diff --git a/doc/languages-frameworks/swift.section.md b/doc/languages-frameworks/swift.section.md index 76e4962fe9e3..eb826246613f 100644 --- a/doc/languages-frameworks/swift.section.md +++ b/doc/languages-frameworks/swift.section.md @@ -11,47 +11,86 @@ nix-shell -p swift --run 'swiftc -' <<< 'print("Hello world!")' The `swift` package also provides the `swift` command, with some caveats: -- Swift Package Manager (SwiftPM) is packaged separately as `swiftpm`. If you - need functionality like `swift build`, `swift run`, `swift test`, you must - also add the `swiftpm` package to your closure. -- On Darwin, the `swift repl` command requires an Xcode installation. This is - because it uses the system LLDB debugserver, which has special entitlements. +- Swift Package Manager (SwiftPM) is packaged separately as `swiftpm`. + If you need functionality like `swift build`, `swift run`, `swift test`, you must also add the `swiftpm` package to your closure. +- On Darwin, the `swift repl` command requires an Xcode installation. + This is because it uses the system LLDB debugserver, which has special entitlements. ## Module search paths {#ssec-swift-module-search-paths} -Like other toolchains in Nixpkgs, the Swift compiler executables are wrapped -to help Swift find your application's dependencies in the Nix store. These -wrappers scan the `buildInputs` of your package derivation for specific -directories where Swift modules are placed by convention, and automatically -add those directories to the Swift compiler search paths. +The Swift compiler executables are patched to find the C and C++ standard libraries associated with its target platform, but they are not wrapped. +They will not find your application’s dependencies automatically in the Nix store. +Your build system is expected to handle this for you. -Swift follows different conventions depending on the platform. The wrappers -look for the following directories: +SwiftPM provides a hook that scans the `buildInputs` of your package derivation for specific directories where the Swift modules are placed by convention. +These directories are added automatically to `swiftpmFlags` when the hook runs. +Swift in Nixpkgs follows a few conventions when installing dependencies: -- On Darwin platforms: `lib/swift/macosx` - (If not targeting macOS, replace `macosx` with the Xcode platform name.) -- On other platforms: `lib/swift/linux/x86_64` - (Where `linux` and `x86_64` are from lowercase `uname -sm`.) -- For convenience, Nixpkgs also adds `lib/swift` to the search path. - This can save a bit of work packaging Swift modules, because many Nix builds - will produce output for just one target anyway. +- Libraries (both shared and static) are installed to `lib`. + This differs from upstream packaging, but it matches how other langauges are packaged in Nixpkgs. + This allows Swift packages to take advantage of existing tooling that expects libraries to be installed in this standard location. +- Modules are installed to `lib/swift/` where `` is the Swift platform for your host platform (e.g., `lib/swift/macosx` or `lib/swift/linux`). + Note that Linux modules may be installed in a directory specific to the target architecture(e.g., `lib/swift/linux/x86_64`), but this is uncommon. + Upstream Swift appears to be moving away from this convention. ## Core libraries {#ssec-swift-core-libraries} -In addition to the standard library, the Swift toolchain contains some -additional 'core libraries' that, on Apple platforms, are normally distributed -as part of the OS or Xcode. These are packaged separately in Nixpkgs and can -be found (for use in `buildInputs`) as: +The `swift` package contains a complete toolchain with the Swift stdlib, Dispatch, Foundation, XCTest, and Swift Testing. +These packages do not need to be added to `buildInputs` when packaging applications. +The Swift compiler will find them automatically in the `swift` toolchain. -- `swiftPackages.Dispatch` -- `swiftPackages.Foundation` -- `swiftPackages.XCTest` +If you do need to use these packages outside of the Swift toolchain, they are available in the following packages: + +- `swiftPackages.stdlib` contains the Swift stdlib and backdeployment dylibs. +- `swiftPackages.swift-corelibs-libdispatch` contains the Dispatch framework. +- `swiftPackages.swift-corelibs-foundation` contains the Foundation framework. +- `swiftPackages.swift-corelibs-xctest` and `swiftPackages.swift-testing` contain the XCTest and Swift Testing frameworks respectively. + +Note: On Darwin, the Swift stdlib has been removed from the SDK. +The Swift toolchain contains the stubs and modules required to build Swift applications with the following exceptions: + +- Swift Differentiation is shipped as a dylib in Nixpkgs because it is no longer shipped with the OS (as of macOS 26.4). + This allows packages using Swift Differentiation to work regardless of OS version. +- The Span back-deployment dylib is shipped with the stdlib. +- This is expected because back-deployment dylibs are normally shipped with the toolchain. +- FoundationMacros is built and shipped as a dylib in `swiftPackages.swift-foundation` and included in the toolchain. + Macros are actually compiler plugins executed at build time. + Without this, FoundationMacros would not work on Darwin. ## Packaging with SwiftPM {#ssec-swift-packaging-with-swiftpm} -Nixpkgs includes a small helper `swiftpm2nix` that can fetch your SwiftPM -dependencies for you, when you need to write a Nix expression to package your -application. +Nixpkgs includes two ways to package dependencies for Swift applications: `fetchSwiftPMDeps` and `swiftpm2nix`. +While `swiftpm2nix` is not deprecated, using `fetchSwiftPMDeps` is preferred because it is easier to use and does not (usually) require shipping extra files with your package. + +### Packaging with `fetchSwiftPMDeps` {#ssec-swift-packaging-with-fetch-swiftpm-deps} + +Swift provides a fetcher that will download all of your dependencies based on the `Package.resolved` shipped by your package. +If your package does not ship one, you will have to generate it yourself and provide it with your package. +Otherwise, set `swiftpmDeps` as follows: + +```nix +{ + swiftpmDeps = fetchSwiftPMDeps { + inherit src; + hash = "sha256-1KfyrQXE1HaO9WsuskzgiiEZxM/oelp40Jwzr8xJEL4="; + }; +} +``` + +The `src` attribute is required as is the `hash`. +The first time you build your package, you will need to set `hash` to an empty value by using `lib.fakeHash` to get the hash for your dependencies. +The following optional attributes can also be used: + +- `name`: Sets the name of the vendored dependencies fixed-output derivation. + You can also use `pname` and `version` to set the `name`. + This is often easier because you can inherit them from `finalAttrs`. +- `sourceRoot`: Sets the path where `Package.swift` and `Package.resolved` can be found if they are not in their default, top-level location. +- `patches`: Can be used to apply patches to your project before the dependencies are vendored. + This is useful to update `Package.swift` or `Package.resolved`. +- `postPatch`: Can be used to perform extra steps after patching. + You can copy a custom `Package.resolved` in `postPatch`. + +### Packaging with `swiftpm2nix` {#ssec-swift-packaging-with-swiftpm2nix} The first step is to run the generator: @@ -65,8 +104,8 @@ swift package resolve swiftpm2nix ``` -This produces some files in a directory `nix`, which will be part of your Nix -expression. The next step is to write that expression: +This produces some files in a directory `nix`, which will be part of your Nix expression. +The next step is to write that expression: ```nix { @@ -126,45 +165,13 @@ stdenv.mkDerivation (finalAttrs: { }) ``` -### Custom build flags {#ssec-swiftpm-custom-build-flags} +#### Patching dependencies {#ssec-swiftpm-patching-dependencies} -If you'd like to build a different configuration than `release`: +In some cases, it may be necessary to patch a SwiftPM dependency. +SwiftPM dependencies are located in `.build/checkouts`, but the `swiftpm2nix` helper provides these as symlinks to read-only `/nix/store` paths. +To patch them, we need to make them writable. -```nix -{ swiftpmBuildConfig = "debug"; } -``` - -It is also possible to provide additional flags to `swift build`: - -```nix -{ swiftpmFlags = [ "--disable-dead-strip" ]; } -``` - -The default `buildPhase` already passes `-j` for parallel building. - -If these two customization options are insufficient, provide your own -`buildPhase` that invokes `swift build`. - -### Running tests {#ssec-swiftpm-running-tests} - -Including `swiftpm` in your `nativeBuildInputs` also provides a default -`checkPhase`, but it must be enabled with: - -```nix -{ doCheck = true; } -``` - -This essentially runs: `swift test -c release` - -### Patching dependencies {#ssec-swiftpm-patching-dependencies} - -In some cases, it may be necessary to patch a SwiftPM dependency. SwiftPM -dependencies are located in `.build/checkouts`, but the `swiftpm2nix` helper -provides these as symlinks to read-only `/nix/store` paths. To patch -them, we need to make them writable. - -A special function `swiftpmMakeMutable` is available to replace the symlink -with a writable copy: +A special function `swiftpmMakeMutable` is available to replace the symlink with a writable copy: ```nix { @@ -183,21 +190,76 @@ with a writable copy: } ``` +### Custom build flags {#ssec-swiftpm-custom-build-flags} + +If you'd like to build a different configuration than `release`: + +```nix +{ swiftpmBuildConfig = "debug"; } +``` + +It is also possible to provide additional flags to `swift build`: + +```nix +{ swiftpmFlags = [ "--disable-dead-strip" ]; } +``` + +The default `buildPhase` already passes `-j` for parallel building. + +If these two customization options are insufficient, provide your own `buildPhase` that invokes `swift build`. + +### Running tests {#ssec-swiftpm-running-tests} + +Including `swiftpm` in your `nativeBuildInputs` also provides a default `checkPhase`, but it must be enabled with: + +```nix +{ doCheck = true; } +``` + +This essentially runs: `swift test -c release` + +### Installing packages {#ssec-swiftpm-install-phase} + +SwiftPM provides a default install phase that installs any products specified in your package’s `Package.swift`. +If your package does not specify any products, which is not uncommon, you will have to manually install them to `out`. +To disable the SwiftPM install phase, include the following in your derivation: + +```nix +{ dontUseSwiftpmInstall = true; } +``` + +## Hooks {#ssec-swift-hooks} + +Swift provides the following hooks to automate builds and unpack dependencies: + +- `swiftpmHook`: Propagated by `swiftpm`. + Also propagates `swiftpmUnpackHook`. + Provides build, install, and check phases. It also adds any dependencies found in `buildInputs` to `swiftpmFlags`. +- `swiftpmUnpackHook`: Sets up `workspace-state.json` and links vendored dependencies to the top-level `Packages` directory in the build environment. + +Swift also provides a hook with the toolchain to replace rpath references to the toolchain with references to the stdlib package. +This hook is used automatically by the `swift` package. +This avoids pulling the entire toolchain into the closure of your package. + ## Considerations for custom build tools {#ssec-swift-considerations-for-custom-build-tools} ### Linking the standard library {#ssec-swift-linking-the-standard-library} -The `swift` package has a separate `lib` output containing just the Swift -standard library, to prevent Swift applications needing a dependency on the -full Swift compiler at runtime. Linking with the Nixpkgs Swift toolchain -already ensures binaries correctly reference the `lib` output. +The Swift stdlib is packaged separately as `swiftPackages.stdlib`. +The shared and static libraries are installed to `lib`. +Most tooling in Nixpkgs should find them automatically when linking. +The stdlib provides a hook to change any rpaths pointing to the toolchain to point to the stdlib instead. -Sometimes, Swift is used only to compile part of a mixed codebase, and the -link step is manual. Custom build tools often locate the standard library -relative to the `swift` compiler executable, and while the result will work, -when this path ends up in the binary, it will have the Swift compiler as an -unintended dependency. +The stdlib modules are installed to `lib/swift/` in the `dev` output of the stdlib package. +These are symlinked together into the `swift` toolchain. +If your build tools locate the modules relative to the `swift` compiler executable, it should do the right thing automatically. -In this case, you should investigate how your build process discovers the -standard library, and override the path. The correct path will be something -like: `"${swift.swift.lib}/${swift.swiftModuleSubdir}"` +### Accessing properties of the Swift platform {#ssec-swift-platform-properties} + +The architecture, platform, and triple used by Swift is available as attributes on the build/host/targetPlatform for the `stdenv`. + +- `stdenv..swift.platform`: The Swift platform (e.g., `macosx` for macOS, `linux` for Linux, etc). +- `stdenv..swift.arch`: The Swift architecture (e.g., `arm64` for Darwin or `aarch64` for Linux, `x86_64`, etc). +- `stdenv..swift.triple`: The triple used by Swift. + This is the same as `stdenv..config` except on Darwin. + On Darwin, it uses the OS name instead of `darwin` and includes the deployment target (e.g., `arm64-apple-macosx14.0`). diff --git a/doc/redirects.json b/doc/redirects.json index c247c05dcd9b..64ac40004f0b 100644 --- a/doc/redirects.json +++ b/doc/redirects.json @@ -1981,6 +1981,9 @@ "sec-darwin-troubleshooting-xcodebuild-absolute-paths": [ "index.html#sec-darwin-troubleshooting-xcodebuild-absolute-paths" ], + "sec-darwin-missing-macros": [ + "index.html#sec-darwin-missing-macros" + ], "sec-darwin-troubleshooting-libiconv": [ "index.html#sec-darwin-troubleshooting-libiconv" ], @@ -4593,14 +4596,26 @@ "ssec-swift-packaging-with-swiftpm": [ "index.html#ssec-swift-packaging-with-swiftpm" ], + "ssec-swift-packaging-with-fetch-swiftpm-deps": [ + "index.html#ssec-swift-packaging-with-fetch-swiftpm-deps" + ], + "ssec-swift-packaging-with-swiftpm2nix": [ + "index.html#ssec-swift-packaging-with-swiftpm2nix" + ], + "ssec-swiftpm-patching-dependencies": [ + "index.html#ssec-swiftpm-patching-dependencies" + ], "ssec-swiftpm-custom-build-flags": [ "index.html#ssec-swiftpm-custom-build-flags" ], "ssec-swiftpm-running-tests": [ "index.html#ssec-swiftpm-running-tests" ], - "ssec-swiftpm-patching-dependencies": [ - "index.html#ssec-swiftpm-patching-dependencies" + "ssec-swiftpm-install-phase": [ + "index.html#ssec-swiftpm-install-phase" + ], + "ssec-swift-hooks": [ + "index.html#ssec-swift-hooks" ], "ssec-swift-considerations-for-custom-build-tools": [ "index.html#ssec-swift-considerations-for-custom-build-tools" @@ -4608,6 +4623,9 @@ "ssec-swift-linking-the-standard-library": [ "index.html#ssec-swift-linking-the-standard-library" ], + "ssec-swift-platform-properties": [ + "index.html#ssec-swift-platform-properties" + ], "sec-language-tcl": [ "index.html#sec-language-tcl" ], diff --git a/doc/release-notes/rl-2611.section.md b/doc/release-notes/rl-2611.section.md index 0de5d13ed18a..11ff5d59f5d7 100644 --- a/doc/release-notes/rl-2611.section.md +++ b/doc/release-notes/rl-2611.section.md @@ -16,6 +16,8 @@ +nixpkgs.url = "https://channels.nixos.org/nixos-26.05/nixexprs.tar.zst"; ``` +- GCC has been updated from GCC 15 to GCC 16. This introduces some backwards-incompatible changes. Refer to the [upstream porting guide](https://gcc.gnu.org/gcc-16/porting_to.html) for details. + - Emacs has been updated to 31. This introduces some backwards‐incompatible changes; see the NEWS for details. NEWS can be viewed from Emacs by typing `C-h n`, or by clicking `Help->Emacs News` from the menu bar. @@ -216,6 +218,16 @@ - `nim-2_0` & `nim-2_2` and respective aliases have been removed; please migrate to `nim` or `nim-unwrapped` (nim 2.2.10). - `domoticz` has been updated from `2024.7` to `2026.x`, breaking third party applications and scripts using the old RType calls. Review the [release notes](https://github.com/domoticz/domoticz/blob/2026.2/History.txt#L398) for more information. +- `swift` is no longer wrapped. + The `NIX_SWIFTFLAGS_COMPILE` variable is no longer supported. + If you need to pass custom flags to the Swift compiler, you must add them via your package’s build system. + The default target version used by `swiftc` on Darwin is the operating system major version. + This value may be overridden by the build system (e.g., SwiftPM defaults to 10.13 instead). + See the Swift documentation in Nixpkgs for details. + +- `swiftpm` is no longer wrapped to include Git to fetch dependencies. + Users with Git-based dependencies will need to add `git` to their dev shells or include it in their environment if they weren’t already. + - `vimacs` has been removed, as it has not been maintained in 10 years and was built for an old version of vim (6.0). - The deprecated `appimageTools.extractType1`, `appimageTools.extractType2`, and `appimageTools.wrapType1` aliases now emit warnings. Use `appimageTools.extract` and `appimageTools.wrapType2` instead. @@ -264,6 +276,9 @@ - Firefox wrapper now accepts an optional `appDataDir` argument, which sets `MOZ_APP_DATA` to relocate Firefox application data. This is especially useful on macOS 27 and later, where wrapped Firefox applications may be denied access to profiles in traditional application data directory. +- Swift has been upgraded to Swift 6.2.4 from Swift 5.10.1. + The Swift packaging has been rewritten. + ## Nixpkgs Library {#sec-nixpkgs-release-26.11-lib} diff --git a/doc/stdenv/platform-notes.chapter.md b/doc/stdenv/platform-notes.chapter.md index 2aeee55ba2cd..7b18ef044745 100644 --- a/doc/stdenv/platform-notes.chapter.md +++ b/doc/stdenv/platform-notes.chapter.md @@ -121,7 +121,8 @@ Generally, only the last SDK release for a major version is packaged. |---------------|-------------|------------------------------| | 15.0–15.4 | 14.4 | `apple-sdk_14` / `apple-sdk` | | 16.0 | 15.0 | `apple-sdk_15` | -| 26.0+ | 26.0+ | `apple-sdk_26`, etc | +| 26.0 | 26.0 | `apple-sdk_26` | +| 27.0+ | 27.0+ | `apple-sdk_27`, etc | #### Darwin Default SDK versions {#sec-darwin-troubleshooting-darwin-defaults} @@ -192,6 +193,13 @@ stdenv.mkDerivation { } ``` +### Macro library not available {#sec-darwin-missing-macros} + +Some frameworks provide macros that are only shipped with Xcode. +For example, the AppleIntelligence framework, Swift Data, and SwiftUI (as of the 27.0 SDK). +A non-free package making these available will be added at a later date. +Until then, they are unfortunately not available in Nixpkgs. + #### How to use libiconv on Darwin {#sec-darwin-troubleshooting-libiconv} The libiconv package is included in the SDK by default along with libresolv and libsbuf. diff --git a/lib/systems/default.nix b/lib/systems/default.nix index 2bd3f8927277..5b37eb20a874 100644 --- a/lib/systems/default.nix +++ b/lib/systems/default.nix @@ -719,6 +719,26 @@ let else null; }; + swift = { + arch = final.uname.processor; + platform = + if final.isMacOS then + "macosx" + else if final.isiOS then + "iphoneos" + else if final.isLinux then + "linux" + else if final.isWindows then + "windows" + else + null; + triple = + if final.isDarwin then + # FIXME: Can this be done a better way? + "${final.swift.arch}-${final.parsed.vendor.name}-${final.swift.platform}${final.darwinMinVersion}" + else + final.config; + }; }; in # Platforms elaborated by pre-26.11 Nixpkgs will include the `linux-kernel` attr, diff --git a/maintainers/team-list.nix b/maintainers/team-list.nix index ab85a7371cdd..aa636525d0d4 100644 --- a/maintainers/team-list.nix +++ b/maintainers/team-list.nix @@ -751,6 +751,7 @@ with lib.maintainers; swift = { members = [ + reckenrode samasaur stephank ]; diff --git a/nixos/modules/services/video/frigate.nix b/nixos/modules/services/video/frigate.nix index 43941e64ac0d..6ee20f7cf582 100644 --- a/nixos/modules/services/video/frigate.nix +++ b/nixos/modules/services/video/frigate.nix @@ -405,7 +405,9 @@ in extraConfig = nginxAuthRequest + '' types { video/mp4 mp4; - image/jpeg jpg; + image/jpeg jpg jpeg; + image/png png; + image/webp webp; } expires 7d; @@ -493,19 +495,6 @@ in } ''; }; - # frontend uses this to fetch the version - "/api/go2rtc/api" = { - proxyPass = "http://frigate-go2rtc/api"; - recommendedProxySettings = true; - extraConfig = - nginxAuthRequest - + nginxProxySettings - + '' - limit_except GET { - deny all; - } - ''; - }; # integrationn uses this to add webrtc candidate "/api/go2rtc/webrtc" = { proxyPass = "http://frigate-go2rtc/api/webrtc"; @@ -541,6 +530,7 @@ in expires off; proxy_cache frigate_api_cache; + proxy_cache_key "$scheme$proxy_host$request_uri|$role|$groups|$user"; proxy_cache_lock on; proxy_cache_use_stale updating; proxy_cache_valid 200 5s; @@ -563,6 +553,13 @@ in ${nginxProxySettings} } + location /api/logout { + auth_request off; + rewrite ^/api(/.*)$ $1 break; + proxy_pass http://frigate-api; + ${nginxProxySettings} + } + location /api/auth/first_time_login { auth_request off; limit_except GET { @@ -747,7 +744,6 @@ in ] ++ optionals (!stdenv.hostPlatform.isAarch64) [ # not available on aarch64-linux - intel-gpu-tools rocmPackages.rocminfo ]; serviceConfig = { @@ -775,11 +771,10 @@ in Group = "frigate"; SupplementaryGroups = [ "render" ] ++ optionals withCoral [ "coral" ]; - AmbientCapabilities = optionals (elem cfg.vaapiDriver [ - "i965" - "iHD" - ]) [ "CAP_PERFMON" ]; # for intel_gpu_top + # No capabilities + CapabilityBoundingSet = [ "" ]; + # Allow delegating access UMask = "0027"; StateDirectory = "frigate"; @@ -797,9 +792,53 @@ in # Sockets/IPC RuntimeDirectory = "frigate"; + RemoveIPC = true; # Reduce visible process scope to cgroup ProtectProc = "invisible"; + + # Allow wide /proc inspection, e.g. for cpuinfo + ProcSubset = "all"; + + # Protect various system locations/interfaces + ProtectControlGroups = true; + ProtectHome = true; + ProtectHostname = true; + ProtectKernelLogs = true; + ProtectKernelModules = true; + ProtectKernelTunables = true; + ProtectSystem = "strict"; + + # No JIT compilation + MemoryDenyWriteExecute = true; + + # No ABI personality changes + LockPersonality = true; + + # Only IP/Unix sockets + RestrictAddressFamilies = [ + "AF_INET" + "AF_INET6" + "AF_UNIX" + ]; + + # Deny namespace creation + RestrictNamespaces = true; + + # No privilege escalation + NoNewPrivileges = true; + RestrictSUIDSGID = true; + + # No realtime schedulign + RestrictRealtime = true; + + # Restrict allowed syscalls + SystemCallFilter = [ + "@system-service" + "~@privileged" + ]; + SystemCallArchitectures = "native"; + SystemCallErrorNumber = "EPERM"; }; }; diff --git a/nixos/tests/frigate.nix b/nixos/tests/frigate.nix index 10712387f421..ca6fc5a5c621 100644 --- a/nixos/tests/frigate.nix +++ b/nixos/tests/frigate.nix @@ -77,5 +77,7 @@ # wait for a recording to appear machine.wait_for_file("/var/cache/frigate/test@*.mp4") + + machine.log(machine.execute("systemd-analyze security frigate.service | grep -v ✓")[1]) ''; } diff --git a/pkgs/applications/graphics/inkscape/default.nix b/pkgs/applications/graphics/inkscape/default.nix index ccea323f700b..9a8426912a17 100644 --- a/pkgs/applications/graphics/inkscape/default.nix +++ b/pkgs/applications/graphics/inkscape/default.nix @@ -13,7 +13,7 @@ gettext, ghostscript, glib, - glibmm, + glibmm_2_4, gobject-introspection, gsl, gspell, @@ -29,7 +29,7 @@ libpng, librevenge, librsvg, - libsigcxx, + libsigcxx_2_0, libvisio, libwpg, libxft, @@ -111,6 +111,8 @@ stdenv.mkDerivation (finalAttrs: { }) # https://gitlab.com/inkscape/inkscape/-/merge_requests/7968 ./fix-build-poppler-26.06.0.patch + # https://gitlab.com/inkscape/inkscape/-/merge_requests/8034 + ./fix-build-poppler-26.07.0.patch ]; postPatch = '' @@ -153,7 +155,7 @@ stdenv.mkDerivation (finalAttrs: { boost gettext glib - glibmm + glibmm_2_4 gsl gtkmm3 gtksourceview4 @@ -165,7 +167,7 @@ stdenv.mkDerivation (finalAttrs: { libpng librevenge librsvg # for loading icons - libsigcxx + libsigcxx_2_0 libvisio libwpg libxft diff --git a/pkgs/applications/graphics/inkscape/fix-build-poppler-26.07.0.patch b/pkgs/applications/graphics/inkscape/fix-build-poppler-26.07.0.patch new file mode 100644 index 000000000000..ddcc4dbb386c --- /dev/null +++ b/pkgs/applications/graphics/inkscape/fix-build-poppler-26.07.0.patch @@ -0,0 +1,331 @@ +From fc52525f8d8d7d3e772c5bfa1bdfe9b33c7f9709 Mon Sep 17 00:00:00 2001 +From: KrIr17 +Date: Sat, 4 Jul 2026 14:07:44 +0200 +Subject: [PATCH] Fix building with Poppler 26.07.0 + +1. `arrayGetfoo()` to `getArray()->getFoo()` [1] +2. `streamGetFoo()` to `getStream()->getFoo()` [2] +3. indextolabel now requires an `std::string *` and not `GooString *` + introduced _POPPLER_STRING_26_7 that changes accordingly. + +Relevant poppler commits: + +[1] [Remove Object::arrayGetNF](https://gitlab.freedesktop.org/poppler/poppler/-/commit/d9ffc4c29d1975a5c81d6bac9d8a1b6dc5aa1f50): Technically only arrayGetNF was removed, but perusing the commit shows that all `arrayGetFoo` are being changed. I assume they are slated for removal in future releases. + +[2] [Remove Object::streamGetDict](gitlab.freedesktop.org/poppler/poppler/-/commit/87edb5a5c40e67e782e54a14a2251547b4acdfb5) + +[3] [Use std::string instead of GooString for label](https://gitlab.freedesktop.org/poppler/poppler/-/commit/9e34004aae04064f1b798b5e711e13d0dddacf9e) +--- + src/extension/internal/pdfinput/pdf-input.cpp | 5 +- + .../internal/pdfinput/pdf-parser.cpp | 54 +++++++++---------- + .../pdfinput/poppler-transition-api.h | 6 +++ + .../internal/pdfinput/poppler-utils.cpp | 29 +++++----- + .../internal/pdfinput/poppler-utils.h | 1 + + 5 files changed, 54 insertions(+), 41 deletions(-) + +diff --git a/src/extension/internal/pdfinput/pdf-input.cpp b/src/extension/internal/pdfinput/pdf-input.cpp +index 4030a95882..0d46a0577f 100644 +--- a/src/extension/internal/pdfinput/pdf-input.cpp ++++ b/src/extension/internal/pdfinput/pdf-input.cpp +@@ -891,9 +891,10 @@ PdfInput::add_builder_page(std::shared_ptrpdf_doc, SvgBuilder *builder, + + // Parse the annotations + if (auto annots = page->getAnnotsObject(); annots.isArray()) { +- auto const size = annots.arrayGetLength(); ++ auto* annotsArray = annots.getArray(); ++ auto const size = annotsArray->getLength(); + for (int i = 0; i < size; i++) { +- pdf_parser.build_annots(annots.arrayGet(i), page_num); ++ pdf_parser.build_annots(annotsArray->get(i), page_num); + } + } + } +diff --git a/src/extension/internal/pdfinput/pdf-parser.cpp b/src/extension/internal/pdfinput/pdf-parser.cpp +index 86fc51b1f2..fac5326988 100644 +--- a/src/extension/internal/pdfinput/pdf-parser.cpp ++++ b/src/extension/internal/pdfinput/pdf-parser.cpp +@@ -289,8 +289,8 @@ PdfParser::PdfParser(std::shared_ptr pdf_doc, Inkscape::Extension::Inter + if (page) { + // Increment the page building here and set page label + Catalog *catalog = pdf_doc->getCatalog(); +- GooString *label = new GooString(""); +- catalog->indexToLabel(page->getNum() - 1, label); ++ _POPPLER_STRING_26_7 label; ++ catalog->indexToLabel(page->getNum() - 1, &label); + builder->pushPage(getString(label), state); + } + +@@ -374,8 +374,8 @@ void PdfParser::parse(Object *obj, GBool topLevel) { + Object obj2; + + if (obj->isArray()) { +- for (int i = 0; i < obj->arrayGetLength(); ++i) { +- _POPPLER_CALL_ARGS(obj2, obj->arrayGet, i); ++ for (int i = 0; i < obj->getArray()->getLength(); ++i) { ++ _POPPLER_CALL_ARGS(obj2, obj->getArray()->get, i); + if (!obj2.isStream()) { + error(errInternal, -1, "Weird page contents"); + _POPPLER_FREE(obj2); +@@ -782,8 +782,8 @@ void PdfParser::opSetExtGState(Object args[], int /*numArgs*/) + for (int &i : backdropColor.c) { + i = 0; + } +- for (int i = 0; i < obj3.arrayGetLength() && i < gfxColorMaxComps; ++i) { +- _POPPLER_CALL_ARGS(obj4, obj3.arrayGet, i); ++ for (int i = 0; i < obj3.getArray()->getLength() && i < gfxColorMaxComps; ++i) { ++ _POPPLER_CALL_ARGS(obj4, obj3.getArray()->get, i); + if (obj4.isNum()) { + backdropColor.c[i] = dblToCol(obj4.getNum()); + } +@@ -792,7 +792,7 @@ void PdfParser::opSetExtGState(Object args[], int /*numArgs*/) + } + _POPPLER_FREE(obj3); + if (_POPPLER_CALL_ARGS_DEREF(obj3, obj2.dictLookup, "G").isStream()) { +- if (_POPPLER_CALL_ARGS_DEREF(obj4, obj3.streamGetDict()->lookup, "Group").isDict()) { ++ if (_POPPLER_CALL_ARGS_DEREF(obj4, obj3.getStream()->getDict()->lookup, "Group").isDict()) { + std::unique_ptr blendingColorSpace; + GBool isolated = gFalse; + GBool knockout = gFalse; +@@ -855,7 +855,7 @@ void PdfParser::doSoftMask(Object *str, GBool alpha, + } + + // get stream dict +- dict = str->streamGetDict(); ++ dict = str->getStream()->getDict(); + + // check form type + _POPPLER_CALL_ARGS(obj1, dict->lookup, "FormType"); +@@ -872,7 +872,7 @@ void PdfParser::doSoftMask(Object *str, GBool alpha, + return; + } + for (i = 0; i < 4; ++i) { +- _POPPLER_CALL_ARGS(obj2, obj1.arrayGet, i); ++ _POPPLER_CALL_ARGS(obj2, obj1.getArray()->get, i); + bbox[i] = obj2.getNum(); + _POPPLER_FREE(obj2); + } +@@ -882,7 +882,7 @@ void PdfParser::doSoftMask(Object *str, GBool alpha, + _POPPLER_CALL_ARGS(obj1, dict->lookup, "Matrix"); + if (obj1.isArray()) { + for (i = 0; i < 6; ++i) { +- _POPPLER_CALL_ARGS(obj2, obj1.arrayGet, i); ++ _POPPLER_CALL_ARGS(obj2, obj1.getArray()->get, i); + m[i] = obj2.getNum(); + _POPPLER_FREE(obj2); + } +@@ -2396,7 +2396,7 @@ void PdfParser::opXObject(Object args[], int /*numArgs*/) + } + + //add layer at root if xObject has type OCG +- _POPPLER_CALL_ARGS(obj2, obj1.streamGetDict()->lookup, "OC"); ++ _POPPLER_CALL_ARGS(obj2, obj1.getStream()->getDict()->lookup, "OC"); + if(obj2.isDict()){ + auto type_dict = obj2.getDict(); + if (type_dict->lookup("Type").isName("OCG")) { +@@ -2406,7 +2406,7 @@ void PdfParser::opXObject(Object args[], int /*numArgs*/) + } + } + +- _POPPLER_CALL_ARGS(obj2, obj1.streamGetDict()->lookup, "Subtype"); ++ _POPPLER_CALL_ARGS(obj2, obj1.getStream()->getDict()->lookup, "Subtype"); + if (obj2.isName(const_cast("Image"))) { + _POPPLER_CALL_ARGS(refObj, res->lookupXObjectNF, name); + doImage(&refObj, obj1.getStream(), gFalse); +@@ -2414,7 +2414,7 @@ void PdfParser::opXObject(Object args[], int /*numArgs*/) + } else if (obj2.isName(const_cast("Form"))) { + doForm(&obj1); + } else if (obj2.isName(const_cast("PS"))) { +- _POPPLER_CALL_ARGS(obj3, obj1.streamGetDict()->lookup, "Level1"); ++ _POPPLER_CALL_ARGS(obj3, obj1.getStream()->getDict()->lookup, "Level1"); + } else if (obj2.isName()) { + error(errSyntaxError, getPos(), "Unknown XObject subtype '{0:s}'", obj2.getName()); + } else { +@@ -2545,7 +2545,7 @@ void PdfParser::doImage(Object * /*ref*/, Stream *str, GBool inlineImg) + _POPPLER_CALL_ARGS(obj1, dict->lookup, "D"); + } + if (obj1.isArray()) { +- _POPPLER_CALL_ARGS(obj2, obj1.arrayGet, 0); ++ _POPPLER_CALL_ARGS(obj2, obj1.getArray()->get, 0); + if (obj2.isInt() && obj2.getInt() == 1) { + invert = gTrue; + } +@@ -2607,7 +2607,7 @@ void PdfParser::doImage(Object * /*ref*/, Stream *str, GBool inlineImg) + goto err1; + } + maskStr = smaskObj.getStream(); +- maskDict = smaskObj.streamGetDict(); ++ maskDict = smaskObj.getStream()->getDict(); + _POPPLER_CALL_ARGS(obj1, maskDict->lookup, "Width"); + if (obj1.isNull()) { + _POPPLER_FREE(obj1); +@@ -2673,8 +2673,8 @@ void PdfParser::doImage(Object * /*ref*/, Stream *str, GBool inlineImg) + } else if (maskObj.isArray()) { + // color key mask + int i; +- for (i = 0; i < maskObj.arrayGetLength() && i < 2*gfxColorMaxComps; ++i) { +- _POPPLER_CALL_ARGS(obj1, maskObj.arrayGet, i); ++ for (i = 0; i < maskObj.getArray()->getLength() && i < 2*gfxColorMaxComps; ++i) { ++ _POPPLER_CALL_ARGS(obj1, maskObj.getArray()->get, i); + maskColors[i] = obj1.getInt(); + _POPPLER_FREE(obj1); + } +@@ -2685,7 +2685,7 @@ void PdfParser::doImage(Object * /*ref*/, Stream *str, GBool inlineImg) + goto err1; + } + maskStr = maskObj.getStream(); +- maskDict = maskObj.streamGetDict(); ++ maskDict = maskObj.getStream()->getDict(); + _POPPLER_CALL_ARGS(obj1, maskDict->lookup, "Width"); + if (obj1.isNull()) { + _POPPLER_FREE(obj1); +@@ -2732,7 +2732,7 @@ void PdfParser::doImage(Object * /*ref*/, Stream *str, GBool inlineImg) + _POPPLER_CALL_ARGS(obj1, maskDict->lookup, "D"); + } + if (obj1.isArray()) { +- _POPPLER_CALL_ARGS(obj2, obj1.arrayGet, 0); ++ _POPPLER_CALL_ARGS(obj2, obj1.getArray()->get, 0); + if (obj2.isInt() && obj2.getInt() == 1) { + maskInvert = gTrue; + } +@@ -2785,7 +2785,7 @@ void PdfParser::doForm(Object *str, double *offset) + } + + // get stream dict +- dict = str->streamGetDict(); ++ dict = str->getStream()->getDict(); + + // check form type + _POPPLER_CALL_ARGS(obj1, dict->lookup, "FormType"); +@@ -2802,7 +2802,7 @@ void PdfParser::doForm(Object *str, double *offset) + return; + } + for (i = 0; i < 4; ++i) { +- _POPPLER_CALL_ARGS(obj1, bboxObj.arrayGet, i); ++ _POPPLER_CALL_ARGS(obj1, bboxObj.getArray()->get, i); + bbox[i] = obj1.getNum(); + _POPPLER_FREE(obj1); + } +@@ -2812,7 +2812,7 @@ void PdfParser::doForm(Object *str, double *offset) + _POPPLER_CALL_ARGS(matrixObj, dict->lookup, "Matrix"); + if (matrixObj.isArray()) { + for (i = 0; i < 6; ++i) { +- _POPPLER_CALL_ARGS(obj1, matrixObj.arrayGet, i); ++ _POPPLER_CALL_ARGS(obj1, matrixObj.getArray()->get, i); + m[i] = obj1.getNum(); + _POPPLER_FREE(obj1); + } +@@ -3248,10 +3248,10 @@ void PdfParser::loadColorProfile() + return; + + Object outputIntents = catDict.dictLookup("OutputIntents"); +- if (!outputIntents.isArray() || outputIntents.arrayGetLength() != 1) ++ if (!outputIntents.isArray() || outputIntents.getArray()->getLength() != 1) + return; + +- Object firstElement = outputIntents.arrayGet(0); ++ Object firstElement = outputIntents.getArray()->get(0); + if (!firstElement.isDict()) + return; + +@@ -3300,7 +3300,7 @@ void PdfParser::build_annots(const Object &annot, int page_num) + _POPPLER_CALL_ARGS(Rect_obj, annot_dict->lookup, "Rect"); + if (Rect_obj.isArray()) { + for (int i = 0; i < 2; i++) { +- _POPPLER_CALL_ARGS(xy_obj, Rect_obj.arrayGet, i); ++ _POPPLER_CALL_ARGS(xy_obj, Rect_obj.getArray()->get, i); + offset[i] = xy_obj.getNum(); + } + doForm(&first_state_obj, offset); +diff --git a/src/extension/internal/pdfinput/poppler-transition-api.h b/src/extension/internal/pdfinput/poppler-transition-api.h +index 23550a3068..22bc8d223d 100644 +--- a/src/extension/internal/pdfinput/poppler-transition-api.h ++++ b/src/extension/internal/pdfinput/poppler-transition-api.h +@@ -15,6 +15,12 @@ + #include + #include + ++#if POPPLER_CHECK_VERSION(26, 7, 0) ++#define _POPPLER_STRING_26_7 std::string ++#else ++#define _POPPLER_STRING_26_7 GooString ++#endif ++ + #if POPPLER_CHECK_VERSION(26, 6, 0) + #define _POPPLER_GET_GRAY(color, gray) getGray(color, gray) + #define _POPPLER_GET_RGB(color, rgb) getRGB(color, rgb) +diff --git a/src/extension/internal/pdfinput/poppler-utils.cpp b/src/extension/internal/pdfinput/poppler-utils.cpp +index 66dcf85e1d..0a82574209 100644 +--- a/src/extension/internal/pdfinput/poppler-utils.cpp ++++ b/src/extension/internal/pdfinput/poppler-utils.cpp +@@ -187,15 +187,16 @@ void InkFontDict::hashFontObject1(const Object *obj, FNVHash *h) + case objNull: + h->hash('z'); + break; +- case objArray: +- h->hash('a'); +- n = obj->arrayGetLength(); +- h->hash((char *)&n, sizeof(int)); +- for (i = 0; i < n; ++i) { +- const Object &obj2 = obj->arrayGetNF(i); +- hashFontObject1(&obj2, h); +- } +- break; ++ case objArray: { ++ h->hash('a'); ++ Array * objArray = obj->getArray(); ++ n = objArray->getLength(); ++ h->hash((char *)&n, sizeof(int)); ++ for (i = 0; i < n; ++i) { ++ const Object &obj2 = objArray->getNF(i); ++ hashFontObject1(&obj2, h); ++ } ++ } break; + case objDict: { + h->hash('d'); + auto objdict = obj->getDict(); +@@ -207,8 +208,7 @@ void InkFontDict::hashFontObject1(const Object *obj, FNVHash *h) + const Object &obj2 = objdict->getValNF(i); + hashFontObject1(&obj2, h); + } +- } +- break; ++ } break; + case objStream: + // this should never happen - streams must be indirect refs + break; +@@ -546,7 +546,7 @@ void _getFontsRecursive(std::shared_ptr pdf_doc, Dict *resources, const + continue; + + Ref resourcesRef; +- const Object resObj = obj2.streamGetDict()->lookup("Resources", &resourcesRef); ++ const Object resObj = obj2.getStream()->getDict()->lookup("Resources", &resourcesRef); + if (resourcesRef != Ref::INVALID() && !visitedObjects.insert(resourcesRef.num).second) + continue; + +@@ -661,6 +661,11 @@ std::string getString(const GooString *value) + return ""; + } + ++std::string getString(const GooString &value) ++{ ++ return getString(value.toStr()); ++} ++ + /** + * Convert PDF strings, which can be formatted as UTF8, UTF16BE or UTF16LE into + * a predictable UTF8 string consistant with svg requirements. +diff --git a/src/extension/internal/pdfinput/poppler-utils.h b/src/extension/internal/pdfinput/poppler-utils.h +index b11ecd11e5..27675b758e 100644 +--- a/src/extension/internal/pdfinput/poppler-utils.h ++++ b/src/extension/internal/pdfinput/poppler-utils.h +@@ -86,6 +86,7 @@ std::string getDictString(Dict *dict, const char *key); + std::string getString(const std::string &value); + std::string getString(const std::unique_ptr &value); + std::string getString(const GooString *value); ++std::string getString(const GooString &value); + std::string validateString(std::string const &in); + std::string sanitizeId(std::string const &in); + +-- +GitLab + diff --git a/pkgs/applications/graphics/sane/backends/default.nix b/pkgs/applications/graphics/sane/backends/default.nix index 02dd36e23d7e..05f67e51cd2a 100644 --- a/pkgs/applications/graphics/sane/backends/default.nix +++ b/pkgs/applications/graphics/sane/backends/default.nix @@ -66,6 +66,16 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-9KKTr7p1vCgvGr6hFY83K5gbL7Ilm4Uzc86JIxv+ahI="; revert = true; }) + + # Fix gphoto2 backend build with glibc 2.43 C23 const-preserving strchr + (fetchpatch { + url = "https://gitlab.com/sane-project/backends/-/commit/d04d17b456d9847021b6df6eb08a3419a75172cf.patch"; + hash = "sha256-4iAzwA+uh8W+xSpUkZgvShQ71kq/OVJ26pKsD1NwiXs="; + }) + (fetchpatch { + url = "https://gitlab.com/sane-project/backends/-/commit/ebd4d82bd7a6b8c57870dbfb492e4c186cf584d8.patch"; + hash = "sha256-vHtv+OMA0f9JR1ReshTg8IOgcZf7cnV7chitRBBCAg4="; + }) ]; postPatch = '' diff --git a/pkgs/applications/networking/browsers/firefox/packages/firefox-esr-140.nix b/pkgs/applications/networking/browsers/firefox/packages/firefox-esr-140.nix index 3750111eba50..766225ea1da7 100644 --- a/pkgs/applications/networking/browsers/firefox/packages/firefox-esr-140.nix +++ b/pkgs/applications/networking/browsers/firefox/packages/firefox-esr-140.nix @@ -37,6 +37,7 @@ buildMozillaMach rec { spec = "firefox@${lib.removeSuffix "esr" version}"; }; }; + broken = true; # doesn't build on glibc 2.44 }; tests = { inherit (nixosTests) firefox-esr-140; diff --git a/pkgs/applications/networking/instant-messengers/pidgin/pidgin-plugins/purple-mm-sms/default.nix b/pkgs/applications/networking/instant-messengers/pidgin/pidgin-plugins/purple-mm-sms/default.nix index 28dd496ffdce..460b5a0963e8 100644 --- a/pkgs/applications/networking/instant-messengers/pidgin/pidgin-plugins/purple-mm-sms/default.nix +++ b/pkgs/applications/networking/instant-messengers/pidgin/pidgin-plugins/purple-mm-sms/default.nix @@ -1,7 +1,7 @@ { lib, stdenv, - glibmm, + glibmm_2_4, pidgin, pkg-config, modemmanager, @@ -27,7 +27,7 @@ stdenv.mkDerivation rec { nativeBuildInputs = [ pkg-config ]; buildInputs = [ - glibmm + glibmm_2_4 pidgin modemmanager ]; diff --git a/pkgs/applications/networking/mailreaders/thunderbird/packages.nix b/pkgs/applications/networking/mailreaders/thunderbird/packages.nix index 5febcfeee1e3..d685dda597d3 100644 --- a/pkgs/applications/networking/mailreaders/thunderbird/packages.nix +++ b/pkgs/applications/networking/mailreaders/thunderbird/packages.nix @@ -15,6 +15,7 @@ let sha512, updateScript, applicationName ? "Thunderbird", + broken ? stdenv.buildPlatform.is32bit, }: (buildMozillaMach rec { pname = "thunderbird"; @@ -49,6 +50,7 @@ let ''; meta = { + inherit broken; changelog = "https://www.thunderbird.net/en-US/thunderbird/${version}/releasenotes/"; description = "Full-featured e-mail client"; homepage = "https://www.thunderbird.net/"; @@ -61,7 +63,6 @@ let vcunat ]; platforms = lib.platforms.unix; - broken = stdenv.buildPlatform.is32bit; # since Firefox 60, build on 32-bit platforms fails with "out of memory". # not in `badPlatforms` because cross-compilation on 64-bit machine might work. license = lib.licenses.mpl20; @@ -120,6 +121,8 @@ rec { versionPrefix = "140"; versionSuffix = "esr"; }; + + broken = true; }; } // lib.optionalAttrs config.allowAliases { diff --git a/pkgs/build-support/go/module.nix b/pkgs/build-support/go/module.nix index 692f9e81497b..bbe918684a0f 100644 --- a/pkgs/build-support/go/module.nix +++ b/pkgs/build-support/go/module.nix @@ -219,7 +219,6 @@ lib.extendMkDerivation { env = args.env or { } // { inherit (go) GOOS GOARCH; - GO111MODULE = "on"; GOTOOLCHAIN = "local"; CGO_ENABLED = args.env.CGO_ENABLED or go.CGO_ENABLED; diff --git a/pkgs/build-support/rust/fetch-cargo-vendor.nix b/pkgs/build-support/rust/fetch-cargo-vendor.nix index 94fd3815e132..b37199c022f6 100644 --- a/pkgs/build-support/rust/fetch-cargo-vendor.nix +++ b/pkgs/build-support/rust/fetch-cargo-vendor.nix @@ -103,6 +103,8 @@ let outputHash = hash; outputHashAlgo = if hash == "" then "sha256" else null; outputHashMode = "recursive"; + + __structuredAttrs = true; } // removeAttrs args removedArgs ); @@ -115,6 +117,8 @@ runCommand "${name}-vendor" cargo replaceWorkspaceValues ]; + strictDeps = true; + __structuredAttrs = true; } '' fetch-cargo-vendor-util create-vendor "$vendorStaging" "$out" diff --git a/pkgs/build-support/rust/hooks/default.nix b/pkgs/build-support/rust/hooks/default.nix index d57f1b09c40a..d17c6c0b4a12 100644 --- a/pkgs/build-support/rust/hooks/default.nix +++ b/pkgs/build-support/rust/hooks/default.nix @@ -132,6 +132,9 @@ substitutions = { libclang = (lib.getLib clang.cc); inherit clang; + targetFlag = lib.optionalString ( + !lib.systems.equals stdenv.targetPlatform stdenv.hostPlatform + ) "--target=${stdenv.targetPlatform.config}"; }; meta.license = lib.licenses.mit; } ./rust-bindgen-hook.sh; diff --git a/pkgs/build-support/rust/hooks/rust-bindgen-hook.sh b/pkgs/build-support/rust/hooks/rust-bindgen-hook.sh index 53624b124f2b..ba39686d3a1b 100644 --- a/pkgs/build-support/rust/hooks/rust-bindgen-hook.sh +++ b/pkgs/build-support/rust/hooks/rust-bindgen-hook.sh @@ -6,7 +6,7 @@ populateBindgenEnv () { export LIBCLANG_PATH=@libclang@/lib - BINDGEN_EXTRA_CLANG_ARGS="$(< @clang@/nix-support/cc-cflags) $(< @clang@/nix-support/libc-cflags) $(< @clang@/nix-support/libcxx-cxxflags) $NIX_CFLAGS_COMPILE" + BINDGEN_EXTRA_CLANG_ARGS="@targetFlag@ $(< @clang@/nix-support/cc-cflags) $(< @clang@/nix-support/libc-cflags) $(< @clang@/nix-support/libcxx-cxxflags) $NIX_CFLAGS_COMPILE" export BINDGEN_EXTRA_CLANG_ARGS } diff --git a/pkgs/build-support/rust/rustc-wrapper/default.nix b/pkgs/build-support/rust/rustc-wrapper/default.nix index 0ec66da5ab1a..3952e8b4cf26 100644 --- a/pkgs/build-support/rust/rustc-wrapper/default.nix +++ b/pkgs/build-support/rust/rustc-wrapper/default.nix @@ -49,6 +49,8 @@ runCommand "${rustc-unwrapped.pname}-wrapper-${rustc-unwrapped.version}" unwrapped = rustc-unwrapped; }; + __structuredAttrs = true; + meta = rustc-unwrapped.meta // { description = "${rustc-unwrapped.meta.description} (wrapper script)"; priority = 10; diff --git a/pkgs/build-support/setup-hooks/multiple-outputs.sh b/pkgs/build-support/setup-hooks/multiple-outputs.sh index cc3ab4816fa2..b744550ea350 100644 --- a/pkgs/build-support/setup-hooks/multiple-outputs.sh +++ b/pkgs/build-support/setup-hooks/multiple-outputs.sh @@ -192,23 +192,25 @@ _multioutPropagateDev() { propagaterOutput="$outputFirst" fi - # Default value: propagate binaries, includes and libraries - if [ -z "${propagatedBuildOutputs+1}" ]; then + local outputsToPropagate=() + if declare -p propagatedBuildOutputs &>/dev/null; then + concatTo outputsToPropagate propagatedBuildOutputs + else local po_dirty="$outputBin $outputInclude $outputLib" set +o pipefail - propagatedBuildOutputs=`echo "$po_dirty" \ + readarray -t outputsToPropagate < <(echo "$po_dirty" \ | tr -s ' ' '\n' | grep -v -F "$propagaterOutput" \ - | sort -u | tr '\n' ' ' ` + | sort -u ) set -o pipefail fi - # The variable was explicitly set to empty or we resolved it so - if [ -z "$propagatedBuildOutputs" ]; then + # Check whether we actually have any outputs to propagate + if [[ "${#outputsToPropagate[@]}" -eq 0 ]]; then return fi mkdir -p "${!propagaterOutput}"/nix-support - for output in $propagatedBuildOutputs; do + for output in "${outputsToPropagate[@]}"; do echo -n " ${!output}" >> "${!propagaterOutput}"/nix-support/propagated-build-inputs done } diff --git a/pkgs/by-name/ab/abseil-cpp/package.nix b/pkgs/by-name/ab/abseil-cpp/package.nix index 61e67450c68b..c5dd8cc0b6c6 100644 --- a/pkgs/by-name/ab/abseil-cpp/package.nix +++ b/pkgs/by-name/ab/abseil-cpp/package.nix @@ -6,7 +6,7 @@ # required LTS branch, leaving `abseil-cpp` as an alias. { - abseil-cpp_202601, + abseil-cpp_202608, cxxStandard ? null, }: -abseil-cpp_202601.override { inherit cxxStandard; } +abseil-cpp_202608.override { inherit cxxStandard; } diff --git a/pkgs/by-name/ad/ada/package.nix b/pkgs/by-name/ad/ada/package.nix index 4afbdecb59de..1b94fac3cef7 100644 --- a/pkgs/by-name/ad/ada/package.nix +++ b/pkgs/by-name/ad/ada/package.nix @@ -23,6 +23,12 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-TvjoLUKO2+YgS1mlyglLb+rBLTO/SWSBVA2S34Z6kMI="; }; + outputs = [ + "out" + "dev" + ]; + + strictDeps = true; nativeBuildInputs = [ cmake validatePkgConfig @@ -54,6 +60,8 @@ stdenv.mkDerivation (finalAttrs: { }; }; + __structuredAttrs = true; + meta = { description = "WHATWG-compliant and fast URL parser written in modern C"; homepage = "https://github.com/ada-url/ada"; diff --git a/pkgs/by-name/ae/aerospike/package.nix b/pkgs/by-name/ae/aerospike/package.nix index b90753491800..1818ad0f0e60 100644 --- a/pkgs/by-name/ae/aerospike/package.nix +++ b/pkgs/by-name/ae/aerospike/package.nix @@ -33,6 +33,9 @@ stdenv.mkDerivation (finalAttrs: { zlib ]; + # glibc 2.43 C23 const-preserving strchr/strstr macros + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + dontUseCmakeConfigure = true; preBuild = '' diff --git a/pkgs/by-name/af/affine/package.nix b/pkgs/by-name/af/affine/package.nix index 43b532795f8c..dcdb19173fd6 100644 --- a/pkgs/by-name/af/affine/package.nix +++ b/pkgs/by-name/af/affine/package.nix @@ -3,6 +3,7 @@ stdenv, stdenvNoCC, fetchFromGitHub, + substitute, rustPlatform, electron, nodejs_22, @@ -51,14 +52,24 @@ stdenv.mkDerivation (finalAttrs: { owner = "toeverything"; repo = "AFFiNE"; tag = "v${finalAttrs.version}"; - hash = "sha256-gtdhWLNZRNY91j9wVVny1bRAjZAwIvNJr11ePQapWYQ="; - }; + hash = "sha256-RotC2mNtMig3QKcKo8zr15myAqkPDuBopvV9wLlr2tQ="; - patches = [ - # Remove after upstream updates to Yarn 4.14 - # https://github.com/toeverything/AFFiNE/blob/canary/package.json#L96 - ./yarn-4.14-support.patch - ]; + # Remove when updating since upstream has updated Yarn + # https://github.com/toeverything/AFFiNE/commit/6375f5ab8c389831327284f4795d8397de085153 + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry.lockfileVersion + ]; + }) + } + ''; + }; cargoDeps = rustPlatform.fetchCargoVendor { inherit (finalAttrs) pname version src; @@ -68,7 +79,7 @@ stdenv.mkDerivation (finalAttrs: { # keep yarnOfflineCache same output style with offlineCache = yarn-berry.fetchYarnBerryDeps { inherit (finalAttrs) src missingHashes; hash = "" }; yarnOfflineCache = stdenvNoCC.mkDerivation { name = "yarn-offline-cache"; - inherit (finalAttrs) src patches; + inherit (finalAttrs) src; nativeBuildInputs = [ yarn-berry cacert @@ -112,7 +123,7 @@ stdenv.mkDerivation (finalAttrs: { ''; dontInstall = true; outputHashMode = "recursive"; - outputHash = "sha256-mNvvKbj9mUioh5Jw4CcRt0CpX1IcQC8JOxUnyy0Lw9c="; + outputHash = "sha256-gje8iTCiy3N/zYRuf/CGUVfGw0RSVXTPu4SjnE9+OY8="; }; buildInputs = lib.optionals hostPlatform.isDarwin [ diff --git a/pkgs/by-name/af/affine/yarn-4.14-support.patch b/pkgs/by-name/af/affine/yarn-4.14-support.patch deleted file mode 100644 index 782730dc89af..000000000000 --- a/pkgs/by-name/af/affine/yarn-4.14-support.patch +++ /dev/null @@ -1,23 +0,0 @@ -diff --git a/.yarnrc.yml b/.yarnrc.yml ---- a/.yarnrc.yml -+++ b/.yarnrc.yml -@@ -12,4 +12,7 @@ npmPublishAccess: public - - npmRegistryServer: "https://registry.npmjs.org" - --yarnPath: .yarn/releases/yarn-4.12.0.cjs -+approvedGitRepositories: -+ - "**" -+ -+enableScripts: true -diff --git a/yarn.lock b/yarn.lock ---- a/yarn.lock -+++ b/yarn.lock -@@ -2,6 +2,6 @@ - # Manual changes might be lost - proceed with caution! - - __metadata: -- version: 8 -+ version: 9 - cacheKey: 10 - diff --git a/pkgs/by-name/af/affine/yarn-fix.patch b/pkgs/by-name/af/affine/yarn-fix.patch new file mode 100644 index 000000000000..00d7fda513dd --- /dev/null +++ b/pkgs/by-name/af/affine/yarn-fix.patch @@ -0,0 +1,58 @@ +diff --git a/.yarnrc.yml b/.yarnrc.yml +--- a/.yarnrc.yml ++++ b/.yarnrc.yml +@@ -12,4 +12,7 @@ npmPublishAccess: public + + npmRegistryServer: "https://registry.npmjs.org" + +-yarnPath: .yarn/releases/yarn-4.12.0.cjs ++approvedGitRepositories: ++ - "**" ++ ++enableScripts: true +diff --git a/yarn.lock b/yarn.lock +--- a/yarn.lock ++++ b/yarn.lock +@@ -2,6 +2,6 @@ + # Manual changes might be lost - proceed with caution! + + __metadata: +- version: 8 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER + cacheKey: 10 + +diff --git a/yarn.lock b/yarn.lock +--- a/yarn.lock ++++ b/yarn.lock +@@ -33250,27 +33250,27 @@ __metadata: + + "resolve@patch:resolve@npm%3A^1.1.6#optional!builtin, resolve@patch:resolve@npm%3A^1.10.0#optional!builtin, resolve@patch:resolve@npm%3A^1.19.0#optional!builtin, resolve@patch:resolve@npm%3A^1.20.0#optional!builtin, resolve@patch:resolve@npm%3A^1.22.1#optional!builtin, resolve@patch:resolve@npm%3A^1.22.8#optional!builtin": + version: 1.22.11 +- resolution: "resolve@patch:resolve@npm%3A1.22.11#optional!builtin::version=1.22.11&hash=c3c19d" ++ resolution: "resolve@patch:resolve@npm%3A1.22.11#optional!builtin::version=1.22.11&hash=9bd1a5" + dependencies: + is-core-module: "npm:^2.16.1" + path-parse: "npm:^1.0.7" + supports-preserve-symlinks-flag: "npm:^1.0.0" + bin: + resolve: bin/resolve +- checksum: 10/fd342cad25e52cd6f4f3d1716e189717f2522bfd6641109fe7aa372f32b5714a296ed7c238ddbe7ebb0c1ddfe0b7f71c9984171024c97cf1b2073e3e40ff71a8 ++ checksum: 10/c990146fed81dd7792c56c1d62c170a8c8330bee86ef5d2524f0b1db79cfd9a6e2b4ad3cd4742b2685e51117b67be5d6f8cfd6ffa9c57bd64a1c8c8c9ff4c965 + languageName: node + linkType: hard + + "resolve@patch:resolve@npm%3A^2.0.0-next.5#optional!builtin": + version: 2.0.0-next.5 +- resolution: "resolve@patch:resolve@npm%3A2.0.0-next.5#optional!builtin::version=2.0.0-next.5&hash=c3c19d" ++ resolution: "resolve@patch:resolve@npm%3A2.0.0-next.5#optional!builtin::version=2.0.0-next.5&hash=9bd1a5" + dependencies: + is-core-module: "npm:^2.13.0" + path-parse: "npm:^1.0.7" + supports-preserve-symlinks-flag: "npm:^1.0.0" + bin: + resolve: bin/resolve +- checksum: 10/05fa778de9d0347c8b889eb7a18f1f06bf0f801b0eb4610b4871a4b2f22e220900cf0ad525e94f990bb8d8921c07754ab2122c0c225ab4cdcea98f36e64fa4c2 ++ checksum: 10/76c221deb1d986c0a80cd576373b0ee09f42871e0085a1f76beda84f73ce04e0d21bab28dffd326eb006a7af83bbc582404566b384aa3b0baa217f56cf7e8618 + languageName: node + linkType: hard + diff --git a/pkgs/by-name/ag/age-plugin-se/package.nix b/pkgs/by-name/ag/age-plugin-se/package.nix index f15699e2ddde..cf49bdaeb314 100644 --- a/pkgs/by-name/ag/age-plugin-se/package.nix +++ b/pkgs/by-name/ag/age-plugin-se/package.nix @@ -1,15 +1,13 @@ { lib, fetchFromGitHub, - llvmPackages, - swiftPackages, + fetchSwiftPMDeps, + stdenv, swift, swiftpm, nix-update-script, }: -let - inherit (llvmPackages) stdenv; -in + stdenv.mkDerivation (finalAttrs: { pname = "age-plugin-se"; version = "0.2.1"; @@ -26,43 +24,18 @@ stdenv.mkDerivation (finalAttrs: { swiftpm ]; - env = lib.optionalAttrs stdenv.hostPlatform.isLinux { - # Can't find libdispatch without this on NixOS. (swift 5.8) - LD_LIBRARY_PATH = "${swiftPackages.Dispatch}/lib"; + swiftpmDeps = fetchSwiftPMDeps { + inherit (finalAttrs) pname version src; + hash = "sha256-rGPaSlNmW4zn2bBhu3LnJvPUWBQhAfFmHnNFm9jKR+8="; }; - postPatch = - let - swift-crypto = fetchFromGitHub { - owner = "apple"; - repo = "swift-crypto"; - tag = "3.7.1"; - hash = "sha256-zxmHxTryAezgqU5qjXlFFThJlfUsPxb1KRBan4DSm9A="; - }; - in - '' - ${lib.optionalString (lib.versionAtLeast swift.version "6") '' - echo "age-plugin-se still applies patch-package-swift-legacy; remove or revisit this patch now that nixpkgs Swift is 6+." - exit 1 - ''} - make patch-package-swift-legacy - ln -s ${swift-crypto} swift-crypto - substituteInPlace Package.swift --replace-fail 'url: "https://github.com/apple/swift-crypto.git"' 'path: "./swift-crypto"), //' - ${lib.optionalString stdenv.hostPlatform.isLinux '' - # Swift 5.10.1's corelibs Foundation lacks Date.ISO8601Format(). - # Remove this substitution once the upstream fallback is released: - # https://github.com/remko/age-plugin-se/issues/20 - substituteInPlace Sources/Plugin.swift --replace-fail \ - 'let createdAt = now.ISO8601Format()' \ - 'let createdAt = ISO8601DateFormatter().string(from: now)' - ''} - ''; - makeFlags = [ "PREFIX=$(out)" "RELEASE=1" ]; + dontUseSwiftpmInstall = true; + passthru.updateScript = nix-update-script { }; meta = { diff --git a/pkgs/by-name/ai/airdrop-cli/package.nix b/pkgs/by-name/ai/airdrop-cli/package.nix index 0b60f966e5d6..98cdac894c5f 100644 --- a/pkgs/by-name/ai/airdrop-cli/package.nix +++ b/pkgs/by-name/ai/airdrop-cli/package.nix @@ -1,13 +1,12 @@ { lib, fetchFromGitHub, + stdenv, swift, - swiftPackages, swiftpm, }: -# Doesn't build without using the same stdenv (and Clang) to build swift -swiftPackages.stdenv.mkDerivation { +stdenv.mkDerivation { pname = "airdrop-cli"; version = "0-unstable-2025-07-14"; @@ -27,6 +26,8 @@ swiftPackages.stdenv.mkDerivation { "PREFIX=$(out)" ]; + dontUseSwiftpmInstall = true; + meta = { description = "Use Airdrop from the CLI on macOS written in Swift"; homepage = "https://github.com/vldmrkl/airdrop-cli"; diff --git a/pkgs/by-name/al/alsa-scarlett-gui/package.nix b/pkgs/by-name/al/alsa-scarlett-gui/package.nix index e96089a715c6..2215e090c31a 100644 --- a/pkgs/by-name/al/alsa-scarlett-gui/package.nix +++ b/pkgs/by-name/al/alsa-scarlett-gui/package.nix @@ -22,7 +22,10 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-DkfpMK0T67B4mnriignf4hx6Ifddls0rN0SxyfEsPZg="; }; - env.NIX_CFLAGS_COMPILE = toString [ "-Wno-error=deprecated-declarations" ]; + env.NIX_CFLAGS_COMPILE = toString [ + "-Wno-error=deprecated-declarations" + "-Wno-error=discarded-qualifiers" + ]; makeFlags = [ "DESTDIR=\${out}" diff --git a/pkgs/by-name/al/alt-tab-macos/0001-replace-count-where-with-filter-.count-for-Swift-5.1.patch b/pkgs/by-name/al/alt-tab-macos/0001-replace-count-where-with-filter-.count-for-Swift-5.1.patch deleted file mode 100644 index 3d26fdb7a744..000000000000 --- a/pkgs/by-name/al/alt-tab-macos/0001-replace-count-where-with-filter-.count-for-Swift-5.1.patch +++ /dev/null @@ -1,39 +0,0 @@ -From 85a2e0440f8af42ae02cf7fee1119255b2459016 Mon Sep 17 00:00:00 2001 -From: nixpkgs -Date: Fri, 10 Jul 2026 12:21:11 +0300 -Subject: [PATCH 1/4] replace count(where:) with filter{}.count for Swift 5.10 - ---- - src/events/TrackpadEvents.swift | 2 +- - src/switcher/main-window/StatusIconsView.swift | 2 +- - 2 files changed, 2 insertions(+), 2 deletions(-) - -diff --git a/src/events/TrackpadEvents.swift b/src/events/TrackpadEvents.swift -index 2f1909df..5e187064 100644 ---- a/src/events/TrackpadEvents.swift -+++ b/src/events/TrackpadEvents.swift -@@ -76,7 +76,7 @@ class TrackpadEvents { - // on macOS, the finger contact surface is not exposed in NSTouch, so we can't detect big contact == palm, for example - // the closest thing we can do to detect resting inputs is remove touches which have .phase == .stationary - let activeTouches = touches.filter { !$0.isResting && ($0.phase == .began || $0.phase == .moved) } -- let fingersDown = touches.count { $0.phase == .began || $0.phase == .moved || $0.phase == .stationary } -+ let fingersDown = touches.filter { $0.phase == .began || $0.phase == .moved || $0.phase == .stationary }.count - let requiredFingers = Preferences.nextWindowGesture.isThreeFinger() ? 3 : 4 - if SwitcherSession.isActive { - handleEventIfAppIsBeingUsed(fingersDown, activeTouches, requiredFingers) -diff --git a/src/switcher/main-window/StatusIconsView.swift b/src/switcher/main-window/StatusIconsView.swift -index beeb2a54..2f35bddc 100644 ---- a/src/switcher/main-window/StatusIconsView.swift -+++ b/src/switcher/main-window/StatusIconsView.swift -@@ -76,7 +76,7 @@ class StatusIconsView: FlippedView { - icons[Self.fullscreenIdx].visible = isFullscreen - icons[Self.minimizedIdx].visible = isMinimized - icons[Self.spaceIdx].visible = showSpace -- visibleCount = icons.count(where: { $0.visible }) -+ visibleCount = icons.filter { $0.visible }.count - } - - func setSpaceStar() { --- -2.55.0 - diff --git a/pkgs/by-name/al/alt-tab-macos/0002-replace-.extraLarge-with-.large-for-macOS-14-SDK.patch b/pkgs/by-name/al/alt-tab-macos/0002-replace-.extraLarge-with-.large-for-macOS-14-SDK.patch deleted file mode 100644 index 15e284d6611f..000000000000 --- a/pkgs/by-name/al/alt-tab-macos/0002-replace-.extraLarge-with-.large-for-macOS-14-SDK.patch +++ /dev/null @@ -1,39 +0,0 @@ -From 7313d220616e756c4bb4f2c8cc5cf6b6b2e4789c Mon Sep 17 00:00:00 2001 -From: nixpkgs -Date: Fri, 10 Jul 2026 12:21:11 +0300 -Subject: [PATCH 2/4] replace .extraLarge with .large for macOS 14 SDK - ---- - src/preferences/settings-window/SettingsWindow.swift | 2 +- - src/switcher/main-window/TilesView.swift | 2 +- - 2 files changed, 2 insertions(+), 2 deletions(-) - -diff --git a/src/preferences/settings-window/SettingsWindow.swift b/src/preferences/settings-window/SettingsWindow.swift -index 866329ea..44f1da76 100644 ---- a/src/preferences/settings-window/SettingsWindow.swift -+++ b/src/preferences/settings-window/SettingsWindow.swift -@@ -462,7 +462,7 @@ class SettingsWindow: NSWindow { - searchField.sendsWholeSearchString = true - searchField.bezelStyle = .roundedBezel - if #available(macOS 26.0, *) { -- searchField.controlSize = .extraLarge -+ searchField.controlSize = .large - } else if #available(macOS 13.0, *) { - searchField.controlSize = .large - } -diff --git a/src/switcher/main-window/TilesView.swift b/src/switcher/main-window/TilesView.swift -index d6c7fb69..b6f374c9 100644 ---- a/src/switcher/main-window/TilesView.swift -+++ b/src/switcher/main-window/TilesView.swift -@@ -142,7 +142,7 @@ class TilesView { - searchField.sendsWholeSearchString = true - searchField.bezelStyle = .roundedBezel - if #available(macOS 26.0, *) { -- searchField.controlSize = .extraLarge -+ searchField.controlSize = .large - } else if #available(macOS 13.0, *) { - searchField.controlSize = .large - } else { --- -2.55.0 - diff --git a/pkgs/by-name/al/alt-tab-macos/0003-use-runtime-dispatch-for-Liquid-Glass-with-SDK-14.patch b/pkgs/by-name/al/alt-tab-macos/0003-use-runtime-dispatch-for-Liquid-Glass-with-SDK-14.patch deleted file mode 100644 index ebd914a0bd0e..000000000000 --- a/pkgs/by-name/al/alt-tab-macos/0003-use-runtime-dispatch-for-Liquid-Glass-with-SDK-14.patch +++ /dev/null @@ -1,193 +0,0 @@ -From 727f4c5aed5960bb429c7df0bbc3a547e05db7dd Mon Sep 17 00:00:00 2001 -From: nixpkgs -Date: Fri, 10 Jul 2026 12:21:12 +0300 -Subject: [PATCH 3/4] use runtime dispatch for Liquid Glass with SDK 14 - ---- - src/switcher/Appearance.swift | 2 +- - .../TilesPanelBackgroundView.swift | 122 +++++++++++------- - 2 files changed, 77 insertions(+), 47 deletions(-) - -diff --git a/src/switcher/Appearance.swift b/src/switcher/Appearance.swift -index dd033fa4..efb70c77 100644 ---- a/src/switcher/Appearance.swift -+++ b/src/switcher/Appearance.swift -@@ -83,7 +83,7 @@ class Appearance { - lightTheme() - } - // for Liquid Glass, we don't want a shadow around the panel -- if #available(macOS 26.0, *), currentStyle == .appIcons && LiquidGlass.canUsePrivateLook { -+ if #available(macOS 26.0, *), currentStyle == .appIcons && LiquidGlassEffectView.canUsePrivateLook { - enablePanelShadow = false - } else { - enablePanelShadow = true -diff --git a/src/switcher/main-window/TilesPanelBackgroundView.swift b/src/switcher/main-window/TilesPanelBackgroundView.swift -index cea0819c..99d12b06 100644 ---- a/src/switcher/main-window/TilesPanelBackgroundView.swift -+++ b/src/switcher/main-window/TilesPanelBackgroundView.swift -@@ -7,12 +7,81 @@ protocol EffectView: NSView { - } - - @available(macOS 26.0, *) --extension NSGlassEffectView: EffectView { -- func updateAppearance() { -- cornerRadius = Appearance.windowCornerRadius -+class LiquidGlassEffectView: NSView, EffectView { -+ private typealias SetIntType = @convention(c) (AnyObject, Selector, Int) -> Void -+ private typealias SetCGFloatType = @convention(c) (AnyObject, Selector, CGFloat) -> Void -+ private typealias SetObjectType = @convention(c) (AnyObject, Selector, AnyObject) -> Void -+ private static let setVariantSelector = NSSelectorFromString("set_variant:") -+ private static let setStyleSelector = NSSelectorFromString("setStyle:") -+ private static let setCornerRadiusSelector = NSSelectorFromString("setCornerRadius:") -+ private static let setContentViewSelector = NSSelectorFromString("setContentView:") -+ private static let glassClass: AnyClass? = NSClassFromString("NSGlassEffectView") -+ -+ static let canUsePrivateLook: Bool = { -+ guard let cls = glassClass else { return false } -+ return class_getInstanceMethod(cls, setVariantSelector) != nil -+ }() -+ -+ private var glassView: NSView? -+ private var contentHost: NSView! -+ -+ var hostView: NSView { contentHost } -+ -+ convenience init(clear: Bool) { -+ self.init(frame: .zero) -+ wantsLayer = true -+ layer!.masksToBounds = true -+ -+ let glass: NSView -+ if let cls = Self.glassClass as? NSView.Type { -+ glass = cls.init(frame: .zero) -+ } else { -+ glass = NSView(frame: .zero) -+ } -+ glass.translatesAutoresizingMaskIntoConstraints = false -+ addSubview(glass) -+ NSLayoutConstraint.activate([ -+ glass.leadingAnchor.constraint(equalTo: leadingAnchor), -+ glass.trailingAnchor.constraint(equalTo: trailingAnchor), -+ glass.topAnchor.constraint(equalTo: topAnchor), -+ glass.bottomAnchor.constraint(equalTo: bottomAnchor), -+ ]) -+ glassView = glass -+ -+ // NSGlassEffectView.Style: regular = 0, clear = 1 -+ Self.invokeIntSetter(glass, Self.setStyleSelector, clear ? 1 : 0) -+ if clear { -+ Self.invokeIntSetter(glass, Self.setVariantSelector, 3) -+ } -+ contentHost = NSView(frame: .zero) -+ Self.invokeObjectSetter(glass, Self.setContentViewSelector, contentHost) -+ updateAppearance() -+ } -+ -+ private static func invokeIntSetter(_ target: AnyObject, _ selector: Selector, _ value: Int) { -+ guard let method = class_getInstanceMethod(object_getClass(target), selector) else { return } -+ let function = unsafeBitCast(method_getImplementation(method), to: SetIntType.self) -+ function(target, selector, value) - } - -- var hostView: NSView { contentView! } -+ private static func invokeCGFloatSetter(_ target: AnyObject, _ selector: Selector, _ value: CGFloat) { -+ guard let method = class_getInstanceMethod(object_getClass(target), selector) else { return } -+ let function = unsafeBitCast(method_getImplementation(method), to: SetCGFloatType.self) -+ function(target, selector, value) -+ } -+ -+ private static func invokeObjectSetter(_ target: AnyObject, _ selector: Selector, _ value: AnyObject) { -+ guard let method = class_getInstanceMethod(object_getClass(target), selector) else { return } -+ let function = unsafeBitCast(method_getImplementation(method), to: SetObjectType.self) -+ function(target, selector, value) -+ } -+ -+ func updateAppearance() { -+ let radius = Appearance.windowCornerRadius -+ layer?.cornerRadius = radius -+ guard let glass = glassView else { return } -+ Self.invokeCGFloatSetter(glass, Self.setCornerRadiusSelector, radius) -+ } - } - - class FrostedGlassEffectView: NSVisualEffectView, EffectView { -@@ -51,28 +120,6 @@ class FrostedGlassEffectView: NSVisualEffectView, EffectView { - } - } - --/// The App Icons style uses the private `set_variant:` on `NSGlassEffectView` to get the macOS --/// Cmd-Tab-like clear glass look. `style = .clear` alone renders nearly fully transparent, so the --/// variant is what makes the panel visible. Lives here as a free helper (no NSGlassEffectView subclass). --enum LiquidGlass { -- private static let setVariantSelector = NSSelectorFromString("set_variant:") -- private typealias SetVariantFn = @convention(c) (AnyObject, Selector, Int) -> Void -- -- static let canUsePrivateLook: Bool = { -- if #available(macOS 26.0, *) { -- return class_getInstanceMethod(object_getClass(NSGlassEffectView()), setVariantSelector) != nil -- } -- return false -- }() -- -- @available(macOS 26.0, *) -- static func applyClearVariant(_ view: NSGlassEffectView) { -- guard let method = class_getInstanceMethod(object_getClass(view), setVariantSelector) else { return } -- let f = unsafeBitCast(method_getImplementation(method), to: SetVariantFn.self) -- f(view, setVariantSelector, 3) -- } --} -- - enum EffectViewKind { - case frosted - case liquidGlassRegular -@@ -82,7 +129,7 @@ enum EffectViewKind { - func requiredEffectViewKind() -> EffectViewKind { - if #available(macOS 26.0, *) { - if Preferences.effectiveAppearanceStyle(SwitcherSession.activeShortcutIndex) == .appIcons, -- LiquidGlass.canUsePrivateLook { -+ LiquidGlassEffectView.canUsePrivateLook { - return .liquidGlassClear - } - return .liquidGlassRegular -@@ -90,28 +137,11 @@ func requiredEffectViewKind() -> EffectViewKind { - return .frosted - } - --@available(macOS 26.0, *) --private func makeGlassEffectView(clear: Bool) -> NSGlassEffectView { -- let glass = NSGlassEffectView() -- glass.style = clear ? .clear : .regular -- if clear { -- LiquidGlass.applyClearVariant(glass) -- } -- // NSGlassEffectView only renders views embedded in `contentView`; this single host holds the -- // scroll view, search field and empty-state label so they all sit inside the glass. -- glass.contentView = NSView() -- glass.updateAppearance() -- // without this, there are weird shadows around the corners (most visible with .regular glass) -- glass.wantsLayer = true -- glass.layer!.masksToBounds = true -- return glass --} -- - func makeEffectView(for kind: EffectViewKind) -> EffectView { - if #available(macOS 26.0, *) { - switch kind { - case .liquidGlassClear: -- return makeGlassEffectView(clear: true) -+ return LiquidGlassEffectView(clear: true) - case .liquidGlassRegular: - if Preferences.effectiveAppearanceStyle(SwitcherSession.activeShortcutIndex) == .appIcons { - Logger.error { -@@ -119,7 +149,7 @@ func makeEffectView(for kind: EffectViewKind) -> EffectView { - return "Private API set_variant is no longer available. macOS version: \(os.majorVersion).\(os.minorVersion).\(os.patchVersion)" - } - } -- return makeGlassEffectView(clear: false) -+ return LiquidGlassEffectView(clear: false) - case .frosted: - break - } --- -2.55.0 - diff --git a/pkgs/by-name/al/alt-tab-macos/0005-avoid-using-obsolete-api.patch b/pkgs/by-name/al/alt-tab-macos/0005-avoid-using-obsolete-api.patch new file mode 100644 index 000000000000..e4658dd7bf27 --- /dev/null +++ b/pkgs/by-name/al/alt-tab-macos/0005-avoid-using-obsolete-api.patch @@ -0,0 +1,53 @@ +diff --git a/src/macos/SystemPermissions.swift b/src/macos/SystemPermissions.swift +index 4a98ef9461..ae983eb73a 100644 +--- a/src/macos/SystemPermissions.swift ++++ b/src/macos/SystemPermissions.swift +@@ -158,24 +158,7 @@ + // their return value is not updated during the app lifetime + // note: shows the system prompt if there's no permission + private static func isGrantedOnSomeDisplay() -> Bool { +- if #available(macOS 12.3, *) { +- return checkWithSCShareableContent() +- } else { +- let mainDisplayID = CGMainDisplayID() +- if checkWithCGDisplayStream(mainDisplayID) { +- return true +- } +- // maybe the main screen can't produce a CGDisplayStream, but another screen can +- // a positive on any screen must mean that the permission is granted; we try on the other screens +- for screen in NSScreen.screens { +- if let id = screen.number(), id != mainDisplayID { +- if checkWithCGDisplayStream(id) { +- return true +- } +- } +- } +- return false +- } ++ return checkWithSCShareableContent() + } + + @available(macOS 12.3, *) +@@ -193,22 +176,6 @@ + } + } + +- private static func checkWithCGDisplayStream(_ id: CGDirectDisplayID) -> Bool { +- return runWithTimeout { completion in +- // this initializer can actually block for a while +- // it's undocumented but has been proven by spindumps shared by AltTab users +- let displayStream = CGDisplayStream( +- dispatchQueueDisplay: id, +- outputWidth: 1, +- outputHeight: 1, +- pixelFormat: Int32(kCVPixelFormatType_32BGRA), +- properties: nil, +- queue: .global() +- ) { _, _, _, _ in } +- completion(displayStream != nil) +- } +- } +- + private static func runWithTimeout(_ block: @escaping (@escaping (Bool) -> Void) -> Void) -> Bool { + let semaphore = DispatchSemaphore(value: 0) + var result = false diff --git a/pkgs/by-name/al/alt-tab-macos/package.nix b/pkgs/by-name/al/alt-tab-macos/package.nix index a5c70709aaac..720cf73741e4 100644 --- a/pkgs/by-name/al/alt-tab-macos/package.nix +++ b/pkgs/by-name/al/alt-tab-macos/package.nix @@ -1,17 +1,16 @@ { lib, - swiftPackages, fetchFromGitHub, actool, lld, + stdenv, + swift, makeWrapper, nix-update-script, rcodesign, }: let - inherit (swiftPackages) stdenv swift; - toPlist = lib.generators.toPlist { escape = true; }; deploymentTarget = "14.0"; sdkVersion = "26.0"; @@ -83,9 +82,6 @@ let allFrameworks = lib.catAttrs "name" frameworks; objcFrameworks = lib.filter (fw: fw ? objc) frameworks; - # apple-sdk_26 cannot be used here because swiftPackages compiles its own modules - # against apple-sdk_14; adding it to buildInputs redirects SDKROOT and breaks Swift's - # foundational modules commonSwiftFlags = [ "-O" "-swift-version" @@ -282,30 +278,15 @@ stdenv.mkDerivation (finalAttrs: { ]; patches = [ - # Swift 5.10 compatibility: count(where:), .extraLarge, Liquid Glass - ./0001-replace-count-where-with-filter-.count-for-Swift-5.1.patch - ./0002-replace-.extraLarge-with-.large-for-macOS-14-SDK.patch - ./0003-use-runtime-dispatch-for-Liquid-Glass-with-SDK-14.patch # Don't offer preferences for services disabled by the source-only stubs. ./0004-hide-settings-for-disabled-services.patch + # Avoids error about `CGDisplayStream` initializer being unavailable on macOS when using the 26.x SDK. + ./0005-avoid-using-obsolete-api.patch ]; - # Remove trailing comma incompatible with Swift 5.10 postPatch = '' substituteInPlace Info.plist \ ${substitutePlistVariables (infoPlistSubstitutions finalAttrs.version)} - - substituteInPlace src/secondary-windows/permission-window/PermissionsWindow.swift \ - --replace-fail \ - '"x-apple.systempreferences:com.apple.preference.security?Privacy_Accessibility",' \ - '"x-apple.systempreferences:com.apple.preference.security?Privacy_Accessibility"' - - # Swift 5.10 compat: additional call site using trailing-closure - # sugar for count(where:). See 0001-replace-count-where-...patch. - substituteInPlace src/util/UsageStats.swift \ - --replace-fail \ - 'getTimestamps(key).count { $0 >= threshold }' \ - 'getTimestamps(key).filter { $0 >= threshold }.count' ''; dontConfigure = true; diff --git a/pkgs/by-name/an/anki/package.nix b/pkgs/by-name/an/anki/package.nix index 5f5119b4d917..d53ca31f1ce4 100644 --- a/pkgs/by-name/an/anki/package.nix +++ b/pkgs/by-name/an/anki/package.nix @@ -24,6 +24,7 @@ yarn, yarn-berry_4, runCommand, + substitute, wrapGAppsHook3, @@ -42,7 +43,7 @@ let srcHash = "sha256-0sqtKiMqw7MLXVFSCT1sKX/VO7q5BY63pJP5OnCE2zo="; cargoHash = "sha256-LQ5uD86ZOKXy9vGbTqPBi3Q57PZEjwQkbHR94QAIVMg="; - yarnHash = "sha256-bOgiZImraPXR/gVk9MB3o9GScMGvLvdhc9mLAaCA4IE="; + yarnHash = "sha256-mpHGclmQxFqiIuZWFTOYBKQW24ugSVhQiYMTmyyk/n4="; pythonDeps = with python3Packages; [ @@ -155,9 +156,16 @@ python3Packages.buildPythonApplication (finalAttrs: { # Used in with-addons.nix ./patches/allow-setting-addons-folder.patch - # Remove after upstream updates to Yarn 4.14 - # https://github.com/ankitects/anki/blob/main/package.json#L99 - ./patches/yarn-4.14-support.patch + # Remove after upstream updates to Yarn 4.15 + # https://github.com/ankitects/anki/blob/main/package.json#L103 + (substitute { + src = ./patches/yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry.lockfileVersion + ]; + }) ]; inherit cargoDeps; diff --git a/pkgs/by-name/an/anki/patches/yarn-4.14-support.patch b/pkgs/by-name/an/anki/patches/yarn-fix.patch similarity index 88% rename from pkgs/by-name/an/anki/patches/yarn-4.14-support.patch rename to pkgs/by-name/an/anki/patches/yarn-fix.patch index c45ad0430e5e..1be64c531419 100644 --- a/pkgs/by-name/an/anki/patches/yarn-4.14-support.patch +++ b/pkgs/by-name/an/anki/patches/yarn-fix.patch @@ -14,6 +14,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10c0 diff --git a/pkgs/by-name/ap/apache-orc/package.nix b/pkgs/by-name/ap/apache-orc/package.nix index 0034206b1d3d..417dbc034790 100644 --- a/pkgs/by-name/ap/apache-orc/package.nix +++ b/pkgs/by-name/ap/apache-orc/package.nix @@ -75,7 +75,7 @@ stdenv.mkDerivation (finalAttrs: { GTEST_HOME = gtest.dev; LZ4_HOME = lz4; ORC_FORMAT_URL = orc-format; - PROTOBUF_HOME = protobuf; + PROTOBUF_HOME = protobuf.full; # Configure script expects to find both executables and headers at this path. SNAPPY_HOME = snappy.dev; ZLIB_HOME = zlib.dev; ZSTD_HOME = zstd.dev; diff --git a/pkgs/by-name/ap/apple-sdk/metadata/disallowed-packages.json b/pkgs/by-name/ap/apple-sdk/metadata/disallowed-packages.json index f407c114fe8e..c834efc16e83 100644 --- a/pkgs/by-name/ap/apple-sdk/metadata/disallowed-packages.json +++ b/pkgs/by-name/ap/apple-sdk/metadata/disallowed-packages.json @@ -482,6 +482,40 @@ { "package": "swift", "libraries": [ + "swift/Cxx.swiftmodule", + "swift/CxxStdlib.swiftmodule", + "swift/Distributed.swiftmodule", + "swift/Observation.swiftmodule", + "swift/RegexBuilder.swiftmodule", + "swift/Runtime.swiftmodule", + "swift/Swift.swiftmodule", + "swift/SwiftOnoneSupport.swiftmodule", + "swift/Synchronization.swiftmodule", + "swift/_Builtin_float.swiftmodule", + "swift/_Concurrency.swiftmodule", + "swift/_Differentiation.swiftmodule", + "swift/_RegexParser.swiftmodule", + "swift/_StringProcessing.swiftmodule", + "swift/_Volatile.swiftmodule", + "swift/lib_InternalSwiftStaticMirror.tbd", + "swift/libcxxshim.h", + "swift/libcxxshim.modulemap", + "swift/libcxxstdlibshim.h", + "swift/libswiftCompatibilitySpan.tbd", + "swift/libswiftCore.tbd", + "swift/libswiftDistributed.tbd", + "swift/libswiftObservation.tbd", + "swift/libswiftRegexBuilder.tbd", + "swift/libswiftRemoteMirror.tbd", + "swift/libswiftRuntime.tbd", + "swift/libswiftSwiftOnoneSupport.tbd", + "swift/libswiftSynchronization.tbd", + "swift/libswift_Builtin_float.tbd", + "swift/libswift_Concurrency.tbd", + "swift/libswift_Differentiation.tbd", + "swift/libswift_RegexParser.tbd", + "swift/libswift_StringProcessing.tbd", + "swift/libswift_Volatile.tbd", "swift/shims" ] }, diff --git a/pkgs/by-name/ap/apple-sdk/metadata/versions.json b/pkgs/by-name/ap/apple-sdk/metadata/versions.json index d655c7ebada9..d589cc6940cf 100644 --- a/pkgs/by-name/ap/apple-sdk/metadata/versions.json +++ b/pkgs/by-name/ap/apple-sdk/metadata/versions.json @@ -22,5 +22,13 @@ ], "version": "26.5", "hash": "sha256-IkDNtiO7PP4GI6OszCNWE1Xb4iepCUKwQHYUyc9NgNA=" + }, + "27": { + "urls": [ + "https://swcdn.apple.com/content/downloads/58/48/082-83364-A_KCEBOO2NJS/0d2rj4y5ucjlkgcvqt6f6a4pergug5tu2b/CLTools_macOSNMOS_SDK.pkg", + "https://web.archive.org/web/20260910221111/https://swcdn.apple.com/content/downloads/58/48/082-83364-A_KCEBOO2NJS/0d2rj4y5ucjlkgcvqt6f6a4pergug5tu2b/CLTools_macOSNMOS_SDK.pkg" + ], + "version": "27.0", + "hash": "sha256-qTDE8wu3pfk21WtgboKHYH/MiJnC8gKpDeMyrRJZaP8=" } } diff --git a/pkgs/by-name/ap/apple-sdk/package.nix b/pkgs/by-name/ap/apple-sdk/package.nix index 761ebb903e8f..04a0fdee1e0a 100644 --- a/pkgs/by-name/ap/apple-sdk/package.nix +++ b/pkgs/by-name/ap/apple-sdk/package.nix @@ -100,6 +100,7 @@ stdenvNoCC.mkDerivation ( passthru = { sdkroot = finalAttrs.finalPackage + "/Platforms/MacOSX.platform/Developer/SDKs/MacOSX.sdk"; + tests = callPackage ./tests { }; }; __structuredAttrs = true; diff --git a/pkgs/by-name/ap/apple-sdk/tests/15/apple-sdk_15-test.m b/pkgs/by-name/ap/apple-sdk/tests/15/apple-sdk_15-test.m new file mode 100644 index 000000000000..f2e55a76e92f --- /dev/null +++ b/pkgs/by-name/ap/apple-sdk/tests/15/apple-sdk_15-test.m @@ -0,0 +1,10 @@ +#include +#include + +int main() { + if (@available(macOS 15, *)) { + printf("%f\n", (double) __sqrtf16(2)); + } else { + printf(":(\n"); + } +} diff --git a/pkgs/by-name/ap/apple-sdk/tests/15/meson.build b/pkgs/by-name/ap/apple-sdk/tests/15/meson.build new file mode 100644 index 000000000000..c2d56fd595d2 --- /dev/null +++ b/pkgs/by-name/ap/apple-sdk/tests/15/meson.build @@ -0,0 +1,2 @@ +project('apple-sdk_15-test', 'objc') +executable('apple-sdk_15-test', 'apple-sdk_15-test.m', install : true) diff --git a/pkgs/by-name/ap/apple-sdk/tests/26/apple-sdk_26-test.m b/pkgs/by-name/ap/apple-sdk/tests/26/apple-sdk_26-test.m new file mode 100644 index 000000000000..21fc3af5253a --- /dev/null +++ b/pkgs/by-name/ap/apple-sdk/tests/26/apple-sdk_26-test.m @@ -0,0 +1,21 @@ +#include +#include + +int main(int argc, char** argv, char** env) { + if (@available(macOS 26, *)) { + int ret; + pid_t pid; + posix_spawn_file_actions_t actions; + if ((ret = posix_spawn_file_actions_init(&actions))) { + printf("cannot create file_actions\n"); + } + if ((ret = posix_spawn_file_actions_addchdir(&actions, "/tmp"))) { + printf("cannot add_chdir\n"); + } + if ((ret = posix_spawnp(&pid, "pwd", &actions, NULL, argv, env))) { + printf("cannot spawn\n"); + } + } else { + printf(":(\n"); + } +} diff --git a/pkgs/by-name/ap/apple-sdk/tests/26/meson.build b/pkgs/by-name/ap/apple-sdk/tests/26/meson.build new file mode 100644 index 000000000000..ef3a4c6179aa --- /dev/null +++ b/pkgs/by-name/ap/apple-sdk/tests/26/meson.build @@ -0,0 +1,2 @@ +project('apple-sdk_26-test', 'objc') +executable('apple-sdk_26-test', 'apple-sdk_26-test.m', install : true) diff --git a/pkgs/by-name/ap/apple-sdk/tests/27/apple-sdk_27-test.m b/pkgs/by-name/ap/apple-sdk/tests/27/apple-sdk_27-test.m new file mode 100644 index 000000000000..6ae05bc7bc69 --- /dev/null +++ b/pkgs/by-name/ap/apple-sdk/tests/27/apple-sdk_27-test.m @@ -0,0 +1,15 @@ +#include +#include + +int main() { + if (@available(macOS 27, *)) { + int ret = dup3(1, 3, 0); + if (ret < 0) { + printf("dup3(1,3,0) failed with error\n"); + return -1; + } + dprintf(3, ":)\n"); + } else { + printf(":(\n"); + } +} diff --git a/pkgs/by-name/ap/apple-sdk/tests/27/meson.build b/pkgs/by-name/ap/apple-sdk/tests/27/meson.build new file mode 100644 index 000000000000..9169cd8d251b --- /dev/null +++ b/pkgs/by-name/ap/apple-sdk/tests/27/meson.build @@ -0,0 +1,2 @@ +project('apple-sdk_27-test', 'objc') +executable('apple-sdk_27-test', 'apple-sdk_27-test.m', install : true) diff --git a/pkgs/by-name/ap/apple-sdk/tests/default.nix b/pkgs/by-name/ap/apple-sdk/tests/default.nix new file mode 100644 index 000000000000..5cb2f5cf7c99 --- /dev/null +++ b/pkgs/by-name/ap/apple-sdk/tests/default.nix @@ -0,0 +1,61 @@ +{ + lib, + stdenv, + ninja, + meson, + apple-sdk_15, + apple-sdk_26, + apple-sdk_27, +}: +{ + apple-sdk_15 = stdenv.mkDerivation { + name = "apple-sdk_15-test"; + + src = ./15; + + nativeBuildInputs = [ + meson + ninja + ]; + + buildInputs = [ + apple-sdk_15 + ]; + + meta.mainProgram = "apple-sdk_15-test"; + }; + + apple-sdk_26 = stdenv.mkDerivation { + name = "apple-sdk_26-test"; + + src = ./26; + + nativeBuildInputs = [ + meson + ninja + ]; + + buildInputs = [ + apple-sdk_26 + ]; + + meta.mainProgram = "apple-sdk_26-test"; + }; + + apple-sdk_27 = stdenv.mkDerivation { + name = "apple-sdk_27-test"; + + src = ./27; + + nativeBuildInputs = [ + meson + ninja + ]; + + buildInputs = [ + apple-sdk_27 + ]; + + meta.mainProgram = "apple-sdk_27-test"; + }; +} diff --git a/pkgs/by-name/ar/ardour/package.nix b/pkgs/by-name/ar/ardour/package.nix index 0f033bf26113..45b6f21c1d5e 100644 --- a/pkgs/by-name/ar/ardour/package.nix +++ b/pkgs/by-name/ar/ardour/package.nix @@ -21,7 +21,7 @@ flac, fluidsynth, glibc, - glibmm, + glibmm_2_4, graphviz, harvid, hidapi, @@ -36,7 +36,7 @@ libpulseaudio, librdf_rasqal, libsamplerate, - libsigcxx, + libsigcxx_2_0, libsndfile, libusb1, libuv, @@ -142,7 +142,7 @@ let fftwSinglePrec flac fluidsynth - glibmm + glibmm_2_4 hidapi itstool kissfft @@ -154,7 +154,7 @@ let libogg librdf_rasqal libsamplerate - libsigcxx + libsigcxx_2_0 libsndfile libusb1 libuv diff --git a/pkgs/by-name/ar/ardour_8/package.nix b/pkgs/by-name/ar/ardour_8/package.nix index 766c6ebc7891..b98bb8f97358 100644 --- a/pkgs/by-name/ar/ardour_8/package.nix +++ b/pkgs/by-name/ar/ardour_8/package.nix @@ -17,7 +17,7 @@ flac, fluidsynth, glibc, - glibmm, + glibmm_2_4, graphviz, harvid, hidapi, @@ -31,7 +31,7 @@ libpulseaudio, librdf_rasqal, libsamplerate, - libsigcxx, + libsigcxx_2_0, libsndfile, libusb1, libuv, @@ -129,7 +129,7 @@ stdenv.mkDerivation ( fftwSinglePrec flac fluidsynth - glibmm + glibmm_2_4 hidapi itstool kissfft @@ -141,7 +141,7 @@ stdenv.mkDerivation ( libpulseaudio librdf_rasqal libsamplerate - libsigcxx + libsigcxx_2_0 libsndfile libusb1 libuv diff --git a/pkgs/by-name/ar/art/package.nix b/pkgs/by-name/ar/art/package.nix index 03974271c6c5..d3414bb8096e 100644 --- a/pkgs/by-name/ar/art/package.nix +++ b/pkgs/by-name/ar/art/package.nix @@ -25,7 +25,7 @@ fftwSinglePrec, expat, pcre2, - libsigcxx, + libsigcxx_2_0, lensfun, librsvg, libcanberra-gtk3, @@ -83,7 +83,7 @@ stdenv.mkDerivation (finalAttrs: { fftwSinglePrec expat pcre2 - libsigcxx + libsigcxx_2_0 lensfun librsvg exiv2 diff --git a/pkgs/by-name/as/asc/package.nix b/pkgs/by-name/as/asc/package.nix index c28bd20cd0ef..2d1bc8b33a84 100644 --- a/pkgs/by-name/as/asc/package.nix +++ b/pkgs/by-name/as/asc/package.nix @@ -6,7 +6,7 @@ SDL_image, SDL_mixer, SDL_sound, - libsigcxx, + libsigcxx_2_0, physfs, boost, expat, @@ -64,7 +64,7 @@ stdenv.mkDerivation { flac libvorbis libogg - libsigcxx + libsigcxx_2_0 ]; meta = { diff --git a/pkgs/by-name/at/atkmm/package.nix b/pkgs/by-name/at/atkmm/package.nix index 40929610a2ce..b2eff2bbbde9 100644 --- a/pkgs/by-name/at/atkmm/package.nix +++ b/pkgs/by-name/at/atkmm/package.nix @@ -3,7 +3,7 @@ stdenv, fetchurl, atk, - glibmm, + glibmm_2_4, pkg-config, gnome, meson, @@ -27,7 +27,7 @@ stdenv.mkDerivation (finalAttrs: { propagatedBuildInputs = [ atk - glibmm + glibmm_2_4 ]; nativeBuildInputs = [ diff --git a/pkgs/by-name/at/ats2/fix-build-glibc-2.44.patch b/pkgs/by-name/at/ats2/fix-build-glibc-2.44.patch new file mode 100644 index 000000000000..5cc48100c380 --- /dev/null +++ b/pkgs/by-name/at/ats2/fix-build-glibc-2.44.patch @@ -0,0 +1,20 @@ +diff --git a/prelude/CATS/array.cats b/prelude/CATS/array.cats +index 70c7e3e..cec3b1d 100644 +--- a/prelude/CATS/array.cats ++++ b/prelude/CATS/array.cats +@@ -56,6 +56,7 @@ void qsort + void *base, size_t nmemb, size_t size + , int(*compar)(const void *, const void *) + ) ; // end of [qsort] ++#ifndef bsearch + extern + void *bsearch + ( +@@ -64,6 +65,7 @@ void *bsearch + , size_t nmemb, size_t size + , int (*compar)(const void *, const void *) + ) ; // end of [bsearch] ++#endif + // + #define atspre_array_qsort qsort + #define atspre_array_bsearch bsearch diff --git a/pkgs/by-name/at/ats2/package.nix b/pkgs/by-name/at/ats2/package.nix index ea804a173894..4f1e7287ec16 100644 --- a/pkgs/by-name/at/ats2/package.nix +++ b/pkgs/by-name/at/ats2/package.nix @@ -49,6 +49,10 @@ stdenv.mkDerivation rec { sed -i 's/gcc/clang/g' utils/*/DATS/atscc_util.dats ''; + patches = [ + ./fix-build-glibc-2.44.patch + ]; + buildInputs = [ gmp ]; # Disable parallel build, errors: diff --git a/pkgs/by-name/au/autokbisw/package.nix b/pkgs/by-name/au/autokbisw/package.nix index 76b601b2ae24..d60467d568a9 100644 --- a/pkgs/by-name/au/autokbisw/package.nix +++ b/pkgs/by-name/au/autokbisw/package.nix @@ -1,8 +1,8 @@ { fetchFromGitHub, lib, + stdenv, swift, - swiftPackages, swiftpm, swiftpm2nix, }: @@ -10,7 +10,7 @@ let # Nix dir generated by running `swiftpm2nix` in the upstream project generated = swiftpm2nix.helpers ./nix; in -swiftPackages.stdenv.mkDerivation rec { +stdenv.mkDerivation rec { pname = "autokbisw"; version = "2.0.1"; src = fetchFromGitHub { diff --git a/pkgs/by-name/aw/aws-cdk-cli/package.nix b/pkgs/by-name/aw/aws-cdk-cli/package.nix index 7541c1d6a2ea..1665cea03159 100644 --- a/pkgs/by-name/aw/aws-cdk-cli/package.nix +++ b/pkgs/by-name/aw/aws-cdk-cli/package.nix @@ -50,7 +50,6 @@ stdenv.mkDerivation (finalAttrs: { NX_VERBOSE_LOGGING = "true"; # Needed to properly embed version info CODEBUILD_RESOLVED_SOURCE_VERSION = finalAttrs.version; - YARN_LOCKFILE_VERSION_OVERRIDE = "8"; }; # Regular "build" is very heavy and does things we don't need. @@ -64,13 +63,6 @@ stdenv.mkDerivation (finalAttrs: { in '' echo '${cliVersionJson}' > packages/@aws-cdk/cloud-assembly-schema/cli-version.json - cat >> .yarnrc.yml <<'EOF' - approvedGitRepositories: - - "**" - enableScripts: true - enableNetwork: false - enableHardenedMode: false - EOF ''; preBuild = '' diff --git a/pkgs/by-name/az/azurite/package.nix b/pkgs/by-name/az/azurite/package.nix index a46a7c0b8f64..7bd89abea9c8 100644 --- a/pkgs/by-name/az/azurite/package.nix +++ b/pkgs/by-name/az/azurite/package.nix @@ -11,16 +11,16 @@ buildNpmPackage (finalAttrs: { pname = "azurite"; - version = "3.35.0"; + version = "3.37.0"; src = fetchFromGitHub { owner = "Azure"; repo = "Azurite"; rev = "v${finalAttrs.version}"; - hash = "sha256-sVYiHQJ3nR5vM+oPAHzr/MjuNBMY14afqCHpw32WCiQ="; + hash = "sha256-gqWwUpUKaMzc9TiIhgubak+NQCX9dvqLQDg6Eysaw14="; }; - npmDepsHash = "sha256-UBHjb65Ud7IANsR30DokbI/16+dVjDEtfhqRPAQhGUw="; + npmDepsHash = "sha256-ZgYGURSFc/4xx6QqJA5wMFzbWSaAH39ztcfBEqCfmVg="; nativeBuildInputs = [ pkg-config diff --git a/pkgs/by-name/bc/bcachefs-tools/package.nix b/pkgs/by-name/bc/bcachefs-tools/package.nix index 343033d99541..437784edbb35 100644 --- a/pkgs/by-name/bc/bcachefs-tools/package.nix +++ b/pkgs/by-name/bc/bcachefs-tools/package.nix @@ -106,12 +106,6 @@ stdenv.mkDerivation (finalAttrs: { PKG_CONFIG_SYSTEMD_SYSTEMDSYSTEMGENERATORDIR = "${placeholder "out"}/lib/systemd/system-generators"; }; - # Workaround for RISCV cross-compilation issue - # https://github.com/koverstreet/bcachefs-tools/issues/850 - preBuild = lib.optionalString stdenv.hostPlatform.isRiscV '' - export BINDGEN_EXTRA_CLANG_ARGS="$BINDGEN_EXTRA_CLANG_ARGS --target=riscv64-unknown-linux-gnu -march=rv64gc" - ''; - # FIXME: Try enabling this once the default linux kernel is at least 6.7 doCheck = false; # needs bcachefs module loaded on builder diff --git a/pkgs/by-name/be/beanstalkd/package.nix b/pkgs/by-name/be/beanstalkd/package.nix index bca64619cf03..45228640a9ee 100644 --- a/pkgs/by-name/be/beanstalkd/package.nix +++ b/pkgs/by-name/be/beanstalkd/package.nix @@ -28,6 +28,9 @@ stdenv.mkDerivation (finalAttrs: { hardeningDisable = [ "fortify" ]; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + makeFlags = [ "PREFIX=${placeholder "out"}" ]; nativeBuildInputs = [ installShellFiles ]; diff --git a/pkgs/by-name/be/bees/package.nix b/pkgs/by-name/be/bees/package.nix index c29b5c0545fa..88c237730baf 100644 --- a/pkgs/by-name/be/bees/package.nix +++ b/pkgs/by-name/be/bees/package.nix @@ -3,6 +3,7 @@ fetchFromGitHub, makeWrapper, nixosTests, + fetchpatch, stdenv, # Build inputs @@ -25,6 +26,14 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-qaiRWRd9+ElJ40QGOS3AxT2NvF3phQCyPnVz6RfTt8c="; }; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/Zygo/bees/commit/14c82dce8a7e9714d6f9cd03229e0fb55460aa25.patch"; + hash = "sha256-bAYacaS3u01XdlM/8+baD+sMuCOyYDtSis4NvTkx8jk="; + }) + ]; + buildInputs = [ btrfs-progs # for btrfs/ioctl.h util-linux # for uuid.h diff --git a/pkgs/by-name/bi/bitfocus-companion/missing-hashes.json b/pkgs/by-name/bi/bitfocus-companion/missing-hashes.json index 0b9886723171..93c04cebef0a 100644 --- a/pkgs/by-name/bi/bitfocus-companion/missing-hashes.json +++ b/pkgs/by-name/bi/bitfocus-companion/missing-hashes.json @@ -1,41 +1,91 @@ { - "@esbuild/aix-ppc64@npm:0.27.4": "ba2c14b9cd901d9e7ea99b7de8ac259b146bf978c69866328d1765f277b11105cd16ed4df82107593b5c9b667bba5fbcde73cb7a9f511d98caca9e26778f64a5", - "@esbuild/android-arm64@npm:0.27.4": "d5a06758f91f0cf795d3a77198fc26fefbd78c3ddfce682df8d8ddb96b31ee65549ead1f6040a496dad2a1fc0fa345fab90692eff3410663bd0f39ed670ac727", - "@esbuild/android-arm@npm:0.27.4": "faeac957ba9eaff1c79871151dea2101d03691cb3772ffd5b4475551f54bf7962e1313346b6c06527e5dce09c63391b6b987b06070a544c4b8aaf91652ffbb84", - "@esbuild/android-x64@npm:0.27.4": "7e294ba0331704c4c455763a7132efff4484066b1a522d64c3068c9017749b9b2c59dbb04bfa6491d78fb65da826109af0ea6a7517b06c8a7d7a64e706390e59", - "@esbuild/darwin-arm64@npm:0.27.4": "57f495c8302bfb58852915195e3066166239de00ea84f91f4cc84b7f46dcd126bdbef0ceb22581e643d0c3a2ca34936dd72a96b40291362c2716d3edb6e051ee", - "@esbuild/darwin-x64@npm:0.27.4": "8b0af048b1b03a2145484fa02283b5c0c9b528fb857d510d9a02150854a2df3a08ee93a4ed269b7e1da54c9009273dac2ce75a419c32fd2f516550bfc534fe11", - "@esbuild/freebsd-arm64@npm:0.27.4": "67a551695f67acdbe7ada9dfa0d97d30ba9065cf79fa96d4e8b75c892200ea25ad8187fb108811b0af1e1ba559fb2b7d4ec572a002916bed70bca654e2888c14", - "@esbuild/freebsd-x64@npm:0.27.4": "a3b0ce4ce0f6e3614b49fded87a7c5989e34a4b81876450650f372cb119d835e627c325039c9ec93cb5fbb098a14dd0e8cfda8a24e8be670ec7900a27e9b90f3", - "@esbuild/linux-arm64@npm:0.27.4": "f3467a2e4f7db00b73df8e074d6c4d7b685d90965d7db8bf1a041460027b61cd9e9f258cca66dc26e0a1b5d8cb84263cd7bec81d7513e27f0ea9dc86253e69da", - "@esbuild/linux-arm@npm:0.27.4": "b30c834aca19a68de625214e912e3e5e2b040a32c82acba0c66a70af741b43f5a02ab07fd1e2f42f2bd7d336e0cf25333993dd070e23c70ea6470170a3ad90a1", - "@esbuild/linux-ia32@npm:0.27.4": "51d5d31a222490225f78802cda61d4ba618a3b5b35f3ea57675725f2cf7af32740c8be078fd5bb42952719b81de4e5b692ea1961d0618d827cbd5bc3b8298a94", - "@esbuild/linux-loong64@npm:0.27.4": "225d208ce874ec7bac4b9028933872aacc1b3d7be886f90741efa1cdf853ad51a064c176bd76ff24f0ce1b21946865b72c69a68bbabdf0653873d0f95398a4c8", - "@esbuild/linux-mips64el@npm:0.27.4": "ca438a7ada46810bc1b24ebfcccf0e2c2cc3098e0690b6d2f4dd031bf33160fb5dde07d5644d5a60bdf3768d89667da7c0df30debee684efc47f0ed5b876c6da", - "@esbuild/linux-ppc64@npm:0.27.4": "da0bb5332234921f746da98765b9a20421a5334bbca2abf8fa0f149929a94c5e1a42319b62aaf9711918d42bc0e397e7dbdbda7389ff64c63f843d451378eb0c", - "@esbuild/linux-riscv64@npm:0.27.4": "b6942603508353c956f804e8c037d9d7092b7885f78c88882753e21e978f5aace82c0aaa42a4100edf2fce3be76ce582ff4e550a7a87079446a4b6228918100c", - "@esbuild/linux-s390x@npm:0.27.4": "719d52323400ce16ee69314886ca17a97d7ed6a9886387b7e4e70fae7133721eecb65a44b521d79d9b6a4f9a3c5fd78bfe65a3b0c5315f11e68847d012344d97", - "@esbuild/linux-x64@npm:0.27.4": "2281d03477bd82fecd14fbbe2c6ee385bc196fef87a2dee9be9eae69429af9972b53f869741db3fdfd404d936f38f3aaf237194f506f8113b79aa9978c26ffba", - "@esbuild/netbsd-arm64@npm:0.27.4": "ca68d9ba6054eb15e7de67283073a82b6492871bec6d9b67cee0785c6d4b9a3391f7c286dfe093206a659a05bf27dc2b58c1e730c0d7ddcb997b7643684cd734", - "@esbuild/netbsd-x64@npm:0.27.4": "9ca4d720a2b681d1a01b50005bd00eb6ac182055585adc845fee4312ff87c55a678d19bbcbaad9f4211e9d409c7d03121748524978aa5404143e375e22d2f900", - "@esbuild/openbsd-arm64@npm:0.27.4": "1459bc44aabc838255cae80e33b32eb22fd375d924ca3eed9e0987e33a1ddae6e59ac61e529564ed9ab7ce9ad108db0f9eb4c5558eb8bc63b952d4ff3692f4a6", - "@esbuild/openbsd-x64@npm:0.27.4": "809917a83bb809d51d11d59ebc1bf9f44b6a94fb1f82bd5d52ac642a7dfaf55c90a71351d263d2c164b2d38700aa0dca69afec4840f929ce56daf90a696eadc9", - "@esbuild/openharmony-arm64@npm:0.27.4": "0f9f7dd181d505e0bedae25a73ac26ad9acd099f7b7c49e2ecf12998b59e49c64331616f22cba6b0da9bd7ea6f5b7fc59f7860014dda5e6673d25661042f4237", - "@esbuild/sunos-x64@npm:0.27.4": "16c38ba94b9b2ed6a2ce17e6b5071459f24e7f1df51e4b6555de7310ff1696743089462585c8c49103ea468b8b1b4ee47913d759c5b44b45c15963795c731150", - "@esbuild/win32-arm64@npm:0.27.4": "6e7361fc9a6d12896443f5b59897e5539d642514b9ba440a2d245f84d82b4589744905b6144d6d345a25cb5b1d80dcbc8a87109f4c9d9e88533919587d76c8bf", - "@esbuild/win32-ia32@npm:0.27.4": "36b0fdfeed7263f87a86c93a47d45c07b5e5502dd31c4a3244f058a0ccfa08c206c8d450eac1cc1e0ab98dc1edeb601b60d3b673cec28015d4ed2fd3a0592da5", - "@esbuild/win32-x64@npm:0.27.4": "70e6d04df925717d37f64cf9945a2ce9d5265169df6a9f5d75e60079023d8f0de7ca9f6ac8826a947c313116990562fc6f92c635f0a185bdb6d02e94e967fe77", - "@napi-rs/canvas-android-arm64@npm:0.1.97": "e36688d7201e7c2f60e3e1691aa4be52059a57d1a076b0fd922ebcb032665d0cfa522f17686d6fa619ab948f22ddf5c454b2695263edad66c0684f22373f22ef", - "@napi-rs/canvas-darwin-arm64@npm:0.1.97": "ec8ff5246e437209e4d2c6ef3cfcacba95cb1f73e1f54734ea3df26cd861761d724342072367b68e377ea5780646384a420f5654711b5afe97704bfde1dc7439", - "@napi-rs/canvas-darwin-x64@npm:0.1.97": "706510e1bbdb5d0d7cd90477714326f420788f6869bdbbf009e46061d23abb043d655ea64d71d6f1332c7fd267acf7250119d2356760743d6243ad0ed08e18fc", - "@napi-rs/canvas-linux-arm-gnueabihf@npm:0.1.97": "f0615e165f53f67aae5eb109763376647c80870d696e3d50a85396816e909088ec4f5a3d5c200a2d87514fb870700362f334034c2e629d1dd377c91f8d566f8a", - "@napi-rs/canvas-linux-arm64-gnu@npm:0.1.97": "972083576ede6a0bbd7698775cfa954bc109ca863cda19dc29b4c7b479ca3d6a8e6e3ff3c2fd25f4b9d5ac140885a469a5f99e9c5fe8ccb8d2f714360cb0522f", - "@napi-rs/canvas-linux-arm64-musl@npm:0.1.97": "ed6f85095031d58d649d094bd4de9d61b81bc33df753711eca284e2f01778eb9a0ffe9259a18e7e3245862ac6299425099a85823322caf691436a60c63396d3e", - "@napi-rs/canvas-linux-riscv64-gnu@npm:0.1.97": "cbe5940f9f0cbf88161aedef662791475b0d7abc43a6c0698a6e35ebc8c0d74630cabc491b484ffcd83f5bc3abea07876b781ca93d369d13acc277f1f5de379b", - "@napi-rs/canvas-linux-x64-gnu@npm:0.1.97": "a3484db20c9db146b16a17697e99929611edd973222ab6afff45f8d76bd56551942d9cf250e11206d9a708cfc14958a93941531eb63ed6a95b4925ae1902bff4", - "@napi-rs/canvas-linux-x64-musl@npm:0.1.97": "2ea96191a243930371271cc34d3ad53d12bc19718e6eeadd5f98e64e6a9c6cb682fc9cc76eacda8daf7a197d7edde56aa3a8171abfd1b47d2dbc358edac21b3f", - "@napi-rs/canvas-win32-arm64-msvc@npm:0.1.97": "67bf5d16e364ac882d3a626c426fb5a46147809ee78e4184839e2b600b72668a5c45143d79e712ae3c6662e54a9c9b2b4f36b03482086f5ac46c25c84dad8771", - "@napi-rs/canvas-win32-x64-msvc@npm:0.1.97": "3435d19347f23ec93eed8adecfbca6c14db368e916298edf1adbe80dfdd9e7679effe3f64ec9ad8c4f683b56528328508fa6e1fad46230c5ce96f2db704cf5c2", + "@esbuild/aix-ppc64@npm:0.28.1": "9b01eaa9c57542436436de762466b9a348b4596aa53dffa6e7034e4180691e1948d33fe34ec302239ab04c280e5166248880f24531011ff419fbec6986a265f3", + "@esbuild/android-arm64@npm:0.28.1": "7c977c8d4cea5126df4b298d5c31c3df8d14aa05d7477aa11c4147ec7baff17d25542234eea0134f279191b59cb1af18fee49c6916afda554484464129e4f9c3", + "@esbuild/android-arm@npm:0.28.1": "44baed9765216202f71b6aae8d9ddb930efa671d34f63f4220d980662b3df4da7972e965c0a0f12922147aa8428083686f6cb23cd9a4f140eaf922ae0b59c2a0", + "@esbuild/android-x64@npm:0.28.1": "1b8183640bef23f41a91598d898a04a6a8e3ca31d0100207c7e75928ee885878c04e3bcf31f27ed9c655d6d8a7c08e35e3afef035aee649488cb2d68e51abf1e", + "@esbuild/darwin-arm64@npm:0.28.1": "8ed80a99836df196c2b7996448eabb2d503ec8c71d0a8be59af4eed457b858fa5fd9292528b1967f0e106d2a045387e375207a2cc262cd45f89596681e94e7fd", + "@esbuild/darwin-x64@npm:0.28.1": "952b23f33c24aea13f5a78fd41731e06e8c7fa732e10995327fa1289115da6b4123899ca0cdb0cf0a56add29efcb9f7891ad6fda0bfb94541347275537a71e77", + "@esbuild/freebsd-arm64@npm:0.28.1": "cc2c4f1f13230607807c3f128680d789e85d4b93309501c4f8d84ed0674f4a2a3e60e279e3b997ee9f797047c1c5b906b25e4fe37de62d19634e4470bcb16f32", + "@esbuild/freebsd-x64@npm:0.28.1": "5b99b980599567ee931520a019beaeea4c7ae2874d0bfab79ee4bd6373a869251d2175946478c527490ce155d10a5bcc795e8c986dceb4a36fb6e813513fc54c", + "@esbuild/linux-arm64@npm:0.28.1": "9348c6bfc2d878e6213cffe482d4455d817b9e56b3c581a9f68b94aac720cddea5733d963dec57ca273039f3a7ca1714f1ac8e39e2e0f85f1af42f5d05e3ed00", + "@esbuild/linux-arm@npm:0.28.1": "654d7af59b4be40f585455e42ecb389657c6f11b1f2be2d5ab04caeac0514574d8b2a28b9f0f9805d92e266a44a5627c5acc8151b0d0379f75ac1490fecc013d", + "@esbuild/linux-ia32@npm:0.28.1": "cce27fbd8d74f34bb5507a5db8c0119aa377c7a070fd0be3881a8efddcdb8adeebe24dc97d55784d74a8bf4a60fb55b48899f41b5e931acaa3eb9f90ecc94a01", + "@esbuild/linux-loong64@npm:0.28.1": "47c3215d378f5da750300694b273b83db26d3e9ed36553696a1769da6d467e7557e289b46d211c93ab7a2978348b7415b66c7fec31658622f5bd356332b9d5b0", + "@esbuild/linux-mips64el@npm:0.28.1": "166d8888e731bdeba0c657382d429c0a979af2136100ee2491ec47b2e2ec55f6924fe2045880b48a6cdaeb3dcc44fc495f3f4b9a5aa3bb8c418d1f53f86b2ba1", + "@esbuild/linux-ppc64@npm:0.28.1": "a8eecb9e43a26dcb70a9805e685dec9f0caff0a8bac691b06a6db7c14ba0a69980ef0c01cb3fc1377ad63e2c4945f396fbbeaf008588bb232e9c0c37dcdb557b", + "@esbuild/linux-riscv64@npm:0.28.1": "cfde883f336e1811fee019a1df402000c7a8e6dc5a2b3577679fd0d9711d1a774c1faa194cc8954b18ca11f3a380ef32905ea90c241803831b61017d8a667c3b", + "@esbuild/linux-s390x@npm:0.28.1": "ea121d2fb6c8f6161312e0239258b584c431b4d23f320ace7cbc18da77034aac5ed383658d2a48fdfa32e38be07126a14aa26802b8e04d0e958e82646fb87f41", + "@esbuild/linux-x64@npm:0.28.1": "9b5458cf012247e31c6bf465e37553f2fc5aef3fccc6593bb30fee0c547958f9f00fbedd44e5bc076cf68d6791a4af2ce8714260fe341cb16843a78643773e3d", + "@esbuild/netbsd-arm64@npm:0.28.1": "86b5cf33fbad27ea5e7345601e711a26717bdf5ad119efa0b1bb9ad6a75f7cb2658c57ffb80f19491e3c7105f4698e76358ee2b6d57f48c9a230de9f588589c7", + "@esbuild/netbsd-x64@npm:0.28.1": "ff24c209715f7f122c711d3c51af099de27659837d3f7bd4cbea9a8868fa99a10b7af785058d18a1e32b2132989d1d1d82b8768df77ff25ab6cf19d58be3697d", + "@esbuild/openbsd-arm64@npm:0.28.1": "fe6590621116132baa0a2b9c2dc95c6342f146170ec1ffb343c29936580c369a69061676bef4e654ee27bad6491f531af3ba985aed7133eb16b758fffae6a445", + "@esbuild/openbsd-x64@npm:0.28.1": "2600c51c394945654f99b096fccba95e1d34fa3ecf4e78f40a7aee4573bf21dd955c274e0586768e9ebef3bff145ffe30231f1cb281ef5e679f7aa78dcc86687", + "@esbuild/openharmony-arm64@npm:0.28.1": "be9e1d1e4af478778ce847e28809fba0b754340a699e37ec03bc1a3cd4e84e4fde30ffea62099757877229b024d50331efd6270580492aa6be38eb2353ef5646", + "@esbuild/sunos-x64@npm:0.28.1": "349b9c7d879496456b2eb28f7bb3decc12a906007bb7fb24cb2b269f6b3e5138af109045b216bd0396762e63b802f0233408cc3dce802be5fcf242d4835b6bc8", + "@esbuild/win32-arm64@npm:0.28.1": "551ada5396e1f10e3d3592dd60a148a7257af1ab2317bba09e9ed18a6d7ee7e5961c68eb1fbaee4e8c1961b504807493e1b8f5c700dd1fb990f0cb36b240ad57", + "@esbuild/win32-ia32@npm:0.28.1": "2676ace6b4d63721da34873974152e869aed9fc8bd9fdff4b8df14a3a3e68b78a9b4566e643b90b948b4e85773cbf288a33a59d13979caaadd43b5adad68312c", + "@esbuild/win32-x64@npm:0.28.1": "8d658b74ed9b7494b3799093551d4c928a7916865ed42d00a135156cbd08612b53072e9e424f0687c10a93a444d30d6b0294b6a1d5fdba78078d706646ba558f", + "@napi-rs/canvas-android-arm64@npm:1.0.1": "1cc67a6e714b9e6cb194709b04a3994ec70679734608244b56aaf2cdd08a451cfc489957ffbaae6d11df2a3ffa9783d27704e14f479720b8ca0002d152f11098", + "@napi-rs/canvas-darwin-arm64@npm:1.0.1": "670bb1e83207a3b100f21c9e46a9539a8c7435264aa83faa7db47697dcefc52ae3c890a3f3f3df4f0e48ae2a0a684ab2e150a917977fa5291e7909bda485dc6e", + "@napi-rs/canvas-darwin-x64@npm:1.0.1": "ad09f3cd6a77b2fce80797ed25dd234906a523d7b7eb3e1a7f282b2d2a5778b2524166a9fb3964211869acb7bdf0bac664f9fb23e3e5301e37f7dc3eee445943", + "@napi-rs/canvas-linux-arm-gnueabihf@npm:1.0.1": "a204cc876f337011d1f04fdb7030af306c52612d8ed62e9fa2d9355f862de52fe56585c08a409b08e8d117200170c368cc6c9a60771f3763532c0ee900ec8e8f", + "@napi-rs/canvas-linux-arm64-gnu@npm:1.0.1": "84847d67398ba2a03b6eb77a3d71fa5ca17a0155483fbd8662a2fed106e3a5cfa7724149b571cc324beea3ebedfe1a5ba74c92254e2db1944c312750e9597349", + "@napi-rs/canvas-linux-arm64-musl@npm:1.0.1": "0f952496e5b22698580182862784ad4ab6afea1822a0398eea66e659f1c548e669a1fc9d805c9bc2e8e784d2ac1e8ca1fddf1584a0abc5abad9a017d5c2213f2", + "@napi-rs/canvas-linux-riscv64-gnu@npm:1.0.1": "2a10b4a1fc89e6dfa152f70de041e5c81ed4f7129ec5ab8ec54d155652540ffde5468b3b536f451c439e1b3b07c77bb3609c486cc9ad4a164267c781cad13a53", + "@napi-rs/canvas-linux-x64-gnu@npm:1.0.1": "41a577d9024e6c01fd47eb44f35514a558d63ce8f71384ad237857613911d667cd22caa3bea8ff470de771987cc293acf2433a5758307dfcfecafb4d2d1598ab", + "@napi-rs/canvas-linux-x64-musl@npm:1.0.1": "2c46a2475e59718f1562639bba501cef507cfbfbbeb15aa92dc5ca9839df781d698d152e3d5e56b258343aff03403b18d984e49a27f48df24013258f9ac9b554", + "@napi-rs/canvas-win32-arm64-msvc@npm:1.0.1": "8ef07e51204c8fb38b5bcd2e94f3dcb731b4456a8a56b3fb4eae3f7c92cc7020e1a7b94b0e566d6432783050d8a1737d40dfb37b06863d5064fdf1519aa11d15", + "@napi-rs/canvas-win32-x64-msvc@npm:1.0.1": "ee22f54b18f16ee09711b63ef67f2d2c6302574ea0140181664d1efcf508875d69c0d8948c2e5be0cc6078bd6f5781e0cb85c1af81e7443251a2983f7f030acd", + "@node-usb/usb-darwin-arm64@npm:3.0.1": "a47f20202b48f309a91aa726b0e5a8ccb3d19d8615988cc90b4e3ef3557f5bceb3da98a8495c6a59d22cd486db2faf78cec69cffc4d6285ac239392ed8be07d5", + "@node-usb/usb-darwin-x64@npm:3.0.1": "a6f0010a97bb3756956b2a14234350fe06cfea03feb087bffe0d9bb5f5b571e3ebe93c6ce0ad4a486bb4d0bb880eabf6fa50f1bc2d273f16e4811905b70e3313", + "@node-usb/usb-linux-arm-gnueabihf@npm:3.0.1": "3caf6677834fae131ed1566aab62eba1da1f9d12da17fb789bf48c142b5ab5fde7eb8fceef59a8b1543a73846bb8bf368a4029ca8bbf9b1c35d30e93cde3ccc8", + "@node-usb/usb-linux-arm64-gnu@npm:3.0.1": "194dbc3d0e594c023efee4c060c61d2523d96e686f74181f06df9747b9b6dd31daa2a757dc0bfa26ea819f68ab10edcd64e12faf052ead2af31ace1e1494a94d", + "@node-usb/usb-linux-arm64-musl@npm:3.0.1": "1bf85e9d653f3418f66e06d7df9da879fa8dc10ef11a1eedac66116d8f9eb459f59e83d033471886a556ea35805bb4bda07070b698d6fdbbb817929e8acd78a6", + "@node-usb/usb-linux-x64-gnu@npm:3.0.1": "0c2e117a42697717fa2c7a72865aabeb148a5c3f2b29d9b06d614282f3da2a536afef0151ea5fe6e826de3f4af4f0be745b30fbc614a82dc2a54ad5a087b14eb", + "@node-usb/usb-linux-x64-musl@npm:3.0.1": "fc8d8ca0efb54b88020ae9fba342f76ee6b5be4faa0ff4bf95b85f35ebaa3a7a52cbf98b9c432c18145a5a199c2a276793308276eb76c6177ba7bbe13545904a", + "@node-usb/usb-win32-arm64-msvc@npm:3.0.1": "0f793ce63cb210b8afe545acb61056941023694ab28c6f98a1153b7f82199efcabecfba5fbc5312e431f7473ef49ee0a2c32ef3e210edbda7e86503cd62f146a", + "@node-usb/usb-win32-ia32-msvc@npm:3.0.1": "2d8aae1e5694e046dfa2bbdcf18265c7b3ede1c17b71b1120efd7c43be30c187133289c6e2495d39c04ac5eb0cb37d8954339eea177024a8cd87ae2cff5557a1", + "@node-usb/usb-win32-x64-msvc@npm:3.0.1": "d3b0ec8570dcccc0e47eb5633bd8bad6276a98134fa1f1d87cfb35f66fb3a9cccbb54efad0842e8f1491d5d40b0620358ba87d247bcbdbdb4307db3d3a41168d", + "@oxc-parser/binding-android-arm-eabi@npm:0.127.0": "945e01f64f415992639081a3dc19aa5919f45e69c38298e20cda23c1e8bba26f79bad55e6dd6190a43866f363dd275970b71843ecf8a51a360cc8768f5900da0", + "@oxc-parser/binding-android-arm64@npm:0.127.0": "f28a90adca64bdabb7e5991941ace223559acaf5ec134fc6fd4f983979a660eafe97b1b03139c6608640e3b37d5a0225684fb49efc38b97486acaac2ebf9f3ef", + "@oxc-parser/binding-darwin-arm64@npm:0.127.0": "490d39689bb179a1f21b6e2230fe877fe6d62520e84d5a673f4d7c704c9a95bf63826bce15208ebacba172bdef0d5fd189b87eb5556de1b9fbf12944be183c8a", + "@oxc-parser/binding-darwin-x64@npm:0.127.0": "8e1ad7af46356aca1d43627e94c9a72d35328a5f66dc184a33bc3e28a086f4ad2b70bd44f097eff6a6b52ab94bafe0e15de396f6eed01d0beee7bd1a45e98541", + "@oxc-parser/binding-freebsd-x64@npm:0.127.0": "7eabf352fd03452bb8f853c7d92581705ddc207a31797b2649f364715b5818d3fb86512bca5a1dd6b3092f0690303f92c240d6ca1738b7a5e27992c08f648cfb", + "@oxc-parser/binding-linux-arm-gnueabihf@npm:0.127.0": "98edb854fd3c30e489237fec6cda7c1e46f0961d1b738369fec357b694989d95ff5ca20b576c835b7af7084ff703888751c877d46862e5745ccaf9e6ac226a0d", + "@oxc-parser/binding-linux-arm-musleabihf@npm:0.127.0": "d4a19c2d8f943c341e452e7ba8adf844998f87ed4ab501b473a05719fca52282bd133973f26e07fee28812963d39cd199702faf424a42300d4e317149079e84d", + "@oxc-parser/binding-linux-arm64-gnu@npm:0.127.0": "d818144ea9a661d54474001e750a501cb5e12460e22d4fb3f1c46506282ee9689a682761e07f4b925d2349fcee2734fa50b6655ca7f519c4ad9a055b0c4dac89", + "@oxc-parser/binding-linux-arm64-musl@npm:0.127.0": "f62825639af42d6be5e4c7a16576f1e23f4386b7db222dec59e320c0c2ccfdcb6efe45903a2969024f14c15f173b174d969473af9a0773cf25c07fdd3bfa4e31", + "@oxc-parser/binding-linux-ppc64-gnu@npm:0.127.0": "e635b0adb9e26bfce5209a87f2b55137ccb1e0d95208e1fd36bc1f0735fc3df95f8a99e11ad9d9ae621031ce21dffe583aa01c40080a9f57b466945306878e83", + "@oxc-parser/binding-linux-riscv64-gnu@npm:0.127.0": "bd16bb323eaf46ed519a583dba0a4b1a5984f65ba19d3773133476a7bec6985e6490efffcfd4d5f711c5acb7e201ffc5898b56ad7fa619cf884990514264bede", + "@oxc-parser/binding-linux-riscv64-musl@npm:0.127.0": "dc38d5b6c6ebe40c2f45ba59c1fa175f9bf148c274c41b0fea39311756e7390fbc25ad1f2399bbb9a2a12f1c2a8d4e284055a12042b6ec90b08d79e579afad33", + "@oxc-parser/binding-linux-s390x-gnu@npm:0.127.0": "a6e6f9c0de7b62087e3950a16b8c6f74b0995e0599a74eff0044b770dc1509e7f390c837f58ef349812036c2cec145cff5ff29800707123813688cbb632b3565", + "@oxc-parser/binding-linux-x64-gnu@npm:0.127.0": "2eea74fcd38d5c2cfdece401e9e8d2099f660266a2efd01603f85abd464aed1f28f77af8951655b2173bde8446da99a0657e7f531af93c941d6e2c851cef093f", + "@oxc-parser/binding-linux-x64-musl@npm:0.127.0": "e746466aaa1f7826130337d83e6b976736d780c59c12c43b5ca4710ad6a24439341e9d5aa58d705d6f6e0618296daf7f422f24e260b3e5c52f7cd0d916bd7ddb", + "@oxc-parser/binding-openharmony-arm64@npm:0.127.0": "5a00e6fcea62d4cfa3993e8d1f4a7f1bc2d70a80f8ac5bcff204eaf820124529194517e94937a3a6d0c28844cf713e7629c0a57cdddd87e0670c786c1890aa74", + "@oxc-parser/binding-wasm32-wasi@npm:0.127.0": "0679729f6bb75538acfda31258110ba0c7c60b195ebf8f0461c1f412fe8cf8a423c35eb107f184e67f3160c44efa32c705581a4014be050feac652a814eb9376", + "@oxc-parser/binding-win32-arm64-msvc@npm:0.127.0": "410ccb3fedde21efef8713198be39e7ba6526509d1328801b52c76e911af3412d1f214aea3609aa828bf30ec8a05e811c82e383da8e6cc3d670415cf17497db8", + "@oxc-parser/binding-win32-ia32-msvc@npm:0.127.0": "86b35f2feea4b23654bafe27b9bbe77194d4923f73f4254f813bcf14de5f12a09ce67e7fdb93b73944c9b859a0433128f3df2ef3fbc56f4c486e99d393508f0b", + "@oxc-parser/binding-win32-x64-msvc@npm:0.127.0": "6993c90d54ecfca7b5fd5a2a6f07909d53ce553b14e55dda739550e8dbc1a593c49f23792063cce95bf286bcae4f67624d0d9f014e28eaa700a31da185f2127b", + "@oxc-resolver/binding-android-arm-eabi@npm:11.19.1": "7fe35b00927acc6b1e9abd7cbf001cc4855f697b1a6604f245cf80ecb09628195d724545680b11ee58c462482247017e6d25d3b6074437ac61842ebb2200e925", + "@oxc-resolver/binding-android-arm64@npm:11.19.1": "2074f0f614aac0178d8c879f0a3897aebbe9cce66241bb8db8dd0400bf30db8a322fbcfb3dffd90e4a9f08eb52f32026155094c3515901f9e50f8c8115508bc2", + "@oxc-resolver/binding-darwin-arm64@npm:11.19.1": "43f0ebd467387f508dd13749b67a1b21b81902dfec7c7fdee24df1976942a78171e29e4ef09390dae88181dcdc4ccf08f43ade727c101572fff961b925f79834", + "@oxc-resolver/binding-darwin-x64@npm:11.19.1": "efad8b905d7cab94ddb749a7b486e7606d21a71ba3f2c8bb117e4a7648aa22499663c96819196e0f38830bb87885f147f517147f3117f805f908274086de01f9", + "@oxc-resolver/binding-freebsd-x64@npm:11.19.1": "750c57d8291f8ab8759f68f16b10aa5967879b7f6f432aed838d3e4b3ea25857c3f5dc1fd4677e79de890e79cc5bdf8bc845ab403bc7d9b7d7827c6af11404a3", + "@oxc-resolver/binding-linux-arm-gnueabihf@npm:11.19.1": "d1a71513000f2d7c300c45ac6b0900831e37759fd0df7c92a6cd2c66b87a724a303da7df94ed16fcbba72ccda45766923212c9711edd228b9f97dfa8da38e08a", + "@oxc-resolver/binding-linux-arm-musleabihf@npm:11.19.1": "4f1b757e8e86fbfdb7f8fd43e9684f3fe339e46606d836b509241c9217ae608397c5c4383b45ba9eabc3b6b4664842839037d41a9e49e726e4ef6e75d871904c", + "@oxc-resolver/binding-linux-arm64-gnu@npm:11.19.1": "6b1342772f5f347fe2a25582a8cd60f3814a7a6e4d2bc8e4a140355409df550858b961ce93932e3ce01fd440e7d4b2dd144978cd6372af325a6e2d85e496b4e8", + "@oxc-resolver/binding-linux-arm64-musl@npm:11.19.1": "40b99fcf1401d0f09a701572927bae4305a15705d2bb44003773ca5bb3ea8f28037e1e64fef5525eef314bd6ef348997b36cd521b4023053e0e0873b6700d52f", + "@oxc-resolver/binding-linux-ppc64-gnu@npm:11.19.1": "3581288514ce58eb79c927a03a43667e7e51b67b20be1f2c8343bce07f1fa848b9802f2d12990af73e8dae790d1ac6200611699c5350bd28a06abe3115a98002", + "@oxc-resolver/binding-linux-riscv64-gnu@npm:11.19.1": "1a8e43df91d8e7fec21c3cf816f20f98a0237b202e99d3768e1a9c49d9ddfbf0acea962991c4ae67dea936f3d2031d77bcacd3af615eecacf7828246be79becc", + "@oxc-resolver/binding-linux-riscv64-musl@npm:11.19.1": "a71fd4c5a13d7cb588d341318811d2728d64111878757988b15c2be3199d0e3f9dacb867ca990ec3cc38ff9eeaf9dfdee7aeb23738028031e6303903f0e501c4", + "@oxc-resolver/binding-linux-s390x-gnu@npm:11.19.1": "f4fc6a75967235ab88550b30891eb17a490e5bcfa8e9b2eaad33b3a4e7fd52ca60e6e0df3dbed5ab9bf4cab51bf05725e86e6d3172a46a1a95a928012a2d52bc", + "@oxc-resolver/binding-linux-x64-gnu@npm:11.19.1": "090f364639f4c6c021f345dc182c37c0d8370bc7b7ce5d93c546a49a3188d400a9c030106cba27a8c02dd7044384efc51187cee4f2e617109593e3c237a65509", + "@oxc-resolver/binding-linux-x64-musl@npm:11.19.1": "653779d9f6b78df664667e5f8693741727cd7c3e74831e0642a3ecd84fbfb36d302c1ae38a53cf33cc9516aef7d7f5ff66dacbb5f3701805baefc5785a5d7669", + "@oxc-resolver/binding-openharmony-arm64@npm:11.19.1": "4d88027b1ad55ab8b4820e8ee24c3a23b6ab6731c14da0da3c6b27394657bb54dd09d01085a64884e8f7219f719b48ea2221f0d7c8f10d2e7288c8a5e0b68287", + "@oxc-resolver/binding-wasm32-wasi@npm:11.19.1": "53be10977b68276a5e72be2a6b56361ff5548243aac269b93178a6058b0cf4dc14484a73ee5d0b68be1582982d96d434d97838515d1a9034a901080aef9d1b75", + "@oxc-resolver/binding-win32-arm64-msvc@npm:11.19.1": "f7671ed2e4f73d9f5ec386355fc9d93940c32bccdfbb7a7fb16bdc51e3cc42ed920cf9cd2f72d77c56e4a4a2c9357e53df3ae88b36106fcb363771e47f50e19e", + "@oxc-resolver/binding-win32-ia32-msvc@npm:11.19.1": "d60ccab0778023eb6977636c32d05c2369b54390aa8bdba4da1809323149548359bc546bccd9e5e717310c46e2a742ccd4dbc3f4750789aa97b5f9cef10ddcf7", + "@oxc-resolver/binding-win32-x64-msvc@npm:11.19.1": "bd84616bb214bd3f63531299f5576538f3f63411f95f1fb470fc8d7434c409fa1922bcbe535c4137673ceb3517e61b102e739a06b1963df600b717a954d22b16", "@parcel/watcher-android-arm64@npm:2.5.1": "f99d569e4f6cf78a1b0097fb9d4682cb201a74370ae440c531da4e1d5021e46141bfcdf8ef708b51a5b9cb1c30f78eea933ce75216d5eeb7b969a2ad27c68e4a", "@parcel/watcher-darwin-arm64@npm:2.5.1": "973c7ef3c94608da9cd1b20b18b9a7de2fb46fe44553731fe372b640de524491976150d0845f3d5953b74ed8ea469cb8d18a48651d0e5fb82f549a6b46b54f79", "@parcel/watcher-darwin-x64@npm:2.5.1": "848c5516aed9c36e14751200dbbf57e83c0bd46cdab0932df33db120e66b9596de18eeb98980e319efde84014f67d9e7924d7555383d8ffcefe35c501166b84b", @@ -49,46 +99,21 @@ "@parcel/watcher-win32-arm64@npm:2.5.1": "e015314d6b9b727cbe25eedf963ca8b23bf6d4e78d3c28008bd0d2657940ad54a271330486df3a93a5f1a30f2b8d052d14415b85cc7e7b747c6c73b5dc055628", "@parcel/watcher-win32-ia32@npm:2.5.1": "920b6ad6a2095aeb9c2d329c5118472a3c14669fa93eaa99aa8050c76c5c2d3d76d92677167ed748c2ac5487c568d5df16d5d94f4bc7c354094fccd8e0d6350c", "@parcel/watcher-win32-x64@npm:2.5.1": "8f1c8e41ec9f86e4dcd0d4db0a077742d5dcc853f15ea888387183e34e2efcff09fd1cc9ec46fc1121b9ad4ddc0e221283f2ffb23cfd7dbcbb8b03060b461963", - "@rolldown/binding-android-arm64@npm:1.0.0-rc.15": "0c78d6321d2dedc0c6ed4b5541328f6c04e8530a3c294b477cd9741e2af7c8377a51474f0171c85ecf63bff5c8bb31ee586f40f13fa265a869247ec3d6293204", - "@rolldown/binding-darwin-arm64@npm:1.0.0-rc.15": "598b8cb87d8ba8df4e880e0d6903f7f4f32b3e7b2804429cb3ccc47a69b8e7b852b2e3115a8c3a882d14979909f9464e8da55c2c52a52cb18a81df7e8a1aa654", - "@rolldown/binding-darwin-x64@npm:1.0.0-rc.15": "92fdfa58a8d9edaec4c1766c38c34f657715d2c8faec141590812d11ba6a6ce52530e55a6a2515fcd2ec6287e50187a458f06ca3c6813130cb9869a99c9f6f29", - "@rolldown/binding-freebsd-x64@npm:1.0.0-rc.15": "04e8288accf007c82e8bbe75af62d4ed570bddd7b25a178506fcf97daa0907cf6f85ea095be5826095242ac1a4923196059f53a9e8fdd0e3c34d9ed1c00d64ae", - "@rolldown/binding-linux-arm-gnueabihf@npm:1.0.0-rc.15": "4cd7452e4fe4433b730585bcbaf210efc50621bca5906204179ffe80748bea187398d4091dae64079f0c7ebfea1987f0b1c045ff60209ab0f60be9e04eccbef7", - "@rolldown/binding-linux-arm64-gnu@npm:1.0.0-rc.15": "fbddea791134b45a94aa5aea640a177d6feacd81a44f9ee3615da3daa824dc2a193ced6e8f2a0bb0676fca7b224525513b451cd8f78b379d7b1983fe6a0360ff", - "@rolldown/binding-linux-arm64-musl@npm:1.0.0-rc.15": "b325fa98753bf41100c5d95145f30ce92b5f69f6989973306344b1644fb21633454aa216f28355c74d0e7bd5885bb6d2c80d0f96dcc2b869ca7e63d8b22dbe91", - "@rolldown/binding-linux-ppc64-gnu@npm:1.0.0-rc.15": "0bff0d2724912079dcedfbc0a86dbad8e3e376d2d619cf36917964701b9ae5a39afa5ff49d3cb5b2c3e17437c559314cf8e17433ad3bfb4b64229d9c8bf1ebca", - "@rolldown/binding-linux-s390x-gnu@npm:1.0.0-rc.15": "6718fd91ead389f3bdefe22fd0344b490d3f9350697e4aa35a0fb55957aa1b127d26aaecf9bc2d49f1dfde62d9d4717cf5dfb7d93ce3b871372ef9c6cb7a1b1a", - "@rolldown/binding-linux-x64-gnu@npm:1.0.0-rc.15": "cb7628e1a7398ab5fd07dc79a38c73a27524d45adc989b5d906ea37e23b7692123d607d07fb9fda35485d6caba545ae41c561b9632aefa0bff76997208f83eae", - "@rolldown/binding-linux-x64-musl@npm:1.0.0-rc.15": "f59fb354b8cac55d123f6f3fe7bf8210402f97ed4be3f3a883c6c544ce1b825e36154f479d45f6e9f23c1fcd8861e9f3873dc24278631db871d263db3bea5580", - "@rolldown/binding-openharmony-arm64@npm:1.0.0-rc.15": "b6c220a48ace9c381d238dce2caaa8453da1d3fe9312bab7babf127a500bdec2bbe30bd381f9945af79c30fe9ca0185108b86ef311fc83ecb83ef24f7a587902", - "@rolldown/binding-wasm32-wasi@npm:1.0.0-rc.15": "9cd39e02ad5f43fc45901d074df10c0e3532d9077a6e334e431de60f90555c15e5445d1b5156c10df49d28839f9f15d5d808666bc8e70ab065bb9af3b8567e7a", - "@rolldown/binding-win32-arm64-msvc@npm:1.0.0-rc.15": "cfc32a72e8a3900f356b0b359520df3f18ac79379a273a4c53b00b1555123dcfd8204cf9976762664898b0c6c949c0edd4be850ae254d2e84a40fcb8352858eb", - "@rolldown/binding-win32-x64-msvc@npm:1.0.0-rc.15": "f0bd2876247f0834f135c1ae150b7d5626d54ff399b4a6193626dc46a0eca22374a43c64afdf3eff8e8e9cf1f20df826bcd9fd4219df3fece03972b8ae080e20", - "@rollup/rollup-android-arm-eabi@npm:4.60.0": "9a4292f59c64fadb8583a1cb20aa76ad07cb14213abcf705a25f21102f618d2c0c225caaa1730d77da3a472ba1660c987f709f364a60ceaf31199ecb2c7bd82e", - "@rollup/rollup-android-arm64@npm:4.60.0": "59f4cffa6b8245a3570479ac30834d18a63bc18d0eef706eec41800fa3256ccf3d5da1d9b0eecd360b8dff4df6c50adf7935b300e5443c72c2348f37307f828d", - "@rollup/rollup-darwin-arm64@npm:4.60.0": "5bdfee08ea0c0c49dd9877773c8a7361628b4274d7ae03925aa83e38dbda0f985d3bf128ee5bba99e50754034e109b8b3faddd47b776e503374fbebec6e98dd4", - "@rollup/rollup-darwin-x64@npm:4.60.0": "eb7bcb4655e1c31eca74ee96bc8c1de3ab3a511de3e5f433d59c14d4075ab6c32f6770722f5faded1cf8b6b64e3cf9378ac50b0722a928f972abb5e9e8b79096", - "@rollup/rollup-freebsd-arm64@npm:4.60.0": "510dc460350a81125c86db154c152af573e97fc77658924ddc126c98fae1b4e7e96274b1943d0c90f6246fc821aa0f90401f8982e18cdc06b5d0d62b0dd8791e", - "@rollup/rollup-freebsd-x64@npm:4.60.0": "5d8f2e66a1d62ddaec83fccce64a407e63174deb6fb4e492a8719c879f18e77baf2b1068b044f5fe0b67a41a80b72ac418f9aeb4baf5d9d9433c7701202d8a06", - "@rollup/rollup-linux-arm-gnueabihf@npm:4.60.0": "ab1f4fcc86f5d25867f84b00dc546f067f2a53ca631452407c03e70c341b554b03d2f77086533f55be20d36d9382a8ec339901bf789482c73dbe59d768adfdc8", - "@rollup/rollup-linux-arm-musleabihf@npm:4.60.0": "e08b56f8e3d7773e5b685100d22b4b0a8a562ea56524817528d214a6aff2319234da462e228d4842d04f5e1b711ceb77f4b041a4d2b69d446b959c1ce5cc603d", - "@rollup/rollup-linux-arm64-gnu@npm:4.60.0": "1cbf82bc9acca2ae204155d38c890faf88c4b02060b3ff4c96993379e48c08e6541aee3adf4e6a6dba986c0accc554eb21f9c23bbfb0257773e607a5d40eb6d1", - "@rollup/rollup-linux-arm64-musl@npm:4.60.0": "94fbd42c786baf0178adb6309c8d2c9fb5daa97cf2db8cd2cbcd88999c80b9de3089240e804f4287545eda3b509aaa67a41a8711ac5799f74261e11469d64dca", - "@rollup/rollup-linux-loong64-gnu@npm:4.60.0": "e840acd88f492be16732c7b365c680e03109702c7e6a33fdae04992abe333378180e713f9d536585348aac09e50dc11fad23d946df7338d13d95913010232bf9", - "@rollup/rollup-linux-loong64-musl@npm:4.60.0": "9775b8fbd12743f82230f4cb42f69c5fa2a96ca132a87d5a141115f8f879e96d37f8f9ee42fa5d9323a9c0e2ff7e5aba4e7ac99fab5aac044e0d47ed4e6dc2b4", - "@rollup/rollup-linux-ppc64-gnu@npm:4.60.0": "343870a783702e938933f8161c9a55abc5899cf52bc4bf44a97c0fe93ede9622f52488d56c33b67ccc18da1f3b369db984a6930d0a005de87221d8d997a827c7", - "@rollup/rollup-linux-ppc64-musl@npm:4.60.0": "3e8bcd82cc55f01a62e900877a56eb307824dc20edc22b0d51f3b21851f873f2da0dd146eaebf4423a7bf1d8ba377e58abf66194deb280d1fae54fb9de3b9d63", - "@rollup/rollup-linux-riscv64-gnu@npm:4.60.0": "3fdef46fa6ec90106db05d313048d970e86a80ed5ac6463b1f6060e1796a9f1c2287787ef47705032e0df704250046b271c9a52e691df727613421953bcb2bb8", - "@rollup/rollup-linux-riscv64-musl@npm:4.60.0": "50fe34aeb87c03f2c5a356884902242d4ddd3b0eec43b946c89ef1323dbab485a504638d024353f6b3aa7fdb1a4ddc979b8b034be22278ced4b0a9595d6ec7b6", - "@rollup/rollup-linux-s390x-gnu@npm:4.60.0": "af9d7f6f876af243960262868146f4f1ebaea0dbf9adeb14ea85b07c60df0e1d4241ddac1008509ee80ef47cac8b924f85099f7076f8c25e807cf87f048f435f", - "@rollup/rollup-linux-x64-gnu@npm:4.60.0": "3ce88bf8a93ab7f732139b3015249c5b8af5f0ceba8058e05f21c3e51144661be844b9a9ab20503b0f420579d930d37e55575dd544d303a0efcc09d979f537b8", - "@rollup/rollup-linux-x64-musl@npm:4.60.0": "893569365547e7fcea9fa83dc5f7824316ba959ee546606df70633576e6223fc5f33db3da89caf18815f2d671e87fd549886bbe7795facb68de9da941680c335", - "@rollup/rollup-openbsd-x64@npm:4.60.0": "ec522dccd3807237927afd6680ba7096041b477d4ebef6142e6a390fcc975fbd6d43d1a0d6e53cf8e97b6d90e528bb51a8ba1029383bbf086f5380fdf90ec6bd", - "@rollup/rollup-openharmony-arm64@npm:4.60.0": "aacd3b633618c1933f413e0ec2c588e75c3dd7830c34e2bc947915a307f97c570d08d103c5b4f30fd6b60a77dc6c81eb9ab4041205ba19414f55ed644a74f180", - "@rollup/rollup-win32-arm64-msvc@npm:4.60.0": "d8ecd24616112de473344717e07481081c0652f0a0d40dcc645ae2ac05e60fc962e2b0f86dcca7ab40b07625886050214403fd125e53297ba3003c877430f71a", - "@rollup/rollup-win32-ia32-msvc@npm:4.60.0": "0362713f7cfeb0b3deeedc11fabd551ec309cf21952735c2e2b76caf083331aef6701a11d2ad7a3824c439a9ff0d0c305aa12ef62f4f0a540eba2e952a18b00c", - "@rollup/rollup-win32-x64-gnu@npm:4.60.0": "1400b3aace00dc90638bfd39d68275bb5f16143d240b9c36eb70f242ed2080c26fe14192fd3375120308ff94a7da1e169a8e0e56efbe41483f59731602d3be84", - "@rollup/rollup-win32-x64-msvc@npm:4.60.0": "c948b3a8ed6e73f2382dc41ffab3e9928f95c4a0e3481272b26ad04a5f73084ca13fd5c253887f9077c37cb1c91bd8494b4a45a7764c874aa105684e8424289a", + "@rolldown/binding-android-arm64@npm:1.1.4": "d59f76669aaf18426811b5e35321cb5598e69bf57c1fe52c384ec157417c2cce95b34af5c41c085eb1098d92b3129ad3f5211df48efc759361ea8df5011efcbc", + "@rolldown/binding-darwin-arm64@npm:1.1.4": "0a1b74f273e25911b0110d289fe517f6273e39b5a08972231ccb74b76035d6229d51ca3a92eb1b0dc774e7377d373404d1c2736493271f576a266c0080a34206", + "@rolldown/binding-darwin-x64@npm:1.1.4": "736b7ee7d9ca8524466c329361c64929fcde7ca98ab99f279383b4e2e8df5824a1cce08bc5b6b0ff5c6753385bb4438b057c0afb7326b568d020848d950b2924", + "@rolldown/binding-freebsd-x64@npm:1.1.4": "d18f28b53889c03a99822f1666684533074329be5519ed79428d0f180d8748a21a1af00cb1de895a4a2e2c4981219d67ffbf894f37b5d45d287402644e4c6c3a", + "@rolldown/binding-linux-arm-gnueabihf@npm:1.1.4": "0229d25aafebcb76beb377ccfa2e4d55ff632563ad1ff8b061e71f5f98408924cd69c7b826265d957f8f392d77503d0acb7b297944915df44718a57ac83c7efb", + "@rolldown/binding-linux-arm64-gnu@npm:1.1.4": "0941dd2d18304ecb46cb08d8be7dfa22f34ed7a6c63632c6a274ff3035987fea4d672ade92d5a4ee5c31113ef66373978a3c9cab598c0b128ab1b2c9e5cee5e1", + "@rolldown/binding-linux-arm64-musl@npm:1.1.4": "a655f61bb3695a470deee665d3b1b6bf1d08e89b71d96e6362de6675dfa058352cb4ae360a4716aa1887cd97163b61411851780b84a2847ccf4cbdbf1dc36565", + "@rolldown/binding-linux-ppc64-gnu@npm:1.1.4": "7af64514357ba55256c6d2c62e1a2f0fc0a807f303353cd5b2703f64f04d1140f0edaa3eea9a94cfb120cb6e4c71a447c30041ecb86983e9a001455de5a1430d", + "@rolldown/binding-linux-s390x-gnu@npm:1.1.4": "abc61c30e8993fec98a17bba70398150b5b1a2a637e869ef767150906e43622ec2dd7cba4d5ec44f2f3aea193c95b75a9b67438e6cf2cb1f2b7e19569821fd80", + "@rolldown/binding-linux-x64-gnu@npm:1.1.4": "a7f99f45df86abb32d0d95023cae3e9923b47f04bad48e276355b9ceda9c9b9c0f70966557d48006bd0d673e7b4b622dd9af4ae3e605f2e7b717fc63f1c43878", + "@rolldown/binding-linux-x64-musl@npm:1.1.4": "1ac0921cfcd2ce3a5fbc70bb8bbc17e7a138a39413cce6a151a943be870d2c91b5679ad6a85ccadc383100f795f52d6fa47a47652a5c217a8bcb1302defddc91", + "@rolldown/binding-openharmony-arm64@npm:1.1.4": "f61e8562d59b91f4c238cfc815d5b43fa170f6a2795f0de6fd18425e155c8a75486f5a1ca53785bc81b4b9fc3b1967d7803b5be89fe50957e823746f6a35484e", + "@rolldown/binding-wasm32-wasi@npm:1.1.4": "e248421de5a5d30667deb15274101b73562e0ccb25de708eb7c1e463d825dfbf42e0a498f70093d8c22bf640d21f660c5d9e158001ecbb0e02c8c2be8db4009a", + "@rolldown/binding-win32-arm64-msvc@npm:1.1.4": "d2893af2319711c04eaab03e248d0f96b320942b7f843267b7d62d829eddd5c47808f0b2534fcce4c79db53da4d4cb57a7912f6ddc2e39ca72f09263d397d87a", + "@rolldown/binding-win32-x64-msvc@npm:1.1.4": "1566f653b56c576927cbe33d6c8aafccc82046ab04bfc6ac1907c58b48d902033610a6db23bfaa3376b2bdcbda1ef1c5c9437367b8bd3df4e247c9469e8beb1f", "@sentry/cli-darwin@npm:2.58.5": "8bb8a01ab9ba6862304d2efbb40a397cc52859665be38c238b75a3c82c0e6b795513a8e018c591da6b992e9531e8e485ba0ca46c60f2beca7690b0693ac5a771", "@sentry/cli-linux-arm64@npm:2.58.5": "1755aea6fe1808306fcc51e2d88f1c161118ea9f40d47f97570d121300da083fe405fb64b8fbbe753930c8ebaadb30da24c951e5e38ae5ed39bc97e02d712d73", "@sentry/cli-linux-arm@npm:2.58.5": "4fa8047b1bfa13969093ab25a643ae8b3e1f65fa3e1c6b2287efb1c6ca086b44e39ed8e7a5dfdac0d71efd7d985eaa12fa9034dfaa0b65e904d0ee082fca0e31", @@ -107,18 +132,38 @@ "@socketsecurity/socket-patch-win32-arm64@npm:2.0.0": "65418168f7f68cd2373000893d96251ea7ee8216a9730f0d51efe24402d67a5126f5255d6eb2d5ccfc4726e685a3ca17fcf7ed0b0d5feab631136902d5f959cc", "@socketsecurity/socket-patch-win32-ia32@npm:2.0.0": "b48b42604530d283c2e1230c5d7604fc5c87f97d0d50ca305a89ddc16c24eec6d833cba39a94fe4e6cc3bb85d3a5e1f47fe1013f1bcc0c0906563b823fc8405f", "@socketsecurity/socket-patch-win32-x64@npm:2.0.0": "8057bbfb19b4601bb1eb4af272fbab315af92c9b870731cdf8cfa7520bfe7b0e4b96c9ad6b1c1959490f97054bc64cc7e3c7dade054a46801b61ddb69e369253", - "@tailwindcss/oxide-android-arm64@npm:4.2.2": "11f6e9bd3c1eb998725a89210a74ec2253e7387e451fad4c9ac171d9299cfd4ca1ce24e687856ff7887a2fd60cfabb267f8bf77e392e3069b2ccb1d22007aac3", - "@tailwindcss/oxide-darwin-arm64@npm:4.2.2": "ddd2d7844ef9be81dfe043b393a4eb7d971d72c53eef241456c132f7c38d5acaf569311dd565d23a345484f0dcc16a3967eb3ed74ad08e672310919f1a0d8502", - "@tailwindcss/oxide-darwin-x64@npm:4.2.2": "29b54e88665e7cb6b08ec143336d56e7bc100f6c621a414ae1c96c5a913de43859d8b5fd197dc9b257c95530dc949d259d841f1b657cc7a037e74b61aee85de9", - "@tailwindcss/oxide-freebsd-x64@npm:4.2.2": "7e89193701c6239dd007eab2e48e4fca0b88337b50bdabd341bbab3660fdc5a151131ae28a24c5a9bb59ee491fd8acc4583018b93dd545e4889da28dc6a445f3", - "@tailwindcss/oxide-linux-arm-gnueabihf@npm:4.2.2": "6bc2f863e02da37c9ce2807ee2fe1f1d00f391d5608fd9092630faefc0902f3982917d9dfb6df38e6e2ae4e3e83d5587db02a178c78a4b896085f3dfe72fa931", - "@tailwindcss/oxide-linux-arm64-gnu@npm:4.2.2": "a8962da367468c8b28b4d0afec55e55dcff3c4c0f885b60ed4ad825b6f3b40c7c7350a646f72cfe502f247d5b3c4c0c1f03b56d96b3867c034e839379e91a78f", - "@tailwindcss/oxide-linux-arm64-musl@npm:4.2.2": "cbab9ca951ccf818c9ccdfa6a9450a18a022fe67ae86c75c30ad325fb2a3e0821362954dc76d188746d3d54cee93b0b1b286bdc3540d6e79a3d504aad8f135ce", - "@tailwindcss/oxide-linux-x64-gnu@npm:4.2.2": "0b6e47b461b9e1168033edb2c72b6405c24e944c5caf867858bd1e5dcdc68dcb5175edc8bbbffc472d00444dc1dfd45d510073fb619cad2887ebb996e485bcbd", - "@tailwindcss/oxide-linux-x64-musl@npm:4.2.2": "c1e258d6d954b0c3fa3c8214478c2b46e5581f60aa1049c11f60a1836668157b023325c691b8ddfabe39b36d8df9ff32e9237d06dc1e8e0beff103324730537d", - "@tailwindcss/oxide-wasm32-wasi@npm:4.2.2": "83ae560e1503cefc9854d5d54b9222d81287a8bd7fc29015f42d032c262cf0ba5ac88f6707219092bb0ec7d8f569a3440e585a9dc084aa07ef7dcfb4dba3defd", - "@tailwindcss/oxide-win32-arm64-msvc@npm:4.2.2": "674ba83bdf03338878cb7839d4a081934404f9fe8771df3c55f6c2f0c09cdf4ab871ec2e821f23eda245c7b0a9b9fdbe32c0d038f887e4958d97c37f9cfe5b3d", - "@tailwindcss/oxide-win32-x64-msvc@npm:4.2.2": "8fd2254df241f2d17417c8a3ecf9ddc51dc23f415a7cd1e7661930296de1a9f4128ae9f3912050f8e9dde4ea0f0f2b2452031b913451aecf12d453f131703c79", + "@tailwindcss/oxide-android-arm64@npm:4.3.2": "d71f84cf523d0b7e617640b2ef6930f8c78321076cca1d0266a531a12f0d1165a0f4b434a1527b3b43640dc19b2ed86c9db8b20de3e2adeb55a63dfbcfa096a8", + "@tailwindcss/oxide-darwin-arm64@npm:4.3.2": "57ee616c3c64a55da3e7a756e7ca82af89a3948646cf4b5117884ab60d922193cb003dc74837b11671f2c888ae28e6c3be69bba898fe7eecdb92cc5e8b6457a7", + "@tailwindcss/oxide-darwin-x64@npm:4.3.2": "30e477d48d3ee6c195583108f70ae861d47eebb35139dce00e57bcde5d58d387918b1ee4b1b1dd320f915a22965faa8caace579cde10707070ca25fdb754a9c3", + "@tailwindcss/oxide-freebsd-x64@npm:4.3.2": "c47f0a698c2e6f13780916468b70de9d13662851ddf085c3a4bc1b481335b4b01028e2446a0f88fe1846c9b325b7cf3c28844b4b5e6c399b768a3481e943637c", + "@tailwindcss/oxide-linux-arm-gnueabihf@npm:4.3.2": "79270082658f16b905cb1861070c87f02a2cf11f24f34b5a543d7da5197c7a7f117847a68f11cc8f39abe1d40a93cd7da9f605f828b2f45eb9fa75e294bbb91c", + "@tailwindcss/oxide-linux-arm64-gnu@npm:4.3.2": "a2a9a54d3a9204585e7af11b17b0f3748d4924364606276938a13a423ae27341dfea6317c35fbaadc436a493a60675851b45ce61c30021d7a4c2cd3c3c839e86", + "@tailwindcss/oxide-linux-arm64-musl@npm:4.3.2": "5abfb9e78a6946f90c1ca2e57b0ac1be87cd5f0dbabb34d9de2e2d652cbfce35d264cc9fd98d0560800f7e000495ab25c45c630916fd621aee7dd20fd3771de8", + "@tailwindcss/oxide-linux-x64-gnu@npm:4.3.2": "5cdd5aaa678665b024d16d557e344d564810e78525be3bde0b86b6b924bcff1e81e2b7e0da88c7f0868c26669955129960c215044a2fd47cb63d2002c6c7e96d", + "@tailwindcss/oxide-linux-x64-musl@npm:4.3.2": "61d39503d79726cae3c497432bf18840c170f198d7ee65b40108e546a24cd661d6f6587adf023254410f11bd6d143a88d09399342f43f4cbcfc017b0aa853d66", + "@tailwindcss/oxide-wasm32-wasi@npm:4.3.2": "6afddcfaf232ac6290ea3368ee3c878bddf8b3c842f3cb71583ef387009de12988067545e9dd4de423f3bca3f93498c4fa46ad105bd9c63582946fbef98e8628", + "@tailwindcss/oxide-win32-arm64-msvc@npm:4.3.2": "68130dff13d07c88b5a59ca1b27acfde384d2c246db910c5a4f98e3fe5ab27ce538e4aca31aa70a68bd5e5a59b50a1875fe9908aeba7b394289c377089753053", + "@tailwindcss/oxide-win32-x64-msvc@npm:4.3.2": "0240e7ab3cb5418d5f655a1b356eb21819c56be193a469b8670a3a89b1f9e66c8cda3120849cffd57c8167ad0098d0e0cfc69ff24577111d5689711f7a13879b", + "@typescript/typescript-aix-ppc64@npm:7.0.2": "6135266f6e9c5928a8efd220b2ec972ecd6fa8c771dea432d2b8ffcec606aedd57b949db98ccb2a216e3fb87d4c6d42fd449258e0ee4cbda3d5994c69c5e84d2", + "@typescript/typescript-darwin-arm64@npm:7.0.2": "c859259821baf9d7a8c1811bc1d0c0cb67b0d7fa9f99f1a3b50aa0e656a2df35c6142f77a9d2b1cd200874fd33bc3bf7ffb5cb5491d57be8e0522319ee3453f8", + "@typescript/typescript-darwin-x64@npm:7.0.2": "4c689effd4a83b881b993903901f58d13aded3c61b2a9b6a0f8f591eeab595dbfab82930b1b2af3b1595829ead0e86c9278ea7b7f8fad47c8c76dd6b0e7fec4c", + "@typescript/typescript-freebsd-arm64@npm:7.0.2": "3339e5cbf127f689cdd977133f903e9549afbf1c85fd12d2b61944bc8cb9cca2c18f45070066476273cb8af992591e340e9b661cbbe62c5bd4882615c2a62892", + "@typescript/typescript-freebsd-x64@npm:7.0.2": "52b1180545def7206ac4a944b3a4bf38809b22b3816e9b0f553e87a4ecbf8e61a6039bb6bcc3a353ad0c16f90195e7ff86f25874ada409dcbbf4c4a587e40c2d", + "@typescript/typescript-linux-arm64@npm:7.0.2": "b3873b9c64ff950230eb1d087eb2f46f7102cbf0f483b5280cb76221626833a1065e4e4dfdd99777151d03c0abde157fde73b605829343a022f3fcc6862490dc", + "@typescript/typescript-linux-arm@npm:7.0.2": "ff6a5f61931a97dd4555c2055001c4720cd0c44e3f102ecb79998799cdf156f39884c87f096036c7a57a09a132b4b545b3830c0ca952292661170a7c10c7ae73", + "@typescript/typescript-linux-loong64@npm:7.0.2": "7cdf90b48bf0792e6cd6f9c151bbfd1963980e50f20e73f75c27fa210ba8de65c8b69092b1dd4c6db5d86396cbe8fb5473ca2986ad45be0afc42e7dc863e5ac6", + "@typescript/typescript-linux-mips64el@npm:7.0.2": "6c669e865878a186249631ac720126ea9a71637170cf14cf6d0aef3dfa0f496cdf8fc1a71db1ed24064b1aa612e9b902c64e53689995a0671e6b6146cc68d156", + "@typescript/typescript-linux-ppc64@npm:7.0.2": "702ac3a57ed2e9932185b2b6a3aaeb12d50152d78b453ced55f936d442d9fd7669a5c8a81c76b44ec60201f96533aa38ad2ca80f70ea8b3e6dcbc5cc4a200208", + "@typescript/typescript-linux-riscv64@npm:7.0.2": "ea92265112cf9320f09fcaef847c8612421cc0a907b50bbc8aa928de1a6306cdf7f4d0c1426c3e475923c99f490dc4469042b2edab3c2eff3afef8c14456650d", + "@typescript/typescript-linux-s390x@npm:7.0.2": "dc6b678125ee4c1b81a91c64076490ec985b84e9dde9c017fbc50ec34808aefe45bf90e04c57bf9d0146ea453d71cd1543ac7c47f7a7ef77635758317d0b2173", + "@typescript/typescript-linux-x64@npm:7.0.2": "93d1142b9099dce38f9f2b25a7c4800289c72699e93e695aba5a6923f3661720b336cdd437f4cb3d49324226b7288c606f24f32a85c8e4be5f97c523f5b27b0a", + "@typescript/typescript-netbsd-arm64@npm:7.0.2": "b3274f1c526a20f4436b0f1167dc0e60dac5606f31491429c61439519a3f6a68fcee3a3f7f26f2fafb6557d918af75795b37d2fb6ede7b857bab772eb529140d", + "@typescript/typescript-netbsd-x64@npm:7.0.2": "d3c15af4176791e21927d35afe4935c8a98d21509db7ecb4dd7769a02c2f983500ef6d0f1646ad614a59a748269d517604af98cbd7c3c0450bb57a12cccd7270", + "@typescript/typescript-openbsd-arm64@npm:7.0.2": "09feda2dcbe2e3f9d31f2e98b09477158da1bb9509fe42dda2ce0b12a33b43bd31bb0caee24c6bde4c735c9d33662bcf65593ee762a2a5fee225798b5d674692", + "@typescript/typescript-openbsd-x64@npm:7.0.2": "e29ffc0538c2843b1e731b90626b5d2855345627fbb6b2ad7ee40b8f88ed1df6f91b03cf5c227645c4fc35a18fb6ff1612de98a9b449da25042f66478e671875", + "@typescript/typescript-sunos-x64@npm:7.0.2": "1647e487c452504c646c01e9e4a504e41c180bc09c9af7ccd2a6db23b6fedad436861de2681674793baccbbfc8970dccc85fce59a4da3d802dd67966774fc188", + "@typescript/typescript-win32-arm64@npm:7.0.2": "26cf8934a58378a2e8467914407f2d06028ca0e211bd68403994f9b27353439d8b0935ebeb7b9a03d8768a64e444285f87756a77ce72211efeecf5239af52bc5", + "@typescript/typescript-win32-x64@npm:7.0.2": "7f8408c4b3a58a2ef8851103c0575b97654e34c5aa0658e32be5584030f395f8a8e8a7fa87eb3afe2c794a01a0eb2e77db743c6025af57ed2915605b8e0a7c82", "dmg-license@npm:1.0.11": "feef35cfb45270a72daadcca9584be5cb840f924448b9d4e543fcd61f1b6d471151049f277c91de1d8b003fad6203d0176066a5f427a01df5fb073402cb8c8b7", "iconv-corefoundation@npm:1.1.7": "bc6f08ac421e5e92ed20f3825f123fd705e036612b2b6aa687958de753c06f32e54f0203ef55540869e3ee189eaea15e43a2757f3a90e555c4dd512c9422da43", "lightningcss-android-arm64@npm:1.32.0": "1cb326ad39dcb02cf9f45025c167b6900e3a04b08f5149d3c5ee26054b00d08db3736fb69183a6c3ed1cb32dddd148608c784b6631b4777623f7dd0c032c392d", @@ -132,22 +177,22 @@ "lightningcss-linux-x64-musl@npm:1.32.0": "a6f48ccc30a73d30563c7b61856d1fd6a8812ce62b1bee797f227e06612df70aab4ccd1908552952f77ca7ff2a51019f62d14ae5310ca67311635eeec55d3a9e", "lightningcss-win32-arm64-msvc@npm:1.32.0": "a919be7fb298c1102bccf18b6f83d54946adfac70ab2ac9c95e4ae38ded76d8f530215b0bcda4d38df4ffc40a70abe3afd91d01d35fd122e7d119ed0e46972d0", "lightningcss-win32-x64-msvc@npm:1.32.0": "5b8d3431aadbdc40a0a7eae32f2415e4f28b547af1a1cd5b35a35d67f772a89492c7fa03e9fc88ce804b14f5f88e412e49fff40d1b0aad67177de815c434207e", - "sass-embedded-all-unknown@npm:1.98.0": "36a9126decd90bb1e7cdb6e5a6ec9913ca644e1ba16748b179daf0b78c87bab1905647b3e4221dcd6dfb8bed9211830ed853d4fab257057f1678a557b4982ec7", - "sass-embedded-android-arm64@npm:1.98.0": "83bcb98adb64adcf01d1bfd0d5726cd28942e3a276b1cf2b8ed426fcb6de4345539b9cde44b6cc3593fd7643f6ac4138ccc5107bccc195438fefe63140f0cecf", - "sass-embedded-android-arm@npm:1.98.0": "7083ddf06fb3685351cef3d95c78044d25b6798f6c9db2898d75ac6f61a140344d591888f8760445e952dfdb6610934b97edab3c323431edc49655ef47d3d3a8", - "sass-embedded-android-riscv64@npm:1.98.0": "dedb467cf1b72c100409268889131ac85f08b517c76ba1fff2a05d829c1f38e14acde11a3081b4ae7063c8a7ee0fda5cdd880cde0d43c3f5bb616419209eb85e", - "sass-embedded-android-x64@npm:1.98.0": "9030281251fa16600de1c90ab8a8995d022fbbb2c7d7a6447ee262f3b3fcd4cbe772c1c9067b7296b8dd6a3311ef5655246ca9c03051b838b978cced82515896", - "sass-embedded-darwin-arm64@npm:1.98.0": "0955f52140dbcd6cc2a35592cbe147e271f988a8d9e2807e28e3c4ba49e950e8d9fbbca00e2187c36530d28de2916e9e79f3ad9ec5c0f214449e3f3d10b15a1b", - "sass-embedded-darwin-x64@npm:1.98.0": "aba47e0c1b61a64f9e0a3899bb84725dfb2b45fb4b3a38e7c2e5d767d0b0ca429ce49dba98699298a2491f4ef2e2e40f2dd32905bf268ec4ef7acaa1ca3730da", - "sass-embedded-linux-arm64@npm:1.98.0": "766a5f93c80ba64f3f1733dbf01ee71e0f0a5a56bf75227f0455bd5151ec0348b85501fb4ee09da6393655638b4c34cfcff420ea96645fb25ba7e6afe5a1a1f9", - "sass-embedded-linux-arm@npm:1.98.0": "109131a0d1173f6b34c987192607d148721f980396f8288df29bd407dbc160142e088320ac95a63fdfda464a07953e6092f00a5d3f1e56540cf2553ad21e2b68", - "sass-embedded-linux-musl-arm64@npm:1.98.0": "bcddf4d567b1e335bb5bdad25469d773d3a965cf9c9972e8c43cf943016d010a79ea441df0c1f47a7c67e7330f4f88fc2d13d07d4fe720138f44e8837f660468", - "sass-embedded-linux-musl-arm@npm:1.98.0": "e1572282ac95d9b20afe7053c9415b21490aebb49d276838d256189387df3cc5804f6ba21794ad43dce0531e925f89722a5bea139f327bd51ff4bcf754a84589", - "sass-embedded-linux-musl-riscv64@npm:1.98.0": "6f0f51d3daac10c8a6ca79f0627304f191ab0db1e9dc120084c23231cc7c60929b51e75d64b6afb77abf5054cea89c2d0b129e40ed552489bfb1662a152017e9", - "sass-embedded-linux-musl-x64@npm:1.98.0": "51e55184d36b60a8777dd89f84354fbc4e0e5c09d8b0a2bd842138bb6a766c7e42bf7817cab5784416541a8e31c5a872121b24ec8d945768ced9e0074e648c1f", - "sass-embedded-linux-riscv64@npm:1.98.0": "6dc8669e8e23f8079a1d29073b8c3947314b4dae7c88db86b7dc6642a86e3aebf1a4f7cf38903423552aa9388fa4aef5c137f332aba5fa37b8447ca11640dcd4", - "sass-embedded-linux-x64@npm:1.98.0": "67dc506dd51e139173539008c07e2a7a397a3d47c7192039a3bc1c9af578a8c19c91fa03768851af653002b850098340e401de7af9041fafc7bb49162848e63b", - "sass-embedded-unknown-all@npm:1.98.0": "c6bc5bc3828d9091e7b669379f7248771ff0b5bae78c5f52d4cc193a387ef0ff30b7a7f17ccb576fcf18502134727a2433ebc5470f67f0b6f5cababdda52a9e4", - "sass-embedded-win32-arm64@npm:1.98.0": "b799485e7afb87d08901bbbb419217ae94e57c60a38ab1ffa74c0f521b1e5f77cb30769807a8403dc0ee27003fbaec402cec2add8ce8bc8d625f48c7afbd5a0d", - "sass-embedded-win32-x64@npm:1.98.0": "c8cb13fafca66b403e829c166ddb57fbecbe7433f515b90841ad49deeb6641b5f8db2238fcfb11a03df094f16ff7e63c0454f4ecdba314a7d7cf7408abfd3658" + "sass-embedded-all-unknown@npm:1.100.0": "ed802ec849fb09307294e942382bd19d72c79f53dd348db51fd431f18354876f50e47bef586a27fa1546fe68c1df638e05d9eace5925074b3e117419f1bd486f", + "sass-embedded-android-arm64@npm:1.100.0": "0a219201304c6e3b37e7099092730e978e1e77bb5ab1b0ecb84d72bb4f78b4703552d7f2937ba29250fa67032a23b0417e47ddbe497ce3abd8386d492fbcbdfb", + "sass-embedded-android-arm@npm:1.100.0": "460f04093b37d7bb0a2b6b689622e084795a0c0b820327ce57b7905e6495de777d669b6ac663bf728fb9f62c99e1ad3a6dfe7cc15aca5005037a217130aeac95", + "sass-embedded-android-riscv64@npm:1.100.0": "5b84b0b8a00197571f7d82977af81c0d88053cda91cc1c283f80821a4d8e45532fc8bc974b2c53a3ff869f49f60b2c8f412c90694fb9fa1e5f7396fb3ca7dc8a", + "sass-embedded-android-x64@npm:1.100.0": "d225b29000a7ff1e0aa2a64e5d60ee63679630eaf717311b20e972326ac31711928c2deb2f78d6a5ad2d3b9ef0bfa918d40940dea01e75232db7146624e66323", + "sass-embedded-darwin-arm64@npm:1.100.0": "ae3b9b1ef84b5cc53f2c364295070b8ef8fe7c8cbde6ea278d34d3fa0e1636168f13abe074155549587300c1c91d90d07b2fba25f1f765f62aa26729a0f2d37c", + "sass-embedded-darwin-x64@npm:1.100.0": "85b6aecb66dfe00a3600eac244b1611c04e608f42fc64720519d0996a5a59692b619176ea726647aa031b496c6a147b3f1b2dc8aef43c61c9cecec63bfe1d138", + "sass-embedded-linux-arm64@npm:1.100.0": "9ea709b02c24242bcbae8cc299913b1b28ea85c95c3a4a14b645b59f7cebe283c199b2e823edf8cb76255216c160c5642b0ff02d63cd9649ed2fc67aec900adf", + "sass-embedded-linux-arm@npm:1.100.0": "1f673e52323446f60d069182dc3488e957df3b7e4b17a6973c39bd1922d073521e665371a64d76f527287a0b1c3e47825b4252c51de0817d02c069c4b3839252", + "sass-embedded-linux-musl-arm64@npm:1.100.0": "f87777a45b855531b990c2969b2a7c8dae02b5a3e80e712e093b61632384db5c176cb776507f886791cc378b504e936da30e4bf97d105454ee7d520f662c25d9", + "sass-embedded-linux-musl-arm@npm:1.100.0": "66887ed9ce2f552942a463f2276c4d93dc2ef6ad55797507e667580f8b1911c5b471a941c3a1a999516fd4802cc833a4f39a738d2e65bb2a2d76172bc56f280b", + "sass-embedded-linux-musl-riscv64@npm:1.100.0": "ceb308bd10e2176e6885303e8f64a414eec5d6db4badf1517069c744fedc4fd05f0d34abae2f71dfa9db4b73b2269e7f1d793a600ff4610f165abda35b06c4a2", + "sass-embedded-linux-musl-x64@npm:1.100.0": "64b02ea419edea470f485b87631f065b891adca5cb555b3089c6922200dc2cd6982ff51dcdf2bd44cb7aa3b6e81590346f672f1f64481609734176536cce6e47", + "sass-embedded-linux-riscv64@npm:1.100.0": "9f443b08cf057d1577b5178608b2fa34963a614e9fe06b132d77065650536f1013dc567f8754e3d059f036e39a4f58013c512cb94bd7497ca839f5d5febce25d", + "sass-embedded-linux-x64@npm:1.100.0": "85307c181232f792bf6b7ed3c4849d043802d4b0a2988cf589efcbf83e4c49099f0a599084d08dea160723ff21a931c5f4cb4eded7d300765c77dd13efd7f1ea", + "sass-embedded-unknown-all@npm:1.100.0": "576eea8f7e866bc5aee12995e219f65c2ddc9da3c848950740c2568e1dd4433a782be6a8b6a87e1c9fb27a03e6e06982efa3da04df8a2dec8cdb685f72f56a63", + "sass-embedded-win32-arm64@npm:1.100.0": "bfd7231a5965a4f9c31cf9778c664a6917ead537742beeacb7042c4e7f40301cc305c409620643bfa255a31efec69bad637ae359e8573376891b41ba9f4eb450", + "sass-embedded-win32-x64@npm:1.100.0": "d78da6f82e616e5ecfc8221648029343320ac2cff8357152ecb582ab5ac5dbd20a838cce78d29a8c9986310e2a097c263dbab93c105affc5c009c71fdb1de5fc" } diff --git a/pkgs/by-name/bi/bitfocus-companion/package.nix b/pkgs/by-name/bi/bitfocus-companion/package.nix index 9bbdfd6c65be..2b2a208dfa49 100644 --- a/pkgs/by-name/bi/bitfocus-companion/package.nix +++ b/pkgs/by-name/bi/bitfocus-companion/package.nix @@ -3,7 +3,7 @@ lib, fetchFromGitHub, fetchurl, - nodejs, + nodejs_26, git, python3, udev, @@ -20,8 +20,8 @@ let builtinSurfaces = { elgato-stream-deck = fetchurl { - url = "https://s4.bitfocus.io/developer-module-builds/surface/elgato-stream-deck/v1.4.3-70e2c01d15a0f58c52a8e80d7d6f4977f157d58e/elgato-stream-deck-v1.4.3.tgz"; - hash = "sha256-bZnXvkyfllzHZTAJtH/hSYIv+J5ZOYWZycUHdz9srGI="; + url = "https://s4.bitfocus.io/developer-module-builds/surface/elgato-stream-deck/v1.4.6-c7ea9961c73fc6bf184b563d03c64b5607312d8d/elgato-stream-deck-v1.4.6.tgz"; + hash = "sha256-0zYgn2ao2yhy3CSlHbdqfV9YWWwUiQ5kibDjT4uqOn8="; }; xkeys = fetchurl { url = "https://s4.bitfocus.io/developer-module-builds/surface/xkeys/v1.0.2-876f00ee194faa57ec14468b7019bbaa516a9e6d/xkeys-v1.0.2.tgz"; @@ -41,7 +41,7 @@ in stdenv.mkDerivation rec { pname = "bitfocus-companion"; - version = "4.3.4"; + version = "5.0.5"; __structuredAttrs = true; strictDeps = true; @@ -50,7 +50,7 @@ stdenv.mkDerivation rec { owner = "bitfocus"; repo = "companion"; tag = "v${version}"; - hash = "sha256-ojSXiWaRKFCjHmAMs/RtzNhgSNUy7RKTZ4CE/wCxEaI="; + hash = "sha256-Q5XQ/r4YYYqLk6YaSlBZqcqEH8nFmpqyzMf7/fMWX74="; }; passthru.updateScript = nix-update-script { }; @@ -59,15 +59,10 @@ stdenv.mkDerivation rec { # patch out git calls to generate version strings. substituteInPlace tools/lib.mts --replace-fail "return await fcn()" "return \"v${version}\" as unknown as T" - # remove unsupported yarn config options (npmMinimalAgeGate, npmPreapprovedPackages removed in newer yarn) - # approvedGitRepositories and compressionLevel required by yarn >= 4.14 for lockfile version < 9 - printf "nodeLinker: node-modules\nenableScripts: false\ncompressionLevel: 0\napprovedGitRepositories:\n - '**'\n" > .yarnrc.yml + # remove yarn config options which require network access at install time + printf "nodeLinker: node-modules\nenableScripts: false\n" > .yarnrc.yml # remove the yarn install during the build, since there is no internet connection, and everything has already been installed by yarnBerryConfigHook - substituteInPlace tools/build/dist.mts \ - --replace-fail 'await $`yarn --cwd node_modules/better-sqlite3 prebuild-install --arch=''${platformInfo.nodeArch} --platform=''${platformInfo.nodePlatform}`' "" \ - --replace-fail 'await $`yarn --cwd node_modules/better-sqlite3 prebuild-install`' "" - substituteInPlace tools/build/package.mts --replace-fail "await $\`yarn install --no-immutable\`" "" # remove node download, since we'll use the nix version @@ -76,11 +71,16 @@ stdenv.mkDerivation rec { --replace-fail "await fs.createSymlink(latestRuntimeDir, path.join(runtimesDir, 'main'), 'dir')" "" substituteInPlace companion/lib/Instance/NodePath.ts \ - --replace-fail "if (!(await fs.pathExists(nodePath))) return null" "return '${lib.getExe nodejs}'" \ + --replace-fail "if (!