the "7z", not "7zz"
_7z = runCommand "7z" { } ''
mkdir -p $out/bin
ln -s ${_7zz}/bin/7zz $out/bin/7z
'';
in
stdenv.mkDerivation (finalAttrs: {
pname = "peazip";
version = "10.6.0";
src = fetchFromGitHub {
owner = "peazip";
repo = "peazip";
rev = version;
rev = finalAttrs.version;
hash = "sha256-oRgsT2j5P6jbaBAgLMGArJ+pCVSgC/CJcHM45mRw6Bs=";
};
sourceRoot = "${src.name}/peazip-sources";
sourceRoot = "${finalAttrs.src.name}/peazip-sources";
postPatch = ''
# set it to use compression programs from $PATH
@@ -35,6 +43,8 @@ stdenv.mkDerivation rec {
qt6Packages.wrapQtAppsHook
lazarus
fpc
# lazarus tries to create files in $HOME/.lazarus
writableTmpDirAsHomeHook
];
buildInputs = [
@@ -45,11 +55,9 @@ stdenv.mkDerivation rec {
libqtpas
]);
NIX_LDFLAGS = "--as-needed -rpath ${lib.makeLibraryPath buildInputs}";
env.NIX_LDFLAGS = "--as-needed -rpath ${lib.makeLibraryPath finalAttrs.buildInputs}";
buildPhase = ''
# lazarus tries to create files in $HOME/.lazarus
export HOME=$(mktemp -d)
pushd dev
lazbuild --lazarusdir=${lazarus}/share/lazarus --add-package metadarkstyle/metadarkstyle.lpk
lazbuild --lazarusdir=${lazarus}/share/lazarus --widgetset=qt6 --build-all project_pea.lpi
@@ -57,29 +65,26 @@ stdenv.mkDerivation rec {
popd
'';
# peazip looks for the "7z", not "7zz"
_7z = runCommand "7z" { } ''
mkdir -p $out/bin
ln -s ${_7zz}/bin/7zz $out/bin/7z
'';
installPhase = ''
runHook preInstall
install -D dev/{pea,peazip} -t $out/lib/peazip
wrapProgram $out/lib/peazip/peazip --prefix PATH : ${
lib.makeBinPath [
_7z
brotli
upx
zpaq
zstd
]
}
mkdir -p $out/bin
ln -s $out/lib/peazip/{pea,peazip} $out/bin/
makeWrapper $out/lib/peazip/peazip $out/bin/peazip \
--prefix PATH : ${
lib.makeBinPath [
_7z
brotli
upx
zpaq
zstd
]
} \
''${qtWrapperArgs[@]} # putting this here as to not have double wrapping
makeWrapper $out/lib/peazip/pea $out/bin/pea \
''${qtWrapperArgs[@]} # putting this here as to not have double wrapping
mkdir -p $out/share/peazip $out/lib/peazip/res/share
mkdir -p $out/share/peazip $out/lib/peazip/res
ln -s $out/share/peazip $out/lib/peazip/res/share
cp -r res/share/{icons,lang,themes,presets} $out/share/peazip/
# Install desktop entries
@@ -101,19 +106,21 @@ stdenv.mkDerivation rec {
runHook postInstall
'';
meta = with lib; {
description = "Cross-platform file and archive manager";
dontWrapQtApps = true;
meta = {
description = "File and archive manager";
longDescription = ''
Free Zip / Unzip software and Rar file extractor. Cross-platform file and archive manager.
Free Zip / Unzip software and Rar file extractor. File and archive manager.
Features volume spanning, compression, authenticated encryption.
Supports 7Z, 7-Zip sfx, ACE, ARJ, Brotli, BZ2, CAB, CHM, CPIO, DEB, GZ, ISO, JAR, LHA/LZH, NSIS, OOo, PEA, RAR, RPM, split, TAR, Z, ZIP, ZIPX, Zstandard.
'';
license = licenses.gpl3Only;
license = lib.licenses.gpl3Only;
homepage = "https://peazip.github.io";
platforms = platforms.linux;
maintainers = with maintainers; [ annaaurora ];
platforms = lib.platforms.linux;
maintainers = with lib.maintainers; [ annaaurora ];
mainProgram = "peazip";
};
}
})

