diff --git a/nixos/modules/services/continuous-integration/github-runner.nix b/nixos/modules/services/continuous-integration/github-runner.nix
index 943c1e4598df..79cc84b1589a 100644
--- a/nixos/modules/services/continuous-integration/github-runner.nix
+++ b/nixos/modules/services/continuous-integration/github-runner.nix
@@ -10,6 +10,8 @@ let
stateDir = "%S/${systemdDir}";
# %L: Log directory root (usually /var/log); see systemd.unit(5)
logsDir = "%L/${systemdDir}";
+ # Name of file stored in service state directory
+ currentConfigTokenFilename = ".current-token";
in
{
options.services.github-runner = {
@@ -143,13 +145,11 @@ in
ExecStart = "${cfg.package}/bin/runsvc.sh";
# Does the following, sequentially:
- # - Copy the current and the previous `tokenFile` to the $RUNTIME_DIRECTORY
- # and make it accessible to the service user to allow for a content
- # comparison.
- # - If the module configuration or the token has changed, clear the state directory.
- # - Configure the runner.
- # - Copy the configured `tokenFile` to the $STATE_DIRECTORY and make it
- # inaccessible to the service user.
+ # - If the module configuration or the token has changed, purge the state directory,
+ # and create the current and the new token file with the contents of the configured
+ # token. While both files have the same content, only the later is accessible by
+ # the service user.
+ # - Configure the runner using the new token file. When finished, delete it.
# - Set up the directory structure by creating the necessary symlinks.
ExecStartPre =
let
@@ -172,37 +172,20 @@ in
currentConfigPath = "$STATE_DIRECTORY/.nixos-current-config.json";
runnerRegistrationConfig = getAttrs [ "name" "tokenFile" "url" "runnerGroup" "extraLabels" ] cfg;
newConfigPath = builtins.toFile "${svcName}-config.json" (builtins.toJSON runnerRegistrationConfig);
- currentConfigTokenFilename = ".current-token";
newConfigTokenFilename = ".new-token";
runnerCredFiles = [
".credentials"
".credentials_rsaparams"
".runner"
];
- ownConfigTokens = writeScript "own-config-tokens" ''
- # Copy current and new token file to runtime dir and make it accessible to the service user
- cp ${escapeShellArg cfg.tokenFile} "$RUNTIME_DIRECTORY/${newConfigTokenFilename}"
- chmod 600 "$RUNTIME_DIRECTORY/${newConfigTokenFilename}"
- chown "$USER" "$RUNTIME_DIRECTORY/${newConfigTokenFilename}"
-
- if [[ -e "$STATE_DIRECTORY/${currentConfigTokenFilename}" ]]; then
- cp "$STATE_DIRECTORY/${currentConfigTokenFilename}" "$RUNTIME_DIRECTORY/${currentConfigTokenFilename}"
- chmod 600 "$RUNTIME_DIRECTORY/${currentConfigTokenFilename}"
- chown "$USER" "$RUNTIME_DIRECTORY/${currentConfigTokenFilename}"
- fi
- '';
- disownConfigTokens = writeScript "disown-config-tokens" ''
- # Make the token inaccessible to the runner service user
- chmod 600 "$STATE_DIRECTORY/${currentConfigTokenFilename}"
- chown root:root "$STATE_DIRECTORY/${currentConfigTokenFilename}"
- '';
unconfigureRunner = writeScript "unconfigure" ''
differs=
# Set `differs = 1` if current and new runner config differ or if `currentConfigPath` does not exist
${pkgs.diffutils}/bin/diff -q '${newConfigPath}' "${currentConfigPath}" >/dev/null 2>&1 || differs=1
# Also trigger a registration if the token content changed
${pkgs.diffutils}/bin/diff -q \
- "$RUNTIME_DIRECTORY"/{${currentConfigTokenFilename},${newConfigTokenFilename}} \
+ "$STATE_DIRECTORY"/${currentConfigTokenFilename} \
+ ${escapeShellArg cfg.tokenFile} \
>/dev/null 2>&1 || differs=1
if [[ -n "$differs" ]]; then
@@ -210,13 +193,18 @@ in
echo "The old runner will still appear in the GitHub Actions UI." \
"You have to remove it manually."
find "$STATE_DIRECTORY/" -mindepth 1 -delete
+
+ # Copy the configured token file to the state dir and allow the service user to read the file
+ install --mode=666 ${escapeShellArg cfg.tokenFile} "$STATE_DIRECTORY/${newConfigTokenFilename}"
+ # Also copy current file to allow for a diff on the next start
+ install --mode=600 ${escapeShellArg cfg.tokenFile} "$STATE_DIRECTORY/${currentConfigTokenFilename}"
fi
'';
configureRunner = writeScript "configure" ''
- empty=$(ls -A "$STATE_DIRECTORY")
- if [[ -z "$empty" ]]; then
+ if [[ -e "$STATE_DIRECTORY/${newConfigTokenFilename}" ]]; then
echo "Configuring GitHub Actions Runner"
- token=$(< "$RUNTIME_DIRECTORY"/${newConfigTokenFilename})
+
+ token=$(< "$STATE_DIRECTORY"/${newConfigTokenFilename})
RUNNER_ROOT="$STATE_DIRECTORY" ${cfg.package}/bin/config.sh \
--unattended \
--work "$RUNTIME_DIRECTORY" \
@@ -233,8 +221,7 @@ in
rm -rf "$STATE_DIRECTORY/_diag/"
# Cleanup token from config
- rm -f "$RUNTIME_DIRECTORY"/${currentConfigTokenFilename}
- mv "$RUNTIME_DIRECTORY"/${newConfigTokenFilename} "$STATE_DIRECTORY/${currentConfigTokenFilename}"
+ rm "$STATE_DIRECTORY/${newConfigTokenFilename}"
# Symlink to new config
ln -s '${newConfigPath}' "${currentConfigPath}"
@@ -249,10 +236,8 @@ in
'';
in
map (x: "${x} ${escapeShellArgs [ stateDir runtimeDir logsDir ]}") [
- "+${ownConfigTokens}" # runs as root
- unconfigureRunner
+ "+${unconfigureRunner}" # runs as root
configureRunner
- "+${disownConfigTokens}" # runs as root
setupRuntimeDir
];
@@ -265,6 +250,13 @@ in
StateDirectoryMode = "0700";
WorkingDirectory = runtimeDir;
+ InaccessiblePaths = [
+ # Token file path given in the configuration
+ cfg.tokenFile
+ # Token file in the state directory
+ "${stateDir}/${currentConfigTokenFilename}"
+ ];
+
# By default, use a dynamically allocated user
DynamicUser = true;
diff --git a/nixos/modules/services/misc/nix-daemon.nix b/nixos/modules/services/misc/nix-daemon.nix
index fb643e7a66e1..869feb05eb7b 100644
--- a/nixos/modules/services/misc/nix-daemon.nix
+++ b/nixos/modules/services/misc/nix-daemon.nix
@@ -192,15 +192,28 @@ in
example = "batch";
description = ''
Nix daemon process CPU scheduling policy. This policy propagates to
- build processes. other is the default scheduling policy for regular
- tasks. The batch policy is similar to other, but optimised for
- non-interactive tasks. idle is for extremely low-priority tasks
- that should only be run when no other task requires CPU time.
+ build processes. other is the default scheduling
+ policy for regular tasks. The batch policy is
+ similar to other, but optimised for
+ non-interactive tasks. idle is for extremely
+ low-priority tasks that should only be run when no other task
+ requires CPU time.
- Please note that while using the idle policy may greatly improve
- responsiveness of a system performing expensive builds, it may also
- slow down and potentially starve crucial configuration updates
- during load.
+ Please note that while using the idle policy may
+ greatly improve responsiveness of a system performing expensive
+ builds, it may also slow down and potentially starve crucial
+ configuration updates during load.
+
+ idle may therefore be a sensible policy for
+ systems that experience only intermittent phases of high CPU load,
+ such as desktop or portable computers used interactively. Other
+ systems should use the other or
+ batch policy instead.
+
+ For more fine-grained resource control, please refer to
+ systemd.resource-control
+ 5 and adjust
+ directly.
'';
};
@@ -210,13 +223,20 @@ in
example = "idle";
description = ''
Nix daemon process I/O scheduling class. This class propagates to
- build processes. best-effort is the default class for regular tasks.
- The idle class is for extremely low-priority tasks that should only
- perform I/O when no other task does.
+ build processes. best-effort is the default
+ class for regular tasks. The idle class is for
+ extremely low-priority tasks that should only perform I/O when no
+ other task does.
- Please note that while using the idle scheduling class can improve
- responsiveness of a system performing expensive builds, it might also
- slow down or starve crucial configuration updates during load.
+ Please note that while using the idle scheduling
+ class can improve responsiveness of a system performing expensive
+ builds, it might also slow down or starve crucial configuration
+ updates during load.
+
+ idle may therefore be a sensible class for
+ systems that experience only intermittent phases of high I/O load,
+ such as desktop or portable computers used interactively. Other
+ systems should use the best-effort class.