(await fs.pathExists(nodePath))) return null" "return '${lib.getExe nodejs_26}'" + + # allow all surface modules (builtin and user-downloaded) to find libudev, by adding + # LD_LIBRARY_PATH to the env whitelist companion uses when spawning module child processes + substituteInPlace companion/lib/Instance/Environment.ts \ + --replace-fail "'DISABLE_IPV6'," "'DISABLE_IPV6', 'LD_LIBRARY_PATH'," ''; nativeBuildInputs = [ - nodejs + nodejs_26 yarn-berry.yarnBerryConfigHook git python3 @@ -91,7 +91,7 @@ stdenv.mkDerivation rec { buildInputs = [ libusb1 dart-sass - nodejs + nodejs_26 electron udev ]; @@ -100,15 +100,13 @@ stdenv.mkDerivation rec { offlineCache = yarn-berry.fetchYarnBerryDeps { inherit src missingHashes; - hash = "sha256-XDXxv+LSr9fYhVhwkcvmd56fAL6gY9FK6kiQlXxTWXo="; + hash = "sha256-Fuh/D3FVtm08h7pW+LHgrEiyN9vmCjy+WekfpIz/Xc4="; }; env = { ELECTRON_SKIP_BINARY_DOWNLOAD = 1; SKIP_LAUNCH_CHECK = true; ELECTRON = 0; - # prevent yarn >= 4.14 from triggering a lockfile refresh for v8 lockfiles - YARN_LOCKFILE_VERSION_OVERRIDE = 8; }; # with dontConfigure it doesn't seem to retrieve node_modules, so empty configurePhase instead @@ -142,20 +140,13 @@ stdenv.mkDerivation rec { rm -rf dist/node-runtimes ''; - postInstall = '' - # patch the env whitelist companion uses when spawning module child processes to include - # LD_LIBRARY_PATH, so all surface modules (builtin and user-downloaded) can find libudev - substituteInPlace $out/share/bitfocus-companion/dist/main.js \ - --replace-fail '"DISABLE_IPV6"],t={}' '"DISABLE_IPV6","LD_LIBRARY_PATH"],t={}' - ''; - installPhase = '' runHook preInstall mkdir -p $out/share/bitfocus-companion cp -r * $out/share/bitfocus-companion/ - makeWrapper ${lib.getExe nodejs} $out/bin/bitfocus-companion \ + makeWrapper ${lib.getExe nodejs_26} $out/bin/bitfocus-companion \ --add-flags $out/share/bitfocus-companion/dist/main.js \ --set LD_LIBRARY_PATH "${ lib.makeLibraryPath [ diff --git a/pkgs/by-name/bo/boehmgc/package.nix b/pkgs/by-name/bo/boehmgc/package.nix index 41a6a88764a6..9a0d3c9d34d5 100644 --- a/pkgs/by-name/bo/boehmgc/package.nix +++ b/pkgs/by-name/bo/boehmgc/package.nix @@ -26,7 +26,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchFromGitHub { owner = "bdwgc"; repo = "bdwgc"; - rev = "v${finalAttrs.version}"; + tag = "v${finalAttrs.version}"; hash = "sha256-5yeAB5Y92YjOutwRXBJkMxoOLkmzmqIJs4PirKX89fE="; }; @@ -43,6 +43,8 @@ stdenv.mkDerivation (finalAttrs: { autoreconfHook ]; + strictDeps = true; + configureFlags = [ "--enable-cplusplus" "--with-libatomic-ops=none" diff --git a/pkgs/by-name/ca/cadabra2/package.nix b/pkgs/by-name/ca/cadabra2/package.nix index 09f0411f9d7d..f8a2af5bb9ea 100644 --- a/pkgs/by-name/ca/cadabra2/package.nix +++ b/pkgs/by-name/ca/cadabra2/package.nix @@ -11,7 +11,7 @@ nix-update-script, boost, - glibmm, + glibmm_2_4, gmpxx, gtkmm3, jsoncpp, @@ -94,7 +94,7 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ boost - glibmm + glibmm_2_4 gmpxx jsoncpp onetbb diff --git a/pkgs/by-name/ca/cairomm_1_0/package.nix b/pkgs/by-name/ca/cairomm_1_0/package.nix index 7d48339c2704..ac957ad4ae54 100644 --- a/pkgs/by-name/ca/cairomm_1_0/package.nix +++ b/pkgs/by-name/ca/cairomm_1_0/package.nix @@ -6,7 +6,7 @@ boost, cairo, fontconfig, - libsigcxx, + libsigcxx_2_0, meson, ninja, }: @@ -41,7 +41,7 @@ stdenv.mkDerivation (finalAttrs: { propagatedBuildInputs = [ cairo - libsigcxx + libsigcxx_2_0 ]; mesonFlags = [ diff --git a/pkgs/by-name/ca/cairomm_1_16/package.nix b/pkgs/by-name/ca/cairomm_1_16/package.nix index 4bb542e104dd..3a4b66a57030 100644 --- a/pkgs/by-name/ca/cairomm_1_16/package.nix +++ b/pkgs/by-name/ca/cairomm_1_16/package.nix @@ -8,7 +8,7 @@ pkg-config, cairo, fontconfig, - libsigcxx30, + libsigcxx_3_0, }: stdenv.mkDerivation (finalAttrs: { @@ -41,7 +41,7 @@ stdenv.mkDerivation (finalAttrs: { propagatedBuildInputs = [ cairo - libsigcxx30 + libsigcxx_3_0 ]; mesonFlags = [ diff --git a/pkgs/by-name/ca/catch2_3/clang-20-disable-broken-test.patch b/pkgs/by-name/ca/catch2_3/clang-20-disable-broken-test.patch deleted file mode 100644 index 372243455aed..000000000000 --- a/pkgs/by-name/ca/catch2_3/clang-20-disable-broken-test.patch +++ /dev/null @@ -1,15 +0,0 @@ -diff --git a/tests/SelfTest/UsageTests/Misc.tests.cpp b/tests/SelfTest/UsageTests/Misc.tests.cpp -index 3697f0695c..8c10aace7b 100644 ---- a/tests/SelfTest/UsageTests/Misc.tests.cpp -+++ b/tests/SelfTest/UsageTests/Misc.tests.cpp -@@ -384,10 +384,6 @@ - REQUIRE(x.size() > 0); - } - --TEMPLATE_PRODUCT_TEST_CASE("Product with differing arities", "[template][product]", std::tuple, (int, (int, double), (int, double, float))) { -- REQUIRE(std::tuple_size::value >= 1); --} -- - using MyTypes = std::tuple; - TEMPLATE_LIST_TEST_CASE("Template test case with test types specified inside std::tuple", "[template][list]", MyTypes) - { diff --git a/pkgs/by-name/ca/catch2_3/package.nix b/pkgs/by-name/ca/catch2_3/package.nix index 381fead86e88..29d15bd0bfc7 100644 --- a/pkgs/by-name/ca/catch2_3/package.nix +++ b/pkgs/by-name/ca/catch2_3/package.nix @@ -7,23 +7,17 @@ spdlog, }: -stdenv.mkDerivation rec { +stdenv.mkDerivation (finalAttrs: { pname = "catch2"; - version = "3.15.3"; + version = "3.16.0"; src = fetchFromGitHub { owner = "catchorg"; repo = "Catch2"; - tag = "v${version}"; - hash = "sha256-ZuH3tUWNklq0bKp0Yu9w3L5FNsQwUxe6lyGBv4M6U1E="; + tag = "v${finalAttrs.version}"; + hash = "sha256-vvPZTQzLNGIcdDbuo0w6sQvxzLdKFCl2LNwcHu0d5I8="; }; - patches = lib.optionals stdenv.cc.isClang [ - # This test fails to compile with Clang 20 - # See: https://github.com/catchorg/Catch2/issues/2991 - ./clang-20-disable-broken-test.patch - ]; - postPatch = '' substituteInPlace CMake/*.pc.in \ --replace-fail "\''${prefix}/" "" @@ -37,10 +31,10 @@ stdenv.mkDerivation rec { cmakeFlags = [ "-DCATCH_DEVELOPMENT_BUILD=ON" - "-DCATCH_BUILD_TESTING=${if doCheck then "ON" else "OFF"}" + "-DCATCH_BUILD_TESTING=${if finalAttrs.doCheck then "ON" else "OFF"}" "-DCATCH_ENABLE_WERROR=OFF" ] - ++ lib.optionals (stdenv.cc.isClang && doCheck) [ + ++ lib.optionals (stdenv.cc.isClang && finalAttrs.doCheck) [ # test has a faulty path normalization technique that won't work in # our darwin/LLVM build environment https://github.com/catchorg/Catch2/issues/1691 "-DCMAKE_CTEST_ARGUMENTS=-E;ApprovalTests" @@ -69,9 +63,9 @@ stdenv.mkDerivation rec { meta = { description = "Modern, C++-native, test framework for unit-tests"; homepage = "https://github.com/catchorg/Catch2"; - changelog = "https://github.com/catchorg/Catch2/blob/${src.tag}/docs/release-notes.md"; + changelog = "https://github.com/catchorg/Catch2/blob/${finalAttrs.src.tag}/docs/release-notes.md"; license = lib.licenses.boost; maintainers = with lib.maintainers; [ dotlambda ]; platforms = with lib.platforms; unix ++ windows; }; -} +}) diff --git a/pkgs/by-name/cd/cdecl/package.nix b/pkgs/by-name/cd/cdecl/package.nix index 8295f1653575..494604a65625 100644 --- a/pkgs/by-name/cd/cdecl/package.nix +++ b/pkgs/by-name/cd/cdecl/package.nix @@ -73,5 +73,6 @@ stdenv.mkDerivation (finalAttrs: { maintainers = with lib.maintainers; [ sigmanificient ]; platforms = lib.platforms.unix; mainProgram = "cdecl"; + broken = true; }; }) diff --git a/pkgs/by-name/cg/cgtcalc/package.nix b/pkgs/by-name/cg/cgtcalc/package.nix index c3720fb38c9e..d90747cd9308 100644 --- a/pkgs/by-name/cg/cgtcalc/package.nix +++ b/pkgs/by-name/cg/cgtcalc/package.nix @@ -4,7 +4,6 @@ nix-update-script, stdenv, swift, - swiftPackages, swiftpm, swiftpm2nix, }: @@ -37,13 +36,7 @@ stdenv.mkDerivation (finalAttrs: { runHook postInstall ''; - buildInputs = [ - swiftPackages.XCTest - ]; - - # libIndexStore.so: cannot open shared object file: No such file or directory - # https://github.com/NixOS/nixpkgs/issues/379859 - doCheck = false; + doCheck = !stdenv.hostPlatform.isDarwin; passthru.updateScript = nix-update-script { extraArgs = [ "--version=branch" ]; diff --git a/pkgs/by-name/ch/chatty/package.nix b/pkgs/by-name/ch/chatty/package.nix index 2b8c04700662..ef4893c0edb4 100644 --- a/pkgs/by-name/ch/chatty/package.nix +++ b/pkgs/by-name/ch/chatty/package.nix @@ -11,7 +11,7 @@ wrapGAppsHook4, evolution-data-server, feedbackd, - glibmm, + glibmm_2_4, libsecret, gnome-desktop, gspell, @@ -53,7 +53,7 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ evolution-data-server feedbackd - glibmm + glibmm_2_4 libsecret gnome-desktop gspell diff --git a/pkgs/by-name/cl/clickhouse/generic.nix b/pkgs/by-name/cl/clickhouse/generic.nix index 4616222f3363..ec64d528972a 100644 --- a/pkgs/by-name/cl/clickhouse/generic.nix +++ b/pkgs/by-name/cl/clickhouse/generic.nix @@ -130,6 +130,9 @@ llvmStdenv.mkDerivation (finalAttrs: { postPatch = '' patchShebangs src/ utils/ + + substituteInPlace contrib/liburing-cmake/CMakeLists.txt \ + --replace-fail "set (LIBURING_CONFIG_HAS_OPEN_HOW FALSE)" "set (LIBURING_CONFIG_HAS_OPEN_HOW TRUE)" '' + lib.optionalString stdenv.hostPlatform.isDarwin '' substituteInPlace cmake/tools.cmake \ diff --git a/pkgs/by-name/cm/cmake/add-nixpkgs-libc-paths.patch b/pkgs/by-name/cm/cmake/add-nixpkgs-libc-paths.patch index 3a1cbf0e11ac..00dda8b8038a 100644 --- a/pkgs/by-name/cm/cmake/add-nixpkgs-libc-paths.patch +++ b/pkgs/by-name/cm/cmake/add-nixpkgs-libc-paths.patch @@ -1,8 +1,8 @@ diff --git a/Modules/Platform/UnixPaths.cmake b/Modules/Platform/UnixPaths.cmake -index e95da44ea4..bdf4155232 100644 +index 9aa659e4fd..ba9974c316 100644 --- a/Modules/Platform/UnixPaths.cmake +++ b/Modules/Platform/UnixPaths.cmake -@@ -71,28 +71,38 @@ +@@ -81,28 +81,38 @@ list(APPEND CMAKE_PLATFORM_IMPLICIT_LINK_DIRECTORIES /lib /lib32 /lib64 /usr/lib /usr/lib32 /usr/lib64 ) diff --git a/pkgs/by-name/cm/cmake/darwin-binary-paths.patch b/pkgs/by-name/cm/cmake/darwin-binary-paths.patch index af9d5af2cfe1..cea6c95ed169 100644 --- a/pkgs/by-name/cm/cmake/darwin-binary-paths.patch +++ b/pkgs/by-name/cm/cmake/darwin-binary-paths.patch @@ -1,21 +1,21 @@ diff --git a/Modules/Platform/Darwin-Initialize.cmake b/Modules/Platform/Darwin-Initialize.cmake -index 196ab18b0b..31dd4346b1 100644 +index c9c88b36f5..0b1fda27d7 100644 --- a/Modules/Platform/Darwin-Initialize.cmake +++ b/Modules/Platform/Darwin-Initialize.cmake -@@ -16,7 +16,7 @@ - endif() +@@ -290,7 +290,7 @@ endif() + # CMAKE_OSX_DEPLOYMENT_TARGET if(NOT CMAKE_CROSSCOMPILING) - execute_process(COMMAND sw_vers -productVersion + execute_process(COMMAND @sw_vers@ -productVersion OUTPUT_VARIABLE _CMAKE_HOST_OSX_VERSION - OUTPUT_STRIP_TRAILING_WHITESPACE) - endif() + OUTPUT_STRIP_TRAILING_WHITESPACE + RESULT_VARIABLE _result) diff --git a/Source/kwsys/SystemInformation.cxx b/Source/kwsys/SystemInformation.cxx -index c65587edbe..0a7cc380c3 100644 +index 743c224437..173ceb0a64 100644 --- a/Source/kwsys/SystemInformation.cxx +++ b/Source/kwsys/SystemInformation.cxx -@@ -3833,7 +3833,7 @@ +@@ -3835,7 +3835,7 @@ long long SystemInformationImplementation::GetHostMemoryUsed() } char const* names[3] = { "Pages wired down:", "Pages active:", nullptr }; long long values[2] = { 0 }; @@ -24,7 +24,7 @@ index c65587edbe..0a7cc380c3 100644 if (ierr) { return -1; } -@@ -5586,7 +5586,7 @@ +@@ -5506,7 +5506,7 @@ int SystemInformationImplementation::CallSwVers(char const* arg, { #ifdef __APPLE__ std::vector args; @@ -34,10 +34,10 @@ index c65587edbe..0a7cc380c3 100644 args.push_back(nullptr); ver = this->RunProcess(args); diff --git a/Tests/CMakeLists.txt b/Tests/CMakeLists.txt -index 15a1e2c0c3..33bb304cf7 100644 +index 8020d96833..d32e6a6693 100644 --- a/Tests/CMakeLists.txt +++ b/Tests/CMakeLists.txt -@@ -1958,7 +1958,7 @@ +@@ -1977,7 +1977,7 @@ if(BUILD_TESTING) if(CMake_TEST_XCODE_VERSION AND NOT CMake_TEST_XCODE_VERSION VERSION_LESS 5) if(NOT CMake_TEST_XCTest_DEPLOYMENT_TARGET) execute_process( @@ -45,4 +45,4 @@ index 15a1e2c0c3..33bb304cf7 100644 + COMMAND @sw_vers@ -productVersion OUTPUT_VARIABLE OSX_VERSION OUTPUT_STRIP_TRAILING_WHITESPACE - ) + RESULT_VARIABLE _sw_vers_result diff --git a/pkgs/by-name/cm/cmake/darwin-bsd-binary-paths.patch b/pkgs/by-name/cm/cmake/darwin-bsd-binary-paths.patch index 8fe699ac2953..4c23425eb79d 100644 --- a/pkgs/by-name/cm/cmake/darwin-bsd-binary-paths.patch +++ b/pkgs/by-name/cm/cmake/darwin-bsd-binary-paths.patch @@ -1,8 +1,8 @@ diff --git a/Modules/CMakeDetermineSystem.cmake b/Modules/CMakeDetermineSystem.cmake -index dc26258eac..dd8d30e3d9 100644 +index c70fea184d..10b18675b0 100644 --- a/Modules/CMakeDetermineSystem.cmake +++ b/Modules/CMakeDetermineSystem.cmake -@@ -68,7 +68,7 @@ +@@ -74,7 +74,7 @@ if(CMAKE_HOST_UNIX) endif() if(_CMAKE_APPLE_SILICON_PROCESSOR) if(";${_CMAKE_APPLE_SILICON_PROCESSOR};" MATCHES "^;(arm64|x86_64);$") @@ -12,10 +12,10 @@ index dc26258eac..dd8d30e3d9 100644 ERROR_VARIABLE _sysctl_stderr RESULT_VARIABLE _sysctl_result diff --git a/Modules/Platform/Darwin-Initialize.cmake b/Modules/Platform/Darwin-Initialize.cmake -index 31dd4346b1..7c4f123a1d 100644 +index 0b1fda27d7..f5491ef048 100644 --- a/Modules/Platform/Darwin-Initialize.cmake +++ b/Modules/Platform/Darwin-Initialize.cmake -@@ -28,7 +28,7 @@ +@@ -22,7 +22,7 @@ set(CMAKE_OSX_ARCHITECTURES "$ENV{CMAKE_OSX_ARCHITECTURES}" CACHE STRING if(NOT CMAKE_CROSSCOMPILING AND CMAKE_SYSTEM_NAME STREQUAL "Darwin" AND CMAKE_HOST_SYSTEM_PROCESSOR MATCHES "^(arm64|x86_64)$") @@ -25,10 +25,10 @@ index 31dd4346b1..7c4f123a1d 100644 ERROR_VARIABLE _sysctl_stderr RESULT_VARIABLE _sysctl_result diff --git a/Modules/ProcessorCount.cmake b/Modules/ProcessorCount.cmake -index 260b6631c0..ffb8fcd8d2 100644 +index b8fa1fabc0..7c3112b817 100644 --- a/Modules/ProcessorCount.cmake +++ b/Modules/ProcessorCount.cmake -@@ -87,8 +87,7 @@ +@@ -87,8 +87,7 @@ function(ProcessorCount var) if(NOT count) # Mac, FreeBSD, OpenBSD (systems with sysctl): @@ -52,10 +52,10 @@ index 8c22b4e43a..6d9ccef5e7 100644 #elif defined(__sun) && (defined(__SVR4) || defined(__svr4__)) /* Solaris */ # define KWSYSPE_PS_COMMAND "ps -e -o pid,ppid" diff --git a/Source/kwsys/SystemInformation.cxx b/Source/kwsys/SystemInformation.cxx -index 0a7cc380c3..9923dc4ab9 100644 +index 173ceb0a64..7bddddf955 100644 --- a/Source/kwsys/SystemInformation.cxx +++ b/Source/kwsys/SystemInformation.cxx -@@ -3876,7 +3876,7 @@ +@@ -3878,7 +3878,7 @@ long long SystemInformationImplementation::GetProcMemoryUsed() long long memUsed = 0; pid_t pid = getpid(); std::ostringstream oss; @@ -65,10 +65,10 @@ index 0a7cc380c3..9923dc4ab9 100644 if (!file) { return -1; diff --git a/Tests/CMakeLists.txt b/Tests/CMakeLists.txt -index 33bb304cf7..7dbda40a81 100644 +index d32e6a6693..683e27ece7 100644 --- a/Tests/CMakeLists.txt +++ b/Tests/CMakeLists.txt -@@ -216,7 +216,7 @@ +@@ -249,7 +249,7 @@ if(BUILD_TESTING) endif() if(CMAKE_SYSTEM_NAME STREQUAL "Darwin" AND NOT DEFINED CMake_TEST_APPLE_SILICON) diff --git a/pkgs/by-name/cm/cmake/nixpkgs-cmake-prefix-path.patch b/pkgs/by-name/cm/cmake/nixpkgs-cmake-prefix-path.patch index 8a572fc08320..896e3aeffe57 100644 --- a/pkgs/by-name/cm/cmake/nixpkgs-cmake-prefix-path.patch +++ b/pkgs/by-name/cm/cmake/nixpkgs-cmake-prefix-path.patch @@ -1,8 +1,8 @@ diff --git a/Source/cmFindBase.cxx b/Source/cmFindBase.cxx -index b8d4765692..902c1e5290 100644 +index e9e8dfd4b9..d115cd1897 100644 --- a/Source/cmFindBase.cxx +++ b/Source/cmFindBase.cxx -@@ -312,6 +312,11 @@ void cmFindBase::FillCMakeEnvironmentPath() +@@ -308,6 +308,11 @@ void cmFindBase::FillCMakeEnvironmentPath() // Add CMAKE_*_PATH environment variables std::string var = cmStrCat("CMAKE_", this->CMakePathName, "_PATH"); paths.AddEnvPrefixPath("CMAKE_PREFIX_PATH"); @@ -15,10 +15,10 @@ index b8d4765692..902c1e5290 100644 if (this->CMakePathName == "PROGRAM") { diff --git a/Source/cmFindPackageCommand.cxx b/Source/cmFindPackageCommand.cxx -index 6201894fd1..9533862a2b 100644 +index 2f2c5c6662..4594afd0e7 100644 --- a/Source/cmFindPackageCommand.cxx +++ b/Source/cmFindPackageCommand.cxx -@@ -2467,6 +2467,7 @@ void cmFindPackageCommand::FillPrefixesCMakeEnvironment() +@@ -2520,6 +2520,7 @@ void cmFindPackageCommand::FillPrefixesCMakeEnvironment() // And now the general CMake environment variables paths.AddEnvPath("CMAKE_PREFIX_PATH"); diff --git a/pkgs/by-name/cm/cmake/package.nix b/pkgs/by-name/cm/cmake/package.nix index 94a68528777c..8d5908b8f5b8 100644 --- a/pkgs/by-name/cm/cmake/package.nix +++ b/pkgs/by-name/cm/cmake/package.nix @@ -52,11 +52,11 @@ stdenv.mkDerivation (finalAttrs: { + lib.optionalString isMinimalBuild "-minimal" + lib.optionalString cursesUI "-cursesUI" + lib.optionalString qt5UI "-qt5UI"; - version = "4.4.2"; + version = "4.4.3"; src = fetchurl { url = "https://cmake.org/files/v${lib.versions.majorMinor finalAttrs.version}/cmake-${finalAttrs.version}.tar.gz"; - hash = "sha256-HbnmHmC24IdMhjhjQLkQOC88XnW5+/tE0SIGMSmieJ0="; + hash = "sha256-xGQAYYtPHytDUH8k+yLzroMMNBbPI7d24W4dQTqokvA="; }; patches = [ diff --git a/pkgs/by-name/cm/cmake/remove-impure-search-paths.patch b/pkgs/by-name/cm/cmake/remove-impure-search-paths.patch index 0e396847f7c6..89d12e93aab1 100644 --- a/pkgs/by-name/cm/cmake/remove-impure-search-paths.patch +++ b/pkgs/by-name/cm/cmake/remove-impure-search-paths.patch @@ -1,8 +1,8 @@ diff --git a/Modules/CMakeDetermineJavaCompiler.cmake b/Modules/CMakeDetermineJavaCompiler.cmake -index b20a255621..bc67fdf4aa 100644 +index f66402e304..175b2235d2 100644 --- a/Modules/CMakeDetermineJavaCompiler.cmake +++ b/Modules/CMakeDetermineJavaCompiler.cmake -@@ -42,19 +42,6 @@ +@@ -42,19 +42,6 @@ if(NOT CMAKE_Java_COMPILER) "[HKEY_LOCAL_MACHINE\\SOFTWARE\\JavaSoft\\Java Development Kit\\1.4;JavaHome]/bin" "[HKEY_LOCAL_MACHINE\\SOFTWARE\\JavaSoft\\Java Development Kit\\1.3;JavaHome]/bin" $ENV{JAVA_HOME}/bin @@ -23,7 +23,7 @@ index b20a255621..bc67fdf4aa 100644 # if no compiler has been specified yet, then look for one if(CMAKE_Java_COMPILER_INIT) diff --git a/Modules/CMakeDetermineSystem.cmake b/Modules/CMakeDetermineSystem.cmake -index dd8d30e3d9..d500364ba5 100644 +index 10b18675b0..3f9b62f02f 100644 --- a/Modules/CMakeDetermineSystem.cmake +++ b/Modules/CMakeDetermineSystem.cmake @@ -9,7 +9,7 @@ @@ -39,7 +39,7 @@ diff --git a/Modules/CMakeFindFrameworks.cmake b/Modules/CMakeFindFrameworks.cma index 87ad38b46b..95f226be40 100644 --- a/Modules/CMakeFindFrameworks.cmake +++ b/Modules/CMakeFindFrameworks.cmake -@@ -39,22 +39,10 @@ +@@ -39,22 +39,10 @@ if(NOT CMAKE_FIND_FRAMEWORKS_INCLUDED) macro(CMAKE_FIND_FRAMEWORKS fwk) set(${fwk}_FRAMEWORKS) if(APPLE) @@ -63,7 +63,7 @@ index 87ad38b46b..95f226be40 100644 # For backwards compatibility reasons, diff --git a/Modules/CMakeFindJavaCommon.cmake b/Modules/CMakeFindJavaCommon.cmake -index 95ca9b57b6..616295e031 100644 +index f3e34936b4..cc4514c1e9 100644 --- a/Modules/CMakeFindJavaCommon.cmake +++ b/Modules/CMakeFindJavaCommon.cmake @@ -15,21 +15,6 @@ else() @@ -89,10 +89,10 @@ index 95ca9b57b6..616295e031 100644 unset(_ENV_JAVA_HOME) endif() diff --git a/Modules/CMakeFindPackageMode.cmake b/Modules/CMakeFindPackageMode.cmake -index 6e2762cf41..f88cf2f7c1 100644 +index 62e33e047f..c5253b9f66 100644 --- a/Modules/CMakeFindPackageMode.cmake +++ b/Modules/CMakeFindPackageMode.cmake -@@ -64,7 +64,7 @@ +@@ -64,7 +64,7 @@ if(UNIX) # from the outside if(NOT CMAKE_SIZEOF_VOID_P) set(CMAKE_SIZEOF_VOID_P 4) @@ -101,7 +101,7 @@ index 6e2762cf41..f88cf2f7c1 100644 set(CMAKE_SIZEOF_VOID_P 8) else() # use the file utility to check whether itself is 64 bit: -@@ -79,22 +79,6 @@ +@@ -81,22 +81,6 @@ if(UNIX) endif() endif() @@ -145,10 +145,10 @@ index fc0ec313b8..46d8418d2c 100644 if(CMAKE_SUBLIMETEXT_EXECUTABLE) diff --git a/Modules/CPackIFW.cmake b/Modules/CPackIFW.cmake -index 2a2f478fd7..f22281bdca 100644 +index 03427823e4..aa6f062581 100644 --- a/Modules/CPackIFW.cmake +++ b/Modules/CPackIFW.cmake -@@ -426,7 +426,7 @@ +@@ -432,7 +432,7 @@ if(WIN32) else() list(APPEND _CPACK_IFW_PATHS "$ENV{HOME}/Qt" @@ -183,10 +183,10 @@ index 9f986a78e7..5a6a9758ea 100644 list(GET _ACML_ROOT 0 _ACML_ROOT) list(GET _ACML_GPU_ROOT 0 _ACML_GPU_ROOT) diff --git a/Modules/FindCUDA.cmake b/Modules/FindCUDA.cmake -index bceb615ca0..2350b15655 100644 +index 96b16598ab..0827dbbd73 100644 --- a/Modules/FindCUDA.cmake +++ b/Modules/FindCUDA.cmake -@@ -854,7 +854,6 @@ +@@ -852,7 +852,6 @@ if(NOT CUDA_TOOLKIT_ROOT_DIR AND NOT CMAKE_CROSSCOMPILING) # Now search default paths find_program(CUDA_TOOLKIT_ROOT_DIR_NVCC NAMES nvcc nvcc.exe @@ -194,7 +194,7 @@ index bceb615ca0..2350b15655 100644 PATH_SUFFIXES cuda/bin DOC "Toolkit location." ) -@@ -1014,7 +1013,6 @@ +@@ -1012,7 +1011,6 @@ macro(cuda_find_library_local_first_with_path_ext _var _names _doc _path_ext ) # Search default search paths, after we search our own set of paths. find_library(${_var} NAMES ${_names} @@ -202,7 +202,7 @@ index bceb615ca0..2350b15655 100644 DOC ${_doc} ) endif() -@@ -1114,11 +1112,6 @@ +@@ -1112,11 +1110,6 @@ elseif(CUDA_USE_STATIC_CUDA_RUNTIME AND CUDA_cudart_static_LIBRARY) if (CUDA_rt_LIBRARY) list(APPEND CUDA_LIBRARIES ${CUDA_rt_LIBRARY}) endif() @@ -214,7 +214,7 @@ index bceb615ca0..2350b15655 100644 else() list(APPEND CUDA_LIBRARIES ${CUDA_CUDART_LIBRARY}) endif() -@@ -1223,8 +1216,6 @@ +@@ -1221,8 +1214,6 @@ find_path(CUDA_SDK_ROOT_DIR common/inc/cutil.h "$ENV{NVSDKCOMPUTE_ROOT}/C" ENV NVSDKCUDA_ROOT "[HKEY_LOCAL_MACHINE\\SOFTWARE\\NVIDIA Corporation\\Installed Products\\NVIDIA SDK 10\\Compute;InstallDir]" @@ -223,7 +223,7 @@ index bceb615ca0..2350b15655 100644 ) # Keep the CUDA_SDK_ROOT_DIR first in order to be able to override the -@@ -1236,7 +1227,6 @@ +@@ -1234,7 +1225,6 @@ set(CUDA_SDK_SEARCH_PATH "${CUDA_TOOLKIT_ROOT_DIR}/NV_CUDA_SDK" "$ENV{HOME}/NVIDIA_CUDA_SDK" "$ENV{HOME}/NVIDIA_CUDA_SDK_MACOSX" @@ -232,10 +232,10 @@ index bceb615ca0..2350b15655 100644 # Example of how to find an include file from the CUDA_SDK_ROOT_DIR diff --git a/Modules/FindCUDAToolkit.cmake b/Modules/FindCUDAToolkit.cmake -index df36f9a19b..825d1e7386 100644 +index 20ca4a47a2..4827c8b8d7 100644 --- a/Modules/FindCUDAToolkit.cmake +++ b/Modules/FindCUDAToolkit.cmake -@@ -830,18 +830,9 @@ else() +@@ -861,18 +861,9 @@ else() # We will also search the default symlink location /usr/local/cuda first since # if CUDAToolkit_ROOT is not specified, it is assumed that the symlinked # directory is the desired location. @@ -255,7 +255,7 @@ index df36f9a19b..825d1e7386 100644 # Iterate the glob results and create a descending list. set(versions) foreach(p ${possible_paths}) -@@ -857,14 +848,6 @@ else() +@@ -888,14 +879,6 @@ else() # With a descending list of versions, populate possible paths to search. set(search_paths) @@ -270,7 +270,7 @@ index df36f9a19b..825d1e7386 100644 # Now search for the toolkit again using the platform default search paths. _CUDAToolkit_find_root_dir(SEARCH_PATHS "${search_paths}" FIND_FLAGS PATH_SUFFIXES bin) -@@ -889,12 +872,6 @@ else() +@@ -920,12 +903,6 @@ else() elseif(CUDAToolkit_ROOT_DIR AND EXISTS "${CUDAToolkit_ROOT_DIR}/${vf}") set(${result_variable} "${CUDAToolkit_ROOT_DIR}/${vf}" PARENT_SCOPE) break() @@ -284,10 +284,10 @@ index df36f9a19b..825d1e7386 100644 endforeach() endfunction() diff --git a/Modules/FindCoin3D.cmake b/Modules/FindCoin3D.cmake -index 1d89c604e0..5b70e71a87 100644 +index 07cbb69e26..f54b31f204 100644 --- a/Modules/FindCoin3D.cmake +++ b/Modules/FindCoin3D.cmake -@@ -76,10 +76,8 @@ +@@ -106,10 +106,8 @@ if (WIN32) else () if(APPLE) find_path(COIN3D_INCLUDE_DIRS Inventor/So.h @@ -299,10 +299,10 @@ index 1d89c604e0..5b70e71a87 100644 set(COIN3D_LIBRARIES "-framework Coin3d" CACHE STRING "Coin3D library for OSX") else() diff --git a/Modules/FindCurses.cmake b/Modules/FindCurses.cmake -index 64600c6c64..de6af241a1 100644 +index c93cb8651a..edaf83b2ec 100644 --- a/Modules/FindCurses.cmake +++ b/Modules/FindCurses.cmake -@@ -136,15 +136,7 @@ +@@ -147,15 +147,7 @@ endif() # message. Cygwin is an ncurses package, so force ncurses on # cygwin if the curses.h is missing if(CURSES_NCURSES_LIBRARY AND CYGWIN) @@ -320,10 +320,10 @@ index 64600c6c64..de6af241a1 100644 diff --git a/Modules/FindDCMTK.cmake b/Modules/FindDCMTK.cmake -index 4e0ff47f52..6db26cb855 100644 +index 181142c4bb..1bff8ec1b5 100644 --- a/Modules/FindDCMTK.cmake +++ b/Modules/FindDCMTK.cmake -@@ -88,14 +88,7 @@ +@@ -158,14 +158,7 @@ files instead: set(_dcmtk_dir_description "The directory of DCMTK build or install tree.") @@ -340,10 +340,10 @@ index 4e0ff47f52..6db26cb855 100644 set(_SAVED_DCMTK_DIR ${DCMTK_DIR}) diff --git a/Modules/FindDart.cmake b/Modules/FindDart.cmake -index 96cce45590..245dffaf21 100644 +index 6d4b9a3e72..a23e33c1c5 100644 --- a/Modules/FindDart.cmake +++ b/Modules/FindDart.cmake -@@ -24,7 +24,6 @@ +@@ -46,7 +46,6 @@ find_path(DART_ROOT README.INSTALL ENV DART_ROOT PATHS ${PROJECT_SOURCE_DIR} @@ -352,10 +352,10 @@ index 96cce45590..245dffaf21 100644 "C:/Program Files" ${PROJECT_SOURCE_DIR}/.. diff --git a/Modules/FindDoxygen.cmake b/Modules/FindDoxygen.cmake -index 2d430994e8..335c733150 100644 +index 888fd2d83e..a84dd74d58 100644 --- a/Modules/FindDoxygen.cmake +++ b/Modules/FindDoxygen.cmake -@@ -755,10 +755,6 @@ +@@ -773,10 +773,6 @@ macro(_Doxygen_find_doxygen) NAMES doxygen PATHS "[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\doxygen_is1;Inno Setup: App Path]/bin" @@ -366,7 +366,7 @@ index 2d430994e8..335c733150 100644 DOC "Doxygen documentation generation tool (https://www.doxygen.nl)" VALIDATOR _Doxygen_version_validator ) -@@ -845,12 +841,6 @@ +@@ -864,12 +860,6 @@ macro(_Doxygen_find_dot) "$ENV{ProgramFiles}/ATT/Graphviz/bin" "C:/Program Files/ATT/Graphviz/bin" [HKEY_LOCAL_MACHINE\\SOFTWARE\\ATT\\Graphviz;InstallPath]/bin @@ -380,10 +380,10 @@ index 2d430994e8..335c733150 100644 ) mark_as_advanced(DOXYGEN_DOT_EXECUTABLE) diff --git a/Modules/FindFontconfig.cmake b/Modules/FindFontconfig.cmake -index 218ad2fbfa..94e6052564 100644 +index 1e37c7c4eb..5c24e9fb5e 100644 --- a/Modules/FindFontconfig.cmake +++ b/Modules/FindFontconfig.cmake -@@ -64,7 +64,6 @@ +@@ -68,7 +68,6 @@ find_path( Fontconfig_INCLUDE_DIR fontconfig/fontconfig.h HINTS ${PKG_FONTCONFIG_INCLUDE_DIRS} @@ -392,10 +392,10 @@ index 218ad2fbfa..94e6052564 100644 find_library( Fontconfig_LIBRARY diff --git a/Modules/FindGLUT.cmake b/Modules/FindGLUT.cmake -index e29758dc1c..d6255f98c2 100644 +index dcb0359f1c..b46b8ccb77 100644 --- a/Modules/FindGLUT.cmake +++ b/Modules/FindGLUT.cmake -@@ -120,12 +120,10 @@ +@@ -125,12 +125,10 @@ else() set(_GLUT_glut_LIB_DIR /boot/develop/lib/x86) else() find_library( GLUT_Xi_LIBRARY Xi @@ -408,7 +408,7 @@ index e29758dc1c..d6255f98c2 100644 ) mark_as_advanced(GLUT_Xmu_LIBRARY) -@@ -145,11 +143,6 @@ +@@ -150,11 +148,6 @@ else() find_path( GLUT_INCLUDE_DIR GL/glut.h PATHS @@ -420,7 +420,7 @@ index e29758dc1c..d6255f98c2 100644 ${_GLUT_INC_DIR} HINTS ${PC_GLUT_INCLUDE_DIRS} -@@ -158,7 +151,6 @@ +@@ -163,7 +156,6 @@ else() find_library( GLUT_glut_LIBRARY glut PATHS @@ -429,10 +429,10 @@ index e29758dc1c..d6255f98c2 100644 HINTS ${PC_GLUT_LIBRARY_DIRS} diff --git a/Modules/FindGTK.cmake b/Modules/FindGTK.cmake -index 6e39f5a989..df231de76e 100644 +index 87325e25b5..f07dc59787 100644 --- a/Modules/FindGTK.cmake +++ b/Modules/FindGTK.cmake -@@ -71,9 +71,6 @@ +@@ -75,9 +75,6 @@ if(UNIX) find_path( GTK_gtk_INCLUDE_PATH NAMES gtk/gtk.h PATH_SUFFIXES gtk-1.2 gtk12 PATHS @@ -442,7 +442,7 @@ index 6e39f5a989..df231de76e 100644 ) # Some Linux distributions (e.g. Red Hat) have glibconfig.h -@@ -84,26 +81,17 @@ +@@ -88,26 +85,17 @@ if(UNIX) find_path( GTK_glibconfig_INCLUDE_PATH NAMES glibconfig.h PATH_SUFFIXES glib/include lib/glib/include include/glib12 PATHS @@ -469,7 +469,7 @@ index 6e39f5a989..df231de76e 100644 ) # -@@ -112,38 +100,26 @@ +@@ -116,38 +104,26 @@ if(UNIX) find_library( GTK_gtk_LIBRARY NAMES gtk gtk12 @@ -509,10 +509,10 @@ index 6e39f5a989..df231de76e 100644 if(GTK_gtk_INCLUDE_PATH diff --git a/Modules/FindGTK2.cmake b/Modules/FindGTK2.cmake -index 9c5bc63272..87f8f81149 100644 +index 2cbb3a6075..68db0ef40b 100644 --- a/Modules/FindGTK2.cmake +++ b/Modules/FindGTK2.cmake -@@ -377,34 +377,12 @@ +@@ -382,34 +382,12 @@ function(_GTK2_FIND_INCLUDE_DIR _var _hdr) "include suffixes = ${_suffixes}") endif() @@ -547,7 +547,7 @@ index 9c5bc63272..87f8f81149 100644 $ENV{GTKMM_BASEPATH}/include $ENV{GTKMM_BASEPATH}/lib [HKEY_CURRENT_USER\\SOFTWARE\\gtkmm\\2.4;Path]/include -@@ -509,8 +487,6 @@ +@@ -514,8 +492,6 @@ function(_GTK2_FIND_LIBRARY _var _lib _expand_vc _append_version) find_library(GTK2_${_var}_LIBRARY_RELEASE NAMES ${_lib_list} PATHS @@ -557,10 +557,10 @@ index 9c5bc63272..87f8f81149 100644 [HKEY_CURRENT_USER\\SOFTWARE\\gtkmm\\2.4;Path]/lib [HKEY_LOCAL_MACHINE\\SOFTWARE\\gtkmm\\2.4;Path]/lib diff --git a/Modules/FindIce.cmake b/Modules/FindIce.cmake -index 82156747d3..cc3f2a64af 100644 +index f672ba86ee..cbe5595183 100644 --- a/Modules/FindIce.cmake +++ b/Modules/FindIce.cmake -@@ -629,11 +629,6 @@ +@@ -634,11 +634,6 @@ function(_Ice_FIND) list(APPEND ice_roots "${ice_location}") endif() endforeach() @@ -572,7 +572,7 @@ index 82156747d3..cc3f2a64af 100644 endif() # Find all Ice programs -@@ -689,7 +684,7 @@ +@@ -695,7 +690,7 @@ function(_Ice_FIND) # In common use on Linux, MacOS X (homebrew) and FreeBSD; prefer # version-specific dir list(APPEND ice_slice_paths @@ -582,10 +582,10 @@ index 82156747d3..cc3f2a64af 100644 "Ice-${Ice_VERSION_SLICE2CPP_FULL}/slice" "Ice-${Ice_VERSION_SLICE2CPP_SHORT}/slice" diff --git a/Modules/FindJNI.cmake b/Modules/FindJNI.cmake -index a70b00f330..1962b55d4a 100644 +index 5ad87279c2..d16db0806d 100644 --- a/Modules/FindJNI.cmake +++ b/Modules/FindJNI.cmake -@@ -367,56 +367,6 @@ if (WIN32) +@@ -367,68 +367,6 @@ if (WIN32) endif() set(_JNI_JAVA_DIRECTORIES_BASE @@ -639,14 +639,26 @@ index a70b00f330..1962b55d4a 100644 - # SuSE specific paths for default JVM - /usr/lib64/jvm/java - /usr/lib64/jvm/jre +- /usr/lib64/jvm/java-26-openjdk +- /usr/lib64/jvm/jre-26-openjdk +- /usr/lib64/jvm/java-25-openjdk +- /usr/lib64/jvm/jre-25-openjdk +- /usr/lib64/jvm/java-21-openjdk +- /usr/lib64/jvm/jre-21-openjdk +- /usr/lib64/jvm/java-17-openjdk +- /usr/lib64/jvm/jre-17-openjdk +- /usr/lib64/jvm/java-11-openjdk +- /usr/lib64/jvm/jre-11-openjdk +- /usr/lib64/jvm/java-1.8.0-openjdk +- /usr/lib64/jvm/jre-1.8.0-openjdk ) set(_JNI_JAVA_AWT_LIBRARY_TRIES) diff --git a/Modules/FindJava.cmake b/Modules/FindJava.cmake -index 1587ce648b..e92213cba7 100644 +index 09e9fd7a7a..dad434ec86 100644 --- a/Modules/FindJava.cmake +++ b/Modules/FindJava.cmake -@@ -199,17 +199,6 @@ +@@ -207,17 +207,6 @@ endif() # Hard-coded guesses should still go in PATHS. This ensures that the user # environment can always override hard guesses. set(_JAVA_PATHS @@ -665,10 +677,10 @@ index 1587ce648b..e92213cba7 100644 find_program(Java_JAVA_EXECUTABLE NAMES java diff --git a/Modules/FindKDE3.cmake b/Modules/FindKDE3.cmake -index ccfad5e7fb..265e99eb1a 100644 +index bc6b0e420e..3da4206065 100644 --- a/Modules/FindKDE3.cmake +++ b/Modules/FindKDE3.cmake -@@ -234,9 +234,6 @@ +@@ -240,9 +240,6 @@ find_package(X11 ${_REQ_STRING_KDE3}) find_program(KDECONFIG_EXECUTABLE NAMES kde-config HINTS $ENV{KDEDIR}/bin @@ -678,7 +690,7 @@ index ccfad5e7fb..265e99eb1a 100644 ) set(KDE3PREFIX) -@@ -261,9 +258,6 @@ +@@ -267,9 +264,6 @@ find_path(KDE3_INCLUDE_DIR kpassdlg.h HINTS $ENV{KDEDIR}/include ${KDE3PREFIX}/include @@ -688,7 +700,7 @@ index ccfad5e7fb..265e99eb1a 100644 PATH_SUFFIXES include/kde ) -@@ -272,9 +266,6 @@ +@@ -278,9 +272,6 @@ find_library(KDE3_KDECORE_LIBRARY NAMES kdecore HINTS $ENV{KDEDIR}/lib ${KDE3PREFIX}/lib @@ -698,7 +710,7 @@ index ccfad5e7fb..265e99eb1a 100644 ) set(QT_AND_KDECORE_LIBS ${QT_LIBRARIES} ${KDE3_KDECORE_LIBRARY}) -@@ -296,27 +287,18 @@ +@@ -302,27 +293,18 @@ find_program(KDE3_DCOPIDL_EXECUTABLE NAMES dcopidl HINTS $ENV{KDEDIR}/bin ${KDE3PREFIX}/bin @@ -727,10 +739,10 @@ index ccfad5e7fb..265e99eb1a 100644 diff --git a/Modules/FindKDE4.cmake b/Modules/FindKDE4.cmake -index 220906b2de..7eb7b692d8 100644 +index 04c76da73d..0b78a56867 100644 --- a/Modules/FindKDE4.cmake +++ b/Modules/FindKDE4.cmake -@@ -52,7 +52,6 @@ +@@ -248,7 +248,6 @@ find_program(KDE4_KDECONFIG_EXECUTABLE NAMES kde4-config HINTS ${CMAKE_INSTALL_PREFIX} ${_KDEDIRS} @@ -739,10 +751,10 @@ index 220906b2de..7eb7b692d8 100644 ) diff --git a/Modules/FindLATEX.cmake b/Modules/FindLATEX.cmake -index e272770af3..9f702c3f6d 100644 +index 7db4fc6805..66d92e9c42 100644 --- a/Modules/FindLATEX.cmake +++ b/Modules/FindLATEX.cmake -@@ -203,14 +203,12 @@ +@@ -209,14 +209,12 @@ endif () find_program(LATEX_COMPILER NAMES latex PATHS ${MIKTEX_BINARY_PATH} @@ -757,7 +769,7 @@ index e272770af3..9f702c3f6d 100644 ) if (PDFLATEX_COMPILER) set(LATEX_PDFLATEX_FOUND TRUE) -@@ -222,7 +220,6 @@ +@@ -228,7 +226,6 @@ endif() find_program(XELATEX_COMPILER NAMES xelatex PATHS ${MIKTEX_BINARY_PATH} @@ -765,7 +777,7 @@ index e272770af3..9f702c3f6d 100644 ) if (XELATEX_COMPILER) set(LATEX_XELATEX_FOUND TRUE) -@@ -234,7 +231,6 @@ +@@ -240,7 +237,6 @@ endif() find_program(LUALATEX_COMPILER NAMES lualatex PATHS ${MIKTEX_BINARY_PATH} @@ -773,7 +785,7 @@ index e272770af3..9f702c3f6d 100644 ) if (LUALATEX_COMPILER) set(LATEX_LUALATEX_FOUND TRUE) -@@ -246,7 +242,6 @@ +@@ -252,7 +248,6 @@ endif() find_program(BIBTEX_COMPILER NAMES bibtex PATHS ${MIKTEX_BINARY_PATH} @@ -781,7 +793,7 @@ index e272770af3..9f702c3f6d 100644 ) if (BIBTEX_COMPILER) set(LATEX_BIBTEX_FOUND TRUE) -@@ -258,7 +253,6 @@ +@@ -264,7 +259,6 @@ endif() find_program(BIBER_COMPILER NAMES biber PATHS ${MIKTEX_BINARY_PATH} @@ -789,7 +801,7 @@ index e272770af3..9f702c3f6d 100644 ) if (BIBER_COMPILER) set(LATEX_BIBER_FOUND TRUE) -@@ -270,7 +264,6 @@ +@@ -276,7 +270,6 @@ endif() find_program(MAKEINDEX_COMPILER NAMES makeindex PATHS ${MIKTEX_BINARY_PATH} @@ -797,7 +809,7 @@ index e272770af3..9f702c3f6d 100644 ) if (MAKEINDEX_COMPILER) set(LATEX_MAKEINDEX_FOUND TRUE) -@@ -282,7 +275,6 @@ +@@ -288,7 +281,6 @@ endif() find_program(XINDY_COMPILER NAMES xindy PATHS ${MIKTEX_BINARY_PATH} @@ -805,7 +817,7 @@ index e272770af3..9f702c3f6d 100644 ) if (XINDY_COMPILER) set(LATEX_XINDY_FOUND TRUE) -@@ -294,7 +286,6 @@ +@@ -300,7 +292,6 @@ endif() find_program(DVIPS_CONVERTER NAMES dvips PATHS ${MIKTEX_BINARY_PATH} @@ -813,7 +825,7 @@ index e272770af3..9f702c3f6d 100644 ) if (DVIPS_CONVERTER) set(LATEX_DVIPS_FOUND TRUE) -@@ -306,7 +297,6 @@ +@@ -312,7 +303,6 @@ endif() find_program(DVIPDF_CONVERTER NAMES dvipdfm dvipdft dvipdf PATHS ${MIKTEX_BINARY_PATH} @@ -821,7 +833,7 @@ index e272770af3..9f702c3f6d 100644 ) if (DVIPDF_CONVERTER) set(LATEX_DVIPDF_FOUND TRUE) -@@ -336,7 +326,6 @@ +@@ -342,7 +332,6 @@ endif() find_program(PDFTOPS_CONVERTER NAMES pdftops PATHS ${MIKTEX_BINARY_PATH} @@ -829,7 +841,7 @@ index e272770af3..9f702c3f6d 100644 ) if (PDFTOPS_CONVERTER) set(LATEX_PDFTOPS_FOUND TRUE) -@@ -348,7 +337,6 @@ +@@ -354,7 +343,6 @@ endif() find_program(LATEX2HTML_CONVERTER NAMES latex2html PATHS ${MIKTEX_BINARY_PATH} @@ -837,7 +849,7 @@ index e272770af3..9f702c3f6d 100644 ) if (LATEX2HTML_CONVERTER) set(LATEX_LATEX2HTML_FOUND TRUE) -@@ -360,7 +348,6 @@ +@@ -366,7 +354,6 @@ endif() find_program(HTLATEX_COMPILER NAMES htlatex PATHS ${MIKTEX_BINARY_PATH} @@ -846,10 +858,10 @@ index e272770af3..9f702c3f6d 100644 if (HTLATEX_COMPILER) set(LATEX_HTLATEX_FOUND TRUE) diff --git a/Modules/FindLua50.cmake b/Modules/FindLua50.cmake -index ac36c86640..fe5d2147e8 100644 +index 0651a56708..c3228777f9 100644 --- a/Modules/FindLua50.cmake +++ b/Modules/FindLua50.cmake -@@ -84,10 +84,6 @@ +@@ -102,10 +102,6 @@ find_path(LUA_INCLUDE_DIR lua.h HINTS ENV LUA_DIR PATH_SUFFIXES lua50 lua5.0 lua5 lua @@ -860,7 +872,7 @@ index ac36c86640..fe5d2147e8 100644 ) find_library(LUA_LIBRARY_lua -@@ -95,10 +91,6 @@ +@@ -113,10 +109,6 @@ find_library(LUA_LIBRARY_lua HINTS ENV LUA_DIR PATH_SUFFIXES lib @@ -871,7 +883,7 @@ index ac36c86640..fe5d2147e8 100644 ) # In an OS X framework, lualib is usually included as part of the framework -@@ -113,7 +105,6 @@ +@@ -131,7 +123,6 @@ else() ENV LUA_DIR PATH_SUFFIXES lib PATHS @@ -880,10 +892,10 @@ index ac36c86640..fe5d2147e8 100644 if(LUA_LIBRARY_lualib AND LUA_LIBRARY_lua) # include the math library for Unix diff --git a/Modules/FindLua51.cmake b/Modules/FindLua51.cmake -index cba30e4b58..21a95cb89f 100644 +index ad8a8ea373..9bc6dcb598 100644 --- a/Modules/FindLua51.cmake +++ b/Modules/FindLua51.cmake -@@ -87,10 +87,6 @@ +@@ -115,10 +115,6 @@ find_path(LUA_INCLUDE_DIR lua.h HINTS ENV LUA_DIR PATH_SUFFIXES lua51 lua5.1 lua-5.1 lua @@ -894,7 +906,7 @@ index cba30e4b58..21a95cb89f 100644 ) find_library(LUA_LIBRARY -@@ -98,10 +94,6 @@ +@@ -126,10 +122,6 @@ find_library(LUA_LIBRARY HINTS ENV LUA_DIR PATH_SUFFIXES lib @@ -906,10 +918,10 @@ index cba30e4b58..21a95cb89f 100644 if(LUA_LIBRARY) diff --git a/Modules/FindMPI.cmake b/Modules/FindMPI.cmake -index 78b1c5c915..741f86aaef 100644 +index ebfd79fe3e..4f22333eb1 100644 --- a/Modules/FindMPI.cmake +++ b/Modules/FindMPI.cmake -@@ -1349,15 +1349,6 @@ +@@ -1510,15 +1510,6 @@ macro(MPI_search_mpi_prefix_folder PREFIX_FOLDER) endmacro() set(MPI_HINT_DIRS ${MPI_HOME} $ENV{MPI_HOME} $ENV{I_MPI_ROOT}) @@ -926,10 +938,10 @@ index 78b1c5c915..741f86aaef 100644 # Most MPI distributions have some form of mpiexec or mpirun which gives us something we can look for. # The MPI standard does not mandate the existence of either, but instead only makes requirements if a distribution diff --git a/Modules/FindMatlab.cmake b/Modules/FindMatlab.cmake -index 8a7bd80957..74009fbebc 100644 +index 5f7c83bc51..5890068ba7 100644 --- a/Modules/FindMatlab.cmake +++ b/Modules/FindMatlab.cmake -@@ -1529,7 +1529,7 @@ +@@ -1749,7 +1749,7 @@ function(_Matlab_find_instances_macos matlab_roots) endif() foreach(_matlab_current_release IN LISTS _matlab_releases) @@ -939,10 +951,10 @@ index 8a7bd80957..74009fbebc 100644 string(REPLACE "." "" _matlab_current_version_without_dot "${_matlab_current_version}") set(_matlab_base_path "${_macos_app_base}/MATLAB_${_matlab_current_release}.app") diff --git a/Modules/FindMotif.cmake b/Modules/FindMotif.cmake -index d72b19309e..5753e5c3dc 100644 +index 1ce164c157..f700305dd6 100644 --- a/Modules/FindMotif.cmake +++ b/Modules/FindMotif.cmake -@@ -39,12 +39,10 @@ +@@ -69,12 +69,10 @@ project target: if(UNIX) find_path(MOTIF_INCLUDE_DIR Xm/Xm.h @@ -956,10 +968,10 @@ index d72b19309e..5753e5c3dc 100644 endif() diff --git a/Modules/FindOpenAL.cmake b/Modules/FindOpenAL.cmake -index dad9ada128..32d02db7c3 100644 +index 766c563824..4bc2a7c887 100644 --- a/Modules/FindOpenAL.cmake +++ b/Modules/FindOpenAL.cmake -@@ -95,9 +95,6 @@ +@@ -109,9 +109,6 @@ find_path(OPENAL_INCLUDE_DIR al.h HINTS ENV OPENALDIR PATHS @@ -969,7 +981,7 @@ index dad9ada128..32d02db7c3 100644 [HKEY_LOCAL_MACHINE\\SOFTWARE\\Creative\ Labs\\OpenAL\ 1.1\ Software\ Development\ Kit\\1.00.0000;InstallDir] PATH_SUFFIXES include/AL include/OpenAL include AL OpenAL ) -@@ -113,9 +110,6 @@ +@@ -127,9 +124,6 @@ find_library(OPENAL_LIBRARY HINTS ENV OPENALDIR PATHS @@ -980,10 +992,10 @@ index dad9ada128..32d02db7c3 100644 PATH_SUFFIXES libx32 lib64 lib libs64 libs ${_OpenAL_ARCH_DIR} ) diff --git a/Modules/FindOpenCL.cmake b/Modules/FindOpenCL.cmake -index 3be945ba1b..4086ebe2f2 100644 +index ff4e1d2c9d..b2893cc9cd 100644 --- a/Modules/FindOpenCL.cmake +++ b/Modules/FindOpenCL.cmake -@@ -113,8 +113,6 @@ +@@ -159,8 +159,6 @@ find_path(OpenCL_INCLUDE_DIR ENV CUDA_PATH ENV ATISTREAMSDKROOT ENV OCL_ROOT @@ -992,7 +1004,7 @@ index 3be945ba1b..4086ebe2f2 100644 PATH_SUFFIXES include OpenCL/common/inc -@@ -170,8 +168,6 @@ +@@ -216,8 +214,6 @@ else() PATHS ENV AMDAPPSDKROOT ENV CUDA_PATH @@ -1001,7 +1013,7 @@ index 3be945ba1b..4086ebe2f2 100644 PATH_SUFFIXES lib/x86 lib) -@@ -181,8 +177,6 @@ +@@ -227,8 +223,6 @@ else() PATHS ENV AMDAPPSDKROOT ENV CUDA_PATH @@ -1011,10 +1023,10 @@ index 3be945ba1b..4086ebe2f2 100644 lib/x86_64 lib/x64 diff --git a/Modules/FindOpenGL.cmake b/Modules/FindOpenGL.cmake -index a842756fcf..a02a66eb60 100644 +index 101dbad77e..4bcb5fe6bd 100644 --- a/Modules/FindOpenGL.cmake +++ b/Modules/FindOpenGL.cmake -@@ -271,12 +271,7 @@ +@@ -390,12 +390,7 @@ else() set(_OPENGL_INCLUDE_PATH /boot/develop/headers/os/opengl) elseif (CMAKE_SYSTEM_NAME STREQUAL "Linux") @@ -1028,7 +1040,7 @@ index a842756fcf..a02a66eb60 100644 endif() # The first line below is to make sure that the proper headers -@@ -287,9 +282,6 @@ +@@ -406,9 +401,6 @@ else() # Make sure the NVIDIA directory comes BEFORE the others. # - Atanas Georgiev find_path(OPENGL_INCLUDE_DIR GL/gl.h @@ -1038,7 +1050,7 @@ index a842756fcf..a02a66eb60 100644 ${_OPENGL_INCLUDE_PATH} ) find_path(OPENGL_GLX_INCLUDE_DIR GL/glx.h ${_OPENGL_INCLUDE_PATH}) -@@ -297,9 +289,6 @@ +@@ -416,9 +408,6 @@ else() find_path(OPENGL_GLES2_INCLUDE_DIR GLES2/gl2.h ${_OPENGL_INCLUDE_PATH}) find_path(OPENGL_GLES3_INCLUDE_DIR GLES3/gl3.h ${_OPENGL_INCLUDE_PATH}) find_path(OPENGL_xmesa_INCLUDE_DIR GL/xmesa.h @@ -1048,7 +1060,7 @@ index a842756fcf..a02a66eb60 100644 ) find_path(OPENGL_GLU_INCLUDE_DIR GL/glu.h ${_OPENGL_INCLUDE_PATH}) -@@ -347,9 +336,6 @@ +@@ -466,9 +455,6 @@ else() find_library(OPENGL_glu_LIBRARY NAMES GLU MesaGLU PATHS ${OPENGL_gl_LIBRARY} @@ -1058,7 +1070,7 @@ index a842756fcf..a02a66eb60 100644 ) list(APPEND _OpenGL_CACHE_VARS -@@ -401,10 +387,7 @@ +@@ -520,10 +506,7 @@ else() # Search for the legacy GL library. find_library(OPENGL_gl_LIBRARY NAMES GL MesaGL @@ -1070,7 +1082,7 @@ index a842756fcf..a02a66eb60 100644 PATH_SUFFIXES libglvnd ) list(APPEND _OpenGL_CACHE_VARS OPENGL_gl_LIBRARY) -@@ -513,9 +496,6 @@ +@@ -636,9 +619,6 @@ else() find_library(OPENGL_glu_LIBRARY NAMES GLU MesaGLU PATHS ${OPENGL_gl_LIBRARY} @@ -1081,10 +1093,10 @@ index a842756fcf..a02a66eb60 100644 endif () diff --git a/Modules/FindPHP4.cmake b/Modules/FindPHP4.cmake -index edef791cb8..5515f44710 100644 +index 46509fed52..c2ccc2fee1 100644 --- a/Modules/FindPHP4.cmake +++ b/Modules/FindPHP4.cmake -@@ -36,15 +36,9 @@ +@@ -48,15 +48,9 @@ Finding PHP: #]=======================================================================] set(PHP4_POSSIBLE_INCLUDE_PATHS @@ -1127,10 +1139,10 @@ index fbe1aade72..34562e7807 100644 endif () diff --git a/Modules/FindPhysFS.cmake b/Modules/FindPhysFS.cmake -index 1894498d9d..03c6e61853 100644 +index 6031d17bf9..2685d2017f 100644 --- a/Modules/FindPhysFS.cmake +++ b/Modules/FindPhysFS.cmake -@@ -52,10 +52,6 @@ +@@ -68,10 +68,6 @@ find_path(PHYSFS_INCLUDE_DIR physfs.h HINTS ENV PHYSFSDIR PATH_SUFFIXES include/physfs include @@ -1141,7 +1153,7 @@ index 1894498d9d..03c6e61853 100644 ) find_library(PHYSFS_LIBRARY -@@ -63,10 +59,6 @@ +@@ -79,10 +75,6 @@ find_library(PHYSFS_LIBRARY HINTS ENV PHYSFSDIR PATH_SUFFIXES lib @@ -1153,10 +1165,10 @@ index 1894498d9d..03c6e61853 100644 include(FindPackageHandleStandardArgs) diff --git a/Modules/FindPkgConfig.cmake b/Modules/FindPkgConfig.cmake -index b230eb5ef5..bf7b204406 100644 +index 924284a46e..75692d033e 100644 --- a/Modules/FindPkgConfig.cmake +++ b/Modules/FindPkgConfig.cmake -@@ -391,7 +391,7 @@ +@@ -845,7 +845,7 @@ macro(_pkg_set_path_internal) if(NOT DEFINED CMAKE_SYSTEM_NAME OR (CMAKE_SYSTEM_NAME MATCHES "^(Linux|GNU)$" AND NOT CMAKE_CROSSCOMPILING)) @@ -1166,10 +1178,10 @@ index b230eb5ef5..bf7b204406 100644 list(APPEND _lib_dirs "lib/${CMAKE_LIBRARY_ARCHITECTURE}/pkgconfig") endif() diff --git a/Modules/FindProducer.cmake b/Modules/FindProducer.cmake -index 1d034bc207..d176655f46 100644 +index 7fbd837344..a09978f7aa 100644 --- a/Modules/FindProducer.cmake +++ b/Modules/FindProducer.cmake -@@ -100,9 +100,6 @@ +@@ -116,9 +116,6 @@ find_path(PRODUCER_INCLUDE_DIR Producer/CameraGroup ENV OSGDIR PATH_SUFFIXES include PATHS @@ -1179,7 +1191,7 @@ index 1d034bc207..d176655f46 100644 [HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Session\ Manager\\Environment;OpenThreads_ROOT] [HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Session\ Manager\\Environment;OSG_ROOT] ) -@@ -114,8 +111,6 @@ +@@ -130,8 +127,6 @@ find_library(PRODUCER_LIBRARY ENV OSG_DIR ENV OSGDIR PATH_SUFFIXES lib @@ -1189,10 +1201,10 @@ index 1d034bc207..d176655f46 100644 include(FindPackageHandleStandardArgs) diff --git a/Modules/FindPython/Support.cmake b/Modules/FindPython/Support.cmake -index a9441646d1..28ba743f60 100644 +index de9fba3a76..96b70fdd72 100644 --- a/Modules/FindPython/Support.cmake +++ b/Modules/FindPython/Support.cmake -@@ -162,9 +162,6 @@ +@@ -162,9 +162,6 @@ macro (_PYTHON_FIND_FRAMEWORKS) file(TO_CMAKE_PATH "$ENV{CMAKE_FRAMEWORK_PATH}" _pff_CMAKE_FRAMEWORK_PATH) set (_pff_frameworks ${CMAKE_FRAMEWORK_PATH} ${_pff_CMAKE_FRAMEWORK_PATH} @@ -1203,10 +1215,10 @@ index a9441646d1..28ba743f60 100644 list (REMOVE_DUPLICATES _pff_frameworks) foreach (_pff_implementation IN LISTS _${_PYTHON_PREFIX}_FIND_IMPLEMENTATIONS) diff --git a/Modules/FindQt.cmake b/Modules/FindQt.cmake -index 98cd1e2abf..90ad88365d 100644 +index 9fc83e6279..6a140bac21 100644 --- a/Modules/FindQt.cmake +++ b/Modules/FindQt.cmake -@@ -63,44 +63,6 @@ +@@ -68,44 +68,6 @@ if(_findqt_testing) return() endif() @@ -1251,7 +1263,7 @@ index 98cd1e2abf..90ad88365d 100644 if (Qt_FIND_VERSION) if (Qt_FIND_VERSION MATCHES "^([34])(\\.[0-9]+.*)?$") set(DESIRED_QT_VERSION ${CMAKE_MATCH_1}) -@@ -135,9 +97,6 @@ +@@ -140,9 +102,6 @@ find_file( QT4_QGLOBAL_H_FILE qglobal.h "[HKEY_CURRENT_USER\\Software\\Trolltech\\Versions\\4.0.0;InstallDir]/include/Qt" ${qt_headers}/Qt $ENV{QTDIR}/include/Qt @@ -1261,7 +1273,7 @@ index 98cd1e2abf..90ad88365d 100644 C:/Progra~1/qt/include/Qt PATH_SUFFIXES qt/include/Qt include/Qt) -@@ -152,9 +111,6 @@ +@@ -157,9 +116,6 @@ find_file( QT3_QGLOBAL_H_FILE qglobal.h "[HKEY_CURRENT_USER\\Software\\Trolltech\\Qt3Versions\\3.1.0;InstallDir]/include/Qt" C:/Qt/3.3.3Educational/include $ENV{QTDIR}/include @@ -1272,10 +1284,10 @@ index 98cd1e2abf..90ad88365d 100644 PATH_SUFFIXES qt/include include/qt3) diff --git a/Modules/FindQt3.cmake b/Modules/FindQt3.cmake -index 2c62a5f17f..772a8d88f6 100644 +index f72261ea0e..7617702faa 100644 --- a/Modules/FindQt3.cmake +++ b/Modules/FindQt3.cmake -@@ -101,10 +101,6 @@ +@@ -125,10 +125,6 @@ if(Qt4_FOUND) endif() @@ -1286,7 +1298,7 @@ index 2c62a5f17f..772a8d88f6 100644 find_path(QT_INCLUDE_DIR NAMES qt.h PATHS -@@ -112,10 +108,7 @@ +@@ -136,10 +132,7 @@ find_path(QT_INCLUDE_DIR "[HKEY_CURRENT_USER\\Software\\Trolltech\\Qt3Versions\\3.2.0;InstallDir]/include/Qt" "[HKEY_CURRENT_USER\\Software\\Trolltech\\Qt3Versions\\3.1.0;InstallDir]/include/Qt" $ENV{QTDIR}/include @@ -1297,15 +1309,15 @@ index 2c62a5f17f..772a8d88f6 100644 PATH_SUFFIXES lib/qt/include lib/qt3/include include/qt include/qt3 qt/include qt3/include ) -@@ -137,7 +130,6 @@ - set(QT_VERSION_STRING "${qt_version_str}") +@@ -162,7 +155,6 @@ if(QT_INCLUDE_DIR) + set(QT_VERSION_STRING "${Qt3_VERSION}") endif() -file(GLOB GLOB_PATHS_LIB /usr/lib/qt-3*/lib/) if (QT_MT_REQUIRED) find_library(QT_QT_LIBRARY NAMES -@@ -148,8 +140,6 @@ +@@ -173,8 +165,6 @@ if (QT_MT_REQUIRED) "[HKEY_CURRENT_USER\\Software\\Trolltech\\Qt3Versions\\3.2.0;InstallDir]" "[HKEY_CURRENT_USER\\Software\\Trolltech\\Qt3Versions\\3.1.0;InstallDir]" ENV QTDIR @@ -1314,7 +1326,7 @@ index 2c62a5f17f..772a8d88f6 100644 C:/Progra~1/qt PATH_SUFFIXES lib lib/qt lib/qt3 qt qt3 qt/lib qt3/lib -@@ -166,8 +156,6 @@ +@@ -191,8 +181,6 @@ else () "[HKEY_CURRENT_USER\\Software\\Trolltech\\Qt3Versions\\3.2.0;InstallDir]" "[HKEY_CURRENT_USER\\Software\\Trolltech\\Qt3Versions\\3.1.0;InstallDir]" ENV QTDIR @@ -1323,7 +1335,7 @@ index 2c62a5f17f..772a8d88f6 100644 C:/Progra~1/qt/lib PATH_SUFFIXES lib lib/qt lib/qt3 qt qt3 qt/lib qt3/lib -@@ -182,8 +170,6 @@ +@@ -207,8 +195,6 @@ find_library(QT_QASSISTANTCLIENT_LIBRARY "[HKEY_CURRENT_USER\\Software\\Trolltech\\Qt3Versions\\3.2.0;InstallDir]" "[HKEY_CURRENT_USER\\Software\\Trolltech\\Qt3Versions\\3.1.0;InstallDir]" ENV QTDIR @@ -1332,7 +1344,7 @@ index 2c62a5f17f..772a8d88f6 100644 C:/Progra~1/qt PATH_SUFFIXES lib lib/qt lib/qt3 qt qt3 qt/lib qt3/lib -@@ -198,8 +184,6 @@ +@@ -223,8 +209,6 @@ find_program(QT_MOC_EXECUTABLE "[HKEY_CURRENT_USER\\Software\\Trolltech\\Qt3Versions\\3.2.1;InstallDir]/include/Qt" "[HKEY_CURRENT_USER\\Software\\Trolltech\\Qt3Versions\\3.2.0;InstallDir]/include/Qt" "[HKEY_CURRENT_USER\\Software\\Trolltech\\Qt3Versions\\3.1.0;InstallDir]/include/Qt" @@ -1341,7 +1353,7 @@ index 2c62a5f17f..772a8d88f6 100644 C:/Progra~1/qt PATH_SUFFIXES bin lib/qt lib/qt3 qt qt3 qt/bin qt3/bin lib/qt/bin lib/qt3/bin -@@ -218,8 +202,6 @@ +@@ -243,8 +227,6 @@ find_program(QT_UIC_EXECUTABLE "[HKEY_CURRENT_USER\\Software\\Trolltech\\Qt3Versions\\3.2.1;InstallDir]/include/Qt" "[HKEY_CURRENT_USER\\Software\\Trolltech\\Qt3Versions\\3.2.0;InstallDir]/include/Qt" "[HKEY_CURRENT_USER\\Software\\Trolltech\\Qt3Versions\\3.1.0;InstallDir]/include/Qt" @@ -1351,7 +1363,7 @@ index 2c62a5f17f..772a8d88f6 100644 PATH_SUFFIXES bin lib/qt lib/qt3 qt qt3 qt/bin qt3/bin lib/qt/bin lib/qt3/bin diff --git a/Modules/FindRuby.cmake b/Modules/FindRuby.cmake -index 863f70a7f2..17e3ac606a 100644 +index 6f865da129..831ca2251b 100644 --- a/Modules/FindRuby.cmake +++ b/Modules/FindRuby.cmake @@ -366,11 +366,6 @@ if (NOT Ruby_EXECUTABLE AND Ruby_FIND_VIRTUALENV MATCHES "^(FIRST|ONLY)$") @@ -1367,10 +1379,10 @@ index 863f70a7f2..17e3ac606a 100644 if (NOT Ruby_EXECUTABLE AND NOT Ruby_FIND_VIRTUALENV STREQUAL "ONLY") _RUBY_CHECK_SYSTEM() diff --git a/Modules/FindSDL.cmake b/Modules/FindSDL.cmake -index a720dcc3df..73e222a27c 100644 +index 5bd34bb642..7e53285860 100644 --- a/Modules/FindSDL.cmake +++ b/Modules/FindSDL.cmake -@@ -214,8 +214,6 @@ +@@ -220,8 +220,6 @@ if(NOT SDL_BUILDING_LIBRARY) HINTS ENV SDLDIR PATH_SUFFIXES lib ${VC_LIB_PATH_SUFFIX} @@ -1380,10 +1392,10 @@ index a720dcc3df..73e222a27c 100644 endif() endif() diff --git a/Modules/FindSDL_sound.cmake b/Modules/FindSDL_sound.cmake -index 954303f3d3..26a5781e2a 100644 +index 19fc2cd081..457a139414 100644 --- a/Modules/FindSDL_sound.cmake +++ b/Modules/FindSDL_sound.cmake -@@ -292,7 +292,6 @@ +@@ -317,7 +317,6 @@ if(SDL_FOUND AND SDL_SOUND_INCLUDE_DIR AND SDL_SOUND_LIBRARY) ENV MIKMODDIR ENV SDLSOUNDDIR ENV SDLDIR @@ -1391,7 +1403,7 @@ index 954303f3d3..26a5781e2a 100644 PATH_SUFFIXES lib ) -@@ -309,7 +308,6 @@ +@@ -334,7 +333,6 @@ if(SDL_FOUND AND SDL_SOUND_INCLUDE_DIR AND SDL_SOUND_LIBRARY) ENV MODPLUGDIR ENV SDLSOUNDDIR ENV SDLDIR @@ -1399,7 +1411,7 @@ index 954303f3d3..26a5781e2a 100644 PATH_SUFFIXES lib ) -@@ -328,7 +326,6 @@ +@@ -353,7 +351,6 @@ if(SDL_FOUND AND SDL_SOUND_INCLUDE_DIR AND SDL_SOUND_LIBRARY) ENV OGGDIR ENV SDLSOUNDDIR ENV SDLDIR @@ -1407,7 +1419,7 @@ index 954303f3d3..26a5781e2a 100644 PATH_SUFFIXES lib ) -@@ -343,7 +340,6 @@ +@@ -368,7 +365,6 @@ if(SDL_FOUND AND SDL_SOUND_INCLUDE_DIR AND SDL_SOUND_LIBRARY) ENV VORBISDIR ENV SDLSOUNDDIR ENV SDLDIR @@ -1415,7 +1427,7 @@ index 954303f3d3..26a5781e2a 100644 PATH_SUFFIXES lib ) -@@ -361,7 +357,6 @@ +@@ -386,7 +382,6 @@ if(SDL_FOUND AND SDL_SOUND_INCLUDE_DIR AND SDL_SOUND_LIBRARY) ENV SMPEGDIR ENV SDLSOUNDDIR ENV SDLDIR @@ -1423,7 +1435,7 @@ index 954303f3d3..26a5781e2a 100644 PATH_SUFFIXES lib ) -@@ -379,7 +374,6 @@ +@@ -404,7 +399,6 @@ if(SDL_FOUND AND SDL_SOUND_INCLUDE_DIR AND SDL_SOUND_LIBRARY) ENV FLACDIR ENV SDLSOUNDDIR ENV SDLDIR @@ -1431,7 +1443,7 @@ index 954303f3d3..26a5781e2a 100644 PATH_SUFFIXES lib ) -@@ -400,7 +394,6 @@ +@@ -425,7 +419,6 @@ if(SDL_FOUND AND SDL_SOUND_INCLUDE_DIR AND SDL_SOUND_LIBRARY) ENV SPEEXDIR ENV SDLSOUNDDIR ENV SDLDIR @@ -1439,7 +1451,7 @@ index 954303f3d3..26a5781e2a 100644 PATH_SUFFIXES lib ) -@@ -419,7 +412,6 @@ +@@ -444,7 +437,6 @@ if(SDL_FOUND AND SDL_SOUND_INCLUDE_DIR AND SDL_SOUND_LIBRARY) ENV SPEEXDIR ENV SDLSOUNDDIR ENV SDLDIR @@ -1448,10 +1460,10 @@ index 954303f3d3..26a5781e2a 100644 ) if(OGG_LIBRARY) diff --git a/Modules/FindX11.cmake b/Modules/FindX11.cmake -index b2f23bd1dd..9a94529589 100644 +index 93aa9329ea..20973713fb 100644 --- a/Modules/FindX11.cmake +++ b/Modules/FindX11.cmake -@@ -138,22 +138,9 @@ +@@ -151,22 +151,9 @@ if (UNIX) set(CMAKE_REQUIRED_QUIET_SAVE ${CMAKE_REQUIRED_QUIET}) set(CMAKE_REQUIRED_QUIET ${X11_FIND_QUIETLY}) set(X11_INC_SEARCH_PATH @@ -1475,10 +1487,10 @@ index b2f23bd1dd..9a94529589 100644 find_path(X11_X11_INCLUDE_PATH X11/X.h ${X11_INC_SEARCH_PATH}) diff --git a/Modules/GNUInstallDirs.cmake b/Modules/GNUInstallDirs.cmake -index ff9c11a9d7..706b34b087 100644 +index d626688c5f..8f87b5c129 100644 --- a/Modules/GNUInstallDirs.cmake +++ b/Modules/GNUInstallDirs.cmake -@@ -336,17 +336,6 @@ +@@ -363,17 +363,6 @@ function(_GNUInstallDirs_get_system_type_for_install out_var) set(${out_var} "conda") endif() endif() @@ -1497,10 +1509,10 @@ index ff9c11a9d7..706b34b087 100644 endfunction() diff --git a/Modules/GetPrerequisites.cmake b/Modules/GetPrerequisites.cmake -index f1f5db7b7b..9b4bdddb36 100644 +index 952e66c0d1..553810fd8c 100644 --- a/Modules/GetPrerequisites.cmake +++ b/Modules/GetPrerequisites.cmake -@@ -458,11 +458,9 @@ +@@ -506,11 +506,9 @@ function(gp_resolve_item context item exepath dirs resolved_item_var) if(NOT resolved) set(ri "ri-NOTFOUND") find_file(ri "${item}" ${exepath} ${dirs} NO_DEFAULT_PATH) @@ -1512,7 +1524,7 @@ index f1f5db7b7b..9b4bdddb36 100644 if(ri) #message(STATUS "info: 'find_file' in exepath/dirs (${ri})") -@@ -472,23 +470,6 @@ +@@ -520,23 +518,6 @@ function(gp_resolve_item context item exepath dirs resolved_item_var) endif() endif() @@ -1537,10 +1549,10 @@ index f1f5db7b7b..9b4bdddb36 100644 # (Converting simple file names into full path names if found.) # diff --git a/Modules/Internal/CMakeCUDAFindToolkit.cmake b/Modules/Internal/CMakeCUDAFindToolkit.cmake -index 8fd408994f..61894813a2 100644 +index ff67ef0755..586e28d8aa 100644 --- a/Modules/Internal/CMakeCUDAFindToolkit.cmake +++ b/Modules/Internal/CMakeCUDAFindToolkit.cmake -@@ -50,18 +50,8 @@ +@@ -50,18 +50,8 @@ macro(cmake_cuda_find_toolkit lang lang_var_) # if CUDAToolkit_ROOT is not specified, it is assumed that the symlinked # directory is the desired location. if(NOT _CUDA_NVCC_EXECUTABLE) @@ -1560,7 +1572,7 @@ index 8fd408994f..61894813a2 100644 # Iterate the glob results and create a descending list. set(versions) foreach(p ${possible_paths}) -@@ -77,14 +67,6 @@ +@@ -77,14 +67,6 @@ macro(cmake_cuda_find_toolkit lang lang_var_) # With a descending list of versions, populate possible paths to search. set(search_paths) @@ -1575,7 +1587,7 @@ index 8fd408994f..61894813a2 100644 # Now search for nvcc again using the platform default search paths. find_program(_CUDA_NVCC_EXECUTABLE -@@ -140,23 +122,13 @@ +@@ -141,23 +123,13 @@ macro(cmake_cuda_find_toolkit lang lang_var_) set(${lang_var_}LIBRARY_ROOT "${_CUDA_COMPILER_LIBRARY_ROOT_FROM_NVVMIR_LIBRARY_DIR}") elseif(EXISTS "${${lang_var_}TOOLKIT_ROOT}/nvvm/libdevice") set(${lang_var_}LIBRARY_ROOT "${${lang_var_}TOOLKIT_ROOT}") @@ -1601,10 +1613,10 @@ index 8fd408994f..61894813a2 100644 # For regular nvcc we the toolkit version is the same as the compiler version and we can parse it from the vendor test output. # For Clang we need to invoke nvcc to get version output. diff --git a/Modules/Internal/CPack/CPackRPM.cmake b/Modules/Internal/CPack/CPackRPM.cmake -index b733cfe964..90709f48e8 100644 +index 84665506d9..2b07f479f0 100644 --- a/Modules/Internal/CPack/CPackRPM.cmake +++ b/Modules/Internal/CPack/CPackRPM.cmake -@@ -640,7 +640,7 @@ +@@ -648,7 +648,7 @@ function(cpack_rpm_debugsymbol_check INSTALL_FILES WORKING_DIR) endif() # With debugedit we prepare source files list @@ -1617,7 +1629,7 @@ diff --git a/Modules/Platform/CYGWIN.cmake b/Modules/Platform/CYGWIN.cmake index cf5e732833..1bbbfeca54 100644 --- a/Modules/Platform/CYGWIN.cmake +++ b/Modules/Platform/CYGWIN.cmake -@@ -15,13 +15,3 @@ +@@ -15,13 +15,3 @@ set(CMAKE_FIND_LIBRARY_SUFFIXES ".dll.a" ".a") set(CMAKE_SHARED_LIBRARY_NAME_WITH_VERSION 1) include(Platform/UnixPaths) @@ -1632,7 +1644,7 @@ index cf5e732833..1bbbfeca54 100644 - /usr/lib/w32api - ) diff --git a/Modules/Platform/Darwin-Initialize.cmake b/Modules/Platform/Darwin-Initialize.cmake -index 7c4f123a1d..4cfd53de9f 100644 +index f5491ef048..1c44eb7fa0 100644 --- a/Modules/Platform/Darwin-Initialize.cmake +++ b/Modules/Platform/Darwin-Initialize.cmake @@ -1,19 +1,7 @@ @@ -1654,9 +1666,9 @@ index 7c4f123a1d..4cfd53de9f 100644 -endif() +set(OSX_DEVELOPER_ROOT "") - if(NOT CMAKE_CROSSCOMPILING) - execute_process(COMMAND @sw_vers@ -productVersion -@@ -277,13 +277,6 @@ if(NOT CMAKE_OSX_SYSROOT) + # Save CMAKE_OSX_ARCHITECTURES from the environment. + set(CMAKE_OSX_ARCHITECTURES "$ENV{CMAKE_OSX_ARCHITECTURES}" CACHE STRING +@@ -277,13 +265,6 @@ if(NOT CMAKE_OSX_SYSROOT) RESULT_VARIABLE _result ) unset(_sdk_macosx) @@ -1671,10 +1683,10 @@ index 7c4f123a1d..4cfd53de9f 100644 #---------------------------------------------------------------------------- diff --git a/Modules/Platform/Darwin.cmake b/Modules/Platform/Darwin.cmake -index 42c6b35424..f2985f3765 100644 +index bd4673248c..9cdbbb964a 100644 --- a/Modules/Platform/Darwin.cmake +++ b/Modules/Platform/Darwin.cmake -@@ -166,7 +166,6 @@ +@@ -156,7 +156,6 @@ endif() # set up the default search directories for frameworks set(CMAKE_SYSTEM_FRAMEWORK_PATH @@ -1682,7 +1694,7 @@ index 42c6b35424..f2985f3765 100644 ) if(_CMAKE_OSX_SYSROOT_PATH) list(APPEND CMAKE_SYSTEM_FRAMEWORK_PATH -@@ -201,10 +200,6 @@ +@@ -191,10 +190,6 @@ if (OSX_DEVELOPER_ROOT AND EXISTS "${OSX_DEVELOPER_ROOT}/Library/Frameworks") list(APPEND CMAKE_SYSTEM_FRAMEWORK_PATH ${OSX_DEVELOPER_ROOT}/Library/Frameworks) endif() @@ -1693,7 +1705,7 @@ index 42c6b35424..f2985f3765 100644 # Warn about known system misconfiguration case. if(CMAKE_OSX_SYSROOT) -@@ -230,10 +225,6 @@ +@@ -220,10 +215,6 @@ endif() # set up the default search directories for application bundles set(_apps_paths) foreach(_path @@ -1704,7 +1716,7 @@ index 42c6b35424..f2985f3765 100644 ) get_filename_component(_apps "${_path}" ABSOLUTE) if(EXISTS "${_apps}") -@@ -249,28 +240,6 @@ +@@ -239,28 +230,6 @@ unset(_apps_paths) include(Platform/UnixPaths) @@ -1733,7 +1745,7 @@ index 42c6b35424..f2985f3765 100644 if(_CMAKE_OSX_SYSROOT_PATH) if(EXISTS ${_CMAKE_OSX_SYSROOT_PATH}/usr/include) list(INSERT CMAKE_SYSTEM_PREFIX_PATH 0 ${_CMAKE_OSX_SYSROOT_PATH}/usr) -@@ -285,7 +254,3 @@ +@@ -275,7 +244,3 @@ if(_CMAKE_OSX_SYSROOT_PATH) endforeach() endif() endif() @@ -1745,7 +1757,7 @@ diff --git a/Modules/Platform/GNU.cmake b/Modules/Platform/GNU.cmake index 6a25b00b81..2430bdb7e4 100644 --- a/Modules/Platform/GNU.cmake +++ b/Modules/Platform/GNU.cmake -@@ -48,13 +48,8 @@ +@@ -48,13 +48,8 @@ else() # checking the platform every time. This option is advanced enough # that only package maintainers should need to adjust it. They are # capable of providing a setting on the command line. @@ -1765,7 +1777,7 @@ diff --git a/Modules/Platform/Linux.cmake b/Modules/Platform/Linux.cmake index 5b61dd6b61..d324b903ed 100644 --- a/Modules/Platform/Linux.cmake +++ b/Modules/Platform/Linux.cmake -@@ -45,25 +45,8 @@ +@@ -45,25 +45,8 @@ else() # checking the platform every time. This option is advanced enough # that only package maintainers should need to adjust it. They are # capable of providing a setting on the command line. @@ -1794,10 +1806,10 @@ index 5b61dd6b61..d324b903ed 100644 - endif() -endif() diff --git a/Modules/Platform/OpenBSD.cmake b/Modules/Platform/OpenBSD.cmake -index 97e2a6a83e..02c607618c 100644 +index 71bb99eb2f..01a1d04ffa 100644 --- a/Modules/Platform/OpenBSD.cmake +++ b/Modules/Platform/OpenBSD.cmake -@@ -31,13 +31,9 @@ +@@ -34,13 +34,9 @@ set(CMAKE_INSTALL_SO_NO_EXE 1) if($ENV{LOCALBASE}) set(OPENBSD_LOCALBASE $ENV{LOCALBASE}) @@ -1815,7 +1827,7 @@ diff --git a/Modules/Platform/SunOS.cmake b/Modules/Platform/SunOS.cmake index e01e892283..d044d81c88 100644 --- a/Modules/Platform/SunOS.cmake +++ b/Modules/Platform/SunOS.cmake -@@ -19,11 +19,6 @@ +@@ -19,11 +19,6 @@ endif() include(Platform/UnixPaths) @@ -1828,7 +1840,7 @@ index e01e892283..d044d81c88 100644 # in the -L path. set(CMAKE_LINK_DEPENDENT_LIBRARY_DIRS 1) diff --git a/Modules/Platform/UnixPaths.cmake b/Modules/Platform/UnixPaths.cmake -index bdf4155232..588064821d 100644 +index ba9974c316..f8f00b487a 100644 --- a/Modules/Platform/UnixPaths.cmake +++ b/Modules/Platform/UnixPaths.cmake @@ -35,10 +35,6 @@ unset(_cmake_running_in_build_tree) @@ -1842,7 +1854,7 @@ index bdf4155232..588064821d 100644 if(_CMAKE_INSTALL_DIR) list(APPEND CMAKE_SYSTEM_PREFIX_PATH # CMake install location -@@ -49,28 +46,6 @@ +@@ -59,28 +55,6 @@ if (NOT CMAKE_FIND_NO_INSTALL_PREFIX) endif() _cmake_record_install_prefix() @@ -1872,10 +1884,10 @@ index bdf4155232..588064821d 100644 if(DEFINED ENV{NIX_CC} AND IS_DIRECTORY "$ENV{NIX_CC}" diff --git a/Modules/Platform/WindowsPaths.cmake b/Modules/Platform/WindowsPaths.cmake -index c56dfaf9ac..4e0b250c1a 100644 +index 0f19b95e85..09143ef09f 100644 --- a/Modules/Platform/WindowsPaths.cmake +++ b/Modules/Platform/WindowsPaths.cmake -@@ -69,11 +69,6 @@ +@@ -79,11 +79,6 @@ if (NOT CMAKE_FIND_NO_INSTALL_PREFIX) endif() _cmake_record_install_prefix() @@ -1888,11 +1900,11 @@ index c56dfaf9ac..4e0b250c1a 100644 ) diff --git a/Modules/ProcessorCount.cmake b/Modules/ProcessorCount.cmake -index ffb8fcd8d2..6b8fcf87dc 100644 +index 7c3112b817..8464875df2 100644 --- a/Modules/ProcessorCount.cmake +++ b/Modules/ProcessorCount.cmake -@@ -128,7 +128,7 @@ - if(NOT count) +@@ -131,7 +131,7 @@ function(ProcessorCount var) + if(NOT (_count_ok EQUAL 0 AND count GREATER 0)) # HPUX (systems with machinfo): find_program(ProcessorCount_cmd_machinfo machinfo - PATHS /usr/contrib/bin) @@ -1900,8 +1912,8 @@ index ffb8fcd8d2..6b8fcf87dc 100644 mark_as_advanced(ProcessorCount_cmd_machinfo) if(ProcessorCount_cmd_machinfo) execute_process(COMMAND ${ProcessorCount_cmd_machinfo} -@@ -160,7 +160,7 @@ - if(NOT count) +@@ -166,7 +166,7 @@ function(ProcessorCount var) + if(NOT count GREATER 0) # AIX (systems with lsconf): find_program(ProcessorCount_cmd_lsconf lsconf - PATHS /usr/sbin) @@ -1909,9 +1921,9 @@ index ffb8fcd8d2..6b8fcf87dc 100644 mark_as_advanced(ProcessorCount_cmd_lsconf) if(ProcessorCount_cmd_lsconf) execute_process(COMMAND ${ProcessorCount_cmd_lsconf} -@@ -190,7 +190,7 @@ +@@ -202,7 +202,7 @@ function(ProcessorCount var) - if(NOT count) + if(NOT count GREATER 0) # Sun (systems where psrinfo tool is available) - find_program(ProcessorCount_cmd_psrinfo psrinfo PATHS /usr/sbin /sbin) + find_program(ProcessorCount_cmd_psrinfo psrinfo) @@ -1919,10 +1931,10 @@ index ffb8fcd8d2..6b8fcf87dc 100644 if (ProcessorCount_cmd_psrinfo) execute_process(COMMAND ${ProcessorCount_cmd_psrinfo} -p -v diff --git a/Modules/UseJava.cmake b/Modules/UseJava.cmake -index b977d955ca..5ff835298d 100644 +index 4192169e0e..b4ca13e363 100644 --- a/Modules/UseJava.cmake +++ b/Modules/UseJava.cmake -@@ -1125,8 +1125,6 @@ +@@ -1182,8 +1182,6 @@ function (find_jar VARIABLE) set(_jar_files) set(_jar_versions) set(_jar_paths @@ -1932,10 +1944,10 @@ index b977d955ca..5ff835298d 100644 set(_jar_doc "NOTSET") diff --git a/Utilities/cmcurl/CMakeLists.txt b/Utilities/cmcurl/CMakeLists.txt -index 2c6a6e6a19..3a43da619a 100644 +index 5b9cdcb217..ab9a0454fb 100644 --- a/Utilities/cmcurl/CMakeLists.txt +++ b/Utilities/cmcurl/CMakeLists.txt -@@ -1566,43 +1566,6 @@ if(_curl_ca_bundle_supported) +@@ -1649,43 +1649,6 @@ if(_curl_ca_bundle_supported) endif() mark_as_advanced(CURL_CA_PATH_SET) @@ -1980,7 +1992,7 @@ index 2c6a6e6a19..3a43da619a 100644 if(BUILD_CURL_EXE AND NOT CURL_CA_EMBED STREQUAL "") if(EXISTS "${CURL_CA_EMBED}") diff --git a/Utilities/cmlibarchive/CMakeLists.txt b/Utilities/cmlibarchive/CMakeLists.txt -index e6ab5de99b..158a407c3e 100644 +index d094dc3753..78cfe39a6b 100644 --- a/Utilities/cmlibarchive/CMakeLists.txt +++ b/Utilities/cmlibarchive/CMakeLists.txt @@ -44,11 +44,6 @@ ENDIF(NOT "${CMAKE_BUILD_TYPE_UPPER}" diff --git a/pkgs/by-name/co/cockpit-zfs/package.nix b/pkgs/by-name/co/cockpit-zfs/package.nix index 2ccadc3f3197..4599d759083e 100644 --- a/pkgs/by-name/co/cockpit-zfs/package.nix +++ b/pkgs/by-name/co/cockpit-zfs/package.nix @@ -1,7 +1,6 @@ { acl, bash, - buildPackages, cockpit, coreutils, fetchFromGitHub, @@ -15,7 +14,7 @@ mbuffer, msmtp, nix-update-script, - nodejs_22, + nodejs, openssh, samba, shadow, @@ -27,22 +26,6 @@ yarn-berry, zfs, }: -let - # Pin to Node <24.15.0: Yarn Berry's PnP linker breaks `require.cache` on - # newer Node, which crashes tailwindcss mid-build (and ESLint, per - # yarnpkg/berry#7106). See NixOS/nixpkgs#530137. - # - # `nodejs` is rebound here (rather than touched at every call site below) - # so the rest of this file is unaffected. - # - # yarn-berry's own `yarn` binary gets patchShebang'd against whatever - # `nodejs` *it* was built with, so overriding nativeBuildInputs alone does - # nothing - we have to rebuild yarn-berry itself against nodejs_22, for - # both the host and build-platform (cross-compilation) variants. - nodejs = nodejs_22; - yarnBerry = yarn-berry.override { inherit nodejs; }; - yarnBerryForBuild = buildPackages.yarn-berry.override { nodejs = buildPackages.nodejs_22; }; -in stdenv.mkDerivation (finalAttrs: { pname = "cockpit-zfs"; @@ -59,17 +42,17 @@ stdenv.mkDerivation (finalAttrs: { missingHashes = ./missing-hashes.json; # Use buildPackages for cross-compilation support - offlineCache = yarnBerryForBuild.fetchYarnBerryDeps { + offlineCache = yarn-berry.fetchYarnBerryDeps { inherit (finalAttrs) src missingHashes; hash = "sha256-nm3iHf9Rm5JFKzH0HAvglkQPFIV6Fl1e9WvNdqevTug="; }; nativeBuildInputs = [ makeWrapper - nodejs_22 + nodejs jq - yarnBerry - yarnBerryForBuild.yarnBerryConfigHook + yarn-berry + yarn-berry.yarnBerryConfigHook ]; disallowedRequisites = [ finalAttrs.offlineCache ]; @@ -86,7 +69,7 @@ stdenv.mkDerivation (finalAttrs: { lsscsi mbuffer msmtp - nodejs_22 + nodejs openssh samba shadow diff --git a/pkgs/by-name/co/convimg/package.nix b/pkgs/by-name/co/convimg/package.nix index 505ac4ff7dc7..f148bfc9d3d0 100644 --- a/pkgs/by-name/co/convimg/package.nix +++ b/pkgs/by-name/co/convimg/package.nix @@ -42,5 +42,6 @@ stdenv.mkDerivation (finalAttrs: { maintainers = [ ]; platforms = lib.platforms.linux; mainProgram = "convimg"; + broken = true; }; }) diff --git a/pkgs/by-name/co/cowsql/package.nix b/pkgs/by-name/co/cowsql/package.nix index d672b987265c..d524cd0a16db 100644 --- a/pkgs/by-name/co/cowsql/package.nix +++ b/pkgs/by-name/co/cowsql/package.nix @@ -9,6 +9,7 @@ sqlite, incus, nix-update-script, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -22,6 +23,14 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-7djVcozWklI/0KhDC20df+H3YQbodUZaXBnQT4Ug8oI="; }; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/cowsql/cowsql/commit/7c4d73151969ead4f81077ae243d81396ce67988.patch"; + hash = "sha256-aJkf3egKbF23KNC0feDkxh8gIEupsyDBY3PTKuT6lcQ="; + }) + ]; + nativeBuildInputs = [ autoreconfHook pkg-config diff --git a/pkgs/by-name/cr/criu/package.nix b/pkgs/by-name/cr/criu/package.nix index f96504b19735..f4e0b527fd66 100644 --- a/pkgs/by-name/cr/criu/package.nix +++ b/pkgs/by-name/cr/criu/package.nix @@ -45,6 +45,12 @@ stdenv.mkDerivation (finalAttrs: { url = "https://github.com/checkpoint-restore/criu/commit/3f3acc3200a23140abaa32a2017ae159d3c2d02c.patch?full_index=1"; hash = "sha256-J8n4TjqjzJLLULnpJdR/6YWa/8moFQMn+wNo4a0otgE="; }) + + # fix build w/ glibc-2.44 + (fetchpatch2 { + url = "https://github.com/checkpoint-restore/criu/commit/a810faba33f43d61372741ed196eafd485546f83.patch?full_index=1"; + hash = "sha256-UHSSC3qI6dvtUAiXNnKXTtuXZYGE0SXpUnQ917SXFaU="; + }) ]; enableParallelBuilding = true; diff --git a/pkgs/by-name/cr/cryptsetup/package.nix b/pkgs/by-name/cr/cryptsetup/package.nix index 0ff0e32e1742..3cb9df938375 100644 --- a/pkgs/by-name/cr/cryptsetup/package.nix +++ b/pkgs/by-name/cr/cryptsetup/package.nix @@ -25,7 +25,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "cryptsetup"; - version = "2.8.7"; + version = "2.8.8"; outputs = [ "bin" @@ -39,7 +39,7 @@ stdenv.mkDerivation (finalAttrs: { url = "mirror://kernel/linux/utils/cryptsetup/v${lib.versions.majorMinor finalAttrs.version}/" + "cryptsetup-${finalAttrs.version}.tar.xz"; - hash = "sha256-53bw04HobKYQQsRXBpSR/o4KwoZ4DHw7Hk+ZIavJYdo="; + hash = "sha256-Os+mhfLdf8yDLgt3vHCTqn2lVKUc6Nr7tBOOqoVO7jU="; }; patches = [ diff --git a/pkgs/by-name/ct/ctx/0001-fix-detections.diff b/pkgs/by-name/ct/ctx/0001-fix-detections.diff deleted file mode 100644 index d2580d0fde1d..000000000000 --- a/pkgs/by-name/ct/ctx/0001-fix-detections.diff +++ /dev/null @@ -1,67 +0,0 @@ -diff -Naur --no-dereference ctx-source-old/configure.sh ctx-source-new/configure.sh ---- ctx-source-old/configure.sh 1969-12-31 21:00:01.000000000 -0300 -+++ ctx-source-new/configure.sh 2023-09-27 19:26:05.403569888 -0300 -@@ -42,15 +42,18 @@ - ENABLE_SWITCH_DISPATCH=1 - - pkg-config sdl2 && HAVE_SDL=1 --pkg-config babl && HAVE_BABL=1 -+ -+pkg-config babl-0.1 && { HAVE_BABL=1; BABL_NAME=babl-0.1; } -+if [ $HAVE_BABL != 1 ]; then -+ pkg-config babl && { HAVE_BABL=1; BABL_NAME=babl; } -+fi -+ - pkg-config libcurl && HAVE_LIBCURL=1 - pkg-config alsa && HAVE_ALSA=1 - pkg-config libdrm && HAVE_KMS=1 - #pkg-config harfbuzz && HAVE_HARFBUZZ=1 - -- -- --ARCH=`uname -m` -+: "${ARCH:="$(uname -m)"}" - - case "$ARCH" in - "x86_64") HAVE_SIMD=1 ;; -@@ -224,8 +227,8 @@ - if [ $HAVE_BABL = 1 ];then - echo "#define CTX_BABL 1 " >> local.conf - echo "#define CTX_ENABLE_CM 1 " >> local.conf -- echo "CTX_CFLAGS+= `pkg-config babl --cflags`" >> build.conf -- echo "CTX_LIBS+= `pkg-config babl --libs` " >> build.conf -+ echo "CTX_CFLAGS+= `pkg-config "${BABL_NAME}" --cflags`" >> build.conf -+ echo "CTX_LIBS+= `pkg-config "${BABL_NAME}" --libs` " >> build.conf - else - echo "#define CTX_BABL 0 " >> local.conf - echo "#define CTX_ENABLE_CM 0 " >> local.conf -@@ -335,7 +338,7 @@ - #echo "Generating build.deps" - #make build.deps 2>/dev/null - --echo -n "configuration summary, architecture $(arch)" -+echo -n "configuration summary, architecture $ARCH" - [ $HAVE_SIMD = 1 ] && echo " SIMD multi-pass" - echo "" - echo "Backends:" -diff -Naur --no-dereference ctx-source-old/Makefile ctx-source-new/Makefile ---- ctx-source-old/Makefile 1969-12-31 21:00:01.000000000 -0300 -+++ ctx-source-new/Makefile 2023-09-27 19:37:23.779830320 -0300 -@@ -206,8 +206,8 @@ - libctx.a: itk.o deps.o $(CTX_OBJS) build.conf Makefile - $(AR) rcs $@ $(CTX_OBJS) deps.o itk.o - libctx.so: $(CTX_OBJS) deps.o itk.o build.conf Makefile -- $(LD) -shared $(LIBS) $(CTX_OBJS) deps.o itk.o $(CTX_LIBS) -o $@ -- #$(LD) --retain-symbols-file=symbols -shared $(LIBS) $? $(CTX_LIBS) -o $@ -+ $(CCC) -shared $(LIBS) $(CTX_OBJS) deps.o itk.o $(CTX_LIBS) -o $@ -+ #$(CCC) --retain-symbols-file=symbols -shared $(LIBS) $? $(CTX_LIBS) -o $@ - - ctx: main.c ctx.h build.conf Makefile $(TERMINAL_OBJS) $(MEDIA_HANDLERS_OBJS) libctx.a - $(CCC) main.c $(TERMINAL_OBJS) $(MEDIA_HANDLERS_OBJS) -o $@ $(CFLAGS) libctx.a $(LIBS) $(CTX_CFLAGS) $(OFLAGS_LIGHT) -lpthread $(CTX_LIBS) -@@ -277,5 +277,5 @@ - for a in `cat itk/css.h | tr ';' ' ' | tr ',' ' ' | tr ')' ' '|tr ':' ' ' | tr '{' ' ' | tr ' ' '\n' | grep 'SQZ_[a-z][0-9a-zA-Z_]*'| sort | uniq`;do b=`echo $$a|tail -c+5|tr '_' '-'`;echo "#define $$a `./squoze/squoze -33 $$b`u // \"$$b\"";done \ - >> $@ - echo '#endif' >> $@ --static.inc: static/* static/*/* tools/gen_fs.sh -+static.inc: static/* tools/gen_fs.sh - ./tools/gen_fs.sh static > $@ diff --git a/pkgs/by-name/ct/ctx/package.nix b/pkgs/by-name/ct/ctx/package.nix deleted file mode 100644 index 37e3ac1582db..000000000000 --- a/pkgs/by-name/ct/ctx/package.nix +++ /dev/null @@ -1,83 +0,0 @@ -{ - lib, - stdenv, - fetchgit, - SDL2, - alsa-lib, - babl, - bash, - curl, - libdrm, # Not documented - pkg-config, - xxd, - enableFb ? false, - nixosTests, -}: - -stdenv.mkDerivation (finalAttrs: { - pname = "ctx"; - version = "0-unstable-2023-09-03"; - - src = fetchgit { - name = "ctx-source"; # because of a dash starting the directory - url = "https://ctx.graphics/.git/"; - rev = "1bac18c152eace3ca995b3c2b829a452085d46fb"; - hash = "sha256-fOcQJ2XCeomdtAUmy0A+vU7Vt325OSwrb1+ccW+gZ38="; - }; - - patches = [ - # Many problematic things fixed - it should be upstreamed somehow: - # - babl changed its name in pkg-config files - # - arch detection made optional - # - LD changed to CCC - # - remove inexistent reference to static/*/* - ./0001-fix-detections.diff - ]; - - postPatch = '' - patchShebangs ./tools/gen_fs.sh - ''; - - nativeBuildInputs = [ - pkg-config - xxd - ]; - - buildInputs = [ - SDL2 - alsa-lib - babl - bash # for ctx-audioplayer - curl - libdrm - ]; - - strictDeps = true; - - env.ARCH = stdenv.hostPlatform.parsed.cpu.arch or stdenv.hostPlatform.parsed.cpu.name; - - configureScript = "./configure.sh"; - configureFlags = lib.optional enableFb "--enable-fb"; - configurePlatforms = [ ]; - dontAddPrefix = true; - dontDisableStatic = true; - - installFlags = [ - "PREFIX=${placeholder "out"}" - ]; - - passthru.tests.test = nixosTests.terminal-emulators.ctx; - - meta = { - homepage = "https://ctx.graphics/"; - description = "Vector graphics terminal"; - longDescription = '' - ctx is an interactive 2D vector graphics, audio, text- canvas and - terminal, with escape sequences that enable a 2D vector drawing API using - a vector graphics protocol. - ''; - license = lib.licenses.gpl3Plus; - maintainers = [ ]; - platforms = lib.platforms.unix; - }; -}) diff --git a/pkgs/by-name/cu/cups/package.nix b/pkgs/by-name/cu/cups/package.nix index dd12a5dcef57..bc7e13d02f1f 100644 --- a/pkgs/by-name/cu/cups/package.nix +++ b/pkgs/by-name/cu/cups/package.nix @@ -2,6 +2,7 @@ lib, stdenv, fetchurl, + fetchpatch, pkg-config, removeReferencesTo, zlib, @@ -42,6 +43,29 @@ stdenv.mkDerivation (finalAttrs: { "man" ]; + patches = [ + (fetchpatch { + name = "CVE-2026-87875.patch"; + url = "https://github.com/OpenPrinting/cups/commit/2b1dc178a2d2325135b855142e384f4e8c42d8e4.patch"; + excludes = [ "CHANGES.md" ]; + hash = "sha256-WHw/UWyUuYEBC6TRADpw+BBCaCts9Nd0jS9qsQHTBMo="; + }) + (fetchpatch { + url = "https://github.com/OpenPrinting/cups/commit/76b515154ce6264dae6d7cc44915d85e0e5fa0f4.patch"; + hash = "sha256-KtwcB4KrFmsLbtAz6u593qxbnozW2Vb/I9yX36gZTd0="; + }) + (fetchpatch { + url = "https://github.com/OpenPrinting/cups/commit/526adb34fe87f7f0cf5f63ae26751c1afa36a5d6.patch"; + hash = "sha256-Pg2xbCXalbvDvv5iI19MrjpOTW03XLKfEHN+lhImG1U="; + }) + (fetchpatch { + name = "CVE-2026-87876.patch"; + url = "https://github.com/OpenPrinting/cups/commit/88e67c00c130a45f3a1edf36686f7a0b2982fef8.patch"; + excludes = [ "CHANGES.md" ]; + hash = "sha256-gohcRO93JE2ldF5uPbR0re9NYxb13AeVn4b/qYsQGaE="; + }) + ]; + postPatch = '' substituteInPlace cups/testfile.c \ --replace 'cupsFileFind("cat", "/bin' 'cupsFileFind("cat", "${coreutils}/bin' diff --git a/pkgs/by-name/da/dark-mode-notify/package.nix b/pkgs/by-name/da/dark-mode-notify/package.nix index 2b941f11b0ed..c71283af5933 100644 --- a/pkgs/by-name/da/dark-mode-notify/package.nix +++ b/pkgs/by-name/da/dark-mode-notify/package.nix @@ -4,12 +4,9 @@ stdenv, swift, swiftpm, - swiftPackages, }: -# Use the same stdenv, including clang, as Swift itself -# Fixes build issues, see https://github.com/NixOS/nixpkgs/pull/296082 and https://github.com/NixOS/nixpkgs/issues/295322 -swiftPackages.stdenv.mkDerivation (finalAttrs: { +stdenv.mkDerivation (finalAttrs: { pname = "dark-mode-notify"; version = "0-unstable-2022-07-18"; @@ -27,6 +24,8 @@ swiftPackages.stdenv.mkDerivation (finalAttrs: { makeFlags = [ "prefix=$(out)" ]; + dontUseSwiftpmInstall = true; + meta = { description = "Run a script whenever dark mode changes in macOS"; homepage = "https://github.com/bouk/dark-mode-notify"; diff --git a/pkgs/by-name/da/darkradiant/package.nix b/pkgs/by-name/da/darkradiant/package.nix index 25f7f9f17809..e0983f0b28e0 100644 --- a/pkgs/by-name/da/darkradiant/package.nix +++ b/pkgs/by-name/da/darkradiant/package.nix @@ -8,7 +8,7 @@ libjpeg, wxwidgets_3_2, libxml2, - libsigcxx, + libsigcxx_2_0, libpng, openal, libvorbis, @@ -50,7 +50,7 @@ stdenv.mkDerivation (finalAttrs: { libjpeg wxwidgets_3_2 libxml2 - libsigcxx + libsigcxx_2_0 libpng openal libvorbis diff --git a/pkgs/by-name/dc/dconf/package.nix b/pkgs/by-name/dc/dconf/package.nix index 73dd2a3fee42..1396fe83303a 100644 --- a/pkgs/by-name/dc/dconf/package.nix +++ b/pkgs/by-name/dc/dconf/package.nix @@ -29,10 +29,14 @@ stdenv.mkDerivation (finalAttrs: { pname = "dconf"; version = "0.49.0"; + __structuredAttrs = true; + strictDeps = true; + outputs = [ "out" "lib" "dev" + "man" ] ++ lib.optional withDocs "devdoc"; diff --git a/pkgs/by-name/di/diod/package.nix b/pkgs/by-name/di/diod/package.nix index 32b3748bed52..a3127d32ab80 100644 --- a/pkgs/by-name/di/diod/package.nix +++ b/pkgs/by-name/di/diod/package.nix @@ -9,6 +9,7 @@ libcap, perl, ncurses, + fetchpatch, }: let lua = lua5_1; @@ -24,6 +25,14 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-Fz+qvgw5ipyAcZlWBGkmSHuGrZ95i5OorLN3dkdsYKU="; }; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/chaos/diod/commit/d56db0c55012c8a9ea2d3c72749022292c0f65b8.patch"; + hash = "sha256-wuPok3D3VKiao9NmHYLcccsL+91xVbhUeSDExw17X/E="; + }) + ]; + postPatch = '' sed -i configure.ac -e '/git describe/c ${finalAttrs.version})' ''; diff --git a/pkgs/by-name/do/dockutil/package.nix b/pkgs/by-name/do/dockutil/package.nix index 9d770bc4bbac..e9ee0e77057f 100644 --- a/pkgs/by-name/do/dockutil/package.nix +++ b/pkgs/by-name/do/dockutil/package.nix @@ -7,7 +7,6 @@ swift, swiftpm, swiftpm2nix, - swiftPackages, libarchive, p7zip, # Building from source on x86_64 fails (among other things) due to: @@ -30,7 +29,7 @@ let platforms = lib.platforms.darwin; }; - buildFromSource = swiftPackages.stdenv.mkDerivation (finalAttrs: { + buildFromSource = stdenv.mkDerivation (finalAttrs: { inherit pname version meta; src = fetchFromGitHub { diff --git a/pkgs/by-name/dr/dragmap/boost-iterator-range.patch b/pkgs/by-name/dr/dragmap/boost-iterator-range.patch deleted file mode 100644 index bd70eab43f49..000000000000 --- a/pkgs/by-name/dr/dragmap/boost-iterator-range.patch +++ /dev/null @@ -1,12 +0,0 @@ -diff --git a/src/lib/map/Mapper.cpp b/src/lib/map/Mapper.cpp -index 6eaa2c5..781988c 100644 ---- a/src/lib/map/Mapper.cpp -+++ b/src/lib/map/Mapper.cpp -@@ -22,6 +22,7 @@ - //#include "common/Crc32Hw.hpp" - #include "common/DragenLogger.hpp" - #include "map/Mapper.hpp" -+#include - - namespace dragenos { - namespace map { diff --git a/pkgs/by-name/dr/dragmap/cstdint.patch b/pkgs/by-name/dr/dragmap/cstdint.patch deleted file mode 100644 index 6004510d2999..000000000000 --- a/pkgs/by-name/dr/dragmap/cstdint.patch +++ /dev/null @@ -1,73 +0,0 @@ -diff --git a/src/include/map/SeedPosition.hpp b/src/include/map/SeedPosition.hpp -index 30a7d47..c05af16 100644 ---- a/src/include/map/SeedPosition.hpp -+++ b/src/include/map/SeedPosition.hpp -@@ -16,6 +16,7 @@ - #define MAP_SEED_POSITION_HPP - - #include -+#include - - #include "sequences/Seed.hpp" - -diff --git a/src/include/sequences/Read.hpp b/src/include/sequences/Read.hpp -index 460c1cb..c7ff619 100644 ---- a/src/include/sequences/Read.hpp -+++ b/src/include/sequences/Read.hpp -@@ -16,6 +16,7 @@ - #define SEQUENCES_READ_HPP - - #include -+#include - #include - #include - -diff --git a/src/include/sequences/Seed.hpp b/src/include/sequences/Seed.hpp -index a242153..dd4d23b 100644 ---- a/src/include/sequences/Seed.hpp -+++ b/src/include/sequences/Seed.hpp -@@ -16,6 +16,7 @@ - #define SEQUENCES_SEED_HPP - - #include -+#include - #include - - #include "sequences/Read.hpp" -diff --git a/src/lib/sequences/tests/unit/CrcHasherMocks.hpp b/src/lib/sequences/tests/unit/CrcHasherMocks.hpp -index 1866be7..5d9b7d7 100644 ---- a/src/lib/sequences/tests/unit/CrcHasherMocks.hpp -+++ b/src/lib/sequences/tests/unit/CrcHasherMocks.hpp -@@ -2,6 +2,7 @@ - - #include - #include -+#include - #include - #include - -diff --git a/stubs/dragen/src/host/dragen_api/read_group_list.hpp b/stubs/dragen/src/host/dragen_api/read_group_list.hpp -index eefb9ae..623a77f 100644 ---- a/stubs/dragen/src/host/dragen_api/read_group_list.hpp -+++ b/stubs/dragen/src/host/dragen_api/read_group_list.hpp -@@ -14,6 +14,7 @@ - #define __READ_GROUP_LIST_HPP__ - - #include "dragen_exception.hpp" -+#include - class ReadGroupList { - public: - const std::string &getReadGroupName(const uint16_t idx) const { - -diff --git a/stubs/dragen/src/host/metrics/public/run_stats.hpp b/stubs/dragen/src/host/metrics/public/run_stats.hpp -index 998fe4e..9561b0b 100644 ---- a/stubs/dragen/src/host/metrics/public/run_stats.hpp -+++ b/stubs/dragen/src/host/metrics/public/run_stats.hpp -@@ -10,6 +10,7 @@ - #include - #include - #include -+#include - // - // RP: HA! HA! HA! That's what you get when you write code logging to cout all - // over the place! diff --git a/pkgs/by-name/dr/dragmap/getHostVersion.patch b/pkgs/by-name/dr/dragmap/getHostVersion.patch deleted file mode 100644 index ba769c9b09a3..000000000000 --- a/pkgs/by-name/dr/dragmap/getHostVersion.patch +++ /dev/null @@ -1,11 +0,0 @@ -diff --git a/thirdparty/dragen/src/common/hash_generation/gen_hash_table.c b/thirdparty/dragen/src/common/hash_generation/gen_hash_table.c -index cdca3df..5a55699 100644 ---- a/thirdparty/dragen/src/common/hash_generation/gen_hash_table.c -+++ b/thirdparty/dragen/src/common/hash_generation/gen_hash_table.c -@@ -249,7 +249,7 @@ void setDefaultHashParams(hashTableConfig_t* defConfig, const char* destDir, Has - free(dir); - } - -- defConfig->hostVersion = (char*)getHostVersion(0); -+ defConfig->hostVersion = (char*)getHostVersion(); - } diff --git a/pkgs/by-name/dr/dragmap/package.nix b/pkgs/by-name/dr/dragmap/package.nix deleted file mode 100644 index 8f554102db65..000000000000 --- a/pkgs/by-name/dr/dragmap/package.nix +++ /dev/null @@ -1,82 +0,0 @@ -{ - lib, - stdenv, - fetchFromGitHub, - boost, - gtest, - zlib, -}: - -stdenv.mkDerivation (finalAttrs: { - pname = "dragmap"; - version = "1.3.0"; - - src = fetchFromGitHub { - owner = "Illumina"; - repo = "DRAGMAP"; - tag = finalAttrs.version; - fetchSubmodules = true; - hash = "sha256-f1jsOErriS1I/iUS4CzJ3+Dz8SMUve/ccb3KaE+L7U8="; - }; - - nativeBuildInputs = [ boost ]; - buildInputs = [ - gtest - zlib - ]; - - # Latest boost do not need system as a linking flag - postPatch = '' - sed -i 's/system filesystem/filesystem/' config.mk - ''; - - patches = [ - # getHostVersion use an empty parameter list. This is now an error for GC - ./getHostVersion.patch - - # pclose is called on a NULL value. This is no longer allowed since - # https://github.com/bminor/glibc/commit/64b1a44183a3094672ed304532bedb9acc707554 - ./stdio-pclose.patch - - # Add missing include cstdint. Upstream does not accept PR. Issue opened at - # https://github.com/Illumina/DRAGMAP/issues/63 - ./cstdint.patch - - # Missing import in Mapper.cpp - # Issue opened upstream https://github.com/Illumina/DRAGMAP/pull/66 - ./boost-iterator-range.patch - ]; - - env = { - GTEST_INCLUDEDIR = "${gtest.dev}/include"; - CPPFLAGS = "-I ${boost.dev}/include"; - LDFLAGS = "-L ${boost.out}/lib"; - }; - - installPhase = '' - runHook preInstall - - mkdir -p $out/bin - cp build/release/dragen-os $out/bin/ - - runHook postInstall - ''; - - # Tests are launched by default from makefile - doCheck = false; - - meta = { - description = "Open Source version of Dragen mapper for genomics"; - mainProgram = "dragen-os"; - longDescription = '' - DRAGMAP is an open-source software implementation of the DRAGEN mapper, - which the Illumina team created to produce the same results as their - proprietary DRAGEN hardware. - ''; - homepage = "https://github.com/Illumina/DRAGMAP"; - changelog = "https://github.com/Illumina/DRAGMAP/releases/tag/${finalAttrs.version}"; - license = lib.licenses.gpl3; - platforms = [ "x86_64-linux" ]; - maintainers = with lib.maintainers; [ apraga ]; - }; -}) diff --git a/pkgs/by-name/dr/dragmap/stdio-pclose.patch b/pkgs/by-name/dr/dragmap/stdio-pclose.patch deleted file mode 100644 index 74e8d57e9fa5..000000000000 --- a/pkgs/by-name/dr/dragmap/stdio-pclose.patch +++ /dev/null @@ -1,12 +0,0 @@ -diff --git a/stubs/dragen/src/host/infra/linux/infra_linux_utils.cpp b/stubs/dragen/src/host/infra/linux/infra_linux_utils.cpp -index cd02cd4..c26e9cf 100644 ---- a/stubs/dragen/src/host/infra/linux/infra_linux_utils.cpp -+++ b/stubs/dragen/src/host/infra/linux/infra_linux_utils.cpp -@@ -57,7 +57,6 @@ int GetDmiValue(const std::string& label, std::string& value) - FILE* dmiOutput = popen("sudo /usr/sbin/dmidecode -t 2", "r"); - if (dmiOutput == NULL) { - perror("dmidecode popen"); -- pclose(dmiOutput); - return -1; - } - diff --git a/pkgs/by-name/dt/dtc/package.nix b/pkgs/by-name/dt/dtc/package.nix index 17fe8f5653e3..c6b4cf138b00 100644 --- a/pkgs/by-name/dt/dtc/package.nix +++ b/pkgs/by-name/dt/dtc/package.nix @@ -14,40 +14,43 @@ replaceVars, swig, libyaml, + gitUpdater, }: stdenv.mkDerivation (finalAttrs: { pname = "dtc"; - version = "1.7.2"; + version = "1.8.1"; src = fetchzip { url = "https://git.kernel.org/pub/scm/utils/dtc/dtc.git/snapshot/dtc-v${finalAttrs.version}.tar.gz"; - hash = "sha256-KZCzrvdWd6zfQHppjyp4XzqNCfH2UnuRneu+BNIRVAY="; + hash = "sha256-l32ZGygimwSB2xmwQEvS+C2c5n86OMH92jQZ/tPI+YI="; }; patches = [ - # backport of https://github.com/dgibson/dtc/pull/141 - # to 1.7.2, to drop in 1.8. - ./static.patch - # backport fix for SWIG 4.3 + # These 4 patches fix build failures on x86_64-linux for tests/dumptrees by replacing it. (fetchpatch2 { - url = "https://github.com/dgibson/dtc/commit/9a969f3b70b07bbf1c9df44a38d7f8d1d3a6e2a5.patch"; - hash = "sha256-YrRzc3ATNmU6LYNHEQeU8wtjt1Ap7/gNFvtRR14PQEE="; + url = "https://github.com/dgibson/dtc/commit/9b53b9a4c2f953a37d8f68d72f5910b20cf5aee0.patch?full_index=1"; + hash = "sha256-HHX3zg1uwD3ZFHbHcANX85gNDpeEMVbkG7zMhyc/87k="; }) - # glibc-2.41 support (fetchpatch2 { - url = "https://github.com/dgibson/dtc/commit/ce1d8588880aecd7af264e422a16a8b33617cef7.patch"; - hash = "sha256-t1CxKnbCXUArtVcniAIdNvahOGXPbYhPCZiTynGLvfo="; + url = "https://github.com/dgibson/dtc/commit/f116f4800edce6cd58f680a36fbaed656018d528.patch?full_index=1"; + hash = "sha256-XcLzfruD3DGs4girNxsqrhBW3Ct/+vAltn8OzIRyU6w="; + }) + (fetchpatch2 { + url = "https://github.com/dgibson/dtc/commit/4df9ca4c8ddb83c40900bf13916b42914a25caf4.patch?full_index=1"; + hash = "sha256-ap3D2DxHxLYOSJPhWAUP/nooi/n2/wLc65NfbjlYl2M="; + }) + (fetchpatch2 { + url = "https://github.com/dgibson/dtc/commit/214372a27398121f8266cf9bb9592561508c4c0f.patch?full_index=1"; + hash = "sha256-Fk0dA1J14NsIfd5qSknOMkB769TEwvWem8e+uEleM84="; }) ] - ++ - lib.optional pythonSupport - # Make Meson use our Python version, not the one it was built with itself - ( - replaceVars ./python-path.patch { - python_bin = lib.getExe python; - } - ); + ++ lib.optionals pythonSupport [ + # Make Meson use our Python version, not the one it was built with itself + (replaceVars ./python-path.patch { + python_bin = lib.getExe python; + }) + ]; nativeBuildInputs = [ meson @@ -55,25 +58,23 @@ stdenv.mkDerivation (finalAttrs: { flex bison pkg-config - which ] ++ lib.optionals pythonSupport [ python - python.pkgs.setuptools-scm swig ]; buildInputs = [ libyaml ]; postPatch = '' - patchShebangs setup.py - # Align the name with pypi - sed -i "s/name='libfdt',/name='pylibfdt',/" setup.py + substituteInPlace pyproject.toml --replace-fail "name = 'libfdt'" "name = 'pylibfdt'" ''; # Required for installation of Python library and is innocuous otherwise. env.DESTDIR = "/"; + # glibc 2.43 C23 const-preserving strchr/strstr macros + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; mesonAutoFeatures = "auto"; mesonFlags = [ @@ -97,6 +98,11 @@ stdenv.mkDerivation (finalAttrs: { # hostPlatform binaries during the configurePhase. (with stdenv; buildPlatform.canExecute hostPlatform); + passthru.updateScript = gitUpdater { + url = "https://git.kernel.org/pub/scm/utils/dtc/dtc.git"; + rev-prefix = "v"; + }; + meta = { description = "Device Tree Compiler"; homepage = "https://git.kernel.org/pub/scm/utils/dtc/dtc.git"; diff --git a/pkgs/by-name/dt/dtc/static.patch b/pkgs/by-name/dt/dtc/static.patch deleted file mode 100644 index 5b368e07243a..000000000000 --- a/pkgs/by-name/dt/dtc/static.patch +++ /dev/null @@ -1,150 +0,0 @@ -commit a881a5b110d2f23a11924604bff64ab3c2755bc6 -Author: Brandon Maier -Date: Thu Mar 6 20:30:47 2025 -0600 - - meson: support building libfdt without static library - - Some packaging systems like NixOS don't support compiling static - libraries. However libfdt's meson.build uses `both_library()` which - forces the build to always compile shared and static libraries. Removing - `both_library()` will make packaging easier. - - libfdt uses `both_libraries()` to support the 'static-build' option. - But we do not need the 'static-build' option as Meson can natively - build static using - - > meson setup builddir/ -Dc_link_args='-static' --prefer-static --default-library=static - - So drop 'static-build' and then replace `both_libraries()` with - `library()`. - - Signed-off-by: Brandon Maier - Signed-off-by: David Gibson - -diff --git a/libfdt/meson.build b/libfdt/meson.build -index bf8343f..c2f4bd6 100644 ---- a/libfdt/meson.build -+++ b/libfdt/meson.build -@@ -26,7 +26,7 @@ else - endif - - link_args += version_script --libfdt = both_libraries( -+libfdt = library( - 'fdt', sources, - version: meson.project_version(), - link_args: link_args, -@@ -34,17 +34,11 @@ libfdt = both_libraries( - install: true, - ) - --if static_build -- link_with = libfdt.get_static_lib() --else -- link_with = libfdt.get_shared_lib() --endif -- - libfdt_inc = include_directories('.') - - libfdt_dep = declare_dependency( - include_directories: libfdt_inc, -- link_with: link_with, -+ link_with: libfdt, - ) - - install_headers( -diff --git a/meson.build b/meson.build -index 310699f..603ffaa 100644 ---- a/meson.build -+++ b/meson.build -@@ -1,7 +1,7 @@ - project('dtc', 'c', - version: files('VERSION.txt'), - license: ['GPL2+', 'BSD-2'], -- default_options: 'werror=true', -+ default_options: ['werror=true', 'default_library=both'], - meson_version: '>=0.57.0' - ) - -@@ -27,16 +27,8 @@ add_project_arguments( - language: 'c' - ) - --if get_option('static-build') -- static_build = true -- extra_link_args = ['-static'] --else -- static_build = false -- extra_link_args = [] --endif -- - yamltree = 'yamltree.c' --yaml = dependency('yaml-0.1', version: '>=0.2.3', required: get_option('yaml'), static: static_build) -+yaml = dependency('yaml-0.1', version: '>=0.2.3', required: get_option('yaml')) - if not yaml.found() - add_project_arguments('-DNO_YAML', language: 'c') - yamltree = [] -@@ -92,7 +84,6 @@ if get_option('tools') - ], - dependencies: util_dep, - install: true, -- link_args: extra_link_args, - ) - endif - -@@ -113,11 +104,10 @@ if get_option('tools') - ], - dependencies: [util_dep, yaml], - install: true, -- link_args: extra_link_args, - ) - - foreach e: ['fdtdump', 'fdtget', 'fdtput', 'fdtoverlay'] -- dtc_tools += executable(e, files(e + '.c'), dependencies: util_dep, install: true, link_args: extra_link_args) -+ dtc_tools += executable(e, files(e + '.c'), dependencies: util_dep, install: true) - endforeach - - install_data( -diff --git a/meson_options.txt b/meson_options.txt -index 36f391a..62b31b3 100644 ---- a/meson_options.txt -+++ b/meson_options.txt -@@ -8,7 +8,5 @@ option('valgrind', type: 'feature', value: 'auto', - description: 'Valgrind support') - option('python', type: 'feature', value: 'auto', - description: 'Build pylibfdt Python library') --option('static-build', type: 'boolean', value: false, -- description: 'Build static binaries') - option('tests', type: 'boolean', value: true, - description: 'Build tests') -diff --git a/tests/meson.build b/tests/meson.build -index 9cf6e3d..baed174 100644 ---- a/tests/meson.build -+++ b/tests/meson.build -@@ -96,22 +96,20 @@ tests += [ - 'truncated_string', - ] - -+test_deps = [testutil_dep, util_dep, libfdt_dep] -+ - dl = cc.find_library('dl', required: false) --if dl.found() and not static_build -+if dl.found() - tests += [ - 'asm_tree_dump', - 'value-labels', - ] --endif -- --test_deps = [testutil_dep, util_dep, libfdt_dep] --if not static_build - test_deps += [dl] - endif - - tests_exe = [] - foreach t: tests -- tests_exe += executable(t, files(t + '.c'), dependencies: test_deps, link_args: extra_link_args) -+ tests_exe += executable(t, files(t + '.c'), dependencies: test_deps) - endforeach - - run_tests = find_program('run_tests.sh') diff --git a/pkgs/by-name/ea/eas-cli/package.nix b/pkgs/by-name/ea/eas-cli/package.nix index 567372a7f135..3f61e5f469ea 100644 --- a/pkgs/by-name/ea/eas-cli/package.nix +++ b/pkgs/by-name/ea/eas-cli/package.nix @@ -2,6 +2,7 @@ lib, stdenv, fetchFromGitHub, + substitute, yarn-berry_4, nodejs, jq, @@ -15,14 +16,25 @@ let owner = "expo"; repo = "eas-cli"; rev = "v${version}"; - hash = "sha256-EMN54PR9lhrZcGMq2iNUsdyBP3wVk4G/isjsneIGslI="; + hash = "sha256-WfzCV304xgTqiKBCsZc5rnzaC+UHA6c155FG+HWBY7s="; + + # Remove after upstream updates to Yarn 4.15 + # https://github.com/expo/eas-cli/blob/main/package.json#L38 + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry_4.lockfileVersion + ]; + }) + } + ''; }; missingHashes = ./missing-hashes.json; - patches = [ - # Remove after upstream updates to Yarn 4.14 - # https://github.com/expo/eas-cli/blob/v18.7.0/package.json#L37 - ./yarn-4.14-support.patch - ]; in # cc is necessary because of building an npm package without a prebuilt binary # for ARM. See comment in nativeBuildInputs below. @@ -32,12 +44,11 @@ stdenv.mkDerivation (finalAttrs: { src version missingHashes - patches ; yarnOfflineCache = yarn-berry_4.fetchYarnBerryDeps { - inherit src missingHashes patches; - hash = "sha256-dOx4T009+FMFEvTZtlyJpAUo2UYBm1O1hIyBnSbqIgw="; + inherit src missingHashes; + hash = "sha256-Iqdk0MpXeiKm5hgF68XOKvl0a+5LpXsNNcelCcbfj3s="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/ea/eas-cli/yarn-4.14-support.patch b/pkgs/by-name/ea/eas-cli/yarn-fix.patch similarity index 89% rename from pkgs/by-name/ea/eas-cli/yarn-4.14-support.patch rename to pkgs/by-name/ea/eas-cli/yarn-fix.patch index 2591021c6269..a67bb75f0925 100644 --- a/pkgs/by-name/ea/eas-cli/yarn-4.14-support.patch +++ b/pkgs/by-name/ea/eas-cli/yarn-fix.patch @@ -15,6 +15,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10c0 diff --git a/pkgs/by-name/ea/easyeffects/package.nix b/pkgs/by-name/ea/easyeffects/package.nix index 9efc3e1b9497..5c0e60b114a8 100644 --- a/pkgs/by-name/ea/easyeffects/package.nix +++ b/pkgs/by-name/ea/easyeffects/package.nix @@ -15,7 +15,7 @@ libbs2b, libebur128, libmysofa, - libsigcxx30, + libsigcxx_3_0, libsndfile, lilv, lsp-plugins, @@ -100,7 +100,7 @@ stdenv.mkDerivation (finalAttrs: { libbs2b libebur128 libmysofa - libsigcxx30 + libsigcxx_3_0 libsndfile lilv lv2 diff --git a/pkgs/by-name/ef/efivar/package.nix b/pkgs/by-name/ef/efivar/package.nix index bdc7a06b9503..12ebaf4a7500 100644 --- a/pkgs/by-name/ef/efivar/package.nix +++ b/pkgs/by-name/ef/efivar/package.nix @@ -6,6 +6,7 @@ pkg-config, popt, mandoc, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -33,6 +34,14 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ popt ]; depsBuildBuild = [ buildPackages.stdenv.cc ]; + patches = [ + # fix build with glibc-2.44 + (fetchpatch { + url = "https://github.com/rhboot/efivar/commit/f521cd7f584c95d8308659ab9d89d750e2bd76da.patch"; + hash = "sha256-I19UIS0tNTsEipuoMQPlTEwih1RrYPz9Q4Wy98u1z0Q="; + }) + ]; + makeFlags = [ "prefix=$(out)" "libdir=$(out)/lib" diff --git a/pkgs/by-name/el/electron-fiddle/package.nix b/pkgs/by-name/el/electron-fiddle/package.nix index f083d5c1b88b..cfe7cf999881 100644 --- a/pkgs/by-name/el/electron-fiddle/package.nix +++ b/pkgs/by-name/el/electron-fiddle/package.nix @@ -1,7 +1,6 @@ { buildFHSEnv, fetchFromGitHub, - fetchYarnDeps, electron, git, lib, @@ -10,6 +9,7 @@ stdenvNoCC, util-linux, yarn-berry_4, + substitute, zip, }: @@ -22,7 +22,23 @@ let owner = "electron"; repo = "fiddle"; tag = "v${version}"; - hash = "sha256-nmmj1PvW9LOoEdwwWRRXe9q9J8z6Fp45Tt038BjWD+k="; + hash = "sha256-5Pw889lHRwWoTUVbLmToPF8/bDz382qFMO9mL/EKLo0="; + + # Remove after upstream updates to Yarn 4.15 + # https://github.com/electron/fiddle/blob/main/package.json#L163 + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry.lockfileVersion + ]; + }) + } + ''; }; patches = [ @@ -31,9 +47,6 @@ let # zip extraction fails on newer nodejs versions without this fix ./bump-yauzl.patch - - # https://github.com/nixos/nixpkgs/issues/542343 - ./yarn-metadata-version.patch ]; missingHashes = ./missing-hashes.json; @@ -49,7 +62,7 @@ let offlineCache = yarn-berry.fetchYarnBerryDeps { inherit src patches missingHashes; - hash = "sha256-xxguRiyZDGdVt3eYh+KUI/odLZZ/LeScRBfexMxAOVI="; + hash = "sha256-O9zaCL0W8JPYQz8EBWOz0qGjW57Js3oMosUbz72YBc4="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/el/electron-fiddle/yarn-fix.patch b/pkgs/by-name/el/electron-fiddle/yarn-fix.patch new file mode 100644 index 000000000000..cf10d3150a43 --- /dev/null +++ b/pkgs/by-name/el/electron-fiddle/yarn-fix.patch @@ -0,0 +1,58 @@ +diff --git a/.yarnrc.yml b/.yarnrc.yml +--- a/.yarnrc.yml ++++ b/.yarnrc.yml +@@ -1,7 +1,5 @@ + nodeLinker: node-modules + +-yarnPath: .yarn/releases/yarn-4.10.3.cjs +- + # see package.json for Electron postinstall + enableScripts: false + +diff --git a/yarn.lock b/yarn.lock +index 365f8b4d..ffa89a3d 100644 +--- a/yarn.lock ++++ b/yarn.lock +@@ -2,6 +2,6 @@ + # Manual changes might be lost - proceed with caution! + + __metadata: +- version: 8 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER + cacheKey: 10c0 + +diff --git a/yarn.lock b/yarn.lock +--- a/yarn.lock ++++ b/yarn.lock +@@ -11277,27 +11277,27 @@ __metadata: + + "resolve@patch:resolve@npm%3A^1.22.1#optional!builtin, resolve@patch:resolve@npm%3A~1.22.2#optional!builtin": + version: 1.22.11 +- resolution: "resolve@patch:resolve@npm%3A1.22.11#optional!builtin::version=1.22.11&hash=c3c19d" ++ resolution: "resolve@patch:resolve@npm%3A1.22.11#optional!builtin::version=1.22.11&hash=9bd1a5" + dependencies: + is-core-module: "npm:^2.16.1" + path-parse: "npm:^1.0.7" + supports-preserve-symlinks-flag: "npm:^1.0.0" + bin: + resolve: bin/resolve +- checksum: 10c0/ee5b182f2e37cb1165465e58c6abc797fec0a80b5ba3231607beb4677db0c9291ac010c47cf092b6daa2b7f518d69a0e21888e7e2b633f68d501a874212a8c63 ++ checksum: 10c0/55f7a298977b1aacf6dbec6dcfc81100ba98675bced193b57d3ac58ced65acc40c3a38927853cea86b7f75edb3c20e1f099a09d48b0d8ceccc25d466993eec47 + languageName: node + linkType: hard + + "resolve@patch:resolve@npm%3A^2.0.0-next.4#optional!builtin": + version: 2.0.0-next.4 +- resolution: "resolve@patch:resolve@npm%3A2.0.0-next.4#optional!builtin::version=2.0.0-next.4&hash=c3c19d" ++ resolution: "resolve@patch:resolve@npm%3A2.0.0-next.4#optional!builtin::version=2.0.0-next.4&hash=9bd1a5" + dependencies: + is-core-module: "npm:^2.9.0" + path-parse: "npm:^1.0.7" + supports-preserve-symlinks-flag: "npm:^1.0.0" + bin: + resolve: bin/resolve +- checksum: 10c0/ed2bb51d616b9cd30fe85cf49f7a2240094d9fa01a221d361918462be81f683d1855b7f192391d2ab5325245b42464ca59690db5bd5dad0a326fc0de5974dd10 ++ checksum: 10c0/c86731c5e95ceaa3bf7a0e5d451a9c5e50f7d8c545300de905cda347b5c6d7e23b500b365757673cc884f9be93c23b8aa4dc5c5350b7e6cdfec8149c4b257479 + languageName: node + linkType: hard + diff --git a/pkgs/by-name/et/ethernet-connection-status/package.nix b/pkgs/by-name/et/ethernet-connection-status/package.nix index 5d37e06da8d5..feef09bc631a 100644 --- a/pkgs/by-name/et/ethernet-connection-status/package.nix +++ b/pkgs/by-name/et/ethernet-connection-status/package.nix @@ -4,12 +4,11 @@ fetchFromGitHub, lib, nix-update-script, - swiftPackages, + stdenv, + swift, }: let - inherit (swiftPackages) stdenv swift; - infoPlist = version: lib.generators.toPlist { escape = true; } { diff --git a/pkgs/by-name/ex/expat/package.nix b/pkgs/by-name/ex/expat/package.nix index ec72f0835768..86590a2c5744 100644 --- a/pkgs/by-name/ex/expat/package.nix +++ b/pkgs/by-name/ex/expat/package.nix @@ -23,13 +23,13 @@ in stdenv.mkDerivation (finalAttrs: { pname = "expat"; - version = "2.8.4"; + version = "2.8.5"; src = fetchurl { url = with finalAttrs; "https://github.com/libexpat/libexpat/releases/download/${tagFor version}/${pname}-${version}.tar.xz"; - hash = "sha256-ZWrhzI2jtOpRO7TiVPM+YkOTgITA7GI52oczdrCZhac="; + hash = "sha256-HnJ7iTPsUad6mp2a/PjmiLzkXZB8E+Nqtzk/425wMYI="; }; strictDeps = true; diff --git a/pkgs/by-name/ff/ffado/package.nix b/pkgs/by-name/ff/ffado/package.nix index 0258e15639d6..64842a377e6e 100644 --- a/pkgs/by-name/ff/ffado/package.nix +++ b/pkgs/by-name/ff/ffado/package.nix @@ -5,7 +5,7 @@ dbus, dbus_cplusplus, fetchurl, - glibmm, + glibmm_2_4, libavc1394, libconfig, libiec61883, @@ -98,7 +98,7 @@ stdenv.mkDerivation rec { buildInputs = [ dbus dbus_cplusplus - glibmm + glibmm_2_4 libavc1394 libconfig libiec61883 diff --git a/pkgs/by-name/fi/file/package.nix b/pkgs/by-name/fi/file/package.nix index 37516e53fe1e..39c185a8fb19 100644 --- a/pkgs/by-name/fi/file/package.nix +++ b/pkgs/by-name/fi/file/package.nix @@ -8,6 +8,8 @@ libgnurx ? windows.libgnurx, updateAutotoolsGnuConfigScriptsHook, testers, + pkgsMusl ? { }, # default to empty set to avoid CI fails with allowVariants = false + versionCheckHook, }: # Note: this package is used for bootstrapping fetchurl, and thus @@ -49,22 +51,30 @@ stdenv.mkDerivation (finalAttrs: { ]; buildInputs = [ zlib ] ++ lib.optional stdenv.hostPlatform.isMinGW libgnurx; - # https://bugs.astron.com/view.php?id=382 - doCheck = !stdenv.buildPlatform.isMusl; + doCheck = true; + + nativeInstallCheckInputs = [ versionCheckHook ]; + doInstallCheck = true; # In native builds, it will use the newly-compiled file instead. makeFlags = lib.optional ( !lib.systems.equals stdenv.hostPlatform stdenv.buildPlatform ) "FILE_COMPILE=${lib.getExe buildPackages.file}"; - passthru.tests.pkg-config = testers.testMetaPkgConfig finalAttrs.finalPackage; + passthru.tests = { + musl = pkgsMusl.file or null; + pkg-config = testers.testMetaPkgConfig finalAttrs.finalPackage; + }; __structuredAttrs = true; meta = { homepage = "https://darwinsys.com/file"; description = "Program that shows the type of files"; - maintainers = with lib.maintainers; [ doronbehar ]; + maintainers = with lib.maintainers; [ + doronbehar + mdaniels5757 + ]; license = lib.licenses.bsd2; pkgConfigModules = [ "libmagic" ]; platforms = lib.platforms.all; diff --git a/pkgs/by-name/fn/fnc/package.nix b/pkgs/by-name/fn/fnc/package.nix index 2e6b2abcde37..20fcea12bbca 100644 --- a/pkgs/by-name/fn/fnc/package.nix +++ b/pkgs/by-name/fn/fnc/package.nix @@ -28,6 +28,8 @@ stdenv.mkDerivation (finalAttrs: { lib.optionals stdenv.cc.isGNU [ # Needed with GCC 12 "-Wno-error=maybe-uninitialized" + # Fix build w/ glibc-2.44 + "-Wno-error=discarded-qualifiers" ] ); diff --git a/pkgs/by-name/fr/freqtweak/package.nix b/pkgs/by-name/fr/freqtweak/package.nix index 82565ad4ebaa..5d252b8ee4bf 100644 --- a/pkgs/by-name/fr/freqtweak/package.nix +++ b/pkgs/by-name/fr/freqtweak/package.nix @@ -6,7 +6,7 @@ pkg-config, fftwFloat, libjack2, - libsigcxx, + libsigcxx_2_0, libxml2, wxwidgets_3_2, @@ -32,7 +32,7 @@ stdenv.mkDerivation { buildInputs = [ fftwFloat libjack2 - libsigcxx + libsigcxx_2_0 libxml2 wxwidgets_3_2 ]; diff --git a/pkgs/by-name/fr/frigate/ai-edge-litert.patch b/pkgs/by-name/fr/frigate/ai-edge-litert.patch deleted file mode 100644 index 3a8c3f8a566f..000000000000 --- a/pkgs/by-name/fr/frigate/ai-edge-litert.patch +++ /dev/null @@ -1,100 +0,0 @@ -diff --git a/frigate/data_processing/real_time/bird.py b/frigate/data_processing/real_time/bird.py -index 7851c0997..520440005 100644 ---- a/frigate/data_processing/real_time/bird.py -+++ b/frigate/data_processing/real_time/bird.py -@@ -22,7 +22,7 @@ from .api import RealTimeProcessorApi - try: - from tflite_runtime.interpreter import Interpreter - except ModuleNotFoundError: -- from tensorflow.lite.python.interpreter import Interpreter -+ from ai_edge_litert.interpreter import Interpreter - - logger = logging.getLogger(__name__) - -diff --git a/frigate/data_processing/real_time/custom_classification.py b/frigate/data_processing/real_time/custom_classification.py -index 229383d9f..2c74a6575 100644 ---- a/frigate/data_processing/real_time/custom_classification.py -+++ b/frigate/data_processing/real_time/custom_classification.py -@@ -32,7 +32,7 @@ from .api import RealTimeProcessorApi - try: - from tflite_runtime.interpreter import Interpreter - except ModuleNotFoundError: -- from tensorflow.lite.python.interpreter import Interpreter -+ from ai_edge_litert.interpreter import Interpreter - - logger = logging.getLogger(__name__) - -@@ -76,7 +76,7 @@ class CustomStateClassificationProcessor(RealTimeProcessorApi): - try: - from tflite_runtime.interpreter import Interpreter - except ModuleNotFoundError: -- from tensorflow.lite.python.interpreter import Interpreter -+ from ai_edge_litert.interpreter import Interpreter - - model_path = os.path.join(self.model_dir, "model.tflite") - labelmap_path = os.path.join(self.model_dir, "labelmap.txt") -diff --git a/frigate/detectors/detector_utils.py b/frigate/detectors/detector_utils.py -index d732de871..d8930b2ae 100644 ---- a/frigate/detectors/detector_utils.py -+++ b/frigate/detectors/detector_utils.py -@@ -6,7 +6,7 @@ import numpy as np - try: - from tflite_runtime.interpreter import Interpreter, load_delegate - except ModuleNotFoundError: -- from tensorflow.lite.python.interpreter import Interpreter, load_delegate -+ from ai_edge_litert.interpreter import Interpreter, load_delegate - - - logger = logging.getLogger(__name__) -diff --git a/frigate/detectors/plugins/cpu_tfl.py b/frigate/detectors/plugins/cpu_tfl.py -index 00351f519..6d336bb6b 100644 ---- a/frigate/detectors/plugins/cpu_tfl.py -+++ b/frigate/detectors/plugins/cpu_tfl.py -@@ -12,7 +12,7 @@ from ..detector_utils import tflite_detect_raw, tflite_init - try: - from tflite_runtime.interpreter import Interpreter - except ModuleNotFoundError: -- from tensorflow.lite.python.interpreter import Interpreter -+ from ai_edge_litert.interpreter import Interpreter - - - logger = logging.getLogger(__name__) -diff --git a/frigate/detectors/plugins/edgetpu_tfl.py b/frigate/detectors/plugins/edgetpu_tfl.py -index 2b94fde39..36c769b4b 100644 ---- a/frigate/detectors/plugins/edgetpu_tfl.py -+++ b/frigate/detectors/plugins/edgetpu_tfl.py -@@ -13,7 +13,7 @@ from frigate.detectors.detector_config import BaseDetectorConfig, ModelTypeEnum - try: - from tflite_runtime.interpreter import Interpreter, load_delegate - except ModuleNotFoundError: -- from tensorflow.lite.python.interpreter import Interpreter, load_delegate -+ from ai_edge_litert.interpreter import Interpreter, load_delegate - - logger = logging.getLogger(__name__) - -diff --git a/frigate/embeddings/onnx/face_embedding.py b/frigate/embeddings/onnx/face_embedding.py -index 04d756897..75dfedc94 100644 ---- a/frigate/embeddings/onnx/face_embedding.py -+++ b/frigate/embeddings/onnx/face_embedding.py -@@ -17,7 +17,7 @@ from .base_embedding import BaseEmbedding - try: - from tflite_runtime.interpreter import Interpreter - except ModuleNotFoundError: -- from tensorflow.lite.python.interpreter import Interpreter -+ from ai_edge_litert.interpreter import Interpreter - - logger = logging.getLogger(__name__) - -diff --git a/frigate/events/audio.py b/frigate/events/audio.py -index e88f2ae71..ad87d19c1 100644 ---- a/frigate/events/audio.py -+++ b/frigate/events/audio.py -@@ -43,7 +43,7 @@ from frigate.video import start_or_restart_ffmpeg, stop_ffmpeg - try: - from tflite_runtime.interpreter import Interpreter - except ModuleNotFoundError: -- from tensorflow.lite.python.interpreter import Interpreter -+ from ai_edge_litert.interpreter import Interpreter - - - logger = logging.getLogger(__name__) diff --git a/pkgs/by-name/fr/frigate/ffmpeg.patch b/pkgs/by-name/fr/frigate/ffmpeg.patch index 2b9d08cf2d06..d2b4a5eea85a 100644 --- a/pkgs/by-name/fr/frigate/ffmpeg.patch +++ b/pkgs/by-name/fr/frigate/ffmpeg.patch @@ -1,47 +1,23 @@ -diff --git a/frigate/config/camera/ffmpeg.py b/frigate/config/camera/ffmpeg.py -index 2c1e4cdca..d1a1f7065 100644 ---- a/frigate/config/camera/ffmpeg.py -+++ b/frigate/config/camera/ffmpeg.py -@@ -1,4 +1,5 @@ - from enum import Enum -+from os.path import join - from typing import Union +diff --git a/frigate/util/config.py b/frigate/util/config.py +index 3e093a978..c9a5d7462 100644 +--- a/frigate/util/config.py ++++ b/frigate/util/config.py +@@ -32,17 +32,7 @@ def resolve_ffmpeg_path(path: str, binary: str = "ffmpeg") -> str: + bundled version so existing configs keep working across an upgrade or a + revert. Custom install paths (anything absolute) are used as-is. + """ +- if path == "default" or ( +- not path.startswith("/") and path not in INCLUDED_FFMPEG_VERSIONS +- ): +- version = DEFAULT_FFMPEG_VERSION +- elif path in INCLUDED_FFMPEG_VERSIONS: +- version = path +- else: +- return f"{path}/bin/{binary}" +- +- return f"/usr/lib/ffmpeg/{version}/bin/{binary}" +- ++ return os.path.join(path, "bin", binary) - from pydantic import Field, field_validator -@@ -71,21 +72,11 @@ class FfmpegConfig(FrigateBaseModel): - - @property - def ffmpeg_path(self) -> str: -- if self.path == "default": -- return f"/usr/lib/ffmpeg/{DEFAULT_FFMPEG_VERSION}/bin/ffmpeg" -- elif self.path in INCLUDED_FFMPEG_VERSIONS: -- return f"/usr/lib/ffmpeg/{self.path}/bin/ffmpeg" -- else: -- return f"{self.path}/bin/ffmpeg" -+ return join(self.path, "bin/ffmpeg") - - @property - def ffprobe_path(self) -> str: -- if self.path == "default": -- return f"/usr/lib/ffmpeg/{DEFAULT_FFMPEG_VERSION}/bin/ffprobe" -- elif self.path in INCLUDED_FFMPEG_VERSIONS: -- return f"/usr/lib/ffmpeg/{self.path}/bin/ffprobe" -- else: -- return f"{self.path}/bin/ffprobe" -+ return join(self.path, "bin/ffprobe") - - - class CameraRoleEnum(str, Enum): -diff --git a/frigate/record/export.py b/frigate/record/export.py -index d4b49bb4b..bbcccff61 100644 ---- a/frigate/record/export.py -+++ b/frigate/record/export.py -@@ -127,7 +127,7 @@ class RecordingExporter(threading.Thread): - minutes = int(diff / 60) - seconds = int(diff % 60) - ffmpeg_cmd = [ -- "/usr/lib/ffmpeg/7.0/bin/ffmpeg", # hardcode path for exports thumbnail due to missing libwebp support -+ self.config.ffmpeg.ffmpeg_path, # hardcode path for exports thumbnail due to missing libwebp support - "-hide_banner", - "-loglevel", - "warning", + def redact_credential(obj: dict[str, Any], key: str) -> None: + """Replace obj[key] with the redaction sentinel if a value is saved, else drop. diff --git a/pkgs/by-name/fr/frigate/fix-tests-media-auth-paths.patch b/pkgs/by-name/fr/frigate/fix-tests-media-auth-paths.patch new file mode 100644 index 000000000000..ac0f75afda85 --- /dev/null +++ b/pkgs/by-name/fr/frigate/fix-tests-media-auth-paths.patch @@ -0,0 +1,32 @@ +From 91711507df5ad880bfcba1e11619441f7d0f9a58 Mon Sep 17 00:00:00 2001 +From: Martin Weinelt +Date: Mon, 13 Jul 2026 14:11:18 +0200 +Subject: [PATCH] Reuse constants in media auth tests + +--- + frigate/test/test_media_auth.py | 5 +++-- + 1 file changed, 3 insertions(+), 2 deletions(-) + +diff --git a/frigate/test/test_media_auth.py b/frigate/test/test_media_auth.py +index d025fea614..0b106047b2 100644 +--- a/frigate/test/test_media_auth.py ++++ b/frigate/test/test_media_auth.py +@@ -20,6 +20,7 @@ + resolve_media_uri, + ) + from frigate.config import FrigateConfig ++from frigate.const import EXPORT_DIR + from frigate.models import Event, Export, Recordings, ReviewSegment + from frigate.test.const import TEST_DB, TEST_DB_CLEANUPS + +@@ -231,8 +232,8 @@ def _insert_export(self, export_id, camera, filename): + camera=camera, + name=f"export-{export_id}", + date=int(datetime.datetime.now().timestamp()), +- video_path=f"/media/frigate/exports/{filename}", +- thumb_path=f"/media/frigate/exports/{filename}.jpg", ++ video_path=os.path.join(EXPORT_DIR, filename), ++ thumb_path=os.path.join(EXPORT_DIR, f"{filename}.jpg"), + in_progress=False, + ).execute() + diff --git a/pkgs/by-name/fr/frigate/models/edgetpu/ssdlite_mobiledet_coco_qat_postprocess/package.nix b/pkgs/by-name/fr/frigate/models/edgetpu/ssdlite_mobiledet_coco_qat_postprocess/package.nix new file mode 100644 index 000000000000..925323b6fbcb --- /dev/null +++ b/pkgs/by-name/fr/frigate/models/edgetpu/ssdlite_mobiledet_coco_qat_postprocess/package.nix @@ -0,0 +1,14 @@ +{ + fetchurl, +}: + +let + model = fetchurl { + url = "https://github.com/google-coral/test_data/raw/release-frogfish/ssdlite_mobiledet_coco_qat_postprocess_edgetpu.tflite"; + hash = "sha256-Siviu7YU5XbVbcuRT6UnUr8PE0EVEnENNV2X+qGzVkE="; + }; +in + +model.overrideAttrs (_: { + passthru.model = model; +}) diff --git a/pkgs/by-name/fr/frigate/models/openvino/ssdlite_mobilenet_v2_coco/package.nix b/pkgs/by-name/fr/frigate/models/openvino/ssdlite_mobilenet_v2_coco/package.nix new file mode 100644 index 000000000000..c961d1291e8a --- /dev/null +++ b/pkgs/by-name/fr/frigate/models/openvino/ssdlite_mobilenet_v2_coco/package.nix @@ -0,0 +1,64 @@ +{ + fetchurl, + frigate, + lib, + stdenv, + ... +}: + +let + inherit (frigate) python3Packages; +in + +stdenv.mkDerivation (finalAttrs: { + pname = "ssdlite_mobilenet_v2_coco"; + version = "2018_05_09"; + + src = fetchurl { + url = "http://download.tensorflow.org/models/object_detection/ssdlite_mobilenet_v2_coco_2018_05_09.tar.gz"; + hash = "sha256-VCRFzOg02/u33xmRQl1HXoWi1+xoxgpPJiuxiqwQyLI="; + }; + + nativeBuildInputs = [ + python3Packages.openvino + ]; + + postPatch = '' + cp --no-preserve=mode ${frigate.src}/docker/main/build_ov_model.py . + substituteInPlace build_ov_model.py \ + --replace-fail "/models/${finalAttrs.pname}_${finalAttrs.version}" "./" \ + --replace-fail "/models/" "dist/" + ''; + + buildPhase = '' + runHook preBuild + mkdir dist + python3 build_ov_model.py + runHook postBuild + ''; + + installPhase = '' + runHook preInstall + mkdir -p $out + cp dist/*.{bin,xml} $out/ + runHook postInstall + ''; + + passthru = { + model = "${finalAttrs.finalPackage}/ssdlite_mobilnet_v2.xml"; + labelmap = fetchurl { + url = "https://github.com/openvinotoolkit/open_model_zoo/raw/master/data/dataset_classes/coco_91cl_bkgr.txt"; + hash = "sha256-cQBhlxYm2yS6s7rm/06c5uZmUFZZkBI/P4bxLThbN9E="; + # https://github.com/blakeblackshear/frigate/commit/8ac3114f9a014356272b8a44b752e82df342f245 + postFetch = '' + sed -i "s/truck/car/g" $out + ''; + }; + }; + + meta = { + description = "Object detection model trained on the COCO dataset."; + license = lib.licenses.asl20; + homepage = "https://www.kaggle.com/models/tensorflow/ssdlite-mobilenet-v2/"; + }; +}) diff --git a/pkgs/by-name/fr/frigate/models/tflite/ssdlite_mobiledet_coco_qat_postprocess/package.nix b/pkgs/by-name/fr/frigate/models/tflite/ssdlite_mobiledet_coco_qat_postprocess/package.nix new file mode 100644 index 000000000000..a9399e969a32 --- /dev/null +++ b/pkgs/by-name/fr/frigate/models/tflite/ssdlite_mobiledet_coco_qat_postprocess/package.nix @@ -0,0 +1,14 @@ +{ + fetchurl, +}: + +let + model = fetchurl { + url = "https://github.com/google-coral/test_data/raw/release-frogfish/ssdlite_mobiledet_coco_qat_postprocess.tflite"; + hash = "sha256-kLszpjTgQZFMwYGapd+ZgY5sOWxNLblSwP16nP/Eck8="; + }; +in + +model.overrideAttrs (_: { + passthru.model = model; +}) diff --git a/pkgs/by-name/fr/frigate/models/tflite/yamnet_classification_v1/package.nix b/pkgs/by-name/fr/frigate/models/tflite/yamnet_classification_v1/package.nix new file mode 100644 index 000000000000..255d8f4d1b2e --- /dev/null +++ b/pkgs/by-name/fr/frigate/models/tflite/yamnet_classification_v1/package.nix @@ -0,0 +1,32 @@ +{ + fetchzip, + lib, + stdenv, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "yamnet_classification_v1"; + version = "0-unstable"; + + src = fetchzip { + url = "https://www.kaggle.com/api/v1/models/google/yamnet/tfLite/classification-tflite/1/download"; + extension = "tar.gz"; + hash = "sha256-FRL0lpbjgAV7HlaZIR1Hf/hr1bcfSMSeYdeGzMYpDf0="; + }; + + dontBuild = true; + + installPhase = '' + runHook preInstall + mkdir $out + mv 1.tflite $out/yamnet_classification_v1.tflite + runHook postInstall + ''; + + passthru.model = "${finalAttrs.finalPackage}/${finalAttrs.pname}.tflite"; + + meta = { + homepage = "https://www.kaggle.com/models/google/yamnet/tfLite/classification-tflite"; + license = lib.licenses.asl20; + }; +}) diff --git a/pkgs/by-name/fr/frigate/package.nix b/pkgs/by-name/fr/frigate/package.nix index f395c2a74eb1..bdf4fb1931d4 100644 --- a/pkgs/by-name/fr/frigate/package.nix +++ b/pkgs/by-name/fr/frigate/package.nix @@ -1,47 +1,21 @@ { - lib, - stdenv, - replaceVars, addDriverRunpath, callPackage, - python313Packages, fetchFromGitHub, rustPlatform, - fetchurl, ffmpeg-headless, - sqlite-vec, frigate, + lib, nixosTests, - go2rtc, + python313Packages, + replaceVars, + sqlite-vec, + stdenv, }: let - version = "0.17.2"; - - src = fetchFromGitHub { - name = "frigate-${version}-source"; - owner = "blakeblackshear"; - repo = "frigate"; - tag = "v${version}"; - hash = "sha256-8ujG5rVGqIJxM+IiQKvudrA0xqfz+3Uisl/zXwARPpY="; - }; - - frigate-web = callPackage ./web.nix { - inherit version src; - }; - python3Packages = python313Packages.overrideScope ( self: super: { - joserfc = super.joserfc.overridePythonAttrs (oldAttrs: { - version = "1.1.0"; - src = fetchFromGitHub { - owner = "authlib"; - repo = "joserfc"; - tag = version; - hash = "sha256-95xtUzzIxxvDtpHX/5uCHnTQTB8Fc08DZGUOR/SdKLs="; - }; - }); - # transformers 4.* is not compatible with the latest tokenizers tokenizers = super.tokenizers.overridePythonAttrs ( oldAttrs: @@ -86,40 +60,19 @@ let ); inherit (python3Packages) python; - - # Tensorflow audio model - # https://github.com/blakeblackshear/frigate/blob/v0.15.0/docker/main/Dockerfile#L125 - tflite_audio_model = fetchurl { - url = "https://www.kaggle.com/api/v1/models/google/yamnet/tfLite/classification-tflite/1/download"; - hash = "sha256-G5cbITJ2AnOl+49dxQToZ4OyeFO7MTXVVa4G8eHjZfM="; - }; - - # Tensorflow Lite models - # https://github.com/blakeblackshear/frigate/blob/v0.15.0/docker/main/Dockerfile#L115-L117 - tflite_cpu_model = fetchurl { - url = "https://github.com/google-coral/test_data/raw/release-frogfish/ssdlite_mobiledet_coco_qat_postprocess.tflite"; - hash = "sha256-kLszpjTgQZFMwYGapd+ZgY5sOWxNLblSwP16nP/Eck8="; - }; - tflite_edgetpu_model = fetchurl { - url = "https://github.com/google-coral/test_data/raw/release-frogfish/ssdlite_mobiledet_coco_qat_postprocess_edgetpu.tflite"; - hash = "sha256-Siviu7YU5XbVbcuRT6UnUr8PE0EVEnENNV2X+qGzVkE="; - }; - - # TODO: OpenVino model - # https://github.com/blakeblackshear/frigate/blob/v0.15.0/docker/main/Dockerfile#L64-L77 - # https://github.com/blakeblackshear/frigate/blob/v0.15.0/docker/main/Dockerfile#L120-L123 - # Convert https://www.kaggle.com/models/tensorflow/ssdlite-mobilenet-v2 with https://github.com/blakeblackshear/frigate/blob/v0.15.0/docker/main/build_ov_model.py into OpenVino IR format - coco_91cl_bkgr = fetchurl { - url = "https://github.com/openvinotoolkit/open_model_zoo/raw/master/data/dataset_classes/coco_91cl_bkgr.txt"; - hash = "sha256-5Cj2vEiWR8Z9d2xBmVoLZuNRv4UOuxHSGZQWTJorXUQ="; - }; in -python3Packages.buildPythonApplication rec { +python3Packages.buildPythonApplication (finalAttrs: { pname = "frigate"; - inherit version; + version = "0.18.0"; pyproject = false; - inherit src; + src = fetchFromGitHub { + name = "frigate-${finalAttrs.version}-source"; + owner = "blakeblackshear"; + repo = "frigate"; + tag = "v${finalAttrs.version}"; + hash = "sha256-2FJG7tEZCuCQ6VJga9BMiuLTeswmlG8oN1MO6t0eroM="; + }; patches = [ # Always lookup ffmpeg from config setting @@ -130,24 +83,27 @@ python3Packages.buildPythonApplication rec { inherit (addDriverRunpath) driverLink; }) - # Use ai-edge-litert as tensorflow interpreter - # https://github.com/blakeblackshear/frigate/pull/21876 - ./ai-edge-litert.patch - # Disable failing optimization in onnxruntime # https://github.com/microsoft/onnxruntime/issues/26717 + # https://github.com/microsoft/onnxruntime/pull/29196 ./onnxruntime-compat.patch - # Fix excessive trailing whitespaces in process commandlines - # https://github.com/blakeblackshear/frigate/pull/22089 - ./proc-cmdline-strip.patch + # Reuse EXPORT_DIR in tests + ./fix-tests-media-auth-paths.patch # Fix more granular dtype resolution in Pandas 3.0 ./pandas3-compat.patch + + # Various fixes for newer library packages, migrates to + # - FastAPI lifespan, + # - native tz-aware objects, + # - Pydantic TypeAdapter + # https://github.com/blakeblackshear/frigate/pull/23641 + ./pr23641.patch ]; postPatch = '' - echo 'VERSION = "${version}"' > frigate/version.py + echo 'VERSION = "${finalAttrs.version}"' > frigate/version.py substituteInPlace \ frigate/app.py \ @@ -174,90 +130,94 @@ python3Packages.buildPythonApplication rec { substituteInPlace frigate/db/sqlitevecq.py \ --replace-fail "/usr/local/lib/vec0" "${lib.getLib sqlite-vec}/lib/vec0${stdenv.hostPlatform.extensions.sharedLibrary}" - # provide default paths for models and maps that are shipped with frigate + # hardcoded default models shipped with Frigate substituteInPlace frigate/config/config.py \ - --replace-fail "/cpu_model.tflite" "${tflite_cpu_model}" \ - --replace-fail "/edgetpu_model.tflite" "${tflite_edgetpu_model}" + --replace-fail "/cpu_model.tflite" "${frigate.models.tflite.ssdlite_mobiledet_coco_qat_postprocess}" \ + --replace-fail "/edgetpu_model.tflite" "${frigate.models.edgetpu.ssdlite_mobiledet_coco_qat_postprocess}" \ + --replace-fail "/openvino-model/ssdlite_mobilenet_v2.xml" "${frigate.models.openvino.ssdlite_mobilenet_v2_coco.model}" \ + --replace-fail "/openvino-model/coco_91cl_bkgr.txt" "${frigate.models.openvino.ssdlite_mobilenet_v2_coco.labelmap}" substituteInPlace frigate/detectors/detector_config.py \ --replace-fail "/labelmap.txt" "${placeholder "out"}/share/frigate/labelmap.txt" substituteInPlace frigate/events/audio.py \ - --replace-fail "/cpu_audio_model.tflite" "${placeholder "out"}/share/frigate/cpu_audio_model.tflite" \ + --replace-fail "/cpu_audio_model.tflite" "${frigate.models.tflite.yamnet_classification_v1.model}" \ --replace-fail "/audio-labelmap.txt" "${placeholder "out"}/share/frigate/audio-labelmap.txt" ''; dontBuild = true; - dependencies = with python3Packages; [ - # docker/main/requirements-wheel.txt - # TODO: degirum (no source repo, binary wheels only) - ai-edge-litert - aiofiles - aiohttp - appdirs - argcomplete - click - contextlib2 - cryptography - distlib - fastapi - faster-whisper - filelock - google-genai - importlib-metadata - importlib-resources - joserfc - keras # via tensorflow.keras - librosa - markupsafe - memray - netaddr - netifaces - norfair - numpy - ollama - onnxruntime - onvif-zeep-async - openai - opencv4 - openvino - paho-mqtt - pandas - pathvalidate - peewee - peewee-migrate - prometheus-client - psutil - py3nvml - pyclipper - pydantic - python-multipart - pytz - py-vapid - pywebpush - pyzmq - rapidfuzz - requests - ruamel-yaml - scipy - setproctitle - shapely - sherpa-onnx - slowapi - soundfile - starlette - starlette-context - tensorflow - titlecase - transformers - tzlocal - unidecode - uvicorn - verboselogs - virtualenv - ws4py - ]; + dependencies = + with python3Packages; + [ + # docker/main/requirements-wheel.txt + ai-edge-litert + aiofiles + aiohttp + appdirs + argcomplete + click + contextlib2 + cryptography + distlib + fastapi + faster-whisper + filelock + google-genai + httpx + importlib-metadata + importlib-resources + joserfc + keras # via tensorflow.keras + librosa + markupsafe + memray + netaddr + netifaces + norfair + numpy + ollama + onnxruntime + onvif-zeep-async + openai + opencv4 + openvino + paho-mqtt + pandas + pathvalidate + peewee + peewee-migrate + prometheus-client + psutil + py3nvml + pyclipper + pydantic + python-multipart + py-vapid + pywebpush + pyzmq + rapidfuzz + requests + ruamel-yaml + scipy + setproctitle + shapely + sherpa-onnx + slowapi + soundfile + starlette + starlette-context + tensorflow + titlecase + transformers + tzlocal + unidecode + uvicorn + verboselogs + virtualenv + ws4py + ] + ++ httpx.optional-dependencies.http2; installPhase = '' runHook preInstall @@ -268,11 +228,7 @@ python3Packages.buildPythonApplication rec { mkdir -p $out/share/frigate cp -R {migrations,labelmap.txt,audio-labelmap.txt} $out/share/frigate/ - tar --extract --gzip --file ${tflite_audio_model} - cp --no-preserve=mode ./1.tflite $out/share/frigate/cpu_audio_model.tflite - - cp --no-preserve=mode ${coco_91cl_bkgr} $out/share/frigate/coco_91cl_bkgr.txt - sed -i 's/truck/car/g' $out/share/frigate/coco_91cl_bkgr.txt + ln -s ${frigate.models.tflite.yamnet_classification_v1.model} $out/share/frigate/cpu_audio_model.tflite runHook postInstall ''; @@ -283,9 +239,9 @@ python3Packages.buildPythonApplication rec { ]; preCheck = '' - # Unavailable in the build sandbox + # FHS paths are unreachable in the build sandbox substituteInPlace frigate/const.py \ - --replace-fail "/var/lib/frigate" "$TMPDIR/" \ + --replace-fail "/var/lib/frigate" "$TMPDIR" \ --replace-fail "/var/cache/frigate" "$TMPDIR" ''; @@ -300,16 +256,47 @@ python3Packages.buildPythonApplication rec { ]; passthru = { - web = frigate-web; - inherit python; - pythonPath = (python3Packages.makePythonPath dependencies) + ":${frigate}/${python.sitePackages}"; + inherit python python3Packages; + pythonPath = + (python3Packages.makePythonPath finalAttrs.finalPackage.dependencies) + + ":${frigate}/${python.sitePackages}"; + web = callPackage ./web.nix { + inherit (finalAttrs) version src; + }; + models = { + # Google Coral Accelerators as Tensorflow Delegate + # https://docs.frigate.video/configuration/object_detectors/#edge-tpu-detector + edgetpu = lib.recurseIntoAttrs ( + lib.packagesFromDirectoryRecursive { + inherit callPackage; + directory = ./models/edgetpu; + } + ); + # Intel OpenVINO for CPU/GPU/NPU + # https://docs.frigate.video/configuration/object_detectors/#openvino-detector + openvino = lib.recurseIntoAttrs ( + lib.packagesFromDirectoryRecursive { + inherit callPackage; + directory = ./models/openvino; + } + ); + # Tensorflow Lite CPU models + # https://docs.frigate.video/configuration/object_detectors/#cpu-detector-not-recommended + # https://docs.frigate.video/configuration/audio_detectors/ + tflite = lib.recurseIntoAttrs ( + lib.packagesFromDirectoryRecursive { + inherit callPackage; + directory = ./models/tflite; + } + ); + }; tests = { inherit (nixosTests) frigate; }; }; meta = { - changelog = "https://github.com/blakeblackshear/frigate/releases/tag/${src.tag}"; + changelog = "https://github.com/blakeblackshear/frigate/releases/tag/${finalAttrs.src.tag}"; description = "NVR with realtime local object detection for IP cameras"; longDescription = '' A complete and local NVR designed for Home Assistant with AI @@ -320,4 +307,4 @@ python3Packages.buildPythonApplication rec { license = lib.licenses.mit; maintainers = with lib.maintainers; [ hexa ]; }; -} +}) diff --git a/pkgs/by-name/fr/frigate/pr23641.patch b/pkgs/by-name/fr/frigate/pr23641.patch new file mode 100644 index 000000000000..281c651fcdde --- /dev/null +++ b/pkgs/by-name/fr/frigate/pr23641.patch @@ -0,0 +1,770 @@ +From e4bba6f9c03af6fe20c8bd090bb1bc94cbd9ef1f Mon Sep 17 00:00:00 2001 +From: Martin Weinelt +Date: Mon, 6 Jul 2026 13:14:54 +0200 +Subject: [PATCH 1/5] Migrate to fastapi lifespan for startup events + +The `on_event` style decorator is deprecated + +https://fastapi.tiangolo.com/advanced/events/ +--- + frigate/api/fastapi_app.py | 21 ++++++++++++--------- + 1 file changed, 12 insertions(+), 9 deletions(-) + +diff --git a/frigate/api/fastapi_app.py b/frigate/api/fastapi_app.py +index 387f0473fc..86058bfdaa 100644 +--- a/frigate/api/fastapi_app.py ++++ b/frigate/api/fastapi_app.py +@@ -1,6 +1,7 @@ + import asyncio + import logging + import re ++from contextlib import asynccontextmanager + + from fastapi import Depends, FastAPI, Request + from fastapi.responses import JSONResponse +@@ -77,9 +78,20 @@ def create_fastapi_app( + enforce_default_admin: bool = True, + config_holder: ConfigHolder | None = None, + ): ++ @asynccontextmanager ++ async def lifespan(app: FastAPI): ++ logger.info("FastAPI started") ++ asyncio.create_task( ++ debug_replay_auto_stop_watchdog( ++ replay_manager, frigate_config, config_publisher ++ ) ++ ) ++ yield ++ + logger.info("Starting FastAPI app") + app = FastAPI( + debug=False, ++ lifespan=lifespan, + swagger_ui_parameters={"apisSorter": "alpha", "operationsSorter": "alpha"}, + dependencies=[Depends(require_admin_by_default())] + if enforce_default_admin +@@ -115,15 +127,6 @@ async def frigate_middleware(request: Request, call_next): + database.close() + return response + +- @app.on_event("startup") +- async def startup(): +- logger.info("FastAPI started") +- asyncio.create_task( +- debug_replay_auto_stop_watchdog( +- replay_manager, frigate_config, config_publisher +- ) +- ) +- + # Rate limiter (used for login endpoint) + if frigate_config.auth.failed_login_rate_limit is None: + limiter.enabled = False + +From ef8fcf2328bd59b6d30c7ca523e39909a8b8c01e Mon Sep 17 00:00:00 2001 +From: Martin Weinelt +Date: Mon, 6 Jul 2026 13:16:58 +0200 +Subject: [PATCH 2/5] Migrate to pydantic TypeAdapter + +https://pydantic.dev/docs/validation/2.12/get-started/migration/#introduction-of-typeadapter +--- + frigate/test/test_object_detector.py | 18 ++++++++++++------ + 1 file changed, 12 insertions(+), 6 deletions(-) + +diff --git a/frigate/test/test_object_detector.py b/frigate/test/test_object_detector.py +index dc15b23516..33748c2807 100644 +--- a/frigate/test/test_object_detector.py ++++ b/frigate/test/test_object_detector.py +@@ -2,7 +2,7 @@ + from unittest.mock import Mock, patch + + import numpy as np +-from pydantic import parse_obj_as ++from pydantic import TypeAdapter + + import frigate.detectors as detectors + import frigate.object_detection.base +@@ -19,8 +19,8 @@ def test_localdetectorprocess_should_only_create_specified_detector_type(self): + "frigate.detectors.api_types", + {det_type: Mock() for det_type in DetectorTypeEnum}, + ): +- test_cfg = parse_obj_as( +- DetectorConfig, ({"type": det_type, "model": {}}) ++ test_cfg = TypeAdapter(DetectorConfig).validate_python( ++ {"type": det_type, "model": {}} + ) + test_cfg.model.path = "/test/modelpath" + test_obj = frigate.object_detection.base.LocalObjectDetector( +@@ -44,7 +44,9 @@ def test_detect_raw_given_tensor_input_should_return_api_detect_raw_result(self) + TEST_DATA = [0, 1, 2, 3, 4, 5, 6, 7, 8, 9] + TEST_DETECT_RESULT = np.ndarray([1, 2, 4, 8, 16, 32]) + test_obj_detect = frigate.object_detection.base.LocalObjectDetector( +- detector_config=parse_obj_as(DetectorConfig, {"type": "cpu", "model": {}}) ++ detector_config=TypeAdapter(DetectorConfig).validate_python( ++ {"type": "cpu", "model": {}} ++ ) + ) + + mock_det_api = mock_cputfl.return_value +@@ -67,7 +69,9 @@ def test_detect_raw_given_tensor_input_should_call_api_detect_raw_with_transpose + TEST_DATA = np.zeros((1, 32, 32, 3), np.uint8) + TEST_DETECT_RESULT = np.ndarray([1, 2, 4, 8, 16, 32]) + +- test_cfg = parse_obj_as(DetectorConfig, {"type": "cpu", "model": {}}) ++ test_cfg = TypeAdapter(DetectorConfig).validate_python( ++ {"type": "cpu", "model": {}} ++ ) + test_cfg.model.input_tensor = InputTensorEnum.nchw + + test_obj_detect = frigate.object_detection.base.LocalObjectDetector( +@@ -116,7 +120,9 @@ def test_detect_given_tensor_input_should_return_lfiltered_detections( + "label-5", + ] + +- test_cfg = parse_obj_as(DetectorConfig, {"type": "cpu", "model": {}}) ++ test_cfg = TypeAdapter(DetectorConfig).validate_python( ++ {"type": "cpu", "model": {}} ++ ) + test_cfg.model = ModelConfig() + test_obj_detect = frigate.object_detection.base.LocalObjectDetector( + detector_config=test_cfg, + +From e9f1435eeb337bf7e269af1b09a0b1b87de719d5 Mon Sep 17 00:00:00 2001 +From: Martin Weinelt +Date: Mon, 6 Jul 2026 13:17:16 +0200 +Subject: [PATCH 3/5] Replace pytz with native tz-aware objects and zoneinfo + library + +Supported from Python 3.9, see https://peps.python.org/pep-0615/. Also +https://blog.ganssle.io/articles/2019/11/utcnow.html. +--- + docker/main/requirements-wheels.txt | 1 - + docs/static/frigate-api.yaml | 14 +++---- + .../api/defs/query/app_query_parameters.py | 2 +- + .../api/defs/query/events_query_parameters.py | 6 +-- + .../defs/query/recordings_query_parameters.py | 2 +- + .../api/defs/query/review_query_parameters.py | 2 +- + frigate/api/media.py | 4 +- + frigate/api/preview.py | 4 +- + frigate/api/record.py | 2 +- + frigate/record/export.py | 10 ++--- + frigate/test/http_api/test_http_media.py | 39 +++++++++---------- + frigate/test/http_api/test_http_review.py | 2 +- + frigate/util/time.py | 17 ++++---- + 13 files changed, 50 insertions(+), 55 deletions(-) + +diff --git a/docker/main/requirements-wheels.txt b/docker/main/requirements-wheels.txt +index 5ed9664fc2..164ab3b853 100644 +--- a/docker/main/requirements-wheels.txt ++++ b/docker/main/requirements-wheels.txt +@@ -25,7 +25,6 @@ peewee_migrate == 1.14.* + psutil == 7.1.* + pydantic == 2.10.* + git+https://github.com/fbcotter/py3nvml#egg=py3nvml +-pytz == 2025.* + pyzmq == 26.2.* + ruamel.yaml == 0.18.* + tzlocal == 5.2 +diff --git a/docs/static/frigate-api.yaml b/docs/static/frigate-api.yaml +index fe467e0c62..3ce79e4ae6 100644 +--- a/docs/static/frigate-api.yaml ++++ b/docs/static/frigate-api.yaml +@@ -2087,7 +2087,7 @@ paths: + required: false + schema: + type: string +- default: utc ++ default: UTC + title: Timezone + responses: + '200': +@@ -3129,7 +3129,7 @@ paths: + anyOf: + - type: string + - type: 'null' +- default: utc ++ default: UTC + title: Timezone + responses: + '200': +@@ -4227,7 +4227,7 @@ paths: + anyOf: + - type: string + - type: 'null' +- default: utc ++ default: UTC + title: Timezone + responses: + '200': +@@ -4479,7 +4479,7 @@ paths: + anyOf: + - type: string + - type: 'null' +- default: utc ++ default: UTC + title: Timezone + - name: min_score + in: query +@@ -4559,7 +4559,7 @@ paths: + anyOf: + - type: string + - type: 'null' +- default: utc ++ default: UTC + title: Timezone + - name: has_clip + in: query +@@ -6854,7 +6854,7 @@ paths: + required: false + schema: + type: string +- default: utc ++ default: UTC + title: Timezone + - name: cameras + in: query +@@ -6904,7 +6904,7 @@ paths: + required: false + schema: + type: string +- default: utc ++ default: UTC + title: Timezone + responses: + '200': +diff --git a/frigate/api/defs/query/app_query_parameters.py b/frigate/api/defs/query/app_query_parameters.py +index 626d39679b..26974d59b9 100644 +--- a/frigate/api/defs/query/app_query_parameters.py ++++ b/frigate/api/defs/query/app_query_parameters.py +@@ -7,4 +7,4 @@ class AppTimelineHourlyQueryParameters(BaseModel): + after: float | None = None + before: float | None = None + limit: int | None = 200 +- timezone: str | None = "utc" ++ timezone: str | None = "UTC" +diff --git a/frigate/api/defs/query/events_query_parameters.py b/frigate/api/defs/query/events_query_parameters.py +index 06d0dfc3af..30d0fcac50 100644 +--- a/frigate/api/defs/query/events_query_parameters.py ++++ b/frigate/api/defs/query/events_query_parameters.py +@@ -39,7 +39,7 @@ class EventsQueryParams(BaseModel): + max_length: float | None = None + event_id: str | None = None + sort: str | None = None +- timezone: str | None = "utc" ++ timezone: str | None = "UTC" + + + class EventsSearchQueryParams(BaseModel): +@@ -66,7 +66,7 @@ class EventsSearchQueryParams(BaseModel): + has_clip: bool | None = None + has_snapshot: bool | None = None + is_submitted: bool | None = None +- timezone: str | None = "utc" ++ timezone: str | None = "UTC" + min_score: float | None = None + max_score: float | None = None + min_speed: float | None = None +@@ -76,6 +76,6 @@ class EventsSearchQueryParams(BaseModel): + + + class EventsSummaryQueryParams(BaseModel): +- timezone: str | None = "utc" ++ timezone: str | None = "UTC" + has_clip: int | None = None + has_snapshot: int | None = None +diff --git a/frigate/api/defs/query/recordings_query_parameters.py b/frigate/api/defs/query/recordings_query_parameters.py +index 770da96bb8..cd7b4221c2 100644 +--- a/frigate/api/defs/query/recordings_query_parameters.py ++++ b/frigate/api/defs/query/recordings_query_parameters.py +@@ -3,7 +3,7 @@ + + + class MediaRecordingsSummaryQueryParams(BaseModel): +- timezone: str = "utc" ++ timezone: str = "UTC" + cameras: str | None = "all" + + +diff --git a/frigate/api/defs/query/review_query_parameters.py b/frigate/api/defs/query/review_query_parameters.py +index b16146a9bc..16f759f42a 100644 +--- a/frigate/api/defs/query/review_query_parameters.py ++++ b/frigate/api/defs/query/review_query_parameters.py +@@ -19,7 +19,7 @@ class ReviewSummaryQueryParams(BaseModel): + cameras: str = "all" + labels: str = "all" + zones: str = "all" +- timezone: str = "utc" ++ timezone: str = "UTC" + + + class ReviewActivityMotionQueryParams(BaseModel): +diff --git a/frigate/api/media.py b/frigate/api/media.py +index c6fa90c068..a5f5e1bab8 100644 +--- a/frigate/api/media.py ++++ b/frigate/api/media.py +@@ -11,10 +11,10 @@ + from pathlib import Path as FilePath + from typing import Any + from urllib.parse import unquote ++from zoneinfo import ZoneInfo + + import cv2 + import numpy as np +-import pytz + from fastapi import APIRouter, Depends, Path, Query, Request, Response + from fastapi.responses import FileResponse, JSONResponse, StreamingResponse + from pathvalidate import sanitize_filename +@@ -714,7 +714,7 @@ async def vod_hour( + parts = year_month.split("-") + start_date = ( + datetime(int(parts[0]), int(parts[1]), day, hour, tzinfo=UTC) +- - datetime.now(pytz.timezone(tz_name.replace(",", "/"))).utcoffset() ++ - datetime.now(ZoneInfo(tz_name.replace(",", "/"))).utcoffset() + ) + end_date = start_date + timedelta(hours=1) - timedelta(milliseconds=1) + start_ts = start_date.timestamp() +diff --git a/frigate/api/preview.py b/frigate/api/preview.py +index 1047591434..af84117fd6 100644 +--- a/frigate/api/preview.py ++++ b/frigate/api/preview.py +@@ -5,8 +5,8 @@ + import os + import threading + from datetime import UTC, datetime, timedelta ++from zoneinfo import ZoneInfo + +-import pytz + from fastapi import APIRouter, Depends, HTTPException + from fastapi.responses import JSONResponse + +@@ -126,7 +126,7 @@ def preview_hour( + parts = year_month.split("-") + start_date = ( + datetime(int(parts[0]), int(parts[1]), int(day), int(hour), tzinfo=UTC) +- - datetime.now(pytz.timezone(tz_name.replace(",", "/"))).utcoffset() ++ - datetime.now(ZoneInfo(tz_name.replace(",", "/"))).utcoffset() + ) + end_date = start_date + timedelta(hours=1) - timedelta(milliseconds=1) + start_ts = start_date.timestamp() +diff --git a/frigate/api/record.py b/frigate/api/record.py +index 5db257f482..3352ec039b 100644 +--- a/frigate/api/record.py ++++ b/frigate/api/record.py +@@ -120,7 +120,7 @@ def all_recordings_summary( + @router.get( + "/{camera_name}/recordings/summary", dependencies=[Depends(require_camera_access)] + ) +-async def recordings_summary(camera_name: str, timezone: str = "utc"): ++async def recordings_summary(camera_name: str, timezone: str = "UTC"): + """Returns hourly summary for recordings of given camera""" + + time_range_query = ( +diff --git a/frigate/record/export.py b/frigate/record/export.py +index 5d307077c9..0564dee04b 100644 +--- a/frigate/record/export.py ++++ b/frigate/record/export.py +@@ -12,8 +12,8 @@ + from collections.abc import Callable + from enum import Enum + from pathlib import Path ++from zoneinfo import ZoneInfo, ZoneInfoNotFoundError + +-import pytz # type: ignore[import-untyped] + from peewee import DoesNotExist + + from frigate.config import FfmpegConfig, FrigateConfig +@@ -371,8 +371,8 @@ def get_datetime_from_timestamp(self, timestamp: int) -> str: + tz_name = self.config.ui.timezone + if tz_name: + try: +- tz = pytz.timezone(tz_name) +- except pytz.UnknownTimeZoneError: ++ tz = ZoneInfo(tz_name) ++ except (ValueError, ZoneInfoNotFoundError): + tz = None + if tz is not None: + return datetime.datetime.fromtimestamp(timestamp, tz=tz).strftime( +@@ -533,8 +533,8 @@ def _build_recording_segment_chapter_metadata_file( + tz: datetime.tzinfo | None = None + if tz_name: + try: +- tz = pytz.timezone(tz_name) +- except pytz.UnknownTimeZoneError: ++ tz = ZoneInfo(tz_name) ++ except (ValueError, ZoneInfoNotFoundError): + tz = None + if tz is None: + tz = datetime.UTC +diff --git a/frigate/test/http_api/test_http_media.py b/frigate/test/http_api/test_http_media.py +index b2d83cbc8a..8a3835c324 100644 +--- a/frigate/test/http_api/test_http_media.py ++++ b/frigate/test/http_api/test_http_media.py +@@ -1,8 +1,8 @@ + """Unit tests for recordings/media API endpoints.""" + + from datetime import UTC, datetime ++from zoneinfo import ZoneInfo + +-import pytz + from fastapi import Request + + from frigate.api.auth import get_allowed_cameras_for_filter, get_current_user +@@ -51,16 +51,16 @@ def test_recordings_summary_across_dst_spring_forward(self): + In 2024, DST in America/New_York transitions on March 10, 2024 at 2:00 AM + Clocks spring forward from 2:00 AM to 3:00 AM (EST to EDT) + """ +- tz = pytz.timezone("America/New_York") ++ tz = ZoneInfo("America/New_York") + + # March 9, 2024 at 12:00 PM EST (before DST) +- march_9_noon = tz.localize(datetime(2024, 3, 9, 12, 0, 0)).timestamp() ++ march_9_noon = datetime(2024, 3, 9, 12, 0, 0, tzinfo=tz).timestamp() + + # March 10, 2024 at 12:00 PM EDT (after DST transition) +- march_10_noon = tz.localize(datetime(2024, 3, 10, 12, 0, 0)).timestamp() ++ march_10_noon = datetime(2024, 3, 10, 12, 0, 0, tzinfo=tz).timestamp() + + # March 11, 2024 at 12:00 PM EDT (after DST) +- march_11_noon = tz.localize(datetime(2024, 3, 11, 12, 0, 0)).timestamp() ++ march_11_noon = datetime(2024, 3, 11, 12, 0, 0, tzinfo=tz).timestamp() + + with AuthTestClient(self.app) as client: + # Insert recordings for each day +@@ -124,19 +124,16 @@ def test_recordings_summary_across_dst_fall_back(self): + In 2024, DST in America/New_York transitions on November 3, 2024 at 2:00 AM + Clocks fall back from 2:00 AM to 1:00 AM (EDT to EST) + """ +- tz = pytz.timezone("America/New_York") ++ tz = ZoneInfo("America/New_York") + + # November 2, 2024 at 12:00 PM EDT (before DST transition) +- nov_2_noon = tz.localize(datetime(2024, 11, 2, 12, 0, 0)).timestamp() ++ nov_2_noon = datetime(2024, 11, 2, 12, 0, 0, tzinfo=tz).timestamp() + + # November 3, 2024 at 12:00 PM EST (after DST transition) +- # Need to specify is_dst=False to get the time after fall back +- nov_3_noon = tz.localize( +- datetime(2024, 11, 3, 12, 0, 0), is_dst=False +- ).timestamp() ++ nov_3_noon = datetime(2024, 11, 3, 12, 0, 0, tzinfo=tz).timestamp() + + # November 4, 2024 at 12:00 PM EST (after DST) +- nov_4_noon = tz.localize(datetime(2024, 11, 4, 12, 0, 0)).timestamp() ++ nov_4_noon = datetime(2024, 11, 4, 12, 0, 0, tzinfo=tz).timestamp() + + with AuthTestClient(self.app) as client: + # Insert recordings for each day +@@ -197,13 +194,13 @@ def test_recordings_summary_multiple_cameras_across_dst(self): + """ + Test recordings summary with multiple cameras across DST boundary. + """ +- tz = pytz.timezone("America/New_York") ++ tz = ZoneInfo("America/New_York") + + # March 9, 2024 at 10:00 AM EST (before DST) +- march_9_morning = tz.localize(datetime(2024, 3, 9, 10, 0, 0)).timestamp() ++ march_9_morning = datetime(2024, 3, 9, 10, 0, 0, tzinfo=tz).timestamp() + + # March 10, 2024 at 3:00 PM EDT (after DST transition) +- march_10_afternoon = tz.localize(datetime(2024, 3, 10, 15, 0, 0)).timestamp() ++ march_10_afternoon = datetime(2024, 3, 10, 15, 0, 0, tzinfo=tz).timestamp() + + with AuthTestClient(self.app) as client: + # Override allowed cameras for this test to include both +@@ -266,15 +263,15 @@ def test_recordings_summary_at_dst_transition_time(self): + """ + Test recordings that span the exact DST transition time. + """ +- tz = pytz.timezone("America/New_York") ++ tz = ZoneInfo("America/New_York") + + # March 10, 2024 at 1:00 AM EST (1 hour before DST transition) + # At 2:00 AM, clocks jump to 3:00 AM +- before_transition = tz.localize(datetime(2024, 3, 10, 1, 0, 0)).timestamp() ++ before_transition = datetime(2024, 3, 10, 1, 0, 0, tzinfo=tz).timestamp() + + # Recording that spans the transition (1:00 AM to 3:30 AM EDT) + # This is 1.5 hours of actual time but spans the "missing" hour +- after_transition = tz.localize(datetime(2024, 3, 10, 3, 30, 0)).timestamp() ++ after_transition = datetime(2024, 3, 10, 3, 30, 0, tzinfo=tz).timestamp() + + with AuthTestClient(self.app) as client: + Recordings.insert( +@@ -334,7 +331,7 @@ def test_recordings_summary_utc_timezone(self): + + # Test with UTC timezone + response = client.get( +- "/recordings/summary", params={"timezone": "utc", "cameras": "all"} ++ "/recordings/summary", params={"timezone": "UTC", "cameras": "all"} + ) + + assert response.status_code == 200 +@@ -365,8 +362,8 @@ def test_recordings_summary_single_camera_filter(self): + """ + Test recordings summary filtered to a single camera. + """ +- tz = pytz.timezone("America/New_York") +- march_10_noon = tz.localize(datetime(2024, 3, 10, 12, 0, 0)).timestamp() ++ tz = ZoneInfo("America/New_York") ++ march_10_noon = datetime(2024, 3, 10, 12, 0, 0, tzinfo=tz).timestamp() + + with AuthTestClient(self.app) as client: + # Insert recordings for both cameras +diff --git a/frigate/test/http_api/test_http_review.py b/frigate/test/http_api/test_http_review.py +index d13a7bd273..62d4f1608d 100644 +--- a/frigate/test/http_api/test_http_review.py ++++ b/frigate/test/http_api/test_http_review.py +@@ -250,7 +250,7 @@ def test_get_review_summary_all_filters(self): + "cameras": "front_door", + "labels": "all", + "zones": "all", +- "timezone": "utc", ++ "timezone": "UTC", + } + response = client.get("/review/summary", params=params) + assert response.status_code == 200 +diff --git a/frigate/util/time.py b/frigate/util/time.py +index 861bec17f6..777ae9cc11 100644 +--- a/frigate/util/time.py ++++ b/frigate/util/time.py +@@ -2,9 +2,8 @@ + + import datetime + import logging +-from zoneinfo import ZoneInfoNotFoundError ++from zoneinfo import ZoneInfo, ZoneInfoNotFoundError + +-import pytz + from tzlocal import get_localzone + + logger = logging.getLogger(__name__) +@@ -12,7 +11,7 @@ + + def get_tz_modifiers(tz_name: str) -> tuple[str, str, float]: + seconds_offset = ( +- datetime.datetime.now(pytz.timezone(tz_name)).utcoffset().total_seconds() ++ datetime.datetime.now(ZoneInfo(tz_name)).utcoffset().total_seconds() + ) + hours_offset = int(seconds_offset / 60 / 60) + minutes_offset = int(seconds_offset / 60 - hours_offset * 60) +@@ -25,7 +24,7 @@ def get_tomorrow_at_time(hour: int) -> datetime.datetime: + """Returns the datetime of the following day at 2am.""" + try: + tomorrow = datetime.datetime.now(get_localzone()) + datetime.timedelta(days=1) +- except ZoneInfoNotFoundError: ++ except (ValueError, ZoneInfoNotFoundError): + tomorrow = datetime.datetime.now(datetime.UTC) + datetime.timedelta(days=1) + logger.warning( + "Using utc for maintenance due to missing or incorrect timezone set" +@@ -45,7 +44,7 @@ def is_current_hour(timestamp: int) -> bool: + + def get_dst_transitions( + tz_name: str, start_time: float, end_time: float +-) -> list[tuple[float, float]]: ++) -> list[tuple[float, float, int]]: + """ + Find DST transition points and return time periods with consistent offsets. + +@@ -59,8 +58,8 @@ def get_dst_transitions( + continuous periods with the same UTC offset + """ + try: +- tz = pytz.timezone(tz_name) +- except pytz.UnknownTimeZoneError: ++ tz = ZoneInfo(tz_name) ++ except (ValueError, ZoneInfoNotFoundError): + # If timezone is invalid, return single period with no offset + return [(start_time, end_time, 0)] + +@@ -68,14 +67,14 @@ def get_dst_transitions( + current = start_time + + # Get initial offset +- dt = datetime.datetime.utcfromtimestamp(current).replace(tzinfo=pytz.UTC) ++ dt = datetime.datetime.fromtimestamp(current, tz=datetime.UTC) + local_dt = dt.astimezone(tz) + prev_offset = local_dt.utcoffset().total_seconds() + period_start = start_time + + # Check each day for offset changes + while current <= end_time: +- dt = datetime.datetime.utcfromtimestamp(current).replace(tzinfo=pytz.UTC) ++ dt = datetime.datetime.fromtimestamp(current, tz=datetime.UTC) + local_dt = dt.astimezone(tz) + current_offset = local_dt.utcoffset().total_seconds() + + +From af86312f3dd57c068c3f6b3ae68d8fa6f77c6e30 Mon Sep 17 00:00:00 2001 +From: Martin Weinelt +Date: Mon, 6 Jul 2026 16:21:01 +0200 +Subject: [PATCH 4/5] Provide lookup for normalized timezone names + +This provides a helper to look up the correct timezone name independent +of the casing of the given timezone name. +--- + frigate/api/media.py | 5 ++++- + frigate/api/preview.py | 5 ++++- + frigate/record/export.py | 6 +++--- + frigate/util/time.py | 22 +++++++++++++++++++--- + 4 files changed, 30 insertions(+), 8 deletions(-) + +diff --git a/frigate/api/media.py b/frigate/api/media.py +index a5f5e1bab8..14ae263053 100644 +--- a/frigate/api/media.py ++++ b/frigate/api/media.py +@@ -54,6 +54,7 @@ + from frigate.util.image import get_image_from_recording, get_image_quality_params + from frigate.util.media import get_keyframe_before + from frigate.util.object import create_empty_regions_grid ++from frigate.util.time import get_normalized_tz_name + + logger = logging.getLogger(__name__) + +@@ -714,7 +715,9 @@ async def vod_hour( + parts = year_month.split("-") + start_date = ( + datetime(int(parts[0]), int(parts[1]), day, hour, tzinfo=UTC) +- - datetime.now(ZoneInfo(tz_name.replace(",", "/"))).utcoffset() ++ - datetime.now( ++ ZoneInfo(get_normalized_tz_name(tz_name.replace(",", "/"))) ++ ).utcoffset() + ) + end_date = start_date + timedelta(hours=1) - timedelta(milliseconds=1) + start_ts = start_date.timestamp() +diff --git a/frigate/api/preview.py b/frigate/api/preview.py +index af84117fd6..81de23d003 100644 +--- a/frigate/api/preview.py ++++ b/frigate/api/preview.py +@@ -22,6 +22,7 @@ + from frigate.api.defs.tags import Tags + from frigate.const import BASE_DIR, CACHE_DIR, PREVIEW_FRAME_TYPE + from frigate.models import Previews ++from frigate.util.time import get_normalized_tz_name + + logger = logging.getLogger(__name__) + +@@ -126,7 +127,9 @@ def preview_hour( + parts = year_month.split("-") + start_date = ( + datetime(int(parts[0]), int(parts[1]), int(day), int(hour), tzinfo=UTC) +- - datetime.now(ZoneInfo(tz_name.replace(",", "/"))).utcoffset() ++ - datetime.now( ++ ZoneInfo(get_normalized_tz_name(tz_name.replace(",", "/"))) ++ ).utcoffset() + ) + end_date = start_date + timedelta(hours=1) - timedelta(milliseconds=1) + start_ts = start_date.timestamp() +diff --git a/frigate/record/export.py b/frigate/record/export.py +index 0564dee04b..ff33063bc3 100644 +--- a/frigate/record/export.py ++++ b/frigate/record/export.py +@@ -31,7 +31,7 @@ + ) + from frigate.models import Export, Previews, Recordings, ReviewSegment + from frigate.util.ffmpeg import run_ffmpeg_with_progress +-from frigate.util.time import is_current_hour ++from frigate.util.time import get_normalized_tz_name, is_current_hour + + logger = logging.getLogger(__name__) + +@@ -371,7 +371,7 @@ def get_datetime_from_timestamp(self, timestamp: int) -> str: + tz_name = self.config.ui.timezone + if tz_name: + try: +- tz = ZoneInfo(tz_name) ++ tz = ZoneInfo(get_normalized_tz_name(tz_name)) + except (ValueError, ZoneInfoNotFoundError): + tz = None + if tz is not None: +@@ -533,7 +533,7 @@ def _build_recording_segment_chapter_metadata_file( + tz: datetime.tzinfo | None = None + if tz_name: + try: +- tz = ZoneInfo(tz_name) ++ tz = ZoneInfo(get_normalized_tz_name(tz_name)) + except (ValueError, ZoneInfoNotFoundError): + tz = None + if tz is None: +diff --git a/frigate/util/time.py b/frigate/util/time.py +index 777ae9cc11..a4395c5d5d 100644 +--- a/frigate/util/time.py ++++ b/frigate/util/time.py +@@ -2,16 +2,32 @@ + + import datetime + import logging +-from zoneinfo import ZoneInfo, ZoneInfoNotFoundError ++from typing import Final ++from zoneinfo import ZoneInfo, ZoneInfoNotFoundError, available_timezones + + from tzlocal import get_localzone + + logger = logging.getLogger(__name__) + ++TIMEZONE_CASEFOLD_INDEX: Final = { ++ timezone.casefold(): timezone for timezone in available_timezones() ++} ++ ++ ++def get_normalized_tz_name(tz_name: str) -> str: ++ """Return the canonical name for a case-insensitive IANA timezone.""" ++ tz = TIMEZONE_CASEFOLD_INDEX.get(tz_name.casefold()) ++ if tz: ++ return tz ++ ++ raise ValueError(f"Unknown timezone: {tz_name}") ++ + + def get_tz_modifiers(tz_name: str) -> tuple[str, str, float]: + seconds_offset = ( +- datetime.datetime.now(ZoneInfo(tz_name)).utcoffset().total_seconds() ++ datetime.datetime.now(ZoneInfo(get_normalized_tz_name(tz_name))) ++ .utcoffset() ++ .total_seconds() + ) + hours_offset = int(seconds_offset / 60 / 60) + minutes_offset = int(seconds_offset / 60 - hours_offset * 60) +@@ -58,7 +74,7 @@ def get_dst_transitions( + continuous periods with the same UTC offset + """ + try: +- tz = ZoneInfo(tz_name) ++ tz = ZoneInfo(get_normalized_tz_name(tz_name)) + except (ValueError, ZoneInfoNotFoundError): + # If timezone is invalid, return single period with no offset + return [(start_time, end_time, 0)] + +From 490f1b93f8cc2aa450e74e882aa31516d6c1078c Mon Sep 17 00:00:00 2001 +From: Martin Weinelt +Date: Mon, 6 Jul 2026 18:12:37 +0200 +Subject: [PATCH 5/5] Test timezone naming normalization and error handling + +--- + frigate/test/test_tz.py | 19 +++++++++++++++++++ + 1 file changed, 19 insertions(+) + create mode 100644 frigate/test/test_tz.py + +diff --git a/frigate/test/test_tz.py b/frigate/test/test_tz.py +new file mode 100644 +index 0000000000..5be8010dda +--- /dev/null ++++ b/frigate/test/test_tz.py +@@ -0,0 +1,19 @@ ++import unittest ++ ++from frigate.util.time import get_normalized_tz_name ++ ++ ++class TestGetNormalizedTzName(unittest.TestCase): ++ def test_valid(self): ++ cases = [ ++ ("utc", "UTC"), ++ ("america/new_york", "America/New_York"), ++ ] ++ ++ for tz_name, expected in cases: ++ with self.subTest(tz_name=tz_name): ++ self.assertEqual(get_normalized_tz_name(tz_name), expected) ++ ++ def test_invalid(self): ++ with self.assertRaisesRegex(ValueError, r"Unknown timezone: foo/bar"): ++ get_normalized_tz_name("foo/bar") diff --git a/pkgs/by-name/fr/frigate/proc-cmdline-strip.patch b/pkgs/by-name/fr/frigate/proc-cmdline-strip.patch deleted file mode 100644 index 2dd131ebf419..000000000000 --- a/pkgs/by-name/fr/frigate/proc-cmdline-strip.patch +++ /dev/null @@ -1,22 +0,0 @@ -diff --git a/frigate/util/services.py b/frigate/util/services.py -index 64d83833d..912ce67bd 100644 ---- a/frigate/util/services.py -+++ b/frigate/util/services.py -@@ -121,7 +121,7 @@ def get_cpu_stats() -> dict[str, dict]: - pid = str(process.info["pid"]) - try: - cpu_percent = process.info["cpu_percent"] -- cmdline = process.info["cmdline"] -+ cmdline = " ".join(process.info["cmdline"]).rstrip() - - with open(f"/proc/{pid}/stat", "r") as f: - stats = f.readline().split() -@@ -155,7 +155,7 @@ def get_cpu_stats() -> dict[str, dict]: - "cpu": str(cpu_percent), - "cpu_average": str(round(cpu_average_usage, 2)), - "mem": f"{mem_pct}", -- "cmdline": clean_camera_user_pass(" ".join(cmdline)), -+ "cmdline": clean_camera_user_pass(cmdline), - } - except Exception: - continue diff --git a/pkgs/by-name/fr/frigate/web.nix b/pkgs/by-name/fr/frigate/web.nix index 7e284818b975..7ea2aecce45d 100644 --- a/pkgs/by-name/fr/frigate/web.nix +++ b/pkgs/by-name/fr/frigate/web.nix @@ -31,7 +31,7 @@ buildNpmPackage { --replace-fail "/tmp/cache" "/var/cache/frigate" ''; - npmDepsHash = "sha256-iIqP3pspkDbaXZkZ5MIT/GVGiKBJCkFXQ7Av5h1rWKk="; + npmDepsHash = "sha256-k21UBr4agbJDZD0PYVjylRcyuRCFeBE2YBqZzE8v+jU="; installPhase = '' cp -rv dist/ $out diff --git a/pkgs/by-name/fu/futility/package.nix b/pkgs/by-name/fu/futility/package.nix index 41416f226c2d..061c0ac54249 100644 --- a/pkgs/by-name/fu/futility/package.nix +++ b/pkgs/by-name/fu/futility/package.nix @@ -27,6 +27,8 @@ stdenv.mkDerivation { nss ]; + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + postPatch = '' patchShebangs ./scripts substituteInPlace ./scripts/getversion.sh \ diff --git a/pkgs/by-name/fy/fyi/package.nix b/pkgs/by-name/fy/fyi/package.nix index e1ea4eaed3e9..f30b86444430 100644 --- a/pkgs/by-name/fy/fyi/package.nix +++ b/pkgs/by-name/fy/fyi/package.nix @@ -7,6 +7,7 @@ ninja, dbus, scdoc, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -19,6 +20,15 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-UGkShHziREQTkQUlbFXT1144BiBApFVbCvu5A1DuoMI="; }; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://codeberg.org/dnkl/fyi/commit/0a663c5230f756d1161a11080d1a113664e79c21.patch"; + hash = "sha256-B4RkenK4pDAl0jYCgoZH27yUDt3evAHaYnassLaFvB4="; + excludes = [ "CHANGELOG.md" ]; + }) + ]; + depsBuildBuild = [ pkg-config ]; nativeBuildInputs = [ diff --git a/pkgs/by-name/gd/gdk-pixbuf/package.nix b/pkgs/by-name/gd/gdk-pixbuf/package.nix index a55bfa0909c6..618f24b74f4b 100644 --- a/pkgs/by-name/gd/gdk-pixbuf/package.nix +++ b/pkgs/by-name/gd/gdk-pixbuf/package.nix @@ -28,7 +28,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "gdk-pixbuf"; - version = "2.44.7"; + version = "2.44.8"; outputs = [ "out" @@ -40,7 +40,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "mirror://gnome/sources/gdk-pixbuf/${lib.versions.majorMinor finalAttrs.version}/gdk-pixbuf-${finalAttrs.version}.tar.xz"; - hash = "sha256-Fy+A42JuwxUgqXBADxo2lOBHGPbCzSiF91JQ+1pplaQ="; + hash = "sha256-kZ9SlRKWGhLoHNS0tGakjDkzRp5/mjEMZRPNT7JSujw="; }; patches = [ diff --git a/pkgs/by-name/gi/git/package.nix b/pkgs/by-name/gi/git/package.nix index f20fdd8eaf3e..380e45075e2c 100644 --- a/pkgs/by-name/gi/git/package.nix +++ b/pkgs/by-name/gi/git/package.nix @@ -86,6 +86,11 @@ let AuthenSASL DigestHMAC ]; + gitJumpBinPath = lib.makeBinPath [ + "$out" + perlPackages.perl + coreutils + ]; in stdenv.mkDerivation (finalAttrs: { @@ -197,6 +202,7 @@ stdenv.mkDerivation (finalAttrs: { (if stdenv.hostPlatform.isFreeBSD then libiconvReal else libiconv) bash ] + ++ lib.optionals pythonSupport [ python3 ] ++ lib.optionals perlSupport [ perlPackages.perl ] ++ lib.optionals guiSupport [ tcl @@ -385,9 +391,11 @@ stdenv.mkDerivation (finalAttrs: { # Also put git-http-backend into $PATH, so that we can use smart # HTTP(s) transports for pushing ln -s $out/libexec/git-core/git-http-backend${stdenv.hostPlatform.extensions.executable} $out/bin/git-http-backend - ln -s $out/share/git/contrib/git-jump/git-jump $out/bin/git-jump '' + lib.optionalString perlSupport '' + makeWrapper $out/share/git/contrib/git-jump/git-jump $out/bin/git-jump \ + --prefix PATH : "${gitJumpBinPath}" + # wrap perl commands makeWrapper "$out/share/git/contrib/credential/netrc/git-credential-netrc.perl" $out/libexec/git-core/git-credential-netrc \ --set PERL5LIB "$out/${perlPackages.perl.libPrefix}:${perlPackages.makePerlPath perlLibs}" @@ -414,6 +422,10 @@ stdenv.mkDerivation (finalAttrs: { done '' + + lib.optionalString pythonSupport '' + patchShebangs $out/share/git/contrib/fast-import/import-zips.py + '' + + ( if svnSupport then '' diff --git a/pkgs/by-name/gi/gitbeaker-cli/package.nix b/pkgs/by-name/gi/gitbeaker-cli/package.nix index bcf6c6ebefb8..3b8b14059ecc 100644 --- a/pkgs/by-name/gi/gitbeaker-cli/package.nix +++ b/pkgs/by-name/gi/gitbeaker-cli/package.nix @@ -2,6 +2,7 @@ lib, stdenv, fetchFromGitHub, + substitute, nodejs, gnutar, makeBinaryWrapper, @@ -17,14 +18,24 @@ stdenv.mkDerivation (finalAttrs: { owner = "jdalrymple"; repo = "gitbeaker"; tag = finalAttrs.version; - hash = "sha256-EVxDUEuxCnMiqqsKFs9JpRVJ86d9hW22K4a4we8eoJA="; - }; + hash = "sha256-zGcSilIQUKn7iMGFkDZuvPZZM9UcZadczelB7JgVYb4="; - patches = [ - # Remove this when updating since upstream migrated to pnpm - # https://github.com/jdalrymple/gitbeaker/blob/main/package.json#L59 - ./yarn-4.14-support.patch - ]; + # Remove when updating since upstream migrated to pnpm + # https://github.com/jdalrymple/gitbeaker/blob/main/package.json#L61 + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry_4.lockfileVersion + ]; + }) + } + ''; + }; # Set for the `nodejsInstall` hooks npmWorkspace = "@gitbeaker/cli"; @@ -42,8 +53,8 @@ stdenv.mkDerivation (finalAttrs: { missingHashes = ./missing-hashes.json; offlineCache = yarn-berry_4.fetchYarnBerryDeps { - inherit (finalAttrs) src missingHashes patches; - hash = "sha256-RTgdHicbfbJbToif51TchLCfdIPZynvT0n/KwrydLYU="; + inherit (finalAttrs) src missingHashes; + hash = "sha256-OMsa/4pRyZVjgYPfYsaj1D+auKOHRAXKtEDYWenI33I="; }; buildPhase = '' diff --git a/pkgs/by-name/gi/gitbeaker-cli/yarn-4.14-support.patch b/pkgs/by-name/gi/gitbeaker-cli/yarn-fix.patch similarity index 89% rename from pkgs/by-name/gi/gitbeaker-cli/yarn-4.14-support.patch rename to pkgs/by-name/gi/gitbeaker-cli/yarn-fix.patch index aa1ac588934c..e55b7512d292 100644 --- a/pkgs/by-name/gi/gitbeaker-cli/yarn-4.14-support.patch +++ b/pkgs/by-name/gi/gitbeaker-cli/yarn-fix.patch @@ -17,6 +17,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10c0 diff --git a/pkgs/by-name/gj/gjs/package.nix b/pkgs/by-name/gj/gjs/package.nix index 08cfe8bd2db4..8f6e794042aa 100644 --- a/pkgs/by-name/gj/gjs/package.nix +++ b/pkgs/by-name/gj/gjs/package.nix @@ -37,6 +37,7 @@ let gdk-pixbuf harfbuzz glib.out + gobject-introspection ]; in stdenv.mkDerivation (finalAttrs: { diff --git a/pkgs/by-name/gl/glibmm/package.nix b/pkgs/by-name/gl/glibmm_2_4/package.nix similarity index 90% rename from pkgs/by-name/gl/glibmm/package.nix rename to pkgs/by-name/gl/glibmm_2_4/package.nix index d5c50259eddb..1bcc205b000b 100644 --- a/pkgs/by-name/gl/glibmm/package.nix +++ b/pkgs/by-name/gl/glibmm_2_4/package.nix @@ -5,7 +5,7 @@ pkg-config, gnum4, glib, - libsigcxx, + libsigcxx_2_0, gnome, meson, ninja, @@ -15,6 +15,9 @@ stdenv.mkDerivation (finalAttrs: { pname = "glibmm"; version = "2.66.8"; + __structuredAttrs = true; + strictDeps = true; + src = fetchurl { url = "mirror://gnome/sources/glibmm/${lib.versions.majorMinor finalAttrs.version}/glibmm-${finalAttrs.version}.tar.xz"; hash = "sha256-ZPEdO5WiTiqNQWbs/1GHMPeezCciLvQfr3x+A0D8kyk="; @@ -34,7 +37,7 @@ stdenv.mkDerivation (finalAttrs: { ]; propagatedBuildInputs = [ glib - libsigcxx + libsigcxx_2_0 ]; doCheck = false; # fails. one test needs the net, another /etc/fstab @@ -42,6 +45,7 @@ stdenv.mkDerivation (finalAttrs: { passthru = { updateScript = gnome.updateScript { packageName = "glibmm"; + attrPath = "glibmm_2_4"; versionPolicy = "odd-unstable"; freeze = true; }; diff --git a/pkgs/by-name/gl/glibmm_2_68/package.nix b/pkgs/by-name/gl/glibmm_2_68/package.nix index e752e91f073a..9745652e0e76 100644 --- a/pkgs/by-name/gl/glibmm_2_68/package.nix +++ b/pkgs/by-name/gl/glibmm_2_68/package.nix @@ -5,7 +5,7 @@ pkg-config, gnum4, glib, - libsigcxx30, + libsigcxx_3_0, gnome, meson, ninja, @@ -15,6 +15,9 @@ stdenv.mkDerivation (finalAttrs: { pname = "glibmm"; version = "2.88.1"; + __structuredAttrs = true; + strictDeps = true; + outputs = [ "out" "dev" @@ -35,7 +38,7 @@ stdenv.mkDerivation (finalAttrs: { propagatedBuildInputs = [ glib - libsigcxx30 + libsigcxx_3_0 ]; doCheck = false; # fails. one test needs the net, another /etc/fstab diff --git a/pkgs/by-name/gn/gn/package.nix b/pkgs/by-name/gn/gn/package.nix index 461d2efb64ce..3cc315badcd7 100644 --- a/pkgs/by-name/gn/gn/package.nix +++ b/pkgs/by-name/gn/gn/package.nix @@ -11,11 +11,11 @@ version ? # This is a workaround for update-source-version to be able to update this let - _version = "0-unstable-2026-07-23"; + _version = "0-unstable-2026-08-14"; in _version, - rev ? "641ace93dd9560e75e7add0d08f77b446fbb3b78", - hash ? "sha256-ovLx6KaORdXqnWgbsGEty10k2CHuCmTk3yEqy5//ovk=", + rev ? "e8a8e0932a5e42a99e5896aa58e3b8290f4e5b8c", + hash ? "sha256-qvQ13Ws2tb4i2Hdu34kBHivYPAn8w06zjLdQgK4BIJg=", }: stdenv.mkDerivation { diff --git a/pkgs/by-name/gn/gnucobol/package.nix b/pkgs/by-name/gn/gnucobol/package.nix index 70931643a432..2e422c7e571b 100644 --- a/pkgs/by-name/gn/gnucobol/package.nix +++ b/pkgs/by-name/gn/gnucobol/package.nix @@ -32,6 +32,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "gnucobol"; version = "3.2"; + __structuredAttrs = true; strictDeps = true; src = fetchurl { diff --git a/pkgs/by-name/gp/gpgme/package.nix b/pkgs/by-name/gp/gpgme/package.nix index eb406544e78e..d87c8e9e73b4 100644 --- a/pkgs/by-name/gp/gpgme/package.nix +++ b/pkgs/by-name/gp/gpgme/package.nix @@ -22,7 +22,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "gpgme"; - version = "2.1.2"; + version = "2.2.0"; outputs = [ "out" @@ -34,7 +34,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "mirror://gnupg/gpgme/gpgme-${finalAttrs.version}.tar.bz2"; - hash = "sha256-BoepWymYccQUH1B8D3QN5rQpyawGfQ+k4GLjJk31+3c="; + hash = "sha256-cWDoDoTa/QDZVshIkcUzu3qxampU++FXSy86zwSWl3s="; }; postPatch = '' diff --git a/pkgs/by-name/gp/gpgmepp/package.nix b/pkgs/by-name/gp/gpgmepp/package.nix index d82e0d1617ba..f2b62e35d84b 100644 --- a/pkgs/by-name/gp/gpgmepp/package.nix +++ b/pkgs/by-name/gp/gpgmepp/package.nix @@ -10,11 +10,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "gpgmepp"; - version = "2.1.0"; + version = "2.2.0"; src = fetchurl { url = "mirror://gnupg/gpgmepp/gpgmepp-${finalAttrs.version}.tar.xz"; - hash = "sha256-V/gERo8CBFBLFyxrE5ywUSS0JjvnrVFJMsfExQYqFuI="; + hash = "sha256-ZlHF9/gBVD1bZ2cZ35/sgFOwpvWrpAuYyg0r7hETbzA="; }; postPatch = '' diff --git a/pkgs/by-name/gr/grpc/package.nix b/pkgs/by-name/gr/grpc/package.nix index 105e69cc23ee..c4b8a870a687 100644 --- a/pkgs/by-name/gr/grpc/package.nix +++ b/pkgs/by-name/gr/grpc/package.nix @@ -25,7 +25,7 @@ # nixpkgs-update: no auto update stdenv.mkDerivation (finalAttrs: { pname = "grpc"; - version = "1.83.0"; # N.B: if you change this, please update: + version = "1.83.1"; # N.B: if you change this, please update: # pythonPackages.grpcio # pythonPackages.grpcio-channelz # pythonPackages.grpcio-health-checking @@ -38,7 +38,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "grpc"; repo = "grpc"; tag = "v${finalAttrs.version}"; - hash = "sha256-A2QtLdsunMOulbpyaSOoAID9caK0tpuiyZJ5C5zrr+k="; + hash = "sha256-h2F+lKF9GH5CGjzS5326ovLUHbYwsPjoqmb8Ljgj2ao="; fetchSubmodules = true; }; diff --git a/pkgs/by-name/gr/grub2/package.nix b/pkgs/by-name/gr/grub2/package.nix index 392a6ed6e794..6ab78b82c4eb 100644 --- a/pkgs/by-name/gr/grub2/package.nix +++ b/pkgs/by-name/gr/grub2/package.nix @@ -223,6 +223,9 @@ stdenv.mkDerivation rec { strictDeps = true; + # glibc 2.43 C23 const-preserving strchr/strstr macros + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + hardeningDisable = [ "all" ]; separateDebugInfo = !xenSupport; diff --git a/pkgs/by-name/gt/gtk-doc/package.nix b/pkgs/by-name/gt/gtk-doc/package.nix index 475149609a7b..97117f61992b 100644 --- a/pkgs/by-name/gt/gtk-doc/package.nix +++ b/pkgs/by-name/gt/gtk-doc/package.nix @@ -5,6 +5,7 @@ ninja, pkg-config, python3, + bashNonInteractive, docbook_xml_dtd_43, docbook-xsl-nons, libxslt, @@ -32,11 +33,9 @@ python3.pkgs.buildPythonApplication (finalAttrs: { postPatch = '' substituteInPlace meson.build \ - --replace "pkg-config" "$PKG_CONFIG" + --replace-fail "pkg-config" "$PKG_CONFIG" ''; - strictDeps = true; - depsBuildBuild = [ python3 pkg-config @@ -51,6 +50,7 @@ python3.pkgs.buildPythonApplication (finalAttrs: { ]; buildInputs = [ + bashNonInteractive docbook_xml_dtd_43 docbook-xsl-nons libxslt @@ -75,7 +75,7 @@ python3.pkgs.buildPythonApplication (finalAttrs: { postFixup = '' # Do not propagate Python substituteInPlace $out/nix-support/propagated-build-inputs \ - --replace "${python3}" "" + --replace-fail "${python3}" "" ''; passthru = { diff --git a/pkgs/by-name/gt/gtk4/package.nix b/pkgs/by-name/gt/gtk4/package.nix index cae25786ec7d..e3ad4dbb9358 100644 --- a/pkgs/by-name/gt/gtk4/package.nix +++ b/pkgs/by-name/gt/gtk4/package.nix @@ -101,6 +101,11 @@ stdenv.mkDerivation (finalAttrs: { url = "https://gitlab.gnome.org/GNOME/gtk/-/commit/10d43de8f4f942cb591ada3103474bd7213425f1.patch"; hash = "sha256-DJIL6M3XcsjBoMO77OxNi84d1DxAphAfot3N7Nq1QqQ="; }) + (fetchpatch { + name = "gtkapplication-wayland-null-check.patch"; + url = "https://gitlab.gnome.org/GNOME/gtk/-/commit/221cd8e1904f2ca35d89dff3c1068616c6ce588c.patch"; + hash = "sha256-SLMmWDZ2mLXW3/GJfFdoszthNg4Hd15yvZO2XOld4Uw="; + }) ]; depsBuildBuild = [ diff --git a/pkgs/by-name/gt/gtkmm3/package.nix b/pkgs/by-name/gt/gtkmm3/package.nix index c1cf3a8489aa..4d8d9cd78ae8 100644 --- a/pkgs/by-name/gt/gtkmm3/package.nix +++ b/pkgs/by-name/gt/gtkmm3/package.nix @@ -7,7 +7,7 @@ ninja, python3, gtk3, - glibmm, + glibmm_2_4, cairomm_1_0, pangomm_1_4, atkmm, @@ -42,7 +42,7 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ libepoxy ]; propagatedBuildInputs = [ - glibmm + glibmm_2_4 gtk3 atkmm cairomm_1_0 diff --git a/pkgs/by-name/gt/gtksourceviewmm/package.nix b/pkgs/by-name/gt/gtksourceviewmm/package.nix index 01909520007a..09337fb3c6f7 100644 --- a/pkgs/by-name/gt/gtksourceviewmm/package.nix +++ b/pkgs/by-name/gt/gtksourceviewmm/package.nix @@ -4,7 +4,7 @@ fetchurl, pkg-config, gtkmm3, - glibmm, + glibmm_2_4, gtksourceview3, gnome, }: @@ -28,7 +28,7 @@ stdenv.mkDerivation (finalAttrs: { nativeBuildInputs = [ pkg-config ]; buildInputs = [ - glibmm + glibmm_2_4 gtkmm3 gtksourceview3 ]; diff --git a/pkgs/by-name/gt/gtkspellmm/package.nix b/pkgs/by-name/gt/gtkspellmm/package.nix index d05aa85f177f..c1143c5ba920 100644 --- a/pkgs/by-name/gt/gtkspellmm/package.nix +++ b/pkgs/by-name/gt/gtkspellmm/package.nix @@ -5,7 +5,7 @@ pkg-config, gtk3, glib, - glibmm, + glibmm_2_4, gtkmm3, gtkspell3, }: @@ -27,7 +27,7 @@ stdenv.mkDerivation rec { buildInputs = [ gtk3 glib - glibmm + glibmm_2_4 gtkmm3 ]; diff --git a/pkgs/by-name/gu/guacamole-server/package.nix b/pkgs/by-name/gu/guacamole-server/package.nix index c79a68bdc5f7..89634c3bc25a 100644 --- a/pkgs/by-name/gu/guacamole-server/package.nix +++ b/pkgs/by-name/gu/guacamole-server/package.nix @@ -2,7 +2,6 @@ lib, stdenv, fetchFromGitHub, - fetchpatch2, pkg-config, autoPatchelfHook, autoreconfHook, @@ -28,13 +27,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "guacamole-server"; - version = "1.6.0-unstable-2025-06-29"; + version = "1.6.0-unstable-2026-08-16"; src = fetchFromGitHub { owner = "apache"; repo = "guacamole-server"; - rev = "f3f5b9d76649ccc24f551cb166c81078f4b5e236"; - hash = "sha256-OjTwAQzKUuXfwZXLsL9XjrJc/0be38CmAGG+CoCeNwk="; + rev = "d3b7828977c63a5b197158d6cbbdaf1846b579fb"; + hash = "sha256-sxZLzF6m35EtfLRHb1+aqR3RF+piOuvPT9w9Hs3cor0="; }; env.NIX_CFLAGS_COMPILE = toString [ diff --git a/pkgs/by-name/gu/guitarix-vst/package.nix b/pkgs/by-name/gu/guitarix-vst/package.nix index 27eb994a4f8a..a131aefeb3ab 100644 --- a/pkgs/by-name/gu/guitarix-vst/package.nix +++ b/pkgs/by-name/gu/guitarix-vst/package.nix @@ -7,7 +7,7 @@ fftwFloat, freetype, glib, - glibmm, + glibmm_2_4, lib, libsndfile, libx11, @@ -54,7 +54,7 @@ stdenv.mkDerivation (finalAttrs: { fftwFloat freetype glib - glibmm + glibmm_2_4 libx11 libxcursor libxext diff --git a/pkgs/by-name/gu/guitarix/package.nix b/pkgs/by-name/gu/guitarix/package.nix index fa60d2efc584..a6c9018d5bff 100644 --- a/pkgs/by-name/gu/guitarix/package.nix +++ b/pkgs/by-name/gu/guitarix/package.nix @@ -13,7 +13,7 @@ gettext, glib, glib-networking, - glibmm, + glibmm_2_4, gperf, gtk3, gtkmm3, @@ -94,7 +94,7 @@ stdenv.mkDerivation (finalAttrs: { gettext glib glib-networking.out - glibmm + glibmm_2_4 gtk3 gtkmm3 ladspa-header diff --git a/pkgs/by-name/ha/handy/package.nix b/pkgs/by-name/ha/handy/package.nix index 64a06881d3dd..0ef3c933fec8 100644 --- a/pkgs/by-name/ha/handy/package.nix +++ b/pkgs/by-name/ha/handy/package.nix @@ -91,6 +91,10 @@ rustPlatform.buildRustPackage (finalAttrs: { # Strip cbindgen build steps find "$cargoDepsCopy" -path "*/ferrous-opencc-*/build.rs" \ -exec sed -i -e '/cbindgen::Builder::new/{:l;/write_to_file/!