From 01313d5181becb977c0c0f3efd3089b462e7f040 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 11 Jul 2026 19:02:59 +0000 Subject: [PATCH 01/53] codebuff: 1.0.681 -> 1.0.684 --- pkgs/by-name/co/codebuff/package-lock.json | 8 ++++---- pkgs/by-name/co/codebuff/package.nix | 6 +++--- 2 files changed, 7 insertions(+), 7 deletions(-) diff --git a/pkgs/by-name/co/codebuff/package-lock.json b/pkgs/by-name/co/codebuff/package-lock.json index 5cf1e70b7750..08e493719250 100644 --- a/pkgs/by-name/co/codebuff/package-lock.json +++ b/pkgs/by-name/co/codebuff/package-lock.json @@ -5,7 +5,7 @@ "packages": { "": { "dependencies": { - "codebuff": "^1.0.681" + "codebuff": "^1.0.684" } }, "node_modules/@isaacs/fs-minipass": { @@ -30,9 +30,9 @@ } }, "node_modules/codebuff": { - "version": "1.0.681", - "resolved": "https://registry.npmjs.org/codebuff/-/codebuff-1.0.681.tgz", - "integrity": "sha512-xRj1kKCvXA522IiomLVV0EyORdsjjS4T/shLVeoTrdM9MNZRqrCcm/b9bsiTIzwlYz4oQFgBfmWeHapKKPjh7A==", + "version": "1.0.684", + "resolved": "https://registry.npmjs.org/codebuff/-/codebuff-1.0.684.tgz", + "integrity": "sha512-nPAkTtzQs1rxGRVV4mjQYPS88NWq+so0OTBPCN/JGfo9x5UNbz1AnEsOiFbsdp6fVKVbnURd85lu82RbKtV/aQ==", "cpu": [ "x64", "arm64" diff --git a/pkgs/by-name/co/codebuff/package.nix b/pkgs/by-name/co/codebuff/package.nix index e8543c35f756..f302badecefc 100644 --- a/pkgs/by-name/co/codebuff/package.nix +++ b/pkgs/by-name/co/codebuff/package.nix @@ -6,16 +6,16 @@ buildNpmPackage (finalAttrs: { pname = "codebuff"; - version = "1.0.681"; + version = "1.0.684"; src = fetchzip { url = "https://registry.npmjs.org/codebuff/-/codebuff-${finalAttrs.version}.tgz"; - hash = "sha256-tkQ8MOkQk4vaS9PFqlFBV6unEgysXcwHrKGgxfe60fM="; + hash = "sha256-mWUIqBh5L39NC+fhPuAAxvcamo3uQPdCNvpniCNMJ8I="; }; strictDeps = true; - npmDepsHash = "sha256-KB0QCfpGP32O5dU+/2dOEmX87iclJrZudIkTNp9ZxSw="; + npmDepsHash = "sha256-JDuK1pipRKFG1wSEeAzJggHSdYqq753mR39Y+3MIwhM="; postPatch = '' cp ${./package-lock.json} package-lock.json From 3d537076cb57833c846c16b17458e13df92455c5 Mon Sep 17 00:00:00 2001 From: Aliaksandr Date: Fri, 17 Jul 2026 05:03:10 +0300 Subject: [PATCH 02/53] stdenv: fix replaceStdenv evaluation Pass empty crossOverlays from the custom stdenv bootstrap and cover it with a regression test. Assisted-by: codex with gpt-5.6-sol-high --- pkgs/stdenv/custom/default.nix | 1 + pkgs/test/top-level/default.nix | 17 +++++++++++++++++ 2 files changed, 18 insertions(+) diff --git a/pkgs/stdenv/custom/default.nix b/pkgs/stdenv/custom/default.nix index b6fefa7c912e..4bbeb46433f5 100644 --- a/pkgs/stdenv/custom/default.nix +++ b/pkgs/stdenv/custom/default.nix @@ -16,6 +16,7 @@ let crossSystem overlays ; + crossOverlays = [ ]; # Remove config.replaceStdenv to ensure termination. config = removeAttrs config [ "replaceStdenv" ]; }; diff --git a/pkgs/test/top-level/default.nix b/pkgs/test/top-level/default.nix index 7d21549c9107..87221deb0f58 100644 --- a/pkgs/test/top-level/default.nix +++ b/pkgs/test/top-level/default.nix @@ -83,6 +83,23 @@ lib.recurseIntoAttrs { assert appended.makeWrapper ? __spliced; pkgs.emptyFile; + replaceStdenv = + let + replacedPkgs = nixpkgsFun { + localSystem = { + inherit (pkgs.stdenv.buildPlatform) system; + }; + config.replaceStdenv = + { pkgs }: + pkgs.stdenv + // { + wasReplaced = true; + }; + }; + in + assert replacedPkgs.stdenv.wasReplaced; + pkgs.emptyFile; + massRebuildVariantComposition = let variants = [ From 196bcb0c780013a9cb9f6409a3bf2820c2f019df Mon Sep 17 00:00:00 2001 From: Aliaksandr Date: Fri, 17 Jul 2026 05:55:39 +0300 Subject: [PATCH 03/53] stdenv: avoid reimporting bootstrap stages Select local bootstrap stages once and pass them to custom and cross stage composition. Assisted-by: codex with gpt-5.6-sol-high --- pkgs/stdenv/cross/default.nix | 14 +------ pkgs/stdenv/custom/default.nix | 16 +------- pkgs/stdenv/default.nix | 70 ++++++++++++++++++++++----------- pkgs/test/top-level/default.nix | 16 ++++++++ 4 files changed, 64 insertions(+), 52 deletions(-) diff --git a/pkgs/stdenv/cross/default.nix b/pkgs/stdenv/cross/default.nix index f2adc91e2bb1..64be14084b74 100644 --- a/pkgs/stdenv/cross/default.nix +++ b/pkgs/stdenv/cross/default.nix @@ -5,21 +5,9 @@ config, overlays, crossOverlays, + bootStages, }: -let - bootStages = import ../. { - inherit lib localSystem overlays; - - crossSystem = localSystem; - crossOverlays = [ ]; - - # Ignore custom stdenvs when cross compiling for compatibility - # Use replaceCrossStdenv instead. - config = removeAttrs config [ "replaceStdenv" ]; - }; - -in lib.init bootStages ++ [ diff --git a/pkgs/stdenv/custom/default.nix b/pkgs/stdenv/custom/default.nix index 4bbeb46433f5..5f8fedf5dceb 100644 --- a/pkgs/stdenv/custom/default.nix +++ b/pkgs/stdenv/custom/default.nix @@ -1,27 +1,13 @@ { - lib, localSystem, crossSystem, config, overlays, + bootStages, }: assert crossSystem == localSystem; -let - bootStages = import ../. { - inherit - lib - localSystem - crossSystem - overlays - ; - crossOverlays = [ ]; - # Remove config.replaceStdenv to ensure termination. - config = removeAttrs config [ "replaceStdenv" ]; - }; - -in bootStages ++ [ diff --git a/pkgs/stdenv/default.nix b/pkgs/stdenv/default.nix index 9e573477f290..76e441039b34 100644 --- a/pkgs/stdenv/default.nix +++ b/pkgs/stdenv/default.nix @@ -25,47 +25,69 @@ let overlays ; }; + + useCrossStdenv = crossSystem != localSystem || crossOverlays != [ ]; + useCustomStdenv = !useCrossStdenv && (config.replaceStdenv or null) != null; + + # Cross and custom stdenvs extend the local bootstrap stages. Keep + # replaceStdenv out of those stages so it is applied only by the appended + # custom stage; cross compilation uses replaceCrossStdenv instead. + bootArgs = commonArgs // { + crossSystem = if useCrossStdenv then localSystem else crossSystem; + config = + if useCrossStdenv || useCustomStdenv then removeAttrs config [ "replaceStdenv" ] else config; + }; + # The native (i.e., impure) build environment. This one uses the # tools installed on the system outside of the Nix environment, # i.e., the stuff in /bin, /usr/bin, etc. This environment should # be used with care, since many Nix packages will not build properly # with it (e.g., because they require GNU Make). - stagesNative = import ./native commonArgs; + stagesNative = import ./native bootArgs; # The Nix build environment. - stagesNix = import ./nix (commonArgs // { bootStages = stagesNative; }); + stagesNix = import ./nix (bootArgs // { bootStages = stagesNative; }); - stagesFreeBSD = import ./freebsd commonArgs; + stagesFreeBSD = import ./freebsd bootArgs; # On Linux systems, the standard build environment consists of Nix-built # instances glibc and the `standard' Unix tools, i.e., the Posix utilities, # the GNU C compiler, and so on. - stagesLinux = import ./linux commonArgs; + stagesLinux = import ./linux bootArgs; - stagesDarwin = import ./darwin commonArgs; + stagesDarwin = import ./darwin bootArgs; - stagesCross = import ./cross (commonArgs // { inherit crossOverlays; }); + bootStages = + if localSystem.isLinux then + stagesLinux + else if localSystem.isDarwin then + stagesDarwin + else + { + # switch + x86_64-solaris = stagesNix; + i686-cygwin = stagesNative; + x86_64-cygwin = stagesNative; + x86_64-freebsd = stagesFreeBSD; + } + .${localSystem.system} or stagesNative; - stagesCustom = import ./custom commonArgs; + stagesCross = import ./cross (commonArgs // { inherit crossOverlays bootStages; }); + + stagesCustom = import ./custom { + inherit + localSystem + crossSystem + config + overlays + bootStages + ; + }; in -# Select the appropriate stages for the platform `system'. -if crossSystem != localSystem || crossOverlays != [ ] then +if useCrossStdenv then stagesCross -# The `or null` fallback is needed for contexts that don't use the module system (e.g. tarball builds). -else if (config.replaceStdenv or null) != null then +else if useCustomStdenv then stagesCustom -else if localSystem.isLinux then - stagesLinux -else if localSystem.isDarwin then - stagesDarwin -# misc special cases else - { - # switch - x86_64-solaris = stagesNix; - i686-cygwin = stagesNative; - x86_64-cygwin = stagesNative; - x86_64-freebsd = stagesFreeBSD; - } - .${localSystem.system} or stagesNative + bootStages diff --git a/pkgs/test/top-level/default.nix b/pkgs/test/top-level/default.nix index 87221deb0f58..cba4ad12a364 100644 --- a/pkgs/test/top-level/default.nix +++ b/pkgs/test/top-level/default.nix @@ -91,6 +91,7 @@ lib.recurseIntoAttrs { }; config.replaceStdenv = { pkgs }: + assert !(pkgs.config ? replaceStdenv); pkgs.stdenv // { wasReplaced = true; @@ -100,6 +101,21 @@ lib.recurseIntoAttrs { assert replacedPkgs.stdenv.wasReplaced; pkgs.emptyFile; + replaceStdenvIgnoredForCross = + let + crossPkgs = nixpkgsFun { + localSystem = { + system = "x86_64-linux"; + }; + crossSystem = { + system = "aarch64-linux"; + }; + config.replaceStdenv = _: throw "replaceStdenv must be ignored when cross compiling"; + }; + in + assert crossPkgs.stdenv.buildPlatform != crossPkgs.stdenv.hostPlatform; + pkgs.emptyFile; + massRebuildVariantComposition = let variants = [ From 6183cdb311710a1883044fdc5fbc8f3cbbf18ad2 Mon Sep 17 00:00:00 2001 From: Aliaksandr Date: Fri, 17 Jul 2026 05:57:47 +0300 Subject: [PATCH 04/53] stdenv: inline the replacement stage The replaceStdenv branch already guarantees that the appended stage is required. Assisted-by: codex with gpt-5.6-sol-high --- pkgs/stdenv/custom/default.nix | 26 -------------------------- pkgs/stdenv/default.nix | 21 +++++++++++---------- 2 files changed, 11 insertions(+), 36 deletions(-) delete mode 100644 pkgs/stdenv/custom/default.nix diff --git a/pkgs/stdenv/custom/default.nix b/pkgs/stdenv/custom/default.nix deleted file mode 100644 index 5f8fedf5dceb..000000000000 --- a/pkgs/stdenv/custom/default.nix +++ /dev/null @@ -1,26 +0,0 @@ -{ - localSystem, - crossSystem, - config, - overlays, - bootStages, -}: - -assert crossSystem == localSystem; - -bootStages -++ [ - - # Additional stage, built using custom stdenv - (vanillaPackages: { - inherit config overlays; - stdenv = - assert vanillaPackages.stdenv.hostPlatform == localSystem; - assert vanillaPackages.stdenv.targetPlatform == localSystem; - let - fn = config.replaceStdenv or null; - in - if fn == null then vanillaPackages.stdenv else fn { pkgs = vanillaPackages; }; - }) - -] diff --git a/pkgs/stdenv/default.nix b/pkgs/stdenv/default.nix index 76e441039b34..bc24cd9a198f 100644 --- a/pkgs/stdenv/default.nix +++ b/pkgs/stdenv/default.nix @@ -74,20 +74,21 @@ let stagesCross = import ./cross (commonArgs // { inherit crossOverlays bootStages; }); - stagesCustom = import ./custom { - inherit - localSystem - crossSystem - config - overlays - bootStages - ; - }; + replaceStdenvStage = + vanillaPackages: + assert crossSystem == localSystem; + { + inherit config overlays; + stdenv = + assert vanillaPackages.stdenv.hostPlatform == localSystem; + assert vanillaPackages.stdenv.targetPlatform == localSystem; + config.replaceStdenv { pkgs = vanillaPackages; }; + }; in if useCrossStdenv then stagesCross else if useCustomStdenv then - stagesCustom + bootStages ++ [ replaceStdenvStage ] else bootStages From 0a354bd12ac4eb4813302d5757983818bd3cd730 Mon Sep 17 00:00:00 2001 From: Aliaksandr Date: Fri, 17 Jul 2026 06:00:44 +0300 Subject: [PATCH 05/53] stdenv: remove redundant replacement assertions Stage selection already guarantees matching local platforms before applying replaceStdenv. Assisted-by: codex with gpt-5.6-sol-high --- pkgs/stdenv/default.nix | 14 ++++---------- 1 file changed, 4 insertions(+), 10 deletions(-) diff --git a/pkgs/stdenv/default.nix b/pkgs/stdenv/default.nix index bc24cd9a198f..5ab72f94b767 100644 --- a/pkgs/stdenv/default.nix +++ b/pkgs/stdenv/default.nix @@ -74,16 +74,10 @@ let stagesCross = import ./cross (commonArgs // { inherit crossOverlays bootStages; }); - replaceStdenvStage = - vanillaPackages: - assert crossSystem == localSystem; - { - inherit config overlays; - stdenv = - assert vanillaPackages.stdenv.hostPlatform == localSystem; - assert vanillaPackages.stdenv.targetPlatform == localSystem; - config.replaceStdenv { pkgs = vanillaPackages; }; - }; + replaceStdenvStage = vanillaPackages: { + inherit config overlays; + stdenv = config.replaceStdenv { pkgs = vanillaPackages; }; + }; in if useCrossStdenv then From bbb150a3314670a6147a72f8485f1200435fdcdf Mon Sep 17 00:00:00 2001 From: Aliaksandr Date: Sat, 18 Jul 2026 23:38:54 +0300 Subject: [PATCH 06/53] stdenv: remove redundant cygwin switch Its already handled by `or stagesNative` condition --- pkgs/stdenv/default.nix | 3 --- 1 file changed, 3 deletions(-) diff --git a/pkgs/stdenv/default.nix b/pkgs/stdenv/default.nix index 5ab72f94b767..8e265d6d3e6b 100644 --- a/pkgs/stdenv/default.nix +++ b/pkgs/stdenv/default.nix @@ -64,10 +64,7 @@ let stagesDarwin else { - # switch x86_64-solaris = stagesNix; - i686-cygwin = stagesNative; - x86_64-cygwin = stagesNative; x86_64-freebsd = stagesFreeBSD; } .