'';
};
diff --git a/nixos/modules/services/web-apps/dokuwiki.nix b/nixos/modules/services/web-apps/dokuwiki.nix
index fc0e23729b3c..9b9ae931f9a7 100644
--- a/nixos/modules/services/web-apps/dokuwiki.nix
+++ b/nixos/modules/services/web-apps/dokuwiki.nix
@@ -308,6 +308,9 @@ in
inherit user;
group = webserver.group;
+ # Not yet compatible with php 8 https://www.dokuwiki.org/requirements
+ # https://github.com/splitbrain/dokuwiki/issues/3545
+ phpPackage = pkgs.php74;
phpEnv = {
DOKUWIKI_LOCAL_CONFIG = "${dokuwikiLocalConfig hostName cfg}";
DOKUWIKI_PLUGINS_LOCAL_CONFIG = "${dokuwikiPluginsLocalConfig hostName cfg}";
@@ -446,5 +449,6 @@ in
meta.maintainers = with maintainers; [
_1000101
onny
+ dandellion
];
}
diff --git a/nixos/modules/services/web-apps/peertube.nix b/nixos/modules/services/web-apps/peertube.nix
index 362a3358b793..d99cfb54f169 100644
--- a/nixos/modules/services/web-apps/peertube.nix
+++ b/nixos/modules/services/web-apps/peertube.nix
@@ -302,6 +302,7 @@ in {
};
storage = {
tmp = lib.mkDefault "/var/lib/peertube/storage/tmp/";
+ bin = lib.mkDefault "/var/lib/peertube/storage/bin/";
avatars = lib.mkDefault "/var/lib/peertube/storage/avatars/";
videos = lib.mkDefault "/var/lib/peertube/storage/videos/";
streaming_playlists = lib.mkDefault "/var/lib/peertube/storage/streaming-playlists/";
@@ -315,6 +316,15 @@ in {
plugins = lib.mkDefault "/var/lib/peertube/storage/plugins/";
client_overrides = lib.mkDefault "/var/lib/peertube/storage/client-overrides/";
};
+ import = {
+ videos = {
+ http = {
+ youtube_dl_release = {
+ python_path = "${pkgs.python3}/bin/python";
+ };
+ };
+ };
+ };
}
(lib.mkIf cfg.redis.enableUnixSocket { redis = { socket = "/run/redis/redis.sock"; }; })
];
@@ -362,7 +372,7 @@ in {
environment = env;
- path = with pkgs; [ bashInteractive ffmpeg nodejs-16_x openssl yarn youtube-dl ];
+ path = with pkgs; [ bashInteractive ffmpeg nodejs-16_x openssl yarn python3 ];
script = ''
#!/bin/sh
diff --git a/nixos/modules/services/web-servers/uwsgi.nix b/nixos/modules/services/web-servers/uwsgi.nix
index ac435951310e..77258626c239 100644
--- a/nixos/modules/services/web-servers/uwsgi.nix
+++ b/nixos/modules/services/web-servers/uwsgi.nix
@@ -20,10 +20,11 @@ let
buildCfg = name: c:
let
- plugins =
+ plugins' =
if any (n: !any (m: m == n) cfg.plugins) (c.plugins or [])
then throw "`plugins` attribute in uWSGI configuration contains plugins not in config.services.uwsgi.plugins"
else c.plugins or cfg.plugins;
+ plugins = unique plugins';
hasPython = v: filter (n: n == "python${v}") plugins != [];
hasPython2 = hasPython "2";
@@ -48,13 +49,10 @@ let
pyhome = "${pythonEnv}";
env =
# Argh, uwsgi expects list of key-values there instead of a dictionary.
- let env' = c.env or [];
- getPath =
- x: if hasPrefix "PATH=" x
- then substring (stringLength "PATH=") (stringLength x) x
- else null;
- oldPaths = filter (x: x != null) (map getPath env');
- in env' ++ [ "PATH=${optionalString (oldPaths != []) "${last oldPaths}:"}${pythonEnv}/bin" ];
+ let envs = partition (hasPrefix "PATH=") (c.env or []);
+ oldPaths = map (x: substring (stringLength "PATH=") (stringLength x) x) envs.right;
+ paths = oldPaths ++ [ "${pythonEnv}/bin" ];
+ in [ "PATH=${concatStringsSep ":" paths}" ] ++ envs.wrong;
}
else if isEmperor
then {
@@ -225,7 +223,7 @@ in {
};
services.uwsgi.package = pkgs.uwsgi.override {
- inherit (cfg) plugins;
+ plugins = unique cfg.plugins;
};
};
}
diff --git a/pkgs/applications/blockchains/dogecoin/default.nix b/pkgs/applications/blockchains/dogecoin/default.nix
index 16ac7a787fb7..35b9fb026e39 100644
--- a/pkgs/applications/blockchains/dogecoin/default.nix
+++ b/pkgs/applications/blockchains/dogecoin/default.nix
@@ -7,13 +7,13 @@
with lib;
stdenv.mkDerivation rec {
name = "dogecoin" + (toString (optional (!withGui) "d")) + "-" + version;
- version = "1.14.4";
+ version = "1.14.5";
src = fetchFromGitHub {
owner = "dogecoin";
repo = "dogecoin";
rev = "v${version}";
- sha256 = "sha256-uITX5DSyC/m0ynwCkkbGgUj8kMuNgnsNo8H8RQSGPEA=";
+ sha256 = "sha256-Ewefy6sptSQDJVbvQqFoawhA/ujKEn9W2JWyoPYD7d0=";
};
nativeBuildInputs = [ pkg-config autoreconfHook ];
diff --git a/pkgs/applications/networking/pjsip/default.nix b/pkgs/applications/networking/pjsip/default.nix
index 5a0d3e4870a3..8b0fad83b960 100644
--- a/pkgs/applications/networking/pjsip/default.nix
+++ b/pkgs/applications/networking/pjsip/default.nix
@@ -2,13 +2,13 @@
stdenv.mkDerivation rec {
pname = "pjsip";
- version = "2.11.1";
+ version = "2.12";
src = fetchFromGitHub {
owner = pname;
repo = "pjproject";
rev = version;
- sha256 = "sha256-mqtlxQDIFee93wpdn8oNWmMPDyjYTCmVqF6IJvJbRBM=";
+ sha256 = "sha256-snp9+PlffU9Ay8o42PM8SqyP60hu9nozp457HM+0bM8=";
};
patches = [
diff --git a/pkgs/applications/networking/remote/vmware-horizon-client/default.nix b/pkgs/applications/networking/remote/vmware-horizon-client/default.nix
index 033386afd1ff..ee9467467cf4 100644
--- a/pkgs/applications/networking/remote/vmware-horizon-client/default.nix
+++ b/pkgs/applications/networking/remote/vmware-horizon-client/default.nix
@@ -1,57 +1,40 @@
{ stdenv
, lib
-, at-spi2-atk
-, atk
, buildFHSUserEnv
-, cairo
-, dbus
, fetchurl
-, fontconfig
-, freetype
-, gdk-pixbuf
-, glib
, gsettings-desktop-schemas
-, gtk2
-, gtk3-x11
-, harfbuzz
-, liberation_ttf
-, libjpeg
-, libtiff
-, libudev0-shim
-, libuuid
-, libX11
-, libXcursor
-, libXext
-, libXi
-, libXinerama
-, libxkbfile
-, libxml2
-, libXrandr
-, libXrender
-, libXScrnSaver
-, libxslt
-, libXtst
, makeDesktopItem
, makeWrapper
-, pango
-, pcsclite
-, pixman
-, zlib
+, writeTextDir
+, configText ? ""
}:
let
- version = "2106.1";
+ version = "2111";
sysArch =
if stdenv.hostPlatform.system == "x86_64-linux" then "x64"
else throw "Unsupported system: ${stdenv.hostPlatform.system}";
# The downloaded archive also contains ARM binaries, but these have not been tested.
+ # For USB support, ensure that /var/run/vmware/
+ # exists and is owned by you. Then run vmware-usbarbitrator as root.
+ bins = [ "vmware-view" "vmware-usbarbitrator" ];
+
+ # This forces the default GTK theme (Adwaita) because Horizon is prone to
+ # UI usability issues when using non-default themes, such as Adwaita-dark.