{N;bl};d}' {} + + + # FoundationModels requires macros that are only shipped with Xcode. The 26.x SDK in Nixpkgs does not have them. + substituteInPlace src-tauri/build.rs \ + --replace-fail 'has_foundation_models = framework_path.exists()' ' has_foundation_models = false' '' + lib.optionalString stdenv.hostPlatform.isLinux '' substituteInPlace "$cargoDepsCopy"/*/libappindicator-sys-*/src/lib.rs \ @@ -153,6 +157,7 @@ rustPlatform.buildRustPackage (finalAttrs: { ); } // lib.optionalAttrs stdenv.hostPlatform.isDarwin { + NIX_LDFLAGS = "-lclang_rt.osx"; # Make sure `__isPlatformVersionAtLeast` is available for runtime version checks. SWIFTC = lib.getExe' swift "swiftc"; # Explicit so the Handy build system can avoid xcrun }; diff --git a/pkgs/by-name/he/hedgedoc/package.nix b/pkgs/by-name/he/hedgedoc/package.nix index a0173a2f6fa9..fc5e594c8e95 100644 --- a/pkgs/by-name/he/hedgedoc/package.nix +++ b/pkgs/by-name/he/hedgedoc/package.nix @@ -2,6 +2,7 @@ lib, stdenv, fetchFromGitHub, + substitute, makeBinaryWrapper, nodejs, python3, @@ -17,22 +18,31 @@ stdenv.mkDerivation (finalAttrs: { owner = "hedgedoc"; repo = "hedgedoc"; tag = finalAttrs.version; - hash = "sha256-QYWDgQuSsMf8xElSK0MpthOMAB6EJXcxfOWcHrR4ODU="; - }; + hash = "sha256-sKmy80FO5cp2aKoirtzaPmf2IqTn5yLUkbakIZMa5aQ="; - patches = [ - # Remove after upstream updates to Yarn 4.14 - # https://github.com/hedgedoc/hedgedoc/blob/develop/package.json#L28 - ./yarn-4.14-support.patch - ]; + # Remove after https://github.com/hedgedoc/hedgedoc/commit/6e6536df1b7b8e1ad30a0929be5b851eef98029f is released + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry_4.lockfileVersion + ]; + }) + } + ''; + }; # Generate this file with: # nix run nixpkgs#yarn-berry_4.yarn-berry-fetcher missing-hashes yarn.lock missingHashes = ./missing-hashes.json; offlineCache = yarn-berry_4.fetchYarnBerryDeps { - inherit (finalAttrs) src missingHashes patches; - hash = "sha256-2qwTV9GRKnVIhK6dsSfis+JOTfjcdwW0RVdrJZa/uJc="; + inherit (finalAttrs) src missingHashes; + hash = "sha256-OywEJNs1DwUnPPjW2CzEYKhfHz03EcSEJ1PUWx8DGUI="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/he/hedgedoc/yarn-4.14-support.patch b/pkgs/by-name/he/hedgedoc/yarn-fix.patch similarity index 90% rename from pkgs/by-name/he/hedgedoc/yarn-4.14-support.patch rename to pkgs/by-name/he/hedgedoc/yarn-fix.patch index 965bede33cf7..c3f584b8e6dd 100644 --- a/pkgs/by-name/he/hedgedoc/yarn-4.14-support.patch +++ b/pkgs/by-name/he/hedgedoc/yarn-fix.patch @@ -18,6 +18,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10 diff --git a/pkgs/by-name/he/helix/package.nix b/pkgs/by-name/he/helix/package.nix index e301693489f6..dd0f7662cab0 100644 --- a/pkgs/by-name/he/helix/package.nix +++ b/pkgs/by-name/he/helix/package.nix @@ -68,7 +68,23 @@ let helixTreeSitterGrammars = lib.filterAttrs (drvName: _: lib.hasAttr (lib.removePrefix "tree-sitter-" drvName) lockedGrammars) - (tree-sitter-grammars.overrideScope (lib.composeExtensions lockedVersionsOverlay grammarsOverlay)); + ( + tree-sitter-grammars.overrideScope ( + lib.composeManyExtensions [ + lockedVersionsOverlay + grammarsOverlay + (self: super: { + tree-sitter-perl = super.tree-sitter-perl.overrideAttrs { + postPatch = '' + rm src/bsearch.c + substituteInPlace src/tsp_unicode.h \ + --replace-fail '#include "bsearch.c"' "" + ''; + }; + }) + ] + ) + ); # Dynamic libraries for the grammars always use the `.so` extension, also on Darwin (should use `.dylib`) # See here: https://github.com/helix-editor/helix/pull/14982 diff --git a/pkgs/by-name/he/hexcurse/package.nix b/pkgs/by-name/he/hexcurse/package.nix index b8863337e7bf..7c72389a47e2 100644 --- a/pkgs/by-name/he/hexcurse/package.nix +++ b/pkgs/by-name/he/hexcurse/package.nix @@ -21,6 +21,7 @@ stdenv.mkDerivation (finalAttrs: { env.NIX_CFLAGS_COMPILE = toString [ "-Wno-error=stringop-overflow" "-Wno-error=stringop-truncation" + "-Wno-error=discarded-qualifiers" ]; patches = [ # gcc7 compat diff --git a/pkgs/by-name/ia/iana-etc/package.nix b/pkgs/by-name/ia/iana-etc/package.nix index da283674f11c..f2be62765784 100644 --- a/pkgs/by-name/ia/iana-etc/package.nix +++ b/pkgs/by-name/ia/iana-etc/package.nix @@ -5,15 +5,17 @@ writeText, }: -stdenvNoCC.mkDerivation rec { +stdenvNoCC.mkDerivation (finalAttrs: { pname = "iana-etc"; version = "20251215"; src = fetchzip { - url = "https://github.com/Mic92/iana-etc/releases/download/${version}/iana-etc-${version}.tar.gz"; - sha256 = "sha256-BUGhVHvWSdFJdqaoPasLt87lTUFVF2B7X7sfigwrJss="; + url = "https://github.com/Mic92/iana-etc/releases/download/${finalAttrs.version}/iana-etc-${finalAttrs.version}.tar.gz"; + hash = "sha256-BUGhVHvWSdFJdqaoPasLt87lTUFVF2B7X7sfigwrJss="; }; + strictDeps = true; + installPhase = '' install -D -m0644 -t $out/etc services protocols ''; @@ -23,10 +25,12 @@ stdenvNoCC.mkDerivation rec { export NIX_ETC_SERVICES=@out@/etc/services ''; + __structuredAttrs = true; + meta = { homepage = "https://github.com/Mic92/iana-etc"; description = "IANA protocol and port number assignments (/etc/protocols and /etc/services)"; platforms = lib.platforms.unix; license = lib.licenses.mit; }; -} +}) diff --git a/pkgs/by-name/ib/ibus/package.nix b/pkgs/by-name/ib/ibus/package.nix index b164f6ead3a7..97f2cb2b2188 100644 --- a/pkgs/by-name/ib/ibus/package.nix +++ b/pkgs/by-name/ib/ibus/package.nix @@ -3,6 +3,7 @@ stdenv, replaceVars, fetchFromGitHub, + fetchpatch, autoreconfHook, gettext, makeWrapper, @@ -88,6 +89,15 @@ stdenv.mkDerivation (finalAttrs: { PYTHON = null; }) ./build-without-dbus-launch.patch + + # Fix crashes in `gtk_im_multicontext_set_delegate` with latest GTK + # GTK issue: https://gitlab.gnome.org/GNOME/gtk/-/work_items/8341 + # Upstream PR: https://github.com/ibus/ibus/pull/2929 + (fetchpatch { + name = "fix-gtk-crashes.patch"; + url = "https://github.com/ibus/ibus/commit/c534999a9dbea2666864250d74e058ecfb46e76f.patch"; + hash = "sha256-1h48hvdrDh2Qh4+SufL147CxlfiwvP/Jv509X0WnbrA="; + }) ]; outputs = [ diff --git a/pkgs/by-name/im/imath/package.nix b/pkgs/by-name/im/imath/package.nix index fe65e5274b95..fe7e53260d6b 100644 --- a/pkgs/by-name/im/imath/package.nix +++ b/pkgs/by-name/im/imath/package.nix @@ -12,12 +12,16 @@ stdenv.mkDerivation (finalAttrs: { src = fetchFromGitHub { owner = "AcademySoftwareFoundation"; repo = "imath"; - rev = "v${finalAttrs.version}"; + tag = "v${finalAttrs.version}"; hash = "sha256-kmWj9g6PnvgEOojjiWYpJ9+lXwT1svpezYDsCns4NP0="; }; nativeBuildInputs = [ cmake ]; + strictDeps = true; + + __structuredAttrs = true; + meta = { description = "C++ and python library of 2D and 3D vector, matrix, and math operations for computer graphics"; homepage = "https://github.com/AcademySoftwareFoundation/Imath"; diff --git a/pkgs/by-name/in/ingen/package.nix b/pkgs/by-name/in/ingen/package.nix index 84d6abace175..d96c966a9676 100644 --- a/pkgs/by-name/in/ingen/package.nix +++ b/pkgs/by-name/in/ingen/package.nix @@ -5,7 +5,7 @@ portaudio, boost, libjack2, - libsigcxx, + libsigcxx_2_0, lilv, pkg-config, python3, @@ -39,7 +39,7 @@ stdenv.mkDerivation { buildInputs = [ boost libjack2 - libsigcxx + libsigcxx_2_0 lilv portaudio raul diff --git a/pkgs/by-name/in/insulator2/package.nix b/pkgs/by-name/in/insulator2/package.nix index 5f42e73a124b..93275d2bb39a 100644 --- a/pkgs/by-name/in/insulator2/package.nix +++ b/pkgs/by-name/in/insulator2/package.nix @@ -3,6 +3,7 @@ stdenv, fetchFromGitHub, + substitute, yarn-berry_4, cargo, @@ -31,19 +32,29 @@ stdenv.mkDerivation (finalAttrs: { owner = "andrewinci"; repo = "insulator2"; rev = "v${finalAttrs.version}"; - hash = "sha256-3eDA+pwchnwWtweGeSDlf+Vt0Hoylmanf4hnvJ2YOGU="; - }; + hash = "sha256-QCoDiFEgVuF/+MqgzcMTXqjC/nDA+A2v3l01kZyviDs="; - patches = [ - # Remove after upstream updates to Yarn 4.14 + # Remove after upstream updates to Yarn 4.15 # https://github.com/andrewinci/insulator2/blob/main/package.json#L105 - ./yarn-4.14-support.patch - ]; + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry_4.lockfileVersion + ]; + }) + } + ''; + }; missingHashes = ./missing-hashes.json; offlineCache = yarn-berry_4.fetchYarnBerryDeps { - inherit (finalAttrs) src missingHashes patches; - hash = "sha256-IechRla3epfANBESCYgti5/8B3QaPCv6Gp2I4eZNiyI="; + inherit (finalAttrs) src missingHashes; + hash = "sha256-2w1fMVwQFClyrpNmJrjJoDqbU2nxRZh9NkBIcMUEjec="; }; cargoDeps = rustPlatform.fetchCargoVendor { diff --git a/pkgs/by-name/in/insulator2/yarn-4.14-support.patch b/pkgs/by-name/in/insulator2/yarn-fix.patch similarity index 88% rename from pkgs/by-name/in/insulator2/yarn-4.14-support.patch rename to pkgs/by-name/in/insulator2/yarn-fix.patch index 017f2d295ca9..868db25c8d32 100644 --- a/pkgs/by-name/in/insulator2/yarn-4.14-support.patch +++ b/pkgs/by-name/in/insulator2/yarn-fix.patch @@ -16,6 +16,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10c0 diff --git a/pkgs/by-name/ip/ipv6calc/package.nix b/pkgs/by-name/ip/ipv6calc/package.nix index fa460738f960..533ca9257a5d 100644 --- a/pkgs/by-name/ip/ipv6calc/package.nix +++ b/pkgs/by-name/ip/ipv6calc/package.nix @@ -6,6 +6,7 @@ ip2location-c, openssl, perl, + fetchpatch, libmaxminddb ? null, geolite-legacy ? null, }: @@ -30,6 +31,14 @@ stdenv.mkDerivation (finalAttrs: { perl ]; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/pbiering/ipv6calc/commit/9b6aebd3690d93b6c2f9efa9346ec72540b1a718.patch"; + hash = "sha256-Y/XBMWdG2/Pfr/vZ2+RGYGj2JS3mWJwQGkXnKvXHArg="; + }) + ]; + postPatch = '' patchShebangs *.sh */*.sh for i in {,databases/}lib/Makefile.in; do diff --git a/pkgs/by-name/j/j/package.nix b/pkgs/by-name/j/j/package.nix index dd4ed59c1fe4..72b5523589ba 100644 --- a/pkgs/by-name/j/j/package.nix +++ b/pkgs/by-name/j/j/package.nix @@ -40,6 +40,9 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-fW6Tc0UEPYFTgEFMUxZaVm2NU5LNFqszifqOqfdFJZY="; }; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + nativeBuildInputs = [ which ]; buildInputs = [ gmp ]; diff --git a/pkgs/by-name/ja/jamesdsp/package.nix b/pkgs/by-name/ja/jamesdsp/package.nix index da668c36f11d..e62bd1b98e3e 100644 --- a/pkgs/by-name/ja/jamesdsp/package.nix +++ b/pkgs/by-name/ja/jamesdsp/package.nix @@ -2,7 +2,7 @@ copyDesktopItems, fetchFromGitHub, fetchpatch, - glibmm, + glibmm_2_4, gst_all_1, lib, libarchive, @@ -49,7 +49,7 @@ stdenv.mkDerivation (finalAttrs: { ]; buildInputs = [ - glibmm + glibmm_2_4 libarchive kdePackages.qtbase kdePackages.qtsvg diff --git a/pkgs/by-name/jb/jbig2dec/package.nix b/pkgs/by-name/jb/jbig2dec/package.nix index 7ccc8cc7f9b3..097483c1bb7f 100644 --- a/pkgs/by-name/jb/jbig2dec/package.nix +++ b/pkgs/by-name/jb/jbig2dec/package.nix @@ -37,6 +37,8 @@ stdenv.mkDerivation (finalAttrs: { libtool ]; + strictDeps = true; + # `autogen.sh` runs `configure`, and expects that any flags needed # by `configure` (like `--host`) are passed to `autogen.sh`. configureScript = "./autogen.sh"; @@ -44,6 +46,8 @@ stdenv.mkDerivation (finalAttrs: { nativeCheckInputs = [ python3 ]; doCheck = true; + __structuredAttrs = true; + meta = { homepage = "https://www.jbig2dec.com/"; description = "Decoder implementation of the JBIG2 image compression format"; diff --git a/pkgs/by-name/jo/joplin-cli/package.nix b/pkgs/by-name/jo/joplin-cli/package.nix index 66a7e4f7882e..b0d81537b620 100644 --- a/pkgs/by-name/jo/joplin-cli/package.nix +++ b/pkgs/by-name/jo/joplin-cli/package.nix @@ -3,6 +3,7 @@ stdenv, nodejs, fetchFromGitHub, + substitute, yarn-berry_4, python3, pkg-config, @@ -24,26 +25,30 @@ stdenv.mkDerivation (finalAttrs: { postFetch = '' # there's a file with a weird name that causes a hash mismatch on darwin rm $out/packages/app-cli/tests/support/photo* + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry_4.lockfileVersion + ]; + }) + } ''; - hash = "sha256-4o8mao7wAqDzwQgJ4QY+DPs9rtsnga6LLnq744l7HVM="; + hash = "sha256-g5b1DwSG0JgzGeL17q50CaTU0mG6u/v5IUwoVBcoMsM="; }; - patches = [ - # Remove after upstream updates to Yarn 4.14 - # https://github.com/laurent22/joplin/blob/dev/package.json#L103 - ./yarn-4.14-support.patch - ]; - missingHashes = ./missing-hashes.json; offlineCache = yarn-berry_4.fetchYarnBerryDeps { inherit (finalAttrs) src missingHashes - patches postPatch ; - hash = "sha256-CHjvFu6r5zak19dqtRkcGkPhPoKgt1nkBVa71ZcvdgE="; + hash = "sha256-IyOnSB21bOYiPnYUorne8/11zxUItIqMtT88ExCoEmU="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/jo/joplin-cli/yarn-4.14-support.patch b/pkgs/by-name/jo/joplin-cli/yarn-fix.patch similarity index 91% rename from pkgs/by-name/jo/joplin-cli/yarn-4.14-support.patch rename to pkgs/by-name/jo/joplin-cli/yarn-fix.patch index 7fecbbdf1031..a8f1e95226ee 100644 --- a/pkgs/by-name/jo/joplin-cli/yarn-4.14-support.patch +++ b/pkgs/by-name/jo/joplin-cli/yarn-fix.patch @@ -21,6 +21,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10 diff --git a/pkgs/by-name/jo/joplin-desktop/package.nix b/pkgs/by-name/jo/joplin-desktop/package.nix index 86c3c59344d5..8ebb75c9d399 100644 --- a/pkgs/by-name/jo/joplin-desktop/package.nix +++ b/pkgs/by-name/jo/joplin-desktop/package.nix @@ -44,6 +44,10 @@ stdenv.mkDerivation (finalAttrs: { postFetch = '' # there's a file with a weird name that causes a hash mismatch on darwin rm $out/packages/app-cli/tests/support/photo* + + # Remove when updating since upstream updated Yarn + # https://github.com/laurent22/joplin/commit/071f205c44da8e2979dcf53a4105648bfa0e7f83 + sed -i '/__metadata/{n;s/version: 8$/version: ${yarn-berry.lockfileVersion}/;}' $out/yarn.lock ''; inherit (releaseData) hash; }; diff --git a/pkgs/by-name/jo/joplin-desktop/release-data.json b/pkgs/by-name/jo/joplin-desktop/release-data.json index ac469f854ccf..7f1937b80a66 100644 --- a/pkgs/by-name/jo/joplin-desktop/release-data.json +++ b/pkgs/by-name/jo/joplin-desktop/release-data.json @@ -1,6 +1,6 @@ { - "version": "3.7.18", - "hash": "sha256-12ZRoEutQsNJlrPypNrsffeIj+2ekqB/s6HN9ks/+rU=", + "version": "3.6.16", + "hash": "sha256-S1PIhotA0Y57ZeT9xBcbMInblwFK8LKwXlcnMs2TB3Q=", "plugins": { "io.github.jackgruber.backup": { "name": "joplin-plugin-backup", @@ -9,5 +9,5 @@ "npmDepsHash": "sha256-xZJ0Oir1A6sLe0ztIyBu39Yy3D6sNrVaciOYG0k85l0=" } }, - "deps_hash": "sha256-W5hXh1i1rTe4OkhTvHPpDQgPSvRqTZ/GsJnHXE2D/2Y=" + "deps_hash": "sha256-mj9s97D/4UJqctl5NtyJRWYTc6fFAC0ueZE78KZVFsQ=" } diff --git a/pkgs/by-name/js/jstest-gtk/package.nix b/pkgs/by-name/js/jstest-gtk/package.nix index ba476a2b6b81..b5ceca969b97 100644 --- a/pkgs/by-name/js/jstest-gtk/package.nix +++ b/pkgs/by-name/js/jstest-gtk/package.nix @@ -5,7 +5,7 @@ cmake, pkg-config, gtkmm3, - libsigcxx, + libsigcxx_2_0, libx11, }: @@ -26,7 +26,7 @@ stdenv.mkDerivation { ]; buildInputs = [ gtkmm3 - libsigcxx + libsigcxx_2_0 libx11 ]; diff --git a/pkgs/by-name/ko/koito/client.nix b/pkgs/by-name/ko/koito/client.nix index d696189f04a2..d611c8659143 100644 --- a/pkgs/by-name/ko/koito/client.nix +++ b/pkgs/by-name/ko/koito/client.nix @@ -17,7 +17,7 @@ stdenv.mkDerivation (finalAttrs: { missingHashes = ./missing-hashes.json; offlineCache = yarn.fetchYarnBerryDeps { inherit (finalAttrs) src sourceRoot missingHashes; - hash = "sha256-VIlWld21GScJ/2UUkKQISM9jyU9wCVwwDNKkge+K044="; + hash = "sha256-2kWRZBGm7pTpOwZ1Wp+pCU5WWFche1xqGyLL86eGEow="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/ko/koito/package.nix b/pkgs/by-name/ko/koito/package.nix index 1b088365b8f8..fd1dc293ed3f 100644 --- a/pkgs/by-name/ko/koito/package.nix +++ b/pkgs/by-name/ko/koito/package.nix @@ -2,6 +2,8 @@ lib, buildGoModule, fetchFromGitHub, + substitute, + yarn-berry_4, callPackage, pkg-config, vips, @@ -15,7 +17,23 @@ buildGoModule (finalAttrs: { owner = "gabehf"; repo = "koito"; rev = "v${finalAttrs.version}"; - hash = "sha256-68+Z4Alzu+4v/PxU1IOboqZkF1pO+y6gswuO+HPS7dk="; + hash = "sha256-z0HeuPYQwkyKkt8K7PKUYseECz2p1C/6UO5sUSxopBQ="; + + # Remove when upstream updates to Yarn 4.15 + # https://github.com/gabehf/Koito/blob/main/client/package.json#L44 + postFetch = '' + cd $out/client + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry_4.lockfileVersion + ]; + }) + } + ''; }; __structuredAttrs = true; @@ -47,6 +65,7 @@ buildGoModule (finalAttrs: { passthru = { client = callPackage ./client.nix { inherit (finalAttrs) src version; + inherit yarn-berry_4; }; tests = { diff --git a/pkgs/by-name/el/electron-fiddle/yarn-metadata-version.patch b/pkgs/by-name/ko/koito/yarn-fix.patch similarity index 57% rename from pkgs/by-name/el/electron-fiddle/yarn-metadata-version.patch rename to pkgs/by-name/ko/koito/yarn-fix.patch index 780b7265824a..7b3deff55c1d 100644 --- a/pkgs/by-name/el/electron-fiddle/yarn-metadata-version.patch +++ b/pkgs/by-name/ko/koito/yarn-fix.patch @@ -1,13 +1,11 @@ diff --git a/yarn.lock b/yarn.lock -index 365f8b4d..ffa89a3d 100644 --- a/yarn.lock +++ b/yarn.lock -@@ -2,7 +2,7 @@ +@@ -2,6 +2,6 @@ # Manual changes might be lost - proceed with caution! __metadata: -- version: 8 -+ version: 9 +- version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10c0 - "@aashutoshrathi/word-wrap@npm:^1.2.3": diff --git a/pkgs/by-name/kr/krb5/package.nix b/pkgs/by-name/kr/krb5/package.nix index 4e97e9867190..9b5b2cc2d628 100644 --- a/pkgs/by-name/kr/krb5/package.nix +++ b/pkgs/by-name/kr/krb5/package.nix @@ -75,7 +75,9 @@ stdenv.mkDerivation (finalAttrs: { # void foo(); # # declaration. - NIX_CFLAGS_COMPILE = "-std=gnu17" + lib.optionalString stdenv.hostPlatform.isStatic " -fcommon"; + NIX_CFLAGS_COMPILE = + "-std=gnu17 -Wno-error=discarded-qualifiers" + + lib.optionalString stdenv.hostPlatform.isStatic " -fcommon"; }; configureFlags = [ diff --git a/pkgs/by-name/kv/kvmtool/package.nix b/pkgs/by-name/kv/kvmtool/package.nix index adfbd884d0e0..f89324a5909d 100644 --- a/pkgs/by-name/kv/kvmtool/package.nix +++ b/pkgs/by-name/kv/kvmtool/package.nix @@ -19,6 +19,9 @@ stdenv.mkDerivation { buildInputs = lib.optionals stdenv.hostPlatform.isAarch64 [ dtc ]; + # glibc 2.43 C23 const-preserving strchr/strstr macros + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + enableParallelBuilding = true; makeFlags = [ diff --git a/pkgs/by-name/la/lame/export-hip-pinfo-symbols.patch b/pkgs/by-name/la/lame/export-hip-pinfo-symbols.patch new file mode 100644 index 000000000000..dad53822ee1a --- /dev/null +++ b/pkgs/by-name/la/lame/export-hip-pinfo-symbols.patch @@ -0,0 +1,18 @@ +Export hip_set_pinfo and hip_finish_pinfo. + +The frontend (get_audio.c) links against these symbols when built with +--enable-analyzer-hooks, but they were missing from the -export-symbols +list, so linking the lame binary failed. Fixed in upstream SVN trunk +after the 4.0 release. + +--- a/include/libmp3lame.sym ++++ b/include/libmp3lame.sym +@@ -188,6 +188,8 @@ hip_decode_exit + hip_set_errorf + hip_set_debugf + hip_set_msgf ++hip_set_pinfo ++hip_finish_pinfo + hip_decode + hip_decode_headers + hip_decode1 diff --git a/pkgs/by-name/la/lame/fix-setlocale-without-iconv.patch b/pkgs/by-name/la/lame/fix-setlocale-without-iconv.patch new file mode 100644 index 000000000000..dcdd1ecb7d6d --- /dev/null +++ b/pkgs/by-name/la/lame/fix-setlocale-without-iconv.patch @@ -0,0 +1,18 @@ +Guard setlocale() the same way as its header include. + +Upstream SVN r6590. parse.c includes only when both +HAVE_ICONV and HAVE_LANGINFO_H are defined, but the setlocale() call +was guarded on HAVE_LANGINFO_H alone, breaking the build on systems +that have langinfo.h but no working iconv (e.g. macOS). + +--- a/frontend/parse.c ++++ b/frontend/parse.c +@@ -1619,7 +1619,7 @@ + enum TextEncoding id3_tenc = TENC_LATIN1; + #endif + +-#ifdef HAVE_LANGINFO_H ++#if defined(HAVE_ICONV) && defined(HAVE_LANGINFO_H) + setlocale(LC_CTYPE, ""); + #endif + inPath[0] = '\0'; \ No newline at end of file diff --git a/pkgs/by-name/la/lame/fix-utf8-id3-tag.patch b/pkgs/by-name/la/lame/fix-utf8-id3-tag.patch new file mode 100644 index 000000000000..5b0b5db52caf --- /dev/null +++ b/pkgs/by-name/la/lame/fix-utf8-id3-tag.patch @@ -0,0 +1,156 @@ +frontend, libmp3lame: fix ID3v2 UTF-8 tag path (SF #524). + +Upstream SVN r6562. The ID3v2 tag writer routed both the UTF-8 and +UTF-16 command-line encodings through a single path typed for UTF-16. +For --id3v2-utf8 that mismatches the actual byte-oriented data and +reaches tag setters GCC 15 rejects as incompatible-pointer-types, +so LAME fails to build with GCC 15. + +Give each encoding its own path so the data and the setters it feeds +match. The test infrastructure changes are omitted as they do not +exist in the 4.0 release tarball. + +--- a/frontend/parse.c ++++ b/frontend/parse.c +@@ -402,41 +402,45 @@ + } + + #ifdef ID3TAGS_EXTENDED ++/* Set an ID3v2 tag field from UTF-16 data. The data pointer is genuinely ++ UTF-16 here, so the UTF-16 id3tag_* setters are used throughout. */ + static int +-set_id3v2tag(lame_global_flags* gfp, TextEncoding enc, int type, unsigned short const* str) ++set_id3v2tag_utf16(lame_global_flags* gfp, int type, unsigned short const* str) + { +- switch (enc) ++ switch (type) + { +- case TENC_UTF8: +- switch (type) +- { +- case 'a': return id3tag_set_textinfo_utf8(gfp, "TPE1", str); +- case 't': return id3tag_set_textinfo_utf8(gfp, "TIT2", str); +- case 'l': return id3tag_set_textinfo_utf8(gfp, "TALB", str); +- case 'g': return id3tag_set_textinfo_utf8(gfp, "TCON", str); +- case 'c': return id3tag_set_comment_ucs2(gfp, 0, 0, str); +- case 'n': return id3tag_set_textinfo_utf8(gfp, "TRCK", str); +- case 'y': return id3tag_set_textinfo_utf8(gfp, "TYER", str); +- case 'v': return id3tag_set_fieldvalue_ucs2(gfp, str); +- } +- ;; +- case TENC_UTF16: +- switch (type) +- { +- case 'a': return id3tag_set_textinfo_utf16(gfp, "TPE1", str); +- case 't': return id3tag_set_textinfo_utf16(gfp, "TIT2", str); +- case 'l': return id3tag_set_textinfo_utf16(gfp, "TALB", str); +- case 'g': return id3tag_set_textinfo_utf16(gfp, "TCON", str); +- case 'c': return id3tag_set_comment_utf16(gfp, 0, 0, str); +- case 'n': return id3tag_set_textinfo_utf16(gfp, "TRCK", str); +- case 'y': return id3tag_set_textinfo_utf16(gfp, "TYER", str); +- case 'v': return id3tag_set_fieldvalue_utf16(gfp, str); +- } +- ;; +- default: +- return -3; ++ case 'a': return id3tag_set_textinfo_utf16(gfp, "TPE1", str); ++ case 't': return id3tag_set_textinfo_utf16(gfp, "TIT2", str); ++ case 'l': return id3tag_set_textinfo_utf16(gfp, "TALB", str); ++ case 'g': return id3tag_set_textinfo_utf16(gfp, "TCON", str); ++ case 'c': return id3tag_set_comment_utf16(gfp, 0, 0, str); ++ case 'n': return id3tag_set_textinfo_utf16(gfp, "TRCK", str); ++ case 'y': return id3tag_set_textinfo_utf16(gfp, "TYER", str); ++ case 'v': return id3tag_set_fieldvalue_utf16(gfp, str); + } ++ return -3; + } ++ ++/* Set an ID3v2 tag field from UTF-8 data. The data pointer is a UTF-8 char ++ string (not UTF-16 as the old, mistyped single handler assumed), so the ++ UTF-8 id3tag_* setters are used - including id3tag_set_fieldvalue_utf8 for ++ 'v', which replaces the removed *_ucs2 calls the UTF-8 path used to make. */ ++static int ++set_id3v2tag_utf8(lame_global_flags* gfp, int type, char const* str) ++{ ++ switch (type) ++ { ++ case 'a': return id3tag_set_textinfo_utf8(gfp, "TPE1", str); ++ case 't': return id3tag_set_textinfo_utf8(gfp, "TIT2", str); ++ case 'l': return id3tag_set_textinfo_utf8(gfp, "TALB", str); ++ case 'g': return id3tag_set_textinfo_utf8(gfp, "TCON", str); ++ case 'c': return id3tag_set_comment_utf8(gfp, 0, 0, str); ++ case 'n': return id3tag_set_textinfo_utf8(gfp, "TRCK", str); ++ case 'y': return id3tag_set_textinfo_utf8(gfp, "TYER", str); ++ case 'v': return id3tag_set_fieldvalue_utf8(gfp, str); ++ } ++ return -3; ++} + #endif + + static int +@@ -480,8 +484,8 @@ + default: + #ifdef ID3TAGS_EXTENDED + case TENC_LATIN1: result = set_id3tag(gfp, type, x); break; +- case TENC_UTF16: result = set_id3v2tag(gfp, enc, type, x); break; +- case TENC_UTF8: result = set_id3v2tag(gfp, enc, type, x); break; ++ case TENC_UTF16: result = set_id3v2tag_utf16(gfp, type, x); break; ++ case TENC_UTF8: result = set_id3v2tag_utf8(gfp, type, x); break; + #else + case TENC_RAW: result = set_id3tag(gfp, type, x); break; + #endif +--- a/include/lame.h ++++ b/include/lame.h +@@ -1297,6 +1297,9 @@ + int CDECL id3tag_set_fieldvalue_utf16(lame_t gfp, const unsigned short *fieldvalue); + + /* experimental */ ++int CDECL id3tag_set_fieldvalue_utf8(lame_t gfp, const char *fieldvalue); ++ ++/* experimental */ + int CDECL id3tag_set_textinfo_utf16(lame_t gfp, char const *id, unsigned short const *text); + + /* experimental */ +--- a/include/lame.def ++++ b/include/lame.def +@@ -306,3 +306,6 @@ + ; two external functions for ID3v2.4 tag support + id3tag_add_v2_4_UTF8 @2029 + id3tag_v2_4_UTF8_only @2030 ++ ++; UTF-8 field-value setter (companion to id3tag_set_fieldvalue_utf16) ++id3tag_set_fieldvalue_utf8 @2031 +--- a/include/libmp3lame.sym ++++ b/include/libmp3lame.sym +@@ -229,6 +229,7 @@ + id3tag_set_comment_ucs2 + id3tag_set_fieldvalue_ucs2 + id3tag_set_fieldvalue_utf16 ++id3tag_set_fieldvalue_utf8 + id3tag_set_textinfo_utf16 + id3tag_set_comment_utf16 + id3tag_set_textinfo_utf8 +--- a/libmp3lame/id3tag.c ++++ b/libmp3lame/id3tag.c +@@ -1844,6 +1844,21 @@ + return id3tag_set_fieldvalue_utf16(gfp, fieldvalue); + } + ++int ++id3tag_set_fieldvalue_utf8(lame_t gfp, const char *fieldvalue) ++{ ++ if (is_lame_internal_flags_null(gfp)) { ++ return 0; ++ } ++ if (fieldvalue && *fieldvalue) { ++ if (strlen(fieldvalue) < 5 || fieldvalue[4] != '=') { ++ return -1; ++ } ++ return id3tag_set_textinfo_utf8(gfp, fieldvalue, &fieldvalue[5]); ++ } ++ return 0; ++} ++ + size_t + lame_get_id3v2_tag(lame_t gfp, unsigned char *buffer, size_t size) + { \ No newline at end of file diff --git a/pkgs/by-name/la/lame/package.nix b/pkgs/by-name/la/lame/package.nix index 7b557369e71f..3c4efc573f1f 100644 --- a/pkgs/by-name/la/lame/package.nix +++ b/pkgs/by-name/la/lame/package.nix @@ -2,6 +2,7 @@ lib, stdenv, fetchurl, + pkg-config, nasmSupport ? true, nasm, # Assembly optimizations cpmlSupport ? true, # Compaq's fast math library @@ -10,6 +11,7 @@ libsndfile, # Use libsndfile, instead of lame's internal routines analyzerHooksSupport ? true, # Use analyzer hooks decoderSupport ? true, # mpg123 decoder + libmpg123, frontendSupport ? true, # Build the lame executable #, mp3xSupport ? false, gtk1 # Build GTK frame analyzer mp3rtpSupport ? false, # Build mp3rtp @@ -18,11 +20,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "lame"; - version = "3.100"; + version = "4.0"; src = fetchurl { url = "mirror://sourceforge/lame/lame-${finalAttrs.version}.tar.gz"; - sha256 = "07nsn5sy3a8xbmw1bidxnsj5fj6kg9ai04icmqw40ybkp353dznx"; + hash = "sha256-PfUSTVrTqYMS/9e6aps2Iw5Pij5m084PQl4zbDLSFus="; }; outputs = [ @@ -32,13 +34,23 @@ stdenv.mkDerivation (finalAttrs: { ]; # a small single header outputMan = "out"; - nativeBuildInputs = [ ] ++ lib.optional nasmSupport nasm; + patches = [ + # fix ID3v2 UTF-8 tag path to avoid incompatible-pointer-types + # with GCC 15; upstream SVN r6562, SF bug #524 + ./fix-utf8-id3-tag.patch + # setlocale() is used under HAVE_LANGINFO_H, but was only + # included together with HAVE_ICONV, breaking the build on macOS; + # upstream SVN r6590 + ./fix-setlocale-without-iconv.patch + # hip_set_pinfo/hip_finish_pinfo are used by the frontend but were missing + # from the exported symbol list, breaking the link with analyzer hooks + # enabled; upstream SVN r6564, SF bug #515 + ./export-hip-pinfo-symbols.patch + ]; - buildInputs = - [ ] - #++ optional efenceSupport libefence - #++ optional mp3xSupport gtk1 - ++ lib.optional sndfileFileIOSupport libsndfile; + nativeBuildInputs = [ pkg-config ] ++ lib.optional nasmSupport nasm; + + buildInputs = lib.optional decoderSupport libmpg123 ++ lib.optional sndfileFileIOSupport libsndfile; configureFlags = [ (lib.enableFeature nasmSupport "nasm") @@ -54,15 +66,9 @@ stdenv.mkDerivation (finalAttrs: { (lib.optionalString debugSupport "--enable-debug=alot") ]; - preConfigure = '' - # Prevent a build failure for 3.100 due to using outdated symbol list - # https://hydrogenaud.io/index.php/topic,114777.msg946373.html#msg946373 - sed -i '/lame_init_old/d' include/libmp3lame.sym - ''; - meta = { description = "High quality MPEG Audio Layer III (MP3) encoder"; - homepage = "http://lame.sourceforge.net"; + homepage = "https://lame.sourceforge.io"; license = lib.licenses.lgpl2; maintainers = [ ]; platforms = lib.platforms.all; diff --git a/pkgs/by-name/ld/ldb/package.nix b/pkgs/by-name/ld/ldb/package.nix index 04d9e7d645bd..45e3f142befb 100644 --- a/pkgs/by-name/ld/ldb/package.nix +++ b/pkgs/by-name/ld/ldb/package.nix @@ -17,6 +17,7 @@ buildPackages, libxcrypt, testers, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -33,6 +34,16 @@ stdenv.mkDerivation (finalAttrs: { "dev" ]; + patches = [ + # Fix rep_memset_s calling C23 memset_explicit with wrong arg count (4 instead of 3). + # Upstream samba commit 04e0fb9b2d; later reworked more broadly in ef08be24e9 and 3e81b73a05 + # which replace memset_s with memset_explicit entirely, but those don't apply to ldb 2.9.2. + (fetchpatch { + url = "https://gitlab.com/samba-team/samba/-/commit/04e0fb9b2d1d87516f1331096c78e8355b4fa9f3.patch"; + hash = "sha256-sBqtVwGBXseCAMlv3QaiSYQmOw7H4cAJwc0Ey5yD6Os="; + }) + ]; + nativeBuildInputs = [ pkg-config python3 diff --git a/pkgs/by-name/le/learn6502/package.nix b/pkgs/by-name/le/learn6502/package.nix index 7f608f7533d9..4131bb10d0b5 100644 --- a/pkgs/by-name/le/learn6502/package.nix +++ b/pkgs/by-name/le/learn6502/package.nix @@ -2,6 +2,7 @@ lib, stdenv, fetchFromGitHub, + substitute, yarn-berry_4, nodejs, meson, @@ -30,22 +31,34 @@ stdenv.mkDerivation (finalAttrs: { owner = "JumpLink"; repo = "Learn6502"; tag = "v${finalAttrs.version}"; - hash = "sha256-wttNOF1ngEK70u+6bBZkFLzvJCQaL9KMfy7EG+mfHIg="; + hash = "sha256-b91b+H5avQDYknDaKUSPGG+Vq6sxSwuJgSiVzdqlbh8="; + + # Remove when updating since upstream migrated to gjsify + # https://github.com/JumpLink/Learn6502/commit/1ae86c179aede8c5785aeda66db334a29d02a7c0 + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry_4.lockfileVersion + ]; + }) + } + ''; }; patches = [ ./get-yarn-from-path.patch - - # Remove after upstream updates to Yarn 4.14 - # https://github.com/JumpLink/Learn6502/blob/main/package.json#L36 - ./yarn-4.14-support.patch ]; missingHashes = ./missing-hashes.json; offlineCache = yarn-berry.fetchYarnBerryDeps { - inherit (finalAttrs) src missingHashes patches; - hash = "sha256-fWx1zawU8pJQ3Q7PYWKmJh3Ko7b8wO0m3KS6XCSd9v8="; + inherit (finalAttrs) src missingHashes; + hash = "sha256-BIP2L6EQXKzpiYrA8qpqQEQ/NnjFrQSyHlmFg7vg1Xk="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/le/learn6502/yarn-4.14-support.patch b/pkgs/by-name/le/learn6502/yarn-fix.patch similarity index 90% rename from pkgs/by-name/le/learn6502/yarn-4.14-support.patch rename to pkgs/by-name/le/learn6502/yarn-fix.patch index 7cf0d4d94092..5a39ecd3f512 100644 --- a/pkgs/by-name/le/learn6502/yarn-4.14-support.patch +++ b/pkgs/by-name/le/learn6502/yarn-fix.patch @@ -18,6 +18,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10c0 diff --git a/pkgs/by-name/le/less/package.nix b/pkgs/by-name/le/less/package.nix index 00823f701cde..7fa226c21f77 100644 --- a/pkgs/by-name/le/less/package.nix +++ b/pkgs/by-name/le/less/package.nix @@ -11,7 +11,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "less"; - version = "704"; + version = "710"; # `less` is provided by the following sources: # - meta.homepage @@ -20,7 +20,7 @@ stdenv.mkDerivation (finalAttrs: { # homepage, and only those not marked as beta. src = fetchurl { url = "https://www.greenwoodsoftware.com/less/less-${finalAttrs.version}.tar.gz"; - hash = "sha256-IKCworslJfpTx+7pvrhUtMnPFy6rsgmvcCB0NUe/6fs="; + hash = "sha256-0QCPt43K4TI92rZkvLNSph8CKxsTG9gBhUjgIdl17Ho="; }; buildInputs = [ diff --git a/pkgs/by-name/li/libaom/outputs.patch b/pkgs/by-name/li/libaom/outputs.patch index 7b34338403f2..d7a6cafba539 100644 --- a/pkgs/by-name/li/libaom/outputs.patch +++ b/pkgs/by-name/li/libaom/outputs.patch @@ -1,8 +1,8 @@ -diff --git a/build/cmake/aom_install.cmake b/build/cmake/aom_install.cmake -index 0bd2bf035..5cf5acea8 100644 ---- a/build/cmake/aom_install.cmake -+++ b/build/cmake/aom_install.cmake -@@ -42,8 +42,8 @@ macro(setup_aom_install_targets) +diff --git a/cmake/aom_install.cmake b/cmake/aom_install.cmake +index a8f6d64361..c5223462ed 100644 +--- a/cmake/aom_install.cmake ++++ b/cmake/aom_install.cmake +@@ -45,8 +45,8 @@ macro(setup_aom_install_targets) -DAOM_ROOT=${AOM_ROOT} -DCMAKE_INSTALL_PREFIX=${CMAKE_INSTALL_PREFIX} -DCMAKE_INSTALL_BINDIR=${CMAKE_INSTALL_BINDIR} @@ -11,9 +11,9 @@ index 0bd2bf035..5cf5acea8 100644 + -DCMAKE_INSTALL_FULL_INCLUDEDIR=${CMAKE_INSTALL_FULL_INCLUDEDIR} + -DCMAKE_INSTALL_FULL_LIBDIR=${CMAKE_INSTALL_FULL_LIBDIR} -DCMAKE_PROJECT_NAME=${CMAKE_PROJECT_NAME} + -DCMAKE_THREAD_LIBS_INIT=${CMAKE_THREAD_LIBS_INIT} -DCONFIG_MULTITHREAD=${CONFIG_MULTITHREAD} - -DCONFIG_TUNE_VMAF=${CONFIG_TUNE_VMAF} -@@ -84,12 +84,12 @@ macro(setup_aom_install_targets) +@@ -115,13 +115,13 @@ macro(setup_aom_install_targets) # Setup the install rules. install() will automatically prepend # CMAKE_INSTALL_PREFIX to relative paths install(FILES ${AOM_INSTALL_INCS} @@ -23,6 +23,7 @@ index 0bd2bf035..5cf5acea8 100644 - DESTINATION "${CMAKE_INSTALL_LIBDIR}/pkgconfig") + DESTINATION "${CMAKE_INSTALL_FULL_LIBDIR}/pkgconfig") install(TARGETS ${AOM_INSTALL_LIBS};${AOM_INSTALL_BINS} + EXPORT "${AOM_TARGETS_EXPORT_NAME}" - RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}" - LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" - ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}") @@ -31,12 +32,12 @@ index 0bd2bf035..5cf5acea8 100644 + ARCHIVE DESTINATION "${CMAKE_INSTALL_FULL_LIBDIR}") endif() endmacro() -diff --git a/build/cmake/pkg_config.cmake b/build/cmake/pkg_config.cmake -index e8fff2e77..b8a73aad4 100644 ---- a/build/cmake/pkg_config.cmake -+++ b/build/cmake/pkg_config.cmake +diff --git a/cmake/pkg_config.cmake b/cmake/pkg_config.cmake +index ad3cf77009..1b46040cd1 100644 +--- a/cmake/pkg_config.cmake ++++ b/cmake/pkg_config.cmake @@ -11,8 +11,8 @@ - cmake_minimum_required(VERSION 3.5) + cmake_minimum_required(VERSION 3.16) set(REQUIRED_ARGS "AOM_ROOT" "AOM_CONFIG_DIR" "CMAKE_INSTALL_PREFIX" - "CMAKE_INSTALL_BINDIR" "CMAKE_INSTALL_INCLUDEDIR" diff --git a/pkgs/by-name/li/libaom/package.nix b/pkgs/by-name/li/libaom/package.nix index c8296dd90fb8..c8cf959b9bf0 100644 --- a/pkgs/by-name/li/libaom/package.nix +++ b/pkgs/by-name/li/libaom/package.nix @@ -23,25 +23,16 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "libaom"; - version = "3.12.1"; + version = "3.15.0"; src = fetchzip { url = "https://aomedia.googlesource.com/aom/+archive/v${finalAttrs.version}.tar.gz"; - hash = "sha256-AAS6wfq4rZ4frm6+gwKoIS3+NVzPhhfW428WXJQ2tQ8="; + hash = "sha256-TixZQP06TEZPtpHvWVOEagzHtXW9hqXWweO2yimBDG4="; stripRoot = false; }; patches = [ ./outputs.patch - ] - ++ lib.optionals (!stdenv.hostPlatform.isDarwin) [ - # This patch defines `_POSIX_C_SOURCE`, which breaks system headers - # on Darwin. - (fetchurl { - name = "musl.patch"; - url = "https://gitweb.gentoo.org/repo/gentoo.git/plain/media-libs/libaom/files/libaom-3.4.0-posix-c-source-ftello.patch?id=50c7c4021e347ee549164595280cf8a23c960959"; - hash = "sha256-6+u7GTxZcSNJgN7D+s+XAVwbMnULufkTcQ0s7l+Ydl0="; - }) ]; nativeBuildInputs = [ @@ -54,11 +45,16 @@ stdenv.mkDerivation (finalAttrs: { propagatedBuildInputs = lib.optional enableVmaf libvmaf; - env = lib.optionalAttrs stdenv.hostPlatform.isFreeBSD { - # This can be removed when we switch to libcxx from llvm 20 - # https://github.com/llvm/llvm-project/pull/122361 - NIX_CFLAGS_COMPILE = "-D_XOPEN_SOURCE=700"; - }; + env = + lib.optionalAttrs stdenv.hostPlatform.isFreeBSD { + # This can be removed when we switch to libcxx from llvm 20 + # https://github.com/llvm/llvm-project/pull/122361 + NIX_CFLAGS_COMPILE = "-D_XOPEN_SOURCE=700"; + } + // lib.optionalAttrs stdenv.hostPlatform.isLinux { + # _POSIX_C_SOURCE breaks system headers on Darwin; it's required on musl + NIX_CFLAGS_COMPILE = "-D_POSIX_C_SOURCE=200112L"; + }; preConfigure = '' # build uses `git describe` to set the build version @@ -91,11 +87,17 @@ stdenv.mkDerivation (finalAttrs: { postFixup = '' moveToOutput lib/libaom.a "$static" + substituteInPlace "$dev"/lib/cmake/*/*.cmake \ + --replace-quiet "$out/lib/libaom.a" "$static/lib/libaom.a" \ + --replace-quiet "$"'{_IMPORT_PREFIX}/include' "$dev/include" '' + lib.optionalString stdenv.hostPlatform.isStatic '' ln -s $static $out ''; + __structuredAttrs = true; + strictDeps = true; + outputs = [ "out" "bin" diff --git a/pkgs/by-name/li/libbladeRF/package.nix b/pkgs/by-name/li/libbladeRF/package.nix index cb340b8bad73..c022cc7b3a34 100644 --- a/pkgs/by-name/li/libbladeRF/package.nix +++ b/pkgs/by-name/li/libbladeRF/package.nix @@ -12,6 +12,7 @@ libusb1, curl, udev, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -29,6 +30,12 @@ stdenv.mkDerivation (finalAttrs: { patches = [ # fix clang build: https://github.com/Nuand/bladeRF/pull/1045 ./clang-fix.patch + + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/Nuand/bladeRF/commit/87bdb1a4bbbc45b749bb90db504fe9cf8fe7a595.patch"; + hash = "sha256-/sB18hwBSIqMkjaC7J0rb4STUrq4BWlJKnyy0Szac9c="; + }) ]; nativeBuildInputs = [ diff --git a/pkgs/by-name/li/libcap_ng/package.nix b/pkgs/by-name/li/libcap_ng/package.nix index c9aaca668faa..a7d3b1ddb757 100644 --- a/pkgs/by-name/li/libcap_ng/package.nix +++ b/pkgs/by-name/li/libcap_ng/package.nix @@ -2,6 +2,7 @@ lib, stdenv, fetchFromGitHub, + fetchpatch, autoreconfHook, pkg-config, swig, @@ -14,15 +15,29 @@ stdenv.mkDerivation (finalAttrs: { pname = "libcap-ng"; - version = "0.9.5"; + version = "0.9.6"; src = fetchFromGitHub { owner = "stevegrubb"; repo = "libcap-ng"; tag = "v${finalAttrs.version}"; - hash = "sha256-HYVbPoFSlkmNuL5EsEQVAekE4fwidgL+biTBBS1BdPM="; + hash = "sha256-+2u3clE04++YfHbTCQAIY9uKmfks9fsPZnVQNE/CmvY="; }; + patches = [ + # https://github.com/stevegrubb/libcap-ng/issues/85 + (fetchpatch { + # static musl has tests failing to compile + url = "https://github.com/stevegrubb/libcap-ng/commit/ef1b34928455fa31ff5427d6ad4166406d5a1df1.patch"; + hash = "sha256-7EZC87RoVH2Dkg859rRXt2A+GhRJVajn/DpmYBUuEBI="; + }) + (fetchpatch { + # tests fail when building on a host with alpine kernel + url = "https://github.com/stevegrubb/libcap-ng/commit/b346f998af31febfb7d0915d0cf5e633a5262e88.patch"; + hash = "sha256-b+OOY4XFXxK7sAH8/PUJ8oDPVtH84LYrzcEvhPfB9QI="; + }) + ]; + # NEWS needs to exist or else the build fails postPatch = '' touch NEWS @@ -86,9 +101,7 @@ stdenv.mkDerivation (finalAttrs: { # assumption: build machine runs linux kernel 5.0 or newer # see https://github.com/stevegrubb/libcap-ng?tab=readme-ov-file#note-to-distributions - # disabled on static due to symbol collision in test file compilation - # see https://github.com/stevegrubb/libcap-ng/issues/85 - doCheck = !stdenv.hostPlatform.isStatic; + doCheck = true; pythonImportsCheck = [ "capng" diff --git a/pkgs/by-name/li/libfaketime/package.nix b/pkgs/by-name/li/libfaketime/package.nix index 1e9667b83fba..7bc9995e09d8 100644 --- a/pkgs/by-name/li/libfaketime/package.nix +++ b/pkgs/by-name/li/libfaketime/package.nix @@ -34,6 +34,11 @@ stdenv.mkDerivation (finalAttrs: { patches = [ ./nix-store-date.patch + # Fixes build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/wolfcw/libfaketime/commit/dbe865dfdba0145d993d70b7fd4ec88b2f47554b.patch"; + hash = "sha256-pn9MInefa4ZKuOorGEpi/sDQOQamCakjdYOkFSNA2VQ="; + }) ] ++ lib.optionals (!stdenv.hostPlatform.isDarwin) [ # GCC 16's unused variable analysis is more advanced than previous diff --git a/pkgs/by-name/li/libgcrypt/package.nix b/pkgs/by-name/li/libgcrypt/package.nix index 0e23409dcd67..940b1d861da7 100644 --- a/pkgs/by-name/li/libgcrypt/package.nix +++ b/pkgs/by-name/li/libgcrypt/package.nix @@ -2,7 +2,6 @@ lib, stdenv, fetchurl, - fetchpatch, gettext, libgpg-error, enableCapabilities ? false, @@ -18,23 +17,13 @@ assert enableCapabilities -> stdenv.hostPlatform.isLinux; stdenv.mkDerivation (finalAttrs: { pname = "libgcrypt"; - version = "1.12.2"; + version = "1.12.4"; src = fetchurl { url = "mirror://gnupg/libgcrypt/libgcrypt-${finalAttrs.version}.tar.bz2"; - hash = "sha256-fOM8JJIiGgQ2+WqFACFenz49y1/SanV81BXnqEO6vV4="; + hash = "sha256-139o9Ih5UQ55ovZZd8zGiYF4HqCSPlvf+sKhk+o9Zg4="; }; - patches = lib.optionals stdenv.hostPlatform.isRiscV64 [ - # Remove in next release - # https://github.com/gpg/libgcrypt/commit/3f684fc6ab3ac98320e245a06b3563ad37ec56f5 - # zvkned AES corrupts CBC/CFB/CTR/OCB/XTS output on VLEN>128 hardware - (fetchpatch { - url = "https://github.com/gpg/libgcrypt/commit/3f684fc6ab3ac98320e245a06b3563ad37ec56f5.patch"; - hash = "sha256-1LSrIwsN0n5IBRDZ+9MJTEjzY+/T6LQO6hX1ke8hSuc="; - }) - ]; - outputs = [ "bin" "lib" diff --git a/pkgs/by-name/li/libgdamm/package.nix b/pkgs/by-name/li/libgdamm/package.nix index 2ac44bd39ced..f9fc5dcda735 100644 --- a/pkgs/by-name/li/libgdamm/package.nix +++ b/pkgs/by-name/li/libgdamm/package.nix @@ -3,7 +3,7 @@ stdenv, fetchurl, pkg-config, - glibmm, + glibmm_2_4, libgda5, libxml2, gnome, @@ -32,7 +32,7 @@ stdenv.mkDerivation rec { nativeBuildInputs = [ pkg-config ]; buildInputs = [ - glibmm + glibmm_2_4 libxml2 ]; propagatedBuildInputs = [ gda ]; diff --git a/pkgs/by-name/li/libheif/package.nix b/pkgs/by-name/li/libheif/package.nix index edee50ffcab4..e1a009bf666b 100644 --- a/pkgs/by-name/li/libheif/package.nix +++ b/pkgs/by-name/li/libheif/package.nix @@ -24,7 +24,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "libheif"; - version = "1.23.3"; + version = "1.23.5"; outputs = [ "bin" @@ -38,7 +38,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "strukturag"; repo = "libheif"; rev = "v${finalAttrs.version}"; - hash = "sha256-cFEEauwgMekd4/xUpyPGqpJh82W4LRyl6PdMvOFWoLA="; + hash = "sha256-+nrUIAclVgkj4N5U3wQ1L6qpZuF3fuzHFDUT+X39h04="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/li/libimobiledevice/package.nix b/pkgs/by-name/li/libimobiledevice/package.nix index 91fd4d468270..9320772113f8 100644 --- a/pkgs/by-name/li/libimobiledevice/package.nix +++ b/pkgs/by-name/li/libimobiledevice/package.nix @@ -15,19 +15,19 @@ unstableGitUpdater, }: -stdenv.mkDerivation rec { +stdenv.mkDerivation (finalAttrs: { pname = "libimobiledevice"; version = "1.4.0"; src = fetchFromGitHub { owner = "libimobiledevice"; repo = "libimobiledevice"; - tag = version; + tag = finalAttrs.version; hash = "sha256-SWWsa7asCXpcz80VNhxoePWr74QY8SP0byGSCp+nGG0="; }; preAutoreconf = '' - export RELEASE_VERSION=${version} + export RELEASE_VERSION=${finalAttrs.version} ''; configureFlags = [ "--without-cython" ]; @@ -39,7 +39,6 @@ stdenv.mkDerivation rec { propagatedBuildInputs = [ openssl - libgcrypt libplist libtasn1 libtatsu @@ -47,6 +46,9 @@ stdenv.mkDerivation rec { libimobiledevice-glue ]; + strictDeps = true; + __structuredAttrs = true; + outputs = [ "out" "dev" @@ -75,4 +77,4 @@ stdenv.mkDerivation rec { platforms = lib.platforms.unix; maintainers = with lib.maintainers; [ RossComputerGuy ]; }; -} +}) diff --git a/pkgs/by-name/li/libmad/package.nix b/pkgs/by-name/li/libmad/package.nix index e2f1cf59cc2e..e2054f281db0 100644 --- a/pkgs/by-name/li/libmad/package.nix +++ b/pkgs/by-name/li/libmad/package.nix @@ -70,6 +70,8 @@ stdenv.mkDerivation (finalAttrs: { nativeBuildInputs = [ autoconf ]; + strictDeps = true; + preConfigure = "autoconf"; passthru.tests = { @@ -83,6 +85,8 @@ stdenv.mkDerivation (finalAttrs: { ocaml-mad = ocamlPackages.mad; }; + __structuredAttrs = true; + meta = { homepage = "https://sourceforge.net/projects/mad/"; description = "High-quality, fixed-point MPEG audio decoder supporting MPEG-1 and MPEG-2"; diff --git a/pkgs/by-name/li/libmongocrypt/package.nix b/pkgs/by-name/li/libmongocrypt/package.nix index 98efd633bdee..808c8b4d97e7 100644 --- a/pkgs/by-name/li/libmongocrypt/package.nix +++ b/pkgs/by-name/li/libmongocrypt/package.nix @@ -29,6 +29,9 @@ stdenv.mkDerivation (finalAttrs: { }) ]; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + nativeBuildInputs = [ cmake pkg-config diff --git a/pkgs/by-name/li/libmysofa/package.nix b/pkgs/by-name/li/libmysofa/package.nix index 360cff5d871d..dc7c0e1f9efd 100644 --- a/pkgs/by-name/li/libmysofa/package.nix +++ b/pkgs/by-name/li/libmysofa/package.nix @@ -3,6 +3,8 @@ stdenv, fetchFromGitHub, cmake, + cunit, + nodejs, zlib, }: @@ -26,10 +28,16 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ zlib ]; + nativeCheckInputs = [ nodejs ]; + + checkInputs = [ cunit ]; + cmakeFlags = [ - (lib.cmakeBool "BUILD_TESTS" false) + (lib.cmakeBool "BUILD_TESTS" finalAttrs.finalPackage.doCheck) ]; + doCheck = true; + __structuredAttrs = true; strictDeps = true; diff --git a/pkgs/by-name/li/libnice/package.nix b/pkgs/by-name/li/libnice/package.nix index 5a0590c209f5..3bb3672769a2 100644 --- a/pkgs/by-name/li/libnice/package.nix +++ b/pkgs/by-name/li/libnice/package.nix @@ -3,7 +3,6 @@ stdenv, testers, fetchFromGitLab, - fetchpatch, nix-update-script, meson, ninja, @@ -27,7 +26,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "libnice"; - version = "0.1.23"; + version = "0.1.24"; outputs = [ "bin" @@ -41,7 +40,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "libnice"; repo = "libnice"; tag = finalAttrs.version; - hash = "sha256-UPppE5kBois0jJwsHKefBC8iTfSIkPZXV6XnUBnEFn8="; + hash = "sha256-7y+yTf/kp4uy9LZCbcMisA1892csBjdXQU5mOVnrxRY="; }; patches = [ @@ -51,12 +50,6 @@ stdenv.mkDerivation (finalAttrs: { ] # TODO: investigate what's wrong ++ lib.optionals (!stdenv.hostPlatform.isDarwin) [ - (fetchpatch { - name = "freebsd.patch"; - url = "https://gitlab.freedesktop.org/libnice/libnice/-/commit/479f0813a571ff035bf00de679db452a0441125b.patch"; - hash = "sha256-rr8pAb8TjU85jYWUjsMMKkLxxXVE3B+IjfAyOw9suo0="; - }) - # https://gitlab.freedesktop.org/libnice/libnice/-/merge_requests/353 ./musl.patch ]; @@ -65,6 +58,13 @@ stdenv.mkDerivation (finalAttrs: { postPatch = '' substituteInPlace docs/reference/libnice/meson.build \ --replace-fail "version: '<1.30', " "" + '' + # Manually remove failing tests until we have disabledTests for meson + # The failures are due to the sandbox restricting network sockets + + '' + substituteInPlace tests/meson.build \ + --replace-fail "'test-slow-resolving'," "" \ + --replace-fail "'test-set-port-range'," "" ''; nativeBuildInputs = [ @@ -107,9 +107,7 @@ stdenv.mkDerivation (finalAttrs: { glib_debug = false; }; - # Tests are flaky - # see https://github.com/NixOS/nixpkgs/pull/53293#issuecomment-453739295 - doCheck = false; + doCheck = !stdenv.hostPlatform.isDarwin; passthru = { updateScript = nix-update-script { }; diff --git a/pkgs/by-name/li/libpaper/package.nix b/pkgs/by-name/li/libpaper/package.nix index 71c6f5326aeb..08be8cc12196 100644 --- a/pkgs/by-name/li/libpaper/package.nix +++ b/pkgs/by-name/li/libpaper/package.nix @@ -16,16 +16,16 @@ stdenv.mkDerivation (finalAttrs: { nativeBuildInputs = [ autoreconfHook ]; + strictDeps = true; + # The configure script of libpaper is buggy: it uses AC_SUBST on a headerfile # to compile sysconfdir into the library. Autoconf however defines sysconfdir # as "${prefix}/etc", which is not expanded by AC_SUBST so libpaper will look # for config files in (literally, without expansion) '${prefix}/etc'. Manually # setting sysconfdir fixes this issue. - preConfigure = '' - configureFlagsArray+=( - "--sysconfdir=$out/etc" - ) - ''; + configureFlags = [ + "--sysconfdir=${placeholder "out"}/etc" + ]; # Set the default paper to letter (this is what libpaper uses as default as well, # if you call getdefaultpapername()). @@ -35,6 +35,8 @@ stdenv.mkDerivation (finalAttrs: { echo letter > $out/etc/papersize ''; + __structuredAttrs = true; + meta = { changelog = "https://github.com/rrthomas/libpaper/releases/tag/v${finalAttrs.version}"; description = "Library for handling paper characteristics"; diff --git a/pkgs/by-name/li/libpar2/package.nix b/pkgs/by-name/li/libpar2/package.nix index 2d29d4d81eb7..5b718cead6c8 100644 --- a/pkgs/by-name/li/libpar2/package.nix +++ b/pkgs/by-name/li/libpar2/package.nix @@ -3,7 +3,7 @@ stdenv, fetchurl, pkg-config, - libsigcxx, + libsigcxx_2_0, }: stdenv.mkDerivation (finalAttrs: { @@ -16,7 +16,7 @@ stdenv.mkDerivation (finalAttrs: { }; nativeBuildInputs = [ pkg-config ]; - buildInputs = [ libsigcxx ]; + buildInputs = [ libsigcxx_2_0 ]; patches = [ ./libpar2-0.4-external-verification.patch ]; diff --git a/pkgs/by-name/li/libpcap/package.nix b/pkgs/by-name/li/libpcap/package.nix index 5abab91f1a89..cfd19f446756 100644 --- a/pkgs/by-name/li/libpcap/package.nix +++ b/pkgs/by-name/li/libpcap/package.nix @@ -28,13 +28,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "libpcap"; - version = "1.10.6"; + version = "1.10.7"; __structuredAttrs = true; src = fetchurl { url = "https://www.tcpdump.org/release/libpcap-${finalAttrs.version}.tar.gz"; - hash = "sha256-hy3REzf+GrAq2dT+4EfJ2iRNaVxt3zTi67cz79Ttiqk="; + hash = "sha256-CzlKyQ28Cpg4/5dGjgXJyaPoc97CUUzVjbZdhZ0pbjE="; }; outputs = [ diff --git a/pkgs/by-name/li/libqrtr-glib/package.nix b/pkgs/by-name/li/libqrtr-glib/package.nix index 16f5a7cb6301..0f8857b2d204 100644 --- a/pkgs/by-name/li/libqrtr-glib/package.nix +++ b/pkgs/by-name/li/libqrtr-glib/package.nix @@ -15,12 +15,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "libqrtr-glib"; - version = "1.2.2"; + version = "1.4.0"; outputs = [ "out" "dev" - "devdoc" ]; src = fetchFromGitLab { @@ -28,7 +27,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "mobile-broadband"; repo = "libqrtr-glib"; rev = finalAttrs.version; - sha256 = "kHLrOXN6wgBrHqipo2KfAM5YejS0/bp7ziBSpt0s1i0="; + sha256 = "sha256-1zsGwZogsI0QvIvvQy5FhcRSq2Q75/J724OcM+K/QBo="; }; strictDeps = true; diff --git a/pkgs/by-name/li/librist/package.nix b/pkgs/by-name/li/librist/package.nix index 606b5f6a5acb..21d163f974d5 100644 --- a/pkgs/by-name/li/librist/package.nix +++ b/pkgs/by-name/li/librist/package.nix @@ -34,6 +34,9 @@ stdenv.mkDerivation (finalAttrs: { pkg-config ]; + # glibc 2.43 C23 const-preserving strchr/strstr macros + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + buildInputs = [ cjson cmocka diff --git a/pkgs/development/libraries/libsigcxx/default.nix b/pkgs/by-name/li/libsigcxx_3_0/2.0.nix similarity index 73% rename from pkgs/development/libraries/libsigcxx/default.nix rename to pkgs/by-name/li/libsigcxx_3_0/2.0.nix index 95f040620245..dbd05819626c 100644 --- a/pkgs/development/libraries/libsigcxx/default.nix +++ b/pkgs/by-name/li/libsigcxx_3_0/2.0.nix @@ -8,13 +8,16 @@ gnome, }: -stdenv.mkDerivation rec { +stdenv.mkDerivation (finalAttrs: { pname = "libsigc++"; version = "2.12.1"; + __structuredAttrs = true; + strictDeps = true; + src = fetchurl { - url = "mirror://gnome/sources/libsigc++/${lib.versions.majorMinor version}/libsigc++-${version}.tar.xz"; - sha256 = "sha256-qdvuMjNR0Qm3ruB0qcuJyj57z4rY7e8YUfTPNZvVCEM="; + url = "mirror://gnome/sources/libsigc++/${lib.versions.majorMinor finalAttrs.version}/libsigc++-${finalAttrs.version}.tar.xz"; + hash = "sha256-qdvuMjNR0Qm3ruB0qcuJyj57z4rY7e8YUfTPNZvVCEM="; }; outputs = [ @@ -33,7 +36,7 @@ stdenv.mkDerivation rec { passthru = { updateScript = gnome.updateScript { packageName = "libsigc++"; - attrPath = "libsigcxx"; + attrPath = "libsigcxx_2_0"; versionPolicy = "odd-unstable"; freeze = "2.99.1"; }; @@ -45,4 +48,4 @@ stdenv.mkDerivation rec { license = lib.licenses.lgpl21Plus; platforms = lib.platforms.all; }; -} +}) diff --git a/pkgs/development/libraries/libsigcxx/3.0.nix b/pkgs/by-name/li/libsigcxx_3_0/package.nix similarity index 92% rename from pkgs/development/libraries/libsigcxx/3.0.nix rename to pkgs/by-name/li/libsigcxx_3_0/package.nix index 8162e731e3da..5a1c82cfe251 100644 --- a/pkgs/development/libraries/libsigcxx/3.0.nix +++ b/pkgs/by-name/li/libsigcxx_3_0/package.nix @@ -12,6 +12,9 @@ stdenv.mkDerivation (finalAttrs: { pname = "libsigc++"; version = "3.8.1"; + __structuredAttrs = true; + strictDeps = true; + src = fetchFromGitHub { owner = "libsigcplusplus"; repo = "libsigcplusplus"; @@ -35,7 +38,7 @@ stdenv.mkDerivation (finalAttrs: { passthru = { updateScript = gnome.updateScript { packageName = "libsigc++"; - attrPath = "libsigcxx30"; + attrPath = "libsigcxx_3_0"; versionPolicy = "odd-unstable"; }; }; diff --git a/pkgs/by-name/li/libsigrok-sipeed/package.nix b/pkgs/by-name/li/libsigrok-sipeed/package.nix index 43874dfe8b13..12eddd96e509 100644 --- a/pkgs/by-name/li/libsigrok-sipeed/package.nix +++ b/pkgs/by-name/li/libsigrok-sipeed/package.nix @@ -11,7 +11,7 @@ check, libserialport, doxygen, - glibmm, + glibmm_2_4, python3, hidapi, libieee1284, @@ -46,7 +46,7 @@ stdenv.mkDerivation { libftdi1 check libserialport - glibmm + glibmm_2_4 hidapi ] ++ lib.optionals stdenv.hostPlatform.isLinux [ diff --git a/pkgs/by-name/li/libsigrok/package.nix b/pkgs/by-name/li/libsigrok/package.nix index 5b8a9dbf62e9..8eafebf76d23 100644 --- a/pkgs/by-name/li/libsigrok/package.nix +++ b/pkgs/by-name/li/libsigrok/package.nix @@ -10,7 +10,7 @@ check, libserialport, doxygen, - glibmm, + glibmm_2_4, python3, hidapi, libieee1284, @@ -43,7 +43,7 @@ stdenv.mkDerivation { libftdi1 check libserialport - glibmm + glibmm_2_4 hidapi ] ++ lib.optionals stdenv.hostPlatform.isLinux [ diff --git a/pkgs/by-name/li/libsoup_3/package.nix b/pkgs/by-name/li/libsoup_3/package.nix index 30a203e84343..872dfff315aa 100644 --- a/pkgs/by-name/li/libsoup_3/package.nix +++ b/pkgs/by-name/li/libsoup_3/package.nix @@ -23,7 +23,7 @@ libnghttp2, }: -stdenv.mkDerivation rec { +stdenv.mkDerivation (finalAttrs: { pname = "libsoup"; version = "3.6.6"; @@ -34,7 +34,7 @@ stdenv.mkDerivation rec { ++ lib.optional withIntrospection "devdoc"; src = fetchurl { - url = "mirror://gnome/sources/${pname}/${lib.versions.majorMinor version}/${pname}-${version}.tar.xz"; + url = "mirror://gnome/sources/libsoup/${lib.versions.majorMinor finalAttrs.version}/libsoup-${finalAttrs.version}.tar.xz"; hash = "sha256-Ue0K4G+dWkD0Af9Fni5fZS+aUQt3MOE1nuZtFNSHJ0A="; }; @@ -148,6 +148,8 @@ stdenv.mkDerivation rec { glib ]; + strictDeps = true; + mesonFlags = [ "-Dtls_check=false" # glib-networking is a runtime dependency, not a compile-time dependency "-Dgssapi=disabled" @@ -187,11 +189,13 @@ stdenv.mkDerivation rec { }; }; + __structuredAttrs = true; + meta = { description = "HTTP client/server library for GNOME"; homepage = "https://gitlab.gnome.org/GNOME/libsoup"; license = lib.licenses.lgpl2Plus; - changelog = "https://gitlab.gnome.org/GNOME/libsoup/-/blob/${version}/NEWS"; + changelog = "https://gitlab.gnome.org/GNOME/libsoup/-/blob/${finalAttrs.version}/NEWS"; inherit (glib.meta) maintainers platforms teams; }; -} +}) diff --git a/pkgs/by-name/li/liburcu/package.nix b/pkgs/by-name/li/liburcu/package.nix index a983e5e99f9a..d0c1d37a4599 100644 --- a/pkgs/by-name/li/liburcu/package.nix +++ b/pkgs/by-name/li/liburcu/package.nix @@ -7,12 +7,12 @@ }: stdenv.mkDerivation (finalAttrs: { - version = "0.15.6"; + version = "0.15.7"; pname = "liburcu"; src = fetchurl { url = "https://lttng.org/files/urcu/userspace-rcu-${finalAttrs.version}.tar.bz2"; - hash = "sha256-hQsZIJbrEevyxw6Pl7x9p0ee5B2hvr60TjmGkIusQU8="; + hash = "sha256-JVa4OtwPmzrIAk5hPhfQFNBMTEkRBgTOVfyxTq4y7dM="; }; outputs = [ @@ -23,6 +23,8 @@ stdenv.mkDerivation (finalAttrs: { nativeCheckInputs = [ perl ]; + strictDeps = true; + enableParallelBuilding = true; preCheck = "patchShebangs tests/unit"; @@ -33,6 +35,8 @@ stdenv.mkDerivation (finalAttrs: { rev-prefix = "v"; }; + __structuredAttrs = true; + meta = { description = "Userspace RCU (read-copy-update) library"; homepage = "https://lttng.org/urcu"; diff --git a/pkgs/by-name/li/libvpx/package.nix b/pkgs/by-name/li/libvpx/package.nix index 5ecf5bf47fe2..684c5244da60 100644 --- a/pkgs/by-name/li/libvpx/package.nix +++ b/pkgs/by-name/li/libvpx/package.nix @@ -136,13 +136,13 @@ assert isCygwin -> unitTestsSupport && webmIOSupport && libyuvSupport; stdenv.mkDerivation (finalAttrs: { pname = "libvpx"; - version = "1.16.0"; + version = "1.17.0"; src = fetchFromGitHub { owner = "webmproject"; repo = "libvpx"; rev = "v${finalAttrs.version}"; - hash = "sha256-z1Ov3BHnAGuayeY4D86oTRiDfuZ2Wpc4ZD7pXGaakVI="; + hash = "sha256-1PBeHQSgBf5nT/IDL36VWBqiWLSHz/1XGM41gy49DsY="; }; postPatch = '' diff --git a/pkgs/by-name/li/libxmlxx5/package.nix b/pkgs/by-name/li/libxmlxx5/package.nix index 98d6077a7ed1..34d668e12259 100644 --- a/pkgs/by-name/li/libxmlxx5/package.nix +++ b/pkgs/by-name/li/libxmlxx5/package.nix @@ -4,7 +4,7 @@ fetchFromGitHub, pkg-config, libxml2, - glibmm, + glibmm_2_4, meson, ninja, }: @@ -26,7 +26,7 @@ stdenv.mkDerivation (finalAttrs: { ninja ]; - buildInputs = [ glibmm ]; + buildInputs = [ glibmm_2_4 ]; propagatedBuildInputs = [ libxml2 ]; diff --git a/pkgs/by-name/li/lightspark/package.nix b/pkgs/by-name/li/lightspark/package.nix index 62539355e3e7..302141088b66 100644 --- a/pkgs/by-name/li/lightspark/package.nix +++ b/pkgs/by-name/li/lightspark/package.nix @@ -17,7 +17,7 @@ xz, nasm, llvm, - glibmm, + glibmm_2_4, }: stdenv.mkDerivation (finalAttrs: { @@ -54,7 +54,7 @@ stdenv.mkDerivation (finalAttrs: { xz nasm llvm - glibmm + glibmm_2_4 ]; meta = { diff --git a/pkgs/by-name/li/links2/package.nix b/pkgs/by-name/li/links2/package.nix index d63aab7bc04b..885bfb3c1158 100644 --- a/pkgs/by-name/li/links2/package.nix +++ b/pkgs/by-name/li/links2/package.nix @@ -76,5 +76,6 @@ stdenv.mkDerivation (finalAttrs: { mainProgram = "links"; license = lib.licenses.gpl2Plus; platforms = lib.platforms.unix; + broken = true; }; }) diff --git a/pkgs/by-name/li/linkwarden/package.nix b/pkgs/by-name/li/linkwarden/package.nix index 7844371304c9..b1041ab8a87c 100644 --- a/pkgs/by-name/li/linkwarden/package.nix +++ b/pkgs/by-name/li/linkwarden/package.nix @@ -4,6 +4,7 @@ buildNpmPackage, fetchFromGitHub, yarn-berry, + substitute, makeBinaryWrapper, nixosTests, stdenv, @@ -75,7 +76,23 @@ stdenvNoCC.mkDerivation (finalAttrs: { owner = "linkwarden"; repo = "linkwarden"; tag = "v${finalAttrs.version}"; - hash = "sha256-4S2/TRZlMa3KHM+tmrWQsqGFk0TZjMbhdS2b1aNTVow="; + hash = "sha256-/Hnavo98+X0XAULkMKLVO2H4eK548I/d8l/b0NzM88I="; + + # Remove after upstream updates to Yarn 4.15 + # https://github.com/linkwarden/linkwarden/blob/main/package.json#L3 + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry.lockfileVersion + ]; + }) + } + ''; }; patches = [ @@ -89,16 +106,12 @@ stdenvNoCC.mkDerivation (finalAttrs: { pkgs/by-name/ne/nextjs-ollama-llm-ui/0002-use-local-google-fonts.patch */ ./01-localfont.patch - - # Remove after upstream updates to Yarn 4.14 - # https://github.com/linkwarden/linkwarden/blob/main/package.json#L3 - ./02-yarn-4.14-support.patch ]; missingHashes = ./missing-hashes.json; yarnOfflineCache = yarn-berry.fetchYarnBerryDeps { - inherit (finalAttrs) src missingHashes patches; - hash = "sha256-f7xIzxN+0JWZeGfeK/3XTiUbxrnnzErbFEukolMMv/s="; + inherit (finalAttrs) src missingHashes; + hash = "sha256-6NiA2gNBk3auIjYqv9TxsbUR/k7ygj6KejrWx+Gy0pg="; }; nativeBuildInputs = [ diff --git a/pkgs/servers/home-assistant/custom-lovelace-modules/horizon-card/yarn-4.14-support.patch b/pkgs/by-name/li/linkwarden/yarn-fix.patch similarity index 89% rename from pkgs/servers/home-assistant/custom-lovelace-modules/horizon-card/yarn-4.14-support.patch rename to pkgs/by-name/li/linkwarden/yarn-fix.patch index 75225db95b78..7a11f6399640 100644 --- a/pkgs/servers/home-assistant/custom-lovelace-modules/horizon-card/yarn-4.14-support.patch +++ b/pkgs/by-name/li/linkwarden/yarn-fix.patch @@ -15,6 +15,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10c0 diff --git a/pkgs/by-name/li/linthesia/package.nix b/pkgs/by-name/li/linthesia/package.nix index 013366e8ff40..96a05b8ebefe 100644 --- a/pkgs/by-name/li/linthesia/package.nix +++ b/pkgs/by-name/li/linthesia/package.nix @@ -5,7 +5,7 @@ SDL2_ttf, alsa-lib, fetchFromGitHub, - glibmm, + glibmm_2_4, gtk3, libGL, libGLU, @@ -44,7 +44,7 @@ stdenv.mkDerivation (finalAttrs: { libGL libGLU alsa-lib - glibmm + glibmm_2_4 sqlite SDL2 SDL2_ttf diff --git a/pkgs/by-name/li/liquidwar/package.nix b/pkgs/by-name/li/liquidwar/package.nix index 8da0022a3421..35761a6e8d8d 100644 --- a/pkgs/by-name/li/liquidwar/package.nix +++ b/pkgs/by-name/li/liquidwar/package.nix @@ -96,6 +96,8 @@ stdenv.mkDerivation (finalAttrs: { "-Wno-error=address" "-Wno-error=use-after-free" "-std=gnu17" + # Fix build w/ glibc-2.44 + "-Wno-error=discarded-qualifiers" ] ++ [ "-Wno-error=deprecated-declarations" diff --git a/pkgs/by-name/li/livegrep/package.nix b/pkgs/by-name/li/livegrep/package.nix index f2b8d4a47463..3fc784850bae 100644 --- a/pkgs/by-name/li/livegrep/package.nix +++ b/pkgs/by-name/li/livegrep/package.nix @@ -94,7 +94,10 @@ buildBazelPackage { "file://${registry}" ]; - env = lib.optionalAttrs stdenv.hostPlatform.isDarwin { + env = { + NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + } + // lib.optionalAttrs stdenv.hostPlatform.isDarwin { LIBTOOL = "${cctools}/bin/libtool"; }; diff --git a/pkgs/by-name/ln/lndir/package.nix b/pkgs/by-name/ln/lndir/package.nix index 0e052be89858..08246fda6bb7 100644 --- a/pkgs/by-name/ln/lndir/package.nix +++ b/pkgs/by-name/ln/lndir/package.nix @@ -7,11 +7,11 @@ }: stdenv.mkDerivation (finalAttrs: { pname = "lndir"; - version = "1.0.5"; + version = "1.0.6"; src = fetchurl { url = "mirror://xorg/individual/util/lndir-${finalAttrs.version}.tar.xz"; - hash = "sha256-O2VXelV1zOCVZk9UkhZKlpQYAP5ikKEjcx1H8+cQTds="; + hash = "sha256-GPbWZOUolLfe4NL8mxceDlhWblCR5E+VNfEObZQZEqQ="; }; strictDeps = true; diff --git a/pkgs/by-name/lo/losslesscut/package.nix b/pkgs/by-name/lo/losslesscut/package.nix index 3aba1df4368f..de14db04ca23 100644 --- a/pkgs/by-name/lo/losslesscut/package.nix +++ b/pkgs/by-name/lo/losslesscut/package.nix @@ -1,6 +1,7 @@ { lib, fetchFromGitHub, + substitute, stdenv, yarn-berry_4, nodejs_24, @@ -25,13 +26,28 @@ stdenv.mkDerivation (finalAttrs: { owner = "mifi"; repo = "lossless-cut"; tag = "v${finalAttrs.version}"; - hash = "sha256-LNh9F2aKxVegZTAPuEAqo2f78ynGMgnpwnDXEP1u2+M="; + hash = "sha256-E0Ds2Wpo+JUSfd+hBY7QdJM1cUlWgNWW4zEiB0rdh6w="; + + # Remove after upstream updates to Yarn 4.15 + # https://github.com/mifi/lossless-cut/blob/master/package.json#L492 + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry.lockfileVersion + ]; + }) + } + ''; }; patches = [ # fixes a few things that try to guess whether it's a dev build ./undev.patch - ./yarn-4.14-support.patch ./disable-update-check.patch # LosslessCut will retrieve a URL from mifi.no (the author's domain) and directly embed the HTML in the app. # This was previously used to show a Ukraine flag, which I don't have strong opinions on. @@ -121,8 +137,8 @@ stdenv.mkDerivation (finalAttrs: { missingHashes = ./missing-hashes.json; offlineCache = yarn-berry.fetchYarnBerryDeps { - inherit (finalAttrs) src missingHashes patches; - hash = "sha256-o0u9dAoo0sTEV+kjQg8TjRNAIcx8fqfk79HsDwAXriA="; + inherit (finalAttrs) src missingHashes; + hash = "sha256-81pebHUkVLEAe01a5olTP9zzQkTCrGMWUvNTYBsW+Bk="; }; postConfigure = '' diff --git a/pkgs/by-name/lo/losslesscut/yarn-4.14-support.patch b/pkgs/by-name/lo/losslesscut/yarn-fix.patch similarity index 84% rename from pkgs/by-name/lo/losslesscut/yarn-4.14-support.patch rename to pkgs/by-name/lo/losslesscut/yarn-fix.patch index d673b914d875..82a6782e429c 100644 --- a/pkgs/by-name/lo/losslesscut/yarn-4.14-support.patch +++ b/pkgs/by-name/lo/losslesscut/yarn-fix.patch @@ -7,7 +7,7 @@ index 1e4550e7..6a2e770c 100644 __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10 "7zip-bin@npm:~5.2.0": diff --git a/pkgs/by-name/lo/loudmouth/package.nix b/pkgs/by-name/lo/loudmouth/package.nix index 91155e474d41..a64d6e61f16a 100644 --- a/pkgs/by-name/lo/loudmouth/package.nix +++ b/pkgs/by-name/lo/loudmouth/package.nix @@ -20,7 +20,10 @@ stdenv.mkDerivation (finalAttrs: { configureFlags = [ "--with-ssl=openssl" ]; - env.NIX_CFLAGS_COMPILE = "-Wno-error=deprecated-declarations"; + env.NIX_CFLAGS_COMPILE = toString [ + "-Wno-error=deprecated-declarations" + "-Wno-error=discarded-qualifiers" + ]; propagatedBuildInputs = [ openssl diff --git a/pkgs/by-name/lu/luit/package.nix b/pkgs/by-name/lu/luit/package.nix index 86cc09527242..765a34ecf46f 100644 --- a/pkgs/by-name/lu/luit/package.nix +++ b/pkgs/by-name/lu/luit/package.nix @@ -31,6 +31,8 @@ stdenv.mkDerivation (finalAttrs: { update-source-version luit "$version" ''; + __structuredAttrs = true; + meta = { description = "Filter between an arbitrary application and a UTF-8 terminal emulator converting the output and input between the locale's encoding and UTF-8"; homepage = "https://invisible-island.net/luit/"; diff --git a/pkgs/by-name/ma/makeBinaryWrapper/make-binary-wrapper.sh b/pkgs/by-name/ma/makeBinaryWrapper/make-binary-wrapper.sh index 595574468ffa..2001f448264c 100644 --- a/pkgs/by-name/ma/makeBinaryWrapper/make-binary-wrapper.sh +++ b/pkgs/by-name/ma/makeBinaryWrapper/make-binary-wrapper.sh @@ -263,6 +263,7 @@ setEnvPrefix() { val=$(escapeStringLiteral "$3") printf '%s' "set_env_prefix(\"$env\", \"$sep\", \"$val\");" assertValidEnvName "$1" + assertNoEmptySegment "--prefix" "$1" "$2" "$3" } # suffix ENV SEP VAL @@ -273,6 +274,7 @@ setEnvSuffix() { val=$(escapeStringLiteral "$3") printf '%s' "set_env_suffix(\"$env\", \"$sep\", \"$val\");" assertValidEnvName "$1" + assertNoEmptySegment "--suffix" "$1" "$2" "$3" } # setEnv KEY VALUE @@ -325,6 +327,20 @@ assertValidEnvName() { esac } +assertNoEmptySegment() { + local flag="$1" env="$2" sep="$3" val="$4" + [ -n "$sep" ] || return 0 + case "$env" in + # In Lua the loader will substitute the default paths or just ignore the empty segment + # https://github.com/lua/lua/blob/v5.5.1/loadlib.c#L274 + # https://github.com/lua/lua/blob/v5.5.1/loadlib.c#L475 + LUA_PATH|LUA_CPATH|LUA_PATH_*|LUA_CPATH_*) return 0 ;; + esac + if [[ "$sep$val$sep" == *"$sep$sep"* ]]; then + printf '\n%s\n' "#error $flag $env would introduce an empty PATH-like segment (empty, or a leading/trailing/doubled \`$sep\`). This is interpreted as \"search the current directory\" by shells, execvp() and the dynamic linker, see https://github.com/NixOS/nixpkgs/security/advisories/GHSA-p7v3-pr2c-8584. Guard the value with e.g. lib.optionalString (list != [])." + fi +} + setSepSurroundCheck() { printf '%s' "\ int is_surrounded_by_sep(char *env, char *ptr, unsigned long len, char *sep) { diff --git a/pkgs/by-name/ma/mamba/package.nix b/pkgs/by-name/ma/mamba/package.nix index d12b7cb7f624..ff9a30389ce6 100644 --- a/pkgs/by-name/ma/mamba/package.nix +++ b/pkgs/by-name/ma/mamba/package.nix @@ -10,7 +10,7 @@ libjack2, alsa-lib, liblo, - libsigcxx, + libsigcxx_2_0, libsmf, }: @@ -37,7 +37,7 @@ stdenv.mkDerivation (finalAttrs: { libjack2 alsa-lib liblo - libsigcxx + libsigcxx_2_0 libsmf ]; diff --git a/pkgs/by-name/ma/mask/package.nix b/pkgs/by-name/ma/mask/package.nix index 6cd1458177c1..f3c9c26e77b9 100644 --- a/pkgs/by-name/ma/mask/package.nix +++ b/pkgs/by-name/ma/mask/package.nix @@ -12,6 +12,7 @@ php, python3, ruby, + swift, }: rustPlatform.buildRustPackage (finalAttrs: { @@ -37,11 +38,7 @@ rustPlatform.buildRustPackage (finalAttrs: { php python3 ruby - ]; - - checkFlags = [ - # requires swift which currently fails to build - "--skip=swift" + swift ]; nativeInstallCheckInputs = [ versionCheckHook ]; diff --git a/pkgs/by-name/ma/mastodon/yarn-4.14-support.patch b/pkgs/by-name/ma/mastodon/yarn-4.14-support.patch deleted file mode 100644 index 017f2d295ca9..000000000000 --- a/pkgs/by-name/ma/mastodon/yarn-4.14-support.patch +++ /dev/null @@ -1,21 +0,0 @@ -diff --git a/.yarnrc.yml b/.yarnrc.yml ---- a/.yarnrc.yml -+++ b/.yarnrc.yml -@@ -1 +1,6 @@ - nodeLinker: node-modules -+ -+approvedGitRepositories: -+ - "**" -+ -+enableScripts: true -diff --git a/yarn.lock b/yarn.lock ---- a/yarn.lock -+++ b/yarn.lock -@@ -2,6 +2,6 @@ - # Manual changes might be lost - proceed with caution! - - __metadata: -- version: 8 -+ version: 9 - cacheKey: 10c0 - diff --git a/pkgs/by-name/me/memcached/package.nix b/pkgs/by-name/me/memcached/package.nix index 8da9b0b5c383..f9350f9874d3 100644 --- a/pkgs/by-name/me/memcached/package.nix +++ b/pkgs/by-name/me/memcached/package.nix @@ -8,12 +8,12 @@ }: stdenv.mkDerivation (finalAttrs: { - version = "1.6.42"; + version = "1.6.45"; pname = "memcached"; src = fetchurl { url = "https://memcached.org/files/memcached-${finalAttrs.version}.tar.gz"; - sha256 = "sha256-UPCLh51PnTbeqdkF6eqt4Vxwjjjbfppz/CHci0U5Xec="; + sha256 = "sha256-02LGTm2NUocVNQHqv3yFtKdhQy+/U/XXsIXQuxZTwd0="; }; configureFlags = [ diff --git a/pkgs/by-name/me/merve/package.nix b/pkgs/by-name/me/merve/package.nix index 066ac8fd351d..08a38426257f 100644 --- a/pkgs/by-name/me/merve/package.nix +++ b/pkgs/by-name/me/merve/package.nix @@ -15,6 +15,14 @@ stdenv.mkDerivation (finalAttrs: { pname = "merve"; version = "1.2.2"; + __structuredAttrs = true; + strictDeps = true; + + outputs = [ + "out" + "dev" + ]; + src = fetchFromGitHub { owner = "nodejs"; repo = "merve"; diff --git a/pkgs/by-name/me/meson/004-gir-fallback-path.patch b/pkgs/by-name/me/meson/004-gir-fallback-path.patch index e6d740265277..f158bdce4872 100644 --- a/pkgs/by-name/me/meson/004-gir-fallback-path.patch +++ b/pkgs/by-name/me/meson/004-gir-fallback-path.patch @@ -1,9 +1,9 @@ diff --git a/mesonbuild/modules/gnome.py b/mesonbuild/modules/gnome.py -index 1c6952df7..9466a0b7d 100644 +index 7be632517b..683818b64c 100644 --- a/mesonbuild/modules/gnome.py +++ b/mesonbuild/modules/gnome.py -@@ -923,6 +923,16 @@ class GnomeModule(ExtensionModule): - if fatal_warnings: +@@ -1264,6 +1264,16 @@ + if kwargs['fatal_warnings']: scan_command.append('--warn-error') + if len(set(girtarget.get_custom_install_dir()[0] for girtarget in girtargets if girtarget.get_custom_install_dir())) > 1: @@ -16,6 +16,6 @@ index 1c6952df7..9466a0b7d 100644 + if fallback_libpath is not None and isinstance(fallback_libpath, str) and len(fallback_libpath) > 0 and fallback_libpath[0] == "/": + scan_command += ['--fallback-library-path=' + fallback_libpath] + - generated_files = [f for f in libsources if isinstance(f, (GeneratedList, CustomTarget, CustomTargetIndex))] - - scan_target = self._make_gir_target(state, girfile, scan_command, generated_files, depends, kwargs) + generated_files: list[build.GeneratedTypes] = [] + depend_files: list[mesonlib.File] = [] + for f in libsources: diff --git a/pkgs/by-name/me/meson/package.nix b/pkgs/by-name/me/meson/package.nix index edd39a451200..f472a97583b4 100644 --- a/pkgs/by-name/me/meson/package.nix +++ b/pkgs/by-name/me/meson/package.nix @@ -10,20 +10,22 @@ pkg-config, python3, replaceVars, + writableTmpDirAsHomeHook, writeShellScriptBin, zlib, }: -python3.pkgs.buildPythonApplication rec { +python3.pkgs.buildPythonApplication (finalAttrs: { pname = "meson"; - version = "1.10.2"; - format = "setuptools"; + version = "1.12.1"; + pyproject = true; + __structuredAttrs = true; src = fetchFromGitHub { owner = "mesonbuild"; repo = "meson"; - tag = version; - hash = "sha256-3Zeavn6aW6920gM7yE73Ms1RPCP2GjX9IUL9YGmISfY="; + tag = finalAttrs.version; + hash = "sha256-cQphgkEWNpjjs7DuV5+6KGDhsmQ4x09cH+FU0lfoB0Y="; }; patches = [ @@ -85,11 +87,20 @@ python3.pkgs.buildPythonApplication rec { else null; + build-system = [ python3.pkgs.setuptools ]; + nativeBuildInputs = [ installShellFiles ]; + optional-dependencies = { + ninja = [ python3.pkgs.ninja ]; + progress = [ python3.pkgs.tqdm ]; + typing = [ python3.pkgs.mypy ]; + }; + nativeCheckInputs = [ ninja pkg-config + writableTmpDirAsHomeHook ] ++ lib.optionals python3.isPyPy [ # Several tests hardcode python3. @@ -114,7 +125,9 @@ python3.pkgs.buildPythonApplication rec { substituteInPlace \ 'test cases/native/8 external program shebang parsing/script.int.in' \ 'test cases/common/274 customtarget exe for test/generate.py' \ - --replace /usr/bin/env ${coreutils}/bin/env + --replace-fail /usr/bin/env ${lib.getExe' coreutils "env"} + substituteInPlace run_project_tests.py \ + --replace-fail "multiprocessing.cpu_count()" "int(os.environ['NIX_BUILD_CORES'])" '' ] # Remove problematic tests @@ -129,6 +142,11 @@ python3.pkgs.buildPythonApplication rec { "test cases/linuxlike/14 static dynamic linkage" # Nixpkgs cctools does not have bitcode support. "test cases/osx/7 bitcode" + # This test tries to compile with flags `-D_FORTIFY_SOURCE=2 -U_FORTIFY_SOURCE -O0`. + # It fails because cc-wrapper adds `-U_FORTIFY_SOURCE -D_FORTIFY_SOURCE=3` + # after the provided args (to ensure that fortify cannot be disabled without + # being allowed by the package definition) + "test cases/common/282 -D_FORTIFY_SOURCE=2 and -O0" ] ++ lib.optionals stdenv.hostPlatform.isDarwin [ # requires llvmPackages.openmp, creating cyclic dependency @@ -146,16 +164,15 @@ python3.pkgs.buildPythonApplication rec { ] )) ++ [ - ''HOME="$TMPDIR" ${ - if python3.isPyPy then python3.interpreter else "python" - } ./run_project_tests.py'' + "${if python3.isPyPy then python3.interpreter else "python"} ./run_project_tests.py" "runHook postCheck" ] ); postInstall = '' - installShellCompletion --zsh data/shell-completions/zsh/_meson - installShellCompletion --bash data/shell-completions/bash/meson + installShellCompletion \ + --bash data/shell-completions/bash/meson \ + --zsh data/shell-completions/zsh/_meson ''; postFixup = '' @@ -170,7 +187,7 @@ python3.pkgs.buildPythonApplication rec { rm $out/nix-support/propagated-build-inputs substituteInPlace "$out/share/bash-completion/completions/meson" \ - --replace "python3 -c " "${python3.interpreter} -c " + --replace-fail "python3 -c " "${python3.interpreter} -c " ''; setupHook = ./setup-hook.sh; @@ -193,5 +210,5 @@ python3.pkgs.buildPythonApplication rec { maintainers = with lib.maintainers; [ qyliss ]; inherit (python3.meta) platforms; }; -} +}) # TODO: a more Nixpkgs-tailoired test suite diff --git a/pkgs/by-name/mi/mimalloc/package.nix b/pkgs/by-name/mi/mimalloc/package.nix index 810596fdfe03..5bedb5faa044 100644 --- a/pkgs/by-name/mi/mimalloc/package.nix +++ b/pkgs/by-name/mi/mimalloc/package.nix @@ -12,13 +12,13 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "mimalloc"; - version = "3.4.5"; + version = "3.5.3"; src = fetchFromGitHub { owner = "microsoft"; repo = "mimalloc"; tag = "v${finalAttrs.version}"; - hash = "sha256-vNVZw2YsDkf0GcdFTNb/fXMQLQYvoc8P425LupPShpo="; + hash = "sha256-GmLMWdUR2/VXJY7A8dZtwoV9FJIx0sxj8KWI4kG8IrU="; }; doCheck = !stdenv.hostPlatform.isStatic; diff --git a/pkgs/by-name/mi/mimic/package.nix b/pkgs/by-name/mi/mimic/package.nix index 931460357fb8..5b158b89ee77 100644 --- a/pkgs/by-name/mi/mimic/package.nix +++ b/pkgs/by-name/mi/mimic/package.nix @@ -55,6 +55,8 @@ stdenv.mkDerivation (finalAttrs: { env.NIX_CFLAGS_COMPILE = toString [ # Needed with GCC 12 "-Wno-error=free-nonheap-object" + # Fix build w/ glibc-2.44 + "-Wno-error=discarded-qualifiers" ]; postInstall = '' diff --git a/pkgs/by-name/mi/mitscheme/package.nix b/pkgs/by-name/mi/mitscheme/package.nix index 8f311d6c15ce..b0be6a25077b 100644 --- a/pkgs/by-name/mi/mitscheme/package.nix +++ b/pkgs/by-name/mi/mitscheme/package.nix @@ -44,6 +44,11 @@ stdenv.mkDerivation { sha256 = "035f92vni0vqmgj9hq2i7vwasz7crx52wll4823vhfkm1qdv5ywc"; }; + postPatch = '' + substituteInPlace "src/microcode/chacha.i" \ + --replace-fail "#define _POSIX_C_SOURCE 200809L" "" + ''; + patches = [ (fetchDebianPatch { pname = "mit-scheme"; diff --git a/pkgs/by-name/mo/modemmanager/package.nix b/pkgs/by-name/mo/modemmanager/package.nix index a7a73ee2c50f..a0bfff3f6468 100644 --- a/pkgs/by-name/mo/modemmanager/package.nix +++ b/pkgs/by-name/mo/modemmanager/package.nix @@ -26,8 +26,8 @@ && stdenv.hostPlatform.emulatorAvailable buildPackages, polkit, withPolkit ? lib.meta.availableOn stdenv.hostPlatform polkit, - systemd, - withSystemd ? lib.meta.availableOn stdenv.hostPlatform systemd, + systemdLibs, + withSystemd ? lib.meta.availableOn stdenv.hostPlatform systemdLibs, }: stdenv.mkDerivation rec { @@ -79,7 +79,7 @@ stdenv.mkDerivation rec { polkit ] ++ lib.optionals withSystemd [ - systemd + systemdLibs ]; nativeInstallCheckInputs = [ diff --git a/pkgs/by-name/mp/mpv-unwrapped/package.nix b/pkgs/by-name/mp/mpv-unwrapped/package.nix index 90755a6f6392..51eeefb9a040 100644 --- a/pkgs/by-name/mp/mpv-unwrapped/package.nix +++ b/pkgs/by-name/mp/mpv-unwrapped/package.nix @@ -128,12 +128,6 @@ stdenv.mkDerivation (finalAttrs: { '' ]; - # Ensure we reference 'lib' (not 'out') of Swift. - # TODO: Remove this once the Swift wrapper doesn’t include these. - preConfigure = lib.optionalString stdenv.hostPlatform.isDarwin '' - export SWIFT_LIB_DYNAMIC="${lib.getLib swift.swift}/lib/swift/macosx" - ''; - mesonFlags = [ (lib.mesonOption "default_library" "shared") (lib.mesonOption "sysconfdir" "/etc") @@ -225,13 +219,6 @@ stdenv.mkDerivation (finalAttrs: { ++ lib.optionals zimgSupport [ zimg ] ++ lib.optionals stdenv.hostPlatform.isLinux [ nv-codec-headers-11 ]; - # https://github.com/mpv-player/mpv/issues/15591#issuecomment-2764797522 - # In file included from ../player/clipboard/clipboard-mac.m:19: - # ./osdep/mac/swift.h:270:9: fatal error: '.../app_bridge_objc-1.pch' file not found - env = lib.optionalAttrs (stdenv.hostPlatform.isDarwin) { - NIX_SWIFTFLAGS_COMPILE = "-disable-bridging-pch"; - }; - postBuild = lib.optionalString stdenv.hostPlatform.isDarwin '' pushd .. # Must be run from the source dir because it uses relative paths python3 TOOLS/osxbundle.py -s build/mpv diff --git a/pkgs/by-name/nb/nbytes/package.nix b/pkgs/by-name/nb/nbytes/package.nix index b886e53522f1..145012080436 100644 --- a/pkgs/by-name/nb/nbytes/package.nix +++ b/pkgs/by-name/nb/nbytes/package.nix @@ -13,6 +13,9 @@ stdenv.mkDerivation (finalAttrs: { pname = "nbytes"; version = "0.1.4"; + __structuredAttrs = true; + strictDeps = true; + src = fetchFromGitHub { owner = "nodejs"; repo = "nbytes"; @@ -20,6 +23,11 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-etCRWjak7tKL6dKlQR7SD6HXx/mn/8gnR4l+CAjoQgA="; }; + outputs = [ + "out" + "dev" + ]; + nativeBuildInputs = [ cmake validatePkgConfig diff --git a/pkgs/by-name/ne/networkmanager/package.nix b/pkgs/by-name/ne/networkmanager/package.nix index 985bb417f410..fab591ddad65 100644 --- a/pkgs/by-name/ne/networkmanager/package.nix +++ b/pkgs/by-name/ne/networkmanager/package.nix @@ -37,9 +37,9 @@ polkit, readline, slang, - systemd, + systemdMinimal, udev, - withSystemd ? lib.meta.availableOn stdenv.hostPlatform systemd, + withSystemd ? lib.meta.availableOn stdenv.hostPlatform systemdMinimal, # external deps bluez5, @@ -222,7 +222,7 @@ stdenv.mkDerivation (finalAttrs: { ppp readline slang - (if withSystemd then systemd else udev) + (if withSystemd then systemdMinimal else udev) ] ++ lib.optionals withNbft [ libnvme @@ -246,7 +246,7 @@ stdenv.mkDerivation (finalAttrs: { '' + lib.optionalString withSystemd '' substituteInPlace data/NetworkManager.service.in \ - --replace-fail /usr/bin/busctl ${lib.getExe' systemd "busctl"} + --replace-fail /usr/bin/busctl ${lib.getExe' systemdMinimal "busctl"} ''; preBuild = '' diff --git a/pkgs/by-name/ng/nghttp3/package.nix b/pkgs/by-name/ng/nghttp3/package.nix index 94cbf454b4d2..d23b6d781fca 100644 --- a/pkgs/by-name/ng/nghttp3/package.nix +++ b/pkgs/by-name/ng/nghttp3/package.nix @@ -8,11 +8,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "nghttp3"; - version = "1.16.0"; + version = "1.17.0"; src = fetchurl { url = "https://github.com/ngtcp2/nghttp3/releases/download/v${finalAttrs.version}/nghttp3-${finalAttrs.version}.tar.bz2"; - hash = "sha256-IsBpidVL0mbUpx817vGS1JuJBlWfFqQfO4gssCNhdGM="; + hash = "sha256-KobUa0Kx37XGLk/sO/5ugO5JVxXhiAqEaFdyiBDJgm0="; }; outputs = [ diff --git a/pkgs/by-name/ng/ngn-k/package.nix b/pkgs/by-name/ng/ngn-k/package.nix deleted file mode 100644 index 92ab2e867624..000000000000 --- a/pkgs/by-name/ng/ngn-k/package.nix +++ /dev/null @@ -1,64 +0,0 @@ -{ - lib, - stdenv, - fetchFromCodeberg, - runtimeShell, -}: - -stdenv.mkDerivation { - pname = "ngn-k"; - version = "0-unstable-2025-11-17"; - - src = fetchFromCodeberg { - owner = "ngn"; - repo = "k"; - rev = "717063f24921d5aff405a39cf7643efedb5bb365"; - hash = "sha256-rUMi+VetQc139PjbFJXlSkmYEuK5wtM6LpQ/f1tcB1s="; - }; - - patches = [ - ./repl-license-path.patch - ./repl-argv-1.patch - ]; - - postPatch = '' - # don't use hardcoded /bin/sh - for f in repl.k m.c;do - substituteInPlace "$f" --replace-fail "/bin/sh" "${runtimeShell}" - done - ''; - - makeFlags = [ "-e" ]; - buildFlags = [ - "k" - "libk.so" - ]; - checkTarget = "t"; - doCheck = true; - - outputs = [ - "out" - "dev" - "lib" - ]; - - # TODO(@sternenseemann): package bulgarian translation - installPhase = '' - runHook preInstall - install -Dm755 k "$out/bin/k" - install -Dm755 repl.k "$out/bin/k-repl" - install -Dm755 libk.so "$lib/lib/libk.so" - install -Dm644 k.h "$dev/include/k.h" - install -Dm644 LICENSE -t "$out/share/ngn-k" - substituteInPlace "$out/bin/k-repl" --replace-fail "#!k" "#!$out/bin/k" - runHook postInstall - ''; - - meta = { - description = "Simple fast vector programming language"; - homepage = "https://codeberg.org/ngn/k"; - license = lib.licenses.agpl3Only; - maintainers = [ lib.maintainers.sternenseemann ]; - platforms = lib.platforms.linux ++ lib.platforms.freebsd; - }; -} diff --git a/pkgs/by-name/ng/ngn-k/repl-argv-1.patch b/pkgs/by-name/ng/ngn-k/repl-argv-1.patch deleted file mode 100644 index 0e54a0845e4a..000000000000 --- a/pkgs/by-name/ng/ngn-k/repl-argv-1.patch +++ /dev/null @@ -1,13 +0,0 @@ -diff --git a/repl.k b/repl.k -index dc89832c..33780850 100755 ---- a/repl.k -+++ b/repl.k -@@ -28,7 +28,7 @@ joinpath:{$[x~,".";y;"/"~*|x;x,y;x,"/",y]} - line0:{c:{0x07~*-2#*x}{(l;r):x;(1:1;r,,(-2_l))}/(x;());"\n"/(*|c),,*c} - line1:{$[#x;;:0];x:-1_x;$[(3>#x)&("\\"=*x)&~^(!cmds)?x 1;cmds[x 1]x 1;.[`1:(fmt;fmtx)[" "~*x]@.:;,x;{`0:`err[]}]];`1:prompt;1} - line:line1@line0@ --$["repl.k"~basename`argv 1;{cmds::@[cmds;x[1]1;:;{y;`0:x}2_x]}'{(&x~\:80#"-")_x:(1+*&x~\:,"/")_-1_x}@0:`argv 1;]; -+$["k-repl"~basename`argv 1;{cmds::@[cmds;x[1]1;:;{y;`0:x}2_x]}'{(&x~\:80#"-")_x:(1+*&x~\:,"/")_-1_x}@0:`argv 1;]; - run:{`1:banner,prompt;{line@1:`}::/`;} - \d . - diff --git a/pkgs/by-name/ng/ngn-k/repl-license-path.patch b/pkgs/by-name/ng/ngn-k/repl-license-path.patch deleted file mode 100644 index d3cd8c781b6b..000000000000 --- a/pkgs/by-name/ng/ngn-k/repl-license-path.patch +++ /dev/null @@ -1,13 +0,0 @@ -diff --git a/repl.k b/repl.k -index dc89832c..7a6e0dcf 100755 ---- a/repl.k -+++ b/repl.k -@@ -21,7 +21,7 @@ tbl:{[w;u;x]h:`k'!x;d:`k''.x;W:(#'h)|/'#''d - r,par'dd[w-2]'sem/'+@[W;&~^`i`d?_@'.x;-:]$'d} - cell:{$[|/`i`d=@y;-x;x]$z} - par:{opn,x,cls} --cmds:(,"a")!{`1:1:joinpath[dirname`argv 0]"LICENSE";} -+cmds:(,"a")!{`1:1:joinpath[dirname`argv 0]"../share/ngn-k/LICENSE";} - basename:{*|"/"\x} - dirname:{$[#x:"/"/-1_"/"\x;x;,"."]} - joinpath:{$[x~,".";y;"/"~*|x;x,y;x,"/",y]} diff --git a/pkgs/by-name/no/non/package.nix b/pkgs/by-name/no/non/package.nix index aad1eee48a15..9fa7a40848d5 100644 --- a/pkgs/by-name/no/non/package.nix +++ b/pkgs/by-name/no/non/package.nix @@ -11,7 +11,7 @@ libsndfile, ladspa-header, liblo, - libsigcxx, + libsigcxx_2_0, lrdf, waf, }: @@ -44,7 +44,7 @@ stdenv.mkDerivation { libsndfile ladspa-header liblo - libsigcxx + libsigcxx_2_0 lrdf ]; diff --git a/pkgs/by-name/nt/ntp/package.nix b/pkgs/by-name/nt/ntp/package.nix index e36dad33bf80..a5ec68840827 100644 --- a/pkgs/by-name/nt/ntp/package.nix +++ b/pkgs/by-name/nt/ntp/package.nix @@ -7,6 +7,7 @@ perl, pps-tools, libcap, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -18,6 +19,14 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-z4TF8/saKVKElCYk2CP/+mNBROCWz8T5lprJjvX0aOU="; }; + patches = [ + # Fix build w/ glibc-2.44 + (fetchpatch { + url = "https://gitlab.archlinux.org/archlinux/packaging/packages/ntp/-/raw/8513bf75be3c0425318475e30f5725a03d8fb067/ntp-4.2.8.p18-glib-2.43.patch"; + hash = "sha256-20ztNAnirijKt8rgaMz6FGoHubBOskNL5ynXte3NTvM="; + }) + ]; + # fix for gcc-14 compile failure postPatch = '' substituteInPlace sntp/m4/openldap-thread-check.m4 \ diff --git a/pkgs/by-name/nz/nzbget/package.nix b/pkgs/by-name/nz/nzbget/package.nix index bd8a64cc1cf3..5e13e2fd94b2 100644 --- a/pkgs/by-name/nz/nzbget/package.nix +++ b/pkgs/by-name/nz/nzbget/package.nix @@ -9,7 +9,7 @@ libgcrypt, libpar2, libcap, - libsigcxx, + libsigcxx_2_0, libxml2, ncurses, openssl, @@ -59,7 +59,7 @@ stdenv.mkDerivation (finalAttrs: { libgcrypt libpar2 libcap - libsigcxx + libsigcxx_2_0 libxml2 ncurses openssl diff --git a/pkgs/by-name/oc/ocf-resource-agents/package.nix b/pkgs/by-name/oc/ocf-resource-agents/package.nix index 0807b266aafb..f86d1bb1e9d5 100644 --- a/pkgs/by-name/oc/ocf-resource-agents/package.nix +++ b/pkgs/by-name/oc/ocf-resource-agents/package.nix @@ -63,6 +63,9 @@ let # Needed with GCC 12 but breaks on darwin (with clang) or older gcc "-Wno-error=maybe-uninitialized" ] + ++ [ + "-Wno-error=discarded-qualifiers" + ] ); meta = { diff --git a/pkgs/by-name/od/odhcp6c/package.nix b/pkgs/by-name/od/odhcp6c/package.nix index 2ddedb629ebb..a149d7597435 100644 --- a/pkgs/by-name/od/odhcp6c/package.nix +++ b/pkgs/by-name/od/odhcp6c/package.nix @@ -18,6 +18,9 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-IDBbVWs017JcrApJ3s8fjEQghWCwrK1d+E6Wp5eHNX4="; }; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + nativeBuildInputs = [ cmake ]; buildInputs = [ libubox ]; diff --git a/pkgs/by-name/od/odp-dpdk/package.nix b/pkgs/by-name/od/odp-dpdk/package.nix index 76b5a869b4e4..c11143fa6c1f 100644 --- a/pkgs/by-name/od/odp-dpdk/package.nix +++ b/pkgs/by-name/od/odp-dpdk/package.nix @@ -34,6 +34,9 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-L6lF8VaycAz7PcFArAgLhI8+sc0jnAHY3gum/uDIYz4="; }; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + nativeBuildInputs = [ autoreconfHook pkg-config diff --git a/pkgs/by-name/od/odyssey/package.nix b/pkgs/by-name/od/odyssey/package.nix index f776d973e23f..69cfacd289d9 100644 --- a/pkgs/by-name/od/odyssey/package.nix +++ b/pkgs/by-name/od/odyssey/package.nix @@ -25,6 +25,12 @@ stdenv.mkDerivation (finalAttrs: { url = "https://github.com/yandex/odyssey/commit/51c0e777aa45157f4f03fbd036113ce6d11ca41f.patch?full_index=1"; hash = "sha256-yytyA2K62v7XwJQ+WJnBGh87AVyeOv0cuzlQ7oYnhFg="; }) + + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/yandex/odyssey/commit/1edf6bfd05dc34324162fda1b4ca4bc38b1b581c.patch"; + hash = "sha256-Rd/dqmvpY2gJMqg3hX5rXMu3vRjOG5V3QXV/S1M625Q="; + }) ]; nativeBuildInputs = [ cmake ]; diff --git a/pkgs/by-name/on/onetbb/fix-hwloc-nullptr-deref.patch b/pkgs/by-name/on/onetbb/fix-hwloc-nullptr-deref.patch new file mode 100644 index 000000000000..65b69293e155 --- /dev/null +++ b/pkgs/by-name/on/onetbb/fix-hwloc-nullptr-deref.patch @@ -0,0 +1,15 @@ +diff --git a/src/tbbbind/tbb_bind.cpp b/src/tbbbind/tbb_bind.cpp +index 26fa6747..2adccea5 100644 +--- a/src/tbbbind/tbb_bind.cpp ++++ b/src/tbbbind/tbb_bind.cpp +@@ -268,7 +268,9 @@ private: + // this function calls the interface that is available in the HWLOC 2.5 only. + #if HWLOC_API_VERSION >= 0x20500 + auto some_core = hwloc_get_next_obj_by_type(topology, HWLOC_OBJ_CORE, nullptr); +- hwloc_get_obj_with_same_locality(topology, some_core, HWLOC_OBJ_CORE, nullptr, nullptr, 0); ++ if (some_core) { ++ hwloc_get_obj_with_same_locality(topology, some_core, HWLOC_OBJ_CORE, nullptr, nullptr, 0); ++ } + #endif + } + diff --git a/pkgs/by-name/on/onetbb/package.nix b/pkgs/by-name/on/onetbb/package.nix index 3ab06b8bc1f7..bf9ed333195e 100644 --- a/pkgs/by-name/on/onetbb/package.nix +++ b/pkgs/by-name/on/onetbb/package.nix @@ -44,6 +44,9 @@ stdenv.mkDerivation (finalAttrs: { # # ./fix-libtbbmalloc-dlopen.patch + + # + ./fix-hwloc-nullptr-deref.patch ]; nativeBuildInputs = [ diff --git a/pkgs/by-name/op/open-vm-tools/package.nix b/pkgs/by-name/op/open-vm-tools/package.nix index 5835333ae557..06e87eeeb82c 100644 --- a/pkgs/by-name/op/open-vm-tools/package.nix +++ b/pkgs/by-name/op/open-vm-tools/package.nix @@ -150,6 +150,9 @@ stdenv.mkDerivation (finalAttrs: { substituteInPlace udev/99-vmware-scsi-udev.rules \ --replace-fail "/bin/sh" "${bash}/bin/sh" + + substituteInPlace lib/rpcChannel/glib_stubs.c \ + --replace-fail "void g_free(void *p) { free(p); }" "" ''; configureFlags = [ diff --git a/pkgs/by-name/op/openexr/package.nix b/pkgs/by-name/op/openexr/package.nix index 1b39a5c662ca..4b6c998e710f 100644 --- a/pkgs/by-name/op/openexr/package.nix +++ b/pkgs/by-name/op/openexr/package.nix @@ -14,13 +14,13 @@ stdenv.mkDerivation rec { pname = "openexr"; - version = "3.4.15"; + version = "3.5.0"; src = fetchFromGitHub { owner = "AcademySoftwareFoundation"; repo = "openexr"; rev = "v${version}"; - hash = "sha256-Z2o2ooDqAof5rnR5lX3RfWnklyD/c98HuwWF6uZA+78="; + hash = "sha256-9gzGQPJIn3AaVp/4lNEcFWrxuersHimwrab6HjB7KfI="; }; outputs = [ diff --git a/pkgs/by-name/op/openmpi/package.nix b/pkgs/by-name/op/openmpi/package.nix index 66f58919896c..b99dd9da3008 100644 --- a/pkgs/by-name/op/openmpi/package.nix +++ b/pkgs/by-name/op/openmpi/package.nix @@ -45,11 +45,11 @@ assert cudaSupport -> !rocmSupport; stdenv.mkDerivation (finalAttrs: { pname = "openmpi"; - version = "5.0.10"; + version = "5.0.11"; src = fetchurl { url = "https://www.open-mpi.org/software/ompi/v${lib.versions.majorMinor finalAttrs.version}/downloads/openmpi-${finalAttrs.version}.tar.bz2"; - sha256 = "sha256-Cs7MT8IY5d69vLikHRgsaw8dKTkwFe12OyqR1dc3TMY="; + sha256 = "sha256-5mijxKzVDEHcIEyKbdmKYR4PJq+Jz2d1d/qb6KJpgAM="; }; postPatch = '' diff --git a/pkgs/by-name/op/openvas-scanner/package.nix b/pkgs/by-name/op/openvas-scanner/package.nix index 8868ea132e0d..72637f8f05f4 100644 --- a/pkgs/by-name/op/openvas-scanner/package.nix +++ b/pkgs/by-name/op/openvas-scanner/package.nix @@ -40,6 +40,9 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-ggmex/BmAVgdE1JNM3kybEmr/uKqrIl8JdSoBnsg+40="; }; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + nativeBuildInputs = [ cmake git diff --git a/pkgs/by-name/op/openvino/package.nix b/pkgs/by-name/op/openvino/package.nix index 8946009c1340..65acf6a9453e 100644 --- a/pkgs/by-name/op/openvino/package.nix +++ b/pkgs/by-name/op/openvino/package.nix @@ -94,6 +94,17 @@ stdenv.mkDerivation (finalAttrs: { ./cmake-install-paths.patch ]; + # Fix arm computelib ar/ranlib toolchain paths for LTO awareness + postPatch = '' + substituteInPlace src/plugins/intel_cpu/thirdparty/ComputeLibrary/SConstruct \ + --replace-fail \ + "env['AR'] = toolchain_prefix + \"ar\"" \ + "env['AR'] = \"${lib.getExe' stdenv.cc.cc "gcc-ar"}\"" \ + --replace-fail \ + "env['RANLIB'] = toolchain_prefix + \"ranlib\"" \ + "env['RANLIB'] = \"${lib.getExe' stdenv.cc.cc "gcc-ranlib"}\"" + ''; + dontUseSconsCheck = true; dontUseSconsBuild = true; dontUseSconsInstall = true; @@ -127,7 +138,7 @@ stdenv.mkDerivation (finalAttrs: { (cmakeBool "ENABLE_SAMPLES" false) # features - (cmakeBool "ENABLE_INTEL_CPU" stdenv.hostPlatform.isx86_64) + (cmakeBool "ENABLE_INTEL_CPU" true) (cmakeBool "ENABLE_INTEL_GPU" true) (cmakeBool "ENABLE_INTEL_NPU" stdenv.hostPlatform.isx86_64) (cmakeBool "ENABLE_JS" false) diff --git a/pkgs/by-name/or/orbuculum/package.nix b/pkgs/by-name/or/orbuculum/package.nix index 80ce39a2c83f..055a5051937e 100644 --- a/pkgs/by-name/or/orbuculum/package.nix +++ b/pkgs/by-name/or/orbuculum/package.nix @@ -39,6 +39,9 @@ stdenv.mkDerivation (finalAttrs: { popd ''; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + nativeBuildInputs = [ meson ninja diff --git a/pkgs/by-name/or/orc/package.nix b/pkgs/by-name/or/orc/package.nix index 4373c742ec9c..65ce5974e3c4 100644 --- a/pkgs/by-name/or/orc/package.nix +++ b/pkgs/by-name/or/orc/package.nix @@ -1,13 +1,13 @@ { lib, stdenv, - fetchurl, + testers, + nix-update-script, + fetchFromGitLab, meson, ninja, - # FIXME: hotdoc errors out due to issues discovering libclang paths - # See https://github.com/NixOS/nixpkgs/issues/514723 hotdoc, - buildDevDoc ? false, + buildDevDoc ? true, # for passthru.tests gnuradio, @@ -18,7 +18,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "orc"; - version = "0.4.42"; + version = "0.4.44"; outputs = [ "out" @@ -26,10 +26,14 @@ stdenv.mkDerivation (finalAttrs: { ] ++ lib.optional buildDevDoc "devdoc"; outputBin = "dev"; # compilation tools + outputDoc = lib.optionalString buildDevDoc "devdoc"; - src = fetchurl { - url = "https://gstreamer.freedesktop.org/src/orc/orc-${finalAttrs.version}.tar.xz"; - hash = "sha256-fskSq1mvPMl4dMRWpWqK4e7FIMOF7ER+ihArK9EiyQw="; + src = fetchFromGitLab { + domain = "gitlab.freedesktop.org"; + owner = "gstreamer"; + repo = "orc"; + tag = finalAttrs.version; + hash = "sha256-/fWXR9LuINXwVMXCAGVm4H6I+Lut1u43rz+xmV+5cVs="; }; postPatch = lib.optionalString (stdenv.hostPlatform.isDarwin && stdenv.hostPlatform.isx86_64) '' @@ -37,12 +41,13 @@ stdenv.mkDerivation (finalAttrs: { sed -i '/memcpy_speed/d' testsuite/meson.build ''; - mesonFlags = [ - (lib.mesonEnable "examples" false) - (lib.mesonEnable "benchmarks" false) - (lib.mesonEnable "tests" finalAttrs.finalPackage.doCheck) - (lib.mesonEnable "hotdoc" buildDevDoc) - ]; + mesonFlags = lib.mapAttrsToList lib.mesonEnable { + examples = false; + benchmarks = false; + tests = finalAttrs.finalPackage.doCheck; + hotdoc = buildDevDoc; + tools = true; + }; nativeBuildInputs = [ meson @@ -61,22 +66,32 @@ stdenv.mkDerivation (finalAttrs: { && lib.versionAtLeast stdenv.cc.version "12" ); - passthru.tests = { - inherit (gst_all_1) gst-plugins-good gst-plugins-bad gst-plugins-ugly; - inherit gnuradio vips; - qt6-qtmultimedia = qt6.qtmultimedia; + passthru = { + tests = { + inherit (gst_all_1) gst-plugins-good gst-plugins-bad gst-plugins-ugly; + inherit gnuradio vips; + qt6-qtmultimedia = qt6.qtmultimedia; + pkg-config = testers.testMetaPkgConfig finalAttrs.finalPackage; + }; + + updateScript = nix-update-script { }; }; meta = { description = "Oil Runtime Compiler"; homepage = "https://gstreamer.freedesktop.org/projects/orc.html"; changelog = "https://gitlab.freedesktop.org/gstreamer/orc/-/blob/${finalAttrs.version}/RELEASE"; + pkgConfigModules = map (name: "${name}-${lib.versions.majorMinor finalAttrs.version}") [ + "orc" + "orc-test" + ]; # The source code implementing the Marsenne Twister algorithm is licensed # under the 3-clause BSD license. The rest is 2-clause BSD license. license = with lib.licenses; [ bsd3 bsd2 ]; + identifiers.cpeParts = lib.meta.cpeFullVersionWithVendor "gstreamer" finalAttrs.version; platforms = lib.platforms.unix; maintainers = with lib.maintainers; [ tmarkus ]; }; diff --git a/pkgs/by-name/or/orcania/package.nix b/pkgs/by-name/or/orcania/package.nix index e034e574341f..be2bc176a70b 100644 --- a/pkgs/by-name/or/orcania/package.nix +++ b/pkgs/by-name/or/orcania/package.nix @@ -5,6 +5,7 @@ cmake, check, subunit, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { pname = "orcania"; @@ -17,6 +18,18 @@ stdenv.mkDerivation (finalAttrs: { sha256 = "sha256-Cz3IE5UrfoWjMxQ/+iR1bLsYxf5DVN+7aJqLBcPjduA="; }; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/babelouest/orcania/commit/ee2f45b5da8b7fb2c747419c17880ccdca14521d.patch"; + hash = "sha256-BNGL2Q5STrrAO8/OKMS4S5GqlikGnvg4hgBwKTMulgU="; + }) + (fetchpatch { + url = "https://github.com/babelouest/orcania/commit/f261393b4dd1b4f50aca389916407e0dfa5f2e55.patch"; + hash = "sha256-KyRedPj5gBFPZmefmjLL49OY8eJNmMyd5jsFsQByTUE="; + }) + ]; + nativeBuildInputs = [ cmake ]; nativeCheckInputs = [ diff --git a/pkgs/by-name/ou/outline/package.nix b/pkgs/by-name/ou/outline/package.nix index d34c69959652..35dfc405e2b8 100644 --- a/pkgs/by-name/ou/outline/package.nix +++ b/pkgs/by-name/ou/outline/package.nix @@ -2,6 +2,7 @@ stdenv, lib, fetchFromGitHub, + substitute, makeWrapper, nodejs, nixosTests, @@ -16,14 +17,24 @@ stdenv.mkDerivation (finalAttrs: { owner = "outline"; repo = "outline"; rev = "v${finalAttrs.version}"; - hash = "sha256-IKkk9jerGkSEJXl5DU/Lel/7BUjmW4VFLCfC6zIxWhk="; - }; + hash = "sha256-msFMfjNkpXaJisbTpJMQowyD0KZ5zfvSgTutEeLp9Vk="; - patches = [ - # Remove after upstream updates to Yarn 4.14 - # https://github.com/outline/outline/blob/main/package.json#L398 - ./yarn-4.14-support.patch - ]; + # Remove after upstream updates to Yarn 4.15 + # https://github.com/outline/outline/blob/main/package.json#L393 + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry_4.lockfileVersion + ]; + }) + } + ''; + }; missingHashes = ./missing-hashes.json; @@ -34,8 +45,8 @@ stdenv.mkDerivation (finalAttrs: { ]; offlineCache = yarn-berry_4.fetchYarnBerryDeps { - inherit (finalAttrs) src missingHashes patches; - hash = "sha256-QRdoS5fpbr9eYFAYgoH2s8Lsu8FYppNrKcAFBhWrbV0="; + inherit (finalAttrs) src missingHashes; + hash = "sha256-bEsnu4NL/Dgv6yPXXvV/4uMvQ7Sc9eDfeAD2fhFCB98="; }; buildPhase = '' diff --git a/pkgs/by-name/ou/outline/yarn-4.14-support.patch b/pkgs/by-name/ou/outline/yarn-4.14-support.patch deleted file mode 100644 index fb43b14db1a5..000000000000 --- a/pkgs/by-name/ou/outline/yarn-4.14-support.patch +++ /dev/null @@ -1,13 +0,0 @@ -diff --git i/yarn.lock w/yarn.lock -index 5cd3bbfbc..b9401d3fd 100644 ---- i/yarn.lock -+++ w/yarn.lock -@@ -2,7 +2,7 @@ - # Manual changes might be lost - proceed with caution! - - __metadata: -- version: 8 -+ version: 9 - cacheKey: 10c0 - - "@antfu/install-pkg@npm:^1.1.0": diff --git a/pkgs/by-name/ou/outline/yarn-fix.patch b/pkgs/by-name/ou/outline/yarn-fix.patch new file mode 100644 index 000000000000..8cf711edfe98 --- /dev/null +++ b/pkgs/by-name/ou/outline/yarn-fix.patch @@ -0,0 +1,19 @@ +--- a/.yarnrc.yml ++++ b/.yarnrc.yml +@@ -12,3 +12,6 @@ npmPreapprovedPackages: + npmAuditIgnoreAdvisories: + - "1113517" # GHSA-mw96-cpmx-2vgc rollup <2.80.0 path traversal (workbox-build, build-time) + - "1113686" # GHSA-5c6j-r48x-rmvq serialize-javascript RCE (@rollup/plugin-terser, build-time) ++ ++approvedGitRepositories: ++ - "**" +--- a/yarn.lock ++++ b/yarn.lock +@@ -2,6 +2,6 @@ + # Manual changes might be lost - proceed with caution! + + __metadata: +- version: 8 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER + cacheKey: 10c0 + diff --git a/pkgs/by-name/pa/pacemaker/package.nix b/pkgs/by-name/pa/pacemaker/package.nix index 7d670749fe05..ff6d8fc48a7b 100644 --- a/pkgs/by-name/pa/pacemaker/package.nix +++ b/pkgs/by-name/pa/pacemaker/package.nix @@ -111,6 +111,9 @@ stdenv.mkDerivation (finalAttrs: { "-Wno-error=strict-prototypes" "-Wno-error=deprecated-declarations" ] + ++ [ + "-Wno-error=discarded-qualifiers" + ] ); enableParallelBuilding = true; diff --git a/pkgs/by-name/pa/pahole/package.nix b/pkgs/by-name/pa/pahole/package.nix index ad58df1572a6..27a388203532 100644 --- a/pkgs/by-name/pa/pahole/package.nix +++ b/pkgs/by-name/pa/pahole/package.nix @@ -14,10 +14,10 @@ stdenv.mkDerivation (finalAttrs: { pname = "pahole"; - version = "1.31"; + version = "1.32"; src = fetchzip { url = "https://git.kernel.org/pub/scm/devel/pahole/pahole.git/snapshot/pahole-${finalAttrs.version}.tar.gz"; - hash = "sha256-Afy0SysuDbTOa8H3m4hexy12Rmuv2NZL2wHfO4JtKL0="; + hash = "sha256-+vydbVzkM+VUROo3Zo+XJeJMkvwtwEIS/4GgxmqvAZE="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/pa/pam-watchid/package.nix b/pkgs/by-name/pa/pam-watchid/package.nix index cd2da4fbd546..3a18b3574641 100644 --- a/pkgs/by-name/pa/pam-watchid/package.nix +++ b/pkgs/by-name/pa/pam-watchid/package.nix @@ -1,12 +1,12 @@ { lib, - swiftPackages, swift, swiftpm, fetchFromGitHub, + stdenv, }: -swiftPackages.stdenv.mkDerivation { +stdenv.mkDerivation { pname = "pam-watchid"; version = "2-unstable-2024-12-24"; diff --git a/pkgs/by-name/pa/pangomm_2_48/1.4.nix b/pkgs/by-name/pa/pangomm_2_48/1.4.nix index 650e26b4a1cb..439628e2ffa9 100644 --- a/pkgs/by-name/pa/pangomm_2_48/1.4.nix +++ b/pkgs/by-name/pa/pangomm_2_48/1.4.nix @@ -7,7 +7,7 @@ ninja, python3, pango, - glibmm, + glibmm_2_4, cairomm_1_0, gnome, }: @@ -37,7 +37,7 @@ stdenv.mkDerivation rec { ]; propagatedBuildInputs = [ pango - glibmm + glibmm_2_4 cairomm_1_0 ]; diff --git a/pkgs/by-name/pa/papi/package.nix b/pkgs/by-name/pa/papi/package.nix index 96c0ee99f1ab..164a7b46104a 100644 --- a/pkgs/by-name/pa/papi/package.nix +++ b/pkgs/by-name/pa/papi/package.nix @@ -13,6 +13,9 @@ stdenv.mkDerivation (finalAttrs: { sha256 = "sha256-qb/4nM85kV1yngiuCgxqcc4Ou+mEEemi6zyDyNsK85w="; }; + # Fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + setSourceRoot = '' sourceRoot=$(echo */src) ''; diff --git a/pkgs/by-name/pa/paprefs/package.nix b/pkgs/by-name/pa/paprefs/package.nix index 386212a8a820..2ba90eacc1c5 100644 --- a/pkgs/by-name/pa/paprefs/package.nix +++ b/pkgs/by-name/pa/paprefs/package.nix @@ -7,7 +7,7 @@ gettext, pkg-config, pulseaudioFull, - glibmm, + glibmm_2_4, gtkmm3, wrapGAppsHook3, }: @@ -31,7 +31,7 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ pulseaudioFull - glibmm + glibmm_2_4 gtkmm3 ]; diff --git a/pkgs/by-name/pa/pavucontrol/package.nix b/pkgs/by-name/pa/pavucontrol/package.nix index d2daf3b76af5..52c92d887482 100644 --- a/pkgs/by-name/pa/pavucontrol/package.nix +++ b/pkgs/by-name/pa/pavucontrol/package.nix @@ -6,7 +6,7 @@ intltool, libpulseaudio, gtkmm4, - libsigcxx, + libsigcxx_2_0, # Since version 6.1, libcanberra is optional withLibcanberra ? true, libcanberra-gtk3, @@ -32,7 +32,7 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ libpulseaudio gtkmm4 - libsigcxx + libsigcxx_2_0 (lib.optionals withLibcanberra libcanberra-gtk3) json-glib adwaita-icon-theme diff --git a/pkgs/by-name/pe/peacock/package.nix b/pkgs/by-name/pe/peacock/package.nix index 144c875e3b16..7710b07f003b 100644 --- a/pkgs/by-name/pe/peacock/package.nix +++ b/pkgs/by-name/pe/peacock/package.nix @@ -1,6 +1,7 @@ { lib, fetchFromGitHub, + substitute, stdenv, nodejs, yarn-berry_4, @@ -19,14 +20,24 @@ stdenv.mkDerivation (finalAttrs: { owner = "thepeacockproject"; repo = "Peacock"; tag = "v${finalAttrs.version}"; - hash = "sha256-uVK9ABA5JoDU9Cmtjo2ZqIRwMvhZdDgdmkIpily/wk8="; - }; + hash = "sha256-8Z2UXz/4ecQruy20RykgSXBm3JjMqZH6KVBVCXRzAI4="; - patches = [ - # Remove after upstream updates to Yarn 4.14 - # https://github.com/thepeacockproject/Peacock/blob/master/package.json#L109 - ./yarn-4.14-support.patch - ]; + # Remove after upstream updates to Yarn 4.15 + # https://github.com/thepeacockproject/Peacock/blob/master/package.json#L107 + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry.lockfileVersion + ]; + }) + } + ''; + }; nativeBuildInputs = [ nodejs @@ -81,8 +92,8 @@ stdenv.mkDerivation (finalAttrs: { missingHashes = ./missing-hashes.json; offlineCache = yarn-berry.fetchYarnBerryDeps { - inherit (finalAttrs) src missingHashes patches; - hash = "sha256-9u/w/zy4f51uPFfkzf0fDZlsj8GFXAfw7RGR9owo5n8="; + inherit (finalAttrs) src missingHashes; + hash = "sha256-O1F/OaVipYyJOIIeNcOEghxTjGYNg8Ba0KMQMnW09EQ="; }; meta = { diff --git a/pkgs/by-name/pe/peacock/yarn-4.14-support.patch b/pkgs/by-name/pe/peacock/yarn-fix.patch similarity index 81% rename from pkgs/by-name/pe/peacock/yarn-4.14-support.patch rename to pkgs/by-name/pe/peacock/yarn-fix.patch index eb94dd5a821e..2d02497c0102 100644 --- a/pkgs/by-name/pe/peacock/yarn-4.14-support.patch +++ b/pkgs/by-name/pe/peacock/yarn-fix.patch @@ -1,5 +1,4 @@ diff --git a/yarn.lock b/yarn.lock -index 286ec90499..ee9a3a9fd3 100644 --- a/yarn.lock +++ b/yarn.lock @@ -2,7 +2,7 @@ @@ -7,7 +6,7 @@ index 286ec90499..ee9a3a9fd3 100644 __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10 "@aashutoshrathi/word-wrap@npm:^1.2.3": diff --git a/pkgs/by-name/pe/performous/package.nix b/pkgs/by-name/pe/performous/package.nix index 71fc1b56f3bd..7593a83693a7 100644 --- a/pkgs/by-name/pe/performous/package.nix +++ b/pkgs/by-name/pe/performous/package.nix @@ -11,7 +11,7 @@ fmt, gettext, glew, - glibmm, + glibmm_2_4, glm, icu, libepoxy, @@ -95,7 +95,7 @@ stdenv.mkDerivation rec { ffmpeg fmt glew - glibmm + glibmm_2_4 glm icu libepoxy diff --git a/pkgs/by-name/pe/pesign/package.nix b/pkgs/by-name/pe/pesign/package.nix index 7fd597e164a8..989062b68f41 100644 --- a/pkgs/by-name/pe/pesign/package.nix +++ b/pkgs/by-name/pe/pesign/package.nix @@ -30,6 +30,12 @@ stdenv.mkDerivation (finalAttrs: { url = "https://github.com/rhboot/pesign/commit/1f9e2fa0b4d872fdd01ca3ba81b04dfb1211a187.patch?full_index=1"; hash = "sha256-viVM4Z0jAEAWC3EdJVHcWe21aQskH5XE85lOd6Xd/qU="; }) + + # fix build w/ glibc-2.44 + (fetchpatch2 { + url = "https://github.com/rhboot/pesign/commit/419d63a8b6434f94b57730bb8a58a32a0bb199aa.patch?full_index=1"; + hash = "sha256-/o0QknZ1IDFwmsQAt1IENx7tr8WRNJS3wl84cHzprzA="; + }) ]; # nss-util is missing because it is already contained in nss diff --git a/pkgs/by-name/pg/pgadmin4/package.nix b/pkgs/by-name/pg/pgadmin4/package.nix index 5c15cf400ab3..9a6676d096d4 100644 --- a/pkgs/by-name/pg/pgadmin4/package.nix +++ b/pkgs/by-name/pg/pgadmin4/package.nix @@ -2,6 +2,7 @@ lib, python3, fetchFromGitHub, + substitute, zlib, nixosTests, postgresqlTestHook, @@ -9,24 +10,36 @@ yarn-berry_4, nodejs, stdenv, - pkgsBuildHost, server-mode ? true, }: let pname = "pgadmin"; version = "9.14"; - yarnHash = "sha256-mJa5L8N40JWogQ8/LllSdX/uJHMzKULCow9+e5gFe/A="; + yarnHash = "sha256-uixmtWC588JD6DfM9INeh6LV5L2S9lc+GFNW62FVm+4="; src = fetchFromGitHub { owner = "pgadmin-org"; repo = "pgadmin4"; rev = "REL-${lib.versions.major version}_${lib.versions.minor version}"; - hash = "sha256-NQe1ZN8jQEJE5qSpL5MjgLwWLGrGXCIHaCd8zLpsx3s="; - }; + hash = "sha256-ZUJEwTRKG23ztLKAp+hDHKeKxPc6VmC8gnJe4x85R44="; - # Remove after https://github.com/pgadmin-org/pgadmin4/commit/79e490c5fa6031af7baa83f04f751bdc790dc408 is released - yarnPatch = ./yarn-4.14-support.patch; + # Remove when updating since upstream has updated Yarn + # https://github.com/pgadmin-org/pgadmin4/commit/aad2dfd7251f769ce73dd1bc3e17c76831a019ed#diff-b861012a5dd72b8a9f3281b7cf09f5a779c98569d040b1bbc1db50f1b15e7cceR183 + postFetch = '' + cd $out/web + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry_4.lockfileVersion + ]; + }) + } + ''; + }; # keep the scope, as it is used throughout the derivation and tests # this also makes potential future overrides easier @@ -53,7 +66,6 @@ pythonPackages.buildPythonApplication rec { inherit missingHashes; src = src + "/web"; hash = yarnHash; - patches = [ yarnPatch ]; }; # from Dockerfile @@ -115,8 +127,6 @@ pythonPackages.buildPythonApplication rec { echo Building the web frontend... cd web ( - PATH=$PATH:${lib.makeBinPath [ pkgsBuildHost.git ]} - git apply ${yarnPatch} export LD=$CC # https://github.com/imagemin/optipng-bin/issues/108 yarnBerryConfigHook ) diff --git a/pkgs/by-name/pg/pgadmin4/yarn-4.14-support.patch b/pkgs/by-name/pg/pgadmin4/yarn-fix.patch similarity index 90% rename from pkgs/by-name/pg/pgadmin4/yarn-4.14-support.patch rename to pkgs/by-name/pg/pgadmin4/yarn-fix.patch index 62b859642205..e689ae3dd496 100644 --- a/pkgs/by-name/pg/pgadmin4/yarn-4.14-support.patch +++ b/pkgs/by-name/pg/pgadmin4/yarn-fix.patch @@ -20,6 +20,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10c0 diff --git a/pkgs/by-name/pi/picolibc/package.nix b/pkgs/by-name/pi/picolibc/package.nix index 0bffb8ddd2e9..d9bf1a174531 100644 --- a/pkgs/by-name/pi/picolibc/package.nix +++ b/pkgs/by-name/pi/picolibc/package.nix @@ -1,5 +1,6 @@ { stdenvNoLibc, + fetchpatch, buildPackages, fetchFromGitHub, lib, @@ -34,6 +35,14 @@ stdenvNoLibc.mkDerivation (finalAttrs: { hash = "sha256-FhTNgffsnHbzIXOOwCMe6O1FGkEtqWfw+e30RW+Y4K4="; }; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/picolibc/picolibc/commit/11a46b6ed03c4dca64e0534435da9841e837b160.patch"; + hash = "sha256-i1dKW1L5si0gf0/Sn4sU/BuIof778tvHgCCCY1TxMME="; + }) + ]; + depsBuildBuild = lib.optionals canExecute [ buildPackages.stdenv.cc ]; diff --git a/pkgs/by-name/pi/pingus/package.nix b/pkgs/by-name/pi/pingus/package.nix index f1795ee2a9aa..daa41c7aa6f0 100644 --- a/pkgs/by-name/pi/pingus/package.nix +++ b/pkgs/by-name/pi/pingus/package.nix @@ -12,7 +12,7 @@ fmt, gtest, libpng, - libsigcxx, + libsigcxx_2_0, argpp, geomcpp, logmich, @@ -50,7 +50,7 @@ stdenv.mkDerivation { fmt gtest libpng - libsigcxx + libsigcxx_2_0 argpp geomcpp logmich diff --git a/pkgs/by-name/pi/pioneer/package.nix b/pkgs/by-name/pi/pioneer/package.nix index 94aeaa7816d9..0d7f1304f0ab 100644 --- a/pkgs/by-name/pi/pioneer/package.nix +++ b/pkgs/by-name/pi/pioneer/package.nix @@ -11,7 +11,7 @@ libGL, libGLU, libpng, - libsigcxx, + libsigcxx_2_0, libvorbis, libx11, lua5_2, @@ -44,7 +44,7 @@ stdenv.mkDerivation (finalAttrs: { libGL libGLU libpng - libsigcxx + libsigcxx_2_0 libvorbis libx11 lua5_2 diff --git a/pkgs/by-name/pi/pipewire/package.nix b/pkgs/by-name/pi/pipewire/package.nix index 981c7f867324..b1161e3c2642 100644 --- a/pkgs/by-name/pi/pipewire/package.nix +++ b/pkgs/by-name/pi/pipewire/package.nix @@ -88,7 +88,7 @@ in stdenv.mkDerivation (finalAttrs: { pname = "pipewire"; - version = "1.6.8"; + version = "1.6.9"; outputs = [ "out" @@ -104,7 +104,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "pipewire"; repo = "pipewire"; tag = finalAttrs.version; - hash = "sha256-sxS6+LtvpEWCKoKLDUSYkW4+rrcIXPjWPBglReIDh/k="; + hash = "sha256-YmICqzAHRuLoGuZ5UwvfLotOr04/usEPsRIKZXF4SLI="; }; patches = [ diff --git a/pkgs/by-name/po/powermode-indicator/package.nix b/pkgs/by-name/po/powermode-indicator/package.nix index e0da8dc9e444..d1dc193e9a6a 100644 --- a/pkgs/by-name/po/powermode-indicator/package.nix +++ b/pkgs/by-name/po/powermode-indicator/package.nix @@ -5,7 +5,7 @@ cmake, pkg-config, gtkmm3, - glibmm, + glibmm_2_4, libappindicator, }: stdenv.mkDerivation { @@ -26,7 +26,7 @@ stdenv.mkDerivation { buildInputs = [ libappindicator gtkmm3 - glibmm + glibmm_2_4 ]; meta = { diff --git a/pkgs/by-name/pp/ppp/package.nix b/pkgs/by-name/pp/ppp/package.nix index 547c7ee8f7dd..da17ab2a17e8 100644 --- a/pkgs/by-name/pp/ppp/package.nix +++ b/pkgs/by-name/pp/ppp/package.nix @@ -11,8 +11,8 @@ openssl, pkg-config, stdenv, - withSystemd ? lib.meta.availableOn stdenv.hostPlatform systemdMinimal, - systemdMinimal, + withSystemd ? lib.meta.availableOn stdenv.hostPlatform systemdLibs, + systemdLibs, }: stdenv.mkDerivation (finalAttrs: { @@ -55,7 +55,7 @@ stdenv.mkDerivation (finalAttrs: { openssl ] ++ lib.optionals withSystemd [ - systemdMinimal + systemdLibs ]; postPatch = '' diff --git a/pkgs/by-name/pr/protoc-gen-swift/package.nix b/pkgs/by-name/pr/protoc-gen-swift/package.nix index 1c6b5dea7215..39a5dc46f8a3 100644 --- a/pkgs/by-name/pr/protoc-gen-swift/package.nix +++ b/pkgs/by-name/pr/protoc-gen-swift/package.nix @@ -1,14 +1,12 @@ { lib, fetchFromGitHub, - swiftPackages, swift, swiftpm, nix-update-script, + stdenv, }: -let - stdenv = swiftPackages.stdenv; -in + stdenv.mkDerivation (finalAttrs: { pname = "protoc-gen-swift"; version = "1.34.1"; @@ -17,7 +15,8 @@ stdenv.mkDerivation (finalAttrs: { owner = "apple"; repo = "swift-protobuf"; rev = "${finalAttrs.version}"; - hash = "sha256-DnnDT4egw00tvy84PuyvSKINjVwueg7QRSQrwD81qbg="; + hash = "sha256-Kit/kQDNs0ohtaNC0xWxG6o0vNGUWWE++YK1JP2o8OM="; + fetchSubmodules = true; }; nativeBuildInputs = [ @@ -25,19 +24,6 @@ stdenv.mkDerivation (finalAttrs: { swiftpm ]; - # Not needed for darwin, as `apple-sdk` is implicit and part of the stdenv - buildInputs = lib.optionals stdenv.hostPlatform.isLinux [ - swiftPackages.Foundation - swiftPackages.Dispatch - ]; - - env = lib.optionalAttrs stdenv.hostPlatform.isLinux { - # swiftpm fails to found libdispatch.so on Linux - LD_LIBRARY_PATH = lib.makeLibraryPath [ - swiftPackages.Dispatch - ]; - }; - installPhase = '' runHook preInstall install -Dm755 .build/release/protoc-gen-swift $out/bin/protoc-gen-swift diff --git a/pkgs/by-name/pr/proton-authenticator/package.nix b/pkgs/by-name/pr/proton-authenticator/package.nix index 3762981974df..88b69429af53 100644 --- a/pkgs/by-name/pr/proton-authenticator/package.nix +++ b/pkgs/by-name/pr/proton-authenticator/package.nix @@ -74,7 +74,7 @@ rustPlatform.buildRustPackage (finalAttrs: { offlineCache = yarn-berry.fetchYarnBerryDeps { inherit (finalAttrs) src missingHashes yarnLock; - hash = "sha256-FiDuAwEj/AIH/lJRLyuNPvthcoynsFGcUYZyx7DMnFA="; + hash = "sha256-YNW6Hqk3WU0IRCbDQpNOTiIHT9T5zBMhNm5GxX1WqrM="; }; postUnpack = '' diff --git a/pkgs/by-name/pr/proton-authenticator/yarn.lock b/pkgs/by-name/pr/proton-authenticator/yarn.lock index e6f025b3dd50..5ce742161099 100644 --- a/pkgs/by-name/pr/proton-authenticator/yarn.lock +++ b/pkgs/by-name/pr/proton-authenticator/yarn.lock @@ -2,7 +2,7 @@ # Manual changes might be lost - proceed with caution! __metadata: - version: 9 + version: 10 cacheKey: 10 "@adobe/css-tools@npm:^4.4.0": diff --git a/pkgs/by-name/ps/pspp/fix-glibc-2.42.patch b/pkgs/by-name/ps/pspp/fix-glibc-2.42.patch new file mode 100644 index 000000000000..8bf84cc53a94 --- /dev/null +++ b/pkgs/by-name/ps/pspp/fix-glibc-2.42.patch @@ -0,0 +1,29 @@ +diff --git a/gl/stdlib.in.h b/gl/stdlib.in.h +index bef0aaa..b2e19c3 100644 +--- a/gl/stdlib.in.h ++++ b/gl/stdlib.in.h +@@ -223,7 +223,7 @@ _GL_INLINE_HEADER_BEGIN + + + /* Declarations for ISO C N3322. */ +-#if defined __GNUC__ && __GNUC__ >= 15 && !defined __clang__ ++#if defined __GNUC__ && __GNUC__ >= 15 && !defined __clang__ && !defined(bsearch) + _GL_EXTERN_C void *bsearch (const void *__key, + const void *__base, size_t __nmemb, size_t __size, + int (*__compare) (const void *, const void *)) +diff --git a/gl/wchar.in.h b/gl/wchar.in.h +index ab602a2..a2aa597 100644 +--- a/gl/wchar.in.h ++++ b/gl/wchar.in.h +@@ -301,9 +301,11 @@ _GL_EXTERN_C int wcsncmp (const wchar_t *__s1, const wchar_t *__s2, size_t __n) + _GL_ATTRIBUTE_NONNULL_IF_NONZERO (1, 3) + _GL_ATTRIBUTE_NONNULL_IF_NONZERO (2, 3); + # ifndef __cplusplus ++# if !defined(wmemchr) + _GL_EXTERN_C wchar_t *wmemchr (const wchar_t *__s, wchar_t __wc, size_t __n) + _GL_ATTRIBUTE_NONNULL_IF_NONZERO (1, 3); + # endif ++# endif + _GL_EXTERN_C wchar_t *wmemset (wchar_t *__s, wchar_t __wc, size_t __n) + # if __GLIBC__ + (__GLIBC_MINOR__ >= 2) > 2 + _GL_ATTRIBUTE_NOTHROW diff --git a/pkgs/by-name/ps/pspp/package.nix b/pkgs/by-name/ps/pspp/package.nix index 7585269dc3d5..0cfad65068fd 100644 --- a/pkgs/by-name/ps/pspp/package.nix +++ b/pkgs/by-name/ps/pspp/package.nix @@ -55,10 +55,17 @@ stdenv.mkDerivation rec { iconv ]; + patches = [ + ./fix-glibc-2.42.patch + ]; + env = { C_INCLUDE_PATH = "${libxml2.dev}/include/libxml2/:" + lib.makeSearchPathOutput "dev" "include" buildInputs; LIBRARY_PATH = lib.makeLibraryPath buildInputs; + + # fix build w/ glibc-2.44 + NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; }; doCheck = false; diff --git a/pkgs/by-name/ps/psqlodbc/package.nix b/pkgs/by-name/ps/psqlodbc/package.nix index b38c756eee66..47522cace89a 100644 --- a/pkgs/by-name/ps/psqlodbc/package.nix +++ b/pkgs/by-name/ps/psqlodbc/package.nix @@ -18,13 +18,13 @@ assert lib.xor withLibiodbc withUnixODBC; stdenv.mkDerivation (finalAttrs: { pname = "psqlodbc"; - version = "18.00.0002"; + version = "18.00.0003"; src = fetchFromGitHub { owner = "postgresql-interfaces"; repo = "psqlodbc"; tag = "REL-${lib.replaceString "." "_" finalAttrs.version}"; - hash = "sha256-qzbyo9P/o784Ux3KDA8NDMbcm0EbnfG8LiBLRk6n698="; + hash = "sha256-U3ZipJFvmhIEtaSCsTQw6BrH7QG02HlJnGOVVKMF3lk="; }; buildInputs = [ diff --git a/pkgs/by-name/pu/pulseaudio/package.nix b/pkgs/by-name/pu/pulseaudio/package.nix index d166190cffc6..a25d261b3a88 100644 --- a/pkgs/by-name/pu/pulseaudio/package.nix +++ b/pkgs/by-name/pu/pulseaudio/package.nix @@ -29,7 +29,7 @@ fftwFloat, soxr, speexdsp, - systemd, + systemdLibs, webrtc-audio-processing_1, gst_all_1, check, @@ -43,7 +43,7 @@ x11Support ? false, - useSystemd ? lib.meta.availableOn stdenv.hostPlatform systemd, + useSystemd ? lib.meta.availableOn stdenv.hostPlatform systemdLibs, # Whether to support the JACK sound system as a backend. jackaudioSupport ? false, @@ -150,7 +150,7 @@ stdenv.mkDerivation rec { libxi libxtst ] - ++ lib.optional useSystemd systemd + ++ lib.optional useSystemd systemdLibs ++ lib.optionals stdenv.hostPlatform.isLinux [ alsa-lib udev diff --git a/pkgs/by-name/pu/pulseeffects-legacy/package.nix b/pkgs/by-name/pu/pulseeffects-legacy/package.nix index 2387c2176f17..d69c55e0aed0 100644 --- a/pkgs/by-name/pu/pulseeffects-legacy/package.nix +++ b/pkgs/by-name/pu/pulseeffects-legacy/package.nix @@ -14,7 +14,7 @@ pulseaudio, gtk3, glib, - glibmm, + glibmm_2_4, gtkmm3, lilv, lv2, @@ -71,7 +71,7 @@ stdenv.mkDerivation { buildInputs = [ pulseaudio glib - glibmm + glibmm_2_4 gtk3 gtkmm3 gst_all_1.gstreamer diff --git a/pkgs/by-name/pu/pulseview/package.nix b/pkgs/by-name/pu/pulseview/package.nix index 86c2f3705a08..dfe4833fcac0 100644 --- a/pkgs/by-name/pu/pulseview/package.nix +++ b/pkgs/by-name/pu/pulseview/package.nix @@ -12,7 +12,7 @@ libzip, libftdi1, hidapi, - glibmm, + glibmm_2_4, python3, bluez, libsForQt5, @@ -47,7 +47,7 @@ stdenv.mkDerivation { libzip libftdi1 hidapi - glibmm + glibmm_2_4 python3 libsForQt5.qtsvg ] diff --git a/pkgs/by-name/r2/r2modman/package.nix b/pkgs/by-name/r2/r2modman/package.nix index e059d255f8a6..8a131396e315 100644 --- a/pkgs/by-name/r2/r2modman/package.nix +++ b/pkgs/by-name/r2/r2modman/package.nix @@ -9,6 +9,7 @@ makeWrapper, nodejs, yarn-berry, + substitute, }: stdenv.mkDerivation (finalAttrs: { @@ -19,23 +20,35 @@ stdenv.mkDerivation (finalAttrs: { owner = "ebkr"; repo = "r2modmanPlus"; tag = "v${finalAttrs.version}"; - hash = "sha256-QGs3kF2GkHlISmRb0cIYOKts1b1RvBj5qkc2cUPawwE="; + hash = "sha256-6vSc3Gx0VZJoGSXm70T6rsOLhlv/7CnjK4HWkPOZv2s="; + + # Remove when updating since upstream migrated to pnpm + # https://github.com/ebkr/r2modmanPlus/commit/db41dfdf4e4b9059ce0d574a7fab0d2d344e633a + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry.lockfileVersion + ]; + }) + } + ''; }; missingHashes = ./missing-hashes.json; offlineCache = yarn-berry.fetchYarnBerryDeps { - inherit (finalAttrs) src patches missingHashes; - hash = "sha256-6CwayFhy0ZwdL1ZOZVtCJLlchCv5raX7WF1V4TvVpq4="; + inherit (finalAttrs) src missingHashes; + hash = "sha256-CAtDbWbl9u8tPdPQKxB2qcN7OhDomwO8EqDdRZppgQU="; }; patches = [ # Make it possible to launch Steam games from r2modman. ./steam-launch-fix.patch - # Remove after upstream updates to Yarn 4.14 - # https://github.com/ebkr/r2modmanPlus/blob/develop/package.json#L118 - ./yarn-4.14-support.patch - # Fix copying of wrapper files to game directory ./wrapper-fix.patch ]; diff --git a/pkgs/by-name/r2/r2modman/yarn-4.14-support.patch b/pkgs/by-name/r2/r2modman/yarn-fix.patch similarity index 88% rename from pkgs/by-name/r2/r2modman/yarn-4.14-support.patch rename to pkgs/by-name/r2/r2modman/yarn-fix.patch index 017f2d295ca9..868db25c8d32 100644 --- a/pkgs/by-name/r2/r2modman/yarn-4.14-support.patch +++ b/pkgs/by-name/r2/r2modman/yarn-fix.patch @@ -16,6 +16,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10c0 diff --git a/pkgs/by-name/ra/radiotray-ng/package.nix b/pkgs/by-name/ra/radiotray-ng/package.nix index e1149c3c17c0..130d0637bbd5 100644 --- a/pkgs/by-name/ra/radiotray-ng/package.nix +++ b/pkgs/by-name/ra/radiotray-ng/package.nix @@ -12,7 +12,7 @@ libbsd, # GUI/Desktop dbus, - glibmm, + glibmm_2_4, gsettings-desktop-schemas, hicolor-icon-theme, libappindicator, @@ -71,7 +71,7 @@ stdenv.mkDerivation (finalAttrs: { boost jsoncpp libbsd - glibmm + glibmm_2_4 hicolor-icon-theme gsettings-desktop-schemas libappindicator diff --git a/pkgs/by-name/ra/rawtherapee/package.nix b/pkgs/by-name/ra/rawtherapee/package.nix index 572c6829e525..2e6dae849f91 100644 --- a/pkgs/by-name/ra/rawtherapee/package.nix +++ b/pkgs/by-name/ra/rawtherapee/package.nix @@ -25,7 +25,7 @@ fftwSinglePrec, expat, pcre2, - libsigcxx, + libsigcxx_2_0, lensfun, librsvg, libcanberra-gtk3, @@ -90,7 +90,7 @@ stdenv.mkDerivation (finalAttrs: { fftwSinglePrec expat pcre2 - libsigcxx + libsigcxx_2_0 lensfun librsvg exiv2 diff --git a/pkgs/by-name/rd/rdma-core/package.nix b/pkgs/by-name/rd/rdma-core/package.nix index 81468ad13506..66b93806a812 100644 --- a/pkgs/by-name/rd/rdma-core/package.nix +++ b/pkgs/by-name/rd/rdma-core/package.nix @@ -16,13 +16,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "rdma-core"; - version = "64.0"; + version = "65.0"; src = fetchFromGitHub { owner = "linux-rdma"; repo = "rdma-core"; rev = "v${finalAttrs.version}"; - hash = "sha256-Y0pCGkvCjZ1F9Ojouesozn2Lxj+x7/0ck6/9tJmdkWw="; + hash = "sha256-cAaWVE6/JU8ezjx+XrxNI6Su6VKxb2Jxl29sxU/yepI="; }; __structuredAttrs = true; diff --git a/pkgs/by-name/re/rectangle/package.nix b/pkgs/by-name/re/rectangle/package.nix index 49a2fbc41be4..1f421204969c 100644 --- a/pkgs/by-name/re/rectangle/package.nix +++ b/pkgs/by-name/re/rectangle/package.nix @@ -1,17 +1,16 @@ { lib, - swiftPackages, fetchFromGitHub, darwin, actool, ibtool, makeWrapper, nix-update-script, + swift, + stdenv, }: let - inherit (swiftPackages) stdenv swift; - masShortcutSrc = fetchFromGitHub { owner = "rxhanson"; repo = "MASShortcut"; diff --git a/pkgs/by-name/rh/rhvoice/package.nix b/pkgs/by-name/rh/rhvoice/package.nix index 039d8ea5fa98..eb611a14607a 100644 --- a/pkgs/by-name/rh/rhvoice/package.nix +++ b/pkgs/by-name/rh/rhvoice/package.nix @@ -5,7 +5,7 @@ ensureNewerSourcesForZipFilesHook, pkg-config, scons, - glibmm, + glibmm_2_4, libpulseaudio, libao, speechd-minimal, @@ -40,7 +40,7 @@ stdenv.mkDerivation (finalAttrs: { ]; buildInputs = [ - glibmm + glibmm_2_4 libpulseaudio libao speechd-minimal diff --git a/pkgs/by-name/ro/rocketchat-desktop/package.nix b/pkgs/by-name/ro/rocketchat-desktop/package.nix index 254ce5c2830f..c1ebd06b619c 100644 --- a/pkgs/by-name/ro/rocketchat-desktop/package.nix +++ b/pkgs/by-name/ro/rocketchat-desktop/package.nix @@ -2,6 +2,7 @@ lib, stdenv, fetchFromGitHub, + substitute, yarn-berry_4, nodejs, pkg-config, @@ -27,22 +28,32 @@ stdenv.mkDerivation (finalAttrs: { owner = "RocketChat"; repo = "Rocket.Chat.Electron"; tag = finalAttrs.version; - hash = "sha256-ToAez48+TBcPJUjrh8xYC84HLwbU+rCxGoor5o4gGgo="; - }; + hash = "sha256-Z9yTtlpud3nCMVnyCTd0eYM3G/9UjrPu2sfTVirDR0k="; - patches = [ - # Remove after upstream updates to Yarn 4.14 - # https://github.com/RocketChat/Rocket.Chat.Electron/blob/master/package.json#L182 - ./yarn-4.14-support.patch - ]; + # Remove after upstream updates to Yarn 4.15 + # https://github.com/RocketChat/Rocket.Chat.Electron/blob/master/package.json#L187 + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry.lockfileVersion + ]; + }) + } + ''; + }; # This might need to be updated between releases. # See https://nixos.org/manual/nixpkgs/stable/#javascript-yarnBerry-missing-hashes missingHashes = ./missing-hashes.json; offlineCache = yarn-berry.fetchYarnBerryDeps { - inherit (finalAttrs) src missingHashes patches; - hash = "sha256-7zPiu8kgZbp64ugf229hrjpwZujQHHDLwCxlGRVgH4E="; + inherit (finalAttrs) src missingHashes; + hash = "sha256-VMCLYLuNAZQzfglLS6ncFCLOcmGsuXPR2J+q+Gn/CP4="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/ro/rocketchat-desktop/yarn-4.14-support.patch b/pkgs/by-name/ro/rocketchat-desktop/yarn-fix.patch similarity index 90% rename from pkgs/by-name/ro/rocketchat-desktop/yarn-4.14-support.patch rename to pkgs/by-name/ro/rocketchat-desktop/yarn-fix.patch index 2977561bd557..ac0fc8f2f4dd 100644 --- a/pkgs/by-name/ro/rocketchat-desktop/yarn-4.14-support.patch +++ b/pkgs/by-name/ro/rocketchat-desktop/yarn-fix.patch @@ -18,6 +18,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10 diff --git a/pkgs/by-name/sc/scopehal-apps/package.nix b/pkgs/by-name/sc/scopehal-apps/package.nix index f0d13037e83e..70c48c675e0d 100644 --- a/pkgs/by-name/sc/scopehal-apps/package.nix +++ b/pkgs/by-name/sc/scopehal-apps/package.nix @@ -10,7 +10,7 @@ libpng, libtirpc, liblxi, - libsigcxx, + libsigcxx_2_0, zlib, wrapGAppsHook3, makeBinaryWrapper, @@ -65,7 +65,7 @@ stdenv.mkDerivation { hidapi liblxi libpng - libsigcxx + libsigcxx_2_0 vulkan-headers vulkan-loader yaml-cpp diff --git a/pkgs/by-name/sc/scribus/package.nix b/pkgs/by-name/sc/scribus/package.nix index 54637d7c1332..2746fe4d217a 100644 --- a/pkgs/by-name/sc/scribus/package.nix +++ b/pkgs/by-name/sc/scribus/package.nix @@ -114,6 +114,11 @@ stdenv.mkDerivation (finalAttrs: { url = "https://github.com/scribusproject/scribus/commit/2b9405a00a96a09e0183190ddc9f83d44963d4e0.patch"; hash = "sha256-4v+Ba+JODwNg4YLmwpFeBfIxk1j+RcZdtznPFeQ+H+w="; }) + (fetchpatch { + name = "fix-build-with-poppler-26.07.0.patch"; + url = "https://github.com/scribusproject/scribus/commit/ba246c3a2dd086b4e84517723beab159736ba9ba.patch"; + hash = "sha256-nfJ3eKBhuWC4IO2+IbqNOz0UWTD4UOKtfZXz5ch6NVE="; + }) ]; postPatch = '' diff --git a/pkgs/by-name/se/sentry-cli/package.nix b/pkgs/by-name/se/sentry-cli/package.nix index 52a9b1f73252..04ae9f6a8bb3 100644 --- a/pkgs/by-name/se/sentry-cli/package.nix +++ b/pkgs/by-name/se/sentry-cli/package.nix @@ -37,6 +37,7 @@ rustPlatform.buildRustPackage (finalAttrs: { # By default including `swiftpm` in `nativeBuildInputs` will take over `buildPhase` dontUseSwiftpmBuild = true; dontUseSwiftpmCheck = true; + dontUseSwiftpmInstall = true; __darwinAllowLocalNetworking = true; diff --git a/pkgs/by-name/sh/shared-mime-info/package.nix b/pkgs/by-name/sh/shared-mime-info/package.nix index 51521a613d37..a09f6f40c8d2 100644 --- a/pkgs/by-name/sh/shared-mime-info/package.nix +++ b/pkgs/by-name/sh/shared-mime-info/package.nix @@ -10,10 +10,20 @@ glib, shared-mime-info, }: - +let + # Upstream doesn't pin the version of `xdgmime` in their git repository, + # so it has to be fetched separately. + xdgmime = fetchFromGitLab { + domain = "gitlab.freedesktop.org"; + owner = "xdg"; + repo = "xdgmime"; + rev = "04ce4cd90cb3fa77d5348662de221a6f33b21b17"; + hash = "sha256-0sjH6qG0RYb1kCw4+veTpzv1zJCzoTd2LPa9pqsZrgY="; + }; +in stdenv.mkDerivation (finalAttrs: { pname = "shared-mime-info"; - version = "2.4"; + version = "2.5.1"; outputs = [ "out" @@ -24,10 +34,18 @@ stdenv.mkDerivation (finalAttrs: { domain = "gitlab.freedesktop.org"; owner = "xdg"; repo = "shared-mime-info"; - rev = finalAttrs.version; - hash = "sha256-5eyMkfSBUOD7p8woIYTgz5C/L8uQMXyr0fhL0l23VMA="; + tag = finalAttrs.version; + hash = "sha256-FZFrsCYRyLSFWSOlAt+f6jUEVNy52plhEytu+0tFFvU="; }; + # Disable fuzzing support for xdgmime: shared-mime-info doesn't use it, + # and it requires Linux-only APIs + postPatch = '' + cp -r --no-preserve=mode ${xdgmime} subprojects/xdgmime + substituteInPlace subprojects/xdgmime/meson.build \ + --replace-fail "subdir('fuzzing')" "" + ''; + nativeBuildInputs = [ meson ninja @@ -46,6 +64,7 @@ stdenv.mkDerivation (finalAttrs: { mesonFlags = [ "-Dupdate-mimedb=true" + "-Dbuild-spec=false" ]; meta = { diff --git a/pkgs/by-name/si/simdjson/package.nix b/pkgs/by-name/si/simdjson/package.nix index 8695dcb4c665..5909a93e78eb 100644 --- a/pkgs/by-name/si/simdjson/package.nix +++ b/pkgs/by-name/si/simdjson/package.nix @@ -18,8 +18,16 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-ZMYYjwyeqqlklwY4UWBgT5sJ0Ojkg38Xcxg6CO461Ec="; }; + outputs = [ + "out" + "dev" + ]; + nativeBuildInputs = [ cmake ]; + strictDeps = true; + __structuredAttrs = true; + cmakeFlags = [ (lib.cmakeBool "SIMDJSON_DEVELOPER_MODE" false) (lib.cmakeBool "BUILD_SHARED_LIBS" (!stdenv.hostPlatform.isStatic)) diff --git a/pkgs/by-name/si/simdutf/package.nix b/pkgs/by-name/si/simdutf/package.nix index 542b6f7248e2..da23a40d43db 100644 --- a/pkgs/by-name/si/simdutf/package.nix +++ b/pkgs/by-name/si/simdutf/package.nix @@ -2,7 +2,6 @@ lib, stdenv, fetchFromGitHub, - fetchpatch2, cmake, libiconv, nix-update-script, @@ -12,22 +11,18 @@ stdenv.mkDerivation (finalAttrs: { pname = "simdutf"; - version = "9.1.0"; + version = "9.1.1"; src = fetchFromGitHub { owner = "simdutf"; repo = "simdutf"; tag = "v${finalAttrs.version}"; - hash = "sha256-PKL495sfkRKjHfN4RroW1dwudJV2JWN7ogB8hyDxj5Y="; + hash = "sha256-u0Ur/o2TRLqYisS7xQHBxN/742BzmbElNUeqgEzpw/I="; }; - # https://github.com/simdutf/simdutf/issues/1032 - # FIXME: remove in next release - patches = lib.optionals (stdenv.hostPlatform.isLoongArch64 && finalAttrs.version == "9.1.0") [ - (fetchpatch2 { - url = "https://github.com/simdutf/simdutf/commit/1f8ef080486c31cbd70db21a05a008700eb03aae.patch?full_index=1"; - hash = "sha256-p1qJFUQ4KhSSLSBIiC9se/TxrWFqywdVKNgh78TkMyE="; - }) + outputs = [ + "out" + "dev" ]; cmakeFlags = [ diff --git a/pkgs/by-name/sm/smc-fuzzer/package.nix b/pkgs/by-name/sm/smc-fuzzer/package.nix index 255182141c8d..7a396e506efb 100644 --- a/pkgs/by-name/sm/smc-fuzzer/package.nix +++ b/pkgs/by-name/sm/smc-fuzzer/package.nix @@ -1,6 +1,5 @@ { lib, - swiftPackages, fetchFromGitHub, stdenv, }: diff --git a/pkgs/by-name/sm/smuview/package.nix b/pkgs/by-name/sm/smuview/package.nix index 05a3dfd3afe0..b6a0ba50722f 100644 --- a/pkgs/by-name/sm/smuview/package.nix +++ b/pkgs/by-name/sm/smuview/package.nix @@ -11,7 +11,7 @@ libzip, libftdi1, hidapi, - glibmm, + glibmm_2_4, python3, bluez, pcre2, @@ -46,7 +46,7 @@ stdenv.mkDerivation { libzip libftdi1 hidapi - glibmm + glibmm_2_4 python3 pcre2 libsForQt5.qwt diff --git a/pkgs/by-name/so/sooperlooper/package.nix b/pkgs/by-name/so/sooperlooper/package.nix index 78b2aa4baa32..22efae021550 100644 --- a/pkgs/by-name/so/sooperlooper/package.nix +++ b/pkgs/by-name/so/sooperlooper/package.nix @@ -11,7 +11,7 @@ libjack2, libsndfile, wxwidgets_3_2, - libsigcxx, + libsigcxx_2_0, libsamplerate, rubberband, gettext, @@ -49,7 +49,7 @@ stdenv.mkDerivation (finalAttrs: { libjack2 libsndfile wxwidgets_3_2 - libsigcxx + libsigcxx_2_0 libsamplerate rubberband gettext diff --git a/pkgs/by-name/sp/spice-vdagent/package.nix b/pkgs/by-name/sp/spice-vdagent/package.nix index 7c7633f86f2c..48ca54f12f46 100644 --- a/pkgs/by-name/sp/spice-vdagent/package.nix +++ b/pkgs/by-name/sp/spice-vdagent/package.nix @@ -56,6 +56,9 @@ stdenv.mkDerivation (finalAttrs: { systemd ]; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + meta = { description = "Enhanced SPICE integration for linux QEMU guest"; longDescription = '' diff --git a/pkgs/by-name/sr/srt/package.nix b/pkgs/by-name/sr/srt/package.nix index 6dc2f322e407..7021a2f3b6ab 100644 --- a/pkgs/by-name/sr/srt/package.nix +++ b/pkgs/by-name/sr/srt/package.nix @@ -3,6 +3,7 @@ stdenv, fetchFromGitHub, cmake, + bashNonInteractive, openssl, windows, }: @@ -14,19 +15,22 @@ stdenv.mkDerivation (finalAttrs: { src = fetchFromGitHub { owner = "Haivision"; repo = "srt"; - rev = "v${finalAttrs.version}"; - sha256 = "sha256-fdgj6URuMaem+ZVy7D8Hnf2Ev1HindevdvX0xyxCL4M="; + tag = "v${finalAttrs.version}"; + hash = "sha256-fdgj6URuMaem+ZVy7D8Hnf2Ev1HindevdvX0xyxCL4M="; }; nativeBuildInputs = [ cmake ]; buildInputs = [ + bashNonInteractive openssl ] ++ lib.optionals stdenv.hostPlatform.isMinGW [ windows.pthreads ]; + strictDeps = true; + patches = [ ] ++ lib.optionals stdenv.hostPlatform.isMinGW [ @@ -45,6 +49,8 @@ stdenv.mkDerivation (finalAttrs: { "-UCMAKE_INSTALL_LIBDIR" ]; + __structuredAttrs = true; + meta = { description = "Secure, Reliable, Transport"; homepage = "https://github.com/Haivision/srt"; diff --git a/pkgs/by-name/sr/srtp/package.nix b/pkgs/by-name/sr/srtp/package.nix index 84ec31998fad..e917d7b948ca 100644 --- a/pkgs/by-name/sr/srtp/package.nix +++ b/pkgs/by-name/sr/srtp/package.nix @@ -11,13 +11,13 @@ stdenv.mkDerivation rec { pname = "libsrtp"; - version = "2.8.0"; + version = "2.8.1"; src = fetchFromGitHub { owner = "cisco"; repo = "libsrtp"; rev = "v${version}"; - sha256 = "sha256-QHDcPFzDhlvgLPnXfFU6247OirscU41SzKStiTPU0oQ="; + sha256 = "sha256-kLuz3gPVDhm1fzcrXL4xky+hrTprJbcxgQCyb4nVThQ="; }; outputs = [ diff --git a/pkgs/by-name/st/stats/package.nix b/pkgs/by-name/st/stats/package.nix index d951e6aff0e2..3636545894e5 100644 --- a/pkgs/by-name/st/stats/package.nix +++ b/pkgs/by-name/st/stats/package.nix @@ -1,9 +1,10 @@ { lib, - swiftPackages, fetchFromGitHub, leveldb, perl, + stdenv, + swift, actool, makeWrapper, rcodesign, @@ -11,8 +12,6 @@ }: let - inherit (swiftPackages) stdenv swift; - frameworks = [ "Kit" "CPU" diff --git a/pkgs/by-name/su/subtitleeditor/package.nix b/pkgs/by-name/su/subtitleeditor/package.nix index ff0427899d63..e037a189158d 100644 --- a/pkgs/by-name/su/subtitleeditor/package.nix +++ b/pkgs/by-name/su/subtitleeditor/package.nix @@ -12,7 +12,7 @@ gtkmm3, gst_all_1, hicolor-icon-theme, - libsigcxx, + libsigcxx_2_0, libxmlxx, xdg-utils, isocodes, @@ -51,7 +51,7 @@ stdenv.mkDerivation (finalAttrs: { gst_all_1.gst-plugins-ugly gst_all_1.gst-libav hicolor-icon-theme - libsigcxx + libsigcxx_2_0 libxmlxx xdg-utils isocodes diff --git a/pkgs/by-name/su/surge-xt/package.nix b/pkgs/by-name/su/surge-xt/package.nix index bad3fc26ea66..f31724aed58d 100644 --- a/pkgs/by-name/su/surge-xt/package.nix +++ b/pkgs/by-name/su/surge-xt/package.nix @@ -39,6 +39,9 @@ stdenv.mkDerivation (finalAttrs: { ./clap-option.diff ]; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + postPatch = '' # see https://github.com/NixOS/nixpkgs/pull/149487#issuecomment-991747333 export XDG_DOCUMENTS_DIR=$(mktemp -d) diff --git a/pkgs/by-name/su/suricata/package.nix b/pkgs/by-name/su/suricata/package.nix index b4c2782e8eb2..5dac04bb6ed9 100644 --- a/pkgs/by-name/su/suricata/package.nix +++ b/pkgs/by-name/su/suricata/package.nix @@ -8,7 +8,7 @@ elfutils, file, jansson, - libbpf_0, + libbpf, libcap_ng, libevent, libmaxminddb, @@ -67,7 +67,7 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ elfutils jansson - libbpf_0 + libbpf libcap_ng libevent libmagic diff --git a/pkgs/by-name/sv/svxlink/package.nix b/pkgs/by-name/sv/svxlink/package.nix index 4a18d7a4ac85..9f16bf326f39 100644 --- a/pkgs/by-name/sv/svxlink/package.nix +++ b/pkgs/by-name/sv/svxlink/package.nix @@ -11,7 +11,7 @@ gsm, libgcrypt, libgpiod_1, - libsigcxx, + libsigcxx_2_0, popt, qt5, rtl-sdr, @@ -65,7 +65,7 @@ stdenv.mkDerivation (finalAttrs: { libgcrypt libgpiod_1 libopus - libsigcxx + libsigcxx_2_0 popt qt5.qtbase rtl-sdr diff --git a/pkgs/by-name/sw/swig/package.nix b/pkgs/by-name/sw/swig/package.nix index 6afb32b575f8..87935887a53e 100644 --- a/pkgs/by-name/sw/swig/package.nix +++ b/pkgs/by-name/sw/swig/package.nix @@ -20,13 +20,14 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-jsi83v9sg0n5kUfDACqdNAS2VuLSyxv+pe2LRcO4Khc="; }; + # It is necessary to pull in the target pcre2-config binary this way because including pcre2 in nativeBuildInputs can create linking failures with cross-compilation + env.PCRE2_CONFIG = "${pcre2.dev}/bin/pcre2-config"; strictDeps = true; nativeBuildInputs = [ autoconf automake libtool bison - pcre2 ]; buildInputs = [ pcre2 ]; diff --git a/pkgs/by-name/sw/swipeaerospace/package.nix b/pkgs/by-name/sw/swipeaerospace/package.nix index cd1f284e59a8..6a9f87583341 100644 --- a/pkgs/by-name/sw/swipeaerospace/package.nix +++ b/pkgs/by-name/sw/swipeaerospace/package.nix @@ -4,12 +4,11 @@ fetchFromGitHub, lib, nix-update-script, - swiftPackages, + stdenv, + swift, }: let - inherit (swiftPackages) stdenv swift; - blueSocket = stdenv.mkDerivation (finalAttrs: { pname = "blue-socket"; version = "2.0.4"; @@ -44,7 +43,7 @@ let -emit-module \ -module-name Socket \ -emit-module-path "$buildDir/Socket.swiftmodule" \ - -Xlinker -install_name -Xlinker "$out/lib/swift/libSocket.dylib" \ + -Xlinker -install_name -Xlinker "$out/lib/libSocket.dylib" \ Sources/Socket/*.swift \ -o "$buildDir/libSocket.dylib" @@ -54,9 +53,9 @@ let installPhase = '' runHook preInstall - mkdir -p "$out/lib/swift" - cp build/libSocket.dylib "$out/lib/swift/" - cp build/Socket.* "$out/lib/swift/" + mkdir -p "$out/lib/swift/macosx" + cp build/libSocket.dylib "$out/lib" + cp build/Socket.* "$out/lib/swift/macosx" runHook postInstall ''; @@ -97,10 +96,6 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-lEWbZ/FvxtlY4VnFRk//tDeVrW9+udyJ+hbUsG61jhI="; }; - # Keep SettingsView unchanged, but open it through a regular WindowGroup. - # @Environment(\.openSettings) does not compile with nixpkgs' SwiftUI SDK. - patches = [ ./settings-window.patch ]; - nativeBuildInputs = [ swift actool @@ -123,6 +118,7 @@ stdenv.mkDerivation (finalAttrs: { done < <(find SwipeAeroSpace -name '*.swift' -print0) swiftc \ + -I${lib.getDev blueSocket}/lib/swift/${stdenv.hostPlatform.swift.platform} \ -O \ -swift-version 5 \ -parse-as-library \ diff --git a/pkgs/by-name/sw/swipeaerospace/settings-window.patch b/pkgs/by-name/sw/swipeaerospace/settings-window.patch deleted file mode 100644 index a70bb1b31375..000000000000 --- a/pkgs/by-name/sw/swipeaerospace/settings-window.patch +++ /dev/null @@ -1,36 +0,0 @@ ---- a/SwipeAeroSpace/SwipeAeroSpaceApp.swift -+++ b/SwipeAeroSpace/SwipeAeroSpaceApp.swift -@@ -10,10 +10,0 @@ import SwiftUI --@available(macOS 14.0, *) --struct SettingsButton: View { -- @Environment(\.openSettings) private var openSettings -- -- var body: some View { -- Button("Settings") { -- openSettings() -- } -- } --} -@@ -64,16 +54,4 @@ struct SwipeAeroSpaceApp: App { -- if #available(macOS 14.0, *) { -- SettingsButton() -- } else { -- Button( -- action: { -- NSApp.sendAction( -- Selector(("showSettingsWindow:")), -- to: nil, -- from: nil -- ) -- }, -- label: { -- Text("Settings") -- } -- ) -+ Button("Settings") { -+ NSApp.activate(ignoringOtherApps: true) -+ openWindow(id: "settings") - } -@@ -92 +70 @@ struct SwipeAeroSpaceApp: App { -- Settings { -+ WindowGroup(id: "settings") { diff --git a/pkgs/by-name/sy/synapse-admin/package.nix b/pkgs/by-name/sy/synapse-admin/package.nix index b65f92a92fae..bc35a9673281 100644 --- a/pkgs/by-name/sy/synapse-admin/package.nix +++ b/pkgs/by-name/sy/synapse-admin/package.nix @@ -2,6 +2,7 @@ lib, stdenv, fetchFromGitHub, + substitute, nodejs, yarn-berry, cacert, @@ -24,19 +25,29 @@ stdenv.mkDerivation (finalAttrs: { owner = "Awesome-Technologies"; repo = "synapse-admin"; tag = finalAttrs.version; - hash = "sha256-rK1Tc1K3wx6/1J8TEw5Lb9g09gbt/1HoZdDrEFzxTQQ="; - }; + hash = "sha256-D7MlFaI49KSNQ7DPj0iGKJqaQ4s5Y6EksB2U3Z5sJXY="; - patches = [ - # Remove after upstream updates to Yarn 4.14 + # Remove after upstream updates to Yarn 4.15 # https://github.com/Awesome-Technologies/synapse-admin/blob/master/package.json#L13 - ./yarn-4.14-support.patch - ]; + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry.lockfileVersion + ]; + }) + } + ''; + }; # we cannot use fetchYarnDeps because that doesn't support yarn 2/berry lockfiles yarnOfflineCache = stdenv.mkDerivation { pname = "yarn-deps"; - inherit (finalAttrs) version src patches; + inherit (finalAttrs) version src; nativeBuildInputs = [ yarn-berry ]; @@ -84,7 +95,7 @@ stdenv.mkDerivation (finalAttrs: { runHook postBuild ''; - outputHash = "sha256-IiViodAB1KAYsRRr8+zw3vrCbUYp7Mdtazi0Y6SEFNU="; + outputHash = "sha256-n5SkXCWOsqdyZkng5EU0HJDKJ0xorfi6SfNvwnuhFTg="; outputHashMode = "recursive"; }; diff --git a/pkgs/by-name/sy/synapse-admin/yarn-4.14-support.patch b/pkgs/by-name/sy/synapse-admin/yarn-4.14-support.patch deleted file mode 100644 index 7acf8fd001bc..000000000000 --- a/pkgs/by-name/sy/synapse-admin/yarn-4.14-support.patch +++ /dev/null @@ -1,20 +0,0 @@ -diff --git a/.yarnrc.yml b/.yarnrc.yml ---- a/.yarnrc.yml -+++ b/.yarnrc.yml -@@ -1 +1,4 @@ --yarnPath: .yarn/releases/yarn-4.4.1.cjs -+approvedGitRepositories: -+ - "**" -+ -+enableScripts: true -diff --git a/yarn.lock b/yarn.lock ---- a/yarn.lock -+++ b/yarn.lock -@@ -2,6 +2,6 @@ - # Manual changes might be lost - proceed with caution! - - __metadata: -- version: 8 -+ version: 9 - cacheKey: 10c0 - diff --git a/pkgs/by-name/sy/synapse-admin/yarn-fix.patch b/pkgs/by-name/sy/synapse-admin/yarn-fix.patch new file mode 100644 index 000000000000..b18faa94fbb0 --- /dev/null +++ b/pkgs/by-name/sy/synapse-admin/yarn-fix.patch @@ -0,0 +1,41 @@ +diff --git a/.yarnrc.yml b/.yarnrc.yml +--- a/.yarnrc.yml ++++ b/.yarnrc.yml +@@ -1 +1,4 @@ +-yarnPath: .yarn/releases/yarn-4.4.1.cjs ++approvedGitRepositories: ++ - "**" ++ ++enableScripts: true +diff --git a/yarn.lock b/yarn.lock +--- a/yarn.lock ++++ b/yarn.lock +@@ -2,6 +2,6 @@ + # Manual changes might be lost - proceed with caution! + + __metadata: +- version: 8 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER + cacheKey: 10c0 + +diff --git a/yarn.lock b/yarn.lock +index 7ecce1c508a4..6df14e5f4603 100644 +--- a/yarn.lock ++++ b/yarn.lock +@@ -7366,14 +7366,14 @@ __metadata: + + "resolve@patch:resolve@npm%3A^1.19.0#optional!builtin, resolve@patch:resolve@npm%3A^1.20.0#optional!builtin, resolve@patch:resolve@npm%3A^1.22.4#optional!builtin": + version: 1.22.8 +- resolution: "resolve@patch:resolve@npm%3A1.22.8#optional!builtin::version=1.22.8&hash=c3c19d" ++ resolution: "resolve@patch:resolve@npm%3A1.22.8#optional!builtin::version=1.22.8&hash=9bd1a5" + dependencies: + is-core-module: "npm:^2.13.0" + path-parse: "npm:^1.0.7" + supports-preserve-symlinks-flag: "npm:^1.0.0" + bin: + resolve: bin/resolve +- checksum: 10c0/0446f024439cd2e50c6c8fa8ba77eaa8370b4180f401a96abf3d1ebc770ac51c1955e12764cde449fde3fff480a61f84388e3505ecdbab778f4bef5f8212c729 ++ checksum: 10c0/4bc6de64a713422234e0e773bff296767d77d6e545b98042ff90a796d356f2b131853f4fa1d54e2c415aa6efa6dc2eed5b3f501f63164f834619fda900e33b8e + languageName: node + linkType: hard + diff --git a/pkgs/by-name/sy/synfigstudio/package.nix b/pkgs/by-name/sy/synfigstudio/package.nix index 14b0d30d1d3f..40451c3161ff 100644 --- a/pkgs/by-name/sy/synfigstudio/package.nix +++ b/pkgs/by-name/sy/synfigstudio/package.nix @@ -10,12 +10,12 @@ cairo, ffmpeg, gettext, - glibmm, + glibmm_2_4, libmng, gtk3, gtkmm3, libjack2, - libsigcxx, + libsigcxx_2_0, libxmlxx, mlt, imagemagick, @@ -79,9 +79,9 @@ let ]; buildInputs = [ ETL - glibmm + glibmm_2_4 mlt - libsigcxx + libsigcxx_2_0 libxmlxx imagemagick harfbuzz @@ -130,12 +130,12 @@ stdenv.mkDerivation (finalAttrs: { ETL synfig cairo - glibmm + glibmm_2_4 gtk3 gtkmm3 imagemagick libjack2 - libsigcxx + libsigcxx_2_0 libxmlxx mlt fontconfig diff --git a/pkgs/by-name/sy/syshud/package.nix b/pkgs/by-name/sy/syshud/package.nix index 0e3b3b852e0e..a32e4128a61d 100644 --- a/pkgs/by-name/sy/syshud/package.nix +++ b/pkgs/by-name/sy/syshud/package.nix @@ -2,7 +2,7 @@ lib, stdenv, fetchFromGitHub, - glibmm, + glibmm_2_4, gtk4-layer-shell, gtkmm4, libevdev, @@ -36,7 +36,7 @@ stdenv.mkDerivation (finalAttrs: { ]; buildInputs = [ - glibmm + glibmm_2_4 gtk4-layer-shell gtkmm4 libevdev diff --git a/pkgs/by-name/ta/target-isns/package.nix b/pkgs/by-name/ta/target-isns/package.nix index b7c9d8f9eba1..cedaf1f35604 100644 --- a/pkgs/by-name/ta/target-isns/package.nix +++ b/pkgs/by-name/ta/target-isns/package.nix @@ -32,6 +32,12 @@ stdenv.mkDerivation (finalAttrs: { url = "https://github.com/open-iscsi/target-isns/commit/e209821423f936d1cc9b946fb8f7a8979b8e751b.patch?full_index=1"; hash = "sha256-86nl8wTiI9WSZ+Hhw/a9VtgS8OLqoFwiot5iU5IK0f8="; }) + + # Fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/open-iscsi/target-isns/commit/d3645f0c357b2b14fb682fa2cd4ba3621efc4cea.patch"; + hash = "sha256-/ew+B4WDF2s5bjfPLZ7glHW+o/pRTI7zPHLTDh+n4lY="; + }) ]; cmakeFlags = [ "-DSUPPORT_SYSTEMD=ON" ]; diff --git a/pkgs/by-name/ta/tayga/package.nix b/pkgs/by-name/ta/tayga/package.nix index c153319c1677..5efecdef4648 100644 --- a/pkgs/by-name/ta/tayga/package.nix +++ b/pkgs/by-name/ta/tayga/package.nix @@ -24,6 +24,12 @@ stdenv.mkDerivation (finalAttrs: { url = "https://github.com/apalrd/tayga/commit/b41bd030846451d72b277854678b58370b1d5c8f.patch?full_index=1"; hash = "sha256-vFQTlZs9ghxdx4k/iODDOUBAglyll1OxUdTjzDtcwB0="; }) + + # Fix build w/ glibc-2.44 + (fetchpatch2 { + url = "https://github.com/apalrd/tayga/commit/807fe4e4510e697fef6916cd76d393a8ab8e495e.patch?full_index=1"; + hash = "sha256-JqRKv5ZAlypQxYvhctBKPdWgC6Opxo1IV1niS5v2CfY="; + }) ]; makeFlags = [ diff --git a/pkgs/by-name/te/termpaint/package.nix b/pkgs/by-name/te/termpaint/package.nix index b9cc6217119d..9656eb68d8e9 100644 --- a/pkgs/by-name/te/termpaint/package.nix +++ b/pkgs/by-name/te/termpaint/package.nix @@ -6,6 +6,7 @@ ninja, pkg-config, python3, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { pname = "termpaint"; @@ -18,7 +19,15 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-7mfGTC5vJ4806bDbrPMSVthtW05a+M3vgUlHGbtaI4Q="; }; - patches = [ ./0001-meson.build-use-prefix.patch ]; + patches = [ + ./0001-meson.build-use-prefix.patch + + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/termpaint/termpaint/commit/6164fb5ff17fd3d05bf44e942539082aa71a2ff3.patch"; + hash = "sha256-rTI0ZdJ6Q/a7M73igihd+4EZT9l6l+7oHGUnKmB5n0o="; + }) + ]; nativeBuildInputs = [ meson diff --git a/pkgs/by-name/th/thrift/package.nix b/pkgs/by-name/th/thrift/package.nix index f8b400534acd..4ef41a762719 100644 --- a/pkgs/by-name/th/thrift/package.nix +++ b/pkgs/by-name/th/thrift/package.nix @@ -18,13 +18,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "thrift"; - version = "0.22.0"; + version = "0.24.0"; src = fetchFromGitHub { owner = "apache"; repo = "thrift"; tag = "v${finalAttrs.version}"; - hash = "sha256-gGAO+D0A/hEoHMm6OvRBc1Mks9y52kfd0q/Sg96pdW4="; + hash = "sha256-+o/2exHsunjQBGjXrNQ1pQ5TKV53++qCxIMeVyOh5QY="; }; postPatch = lib.optionalString (!finalAttrs.finalPackage.doCheck) '' diff --git a/pkgs/by-name/ti/tilt/assets.nix b/pkgs/by-name/ti/tilt/assets.nix index 12b145261390..d8fb770d939e 100644 --- a/pkgs/by-name/ti/tilt/assets.nix +++ b/pkgs/by-name/ti/tilt/assets.nix @@ -8,17 +8,10 @@ src, }: -let - patches = [ - # Remove after upstream updates to Yarn 4.14 - # https://github.com/tilt-dev/tilt/blob/master/web/package.json#L94 - ./yarn-4.14-support.patch - ]; -in stdenvNoCC.mkDerivation { pname = "tilt-assets"; src = "${src}/web"; - inherit version patches; + inherit version; nativeBuildInputs = [ nodejs @@ -29,8 +22,6 @@ stdenvNoCC.mkDerivation { name = "tilt-assets-deps"; src = "${src}/web"; - inherit patches; - nativeBuildInputs = [ yarn-berry ]; supportedArchitectures = builtins.toJSON { @@ -77,7 +68,7 @@ stdenvNoCC.mkDerivation { dontInstall = true; outputHashAlgo = "sha256"; - outputHash = "sha256-MOEf6LZuHoOMX6OWqTn9j7AKIyC2lzt4SUXKWfE8B5A="; + outputHash = "sha256-fJwBXemRFvT5pA0McrXMGeuaCLjyHXwTMf5/Rh+jPvs="; outputHashMode = "recursive"; }; diff --git a/pkgs/by-name/ti/tilt/package.nix b/pkgs/by-name/ti/tilt/package.nix index 1a126ed6927c..6f9692e8d387 100644 --- a/pkgs/by-name/ti/tilt/package.nix +++ b/pkgs/by-name/ti/tilt/package.nix @@ -1,6 +1,8 @@ { fetchFromGitHub, + substitute, callPackage, + yarn-berry, }: let args = rec { @@ -15,10 +17,26 @@ let owner = "tilt-dev"; repo = "tilt"; tag = "v${version}"; - hash = "sha256-tMP3EYgwulyqmuL3yE3CtCBIs2QhoWzW8PnYF+//bgs="; + hash = "sha256-ECECNXxO7fkX3eyNBWMlr9yqgiJKas0XpDA48lQNnr8="; + + # Remove after upstream updates to Yarn 4.15 + # https://github.com/tilt-dev/tilt/blob/master/web/package.json#L98 + postFetch = '' + cd $out/web + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry.lockfileVersion + ]; + }) + } + ''; }; }; - tilt-assets = callPackage ./assets.nix args; + tilt-assets = callPackage ./assets.nix (args // { inherit yarn-berry; }); in callPackage ./binary.nix (args // { inherit tilt-assets; }) diff --git a/pkgs/by-name/ti/tilt/yarn-4.14-support.patch b/pkgs/by-name/ti/tilt/yarn-4.14-support.patch deleted file mode 100644 index 44b7fd0a4008..000000000000 --- a/pkgs/by-name/ti/tilt/yarn-4.14-support.patch +++ /dev/null @@ -1,23 +0,0 @@ -diff --git a/.yarnrc.yml b/.yarnrc.yml ---- a/.yarnrc.yml -+++ b/.yarnrc.yml -@@ -6,4 +6,7 @@ enableGlobalCache: false - - nodeLinker: node-modules - --yarnPath: .yarn/releases/yarn-4.9.3.cjs -+approvedGitRepositories: -+ - "**" -+ -+enableScripts: true -diff --git a/yarn.lock b/yarn.lock ---- a/yarn.lock -+++ b/yarn.lock -@@ -2,6 +2,6 @@ - # Manual changes might be lost - proceed with caution! - - __metadata: -- version: 8 -+ version: 9 - cacheKey: 10 - diff --git a/pkgs/by-name/ti/tilt/yarn-fix.patch b/pkgs/by-name/ti/tilt/yarn-fix.patch new file mode 100644 index 000000000000..925ce855de11 --- /dev/null +++ b/pkgs/by-name/ti/tilt/yarn-fix.patch @@ -0,0 +1,58 @@ +diff --git a/.yarnrc.yml b/.yarnrc.yml +--- a/.yarnrc.yml ++++ b/.yarnrc.yml +@@ -6,4 +6,7 @@ enableGlobalCache: false + + nodeLinker: node-modules + +-yarnPath: .yarn/releases/yarn-4.9.3.cjs ++approvedGitRepositories: ++ - "**" ++ ++enableScripts: true +diff --git a/yarn.lock b/yarn.lock +--- a/yarn.lock ++++ b/yarn.lock +@@ -2,6 +2,6 @@ + # Manual changes might be lost - proceed with caution! + + __metadata: +- version: 8 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER + cacheKey: 10 + +diff --git a/yarn.lock b/yarn.lock +--- a/yarn.lock ++++ b/yarn.lock +@@ -18405,27 +18405,27 @@ __metadata: + + "resolve@patch:resolve@npm%3A^1.1.7#optional!builtin, resolve@patch:resolve@npm%3A^1.10.0#optional!builtin, resolve@patch:resolve@npm%3A^1.14.2#optional!builtin, resolve@patch:resolve@npm%3A^1.19.0#optional!builtin, resolve@patch:resolve@npm%3A^1.20.0#optional!builtin, resolve@patch:resolve@npm%3A^1.22.2#optional!builtin, resolve@patch:resolve@npm%3A^1.22.4#optional!builtin, resolve@patch:resolve@npm%3A^1.3.2#optional!builtin": + version: 1.22.8 +- resolution: "resolve@patch:resolve@npm%3A1.22.8#optional!builtin::version=1.22.8&hash=c3c19d" ++ resolution: "resolve@patch:resolve@npm%3A1.22.8#optional!builtin::version=1.22.8&hash=9bd1a5" + dependencies: + is-core-module: "npm:^2.13.0" + path-parse: "npm:^1.0.7" + supports-preserve-symlinks-flag: "npm:^1.0.0" + bin: + resolve: bin/resolve +- checksum: 10/f345cd37f56a2c0275e3fe062517c650bb673815d885e7507566df589375d165bbbf4bdb6aa95600a9bc55f4744b81f452b5a63f95b9f10a72787dba3c90890a ++ checksum: 10/b14c82cbce48701a1e963c60f196b91a289186e8b596334e09c881df8069cefcfb0ac9ce85ea768742b361a58005494bf2428a95dc5056d2ba441aa993731b1f + languageName: node + linkType: hard + + "resolve@patch:resolve@npm%3A^2.0.0-next.4#optional!builtin": + version: 2.0.0-next.5 +- resolution: "resolve@patch:resolve@npm%3A2.0.0-next.5#optional!builtin::version=2.0.0-next.5&hash=c3c19d" ++ resolution: "resolve@patch:resolve@npm%3A2.0.0-next.5#optional!builtin::version=2.0.0-next.5&hash=9bd1a5" + dependencies: + is-core-module: "npm:^2.13.0" + path-parse: "npm:^1.0.7" + supports-preserve-symlinks-flag: "npm:^1.0.0" + bin: + resolve: bin/resolve +- checksum: 10/05fa778de9d0347c8b889eb7a18f1f06bf0f801b0eb4610b4871a4b2f22e220900cf0ad525e94f990bb8d8921c07754ab2122c0c225ab4cdcea98f36e64fa4c2 ++ checksum: 10/76c221deb1d986c0a80cd576373b0ee09f42871e0085a1f76beda84f73ce04e0d21bab28dffd326eb006a7af83bbc582404566b384aa3b0baa217f56cf7e8618 + languageName: node + linkType: hard + diff --git a/pkgs/by-name/tr/trurl/0001-build-constify-strchr-memchr-results.patch b/pkgs/by-name/tr/trurl/0001-build-constify-strchr-memchr-results.patch new file mode 100644 index 000000000000..eb43174b2f28 --- /dev/null +++ b/pkgs/by-name/tr/trurl/0001-build-constify-strchr-memchr-results.patch @@ -0,0 +1,146 @@ +From f081fc506e0e53f671f02ebac8b324f3fd421ee8 Mon Sep 17 00:00:00 2001 +From: Viktor Szakats +Date: Sun, 1 Mar 2026 11:39:41 +0100 +Subject: [PATCH] build: constify `strchr()`/`memchr()` results + +To fix building with glibc-2.43. +(also seen with gcc 16 on Fedora rawhide/f44) + +Also: +- scope a variable while there. +- fix altering the const format buffer on bad syntax. + +Reported-by: Gustavo Costa +Fixes #430 +Reported-by: Michael Ablassmeier +Fixes #431 + +Closes #432 +--- + trurl.c | 37 +++++++++++++++++++------------------ + 1 file changed, 19 insertions(+), 18 deletions(-) + +diff --git a/trurl.c b/trurl.c +index b5a716c..d150a93 100644 +--- a/trurl.c ++++ b/trurl.c +@@ -483,7 +483,7 @@ static void pathadd(struct option *o, const char *path) + + static char *encodeassign(const char *query) + { +- char *p = strchr(query, '='); ++ const char *p = strchr(query, '='); + char *urle; + if(p) { + /* URL encode the left and the right side of the '=' separately */ +@@ -600,7 +600,7 @@ static int getarg(struct option *o, + gap = false; + } + else if((flag[0] == '-') && (flag[1] == '-')) { +- char *equals = strchr(&flag[2], '='); ++ const char *equals = strchr(&flag[2], '='); + if(equals) { + arg = (char *)&equals[1]; + gap = false; +@@ -861,9 +861,10 @@ static void get(struct option *o, CURLU *uh) + else { + /* this is meant as a variable to output */ + const char *start = ptr; +- char *end; +- char *cl; ++ const char *end; ++ const char *cl; + size_t vlen; ++ size_t badlen = 0; + bool isquery = false; + bool queryall = false; + bool strict = false; /* strict mode, fail on URL decode problems */ +@@ -923,7 +924,7 @@ static void get(struct option *o, CURLU *uh) + else { + /* syntax error */ + vlen = 0; +- end[1] = '\0'; ++ badlen = end - start + 1; + } + break; + } +@@ -938,7 +939,7 @@ static void get(struct option *o, CURLU *uh) + queryall); + } + else if(!vlen) +- errorf(o, ERROR_GET, "Bad --get syntax: %s", start); ++ errorf(o, ERROR_GET, "Bad --get syntax: %.*s", (int)badlen, start); + else if(!strncmp(ptr, "url", vlen)) + showurl(stream, o, mods, uh); + else { +@@ -1022,7 +1023,7 @@ static void get(struct option *o, CURLU *uh) + static const struct var *setone(CURLU *uh, const char *setline, + struct option *o) + { +- char *ptr = strchr(setline, '='); ++ const char *ptr = strchr(setline, '='); + const struct var *v = NULL; + if(ptr && (ptr > setline)) { + size_t vlen = ptr - setline; +@@ -1269,9 +1270,9 @@ static bool trim(struct option *o) + inslen--; + } + +- for(i = 0 ; i < nqpairs; i++) { +- char *q = qpairs[i].str; +- char *sep = strchr(q, '='); ++ for(i = 0; i < nqpairs; i++) { ++ const char *q = qpairs[i].str; ++ const char *sep = strchr(q, '='); + size_t qlen; + if(sep) + qlen = sep - q; +@@ -1546,10 +1547,9 @@ static bool extractqpairs(CURLU *uh, struct option *o) + /* extract the query */ + if(!curl_url_get(uh, CURLUPART_QUERY, &q, 0)) { + char *p = q; +- char *amp; + while(*p) { + size_t len; +- amp = strchr(p, o->qsep[0]); ++ char *amp = strchr(p, o->qsep[0]); + if(!amp) + len = strlen(p); + else +@@ -1684,7 +1684,7 @@ static char *canonical_path(const char *path) + { + /* split the path per slash, URL decode + encode, then put together again */ + size_t len = strlen(path); +- char *sl; ++ const char *sl; + char *dupe = NULL; + + do { +@@ -1810,7 +1810,8 @@ static void singleurl(struct option *o, + size_t plen; + const char *w; + size_t wlen; +- char *sep; ++ const char *sep; ++ char *sepw; + bool urlencode = true; + const struct var *v; + +@@ -1852,10 +1853,10 @@ static void singleurl(struct option *o, + w = iinfo->ptr; + } + +- sep = strchr(w, ' '); +- if(sep) { +- wlen = sep - w; +- iinfo->ptr = sep + 1; /* next word is here */ ++ sepw = strchr(w, ' '); ++ if(sepw) { ++ wlen = sepw - w; ++ iinfo->ptr = sepw + 1; /* next word is here */ + } + else { + /* last word */ +-- +2.54.0 + diff --git a/pkgs/by-name/tr/trurl/package.nix b/pkgs/by-name/tr/trurl/package.nix index 5cddcd00a35e..bd2e932fd697 100644 --- a/pkgs/by-name/tr/trurl/package.nix +++ b/pkgs/by-name/tr/trurl/package.nix @@ -6,7 +6,6 @@ curl, python3, perl, - trurl, versionCheckHook, }: @@ -22,6 +21,14 @@ stdenv.mkDerivation rec { }; patches = [ + # fix build w/ glibc-2.44 + # https://github.com/curl/trurl/commit/6e1479cc3bdece8d9a7602e6f8f799305d5a5b7d, but rebased + ./0001-build-constify-strchr-memchr-results.patch + (fetchpatch { + url = "https://github.com/curl/trurl/commit/b3c2faf7ee519e4686248957ee079a2452741d61.patch"; + hash = "sha256-khA77XHPVF+2Vn492UuPrhVAEUijRBA2P8lvPlKYSQM="; + }) + (fetchpatch { url = "https://github.com/curl/trurl/commit/f22a2c45956f35702e437fb83ac05376f1956ec5.patch"; hash = "sha256-7CkUs5tMk77WKc7SlgE2NslHtU5cViKSGhHj3IBlpWo="; diff --git a/pkgs/by-name/tu/tuxpaint/package.nix b/pkgs/by-name/tu/tuxpaint/package.nix index 3152be909715..5e81c3583ef4 100644 --- a/pkgs/by-name/tu/tuxpaint/package.nix +++ b/pkgs/by-name/tu/tuxpaint/package.nix @@ -23,6 +23,7 @@ SDL2_Pango, SDL2_ttf, netpbm, + fetchpatch, }: let @@ -50,6 +51,15 @@ stdenv.mkDerivation (finalAttrs: { strictDeps = true; + patches = [ + # Fix build w/ glibc-2.44 + # https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=51c28b814990551897631be7a222af2d922030a9 + (fetchpatch { + url = "https://gitweb.gentoo.org/repo/gentoo.git/plain/media-gfx/tuxpaint/files/tuxpaint-0.9.35-glibc-2.43.patch?id=51c28b814990551897631be7a222af2d922030a9"; + hash = "sha256-xkV73GoCd/epeyWfLHq2MNmRNfKaledoFsukwVKiZSI="; + }) + ]; + nativeBuildInputs = [ gettext gperf diff --git a/pkgs/by-name/tz/tzdata/package.nix b/pkgs/by-name/tz/tzdata/package.nix index 7e3f8f38535d..1d6cb31e1d2b 100644 --- a/pkgs/by-name/tz/tzdata/package.nix +++ b/pkgs/by-name/tz/tzdata/package.nix @@ -3,21 +3,22 @@ stdenv, fetchurl, buildPackages, + bashNonInteractive, postgresql, }: stdenv.mkDerivation (finalAttrs: { pname = "tzdata"; - version = "2026c"; + version = "2026d"; srcs = [ (fetchurl { url = "https://data.iana.org/time-zones/releases/tzdata${finalAttrs.version}.tar.gz"; - hash = "sha256-5KF4pEd/PQ6nfMMYKP9yqjj+/41hqhPn6Z4ULp2QK+Q="; + hash = "sha256-DLKqjjM8PcBJutxCoMYfIZh7jNROEH+pALrXZKrMd2c="; }) (fetchurl { url = "https://data.iana.org/time-zones/releases/tzcode${finalAttrs.version}.tar.gz"; - hash = "sha256-sc/8Os5MTHzQ77ovet2G7D0LedpIvPA1gmcf08j+rOg="; + hash = "sha256-L1yff+Kea4y4Y1g2Z4hLjOF7CkhTVaBUtZHGvfzYF5E="; }) ]; @@ -35,6 +36,8 @@ stdenv.mkDerivation (finalAttrs: { ]; propagatedBuildOutputs = [ ]; + buildInputs = [ bashNonInteractive ]; # for 'tzselect' + strictDeps = true; makeFlags = [ diff --git a/pkgs/by-name/uc/ucc/package.nix b/pkgs/by-name/uc/ucc/package.nix index ebc88215053a..4e55618df4b3 100644 --- a/pkgs/by-name/uc/ucc/package.nix +++ b/pkgs/by-name/uc/ucc/package.nix @@ -40,13 +40,13 @@ effectiveStdenv.mkDerivation (finalAttrs: { strictDeps = true; pname = "ucc"; - version = "1.8.0"; + version = "1.9.0"; src = fetchFromGitHub { owner = "openucx"; repo = "ucc"; tag = "v${finalAttrs.version}"; - hash = "sha256-rH/bG0pYO4VKfrnkXLXy/67hjaz6i3R0YoYdsGBqPsU="; + hash = "sha256-UiVbvT/9lWlfAcxXynzcVNjV5tLn6GRFqg2/SwcEQSg="; }; outputs = [ diff --git a/pkgs/by-name/uc/ucode/package.nix b/pkgs/by-name/uc/ucode/package.nix index a8309fbc4e26..ed014133c91d 100644 --- a/pkgs/by-name/uc/ucode/package.nix +++ b/pkgs/by-name/uc/ucode/package.nix @@ -5,6 +5,7 @@ cmake, pkg-config, json_c, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -18,6 +19,22 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-V8WGd4rSuCtGIA5oTfnagp0Dmh5FNG87/MJSeILtbM4="; }; + patches = [ + (fetchpatch { + url = "https://github.com/jow-/ucode/commit/4d81e6c13506599261208786cfe4ee068f346dcd.patch"; + hash = "sha256-RZhD422ue00bqam4n7jAynPDJdOzOFJnf34YbT2wH/s="; + }) + (fetchpatch { + url = "https://github.com/jow-/ucode/commit/a7ead3169ebf355e66b399aca1dd3a5ce29e1e5b.patch"; + hash = "sha256-sc+jSAlix1jE9Cb4MMuqI7VHG6h+zpCL7UZ84awOL6M="; + }) + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/jow-/ucode/commit/beafcff845fcdbb46308ee54422661e80300079d.patch"; + hash = "sha256-JcBk8kJHDlHLRuVR2fmsSfWqVmbFZMPF16+nPp6QFf4="; + }) + ]; + buildInputs = [ json_c ]; diff --git a/pkgs/by-name/ul/ulfius/package.nix b/pkgs/by-name/ul/ulfius/package.nix index 21542df0d6ad..6db5cbc75f7d 100644 --- a/pkgs/by-name/ul/ulfius/package.nix +++ b/pkgs/by-name/ul/ulfius/package.nix @@ -40,6 +40,9 @@ stdenv.mkDerivation (finalAttrs: { cmake ]; + # Fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + propagatedBuildInputs = [ libmicrohttpd orcania diff --git a/pkgs/by-name/un/unbound/package.nix b/pkgs/by-name/un/unbound/package.nix index 842382c59adc..35add0725258 100644 --- a/pkgs/by-name/un/unbound/package.nix +++ b/pkgs/by-name/un/unbound/package.nix @@ -64,13 +64,13 @@ assert lib.assertMsg ( ) "unbound: withDoQ requires OpenSSL with QUIC support (OpenSSL >= 3.5)"; stdenv.mkDerivation (finalAttrs: { pname = "unbound"; - version = "1.26.0"; + version = "1.26.1"; src = fetchFromGitHub { owner = "NLnetLabs"; repo = "unbound"; tag = "release-${finalAttrs.version}"; - hash = "sha256-ESRboc5vwsNZ/Yynl2JGRWhH1QEYZumoTzgSvN3NbSU="; + hash = "sha256-gf4vASdB6XzSGhJ2GKbUhgs0wpR32Du2ARx4bBQ+vJA="; }; outputs = [ diff --git a/pkgs/by-name/up/uppy-companion/package.nix b/pkgs/by-name/up/uppy-companion/package.nix index db022758e528..c9935fbebb75 100644 --- a/pkgs/by-name/up/uppy-companion/package.nix +++ b/pkgs/by-name/up/uppy-companion/package.nix @@ -3,6 +3,7 @@ stdenv, nodejs, fetchFromGitHub, + substitute, yarn-berry_4, }: @@ -14,14 +15,24 @@ stdenv.mkDerivation (finalAttrs: { owner = "transloadit"; repo = "uppy"; tag = "@uppy/companion@${finalAttrs.version}"; - hash = "sha256-FF5I4D9obRVJqyjucemnxZiPcNHdQdo3S0z/h96Fe6c="; - }; + hash = "sha256-4Xbw4d0SaLPk4mmvG9QWkUuVX/SM1SmGtuaK85rLihU="; - patches = [ - # Remove after upstream updates to Yarn 4.14 - # https://github.com/transloadit/uppy/blob/main/package.json#L39 - ./yarn-4.14-support.patch - ]; + # Remove after upstream updates to Yarn 4.15 + # https://github.com/transloadit/uppy/blob/main/package.json#L38 + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry_4.lockfileVersion + ]; + }) + } + ''; + }; nativeBuildInputs = [ nodejs @@ -36,8 +47,8 @@ stdenv.mkDerivation (finalAttrs: { missingHashes = ./missing-hashes.json; offlineCache = yarn-berry_4.fetchYarnBerryDeps { - inherit (finalAttrs) src missingHashes patches; - hash = "sha256-vmya3c+ec93T8kNoooUu4risqScY0b4cwML7d2kYz88="; + inherit (finalAttrs) src missingHashes; + hash = "sha256-MQTaNbeJuvWDtRajJQYRtuxiMrLGKtlasyB6sKeOIgs="; }; buildPhase = '' diff --git a/pkgs/by-name/up/uppy-companion/yarn-4.14-support.patch b/pkgs/by-name/up/uppy-companion/yarn-fix.patch similarity index 89% rename from pkgs/by-name/up/uppy-companion/yarn-4.14-support.patch rename to pkgs/by-name/up/uppy-companion/yarn-fix.patch index 1cb3aa5b44da..10fddf10793a 100644 --- a/pkgs/by-name/up/uppy-companion/yarn-4.14-support.patch +++ b/pkgs/by-name/up/uppy-companion/yarn-fix.patch @@ -17,6 +17,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10 diff --git a/pkgs/by-name/ur/urweb/package.nix b/pkgs/by-name/ur/urweb/package.nix index 445c01cec8f0..e79a09bfda7a 100644 --- a/pkgs/by-name/ur/urweb/package.nix +++ b/pkgs/by-name/ur/urweb/package.nix @@ -64,6 +64,7 @@ stdenv.mkDerivation rec { env.NIX_CFLAGS_COMPILE = toString [ # Needed with GCC 12 "-Wno-error=use-after-free" + "-Wno-error=discarded-qualifiers" ]; # Be sure to keep the statically linked libraries diff --git a/pkgs/by-name/ut/utf8cpp/package.nix b/pkgs/by-name/ut/utf8cpp/package.nix index e5ee3a2477d3..d0861d2a93bf 100644 --- a/pkgs/by-name/ut/utf8cpp/package.nix +++ b/pkgs/by-name/ut/utf8cpp/package.nix @@ -7,13 +7,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "utf8cpp"; - version = "4.2.0"; + version = "4.2.1"; src = fetchFromGitHub { owner = "nemtrif"; repo = "utfcpp"; tag = "v${finalAttrs.version}"; - hash = "sha256-vc7nKVVZ/h6q+dQUNiuXnkcqX7L2CkG6WUiybLNXAjU="; + hash = "sha256-/YpP2ZThfOL1O7aunjKYv5TCjVzMnXVGEefmBpRBIGY="; }; nativeBuildInputs = [ cmake ]; diff --git a/pkgs/by-name/ut/util-linux/package.nix b/pkgs/by-name/ut/util-linux/package.nix index 56ada6d03da3..6daa0d3f3ca6 100644 --- a/pkgs/by-name/ut/util-linux/package.nix +++ b/pkgs/by-name/ut/util-linux/package.nix @@ -3,8 +3,6 @@ stdenv, fetchurl, pkg-config, - autoconf, - automake116x, zlib, shadow, capabilitiesSupport ? stdenv.hostPlatform.isLinux, @@ -160,8 +158,6 @@ stdenv.mkDerivation (finalAttrs: { ]; nativeBuildInputs = [ - autoconf - automake116x installShellFiles pkg-config ] diff --git a/pkgs/by-name/uv/uvwasi/package.nix b/pkgs/by-name/uv/uvwasi/package.nix index 5194fdc7ab07..c3b85b5c8308 100644 --- a/pkgs/by-name/uv/uvwasi/package.nix +++ b/pkgs/by-name/uv/uvwasi/package.nix @@ -22,6 +22,9 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-+vz/qTMRRDHV1VE4nny9vYYtarZHk1xoM4EZiah3jnY="; }; + __structuredAttrs = true; + strictDeps = true; + patches = [ # FIXME: remove when included in a release (fetchpatch2 { @@ -38,6 +41,7 @@ stdenv.mkDerivation (finalAttrs: { outputs = [ "out" + "dev" ]; nativeBuildInputs = [ diff --git a/pkgs/by-name/vb/vboot-utils/package.nix b/pkgs/by-name/vb/vboot-utils/package.nix index 981202ea1fa0..d04f8a109aaf 100644 --- a/pkgs/by-name/vb/vboot-utils/package.nix +++ b/pkgs/by-name/vb/vboot-utils/package.nix @@ -36,6 +36,9 @@ stdenv.mkDerivation (finalAttrs: { ] ++ lib.optional withFlashrom finalAttrs.passthru.flashromChromeos; + # Fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + enableParallelBuilding = true; postPatch = '' diff --git a/pkgs/by-name/vg/vg/package.nix b/pkgs/by-name/vg/vg/package.nix index b0c38d6c3cd5..5cc0fb425efb 100644 --- a/pkgs/by-name/vg/vg/package.nix +++ b/pkgs/by-name/vg/vg/package.nix @@ -133,6 +133,7 @@ stdenv.mkDerivation (finalAttrs: { NIX_CFLAGS_COMPILE = toString [ "-Wno-error=stringop-overflow" "-Wno-error=unterminated-string-initialization" + "-Wno-error=discarded-qualifiers" ]; }; diff --git a/pkgs/by-name/vi/virt-viewer/package.nix b/pkgs/by-name/vi/virt-viewer/package.nix index 56a1962294ab..c599d66504ed 100644 --- a/pkgs/by-name/vi/virt-viewer/package.nix +++ b/pkgs/by-name/vi/virt-viewer/package.nix @@ -49,6 +49,12 @@ stdenv.mkDerivation (finalAttrs: { url = "https://gitlab.com/virt-viewer/virt-viewer/-/commit/98d9f202ef768f22ae21b5c43a080a1aa64a7107.patch"; sha256 = "sha256-3AbnkbhWOh0aNjUkmVoSV/9jFQtvTllOr7plnkntb2o="; }) + + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://gitlab.com/virt-viewer/virt-viewer/-/commit/a634fa8d9fbc59b093f2f07110b2c867f622599d.patch"; + hash = "sha256-xNwpuVwYajlfQUbT6aDrTBqwa61Je8EhD0C9+PL/qx0="; + }) ]; nativeBuildInputs = [ diff --git a/pkgs/by-name/vu/vultisig-cli/package.nix b/pkgs/by-name/vu/vultisig-cli/package.nix index d32fc0695366..8de1998919d2 100644 --- a/pkgs/by-name/vu/vultisig-cli/package.nix +++ b/pkgs/by-name/vu/vultisig-cli/package.nix @@ -4,6 +4,7 @@ fetchFromGitHub, nodejs, yarn-berry, + substitute, makeWrapper, }: @@ -15,20 +16,30 @@ stdenv.mkDerivation (finalAttrs: { owner = "vultisig"; repo = "vultisig-sdk"; tag = "v${finalAttrs.version}"; - hash = "sha256-4I+N9uKZBzw0AePjS8CiALye/fuykBtpAoYxp+5iTW8="; - }; + hash = "sha256-IFEses2Gs0HdgXVMpNYA6y7PtnMMDVLSoAuyi3a+ZgE="; - patches = [ - # Remove after upstream updates to Yarn 4.14 - # https://github.com/vultisig/vultisig-sdk/blob/main/package.json#L4 - ./yarn-4.14-support.patch - ]; + # Remove when updating since upstream has updated to Yarn 4.16 + # https://github.com/vultisig/vultisig-sdk/commit/45611297a55da72d3c56b1a2ffe6522da1b64d7b + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry.lockfileVersion + ]; + }) + } + ''; + }; missingHashes = ./missing-hashes.json; offlineCache = yarn-berry.fetchYarnBerryDeps { - inherit (finalAttrs) src missingHashes patches; - hash = "sha256-EW0Vc3502xoL4iDr2hPDXQ39McvvsiBWpMKgZRtF44M="; + inherit (finalAttrs) src missingHashes; + hash = "sha256-e5sNNDJVYY4PgbpYtrzxzOL+rtYq1ZwOYglJvZ6OKzo="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/vu/vultisig-cli/yarn-4.14-support.patch b/pkgs/by-name/vu/vultisig-cli/yarn-fix.patch similarity index 89% rename from pkgs/by-name/vu/vultisig-cli/yarn-4.14-support.patch rename to pkgs/by-name/vu/vultisig-cli/yarn-fix.patch index acf6feee69fe..99385ae64a32 100644 --- a/pkgs/by-name/vu/vultisig-cli/yarn-4.14-support.patch +++ b/pkgs/by-name/vu/vultisig-cli/yarn-fix.patch @@ -17,6 +17,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10c0 diff --git a/pkgs/by-name/vz/vzvm/package.nix b/pkgs/by-name/vz/vzvm/package.nix index 1d977008a91d..0dd81712992d 100644 --- a/pkgs/by-name/vz/vzvm/package.nix +++ b/pkgs/by-name/vz/vzvm/package.nix @@ -2,12 +2,12 @@ lib, fetchFromGitHub, darwin, + stdenv, swift, - swiftPackages, nix-update-script, }: -swiftPackages.stdenv.mkDerivation (finalAttrs: { +stdenv.mkDerivation (finalAttrs: { pname = "vzvm"; version = "1.0.0"; diff --git a/pkgs/by-name/wa/waybar/package.nix b/pkgs/by-name/wa/waybar/package.nix index c7f454a67efc..e1a58ed3d510 100644 --- a/pkgs/by-name/wa/waybar/package.nix +++ b/pkgs/by-name/wa/waybar/package.nix @@ -22,7 +22,7 @@ libmpdclient, libnl, libpulseaudio, - libsigcxx, + libsigcxx_2_0, libxkbcommon, meson, ncurses, @@ -123,7 +123,7 @@ stdenv.mkDerivation (finalAttrs: { gtk-layer-shell gtkmm3 jsoncpp - libsigcxx + libsigcxx_2_0 libxkbcommon spdlog wayland diff --git a/pkgs/by-name/wo/workrave/package.nix b/pkgs/by-name/wo/workrave/package.nix index 9a679a3636ca..240d6f80ec65 100644 --- a/pkgs/by-name/wo/workrave/package.nix +++ b/pkgs/by-name/wo/workrave/package.nix @@ -16,7 +16,7 @@ libxtst, gobject-introspection, glib, - glibmm, + glibmm_2_4, gtkmm3, atk, pango, @@ -26,7 +26,7 @@ dbus, dbus-glib, gst_all_1, - libsigcxx, + libsigcxx_2_0, boost, python3Packages, }: @@ -61,7 +61,7 @@ stdenv.mkDerivation (finalAttrs: { libxscrnsaver libxtst glib - glibmm + glibmm_2_4 gtkmm3 atk pango @@ -73,7 +73,7 @@ stdenv.mkDerivation (finalAttrs: { gst_all_1.gstreamer gst_all_1.gst-plugins-base gst_all_1.gst-plugins-good - libsigcxx + libsigcxx_2_0 boost ]; diff --git a/pkgs/by-name/x1/x16/package.nix b/pkgs/by-name/x1/x16/package.nix index b1114d51b5fe..f1226c2f2bc9 100644 --- a/pkgs/by-name/x1/x16/package.nix +++ b/pkgs/by-name/x1/x16/package.nix @@ -7,6 +7,7 @@ callPackage, zlib, nix-update-script, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -30,6 +31,9 @@ stdenv.mkDerivation (finalAttrs: { }) ]; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + postPatch = '' substituteInPlace Makefile \ --replace-fail '/bin/echo' 'echo' diff --git a/pkgs/by-name/xb/xbps/package.nix b/pkgs/by-name/xb/xbps/package.nix index 6f3e1ef231ea..b343f27c4909 100644 --- a/pkgs/by-name/xb/xbps/package.nix +++ b/pkgs/by-name/xb/xbps/package.nix @@ -7,6 +7,7 @@ zlib, openssl, libarchive, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -33,6 +34,23 @@ stdenv.mkDerivation (finalAttrs: { patches = [ ./cert-paths.patch + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/void-linux/xbps/commit/7d02b79d3d7e0bf644adf8b412e76dba1b1fdce1.patch"; + hash = "sha256-iUNBmkkfR02/EFDkax/ZpE7oM+5IVDMmD0FYz7p0dQ4="; + }) + (fetchpatch { + url = "https://github.com/void-linux/xbps/commit/9a8002c5688c3cdda700b022bf432b4426d64042.patch"; + hash = "sha256-/94HKeyv9LaQv6QHE0CqmM1ajBOSNt9Sfh0XKV0RLMQ="; + }) + (fetchpatch { + url = "https://github.com/void-linux/xbps/commit/7f2f10300f235639c5880bea1e4b14245fd5fbda.patch"; + hash = "sha256-iZXiNYrSFaP55qyzefc3hqJ+SoIOsFILqnra6u5iGpM="; + }) + (fetchpatch { + url = "https://github.com/void-linux/xbps/commit/84f6a1be26348c265afedebe9cea958424b0aabf.patch"; + hash = "sha256-WDsGkI+3JnJskM+UKjI/UZP6ypMCd5+3rYtlQgQEr40="; + }) ]; env.NIX_CFLAGS_COMPILE = "-Wno-error=unused-result -Wno-error=deprecated-declarations"; diff --git a/pkgs/by-name/xc/xcodegen/package.nix b/pkgs/by-name/xc/xcodegen/package.nix index 2cc6595d8361..7fa42c144709 100644 --- a/pkgs/by-name/xc/xcodegen/package.nix +++ b/pkgs/by-name/xc/xcodegen/package.nix @@ -1,12 +1,12 @@ { lib, - swiftPackages, swift, swiftpm, swiftpm2nix, fetchFromGitHub, versionCheckHook, nix-update-script, + stdenv, }: let @@ -14,7 +14,7 @@ let generated = swiftpm2nix.helpers ./nix; in -swiftPackages.stdenv.mkDerivation (finalAttrs: { +stdenv.mkDerivation (finalAttrs: { pname = "xcodegen"; version = "2.44.1"; @@ -33,10 +33,6 @@ swiftPackages.stdenv.mkDerivation (finalAttrs: { swiftpm ]; - buildInputs = [ - swiftPackages.XCTest - ]; - # The helper provides a configure snippet that will prepare all dependencies # in the correct place, where SwiftPM expects them. configurePhase = generated.configure + '' diff --git a/pkgs/by-name/xc/xcodes/package.nix b/pkgs/by-name/xc/xcodes/package.nix index 1fad5edafa02..9c8f30b64131 100644 --- a/pkgs/by-name/xc/xcodes/package.nix +++ b/pkgs/by-name/xc/xcodes/package.nix @@ -1,7 +1,7 @@ { lib, fetchFromGitHub, - swiftPackages, + stdenv, swift, swiftpm, swiftpm2nix, @@ -10,7 +10,6 @@ }: let generated = swiftpm2nix.helpers ./generated; - stdenv = swiftPackages.stdenv; in stdenv.mkDerivation (finalAttrs: { pname = "xcodes"; diff --git a/pkgs/by-name/xd/xdg-dbus-proxy/package.nix b/pkgs/by-name/xd/xdg-dbus-proxy/package.nix index 098785d5556c..e580314238f5 100644 --- a/pkgs/by-name/xd/xdg-dbus-proxy/package.nix +++ b/pkgs/by-name/xd/xdg-dbus-proxy/package.nix @@ -14,11 +14,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "xdg-dbus-proxy"; - version = "0.1.7"; + version = "0.1.8"; src = fetchurl { url = "https://github.com/flatpak/xdg-dbus-proxy/releases/download/${finalAttrs.version}/xdg-dbus-proxy-${finalAttrs.version}.tar.xz"; - hash = "sha256-OtPSe6V04XisteTUOLo2rOJeNWT4mcNvMcVvgsetu+c="; + hash = "sha256-tmML0k+BYbDiVG0qy7AUo7Mkn1wNdfKoY63omLkDTT0="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/xf/xfstests/package.nix b/pkgs/by-name/xf/xfstests/package.nix index 97cc46233cd9..b3aeb33f7fc9 100644 --- a/pkgs/by-name/xf/xfstests/package.nix +++ b/pkgs/by-name/xf/xfstests/package.nix @@ -10,6 +10,7 @@ coreutils, e2fsprogs, fetchzip, + fetchpatch, fio, gawk, keyutils, @@ -45,6 +46,14 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-jnwEcGUSkKW9afGQTUsWR7CNQECWz/sYdSaDx0hY1Uo="; }; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://lore.kernel.org/fstests/20260813150846.280498-1-zlang@kernel.org/raw"; + hash = "sha256-NOPMo0cdKKoPMwG53BdTe+G+vDXb+2ICGYFRs4g+edQ="; + }) + ]; + nativeBuildInputs = [ autoconf automake @@ -65,7 +74,7 @@ stdenv.mkDerivation (finalAttrs: { hardeningDisable = [ "format" ]; enableParallelBuilding = true; - patchPhase = '' + postPatch = '' substituteInPlace Makefile \ --replace-fail "cp include/install-sh ." "cp -f include/install-sh ." diff --git a/pkgs/by-name/xk/xkb-switch-i3/package.nix b/pkgs/by-name/xk/xkb-switch-i3/package.nix index b7884c88e950..a2a3e51e720b 100644 --- a/pkgs/by-name/xk/xkb-switch-i3/package.nix +++ b/pkgs/by-name/xk/xkb-switch-i3/package.nix @@ -5,7 +5,7 @@ fetchFromGitHub, i3, jsoncpp, - libsigcxx, + libsigcxx_2_0, libx11, libxkbfile, pkg-config, @@ -45,7 +45,7 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ i3 jsoncpp - libsigcxx + libsigcxx_2_0 libx11 libxkbfile ]; diff --git a/pkgs/by-name/xt/xtuner/package.nix b/pkgs/by-name/xt/xtuner/package.nix index ed94f34e9a20..4375e8750231 100644 --- a/pkgs/by-name/xt/xtuner/package.nix +++ b/pkgs/by-name/xt/xtuner/package.nix @@ -8,7 +8,7 @@ libx11, libjack2, liblo, - libsigcxx, + libsigcxx_2_0, zita-resampler, fftwFloat, }: @@ -42,7 +42,7 @@ stdenv.mkDerivation (finalAttrs: { libx11 libjack2 liblo - libsigcxx + libsigcxx_2_0 zita-resampler fftwFloat ]; diff --git a/pkgs/by-name/xz/xz/package.nix b/pkgs/by-name/xz/xz/package.nix index 1313bc1779a2..83a1358cd2c1 100644 --- a/pkgs/by-name/xz/xz/package.nix +++ b/pkgs/by-name/xz/xz/package.nix @@ -15,13 +15,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "xz"; - version = "5.8.3"; + version = "5.8.4"; src = fetchurl { url = with finalAttrs; "https://github.com/tukaani-project/xz/releases/download/v${version}/xz-${version}.tar.xz"; - hash = "sha256-//H/zysNqE0wihTeUToaoj1OmqNGTRfmS5cUv90Lv7Y="; + hash = "sha256-TOJAOP1CIeDRO8Gi3npNtW6QuSs791Mh9sFL5z9l3ks="; }; strictDeps = true; diff --git a/pkgs/by-name/ya/yarn-berry/fetcher/berry-4-offline.patch b/pkgs/by-name/ya/yarn-berry/fetcher/berry-4-offline.patch index 7ebf48b64233..4ba700157bd7 100644 --- a/pkgs/by-name/ya/yarn-berry/fetcher/berry-4-offline.patch +++ b/pkgs/by-name/ya/yarn-berry/fetcher/berry-4-offline.patch @@ -6,7 +6,7 @@ index 90ba55349..ef5368c1b 100644 for (const rule of LOCKFILE_MIGRATION_RULES) { if (rule.selector(lockfileLastVersion) && typeof configuration.sources.get(rule.name) === `undefined`) { -+ throw new Error(`Tried to use yarn-berry_4.yarnConfigHook (nixpkgs) which expects lockfile version 8, but found lockfile version ${lockfileLastVersion}`); ++ throw new Error(`Tried to use yarn-berry_4.yarnConfigHook (nixpkgs) which expects lockfile version @YARN_LOCKFILE_VERSION_PLACEHOLDER@, but found lockfile version ${lockfileLastVersion}`); configuration.use(``, {[rule.name]: rule.value}, project.cwd, {overwrite: true}); newSettings[rule.name] = rule.value; } diff --git a/pkgs/by-name/ya/yarn-berry/fetcher/default.nix b/pkgs/by-name/ya/yarn-berry/fetcher/default.nix index 5392c6450ccd..2aec5c4f356e 100644 --- a/pkgs/by-name/ya/yarn-berry/fetcher/default.nix +++ b/pkgs/by-name/ya/yarn-berry/fetcher/default.nix @@ -40,6 +40,7 @@ let berryOfflinePatches = [ (replaceVars ./berry-4-offline.patch { yarnv1 = lib.getExe yarn; + YARN_LOCKFILE_VERSION_PLACEHOLDER = yarn-berry.lockfileVersion; }) ]; diff --git a/pkgs/by-name/ya/yarn-berry/package.nix b/pkgs/by-name/ya/yarn-berry/package.nix index 88d0538d74de..fdf5601b4e6e 100644 --- a/pkgs/by-name/ya/yarn-berry/package.nix +++ b/pkgs/by-name/ya/yarn-berry/package.nix @@ -8,20 +8,24 @@ stdenv, testers, yarn, + gitMinimal, callPackage, berryVersion ? 