${localSystem.system} or stagesNative; From 2dd1349006abecf79eb0c53473191d48207ff34d Mon Sep 17 00:00:00 2001 From: Aliaksandr Date: Sun, 19 Jul 2026 00:11:51 +0300 Subject: [PATCH 07/53] stdenv: stop passing crossSystem to local stages The dispatcher now constructs local bootstrap stages directly, so their target is represented entirely by localSystem. Remove the redundant crossSystem arguments and equality assertions from each local stage implementation. Assisted-by: codex with gpt-5.6-sol-high --- pkgs/stdenv/darwin/default.nix | 3 --- pkgs/stdenv/default.nix | 26 +++++++++++++------------- pkgs/stdenv/freebsd/default.nix | 2 -- pkgs/stdenv/linux/default.nix | 3 --- pkgs/stdenv/native/default.nix | 3 --- pkgs/stdenv/nix/default.nix | 2 -- 6 files changed, 13 insertions(+), 26 deletions(-) diff --git a/pkgs/stdenv/darwin/default.nix b/pkgs/stdenv/darwin/default.nix index b19cdcc54de2..e87ceb8660aa 100644 --- a/pkgs/stdenv/darwin/default.nix +++ b/pkgs/stdenv/darwin/default.nix @@ -10,7 +10,6 @@ { lib, localSystem, - crossSystem, config, overlays, # Allow passing in bootstrap files directly so we can test the stdenv bootstrap process when changing the bootstrap tools @@ -22,8 +21,6 @@ ), }: -assert crossSystem == localSystem; - let inherit (localSystem) system; genericStdenv = import ../generic { defaultConfig = config; }; diff --git a/pkgs/stdenv/default.nix b/pkgs/stdenv/default.nix index 8e265d6d3e6b..56ae4538ea6a 100644 --- a/pkgs/stdenv/default.nix +++ b/pkgs/stdenv/default.nix @@ -16,24 +16,14 @@ }: let - commonArgs = { - inherit - lib - localSystem - crossSystem - config - overlays - ; - }; - useCrossStdenv = crossSystem != localSystem || crossOverlays != [ ]; useCustomStdenv = !useCrossStdenv && (config.replaceStdenv or null) != null; # Cross and custom stdenvs extend the local bootstrap stages. Keep # replaceStdenv out of those stages so it is applied only by the appended # custom stage; cross compilation uses replaceCrossStdenv instead. - bootArgs = commonArgs // { - crossSystem = if useCrossStdenv then localSystem else crossSystem; + bootArgs = { + inherit lib localSystem overlays; config = if useCrossStdenv || useCustomStdenv then removeAttrs config [ "replaceStdenv" ] else config; }; @@ -69,7 +59,17 @@ let } .${localSystem.system} or stagesNative; - stagesCross = import ./cross (commonArgs // { inherit crossOverlays bootStages; }); + stagesCross = import ./cross { + inherit + lib + localSystem + crossSystem + config + overlays + crossOverlays + bootStages + ; + }; replaceStdenvStage = vanillaPackages: { inherit config overlays; diff --git a/pkgs/stdenv/freebsd/default.nix b/pkgs/stdenv/freebsd/default.nix index 61c386b8437b..0192238b7ae8 100644 --- a/pkgs/stdenv/freebsd/default.nix +++ b/pkgs/stdenv/freebsd/default.nix @@ -3,7 +3,6 @@ { lib, localSystem, - crossSystem, config, overlays, bootstrapFiles ? @@ -18,7 +17,6 @@ files, }: -assert crossSystem == localSystem; let genericStdenv = import ../generic { defaultConfig = config; }; diff --git a/pkgs/stdenv/linux/default.nix b/pkgs/stdenv/linux/default.nix index c9b64c3086e8..3948fc5f71ca 100644 --- a/pkgs/stdenv/linux/default.nix +++ b/pkgs/stdenv/linux/default.nix @@ -56,7 +56,6 @@ { lib, localSystem, - crossSystem, config, overlays, bootstrapFiles ? @@ -116,8 +115,6 @@ (config.replaceBootstrapFiles or lib.id) files, }: -assert crossSystem == localSystem; - let genericStdenv = import ../generic { defaultConfig = config; }; diff --git a/pkgs/stdenv/native/default.nix b/pkgs/stdenv/native/default.nix index 690107af303f..1def78bcd6a9 100644 --- a/pkgs/stdenv/native/default.nix +++ b/pkgs/stdenv/native/default.nix @@ -1,13 +1,10 @@ { lib, localSystem, - crossSystem, config, overlays, }: -assert crossSystem == localSystem; - let genericStdenv = import ../generic { defaultConfig = config; }; diff --git a/pkgs/stdenv/nix/default.nix b/pkgs/stdenv/nix/default.nix index f85971479bee..a7de0d82ee56 100644 --- a/pkgs/stdenv/nix/default.nix +++ b/pkgs/stdenv/nix/default.nix @@ -1,13 +1,11 @@ { lib, localSystem, - crossSystem, config, overlays, bootStages, }: -assert crossSystem == localSystem; let genericStdenv = import ../generic { defaultConfig = config; }; in From 0eb47ff8069ca5c482e81d4727daf57e755da7c8 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 8 Aug 2026 15:51:12 +0000 Subject: [PATCH 08/53] python3Packages.tesserocr: 2.10.0 -> 2.11.0 --- pkgs/development/python-modules/tesserocr/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/tesserocr/default.nix b/pkgs/development/python-modules/tesserocr/default.nix index 7fd889f621c5..c104852f85df 100644 --- a/pkgs/development/python-modules/tesserocr/default.nix +++ b/pkgs/development/python-modules/tesserocr/default.nix @@ -22,14 +22,14 @@ buildPythonPackage (finalAttrs: { pname = "tesserocr"; - version = "2.10.0"; + version = "2.11.0"; pyproject = true; src = fetchFromGitHub { owner = "sirfz"; repo = "tesserocr"; tag = "v${finalAttrs.version}"; - hash = "sha256-y/3MXkocO4hRMjREPT6yvqH87EZm79zerinp5TUHNP4="; + hash = "sha256-DkwWTCsuDs9dmHjZ8CQrqfVJjWVxnn7Bx0UhylY/AMY="; }; postPatch = '' From ec1c60c92eb9f7c21475ab15dded686e56d22233 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 11 Aug 2026 07:35:45 +0000 Subject: [PATCH 09/53] inshellisense: 0.0.2 -> 0.0.3 --- pkgs/by-name/in/inshellisense/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/in/inshellisense/package.nix b/pkgs/by-name/in/inshellisense/package.nix index 8f680e3c8f4f..74335cab470e 100644 --- a/pkgs/by-name/in/inshellisense/package.nix +++ b/pkgs/by-name/in/inshellisense/package.nix @@ -7,20 +7,20 @@ buildNpmPackage rec { pname = "inshellisense"; - version = "0.0.2"; + version = "0.0.3"; src = fetchFromGitHub { owner = "microsoft"; repo = "inshellisense"; tag = version; - hash = "sha256-7PgfDOFUHV9SyRnsP/6QWWwvge5Ib3bK97M5mqSJ1Lk="; + hash = "sha256-Zo9ogCmkTwRqkvL1R/BnOGDZR1Hzmgegf19N2ZmVmkM="; }; # Building against nodejs-24 is not yet supported by upstream. # https://github.com/microsoft/inshellisense/issues/369 nodejs = nodejs_22; - npmDepsHash = "sha256-SHIkFdf6p2JoBeUW/WfRX94Px+L1h3E/4BRk2WfIvSw="; + npmDepsHash = "sha256-d88ybpAwDkhxKyq9dgOMeoUbY7WVtqJUkk6mNp9Rsuk="; meta = { description = "IDE style command line auto complete"; From 9f6ba542cae5ef4580c3e8d87f9198727632296d Mon Sep 17 00:00:00 2001 From: Chris Moultrie <821688+tebriel@users.noreply.github.com> Date: Mon, 15 Jun 2026 15:44:54 -0400 Subject: [PATCH 10/53] homebox: 0.25.0 -> 0.26.2 changelog: https://github.com/sysadminsmedia/homebox/releases/tag/v0.26.2 --- doc/release-notes/rl-2611.section.md | 2 ++ pkgs/by-name/ho/homebox/package.nix | 8 ++++---- 2 files changed, 6 insertions(+), 4 deletions(-) diff --git a/doc/release-notes/rl-2611.section.md b/doc/release-notes/rl-2611.section.md index 33cdf427dd32..9e9d1a5dfda5 100644 --- a/doc/release-notes/rl-2611.section.md +++ b/doc/release-notes/rl-2611.section.md @@ -123,6 +123,8 @@ - `keycloak` was updated to >= 26.7.0 and includes some breaking internal (API) changes. See the [upstream migration guide](https://www.keycloak.org/docs/latest/upgrading/#migrating-to-26-7-0) for more information. +- `homebox` v0.26.0 introduced a new, required value to be set, `HBOX_AUTH_API_KEY_PEPPER`. It cannot be started without this. + - `librest` providing 0.7 ABI was removed. `librest_1_0` providing 1.0 ABI was renamed to `librest` and `librest_1_0` was kept as an alias. - `luaPackages.lrexlib-pcre` has been removed as part of the process to fully migrate from the end-of-life PRCE library to PCRE2. `luaPackages.lrexlib-pcre2` and multiple other versions of lrexlib can be used instead. diff --git a/pkgs/by-name/ho/homebox/package.nix b/pkgs/by-name/ho/homebox/package.nix index 8b68f19b72a8..3c895adea089 100644 --- a/pkgs/by-name/ho/homebox/package.nix +++ b/pkgs/by-name/ho/homebox/package.nix @@ -13,18 +13,18 @@ }: let pname = "homebox"; - version = "0.25.0"; + version = "0.26.2"; src = fetchFromGitHub { owner = "sysadminsmedia"; repo = "homebox"; tag = "v${version}"; - hash = "sha256-mAC7n8AjsSHzO+l0ILJhf4LPAuVZ5KIYO6mXftZpVbE="; + hash = "sha256-JUhRpUWbydy28Xw7j6oCKJLBmaOxcruWAdkqm+hvouY="; }; in buildGoModule { inherit pname version src; - vendorHash = "sha256-FuZEGUduKZyTuW63z3rk8g1KE8wyx55xoNSvqbvF0PA="; + vendorHash = "sha256-peQaPSbxGn8MnbZPqCi5ptW+dMh9l4W1hB6HqBLTqh4="; modRoot = "backend"; # the goModules derivation inherits our buildInputs and buildPhases # Since we do pnpm thing in those it fails if we don't explicitly remove them @@ -42,7 +42,7 @@ buildGoModule { src = "${src}/frontend"; pnpm = pnpm_10; fetcherVersion = 3; - hash = "sha256-LrK0ijH8ahmDU4t9ckmIf1TJmybLLDRRHA67djUwRBk="; + hash = "sha256-oHS2uMWyuqpiK7yWznmZ2mgxPJpWsyOZL2wz6zBu0cc="; }; pnpmRoot = "../frontend"; From cdb300c9a34d5f24b9cf2c2a582b92d42c1f5daf Mon Sep 17 00:00:00 2001 From: Chris Moultrie <821688+tebriel@users.noreply.github.com> Date: Mon, 15 Jun 2026 15:45:57 -0400 Subject: [PATCH 11/53] nixos.homebox: handle new AUTH_API_KEY_PEPPER configuration Assisted-By: GitHub Copilot:gpt-5.4 --- doc/release-notes/rl-2611.section.md | 4 +- nixos/modules/services/web-apps/homebox.nix | 164 ++++++++++++++------ nixos/tests/homebox.nix | 30 +++- 3 files changed, 148 insertions(+), 50 deletions(-) diff --git a/doc/release-notes/rl-2611.section.md b/doc/release-notes/rl-2611.section.md index 9e9d1a5dfda5..ed43b7af0412 100644 --- a/doc/release-notes/rl-2611.section.md +++ b/doc/release-notes/rl-2611.section.md @@ -123,8 +123,6 @@ - `keycloak` was updated to >= 26.7.0 and includes some breaking internal (API) changes. See the [upstream migration guide](https://www.keycloak.org/docs/latest/upgrading/#migrating-to-26-7-0) for more information. -- `homebox` v0.26.0 introduced a new, required value to be set, `HBOX_AUTH_API_KEY_PEPPER`. It cannot be started without this. - - `librest` providing 0.7 ABI was removed. `librest_1_0` providing 1.0 ABI was renamed to `librest` and `librest_1_0` was kept as an alias. - `luaPackages.lrexlib-pcre` has been removed as part of the process to fully migrate from the end-of-life PRCE library to PCRE2. `luaPackages.lrexlib-pcre2` and multiple other versions of lrexlib can be used instead. @@ -165,6 +163,8 @@ - The fwts efi-runtime kernel module was removed. +- `homebox` v0.26.0 introduced a new, required value to be set, `HBOX_AUTH_API_KEY_PEPPER`. If one is not provided the module will create one, it is recommended that you back this up as it is part of API Key generation and validation. + - Emacs loads the `early-default` library after `early-init.el`. Users can add `early-init.el` via `emacs.pkgs.withPackages` by packaging `early-init.el` into a library named `early-default`. diff --git a/nixos/modules/services/web-apps/homebox.nix b/nixos/modules/services/web-apps/homebox.nix index 901d393d86ec..86d5a22a9326 100644 --- a/nixos/modules/services/web-apps/homebox.nix +++ b/nixos/modules/services/web-apps/homebox.nix @@ -1,12 +1,14 @@ { lib, config, + options, pkgs, ... }: let cfg = config.services.homebox; inherit (lib) + literalExpression mkEnableOption mkPackageOption mkDefault @@ -17,6 +19,11 @@ let defaultUser = "homebox"; defaultGroup = "homebox"; + + pepperDefault = + (cfg.secrets ? HBOX_AUTH_API_KEY_PEPPER) + && (cfg.secrets.HBOX_AUTH_API_KEY_PEPPER == "/var/lib/homebox/api-pepper-secret"); + opts = options.services.homebox; in { options.services.homebox = { @@ -61,6 +68,37 @@ in ''; }; }; + secrets = mkOption { + type = types.submodule { + options = { + HBOX_AUTH_API_KEY_PEPPER = mkOption { + type = types.externalPath; + default = "/var/lib/homebox/api-pepper-secret"; + description = '' + Path to the API key pepper secret file (required for homebox to start). + ''; + example = "/run/secrets/homebox-api-pepper"; + }; + }; + freeformType = types.attrsOf types.externalPath; + }; + + default = { }; + description = '' + This follows the same structure as {option}`${opts.settings}` + but the value of each key is a path. + + The specified secret path is then read by systemd via [`LoadCredential=`] + and templated into {option}`${opts.settings}` for you. + + [`LoadCredential=`]: https://www.freedesktop.org/software/systemd/man/latest/systemd.exec.html#Credentials + ''; + example = literalExpression '' + { + HBOX_AUTH_API_KEY_PEPPER = "/run/secrets/homebox-api-pepper"; + } + ''; + }; }; config = mkIf cfg.enable { @@ -92,7 +130,7 @@ in HBOX_DATABASE_DRIVER = "sqlite3"; HBOX_DATABASE_SQLITE_PATH = "/var/lib/homebox/data/homebox.db?_pragma=busy_timeout=999&_pragma=journal_mode=WAL&_fk=1"; HBOX_OPTIONS_ALLOW_REGISTRATION = "false"; - HBOX_OPTIONS_CHECK_GITHUB_RELEASE = "false"; + HBOX_OPTIONS_GITHUB_RELEASE_CHECK = "false"; HBOX_MODE = "production"; # Fix this startup issue: # failed to create modcache index dir: mkdir /var/empty/.cache: read-only file system @@ -121,58 +159,92 @@ in } ]; }; - systemd.services.homebox = { - requires = lib.optional cfg.database.createLocally "postgresql.target"; - after = lib.optional cfg.database.createLocally "postgresql.target"; - environment = lib.filterAttrs (_: v: v != null) cfg.settings; - preStart = '' - "${pkgs.coreutils}/bin/rm" -rf /var/lib/homebox/tmp - "${pkgs.coreutils}/bin/mkdir" -p /var/lib/homebox/tmp + systemd.services.homebox-setup = mkIf pepperDefault { + script = '' + if [ ! -r "$STATE_DIRECTORY"/api-pepper-secret ]; then + umask 0277 + openssl rand -base64 48 > "$STATE_DIRECTORY"/api-pepper-secret + fi ''; + path = [ + pkgs.openssl + ]; serviceConfig = { + Type = "oneshot"; User = cfg.user; Group = cfg.group; - ExecStart = lib.getExe cfg.package; - LimitNOFILE = "1048576"; - PrivateTmp = true; - PrivateDevices = true; - Restart = "always"; StateDirectory = "homebox"; - - # Hardening - CapabilityBoundingSet = ""; - LockPersonality = true; - MemoryDenyWriteExecute = true; - PrivateUsers = true; - ProtectClock = true; - ProtectControlGroups = true; - ProtectHome = true; - ProtectHostname = true; - ProtectKernelLogs = true; - ProtectKernelModules = true; - ProtectKernelTunables = true; - ProtectProc = "invisible"; - ProcSubset = "pid"; - ProtectSystem = "strict"; - RestrictAddressFamilies = [ - "AF_UNIX" - "AF_INET" - "AF_INET6" - "AF_NETLINK" - ]; - RestrictNamespaces = true; - RestrictRealtime = true; - SystemCallArchitectures = "native"; - SystemCallFilter = [ - "@system-service" - "@pkey" - ]; - RestrictSUIDSGID = true; - PrivateMounts = true; - UMask = "0077"; }; - wantedBy = [ "multi-user.target" ]; }; + systemd.services.homebox = + let + deps = + lib.optionals pepperDefault [ + "homebox-setup.service" + ] + ++ lib.optionals cfg.database.createLocally [ + "postgresql.target" + ]; + in + { + requires = deps; + after = deps; + environment = lib.filterAttrs (_: v: v != null) cfg.settings; + preStart = '' + "${pkgs.coreutils}/bin/rm" -rf /var/lib/homebox/tmp + "${pkgs.coreutils}/bin/mkdir" -p /var/lib/homebox/tmp + ''; + script = '' + ${lib.strings.concatLines ( + lib.mapAttrsToList (name: _: "export ${name}=$(<\"$CREDENTIALS_DIRECTORY\"/${name})") cfg.secrets + )} + + exec ${lib.getExe cfg.package} + ''; + serviceConfig = { + User = cfg.user; + Group = cfg.group; + LoadCredential = (lib.mapAttrsToList (name: path: "${name}:${path}") cfg.secrets); + LimitNOFILE = "1048576"; + PrivateTmp = true; + PrivateDevices = true; + Restart = "always"; + StateDirectory = "homebox"; + + # Hardening + CapabilityBoundingSet = ""; + LockPersonality = true; + MemoryDenyWriteExecute = true; + PrivateUsers = true; + ProtectClock = true; + ProtectControlGroups = true; + ProtectHome = true; + ProtectHostname = true; + ProtectKernelLogs = true; + ProtectKernelModules = true; + ProtectKernelTunables = true; + ProtectProc = "invisible"; + ProcSubset = "pid"; + ProtectSystem = "strict"; + RestrictAddressFamilies = [ + "AF_UNIX" + "AF_INET" + "AF_INET6" + "AF_NETLINK" + ]; + RestrictNamespaces = true; + RestrictRealtime = true; + SystemCallArchitectures = "native"; + SystemCallFilter = [ + "@system-service" + "@pkey" + ]; + RestrictSUIDSGID = true; + PrivateMounts = true; + UMask = "0077"; + }; + wantedBy = [ "multi-user.target" ]; + }; }; meta.maintainers = with lib.maintainers; [ patrickdag diff --git a/nixos/tests/homebox.nix b/nixos/tests/homebox.nix index 160d09f116bb..5842668479e0 100644 --- a/nixos/tests/homebox.nix +++ b/nixos/tests/homebox.nix @@ -4,8 +4,8 @@ let in { name = "homebox"; - meta = with pkgs.lib.maintainers; { - maintainers = [ patrickdag ]; + meta = { + inherit (pkgs.homebox.meta) maintainers; }; nodes = let @@ -21,6 +21,31 @@ in imports = [ self.simple ]; services.homebox.database.createLocally = true; }; + + explicitPepper = + { + config, + lib, + ... + }: + let + inherit (config.services.homebox) + user + group + ; + in + { + systemd.tmpfiles.rules = [ + "d /run/homebox 0700 ${user} ${group}" + "f /run/homebox/pepper 0400 ${user} ${group} - 0a7524fa7b4555ab793c177557b7b8db6619b47cc0574fb99716315e03b6ddf1d67961ee9bf36b19bef448ed3e530957" + ]; + imports = [ self.simple ]; + services.homebox = { + secrets = { + HBOX_AUTH_API_KEY_PEPPER = "/run/homebox/pepper"; + }; + }; + }; }; in self; @@ -37,5 +62,6 @@ in simple.send_monitor_command("quit") simple.wait_for_shutdown() test_homebox(postgres) + test_homebox(explicitPepper) ''; } From 8f54e9f26c67117275ea5620f205a77dcb934793 Mon Sep 17 00:00:00 2001 From: XYenon Date: Fri, 27 Feb 2026 14:44:31 +0800 Subject: [PATCH 12/53] nixos/prometheus-exporters/kvrocks: init --- .../manual/release-notes/rl-2611.section.md | 2 ++ .../monitoring/prometheus/exporters.nix | 1 + .../prometheus/exporters/kvrocks.nix | 19 +++++++++++++++++++ nixos/tests/prometheus-exporters.nix | 16 ++++++++++++++++ .../prometheus-kvrocks-exporter/package.nix | 6 +++++- 5 files changed, 43 insertions(+), 1 deletion(-) create mode 100644 nixos/modules/services/monitoring/prometheus/exporters/kvrocks.nix diff --git a/nixos/doc/manual/release-notes/rl-2611.section.md b/nixos/doc/manual/release-notes/rl-2611.section.md index d397baed0cdb..08ab4342dbd1 100644 --- a/nixos/doc/manual/release-notes/rl-2611.section.md +++ b/nixos/doc/manual/release-notes/rl-2611.section.md @@ -92,6 +92,8 @@ - [Kvrocks](https://kvrocks.apache.org/), a distributed key value NoSQL database compatible with the Redis protocol. Available as [services.kvrocks](#opt-services.kvrocks.enable). +- [kvrocks_exporter](https://github.com/RocksLabs/kvrocks_exporter), a Prometheus exporter for Kvrocks metrics. Available as [services.prometheus.exporters.kvrocks](#opt-services.prometheus.exporters.kvrocks.enable). + ## Backward Incompatibilities {#sec-release-26.11-incompatibilities} diff --git a/nixos/modules/services/monitoring/prometheus/exporters.nix b/nixos/modules/services/monitoring/prometheus/exporters.nix index b1d7f62b582e..530315264562 100644 --- a/nixos/modules/services/monitoring/prometheus/exporters.nix +++ b/nixos/modules/services/monitoring/prometheus/exporters.nix @@ -82,6 +82,7 @@ let "keylight" "klipper" "knot" + "kvrocks" "libvirt" "lnd" "mail" diff --git a/nixos/modules/services/monitoring/prometheus/exporters/kvrocks.nix b/nixos/modules/services/monitoring/prometheus/exporters/kvrocks.nix new file mode 100644 index 000000000000..4822c6977479 --- /dev/null +++ b/nixos/modules/services/monitoring/prometheus/exporters/kvrocks.nix @@ -0,0 +1,19 @@ +{ + config, + lib, + pkgs, + ... +}: + +let + cfg = config.services.prometheus.exporters.kvrocks; +in +{ + port = 9121; + serviceOpts = { + serviceConfig = { + RestrictAddressFamilies = [ "AF_UNIX" ]; + ExecStart = "${lib.getExe pkgs.prometheus-kvrocks-exporter} -web.listen-address ${cfg.listenAddress}:${toString cfg.port} ${lib.escapeShellArgs cfg.extraFlags}"; + }; + }; +} diff --git a/nixos/tests/prometheus-exporters.nix b/nixos/tests/prometheus-exporters.nix index 3c1c5dc1d756..7a246ba5eb35 100644 --- a/nixos/tests/prometheus-exporters.nix +++ b/nixos/tests/prometheus-exporters.nix @@ -806,6 +806,22 @@ let ''; }; + kvrocks = + { ... }: + { + exporterConfig = { + enable = true; + }; + metricProvider.services.kvrocks.enable = true; + exporterTest = '' + wait_for_unit("kvrocks.service") + wait_for_unit("prometheus-kvrocks-exporter.service") + wait_for_open_port(6666) + wait_for_open_port(9121) + wait_until_succeeds("curl -sSf localhost:9121/metrics | grep 'kvrocks_up 1'") + ''; + }; + lnd = { pkgs, ... }: { diff --git a/pkgs/by-name/pr/prometheus-kvrocks-exporter/package.nix b/pkgs/by-name/pr/prometheus-kvrocks-exporter/package.nix index 53c493316c75..f6c20231785d 100644 --- a/pkgs/by-name/pr/prometheus-kvrocks-exporter/package.nix +++ b/pkgs/by-name/pr/prometheus-kvrocks-exporter/package.nix @@ -4,6 +4,7 @@ fetchFromGitHub, kvrocks, nix-update-script, + nixosTests, }: buildGoModule (finalAttrs: { @@ -63,7 +64,10 @@ buildGoModule (finalAttrs: { in [ "-skip=^(${builtins.concatStringsSep "|" skippedTests})$" ]; - passthru.updateScript = nix-update-script { }; + passthru = { + updateScript = nix-update-script { }; + tests = { inherit (nixosTests.prometheus-exporters) kvrocks; }; + }; meta = { description = "Prometheus exporter for Kvrocks metrics"; From 29fbf281331735710045cffeee828b6ba1dd960f Mon Sep 17 00:00:00 2001 From: Holiu618 <165534185+Holiu618@users.noreply.github.com> Date: Fri, 14 Aug 2026 14:02:10 +0800 Subject: [PATCH 13/53] dolt: 2.2.4 -> 2.3.0 --- pkgs/by-name/do/dolt/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/do/dolt/package.nix b/pkgs/by-name/do/dolt/package.nix index e50f124ca4b0..19c59b5946e8 100644 --- a/pkgs/by-name/do/dolt/package.nix +++ b/pkgs/by-name/do/dolt/package.nix @@ -7,13 +7,13 @@ buildGoModule (finalAttrs: { pname = "dolt"; - version = "2.2.4"; + version = "2.3.0"; src = fetchFromGitHub { owner = "dolthub"; repo = "dolt"; tag = "v${finalAttrs.version}"; - hash = "sha256-XAc584mxGsadxmY1Jf4JgaaBAUg9hXainGkaWIgdp5A="; + hash = "sha256-ho0mUdiwYTmczU7791pyD3MpCMje2a/IVt40QIiCJd4="; }; modRoot = "./go"; From bb2d51d1d6ace75f4c953b080bd2d31e7e04dff0 Mon Sep 17 00:00:00 2001 From: fliiiix Date: Fri, 14 Aug 2026 09:12:51 +0200 Subject: [PATCH 14/53] qtcreator: 19.0.1 -> 20.0.1 --- pkgs/by-name/qt/qtcreator/package.nix | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/qt/qtcreator/package.nix b/pkgs/by-name/qt/qtcreator/package.nix index 1eb30a7702cc..332dc2b396a9 100644 --- a/pkgs/by-name/qt/qtcreator/package.nix +++ b/pkgs/by-name/qt/qtcreator/package.nix @@ -21,10 +21,10 @@ }: let pname = "qtcreator"; - version = "19.0.1"; + version = "20.0.1"; src = fetchurl { url = "mirror://qt/official_releases/${pname}/${lib.versions.majorMinor version}/${version}/qt-creator-opensource-src-${version}.tar.xz"; - hash = "sha256-IAVmOmlQOyQETf7QdwajTETKvBn0dqwcEUTe8cSr+r4="; + hash = "sha256-XsO8zwbumhkFqHYKyfunoShWcvFAqX4MUsniSNkFGrg="; }; goModules = (buildGoModule { @@ -130,6 +130,7 @@ stdenv'.mkDerivation { maintainers = with lib.maintainers; [ wineee zatm8 + l33tname ]; platforms = lib.platforms.linux; mainProgram = "qtcreator"; From f50187839928c2b2b4a061332b0a3d24949a8eed Mon Sep 17 00:00:00 2001 From: wazzy Date: Fri, 14 Aug 2026 21:12:44 -0400 Subject: [PATCH 15/53] brave, brave-origin: 1.93.129 -> 1.93.136 https://community.brave.app/t/release-channel-1-93-136/656920 --- .../networking/browsers/brave/packages/brave-origin.nix | 8 ++++---- .../networking/browsers/brave/packages/brave.nix | 8 ++++---- 2 files changed, 8 insertions(+), 8 deletions(-) diff --git a/pkgs/applications/networking/browsers/brave/packages/brave-origin.nix b/pkgs/applications/networking/browsers/brave/packages/brave-origin.nix index 326f78ee7bad..10b78f30c57a 100644 --- a/pkgs/applications/networking/browsers/brave/packages/brave-origin.nix +++ b/pkgs/applications/networking/browsers/brave/packages/brave-origin.nix @@ -1,21 +1,21 @@ # Expression generated by update.sh; do not edit it by hand! rec { pname = "brave-origin"; - version = "1.93.129"; + version = "1.93.136"; flavor = "origin"; archives = { aarch64-linux = { url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-origin_${version}_arm64.deb"; - hash = "sha256-29NLuWH3TAUGkiiY00J+e+IGaqfIZ/g2vLI1aDXacVw="; + hash = "sha256-HHqMkIa5cqnrqxT6aJYq/RJs6YrX3BLoCyo9Twj2jy4="; }; x86_64-linux = { url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-origin_${version}_amd64.deb"; - hash = "sha256-F5d660t4t52L27gt8SF9n/54lmK+CeqZeqlbS84wjvU="; + hash = "sha256-rg5XjxusjUKl4YzTpX1zIVmhv71YwV6qgVprrW/Gklo="; }; aarch64-darwin = { url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-origin-v${version}-darwin-arm64.zip"; - hash = "sha256-H+UHhEPMBT/wki30DBic1jSpXI8jlddYruEs9TU0Mx8="; + hash = "sha256-hMwl4kSfPd6PCzvgt9xVyTDhDIMGb9cCRTZ8nwNdcI8="; }; }; } diff --git a/pkgs/applications/networking/browsers/brave/packages/brave.nix b/pkgs/applications/networking/browsers/brave/packages/brave.nix index 055bca8d9ae0..7b149566bd1e 100644 --- a/pkgs/applications/networking/browsers/brave/packages/brave.nix +++ b/pkgs/applications/networking/browsers/brave/packages/brave.nix @@ -1,20 +1,20 @@ # Expression generated by update.sh; do not edit it by hand! rec { pname = "brave"; - version = "1.93.129"; + version = "1.93.136"; archives = { aarch64-linux = { url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-browser_${version}_arm64.deb"; - hash = "sha256-pO6vTzTv7OKcP5uJwlcc+vUdg/0Lm2Q6apnEhjRxasM="; + hash = "sha256-M02+zpWert27gtP+Cdp1raFFDGj2xi053AveDHfGS+o="; }; x86_64-linux = { url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-browser_${version}_amd64.deb"; - hash = "sha256-fOyneo8kzoGqldT6nYRzFqgy1+WhKGhcSkJQTCd4w6k="; + hash = "sha256-lznlqu5DA+tBmcA4sEp117x6wIMUr592MBHiEd6mKZk="; }; aarch64-darwin = { url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-v${version}-darwin-arm64.zip"; - hash = "sha256-phHj7wAZKhRsqYrApNONbjM3RQBra893cDUq6e2lBrs="; + hash = "sha256-x8qEXimCjYohSlsd+WoO3l2BWdUqOmlYOtBMM+nWhp8="; }; }; } From ee4ec29b2f188e5cf0f7e668c22c1439337756a6 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 15 Aug 2026 05:57:27 +0000 Subject: [PATCH 16/53] gitify: 7.2.0 -> 7.3.3 --- pkgs/by-name/gi/gitify/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/gi/gitify/package.nix b/pkgs/by-name/gi/gitify/package.nix index 5a92c279f1b2..1725c5bd322a 100644 --- a/pkgs/by-name/gi/gitify/package.nix +++ b/pkgs/by-name/gi/gitify/package.nix @@ -20,13 +20,13 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "gitify"; - version = "7.2.0"; + version = "7.3.3"; src = fetchFromGitHub { owner = "gitify-app"; repo = "gitify"; tag = "v${finalAttrs.version}"; - hash = "sha256-tAI9lcpikYuLuwBHbVYLha5epmVRHz2fNR1d3uemYiw="; + hash = "sha256-Kr4+U6UD/cfbAzIZ8GrPgxGmV8ktENxd9o2/x3C4v+c="; }; nativeBuildInputs = [ @@ -46,7 +46,7 @@ stdenv.mkDerivation (finalAttrs: { inherit (finalAttrs) pname version src; inherit pnpm; fetcherVersion = 4; - hash = "sha256-+BJWidye9YfffDJgRnSPc7fjPfT8jcEvbwWKMLrIvCY="; + hash = "sha256-Uxta96e9t0jOfsgR82fMuzc1V5KC0t1n2TJ90qv73wg="; }; env.ELECTRON_SKIP_BINARY_DOWNLOAD = 1; From 21c7fc00973c7cbe3c890068cc40f3f8c1ca7ebc Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 15 Aug 2026 08:21:24 +0000 Subject: [PATCH 17/53] super-productivity: 18.17.0 -> 18.19.0 --- pkgs/by-name/su/super-productivity/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/su/super-productivity/package.nix b/pkgs/by-name/su/super-productivity/package.nix index 2c5b414374af..a0617fc65c93 100644 --- a/pkgs/by-name/su/super-productivity/package.nix +++ b/pkgs/by-name/su/super-productivity/package.nix @@ -20,7 +20,7 @@ let in buildNpmPackage rec { pname = "super-productivity"; - version = "18.17.0"; + version = "18.19.0"; inherit nodejs; @@ -28,7 +28,7 @@ buildNpmPackage rec { owner = "super-productivity"; repo = "super-productivity"; tag = "v${version}"; - hash = "sha256-Zp5qhSo6uj6eGM0mGFIhSuKHmX+eIpdVJhc2xfxMqpc="; + hash = "sha256-tUK2vytQ/fBSw8drjBLh4HlrnQh/0tX9e9otYMhXYsA="; }; # Use custom fetcher for deps because super-productivity uses multiple @@ -74,7 +74,7 @@ buildNpmPackage rec { dontInstall = true; outputHashMode = "recursive"; - hash = "sha256-Gn3H6YQZTxINOSrfqh5hVFGe19b2UNVLKcR8Ey0S5Gk="; + hash = "sha256-Je3pHgkBwt35sIvxQqnYX3F+uJQeBGc5kzCAL9czCYs="; } ); From 8572535e73491fb26118210c592adb232b45bf67 Mon Sep 17 00:00:00 2001 From: emilylange Date: Mon, 8 Jun 2026 19:59:01 +0200 Subject: [PATCH 18/53] nixos/forgejo-runner: init --- .../manual/release-notes/rl-2611.section.md | 2 + nixos/modules/module-list.nix | 1 + .../continuous-integration/forgejo-runner.nix | 529 ++++++++++++++++++ 3 files changed, 532 insertions(+) create mode 100644 nixos/modules/services/continuous-integration/forgejo-runner.nix diff --git a/nixos/doc/manual/release-notes/rl-2611.section.md b/nixos/doc/manual/release-notes/rl-2611.section.md index fafd7c8af491..dbd80927690b 100644 --- a/nixos/doc/manual/release-notes/rl-2611.section.md +++ b/nixos/doc/manual/release-notes/rl-2611.section.md @@ -64,6 +64,8 @@ - [Lix TOML remote builders](https://docs.lix.systems/manual/lix/stable/advanced-topics/distributed-builds.html#using-a-toml-configuration), remote builder configuration using lix's TOML format. Available as [lix.buildMachines](#opt-lix.buildMachines). Note: incompatible with `nix.buildMachines`. +- [Forgejo Runner](https://forgejo.org/docs/latest/admin/actions/), a daemon for Forgejo Actions. Available as [services.forgejo-runner](#opt-services.forgejo-runner.instances). + - [Koito](https://koito.io/), a modern, themeable scrobbler that you can use with any program that scrobbles to a custom ListenBrainz URL. Available as [services.koito](#opt-services.koito.enable). - [Zapret2](https://github.com/bol-van/zapret2), an extensible DPI bypass program. Available as [services.zapret2](#opt-services.zapret2.enable). diff --git a/nixos/modules/module-list.nix b/nixos/modules/module-list.nix index d981c49c7813..3ea0cb555992 100644 --- a/nixos/modules/module-list.nix +++ b/nixos/modules/module-list.nix @@ -523,6 +523,7 @@ ./services/continuous-integration/buildbot/master.nix ./services/continuous-integration/buildbot/worker.nix ./services/continuous-integration/buildkite-agents.nix + ./services/continuous-integration/forgejo-runner.nix ./services/continuous-integration/gitea-actions-runner.nix ./services/continuous-integration/github-runners.nix ./services/continuous-integration/gitlab-runner/runner.nix diff --git a/nixos/modules/services/continuous-integration/forgejo-runner.nix b/nixos/modules/services/continuous-integration/forgejo-runner.nix new file mode 100644 index 000000000000..e8d65cd2ccbc --- /dev/null +++ b/nixos/modules/services/continuous-integration/forgejo-runner.nix @@ -0,0 +1,529 @@ +{ + config, + lib, + pkgs, + utils, + ... +}: + +let + inherit (lib) + foldlAttrs + literalExpression + literalMD + mkEnableOption + mkIf + mkOption + mkPackageOption + mkRemovedOptionModule + mkRenamedOptionModule + nameValuePair + optionals + types + ; + + cfg = config.services.forgejo-runner; + settingsFormat = pkgs.formats.yaml { }; + config' = config; + + # An option type for cfg.secrets that is like cfg.settings (free-form yaml), but limited + # to just path and attrsOf path. It uses the same implementation primivites as + # pkgs.formats.yaml (serializableValueWith). + # The alternative would be something like types.any, which is too weak, or a hard-coded + # max-depth by chaining multiple types.oneOf and types.attrsOf together, which is both + # longer in code and less future-proof. + secretsTypeBase = types.oneOf [ + types.externalPath + (types.attrsOf secretsTypeBase) + ]; + secretsType = secretsTypeBase // { + description = "nested attribute set of ${types.externalPath.description}"; + }; + + labels = + instance: + instance.settings.runner.labels + ++ (lib.flatten ( + lib.mapAttrsToList (_: value: value.labels or [ ]) instance.settings.server.connections + )); +in +{ + meta.maintainers = pkgs.forgejo-runner.meta.maintainers; + + options.services.forgejo-runner = { + package = mkPackageOption pkgs "forgejo-runner" { }; + + instances = mkOption { + default = { }; + description = '' + Forgejo Runner instances. + ''; + type = types.attrsOf ( + types.submodule ( + { + options, + config, + name, + ... + }: + + { + imports = [ + ../../misc/assertions.nix + + # compat for users coming from nixos/gitea-actions-runner + (mkRenamedOptionModule [ "url" ] [ "settings" "server" "connections" "default" "url" ]) + (mkRenamedOptionModule [ "labels" ] [ "settings" "runner" "labels" ]) + (mkRemovedOptionModule [ "name" ] '' + The option `${options.name}' has been removed, because it has no longer + any effect, as runners no longer self-report their name to Forgejo. + '') + (mkRemovedOptionModule [ "token" ] '' + The option `${options.token}' has been renamed to + `${options.settings}.server.connections.default.token' + but additional attention is required. + + Assuming you are migrating from `services.gitea-actions-runner', you will need to: + + 1. Find the old `.runner' file of your previously registered runner. You will need + to extract two values from it. Given the instance name of "${name}", you should + be able to find it at `/var/lib/gitea-runner/${name}/.runner'. + + 2. Read the contents of it, for example using `cat /var/lib/gitea-runner/native/.runner'. + + 3. Take note of the "uuid" and set the option `${options.settings}.server.connections.default.uuid' + to that value. For example "c9e50be9-a7c3-4aee-ba35-624c4ff8c519". + + 4. Take note of the "token" and set the option `${options.settings}.server.connections.default.token' + to that value. For example "6634bb58be0db23cc013a2e72dd1828ae0257cf". + + 5. Remove option `${options.token}'. + '') + (mkRemovedOptionModule [ "tokenFile" ] '' + The option `${options.tokenFile}' has been renamed to + `${options.secrets}.server.connections.default.token_url' + but additional attention is required. + + Assuming you are migrating from `services.gitea-actions-runner', you will need to: + + 1. Find the old `.runner' file of your previously registered runner. You will need + to extract two values from it. Given the instance name of "${name}", you should + be able to find it at `/var/lib/gitea-runner/${name}/.runner'. + + 2. Read the contents of it, for example using `cat /var/lib/gitea-runner/native/.runner'. + + 3. Take note of the "uuid" and set the option `${options.settings}.server.connections.default.uuid' + to that value. For example "c9e50be9-a7c3-4aee-ba35-624c4ff8c519". + + 4. Take note of the "token" and replace the contents of your existing token file with it. + You no longer need to prefix the token with `TOKEN='. Put just the token in that file + and nothing else. + + 5. Rename `${options.tokenFile}' to `${options.secrets}.server.connections.default.token_url'. + '') + ]; + + config = mkIf config.enable { + assertions = [ + { + assertion = + lib.any (label: lib.hasInfix ":docker" label) (labels config) + -> ( + config.runtimes.docker + || config.runtimes.podman + # Mute assertion as an escape hatch for end-users + # that override our options.runtimes default. + || options.runtimes.docker.highestPrio < (lib.mkOptionDefault { }).priority + || options.runtimes.podman.highestPrio < (lib.mkOptionDefault { }).priority + ); + message = '' + The option `${options.settings}' has at least one label of + type `docker' configured, but no compatible container runtime enabled. + + You need to enable either + `config.virtualisation.docker.enable' or + `config.virtualisation.podman.enable'. + + If you are absolutely sure what you are doing + and are certain this is wrong, you can set + `${options.runtimes.docker}' or + `${options.runtimes.podman}' to dismiss this assertion. + ''; + } + { + assertion = config.settings.server.connections != { }; + message = '' + The option `${options.settings}.server.connections' requires at least one connection. + ''; + } + ] + ++ (foldlAttrs ( + assertions: _: connection: + assertions ++ connection.assertions + ) [ ] config.settings.server.connections); + }; + + options = { + enable = mkEnableOption "this Forgejo Runner instance"; + + settings = mkOption { + default = { }; + description = '' + Free-form settings written directly to the {file}`config.yaml` file. + Refer to [`config.example.yaml`] or run {command}`forgejo-runner generation-config` for supported values. + + [`config.example.yaml`]: https://code.forgejo.org/forgejo/runner/src/branch/main/internal/pkg/config/config.example.yaml + ''; + type = types.submodule { + freeformType = settingsFormat.type; + + config = lib.mapAttrsRecursive ( + path: _: "file:$CREDENTIALS_DIRECTORY/${lib.join "__" path}" + ) config.secrets; + + options = { + runner = { + labels = mkOption { + # TODO: Support new attrset format (yaml map) + # https://code.forgejo.org/forgejo/runner/pulls/1571 + type = types.listOf types.str; + example = literalExpression '' + [ + # provide a debian base with nodejs for actions + "debian-latest:docker://node:current" + # fake the ubuntu name, because node provides no ubuntu builds + "ubuntu-latest:docker://node:current" + # provide native execution on the host + #"native:host" + ] + ''; + description = '' + Labels used to map jobs to their runtime environment. + + Many common actions require {command}`bash`, {command}`git` and {command}`node`, + as well as a filesystem that follows the filesystem hierarchy standard. + + If you specify a label of type `docker`, the resulting runner service + will be automatically added to the *Podman* or *Docker* group. + + See . + + ::: {.note} + Labels of type [`lxc`] are currently not supported. + ::: + + [`lxc`]: https://forgejo.org/docs/latest/admin/actions/configuration/#lxc + ''; + }; + }; + + server = { + connections = mkOption { + default = { }; + description = '' + One or more connections to Forgejo instances, each with a UUID and Token pair. + + See . + + ::: {.note} + Ephemeral runner mode is not yet supported by this module. + ::: + ''; + example = literalExpression '' + { + default = { + url = "https://example.com/"; + uuid = "c9e50be9-a7c3-4aee-ba35-624c4ff8c519"; + + # Also see ${options.secrets}.server.connections..token_url + token = "6634bb58be0db23cc013a2e72dd1828ae0257cf"; + }; + } + ''; + type = types.attrsOf ( + types.submodule ( + { name, config, ... }: + + { + freeformType = settingsFormat.type; + + imports = [ + ../../misc/assertions.nix + ]; + + config = { + assertions = [ + { + assertion = + (config.token == null && config ? token_url && config.token_url != null) + || (config.token != null && config ? token_url && config.token_url == null) + || (config.token != null && !config ? token_url); + message = '' + The option `${options.settings}' needs to have exactly one of + `server.connections.${name}.token_url': ${ + if config ? token_url then lib.toJSON config.token_url else "" + } or + `server.connections.${name}.token': ${lib.toJSON config.token} + that is *not* null. + + Hint: + `${options.secrets}.server.connections.${name}.token_url' will set + `${options.settings}.server.connections.${name}.token_url' for you. + ''; + } + ]; + }; + + options = { + url = mkOption { + type = types.str; + example = "https://example.com/"; + description = '' + Base URL of your Forgejo instance. + ''; + }; + uuid = mkOption { + type = types.str; + example = "c9e50be9-a7c3-4aee-ba35-624c4ff8c519"; + description = '' + UUID of this runner. + + See . + ''; + }; + token = mkOption { + type = types.nullOr types.str; + example = "6634bb58be0db23cc013a2e72dd1828ae0257cf"; + description = '' + Token of this runner. + + See . + + ::: {.note} + The deprecated "Registration Token" is not supported. + You need a UUID and Token pair. + ::: + + ::: {.warning} + The value will be stored unencrypted in the world-readable Nix store. + To store the secret securely, see {option}`${options.secrets}.server.connections..token_url`. + ::: + ''; + }; + }; + } + ) + ); + }; + }; + }; + }; + }; + + secrets = mkOption { + type = secretsType; + default = { }; + description = '' + This follows the same structure as {option}`${options.settings}` + but the value of each key is a path. + + The specified secret path is then read by systemd via [`LoadCredential=`] + and templated into {option}`${options.settings}` for you. + + [`LoadCredential=`]: https://www.freedesktop.org/software/systemd/man/latest/systemd.exec.html#Credentials + ''; + example = literalExpression '' + { + server.connections.example = { + token_url = "/run/keys/forgejo-runner_token"; + }; + + cache = { + secret_url = "/run/keys/forgejo-runner_cache-secret"; + }; + } + ''; + }; + + hostPackages = mkOption { + type = types.listOf types.package; + default = with pkgs; [ + bash + coreutils + curl + gawk + gnused + nodejs + wget + ]; + defaultText = literalExpression '' + with pkgs; [ + bash + coreutils + curl + gawk + gnused + nodejs + wget + ] + ''; + description = '' + List of packages that are available to your workflow and actions when the + runner is configured with a label of type `host` ({option}`${options.runtimes.host}`). + + ::: {.note} + {command}`gitMinimal` is always part of the environment because {command}`forgejo-runner` + depends on it. If you need a different variant of {command}`git`, e.g. {command}`gitFull`, + add it here. Your package will take priority over {command}`gitMinimal`. + ::: + ''; + }; + + runtimes = { + host = mkOption { + type = types.bool; + default = lib.any (label: lib.hasSuffix ":host" label) (labels config); + defaultText = literalMD "Whether this instance has at least one label with suffix `:host`."; + description = '' + Whether to configure the systemd service for jobs with the backend of type `host`. + + ::: {.warning} + Setting this will override the automatic detection and safeguards. + ::: + ''; + }; + + docker = mkOption { + type = types.bool; + default = + lib.any (label: lib.hasInfix ":docker" label) (labels config) + && config'.virtualisation.docker.enable; + defaultText = literalMD '' + Whether this instance has at least one label with infix `:docker` + and {option}`config.virtualisation.docker.enable` set to `true`. + ''; + description = '' + Whether to configure the systemd service to work with Docker. + + ::: {.warning} + Setting this will override the automatic detection and safeguards. + ::: + ''; + }; + + podman = mkOption { + type = types.bool; + default = + lib.any (label: lib.hasInfix ":docker" label) (labels config) + && config'.virtualisation.podman.enable; + defaultText = literalMD '' + Whether this instance has at least one label with infix `:docker` + and {option}`config.virtualisation.podman.enable` set to `true`. + ''; + description = '' + Whether to configure the systemd service to work with Podman. + + ::: {.warning} + Setting this will override the automatic detection and safeguards. + ::: + ''; + }; + }; + + configFile = mkOption { + internal = true; + readOnly = true; + type = types.path; + default = settingsFormat.generate "config.yaml" ( + # Filter out remains of ../misc/assertions.nix. + # Note: This is for optics only, as forgejo-runner simply ignores settings it does not know. + lib.filterAttrsRecursive (n: _: n != "assertions" && n != "warnings") config.settings + ); + description = '' + Implementation detail for use in {file}`nixos/tests/forgejo.nix`. + + FIXME: Offload into top-level config once upstream supports {var}`uuid_url`. + ''; + }; + }; + } + ) + ); + }; + }; + + config = mkIf (cfg.instances != { }) { + assertions = ( + foldlAttrs ( + assertions: _: instance: + assertions ++ instance.assertions + ) [ ] cfg.instances + ); + + warnings = ( + foldlAttrs ( + warnings: _: instance: + warnings ++ instance.warnings + ) [ ] cfg.instances + ); + + systemd.services = lib.mapAttrs' ( + name: instance: + nameValuePair "forgejo-runner-${utils.escapeSystemdPath name}" { + inherit (instance) enable; + description = "Forgejo Runner"; + wants = [ "network-online.target" ]; + after = [ + "network-online.target" + ] + ++ optionals instance.runtimes.docker [ + "docker.service" + ] + ++ optionals instance.runtimes.podman [ + # TODO: Add support for rootless Podman + "podman.service" + ]; + wantedBy = [ + "multi-user.target" + ]; + environment = { + HOME = "/var/lib/forgejo-runner/${name}"; + }; + path = optionals instance.runtimes.host instance.hostPackages ++ [ pkgs.gitMinimal ]; + + serviceConfig = { + DynamicUser = true; + StateDirectory = "forgejo-runner/${name}"; + WorkingDirectory = "/var/lib/forgejo-runner/${name}"; + + # DynamicUser will try to use id-mapped mounts for exec directories, + # which has the side-effect of setting nosuid and noexec as mount option. + # Users of host runners expect to be able to execute scripts in their + # pipeline, so we override the noexec mount option by setting ExecPaths. + ExecPaths = optionals instance.runtimes.host [ "/var/lib/forgejo-runner/${name}" ]; + ExecStart = toString [ + (lib.getExe cfg.package) + "daemon" + "--config" + instance.configFile + ]; + + Restart = "on-failure"; + RestartSec = 10; + + LoadCredential = lib.mapAttrsToListRecursive ( + path: value: "${lib.join "__" path}:${value}" + ) instance.secrets; + + SupplementaryGroups = + optionals instance.runtimes.docker [ + "docker" + ] + ++ optionals instance.runtimes.podman [ + "podman" + ]; + }; + } + ) cfg.instances; + }; +} From 61124922a9e87a977617e40939713309d4ff9c07 Mon Sep 17 00:00:00 2001 From: emilylange Date: Mon, 8 Jun 2026 19:59:46 +0200 Subject: [PATCH 19/53] nixos/tests/forgejo: test `nixos/forgejo-runner` --- nixos/tests/forgejo.nix | 121 ++++++++++++++++++++++++++++++---------- 1 file changed, 90 insertions(+), 31 deletions(-) diff --git a/nixos/tests/forgejo.nix b/nixos/tests/forgejo.nix index 1dc3f5a53843..6bc767340d72 100644 --- a/nixos/tests/forgejo.nix +++ b/nixos/tests/forgejo.nix @@ -60,7 +60,7 @@ let ]; services.openssh.enable = true; - specialisation.runner = { + specialisation.gitea-actions-runner = { inheritParentConfig = true; configuration.services.gitea-actions-runner = { package = pkgs.forgejo-runner; @@ -76,6 +76,45 @@ let }; }; }; + specialisation.forgejo-runner = { + inheritParentConfig = true; + configuration = ( + { config, ... }: + + { + services.forgejo-runner = { + instances."test" = { + enable = true; + settings = { + runner.labels = [ + # type ":host" does not depend on docker/podman/lxc + "native:host" + ]; + server.connections.default = { + url = "http://localhost:3000"; + uuid = "@UUID@"; + }; + }; + secrets.server.connections.default.token_url = "/forgejo-runner_token"; + }; + }; + + # FIXME: Remove once upstream supports uuid_url just like token_url + systemd.services.forgejo-runner-test = { + preStart = '' + cp -v ${config.services.forgejo-runner.instances."test".configFile} ./config.yaml + chmod u+w ./config.yaml + ${lib.getExe pkgs.replace-secret} "@UUID@" "$CREDENTIALS_DIRECTORY/UUID" ./config.yaml + chmod u-w ./config.yaml + ''; + serviceConfig = { + ExecStart = lib.mkForce "${lib.getExe config.services.forgejo-runner.package} daemon --config ./config.yaml"; + LoadCredential = [ "UUID:/forgejo-runner_uuid" ]; + }; + }; + } + ); + }; specialisation.dump = { inheritParentConfig = true; configuration.services.forgejo.dump = { @@ -172,7 +211,7 @@ let + "Please contact your site administrator.'" ) server.succeed( - "su -l forgejo -c 'GITEA_WORK_DIR=/var/lib/forgejo forgejo admin user create " + "su -l forgejo -c 'GITEA_WORK_DIR=/var/lib/forgejo forgejo admin user create --admin " + "--username test --password totallysafe --email test@localhost --must-change-password=false'" ) @@ -217,22 +256,22 @@ let server.fail("curl --fail http://localhost:3000/metrics") server.succeed('curl --fail http://localhost:3000/metrics -H "Authorization: Bearer ${metricSecret}"') - with subtest("Testing runner registration and action workflow"): - server.succeed( - "su -l forgejo -c 'GITEA_WORK_DIR=/var/lib/forgejo forgejo actions generate-runner-token' | sed 's/^/TOKEN=/' | tee /var/lib/forgejo/runner_token" - ) - server.succeed("${serverSystem}/specialisation/runner/bin/switch-to-configuration test") - server.wait_for_unit("gitea-runner-test.service") - server.succeed("journalctl -o cat -u gitea-runner-test.service | grep -q 'Runner registered successfully'") + def poll_workflow_action_status(id: int) -> bool: + try: + response = server.succeed("curl --fail http://localhost:3000/api/v1/repos/test/repo/actions/tasks") + status = json.loads(response).get("workflow_runs")[id].get("status") - # enable actions feature for this repository, defaults to disabled - server.succeed( - "curl --fail -X PATCH http://localhost:3000/api/v1/repos/test/repo " - + "-H 'Accept: application/json' -H 'Content-Type: application/json' " - + f"-H 'Authorization: token {api_token}'" - + ' -d \'{"has_actions":true}\''' - ) + except IndexError: + status = "???" + server.log(f"Workflow status: {status}") + + if status == "failure": + raise Exception("Workflow failed") + + return status == "success" + + with subtest("Testing deprecated gitea-actions-runner registration and action workflow"): # mirror "actions/checkout" action client.succeed("cp -R ${checkoutActionSource}/ /tmp/checkout") client.succeed("git -C /tmp/checkout init") @@ -248,23 +287,43 @@ let client.succeed("git -C /tmp/repo commit -m 'Add dummy workflow'") client.succeed("git -C /tmp/repo push origin main") - def poll_workflow_action_status(_) -> bool: - try: - response = server.succeed("curl --fail http://localhost:3000/api/v1/repos/test/repo/actions/tasks") - status = json.loads(response).get("workflow_runs")[0].get("status") - - except IndexError: - status = "???" - - server.log(f"Workflow status: {status}") - - if status == "failure": - raise Exception("Workflow failed") - - return status == "success" + # enable actions feature for this repository, defaults to disabled + server.succeed( + "curl --fail -X PATCH http://localhost:3000/api/v1/repos/test/repo " + + "-H 'Accept: application/json' -H 'Content-Type: application/json' " + + f"-H 'Authorization: token {api_token}'" + + ' -d \'{"has_actions":true}\''' + ) + server.succeed( + "su -l forgejo -c 'GITEA_WORK_DIR=/var/lib/forgejo forgejo actions generate-runner-token' | sed 's/^/TOKEN=/' | tee /var/lib/forgejo/runner_token" + ) + server.succeed("${serverSystem}/specialisation/gitea-actions-runner/bin/switch-to-configuration test") + server.wait_for_unit("gitea-runner-test.service") + server.succeed("journalctl -o cat -u gitea-runner-test.service | grep -q 'Runner registered successfully'") with server.nested("Waiting for the workflow run to be successful"): - retry(poll_workflow_action_status, 60) + retry(lambda _: poll_workflow_action_status(0), 180) + + with subtest("Testing forgejo-runner registration and action workflow"): + runner_registration_response = server.succeed( + "curl --fail http://localhost:3000/api/v1/admin/actions/runners " + + f"-H 'Authorization: token {api_token}' " + + '--json \'{"name":"NixOS", "ephemeral":false}\''' + ) + + runner_registration = json.loads(runner_registration_response) + server.succeed(f"echo {runner_registration.get("token")} > /forgejo-runner_token") + server.succeed(f"echo {runner_registration.get("uuid")} > /forgejo-runner_uuid") + + server.succeed("${serverSystem}/specialisation/forgejo-runner/bin/switch-to-configuration test") + server.wait_for_unit("forgejo-runner-test.service") + server.succeed("journalctl -o cat -u forgejo-runner-test.service | grep -q 'declared successfully'") + + client.succeed("git -C /tmp/repo commit --allow-empty -m 'Retrigger dummy workflow'") + client.succeed("git -C /tmp/repo push origin main") + + with server.nested("Waiting for the workflow run to be successful"): + retry(lambda _: poll_workflow_action_status(1), 180) with subtest("Testing backup service"): server.succeed("${serverSystem}/specialisation/dump/bin/switch-to-configuration test") From d505edf7a4f7db476e7c9c474906c4731944baec Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 15 Aug 2026 17:36:40 +0000 Subject: [PATCH 20/53] go-musicfox: 4.8.1 -> 5.1.0 --- pkgs/by-name/go/go-musicfox/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/go/go-musicfox/package.nix b/pkgs/by-name/go/go-musicfox/package.nix index 006fddff5385..0b1a6e032323 100644 --- a/pkgs/by-name/go/go-musicfox/package.nix +++ b/pkgs/by-name/go/go-musicfox/package.nix @@ -11,18 +11,18 @@ buildGoModule (finalAttrs: { pname = "go-musicfox"; - version = "4.8.1"; + version = "5.1.0"; src = fetchFromGitHub { owner = "go-musicfox"; repo = "go-musicfox"; rev = "v${finalAttrs.version}"; - hash = "sha256-EwN8tWoyghG9L++Tl5iz2ZyNsI5IroZXM0Dd5N182dU="; + hash = "sha256-gM3gnUbevPSa2gmiC0DGYPrVRtwHF2TQB0Hu99ISVU8="; }; deleteVendor = true; - vendorHash = "sha256-MEcdWJts7hzt8fuhVsxHl1mQ57R8vNd3H3Tmpx4A9a4="; + vendorHash = "sha256-+lmsd7fqdlKxxXGh6Zwl9xtNXPZrR3xqgROzI9L4xls="; subPackages = [ "cmd/musicfox.go" ]; From 7b8deb1f2373e04031d5655d3f5061609cdd846f Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 15 Aug 2026 20:20:57 +0000 Subject: [PATCH 21/53] python3Packages.unidata-blocks: 0.0.25 -> 0.0.26 --- pkgs/development/python-modules/unidata-blocks/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/unidata-blocks/default.nix b/pkgs/development/python-modules/unidata-blocks/default.nix index 2fb62a70f06f..b505349387f5 100644 --- a/pkgs/development/python-modules/unidata-blocks/default.nix +++ b/pkgs/development/python-modules/unidata-blocks/default.nix @@ -10,14 +10,14 @@ buildPythonPackage (finalAttrs: { pname = "unidata-blocks"; - version = "0.0.25"; + version = "0.0.26"; pyproject = true; src = fetchFromGitHub { owner = "TakWolf"; repo = "unidata-blocks"; tag = finalAttrs.version; - hash = "sha256-BWcKqTMYdJ59XncPL29wCms2kCVTrcrV1zSY8mkbErs="; + hash = "sha256-pGFZc1LeatyH1tB1JCijKYKovcjFafGB0G+2tUhHgYY="; }; build-system = [ uv-build ]; From 916a2b92fb3d2b02382dfd3cd92db4487096bb2f Mon Sep 17 00:00:00 2001 From: coolcuber Date: Sat, 15 Aug 2026 16:55:07 -0400 Subject: [PATCH 22/53] fffuu: fix version, use hash --- pkgs/tools/misc/fffuu/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/tools/misc/fffuu/default.nix b/pkgs/tools/misc/fffuu/default.nix index 9a9d57f15425..07459d0251aa 100644 --- a/pkgs/tools/misc/fffuu/default.nix +++ b/pkgs/tools/misc/fffuu/default.nix @@ -7,13 +7,13 @@ mkDerivation { pname = "fffuu"; - version = "unstable-2018-05-26"; + version = "0.1.0.0-unstable-2018-05-26"; src = fetchFromGitHub { owner = "diekmann"; repo = "Iptables_Semantics"; rev = "e0a2516bd885708fce875023b474ae341cbdee29"; - sha256 = "1qc7p44dqja6qrjbjdc2xn7n9v41j5v59sgjnxjj5k0mxp58y1ch"; + hash = "sha256-kAWPyu0VzCJlt/LpVHaRgexkj+2CNblkxkZJ3Ai5h+E="; }; postUnpack = '' From dcaa2f6d5df50aa0cc4c3039731f146a1c5643eb Mon Sep 17 00:00:00 2001 From: coolcuber Date: Sat, 15 Aug 2026 17:04:56 -0400 Subject: [PATCH 23/53] filegive: fix version, use finalAttrs --- pkgs/by-name/fi/filegive/package.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/fi/filegive/package.nix b/pkgs/by-name/fi/filegive/package.nix index 490f661b733f..ee582da96186 100644 --- a/pkgs/by-name/fi/filegive/package.nix +++ b/pkgs/by-name/fi/filegive/package.nix @@ -4,13 +4,13 @@ fetchurl, }: -buildGoModule rec { +buildGoModule (finalAttrs: { pname = "filegive"; - version = "unstable-2022-05-29"; + version = "0.8.0-unstable-2022-05-29"; rev = "5b28e7087a"; src = fetchurl { - url = "https://viric.name/cgi-bin/filegive/tarball/${rev}/filegive-${rev}.tar.gz"; + url = "https://viric.name/cgi-bin/filegive/tarball/${finalAttrs.rev}/filegive-${finalAttrs.rev}.tar.gz"; hash = "sha256-A69oys59GEysZvQLaYsfoX/X2ENMMH2BGfJqXohQjpc="; }; @@ -28,4 +28,4 @@ buildGoModule rec { maintainers = [ ]; mainProgram = "filegive"; }; -} +}) From 257b5857b4a7fea67dc7bedd67f0e20d3ec2367b Mon Sep 17 00:00:00 2001 From: coolcuber Date: Sat, 15 Aug 2026 17:10:55 -0400 Subject: [PATCH 24/53] finalfrontier: fix version, use hash --- pkgs/by-name/fi/finalfrontier/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/fi/finalfrontier/package.nix b/pkgs/by-name/fi/finalfrontier/package.nix index 986d9a9b114c..afca8bbf8b62 100644 --- a/pkgs/by-name/fi/finalfrontier/package.nix +++ b/pkgs/by-name/fi/finalfrontier/package.nix @@ -11,13 +11,13 @@ rustPlatform.buildRustPackage { pname = "finalfrontier"; - version = "unstable-2022-01-06"; + version = "0.9.4-unstable-2022-01-06"; src = fetchFromGitHub { owner = "finalfusion"; repo = "finalfrontier"; rev = "2461fb1dde13b73039926aa66606e470907a1b59"; - sha256 = "sha256-bnRzXIYairlBjv2JxU16UXYc5BB3VeKZNiJ4+XDzub4="; + hash = "sha256-bnRzXIYairlBjv2JxU16UXYc5BB3VeKZNiJ4+XDzub4="; }; cargoHash = "sha256-AQiXRKOXV7kXiu9GbtPE0Rddy93t1Y5tuJmww4xFSaU="; From 61ab1560835c76a562d1ca63f39fb1120836efbf Mon Sep 17 00:00:00 2001 From: Aliaksandr Date: Mon, 18 May 2026 00:21:22 +0300 Subject: [PATCH 25/53] nixos/fwupd: don't install grub hook on non-grub bootloaders The fwupd package ships /etc/grub.d/35_fwupd, which the module symlinks unconditionally via filesInstalledToEtc. Gate it on config.boot.loader.grub.enable option so the hook only appears on GRUB systems. Assisted-by: claude-code with Opus 4.7 xhigh --- nixos/modules/services/hardware/fwupd.nix | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/nixos/modules/services/hardware/fwupd.nix b/nixos/modules/services/hardware/fwupd.nix index 7ba25207cf23..9c0a9cedc4a7 100644 --- a/nixos/modules/services/hardware/fwupd.nix +++ b/nixos/modules/services/hardware/fwupd.nix @@ -31,8 +31,11 @@ let originalEtc = let mkEtcFile = n: lib.nameValuePair n { source = "${cfg.package}/etc/${n}"; }; + etcFiles = lib.filter ( + f: config.boot.loader.grub.enable || f != "grub.d/35_fwupd" + ) cfg.package.filesInstalledToEtc; in - lib.listToAttrs (map mkEtcFile cfg.package.filesInstalledToEtc); + lib.listToAttrs (map mkEtcFile etcFiles); extraTrustedKeys = let mkName = p: "pki/fwupd/${baseNameOf p}"; From a1b280a969e4ffa5a1eb3d0964021a9f7004ffd0 Mon Sep 17 00:00:00 2001 From: Anton Lydike Date: Mon, 7 Jul 2025 15:58:12 +0100 Subject: [PATCH 26/53] nixos/fwupd: add missing lib.mkDefault for EspLocation --- nixos/modules/services/hardware/fwupd.