+ wrapBinCommands = name: ''
+ makeWrapper "$out/bin/${name}" "$out/bin/${name}_wrapper" \
+ --set GTK_THEME Adwaita \
+ --suffix XDG_DATA_DIRS : "${gsettings-desktop-schemas}/share/gsettings-schemas/${gsettings-desktop-schemas.name}" \
+ --suffix LD_LIBRARY_PATH : "$out/lib/vmware/view/crtbora:$out/lib/vmware"
+ '';
+
vmwareHorizonClientFiles = stdenv.mkDerivation {
name = "vmwareHorizonClientFiles";
inherit version;
src = fetchurl {
- url = "https://download3.vmware.com/software/view/viewclients/CART22FQ2/VMware-Horizon-Client-Linux-2106.1-8.3.1-18435609.tar.gz";
- sha256 = "b42ddb9d7e9c8d0f8b86b69344fcfca45251c5a5f1e06a18a3334d5a04e18c39";
+ url = "https://download3.vmware.com/software/view/viewclients/CART22FH2/VMware-Horizon-Client-Linux-2111-8.4.0-18957622.tar.gz";
+ sha256 = "2f79d2d8d34e6f85a5d21a3350618c4763d60455e7d68647ea40715eaff486f7";
};
nativeBuildInputs = [ makeWrapper ];
installPhase = ''
@@ -65,27 +48,19 @@ let
# Deleting the bundled library is the simplest way to force it to use our version.
rm "$out/lib/vmware/gcc/libstdc++.so.6"
- # This libjpeg library interferes with Chromium, so we will be using ours instead.
- rm $out/lib/vmware/libjpeg.*
-
# This library causes the program to core-dump occasionally. Use ours instead.
rm $out/lib/vmware/view/crtbora/libcairo.*
- # Force the default GTK theme (Adwaita) because Horizon is prone to
- # UI usability issues when using non-default themes, such as Adwaita-dark.
- makeWrapper "$out/bin/vmware-view" "$out/bin/vmware-view_wrapper" \
- --set GTK_THEME Adwaita \
- --suffix XDG_DATA_DIRS : "${gsettings-desktop-schemas}/share/gsettings-schemas/${gsettings-desktop-schemas.name}" \
- --suffix LD_LIBRARY_PATH : "$out/lib/vmware/view/crtbora:$out/lib/vmware"
+ ${lib.concatMapStrings wrapBinCommands bins}
'';
};
- vmwareFHSUserEnv = buildFHSUserEnv {
- name = "vmware-view";
+ vmwareFHSUserEnv = name: buildFHSUserEnv {
+ inherit name;
- runScript = "${vmwareHorizonClientFiles}/bin/vmware-view_wrapper";
+ runScript = "${vmwareHorizonClientFiles}/bin/${name}_wrapper";
- targetPkgs = pkgs: [
+ targetPkgs = pkgs: with pkgs; [
at-spi2-atk
atk
cairo
@@ -99,25 +74,29 @@ let
harfbuzz
liberation_ttf
libjpeg
+ libpulseaudio
libtiff
libudev0-shim
libuuid
- libX11
- libXcursor
- libXext
- libXi
- libXinerama
- libxkbfile
+ libv4l
libxml2
- libXrandr
- libXrender
- libXScrnSaver
- libXtst
pango
pcsclite
pixman
vmwareHorizonClientFiles
+ xorg.libX11
+ xorg.libXcursor
+ xorg.libXext
+ xorg.libXi
+ xorg.libXinerama
+ xorg.libxkbfile
+ xorg.libXrandr
+ xorg.libXrender
+ xorg.libXScrnSaver
+ xorg.libXtst
zlib
+
+ (writeTextDir "etc/vmware/config" configText)
];
};
@@ -125,20 +104,25 @@ let
name = "vmware-view";
desktopName = "VMware Horizon Client";
icon = "${vmwareHorizonClientFiles}/share/icons/vmware-view.png";
- exec = "${vmwareFHSUserEnv}/bin/vmware-view %u";
+ exec = "${vmwareFHSUserEnv "vmware-view"}/bin/vmware-view %u";
mimeType = "x-scheme-handler/vmware-view";
};
+ binLinkCommands = lib.concatMapStringsSep
+ "\n"
+ (bin: "ln -s ${vmwareFHSUserEnv bin}/bin/${bin} $out/bin/")
+ bins;
+
in
stdenv.mkDerivation {
- name = "vmware-view";
+ name = "vmware-horizon-client";
dontUnpack = true;
installPhase = ''
mkdir -p $out/bin $out/share/applications
- cp "${desktopItem}"/share/applications/* $out/share/applications/
- ln -s "${vmwareFHSUserEnv}/bin/vmware-view" "$out/bin/"
+ cp ${desktopItem}/share/applications/* $out/share/applications/
+ ${binLinkCommands}
'';
unwrapped = vmwareHorizonClientFiles;
@@ -146,10 +130,11 @@ stdenv.mkDerivation {
passthru.updateScript = ./update.sh;
meta = with lib; {
+ mainProgram = "vmware-view";
description = "Allows you to connect to your VMware Horizon virtual desktop";
homepage = "https://www.vmware.com/go/viewclients";
license = licenses.unfree;
- platforms = platforms.linux;
+ platforms = [ "x86_64-linux" ];
maintainers = with maintainers; [ buckley310 ];
};
}
diff --git a/pkgs/applications/version-management/redmine/Gemfile b/pkgs/applications/version-management/redmine/Gemfile
index 9835e23f2828..c3c25dafd544 100644
--- a/pkgs/applications/version-management/redmine/Gemfile
+++ b/pkgs/applications/version-management/redmine/Gemfile
@@ -3,7 +3,7 @@ source 'https://rubygems.org'
ruby '>= 2.4.0', '< 2.8.0'
gem 'bundler', '>= 1.12.0'
-gem 'rails', '5.2.6'
+gem 'rails', '5.2.6.2'
gem 'sprockets', '~> 3.7.2' if RUBY_VERSION < '2.5'
gem 'globalid', '~> 0.4.2' if Gem.ruby_version < Gem::Version.new('2.6.0')
gem 'rouge', '~> 3.26.0'
diff --git a/pkgs/applications/version-management/redmine/Gemfile.lock b/pkgs/applications/version-management/redmine/Gemfile.lock
index 00ac026e8696..b745c54520b1 100644
--- a/pkgs/applications/version-management/redmine/Gemfile.lock
+++ b/pkgs/applications/version-management/redmine/Gemfile.lock
@@ -1,19 +1,19 @@
GEM
remote: https://rubygems.org/
specs:
- actioncable (5.2.6)
- actionpack (= 5.2.6)
+ actioncable (5.2.6.2)
+ actionpack (= 5.2.6.2)
nio4r (~> 2.0)
websocket-driver (>= 0.6.1)
- actionmailer (5.2.6)
- actionpack (= 5.2.6)
- actionview (= 5.2.6)
- activejob (= 5.2.6)
+ actionmailer (5.2.6.2)
+ actionpack (= 5.2.6.2)
+ actionview (= 5.2.6.2)
+ activejob (= 5.2.6.2)
mail (~> 2.5, >= 2.5.4)
rails-dom-testing (~> 2.0)
- actionpack (5.2.6)
- actionview (= 5.2.6)
- activesupport (= 5.2.6)
+ actionpack (5.2.6.2)
+ actionview (= 5.2.6.2)
+ activesupport (= 5.2.6.2)
rack (~> 2.0, >= 2.0.8)
rack-test (>= 0.6.3)
rails-dom-testing (~> 2.0)
@@ -21,26 +21,26 @@ GEM
actionpack-xml_parser (2.0.1)
actionpack (>= 5.0)
railties (>= 5.0)
- actionview (5.2.6)