4, }: let - version_4 = "4.14.1"; + version_4 = "4.18.0"; version_3 = "3.8.7"; - hash_4 = "sha256-0UnU5jRSUFMw+WowvXqYqaaN1ZbZAdLLJ6LPyuK6iCc="; + hash_4 = "sha256-pO89wh17cW9/RGKjo70yiefr+9nlJAQs4ZEdUnzdgQM="; hash_3 = "sha256-vRrk+Fs/7dZha3h7yI5NpMfd1xezesnigpFgTRCACZo="; + lockfileVersion_4 = "10"; + lockfileVersion_3 = "6"; in stdenv.mkDerivation (finalAttrs: { pname = "yarn-berry"; version = if berryVersion == 4 then version_4 else version_3; + lockfileVersion = if berryVersion == 4 then lockfileVersion_4 else lockfileVersion_3; src = fetchFromGitHub { owner = "yarnpkg"; @@ -37,6 +41,7 @@ stdenv.mkDerivation (finalAttrs: { nativeBuildInputs = [ nodejs yarn + gitMinimal unzip zip ]; @@ -64,6 +69,28 @@ stdenv.mkDerivation (finalAttrs: { runHook postBuild ''; + # Confirms that lockfileVersion matches the one defined above + doCheck = true; + checkPhase = '' + runHook preCheck + + YARN_JS_PATH=$(pwd)/packages/yarnpkg-cli/bundles/yarn.js + TEST_DIR=$(mktemp -d) + export HOME=$(mktemp -d) + git config --global user.name nixbld + git config --global user.email nixbld@localhost + cd $TEST_DIR + + node $YARN_JS_PATH config set --home enableTelemetry 0 + node $YARN_JS_PATH init + node $YARN_JS_PATH install # Yarn 3 doesn't run install during init + grep -Pzq '\n__metadata:\n version: ${finalAttrs.lockfileVersion}\n' yarn.lock + + cd - + + runHook postCheck + ''; + installPhase = '' runHook preInstall install -Dm 755 ./packages/yarnpkg-cli/bundles/yarn.js "$out/bin/yarn" diff --git a/pkgs/by-name/yt/ytmdesktop/package.nix b/pkgs/by-name/yt/ytmdesktop/package.nix index 044aa6a8c6eb..6b8fdec4fb50 100644 --- a/pkgs/by-name/yt/ytmdesktop/package.nix +++ b/pkgs/by-name/yt/ytmdesktop/package.nix @@ -9,6 +9,7 @@ makeWrapper, nodejs, yarn-berry_4, + substitute, zip, electron, @@ -34,9 +35,22 @@ stdenv.mkDerivation (finalAttrs: { cd $out git rev-parse HEAD > .COMMIT find -name .git -print0 | xargs -0 rm -rf + + # Remove after upstream updates to Yarn 4.14 + # https://github.com/ytmdesktop/ytmdesktop/blob/v2.0.11/package.json#L77 + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry.lockfileVersion + ]; + }) + } ''; - hash = "sha256-fT5UdJ9YYK3hXC8GkEeJ/LK1bCyXofcKA0aCJUnjZdk="; + hash = "sha256-48PeFM6azfPJBc3c6gNRE6mQnfYWMkMI9WQOcnFQCuA="; }; patches = [ @@ -44,10 +58,6 @@ stdenv.mkDerivation (finalAttrs: { # use the .COMMIT file generated in the fetcher FOD ./git-rev-parse.patch - # Remove after upstream updates to Yarn 4.14 - # https://github.com/ytmdesktop/ytmdesktop/blob/v2.0.11/package.json#L77 - ./yarn-4.14-support.patch - # zip extraction fails on newer nodejs versions without this fix # generated by running `yarn set resolution yauzl@npm:^2.10.0 npm:^3.3.1` ./bump-yauzl.patch @@ -65,7 +75,7 @@ stdenv.mkDerivation (finalAttrs: { yarnOfflineCache = yarn-berry.fetchYarnBerryDeps { inherit (finalAttrs) src missingHashes patches; - hash = "sha256-fpvBE4QZcDaWGgqU3jQlOe+bOLtnDEVNR4IuKBo35BQ="; + hash = "sha256-oDouMkHjvENQrGBHfgGC/+ZBRJSAdXR+f2Fb0fkM9Sw="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/yt/ytmdesktop/yarn-4.14-support.patch b/pkgs/by-name/yt/ytmdesktop/yarn-fix.patch similarity index 89% rename from pkgs/by-name/yt/ytmdesktop/yarn-4.14-support.patch rename to pkgs/by-name/yt/ytmdesktop/yarn-fix.patch index 577c6d19d696..b7de21d69201 100644 --- a/pkgs/by-name/yt/ytmdesktop/yarn-4.14-support.patch +++ b/pkgs/by-name/yt/ytmdesktop/yarn-fix.patch @@ -17,6 +17,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10c0 diff --git a/pkgs/by-name/zo/zookeeper_mt/package.nix b/pkgs/by-name/zo/zookeeper_mt/package.nix index 44dc1fdf8cd8..4d7d4eaf5986 100644 --- a/pkgs/by-name/zo/zookeeper_mt/package.nix +++ b/pkgs/by-name/zo/zookeeper_mt/package.nix @@ -21,6 +21,9 @@ stdenv.mkDerivation rec { sourceRoot = "apache-${zookeeper.pname}-${version}/zookeeper-client/zookeeper-client-c"; + # Fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + nativeBuildInputs = [ autoreconfHook pkg-config diff --git a/pkgs/by-name/zu/zutty/package.nix b/pkgs/by-name/zu/zutty/package.nix index 06f975b68420..5a6f7ebfb87d 100644 --- a/pkgs/by-name/zu/zutty/package.nix +++ b/pkgs/by-name/zu/zutty/package.nix @@ -57,5 +57,6 @@ stdenv.mkDerivation (finalAttrs: { license = lib.licenses.gpl3Plus; maintainers = [ lib.maintainers.rolfschr ]; platforms = lib.platforms.linux; + broken = true; # Added 2026-09-19, fails with latest glibc }; }) diff --git a/pkgs/development/compilers/dotnet/source/vmr.nix b/pkgs/development/compilers/dotnet/source/vmr.nix index 6ea56283a780..593047ef9b73 100644 --- a/pkgs/development/compilers/dotnet/source/vmr.nix +++ b/pkgs/development/compilers/dotnet/source/vmr.nix @@ -16,8 +16,8 @@ glibcLocales, ensureNewerSourcesForZipFilesHook, darwin, + swift, xcbuild, - swiftPackages, openssl, getconf, python3, @@ -47,7 +47,6 @@ let targetPlatform ; inherit (stdenv.hostPlatform) isLinux isDarwin; - inherit (swiftPackages) swift; releaseManifest = lib.importJSON releaseManifestFile; inherit (releaseManifest) sourceRepository tag; diff --git a/pkgs/development/compilers/dotnet/wrapper.nix b/pkgs/development/compilers/dotnet/wrapper.nix index b81cc38e28df..9aad807a4d0e 100644 --- a/pkgs/development/compilers/dotnet/wrapper.nix +++ b/pkgs/development/compilers/dotnet/wrapper.nix @@ -12,7 +12,7 @@ installShellFiles, callPackage, zlib, - swiftPackages, + swift, icu, lndir, replaceVars, @@ -226,13 +226,13 @@ stdenvNoCC.mkDerivation (finalAttrs: { // lib.optionalAttrs finalAttrs.finalPackage.hasILCompiler { aot = mkConsoleTest { name = "aot"; - stdenv = if stdenv.hostPlatform.isDarwin then swiftPackages.stdenv else stdenv; + inherit stdenv; usePackageSource = true; buildInputs = [ zlib ] ++ lib.optionals stdenv.hostPlatform.isDarwin [ - swiftPackages.swift + swift darwin.ICU ]; build = '' diff --git a/pkgs/development/compilers/ghc/common-hadrian.nix b/pkgs/development/compilers/ghc/common-hadrian.nix index 51fc88540c9c..d3049455a1d6 100644 --- a/pkgs/development/compilers/ghc/common-hadrian.nix +++ b/pkgs/development/compilers/ghc/common-hadrian.nix @@ -254,21 +254,14 @@ "sha256-vtjT+TL/7sYPu4rcVV3xCqJQ+uqkyBbf9l0KIi97j/0="; }) ] - ++ - lib.optionals - ( - (stdenv.hostPlatform.isRiscV64 || stdenv.hostPlatform.isLoongArch64) - && lib.versionAtLeast version "9.10" - && lib.versionOlder version "9.12" - ) - [ - # Fix LLVM backend split sections causing bin/out reference cycles: https://gitlab.haskell.org/ghc/ghc/-/issues/26770 - (fetchpatch { - name = "ghc-llvm-fix-split-sections.patch"; - url = "https://gitlab.haskell.org/ghc/ghc/-/commit/b18b2c42c32488ad6d3480a56a1fcd753cad2023.patch"; - hash = "sha256-kEgZARwcdnWcvjuTfyqnn8V1zAUczZN0qiy/1WbCy1s="; - }) - ] + ++ lib.optionals (lib.versionAtLeast version "9.10" && lib.versionOlder version "9.12") [ + # Fix LLVM backend split sections causing bin/out reference cycles: https://gitlab.haskell.org/ghc/ghc/-/issues/26770 + (fetchpatch { + name = "ghc-llvm-fix-split-sections.patch"; + url = "https://gitlab.haskell.org/ghc/ghc/-/commit/b18b2c42c32488ad6d3480a56a1fcd753cad2023.patch"; + hash = "sha256-kEgZARwcdnWcvjuTfyqnn8V1zAUczZN0qiy/1WbCy1s="; + }) + ] ++ lib.optionals (lib.versionOlder version "9.12") [ (fetchpatch { name = "ghc-rts-Fix-compile-on-powerpc64-elf-v1.patch"; diff --git a/pkgs/development/compilers/go/1.26.nix b/pkgs/development/compilers/go/1.26.nix index ccb5b67f17af..0a2708bba8da 100644 --- a/pkgs/development/compilers/go/1.26.nix +++ b/pkgs/development/compilers/go/1.26.nix @@ -25,11 +25,11 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "go"; - version = "1.26.7"; + version = "1.26.8"; src = fetchurl { url = "https://go.dev/dl/go${finalAttrs.version}.src.tar.gz"; - hash = "sha256-DtJOrHVRBQhbif6cq8J0K5GgrXuUtZ0602SRjryJVq0="; + hash = "sha256-Tjm5jkL5RvoFrIvFtxh335fb23y7Gnd7VBZnrXEX/S4="; }; strictDeps = true; diff --git a/pkgs/development/compilers/go/binary.nix b/pkgs/development/compilers/go/binary.nix index 2e02355dceec..b4cc4b59b36a 100644 --- a/pkgs/development/compilers/go/binary.nix +++ b/pkgs/development/compilers/go/binary.nix @@ -1,14 +1,17 @@ { lib, - stdenv, + stdenvNoCC, fetchurl, version, hashes, + bashNonInteractive, }: let - platform = with stdenv.hostPlatform.go; "${GOOS}-${if GOARCH == "arm" then "armv6l" else GOARCH}"; + platform = + with stdenvNoCC.hostPlatform.go; + "${GOOS}-${if GOARCH == "arm" then "armv6l" else GOARCH}"; in -stdenv.mkDerivation { +stdenvNoCC.mkDerivation { name = "go-${version}-${platform}-bootstrap"; src = fetchurl { @@ -16,8 +19,14 @@ stdenv.mkDerivation { sha256 = hashes.${platform} or (throw "Missing Go bootstrap hash for platform ${platform}"); }; + buildInputs = [ + bashNonInteractive + ]; + # We must preserve the signature on Darwin - dontStrip = stdenv.hostPlatform.isDarwin; + dontStrip = stdenvNoCC.hostPlatform.isDarwin; + + strictDeps = true; installPhase = '' runHook preInstall @@ -27,6 +36,8 @@ stdenv.mkDerivation { runHook postInstall ''; + __structuredAttrs = true; + meta = { sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ]; changelog = "https://go.dev/doc/devel/release#go${lib.versions.majorMinor version}"; diff --git a/pkgs/development/compilers/llvm/18/lldb/backport-ParseTrieEntries-fixes.patch b/pkgs/development/compilers/llvm/18/lldb/backport-ParseTrieEntries-fixes.patch new file mode 100644 index 000000000000..f165c7e9ebbe --- /dev/null +++ b/pkgs/development/compilers/llvm/18/lldb/backport-ParseTrieEntries-fixes.patch @@ -0,0 +1,124 @@ +diff --git a/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp b/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp +index 2c7005449f..e0c426afa0 100644 +--- a/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp ++++ b/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp +@@ -137,6 +137,14 @@ + using namespace lldb_private; + using namespace llvm::MachO; + ++/// Upper bound on the length of a symbol name assembled from export-trie edge ++/// labels. A corrupt trie can encode an edge label whose terminator is far ++/// away in the trie data, so a single label is many megabytes long; appending ++/// it to the running name would otherwise request an unbounded allocation. No ++/// legitimate symbol name comes close to this size. Also 1 MiB is the ++/// symbol length limit in ld. ++static constexpr size_t kMaxTrieSymbolNameLength = 1 << 20; // 1 MiB ++ + LLDB_PLUGIN_DEFINE(ObjectFileMachO) + + static void PrintRegisterValue(RegisterContext *reg_ctx, const char *name, +@@ -2050,15 +2058,21 @@ + } + }; + +-static bool ParseTrieEntries(DataExtractor &data, lldb::offset_t offset, +- const bool is_arm, addr_t text_seg_base_addr, +- std::vector &nameSlices, +- std::set &resolver_addresses, +- std::vector &reexports, +- std::vector &ext_symbols) { ++static bool ParseTrieEntriesImpl(DataExtractor &data, lldb::offset_t offset, ++ const bool is_arm, addr_t text_seg_base_addr, ++ std::string &prefix, ++ std::set &resolver_addresses, ++ std::vector &reexports, ++ std::vector &ext_symbols, ++ std::set &visited_nodes) { + if (!data.ValidOffset(offset)) + return true; + ++ // Every node in a well-formed trie is reached by exactly one path, so a node ++ // offset seen twice means the trie is corrupt. ++ if (!visited_nodes.insert(offset).second) ++ return false; ++ + // Terminal node -- end of a branch, possibly add this to + // the symbol table or resolver table. + const uint64_t terminalSize = data.GetULEB128(&offset); +@@ -2098,14 +2112,9 @@ + add_this_entry = true; + } + if (add_this_entry) { +- std::string name; +- if (!nameSlices.empty()) { +- for (auto name_slice : nameSlices) +- name.append(name_slice.data(), name_slice.size()); +- } +- if (name.size() > 1) { ++ if (prefix.size() > 1) { + // Skip the leading '_' +- e.entry.name.SetCStringWithLength(name.c_str() + 1, name.size() - 1); ++ e.entry.name.SetString(llvm::StringRef(prefix).drop_front()); + } + if (import_name) { + // Skip the leading '_' +@@ -2126,23 +2135,36 @@ + const uint8_t childrenCount = data.GetU8(&children_offset); + for (uint8_t i = 0; i < childrenCount; ++i) { + const char *cstr = data.GetCStr(&children_offset); +- if (cstr) +- nameSlices.push_back(llvm::StringRef(cstr)); +- else ++ if (!cstr) + return false; // Corrupt data ++ if (prefix.size() + llvm::StringRef(cstr).size() > kMaxTrieSymbolNameLength) ++ return false; // Corrupt data: implausibly long symbol name. ++ const size_t prevSize = prefix.size(); ++ prefix.append(cstr); + lldb::offset_t childNodeOffset = data.GetULEB128(&children_offset); +- if (childNodeOffset) { +- if (!ParseTrieEntries(data, childNodeOffset, is_arm, text_seg_base_addr, +- nameSlices, resolver_addresses, reexports, +- ext_symbols)) { +- return false; +- } +- } +- nameSlices.pop_back(); ++ // A child offset of 0 points back at the root; like any other repeated ++ // offset it is a cycle, which ParseTrieEntriesImpl rejects as corrupt. ++ if (!ParseTrieEntriesImpl(data, childNodeOffset, is_arm, text_seg_base_addr, ++ prefix, resolver_addresses, reexports, ++ ext_symbols, visited_nodes)) ++ return false; ++ prefix.resize(prevSize); + } + return true; + } + ++static bool ParseTrieEntries( ++ DataExtractor &data, const bool is_arm, lldb::addr_t text_seg_base_addr, ++ std::set &resolver_addresses, ++ std::vector &reexports, ++ std::vector &ext_symbols) { ++ lldb::offset_t offset = 0; ++ std::set visited_nodes; ++ std::string prefix; ++ return ParseTrieEntriesImpl(data, offset, is_arm, text_seg_base_addr, prefix, ++ resolver_addresses, reexports, ext_symbols, ++ visited_nodes); ++} + static SymbolType GetSymbolType(const char *&symbol_name, + bool &demangled_is_synthesized, + const SectionSP &text_section_sp, +@@ -2666,9 +2688,8 @@ + lldb::addr_t text_segment_file_addr = LLDB_INVALID_ADDRESS; + if (text_segment_sp) + text_segment_file_addr = text_segment_sp->GetFileAddress(); +- std::vector nameSlices; +- ParseTrieEntries(dyld_trie_data, 0, is_arm, text_segment_file_addr, +- nameSlices, resolver_addresses, reexport_trie_entries, ++ ParseTrieEntries(dyld_trie_data, is_arm, text_segment_file_addr, ++ resolver_addresses, reexport_trie_entries, + external_sym_trie_entries); + } + diff --git a/pkgs/development/compilers/llvm/18/llvm/backport-minimal-arm64e_x1-support.patch b/pkgs/development/compilers/llvm/18/llvm/backport-minimal-arm64e_x1-support.patch new file mode 100644 index 000000000000..3547062520c5 --- /dev/null +++ b/pkgs/development/compilers/llvm/18/llvm/backport-minimal-arm64e_x1-support.patch @@ -0,0 +1,205 @@ +--- llvm/include/llvm/BinaryFormat/MachO.h ++++ llvm/include/llvm/BinaryFormat/MachO.h +@@ -1641,6 +1641,7 @@ + CPU_SUBTYPE_ARM64_ALL = 0, + CPU_SUBTYPE_ARM64_V8 = 1, + CPU_SUBTYPE_ARM64E = 2, ++ CPU_SUBTYPE_ARM64E_X1 = 12, + }; + + enum CPUSubTypeARM64_32 { CPU_SUBTYPE_ARM64_32_V8 = 1 }; +--- llvm/include/llvm/TargetParser/Triple.h ++++ llvm/include/llvm/TargetParser/Triple.h +@@ -147,6 +147,7 @@ + ARMSubArch_v4t, + + AArch64SubArch_arm64e, ++ AArch64SubArch_arm64e_x1, + AArch64SubArch_arm64ec, + + KalimbaSubArch_v3, +@@ -1008,6 +1009,11 @@ + getSubArch() == Triple::AArch64SubArch_arm64e; + } + ++ bool isArm64e_x1() const { ++ return getArch() == Triple::aarch64 && ++ getSubArch() == Triple::AArch64SubArch_arm64e_x1; ++ } ++ + /// Tests whether the target is X32. + bool isX32() const { + EnvironmentType Env = getEnvironment(); +--- llvm/include/llvm/TextAPI/Architecture.def ++++ llvm/include/llvm/TextAPI/Architecture.def +@@ -37,7 +37,7 @@ + /// + ARCHINFO(arm64, arm64, MachO::CPU_TYPE_ARM64, MachO::CPU_SUBTYPE_ARM64_ALL, 64) + ARCHINFO(arm64e, arm64e, MachO::CPU_TYPE_ARM64, MachO::CPU_SUBTYPE_ARM64E, 64) +- ++ARCHINFO(arm64e_x1, arm64e.x1, MachO::CPU_TYPE_ARM64, MachO::CPU_SUBTYPE_ARM64E_X1, 64) + + /// + /// ARM64_32 architectures sorted by cpu sub type id +--- llvm/lib/BinaryFormat/MachO.cpp ++++ llvm/lib/BinaryFormat/MachO.cpp +@@ -60,6 +60,8 @@ + return (MachO::CPUSubTypeARM64)MachO::CPU_SUBTYPE_ARM64_32_V8; + if (T.isArm64e()) + return MachO::CPU_SUBTYPE_ARM64E; ++ if (T.isArm64e_x1()) ++ return MachO::CPU_SUBTYPE_ARM64E_X1; + + return MachO::CPU_SUBTYPE_ARM64_ALL; + } +--- llvm/lib/Object/MachOObjectFile.cpp ++++ llvm/lib/Object/MachOObjectFile.cpp +@@ -2807,6 +2807,12 @@ + if (ArchFlag) + *ArchFlag = "arm64e"; + return Triple("arm64e-apple-darwin"); ++ case MachO::CPU_SUBTYPE_ARM64E_X1: ++ if (McpuDefault) ++ *McpuDefault = "apple-a20"; ++ if (ArchFlag) ++ *ArchFlag = "arm64e.x1"; ++ return Triple("arm64e.x1-apple-darwin"); + default: + return Triple(); + } +--- llvm/lib/TargetParser/Triple.cpp ++++ llvm/lib/TargetParser/Triple.cpp +@@ -114,6 +114,8 @@ + return "arm64ec"; + if (SubArch == AArch64SubArch_arm64e) + return "arm64e"; ++ if (SubArch == AArch64SubArch_arm64e_x1) ++ return "arm64e.x1"; + break; + default: + break; +@@ -515,6 +517,7 @@ + .Case("arm64", Triple::aarch64) + .Case("arm64_32", Triple::aarch64_32) + .Case("arm64e", Triple::aarch64) ++ .Case("arm64e.x1", Triple::aarch64) + .Case("arm64ec", Triple::aarch64) + .Case("arm", Triple::arm) + .Case("armeb", Triple::armeb) +@@ -720,6 +723,8 @@ + + if (SubArchName == "arm64e") + return Triple::AArch64SubArch_arm64e; ++ if (SubArchName == "arm64e.x1") ++ return Triple::AArch64SubArch_arm64e_x1; + + if (SubArchName == "arm64ec") + return Triple::AArch64SubArch_arm64ec; +--- llvm/test/tools/llvm-readobj/MachO/file-headers-arm64.test ++++ llvm/test/tools/llvm-readobj/MachO/file-headers-arm64.test +@@ -13,6 +13,11 @@ + # RUN: llvm-readobj -h %t.arm64e \ + # RUN: | FileCheck %s --strict-whitespace --match-full-lines -DFILE=%t.arm64e --check-prefix=ARM64 -DSUBTYPE="CPU_SUBTYPE_ARM64E (0x2)" + ++## Check subtype Arm64E.X1: ++# RUN: yaml2obj %s -o %t.arm64e.x1 -DSUBTYPE=0xC ++# RUN: llvm-readobj -h %t.arm64e.x1 \ ++# RUN: | FileCheck %s --strict-whitespace --match-full-lines -DFILE=%t.arm64e.x1 --check-prefix=ARM64 -DSUBTYPE="CPU_SUBTYPE_ARM64E_X1 (0xC)" ++ + # ARM64:File: [[FILE]] + # ARM64-NEXT:Format: Mach-O arm64 + # ARM64-NEXT:Arch: aarch64 +--- llvm/tools/llvm-objdump/MachODump.cpp ++++ llvm/tools/llvm-objdump/MachODump.cpp +@@ -2323,6 +2323,10 @@ + outs() << " cputype CPU_TYPE_ARM64\n"; + outs() << " cpusubtype CPU_SUBTYPE_ARM64E\n"; + break; ++ case MachO::CPU_SUBTYPE_ARM64E_X1: ++ outs() << " cputype CPU_TYPE_ARM64\n"; ++ outs() << " cpusubtype CPU_SUBTYPE_ARM64E_X1\n"; ++ break; + default: + printUnknownCPUType(cputype, cpusubtype); + break; +@@ -8213,6 +8217,9 @@ + case MachO::CPU_SUBTYPE_ARM64E: + outs() << " E"; + break; ++ case MachO::CPU_SUBTYPE_ARM64E_X1: ++ outs() << " E.X1"; ++ break; + default: + outs() << format(" %10d", cpusubtype & ~MachO::CPU_SUBTYPE_MASK); + break; +--- llvm/tools/llvm-readobj/MachODumper.cpp ++++ llvm/tools/llvm-readobj/MachODumper.cpp +@@ -170,6 +170,7 @@ + LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64_ALL), + LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64_V8), + LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64E), ++ LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64E_X1), + }; + + const EnumEntry MachOHeaderCpuSubtypesSPARC[] = { +--- llvm/unittests/BinaryFormat/MachOTest.cpp ++++ llvm/unittests/BinaryFormat/MachOTest.cpp +@@ -57,6 +57,7 @@ + CHECK_CPUTYPE("thumbv7-apple-darwin", MachO::CPU_TYPE_ARM); + CHECK_CPUTYPE("arm64-apple-darwin", MachO::CPU_TYPE_ARM64); + CHECK_CPUTYPE("arm64e-apple-darwin", MachO::CPU_TYPE_ARM64); ++ CHECK_CPUTYPE("arm64e.x1-apple-darwin", MachO::CPU_TYPE_ARM64); + CHECK_CPUTYPE("arm64_32-apple-darwin", MachO::CPU_TYPE_ARM64_32); + + { +@@ -98,6 +99,7 @@ + CHECK_CPUSUBTYPE("thumbv6-apple-darwin", MachO::CPU_SUBTYPE_ARM_V6); + CHECK_CPUSUBTYPE("arm64-apple-darwin", MachO::CPU_SUBTYPE_ARM64_ALL); + CHECK_CPUSUBTYPE("arm64e-apple-darwin", MachO::CPU_SUBTYPE_ARM64E); ++ CHECK_CPUSUBTYPE("arm64e.x1-apple-darwin", MachO::CPU_SUBTYPE_ARM64E_X1); + CHECK_CPUSUBTYPE("arm64_32-apple-darwin", MachO::CPU_SUBTYPE_ARM64_32_V8); + + { +--- /dev/null ++++ lld/test/MachO/arm64-x1.s +@@ -0,0 +1,20 @@ ++# REQUIRES: aarch64 ++ ++## Test that arm64.x1-macos is ignored instead of causing an error. ++## linked re-exported dylibs that only declare arm64e-macos targets, even if targeting arm64. ++# arm64 and arm64e are ABI compatible (same CPU type), and ld64 accepts this. ++ ++# RUN: rm -rf %t; split-file --no-leading-lines %s %t ++ ++# RUN: llvm-mc -filetype=obj -triple=arm64-apple-macos -o %t/test.o /dev/null ++ ++# RUN: %no-arg-lld -syslibroot %t/sdk -lSystem -dylib -arch arm64 \ ++# RUN: -platform_version macos 15 26 %t/test.o -o /dev/null ++ ++#--- sdk/usr/lib/libSystem.tbd ++--- !tapi-tbd ++tbd-version: 4 ++targets: [ arm64-macos, arm64e.x1-macos ] ++install-name: '/usr/lib/libSystem.dylib' ++current-version: 0001.001.1 ++... +--- /dev/null ++++ llvm/test/tools/llvm-readobj/macho-arm64e_x1.test +@@ -0,0 +1,17 @@ ++# RUN: yaml2obj %s -o %t.o ++# RUN: llvm-readobj -h %t.o | FileCheck %s ++ ++# CHECK: Magic: Magic64 (0xFEEDFACF) ++# CHECK: CpuType: Arm64 (0x100000C) ++# CHECK: CpuSubType: CPU_SUBTYPE_ARM64E_X1 (0xC) ++ ++--- !mach-o ++FileHeader: ++ magic: 0xFEEDFACF ++ cputype: 0x0100000C ++ cpusubtype: 0x0000000C ++ filetype: 0x00000001 ++ ncmds: 0 ++ sizeofcmds: 0 ++ flags: 0x00000000 ++ reserved: 0x00000000 diff --git a/pkgs/development/compilers/llvm/19/llvm/backport-minimal-arm64e_x1-support.patch b/pkgs/development/compilers/llvm/19/llvm/backport-minimal-arm64e_x1-support.patch new file mode 100644 index 000000000000..aed2b844a0b2 --- /dev/null +++ b/pkgs/development/compilers/llvm/19/llvm/backport-minimal-arm64e_x1-support.patch @@ -0,0 +1,205 @@ +--- llvm/include/llvm/BinaryFormat/MachO.h ++++ llvm/include/llvm/BinaryFormat/MachO.h +@@ -1641,6 +1641,7 @@ + CPU_SUBTYPE_ARM64_ALL = 0, + CPU_SUBTYPE_ARM64_V8 = 1, + CPU_SUBTYPE_ARM64E = 2, ++ CPU_SUBTYPE_ARM64E_X1 = 12, + }; + + enum CPUSubTypeARM64_32 { CPU_SUBTYPE_ARM64_32_V8 = 1 }; +--- llvm/include/llvm/TargetParser/Triple.h ++++ llvm/include/llvm/TargetParser/Triple.h +@@ -147,6 +147,7 @@ + ARMSubArch_v4t, + + AArch64SubArch_arm64e, ++ AArch64SubArch_arm64e_x1, + AArch64SubArch_arm64ec, + + KalimbaSubArch_v3, +@@ -1042,6 +1043,11 @@ + getSubArch() == Triple::AArch64SubArch_arm64e; + } + ++ bool isArm64e_x1() const { ++ return getArch() == Triple::aarch64 && ++ getSubArch() == Triple::AArch64SubArch_arm64e_x1; ++ } ++ + /// Tests whether the target is X32. + bool isX32() const { + EnvironmentType Env = getEnvironment(); +--- llvm/include/llvm/TextAPI/Architecture.def ++++ llvm/include/llvm/TextAPI/Architecture.def +@@ -37,7 +37,7 @@ + /// + ARCHINFO(arm64, arm64, MachO::CPU_TYPE_ARM64, MachO::CPU_SUBTYPE_ARM64_ALL, 64) + ARCHINFO(arm64e, arm64e, MachO::CPU_TYPE_ARM64, MachO::CPU_SUBTYPE_ARM64E, 64) +- ++ARCHINFO(arm64e_x1, arm64e.x1, MachO::CPU_TYPE_ARM64, MachO::CPU_SUBTYPE_ARM64E_X1, 64) + + /// + /// ARM64_32 architectures sorted by cpu sub type id +--- llvm/lib/BinaryFormat/MachO.cpp ++++ llvm/lib/BinaryFormat/MachO.cpp +@@ -60,6 +60,8 @@ + return (MachO::CPUSubTypeARM64)MachO::CPU_SUBTYPE_ARM64_32_V8; + if (T.isArm64e()) + return MachO::CPU_SUBTYPE_ARM64E; ++ if (T.isArm64e_x1()) ++ return MachO::CPU_SUBTYPE_ARM64E_X1; + + return MachO::CPU_SUBTYPE_ARM64_ALL; + } +--- llvm/lib/Object/MachOObjectFile.cpp ++++ llvm/lib/Object/MachOObjectFile.cpp +@@ -2807,6 +2807,12 @@ + if (ArchFlag) + *ArchFlag = "arm64e"; + return Triple("arm64e-apple-darwin"); ++ case MachO::CPU_SUBTYPE_ARM64E_X1: ++ if (McpuDefault) ++ *McpuDefault = "apple-a20"; ++ if (ArchFlag) ++ *ArchFlag = "arm64e.x1"; ++ return Triple("arm64e.x1-apple-darwin"); + default: + return Triple(); + } +--- llvm/lib/TargetParser/Triple.cpp ++++ llvm/lib/TargetParser/Triple.cpp +@@ -114,6 +114,8 @@ + return "arm64ec"; + if (SubArch == AArch64SubArch_arm64e) + return "arm64e"; ++ if (SubArch == AArch64SubArch_arm64e_x1) ++ return "arm64e.x1"; + break; + case Triple::dxil: + switch (SubArch) { +@@ -549,6 +551,7 @@ + .Case("arm64", Triple::aarch64) + .Case("arm64_32", Triple::aarch64_32) + .Case("arm64e", Triple::aarch64) ++ .Case("arm64e.x1", Triple::aarch64) + .Case("arm64ec", Triple::aarch64) + .Case("arm", Triple::arm) + .Case("armeb", Triple::armeb) +@@ -764,6 +767,8 @@ + + if (SubArchName == "arm64e") + return Triple::AArch64SubArch_arm64e; ++ if (SubArchName == "arm64e.x1") ++ return Triple::AArch64SubArch_arm64e_x1; + + if (SubArchName == "arm64ec") + return Triple::AArch64SubArch_arm64ec; +--- llvm/test/tools/llvm-readobj/MachO/file-headers-arm64.test ++++ llvm/test/tools/llvm-readobj/MachO/file-headers-arm64.test +@@ -13,6 +13,11 @@ + # RUN: llvm-readobj -h %t.arm64e \ + # RUN: | FileCheck %s --strict-whitespace --match-full-lines -DFILE=%t.arm64e --check-prefix=ARM64 -DSUBTYPE="CPU_SUBTYPE_ARM64E (0x2)" + ++## Check subtype Arm64E.X1: ++# RUN: yaml2obj %s -o %t.arm64e.x1 -DSUBTYPE=0xC ++# RUN: llvm-readobj -h %t.arm64e.x1 \ ++# RUN: | FileCheck %s --strict-whitespace --match-full-lines -DFILE=%t.arm64e.x1 --check-prefix=ARM64 -DSUBTYPE="CPU_SUBTYPE_ARM64E_X1 (0xC)" ++ + # ARM64:File: [[FILE]] + # ARM64-NEXT:Format: Mach-O arm64 + # ARM64-NEXT:Arch: aarch64 +--- llvm/tools/llvm-objdump/MachODump.cpp ++++ llvm/tools/llvm-objdump/MachODump.cpp +@@ -2323,6 +2323,10 @@ + outs() << " cputype CPU_TYPE_ARM64\n"; + outs() << " cpusubtype CPU_SUBTYPE_ARM64E\n"; + break; ++ case MachO::CPU_SUBTYPE_ARM64E_X1: ++ outs() << " cputype CPU_TYPE_ARM64\n"; ++ outs() << " cpusubtype CPU_SUBTYPE_ARM64E_X1\n"; ++ break; + default: + printUnknownCPUType(cputype, cpusubtype); + break; +@@ -8325,6 +8329,9 @@ + case MachO::CPU_SUBTYPE_ARM64E: + outs() << " E"; + break; ++ case MachO::CPU_SUBTYPE_ARM64E_X1: ++ outs() << " E.X1"; ++ break; + default: + outs() << format(" %10d", cpusubtype & ~MachO::CPU_SUBTYPE_MASK); + break; +--- llvm/tools/llvm-readobj/MachODumper.cpp ++++ llvm/tools/llvm-readobj/MachODumper.cpp +@@ -170,6 +170,7 @@ + LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64_ALL), + LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64_V8), + LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64E), ++ LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64E_X1), + }; + + const EnumEntry MachOHeaderCpuSubtypesSPARC[] = { +--- llvm/unittests/BinaryFormat/MachOTest.cpp ++++ llvm/unittests/BinaryFormat/MachOTest.cpp +@@ -66,6 +66,7 @@ + CHECK_CPUTYPE("thumbv7-apple-darwin", MachO::CPU_TYPE_ARM); + CHECK_CPUTYPE("arm64-apple-darwin", MachO::CPU_TYPE_ARM64); + CHECK_CPUTYPE("arm64e-apple-darwin", MachO::CPU_TYPE_ARM64); ++ CHECK_CPUTYPE("arm64e.x1-apple-darwin", MachO::CPU_TYPE_ARM64); + CHECK_CPUTYPE("arm64_32-apple-darwin", MachO::CPU_TYPE_ARM64_32); + + { +@@ -107,6 +108,7 @@ + CHECK_CPUSUBTYPE("thumbv6-apple-darwin", MachO::CPU_SUBTYPE_ARM_V6); + CHECK_CPUSUBTYPE("arm64-apple-darwin", MachO::CPU_SUBTYPE_ARM64_ALL); + CHECK_CPUSUBTYPE("arm64e-apple-darwin", MachO::CPU_SUBTYPE_ARM64E); ++ CHECK_CPUSUBTYPE("arm64e.x1-apple-darwin", MachO::CPU_SUBTYPE_ARM64E_X1); + CHECK_CPUSUBTYPE("arm64_32-apple-darwin", MachO::CPU_SUBTYPE_ARM64_32_V8); + + { +--- /dev/null ++++ lld/test/MachO/arm64-x1.s +@@ -0,0 +1,20 @@ ++# REQUIRES: aarch64 ++ ++## Test that arm64.x1-macos is ignored instead of causing an error. ++## linked re-exported dylibs that only declare arm64e-macos targets, even if targeting arm64. ++# arm64 and arm64e are ABI compatible (same CPU type), and ld64 accepts this. ++ ++# RUN: rm -rf %t; split-file --no-leading-lines %s %t ++ ++# RUN: llvm-mc -filetype=obj -triple=arm64-apple-macos -o %t/test.o /dev/null ++ ++# RUN: %no-arg-lld -syslibroot %t/sdk -lSystem -dylib -arch arm64 \ ++# RUN: -platform_version macos 15 26 %t/test.o -o /dev/null ++ ++#--- sdk/usr/lib/libSystem.tbd ++--- !tapi-tbd ++tbd-version: 4 ++targets: [ arm64-macos, arm64e.x1-macos ] ++install-name: '/usr/lib/libSystem.dylib' ++current-version: 0001.001.1 ++... +--- /dev/null ++++ llvm/test/tools/llvm-readobj/macho-arm64e_x1.test +@@ -0,0 +1,17 @@ ++# RUN: yaml2obj %s -o %t.o ++# RUN: llvm-readobj -h %t.o | FileCheck %s ++ ++# CHECK: Magic: Magic64 (0xFEEDFACF) ++# CHECK: CpuType: Arm64 (0x100000C) ++# CHECK: CpuSubType: CPU_SUBTYPE_ARM64E_X1 (0xC) ++ ++--- !mach-o ++FileHeader: ++ magic: 0xFEEDFACF ++ cputype: 0x0100000C ++ cpusubtype: 0x0000000C ++ filetype: 0x00000001 ++ ncmds: 0 ++ sizeofcmds: 0 ++ flags: 0x00000000 ++ reserved: 0x00000000 diff --git a/pkgs/development/compilers/llvm/20/llvm/backport-minimal-arm64e_x1-support.patch b/pkgs/development/compilers/llvm/20/llvm/backport-minimal-arm64e_x1-support.patch new file mode 100644 index 000000000000..a5b592d0f611 --- /dev/null +++ b/pkgs/development/compilers/llvm/20/llvm/backport-minimal-arm64e_x1-support.patch @@ -0,0 +1,205 @@ +--- llvm/include/llvm/BinaryFormat/MachO.h ++++ llvm/include/llvm/BinaryFormat/MachO.h +@@ -1641,6 +1641,7 @@ + CPU_SUBTYPE_ARM64_ALL = 0, + CPU_SUBTYPE_ARM64_V8 = 1, + CPU_SUBTYPE_ARM64E = 2, ++ CPU_SUBTYPE_ARM64E_X1 = 12, + + // arm64e uses the capability bits to encode ptrauth ABI information. + // Bit 63 marks the binary as Versioned. +--- llvm/include/llvm/TargetParser/Triple.h ++++ llvm/include/llvm/TargetParser/Triple.h +@@ -146,6 +146,7 @@ + ARMSubArch_v4t, + + AArch64SubArch_arm64e, ++ AArch64SubArch_arm64e_x1, + AArch64SubArch_arm64ec, + + KalimbaSubArch_v3, +@@ -1077,6 +1077,11 @@ + getSubArch() == Triple::AArch64SubArch_arm64e; + } + ++ bool isArm64e_x1() const { ++ return getArch() == Triple::aarch64 && ++ getSubArch() == Triple::AArch64SubArch_arm64e_x1; ++ } ++ + // Tests whether the target is N32. + bool isABIN32() const { + EnvironmentType Env = getEnvironment(); +--- llvm/include/llvm/TextAPI/Architecture.def ++++ llvm/include/llvm/TextAPI/Architecture.def +@@ -37,7 +37,7 @@ + /// + ARCHINFO(arm64, arm64, MachO::CPU_TYPE_ARM64, MachO::CPU_SUBTYPE_ARM64_ALL, 64) + ARCHINFO(arm64e, arm64e, MachO::CPU_TYPE_ARM64, MachO::CPU_SUBTYPE_ARM64E, 64) +- ++ARCHINFO(arm64e_x1, arm64e.x1, MachO::CPU_TYPE_ARM64, MachO::CPU_SUBTYPE_ARM64E_X1, 64) + + /// + /// ARM64_32 architectures sorted by cpu sub type id +--- llvm/lib/BinaryFormat/MachO.cpp ++++ llvm/lib/BinaryFormat/MachO.cpp +@@ -60,6 +60,8 @@ + return (MachO::CPUSubTypeARM64)MachO::CPU_SUBTYPE_ARM64_32_V8; + if (T.isArm64e()) + return MachO::CPU_SUBTYPE_ARM64E; ++ if (T.isArm64e_x1()) ++ return MachO::CPU_SUBTYPE_ARM64E_X1; + + return MachO::CPU_SUBTYPE_ARM64_ALL; + } +--- llvm/lib/Object/MachOObjectFile.cpp ++++ llvm/lib/Object/MachOObjectFile.cpp +@@ -2806,6 +2806,12 @@ + if (ArchFlag) + *ArchFlag = "arm64e"; + return Triple("arm64e-apple-darwin"); ++ case MachO::CPU_SUBTYPE_ARM64E_X1: ++ if (McpuDefault) ++ *McpuDefault = "apple-a20"; ++ if (ArchFlag) ++ *ArchFlag = "arm64e.x1"; ++ return Triple("arm64e.x1-apple-darwin"); + default: + return Triple(); + } +--- llvm/lib/TargetParser/Triple.cpp ++++ llvm/lib/TargetParser/Triple.cpp +@@ -114,6 +191,8 @@ + return "arm64ec"; + if (SubArch == AArch64SubArch_arm64e) + return "arm64e"; ++ if (SubArch == AArch64SubArch_arm64e_x1) ++ return "arm64e.x1"; + break; + case Triple::spirv: + switch (SubArch) { +@@ -574,6 +576,7 @@ + .Case("arm64", Triple::aarch64) + .Case("arm64_32", Triple::aarch64_32) + .Case("arm64e", Triple::aarch64) ++ .Case("arm64e.x1", Triple::aarch64) + .Case("arm64ec", Triple::aarch64) + .Case("arm", Triple::arm) + .Case("armeb", Triple::armeb) +@@ -793,6 +796,8 @@ + + if (SubArchName == "arm64e") + return Triple::AArch64SubArch_arm64e; ++ if (SubArchName == "arm64e.x1") ++ return Triple::AArch64SubArch_arm64e_x1; + + if (SubArchName == "arm64ec") + return Triple::AArch64SubArch_arm64ec; +--- llvm/test/tools/llvm-readobj/MachO/file-headers-arm64.test ++++ llvm/test/tools/llvm-readobj/MachO/file-headers-arm64.test +@@ -13,6 +13,11 @@ + # RUN: llvm-readobj -h %t.arm64e \ + # RUN: | FileCheck %s --strict-whitespace --match-full-lines -DFILE=%t.arm64e --check-prefix=ARM64 -DSUBTYPE="CPU_SUBTYPE_ARM64E (0x2)" + ++## Check subtype Arm64E.X1: ++# RUN: yaml2obj %s -o %t.arm64e.x1 -DSUBTYPE=0xC ++# RUN: llvm-readobj -h %t.arm64e.x1 \ ++# RUN: | FileCheck %s --strict-whitespace --match-full-lines -DFILE=%t.arm64e.x1 --check-prefix=ARM64 -DSUBTYPE="CPU_SUBTYPE_ARM64E_X1 (0xC)" ++ + # ARM64:File: [[FILE]] + # ARM64-NEXT:Format: Mach-O arm64 + # ARM64-NEXT:Arch: aarch64 +--- llvm/tools/llvm-objdump/MachODump.cpp ++++ llvm/tools/llvm-objdump/MachODump.cpp +@@ -2323,6 +2323,10 @@ + outs() << " cputype CPU_TYPE_ARM64\n"; + outs() << " cpusubtype CPU_SUBTYPE_ARM64E\n"; + break; ++ case MachO::CPU_SUBTYPE_ARM64E_X1: ++ outs() << " cputype CPU_TYPE_ARM64\n"; ++ outs() << " cpusubtype CPU_SUBTYPE_ARM64E_X1\n"; ++ break; + default: + printUnknownCPUType(cputype, cpusubtype); + break; +@@ -8337,6 +8341,9 @@ + case MachO::CPU_SUBTYPE_ARM64E: + outs() << " E"; + break; ++ case MachO::CPU_SUBTYPE_ARM64E_X1: ++ outs() << " E.X1"; ++ break; + default: + outs() << format(" %10d", cpusubtype & ~MachO::CPU_SUBTYPE_MASK); + break; +--- llvm/tools/llvm-readobj/MachODumper.cpp ++++ llvm/tools/llvm-readobj/MachODumper.cpp +@@ -170,6 +170,7 @@ + LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64_ALL), + LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64_V8), + LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64E), ++ LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64E_X1), + }; + + const EnumEntry MachOHeaderCpuSubtypesSPARC[] = { +--- llvm/unittests/BinaryFormat/MachOTest.cpp ++++ llvm/unittests/BinaryFormat/MachOTest.cpp +@@ -66,6 +66,7 @@ + CHECK_CPUTYPE("thumbv7-apple-darwin", MachO::CPU_TYPE_ARM); + CHECK_CPUTYPE("arm64-apple-darwin", MachO::CPU_TYPE_ARM64); + CHECK_CPUTYPE("arm64e-apple-darwin", MachO::CPU_TYPE_ARM64); ++ CHECK_CPUTYPE("arm64e.x1-apple-darwin", MachO::CPU_TYPE_ARM64); + CHECK_CPUTYPE("arm64_32-apple-darwin", MachO::CPU_TYPE_ARM64_32); + + { +@@ -107,6 +108,7 @@ + CHECK_CPUSUBTYPE("thumbv6-apple-darwin", MachO::CPU_SUBTYPE_ARM_V6); + CHECK_CPUSUBTYPE("arm64-apple-darwin", MachO::CPU_SUBTYPE_ARM64_ALL); + CHECK_CPUSUBTYPE("arm64e-apple-darwin", MachO::CPU_SUBTYPE_ARM64E); ++ CHECK_CPUSUBTYPE("arm64e.x1-apple-darwin", MachO::CPU_SUBTYPE_ARM64E_X1); + CHECK_CPUSUBTYPE("arm64_32-apple-darwin", MachO::CPU_SUBTYPE_ARM64_32_V8); + + { +--- /dev/null ++++ lld/test/MachO/arm64-x1.s +@@ -0,0 +1,20 @@ ++# REQUIRES: aarch64 ++ ++## Test that arm64.x1-macos is ignored instead of causing an error. ++## linked re-exported dylibs that only declare arm64e-macos targets, even if targeting arm64. ++# arm64 and arm64e are ABI compatible (same CPU type), and ld64 accepts this. ++ ++# RUN: rm -rf %t; split-file --no-leading-lines %s %t ++ ++# RUN: llvm-mc -filetype=obj -triple=arm64-apple-macos -o %t/test.o /dev/null ++ ++# RUN: %no-arg-lld -syslibroot %t/sdk -lSystem -dylib -arch arm64 \ ++# RUN: -platform_version macos 15 26 %t/test.o -o /dev/null ++ ++#--- sdk/usr/lib/libSystem.tbd ++--- !tapi-tbd ++tbd-version: 4 ++targets: [ arm64-macos, arm64e.x1-macos ] ++install-name: '/usr/lib/libSystem.dylib' ++current-version: 0001.001.1 ++... +--- /dev/null ++++ llvm/test/tools/llvm-readobj/macho-arm64e_x1.test +@@ -0,0 +1,17 @@ ++# RUN: yaml2obj %s -o %t.o ++# RUN: llvm-readobj -h %t.o | FileCheck %s ++ ++# CHECK: Magic: Magic64 (0xFEEDFACF) ++# CHECK: CpuType: Arm64 (0x100000C) ++# CHECK: CpuSubType: CPU_SUBTYPE_ARM64E_X1 (0xC) ++ ++--- !mach-o ++FileHeader: ++ magic: 0xFEEDFACF ++ cputype: 0x0100000C ++ cpusubtype: 0x0000000C ++ filetype: 0x00000001 ++ ncmds: 0 ++ sizeofcmds: 0 ++ flags: 0x00000000 ++ reserved: 0x00000000 diff --git a/pkgs/development/compilers/llvm/22/lldb/backport-ParseTrieEntries-fixes.patch b/pkgs/development/compilers/llvm/22/lldb/backport-ParseTrieEntries-fixes.patch new file mode 100644 index 000000000000..312be42ec2fb --- /dev/null +++ b/pkgs/development/compilers/llvm/22/lldb/backport-ParseTrieEntries-fixes.patch @@ -0,0 +1,125 @@ +diff --git a/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp b/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp +index 0be7b4c6f8..f9d9a05920 100644 +--- a/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp ++++ b/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp +@@ -137,6 +137,14 @@ + static constexpr llvm::StringLiteral g_loader_path = "@loader_path"; + static constexpr llvm::StringLiteral g_executable_path = "@executable_path"; + ++/// Upper bound on the length of a symbol name assembled from export-trie edge ++/// labels. A corrupt trie can encode an edge label whose terminator is far ++/// away in the trie data, so a single label is many megabytes long; appending ++/// it to the running name would otherwise request an unbounded allocation. No ++/// legitimate symbol name comes close to this size. Also 1 MiB is the ++/// symbol length limit in ld. ++static constexpr size_t kMaxTrieSymbolNameLength = 1 << 20; // 1 MiB ++ + LLDB_PLUGIN_DEFINE(ObjectFileMachO) + + static void PrintRegisterValue(RegisterContext *reg_ctx, const char *name, +@@ -1994,15 +2002,21 @@ + } + }; + +-static bool ParseTrieEntries(DataExtractor &data, lldb::offset_t offset, +- const bool is_arm, addr_t text_seg_base_addr, +- std::vector &nameSlices, +- std::set &resolver_addresses, +- std::vector &reexports, +- std::vector &ext_symbols) { ++static bool ParseTrieEntriesImpl(DataExtractor &data, lldb::offset_t offset, ++ const bool is_arm, addr_t text_seg_base_addr, ++ std::string &prefix, ++ std::set &resolver_addresses, ++ std::vector &reexports, ++ std::vector &ext_symbols, ++ std::set &visited_nodes) { + if (!data.ValidOffset(offset)) + return true; + ++ // Every node in a well-formed trie is reached by exactly one path, so a node ++ // offset seen twice means the trie is corrupt. ++ if (!visited_nodes.insert(offset).second) ++ return false; ++ + // Terminal node -- end of a branch, possibly add this to + // the symbol table or resolver table. + const uint64_t terminalSize = data.GetULEB128(&offset); +@@ -2042,14 +2056,9 @@ + add_this_entry = true; + } + if (add_this_entry) { +- std::string name; +- if (!nameSlices.empty()) { +- for (auto name_slice : nameSlices) +- name.append(name_slice.data(), name_slice.size()); +- } +- if (name.size() > 1) { ++ if (prefix.size() > 1) { + // Skip the leading '_' +- e.entry.name.SetCStringWithLength(name.c_str() + 1, name.size() - 1); ++ e.entry.name.SetString(llvm::StringRef(prefix).drop_front()); + } + if (import_name) { + // Skip the leading '_' +@@ -2070,23 +2079,37 @@ + const uint8_t childrenCount = data.GetU8(&children_offset); + for (uint8_t i = 0; i < childrenCount; ++i) { + const char *cstr = data.GetCStr(&children_offset); +- if (cstr) +- nameSlices.push_back(llvm::StringRef(cstr)); +- else ++ if (!cstr) + return false; // Corrupt data ++ if (prefix.size() + llvm::StringRef(cstr).size() > kMaxTrieSymbolNameLength) ++ return false; // Corrupt data: implausibly long symbol name. ++ const size_t prevSize = prefix.size(); ++ prefix.append(cstr); + lldb::offset_t childNodeOffset = data.GetULEB128(&children_offset); +- if (childNodeOffset) { +- if (!ParseTrieEntries(data, childNodeOffset, is_arm, text_seg_base_addr, +- nameSlices, resolver_addresses, reexports, +- ext_symbols)) { +- return false; +- } +- } +- nameSlices.pop_back(); ++ // A child offset of 0 points back at the root; like any other repeated ++ // offset it is a cycle, which ParseTrieEntriesImpl rejects as corrupt. ++ if (!ParseTrieEntriesImpl(data, childNodeOffset, is_arm, text_seg_base_addr, ++ prefix, resolver_addresses, reexports, ++ ext_symbols, visited_nodes)) ++ return false; ++ prefix.resize(prevSize); + } + return true; + } + ++static bool ParseTrieEntries( ++ DataExtractor &data, const bool is_arm, lldb::addr_t text_seg_base_addr, ++ std::set &resolver_addresses, ++ std::vector &reexports, ++ std::vector &ext_symbols) { ++ lldb::offset_t offset = 0; ++ std::set visited_nodes; ++ std::string prefix; ++ return ParseTrieEntriesImpl(data, offset, is_arm, text_seg_base_addr, prefix, ++ resolver_addresses, reexports, ext_symbols, ++ visited_nodes); ++} ++ + static bool + TryParseV2ObjCMetadataSymbol(const char *&symbol_name, + const char *&symbol_name_non_abi_mangled, +@@ -2659,9 +2682,8 @@ + lldb::addr_t text_segment_file_addr = LLDB_INVALID_ADDRESS; + if (text_segment_sp) + text_segment_file_addr = text_segment_sp->GetFileAddress(); +- std::vector nameSlices; +- ParseTrieEntries(dyld_trie_data, 0, is_arm, text_segment_file_addr, +- nameSlices, resolver_addresses, reexport_trie_entries, ++ ParseTrieEntries(dyld_trie_data, is_arm, text_segment_file_addr, ++ resolver_addresses, reexport_trie_entries, + external_sym_trie_entries); + } + diff --git a/pkgs/development/compilers/llvm/22/llvm/backport-minimal-arm64e_x1-support.patch b/pkgs/development/compilers/llvm/22/llvm/backport-minimal-arm64e_x1-support.patch new file mode 100644 index 000000000000..9aaa39d98eaa --- /dev/null +++ b/pkgs/development/compilers/llvm/22/llvm/backport-minimal-arm64e_x1-support.patch @@ -0,0 +1,205 @@ +--- llvm/include/llvm/BinaryFormat/MachO.h ++++ llvm/include/llvm/BinaryFormat/MachO.h +@@ -1715,6 +1715,7 @@ + CPU_SUBTYPE_ARM64_ALL = 0, + CPU_SUBTYPE_ARM64_V8 = 1, + CPU_SUBTYPE_ARM64E = 2, ++ CPU_SUBTYPE_ARM64E_X1 = 12, + + // arm64e uses the capability bits to encode ptrauth ABI information. + // Bit 63 marks the binary as Versioned. +--- llvm/include/llvm/TargetParser/Triple.h ++++ llvm/include/llvm/TargetParser/Triple.h +@@ -157,6 +157,7 @@ + ARMSubArch_v4t, + + AArch64SubArch_arm64e, ++ AArch64SubArch_arm64e_x1, + AArch64SubArch_arm64ec, + AArch64SubArch_lfi, + +@@ -1220,6 +1221,11 @@ + getSubArch() == Triple::AArch64SubArch_arm64e; + } + ++ bool isArm64e_x1() const { ++ return getArch() == Triple::aarch64 && ++ getSubArch() == Triple::AArch64SubArch_arm64e_x1; ++ } ++ + // Tests whether the target is N32. + bool isABIN32() const { + EnvironmentType Env = getEnvironment(); +--- llvm/include/llvm/TextAPI/Architecture.def ++++ llvm/include/llvm/TextAPI/Architecture.def +@@ -39,7 +39,7 @@ + /// + ARCHINFO(arm64, arm64, MachO::CPU_TYPE_ARM64, MachO::CPU_SUBTYPE_ARM64_ALL, 64) + ARCHINFO(arm64e, arm64e, MachO::CPU_TYPE_ARM64, MachO::CPU_SUBTYPE_ARM64E, 64) +- ++ARCHINFO(arm64e_x1, arm64e.x1, MachO::CPU_TYPE_ARM64, MachO::CPU_SUBTYPE_ARM64E_X1, 64) + + /// + /// ARM64_32 architectures sorted by cpu sub type id +--- llvm/lib/BinaryFormat/MachO.cpp ++++ llvm/lib/BinaryFormat/MachO.cpp +@@ -66,6 +66,8 @@ + return (MachO::CPUSubTypeARM64)MachO::CPU_SUBTYPE_ARM64_32_V8; + if (T.isArm64e()) + return MachO::CPU_SUBTYPE_ARM64E; ++ if (T.isArm64e_x1()) ++ return MachO::CPU_SUBTYPE_ARM64E_X1; + + return MachO::CPU_SUBTYPE_ARM64_ALL; + } +--- llvm/lib/Object/MachOObjectFile.cpp ++++ llvm/lib/Object/MachOObjectFile.cpp +@@ -2919,6 +2919,12 @@ + if (ArchFlag) + *ArchFlag = "arm64e"; + return Triple("arm64e-apple-darwin"); ++ case MachO::CPU_SUBTYPE_ARM64E_X1: ++ if (McpuDefault) ++ *McpuDefault = "apple-a20"; ++ if (ArchFlag) ++ *ArchFlag = "arm64e.x1"; ++ return Triple("arm64e.x1-apple-darwin"); + default: + return Triple(); + } +--- llvm/lib/TargetParser/Triple.cpp ++++ llvm/lib/TargetParser/Triple.cpp +@@ -191,6 +191,8 @@ + return "arm64ec"; + if (SubArch == AArch64SubArch_arm64e) + return "arm64e"; ++ if (SubArch == AArch64SubArch_arm64e_x1) ++ return "arm64e.x1"; + if (SubArch == AArch64SubArch_lfi) + return "aarch64_lfi"; + break; +@@ -612,6 +614,7 @@ + .Case("arm64", Triple::aarch64) + .Case("arm64_32", Triple::aarch64_32) + .Case("arm64e", Triple::aarch64) ++ .Case("arm64e.x1", Triple::aarch64) + .Case("arm64ec", Triple::aarch64) + .Case("arm", Triple::arm) + .Case("armeb", Triple::armeb) +@@ -739,6 +742,8 @@ + + if (SubArchName == "arm64e") + return Triple::AArch64SubArch_arm64e; ++ if (SubArchName == "arm64e.x1") ++ return Triple::AArch64SubArch_arm64e_x1; + + if (SubArchName == "arm64ec") + return Triple::AArch64SubArch_arm64ec; +--- llvm/test/tools/llvm-readobj/MachO/file-headers-arm64.test ++++ llvm/test/tools/llvm-readobj/MachO/file-headers-arm64.test +@@ -13,6 +13,11 @@ + # RUN: llvm-readobj -h %t.arm64e \ + # RUN: | FileCheck %s --strict-whitespace --match-full-lines -DFILE=%t.arm64e --check-prefix=ARM64 -DSUBTYPE="CPU_SUBTYPE_ARM64E (0x2)" + ++## Check subtype Arm64E.X1: ++# RUN: yaml2obj %s -o %t.arm64e.x1 -DSUBTYPE=0xC ++# RUN: llvm-readobj -h %t.arm64e.x1 \ ++# RUN: | FileCheck %s --strict-whitespace --match-full-lines -DFILE=%t.arm64e.x1 --check-prefix=ARM64 -DSUBTYPE="CPU_SUBTYPE_ARM64E_X1 (0xC)" ++ + # ARM64:File: [[FILE]] + # ARM64-NEXT:Format: Mach-O arm64 + # ARM64-NEXT:Arch: aarch64 +--- llvm/tools/llvm-objdump/MachODump.cpp ++++ llvm/tools/llvm-objdump/MachODump.cpp +@@ -2344,6 +2344,10 @@ + outs() << " cputype CPU_TYPE_ARM64\n"; + outs() << " cpusubtype CPU_SUBTYPE_ARM64E\n"; + break; ++ case MachO::CPU_SUBTYPE_ARM64E_X1: ++ outs() << " cputype CPU_TYPE_ARM64\n"; ++ outs() << " cpusubtype CPU_SUBTYPE_ARM64E_X1\n"; ++ break; + default: + printUnknownCPUType(cputype, cpusubtype); + break; +@@ -8472,6 +8476,9 @@ + case MachO::CPU_SUBTYPE_ARM64E: + outs() << " E"; + break; ++ case MachO::CPU_SUBTYPE_ARM64E_X1: ++ outs() << " E.X1"; ++ break; + default: + outs() << format(" %10d", cpusubtype & ~MachO::CPU_SUBTYPE_MASK); + break; +--- llvm/tools/llvm-readobj/MachODumper.cpp ++++ llvm/tools/llvm-readobj/MachODumper.cpp +@@ -190,6 +190,7 @@ + LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64_ALL), + LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64_V8), + LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64E), ++ LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64E_X1), + }; + constexpr auto MachOHeaderCpuSubtypesARM64 = + BUILD_ENUM_STRINGS(MachOHeaderCpuSubtypesARM64Defs); +--- llvm/unittests/BinaryFormat/MachOTest.cpp ++++ llvm/unittests/BinaryFormat/MachOTest.cpp +@@ -66,6 +66,7 @@ + CHECK_CPUTYPE("thumbv7-apple-darwin", MachO::CPU_TYPE_ARM); + CHECK_CPUTYPE("arm64-apple-darwin", MachO::CPU_TYPE_ARM64); + CHECK_CPUTYPE("arm64e-apple-darwin", MachO::CPU_TYPE_ARM64); ++ CHECK_CPUTYPE("arm64e.x1-apple-darwin", MachO::CPU_TYPE_ARM64); + CHECK_CPUTYPE("arm64_32-apple-darwin", MachO::CPU_TYPE_ARM64_32); + + { +@@ -107,6 +108,7 @@ + CHECK_CPUSUBTYPE("thumbv6-apple-darwin", MachO::CPU_SUBTYPE_ARM_V6); + CHECK_CPUSUBTYPE("arm64-apple-darwin", MachO::CPU_SUBTYPE_ARM64_ALL); + CHECK_CPUSUBTYPE("arm64e-apple-darwin", MachO::CPU_SUBTYPE_ARM64E); ++ CHECK_CPUSUBTYPE("arm64e.x1-apple-darwin", MachO::CPU_SUBTYPE_ARM64E_X1); + CHECK_CPUSUBTYPE("arm64_32-apple-darwin", MachO::CPU_SUBTYPE_ARM64_32_V8); + CHECK_CPUSUBTYPE("armv8m.main-apple-darwin", MachO::CPU_SUBTYPE_ARM_V8M_MAIN); + CHECK_CPUSUBTYPE("armv8m.base-apple-darwin", MachO::CPU_SUBTYPE_ARM_V8M_BASE); +--- /dev/null ++++ lld/test/MachO/arm64-x1.s +@@ -0,0 +1,20 @@ ++# REQUIRES: aarch64 ++ ++## Test that arm64.x1-macos is ignored instead of causing an error. ++## linked re-exported dylibs that only declare arm64e-macos targets, even if targeting arm64. ++# arm64 and arm64e are ABI compatible (same CPU type), and ld64 accepts this. ++ ++# RUN: rm -rf %t; split-file --no-leading-lines %s %t ++ ++# RUN: llvm-mc -filetype=obj -triple=arm64-apple-macos -o %t/test.o /dev/null ++ ++# RUN: %no-arg-lld -syslibroot %t/sdk -lSystem -dylib -arch arm64 \ ++# RUN: -platform_version macos 15 26 %t/test.o -o /dev/null ++ ++#--- sdk/usr/lib/libSystem.tbd ++--- !tapi-tbd ++tbd-version: 4 ++targets: [ arm64-macos, arm64e.x1-macos ] ++install-name: '/usr/lib/libSystem.dylib' ++current-version: 0001.001.1 ++... +--- /dev/null ++++ llvm/test/tools/llvm-readobj/macho-arm64e_x1.test +@@ -0,0 +1,17 @@ ++# RUN: yaml2obj %s -o %t.o ++# RUN: llvm-readobj -h %t.o | FileCheck %s ++ ++# CHECK: Magic: Magic64 (0xFEEDFACF) ++# CHECK: CpuType: Arm64 (0x100000C) ++# CHECK: CpuSubType: CPU_SUBTYPE_ARM64E_X1 (0xC) ++ ++--- !mach-o ++FileHeader: ++ magic: 0xFEEDFACF ++ cputype: 0x0100000C ++ cpusubtype: 0x0000000C ++ filetype: 0x00000001 ++ ncmds: 0 ++ sizeofcmds: 0 ++ flags: 0x00000000 ++ reserved: 0x00000000 diff --git a/pkgs/development/compilers/llvm/common/clang-tools/default.nix b/pkgs/development/compilers/llvm/common/clang-tools/default.nix index 91daa95d07cf..4fab7f98164d 100644 --- a/pkgs/development/compilers/llvm/common/clang-tools/default.nix +++ b/pkgs/development/compilers/llvm/common/clang-tools/default.nix @@ -3,6 +3,7 @@ stdenv, runCommand, writeText, + bashNonInteractive, clang-unwrapped, clang, libcxxClang, @@ -20,6 +21,8 @@ stdenv.mkDerivation (finalAttrs: { strictDeps = true; __structuredAttrs = true; + buildInputs = [ bashNonInteractive ]; + installPhase = '' runHook preInstall @@ -63,9 +66,11 @@ stdenv.mkDerivation (finalAttrs: { passthru.tests = let src = writeText "main.cpp" '' + #include #include int main() { + assert(true); std::cout << "Hi!"; } ''; @@ -76,6 +81,10 @@ stdenv.mkDerivation (finalAttrs: { ${finalAttrs.finalPackage}/bin/clangd --check=${src} touch $out ''; + smokeOkClangTidy = runCommand "clang-tidy-test-smoke-ok" { } '' + ${finalAttrs.finalPackage}/bin/clang-tidy ${src} + touch $out + ''; smokeErr = runCommand "clang-tools-test-smoke-err" { } '' (${finalAttrs.finalPackage}/bin/clangd --query-driver='**' --check=${src} 2>&1 || true) \ | grep 'use of undeclared identifier' diff --git a/pkgs/development/compilers/llvm/common/clang-tools/wrapper b/pkgs/development/compilers/llvm/common/clang-tools/wrapper index 6601d6875f8e..247d858b9488 100755 --- a/pkgs/development/compilers/llvm/common/clang-tools/wrapper +++ b/pkgs/development/compilers/llvm/common/clang-tools/wrapper @@ -1,4 +1,4 @@ -#!/bin/sh +#!/usr/bin/env bash buildcpath() { local path after diff --git a/pkgs/development/compilers/llvm/common/lldb/default.nix b/pkgs/development/compilers/llvm/common/lldb/default.nix index ec43ac177fce..fa01bd8e760b 100644 --- a/pkgs/development/compilers/llvm/common/lldb/default.nix +++ b/pkgs/development/compilers/llvm/common/lldb/default.nix @@ -82,6 +82,10 @@ stdenv.mkDerivation ( # Fix build with gcc15 # https://github.com/llvm/llvm-project/commit/bb59f04e7e75dcbe39f1bf952304a157f0035314 ./lldb-add-include-cstdint.patch + ] + ++ lib.optionals (lib.versionOlder (lib.versions.major release_version) "23") [ + # Backports several fixes to export trie parsing. Otherwise, LLDB crashes when starting a debugging session on macOS 27. + (getVersionFile "lldb/backport-ParseTrieEntries-fixes.patch") ]; nativeBuildInputs = [ diff --git a/pkgs/development/compilers/llvm/common/llvm/default.nix b/pkgs/development/compilers/llvm/common/llvm/default.nix index 6bde3d2a6d9c..8808e9987e97 100644 --- a/pkgs/development/compilers/llvm/common/llvm/default.nix +++ b/pkgs/development/compilers/llvm/common/llvm/default.nix @@ -263,6 +263,21 @@ stdenv.mkDerivation ( # This patch is a backport of the target parsing changes in LLVM 23, which fixes the problem. # Hopefully, Apple does not change the version number scheme again any time soon. (getVersionFile "llvm/backport-darwin-triple-parsing.patch") + ] + ++ lib.optionals (lib.versionOlder release_version "22") [ + # Needed to add arm64e.x1 support, as the enum name differs from the architecture name + (fetchpatch { + name = "llvm-textapi-separate-arch-name-enum-label.patch"; + url = "https://github.com/llvm/llvm-project/commit/477a65a051ce151895193f8dede1262fdc251132.patch"; + stripLen = 1; + hash = "sha256-XXteX2zK5TzFQX+XhLzUtikY4PkCWF1f8l5MshelzX4="; + }) + ] + ++ lib.optionals (lib.versionOlder release_version "23") [ + # Needed to link with the macOS 27 sdk, as it has libraries linked for arm64e.x1 + # a new arm64 subtype that gives more pointer authentication machinery. + # Vendored backport of the patch for LLVM 23 + (getVersionFile "llvm/backport-minimal-arm64e_x1-support.patch") ]; nativeBuildInputs = [ diff --git a/pkgs/development/compilers/llvm/common/patches.nix b/pkgs/development/compilers/llvm/common/patches.nix index c01d9a333030..6e4e8531605a 100644 --- a/pkgs/development/compilers/llvm/common/patches.nix +++ b/pkgs/development/compilers/llvm/common/patches.nix @@ -20,6 +20,17 @@ path = ../18; } ]; + "lldb/backport-ParseTrieEntries-fixes.patch" = [ + { + before = "22"; + path = ../18; + } + { + after = "22"; + before = "23"; + path = ../22; + } + ]; "lldb/gnu-install-dirs.patch" = [ { before = "23"; @@ -41,6 +52,27 @@ path = ../21; } ]; + "llvm/backport-minimal-arm64e_x1-support.patch" = [ + { + after = "18"; + before = "19"; + path = ../18; + } + { + after = "19"; + before = "20"; + path = ../19; + } + { + after = "20"; + before = "22"; + path = ../20; + } + { + after = "22"; + path = ../22; + } + ]; "llvm/gnu-install-dirs.patch" = [ { after = "23"; diff --git a/pkgs/development/compilers/rust/binary.nix b/pkgs/development/compilers/rust/binary.nix index 5dc36c54d3fb..ecbb2932eea9 100644 --- a/pkgs/development/compilers/rust/binary.nix +++ b/pkgs/development/compilers/rust/binary.nix @@ -48,6 +48,8 @@ rec { ++ lib.optional (!stdenv.hostPlatform.isDarwin && !stdenv.hostPlatform.isFreeBSD) gcc.cc.lib ++ lib.optional (!stdenv.hostPlatform.isDarwin) zlib; + strictDeps = true; + postPatch = '' patchShebangs . ''; @@ -90,6 +92,8 @@ rec { setupHooks = ./setup-hook.sh; + __structuredAttrs = true; + passthru = rec { targetPlatformsWithHostTools = [ # Platforms with host tools from @@ -172,6 +176,9 @@ rec { ] ++ lib.optional (!stdenv.hostPlatform.isDarwin && !stdenv.hostPlatform.isFreeBSD) gcc.cc.lib; + strictDeps = true; + __structuredAttrs = true; + postPatch = '' patchShebangs . ''; diff --git a/pkgs/development/compilers/rust/cargo-auditable-cargo-wrapper.nix b/pkgs/development/compilers/rust/cargo-auditable-cargo-wrapper.nix index 420b3bc82052..4878387dcb57 100644 --- a/pkgs/development/compilers/rust/cargo-auditable-cargo-wrapper.nix +++ b/pkgs/development/compilers/rust/cargo-auditable-cargo-wrapper.nix @@ -14,6 +14,8 @@ else { nativeBuildInputs = [ makeBinaryWrapper ]; + strictDeps = true; + passthru.tests = runCommand "rust-audit-info-test" { @@ -23,6 +25,8 @@ else rust-audit-info ${lib.getBin rust-audit-info}/bin/rust-audit-info > $out ''; + __structuredAttrs = true; + meta = cargo-auditable.meta // { mainProgram = "cargo"; }; diff --git a/pkgs/development/compilers/rust/cargo.nix b/pkgs/development/compilers/rust/cargo.nix index 3fb4f948a223..64aa7d9cffd2 100644 --- a/pkgs/development/compilers/rust/cargo.nix +++ b/pkgs/development/compilers/rust/cargo.nix @@ -116,6 +116,8 @@ rustPlatform.buildRustPackage.override rustPlatform.rust.rustc.unwrapped ]; + __structuredAttrs = true; + meta = { homepage = "https://crates.io"; description = "Downloads your Rust project's dependencies and builds your project"; diff --git a/pkgs/development/compilers/rust/rustc.nix b/pkgs/development/compilers/rust/rustc.nix index f5c09e0740ba..a2cfbe1b4a9f 100644 --- a/pkgs/development/compilers/rust/rustc.nix +++ b/pkgs/development/compilers/rust/rustc.nix @@ -20,6 +20,7 @@ rustc, rustfmt, pkg-config, + bashNonInteractive, openssl, xz, zlib, @@ -402,6 +403,7 @@ stdenv.mkDerivation (finalAttrs: { ]; buildInputs = [ + bashNonInteractive openssl rust-jemalloc-sys ] @@ -411,6 +413,8 @@ stdenv.mkDerivation (finalAttrs: { ++ optional (!withBundledLLVM) llvmShared.lib ++ optional (useLLVM && !withBundledLLVM) llvmPackages.libunwind; + strictDeps = true; + outputs = [ "out" "man" diff --git a/pkgs/development/compilers/swift/by-name/fe/fetchSwiftPMDeps/package.nix b/pkgs/development/compilers/swift/by-name/fe/fetchSwiftPMDeps/package.nix new file mode 100644 index 000000000000..945f7dea168e --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/fe/fetchSwiftPMDeps/package.nix @@ -0,0 +1,153 @@ +# Fetches a package based on its metadata from `Package.resolved` +{ + lib, + cacert, + jq, + nix, + nix-prefetch-git, + runCommand, + stdenvNoCC, +}: + +{ + name ? if args ? pname && args ? version then "${args.pname}-${args.version}" else "swiftpm-deps", + hash ? (throw "fetchSwiftPMDeps requires a `hash` value to be set for ${name}"), + nativeBuildInputs ? [ ], + ... +}@args: + +let + removedArgs = [ + "name" + "pname" + "version" + "nativeBuildInputs" + "hash" + ]; + + vendorStaging = stdenvNoCC.mkDerivation ( + { + name = "${name}-vendor-staging"; + + impureEnvVars = lib.fetchers.proxyImpureEnvVars; + + strictDeps = true; + + nativeBuildInputs = [ + cacert + jq + nix-prefetch-git + ] + ++ nativeBuildInputs; + + buildPhase = '' + runHook preBuild + + resolved=$PWD/Package.resolved + stagingResolved=$out/Package.resolved + + mkdir -p "$out" + + # Convert version 1 to version 2 because its pins `schema` differs. + # Version 3 has the same pins schema, so it is already compatible. + if [ "$(jq --raw-output '.version' < "$resolved")" = "1" ]; then + jq ' + { + pins: [ + .object.pins[] | { + identity: .package, + kind: "remoteSourceControl", + location: .repositoryURL, + state: .state + } + ], + version: 2 + } + ' < "$resolved" > "$stagingResolved" + else + cp "$resolved" "$stagingResolved" + fi + + if [ -n "$(jq --raw-output '.pins[] | select(.kind != "remoteSourceControl")' < "$stagingResolved")" ]; then + echo "Only Git-based dependencies are supported by fetchSwiftPMDeps" + exit 1 + fi + + jq --raw-output0 '.pins[] | select(.kind == "remoteSourceControl")' < "$stagingResolved" | while IFS= read -d "" pin; do + url=$(jq --raw-output '.location' <<< "$pin") + name=$(basename "$url" .git) + rev=$(jq --raw-output '.state.revision' <<< "$pin") + nix-prefetch-git --builder --quiet --fetch-submodules --url "$url" --rev "$rev" --out "$out/Packages/$name" + done + + runHook postBuild + ''; + + dontConfigure = true; + dontInstall = true; + dontFixup = true; + + outputHash = hash; + outputHashAlgo = if hash == "" then "sha256" else null; + outputHashMode = "recursive"; + + __structuredAttrs = true; + } + // builtins.removeAttrs args removedArgs + ); +in + +# `fetchSwiftPMDeps` splits the workspace-state generation into a separate, non-FOD derivation in case the format +# of the file ever changes or in case we have to do additional processing due to changes in SwiftPM. +runCommand "${name}-vendor" + { + inherit vendorStaging; + nativeBuildInputs = [ jq ]; + } + '' + mkdir -p "$out" + + # SwiftPM uses workspace-state.json to determine whether it needs to fetch dependencies. + # Generate it to prevent that from happening. + jq --compact-output --sort-keys ' + { + "object": { + "artifacts": [ ], + "dependencies": [ .pins[] | + { + "basedOn": { + "basedOn": null, + "packageRef": { + "identity": .identity, + "kind": .kind, + "location": .location, + "name": .location | sub("\\.git$"; "") | split("/")[-1] + }, + "state": { + "checkoutState": .state, + "name": "sourceControlCheckout" + }, + "subpath": .location | sub("\\.git$"; "") | split("/")[-1] + }, + "packageRef": { + "identity": .identity, + "kind": .kind, + "location": .location, + "name": .location | sub("\\.git$"; "") | split("/")[-1] + }, + "state": { + "name": "edited", + "path": null + }, + "subpath": .location | sub("\\.git$"; "") | split("/")[-1] + } + ], + "prebuilts": [ ] + }, + "version": 7 + } + ' < "$vendorStaging/Package.resolved" > "$out/workspace-state.json" + + # Symlink the packages from the staging area. There’s no reason to waste space copying them. + ln -s "$vendorStaging/Packages" "$out/Packages" + '' diff --git a/pkgs/development/compilers/swift/by-name/ll/llvmPackages/package.nix b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/package.nix new file mode 100644 index 000000000000..8818d083d358 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/package.nix @@ -0,0 +1,174 @@ +# Swift needs to be built against the matching tag from the LLVM fork in the swiftlang repo. +# Ideally, it would build against upstream LLVM, but it depends on APIs that have not been upstreamed. +# For example: https://github.com/swiftlang/llvm-project/blob/901f89886dcd5d1eaf07c8504d58c90f37b0cfdf/clang/include/clang/AST/StableHash.h + +{ + lib, + apple-sdk_26, + darwin, + fetchFromGitHub, + generateSplicesForMkScope, + libuuid, + lld, + llvmPackages_19, # Needs to match the `llvmVersion` of the fork. + python3, + stdenv, + stdlib, + swift-cmark, + swiftc, + swift_release, + swift_sources, +}: + +let + swiftLlvmVersion = "17.0.0"; # From https://github.com/swiftlang/swift/blob/swift-$swiftVersion-RELEASE/utils/build_swift/build_swift/defaults.py#L51 + llvmVersion = "19.1.5"; # From https://github.com/swiftlang/llvm-project/blob/swift-$swiftVersion-RELEASE/cmake/Modules/LLVMVersion.cmake +in + +(llvmPackages_19.override { + officialRelease.version = llvmVersion; + + monorepoSrc = fetchFromGitHub { + owner = "swiftlang"; + repo = "llvm-project"; + tag = "swift-${swift_release}-RELEASE"; + inherit (swift_sources.llvm-project) hash; + }; + + otherSplices = generateSplicesForMkScope [ + "swiftPackages" + "llvmPackages" + ]; + + patchesFn = + patches: + patches + // { + # Updated patch that also prevents Clang from trying to copy `clang-deps-launcher.py` to `${llvm}/bin`. + "clang/gnu-install-dirs.patch" = [ { path = ./patches; } ]; + # The patch needs slightly tweaked to apply to Swift’s LLDB fork. + "lldb/backport-ParseTrieEntries-fixes.patch" = [ { path = ./patches; } ]; + # Update backport of the Darwin triple changes for macOS 27. + "llvm/backport-darwin-triple-parsing.patch" = [ { path = ./patches; } ]; + # Backport support for arm64e.x1, the new cpu subtype for A20 and M6 + "llvm/backport-minimal-arm64e_x1-support.patch" = [ { path = ./patches; } ]; + }; +}).overrideScope + ( + final: prev: { + version = swiftLlvmVersion; + release_version = llvmVersion; + + libclang = + let + clangWithLauncher = prev.libclang.overrideAttrs (old: { + postInstall = (old.postInstall or "") + '' + moveToOutput bin/clang-deps-launcher.py "$python" + ''; + }); + in + final.callPackage clangWithLauncher.override { inherit stdenv; }; + + libllvm = + let + # The Swift build system expects to link statically against LLVM. Trying to link to the `libLLVM` shared + # library causes `swift-frontend` to crash during the build on Linux. + staticLibllvm = final.callPackage prev.libllvm.override { + inherit stdenv; + enableSharedLibraries = false; + }; + in + staticLibllvm.overrideAttrs ( + old: + # Don’t apply the following changes when manpages are built, + # which nulls out these attrs and sets `doCheck` to false. + lib.optionalAttrs (old.pname != "llvm-manpages") { + patches = (old.patches or [ ]) ++ [ + # Ensure the LLVM module cache is in a writable location during builds. + ./patches/llvm/module-cache.patch + ]; + doCheck = false; # TODO: fix fork-specific tests that fail due to, e.g., not finding `libLLVM.dylib` during the test + # Swift relies on LLVM’s private `config.h` for feature checks (e.g., for `unistd.h`). + postInstall = (old.postInstall or "") + '' + cp include/llvm/Config/config.h "$dev/include/llvm/Config/config.h" + ''; + } + ); + + lldb = + let + python3-with-distutils = python3.withPackages (pkgs: [ pkgs.distutils ]); + + swiftLLDB = prev.lldb.overrideAttrs (old: { + patches = (old.patches or [ ]) ++ [ + # The LLDB build on Linux assumes the rpath is set relative to the toolchain and that `SWIFT_LIBRARY_DIR` + # consists of only one path (and is not a list). It needs to point to the stdlib. + ./patches/lldb/0001-Set-stdlib-path-on-Linux.patch + # Otherwise, linking `lldb-server` fails with a missing symbol error on Linux. + ./patches/lldb/0002-Link-lldb-server-to-swiftCore.patch + # Don’t resolve the liblldb symlink to help it find the Swift toolchain that it’s linked into. + ./patches/lldb/0003-Don-t-follow-symlinks-when-finding-liblldb.patch + # Darwin needs to find the path to LLDB via the main executable because dyld always resolves symlinks + # when loading dylibs from disk. + ./patches/lldb/0004-Use-the-LLDB-executable-path-to-find-the-stdlib.patch + ]; + buildInputs = + (old.buildInputs or [ ]) + ++ [ + stdlib # The LLDB build system expects the stdlib libraries to be available on the default linker path. + ] + # For `swift_coroFrameAlloc`, which needs an SDK with libswiftCore text-based stubs that have the symbol. + ++ lib.optionals stdenv.hostPlatform.isDarwin [ apple-sdk_26 ]; + # Swift’s fork of LLDB has extra requirements. + nativeBuildInputs = + (old.nativeBuildInputs or [ ]) + ++ [ + python3-with-distutils # distutils is needed for the bundled Python plugin. + ] + ++ lib.optionals stdenv.hostPlatform.isDarwin [ + darwin.sigtool # Required for code-signing. + lld # Otherwise results in `can't find ordinal for imported symbol '_objc_opt_self'` when linking. + ]; + # These aren’t set correctly otherwise. The LLDB build system needs an explicit Swift path regardless. + cmakeFlags = + (old.cmakeFlags or [ ]) + ++ [ + (lib.cmakeFeature "LLVM_DIR" "${lib.getDev final.libllvm}/lib/cmake/llvm") + (lib.cmakeFeature "Swift_DIR" "${lib.getOutput "static" swiftc}") + (lib.cmakeFeature "cmark-gfm_DIR" "${swift-cmark.out}/lib/cmake") + (lib.cmakeFeature "LLDB_SWIFT_LIBS" "${lib.getDev stdlib}/lib/swift") + # LLDB looks for Clang’s resource root in `${swiftc}/lib/swift/clang`. When it’s not there, which it’s + # not because it’s been moved to the `swift` package, LLDB falls back to `CLANG_RESOURCE_DIR`, + # but that’s `libclang.lib`, which also doesn’t have it. So use the wrapped Clang’s resource root. + (lib.cmakeFeature "CLANG_RESOURCE_DIR" "../../../../${lib.getBin final.clang}/resource-root") + ] + ++ lib.optionals stdenv.hostPlatform.isDarwin [ + (lib.cmakeFeature "CMAKE_LINKER_TYPE" "LLD") # Darwin fails to link correctly using ld64 (see above). + ]; + + # Make sure LLDB can find the Swift compiler shared libraries. + postInstall = + (old.postInstall or "") + + lib.optionalString stdenv.hostPlatform.isElf '' + for output in $(getAllOutputNames); do + while IFS= read -d "" f; do + if isELF "$f"; then + # Make sure all rpaths are present. Why is libuuid getting dropped? I have no idea. + patchelf --add-rpath ${ + lib.escapeShellArg (lib.makeSearchPathOutput "out" "lib/swift/host/compiler" [ swiftc ]) + } "$f" || true + patchelf --add-rpath ${lib.escapeShellArg (lib.makeLibraryPath [ libuuid ])} "$f" || true + fi + done < <(find "''${!output}" -type f -print0) + done + # Reduce LLDB closure size by symlinking `lib/swift` into LLDB instead of copying it. + rm -rf "''$out/lib/swift" + ln -s ${lib.escapeShellArg swiftc}/lib/swift "$out/lib/swift" + ''; + }); + in + # Linux tries to use a GCC stdenv to build LLDB, but the Swift headers aren’t compatible with GCC. + # The stdenv passed in from the package set arguments is the Clang-based stdenv from `swift-packages.nix`. + final.callPackage swiftLLDB.override { inherit stdenv; }; + } + ) diff --git a/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/clang/gnu-install-dirs.patch b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/clang/gnu-install-dirs.patch new file mode 100644 index 000000000000..56fe048df79d --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/clang/gnu-install-dirs.patch @@ -0,0 +1,95 @@ +diff --git a/cmake/modules/AddClang.cmake b/cmake/modules/AddClang.cmake +index 75b0080f6..c895b884c 100644 +--- a/cmake/modules/AddClang.cmake ++++ b/cmake/modules/AddClang.cmake +@@ -119,8 +119,8 @@ macro(add_clang_library name) + install(TARGETS ${lib} + COMPONENT ${lib} + ${export_to_clangtargets} +- LIBRARY DESTINATION lib${LLVM_LIBDIR_SUFFIX} +- ARCHIVE DESTINATION lib${LLVM_LIBDIR_SUFFIX} ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}${LLVM_LIBDIR_SUFFIX}" ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}${LLVM_LIBDIR_SUFFIX}" + RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") + + if (NOT LLVM_ENABLE_IDE) +diff --git a/lib/Headers/CMakeLists.txt b/lib/Headers/CMakeLists.txt +index e6ae4e19e..5ef01aea2 100644 +--- a/lib/Headers/CMakeLists.txt ++++ b/lib/Headers/CMakeLists.txt +@@ -337,6 +337,7 @@ set(llvm_libc_wrapper_files + + include(GetClangResourceDir) + get_clang_resource_dir(output_dir PREFIX ${LLVM_LIBRARY_OUTPUT_INTDIR}/.. SUBDIR include) ++set(header_install_dir ${CMAKE_INSTALL_LIBDIR}${LLVM_LIBDIR_SUFFIX}/clang/${CLANG_VERSION_MAJOR}/include) + set(out_files) + set(generated_files) + +diff --git a/tools/libclang/CMakeLists.txt b/tools/libclang/CMakeLists.txt +index b5b6d2807..6b592d255 100644 +--- a/tools/libclang/CMakeLists.txt ++++ b/tools/libclang/CMakeLists.txt +@@ -246,7 +246,7 @@ foreach(PythonVersion ${CLANG_PYTHON_BINDINGS_VERSIONS}) + COMPONENT + libclang-python-bindings + DESTINATION +- "lib${LLVM_LIBDIR_SUFFIX}/python${PythonVersion}/site-packages") ++ "${CMAKE_INSTALL_LIBDIR}${LLVM_LIBDIR_SUFFIX}/python${PythonVersion}/site-packages") + endforeach() + if(NOT LLVM_ENABLE_IDE) + add_custom_target(libclang-python-bindings) +diff --git a/tools/scan-build-py/CMakeLists.txt b/tools/scan-build-py/CMakeLists.txt +index 3aca22c0b..3115353e3 100644 +--- a/tools/scan-build-py/CMakeLists.txt ++++ b/tools/scan-build-py/CMakeLists.txt +@@ -88,7 +88,7 @@ foreach(lib ${LibScanbuild}) + DEPENDS ${CMAKE_CURRENT_SOURCE_DIR}/lib/libscanbuild/${lib}) + list(APPEND Depends ${CMAKE_BINARY_DIR}/lib/libscanbuild/${lib}) + install(FILES lib/libscanbuild/${lib} +- DESTINATION lib/libscanbuild ++ DESTINATION "${CMAKE_INSTALL_LIBDIR}/libscanbuild" + COMPONENT scan-build-py) + endforeach() + +@@ -106,7 +106,7 @@ foreach(resource ${LibScanbuildResources}) + DEPENDS ${CMAKE_CURRENT_SOURCE_DIR}/lib/libscanbuild/resources/${resource}) + list(APPEND Depends ${CMAKE_BINARY_DIR}/lib/libscanbuild/resources/${resource}) + install(FILES lib/libscanbuild/resources/${resource} +- DESTINATION lib/libscanbuild/resources ++ DESTINATION "${CMAKE_INSTALL_LIBDIR}/libscanbuild/resources" + COMPONENT scan-build-py) + endforeach() + +@@ -122,7 +122,7 @@ foreach(lib ${LibEar}) + DEPENDS ${CMAKE_CURRENT_SOURCE_DIR}/lib/libear/${lib}) + list(APPEND Depends ${CMAKE_BINARY_DIR}/lib/libear/${lib}) + install(FILES lib/libear/${lib} +- DESTINATION lib/libear ++ DESTINATION "${CMAKE_INSTALL_LIBDIR}/libear" + COMPONENT scan-build-py) + endforeach() + +diff --git a/clang/tools/clang-scan-deps/CMakeLists.txt b/clang/tools/clang-scan-deps/CMakeLists.txt +index d0ab60b890..7cec331b68 100644 +--- a/tools/clang-scan-deps/CMakeLists.txt ++++ b/tools/clang-scan-deps/CMakeLists.txt +@@ -36,17 +36,9 @@ + ${CLANG_SCAN_DEPS_LIB_DEPS} + ) + +-add_custom_command(OUTPUT ${LLVM_TOOLS_BINARY_DIR}/clang-deps-launcher.py +- DEPENDS ${CMAKE_CURRENT_SOURCE_DIR}/clang-deps-launcher.py +- COMMAND ${CMAKE_COMMAND} -E copy_if_different +- "${CMAKE_CURRENT_SOURCE_DIR}/clang-deps-launcher.py" +- "${LLVM_TOOLS_BINARY_DIR}/clang-deps-launcher.py" +- COMMENT "Copy clang-deps-launcher.py..." +- ) +- +-add_custom_target(clang-deps-launcher ALL DEPENDS ${LLVM_TOOLS_BINARY_DIR}/clang-deps-launcher.py) ++add_custom_target(clang-deps-launcher ALL DEPENDS ${CMAKE_CURRENT_SOURCE_DIR}/clang-deps-launcher.py) + install( +- FILES ${LLVM_TOOLS_BINARY_DIR}/clang-deps-launcher.py ++ FILES ${CMAKE_CURRENT_SOURCE_DIR}/clang-deps-launcher.py + DESTINATION bin + PERMISSIONS OWNER_READ OWNER_WRITE OWNER_EXECUTE GROUP_READ GROUP_EXECUTE WORLD_READ WORLD_EXECUTE + COMPONENT clang-deps-launcher) diff --git a/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/lldb/0001-Set-stdlib-path-on-Linux.patch b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/lldb/0001-Set-stdlib-path-on-Linux.patch new file mode 100644 index 000000000000..e2862a504d38 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/lldb/0001-Set-stdlib-path-on-Linux.patch @@ -0,0 +1,30 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Tue, 21 Jul 2026 23:04:32 -0400 +Subject: [PATCH 1/4] Set stdlib path on Linux + +--- + tools/repl/swift/CMakeLists.txt | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/tools/repl/swift/CMakeLists.txt b/tools/repl/swift/CMakeLists.txt +index 46989e7c25b5..4199b71f488d 100644 +--- a/tools/repl/swift/CMakeLists.txt ++++ b/tools/repl/swift/CMakeLists.txt +@@ -26,11 +26,11 @@ elseif(CMAKE_SYSTEM_NAME STREQUAL Linux) + BUILD_RPATH ${SWIFT_LIBRARY_DIR}/swift/linux/powerpc64le) + else() + set_target_properties(repl_swift PROPERTIES +- BUILD_RPATH ${SWIFT_LIBRARY_DIR}/swift/linux) ++ BUILD_RPATH ${SWIFT_STDLIB_DIR}) + endif() + set_target_properties(repl_swift PROPERTIES + BUILD_WITH_INSTALL_RPATH NO +- INSTALL_RPATH "$ORIGIN/../lib/swift/linux") ++ INSTALL_RPATH ${SWIFT_STDLIB_DIR}) + endif() + + # The dummy repl executable is a C program, but we always look for a mangled +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/lldb/0002-Link-lldb-server-to-swiftCore.patch b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/lldb/0002-Link-lldb-server-to-swiftCore.patch new file mode 100644 index 000000000000..a058fb4b327e --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/lldb/0002-Link-lldb-server-to-swiftCore.patch @@ -0,0 +1,28 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Wed, 22 Jul 2026 21:02:05 -0400 +Subject: [PATCH 2/4] Link lldb-server to swiftCore + +Fixes a missing symbol error when linking lldb-server on Linux: + + ld.bfd: /lib/libswiftASTGen.a(LexicalLookup.swift.o): undefined reference to symbol '$ss10SetAlgebraP9formUnionyyxnFTq' + ld.bfd: /lib/libswiftCore.so: error adding symbols: DSO missing from command line +--- + tools/lldb-server/CMakeLists.txt | 1 + + 1 file changed, 1 insertion(+) + +diff --git a/tools/lldb-server/CMakeLists.txt b/tools/lldb-server/CMakeLists.txt +index 4ac3fddf2b53..6c2603626e44 100644 +--- a/tools/lldb-server/CMakeLists.txt ++++ b/tools/lldb-server/CMakeLists.txt +@@ -55,6 +55,7 @@ add_lldb_tool(lldb-server + lldbPluginInstructionMIPS64 + lldbPluginInstructionRISCV + ${LLDB_SYSTEM_LIBS} ++ swiftCore + + LINK_COMPONENTS + Option +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/lldb/0003-Don-t-follow-symlinks-when-finding-liblldb.patch b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/lldb/0003-Don-t-follow-symlinks-when-finding-liblldb.patch new file mode 100644 index 000000000000..2bd1bb7172af --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/lldb/0003-Don-t-follow-symlinks-when-finding-liblldb.patch @@ -0,0 +1,92 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Wed, 5 Aug 2026 07:36:33 -0400 +Subject: [PATCH 3/4] =?UTF-8?q?Don=E2=80=99t=20follow=20symlinks=20when=20?= + =?UTF-8?q?finding=20liblldb?= +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Various dependencies are symlinked together into the Swift toolchain in +Nixpkgs. If LLDB resolves the location of liblldb, it will always find +it in the LLDB derivation’s output, which prevents finding the Swift +toolchain when running the Swift REPL. +--- + include/lldb/Host/Host.h | 2 +- + source/Host/common/Host.cpp | 6 ++++-- + source/Host/common/HostInfoBase.cpp | 6 +++++- + source/Host/windows/Host.cpp | 2 +- + 4 files changed, 11 insertions(+), 5 deletions(-) + +diff --git a/include/lldb/Host/Host.h b/include/lldb/Host/Host.h +index 23d5383163ff..4a17900be75d 100644 +--- a/include/lldb/Host/Host.h ++++ b/include/lldb/Host/Host.h +@@ -120,7 +120,7 @@ public: + /// \b A file spec with the module that contains \a host_addr, + /// which may be invalid if \a host_addr doesn't fall into + /// any valid module address range. +- static FileSpec GetModuleFileSpecForHostAddress(const void *host_addr); ++ static FileSpec GetModuleFileSpecForHostAddress(const void *host_addr, bool resolvePath = true); + + /// If you have an executable that is in a bundle and want to get back to + /// the bundle directory from the path itself, this function will change a +diff --git a/source/Host/common/Host.cpp b/source/Host/common/Host.cpp +index 04380c6255f1..2510f2d7b54e 100644 +--- a/source/Host/common/Host.cpp ++++ b/source/Host/common/Host.cpp +@@ -344,14 +344,16 @@ bool Host::ResolveExecutableInBundle(FileSpec &file) { return false; } + + #ifndef _WIN32 + +-FileSpec Host::GetModuleFileSpecForHostAddress(const void *host_addr) { ++FileSpec Host::GetModuleFileSpecForHostAddress(const void *host_addr, bool resolvePath) { + FileSpec module_filespec; + #if !defined(__ANDROID__) + Dl_info info; + if (::dladdr(host_addr, &info)) { + if (info.dli_fname) { + module_filespec.SetFile(info.dli_fname, FileSpec::Style::native); +- FileSystem::Instance().Resolve(module_filespec); ++ if (resolvePath) { ++ FileSystem::Instance().Resolve(module_filespec); ++ } + } + } + #endif +diff --git a/source/Host/common/HostInfoBase.cpp b/source/Host/common/HostInfoBase.cpp +index 5c44c2f38b28..cb10bded1470 100644 +--- a/source/Host/common/HostInfoBase.cpp ++++ b/source/Host/common/HostInfoBase.cpp +@@ -249,10 +249,14 @@ bool HostInfoBase::ComputeSharedLibraryDirectory(FileSpec &file_spec) { + // On other posix systems, we will get .../lib(64|32)?/liblldb.so. + + FileSpec lldb_file_spec(Host::GetModuleFileSpecForHostAddress( +- reinterpret_cast(HostInfoBase::ComputeSharedLibraryDirectory))); ++ reinterpret_cast(HostInfoBase::ComputeSharedLibraryDirectory), /* resolvePath */ false)); + ++// If g_shlib_dir_helper is set on Linux, it will resolve the symlink, which we don’t want. ++// Getting the shared library where it is saves ~280 MiB of toolchain closure size. ++#ifdef _WIN32 + if (g_shlib_dir_helper) + g_shlib_dir_helper(lldb_file_spec); ++#endif + + // Remove the filename so that this FileSpec only represents the directory. + file_spec.SetDirectory(lldb_file_spec.GetDirectory()); +diff --git a/source/Host/windows/Host.cpp b/source/Host/windows/Host.cpp +index e8973a3fb937..5955cf742059 100644 +--- a/source/Host/windows/Host.cpp ++++ b/source/Host/windows/Host.cpp +@@ -113,7 +113,7 @@ void Host::Kill(lldb::pid_t pid, int signo) { + + const char *Host::GetSignalAsCString(int signo) { return NULL; } + +-FileSpec Host::GetModuleFileSpecForHostAddress(const void *host_addr) { ++FileSpec Host::GetModuleFileSpecForHostAddress(const void *host_addr, bool resolvePath) { + FileSpec module_filespec; + + HMODULE hmodule = NULL; +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/lldb/0004-Use-the-LLDB-executable-path-to-find-the-stdlib.patch b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/lldb/0004-Use-the-LLDB-executable-path-to-find-the-stdlib.patch new file mode 100644 index 000000000000..6e6d60cbbafb --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/lldb/0004-Use-the-LLDB-executable-path-to-find-the-stdlib.patch @@ -0,0 +1,33 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 5 Sep 2026 08:24:48 -0400 +Subject: [PATCH 4/4] Use the LLDB executable path to find the stdlib + +dyld always resolves symlinks when loading an image, which prevents +`GetModuleFileSpecForHostAddress` from returning the unresolved path to +`liblldb.dylib`. We could break the symlink by copying the dylib, but +that would make the closure much larger. Fortunately, we can use the +path of the LLDB executable, which will need to be copied into the +toolchain anyway for other reasons. +--- + source/Host/macosx/objcxx/HostInfoMacOSXSwift.cpp | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/source/Host/macosx/objcxx/HostInfoMacOSXSwift.cpp b/source/Host/macosx/objcxx/HostInfoMacOSXSwift.cpp +index 716d0fbb4f63..18ed6cf55ff7 100644 +--- a/source/Host/macosx/objcxx/HostInfoMacOSXSwift.cpp ++++ b/source/Host/macosx/objcxx/HostInfoMacOSXSwift.cpp +@@ -79,8 +79,8 @@ FileSpec HostInfoMacOSX::GetSwiftResourceDir() { + static std::once_flag g_once_flag; + static FileSpec g_swift_resource_dir; + std::call_once(g_once_flag, []() { +- FileSpec lldb_file_spec = HostInfo::GetShlibDir(); +- ComputeSwiftResourceDirectory(lldb_file_spec, g_swift_resource_dir, true); ++ auto exe_path = HostInfoMacOSX::GetProgramFileSpec().CopyByRemovingLastPathComponent(); ++ ComputeSwiftResourceDirectory(exe_path, g_swift_resource_dir, true); + Log *log = GetLog(LLDBLog::Host); + LLDB_LOG(log, "swift dir -> '{0}'", g_swift_resource_dir); + }); +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/lldb/backport-ParseTrieEntries-fixes.patch b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/lldb/backport-ParseTrieEntries-fixes.patch new file mode 100644 index 000000000000..82961ad15398 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/lldb/backport-ParseTrieEntries-fixes.patch @@ -0,0 +1,125 @@ +diff --git a/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp b/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp +index 9fe3e27ca0..2040879a51 100644 +--- a/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp ++++ b/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp +@@ -144,6 +144,14 @@ + static constexpr llvm::StringLiteral g_loader_path = "@loader_path"; + static constexpr llvm::StringLiteral g_executable_path = "@executable_path"; + ++/// Upper bound on the length of a symbol name assembled from export-trie edge ++/// labels. A corrupt trie can encode an edge label whose terminator is far ++/// away in the trie data, so a single label is many megabytes long; appending ++/// it to the running name would otherwise request an unbounded allocation. No ++/// legitimate symbol name comes close to this size. Also 1 MiB is the ++/// symbol length limit in ld. ++static constexpr size_t kMaxTrieSymbolNameLength = 1 << 20; // 1 MiB ++ + LLDB_PLUGIN_DEFINE(ObjectFileMachO) + + static void PrintRegisterValue(RegisterContext *reg_ctx, const char *name, +@@ -2213,15 +2221,21 @@ + } + }; + +-static bool ParseTrieEntries(DataExtractor &data, lldb::offset_t offset, +- const bool is_arm, addr_t text_seg_base_addr, +- std::vector &nameSlices, +- std::set &resolver_addresses, +- std::vector &reexports, +- std::vector &ext_symbols) { ++static bool ParseTrieEntriesImpl(DataExtractor &data, lldb::offset_t offset, ++ const bool is_arm, addr_t text_seg_base_addr, ++ std::string &prefix, ++ std::set &resolver_addresses, ++ std::vector &reexports, ++ std::vector &ext_symbols, ++ std::set &visited_nodes) { + if (!data.ValidOffset(offset)) + return true; + ++ // Every node in a well-formed trie is reached by exactly one path, so a node ++ // offset seen twice means the trie is corrupt. ++ if (!visited_nodes.insert(offset).second) ++ return false; ++ + // Terminal node -- end of a branch, possibly add this to + // the symbol table or resolver table. + const uint64_t terminalSize = data.GetULEB128(&offset); +@@ -2261,14 +2275,9 @@ + add_this_entry = true; + } + if (add_this_entry) { +- std::string name; +- if (!nameSlices.empty()) { +- for (auto name_slice : nameSlices) +- name.append(name_slice.data(), name_slice.size()); +- } +- if (name.size() > 1) { ++ if (prefix.size() > 1) { + // Skip the leading '_' +- e.entry.name.SetCStringWithLength(name.c_str() + 1, name.size() - 1); ++ e.entry.name.SetString(llvm::StringRef(prefix).drop_front()); + } + if (import_name) { + // Skip the leading '_' +@@ -2289,23 +2298,37 @@ + const uint8_t childrenCount = data.GetU8(&children_offset); + for (uint8_t i = 0; i < childrenCount; ++i) { + const char *cstr = data.GetCStr(&children_offset); +- if (cstr) +- nameSlices.push_back(llvm::StringRef(cstr)); +- else ++ if (!cstr) + return false; // Corrupt data ++ if (prefix.size() + llvm::StringRef(cstr).size() > kMaxTrieSymbolNameLength) ++ return false; // Corrupt data: implausibly long symbol name. ++ const size_t prevSize = prefix.size(); ++ prefix.append(cstr); + lldb::offset_t childNodeOffset = data.GetULEB128(&children_offset); +- if (childNodeOffset) { +- if (!ParseTrieEntries(data, childNodeOffset, is_arm, text_seg_base_addr, +- nameSlices, resolver_addresses, reexports, +- ext_symbols)) { +- return false; +- } +- } +- nameSlices.pop_back(); ++ // A child offset of 0 points back at the root; like any other repeated ++ // offset it is a cycle, which ParseTrieEntriesImpl rejects as corrupt. ++ if (!ParseTrieEntriesImpl(data, childNodeOffset, is_arm, text_seg_base_addr, ++ prefix, resolver_addresses, reexports, ++ ext_symbols, visited_nodes)) ++ return false; ++ prefix.resize(prevSize); + } + return true; + } + ++static bool ParseTrieEntries( ++ DataExtractor &data, const bool is_arm, lldb::addr_t text_seg_base_addr, ++ std::set &resolver_addresses, ++ std::vector &reexports, ++ std::vector &ext_symbols) { ++ lldb::offset_t offset = 0; ++ std::set visited_nodes; ++ std::string prefix; ++ return ParseTrieEntriesImpl(data, offset, is_arm, text_seg_base_addr, prefix, ++ resolver_addresses, reexports, ext_symbols, ++ visited_nodes); ++} ++ + static bool + TryParseV2ObjCMetadataSymbol(const char *&symbol_name, + const char *&symbol_name_non_abi_mangled, +@@ -2887,9 +2910,8 @@ + lldb::addr_t text_segment_file_addr = LLDB_INVALID_ADDRESS; + if (text_segment_sp) + text_segment_file_addr = text_segment_sp->GetFileAddress(); +- std::vector nameSlices; +- ParseTrieEntries(dyld_trie_data, 0, is_arm, text_segment_file_addr, +- nameSlices, resolver_addresses, reexport_trie_entries, ++ ParseTrieEntries(dyld_trie_data, is_arm, text_segment_file_addr, ++ resolver_addresses, reexport_trie_entries, + external_sym_trie_entries); + } + diff --git a/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/llvm/backport-darwin-triple-parsing.patch b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/llvm/backport-darwin-triple-parsing.patch new file mode 100644 index 000000000000..e8965369cc56 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/llvm/backport-darwin-triple-parsing.patch @@ -0,0 +1,19 @@ +diff --git a/lib/TargetParser/Triple.cpp b/lib/TargetParser/Triple.cpp +index 53922e7586..665e1e1d62 100644 +--- a/lib/TargetParser/Triple.cpp ++++ b/lib/TargetParser/Triple.cpp +@@ -1398,9 +1398,12 @@ + } else if (Version.getMajor() < 25) { + // darwin20-24 corresponds to macOS 11-15. + Version = VersionTuple(11 + Version.getMajor() - 20); +- } else { +- // darwin25 corresponds with macOS26+. ++ } else if ((Version.getMajor() == 25) || (Version.getMajor() == 26)) { ++ // darwin25-26 corresponds to macOS 26-27. + Version = VersionTuple(Version.getMajor() + 1); ++ } else { ++ // Starting with darwin27, it naturally corresponds to the same macOS ++ // version. + } + break; + case MacOSX: diff --git a/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/llvm/backport-minimal-arm64e_x1-support.patch b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/llvm/backport-minimal-arm64e_x1-support.patch new file mode 100644 index 000000000000..78c93624c17a --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/llvm/backport-minimal-arm64e_x1-support.patch @@ -0,0 +1,205 @@ +--- llvm/include/llvm/BinaryFormat/MachO.h ++++ llvm/include/llvm/BinaryFormat/MachO.h +@@ -1643,6 +1643,7 @@ + CPU_SUBTYPE_ARM64_ALL = 0, + CPU_SUBTYPE_ARM64_V8 = 1, + CPU_SUBTYPE_ARM64E = 2, ++ CPU_SUBTYPE_ARM64E_X1 = 12, + + // arm64 reserves bits in the high byte for subtype-specific flags. + // On arm64e, the 6 low bits represent the ptrauth ABI version. +--- llvm/include/llvm/TargetParser/Triple.h ++++ llvm/include/llvm/TargetParser/Triple.h +@@ -147,6 +147,7 @@ + ARMSubArch_v4t, + + AArch64SubArch_arm64e, ++ AArch64SubArch_arm64e_x1, + AArch64SubArch_arm64ec, + + KalimbaSubArch_v3, +@@ -1048,6 +1049,11 @@ + getSubArch() == Triple::AArch64SubArch_arm64e; + } + ++ bool isArm64e_x1() const { ++ return getArch() == Triple::aarch64 && ++ getSubArch() == Triple::AArch64SubArch_arm64e_x1; ++ } ++ + /// Tests whether the target is X32. + bool isX32() const { + EnvironmentType Env = getEnvironment(); +--- llvm/include/llvm/TextAPI/Architecture.def ++++ llvm/include/llvm/TextAPI/Architecture.def +@@ -37,7 +37,7 @@ + /// + ARCHINFO(arm64, arm64, MachO::CPU_TYPE_ARM64, MachO::CPU_SUBTYPE_ARM64_ALL, 64) + ARCHINFO(arm64e, arm64e, MachO::CPU_TYPE_ARM64, MachO::CPU_SUBTYPE_ARM64E, 64) +- ++ARCHINFO(arm64e_x1, arm64e.x1, MachO::CPU_TYPE_ARM64, MachO::CPU_SUBTYPE_ARM64E_X1, 64) + + /// + /// ARM64_32 architectures sorted by cpu sub type id +--- llvm/lib/BinaryFormat/MachO.cpp ++++ llvm/lib/BinaryFormat/MachO.cpp +@@ -60,6 +60,8 @@ + return (MachO::CPUSubTypeARM64)MachO::CPU_SUBTYPE_ARM64_32_V8; + if (T.isArm64e()) + return MachO::CPU_SUBTYPE_ARM64E; ++ if (T.isArm64e_x1()) ++ return MachO::CPU_SUBTYPE_ARM64E_X1; + + return MachO::CPU_SUBTYPE_ARM64_ALL; + } +--- llvm/lib/Object/MachOObjectFile.cpp ++++ llvm/lib/Object/MachOObjectFile.cpp +@@ -2810,6 +2810,12 @@ + if (ArchFlag) + *ArchFlag = "arm64e"; + return Triple("arm64e-apple-darwin"); ++ case MachO::CPU_SUBTYPE_ARM64E_X1: ++ if (McpuDefault) ++ *McpuDefault = "apple-a20"; ++ if (ArchFlag) ++ *ArchFlag = "arm64e.x1"; ++ return Triple("arm64e.x1-apple-darwin"); + default: + return Triple(); + } +--- llvm/lib/TargetParser/Triple.cpp ++++ llvm/lib/TargetParser/Triple.cpp +@@ -114,6 +114,8 @@ + return "arm64ec"; + if (SubArch == AArch64SubArch_arm64e) + return "arm64e"; ++ if (SubArch == AArch64SubArch_arm64e_x1) ++ return "arm64e.x1"; + break; + case Triple::dxil: + switch (SubArch) { +@@ -550,6 +552,7 @@ + .Case("arm64", Triple::aarch64) + .Case("arm64_32", Triple::aarch64_32) + .Case("arm64e", Triple::aarch64) ++ .Case("arm64e.x1", Triple::aarch64) + .Case("arm64ec", Triple::aarch64) + .Case("arm", Triple::arm) + .Case("armeb", Triple::armeb) +@@ -766,6 +769,8 @@ + + if (SubArchName == "arm64e") + return Triple::AArch64SubArch_arm64e; ++ if (SubArchName == "arm64e.x1") ++ return Triple::AArch64SubArch_arm64e_x1; + + if (SubArchName == "arm64ec") + return Triple::AArch64SubArch_arm64ec; +--- llvm/test/tools/llvm-readobj/MachO/file-headers-arm64.test ++++ llvm/test/tools/llvm-readobj/MachO/file-headers-arm64.test +@@ -13,6 +13,11 @@ + # RUN: llvm-readobj -h %t.arm64e \ + # RUN: | FileCheck %s --strict-whitespace --match-full-lines -DFILE=%t.arm64e --check-prefix=ARM64 -DSUBTYPE="CPU_SUBTYPE_ARM64E (0x2)" + ++## Check subtype Arm64E.X1: ++# RUN: yaml2obj %s -o %t.arm64e.x1 -DSUBTYPE=0xC ++# RUN: llvm-readobj -h %t.arm64e.x1 \ ++# RUN: | FileCheck %s --strict-whitespace --match-full-lines -DFILE=%t.arm64e.x1 --check-prefix=ARM64 -DSUBTYPE="CPU_SUBTYPE_ARM64E_X1 (0xC)" ++ + # ARM64:File: [[FILE]] + # ARM64-NEXT:Format: Mach-O arm64{{e?}} + # ARM64-NEXT:Arch: aarch64 +--- llvm/tools/llvm-objdump/MachODump.cpp ++++ llvm/tools/llvm-objdump/MachODump.cpp +@@ -2323,6 +2323,10 @@ + outs() << " cputype CPU_TYPE_ARM64\n"; + outs() << " cpusubtype CPU_SUBTYPE_ARM64E\n"; + break; ++ case MachO::CPU_SUBTYPE_ARM64E_X1: ++ outs() << " cputype CPU_TYPE_ARM64\n"; ++ outs() << " cpusubtype CPU_SUBTYPE_ARM64E_X1\n"; ++ break; + default: + printUnknownCPUType(cputype, cpusubtype); + break; +@@ -8333,6 +8337,9 @@ + case MachO::CPU_SUBTYPE_ARM64E: + outs() << " E"; + break; ++ case MachO::CPU_SUBTYPE_ARM64E_X1: ++ outs() << " E.X1"; ++ break; + default: + outs() << format(" %10d", cpusubtype & ~MachO::CPU_SUBTYPE_MASK); + break; +--- llvm/tools/llvm-readobj/MachODumper.cpp ++++ llvm/tools/llvm-readobj/MachODumper.cpp +@@ -170,6 +170,7 @@ + LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64_ALL), + LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64_V8), + LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64E), ++ LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64E_X1), + }; + + const EnumEntry MachOHeaderCpuSubtypesSPARC[] = { +--- llvm/unittests/BinaryFormat/MachOTest.cpp ++++ llvm/unittests/BinaryFormat/MachOTest.cpp +@@ -66,6 +66,7 @@ + CHECK_CPUTYPE("thumbv7-apple-darwin", MachO::CPU_TYPE_ARM); + CHECK_CPUTYPE("arm64-apple-darwin", MachO::CPU_TYPE_ARM64); + CHECK_CPUTYPE("arm64e-apple-darwin", MachO::CPU_TYPE_ARM64); ++ CHECK_CPUTYPE("arm64e.x1-apple-darwin", MachO::CPU_TYPE_ARM64); + CHECK_CPUTYPE("arm64_32-apple-darwin", MachO::CPU_TYPE_ARM64_32); + + { +@@ -107,6 +108,7 @@ + CHECK_CPUSUBTYPE("thumbv6-apple-darwin", MachO::CPU_SUBTYPE_ARM_V6); + CHECK_CPUSUBTYPE("arm64-apple-darwin", MachO::CPU_SUBTYPE_ARM64_ALL); + CHECK_CPUSUBTYPE("arm64e-apple-darwin", MachO::CPU_SUBTYPE_ARM64E); ++ CHECK_CPUSUBTYPE("arm64e.x1-apple-darwin", MachO::CPU_SUBTYPE_ARM64E_X1); + CHECK_CPUSUBTYPE("arm64_32-apple-darwin", MachO::CPU_SUBTYPE_ARM64_32_V8); + + { +--- /dev/null ++++ lld/test/MachO/arm64-x1.s +@@ -0,0 +1,20 @@ ++# REQUIRES: aarch64 ++ ++## Test that arm64.x1-macos is ignored instead of causing an error. ++## linked re-exported dylibs that only declare arm64e-macos targets, even if targeting arm64. ++# arm64 and arm64e are ABI compatible (same CPU type), and ld64 accepts this. ++ ++# RUN: rm -rf %t; split-file --no-leading-lines %s %t ++ ++# RUN: llvm-mc -filetype=obj -triple=arm64-apple-macos -o %t/test.o /dev/null ++ ++# RUN: %no-arg-lld -syslibroot %t/sdk -lSystem -dylib -arch arm64 \ ++# RUN: -platform_version macos 15 26 %t/test.o -o /dev/null ++ ++#--- sdk/usr/lib/libSystem.tbd ++--- !tapi-tbd ++tbd-version: 4 ++targets: [ arm64-macos, arm64e.x1-macos ] ++install-name: '/usr/lib/libSystem.dylib' ++current-version: 0001.001.1 ++... +--- /dev/null ++++ llvm/test/tools/llvm-readobj/macho-arm64e_x1.test +@@ -0,0 +1,17 @@ ++# RUN: yaml2obj %s -o %t.o ++# RUN: llvm-readobj -h %t.o | FileCheck %s ++ ++# CHECK: Magic: Magic64 (0xFEEDFACF) ++# CHECK: CpuType: Arm64 (0x100000C) ++# CHECK: CpuSubType: CPU_SUBTYPE_ARM64E_X1 (0xC) ++ ++--- !mach-o ++FileHeader: ++ magic: 0xFEEDFACF ++ cputype: 0x0100000C ++ cpusubtype: 0x0000000C ++ filetype: 0x00000001 ++ ncmds: 0 ++ sizeofcmds: 0 ++ flags: 0x00000000 ++ reserved: 0x00000000 diff --git a/pkgs/development/compilers/swift/compiler/patches/llvm-module-cache.patch b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/llvm/module-cache.patch similarity index 57% rename from pkgs/development/compilers/swift/compiler/patches/llvm-module-cache.patch rename to pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/llvm/module-cache.patch index 9a22d0482ea5..d140f1eb5587 100644 --- a/pkgs/development/compilers/swift/compiler/patches/llvm-module-cache.patch +++ b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/llvm/module-cache.patch @@ -3,12 +3,14 @@ cache. This patch detects and rejects the fake, non-existant $HOME used in Nix builds. We could simply return false in `cache_directory`, but that completely disables -module caching, and may unnecessarily slow down builds. Instead, let it use -'/tmp/.cache'. +module caching, and may unnecessarily slow down builds. Instead, let it use a +a `module-cache` folder at the top of the build. +diff --git a/lib/Support/Unix/Path.inc b/lib/Support/Unix/Path.inc +index 660b3a6a3fe0..92fad8a72534 100644 --- a/lib/Support/Unix/Path.inc +++ b/lib/Support/Unix/Path.inc -@@ -1380,6 +1380,9 @@ bool user_config_directory(SmallVectorImpl &result) { +@@ -1431,6 +1431,9 @@ bool user_config_directory(SmallVectorImpl &result) { if (!home_directory(result)) { return false; } @@ -18,12 +20,15 @@ module caching, and may unnecessarily slow down builds. Instead, let it use append(result, ".config"); return true; } -@@ -1401,6 +1404,9 @@ bool cache_directory(SmallVectorImpl &result) { +@@ -1452,6 +1455,12 @@ bool cache_directory(SmallVectorImpl &result) { if (!home_directory(result)) { return false; } -+ if (std::equal(result.begin(), result.end(), "/homeless-shelter")) { -+ system_temp_directory(true/*ErasedOnReboot*/, result); ++ if (const char *NixBuildTop = getenv("NIX_BUILD_TOP")) { ++ result.clear(); ++ result.append(NixBuildTop, NixBuildTop + strlen(NixBuildTop)); ++ append(result, "module-cache"); ++ return true; + } append(result, ".cache"); return true; diff --git a/pkgs/development/compilers/swift/by-name/so/sourcekit-lsp/Package.resolved b/pkgs/development/compilers/swift/by-name/so/sourcekit-lsp/Package.resolved new file mode 100644 index 000000000000..f084392f4564 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/so/sourcekit-lsp/Package.resolved @@ -0,0 +1,195 @@ +{ + "originHash" : "5f567b0c0cf4b1a211e9fb649f0b00e14f04b8ea55a3c96cc77462e3b6f933be", + "pins" : [ + { + "identity" : "indexstore-db", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/indexstore-db.git", + "state" : { + "branch" : "release/6.2", + "revision" : "cf29ef4e5e5243a3b6f518d72c6e527b5290375a" + } + }, + { + "identity" : "swift-argument-parser", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-argument-parser.git", + "state" : { + "revision" : "6a52f3251125d74daf04fcbd5e6f08a75d074382", + "version" : "1.8.2" + } + }, + { + "identity" : "swift-asn1", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-asn1.git", + "state" : { + "revision" : "a9a5efd40eaf558a2bcd48d64b1d1646be686008", + "version" : "1.7.1" + } + }, + { + "identity" : "swift-atomics", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-atomics.git", + "state" : { + "revision" : "0442cb5a3f98ab802acb777929fdb446bda11a34", + "version" : "1.3.1" + } + }, + { + "identity" : "swift-certificates", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-certificates.git", + "state" : { + "revision" : "2f797305c1b5b982acaa6005d8a9f970cc4e97ff", + "version" : "1.5.0" + } + }, + { + "identity" : "swift-cmark", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-cmark.git", + "state" : { + "branch" : "release/6.2", + "revision" : "5d9bdaa4228b381639fff09403e39a04926e2dbe" + } + }, + { + "identity" : "swift-collections", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-collections.git", + "state" : { + "revision" : "c11818f3cae0780656baa430b49e7f163f08dffd", + "version" : "1.1.6" + } + }, + { + "identity" : "swift-crypto", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-crypto.git", + "state" : { + "revision" : "629f0b679d0fd0a6ae823d7f750b9ab032c00b80", + "version" : "3.0.0" + } + }, + { + "identity" : "swift-docc", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-docc.git", + "state" : { + "branch" : "release/6.2", + "revision" : "4be8229cd268c2e4d036a848376b290ecbbc4d64" + } + }, + { + "identity" : "swift-docc-symbolkit", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-docc-symbolkit.git", + "state" : { + "branch" : "release/6.2", + "revision" : "467084cd380d352abcd128b27927ecdc8cb5bae8" + } + }, + { + "identity" : "swift-driver", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-driver.git", + "state" : { + "branch" : "release/6.2", + "revision" : "aedacc6c1583db4f2989a367e3c41968558a5b8e" + } + }, + { + "identity" : "swift-format", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-format.git", + "state" : { + "branch" : "release/6.2", + "revision" : "63687c7f450abe1fc96765e2caf173e82ebe780d" + } + }, + { + "identity" : "swift-llbuild", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-llbuild.git", + "state" : { + "branch" : "release/6.2", + "revision" : "073dff55529d7c4ecbd615ab5f5ac52ae5b380da" + } + }, + { + "identity" : "swift-lmdb", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-lmdb.git", + "state" : { + "branch" : "release/6.2", + "revision" : "1ad9a2d80b6fcde498c2242f509bd1be7d667ff8" + } + }, + { + "identity" : "swift-markdown", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-markdown.git", + "state" : { + "branch" : "release/6.2", + "revision" : "9063d10a2ac546227a0f08f3f7b4c6029d2757b1" + } + }, + { + "identity" : "swift-nio", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-nio.git", + "state" : { + "revision" : "cd3e1152083706d77b223fb29110e590efcc70c0", + "version" : "2.101.2" + } + }, + { + "identity" : "swift-package-manager", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-package-manager.git", + "state" : { + "branch" : "release/6.2", + "revision" : "215e9f91823d7e44c379fa17bf1eef189438fc24" + } + }, + { + "identity" : "swift-syntax", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-syntax.git", + "state" : { + "branch" : "release/6.2", + "revision" : "5a87516fc3dddbd23cb76358eb489915ee86b444" + } + }, + { + "identity" : "swift-system", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-system.git", + "state" : { + "revision" : "7502b711c92a17741fa625d722b0ccbd595d8ed1", + "version" : "1.7.2" + } + }, + { + "identity" : "swift-toolchain-sqlite", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-toolchain-sqlite", + "state" : { + "revision" : "05c9f4d17fae1eb586e716e11e5aa52bac464d00", + "version" : "1.0.10" + } + }, + { + "identity" : "swift-tools-support-core", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-tools-support-core.git", + "state" : { + "branch" : "release/6.2", + "revision" : "5a993c8848487c934d53ffceef8e1cad0a241dc1" + } + } + ], + "version" : 3 +} diff --git a/pkgs/development/compilers/swift/by-name/so/sourcekit-lsp/package.nix b/pkgs/development/compilers/swift/by-name/so/sourcekit-lsp/package.nix new file mode 100644 index 000000000000..3ceac0465b0a --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/so/sourcekit-lsp/package.nix @@ -0,0 +1,96 @@ +{ + lib, + fetchFromGitHub, + fetchSwiftPMDeps, + llvmPackages, + ncurses, + pkg-config, + replaceVars, + sqlite, + stdenv, + swift, + swift-corelibs-libdispatch, + swiftpm, + swift_release, + swift_sources, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "sourcekit-lsp"; + version = swift_release; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "sourcekit-lsp"; + tag = "swift-${finalAttrs.version}-RELEASE"; + inherit (swift_sources.sourcekit-lsp) hash; + }; + + patches = [ + # We can’t use the XCTest framework on Darwin and have to use swift-corelibs-xctest. Patch the `PerfTestCase` + # base class to build with it on Darwin. + ./patches/0001-Fix-for-using-swift-corelibs-xctest-on-Darwin.patch + # SourceKit-LSP tries to load IndexStore from the toolchain, but we want to load it from the store directly instead. + (replaceVars ./patches/0002-Load-IndexStore-from-the-store.patch { + libclang = lib.getLib llvmPackages.libclang; + }) + ]; + + # The SwiftPM patches can’t be included in the swiftpmDeps FOD because they reference store paths. + swiftpmPatches = swiftpm.patches; + + postPatch = '' + packagesPath=$(readlink -f Packages) + + rm Packages + cp -r "$packagesPath" Packages + chmod -R u+w Packages/swift-package-manager + + for p in "''${swiftpmPatches[@]}"; do + # Don’t apply the backdeploy patch because it creates a link to the Swift toolchain, + # which bloats up the SourceKit-LSP closure quite significantly. + if ! [[ $p =~ fix-backdeploy-rpath\.patch ]]; then + echo "applying patch $p" + patch -d Packages/swift-package-manager -p1 < "$p" + fi + done + ''; + + swiftpmDeps = fetchSwiftPMDeps { + inherit (finalAttrs) pname version src; + inherit (swift_sources.sourcekit-lsp.swiftpmDeps) hash; + + # Upstream doesn’t provide `Package.resolved`. + postPatch = '' + ln -s ${./Package.resolved} Package.resolved + ''; + }; + + strictDeps = true; + + nativeBuildInputs = [ + pkg-config + swift + swiftpm + ]; + + buildInputs = [ + ncurses + sqlite + ] + ++ lib.optionals (!stdenv.hostPlatform.isDarwin) [ swift-corelibs-libdispatch ]; + + # Tests crash with `*** bit out of range 0 - FD_SETSIZE on fd_set ***: terminated` + doCheck = false; # !stdenv.hostPlatform.isDarwin; + + __structuredAttrs = true; + + meta = { + description = "Language Server Protocol implementation for Swift and C-based languages"; + mainProgram = "sourcekit-lsp"; + homepage = "https://github.com/apple/sourcekit-lsp"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift/by-name/so/sourcekit-lsp/patches/0001-Fix-for-using-swift-corelibs-xctest-on-Darwin.patch b/pkgs/development/compilers/swift/by-name/so/sourcekit-lsp/patches/0001-Fix-for-using-swift-corelibs-xctest-on-Darwin.patch new file mode 100644 index 000000000000..c137baa63833 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/so/sourcekit-lsp/patches/0001-Fix-for-using-swift-corelibs-xctest-on-Darwin.patch @@ -0,0 +1,27 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 11 Jul 2026 15:55:24 -0400 +Subject: [PATCH 1/2] Fix for using swift-corelibs-xctest on Darwin + +Darwin in Nixpkgs also uses swift-corelibs-xctest, so we need to use the +logic as other platforms to define the base class for performance tests. +--- + Sources/SKTestSupport/PerfTestCase.swift | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/Sources/SKTestSupport/PerfTestCase.swift b/Sources/SKTestSupport/PerfTestCase.swift +index ba716c49..5b5cfccc 100644 +--- a/Sources/SKTestSupport/PerfTestCase.swift ++++ b/Sources/SKTestSupport/PerfTestCase.swift +@@ -23,7 +23,7 @@ open class PerfTestCase: XCTestCase { + + #if !ENABLE_PERF_TESTS + +- #if os(macOS) ++ #if false + open override func startMeasuring() {} + open override func stopMeasuring() {} + open override func measureMetrics( +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/so/sourcekit-lsp/patches/0002-Load-IndexStore-from-the-store.patch b/pkgs/development/compilers/swift/by-name/so/sourcekit-lsp/patches/0002-Load-IndexStore-from-the-store.patch new file mode 100644 index 000000000000..657f3e2b5d18 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/so/sourcekit-lsp/patches/0002-Load-IndexStore-from-the-store.patch @@ -0,0 +1,48 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 11 Jul 2026 16:07:13 -0400 +Subject: [PATCH 2/2] Load IndexStore from the store + +--- + Sources/ToolchainRegistry/Toolchain.swift | 7 ++----- + Tests/ToolchainRegistryTests/ToolchainRegistryTests.swift | 7 +------ + 2 files changed, 3 insertions(+), 11 deletions(-) + +diff --git a/Sources/ToolchainRegistry/Toolchain.swift b/Sources/ToolchainRegistry/Toolchain.swift +index 41d697bd..008a77af 100644 +--- a/Sources/ToolchainRegistry/Toolchain.swift ++++ b/Sources/ToolchainRegistry/Toolchain.swift +@@ -330,11 +330,8 @@ public final class Toolchain: Sendable { + foundAny = true + } + +- #if os(Windows) +- let libIndexStorePath = binPath.appendingPathComponent("libIndexStore\(dylibExtension)") +- #else +- let libIndexStorePath = libPath.appendingPathComponent("libIndexStore\(dylibExtension)") +- #endif ++ let libIndexStorePath = URL(filePath: "@libclang@").appending(components: "lib", "libIndexStore\(dylibExtension)") ++ + if FileManager.default.isFile(at: libIndexStorePath) { + libIndexStore = libIndexStorePath + foundAny = true +diff --git a/Tests/ToolchainRegistryTests/ToolchainRegistryTests.swift b/Tests/ToolchainRegistryTests/ToolchainRegistryTests.swift +index 60c4bf10..c8582c7a 100644 +--- a/Tests/ToolchainRegistryTests/ToolchainRegistryTests.swift ++++ b/Tests/ToolchainRegistryTests/ToolchainRegistryTests.swift +@@ -758,11 +758,6 @@ private func makeToolchain( + #endif + } + if libIndexStore { +- #if os(Windows) +- // Windows has a prefix of `lib` on this particular library ... +- try Data().write(to: binPath.appendingPathComponent("libIndexStore\(dylibSuffix)")) +- #else +- try Data().write(to: libPath.appendingPathComponent("libIndexStore\(dylibSuffix)")) +- #endif ++ try Data().write(to: URL(filePath: "@libclang@").appending(components: "lib", "libIndexStore\(dylibSuffix)")) + } + } +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/st/stdlib/package.nix b/pkgs/development/compilers/swift/by-name/st/stdlib/package.nix new file mode 100644 index 000000000000..be9c1cf8fdd5 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/st/stdlib/package.nix @@ -0,0 +1,114 @@ +{ + lib, + llvmPackages_upstream, + stdenv, + swiftc, +}: + +let + swiftPlatform = stdenv.hostPlatform.swift.platform; + libraryExtension = stdenv.hostPlatform.extensions.library; + + toolLTO = lib.cmakeFeature "SWIFT_TOOLS_ENABLE_LTO" "thin"; +in +(swiftc.override { + stdlib = null; + swiftComponents = [ + "back-deployment" + "sdk-overlay" + "static-mirror-lib" + "swift-remote-mirror" + "swift-remote-mirror-headers" + "stdlib" + ]; +}).overrideAttrs + (old: { + pname = "stdlib"; + + outputs = [ + "out" + "dev" + ]; + + cmakeFlags = + # Only enable LTO for the stdlib. Remove it if it’s enabled for the tools. + (lib.filter (flag: flag != toolLTO) (old.cmakeFlags or [ ])) + # LTO is slow (and pointless due to using system libraries) on Darwin, so only enable it for other platforms. + ++ lib.optionals (!stdenv.hostPlatform.isDarwin) [ + (lib.cmakeFeature "SWIFT_STDLIB_ENABLE_LTO" "thin") + ]; + + postInstall = '' + moveToOutput "lib/swift/${swiftPlatform}" "''${!outputLib}" + + # Static libraries, Swift modules, and shims are only needed for development. + moveToOutput "lib/swift/${swiftPlatform}/*.swiftmodule" "''${!outputDev}" + moveToOutput "lib/swift/_InternalSwiftStaticMirror" "''${!outputDev}" + moveToOutput "lib/swift/embedded" "''${!outputDev}" + moveToOutput "lib/swift/module.modulemap" "''${!outputDev}" + moveToOutput "lib/swift/shims" "''${!outputDev}" + moveToOutput "lib/swift_static" "''${!outputDev}" + + # Move libraries out of `lib/swift/`, so ld-wrapper will find them automatically. + mv -v "''${!outputLib}/lib/swift/${swiftPlatform}"/*${libraryExtension} "''${!outputLib}/lib" + + # Install C++ interop libraries and headers + cp -v lib/swift/${swiftPlatform}/libswiftCxx*${stdenv.hostPlatform.extensions.staticLibrary} "''${!outputDev}/lib" + cp -rv lib/swift/${swiftPlatform}/Cxx*.swiftmodule "''${!outputDev}/lib/swift/${swiftPlatform}" + + mkdir -p "''${!outputDev}/include/swiftToCxx" + cp -v ../lib/PrintAsClang/{_SwiftCxxInteroperability.h,_SwiftStdlibCxxOverlay.h,experimental-interoperability-version.json} \ + "''${!outputDev}/include/swiftToCxx" + cp -v lib/swift/${swiftPlatform}/libcxx* "''${!outputDev}/lib/swift/${swiftPlatform}" + '' + # libstdc++ does not come with a modulemap. It needs one provided by Swift. + + lib.optionalString (stdenv.cc.libcxx == null) '' + moveToOutput "lib/swift/${swiftPlatform}/libstdcxx.*" "''${!outputDev}" + '' + # Linux has some extra development files that need moved to $dev + + lib.optionalString stdenv.hostPlatform.isLinux '' + moveToOutput lib/swift/${swiftPlatform}/${stdenv.hostPlatform.swift.arch} "''${!outputDev}" + '' + # Convert LLVM bitcode files into native code to avoid requiring LTO for C++ interop. + + lib.optionalString stdenv.hostPlatform.isElf '' + ${lib.escapeShellArg (lib.getExe' llvmPackages_upstream.llvm "llc")} stdlib/public/Cxx/${lib.toUpper stdenv.hostPlatform.swift.platform}/${stdenv.hostPlatform.swift.arch}/Cxx.o -o Cxx.o -filetype=obj + "$AR" Drs "''${!outputDev}/lib/libswiftCxx.a" Cxx.o + ${lib.escapeShellArg (lib.getExe' llvmPackages_upstream.llvm "llc")} stdlib/public/Cxx/std/${lib.toUpper stdenv.hostPlatform.swift.platform}/${stdenv.hostPlatform.swift.arch}/CxxStdlib.o -o CxxStdlib.o -filetype=obj + "$AR" Drs "''${!outputDev}/lib/libswiftCxxStdlib.a" CxxStdlib.o + '' + + lib.optionalString stdenv.hostPlatform.isDarwin '' + # Back-deployment libraries are installed as part of the compiler component, so install them manually. + cp -rv lib/swift/macosx/libswiftCompatibility*.a "''${!outputDev}/lib" + + # Install `Span`-compatibility back-deployment library. + mkdir -p "''${!outputLib}/lib/swift-6.2/macosx" + cp -v lib/swift-6.2/macosx/libswiftCompatibilitySpan.dylib "''${!outputLib}/lib/swift-6.2/macosx/libswiftCompatibilitySpan.dylib" + + # macOS 26.4 dropped the Swift Differentiation dylibs. Use the one in the store instead of `/usr/lib/swift`. + install_name_tool "''${!outputLib}/lib/libswift_Differentiation.dylib" -id "''${!outputLib}/lib/libswift_Differentiation.dylib" + + # Generate text-based stubs for the stdlib. Darwin links against the system library, so they aren’t necessary. + for dylib in "''${!outputLib}/lib/"*.dylib; do + dylibName=$(basename "$dylib" .dylib) + if [ "$dylibName" = "libswiftCompatibilitySpan" ]; then + # Follow the SDK, which symlinks `libswiftCompatibilitySpan.tbd` to `libswiftCore.tbd`. + ln -s libswiftCore.tbd "''${!outputDev}/lib/$dylibName.tbd" + else + ${lib.escapeShellArg (lib.getExe' llvmPackages_upstream.llvm "llvm-readtapi")} --filetype=tbd-v4 \ + "$dylib" -o "''${!outputDev}/lib/$dylibName.tbd" + fi + if [ "$dylibName" != "libswift_Differentiation" ]; then + rm "$dylib" + fi + done + + # The linker should be using the stubs in $dev, which will reference the dylibs in $lib. + # There’s no need to propagate it on Darwin. + rm -rf "''${!outputDev}/nix-support" + + # Clean up empty folders. + rmdir "''${!outputLib}/lib/swift/${swiftPlatform}" "''${!outputLib}/lib/swift" + ''; + + postFixup = null; + }) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-argument-parser/files/ArgumentParserConfig.cmake b/pkgs/development/compilers/swift/by-name/sw/swift-argument-parser/files/ArgumentParserConfig.cmake new file mode 100644 index 000000000000..d2fa30ba8493 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-argument-parser/files/ArgumentParserConfig.cmake @@ -0,0 +1,5 @@ +add_library(ArgumentParser @buildType@ IMPORTED) +set_target_properties(ArgumentParser PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}ArgumentParser${CMAKE_@buildType@_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@include@/lib/swift/@swiftPlatform@;@include@/lib/swift_static/@swiftPlatform@" +) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-argument-parser/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-argument-parser/package.nix new file mode 100644 index 000000000000..3e1313d8e2ce --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-argument-parser/package.nix @@ -0,0 +1,79 @@ +{ + lib, + cmake, + fetchFromGitHub, + gitUpdater, + llvm_libtool, + ninja, + stdenv, + swift-foundation, + swift-minimal, +}: + +let + swiftPlatform = stdenv.hostPlatform.swift.platform; + swift = swift-minimal.override { inherit swift-foundation; }; # Swift Argument Parser requires Foundation. +in + +# Swift Argument Parser is a dependency to both Swift Compiler Driver and SwiftPM. +# It must be built with CMake and use Swift without swift-driver to avoid dependency cycles. +stdenv.mkDerivation (finalAttrs: { + pname = "swift-argument-parser"; + version = "1.8.2"; + + outputs = [ + "out" + "dev" + ]; + + src = fetchFromGitHub { + owner = "apple"; + repo = "swift-argument-parser"; + tag = finalAttrs.version; + hash = "sha256-BWm2ZbNIvlamNp8cxoicFlAcujjhH22VPzs67lEIXWU="; + }; + + patches = [ + # Install libSwiftArgumentParserToolInfo.a and its module as well. + ./patches/0001-install-argument-parser-tool-info.patch + ]; + + strictDeps = true; + + preConfigure = '' + appendToVar cmakeFlags -DCMAKE_Swift_COMPILER_TARGET=${stdenv.hostPlatform.swift.triple} + appendToVar cmakeFlags -DCMAKE_Swift_FLAGS=-module-cache-path\ "$NIX_BUILD_TOP/module-cache" + ''; + + nativeBuildInputs = [ + cmake + ninja + swift + ] + ++ lib.optionals stdenv.hostPlatform.isDarwin [ llvm_libtool ]; + + postInstall = '' + moveToOutput lib/swift "''${!outputDev}" + moveToOutput lib/swift_static "''${!outputDev}" + + # Install CMake config file for the Swift Argument Parser library. + mkdir -p "''${!outputDev}/lib/cmake/ArgumentParser" + substitute ${./files/ArgumentParserConfig.cmake} "''${!outputDev}/lib/cmake/ArgumentParser/ArgumentParserConfig.cmake" \ + --replace-fail '@buildType@' ${if stdenv.hostPlatform.isStatic then "STATIC" else "SHARED"} \ + --replace-fail '@include@' "''${!outputDev}" \ + --replace-fail '@lib@' "''${!outputLib}" \ + --replace-fail '@swiftPlatform@' ${swiftPlatform} + ''; + + passthru.updateScript = gitUpdater { }; + + __structuredAttrs = true; + + meta = { + homepage = "https://github.com/apple/swift-argument-parser"; + description = "Type-safe argument parsing for Swift"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-argument-parser/patches/0001-install-argument-parser-tool-info.patch b/pkgs/development/compilers/swift/by-name/sw/swift-argument-parser/patches/0001-install-argument-parser-tool-info.patch new file mode 100644 index 000000000000..d5e3859a79e9 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-argument-parser/patches/0001-install-argument-parser-tool-info.patch @@ -0,0 +1,22 @@ +From afdddf3098f0cd0a7340609950df4f9471a12c61 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 28 Feb 2026 13:32:37 -0500 +Subject: [PATCH] install-argument-parser-tool-info + +--- + Sources/ArgumentParserToolInfo/CMakeLists.txt | 1 + + 1 file changed, 1 insertion(+) + +diff --git a/Sources/ArgumentParserToolInfo/CMakeLists.txt b/Sources/ArgumentParserToolInfo/CMakeLists.txt +index b82adb7..478f89d 100644 +--- a/Sources/ArgumentParserToolInfo/CMakeLists.txt ++++ b/Sources/ArgumentParserToolInfo/CMakeLists.txt +@@ -7,4 +7,5 @@ target_compile_options(ArgumentParserToolInfo PRIVATE + $<$:-enable-testing>) + + ++_install_target(ArgumentParserToolInfo) + set_property(GLOBAL APPEND PROPERTY ArgumentParser_EXPORTS ArgumentParserToolInfo) +-- +2.51.2 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-asn1/files/SwiftASN1Config.cmake b/pkgs/development/compilers/swift/by-name/sw/swift-asn1/files/SwiftASN1Config.cmake new file mode 100644 index 000000000000..ddcb6b154d6d --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-asn1/files/SwiftASN1Config.cmake @@ -0,0 +1,5 @@ +add_library(SwiftASN1 @buildType@ IMPORTED) +set_target_properties(SwiftASN1 PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}SwiftASN1${CMAKE_@buildType@_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@include@/lib/swift/@swiftPlatform@" +) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-asn1/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-asn1/package.nix new file mode 100644 index 000000000000..eddec9f79f3c --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-asn1/package.nix @@ -0,0 +1,72 @@ +{ + lib, + cmake, + fetchFromGitHub, + gitUpdater, + ninja, + stdenv, + swift, +}: + +# Swift-ASN1 is a dependency of SwiftPM. It must be built with CMake to avoid dependency cycles. +stdenv.mkDerivation (finalAttrs: { + pname = "swift-asn1"; + version = "1.7.1"; + + outputs = [ + "out" + "dev" + ]; + + src = fetchFromGitHub { + owner = "apple"; + repo = "swift-asn1"; + tag = finalAttrs.version; + hash = "sha256-hikWOlKKW0VplBuDgrt/Xyao3gsDS5IkxsMfbITHT2I="; + }; + + postPatch = '' + substituteInPlace cmake/modules/SwiftSupport.cmake \ + --replace-fail 'ARCHIVE DESTINATION lib/''${swift}/''${swift_os}' 'ARCHIVE DESTINATION ''${CMAKE_INSTALL_LIBDIR}' \ + --replace-fail 'LIBRARY DESTINATION lib/''${swift}/''${swift_os}' 'LIBRARY DESTINATION ''${CMAKE_INSTALL_LIBDIR}' \ + --replace-fail 'RUNTIME DESTINATION bin' 'RUNTIME DESTINATION ''${CMAKE_INSTALL_BINDIR}' + ''; + + strictDeps = true; + + preConfigure = '' + appendToVar cmakeFlags -DCMAKE_Swift_COMPILER_TARGET=${stdenv.hostPlatform.swift.triple} + appendToVar cmakeFlags -DCMAKE_Swift_FLAGS=-module-cache-path\ "$NIX_BUILD_TOP/module-cache" + ''; + + nativeBuildInputs = [ + cmake + ninja + swift + ]; + + postInstall = '' + moveToOutput lib/swift "''${!outputDev}" + moveToOutput lib/swift_static "''${!outputDev}" + + # Install CMake config file for the SwiftASN1 library. + mkdir -p "''${!outputDev}/lib/cmake/SwiftASN1" + substitute ${./files/SwiftASN1Config.cmake} "''${!outputDev}/lib/cmake/SwiftASN1/SwiftASN1Config.cmake" \ + --replace-fail '@buildType@' ${if stdenv.hostPlatform.isStatic then "STATIC" else "SHARED"} \ + --replace-fail '@include@' "''${!outputDev}" \ + --replace-fail '@lib@' "''${!outputLib}" \ + --replace-fail '@swiftPlatform@' ${stdenv.hostPlatform.swift.platform} + ''; + + passthru.updateScript = gitUpdater { }; + + __structuredAttrs = true; + + meta = { + homepage = "https://github.com/apple/swift-asn1"; + description = "An implementation of ASN.1 for Swift"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-build/extra-bins/copypng b/pkgs/development/compilers/swift/by-name/sw/swift-build/extra-bins/copypng new file mode 100755 index 000000000000..634c339ef173 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-build/extra-bins/copypng @@ -0,0 +1,64 @@ +#!/usr/bin/env bash + +set -eu -o pipefail + +compress=false +optimize="" + +declare -a files=() + +echo "All args: $@" + +for arg in "${@}"; do + echo "Got arg: $arg" + test -n "$arg" && continue # Sometimes xcbuild passes empty arguments + case "$arg" in + -strip-PNG-text) + echo "Removing text chunks" + optimize="--strip tEXt,iTXt,zTXt" + ;; + -skip-PNGs) + echo "Not actually compressing" + compress=false + ;; + -compress) + echo "Actually in fact compressing" + compress=true + ;; + -*) + echo "warning: unrecognized option $1." >&2 + ;; + *) + echo "Adding $1 to files" + files+=("$(realpath "$1")") + ;; + esac +done + +echo "Got: ${files[@]} with length ${#files[@]}" + +case "${#files[@]}" in + 0) + echo "error: missing source and destination files" >&2 + exit 1 + ;; + 1) + echo "error: missing destination files" >&2 + exit 1 + ;; + 2) + source=${files[0]} + dest=${files[1]} + ;; + *) + echo "warning: ignoring extra files passed to \`copypng\`" + source=${files[0]} + dest=${files[1]} + ;; +esac + +if $compress; then + oxipng $optimize "$source" --force --out "$dest" +else + @coreutils@/bin/cp "$source" "$dest" +fi diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-build/extra-bins/tiffutil b/pkgs/development/compilers/swift/by-name/sw/swift-build/extra-bins/tiffutil new file mode 100755 index 000000000000..b987913d59f1 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-build/extra-bins/tiffutil @@ -0,0 +1,77 @@ +#!/usr/bin/env bash + +set -eux -o pipefail + +compression="" +cmd=copy +outfile="" + +declare -a files=() + +while [ "$#" -gt 0 ]; do + test -z "$1" && continue # Sometimes xcbuild passes empty arguments + case "$1" in + -none) + compression="" + ;; + -lzw) + compression="-c lzw" + ;; + -packbits) + compression="-c packbits" + ;; + -cat) + cmd=cat + ;; + -catnosizecheck) + echo "warning: size checks are not implemented" >&2 + cmd=cat + ;; + -cathidpicheck) + echo "warning: DPI guidelines checks are not implemented" >&2 + cmd=cat + ;; + -extract) + shift + index=$1 + shift + file=$(realpath "$1") + files+=("$file,$index") + ;; + -info|-verboseinfo|-dump) + cmd=info + ;; + -out) + shift + outfile=$(realpath "$1") + ;; + *) + files+=("$(realpath "$1")") + ;; + esac + shift +done + +echo "Files: ${files[@]}" +case "${#files[@]},$cmd" in + 0,*) + echo "error: missing source and destination files" >&2 + exit 1 + ;; + 1,*) + echo "Got one file, yay" + ;; + *,copy|*,info) + echo "error: too many input files specified" + exit 1 + ;; +esac + +case $cmd in + cat|copy) + tiffcp $compression "${files[@]}" "$outfile" + ;; + info) + tiffinfo "${files[@]}" + ;; +esac diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-build/files/SwiftBuildConfig.cmake b/pkgs/development/compilers/swift/by-name/sw/swift-build/files/SwiftBuildConfig.cmake new file mode 100644 index 000000000000..e3eccaa4f08b --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-build/files/SwiftBuildConfig.cmake @@ -0,0 +1,11 @@ +add_library(SwiftBuild::SwiftBuild @buildType@ IMPORTED) +set_target_properties(SwiftBuild::SwiftBuild PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}SwiftBuild${CMAKE_@buildType@_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@include@/include;@include@/lib/swift/@swiftPlatform@" +) + +add_library(SwiftBuild::SWBBuildService @buildType@ IMPORTED) +set_target_properties(SwiftBuild::SWBBuildService PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}SWBBuildService${CMAKE_@buildType@_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@include@/include;@include@/lib/swift/@swiftPlatform@" +) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-build/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-build/package.nix new file mode 100644 index 000000000000..e13b8b65de2f --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-build/package.nix @@ -0,0 +1,166 @@ +{ + lib, + cmake, + coreutils, + darwin, + diffutils, + fetchFromGitHub, + gnused, + libiconv, + libtiff, + llvmPackages_upstream, + llvm_libtool, + ninja, + oxipng, + replaceVars, + sqlite, + stdenv, + stdenvNoCC, + swift, + swift-argument-parser, + swift-driver, + swift-llbuild, + swift-system, + swift-tools-support-core, + xcbuild, + swift_release, + swift_sources, +}: + +let + graphics_cmds = stdenvNoCC.mkDerivation { + pname = "graphics_cmds"; + version = "1"; + + # Note: These depend on oxipng and tools from libtiff, but we don’t want to pull them into the Swift Build + # closure unnecessarily. Packages using those commands will have to add them themselves. + buildCommand = '' + install -m755 -D ${replaceVars ./extra-bins/copypng { inherit coreutils; }} "$out/bin/copypng" + install -m755 -D ${replaceVars ./extra-bins/tiffutil { }} "$out/bin/tiffutil" + ''; + }; + + swiftPlatform = stdenv.hostPlatform.swift.platform; +in + +# Swift Build is a dependency of SwiftPM. It must be built with CMake to avoid dependency cycles. +stdenv.mkDerivation (finalAttrs: { + pname = "swift-build"; + version = swift_release; + + outputs = [ + "out" + "dev" + "lib" + ]; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-build"; + tag = "swift-${finalAttrs.version}-RELEASE"; + inherit (swift_sources.swift-build) hash; + }; + + patches = [ + # Remove as many impure paths as possible. + (replaceVars ./patches/0001-replace-impure-paths.patch { + xcrun = if stdenv.hostPlatform.isDarwin then xcbuild.xcrun else "/not-supported"; + inherit graphics_cmds; + coreutils = lib.getBin coreutils; + diffutils = lib.getBin diffutils; + gnused = lib.getBin gnused; + libiconv = lib.getBin libiconv; + libtool = lib.getBin llvm_libtool; + llvm = lib.getBin llvmPackages_upstream.llvm; + shell_cmds = + if stdenv.hostPlatform.isDarwin then lib.getBin darwin.shell_cmds else "/not-supported"; + sigtool = lib.getBin darwin.sigtool; + }) + # Swift Build checks whether the SDK is Xcode by looking at the `DEVELOPER_DIR` path for Xcode. + # Have it treat store paths as being Xcode SDKs so that the nixpkgs SDK is treated as a Darwin platform. + (replaceVars ./patches/0002-treat-nixpkgs-sdk-as-xcode.patch { + store-dir = builtins.storeDir; + }) + # Don’t look in the build directory for bundles. Look only in the store. + ./patches/0003-find-bundles-in-store.patch + ]; + + # FIXME: Make this a patch + postPatch = '' + # Allow Swift Build to find `SWBBuildServiceBundle` in `$out/libexec`. + substituteInPlace Sources/SwiftBuild/SWBBuildServiceConnection.swift \ + --replace-fail 'Bundle(for: SWBBuildServiceConnection.self).bundleURL.deletingLastPathComponent()' 'URL(filePath: "@lib@/libexec")' \ + --replace-fail 'Bundle.main.executableURL?.deletingLastPathComponent()' '.some(URL(filePath: "@lib@/libexec"))?' \ + --replace-fail '@lib@' "''${!outputLib}" + + # Use the path to `swift` to find the plugin server binary + substituteInPlace Sources/SWBCore/Settings/Settings.swift \ + --replace-fail '\(toolchain.path.str)/usr/bin/swift-plugin-server' ${lib.getExe' swift.swiftc "swift-plugin-server"} + ''; + + strictDeps = true; + + cmakeFlags = [ + # The CMake hook doesn’t set `${CMAKE_INSTALL_DATADIR}` to a store path, so it needs to be specified manually. + (lib.cmakeFeature "CMAKE_INSTALL_DATADIR" "${placeholder "lib"}/share") + ]; + + preConfigure = '' + appendToVar cmakeFlags -DCMAKE_Swift_COMPILER_TARGET=${stdenv.hostPlatform.swift.triple} + appendToVar cmakeFlags -DCMAKE_Swift_FLAGS=-module-cache-path\ "$NIX_BUILD_TOP/module-cache" + ''; + + nativeBuildInputs = [ + cmake + ninja + swift + ]; + + buildInputs = [ + sqlite + swift-argument-parser + swift-driver + swift-llbuild + swift-system + swift-tools-support-core + ]; + + # Needed for `fixDarwinDylibNames` to work. + env.NIX_LDFLAGS = lib.optionalString stdenv.hostPlatform.isDarwin "-headerpad_max_install_names"; + + postInstall = '' + mkdir -p "''${!outputLib}/libexec" + mv "''${!outputBin}/bin/SWBBuildServiceBundle" "''${!outputLib}/libexec/SWBBuildServiceBundle" + + # Install the swiftmodules. + mkdir -p "''${!outputDev}/lib/swift/${swiftPlatform}" + cp -v swift/*.swiftmodule "''${!outputDev}/lib/swift/${swiftPlatform}" + + # Install the C module + mkdir -p "''${!outputDev}/include" + cp -v "$NIX_BUILD_TOP/$sourceRoot/Sources/SWBCLibc/include"/*.h "''${!outputDev}/include" + cp -v "$NIX_BUILD_TOP/$sourceRoot/Sources/SWBCSupport"/*.h "''${!outputDev}/include" + cat \ + "$NIX_BUILD_TOP/$sourceRoot/Sources/SWBCLibc/include/module.modulemap" \ + "$NIX_BUILD_TOP/$sourceRoot/Sources/SWBCSupport/module.modulemap" \ + > "''${!outputDev}/include/module.modulemap" + + # Install CMake config file for the Swift Build library. + mkdir -p "''${!outputDev}/lib/cmake/SwiftBuild" + substitute ${./files/SwiftBuildConfig.cmake} "''${!outputDev}/lib/cmake/SwiftBuild/SwiftBuildConfig.cmake" \ + --replace-fail '@buildType@' ${if stdenv.hostPlatform.isStatic then "STATIC" else "SHARED"} \ + --replace-fail '@include@' "''${!outputDev}" \ + --replace-fail '@lib@' "''${!outputLib}" \ + --replace-fail '@swiftPlatform@' ${swiftPlatform} + ''; + + __structuredAttrs = true; + + meta = { + homepage = "https://github.com/swiftlang/swift-build"; + description = "High-level build system based on llbuild"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-build/patches/0001-replace-impure-paths.patch b/pkgs/development/compilers/swift/by-name/sw/swift-build/patches/0001-replace-impure-paths.patch new file mode 100644 index 000000000000..8a22a52cebe8 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-build/patches/0001-replace-impure-paths.patch @@ -0,0 +1,1090 @@ +From 10f011cf8753c2175456a850b51c9968b2908081 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Tue, 9 Dec 2025 20:57:45 -0500 +Subject: [PATCH] replace-impure-paths + +--- + Plugins/run-xcodebuild/run-xcodebuild.swift | 2 +- + Sources/SWBAndroidPlatform/Plugin.swift | 2 +- + Sources/SWBBuildService/Messages.swift | 2 +- + .../CommandLineToolSpec.swift | 2 +- + .../SpecImplementations/Tools/CodeSign.swift | 2 +- + .../SpecImplementations/Tools/TouchTool.swift | 2 +- + Sources/SWBCore/Specs/CoreBuildSystem.xcspec | 2 +- + .../SWBCore/Specs/NativeBuildSystem.xcspec | 10 ++-- + Sources/SWBGenericUnixPlatform/Plugin.swift | 4 +- + .../SWBTaskExecution/BuildDescription.swift | 4 +- + .../TaskActions/CopyTiffTaskAction.swift | 2 +- + .../EmbedSwiftStdLibTaskAction.swift | 2 +- + Sources/SWBTestSupport/CoreBasedTests.swift | 6 +-- + Sources/SWBTestSupport/FSUtilities.swift | 4 +- + .../SWBTestSupport/LibraryGeneration.swift | 4 +- + Sources/SWBTestSupport/Xcode.swift | 2 +- + .../Specs/CodeSign.xcspec | 2 +- + Sources/SWBUtil/Signatures.swift | 2 +- + .../CoreQualificationTester.swift | 2 +- + Tests/SWBCoreTests/CommandLineSpecTests.swift | 2 +- + .../CodeSignTaskConstructionTests.swift | 48 +++++++++---------- + .../MergeableLibraryTests.swift | 10 ++-- + .../PlatformTaskConstructionTests.swift | 8 ++-- + .../PostprocessingTaskConstructionTests.swift | 4 +- + .../SwiftTaskConstructionTests.swift | 6 +-- + .../TaskConstructionTests.swift | 26 +++++----- + .../UnitTestTaskConstructionTests.swift | 12 ++--- + .../WatchTaskConstructionTests.swift | 12 ++--- + .../SignatureCollectionActionTests.swift | 4 +- + Tests/SWBUtilTests/MiscTests.swift | 2 +- + Tests/SWBUtilTests/SignaturesTests.swift | 4 +- + .../SwiftBuildTests/BuildOperationTests.swift | 16 +++---- + 32 files changed, 106 insertions(+), 106 deletions(-) + +diff --git a/Plugins/run-xcodebuild/run-xcodebuild.swift b/Plugins/run-xcodebuild/run-xcodebuild.swift +index 710a84a..c83982d 100644 +--- a/Plugins/run-xcodebuild/run-xcodebuild.swift ++++ b/Plugins/run-xcodebuild/run-xcodebuild.swift +@@ -39,7 +39,7 @@ struct RunXcodebuild: CommandPlugin { + } + + let process = Process() +- process.executableURL = URL(fileURLWithPath: "/usr/bin/xcrun") ++ process.executableURL = URL(fileURLWithPath: "@xcrun@/bin/xcrun") + process.arguments = ["xcodebuild"] + args.remainingArguments + process.environment = ProcessInfo.processInfo.environment.merging(["XCBBUILDSERVICE_PATH": buildServiceURL.path()]) { _, new in new } + try await process.run() +diff --git a/Sources/SWBAndroidPlatform/Plugin.swift b/Sources/SWBAndroidPlatform/Plugin.swift +index 117e7c6..6014cad 100644 +--- a/Sources/SWBAndroidPlatform/Plugin.swift ++++ b/Sources/SWBAndroidPlatform/Plugin.swift +@@ -118,7 +118,7 @@ struct AndroidPlatformExtension: PlatformInfoExtension { + "GENERATE_TEXT_BASED_STUBS": "NO", + "GENERATE_INTERMEDIATE_TEXT_BASED_STUBS": "NO", + +- "CHOWN": "/usr/bin/chown", ++ "CHOWN": "@coreutils@/bin/chown", + + "LIBTOOL": .plString(host.imageFormat.executableName(basename: "llvm-lib")), + "AR": .plString(host.imageFormat.executableName(basename: "llvm-ar")), +diff --git a/Sources/SWBBuildService/Messages.swift b/Sources/SWBBuildService/Messages.swift +index 070b5d3..47c7c3b 100644 +--- a/Sources/SWBBuildService/Messages.swift ++++ b/Sources/SWBBuildService/Messages.swift +@@ -192,7 +192,7 @@ extension SetSessionWorkspaceContainerPathRequest: PIFProvidingRequest { + try fs.createDirectory(dir, recursive: true) + let pifPath = dir.join(Foundation.UUID().description + ".json") + let argument = isProject ? "-project" : "-workspace" +- let result = try await Process.getOutput(url: URL(fileURLWithPath: "/usr/bin/xcrun"), arguments: ["xcodebuild", "-dumpPIF", pifPath.str, argument, path.str], currentDirectoryURL: URL(fileURLWithPath: containerPath.dirname.str, isDirectory: true), environment: Environment.current.addingContents(of: [.developerDir: session.core.developerPath.path.str])) ++ let result = try await Process.getOutput(url: URL(fileURLWithPath: "@xcrun@/bin/xcrun"), arguments: ["xcodebuild", "-dumpPIF", pifPath.str, argument, path.str], currentDirectoryURL: URL(fileURLWithPath: containerPath.dirname.str, isDirectory: true), environment: Environment.current.addingContents(of: [.developerDir: session.core.developerPath.path.str])) + if !result.exitStatus.isSuccess { + throw StubError.error("Could not dump PIF for '\(path.str)': \(String(decoding: result.stderr, as: UTF8.self))") + } +diff --git a/Sources/SWBCore/SpecImplementations/CommandLineToolSpec.swift b/Sources/SWBCore/SpecImplementations/CommandLineToolSpec.swift +index 116a390..66d030f 100644 +--- a/Sources/SWBCore/SpecImplementations/CommandLineToolSpec.swift ++++ b/Sources/SWBCore/SpecImplementations/CommandLineToolSpec.swift +@@ -246,7 +246,7 @@ extension DiscoveredCommandLineToolSpecInfo { + if !toolPath.isAbsolute { + throw StubError.error("\(toolPath.str) is not absolute") + } +- return try await producer.discoveredCommandLineToolSpecInfo(delegate, toolPath.basename, ["/usr/bin/what", "-q", toolPath.str]) { executionResult in ++ return try await producer.discoveredCommandLineToolSpecInfo(delegate, toolPath.basename, ["@shell_cmds@/bin/what", "-q", toolPath.str]) { executionResult in + let outputString = String(decoding: executionResult.stdout, as: UTF8.self).trimmingCharacters(in: .whitespacesAndNewlines) + let lines = Set(outputString.split(separator: "\n").map(String.init)) // version info is printed once per architecture slice, but we never expect them to differ + return try construct(AppleGenericVersionInfo(string: lines.only ?? outputString)) +diff --git a/Sources/SWBCore/SpecImplementations/Tools/CodeSign.swift b/Sources/SWBCore/SpecImplementations/Tools/CodeSign.swift +index d8d7ead..ea8fb21 100644 +--- a/Sources/SWBCore/SpecImplementations/Tools/CodeSign.swift ++++ b/Sources/SWBCore/SpecImplementations/Tools/CodeSign.swift +@@ -20,7 +20,7 @@ public final class CodesignToolSpec : CommandLineToolSpec, SpecIdentifierType, @ + public override func computeExecutablePath(_ cbc: CommandBuildContext) -> String { + var codesign = Path(cbc.scope.evaluate(BuiltinMacros.CODESIGN)) + if codesign.isEmpty { +- codesign = Path("/usr/bin/codesign") ++ codesign = Path("@sigtool@/bin/codesign") + } + if !codesign.isAbsolute { + codesign = resolveExecutablePath(cbc, codesign) +diff --git a/Sources/SWBCore/SpecImplementations/Tools/TouchTool.swift b/Sources/SWBCore/SpecImplementations/Tools/TouchTool.swift +index e6997b7..9644d09 100644 +--- a/Sources/SWBCore/SpecImplementations/Tools/TouchTool.swift ++++ b/Sources/SWBCore/SpecImplementations/Tools/TouchTool.swift +@@ -45,7 +45,7 @@ final class TouchToolSpec : CommandLineToolSpec, SpecIdentifierType, @unchecked + // FIXME: Need to properly quote the path here, or generally handle this better + commandLine = [commandShellPath, "/c", "copy /b \"\(input.absolutePath.str)\" +,,"] + } else { +- commandLine = ["/usr/bin/touch", "-c", input.absolutePath.str] ++ commandLine = ["@coreutils@/bin/touch", "-c", input.absolutePath.str] + } + + delegate.createTask(type: self, ruleInfo: ["Touch", input.absolutePath.str], commandLine: commandLine, environment: EnvironmentBindings(), workingDirectory: cbc.producer.defaultWorkingDirectory, inputs: [delegate.createNode(input.absolutePath)], outputs: outputs, mustPrecede: [], action: delegate.taskActionCreationDelegate.createDeferredExecutionTaskActionIfRequested(userPreferences: cbc.producer.userPreferences), execDescription: resolveExecutionDescription(cbc, delegate, lookup: outputFileOverride), enableSandboxing: enableSandboxing) +diff --git a/Sources/SWBCore/Specs/CoreBuildSystem.xcspec b/Sources/SWBCore/Specs/CoreBuildSystem.xcspec +index 467e061..cee7bd1 100644 +--- a/Sources/SWBCore/Specs/CoreBuildSystem.xcspec ++++ b/Sources/SWBCore/Specs/CoreBuildSystem.xcspec +@@ -3176,7 +3176,7 @@ For more information on mergeable libraries, see [Configuring your project to us + { + Name = "JAVA_COMPILER"; + Type = Path; +- DefaultValue = "/usr/bin/javac"; ++ DefaultValue = "javac"; + }, + { + Name = "JAVA_ARCHIVE_CLASSES"; +diff --git a/Sources/SWBCore/Specs/NativeBuildSystem.xcspec b/Sources/SWBCore/Specs/NativeBuildSystem.xcspec +index b4fcfa8..79f4b99 100644 +--- a/Sources/SWBCore/Specs/NativeBuildSystem.xcspec ++++ b/Sources/SWBCore/Specs/NativeBuildSystem.xcspec +@@ -823,23 +823,23 @@ When `GENERATE_INFOPLIST_FILE` is enabled, sets the value of the [CFBundleExecut + }, + { Name = ICONV; + Type = Path; +- DefaultValue = "/usr/bin/iconv"; ++ DefaultValue = "@libiconv@/bin/iconv"; + }, + { Name = SED; + Type = Path; +- DefaultValue = "/usr/bin/sed"; ++ DefaultValue = "@gnused@/bin/sed"; + }, + { Name = CHOWN; + Type = Path; +- DefaultValue = "/usr/sbin/chown"; ++ DefaultValue = "@coreutils@/bin/chown"; + }, + { Name = CHMOD; + Type = Path; +- DefaultValue = "/bin/chmod"; ++ DefaultValue = "@coreutils@/bin/chmod"; + }, + { Name = DIFF; + Type = Path; +- DefaultValue = "/usr/bin/diff"; ++ DefaultValue = "@diffutils@/bin/diff"; + }, + + // Utility settings +diff --git a/Sources/SWBGenericUnixPlatform/Plugin.swift b/Sources/SWBGenericUnixPlatform/Plugin.swift +index 632a4ca..5b18fc4 100644 +--- a/Sources/SWBGenericUnixPlatform/Plugin.swift ++++ b/Sources/SWBGenericUnixPlatform/Plugin.swift +@@ -120,8 +120,8 @@ struct GenericUnixSDKRegistryExtension: SDKRegistryExtension { + "GENERATE_TEXT_BASED_STUBS": "NO", + "GENERATE_INTERMEDIATE_TEXT_BASED_STUBS": "NO", + +- "CHOWN": "/usr/bin/chown", +- "AR": "llvm-ar", ++ "CHOWN": "@coreutils@/bin/chown", ++ "AR": "@llvm@/bin/llvm-ar", + ] + default: + defaultProperties = [:] +diff --git a/Sources/SWBTaskExecution/BuildDescription.swift b/Sources/SWBTaskExecution/BuildDescription.swift +index 53aae73..15fc1ea 100644 +--- a/Sources/SWBTaskExecution/BuildDescription.swift ++++ b/Sources/SWBTaskExecution/BuildDescription.swift +@@ -896,7 +896,7 @@ package final class BuildDescriptionBuilder { + + var commandLine = commandLine + if bypassActualTasks { +- commandLine = [ByteString(encodingAsUTF8: "/usr/bin/true")] + commandLine ++ commandLine = [ByteString(encodingAsUTF8: "@coreutils@/bin/true")] + commandLine + } + + // Add the command definition. +@@ -976,7 +976,7 @@ package final class BuildDescriptionBuilder { + func addCustomCommand(_ task: any PlannedTask, tool: String, inputs: [any PlannedNode], outputs: [any PlannedNode], deps: DependencyDataStyle? = nil, allowMissingInputs: Bool, alwaysOutOfDate: Bool, description: [String]) throws { + // Honor `bypassActualTasks`. + if bypassActualTasks { +- try addSubprocessCommand(task, inputs: inputs, outputs: outputs, description: description, commandLine: ["/usr/bin/true"], allowMissingInputs: allowMissingInputs, alwaysOutOfDate: alwaysOutOfDate, isUnsafeToInterrupt: false) ++ try addSubprocessCommand(task, inputs: inputs, outputs: outputs, description: description, commandLine: ["@coreutils@/bin/true"], allowMissingInputs: allowMissingInputs, alwaysOutOfDate: alwaysOutOfDate, isUnsafeToInterrupt: false) + return + } + +diff --git a/Sources/SWBTaskExecution/TaskActions/CopyTiffTaskAction.swift b/Sources/SWBTaskExecution/TaskActions/CopyTiffTaskAction.swift +index df1675a..9e4b37c 100644 +--- a/Sources/SWBTaskExecution/TaskActions/CopyTiffTaskAction.swift ++++ b/Sources/SWBTaskExecution/TaskActions/CopyTiffTaskAction.swift +@@ -141,7 +141,7 @@ public final class CopyTiffTaskAction: TaskAction { + + // If we have a compression argument, pass through tiffutil. + if let compression = options.compression { +- let tiffutilCommand = ["/usr/bin/tiffutil", "-\(compression)", input.str, "-out", output.str] ++ let tiffutilCommand = ["@graphics_cmds@/bin/tiffutil", "-\(compression)", input.str, "-out", output.str] + + let processDelegate = TaskProcessDelegate(outputDelegate: outputDelegate) + do { +diff --git a/Sources/SWBTaskExecution/TaskActions/EmbedSwiftStdLibTaskAction.swift b/Sources/SWBTaskExecution/TaskActions/EmbedSwiftStdLibTaskAction.swift +index 40509fc..e2a3ae6 100644 +--- a/Sources/SWBTaskExecution/TaskActions/EmbedSwiftStdLibTaskAction.swift ++++ b/Sources/SWBTaskExecution/TaskActions/EmbedSwiftStdLibTaskAction.swift +@@ -847,7 +847,7 @@ public final class EmbedSwiftStdLibTaskAction: TaskAction { + // Codesign the Swift libraries in $build_dir/$frameworks + // but not the libraries in $build_dir/$unsigned_frameworks. + if codeSignIdentity != nil && !swiftLibs.isEmpty { +- let codesign = Path(self.effectiveEnvironment["CODESIGN"] ?? "/usr/bin/codesign") ++ let codesign = Path(self.effectiveEnvironment["CODESIGN"] ?? "@sigtool@/bin/codesign") + + // Swift libraries that are up-to-date get codesigned anyway + // (in case options changed or a previous build was incomplete). +diff --git a/Sources/SWBTestSupport/CoreBasedTests.swift b/Sources/SWBTestSupport/CoreBasedTests.swift +index ff76cf5..4d3ea5c 100644 +--- a/Sources/SWBTestSupport/CoreBasedTests.swift ++++ b/Sources/SWBTestSupport/CoreBasedTests.swift +@@ -227,9 +227,9 @@ extension CoreBasedTests { + package var libtoolPath: Path { + get async throws { + let (core, defaultToolchain) = try await coreAndToolchain() +- let fallbacklibtool = Path("/usr/bin/libtool") ++ let fallbacklibtool = Path("@libtool@/bin/libtool") + return try #require(defaultToolchain.executableSearchPaths.findExecutable(operatingSystem: core.hostOperatingSystem, basename: "libtool") +- ?? defaultToolchain.executableSearchPaths.findExecutable(operatingSystem: core.hostOperatingSystem, basename: "llvm-ar") ++ ?? defaultToolchain.executableSearchPaths.findExecutable(operatingSystem: core.hostOperatingSystem, basename: "@llvm@/bin/llvm-ar") + ?? (localFS.exists(fallbacklibtool) ? fallbacklibtool : nil), "couldn't find libtool in default toolchain") + } + } +@@ -238,7 +238,7 @@ extension CoreBasedTests { + package var llvmlibPath: Path { + get async throws { + let (core, defaultToolchain) = try await coreAndToolchain() +- let fallbacklibtool = Path("/usr/bin/llvm-lib") ++ let fallbacklibtool = Path("@llvm@/bin/llvm-lib") + return try #require(defaultToolchain.executableSearchPaths.findExecutable(operatingSystem: core.hostOperatingSystem, basename: "llvm-lib") ?? (localFS.exists(fallbacklibtool) ? fallbacklibtool : nil), "couldn't find llvm-lib in default toolchain") + } + } +diff --git a/Sources/SWBTestSupport/FSUtilities.swift b/Sources/SWBTestSupport/FSUtilities.swift +index e95573a..972df55 100644 +--- a/Sources/SWBTestSupport/FSUtilities.swift ++++ b/Sources/SWBTestSupport/FSUtilities.swift +@@ -325,9 +325,9 @@ package extension FSProxy { + + if self === localFS { + if !shallow { +- _ = try await runProcess(["/usr/bin/codesign", "-s", "-", binary.join(path.basenameWithoutSuffix).str]) ++ _ = try await runProcess(["@sigtool@/bin/codesign", "-s", "-", binary.join(path.basenameWithoutSuffix).str]) + } +- _ = try await runProcess(["/usr/bin/codesign", "-s", "-", (shallow ? path : contents).str]) ++ _ = try await runProcess(["@sigtool@/bin/codesign", "-s", "-", (shallow ? path : contents).str]) + } else { + try await writeFileContents(contents.join("_CodeSignature/CodeSignature")) { $0 <<< "signature" } + } +diff --git a/Sources/SWBTestSupport/LibraryGeneration.swift b/Sources/SWBTestSupport/LibraryGeneration.swift +index 1a23807..3f750f3 100644 +--- a/Sources/SWBTestSupport/LibraryGeneration.swift ++++ b/Sources/SWBTestSupport/LibraryGeneration.swift +@@ -87,7 +87,7 @@ extension InstalledXcode { + let linkArgs = [["-sdk", platform.sdkName, "clang", "-dynamiclib", "-target", target], targetVariantArgs, linkerArgs, ["-L" + swiftRuntimeLibraryDirectoryPath(name: platform.sdkName), "-L/usr/lib/swift", "-o", machoPath.str, objectPath.str]].reduce([], +) + _ = try await xcrun(linkArgs, workingDirectory: workingDirectory) + if needSigned { +- _ = try await runProcessWithDeveloperDirectory(["/usr/bin/codesign", "-s", "-", machoPath.str]) ++ _ = try await runProcessWithDeveloperDirectory(["@sigtool@/bin/codesign", "-s", "-", machoPath.str]) + } + return machoPath + } +@@ -178,7 +178,7 @@ extension InstalledXcode { + } else { + _ = try await xcrun(["-sdk", platform.sdkName, "clang", "-dynamiclib", "-target", target] + targetVariantArgs + linkerArgs + ["-o", machoPath.str, objectPath.str]) + if needSigned { +- _ = try await runProcessWithDeveloperDirectory(["/usr/bin/codesign", "-s", "-", machoPath.str]) ++ _ = try await runProcessWithDeveloperDirectory(["@sigtool@/bin/codesign", "-s", "-", machoPath.str]) + } + machos.append(machoPath) + } +diff --git a/Sources/SWBTestSupport/Xcode.swift b/Sources/SWBTestSupport/Xcode.swift +index 969fc92..087816c 100644 +--- a/Sources/SWBTestSupport/Xcode.swift ++++ b/Sources/SWBTestSupport/Xcode.swift +@@ -32,7 +32,7 @@ package struct InstalledXcode: Sendable { + } + + package func xcrun(_ args: [String], workingDirectory: Path? = nil, redirectStderr: Bool = true) async throws -> String { +- return try await runProcessWithDeveloperDirectory(["/usr/bin/xcrun"] + args, workingDirectory: workingDirectory, overrideDeveloperDirectory: self.developerDirPath.str, redirectStderr: redirectStderr) ++ return try await runProcessWithDeveloperDirectory(["@xcrun@/bin/xcrun"] + args, workingDirectory: workingDirectory, overrideDeveloperDirectory: self.developerDirPath.str, redirectStderr: redirectStderr) + } + + package func productBuildVersion() throws -> ProductBuildVersion { +diff --git a/Sources/SWBUniversalPlatform/Specs/CodeSign.xcspec b/Sources/SWBUniversalPlatform/Specs/CodeSign.xcspec +index 02ec3dd..51629c9 100644 +--- a/Sources/SWBUniversalPlatform/Specs/CodeSign.xcspec ++++ b/Sources/SWBUniversalPlatform/Specs/CodeSign.xcspec +@@ -17,7 +17,7 @@ + Description = "Code-sign a framework, application, or other built target."; + ExecDescription = "Sign $(InputFileName)"; + ProgressDescription = "Signing product"; +- ExecPath = "/usr/bin/codesign"; ++ ExecPath = "@sigtool@/bin/codesign"; + // codesign is currently not safe to interrupt, tracked by 20712615. + IsUnsafeToInterrupt = YES; + CommandOutputParser = ( +diff --git a/Sources/SWBUtil/Signatures.swift b/Sources/SWBUtil/Signatures.swift +index eb3c1e2..180dcc6 100644 +--- a/Sources/SWBUtil/Signatures.swift ++++ b/Sources/SWBUtil/Signatures.swift +@@ -140,7 +140,7 @@ public struct CodeSignatureInfo: Codable, Sendable { + + static public func invokeCodesignVerification(for path: String, treatUnsignedAsError: Bool) async throws { + #if os(macOS) +- let executionResult = try await Process.getOutput(url: URL(filePath: "/usr/bin/codesign"), arguments: ["-vvvv", path]) ++ let executionResult = try await Process.getOutput(url: URL(filePath: "@sigtool@/bin/codesign"), arguments: ["-vvvv", path]) + let stdoutContent = String(data: executionResult.stdout, encoding: .utf8)?.trimmingCharacters(in: .whitespacesAndNewlines) ?? "" + let stderrContent = String(data: executionResult.stderr, encoding: .utf8)?.trimmingCharacters(in: .whitespacesAndNewlines) ?? "" + +diff --git a/Sources/SwiftBuildTestSupport/CoreQualificationTester.swift b/Sources/SwiftBuildTestSupport/CoreQualificationTester.swift +index 8495d9f..1e4dd60 100644 +--- a/Sources/SwiftBuildTestSupport/CoreQualificationTester.swift ++++ b/Sources/SwiftBuildTestSupport/CoreQualificationTester.swift +@@ -326,7 +326,7 @@ extension FileContentsCheckingResult { + let plist: PropertyListItem? + switch destination { + case .signed: +- let bytes = try await Array(xcode.xcrun(["/usr/bin/codesign", "-a", slice.arch, "-d", "--entitlements", ":-", binaryPath.str], redirectStderr: false).utf8) ++ let bytes = try await Array(xcode.xcrun(["@sigtool@/bin/codesign", "-a", slice.arch, "-d", "--entitlements", ":-", binaryPath.str], redirectStderr: false).utf8) + plist = try !bytes.isEmpty ? PropertyList.fromBytes(bytes) : nil + case .simulated: + // xcrun otool-classic [-arch arch] -X -s __TEXT __entitlements +diff --git a/Tests/SWBCoreTests/CommandLineSpecTests.swift b/Tests/SWBCoreTests/CommandLineSpecTests.swift +index 77813bc..03df67f 100644 +--- a/Tests/SWBCoreTests/CommandLineSpecTests.swift ++++ b/Tests/SWBCoreTests/CommandLineSpecTests.swift +@@ -1721,7 +1721,7 @@ import SWBMacro + let commandShellPath = try #require(getEnvironmentVariable("ComSpec"), "Can't determine path to cmd.exe because the ComSpec environment variable is not set") + task.checkCommandLine([commandShellPath, "/c", "copy /b \"\(Path.root.join("tmp/input").str)\" +,,"]) + } else { +- task.checkCommandLine(["/usr/bin/touch", "-c", Path.root.join("tmp/input").str]) ++ task.checkCommandLine(["@coreutils@/bin/touch", "-c", Path.root.join("tmp/input").str]) + } + #expect(task.execDescription == "Touch input") + } +diff --git a/Tests/SWBTaskConstructionTests/CodeSignTaskConstructionTests.swift b/Tests/SWBTaskConstructionTests/CodeSignTaskConstructionTests.swift +index 33972fe..838b3d0 100644 +--- a/Tests/SWBTaskConstructionTests/CodeSignTaskConstructionTests.swift ++++ b/Tests/SWBTaskConstructionTests/CodeSignTaskConstructionTests.swift +@@ -572,7 +572,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["ENABLE_LIBRARY_VALIDATION": "YES", "ENABLE_HARDENED_RUNTIME": "YES", "CODE_SIGN_RESTRICT": "YES"]), runDestination: .macOS) { results in + results.checkTarget("macOSFramework") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "-", "-o", "library,restrict,runtime", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "-", "-o", "library,restrict,runtime", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) + } + } + +@@ -583,7 +583,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["ENABLE_LIBRARY_VALIDATION": "NO", "ENABLE_HARDENED_RUNTIME": "NO", "CODE_SIGN_RESTRICT": "NO"]), runDestination: .macOS) { results in + results.checkTarget("macOSFramework") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) + } + } + +@@ -594,7 +594,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["ENABLE_LIBRARY_VALIDATION": "NO", "ENABLE_HARDENED_RUNTIME": "NO", "CODE_SIGN_RESTRICT": "YES", "OTHER_CODE_SIGN_FLAGS": "-o library,restrict"]), runDestination: .macOS) { results in + results.checkTarget("macOSFramework") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "-", "-o", "library,restrict", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "-", "-o", "library,restrict", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) + } + } + +@@ -605,7 +605,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["ENABLE_LIBRARY_VALIDATION": "NO", "ENABLE_HARDENED_RUNTIME": "NO", "CODE_SIGN_RESTRICT": "NO", "OTHER_CODE_SIGN_FLAGS": "-o library,restrict,runtime"]), runDestination: .macOS) { results in + results.checkTarget("macOSFramework") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "-", "-o", "library,restrict,runtime", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "-", "-o", "library,restrict,runtime", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) + } + } + +@@ -616,7 +616,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["ENABLE_LIBRARY_VALIDATION": "NO", "ENABLE_HARDENED_RUNTIME": "NO", "CODE_SIGN_RESTRICT": "NO", "OTHER_CODE_SIGN_FLAGS": "-o library,restrict,runtime", "DISABLE_FREEFORM_CODE_SIGN_OPTION_FLAGS": "YES"]), runDestination: .macOS) { results in + results.checkTarget("macOSFramework") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) + } + } + +@@ -630,7 +630,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["ENABLE_LIBRARY_VALIDATION": "YES", "ENABLE_HARDENED_RUNTIME": "YES", "CODE_SIGN_RESTRICT": "YES", "OTHER_CODE_SIGN_FLAGS": "--options kill,hard,host,expires,linker-signed"]), runDestination: .macOS) { results in // ignore-unacceptable-language; codesign tool option + results.checkTarget("macOSFramework") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "-", "--options", "expires,hard,host,kill,library,linker-signed,restrict,runtime", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) // ignore-unacceptable-language; codesign tool option ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--options", "expires,hard,host,kill,library,linker-signed,restrict,runtime", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) // ignore-unacceptable-language; codesign tool option + } + } + +@@ -641,7 +641,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["ENABLE_LIBRARY_VALIDATION": "NO", "ENABLE_HARDENED_RUNTIME": "NO", "CODE_SIGN_RESTRICT": "YES", "OTHER_CODE_SIGN_FLAGS": "--options kill,hard,host,expires,linker-signed"]), runDestination: .macOS) { results in // ignore-unacceptable-language; codesign tool option + results.checkTarget("macOSFramework") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "-", "--options", "expires,hard,host,kill,linker-signed,restrict", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) // ignore-unacceptable-language; codesign tool option ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--options", "expires,hard,host,kill,linker-signed,restrict", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) // ignore-unacceptable-language; codesign tool option + } + } + +@@ -892,7 +892,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["ENABLE_HARDENED_RUNTIME": "YES"]), runDestination: .macCatalyst, fs: fs) { results in + results.checkTarget("App") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "3ACDE4E702E4", "-o", "runtime", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "3ACDE4E702E4", "-o", "runtime", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) + } + results.checkNoDiagnostics() + } +@@ -900,7 +900,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["OTHER_CODE_SIGN_FLAGS": "-o library,restrict,runtime"]), runDestination: .macCatalyst, fs: fs) { results in + results.checkTarget("App") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "3ACDE4E702E4", "-o", "library,restrict,runtime", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "3ACDE4E702E4", "-o", "library,restrict,runtime", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) + } + results.checkNoDiagnostics() + } +@@ -908,7 +908,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["ENABLE_LIBRARY_VALIDATION": "YES", "ENABLE_HARDENED_RUNTIME": "YES", "CODE_SIGN_RESTRICT": "YES"]), runDestination: .iOS, fs: fs) { results in + results.checkTarget("App") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "-o", "library,restrict,runtime", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "-o", "library,restrict,runtime", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) + } + results.checkNoDiagnostics() + } +@@ -916,7 +916,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["ENABLE_HARDENED_RUNTIME": "YES"]), runDestination: .iOS, fs: fs) { results in + results.checkTarget("App") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "-o", "runtime", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "-o", "runtime", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) + } + results.checkNoDiagnostics() + } +@@ -924,7 +924,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["ENABLE_HARDENED_RUNTIME": "YES"]), runDestination: .macOS, fs: fs) { results in + results.checkTarget("macOSFramework") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "3ACDE4E702E4", "-o", "runtime", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "3ACDE4E702E4", "-o", "runtime", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) + } + results.checkNoDiagnostics() + } +@@ -932,7 +932,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["ENABLE_HARDENED_RUNTIME": "YES"]), runDestination: .watchOS, fs: fs) { results in + results.checkTarget("watchOSFramework") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "-o", "runtime", "--entitlements", .suffix("watchOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/watchOSFramework.framework"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "-o", "runtime", "--entitlements", .suffix("watchOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/watchOSFramework.framework"]) + } + results.checkNoDiagnostics() + } +@@ -942,7 +942,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["ENABLE_HARDENED_RUNTIME": "YES"]), runDestination: .iOSSimulator, fs: fs) { results in + results.checkTarget("App") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) + } + results.checkNoDiagnostics() + } +@@ -950,7 +950,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["ENABLE_LIBRARY_VALIDATION": "YES", "ENABLE_HARDENED_RUNTIME": "YES", "CODE_SIGN_RESTRICT": "YES"]), runDestination: .iOSSimulator, fs: fs) { results in + results.checkTarget("App") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "-o", "library,restrict", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "-o", "library,restrict", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) + } + results.checkNoDiagnostics() + } +@@ -958,7 +958,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["OTHER_CODE_SIGN_FLAGS": "-o runtime"]), runDestination: .iOSSimulator, fs: fs) { results in + results.checkTarget("App") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) + } + results.checkNoDiagnostics() + } +@@ -966,7 +966,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["OTHER_CODE_SIGN_FLAGS": "-o library,restrict,runtime"]), runDestination: .iOSSimulator, fs: fs) { results in + results.checkTarget("App") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "-o", "library,restrict", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "-o", "library,restrict", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) + } + results.checkNoDiagnostics() + } +@@ -974,7 +974,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["ENABLE_HARDENED_RUNTIME": "YES"]), runDestination: .watchOSSimulator, fs: fs) { results in + results.checkTarget("watchOSFramework") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", .suffix("watchOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/watchOSFramework.framework"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", .suffix("watchOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/watchOSFramework.framework"]) + } + results.checkNoDiagnostics() + } +@@ -1019,7 +1019,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["LAUNCH_CONSTRAINT_SELF": "/tmp/SelfLaunchConstraint.plist"]), runDestination: .macOS) { results in + results.checkTarget("Tool") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("Tool.xcent"), "--generate-entitlement-der", "--launch-constraint-self", .suffix("SelfLaunchConstraint.plist"), "/tmp/aProject.dst/usr/local/bin/Tool"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("Tool.xcent"), "--generate-entitlement-der", "--launch-constraint-self", .suffix("SelfLaunchConstraint.plist"), "/tmp/aProject.dst/usr/local/bin/Tool"]) + } + } + } +@@ -1028,7 +1028,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["LAUNCH_CONSTRAINT_PARENT": "/tmp/ParentLaunchConstraint.plist"]), runDestination: .macOS) { results in + results.checkTarget("Tool") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("Tool.xcent"), "--generate-entitlement-der", "--launch-constraint-parent", .suffix("ParentLaunchConstraint.plist"), "/tmp/aProject.dst/usr/local/bin/Tool"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("Tool.xcent"), "--generate-entitlement-der", "--launch-constraint-parent", .suffix("ParentLaunchConstraint.plist"), "/tmp/aProject.dst/usr/local/bin/Tool"]) + } + } + } +@@ -1038,7 +1038,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["LAUNCH_CONSTRAINT_RESPONSIBLE": "/tmp/ResponsibleLaunchConstraint.plist"]), runDestination: .macOS) { results in + results.checkTarget("Tool") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("Tool.xcent"), "--generate-entitlement-der", "--launch-constraint-responsible", .suffix("ResponsibleLaunchConstraint.plist"), "/tmp/aProject.dst/usr/local/bin/Tool"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("Tool.xcent"), "--generate-entitlement-der", "--launch-constraint-responsible", .suffix("ResponsibleLaunchConstraint.plist"), "/tmp/aProject.dst/usr/local/bin/Tool"]) + } + } + } +@@ -1047,7 +1047,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["LAUNCH_CONSTRAINT_SELF": "/tmp/SelfLaunchConstraint.plist", "LAUNCH_CONSTRAINT_PARENT": "/tmp/ParentLaunchConstraint.plist", "LAUNCH_CONSTRAINT_RESPONSIBLE": "/tmp/ResponsibleLaunchConstraint.plist"]), runDestination: .macOS) { results in + results.checkTarget("Tool") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("Tool.xcent"), "--generate-entitlement-der", "--launch-constraint-self", .suffix("SelfLaunchConstraint.plist"), "--launch-constraint-parent", .suffix("ParentLaunchConstraint.plist"), "--launch-constraint-responsible", .suffix("ResponsibleLaunchConstraint.plist"), "/tmp/aProject.dst/usr/local/bin/Tool"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("Tool.xcent"), "--generate-entitlement-der", "--launch-constraint-self", .suffix("SelfLaunchConstraint.plist"), "--launch-constraint-parent", .suffix("ParentLaunchConstraint.plist"), "--launch-constraint-responsible", .suffix("ResponsibleLaunchConstraint.plist"), "/tmp/aProject.dst/usr/local/bin/Tool"]) + } + } + } +@@ -1091,7 +1091,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["LIBRARY_LOAD_CONSTRAINT": "/tmp/LibraryLoadConstraint.plist"]), runDestination: .macOS, systemInfo: SystemInfo(operatingSystemVersion: Version(14), productBuildVersion: "99A98", nativeArchitecture: "arm64")) { results in + results.checkTarget("Tool") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("Tool.xcent"), "--generate-entitlement-der", "--library-constraint", .suffix("LibraryLoadConstraint.plist"), "/tmp/aProject.dst/usr/local/bin/Tool"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("Tool.xcent"), "--generate-entitlement-der", "--library-constraint", .suffix("LibraryLoadConstraint.plist"), "/tmp/aProject.dst/usr/local/bin/Tool"]) + } + } + } +@@ -1100,7 +1100,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["LIBRARY_LOAD_CONSTRAINT": "/tmp/LibraryLoadConstraint.plist"]), runDestination: .macOS, systemInfo: SystemInfo(operatingSystemVersion: Version(13), productBuildVersion: "99A98", nativeArchitecture: "arm64")) { results in + results.checkTarget("Tool") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("Tool.