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/nixos/modules/services/hardware/fwupd.nix b/nixos/modules/services/hardware/fwupd.nix index 9c0a9cedc4a7..3ff901e257d9 100644 --- a/nixos/modules/services/hardware/fwupd.nix +++ b/nixos/modules/services/hardware/fwupd.nix @@ -187,7 +187,7 @@ in config = lib.mkIf cfg.enable { # Disable test related plug-ins implicitly so that users do not have to care about them. services.fwupd.daemonSettings = { - EspLocation = config.boot.loader.efi.efiSysMountPoint; + EspLocation = lib.mkDefault config.boot.loader.efi.efiSysMountPoint; }; environment.systemPackages = [ cfg.package ]; From ed34dae9123b4b5075b9a1d328cc05afd58b4e16 Mon Sep 17 00:00:00 2001 From: coolcuber Date: Sat, 15 Aug 2026 17:58:21 -0400 Subject: [PATCH 27/53] fverb: fix version, modernize --- pkgs/by-name/fv/fverb/package.nix | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/fv/fverb/package.nix b/pkgs/by-name/fv/fverb/package.nix index 532360cf4156..0328cddf74cb 100644 --- a/pkgs/by-name/fv/fverb/package.nix +++ b/pkgs/by-name/fv/fverb/package.nix @@ -8,13 +8,16 @@ stdenv.mkDerivation { pname = "fverb"; # no release yet: https://github.com/jpcima/fverb/issues/2 - version = "unstable-2020-06-09"; + version = "0-unstable-2020-06-09"; + + __structuredAttrs = true; + strictDeps = true; src = fetchFromGitHub { owner = "jpcima"; repo = "fverb"; rev = "462020e33e24c0204a375dc95e2c28654cc917b8"; - sha256 = "12nl7qn7mnykk7v8q0j2n8kfq0xc46n0i45z6qcywspadwnncmd4"; + hash = "sha256-pFVmLW/qau4ZNr+QCKwhrAPsJrJCAoz2mdPbeiw+1Io="; fetchSubmodules = true; }; From 06994a3768acd99a957534a870efb37f301cad91 Mon Sep 17 00:00:00 2001 From: Raito Bezarius Date: Wed, 27 May 2026 11:36:33 +0200 Subject: [PATCH 28/53] fwupd: move EFI app location in /run This introduces a breaking change where the default location for EFI apps are now in /run/fwupd-efi. This is not breaking for lanzaboote users who already had the environment variable setting but this setting was removed in https://github.com/fwupd/fwupd/pull/9846. Since 2.1.6 this no longer needs a meson.build patch: upstream exposes the location as the `efi_app_location` meson option, which we already set to point at the fwupd-efi store path. Point it at the runtime directory instead; the NixOS module populates it from `fwupd.fwupd-efi`. Ref: https://github.com/fwupd/fwupd/issues/10202 Change-Id: Ie058ece7d284cbce960fdf0ce14a151f1cf269ca Signed-off-by: Raito Bezarius Co-authored-by: Aliaksandr Assisted-by: claude-code with claude-opus-5[1m]-high --- pkgs/by-name/fw/fwupd/package.nix | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/fw/fwupd/package.nix b/pkgs/by-name/fw/fwupd/package.nix index e1e818279f73..3cbf4946597f 100644 --- a/pkgs/by-name/fw/fwupd/package.nix +++ b/pkgs/by-name/fw/fwupd/package.nix @@ -233,8 +233,10 @@ stdenv.mkDerivation (finalAttrs: { "--sysconfdir=/etc" (lib.mesonOption "sysconfdir_install" "${placeholder "out"}/etc") (lib.mesonOption "efi_os_dir" "nixos") - # Use the EFI app from the separate fwupd-efi package. - (lib.mesonOption "efi_app_location" "${fwupd-efi}/libexec/fwupd/efi") + # Signing setups (lanzaboote, sbctl, …) must place the signed EFI app next + # to the unsigned one, which the store does not allow. + # https://github.com/fwupd/fwupd/issues/10202 + (lib.mesonOption "efi_app_location" "/run/fwupd-efi") # HSI is auto-disabled on non-x86 upstream; auto_features=enabled overrides # that, breaking the fwupdtool installed test which expects rc=1 on non-x86. (lib.mesonEnable "hsi" isx86) From eeff2987185d93834a8f424d050b6f300b54cb3e Mon Sep 17 00:00:00 2001 From: Aliaksandr Date: Sun, 16 Aug 2026 01:24:15 +0300 Subject: [PATCH 29/53] nixos/fwupd: populate /run/fwupd-efi via systemd-tmpfiles fwupd is now built with `efi_app_location = /run/fwupd-efi` so that setups signing their EFI binaries (lanzaboote, sbctl, ...) can place the signed app next to the unsigned one, which is impossible inside the read-only store. Nothing created that directory yet, so copy the unsigned app there from `fwupd.fwupd-efi`. `C+` merges into an existing directory without replacing files, so signed variants written by a bootloader module are kept; the copy is refreshed whenever the rule (and thus the fwupd-efi store path) changes. Assisted-by: claude-code with claude-opus-5[1m]-high --- nixos/modules/services/hardware/fwupd.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/nixos/modules/services/hardware/fwupd.nix b/nixos/modules/services/hardware/fwupd.nix index 3ff901e257d9..7c64c936f4c8 100644 --- a/nixos/modules/services/hardware/fwupd.nix +++ b/nixos/modules/services/hardware/fwupd.nix @@ -205,6 +205,12 @@ in systemd = { packages = [ cfg.package ]; + # fwupd looks for its EFI app in /run/fwupd-efi so that signed variants can + # be placed next to it; `C+` keeps those signed files across a rebuild. + tmpfiles.rules = [ + "C+ /run/fwupd-efi - - - - ${cfg.package.fwupd-efi}/libexec/fwupd/efi" + ]; + # The upstream unit runs as User=fwupd-refresh; ensure it can take # ownership of /var/lib/fwupd. services.fwupd-refresh.serviceConfig = { From 6ccc493231c9024c3b80614c32fbb14b4cddc2b4 Mon Sep 17 00:00:00 2001 From: Aliaksandr Date: Sun, 16 Aug 2026 01:24:16 +0300 Subject: [PATCH 30/53] nixos/limine: drop dead FWUPD_EFIAPPDIR override fwupd stopped honouring the FWUPD_EFIAPPDIR environment variable in https://github.com/fwupd/fwupd/pull/9846; the location is a compile-time constant (`EFI_APP_LOCATION`) since then, so setting the variable on fwupd.service had no effect. Drop `RuntimeDirectory` from the signing unit too: the directory is now created and populated by the fwupd module, and RuntimeDirectoryPreserve defaults to `no`, so systemd removed it (together with the unsigned app) whenever the unit stopped -- which `partOf = fwupd.service` makes happen on every fwupd restart. Cover the whole path in the limine secure boot test, which so far never enabled fwupd: it now asserts that both the unsigned app and the signed variant end up in /run/fwupd-efi. Assisted-by: claude-code with claude-opus-5[1m]-high --- nixos/modules/system/boot/loader/limine/limine.nix | 7 ++----- nixos/tests/limine/secure-boot.nix | 9 +++++++++ 2 files changed, 11 insertions(+), 5 deletions(-) diff --git a/nixos/modules/system/boot/loader/limine/limine.nix b/nixos/modules/system/boot/loader/limine/limine.nix index 956fa78800ef..f84ff61e66fb 100644 --- a/nixos/modules/system/boot/loader/limine/limine.nix +++ b/nixos/modules/system/boot/loader/limine/limine.nix @@ -506,21 +506,18 @@ in # Fwupd binary needs to be signed in secure boot mode (lib.mkIf (cfg.enable && cfg.secureBoot.enable && config.services.fwupd.enable) { - systemd.services.fwupd = { - environment.FWUPD_EFIAPPDIR = "/run/fwupd-efi"; - }; - systemd.services.fwupd-efi = { description = "Sign fwupd EFI app for secure boot"; wantedBy = [ "fwupd.service" ]; partOf = [ "fwupd.service" ]; before = [ "fwupd.service" ]; + # /run/fwupd-efi is populated by the fwupd module. + after = [ "systemd-tmpfiles-setup.service" ]; unitConfig.ConditionPathIsDirectory = "/var/lib/sbctl"; serviceConfig = { Type = "oneshot"; RemainAfterExit = true; - RuntimeDirectory = "fwupd-efi"; }; script = '' diff --git a/nixos/tests/limine/secure-boot.nix b/nixos/tests/limine/secure-boot.nix index 798b200dee32..d8e8001e99cb 100644 --- a/nixos/tests/limine/secure-boot.nix +++ b/nixos/tests/limine/secure-boot.nix @@ -29,11 +29,20 @@ boot.loader.limine.secureBoot.autoEnrollKeys.extraArgs = [ "--yes-this-might-brick-my-machine" ]; boot.loader.timeout = 0; + services.fwupd.enable = true; + environment.systemPackages = [ pkgs.mokutil ]; }; testScript = '' machine.start() assert "SecureBoot enabled" in machine.succeed("mokutil --sb-state") + + # fwupd is D-Bus activated, so the signing unit only runs on demand. + machine.succeed("systemctl start fwupd.service") + machine.wait_for_unit("fwupd-efi.service") + # the unsigned app is copied in by the fwupd module, the signed one added here + machine.succeed("ls /run/fwupd-efi/fwupd*.efi") + machine.succeed("ls /run/fwupd-efi/fwupd*.efi.signed") ''; } From a4922c454b56487b6ebaf0ce6bbd38f47503810b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Sat, 15 Aug 2026 18:28:21 -0700 Subject: [PATCH 31/53] deltachat-desktop: 2.57.0 -> 2.59.0 Diff: https://github.com/deltachat/deltachat-desktop/compare/v2.57.0...v2.59.0 Changelog: https://github.com/deltachat/deltachat-desktop/blob/v2.59.0/CHANGELOG.md --- pkgs/by-name/de/deltachat-desktop/package.nix | 12 ++++++------ pkgs/by-name/de/deltachat-tauri/package.nix | 2 +- 2 files changed, 7 insertions(+), 7 deletions(-) diff --git a/pkgs/by-name/de/deltachat-desktop/package.nix b/pkgs/by-name/de/deltachat-desktop/package.nix index 7d0ce38c1cfe..274ef0faf047 100644 --- a/pkgs/by-name/de/deltachat-desktop/package.nix +++ b/pkgs/by-name/de/deltachat-desktop/package.nix @@ -22,38 +22,38 @@ let deltachat-rpc-server' = deltachat-rpc-server.overrideAttrs rec { - version = "2.57.0"; + version = "2.59.0"; src = fetchFromGitHub { owner = "chatmail"; repo = "core"; tag = "v${version}"; - hash = "sha256-MZhb3w4khWjWGEA9XvXgHjYiY9hQ5jCBWRwu6yMuaho="; + hash = "sha256-I0CZxuHVBQCbvMfaPUL+W1HU8plL7kKo53bSbUZskNE="; }; cargoDeps = rustPlatform.fetchCargoVendor { pname = "chatmail-core"; inherit version src; - hash = "sha256-gRtNhrKue2cMhq3J/jFQihJTpa6k1IJeIJ9C5hAbiOM="; + hash = "sha256-oI/btypttMFLxAe2shYoLbHqwXMhlqzschORHoAQ/Wc="; }; }; electron = electron_42; in stdenv.mkDerivation (finalAttrs: { pname = "deltachat-desktop"; - version = "2.57.0"; + version = "2.59.0"; __structuredAttrs = true; src = fetchFromGitHub { owner = "deltachat"; repo = "deltachat-desktop"; tag = "v${finalAttrs.version}"; - hash = "sha256-HQP8O2c2xSJDY4PEicyIW8md5ux0HExjiRp8uoPhIlo="; + hash = "sha256-Qr9QCH62Hd41rihaxB4nYwa68qiB4HDxx2333DkRkvA="; }; pnpmDeps = fetchPnpmDeps { inherit (finalAttrs) pname version src; pnpm = pnpm_10; fetcherVersion = 4; - hash = "sha256-ATfjQbCZDvTWjq3iUTTcKkRm9bbFFIJ2Dm7p3IyoIxg="; + hash = "sha256-RApYXI5k/CQGe/6K9vGWqP+C125xqNMEqjiE4W42TMc="; }; strictDeps = true; diff --git a/pkgs/by-name/de/deltachat-tauri/package.nix b/pkgs/by-name/de/deltachat-tauri/package.nix index 4f6278c73cbf..17ac129b8ef8 100644 --- a/pkgs/by-name/de/deltachat-tauri/package.nix +++ b/pkgs/by-name/de/deltachat-tauri/package.nix @@ -35,7 +35,7 @@ rustPlatform.buildRustPackage (finalAttrs: { ; __structuredAttrs = true; - cargoHash = "sha256-0/TmIwg8y1vUN9SvlBhKQ3krvdaBcWFfk/+CVhBgXaU="; + cargoHash = "sha256-Z3uZ+IARmCZbJiIotYjdQRzYZFplRwE3xO0Yb0tLbcE="; postPatch = lib.optionalString stdenv.hostPlatform.isLinux '' substituteInPlace $cargoDepsCopy/*/libappindicator-sys-*/src/lib.rs \ From 234007a3546333e3bbb5ad0d43d9698840cc9ffc Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 16 Aug 2026 05:27:04 +0000 Subject: [PATCH 32/53] xenia-canary: 0-unstable-2026-08-06 -> 0-unstable-2026-08-13 --- pkgs/by-name/xe/xenia-canary/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/xe/xenia-canary/package.nix b/pkgs/by-name/xe/xenia-canary/package.nix index 3be2a856e020..7ed8c138ba22 100644 --- a/pkgs/by-name/xe/xenia-canary/package.nix +++ b/pkgs/by-name/xe/xenia-canary/package.nix @@ -33,14 +33,14 @@ let in llvmPackages_20.stdenv.mkDerivation { pname = "xenia-canary"; - version = "0-unstable-2026-08-06"; + version = "0-unstable-2026-08-13"; src = fetchFromGitHub { owner = "xenia-canary"; repo = "xenia-canary"; fetchSubmodules = true; - rev = "6a454520877624f35ac5e2c34b4e8317c34f1ab6"; - hash = "sha256-zFr7BHcWVjNWQtKHihutC4AP/xZv+23+Qjb+vqdy2nU="; + rev = "907d92bf8cfad334cb1b83755f48b6bfea391806"; + hash = "sha256-5ATxs7iD5QS7VKAevRNOfCAAjMRDLuk5djAQrhBMnfQ="; }; dontConfigure = true; From 2fcdc0468c0b34828ace7cd591074217f97963c1 Mon Sep 17 00:00:00 2001 From: ReBiz <70316178+rebizzz@users.noreply.github.com> Date: Sun, 16 Aug 2026 15:27:37 +0530 Subject: [PATCH 33/53] lact: 0.9.1 -> 0.10.0 --- pkgs/by-name/la/lact/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/la/lact/package.nix b/pkgs/by-name/la/lact/package.nix index 26aaa4854f0f..836a53e5cd40 100644 --- a/pkgs/by-name/la/lact/package.nix +++ b/pkgs/by-name/la/lact/package.nix @@ -26,16 +26,16 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "lact"; - version = "0.9.1"; + version = "0.10.0"; src = fetchFromGitHub { owner = "ilya-zlobintsev"; repo = "LACT"; tag = "v${finalAttrs.version}"; - hash = "sha256-/b5Cfexi/RtE3DkON5J3dc4aEX6aLZvIcAhsg6Kdv7M="; + hash = "sha256-dLy/q+PfnHfNJ/PS7Y7MVfiZ5ZoYM+6PpHrUTpdvCp4="; }; - cargoHash = "sha256-XV37VRbCaxySMgEqXmIA0TUpI9uR+6jGOzdMlEfWxDw="; + cargoHash = "sha256-h1czRa3xBXhQYZlNHo2psGD7r3AnDiplUWauO4+/l30="; nativeBuildInputs = [ pkg-config From b35ff61cd79059b78cd3b86e3f4513475c8a5502 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 16 Aug 2026 11:36:33 +0000 Subject: [PATCH 34/53] xbyak: 7.38 -> 7.40 --- pkgs/by-name/xb/xbyak/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/xb/xbyak/package.nix b/pkgs/by-name/xb/xbyak/package.nix index faa83b7bd72b..9e37ae745272 100644 --- a/pkgs/by-name/xb/xbyak/package.nix +++ b/pkgs/by-name/xb/xbyak/package.nix @@ -6,13 +6,13 @@ }: stdenv.mkDerivation (finalAttrs: { pname = "xbyak"; - version = "7.38"; + version = "7.40"; src = fetchFromGitHub { owner = "herumi"; repo = "xbyak"; tag = "v${finalAttrs.version}"; - hash = "sha256-EHQSUZt0fvR1GZBpMqBuXxlPt3j3cLKTtc9JNkCNlt4="; + hash = "sha256-4AELojCkOK0O9Rs9DwR4otZOcEFnNKRG4VAJFoX5Bds="; }; nativeBuildInputs = [ cmake ]; From 39a84e7002087c96802809b5688b4f39103f3c91 Mon Sep 17 00:00:00 2001 From: nikp123 Date: Mon, 23 Feb 2026 16:21:15 +0100 Subject: [PATCH 35/53] platformio-chrootenv: Add libusb1 as a chroot dep The reason why we need this as a chroot dependency is because some tools that get installed via platformio will depend on libusb for proper functionality (like minichlink). As an example: minichlink is NOT packaged in nix and it requires libusb to talk to the flashers for ch32 series of chips. --- pkgs/by-name/pl/platformio-chrootenv/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/pl/platformio-chrootenv/package.nix b/pkgs/by-name/pl/platformio-chrootenv/package.nix index 6e9b2710320c..1a0f6fe5644f 100644 --- a/pkgs/by-name/pl/platformio-chrootenv/package.nix +++ b/pkgs/by-name/pl/platformio-chrootenv/package.nix @@ -14,6 +14,7 @@ let platformio-core zlib git + libusb1 xdg-user-dirs ncurses udev From 67e2fe3505494d792ef65b529c8e598b2d93ebf7 Mon Sep 17 00:00:00 2001 From: nikp123 Date: Fri, 14 Aug 2026 17:44:04 +0200 Subject: [PATCH 36/53] maintainer: add nikp123 --- maintainers/maintainer-list.