- activesupport (= 5.2.6)
+ actionview (5.2.6.2)
+ activesupport (= 5.2.6.2)
builder (~> 3.1)
erubi (~> 1.4)
rails-dom-testing (~> 2.0)
rails-html-sanitizer (~> 1.0, >= 1.0.3)
- activejob (5.2.6)
- activesupport (= 5.2.6)
+ activejob (5.2.6.2)
+ activesupport (= 5.2.6.2)
globalid (>= 0.3.6)
- activemodel (5.2.6)
- activesupport (= 5.2.6)
- activerecord (5.2.6)
- activemodel (= 5.2.6)
- activesupport (= 5.2.6)
+ activemodel (5.2.6.2)
+ activesupport (= 5.2.6.2)
+ activerecord (5.2.6.2)
+ activemodel (= 5.2.6.2)
+ activesupport (= 5.2.6.2)
arel (>= 9.0)
- activestorage (5.2.6)
- actionpack (= 5.2.6)
- activerecord (= 5.2.6)
+ activestorage (5.2.6.2)
+ actionpack (= 5.2.6.2)
+ activerecord (= 5.2.6.2)
marcel (~> 1.0.0)
- activesupport (5.2.6)
+ activesupport (5.2.6.2)
concurrent-ruby (~> 1.0, >= 1.0.2)
i18n (>= 0.7, < 2)
minitest (~> 5.1)
@@ -58,21 +58,21 @@ GEM
rack-test (>= 0.6.3)
regexp_parser (~> 1.5)
xpath (~> 3.2)
- childprocess (3.0.0)
+ childprocess (4.1.0)
chunky_png (1.4.0)
concurrent-ruby (1.1.9)
crass (1.0.6)
- css_parser (1.10.0)
+ css_parser (1.11.0)
addressable
csv (3.1.9)
docile (1.4.0)
erubi (1.10.0)
- globalid (0.5.2)
+ globalid (1.0.0)
activesupport (>= 5.0)
htmlentities (4.3.4)
- i18n (1.8.10)
+ i18n (1.8.11)
concurrent-ruby (~> 1.0)
- loofah (2.12.0)
+ loofah (2.14.0)
crass (~> 1.0.2)
nokogiri (>= 1.5.9)
mail (2.7.1)
@@ -82,7 +82,7 @@ GEM
mini_magick (4.11.0)
mini_mime (1.0.3)
mini_portile2 (2.5.3)
- minitest (5.14.4)
+ minitest (5.15.0)
mocha (1.13.0)
mysql2 (0.5.3)
net-ldap (0.17.0)
@@ -91,44 +91,44 @@ GEM
mini_portile2 (~> 2.5.0)
racc (~> 1.4)
parallel (1.21.0)
- parser (3.0.2.0)
+ parser (3.1.1.0)
ast (~> 2.4.1)
pg (1.2.3)
public_suffix (4.0.6)
- puma (5.5.2)
+ puma (5.6.2)
nio4r (~> 2.0)
- racc (1.5.2)
+ racc (1.6.0)
rack (2.2.3)
rack-openid (1.4.2)
rack (>= 1.1.0)
ruby-openid (>= 2.1.8)
rack-test (1.1.0)
rack (>= 1.0, < 3)
- rails (5.2.6)
- actioncable (= 5.2.6)
- actionmailer (= 5.2.6)
- actionpack (= 5.2.6)
- actionview (= 5.2.6)
- activejob (= 5.2.6)
- activemodel (= 5.2.6)
- activerecord (= 5.2.6)
- activestorage (= 5.2.6)
- activesupport (= 5.2.6)
+ rails (5.2.6.2)
+ actioncable (= 5.2.6.2)
+ actionmailer (= 5.2.6.2)
+ actionpack (= 5.2.6.2)
+ actionview (= 5.2.6.2)
+ activejob (= 5.2.6.2)
+ activemodel (= 5.2.6.2)
+ activerecord (= 5.2.6.2)
+ activestorage (= 5.2.6.2)
+ activesupport (= 5.2.6.2)
bundler (>= 1.3.0)
- railties (= 5.2.6)
+ railties (= 5.2.6.2)
sprockets-rails (>= 2.0.0)
rails-dom-testing (2.0.3)
activesupport (>= 4.2.0)
nokogiri (>= 1.6)
rails-html-sanitizer (1.4.2)
loofah (~> 2.3)
- railties (5.2.6)
- actionpack (= 5.2.6)
- activesupport (= 5.2.6)
+ railties (5.2.6.2)
+ actionpack (= 5.2.6.2)
+ activesupport (= 5.2.6.2)
method_source
rake (>= 0.8.7)
thor (>= 0.19.0, < 2.0)
- rainbow (3.0.0)
+ rainbow (3.1.1)
rake (13.0.6)
rbpdf (1.20.1)
htmlentities
@@ -136,7 +136,7 @@ GEM
rbpdf-font (1.19.1)
redcarpet (3.5.1)
regexp_parser (1.8.2)
- request_store (1.5.0)
+ request_store (1.5.1)
rack (>= 1.4)
rexml (3.2.5)
roadie (4.0.0)
@@ -147,7 +147,7 @@ GEM
roadie (>= 3.1, < 5.0)
rotp (6.2.0)
rouge (3.26.1)
- rqrcode (2.1.0)
+ rqrcode (2.1.1)
chunky_png (~> 1.0)
rqrcode_core (~> 1.0)
rqrcode_core (1.2.0)
@@ -160,8 +160,8 @@ GEM
rubocop-ast (>= 1.2.0, < 2.0)
ruby-progressbar (~> 1.7)
unicode-display_width (>= 1.4.0, < 3.0)
- rubocop-ast (1.12.0)
- parser (>= 3.0.1.1)
+ rubocop-ast (1.16.0)
+ parser (>= 3.1.1.0)
rubocop-performance (1.10.2)
rubocop (>= 0.90.0, < 2.0)
rubocop-ast (>= 0.4.0)
@@ -172,8 +172,9 @@ GEM
ruby-openid (2.9.2)
ruby-progressbar (1.11.0)
rubyzip (2.3.2)
- selenium-webdriver (3.142.7)
- childprocess (>= 0.5, < 4.0)
+ selenium-webdriver (4.1.0)
+ childprocess (>= 0.5, < 5.0)
+ rexml (~> 3.2, >= 3.2.5)
rubyzip (>= 1.2.2)
simplecov (0.18.5)
docile (~> 1.1)
@@ -182,25 +183,27 @@ GEM
sprockets (4.0.2)
concurrent-ruby (~> 1.0)
rack (> 1, < 3)
- sprockets-rails (3.2.2)
- actionpack (>= 4.0)
- activesupport (>= 4.0)
+ sprockets-rails (3.4.2)
+ actionpack (>= 5.2)
+ activesupport (>= 5.2)
sprockets (>= 3.0.0)
- thor (1.1.0)
+ thor (1.2.1)
thread_safe (0.3.6)
tzinfo (1.2.9)
thread_safe (~> 0.1)
unicode-display_width (2.1.0)
- webdrivers (4.6.1)
+ webdrivers (4.7.0)
nokogiri (~> 1.6)
rubyzip (>= 1.3.0)
- selenium-webdriver (>= 3.0, < 4.0)
+ selenium-webdriver (> 3.141, < 5.0)
+ webrick (1.7.0)
websocket-driver (0.7.5)
websocket-extensions (>= 0.1.0)
websocket-extensions (0.1.5)
xpath (3.2.0)
nokogiri (~> 1.8)
- yard (0.9.26)
+ yard (0.9.27)
+ webrick (~> 1.7.0)
PLATFORMS
ruby
@@ -224,7 +227,7 @@ DEPENDENCIES
pg (~> 1.2.2)
puma
rack-openid
- rails (= 5.2.6)
+ rails (= 5.2.6.2)
rails-dom-testing
rbpdf (~> 1.20.0)
redcarpet (~> 3.5.1)
diff --git a/pkgs/applications/version-management/redmine/default.nix b/pkgs/applications/version-management/redmine/default.nix
index 5a964f51e362..39e46d90b88d 100644
--- a/pkgs/applications/version-management/redmine/default.nix
+++ b/pkgs/applications/version-management/redmine/default.nix
@@ -1,7 +1,7 @@
{ lib, stdenv, fetchurl, bundlerEnv, ruby, makeWrapper }:
let
- version = "4.2.3";
+ version = "4.2.4";
rubyEnv = bundlerEnv {
name = "redmine-env-${version}";
@@ -15,8 +15,10 @@ in
inherit version;
src = fetchurl {
- url = "https://www.redmine.org/releases/${pname}-${version}.tar.gz";
- sha256 = "033slhr5kmz5b29v7n52336i0r7y4m9si748b22r85s2jpf37xkj";
+ # https://www.redmine.org/news/134
+ # > "These releases are not available yet on the releases page from a technical reason, we are sorry for this and we expected to have them uploaded next week. I'll post here an update after we have them uploaded."