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/usr/local/bin/Tool"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("Tool.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/usr/local/bin/Tool"]) + } + } + } +diff --git a/Tests/SWBTaskConstructionTests/MergeableLibraryTests.swift b/Tests/SWBTaskConstructionTests/MergeableLibraryTests.swift +index 4584f5d..edc83b1 100644 +--- a/Tests/SWBTaskConstructionTests/MergeableLibraryTests.swift ++++ b/Tests/SWBTaskConstructionTests/MergeableLibraryTests.swift +@@ -289,7 +289,7 @@ fileprivate struct MergeableLibraryTests: CoreBasedTests { + let signedDir = String("\(FWK_FULL_PRODUCT_NAME)/\(FWK_CONTENTS_DIR_SUBPATH)".dropLast()) // Chop off the trailing '/' + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemPattern(.suffix(signedDir))) { task in + task.checkRuleInfo(["CodeSign", "\(BUILT_PRODUCTS_DIR)/\(FULL_PRODUCT_NAME)/\(FWK_CONTENTS_DIR_SUBPATH)\(reexportedBinariesDirectoryName)/\(signedDir)"]) +- task.checkCommandLineContains(["/usr/bin/codesign", "--preserve-metadata=identifier,entitlements,flags", "\(BUILT_PRODUCTS_DIR)/\(FULL_PRODUCT_NAME)/\(FWK_CONTENTS_DIR_SUBPATH)\(reexportedBinariesDirectoryName)/\(signedDir)"]) ++ task.checkCommandLineContains(["@sigtool@/bin/codesign", "--preserve-metadata=identifier,entitlements,flags", "\(BUILT_PRODUCTS_DIR)/\(FULL_PRODUCT_NAME)/\(FWK_CONTENTS_DIR_SUBPATH)\(reexportedBinariesDirectoryName)/\(signedDir)"]) + results.checkTaskFollows(task, [.matchTarget(target), .matchRuleType("Copy"), .matchRuleItemBasename(FWK_FULL_PRODUCT_NAME)]) + } + } +@@ -303,7 +303,7 @@ fileprivate struct MergeableLibraryTests: CoreBasedTests { + } + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename(DYLIB_FULL_PRODUCT_NAME)) { task in + task.checkRuleInfo(["CodeSign", "\(BUILT_PRODUCTS_DIR)/\(FULL_PRODUCT_NAME)/\(FWK_CONTENTS_DIR_SUBPATH)\(reexportedBinariesDirectoryName)/\(DYLIB_FULL_PRODUCT_NAME)"]) +- task.checkCommandLineContains(["/usr/bin/codesign", "--preserve-metadata=identifier,entitlements,flags", "\(BUILT_PRODUCTS_DIR)/\(FULL_PRODUCT_NAME)/\(FWK_CONTENTS_DIR_SUBPATH)\(reexportedBinariesDirectoryName)/\(DYLIB_FULL_PRODUCT_NAME)"]) ++ task.checkCommandLineContains(["@sigtool@/bin/codesign", "--preserve-metadata=identifier,entitlements,flags", "\(BUILT_PRODUCTS_DIR)/\(FULL_PRODUCT_NAME)/\(FWK_CONTENTS_DIR_SUBPATH)\(reexportedBinariesDirectoryName)/\(DYLIB_FULL_PRODUCT_NAME)"]) + results.checkTaskFollows(task, [.matchTarget(target), .matchRuleType("Copy"), .matchRuleItemBasename(DYLIB_FULL_PRODUCT_NAME)]) + } + } +@@ -732,7 +732,7 @@ fileprivate struct MergeableLibraryTests: CoreBasedTests { + let signedDir = String("\(FWK_FULL_PRODUCT_NAME)/\(FWK_CONTENTS_DIR_SUBPATH)".dropLast()) // Chop off the trailing '/' + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemPattern(.suffix(signedDir))) { task in + task.checkRuleInfo(["CodeSign", "\(BUILT_PRODUCTS_DIR)/\(FULL_PRODUCT_NAME)/\(FWK_CONTENTS_DIR_SUBPATH)\(reexportedBinariesDirectoryName)/\(signedDir)"]) +- task.checkCommandLineContains(["/usr/bin/codesign", "--preserve-metadata=identifier,entitlements,flags", "\(BUILT_PRODUCTS_DIR)/\(FULL_PRODUCT_NAME)/\(FWK_CONTENTS_DIR_SUBPATH)\(reexportedBinariesDirectoryName)/\(signedDir)"]) ++ task.checkCommandLineContains(["@sigtool@/bin/codesign", "--preserve-metadata=identifier,entitlements,flags", "\(BUILT_PRODUCTS_DIR)/\(FULL_PRODUCT_NAME)/\(FWK_CONTENTS_DIR_SUBPATH)\(reexportedBinariesDirectoryName)/\(signedDir)"]) + results.checkTaskFollows(task, [.matchTarget(target), .matchRuleType("Copy"), .matchRuleItemBasename(FWK_FULL_PRODUCT_NAME)]) + } + } +@@ -1113,7 +1113,7 @@ fileprivate struct MergeableLibraryTests: CoreBasedTests { + } + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("FwkTarget.framework")) { task in + task.checkRuleInfo(["CodeSign", "\(SYMROOT)/Config-iphoneos/\(targetName).framework/\(reexportedBinariesDirectoryName)/FwkTarget.framework"]) +- task.checkCommandLineContains(["/usr/bin/codesign", "--preserve-metadata=identifier,entitlements,flags", "\(SYMROOT)/Config-iphoneos/\(targetName).framework/\(reexportedBinariesDirectoryName)/FwkTarget.framework"]) ++ task.checkCommandLineContains(["@sigtool@/bin/codesign", "--preserve-metadata=identifier,entitlements,flags", "\(SYMROOT)/Config-iphoneos/\(targetName).framework/\(reexportedBinariesDirectoryName)/FwkTarget.framework"]) + results.checkTaskFollows(task, [.matchTarget(target), .matchRuleType("Copy"), .matchRuleItemBasename("FwkTarget.framework")]) + } + +@@ -2242,7 +2242,7 @@ fileprivate struct MergeableLibraryTests: CoreBasedTests { + } + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemPattern(.suffix("\(reexportedBinariesDirectoryName)/\(fwkTargetName).framework"))) { task in + task.checkRuleInfo(["CodeSign", "\(SYMROOT)/Config-iphoneos/\(targetName).app/\(reexportedBinariesDirectoryName)/\(fwkTargetName).framework"]) +- task.checkCommandLineContains(["/usr/bin/codesign", "--preserve-metadata=identifier,entitlements,flags", "\(SYMROOT)/Config-iphoneos/\(targetName).app/\(reexportedBinariesDirectoryName)/\(fwkTargetName).framework"]) ++ task.checkCommandLineContains(["@sigtool@/bin/codesign", "--preserve-metadata=identifier,entitlements,flags", "\(SYMROOT)/Config-iphoneos/\(targetName).app/\(reexportedBinariesDirectoryName)/\(fwkTargetName).framework"]) + results.checkTaskFollows(task, [.matchTarget(target), .matchRuleType("Copy"), .matchRuleItemPattern(.suffix("\(reexportedBinariesDirectoryName)/\(fwkTargetName).framework"))]) + } + } +diff --git a/Tests/SWBTaskConstructionTests/PlatformTaskConstructionTests.swift b/Tests/SWBTaskConstructionTests/PlatformTaskConstructionTests.swift +index f2e561d..5a11f29 100644 +--- a/Tests/SWBTaskConstructionTests/PlatformTaskConstructionTests.swift ++++ b/Tests/SWBTaskConstructionTests/PlatformTaskConstructionTests.swift +@@ -191,7 +191,7 @@ fileprivate struct PlatformTaskConstructionTests: CoreBasedTests { + } + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("FwkTarget.framework")) { task in + task.checkRuleInfo(["CodeSign", "\(SRCROOT)/build/Debug-iphoneos/AppTarget.app/Frameworks/FwkTarget.framework"]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "--timestamp=none", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "\(SRCROOT)/build/Debug-iphoneos/AppTarget.app/Frameworks/FwkTarget.framework"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "--timestamp=none", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "\(SRCROOT)/build/Debug-iphoneos/AppTarget.app/Frameworks/FwkTarget.framework"]) + task.checkInputs([ + .path("\(SRCROOT)/build/Debug-iphoneos/AppTarget.app/Frameworks/FwkTarget.framework"), + .path("\(SRCROOT)/build/Debug-iphoneos/AppTarget.app/Frameworks/FwkTarget.framework"), +@@ -211,7 +211,7 @@ fileprivate struct PlatformTaskConstructionTests: CoreBasedTests { + // There should be a codesign task for the app. + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("AppTarget.app")) { task in + #expect(task.ruleInfo[1] == "\(SRCROOT)/build/Debug-iphoneos/AppTarget.app") +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-iphoneos/AppTarget.build/AppTarget.app.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug-iphoneos/AppTarget.app"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-iphoneos/AppTarget.build/AppTarget.app.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug-iphoneos/AppTarget.app"]) + task.checkEnvironment([ + "CODESIGN_ALLOCATE": .equal("codesign_allocate"), + ], exact: true) +@@ -322,7 +322,7 @@ fileprivate struct PlatformTaskConstructionTests: CoreBasedTests { + } + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("FwkTarget.framework")) { task in + task.checkRuleInfo(["CodeSign", "\(SRCROOT)/build/Debug-iphonesimulator/AppTarget.app/Frameworks/FwkTarget.framework"]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "--timestamp=none", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "\(SRCROOT)/build/Debug-iphonesimulator/AppTarget.app/Frameworks/FwkTarget.framework"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "--timestamp=none", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "\(SRCROOT)/build/Debug-iphonesimulator/AppTarget.app/Frameworks/FwkTarget.framework"]) + task.checkInputs([ + .path("\(SRCROOT)/build/Debug-iphonesimulator/AppTarget.app/Frameworks/FwkTarget.framework"), + .path("\(SRCROOT)/build/Debug-iphonesimulator/AppTarget.app/Frameworks/FwkTarget.framework"), +@@ -346,7 +346,7 @@ fileprivate struct PlatformTaskConstructionTests: CoreBasedTests { + // There should be a codesign task for the app. + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("AppTarget.app")) { task in + #expect(task.ruleInfo[1] == "\(SRCROOT)/build/Debug-iphonesimulator/AppTarget.app") +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-iphonesimulator/AppTarget.build/AppTarget.app.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug-iphonesimulator/AppTarget.app"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-iphonesimulator/AppTarget.build/AppTarget.app.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug-iphonesimulator/AppTarget.app"]) + } + + // There should be one product validation task. +diff --git a/Tests/SWBTaskConstructionTests/PostprocessingTaskConstructionTests.swift b/Tests/SWBTaskConstructionTests/PostprocessingTaskConstructionTests.swift +index 85fd06e..d5d7251 100644 +--- a/Tests/SWBTaskConstructionTests/PostprocessingTaskConstructionTests.swift ++++ b/Tests/SWBTaskConstructionTests/PostprocessingTaskConstructionTests.swift +@@ -75,7 +75,7 @@ fileprivate struct PostprocessingTaskConstructionTests: CoreBasedTests { + let suffix = buildVariant == "normal" ? "" : "_\(buildVariant)" + + task.checkRuleInfo(["SetOwnerAndGroup", "exampleUser:exampleGroup", "/tmp/aProject.dst/usr/local/lib/Library\(suffix).dylib"]) +- task.checkCommandLine(["/usr/sbin/chown", "-RH", "exampleUser:exampleGroup", "/tmp/aProject.dst/usr/local/lib/Library\(suffix).dylib"]) ++ task.checkCommandLine(["@coreutils@/bin/chown", "-RH", "exampleUser:exampleGroup", "/tmp/aProject.dst/usr/local/lib/Library\(suffix).dylib"]) + + task.checkInputs([ + .path("/tmp/aProject.dst/usr/local/lib/Library\(suffix).dylib"), +@@ -117,7 +117,7 @@ fileprivate struct PostprocessingTaskConstructionTests: CoreBasedTests { + results.checkTarget("Framework") { target in + results.checkTask(.matchTarget(target), .matchRuleType("SetOwnerAndGroup")) { task in + task.checkRuleInfo(["SetOwnerAndGroup", "exampleUser:exampleGroup", "/tmp/aProject.dst/Library/Frameworks/Framework.framework"]) +- task.checkCommandLine(["/usr/sbin/chown", "-RH", "exampleUser:exampleGroup", "/tmp/aProject.dst/Library/Frameworks/Framework.framework"]) ++ task.checkCommandLine(["@coreutils@/bin/chown", "-RH", "exampleUser:exampleGroup", "/tmp/aProject.dst/Library/Frameworks/Framework.framework"]) + + task.checkInputs([ + .path("/tmp/aProject.dst/Library/Frameworks/Framework.framework"), +diff --git a/Tests/SWBTaskConstructionTests/SwiftTaskConstructionTests.swift b/Tests/SWBTaskConstructionTests/SwiftTaskConstructionTests.swift +index 1d901c0..c184bd2 100644 +--- a/Tests/SWBTaskConstructionTests/SwiftTaskConstructionTests.swift ++++ b/Tests/SWBTaskConstructionTests/SwiftTaskConstructionTests.swift +@@ -181,7 +181,7 @@ fileprivate struct SwiftTaskConstructionTests: CoreBasedTests { + // Create a fake codesign_allocate tool so it can be found in the executable search paths. + let fs = PseudoFS() + try await fs.writeFileContents(swiftCompilerPath) { $0 <<< "binary" } +- try await fs.writeFileContents(core.developerPath.path.join("Toolchains/XcodeDefault.xctoolchain/usr/bin/codesign_allocate")) { $0 <<< "binary" } ++ try await fs.writeFileContents(core.developerPath.path.join("@sigtool@/bin/codesign_allocate")) { $0 <<< "binary" } + + // NOTE: The toolchain cannot be set normally and must be passed in as an override. + var overrides = ["TOOLCHAINS": toolchainIdentifier] +@@ -437,7 +437,7 @@ fileprivate struct SwiftTaskConstructionTests: CoreBasedTests { + .name("CopySwiftStdlib \(SRCROOT)/build/Debug/AppTarget.app"),]) + + task.checkEnvironment([ +- "CODESIGN_ALLOCATE": .equal(core.developerPath.path.join("Toolchains/XcodeDefault.xctoolchain/usr/bin/codesign_allocate").str), ++ "CODESIGN_ALLOCATE": .equal(core.developerPath.path.join("@sigtool@/bin/codesign_allocate").str), + "DEVELOPER_DIR": .equal(core.developerPath.path.str), + "SDKROOT": .equal(core.loadSDK(.macOS).path.str), + // This is coming from our overrides in unit test infrastructure. +@@ -448,7 +448,7 @@ fileprivate struct SwiftTaskConstructionTests: CoreBasedTests { + // There should be a product 'Touch' task. + results.checkTask(.matchTarget(target), .matchRuleType("Touch")) { task in + task.checkRuleInfo(["Touch", "\(SRCROOT)/build/Debug/AppTarget.app"]) +- task.checkCommandLine(["/usr/bin/touch", "-c", "\(SRCROOT)/build/Debug/AppTarget.app"]) ++ task.checkCommandLine(["@coreutils@/bin/touch", "-c", "\(SRCROOT)/build/Debug/AppTarget.app"]) + } + + results.checkTask(.matchTarget(target), .matchRuleType("RegisterExecutionPolicyException")) { task in +diff --git a/Tests/SWBTaskConstructionTests/TaskConstructionTests.swift b/Tests/SWBTaskConstructionTests/TaskConstructionTests.swift +index 4f9a3e5..ee50974 100644 +--- a/Tests/SWBTaskConstructionTests/TaskConstructionTests.swift ++++ b/Tests/SWBTaskConstructionTests/TaskConstructionTests.swift +@@ -960,7 +960,7 @@ fileprivate struct TaskConstructionTests: CoreBasedTests { + // There should be a chown and chmod task. + results.checkTask(.matchTarget(target), .matchRuleType("SetOwnerAndGroup")) { task in + task.checkRuleInfo(["SetOwnerAndGroup", "exampleUser:exampleGroup", "/tmp/aProject.dst/Applications/AppTarget.app"]) +- task.checkCommandLine(["/usr/sbin/chown", "-RH", "exampleUser:exampleGroup", "/tmp/aProject.dst/Applications/AppTarget.app"]) ++ task.checkCommandLine(["@coreutils@/bin/chown", "-RH", "exampleUser:exampleGroup", "/tmp/aProject.dst/Applications/AppTarget.app"]) + + task.checkInputs([ + .path("/tmp/aProject.dst/Applications/AppTarget.app"), +@@ -996,7 +996,7 @@ fileprivate struct TaskConstructionTests: CoreBasedTests { + // There should be a chown task targeting the file in the the ALTERNATE_PERMISSIONS_FILES build setting. + results.checkTask(.matchTarget(target), .matchRuleType("SetOwner")) { task in + task.checkRuleInfo(["SetOwner", "fooOwner", "/tmp/aProject.dst/Applications/AlternatePermissions.txt"]) +- task.checkCommandLine(["/usr/sbin/chown", "-RH", "fooOwner", "/tmp/aProject.dst/Applications/AlternatePermissions.txt"]) ++ task.checkCommandLine(["@coreutils@/bin/chown", "-RH", "fooOwner", "/tmp/aProject.dst/Applications/AlternatePermissions.txt"]) + + task.checkInputs([ + .path("/tmp/aProject.dst/Applications/AlternatePermissions.txt"), +@@ -1056,7 +1056,7 @@ fileprivate struct TaskConstructionTests: CoreBasedTests { + + // There should be three codesign tasks (one for the copied FW, one for the copied dylib, one for the app), two of which should be re-signing tasks. + results.checkTask(.matchTarget(target), .matchRule(["CodeSign", "/tmp/aProject.dst/Applications/AppTarget.app/Contents/Frameworks/FWToCopy.framework/Versions/A"])) { task in +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "/tmp/aProject.dst/Applications/AppTarget.app/Contents/Frameworks/FWToCopy.framework/Versions/A"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "/tmp/aProject.dst/Applications/AppTarget.app/Contents/Frameworks/FWToCopy.framework/Versions/A"]) + task.checkInputs([ + .path("/tmp/aProject.dst/Applications/AppTarget.app/Contents/Frameworks/FWToCopy.framework"), + .path("/tmp/aProject.dst/Applications/AppTarget.app/Contents/Frameworks/FWToCopy.framework/Versions/A"), +@@ -1077,7 +1077,7 @@ fileprivate struct TaskConstructionTests: CoreBasedTests { + ]) + } + results.checkTask(.matchTarget(target), .matchRule(["CodeSign", "/tmp/aProject.dst/Applications/AppTarget.app/Contents/Frameworks/libdynamic.dylib"])) { task in +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "/tmp/aProject.dst/Applications/AppTarget.app/Contents/Frameworks/libdynamic.dylib"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "/tmp/aProject.dst/Applications/AppTarget.app/Contents/Frameworks/libdynamic.dylib"]) + task.checkInputs([ + .path("/tmp/aProject.dst/Applications/AppTarget.app/Contents/Frameworks/libdynamic.dylib"), + .path("/tmp/aProject.dst/Applications/AppTarget.app/Contents/Frameworks/libdynamic.dylib"), +@@ -1095,7 +1095,7 @@ fileprivate struct TaskConstructionTests: CoreBasedTests { + ]) + } + results.checkTask(.matchTarget(target), .matchRule(["CodeSign", "/tmp/aProject.dst/Applications/AppTarget.app"])) { task in +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Release/AppTarget.build/AppTarget.app.xcent", "--generate-entitlement-der", "/tmp/aProject.dst/Applications/AppTarget.app"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Release/AppTarget.build/AppTarget.app.xcent", "--generate-entitlement-der", "/tmp/aProject.dst/Applications/AppTarget.app"]) + task.checkInputs([ + .path("/tmp/aProject.dst/Applications/AppTarget.app"), + .path("/tmp/aProject.dst/Applications/AppTarget.app"), +@@ -4167,7 +4167,7 @@ fileprivate struct TaskConstructionTests: CoreBasedTests { + // There should be two code signing tasks, one for the library and one for the product. + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("libclang_rt.asan_osx_dynamic.dylib")) { task in + task.checkRuleInfo([.equal("CodeSign"), .equal("\(SRCROOT)/build/Debug/\(targetName).app/Contents/Frameworks/libclang_rt.asan_osx_dynamic.dylib")]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--timestamp=none", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app/Contents/Frameworks/libclang_rt.asan_osx_dynamic.dylib"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--timestamp=none", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app/Contents/Frameworks/libclang_rt.asan_osx_dynamic.dylib"]) + task.checkInputs([ + .path("\(SRCROOT)/build/Debug/AppTarget.app/Contents/Frameworks/libclang_rt.asan_osx_dynamic.dylib"), + .path("\(SRCROOT)/build/Debug/AppTarget.app/Contents/Frameworks/libclang_rt.asan_osx_dynamic.dylib"), +@@ -4178,7 +4178,7 @@ fileprivate struct TaskConstructionTests: CoreBasedTests { + } + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("\(targetName).app")) { task in + task.checkRuleInfo([.equal("CodeSign"), .equal("\(SRCROOT)/build/Debug/\(targetName).app")]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/AppTarget.build/AppTarget.app.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/AppTarget.build/AppTarget.app.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app"]) + } + } + +@@ -4225,7 +4225,7 @@ fileprivate struct TaskConstructionTests: CoreBasedTests { + // There should be one code signing task for the ASan library. + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("libclang_rt.asan_osx_dynamic.dylib")) { task in + task.checkRuleInfo([.equal("CodeSign"), .equal("\(SRCROOT)/build/Debug/\(targetName).app/Contents/Frameworks/libclang_rt.asan_osx_dynamic.dylib")]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--timestamp=none", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app/Contents/Frameworks/libclang_rt.asan_osx_dynamic.dylib"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--timestamp=none", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app/Contents/Frameworks/libclang_rt.asan_osx_dynamic.dylib"]) + task.checkInputs([ + .path("\(SRCROOT)/build/Debug/AppTarget.app/Contents/Frameworks/libclang_rt.asan_osx_dynamic.dylib"), + .path("\(SRCROOT)/build/Debug/AppTarget.app/Contents/Frameworks/libclang_rt.asan_osx_dynamic.dylib"), +@@ -4238,7 +4238,7 @@ fileprivate struct TaskConstructionTests: CoreBasedTests { + // There should be one code signing task for the TSan library. + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("libclang_rt.tsan_osx_dynamic.dylib")) { task in + task.checkRuleInfo([.equal("CodeSign"), .equal("\(SRCROOT)/build/Debug/\(targetName).app/Contents/Frameworks/libclang_rt.tsan_osx_dynamic.dylib")]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--timestamp=none", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app/Contents/Frameworks/libclang_rt.tsan_osx_dynamic.dylib"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--timestamp=none", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app/Contents/Frameworks/libclang_rt.tsan_osx_dynamic.dylib"]) + task.checkInputs([ + .path("\(SRCROOT)/build/Debug/AppTarget.app/Contents/Frameworks/libclang_rt.tsan_osx_dynamic.dylib"), + .path("\(SRCROOT)/build/Debug/AppTarget.app/Contents/Frameworks/libclang_rt.tsan_osx_dynamic.dylib"), +@@ -4301,7 +4301,7 @@ fileprivate struct TaskConstructionTests: CoreBasedTests { + // There should be two code signing tasks, one for the library and one for the product. + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("libclang_rt.tsan_osx_dynamic.dylib")) { task in + task.checkRuleInfo([.equal("CodeSign"), .equal("\(SRCROOT)/build/Debug/\(targetName).app/Contents/Frameworks/libclang_rt.tsan_osx_dynamic.dylib")]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--timestamp=none", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app/Contents/Frameworks/libclang_rt.tsan_osx_dynamic.dylib"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--timestamp=none", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app/Contents/Frameworks/libclang_rt.tsan_osx_dynamic.dylib"]) + task.checkInputs([ + .path("\(SRCROOT)/build/Debug/AppTarget.app/Contents/Frameworks/libclang_rt.tsan_osx_dynamic.dylib"), + .path("\(SRCROOT)/build/Debug/AppTarget.app/Contents/Frameworks/libclang_rt.tsan_osx_dynamic.dylib"), +@@ -4312,7 +4312,7 @@ fileprivate struct TaskConstructionTests: CoreBasedTests { + } + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("\(targetName).app")) { task in + task.checkRuleInfo([.equal("CodeSign"), .equal("\(SRCROOT)/build/Debug/\(targetName).app")]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/AppTarget.build/AppTarget.app.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/AppTarget.build/AppTarget.app.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app"]) + } + } + +@@ -4356,7 +4356,7 @@ fileprivate struct TaskConstructionTests: CoreBasedTests { + // There should be two code signing tasks, one for the library and one for the product. + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("libclang_rt.ubsan_osx_dynamic.dylib")) { task in + task.checkRuleInfo([.equal("CodeSign"), .equal("\(SRCROOT)/build/Debug/\(targetName).app/Contents/Frameworks/libclang_rt.ubsan_osx_dynamic.dylib")]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--timestamp=none", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app/Contents/Frameworks/libclang_rt.ubsan_osx_dynamic.dylib"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--timestamp=none", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app/Contents/Frameworks/libclang_rt.ubsan_osx_dynamic.dylib"]) + task.checkInputs([ + .path("\(SRCROOT)/build/Debug/AppTarget.app/Contents/Frameworks/libclang_rt.ubsan_osx_dynamic.dylib"), + .path("\(SRCROOT)/build/Debug/AppTarget.app/Contents/Frameworks/libclang_rt.ubsan_osx_dynamic.dylib"), +@@ -4367,7 +4367,7 @@ fileprivate struct TaskConstructionTests: CoreBasedTests { + } + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("\(targetName).app")) { task in + task.checkRuleInfo([.equal("CodeSign"), .equal("\(SRCROOT)/build/Debug/\(targetName).app")]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/AppTarget.build/AppTarget.app.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/AppTarget.build/AppTarget.app.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app"]) + } + } + +diff --git a/Tests/SWBTaskConstructionTests/UnitTestTaskConstructionTests.swift b/Tests/SWBTaskConstructionTests/UnitTestTaskConstructionTests.swift +index 761146f..95bfcb7 100644 +--- a/Tests/SWBTaskConstructionTests/UnitTestTaskConstructionTests.swift ++++ b/Tests/SWBTaskConstructionTests/UnitTestTaskConstructionTests.swift +@@ -657,7 +657,7 @@ fileprivate struct UnitTestTaskConstructionTests: CoreBasedTests { + } + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("UnitTestTargetOne.xctest")) { task in + task.checkRuleInfo(["CodeSign", "\(SRCROOT)/build/Debug/AppTarget.app/Contents/PlugIns/UnitTestTargetOne.xctest"]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/UnitTestTargetOne.build/UnitTestTargetOne.xctest.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/AppTarget.app/Contents/PlugIns/UnitTestTargetOne.xctest"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/UnitTestTargetOne.build/UnitTestTargetOne.xctest.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/AppTarget.app/Contents/PlugIns/UnitTestTargetOne.xctest"]) + task.checkInputs([ + .path("\(SRCROOT)/build/Debug/AppTarget.app/Contents/PlugIns/UnitTestTargetOne.xctest"), + .path("\(SRCROOT)/build/Debug/AppTarget.app/Contents/PlugIns/UnitTestTargetOne.xctest"), +@@ -843,7 +843,7 @@ fileprivate struct UnitTestTaskConstructionTests: CoreBasedTests { + results.checkTask(.matchTarget(target), .matchRuleType("ProcessProductPackagingDER")) { _ in } + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("UnitTestTargetOne.xctest")) { task in + task.checkRuleInfo(["CodeSign", "\(SRCROOT)/build/UninstalledProducts/macosx/UnitTestTargetOne.xctest"]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/UnitTestTargetOne.build/UnitTestTargetOne.xctest.xcent", "--generate-entitlement-der", "\(SRCROOT)/build/UninstalledProducts/macosx/UnitTestTargetOne.xctest"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/UnitTestTargetOne.build/UnitTestTargetOne.xctest.xcent", "--generate-entitlement-der", "\(SRCROOT)/build/UninstalledProducts/macosx/UnitTestTargetOne.xctest"]) + task.checkInputs([ + .path("\(SRCROOT)/build/UninstalledProducts/macosx/UnitTestTargetOne.xctest"), + .path("\(SRCROOT)/build/UninstalledProducts/macosx/UnitTestTargetOne.xctest"), +@@ -2515,7 +2515,7 @@ fileprivate struct UnitTestTaskConstructionTests: CoreBasedTests { + } + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("UITestTarget.xctest")) { task in + task.checkRuleInfo(["CodeSign", "\(SRCROOT)/build/Debug/UITestTarget-Runner.app/Contents/PlugIns/UITestTarget.xctest"]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/UITestTarget.build/UITestTarget.xctest.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/UITestTarget-Runner.app/Contents/PlugIns/UITestTarget.xctest"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/UITestTarget.build/UITestTarget.xctest.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/UITestTarget-Runner.app/Contents/PlugIns/UITestTarget.xctest"]) + task.checkInputs(contain: [ + .path("\(SRCROOT)/build/Debug/UITestTarget-Runner.app/Contents/PlugIns/UITestTarget.xctest"), + .path("\(SRCROOT)/build/Debug/UITestTarget-Runner.app/Contents/PlugIns/UITestTarget.xctest"), +@@ -2535,7 +2535,7 @@ fileprivate struct UnitTestTaskConstructionTests: CoreBasedTests { + } + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("UITestTarget-Runner.app")) { task in + task.checkRuleInfo(["CodeSign", "\(SRCROOT)/build/Debug/UITestTarget-Runner.app"]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/UITestTarget.build/UITestTarget.xctest.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/UITestTarget-Runner.app"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/UITestTarget.build/UITestTarget.xctest.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/UITestTarget-Runner.app"]) + task.checkInputs(contain: ([[ + .path("\(SRCROOT)/build/Debug/UITestTarget-Runner.app/Contents/PlugIns/UITestTarget.xctest"), + .path("\(SRCROOT)/build/Debug/UITestTarget-Runner.app"), +@@ -2689,7 +2689,7 @@ fileprivate struct UnitTestTaskConstructionTests: CoreBasedTests { + results.checkTask(.matchTarget(target), .matchRuleType("ProcessProductPackagingDER"), .matchRuleItemPattern(.suffix(".xcent"))) { _ in } + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("UITestTarget.xctest")) { task in + task.checkRuleInfo(["CodeSign", "\(SRCROOT)/build/UninstalledProducts/macosx/UITestTarget-Runner.app/Contents/PlugIns/UITestTarget.xctest"]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/UITestTarget.build/UITestTarget.xctest.xcent", "--generate-entitlement-der", "\(SRCROOT)/build/UninstalledProducts/macosx/UITestTarget-Runner.app/Contents/PlugIns/UITestTarget.xctest"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/UITestTarget.build/UITestTarget.xctest.xcent", "--generate-entitlement-der", "\(SRCROOT)/build/UninstalledProducts/macosx/UITestTarget-Runner.app/Contents/PlugIns/UITestTarget.xctest"]) + task.checkInputs(contain: [ + .path("\(SRCROOT)/build/UninstalledProducts/macosx/UITestTarget-Runner.app/Contents/PlugIns/UITestTarget.xctest"), + .path("\(SRCROOT)/build/UninstalledProducts/macosx/UITestTarget-Runner.app/Contents/PlugIns/UITestTarget.xctest"), +@@ -2709,7 +2709,7 @@ fileprivate struct UnitTestTaskConstructionTests: CoreBasedTests { + } + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("UITestTarget-Runner.app")) { task in + task.checkRuleInfo(["CodeSign", "\(SRCROOT)/build/UninstalledProducts/macosx/UITestTarget-Runner.app"]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/UITestTarget.build/UITestTarget.xctest.xcent", "--generate-entitlement-der", "\(SRCROOT)/build/UninstalledProducts/macosx/UITestTarget-Runner.app"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/UITestTarget.build/UITestTarget.xctest.xcent", "--generate-entitlement-der", "\(SRCROOT)/build/UninstalledProducts/macosx/UITestTarget-Runner.app"]) + task.checkInputs(contain: ([[ + .path("\(SRCROOT)/build/UninstalledProducts/macosx/UITestTarget-Runner.app/Contents/PlugIns/UITestTarget.xctest"), + .path("\(SRCROOT)/build/UninstalledProducts/macosx/UITestTarget-Runner.app"), +diff --git a/Tests/SWBTaskConstructionTests/WatchTaskConstructionTests.swift b/Tests/SWBTaskConstructionTests/WatchTaskConstructionTests.swift +index db2a64f..7319fdd 100644 +--- a/Tests/SWBTaskConstructionTests/WatchTaskConstructionTests.swift ++++ b/Tests/SWBTaskConstructionTests/WatchTaskConstructionTests.swift +@@ -296,7 +296,7 @@ fileprivate struct WatchTaskConstructionTests: CoreBasedTests { + // There should be one codesign task. + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in + #expect(task.ruleInfo[1] == "\(SRCROOT)/build/Debug-watchos/Watchable WatchKit Extension.appex") +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-watchos/\(target.target.name).build/\(target.target.name).appex.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug-watchos/\(target.target.name).appex"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-watchos/\(target.target.name).build/\(target.target.name).appex.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug-watchos/\(target.target.name).appex"]) + task.checkEnvironment([ + "CODESIGN_ALLOCATE": .equal("codesign_allocate"), + ], exact: true) +@@ -384,7 +384,7 @@ fileprivate struct WatchTaskConstructionTests: CoreBasedTests { + // There should be one codesign task. + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in + #expect(task.ruleInfo[1] == builtWatchAppPath) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-watchos/Watchable WatchKit App.build/Watchable WatchKit App.app.xcent", "--timestamp=none", "--generate-entitlement-der", builtWatchAppPath]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-watchos/Watchable WatchKit App.build/Watchable WatchKit App.app.xcent", "--timestamp=none", "--generate-entitlement-der", builtWatchAppPath]) + task.checkEnvironment([ + "CODESIGN_ALLOCATE": .equal("codesign_allocate"), + ], exact: true) +@@ -490,7 +490,7 @@ fileprivate struct WatchTaskConstructionTests: CoreBasedTests { + // There should be one codesign task. + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in + #expect(task.ruleInfo[1] == builtHostIOSAppPath) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-iphoneos/Watchable.build/Watchable.app.xcent", "--timestamp=none", "--generate-entitlement-der", builtHostIOSAppPath]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-iphoneos/Watchable.build/Watchable.app.xcent", "--timestamp=none", "--generate-entitlement-der", builtHostIOSAppPath]) + task.checkEnvironment([ + "CODESIGN_ALLOCATE": .equal("codesign_allocate"), + ], exact: true) +@@ -599,7 +599,7 @@ fileprivate struct WatchTaskConstructionTests: CoreBasedTests { + // There should be one codesign task. + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in + #expect(task.ruleInfo[1] == "\(SRCROOT)/build/Debug-watchsimulator/Watchable WatchKit Extension.appex") +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-watchsimulator/Watchable WatchKit Extension.build/Watchable WatchKit Extension.appex.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug-watchsimulator/Watchable WatchKit Extension.appex"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-watchsimulator/Watchable WatchKit Extension.build/Watchable WatchKit Extension.appex.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug-watchsimulator/Watchable WatchKit Extension.appex"]) + task.checkEnvironment([ + "CODESIGN_ALLOCATE": .equal("codesign_allocate"), + ], exact: true) +@@ -667,7 +667,7 @@ fileprivate struct WatchTaskConstructionTests: CoreBasedTests { + // There should be one codesign task. + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in + #expect(task.ruleInfo[1] == builtWatchAppPath) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-watchsimulator/Watchable WatchKit App.build/Watchable WatchKit App.app.xcent", "--timestamp=none", "--generate-entitlement-der", builtWatchAppPath]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-watchsimulator/Watchable WatchKit App.build/Watchable WatchKit App.app.xcent", "--timestamp=none", "--generate-entitlement-der", builtWatchAppPath]) + task.checkEnvironment([ + "CODESIGN_ALLOCATE": .equal("codesign_allocate"), + ], exact: true) +@@ -768,7 +768,7 @@ fileprivate struct WatchTaskConstructionTests: CoreBasedTests { + // There should be one codesign task. + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in + #expect(task.ruleInfo[1] == builtHostIOSAppPath) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-iphonesimulator/Watchable.build/Watchable.app.xcent", "--timestamp=none", "--generate-entitlement-der", builtHostIOSAppPath]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-iphonesimulator/Watchable.build/Watchable.app.xcent", "--timestamp=none", "--generate-entitlement-der", builtHostIOSAppPath]) + task.checkEnvironment([ + "CODESIGN_ALLOCATE": .equal("codesign_allocate"), + ], exact: true) +diff --git a/Tests/SWBTaskExecutionTests/SignatureCollectionActionTests.swift b/Tests/SWBTaskExecutionTests/SignatureCollectionActionTests.swift +index 3c11b2c..1842a9f 100644 +--- a/Tests/SWBTaskExecutionTests/SignatureCollectionActionTests.swift ++++ b/Tests/SWBTaskExecutionTests/SignatureCollectionActionTests.swift +@@ -107,7 +107,7 @@ fileprivate struct SignatureCollectionActionTests { + let bundlePath = rootPath.join("test.bundle") + try fs.copy(Path(Bundle.module.bundlePath), to: bundlePath) + +- let codesignTool = URL(fileURLWithPath: "/usr/bin/codesign") ++ let codesignTool = URL(fileURLWithPath: "@sigtool@/bin/codesign") + let codesignResult = try await Process.run(url: codesignTool, arguments: ["--remove-signature", bundlePath.str]) + #expect(codesignResult.isSuccess) + +@@ -162,7 +162,7 @@ fileprivate struct SignatureCollectionActionTests { + let bundlePath = rootPath.join("test.bundle") + try fs.copy(Path(Bundle.module.bundlePath), to: bundlePath) + +- let codesignTool = URL(fileURLWithPath: "/usr/bin/codesign") ++ let codesignTool = URL(fileURLWithPath: "@sigtool@/bin/codesign") + let codesignResult = try await Process.run(url: codesignTool, arguments: ["--remove-signature", bundlePath.str]) + #expect(codesignResult.isSuccess) + +diff --git a/Tests/SWBUtilTests/MiscTests.swift b/Tests/SWBUtilTests/MiscTests.swift +index f93094a..2ff6572 100644 +--- a/Tests/SWBUtilTests/MiscTests.swift ++++ b/Tests/SWBUtilTests/MiscTests.swift +@@ -62,7 +62,7 @@ import SWBUtil + let path = try await xcode.compileFramework(path: tmpDir, platform: .iOS, infoLookup: Lookup(), archs: ["arm64"], useSwift: false) + #expect(!pbxcp_path_is_code_signed(path), "binary was unexpectedly code signed") + +- _ = try await runProcess(["/usr/bin/codesign", "-s", "-", path.str]) ++ _ = try await runProcess(["@sigtool@/bin/codesign", "-s", "-", path.str]) + #expect(pbxcp_path_is_code_signed(path), "binary was unexpectedly NOT code signed") + } + } +diff --git a/Tests/SWBUtilTests/SignaturesTests.swift b/Tests/SWBUtilTests/SignaturesTests.swift +index ca93d8f..c853bd2 100644 +--- a/Tests/SWBUtilTests/SignaturesTests.swift ++++ b/Tests/SWBUtilTests/SignaturesTests.swift +@@ -28,7 +28,7 @@ fileprivate struct SignaturesTests { + try await fs.writePlist(bundlePath.join("Info.plist"), .plDict([:])) + try fs.write(bundlePath.join("test"), contents: "#!/bin/bash", atomically: true) + +- let codesignTool = URL(fileURLWithPath: "/usr/bin/codesign") ++ let codesignTool = URL(fileURLWithPath: "@sigtool@/bin/codesign") + + // Set-up the ad-hoc signed bundle for testing. + let codesignSigningResult = try await Process.run(url: codesignTool, arguments: ["-s", "-", "-i", "test-ident", bundlePath.str]) +@@ -48,7 +48,7 @@ fileprivate struct SignaturesTests { + try await fs.writePlist(bundlePath.join("Info.plist"), .plDict([:])) + try fs.write(bundlePath.join("test"), contents: "#!/bin/bash", atomically: true) + +- let codesignTool = URL(fileURLWithPath: "/usr/bin/codesign") ++ let codesignTool = URL(fileURLWithPath: "@sigtool@/bin/codesign") + + // Set-up the ad-hoc signed bundle for testing. + let codesignSigningResult = try await Process.run(url: codesignTool, arguments: ["-s", "-", bundlePath.str]) +diff --git a/Tests/SwiftBuildTests/BuildOperationTests.swift b/Tests/SwiftBuildTests/BuildOperationTests.swift +index 077da08..6a14464 100644 +--- a/Tests/SwiftBuildTests/BuildOperationTests.swift ++++ b/Tests/SwiftBuildTests/BuildOperationTests.swift +@@ -213,7 +213,7 @@ fileprivate struct BuildOperationTests: CoreBasedTests { + buildPhases: [ + TestShellScriptBuildPhase( + name: "A.Script", originalObjectID: "A.Script", contents: (OutputByteStream() +- <<< "/usr/bin/touch ${SCRIPT_OUTPUT_FILE_0}" ++ <<< "@coreutils@/bin/touch ${SCRIPT_OUTPUT_FILE_0}" + ).bytes.asString, inputs: [], outputs: ["$(DERIVED_FILE_DIR)/stamp"]) + ], + dependencies: ["B"] +@@ -228,7 +228,7 @@ fileprivate struct BuildOperationTests: CoreBasedTests { + // This task will be up-to-date after the first build + TestShellScriptBuildPhase( + name: "B.Once", originalObjectID: "B.Once", +- contents: "/usr/bin/touch ${SCRIPT_OUTPUT_FILE_0}", ++ contents: "@coreutils@/bin/touch ${SCRIPT_OUTPUT_FILE_0}", + inputs: [], outputs: ["$(DERIVED_FILE_DIR)/stamp"]), + // This task will always run. + TestShellScriptBuildPhase( +@@ -1260,7 +1260,7 @@ fileprivate struct BuildOperationTests: CoreBasedTests { + "PRODUCT_NAME": "$(TARGET_NAME)", + "USE_HEADERMAP": "NO", + // We run a task which will never finish. +- "CC": "/usr/bin/yes", ++ "CC": "@coreutils@/bin/yes", + ])], + buildPhases: [ + TestSourcesBuildPhase([TestBuildFile("foo.c")]), +@@ -1331,7 +1331,7 @@ fileprivate struct BuildOperationTests: CoreBasedTests { + "PRODUCT_NAME": "$(TARGET_NAME)", + "USE_HEADERMAP": "NO", + // We run a task which will never finish. +- "CC": "/usr/bin/yes", ++ "CC": "@coreutils@/bin/yes", + ])], + buildPhases: [ + TestSourcesBuildPhase([TestBuildFile("foo.c")]), +@@ -1403,7 +1403,7 @@ fileprivate struct BuildOperationTests: CoreBasedTests { + "PRODUCT_NAME": "$(TARGET_NAME)", + "USE_HEADERMAP": "NO", + // We run a task which will never finish. +- "CC": "/usr/bin/yes", ++ "CC": "@coreutils@/bin/yes", + ])], + buildPhases: [ + TestSourcesBuildPhase([TestBuildFile("foo.c")]), +@@ -1485,7 +1485,7 @@ fileprivate struct BuildOperationTests: CoreBasedTests { + "PRODUCT_NAME": "$(TARGET_NAME)", + "USE_HEADERMAP": "NO", + // We run a task which will never finish. +- "CC": "/usr/bin/yes", ++ "CC": "@coreutils@/bin/yes", + ])], + buildPhases: [ + TestSourcesBuildPhase([TestBuildFile("foo.c")]), +@@ -1565,7 +1565,7 @@ fileprivate struct BuildOperationTests: CoreBasedTests { + "PRODUCT_NAME": "$(TARGET_NAME)", + "USE_HEADERMAP": "NO", + // We run a task which will never finish. +- "CC": "/usr/bin/yes", ++ "CC": "@coreutils@/bin/yes", + ])], + buildPhases: [ + TestSourcesBuildPhase([TestBuildFile("foo.c")]), +@@ -1724,7 +1724,7 @@ fileprivate struct BuildOperationTests: CoreBasedTests { + "PRODUCT_NAME": "$(TARGET_NAME)", + "USE_HEADERMAP": "NO", + // We run a task which will never finish. +- "CC": "/usr/bin/yes", ++ "CC": "@coreutils@/bin/yes", + ])], + buildPhases: [ + TestSourcesBuildPhase([TestBuildFile("foo.c")]), +-- +2.51.2 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-build/patches/0002-treat-nixpkgs-sdk-as-xcode.patch b/pkgs/development/compilers/swift/by-name/sw/swift-build/patches/0002-treat-nixpkgs-sdk-as-xcode.patch new file mode 100644 index 000000000000..8e6a921ac3e5 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-build/patches/0002-treat-nixpkgs-sdk-as-xcode.patch @@ -0,0 +1,49 @@ +From 0e17f25cf6827dfa94ad37590964d4f7b1d23625 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Tue, 9 Dec 2025 21:03:16 -0500 +Subject: [PATCH] treat-nixpkgs-sdk-as-xcode + +--- + Sources/SWBCore/Core.swift | 4 ++-- + Sources/SWBTestSupport/SkippedTestSupport.swift | 3 ++- + 2 files changed, 4 insertions(+), 3 deletions(-) + +diff --git a/Sources/SWBCore/Core.swift b/Sources/SWBCore/Core.swift +index 8a19a5e..7ab64fd 100644 +--- a/Sources/SWBCore/Core.swift ++++ b/Sources/SWBCore/Core.swift +@@ -267,7 +267,7 @@ public final class Core: Sendable { + + switch developerPath { + case .xcode(let path): +- toolchainPaths.append((path.join("Toolchains"), strict: path.str.hasSuffix(".app/Contents/Developer"))) ++ toolchainPaths.append((path.join("Toolchains"), strict: path.str.hasSuffix(".app/Contents/Developer") || path.str.hasPrefix("@store-dir@"))) + case .swiftToolchain(let path, xcodeDeveloperPath: let xcodeDeveloperPath): + if hostOperatingSystem == .windows { + toolchainPaths.append((path.join("Toolchains"), strict: true)) +@@ -275,7 +275,7 @@ public final class Core: Sendable { + toolchainPaths.append((path, strict: true)) + } + if let xcodeDeveloperPath { +- toolchainPaths.append((xcodeDeveloperPath.join("Toolchains"), strict: xcodeDeveloperPath.str.hasSuffix(".app/Contents/Developer"))) ++ toolchainPaths.append((xcodeDeveloperPath.join("Toolchains"), strict: xcodeDeveloperPath.str.hasSuffix(".app/Contents/Developer") || path.str.hasPrefix("@store-dir@"))) + } + } + +diff --git a/Sources/SWBTestSupport/SkippedTestSupport.swift b/Sources/SWBTestSupport/SkippedTestSupport.swift +index 1db4090..08e3109 100644 +--- a/Sources/SWBTestSupport/SkippedTestSupport.swift ++++ b/Sources/SWBTestSupport/SkippedTestSupport.swift +@@ -148,7 +148,8 @@ extension Trait where Self == Testing.ConditionTrait { + /// Constructs a condition trait that causes a test to be disabled if the developer directory is pointing at an Xcode developer directory. + package static var skipXcodeToolchain: Self { + disabled("This test is incompatible with Xcode toolchains.", { +- try await ConditionTraitContext.shared.getCore().developerPath.path.str.contains(".app/Contents/Developer") ++ let core = try await ConditionTraitContext.shared.getCore() ++ return core.developerPath.path.str.contains(".app/Contents/Developer") || core.developerPath.path.str.hasPrefix("@store-dir@") + }) + } + +-- +2.51.2 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-build/patches/0003-find-bundles-in-store.patch b/pkgs/development/compilers/swift/by-name/sw/swift-build/patches/0003-find-bundles-in-store.patch new file mode 100644 index 000000000000..b2d8e2467e05 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-build/patches/0003-find-bundles-in-store.patch @@ -0,0 +1,48 @@ +From a60ea4fbf21654eac779eece5c6d304e0f7b64c8 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 13 Dec 2025 09:40:18 -0500 +Subject: [PATCH] find-bundles-in-store + +--- + Sources/CMakeLists.txt | 11 +++++------ + 1 file changed, 5 insertions(+), 6 deletions(-) + +diff --git a/Sources/CMakeLists.txt b/Sources/CMakeLists.txt +index c0d0304..9df123e 100644 +--- a/Sources/CMakeLists.txt ++++ b/Sources/CMakeLists.txt +@@ -24,18 +24,17 @@ function(SwiftBuild_Bundle) + ${CMAKE_COMMAND} -E copy_if_different ${BundleXCSpecs_FILES} "${CMAKE_BINARY_DIR}/share/pm/SwiftBuild_${BundleXCSpecs_MODULE}.resources/") + + +- file(TO_NATIVE_PATH "${CMAKE_BINARY_DIR}/share/pm/SwiftBuild_${BundleXCSpecs_MODULE}.resources" _SWIFT_BUILD_RESOURCE_BUNDLE_BUILD_PATH) ++ file(TO_NATIVE_PATH "${CMAKE_INSTALL_DATADIR}/pm/SwiftBuild_${BundleXCSpecs_MODULE}.resources" _SWIFT_BUILD_RESOURCE_BUNDLE_BUILD_PATH) + file(CONFIGURE + OUTPUT "${CMAKE_BINARY_DIR}/resource_accessors/SwiftBuild_${BundleXCSpecs_MODULE}_resource_bundle_accessor.swift" + CONTENT [[ + import Foundation + extension Foundation.Bundle { + static let module: Bundle = { +- let mainPath = Bundle.main.bundleURL.appendingPathComponent("SwiftBuild_@BundleXCSpecs_MODULE@.resources").path +- let buildPath = #"@_SWIFT_BUILD_RESOURCE_BUNDLE_BUILD_PATH@"# ++ let mainPath = #"@_SWIFT_BUILD_RESOURCE_BUNDLE_BUILD_PATH@"# + let preferredBundle = Bundle(path: mainPath) +- guard let bundle = preferredBundle ?? Bundle(path: buildPath) else { +- Swift.fatalError("could not load resource bundle: from \(mainPath) or \(buildPath)") ++ guard let bundle = preferredBundle else { ++ Swift.fatalError("could not load resource bundle: from \(mainPath)") + } + return bundle + }() +@@ -48,7 +47,7 @@ function(SwiftBuild_Bundle) + + install(DIRECTORY + "${CMAKE_BINARY_DIR}/share/pm/SwiftBuild_${BundleXCSpecs_MODULE}.resources/" +- DESTINATION share/pm/SwiftBuild_${BundleXCSpecs_MODULE}.resources/) ++ DESTINATION ${CMAKE_INSTALL_DATADIR}/pm/SwiftBuild_${BundleXCSpecs_MODULE}.resources/) + endfunction() + + add_subdirectory(SWBCSupport) +-- +2.51.2 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-certificates/files/SwiftCertificatesConfig.cmake b/pkgs/development/compilers/swift/by-name/sw/swift-certificates/files/SwiftCertificatesConfig.cmake new file mode 100644 index 000000000000..702338ff038b --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-certificates/files/SwiftCertificatesConfig.cmake @@ -0,0 +1,5 @@ +add_library(X509 @buildType@ IMPORTED) +set_target_properties(X509 PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}X509${CMAKE_@buildType@_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@include@/lib/swift/@swiftPlatform@" +) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-certificates/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-certificates/package.nix new file mode 100644 index 000000000000..7ea70f784983 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-certificates/package.nix @@ -0,0 +1,76 @@ +{ + lib, + cmake, + fetchFromGitHub, + gitUpdater, + ninja, + stdenv, + swift, + swift-asn1, + swift-crypto, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "swift-certificates"; + version = "1.19.4"; + + outputs = [ + "out" + "dev" + ]; + + src = fetchFromGitHub { + owner = "apple"; + repo = "swift-certificates"; + tag = finalAttrs.version; + hash = "sha256-8I7/JAcGYrk22DymtlM2aiFXlQc3OijBAGL3DtoJWTE="; + }; + + postPatch = '' + substituteInPlace cmake/modules/SwiftSupport.cmake \ + --replace-fail 'ARCHIVE DESTINATION lib/''${swift}/''${swift_os}' 'ARCHIVE DESTINATION ''${CMAKE_INSTALL_LIBDIR}' \ + --replace-fail 'LIBRARY DESTINATION lib/''${swift}/''${swift_os}' 'LIBRARY DESTINATION ''${CMAKE_INSTALL_LIBDIR}' \ + --replace-fail 'RUNTIME DESTINATION bin' 'RUNTIME DESTINATION ''${CMAKE_INSTALL_BINDIR}' \ + --replace-fail ' DESTINATION lib' "DESTINATION ''${!outputInclude}/lib" + ''; + + strictDeps = true; + + preConfigure = '' + appendToVar cmakeFlags -DCMAKE_Swift_COMPILER_TARGET=${stdenv.hostPlatform.swift.triple} + appendToVar cmakeFlags -DCMAKE_Swift_FLAGS=-module-cache-path\ "$NIX_BUILD_TOP/module-cache" + ''; + + nativeBuildInputs = [ + cmake + ninja + swift + ]; + + buildInputs = [ + swift-asn1 + swift-crypto + ]; + + postInstall = '' + # Install CMake config file for the Swift Certificates library. + mkdir -p "''${!outputDev}/lib/cmake/SwiftCertificates" + substitute ${./files/SwiftCertificatesConfig.cmake} "''${!outputDev}/lib/cmake/SwiftCertificates/SwiftCertificatesConfig.cmake" \ + --replace-fail '@buildType@' ${if stdenv.hostPlatform.isStatic then "STATIC" else "SHARED"} \ + --replace-fail '@include@' "''${!outputDev}" \ + --replace-fail '@lib@' "''${!outputLib}" \ + --replace-fail '@swiftPlatform@' ${stdenv.hostPlatform.swift.platform} + ''; + + passthru.updateScript = gitUpdater { }; + + __structuredAttrs = true; + + meta = { + homepage = "https://github.com/apple/swift-certificates"; + description = "An implementation of X.509 for Swift"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-cmark/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-cmark/package.nix new file mode 100644 index 000000000000..c6464db67e6b --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-cmark/package.nix @@ -0,0 +1,44 @@ +{ + lib, + cmake, + fetchFromGitHub, + gitUpdater, + ninja, + stdenv, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "swift-cmark"; + version = "0.8.0"; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-cmark"; + tag = finalAttrs.version; + hash = "sha256-0pyZ5yQRsbiKwz2XT8N6dMwCLcmM28qQOrxHcV6uH7g="; + }; + + strictDeps = true; + + nativeBuildInputs = [ + cmake + ninja + ]; + + doCheck = stdenv.buildPlatform.canExecute stdenv.hostPlatform; + + passthru.updateScript = gitUpdater { }; + + __structuredAttrs = true; + + meta = { + description = "CommonMark parsing and rendering library"; + homepage = "https://github.com/swiftlang/swift-cmark"; + platforms = lib.platforms.unix ++ lib.platforms.windows ++ lib.platforms.wasi; + license = [ + lib.licenses.bsd2 + lib.licenses.mit + ]; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-collections/files/SwiftCollectionsConfig.cmake b/pkgs/development/compilers/swift/by-name/sw/swift-collections/files/SwiftCollectionsConfig.cmake new file mode 100644 index 000000000000..6847ed976e5c --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-collections/files/SwiftCollectionsConfig.cmake @@ -0,0 +1,21 @@ +set(CollectionModules + _RopeModule + BasicContainers + BitCollections + Collections + ContainersPreview + DequeModule + HashTreeCollections + HeapModule + InternalCollectionsUtilities + OrderedCollections + TrailingElementsModule +) + +foreach(CollectionModule ${CollectionModules}) + add_library(SwiftCollections::${CollectionModule} @buildType@ IMPORTED) + set_target_properties(SwiftCollections::${CollectionModule} PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}${CollectionModule}${CMAKE_@buildType@_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@include@/lib/swift/@swiftPlatform@" + ) +endforeach() diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-collections/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-collections/package.nix new file mode 100644 index 000000000000..b9ba08469736 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-collections/package.nix @@ -0,0 +1,75 @@ +{ + lib, + cmake, + fetchFromGitHub, + gitUpdater, + ninja, + stdenv, + swift-minimal, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "swift-collections"; + version = "1.6.0"; + + outputs = [ + "out" + "dev" + ]; + + src = fetchFromGitHub { + owner = "apple"; + repo = "swift-collections"; + tag = finalAttrs.version; + hash = "sha256-oLYfOxB4CGH5tTkNOi0IX3iHTO64YBoaFyu+/1I5HNE="; + }; + + postPatch = '' + substituteInPlace cmake/modules/SwiftSupport.cmake \ + --replace-fail ' DESTINATION lib' "DESTINATION ''${!outputDev}/lib" \ + --replace-fail 'lib/''${swift}/''${COLLECTIONS_PLATFORM}$<$:/''${COLLECTIONS_ARCH}>' \''${CMAKE_INSTALL_LIBDIR} + ''; + + strictDeps = true; + + cmakeFlags = [ + # Defaults to not building shared libs on Linux. + (lib.cmakeBool "BUILD_SHARED_LIBS" (!stdenv.hostPlatform.isStatic)) + ]; + + preConfigure = '' + appendToVar cmakeFlags -DCMAKE_Swift_COMPILER_TARGET=${stdenv.hostPlatform.swift.triple} + appendToVar cmakeFlags -DCMAKE_Swift_FLAGS=-module-cache-path\ "$NIX_BUILD_TOP/module-cache" + ''; + + nativeBuildInputs = [ + cmake + ninja + swift-minimal + ]; + + postInstall = '' + moveToOutput lib/swift "''${!outputDev}" + moveToOutput lib/swift_static "''${!outputDev}" + + # Install CMake config file for the Swift Collections library. + mkdir -p "''${!outputDev}/lib/cmake/SwiftCollections" + substitute ${./files/SwiftCollectionsConfig.cmake} "''${!outputDev}/lib/cmake/SwiftCollections/SwiftCollectionsConfig.cmake" \ + --replace-fail '@buildType@' ${if stdenv.hostPlatform.isStatic then "STATIC" else "SHARED"} \ + --replace-fail '@include@' "''${!outputDev}" \ + --replace-fail '@lib@' "''${!outputLib}" \ + --replace-fail '@swiftPlatform@' ${stdenv.hostPlatform.swift.platform} + ''; + + __structuredAttrs = true; + + passthru.updateScript = gitUpdater { }; + + meta = { + homepage = "https://github.com/apple/swift-collections"; + description = "Commonly used data structures for Swift"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-foundation/files/FoundationConfig.cmake b/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-foundation/files/FoundationConfig.cmake new file mode 100644 index 000000000000..159354b71c3e --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-foundation/files/FoundationConfig.cmake @@ -0,0 +1,25 @@ +if (NOT TARGET _FoundationICU) + find_package(_FoundationICU) +endif () + +if (NOT TARGET SwiftCollections::_RopeModule) + find_package(SwiftCollections) +endif () + +if (NOT TARGET FoundationEssentials) + find_package(SwiftFoundation) +endif () + +add_library(Foundation @buildType@ IMPORTED) +set_target_properties(Foundation PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}Foundation${CMAKE_@buildType@_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@dev@/lib/swift;@dev@/lib/swift/@swiftPlatform@" +) +target_link_libraries(FoundationEssentials INTERFACE + _FoundationICU + FoundationEssentials + FoundationInternationalization + SwiftCollections::_RopeModule + SwiftCollections::InternalCollectionsUtilities + SwiftCollections::OrderedCollections +) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-foundation/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-foundation/package.nix new file mode 100644 index 000000000000..3e544bb2cbcd --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-foundation/package.nix @@ -0,0 +1,118 @@ +{ + lib, + cmake, + curl, + fetchFromGitHub, + libxml2, + ninja, + stdenv, + swift-corelibs-libdispatch, + swift-foundation, + swift-foundation-icu, + swift-minimal, + swift_release, + swift_sources, +}: + +let + doInstallCheck = stdenv.buildPlatform.canExecute stdenv.hostPlatform; +in + +stdenv.mkDerivation (finalAttrs: { + pname = "swift-corelibs-foundation"; + version = swift_release; + + outputs = [ + "out" + "dev" + ]; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-corelibs-foundation"; + tag = "swift-${finalAttrs.version}-RELEASE"; + inherit (swift_sources.swift-corelibs-foundation) hash; + }; + + patches = [ + ./patches/0001-gnu-install-dirs.patch + ./patches/0002-Devendor-SwiftFoundation-and-SwiftFoundationICU.patch + ]; + + strictDeps = true; + + nativeBuildInputs = [ + cmake + ninja + swift-minimal + ]; + + buildInputs = [ + curl + libxml2 + swift-corelibs-libdispatch + swift-foundation + swift-foundation-icu + ]; + + postInstall = '' + moveToOutput lib/swift "''${!outputDev}" + + # Install CMake config file for the Swift Collections library. + mkdir -p "''${!outputDev}/lib/cmake/Foundation" + substitute ${./files/FoundationConfig.cmake} "''${!outputDev}/lib/cmake/Foundation/FoundationConfig.cmake" \ + --replace-fail '@buildType@' ${if stdenv.hostPlatform.isStatic then "STATIC" else "SHARED"} \ + --replace-fail '@dev@' "''${!outputDev}" \ + --replace-fail '@lib@' "''${!outputLib}" \ + --replace-fail '@swiftPlatform@' ${stdenv.hostPlatform.swift.platform} + '' + + lib.optionalString (stdenv.hostPlatform.isElf && !stdenv.hostPlatform.isStatic) '' + # Make sure swift-corelibs-foundation has an rpath pointing at the stdlib (since it is installed outside of it) + # as well as to Dispatch and Swift Foundation. Also do the same for `plutil`. + for f in "$out/bin/plutil" "$out/lib/libFoundation${stdenv.hostPlatform.extensions.sharedLibrary}"; do + patchelf --add-rpath ${ + lib.escapeShellArg ( + lib.makeSearchPathOutput "out" "lib/swift/${stdenv.hostPlatform.swift.platform}" [ swift-minimal ] + ) + } "$f" + patchelf --add-rpath ${ + lib.escapeShellArg ( + lib.makeLibraryPath [ + # Need both for the Swift and non-Swift shared libraries + swift-corelibs-libdispatch + (swift-corelibs-libdispatch.override { useSwift = false; }) + swift-foundation + ] + ) + } "$f" + done + patchelf --add-rpath ${ + lib.escapeShellArg (lib.makeLibraryPath [ curl ]) + } "$out/lib/libFoundationNetworking${stdenv.hostPlatform.extensions.sharedLibrary}" + patchelf --add-rpath ${ + lib.escapeShellArg (lib.makeLibraryPath [ libxml2 ]) + } "$out/lib/libFoundationXML${stdenv.hostPlatform.extensions.sharedLibrary}" + ''; + + inherit doInstallCheck; + + # Can’t use `versionCheckHook` because `plutil` does not have an option to print the version. + installCheckPhase = '' + runHook preInstallCheck + + "''${!outputBin}/bin/${finalAttrs.meta.mainProgram}" -help | grep "plutil:" + + runHook postInstallCheck + ''; + + __structuredAttrs = true; + + meta = { + description = "Core utilities, internationalization, and OS independence for Swift"; + mainProgram = "plutil"; + homepage = "https://github.com/swiftlang/swift-corelibs-foundation"; + platforms = lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-foundation/patches/0001-gnu-install-dirs.patch b/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-foundation/patches/0001-gnu-install-dirs.patch new file mode 100644 index 000000000000..f8f0351a201c --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-foundation/patches/0001-gnu-install-dirs.patch @@ -0,0 +1,40 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 4 Jul 2026 10:55:52 -0400 +Subject: [PATCH 1/2] gnu-install-dirs + +--- + cmake/modules/FoundationSwiftSupport.cmake | 8 ++++---- + 1 file changed, 4 insertions(+), 4 deletions(-) + +diff --git a/cmake/modules/FoundationSwiftSupport.cmake b/cmake/modules/FoundationSwiftSupport.cmake +index 85868392..706f4b19 100644 +--- a/cmake/modules/FoundationSwiftSupport.cmake ++++ b/cmake/modules/FoundationSwiftSupport.cmake +@@ -23,8 +23,8 @@ function(_foundation_install_target module) + endif() + + install(TARGETS ${module} +- ARCHIVE DESTINATION lib/${swift}/${swift_os} +- LIBRARY DESTINATION lib/${swift}/${swift_os} ++ ARCHIVE DESTINATION ${CMAKE_INSTALL_LIBDIR} ++ LIBRARY DESTINATION ${CMAKE_INSTALL_LIBDIR} + RUNTIME DESTINATION ${CMAKE_INSTALL_BINDIR}) + if(type STREQUAL EXECUTABLE) + return() +@@ -36,10 +36,10 @@ function(_foundation_install_target module) + endif() + + install(FILES $/${module_name}.swiftdoc +- DESTINATION lib/${swift}/${swift_os}/${module_name}.swiftmodule ++ DESTINATION ${CMAKE_INSTALL_INCLUDEDIR}/../lib/${swift}/${swift_os}/${module_name}.swiftmodule + RENAME ${SwiftFoundation_MODULE_TRIPLE}.swiftdoc) + install(FILES $/${module_name}.swiftmodule +- DESTINATION lib/${swift}/${swift_os}/${module_name}.swiftmodule ++ DESTINATION ${CMAKE_INSTALL_INCLUDEDIR}/../lib/${swift}/${swift_os}/${module_name}.swiftmodule + RENAME ${SwiftFoundation_MODULE_TRIPLE}.swiftmodule) + + endfunction() +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-foundation/patches/0002-Devendor-SwiftFoundation-and-SwiftFoundationICU.patch b/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-foundation/patches/0002-Devendor-SwiftFoundation-and-SwiftFoundationICU.patch new file mode 100644 index 000000000000..668f48fbe4da --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-foundation/patches/0002-Devendor-SwiftFoundation-and-SwiftFoundationICU.patch @@ -0,0 +1,45 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 4 Jul 2026 10:13:45 -0400 +Subject: [PATCH 2/2] Devendor SwiftFoundation and SwiftFoundationICU + +--- + CMakeLists.txt | 22 ++-------------------- + 1 file changed, 2 insertions(+), 20 deletions(-) + +diff --git a/CMakeLists.txt b/CMakeLists.txt +index 08f69905..540afe42 100644 +--- a/CMakeLists.txt ++++ b/CMakeLists.txt +@@ -81,26 +81,8 @@ option(FOUNDATION_BUILD_NETWORKING "build FoundationNetworking" + + set(CMAKE_POSITION_INDEPENDENT_CODE YES) + +-# Fetchable dependencies +-include(FetchContent) +-if (_SwiftFoundationICU_SourceDIR) +- FetchContent_Declare(SwiftFoundationICU +- SOURCE_DIR ${_SwiftFoundationICU_SourceDIR}) +-else() +- FetchContent_Declare(SwiftFoundationICU +- GIT_REPOSITORY https://github.com/apple/swift-foundation-icu.git +- GIT_TAG 0.0.9) +-endif() +- +-if (_SwiftFoundation_SourceDIR) +- FetchContent_Declare(SwiftFoundation +- SOURCE_DIR ${_SwiftFoundation_SourceDIR}) +-else() +- FetchContent_Declare(SwiftFoundation +- GIT_REPOSITORY https://github.com/apple/swift-foundation.git +- GIT_TAG main) +-endif() +-FetchContent_MakeAvailable(SwiftFoundationICU SwiftFoundation) ++find_package(SwiftFoundation) ++find_package(SwiftFoundationICU) + + include(CheckLinkerFlag) + include(CheckSymbolExists) +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-libdispatch/files/dispatchConfig.cmake b/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-libdispatch/files/dispatchConfig.cmake new file mode 100644 index 000000000000..514017631268 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-libdispatch/files/dispatchConfig.cmake @@ -0,0 +1,20 @@ +add_library(BlocksRuntime @buildType@ IMPORTED) +set_target_properties(BlocksRuntime PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}BlocksRuntime${CMAKE_@buildType@_LIBRARY_SUFFIX}" +) + +add_library(dispatch @buildType@ IMPORTED) +set_target_properties(dispatch PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}dispatch${CMAKE_@buildType@_LIBRARY_SUFFIX}" +) + +set_target_properties(dispatch PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES "@dev@/include" + INTERFACE_LINK_LIBRARIES "BlocksRuntime" +) + +add_library(swiftDispatch @buildType@ IMPORTED) +set_target_properties(swiftDispatch PROPERTIES + IMPORTED_LOCATION "@out-swift@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}swiftDispatch${CMAKE_@buildType@_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@dev-swift@/lib/swift;@dev-swift@/lib/swift/@swiftPlatform@" +) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-libdispatch/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-libdispatch/package.nix new file mode 100644 index 000000000000..e95f74521218 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-libdispatch/package.nix @@ -0,0 +1,128 @@ +{ + lib, + cmake, + fetchFromGitHub, + fetchpatch2, + lld, + ninja, + stdenv, + swift-corelibs-libdispatch, + swift-minimal, + swift_release, + swift_sources, + useSwift ? true, # Where to build the Swift overlay and swiftDispatch shared library. +}: + +let + swift-corelibs-libdispatch-no-overlay = swift-corelibs-libdispatch.override { useSwift = false; }; + + swift-corelibs-libdispatch-no-overlay-lib = + if useSwift then + lib.escapeShellArg (lib.getLib swift-corelibs-libdispatch-no-overlay) + else + placeholder "out"; + + swift-corelibs-libdispatch-no-overlay-dev = + if useSwift then + lib.escapeShellArg (lib.getDev swift-corelibs-libdispatch-no-overlay) + else + placeholder "dev"; +in + +stdenv.mkDerivation (finalAttrs: { + pname = "swift-corelibs-libdispatch${lib.optionalString useSwift "-swift-overlay"}"; + version = swift_release; + + outputs = [ + "out" + "dev" + "man" + ]; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-corelibs-libdispatch"; + tag = "swift-${finalAttrs.version}-RELEASE"; + inherit (swift_sources.swift-corelibs-libdispatch) hash; + }; + + patches = [ + ./patches/0001-gnu-install-dirs.patch + # Nixpkgs includes `sys/cdefs.h` from Alpine, which breaks the build due to `-Werror`. + ./patches/0002-Don-t-include-sys-cdefs-on-Musl.patch + # Fixes `implicit conversion changes signedness` error. + (fetchpatch2 { + url = "https://github.com/swiftlang/swift-corelibs-libdispatch/commit/38872e2d44d66d2fb94186988509defc734888a5.patch?full_index=1"; + hash = "sha256-BXTv79ej93CBrHtEzHDu+3WkIfzEctwyqBoPkNQQkAA="; + }) + ]; + + strictDeps = true; + + cmakeFlags = [ + # The Swift overlay is built separately using the no-overlay derivation as a base. + (lib.cmakeBool "ENABLE_SWIFT" useSwift) + ] + ++ lib.optionals stdenv.hostPlatform.isMusl [ + # Musl requires _GNU_SOURCE or the getprogname shim fails to build. + (lib.cmakeFeature "CMAKE_C_FLAGS" "-D_GNU_SOURCE=1") + ] + ++ lib.optionals stdenv.hostPlatform.isWindows [ + # Linking for Windows requires using LLD. + (lib.cmakeFeature "CMAKE_LINKER_TYPE" "LLD") + ]; + + nativeBuildInputs = [ + cmake + ninja + ] + ++ lib.optionals useSwift [ swift-minimal ] + ++ lib.optionals stdenv.hostPlatform.isWindows [ lld ]; + + postInstall = '' + libExt=${stdenv.hostPlatform.extensions.library} + + # Provide a CMake module. This is primarily used to glue together parts of + # the Swift toolchain. Modifying the CMake config to do this for us is + # otherwise more trouble. + mkdir -p "''${!outputDev}/lib/cmake/dispatch" + substitute ${./files/dispatchConfig.cmake} "''${!outputDev}/lib/cmake/dispatch/dispatchConfig.cmake" \ + --replace-fail '@buildType@' ${if stdenv.hostPlatform.isStatic then "STATIC" else "SHARED"} \ + --replace-fail '@swiftPlatform@' ${stdenv.hostPlatform.swift.platform} \ + --replace-fail '@lib@' ${swift-corelibs-libdispatch-no-overlay-lib} \ + --replace-fail '@dev@' ${swift-corelibs-libdispatch-no-overlay-dev} \ + --replace-fail '@out-swift@' "$out" \ + --replace-fail '@dev-swift@' "''${!outputDev}" + '' + + lib.optionalString useSwift ( + '' + mkdir -p "$dev/nix-support" "$man" + + moveToOutput lib/swift "''${!outputDev}" + + # Rely on `propagated-build-inputs` to propagate the non-Swift shared libraries, + # so with or without overlay uses the same ones. + rm "''${!outputLib}/lib/libdispatch$libExt" "''${!outputLib}/lib/libBlocksRuntime$libExt" + + ln -s ${lib.escapeShellArg (lib.getMan swift-corelibs-libdispatch-no-overlay)}/* "$man" + + echo -n ${swift-corelibs-libdispatch-no-overlay-dev} >> "$dev/nix-support/propagated-build-inputs" + '' + # Clean up the rpaths to reference the non-overlay shared libraries. + + lib.optionalString stdenv.hostPlatform.isElf '' + dylib="''${!outputLib}/lib/libswiftDispatch${stdenv.hostPlatform.extensions.sharedLibrary}" + patchelf --add-rpath ${swift-corelibs-libdispatch-no-overlay-lib}/lib "$dylib" + '' + ); + + __structuredAttrs = true; + + meta = { + description = "Grand Central Dispatch"; + homepage = "https://github.com/swiftlang/swift-corelibs-libdispatch"; + platforms = lib.platforms.freebsd ++ lib.platforms.linux ++ lib.platforms.windows; + license = lib.licenses.asl20; + maintainers = with lib.maintainers; [ cmm ]; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-libdispatch/patches/0001-gnu-install-dirs.patch b/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-libdispatch/patches/0001-gnu-install-dirs.patch new file mode 100644 index 000000000000..c6abc42dc584 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-libdispatch/patches/0001-gnu-install-dirs.patch @@ -0,0 +1,60 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 4 Jul 2026 15:19:17 -0400 +Subject: [PATCH 1/2] gnu-install-dirs + +--- + src/BlocksRuntime/CMakeLists.txt | 4 ++-- + src/CMakeLists.txt | 4 ++-- + src/swift/CMakeLists.txt | 6 +++--- + 3 files changed, 7 insertions(+), 7 deletions(-) + +diff --git a/src/BlocksRuntime/CMakeLists.txt b/src/BlocksRuntime/CMakeLists.txt +index f6fde93..189131e 100644 +--- a/src/BlocksRuntime/CMakeLists.txt ++++ b/src/BlocksRuntime/CMakeLists.txt +@@ -34,6 +34,6 @@ endif() + set_property(GLOBAL APPEND PROPERTY DISPATCH_EXPORTS BlocksRuntime) + install(TARGETS BlocksRuntime + EXPORT dispatchExports +- ARCHIVE DESTINATION ${INSTALL_TARGET_DIR} +- LIBRARY DESTINATION ${INSTALL_TARGET_DIR} ++ ARCHIVE DESTINATION ${CMAKE_INSTALL_LIBDIR} ++ LIBRARY DESTINATION ${CMAKE_INSTALL_LIBDIR} + RUNTIME DESTINATION ${CMAKE_INSTALL_BINDIR}) +diff --git a/src/CMakeLists.txt b/src/CMakeLists.txt +index 846fb39..d09a5aa 100644 +--- a/src/CMakeLists.txt ++++ b/src/CMakeLists.txt +@@ -182,6 +182,6 @@ endif() + set_property(GLOBAL APPEND PROPERTY DISPATCH_EXPORTS dispatch) + install(TARGETS dispatch + EXPORT dispatchExports +- ARCHIVE DESTINATION ${INSTALL_TARGET_DIR} +- LIBRARY DESTINATION ${INSTALL_TARGET_DIR} ++ ARCHIVE DESTINATION ${CMAKE_INSTALL_LIBDIR} ++ LIBRARY DESTINATION ${CMAKE_INSTALL_LIBDIR} + RUNTIME DESTINATION ${CMAKE_INSTALL_BINDIR}) +diff --git a/src/swift/CMakeLists.txt b/src/swift/CMakeLists.txt +index 38bef37..3326735 100644 +--- a/src/swift/CMakeLists.txt ++++ b/src/swift/CMakeLists.txt +@@ -40,12 +40,12 @@ get_swift_host_arch(swift_arch) + install(FILES + ${CMAKE_CURRENT_BINARY_DIR}/swift/Dispatch.swiftmodule + ${CMAKE_CURRENT_BINARY_DIR}/swift/Dispatch.swiftdoc +- DESTINATION ${INSTALL_TARGET_DIR}/${swift_arch}) ++ DESTINATION "${CMAKE_INSTALL_INCLUDEDIR}/../lib/swift$<$>:_static>/${SWIFT_SYSTEM_NAME}") + set_property(GLOBAL APPEND PROPERTY DISPATCH_EXPORTS swiftDispatch) + install(TARGETS swiftDispatch + EXPORT dispatchExports +- ARCHIVE DESTINATION ${INSTALL_TARGET_DIR} +- LIBRARY DESTINATION ${INSTALL_TARGET_DIR} ++ ARCHIVE DESTINATION ${CMAKE_INSTALL_LIBDIR} ++ LIBRARY DESTINATION ${CMAKE_INSTALL_LIBDIR} + RUNTIME DESTINATION ${CMAKE_INSTALL_BINDIR}) + if(HAVE_OBJC AND NOT BUILD_SHARED_LIBS) + set_property(GLOBAL APPEND PROPERTY DISPATCH_EXPORTS DispatchStubs) +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-libdispatch/patches/0002-Don-t-include-sys-cdefs-on-Musl.patch b/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-libdispatch/patches/0002-Don-t-include-sys-cdefs-on-Musl.patch new file mode 100644 index 000000000000..9ef0c0462ba9 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-libdispatch/patches/0002-Don-t-include-sys-cdefs-on-Musl.patch @@ -0,0 +1,32 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Thu, 13 Aug 2026 20:26:09 -0400 +Subject: [PATCH 2/2] =?UTF-8?q?Don=E2=80=99t=20include=20=20on?= + =?UTF-8?q?=20Musl?= +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Nixpkgs includes `sys/cdefs.h` from Alpine, which causes the +`__has_header` check to pass. This would be harmless, but the `#warning` +at the top of `sys/cdefs.h` is turned into an error by `-Werror`. +--- + os/generic_unix_base.h | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/os/generic_unix_base.h b/os/generic_unix_base.h +index b77d2ad..95ffd80 100644 +--- a/os/generic_unix_base.h ++++ b/os/generic_unix_base.h +@@ -25,7 +25,7 @@ + #endif + #include + +-#if __has_include() ++#if __has_include() && (!defined(__linux__) || defined(__GLIBC__)) + #include + #endif + +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-xctest/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-xctest/package.nix new file mode 100644 index 000000000000..7c5310b501cd --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-xctest/package.nix @@ -0,0 +1,88 @@ +{ + lib, + cmake, + fetchFromGitHub, + ninja, + stdenv, + swift-corelibs-foundation, + swift-corelibs-libdispatch, + swift-foundation, + swift-foundation-icu, + swift-minimal, + swift_release, + swift_sources, +}: + +let + # Our minimum deployment target is higher than 10.12, but we can target lower, and some dependants require it. + # This is harmless on non-Darwin. + minTriple = + lib.replaceString stdenv.hostPlatform.darwinMinVersion "10.12" + stdenv.hostPlatform.swift.triple; + + # swift-corelibs-xctest requires Dispatch and Foundation. + swift = swift-minimal.override { inherit swift-corelibs-libdispatch swift-foundation; }; +in + +stdenv.mkDerivation (finalAttrs: { + pname = "swift-corelibs-xctest"; + version = swift_release; + + outputs = [ + "out" + "dev" + ]; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-corelibs-xctest"; + tag = "swift-${finalAttrs.version}-RELEASE"; + inherit (swift_sources.swift-corelibs-xctest) hash; + }; + + strictDeps = true; + + cmakeFlags = [ (lib.cmakeBool "USE_FOUNDATION_FRAMEWORK" true) ]; + + preConfigure = '' + appendToVar cmakeFlags -DCMAKE_Swift_COMPILER_TARGET=${minTriple} + appendToVar cmakeFlags -DCMAKE_Swift_FLAGS=-module-cache-path\ "$NIX_BUILD_TOP/module-cache" + ''; + + nativeBuildInputs = [ + cmake + ninja + swift + ]; + + buildInputs = + # swift-corelibs-xctest expects to find these via CMake on non-Darwin platforms. + lib.optionals (!stdenv.hostPlatform.isDarwin) [ + swift-corelibs-foundation + swift-corelibs-libdispatch + swift-foundation + swift-foundation-icu + ]; + + postInstall = '' + dylib_name=libXCTest${stdenv.hostPlatform.extensions.library} + dylib_path="''${!outputLib}/lib/swift/${stdenv.hostPlatform.swift.platform}" + mv "$dylib_path/$dylib_name" "''${!outputLib}/lib/$dylib_name" + + moveToOutput lib/swift/${stdenv.hostPlatform.swift.platform} "''${!outputDev}" + '' + + lib.optionalString stdenv.hostPlatform.isDarwin '' + install_name_tool "''${!outputLib}/lib/$dylib_name" \ + -change "$dylib_path/$dylib_name" "''${!outputLib}/lib/$dylib_name" + ''; + + __structuredAttrs = true; + + meta = { + description = "Framework for writing unit tests in Swift"; + homepage = "https://github.com/swiftlang/swift-corelibs-xctest"; + platforms = lib.platforms.darwin ++ lib.platforms.linux ++ lib.platforms.windows; + license = lib.licenses.asl20; + maintainers = lib.teams.swift.members; + }; +}) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-crypto/files/SwiftCryptoConfig.cmake b/pkgs/development/compilers/swift/by-name/sw/swift-crypto/files/SwiftCryptoConfig.cmake new file mode 100644 index 000000000000..b7a7b36566f7 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-crypto/files/SwiftCryptoConfig.cmake @@ -0,0 +1,5 @@ +add_library(Crypto @buildType@ IMPORTED) +set_target_properties(Crypto PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}Crypto${CMAKE_@buildType@_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@include@/lib/swift/@swiftPlatform@;@include@/lib/swift_static/@swiftPlatform@" +) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-crypto/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-crypto/package.nix new file mode 100644 index 000000000000..40478e348535 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-crypto/package.nix @@ -0,0 +1,87 @@ +{ + lib, + cmake, + fetchFromGitHub, + gitUpdater, + ninja, + stdenv, + swift, + swift-asn1, +}: + +let + swiftPlatform = stdenv.hostPlatform.swift.platform; +in + +stdenv.mkDerivation (finalAttrs: { + pname = "swift-crypto"; + version = "4.5.1"; + + outputs = [ + "out" + "dev" + ]; + + src = fetchFromGitHub { + owner = "apple"; + repo = "swift-crypto"; + tag = finalAttrs.version; + hash = "sha256-RLZmCrRmu6ZYre+VT4YzxpM8LgM7lLCbcMD/CVPiRTg="; + }; + + patches = [ + # Install _CryptoExtras and CryptoBoringWrapper + ./patches/0001-install-missing-modules.patch + ]; + + postPatch = '' + substituteInPlace CMakeLists.txt \ + --replace-fail '/usr/bin/ar' '$ENV{AR}' \ + --replace-fail '/usr/bin/ranlib' '$ENV{RANLIB}' + + substituteInPlace cmake/modules/SwiftSupport.cmake \ + --replace-fail 'ARCHIVE DESTINATION lib/''${swift}/''${swift_os}' 'ARCHIVE DESTINATION ''${CMAKE_INSTALL_LIBDIR}' \ + --replace-fail 'LIBRARY DESTINATION lib/''${swift}/''${swift_os}' 'LIBRARY DESTINATION ''${CMAKE_INSTALL_LIBDIR}' \ + --replace-fail 'RUNTIME DESTINATION bin' 'RUNTIME DESTINATION ''${CMAKE_INSTALL_BINDIR}' \ + ''; + + strictDeps = true; + + preConfigure = '' + appendToVar cmakeFlags -DCMAKE_Swift_COMPILER_TARGET=${stdenv.hostPlatform.swift.triple} + appendToVar cmakeFlags -DCMAKE_Swift_FLAGS=-module-cache-path\ "$NIX_BUILD_TOP/module-cache" + ''; + + nativeBuildInputs = [ + cmake + ninja + swift + ]; + + buildInputs = [ (lib.getInclude swift-asn1) ]; + + postInstall = '' + moveToOutput lib/swift "''${!outputDev}" + moveToOutput lib/swift_static "''${!outputDev}" + + # Install CMake config file for the Swift Crypto library. + mkdir -p "''${!outputDev}/lib/cmake/SwiftCrypto" + substitute ${./files/SwiftCryptoConfig.cmake} "''${!outputDev}/lib/cmake/SwiftCrypto/SwiftCryptoConfig.cmake" \ + --replace-fail '@buildType@' ${if stdenv.hostPlatform.isStatic then "STATIC" else "SHARED"} \ + --replace-fail '@include@' "''${!outputDev}" \ + --replace-fail '@lib@' "''${!outputLib}" \ + --replace-fail '@swiftPlatform@' ${swiftPlatform} + ''; + + __structuredAttrs = true; + + passthru.updateScript = gitUpdater { }; + + meta = { + homepage = "https://github.com/apple/swift-crypto"; + description = "Open-source implementation of most of CryptoKit for Swift"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-crypto/patches/0001-install-missing-modules.patch b/pkgs/development/compilers/swift/by-name/sw/swift-crypto/patches/0001-install-missing-modules.patch new file mode 100644 index 000000000000..d49beb69853b --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-crypto/patches/0001-install-missing-modules.patch @@ -0,0 +1,64 @@ +From fad5e514f44a546b9f41d68f8a99d1a9beab2066 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Thu, 18 Dec 2025 20:58:24 -0500 +Subject: [PATCH] install-missing-modules + +--- + Sources/CMakeLists.txt | 1 + + Sources/CryptoBoringWrapper/CMakeLists.txt | 1 + + Sources/CryptoExtras/CMakeLists.txt | 1 + + Sources/_CryptoExtras/CMakeLists.txt | 13 +++++++++++++ + 4 files changed, 16 insertions(+) + create mode 100644 Sources/_CryptoExtras/CMakeLists.txt + +diff --git a/Sources/CMakeLists.txt b/Sources/CMakeLists.txt +index 4616a1f..caf7440 100644 +--- a/Sources/CMakeLists.txt ++++ b/Sources/CMakeLists.txt +@@ -19,3 +19,4 @@ add_subdirectory(CXKCPShims) + add_subdirectory(CryptoBoringWrapper) + add_subdirectory(Crypto) + add_subdirectory(CryptoExtras) ++add_subdirectory(_CryptoExtras) +diff --git a/Sources/CryptoBoringWrapper/CMakeLists.txt b/Sources/CryptoBoringWrapper/CMakeLists.txt +index 980f33c..0c852bf 100644 +--- a/Sources/CryptoBoringWrapper/CMakeLists.txt ++++ b/Sources/CryptoBoringWrapper/CMakeLists.txt +@@ -36,4 +36,5 @@ target_compile_options(CryptoBoringWrapper PRIVATE ${SWIFT_CRYPTO_COMPILE_OPTION + set_target_properties(CryptoBoringWrapper PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + ++_install_target(CryptoBoringWrapper) + set_property(GLOBAL APPEND PROPERTY SWIFT_CRYPTO_EXPORTS CryptoBoringWrapper) +diff --git a/Sources/CryptoExtras/CMakeLists.txt b/Sources/CryptoExtras/CMakeLists.txt +index e081070..89ce053 100644 +--- a/Sources/CryptoExtras/CMakeLists.txt ++++ b/Sources/CryptoExtras/CMakeLists.txt +@@ -102,4 +102,5 @@ target_link_options(CryptoExtras PRIVATE + set_target_properties(CryptoExtras PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + ++_install_target(CryptoExtras) + set_property(GLOBAL APPEND PROPERTY SWIFT_CRYPTO_EXPORTS CryptoExtras) +diff --git a/Sources/_CryptoExtras/CMakeLists.txt b/Sources/_CryptoExtras/CMakeLists.txt +new file mode 100644 +index 0000000..5e6c283 +--- /dev/null ++++ b/Sources/_CryptoExtras/CMakeLists.txt +@@ -0,0 +1,13 @@ ++add_library(_CryptoExtras STATIC ++ Exports.swift ++) ++ ++target_link_libraries(_CryptoExtras PUBLIC ++ CryptoExtras) ++ ++ ++set_target_properties(_CryptoExtras PROPERTIES ++ INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) ++ ++_install_target(_CryptoExtras) ++set_property(GLOBAL APPEND PROPERTY SWIFT_CRYPTO_EXPORTS _CryptoExtras) +-- +2.50.1 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-docc-render/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-docc-render/package.nix new file mode 100644 index 000000000000..8448446f8bec --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-docc-render/package.nix @@ -0,0 +1,62 @@ +{ + lib, + buildNpmPackage, + fetchFromGitHub, + fetchNpmDeps, + nodejs_22, + fetchpatch2, + swift_release, + swift_sources, +}: + +# swift-docc-render does not tag releases. Only the built artifacts are tagged. To build this from source: +# 1. Go to https://github.com/swiftlang/swift-docc-render-artifact and check the tagged release for the Swift release; +# 2. Note the parent commit. This will be needed to find the build in Swift’s CI; +# 3. Go to https://ci.swift.org and navigate to the builds for the Swift release being built (e.g., 6.2 for 6.2.4); +# 4. Find the successful build with the same commit for swiftlang/swift-docc-render-artifact as the parent commit for +# the tagged release. You have to check the parent because Jenkins is reporting the current state of the branch; +# 5. The githubweb link is the commit that was built and tagged in swiftlang/swift-docc-render-artifact. + +# For example, for Swift 6.2.4: +# - The parent commit for the pre-built artifact at https://github.com/swiftlang/swift-docc-render-artifact/tree/swift-6.2.4-RELEASE +# is b2bf4e5426851306760607d79b0bf9af2b6f479b. +# - The successful build with that parent commit is https://ci.swift.org/view/Swift%206.2/job/swift-6.2-docc-render-sync/21/. +# - The corresponding commit on GitHub is https://github.com/swiftlang/swift-docc-render/commit/451103e0f055db233467e4e6b67384cf0d4625a0. +# - The `rev` to use in `src` below is 451103e0f055db233467e4e6b67384cf0d4625a0. + +buildNpmPackage (finalAttrs: { + pname = "swift-docc-render"; + version = "${swift_release}-unstable-2025-09-16"; + + # Note! We don’t use the commit from Swift 6.2.4 but a later one that is compatible with Node.js 22. + # Otherwise, it would require Node.js 20, which is no longer supported in Nixpkgs. + # This comment can be dropped after the Swift 6.3 update, which includes this commit. + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-docc-render"; + inherit (swift_sources.swift-docc-render) rev hash; + }; + + nodejs = nodejs_22; + + npmDeps = fetchNpmDeps { + name = "${finalAttrs.pname}-${finalAttrs.version}-npm-deps"; + inherit (finalAttrs) src; + inherit (swift_sources.swift-docc-render.npmDeps) hash; + }; + + installPhase = '' + runHook preInstall + mkdir -p "$out" + cp -rv dist "$out/dist" + runHook postInstall + ''; + + meta = { + description = "Web renderer for Swift DocC documentation"; + homepage = "https://github.com/swiftlang/swift-docc-render"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-docc/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-docc/package.nix new file mode 100644 index 000000000000..d2adb46a9e1f --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-docc/package.nix @@ -0,0 +1,66 @@ +{ + lib, + fetchFromGitHub, + fetchSwiftPMDeps, + stdenv, + swift, + swift-docc-render, + swiftpm, + swift_release, + swift_sources, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "swift-docc"; + version = swift_release; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-docc"; + tag = "swift-${finalAttrs.version}-RELEASE"; + inherit (swift_sources.swift-docc) hash; + }; + + postPatch = + # SignalTests.testTrappingSignal tries to access `/bin/bash`. Replace it with the shell in the stdenv. + '' + substituteInPlace Tests/SwiftDocCUtilitiesTests/SignalTests.swift \ + --replace-fail '/bin/bash' ${lib.escapeShellArg stdenv.shell} + ''; + + strictDeps = true; + + swiftpmDeps = fetchSwiftPMDeps { + inherit (finalAttrs) pname version src; + inherit (swift_sources.swift-docc.swiftpmDeps) hash; + }; + + swiftpmFlags = [ + # Otherwise fails to build with `error: module 'SwiftDocC' was not compiled for testing`. + "-Xswiftc" + "-enable-testing" + ]; + + nativeBuildInputs = [ + swift + swiftpm + ]; + + doCheck = !stdenv.hostPlatform.isDarwin; + + postInstall = '' + mkdir -p "$out/share/docc" + ln -s "${swift-docc-render}/dist" "$out/share/docc/render" + ''; + + __structuredAttrs = true; + + meta = { + description = "Documentation compiler for Swift"; + mainProgram = "docc"; + homepage = "https://github.com/swiftlang/swift-docc"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-driver/files/SwiftDriverConfig.cmake b/pkgs/development/compilers/swift/by-name/sw/swift-driver/files/SwiftDriverConfig.cmake new file mode 100644 index 000000000000..02cc584e3d9e --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-driver/files/SwiftDriverConfig.cmake @@ -0,0 +1,5 @@ +add_library(SwiftDriver @buildType@ IMPORTED) +set_target_properties(SwiftDriver PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}SwiftDriver${CMAKE_@buildType@_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@dev@/lib/swift/@swiftPlatform@" +) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-driver/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-driver/package.nix new file mode 100644 index 000000000000..683e923f374d --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-driver/package.nix @@ -0,0 +1,125 @@ +{ + lib, + callPackage, + cmake, + fetchFromGitHub, + llvm_libtool, + ninja, + stdenv, + swift-argument-parser, + swift-corelibs-libdispatch, + swift-foundation, + swift-llbuild, + swift-minimal, + swift-tools-support-core, + swift_release, + swift_sources, +}: + +let + swiftPlatform = stdenv.hostPlatform.swift.platform; + # Swift Driver requires Dispatch and Foundation. + swift = swift-minimal.override { inherit swift-corelibs-libdispatch swift-foundation; }; +in + +stdenv.mkDerivation (finalAttrs: { + pname = "swift-driver"; + version = swift_release; + + outputs = [ + "out" + "dev" + "lib" + ]; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-driver"; + tag = "swift-${finalAttrs.version}-RELEASE"; + inherit (swift_sources.swift-driver) hash; + }; + + patches = [ + ./patches/0001-gnu-install-dirs.patch + # Adjust the built libraries to match the way SwiftPM would build the Swift Compiler Driver. + ./patches/0002-Match-SwiftPM-products-when-building-with-CMake.patch + # Align Swift Driver’s subcommand lookup behavior with the legacy/C++ frontend. Nixpkgs needs this because it + # builds and installs SwiftPM separately from the rest of the Swift toolchain. Otherwise, `swift build` will fail. + ./patches/0003-Search-PATH-for-subcommands.patch + # The stdlib is located at the top-level `lib` folder in the toolchain in Nixpkgs. Help `swift repl` find it there. + ./patches/0004-Help-the-repl-find-the-stdlib-in-Nixpkgs.patch + ]; + + strictDeps = true; + + preConfigure = '' + appendToVar cmakeFlags -DCMAKE_Swift_COMPILER_TARGET=${stdenv.hostPlatform.swift.triple} + appendToVar cmakeFlags -DCMAKE_Swift_FLAGS=-module-cache-path\ "$NIX_BUILD_TOP/module-cache" + ''; + + nativeBuildInputs = [ + cmake + ninja + swift + ] + ++ lib.optionals stdenv.hostPlatform.isDarwin [ llvm_libtool ]; + + buildInputs = [ + swift-argument-parser + swift-llbuild + swift-tools-support-core + ]; + + env.NIX_LDFLAGS = lib.optionalString stdenv.hostPlatform.isDarwin "-headerpad_max_install_names"; + + postInstall = '' + mkdir -p "''${!outputDev}/lib/swift/${swiftPlatform}" "''${!outputLib}/lib" + + # Install the SwiftOptions static library (needed by Swift Build). + cp -v lib/libSwiftOptions.a "''${!outputLib}/lib" + + # Install the swiftmodule. + cp -v swift/*.swiftmodule "''${!outputDev}/lib/swift/${swiftPlatform}" + + # Install CMake config file for the Swift Compiler Driver library. + mkdir -p "''${!outputDev}/lib/cmake/SwiftDriver" + substitute ${./files/SwiftDriverConfig.cmake} "''${!outputDev}/lib/cmake/SwiftDriver/SwiftDriverConfig.cmake" \ + --replace-fail '@buildType@' ${if stdenv.hostPlatform.isStatic then "STATIC" else "SHARED"} \ + --replace-fail '@dev@' "''${!outputDev}" \ + --replace-fail '@lib@' "''${!outputLib}" \ + --replace-fail '@swiftPlatform@' ${swiftPlatform} + '' + # For some reason, these rpaths get dropped during installation phase on Linux. + + lib.optionalString stdenv.hostPlatform.isLinux '' + for f in "$out/bin/"* "$lib/lib/"*; do + if isELF "$f"; then + patchelf --add-rpath ${ + lib.escapeShellArg ( + lib.makeLibraryPath [ + swift-argument-parser + swift-tools-support-core + swift-llbuild + ] + ) + } "$f" + patchelf --force-rpath "$f" # Otherwise, libswiftSynchronization.so won’t be found. + fi + done + ''; + + __structuredAttrs = true; + + passthru.tests = lib.packagesFromDirectoryRecursive { + inherit callPackage; + directory = ./tests; + }; + + meta = { + mainProgram = "swift-driver"; + homepage = "https://github.com/swiftlang/swift-driver"; + description = "Swift compiler driver written in Swift"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-driver/patches/0001-gnu-install-dirs.patch b/pkgs/development/compilers/swift/by-name/sw/swift-driver/patches/0001-gnu-install-dirs.patch new file mode 100644 index 000000000000..c9dc0c73c8ac --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-driver/patches/0001-gnu-install-dirs.patch @@ -0,0 +1,56 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Mon, 7 Sep 2026 19:24:07 -0400 +Subject: [PATCH 1/4] gnu-install-dirs + +--- + Sources/SwiftDriver/CMakeLists.txt | 6 +++--- + Sources/SwiftDriverExecution/CMakeLists.txt | 6 +++--- + Sources/SwiftOptions/CMakeLists.txt | 6 +++--- + 3 files changed, 9 insertions(+), 9 deletions(-) + +diff --git a/Sources/SwiftDriver/CMakeLists.txt b/Sources/SwiftDriver/CMakeLists.txt +index d6594845..fb30f2bf 100644 +--- a/Sources/SwiftDriver/CMakeLists.txt ++++ b/Sources/SwiftDriver/CMakeLists.txt +@@ -140,6 +140,6 @@ set_target_properties(SwiftDriver PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + + install(TARGETS SwiftDriver +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/SwiftDriverExecution/CMakeLists.txt b/Sources/SwiftDriverExecution/CMakeLists.txt +index c42a4dec..91c9bc12 100644 +--- a/Sources/SwiftDriverExecution/CMakeLists.txt ++++ b/Sources/SwiftDriverExecution/CMakeLists.txt +@@ -26,6 +26,6 @@ set_target_properties(SwiftDriverExecution PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + + install(TARGETS SwiftDriverExecution +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/SwiftOptions/CMakeLists.txt b/Sources/SwiftOptions/CMakeLists.txt +index c6262682..d4dbbcc3 100644 +--- a/Sources/SwiftOptions/CMakeLists.txt ++++ b/Sources/SwiftOptions/CMakeLists.txt +@@ -25,6 +25,6 @@ set_target_properties(SwiftOptions PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + + install(TARGETS SwiftOptions +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-driver/patches/0002-Match-SwiftPM-products-when-building-with-CMake.patch b/pkgs/development/compilers/swift/by-name/sw/swift-driver/patches/0002-Match-SwiftPM-products-when-building-with-CMake.patch new file mode 100644 index 000000000000..5260a2d00025 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-driver/patches/0002-Match-SwiftPM-products-when-building-with-CMake.patch @@ -0,0 +1,59 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Mon, 7 Sep 2026 19:24:08 -0400 +Subject: [PATCH 2/4] Match SwiftPM products when building with CMake + +Adjust the built libraries to match the way SwiftPM would build the +Swift Compiler Driver. +--- + Sources/SwiftDriverExecution/CMakeLists.txt | 7 +------ + Sources/SwiftOptions/CMakeLists.txt | 7 +------ + 2 files changed, 2 insertions(+), 12 deletions(-) + +diff --git a/Sources/SwiftDriverExecution/CMakeLists.txt b/Sources/SwiftDriverExecution/CMakeLists.txt +index 91c9bc12..17adca61 100644 +--- a/Sources/SwiftDriverExecution/CMakeLists.txt ++++ b/Sources/SwiftDriverExecution/CMakeLists.txt +@@ -6,7 +6,7 @@ + # See http://swift.org/LICENSE.txt for license information + # See http://swift.org/CONTRIBUTORS.txt for Swift project authors + +-add_library(SwiftDriverExecution ++add_library(SwiftDriverExecution STATIC + llbuild.swift + MultiJobExecutor.swift + SwiftDriverExecutor.swift) +@@ -24,8 +24,3 @@ set_property(GLOBAL APPEND PROPERTY SWIFTDRIVER_EXPORTS SwiftDriverExecution) + # NOTE: workaround for CMake not setting up include flags yet + set_target_properties(SwiftDriverExecution PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) +- +-install(TARGETS SwiftDriverExecution +- ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" +- LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" +- RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/SwiftOptions/CMakeLists.txt b/Sources/SwiftOptions/CMakeLists.txt +index d4dbbcc3..4dea39d6 100644 +--- a/Sources/SwiftOptions/CMakeLists.txt ++++ b/Sources/SwiftOptions/CMakeLists.txt +@@ -6,7 +6,7 @@ + # See http://swift.org/LICENSE.txt for license information + # See http://swift.org/CONTRIBUTORS.txt for Swift project authors + +-add_library(SwiftOptions ++add_library(SwiftOptions STATIC + DriverKind.swift + Option.swift + OptionTable.swift +@@ -23,8 +23,3 @@ set_property(GLOBAL APPEND PROPERTY SWIFTDRIVER_EXPORTS SwiftOptions) + # NOTE: workaround for CMake not setting up include flags yet + set_target_properties(SwiftOptions PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) +- +-install(TARGETS SwiftOptions +- ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" +- LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" +- RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-driver/patches/0003-Search-PATH-for-subcommands.patch b/pkgs/development/compilers/swift/by-name/sw/swift-driver/patches/0003-Search-PATH-for-subcommands.patch new file mode 100644 index 000000000000..d2abcc88a979 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-driver/patches/0003-Search-PATH-for-subcommands.patch @@ -0,0 +1,40 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Mon, 7 Sep 2026 19:24:08 -0400 +Subject: [PATCH 3/4] Search PATH for subcommands +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +This aligns Swift Driver with the legacy/C++ frontend’s behavior when +searching for subcommands. +--- + Sources/swift-driver/main.swift | 9 +++------ + 1 file changed, 3 insertions(+), 6 deletions(-) + +diff --git a/Sources/swift-driver/main.swift b/Sources/swift-driver/main.swift +index d34ee811..ea3f5607 100644 +--- a/Sources/swift-driver/main.swift ++++ b/Sources/swift-driver/main.swift +@@ -120,15 +120,12 @@ do { + if case .subcommand(let subcommand) = mode { + // We are running as a subcommand, try to find the subcommand adjacent to the executable we are running as. + // If we didn't find the tool there, let the OS search for it. +- let subcommandPath: AbsolutePath? +- if let executablePath = Process.findExecutable(CommandLine.arguments[0]) { ++ let executablePath = try Process.findExecutable(ProcessInfo.processInfo.arguments[0]).map { + // Attempt to resolve the executable symlink in order to be able to + // resolve compiler-adjacent library locations. +- subcommandPath = try TSCBasic.resolveSymlinks(executablePath).parentDirectory.appending(component: subcommand) +- } else { +- subcommandPath = Process.findExecutable(subcommand) ++ try TSCBasic.resolveSymlinks($0).parentDirectory + } +- ++ let subcommandPath = Process.findExecutable(subcommand, workingDirectory: executablePath) + guard let subcommandPath = subcommandPath, + localFileSystem.exists(subcommandPath) else { + throw Driver.Error.unknownOrMissingSubcommand(subcommand, nil) +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-driver/patches/0004-Help-the-repl-find-the-stdlib-in-Nixpkgs.patch b/pkgs/development/compilers/swift/by-name/sw/swift-driver/patches/0004-Help-the-repl-find-the-stdlib-in-Nixpkgs.patch new file mode 100644 index 000000000000..eab86d85e61d --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-driver/patches/0004-Help-the-repl-find-the-stdlib-in-Nixpkgs.patch @@ -0,0 +1,30 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Mon, 7 Sep 2026 19:24:08 -0400 +Subject: [PATCH 4/4] Help the repl find the stdlib in Nixpkgs + +The stdlib is located at `lib` instead of `lib/swift/`, but +`swift repl` only searches the latter for it. +--- + Sources/SwiftDriver/Jobs/ReplJob.swift | 5 +++++ + 1 file changed, 5 insertions(+) + +diff --git a/Sources/SwiftDriver/Jobs/ReplJob.swift b/Sources/SwiftDriver/Jobs/ReplJob.swift +index e7ff7999..d3f75ff2 100644 +--- a/Sources/SwiftDriver/Jobs/ReplJob.swift ++++ b/Sources/SwiftDriver/Jobs/ReplJob.swift +@@ -25,6 +25,11 @@ extension Driver { + ) + try commandLine.appendAll(.framework, .L, from: &parsedOptions) + ++ // Nixpkgs puts Swift libraries in `lib` instead of `lib/swift/`. Help `swift repl` find the stdlib there. ++ let toolchainPath = try toolchain.resolvedTool(.swiftCompiler).path.parentDirectory.parentDirectory ++ let libPath = toolchainPath.appending(component: "lib") ++ commandLine.append(contentsOf: [.flag("-L"), .path(.absolute(libPath))]) ++ + // Squash important frontend options into a single argument for LLDB. + let lldbCommandLine: [Job.ArgTemplate] = [.squashedArgumentList(option: "--repl=", args: commandLine)] + return Job( +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-driver/tests/not-in-toolchain/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-driver/tests/not-in-toolchain/package.nix new file mode 100644 index 000000000000..8c90fc510197 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-driver/tests/not-in-toolchain/package.nix @@ -0,0 +1,18 @@ +{ + runCommand, + swift, + swiftpm, + swift_release, +}: + +runCommand "swift-driver-test-not-in-toolchain" + { + nativeBuildInputs = [ + swift + swiftpm + ]; + } + '' + swift package --version | grep "Swift Package Manager - Swift ${swift_release}" + touch "$out" + '' diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-driver/tests/swift-not-on-path/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-driver/tests/swift-not-on-path/package.nix new file mode 100644 index 000000000000..bebce0932044 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-driver/tests/swift-not-on-path/package.nix @@ -0,0 +1,10 @@ +{ + lib, + runCommand, + swift, +}: + +runCommand "swift-driver-test-swift-not-on-path" { } '' + PATH= ${lib.getExe swift} help --help | grep "USAGE: swift-help" + touch "$out" +'' diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-format/Package.resolved b/pkgs/development/compilers/swift/by-name/sw/swift-format/Package.resolved new file mode 100644 index 000000000000..94c7fd80deef --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-format/Package.resolved @@ -0,0 +1,41 @@ +{ + "pins" : [ + { + "identity" : "swift-argument-parser", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-argument-parser.git", + "state" : { + "revision" : "6a52f3251125d74daf04fcbd5e6f08a75d074382", + "version" : "1.8.2" + } + }, + { + "identity" : "swift-cmark", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-cmark.git", + "state" : { + "revision" : "924936d0427cb25a61169739a7660230bffa6ea6", + "version" : "0.8.0" + } + }, + { + "identity" : "swift-markdown", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-markdown.git", + "state" : { + "revision" : "3c6f9523da3a1ec2fd829673e472d95b8097a3b8", + "version" : "0.8.0" + } + }, + { + "identity" : "swift-syntax", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-syntax.git", + "state" : { + "branch" : "release/6.2", + "revision" : "5a87516fc3dddbd23cb76358eb489915ee86b444" + } + } + ], + "version" : 2 +} diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-format/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-format/package.nix new file mode 100644 index 000000000000..09d6b8c80e97 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-format/package.nix @@ -0,0 +1,52 @@ +{ + lib, + fetchFromGitHub, + fetchSwiftPMDeps, + stdenv, + swift, + swiftpm, + swift_release, + swift_sources, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "swift-format"; + version = swift_release; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-format"; + tag = "swift-${finalAttrs.version}-RELEASE"; + inherit (swift_sources.swift-format) hash; + }; + + strictDeps = true; + + swiftpmDeps = fetchSwiftPMDeps { + inherit (finalAttrs) pname version src; + inherit (swift_sources.swift-format.swiftpmDeps) hash; + + # Upstream doesn’t provide `Package.resolved`. + postPatch = '' + ln -s ${./Package.resolved} Package.resolved + ''; + }; + + nativeBuildInputs = [ + swift + swiftpm + ]; + + doCheck = !stdenv.hostPlatform.isDarwin; + + __structuredAttrs = true; + + meta = { + mainProgram = "swift-format"; + homepage = "https://github.com/swiftlang/swift-format"; + description = "Swift code formatter"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-foundation-icu/files/SwiftFoundationICUConfig.cmake b/pkgs/development/compilers/swift/by-name/sw/swift-foundation-icu/files/SwiftFoundationICUConfig.cmake new file mode 100644 index 000000000000..83eef9ba0337 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-foundation-icu/files/SwiftFoundationICUConfig.cmake @@ -0,0 +1,5 @@ +add_library(_FoundationICU @buildType@ IMPORTED) +set_target_properties(_FoundationICU PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}icucore${CMAKE_@buildType@_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@dev@/lib/swift" +) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-foundation-icu/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-foundation-icu/package.nix new file mode 100644 index 000000000000..5296a0e473f9 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-foundation-icu/package.nix @@ -0,0 +1,54 @@ +{ + lib, + fetchFromGitHub, + stdenvNoCC, + darwin, + swift_release, + swift_sources, +}: + +stdenvNoCC.mkDerivation { + pname = "swift-foundation-icu"; + version = lib.getVersion darwin.ICU; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-foundation-icu"; + tag = "swift-${swift_release}-RELEASE"; + inherit (swift_sources.swift-foundation-icu) hash; + }; + + propagatedBuildInputs = [ (lib.getLib darwin.ICU) ]; + + buildCommand = '' + runPhase unpackPhase + + # Provide a CMake module. This is primarily used to glue together parts of the Swift toolchain. + # Upstream provides a build that does this for us, but we want to reuse our existing ICU build. + mkdir -p "''${!outputDev}/lib/cmake/SwiftFoundationICU" + export dylibExt="${stdenvNoCC.hostPlatform.extensions.sharedLibrary}" + + substitute ${./files/SwiftFoundationICUConfig.cmake} "''${!outputDev}/lib/cmake/SwiftFoundationICU/SwiftFoundationICUConfig.cmake" \ + --replace-fail '@buildType@' ${if stdenvNoCC.hostPlatform.isStatic then "STATIC" else "SHARED"} \ + --replace-fail '@lib@' ${lib.escapeShellArg (lib.getLib darwin.ICU)} \ + --replace-fail '@dev@' "''${!outputDev}" + + # Copy headers to `_foundation_unicode`. The translation is needed to make sure they’re found in the tooclhain. + mkdir -p "$out/lib/swift/_foundation_unicode" + for header in ${lib.escapeShellArg (lib.getInclude darwin.ICU)}/include/unicode/*; do + # Not all files include other files, so these can’t be `--replace-fail`. Use both `"` and `<` to be thorough. + substitute "$header" "$out/lib/swift/_foundation_unicode/$(basename "$header")" \ + --replace-quiet 'include "unicode/' 'include "_foundation_unicode/' \ + --replace-quiet 'include +Date: Sat, 27 Jun 2026 22:02:03 -0400 +Subject: [PATCH 1/3] gnu-install-dirs + +--- + cmake/modules/SwiftFoundationSwiftSupport.cmake | 8 ++++---- + 1 file changed, 4 insertions(+), 4 deletions(-) + +diff --git a/cmake/modules/SwiftFoundationSwiftSupport.cmake b/cmake/modules/SwiftFoundationSwiftSupport.cmake +index cbdfc2a..9418500 100644 +--- a/cmake/modules/SwiftFoundationSwiftSupport.cmake ++++ b/cmake/modules/SwiftFoundationSwiftSupport.cmake +@@ -21,8 +21,8 @@ function(_swift_foundation_install_target module) + endif() + + install(TARGETS ${module} +- ARCHIVE DESTINATION lib/${swift}/${swift_os} +- LIBRARY DESTINATION lib/${swift}/${swift_os} ++ ARCHIVE DESTINATION ${CMAKE_INSTALL_LIBDIR} ++ LIBRARY DESTINATION ${CMAKE_INSTALL_LIBDIR} + RUNTIME DESTINATION ${CMAKE_INSTALL_BINDIR}) + if(type STREQUAL EXECUTABLE) + return() +@@ -45,10 +45,10 @@ function(_swift_foundation_install_target module) + endif() + + install(FILES $/${module_name}.swiftdoc +- DESTINATION lib/${swift}/${swift_os}/${module_name}.swiftmodule ++ DESTINATION ${CMAKE_INSTALL_INCLUDEDIR}/../lib/${swift}/${swift_os}/${module_name}.swiftmodule + RENAME ${SwiftFoundation_MODULE_TRIPLE}.swiftdoc) + install(FILES $/${module_name}.swiftmodule +- DESTINATION lib/${swift}/${swift_os}/${module_name}.swiftmodule ++ DESTINATION ${CMAKE_INSTALL_INCLUDEDIR}/../lib/${swift}/${swift_os}/${module_name}.swiftmodule + RENAME ${SwiftFoundation_MODULE_TRIPLE}.swiftmodule) + + endfunction() +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-foundation/patches/0002-Devendor-SwiftFoundationICU.patch b/pkgs/development/compilers/swift/by-name/sw/swift-foundation/patches/0002-Devendor-SwiftFoundationICU.patch new file mode 100644 index 000000000000..07bbb665bc3d --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-foundation/patches/0002-Devendor-SwiftFoundationICU.patch @@ -0,0 +1,48 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 27 Jun 2026 20:50:03 -0400 +Subject: [PATCH 2/3] Devendor SwiftFoundationICU +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Swift Collections is not devendored because its module needs to be in +the toolchain, and we don’t want to leak Swift Collections into it. +--- + CMakeLists.txt | 13 ++----------- + 1 file changed, 2 insertions(+), 11 deletions(-) + +diff --git a/CMakeLists.txt b/CMakeLists.txt +index 8b4f45e..f71be26 100644 +--- a/CMakeLists.txt ++++ b/CMakeLists.txt +@@ -67,16 +67,7 @@ set(SwiftFoundation_MACRO "" CACHE STRING "Path to Foundation macro plugin") + + # Make sure our dependencies exists + include(FetchContent) +-if (_SwiftFoundationICU_SourceDIR) +- message(STATUS "_SwiftFoundationICU_SourceDIR provided, using swift-foundation-icu checkout at ${_SwiftFoundationICU_SourceDIR}") +- FetchContent_Declare(SwiftFoundationICU +- SOURCE_DIR ${_SwiftFoundationICU_SourceDIR}) +-else() +- message(STATUS "_SwiftFoundationICU_SourceDIR not provided, checking out local copy of swift-foundation-icu") +- FetchContent_Declare(SwiftFoundationICU +- GIT_REPOSITORY https://github.com/apple/swift-foundation-icu.git +- GIT_TAG release/6.2) +-endif() ++find_package(SwiftFoundationICU) + + if (_SwiftCollections_SourceDIR) + message(STATUS "_SwiftCollections_SourceDIR provided, using swift-foundation-icu checkout at ${_SwiftCollections_SourceDIR}") +@@ -88,7 +79,7 @@ else() + GIT_REPOSITORY https://github.com/apple/swift-collections.git + GIT_TAG 1.1.2) + endif() +-FetchContent_MakeAvailable(SwiftFoundationICU SwiftCollections) ++FetchContent_MakeAvailable(SwiftCollections) + + list(APPEND CMAKE_MODULE_PATH ${SwiftFoundation_SOURCE_DIR}/cmake/modules) + +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-llbuild/files/LLBuildConfig.cmake b/pkgs/development/compilers/swift/by-name/sw/swift-llbuild/files/LLBuildConfig.cmake new file mode 100644 index 000000000000..5b32819de214 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-llbuild/files/LLBuildConfig.cmake @@ -0,0 +1,11 @@ +add_library(llbuild STATIC IMPORTED) +set_target_properties(llbuild PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_STATIC_LIBRARY_PREFIX}llbuild${CMAKE_STATIC_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@dev@/include" +) + +add_library(llbuildSwift @buildType@ IMPORTED) +set_target_properties(llbuildSwift PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}llbuildSwift${CMAKE_@buildType@_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@dev@/include;@dev@/lib/swift/@swiftPlatform@" +) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-llbuild/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-llbuild/package.nix new file mode 100644 index 000000000000..d53f28bb934d --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-llbuild/package.nix @@ -0,0 +1,115 @@ +{ + lib, + cmake, + fetchFromGitHub, + fixDarwinDylibNames, + ncurses, + ninja, + sqlite, + stdenv, + swift-corelibs-libdispatch, + swift-foundation, + swift-minimal, + swift_release, + swift_sources, +}: + +let + swiftPlatform = stdenv.hostPlatform.swift.platform; + # swift-llbuild requires Foundation and Dispatch. + swift = swift-minimal.override { inherit swift-corelibs-libdispatch swift-foundation; }; +in + +# LLBuild is a dependency to both Swift Compiler Driver and SwiftPM. +# It must be built with CMake and use Swift without swift-driver to avoid dependency cycles. +stdenv.mkDerivation (finalAttrs: { + pname = "swift-llbuild"; + version = swift_release; + + outputs = [ + "out" + "dev" + "lib" + ]; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-llbuild"; + tag = "swift-${finalAttrs.version}-RELEASE"; + inherit (swift_sources.swift-llbuild) hash; + }; + + patches = [ ./patches/0001-gnu-install-dirs.patch ]; + + postPatch = '' + # Disable performance tests, which require XCTest.framework. XCTest.framework is not available. + substituteInPlace CMakeLists.txt --replace-fail 'add_subdirectory(perftests)' "" + + # Disable building the framework on Darwin, which we don’t use. + substituteInPlace products/libllbuild/CMakeLists.txt \ + --replace-fail 'if(''${CMAKE_SYSTEM_NAME} MATCHES "Darwin")' "if(FALSE)" + + # Use ncurses instead of curses + grep -rl 'curses)' -Z | while IFS= read -d "" file; do + substituteInPlace "$file" --replace-fail 'curses)' 'ncurses)' + done + ''; + + strictDeps = true; + + cmakeFlags = [ + # Defaults to not building shared libs. + (lib.cmakeBool "BUILD_SHARED_LIBS" (!stdenv.hostPlatform.isStatic)) + # Swift bindings are needed to build swift-driver. + (lib.cmakeFeature "LLBUILD_SUPPORT_BINDINGS" "Swift") + ] + ++ lib.optionals stdenv.hostPlatform.isDarwin [ + # Defaults to the `buildPlatform` architecture if this is not set. + (lib.cmakeFeature "CMAKE_OSX_ARCHITECTURES" stdenv.hostPlatform.darwinArch) + ]; + + preConfigure = '' + appendToVar cmakeFlags -DCMAKE_Swift_COMPILER_TARGET=${stdenv.hostPlatform.swift.triple} + appendToVar cmakeFlags -DCMAKE_Swift_FLAGS=-module-cache-path\ "$NIX_BUILD_TOP/module-cache" + ''; + + nativeBuildInputs = [ + cmake + ninja + swift + ] + ++ lib.optionals stdenv.hostPlatform.isDarwin [ fixDarwinDylibNames ]; + + buildInputs = [ + ncurses + sqlite + ]; + + postInstall = '' + # Install the module map for the `llbuild` module. + mkdir -p "''${!outputDev}/include" + cp -v "$NIX_BUILD_TOP/$sourceRoot/products/libllbuild/include/module.modulemap" "''${!outputDev}/include" + + # Install the swiftmodule (needed to use `llbuildSwift`). + mkdir -p "''${!outputDev}/lib/swift/${swiftPlatform}" + cp -v products/llbuildSwift/llbuildSwift.swiftmodule "''${!outputDev}/lib/swift/${swiftPlatform}" + + # Install CMake config file for llbuild and llbuildSwift. + mkdir -p "''${!outputDev}/lib/cmake/LLBuild" + substitute ${./files/LLBuildConfig.cmake} "''${!outputDev}/lib/cmake/LLBuild/LLBuildConfig.cmake" \ + --replace-fail '@buildType@' ${if stdenv.hostPlatform.isStatic then "STATIC" else "SHARED"} \ + --replace-fail '@dev@' "''${!outputDev}" \ + --replace-fail '@lib@' "''${!outputLib}" \ + --replace-fail '@swiftPlatform@' ${swiftPlatform} + ''; + + __structuredAttrs = true; + + meta = { + homepage = "https://github.com/swiftlang/swift-llbuild"; + description = "Low-level build system used by SwiftPM and Xcode"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-llbuild/patches/0001-gnu-install-dirs.patch b/pkgs/development/compilers/swift/by-name/sw/swift-llbuild/patches/0001-gnu-install-dirs.patch new file mode 100644 index 000000000000..126c7a4ee6bd --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-llbuild/patches/0001-gnu-install-dirs.patch @@ -0,0 +1,61 @@ +From ff5456f94260823fb9c7f1af728123019b31dc3b Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 6 Dec 2025 20:09:51 -0500 +Subject: [PATCH] gnu-install-dirs + +--- + products/libllbuild/CMakeLists.txt | 10 +++++----- + products/llbuildSwift/CMakeLists.txt | 6 +++--- + 2 files changed, 8 insertions(+), 8 deletions(-) + +diff --git a/products/libllbuild/CMakeLists.txt b/products/libllbuild/CMakeLists.txt +index dcf5d40b..30db822d 100644 +--- a/products/libllbuild/CMakeLists.txt ++++ b/products/libllbuild/CMakeLists.txt +@@ -40,21 +40,21 @@ include_directories(BEFORE + ${CMAKE_CURRENT_SOURCE_DIR}/include) + + install(DIRECTORY include/ +- DESTINATION include ++ DESTINATION "${CMAKE_INSTALL_INCLUDEDIR}" + COMPONENT libllbuild + FILES_MATCHING + PATTERN "*.h") + + install(DIRECTORY ${CMAKE_CURRENT_BINARY_DIR}/include/ +- DESTINATION include ++ DESTINATION "${CMAKE_INSTALL_INCLUDEDIR}" + COMPONENT libllbuild + FILES_MATCHING + PATTERN "*.h") + + install(TARGETS libllbuild +- ARCHIVE DESTINATION lib${LLBUILD_LIBDIR_SUFFIX} +- LIBRARY DESTINATION lib${LLBUILD_LIBDIR_SUFFIX} +- RUNTIME DESTINATION bin ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}" + COMPONENT libllbuild) + set_property(GLOBAL APPEND PROPERTY LLBuild_EXPORTS libllbuild) + +diff --git a/products/llbuildSwift/CMakeLists.txt b/products/llbuildSwift/CMakeLists.txt +index fe12e7f3..cd0a4f64 100644 +--- a/products/llbuildSwift/CMakeLists.txt ++++ b/products/llbuildSwift/CMakeLists.txt +@@ -62,9 +62,9 @@ set_target_properties(llbuildSwift PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES "${CMAKE_CURRENT_BINARY_DIR};${PROJECT_SOURCE_DIR}/products/libllbuild/include") + + install(TARGETS llbuildSwift +- ARCHIVE DESTINATION lib/swift/pm/llbuild COMPONENT libllbuildSwift +- LIBRARY DESTINATION lib/swift/pm/llbuild COMPONENT libllbuildSwift +- RUNTIME DESTINATION bin COMPONENT libllbuildSwift) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" COMPONENT libllbuildSwift ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" COMPONENT libllbuildSwift ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}" COMPONENT libllbuildSwift) + set_property(GLOBAL APPEND PROPERTY LLBuild_EXPORTS llbuildSwift) + + # Add install target. +-- +2.51.2 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-syntax/files/SwiftSyntaxConfig.cmake b/pkgs/development/compilers/swift/by-name/sw/swift-syntax/files/SwiftSyntaxConfig.cmake new file mode 100644 index 000000000000..e388c685d3fe --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-syntax/files/SwiftSyntaxConfig.cmake @@ -0,0 +1,24 @@ +set(SyntaxModules + SwiftBasicFormat + SwiftCompilerPlugin + SwiftCompilerPluginMessageHandling + SwiftDiagnostics + SwiftIDEUtils + SwiftIfConfig + SwiftLexicalLookup + SwiftOperators + SwiftParser + SwiftParserDiagnostics + SwiftSyntax + SwiftSyntaxBuilder + SwiftSyntaxMacroExpansion + SwiftSyntaxMacros +) + +foreach(SyntaxModule ${SyntaxModules}) + add_library(SwiftSyntax::${SyntaxModule} @buildType@ IMPORTED) + set_target_properties(SwiftSyntax::${SyntaxModule} PROPERTIES + IMPORTED_LOCATION "@lib@/lib/swift/host/${CMAKE_@buildType@_LIBRARY_PREFIX}${SyntaxModule}${CMAKE_@buildType@_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@dev@/lib/swift/host" + ) +endforeach() diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-syntax/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-syntax/package.nix new file mode 100644 index 000000000000..374874b08c7e --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-syntax/package.nix @@ -0,0 +1,93 @@ +{ + lib, + cmake, + fetchFromGitHub, + ninja, + stdenv, + swift, + swift_release, + swift_sources, + # Using toolchain libraries is intended for building macro library plugins included in the Swift toolchain. + # Everything else should use a non-toolchain build of Swift Syntax. + useToolchainLibraries ? true, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "swift-syntax"; + version = swift_release; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-syntax"; + tag = "swift-${finalAttrs.version}-RELEASE"; + inherit (swift_sources.swift-syntax) hash; + }; + + outputs = [ "out" ] ++ lib.optionals (!useToolchainLibraries) [ "dev" ]; + + patches = [ ./patches/0001-gnu-install-dirs.patch ]; + + strictDeps = true; + + cmakeFlags = lib.optionals (!useToolchainLibraries) [ + # Defaults to not building shared libs. + (lib.cmakeBool "BUILD_SHARED_LIBS" (!stdenv.hostPlatform.isStatic)) + # Build and install the modules. + (lib.cmakeBool "SWIFTSYNTAX_EMIT_MODULE" true) + ]; + + nativeBuildInputs = lib.optionals (!useToolchainLibraries) [ + cmake + ninja + swift + ]; + + dontConfigure = useToolchainLibraries; + + preConfigure = '' + appendToVar cmakeFlags -DCMAKE_Swift_COMPILER_TARGET=${stdenv.hostPlatform.swift.triple} + appendToVar cmakeFlags -DCMAKE_Swift_FLAGS=-module-cache-path\ "$NIX_BUILD_TOP/module-cache" + ''; + + dontBuild = useToolchainLibraries; + + postBuild = '' + # For some reason, this library doesn’t get built even though the install phase expects it to have been. + ninja -j''${NIX_BUILD_CORES:-1} libSwiftCompilerPlugin${stdenv.hostPlatform.extensions.library} + ''; + + postInstall = + # Different paths are needed depending on whether we’re providing CMake config for the Swift compiler’s build + # or for the stand-alone Swift Syntax build. + if useToolchainLibraries then + '' + # Install CMake config file for Swift Syntax in the toolchain. This is needed to build toolchain macros separately + # from the compiler. + mkdir -p "''${!outputDev}/lib/cmake/SwiftSyntax" + substitute ${./files/SwiftSyntaxConfig.cmake} "''${!outputDev}/lib/cmake/SwiftSyntax/SwiftSyntaxConfig.cmake" \ + --replace-fail '@buildType@' ${if stdenv.hostPlatform.isStatic then "STATIC" else "SHARED"} \ + --replace-fail '@dev@' ${lib.escapeShellArg swift.swiftc.out} \ + --replace-fail '@lib@' ${lib.escapeShellArg swift.swiftc.out} + '' + else + '' + moveToOutput lib/swift/host "''${!outputDev}" + + # Install CMake config file for Swift Syntax. + mkdir -p "''${!outputDev}/lib/cmake/SwiftSyntax" + substitute ${./files/SwiftSyntaxConfig.cmake} "''${!outputDev}/lib/cmake/SwiftSyntax/SwiftSyntaxConfig.cmake" \ + --replace-fail '@buildType@' ${if stdenv.hostPlatform.isStatic then "STATIC" else "SHARED"} \ + --replace-fail '@dev@' "''${!outputDev}" \ + --replace-fail '@lib@/lib/swift/host' "''${!outputLib}/lib" + ''; + + __structuredAttrs = true; + + meta = { + homepage = "https://github.com/swiftlang/swift-syntax"; + description = "Swift libraries for parsing Swift source code"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-syntax/patches/0001-gnu-install-dirs.patch b/pkgs/development/compilers/swift/by-name/sw/swift-syntax/patches/0001-gnu-install-dirs.patch new file mode 100644 index 000000000000..a57a008b3315 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-syntax/patches/0001-gnu-install-dirs.patch @@ -0,0 +1,36 @@ +From fa08f0527d1ec76369852dfe8d5d2fd9d3feee8d Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Fri, 26 Dec 2025 11:39:45 -0500 +Subject: [PATCH] gnu-install-dirs + +--- + cmake/modules/AddSwiftHostLibrary.cmake | 8 ++++---- + 1 file changed, 4 insertions(+), 4 deletions(-) + +diff --git a/cmake/modules/AddSwiftHostLibrary.cmake b/cmake/modules/AddSwiftHostLibrary.cmake +index d2f7bc69..4f89a61d 100644 +--- a/cmake/modules/AddSwiftHostLibrary.cmake ++++ b/cmake/modules/AddSwiftHostLibrary.cmake +@@ -184,15 +184,15 @@ function(add_swift_syntax_library name) + # Install this target + install(TARGETS ${target} + EXPORT SwiftSyntaxTargets +- ARCHIVE DESTINATION lib/${SWIFT_HOST_LIBRARIES_SUBDIRECTORY} +- LIBRARY DESTINATION lib/${SWIFT_HOST_LIBRARIES_SUBDIRECTORY} +- RUNTIME DESTINATION bin ++ ARCHIVE DESTINATION ${CMAKE_INSTALL_LIBDIR} ++ LIBRARY DESTINATION ${CMAKE_INSTALL_LIBDIR} ++ RUNTIME DESTINATION ${CMAKE_INSTALL_BINDIR} + ) + + # Install the module files. + install( + DIRECTORY ${module_base} +- DESTINATION lib/${SWIFT_HOST_LIBRARIES_SUBDIRECTORY} ++ DESTINATION ${CMAKE_INSTALL_INCLUDEDIR}/../lib/${SWIFT_HOST_LIBRARIES_SUBDIRECTORY} + FILES_MATCHING PATTERN "*.swiftinterface" + ) + else() +-- +2.51.2 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-system/files/SwiftSystemConfig.cmake b/pkgs/development/compilers/swift/by-name/sw/swift-system/files/SwiftSystemConfig.cmake new file mode 100644 index 000000000000..cbf2d99fe6f2 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-system/files/SwiftSystemConfig.cmake @@ -0,0 +1,11 @@ +add_library(CSystem STATIC IMPORTED) +set_target_properties(CSystem PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_STATIC_LIBRARY_PREFIX}CSystem${CMAKE_STATIC_LIBRARY_SUFFIX}" +) + +add_library(SwiftSystem::SystemPackage STATIC IMPORTED) +set_target_properties(SwiftSystem::SystemPackage PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_STATIC_LIBRARY_PREFIX}SystemPackage${CMAKE_STATIC_LIBRARY_SUFFIX}" + INTERFACE_LINK_LIBRARIES CSystem + INTERFACE_INCLUDE_DIRECTORIES "@dev@/include;@dev@/lib/swift_static/@swiftPlatform@" +) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-system/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-system/package.nix new file mode 100644 index 000000000000..86b008c41746 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-system/package.nix @@ -0,0 +1,68 @@ +{ + lib, + cmake, + fetchFromGitHub, + gitUpdater, + ninja, + stdenv, + swift, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "swift-system"; + version = "1.8.1"; + + outputs = [ + "out" + "dev" + ]; + + src = fetchFromGitHub { + owner = "apple"; + repo = "swift-system"; + tag = finalAttrs.version; + hash = "sha256-mnQcCHYW0oCadmIE9ayjs3aZiCVQRuliQ0qWpQ22OFQ="; + }; + + patches = [ ./patches/0001-gnu-install-dirs.patch ]; + + strictDeps = true; + + preConfigure = '' + appendToVar cmakeFlags -DCMAKE_Swift_COMPILER_TARGET=${stdenv.hostPlatform.swift.triple} + appendToVar cmakeFlags -DCMAKE_Swift_FLAGS=-module-cache-path\ "$NIX_BUILD_TOP/module-cache" + ''; + + nativeBuildInputs = [ + cmake + ninja + swift + ]; + + postInstall = '' + moveToOutput lib/swift "''${!outputDev}" + moveToOutput lib/swift_static "''${!outputDev}" + + # This isn’t installed by the upstream CMake files, but it’s needed. + cp lib/libCSystem.a "$out/lib/libCSystem.a" + + # Install CMake config file for Swift System. + mkdir -p "''${!outputDev}/lib/cmake/SwiftSystem" + substitute ${./files/SwiftSystemConfig.cmake} "''${!outputDev}/lib/cmake/SwiftSystem/SwiftSystemConfig.cmake" \ + --replace-fail '@dev@' "''${!outputDev}" \ + --replace-fail '@lib@' "''${!outputLib}" \ + --replace-fail '@swiftPlatform@' ${stdenv.hostPlatform.swift.platform} + ''; + + __structuredAttrs = true; + + passthru.updateScript = gitUpdater { }; + + meta = { + homepage = "https://github.com/apple/swift-system"; + description = "Low-level APIs and types for Swift"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-system/patches/0001-gnu-install-dirs.patch b/pkgs/development/compilers/swift/by-name/sw/swift-system/patches/0001-gnu-install-dirs.patch new file mode 100644 index 000000000000..aa9bdeb78adc --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-system/patches/0001-gnu-install-dirs.patch @@ -0,0 +1,23 @@ +From ab44a593012e8092bd17c63aba77641993624f12 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Wed, 17 Dec 2025 20:59:10 -0500 +Subject: [PATCH] gnu-install-dirs + +--- + Sources/CSystem/CMakeLists.txt | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/Sources/CSystem/CMakeLists.txt b/Sources/CSystem/CMakeLists.txt +index faf730e..0860dbc 100644 +--- a/Sources/CSystem/CMakeLists.txt ++++ b/Sources/CSystem/CMakeLists.txt +@@ -16,5 +16,5 @@ install(FILES + include/CSystemLinux.h + include/CSystemWindows.h + include/module.modulemap +- DESTINATION include/CSystem) ++ DESTINATION "${CMAKE_INSTALL_INCLUDEDIR}") + set_property(GLOBAL APPEND PROPERTY SWIFT_SYSTEM_EXPORTS CSystem) +-- +2.50.1 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-testing/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-testing/package.nix new file mode 100644 index 000000000000..8b52585f905c --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-testing/package.nix @@ -0,0 +1,88 @@ +{ + lib, + cmake, + fetchFromGitHub, + ninja, + stdenv, + swift, + swift-syntax, + swift_release, + swift_sources, +}: + +let + inherit (stdenv.hostPlatform.extensions) sharedLibrary; + buildSharedLibrary = stdenv.buildPlatform.extensions.sharedLibrary; + + # Can’t use `swift-minimal`. Swift Testing fails to build using the classic Swift frontend. + # It requires the new Swift compiler driver. + swift' = swift.override { swift-testing = null; }; +in + +stdenv.mkDerivation (finalAttrs: { + pname = "swift-testing"; + version = swift_release; + + outputs = [ + "out" + "dev" + ]; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-testing"; + tag = "swift-${finalAttrs.version}-RELEASE"; + inherit (swift_sources.swift-testing) hash; + }; + + patches = [ ./patches/0001-gnu-install-dirs.patch ]; + + postPatch = '' + # Need to reference $include, so this can’t be substituted by `replaceVars`. + substituteInPlace CMakeLists.txt --replace-fail '@include@' "''${!outputInclude}" + ''; + + strictDeps = true; + + cmakeFlags = [ (lib.cmakeBool "BUILD_SHARED_LIBS" (!stdenv.hostPlatform.isStatic)) ]; + + preConfigure = '' + appendToVar cmakeFlags -DCMAKE_Swift_COMPILER_TARGET=${stdenv.hostPlatform.swift.triple} + appendToVar cmakeFlags -DCMAKE_Swift_FLAGS=-module-cache-path\ "$NIX_BUILD_TOP/module-cache" + ''; + + nativeBuildInputs = [ + cmake + ninja + swift' + ]; + + buildInputs = [ swift-syntax ]; + + postInstall = ( + if stdenv.hostPlatform.isDarwin then + '' + install -D -t "''${!outputDev}/lib/swift/host/plugins/testing" \ + lib/swift/host/plugins/testing/libTestingMacros${sharedLibrary} + install_name_tool "''${!outputLib}/lib/libTesting${sharedLibrary}" \ + -id "''${!outputLib}/lib/libTesting${sharedLibrary}" + install_name_tool "''${!outputDev}/lib/swift/host/plugins/testing/libTestingMacros${buildSharedLibrary}" \ + -id "''${!outputDev}/lib/swift/host/plugins/testing/libTestingMacros${buildSharedLibrary}" + '' + else + '' + install -D -t "''${!outputDev}/lib/swift/host/plugins/testing" \ + lib/swift/host/plugins/libTestingMacros${sharedLibrary} + '' + ); + + __structuredAttrs = true; + + meta = { + description = "Modern testing package for Swift"; + homepage = "https://github.com/swiftlang/swift-testing"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + maintainers = lib.teams.swift.members; + }; +}) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-testing/patches/0001-gnu-install-dirs.patch b/pkgs/development/compilers/swift/by-name/sw/swift-testing/patches/0001-gnu-install-dirs.patch new file mode 100644 index 000000000000..caa75758e8c8 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-testing/patches/0001-gnu-install-dirs.patch @@ -0,0 +1,27 @@ +From 6d92a130bca4f066211e405ee733ea22eed54e37 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Fri, 26 Dec 2025 21:20:40 -0500 +Subject: [PATCH] gnu-install-dirs + +--- + CMakeLists.txt | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/CMakeLists.txt b/CMakeLists.txt +index 38aeda61..2499a8db 100644 +--- a/CMakeLists.txt ++++ b/CMakeLists.txt +@@ -51,8 +51,8 @@ include(PlatformInfo) + include(SwiftModuleInstallation) + + option(SwiftTesting_INSTALL_NESTED_SUBDIR "Install libraries under a platform and architecture subdirectory" NO) +-set(SwiftTesting_INSTALL_LIBDIR "${CMAKE_INSTALL_LIBDIR}/swift$<$>:_static>/${SwiftTesting_PLATFORM_SUBDIR}$<$,$>>:/testing>$<$:/${SwiftTesting_ARCH_SUBDIR}>") +-set(SwiftTesting_INSTALL_SWIFTMODULEDIR "${CMAKE_INSTALL_LIBDIR}/swift$<$>:_static>/${SwiftTesting_PLATFORM_SUBDIR}$<$,$>>:/testing>") ++set(SwiftTesting_INSTALL_LIBDIR "${CMAKE_INSTALL_LIBDIR}") ++set(SwiftTesting_INSTALL_SWIFTMODULEDIR "@include@/lib/swift$<$>:_static>/${SwiftTesting_PLATFORM_SUBDIR}$<$,$>>:/testing>") + + add_compile_options($<$:-no-toolchain-stdlib-rpath>) + +-- +2.51.2 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-tools-support-core/files/TSCConfig.cmake b/pkgs/development/compilers/swift/by-name/sw/swift-tools-support-core/files/TSCConfig.cmake new file mode 100644 index 000000000000..aaf13a84c523 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-tools-support-core/files/TSCConfig.cmake @@ -0,0 +1,11 @@ +add_library(TSCBasic @buildType@ IMPORTED) +set_target_properties(TSCBasic PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}SwiftToolsSupport${CMAKE_@buildType@_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@dev@/include;@dev@/lib/swift/@swiftPlatform@" +) + +add_library(TSCUtility @buildType@ IMPORTED) +set_target_properties(TSCUtility PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}SwiftToolsSupport${CMAKE_@buildType@_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@dev@/include;@dev@/lib/swift/@swiftPlatform@" +) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-tools-support-core/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-tools-support-core/package.nix new file mode 100644 index 000000000000..f1b7c717d239 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-tools-support-core/package.nix @@ -0,0 +1,100 @@ +{ + lib, + cmake, + fetchFromGitHub, + gitUpdater, + llvm_libtool, + ninja, + stdenv, + swift-corelibs-libdispatch, + swift-foundation, + swift-minimal, + swift_release, + swift_sources, +}: + +let + swiftPlatform = stdenv.hostPlatform.swift.platform; + # Swift Tools Support Core requires Dispatch and Foundation. + swift = swift-minimal.override { inherit swift-corelibs-libdispatch swift-foundation; }; +in + +stdenv.mkDerivation (finalAttrs: { + pname = "swift-tools-support-core"; + version = swift_release; + + outputs = [ + "out" + "dev" + ]; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-tools-support-core"; + tag = "swift-${finalAttrs.version}-RELEASE"; + inherit (swift_sources.swift-tools-support-core) hash; + }; + + patches = [ + # Match the dynamic library structure of the SwiftPM build when using CMake. + ./patches/0001-build-SwiftToolsSupport.patch + ]; + + postPatch = + # Disable using XCTest framework properties that aren’t provided by swift-corelibs-xctest. + '' + substituteInPlace "Sources/TSCTestSupport/XCTestCasePerf.swift" \ + --replace-fail '#if canImport(Darwin)' '#if false' + ''; + + strictDeps = true; + + preConfigure = '' + appendToVar cmakeFlags -DCMAKE_Swift_COMPILER_TARGET=${stdenv.hostPlatform.swift.triple} + appendToVar cmakeFlags -DCMAKE_Swift_FLAGS=-module-cache-path\ "$NIX_BUILD_TOP/module-cache" + ''; + + nativeBuildInputs = [ + cmake + ninja + swift + ] + ++ lib.optionals stdenv.hostPlatform.isDarwin [ llvm_libtool ]; + + postInstall = '' + # Install the swiftmodule. + mkdir -p "''${!outputDev}/lib/swift/${swiftPlatform}" + cp -v swift/*.swiftmodule "''${!outputDev}/lib/swift/${swiftPlatform}" + + # Install the C module + mkdir -p "''${!outputDev}/include" + cp -v ../Sources/TSCclibc/include/* "''${!outputDev}/include" + + # Install CMake config file for the SwiftSupportTools library. + mkdir -p "''${!outputDev}/lib/cmake/TSC" + substitute ${./files/TSCConfig.cmake} "''${!outputDev}/lib/cmake/TSC/TSCConfig.cmake" \ + --replace-fail '@buildType@' ${if stdenv.hostPlatform.isStatic then "STATIC" else "SHARED"} \ + --replace-fail '@dev@' "''${!outputDev}" \ + --replace-fail '@lib@' "''${!outputLib}" \ + --replace-fail '@swiftPlatform@' ${swiftPlatform} + '' + # These are not linked into the shared library and are linked separate only on Linux. + + lib.optionalString (!stdenv.hostPlatform.isDarwin) '' + libExt=${stdenv.hostPlatform.extensions.staticLibrary} + for libName in TSCBasic TSCLibc; do + cp -v lib/lib$libName$libExt "''${!outputLib}/lib/lib$libName$libExt" + done + ''; + + __structuredAttrs = true; + + passthru.updateScript = gitUpdater { }; + + meta = { + homepage = "https://github.com/swiftlang/swift-tools-support-core"; + description = "Common infrastructure code used by SwiftPM and llbuild"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift-tools-support-core/patches/0001-build-SwiftToolsSupport.patch b/pkgs/development/compilers/swift/by-name/sw/swift-tools-support-core/patches/0001-build-SwiftToolsSupport.patch new file mode 100644 index 000000000000..e829a41f9263 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift-tools-support-core/patches/0001-build-SwiftToolsSupport.patch @@ -0,0 +1,108 @@ +From 2e4200e2586b2389f2214506bfe5e06102060f15 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Mon, 8 Dec 2025 17:40:01 -0500 +Subject: [PATCH] build SwiftToolsSupport + +--- + Sources/TSCBasic/CMakeLists.txt | 7 +------ + Sources/TSCUtility/CMakeLists.txt | 25 +++++++++++++------------ + Sources/TSCclibc/CMakeLists.txt | 6 ++---- + 3 files changed, 16 insertions(+), 22 deletions(-) + +diff --git a/Sources/TSCBasic/CMakeLists.txt b/Sources/TSCBasic/CMakeLists.txt +index d8b85ea..ebb8cbe 100644 +--- a/Sources/TSCBasic/CMakeLists.txt ++++ b/Sources/TSCBasic/CMakeLists.txt +@@ -6,7 +6,7 @@ + # See http://swift.org/LICENSE.txt for license information + # See http://swift.org/CONTRIBUTORS.txt for Swift project authors + +-add_library(TSCBasic ++add_library(TSCBasic STATIC + Await.swift + ByteString.swift + CStringArray.swift +@@ -69,9 +69,4 @@ target_link_libraries(TSCBasic PRIVATE + set_target_properties(TSCBasic PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + +-install(TARGETS TSCBasic +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) +- + set_property(GLOBAL APPEND PROPERTY TSC_EXPORTS TSCBasic) +diff --git a/Sources/TSCUtility/CMakeLists.txt b/Sources/TSCUtility/CMakeLists.txt +index 8e0a232..78e4558 100644 +--- a/Sources/TSCUtility/CMakeLists.txt ++++ b/Sources/TSCUtility/CMakeLists.txt +@@ -6,7 +6,7 @@ + # See http://swift.org/LICENSE.txt for license information + # See http://swift.org/CONTRIBUTORS.txt for Swift project authors + +-add_library(TSCUtility ++add_library(SwiftToolsSupport + Archiver.swift + ArgumentParser.swift + ArgumentParserShellCompletion.swift +@@ -42,29 +42,30 @@ add_library(TSCUtility + dlopen.swift + misc.swift + ) +-target_link_libraries(TSCUtility PUBLIC +- TSCBasic) +-target_link_libraries(TSCUtility PRIVATE ++target_link_libraries(SwiftToolsSupport PUBLIC ++ $) ++target_link_libraries(SwiftToolsSupport PRIVATE + TSCclibc + ${CMAKE_DL_LIBS} + Threads::Threads) + + if(NOT CMAKE_SYSTEM_NAME STREQUAL Darwin) + if(CMAKE_SYSTEM_NAME STREQUAL OpenBSD OR CMAKE_SYSTEM_NAME STREQUAL FreeBSD) +- target_link_directories(TSCUtility PRIVATE /usr/local/lib) ++ target_link_directories(SwiftToolsSupport PRIVATE /usr/local/lib) + endif() + if(Foundation_FOUND) +- target_link_libraries(TSCUtility PUBLIC ++ target_link_libraries(SwiftToolsSupport PUBLIC + FoundationNetworking) + endif() + endif() + # NOTE(compnerd) workaround for CMake not setting up include flags yet +-set_target_properties(TSCUtility PROPERTIES ++set_target_properties(SwiftToolsSupport PROPERTIES ++ Swift_MODULE_NAME TSCUtility + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + +-install(TARGETS TSCUtility +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++install(TARGETS SwiftToolsSupport ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") + +-set_property(GLOBAL APPEND PROPERTY TSC_EXPORTS TSCUtility) ++set_property(GLOBAL APPEND PROPERTY TSC_EXPORTS SwiftToolsSupport) +diff --git a/Sources/TSCclibc/CMakeLists.txt b/Sources/TSCclibc/CMakeLists.txt +index e28860c..8048c24 100644 +--- a/Sources/TSCclibc/CMakeLists.txt ++++ b/Sources/TSCclibc/CMakeLists.txt +@@ -14,9 +14,7 @@ target_compile_definitions(TSCclibc PRIVATE + "$<$:_GNU_SOURCE>") + set_target_properties(TSCclibc PROPERTIES POSITION_INDEPENDENT_CODE YES) + +-if(NOT BUILD_SHARED_LIBS) +- install(TARGETS TSCclibc +- ARCHIVE DESTINATION lib) +-endif() ++install(TARGETS TSCclibc ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}") + + set_property(GLOBAL APPEND PROPERTY TSC_EXPORTS TSCclibc) +-- +2.51.2 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swift/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift/package.nix new file mode 100644 index 000000000000..bc96a9cd7f91 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift/package.nix @@ -0,0 +1,257 @@ +{ + lib, + config, + apple-sdk_14, + apple-sdk_26, + callPackage, + llvmPackages, + llvmPackages_upstream, + patchelf, + stdenv, + stdlib, + swift-corelibs-foundation, + swift-corelibs-libdispatch, + swift-corelibs-xctest, + swift-driver, + swift-foundation, + swift-foundation-icu, + swift-testing, + swiftc, + symlinkJoin, + swift_release, + enableRepl ? true, # Whether to build and include LLDB for the Swift REPL. +}: + +let + includeTesting = swiftc.supportsMacros && swift-testing != null; + + # Need to use an older SDK if `swiftc` does not support macros. + propagated-sdk = if swiftc.supportsMacros then apple-sdk_26 else apple-sdk_14; + + # The toolchain needs to propagate libdispatch with and without the Swift overlay to make sure it propagates + # both the non-Swift shared libraries and the Swift overlay shared library. + swift-corelibs-libdispatch-no-overlay = swift-corelibs-libdispatch.override { useSwift = false; }; + + # `out` and `dev` are merged because that’s what Swift expects. + outLinks = symlinkJoin { + name = "swift" + lib.removePrefix "swiftc" (lib.getName swiftc) + "-${swift_release}-out"; + paths = [ + swiftc.out + swiftc.dev + ] + ++ lib.optionals enableRepl [ + # LLDB is used by `swift repl` to provide the REPL. + llvmPackages.lldb.out + ] + ++ lib.optionals includeTesting [ + swift-corelibs-xctest.dev + swift-corelibs-xctest.out + swift-testing.dev + swift-testing.out + ] + ++ lib.optionals (stdlib != null) [ + stdlib.dev + stdlib.out + swiftc.dev + ] + ++ lib.optionals (swift-driver != null) [ + swift-driver.out + swift-driver.dev + swift-driver.lib + ] + ++ lib.optionals (stdenv.hostPlatform.isDarwin && swift-foundation != null) [ + # Needed for FoundationMacros, which is otherwise not part of the SDK on Darwin. + swift-foundation.out + ] + ++ lib.optionals (!stdenv.hostPlatform.isDarwin) ( + lib.optionals (swift-corelibs-libdispatch != null) [ + swift-corelibs-libdispatch.out + swift-corelibs-libdispatch.dev + swift-corelibs-libdispatch-no-overlay.out + swift-corelibs-libdispatch-no-overlay.dev + ] + ++ lib.optionals (swift-foundation != null) [ + swift-corelibs-foundation.out + swift-corelibs-foundation.dev + swift-foundation-icu.out + swift-foundation.dev + swift-foundation.out + ] + ); + }; + + docLinks = symlinkJoin { + name = "swift" + lib.removePrefix "swiftc" (lib.getName swiftc) + "-${swift_release}-doc"; + paths = [ + swiftc.doc + ]; + }; + + manLinks = symlinkJoin { + name = "swift" + lib.removePrefix "swiftc" (lib.getName swiftc) + "-${swift_release}-man"; + paths = [ + swiftc.man + ] + ++ lib.optionals (!stdenv.hostPlatform.isDarwin && swift-corelibs-libdispatch != null) [ + swift-corelibs-libdispatch.man + ]; + }; +in + +stdenv.mkDerivation (finalAttrs: { + pname = "swift" + lib.removePrefix "swiftc" (lib.getName swiftc); + version = swift_release; + + outputs = [ + "out" + "doc" + "man" + ]; + + strictDeps = true; + + # Will effectively be `buildInputs` when swift is put in `nativeBuildInputs`. + depsTargetTargetPropagated = + lib.optionals stdenv.targetPlatform.isDarwin [ propagated-sdk ] + ++ lib.optionals (stdlib != null) [ + # Propagate the stdlib to make sure the linker wrapper will pick up the dynamic and static libraries. + stdlib + ] + ++ lib.optionals includeTesting [ + swift-corelibs-xctest.out + swift-testing.out + ] + ++ lib.optionals (!stdenv.hostPlatform.isDarwin) ( + lib.optionals (swift-corelibs-libdispatch != null) [ + swift-corelibs-libdispatch-no-overlay.out + swift-corelibs-libdispatch.out + ] + ++ lib.optionals (swift-foundation != null) [ + swift-corelibs-foundation.out + swift-foundation-icu.out + swift-foundation.out + ] + ); + + buildCommand = '' + mkdir -p "$out" "$doc" "$man" + + cp -r ${lib.escapeShellArg outLinks}/* "$out" + cp -r ${lib.escapeShellArg docLinks}/* "$doc" + cp -r ${lib.escapeShellArg manLinks}/* "$man" + + # Make writable temporarily to allow for the fixups below to be made to the outputs. + chmod -R u+w "$out/bin" "$out/lib" "$out/nix-support" + + # Swift expects to find Clang next to it. + ln -s ${lib.escapeShellArg (lib.getExe' llvmPackages_upstream.clang "clang")} "$out/bin/clang" + ln -s ${lib.escapeShellArg (lib.getExe' llvmPackages_upstream.clang "clang++")} "$out/bin/clang++" + + # Swift has a separate resource root from Clang, but locates the Clang resource root via subdir or symlink. + # + # NOTE: We don’t symlink directly here, because that’d add a run-time dep on the full Clang compiler to every + # Swift executable. We instead symlink compiler-rt and copy the headers from Clang to keep the closure size down. + mkdir -p "$out/lib/swift/clang" + ln -s ${lib.escapeShellArg (lib.getBin llvmPackages.compiler-rt)}/{lib,share} "$out/lib/swift/clang/" + cp -rH ${lib.escapeShellArg (lib.getBin llvmPackages.clang)}/resource-root/include/ "$out/lib/swift/clang/" + + # `swift-frontend` expects to find everything relative to its location after resolving symlinks. + # Also copy `swift-driver` assuming it does similar. + for exe in swift-driver swift-frontend; do + if [ -e "$out/bin/$exe" ]; then + orig=$(readlink "$out/bin/$exe") + rm "$out/bin/$exe" + cp "$orig" "$out/bin/$exe" + fi + done + + # Make sure `swift` and `swiftc` point to `swift-driver` if present. + if [ -e "$out/bin/swift-driver" ]; then + for exe in swift swiftc; do + rm -f "$out/bin/$exe" + ln -s swift-driver "$out/bin/$exe" + done + fi + + # Propagated inputs in `$dev/nix-support` have to be substituted to use this derivation instead of swiftc. + for f in "$out/nix-support/"*; do + orig=$(readlink "$f") + rm "$f" + substitute "$orig" "$f" \ + --replace-quiet ${lib.escapeShellArg swiftc.out} "$out" + done + + # Don’t propagate CMake files for toolchain dependencies. These are an implementation detail of the package set. + rm -rf "$out/lib/cmake" + + recordPropagatedDependencies + + ${lib.optionalString (stdlib != null) '' + # Can’t use `replaceVars` because it needs to substitute $out. + substitute ${./setup-hook.sh} "$out/nix-support/setup-hook" \ + --replace-fail @patchelf@ ${lib.escapeShellArg (lib.getExe patchelf)} \ + --replace-fail @objdump@ ${lib.escapeShellArg (lib.getExe' llvmPackages_upstream.llvm "llvm-objdump")} \ + --replace-fail @install_name_tool@ ${lib.escapeShellArg (lib.getExe' llvmPackages_upstream.llvm "llvm-install-name-tool")} \ + --replace-fail @stdlibPath@ ${lib.escapeShellArg stdlib.out} \ + --replace-fail @swiftPath@ "$out" \ + --replace-fail @swiftPlatform@ ${stdenv.hostPlatform.swift.platform} + ''} + ${lib.optionalString enableRepl '' + # LLDB expects to find Swift relative to its location. Both the wrapper and its binary need copied, + # and the wrapper needs updated to find the binary in the new location. + lldbBinPath=$(dirname $(readlink "$out/bin/lldb")) + for lldbExe in lldb .lldb-wrapped; do + rm "$out/bin/$lldbExe" + cp "$lldbBinPath/$lldbExe" "$out/bin/$lldbExe" + done + substituteInPlace "$out/bin/lldb" \ + --replace-fail "$lldbBinPath" "$out/bin" + ${lib.optionalString stdenv.hostPlatform.isElf '' + # LLDB tries to find the Swift resource folder relative to where it finds `liblldb.so` via RPATH. + oldRpaths=$(patchelf --print-rpath "$out/bin/.lldb-wrapped") + lldbRpath=${lib.escapeShellArg llvmPackages.lldb.out} + + chmod u+w "$out/bin/.lldb-wrapped" + patchelf --set-rpath "''${oldRpaths/$lldbRpath/$out}" "$out/bin/.lldb-wrapped" + ''} + ''} + chmod -R u-w "$out/bin" "$out/lib" "$out/nix-support" + + # Have to invoke manually because of `buildCommand`. + noBrokenSymlinksInAllOutputs + ''; + + __structuredAttrs = true; + + passthru = { + inherit swiftc swift-driver; + tests = lib.packagesFromDirectoryRecursive { + inherit callPackage; + directory = ./tests; + }; + + # Swift libraries are installed in `lib` to make it easier to use Nixpkgs tooling with them. + swiftLibSubdir = "lib"; + swiftStaticLibSubdir = "lib"; + + # Our toolchain builds install modules in `lib/swift/`, which matches what upstream toolchains do. + swiftModuleSubdir = "lib/swift/${stdenv.hostPlatform.swift.platform}"; + swiftStaticModuleSubdir = "lib/swift_static/${stdenv.hostPlatform.swift.platform}"; + } + // lib.optionalAttrs config.allowAliases { + # Legacy aliases for the old Swift packaging. These should eventually be removed. + swift = lib.warnOnInstantiate "`swift` is an alias for this (`swift`) package. Just use it directly." finalAttrs.finalPackage; + swiftArch = lib.warn "'swiftArch' is an alias for 'stdenv.hostPlatform.swift.arch'." stdenv.hostPlatform.swift.arch; + swiftDriver = lib.warnOnInstantiate "'swiftDriver' has been renamed to 'swift-driver'" finalAttrs.passthru.swift-driver; + swiftOs = lib.warn "'swiftOs' is an alias for 'stdenv.hostPlatform.swift.platform'." stdenv.hostPlatform.swift.platform; + }; + + meta = { + mainProgram = "swift"; + description = "Swift Programming Language"; + homepage = "https://github.com/swiftlang/swift"; + inherit (swiftc.meta) platforms badPlatforms; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift/setup-hook.sh b/pkgs/development/compilers/swift/by-name/sw/swift/setup-hook.sh new file mode 100644 index 000000000000..1d82805dab7b --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift/setup-hook.sh @@ -0,0 +1,30 @@ +fixSwiftRpathsIn() { + local dir=$1 + + local swiftPath=@swiftPath@/lib + local swiftPathForPlatform=@swiftPath@/lib/swift/@swiftPlatform@ + local stdlibPath=@stdlibPath@/lib + + local f + while IFS= read -d "" f; do + if LC_ALL=C isMachO "$f"; then + IFS= readarray -d $'\n' -t rpaths < <(@objdump@ --macho --rpaths "$f" | tail -n +2) + for oldPath in "${rpaths[@]}"; do + local newPath=${oldPath/$swiftPathForPlatform/$stdlibPath} + newPath=${newPath/$swiftPath/$stdlibPath} + if [ "$newPath" != "$oldPath" ]; then + @install_name_tool@ "$f" -rpath "$oldPath" "$newPath" + fi + done + elif isELF "$f"; then + local oldRpaths=$(@patchelf@ --print-rpath "$f") + local newRpaths=${oldRpaths/$swiftPathForPlatform/$stdlibPath} + newRpaths=${newRpaths/$swiftPath/$stdlibPath} + if [ "$newRpaths" != "$oldRpaths" ]; then + @patchelf@ --set-rpath "$newRpaths" "$f" + fi + fi + done < <(find "$dir" -type f -print0) +} + +fixupOutputHooks+=('fixSwiftRpathsIn $prefix') diff --git a/pkgs/development/compilers/swift/by-name/sw/swift/tests/cxx-interop/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift/tests/cxx-interop/package.nix new file mode 100644 index 000000000000..3a772f5ac7fa --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift/tests/cxx-interop/package.nix @@ -0,0 +1,31 @@ +{ + stdenv, + swift, + swiftpm, +}: + +stdenv.mkDerivation { + name = "swift-test-cxx-interop"; + + src = ./src; + + strictDeps = true; + + nativeBuildInputs = [ + swift + swiftpm + ]; + + buildPhase = '' + swiftpmBuildPhase + make + ''; + + installPhase = '' + swift run -c release CxxInteropTest | grep 'Hello, Swift!' + ./SwiftToCxxInteropTest | grep 'Hello, C++!' + touch "$out" + ''; + + __structuredAttrs = true; +} diff --git a/pkgs/development/compilers/swift/by-name/sw/swift/tests/cxx-interop/src/Makefile b/pkgs/development/compilers/swift/by-name/sw/swift/tests/cxx-interop/src/Makefile new file mode 100644 index 000000000000..90139e6b3ef3 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift/tests/cxx-interop/src/Makefile @@ -0,0 +1,11 @@ +.PHONY: all +all: SwiftToCxxInteropTest + +SwiftStruct.o Check-SwiftStruct.h: Sources/SwiftStruct.swift + swiftc -parse-as-library -emit-clang-header-path Check-SwiftStruct.h -module-name Check -cxx-interoperability-mode=default $^ -c -o SwiftStruct.o + +main.o: main.cpp Check-SwiftStruct.h + clang++ $< -c -o $@ + +SwiftToCxxInteropTest: main.o SwiftStruct.o + swiftc $^ -o $@ diff --git a/pkgs/development/compilers/swift/cxx-interop-test/src/Package.swift b/pkgs/development/compilers/swift/by-name/sw/swift/tests/cxx-interop/src/Package.swift similarity index 76% rename from pkgs/development/compilers/swift/cxx-interop-test/src/Package.swift rename to pkgs/development/compilers/swift/by-name/sw/swift/tests/cxx-interop/src/Package.swift index 4c664f22c467..2ec53f023be8 100644 --- a/pkgs/development/compilers/swift/cxx-interop-test/src/Package.swift +++ b/pkgs/development/compilers/swift/by-name/sw/swift/tests/cxx-interop/src/Package.swift @@ -4,6 +4,9 @@ import PackageDescription let package = Package( name: "CxxInteropTest", + products: [ + .executable(name: "CxxInteropTest", targets: ["CxxInteropTest"]) + ], targets: [ .executableTarget( name: "CxxInteropTest", diff --git a/pkgs/development/compilers/swift/by-name/sw/swift/tests/cxx-interop/src/Sources/SwiftStruct.swift b/pkgs/development/compilers/swift/by-name/sw/swift/tests/cxx-interop/src/Sources/SwiftStruct.swift new file mode 100644 index 000000000000..cdadd6b97f34 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift/tests/cxx-interop/src/Sources/SwiftStruct.swift @@ -0,0 +1,9 @@ +import CxxStdlib + +public struct SwiftStruct { + public let hello: std.string + + public init(hello: std.string) { + self.hello = hello + } +} diff --git a/pkgs/development/compilers/swift/by-name/sw/swift/tests/cxx-interop/src/Sources/main.swift b/pkgs/development/compilers/swift/by-name/sw/swift/tests/cxx-interop/src/Sources/main.swift new file mode 100644 index 000000000000..1e89c7a14867 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift/tests/cxx-interop/src/Sources/main.swift @@ -0,0 +1,3 @@ +let swiftStruct = SwiftStruct(hello: "Hello, Swift!") +let cxxHello = swiftStruct.hello +print(String(cxxHello)) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift/tests/cxx-interop/src/main.cpp b/pkgs/development/compilers/swift/by-name/sw/swift/tests/cxx-interop/src/main.cpp new file mode 100644 index 000000000000..24d12e48c9ca --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift/tests/cxx-interop/src/main.cpp @@ -0,0 +1,8 @@ +#include + +#include "Check-SwiftStruct.h" + +int main() { + auto swiftStruct = Check::SwiftStruct::init("Hello, C++!"); + std::cout << swiftStruct.getHello() << std::endl; +} diff --git a/pkgs/development/compilers/swift/by-name/sw/swift/tests/differentiation/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift/tests/differentiation/package.nix new file mode 100644 index 000000000000..8b45cc36728f --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift/tests/differentiation/package.nix @@ -0,0 +1,27 @@ +{ + stdenv, + swift, + swiftpm, +}: + +# Test that Swift Differentiation works. This test is particularly important for Darwin because the +# Swift Differentiation dylib is no longer distributed with macOS (as of 26.4). +stdenv.mkDerivation { + name = "swift-test-differentiation"; + + src = ./src; + + strictDeps = true; + + nativeBuildInputs = [ + swift + swiftpm + ]; + + installPhase = '' + swift run -c release differentiation 4 | grep '8.0' + touch "$out" + ''; + + __structuredAttrs = true; +} diff --git a/pkgs/development/compilers/swift/by-name/sw/swift/tests/differentiation/src/Package.swift b/pkgs/development/compilers/swift/by-name/sw/swift/tests/differentiation/src/Package.swift new file mode 100644 index 000000000000..3c1ca846970f --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift/tests/differentiation/src/Package.swift @@ -0,0 +1,13 @@ +// swift-tools-version: 6.2 + +import PackageDescription + +let package = Package( + name: "differentiation", + products: [ + .executable(name: "differentiation", targets: ["differentiation"]) + ], + targets: [ + .executableTarget(name: "differentiation", path: "Sources") + ] +) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift/tests/differentiation/src/Sources/main.swift b/pkgs/development/compilers/swift/by-name/sw/swift/tests/differentiation/src/Sources/main.swift new file mode 100644 index 000000000000..74d86fe609cf --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift/tests/differentiation/src/Sources/main.swift @@ -0,0 +1,10 @@ +import _Differentiation + +@differentiable(reverse) +func f(x: Double) -> Double { + return x * x +} + +let m = gradient(at: Double(CommandLine.arguments[1])!, of: f) + +print(m) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift/tests/foundation-macros/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift/tests/foundation-macros/package.nix new file mode 100644 index 000000000000..0e22d74b2b2b --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift/tests/foundation-macros/package.nix @@ -0,0 +1,26 @@ +{ + stdenv, + swift, + swiftpm, +}: + +# The primary goal of this test is to confirm that the foundation macros built with the toolchain work on Darwin. +stdenv.mkDerivation { + name = "swift-test-foundation-macros"; + + src = ./src; + + strictDeps = true; + + nativeBuildInputs = [ + swift + swiftpm + ]; + + installPhase = '' + swift run -c release foundation-macros | grep 'Hello, foundation macros' + touch "$out" + ''; + + __structuredAttrs = true; +} diff --git a/pkgs/development/compilers/swift/by-name/sw/swift/tests/foundation-macros/src/Package.swift b/pkgs/development/compilers/swift/by-name/sw/swift/tests/foundation-macros/src/Package.swift new file mode 100644 index 000000000000..99cd2a9934cb --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift/tests/foundation-macros/src/Package.swift @@ -0,0 +1,14 @@ +// swift-tools-version: 6.2 + +import PackageDescription + +let package = Package( + name: "foundation-macros", + platforms: [.macOS("14.0")], + products: [ + .executable(name: "foundation-macros", targets: ["foundation-macros"]) + ], + targets: [ + .executableTarget(name: "foundation-macros", path: "Sources") + ] +) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift/tests/foundation-macros/src/Sources/main.swift b/pkgs/development/compilers/swift/by-name/sw/swift/tests/foundation-macros/src/Sources/main.swift new file mode 100644 index 000000000000..3e2a66c57b9a --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift/tests/foundation-macros/src/Sources/main.swift @@ -0,0 +1,14 @@ +import Foundation + +let wordPred = #Predicate { s in s == "foundation" || s == "macros" } + +let words = [ + "foo", + "foundation", + "macros", + "swift", + "world", +] +let filtered = try! words.filter(wordPred) + +print("Hello, \(filtered.joined(separator: " "))") diff --git a/pkgs/development/compilers/swift/by-name/sw/swift/tests/repl/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift/tests/repl/package.nix new file mode 100644 index 000000000000..09353c38fef2 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift/tests/repl/package.nix @@ -0,0 +1,23 @@ +{ + lib, + runCommand, + swift, +}: + +# Make sure the REPL works. It’s a bit finicky on Linux. +runCommand "swift-test-repl" + { + nativeBuildInputs = [ swift ]; + meta.badPlatforms = [ + # Darwin can’t run this test because it requires `debugserver`, which is non-free. + # Even if it could use `debugserver`, the build user would need debugging access, which it will not have. + lib.systems.inspect.patterns.isDarwin + ]; + } + '' + swift repl < Double { + return x * x +} + +let m = gradient(at: Double(CommandLine.arguments[1])!, of: f) + +let data = Data("Hello, \(m)".utf8) +let str = String(decoding: data, as: UTF8.self) + +print(str) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift/tests/swift-testing/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift/tests/swift-testing/package.nix new file mode 100644 index 000000000000..a320da544018 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift/tests/swift-testing/package.nix @@ -0,0 +1,32 @@ +{ + lib, + swift, + swiftpm, + stdenv, +}: + +stdenv.mkDerivation { + name = "swift-test-swift-testing"; + + src = ./src; + + strictDeps = true; + + nativeBuildInputs = [ + swift + swiftpm + ]; + + doCheck = true; + + installPhase = '' + touch "$out" + ''; + + __structuredAttrs = true; + + meta.badPlatforms = [ + # This test won’t work on Darwin until XCTest is modified to work on Darwin without requiring Xcode. + lib.systems.inspect.patterns.isDarwin + ]; +} diff --git a/pkgs/development/compilers/swift/by-name/sw/swift/tests/swift-testing/src/Package.swift b/pkgs/development/compilers/swift/by-name/sw/swift/tests/swift-testing/src/Package.swift new file mode 100644 index 000000000000..e707f58c6b29 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift/tests/swift-testing/src/Package.swift @@ -0,0 +1,18 @@ +// swift-tools-version: 6.2 + +import PackageDescription + +let package = Package( + name: "test-swift-testing", + products: [ + .library(name: "test-swift-testing", type: .dynamic, targets: ["test-swift-testing"]) + ], + targets: [ + .target(name: "test-swift-testing", path: "Sources"), + .testTarget( + name: "test-swift-testing-tests", + dependencies: ["test-swift-testing"], + path: "Tests" + ), + ] +) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift/tests/swift-testing/src/Sources/Hello.swift b/pkgs/development/compilers/swift/by-name/sw/swift/tests/swift-testing/src/Sources/Hello.swift new file mode 100644 index 000000000000..1fa85f9560f5 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift/tests/swift-testing/src/Sources/Hello.swift @@ -0,0 +1,5 @@ +struct HelloStruct { + let message: String + + func sayHello() -> String { "Hello, \(self.message)" } +} diff --git a/pkgs/development/compilers/swift/by-name/sw/swift/tests/swift-testing/src/Tests/HelloTests.swift b/pkgs/development/compilers/swift/by-name/sw/swift/tests/swift-testing/src/Tests/HelloTests.swift new file mode 100644 index 000000000000..c4fa23805b2c --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swift/tests/swift-testing/src/Tests/HelloTests.swift @@ -0,0 +1,14 @@ +import Testing + +@testable import test_swift_testing + +@Suite struct HelloStructTests { + @Test func itSaysHello() { + let expected = "Hello, Nixpkgs!" + + let s = HelloStruct(message: "Nixpkgs!") + let result = s.sayHello() + + #expect(result == expected) + } +} diff --git a/pkgs/development/compilers/swift/by-name/sw/swiftc/package.nix b/pkgs/development/compilers/swift/by-name/sw/swiftc/package.nix new file mode 100644 index 000000000000..3e237e12ae2d --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swiftc/package.nix @@ -0,0 +1,572 @@ +{ + lib, + apple-sdk_14, + apple-sdk_26, + bootstrapStage, + buildSwiftPackages, + cmake, + darwin, + fetchFromGitHub, + fetchpatch2, + libedit, + libffi, + libuuid, + libxml2, + llvmPackages, + llvm_libtool, + ninja, + perl, + python3, + replaceVars, + srcOnly, + stdenv, + stdlib, + swift-cmark, + swift-corelibs-libdispatch, + swift-syntax, + xcbuild, + xz, + zlib, + zstd, + swift_release, + swift_sources, + # This matches _SWIFT_DEFAULT_COMPONENTS, with specific components disabled. + swiftComponents ? [ + "autolink-driver" + # "clang-builtin-headers" + # "clang-resource-dir-symlink" + "compiler" + "compiler-swift-syntax-lib" + # "dev" + "editor-integration" + # "llvm-toolchain-dev-tools" + "license" + "sdk-overlay" + (if stdenv.hostPlatform.isDarwin then "sourcekit-xpc-service" else "sourcekit-inproc") + # "stdlib-experimental" + "swift-syntax-lib" + # "testsuite-tools" + "toolchain-dev-tools" + "toolchain-tools" + # "tools" + ] + ++ lib.optionals (stdlib == null) [ + "back-deployment" + "sdk-overlay" + "static-mirror-lib" + "stdlib" + "swift-remote-mirror" + "swift-remote-mirror-headers" + ], +}: + +let + # SDK versions past 14.x don’t work with the c++-based bootstrap compiler due to unconditionally exposing macros. + build-sdk = if bootstrapStage == 2 then apple-sdk_26 else apple-sdk_14; + + # `buildSwiftPackages` is always the previous stage. Building the stage 2 compiler requires linking against the + # separately built stdlib because it does not build its own. Override the stage 1 compiler to use it. + # Otherwise, packages with macros will fail to build with missing symbols in Swift Syntax. + swift = + if bootstrapStage == 2 then + buildSwiftPackages.swift.override { inherit stdlib; } + else + buildSwiftPackages.swift; + + swift-driver = swift.swift-driver or null; + + inherit (llvmPackages) + clang + clang-unwrapped + llvm + + libclang + libllvm + ; + + inherit (darwin) sigtool; + + doCheck = false; # TODO: Implement tests per https://github.com/swiftlang/swift/blob/main/docs/Testing.md. + + dylibExt = stdenv.hostPlatform.extensions.sharedLibrary; + + isNotSwiftSyntax = if bootstrapStage == 0 then c: !lib.hasInfix "swift-syntax" c else _: true; + + swiftComponents' = lib.filter isNotSwiftSyntax swiftComponents; + + swiftPlatform = stdenv.hostPlatform.swift.platform; + + srcs = { + swift-experimental-string-processing = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-experimental-string-processing"; + tag = "swift-${swift_release}-RELEASE"; + inherit (swift_sources.swift-experimental-string-processing) hash; + }; + + swift-syntax = srcOnly { + inherit (swift-syntax) + name + version + src + patches + stdenv + ; + }; + }; +in + +stdenv.mkDerivation (finalAttrs: { + pname = + "swiftc" + + lib.optionalString (bootstrapStage == 0) "-cxx_bootstrap" + + lib.optionalString (bootstrapStage == 1) "-bootstrap"; + version = swift_release; + + outputs = [ + "out" + "dev" + "doc" + "man" + ] + ++ lib.optionals (bootstrapStage == 2) [ + # Static libs from the compiler build (needed to build LLDB). + "static" + ]; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift"; + tag = "swift-${swift_release}-RELEASE"; + inherit (swift_sources.swift) hash; + }; + + postUnpack = lib.optionalString (bootstrapStage >= 1) '' + ln -s ${lib.escapeShellArg srcs.swift-experimental-string-processing} "$NIX_BUILD_TOP/swift-experimental-string-processing" + ln -s ${lib.escapeShellArg srcs.swift-syntax} "$NIX_BUILD_TOP/swift-syntax" + ''; + + patches = [ + # ClangImporter needs help finding the location of libc and libc++ (and using it). + ./patches/0001-Read-C-and-C-stdlib-flags-from-the-wrapped-compiler.patch + ./patches/0002-Use-Nixpkgs-C-and-C-stdlib-paths-in-ClangImporter.patch + # Backport linking against an external swift-cmark. + # From https://github.com/swiftlang/swift/pull/70791. + ./patches/0003-cmark-build-revamp.patch + # Fix compilation errors when building the SIL module during bootstrap. + # error: field has incomplete type 'clang::DeclContext::all_lookups_iterator' + # error: field has incomplete type 'clang::DeclContext::ddiag_iterator' + ./patches/0004-sil-missing-headers.patch + # Use libLTO.dylib from the LLVM built for Swift + (replaceVars ./patches/0005-specify-liblto-path.patch { + libllvm_path = lib.getLib libllvm; + }) + # Use libdispatch from nixpkgs instead of building it in-tree + ./patches/0006-use-nixpkgs-libdispatch.patch + # The Swift JIT needs help finding dylibs when they are linked into the toolchain at `$out/lib`. + (replaceVars ./patches/0007-Help-Swift-JIT-find-the-separate-stdlib-and-framewor.patch { + swiftPlatform = stdenv.hostPlatform.swift.platform; + }) + # Fix missing when building against libstdc++ 15 + (fetchpatch2 { + url = "https://github.com/swiftlang/swift/commit/a5c727125e952839c373fe47e9f9e359db3d4d38.patch?full_index=1"; + hash = "sha256-OoTcPyqTzAhkxaRAMeu+hab3yoIDRPq6YzK5hrLk4Jg="; + }) + # Fix missing null-terminator on Linux, which results in a crash in `swift repl`. + (fetchpatch2 { + url = "https://github.com/swiftlang/swift/commit/cfbe70db5d1e65bed2388f97ee52f65719c812b3.patch?full_index=1"; + hash = "sha256-XxdP3Qs2YfT20d5E216cOQy+fUgYQpwMDWSyl77NQHw="; + }) + ] + ++ lib.optionals (bootstrapStage == 0) [ + # Revert optimizer changes that cause the C++-based bootstrap compiler to be unable to compile functions with + # infinite loops that return from the loop. This doesn’t affect the later stages, so it’s applied conditionally. + # https://github.com/swiftlang/swift/pull/79186 + ./patches/0008-revert-optimizer-changes.patch + # Work around a compiler crash by partially reverting https://github.com/swiftlang/swift/pull/80920. + ./patches/0009-siloptimizer-bootstrap-workaround.patch + ] + ++ lib.optionals (bootstrapStage == 1) [ + # Stage 1 doesn’t have a compiler that supports _StringProcessing. + # This isn’t a problem on Darwin, but it fails on Linux. + ./patches/0010-Remove-dependency-on-_StringProcessing-during-stage-.patch + ]; + + postPatch = '' + # Swift doesn’t really _need_ LLVM’s build folder. It only needs to find a built LLVM, which we can provide. + substituteInPlace cmake/modules/SwiftSharedCMakeConfig.cmake \ + --replace-fail "precondition_translate_flag(LLVM_BUILD_LIBRARY_DIR LLVM_LIBRARY_DIR)" "" + + # Fix the path to LLVM’s CMake modules. + substituteInPlace lib/Basic/CMakeLists.txt \ + --replace-fail \''${LLVM_MAIN_SRC_DIR}/cmake/modules ${lib.escapeShellArg (lib.getDev libllvm)}/lib/cmake/llvm + + # Find `features.json` in Clang’s $out not LLVM’s. + substituteInPlace lib/Option/CMakeLists.txt \ + --replace-fail \''${LLVM_BINARY_DIR} ${lib.escapeShellArg (lib.getBin clang-unwrapped)} + + # Make sure Swift can find Clang’s resource dir during the build. + substituteInPlace stdlib/public/SwiftShims/swift/shims/CMakeLists.txt \ + --replace-fail \ + 'set(clang_headers_location "''${LLVM_LIBRARY_OUTPUT_INTDIR}/clang/''${CLANG_VERSION${lib.optionalString (lib.versionAtLeast finalAttrs.version "6.0") "_MAJOR"}}")' \ + 'set(clang_headers_location "${lib.getBin clang}/resource-root")' + + # Use absolute path references for `dlopen`. + substituteInPlace stdlib/public/RuntimeModule/Compression.swift \ + --replace-fail liblzma${dylibExt} ${lib.escapeShellArg (lib.getLib xz)}/lib/liblzma${dylibExt} \ + --replace-fail libz${dylibExt} ${lib.escapeShellArg (lib.getLib zlib)}/lib/libz${dylibExt} \ + --replace-fail libzstd${dylibExt} ${lib.escapeShellArg (lib.getLib zstd)}/lib/libzstd${dylibExt} + + # Make sure Swift uses the external macro plugin server built with the compiler. + substituteInPlace lib/Driver/DarwinToolChains.cpp \ + --replace-fail 'basePath, "usr", "bin", "swift-plugin-server"' "\"$out/bin/swift-plugin-server\"" + + # Only build the runtime for aarch64-darwin. Universal builds aren’t really supported in nixpkgs, + # and the dylibs in the SDK aren’t built as universal. Use `grep` to assert the change was made. + sed -i cmake/modules/SwiftConfigureSDK.cmake \ + -e 's/^\( *\)remove_sdk_unsupported_archs(.