View File

@@ -6,13 +6,13 @@
buildGoModule rec {
pname = "pluto";
version = "5.22.2";
version = "5.22.3";
src = fetchFromGitHub {
owner = "FairwindsOps";
repo = "pluto";
rev = "v${version}";
hash = "sha256-hjYWxeTa0i6Gv+dFUH8AO9740pOZ27hP4Tb44EfXubg=";
hash = "sha256-7INiYL8ymry2HKPIYVWSEiJccUyntVZQM7mM1WTt6Ww=";
};
vendorHash = "sha256-59mRVfQ2rduTvIJE1l/j3K+PY3OEMfNpjjYg3hqNUhs=";

View File

@@ -0,0 +1,76 @@
{
lib,
python3,
fetchFromGitHub,
go-md2man,
podman,
withPodman ? true,
# passthru
ramalama,
}:
python3.pkgs.buildPythonApplication rec {
pname = "ramalama";
version = "0.11.3";
pyproject = true;
src = fetchFromGitHub {
owner = "containers";
repo = "ramalama";
tag = "v${version}";
hash = "sha256-dvNFSPPdMnxgwGK2rVSsyaYwvz0wHutqjLFhsCps80A=";
};
build-system = with python3.pkgs; [
setuptools
wheel
];
dependencies = [
python3.pkgs.argcomplete
];
nativeBuildInputs = [
go-md2man
];
preBuild = ''
make docs
'';
postInstall = lib.optionalString withPodman ''
wrapProgram $out/bin/ramalama \
--prefix PATH : ${lib.makeBinPath [ podman ]}
'';
pythonImportsCheck = [
"ramalama"
];
nativeCheckInputs = [
python3.pkgs.pytestCheckHook
];
passthru = {
tests = {
withoutPodman = ramalama.override {
withPodman = false;
};
};
};
meta = {
description = "Serving AI models locally using familiar container workflows";
longDescription = ''
Ramalama is an open-source developer tool that simplifies the local
serving of AI models from any source and facilitates their use for
inference in production, all through the familiar language of containers
'';
homepage = "https://ramalama.ai/";
license = lib.licenses.mit;
maintainers = with lib.maintainers; [ booxter ];
mainProgram = "ramalama";
};
}

View File

@@ -9,16 +9,16 @@
buildNpmPackage rec {
pname = "redocly";
version = "1.34.4";
version = "2.0.2";
src = fetchFromGitHub {
owner = "Redocly";
repo = "redocly-cli";
rev = "@redocly/cli@${version}";
hash = "sha256-iGgttEJJI8FHAU+ZF4ZiTH/6FMCWZyF66ntq4MhLvnc=";
hash = "sha256-dIPKvvJpNOvJLQ/tT0EOtRIx9/LfQf0g4+N9JChk37U=";
};
npmDepsHash = "sha256-nltS5exGhrZU/xBzTaQiWK0nIzU0ig+/nll0JSaloKE=";
npmDepsHash = "sha256-nb6QPtCqnXeRA7YEG3+U3ZWWG41v5cpkIplgNYej4dQ=";
npmBuildScript = "prepare";

View File

@@ -9,13 +9,13 @@
buildGoModule rec {
pname = "spacectl";
version = "1.14.4";
version = "1.15.0";
src = fetchFromGitHub {
owner = "spacelift-io";
repo = "spacectl";
rev = "v${version}";
hash = "sha256-l55mkCHx7x4a423u88PfZwXXdfUcdk1PqRfeDYKz1i8=";
hash = "sha256-nqB39rOHxDge4iopX7BmQpVcpxm2C7e2UMQHNWjfEuY=";
};
vendorHash = "sha256-iyB6GFkTa4ci+TC2mDTtkuqCXFBnz3rwLns+3ovkUxg=";