+ url = "https://www.redmine.org/attachments/download/28862/${pname}-${version}.tar.gz";
+ sha256 = "7f50fd4a6cf1c1e48091a87696b813ba264e11f04dec67fb006858a1b49a5c7d";
};
nativeBuildInputs = [ makeWrapper ];
diff --git a/pkgs/applications/version-management/redmine/gemset.nix b/pkgs/applications/version-management/redmine/gemset.nix
index dbbef0f218aa..a18e819fc90a 100644
--- a/pkgs/applications/version-management/redmine/gemset.nix
+++ b/pkgs/applications/version-management/redmine/gemset.nix
@@ -5,10 +5,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "1s778lwghaf0zwfvbhzvjq691rl75d85raiqg1c7zly8p9afq8ym";
+ sha256 = "0il9l30jz1gfjccrahfk2gl57b31dqgjlzjc8cfifm76ggywmz67";
type = "gem";
};
- version = "5.2.6";
+ version = "5.2.6.2";
};
actionmailer = {
dependencies = ["actionpack" "actionview" "activejob" "mail" "rails-dom-testing"];
@@ -16,10 +16,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "0gwvn4lrkhqmxp96npjp4sfaz78h9ab2lrl20sjph7xxakfwknld";
+ sha256 = "1cci24da56d467ldq40n3l176h9qdw691w1b703c251izh6c4n5d";
type = "gem";
};
- version = "5.2.6";
+ version = "5.2.6.2";
};
actionpack = {
dependencies = ["actionview" "activesupport" "rack" "rack-test" "rails-dom-testing" "rails-html-sanitizer"];
@@ -27,10 +27,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "0b2xl458f2ygnjbvv0hacc8bk9qxbx64m2g7vw6f9y7k8q85930y";
+ sha256 = "1xis55xvs4hja6fnmj4785rzafk553k5f0xb7jprqf38c6dzmiak";
type = "gem";
};
- version = "5.2.6";
+ version = "5.2.6.2";
};
actionpack-xml_parser = {
dependencies = ["actionpack" "railties"];
@@ -49,10 +49,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "06f8212kplqhap9jpi49dvqlhwkfxxxm9nh8al6qjvl7mfh9qbzg";
+ sha256 = "00a9g63xwfimnzsrcrnr4vmdwhg7jaic49jas70r695nznwkxr9x";
type = "gem";
};
- version = "5.2.6";
+ version = "5.2.6.2";
};
activejob = {
dependencies = ["activesupport" "globalid"];
@@ -60,10 +60,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "1cdvxkbzbs4cdh4bgf2cg7i886a20gvr43hg76kx5rzd8xal7xnd";
+ sha256 = "0fm5qxrv8pxhl7m88p17xxpizddasm9kknaldkax8im3b9vrgnr9";
type = "gem";
};
- version = "5.2.6";
+ version = "5.2.6.2";
};
activemodel = {
dependencies = ["activesupport"];
@@ -71,10 +71,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "1r28kcnzr8dm6idirndd8pvbmg5c678ijxk845g84ykq1l69czs6";
+ sha256 = "0k0xizwbcadmslc8rkg2vnsbrsqivm6yj2yjrzb6rhqwphcr9zjf";
type = "gem";
};
- version = "5.2.6";
+ version = "5.2.6.2";
};
activerecord = {
dependencies = ["activemodel" "activesupport" "arel"];
@@ -82,10 +82,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "05qqnichgxml6z3d1dpgjy2fi62dppnqxgg37hr9a35hwhn05fzc";
+ sha256 = "1m00zh62rfn2h15vfn89jg39wxmghc88v2vjb5r4m0c7g24vrb14";
type = "gem";
};
- version = "5.2.6";
+ version = "5.2.6.2";
};
activestorage = {
dependencies = ["actionpack" "activerecord" "marcel"];
@@ -93,10 +93,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "0wnzac1qs4y339p13xyr03rx4ql3i4ywzfhyzn118d2zz82xnpfl";
+ sha256 = "0h3z331xli0j5didh0g9cv4zrlx32b5csp1566fpy0fr2kgqmpi9";
type = "gem";
};
- version = "5.2.6";
+ version = "5.2.6.2";
};
activesupport = {
dependencies = ["concurrent-ruby" "i18n" "minitest" "tzinfo"];
@@ -104,10 +104,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "1vybx4cj42hr6m8cdwbrqq2idh98zms8c11kr399xjczhl9ywjbj";
+ sha256 = "164lmi9w96wdwd00dnly8f9dcak3blv49ymyqz30q2fdjn45c775";
type = "gem";
};
- version = "5.2.6";
+ version = "5.2.6.2";
};
addressable = {
dependencies = ["public_suffix"];
@@ -166,10 +166,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "1ic028k8xgm2dds9mqnvwwx3ibaz32j8455zxr9f4bcnviyahya5";
+ sha256 = "1lvcp8bsd35g57f7wz4jigcw2sryzzwrpcgjwwf3chmjrjcww5in";
type = "gem";
};
- version = "3.0.0";
+ version = "4.1.0";
};
chunky_png = {
groups = ["default"];
@@ -207,10 +207,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "1q8gj3wkc2mbzsqw5zcsr3kyzrrb2pda03pi769rjbvqr94g3bm5";
+ sha256 = "1qbdgp36dhcyljhmfxrvbgp1ha9yqxhxgyg3sdm48y9m371jd2an";
type = "gem";
};
- version = "1.10.0";
+ version = "1.11.0";
};
csv = {
groups = ["default"];
@@ -248,10 +248,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "0k6ww3shk3mv119xvr9m99l6ql0czq91xhd66hm8hqssb18r2lvm";
+ sha256 = "1n5yc058i8xhi1fwcp1w7mfi6xaxfmrifdb4r4hjfff33ldn8lqj";
type = "gem";
};
- version = "0.5.2";
+ version = "1.0.0";
};
htmlentities = {
groups = ["default"];
@@ -269,10 +269,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "0g2fnag935zn2ggm5cn6k4s4xvv53v2givj1j90szmvavlpya96a";
+ sha256 = "0vdd1kii40qhbr9n8qx71k2gskq6rkl8ygy8hw5hfj8bb5a364xf";
type = "gem";
};
- version = "1.8.10";
+ version = "1.8.11";
};
loofah = {
dependencies = ["crass" "nokogiri"];
@@ -280,10 +280,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "1nqcya57x2n58y1dify60i0dpla40n4yir928khp4nj5jrn9mgmw";
+ sha256 = "0z8bdcmw66j3dy6ivcc02yq32lx3n9bavx497llln8qy014xjm4w";
type = "gem";
};
- version = "2.12.0";
+ version = "2.14.0";
};
mail = {
dependencies = ["mini_mime"];
@@ -351,10 +351,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "19z7wkhg59y8abginfrm2wzplz7py3va8fyngiigngqvsws6cwgl";
+ sha256 = "06xf558gid4w8lwx13jwfdafsch9maz8m0g85wnfymqj63x5nbbd";
type = "gem";
};
- version = "5.14.4";
+ version = "5.15.0";
};
mocha = {
groups = ["test"];
@@ -431,10 +431,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "06ma6w87ph8lnc9z4hi40ynmcdnjv0p8x53x0s3fjkz4q2p6sxh5";
+ sha256 = "0zaghgvva2q4jqbachg8jvpwgbg3w1jqr0d00m8rqciqznjgsw3c";
type = "gem";
};
- version = "3.0.2.0";
+ version = "3.1.1.0";
};
pg = {
groups = ["default"];
@@ -470,20 +470,20 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "1xblxnrs0c5m326v7kgr32k4m00cl2ipcf5m0qvyisrw62vd5dbn";
+ sha256 = "1np2myaxlk5iab1zarwgmp7zsjvm5j8ssg35ijv8b6dpvc3cjd56";
type = "gem";
};
- version = "5.5.2";
+ version = "5.6.2";
};
racc = {
groups = ["default" "test"];
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "178k7r0xn689spviqzhvazzvxfq6fyjldxb3ywjbgipbfi4s8j1g";
+ sha256 = "0la56m0z26j3mfn1a9lf2l03qx1xifanndf9p3vx1azf6sqy7v9d";
type = "gem";
};
- version = "1.5.2";
+ version = "1.6.0";
};
rack = {
groups = ["default" "openid" "test"];
@@ -523,10 +523,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "1p17dmifd0v3knh9wja4z4rv0qaybwansnwxmvx6f3rcgkszkpnc";
+ sha256 = "0fgbld733j2j85pf8kpv1mvp8rmlkqs7ccv77q2mwfm7ri4yisy0";
type = "gem";
};
- version = "5.2.6";
+ version = "5.2.6.2";
};
rails-dom-testing = {
dependencies = ["activesupport" "nokogiri"];
@@ -556,20 +556,20 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "0rs97fxv13hgpbmyhk8ag8qzgkh25css0797h90k9w1vg9djl84k";
+ sha256 = "1fgyw80j2mss3hdhzxa1b12c7j17az55znq0d16md69if8dwfmic";
type = "gem";
};
- version = "5.2.6";
+ version = "5.2.6.2";
};
rainbow = {
groups = ["default" "test"];
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "0bb2fpjspydr6x0s8pn1pqkzmxszvkfapv0p4627mywl7ky4zkhk";
+ sha256 = "0smwg4mii0fm38pyb5fddbmrdpifwv22zv3d3px2xx497am93503";