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/maintainers/maintainer-list.nix b/maintainers/maintainer-list.nix index 331e80e39beb..653fe3e4cd38 100644 --- a/maintainers/maintainer-list.nix +++ b/maintainers/maintainer-list.nix @@ -20533,6 +20533,12 @@ githubId = 70602908; github = "nikolaizombie1"; }; + nikp123 = { + name = "nikp123"; + email = "nikp123@e.email"; + github = "nikp123"; + githubId = 4696350; + }; nikstur = { email = "nikstur@outlook.com"; name = "nikstur"; From 1b9c1f0fb94d1cfc9c8cf8c722e1f3be7589a310 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 16 Aug 2026 18:24:35 +0000 Subject: [PATCH 37/53] xremap: 0.15.10 -> 0.15.11 --- pkgs/by-name/xr/xremap/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/xr/xremap/package.nix b/pkgs/by-name/xr/xremap/package.nix index c6138945a2d9..39dcbf1869cd 100644 --- a/pkgs/by-name/xr/xremap/package.nix +++ b/pkgs/by-name/xr/xremap/package.nix @@ -58,13 +58,13 @@ assert ( ); rustPlatform.buildRustPackage (finalAttrs: { pname = "xremap${variant.suffix or ""}"; - version = "0.15.10"; + version = "0.15.11"; src = fetchFromGitHub { owner = "xremap"; repo = "xremap"; tag = "v${finalAttrs.version}"; - hash = "sha256-tOQ5q+Xg7JN2P9c1UEG7s9hysC+Z06wxiJ0yPweA4fw="; + hash = "sha256-N5JItxzg0nU9hsW+fOEJ9FHiq6L0rt8jXvieefuHc5k="; }; nativeBuildInputs = [ pkg-config ]; @@ -72,7 +72,7 @@ rustPlatform.buildRustPackage (finalAttrs: { buildNoDefaultFeatures = true; buildFeatures = variant.features; - cargoHash = "sha256-HbM6UwGRyQIS/Sq0OQdm0eYok6CemTOu88i4w7X5aIY="; + cargoHash = "sha256-45YN1ZjM485phmvMNOna/hXE+EorZcz3xLpTVZIWZn8="; passthru = lib.mapAttrs (name: lib.const (xremap.override { withVariant = name; })) variants; From 8cc89f6ea8eb92fed700dfb84d519c7a6f029e11 Mon Sep 17 00:00:00 2001 From: nikp123 Date: Sun, 16 Aug 2026 19:21:44 +0200 Subject: [PATCH 38/53] platformio-chrootenv: add nikp123 as maintainer Co-authored-by: Sandro --- pkgs/by-name/pl/platformio-chrootenv/package.nix | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/pl/platformio-chrootenv/package.nix b/pkgs/by-name/pl/platformio-chrootenv/package.nix index 1a0f6fe5644f..4dd6c4aee6fd 100644 --- a/pkgs/by-name/pl/platformio-chrootenv/package.nix +++ b/pkgs/by-name/pl/platformio-chrootenv/package.nix @@ -45,7 +45,10 @@ buildFHSEnv { meta = { description = "Open source ecosystem for IoT development"; homepage = "https://platformio.org"; - maintainers = with lib.maintainers; [ mog ]; + maintainers = with lib.maintainers; [ + mog + nikp123 + ]; license = lib.licenses.asl20; platforms = with lib.platforms; linux; }; From 0d5649a5c4c508aad406005ce6c7daba6513dc9a Mon Sep 17 00:00:00 2001 From: Lucas Fernando Cardoso Nunes Date: Fri, 22 May 2026 21:53:55 -0300 Subject: [PATCH 39/53] nixos/dnscrypt-proxy: refactor settings type --- .../services/networking/dnscrypt-proxy.nix | 3 ++- nixos/tests/dnscrypt-proxy.nix | 21 ++++++++++++++++--- 2 files changed, 20 insertions(+), 4 deletions(-) diff --git a/nixos/modules/services/networking/dnscrypt-proxy.nix b/nixos/modules/services/networking/dnscrypt-proxy.nix index 5f9acc6d025c..202eac103a9b 100644 --- a/nixos/modules/services/networking/dnscrypt-proxy.nix +++ b/nixos/modules/services/networking/dnscrypt-proxy.nix @@ -8,6 +8,7 @@ let cfg = config.services.dnscrypt-proxy; + settingsFormat = pkgs.formats.toml { }; in @@ -36,7 +37,7 @@ in }; } ''; - type = lib.types.attrs; + type = settingsFormat.type; default = { }; }; diff --git a/nixos/tests/dnscrypt-proxy.nix b/nixos/tests/dnscrypt-proxy.nix index 72a65f449670..683641196d6b 100644 --- a/nixos/tests/dnscrypt-proxy.nix +++ b/nixos/tests/dnscrypt-proxy.nix @@ -1,6 +1,7 @@ { lib, ... }: let localProxyPort = 43; + localProxyExtraPort = 44; in { name = "dnscrypt-proxy"; @@ -12,11 +13,21 @@ in client = { ... }: { - security.apparmor.enable = true; + imports = [ + # Tests if dnscrypt-proxy settings correctly deep-merge across modules, + # and that the resulting config works. + # See https://github.com/NixOS/nixpkgs/issues/523152 + { + services.dnscrypt-proxy.settings.listen_addresses = [ "127.0.0.1:${toString localProxyPort}" ]; + } + { + services.dnscrypt-proxy.settings.listen_addresses = [ "127.0.0.1:${toString localProxyExtraPort}" ]; + } + ]; + security.apparmor.enable = true; services.dnscrypt-proxy.enable = true; services.dnscrypt-proxy.settings = { - listen_addresses = [ "127.0.0.1:${toString localProxyPort}" ]; sources.public-resolvers = { urls = [ "https://download.dnscrypt.info/resolvers-list/v2/public-resolvers.md" ]; cache_file = "public-resolvers.md"; @@ -26,7 +37,10 @@ in }; services.dnsmasq.enable = true; - services.dnsmasq.settings.server = [ "127.0.0.1#${toString localProxyPort}" ]; + services.dnsmasq.settings.server = [ + "127.0.0.1#${toString localProxyPort}" + "127.0.0.1#${toString localProxyExtraPort}" + ]; }; }; @@ -34,5 +48,6 @@ in client.wait_for_unit("dnsmasq") client.wait_for_unit("dnscrypt-proxy") client.wait_until_succeeds("ss --numeric --udp --listening | grep -q ${toString localProxyPort}") + client.wait_until_succeeds("ss --numeric --udp --listening | grep -q ${toString localProxyExtraPort}") ''; } From 641666753573e58e0081a87da5cddc226a569c3e Mon Sep 17 00:00:00 2001 From: Tom Parker-Shemilt Date: Sun, 16 Aug 2026 21:53:35 +0100 Subject: [PATCH 40/53] cargo-llvm-cov: 0.8.7 -> 0.9.0 --- pkgs/by-name/ca/cargo-llvm-cov/Cargo.lock | 68 +++++++++++----------- pkgs/by-name/ca/cargo-llvm-cov/package.nix | 6 +- 2 files changed, 37 insertions(+), 37 deletions(-) diff --git a/pkgs/by-name/ca/cargo-llvm-cov/Cargo.lock b/pkgs/by-name/ca/cargo-llvm-cov/Cargo.lock index a9c07eec84e6..581557e8e329 100644 --- a/pkgs/by-name/ca/cargo-llvm-cov/Cargo.lock +++ b/pkgs/by-name/ca/cargo-llvm-cov/Cargo.lock @@ -13,9 +13,9 @@ dependencies = [ [[package]] name = "anyhow" -version = "1.0.103" +version = "1.0.104" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "2a4385e2e34eb35d6b3efe798b9eb88096925d87726c0798709bf56d9ed84af3" +checksum = "330a5ed07fa54e4702c9d6c4174f74427fc0ef6e214bbd677ae50a5099946470" [[package]] name = "autocfg" @@ -48,15 +48,15 @@ checksum = "ebb068a5ba5b65a7cdba869497ca2a352e88e6093c4909ddf4d12d9d3151ee9c" [[package]] name = "camino" -version = "1.2.4" +version = "1.2.5" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "5f2d30e4173c4026932d51d31d6b0613b1fd3014bf3f9f8943d4ba139c437ba0" +checksum = "bb1307f12aa967b5a58416e87b3653360e0fd614a016b6e970db08fecbb1b80d" [[package]] name = "cargo-config2" -version = "0.1.44" +version = "0.1.45" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "25ada53f7339c78084fb37d7e17f34e76537541c4fbb02fa3a2baa14b8faad37" +checksum = "855d1b74d8faf6c56e02ddbb8a60f6eae479bba5ee6ee29cddee73fe9484f261" dependencies = [ "serde", "serde_derive", @@ -65,7 +65,7 @@ dependencies = [ [[package]] name = "cargo-llvm-cov" -version = "0.8.7" +version = "0.9.0" dependencies = [ "anyhow", "build-context", @@ -122,9 +122,9 @@ dependencies = [ [[package]] name = "fastrand" -version = "2.4.1" +version = "2.5.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "9f1f227452a390804cdb637b74a86990f2a7d7ba4b7d5693aac9b4dd6defd8d6" +checksum = "da7c62ceae207dd37ea5b845da6a0696c799f85e97da1ab5b7910be3c1c80223" [[package]] name = "filetime" @@ -147,9 +147,9 @@ dependencies = [ [[package]] name = "glob" -version = "0.3.3" +version = "0.3.4" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "0cc23270f6e1808e30a928bdc84dea0b9b4136a8bc82338574f23baf47bbd280" +checksum = "e4eba85ea1d0a966a983acd07deee566e67395d2d96b6fb39e62b5a833f1eb0b" [[package]] name = "itoa" @@ -177,9 +177,9 @@ checksum = "803ec87c9cfb29b9d2633f20cba1f488db3fd53f2158b1024cbefb47ba05d413" [[package]] name = "libc" -version = "0.2.186" +version = "0.2.189" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "68ab91017fe16c622486840e4c83c9a37afeff978bd239b5293d61ece587de66" +checksum = "3eaf3ede3fee6db1a4c2ee091bf8a8b4dccdc6d17f656fb07896ee72867612f2" [[package]] name = "linux-raw-sys" @@ -231,9 +231,9 @@ dependencies = [ [[package]] name = "proc-macro2" -version = "1.0.106" +version = "1.0.107" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "8fd00f0bb2e90d81d1044c2b32617f68fcb9fa3bb7640c23e9c748e53fb30934" +checksum = "985e7ec9bb745e6ce6535b544d84d6cd6f7ad8bd711c398938ae983b91a766d9" dependencies = [ "unicode-ident", ] @@ -249,9 +249,9 @@ dependencies = [ [[package]] name = "quote" -version = "1.0.46" +version = "1.0.47" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "dfbc457d0c7a0759a614551b11a6409e5951f6c7537be1f1b7682b9ae9230368" +checksum = "1fbf4db142a473a8d80c26bbf18454ed458bf8d26c8219c331daecfdbd079001" dependencies = [ "proc-macro2", ] @@ -312,9 +312,9 @@ checksum = "cf54715a573b99ac80df0bc206da022bcd442c974952c7b9720069370852e21f" [[package]] name = "ruzstd" -version = "0.8.3" +version = "0.9.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "a7c1c839d570d835527c9a5e4db7cb2198683a988cb9d7293fc8674e6bd58fc8" +checksum = "a252f5e20f038fe7b4ea53e073e65398d652c864cc162fc77c56c2f13717b888" [[package]] name = "same-file" @@ -327,27 +327,27 @@ dependencies = [ [[package]] name = "serde" -version = "1.0.228" +version = "1.0.229" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "9a8e94ea7f378bd32cbbd37198a4a91436180c5bb472411e48b5ec2e2124ae9e" +checksum = "4148590afebada386688f18773da617792bf2ef03ffc1e4cbd2b1d45b023e0ba" dependencies = [ "serde_core", ] [[package]] name = "serde_core" -version = "1.0.228" +version = "1.0.229" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "41d385c7d4ca58e59fc732af25c3983b67ac852c1a25000afe1175de458b67ad" +checksum = "67dca2c9c51e58a4791a4b1ed58308b39c64224d349a935ab5039aa360942a48" dependencies = [ "serde_derive", ] [[package]] name = "serde_derive" -version = "1.0.228" +version = "1.0.229" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "d540f220d3187173da220f885ab66608367b6574e925011a9353e4badda91d79" +checksum = "e7a5d71263a5a7d47b41f6b3f06ba276f10cc18b0931f1799f710578e2309348" dependencies = [ "proc-macro2", "quote", @@ -356,9 +356,9 @@ dependencies = [ [[package]] name = "serde_json" -version = "1.0.150" +version = "1.0.151" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "e8014e44b4736ed0538adeecded0fce2a272f22dc9578a7eb6b2d9993c74cfb9" +checksum = "c841b55ecdae098c80dcae9cf767f6f8a0c2cdb3416bbef72181df4d0fe73f14" dependencies = [ "itoa", "memchr", @@ -400,9 +400,9 @@ checksum = "45bb67a18fa91266cc7807181f62f9178a6873bfad7dc788c42e6430db40184f" [[package]] name = "syn" -version = "2.0.119" +version = "3.0.3" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "872831b642d1a07999a962a351ed35b955ea2cfc8f3862091e2a240a84f17297" +checksum = "53e9bae58849f64dfa4f5d5ae372c8341f7305f82a3868709269343628b659a3" dependencies = [ "proc-macro2", "quote", @@ -444,16 +444,16 @@ dependencies = [ [[package]] name = "test-helper" version = "0.0.0" -source = "git+https://github.com/taiki-e/test-helper.git?rev=f38a7f5#f38a7f5895cb5f562195c6116cffc139d712acf5" +source = "git+https://github.com/taiki-e/test-helper.git?rev=82e3b012a49fb16587e165986674290ef682a5b0#82e3b012a49fb16587e165986674290ef682a5b0" dependencies = [ "fs-err", ] [[package]] name = "toml" -version = "1.1.3+spec-1.1.0" +version = "1.1.4+spec-1.1.