View File

@@ -5,6 +5,7 @@
jdk11,
makeDesktopItem,
makeWrapper,
wrapGAppsHook3,
copyDesktopItems,
nix-update-script,
}:
@@ -55,6 +56,7 @@ stdenv.mkDerivation rec {
nativeBuildInputs = [
jdk11
makeWrapper
wrapGAppsHook3
copyDesktopItems
];
@@ -85,7 +87,8 @@ stdenv.mkDerivation rec {
install -D ${pname}.jar -t $out/share/java/
makeWrapper ${jdk11}/bin/java $out/bin/${pname} \
--add-flags "-jar $out/share/java/${pname}.jar" \
--prefix _JAVA_OPTIONS " " "-Dawt.useSystemAAFontSettings=gasp"
--prefix _JAVA_OPTIONS " " "-Dawt.useSystemAAFontSettings=gasp" \
''${gappsWrapperArgs[@]}
cat << EOF > $out/share/mime/packages/structorizer.xml
<?xml version="1.0" encoding="UTF-8"?>
@@ -107,6 +110,8 @@ stdenv.mkDerivation rec {
runHook postInstall
'';
dontWrapGApps = true;
passthru.updateScript = nix-update-script { };
meta = with lib; {

View File

@@ -10,18 +10,18 @@
rustPlatform.buildRustPackage rec {
pname = "svix-server";
version = "1.70.0";
version = "1.71.0";
src = fetchFromGitHub {
owner = "svix";
repo = "svix-webhooks";
rev = "v${version}";
hash = "sha256-82QB+EmZf1v3L5zTLydaa4WlIUK5IJT0ghOpmIC1nRE=";
hash = "sha256-LwU3Bfz/J2bsmaDrIBafHNELlU7mEXSSN6Vy+wslCrw=";
};
sourceRoot = "${src.name}/server";
cargoHash = "sha256-f6nU5i9Dhy9inqqpHlNjR1M2E781398xo/T7hVGuCvk=";
cargoHash = "sha256-c3pQ6CSvzp8qkuLqWBDF5IZueqwRbjciu0QcG9uO4Vo=";
nativeBuildInputs = [ pkg-config ];

View File

@@ -8,16 +8,16 @@
rustPlatform.buildRustPackage rec {
pname = "typos";
version = "1.34.0";
version = "1.35.3";
src = fetchFromGitHub {
owner = "crate-ci";
repo = "typos";
tag = "v${version}";
hash = "sha256-fQFCjeqk7IGObusFpT19fxaZvbt9KNLtecgNPirwhhU=";
hash = "sha256-eyP88wUtjF7c6tjV3lBk7pYvdF8ur8zuyaxynqaQiN4=";
};
cargoHash = "sha256-6MKlpKBmA/y2cSs2bRqwZs4K/duPurlUDLw9uBdWpUs=";
cargoHash = "sha256-3cKYgun2vP1otdEudUeaBQMh6vfVqeVgQm+/eBcCL5c=";
passthru.updateScript = nix-update-script { };

View File

@@ -48,14 +48,14 @@ effectiveStdenv.mkDerivation rec {
# in \
# rWrapper.override{ packages = [ xgb ]; }"
pname = lib.optionalString rLibrary "r-" + pnameBase;
version = "3.0.3";
version = "3.0.4";
src = fetchFromGitHub {
owner = "dmlc";
repo = pnameBase;
tag = "v${version}";
fetchSubmodules = true;
hash = "sha256-UXYefQMb1xwwH5Jv8FT4rVbXP7xo+8Ya9wFhgMkm/rI=";
hash = "sha256-4p+Qhsf6G6yWmJo1O4EOPdBmWTtLc2Q9SmyxUZYJzLo=";
};
nativeBuildInputs = [

View File

@@ -50,7 +50,7 @@ in
stdenv.mkDerivation rec {
pname = "libinput";
version = "1.28.1";
version = "1.29.0";
outputs = [
"bin"
@@ -63,7 +63,7 @@ stdenv.mkDerivation rec {
owner = "libinput";
repo = "libinput";
rev = version;
hash = "sha256-kte5BzGEz7taW/ccnxmkJjXn3FeikzuD6Hm10l+X7c0=";
hash = "sha256-wZRec6zIOALy1O6/NRRl0VxuS16SiL5SjXsley4K+c0=";
};
patches = [