type = "gem";
};
- version = "3.0.0";
+ version = "3.1.1";
};
rake = {
groups = ["default"];
@@ -628,10 +628,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "0cx74kispmnw3ljwb239j65a2j14n8jlsygy372hrsa8mxc71hxi";
+ sha256 = "13ppgmsbrqah08j06bybd3cddv6dml79yzyjn7r8j1src78h98h7";
type = "gem";
};
- version = "1.5.0";
+ version = "1.5.1";
};
rexml = {
groups = ["default" "test"];
@@ -691,10 +691,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "0444sgvx3ahvgr3c9swpy32kcdpciwgcqahp3pb4m7d23xp1qjdc";
+ sha256 = "10sq4aknch9rzpy8af77rqxk8rr59d33slg1kwg9h7fw9f1spmjn";
type = "gem";
};
- version = "2.1.0";
+ version = "2.1.1";
};
rqrcode_core = {
groups = ["default"];
@@ -723,10 +723,10 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "0x0xfq2mpg194rcanbjrgvjbh94s9kq72jynxx61789s628kxy59";
+ sha256 = "1bd2z82ly7fix8415gvfiwzb6bjialz5rs3sr72kv1lk68rd23wv";
type = "gem";
};
- version = "1.12.0";
+ version = "1.16.0";
};
rubocop-performance = {
dependencies = ["rubocop" "rubocop-ast"];
@@ -781,15 +781,15 @@
version = "2.3.2";
};
selenium-webdriver = {
- dependencies = ["childprocess" "rubyzip"];
+ dependencies = ["childprocess" "rexml" "rubyzip"];
groups = ["test"];
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "0adcvp86dinaqq3nhf8p3m0rl2g6q0a4h52k0i7kdnsg1qz9k86y";
+ sha256 = "17hilxa40cj7q48k6wcx1cbdb1v3q9c4nx89fji7gyqpcfm16vq7";
type = "gem";
};
- version = "3.142.7";
+ version = "4.1.0";
};
simplecov = {
dependencies = ["docile" "simplecov-html"];
@@ -829,20 +829,20 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "0mwmz36265646xqfyczgr1mhkm1hfxgxxvgdgr4xfcbf2g72p1k2";
+ sha256 = "1b9i14qb27zs56hlcc2hf139l0ghbqnjpmfi0054dxycaxvk5min";
type = "gem";
};
- version = "3.2.2";
+ version = "3.4.2";
};
thor = {
groups = ["default"];
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "18yhlvmfya23cs3pvhr1qy38y41b6mhr5q9vwv5lrgk16wmf3jna";
+ sha256 = "0inl77jh4ia03jw3iqm5ipr76ghal3hyjrd6r8zqsswwvi9j2xdi";
type = "gem";
};
- version = "1.1.0";
+ version = "1.2.1";
};
thread_safe = {
groups = ["default" "test"];
@@ -881,10 +881,20 @@
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "1naymcfmm9pkf0f67xd99d9f6dpv477ggyvc1c04gxifirynfydp";
+ sha256 = "05fdb6z8541p912xanjbl9y15cyj6g44530y0nib6qhv6i90rkzp";
type = "gem";
};
- version = "4.6.1";
+ version = "4.7.0";
+ };
+ webrick = {
+ groups = ["default" "development"];
+ platforms = [];
+ source = {
+ remotes = ["https://rubygems.org"];
+ sha256 = "1d4cvgmxhfczxiq5fr534lmizkhigd15bsx5719r5ds7k7ivisc7";
+ type = "gem";
+ };
+ version = "1.7.0";
};
websocket-driver = {
dependencies = ["websocket-extensions"];
@@ -919,13 +929,14 @@
version = "3.2.0";
};
yard = {
+ dependencies = ["webrick"];
groups = ["development"];
platforms = [];
source = {
remotes = ["https://rubygems.org"];
- sha256 = "0qzr5j1a1cafv81ib3i51qyl8jnmwdxlqi3kbiraldzpbjh4ln9h";
+ sha256 = "0d08gkis1imlvppyh8dbslk89hwj5af2fmlzvmwahgx2bm48d9sn";
type = "gem";
};
- version = "0.9.26";
+ version = "0.9.27";
};
}
diff --git a/pkgs/development/coq-modules/mathcomp-bigenough/default.nix b/pkgs/development/coq-modules/mathcomp-bigenough/default.nix
index 296bd738928f..2283d5ef1733 100644
--- a/pkgs/development/coq-modules/mathcomp-bigenough/default.nix
+++ b/pkgs/development/coq-modules/mathcomp-bigenough/default.nix
@@ -6,9 +6,15 @@ with lib; mkCoqDerivation {
pname = "bigenough";
owner = "math-comp";
- release = { "1.0.0".sha256 = "10g0gp3hk7wri7lijkrqna263346wwf6a3hbd4qr9gn8hmsx70wg"; };
+ release = {
+ "1.0.0".sha256 = "10g0gp3hk7wri7lijkrqna263346wwf6a3hbd4qr9gn8hmsx70wg";
+ "1.0.1".sha256 = "sha256:02f4dv4rz72liciwxb2k7acwx6lgqz4381mqyq5854p3nbyn06aw";
+ };
inherit version;
- defaultVersion = "1.0.0";
+ defaultVersion = with versions; switch coq.version [
+ { case = range "8.10" "8.15"; out = "1.0.1"; }
+ { case = range "8.5" "8.14"; out = "1.0.0"; }
+ ] null;
propagatedBuildInputs = [ mathcomp.ssreflect ];
diff --git a/pkgs/development/libraries/pipewire/default.nix b/pkgs/development/libraries/pipewire/default.nix
index 5600cbd266b9..6c8cbd11ee5a 100644
--- a/pkgs/development/libraries/pipewire/default.nix
+++ b/pkgs/development/libraries/pipewire/default.nix
@@ -26,6 +26,8 @@
, webrtc-audio-processing
, ncurses
, readline81 # meson can't find <7 as those versions don't have a .pc file
+, lilv
+, openssl
, makeFontsConf
, callPackage
, nixosTests
@@ -63,7 +65,7 @@ let
self = stdenv.mkDerivation rec {
pname = "pipewire";
- version = "0.3.40";
+ version = "0.3.42";
outputs = [
"out"
@@ -81,7 +83,7 @@ let
owner = "pipewire";
repo = "pipewire";
rev = version;
- sha256 = "sha256-eY6uQa4+sC6yUWhF4IpAgRoppwhHO4s5fIMXOkS0z7A=";
+ sha256 = "sha256-Iyd5snOt+iCT7W0+FlfvhMUZo/gF+zr9JX4HIGVdHto=";
};
patches = [
@@ -125,7 +127,9 @@ let
libjack2
libusb1
libsndfile
+ lilv
ncurses
+ openssl
readline81
udev
vulkan-headers
diff --git a/pkgs/development/python-modules/celery/default.nix b/pkgs/development/python-modules/celery/default.nix
index cd6d21b7c651..1f15c611a0cb 100644
--- a/pkgs/development/python-modules/celery/default.nix
+++ b/pkgs/development/python-modules/celery/default.nix
@@ -1,6 +1,7 @@
{ lib, buildPythonPackage, fetchPypi
, billiard, click, click-didyoumean, click-plugins, click-repl, kombu, pytz, vine
, boto3, case, moto, pytest, pytest-celery, pytest-subtests, pytest-timeout
+, fetchpatch
}:
buildPythonPackage rec {
@@ -12,6 +13,14 @@ buildPythonPackage rec {
sha256 = "8d9a3de9162965e97f8e8cc584c67aad83b3f7a267584fa47701ed11c3e0d4b0";
};
+ patches = [
+ (fetchpatch {
+ name = "CVE-2021-23727.patch";
+ url = "https://github.com/celery/celery/commit/1f7ad7e6df1e02039b6ab9eec617d283598cad6b.patch";
+ sha256 = "0dhd4hq2piv0iqjd9dap6dvxhb2c24mrnrgz31f8wcql4vdlf8n1";
+ })
+ ];
+
# click is only used for the repl, in most cases this shouldn't impact
# downstream packages
postPatch = ''
diff --git a/pkgs/development/tools/build-managers/bloop/default.nix b/pkgs/development/tools/build-managers/bloop/default.nix
index 10d3dca84123..11b25bec3816 100644
--- a/pkgs/development/tools/build-managers/bloop/default.nix
+++ b/pkgs/development/tools/build-managers/bloop/default.nix
@@ -11,7 +11,7 @@
stdenv.mkDerivation rec {
pname = "bloop";
- version = "1.4.12";
+ version = "1.4.13";
bloop-coursier-channel = fetchurl {
url = "https://github.com/scalacenter/bloop/releases/download/v${version}/bloop-coursier.json";
@@ -60,8 +60,8 @@ stdenv.mkDerivation rec {
outputHashMode = "recursive";
outputHashAlgo = "sha256";
- outputHash = if stdenv.isLinux && stdenv.isx86_64 then "jqcecAM51qEDmTim2VBNm8IO8wQmwU19R57Zk4pxwSA="
- else if stdenv.isDarwin && stdenv.isx86_64 then "15m2rahf9kihw29hp6bwd9xqav6dcr17w5c2rsw0ijpchr2av72q"
+ outputHash = if stdenv.isLinux && stdenv.isx86_64 then "sha256-jqcecAM51qEDmTim2VBNm8IO8wQmwU19R57Zk4pxwSA="
+ else if stdenv.isDarwin && stdenv.isx86_64 then "sha256-WJytRIbsygi4zoIVfkJmzWyFe2p8mQuT4DDO5KDKopY="
else throw "unsupported platform";