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "53c96ecdfa941c8fc4fcaed14f99ada8ebed502eef533015095a07e3301d4c3c" +checksum = "3aace63f4bbcdfc2c965b059de67119c89c4017a70d633be6c104910f67056f5" dependencies = [ "serde_core", "serde_spanned", @@ -473,9 +473,9 @@ dependencies = [ [[package]] name = "toml_parser" -version = "1.1.2+spec-1.1.0" +version = "1.1.3+spec-1.1.0" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "a2abe9b86193656635d2411dc43050282ca48aa31c2451210f4202550afb7526" +checksum = "1d38ac1cf9b95face32296c0a3ede1fdc270627c9d9c02a7274dd6d960dc4d56" dependencies = [ "winnow", ] diff --git a/pkgs/by-name/ca/cargo-llvm-cov/package.nix b/pkgs/by-name/ca/cargo-llvm-cov/package.nix index 74e2d855cce3..78e9d9f569e9 100644 --- a/pkgs/by-name/ca/cargo-llvm-cov/package.nix +++ b/pkgs/by-name/ca/cargo-llvm-cov/package.nix @@ -25,7 +25,7 @@ let pname = "cargo-llvm-cov"; - version = "0.8.7"; + version = "0.9.0"; owner = "taiki-e"; homepage = "https://github.com/${owner}/${pname}"; @@ -42,7 +42,7 @@ rustPlatform.buildRustPackage (finalAttrs: { inherit owner; repo = "cargo-llvm-cov"; rev = "v${version}"; - sha256 = "sha256-flHZfjwEEIBEJHYGozlRgH9OHTJHgAR+OZxYJS/vHpQ="; + sha256 = "sha256-tPW36leXKuJCaZYOXF0mTd+WYHfGnHNg8foSQ2N+8kU="; }; # Upstream doesn't include the lockfile so we need to add it back @@ -53,7 +53,7 @@ rustPlatform.buildRustPackage (finalAttrs: { cargoLock = { lockFile = ./Cargo.lock; outputHashes = { - "test-helper-0.0.0" = "sha256-MjylM9agdGIGMp1Iip/jolHCzErST2XiEl5PIqt+ykg="; + "test-helper-0.0.0" = "sha256-nPNYhfGVL6rNdfCoWLNJuVeP6Gt4m1CwEOyPtFYIXfk="; }; }; From 25d7f7de9ca3a2e96a93dea89cf06fea46587e33 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 16 Aug 2026 22:11:52 +0000 Subject: [PATCH 41/53] ttop: 1.6.1 -> 1.6.2 --- pkgs/by-name/tt/ttop/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/tt/ttop/package.nix b/pkgs/by-name/tt/ttop/package.nix index 5dadb36f269f..3d4a5d19cc44 100644 --- a/pkgs/by-name/tt/ttop/package.nix +++ b/pkgs/by-name/tt/ttop/package.nix @@ -7,13 +7,13 @@ buildNimPackage (finalAttrs: { pname = "ttop"; - version = "1.6.1"; + version = "1.6.2"; src = fetchFromGitHub { owner = "inv2004"; repo = "ttop"; rev = "v${finalAttrs.version}"; - hash = "sha256-qq+8LEP6rHL3opwsQixwNnMbbk0TN+mIrrdCjuKnAfA="; + hash = "sha256-+QQ5eLqEWZFCOyPKtYLWFZwt+8D2c87GvE3GyDpkiyE="; }; lockFile = ./lock.json; From 5a881e86c86937223181599e9ccaecbc76c5f1dc Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 16 Aug 2026 22:56:48 +0000 Subject: [PATCH 42/53] euphonica: 0.99.5-beta -> 0.99.6-beta --- pkgs/by-name/eu/euphonica/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/eu/euphonica/package.nix b/pkgs/by-name/eu/euphonica/package.nix index 0c047a630348..8535f598cc94 100644 --- a/pkgs/by-name/eu/euphonica/package.nix +++ b/pkgs/by-name/eu/euphonica/package.nix @@ -27,13 +27,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "euphonica"; - version = "0.99.5-beta"; + version = "0.99.6-beta"; src = fetchFromGitHub { owner = "htkhiem"; repo = "euphonica"; tag = "v${finalAttrs.version}"; - hash = "sha256-/U0ugG6refcMliHO1Eouk+yQyzXWh7Y/mzSTskU6/co="; + hash = "sha256-uAyoiHgpzcgpjEe0ugUe39kisjFJR136ZKXuOLKCH7E="; fetchSubmodules = true; }; @@ -46,7 +46,7 @@ stdenv.mkDerivation (finalAttrs: { cargoDeps = rustPlatform.fetchCargoVendor { inherit (finalAttrs) pname version src; - hash = "sha256-eB5m2wa61k3m3uKzo7sgKxJZ3hZqvNqP8fs15e6tiZA="; + hash = "sha256-jSetSKfGe+R3Rp2pDrvEbzzV+Tnnwh7noGo3VLrXgnQ="; }; mesonBuildType = "release"; From 06417b2a07b8e70cd5528fdd6fe3325f45e8f78f Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 16 Aug 2026 23:03:54 +0000 Subject: [PATCH 43/53] labwc-menu-generator: 0.2.0-unstable-2026-06-02 -> 0.2.0-unstable-2026-08-15 --- pkgs/by-name/la/labwc-menu-generator/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/la/labwc-menu-generator/package.nix b/pkgs/by-name/la/labwc-menu-generator/package.nix index c4888cca51cd..09b78f61ddac 100644 --- a/pkgs/by-name/la/labwc-menu-generator/package.nix +++ b/pkgs/by-name/la/labwc-menu-generator/package.nix @@ -11,13 +11,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "labwc-menu-generator"; - version = "0.2.0-unstable-2026-06-02"; + version = "0.2.0-unstable-2026-08-15"; src = fetchFromGitHub { owner = "labwc"; repo = "labwc-menu-generator"; - rev = "3785977b3b1bc8a5c4397762538929c5232c5707"; - hash = "sha256-DHqNGtm14tSDKpSZiYGaCaK9ouZPjSJOhq/9CLCMhQw="; + rev = "ae466068ffaea10d10819d993b012da9e27a169a"; + hash = "sha256-mzBgqmpMLq3VTn9gkbEkH3jHMsDBWZ/XnWUFIcOo28s="; }; nativeBuildInputs = [ From bfc7ba74ba2e08e946698dd67460450026c96396 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 16 Aug 2026 23:23:40 +0000 Subject: [PATCH 44/53] cockpit-zfs: 1.2.33 -> 1.3.0 --- pkgs/by-name/co/cockpit-zfs/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/co/cockpit-zfs/package.nix b/pkgs/by-name/co/cockpit-zfs/package.nix index 23189d2644da..2ccadc3f3197 100644 --- a/pkgs/by-name/co/cockpit-zfs/package.nix +++ b/pkgs/by-name/co/cockpit-zfs/package.nix @@ -46,14 +46,14 @@ in stdenv.mkDerivation (finalAttrs: { pname = "cockpit-zfs"; - version = "1.2.33"; + version = "1.3.0"; src = fetchFromGitHub { owner = "45Drives"; repo = "cockpit-zfs"; tag = "v${finalAttrs.version}"; fetchSubmodules = true; - hash = "sha256-3KoCp4gcWYuama+7t1oQhif3/Ii/zSlhyeNTH3mvbNg="; + hash = "sha256-AeHawdStX+A+/8z4IWaf1w5irNZDIWs52y1nsEF+fHg="; }; missingHashes = ./missing-hashes.json; From 698537ffde155a1cf44fd425379c7b397bc32e3d Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 16 Aug 2026 23:27:30 +0000 Subject: [PATCH 45/53] reframe: 1.20.0 -> 1.20.1 --- pkgs/by-name/re/reframe/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/re/reframe/package.nix b/pkgs/by-name/re/reframe/package.nix index 46ca8eb15bbb..6829af7008d0 100644 --- a/pkgs/by-name/re/reframe/package.nix +++ b/pkgs/by-name/re/reframe/package.nix @@ -25,13 +25,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "reframe"; - version = "1.20.0"; + version = "1.20.1"; src = fetchFromGitHub { owner = "AlynxZhou"; repo = "reframe"; tag = "v${finalAttrs.version}"; - hash = "sha256-Lh9El4/NKtU9aRJfMP6odLX1FiX8wdaOMeBFJNWmjKE="; + hash = "sha256-Y67tjv4HXOsilU4ki56queSid517F0TzGnf66l+7zok="; fetchSubmodules = true; }; From 17bfb0eab1d12c2d20db52465273eb0bd838329e Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 17 Aug 2026 00:29:49 +0000 Subject: [PATCH 46/53] stalwart-vandelay: 1.0.7 -> 1.0.8 --- pkgs/by-name/st/stalwart-vandelay/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/st/stalwart-vandelay/package.nix b/pkgs/by-name/st/stalwart-vandelay/package.nix index 941299f6f2b2..5fd7aa3fc527 100644 --- a/pkgs/by-name/st/stalwart-vandelay/package.nix +++ b/pkgs/by-name/st/stalwart-vandelay/package.nix @@ -8,14 +8,14 @@ }: rustPlatform.buildRustPackage (finalAttrs: { pname = "vandelay"; - version = "1.0.7"; + version = "1.0.8"; src = fetchFromGitHub { owner = "stalwartlabs"; repo = "vandelay"; tag = "v${finalAttrs.version}"; - hash = "sha256-hjGUoF/EPeKBjdUic5svKVlNiHSfvkH4SgMzRLVQQDc="; + hash = "sha256-2KknqhkbdqEcdmJmfLaJZE6LVQ9C6S1F9aMz1OJB5Nc="; }; - cargoHash = "sha256-BEN0l+7LKA873VLg4bdPKGgg6acgq9985yHhcZuK1qM="; + cargoHash = "sha256-dHWnfKvwRsw8XVg+aJrBCTeLx7z/oAJuF75O00/Vg/c="; __structuredAttrs = true; __darwinAllowLocalNetworking = true; # called `Result::unwrap()` on an `Err` value: Tls("rustls platform verifier: unexpected error: No CA certificates were loaded from the system") From 381bc104b08874eaf78308db556e952820b79ecd Mon Sep 17 00:00:00 2001 From: Ethan Carter Edwards Date: Fri, 14 Aug 2026 20:19:08 -0700 Subject: [PATCH 47/53] harmonist: fix Darwin src hash Unfortunate weird darwin case-insensitivity bug... map-d.png vs map-D.png :( Signed-off-by: Ethan Carter Edwards --- pkgs/by-name/ha/harmonist/package.nix | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/ha/harmonist/package.nix b/pkgs/by-name/ha/harmonist/package.nix index 4a79cb375c34..006f2ca9ded1 100644 --- a/pkgs/by-name/ha/harmonist/package.nix +++ b/pkgs/by-name/ha/harmonist/package.nix @@ -1,5 +1,6 @@ { lib, + stdenv, buildGoModule, fetchFromCodeberg, }: @@ -12,7 +13,13 @@ buildGoModule (finalAttrs: { owner = "anaseto"; repo = "harmonist"; tag = "v${finalAttrs.version}"; - hash = "sha256-9cEKkvQze+hg4CwDe5epTpuQPevylwnSP5xQAVGJ/wQ="; + hash = + # darwin's case-insensitive filesystem produces a different source hash because of map-d vs map-D + # is this a correctness issue? + if stdenv.hostPlatform.isDarwin then + "sha256-yNPGoCvCdrmFaUjtA1p8pgPIC9ekIizhG6oMiYRFYGA=" + else + "sha256-9cEKkvQze+hg4CwDe5epTpuQPevylwnSP5xQAVGJ/wQ="; }; vendorHash = "sha256-wibNLDdykV2psOnJbMKu0EZSrrhKRxrN/OTWXmUz2FM="; From fdc6ca2c79e13f05d544dc1797f27b91201dbf05 Mon Sep 17 00:00:00 2001 From: Ethan Carter Edwards Date: Fri, 14 Aug 2026 20:22:34 -0700 Subject: [PATCH 48/53] harmonist: add versionCheckHook Signed-off-by: Ethan Carter Edwards --- pkgs/by-name/ha/harmonist/package.nix | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/ha/harmonist/package.nix b/pkgs/by-name/ha/harmonist/package.nix index 006f2ca9ded1..1655ae043dfd 100644 --- a/pkgs/by-name/ha/harmonist/package.nix +++ b/pkgs/by-name/ha/harmonist/package.nix @@ -3,6 +3,7 @@ stdenv, buildGoModule, fetchFromCodeberg, + versionCheckHook, }: buildGoModule (finalAttrs: { @@ -26,9 +27,11 @@ buildGoModule (finalAttrs: { ldflags = [ "-s" - "-w" ]; + nativeInstallCheckInputs = [ versionCheckHook ]; + doInstallCheck = true; + meta = { description = "Stealth coffee-break roguelike game"; mainProgram = "harmonist"; From 2f14ec44a7b06dfd579527d45bd192fc861f94d4 Mon Sep 17 00:00:00 2001 From: Ethan Carter Edwards Date: Fri, 14 Aug 2026 20:23:36 -0700 Subject: [PATCH 49/53] harmonist: enable __structuredAttrs Signed-off-by: Ethan Carter Edwards --- pkgs/by-name/ha/harmonist/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/ha/harmonist/package.nix b/pkgs/by-name/ha/harmonist/package.nix index 1655ae043dfd..7a1810682845 100644 --- a/pkgs/by-name/ha/harmonist/package.nix +++ b/pkgs/by-name/ha/harmonist/package.nix @@ -10,6 +10,8 @@ buildGoModule (finalAttrs: { pname = "harmonist"; version = "1.0.3"; + __structuredAttrs = true; + src = fetchFromCodeberg { owner = "anaseto"; repo = "harmonist"; From ddb50d23e7642e1f25b909ad8a6ac328278817ed Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 17 Aug 2026 00:55:04 +0000 Subject: [PATCH 50/53] honeycomb-refinery: 3.2.2 -> 3.3.0 --- pkgs/by-name/ho/honeycomb-refinery/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ho/honeycomb-refinery/package.nix b/pkgs/by-name/ho/honeycomb-refinery/package.nix index 53ef518056c8..8753d448d7b6 100644 --- a/pkgs/by-name/ho/honeycomb-refinery/package.nix +++ b/pkgs/by-name/ho/honeycomb-refinery/package.nix @@ -8,13 +8,13 @@ buildGoModule (finalAttrs: { pname = "honeycomb-refinery"; - version = "3.2.2"; + version = "3.3.0"; src = fetchFromGitHub { owner = "honeycombio"; repo = "refinery"; rev = "v${finalAttrs.version}"; - hash = "sha256-slINvCsw4s5I9s9LaTXuR/5Rvv1K1qzqNiatwr6p4FM="; + hash = "sha256-fip02kKy+LLySFVBI/cKMEZdQRus+4dXBUfm0yGlBlc="; }; env.NO_REDIS_TEST = true; @@ -37,7 +37,7 @@ buildGoModule (finalAttrs: { "-X main.BuildID=${finalAttrs.version}" ]; - vendorHash = "sha256-DxqVKGox3NbRwvkGrW29MbsE4KKK0/Og8uH5hgtgPMo="; + vendorHash = "sha256-5TWPbtmY3f8Wpvs5GblNOmTwFxEeL7dKKWvA6jGClhs="; doCheck = true; From 85fc90a8630c9627fa85f80de22edb5c568459ae Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 17 Aug 2026 01:47:59 +0000 Subject: [PATCH 51/53] blesh: 0.4.0-devel3-unstable-2026-07-11 -> 0.4.0-devel3-unstable-2026-08-12 --- pkgs/by-name/bl/blesh/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/bl/blesh/package.nix b/pkgs/by-name/bl/blesh/package.nix index 55a7251a0c87..372e08738148 100644 --- a/pkgs/by-name/bl/blesh/package.nix +++ b/pkgs/by-name/bl/blesh/package.nix @@ -10,14 +10,14 @@ stdenvNoCC.mkDerivation (finalAttrs: { pname = "blesh"; - version = "0.4.0-devel3-unstable-2026-07-11"; + version = "0.4.0-devel3-unstable-2026-08-12"; src = fetchFromGitHub { owner = "akinomyoga"; repo = "ble.sh"; - rev = "d69e4d549a1881a37300fe6b4a05478bd9157dfc"; + rev = "95ae551dd687a0c61227839dda43f52ac7ea6631"; fetchSubmodules = true; - hash = "sha256-w2d7JCa/cBpe8x+pnGWq+h6cpUVJCNyHZymgbKKPDQE="; + hash = "sha256-dsQK5uu8LvPWBHr+CGK6QAP1ka0qHtCD/WH9nbsrTxI="; }; nativeBuildInputs = [ From 3f0891471b25768ffe568888fb53123cd378ef15 Mon Sep 17 00:00:00 2001 From: XYenon Date: Mon, 17 Aug 2026 10:44:49 +0800 Subject: [PATCH 52/53] nixos/kvrocks: unwrap list-coerced settings --- nixos/modules/services/databases/kvrocks.nix | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/nixos/modules/services/databases/kvrocks.nix b/nixos/modules/services/databases/kvrocks.nix index d6bb3a1361c5..5710d35848db 100644 --- a/nixos/modules/services/databases/kvrocks.nix +++ b/nixos/modules/services/databases/kvrocks.nix @@ -21,10 +21,11 @@ let isDefaultDir = dataDir == defaultDir; # Defaults match upstream Config field defaults (config.cc). - workers = cfg.settings.workers or 8; - maxBackgroundJobs = cfg.settings."rocksdb.max_background_jobs" or 4; - maxclients = cfg.settings.maxclients or 10240; - maxOpenFiles = cfg.settings."rocksdb.max_open_files" or 8096; + # freeformType uses listsAsDuplicateKeys, so set values are singleton lists. + workers = lib.head (cfg.settings.workers or [ 8 ]); + maxBackgroundJobs = lib.head (cfg.settings."rocksdb.max_background_jobs" or [ 4 ]); + maxclients = lib.head (cfg.settings.maxclients or [ 10240 ]); + maxOpenFiles = lib.head (cfg.settings."rocksdb.max_open_files" or [ 8096 ]); # Thread inventory from server.cc ("Kvrocks threads list") + Server::Start: # always-on: main, workers, task-runner (1), server-cron, compact-check, From b494317f9e4f7acfe4932c83a233a97266ed6d26 Mon Sep 17 00:00:00 2001 From: matthewcroughan Date: Mon, 17 Aug 2026 04:23:37 +0100 Subject: [PATCH 53/53] hexagonrpc: 0.4.0 -> 0.5.0 --- pkgs/by-name/he/hexagonrpc/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/he/hexagonrpc/package.nix b/pkgs/by-name/he/hexagonrpc/package.nix index dc0346b868ef..42e26700dc78 100644 --- a/pkgs/by-name/he/hexagonrpc/package.nix +++ b/pkgs/by-name/he/hexagonrpc/package.nix @@ -10,13 +10,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "hexagonrpc"; - version = "0.4.0"; + version = "0.5.0"; src = fetchFromGitHub { owner = "linux-msm"; repo = "hexagonrpc"; tag = "v${finalAttrs.version}"; - hash = "sha256-OC6wXBCIW4XznWG0zzxRK3BzWMVK2Jq/gTL36sJV1PE="; + hash = "sha256-njhDLpkEuA2PSPe9rpYvlDN4JLgkYCfgZ5oX/NFx2Ho="; }; outputs = [