View File

@@ -3,4 +3,16 @@
callPackage ./generic.nix {
version = "3.6.4";
hash = "sha256-y5YqKtjW4IXyIZkoJvwCGC4scx0qdeV40rynHza4NUE=";
patches = [
# Fixes the build with GCC 14 on aarch64.
#
# See:
# * <https://github.com/openwrt/openwrt/pull/15479>
# * <https://github.com/Mbed-TLS/mbedtls/issues/9003>
(fetchurl {
url = "https://raw.githubusercontent.com/openwrt/openwrt/52b6c9247997e51a97f13bb9e94749bc34e2d52e/package/libs/mbedtls/patches/100-fix-gcc14-build.patch";
hash = "sha256-20bxGoUHkrOEungN3SamYKNgj95pM8IjbisNRh68Wlw=";
})
];
}

View File

@@ -25,7 +25,7 @@
buildPythonPackage rec {
pname = "python-roborock";
version = "2.29.1";
version = "2.35.0";
pyproject = true;
disabled = pythonOlder "3.11";
@@ -34,7 +34,7 @@ buildPythonPackage rec {
owner = "humbertogontijo";
repo = "python-roborock";
tag = "v${version}";
hash = "sha256-6Y/nqgGZQgmgaMjdAcYEidhr2h913deWtBoWnQz966o=";
hash = "sha256-4coslBoLZydw8g1fokYH2oGHJn+UFQ/Kzc3T/6bHuiY=";
};
postPatch = ''

View File

@@ -1,6 +1,6 @@
{
lib,
buildGo123Module,
buildGoModule,
fetchFromGitHub,
symlinkJoin,
nixosTests,
@@ -8,11 +8,11 @@
}:
let
version = "3.5.21";
etcdSrcHash = "sha256-0L/lA9/9SNKMz74R6UPF1I7gj03/e91EpNr4LxKoisw=";
etcdServerVendorHash = "sha256-JMxkcDibRcXhU+T7BQMAz95O7xDKefu1YPZK0GU7osk=";
etcdUtlVendorHash = "sha256-901QcnEQ8PWnkliqwL4CrbCD+0ja8vJlDke0P4ya8cA=";
etcdCtlVendorHash = "sha256-BJ924wRPQTqbqtNtXL3l/OSdQv1UmU1y6Zqu//EWTHI=";
version = "3.5.22";
etcdSrcHash = "sha256-tS1IFMxfb8Vk9HJTAK+BGPZiVE3ls4Q2DQSerALOQCc=";
etcdServerVendorHash = "sha256-ul3R0c6RoCqLvlD2dfso1KwfHjsHfzQiUVJZJmz28ks=";
etcdUtlVendorHash = "sha256-S2pje2fTDaZwf6jnyE2YXWcs/fgqF51nxCVfEwg0Gsw=";
etcdCtlVendorHash = "sha256-lZ6o0oWUsc3WiCa87ynm7UAG6VxTf81a301QMSPOvW0=";
src = fetchFromGitHub {
owner = "etcd-io";
@@ -29,11 +29,13 @@ let
description = "Distributed reliable key-value store for the most critical data of a distributed system";
license = licenses.asl20;
homepage = "https://etcd.io/";
maintainers = with maintainers; [ offline ];
maintainers = with maintainers; [
dtomvan
];
platforms = platforms.darwin ++ platforms.linux;
};
etcdserver = buildGo123Module {
etcdserver = buildGoModule {
pname = "etcdserver";
inherit
@@ -43,6 +45,8 @@ let
version
;
__darwinAllowLocalNetworking = true;
vendorHash = etcdServerVendorHash;
modRoot = "./server";
@@ -58,7 +62,7 @@ let
ldflags = [ "-X go.etcd.io/etcd/api/v3/version.GitSHA=GitNotFound" ];
};
etcdutl = buildGo123Module rec {
etcdutl = buildGoModule {
pname = "etcdutl";
inherit
@@ -73,7 +77,7 @@ let
modRoot = "./etcdutl";
};
etcdctl = buildGo123Module rec {
etcdctl = buildGoModule {
pname = "etcdctl";
inherit
@@ -94,7 +98,10 @@ symlinkJoin {
inherit meta version;
passthru = {
inherit etcdserver etcdutl etcdctl;
deps = {
inherit etcdserver etcdutl etcdctl;
};
tests = {
inherit (nixosTests) etcd etcd-cluster;
k3s = k3s.passthru.tests.etcd;