};
diff --git a/pkgs/development/tools/build-managers/samurai/default.nix b/pkgs/development/tools/build-managers/samurai/default.nix
index 1fb4206d5cec..cd058bfc2632 100644
--- a/pkgs/development/tools/build-managers/samurai/default.nix
+++ b/pkgs/development/tools/build-managers/samurai/default.nix
@@ -1,4 +1,4 @@
-{ lib, stdenv, fetchFromGitHub }:
+{ lib, stdenv, fetchFromGitHub, fetchpatch }:
stdenv.mkDerivation rec {
pname = "samurai";
@@ -13,6 +13,19 @@ stdenv.mkDerivation rec {
makeFlags = [ "DESTDIR=" "PREFIX=${placeholder "out"}" ];
+ patches = [
+ (fetchpatch {
+ name = "CVE-2021-30218.patch";
+ url = "https://github.com/michaelforney/samurai/commit/e84b6d99c85043fa1ba54851ee500540ec206918.patch";
+ sha256 = "sha256-hyndwj6st4rwOJ35Iu0qL12dR5E6CBvsulvR27PYKMw=";
+ })
+ (fetchpatch {
+ name = "CVE-2021-30219.patch";
+ url = "https://github.com/michaelforney/samurai/commit/d2af3bc375e2a77139c3a28d6128c60cd8d08655.patch";
+ sha256 = "sha256-rcdwKjHeq5Oaga9wezdHSg/7ljkynfbnkBc2ciMW5so=";
+ })
+ ];
+
meta = with lib; {
description = "ninja-compatible build tool written in C";
homepage = "https://github.com/michaelforney/samurai";
diff --git a/pkgs/development/tools/build-managers/scala-cli/default.nix b/pkgs/development/tools/build-managers/scala-cli/default.nix
index 33f9811ab836..979cbae99a20 100644
--- a/pkgs/development/tools/build-managers/scala-cli/default.nix
+++ b/pkgs/development/tools/build-managers/scala-cli/default.nix
@@ -1,15 +1,15 @@
{ stdenv, coreutils, lib, installShellFiles, zlib, autoPatchelfHook, fetchurl }:
let
- version = "0.0.9";
+ version = "0.1.0";
assets = {
x86_64-darwin = {
asset = "scala-cli-x86_64-apple-darwin.gz";
- sha256 = "sha256-1KwJuapqGhMEIMwrJp2LKlpYFtl+OP9DyaMtge9ZedI=";
+ sha256 = "sha256-YoMwtaif7q7Ht8fWRQRGeP03Pl5KTIUk8fGGKhelc68=";
};
x86_64-linux = {
asset = "scala-cli-x86_64-pc-linux.gz";
- sha256 = "sha256-IDXO+MgFlnT7VPugcQr/IGLZeD/vWFqJ0D0zVIbTtk4=";
+ sha256 = "sha256-YjMdhuo9hQCGtq1qYFKUY8S6nz8dpZt+PsngbF6r/C8=";
};
};
in
diff --git a/pkgs/misc/emulators/cdemu/vhba.nix b/pkgs/misc/emulators/cdemu/vhba.nix
index 6e7cb08e449a..aeadcf5c1c1d 100644
--- a/pkgs/misc/emulators/cdemu/vhba.nix
+++ b/pkgs/misc/emulators/cdemu/vhba.nix
@@ -2,11 +2,11 @@
stdenv.mkDerivation rec {
pname = "vhba";
- version = "20211023";
+ version = "20211218";
src = fetchurl {
url = "mirror://sourceforge/cdemu/vhba-module-${version}.tar.xz";
- sha256 = "sha256-YAh7qqkozvoG1WhHBv7z1IcSrP75LLMq/FB6sZrevxA=";
+ sha256 = "sha256-csWowcRSgF5M74yv787MLSXOGXrkxnODCCgC5a3Nd7Y=";
};
makeFlags = [ "KDIR=${kernel.dev}/lib/modules/${kernel.modDirVersion}/build" "INSTALL_MOD_PATH=$(out)" ];
diff --git a/pkgs/misc/vscode-extensions/python/default.nix b/pkgs/misc/vscode-extensions/python/default.nix
index beaa8d557a75..09c5c02aee93 100644
--- a/pkgs/misc/vscode-extensions/python/default.nix
+++ b/pkgs/misc/vscode-extensions/python/default.nix
@@ -72,13 +72,15 @@ in vscode-utils.buildVscodeMarketplaceExtension rec {
icu
curl
openssl
+ ] ++ lib.optionals stdenv.isLinux [
lttng-ust-2-10
musl
];
nativeBuildInputs = [
- autoPatchelfHook
python3.pkgs.wrapPython
+ ] ++ lib.optionals stdenv.isLinux [
+ autoPatchelfHook
];
pythonPath = with python3.pkgs; [
@@ -101,6 +103,8 @@ in vscode-utils.buildVscodeMarketplaceExtension rec {
cd pythonFiles/lib/python/debugpy/_vendored/pydevd/pydevd_attach_to_process
declare kept_aside="${{
"x86_64-linux" = "attach_linux_amd64.so";
+ "aarch64-darwin" = "attach_x86_64.dylib";
+ "x86_64-darwin" = "attach_x86_64.dylib";
}.${stdenv.hostPlatform.system} or (throw "Unsupported system: ${stdenv.hostPlatform.system}")}"
mv "$kept_aside" "$kept_aside.hidden"
rm *.so *.dylib *.dll *.exe *.pdb
@@ -118,7 +122,7 @@ in vscode-utils.buildVscodeMarketplaceExtension rec {
meta = with lib; {
license = licenses.mit;
- platforms = [ "x86_64-linux" ];
- maintainers = [ maintainers.jraygauthier ];
+ platforms = [ "x86_64-linux" "aarch64-darwin" "x86_64-darwin" ];
+ maintainers = with maintainers; [ jraygauthier jfchevrette ];
};
}
diff --git a/pkgs/os-specific/linux/bionic-prebuilt/default.nix b/pkgs/os-specific/linux/bionic-prebuilt/default.nix
index 920732a2020d..8fa17036c4ad 100644
--- a/pkgs/os-specific/linux/bionic-prebuilt/default.nix
+++ b/pkgs/os-specific/linux/bionic-prebuilt/default.nix
@@ -1,4 +1,6 @@
-{ stdenvNoCC, lib, fetchzip, pkgs
+{ stdenv, stdenvNoCC, lib, fetchzip, pkgs
+, enableStatic ? stdenv.hostPlatform.isStatic
+, enableShared ? !stdenv.hostPlatform.isStatic
}:
let
@@ -92,10 +94,17 @@ stdenvNoCC.mkDerivation rec {
cp -v ${prebuilt_crt.out}/*.o $out/lib/
cp -v ${prebuilt_crt.out}/libgcc.a $out/lib/
cp -v ${prebuilt_ndk_crt.out}/*.o $out/lib/
+ '' + lib.optionalString enableShared ''
for i in libc.so libm.so libdl.so liblog.so; do
cp -v ${prebuilt_libs.out}/$i $out/lib/
done
-
+ '' + lib.optionalString enableStatic ''
+ # no liblog.a; while it's also part of the base libraries,
+ # it's only available as shared object in the prebuilts.
+ for i in libc.a libm.a libdl.a; do
+ cp -v ${prebuilt_ndk_crt.out}/$i $out/lib/
+ done
+ '' + ''
mkdir -p $dev/include
cp -v $out/include/*.h $dev/include/
'';
diff --git a/pkgs/os-specific/linux/system76-power/default.nix b/pkgs/os-specific/linux/system76-power/default.nix
index 8ef0e40312f5..edaf2b5c8144 100644
--- a/pkgs/os-specific/linux/system76-power/default.nix
+++ b/pkgs/os-specific/linux/system76-power/default.nix
@@ -2,19 +2,19 @@
rustPlatform.buildRustPackage rec {
pname = "system76-power";
- version = "1.1.18";
+ version = "1.1.20";
src = fetchFromGitHub {
owner = "pop-os";
repo = "system76-power";
rev = version;
- sha256 = "1zm06ywc3siwh2fpb8p7lp3xqjy4c08j8c8lipd6dyy3bakjh4r1";
+ sha256 = "sha256-Qk9zHqwFlUTWE+YRt2GASIekbDoBCHPAUUN3+0wpvfw=";
};
nativeBuildInputs = [ pkg-config ];
buildInputs = [ dbus libusb1 ];
- cargoSha256 = "0hda8cxa1pjz90bg215qmx5x2scz9mawq7irxbsw6zmcm7wahlii";
+ cargoSha256 = "sha256-iG7M9ICFRTFVkbC89DyfR+Iyi7jaT9WmG3PSdBOF7YI=";
postInstall = ''
install -D -m 0644 data/system76-power.conf $out/etc/dbus-1/system.d/system76-power.conf
diff --git a/pkgs/servers/openafs/1.8/default.nix b/pkgs/servers/openafs/1.8/default.nix
index 918a20ce5a32..e84cac380ab3 100644
--- a/pkgs/servers/openafs/1.8/default.nix
+++ b/pkgs/servers/openafs/1.8/default.nix
@@ -1,7 +1,23 @@
-{ lib, stdenv, buildPackages, fetchurl, which, autoconf, automake, flex
-, bison , glibc, perl, libkrb5, libxslt, docbook_xsl, file
-, docbook_xml_dtd_43, libtool_2
-, withDevdoc ? false, doxygen, dblatex # Extra developer documentation
+{ lib
+, stdenv
+, buildPackages
+, fetchurl
+, which
+, autoconf
+, automake
+, flex
+, bison
+, glibc
+, perl
+, libkrb5
+, libxslt
+, docbook_xsl
+, file
+, docbook_xml_dtd_43
+, libtool_2
+, withDevdoc ? false
+, doxygen
+, dblatex # Extra developer documentation
, ncurses # Extra ncurses utilities. Needed for debugging and monitoring.