*$/\1set(SWIFT_SDK_''${prefix}_ARCHITECTURES "arm64")/' + grep -q 'set(SWIFT_SDK_''${prefix}_ARCHITECTURES "arm64")' cmake/modules/SwiftConfigureSDK.cmake + ''; + + dontFixCmake = true; + + cmakeFlags = [ + # The bootstrap is managed via Nix instead of upstream’s bootstrap-specific bootstrapping modes. + (lib.cmakeFeature "BOOTSTRAPPING_MODE" "HOSTTOOLS") + (lib.cmakeOptionType "list" "SWIFT_INSTALL_COMPONENTS" (lib.concatStringsSep ";" swiftComponents')) + # Needs to be disabled in stage 0 to enable the C++ bootstrap. + (lib.cmakeBool "SWIFT_ENABLE_SWIFT_IN_SWIFT" (bootstrapStage > 0)) + # Swift installs its dylibs to `$lib/lib/swift/host` instead of `$lib/lib`. + (lib.cmakeFeature "CMAKE_INSTALL_NAME_DIR" "${placeholder "out"}/lib/swift/host") + # Make Swift use Clang from nixpkgs instead of building its own. + (lib.cmakeBool "SWIFT_PREBUILT_CLANG" true) + (lib.cmakeFeature "SWIFT_NATIVE_CLANG_TOOLS_PATH" "${lib.getBin clang}/bin") + (lib.cmakeFeature "SWIFT_NATIVE_LLVM_TOOLS_PATH" "${lib.getBin llvm}/bin") + # Swift expects to find these relative to `$src`, but it only actually needs their final build products. + # Instead of being built in the Swift derivation, they’re built separately. This tells CMake how to find them. + (lib.cmakeFeature "Clang_DIR" "${lib.getDev libclang}/lib/cmake/clang") + (lib.cmakeFeature "LLVM_DIR" "${lib.getDev libllvm}/lib/cmake/llvm") + (lib.cmakeFeature "cmark-gfm_DIR" "${swift-cmark.out}/lib/cmake") + # Swift defaults to 10.13, which is too old. Set the deployment target to the minimum supported in nixpkgs. + (lib.cmakeFeature "SWIFT_DARWIN_DEPLOYMENT_VERSION_OSX" stdenv.hostPlatform.darwinMinVersion) + (lib.cmakeFeature "SWIFT_HOST_TRIPLE" stdenv.hostPlatform.swift.triple) + # Tests should only be built when building a regular compiler. The bootstrap compiler is not functional enough. + (lib.cmakeBool "SWIFT_INCLUDE_TESTS" doCheck) + # Swift Concurrency is needed to build the stage 1 compiler on Linux. + (lib.cmakeBool "SWIFT_ENABLE_EXPERIMENTAL_CONCURRENCY" true) + ] + ++ lib.optionals (bootstrapStage == 1) [ + # Work around crashes in ownership verifier in the bootstrap compiler. + # See https://github.com/swiftlang/swift/issues/84552#issuecomment-3409245634 + "-DCMAKE_Swift_FLAGS=-Xfrontend -disable-sil-ownership-verifier" + ] + ++ lib.optionals (bootstrapStage >= 1) [ + # These features are needed for the final build due to using unguarded macros in the SDK required to build it. + (lib.cmakeBool "SWIFT_BUILD_SWIFT_SYNTAX" true) + (lib.cmakeBool "SWIFT_ENABLE_EXPERIMENTAL_OBSERVATION" true) + (lib.cmakeBool "SWIFT_ENABLE_EXPERIMENTAL_STRING_PROCESSING" true) + # Synchronization is required to build Foundation. + (lib.cmakeBool "SWIFT_ENABLE_SYNCHRONIZATION" true) + ] + ++ lib.optionals (bootstrapStage >= 2) ( + [ + # Build Swift with LTO for better performance. Only enable it for tools. The stdlib will enable it separately. + (lib.cmakeFeature "SWIFT_TOOLS_ENABLE_LTO" "thin") + # LTO is slow with ld64. Only use it for targets that benefit from LTO. + (lib.cmakeBool "SWIFT_TOOLS_LD64_LTO_CODEGEN_ONLY_FOR_SUPPORTING_TARGETS" stdenv.hostPlatform.isDarwin) + # Enable the remaining features. + (lib.cmakeBool "SWIFT_ENABLE_BACKTRACING" true) + (lib.cmakeBool "SWIFT_ENABLE_EXPERIMENTAL_CXX_INTEROP" true) + (lib.cmakeBool "SWIFT_ENABLE_EXPERIMENTAL_DIFFERENTIABLE_PROGRAMMING" true) + (lib.cmakeBool "SWIFT_ENABLE_EXPERIMENTAL_DISTRIBUTED" true) + (lib.cmakeBool "SWIFT_ENABLE_EXPERIMENTAL_PARSER_VALIDATION" true) + (lib.cmakeBool "SWIFT_ENABLE_EXPERIMENTAL_POINTER_BOUNDS" true) + (lib.cmakeBool "SWIFT_ENABLE_EXPERIMENTAL_RUNTIME_MODULE" true) + (lib.cmakeBool "SWIFT_ENABLE_VOLATILE" true) + (lib.cmakeBool "SWIFT_ENABLE_RUNTIME_MODULE" true) + (lib.cmakeBool "SWIFT_STDLIB_ENABLE_STRICT_AVAILABILITY" true) + ] + ++ lib.optionals stdenv.cc.bintools.isGNU [ + # Use `llvm-ar` and `llvm-ranlib` when LTO is enabled, or builds will fail due missing symbol tables in archives. + # e.g., `error: lib/libswiftDemangling.a: no archive symbol table (run ranlib)`. + (lib.cmakeFeature "CMAKE_AR" (lib.getExe' llvm "llvm-ar")) + (lib.cmakeFeature "CMAKE_RANLIB" (lib.getExe' llvm "llvm-ranlib")) + # Make sure Swift is built with a consistent toolchan version. This doesn’t matter for non-LTO builds, but it causes + # LTO builds to fail when objects built with a newer Clang are processed by the Swift Clang’s libLTO. + (lib.cmakeFeature "CMAKE_C_COMPILER" (lib.getExe' clang "clang")) + (lib.cmakeFeature "CMAKE_CXX_COMPILER" (lib.getExe' clang "clang++")) + ] + ); + + env = { + # Swift uses `-apple.macosx` triples instead of `-apple-darwin`, which causes tons of warnings. + NIX_CC_WRAPPER_SUPPRESS_TARGET_WARNING = true; + NIX_CFLAGS_COMPILE = toString ( + # Swift compiles some of its stdlib for older deployment targets without using availability checks. + [ "-Wno-error=unguarded-availability" ] + # Enable fat LTO (ELF only). This allows the compiler and stdlib to built with LTO while not requiring + # dependent packages to require a linker plugin to read the LLVM bitcode. + ++ lib.optionals (bootstrapStage == 2 && stdenv.hostPlatform.isElf) [ "-ffat-lto-objects" ] + ); + }; + + preConfigure = + # Swift 6.2 needs to weakly link against `swift_coroFrameAlloc`, which is only in the 26.0 SDK. + # Unfortunately, the 26.0 SDK uses unguarded macros, so the C++ bootstrap compiler has to use the 14.4 SDK. + lib.optionalString stdenv.hostPlatform.isDarwin '' + if [ $NIX_APPLE_SDK_VERSION -lt 260000 ]; then + NIX_LDFLAGS+=" -undefined dynamic_lookup" + fi + '' + + lib.optionalString (swift-driver != null) '' + appendToVar cmakeFlags "-DSWIFT_EARLY_SWIFT_DRIVER_BUILD:PATH=${lib.escapeShellArg (lib.getBin swift-driver)}/bin" + '' + + lib.optionalString (bootstrapStage >= 1) '' + appendToVar cmakeFlags "-DSWIFT_PATH_TO_STRING_PROCESSING_SOURCE:PATH=$NIX_BUILD_TOP/swift-experimental-string-processing" + appendToVar cmakeFlags "-DSWIFT_PATH_TO_SWIFT_SYNTAX_SOURCE:PATH=$NIX_BUILD_TOP/swift-syntax" + ''; + + postConfigure = + # Make sure `swift` can locate the C and C++ standard library relative to `swift` binary in `bin`. + '' + ln -s ${lib.escapeShellArg (lib.getExe' clang "clang")} bin/clang + ''; + + strictDeps = true; + + ninjaFlags = swiftComponents'; + + nativeBuildInputs = [ + cmake + ninja + perl # For pod2man + python3 + swift + ] + ++ lib.optionals stdenv.hostPlatform.isDarwin [ + llvm_libtool + sigtool + xcbuild + ]; + + buildInputs = [ + libedit + libffi + libllvm + libxml2 + swift-cmark.out + zlib + ] + ++ lib.optionals stdenv.hostPlatform.isDarwin [ build-sdk ] + ++ lib.optionals (!stdenv.hostPlatform.isDarwin) [ + libuuid + (swift-corelibs-libdispatch.override { useSwift = false; }) + ]; + + inherit doCheck; + + postInstall = + # Swift 6 installs private Swift Syntax dylibs to $lib/lib/swift/host/compiler, which `CMAKE_INSTALL_NAME_DIR` + # mangles to the wrong paths. + # Fix up the install names of all the dylibs generated by the build process. fixupDarwinDylibNames doesn’t work. + '' + while IFS= read -d "" dylib; do + dylib_name=$(basename "$dylib") + echo "$dylib: fixing dylib" + install_name_tool "$dylib" -id "$dylib" + done < <(find "''${!outputLib}/lib/swift/host/compiler" -name '*.dylib' -print0) + readarray -t -d "" args < <( + find "''${!outputLib}/lib/swift/host/compiler" -name '*.dylib' \ + -printf "-change\0''${!outputLib}/lib/swift/host/%f\0%p\0" + ) + while IFS= read -d "" exe; do + if [[ "$exe" != *.a ]] && LC_ALL=C isMachO "$exe"; then + res=$(install_name_tool "$exe" "''${args[@]}" 2>&1) + if [[ "$res" =~ invalidate ]]; then codesign -s - -f "$exe"; fi + fi + done < <(find "$out" -type f -print0) + '' + # Swift installs some back-deployment and stdlib components as part of the compiler component. Delete them. + + lib.optionalString (stdlib != null) '' + rm -rf "''${!outputLib}/lib/swift/${swiftPlatform}" + rm -rf "''${!outputLib}/lib/swift-6.2" + rm -rf "''${!outputLib}/lib/swift_static" + '' + # Remove early Swift Driver from `$out/bin`. It will be supplied by the `swift` derivation. + + lib.optionalString (swift-driver != null) '' + declare -a swiftDriverFiles=( + swift + swift-driver + swift-help + swift-legacy-driver + swiftc + swiftc-legacy-driver + ) + for file in "''${swiftDriverFiles[@]}"; do + rm "''${!outputBin}/bin/$file" + done + ln -s swift-frontend "''${!outputBin}/bin/swift" + ln -s swift-frontend "''${!outputBin}/bin/swiftc" + '' + + lib.optionalString (bootstrapStage == 2) '' + mkdir -p "$static/lib" + + # Copy Swift compiler libraries needed by LLDB into $static. The following list should match the ones found at: + # - https://github.com/swiftlang/llvm-project/blob/swift-$swiftVersion-RELEASE/lldb/source/Plugins/ExpressionParser/Swift/CMakeLists.txt + # - https://github.com/swiftlang/llvm-project/blob/swift-$swiftVersion-RELEASE/lldb/source/Plugins/Language/Swift/CMakeLists.txt + # - https://github.com/swiftlang/llvm-project/blob/swift-$swiftVersion-RELEASE/lldb/source/Plugins/LanguageRuntime/Swift/CMakeLists.txt + # - https://github.com/swiftlang/llvm-project/blob/swift-$swiftVersion-RELEASE/lldb/source/Symbol/CMakeLists.txt + # - https://github.com/swiftlang/swift/blob/swift-$swiftVersion-RELEASE/SwiftCompilerSources/CMakeLists.txt + declare -a swiftLibs=( + libswiftAST + libswiftASTSectionImporter + libswiftBasic + libswiftClangImporter + libswiftFrontend + libswiftIDE + libswiftParse + libswiftRemoteAST + libswiftRemoteInspection + libswiftSIL + libswiftSILOptimizer + libswiftSerialization + ) + # These are dependencies of the above + declare -a swiftLibsDeps=( + lib_CompilerRegexParser + libswiftAPIDigester + libswiftASTGen + libswiftCompilerModules + libswiftConstExtract + libswiftDemangling + libswiftDriver + libswiftIDEUtilsBridging + libswiftIRGen + libswiftLLVMPasses + libswiftLocalization + libswiftMacroEvaluation + libswiftMarkup + libswiftOption + libswiftSILGen + libswiftSema + libswiftSymbolGraphGen + swift/host/compiler/lib_Compiler_SwiftLibraryPluginProviderCShims + swift/host/compiler/lib_Compiler_SwiftSyntaxCShims + swift/host/lib_SwiftLibraryPluginProviderCShims + swift/host/lib_SwiftSyntaxCShims + ) + for swiftLib in "''${swiftLibs[@]}" "''${swiftLibsDeps[@]}"; do + src=lib/$swiftLib${stdenv.hostPlatform.extensions.staticLibrary} + dest=$static/lib/$swiftLib${stdenv.hostPlatform.extensions.staticLibrary} + ninja "$(basename "$src")" # Make sure the static library was built. Some aren’t by default. + mkdir -p "$(dirname "$dest")" + cp -v "$src" "$dest" + done + # swiftCompilerStub is actually just an object file + cp SwiftCompilerSources/CMakeFiles/swiftCompilerStub.dir/stubs.cpp.o "$static/lib/stubs.cpp.o" + ''; + + postFixup = + # The Swift fork of LLDB needs several internal headers and build artifacts. These are copied in `postFixup` instead + # of in `postInstall` to prevent the multiple outputs hook from moving them to $dev. We don’t want them in + # $dev to keep the closure size down when using `swiftc` outside of buidling LLDB. + lib.optionalString (bootstrapStage == 2) '' + staticLibExt=${stdenv.hostPlatform.extensions.staticLibrary} + sharedLibExt=${stdenv.hostPlatform.extensions.sharedLibrary} + + stdlibLibPath=${lib.escapeShellArg (lib.getLib stdlib)} + stdlibDevPath=${lib.escapeShellArg (lib.getDev stdlib)} + stdlibIncPath=${lib.escapeShellArg (lib.getInclude stdlib)} + + swiftcLibPath=''${!outputLib} + swiftcDevPath=$static + swiftcIncPath=''${!outputInclude} + + swiftBinaryDir=''${!outputBin} + swiftIncludeDirs=$swiftcIncPath/include\;$stdlibIncPath/lib\;$stdlibIncPath/include\;$static/include + swiftLibraryDirs=$swiftcDevPath/lib\;$swiftcLibPath/lib\;$stdlibLibPath/lib\;$stdlibDevPath/lib + + swiftArch=${stdenv.hostPlatform.swift.arch} + swiftPlatform=${stdenv.hostPlatform.swift.platform} + + buildDir=$NIX_BUILD_TOP/$sourceRoot/build + buildType=''${cmakeBuildType:-Release} + + # Some headers reference headers from the source tree, so copy all of them. This has to be done in `postFixup` + # instead of `postInstall` to prevent the multiple outputs hook from moving them to $dev. + cp -rv include "$static" # For generated config headers. + + # When the store is on a case-insensitive filesystem, which is currently the default on Darwin for both the old + # and the new installers, this header will conflict with `$static/include/swift/Bridging`. + mv "$static/include/swift/bridging" "$static/include/swift/bridging.h" + + while IFS= read -d "" f; do + # Don’t copy build products. Only copy headers from the original source tree. + if [[ ! "$f" =~ \.\./build ]]; then + dest=$static/''${f#../} + mkdir -p "$(dirname "$dest")" + cp -v "$f" "$dest" + fi + done < <(find .. \( -name '*.def' -o -name '*.h' \) -print0) + + # Fix up any references to `swift/bridging`, which was renamed above. + while IFS= read -d "" f; do + substituteInPlace "$f" --replace-fail 'swift/bridging' 'swift/bridging.h' + done < <(grep -rlz 'include.*swift/bridging' "$static") + + # Copy the Swift CMake config but fix it up to point to the store instead of to the source folder. + # This also has to be done here to avoid having them moved to $dev. + mkdir -p "$static/lib/cmake/modules" + cp -rv lib/cmake/swift "$static/lib/cmake" + + # Clean up the config paths and drop the main source location (because it references the build folder). + # The `find_package` is because our Swift builds against an external swift-cmark, which dependents + # need to be able to find and use as well. Otherwise, they try to link liblibcmark-gfm, which is wrong. + sed -i "$static/lib/cmake/swift/SwiftConfig.cmake" \ + -e '1i find_package(cmark-gfm)' \ + -e "2i set(SWIFT_STDLIB_DIR \"$stdlibLibPath/lib\")" \ + -e '/SWIFT_MAIN_SRC_DIR/d' \ + -e "/SWIFT_BINARY_DIR /c set(SWIFT_BINARY_DIR \"$swiftBinaryDir\")" \ + -e "/SWIFT_INCLUDE_DIR /c set(SWIFT_INCLUDE_DIR \"$swiftIncludeDirs\")" \ + -e "/SWIFT_INCLUDE_DIRS /c set(SWIFT_INCLUDE_DIRS \"$swiftIncludeDirs\")" \ + -e "/SWIFT_LIBRARY_DIR /c set(SWIFT_LIBRARY_DIR \"$swiftLibraryDirs\")" \ + -e "/SWIFT_LIBRARY_DIRS /c set(SWIFT_LIBRARY_DIRS \"$swiftLibraryDirs\")" \ + -e "/SWIFT_CMAKE_DIR /c set(SWIFT_CMAKE_DIR \"$static/lib/cmake/modules\")" \ + -e "/include(\"''${NIX_BUILD_TOP//\//\\\/}/c include(\"$static/lib/cmake/swift/SwiftExports.cmake\")" + + # Change exports to point to the locations in the store. This is a ugly because the exports could be in + # one of several outputs belong to different derivations. + sed -i "$static/lib/cmake/swift/SwiftExports.cmake" \ + -e "s|IMPORTED_LOCATION_''${buildType^^} \"$buildDir/lib/swift/$swiftPlatform/$swiftArch/\(.*$sharedLibExt\)\"|IMPORTED_LOCATION_''${buildType^^} \"$stdlibLibPath/lib/\1\"|g" \ + -e "s|IMPORTED_LOCATION_''${buildType^^} \"$buildDir/lib/swift/$swiftPlatform/$swiftArch/\(.*$staticLibExt\)\"|IMPORTED_LOCATION_''${buildType^^} \"$stdlibDevPath/lib/\1\"|g" \ + -e "s|IMPORTED_LOCATION_''${buildType^^} \"$buildDir/lib/\(swift-[^/]*\)/$swiftPlatform/$swiftArch/\([^/\"]*\)\"|IMPORTED_LOCATION_''${buildType^^} \"$stdlibLibPath/lib/\1/\2\"|g" \ + -e "s|IMPORTED_LOCATION_''${buildType^^} \"$buildDir/lib/swift/host/\(.*$sharedLibExt\)\"|IMPORTED_LOCATION_''${buildType^^} \"$swiftcLibPath/lib/swift/host/\1\"|g" \ + -e "s|IMPORTED_LOCATION_''${buildType^^} \"$buildDir/lib/swift/host/\(.*$staticLibExt\)\"|IMPORTED_LOCATION_''${buildType^^} \"$swiftcDevPath/lib/swift/host/\1\"|g" \ + -e "s|IMPORTED_LOCATION_''${buildType^^} \"$buildDir/lib/\(lib_Internal[^/\"]*\)\"|IMPORTED_LOCATION_''${buildType^^} \"$swiftcLibPath/lib/swift/host/compiler/\1\"|g" \ + -e "s|IMPORTED_LOCATION_''${buildType^^} \"$buildDir/lib/\(.*$sharedLibExt\)\"|IMPORTED_LOCATION_''${buildType^^} \"$swiftcLibPath/lib/\1\"|g" \ + -e "s|IMPORTED_LOCATION_''${buildType^^} \"$buildDir/lib/\(.*.framework/[^\"]*\)\"|IMPORTED_LOCATION_''${buildType^^} \"$swiftcLibPath/lib/\1\"|g" \ + -e "s|IMPORTED_LOCATION_''${buildType^^} \"$buildDir/lib/\(.*$staticLibExt\)\"|IMPORTED_LOCATION_''${buildType^^} \"$swiftcDevPath/lib/\1\"|g" \ + -e "s|IMPORTED_LOCATION_''${buildType^^} \"$buildDir/bin/\([^/\"]*\)\"|IMPORTED_LOCATION_''${buildType^^} \"$swiftBinaryDir/bin/\1\"|g" \ + -e "s|IMPORTED_OBJECTS_''${buildType^^} \"$buildDir/.*/\([^/\"]*.o\)\"|IMPORTED_OBJECTS_''${buildType^^} \"$swiftcDevPath/lib\/\1\"|g" \ + -e "/INTERFACE_INCLUDE_DIRECTORIES/c INTERFACE_INCLUDE_DIRECTORIES \"$swiftIncludeDirs\"" \ + -e "/INTERFACE_LINK_DIRECTORIES/c INTERFACE_LINK_DIRECTORIES \"$swiftLibraryDirs\"" + + # Copy SwiftAddCustomCommandTarget and its required support module (SwiftUtils), which is needed by LLDB. + cp -v ../cmake/modules/SwiftUtils.cmake "$static/lib/cmake/modules/SwiftUtils.cmake" + cp -v ../cmake/modules/SwiftAddCustomCommandTarget.cmake "$static/lib/cmake/modules/SwiftAddCustomCommandTarget.cmake" + ''; + + passthru.supportsMacros = bootstrapStage >= 1; + + __structuredAttrs = true; + + meta = { + description = "Swift Programming Language"; + homepage = "https://github.com/swiftlang/swift"; + mainProgram = "swiftc"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + badPlatforms = [ lib.systems.inspect.patterns.is32bit ]; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0001-Read-C-and-C-stdlib-flags-from-the-wrapped-compiler.patch b/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0001-Read-C-and-C-stdlib-flags-from-the-wrapped-compiler.patch new file mode 100644 index 000000000000..7f8aacde44a1 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0001-Read-C-and-C-stdlib-flags-from-the-wrapped-compiler.patch @@ -0,0 +1,196 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sun, 4 Jan 2026 14:37:05 -0500 +Subject: [PATCH 01/10] Read C and C++ stdlib flags from the wrapped compiler +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +On most platforms supported by Nixpkgs, the C and C++ standard libraries +are located separately and are not part of the sysroot, but Swift’s +ClangImporter assumes they are part of the sysroot by default. + +While it is possible to create a sysroot for use with Swift, this has +negative affects on every package that wants to use Swift and compile +C++ code. The C++ library must be removed from the standard platform +configuration, which makes adding Swift as a dependency too disruptive. +--- + include/swift/ClangImporter/ClangImporter.h | 3 +- + lib/ClangImporter/ClangImporter.cpp | 8 ++++ + lib/ClangImporter/ClangIncludePaths.cpp | 18 ++++++-- + lib/ClangImporter/ClangIncludePaths.h | 51 +++++++++++++++++++++ + lib/Frontend/CompilerInvocation.cpp | 2 +- + 5 files changed, 76 insertions(+), 6 deletions(-) + +diff --git a/include/swift/ClangImporter/ClangImporter.h b/include/swift/ClangImporter/ClangImporter.h +index 274c659d54c..d478fbbccec 100644 +--- a/include/swift/ClangImporter/ClangImporter.h ++++ b/include/swift/ClangImporter/ClangImporter.h +@@ -231,7 +231,8 @@ public: + static llvm::opt::InputArgList + createClangArgs(const ClangImporterOptions &ClangImporterOpts, + const SearchPathOptions &SearchPathOpts, +- clang::driver::Driver &clangDriver); ++ clang::driver::Driver &clangDriver, ++ bool enableCXXInterop); + + ClangImporter(const ClangImporter &) = delete; + ClangImporter(ClangImporter &&) = delete; +diff --git a/lib/ClangImporter/ClangImporter.cpp b/lib/ClangImporter/ClangImporter.cpp +index 47361b38a0f..1b50ea3ab44 100644 +--- a/lib/ClangImporter/ClangImporter.cpp ++++ b/lib/ClangImporter/ClangImporter.cpp +@@ -564,7 +564,15 @@ void importer::getNormalInvocationArguments( + }); + } + ++ // Ensure libc is available. The C standard library is separate from the sysroot ++ // on most platforms in Nixpkgs. (Darwin is a prominent exception.) ++ addFlagsFromNixCC(invocationArgStrs, "libc-cflags"); ++ + if (LangOpts.EnableCXXInterop) { ++ // Ensure the libc++ headers are available. The C++ standard library is separate ++ // from the sysroot on most platforms in Nixpkgs. ++ addFlagsFromNixCC(invocationArgStrs, "libcxx-cxxflags"); ++ + if (auto path = getCxxShimModuleMapPath(searchPathOpts, LangOpts, triple)) { + invocationArgStrs.push_back((Twine("-fmodule-map-file=") + *path).str()); + } +diff --git a/lib/ClangImporter/ClangIncludePaths.cpp b/lib/ClangImporter/ClangIncludePaths.cpp +index 948b99876f0..b46ec2980f0 100644 +--- a/lib/ClangImporter/ClangIncludePaths.cpp ++++ b/lib/ClangImporter/ClangIncludePaths.cpp +@@ -178,12 +178,22 @@ static std::optional findFirstIncludeDir( + llvm::opt::InputArgList + ClangImporter::createClangArgs(const ClangImporterOptions &ClangImporterOpts, + const SearchPathOptions &SearchPathOpts, +- clang::driver::Driver &clangDriver) { ++ clang::driver::Driver &clangDriver, ++ bool enableCXXInterop) { + // Flags passed to Swift with `-Xcc` might affect include paths. + std::vector clangArgs; + for (const auto &each : ClangImporterOpts.ExtraArgs) { + clangArgs.push_back(each.c_str()); + } ++ ++ // Ensure libc is available. The C standard library is separate from the sysroot ++ // on most platforms in Nixpkgs. (Darwin is a prominent exception.) ++ addFlagsFromNixCC(clangArgs, "libc-cflags"); ++ ++ if (enableCXXInterop) { ++ addFlagsFromNixCC(clangArgs, "libcxx-cxxflags"); ++ } ++ + llvm::opt::InputArgList clangDriverArgs = + parseClangDriverArgs(clangDriver, clangArgs); + // If an SDK path was explicitly passed to Swift, make sure to pass it to +@@ -207,7 +217,7 @@ getLibcFileMapping(const ASTContext &ctx, StringRef modulemapFileName, + auto [clangDriver, clangDiagEngine] = ClangImporter::createClangDriver( + ctx.LangOpts, ctx.ClangImporterOpts, vfs); + auto clangDriverArgs = ClangImporter::createClangArgs( +- ctx.ClangImporterOpts, ctx.SearchPathOpts, clangDriver); ++ ctx.ClangImporterOpts, ctx.SearchPathOpts, clangDriver, ctx.LangOpts.EnableCXXInterop); + + llvm::opt::ArgStringList includeArgStrings; + const auto &clangToolchain = +@@ -286,7 +296,7 @@ static void getLibStdCxxFileMapping( + auto [clangDriver, clangDiagEngine] = ClangImporter::createClangDriver( + ctx.LangOpts, ctx.ClangImporterOpts, vfs); + auto clangDriverArgs = ClangImporter::createClangArgs( +- ctx.ClangImporterOpts, ctx.SearchPathOpts, clangDriver); ++ ctx.ClangImporterOpts, ctx.SearchPathOpts, clangDriver, ctx.LangOpts.EnableCXXInterop); + + llvm::opt::ArgStringList stdlibArgStrings; + const auto &clangToolchain = +@@ -467,7 +477,7 @@ void GetWindowsFileMappings( + auto [Driver, clangDiagEngine] = ClangImporter::createClangDriver( + Context.LangOpts, Context.ClangImporterOpts, driverVFS); + const llvm::opt::InputArgList Args = ClangImporter::createClangArgs( +- Context.ClangImporterOpts, Context.SearchPathOpts, Driver); ++ Context.ClangImporterOpts, Context.SearchPathOpts, Driver, Context.LangOpts.EnableCXXInterop); + const clang::driver::ToolChain &ToolChain = Driver.getToolChain(Args, Triple); + llvm::vfs::FileSystem &VFS = ToolChain.getVFS(); + +diff --git a/lib/ClangImporter/ClangIncludePaths.h b/lib/ClangImporter/ClangIncludePaths.h +index 7f08397fa7d..69be98357d9 100644 +--- a/lib/ClangImporter/ClangIncludePaths.h ++++ b/lib/ClangImporter/ClangIncludePaths.h +@@ -14,6 +14,8 @@ + #define SWIFT_CLANG_INCLUDE_PATHS_H + + #include "swift/AST/ASTContext.h" ++#include "llvm/ADT/StringRef.h" ++#include "llvm/Support/CommandLine.h" + + namespace swift { + +@@ -23,4 +25,53 @@ getCxxShimModuleMapPath(SearchPathOptions &opts, const LangOptions &langOpts, + + } // namespace swift + ++template ++void addFlagsFromNixCC(std::vector &invocationArgStrs, const char* flagFile) { ++ auto swiftPath = llvm::sys::fs::getMainExecutable(nullptr, nullptr); ++ ++ if (swiftPath != "") { ++ llvm::BumpPtrAllocator allocator; ++ llvm::StringSaver saver(allocator); ++ ++ // Read `flagFile` from Clang’s `nix-support` folder by finding it relative to the store ++ // location of `clang`, which is expected to be adjacent to Swift in `$out/bin`. ++ llvm::SmallString<256> clangPath = llvm::StringRef(swiftPath); ++ llvm::sys::path::remove_filename(clangPath); ++ llvm::sys::path::append(clangPath, "clang"); ++ ++ llvm::SmallString<256> path; ++ ++ // This shouldn’t happen, but if `real_path` fails to resolve `clang`, give up. ++ if (llvm::sys::fs::real_path(clangPath, path, /*expand_tilde*/ true)) { return; } ++ ++ llvm::sys::path::remove_filename(path); ++ llvm::sys::path::remove_filename(path); ++ llvm::sys::path::append(path, "nix-support", flagFile); ++ ++ // Treat `flagFile` as a response file for Clang. Because Clang expects response ++ // files to be expanded already at this point, it has to be expanded manually. ++ if (auto buffer = llvm::vfs::getRealFileSystem()->getBufferForFile(path)) { ++ auto contents = (*buffer)->getMemBufferRef().getBuffer(); ++ llvm::SmallVector args; ++#if _WIN32 ++ llvm::cl::TokenizeWindowsCommandLineNoCopy(contents, saver, args); ++#else ++ llvm::cl::TokenizeGNUCommandLine(contents, saver, args); ++#endif ++ for (auto arg : args) { ++ auto arg_str = [&arg = arg]() constexpr { ++ if constexpr (std::is_same::value) { ++ // This leaks, but there doesn’t seem to be a better way. ++ auto len = std::strlen(arg) + 1; ++ return std::strncpy(new char[len], arg, len); ++ } else { ++ return arg; ++ } ++ }(); ++ invocationArgStrs.push_back(arg_str); ++ } ++ } ++ } ++} ++ + #endif // SWIFT_CLANG_INCLUDE_PATHS_H +diff --git a/lib/Frontend/CompilerInvocation.cpp b/lib/Frontend/CompilerInvocation.cpp +index ed413f2be91..f866b49ba3a 100644 +--- a/lib/Frontend/CompilerInvocation.cpp ++++ b/lib/Frontend/CompilerInvocation.cpp +@@ -401,7 +401,7 @@ void CompilerInvocation::computeCXXStdlibOptions() { + auto [clangDriver, clangDiagEngine] = + ClangImporter::createClangDriver(LangOpts, ClangImporterOpts); + auto clangDriverArgs = ClangImporter::createClangArgs( +- ClangImporterOpts, SearchPathOpts, clangDriver); ++ ClangImporterOpts, SearchPathOpts, clangDriver, LangOpts.EnableCXXInterop); + auto &clangToolchain = + clangDriver.getToolChain(clangDriverArgs, LangOpts.Target); + auto cxxStdlibKind = clangToolchain.GetCXXStdlibType(clangDriverArgs); +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/compiler/patches/swift-linux-fix-libc-paths.patch b/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0002-Use-Nixpkgs-C-and-C-stdlib-paths-in-ClangImporter.patch similarity index 56% rename from pkgs/development/compilers/swift/compiler/patches/swift-linux-fix-libc-paths.patch rename to pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0002-Use-Nixpkgs-C-and-C-stdlib-paths-in-ClangImporter.patch index 61915c66f503..65f9552f0a0f 100644 --- a/pkgs/development/compilers/swift/compiler/patches/swift-linux-fix-libc-paths.patch +++ b/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0002-Use-Nixpkgs-C-and-C-stdlib-paths-in-ClangImporter.patch @@ -1,19 +1,30 @@ -This code injects an LLVM modulemap for glibc and libstdc++ by overriding -specific VFS paths. In order to do that, it needs to know the actual locations -of glibc and libstdc++, but it only searches `-sysroot` and fails. Here we -patch it to also consider `-idirafter` and `-isystem` as added by cc-wrapper. +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sun, 4 Jan 2026 14:37:05 -0500 +Subject: [PATCH 02/10] Use Nixpkgs C and C++ stdlib paths in ClangImporter +This code injects an LLVM modulemap for glibc and libstdc++ by +overriding specific VFS paths. In order to do that, it needs to know the +actual locations of glibc and libstdc++, but it only searches `-sysroot` +and fails. Here we patch it to also consider `-idirafter` and `-isystem` +as added by cc-wrapper. +--- + lib/ClangImporter/ClangIncludePaths.cpp | 13 +++++++++++-- + 1 file changed, 11 insertions(+), 2 deletions(-) + +diff --git a/lib/ClangImporter/ClangIncludePaths.cpp b/lib/ClangImporter/ClangIncludePaths.cpp +index b46ec2980f0..9099b3066ab 100644 --- a/lib/ClangImporter/ClangIncludePaths.cpp +++ b/lib/ClangImporter/ClangIncludePaths.cpp -@@ -142,6 +142,7 @@ +@@ -144,6 +144,7 @@ ClangImporter::createClangDriver( /// \return a path without dots (`../`, './'). - static llvm::Optional findFirstIncludeDir( + static std::optional findFirstIncludeDir( const llvm::opt::InputArgList &args, + const llvm::opt::ArgList &DriverArgs, const ArrayRef expectedFileNames, const llvm::IntrusiveRefCntPtr &vfs) { // C++ stdlib paths are added as `-internal-isystem`. -@@ -151,6 +152,14 @@ +@@ -153,6 +154,14 @@ static std::optional findFirstIncludeDir( llvm::append_range(includeDirs, args.getAllArgValues( clang::driver::options::OPT_internal_externc_isystem)); @@ -28,17 +39,17 @@ patch it to also consider `-idirafter` and `-isystem` as added by cc-wrapper. for (const auto &includeDir : includeDirs) { Path dir(includeDir); -@@ -218,7 +227,7 @@ +@@ -231,7 +240,7 @@ getLibcFileMapping(const ASTContext &ctx, StringRef modulemapFileName, // modulemap are present. - Path glibcDir; + Path libcDir; if (auto dir = findFirstIncludeDir( - parsedIncludeArgs, {"inttypes.h", "unistd.h", "stdint.h"}, vfs)) { + parsedIncludeArgs, clangDriverArgs, {"inttypes.h", "unistd.h", "stdint.h"}, vfs)) { - glibcDir = dir.value(); + libcDir = dir.value(); } else { - ctx.Diags.diagnose(SourceLoc(), diag::glibc_not_found, triple.str()); -@@ -276,7 +285,7 @@ - auto parsedStdlibArgs = parseClangDriverArgs(clangDriver, stdlibArgStrings); + if (!suppressDiagnostic) +@@ -312,7 +321,7 @@ static void getLibStdCxxFileMapping( + return; Path cxxStdlibDir; - if (auto dir = findFirstIncludeDir(parsedStdlibArgs, @@ -46,3 +57,6 @@ patch it to also consider `-idirafter` and `-isystem` as added by cc-wrapper. {"cstdlib", "string", "vector"}, vfs)) { cxxStdlibDir = dir.value(); } else { +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0003-cmark-build-revamp.patch b/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0003-cmark-build-revamp.patch new file mode 100644 index 000000000000..2d43885b8bdb --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0003-cmark-build-revamp.patch @@ -0,0 +1,58 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sun, 4 Jan 2026 14:38:01 -0500 +Subject: [PATCH 03/10] cmark-build-revamp + +--- + cmake/modules/SwiftSharedCMakeConfig.cmake | 28 ---------------------- + 1 file changed, 28 deletions(-) + +diff --git a/cmake/modules/SwiftSharedCMakeConfig.cmake b/cmake/modules/SwiftSharedCMakeConfig.cmake +index ff552d65a90..3bbd6a13262 100644 +--- a/cmake/modules/SwiftSharedCMakeConfig.cmake ++++ b/cmake/modules/SwiftSharedCMakeConfig.cmake +@@ -198,33 +198,6 @@ macro(swift_common_standalone_build_config_clang product) + include_directories(${CLANG_INCLUDE_DIRS}) + endmacro() + +-macro(swift_common_standalone_build_config_cmark product) +- set(${product}_PATH_TO_CMARK_SOURCE "${${product}_PATH_TO_CMARK_SOURCE}" +- CACHE PATH "Path to CMark source code.") +- set(${product}_PATH_TO_CMARK_BUILD "${${product}_PATH_TO_CMARK_BUILD}" +- CACHE PATH "Path to the directory where CMark was built.") +- set(${product}_CMARK_LIBRARY_DIR "${${product}_CMARK_LIBRARY_DIR}" CACHE PATH +- "Path to the directory where CMark was installed.") +- get_filename_component(PATH_TO_CMARK_BUILD "${${product}_PATH_TO_CMARK_BUILD}" +- ABSOLUTE) +- get_filename_component(CMARK_MAIN_SRC_DIR "${${product}_PATH_TO_CMARK_SOURCE}" +- ABSOLUTE) +- get_filename_component(CMARK_LIBRARY_DIR "${${product}_CMARK_LIBRARY_DIR}" +- ABSOLUTE) +- +- set(CMARK_MAIN_INCLUDE_DIR "${CMARK_MAIN_SRC_DIR}/src/include") +- set(CMARK_BUILD_INCLUDE_DIR "${PATH_TO_CMARK_BUILD}/src") +- +- file(TO_CMAKE_PATH "${CMARK_MAIN_INCLUDE_DIR}" CMARK_MAIN_INCLUDE_DIR) +- file(TO_CMAKE_PATH "${CMARK_BUILD_INCLUDE_DIR}" CMARK_BUILD_INCLUDE_DIR) +- +- include_directories("${CMARK_MAIN_INCLUDE_DIR}" +- "${CMARK_BUILD_INCLUDE_DIR}") +- +- include(${PATH_TO_CMARK_BUILD}/src/cmarkTargets.cmake) +- add_definitions(-DCMARK_STATIC_DEFINE) +-endmacro() +- + # Common cmake project config for standalone builds. + # + # Parameters: +@@ -235,7 +208,6 @@ macro(swift_common_standalone_build_config product) + swift_common_standalone_build_config_llvm(${product}) + if(SWIFT_INCLUDE_TOOLS) + swift_common_standalone_build_config_clang(${product}) +- swift_common_standalone_build_config_cmark(${product}) + endif() + + # Enable groups for IDE generators (Xcode and MSVC). +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0004-sil-missing-headers.patch b/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0004-sil-missing-headers.patch new file mode 100644 index 000000000000..12e9e1df17a9 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0004-sil-missing-headers.patch @@ -0,0 +1,29 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sun, 4 Jan 2026 14:46:08 -0500 +Subject: [PATCH 04/10] sil-missing-headers + +Fix compilation errors when building the SIL module during bootstrap. + + error: field has incomplete type 'clang::DeclContext::all_lookups_iterator' + error: field has incomplete type 'clang::DeclContext::ddiag_iterator' +--- + include/swift/AST/ASTBridging.h | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/include/swift/AST/ASTBridging.h b/include/swift/AST/ASTBridging.h +index 115d6849866..deeb500e3b3 100644 +--- a/include/swift/AST/ASTBridging.h ++++ b/include/swift/AST/ASTBridging.h +@@ -24,6 +24,8 @@ + #ifdef USED_IN_CPP_SOURCE + #include "swift/AST/Attr.h" + #include "swift/AST/Decl.h" ++#include "clang/AST/DeclLookups.h" ++#include "clang/AST/DependentDiagnostic.h" + #endif + + SWIFT_BEGIN_NULLABILITY_ANNOTATIONS +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0005-specify-liblto-path.patch b/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0005-specify-liblto-path.patch new file mode 100644 index 000000000000..fab4599628c1 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0005-specify-liblto-path.patch @@ -0,0 +1,44 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sun, 4 Jan 2026 14:47:06 -0500 +Subject: [PATCH 05/10] specify-liblto-path + +--- + cmake/modules/UnixCompileRules.cmake | 2 +- + lib/Driver/DarwinToolChains.cpp | 7 ++----- + 2 files changed, 3 insertions(+), 6 deletions(-) + +diff --git a/cmake/modules/UnixCompileRules.cmake b/cmake/modules/UnixCompileRules.cmake +index 06a597b5ebb..e9086801408 100644 +--- a/cmake/modules/UnixCompileRules.cmake ++++ b/cmake/modules/UnixCompileRules.cmake +@@ -18,7 +18,7 @@ set(CMAKE_CXX_ARCHIVE_FINISH "") + # just-built bitcode format. So let's instead ask ar/ranlib/libtool to use the + # just-built libLTO.dylib from the toolchain that we're using to build. + if(APPLE AND SWIFT_NATIVE_CLANG_TOOLS_PATH) +- set(liblto_path "${SWIFT_NATIVE_CLANG_TOOLS_PATH}/../lib/libLTO.dylib") ++ set(liblto_path "@libllvm_path@/lib/libLTO.dylib") + + set(CMAKE_C_ARCHIVE_CREATE "${CMAKE_COMMAND} -E env LIBLTO_PATH=${liblto_path} crs ") + set(CMAKE_C_ARCHIVE_APPEND "${CMAKE_COMMAND} -E env LIBLTO_PATH=${liblto_path} qs ") +diff --git a/lib/Driver/DarwinToolChains.cpp b/lib/Driver/DarwinToolChains.cpp +index 7d4d7d61071..832c2dffde3 100644 +--- a/lib/Driver/DarwinToolChains.cpp ++++ b/lib/Driver/DarwinToolChains.cpp +@@ -270,11 +270,8 @@ void toolchains::Darwin::addLTOLibArgs(ArgStringList &Arguments, + Arguments.push_back("-lto_library"); + Arguments.push_back(context.Args.MakeArgString(context.OI.LibLTOPath)); + } else { +- // Check for relative libLTO.dylib. This would be the expected behavior in an +- // Xcode toolchain. +- StringRef P = llvm::sys::path::parent_path(getDriver().getSwiftProgramPath()); +- llvm::SmallString<128> LibLTOPath(P); +- llvm::sys::path::remove_filename(LibLTOPath); // Remove '/bin' ++ // Use the LTO dylib from the LLVM built for Swift. ++ llvm::SmallString<128> LibLTOPath("@libllvm_path@"); + llvm::sys::path::append(LibLTOPath, "lib"); + llvm::sys::path::append(LibLTOPath, "libLTO.dylib"); + if (llvm::sys::fs::exists(LibLTOPath)) { +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0006-use-nixpkgs-libdispatch.patch b/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0006-use-nixpkgs-libdispatch.patch new file mode 100644 index 000000000000..60712b733a5d --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0006-use-nixpkgs-libdispatch.patch @@ -0,0 +1,70 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Fri, 13 Feb 2026 20:51:47 -0500 +Subject: [PATCH 06/10] use-nixpkgs-libdispatch + +--- + CMakeLists.txt | 10 ++-------- + stdlib/cmake/modules/StdlibOptions.cmake | 3 --- + stdlib/public/Concurrency/CMakeLists.txt | 3 --- + 3 files changed, 2 insertions(+), 14 deletions(-) + +diff --git a/CMakeLists.txt b/CMakeLists.txt +index e4cbfb844e0..c6ea0234823 100644 +--- a/CMakeLists.txt ++++ b/CMakeLists.txt +@@ -853,12 +853,6 @@ if(SWIFT_ENABLE_DISPATCH AND NOT CMAKE_SYSTEM_NAME STREQUAL "Darwin") + if(SWIFT_INCLUDE_TOOLS AND SWIFT_BUILD_SOURCEKIT) + set(SWIFT_BUILD_HOST_DISPATCH TRUE) + endif() +- +- if(SWIFT_BUILD_HOST_DISPATCH) +- if(NOT EXISTS "${SWIFT_PATH_TO_LIBDISPATCH_SOURCE}") +- message(SEND_ERROR "SourceKit requires libdispatch on non-Darwin hosts. Please specify SWIFT_PATH_TO_LIBDISPATCH_SOURCE") +- endif() +- endif() + endif() + + file(STRINGS "utils/availability-macros.def" SWIFT_STDLIB_AVAILABILITY_DEFINITIONS) +@@ -1492,8 +1486,8 @@ if (LLVM_ENABLE_DOXYGEN) + message(STATUS "Doxygen: enabled") + endif() + +-if(SWIFT_ENABLE_DISPATCH) +- include(Libdispatch) ++if(SWIFT_ENABLE_DISPATCH AND NOT CMAKE_SYSTEM_NAME STREQUAL "Darwin") ++ find_package(dispatch) + endif() + + # Add all of the subdirectories, where we actually do work. +diff --git a/stdlib/cmake/modules/StdlibOptions.cmake b/stdlib/cmake/modules/StdlibOptions.cmake +index 24d1b836211..b3a105180ce 100644 +--- a/stdlib/cmake/modules/StdlibOptions.cmake ++++ b/stdlib/cmake/modules/StdlibOptions.cmake +@@ -221,9 +221,6 @@ if (SWIFT_ENABLE_EXPERIMENTAL_CONCURRENCY) + + if (SWIFT_ENABLE_DISPATCH) + set(SWIFT_CONCURRENCY_USES_DISPATCH TRUE) +- if (NOT CMAKE_SYSTEM_NAME STREQUAL "Darwin" AND NOT EXISTS "${SWIFT_PATH_TO_LIBDISPATCH_SOURCE}") +- message(SEND_ERROR "Concurrency requires libdispatch on non-Darwin hosts. Please specify SWIFT_PATH_TO_LIBDISPATCH_SOURCE") +- endif() + endif() + + if(SWIFT_CONCURRENCY_USES_DISPATCH) +diff --git a/stdlib/public/Concurrency/CMakeLists.txt b/stdlib/public/Concurrency/CMakeLists.txt +index d3a5011058c..fb037e40bbb 100644 +--- a/stdlib/public/Concurrency/CMakeLists.txt ++++ b/stdlib/public/Concurrency/CMakeLists.txt +@@ -25,9 +25,6 @@ set(swift_concurrency_incorporate_object_libraries_so swiftThreading) + + if("${SWIFT_CONCURRENCY_GLOBAL_EXECUTOR}" STREQUAL "dispatch") + if(NOT CMAKE_SYSTEM_NAME STREQUAL "Darwin") +- include_directories(AFTER +- ${SWIFT_PATH_TO_LIBDISPATCH_SOURCE}) +- + # FIXME: we can't rely on libdispatch having been built for the + # target at this point in the process. Currently, we're relying + # on soft-linking. +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0007-Help-Swift-JIT-find-the-separate-stdlib-and-framewor.patch b/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0007-Help-Swift-JIT-find-the-separate-stdlib-and-framewor.patch new file mode 100644 index 000000000000..afc2e5b470a4 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0007-Help-Swift-JIT-find-the-separate-stdlib-and-framewor.patch @@ -0,0 +1,49 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Wed, 15 Jul 2026 00:02:16 -0400 +Subject: [PATCH 07/10] Help Swift JIT find the separate stdlib and frameworks + +This is needed because the stdlib and several frameworks are all built +separately then symlinked into the final Swift toolchain. +--- + lib/Immediate/Immediate.cpp | 17 +++++++++++++++++ + 1 file changed, 17 insertions(+) + +diff --git a/lib/Immediate/Immediate.cpp b/lib/Immediate/Immediate.cpp +index 7d24b0d473e..bfd8ae3a129 100644 +--- a/lib/Immediate/Immediate.cpp ++++ b/lib/Immediate/Immediate.cpp +@@ -45,6 +45,8 @@ + #include "llvm/Support/Path.h" + #include "llvm/Transforms/IPO.h" + ++#include ++ + // TODO: Replace pass manager + // Removed in: d623b2f95fd559901f008a0588dddd0949a8db01 + /* #include "llvm/Transforms/IPO/PassManagerBuilder.h" */ +@@ -83,6 +85,21 @@ static void *loadRuntimeLib(StringRef sharedLibName, + for (auto &runtimeLibPath : runtimeLibPaths) { + if (void *handle = loadRuntimeLibAtPath(sharedLibName, runtimeLibPath)) + return handle; ++ else { ++ // Runtime libraries may also be located in `lib` for `lib/swift/`. ++ std::filesystem::path libPath = runtimeLibPath; ++ ++ if (libPath.filename() != "@swiftPlatform@") ++ continue; ++ libPath = libPath.parent_path(); ++ ++ if (libPath.filename() != "swift") ++ continue; ++ libPath = libPath.parent_path(); ++ ++ if (void *handle = loadRuntimeLibAtPath(sharedLibName, libPath.string())) ++ return handle; ++ } + } + return nullptr; + } +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0008-revert-optimizer-changes.patch b/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0008-revert-optimizer-changes.patch new file mode 100644 index 000000000000..07000cf9ec55 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0008-revert-optimizer-changes.patch @@ -0,0 +1,981 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sun, 4 Jan 2026 14:40:44 -0500 +Subject: [PATCH 08/10] revert-optimizer-changes + +We need to restore several optimizations that were removed to Swift +because otherwise the C++-only bootstrap driver will crash when building +Swift Compiler Driver and its dependencies for early-swift-driver. +--- + .../swift/SILOptimizer/PassManager/Passes.def | 2 + + .../swift/SILOptimizer/Utils/InstOptUtils.h | 5 + + .../Mandatory/PredictableMemOpt.cpp | 820 ++++++++++++++++++ + lib/SILOptimizer/PassManager/PassPipeline.cpp | 2 +- + 4 files changed, 828 insertions(+), 1 deletion(-) + +diff --git a/include/swift/SILOptimizer/PassManager/Passes.def b/include/swift/SILOptimizer/PassManager/Passes.def +index c9a500bbb66..b97790ba1f3 100644 +--- a/include/swift/SILOptimizer/PassManager/Passes.def ++++ b/include/swift/SILOptimizer/PassManager/Passes.def +@@ -381,6 +381,8 @@ LEGACY_PASS(PerformanceConstantPropagation, "performance-constant-propagation", + "Constant Propagation for Performance without Diagnostics") + LEGACY_PASS(PerformanceDiagnostics, "performance-diagnostics", + "Constant Propagation for Performance without Diagnostics") ++LEGACY_PASS(PredictableMemoryAccessOptimizations, "predictable-memaccess-opts", ++ "Predictable Memory Access Optimizations for Diagnostics") + LEGACY_PASS(PredictableDeadAllocationElimination, "predictable-deadalloc-elim", + "Eliminate dead temporary allocations after diagnostics") + LEGACY_PASS(RedundantPhiElimination, "redundant-phi-elimination", +diff --git a/include/swift/SILOptimizer/Utils/InstOptUtils.h b/include/swift/SILOptimizer/Utils/InstOptUtils.h +index d48e78938da..71805e93abf 100644 +--- a/include/swift/SILOptimizer/Utils/InstOptUtils.h ++++ b/include/swift/SILOptimizer/Utils/InstOptUtils.h +@@ -592,6 +592,11 @@ bool tryEliminateOnlyOwnershipUsedForwardingInst( + IntegerLiteralInst *optimizeBuiltinCanBeObjCClass(BuiltinInst *bi, + SILBuilder &builder); + ++/// Performs "predictable" memory access optimizations. ++/// ++/// See the PredictableMemoryAccessOptimizations pass. ++bool optimizeMemoryAccesses(SILFunction *fn); ++ + /// Performs "predictable" dead allocation optimizations. + /// + /// See the PredictableDeadAllocationElimination pass. +diff --git a/lib/SILOptimizer/Mandatory/PredictableMemOpt.cpp b/lib/SILOptimizer/Mandatory/PredictableMemOpt.cpp +index 20e0211c91b..8f57ce653c0 100644 +--- a/lib/SILOptimizer/Mandatory/PredictableMemOpt.cpp ++++ b/lib/SILOptimizer/Mandatory/PredictableMemOpt.cpp +@@ -41,6 +41,7 @@ using namespace swift; + static llvm::cl::opt EnableAggressiveExpansionBlocking( + "enable-aggressive-expansion-blocking", llvm::cl::init(false)); + ++STATISTIC(NumLoadPromoted, "Number of loads promoted"); + STATISTIC(NumLoadTakePromoted, "Number of load takes promoted"); + STATISTIC(NumDestroyAddrPromoted, "Number of destroy_addrs promoted"); + STATISTIC(NumAllocRemoved, "Number of allocations completely removed"); +@@ -496,6 +497,12 @@ struct AvailableValueDataflowFixup: AvailableValueFixup { + // Clears insertedInsts. + void verifyOwnership(DeadEndBlocks &deBlocks); + ++ // Fix ownership of inserted instructions and delete dead instructions. ++ // ++ // Clears insertedInsts. ++ void fixupOwnership(InstructionDeleter &deleter, ++ DeadEndBlocks &deBlocks); ++ + // Deletes all insertedInsts without fixing ownership. + // Clears insertedInsts. + void deleteInsertedInsts(InstructionDeleter &deleter); +@@ -542,6 +549,32 @@ void AvailableValueDataflowFixup::verifyOwnership(DeadEndBlocks &deBlocks) { + insertedInsts.clear(); + } + ++// In OptimizationMode::PreserveAlloc, delete any inserted instructions that are ++// still dead and fix ownership of any live inserted copies or casts ++// (mark_dependence). ++void AvailableValueDataflowFixup::fixupOwnership(InstructionDeleter &deleter, ++ DeadEndBlocks &deBlocks) { ++ for (auto *inst : insertedInsts) { ++ if (inst->isDeleted()) ++ continue; ++ ++ deleter.deleteIfDead(inst); ++ } ++ auto *function = const_cast(deBlocks.getFunction()); ++ OSSALifetimeCompletion completion(function, /*DomInfo*/ nullptr, deBlocks); ++ for (auto *inst : insertedInsts) { ++ if (inst->isDeleted()) ++ continue; ++ ++ // If any inserted instruction was not removed, complete its lifetime. ++ for (auto result : inst->getResults()) { ++ completion.completeOSSALifetime( ++ result, OSSALifetimeCompletion::Boundary::Liveness); ++ } ++ } ++ insertedInsts.clear(); ++} ++ + void AvailableValueDataflowFixup:: + deleteInsertedInsts(InstructionDeleter &deleter) { + for (auto *inst : insertedInsts) { +@@ -561,6 +594,11 @@ struct AvailableValueAggregationFixup: AvailableValueFixup { + /// The list of phi nodes inserted by the SSA updater. + SmallVector insertedPhiNodes; + ++ /// A set of copy_values whose lifetime we balanced while inserting phi ++ /// nodes. This means that these copy_value must be skipped in ++ /// addMissingDestroysForCopiedValues. ++ SmallPtrSet copyValueProcessedWithPhiNodes; ++ + AvailableValueAggregationFixup(DeadEndBlocks &deadEndBlocks) + : deadEndBlocks(deadEndBlocks) {} + +@@ -572,12 +610,29 @@ struct AvailableValueAggregationFixup: AvailableValueFixup { + SILInstruction *availableAtInst, + bool isFullyAvailable); + ++ /// Call this after mergeSingleValueCopies() or mergeAggregateCopies(). ++ void fixupOwnership(SILInstruction *load, SILValue newVal) { ++ addHandOffCopyDestroysForPhis(load, newVal); ++ ++ // TODO: use OwnershipLifetimeCompletion instead. ++ addMissingDestroysForCopiedValues(load, newVal); ++ ++ insertedInsts.clear(); ++ insertedPhiNodes.clear(); ++ copyValueProcessedWithPhiNodes.clear(); ++ } ++ + private: + /// As a result of us using the SSA updater, insert hand off copy/destroys at + /// each phi and make sure that intermediate phis do not leak by inserting + /// destroys along paths that go through the intermediate phi that do not also + /// go through the. + void addHandOffCopyDestroysForPhis(SILInstruction *load, SILValue newVal); ++ ++ /// If as a result of us copying values, we may have unconsumed destroys, find ++ /// the appropriate location and place the values there. Only used when ++ /// ownership is enabled. ++ void addMissingDestroysForCopiedValues(SILInstruction *load, SILValue newVal); + }; + + // For OptimizationMode::PreserveAlloc, insert copies at the available value's +@@ -663,6 +718,406 @@ SILValue AvailableValueAggregationFixup::mergeCopies( + .emitCopyValueOperation(availableAtInst->getLoc(), result); + } + ++ ++namespace { ++ ++class PhiNodeCopyCleanupInserter { ++ llvm::SmallMapVector incomingValues; ++ ++ /// Map from index -> (incomingValueIndex, copy). ++ /// ++ /// We are going to stable_sort this array using the indices of ++ /// incomingValueIndex. This will ensure that we always visit in ++ /// insertion order our incoming values (since the indices we are ++ /// sorting by are the count of incoming values we have seen so far ++ /// when we see the incoming value) and maintain the internal ++ /// insertion sort within our range as well. This ensures that we ++ /// visit our incoming values in visitation order and that within ++ /// their own values, also visit them in visitation order with ++ /// respect to each other. ++ SmallFrozenMultiMap copiesToCleanup; ++ ++ /// The lifetime frontier that we use to compute lifetime endpoints ++ /// when emitting cleanups. ++ ValueLifetimeAnalysis::Frontier lifetimeFrontier; ++ ++public: ++ PhiNodeCopyCleanupInserter() = default; ++ ++ void trackNewCleanup(SILValue incomingValue, CopyValueInst *copy) { ++ auto entry = std::make_pair(incomingValue, incomingValues.size()); ++ auto iter = incomingValues.insert(entry); ++ // If we did not succeed, then iter.first.second is the index of ++ // incoming value. Otherwise, it will be nextIndex. ++ copiesToCleanup.insert(iter.first->second, copy); ++ } ++ ++ void emit(DeadEndBlocks &deadEndBlocks) &&; ++}; ++ ++} // end anonymous namespace ++ ++static SILInstruction * ++getNonPhiBlockIncomingValueDef(SILValue incomingValue, ++ SingleValueInstruction *phiCopy) { ++ assert(isa(phiCopy)); ++ auto *phiBlock = phiCopy->getParent(); ++ if (phiBlock == incomingValue->getParentBlock()) { ++ return nullptr; ++ } ++ ++ if (auto *cvi = dyn_cast(incomingValue)) { ++ return cvi; ++ } ++ ++ assert(isa(incomingValue)); ++ ++ // Otherwise, our copy_value may not be post-dominated by our phi. To ++ // work around that, we need to insert destroys along the other ++ // paths. So set base to the first instruction in our argument's block, ++ // so we can insert destroys for our base. ++ return &*incomingValue->getParentBlock()->begin(); ++} ++ ++static bool ++terminatorHasAnyKnownPhis(TermInst *ti, ++ ArrayRef insertedPhiNodesSorted) { ++ for (auto succArgList : ti->getSuccessorBlockArgumentLists()) { ++ if (llvm::any_of(succArgList, [&](SILArgument *arg) { ++ return binary_search(insertedPhiNodesSorted, ++ cast(arg)); ++ })) { ++ return true; ++ } ++ } ++ ++ return false; ++} ++ ++void PhiNodeCopyCleanupInserter::emit(DeadEndBlocks &deadEndBlocks) && { ++ // READ THIS: We are being very careful here to avoid allowing for ++ // non-determinism to enter here. ++ // ++ // 1. First we create a list of indices of our phi node data. Then we use a ++ // stable sort those indices into the order in which our phi node cleanups ++ // would be in if we compared just using incomingValues. We use a stable ++ // sort here to ensure that within the same "cohort" of values, our order ++ // is insertion order. ++ // ++ // 2. We go through the list of phiNodeCleanupStates in insertion order. We ++ // also maintain a set of already visited base values. When we visit the ++ // first phiNodeCleanupState for a specific phi, we process the phi ++ // then. This ensures that we always process the phis in insertion order as ++ // well. ++ copiesToCleanup.setFrozen(); ++ ++ for (auto keyValue : copiesToCleanup.getRange()) { ++ unsigned incomingValueIndex = keyValue.first; ++ auto copies = keyValue.second; ++ ++ SILValue incomingValue = ++ std::next(incomingValues.begin(), incomingValueIndex)->first; ++ SingleValueInstruction *phiCopy = copies.front(); ++ auto *insertPt = getNonPhiBlockIncomingValueDef(incomingValue, phiCopy); ++ auto loc = RegularLocation::getAutoGeneratedLocation(); ++ ++ // Before we do anything, see if we have a single cleanup state. In such a ++ // case, we could have that we have a phi node as an incoming value and a ++ // copy_value in that same block. In such a case, we want to just insert the ++ // copy and continue. This means that ++ // cleanupState.getNonPhiBlockIncomingValueDef() should always return a ++ // non-null value in the code below. ++ if (copies.size() == 1 && isa(incomingValue) && !insertPt) { ++ SILBasicBlock *phiBlock = phiCopy->getParent(); ++ SILBuilderWithScope builder(phiBlock->getTerminator()); ++ builder.createDestroyValue(loc, incomingValue); ++ continue; ++ } ++ ++ // Otherwise, we know that we have for this incomingValue, multiple ++ // potential insert pts that we need to handle at the same time with our ++ // lifetime query. Lifetime extend our base over these copy_value uses. ++ assert(lifetimeFrontier.empty()); ++ auto *def = getNonPhiBlockIncomingValueDef(incomingValue, phiCopy); ++ assert(def && "Should never have a nullptr here since we handled all of " ++ "the single block cases earlier"); ++ ValueLifetimeAnalysis analysis(def, copies); ++ bool foundCriticalEdges = !analysis.computeFrontier( ++ lifetimeFrontier, ValueLifetimeAnalysis::DontModifyCFG, &deadEndBlocks); ++ (void)foundCriticalEdges; ++ assert(!foundCriticalEdges); ++ ++ while (!lifetimeFrontier.empty()) { ++ auto *insertPoint = lifetimeFrontier.pop_back_val(); ++ SILBuilderWithScope builder(insertPoint); ++ builder.createDestroyValue(loc, incomingValue); ++ } ++ } ++} ++ ++void AvailableValueAggregationFixup::addHandOffCopyDestroysForPhis( ++ SILInstruction *load, SILValue newVal) { ++ assert(isa(load) || isa(load)); ++ ++ if (insertedPhiNodes.empty()) ++ return; ++ ++ SmallVector leakingBlocks; ++ SmallVector, 8> incomingValues; ++ auto loc = RegularLocation::getAutoGeneratedLocation(); ++ ++#ifndef NDEBUG ++ LLVM_DEBUG(llvm::dbgs() << "Inserted Phis!\n"); ++ for (auto *phi : insertedPhiNodes) { ++ LLVM_DEBUG(llvm::dbgs() << "Phi: " << *phi); ++ } ++#endif ++ ++ // Before we begin, identify the offset for all phis that are intermediate ++ // phis inserted by the SSA updater. We are taking advantage of the fact that ++ // the SSA updater just constructs the web without knowledge of ownership. So ++ // if a phi node is only used by another phi node that we inserted, then we ++ // have an intermediate phi node. ++ // ++ // TODO: There should be a better way of doing this than doing a copy + sort. ++ SmallVector insertedPhiNodesSorted; ++ llvm::copy(insertedPhiNodes, std::back_inserter(insertedPhiNodesSorted)); ++ llvm::sort(insertedPhiNodesSorted); ++ ++ SmallBitVector intermediatePhiOffsets(insertedPhiNodes.size()); ++ for (unsigned i : indices(insertedPhiNodes)) { ++ if (TermInst *termInst = ++ insertedPhiNodes[i]->getSingleUserOfType()) { ++ // Only set the value if we find termInst has a successor with a phi node ++ // in our insertedPhiNodes. ++ if (terminatorHasAnyKnownPhis(termInst, insertedPhiNodesSorted)) { ++ intermediatePhiOffsets.set(i); ++ } ++ } ++ } ++ ++ // First go through all of our phi nodes doing the following: ++ // ++ // 1. If any of the phi node have a copy_value as an operand, we know that the ++ // copy_value does not dominate our final definition since otherwise the ++ // SSA updater would not have inserted a phi node here. In such a case ++ // since we may not have that the copy_value is post-dominated by the phi, ++ // we need to insert a copy_value at the phi to allow for post-domination ++ // and then use the ValueLifetimeChecker to determine the rest of the ++ // frontier for the base value. ++ // ++ // 2. If our phi node is used by another phi node, we run into a similar ++ // problem where we could have that our original phi node does not dominate ++ // our final definition (since the SSA updater would not have inserted the ++ // phi) and may not be strongly control dependent on our phi. To work ++ // around this problem, we insert at the phi a copy_value to allow for the ++ // phi to post_dominate its copy and then extend the lifetime of the phied ++ // value over that copy. ++ // ++ // As an extra complication to this, when we insert compensating releases for ++ // any copy_values from (1), we need to insert the destroy_value on "base ++ // values" (either a copy_value or the first instruction of a phi argument's ++ // block) /after/ we have found all of the base_values to ensure that if the ++ // same base value is used by multiple phis, we do not insert too many destroy ++ // value. ++ // ++ // NOTE: At first glance one may think that such a problem could not occur ++ // with phi nodes as well. Sadly if we allow for double backedge loops, it is ++ // possible (there may be more cases). ++ PhiNodeCopyCleanupInserter cleanupInserter; ++ ++ for (unsigned i : indices(insertedPhiNodes)) { ++ auto *phi = insertedPhiNodes[i]; ++ ++ // If our phi is not owned, continue. No fixes are needed. ++ if (phi->getOwnershipKind() != OwnershipKind::Owned) ++ continue; ++ ++ LLVM_DEBUG(llvm::dbgs() << "Visiting inserted phi: " << *phi); ++ // Otherwise, we have a copy_value that may not be strongly control ++ // equivalent with our phi node. In such a case, we need to use ++ // ValueLifetimeAnalysis to lifetime extend the copy such that we can ++ // produce a new copy_value at the phi. We insert destroys along the ++ // frontier. ++ leakingBlocks.clear(); ++ incomingValues.clear(); ++ ++ phi->getIncomingPhiValues(incomingValues); ++ unsigned phiIndex = phi->getIndex(); ++ for (auto pair : incomingValues) { ++ SILValue value = pair.second; ++ ++ // If we had a non-trivial type with non-owned ownership, we will not see ++ // a copy_value, so skip them here. ++ if (value->getOwnershipKind() != OwnershipKind::Owned) ++ continue; ++ ++ // Otherwise, value should be from a copy_value or a phi node. ++ assert(isa(value) || isa(value)); ++ ++ // If we have a copy_value, remove it from the inserted insts set so we ++ // skip it when we start processing insertedInstrs. ++ if (auto *cvi = dyn_cast(value)) { ++ copyValueProcessedWithPhiNodes.insert(cvi); ++ ++ // Then check if our termInst is in the same block as our copy_value. In ++ // such a case, we can just use the copy_value as our phi's value ++ // without needing to worry about any issues around control equivalence. ++ if (pair.first == cvi->getParent()) ++ continue; ++ } else { ++ assert(isa(value)); ++ } ++ ++ // Otherwise, insert a copy_value instruction right before the phi. We use ++ // that for our actual phi. ++ auto *termInst = pair.first->getTerminator(); ++ SILBuilderWithScope builder(termInst); ++ CopyValueInst *phiCopy = builder.createCopyValue(loc, value); ++ termInst->setOperand(phiIndex, phiCopy); ++ ++ // Now that we know our base, phi, phiCopy for this specific incoming ++ // value, append it to the phiNodeCleanupState so we can insert ++ // destroy_values late after we visit all insertedPhiNodes. ++ cleanupInserter.trackNewCleanup(value, phiCopy); ++ } ++ ++ // Then see if our phi is an intermediate phi. If it is an intermediate phi, ++ // we know that this is not the phi node that is post-dominated by the ++ // load_borrow and that we will lifetime extend it via the child ++ // phi. Instead, we need to just ensure that our phi arg does not leak onto ++ // its set of post-dominating paths, subtracting from that set the path ++ // through our terminator use. ++ if (intermediatePhiOffsets[i]) { ++ continue; ++ } ++ ++ // If we reach this point, then we know that we are a phi node that actually ++ // dominates our user so we need to lifetime extend it over the ++ // load_borrow. Thus insert copy_value along the incoming edges and then ++ // lifetime extend the phi node over the load_borrow. ++ // ++ // The linear lifetime checker doesn't care if the passed in load is ++ // actually a user of our copy_value. What we care about is that the load is ++ // guaranteed to be in the block where we have reformed the tuple in a ++ // consuming manner. This means if we add it as the consuming use of the ++ // copy, we can find the leaking places if any exist. ++ // ++ // Then perform the linear lifetime check. If we succeed, continue. We have ++ // no further work to do. ++ auto *loadOperand = &load->getAllOperands()[0]; ++ LinearLifetimeChecker checker(&deadEndBlocks); ++ bool consumedInLoop = checker.completeConsumingUseSet( ++ phi, loadOperand, [&](SILBasicBlock::iterator iter) { ++ SILBuilderWithScope builder(iter); ++ builder.emitDestroyValueOperation(loc, phi); ++ }); ++ ++ // Ok, we found some leaking blocks and potentially that our load is ++ // "consumed" inside a different loop in the loop nest from cvi. If we are ++ // consumed in the loop, then our visit should have inserted all of the ++ // necessary destroys for us by inserting the destroys on the loop ++ // boundaries. So, continue. ++ // ++ // NOTE: This includes cases where due to an infinite loop, we did not ++ // insert /any/ destroys since the loop has no boundary in a certain sense. ++ if (consumedInLoop) { ++ continue; ++ } ++ ++ // Otherwise, we need to insert one last destroy after the load for our phi. ++ auto next = std::next(load->getIterator()); ++ SILBuilderWithScope builder(next); ++ builder.emitDestroyValueOperation( ++ RegularLocation::getAutoGeneratedLocation(), phi); ++ } ++ ++ // Alright! In summary, we just lifetime extended all of our phis, ++ // lifetime extended them to the load block, and inserted phi copies ++ // at all of our intermediate phi nodes. Now we need to cleanup and ++ // insert all of the compensating destroy_value that we need. ++ std::move(cleanupInserter).emit(deadEndBlocks); ++ ++ // Clear the phi node array now that we are done. ++ insertedPhiNodes.clear(); ++} ++ ++// TODO: use standard lifetime completion ++void AvailableValueAggregationFixup::addMissingDestroysForCopiedValues( ++ SILInstruction *load, SILValue newVal) { ++ assert(load->getFunction()->hasOwnership() && ++ "We assume this is only called if we have ownership"); ++ ++ SmallVector leakingBlocks; ++ auto loc = RegularLocation::getAutoGeneratedLocation(); ++ ++ for (auto *inst : insertedInsts) { ++ // Otherwise, see if this is a load [copy]. It if it a load [copy], then we ++ // know that the load [copy] must be in the load block meaning we can just ++ // put a destroy_value /after/ the load_borrow to ensure that the value ++ // lives long enough for us to copy_value it or a derived value for the ++ // begin_borrow. ++ if (auto *li = dyn_cast(inst)) { ++ if (li->getOwnershipQualifier() == LoadOwnershipQualifier::Copy) { ++ assert(li->getParent() == load->getParent()); ++ auto next = std::next(load->getIterator()); ++ SILBuilderWithScope builder(next); ++ builder.emitDestroyValueOperation( ++ RegularLocation::getAutoGeneratedLocation(), li); ++ continue; ++ } ++ } ++ ++ // Our copy_value may have been unset above if it was used by a phi ++ // (implying it does not dominate our final user). ++ auto *cvi = dyn_cast(inst); ++ if (!cvi) ++ continue; ++ ++ // If we already handled this copy_value above when handling phi nodes, just ++ // continue. ++ if (copyValueProcessedWithPhiNodes.count(cvi)) ++ continue; ++ ++ // Clear our state. ++ leakingBlocks.clear(); ++ ++ // The linear lifetime checker doesn't care if the passed in load is ++ // actually a user of our copy_value. What we care about is that the load is ++ // guaranteed to be in the block where we have reformed the tuple in a ++ // consuming manner. This means if we add it as the consuming use of the ++ // copy, we can find the leaking places if any exist. ++ // ++ // Then perform the linear lifetime check. If we succeed, continue. We have ++ // no further work to do. ++ auto *loadOperand = &load->getAllOperands()[0]; ++ LinearLifetimeChecker checker(&deadEndBlocks); ++ bool consumedInLoop = checker.completeConsumingUseSet( ++ cvi, loadOperand, [&](SILBasicBlock::iterator iter) { ++ SILBuilderWithScope builder(iter); ++ builder.emitDestroyValueOperation(loc, cvi); ++ }); ++ ++ // Ok, we found some leaking blocks and potentially that our load is ++ // "consumed" inside a different loop in the loop nest from cvi. If we are ++ // consumed in the loop, then our visit should have inserted all of the ++ // necessary destroys for us by inserting the destroys on the loop ++ // boundaries. So, continue. ++ // ++ // NOTE: This includes cases where due to an infinite loop, we did not ++ // insert /any/ destroys since the loop has no boundary in a certain sense. ++ if (consumedInLoop) { ++ continue; ++ } ++ ++ // Otherwise, we need to insert one last destroy after the load for our phi. ++ auto next = std::next(load->getIterator()); ++ SILBuilderWithScope builder(next); ++ builder.emitDestroyValueOperation( ++ RegularLocation::getAutoGeneratedLocation(), cvi); ++ } ++} ++ + //===----------------------------------------------------------------------===// + // Available Value Aggregation + //===----------------------------------------------------------------------===// +@@ -735,6 +1190,15 @@ public: + return expectedOwnership == AvailableValueExpectedOwnership::Copy; + } + ++ /// Given a load_borrow that we have aggregated a new value for, fixup the ++ /// reference counts of the intermediate copies and phis to ensure that all ++ /// forwarding operations in the CFG are strongly control equivalent (i.e. run ++ /// the same number of times). ++ void fixupOwnership(SILInstruction *load, SILValue newVal) { ++ assert(isa(load) || isa(load)); ++ ownershipFixup.fixupOwnership(load, newVal); ++ } ++ + private: + SILValue aggregateFullyAvailableValue(SILType loadTy, unsigned firstElt); + SILValue aggregateTupleSubElts(TupleType *tt, SILType loadTy, +@@ -1071,6 +1535,11 @@ public: + ownershipFixup.verifyOwnership(deBlocks); + } + ++ void fixupOwnership(InstructionDeleter &deleter, ++ DeadEndBlocks &deBlocks) { ++ ownershipFixup.fixupOwnership(deleter, deBlocks); ++ } ++ + void deleteInsertedInsts(InstructionDeleter &deleter) { + ownershipFixup.deleteInsertedInsts(deleter); + } +@@ -1788,6 +2257,10 @@ bool AvailableValueDataflowContext::hasEscapedAt(SILInstruction *I) { + return HasAnyEscape; + } + ++//===----------------------------------------------------------------------===// ++// Optimize loads ++//===----------------------------------------------------------------------===// ++ + static SILType getMemoryType(AllocationInst *memory) { + // Compute the type of the memory object. + if (auto *abi = dyn_cast(memory)) { +@@ -1801,6 +2274,286 @@ static SILType getMemoryType(AllocationInst *memory) { + return cast(memory)->getElementType(); + } + ++namespace { ++ ++/// This performs load promotion and deletes synthesized allocations if all ++/// loads can be removed. ++class OptimizeAllocLoads { ++ ++ SILModule &Module; ++ ++ /// This is either an alloc_box or alloc_stack instruction. ++ AllocationInst *TheMemory; ++ ++ /// This is the SILType of the memory object. ++ SILType MemoryType; ++ ++ /// The number of primitive subelements across all elements of this memory ++ /// value. ++ unsigned NumMemorySubElements; ++ ++ SmallVectorImpl &Uses; ++ ++ InstructionDeleter &deleter; ++ ++ DeadEndBlocks &deadEndBlocks; ++ ++ /// A structure that we use to compute our available values. ++ AvailableValueDataflowContext DataflowContext; ++ ++public: ++ OptimizeAllocLoads(AllocationInst *memory, ++ SmallVectorImpl &uses, ++ DeadEndBlocks &deadEndBlocks, ++ InstructionDeleter &deleter) ++ : Module(memory->getModule()), TheMemory(memory), ++ MemoryType(getMemoryType(memory)), ++ NumMemorySubElements(getNumSubElements( ++ MemoryType, *memory->getFunction(), ++ TypeExpansionContext(*memory->getFunction()))), ++ Uses(uses), deleter(deleter), deadEndBlocks(deadEndBlocks), ++ DataflowContext(TheMemory, NumMemorySubElements, ++ OptimizationMode::PreserveAlloc, uses, ++ deleter, deadEndBlocks) {} ++ ++ bool optimize(); ++ ++private: ++ bool optimizeLoadUse(SILInstruction *inst); ++ bool promoteLoadCopy(LoadInst *li); ++ bool promoteLoadBorrow(LoadBorrowInst *lbi); ++ bool promoteCopyAddr(CopyAddrInst *cai); ++}; ++ ++} // end anonymous namespace ++ ++/// If we are able to optimize \p Inst, return the source address that ++/// instruction is loading from. If we can not optimize \p Inst, then just ++/// return an empty SILValue. ++static SILValue tryFindSrcAddrForLoad(SILInstruction *i) { ++ // We can always promote a load_borrow. ++ if (auto *lbi = dyn_cast(i)) ++ return lbi->getOperand(); ++ ++ // We only handle load [copy], load [trivial], load and copy_addr right ++ // now. Notably we do not support load [take] when promoting loads. ++ if (auto *li = dyn_cast(i)) ++ if (li->getOwnershipQualifier() != LoadOwnershipQualifier::Take) ++ return li->getOperand(); ++ ++ // If this is a CopyAddr, verify that the element type is loadable. If not, ++ // we can't explode to a load. ++ auto *cai = dyn_cast(i); ++ if (!cai || !cai->getSrc()->getType().isLoadable(*cai->getFunction())) ++ return SILValue(); ++ return cai->getSrc(); ++} ++ ++/// At this point, we know that this element satisfies the definitive init ++/// requirements, so we can try to promote loads to enable SSA-based dataflow ++/// analysis. We know that accesses to this element only access this element, ++/// cross element accesses have been scalarized. ++/// ++/// This returns true if the load has been removed from the program. ++bool OptimizeAllocLoads::promoteLoadCopy(LoadInst *li) { ++ // Note that we intentionally don't support forwarding of weak pointers, ++ // because the underlying value may drop be deallocated at any time. We would ++ // have to prove that something in this function is holding the weak value ++ // live across the promoted region and that isn't desired for a stable ++ // diagnostics pass this like one. ++ ++ // First attempt to find a source addr for our "load" instruction. If we fail ++ // to find a valid value, just return. ++ SILValue srcAddr = tryFindSrcAddrForLoad(li); ++ if (!srcAddr) ++ return false; ++ ++ SmallVector availableValues; ++ auto loadInfo = DataflowContext.computeAvailableValues(srcAddr, li, availableValues); ++ if (!loadInfo.has_value()) ++ return false; ++ ++ // Aggregate together all of the subelements into something that has the same ++ // type as the load did, and emit smaller loads for any subelements that were ++ // not available. We are "propagating" a +1 available value from the store ++ // points. ++ AvailableValueAggregator agg(li, availableValues, Uses, deadEndBlocks, ++ AvailableValueExpectedOwnership::Copy); ++ SILValue newVal = agg.aggregateValues(loadInfo->loadType, li->getOperand(), ++ loadInfo->firstElt); ++ ++ LLVM_DEBUG(llvm::dbgs() << " *** Promoting load: " << *li); ++ LLVM_DEBUG(llvm::dbgs() << " To value: " << *newVal); ++ ++NumLoadPromoted; ++ ++ // If we inserted any copies, we created the copies at our stores. We know ++ // that in our load block, we will reform the aggregate as appropriate at the ++ // load implying that the value /must/ be fully consumed. If we promoted a +0 ++ // value, we created dominating destroys along those paths. Thus any leaking ++ // blocks that we may have can be found by performing a linear lifetime check ++ // over all copies that we found using the load as the "consuming uses" (just ++ // for the purposes of identifying the consuming block). ++ agg.fixupOwnership(li, newVal); ++ ++ // Now that we have fixed up all of our missing destroys, insert the copy ++ // value for our actual load, in case the load was in an inner loop, and RAUW. ++ newVal = SILBuilderWithScope(li).emitCopyValueOperation(li->getLoc(), newVal); ++ ++ li->replaceAllUsesWith(newVal); ++ ++ SILValue addr = li->getOperand(); ++ deleter.forceDelete(li); ++ if (auto *addrI = addr->getDefiningInstruction()) ++ deleter.deleteIfDead(addrI); ++ return true; ++} ++ ++bool OptimizeAllocLoads::promoteCopyAddr(CopyAddrInst *cai) { ++ // Note that we intentionally don't support forwarding of weak pointers, ++ // because the underlying value may drop be deallocated at any time. We would ++ // have to prove that something in this function is holding the weak value ++ // live across the promoted region and that isn't desired for a stable ++ // diagnostics pass this like one. ++ ++ // First attempt to find a source addr for our "load" instruction. If we fail ++ // to find a valid value, just return. ++ SILValue srcAddr = tryFindSrcAddrForLoad(cai); ++ if (!srcAddr) ++ return false; ++ ++ SmallVector availableValues; ++ auto result = DataflowContext.computeAvailableValues(srcAddr, cai, ++ availableValues); ++ if (!result.has_value()) ++ return false; ++ ++ // Ok, we have some available values. If we have a copy_addr, explode it now, ++ // exposing the load operation within it. Subsequent optimization passes will ++ // see the load and propagate the available values into it. ++ DataflowContext.explodeCopyAddr(cai); ++ ++ // This is removing the copy_addr, but explodeCopyAddr takes care of ++ // removing the instruction from Uses for us, so we return false. ++ return false; ++} ++ ++/// At this point, we know that this element satisfies the definitive init ++/// requirements, so we can try to promote loads to enable SSA-based dataflow ++/// analysis. We know that accesses to this element only access this element, ++/// cross element accesses have been scalarized. ++/// ++/// This returns true if the load has been removed from the program. ++bool OptimizeAllocLoads::promoteLoadBorrow(LoadBorrowInst *lbi) { ++ // Note that we intentionally don't support forwarding of weak pointers, ++ // because the underlying value may drop be deallocated at any time. We would ++ // have to prove that something in this function is holding the weak value ++ // live across the promoted region and that isn't desired for a stable ++ // diagnostics pass this like one. ++ ++ // First attempt to find a source addr for our "load" instruction. If we fail ++ // to find a valid value, just return. ++ SILValue srcAddr = tryFindSrcAddrForLoad(lbi); ++ if (!srcAddr) ++ return false; ++ ++ SmallVector availableValues; ++ auto loadInfo = DataflowContext.computeAvailableValues(srcAddr, lbi, ++ availableValues); ++ if (!loadInfo.has_value()) ++ return false; ++ ++ // Bail if the load_borrow has reborrows. In this case it's not so easy to ++ // find the insertion points for the destroys. ++ if (!lbi->getUsersOfType().empty()) { ++ return false; ++ } ++ ++ ++NumLoadPromoted; ++ ++ // Aggregate together all of the subelements into something that has the same ++ // type as the load did, and emit smaller loads for any subelements that were ++ // not available. We are "propagating" a +1 available value from the store ++ // points. ++ AvailableValueAggregator agg(lbi, availableValues, Uses, deadEndBlocks, ++ AvailableValueExpectedOwnership::Borrow); ++ SILValue newVal = agg.aggregateValues(loadInfo->loadType, lbi->getOperand(), ++ loadInfo->firstElt); ++ ++ LLVM_DEBUG(llvm::dbgs() << " *** Promoting load: " << *lbi); ++ LLVM_DEBUG(llvm::dbgs() << " To value: " << *newVal); ++ ++ // If we inserted any copies, we created the copies at our ++ // stores. We know that in our load block, we will reform the ++ // aggregate as appropriate, will borrow the value there and give us ++ // a whole pristine new value. Now in this routine, we go through ++ // all of the copies and phis that we inserted and ensure that: ++ // ++ // 1. Phis are always strongly control equivalent to the copies that ++ // produced their incoming values. ++ // ++ // 2. All intermediate copies are properly lifetime extended to the ++ // load block and all leaking blocks are filled in as appropriate ++ // with destroy_values. ++ agg.fixupOwnership(lbi, newVal); ++ ++ // Now that we have fixed up the lifetimes of all of our incoming copies so ++ // that they are alive over the load point, copy, borrow newVal and insert ++ // destroy_value after the end_borrow and then RAUW. ++ SILBuilderWithScope builder(lbi); ++ SILValue copiedVal = builder.emitCopyValueOperation(lbi->getLoc(), newVal); ++ newVal = builder.createBeginBorrow(lbi->getLoc(), copiedVal); ++ ++ for (auto *ebi : lbi->getUsersOfType()) { ++ auto next = std::next(ebi->getIterator()); ++ SILBuilderWithScope(next).emitDestroyValueOperation(ebi->getLoc(), ++ copiedVal); ++ } ++ ++ lbi->replaceAllUsesWith(newVal); ++ ++ SILValue addr = lbi->getOperand(); ++ deleter.forceDelete(lbi); ++ if (auto *addrI = addr->getDefiningInstruction()) ++ deleter.deleteIfDead(addrI); ++ return true; ++} ++ ++bool OptimizeAllocLoads::optimize() { ++ bool changed = false; ++ ++ // If we've successfully checked all of the definitive initialization ++ // requirements, try to promote loads. This can explode copy_addrs, so the ++ // use list may change size. ++ for (unsigned i = 0; i != Uses.size(); ++i) { ++ auto &use = Uses[i]; ++ // Ignore entries for instructions that got expanded along the way. ++ if (use.Inst && use.Kind == PMOUseKind::Load) { ++ if (optimizeLoadUse(use.Inst)) { ++ changed = true; ++ Uses[i].Inst = nullptr; // remove entry if load got deleted. ++ } ++ } ++ } ++ return changed; ++} ++ ++bool OptimizeAllocLoads::optimizeLoadUse(SILInstruction *inst) { ++ // After replacing load uses with promoted values, fixup ownership for copies ++ // or casts inserted during dataflow. ++ SWIFT_DEFER { DataflowContext.fixupOwnership(deleter, deadEndBlocks); }; ++ ++ if (auto *cai = dyn_cast(inst)) ++ return promoteCopyAddr(cai); ++ ++ if (auto *lbi = dyn_cast(inst)) ++ return promoteLoadBorrow(lbi); ++ ++ if (auto *li = dyn_cast(inst)) ++ return promoteLoadCopy(li); ++ ++ return false; ++} ++ + //===----------------------------------------------------------------------===// + // Optimize dead allocation: + // Fully promote each access +@@ -2453,6 +3206,49 @@ static AllocationInst *getOptimizableAllocation(SILInstruction *i) { + return alloc; + } + ++bool swift::optimizeMemoryAccesses(SILFunction *fn) { ++ if (!fn->hasOwnership()) { ++ return false; ++ } ++ ++ bool changed = false; ++ DeadEndBlocks deadEndBlocks(fn); ++ InstructionDeleter deleter; ++ for (auto &bb : *fn) { ++ for (SILInstruction &inst : bb.deletableInstructions()) { ++ // First see if i is an allocation that we can optimize. If not, skip it. ++ AllocationInst *alloc = getOptimizableAllocation(&inst); ++ if (!alloc) { ++ continue; ++ } ++ ++ LLVM_DEBUG(llvm::dbgs() ++ << "*** PMO Optimize Memory Accesses looking at: " << *alloc); ++ PMOMemoryObjectInfo memInfo(alloc); ++ ++ // Set up the datastructure used to collect the uses of the allocation. ++ SmallVector uses; ++ ++ // Walk the use list of the pointer, collecting them. If we are not able ++ // to optimize, skip this value. *NOTE* We may still scalarize values ++ // inside the value. ++ if (!collectPMOElementUsesFrom(memInfo, uses)) { ++ // Avoid advancing this iterator until after collectPMOElementUsesFrom() ++ // runs. It creates and deletes instructions other than alloc. ++ continue; ++ } ++ OptimizeAllocLoads optimizeAllocLoads(alloc, uses, deadEndBlocks, ++ deleter); ++ changed |= optimizeAllocLoads.optimize(); ++ ++ // Move onto the next instruction. We know this is safe since we do not ++ // eliminate allocations here. ++ } ++ } ++ ++ return changed; ++} ++ + bool swift::eliminateDeadAllocations(SILFunction *fn, DominanceInfo *domInfo) { + if (!fn->hasOwnership()) { + return false; +@@ -2498,6 +3294,26 @@ bool swift::eliminateDeadAllocations(SILFunction *fn, DominanceInfo *domInfo) { + + namespace { + ++class PredictableMemoryAccessOptimizations : public SILFunctionTransform { ++ /// The entry point to the transformation. ++ /// ++ /// FIXME: This pass should not need to rerun on deserialized ++ /// functions. Nothing should have changed in the upstream pipeline after ++ /// deserialization. However, rerunning does improve some benchmarks. This ++ /// either indicates that this pass missing some opportunities the first time, ++ /// or has a pass order dependency on other early passes. ++ void run() override { ++ auto *func = getFunction(); ++ if (!func->hasOwnership()) ++ return; ++ ++ LLVM_DEBUG(llvm::dbgs() << "Looking at: " << func->getName() << "\n"); ++ // TODO: Can we invalidate here just instructions? ++ if (optimizeMemoryAccesses(func)) ++ invalidateAnalysis(SILAnalysis::InvalidationKind::FunctionBody); ++ } ++}; ++ + class PredictableDeadAllocationElimination : public SILFunctionTransform { + void run() override { + auto *func = getFunction(); +@@ -2516,6 +3332,10 @@ class PredictableDeadAllocationElimination : public SILFunctionTransform { + + } // end anonymous namespace + ++SILTransform *swift::createPredictableMemoryAccessOptimizations() { ++ return new PredictableMemoryAccessOptimizations(); ++} ++ + SILTransform *swift::createPredictableDeadAllocationElimination() { + return new PredictableDeadAllocationElimination(); + } +diff --git a/lib/SILOptimizer/PassManager/PassPipeline.cpp b/lib/SILOptimizer/PassManager/PassPipeline.cpp +index 92a084c2df5..620718451e7 100644 +--- a/lib/SILOptimizer/PassManager/PassPipeline.cpp ++++ b/lib/SILOptimizer/PassManager/PassPipeline.cpp +@@ -206,7 +206,7 @@ static void addMandatoryDiagnosticOptPipeline(SILPassPipelinePlan &P) { + + // Promote loads as necessary to ensure we have enough SSA formation to emit + // SSA based diagnostics. +- P.addMandatoryRedundantLoadElimination(); ++ P.addPredictableMemoryAccessOptimizations(); + + // This phase performs optimizations necessary for correct interoperation of + // Swift os log APIs with C os_log ABIs. +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0009-siloptimizer-bootstrap-workaround.patch b/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0009-siloptimizer-bootstrap-workaround.patch new file mode 100644 index 000000000000..3b7f4705ff24 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0009-siloptimizer-bootstrap-workaround.patch @@ -0,0 +1,34 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sun, 4 Jan 2026 14:44:49 -0500 +Subject: [PATCH 09/10] siloptimizer-bootstrap-workaround +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Restore the SimplifyCFG optimization when bootstrapping. Even though +it’s buggy, it’s needed to build later stages of the bootstrap. +--- + lib/SILOptimizer/Transforms/SimplifyCFG.cpp | 6 ------ + 1 file changed, 6 deletions(-) + +diff --git a/lib/SILOptimizer/Transforms/SimplifyCFG.cpp b/lib/SILOptimizer/Transforms/SimplifyCFG.cpp +index f4781b4ca5c..ef99a41d864 100644 +--- a/lib/SILOptimizer/Transforms/SimplifyCFG.cpp ++++ b/lib/SILOptimizer/Transforms/SimplifyCFG.cpp +@@ -3322,12 +3322,6 @@ static bool splitBBArguments(SILFunction &Fn) { + } + + bool SimplifyCFG::run() { +-#ifndef SWIFT_ENABLE_SWIFT_IN_SWIFT +- // This pass results in verification failures when Swift sources are not +- // enabled. +- LLVM_DEBUG(llvm::dbgs() << "SimplifyCFG disabled in C++-only Swift compiler\n"); +- return false; +-#endif //!SWIFT_ENABLE_SWIFT_IN_SWIFT + LLVM_DEBUG(llvm::dbgs() << "### Run SimplifyCFG on " << Fn.getName() << '\n'); + + // Disable some expensive optimizations if the function is huge. +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0010-Remove-dependency-on-_StringProcessing-during-stage-.patch b/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0010-Remove-dependency-on-_StringProcessing-during-stage-.patch new file mode 100644 index 000000000000..d1a1b7b4dd76 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0010-Remove-dependency-on-_StringProcessing-during-stage-.patch @@ -0,0 +1,59 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 4 Jul 2026 12:34:17 -0400 +Subject: [PATCH 10/10] Remove dependency on _StringProcessing during stage 1 + bootstrap + +--- + .../SwiftMacros/DebugDescriptionMacro.swift | 25 ++++++++----------- + 1 file changed, 10 insertions(+), 15 deletions(-) + +diff --git a/lib/Macros/Sources/SwiftMacros/DebugDescriptionMacro.swift b/lib/Macros/Sources/SwiftMacros/DebugDescriptionMacro.swift +index 4483bf7a0c9..7dbc301a1d0 100644 +--- a/lib/Macros/Sources/SwiftMacros/DebugDescriptionMacro.swift ++++ b/lib/Macros/Sources/SwiftMacros/DebugDescriptionMacro.swift +@@ -13,7 +13,6 @@ + import SwiftSyntax + import SwiftSyntaxMacros + import SwiftDiagnostics +-import _StringProcessing + + public enum DebugDescriptionMacro {} + public enum _DebugDescriptionPropertyMacro {} +@@ -515,23 +514,19 @@ extension String { + + extension String { + fileprivate func escapedForLLDB() -> String { +- guard #available(macOS 13, *) else { +- guard self.firstIndex(of: "$") != nil else { +- return self +- } ++ guard self.firstIndex(of: "$") != nil else { ++ return self ++ } + +- var result = "" +- for char in self { +- if char == "$" { +- result.append("\\$") +- } else { +- result.append(char) +- } ++ var result = "" ++ for char in self { ++ if char == "$" { ++ result.append("\\$") ++ } else { ++ result.append(char) + } +- return result + } +- +- return self.replacing("$", with: "\\$") ++ return result + } + } + +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swiftly/package.nix b/pkgs/development/compilers/swift/by-name/sw/swiftly/package.nix new file mode 100644 index 000000000000..4afebbb30b05 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swiftly/package.nix @@ -0,0 +1,59 @@ +{ + lib, + fetchFromGitHub, + fetchSwiftPMDeps, + gitUpdater, + libarchive, + pkg-config, + stdenv, + swift, + swiftpm, + zlib, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "swiftly"; + version = "1.1.3"; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swiftly"; + tag = finalAttrs.version; + hash = "sha256-VFgmgo69Q4Y8Je0SMdB3jKGt9lNoVYAaUhSuK3RUkFE="; + }; + + swiftpmDeps = fetchSwiftPMDeps { + inherit (finalAttrs) pname version src; + hash = "sha256-1KfyrQXE1HaO9WsuskzgiiEZxM/oelp40Jwzr8xJEL4="; + }; + + strictDeps = true; + + nativeBuildInputs = [ + swift + swiftpm + ] + # Required for libarchive. + ++ lib.optionals stdenv.hostPlatform.isLinux [ pkg-config ]; + + buildInputs = [ + zlib + ] + # Swiftly requires libarchive on Linux but not Darwin. + ++ lib.optionals stdenv.hostPlatform.isLinux [ libarchive ]; + + doCheck = false; # Too many impure tests that fail. Need a mechanism to disable just those tests. + + __structuredAttrs = true; + + passthru.updateScript = gitUpdater { }; + + meta = { + description = "Swift toolchain installer and manager"; + mainProgram = "swiftly"; + homepage = "https://github.com/swiftlang/swiftly"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift/by-name/sw/swiftpm/package.nix b/pkgs/development/compilers/swift/by-name/sw/swiftpm/package.nix new file mode 100644 index 000000000000..3f879b94da5e --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swiftpm/package.nix @@ -0,0 +1,177 @@ +{ + lib, + callPackage, + cmake, + fetchFromGitHub, + fetchpatch2, + llvmPackages, + ninja, + replaceVars, + sqlite, + stdenv, + swift, + swift-argument-parser, + swift-asn1, + swift-build, + swift-certificates, + swift-collections, + swift-crypto, + swift-driver, + swift-llbuild, + swift-syntax, + swift-system, + swift-tools-support-core, + swiftpmHook, + swift_release, + swift_sources, +}: + +let + swift-syntax-no-toolchain = swift-syntax.override { useToolchainLibraries = false; }; + + rpaths = lib.makeLibraryPath [ + sqlite + swift-argument-parser + swift-asn1 + swift-build + swift-certificates + swift-collections + swift-crypto + swift-driver + swift-llbuild + swift-syntax-no-toolchain + swift-system + swift-tools-support-core + ]; +in + +stdenv.mkDerivation (finalAttrs: { + pname = "swiftpm"; + version = swift_release; + + outputs = [ + "out" + "dev" + ]; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-package-manager"; + tag = "swift-${finalAttrs.version}-RELEASE"; + inherit (swift_sources.swift-package-manager) hash; + }; + + patches = [ + ./patches/0001-gnu-install-dirs.patch + # Use swift-corelibs-xctest even on Darwin (because XCTest.framework is not available in nixpkgs). + ./patches/0002-darwin-swift-corelibs-xctest.patch + # SwiftPM tries to use `sandbox-exec` for sandboxing, which will fail when it is run in the Nix sandbox. + ./patches/0003-disable-sandbox.patch + # SwiftPM falls back to looking for manifests and plugins in the Swift compiler location. Find them in $out. + ./patches/0005-fix-manifest-path.patch + # Silence warnings about not finding the cache folder when building packages by moving it to $NIX_BUILD_TOP. + ./patches/0006-nix-build-caches.patch + # SwiftPM does its own `.pc` parsing, so it avoids the `pkg-config` wrapper used in nixpkgs to support + # cross-compilation. This patch adds support for `"PKG_CONFIG_PATH_FOR_TARGET` to SwiftPM. + ./patches/0007-nix-pkgconfig-vars.patch + # SwiftPM assumes that you are using Apple Clang on macOS, but nixpkgs builds Clang from upstream LLVM. + # This effectively disables using `-index-store-path`, which isn’t supported by LLVM’s Clang. + ./patches/0008-set-compiler-vendor.patch + # A couple of required libraries are missing from the `CMakeLists.txt` files. + ./patches/0009-add-missing-libraries.patch + # SwiftPM tries to load IndexStoreDB from the toolchain, but load it from the store instead. + (replaceVars ./patches/0010-Load-IndexStore-from-the-store.patch { + libclang = lib.getLib llvmPackages.libclang; + }) + # SwiftPM tries to find Clang via `CC`, but that can be GCC on Linux, which doesn’t actually work with SwiftPM. + ./patches/0011-Always-find-Clang-in-the-toolchain.patch + # Build missing `swift-package-collection` and `swift-package-registry` binaries. + (fetchpatch2 { + url = "https://github.com/swiftlang/swift-package-manager/commit/e1910f814cc1be40c709c3987a29488b9bee2f92.patch?full_index=1"; + hash = "sha256-4Ew/cKlk+Zn8cIQvh0jQy4Fz+xGYBYwch4+SBu1nKpI="; + }) + ]; + + postPatch = '' + # Need to reference $out, so this can’t be substituted by `replaceVars`. + substituteInPlace Sources/PackageModel/UserToolchain.swift \ + --replace-fail '@out@' "$out" + + # Replace hardcoded references to `xcrun` with `PATH`-based references. + find Sources -name '*.swift' -exec sed -i '{}' -e 's|/usr/bin/xcrun|xcrun|g' \; + + # Set the deployment target when building package manifests to one supported in nixpkgs. + substituteInPlace Sources/PackageLoading/ManifestLoader.swift \ + --replace-fail '.tripleString(forPlatformVersion: version)' ".tripleString(forPlatformVersion: \"$MACOSX_DEPLOYMENT_TARGET\")" + ''; + + strictDeps = true; + + preConfigure = '' + appendToVar cmakeFlags -DCMAKE_Swift_COMPILER_TARGET=${stdenv.hostPlatform.swift.triple} + appendToVar cmakeFlags -DCMAKE_Swift_FLAGS=-module-cache-path\ "$NIX_BUILD_TOP/module-cache" + ''; + + nativeBuildInputs = [ + cmake + ninja + swift + ]; + + propagatedBuildInputs = [ swiftpmHook ]; + + buildInputs = [ + sqlite + swift-argument-parser + swift-asn1 + swift-build + swift-certificates + swift-collections + swift-crypto + swift-driver + swift-llbuild + swift-syntax-no-toolchain + swift-system + swift-tools-support-core + ]; + + postInstall = + lib.optionalString stdenv.hostPlatform.isDarwin '' + # Replace `@rpath` with absolute paths on Darwin. For some reason, this isn’t always done during installation. + # `fixDarwinDylibNames` doesn’t work either. + IFS= readarray -d "" dylibs < <(find "$out" -type f -and -name '*.dylib' -print0) + declare -a mappings + + for dylib in "''${dylibs[@]}"; do + mappings+=(-change "@rpath/$(basename "$dylib")" "$dylib") + done + + for dylib in "''${dylibs[@]}"; do + install_name_tool "$dylib" ''${mappings[@]} + done + '' + + lib.optionalString stdenv.hostPlatform.isElf '' + for output in "''${outputs[@]}"; do + while IFS= read -d "" f; do + if isELF "$f"; then + patchelf --add-rpath ${lib.escapeShellArg rpaths} "$f" + fi + done < <(find "$output" -type f -print0) + done + ''; + + passthru.tests = lib.packagesFromDirectoryRecursive { + inherit callPackage; + directory = ./tests; + }; + + __structuredAttrs = true; + + meta = { + description = "Package Manager for the Swift Programming Language"; + homepage = "https://github.com/swiftlang/swift-package-manager"; + inherit (swift.meta) badPlatforms platforms; + license = lib.licenses.asl20; + maintainers = lib.teams.swift.members; + }; +}) diff --git a/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0001-gnu-install-dirs.patch b/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0001-gnu-install-dirs.patch new file mode 100644 index 000000000000..5851bb9b15a4 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0001-gnu-install-dirs.patch @@ -0,0 +1,362 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Fri, 19 Dec 2025 20:12:12 -0500 +Subject: [PATCH 01/11] gnu-install-dirs + +--- + Sources/Basics/CMakeLists.txt | 6 +++--- + Sources/Build/CMakeLists.txt | 6 +++--- + Sources/Commands/CMakeLists.txt | 6 +++--- + Sources/CoreCommands/CMakeLists.txt | 6 +++--- + Sources/DriverSupport/CMakeLists.txt | 6 +++--- + Sources/PackageCollections/CMakeLists.txt | 6 +++--- + Sources/PackageCollectionsModel/CMakeLists.txt | 6 +++--- + Sources/PackageCollectionsSigning/CMakeLists.txt | 6 +++--- + Sources/PackageGraph/CMakeLists.txt | 6 +++--- + Sources/PackageLoading/CMakeLists.txt | 6 +++--- + Sources/PackageModel/CMakeLists.txt | 6 +++--- + Sources/PackageModelSyntax/CMakeLists.txt | 6 +++--- + Sources/PackageRegistryCommand/CMakeLists.txt | 6 +++--- + Sources/QueryEngine/CMakeLists.txt | 6 +++--- + Sources/SPMBuildCore/CMakeLists.txt | 6 +++--- + Sources/SourceControl/CMakeLists.txt | 6 +++--- + Sources/SwiftSDKCommand/CMakeLists.txt | 6 +++--- + Sources/Workspace/CMakeLists.txt | 6 +++--- + Sources/_AsyncFileSystem/CMakeLists.txt | 6 +++--- + Sources/swift-experimental-sdk/CMakeLists.txt | 2 +- + Sources/swift-package/CMakeLists.txt | 2 +- + Sources/swift-run/CMakeLists.txt | 2 +- + Sources/swift-sdk/CMakeLists.txt | 2 +- + Sources/swift-test/CMakeLists.txt | 2 +- + 24 files changed, 62 insertions(+), 62 deletions(-) + +diff --git a/Sources/Basics/CMakeLists.txt b/Sources/Basics/CMakeLists.txt +index e2910d09b..2f523dedb 100644 +--- a/Sources/Basics/CMakeLists.txt ++++ b/Sources/Basics/CMakeLists.txt +@@ -97,7 +97,7 @@ target_link_options(Basics PRIVATE + "$<$:SHELL:-Xlinker -framework -Xlinker Security>") + + install(TARGETS Basics +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") + set_property(GLOBAL APPEND PROPERTY SwiftPM_EXPORTS Basics) +diff --git a/Sources/Build/CMakeLists.txt b/Sources/Build/CMakeLists.txt +index 495bd7a87..9b32067ff 100644 +--- a/Sources/Build/CMakeLists.txt ++++ b/Sources/Build/CMakeLists.txt +@@ -49,7 +49,7 @@ set_target_properties(Build PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + + install(TARGETS Build +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") + set_property(GLOBAL APPEND PROPERTY SwiftPM_EXPORTS Build) +diff --git a/Sources/Commands/CMakeLists.txt b/Sources/Commands/CMakeLists.txt +index c62c7424e..5efcc760d 100644 +--- a/Sources/Commands/CMakeLists.txt ++++ b/Sources/Commands/CMakeLists.txt +@@ -80,6 +80,6 @@ set_target_properties(Commands PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + + install(TARGETS Commands +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/CoreCommands/CMakeLists.txt b/Sources/CoreCommands/CMakeLists.txt +index 54bc10b2b..dbaadcb3f 100644 +--- a/Sources/CoreCommands/CMakeLists.txt ++++ b/Sources/CoreCommands/CMakeLists.txt +@@ -29,6 +29,6 @@ set_target_properties(CoreCommands PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + + install(TARGETS CoreCommands +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/DriverSupport/CMakeLists.txt b/Sources/DriverSupport/CMakeLists.txt +index 1044df0e9..29234574c 100644 +--- a/Sources/DriverSupport/CMakeLists.txt ++++ b/Sources/DriverSupport/CMakeLists.txt +@@ -18,7 +18,7 @@ target_link_libraries(DriverSupport PUBLIC + SwiftDriver) + + install(TARGETS DriverSupport +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") + set_property(GLOBAL APPEND PROPERTY SwiftPM_EXPORTS DriverSupport) +diff --git a/Sources/PackageCollections/CMakeLists.txt b/Sources/PackageCollections/CMakeLists.txt +index 63eb94c2f..4f3c183e4 100644 +--- a/Sources/PackageCollections/CMakeLists.txt ++++ b/Sources/PackageCollections/CMakeLists.txt +@@ -56,6 +56,6 @@ if(NOT APPLE) + endif() + + install(TARGETS PackageCollections +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/PackageCollectionsModel/CMakeLists.txt b/Sources/PackageCollectionsModel/CMakeLists.txt +index 9f98827a5..c99c5d81c 100644 +--- a/Sources/PackageCollectionsModel/CMakeLists.txt ++++ b/Sources/PackageCollectionsModel/CMakeLists.txt +@@ -20,6 +20,6 @@ if(NOT APPLE) + endif() + + install(TARGETS PackageCollectionsModel +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/PackageCollectionsSigning/CMakeLists.txt b/Sources/PackageCollectionsSigning/CMakeLists.txt +index 5f3d69abe..7390bb783 100644 +--- a/Sources/PackageCollectionsSigning/CMakeLists.txt ++++ b/Sources/PackageCollectionsSigning/CMakeLists.txt +@@ -36,6 +36,6 @@ if(NOT APPLE) + endif() + + install(TARGETS PackageCollectionsSigning +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/PackageGraph/CMakeLists.txt b/Sources/PackageGraph/CMakeLists.txt +index 46bd6580f..4e7a5e04d 100644 +--- a/Sources/PackageGraph/CMakeLists.txt ++++ b/Sources/PackageGraph/CMakeLists.txt +@@ -51,7 +51,7 @@ set_target_properties(PackageGraph PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + + install(TARGETS PackageGraph +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") + set_property(GLOBAL APPEND PROPERTY SwiftPM_EXPORTS PackageGraph) +diff --git a/Sources/PackageLoading/CMakeLists.txt b/Sources/PackageLoading/CMakeLists.txt +index 476588dbf..f363cd12d 100644 +--- a/Sources/PackageLoading/CMakeLists.txt ++++ b/Sources/PackageLoading/CMakeLists.txt +@@ -36,7 +36,7 @@ set_target_properties(PackageLoading PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + + install(TARGETS PackageLoading +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") + set_property(GLOBAL APPEND PROPERTY SwiftPM_EXPORTS PackageLoading) +diff --git a/Sources/PackageModel/CMakeLists.txt b/Sources/PackageModel/CMakeLists.txt +index 48ff3b9ba..3c2e305a9 100644 +--- a/Sources/PackageModel/CMakeLists.txt ++++ b/Sources/PackageModel/CMakeLists.txt +@@ -75,7 +75,7 @@ set_target_properties(PackageModel PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + + install(TARGETS PackageModel +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") + set_property(GLOBAL APPEND PROPERTY SwiftPM_EXPORTS PackageModel) +diff --git a/Sources/PackageModelSyntax/CMakeLists.txt b/Sources/PackageModelSyntax/CMakeLists.txt +index 02142c690..70dcf942c 100644 +--- a/Sources/PackageModelSyntax/CMakeLists.txt ++++ b/Sources/PackageModelSyntax/CMakeLists.txt +@@ -39,7 +39,7 @@ set_target_properties(PackageModelSyntax PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + + install(TARGETS PackageModelSyntax +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") + set_property(GLOBAL APPEND PROPERTY SwiftPM_EXPORTS PackageModelSyntax) +diff --git a/Sources/PackageRegistryCommand/CMakeLists.txt b/Sources/PackageRegistryCommand/CMakeLists.txt +index 92c7785ed..a62300a1a 100644 +--- a/Sources/PackageRegistryCommand/CMakeLists.txt ++++ b/Sources/PackageRegistryCommand/CMakeLists.txt +@@ -34,6 +34,6 @@ if(NOT APPLE) + endif() + + install(TARGETS PackageRegistryCommand +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/QueryEngine/CMakeLists.txt b/Sources/QueryEngine/CMakeLists.txt +index 869c52c45..36d71c89c 100644 +--- a/Sources/QueryEngine/CMakeLists.txt ++++ b/Sources/QueryEngine/CMakeLists.txt +@@ -27,6 +27,6 @@ if(NOT APPLE) + endif() + + install(TARGETS QueryEngine +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/SPMBuildCore/CMakeLists.txt b/Sources/SPMBuildCore/CMakeLists.txt +index eaf92ddd1..ed7f25ca9 100644 +--- a/Sources/SPMBuildCore/CMakeLists.txt ++++ b/Sources/SPMBuildCore/CMakeLists.txt +@@ -40,7 +40,7 @@ target_link_libraries(SPMBuildCore PUBLIC + + + install(TARGETS SPMBuildCore +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") + set_property(GLOBAL APPEND PROPERTY SwiftPM_EXPORTS SPMBuildCore) +diff --git a/Sources/SourceControl/CMakeLists.txt b/Sources/SourceControl/CMakeLists.txt +index 8e1377d9b..e660bae2d 100644 +--- a/Sources/SourceControl/CMakeLists.txt ++++ b/Sources/SourceControl/CMakeLists.txt +@@ -22,7 +22,7 @@ set_target_properties(SourceControl PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + + install(TARGETS SourceControl +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") + set_property(GLOBAL APPEND PROPERTY SwiftPM_EXPORTS SourceControl) +diff --git a/Sources/SwiftSDKCommand/CMakeLists.txt b/Sources/SwiftSDKCommand/CMakeLists.txt +index 4dcfa36a2..ccca0ac3b 100644 +--- a/Sources/SwiftSDKCommand/CMakeLists.txt ++++ b/Sources/SwiftSDKCommand/CMakeLists.txt +@@ -29,6 +29,6 @@ set_target_properties(SwiftSDKCommand PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + + install(TARGETS SwiftSDKCommand +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/Workspace/CMakeLists.txt b/Sources/Workspace/CMakeLists.txt +index cdc939112..78b79ac25 100644 +--- a/Sources/Workspace/CMakeLists.txt ++++ b/Sources/Workspace/CMakeLists.txt +@@ -62,6 +62,6 @@ set_target_properties(Workspace PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + + install(TARGETS Workspace +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/_AsyncFileSystem/CMakeLists.txt b/Sources/_AsyncFileSystem/CMakeLists.txt +index adf09b29c..ad2ce7c4a 100644 +--- a/Sources/_AsyncFileSystem/CMakeLists.txt ++++ b/Sources/_AsyncFileSystem/CMakeLists.txt +@@ -24,8 +24,8 @@ set_target_properties(_AsyncFileSystem PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + + install(TARGETS _AsyncFileSystem +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") + + set_property(GLOBAL APPEND PROPERTY SwiftPM_EXPORTS _AsyncFileSystem) +diff --git a/Sources/swift-experimental-sdk/CMakeLists.txt b/Sources/swift-experimental-sdk/CMakeLists.txt +index edad12be8..f07bd15a7 100644 +--- a/Sources/swift-experimental-sdk/CMakeLists.txt ++++ b/Sources/swift-experimental-sdk/CMakeLists.txt +@@ -15,4 +15,4 @@ target_compile_options(swift-experimental-sdk PRIVATE + -parse-as-library) + + install(TARGETS swift-experimental-sdk +- RUNTIME DESTINATION bin) ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/swift-package/CMakeLists.txt b/Sources/swift-package/CMakeLists.txt +index 3468bdefc..4b4a8d190 100644 +--- a/Sources/swift-package/CMakeLists.txt ++++ b/Sources/swift-package/CMakeLists.txt +@@ -16,4 +16,4 @@ target_compile_options(swift-package PRIVATE + -parse-as-library) + + install(TARGETS swift-package +- RUNTIME DESTINATION bin) ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/swift-run/CMakeLists.txt b/Sources/swift-run/CMakeLists.txt +index 9c609f84e..719a2228a 100644 +--- a/Sources/swift-run/CMakeLists.txt ++++ b/Sources/swift-run/CMakeLists.txt +@@ -15,4 +15,4 @@ target_compile_options(swift-run PRIVATE + -parse-as-library) + + install(TARGETS swift-run +- RUNTIME DESTINATION bin) ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/swift-sdk/CMakeLists.txt b/Sources/swift-sdk/CMakeLists.txt +index ee3be128b..4ed4a522a 100644 +--- a/Sources/swift-sdk/CMakeLists.txt ++++ b/Sources/swift-sdk/CMakeLists.txt +@@ -15,4 +15,4 @@ target_compile_options(swift-sdk PRIVATE + -parse-as-library) + + install(TARGETS swift-sdk +- RUNTIME DESTINATION bin) ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/swift-test/CMakeLists.txt b/Sources/swift-test/CMakeLists.txt +index 79c910294..ef2305587 100644 +--- a/Sources/swift-test/CMakeLists.txt ++++ b/Sources/swift-test/CMakeLists.txt +@@ -15,4 +15,4 @@ target_compile_options(swift-test PRIVATE + -parse-as-library) + + install(TARGETS swift-test +- RUNTIME DESTINATION bin) ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0002-darwin-swift-corelibs-xctest.patch b/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0002-darwin-swift-corelibs-xctest.patch new file mode 100644 index 000000000000..475cb0b2c893 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0002-darwin-swift-corelibs-xctest.patch @@ -0,0 +1,102 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 13 Dec 2025 22:57:10 -0500 +Subject: [PATCH 02/11] darwin-swift-corelibs-xctest + +--- + .../Commands/Utilities/TestingSupport.swift | 65 ------------------- + 1 file changed, 65 deletions(-) + +diff --git a/Sources/Commands/Utilities/TestingSupport.swift b/Sources/Commands/Utilities/TestingSupport.swift +index 81b329613..536babca5 100644 +--- a/Sources/Commands/Utilities/TestingSupport.swift ++++ b/Sources/Commands/Utilities/TestingSupport.swift +@@ -29,46 +29,6 @@ import func TSCBasic.withTemporaryFile + /// Note: In the long term this should be factored into a reusable module that + /// can run and report results on tests from both CLI and libSwiftPM API. + enum TestingSupport { +- /// Locates XCTestHelper tool inside the libexec directory and bin directory. +- /// Note: It is a fatalError if we are not able to locate the tool. +- /// +- /// - Returns: Path to XCTestHelper tool. +- static func xctestHelperPath(swiftCommandState: SwiftCommandState) throws -> AbsolutePath { +- var triedPaths = [AbsolutePath]() +- +- func findXCTestHelper(swiftBuildPath: AbsolutePath) -> AbsolutePath? { +- // XCTestHelper tool is installed in libexec. +- let maybePath = swiftBuildPath.parentDirectory.parentDirectory.appending( +- components: "libexec", "swift", "pm", "swiftpm-xctest-helper" +- ) +- if swiftCommandState.fileSystem.isFile(maybePath) { +- return maybePath +- } else { +- triedPaths.append(maybePath) +- return nil +- } +- } +- +- if let firstCLIArgument = CommandLine.arguments.first { +- let runningSwiftBuildPath = try AbsolutePath(validating: firstCLIArgument, relativeTo: swiftCommandState.originalWorkingDirectory) +- if let xctestHelperPath = findXCTestHelper(swiftBuildPath: runningSwiftBuildPath) { +- return xctestHelperPath +- } +- } +- +- // This will be true during swiftpm development or when using swift.org toolchains. +- let xcodePath = try AsyncProcess.checkNonZeroExit(args: "/usr/bin/xcode-select", "--print-path").spm_chomp() +- let installedSwiftBuildPath = try AsyncProcess.checkNonZeroExit( +- args: "/usr/bin/xcrun", "--find", "swift-build", +- environment: ["DEVELOPER_DIR": xcodePath] +- ).spm_chomp() +- if let xctestHelperPath = findXCTestHelper(swiftBuildPath: try AbsolutePath(validating: installedSwiftBuildPath)) { +- return xctestHelperPath +- } +- +- throw InternalError("XCTestHelper binary not found, tried \(triedPaths.map { $0.pathString }.joined(separator: ", "))") +- } +- + static func getTestSuites( + in testProducts: [BuiltTestProduct], + swiftCommandState: SwiftCommandState, +@@ -112,30 +72,6 @@ enum TestingSupport { + ) throws -> [TestSuite] { + // Run the correct tool. + var args = [String]() +- #if os(macOS) +- let data: String = try withTemporaryFile { tempFile in +- args = [try Self.xctestHelperPath(swiftCommandState: swiftCommandState).pathString, path.pathString, tempFile.path.pathString] +- let env = try Self.constructTestEnvironment( +- toolchain: try swiftCommandState.getTargetToolchain(), +- destinationBuildParameters: swiftCommandState.buildParametersForTest( +- enableCodeCoverage: enableCodeCoverage, +- shouldSkipBuilding: shouldSkipBuilding, +- experimentalTestOutput: experimentalTestOutput +- ).productsBuildParameters, +- sanitizers: sanitizers, +- library: .xctest +- ) +- try Self.runProcessWithExistenceCheck( +- path: path, +- fileSystem: swiftCommandState.fileSystem, +- args: args, +- env: env +- ) +- +- // Read the temporary file's content. +- return try swiftCommandState.fileSystem.readFileContents(AbsolutePath(tempFile.path)) +- } +- #else + let env = try Self.constructTestEnvironment( + toolchain: try swiftCommandState.getTargetToolchain(), + destinationBuildParameters: swiftCommandState.buildParametersForTest( +@@ -152,7 +88,6 @@ enum TestingSupport { + args: args, + env: env + ) +- #endif + // Parse json and return TestSuites. + return try TestSuite.parse(jsonString: data, context: args.joined(separator: " ")) + } +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0003-disable-sandbox.patch b/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0003-disable-sandbox.patch new file mode 100644 index 000000000000..dd9952255e9d --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0003-disable-sandbox.patch @@ -0,0 +1,47 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 13 Dec 2025 22:57:33 -0500 +Subject: [PATCH 03/11] disable-sandbox + +--- + Sources/Basics/Sandbox.swift | 22 ++++++++++++---------- + 1 file changed, 12 insertions(+), 10 deletions(-) + +diff --git a/Sources/Basics/Sandbox.swift b/Sources/Basics/Sandbox.swift +index f24636cac..8b65b2489 100644 +--- a/Sources/Basics/Sandbox.swift ++++ b/Sources/Basics/Sandbox.swift +@@ -57,18 +57,20 @@ public enum Sandbox { + allowNetworkConnections: [SandboxNetworkPermission] = [] + ) throws -> [String] { + #if os(macOS) +- let profile = try macOSSandboxProfile( +- fileSystem: fileSystem, +- strictness: strictness, +- writableDirectories: writableDirectories, +- readOnlyDirectories: readOnlyDirectories, +- allowNetworkConnections: allowNetworkConnections +- ) +- return ["/usr/bin/sandbox-exec", "-p", profile] + command +- #else ++ let env = ProcessInfo.processInfo.environment ++ if env["NIX_BUILD_TOP"] == nil || env["IN_NIX_SHELL"] != nil { ++ let profile = try macOSSandboxProfile( ++ fileSystem: fileSystem, ++ strictness: strictness, ++ writableDirectories: writableDirectories, ++ readOnlyDirectories: readOnlyDirectories, ++ allowNetworkConnections: allowNetworkConnections ++ ) ++ return ["/usr/bin/sandbox-exec", "-p", profile] + command ++ } ++ #endif + // rdar://40235432, rdar://75636874 tracks implementing sandboxes for other platforms. + return command +- #endif + } + + /// Basic strictness level of a sandbox applied to a command line. +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0005-fix-manifest-path.patch b/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0005-fix-manifest-path.patch new file mode 100644 index 000000000000..a9ac3f1db1b0 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0005-fix-manifest-path.patch @@ -0,0 +1,31 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 13 Dec 2025 22:58:33 -0500 +Subject: [PATCH 05/11] fix-manifest-path + +--- + Sources/PackageModel/UserToolchain.swift | 8 ++++++++ + 1 file changed, 8 insertions(+) + +diff --git a/Sources/PackageModel/UserToolchain.swift b/Sources/PackageModel/UserToolchain.swift +index 7f21304c6..39d7333c5 100644 +--- a/Sources/PackageModel/UserToolchain.swift ++++ b/Sources/PackageModel/UserToolchain.swift +@@ -956,6 +956,14 @@ public final class UserToolchain: Toolchain { + } + } + ++ // The manifest and plugin paths should be in the store if they’re nowhere else. ++ if let storeLibraryPath = try? Basics.AbsolutePath(validating: "@out@/lib/swift/pm") { ++ return .init( ++ manifestLibraryPath: storeLibraryPath.appending("ManifestAPI"), ++ pluginLibraryPath: storeLibraryPath.appending("PluginAPI") ++ ) ++ } ++ + // we are using a SwiftPM outside a toolchain, use the compiler path to compute the location + return .init(swiftCompilerPath: swiftCompilerPath) + } +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0006-nix-build-caches.patch b/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0006-nix-build-caches.patch new file mode 100644 index 000000000000..aa72be9610f4 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0006-nix-build-caches.patch @@ -0,0 +1,36 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 13 Dec 2025 22:58:44 -0500 +Subject: [PATCH 06/11] nix-build-caches + +--- + Sources/Basics/FileSystem/FileSystem+Extensions.swift | 6 ++++++ + 1 file changed, 6 insertions(+) + +diff --git a/Sources/Basics/FileSystem/FileSystem+Extensions.swift b/Sources/Basics/FileSystem/FileSystem+Extensions.swift +index 5f9674b2e..49f83e175 100644 +--- a/Sources/Basics/FileSystem/FileSystem+Extensions.swift ++++ b/Sources/Basics/FileSystem/FileSystem+Extensions.swift +@@ -12,6 +12,7 @@ + + import struct Foundation.Data + import class Foundation.FileManager ++import class Foundation.ProcessInfo + import struct Foundation.UUID + + import struct TSCBasic.ByteString +@@ -245,6 +246,11 @@ extension FileSystem { + /// SwiftPM cache directory under user's caches directory (if exists) + public var swiftPMCacheDirectory: AbsolutePath { + get throws { ++ let env = ProcessInfo.processInfo.environment ++ // Set up the caches in the build environment for Nix-managed builds ++ if let nixBuildTop = env["NIX_BUILD_TOP"] { ++ return try! AbsolutePath(validating: nixBuildTop).appending("swiftpm-cache") ++ } + if let path = self.idiomaticUserCacheDirectory { + return path.appending("org.swift.swiftpm") + } else { +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0007-nix-pkgconfig-vars.patch b/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0007-nix-pkgconfig-vars.patch new file mode 100644 index 000000000000..5721c1c66f43 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0007-nix-pkgconfig-vars.patch @@ -0,0 +1,41 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 13 Dec 2025 22:59:18 -0500 +Subject: [PATCH 07/11] nix-pkgconfig-vars + +--- + Sources/PackageLoading/PkgConfig.swift | 17 ++++++++++------- + 1 file changed, 10 insertions(+), 7 deletions(-) + +diff --git a/Sources/PackageLoading/PkgConfig.swift b/Sources/PackageLoading/PkgConfig.swift +index 21e0c514e..eaf9c803c 100644 +--- a/Sources/PackageLoading/PkgConfig.swift ++++ b/Sources/PackageLoading/PkgConfig.swift +@@ -131,14 +131,17 @@ public struct PkgConfig { + + private static var envSearchPaths: [Basics.AbsolutePath] { + get throws { +- if let configPath = Environment.current["PKG_CONFIG_PATH"] { +- #if os(Windows) +- return try configPath.split(separator: ";").map({ try AbsolutePath(validating: String($0)) }) +- #else +- return try configPath.split(separator: ":").map({ try AbsolutePath(validating: String($0)) }) +- #endif ++ var result: [Basics.AbsolutePath] = [] ++ for envVar in ["PKG_CONFIG_PATH", "PKG_CONFIG_PATH_FOR_TARGET"] { ++ if let configPath = Environment.current[EnvironmentKey(envVar)] { ++ #if os(Windows) ++ result += try configPath.split(separator: ";").map({ try Basics.AbsolutePath(validating: String($0)) }) ++ #else ++ result += try configPath.split(separator: ":").map({ try Basics.AbsolutePath(validating: String($0)) }) ++ #endif ++ } + } +- return [] ++ return result + } + } + } +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0008-set-compiler-vendor.patch b/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0008-set-compiler-vendor.patch new file mode 100644 index 000000000000..ea210e2efb26 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0008-set-compiler-vendor.patch @@ -0,0 +1,30 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 13 Dec 2025 22:59:36 -0500 +Subject: [PATCH 08/11] set-compiler-vendor + +--- + Sources/PackageModel/UserToolchain.swift | 6 ------ + 1 file changed, 6 deletions(-) + +diff --git a/Sources/PackageModel/UserToolchain.swift b/Sources/PackageModel/UserToolchain.swift +index 39d7333c5..b63997bad 100644 +--- a/Sources/PackageModel/UserToolchain.swift ++++ b/Sources/PackageModel/UserToolchain.swift +@@ -409,13 +409,7 @@ public final class UserToolchain: Toolchain { + } + + public func _isClangCompilerVendorApple() throws -> Bool? { +- // Assume the vendor is Apple on macOS. +- // FIXME: This might not be the best way to determine this. +- #if os(macOS) +- return true +- #else + return false +- #endif + } + + /// Returns the path to lldb. +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0009-add-missing-libraries.patch b/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0009-add-missing-libraries.patch new file mode 100644 index 000000000000..0f6fb621536f --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0009-add-missing-libraries.patch @@ -0,0 +1,45 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 13 Dec 2025 22:59:57 -0500 +Subject: [PATCH 09/11] add-missing-libraries + +--- + Sources/PackageSigning/CMakeLists.txt | 1 + + Sources/SwiftBuildSupport/CMakeLists.txt | 2 ++ + 2 files changed, 3 insertions(+) + +diff --git a/Sources/PackageSigning/CMakeLists.txt b/Sources/PackageSigning/CMakeLists.txt +index 13a7b8cd5..d00c7d01e 100644 +--- a/Sources/PackageSigning/CMakeLists.txt ++++ b/Sources/PackageSigning/CMakeLists.txt +@@ -21,6 +21,7 @@ target_link_libraries(PackageSigning PUBLIC + Basics + Crypto + PackageModel ++ SwiftASN1 + TSCBasic + TSCUtility + X509) +diff --git a/Sources/SwiftBuildSupport/CMakeLists.txt b/Sources/SwiftBuildSupport/CMakeLists.txt +index 3bd426bbf..c926ab811 100644 +--- a/Sources/SwiftBuildSupport/CMakeLists.txt ++++ b/Sources/SwiftBuildSupport/CMakeLists.txt +@@ -19,6 +19,7 @@ add_library(SwiftBuildSupport STATIC + PIFBuilder.swift + SwiftBuildSystem.swift) + target_link_libraries(SwiftBuildSupport PUBLIC ++ ArgumentParser + Build + DriverSupport + TSCBasic +@@ -26,6 +27,7 @@ target_link_libraries(SwiftBuildSupport PUBLIC + PackageGraph + SwiftBuild::SwiftBuild + SwiftBuild::SWBBuildService ++ SwiftSystem::SystemPackage + ) + + set_target_properties(SwiftBuildSupport PROPERTIES +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0010-Load-IndexStore-from-the-store.patch b/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0010-Load-IndexStore-from-the-store.patch new file mode 100644 index 000000000000..8d4e7cbf3889 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0010-Load-IndexStore-from-the-store.patch @@ -0,0 +1,35 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 11 Jul 2026 14:43:47 -0400 +Subject: [PATCH 10/11] Load IndexStore from the store + +--- + Sources/Build/LLBuildProgressTracker.swift | 9 +++------ + 1 file changed, 3 insertions(+), 6 deletions(-) + +diff --git a/Sources/Build/LLBuildProgressTracker.swift b/Sources/Build/LLBuildProgressTracker.swift +index 63a6a6caa..ac9b63419 100644 +--- a/Sources/Build/LLBuildProgressTracker.swift ++++ b/Sources/Build/LLBuildProgressTracker.swift +@@ -114,15 +114,12 @@ public final class BuildExecutionContext { + // library is currently installed as `libIndexStore.dll` rather than + // `IndexStore.dll`. In the future, this may require a fallback + // search, preferring `IndexStore.dll` over `libIndexStore.dll`. +- let indexStoreLib = self.toolsBuildParameters.toolchain.swiftCompilerPath +- .parentDirectory +- .appending("libIndexStore.dll") ++ let indexStoreLib = TSCAbsolutePath("@libclang@").appending(components: "lib", "libIndexStore.dll") + #else + let ext = self.toolsBuildParameters.triple.dynamicLibraryExtension +- let indexStoreLib = try toolsBuildParameters.toolchain.toolchainLibDir +- .appending("libIndexStore" + ext) ++ let indexStoreLib = TSCAbsolutePath("@libclang@").appending(components: "lib", "libIndexStore" + ext) + #endif +- return try .success(IndexStoreAPI(dylib: TSCAbsolutePath(indexStoreLib))) ++ return try .success(IndexStoreAPI(dylib: indexStoreLib)) + } catch { + return .failure(error) + } +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0011-Always-find-Clang-in-the-toolchain.patch b/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0011-Always-find-Clang-in-the-toolchain.patch new file mode 100644 index 000000000000..618822002a2f --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0011-Always-find-Clang-in-the-toolchain.patch @@ -0,0 +1,40 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sun, 23 Aug 2026 21:49:05 -0400 +Subject: [PATCH 11/11] Always find Clang in the toolchain +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +We want Swift to be usable in a default stdenv, which means `CC` is GCC +on Linux. Since SwiftPM doesn’t actually support GCC, use Clang from the +toolchain. This means you can’t override the Clang version, but that’s +probably not a good idea usually. +--- + Sources/PackageModel/UserToolchain.swift | 10 ---------- + 1 file changed, 10 deletions(-) + +diff --git a/Sources/PackageModel/UserToolchain.swift b/Sources/PackageModel/UserToolchain.swift +index b63997bad..903bdeba3 100644 +--- a/Sources/PackageModel/UserToolchain.swift ++++ b/Sources/PackageModel/UserToolchain.swift +@@ -377,16 +377,6 @@ public final class UserToolchain: Toolchain { + return clang + } + +- // Check in the environment variable first. +- if let toolPath = UserToolchain.lookup( +- variable: "CC", +- searchPaths: self.envSearchPaths, +- environment: environment +- ) { +- self._clangCompiler = toolPath +- return toolPath +- } +- + // Then, check the toolchain. + if let toolPath = try? UserToolchain.getTool( + "clang", +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/package.nix b/pkgs/development/compilers/swift/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/package.nix new file mode 100644 index 000000000000..ab218a518210 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/package.nix @@ -0,0 +1,53 @@ +{ + lib, + stdenv, + stdlib, + swift, + swiftpm, +}: + +stdenv.mkDerivation { + name = "test-swiftpm-backdeploy-references-stdlib"; + + src = ./src; + + strictDeps = true; + + nativeBuildInputs = [ + swift + swiftpm + ]; + + doCheck = true; + + checkPhase = '' + swift run -c release | grep 'x: 1;x: 2;x: 3;x: 4' + ''; + + postFixup = '' + # This check has to be done post-fixup to make sure the stdlib’s rpath hook has run. + foundStdlib=0 + foundSwift=0 + + IFS= readarray -d $'\n' -t rpaths < <(objdump --macho --rpaths $out/bin/backdeploy-references-stdlib | tail -n +2) + for rpath in "''${rpaths[@]}"; do + if [[ "$rpath" =~ ${lib.escapeShellArg (lib.getLib stdlib)} ]]; then + foundStdlib=1 + fi + if [[ "$rpath" =~ ${lib.escapeShellArg (lib.getLib swift)} ]]; then + foundSwift=1 + fi + done + rm -rf "$out" + if [[ "$foundStdlib" == 0 || "$foundSwift" == 1 ]]; then + exit 1 + else + touch "$out" + fi + ''; + + __structuredAttrs = true; + + # Backdeployment is only used on Darwin. + meta.platforms = lib.platforms.darwin; +} diff --git a/pkgs/development/compilers/swift/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/src/Package.swift b/pkgs/development/compilers/swift/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/src/Package.swift new file mode 100644 index 000000000000..d5d9308d9948 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/src/Package.swift @@ -0,0 +1,14 @@ +// swift-tools-version: 6.2 + +import PackageDescription + +let package = Package( + name: "backdeploy-references-stdlib", + platforms: [.macOS("11.0")], + products: [ + .executable(name: "backdeploy-references-stdlib", targets: ["backdeploy-references-stdlib"]) + ], + targets: [ + .executableTarget(name: "backdeploy-references-stdlib", path: "Sources") + ] +) diff --git a/pkgs/development/compilers/swift/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/src/Sources/main.swift b/pkgs/development/compilers/swift/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/src/Sources/main.swift new file mode 100644 index 000000000000..6dbf25a4e06b --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/src/Sources/main.swift @@ -0,0 +1,11 @@ +// Array.span can’t be backdeployed, so we have to work with buffer pointers for the test. +// See: https://forums.swift.org/t/using-span-on-pre-26-apple-os-versions/80513/4 +let arr = [1, 2, 3, 4] + +// Avoid `error: lifetime-dependent value escapes its scope` by extending the lifetime of the span. +arr.withUnsafeBufferPointer { ptr in + let span = ptr.span + for idx in span.indices { + print("x: \(span[idx]);", terminator: "") + } +} diff --git a/pkgs/development/compilers/swift/swiftpm2nix/default.nix b/pkgs/development/compilers/swift/by-name/sw/swiftpm2nix/package.nix similarity index 92% rename from pkgs/development/compilers/swift/swiftpm2nix/default.nix rename to pkgs/development/compilers/swift/by-name/sw/swiftpm2nix/package.nix index 208067014730..24d84ea51502 100644 --- a/pkgs/development/compilers/swift/swiftpm2nix/default.nix +++ b/pkgs/development/compilers/swift/by-name/sw/swiftpm2nix/package.nix @@ -10,6 +10,8 @@ stdenv.mkDerivation { name = "swiftpm2nix"; + strictDeps = true; + nativeBuildInputs = [ makeWrapper ]; dontUnpack = true; @@ -29,6 +31,8 @@ stdenv.mkDerivation { passthru = callPackage ./support.nix { }; + __structuredAttrs = true; + meta = { description = "Generate a Nix expression to fetch swiftpm dependencies"; mainProgram = "swiftpm2nix"; diff --git a/pkgs/development/compilers/swift/swiftpm2nix/support.nix b/pkgs/development/compilers/swift/by-name/sw/swiftpm2nix/support.nix similarity index 52% rename from pkgs/development/compilers/swift/swiftpm2nix/support.nix rename to pkgs/development/compilers/swift/by-name/sw/swiftpm2nix/support.nix index 0ddab549b98d..07525e1b656a 100644 --- a/pkgs/development/compilers/swift/swiftpm2nix/support.nix +++ b/pkgs/development/compilers/swift/by-name/sw/swiftpm2nix/support.nix @@ -2,6 +2,9 @@ lib, fetchgit, formats, + jq, + swiftpmHook, + swiftpmUnpackHook, }: let inherit (lib) @@ -53,22 +56,51 @@ rec { # Configure phase snippet for use in packaging. configure = '' - mkdir -p .build/checkouts - ln -sf ${pinFile} ./Package.resolved - install -m 0600 ${workspaceStateFile} ./.build/workspace-state.json + swiftpmDeps=$NIX_BUILD_TOP/swiftpmDeps + mkdir -p "$swiftpmDeps/Packages" + + # Rewrite the workspace-state.json to put the packages in edit mode. This is needed for compatibility with + # `swiftpmUnpackDeps`, which uses edit mode for vendoring. + ${lib.getExe jq} ' + { + "object": { + "artifacts": .object.artifacts[] // [ ], + "dependencies": [ .object.dependencies[] | + { + "basedOn": .basedOn, + "packageRef": .packageRef, + "state": { + "name": "edited", + "path": null + }, + "subpath": .subpath, + } + ], + "prebuilts": [ ], + }, + "version": 7 + } + ' < ${workspaceStateFile} > "$swiftpmDeps/workspace-state.json" '' + concatStrings ( mapAttrsToList (name: src: '' - ln -s '${src}' '.build/checkouts/${name}' + ln -s '${src}' "$swiftpmDeps/Packages/${name}" '') sources ) + '' + swiftpmUnpackDeps + # Helper that makes a swiftpm dependency mutable by copying the source. swiftpmMakeMutable() { - local orig="$(readlink .build/checkouts/$1)" - rm .build/checkouts/$1 - cp -r "$orig" .build/checkouts/$1 - chmod -R u+w .build/checkouts/$1 + local checkoutDir=$NIX_BUILD_TOP/$sourceRoot/.build/checkouts + local orig=$(readlink -f "Packages/$1") + + mkdir -p "$checkoutDir" + cp -r "$orig" "$checkoutDir/$1" + chmod -R u+w "$checkoutDir/$1" + + rm "Packages/$1" + ln -s "$checkoutDir/$1" "Packages/$1" } ''; diff --git a/pkgs/development/compilers/swift/swiftpm2nix/swiftpm2nix.sh b/pkgs/development/compilers/swift/by-name/sw/swiftpm2nix/swiftpm2nix.sh old mode 100755 new mode 100644 similarity index 94% rename from pkgs/development/compilers/swift/swiftpm2nix/swiftpm2nix.sh rename to pkgs/development/compilers/swift/by-name/sw/swiftpm2nix/swiftpm2nix.sh index f5f9780aa95d..e5525c51b200 --- a/pkgs/development/compilers/swift/swiftpm2nix/swiftpm2nix.sh +++ b/pkgs/development/compilers/swift/by-name/sw/swiftpm2nix/swiftpm2nix.sh @@ -1,7 +1,7 @@ #!/usr/bin/env bash # Generates a Nix expression to fetch swiftpm dependencies, and a -# configurePhase snippet to prepare a working directory for swift-build. +# configurePhase snippet to prepare a working directory for swift build. set -eu -o pipefail shopt -s lastpipe @@ -13,7 +13,7 @@ if [[ ! -f "$stateFile" ]]; then fi stateVersion="$(jq .version $stateFile)" -if [[ $stateVersion -lt 5 || $stateVersion -gt 6 ]]; then +if [[ $stateVersion -lt 5 || $stateVersion -gt 7 ]]; then echo >&2 "Unsupported $stateFile version" exit 1 fi diff --git a/pkgs/development/compilers/swift/by-name/sw/swiftpmHook/package.nix b/pkgs/development/compilers/swift/by-name/sw/swiftpmHook/package.nix new file mode 100644 index 000000000000..8b3a253e4308 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swiftpmHook/package.nix @@ -0,0 +1,43 @@ +{ + lib, + cctools, + jq, + llvmPackages_upstream, + llvm_libtool, + makeSetupHook, + stdenv, + stdenvNoCC, + swiftpm, + swiftpmUnpackHook, +}: + +let + vtool = stdenvNoCC.mkDerivation { + pname = "cctools-vtool"; + version = lib.getVersion cctools; + + buildCommand = '' + mkdir -p "$out/bin" + ln -s ${lib.getExe' cctools "vtool"} "$out/bin/vtool" + ''; + }; +in + +makeSetupHook { + name = "${lib.getName swiftpm}-hook-${lib.getVersion swiftpm}"; + propagatedBuildInputs = [ + swiftpmUnpackHook + ] + ++ lib.optionals stdenvNoCC.hostPlatform.isDarwin [ + # SwiftPM requires these tools for builds on Darwin. + # It also requires xcrun, which is already part of the Darwin stdenv. + llvm_libtool + vtool + ]; + substitutions = { + inherit (stdenvNoCC.hostPlatform.extensions) sharedLibrary; + swiftPlatform = stdenv.hostPlatform.swift.platform; + install_name_tool = lib.getExe' llvmPackages_upstream.llvm "llvm-install-name-tool"; + jq = lib.getExe jq; + }; +} ./setup-hook.sh diff --git a/pkgs/development/compilers/swift/by-name/sw/swiftpmHook/setup-hook.sh b/pkgs/development/compilers/swift/by-name/sw/swiftpmHook/setup-hook.sh new file mode 100644 index 000000000000..2a76abd6a80e --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swiftpmHook/setup-hook.sh @@ -0,0 +1,169 @@ +# shellcheck shell=bash + +swiftpm_addCVars() { + swiftLibDir='.*/lib/swift\(_static\)?/\(host\|@swiftPlatform@\)\(/plugins\|/plugins/testing\|/testing\)?$' + while IFS= read -d "" d; do + # Avoid adding paths that have already been added + if [[ "${swiftpmFlags-}" =~ \ $d\ ]]; then + continue + fi + # Only add the folder if it actually contains Swift modules. + if [ -n "$(ls "$d"/*.swiftmodule)" ]; then + appendToVar swiftpmFlags -Xswiftc -I -Xswiftc "$d" + fi + # Compiler plugins + if [[ "$d" =~ plugins(/testing)?$ && -n "$(ls "$d"/*@sharedLibrary@)" ]]; then + appendToVar swiftpmFlags -Xswiftc -plugin-path -Xswiftc "$d" + fi + done < <(find "$1" -type d -and -regex "$swiftLibDir" -print0) +} + +addEnvHooks "$targetOffset" swiftpm_addCVars + +# Build using 'swift build'. +swiftpmBuildPhase() { + runHook preBuild + + local buildCores=1 + if [ "${enableParallelBuilding-1}" ]; then + buildCores="$NIX_BUILD_CORES" + fi + + local flagsArray=( + -j "$buildCores" + -c "${swiftpmBuildConfig-release}" + -Xswiftc -module-cache-path -Xswiftc "$NIX_BUILD_TOP/module-cache" + ) + concatTo flagsArray swiftpmFlags swiftpmFlagsArray + + echoCmd 'SwiftPM flags' "${flagsArray[@]}" + TERM=dumb swift build --disable-sandbox "${flagsArray[@]}" + + runHook postBuild +} + +if [ -z "${dontUseSwiftpmBuild-}" ] && [ -z "${buildPhase-}" ]; then + buildPhase=swiftpmBuildPhase +fi + +# Check using 'swift test'. +swiftpmCheckPhase() { + runHook preCheck + + local buildCores=1 + if [ "${enableParallelBuilding-1}" ]; then + buildCores="$NIX_BUILD_CORES" + fi + + local flagsArray=( + -j "$buildCores" + -c "${swiftpmBuildConfig-release}" + ) + concatTo flagsArray swiftpmFlags swiftpmFlagsArray + + echoCmd 'check flags' "${flagsArray[@]}" + TERM=dumb swift test "${flagsArray[@]}" + + runHook postCheck +} + +if [ -z "${dontUseSwiftpmCheck-}" ] && [ -z "${checkPhase-}" ]; then + checkPhase=swiftpmCheckPhase +fi + +# Helper used to find the binary output path. +# Useful for performing the installPhase of swiftpm packages. +swiftpmBinPath() { + local flagsArray=( + -c "${swiftpmBuildConfig-release}" + ) + concatTo flagsArray swiftpmFlags swiftpmFlagsArray + + swift build --show-bin-path "${flagsArray[@]}" +} + +# TODO: Support static libraries. +swiftpmInstallPhase() { + runHook preInstall + + local products=$(swiftpmBinPath) + while IFS= read -d "" exe; do + install -D -m 755 "$products/$exe" "${!outputBin}/bin/$exe" + done < <(swift package dump-package | @jq@ --raw-output0 '.products[] | select(.type | has("executable")) | .name') + + local libsToInstall=() + local modulesToInstall=() + + while IFS= read -d "" library; do + if [ -e "$products/lib$library@sharedLibrary@" ]; then + if isMachO "$products/lib$library@sharedLibrary@"; then + @install_name_tool@ "$products/lib$library@sharedLibrary@" \ + -id "${!outputLib}/lib/lib$library@sharedLibrary@" + fi + appendToVar libsToInstall "$products/lib$library@sharedLibrary@" + fi + if [ -e "$products/$library.swiftmodule" ]; then + appendToVar modulesToInstall "$products/$library.swiftmodule" + fi + if [ -e "$products/Modules/$library.swiftmodule" ]; then + appendToVar modulesToInstall "$products/Modules/$library.swiftmodule" + fi + done < <(swift package dump-package | @jq@ --raw-output0 '.products[] | select(.type | has("library")) | .name') + + if [ -n "${libsToInstall}" ]; then + install -D -t "${!outputLib}/lib" "${libsToInstall[@]}" + # Only install modules if there are any library products. + if [ -n "${modulesToInstall}" ]; then + install -D -t "${!outputInclude}/lib/swift/@swiftPlatform@" "${modulesToInstall[@]}" + fi + fi + + runHook postInstall +} + +if [ -z "${dontUseSwiftpmInstall-}" ] && [ -z "${installPhase-}" ]; then + installPhase=swiftpmInstallPhase +fi + +# Based on CMake’s setup-hook +makeSwiftPMFindLibs() { + local -A swiftpmLibFlags + isystem_seen= + iframework_seen= + for flag in ${NIX_CFLAGS_COMPILE-}; do + if test -n "$isystem_seen" && test -d "$flag"; then + isystem_seen= + swiftpmLibFlags["${flag}"]="-Xcc -isystem -Xcc" + elif test -n "$iframework_seen" && test -d "$flag"; then + iframework_seen= + swiftpmLibFlags["${flag}"]="-Xcc -iframework -Xcc" + else + isystem_seen= + iframework_seen= + case $flag in + -I*) + swiftpmLibFlags["${flag:2}"]="-Xcc -I -Xcc" + ;; + -L*) + swiftpmLibFlags["${flag:2}"]="-Xlinker -L -Xlinker" + ;; + -F*) + swiftpmLibFlags["${flag:2}"]="-Xcc -F -Xcc" + ;; + -isystem) + isystem_seen=1 + ;; + -iframework) + iframework_seen=1 + ;; + esac + fi + done + for flag in "${!swiftpmLibFlags[@]}"; do + appendToVar swiftpmFlags ${swiftpmLibFlags["${flag}"]} "$flag" + done +} + +# not using setupHook, because it could be a setupHook adding additional +# include flags to NIX_CFLAGS_COMPILE +postHooks+=(makeSwiftPMFindLibs) diff --git a/pkgs/development/compilers/swift/by-name/sw/swiftpmUnpackHook/package.nix b/pkgs/development/compilers/swift/by-name/sw/swiftpmUnpackHook/package.nix new file mode 100644 index 000000000000..e3c19f343b7e --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swiftpmUnpackHook/package.nix @@ -0,0 +1,13 @@ +{ + lib, + jq, + makeSetupHook, + swiftpm, +}: + +makeSetupHook { + name = "${lib.getName swiftpm}-unpack-hook-${lib.getVersion swiftpm}"; + substitutions = { + jq = lib.getExe jq; + }; +} ./setup-hook.sh diff --git a/pkgs/development/compilers/swift/by-name/sw/swiftpmUnpackHook/setup-hook.sh b/pkgs/development/compilers/swift/by-name/sw/swiftpmUnpackHook/setup-hook.sh new file mode 100644 index 000000000000..c991654efa92 --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/sw/swiftpmUnpackHook/setup-hook.sh @@ -0,0 +1,46 @@ +# shellcheck shell=bash + +swiftpmUnpackDeps() { + if [ -n "$swiftpmDeps" ]; then + echo "Unpacking SwiftPM dependencies" + + # Set up `workspace-state.json`. Local packages must be added now, or SwiftPM will try to fetch their dependencies. + mkdir -p "$NIX_BUILD_TOP/$sourceRoot/.build" + @jq@ -s --sort-keys ' + { + "object": { + "artifacts": [ ], + "dependencies": ( + (.[0] | .object.dependencies) + + [ .[1] | .dependencies[] | select(.fileSystem) | .[][] | + { + "basedOn": null, + "packageRef": { + "identity": .identity, + "kind": "fileSystem", + "location": .path, + "name": .path | sub("\\.git$"; "") | split("/")[-1] + }, + "state": { + "name": "fileSystem", + "path": .path + }, + "subpath": .identity + } + ] + ), + "prebuilts": [ ], + }, + "version": 7 + } + ' "$swiftpmDeps/workspace-state.json" <(swift package dump-package --package-path "$NIX_BUILD_TOP/$sourceRoot") \ + > "$NIX_BUILD_TOP/$sourceRoot/.build/workspace-state.json~" + mv "$NIX_BUILD_TOP/$sourceRoot/.build/workspace-state.json~" "$NIX_BUILD_TOP/$sourceRoot/.build/workspace-state.json" + + # The closest thing to vendoring SwiftPM supports is setting up a dependencies as edited at `Packages`. + ln -s "$swiftpmDeps/Packages" "$NIX_BUILD_TOP/$sourceRoot/Packages" + fi +} + +appendToVar postUnpackHooks swiftpmUnpackDeps + diff --git a/pkgs/development/compilers/swift/compiler/default.nix b/pkgs/development/compilers/swift/compiler/default.nix deleted file mode 100644 index 454bee2c49f7..000000000000 --- a/pkgs/development/compilers/swift/compiler/default.nix +++ /dev/null @@ -1,842 +0,0 @@ -{ - lib, - stdenv, - callPackage, - cmake, - bash, - coreutils, - gnugrep, - perl, - ninja_1_11, - pkg-config, - clang, - bintools, - python312Packages, - git, - fetchpatch, - fetchpatch2, - makeWrapper, - gnumake, - file, - runCommand, - writeShellScriptBin, - # For lldb - libedit, - ncurses, - swig, - libxml2, - # Linux-specific - glibc, - libuuid, - # Darwin-specific - replaceVars, - fixDarwinDylibNames, - xcbuild, - cctools, # libtool - sigtool, - DarwinTools, - apple-sdk_14, - darwinMinVersionHook, -}: - -let - apple-sdk_swift = apple-sdk_14; # Use the SDK that was available when Swift shipped. - - deploymentVersion = - if lib.versionOlder (targetPlatform.darwinMinVersion or "0") "10.15" then - "10.15" - else - targetPlatform.darwinMinVersion; - - # Use Python 3.12 for now because Swift 5.8 depends on Python's PyEval_ThreadsInitialized(), which was removed in 3.13. - python3 = python312Packages.python.withPackages (p: [ p.setuptools ]); # python 3.12 compat. - - inherit (stdenv) hostPlatform targetPlatform; - - sources = callPackage ../sources.nix { }; - - # There are apparently multiple naming conventions on Darwin. Swift uses the - # xcrun naming convention. See `configure_sdk_darwin` calls in CMake files. - swiftOs = - if targetPlatform.isDarwin then - { - "macos" = "macosx"; - "ios" = "iphoneos"; - #iphonesimulator - #appletvos - #appletvsimulator - #watchos - #watchsimulator - } - .${targetPlatform.darwinPlatform} - or (throw "Cannot build Swift for target Darwin platform '${targetPlatform.darwinPlatform}'") - else - targetPlatform.parsed.kernel.name; - - # This causes swiftPackages.XCTest to fail to build on aarch64-linux - # as I believe this is because Apple calls the architecture aarch64 - # on Linux rather than arm64 when used with macOS. - swiftArch = - if hostPlatform.isDarwin then hostPlatform.darwinArch else targetPlatform.parsed.cpu.name; - - # On Darwin, a `.swiftmodule` is a subdirectory in `lib/swift/`, - # containing binaries for supported archs. On other platforms, binaries are - # installed to `lib/swift//`. Note that our setup-hook also adds - # `lib/swift` for convenience. - swiftLibSubdir = "lib/swift/${swiftOs}"; - swiftModuleSubdir = - if hostPlatform.isDarwin then "lib/swift/${swiftOs}" else "lib/swift/${swiftOs}/${swiftArch}"; - - # And then there's also a separate subtree for statically linked modules. - toStaticSubdir = lib.replaceStrings [ "/swift/" ] [ "/swift_static/" ]; - swiftStaticLibSubdir = toStaticSubdir swiftLibSubdir; - swiftStaticModuleSubdir = toStaticSubdir swiftModuleSubdir; - - # This matches _SWIFT_DEFAULT_COMPONENTS, with specific components disabled. - swiftInstallComponents = [ - "autolink-driver" - "compiler" - # "clang-builtin-headers" - "stdlib" - "sdk-overlay" - "static-mirror-lib" - "editor-integration" - # "tools" - # "testsuite-tools" - "toolchain-tools" - "toolchain-dev-tools" - "license" - (if stdenv.hostPlatform.isDarwin then "sourcekit-xpc-service" else "sourcekit-inproc") - "swift-remote-mirror" - "swift-remote-mirror-headers" - ]; - - clangForWrappers = clang.override (prev: { - extraBuildCommands = - prev.extraBuildCommands - # We need to use the resource directory corresponding to Swift’s - # version of Clang instead of passing along the one from the - # `cc-wrapper` flags. - + '' - substituteInPlace $out/nix-support/cc-cflags \ - --replace-fail " -resource-dir=$out/resource-root" "" - '' - + - lib.optionalString - (targetPlatform.isLinux && targetPlatform.isx86 && lib.versionAtLeast (lib.getVersion clang) "19.1") - '' - # Swift bundles Clang 16, which predates -mtls-dialect=gnu2 - # support (added in Clang 19.1). The cc-wrapper adds it based - # on the system Clang version, so strip it here. - substituteInPlace $out/nix-support/add-local-cc-cflags-before.sh \ - --replace-fail "'-mtls-dialect=gnu2'" "" - ''; - }); - - # Build a tool used during the build to create a custom clang wrapper, with - # which we wrap the clang produced by the swift build. - # - # This is used in a `POST_BUILD` for the CMake target, so we rename the - # actual clang to clang-unwrapped, then put the wrapper in place. - # - # We replace the `exec ...