View File

@@ -45,7 +45,7 @@ if [ ! "$OLD_VERSION" = "$LATEST_VERSION" ]; then
setKV $PKG_KEY $EMPTY_HASH
set +e
VENDOR_HASH=$(nurl -e "(import ${NIXPKGS_PATH}/. {}).$ETCD_PKG_NAME.passthru.$INNER_PKG.goModules")
VENDOR_HASH=$(nurl -e "(import ${NIXPKGS_PATH}/. {}).$ETCD_PKG_NAME.passthru.deps.$INNER_PKG.goModules")
set -e
if [ -n "${VENDOR_HASH:-}" ]; then

View File

@@ -3,6 +3,7 @@
stdenv,
buildGoModule,
fetchFromGitHub,
fetchpatch,
removeReferencesTo,
tzdata,
wire,
@@ -56,6 +57,15 @@ buildGoModule rec {
hash = "sha256-yraCuPLe68ryCgFzOZPL1H/JYynEvxijjgxMmQvcPZE=";
};
# Fix build
# FIXME: remove in next update
patches = [
(fetchpatch {
url = "https://github.com/grafana/grafana/commit/21f305c6a0e242463f5219cc6944fb880ea809f0.patch";
hash = "sha256-sXooRlnKY5ax0+1CPhy4zxDQtDGspbSdOoHHciqLTD8=";
})
];
# borrowed from: https://github.com/NixOS/nixpkgs/blob/d70d9425f49f9aba3c49e2c389fe6d42bac8c5b0/pkgs/development/tools/analysis/snyk/default.nix#L20-L22
env = {
CYPRESS_INSTALL_BINARY = 0;

View File

@@ -0,0 +1,25 @@
diff --git a/src/openvpn/ovpn_dco_linux.h b/src/openvpn/ovpn_dco_linux.h
index 73e19b5..46c2786 100644
--- a/src/openvpn/ovpn_dco_linux.h
+++ b/src/openvpn/ovpn_dco_linux.h
@@ -237,20 +237,4 @@ enum ovpn_netlink_packet_attrs {
OVPN_PACKET_ATTR_MAX = __OVPN_PACKET_ATTR_AFTER_LAST - 1,
};
-enum ovpn_ifla_attrs {
- IFLA_OVPN_UNSPEC = 0,
- IFLA_OVPN_MODE,
-
- __IFLA_OVPN_AFTER_LAST,
- IFLA_OVPN_MAX = __IFLA_OVPN_AFTER_LAST - 1,
-};
-
-enum ovpn_mode {
- __OVPN_MODE_FIRST = 0,
- OVPN_MODE_P2P = __OVPN_MODE_FIRST,
- OVPN_MODE_MP,
-
- __OVPN_MODE_AFTER_LAST,
-};
-
#endif /* _UAPI_LINUX_OVPN_DCO_H_ */

View File

@@ -30,6 +30,13 @@ stdenv.mkDerivation (finalAttrs: {
hash = "sha256-nramYYNS+ee3canTiuFjG17f7tbUAjPiQ+YC3fIZXno=";
};
# Effectively a backport of https://github.com/OpenVPN/openvpn/commit/1d3c2b67a73a0aa011c13e62f876d24e49d41df0
# to fix build on linux-headers 6.16.
# FIXME: remove in next update
patches = [
./dco.patch
];
nativeBuildInputs = [
pkg-config
]

View File

@@ -10043,7 +10043,9 @@ with pkgs;
etcd = etcd_3_5;
etcd_3_4 = callPackage ../servers/etcd/3.4.nix { };
etcd_3_5 = callPackage ../servers/etcd/3.5 { };
etcd_3_5 = callPackage ../servers/etcd/3_5 {
buildGoModule = buildGo123Module;
};
prosody = callPackage ../servers/xmpp/prosody {
withExtraLibs = [ ];