, tsmbac ? null # Tivoli Storage Manager Backup Client from IBM
}:
@@ -10,13 +26,22 @@ with (import ./srcs.nix { inherit fetchurl; });
let
inherit (lib) optional optionalString optionals;
-in stdenv.mkDerivation {
+in
+stdenv.mkDerivation {
pname = "openafs";
inherit version srcs;
depsBuildBuild = [ buildPackages.stdenv.cc ];
- nativeBuildInputs = [ autoconf automake flex libxslt libtool_2 perl
- which bison ] ++ optionals withDevdoc [ doxygen dblatex ];
+ nativeBuildInputs = [
+ autoconf
+ automake
+ flex
+ libxslt
+ libtool_2
+ perl
+ which
+ bison
+ ] ++ optionals withDevdoc [ doxygen dblatex ];
buildInputs = [ libkrb5 ncurses ];
diff --git a/pkgs/servers/openafs/1.8/module.nix b/pkgs/servers/openafs/1.8/module.nix
index 2543aef37690..f8b2d222af17 100644
--- a/pkgs/servers/openafs/1.8/module.nix
+++ b/pkgs/servers/openafs/1.8/module.nix
@@ -1,5 +1,17 @@
-{ lib, stdenv, fetchurl, which, autoconf, automake, flex, bison
-, kernel, glibc, perl, libtool_2, libkrb5, fetchpatch }:
+{ lib
+, stdenv
+, fetchurl
+, which
+, autoconf
+, automake
+, flex
+, bison
+, kernel
+, glibc
+, perl
+, libtool_2
+, libkrb5
+}:
with (import ./srcs.nix {
inherit fetchurl;
@@ -9,7 +21,8 @@ let
modDestDir = "$out/lib/modules/${kernel.modDirVersion}/extra/openafs";
kernelBuildDir = "${kernel.dev}/lib/modules/${kernel.modDirVersion}/build";
-in stdenv.mkDerivation {
+in
+stdenv.mkDerivation {
name = "openafs-${version}-${kernel.modDirVersion}";
inherit version src;
@@ -18,23 +31,6 @@ in stdenv.mkDerivation {
buildInputs = [ libkrb5 ];
- patches = [
- # LINUX 5.14: explicitly set set_page_dirty to default
- ((fetchpatch {
- url = "https://gerrit.openafs.org/changes/14830/revisions/20b8a37950b3718b85a4a3d21b23469a5176eb6a/patch";
- sha256 = "1mkfwq0pbwvfjspsy2lxhi0f09hljgc6xyn3y97sai0dyivn05jp";
- }).overrideAttrs (o: {
- postFetch = "mv $out p; base64 -d p > $out; " + o.postFetch;
- }))
- # Linux 5.15: Convert osi_Msg macro to a function
- ((fetchpatch {
- url = "https://gerrit.openafs.org/changes/14831/revisions/6cfa9046229d90c0625687e3fddb7877f21fbcff/patch";
- sha256 = "18rip9a1krxf47fizf3f12ddq55apzb2w3wjj5qs7n3sh2nwks7g";
- }).overrideAttrs (o: {
- postFetch = "mv $out p; base64 -d p > $out; " + o.postFetch;
- }))
- ];
-
hardeningDisable = [ "pic" ];
configureFlags = [
diff --git a/pkgs/servers/openafs/1.8/srcs.nix b/pkgs/servers/openafs/1.8/srcs.nix
index f35903e50916..b8ea522fe4fe 100644
--- a/pkgs/servers/openafs/1.8/srcs.nix
+++ b/pkgs/servers/openafs/1.8/srcs.nix
@@ -1,14 +1,16 @@
{ fetchurl }:
rec {
- version = "1.8.8";
+ version = "1.8.8.1";
src = fetchurl {
url = "https://www.openafs.org/dl/openafs/${version}/openafs-${version}-src.tar.bz2";
- sha256 = "sha256-2qjvhqdyf6z83jvJemrRQxKcHCXuNfM0cIDsfp0oTaA=";
+ sha256 = "sha256-58S+1wdbzWQC4/DC1bnb52rS7jxf1d3DlzozVsoj70Q=";
};
- srcs = [ src
+ srcs = [
+ src
(fetchurl {
url = "https://www.openafs.org/dl/openafs/${version}/openafs-${version}-doc.tar.bz2";
- sha256 = "sha256-3cxODH1KvOTxrGB+acEudxGCX1iBPjZcTfjpfraOm+U=";
- })];
+ sha256 = "sha256-y17O3C4WS+o7SMayydbxw2v96R0GikxiqciF30j+jms=";
+ })
+ ];
}
diff --git a/pkgs/servers/peertube/default.nix b/pkgs/servers/peertube/default.nix
index 67f7fd76606c..9961e9d581aa 100644
--- a/pkgs/servers/peertube/default.nix
+++ b/pkgs/servers/peertube/default.nix
@@ -1,34 +1,33 @@
{ lib, stdenv, callPackage, fetchurl, fetchFromGitHub, buildGoModule, fetchYarnDeps, nixosTests
-, esbuild, fixup_yarn_lock, jq, nodejs, yarn
-, nodePackages, youtube-dl
+, fixup_yarn_lock, jq, nodejs, yarn
}:
let
arch =
if stdenv.hostPlatform.system == "x86_64-linux" then "linux-x64"
else throw "Unsupported architecture: ${stdenv.hostPlatform.system}";
- version = "3.4.1";
+ version = "4.1.0";
source = fetchFromGitHub {
owner = "Chocobozzz";
repo = "PeerTube";
rev = "v${version}";
- sha256 = "0l1ibqmliy4aq60a16v383v4ijv1c9sf2a35k9q365mkl42jbzx1";
+ sha256 = "sha256-gW/dzWns6wK3zzNjbW19HrV2jqzjdXR5uMMNXL4Xfdw=";
};
yarnOfflineCacheServer = fetchYarnDeps {
yarnLock = "${source}/yarn.lock";
- sha256 = "0zyxf1km79w6329jay4bcpw5bgvhnvmvl11r9hka5c6s46d3ms7n";
+ sha256 = "sha256-L1Nr6sGjYVm42OyeFOQeQ6WEXjmNkngWilBtfQJ6bPE=";
};
yarnOfflineCacheTools = fetchYarnDeps {
yarnLock = "${source}/server/tools/yarn.lock";
- sha256 = "12xmwc8lnalcpx3nww457avn5zw04ly4pp4kjxkvhsqs69arfl2m";
+ sha256 = "sha256-maPR8OCiuNlle0JQIkZSgAqW+BrSxPwVm6CkxIrIg5k=";
};
yarnOfflineCacheClient = fetchYarnDeps {
yarnLock = "${source}/client/yarn.lock";
- sha256 = "1glnip6mpizif36vil61sw8i8lnn0jg5hrqgqw6k4cc7hkd2qkpc";
+ sha256 = "sha256-wniMvtz7i3I4pn9xyzfNi1k7gQuzDl1GmEO8LqPBMKg=";
};
bcrypt_version = "5.0.1";
@@ -37,33 +36,12 @@ let
sha256 = "3R3dBZyPansTuM77Nmm3f7BbTDkDdiT2HQIrti2Ottc=";
};
- wrtc_version = "0.4.7";
- wrtc_lib = fetchurl {
- url = "https://node-webrtc.s3.amazonaws.com/wrtc/v${wrtc_version}/Release/${arch}.tar.gz";
- sha256 = "1zd3jlwq3lc2vhmr3bs1h6mrzyswdp3y20vb4d9s67ir9q7jn1zf";
- };
-
- esbuild_locked = buildGoModule rec {
- pname = "esbuild";
- version = "0.12.17";
-
- src = fetchFromGitHub {
- owner = "evanw";
- repo = "esbuild";
- rev = "v${version}";
- sha256 = "16xxscha2y69mgm20rpjdxykyqiy0qy8gayh8046q6m0sf6834y1";
- };
- vendorSha256 = "1n5538yik72x94vzfq31qaqrkpxds5xys1wlibw2gn2am0z5c06q";
- };
-
in stdenv.mkDerivation rec {
inherit version;
pname = "peertube";
src = source;
- nativeBuildInputs = [ esbuild fixup_yarn_lock jq nodejs yarn ];
-
- buildInputs = [ nodePackages.node-gyp-build youtube-dl ];
+ nativeBuildInputs = [ fixup_yarn_lock jq nodejs yarn ];
buildPhase = ''
# Build node modules
@@ -93,31 +71,16 @@ in stdenv.mkDerivation rec {
fi
mkdir -p ./lib/binding && tar -C ./lib/binding -xf ${bcrypt_lib}
- # Fix youtube-dl node module
- cd ~/node_modules/youtube-dl
- mkdir ./bin
- ln -s ${youtube-dl}/bin/youtube-dl ./bin/youtube-dl
- cat > ./bin/details <