` command with `exec -a "$0"` in order to - # preserve $0 for clang. This is because, unlike Nix, we don't have - # separate wrappers for clang/clang++, and clang uses $0 to detect C++. - # - # Similarly, the C++ detection in the wrapper itself also won't work for us, - # so we base it on $0 as well. - makeClangWrapper = writeShellScriptBin "nix-swift-make-clang-wrapper" '' - set -euo pipefail - - targetFile="$1" - unwrappedClang="$targetFile-unwrapped" - - mv "$targetFile" "$unwrappedClang" - sed < '${clangForWrappers}/bin/clang' > "$targetFile" \ - -e 's|^\s*exec|exec -a "$0"|g' \ - -e 's|^\[\[ "${clang.cc}/bin/clang" = \*++ ]]|[[ "$0" = *++ ]]|' \ - -e "s|${clang.cc}/bin/clang|$unwrappedClang|g" \ - -e "s|^\(\s*\)\($unwrappedClang\) \"@\\\$responseFile\"|\1argv0=\$0\n\1${bash}/bin/bash -c \"exec -a '\$argv0' \2 '@\$responseFile'\"|" \ - ${lib.optionalString (clang.libcxx != null) '' - -e 's|$NIX_CXXSTDLIB_COMPILE_${clang.suffixSalt}|-isystem '$SWIFT_BUILD_ROOT'/libcxx/include/c++/v1|g' - ''} - chmod a+x "$targetFile" - ''; - - # Create a tool used during the build to create a custom swift wrapper for - # each of the swift executables produced by the build. - # - # The build produces several `swift-frontend` executables during - # bootstrapping. Each of these has numerous aliases via symlinks, and the - # executable uses $0 to detect what tool is called. - wrapperParams = { - inherit bintools; - coreutils_bin = lib.getBin coreutils; - gnugrep_bin = gnugrep; - suffixSalt = lib.replaceStrings [ "-" "." ] [ "_" "_" ] targetPlatform.config; - use_response_file_by_default = 1; - swiftDriver = ""; - # NOTE: @cc_wrapper@ and @prog@ need to be filled elsewhere. - }; - swiftWrapper = runCommand "swift-wrapper.sh" wrapperParams '' - # Make empty to avoid adding the SDK’s modules in the bootstrap wrapper. Otherwise, the SDK conflicts with the - # shims the wrapper tries to build. - darwinMinVersion="" substituteAll '${../wrapper/wrapper.sh}' "$out" - ''; - makeSwiftcWrapper = writeShellScriptBin "nix-swift-make-swift-wrapper" '' - set -euo pipefail - - targetFile="$1" - unwrappedSwift="$targetFile-unwrapped" - - mv "$targetFile" "$unwrappedSwift" - sed < '${swiftWrapper}' > "$targetFile" \ - -e "s|@prog@|'$unwrappedSwift'|g" \ - -e 's|@cc_wrapper@|${clangForWrappers}|g' \ - -e 's|exec "$prog"|exec -a "$0" "$prog"|g' \ - ${lib.optionalString (clang.libcxx != null) '' - -e 's|$NIX_CXXSTDLIB_COMPILE_${clang.suffixSalt}|-isystem '$SWIFT_BUILD_ROOT'/libcxx/include/c++/v1|g' - ''} - chmod a+x "$targetFile" - ''; - - # On Darwin, we need to use BOOTSTRAPPING-WITH-HOSTLIBS because of ABI - # stability, and have to provide the definitions for the system stdlib. - appleSwiftCore = stdenv.mkDerivation { - name = "apple-swift-core"; - dontUnpack = true; - - buildInputs = [ apple-sdk_swift ]; - - installPhase = '' - mkdir -p $out/lib/swift - cp -r \ - "$SDKROOT/usr/lib/swift/Swift.swiftmodule" \ - "$SDKROOT/usr/lib/swift/CoreFoundation.swiftmodule" \ - "$SDKROOT/usr/lib/swift/Dispatch.swiftmodule" \ - "$SDKROOT/usr/lib/swift/ObjectiveC.swiftmodule" \ - "$SDKROOT/usr/lib/swift/libswiftCore.tbd" \ - "$SDKROOT/usr/lib/swift/libswiftCoreFoundation.tbd" \ - "$SDKROOT/usr/lib/swift/libswiftDispatch.tbd" \ - "$SDKROOT/usr/lib/swift/libswiftFoundation.tbd" \ - "$SDKROOT/usr/lib/swift/libswiftObjectiveC.tbd" \ - $out/lib/swift/ - ''; - }; - - # https://github.com/NixOS/nixpkgs/issues/327836 - # Fail to build with ninja 1.12 when NIX_BUILD_CORES is low (Hydra or Github Actions). - # Can reproduce using `nix --option cores 2 build -f . swiftPackages.swift-unwrapped`. - # Until we find out the exact cause, follow [swift upstream][1], pin ninja to version - # 1.11.1. - # [1]: https://github.com/swiftlang/swift/pull/72989 - ninja = ninja_1_11; - -in -stdenv.mkDerivation { - pname = "swift"; - inherit (sources) version; - - outputs = [ - "out" - "lib" - "dev" - "doc" - "man" - ]; - - nativeBuildInputs = [ - cmake - git - ninja - perl # pod2man - pkg-config - python3 - makeWrapper - makeClangWrapper - makeSwiftcWrapper - ] - ++ lib.optionals stdenv.hostPlatform.isDarwin [ - xcbuild - sigtool # codesign - DarwinTools # sw_vers - fixDarwinDylibNames - cctools.libtool - ]; - - buildInputs = [ - # For lldb - python3 - swig - libxml2 - ] - ++ lib.optionals stdenv.hostPlatform.isLinux [ - libuuid - ] - ++ lib.optionals stdenv.hostPlatform.isDarwin [ - apple-sdk_swift - ]; - - # Will effectively be `buildInputs` when swift is put in `nativeBuildInputs`. - depsTargetTargetPropagated = lib.optionals stdenv.targetPlatform.isDarwin [ - apple-sdk_swift - ]; - - # This is a partial reimplementation of our setup hook. Because we reuse - # the Swift wrapper for the Swift build itself, we need to do some of the - # same preparation. - postHook = '' - for pkg in "''${pkgsHostTarget[@]}" '${clang.libc}'; do - for subdir in ${swiftModuleSubdir} ${swiftStaticModuleSubdir} lib/swift; do - if [[ -d "$pkg/$subdir" ]]; then - export NIX_SWIFTFLAGS_COMPILE+=" -I $pkg/$subdir" - fi - done - for subdir in ${swiftLibSubdir} ${swiftStaticLibSubdir} lib/swift; do - if [[ -d "$pkg/$subdir" ]]; then - export NIX_LDFLAGS+=" -L $pkg/$subdir" - fi - done - done - ''; - - # We setup custom build directories. - dontUseCmakeBuildDir = true; - - unpackPhase = - let - copySource = repo: "cp -r ${sources.${repo}} ${repo}"; - in - '' - mkdir src - cd src - - ${copySource "swift-cmark"} - ${copySource "llvm-project"} - ${copySource "swift"} - ${copySource "swift-experimental-string-processing"} - ${copySource "swift-syntax"} - ${lib.optionalString (!stdenv.hostPlatform.isDarwin) (copySource "swift-corelibs-libdispatch")} - - chmod -R u+w . - ''; - - patchPhase = '' - # Just patch all the things for now, we can focus this later. - # TODO: eliminate use of env. - find -type f -print0 | xargs -0 sed -i \ - ${lib.optionalString stdenv.hostPlatform.isDarwin "-e 's|/usr/libexec/PlistBuddy|${xcbuild}/bin/PlistBuddy|g'"} \ - -e 's|/usr/bin/env|${coreutils}/bin/env|g' \ - -e 's|/usr/bin/make|${gnumake}/bin/make|g' \ - -e 's|/bin/mkdir|${coreutils}/bin/mkdir|g' \ - -e 's|/bin/cp|${coreutils}/bin/cp|g' \ - -e 's|/usr/bin/file|${file}/bin/file|g' - - patch -p1 -d swift -i ${./patches/swift-wrap.patch} - patch -p1 -d swift -i ${./patches/swift-linux-fix-libc-paths.patch} - patch -p1 -d swift -i ${ - replaceVars ./patches/swift-linux-fix-linking.patch { - inherit clang; - } - } - patch -p1 -d swift -i ${ - replaceVars ./patches/swift-darwin-plistbuddy-workaround.patch { - inherit swiftArch; - } - } - patch -p1 -d swift -i ${ - replaceVars ./patches/swift-prevent-sdk-dirs-warning.patch { - inherit (builtins) storeDir; - } - } - patch -p1 -d swift -i ${./patches/swift-Frontend-Fix-a-small-unique_ptr-array-access.patch} - - # This patch needs to know the lib output location, so must be substituted - # in the same derivation as the compiler. - storeDir="${builtins.storeDir}" \ - substituteAll ${./patches/swift-separate-lib.patch} $TMPDIR/swift-separate-lib.patch - patch -p1 -d swift -i $TMPDIR/swift-separate-lib.patch - - patch -p1 -d llvm-project/llvm -i ${./patches/llvm-module-cache.patch} - for root in llvm-project/llvm swift/stdlib; do - patch -p1 -d $root -i ${ - (fetchpatch { - name = "fix-SmallVector-compile-error.patch"; - url = "https://github.com/llvm/llvm-project/commit/7e44305041d96b064c197216b931ae3917a34ac1.patch"; - stripLen = 1; - hash = "sha256-1htuzsaPHbYgravGc1vrR8sqpQ/NSQ8PUZeAU8ucCFk="; - }) - } - done - patch -p2 -d llvm-project/llvm -i ${./patches/llvm-fix-X86MCTargetDesc-compile-error.patch} - - for lldbPatch in ${ - lib.escapeShellArgs [ - # Fix the build with modern libc++. - (fetchpatch { - name = "add-cstdio.patch"; - url = "https://github.com/llvm/llvm-project/commit/73e15b5edb4fa4a77e68c299a6e3b21e610d351f.patch"; - stripLen = 1; - hash = "sha256-eFcvxZaAuBsY/bda1h9212QevrXyvCHw8Cr9ngetDr0="; - }) - (fetchpatch { - url = "https://github.com/llvm/llvm-project/commit/68744ffbdd7daac41da274eef9ac0d191e11c16d.patch"; - stripLen = 1; - hash = "sha256-QCGhsL/mi7610ZNb5SqxjRGjwJeK2rwtsFVGeG3PUGc="; - }) - (fetchpatch { - name = "LLDB-Add-cstdint-to-AddressableBits-102110.patch"; - url = "https://github.com/llvm/llvm-project/commit/bb59f04e7e75dcbe39f1bf952304a157f0035314.patch"; - stripLen = 1; - hash = "sha256-+CcmZRxCaozFe1Kuf2HX+kGKuh/PDuoFBEFA/t7tL9A="; - }) - ] - }; do - patch -p1 -d llvm-project/lldb -i $lldbPatch - done - - patch -p1 -d llvm-project/clang -i ${./patches/clang-toolchain-dir.patch} - patch -p1 -d llvm-project/clang -i ${./patches/clang-wrap.patch} - patch -p1 -d llvm-project/clang -i ${./patches/clang-purity.patch} - - patch -p1 -d llvm-project/cmake -i ${ - fetchpatch2 { - name = "cmake-fix.patch"; - url = "https://github.com/llvm/llvm-project/commit/3676a86a4322e8c2b9c541f057b5d3704146b8f3.patch?full_index=1"; - stripLen = 1; - hash = "sha256-zP9dQOmWs7qrxkBRj70DyQBbRjH78B6tNJVy6ilA1xM="; - } - } - - ${lib.optionalString stdenv.hostPlatform.isLinux '' - substituteInPlace llvm-project/clang/lib/Driver/ToolChains/Linux.cpp \ - --replace-fail 'LibDir = "lib";' 'LibDir = "${glibc}/lib";' \ - --replace-fail 'LibDir = "lib64";' 'LibDir = "${glibc}/lib";' \ - --replace-fail 'LibDir = X32 ? "libx32" : "lib64";' 'LibDir = "${glibc}/lib";' - - # uuid.h is not part of glibc, but of libuuid. - sed -i 's|''${GLIBC_INCLUDE_PATH}/uuid/uuid.h|${libuuid.dev}/include/uuid/uuid.h|' \ - swift/stdlib/public/Platform/glibc.modulemap.gyb - ''} - - # Remove tests for cross compilation, which we don't currently support. - rm swift/test/Interop/Cxx/class/constructors-copy-irgen-*.swift - rm swift/test/Interop/Cxx/class/constructors-irgen-*.swift - - # TODO: consider fixing and re-adding. This test fails due to a non-standard "install_prefix". - rm swift/validation-test/Python/build_swift.swift - - # We cannot handle the SDK location being in "Weird Location" due to Nix isolation. - rm swift/test/DebugInfo/compiler-flags.swift - - # TODO: Fix issue with ld.gold invoked from script finding crtbeginS.o and crtendS.o. - rm swift/test/IRGen/ELF-remove-autolink-section.swift - - # The following two tests fail because we use don't use the bundled libicu: - # [SOURCE_DIR/utils/build-script] ERROR: can't find source directory for libicu (tried /build/src/icu) - rm swift/validation-test/BuildSystem/default_build_still_performs_epilogue_opts_after_split.test - rm swift/validation-test/BuildSystem/test_early_swift_driver_and_infer.swift - - # TODO: This test fails for some unknown reason - rm swift/test/Serialization/restrict-swiftmodule-to-revision.swift - - # This test was flaky in ofborg, see #186476 - rm swift/test/AutoDiff/compiler_crashers_fixed/issue-56649-missing-debug-scopes-in-pullback-trampoline.swift - - patchShebangs . - - ${lib.optionalString (!stdenv.hostPlatform.isDarwin) '' - patch -p1 -d swift-corelibs-libdispatch -i ${ - # Fix the build with modern Clang. - fetchpatch { - url = "https://github.com/swiftlang/swift-corelibs-libdispatch/commit/30bb8019ba79cdae0eb1dc0c967c17996dd5cc0a.patch"; - hash = "sha256-wPZQ4wtEWk8HaKMfzjamlU6p/IW5EFiTssY63rGM+ZA="; - } - } - patch -p1 -d swift-corelibs-libdispatch -i ${ - # Fix the build with modern Clang. - fetchpatch { - url = "https://github.com/swiftlang/swift-corelibs-libdispatch/commit/38872e2d44d66d2fb94186988509defc734888a5.patch"; - hash = "sha256-GABwDeTjciV36Sa0FS10mCfFCqRoBBstgW/OiKdPahA="; - } - } - ''} - ''; - - # > clang-15-unwrapped: error: unsupported option '-fzero-call-used-regs=used-gpr' for target 'arm64-apple-macosx10.9.0' - # > clang-15-unwrapped: error: argument unused during compilation: '-fstack-clash-protection' [-Werror,-Wunused-command-line-argument] - hardeningDisable = lib.optionals stdenv.hostPlatform.isAarch64 [ - "zerocallusedregs" - "stackclashprotection" - ]; - - configurePhase = '' - export SWIFT_SOURCE_ROOT="$PWD" - mkdir -p ../build - cd ../build - export SWIFT_BUILD_ROOT="$PWD" - ''; - - # These steps are derived from doing a normal build with. - # - # ./swift/utils/build-toolchain test --dry-run - # - # But dealing with the custom Python build system is far more trouble than - # simply invoking CMake directly. Few variables it passes to CMake are - # actually required or non-default. - # - # Using CMake directly also allows us to split up the already large build, - # and package Swift components separately. - # - # Besides `--dry-run`, another good way to compare build changes between - # Swift releases is to diff the scripts: - # - # git diff swift-5.6.3-RELEASE..swift-5.7-RELEASE -- utils/build* - # - buildPhase = '' - # Helper to build a subdirectory. - # - # Always reset cmakeFlags before calling this. The cmakeConfigurePhase - # amends flags and would otherwise keep expanding it. - function buildProject() { - mkdir -p $SWIFT_BUILD_ROOT/$1 - cd $SWIFT_BUILD_ROOT/$1 - - cmakeDir=$SWIFT_SOURCE_ROOT/''${2-$1} - cmakeConfigurePhase - - ninjaBuildPhase - } - - cmakeFlags="-GNinja" - buildProject swift-cmark - - ${lib.optionalString (clang.libcxx != null) '' - # Install the libc++ headers corresponding to the LLVM version of - # Swift’s Clang. - cmakeFlags=" - -GNinja - -DLLVM_ENABLE_RUNTIMES=libcxx;libcxxabi - -DLIBCXXABI_INSTALL_INCLUDE_DIR=$dev/include/c++/v1 - " - ninjaFlags="install-cxx-headers install-cxxabi-headers" - buildProject libcxx llvm-project/runtimes - unset ninjaFlags - ''} - - # Some notes: - # - The Swift build just needs Clang. - # - We can further reduce targets to just our targetPlatform. - cmakeFlags=" - -GNinja - -DLLVM_BUILD_TOOLS=NO - -DLLVM_ENABLE_PROJECTS=clang - -DLLVM_TARGETS_TO_BUILD=${ - { - "x86_64" = "X86"; - "aarch64" = "AArch64"; - } - .${targetPlatform.parsed.cpu.name} - or (throw "Unsupported CPU architecture: ${targetPlatform.parsed.cpu.name}") - } - " - buildProject llvm llvm-project/llvm - - # Ensure that the built Clang can find the runtime libraries by - # copying the symlinks from the main wrapper. - cp -P ${clang}/resource-root/{lib,share} $SWIFT_BUILD_ROOT/llvm/lib/clang/16.0.0/ - - '' - + lib.optionalString stdenv.hostPlatform.isDarwin '' - # Add appleSwiftCore to the search paths. Adding the whole SDK results in build failures. - OLD_NIX_SWIFTFLAGS_COMPILE="$NIX_SWIFTFLAGS_COMPILE" - OLD_NIX_LDFLAGS="$NIX_LDFLAGS" - OLD_NIX_CFLAGS_COMPILE="$NIX_CFLAGS_COMPILE" - export NIX_SWIFTFLAGS_COMPILE=" -I ${appleSwiftCore}/lib/swift" - export NIX_LDFLAGS+=" -L ${appleSwiftCore}/lib/swift" - export NIX_CFLAGS_COMPILE+=" -Wno-error=unguarded-availability" - '' - + '' - - # Some notes: - # - BOOTSTRAPPING_MODE defaults to OFF in CMake, but is enabled in standard - # builds, so we enable it as well. On Darwin, we have to use the system - # Swift libs because of ABI-stability, but this may be trouble if the - # builder is an older macOS. - # - Experimental features are OFF by default in CMake, but are enabled in - # official builds, so we do the same. (Concurrency is also required in - # the stdlib. StringProcessing is often implicitely imported, causing - # lots of warnings if missing.) - # - SWIFT_STDLIB_ENABLE_OBJC_INTEROP is set explicitely because its check - # is buggy. (Uses SWIFT_HOST_VARIANT_SDK before initialized.) - # Fixed in: https://github.com/apple/swift/commit/84083afef1de5931904d5c815d53856cdb3fb232 - cmakeFlags=" - -GNinja - -DBOOTSTRAPPING_MODE=BOOTSTRAPPING${lib.optionalString stdenv.hostPlatform.isDarwin "-WITH-HOSTLIBS"} - -DSWIFT_ENABLE_EXPERIMENTAL_DIFFERENTIABLE_PROGRAMMING=ON - -DSWIFT_ENABLE_EXPERIMENTAL_CONCURRENCY=ON - -DSWIFT_ENABLE_EXPERIMENTAL_CXX_INTEROP=ON - -DSWIFT_ENABLE_EXPERIMENTAL_DISTRIBUTED=ON - -DSWIFT_ENABLE_EXPERIMENTAL_STRING_PROCESSING=ON - -DSWIFT_ENABLE_BACKTRACING=ON - -DSWIFT_ENABLE_EXPERIMENTAL_OBSERVATION=ON - -DLLVM_DIR=$SWIFT_BUILD_ROOT/llvm/lib/cmake/llvm - -DClang_DIR=$SWIFT_BUILD_ROOT/llvm/lib/cmake/clang - -DSWIFT_PATH_TO_CMARK_SOURCE=$SWIFT_SOURCE_ROOT/swift-cmark - -DSWIFT_PATH_TO_CMARK_BUILD=$SWIFT_BUILD_ROOT/swift-cmark - -DSWIFT_PATH_TO_LIBDISPATCH_SOURCE=$SWIFT_SOURCE_ROOT/swift-corelibs-libdispatch - -DSWIFT_PATH_TO_SWIFT_SYNTAX_SOURCE=$SWIFT_SOURCE_ROOT/swift-syntax - -DSWIFT_PATH_TO_STRING_PROCESSING_SOURCE=$SWIFT_SOURCE_ROOT/swift-experimental-string-processing - -DSWIFT_INSTALL_COMPONENTS=${lib.concatStringsSep ";" swiftInstallComponents} - -DSWIFT_STDLIB_ENABLE_OBJC_INTEROP=${if stdenv.hostPlatform.isDarwin then "ON" else "OFF"} - -DSWIFT_DARWIN_DEPLOYMENT_VERSION_OSX=${deploymentVersion} - " - buildProject swift - - '' - + lib.optionalString stdenv.hostPlatform.isDarwin '' - # Restore search paths to remove appleSwiftCore. - export NIX_SWIFTFLAGS_COMPILE="$OLD_NIX_SWIFTFLAGS_COMPILE" - export NIX_LDFLAGS="$OLD_NIX_LDFLAGS" - export NIX_CFLAGS_COMPILE="$OLD_NIX_CFLAGS_COMPILE" - '' - + '' - - # These are based on flags in `utils/build-script-impl`. - # - # LLDB_USE_SYSTEM_DEBUGSERVER=ON disables the debugserver build on Darwin, - # which requires a special signature. - # - # CMAKE_BUILD_WITH_INSTALL_NAME_DIR ensures we don't use rpath on Darwin. - cmakeFlags=" - -GNinja - -DLLDB_SWIFTC=$SWIFT_BUILD_ROOT/swift/bin/swiftc - -DLLDB_SWIFT_LIBS=$SWIFT_BUILD_ROOT/swift/lib/swift - -DLLVM_DIR=$SWIFT_BUILD_ROOT/llvm/lib/cmake/llvm - -DClang_DIR=$SWIFT_BUILD_ROOT/llvm/lib/cmake/clang - -DSwift_DIR=$SWIFT_BUILD_ROOT/swift/lib/cmake/swift - -DLLDB_ENABLE_CURSES=ON - -DLLDB_ENABLE_LIBEDIT=ON - -DLLDB_ENABLE_PYTHON=ON - -DLLDB_ENABLE_LZMA=OFF - -DLLDB_ENABLE_LUA=OFF - -DLLDB_INCLUDE_TESTS=OFF - -DCMAKE_BUILD_WITH_INSTALL_NAME_DIR=ON - ${lib.optionalString stdenv.hostPlatform.isDarwin '' - -DLLDB_USE_SYSTEM_DEBUGSERVER=ON - ''} - -DLibEdit_INCLUDE_DIRS=${lib.getInclude libedit}/include - -DLibEdit_LIBRARIES=${lib.getLib libedit}/lib/libedit${stdenv.hostPlatform.extensions.sharedLibrary} - -DCURSES_INCLUDE_DIRS=${lib.getInclude ncurses}/include - -DCURSES_LIBRARIES=${lib.getLib ncurses}/lib/libncurses${stdenv.hostPlatform.extensions.sharedLibrary} - -DPANEL_LIBRARIES=${lib.getLib ncurses}/lib/libpanel${stdenv.hostPlatform.extensions.sharedLibrary} - "; - buildProject lldb llvm-project/lldb - - ${lib.optionalString stdenv.targetPlatform.isDarwin '' - # Need to do a standalone build of concurrency for Darwin back deployment. - # Based on: utils/swift_build_support/swift_build_support/products/backdeployconcurrency.py - cmakeFlags=" - -GNinja - -DCMAKE_Swift_COMPILER=$SWIFT_BUILD_ROOT/swift/bin/swiftc - -DSWIFT_PATH_TO_SWIFT_SYNTAX_SOURCE=$SWIFT_SOURCE_ROOT/swift-syntax - - -DTOOLCHAIN_DIR=/var/empty - -DSWIFT_NATIVE_LLVM_TOOLS_PATH=${stdenv.cc}/bin - -DSWIFT_NATIVE_CLANG_TOOLS_PATH=${stdenv.cc}/bin - -DSWIFT_NATIVE_SWIFT_TOOLS_PATH=$SWIFT_BUILD_ROOT/swift/bin - - -DCMAKE_CROSSCOMPILING=ON - - -DBUILD_SWIFT_CONCURRENCY_BACK_DEPLOYMENT_LIBRARIES=ON - -DSWIFT_INCLUDE_TOOLS=OFF - -DSWIFT_BUILD_STDLIB_EXTRA_TOOLCHAIN_CONTENT=OFF - -DSWIFT_BUILD_TEST_SUPPORT_MODULES=OFF - -DSWIFT_BUILD_STDLIB=OFF - -DSWIFT_BUILD_DYNAMIC_STDLIB=OFF - -DSWIFT_BUILD_STATIC_STDLIB=OFF - -DSWIFT_BUILD_REMOTE_MIRROR=OFF - -DSWIFT_BUILD_SDK_OVERLAY=OFF - -DSWIFT_BUILD_DYNAMIC_SDK_OVERLAY=OFF - -DSWIFT_BUILD_STATIC_SDK_OVERLAY=OFF - -DSWIFT_INCLUDE_TESTS=OFF - -DSWIFT_BUILD_PERF_TESTSUITE=OFF - - -DSWIFT_HOST_VARIANT_ARCH=${swiftArch} - -DBUILD_STANDALONE=ON - - -DSWIFT_INSTALL_COMPONENTS=back-deployment - - -DSWIFT_SDKS=${ - { - "macos" = "OSX"; - "ios" = "IOS"; - #IOS_SIMULATOR - #TVOS - #TVOS_SIMULATOR - #WATCHOS - #WATCHOS_SIMULATOR - } - .${targetPlatform.darwinPlatform} - } - - -DLLVM_DIR=$SWIFT_BUILD_ROOT/llvm/lib/cmake/llvm - - -DSWIFT_DEST_ROOT=$out - -DSWIFT_HOST_VARIANT_SDK=OSX - - -DSWIFT_DARWIN_DEPLOYMENT_VERSION_OSX=${deploymentVersion} - -DSWIFT_DARWIN_DEPLOYMENT_VERSION_IOS=13.0 - -DSWIFT_DARWIN_DEPLOYMENT_VERSION_MACCATALYST=13.0 - -DSWIFT_DARWIN_DEPLOYMENT_VERSION_TVOS=13.0 - -DSWIFT_DARWIN_DEPLOYMENT_VERSION_WATCHOS=6.0 - " - - # This depends on the special Clang build specific to the Swift branch. - # We also need to call a specific Ninja target. - export CC=$SWIFT_BUILD_ROOT/llvm/bin/clang - export CXX=$SWIFT_BUILD_ROOT/llvm/bin/clang++ - ninjaFlags="back-deployment" - - buildProject swift-concurrency-backdeploy swift - - export CC=$NIX_CC/bin/clang - export CXX=$NIX_CC/bin/clang++ - unset ninjaFlags - ''} - ''; - - # TODO: ~50 failing tests on x86_64-linux. Other platforms not checked. - doCheck = false; - nativeCheckInputs = [ file ]; - # TODO: consider using stress-tester and integration-test. - checkPhase = '' - cd $SWIFT_BUILD_ROOT/swift - checkTarget=check-swift-all - ninjaCheckPhase - unset checkTarget - ''; - - installPhase = '' - # Undo the clang and swift wrapping we did for the build. - # (This happened via patches to cmake files.) - cd $SWIFT_BUILD_ROOT - mv llvm/bin/clang-16{-unwrapped,} - mv swift/bin/swift-frontend{-unwrapped,} - - mkdir $lib - - # Install clang binaries only. We hide these with the wrapper, so they are - # for private use by Swift only. - cd $SWIFT_BUILD_ROOT/llvm - installTargets=install-clang - ninjaInstallPhase - unset installTargets - - # LLDB is also a private install. - cd $SWIFT_BUILD_ROOT/lldb - ninjaInstallPhase - - cd $SWIFT_BUILD_ROOT/swift - ninjaInstallPhase - - ${lib.optionalString stdenv.hostPlatform.isDarwin '' - cd $SWIFT_BUILD_ROOT/swift-concurrency-backdeploy - installTargets=install-back-deployment - ninjaInstallPhase - unset installTargets - ''} - - # Separate $lib output here, because specific logic follows. - # Only move the dynamic run-time parts, to keep $lib small. Every Swift - # build will depend on it. - moveToOutput "lib/swift" "$lib" - moveToOutput "lib/libswiftDemangle.*" "$lib" - - # This link is here because various tools (swiftpm) check for stdlib - # relative to the swift compiler. It's fine if this is for build-time - # stuff, but we should patch all cases were it would end up in an output. - ln -s $lib/lib/swift $out/lib/swift - - # Swift has a separate resource root from Clang, but locates the Clang - # resource root via subdir or symlink. - mv $SWIFT_BUILD_ROOT/llvm/lib/clang/16.0.0 $lib/lib/swift/clang - ''; - - preFixup = lib.optionalString stdenv.hostPlatform.isLinux '' - # This is cheesy, but helps the patchelf hook remove /build from RPATH. - cd $SWIFT_BUILD_ROOT/.. - mv build buildx - ''; - - postFixup = lib.optionalString stdenv.hostPlatform.isDarwin '' - # These libraries need to use the system install name. The official SDK - # does the same (as opposed to using rpath). Presumably, they are part of - # the stable ABI. Not using the system libraries at run-time is known to - # cause ObjC class conflicts and segfaults. - declare -A systemLibs=( - [libswiftCore.dylib]=1 - [libswiftDarwin.dylib]=1 - [libswiftSwiftOnoneSupport.dylib]=1 - [libswift_Concurrency.dylib]=1 - ) - - for systemLib in "''${!systemLibs[@]}"; do - install_name_tool -id /usr/lib/swift/$systemLib $lib/${swiftLibSubdir}/$systemLib - done - - for file in $out/bin/swift-frontend $lib/${swiftLibSubdir}/*.dylib; do - changeArgs="" - for dylib in $(otool -L $file | awk '{ print $1 }'); do - if [[ ''${systemLibs["$(basename $dylib)"]} ]]; then - changeArgs+=" -change $dylib /usr/lib/swift/$(basename $dylib)" - elif [[ "$dylib" = */bootstrapping1/* ]]; then - changeArgs+=" -change $dylib $lib/lib/swift/$(basename $dylib)" - fi - done - if [[ -n "$changeArgs" ]]; then - install_name_tool $changeArgs $file - fi - done - - wrapProgram $out/bin/swift-frontend \ - --prefix PATH : ${lib.makeBinPath [ cctools.libtool ]} - - # Needs to be propagated by the compiler not by its dev output. - moveToOutput nix-support/propagated-target-target-deps "$out" - ''; - - passthru = { - inherit - swiftOs - swiftArch - swiftModuleSubdir - swiftLibSubdir - swiftStaticModuleSubdir - swiftStaticLibSubdir - ; - - tests = { - cxx-interop-test = callPackage ../cxx-interop-test { }; - }; - - # Internal attr for the wrapper. - _wrapperParams = wrapperParams; - }; - - meta = { - description = "Swift Programming Language"; - homepage = "https://github.com/apple/swift"; - teams = [ lib.teams.swift ]; - license = lib.licenses.asl20; - platforms = [ - "x86_64-linux" - "aarch64-linux" - "x86_64-darwin" - "aarch64-darwin" - ]; - # Swift doesn't support 32-bit Linux, unknown on other platforms. - badPlatforms = lib.platforms.i686; - timeout = 86400; # 24 hours. - }; -} diff --git a/pkgs/development/compilers/swift/compiler/patches/clang-purity.patch b/pkgs/development/compilers/swift/compiler/patches/clang-purity.patch deleted file mode 100644 index dcb7771008d9..000000000000 --- a/pkgs/development/compilers/swift/compiler/patches/clang-purity.patch +++ /dev/null @@ -1,21 +0,0 @@ -From 4add81bba40dcec62c4ea4481be8e35ac53e89d8 Mon Sep 17 00:00:00 2001 -From: Will Dietz -Date: Thu, 18 May 2017 11:56:12 -0500 -Subject: [PATCH] "purity" patch for 5.0 - ---- clang/lib/Driver/ToolChains/Gnu.cpp -+++ clang/lib/Driver/ToolChains/Gnu.cpp -@@ -480,13 +480,6 @@ - } else { - if (Args.hasArg(options::OPT_rdynamic)) - CmdArgs.push_back("-export-dynamic"); -- -- if (!Args.hasArg(options::OPT_shared) && !IsStaticPIE && -- !Args.hasArg(options::OPT_r)) { -- CmdArgs.push_back("-dynamic-linker"); -- CmdArgs.push_back(Args.MakeArgString(Twine(D.DyldPrefix) + -- ToolChain.getDynamicLinker(Args))); -- } - } - - CmdArgs.push_back("-o"); diff --git a/pkgs/development/compilers/swift/compiler/patches/clang-toolchain-dir.patch b/pkgs/development/compilers/swift/compiler/patches/clang-toolchain-dir.patch deleted file mode 100644 index 40d7728cf788..000000000000 --- a/pkgs/development/compilers/swift/compiler/patches/clang-toolchain-dir.patch +++ /dev/null @@ -1,13 +0,0 @@ -Use the Nix include dirs and gcc runtime dir, when no sysroot is configured. - ---- a/lib/Driver/ToolChains/Linux.cpp -+++ b/lib/Driver/ToolChains/Linux.cpp -@@ -574,7 +574,7 @@ - - // Check for configure-time C include directories. - StringRef CIncludeDirs(C_INCLUDE_DIRS); -- if (CIncludeDirs != "") { -+ if (CIncludeDirs != "" && (SysRoot.empty() || SysRoot == "/")) { - SmallVector dirs; - CIncludeDirs.split(dirs, ":"); - for (StringRef dir : dirs) { diff --git a/pkgs/development/compilers/swift/compiler/patches/clang-wrap.patch b/pkgs/development/compilers/swift/compiler/patches/clang-wrap.patch deleted file mode 100644 index 9c6cafed3699..000000000000 --- a/pkgs/development/compilers/swift/compiler/patches/clang-wrap.patch +++ /dev/null @@ -1,18 +0,0 @@ -Wrap the clang produced during the build - ---- a/tools/driver/CMakeLists.txt -+++ b/tools/driver/CMakeLists.txt -@@ -59,6 +59,13 @@ endif() - - add_dependencies(clang clang-resource-headers) - -+# Nix: wrap the clang build. -+add_custom_command( -+ TARGET clang POST_BUILD -+ COMMAND nix-swift-make-clang-wrapper $ -+ VERBATIM -+) -+ - if(NOT CLANG_LINKS_TO_CREATE) - set(CLANG_LINKS_TO_CREATE clang++ clang-cl clang-cpp) - endif() diff --git a/pkgs/development/compilers/swift/compiler/patches/llvm-fix-X86MCTargetDesc-compile-error.patch b/pkgs/development/compilers/swift/compiler/patches/llvm-fix-X86MCTargetDesc-compile-error.patch deleted file mode 100644 index 3ced4d2c32b8..000000000000 --- a/pkgs/development/compilers/swift/compiler/patches/llvm-fix-X86MCTargetDesc-compile-error.patch +++ /dev/null @@ -1,34 +0,0 @@ -From f03ab75680385b1ea62af3ab15c423a3bc0f3588 Mon Sep 17 00:00:00 2001 -From: Stephan Hageboeck -Date: Mon, 20 Jan 2025 17:52:47 +0100 -Subject: [PATCH] Add missing include to X86MCTargetDesc.h (#123320) - -In gcc-15, explicit includes of `` are required when fixed-size -integers are used. In this file, this include only happened as a side -effect of including SmallVector.h - -Although llvm compiles fine, the root-project would benefit from -explicitly including it here, so we can backport the patch. - -Maybe interesting for @hahnjo and @vgvassilev - -(cherry picked from commit 7abf44069aec61eee147ca67a6333fc34583b524) ---- - llvm/lib/Target/X86/MCTargetDesc/X86MCTargetDesc.h | 1 + - 1 file changed, 1 insertion(+) - -diff --git a/llvm/lib/Target/X86/MCTargetDesc/X86MCTargetDesc.h b/llvm/lib/Target/X86/MCTargetDesc/X86MCTargetDesc.h -index d0530bd4d650..10b59462aebe 100644 ---- a/llvm/lib/Target/X86/MCTargetDesc/X86MCTargetDesc.h -+++ b/llvm/lib/Target/X86/MCTargetDesc/X86MCTargetDesc.h -@@ -13,6 +13,7 @@ - #ifndef LLVM_LIB_TARGET_X86_MCTARGETDESC_X86MCTARGETDESC_H - #define LLVM_LIB_TARGET_X86_MCTARGETDESC_X86MCTARGETDESC_H - -+#include - #include - #include - --- -2.52.0 - diff --git a/pkgs/development/compilers/swift/compiler/patches/swift-Frontend-Fix-a-small-unique_ptr-array-access.patch b/pkgs/development/compilers/swift/compiler/patches/swift-Frontend-Fix-a-small-unique_ptr-array-access.patch deleted file mode 100644 index 0059c7f7c9ee..000000000000 --- a/pkgs/development/compilers/swift/compiler/patches/swift-Frontend-Fix-a-small-unique_ptr-array-access.patch +++ /dev/null @@ -1,35 +0,0 @@ -From 1a2293c7593e4eeb3fbad74fa8d362abafb43b56 Mon Sep 17 00:00:00 2001 -From: Tony Allevato -Date: Wed, 9 Oct 2024 13:54:43 -0400 -Subject: [PATCH] [Frontend] Fix a small `unique_ptr` array access. - -When the size of the array accessed here is zero, retrieving the -address of the zero-th element here is undefined. When the frontend -is linked against a libc++ that has the `unique_ptr` hardening in -[this commit](https://github.com/llvm/llvm-project/commit/18df9d23ea390eaa50b41f3083a42f700a2b0e39) -enabled, it traps here. - -Instead, simply call `.get()` to retrieve the address of the -array, which works even when it is a zero-byte allocation. - -(cherry picked from commit bdf40184ab40eb59642cd825781d71d0711493eb) ---- - lib/FrontendTool/FrontendTool.cpp | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/lib/FrontendTool/FrontendTool.cpp b/lib/FrontendTool/FrontendTool.cpp -index afbc57cdf2f..ba64a306494 100644 ---- a/lib/FrontendTool/FrontendTool.cpp -+++ b/lib/FrontendTool/FrontendTool.cpp -@@ -2202,7 +2202,7 @@ int swift::performFrontend(ArrayRef Args, - std::make_unique[]>( - configurationFileBuffers.size()); - for_each(configurationFileBuffers.begin(), configurationFileBuffers.end(), -- &configurationFileStackTraces[0], -+ configurationFileStackTraces.get(), - [](const std::unique_ptr &buffer, - llvm::Optional &trace) { - trace.emplace(*buffer); --- -2.52.0 - diff --git a/pkgs/development/compilers/swift/compiler/patches/swift-darwin-plistbuddy-workaround.patch b/pkgs/development/compilers/swift/compiler/patches/swift-darwin-plistbuddy-workaround.patch deleted file mode 100644 index a3cf4f60675c..000000000000 --- a/pkgs/development/compilers/swift/compiler/patches/swift-darwin-plistbuddy-workaround.patch +++ /dev/null @@ -1,17 +0,0 @@ -CMake tries to read a list field from SDKSettings.plist, but the output of -facebook/xcbuild PlistBuddy is incompatible with Apple's. - -Simply set the supported architectures to the one target architecture we're -building for. - ---- a/cmake/modules/SwiftConfigureSDK.cmake -+++ b/cmake/modules/SwiftConfigureSDK.cmake -@@ -189,7 +189,7 @@ macro(configure_sdk_darwin - endif() - - # Remove any architectures not supported by the SDK. -- remove_sdk_unsupported_archs(${name} ${xcrun_name} ${SWIFT_SDK_${prefix}_PATH} SWIFT_SDK_${prefix}_ARCHITECTURES) -+ set(SWIFT_SDK_${prefix}_ARCHITECTURES "@swiftArch@") - - list_intersect( - "${SWIFT_DARWIN_MODULE_ARCHS}" # lhs diff --git a/pkgs/development/compilers/swift/compiler/patches/swift-linux-fix-linking.patch b/pkgs/development/compilers/swift/compiler/patches/swift-linux-fix-linking.patch deleted file mode 100644 index c10b4038a9c4..000000000000 --- a/pkgs/development/compilers/swift/compiler/patches/swift-linux-fix-linking.patch +++ /dev/null @@ -1,17 +0,0 @@ -diff --git a/lib/Driver/ToolChains.cpp b/lib/Driver/ToolChains.cpp -index c0ee9217e8..bf7737d6fa 100644 ---- a/lib/Driver/ToolChains.cpp -+++ b/lib/Driver/ToolChains.cpp -@@ -1489,6 +1489,12 @@ - LinkerDriver = Args.MakeArgString(tool.get()); - } - -+ // For Nix, prefer linking using the wrapped Nixpkgs clang, instead of using -+ // the unwrapped clang packaged with swift. The latter is unable to link, but -+ // we still want to use it for other purposes (clang importer). -+ if (auto tool = llvm::sys::findProgramByName(LinkerDriver, {"@clang@/bin"})) -+ return Args.MakeArgString(tool.get()); -+ - return LinkerDriver; - } - diff --git a/pkgs/development/compilers/swift/compiler/patches/swift-prevent-sdk-dirs-warning.patch b/pkgs/development/compilers/swift/compiler/patches/swift-prevent-sdk-dirs-warning.patch deleted file mode 100644 index 987b99d74539..000000000000 --- a/pkgs/development/compilers/swift/compiler/patches/swift-prevent-sdk-dirs-warning.patch +++ /dev/null @@ -1,39 +0,0 @@ -Prevents a user-visible warning on every compilation: - - ld: warning: directory not found for option '-L.../MacOSX11.0.sdk/usr/lib/swift' - ---- a/lib/Driver/ToolChains.cpp -+++ b/lib/Driver/ToolChains.cpp -@@ -1455,9 +1455,11 @@ void ToolChain::getRuntimeLibraryPaths(SmallVectorImpl &runtimeLibP - runtimeLibPaths.push_back(std::string(scratchPath.str())); - } - -+ if (!SDKPath.startswith("@storeDir@")) { - scratchPath = SDKPath; - llvm::sys::path::append(scratchPath, "usr", "lib", "swift"); - runtimeLibPaths.push_back(std::string(scratchPath.str())); -+ } - } - } - ---- a/lib/Frontend/CompilerInvocation.cpp -+++ b/lib/Frontend/CompilerInvocation.cpp -@@ -185,7 +185,9 @@ static void updateRuntimeLibraryPaths(SearchPathOptions &SearchPathOpts, - RuntimeLibraryImportPaths.push_back(std::string(LibPath.str())); - } - -- LibPath = SearchPathOpts.getSDKPath(); -+ auto SDKPath = SearchPathOpts.getSDKPath(); -+ if (!SDKPath.startswith("@storeDir@")) { -+ LibPath = SDKPath; - llvm::sys::path::append(LibPath, "usr", "lib", "swift"); - if (!Triple.isOSDarwin()) { - // Use the non-architecture suffixed form with directory-layout -@@ -200,6 +202,7 @@ static void updateRuntimeLibraryPaths(SearchPathOptions &SearchPathOpts, - llvm::sys::path::append(LibPath, swift::getMajorArchitectureName(Triple)); - } - RuntimeLibraryImportPaths.push_back(std::string(LibPath.str())); -+ } - } - SearchPathOpts.setRuntimeLibraryImportPaths(RuntimeLibraryImportPaths); - } diff --git a/pkgs/development/compilers/swift/compiler/patches/swift-separate-lib.patch b/pkgs/development/compilers/swift/compiler/patches/swift-separate-lib.patch deleted file mode 100644 index 20d81a6e8296..000000000000 --- a/pkgs/development/compilers/swift/compiler/patches/swift-separate-lib.patch +++ /dev/null @@ -1,26 +0,0 @@ -Patch paths to use the separate 'lib' output. One of the things this patch -fixes is the output of `swift -frontend -print-target-info`, which swiftpm uses -to set rpath on Linux. - -The check if the executable path starts with 'out' is necessary for -bootstrapping, or the compiler will fail when run from the build directory. - ---- a/lib/Frontend/CompilerInvocation.cpp -+++ b/lib/Frontend/CompilerInvocation.cpp -@@ -49,11 +49,16 @@ swift::CompilerInvocation::CompilerInvocation() { - void CompilerInvocation::computeRuntimeResourcePathFromExecutablePath( - StringRef mainExecutablePath, bool shared, - llvm::SmallVectorImpl &runtimeResourcePath) { -+ if (mainExecutablePath.startswith("@storeDir@")) { -+ auto libPath = StringRef("@lib@"); -+ runtimeResourcePath.append(libPath.begin(), libPath.end()); -+ } else { - runtimeResourcePath.append(mainExecutablePath.begin(), - mainExecutablePath.end()); - - llvm::sys::path::remove_filename(runtimeResourcePath); // Remove /swift - llvm::sys::path::remove_filename(runtimeResourcePath); // Remove /bin -+ } - appendSwiftLibDir(runtimeResourcePath, shared); - } - diff --git a/pkgs/development/compilers/swift/compiler/patches/swift-wrap.patch b/pkgs/development/compilers/swift/compiler/patches/swift-wrap.patch deleted file mode 100644 index e4697f631e70..000000000000 --- a/pkgs/development/compilers/swift/compiler/patches/swift-wrap.patch +++ /dev/null @@ -1,46 +0,0 @@ -Wrap the swift compiler produced during the build - ---- a/tools/driver/CMakeLists.txt -+++ b/tools/driver/CMakeLists.txt -@@ -16,6 +16,13 @@ if(${LIBSWIFT_BUILD_MODE} MATCHES "BOOTSTRAPPING.*") - swiftDriverTool - libswiftStub) - -+ # Nix: wrap the swift build. -+ add_custom_command( -+ TARGET swift-frontend-bootstrapping0 POST_BUILD -+ COMMAND nix-swift-make-swift-wrapper $ -+ VERBATIM -+ ) -+ - swift_create_post_build_symlink(swift-frontend-bootstrapping0 - SOURCE "swift-frontend${CMAKE_EXECUTABLE_SUFFIX}" - DESTINATION "swiftc${CMAKE_EXECUTABLE_SUFFIX}" -@@ -34,6 +41,13 @@ if(${LIBSWIFT_BUILD_MODE} MATCHES "BOOTSTRAPPING.*") - swiftDriverTool - libswift-bootstrapping1) - -+ # Nix: wrap the swift build. -+ add_custom_command( -+ TARGET swift-frontend-bootstrapping1 POST_BUILD -+ COMMAND nix-swift-make-swift-wrapper $ -+ VERBATIM -+ ) -+ - swift_create_post_build_symlink(swift-frontend-bootstrapping1 - SOURCE "swift-frontend${CMAKE_EXECUTABLE_SUFFIX}" - DESTINATION "swiftc${CMAKE_EXECUTABLE_SUFFIX}" -@@ -50,6 +64,13 @@ target_link_libraries(swift-frontend - swiftDriverTool - libswift) - -+# Nix: wrap the swift build. -+add_custom_command( -+ TARGET swift-frontend POST_BUILD -+ COMMAND nix-swift-make-swift-wrapper $ -+ VERBATIM -+) -+ - # Create a `swift-driver` executable adjacent to the `swift-frontend` executable - # to ensure that `swiftc` forwards to the standalone driver when invoked. - swift_create_early_driver_copies(swift-frontend) diff --git a/pkgs/development/compilers/swift/cxx-interop-test/default.nix b/pkgs/development/compilers/swift/cxx-interop-test/default.nix deleted file mode 100644 index 12640750d622..000000000000 --- a/pkgs/development/compilers/swift/cxx-interop-test/default.nix +++ /dev/null @@ -1,57 +0,0 @@ -{ - lib, - stdenv, - swift, - swiftpm, - swiftPackages, -}: - -swiftPackages.stdenv.mkDerivation (finalAttrs: { - name = "swift-cxx-interop-test"; - - src = ./src; - - nativeBuildInputs = [ - swift - swiftpm - ]; - - installPhase = '' - runHook preInstall - - binPath="$(swiftpmBinPath)" - mkdir -p -- "$out/bin" - cp -- "$binPath/${finalAttrs.meta.mainProgram}" "$out/bin" - - runHook postInstall - ''; - - installCheckPhase = '' - runHook preInstallCheck - - "$out/bin/${finalAttrs.meta.mainProgram}" | grep 'Hello, world!' - - runHook postInstallCheck - ''; - - doInstallCheck = true; - - env = { - # Gross hack copied from `protoc-gen-swift` :( - LD_LIBRARY_PATH = lib.optionalString stdenv.hostPlatform.isLinux ( - lib.makeLibraryPath [ - swiftPackages.Dispatch - ] - ); - }; - - meta = { - inherit (swift.meta) - team - platforms - badPlatforms - ; - license = lib.licenses.mit; - mainProgram = "CxxInteropTest"; - }; -}) diff --git a/pkgs/development/compilers/swift/cxx-interop-test/src/.gitignore b/pkgs/development/compilers/swift/cxx-interop-test/src/.gitignore deleted file mode 100644 index 3b29812086f2..000000000000 --- a/pkgs/development/compilers/swift/cxx-interop-test/src/.gitignore +++ /dev/null @@ -1,9 +0,0 @@ -.DS_Store -/.build -/Packages -/*.xcodeproj -xcuserdata/ -DerivedData/ -.swiftpm/config/registries.json -.swiftpm/xcode/package.xcworkspace/contents.xcworkspacedata -.netrc diff --git a/pkgs/development/compilers/swift/cxx-interop-test/src/Sources/main.swift b/pkgs/development/compilers/swift/cxx-interop-test/src/Sources/main.swift deleted file mode 100644 index abe1c879beba..000000000000 --- a/pkgs/development/compilers/swift/cxx-interop-test/src/Sources/main.swift +++ /dev/null @@ -1,3 +0,0 @@ -import CxxStdlib - -print(String(std.string("Hello, world!"))) diff --git a/pkgs/development/compilers/swift/default.nix b/pkgs/development/compilers/swift/default.nix deleted file mode 100644 index ad4fe81c46cb..000000000000 --- a/pkgs/development/compilers/swift/default.nix +++ /dev/null @@ -1,85 +0,0 @@ -{ - lib, - newScope, - stdenv, - llvmPackages, - darwin, -}: - -let - self = rec { - - callPackage = newScope self; - - # Provided for backwards compatibility. - inherit stdenv; - - swift-unwrapped = callPackage ./compiler { - inherit (llvmPackages) stdenv; - inherit (darwin) DarwinTools sigtool; - }; - - swiftNoSwiftDriver = callPackage ./wrapper { - swift = swift-unwrapped; - useSwiftDriver = false; - }; - - Dispatch = - if stdenv.hostPlatform.isDarwin then - null # part of apple-sdk - else - callPackage ./libdispatch { - inherit (llvmPackages) stdenv; - swift = swiftNoSwiftDriver; - }; - - Foundation = - if stdenv.hostPlatform.isDarwin then - null # part of apple-sdk - else - callPackage ./foundation { - inherit (llvmPackages) stdenv; - swift = swiftNoSwiftDriver; - }; - - # TODO: Apple distributes a binary XCTest with Xcode, but it is not part of - # CLTools (or SUS), so would have to figure out how to fetch it. The binary - # version has several extra features, like a test runner and ObjC support. - XCTest = callPackage ./xctest { - inherit (darwin) DarwinTools; - swift = swiftNoSwiftDriver; - }; - - swiftpm = callPackage ./swiftpm { - inherit (llvmPackages) stdenv; - inherit (darwin) DarwinTools; - swift = swiftNoSwiftDriver; - }; - - swift-driver = callPackage ./swift-driver { - inherit (llvmPackages) stdenv; - swift = swiftNoSwiftDriver; - }; - - swift = callPackage ./wrapper { - swift = swift-unwrapped; - }; - - sourcekit-lsp = callPackage ./sourcekit-lsp { - inherit (llvmPackages) stdenv; - }; - - swift-docc = callPackage ./swift-docc { - inherit (llvmPackages) stdenv; - }; - - swift-format = callPackage ./swift-format { - inherit (llvmPackages) stdenv; - }; - - swiftpm2nix = callPackage ./swiftpm2nix { }; - - }; - -in -self diff --git a/pkgs/development/compilers/swift/foundation/default.nix b/pkgs/development/compilers/swift/foundation/default.nix deleted file mode 100644 index 60d781ed7746..000000000000 --- a/pkgs/development/compilers/swift/foundation/default.nix +++ /dev/null @@ -1,71 +0,0 @@ -{ - lib, - stdenv, - fetchpatch, - callPackage, - cmake, - ninja, - swift, - Dispatch, - icu, - libxml2, - curl, -}: - -let - sources = callPackage ../sources.nix { }; -in -stdenv.mkDerivation { - pname = "swift-corelibs-foundation"; - - inherit (sources) version; - src = sources.swift-corelibs-foundation; - - outputs = [ - "out" - "dev" - ]; - - nativeBuildInputs = [ - cmake - ninja - swift - ]; - buildInputs = [ - icu - libxml2 - curl - ]; - propagatedBuildInputs = [ Dispatch ]; - - preConfigure = '' - # Fails to build with -D_FORTIFY_SOURCE. - NIX_HARDENING_ENABLE=''${NIX_HARDENING_ENABLE/fortify/} - ''; - - postInstall = '' - # Split up the output. - mkdir $dev - mv $out/lib/swift/${swift.swiftOs} $out/swiftlibs - mv $out/lib/swift $dev/include - mkdir $out/lib/swift - mv $out/swiftlibs $out/lib/swift/${swift.swiftOs} - - # Provide a CMake module. This is primarily used to glue together parts of - # the Swift toolchain. Modifying the CMake config to do this for us is - # otherwise more trouble. - mkdir -p $dev/lib/cmake/Foundation - export dylibExt="${stdenv.hostPlatform.extensions.sharedLibrary}" - export swiftOs="${swift.swiftOs}" - substituteAll ${./glue.cmake} $dev/lib/cmake/Foundation/FoundationConfig.cmake - ''; - - meta = { - description = "Core utilities, internationalization, and OS independence for Swift"; - mainProgram = "plutil"; - homepage = "https://github.com/apple/swift-corelibs-foundation"; - platforms = lib.platforms.linux; - license = lib.licenses.asl20; - teams = [ lib.teams.swift ]; - }; -} diff --git a/pkgs/development/compilers/swift/foundation/glue.cmake b/pkgs/development/compilers/swift/foundation/glue.cmake deleted file mode 100644 index a34984d19f04..000000000000 --- a/pkgs/development/compilers/swift/foundation/glue.cmake +++ /dev/null @@ -1,8 +0,0 @@ -add_library(Foundation SHARED IMPORTED) -set_property(TARGET Foundation PROPERTY IMPORTED_LOCATION "@out@/lib/swift/@swiftOs@/libFoundation@dylibExt@") - -add_library(FoundationNetworking SHARED IMPORTED) -set_property(TARGET FoundationNetworking PROPERTY IMPORTED_LOCATION "@out@/lib/swift/@swiftOs@/libFoundationNetworking@dylibExt@") - -add_library(FoundationXML SHARED IMPORTED) -set_property(TARGET FoundationXML PROPERTY IMPORTED_LOCATION "@out@/lib/swift/@swiftOs@/libFoundationXML@dylibExt@") diff --git a/pkgs/development/compilers/swift/libdispatch/default.nix b/pkgs/development/compilers/swift/libdispatch/default.nix deleted file mode 100644 index 3c99720ef75c..000000000000 --- a/pkgs/development/compilers/swift/libdispatch/default.nix +++ /dev/null @@ -1,68 +0,0 @@ -{ - lib, - stdenv, - callPackage, - fetchpatch, - cmake, - ninja, - useSwift ? true, - swift, -}: - -let - sources = callPackage ../sources.nix { }; -in -stdenv.mkDerivation { - pname = "swift-corelibs-libdispatch"; - - inherit (sources) version; - src = sources.swift-corelibs-libdispatch; - - outputs = [ - "out" - "dev" - "man" - ]; - - nativeBuildInputs = [ - cmake - ] - ++ lib.optionals useSwift [ - ninja - swift - ]; - - patches = [ - # Fix the build with modern Clang. - (fetchpatch { - url = "https://github.com/swiftlang/swift-corelibs-libdispatch/commit/30bb8019ba79cdae0eb1dc0c967c17996dd5cc0a.patch"; - hash = "sha256-wPZQ4wtEWk8HaKMfzjamlU6p/IW5EFiTssY63rGM+ZA="; - }) - (fetchpatch { - url = "https://github.com/swiftlang/swift-corelibs-libdispatch/commit/38872e2d44d66d2fb94186988509defc734888a5.patch"; - hash = "sha256-GABwDeTjciV36Sa0FS10mCfFCqRoBBstgW/OiKdPahA="; - }) - - ./disable-swift-overlay.patch - ]; - - cmakeFlags = lib.optional useSwift "-DENABLE_SWIFT=ON"; - - postInstall = '' - # Provide a CMake module. This is primarily used to glue together parts of - # the Swift toolchain. Modifying the CMake config to do this for us is - # otherwise more trouble. - mkdir -p $dev/lib/cmake/dispatch - export dylibExt="${stdenv.hostPlatform.extensions.sharedLibrary}" - substituteAll ${./glue.cmake} $dev/lib/cmake/dispatch/dispatchConfig.cmake - ''; - - meta = { - description = "Grand Central Dispatch"; - homepage = "https://github.com/swiftlang/swift-corelibs-libdispatch"; - platforms = lib.platforms.linux; - license = lib.licenses.asl20; - maintainers = with lib.maintainers; [ cmm ]; - teams = [ lib.teams.swift ]; - }; -} diff --git a/pkgs/development/compilers/swift/libdispatch/disable-swift-overlay.patch b/pkgs/development/compilers/swift/libdispatch/disable-swift-overlay.patch deleted file mode 100644 index 0ea1869d5528..000000000000 --- a/pkgs/development/compilers/swift/libdispatch/disable-swift-overlay.patch +++ /dev/null @@ -1,35 +0,0 @@ -Enabling Swift support is normally intended for building an overlay for a -Swift SDK, which changes the installation layout. Prevent this. - ---- a/CMakeLists.txt -+++ b/CMakeLists.txt -@@ -287,7 +287,7 @@ configure_file("${PROJECT_SOURCE_DIR}/cmake/config.h.in" - add_compile_definitions($<$,$>:HAVE_CONFIG_H>) - - --if(ENABLE_SWIFT) -+if(0) - set(INSTALL_TARGET_DIR "${CMAKE_INSTALL_LIBDIR}/swift$<$>:_static>/$" CACHE PATH "Path where the libraries will be installed") - set(INSTALL_DISPATCH_HEADERS_DIR "${CMAKE_INSTALL_LIBDIR}/swift$<$>:_static>/dispatch" CACHE PATH "Path where the headers will be installed for libdispatch") - set(INSTALL_BLOCK_HEADERS_DIR "${CMAKE_INSTALL_LIBDIR}/swift$<$>:_static>/Block" CACHE PATH "Path where the headers will be installed for the blocks runtime") ---- a/man/CMakeLists.txt -+++ b/man/CMakeLists.txt -@@ -1,6 +1,6 @@ - - # TODO(compnerd) add symlinks --if(NOT ENABLE_SWIFT) -+if(1) - install(FILES - dispatch.3 - dispatch_after.3 ---- a/src/swift/CMakeLists.txt -+++ b/src/swift/CMakeLists.txt -@@ -47,7 +47,7 @@ get_swift_host_arch(swift_arch) - install(FILES - ${CMAKE_CURRENT_BINARY_DIR}/swift/Dispatch.swiftmodule - ${CMAKE_CURRENT_BINARY_DIR}/swift/Dispatch.swiftdoc -- DESTINATION ${INSTALL_TARGET_DIR}/${swift_arch}) -+ DESTINATION ${INSTALL_TARGET_DIR}/swift) - set_property(GLOBAL APPEND PROPERTY DISPATCH_EXPORTS swiftDispatch) - install(TARGETS swiftDispatch - EXPORT dispatchExports diff --git a/pkgs/development/compilers/swift/libdispatch/glue.cmake b/pkgs/development/compilers/swift/libdispatch/glue.cmake deleted file mode 100644 index dd696dc61085..000000000000 --- a/pkgs/development/compilers/swift/libdispatch/glue.cmake +++ /dev/null @@ -1,5 +0,0 @@ -add_library(dispatch SHARED IMPORTED) -set_property(TARGET dispatch PROPERTY IMPORTED_LOCATION "@out@/lib/libdispatch@dylibExt@") - -add_library(swiftDispatch SHARED IMPORTED) -set_property(TARGET swiftDispatch PROPERTY IMPORTED_LOCATION "@out@/lib/libswiftDispatch@dylibExt@") diff --git a/pkgs/development/compilers/swift/sourcekit-lsp/default.nix b/pkgs/development/compilers/swift/sourcekit-lsp/default.nix deleted file mode 100644 index 7ad17d6624bb..000000000000 --- a/pkgs/development/compilers/swift/sourcekit-lsp/default.nix +++ /dev/null @@ -1,89 +0,0 @@ -{ - lib, - stdenv, - callPackage, - fetchpatch, - pkg-config, - swift, - swiftpm, - swiftpm2nix, - Dispatch, - Foundation, - XCTest, - sqlite, - ncurses, -}: -let - sources = callPackage ../sources.nix { }; - generated = swiftpm2nix.helpers ./generated; - - # On Darwin, we only want ncurses in the linker search path, because headers - # are part of libsystem. Adding its headers to the search path causes strange - # mixing and errors. - # TODO: Find a better way to prevent this conflict. - ncursesInput = if stdenv.hostPlatform.isDarwin then ncurses.out else ncurses; -in -stdenv.mkDerivation { - pname = "sourcekit-lsp"; - - inherit (sources) version; - src = sources.sourcekit-lsp; - - nativeBuildInputs = [ - pkg-config - swift - swiftpm - ]; - buildInputs = [ - Foundation - XCTest - sqlite - ncursesInput - ]; - - env.LD_LIBRARY_PATH = lib.optionalString stdenv.hostPlatform.isLinux ( - lib.makeLibraryPath [ Dispatch ] - ); - - configurePhase = generated.configure + '' - swiftpmMakeMutable indexstore-db - patch -p1 -d .build/checkouts/indexstore-db -i ${./patches/indexstore-db-macos-target.patch} - patch -p1 -d .build/checkouts/indexstore-db -i ${ - # Fix the build with modern Clang. - fetchpatch { - url = "https://github.com/swiftlang/indexstore-db/commit/6120b53b1e8774ef4e2ad83438d4d94961331e72.patch"; - hash = "sha256-tMAfTIa3RKiA/jDtP02mHcpPaF2s9a+3q/PLJxqn30M="; - } - } - - # This toggles a section specific to Xcode XCTest, which doesn't work on - # Darwin, where we also use swift-corelibs-xctest. - substituteInPlace Sources/LSPTestSupport/PerfTestCase.swift \ - --replace-fail '#if os(macOS)' '#if false' - - # Required to link with swift-corelibs-xctest on Darwin. - export SWIFTTSC_MACOS_DEPLOYMENT_TARGET=10.12 - ''; - - # TODO: BuildServerBuildSystemTests fails - #doCheck = true; - - installPhase = '' - binPath="$(swiftpmBinPath)" - mkdir -p $out/bin - cp $binPath/sourcekit-lsp $out/bin/ - ''; - - # Canary to verify output of our Swift toolchain does not depend on the Swift - # compiler itself. (Only its 'lib' output.) - disallowedRequisites = [ swift.swift ]; - - meta = { - description = "Language Server Protocol implementation for Swift and C-based languages"; - mainProgram = "sourcekit-lsp"; - homepage = "https://github.com/swiftlang/sourcekit-lsp"; - platforms = with lib.platforms; linux ++ darwin; - license = lib.licenses.asl20; - teams = [ lib.teams.swift ]; - }; -} diff --git a/pkgs/development/compilers/swift/sourcekit-lsp/generated/default.nix b/pkgs/development/compilers/swift/sourcekit-lsp/generated/default.nix deleted file mode 100644 index eb316fdf48c8..000000000000 --- a/pkgs/development/compilers/swift/sourcekit-lsp/generated/default.nix +++ /dev/null @@ -1,19 +0,0 @@ -# This file was generated by swiftpm2nix. -{ - workspaceStateFile = ./workspace-state.json; - hashes = { - "indexstore-db" = "sha256-2EIzEaVLHZ5vwO8skTaq9HoAaLuT9WFVLMgcgGYuVAk="; - "swift-argument-parser" = "sha256-qEJ329hqQyQVxtHScD7qPmWW9ZDf9bX+4xgpDlX0w5A="; - "swift-asn1" = "sha256-aN6BJOBvUCFn62mPv0nT4Z3edD1bQZ2zT5GubzdXZDw="; - "swift-certificates" = "sha256-34FcJfZgdufFehgjxgo8UbbFPnWnYsS6qR8SIba/WZg="; - "swift-collections" = "sha256-+f9Azcl+NbDvxlMsX0UbT3n87aYaBR1Kjp3rDqoLgkA="; - "swift-crypto" = "sha256-lcB497b/T1bHShPrjNjHthrs76pDFpU+4uN0uW4tz+4="; - "swift-driver" = "sha256-Xaz9gZuOspDb+PB67d6tXfpcs+kkDCPSkhu+eIfrb0A="; - "swift-llbuild" = "sha256-kUm8/+DWDBhuqU/kJBleqSl8/Vz478pMhx5QK2g7k0o="; - "swift-package-manager" = "sha256-7jkAum4nJj9ofVRF3RZDXAR6PyAjORPMnftTNnUrA+U="; - "swift-syntax" = "sha256-8XV2dlB3Vio5O+wFnS5EQeHyPCIgFyCjEYFGCWzOPwE="; - "swift-system" = "sha256-NpTzyppbOQR0Bg/0jrwdphZgbxyRrXy/4dnYcjFvY6w="; - "swift-tools-support-core" = "sha256-Pqy01AyDg7ZTyDM6lV69e6nhfhxwFTOhGFTfhcA1e9E="; - "Yams" = "sha256-AY/fIvB7THrl9GWzGJL8eDBbkcLw27tSRTGtUqmYw8k="; - }; -} diff --git a/pkgs/development/compilers/swift/sourcekit-lsp/generated/workspace-state.json b/pkgs/development/compilers/swift/sourcekit-lsp/generated/workspace-state.json deleted file mode 100644 index b0cf93cb193c..000000000000 --- a/pkgs/development/compilers/swift/sourcekit-lsp/generated/workspace-state.json +++ /dev/null @@ -1,229 +0,0 @@ -{ - "object": { - "artifacts": [], - "dependencies": [ - { - "basedOn": null, - "packageRef": { - "identity": "indexstore-db", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/indexstore-db.git", - "name": "IndexStoreDB" - }, - "state": { - "checkoutState": { - "branch": "release/5.10", - "revision": "89ec16c2ac1bb271614e734a2ee792224809eb20" - }, - "name": "sourceControlCheckout" - }, - "subpath": "indexstore-db" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-argument-parser", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-argument-parser.git", - "name": "swift-argument-parser" - }, - "state": { - "checkoutState": { - "revision": "8f4d2753f0e4778c76d5f05ad16c74f707390531", - "version": "1.2.3" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-argument-parser" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-asn1", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-asn1.git", - "name": "swift-asn1" - }, - "state": { - "checkoutState": { - "revision": "df5d2fcd22e3f480e3ef85bf23e277a4a0ef524d", - "version": "1.2.0" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-asn1" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-certificates", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-certificates.git", - "name": "swift-certificates" - }, - "state": { - "checkoutState": { - "revision": "83640c8097acaec17c9835a083e89678cb0f2b66", - "version": "1.3.0" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-certificates" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-collections", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-collections.git", - "name": "swift-collections" - }, - "state": { - "checkoutState": { - "revision": "c11818f3cae0780656baa430b49e7f163f08dffd", - "version": "1.1.6" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-collections" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-crypto", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-crypto.git", - "name": "swift-crypto" - }, - "state": { - "checkoutState": { - "revision": "629f0b679d0fd0a6ae823d7f750b9ab032c00b80", - "version": "3.0.0" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-crypto" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-driver", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-driver.git", - "name": "swift-driver" - }, - "state": { - "checkoutState": { - "branch": "release/5.10", - "revision": "b461fd4fc51be8e1f2a3f4a2184b664b8846b46f" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-driver" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-llbuild", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-llbuild.git", - "name": "llbuild" - }, - "state": { - "checkoutState": { - "branch": "release/5.10", - "revision": "fd7c2e0d9279edd023ced6b0a590f8407f5472f9" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-llbuild" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-package-manager", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-package-manager.git", - "name": "SwiftPM" - }, - "state": { - "checkoutState": { - "branch": "release/5.10", - "revision": "b5f8ad931b7a40b81f64765fa08c2751164759b4" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-package-manager" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-syntax", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-syntax.git", - "name": "swift-syntax" - }, - "state": { - "checkoutState": { - "branch": "release/5.10", - "revision": "cdd571f366a4298bb863a9dcfe1295bb595041d5" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-syntax" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-system", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-system.git", - "name": "swift-system" - }, - "state": { - "checkoutState": { - "revision": "d2ba781702a1d8285419c15ee62fd734a9437ff5", - "version": "1.3.2" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-system" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-tools-support-core", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-tools-support-core.git", - "name": "swift-tools-support-core" - }, - "state": { - "checkoutState": { - "branch": "release/5.10", - "revision": "90bdc2a157ebacc5d3de0c83e085d05d22ca5fa0" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-tools-support-core" - }, - { - "basedOn": null, - "packageRef": { - "identity": "yams", - "kind": "remoteSourceControl", - "location": "https://github.com/jpsim/Yams.git", - "name": "Yams" - }, - "state": { - "checkoutState": { - "revision": "0d9ee7ea8c4ebd4a489ad7a73d5c6cad55d6fed3", - "version": "5.0.6" - }, - "name": "sourceControlCheckout" - }, - "subpath": "Yams" - } - ] - }, - "version": 6 -} diff --git a/pkgs/development/compilers/swift/sourcekit-lsp/patches/indexstore-db-macos-target.patch b/pkgs/development/compilers/swift/sourcekit-lsp/patches/indexstore-db-macos-target.patch deleted file mode 100644 index 53e790874d5d..000000000000 --- a/pkgs/development/compilers/swift/sourcekit-lsp/patches/indexstore-db-macos-target.patch +++ /dev/null @@ -1,12 +0,0 @@ -Raise the deployment target of IndexStoreDB so it can link against our XCTest. - ---- a/Package.swift -+++ b/Package.swift -@@ -4,6 +4,7 @@ import PackageDescription - - let package = Package( - name: "IndexStoreDB", -+ platforms: [.macOS("10.12")], - products: [ - .library( - name: "IndexStoreDB", diff --git a/pkgs/development/compilers/swift/sources-6.2.json b/pkgs/development/compilers/swift/sources-6.2.json new file mode 100644 index 000000000000..6d78b3718f52 --- /dev/null +++ b/pkgs/development/compilers/swift/sources-6.2.json @@ -0,0 +1,72 @@ +{ + "llvm-project": { + "hash": "sha256-5Nb8rQmk6onrc4wKW/kT38FsYsWTqMBWtsHYZLA/0Po=" + }, + "sourcekit-lsp": { + "hash": "sha256-vDMZJSIeM+oIheeJCEfP0+FAJn+RyNYDDdWrHJDRcyE=", + "swiftpmDeps": { + "hash": "sha256-xpvXcm2qtCd2xhClbR6BLwmaupSHg1H25uJd7Thgd/4=" + } + }, + "swift": { + "hash": "sha256-apbBe/TMzq0+1XLkaTOj5NaYzLQ81i+vU+O7VSEJrKo=" + }, + "swift-build": { + "hash": "sha256-uwxnn9B/79mCyceKDIdM+iqxKoCHh8dgEijU4NM2MnM=" + }, + "swift-corelibs-foundation": { + "hash": "sha256-Ytxiu80su2jnF/xLcLVEaHXYvI4spLO8d+qEhDxqAdQ=" + }, + "swift-corelibs-libdispatch": { + "hash": "sha256-Tu2G9FAP4q1xgM1n9q17T6VrqJ3tv8RezyUex38yNds=" + }, + "swift-corelibs-xctest": { + "hash": "sha256-BbzY1kZUaHu7O29c8J7xDuelik6lhqmfSSskvvPZ7R4=" + }, + "swift-docc": { + "hash": "sha256-zu70RyYvnfhW3DdovSeLFXTNmdHrhdnSYCN8RisSkt8=", + "swiftpmDeps": { + "hash": "sha256-kJFuNw/pRn2A4UMvGcX3j04Faz44mriSz90u8hLdaZc=" + } + }, + "swift-docc-render": { + "hash": "sha256-uikFKvbjdU2BW3G0hCLah5Dt86DfAJ0etirX2nYVD+8=", + "npmDeps": { + "hash": "sha256-10RbVbf8lA4Glqw9NZGRCFmpE660UfbTBllIKJYQ+U8=" + }, + "rev": "1eb260c405bea1a57d843563e1085baa632262c6" + }, + "swift-driver": { + "hash": "sha256-CZYqUadpAsAUnCTZElobZS9nlMfCuHiMnac3o0k7hnI=" + }, + "swift-experimental-string-processing": { + "hash": "sha256-WtLLqdvYTmLWSS5q42b8yXFrJcC+dUy4uTuCeIflRFs=" + }, + "swift-format": { + "hash": "sha256-01lnZFaFAcjWN9Hn0y60gEANz7RbYRvjESysYqB9iSo=", + "swiftpmDeps": { + "hash": "sha256-UAvKJKEN32FVILwdADqXAZ7opS3Tf3e7Qp+RhD4R4QE=" + } + }, + "swift-foundation": { + "hash": "sha256-otE5EGG53zadZVZ0P67rr+4h4x/c3rWWEdZyL23Mxio=" + }, + "swift-foundation-icu": { + "hash": "sha256-C2rq5Q0F1id89mTN4+B/fKSvX1SEAf3/Zgvb/3IdsJ8=" + }, + "swift-llbuild": { + "hash": "sha256-nZdiFXYrUiTSlSl6lxNFVpD2x8KGC4OVUUvJSOqH7gU=" + }, + "swift-package-manager": { + "hash": "sha256-RIJLOoyDWWseBdDbJ5fluoZVq11jOdlV1yjq+m5xIws=" + }, + "swift-syntax": { + "hash": "sha256-DMMVJQj590RGGBkTgA89u01ZP2B8kbJTmfu+oxzYPds=" + }, + "swift-testing": { + "hash": "sha256-HgvwoAbUeFTVnrOTNVIgFRLOpGyCQHRgQqulHQ1LYnQ=" + }, + "swift-tools-support-core": { + "hash": "sha256-mV+z5sdG/maUzXUhK1vMtsnLCclcjqyXSMO6J2FjBEg=" + } +} diff --git a/pkgs/development/compilers/swift/sources.nix b/pkgs/development/compilers/swift/sources.nix deleted file mode 100644 index 5b5c468a6d06..000000000000 --- a/pkgs/development/compilers/swift/sources.nix +++ /dev/null @@ -1,39 +0,0 @@ -{ lib, fetchFromGitHub }: - -let - - # These packages are all part of the Swift toolchain, and have a single - # upstream version that should match. We also list the hashes here so a basic - # version upgrade touches only this file. - version = "5.10.1"; - hashes = { - llvm-project = "sha256-D+zZjLgnAFy6zBuUQwRI0VmDrgr2TQeNUnDbDtvtRZ4="; - sourcekit-lsp = "sha256-mMZ8zPkyoht0aSSnStIULWbLjowahdza9DQXboT1D0o="; - swift = "sha256-UK8yPwHu/sCvcuKKmBMCP9rGRJCZE3ct0ckdNw2BVbE="; - swift-cmark = "sha256-GK2tFu49Sw8jJWJpxQerVFqsuUJwkAhRloa2/aUTYB8="; - swift-corelibs-foundation = "sha256-izYpdCZaf3ktgz/k3pjmHJHH5BebdG7nj8l6vbuk+o0="; - swift-corelibs-libdispatch = "sha256-pta3wJj2LJ/lsYAWQpw0wSGLDMO41mN8Zbl78LUCaQo="; - swift-corelibs-xctest = "sha256-HgnVFYUuefCZKsOjXgt98ebMsLdMl0oXFXy2Pb2iUdw="; - swift-docc = "sha256-zgGahAanYI95nQZ+3zAYrs0h4APNamPrZfwF81k1si0="; - swift-docc-render-artifact = "sha256-Ky9l6tzAxQOpcPFq2FeGnFUl8i59TifRBSHNaZg8wfw="; - swift-driver = "sha256-Xaz9gZuOspDb+PB67d6tXfpcs+kkDCPSkhu+eIfrb0A="; - swift-experimental-string-processing = "sha256-gv3xY9s6gdv0lpXH8RGfiLAvZWM7xVsUSLcqyb4rSeQ="; - swift-format = "sha256-oYf9Qt0b/6G3+uQaoExQRKzgpi1RPYSSpZLfwhuRmF8="; - swift-package-manager = "sha256-yL/cPCt7pZ0XqbbxEnrbzM2X3EkU9klon7SzO2Z13SA="; - swift-syntax = "sha256-OcrOdlnLYpMxH5CGWNGbs5XW3gJaGgKWQqB9YtwmZeY="; - }; - - # Create fetch derivations. - sources = lib.mapAttrs ( - repo: hash: - fetchFromGitHub { - owner = "apple"; - inherit repo; - rev = "swift-${version}-RELEASE"; - name = "${repo}-${version}-src"; - hash = hashes.${repo}; - } - ) hashes; - -in -sources // { inherit version; } diff --git a/pkgs/development/compilers/swift/swift-docc/default.nix b/pkgs/development/compilers/swift/swift-docc/default.nix deleted file mode 100644 index 2ec0b4c10746..000000000000 --- a/pkgs/development/compilers/swift/swift-docc/default.nix +++ /dev/null @@ -1,73 +0,0 @@ -{ - lib, - stdenv, - callPackage, - swift, - swiftpm, - swiftpm2nix, - Foundation, - XCTest, -}: -let - sources = callPackage ../sources.nix { }; - generated = swiftpm2nix.helpers ./generated; -in -stdenv.mkDerivation { - pname = "swift-docc"; - - inherit (sources) version; - src = sources.swift-docc; - # TODO: We could build this from `apple/swift-docc-render` source, but that - # repository is not tagged. - renderArtifact = sources.swift-docc-render-artifact; - - nativeBuildInputs = [ - swift - swiftpm - ]; - buildInputs = [ - Foundation - XCTest - ]; - - configurePhase = - generated.configure - # Fix the build with modern Clang. - # - # Based on the upstream fix for Musl: - # - + '' - swiftpmMakeMutable swift-nio - patch -p1 -d .build/checkouts/swift-nio -i ${./fix-swift-nio.patch} - ''; - - # We only install the docc binary, so don't need the other products. - # This works around a failure building generate-symbol-graph: - # Sources/generate-symbol-graph/main.swift:13:18: error: module 'SwiftDocC' was not compiled for testing - # TODO: Figure out the cause. It doesn't seem to happen outside Nixpkgs. - swiftpmFlags = [ "--product docc" ]; - - # TODO: Tests depend on indexstore-db being provided by an existing Swift - # toolchain. (ie. looks for `../lib/libIndexStore.so` relative to swiftc. - #doCheck = true; - - installPhase = '' - binPath="$(swiftpmBinPath)" - mkdir -p $out/bin $out/share/docc - cp $binPath/docc $out/bin/ - ln -s $renderArtifact/dist $out/share/docc/render - ''; - - # Canary to verify output of our Swift toolchain does not depend on the Swift - # compiler itself. (Only its 'lib' output.) - disallowedRequisites = [ swift.swift ]; - - meta = { - description = "Documentation compiler for Swift"; - mainProgram = "docc"; - homepage = "https://github.com/apple/swift-docc"; - platforms = with lib.platforms; linux ++ darwin; - license = lib.licenses.asl20; - teams = [ lib.teams.swift ]; - }; -} diff --git a/pkgs/development/compilers/swift/swift-docc/fix-swift-nio.patch b/pkgs/development/compilers/swift/swift-docc/fix-swift-nio.patch deleted file mode 100644 index ccab988906fa..000000000000 --- a/pkgs/development/compilers/swift/swift-docc/fix-swift-nio.patch +++ /dev/null @@ -1,13 +0,0 @@ -diff --git a/Package.swift b/Package.swift -index 39c6fb4b2f..02c08b898d 100644 ---- a/Package.swift -+++ b/Package.swift -@@ -26,7 +26,7 @@ - .target(name: "NIOFoundationCompat", dependencies: ["NIO"]), - .target(name: "CNIOAtomics", dependencies: []), - .target(name: "CNIOSHA1", dependencies: []), -- .target(name: "CNIOLinux", dependencies: []), -+ .target(name: "CNIOLinux", dependencies: [], cSettings: [.define("_GNU_SOURCE")]), - .target(name: "CNIODarwin", dependencies: [], cSettings: [.define("__APPLE_USE_RFC_3542")]), - .target(name: "CNIOWindows", dependencies: []), - .target(name: "NIOConcurrencyHelpers", diff --git a/pkgs/development/compilers/swift/swift-docc/generated/default.nix b/pkgs/development/compilers/swift/swift-docc/generated/default.nix deleted file mode 100644 index 22bec28c102f..000000000000 --- a/pkgs/development/compilers/swift/swift-docc/generated/default.nix +++ /dev/null @@ -1,16 +0,0 @@ -# This file was generated by swiftpm2nix. -{ - workspaceStateFile = ./workspace-state.json; - hashes = { - "swift-argument-parser" = "sha256-G4Tz/AdL5WbRq93aJnQhMjHLH7dEuhmXL3PPn+0H6vM="; - "swift-atomics" = "sha256-fjRGySMI7Mv52sCYejWI5YA+IcehOdz5XxK3p+hxwmU="; - "swift-cmark" = "sha256-1/LnvAggPkpfJZo9evfP+fCj6NXY9SMxwo7WJA2kXOM="; - "swift-collections" = "sha256-VtnHFWd5OUmRBnmIeOF8xn8PASLrHG/pfONWnEuX2sw="; - "swift-crypto" = "sha256-vBDjXtynl3HMq1RK/hMOu36b+0hX2SRRnwhPNjPUOsU="; - "swift-docc-plugin" = "sha256-r+cFtDTK6rRWDOOsgJNF6J2mfm/oKxoK7HIv6fpFW4o="; - "swift-docc-symbolkit" = "sha256-hAcoe57wE9gkPc1E/lXY41W+Eh3a7cUWfRv3Xi4rO2M="; - "swift-lmdb" = "sha256-dZDN2pBOE0ZPtneQvEjF+AE4PDwbcaTausR2W4lg9Ss="; - "swift-markdown" = "sha256-qb+mSS1A3WzLQdCB9lIz+UhSG9tf0hknitTfh6VIrHs="; - "swift-nio" = "sha256-KOvnE5VF6lw9hfTLHIlG+6EV/7kl8hL4IOIVoP2om3Q="; - }; -} diff --git a/pkgs/development/compilers/swift/swift-docc/generated/workspace-state.json b/pkgs/development/compilers/swift/swift-docc/generated/workspace-state.json deleted file mode 100644 index 76f5f228b274..000000000000 --- a/pkgs/development/compilers/swift/swift-docc/generated/workspace-state.json +++ /dev/null @@ -1,178 +0,0 @@ -{ - "object": { - "artifacts": [], - "dependencies": [ - { - "basedOn": null, - "packageRef": { - "identity": "swift-argument-parser", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-argument-parser", - "name": "swift-argument-parser" - }, - "state": { - "checkoutState": { - "revision": "fee6933f37fde9a5e12a1e4aeaa93fe60116ff2a", - "version": "1.2.2" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-argument-parser" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-atomics", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-atomics.git", - "name": "swift-atomics" - }, - "state": { - "checkoutState": { - "revision": "6c89474e62719ddcc1e9614989fff2f68208fe10", - "version": "1.1.0" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-atomics" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-cmark", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-cmark.git", - "name": "cmark-gfm" - }, - "state": { - "checkoutState": { - "branch": "gfm", - "revision": "eb9a6a357b6816c68f4b194eaa5b67f3cd1fa5c3" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-cmark" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-collections", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-collections.git", - "name": "swift-collections" - }, - "state": { - "checkoutState": { - "revision": "937e904258d22af6e447a0b72c0bc67583ef64a2", - "version": "1.0.4" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-collections" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-crypto", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-crypto.git", - "name": "swift-crypto" - }, - "state": { - "checkoutState": { - "revision": "33a20e650c33f6d72d822d558333f2085effa3dc", - "version": "2.5.0" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-crypto" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-docc-plugin", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-docc-plugin", - "name": "SwiftDocCPlugin" - }, - "state": { - "checkoutState": { - "revision": "9b1258905c21fc1b97bf03d1b4ca12c4ec4e5fda", - "version": "1.2.0" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-docc-plugin" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-docc-symbolkit", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-docc-symbolkit", - "name": "SymbolKit" - }, - "state": { - "checkoutState": { - "branch": "release/5.10", - "revision": "1d5aba8186fc648e17b30631b34043110ca8dd19" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-docc-symbolkit" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-lmdb", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-lmdb.git", - "name": "CLMDB" - }, - "state": { - "checkoutState": { - "branch": "release/5.10", - "revision": "584941b1236b15bad74d8163785d389c028b1ad8" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-lmdb" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-markdown", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-markdown.git", - "name": "swift-markdown" - }, - "state": { - "checkoutState": { - "branch": "release/5.10", - "revision": "636291555b65bd59b2b3279abc7d03a622aa7c55" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-markdown" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-nio", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-nio.git", - "name": "swift-nio" - }, - "state": { - "checkoutState": { - "revision": "2d8e6ca36fe3e8ed74b0883f593757a45463c34d", - "version": "2.53.0" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-nio" - } - ] - }, - "version": 6 -} diff --git a/pkgs/development/compilers/swift/swift-driver/default.nix b/pkgs/development/compilers/swift/swift-driver/default.nix deleted file mode 100644 index 04d41a663cd7..000000000000 --- a/pkgs/development/compilers/swift/swift-driver/default.nix +++ /dev/null @@ -1,82 +0,0 @@ -{ - lib, - stdenv, - callPackage, - fetchpatch, - swift, - swiftpm, - swiftpm2nix, - Foundation, - XCTest, - sqlite, - ncurses, - clang, - replaceVars, -}: -let - sources = callPackage ../sources.nix { }; - generated = swiftpm2nix.helpers ./generated; - - # On Darwin, we only want ncurses in the linker search path, because headers - # are part of libsystem. Adding its headers to the search path causes strange - # mixing and errors. - # TODO: Find a better way to prevent this conflict. - ncursesInput = if stdenv.hostPlatform.isDarwin then ncurses.out else ncurses; -in -stdenv.mkDerivation { - pname = "swift-driver"; - - inherit (sources) version; - src = sources.swift-driver; - - nativeBuildInputs = [ - swift - swiftpm - ]; - buildInputs = [ - Foundation - XCTest - sqlite - ncursesInput - ]; - - patches = [ - ./patches/disable-catalyst.patch - (replaceVars ./patches/linux-fix-linking.patch { - inherit clang; - }) - # TODO: Replace with branch patch once merged: - # https://github.com/apple/swift-driver/pull/1197 - (fetchpatch { - url = "https://github.com/apple/swift-driver/commit/d3ef9cdf4871a58eddec7ff0e28fe611130da3f9.patch"; - hash = "sha256-eVBaKN6uzj48ZnHtwGV0k5ChKjak1tDCyE+wTdyGq2c="; - }) - # Prevent a warning about SDK directories we don't have. - (replaceVars ./patches/prevent-sdk-dirs-warnings.patch { - inherit (builtins) storeDir; - }) - ]; - - configurePhase = generated.configure; - - # TODO: Tests depend on indexstore-db being provided by an existing Swift - # toolchain. (ie. looks for `../lib/libIndexStore.so` relative to swiftc. - #doCheck = true; - - # TODO: Darwin-specific installation includes more, but not sure why. - installPhase = '' - binPath="$(swiftpmBinPath)" - mkdir -p $out/bin - for executable in swift-driver swift-help swift-build-sdk-interfaces; do - cp $binPath/$executable $out/bin/ - done - ''; - - meta = { - description = "Swift compiler driver"; - homepage = "https://github.com/apple/swift-driver"; - platforms = with lib.platforms; linux ++ darwin; - license = lib.licenses.asl20; - teams = [ lib.teams.swift ]; - }; -} diff --git a/pkgs/development/compilers/swift/swift-driver/generated/default.nix b/pkgs/development/compilers/swift/swift-driver/generated/default.nix deleted file mode 100644 index 3651538c1a01..000000000000 --- a/pkgs/development/compilers/swift/swift-driver/generated/default.nix +++ /dev/null @@ -1,11 +0,0 @@ -# This file was generated by swiftpm2nix. -{ - workspaceStateFile = ./workspace-state.json; - hashes = { - "swift-argument-parser" = "sha256-G4Tz/AdL5WbRq93aJnQhMjHLH7dEuhmXL3PPn+0H6vM="; - "swift-llbuild" = "sha256-kUm8/+DWDBhuqU/kJBleqSl8/Vz478pMhx5QK2g7k0o="; - "swift-system" = "sha256-p18QHzO+NtoY/WQzOD+PfD+bjqrIWsbeEbsJLPqEAhA="; - "swift-tools-support-core" = "sha256-Pqy01AyDg7ZTyDM6lV69e6nhfhxwFTOhGFTfhcA1e9E="; - "Yams" = "sha256-5qxuCkmopm3uFcoYJKQA8ofW98f53H1gZaPiOh2DS4U="; - }; -} diff --git a/pkgs/development/compilers/swift/swift-driver/generated/workspace-state.json b/pkgs/development/compilers/swift/swift-driver/generated/workspace-state.json deleted file mode 100644 index 55bd4ea5fad1..000000000000 --- a/pkgs/development/compilers/swift/swift-driver/generated/workspace-state.json +++ /dev/null @@ -1,93 +0,0 @@ -{ - "object": { - "artifacts": [], - "dependencies": [ - { - "basedOn": null, - "packageRef": { - "identity": "swift-argument-parser", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-argument-parser.git", - "name": "swift-argument-parser" - }, - "state": { - "checkoutState": { - "revision": "fee6933f37fde9a5e12a1e4aeaa93fe60116ff2a", - "version": "1.2.2" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-argument-parser" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-llbuild", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-llbuild.git", - "name": "llbuild" - }, - "state": { - "checkoutState": { - "branch": "release/5.10", - "revision": "fd7c2e0d9279edd023ced6b0a590f8407f5472f9" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-llbuild" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-system", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-system.git", - "name": "swift-system" - }, - "state": { - "checkoutState": { - "revision": "836bc4557b74fe6d2660218d56e3ce96aff76574", - "version": "1.1.1" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-system" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-tools-support-core", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-tools-support-core.git", - "name": "swift-tools-support-core" - }, - "state": { - "checkoutState": { - "branch": "release/5.10", - "revision": "90bdc2a157ebacc5d3de0c83e085d05d22ca5fa0" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-tools-support-core" - }, - { - "basedOn": null, - "packageRef": { - "identity": "yams", - "kind": "remoteSourceControl", - "location": "https://github.com/jpsim/Yams.git", - "name": "Yams" - }, - "state": { - "checkoutState": { - "revision": "01835dc202670b5bb90d07f3eae41867e9ed29f6", - "version": "5.0.1" - }, - "name": "sourceControlCheckout" - }, - "subpath": "Yams" - } - ] - }, - "version": 6 -} diff --git a/pkgs/development/compilers/swift/swift-driver/patches/disable-catalyst.patch b/pkgs/development/compilers/swift/swift-driver/patches/disable-catalyst.patch deleted file mode 100644 index b9eb23f21061..000000000000 --- a/pkgs/development/compilers/swift/swift-driver/patches/disable-catalyst.patch +++ /dev/null @@ -1,17 +0,0 @@ -Tries to parse SDKSettings.plist looking for a Catalyst version map, but we -don't currently support this. - ---- a/Sources/SwiftDriver/Toolchains/DarwinToolchain.swift -+++ b/Sources/SwiftDriver/Toolchains/DarwinToolchain.swift -@@ -297,11 +297,7 @@ public final class DarwinToolchain: Toolchain { - debugDescription: "Malformed version string") - } - self.version = version -- if self.canonicalName.hasPrefix("macosx") { -- self.versionMap = try keyedContainer.decode(VersionMap.self, forKey: .versionMap) -- } else { - self.versionMap = VersionMap() -- } - } - - diff --git a/pkgs/development/compilers/swift/swift-driver/patches/linux-fix-linking.patch b/pkgs/development/compilers/swift/swift-driver/patches/linux-fix-linking.patch deleted file mode 100644 index dcdb5292687d..000000000000 --- a/pkgs/development/compilers/swift/swift-driver/patches/linux-fix-linking.patch +++ /dev/null @@ -1,40 +0,0 @@ -diff --git a/Sources/SwiftDriver/Jobs/GenericUnixToolchain+LinkerSupport.swift b/Sources/SwiftDriver/Jobs/GenericUnixToolchain+LinkerSupport.swift -index a4a735f498..381522cc1f 100644 ---- a/Sources/SwiftDriver/Jobs/GenericUnixToolchain+LinkerSupport.swift -+++ b/Sources/SwiftDriver/Jobs/GenericUnixToolchain+LinkerSupport.swift -@@ -10,6 +10,7 @@ - // - //===----------------------------------------------------------------------===// - -+import Foundation - import SwiftOptions - - import func TSCBasic.lookupExecutablePath -@@ -130,7 +131,18 @@ - } - - let clangTool: Tool = cxxCompatEnabled ? .clangxx : .clang -- var clangPath = try getToolPath(clangTool) -+ -+ // For Nix, prefer linking using the wrapped Nixpkgs clang, instead of using -+ // the unwrapped clang packaged with swift. The latter is unable to link, but -+ // we still want to use it for other purposes (clang importer). -+ var clangPath: AbsolutePath -+ if let binPath = try? AbsolutePath(validating: "@clang@/bin"), -+ let tool = lookupExecutablePath(filename: cxxCompatEnabled -+ ? "clang++" : "clang", -+ searchPaths: [binPath]) { -+ clangPath = tool -+ } else { -+ clangPath = try getToolPath(clangTool) - if let toolsDirPath = parsedOptions.getLastArgument(.toolsDirectory) { - // FIXME: What if this isn't an absolute path? - let toolsDir = try AbsolutePath(validating: toolsDirPath.asSingle) -@@ -146,6 +158,7 @@ - commandLine.appendFlag("-B") - commandLine.appendPath(toolsDir) - } -+ } // Nix - - // Executables on Linux get -pie - if targetTriple.os == .linux && linkerOutputType == .executable { diff --git a/pkgs/development/compilers/swift/swift-driver/patches/prevent-sdk-dirs-warnings.patch b/pkgs/development/compilers/swift/swift-driver/patches/prevent-sdk-dirs-warnings.patch deleted file mode 100644 index 6080865ebe37..000000000000 --- a/pkgs/development/compilers/swift/swift-driver/patches/prevent-sdk-dirs-warnings.patch +++ /dev/null @@ -1,16 +0,0 @@ -Prevents a user-visible warning on every compilation: - - ld: warning: directory not found for option '-L.../MacOSX11.0.sdk/usr/lib/swift' - ---- a/Sources/SwiftDriver/Jobs/Toolchain+LinkerSupport.swift -+++ b/Sources/SwiftDriver/Jobs/Toolchain+LinkerSupport.swift -@@ -50,7 +50,9 @@ extension Toolchain { - result.append(sdkPath.appending(components: "System", "iOSSupport", "usr", "lib", "swift")) - } - -+ if sdkPath.absolutePath?.pathString.starts(with: "@storeDir@") == false { - result.append(sdkPath.appending(components: "usr", "lib", "swift")) -+ } - } - - return result diff --git a/pkgs/development/compilers/swift/swift-format/default.nix b/pkgs/development/compilers/swift/swift-format/default.nix deleted file mode 100644 index 9f265bc4d6f1..000000000000 --- a/pkgs/development/compilers/swift/swift-format/default.nix +++ /dev/null @@ -1,62 +0,0 @@ -{ - lib, - stdenv, - callPackage, - swift, - swiftpm, - swiftpm2nix, - installShellFiles, - Dispatch, - Foundation, -}: -let - sources = callPackage ../sources.nix { }; - generated = swiftpm2nix.helpers ./generated; -in -stdenv.mkDerivation { - pname = "swift-format"; - - inherit (sources) version; - src = sources.swift-format; - - nativeBuildInputs = [ - swift - swiftpm - installShellFiles - ]; - buildInputs = [ Foundation ]; - - env.LD_LIBRARY_PATH = lib.optionalString stdenv.hostPlatform.isLinux ( - lib.makeLibraryPath [ Dispatch ] - ); - - configurePhase = generated.configure; - - # We only install the swift-format binary, so don't need the other products. - swiftpmFlags = [ "--product swift-format" ]; - - installPhase = '' - binPath="$(swiftpmBinPath)" - mkdir -p $out/bin - cp $binPath/swift-format $out/bin/ - - # Generate shell completions - for shell in bash zsh fish; do - $out/bin/swift-format --generate-completion-script $shell > swift-format.$shell - done - - installShellCompletion --cmd swift-format \ - --bash swift-format.bash \ - --zsh swift-format.zsh \ - --fish swift-format.fish - ''; - - meta = { - description = "Formatting technology for Swift source code"; - homepage = "https://github.com/swiftlang/swift-format"; - platforms = with lib.platforms; linux ++ darwin; - license = lib.licenses.asl20; - teams = [ lib.teams.swift ]; - mainProgram = "swift-format"; - }; -} diff --git a/pkgs/development/compilers/swift/swift-format/generated/default.nix b/pkgs/development/compilers/swift/swift-format/generated/default.nix deleted file mode 100644 index b01e3c6abf2d..000000000000 --- a/pkgs/development/compilers/swift/swift-format/generated/default.nix +++ /dev/null @@ -1,10 +0,0 @@ -# This file was generated by swiftpm2nix. -{ - workspaceStateFile = ./workspace-state.json; - hashes = { - "swift-argument-parser" = "sha256-JXNjFpLNaqzOGXlIgQtwzG2Yq1daOl4tmTAUcZL4thM="; - "swift-cmark" = "sha256-npLzvHtMmWZlqNIYOMAZfqyX2TOkICZNHCN1+laOBZA="; - "swift-markdown" = "sha256-F8xJYp8kf9IzLAe+HuKLFWJe3fdC2yewb+zaJgyeJ1U="; - "swift-syntax" = "sha256-8XV2dlB3Vio5O+wFnS5EQeHyPCIgFyCjEYFGCWzOPwE="; - }; -} diff --git a/pkgs/development/compilers/swift/swift-format/generated/workspace-state.json b/pkgs/development/compilers/swift/swift-format/generated/workspace-state.json deleted file mode 100644 index 388535f3770f..000000000000 --- a/pkgs/development/compilers/swift/swift-format/generated/workspace-state.json +++ /dev/null @@ -1,76 +0,0 @@ -{ - "object": { - "artifacts": [], - "dependencies": [ - { - "basedOn": null, - "packageRef": { - "identity": "swift-argument-parser", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-argument-parser.git", - "name": "swift-argument-parser" - }, - "state": { - "checkoutState": { - "revision": "309a47b2b1d9b5e991f36961c983ecec72275be3", - "version": "1.6.1" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-argument-parser" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-cmark", - "kind": "remoteSourceControl", - "location": "https://github.com/swiftlang/swift-cmark.git", - "name": "cmark-gfm" - }, - "state": { - "checkoutState": { - "revision": "b97d09472e847a416629f026eceae0e2afcfad65", - "version": "0.7.0" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-cmark" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-markdown", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-markdown.git", - "name": "swift-markdown" - }, - "state": { - "checkoutState": { - "revision": "d8cf111c276ed18cff82d3cad563d2ca5903b982", - "version": "0.7.1" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-markdown" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-syntax", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-syntax.git", - "name": "swift-syntax" - }, - "state": { - "checkoutState": { - "branch": "release/5.10", - "revision": "cdd571f366a4298bb863a9dcfe1295bb595041d5" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-syntax" - } - ] - }, - "version": 6 -} diff --git a/pkgs/development/compilers/swift/swiftpm/cmake-glue.nix b/pkgs/development/compilers/swift/swiftpm/cmake-glue.nix deleted file mode 100644 index 70af831142a9..000000000000 --- a/pkgs/development/compilers/swift/swiftpm/cmake-glue.nix +++ /dev/null @@ -1,107 +0,0 @@ -# SwiftPM dependencies are normally not installed using CMake, and only provide -# CMake modules to link them together in a build tree. We have separate -# derivations, so need a real install step. Here we provide our own minimal -# CMake modules to install along with the build products. -{ - lib, - stdenv, - swift, -}: -let - - inherit (stdenv.hostPlatform) extensions; - - # This file exports shell snippets for use in postInstall. - mkInstallScript = module: template: '' - mkdir -p $out/lib/cmake/${module} - ( - export staticLibExt="${extensions.staticLibrary}" - export sharedLibExt="${extensions.sharedLibrary}" - export swiftOs="${swift.swiftOs}" - substituteAll \ - ${builtins.toFile "${module}Config.cmake" template} \ - $out/lib/cmake/${module}/${module}Config.cmake - ) - ''; - -in -lib.mapAttrs mkInstallScript { - SwiftSystem = '' - add_library(SwiftSystem::SystemPackage STATIC IMPORTED) - set_property(TARGET SwiftSystem::SystemPackage PROPERTY IMPORTED_LOCATION "@out@/lib/swift_static/@swiftOs@/libSystemPackage@staticLibExt@") - ''; - - SwiftCollections = '' - add_library(SwiftCollections::Collections STATIC IMPORTED) - set_property(TARGET SwiftCollections::Collections PROPERTY IMPORTED_LOCATION "@out@/lib/swift_static/@swiftOs@/libCollections@staticLibExt@") - - add_library(SwiftCollections::DequeModule STATIC IMPORTED) - set_property(TARGET SwiftCollections::DequeModule PROPERTY IMPORTED_LOCATION "@out@/lib/swift_static/@swiftOs@/libDequeModule@staticLibExt@") - - add_library(SwiftCollections::OrderedCollections STATIC IMPORTED) - set_property(TARGET SwiftCollections::OrderedCollections PROPERTY IMPORTED_LOCATION "@out@/lib/swift_static/@swiftOs@/libOrderedCollections@staticLibExt@") - ''; - - TSC = '' - add_library(TSCLibc SHARED IMPORTED) - set_property(TARGET TSCLibc PROPERTY IMPORTED_LOCATION "@out@/lib/libTSCLibc@sharedLibExt@") - - add_library(TSCBasic SHARED IMPORTED) - set_property(TARGET TSCBasic PROPERTY IMPORTED_LOCATION "@out@/lib/libTSCBasic@sharedLibExt@") - - add_library(TSCUtility SHARED IMPORTED) - set_property(TARGET TSCUtility PROPERTY IMPORTED_LOCATION "@out@/lib/libTSCUtility@sharedLibExt@") - ''; - - ArgumentParser = '' - add_library(ArgumentParser SHARED IMPORTED) - set_property(TARGET ArgumentParser PROPERTY IMPORTED_LOCATION "@out@/lib/swift/@swiftOs@/libArgumentParser@sharedLibExt@") - - add_library(ArgumentParserToolInfo SHARED IMPORTED) - set_property(TARGET ArgumentParserToolInfo PROPERTY IMPORTED_LOCATION "@out@/lib/swift/@swiftOs@/libArgumentParserToolInfo@sharedLibExt@") - ''; - - Yams = '' - add_library(Yams SHARED IMPORTED) - set_property(TARGET Yams PROPERTY IMPORTED_LOCATION "@out@/lib/swift/@swiftOs@/libYams@sharedLibExt@") - ''; - - LLBuild = '' - add_library(libllbuild SHARED IMPORTED) - set_property(TARGET libllbuild PROPERTY IMPORTED_LOCATION "@out@/lib/libllbuild@sharedLibExt@") - - add_library(llbuildSwift SHARED IMPORTED) - set_property(TARGET llbuildSwift PROPERTY IMPORTED_LOCATION "@out@/lib/swift/pm/llbuild/libllbuildSwift@sharedLibExt@") - ''; - - SwiftDriver = '' - add_library(SwiftDriver SHARED IMPORTED) - set_property(TARGET SwiftDriver PROPERTY IMPORTED_LOCATION "@out@/lib/libSwiftDriver@sharedLibExt@") - - add_library(SwiftDriverExecution SHARED IMPORTED) - set_property(TARGET SwiftDriverExecution PROPERTY IMPORTED_LOCATION "@out@/lib/libSwiftDriverExecution@sharedLibExt@") - - add_library(SwiftOptions SHARED IMPORTED) - set_property(TARGET SwiftOptions PROPERTY IMPORTED_LOCATION "@out@/lib/libSwiftOptions@sharedLibExt@") - ''; - - SwiftCrypto = '' - add_library(Crypto SHARED IMPORTED) - set_property(TARGET Crypto PROPERTY IMPORTED_LOCATION "@out@/lib/swift/@swiftOs@/libCrypto@sharedLibExt@") - - add_library(_CryptoExtras SHARED IMPORTED) - # this can't possibly be right... I really think it should be `libCryptoExtras` - # swift-certificates did build with this though..... - set_property(TARGET _CryptoExtras PROPERTY IMPORTED_LOCATION "@out@/lib/swift/@swiftOs@/libCrypto@sharedLibExt@") - ''; - - SwiftASN1 = '' - add_library(SwiftASN1 SHARED IMPORTED) - set_property(TARGET SwiftASN1 PROPERTY IMPORTED_LOCATION "@out@/lib/swift/@swiftOs@/libSwiftASN1@sharedLibExt@") - ''; - - SwiftCertificates = '' - add_library(SwiftCertificates SHARED IMPORTED) - set_property(TARGET SwiftCertificates PROPERTY IMPORTED_LOCATION "@out@/lib/swift/@swiftOs@/libCertificates@sharedLibExt@") - ''; -} diff --git a/pkgs/development/compilers/swift/swiftpm/default.nix b/pkgs/development/compilers/swift/swiftpm/default.nix deleted file mode 100644 index e6858f08cf18..000000000000 --- a/pkgs/development/compilers/swift/swiftpm/default.nix +++ /dev/null @@ -1,501 +0,0 @@ -{ - lib, - stdenv, - callPackage, - fetchFromGitHub, - cmake, - ninja, - git, - swift, - swiftpm2nix, - Foundation, - XCTest, - pkg-config, - sqlite, - ncurses, - replaceVars, - runCommandLocal, - makeWrapper, - DarwinTools, # sw_vers - cctools, # vtool - xcbuild, -}: - -let - - inherit (swift) - swiftOs - swiftModuleSubdir - swiftStaticModuleSubdir - ; - sharedLibraryExt = stdenv.hostPlatform.extensions.sharedLibrary; - - sources = callPackage ../sources.nix { }; - generated = swiftpm2nix.helpers ./generated; - cmakeGlue = callPackage ./cmake-glue.nix { }; - - # Common attributes for the bootstrap swiftpm and the final swiftpm. - commonAttrs = { - inherit (sources) version; - src = sources.swift-package-manager; - nativeBuildInputs = [ makeWrapper ]; - # Required at run-time for the host platform to build package manifests. - propagatedBuildInputs = [ Foundation ]; - patches = [ - ./patches/cmake-disable-rpath.patch - ./patches/disable-index-store.patch - ./patches/disable-sandbox.patch - ./patches/disable-xctest.patch - ./patches/fix-clang-cxx.patch - ./patches/nix-pkgconfig-vars.patch - (replaceVars ./patches/fix-stdlib-path.patch { - inherit (builtins) storeDir; - swiftLib = swift.swift.lib; - }) - ]; - postPatch = '' - # The location of xcrun is hardcoded. We need PATH lookup instead. - find Sources -name '*.swift' | xargs sed -i -e 's|/usr/bin/xcrun|xcrun|g' - - # Patch the location where swiftpm looks for its API modules. - substituteInPlace Sources/PackageModel/UserToolchain.swift \ - --replace-fail \ - 'librariesPath = applicationPath.parentDirectory' \ - "librariesPath = try AbsolutePath(validating: \"$out\")" - ''; - }; - - # Tools invoked by swiftpm at run-time. - runtimeDeps = [ - git - ] - ++ lib.optionals stdenv.hostPlatform.isDarwin [ - xcbuild.xcrun - # These tools are part of cctools, but adding that as a build input puts - # an unwrapped linker in PATH, and breaks builds. This small derivation - # exposes just the tools we need: - # - vtool is used to determine a minimum deployment target. - # - libtool is used to build static libraries. - (runCommandLocal "swiftpm-cctools" { } '' - mkdir -p $out/bin - ln -s ${cctools}/bin/vtool $out/bin/vtool - ln -s ${cctools}/bin/libtool $out/bin/libtool - '') - ]; - - # Common attributes for the bootstrap derivations. - mkBootstrapDerivation = - attrs: - stdenv.mkDerivation ( - attrs - // { - nativeBuildInputs = - (attrs.nativeBuildInputs or [ ]) - ++ [ - cmake - ninja - swift - ] - ++ lib.optionals stdenv.hostPlatform.isDarwin [ DarwinTools ]; - - buildInputs = (attrs.buildInputs or [ ]) ++ [ Foundation ]; - - postPatch = - (attrs.postPatch or "") - + lib.optionalString stdenv.hostPlatform.isDarwin '' - # On Darwin only, Swift uses arm64 as cpu arch. - if [ -e cmake/modules/SwiftSupport.cmake ]; then - # At least in swift-asn1, this has been removed and the module uses the full target triple as the name - # (https://github.com/apple/swift-asn1/pull/103) - substituteInPlace cmake/modules/SwiftSupport.cmake \ - --replace '"aarch64" PARENT_SCOPE' '"arm64" PARENT_SCOPE' - fi - ''; - - postInstall = - (attrs.postInstall or "") - + lib.optionalString stdenv.hostPlatform.isDarwin '' - # The install name of libraries is incorrectly set to lib/ (via our - # CMake setup hook) instead of lib/swift/. This'd be easily fixed by - # fixDarwinDylibNames, but some builds create libraries that reference - # eachother, and we also have to fix those references. - dylibs="$(find $out/lib/swift* -name '*.dylib')" - changes="" - for dylib in $dylibs; do - changes+=" -change $(otool -D $dylib | tail -n 1) $dylib" - done - for dylib in $dylibs; do - install_name_tool -id $dylib $changes $dylib - done - ''; - - cmakeFlags = (attrs.cmakeFlags or [ ]) ++ [ - # Some builds link to libraries within the same build. Make sure these - # create references to $out. None of our builds run their own products, - # so we don't have to account for that scenario. - "-DCMAKE_BUILD_WITH_INSTALL_NAME_DIR=ON" - ]; - } - ); - - # On Darwin, we only want ncurses in the linker search path, because headers - # are part of libsystem. Adding its headers to the search path causes strange - # mixing and errors. - # TODO: Find a better way to prevent this conflict. - ncursesInput = if stdenv.hostPlatform.isDarwin then ncurses.out else ncurses; - - # Derivations for bootstrapping dependencies using CMake. - # This is based on the `swiftpm/Utilities/bootstrap` script. - # - # Some of the installation steps here are a bit hacky, because it seems like - # these packages were not really meant to be installed using CMake. The - # regular swiftpm bootstrap simply refers to the source and build - # directories. The advantage of separate builds is that we can more easily - # link libs together using existing Nixpkgs infra. - # - # In the end, we don't expose these derivations, and they only exist during - # the bootstrap phase. The final swiftpm derivation does not depend on them. - - swift-system = mkBootstrapDerivation { - name = "swift-system"; - src = generated.sources.swift-system; - - postInstall = - cmakeGlue.SwiftSystem - + lib.optionalString (!stdenv.hostPlatform.isDarwin) '' - # The cmake rules apparently only use the Darwin install convention. - # Fix up the installation so the module can be found on non-Darwin. - mkdir -p $out/${swiftStaticModuleSubdir} - mv $out/lib/swift_static/${swiftOs}/*.swiftmodule $out/${swiftStaticModuleSubdir}/ - ''; - }; - - swift-collections = mkBootstrapDerivation { - name = "swift-collections"; - src = generated.sources.swift-collections; - - postPatch = '' - # Only builds static libs on Linux, but this installation difference is a - # hassle. Because this installation is temporary for the bootstrap, may - # as well build static libs everywhere. - sed -i -e '/BUILD_SHARED_LIBS/d' CMakeLists.txt - ''; - - postInstall = - cmakeGlue.SwiftCollections - + lib.optionalString (!stdenv.hostPlatform.isDarwin) '' - # The cmake rules apparently only use the Darwin install convention. - # Fix up the installation so the module can be found on non-Darwin. - mkdir -p $out/${swiftStaticModuleSubdir} - mv $out/lib/swift_static/${swiftOs}/*.swiftmodule $out/${swiftStaticModuleSubdir}/ - ''; - }; - - swift-tools-support-core = mkBootstrapDerivation { - name = "swift-tools-support-core"; - src = generated.sources.swift-tools-support-core; - - buildInputs = [ - swift-system - sqlite - ]; - - postInstall = cmakeGlue.TSC + '' - # Swift modules are not installed. - mkdir -p $out/${swiftModuleSubdir} - cp swift/*.swift{module,doc} $out/${swiftModuleSubdir}/ - - # Static libs are not installed. - cp lib/*.a $out/lib/ - - # Headers are not installed. - mkdir -p $out/include - cp -r ../Sources/TSCclibc/include $out/include/TSC - ''; - }; - - swift-argument-parser = mkBootstrapDerivation { - name = "swift-argument-parser"; - src = generated.sources.swift-argument-parser; - - buildInputs = [ - ncursesInput - sqlite - ]; - - cmakeFlags = [ - "-DBUILD_TESTING=NO" - "-DBUILD_EXAMPLES=NO" - ]; - - postInstall = - cmakeGlue.ArgumentParser - + lib.optionalString stdenv.hostPlatform.isLinux '' - # Fix rpath so ArgumentParserToolInfo can be found. - patchelf --add-rpath "$out/lib/swift/${swiftOs}" \ - $out/lib/swift/${swiftOs}/libArgumentParser.so - ''; - }; - - Yams = mkBootstrapDerivation { - name = "Yams"; - src = generated.sources.Yams; - - # Conflicts with BUILD file on case-insensitive filesystems. - cmakeBuildDir = "_build"; - - postInstall = cmakeGlue.Yams; - }; - - llbuild = mkBootstrapDerivation { - name = "llbuild"; - src = generated.sources.swift-llbuild; - - nativeBuildInputs = lib.optional stdenv.hostPlatform.isDarwin xcbuild; - buildInputs = [ - ncursesInput - sqlite - ]; - - patches = [ - ./patches/llbuild-cmake-disable-rpath.patch - ./patches/llbuild-fix-missing-cstdint.patch - ]; - - postPatch = '' - # Substitute ncurses for curses. - find . -name CMakeLists.txt | xargs sed -i -e 's/curses/ncurses/' - - # Use absolute install names instead of rpath. - substituteInPlace \ - products/libllbuild/CMakeLists.txt \ - products/llbuildSwift/CMakeLists.txt \ - --replace-fail '@rpath' "$out/lib" - - # This subdirectory is enabled for Darwin only, but requires ObjC XCTest - # (and only Swift XCTest is open source). - substituteInPlace perftests/CMakeLists.txt \ - --replace-fail 'add_subdirectory(Xcode/' '#add_subdirectory(Xcode/' - ''; - - cmakeFlags = [ - "-DLLBUILD_SUPPORT_BINDINGS=Swift" - ]; - - postInstall = cmakeGlue.LLBuild + '' - # Install module map. - cp ../products/libllbuild/include/module.modulemap $out/include - - # Swift modules are not installed. - mkdir -p $out/${swiftModuleSubdir} - cp products/llbuildSwift/*.swift{module,doc} $out/${swiftModuleSubdir}/ - ''; - }; - - swift-driver = mkBootstrapDerivation { - name = "swift-driver"; - src = generated.sources.swift-driver; - - buildInputs = [ - Yams - llbuild - swift-system - swift-argument-parser - swift-tools-support-core - ]; - - postPatch = '' - # Tries to link against CYaml, but that's private. - substituteInPlace Sources/SwiftDriver/CMakeLists.txt \ - --replace-fail CYaml "" - ''; - - postInstall = cmakeGlue.SwiftDriver + '' - # Swift modules are not installed. - mkdir -p $out/${swiftModuleSubdir} - cp swift/*.swift{module,doc} $out/${swiftModuleSubdir}/ - ''; - }; - - swift-crypto = mkBootstrapDerivation { - name = "swift-crypto"; - src = fetchFromGitHub { - owner = "swiftlang"; - repo = "swift-crypto"; - rev = "95ba0316a9b733e92bb6b071255ff46263bbe7dc"; # 3.15.1, as opposed to the pinned version of 3.0.0 - sha256 = "sha256-RzoUBx4l12v0ZamSIAEpHHCRQXxJkXJCwVBEj7Qwg9I="; - fetchSubmodules = true; - }; - - buildInputs = [ - swift-asn1 - ]; - - patches = [ - ./patches/install-crypto-extras.patch - ]; - - postPatch = '' - # Fix use of hardcoded tool paths on Darwin. - substituteInPlace CMakeLists.txt \ - --replace-fail /usr/bin/ar $NIX_CC/bin/ar - substituteInPlace CMakeLists.txt \ - --replace-fail /usr/bin/ranlib $NIX_CC/bin/ranlib - ''; - - postInstall = cmakeGlue.SwiftCrypto + '' - # Static libs are not installed. - cp lib/*.a $out/lib/ - - # Headers are not installed. - cp -r ../Sources/CCryptoBoringSSL/include $out/include - - # Swift modules are put in the wrong place by default (and not all are linked) - mkdir -p $out/${swiftModuleSubdir} - rm -rf $out/${swiftModuleSubdir}/*.swift{module,doc} - # I assume we don't care about .swiftsourceinfo - cp swift/*.swift{module,doc} $out/${swiftModuleSubdir}/ - ''; - }; - - swift-asn1 = mkBootstrapDerivation { - name = "swift-asn1"; - src = generated.sources.swift-asn1; - - postInstall = - cmakeGlue.SwiftASN1 - + lib.optionalString (!stdenv.hostPlatform.isDarwin) '' - # SwiftASN1 uses the full target triple as the name of the swiftmodule - # (https://github.com/apple/swift-asn1/pull/103) - mkdir -p $out/${swiftModuleSubdir} - cp swift/*.swift{module,doc} $out/${swiftModuleSubdir}/ - ''; - }; - - swift-certificates = mkBootstrapDerivation { - name = "swift-certificates"; - src = generated.sources.swift-certificates; - - buildInputs = [ - swift-asn1 - swift-crypto - ]; - - postInstall = cmakeGlue.SwiftCertificates; - }; - - # Build a bootstrapping swiftpm using CMake. - swiftpm-bootstrap = mkBootstrapDerivation ( - commonAttrs - // { - pname = "swiftpm-bootstrap"; - - buildInputs = [ - llbuild - sqlite - swift-argument-parser - swift-asn1 - swift-certificates - swift-collections - swift-crypto - swift-driver - swift-system - swift-tools-support-core - ]; - - cmakeFlags = [ - "-DUSE_CMAKE_INSTALL=ON" - ]; - - postInstall = '' - for program in $out/bin/swift-*; do - wrapProgram $program --prefix PATH : ${lib.makeBinPath runtimeDeps} - done - ''; - } - ); - -in -# Build the final swiftpm with the bootstrapping swiftpm. -stdenv.mkDerivation ( - commonAttrs - // { - pname = "swiftpm"; - - nativeBuildInputs = commonAttrs.nativeBuildInputs ++ [ - pkg-config - swift - swiftpm-bootstrap - ]; - buildInputs = [ - ncursesInput - sqlite - XCTest - ]; - - configurePhase = generated.configure + '' - # Functionality provided by Xcode XCTest, but not available in - # swift-corelibs-xctest. - swiftpmMakeMutable swift-tools-support-core - substituteInPlace .build/checkouts/swift-tools-support-core/Sources/TSCTestSupport/XCTestCasePerf.swift \ - --replace-fail 'canImport(Darwin)' 'false' - - # Prevent a warning about SDK directories we don't have. - swiftpmMakeMutable swift-driver - patch -p1 -d .build/checkouts/swift-driver -i ${ - replaceVars ../swift-driver/patches/prevent-sdk-dirs-warnings.patch { - inherit (builtins) storeDir; - } - } - ''; - - buildPhase = '' - TERM=dumb swift-build -c release - ''; - - # TODO: Tests depend on indexstore-db being provided by an existing Swift - # toolchain. (ie. looks for `../lib/libIndexStore.so` relative to swiftc. - #doCheck = true; - #checkPhase = '' - # TERM=dumb swift-test -c release - #''; - - # The following is derived from Utilities/bootstrap, see install_swiftpm. - installPhase = '' - binPath="$(swift-build --show-bin-path -c release)" - - mkdir -p $out/bin $out/lib/swift - - cp $binPath/swift-package-manager $out/bin/swift-package - wrapProgram $out/bin/swift-package \ - --prefix PATH : ${lib.makeBinPath runtimeDeps} - for tool in swift-build swift-test swift-run swift-package-collection swift-experimental-destination; do - ln -s $out/bin/swift-package $out/bin/$tool - done - - installSwiftpmModule() { - mkdir -p $out/lib/swift/pm/$2 - cp $binPath/lib$1${sharedLibraryExt} $out/lib/swift/pm/$2/ - - if [[ -f $binPath/$1.swiftinterface ]]; then - cp $binPath/$1.swiftinterface $out/lib/swift/pm/$2/ - else - cp -r $binPath/$1.swiftmodule $out/lib/swift/pm/$2/ - fi - cp $binPath/$1.swiftdoc $out/lib/swift/pm/$2/ - } - installSwiftpmModule PackageDescription ManifestAPI - installSwiftpmModule PackagePlugin PluginAPI - ''; - - setupHook = ./setup-hook.sh; - - meta = { - description = "Package Manager for the Swift Programming Language"; - homepage = "https://github.com/swiftlang/swift-package-manager"; - platforms = with lib.platforms; linux ++ darwin; - license = lib.licenses.asl20; - teams = [ lib.teams.swift ]; - }; - } -) diff --git a/pkgs/development/compilers/swift/swiftpm/generated/default.nix b/pkgs/development/compilers/swift/swiftpm/generated/default.nix deleted file mode 100644 index 68e3f885d542..000000000000 --- a/pkgs/development/compilers/swift/swiftpm/generated/default.nix +++ /dev/null @@ -1,16 +0,0 @@ -# This file was generated by swiftpm2nix. -{ - workspaceStateFile = ./workspace-state.json; - hashes = { - "swift-argument-parser" = "sha256-qEJ329hqQyQVxtHScD7qPmWW9ZDf9bX+4xgpDlX0w5A="; - "swift-asn1" = "sha256-6NqPGUuM55YOXCMqNsqPm/3smKhSC2UIYHJSwtIiuoc="; - "swift-certificates" = "sha256-n5dE5J8f7PAVoJkIpiKrrDvB0xIil5VwtzC2mx6vz80="; - "swift-collections" = "sha256-WNj19mRvDSZNcDzZvmtS+jZxngBooiHekh3IsPZnKUQ="; - "swift-crypto" = "sha256-lcB497b/T1bHShPrjNjHthrs76pDFpU+4uN0uW4tz+4="; - "swift-driver" = "sha256-Xaz9gZuOspDb+PB67d6tXfpcs+kkDCPSkhu+eIfrb0A="; - "swift-llbuild" = "sha256-kUm8/+DWDBhuqU/kJBleqSl8/Vz478pMhx5QK2g7k0o="; - "swift-system" = "sha256-p18QHzO+NtoY/WQzOD+PfD+bjqrIWsbeEbsJLPqEAhA="; - "swift-tools-support-core" = "sha256-Pqy01AyDg7ZTyDM6lV69e6nhfhxwFTOhGFTfhcA1e9E="; - "Yams" = "sha256-AY/fIvB7THrl9GWzGJL8eDBbkcLw27tSRTGtUqmYw8k="; - }; -} diff --git a/pkgs/development/compilers/swift/swiftpm/generated/workspace-state.json b/pkgs/development/compilers/swift/swiftpm/generated/workspace-state.json deleted file mode 100644 index 4b9689d8ab30..000000000000 --- a/pkgs/development/compilers/swift/swiftpm/generated/workspace-state.json +++ /dev/null @@ -1,178 +0,0 @@ -{ - "object": { - "artifacts": [], - "dependencies": [ - { - "basedOn": null, - "packageRef": { - "identity": "swift-argument-parser", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-argument-parser.git", - "name": "swift-argument-parser" - }, - "state": { - "checkoutState": { - "revision": "8f4d2753f0e4778c76d5f05ad16c74f707390531", - "version": "1.2.3" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-argument-parser" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-asn1", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-asn1.git", - "name": "swift-asn1" - }, - "state": { - "checkoutState": { - "revision": "f70225981241859eb4aa1a18a75531d26637c8cc", - "version": "1.4.0" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-asn1" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-certificates", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-certificates.git", - "name": "swift-certificates" - }, - "state": { - "checkoutState": { - "revision": "01d7664523af5c169f26038f1e5d444ce47ae5ff", - "version": "1.0.1" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-certificates" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-collections", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-collections.git", - "name": "swift-collections" - }, - "state": { - "checkoutState": { - "revision": "d029d9d39c87bed85b1c50adee7c41795261a192", - "version": "1.0.6" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-collections" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-crypto", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-crypto.git", - "name": "swift-crypto" - }, - "state": { - "checkoutState": { - "revision": "629f0b679d0fd0a6ae823d7f750b9ab032c00b80", - "version": "3.0.0" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-crypto" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-driver", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-driver.git", - "name": "swift-driver" - }, - "state": { - "checkoutState": { - "branch": "release/5.10", - "revision": "b461fd4fc51be8e1f2a3f4a2184b664b8846b46f" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-driver" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-llbuild", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-llbuild.git", - "name": "llbuild" - }, - "state": { - "checkoutState": { - "branch": "release/5.10", - "revision": "fd7c2e0d9279edd023ced6b0a590f8407f5472f9" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-llbuild" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-system", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-system.git", - "name": "swift-system" - }, - "state": { - "checkoutState": { - "revision": "836bc4557b74fe6d2660218d56e3ce96aff76574", - "version": "1.1.1" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-system" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-tools-support-core", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-tools-support-core.git", - "name": "swift-tools-support-core" - }, - "state": { - "checkoutState": { - "branch": "release/5.10", - "revision": "90bdc2a157ebacc5d3de0c83e085d05d22ca5fa0" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-tools-support-core" - }, - { - "basedOn": null, - "packageRef": { - "identity": "yams", - "kind": "remoteSourceControl", - "location": "https://github.com/jpsim/Yams.git", - "name": "Yams" - }, - "state": { - "checkoutState": { - "revision": "0d9ee7ea8c4ebd4a489ad7a73d5c6cad55d6fed3", - "version": "5.0.6" - }, - "name": "sourceControlCheckout" - }, - "subpath": "Yams" - } - ] - }, - "version": 6 -} diff --git a/pkgs/development/compilers/swift/swiftpm/patches/cmake-disable-rpath.patch b/pkgs/development/compilers/swift/swiftpm/patches/cmake-disable-rpath.patch deleted file mode 100644 index f5997fa7ce5b..000000000000 --- a/pkgs/development/compilers/swift/swiftpm/patches/cmake-disable-rpath.patch +++ /dev/null @@ -1,36 +0,0 @@ -Disable rpath for the bootstrap build with CMake. - ---- a/Sources/PackageDescription/CMakeLists.txt -+++ b/Sources/PackageDescription/CMakeLists.txt -@@ -27,14 +27,11 @@ - $<$:-package-description-version$999.0>) - - if(CMAKE_HOST_SYSTEM_NAME STREQUAL Darwin) -- target_link_options(PackageDescription PRIVATE -- "SHELL:-Xlinker -install_name -Xlinker @rpath/libPackageDescription.dylib") - endif() - - set_target_properties(PackageDescription PROPERTIES - Swift_MODULE_NAME PackageDescription - Swift_MODULE_DIRECTORY ${CMAKE_BINARY_DIR}/pm/ManifestAPI -- INSTALL_NAME_DIR \\@rpath - OUTPUT_DIRECTORY ${CMAKE_BINARY_DIR}/pm/ManifestAPI - OUTPUT_NAME PackageDescription - ARCHIVE_OUTPUT_DIRECTORY ${CMAKE_BINARY_DIR}/pm/ManifestAPI ---- a/Sources/PackagePlugin/CMakeLists.txt -+++ b/Sources/PackagePlugin/CMakeLists.txt -@@ -29,14 +29,11 @@ if(CMAKE_HOST_SYSTEM_NAME STREQUAL Darwin) - set(SWIFT_INTERFACE_PATH ${CMAKE_BINARY_DIR}/pm/PluginAPI/PackagePlugin.swiftinterface) - target_compile_options(PackagePlugin PUBLIC - $<$:-emit-module-interface-path$${SWIFT_INTERFACE_PATH}>) -- target_link_options(PackagePlugin PRIVATE -- "SHELL:-Xlinker -install_name -Xlinker @rpath/libPackagePlugin.dylib") - endif() - - set_target_properties(PackagePlugin PROPERTIES - Swift_MODULE_NAME PackagePlugin - Swift_MODULE_DIRECTORY ${CMAKE_BINARY_DIR}/pm/PluginAPI -- INSTALL_NAME_DIR \\@rpath - OUTPUT_DIRECTORY ${CMAKE_BINARY_DIR}/pm/PluginAPI - OUTPUT_NAME PackagePlugin - ARCHIVE_OUTPUT_DIRECTORY ${CMAKE_BINARY_DIR}/pm/PluginAPI diff --git a/pkgs/development/compilers/swift/swiftpm/patches/disable-index-store.patch b/pkgs/development/compilers/swift/swiftpm/patches/disable-index-store.patch deleted file mode 100644 index ca701ae32543..000000000000 --- a/pkgs/development/compilers/swift/swiftpm/patches/disable-index-store.patch +++ /dev/null @@ -1,23 +0,0 @@ -The `-index-store-path` option is an Apple extension not available in our -Clang. Make it opt-in by default. - -(It is assumed the `target.type == test` check is for Xcode support, because -there is no evidence of it in swift-corelibs-xctest.) - ---- a/Sources/Build/BuildPlan/BuildPlan.swift -+++ b/Sources/Build/BuildPlan/BuildPlan.swift -@@ -111,14 +111,7 @@ - case .off: - addIndexStoreArguments = false - case .auto: -- if configuration == .debug { -- addIndexStoreArguments = true -- } else if target.type == .test { -- // Test discovery requires an index store for the test target to discover the tests -- addIndexStoreArguments = true -- } else { - addIndexStoreArguments = false -- } - } - - if addIndexStoreArguments { diff --git a/pkgs/development/compilers/swift/swiftpm/patches/disable-sandbox.patch b/pkgs/development/compilers/swift/swiftpm/patches/disable-sandbox.patch deleted file mode 100644 index b83e16e3c78f..000000000000 --- a/pkgs/development/compilers/swift/swiftpm/patches/disable-sandbox.patch +++ /dev/null @@ -1,27 +0,0 @@ -Nix may already sandbox the build, in which case sandbox_apply will fail. - ---- a/Sources/Basics/Sandbox.swift -+++ b/Sources/Basics/Sandbox.swift -@@ -57,6 +57,8 @@ - allowNetworkConnections: [SandboxNetworkPermission] = [] - ) throws -> [String] { - #if os(macOS) -+ let env = ProcessInfo.processInfo.environment -+ if env["NIX_BUILD_TOP"] == nil || env["IN_NIX_SHELL"] != nil { - let profile = try macOSSandboxProfile( - fileSystem: fileSystem, - strictness: strictness, -@@ -65,10 +67,10 @@ - allowNetworkConnections: allowNetworkConnections - ) - return ["/usr/bin/sandbox-exec", "-p", profile] + command -- #else -+ } -+ #endif - // rdar://40235432, rdar://75636874 tracks implementing sandboxes for other platforms. - return command -- #endif - } - - /// Basic strictness level of a sandbox applied to a command line. - diff --git a/pkgs/development/compilers/swift/swiftpm/patches/disable-xctest.patch b/pkgs/development/compilers/swift/swiftpm/patches/disable-xctest.patch deleted file mode 100644 index 71aca0071e83..000000000000 --- a/pkgs/development/compilers/swift/swiftpm/patches/disable-xctest.patch +++ /dev/null @@ -1,14 +0,0 @@ -XCTest is not fully open-source, only the Swift library parts. We don't have a -command-line runner available, so disable support. - ---- a/Sources/Commands/Utilities/TestingSupport.swift -+++ b/Sources/Commands/Utilities/TestingSupport.swift -@@ -105,7 +105,7 @@ - ) throws -> [TestSuite] { - // Run the correct tool. - var args = [String]() -- #if os(macOS) -+ #if false - let data: String = try withTemporaryFile { tempFile in - args = [try Self.xctestHelperPath(swiftTool: swiftTool).pathString, path.pathString, tempFile.path.pathString] - var env = try Self.constructTestEnvironment( diff --git a/pkgs/development/compilers/swift/swiftpm/patches/fix-clang-cxx.patch b/pkgs/development/compilers/swift/swiftpm/patches/fix-clang-cxx.patch deleted file mode 100644 index 877337924bbe..000000000000 --- a/pkgs/development/compilers/swift/swiftpm/patches/fix-clang-cxx.patch +++ /dev/null @@ -1,126 +0,0 @@ -Swiftpm may invoke clang, not clang++, to compile C++. Our cc-wrapper also -doesn't pick up the arguments that enable C++ compilation in this case. Patch -swiftpm to properly invoke clang++. - ---- a/Sources/Build/BuildPlan/BuildPlan+Product.swift -+++ b/Sources/Build/BuildPlan/BuildPlan+Product.swift -@@ -53,7 +53,7 @@ - for target in dependencies.staticTargets { - if case let target as ClangTarget = target.underlyingTarget, target.isCXX { - if buildParameters.targetTriple.isDarwin() { -- buildProduct.additionalFlags += ["-lc++"] -+ buildProduct.additionalFlags += ["-lc++", "-lc++abi"] - } else if buildParameters.targetTriple.isWindows() { - // Don't link any C++ library. - } else { ---- a/Sources/Build/BuildManifest/LLBuildManifestBuilder+Clang.swift -+++ b/Sources/Build/BuildManifest/LLBuildManifestBuilder+Clang.swift -@@ -97,7 +97,7 @@ - - args += ["-c", path.source.pathString, "-o", path.object.pathString] - -- let clangCompiler = try buildParameters.toolchain.getClangCompiler().pathString -+ let clangCompiler = try buildParameters.toolchain.getClangCompiler(isCXX: isCXX).pathString - args.insert(clangCompiler, at: 0) - - let objectFileNode: Node = .file(path.object) ---- a/Sources/PackageModel/Toolchain.swift -+++ b/Sources/PackageModel/Toolchain.swift -@@ -23,7 +23,7 @@ public protocol Toolchain { - var macosSwiftStdlib: AbsolutePath { get throws } - - /// Path of the `clang` compiler. -- func getClangCompiler() throws -> AbsolutePath -+ func getClangCompiler(isCXX: Bool) throws -> AbsolutePath - - // FIXME: This is a temporary API until index store is widely available in - // the OSS clang compiler. This API should not used for any other purpose. ---- a/Sources/PackageModel/UserToolchain.swift -+++ b/Sources/PackageModel/UserToolchain.swift -@@ -57,7 +57,7 @@ public final class UserToolchain: Toolchain { - /// Only use search paths, do not fall back to `xcrun`. - let useXcrun: Bool - -- private var _clangCompiler: AbsolutePath? -+ private var _clangCompiler: [Bool: AbsolutePath] = [:] - - private let environment: EnvironmentVariables - -@@ -262,33 +262,35 @@ - } - - /// Returns the path to clang compiler tool. -- public func getClangCompiler() throws -> AbsolutePath { -+ public func getClangCompiler(isCXX: Bool) throws -> AbsolutePath { - // Check if we already computed. -- if let clang = self._clangCompiler { -+ if let clang = self._clangCompiler[isCXX] { - return clang - } - - // Check in the environment variable first. -+ let envVar = isCXX ? "CXX" : "CC" - if let toolPath = UserToolchain.lookup( -- variable: "CC", -+ variable: envVar, - searchPaths: self.envSearchPaths, - environment: environment - ) { -- self._clangCompiler = toolPath -+ self._clangCompiler[isCXX] = toolPath - return toolPath - } - - // Then, check the toolchain. -+ let tool = isCXX ? "clang++" : "clang" - do { -- if let toolPath = try? UserToolchain.getTool("clang", binDirectories: self.swiftSDK.toolset.rootPaths) { -- self._clangCompiler = toolPath -+ if let toolPath = try? UserToolchain.getTool(tool, binDirectories: self.swiftSDK.toolset.rootPaths) { -+ self._clangCompiler[isCXX] = toolPath - return toolPath - } - } - - // Otherwise, lookup it up on the system. -- let toolPath = try UserToolchain.findTool("clang", envSearchPaths: self.envSearchPaths, useXcrun: useXcrun) -- self._clangCompiler = toolPath -+ let toolPath = try UserToolchain.findTool(tool, envSearchPaths: self.envSearchPaths, useXcrun: useXcrun) -+ self._clangCompiler[isCXX] = toolPath - return toolPath - } - - ---- a/Sources/SPMBuildCore/BuildParameters/BuildParameters.swift -+++ b/Sources/SPMBuildCore/BuildParameters/BuildParameters.swift -@@ -394,7 +394,7 @@ private struct _Toolchain: Encodable { - public func encode(to encoder: Encoder) throws { - var container = encoder.container(keyedBy: CodingKeys.self) - try container.encode(toolchain.swiftCompilerPath, forKey: .swiftCompiler) -- try container.encode(toolchain.getClangCompiler(), forKey: .clangCompiler) -+ try container.encode(toolchain.getClangCompiler(isCXX: false), forKey: .clangCompiler) - - try container.encode(toolchain.extraFlags.cCompilerFlags, forKey: .extraCCFlags) - // Maintaining `extraCPPFlags` key for compatibility with older encoding. ---- a/Sources/XCBuildSupport/XcodeBuildSystem.swift -+++ b/Sources/XCBuildSupport/XcodeBuildSystem.swift -@@ -182,7 +182,7 @@ public final class XcodeBuildSystem: SPMBuildCore.BuildSystem { - // Generate a table of any overriding build settings. - var settings: [String: String] = [:] - // An error with determining the override should not be fatal here. -- settings["CC"] = try? buildParameters.toolchain.getClangCompiler().pathString -+ settings["CC"] = try? buildParameters.toolchain.getClangCompiler(isCXX: false).pathString - // Always specify the path of the effective Swift compiler, which was determined in the same way as for the native build system. - settings["SWIFT_EXEC"] = buildParameters.toolchain.swiftCompilerPath.pathString - settings["LIBRARY_SEARCH_PATHS"] = "$(inherited) \(try buildParameters.toolchain.toolchainLibDir.pathString)" ---- a/Tests/BuildTests/MockBuildTestHelper.swift -+++ b/Tests/BuildTests/MockBuildTestHelper.swift -@@ -36,7 +36,7 @@ - let extraFlags = PackageModel.BuildFlags() - let installedSwiftPMConfiguration = InstalledSwiftPMConfiguration.default - -- func getClangCompiler() throws -> AbsolutePath { -+ func getClangCompiler(isCXX: Bool) throws -> AbsolutePath { - return "/fake/path/to/clang" - } - diff --git a/pkgs/development/compilers/swift/swiftpm/patches/fix-stdlib-path.patch b/pkgs/development/compilers/swift/swiftpm/patches/fix-stdlib-path.patch deleted file mode 100644 index 68698cafcdf6..000000000000 --- a/pkgs/development/compilers/swift/swiftpm/patches/fix-stdlib-path.patch +++ /dev/null @@ -1,25 +0,0 @@ -Swiftpm looks for the Swift stdlib relative to the swift compiler, but that's a -wrapper in our case. It wants to add the stdlib to the rpath, which is -necessary for back-deployment of some features. - ---- a/Sources/PackageModel/Toolchain.swift -+++ b/Sources/PackageModel/Toolchain.swift -@@ -53,12 +53,18 @@ extension Toolchain { - - public var macosSwiftStdlib: AbsolutePath { - get throws { -+ if swiftCompilerPath.pathString.starts(with: "@storeDir@") { -+ return try AbsolutePath(validating: "@swiftLib@/lib/swift/macosx") -+ } - return try AbsolutePath(validating: "../../lib/swift/macosx", relativeTo: resolveSymlinks(swiftCompilerPath)) - } - } - - public var toolchainLibDir: AbsolutePath { - get throws { -+ if swiftCompilerPath.pathString.starts(with: "@storeDir@") { -+ return try AbsolutePath(validating: "@swiftLib@/lib") -+ } - // FIXME: Not sure if it's better to base this off of Swift compiler or our own binary. - return try AbsolutePath(validating: "../../lib", relativeTo: resolveSymlinks(swiftCompilerPath)) - } diff --git a/pkgs/development/compilers/swift/swiftpm/patches/install-crypto-extras.patch b/pkgs/development/compilers/swift/swiftpm/patches/install-crypto-extras.patch deleted file mode 100644 index bdbd1c4d596e..000000000000 --- a/pkgs/development/compilers/swift/swiftpm/patches/install-crypto-extras.patch +++ /dev/null @@ -1,10 +0,0 @@ -Install _CryptoExtras target when building with CMake - ---- a/Sources/_CryptoExtras/CMakeLists.txt -+++ b/Sources/_CryptoExtras/CMakeLists.txt -@@ -42,4 +42,5 @@ target_link_options(_CryptoExtras PRIVATE - set_target_properties(_CryptoExtras PROPERTIES - INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) - -+_install_target(_CryptoExtras) - set_property(GLOBAL APPEND PROPERTY SWIFT_CRYPTO_EXPORTS _CryptoExtras) diff --git a/pkgs/development/compilers/swift/swiftpm/patches/llbuild-cmake-disable-rpath.patch b/pkgs/development/compilers/swift/swiftpm/patches/llbuild-cmake-disable-rpath.patch deleted file mode 100644 index 785e82cc34b6..000000000000 --- a/pkgs/development/compilers/swift/swiftpm/patches/llbuild-cmake-disable-rpath.patch +++ /dev/null @@ -1,14 +0,0 @@ -Specifying `-platform_version` targeting macos before 10.15 causes cctools ld -to link with `@rpath`. This may have something to do with Swift ABI stability. - ---- a/products/llbuildSwift/CMakeLists.txt -+++ b/products/llbuildSwift/CMakeLists.txt -@@ -22,7 +17,7 @@ endif() - - # TODO(compnerd) move both of these outside of the CMake into the invocation - if(CMAKE_SYSTEM_NAME STREQUAL Darwin) -- add_compile_options(-target ${CMAKE_OSX_ARCHITECTURES}-apple-macosx10.10) -+ add_compile_options(-target ${CMAKE_OSX_ARCHITECTURES}-apple-macosx10.15) - if(NOT CMAKE_OSX_SYSROOT STREQUAL "") - add_compile_options(-sdk ${CMAKE_OSX_SYSROOT}) - endif() diff --git a/pkgs/development/compilers/swift/swiftpm/patches/llbuild-fix-missing-cstdint.patch b/pkgs/development/compilers/swift/swiftpm/patches/llbuild-fix-missing-cstdint.patch deleted file mode 100644 index 9dcbe6502356..000000000000 --- a/pkgs/development/compilers/swift/swiftpm/patches/llbuild-fix-missing-cstdint.patch +++ /dev/null @@ -1,12 +0,0 @@ -diff --git a/utils/unittest/googletest/src/gtest-death-test.cc b/utils/unittest/googletest/src/gtest-death-test.cc -index ede8378..bdef225 100644 ---- a/utils/unittest/googletest/src/gtest-death-test.cc -+++ b/utils/unittest/googletest/src/gtest-death-test.cc -@@ -33,6 +33,7 @@ - #include "gtest/gtest-death-test.h" - - #include -+#include - - #include "gtest/internal/gtest-port.h" - #include "gtest/internal/custom/gtest.h" diff --git a/pkgs/development/compilers/swift/swiftpm/patches/nix-pkgconfig-vars.patch b/pkgs/development/compilers/swift/swiftpm/patches/nix-pkgconfig-vars.patch deleted file mode 100644 index e032ce80bf90..000000000000 --- a/pkgs/development/compilers/swift/swiftpm/patches/nix-pkgconfig-vars.patch +++ /dev/null @@ -1,28 +0,0 @@ -Swift parses .pc files manually, but this means it bypasses our pkg-config -wrapper. That wrapper normally takes care of introducing the correct -PKG_CONFIG_PATH for cross compiling. - ---- a/Sources/PackageLoading/PkgConfig.swift -+++ b/Sources/PackageLoading/PkgConfig.swift -@@ -123,14 +123,17 @@ public struct PkgConfig { - - private static var envSearchPaths: [AbsolutePath] { - get throws { -- if let configPath = ProcessEnv.vars["PKG_CONFIG_PATH"] { -+ var result: [AbsolutePath] = [] -+ for envVar in ["PKG_CONFIG_PATH", "PKG_CONFIG_PATH_FOR_TARGET"] { -+ if let configPath = ProcessEnv.vars[envVar] { - #if os(Windows) -- return try configPath.split(separator: ";").map({ try AbsolutePath(validating: String($0)) }) -+ result += try configPath.split(separator: ";").map({ try AbsolutePath(validating: String($0)) }) - #else -- return try configPath.split(separator: ":").map({ try AbsolutePath(validating: String($0)) }) -+ result += try configPath.split(separator: ":").map({ try AbsolutePath(validating: String($0)) }) - #endif - } -- return [] -+ } -+ return result - } - } - } diff --git a/pkgs/development/compilers/swift/swiftpm/setup-hook.sh b/pkgs/development/compilers/swift/swiftpm/setup-hook.sh deleted file mode 100644 index 260d874ebfd7..000000000000 --- a/pkgs/development/compilers/swift/swiftpm/setup-hook.sh +++ /dev/null @@ -1,62 +0,0 @@ -# shellcheck shell=bash - -# Build using 'swift-build'. -swiftpmBuildPhase() { - runHook preBuild - - local buildCores=1 - if [ "${enableParallelBuilding-1}" ]; then - buildCores="$NIX_BUILD_CORES" - fi - - local flagsArray=( - -j "$buildCores" - -c "${swiftpmBuildConfig-release}" - ) - concatTo flagsArray swiftpmFlags swiftpmFlagsArray - - echoCmd 'build flags' "${flagsArray[@]}" - TERM=dumb swift-build "${flagsArray[@]}" - - runHook postBuild -} - -if [ -z "${dontUseSwiftpmBuild-}" ] && [ -z "${buildPhase-}" ]; then - buildPhase=swiftpmBuildPhase -fi - -# Check using 'swift-test'. -swiftpmCheckPhase() { - runHook preCheck - - local buildCores=1 - if [ "${enableParallelBuilding-1}" ]; then - buildCores="$NIX_BUILD_CORES" - fi - - local flagsArray=( - -j "$buildCores" - -c "${swiftpmBuildConfig-release}" - ) - concatTo flagsArray swiftpmFlags swiftpmFlagsArray - - echoCmd 'check flags' "${flagsArray[@]}" - TERM=dumb swift-test "${flagsArray[@]}" - - runHook postCheck -} - -if [ -z "${dontUseSwiftpmCheck-}" ] && [ -z "${checkPhase-}" ]; then - checkPhase=swiftpmCheckPhase -fi - -# Helper used to find the binary output path. -# Useful for performing the installPhase of swiftpm packages. -swiftpmBinPath() { - local flagsArray=( - -c "${swiftpmBuildConfig-release}" - ) - concatTo flagsArray swiftpmFlags swiftpmFlagsArray - - swift-build --show-bin-path "${flagsArray[@]}" -} diff --git a/pkgs/development/compilers/swift/wrapper/default.nix b/pkgs/development/compilers/swift/wrapper/default.nix deleted file mode 100644 index 9cd9cb347a23..000000000000 --- a/pkgs/development/compilers/swift/wrapper/default.nix +++ /dev/null @@ -1,119 +0,0 @@ -{ - lib, - stdenv, - swift, - useSwiftDriver ? true, - swift-driver, - clang, -}: - -stdenv.mkDerivation ( - swift._wrapperParams - // { - pname = "swift-wrapper"; - inherit (swift) version meta; - - outputs = [ - "out" - "man" - ]; - - # Wrapper and setup hook variables. - inherit swift; - inherit (swift) - swiftOs - swiftArch - swiftModuleSubdir - swiftLibSubdir - swiftStaticModuleSubdir - swiftStaticLibSubdir - ; - swiftDriver = lib.optionalString useSwiftDriver "${swift-driver}/bin/swift-driver"; - cc_wrapper = clang.override (prev: { - extraBuildCommands = - prev.extraBuildCommands - # We need to use the resource directory corresponding to Swift’s - # version of Clang instead of passing along the one from the - # `cc-wrapper` flags. - + '' - rm -r $out/resource-root - substituteInPlace $out/nix-support/cc-cflags \ - --replace-fail \ - "-resource-dir=$out/resource-root" \ - "-resource-dir=${lib.getLib swift}/lib/swift/clang" - '' - + - lib.optionalString - ( - stdenv.targetPlatform.isLinux - && stdenv.targetPlatform.isx86 - && lib.versionAtLeast (lib.getVersion clang) "19.1" - ) - '' - # Swift bundles Clang 16, which predates -mtls-dialect=gnu2 - # support (added in Clang 19.1). The cc-wrapper adds it based - # on the system Clang version, so strip it here. - substituteInPlace $out/nix-support/add-local-cc-cflags-before.sh \ - --replace-fail "'-mtls-dialect=gnu2'" "" - '' - # We need the libc++ headers corresponding to the LLVM version of - # Swift’s Clang. - + lib.optionalString (clang.libcxx != null) '' - include -isystem "${lib.getDev swift}/include/c++/v1" > $out/nix-support/libcxx-cxxflags - ''; - }); - - env.darwinMinVersion = lib.optionalString stdenv.targetPlatform.isDarwin ( - stdenv.targetPlatform.darwinMinVersion - ); - - buildCommand = '' - mkdir -p $out/bin $out/nix-support - - # Symlink all Swift binaries first. - # NOTE: This specifically omits clang binaries. We want to hide these for - # private use by Swift only. - ln -s -t $out/bin/ $swift/bin/swift* - - # Replace specific binaries with wrappers. - for executable in swift swiftc swift-frontend; do - export prog=$swift/bin/$executable - rm $out/bin/$executable - substituteAll '${./wrapper.sh}' $out/bin/$executable - chmod a+x $out/bin/$executable - done - - ${lib.optionalString useSwiftDriver '' - # Symlink swift-driver executables. - ln -s -t $out/bin/ ${swift-driver}/bin/* - ''} - - ln -s ${swift.man} $man - - # This link is here because various tools (swiftpm) check for stdlib - # relative to the swift compiler. It's fine if this is for build-time - # stuff, but we should patch all cases were it would end up in an output. - ln -s ${swift.lib}/lib $out/lib - - substituteAll ${./setup-hook.sh} $out/nix-support/setup-hook - - # Propagate any propagated inputs from the unwrapped Swift compiler, if any. - if [ -e "$swift/nix-support" ]; then - for input in "$swift/nix-support/"*propagated*; do - cp "$input" "$out/nix-support/$(basename "$input")" - done - fi - ''; - - passthru = { - inherit swift; - inherit (swift) - swiftOs - swiftArch - swiftModuleSubdir - swiftLibSubdir - tests - ; - }; - } -) diff --git a/pkgs/development/compilers/swift/wrapper/setup-hook.sh b/pkgs/development/compilers/swift/wrapper/setup-hook.sh deleted file mode 100644 index 398f19977f66..000000000000 --- a/pkgs/development/compilers/swift/wrapper/setup-hook.sh +++ /dev/null @@ -1,28 +0,0 @@ -# Add import paths for build inputs. -swiftWrapper_addImports () { - # Include subdirectories following both the Swift platform convention, and - # a simple `lib/swift` for Nix convenience. - for subdir in @swiftModuleSubdir@ @swiftStaticModuleSubdir@ lib/swift; do - if [[ -d "$1/$subdir" ]]; then - export NIX_SWIFTFLAGS_COMPILE+=" -I $1/$subdir" - fi - done - for subdir in @swiftLibSubdir@ @swiftStaticLibSubdir@ lib/swift; do - if [[ -d "$1/$subdir" ]]; then - export NIX_LDFLAGS+=" -L $1/$subdir" - fi - done -} - -addEnvHooks "$targetOffset" swiftWrapper_addImports - -# Use a postHook here because we rely on NIX_CC, which is set by the cc-wrapper -# setup hook, so delay until we're sure it was run. -swiftWrapper_postHook () { - # On Darwin, libc also contains Swift modules. - if [[ -e "$NIX_CC/nix-support/orig-libc" ]]; then - swiftWrapper_addImports "$(<$NIX_CC/nix-support/orig-libc)" - fi -} - -postHooks+=(swiftWrapper_postHook) diff --git a/pkgs/development/compilers/swift/wrapper/wrapper.sh b/pkgs/development/compilers/swift/wrapper/wrapper.sh deleted file mode 100644 index 77f7c31d6812..000000000000 --- a/pkgs/development/compilers/swift/wrapper/wrapper.sh +++ /dev/null @@ -1,313 +0,0 @@ -#! @shell@ -# NOTE: This wrapper is derived from cc-wrapper.sh, and is hopefully somewhat -# diffable with the original, so changes can be merged if necessary. -set -eu -o pipefail +o posix -shopt -s nullglob - -if (( "${NIX_DEBUG:-0}" >= 7 )); then - set -x -fi - -cc_wrapper="@cc_wrapper@" - -source $cc_wrapper/nix-support/utils.bash - -source $cc_wrapper/nix-support/darwin-sdk-setup.bash - -expandResponseParams "$@" - -# Check if we should wrap this Swift invocation at all, and how. Specifically, -# there are some internal tools we don't wrap, plus swift-frontend doesn't link -# and doesn't understand linker flags. This follows logic in -# `lib/DriverTool/driver.cpp`. -prog=@prog@ -progName="$(basename "$prog")" -firstArg="${params[0]:-}" -isFrontend=0 -isRepl=0 - -# These checks follow `shouldRunAsSubcommand`. -if [[ "$progName" == swift ]]; then - case "$firstArg" in - "" | -* | *.* | */* | repl) - ;; - *) - exec "swift-$firstArg" "${params[@]:1}" - ;; - esac -fi - -# These checks follow the first part of `run_driver`. -# -# NOTE: The original function short-circuits, but we can't here, because both -# paths must be wrapped. So we use an 'isFrontend' flag instead. -case "$firstArg" in - -frontend) - isFrontend=1 - # Ensure this stays the first argument. - params=( "${params[@]:1}" ) - extraBefore+=( "-frontend" ) - ;; - -modulewrap) - # Don't wrap this integrated tool. - exec "$prog" "${params[@]}" - ;; - repl) - isRepl=1 - params=( "${params[@]:1}" ) - ;; - --driver-mode=*) - ;; - *) - if [[ "$progName" == swift-frontend ]]; then - isFrontend=1 - fi - ;; -esac - -# For many tasks, Swift reinvokes swift-driver, the new driver implementation -# written in Swift. It needs some help finding the executable, though, and -# reimplementing the logic here is little effort. These checks follow -# `shouldDisallowNewDriver`. -if [[ - $isFrontend = 0 && - -n "@swiftDriver@" && - -z "${SWIFT_USE_OLD_DRIVER:-}" && - ( "$progName" == "swift" || "$progName" == "swiftc" ) -]]; then - prog=@swiftDriver@ - # Driver mode must be the very first argument. - extraBefore+=( "--driver-mode=$progName" ) - if [[ $isRepl = 1 ]]; then - extraBefore+=( "-repl" ) - fi - - # Ensure swift-driver invokes the unwrapped frontend (instead of finding - # the wrapped one via PATH), because we don't have to wrap a second time. - export SWIFT_DRIVER_SWIFT_FRONTEND_EXEC="@swift@/bin/swift-frontend" - - # Ensure swift-driver can find the LLDB with Swift support for the REPL. - export SWIFT_DRIVER_LLDB_EXEC="@swift@/bin/lldb" -fi - -path_backup="$PATH" - -# That @-vars are substituted separately from bash evaluation makes -# shellcheck think this, and others like it, are useless conditionals. -# shellcheck disable=SC2157 -if [[ -n "@coreutils_bin@" && -n "@gnugrep_bin@" ]]; then - PATH="@coreutils_bin@/bin:@gnugrep_bin@/bin" -fi - -# Parse command line options and set several variables. -# For instance, figure out if linker flags should be passed. -# GCC prints annoying warnings when they are not needed. -isCxx=0 -dontLink=$isFrontend - -for p in "${params[@]}"; do - case "$p" in - -cxx-interoperability-mode=default | -enable-cxx-interop | -enable-experimental-cxx-interop) - isCxx=1 ;; - esac -done - -# NOTE: We don't modify these for Swift, but sourced scripts may use them. -cxxInclude=1 -cxxLibrary=1 -cInclude=1 - -linkType=$(checkLinkType "${params[@]}") - -# Optionally filter out paths not refering to the store. -if [[ "${NIX_ENFORCE_PURITY:-}" = 1 && -n "$NIX_STORE" ]]; then - kept=() - nParams=${#params[@]} - declare -i n=0 - while (( "$n" < "$nParams" )); do - p=${params[n]} - p2=${params[n+1]:-} # handle `p` being last one - n+=1 - - skipNext=false - path="" - case "$p" in - -[IL]/*) path=${p:2} ;; - -[IL]) path=$p2 skipNext=true ;; - esac - - if [[ -n $path ]] && badPath "$path"; then - skip "$path" - $skipNext && n+=1 - continue - fi - - kept+=("$p") - done - # Old bash empty array hack - params=(${kept+"${kept[@]}"}) -fi - -# Flirting with a layer violation here. -if [ -z "${NIX_BINTOOLS_WRAPPER_FLAGS_SET_@suffixSalt@:-}" ]; then - source @bintools@/nix-support/add-flags.sh -fi - -# Put this one second so libc ldflags take priority. -if [ -z "${NIX_CC_WRAPPER_FLAGS_SET_@suffixSalt@:-}" ]; then - source $cc_wrapper/nix-support/add-flags.sh -fi - -# Only add darwin min version flag and set up `DEVELOPER_DIR` if a default darwin min version is set, -# which is a signal that we're targeting darwin. (Copied from add-flags in libc but tailored for Swift). -if [ "@darwinMinVersion@" ]; then - # Make sure the wrapped Swift compiler can find the overlays in the SDK. - NIX_SWIFTFLAGS_COMPILE+=" -I $SDKROOT/usr/lib/swift" - NIX_LDFLAGS_@suffixSalt@+=" -L $SDKROOT/usr/lib/swift" -fi - -if [[ "$isCxx" = 1 ]]; then - if [[ "$cxxInclude" = 1 ]]; then - NIX_CFLAGS_COMPILE_@suffixSalt@+=" $NIX_CXXSTDLIB_COMPILE_@suffixSalt@" - fi - if [[ "$cxxLibrary" = 1 ]]; then - NIX_CFLAGS_LINK_@suffixSalt@+=" $NIX_CXXSTDLIB_LINK_@suffixSalt@" - fi -fi - -source $cc_wrapper/nix-support/add-hardening.sh - -# Add the flags for the C compiler proper. -addCFlagsToList() { - declare -n list="$1" - shift - - for ((i = 1; i <= $#; i++)); do - local val="${!i}" - case "$val" in - # Pass through using -Xcc, but also convert to Swift -I. - # These have slightly different meaning for Clang, but Swift - # doesn't have exact equivalents. - -isystem | -cxx-isystem | -idirafter) - i=$((i + 1)) - list+=("-Xcc" "$val" "-Xcc" "${!i}" "-I" "${!i}") - ;; - # Simple rename. - -iframework) - i=$((i + 1)) - list+=("-Fsystem" "${!i}") - ;; - # Pass through verbatim. - -I | -Fsystem) - i=$((i + 1)) - list+=("${val}" "${!i}") - ;; - -I* | -L* | -F*) - list+=("${val}") - ;; - # Pass through using -Xcc. - *) - list+=("-Xcc" "$val") - ;; - esac - done -} -for i in ${NIX_SWIFTFLAGS_COMPILE:-}; do - extraAfter+=("$i") -done -for i in ${NIX_SWIFTFLAGS_COMPILE_BEFORE:-}; do - extraBefore+=("$i") -done -addCFlagsToList extraAfter $NIX_CFLAGS_COMPILE_@suffixSalt@ -addCFlagsToList extraBefore ${hardeningCFlags[@]+"${hardeningCFlags[@]}"} $NIX_CFLAGS_COMPILE_BEFORE_@suffixSalt@ - -if [ "$dontLink" != 1 ]; then - - # Add the flags that should only be passed to the compiler when - # linking. - addCFlagsToList extraAfter $(filterRpathFlags "$linkType" $NIX_CFLAGS_LINK_@suffixSalt@) - - # Add the flags that should be passed to the linker (and prevent - # `ld-wrapper' from adding NIX_LDFLAGS_@suffixSalt@ again). - for i in $(filterRpathFlags "$linkType" $NIX_LDFLAGS_BEFORE_@suffixSalt@); do - extraBefore+=("-Xlinker" "$i") - done - if [[ "$linkType" == dynamic && -n "$NIX_DYNAMIC_LINKER_@suffixSalt@" ]]; then - extraBefore+=("-Xlinker" "-dynamic-linker=$NIX_DYNAMIC_LINKER_@suffixSalt@") - fi - for i in $(filterRpathFlags "$linkType" $NIX_LDFLAGS_@suffixSalt@); do - if [ "${i:0:3}" = -L/ ]; then - extraAfter+=("$i") - else - extraAfter+=("-Xlinker" "$i") - fi - done - export NIX_LINK_TYPE_@suffixSalt@=$linkType -fi - -# TODO: If we ever need to expand functionality of this hook, it may no longer -# be compatible with Swift. Right now, it is only used on Darwin to force -# -target, which also happens to work with Swift. -# As of 369cc5c66b1efdbca2f136aa0055fedca1117304 (#445119), this hook also sets -# the -Werror=unguarded-availability flag, which Swift can't accept. We prefix -# that flag with -Xcc in the for loop below -if [[ -e $cc_wrapper/nix-support/add-local-cc-cflags-before.sh ]]; then - source $cc_wrapper/nix-support/add-local-cc-cflags-before.sh -fi - -for ((i=0; i < ${#extraBefore[@]}; i++));do - case "${extraBefore[i]}" in - -target) - i=$((i + 1)) - # On Darwin only, need to change 'aarch64' to 'arm64'. - extraBefore[i]="${extraBefore[i]/aarch64-apple-/arm64-apple-}" - # On Darwin, Swift requires the triple to be annotated with a version. - # TODO: Assumes macOS. - extraBefore[i]="${extraBefore[i]/-apple-darwin/-apple-macosx${MACOSX_DEPLOYMENT_TARGET:-11.0}}" - ;; - -march=*|-mcpu=*|-mfloat-abi=*|-mfpu=*|-mmode=*|-mthumb|-marm|-mtune=*|-Werror=*) - [[ i -gt 0 && ${extraBefore[i-1]} == -Xcc ]] && continue - extraBefore=( - "${extraBefore[@]:0:i}" - -Xcc - "${extraBefore[@]:i:${#extraBefore[@]}}" - ) - i=$((i + 1)) - ;; - esac -done - -# As a very special hack, if the arguments are just `-v', then don't -# add anything. This is to prevent `gcc -v' (which normally prints -# out the version number and returns exit code 0) from printing out -# `No input files specified' and returning exit code 1. -if [ "$*" = -v ]; then - extraAfter=() - extraBefore=() -fi - -# Optionally print debug info. -if (( "${NIX_DEBUG:-0}" >= 1 )); then - # Old bash workaround, see ld-wrapper for explanation. - echo "extra flags before to $prog:" >&2 - printf " %q\n" ${extraBefore+"${extraBefore[@]}"} >&2 - echo "original flags to $prog:" >&2 - printf " %q\n" ${params+"${params[@]}"} >&2 - echo "extra flags after to $prog:" >&2 - printf " %q\n" ${extraAfter+"${extraAfter[@]}"} >&2 -fi - -PATH="$path_backup" -# Old bash workaround, see above. - -if (( "${NIX_CC_USE_RESPONSE_FILE:-@use_response_file_by_default@}" >= 1 )); then - exec "$prog" @<(printf "%q\n" \ - ${extraBefore+"${extraBefore[@]}"} \ - ${params+"${params[@]}"} \ - ${extraAfter+"${extraAfter[@]}"}) -else - exec "$prog" \ - ${extraBefore+"${extraBefore[@]}"} \ - ${params+"${params[@]}"} \ - ${extraAfter+"${extraAfter[@]}"} -fi diff --git a/pkgs/development/compilers/swift/xctest/default.nix b/pkgs/development/compilers/swift/xctest/default.nix deleted file mode 100644 index 8b8128c206a6..000000000000 --- a/pkgs/development/compilers/swift/xctest/default.nix +++ /dev/null @@ -1,61 +0,0 @@ -{ - lib, - stdenv, - callPackage, - cmake, - ninja, - swift, - Foundation, - DarwinTools, -}: - -let - sources = callPackage ../sources.nix { }; -in -stdenv.mkDerivation { - pname = "swift-corelibs-xctest"; - - inherit (sources) version; - src = sources.swift-corelibs-xctest; - - outputs = [ "out" ]; - - nativeBuildInputs = [ - cmake - ninja - swift - ] - ++ lib.optional stdenv.hostPlatform.isDarwin DarwinTools; # sw_vers - buildInputs = [ Foundation ]; - - postPatch = lib.optionalString stdenv.hostPlatform.isDarwin '' - # On Darwin only, Swift uses arm64 as cpu arch. - substituteInPlace cmake/modules/SwiftSupport.cmake \ - --replace-fail '"aarch64" PARENT_SCOPE' '"arm64" PARENT_SCOPE' - ''; - - preConfigure = '' - # On aarch64-darwin, our minimum target is 11.0, but we can target lower, - # and some dependants require a lower target. Harmless on non-Darwin. - export MACOSX_DEPLOYMENT_TARGET=10.12 - ''; - - cmakeFlags = lib.optional stdenv.hostPlatform.isDarwin "-DUSE_FOUNDATION_FRAMEWORK=ON"; - - postInstall = lib.optionalString stdenv.hostPlatform.isDarwin '' - # Darwin normally uses the Xcode version of XCTest. Installing - # swift-corelibs-xctest is probably not officially supported, but we have - # no alternative. Fix up the installation here. - mv $out/lib/swift/darwin/${swift.swiftArch}/* $out/lib/swift/darwin - rmdir $out/lib/swift/darwin/${swift.swiftArch} - mv $out/lib/swift/darwin $out/lib/swift/${swift.swiftOs} - ''; - - meta = { - description = "Framework for writing unit tests in Swift"; - homepage = "https://github.com/apple/swift-corelibs-xctest"; - platforms = lib.platforms.all; - license = lib.licenses.asl20; - teams = [ lib.teams.swift ]; - }; -} diff --git a/pkgs/development/interpreters/tcl/generic.nix b/pkgs/development/interpreters/tcl/generic.nix index 6099bd14b079..535ac2bd30d0 100644 --- a/pkgs/development/interpreters/tcl/generic.nix +++ b/pkgs/development/interpreters/tcl/generic.nix @@ -196,6 +196,7 @@ stdenv.mkDerivation (finalAttrs: { homepage = "https://www.tcl.tk/"; license = lib.licenses.tcltk; platforms = lib.platforms.all; + mainProgram = "tclsh"; maintainers = with lib.maintainers; [ agbrooks ]; }; @@ -222,7 +223,9 @@ stdenv.mkDerivation (finalAttrs: { { buildPackages }: makeSetupHook { name = "tcl-requires-check-hook"; - propagatedBuildInputs = [ buildPackages.makeBinaryWrapper ]; + substitutions = { + tcl_hook = ./tcl-requires-check-hook.tcl; + }; meta = { inherit (finalAttrs.meta) maintainers platforms; license = lib.licenses.mit; diff --git a/pkgs/development/interpreters/tcl/tcl-requires-check-hook.sh b/pkgs/development/interpreters/tcl/tcl-requires-check-hook.sh index 76c5901f2a33..6e3066d03b48 100644 --- a/pkgs/development/interpreters/tcl/tcl-requires-check-hook.sh +++ b/pkgs/development/interpreters/tcl/tcl-requires-check-hook.sh @@ -6,27 +6,8 @@ tclRequiresCheckPhase () { if [ -n "$tclRequiresCheck" ]; then export TCLLIBPATH="$out/lib $TCLLIBPATH" # Redundant if tcl-package-hook is also used - tclsh <<'EOF' - if {[info exists env(NIX_ATTRS_JSON_FILE)]} { - set nix_attrs_json_file [open $env(NIX_ATTRS_JSON_FILE)] - set nix_attrs_json [read $nix_attrs_json_file] - close $nix_attrs_json_file - # Normally we'd use one of tcllib/tdom/rl_json/yajl-tcl to parse JSON, - # however we don't want to introduce a circular dependency, - # so we rely on the JSON capabilities of the builtin sqlite package - # https://wiki.tcl-lang.org/page/SQLite+extension+JSON1 - package require sqlite3 - sqlite3 db :memory: -readonly 1 - set packages_to_check [db eval { - select value from json_each(jsonb_extract($nix_attrs_json, '$.tclRequiresCheck')) - }] - db close - } else { - set packages_to_check $env(tclRequiresCheck) - } - puts "Check whether the following packages can be required: $packages_to_check" - exit [catch {foreach pkg $packages_to_check {package require $pkg}}] -EOF + # FIXME: For some reason the output gets swallowed unless we pipe it through cat‽ + tclsh @tcl_hook@ 2>&1 | cat fi } diff --git a/pkgs/development/interpreters/tcl/tcl-requires-check-hook.tcl b/pkgs/development/interpreters/tcl/tcl-requires-check-hook.tcl new file mode 100644 index 000000000000..ee373586144a --- /dev/null +++ b/pkgs/development/interpreters/tcl/tcl-requires-check-hook.tcl @@ -0,0 +1,20 @@ +#!/usr/bin/env tclsh +if {[info exists env(NIX_ATTRS_JSON_FILE)]} { + set nix_attrs_json_file [open $env(NIX_ATTRS_JSON_FILE)] + set nix_attrs_json [read $nix_attrs_json_file] + close $nix_attrs_json_file + # Normally we'd use one of tcllib/tdom/rl_json/yajl-tcl to parse JSON, + # however we don't want to introduce a circular dependency, + # so we rely on the JSON capabilities of the builtin sqlite package + # https://wiki.tcl-lang.org/page/SQLite+extension+JSON1 + package require sqlite3 + sqlite3 db :memory: -readonly 1 + set packages_to_check [db eval { + select value from json_each(jsonb_extract($nix_attrs_json, '$.tclRequiresCheck')) + }] + db close +} else { + set packages_to_check $env(tclRequiresCheck) +} +puts "Check whether the following packages can be required: $packages_to_check" +foreach pkg $packages_to_check {package require $pkg} diff --git a/pkgs/development/libraries/db/generic.nix b/pkgs/development/libraries/db/generic.nix index 25dc5785f6e0..367a244cee1c 100644 --- a/pkgs/development/libraries/db/generic.nix +++ b/pkgs/development/libraries/db/generic.nix @@ -31,6 +31,8 @@ stdenv.mkDerivation ( # which causes configure checks to work incorrectly with clang 16. nativeBuildInputs = lib.optionals stdenv.cc.isClang [ autoconf269 ] ++ [ autoreconfHook ]; + strictDeps = true; + patches = [ (fetchpatch { name = "gcc15.patch"; @@ -112,6 +114,8 @@ stdenv.mkDerivation ( make examples_c examples_cxx ''; + __structuredAttrs = true; + meta = { homepage = "https://www.oracle.com/database/technologies/related/berkeleydb.html"; description = "Berkeley DB"; diff --git a/pkgs/development/libraries/glibc/0001-Revert-Remove-all-usage-of-BASH-or-BASH-in-installed.patch b/pkgs/development/libraries/glibc/0001-Revert-Remove-all-usage-of-BASH-or-BASH-in-installed.patch index 25cb329e086e..d1ea3ad0cdd2 100644 --- a/pkgs/development/libraries/glibc/0001-Revert-Remove-all-usage-of-BASH-or-BASH-in-installed.patch +++ b/pkgs/development/libraries/glibc/0001-Revert-Remove-all-usage-of-BASH-or-BASH-in-installed.patch @@ -1,4 +1,4 @@ -From c1c36f73aa3085a856c7cf36d69c21d18d3ef5ac Mon Sep 17 00:00:00 2001 +From 0ea28d2f38500559734cb0fe99eae40c04783730 Mon Sep 17 00:00:00 2001 From: Bernardo Meurer Date: Fri, 22 Jul 2022 22:11:07 -0700 Subject: [PATCH] Revert "Remove all usage of @BASH@ or ${BASH} in installed @@ -22,10 +22,10 @@ Co-authored-by: Maximilian Bosch 8 files changed, 15 insertions(+), 10 deletions(-) diff --git a/debug/Makefile b/debug/Makefile -index 6a05205ce6..dd63b16ae8 100644 +index c6c1069b40..ccecf6b70b 100644 --- a/debug/Makefile +++ b/debug/Makefile -@@ -345,8 +345,9 @@ $(objpfx)pcprofiledump: $(objpfx)pcprofiledump.o +@@ -407,8 +407,9 @@ $(objpfx)pcprofiledump: $(objpfx)pcprofiledump.o $(objpfx)xtrace: xtrace.sh rm -f $@.new @@ -38,17 +38,17 @@ index 6a05205ce6..dd63b16ae8 100644 && rm -f $@ && mv $@.new $@ && chmod +x $@ diff --git a/debug/xtrace.sh b/debug/xtrace.sh -index 00bafd33db..d0f9fca9a9 100755 +index a1bb50eeaf..01383c7c79 100755 --- a/debug/xtrace.sh +++ b/debug/xtrace.sh @@ -1,4 +1,4 @@ -#!/bin/bash +#! @BASH@ - # Copyright (C) 1999-2025 Free Software Foundation, Inc. + # Copyright (C) 1999-2026 Free Software Foundation, Inc. # This file is part of the GNU C Library. diff --git a/elf/Makefile b/elf/Makefile -index 4b1d0d8741..bbcf688c99 100644 +index d279a5135c..dc39ccea60 100644 --- a/elf/Makefile +++ b/elf/Makefile @@ -250,7 +250,8 @@ $(objpfx)sotruss-lib.so: $(common-objpfx)libc.so $(objpfx)ld.so \ @@ -61,7 +61,7 @@ index 4b1d0d8741..bbcf688c99 100644 -e 's%@TEXTDOMAINDIR@%$(localedir)%g' \ -e 's%@PREFIX@%$(prefix)%g' \ -e 's|@PKGVERSION@|$(PKGVERSION)|g' \ -@@ -1556,6 +1557,7 @@ ldd-rewrite = -e 's%@RTLD@%$(rtlddir)/$(rtld-installed-name)%g' \ +@@ -1720,6 +1721,7 @@ ldd-rewrite = -e 's%@RTLD@%$(rtlddir)/$(rtld-installed-name)%g' \ -e 's%@VERSION@%$(version)%g' \ -e 's|@PKGVERSION@|$(PKGVERSION)|g' \ -e 's|@REPORT_BUGS_TO@|$(REPORT_BUGS_TO)|g' \ @@ -70,30 +70,30 @@ index 4b1d0d8741..bbcf688c99 100644 ifeq ($(ldd-rewrite-script),no) diff --git a/elf/ldd.bash.in b/elf/ldd.bash.in -index 2d3df6e57e..0faf83dc86 100644 +index bfc40f6505..59ca54e2d9 100644 --- a/elf/ldd.bash.in +++ b/elf/ldd.bash.in @@ -1,4 +1,4 @@ -#!/bin/bash +#! @BASH@ - # Copyright (C) 1996-2025 Free Software Foundation, Inc. + # Copyright (C) 1996-2026 Free Software Foundation, Inc. # This file is part of the GNU C Library. diff --git a/elf/sotruss.sh b/elf/sotruss.sh -index 8944645df9..1c36981b22 100755 +index c90abaaed9..03cb25bc57 100755 --- a/elf/sotruss.sh +++ b/elf/sotruss.sh @@ -1,4 +1,4 @@ -#!/bin/bash +#! @BASH@ - # Copyright (C) 2011-2025 Free Software Foundation, Inc. + # Copyright (C) 2011-2026 Free Software Foundation, Inc. # This file is part of the GNU C Library. diff --git a/malloc/Makefile b/malloc/Makefile -index e2b2c1ae1b..67a399f1dd 100644 +index 72aa77af20..e148b6480a 100644 --- a/malloc/Makefile +++ b/malloc/Makefile -@@ -359,8 +359,9 @@ $(objpfx)mtrace: mtrace.pl +@@ -484,8 +484,9 @@ $(objpfx)mtrace: mtrace.pl $(objpfx)memusage: memusage.sh rm -f $@.new @@ -106,20 +106,20 @@ index e2b2c1ae1b..67a399f1dd 100644 && rm -f $@ && mv $@.new $@ && chmod +x $@ diff --git a/malloc/memusage.sh b/malloc/memusage.sh -index 8ae435d2f8..c929d16af7 100755 +index 309991a7c9..28117c4561 100755 --- a/malloc/memusage.sh +++ b/malloc/memusage.sh @@ -1,4 +1,4 @@ -#!/bin/bash +#! @BASH@ - # Copyright (C) 1999-2025 Free Software Foundation, Inc. + # Copyright (C) 1999-2026 Free Software Foundation, Inc. # This file is part of the GNU C Library. diff --git a/timezone/Makefile b/timezone/Makefile -index ebe5cf73a1..e9cf92861c 100644 +index ce9abe6cb2..3ee1eed54a 100644 --- a/timezone/Makefile +++ b/timezone/Makefile -@@ -139,7 +139,8 @@ $(testdata)/XT5: testdata/gen-XT5.sh +@@ -136,7 +136,8 @@ $(testdata)/XT5: testdata/gen-XT5.sh mv $@.tmp $@ $(objpfx)tzselect: tzselect.ksh $(common-objpfx)config.make @@ -130,5 +130,5 @@ index ebe5cf73a1..e9cf92861c 100644 -e '/PKGVERSION=/s|=.*|="$(PKGVERSION)"|' \ -e '/REPORT_BUGS_TO=/s|=.*|="$(REPORT_BUGS_TO)"|' \ -- -2.47.2 +2.54.0 diff --git a/pkgs/development/libraries/glibc/2.42-master.patch b/pkgs/development/libraries/glibc/2.42-master.patch deleted file mode 100644 index 8abd567ee32b..000000000000 --- a/pkgs/development/libraries/glibc/2.42-master.patch +++ /dev/null @@ -1,11174 +0,0 @@ -commit bdea6c37197a3c9bd976911cce5f580dea1c28dd -Author: Andreas K. Hüttel -Date: Mon Jul 28 20:35:38 2025 +0200 - - Replace advisories directory with pointer file - - Signed-off-by: Andreas K. Hüttel - -diff --git a/advisories/GLIBC-SA-2023-0001 b/advisories/GLIBC-SA-2023-0001 -deleted file mode 100644 -index 3d19c91b6a..0000000000 ---- a/advisories/GLIBC-SA-2023-0001 -+++ /dev/null -@@ -1,14 +0,0 @@ --printf: incorrect output for integers with thousands separator and width field -- --When the printf family of functions is called with a format specifier --that uses an (enable grouping) and a minimum width --specifier, the resulting output could be larger than reasonably expected --by a caller that computed a tight bound on the buffer size. The --resulting larger than expected output could result in a buffer overflow --in the printf family of functions. -- --CVE-Id: CVE-2023-25139 --Public-Date: 2023-02-02 --Vulnerable-Commit: e88b9f0e5cc50cab57a299dc7efe1a4eb385161d (2.37) --Fix-Commit: c980549cc6a1c03c23cc2fe3e7b0fe626a0364b0 (2.38) --Fix-Commit: 07b9521fc6369d000216b96562ff7c0ed32a16c4 (2.37-4) -diff --git a/advisories/GLIBC-SA-2023-0002 b/advisories/GLIBC-SA-2023-0002 -deleted file mode 100644 -index 5122669a64..0000000000 ---- a/advisories/GLIBC-SA-2023-0002 -+++ /dev/null -@@ -1,15 +0,0 @@ --getaddrinfo: Stack read overflow in no-aaaa mode -- --If the system is configured in no-aaaa mode via /etc/resolv.conf, --getaddrinfo is called for the AF_UNSPEC address family, and a DNS --response is received over TCP that is larger than 2048 bytes, --getaddrinfo may potentially disclose stack contents via the returned --address data, or crash. -- --CVE-Id: CVE-2023-4527 --Public-Date: 2023-09-12 --Vulnerable-Commit: f282cdbe7f436c75864e5640a409a10485e9abb2 (2.36) --Fix-Commit: bd77dd7e73e3530203be1c52c8a29d08270cb25d (2.39) --Fix-Commit: 4ea972b7edd7e36610e8cde18bf7a8149d7bac4f (2.36-113) --Fix-Commit: b7529346025a130fee483d42178b5c118da971bb (2.37-38) --Fix-Commit: b25508dd774b617f99419bdc3cf2ace4560cd2d6 (2.38-19) -diff --git a/advisories/GLIBC-SA-2023-0003 b/advisories/GLIBC-SA-2023-0003 -deleted file mode 100644 -index d3aef80348..0000000000 ---- a/advisories/GLIBC-SA-2023-0003 -+++ /dev/null -@@ -1,15 +0,0 @@ --getaddrinfo: Potential use-after-free -- --When an NSS plugin only implements the _gethostbyname2_r and --_getcanonname_r callbacks, getaddrinfo could use memory that was freed --during buffer resizing, potentially causing a crash or read or write to --arbitrary memory. -- --CVE-Id: CVE-2023-4806 --Public-Date: 2023-09-12 --Fix-Commit: 973fe93a5675c42798b2161c6f29c01b0e243994 (2.39) --Fix-Commit: e09ee267c03e3150c2c9ba28625ab130705a485e (2.34-420) --Fix-Commit: e3ccb230a961b4797510e6a1f5f21fd9021853e7 (2.35-270) --Fix-Commit: a9728f798ec7f05454c95637ee6581afaa9b487d (2.36-115) --Fix-Commit: 6529a7466c935f36e9006b854d6f4e1d4876f942 (2.37-39) --Fix-Commit: 00ae4f10b504bc4564e9f22f00907093f1ab9338 (2.38-20) -diff --git a/advisories/GLIBC-SA-2023-0004 b/advisories/GLIBC-SA-2023-0004 -deleted file mode 100644 -index 5286a7aa54..0000000000 ---- a/advisories/GLIBC-SA-2023-0004 -+++ /dev/null -@@ -1,16 +0,0 @@ --tunables: local privilege escalation through buffer overflow -- --If a tunable of the form NAME=NAME=VAL is passed in the environment of a --setuid program and NAME is valid, it may result in a buffer overflow, --which could be exploited to achieve escalated privileges. This flaw was --introduced in glibc 2.34. -- --CVE-Id: CVE-2023-4911 --Public-Date: 2023-10-03 --Vulnerable-Commit: 2ed18c5b534d9e92fc006202a5af0df6b72e7aca (2.34) --Fix-Commit: 1056e5b4c3f2d90ed2b4a55f96add28da2f4c8fa (2.39) --Fix-Commit: dcc367f148bc92e7f3778a125f7a416b093964d9 (2.34-423) --Fix-Commit: c84018a05aec80f5ee6f682db0da1130b0196aef (2.35-274) --Fix-Commit: 22955ad85186ee05834e47e665056148ca07699c (2.36-118) --Fix-Commit: b4e23c75aea756b4bddc4abcf27a1c6dca8b6bd3 (2.37-45) --Fix-Commit: 750a45a783906a19591fb8ff6b7841470f1f5701 (2.38-27) -diff --git a/advisories/GLIBC-SA-2023-0005 b/advisories/GLIBC-SA-2023-0005 -deleted file mode 100644 -index cc4eb90b82..0000000000 ---- a/advisories/GLIBC-SA-2023-0005 -+++ /dev/null -@@ -1,18 +0,0 @@ --getaddrinfo: DoS due to memory leak -- --The fix for CVE-2023-4806 introduced a memory leak when an application --calls getaddrinfo for AF_INET6 with AI_CANONNAME, AI_ALL and AI_V4MAPPED --flags set. -- --CVE-Id: CVE-2023-5156 --Public-Date: 2023-09-25 --Vulnerable-Commit: e09ee267c03e3150c2c9ba28625ab130705a485e (2.34-420) --Vulnerable-Commit: e3ccb230a961b4797510e6a1f5f21fd9021853e7 (2.35-270) --Vulnerable-Commit: a9728f798ec7f05454c95637ee6581afaa9b487d (2.36-115) --Vulnerable-Commit: 6529a7466c935f36e9006b854d6f4e1d4876f942 (2.37-39) --Vulnerable-Commit: 00ae4f10b504bc4564e9f22f00907093f1ab9338 (2.38-20) --Fix-Commit: 8006457ab7e1cd556b919f477348a96fe88f2e49 (2.34-421) --Fix-Commit: 17092c0311f954e6f3c010f73ce3a78c24ac279a (2.35-272) --Fix-Commit: 856bac55f98dc840e7c27cfa82262b933385de90 (2.36-116) --Fix-Commit: 4473d1b87d04b25cdd0e0354814eeaa421328268 (2.37-42) --Fix-Commit: 5ee59ca371b99984232d7584fe2b1a758b4421d3 (2.38-24) -diff --git a/advisories/GLIBC-SA-2024-0001 b/advisories/GLIBC-SA-2024-0001 -deleted file mode 100644 -index 28931c75ae..0000000000 ---- a/advisories/GLIBC-SA-2024-0001 -+++ /dev/null -@@ -1,15 +0,0 @@ --syslog: Heap buffer overflow in __vsyslog_internal -- --__vsyslog_internal did not handle a case where printing a SYSLOG_HEADER --containing a long program name failed to update the required buffer --size, leading to the allocation and overflow of a too-small buffer on --the heap. -- --CVE-Id: CVE-2023-6246 --Public-Date: 2024-01-30 --Vulnerable-Commit: 52a5be0df411ef3ff45c10c7c308cb92993d15b1 (2.37) --Fix-Commit: 6bd0e4efcc78f3c0115e5ea9739a1642807450da (2.39) --Fix-Commit: 23514c72b780f3da097ecf33a793b7ba9c2070d2 (2.38-42) --Fix-Commit: 97a4292aa4a2642e251472b878d0ec4c46a0e59a (2.37-57) --Vulnerable-Commit: b0e7888d1fa2dbd2d9e1645ec8c796abf78880b9 (2.36-16) --Fix-Commit: d1a83b6767f68b3cb5b4b4ea2617254acd040c82 (2.36-126) -diff --git a/advisories/GLIBC-SA-2024-0002 b/advisories/GLIBC-SA-2024-0002 -deleted file mode 100644 -index 940bfcf2fc..0000000000 ---- a/advisories/GLIBC-SA-2024-0002 -+++ /dev/null -@@ -1,15 +0,0 @@ --syslog: Heap buffer overflow in __vsyslog_internal -- --__vsyslog_internal used the return value of snprintf/vsnprintf to --calculate buffer sizes for memory allocation. If these functions (for --any reason) failed and returned -1, the resulting buffer would be too --small to hold output. -- --CVE-Id: CVE-2023-6779 --Public-Date: 2024-01-30 --Vulnerable-Commit: 52a5be0df411ef3ff45c10c7c308cb92993d15b1 (2.37) --Fix-Commit: 7e5a0c286da33159d47d0122007aac016f3e02cd (2.39) --Fix-Commit: d0338312aace5bbfef85e03055e1212dd0e49578 (2.38-43) --Fix-Commit: 67062eccd9a65d7fda9976a56aeaaf6c25a80214 (2.37-58) --Vulnerable-Commit: b0e7888d1fa2dbd2d9e1645ec8c796abf78880b9 (2.36-16) --Fix-Commit: 2bc9d7c002bdac38b5c2a3f11b78e309d7765b83 (2.36-127) -diff --git a/advisories/GLIBC-SA-2024-0003 b/advisories/GLIBC-SA-2024-0003 -deleted file mode 100644 -index b43a5150ab..0000000000 ---- a/advisories/GLIBC-SA-2024-0003 -+++ /dev/null -@@ -1,13 +0,0 @@ --syslog: Integer overflow in __vsyslog_internal -- --__vsyslog_internal calculated a buffer size by adding two integers, but --did not first check if the addition would overflow. -- --CVE-Id: CVE-2023-6780 --Public-Date: 2024-01-30 --Vulnerable-Commit: 52a5be0df411ef3ff45c10c7c308cb92993d15b1 (2.37) --Fix-Commit: ddf542da94caf97ff43cc2875c88749880b7259b (2.39) --Fix-Commit: d37c2b20a4787463d192b32041c3406c2bd91de0 (2.38-44) --Fix-Commit: 2b58cba076e912961ceaa5fa58588e4b10f791c0 (2.37-59) --Vulnerable-Commit: b0e7888d1fa2dbd2d9e1645ec8c796abf78880b9 (2.36-16) --Fix-Commit: b9b7d6a27aa0632f334352fa400771115b3c69b7 (2.36-128) -diff --git a/advisories/GLIBC-SA-2024-0004 b/advisories/GLIBC-SA-2024-0004 -deleted file mode 100644 -index 08df2b3118..0000000000 ---- a/advisories/GLIBC-SA-2024-0004 -+++ /dev/null -@@ -1,28 +0,0 @@ --ISO-2022-CN-EXT: fix out-of-bound writes when writing escape sequence -- --The iconv() function in the GNU C Library versions 2.39 and older may --overflow the output buffer passed to it by up to 4 bytes when converting --strings to the ISO-2022-CN-EXT character set, which may be used to --crash an application or overwrite a neighbouring variable. -- --ISO-2022-CN-EXT uses escape sequences to indicate character set changes --(as specified by RFC 1922). While the SOdesignation has the expected --bounds checks, neither SS2designation nor SS3designation have its; --allowing a write overflow of 1, 2, or 3 bytes with fixed values: --'$+I', '$+J', '$+K', '$+L', '$+M', or '$*H'. -- --CVE-Id: CVE-2024-2961 --Public-Date: 2024-04-17 --Vulnerable-Commit: 755104edc75c53f4a0e7440334e944ad3c6b32fc (2.1.93-169) --Fix-Commit: f9dc609e06b1136bb0408be9605ce7973a767ada (2.40) --Fix-Commit: 31da30f23cddd36db29d5b6a1c7619361b271fb4 (2.39-31) --Fix-Commit: e1135387deded5d73924f6ca20c72a35dc8e1bda (2.38-66) --Fix-Commit: 89ce64b269a897a7780e4c73a7412016381c6ecf (2.37-89) --Fix-Commit: 4ed98540a7fd19f458287e783ae59c41e64df7b5 (2.36-164) --Fix-Commit: 36280d1ce5e245aabefb877fe4d3c6cff95dabfa (2.35-315) --Fix-Commit: a8b0561db4b9847ebfbfec20075697d5492a363c (2.34-459) --Fix-Commit: ed4f16ff6bed3037266f1fa682ebd32a18fce29c (2.33-263) --Fix-Commit: 682ad4c8623e611a971839990ceef00346289cc9 (2.32-140) --Fix-Commit: 3703c32a8d304c1ee12126134ce69be965f38000 (2.31-154) -- --Reported-By: Charles Fol -diff --git a/advisories/GLIBC-SA-2024-0005 b/advisories/GLIBC-SA-2024-0005 -deleted file mode 100644 -index a59596610a..0000000000 ---- a/advisories/GLIBC-SA-2024-0005 -+++ /dev/null -@@ -1,22 +0,0 @@ --nscd: Stack-based buffer overflow in netgroup cache -- --If the Name Service Cache Daemon's (nscd) fixed size cache is exhausted --by client requests then a subsequent client request for netgroup data --may result in a stack-based buffer overflow. This flaw was introduced --in glibc 2.15 when the cache was added to nscd. -- --This vulnerability is only present in the nscd binary. -- --CVE-Id: CVE-2024-33599 --Public-Date: 2024-04-23 --Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) --Fix-Commit: 69c58d5ef9f584ea198bd00f7964d364d0e6b921 (2.31-155) --Fix-Commit: a77064893bfe8a701770e2f53a4d33805bc47a5a (2.32-141) --Fix-Commit: 5c75001a96abcd50cbdb74df24c3f013188d076e (2.33-264) --Fix-Commit: 52f73e5c4e29b14e79167272297977f360ae1e97 (2.34-460) --Fix-Commit: 7a95873543ce225376faf13bb71c43dea6d24f86 (2.35-316) --Fix-Commit: caa3151ca460bdd9330adeedd68c3112d97bffe4 (2.36-165) --Fix-Commit: f75c298e747b2b8b41b1c2f551c011a52c41bfd1 (2.37-91) --Fix-Commit: 5968aebb86164034b8f8421b4abab2f837a5bdaf (2.38-72) --Fix-Commit: 1263d583d2e28afb8be53f8d6922f0842036f35d (2.39-35) --Fix-Commit: 87801a8fd06db1d654eea3e4f7626ff476a9bdaa (2.40) -diff --git a/advisories/GLIBC-SA-2024-0006 b/advisories/GLIBC-SA-2024-0006 -deleted file mode 100644 -index d44148d3d9..0000000000 ---- a/advisories/GLIBC-SA-2024-0006 -+++ /dev/null -@@ -1,32 +0,0 @@ --nscd: Null pointer crash after notfound response -- --If the Name Service Cache Daemon's (nscd) cache fails to add a not-found --netgroup response to the cache, the client request can result in a null --pointer dereference. This flaw was introduced in glibc 2.15 when the --cache was added to nscd. -- --This vulnerability is only present in the nscd binary. -- --CVE-Id: CVE-2024-33600 --Public-Date: 2024-04-24 --Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) --Fix-Commit: b048a482f088e53144d26a61c390bed0210f49f2 (2.40) --Fix-Commit: 7835b00dbce53c3c87bbbb1754a95fb5e58187aa (2.40) --Fix-Commit: c99f886de54446cd4447db6b44be93dabbdc2f8b (2.39-37) --Fix-Commit: 5a508e0b508c8ad53bd0d2fb48fd71b242626341 (2.39-36) --Fix-Commit: 2ae9446c1b7a3064743b4a51c0bbae668ee43e4c (2.38-74) --Fix-Commit: 541ea5172aa658c4bd5c6c6d6fd13903c3d5bb0a (2.38-73) --Fix-Commit: a8070b31043c7585c36ba68a74298c4f7af075c3 (2.37-93) --Fix-Commit: 5eea50c4402e39588de98aa1d4469a79774703d4 (2.37-92) --Fix-Commit: f205b3af56740e3b014915b1bd3b162afe3407ef (2.36-167) --Fix-Commit: c34f470a615b136170abd16142da5dd0c024f7d1 (2.36-166) --Fix-Commit: bafadc589fbe21ae330e8c2af74db9da44a17660 (2.35-318) --Fix-Commit: 4370bef52b0f3f3652c6aa13d7a9bb3ac079746d (2.35-317) --Fix-Commit: 1f94122289a9bf7dba573f5d60327aaa2b85cf2e (2.34-462) --Fix-Commit: 966d6ac9e40222b84bb21674cc4f83c8d72a5a26 (2.34-461) --Fix-Commit: e3eef1b8fbdd3a7917af466ca9c4b7477251ca79 (2.33-266) --Fix-Commit: f20a8d696b13c6261b52a6434899121f8b19d5a7 (2.33-265) --Fix-Commit: be602180146de37582a3da3a0caa4b719645de9c (2.32-143) --Fix-Commit: 394eae338199078b7961b051c191539870742d7b (2.32-142) --Fix-Commit: 8d7949183760170c61e55def723c1d8050187874 (2.31-157) --Fix-Commit: 304ce5fe466c4762b21b36c26926a4657b59b53e (2.31-156) -diff --git a/advisories/GLIBC-SA-2024-0007 b/advisories/GLIBC-SA-2024-0007 -deleted file mode 100644 -index b6928fa27a..0000000000 ---- a/advisories/GLIBC-SA-2024-0007 -+++ /dev/null -@@ -1,28 +0,0 @@ --nscd: netgroup cache may terminate daemon on memory allocation failure -- --The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or --xrealloc and these functions may terminate the process due to a memory --allocation failure resulting in a denial of service to the clients. The --flaw was introduced in glibc 2.15 when the cache was added to nscd. -- --This vulnerability is only present in the nscd binary. -- --Subsequent refactoring of the netgroup cache only added more uses of --xmalloc and xrealloc. Uses of xmalloc and xrealloc in other parts of --nscd only occur during startup of the daemon and so are not affected by --client requests that could trigger an out of memory followed by --termination. -- --CVE-Id: CVE-2024-33601 --Public-Date: 2024-04-24 --Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) --Fix-Commit: c04a21e050d64a1193a6daab872bca2528bda44b (2.40) --Fix-Commit: a9a8d3eebb145779a18d90e3966009a1daa63cd8 (2.39-38) --Fix-Commit: 71af8ca864345d39b746d5cee84b94b430fad5db (2.38-75) --Fix-Commit: 6e106dc214d6a033a4e945d1c6cf58061f1c5f1f (2.37-94) --Fix-Commit: b6742463694b1dfdd5120b91ee21cf05d15ec2e2 (2.36-168) --Fix-Commit: 7a5864cac60e06000394128a5a2817b03542f5a3 (2.35-319) --Fix-Commit: 86f1d5f4129c373ac6fb6df5bcf38273838843cb (2.34-463) --Fix-Commit: 4d27d4b9a188786fc6a56745506cec2acfc51f83 (2.33-267) --Fix-Commit: 3ed195a8ec89da281e3c4bf887a13d281b72d8f4 (2.32-144) --Fix-Commit: bbf5a58ccb55679217f94de706164d15372fbbc0 (2.31-158) -diff --git a/advisories/GLIBC-SA-2024-0008 b/advisories/GLIBC-SA-2024-0008 -deleted file mode 100644 -index d93e2a6f0b..0000000000 ---- a/advisories/GLIBC-SA-2024-0008 -+++ /dev/null -@@ -1,26 +0,0 @@ --nscd: netgroup cache assumes NSS callback uses in-buffer strings -- --The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory --when the NSS callback does not store all strings in the provided buffer. --The flaw was introduced in glibc 2.15 when the cache was added to nscd. -- --This vulnerability is only present in the nscd binary. -- --There is no guarantee from the NSS callback API that the returned --strings are all within the buffer. However, the netgroup cache code --assumes that the NSS callback uses in-buffer strings and if it doesn't --the buffer resizing logic could lead to potential memory corruption. -- --CVE-Id: CVE-2024-33602 --Public-Date: 2024-04-24 --Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) --Fix-Commit: c04a21e050d64a1193a6daab872bca2528bda44b (2.40) --Fix-Commit: a9a8d3eebb145779a18d90e3966009a1daa63cd8 (2.39-38) --Fix-Commit: 71af8ca864345d39b746d5cee84b94b430fad5db (2.38-75) --Fix-Commit: 6e106dc214d6a033a4e945d1c6cf58061f1c5f1f (2.37-94) --Fix-Commit: b6742463694b1dfdd5120b91ee21cf05d15ec2e2 (2.36-168) --Fix-Commit: 7a5864cac60e06000394128a5a2817b03542f5a3 (2.35-319) --Fix-Commit: 86f1d5f4129c373ac6fb6df5bcf38273838843cb (2.34-463) --Fix-Commit: 4d27d4b9a188786fc6a56745506cec2acfc51f83 (2.33-267) --Fix-Commit: 3ed195a8ec89da281e3c4bf887a13d281b72d8f4 (2.32-144) --Fix-Commit: bbf5a58ccb55679217f94de706164d15372fbbc0 (2.31-158) -diff --git a/advisories/GLIBC-SA-2025-0001 b/advisories/GLIBC-SA-2025-0001 -deleted file mode 100644 -index b053d32e91..0000000000 ---- a/advisories/GLIBC-SA-2025-0001 -+++ /dev/null -@@ -1,40 +0,0 @@ --assert: Buffer overflow when printing assertion failure message -- --When the assert() function fails, it does not allocate enough space for the --assertion failure message string and size information, which may lead to a --buffer overflow if the message string size aligns to page size. -- --This bug can be triggered when an assertion in a program fails. The assertion --failure message is allocated to allow developers to see this failure in core --dumps and it typically includes, in addition to the invariant assertion --string and function name, the name of the program. If the name of the failing --program is user controlled, for example on a local system, this could allow an --attacker to control the assertion failure to trigger this buffer overflow. -- --The only viable vector for exploitation of this bug is local, if a setuid --program exists that has an existing bug that results in an assertion failure. --No such program has been discovered at the time of publishing this advisory, --but the presence of custom setuid programs, although strongly discouraged as a --security practice, cannot be discounted. -- --CVE-Id: CVE-2025-0395 --Public-Date: 2025-01-22 --Vulnerable-Commit: f8a3b5bf8fa1d0c43d2458e03cc109a04fdef194 (2.13-175) --Fix-Commit: 68ee0f704cb81e9ad0a78c644a83e1e9cd2ee578 (2.41) --Fix-Commit: cdb9ba84191ce72e86346fb8b1d906e7cd930ea2 (2.42) --Fix-Commit: 69fda28279b497bd405fdd442a6d8e4d3d5f681b (2.41-7) --Fix-Commit: 7d4b6bcae91f29d7b4daf15bab06b66cf1d2217c (2.40-66) --Fix-Commit: d6c156c326999f144cb5b73d29982108d549ad8a (2.40-71) --Fix-Commit: 808a84a8b81468b517a4d721fdc62069cb8c211f (2.39-146) --Fix-Commit: f6d48470aef9264d2d56f4c4533eb76db7f9c2e4 (2.39-150) --Fix-Commit: c32fd59314c343db88c3ea4a203870481d33c3d2 (2.38-122) --Fix-Commit: f984e2d7e8299726891a1a497a3c36cd5542a0bf (2.38-124) --Fix-Commit: a3d7865b098a3a67c44f7812208d9ce4718873ba (2.37-143) --Fix-Commit: b989519fe1683c204ac24ec92830e3fe3bfaccad (2.37-146) --Fix-Commit: 7971add7ee4171fdd8dfd17e7c04c4ed77a18845 (2.36-216) --Fix-Commit: 0487893d5c5bc6710d83d7c3152d888a0339559e (2.36-219) --Fix-Commit: 8b5d4be762419c4f6176261c6fea40ac559b88dc (2.35-370) --Fix-Commit: 8b3d09dc0d350191985f9d291cc30ce96f034b49 (2.35-373) --Fix-Commit: df4e1f4a5096b385c9bcc94424cf2eaa227b3761 (2.34-500) --Fix-Commit: 31eb872cb21449832ab47ad5db83281d240e1d03 (2.34-503) --Reported-By: Qualys Security Advisory -diff --git a/advisories/GLIBC-SA-2025-0002 b/advisories/GLIBC-SA-2025-0002 -deleted file mode 100644 -index 161da13dd4..0000000000 ---- a/advisories/GLIBC-SA-2025-0002 -+++ /dev/null -@@ -1,23 +0,0 @@ --elf: static setuid binary dlopen may incorrectly search LD_LIBRARY_PATH -- --A statically linked setuid binary that calls dlopen (including internal --dlopen calls after setlocale or calls to NSS functions such as getaddrinfo) --may incorrectly search LD_LIBRARY_PATH to determine which library to load, --leading to the execution of library code that is attacker controlled. -- --The only viable vector for exploitation of this bug is local, if a static --setuid program exists, and that program calls dlopen, then it may search --LD_LIBRARY_PATH to locate the SONAME to load. No such program has been --discovered at the time of publishing this advisory, but the presence of --custom setuid programs, although strongly discouraged as a security --practice, cannot be discounted. -- --CVE-Id: CVE-2025-4802 --Public-Date: 2025-05-16 --Vulnerable-Commit: 10e93d968716ab82931d593bada121c17c0a4b93 (2.27) --Fix-Commit: 5451fa962cd0a90a0e2ec1d8910a559ace02bba0 (2.39) --Fix-Commit: 3be3728df2f1912c80abd3288bc6e3a25ad679e4 (2.38-132) --Fix-Commit: 7403ede2d7752e59e0c47d5d33d73c2bf850e7be (2.37-154) --Fix-Commit: 2ef7850279b2931caf6d6d6743ebaa91839e1cf7 (2.36-227) --Fix-Commit: 621c65ccf12ddd415ceeb2234423bd1acd0fabb3 (2.35-387) --Fix-Commit: 35018c0fd20eac9ceaf60060fed2745b3177359d (2.34-517) -diff --git a/advisories/GLIBC-SA-2025-0003 b/advisories/GLIBC-SA-2025-0003 -deleted file mode 100644 -index 2adeb3ce00..0000000000 ---- a/advisories/GLIBC-SA-2025-0003 -+++ /dev/null -@@ -1,30 +0,0 @@ --power10: strcmp fails to save and restore nonvolatile vector registers -- --The Power 10 implementation of strcmp in --sysdeps/powerpc/powerpc64/le/power10/strcmp.S failed to save/restore --nonvolatile vector registers in the 32-byte aligned loop path. This --results in callers reading content from those registers in a different --context, potentially altering program logic. -- --There could be a program context where a user controlled string could --leak through strcmp into program code, thus altering its logic. There --is also a potential for sensitive strings passed into strcmp leaking --through the clobbered registers into parts of the calling program that --should otherwise not have had access to those strings. -- --The impact of this flaw is limited to applications running on Power 10 --hardware that use the nonvolatile vector registers, i.e. v20 to v31 --assuming that they have been treated in accordance with the OpenPower --psABI. It is possible to work around the issue for those specific --applications by setting the glibc.cpu.hwcaps tunable to "-arch_3_1" like --so: -- -- export GLIBC_TUNABLES=glibc.cpu.hwcaps=-arch_3_1 -- --CVE-Id: CVE-2025-5702 --Public-Date: 2025-06-04 --Vulnerable-Commit: 3367d8e180848030d1646f088759f02b8dfe0d6f (2.39) --Fix-Commit: 15808c77b35319e67ee0dc8f984a9a1a434701bc (2.42) --Fix-Commit: 0c76c951620f9e12df2a89b2c684878b55bb6795 (2.41-60) --Fix-Commit: 7e12550b8e3a11764a4a9090ce6bd3fc23fc8a8e (2.40-139) --Fix-Commit: 06a70769fd0b2e1f2a3085ad50ab620282bd77b3 (2.39-209) -diff --git a/advisories/GLIBC-SA-2025-0004 b/advisories/GLIBC-SA-2025-0004 -deleted file mode 100644 -index 9409ca27c4..0000000000 ---- a/advisories/GLIBC-SA-2025-0004 -+++ /dev/null -@@ -1,29 +0,0 @@ --power10: strncmp fails to save and restore nonvolatile vector registers -- --The Power 10 implementation of strncmp in --sysdeps/powerpc/powerpc64/le/power10/strncmp.S failed to save/restore --nonvolatile vector registers in the 32-byte aligned loop path. This --results in callers reading content from those registers in a different --context, potentially altering program logic. -- --There could be a program context where a user controlled string could --leak through strncmp into program code, thus altering its logic. There --is also a potential for sensitive strings passed into strncmp leaking --through the clobbered registers into parts of the calling program that --should otherwise not have had access to those strings. -- --The impact of this flaw is limited to applications running on Power 10 --hardware that use the nonvolatile vector registers, i.e. v20 to v31 --assuming that they have been treated in accordance with the OpenPower --psABI. It is possible to work around the issue for those specific --applications by setting the glibc.cpu.hwcaps tunable to "-arch_3_1" like --so: -- -- export GLIBC_TUNABLES=glibc.cpu.hwcaps=-arch_3_1 -- --CVE-Id: CVE-2025-5745 --Public-Date: 2025-06-05 --Vulnerable-Commit: 23f0d81608d0ca6379894ef81670cf30af7fd081 (2.40) --Fix-Commit: 63c60101ce7c5eac42be90f698ba02099b41b965 (2.42) --Fix-Commit: 84bdbf8a6f2fdafd3661489dbb7f79835a52da82 (2.41-57) --Fix-Commit: 42a5a940c974d02540c8da26d6374c744d148cb9 (2.40-136) -diff --git a/advisories/GLIBC-SA-2025-0005 b/advisories/GLIBC-SA-2025-0005 -deleted file mode 100644 -index 8bcccc59a5..0000000000 ---- a/advisories/GLIBC-SA-2025-0005 -+++ /dev/null -@@ -1,14 +0,0 @@ --posix: Fix double-free after allocation failure in regcomp -- --The regcomp function in the GNU C library version from 2.4 to 2.41 is --subject to a double free if some previous allocation fails. It can be --accomplished either by a malloc failure or by using an interposed --malloc that injects random malloc failures. The double free can allow --buffer manipulation depending of how the regex is constructed. --This issue affects all architectures and ABIs supported by the GNU C --library. -- --CVE-Id: CVE-2025-8058 --Public-Date: 2025-07-22 --Vulnerable-Commit: 963d8d782fc98fb6dc3a66f0068795f9920c269d (2.3.3-1596) --Fix-Commit: 7ea06e994093fa0bcca0d0ee2c1db271d8d7885d (2.42) -diff --git a/advisories/README b/advisories/README -deleted file mode 100644 -index b8f8a829ca..0000000000 ---- a/advisories/README -+++ /dev/null -@@ -1,77 +0,0 @@ --GNU C Library Security Advisory Format --====================================== -- --Security advisories in this directory follow a simple git commit log --format, with a heading and free-format description augmented with tags --to allow parsing key information. References to code changes are --specific to the glibc repository and follow a specific format: -- -- Tag-name: (release-version) -- --The indicates a specific commit in the repository. The --release-version indicates the publicly consumable release in which this --commit is known to exist. The release-version is derived from the --git-describe format, (i.e. stripped out from glibc-2.34.NNN-gxxxx) and --is of the form 2.34-NNN. If the -NNN suffix is absent, it means that --the change is in that release tarball, otherwise the change is on the --release/2.YY/master branch and not in any released tarball. -- --The following tags are currently being used: -- --CVE-Id: --This is the CVE-Id assigned under the CVE Program --(https://www.cve.org/). -- --Public-Date: --The date this issue became publicly known. -- --Vulnerable-Commit: --The commit that introduced this vulnerability. There could be multiple --entries, one for each release branch in the glibc repository; the --release-version portion of this tag should tell you which branch this is --on. -- --Fix-Commit: --The commit that fixed this vulnerability. There could be multiple --entries for each release branch in the glibc repository, indicating that --all of those commits contributed to fixing that issue in each of those --branches. -- --Reported-By: --The entity that reported this issue. There could be multiple entries, one for --each reporter. -- --Adding an Advisory -------------------- -- --An advisory for a CVE needs to be added on the master branch in two steps: -- --1. Add the text of the advisory without any Fix-Commit tags along with -- the fix for the CVE. Add the Vulnerable-Commit tag, if applicable. -- The advisories directory does not exist in release branches, so keep -- the advisory text commit distinct from the code changes, to ease -- backports. Ask for the GLIBC-SA advisory number from the security -- team. -- --2. Finish all backports on release branches and then back on the msater -- branch, add all commit refs to the advisory using the Fix-Commit -- tags. Don't bother adding the release-version subscript since the -- next step will overwrite it. -- --3. Run the process-advisories.sh script in the scripts directory on the -- advisory: -- -- scripts/process-advisories.sh update GLIBC-SA-YYYY-NNNN -- -- (replace YYYY-NNNN with the actual advisory number). -- --4. Verify the updated advisory and push the result. -- --Getting a NEWS snippet from advisories ---------------------------------------- -- --Run: -- -- scripts/process-advisories.sh news -- --and copy the content into the NEWS file. - -commit 3ec4dd77f648da031bba4d3fa14825e057b5a40d -Author: Andreas K. Hüttel -Date: Mon Jul 28 23:39:48 2025 +0200 - - NEWS: add new section - - Signed-off-by: Andreas K. Hüttel - -diff --git a/NEWS b/NEWS -index f0b0e924a4..9cb8de11f9 100644 ---- a/NEWS -+++ b/NEWS -@@ -5,6 +5,12 @@ See the end for copying conditions. - Please send GNU C library bug reports via - using `glibc' in the "product" field. - -+Version 2.42.1 -+ -+The following bugs were resolved with this release: -+ -+ [insert bugs here] -+ - Version 2.42 - - Major new features: - -commit bc13db73937730401d592b33092db6df806d193e -Author: Sam James -Date: Mon Jul 28 21:55:30 2025 +0100 - - inet-fortified: fix namespace violation (bug 33227) - - We need to use __sz, not sz, as we do elsewhere. - - Reviewed-by: Florian Weimer - (cherry picked from commit 87afbd7a1ad9c1dd116921817fa97198171045db) - -diff --git a/inet/bits/inet-fortified.h b/inet/bits/inet-fortified.h -index 6738221a54..cc476ebcfd 100644 ---- a/inet/bits/inet-fortified.h -+++ b/inet/bits/inet-fortified.h -@@ -45,15 +45,15 @@ __NTH (inet_pton (int __af, - __fortify_clang_warning_only_if_bos0_lt - (4, __dst, "inet_pton called with destination buffer size less than 4") - { -- size_t sz = 0; -+ size_t __sz = 0; - if (__af == AF_INET) -- sz = sizeof (struct in_addr); -+ __sz = sizeof (struct in_addr); - else if (__af == AF_INET6) -- sz = sizeof (struct in6_addr); -+ __sz = sizeof (struct in6_addr); - else - return __inet_pton_alias (__af, __src, __dst); - -- return __glibc_fortify (inet_pton, sz, sizeof (char), -+ return __glibc_fortify (inet_pton, __sz, sizeof (char), - __glibc_objsize (__dst), - __af, __src, __dst); - }; - -commit fd18059c0fcf5568db3688da47403b663cf91c5e -Author: Davide Cavalca -Date: Thu Jul 31 17:32:58 2025 +0200 - - stdlib: resolve a double lock init issue after fork [BZ #32994] - - The __abort_fork_reset_child (introduced in - d40ac01cbbc66e6d9dbd8e3485605c63b2178251) call resets the lock after the - fork. This causes a DRD regression in valgrind - (https://bugs.kde.org/show_bug.cgi?id=503668), as it's effectively a - double initialization, despite it being actually ok in this case. As - suggested in https://sourceware.org/bugzilla/show_bug.cgi?id=32994#c2 - we replace it here with a memcpy of another initialized lock instead, - which makes valgrind happy. - - Reviewed-by: Florian Weimer - (cherry picked from commit d9a348d0927c7a1aec5caf3df3fcd36956b3eb23) - -diff --git a/NEWS b/NEWS -index 9cb8de11f9..4610b8bbc6 100644 ---- a/NEWS -+++ b/NEWS -@@ -9,7 +9,7 @@ Version 2.42.1 - - The following bugs were resolved with this release: - -- [insert bugs here] -+ [32994] stdlib: resolve a double lock init issue after fork - - Version 2.42 - -diff --git a/stdlib/abort.c b/stdlib/abort.c -index caa9e6dc04..904244a2fb 100644 ---- a/stdlib/abort.c -+++ b/stdlib/abort.c -@@ -19,6 +19,7 @@ - #include - #include - #include -+#include - #include - - /* Try to get a machine dependent instruction which will make the -@@ -42,7 +43,10 @@ __libc_rwlock_define_initialized (static, lock); - void - __abort_fork_reset_child (void) - { -- __libc_rwlock_init (lock); -+ /* Reinitialize lock without calling pthread_rwlock_init, to -+ avoid a valgrind DRD false positive. */ -+ __libc_rwlock_define_initialized (, reset_lock); -+ memcpy (&lock, &reset_lock, sizeof (lock)); - } - - void - -commit 2fadee530155bae6682ab2965d6ff3a2fc9eced6 -Author: Florian Weimer -Date: Fri Aug 1 19:27:04 2025 +0200 - - elf: Extract rtld_setup_phdr function from dl_main - - Remove historic binutils reference from comment and update - how this data is used by applications. - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 2cac9559e06044ba520e785c151fbbd25011865f) - -diff --git a/elf/rtld.c b/elf/rtld.c -index 493f9696ea..6fb900fb31 100644 ---- a/elf/rtld.c -+++ b/elf/rtld.c -@@ -1239,6 +1239,37 @@ rtld_setup_main_map (struct link_map *main_map) - return has_interp; - } - -+/* Set up the program header information for the dynamic linker -+ itself. It can be accessed via _r_debug and dl_iterate_phdr -+ callbacks. */ -+static void -+rtld_setup_phdr (void) -+{ -+ /* Starting from binutils-2.23, the linker will define the magic -+ symbol __ehdr_start to point to our own ELF header if it is -+ visible in a segment that also includes the phdrs. */ -+ -+ const ElfW(Ehdr) *rtld_ehdr = &__ehdr_start; -+ assert (rtld_ehdr->e_ehsize == sizeof *rtld_ehdr); -+ assert (rtld_ehdr->e_phentsize == sizeof (ElfW(Phdr))); -+ -+ const ElfW(Phdr) *rtld_phdr = (const void *) rtld_ehdr + rtld_ehdr->e_phoff; -+ -+ _dl_rtld_map.l_phdr = rtld_phdr; -+ _dl_rtld_map.l_phnum = rtld_ehdr->e_phnum; -+ -+ -+ /* PT_GNU_RELRO is usually the last phdr. */ -+ size_t cnt = rtld_ehdr->e_phnum; -+ while (cnt-- > 0) -+ if (rtld_phdr[cnt].p_type == PT_GNU_RELRO) -+ { -+ _dl_rtld_map.l_relro_addr = rtld_phdr[cnt].p_vaddr; -+ _dl_rtld_map.l_relro_size = rtld_phdr[cnt].p_memsz; -+ break; -+ } -+} -+ - /* Adjusts the contents of the stack and related globals for the user - entry point. The ld.so processed skip_args arguments and bumped - _dl_argv and _dl_argc accordingly. Those arguments are removed from -@@ -1705,33 +1736,7 @@ dl_main (const ElfW(Phdr) *phdr, - ++GL(dl_ns)[LM_ID_BASE]._ns_nloaded; - ++GL(dl_load_adds); - -- /* Starting from binutils-2.23, the linker will define the magic symbol -- __ehdr_start to point to our own ELF header if it is visible in a -- segment that also includes the phdrs. If that's not available, we use -- the old method that assumes the beginning of the file is part of the -- lowest-addressed PT_LOAD segment. */ -- -- /* Set up the program header information for the dynamic linker -- itself. It is needed in the dl_iterate_phdr callbacks. */ -- const ElfW(Ehdr) *rtld_ehdr = &__ehdr_start; -- assert (rtld_ehdr->e_ehsize == sizeof *rtld_ehdr); -- assert (rtld_ehdr->e_phentsize == sizeof (ElfW(Phdr))); -- -- const ElfW(Phdr) *rtld_phdr = (const void *) rtld_ehdr + rtld_ehdr->e_phoff; -- -- _dl_rtld_map.l_phdr = rtld_phdr; -- _dl_rtld_map.l_phnum = rtld_ehdr->e_phnum; -- -- -- /* PT_GNU_RELRO is usually the last phdr. */ -- size_t cnt = rtld_ehdr->e_phnum; -- while (cnt-- > 0) -- if (rtld_phdr[cnt].p_type == PT_GNU_RELRO) -- { -- _dl_rtld_map.l_relro_addr = rtld_phdr[cnt].p_vaddr; -- _dl_rtld_map.l_relro_size = rtld_phdr[cnt].p_memsz; -- break; -- } -+ rtld_setup_phdr (); - - /* Add the dynamic linker to the TLS list if it also uses TLS. */ - if (_dl_rtld_map.l_tls_blocksize != 0) - -commit 5e298d2d937b6da06500478be956abeb24357e05 -Author: Florian Weimer -Date: Fri Aug 1 19:27:35 2025 +0200 - - elf: Handle ld.so with LOAD segment gaps in _dl_find_object (bug 31943) - - Detect if ld.so not contiguous and handle that case in _dl_find_object. - Set l_find_object_processed even for initially loaded link maps, - otherwise dlopen of an initially loaded object adds it to - _dlfo_loaded_mappings (where maps are expected to be contiguous), - in addition to _dlfo_nodelete_mappings. - - Test elf/tst-link-map-contiguous-ldso iterates over the loader - image, reading every word to make sure memory is actually mapped. - It only does that if the l_contiguous flag is set for the link map. - Otherwise, it finds gaps with mmap and checks that _dl_find_object - does not return the ld.so mapping for them. - - The test elf/tst-link-map-contiguous-main does the same thing for - the libc.so shared object. This only works if the kernel loaded - the main program because the glibc dynamic loader may fill - the gaps with PROT_NONE mappings in some cases, making it contiguous, - but accesses to individual words may still fault. - - Test elf/tst-link-map-contiguous-libc is again slightly different - because the dynamic loader always fills the gaps with PROT_NONE - mappings, so a different form of probing has to be used. - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 20681be149b9eb1b6c1f4246bf4bd801221c86cd) - -diff --git a/NEWS b/NEWS -index 4610b8bbc6..cbe11ac95b 100644 ---- a/NEWS -+++ b/NEWS -@@ -9,6 +9,7 @@ Version 2.42.1 - - The following bugs were resolved with this release: - -+ [31943] _dl_find_object can fail if ld.so contains gaps between load segments - [32994] stdlib: resolve a double lock init issue after fork - - Version 2.42 -diff --git a/elf/Makefile b/elf/Makefile -index 48aa0b57e5..3a5596e2bb 100644 ---- a/elf/Makefile -+++ b/elf/Makefile -@@ -543,6 +543,8 @@ tests-internal += \ - tst-dl_find_object-threads \ - tst-dlmopen2 \ - tst-hash-collision3 \ -+ tst-link-map-contiguous-ldso \ -+ tst-link-map-contiguous-libc \ - tst-ptrguard1 \ - tst-stackguard1 \ - tst-tls-surplus \ -@@ -554,6 +556,10 @@ tests-internal += \ - unload2 \ - # tests-internal - -+ifeq ($(build-hardcoded-path-in-tests),yes) -+tests-internal += tst-link-map-contiguous-main -+endif -+ - tests-container += \ - tst-dlopen-self-container \ - tst-dlopen-tlsmodid-container \ -diff --git a/elf/dl-find_object.c b/elf/dl-find_object.c -index 1e76373292..c9f4c1c8d1 100644 ---- a/elf/dl-find_object.c -+++ b/elf/dl-find_object.c -@@ -465,6 +465,37 @@ _dl_find_object (void *pc1, struct dl_find_object *result) - } - rtld_hidden_def (_dl_find_object) - -+/* Subroutine of _dlfo_process_initial to split out noncontigous link -+ maps. NODELETE is the number of used _dlfo_nodelete_mappings -+ elements. It is incremented as needed, and the new NODELETE value -+ is returned. */ -+static size_t -+_dlfo_process_initial_noncontiguous_map (struct link_map *map, -+ size_t nodelete) -+{ -+ struct dl_find_object_internal dlfo; -+ _dl_find_object_from_map (map, &dlfo); -+ -+ /* PT_LOAD segments for a non-contiguous link map are added to the -+ non-closeable mappings. */ -+ const ElfW(Phdr) *ph = map->l_phdr; -+ const ElfW(Phdr) *ph_end = map->l_phdr + map->l_phnum; -+ for (; ph < ph_end; ++ph) -+ if (ph->p_type == PT_LOAD) -+ { -+ if (_dlfo_nodelete_mappings != NULL) -+ { -+ /* Second pass only. */ -+ _dlfo_nodelete_mappings[nodelete] = dlfo; -+ ElfW(Addr) start = ph->p_vaddr + map->l_addr; -+ _dlfo_nodelete_mappings[nodelete].map_start = start; -+ _dlfo_nodelete_mappings[nodelete].map_end = start + ph->p_memsz; -+ } -+ ++nodelete; -+ } -+ return nodelete; -+} -+ - /* _dlfo_process_initial is called twice. First to compute the array - sizes from the initial loaded mappings. Second to fill in the - bases and infos arrays with the (still unsorted) data. Returns the -@@ -476,29 +507,8 @@ _dlfo_process_initial (void) - - size_t nodelete = 0; - if (!main_map->l_contiguous) -- { -- struct dl_find_object_internal dlfo; -- _dl_find_object_from_map (main_map, &dlfo); -- -- /* PT_LOAD segments for a non-contiguous are added to the -- non-closeable mappings. */ -- for (const ElfW(Phdr) *ph = main_map->l_phdr, -- *ph_end = main_map->l_phdr + main_map->l_phnum; -- ph < ph_end; ++ph) -- if (ph->p_type == PT_LOAD) -- { -- if (_dlfo_nodelete_mappings != NULL) -- { -- /* Second pass only. */ -- _dlfo_nodelete_mappings[nodelete] = dlfo; -- _dlfo_nodelete_mappings[nodelete].map_start -- = ph->p_vaddr + main_map->l_addr; -- _dlfo_nodelete_mappings[nodelete].map_end -- = _dlfo_nodelete_mappings[nodelete].map_start + ph->p_memsz; -- } -- ++nodelete; -- } -- } -+ /* Contiguous case already handled in _dl_find_object_init. */ -+ nodelete = _dlfo_process_initial_noncontiguous_map (main_map, nodelete); - - size_t loaded = 0; - for (Lmid_t ns = 0; ns < GL(dl_nns); ++ns) -@@ -510,11 +520,18 @@ _dlfo_process_initial (void) - /* lt_library link maps are implicitly NODELETE. */ - if (l->l_type == lt_library || l->l_nodelete_active) - { -- if (_dlfo_nodelete_mappings != NULL) -- /* Second pass only. */ -- _dl_find_object_from_map -- (l, _dlfo_nodelete_mappings + nodelete); -- ++nodelete; -+ /* The kernel may have loaded ld.so with gaps. */ -+ if (!l->l_contiguous && is_rtld_link_map (l)) -+ nodelete -+ = _dlfo_process_initial_noncontiguous_map (l, nodelete); -+ else -+ { -+ if (_dlfo_nodelete_mappings != NULL) -+ /* Second pass only. */ -+ _dl_find_object_from_map -+ (l, _dlfo_nodelete_mappings + nodelete); -+ ++nodelete; -+ } - } - else if (l->l_type == lt_loaded) - { -@@ -764,7 +781,6 @@ _dl_find_object_update_1 (struct link_map **loaded, size_t count) - /* Prefer newly loaded link map. */ - assert (loaded_index1 > 0); - _dl_find_object_from_map (loaded[loaded_index1 - 1], dlfo); -- loaded[loaded_index1 - 1]->l_find_object_processed = 1; - --loaded_index1; - } - -diff --git a/elf/dl-find_object.h b/elf/dl-find_object.h -index 9aa2439eaa..d9d75c4ad9 100644 ---- a/elf/dl-find_object.h -+++ b/elf/dl-find_object.h -@@ -94,7 +94,7 @@ _dl_find_object_to_external (struct dl_find_object_internal *internal, - } - - /* Extract the object location data from a link map and writes it to -- *RESULT using relaxed MO stores. */ -+ *RESULT using relaxed MO stores. Set L->l_find_object_processed. */ - static void __attribute__ ((unused)) - _dl_find_object_from_map (struct link_map *l, - struct dl_find_object_internal *result) -@@ -141,8 +141,11 @@ _dl_find_object_from_map (struct link_map *l, - break; - } - if (read_seg == 3) -- return; -+ goto done; - } -+ -+ done: -+ l->l_find_object_processed = 1; - } - - /* Called by the dynamic linker to set up the data structures for the -diff --git a/elf/rtld.c b/elf/rtld.c -index 6fb900fb31..ef4d96c053 100644 ---- a/elf/rtld.c -+++ b/elf/rtld.c -@@ -1241,7 +1241,7 @@ rtld_setup_main_map (struct link_map *main_map) - - /* Set up the program header information for the dynamic linker - itself. It can be accessed via _r_debug and dl_iterate_phdr -- callbacks. */ -+ callbacks, and it is used by _dl_find_object. */ - static void - rtld_setup_phdr (void) - { -@@ -1259,6 +1259,29 @@ rtld_setup_phdr (void) - _dl_rtld_map.l_phnum = rtld_ehdr->e_phnum; - - -+ _dl_rtld_map.l_contiguous = 1; -+ /* The linker may not have produced a contiguous object. The kernel -+ will load the object with actual gaps (unlike the glibc loader -+ for shared objects, which always produces a contiguous mapping). -+ See similar logic in rtld_setup_main_map above. */ -+ { -+ ElfW(Addr) expected_load_address = 0; -+ for (const ElfW(Phdr) *ph = rtld_phdr; ph < &rtld_phdr[rtld_ehdr->e_phnum]; -+ ++ph) -+ if (ph->p_type == PT_LOAD) -+ { -+ ElfW(Addr) mapstart = ph->p_vaddr & ~(GLRO(dl_pagesize) - 1); -+ if (_dl_rtld_map.l_contiguous && expected_load_address != 0 -+ && expected_load_address != mapstart) -+ _dl_rtld_map.l_contiguous = 0; -+ ElfW(Addr) allocend = ph->p_vaddr + ph->p_memsz; -+ /* The next expected address is the page following this load -+ segment. */ -+ expected_load_address = ((allocend + GLRO(dl_pagesize) - 1) -+ & ~(GLRO(dl_pagesize) - 1)); -+ } -+ } -+ - /* PT_GNU_RELRO is usually the last phdr. */ - size_t cnt = rtld_ehdr->e_phnum; - while (cnt-- > 0) -diff --git a/elf/tst-link-map-contiguous-ldso.c b/elf/tst-link-map-contiguous-ldso.c -new file mode 100644 -index 0000000000..04de808bb2 ---- /dev/null -+++ b/elf/tst-link-map-contiguous-ldso.c -@@ -0,0 +1,98 @@ -+/* Check that _dl_find_object behavior matches up with gaps. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+ -+static int -+do_test (void) -+{ -+ struct link_map *l = xdlopen (LD_SO, RTLD_NOW); -+ if (!l->l_contiguous) -+ { -+ puts ("info: ld.so link map is not contiguous"); -+ -+ /* Try to find holes by probing with mmap. */ -+ int pagesize = getpagesize (); -+ bool gap_found = false; -+ ElfW(Addr) addr = l->l_map_start; -+ TEST_COMPARE (addr % pagesize, 0); -+ while (addr < l->l_map_end) -+ { -+ void *expected = (void *) addr; -+ void *ptr = xmmap (expected, 1, PROT_READ | PROT_WRITE, -+ MAP_PRIVATE | MAP_ANONYMOUS, -1); -+ struct dl_find_object dlfo; -+ int dlfo_ret = _dl_find_object (expected, &dlfo); -+ if (ptr == expected) -+ { -+ if (dlfo_ret < 0) -+ { -+ TEST_COMPARE (dlfo_ret, -1); -+ printf ("info: hole without mapping data found at %p\n", ptr); -+ } -+ else -+ FAIL ("object \"%s\" found in gap at %p", -+ dlfo.dlfo_link_map->l_name, ptr); -+ gap_found = true; -+ } -+ else if (dlfo_ret == 0) -+ { -+ if ((void *) dlfo.dlfo_link_map != (void *) l) -+ { -+ printf ("info: object \"%s\" found at %p\n", -+ dlfo.dlfo_link_map->l_name, ptr); -+ gap_found = true; -+ } -+ } -+ else -+ TEST_COMPARE (dlfo_ret, -1); -+ xmunmap (ptr, 1); -+ addr += pagesize; -+ } -+ if (!gap_found) -+ FAIL ("no ld.so gap found"); -+ } -+ else -+ { -+ puts ("info: ld.so link map is contiguous"); -+ -+ /* Assert that ld.so is truly contiguous in memory. */ -+ volatile long int *p = (volatile long int *) l->l_map_start; -+ volatile long int *end = (volatile long int *) l->l_map_end; -+ while (p < end) -+ { -+ *p; -+ ++p; -+ } -+ } -+ -+ xdlclose (l); -+ -+ return 0; -+} -+ -+#include -diff --git a/elf/tst-link-map-contiguous-libc.c b/elf/tst-link-map-contiguous-libc.c -new file mode 100644 -index 0000000000..eb5728c765 ---- /dev/null -+++ b/elf/tst-link-map-contiguous-libc.c -@@ -0,0 +1,57 @@ -+/* Check that the entire libc.so program image is readable if contiguous. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+ -+static int -+do_test (void) -+{ -+ struct link_map *l = xdlopen (LIBC_SO, RTLD_NOW); -+ -+ /* The dynamic loader fills holes with PROT_NONE mappings. */ -+ if (!l->l_contiguous) -+ FAIL_EXIT1 ("libc.so link map is not contiguous"); -+ -+ /* Direct probing does not work because not everything is readable -+ due to PROT_NONE mappings. */ -+ int pagesize = getpagesize (); -+ ElfW(Addr) addr = l->l_map_start; -+ TEST_COMPARE (addr % pagesize, 0); -+ while (addr < l->l_map_end) -+ { -+ void *expected = (void *) addr; -+ void *ptr = xmmap (expected, 1, PROT_READ | PROT_WRITE, -+ MAP_PRIVATE | MAP_ANONYMOUS, -1); -+ if (ptr == expected) -+ FAIL ("hole in libc.so memory image after %lu bytes", -+ (unsigned long int) (addr - l->l_map_start)); -+ xmunmap (ptr, 1); -+ addr += pagesize; -+ } -+ -+ xdlclose (l); -+ -+ return 0; -+} -+#include -diff --git a/elf/tst-link-map-contiguous-main.c b/elf/tst-link-map-contiguous-main.c -new file mode 100644 -index 0000000000..2d1a054f0f ---- /dev/null -+++ b/elf/tst-link-map-contiguous-main.c -@@ -0,0 +1,45 @@ -+/* Check that the entire main program image is readable if contiguous. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+ -+static int -+do_test (void) -+{ -+ struct link_map *l = xdlopen ("", RTLD_NOW); -+ if (!l->l_contiguous) -+ FAIL_UNSUPPORTED ("main link map is not contiguous"); -+ -+ /* This check only works if the kernel loaded the main program. The -+ dynamic loader replaces gaps with PROT_NONE mappings, resulting -+ in faults. */ -+ volatile long int *p = (volatile long int *) l->l_map_start; -+ volatile long int *end = (volatile long int *) l->l_map_end; -+ while (p < end) -+ { -+ *p; -+ ++p; -+ } -+ -+ xdlclose (l); -+ -+ return 0; -+} -+#include - -commit b38f3f60d5b157edcf4d8bd1fd3ed02d417889e0 -Author: Adhemerval Zanella -Date: Fri Aug 1 15:00:25 2025 -0300 - - nptl: Fix SYSCALL_CANCEL for return values larger than INT_MAX (BZ 33245) - - The SYSCALL_CANCEL calls __syscall_cancel, which in turn - calls __internal_syscall_cancel with an 'int' return instead of the - expected 'long int'. This causes issues with syscalls that return - values larger than INT_MAX, such as copy_file_range [1]. - - Checked on x86_64-linux-gnu. - - [1] https://debbugs.gnu.org/cgi/bugreport.cgi?bug=79139 - - Reviewed-by: Andreas K. Huettel - (cherry picked from commit 7107bebf19286f42dcb0a97581137a5893c16206) - -diff --git a/NEWS b/NEWS -index cbe11ac95b..1d04bdfef8 100644 ---- a/NEWS -+++ b/NEWS -@@ -11,6 +11,7 @@ The following bugs were resolved with this release: - - [31943] _dl_find_object can fail if ld.so contains gaps between load segments - [32994] stdlib: resolve a double lock init issue after fork -+ [33245] nptl: nptl: error in internal cancellation syscall handling - - Version 2.42 - -diff --git a/nptl/cancellation.c b/nptl/cancellation.c -index 156e63dcf0..bed0383a23 100644 ---- a/nptl/cancellation.c -+++ b/nptl/cancellation.c -@@ -72,8 +72,8 @@ __syscall_cancel (__syscall_arg_t a1, __syscall_arg_t a2, - __syscall_arg_t a5, __syscall_arg_t a6, - __SYSCALL_CANCEL7_ARG_DEF __syscall_arg_t nr) - { -- int r = __internal_syscall_cancel (a1, a2, a3, a4, a5, a6, -- __SYSCALL_CANCEL7_ARG nr); -+ long int r = __internal_syscall_cancel (a1, a2, a3, a4, a5, a6, -+ __SYSCALL_CANCEL7_ARG nr); - return __glibc_unlikely (INTERNAL_SYSCALL_ERROR_P (r)) - ? SYSCALL_ERROR_LABEL (INTERNAL_SYSCALL_ERRNO (r)) - : r; - -commit 9d5bf9c17db0f35268cd798660c8bbeea1f4071d -Author: H.J. Lu -Date: Sat Jul 19 07:43:26 2025 -0700 - - Delete temporary files in support_subprocess - - Call support_delete_temp_files to delete temporary files before exit in - support_subprocess. - - This partially fixes BZ #33182. - - Signed-off-by: H.J. Lu - Reviewed-by: Adhemerval Zanella - (cherry picked from commit d27b1a71cd424710813bd3d81afb32a36470d643) - -diff --git a/support/support_subprocess.c b/support/support_subprocess.c -index be00dde3a7..8bf9a33ea2 100644 ---- a/support/support_subprocess.c -+++ b/support/support_subprocess.c -@@ -25,6 +25,7 @@ - #include - #include - #include -+#include - - static struct support_subprocess - support_subprocess_init (void) -@@ -60,6 +61,8 @@ support_subprocess (void (*callback) (void *), void *closure) - xclose (result.stdout_pipe[1]); - xclose (result.stderr_pipe[1]); - callback (closure); -+ /* Make sure that temporary files are deleted. */ -+ support_delete_temp_files (); - _exit (0); - } - xclose (result.stdout_pipe[1]); - -commit 9ec7a532ffdb9a6e0a4b220d7a694d6120701035 -Author: H.J. Lu -Date: Sat Jul 19 07:43:27 2025 -0700 - - tst-fopen-threaded.c: Delete temporary file - - Update tst-fopen-threaded.c to call support_create_temp_directory to - create a temporary directory and open "file" in the temporary directory, - instead of using /tmp/openclosetest and leaving it behind. - - This partially fixes BZ #33182. - - Signed-off-by: H.J. Lu - Reviewed-by: Adhemerval Zanella - (cherry picked from commit e7db5150603bb2224a2bfd9628cae04ddcbe49e3) - -diff --git a/sysdeps/pthread/tst-fopen-threaded.c b/sysdeps/pthread/tst-fopen-threaded.c -index ade58ad19e..c17f1eaa13 100644 ---- a/sysdeps/pthread/tst-fopen-threaded.c -+++ b/sysdeps/pthread/tst-fopen-threaded.c -@@ -34,11 +34,13 @@ - #include - #include - #include -+#include - - #include - #include - #include - #include -+#include - - #define NUM_THREADS 100 - #define ITERS 10 -@@ -111,7 +113,8 @@ threadOpenCloseRoutine (void *argv) - /* Wait for all threads to be ready to call fopen and fclose. */ - xpthread_barrier_wait (&barrier); - -- FILE *fd = xfopen ("/tmp/openclosetest", "w+"); -+ char *file = (char *) argv; -+ FILE *fd = xfopen (file, "w+"); - xfclose (fd); - return NULL; - } -@@ -235,6 +238,10 @@ do_test (void) - xfclose (fd_file); - } - -+ char *tempdir = support_create_temp_directory ("openclosetest-"); -+ char *file = xasprintf ("%s/file", tempdir); -+ add_temp_file (file); -+ - /* Test 3: Concurrent open/close. */ - for (int reps = 1; reps <= ITERS; reps++) - { -@@ -243,7 +250,7 @@ do_test (void) - { - threads[i] = - xpthread_create (support_small_stack_thread_attribute (), -- threadOpenCloseRoutine, NULL); -+ threadOpenCloseRoutine, file); - } - for (int i = 0; i < NUM_THREADS; i++) - { -@@ -252,6 +259,9 @@ do_test (void) - xpthread_barrier_destroy (&barrier); - } - -+ free (file); -+ free (tempdir); -+ - return 0; - } - - -commit 41a77b78cff821007e3dd874619ebec7ce708c3d -Author: H.J. Lu -Date: Sat Jul 19 07:43:28 2025 -0700 - - tst-freopen4-main.c: Call support_capture_subprocess with chroot - - Update tst-freopen4-main.c to call support_capture_subprocess with chroot, - which makes temporary files inaccessible, so that temporary files can be - deleted. - - This partially fixes BZ #33182. - - Signed-off-by: H.J. Lu - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 6463d4a7b28e5ee3891c34a8a1f0a59c24dfa9de) - -diff --git a/stdio-common/tst-freopen4-main.c b/stdio-common/tst-freopen4-main.c -index 3336f5327d..436da4d203 100644 ---- a/stdio-common/tst-freopen4-main.c -+++ b/stdio-common/tst-freopen4-main.c -@@ -28,25 +28,15 @@ - #include - #include - #include -+#include - --int --do_test (void) -+static void -+do_test_chroot (void *data) - { -- mtrace (); -- char *temp_dir; -+ char *temp_dir = (char *) data; - FILE *fp; - int ret; - -- /* These chroot tests verify that either reopening a renamed or -- deleted file works even in the absence of /proc, or that it fails -- (without memory leaks); thus, for example, such reopening does -- not crash in the absence of /proc. */ -- -- support_become_root (); -- if (!support_can_chroot ()) -- return EXIT_UNSUPPORTED; -- -- temp_dir = support_create_temp_directory ("tst-freopen4"); - xchroot (temp_dir); - - /* Test freopen with NULL, renamed file. This verifies that -@@ -96,6 +86,32 @@ do_test (void) - puts ("freopen of deleted file failed (OK)"); - - free (temp_dir); -+} -+ -+int -+do_test (void) -+{ -+ mtrace (); -+ char *temp_dir; -+ -+ /* These chroot tests verify that either reopening a renamed or -+ deleted file works even in the absence of /proc, or that it fails -+ (without memory leaks); thus, for example, such reopening does -+ not crash in the absence of /proc. */ -+ -+ support_become_root (); -+ if (!support_can_chroot ()) -+ return EXIT_UNSUPPORTED; -+ -+ temp_dir = support_create_temp_directory ("tst-freopen4"); -+ -+ struct support_capture_subprocess result; -+ result = support_capture_subprocess (do_test_chroot, temp_dir); -+ support_capture_subprocess_check (&result, "freopen4", 0, -+ sc_allow_stdout); -+ fputs (result.out.buffer, stdout); -+ support_capture_subprocess_free (&result); -+ - return 0; - } - - -commit c090b0cb1cde74aaeec01663dd55d6681dc92075 -Author: H.J. Lu -Date: Sat Jul 19 07:43:29 2025 -0700 - - tst-env-setuid: Delete LD_DEBUG_OUTPUT output - - Update tst-env-setuid.c to delete LD_DEBUG_OUTPUT output, instead of - leaving it behind. - - This partially fixes BZ #33182. - - Signed-off-by: H.J. Lu - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 5d23dfb289174d73b8907b86d2bef7a3ca889840) - -diff --git a/elf/tst-env-setuid.c b/elf/tst-env-setuid.c -index 7209acd616..ff3eda7f91 100644 ---- a/elf/tst-env-setuid.c -+++ b/elf/tst-env-setuid.c -@@ -40,6 +40,8 @@ static char SETGID_CHILD[] = "setgid-child"; - # define PROFILE_LIB "tst-sonamemove-runmod2.so" - #endif - -+#define LD_DEBUG_OUTPUT "/tmp/some-file" -+ - struct envvar_t - { - const char *env; -@@ -61,7 +63,7 @@ static const struct envvar_t filtered_envvars[] = - { "MALLOC_TRIM_THRESHOLD_", FILTERED_VALUE }, - { "RES_OPTIONS", FILTERED_VALUE }, - { "LD_DEBUG", "all" }, -- { "LD_DEBUG_OUTPUT", "/tmp/some-file" }, -+ { "LD_DEBUG_OUTPUT", LD_DEBUG_OUTPUT }, - { "LD_WARN", FILTERED_VALUE }, - { "LD_VERBOSE", FILTERED_VALUE }, - { "LD_BIND_NOW", "0" }, -@@ -74,6 +76,14 @@ static const struct envvar_t unfiltered_envvars[] = - { "LD_ASSUME_KERNEL", UNFILTERED_VALUE }, - }; - -+static void -+unlink_ld_debug_output (pid_t pid) -+{ -+ char *output = xasprintf ("%s.%d", LD_DEBUG_OUTPUT, pid); -+ unlink (output); -+ free (output); -+} -+ - static int - test_child (void) - { -@@ -138,13 +148,21 @@ do_test (int argc, char **argv) - /* Setgid child process. */ - if (argc == 2 && strcmp (argv[1], SETGID_CHILD) == 0) - { -+ pid_t ppid = getppid (); -+ - if (getgid () == getegid ()) -- /* This can happen if the file system is mounted nosuid. */ -- FAIL_UNSUPPORTED ("SGID failed: GID and EGID match (%jd)\n", -- (intmax_t) getgid ()); -+ { -+ /* This can happen if the file system is mounted nosuid. */ -+ unlink_ld_debug_output (ppid); -+ -+ FAIL_UNSUPPORTED ("SGID failed: GID and EGID match (%jd)\n", -+ (intmax_t) getgid ()); -+ } - - int ret = test_child (); - -+ unlink_ld_debug_output (ppid); -+ - if (ret != 0) - exit (1); - return 0; - -commit e5754399b542640f3f69c5e2513c57a307656032 -Author: H.J. Lu -Date: Tue Aug 5 09:16:14 2025 -0700 - - Revert "tst-freopen4-main.c: Call support_capture_subprocess with chroot" - - Revert commit 6463d4a7b28e5ee3891c34a8a1f0a59c24dfa9de to fix - - FAIL: stdio-common/tst-freopen4-mem - FAIL: stdio-common/tst-freopen64-4-mem - - This fixes BZ #33254. - - Reviewed-by: Sam James - (cherry picked from commit adec0bf05bc23ec35573c7a5b96440089b69265e) - -diff --git a/stdio-common/tst-freopen4-main.c b/stdio-common/tst-freopen4-main.c -index 436da4d203..3336f5327d 100644 ---- a/stdio-common/tst-freopen4-main.c -+++ b/stdio-common/tst-freopen4-main.c -@@ -28,15 +28,25 @@ - #include - #include - #include --#include - --static void --do_test_chroot (void *data) -+int -+do_test (void) - { -- char *temp_dir = (char *) data; -+ mtrace (); -+ char *temp_dir; - FILE *fp; - int ret; - -+ /* These chroot tests verify that either reopening a renamed or -+ deleted file works even in the absence of /proc, or that it fails -+ (without memory leaks); thus, for example, such reopening does -+ not crash in the absence of /proc. */ -+ -+ support_become_root (); -+ if (!support_can_chroot ()) -+ return EXIT_UNSUPPORTED; -+ -+ temp_dir = support_create_temp_directory ("tst-freopen4"); - xchroot (temp_dir); - - /* Test freopen with NULL, renamed file. This verifies that -@@ -86,32 +96,6 @@ do_test_chroot (void *data) - puts ("freopen of deleted file failed (OK)"); - - free (temp_dir); --} -- --int --do_test (void) --{ -- mtrace (); -- char *temp_dir; -- -- /* These chroot tests verify that either reopening a renamed or -- deleted file works even in the absence of /proc, or that it fails -- (without memory leaks); thus, for example, such reopening does -- not crash in the absence of /proc. */ -- -- support_become_root (); -- if (!support_can_chroot ()) -- return EXIT_UNSUPPORTED; -- -- temp_dir = support_create_temp_directory ("tst-freopen4"); -- -- struct support_capture_subprocess result; -- result = support_capture_subprocess (do_test_chroot, temp_dir); -- support_capture_subprocess_check (&result, "freopen4", 0, -- sc_allow_stdout); -- fputs (result.out.buffer, stdout); -- support_capture_subprocess_free (&result); -- - return 0; - } - - -commit c5476b7907d01207ede6bf57b26cef151b601f35 -Author: Samuel Thibault -Date: Fri Jul 18 23:14:40 2025 +0200 - - hurd: support: Fix running SGID tests - - Secure mode is enabled only if SGID actually provides a new privilege, - so we have to drop it before gaining it again. - - Fixes commit 3a3fb2ed83f79100c116c824454095ecfb335ad7 - ("Fix error reporting (false negatives) in SGID tests") - - (cherry picked from commit ad4589e2d834c80a042a8c354fb00cf33e06802c) - -diff --git a/support/support_capture_subprocess.c b/support/support_capture_subprocess.c -index b4e4bf9502..c89e65b534 100644 ---- a/support/support_capture_subprocess.c -+++ b/support/support_capture_subprocess.c -@@ -133,6 +133,27 @@ copy_and_spawn_sgid (const char *child_id, gid_t gid) - if (chmod (execname, 02750) != 0) - FAIL_UNSUPPORTED ("cannot make \"%s\" SGID: %m ", execname); - -+ /* Now we can drop the privilege of that group. */ -+ const int count = 64; -+ gid_t groups[count]; -+ int ngroups = getgroups(count, groups); -+ -+ if (ngroups < 0) -+ FAIL_UNSUPPORTED ("Could not get group list again for user %jd\n", -+ (intmax_t) getuid ()); -+ -+ int n = 0; -+ for (int i = 0; i < ngroups; i++) -+ { -+ if (groups[i] != gid) -+ { -+ if (n != i) -+ groups[n] = groups[i]; -+ n++; -+ } -+ } -+ setgroups (n, groups); -+ - /* We have the binary, now spawn the subprocess. Avoid using - support_subprogram because we only want the program exit status, not the - contents. */ - -commit 8a726b63047241c6dd4b55bf85eacd02244362a2 -Author: Wilco Dijkstra -Date: Thu Jul 10 15:49:14 2025 +0000 - - malloc: Remove redundant NULL check - - Remove a redundant NULL check from tcache_get_n. - - Reviewed-by: Cupertino Miranda - (cherry picked from commit 089b4fb90fac8ed53039bc4c465c4d333c6b4048) - -diff --git a/malloc/malloc.c b/malloc/malloc.c -index 5ca390cc22..cf5c02ff64 100644 ---- a/malloc/malloc.c -+++ b/malloc/malloc.c -@@ -3208,11 +3208,10 @@ tcache_get_n (size_t tc_idx, tcache_entry **ep, bool mangled) - if (__glibc_unlikely (misaligned_mem (e))) - malloc_printerr ("malloc(): unaligned tcache chunk detected"); - -- void *ne = e == NULL ? NULL : REVEAL_PTR (e->next); - if (!mangled) -- *ep = ne; -+ *ep = REVEAL_PTR (e->next); - else -- *ep = PROTECT_PTR (ep, ne); -+ *ep = PROTECT_PTR (ep, REVEAL_PTR (e->next)); - - ++(tcache->num_slots[tc_idx]); - e->key = 0; -@@ -3229,7 +3228,7 @@ tcache_put (mchunkptr chunk, size_t tc_idx) - static __always_inline void * - tcache_get (size_t tc_idx) - { -- return tcache_get_n (tc_idx, & tcache->entries[tc_idx], false); -+ return tcache_get_n (tc_idx, &tcache->entries[tc_idx], false); - } - - static __always_inline tcache_entry ** - -commit c491dabd8a3de090d1ccb4589421a44e79c5b185 -Author: Wilco Dijkstra -Date: Thu Jul 17 14:31:06 2025 +0000 - - malloc: Fix MAX_TCACHE_SMALL_SIZE - - MAX_TCACHE_SMALL_SIZE should use chunk size since it is used after - checked_request2size. Increase limit of tcache_max_bytes by 1 since all - comparisons use '<'. As a result, the last tcache entry is now used as - expected. - - Reviewed-by: DJ Delorie - (cherry picked from commit ad4caba4146583fc543cd434221dec7113c03e09) - -diff --git a/malloc/malloc.c b/malloc/malloc.c -index cf5c02ff64..b89b654f17 100644 ---- a/malloc/malloc.c -+++ b/malloc/malloc.c -@@ -294,9 +294,9 @@ - # define TCACHE_SMALL_BINS 64 - # define TCACHE_LARGE_BINS 12 /* Up to 4M chunks */ - # define TCACHE_MAX_BINS (TCACHE_SMALL_BINS + TCACHE_LARGE_BINS) --# define MAX_TCACHE_SMALL_SIZE tidx2usize (TCACHE_SMALL_BINS-1) -+# define MAX_TCACHE_SMALL_SIZE tidx2csize (TCACHE_SMALL_BINS-1) - --/* Only used to pre-fill the tunables. */ -+# define tidx2csize(idx) (((size_t) idx) * MALLOC_ALIGNMENT + MINSIZE) - # define tidx2usize(idx) (((size_t) idx) * MALLOC_ALIGNMENT + MINSIZE - SIZE_SZ) - - /* When "x" is from chunksize(). */ -@@ -1932,7 +1932,7 @@ static struct malloc_par mp_ = - , - .tcache_count = TCACHE_FILL_COUNT, - .tcache_small_bins = TCACHE_SMALL_BINS, -- .tcache_max_bytes = MAX_TCACHE_SMALL_SIZE, -+ .tcache_max_bytes = MAX_TCACHE_SMALL_SIZE + 1, - .tcache_unsorted_limit = 0 /* No limit. */ - #endif - }; -@@ -5586,15 +5586,13 @@ do_set_arena_max (size_t value) - static __always_inline int - do_set_tcache_max (size_t value) - { -+ if (value > PTRDIFF_MAX) -+ return 0; -+ - size_t nb = request2size (value); - size_t tc_idx = csize2tidx (nb); - -- /* To check that value is not too big and request2size does not return an -- overflown value. */ -- if (value > nb) -- return 0; -- -- if (nb > MAX_TCACHE_SMALL_SIZE) -+ if (tc_idx >= TCACHE_SMALL_BINS) - tc_idx = large_csize2tidx (nb); - - LIBC_PROBE (memory_tunable_tcache_max_bytes, 2, value, mp_.tcache_max_bytes); -@@ -5603,7 +5601,7 @@ do_set_tcache_max (size_t value) - { - if (tc_idx < TCACHE_SMALL_BINS) - mp_.tcache_small_bins = tc_idx + 1; -- mp_.tcache_max_bytes = nb; -+ mp_.tcache_max_bytes = nb + 1; - return 1; - } - - -commit a96a82c4a5efd3139e75cd11fd2a5554164dd5a0 -Author: Samuel Thibault -Date: Wed Jul 30 01:55:22 2025 +0200 - - malloc: Make sure tcache_key is odd enough - - We want tcache_key not to be a commonly-occurring value in memory, so ensure - a minimum amount of one and zero bits. - - And we need it non-zero, otherwise even if tcache_double_free_verify sets - e->key to 0 before calling __libc_free, it gets called again by __libc_free, - thus looping indefinitely. - - Fixes: c968fe50628db74b52124d863cd828225a1d305c ("malloc: Use tailcalls in __libc_free") - (cherry picked from commit 2536c4f8584082a1ac4c5e0a2a6222e290d43983) - -diff --git a/malloc/malloc.c b/malloc/malloc.c -index b89b654f17..e4e2f03600 100644 ---- a/malloc/malloc.c -+++ b/malloc/malloc.c -@@ -230,6 +230,9 @@ - /* For uintptr_t. */ - #include - -+/* For stdc_count_ones. */ -+#include -+ - /* For va_arg, va_start, va_end. */ - #include - -@@ -3152,6 +3155,19 @@ tcache_key_initialize (void) - if (__getrandom_nocancel_nostatus_direct (&tcache_key, sizeof(tcache_key), - GRND_NONBLOCK) - != sizeof (tcache_key)) -+ tcache_key = 0; -+ -+ /* We need tcache_key to be non-zero (otherwise tcache_double_free_verify's -+ clearing of e->key would go unnoticed and it would loop getting called -+ through __libc_free), and we want tcache_key not to be a -+ commonly-occurring value in memory, so ensure a minimum amount of one and -+ zero bits. */ -+ int minimum_bits = __WORDSIZE / 4; -+ int maximum_bits = __WORDSIZE - minimum_bits; -+ -+ while (labs (tcache_key) <= 0x1000000 -+ || stdc_count_ones (tcache_key) < minimum_bits -+ || stdc_count_ones (tcache_key) > maximum_bits) - { - tcache_key = random_bits (); - #if __WORDSIZE == 64 - -commit d7274d718e6f3655eabe311d4eb70fabb5ffa7ef -Author: Samuel Thibault -Date: Sun Aug 10 23:43:37 2025 +0200 - - malloc: Fix checking for small negative values of tcache_key - - tcache_key is unsigned so we should turn it explicitly to signed before - taking its absolute value. - - (cherry picked from commit 8543577b04ded6d979ffcc5a818930e4d74d0645) - -diff --git a/malloc/malloc.c b/malloc/malloc.c -index e4e2f03600..5f3e701fd1 100644 ---- a/malloc/malloc.c -+++ b/malloc/malloc.c -@@ -3165,7 +3165,7 @@ tcache_key_initialize (void) - int minimum_bits = __WORDSIZE / 4; - int maximum_bits = __WORDSIZE - minimum_bits; - -- while (labs (tcache_key) <= 0x1000000 -+ while (labs ((intptr_t) tcache_key) <= 0x1000000 - || stdc_count_ones (tcache_key) < minimum_bits - || stdc_count_ones (tcache_key) > maximum_bits) - { - -commit 8dbaecbe92ac7ab73b7d0aae84626af59131e41b -Author: Jens Remus -Date: Fri Jul 25 15:40:03 2025 +0200 - - Use TLS initial-exec model for __libc_tsd_CTYPE_* thread variables [BZ #33234] - - Commit 10a66a8e421b ("Remove ") removed the TLS initial-exec - (IE) model attribute from the __libc_tsd_CTYPE_* thread variable declarations - and definitions. Commit a894f04d8776 ("Optimize __libc_tsd_* thread - variable access") restored it on declarations. - - Restore the TLS initial-exec model attribute on __libc_tsd_CTYPE_* thread - variable definitions. - - This resolves test tst-locale1 failure on s390 32-bit, when using a - GNU linker without the fix from GNU binutils commit aefebe82dc89 - ("IBM zSystems: Fix offset relative to static TLS"). - - Reviewed-by: Florian Weimer - (cherry picked from commit e5363e6f460c2d58809bf10fc96d70fd1ef8b5b2) - -diff --git a/NEWS b/NEWS -index 1d04bdfef8..69aa600c6d 100644 ---- a/NEWS -+++ b/NEWS -@@ -11,6 +11,7 @@ The following bugs were resolved with this release: - - [31943] _dl_find_object can fail if ld.so contains gaps between load segments - [32994] stdlib: resolve a double lock init issue after fork -+ [33234] Use TLS initial-exec model for __libc_tsd_CTYPE_* thread variables - [33245] nptl: nptl: error in internal cancellation syscall handling - - Version 2.42 -diff --git a/ctype/ctype-info.c b/ctype/ctype-info.c -index b7d3422726..fb5acf9419 100644 ---- a/ctype/ctype-info.c -+++ b/ctype/ctype-info.c -@@ -24,11 +24,11 @@ - __ctype_init before user code runs, but this does not happen for - threads in secondary namespaces. With the initializers, secondary - namespaces at least get locale data from the C locale. */ --__thread const uint16_t * __libc_tsd_CTYPE_B -+__thread const uint16_t * __libc_tsd_CTYPE_B attribute_tls_model_ie - = (const uint16_t *) _nl_C_LC_CTYPE_class + 128; --__thread const int32_t * __libc_tsd_CTYPE_TOLOWER -+__thread const int32_t * __libc_tsd_CTYPE_TOLOWER attribute_tls_model_ie - = (const int32_t *) _nl_C_LC_CTYPE_tolower + 128; --__thread const int32_t * __libc_tsd_CTYPE_TOUPPER -+__thread const int32_t * __libc_tsd_CTYPE_TOUPPER attribute_tls_model_ie - = (const int32_t *) _nl_C_LC_CTYPE_toupper + 128; - - - -commit d0f72b96f2e91e1aa93f7e826c71f74078ada7d0 -Author: H.J. Lu -Date: Mon Jul 28 12:16:11 2025 -0700 - - i386: Add GLIBC_ABI_GNU_TLS version [BZ #33221] - - On i386, programs and shared libraries with __thread usage may fail - silently at run-time against glibc without the TLS run-time fix for: - - https://sourceware.org/bugzilla/show_bug.cgi?id=32996 - - Add GLIBC_ABI_GNU_TLS version to indicate that glibc has the working - GNU TLS run-time. Linker can add the GLIBC_ABI_GNU_TLS version to - binaries which depend on the working TLS run-time so that such programs - and shared libraries will fail to load and run at run-time against - libc.so without the GLIBC_ABI_GNU_TLS version, instead of fail silently - at random. - - This fixes BZ #33221. - - Signed-off-by: H.J. Lu - Reviewed-by: Sam James - (cherry picked from commit ed1b7a5a489ab555a27fad9c101ebe2e1c1ba881) - -diff --git a/sysdeps/i386/Makefile b/sysdeps/i386/Makefile -index ee6470d78e..c0c017b899 100644 ---- a/sysdeps/i386/Makefile -+++ b/sysdeps/i386/Makefile -@@ -60,6 +60,15 @@ $(objpfx)tst-ld-sse-use.out: ../sysdeps/i386/tst-ld-sse-use.sh $(objpfx)ld.so - @echo "Checking ld.so for SSE register use. This will take a few seconds..." - $(BASH) $< $(objpfx) '$(NM)' '$(OBJDUMP)' '$(READELF)' > $@; \ - $(evaluate-test) -+ -+tests-special += $(objpfx)check-gnu-tls.out -+ -+$(objpfx)check-gnu-tls.out: $(common-objpfx)libc.so -+ LC_ALL=C $(READELF) -V -W $< \ -+ | sed -ne '/.gnu.version_d/, /.gnu.version_r/ p' \ -+ | grep GLIBC_ABI_GNU_TLS > $@; \ -+ $(evaluate-test) -+generated += check-gnu-tls.out - else - CFLAGS-.os += $(if $(filter rtld-%.os,$(@F)), $(rtld-CFLAGS)) - endif -diff --git a/sysdeps/i386/Versions b/sysdeps/i386/Versions -index 36e23b466a..9c84c8ef04 100644 ---- a/sysdeps/i386/Versions -+++ b/sysdeps/i386/Versions -@@ -28,6 +28,11 @@ libc { - GLIBC_2.13 { - __fentry__; - } -+ GLIBC_ABI_GNU_TLS { -+ # This symbol is used only for empty version map and will be removed -+ # by scripts/versions.awk. -+ __placeholder_only_for_empty_version_map; -+ } - } - libm { - GLIBC_2.1 { - -commit 3970785bebcc3f1de4460072f3a041d178f64846 -Author: H.J. Lu -Date: Mon Jul 28 12:18:22 2025 -0700 - - x86-64: Add GLIBC_ABI_GNU2_TLS version [BZ #33129] - - Programs and shared libraries compiled with -mtls-dialect=gnu2 may fail - silently at run-time against glibc without the GNU2 TLS run-time fix - for: - - https://sourceware.org/bugzilla/show_bug.cgi?id=31372 - - Add GLIBC_ABI_GNU2_TLS version to indicate that glibc has the working - GNU2 TLS run-time. Linker can add the GLIBC_ABI_GNU2_TLS version to - binaries which depend on the working GNU2 TLS run-time: - - https://sourceware.org/bugzilla/show_bug.cgi?id=33130 - - so that such programs and shared libraries will fail to load and run at - run-time against libc.so without the GLIBC_ABI_GNU2_TLS version, instead - of fail silently at random. - - This fixes BZ #33129. - - Signed-off-by: H.J. Lu - Reviewed-by: Sam James - (cherry picked from commit 9df8fa397d515dc86ff5565f6c45625e672d539e) - -diff --git a/sysdeps/x86_64/Makefile b/sysdeps/x86_64/Makefile -index c3e1065c81..3ab8c1ed0f 100644 ---- a/sysdeps/x86_64/Makefile -+++ b/sysdeps/x86_64/Makefile -@@ -212,6 +212,15 @@ LDFLAGS-tst-plt-rewrite2 = -Wl,-z,now - LDFLAGS-tst-plt-rewritemod2.so = -Wl,-z,now,-z,undefs - tst-plt-rewrite2-ENV = GLIBC_TUNABLES=glibc.cpu.plt_rewrite=2 - $(objpfx)tst-plt-rewrite2: $(objpfx)tst-plt-rewritemod2.so -+ -+tests-special += $(objpfx)check-gnu2-tls.out -+ -+$(objpfx)check-gnu2-tls.out: $(common-objpfx)libc.so -+ LC_ALL=C $(READELF) -V -W $< \ -+ | sed -ne '/.gnu.version_d/, /.gnu.version_r/ p' \ -+ | grep GLIBC_ABI_GNU2_TLS > $@; \ -+ $(evaluate-test) -+generated += check-gnu2-tls.out - endif - - test-internal-extras += tst-gnu2-tls2mod1 -diff --git a/sysdeps/x86_64/Versions b/sysdeps/x86_64/Versions -index e94758b236..a63c11bcb2 100644 ---- a/sysdeps/x86_64/Versions -+++ b/sysdeps/x86_64/Versions -@@ -5,6 +5,11 @@ libc { - GLIBC_2.13 { - __fentry__; - } -+ GLIBC_ABI_GNU2_TLS { -+ # This symbol is used only for empty version map and will be removed -+ # by scripts/versions.awk. -+ __placeholder_only_for_empty_version_map; -+ } - } - libm { - GLIBC_2.1 { - -commit 7a8f3c6ee4b565a02da4ba0dad9aaeaeed4639ce -Author: H.J. Lu -Date: Thu Aug 14 07:03:20 2025 -0700 - - x86-64: Add GLIBC_ABI_DT_X86_64_PLT [BZ #33212] - - When the linker -z mark-plt option is used to add DT_X86_64_PLT, - DT_X86_64_PLTSZ and DT_X86_64_PLTENT, the r_addend field of the - R_X86_64_JUMP_SLOT relocation stores the offset of the indirect - branch instruction. However, glibc versions without the commit: - - commit f8587a61892cbafd98ce599131bf4f103466f084 - Author: H.J. Lu - Date: Fri May 20 19:21:48 2022 -0700 - - x86-64: Ignore r_addend for R_X86_64_GLOB_DAT/R_X86_64_JUMP_SLOT - - According to x86-64 psABI, r_addend should be ignored for R_X86_64_GLOB_DAT - and R_X86_64_JUMP_SLOT. Since linkers always set their r_addends to 0, we - can ignore their r_addends. - - Reviewed-by: Fangrui Song - - won't ignore the r_addend value in the R_X86_64_JUMP_SLOT relocation. - Such programs and shared libraries will fail at run-time randomly. - - Add GLIBC_ABI_DT_X86_64_PLT version to indicate that glibc is compatible - with DT_X86_64_PLT. - - The linker can add the glibc GLIBC_ABI_DT_X86_64_PLT version dependency - whenever -z mark-plt is passed to the linker. The resulting programs and - shared libraries will fail to load at run-time against libc.so without the - GLIBC_ABI_DT_X86_64_PLT version, instead of fail randomly. - - This fixes BZ #33212. - - Signed-off-by: H.J. Lu - Reviewed-by: Sam James - (cherry picked from commit 399384e0c8193e31aea014220ccfa24300ae5938) - -diff --git a/sysdeps/x86_64/Makefile b/sysdeps/x86_64/Makefile -index 3ab8c1ed0f..01100597a8 100644 ---- a/sysdeps/x86_64/Makefile -+++ b/sysdeps/x86_64/Makefile -@@ -213,6 +213,15 @@ LDFLAGS-tst-plt-rewritemod2.so = -Wl,-z,now,-z,undefs - tst-plt-rewrite2-ENV = GLIBC_TUNABLES=glibc.cpu.plt_rewrite=2 - $(objpfx)tst-plt-rewrite2: $(objpfx)tst-plt-rewritemod2.so - -+tests-special += $(objpfx)check-dt-x86-64-plt.out -+ -+$(objpfx)check-dt-x86-64-plt.out: $(common-objpfx)libc.so -+ LC_ALL=C $(READELF) -V -W $< \ -+ | sed -ne '/.gnu.version_d/, /.gnu.version_r/ p' \ -+ | grep GLIBC_ABI_DT_X86_64_PLT > $@; \ -+ $(evaluate-test) -+generated += check-dt-x86-64-plt.out -+ - tests-special += $(objpfx)check-gnu2-tls.out - - $(objpfx)check-gnu2-tls.out: $(common-objpfx)libc.so -diff --git a/sysdeps/x86_64/Versions b/sysdeps/x86_64/Versions -index a63c11bcb2..0a759029e5 100644 ---- a/sysdeps/x86_64/Versions -+++ b/sysdeps/x86_64/Versions -@@ -10,6 +10,11 @@ libc { - # by scripts/versions.awk. - __placeholder_only_for_empty_version_map; - } -+ GLIBC_ABI_DT_X86_64_PLT { -+ # This symbol is used only for empty version map and will be removed -+ # by scripts/versions.awk. -+ __placeholder_only_for_empty_version_map; -+ } - } - libm { - GLIBC_2.1 { - -commit e87844ec42b77363a499ea4da6c4a6ab85eba310 -Author: H.J. Lu -Date: Mon Aug 18 09:06:48 2025 -0700 - - i386: Also add GLIBC_ABI_GNU2_TLS version [BZ #33129] - - Since the GNU2 TLS run-time bug: - - https://sourceware.org/bugzilla/show_bug.cgi?id=31372 - - affects both i386 and x86-64, also add GLIBC_ABI_GNU2_TLS version to i386 - to indicate the working GNU2 TLS run-time. For x86-64, the additional - GNU2 TLS run-time bug fix is needed for - - https://sourceware.org/bugzilla/show_bug.cgi?id=31501 - - Signed-off-by: H.J. Lu - Reviewed-by: Sam James - (cherry picked from commit bd4628f3f18ac312408782eea450429c6f044860) - -diff --git a/sysdeps/x86/Makefile b/sysdeps/x86/Makefile -index 4fbd48e1c8..9e1c8cce85 100644 ---- a/sysdeps/x86/Makefile -+++ b/sysdeps/x86/Makefile -@@ -135,6 +135,15 @@ LDFLAGS-tst-tls23 += -rdynamic - tst-tls23-mod.so-no-z-defs = yes - - $(objpfx)tst-tls23-mod.so: $(libsupport) -+ -+tests-special += $(objpfx)check-gnu2-tls.out -+ -+$(objpfx)check-gnu2-tls.out: $(common-objpfx)libc.so -+ LC_ALL=C $(READELF) -V -W $< \ -+ | sed -ne '/.gnu.version_d/, /.gnu.version_r/ p' \ -+ | grep GLIBC_ABI_GNU2_TLS > $@; \ -+ $(evaluate-test) -+generated += check-gnu2-tls.out - endif - - ifeq ($(subdir),gmon) -diff --git a/sysdeps/x86/Versions b/sysdeps/x86/Versions -index 4b10c4b5d7..e8dcfccbe4 100644 ---- a/sysdeps/x86/Versions -+++ b/sysdeps/x86/Versions -@@ -7,4 +7,9 @@ libc { - GLIBC_2.33 { - __x86_get_cpuid_feature_leaf; - } -+ GLIBC_ABI_GNU2_TLS { -+ # This symbol is used only for empty version map and will be removed -+ # by scripts/versions.awk. -+ __placeholder_only_for_empty_version_map; -+ } - } -diff --git a/sysdeps/x86_64/Makefile b/sysdeps/x86_64/Makefile -index 01100597a8..fe9f1cdddb 100644 ---- a/sysdeps/x86_64/Makefile -+++ b/sysdeps/x86_64/Makefile -@@ -221,15 +221,6 @@ $(objpfx)check-dt-x86-64-plt.out: $(common-objpfx)libc.so - | grep GLIBC_ABI_DT_X86_64_PLT > $@; \ - $(evaluate-test) - generated += check-dt-x86-64-plt.out -- --tests-special += $(objpfx)check-gnu2-tls.out -- --$(objpfx)check-gnu2-tls.out: $(common-objpfx)libc.so -- LC_ALL=C $(READELF) -V -W $< \ -- | sed -ne '/.gnu.version_d/, /.gnu.version_r/ p' \ -- | grep GLIBC_ABI_GNU2_TLS > $@; \ -- $(evaluate-test) --generated += check-gnu2-tls.out - endif - - test-internal-extras += tst-gnu2-tls2mod1 -diff --git a/sysdeps/x86_64/Versions b/sysdeps/x86_64/Versions -index 0a759029e5..6a989ad3b3 100644 ---- a/sysdeps/x86_64/Versions -+++ b/sysdeps/x86_64/Versions -@@ -5,11 +5,6 @@ libc { - GLIBC_2.13 { - __fentry__; - } -- GLIBC_ABI_GNU2_TLS { -- # This symbol is used only for empty version map and will be removed -- # by scripts/versions.awk. -- __placeholder_only_for_empty_version_map; -- } - GLIBC_ABI_DT_X86_64_PLT { - # This symbol is used only for empty version map and will be removed - # by scripts/versions.awk. - -commit e34453cd6a8c592c325756ff3c7ac0afd3975cb4 -Author: Pierre Blanchard -Date: Wed Aug 20 17:41:50 2025 +0000 - - AArch64: Fix SVE powf routine [BZ #33299] - - Fix a bug in predicate logic introduced in last change. - A slight performance improvement from relying on all true - predicates during conversion from single to double. - This fixes BZ #33299. - - Reviewed-by: Wilco Dijkstra - (cherry picked from commit aac077645a645bba0d67f3250e82017c539d0f4b) - -diff --git a/sysdeps/aarch64/fpu/powf_sve.c b/sysdeps/aarch64/fpu/powf_sve.c -index 7046990aa1..65e9bd29d9 100644 ---- a/sysdeps/aarch64/fpu/powf_sve.c -+++ b/sysdeps/aarch64/fpu/powf_sve.c -@@ -223,15 +223,15 @@ sv_powf_core (const svbool_t pg, svuint32_t i, svuint32_t iz, svint32_t k, - const svbool_t ptrue = svptrue_b64 (); - - /* Unpack and promote input vectors (pg, y, z, i, k and sign_bias) into two -- * in order to perform core computation in double precision. */ -+ in order to perform core computation in double precision. */ - const svbool_t pg_lo = svunpklo (pg); - const svbool_t pg_hi = svunpkhi (pg); -- svfloat64_t y_lo -- = svcvt_f64_x (pg, svreinterpret_f32 (svunpklo (svreinterpret_u32 (y)))); -- svfloat64_t y_hi -- = svcvt_f64_x (pg, svreinterpret_f32 (svunpkhi (svreinterpret_u32 (y)))); -- svfloat64_t z_lo = svcvt_f64_x (pg, svreinterpret_f32 (svunpklo (iz))); -- svfloat64_t z_hi = svcvt_f64_x (pg, svreinterpret_f32 (svunpkhi (iz))); -+ svfloat64_t y_lo = svcvt_f64_x ( -+ ptrue, svreinterpret_f32 (svunpklo (svreinterpret_u32 (y)))); -+ svfloat64_t y_hi = svcvt_f64_x ( -+ ptrue, svreinterpret_f32 (svunpkhi (svreinterpret_u32 (y)))); -+ svfloat64_t z_lo = svcvt_f64_x (ptrue, svreinterpret_f32 (svunpklo (iz))); -+ svfloat64_t z_hi = svcvt_f64_x (ptrue, svreinterpret_f32 (svunpkhi (iz))); - svuint64_t i_lo = svunpklo (i); - svuint64_t i_hi = svunpkhi (i); - svint64_t k_lo = svunpklo (k); -@@ -312,7 +312,7 @@ svfloat32_t SV_NAME_F2 (pow) (svfloat32_t x, svfloat32_t y, const svbool_t pg) - (23 - V_POWF_EXP2_TABLE_BITS)); - - /* Compute core in extended precision and return intermediate ylogx results -- * to handle cases of underflow and underflow in exp. */ -+ to handle cases of underflow and overflow in exp. */ - svfloat32_t ylogx; - svfloat32_t ret - = sv_powf_core (yint_or_xpos, i, iz, k, y, sign_bias, &ylogx, d); - -commit 1166170d95863e5a6f8121a5ca9d97713f524f49 -Author: Florian Weimer -Date: Fri Sep 5 19:02:57 2025 +0200 - - libio: Define AT_RENAME_* with the same tokens as Linux - - Linux uses different expressions for the RENAME_* and AT_RENAME_* - constants. Mirror that in , so that the macro redefinitions - do not result in preprocessor warnings. - - Reviewed-by: Collin Funk - (cherry picked from commit b173557da978a04ac3bdfc0bd3b0e7ac583b44d5) - -diff --git a/libio/stdio.h b/libio/stdio.h -index d042b36618..e0e70945fa 100644 ---- a/libio/stdio.h -+++ b/libio/stdio.h -@@ -168,11 +168,11 @@ extern int renameat (int __oldfd, const char *__old, int __newfd, - #ifdef __USE_GNU - /* Flags for renameat2. */ - # define RENAME_NOREPLACE (1 << 0) --# define AT_RENAME_NOREPLACE RENAME_NOREPLACE -+# define AT_RENAME_NOREPLACE 0x0001 - # define RENAME_EXCHANGE (1 << 1) --# define AT_RENAME_EXCHANGE RENAME_EXCHANGE -+# define AT_RENAME_EXCHANGE 0x0002 - # define RENAME_WHITEOUT (1 << 2) --# define AT_RENAME_WHITEOUT RENAME_WHITEOUT -+# define AT_RENAME_WHITEOUT 0x0004 - - /* Rename file OLD relative to OLDFD to NEW relative to NEWFD, with - additional flags. */ -diff --git a/stdio-common/tst-renameat2.c b/stdio-common/tst-renameat2.c -index 12aa0f8b0f..6213e1376d 100644 ---- a/stdio-common/tst-renameat2.c -+++ b/stdio-common/tst-renameat2.c -@@ -28,6 +28,12 @@ - #include - #include - -+/* These constants are defined with different token sequences, -+ matching the Linux definitions, to avoid preprocessor warnings. */ -+_Static_assert (RENAME_NOREPLACE == AT_RENAME_NOREPLACE, "RENAME_NOREPLACE"); -+_Static_assert (RENAME_EXCHANGE == AT_RENAME_EXCHANGE, "RENAME_EXCHANGE"); -+_Static_assert (RENAME_WHITEOUT == AT_RENAME_WHITEOUT, "RENAME_WHITEOUT"); -+ - /* Directory with the temporary files. */ - static char *directory; - static int directory_fd; - -commit 46b4e37c9e0619d0cf065ba207c29996b326a06f -Author: Florian Weimer -Date: Fri Sep 12 21:33:34 2025 +0200 - - nss: Group merge does not react to ERANGE during merge (bug 33361) - - The break statement in CHECK_MERGE is expected to exit the surrounding - while loop, not the do-while loop with in the macro. Remove the - do-while loop from the macro. It is not needed to turn the macro - expansion into a single statement due to the way CHECK_MERGE is used - (and the statement expression would cover this anyway). - - Reviewed-by: Collin Funk - (cherry picked from commit 0fceed254559836b57ee05188deac649bc505d05) - -diff --git a/NEWS b/NEWS -index 69aa600c6d..06c27a8e17 100644 ---- a/NEWS -+++ b/NEWS -@@ -13,6 +13,7 @@ The following bugs were resolved with this release: - [32994] stdlib: resolve a double lock init issue after fork - [33234] Use TLS initial-exec model for __libc_tsd_CTYPE_* thread variables - [33245] nptl: nptl: error in internal cancellation syscall handling -+ [33361] nss: Group merge does not react to ERANGE during merge - - Version 2.42 - -diff --git a/nss/getXXbyYY_r.c b/nss/getXXbyYY_r.c -index eae6c3480e..2b0735fb6a 100644 ---- a/nss/getXXbyYY_r.c -+++ b/nss/getXXbyYY_r.c -@@ -157,19 +157,15 @@ __merge_einval (LOOKUP_TYPE *a, - - #define CHECK_MERGE(err, status) \ - ({ \ -- do \ -+ if (err) \ - { \ -- if (err) \ -- { \ -- __set_errno (err); \ -- if (err == ERANGE) \ -- status = NSS_STATUS_TRYAGAIN; \ -- else \ -- status = NSS_STATUS_UNAVAIL; \ -- break; \ -- } \ -+ __set_errno (err); \ -+ if (err == ERANGE) \ -+ status = NSS_STATUS_TRYAGAIN; \ -+ else \ -+ status = NSS_STATUS_UNAVAIL; \ -+ break; \ - } \ -- while (0); \ - }) - - /* Type of the lookup function we need here. */ - -commit 18fd689cdced8348e42991964557cddea0ba2dc5 -Author: Adhemerval Zanella -Date: Mon Sep 8 13:06:13 2025 -0300 - - nptl: Fix MADV_GUARD_INSTALL logic for thread without guard page (BZ 33356) - - The main issue is that setup_stack_prot fails to account for cases where - the cached thread stack lacks a guard page, which can cause madvise to - fail. Update the logic to also handle whether MADV_GUARD_INSTALL is - supported when resizing the guard page. - - Checked on x86_64-linux-gnu with 6.8.0 and 6.15 kernels. - - Reviewed-by: Florian Weimer - (cherry picked from commit 855bfa2566bbefefa27c516b344df58a75824a5c) - -diff --git a/NEWS b/NEWS -index 06c27a8e17..ed3c114c7a 100644 ---- a/NEWS -+++ b/NEWS -@@ -13,6 +13,8 @@ The following bugs were resolved with this release: - [32994] stdlib: resolve a double lock init issue after fork - [33234] Use TLS initial-exec model for __libc_tsd_CTYPE_* thread variables - [33245] nptl: nptl: error in internal cancellation syscall handling -+ [33356] nptl: creating thread stack with guardsize 0 can erroneously -+ conclude MADV_GUARD_INSTALL is available - [33361] nss: Group merge does not react to ERANGE during merge - - Version 2.42 -diff --git a/nptl/allocatestack.c b/nptl/allocatestack.c -index 800ca89720..fb8a60a21d 100644 ---- a/nptl/allocatestack.c -+++ b/nptl/allocatestack.c -@@ -240,7 +240,7 @@ setup_stack_prot (char *mem, size_t size, struct pthread *pd, - /* Update the guard area of the thread stack MEM of size SIZE with the new - GUARDISZE. It uses the method defined by PD stack_mode. */ - static inline bool --adjust_stack_prot (char *mem, size_t size, const struct pthread *pd, -+adjust_stack_prot (char *mem, size_t size, struct pthread *pd, - size_t guardsize, size_t pagesize_m1) - { - /* The required guard area is larger than the current one. For -@@ -258,11 +258,23 @@ adjust_stack_prot (char *mem, size_t size, const struct pthread *pd, - so use the new guard placement with the new size. */ - if (guardsize > pd->guardsize) - { -+ /* There was no need to previously setup a guard page, so we need -+ to check whether the kernel supports guard advise. */ - char *guard = guard_position (mem, size, guardsize, pd, pagesize_m1); -- if (pd->stack_mode == ALLOCATE_GUARD_MADV_GUARD) -- return __madvise (guard, guardsize, MADV_GUARD_INSTALL) == 0; -- else if (pd->stack_mode == ALLOCATE_GUARD_PROT_NONE) -- return __mprotect (guard, guardsize, PROT_NONE) == 0; -+ if (atomic_load_relaxed (&allocate_stack_mode) -+ == ALLOCATE_GUARD_MADV_GUARD) -+ { -+ if (__madvise (guard, guardsize, MADV_GUARD_INSTALL) == 0) -+ { -+ pd->stack_mode = ALLOCATE_GUARD_MADV_GUARD; -+ return true; -+ } -+ atomic_store_relaxed (&allocate_stack_mode, -+ ALLOCATE_GUARD_PROT_NONE); -+ } -+ -+ pd->stack_mode = ALLOCATE_GUARD_PROT_NONE; -+ return __mprotect (guard, guardsize, PROT_NONE) == 0; - } - /* The current guard area is larger than the required one. For - _STACK_GROWS_DOWN is means change the guard as: -diff --git a/nptl/tst-guard1.c b/nptl/tst-guard1.c -index e3e06df0fc..1c73d3fc93 100644 ---- a/nptl/tst-guard1.c -+++ b/nptl/tst-guard1.c -@@ -21,6 +21,7 @@ - #include - #include - #include -+#include - #include - #include - #include -@@ -202,7 +203,7 @@ tf (void *closure) - - /* Test 1: caller provided stack without guard. */ - static void --do_test1 (void) -+do_test1 (void *closure) - { - pthread_attr_t attr; - xpthread_attr_init (&attr); -@@ -227,7 +228,7 @@ do_test1 (void) - - /* Test 2: same as 1., but with a guard area. */ - static void --do_test2 (void) -+do_test2 (void *closure) - { - pthread_attr_t attr; - xpthread_attr_init (&attr); -@@ -250,18 +251,9 @@ do_test2 (void) - xmunmap (stack, stacksize); - } - --/* Test 3: pthread_create with default values. */ -+/* Test 3: pthread_create without a guard area. */ - static void --do_test3 (void) --{ -- pthread_t t = xpthread_create (NULL, tf, NULL); -- void *status = xpthread_join (t); -- TEST_VERIFY (status == 0); --} -- --/* Test 4: pthread_create without a guard area. */ --static void --do_test4 (void) -+do_test3 (void *closure) - { - pthread_attr_t attr; - xpthread_attr_init (&attr); -@@ -277,9 +269,18 @@ do_test4 (void) - xpthread_attr_destroy (&attr); - } - -+/* Test 4: pthread_create with default values. */ -+static void -+do_test4 (void *closure) -+{ -+ pthread_t t = xpthread_create (NULL, tf, NULL); -+ void *status = xpthread_join (t); -+ TEST_VERIFY (status == 0); -+} -+ - /* Test 5: pthread_create with non default stack and guard size value. */ - static void --do_test5 (void) -+do_test5 (void *closure) - { - pthread_attr_t attr; - xpthread_attr_init (&attr); -@@ -299,7 +300,7 @@ do_test5 (void) - test 3, but with a larger guard area. The pthread_create will need to - increase the guard area. */ - static void --do_test6 (void) -+do_test6 (void *closure) - { - pthread_attr_t attr; - xpthread_attr_init (&attr); -@@ -320,7 +321,7 @@ do_test6 (void) - pthread_create should use the cached stack from previous tests, but it - would require to reduce the guard area. */ - static void --do_test7 (void) -+do_test7 (void *closure) - { - pthread_t t = xpthread_create (NULL, tf, NULL); - void *status = xpthread_join (t); -@@ -346,21 +347,40 @@ do_test (void) - - static const struct { - const char *descr; -- void (*test)(void); -+ void (*test) (void *); - } tests[] = { - { "user provided stack without guard", do_test1 }, - { "user provided stack with guard", do_test2 }, -- { "default attribute", do_test3 }, -- { "default attribute without guard", do_test4 }, -+ /* N.B: do_test3 should be before do_test4 to check if a new thread -+ that uses the thread stack previously allocated without a guard -+ page correctly sets up the guard pages even on a kernel without -+ MADV_GUARD_INSTALL support (BZ 33356). */ -+ { "default attribute without guard", do_test3 }, -+ { "default attribute", do_test4 }, -+ /* Also checks if the guard is correctly removed from the cache thread -+ stack. */ -+ { "default attribute without guard", do_test3 }, - { "non default stack and guard sizes", do_test5 }, - { "reused stack with larger guard", do_test6 }, - { "reused stack with smaller guard", do_test7 }, - }; - -+ /* Run each test with a clean state. */ -+ for (int i = 0; i < array_length (tests); i++) -+ { -+ printf ("debug: fork: test%01d: %s\n", i, tests[i].descr); -+ struct support_capture_subprocess result = -+ support_capture_subprocess (tests[i].test, NULL); -+ support_capture_subprocess_check (&result, tests[i].descr, 0, -+ sc_allow_none); -+ support_capture_subprocess_free (&result); -+ } -+ -+ /* And now run the same tests along with the thread stack cache. */ - for (int i = 0; i < array_length (tests); i++) - { - printf ("debug: test%01d: %s\n", i, tests[i].descr); -- tests[i].test(); -+ tests[i].test ( NULL); - } - - return 0; - -commit bf48b17a28066a54f172e0d63da9fc5dc60c6355 -Author: Sunil K Pandey -Date: Mon Oct 6 18:13:04 2025 -0700 - - x86: Detect Intel Wildcat Lake Processor - - Detect Intel Wildcat Lake Processor and tune it similar to Intel Panther - Lake. https://cdrdv2.intel.com/v1/dl/getContent/671368 Section 1.2. - - Reviewed-by: H.J. Lu - (cherry picked from commit f8dd52901b72805a831d5a4cb7d971e4a3c9970b) - -diff --git a/sysdeps/x86/cpu-features.c b/sysdeps/x86/cpu-features.c -index b7d1506135..4bdade883e 100644 ---- a/sysdeps/x86/cpu-features.c -+++ b/sysdeps/x86/cpu-features.c -@@ -543,6 +543,7 @@ enum intel_microarch - INTEL_BIGCORE_PANTHERLAKE, - INTEL_BIGCORE_GRANITERAPIDS, - INTEL_BIGCORE_DIAMONDRAPIDS, -+ INTEL_BIGCORE_WILDCATLAKE, - - /* Mixed (bigcore + atom SOC). */ - INTEL_MIXED_LAKEFIELD, -@@ -702,6 +703,8 @@ intel_get_fam6_microarch (unsigned int model, - return INTEL_BIGCORE_ARROWLAKE; - case 0xCC: - return INTEL_BIGCORE_PANTHERLAKE; -+ case 0xD5: -+ return INTEL_BIGCORE_WILDCATLAKE; - case 0xAD: - case 0xAE: - return INTEL_BIGCORE_GRANITERAPIDS; -@@ -934,6 +937,7 @@ disable_tsx: - case INTEL_BIGCORE_LUNARLAKE: - case INTEL_BIGCORE_ARROWLAKE: - case INTEL_BIGCORE_PANTHERLAKE: -+ case INTEL_BIGCORE_WILDCATLAKE: - case INTEL_BIGCORE_SAPPHIRERAPIDS: - case INTEL_BIGCORE_EMERALDRAPIDS: - case INTEL_BIGCORE_GRANITERAPIDS: - -commit ab8c1b5d62d7be2c3c23f535bea3d7fff19c53ae -Author: Sunil K Pandey -Date: Wed Sep 24 09:38:17 2025 -0700 - - x86: Detect Intel Nova Lake Processor - - Detect Intel Nova Lake Processor and tune it similar to Intel Panther - Lake. https://cdrdv2.intel.com/v1/dl/getContent/671368 Section 1.2. - - Reviewed-by: H.J. Lu - (cherry picked from commit a114e29ddd530962d2b44aa9d89f1f6075abe7fa) - -diff --git a/sysdeps/x86/cpu-features.c b/sysdeps/x86/cpu-features.c -index 4bdade883e..b67ef541dd 100644 ---- a/sysdeps/x86/cpu-features.c -+++ b/sysdeps/x86/cpu-features.c -@@ -544,6 +544,7 @@ enum intel_microarch - INTEL_BIGCORE_GRANITERAPIDS, - INTEL_BIGCORE_DIAMONDRAPIDS, - INTEL_BIGCORE_WILDCATLAKE, -+ INTEL_BIGCORE_NOVALAKE, - - /* Mixed (bigcore + atom SOC). */ - INTEL_MIXED_LAKEFIELD, -@@ -821,6 +822,17 @@ disable_tsx: - break; - } - } -+ else if (family == 18) -+ switch (model) -+ { -+ case 0x01: -+ case 0x03: -+ microarch = INTEL_BIGCORE_NOVALAKE; -+ break; -+ -+ default: -+ break; -+ } - else if (family == 19) - switch (model) - { -@@ -938,6 +950,7 @@ disable_tsx: - case INTEL_BIGCORE_ARROWLAKE: - case INTEL_BIGCORE_PANTHERLAKE: - case INTEL_BIGCORE_WILDCATLAKE: -+ case INTEL_BIGCORE_NOVALAKE: - case INTEL_BIGCORE_SAPPHIRERAPIDS: - case INTEL_BIGCORE_EMERALDRAPIDS: - case INTEL_BIGCORE_GRANITERAPIDS: - -commit 6de12fc9ad56bc19fa6fcbd8ee502f29b5170d47 -Author: Yury Khrustalev -Date: Thu Sep 25 15:51:30 2025 +0100 - - aarch64: define macro for calling __libc_arm_za_disable - - A common sequence of instructions is used in several places - in assembly files, so define it in one place as an assembly - macro. - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit b4b713bd8921aff04773557da94fabb5fb9dd705) - -diff --git a/sysdeps/aarch64/__longjmp.S b/sysdeps/aarch64/__longjmp.S -index 70ac02c44b..53b42e1bdc 100644 ---- a/sysdeps/aarch64/__longjmp.S -+++ b/sysdeps/aarch64/__longjmp.S -@@ -26,16 +26,8 @@ - ENTRY (__longjmp) - - #if IS_IN(libc) -- /* Disable ZA state of SME in libc.a and libc.so, but not in ld.so. -- The calling convention of __libc_arm_za_disable allows to do -- this thus allowing to avoid saving to and reading from stack. -- As a result we also don't need to sign the return address and -- check it after returning because it is not stored to stack. */ -- mov x13, x30 -- cfi_register (x30, x13) -- bl __libc_arm_za_disable -- mov x30, x13 -- cfi_register (x13, x30) -+ /* Disable ZA state of SME in libc.a and libc.so, but not in ld.so. */ -+ CALL_LIBC_ARM_ZA_DISABLE - #endif - - cfi_def_cfa (x0, 0) -diff --git a/sysdeps/aarch64/setjmp.S b/sysdeps/aarch64/setjmp.S -index 53c5e7d8cc..92cedfad83 100644 ---- a/sysdeps/aarch64/setjmp.S -+++ b/sysdeps/aarch64/setjmp.S -@@ -37,16 +37,8 @@ ENTRY_ALIGN (__sigsetjmp, 2) - 1: - - #if IS_IN(libc) -- /* Disable ZA state of SME in libc.a and libc.so, but not in ld.so. -- The calling convention of __libc_arm_za_disable allows to do -- this thus allowing to avoid saving to and reading from stack. -- As a result we also don't need to sign the return address and -- check it after returning because it is not stored to stack. */ -- mov x13, x30 -- cfi_register (x30, x13) -- bl __libc_arm_za_disable -- mov x30, x13 -- cfi_register (x13, x30) -+ /* Disable ZA state of SME in libc.a and libc.so, but not in ld.so. */ -+ CALL_LIBC_ARM_ZA_DISABLE - #endif - - stp x19, x20, [x0, #JB_X19<<3] -diff --git a/sysdeps/unix/sysv/linux/aarch64/setcontext.S b/sysdeps/unix/sysv/linux/aarch64/setcontext.S -index d9716f012e..8e98594663 100644 ---- a/sysdeps/unix/sysv/linux/aarch64/setcontext.S -+++ b/sysdeps/unix/sysv/linux/aarch64/setcontext.S -@@ -49,15 +49,7 @@ ENTRY (__setcontext) - b C_SYMBOL_NAME (__syscall_error) - 1: - /* Clear ZA state of SME. */ -- /* The calling convention of __libc_arm_za_disable allows to do -- this thus allowing to avoid saving to and reading from stack. -- As a result we also don't need to sign the return address and -- check it after returning because it is not stored to stack. */ -- mov x13, x30 -- cfi_register (x30, x13) -- bl __libc_arm_za_disable -- mov x30, x13 -- cfi_register (x13, x30) -+ CALL_LIBC_ARM_ZA_DISABLE - /* Restore the general purpose registers. */ - mov x0, x9 - cfi_def_cfa (x0, 0) -diff --git a/sysdeps/unix/sysv/linux/aarch64/sysdep.h b/sysdeps/unix/sysv/linux/aarch64/sysdep.h -index f0e8d64eef..fa01386b25 100644 ---- a/sysdeps/unix/sysv/linux/aarch64/sysdep.h -+++ b/sysdeps/unix/sysv/linux/aarch64/sysdep.h -@@ -150,6 +150,18 @@ - mov x8, SYS_ify (syscall_name); \ - svc 0 - -+/* Clear ZA state of SME (ASM version). */ -+/* The __libc_arm_za_disable function has special calling convention -+ that allows to call it without stack manipulation and preserving -+ most of the registers. */ -+ .macro CALL_LIBC_ARM_ZA_DISABLE -+ mov x13, x30 -+ .cfi_register x30, x13 -+ bl __libc_arm_za_disable -+ mov x30, x13 -+ .cfi_register x13, x30 -+ .endm -+ - #else /* not __ASSEMBLER__ */ - - # define VDSO_NAME "LINUX_2.6.39" - -commit 256030b9842a10b1f22851b1de0c119761417544 -Author: Yury Khrustalev -Date: Thu Sep 25 15:54:36 2025 +0100 - - aarch64: clear ZA state of SME before clone and clone3 syscalls - - This change adds a call to the __arm_za_disable() function immediately - before the SVC instruction inside clone() and clone3() wrappers. It also - adds a macro for inline clone() used in fork() and adds the same call to - the vfork implementation. This sets the ZA state of SME to "off" on return - from these functions (for both the child and the parent). - - The __arm_za_disable() function is described in [1] (8.1.3). Note that - the internal Glibc name for this function is __libc_arm_za_disable(). - - When this change was originally proposed [2,3], it generated a long - discussion where several questions and concerns were raised. Here we - will address these concerns and explain why this change is useful and, - in fact, necessary. - - In a nutshell, a C library that conforms to the AAPCS64 spec [1] (pertinent - to this change, mainly, the chapters 6.2 and 6.6), should have a call to the - __arm_za_disable() function in clone() and clone3() wrappers. The following - explains in detail why this is the case. - - When we consider using the __arm_za_disable() function inside the clone() - and clone3() libc wrappers, we talk about the C library subroutines clone() - and clone3() rather than the syscalls with similar names. In the current - version of Glibc, clone() is public and clone3() is private, but it being - private is not pertinent to this discussion. - - We will begin with stating that this change is NOT a bug fix for something - in the kernel. The requirement to call __arm_za_disable() does NOT come from - the kernel. It also is NOT needed to satisfy a contract between the kernel - and userspace. This is why it is not for the kernel documentation to describe - this requirement. This requirement is instead needed to satisfy a pure userspace - scheme outlined in [1] and to make sure that software that uses Glibc (or any - other C library that has correct handling of SME states (see below)) conforms - to [1] without having to unnecessarily become SME-aware thus losing portability. - - To recap (see [1] (6.2)), SME extension defines SME state which is part of - processor state. Part of this SME state is ZA state that is necessary to - manage ZA storage register in the context of the ZA lazy saving scheme [1] - (6.6). This scheme exists because it would be challenging to handle ZA - storage of SME in either callee-saved or caller-saved manner. - - There are 3 kinds of ZA state that are defined in terms of the PSTATE.ZA - bit and the TPIDR2_EL0 register (see [1] (6.6.3)): - - - "off":       PSTATE.ZA == 0 - - "active":    PSTATE.ZA == 1 TPIDR2_EL0 == null - - "dormant":   PSTATE.ZA == 1 TPIDR2_EL0 != null - - As [1] (6.7.2) outlines, every subroutine has exactly one SME-interface - depending on the permitted ZA-states on entry and on normal return from - a call to this subroutine. Callers of a subroutine must know and respect - the ZA-interface of the subroutines they are using. Using a subroutine - in a way that is not permitted by its ZA-interface is undefined behaviour. - - In particular, clone() and clone3() (the C library functions) have the - ZA-private interface. This means that the permitted ZA-states on entry - are "off" and "dormant" and that the permitted states on return are "off" - or "dormant" (but if and only if it was "dormant" on entry). - - This means that both functions in question should correctly handle both - "off" and "dormant" ZA-states on entry. The conforming states on return - are "off" and "dormant" (if inbound state was already "dormant"). - - This change ensures that the ZA-state on return is always "off". Note, - that, in the context of clone() and clone3(), "on return" means a point - when execution resumes at certain address after transferring from clone() - or clone3(). For the caller (we may refer to it as "parent") this is the - return address in the link register where the RET instruction jumps. For - the "child", this is the target branch address. - - So, the "off" state on return is permitted and conformant. Why can't we - retain the "dormant" state? In theory, we can, but we shouldn't, here is - why. - - Every subroutine with a private-ZA interface, including clone() and clone3(), - must comply with the lazy saving scheme [1] (6.7.2). This puts additional - responsibility on a subroutine if ZA-state on return is "dormant" because - this state has special meaning. The "caller" (that is the place in code - where execution is transferred to, so this include both "parent" and "child") - may check the ZA-state and use it as per the spec of the "dormant" state that - is outlined in [1] (6.6.6 and 6.6.7). - - Conforming to this would require more code inside of clone() and clone3() - which hardly is desirable. - - For the return to "parent" this could be achieved in theory, but given that - neither clone() nor clone3() are supposed to be used in the middle of an - SME operation, if wouldn't be useful. For the "return" to "child" this - would be particularly difficult to achieve given the complexity of these - functions and their interfaces. Most importantly, it would be illegal - and somewhat meaningless to allow a "child" to start execution in the - "dormant" ZA-state because the very essence of the "dormant" state implies - that there is a place to return and that there is some outer context that - we are allowed to interact with. - - To sum up, calling __arm_za_disable() to ensure the "off" ZA-state when the - execution resumes after a call to clone() or clone3() is correct and also - the most simple way to conform to [1]. - - Can there be situations when we can avoid calling __arm_za_disable()? - - Calling __arm_za_disable() implies certain (sufficiently small) overhead, - so one might rightly ponder avoiding making a call to this function when - we can afford not to. The most trivial cases like this (e.g. when the - calling thread doesn't have access to SME or to the TPIDR2_EL0 register) - are already handled by this function (see [1] (8.1.3 and 8.1.2)). Reasoning - about other possible use cases would require making code inside clone() and - clone3() more complicated and it would defeat the point of trying to make - an optimisation of not calling __arm_za_disable(). - - Why can't the kernel do this instead? - - The handling of SME state by the kernel is described in [4]. In short, - kernel must not impose a specific ZA-interface onto a userspace function. - Interaction with the kernel happens (among other thing) via system calls. - In Glibc many of the system calls (notably, including SYS_clone and - SYS_clone3) are used via wrappers, and the kernel has no control of them - and, moreover, it cannot dictate how these wrappers should behave because - it is simply outside of the kernel's remit. - - However, in certain cases, the kernel may ensure that a "child" doesn't - start in an incorrect state. This is what is done by the recent change - included in 6.16 kernel [5]. This is not enough to ensure that code that - uses clone() and clone3() function conforms to [1] when it runs on a - system that provides SME, hence this change. - - [1]: https://github.com/ARM-software/abi-aa/blob/main/aapcs64/aapcs64.rst - [2]: https://inbox.sourceware.org/libc-alpha/20250522114828.2291047-1-yury.khrustalev@arm.com - [3]: https://inbox.sourceware.org/libc-alpha/20250609121407.3316070-1-yury.khrustalev@arm.com - [4]: https://www.kernel.org/doc/html/v6.16/arch/arm64/sme.html - [5]: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=cde5c32db55740659fca6d56c09b88800d88fd29 - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 27effb3d50424fb9634be77a2acd614b0386ff25) - -diff --git a/sysdeps/unix/sysv/linux/aarch64/clone.S b/sysdeps/unix/sysv/linux/aarch64/clone.S -index 40015c6933..53f1efd728 100644 ---- a/sysdeps/unix/sysv/linux/aarch64/clone.S -+++ b/sysdeps/unix/sysv/linux/aarch64/clone.S -@@ -45,6 +45,9 @@ ENTRY(__clone) - and x1, x1, -16 - cbz x1, .Lsyscall_error - -+ /* Clear ZA state of SME. */ -+ CALL_LIBC_ARM_ZA_DISABLE -+ - /* Do the system call. */ - /* X0:flags, x1:newsp, x2:parenttidptr, x3:newtls, x4:childtid. */ - mov x0, x2 /* flags */ -diff --git a/sysdeps/unix/sysv/linux/aarch64/clone3.S b/sysdeps/unix/sysv/linux/aarch64/clone3.S -index c9ca845ef2..bc978b7e10 100644 ---- a/sysdeps/unix/sysv/linux/aarch64/clone3.S -+++ b/sysdeps/unix/sysv/linux/aarch64/clone3.S -@@ -46,6 +46,9 @@ ENTRY(__clone3) - cbz x10, .Lsyscall_error /* No NULL cl_args pointer. */ - cbz x2, .Lsyscall_error /* No NULL function pointer. */ - -+ /* Clear ZA state of SME. */ -+ CALL_LIBC_ARM_ZA_DISABLE -+ - /* Do the system call, the kernel expects: - x8: system call number - x0: cl_args -diff --git a/sysdeps/unix/sysv/linux/aarch64/sysdep.h b/sysdeps/unix/sysv/linux/aarch64/sysdep.h -index fa01386b25..30003c0145 100644 ---- a/sysdeps/unix/sysv/linux/aarch64/sysdep.h -+++ b/sysdeps/unix/sysv/linux/aarch64/sysdep.h -@@ -242,6 +242,31 @@ - #undef HAVE_INTERNAL_BRK_ADDR_SYMBOL - #define HAVE_INTERNAL_BRK_ADDR_SYMBOL 1 - -+/* Clear ZA state of SME (C version). */ -+/* The __libc_arm_za_disable function has special calling convention -+ that allows to call it without stack manipulation and preserving -+ most of the registers. */ -+#define CALL_LIBC_ARM_ZA_DISABLE() \ -+({ \ -+ unsigned long int __tmp; \ -+ asm volatile ( \ -+ " mov %0, x30\n" \ -+ " .cfi_register x30, %0\n" \ -+ " bl __libc_arm_za_disable\n" \ -+ " mov x30, %0\n" \ -+ " .cfi_register %0, x30\n" \ -+ : "=r" (__tmp) \ -+ : \ -+ : "x14", "x15", "x16", "x17", "x18", "memory" ); \ -+}) -+ -+/* Do clear ZA state of SME before making normal clone syscall. */ -+#define INLINE_CLONE_SYSCALL(a0, a1, a2, a3, a4) \ -+({ \ -+ CALL_LIBC_ARM_ZA_DISABLE (); \ -+ INLINE_SYSCALL_CALL (clone, a0, a1, a2, a3, a4); \ -+}) -+ - #endif /* __ASSEMBLER__ */ - - #endif /* linux/aarch64/sysdep.h */ -diff --git a/sysdeps/unix/sysv/linux/aarch64/vfork.S b/sysdeps/unix/sysv/linux/aarch64/vfork.S -index d5943a7485..2600bc9be3 100644 ---- a/sysdeps/unix/sysv/linux/aarch64/vfork.S -+++ b/sysdeps/unix/sysv/linux/aarch64/vfork.S -@@ -27,6 +27,9 @@ - - ENTRY (__vfork) - -+ /* Clear ZA state of SME. */ -+ CALL_LIBC_ARM_ZA_DISABLE -+ - mov x0, #0x4111 /* CLONE_VM | CLONE_VFORK | SIGCHLD */ - mov x1, sp - DO_CALL (clone, 2) - -commit 71874f167aa5bb1538ff7e394beaacee28ebe65f -Author: Yury Khrustalev -Date: Fri Sep 26 10:03:45 2025 +0100 - - aarch64: tests for SME - - This commit adds tests for the following use cases relevant to handing of - the SME state: - - - fork() and vfork() - - clone() and clone3() - - signal handler - - While most cases are trivial, the case of clone3() is more complicated since - the clone3() symbol is not public in Glibc. - - To avoid having to check all possible ways clone3() may be called via other - public functions (e.g. vfork() or pthread_create()), we put together a test - that links directly with clone3.o. All the existing functions that have calls - to clone3() may not actually use it, in which case the outcome of such tests - would be unexpected. Having a direct call to the clone3() symbol in the test - allows to check precisely what we need to test: that the __arm_za_disable() - function is indeed called and has the desired effect. - - Linking to clone3.o also requires linking to __arm_za_disable.o that in - turn requires the _dl_hwcap2 hidden symbol which to provide in the test - and initialise it before using. - - Co-authored-by: Adhemerval Zanella Netto - Reviewed-by: Adhemerval Zanella - (cherry picked from commit ecb0fc2f0f839f36cd2a106283142c9df8ea8214) - -diff --git a/sysdeps/aarch64/Makefile b/sysdeps/aarch64/Makefile -index bb97d31355..9479fb9679 100644 ---- a/sysdeps/aarch64/Makefile -+++ b/sysdeps/aarch64/Makefile -@@ -79,8 +79,18 @@ sysdep_routines += \ - - tests += \ - tst-sme-jmp \ -+ tst-sme-signal \ - tst-sme-za-state \ - # tests -+tests-internal += \ -+ tst-sme-clone \ -+ tst-sme-clone3 \ -+ tst-sme-fork \ -+ tst-sme-vfork \ -+ # tests-internal -+ -+$(objpfx)tst-sme-clone3: $(objpfx)clone3.o $(objpfx)__arm_za_disable.o -+ - endif - - ifeq ($(subdir),malloc) -diff --git a/sysdeps/aarch64/tst-sme-clone.c b/sysdeps/aarch64/tst-sme-clone.c -new file mode 100644 -index 0000000000..7106ec7926 ---- /dev/null -+++ b/sysdeps/aarch64/tst-sme-clone.c -@@ -0,0 +1,53 @@ -+/* Test that ZA state of SME is cleared in both parent and child -+ when clone() syscall is used. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include "tst-sme-skeleton.c" -+ -+#include -+ -+static int -+fun (void * const arg) -+{ -+ printf ("in child: %s\n", (const char *)arg); -+ /* Check that ZA state of SME was disabled in child. */ -+ check_sme_za_state ("after clone in child", /* Clear. */ true); -+ return 0; -+} -+ -+static char __attribute__((aligned(16))) -+stack[1024 * 1024]; -+ -+static void -+run (struct blk *ptr) -+{ -+ char *syscall_name = (char *)"clone"; -+ printf ("in parent: before %s\n", syscall_name); -+ -+ /* Enabled ZA state so that effect of disabling be observable. */ -+ enable_sme_za_state (ptr); -+ check_sme_za_state ("before clone", /* Clear. */ false); -+ -+ pid_t pid = xclone (fun, syscall_name, stack, sizeof (stack), -+ CLONE_NEWUSER | CLONE_NEWNS | SIGCHLD); -+ -+ /* Check that ZA state of SME was disabled in parent. */ -+ check_sme_za_state ("after clone in parent", /* Clear. */ true); -+ -+ TEST_VERIFY (xwaitpid (pid, NULL, 0) == pid); -+} -diff --git a/sysdeps/aarch64/tst-sme-clone3.c b/sysdeps/aarch64/tst-sme-clone3.c -new file mode 100644 -index 0000000000..402b040cfd ---- /dev/null -+++ b/sysdeps/aarch64/tst-sme-clone3.c -@@ -0,0 +1,84 @@ -+/* Test that ZA state of SME is cleared in both parent and child -+ when clone3() syscall is used. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include "tst-sme-skeleton.c" -+ -+#include -+ -+#include -+#include -+#include -+ -+/* Since clone3 is not a public symbol, we link this test explicitly -+ with clone3.o and have to provide this declaration. */ -+int __clone3 (struct clone_args *cl_args, size_t size, -+ int (*func)(void *arg), void *arg); -+ -+static int -+fun (void * const arg) -+{ -+ printf ("in child: %s\n", (const char *)arg); -+ /* Check that ZA state of SME was disabled in child. */ -+ check_sme_za_state ("after clone3 in child", /* Clear. */ true); -+ return 0; -+} -+ -+static char __attribute__((aligned(16))) -+stack[1024 * 1024]; -+ -+/* Required by __arm_za_disable.o and provided by the startup code -+ as a hidden symbol. */ -+uint64_t _dl_hwcap2; -+ -+static void -+run (struct blk *ptr) -+{ -+ _dl_hwcap2 = getauxval (AT_HWCAP2); -+ -+ char *syscall_name = (char *)"clone3"; -+ struct clone_args args = { -+ .flags = CLONE_VM | CLONE_VFORK, -+ .exit_signal = SIGCHLD, -+ .stack = (uintptr_t) stack, -+ .stack_size = sizeof (stack), -+ }; -+ printf ("in parent: before %s\n", syscall_name); -+ -+ /* Enabled ZA state so that effect of disabling be observable. */ -+ enable_sme_za_state (ptr); -+ check_sme_za_state ("before clone3", /* Clear. */ false); -+ -+ pid_t pid = __clone3 (&args, sizeof (args), fun, syscall_name); -+ -+ /* Check that ZA state of SME was disabled in parent. */ -+ check_sme_za_state ("after clone3 in parent", /* Clear. */ true); -+ -+ printf ("%s child pid: %d\n", syscall_name, pid); -+ -+ xwaitpid (pid, NULL, 0); -+ printf ("in parent: after %s\n", syscall_name); -+} -+ -+/* Workaround to simplify linking with clone3.o. */ -+void __syscall_error(int code) -+{ -+ int err = -code; -+ fprintf (stderr, "syscall error %d (%s)\n", err, strerror (err)); -+ exit (err); -+} -diff --git a/sysdeps/aarch64/tst-sme-fork.c b/sysdeps/aarch64/tst-sme-fork.c -new file mode 100644 -index 0000000000..b003b08884 ---- /dev/null -+++ b/sysdeps/aarch64/tst-sme-fork.c -@@ -0,0 +1,43 @@ -+/* Test that ZA state of SME is cleared in both parent and child -+ when fork() function is used. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include "tst-sme-skeleton.c" -+ -+static void -+run (struct blk *blk) -+{ -+ /* Enabled ZA state so that effect of disabling be observable. */ -+ enable_sme_za_state (blk); -+ check_sme_za_state ("before fork", /* Clear. */ false); -+ fflush (stdout); -+ -+ pid_t pid = xfork (); -+ -+ if (pid == 0) -+ { -+ /* Check that ZA state of SME was disabled in child. */ -+ check_sme_za_state ("after fork in child", /* Clear. */ true); -+ exit (0); -+ } -+ -+ /* Check that ZA state of SME was disabled in parent. */ -+ check_sme_za_state ("after fork in parent", /* Clear. */ true); -+ -+ TEST_VERIFY (xwaitpid (pid, NULL, 0) == pid); -+} -diff --git a/sysdeps/aarch64/tst-sme-helper.h b/sysdeps/aarch64/tst-sme-helper.h -index f049416c2b..ab9c503e45 100644 ---- a/sysdeps/aarch64/tst-sme-helper.h -+++ b/sysdeps/aarch64/tst-sme-helper.h -@@ -16,9 +16,6 @@ - License along with the GNU C Library; if not, see - . */ - --/* Streaming SVE vector register size. */ --static unsigned long svl; -- - struct blk { - void *za_save_buffer; - uint16_t num_za_save_slices; -@@ -68,10 +65,10 @@ start_za (void) - - /* Load data into ZA byte by byte from p. */ - static void __attribute__ ((noinline)) --load_za (const void *p) -+load_za (const void *buf, unsigned long svl) - { - register unsigned long x15 asm ("x15") = 0; -- register unsigned long x16 asm ("x16") = (unsigned long)p; -+ register unsigned long x16 asm ("x16") = (unsigned long)buf; - register unsigned long x17 asm ("x17") = svl; - - asm volatile ( -diff --git a/sysdeps/aarch64/tst-sme-jmp.c b/sysdeps/aarch64/tst-sme-jmp.c -index 103897ad36..b2d21c6e1a 100644 ---- a/sysdeps/aarch64/tst-sme-jmp.c -+++ b/sysdeps/aarch64/tst-sme-jmp.c -@@ -29,6 +29,9 @@ - - #include "tst-sme-helper.h" - -+/* Streaming SVE vector register size. */ -+static unsigned long svl; -+ - static uint8_t *za_orig; - static uint8_t *za_dump; - static uint8_t *za_save; -@@ -82,7 +85,7 @@ longjmp_test (void) - FAIL_EXIT1 ("svcr != 0: %lu", svcr); - set_tpidr2 (&blk); - start_za (); -- load_za (za_orig); -+ load_za (za_orig, svl); - - print_data ("za save space", za_save); - p = get_tpidr2 (); -@@ -131,7 +134,7 @@ setcontext_test (void) - FAIL_EXIT1 ("svcr != 0: %lu", svcr); - set_tpidr2 (&blk); - start_za (); -- load_za (za_orig); -+ load_za (za_orig, svl); - - print_data ("za save space", za_save); - p = get_tpidr2 (); -diff --git a/sysdeps/aarch64/tst-sme-signal.c b/sysdeps/aarch64/tst-sme-signal.c -new file mode 100644 -index 0000000000..b4b07bcc44 ---- /dev/null -+++ b/sysdeps/aarch64/tst-sme-signal.c -@@ -0,0 +1,115 @@ -+/* Test handling of SME state in a signal handler. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include "tst-sme-skeleton.c" -+ -+#include -+ -+static struct _aarch64_ctx * -+extension (void *p) -+{ -+ return p; -+} -+ -+#ifndef TPIDR2_MAGIC -+#define TPIDR2_MAGIC 0x54504902 -+#endif -+ -+#ifndef ZA_MAGIC -+#define ZA_MAGIC 0x54366345 -+#endif -+ -+#ifndef ZT_MAGIC -+#define ZT_MAGIC 0x5a544e01 -+#endif -+ -+#ifndef EXTRA_MAGIC -+#define EXTRA_MAGIC 0x45585401 -+#endif -+ -+/* We use a pipe to make sure that the final check of the SME state -+ happens after signal handler finished. */ -+static int pipefd[2]; -+ -+#define WRITE(msg) xwrite (1, msg, sizeof (msg)); -+ -+static void -+handler (int signo, siginfo_t *si, void *ctx) -+{ -+ TEST_VERIFY (signo == SIGUSR1); -+ WRITE ("in the handler\n"); -+ check_sme_za_state ("during signal", true /* State is clear. */); -+ ucontext_t *uc = ctx; -+ void *p = uc->uc_mcontext.__reserved; -+ unsigned int found = 0; -+ uint32_t m; -+ while ((m = extension (p)->magic)) -+ { -+ if (m == TPIDR2_MAGIC) -+ { -+ WRITE ("found TPIDR2_MAGIC\n"); -+ found += 1; -+ } -+ if (m == ZA_MAGIC) -+ { -+ WRITE ("found ZA_MAGIC\n"); -+ found += 1; -+ } -+ if (m == ZT_MAGIC) -+ { -+ WRITE ("found ZT_MAGIC\n"); -+ found += 1; -+ } -+ if (m == EXTRA_MAGIC) -+ { -+ WRITE ("found EXTRA_MAGIC\n"); -+ struct { struct _aarch64_ctx h; uint64_t data; } *e = p; -+ p = (char *)e->data; -+ continue; -+ } -+ p = (char *)p + extension (p)->size; -+ } -+ TEST_COMPARE (found, 3); -+ -+ /* Signal that the wait is over (see below). */ -+ char message = '\0'; -+ xwrite (pipefd[1], &message, 1); -+} -+ -+static void -+run (struct blk *blk) -+{ -+ xpipe (pipefd); -+ -+ struct sigaction sigact; -+ sigemptyset (&sigact.sa_mask); -+ sigact.sa_flags = 0; -+ sigact.sa_flags |= SA_SIGINFO; -+ sigact.sa_sigaction = handler; -+ xsigaction (SIGUSR1, &sigact, NULL); -+ -+ enable_sme_za_state (blk); -+ check_sme_za_state ("before signal", false /* State is not clear. */); -+ xraise (SIGUSR1); -+ -+ /* Wait for signal handler to complete. */ -+ char response; -+ xread (pipefd[0], &response, 1); -+ -+ check_sme_za_state ("after signal", false /* State is not clear. */); -+} -diff --git a/sysdeps/aarch64/tst-sme-skeleton.c b/sysdeps/aarch64/tst-sme-skeleton.c -new file mode 100644 -index 0000000000..ba84dda1cb ---- /dev/null -+++ b/sysdeps/aarch64/tst-sme-skeleton.c -@@ -0,0 +1,101 @@ -+/* Template for SME tests. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+ -+#include -+#include -+#include -+#include -+#include -+ -+#include "tst-sme-helper.h" -+ -+/* Streaming SVE vector register size. */ -+static unsigned long svl; -+ -+static uint8_t *state; -+ -+static void -+enable_sme_za_state (struct blk *blk) -+{ -+ start_za (); -+ set_tpidr2 (blk); -+ load_za (blk, svl); -+} -+ -+/* Check if SME state is disabled (when CLEAR is true) or -+ enabled (when CLEAR is false). */ -+static void -+check_sme_za_state (const char msg[], bool clear) -+{ -+ unsigned long svcr = get_svcr (); -+ void *tpidr2 = get_tpidr2 (); -+ printf ("[%s]\n", msg); -+ printf ("svcr = %016lx\n", svcr); -+ printf ("tpidr2 = %016lx\n", (unsigned long)tpidr2); -+ if (clear) -+ { -+ TEST_VERIFY (svcr == 0); -+ TEST_VERIFY (tpidr2 == NULL); -+ } -+ else -+ { -+ TEST_VERIFY (svcr != 0); -+ TEST_VERIFY (tpidr2 != NULL); -+ } -+} -+ -+/* Should be defined in actual test that includes this -+ skeleton file. */ -+static void -+run (struct blk *ptr); -+ -+static int -+do_test (void) -+{ -+ unsigned long hwcap2 = getauxval (AT_HWCAP2); -+ if ((hwcap2 & HWCAP2_SME) == 0) -+ return EXIT_UNSUPPORTED; -+ -+ /* Get current streaming SVE vector length in bytes. */ -+ svl = get_svl (); -+ printf ("svl: %lu\n", svl); -+ -+ TEST_VERIFY_EXIT (!(svl < 16 || svl % 16 != 0 || svl >= (1 << 16))); -+ -+ /* Initialise buffer for ZA state of SME. */ -+ state = xmalloc (svl * svl); -+ memset (state, 1, svl * svl); -+ struct blk blk = { -+ .za_save_buffer = state, -+ .num_za_save_slices = svl, -+ .__reserved = {0}, -+ }; -+ -+ run (&blk); -+ -+ free (state); -+ return 0; -+} -+ -+#include -diff --git a/sysdeps/aarch64/tst-sme-vfork.c b/sysdeps/aarch64/tst-sme-vfork.c -new file mode 100644 -index 0000000000..3feea065e5 ---- /dev/null -+++ b/sysdeps/aarch64/tst-sme-vfork.c -@@ -0,0 +1,43 @@ -+/* Test that ZA state of SME is cleared in both parent and child -+ when vfork() function is used. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include "tst-sme-skeleton.c" -+ -+static void -+run (struct blk *blk) -+{ -+ /* Enabled ZA state so that effect of disabling be observable. */ -+ enable_sme_za_state (blk); -+ check_sme_za_state ("before vfork", /* Clear. */ false); -+ fflush (stdout); -+ -+ pid_t pid = vfork (); -+ -+ if (pid == 0) -+ { -+ /* Check that ZA state of SME was disabled in child. */ -+ check_sme_za_state ("after vfork in child", /* Clear. */ true); -+ _exit (0); -+ } -+ -+ /* Check that ZA state of SME was disabled in parent. */ -+ check_sme_za_state ("after vfork in parent", /* Clear. */ true); -+ -+ TEST_VERIFY (xwaitpid (pid, NULL, 0) == pid); -+} -diff --git a/sysdeps/aarch64/tst-sme-za-state.c b/sysdeps/aarch64/tst-sme-za-state.c -index 63f6eebeb4..00118ef506 100644 ---- a/sysdeps/aarch64/tst-sme-za-state.c -+++ b/sysdeps/aarch64/tst-sme-za-state.c -@@ -16,47 +16,9 @@ - License along with the GNU C Library; if not, see - . */ - --#include --#include --#include --#include --#include -- --#include --#include --#include -- --#include "tst-sme-helper.h" -- --static uint8_t *state; -- --static void --enable_sme_za_state (struct blk *ptr) --{ -- set_tpidr2 (ptr); -- start_za (); -- load_za (state); --} -+#include "tst-sme-skeleton.c" - --static void --check_sme_za_state (const char msg[], bool clear) --{ -- unsigned long svcr = get_svcr (); -- void *tpidr2 = get_tpidr2 (); -- printf ("[%s]\n", msg); -- printf ("svcr = %016lx\n", svcr); -- printf ("tpidr2 = %016lx\n", (unsigned long)tpidr2); -- if (clear) -- { -- TEST_VERIFY (svcr == 0); -- TEST_VERIFY (tpidr2 == NULL); -- } -- else -- { -- TEST_VERIFY (svcr != 0); -- TEST_VERIFY (tpidr2 != NULL); -- } --} -+#include - - static void - run (struct blk *ptr) -@@ -88,32 +50,3 @@ run (struct blk *ptr) - TEST_COMPARE (ret, 42); - check_sme_za_state ("after longjmp", /* Clear. */ true); - } -- --static int --do_test (void) --{ -- unsigned long hwcap2 = getauxval (AT_HWCAP2); -- if ((hwcap2 & HWCAP2_SME) == 0) -- return EXIT_UNSUPPORTED; -- -- /* Get current streaming SVE vector register size. */ -- svl = get_svl (); -- printf ("svl: %lu\n", svl); -- TEST_VERIFY_EXIT (!(svl < 16 || svl % 16 != 0 || svl >= (1 << 16))); -- -- /* Initialise buffer for ZA state of SME. */ -- state = xmalloc (svl * svl); -- memset (state, 1, svl * svl); -- struct blk blk = { -- .za_save_buffer = state, -- .num_za_save_slices = svl, -- .__reserved = {0}, -- }; -- -- run (&blk); -- -- free (state); -- return 0; --} -- --#include - -commit bf499c2a4964bddc25a006ec1402f8996d78c6ff -Author: Jiamei Xie -Date: Tue Oct 14 20:14:11 2025 +0800 - - x86: fix wmemset ifunc stray '!' (bug 33542) - - The ifunc selector for wmemset had a stray '!' in the - X86_ISA_CPU_FEATURES_ARCH_P(...) check: - - if (X86_ISA_CPU_FEATURE_USABLE_P (cpu_features, AVX2) - && X86_ISA_CPU_FEATURES_ARCH_P (cpu_features, - AVX_Fast_Unaligned_Load, !)) - - This effectively negated the predicate and caused the AVX2/AVX512 - paths to be skipped, making the dispatcher fall back to the SSE2 - implementation even on CPUs where AVX2/AVX512 are available. The - regression leads to noticeable throughput loss for wmemset. - - Remove the stray '!' so the AVX_Fast_Unaligned_Load capability is - tested as intended and the correct AVX2/EVEX variants are selected. - - Impact: - - On AVX2/AVX512-capable x86_64, wmemset no longer incorrectly - falls back to SSE2; perf now shows __wmemset_evex/avx2 variants. - - Testing: - - benchtests/bench-wmemset shows improved bandwidth across sizes. - - perf confirm the selected symbol is no longer SSE2. - - Signed-off-by: xiejiamei - Signed-off-by: Li jing - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 4d86b6cdd8132e0410347e07262239750f86dfb4) - -diff --git a/sysdeps/x86_64/multiarch/ifunc-wmemset.h b/sysdeps/x86_64/multiarch/ifunc-wmemset.h -index f95cca6ae5..50af138230 100644 ---- a/sysdeps/x86_64/multiarch/ifunc-wmemset.h -+++ b/sysdeps/x86_64/multiarch/ifunc-wmemset.h -@@ -35,7 +35,7 @@ IFUNC_SELECTOR (void) - - if (X86_ISA_CPU_FEATURE_USABLE_P (cpu_features, AVX2) - && X86_ISA_CPU_FEATURES_ARCH_P (cpu_features, -- AVX_Fast_Unaligned_Load, !)) -+ AVX_Fast_Unaligned_Load,)) - { - if (X86_ISA_CPU_FEATURE_USABLE_P (cpu_features, AVX512VL)) - { - -commit de1fe81f471496366580ad728b8986a3424b2fd7 -Author: Yury Khrustalev -Date: Tue Oct 28 11:01:50 2025 +0000 - - aarch64: fix cfi directives around __libc_arm_za_disable - - Incorrect CFI directive corrupted call stack information - and prevented debuggers from correctly displaying call - stack information. - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 2f77aec043f61e8533487850b11941a640ae2dea) - -diff --git a/sysdeps/unix/sysv/linux/aarch64/sysdep.h b/sysdeps/unix/sysv/linux/aarch64/sysdep.h -index 30003c0145..8a7690d4a8 100644 ---- a/sysdeps/unix/sysv/linux/aarch64/sysdep.h -+++ b/sysdeps/unix/sysv/linux/aarch64/sysdep.h -@@ -155,11 +155,12 @@ - that allows to call it without stack manipulation and preserving - most of the registers. */ - .macro CALL_LIBC_ARM_ZA_DISABLE -+ cfi_remember_state - mov x13, x30 -- .cfi_register x30, x13 -+ cfi_register(x30, x13) - bl __libc_arm_za_disable - mov x30, x13 -- .cfi_register x13, x30 -+ cfi_restore_state - .endm - - #else /* not __ASSEMBLER__ */ -@@ -250,11 +251,12 @@ - ({ \ - unsigned long int __tmp; \ - asm volatile ( \ -+ " .cfi_remember_state\n" \ - " mov %0, x30\n" \ -- " .cfi_register x30, %0\n" \ -+ " .cfi_register x30, %0\n" \ - " bl __libc_arm_za_disable\n" \ - " mov x30, %0\n" \ -- " .cfi_register %0, x30\n" \ -+ " .cfi_restore_state\n" \ - : "=r" (__tmp) \ - : \ - : "x14", "x15", "x16", "x17", "x18", "memory" ); \ - -commit 17c3eab387c3ceb6972e57888a89b1480793f81a -Author: Yury Khrustalev -Date: Tue Nov 11 11:40:25 2025 +0000 - - aarch64: fix includes in SME tests - - Use the correct include for the SIGCHLD macro: signal.h - - Reviewed-by: Wilco Dijkstra - (cherry picked from commit a9c426bcca59a9e228c4fbe75e75154217ec4ada) - -diff --git a/sysdeps/aarch64/tst-sme-clone.c b/sysdeps/aarch64/tst-sme-clone.c -index 7106ec7926..b6ad54fa37 100644 ---- a/sysdeps/aarch64/tst-sme-clone.c -+++ b/sysdeps/aarch64/tst-sme-clone.c -@@ -19,6 +19,7 @@ - - #include "tst-sme-skeleton.c" - -+#include - #include - - static int -diff --git a/sysdeps/aarch64/tst-sme-clone3.c b/sysdeps/aarch64/tst-sme-clone3.c -index 402b040cfd..f420d5984d 100644 ---- a/sysdeps/aarch64/tst-sme-clone3.c -+++ b/sysdeps/aarch64/tst-sme-clone3.c -@@ -22,7 +22,7 @@ - #include - - #include --#include -+#include - #include - - /* Since clone3 is not a public symbol, we link this test explicitly - -commit 97297120ce04f0edd16ed0357a11ef8731c5bd1e -Author: Joe Ramsay -Date: Thu Nov 6 15:36:03 2025 +0000 - - AArch64: Optimise SVE scalar callbacks - - Instead of using SVE instructions to marshall special results into the - correct lane, just write the entire vector (and the predicate) to - memory, then use cheaper scalar operations. - - Geomean speedup of 16% in special intervals on Neoverse with GCC 14. - - Reviewed-by: Wilco Dijkstra - (cherry picked from commit 5b82fb18827e962af9f080fdf3c1a69802783f67) - -diff --git a/sysdeps/aarch64/fpu/sv_math.h b/sysdeps/aarch64/fpu/sv_math.h -index 3d576df4cc..65d7f0ff20 100644 ---- a/sysdeps/aarch64/fpu/sv_math.h -+++ b/sysdeps/aarch64/fpu/sv_math.h -@@ -24,11 +24,29 @@ - - #include "vecmath_config.h" - -+#if !defined(__ARM_FEATURE_SVE_BITS) || __ARM_FEATURE_SVE_BITS == 0 -+/* If not specified by -msve-vector-bits, assume maximum vector length. */ -+# define SVE_VECTOR_BYTES 256 -+#else -+# define SVE_VECTOR_BYTES (__ARM_FEATURE_SVE_BITS / 8) -+#endif -+#define SVE_NUM_FLTS (SVE_VECTOR_BYTES / sizeof (float)) -+#define SVE_NUM_DBLS (SVE_VECTOR_BYTES / sizeof (double)) -+/* Predicate is stored as one bit per byte of VL so requires VL / 64 bytes. */ -+#define SVE_NUM_PG_BYTES (SVE_VECTOR_BYTES / sizeof (uint64_t)) -+ - #define SV_NAME_F1(fun) _ZGVsMxv_##fun##f - #define SV_NAME_D1(fun) _ZGVsMxv_##fun - #define SV_NAME_F2(fun) _ZGVsMxvv_##fun##f - #define SV_NAME_D2(fun) _ZGVsMxvv_##fun - -+static inline void -+svstr_p (uint8_t *dst, svbool_t p) -+{ -+ /* Predicate STR does not currently have an intrinsic. */ -+ __asm__("str %0, [%x1]\n" : : "Upa"(p), "r"(dst) : "memory"); -+} -+ - /* Double precision. */ - static inline svint64_t - sv_s64 (int64_t x) -@@ -51,33 +69,35 @@ sv_f64 (double x) - static inline svfloat64_t - sv_call_f64 (double (*f) (double), svfloat64_t x, svfloat64_t y, svbool_t cmp) - { -- svbool_t p = svpfirst (cmp, svpfalse ()); -- while (svptest_any (cmp, p)) -+ double tmp[SVE_NUM_DBLS]; -+ uint8_t pg_bits[SVE_NUM_PG_BYTES]; -+ svstr_p (pg_bits, cmp); -+ svst1 (svptrue_b64 (), tmp, svsel (cmp, x, y)); -+ -+ for (int i = 0; i < svcntd (); i++) - { -- double elem = svclastb_n_f64 (p, 0, x); -- elem = (*f) (elem); -- svfloat64_t y2 = svdup_n_f64 (elem); -- y = svsel_f64 (p, y2, y); -- p = svpnext_b64 (cmp, p); -+ if (pg_bits[i] & 1) -+ tmp[i] = f (tmp[i]); - } -- return y; -+ return svld1 (svptrue_b64 (), tmp); - } - - static inline svfloat64_t - sv_call2_f64 (double (*f) (double, double), svfloat64_t x1, svfloat64_t x2, - svfloat64_t y, svbool_t cmp) - { -- svbool_t p = svpfirst (cmp, svpfalse ()); -- while (svptest_any (cmp, p)) -+ double tmp1[SVE_NUM_DBLS], tmp2[SVE_NUM_DBLS]; -+ uint8_t pg_bits[SVE_NUM_PG_BYTES]; -+ svstr_p (pg_bits, cmp); -+ svst1 (svptrue_b64 (), tmp1, svsel (cmp, x1, y)); -+ svst1 (cmp, tmp2, x2); -+ -+ for (int i = 0; i < svcntd (); i++) - { -- double elem1 = svclastb_n_f64 (p, 0, x1); -- double elem2 = svclastb_n_f64 (p, 0, x2); -- double ret = (*f) (elem1, elem2); -- svfloat64_t y2 = svdup_n_f64 (ret); -- y = svsel_f64 (p, y2, y); -- p = svpnext_b64 (cmp, p); -+ if (pg_bits[i] & 1) -+ tmp1[i] = f (tmp1[i], tmp2[i]); - } -- return y; -+ return svld1 (svptrue_b64 (), tmp1); - } - - static inline svuint64_t -@@ -109,33 +129,40 @@ sv_f32 (float x) - static inline svfloat32_t - sv_call_f32 (float (*f) (float), svfloat32_t x, svfloat32_t y, svbool_t cmp) - { -- svbool_t p = svpfirst (cmp, svpfalse ()); -- while (svptest_any (cmp, p)) -+ float tmp[SVE_NUM_FLTS]; -+ uint8_t pg_bits[SVE_NUM_PG_BYTES]; -+ svstr_p (pg_bits, cmp); -+ svst1 (svptrue_b32 (), tmp, svsel (cmp, x, y)); -+ -+ for (int i = 0; i < svcntd (); i++) - { -- float elem = svclastb_n_f32 (p, 0, x); -- elem = f (elem); -- svfloat32_t y2 = svdup_n_f32 (elem); -- y = svsel_f32 (p, y2, y); -- p = svpnext_b32 (cmp, p); -+ uint8_t p = pg_bits[i]; -+ if (p & 1) -+ tmp[i * 2] = f (tmp[i * 2]); -+ if (p & (1 << 4)) -+ tmp[i * 2 + 1] = f (tmp[i * 2 + 1]); - } -- return y; -+ return svld1 (svptrue_b32 (), tmp); - } - - static inline svfloat32_t - sv_call2_f32 (float (*f) (float, float), svfloat32_t x1, svfloat32_t x2, - svfloat32_t y, svbool_t cmp) - { -- svbool_t p = svpfirst (cmp, svpfalse ()); -- while (svptest_any (cmp, p)) -+ float tmp1[SVE_NUM_FLTS], tmp2[SVE_NUM_FLTS]; -+ uint8_t pg_bits[SVE_NUM_PG_BYTES]; -+ svstr_p (pg_bits, cmp); -+ svst1 (svptrue_b32 (), tmp1, svsel (cmp, x1, y)); -+ svst1 (cmp, tmp2, x2); -+ -+ for (int i = 0; i < svcntd (); i++) - { -- float elem1 = svclastb_n_f32 (p, 0, x1); -- float elem2 = svclastb_n_f32 (p, 0, x2); -- float ret = f (elem1, elem2); -- svfloat32_t y2 = svdup_n_f32 (ret); -- y = svsel_f32 (p, y2, y); -- p = svpnext_b32 (cmp, p); -+ uint8_t p = pg_bits[i]; -+ if (p & 1) -+ tmp1[i * 2] = f (tmp1[i * 2], tmp2[i * 2]); -+ if (p & (1 << 4)) -+ tmp1[i * 2 + 1] = f (tmp1[i * 2 + 1], tmp2[i * 2 + 1]); - } -- return y; -+ return svld1 (svptrue_b32 (), tmp1); - } -- - #endif - -commit ec041b1f53bf1fd29d94ee147fac69da66437dc6 -Author: Joe Ramsay -Date: Thu Nov 6 18:26:54 2025 +0000 - - AArch64: Fix instability in AdvSIMD tan - - Previously presence of special-cases in one lane could affect the - results in other lanes due to unconditional scalar fallback. The old - WANT_SIMD_EXCEPT option (which has never been enabled in libmvec) has - been removed from AOR, making it easier to spot and fix this. 4% - improvement in throughput with GCC 14 on Neoverse V1. This bug is - present as far back as 2.39 (where tan was first introduced). - - Reviewed-by: Wilco Dijkstra - (cherry picked from commit 6c22823da57aa5218f717f569c04c9573c0448c5) - -diff --git a/sysdeps/aarch64/fpu/tan_advsimd.c b/sysdeps/aarch64/fpu/tan_advsimd.c -index 825c9754b3..d391a003d8 100644 ---- a/sysdeps/aarch64/fpu/tan_advsimd.c -+++ b/sysdeps/aarch64/fpu/tan_advsimd.c -@@ -25,9 +25,7 @@ static const struct data - float64x2_t poly[9]; - double half_pi[2]; - float64x2_t two_over_pi, shift; --#if !WANT_SIMD_EXCEPT - float64x2_t range_val; --#endif - } data = { - /* Coefficients generated using FPMinimax. */ - .poly = { V2 (0x1.5555555555556p-2), V2 (0x1.1111111110a63p-3), -@@ -38,20 +36,17 @@ static const struct data - .half_pi = { 0x1.921fb54442d18p0, 0x1.1a62633145c07p-54 }, - .two_over_pi = V2 (0x1.45f306dc9c883p-1), - .shift = V2 (0x1.8p52), --#if !WANT_SIMD_EXCEPT - .range_val = V2 (0x1p23), --#endif - }; - - #define RangeVal 0x4160000000000000 /* asuint64(0x1p23). */ - #define TinyBound 0x3e50000000000000 /* asuint64(2^-26). */ --#define Thresh 0x310000000000000 /* RangeVal - TinyBound. */ - - /* Special cases (fall back to scalar calls). */ - static float64x2_t VPCS_ATTR NOINLINE --special_case (float64x2_t x) -+special_case (float64x2_t x, float64x2_t n, float64x2_t d, uint64x2_t special) - { -- return v_call_f64 (tan, x, x, v_u64 (-1)); -+ return v_call_f64 (tan, x, vdivq_f64 (n, d), special); - } - - /* Vector approximation for double-precision tan. -@@ -65,14 +60,6 @@ float64x2_t VPCS_ATTR V_NAME_D1 (tan) (float64x2_t x) - very large inputs. Fall back to scalar routine for all lanes if any are - too large, or Inf/NaN. If fenv exceptions are expected, also fall back for - tiny input to avoid underflow. */ --#if WANT_SIMD_EXCEPT -- uint64x2_t iax = vreinterpretq_u64_f64 (vabsq_f64 (x)); -- /* iax - tiny_bound > range_val - tiny_bound. */ -- uint64x2_t special -- = vcgtq_u64 (vsubq_u64 (iax, v_u64 (TinyBound)), v_u64 (Thresh)); -- if (__glibc_unlikely (v_any_u64 (special))) -- return special_case (x); --#endif - - /* q = nearest integer to 2 * x / pi. */ - float64x2_t q -@@ -81,9 +68,8 @@ float64x2_t VPCS_ATTR V_NAME_D1 (tan) (float64x2_t x) - - /* Use q to reduce x to r in [-pi/4, pi/4], by: - r = x - q * pi/2, in extended precision. */ -- float64x2_t r = x; - float64x2_t half_pi = vld1q_f64 (dat->half_pi); -- r = vfmsq_laneq_f64 (r, q, half_pi, 0); -+ float64x2_t r = vfmsq_laneq_f64 (x, q, half_pi, 0); - r = vfmsq_laneq_f64 (r, q, half_pi, 1); - /* Further reduce r to [-pi/8, pi/8], to be reconstructed using double angle - formula. */ -@@ -114,12 +100,13 @@ float64x2_t VPCS_ATTR V_NAME_D1 (tan) (float64x2_t x) - - uint64x2_t no_recip = vtstq_u64 (vreinterpretq_u64_s64 (qi), v_u64 (1)); - --#if !WANT_SIMD_EXCEPT - uint64x2_t special = vcageq_f64 (x, dat->range_val); -+ float64x2_t swap = vbslq_f64 (no_recip, n, vnegq_f64 (d)); -+ d = vbslq_f64 (no_recip, d, n); -+ n = swap; -+ - if (__glibc_unlikely (v_any_u64 (special))) -- return special_case (x); --#endif -+ return special_case (x, n, d, special); - -- return vdivq_f64 (vbslq_f64 (no_recip, n, vnegq_f64 (d)), -- vbslq_f64 (no_recip, d, n)); -+ return vdivq_f64 (n, d); - } - -commit 0c9430ed976b961343dd29b752091f3c4771cf30 -Author: Joe Ramsay -Date: Thu Nov 6 18:29:33 2025 +0000 - - AArch64: Fix instability in AdvSIMD sinh - - Previously presence of special-cases in one lane could affect the - results in other lanes due to unconditional scalar fallback. The old - WANT_SIMD_EXCEPT option (which has never been enabled in libmvec) has - been removed from AOR, making it easier to spot and fix - this. No measured change in performance. This patch applies cleanly as - far back as 2.41, however there are conflicts with 2.40 where sinh was - first introduced. - - Reviewed-by: Wilco Dijkstra - (cherry picked from commit e45af510bc816e860c8e2e1d4a652b4fe15c4b34) - -diff --git a/sysdeps/aarch64/fpu/sinh_advsimd.c b/sysdeps/aarch64/fpu/sinh_advsimd.c -index 0d6a4856f8..b6b60262c6 100644 ---- a/sysdeps/aarch64/fpu/sinh_advsimd.c -+++ b/sysdeps/aarch64/fpu/sinh_advsimd.c -@@ -24,36 +24,26 @@ static const struct data - { - struct v_expm1_data d; - uint64x2_t halff; --#if WANT_SIMD_EXCEPT -- uint64x2_t tiny_bound, thresh; --#else - float64x2_t large_bound; --#endif - } data = { - .d = V_EXPM1_DATA, - .halff = V2 (0x3fe0000000000000), --#if WANT_SIMD_EXCEPT -- /* 2^-26, below which sinh(x) rounds to x. */ -- .tiny_bound = V2 (0x3e50000000000000), -- /* asuint(large_bound) - asuint(tiny_bound). */ -- .thresh = V2 (0x0230000000000000), --#else - /* 2^9. expm1 helper overflows for large input. */ - .large_bound = V2 (0x1p+9), --#endif - }; - - static float64x2_t NOINLINE VPCS_ATTR --special_case (float64x2_t x) -+special_case (float64x2_t x, float64x2_t t, float64x2_t halfsign, -+ uint64x2_t special) - { -- return v_call_f64 (sinh, x, x, v_u64 (-1)); -+ return v_call_f64 (sinh, x, vmulq_f64 (t, halfsign), special); - } - - /* Approximation for vector double-precision sinh(x) using expm1. - sinh(x) = (exp(x) - exp(-x)) / 2. - The greatest observed error is 2.52 ULP: -- _ZGVnN2v_sinh(-0x1.a098a2177a2b9p-2) got -0x1.ac2f05bb66fccp-2 -- want -0x1.ac2f05bb66fc9p-2. */ -+ _ZGVnN2v_sinh(0x1.9f6ff2ab6fb19p-2) got 0x1.aaed83a3153ccp-2 -+ want 0x1.aaed83a3153c9p-2. */ - float64x2_t VPCS_ATTR V_NAME_D1 (sinh) (float64x2_t x) - { - const struct data *d = ptr_barrier (&data); -@@ -63,21 +53,16 @@ float64x2_t VPCS_ATTR V_NAME_D1 (sinh) (float64x2_t x) - float64x2_t halfsign = vreinterpretq_f64_u64 ( - vbslq_u64 (v_u64 (0x8000000000000000), ix, d->halff)); - --#if WANT_SIMD_EXCEPT -- uint64x2_t special = vcgeq_u64 ( -- vsubq_u64 (vreinterpretq_u64_f64 (ax), d->tiny_bound), d->thresh); --#else - uint64x2_t special = vcageq_f64 (x, d->large_bound); --#endif -- -- /* Fall back to scalar variant for all lanes if any of them are special. */ -- if (__glibc_unlikely (v_any_u64 (special))) -- return special_case (x); - - /* Up to the point that expm1 overflows, we can use it to calculate sinh - using a slight rearrangement of the definition of sinh. This allows us to - retain acceptable accuracy for very small inputs. */ - float64x2_t t = expm1_inline (ax, &d->d); - t = vaddq_f64 (t, vdivq_f64 (t, vaddq_f64 (t, v_f64 (1.0)))); -+ -+ if (__glibc_unlikely (v_any_u64 (special))) -+ return special_case (x, t, halfsign, special); -+ - return vmulq_f64 (t, halfsign); - } - -commit 710d7a2e8374cf09280a0db170a6c813b70b59e5 -Author: Pierre Blanchard -Date: Tue Nov 18 15:03:10 2025 +0000 - - AArch64: fix SVE tanpi(f) [BZ #33642] - - Fixed svld1rq using incorrect predicates (BZ #33642). - Next to no performance variations (tested on V1). - - Reviewed-by: Wilco Dijkstra  - (cherry picked from commit e889160273a4c2b68870c9adf341955867d76a7d) - -diff --git a/sysdeps/aarch64/fpu/tanpi_sve.c b/sysdeps/aarch64/fpu/tanpi_sve.c -index 57c643ae29..bfe6828e1f 100644 ---- a/sysdeps/aarch64/fpu/tanpi_sve.c -+++ b/sysdeps/aarch64/fpu/tanpi_sve.c -@@ -1,6 +1,6 @@ - /* Double-precision (SVE) tanpi function - -- Copyright (C) 2024 Free Software Foundation, Inc. -+ Copyright (C) 2024-2025 Free Software Foundation, Inc. - This file is part of the GNU C Library. - - The GNU C Library is free software; you can redistribute it and/or -@@ -58,10 +58,10 @@ svfloat64_t SV_NAME_D1 (tanpi) (svfloat64_t x, const svbool_t pg) - svfloat64_t r2 = svmul_x (pg, r, r); - svfloat64_t r4 = svmul_x (pg, r2, r2); - -- svfloat64_t c_1_3 = svld1rq (pg, &d->c1); -- svfloat64_t c_5_7 = svld1rq (pg, &d->c5); -- svfloat64_t c_9_11 = svld1rq (pg, &d->c9); -- svfloat64_t c_13_14 = svld1rq (pg, &d->c13); -+ svfloat64_t c_1_3 = svld1rq (svptrue_b64 (), &d->c1); -+ svfloat64_t c_5_7 = svld1rq (svptrue_b64 (), &d->c5); -+ svfloat64_t c_9_11 = svld1rq (svptrue_b64 (), &d->c9); -+ svfloat64_t c_13_14 = svld1rq (svptrue_b64 (), &d->c13); - svfloat64_t p01 = svmla_lane (sv_f64 (d->c0), r2, c_1_3, 0); - svfloat64_t p23 = svmla_lane (sv_f64 (d->c2), r2, c_1_3, 1); - svfloat64_t p45 = svmla_lane (sv_f64 (d->c4), r2, c_5_7, 0); -diff --git a/sysdeps/aarch64/fpu/tanpif_sve.c b/sysdeps/aarch64/fpu/tanpif_sve.c -index 0285f56f34..6894379564 100644 ---- a/sysdeps/aarch64/fpu/tanpif_sve.c -+++ b/sysdeps/aarch64/fpu/tanpif_sve.c -@@ -1,6 +1,6 @@ - /* Single-precision (SVE) tanpi function - -- Copyright (C) 2024 Free Software Foundation, Inc. -+ Copyright (C) 2024-2025 Free Software Foundation, Inc. - This file is part of the GNU C Library. - - The GNU C Library is free software; you can redistribute it and/or -@@ -37,7 +37,7 @@ const static struct v_tanpif_data - svfloat32_t SV_NAME_F1 (tanpi) (svfloat32_t x, const svbool_t pg) - { - const struct v_tanpif_data *d = ptr_barrier (&tanpif_data); -- svfloat32_t odd_coeffs = svld1rq (pg, &d->c1); -+ svfloat32_t odd_coeffs = svld1rq (svptrue_b32 (), &d->c1); - svfloat32_t n = svrintn_x (pg, x); - - /* inf produces nan that propagates. */ - -commit 828b8d23f3fa05234d35032a61a746918accf91d -Author: Pierre Blanchard -Date: Tue Nov 18 15:09:05 2025 +0000 - - AArch64: Fix and improve SVE pow(f) special cases - - powf: - - Update scalar special case function to best use new interface. - - pow: - - Make specialcase NOINLINE to prevent str/ldr leaking in fast path. - Remove depency in sv_call2, as new callback impl is not a - performance gain. - Replace with vectorised specialcase since structure of scalar - routine is fairly simple. - - Throughput gain of about 5-10% on V1 for large values and 25% for subnormal `x`. - - Reviewed-by: Wilco Dijkstra  - (cherry picked from commit bb6519de1e6fe73d79bc71588ec4e5668907f080) - -diff --git a/sysdeps/aarch64/fpu/pow_sve.c b/sysdeps/aarch64/fpu/pow_sve.c -index b8c1b39dca..becf1a8410 100644 ---- a/sysdeps/aarch64/fpu/pow_sve.c -+++ b/sysdeps/aarch64/fpu/pow_sve.c -@@ -31,8 +31,8 @@ - The SVE algorithm drops the tail in the exp computation at the price of - a lower accuracy, slightly above 1ULP. - The SVE algorithm also drops the special treatement of small (< 2^-65) and -- large (> 2^63) finite values of |y|, as they only affect non-round to nearest -- modes. -+ large (> 2^63) finite values of |y|, as they only affect non-round to -+ nearest modes. - - Maximum measured error is 1.04 ULPs: - SV_NAME_D2 (pow) (0x1.3d2d45bc848acp+63, -0x1.a48a38b40cd43p-12) -@@ -156,42 +156,22 @@ sv_zeroinfnan (svbool_t pg, svuint64_t i) - a double. (int32_t)KI is the k used in the argument reduction and exponent - adjustment of scale, positive k here means the result may overflow and - negative k means the result may underflow. */ --static inline double --specialcase (double tmp, uint64_t sbits, uint64_t ki) --{ -- double scale; -- if ((ki & 0x80000000) == 0) -- { -- /* k > 0, the exponent of scale might have overflowed by <= 460. */ -- sbits -= 1009ull << 52; -- scale = asdouble (sbits); -- return 0x1p1009 * (scale + scale * tmp); -- } -- /* k < 0, need special care in the subnormal range. */ -- sbits += 1022ull << 52; -- /* Note: sbits is signed scale. */ -- scale = asdouble (sbits); -- double y = scale + scale * tmp; -- return 0x1p-1022 * y; --} -- --/* Scalar fallback for special cases of SVE pow's exp. */ - static inline svfloat64_t --sv_call_specialcase (svfloat64_t x1, svuint64_t u1, svuint64_t u2, -- svfloat64_t y, svbool_t cmp) -+specialcase (svfloat64_t tmp, svuint64_t sbits, svuint64_t ki, svbool_t cmp) - { -- svbool_t p = svpfirst (cmp, svpfalse ()); -- while (svptest_any (cmp, p)) -- { -- double sx1 = svclastb (p, 0, x1); -- uint64_t su1 = svclastb (p, 0, u1); -- uint64_t su2 = svclastb (p, 0, u2); -- double elem = specialcase (sx1, su1, su2); -- svfloat64_t y2 = sv_f64 (elem); -- y = svsel (p, y2, y); -- p = svpnext_b64 (cmp, p); -- } -- return y; -+ svbool_t p_pos = svcmpge_n_f64 (cmp, svreinterpret_f64_u64 (ki), 0.0); -+ -+ /* Scale up or down depending on sign of k. */ -+ svint64_t offset -+ = svsel_s64 (p_pos, sv_s64 (1009ull << 52), sv_s64 (-1022ull << 52)); -+ svfloat64_t factor -+ = svsel_f64 (p_pos, sv_f64 (0x1p1009), sv_f64 (0x1p-1022)); -+ -+ svuint64_t offset_sbits -+ = svsub_u64_x (cmp, sbits, svreinterpret_u64_s64 (offset)); -+ svfloat64_t scale = svreinterpret_f64_u64 (offset_sbits); -+ svfloat64_t res = svmad_f64_x (cmp, scale, tmp, scale); -+ return svmul_f64_x (cmp, res, factor); - } - - /* Compute y+TAIL = log(x) where the rounded result is y and TAIL has about -@@ -214,8 +194,8 @@ sv_log_inline (svbool_t pg, svuint64_t ix, svfloat64_t *tail, - - /* log(x) = k*Ln2 + log(c) + log1p(z/c-1). */ - /* SVE lookup requires 3 separate lookup tables, as opposed to scalar version -- that uses array of structures. We also do the lookup earlier in the code to -- make sure it finishes as early as possible. */ -+ that uses array of structures. We also do the lookup earlier in the code -+ to make sure it finishes as early as possible. */ - svfloat64_t invc = svld1_gather_index (pg, __v_pow_log_data.invc, i); - svfloat64_t logc = svld1_gather_index (pg, __v_pow_log_data.logc, i); - svfloat64_t logctail = svld1_gather_index (pg, __v_pow_log_data.logctail, i); -@@ -325,14 +305,14 @@ sv_exp_inline (svbool_t pg, svfloat64_t x, svfloat64_t xtail, - svbool_t oflow = svcmpge (pg, abstop, HugeExp); - oflow = svand_z (pg, uoflow, svbic_z (pg, oflow, uflow)); - -- /* For large |x| values (512 < |x| < 1024) scale * (1 + TMP) can overflow -- or underflow. */ -+ /* Handle underflow and overlow in scale. -+ For large |x| values (512 < |x| < 1024), scale * (1 + TMP) can -+ overflow or underflow. */ - svbool_t special = svbic_z (pg, uoflow, svorr_z (pg, uflow, oflow)); -+ if (__glibc_unlikely (svptest_any (pg, special))) -+ z = svsel (special, specialcase (tmp, sbits, ki, special), z); - -- /* Update result with special and large cases. */ -- z = sv_call_specialcase (tmp, sbits, ki, z, special); -- -- /* Handle underflow and overflow. */ -+ /* Handle underflow and overflow in exp. */ - svbool_t x_is_neg = svcmplt (pg, x, 0); - svuint64_t sign_mask - = svlsl_x (pg, sign_bias, 52 - V_POW_EXP_TABLE_BITS); -@@ -353,7 +333,7 @@ sv_exp_inline (svbool_t pg, svfloat64_t x, svfloat64_t xtail, - } - - static inline double --pow_sc (double x, double y) -+pow_specialcase (double x, double y) - { - uint64_t ix = asuint64 (x); - uint64_t iy = asuint64 (y); -@@ -382,6 +362,14 @@ pow_sc (double x, double y) - return x; - } - -+/* Scalar fallback for special case routines with custom signature. */ -+static svfloat64_t NOINLINE -+sv_pow_specialcase (svfloat64_t x1, svfloat64_t x2, svfloat64_t y, -+ svbool_t cmp) -+{ -+ return sv_call2_f64 (pow_specialcase, x1, x2, y, cmp); -+} -+ - svfloat64_t SV_NAME_D2 (pow) (svfloat64_t x, svfloat64_t y, const svbool_t pg) - { - const struct data *d = ptr_barrier (&data); -@@ -444,7 +432,7 @@ svfloat64_t SV_NAME_D2 (pow) (svfloat64_t x, svfloat64_t y, const svbool_t pg) - - /* Cases of zero/inf/nan x or y. */ - if (__glibc_unlikely (svptest_any (svptrue_b64 (), special))) -- vz = sv_call2_f64 (pow_sc, x, y, vz, special); -+ vz = sv_pow_specialcase (x, y, vz, special); - - return vz; - } -diff --git a/sysdeps/aarch64/fpu/powf_sve.c b/sysdeps/aarch64/fpu/powf_sve.c -index 65e9bd29d9..76f54b3522 100644 ---- a/sysdeps/aarch64/fpu/powf_sve.c -+++ b/sysdeps/aarch64/fpu/powf_sve.c -@@ -116,11 +116,10 @@ zeroinfnan (uint32_t ix) - preamble of scalar powf except that we do not update ix and sign_bias. This - is done in the preamble of the SVE powf. */ - static inline float --powf_specialcase (float x, float y, float z) -+powf_specialcase (float x, float y) - { - uint32_t ix = asuint (x); - uint32_t iy = asuint (y); -- /* Either (x < 0x1p-126 or inf or nan) or (y is 0 or inf or nan). */ - if (__glibc_unlikely (zeroinfnan (iy))) - { - if (2 * iy == 0) -@@ -142,32 +141,15 @@ powf_specialcase (float x, float y, float z) - x2 = -x2; - return iy & 0x80000000 ? 1 / x2 : x2; - } -- /* We need a return here in case x<0 and y is integer, but all other tests -- need to be run. */ -- return z; -+ /* Return x for convenience, but make sure result is never used. */ -+ return x; - } - - /* Scalar fallback for special case routines with custom signature. */ - static svfloat32_t NOINLINE --sv_call_powf_sc (svfloat32_t x1, svfloat32_t x2, svfloat32_t y) -+sv_call_powf_sc (svfloat32_t x1, svfloat32_t x2, svfloat32_t y, svbool_t cmp) - { -- /* Special cases of x or y: zero, inf and nan. */ -- svbool_t xspecial = sv_zeroinfnan (svptrue_b32 (), svreinterpret_u32 (x1)); -- svbool_t yspecial = sv_zeroinfnan (svptrue_b32 (), svreinterpret_u32 (x2)); -- svbool_t cmp = svorr_z (svptrue_b32 (), xspecial, yspecial); -- -- svbool_t p = svpfirst (cmp, svpfalse ()); -- while (svptest_any (cmp, p)) -- { -- float sx1 = svclastb (p, 0, x1); -- float sx2 = svclastb (p, 0, x2); -- float elem = svclastb (p, 0, y); -- elem = powf_specialcase (sx1, sx2, elem); -- svfloat32_t y2 = sv_f32 (elem); -- y = svsel (p, y2, y); -- p = svpnext_b32 (cmp, p); -- } -- return y; -+ return sv_call2_f32 (powf_specialcase, x1, x2, y, cmp); - } - - /* Compute core for half of the lanes in double precision. */ -@@ -330,7 +312,7 @@ svfloat32_t SV_NAME_F2 (pow) (svfloat32_t x, svfloat32_t y, const svbool_t pg) - ret = svsel (yint_or_xpos, ret, sv_f32 (__builtin_nanf (""))); - - if (__glibc_unlikely (svptest_any (cmp, cmp))) -- return sv_call_powf_sc (x, y, ret); -+ return sv_call_powf_sc (x, y, ret, cmp); - - return ret; - } - -commit 6b2957cfe8ad1e02c03a28abfc5a251c05e4005e -Author: Sachin Monga -Date: Fri Nov 21 00:30:04 2025 -0500 - - ppc64le: Restore optimized strcmp for power10 - - This patch addresses the actual cause of CVE-2025-5702 - - The vector non-volatile registers are not used anymore for - 32 byte load and comparison operation - - Additionally, the assembler workaround used earlier for the - instruction lxvp is replaced with actual instruction. - - Signed-off-by: Sachin Monga - Co-authored-by: Paul Murphy - (cherry picked from commit 9a40b1cda519cc4f532acb6d020390829df3d81b) - -diff --git a/sysdeps/powerpc/powerpc64/le/power10/strcmp.S b/sysdeps/powerpc/powerpc64/le/power10/strcmp.S -new file mode 100644 -index 0000000000..0d4a53317c ---- /dev/null -+++ b/sysdeps/powerpc/powerpc64/le/power10/strcmp.S -@@ -0,0 +1,185 @@ -+/* Optimized strcmp implementation for PowerPC64/POWER10. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+#include -+ -+#ifndef STRCMP -+# define STRCMP strcmp -+#endif -+ -+/* Implements the function -+ int [r3] strcmp (const char *s1 [r3], const char *s2 [r4]). */ -+ -+ -+#define COMPARE_16(vreg1,vreg2,offset) \ -+ lxv vreg1+32,offset(r3); \ -+ lxv vreg2+32,offset(r4); \ -+ vcmpnezb. v7,vreg1,vreg2; \ -+ bne cr6,L(different); \ -+ -+#define COMPARE_32(vreg1,vreg2,offset,label1,label2) \ -+ lxvp vreg1+32,offset(r3); \ -+ lxvp vreg2+32,offset(r4); \ -+ vcmpnezb. v7,vreg1+1,vreg2+1; \ -+ bne cr6,L(label1); \ -+ vcmpnezb. v7,vreg1,vreg2; \ -+ bne cr6,L(label2); \ -+ -+#define TAIL(vreg1,vreg2) \ -+ vctzlsbb r6,v7; \ -+ vextubrx r5,r6,vreg1; \ -+ vextubrx r4,r6,vreg2; \ -+ subf r3,r4,r5; \ -+ blr; \ -+ -+#define CHECK_N_BYTES(reg1,reg2,len_reg) \ -+ sldi r0,len_reg,56; \ -+ lxvl 32+v4,reg1,r0; \ -+ lxvl 32+v5,reg2,r0; \ -+ add reg1,reg1,len_reg; \ -+ add reg2,reg2,len_reg; \ -+ vcmpnezb. v7,v4,v5; \ -+ vctzlsbb r6,v7; \ -+ cmpld cr7,r6,len_reg; \ -+ blt cr7,L(different); \ -+ -+ -+ .machine power10 -+ENTRY_TOCLESS (STRCMP, 4) -+ li r11,16 -+ /* eq bit of cr1 used as swap status flag to indicate if -+ source pointers were swapped. */ -+ crclr 4*cr1+eq -+ andi. r7,r3,15 -+ sub r7,r11,r7 /* r7(nalign1) = 16 - (str1 & 15). */ -+ andi. r9,r4,15 -+ sub r5,r11,r9 /* r5(nalign2) = 16 - (str2 & 15). */ -+ cmpld cr7,r7,r5 -+ beq cr7,L(same_aligned) -+ blt cr7,L(nalign1_min) -+ /* Swap r3 and r4, and r7 and r5 such that r3 and r7 hold the -+ pointer which is closer to the next 16B boundary so that only -+ one CHECK_N_BYTES is needed before entering the loop below. */ -+ mr r8,r4 -+ mr r4,r3 -+ mr r3,r8 -+ mr r12,r7 -+ mr r7,r5 -+ mr r5,r12 -+ crset 4*cr1+eq /* Set bit on swapping source pointers. */ -+ -+ .p2align 5 -+L(nalign1_min): -+ CHECK_N_BYTES(r3,r4,r7) -+ -+ .p2align 5 -+L(s1_aligned): -+ /* r9 and r5 is number of bytes to be read after and before -+ page boundary correspondingly. */ -+ sub r5,r5,r7 -+ subfic r9,r5,16 -+ /* Now let r7 hold the count of quadwords which can be -+ checked without crossing a page boundary. quadword offset is -+ (str2>>4)&0xFF. */ -+ rlwinm r7,r4,28,0xFF -+ /* Below check is required only for first iteration. For second -+ iteration and beyond, the new loop counter is always 255. */ -+ cmpldi r7,255 -+ beq L(L3) -+ /* Get the initial loop count by 255-((str2>>4)&0xFF). */ -+ subfic r11,r7,255 -+ -+ .p2align 5 -+L(L1): -+ mtctr r11 -+ -+ .p2align 5 -+L(L2): -+ COMPARE_16(v4,v5,0) /* Load 16B blocks using lxv. */ -+ addi r3,r3,16 -+ addi r4,r4,16 -+ bdnz L(L2) -+ /* Cross the page boundary of s2, carefully. */ -+ -+ .p2align 5 -+L(L3): -+ CHECK_N_BYTES(r3,r4,r5) -+ CHECK_N_BYTES(r3,r4,r9) -+ li r11,255 /* Load the new loop counter. */ -+ b L(L1) -+ -+ .p2align 5 -+L(same_aligned): -+ CHECK_N_BYTES(r3,r4,r7) -+ /* Align s1 to 32B and adjust s2 address. -+ Use lxvp only if both s1 and s2 are 32B aligned. */ -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ COMPARE_16(v4,v5,32) -+ COMPARE_16(v4,v5,48) -+ addi r3,r3,64 -+ addi r4,r4,64 -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ -+ clrldi r6,r3,59 -+ subfic r5,r6,32 -+ add r3,r3,r5 -+ add r4,r4,r5 -+ andi. r5,r4,0x1F -+ beq cr0,L(32B_aligned_loop) -+ -+ .p2align 5 -+L(16B_aligned_loop): -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ COMPARE_16(v4,v5,32) -+ COMPARE_16(v4,v5,48) -+ addi r3,r3,64 -+ addi r4,r4,64 -+ b L(16B_aligned_loop) -+ -+ /* Calculate and return the difference. */ -+L(different): -+ vctzlsbb r6,v7 -+ vextubrx r5,r6,v4 -+ vextubrx r4,r6,v5 -+ bt 4*cr1+eq,L(swapped) -+ subf r3,r4,r5 -+ blr -+ -+ /* If src pointers were swapped, then swap the -+ indices and calculate the return value. */ -+L(swapped): -+ subf r3,r5,r4 -+ blr -+ -+ .p2align 5 -+L(32B_aligned_loop): -+ COMPARE_32(v14,v16,0,tail1,tail2) -+ COMPARE_32(v14,v16,32,tail1,tail2) -+ COMPARE_32(v14,v16,64,tail1,tail2) -+ COMPARE_32(v14,v16,96,tail1,tail2) -+ addi r3,r3,128 -+ addi r4,r4,128 -+ b L(32B_aligned_loop) -+ -+L(tail1): TAIL(v15,v17) -+L(tail2): TAIL(v14,v16) -+ -+END (STRCMP) -+libc_hidden_builtin_def (strcmp) -diff --git a/sysdeps/powerpc/powerpc64/multiarch/Makefile b/sysdeps/powerpc/powerpc64/multiarch/Makefile -index e321ce54e0..818f287925 100644 ---- a/sysdeps/powerpc/powerpc64/multiarch/Makefile -+++ b/sysdeps/powerpc/powerpc64/multiarch/Makefile -@@ -32,7 +32,7 @@ sysdep_routines += memcpy-power8-cached memcpy-power7 memcpy-a2 memcpy-power6 \ - ifneq (,$(filter %le,$(config-machine))) - sysdep_routines += memcmp-power10 memcpy-power10 memmove-power10 memset-power10 \ - rawmemchr-power9 rawmemchr-power10 \ -- strcmp-power9 strncmp-power9 \ -+ strcmp-power9 strcmp-power10 strncmp-power9 \ - strcpy-power9 strcat-power10 stpcpy-power9 \ - strlen-power9 strncpy-power9 stpncpy-power9 strlen-power10 - endif -diff --git a/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c b/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c -index 016d05fd16..dde3bec709 100644 ---- a/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c -+++ b/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c -@@ -366,6 +366,10 @@ __libc_ifunc_impl_list (const char *name, struct libc_ifunc_impl *array, - /* Support sysdeps/powerpc/powerpc64/multiarch/strcmp.c. */ - IFUNC_IMPL (i, name, strcmp, - #ifdef __LITTLE_ENDIAN__ -+ IFUNC_IMPL_ADD (array, i, strcmp, -+ (hwcap2 & PPC_FEATURE2_ARCH_3_1) -+ && (hwcap & PPC_FEATURE_HAS_VSX), -+ __strcmp_power10) - IFUNC_IMPL_ADD (array, i, strcmp, - hwcap2 & PPC_FEATURE2_ARCH_3_00 - && hwcap & PPC_FEATURE_HAS_ALTIVEC, -diff --git a/sysdeps/powerpc/powerpc64/multiarch/strcmp-power10.S b/sysdeps/powerpc/powerpc64/multiarch/strcmp-power10.S -new file mode 100644 -index 0000000000..a4ee7fb53c ---- /dev/null -+++ b/sysdeps/powerpc/powerpc64/multiarch/strcmp-power10.S -@@ -0,0 +1,26 @@ -+/* Optimized strcmp implementation for POWER10/PPC64. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#if defined __LITTLE_ENDIAN__ && IS_IN (libc) -+#define STRCMP __strcmp_power10 -+ -+#undef libc_hidden_builtin_def -+#define libc_hidden_builtin_def(name) -+ -+#include -+#endif /* __LITTLE_ENDIAN__ && IS_IN (libc) */ -diff --git a/sysdeps/powerpc/powerpc64/multiarch/strcmp.c b/sysdeps/powerpc/powerpc64/multiarch/strcmp.c -index 7c77c084a7..3c636e3bbc 100644 ---- a/sysdeps/powerpc/powerpc64/multiarch/strcmp.c -+++ b/sysdeps/powerpc/powerpc64/multiarch/strcmp.c -@@ -29,12 +29,16 @@ extern __typeof (strcmp) __strcmp_power7 attribute_hidden; - extern __typeof (strcmp) __strcmp_power8 attribute_hidden; - # ifdef __LITTLE_ENDIAN__ - extern __typeof (strcmp) __strcmp_power9 attribute_hidden; -+extern __typeof (strcmp) __strcmp_power10 attribute_hidden; - # endif - - # undef strcmp - - libc_ifunc_redirected (__redirect_strcmp, strcmp, - # ifdef __LITTLE_ENDIAN__ -+ (hwcap2 & PPC_FEATURE2_ARCH_3_1 -+ && hwcap & PPC_FEATURE_HAS_VSX) -+ ? __strcmp_power10 : - (hwcap2 & PPC_FEATURE2_ARCH_3_00 - && hwcap & PPC_FEATURE_HAS_ALTIVEC) - ? __strcmp_power9 : - -commit 2dbf973fe03f9b8fd5a4740ee0af0d47afdd7bbd -Author: Sachin Monga -Date: Fri Nov 21 00:30:52 2025 -0500 - - ppc64le: Restore optimized strncmp for power10 - - This patch addresses the actual cause of CVE-2025-5745 - - The vector non-volatile registers are not used anymore for - 32 byte load and comparison operation - - Additionally, the assembler workaround used earlier for the - instruction lxvp is replaced with actual instruction. - - Signed-off-by: Sachin Monga - Co-authored-by: Paul Murphy - (cherry picked from commit 2ea943f7d487d6a4166658b32af7c5365889fc34) - -diff --git a/sysdeps/powerpc/powerpc64/le/power10/strncmp.S b/sysdeps/powerpc/powerpc64/le/power10/strncmp.S -new file mode 100644 -index 0000000000..6e09fcb7f2 ---- /dev/null -+++ b/sysdeps/powerpc/powerpc64/le/power10/strncmp.S -@@ -0,0 +1,252 @@ -+/* Optimized strncmp implementation for PowerPC64/POWER10. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+ -+/* Implements the function -+ -+ int [r3] strncmp (const char *s1 [r3], const char *s2 [r4], size_t [r5] n) -+ -+ The implementation uses unaligned doubleword access to avoid specialized -+ code paths depending of data alignment for first 32 bytes and uses -+ vectorised loops after that. */ -+ -+#ifndef STRNCMP -+# define STRNCMP strncmp -+#endif -+ -+#define COMPARE_16(vreg1,vreg2,offset) \ -+ lxv vreg1+32,offset(r3); \ -+ lxv vreg2+32,offset(r4); \ -+ vcmpnezb. v7,vreg1,vreg2; \ -+ bne cr6,L(different); \ -+ cmpldi cr7,r5,16; \ -+ ble cr7,L(ret0); \ -+ addi r5,r5,-16; -+ -+#define COMPARE_32(vreg1,vreg2,offset,label1,label2) \ -+ lxvp vreg1+32,offset(r3); \ -+ lxvp vreg2+32,offset(r4); \ -+ vcmpnezb. v7,vreg1+1,vreg2+1; \ -+ bne cr6,L(label1); \ -+ vcmpnezb. v7,vreg1,vreg2; \ -+ bne cr6,L(label2); \ -+ cmpldi cr7,r5,32; \ -+ ble cr7,L(ret0); \ -+ addi r5,r5,-32; -+ -+#define TAIL_FIRST_16B(vreg1,vreg2) \ -+ vctzlsbb r6,v7; \ -+ cmpld cr7,r5,r6; \ -+ ble cr7,L(ret0); \ -+ vextubrx r5,r6,vreg1; \ -+ vextubrx r4,r6,vreg2; \ -+ subf r3,r4,r5; \ -+ blr; -+ -+#define TAIL_SECOND_16B(vreg1,vreg2) \ -+ vctzlsbb r6,v7; \ -+ addi r0,r6,16; \ -+ cmpld cr7,r5,r0; \ -+ ble cr7,L(ret0); \ -+ vextubrx r5,r6,vreg1; \ -+ vextubrx r4,r6,vreg2; \ -+ subf r3,r4,r5; \ -+ blr; -+ -+#define CHECK_N_BYTES(reg1,reg2,len_reg) \ -+ sldi r6,len_reg,56; \ -+ lxvl 32+v4,reg1,r6; \ -+ lxvl 32+v5,reg2,r6; \ -+ add reg1,reg1,len_reg; \ -+ add reg2,reg2,len_reg; \ -+ vcmpnezb v7,v4,v5; \ -+ vctzlsbb r6,v7; \ -+ cmpld cr7,r6,len_reg; \ -+ blt cr7,L(different); \ -+ cmpld cr7,r5,len_reg; \ -+ ble cr7,L(ret0); \ -+ sub r5,r5,len_reg; \ -+ -+ .machine power10 -+ENTRY_TOCLESS (STRNCMP, 4) -+ /* Check if size is 0. */ -+ cmpdi cr0,r5,0 -+ beq cr0,L(ret0) -+ andi. r7,r3,4095 -+ andi. r8,r4,4095 -+ cmpldi cr0,r7,4096-16 -+ cmpldi cr1,r8,4096-16 -+ bgt cr0,L(crosses) -+ bgt cr1,L(crosses) -+ COMPARE_16(v4,v5,0) -+ addi r3,r3,16 -+ addi r4,r4,16 -+ -+L(crosses): -+ andi. r7,r3,15 -+ subfic r7,r7,16 /* r7(nalign1) = 16 - (str1 & 15). */ -+ andi. r9,r4,15 -+ subfic r8,r9,16 /* r8(nalign2) = 16 - (str2 & 15). */ -+ cmpld cr7,r7,r8 -+ beq cr7,L(same_aligned) -+ blt cr7,L(nalign1_min) -+ -+ /* nalign2 is minimum and s2 pointer is aligned. */ -+ CHECK_N_BYTES(r3,r4,r8) -+ /* Are we on the 64B hunk which crosses a page? */ -+ andi. r10,r3,63 /* Determine offset into 64B hunk. */ -+ andi. r8,r3,15 /* The offset into the 16B hunk. */ -+ neg r7,r3 -+ andi. r9,r7,15 /* Number of bytes after a 16B cross. */ -+ rlwinm. r7,r7,26,0x3F /* ((r4-4096))>>6&63. */ -+ beq L(compare_64_pagecross) -+ mtctr r7 -+ b L(compare_64B_unaligned) -+ -+ /* nalign1 is minimum and s1 pointer is aligned. */ -+L(nalign1_min): -+ CHECK_N_BYTES(r3,r4,r7) -+ /* Are we on the 64B hunk which crosses a page? */ -+ andi. r10,r4,63 /* Determine offset into 64B hunk. */ -+ andi. r8,r4,15 /* The offset into the 16B hunk. */ -+ neg r7,r4 -+ andi. r9,r7,15 /* Number of bytes after a 16B cross. */ -+ rlwinm. r7,r7,26,0x3F /* ((r4-4096))>>6&63. */ -+ beq L(compare_64_pagecross) -+ mtctr r7 -+ -+ .p2align 5 -+L(compare_64B_unaligned): -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ COMPARE_16(v4,v5,32) -+ COMPARE_16(v4,v5,48) -+ addi r3,r3,64 -+ addi r4,r4,64 -+ bdnz L(compare_64B_unaligned) -+ -+ /* Cross the page boundary of s2, carefully. Only for first -+ iteration we have to get the count of 64B blocks to be checked. -+ From second iteration and beyond, loop counter is always 63. */ -+L(compare_64_pagecross): -+ li r11, 63 -+ mtctr r11 -+ cmpldi r10,16 -+ ble L(cross_4) -+ cmpldi r10,32 -+ ble L(cross_3) -+ cmpldi r10,48 -+ ble L(cross_2) -+L(cross_1): -+ CHECK_N_BYTES(r3,r4,r9) -+ CHECK_N_BYTES(r3,r4,r8) -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ COMPARE_16(v4,v5,32) -+ addi r3,r3,48 -+ addi r4,r4,48 -+ b L(compare_64B_unaligned) -+L(cross_2): -+ COMPARE_16(v4,v5,0) -+ addi r3,r3,16 -+ addi r4,r4,16 -+ CHECK_N_BYTES(r3,r4,r9) -+ CHECK_N_BYTES(r3,r4,r8) -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ addi r3,r3,32 -+ addi r4,r4,32 -+ b L(compare_64B_unaligned) -+L(cross_3): -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ addi r3,r3,32 -+ addi r4,r4,32 -+ CHECK_N_BYTES(r3,r4,r9) -+ CHECK_N_BYTES(r3,r4,r8) -+ COMPARE_16(v4,v5,0) -+ addi r3,r3,16 -+ addi r4,r4,16 -+ b L(compare_64B_unaligned) -+L(cross_4): -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ COMPARE_16(v4,v5,32) -+ addi r3,r3,48 -+ addi r4,r4,48 -+ CHECK_N_BYTES(r3,r4,r9) -+ CHECK_N_BYTES(r3,r4,r8) -+ b L(compare_64B_unaligned) -+ -+L(same_aligned): -+ CHECK_N_BYTES(r3,r4,r7) -+ /* Align s1 to 32B and adjust s2 address. -+ Use lxvp only if both s1 and s2 are 32B aligned. */ -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ COMPARE_16(v4,v5,32) -+ COMPARE_16(v4,v5,48) -+ addi r3,r3,64 -+ addi r4,r4,64 -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ addi r5,r5,32 -+ -+ clrldi r6,r3,59 -+ subfic r7,r6,32 -+ add r3,r3,r7 -+ add r4,r4,r7 -+ subf r5,r7,r5 -+ andi. r7,r4,0x1F -+ beq cr0,L(32B_aligned_loop) -+ -+ .p2align 5 -+L(16B_aligned_loop): -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ COMPARE_16(v4,v5,32) -+ COMPARE_16(v4,v5,48) -+ addi r3,r3,64 -+ addi r4,r4,64 -+ b L(16B_aligned_loop) -+ -+ /* Calculate and return the difference. */ -+L(different): -+ TAIL_FIRST_16B(v4,v5) -+ -+ .p2align 5 -+L(32B_aligned_loop): -+ COMPARE_32(v14,v16,0,tail1,tail2) -+ COMPARE_32(v14,v16,32,tail1,tail2) -+ COMPARE_32(v14,v16,64,tail1,tail2) -+ COMPARE_32(v14,v16,96,tail1,tail2) -+ addi r3,r3,128 -+ addi r4,r4,128 -+ b L(32B_aligned_loop) -+ -+L(tail1): TAIL_FIRST_16B(v15,v17) -+L(tail2): TAIL_SECOND_16B(v14,v16) -+ -+ .p2align 5 -+L(ret0): -+ li r3,0 -+ blr -+ -+END(STRNCMP) -+libc_hidden_builtin_def(strncmp) -diff --git a/sysdeps/powerpc/powerpc64/multiarch/Makefile b/sysdeps/powerpc/powerpc64/multiarch/Makefile -index 818f287925..c9178223a8 100644 ---- a/sysdeps/powerpc/powerpc64/multiarch/Makefile -+++ b/sysdeps/powerpc/powerpc64/multiarch/Makefile -@@ -32,7 +32,7 @@ sysdep_routines += memcpy-power8-cached memcpy-power7 memcpy-a2 memcpy-power6 \ - ifneq (,$(filter %le,$(config-machine))) - sysdep_routines += memcmp-power10 memcpy-power10 memmove-power10 memset-power10 \ - rawmemchr-power9 rawmemchr-power10 \ -- strcmp-power9 strcmp-power10 strncmp-power9 \ -+ strcmp-power9 strcmp-power10 strncmp-power9 strncmp-power10 \ - strcpy-power9 strcat-power10 stpcpy-power9 \ - strlen-power9 strncpy-power9 stpncpy-power9 strlen-power10 - endif -diff --git a/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c b/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c -index dde3bec709..f2b9cccde3 100644 ---- a/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c -+++ b/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c -@@ -164,6 +164,9 @@ __libc_ifunc_impl_list (const char *name, struct libc_ifunc_impl *array, - /* Support sysdeps/powerpc/powerpc64/multiarch/strncmp.c. */ - IFUNC_IMPL (i, name, strncmp, - #ifdef __LITTLE_ENDIAN__ -+ IFUNC_IMPL_ADD (array, i, strncmp, hwcap2 & PPC_FEATURE2_ARCH_3_1 -+ && hwcap & PPC_FEATURE_HAS_VSX, -+ __strncmp_power10) - IFUNC_IMPL_ADD (array, i, strncmp, hwcap2 & PPC_FEATURE2_ARCH_3_00 - && hwcap & PPC_FEATURE_HAS_ALTIVEC, - __strncmp_power9) -diff --git a/sysdeps/powerpc/powerpc64/multiarch/strncmp-power10.S b/sysdeps/powerpc/powerpc64/multiarch/strncmp-power10.S -new file mode 100644 -index 0000000000..bb25bc75b8 ---- /dev/null -+++ b/sysdeps/powerpc/powerpc64/multiarch/strncmp-power10.S -@@ -0,0 +1,25 @@ -+/* Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#if defined __LITTLE_ENDIAN__ && IS_IN (libc) -+#define STRNCMP __strncmp_power10 -+ -+#undef libc_hidden_builtin_def -+#define libc_hidden_builtin_def(name) -+ -+#include -+#endif -diff --git a/sysdeps/powerpc/powerpc64/multiarch/strncmp.c b/sysdeps/powerpc/powerpc64/multiarch/strncmp.c -index 4cfe27fa45..0a664a620d 100644 ---- a/sysdeps/powerpc/powerpc64/multiarch/strncmp.c -+++ b/sysdeps/powerpc/powerpc64/multiarch/strncmp.c -@@ -29,6 +29,7 @@ extern __typeof (strncmp) __strncmp_ppc attribute_hidden; - extern __typeof (strncmp) __strncmp_power8 attribute_hidden; - # ifdef __LITTLE_ENDIAN__ - extern __typeof (strncmp) __strncmp_power9 attribute_hidden; -+extern __typeof (strncmp) __strncmp_power10 attribute_hidden; - # endif - # undef strncmp - -@@ -36,6 +37,9 @@ extern __typeof (strncmp) __strncmp_power9 attribute_hidden; - ifunc symbol properly. */ - libc_ifunc_redirected (__redirect_strncmp, strncmp, - # ifdef __LITTLE_ENDIAN__ -+ (hwcap2 & PPC_FEATURE2_ARCH_3_1 -+ && hwcap & PPC_FEATURE_HAS_VSX) -+ ? __strncmp_power10 : - (hwcap2 & PPC_FEATURE2_ARCH_3_00 - && hwcap & PPC_FEATURE_HAS_ALTIVEC) - ? __strncmp_power9 : - -commit 8aaf4b732d7650c2db3beb4dc8bb70eab5b022c3 -Author: Sachin Monga -Date: Thu Nov 27 03:28:17 2025 -0500 - - ppc64le: Power 10 rawmemchr clobbers v20 (bug #33091) - - Replace non-volatile(v20) by volatile(v17) - since v20 is not restored - - Reviewed-by: Peter Bergner - (cherry picked from commit b59799f14f97f697c3a36b4380bd4ce2fbe65f11) - -diff --git a/sysdeps/powerpc/powerpc64/le/power10/strlen.S b/sysdeps/powerpc/powerpc64/le/power10/strlen.S -index ec644d5bff..29a5a7d960 100644 ---- a/sysdeps/powerpc/powerpc64/le/power10/strlen.S -+++ b/sysdeps/powerpc/powerpc64/le/power10/strlen.S -@@ -31,7 +31,7 @@ - # define FUNCNAME RAWMEMCHR - # endif - # define MCOUNT_NARGS 2 --# define VREG_ZERO v20 -+# define VREG_ZERO v17 - # define OFF_START_LOOP 256 - # define RAWMEMCHR_SUBTRACT_VECTORS \ - vsububm v4,v4,v18; \ - -commit b11411fe2ee7a8f3c3a2c1ee99c1729adb9a0efe -Author: Yury Khrustalev -Date: Thu Nov 6 12:57:58 2025 +0000 - - posix: Fix invalid flags test for p{write,read}v2 - - Two tests fail from time to time when a new flag is added for the - p{write,read}v2 functions in a new Linux kernel: - - - misc/tst-preadvwritev2 - - misc/tst-preadvwritev64v2 - - This disrupts when testing Glibc on a system with a newer kernel - and it seems we can try improve testing for invalid flags setting - all the bits that are not supposed to be supported (rather than - setting only the next unsupported bit). - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 58a31b4316f1f687184eb147ffa1c676bc6a190e) - -diff --git a/misc/tst-preadvwritev2-common.c b/misc/tst-preadvwritev2-common.c -index ff1007d6d2..5182fcdce0 100644 ---- a/misc/tst-preadvwritev2-common.c -+++ b/misc/tst-preadvwritev2-common.c -@@ -109,9 +109,8 @@ do_test_with_invalid_iov (void) - static void - do_test_with_invalid_flags (void) - { -- /* Set the next bit from the mask of all supported flags. */ -- int invalid_flag = RWF_SUPPORTED != 0 ? __builtin_clz (RWF_SUPPORTED) : 2; -- invalid_flag = 0x1 << ((sizeof (int) * CHAR_BIT) - invalid_flag); -+ /* Set all the bits that are not used by the supported flags. */ -+ int invalid_flag = ~RWF_SUPPORTED; - - char buf[32]; - const struct iovec vec = { .iov_base = buf, .iov_len = sizeof (buf) }; - -commit efdf4c0c879590109778244046f84a80a4bf8fee -Author: DJ Delorie -Date: Wed Oct 15 21:37:56 2025 -0400 - - sprof: check pread size and offset for overflow - - Add a bit of descriptive paranoia to the values we read from - the ELF headers and use to access data. - - Reviewed-by: Collin Funk - (cherry picked from commit 324084649b2da2f6840e3a1b84159a4e9a9e9a74) - -diff --git a/elf/sprof.c b/elf/sprof.c -index c82c7c9db6..e9d2a66a4f 100644 ---- a/elf/sprof.c -+++ b/elf/sprof.c -@@ -38,6 +38,7 @@ - #include - #include - #include -+#include - - /* Get libc version number. */ - #include "../version.h" -@@ -410,6 +411,7 @@ load_shobj (const char *name) - int fd; - ElfW(Shdr) *shdr; - size_t pagesize = getpagesize (); -+ struct stat st; - - /* Since we use dlopen() we must be prepared to work around the sometimes - strange lookup rules for the shared objects. If we have a file foo.so -@@ -550,14 +552,39 @@ load_shobj (const char *name) - error (EXIT_FAILURE, errno, _("Reopening shared object `%s' failed"), - map->l_name); - -+ if (fstat (fd, &st) < 0) -+ error (EXIT_FAILURE, errno, _("stat(%s) failure"), map->l_name); -+ -+ /* We're depending on data that's being read from the file, so be a -+ bit paranoid here and make sure the requests are reasonable - -+ i.e. both size and offset are nonnegative and smaller than the -+ file size, as well as the offset of the end of the data. PREAD -+ would have failed anyway, but this is more robust and explains -+ what happened better. Note that SZ must be unsigned and OFF may -+ be signed or unsigned. */ -+#define PCHECK(sz1,off1) { \ -+ size_t sz = sz1, end_off; \ -+ off_t off = off1; \ -+ if (sz > st.st_size \ -+ || off < 0 || off > st.st_size \ -+ || INT_ADD_WRAPV (sz, off, &end_off) \ -+ || end_off > st.st_size) \ -+ error (EXIT_FAILURE, ERANGE, \ -+ _("read outside of file extents %zu + %zd > %zu"), \ -+ sz, off, st.st_size); \ -+ } -+ - /* Map the section header. */ - size_t size = ehdr->e_shnum * sizeof (ElfW(Shdr)); - shdr = (ElfW(Shdr) *) alloca (size); -+ PCHECK (size, ehdr->e_shoff); - if (pread (fd, shdr, size, ehdr->e_shoff) != size) - error (EXIT_FAILURE, errno, _("reading of section headers failed")); - - /* Get the section header string table. */ - char *shstrtab = (char *) alloca (shdr[ehdr->e_shstrndx].sh_size); -+ PCHECK (shdr[ehdr->e_shstrndx].sh_size, -+ shdr[ehdr->e_shstrndx].sh_offset); - if (pread (fd, shstrtab, shdr[ehdr->e_shstrndx].sh_size, - shdr[ehdr->e_shstrndx].sh_offset) - != shdr[ehdr->e_shstrndx].sh_size) -@@ -585,6 +612,7 @@ load_shobj (const char *name) - size_t size = debuglink_entry->sh_size; - char *debuginfo_fname = (char *) alloca (size + 1); - debuginfo_fname[size] = '\0'; -+ PCHECK (size, debuglink_entry->sh_offset); - if (pread (fd, debuginfo_fname, size, debuglink_entry->sh_offset) - != size) - { -@@ -638,21 +666,32 @@ load_shobj (const char *name) - if (fd2 != -1) - { - ElfW(Ehdr) ehdr2; -+ struct stat st; -+ -+ if (fstat (fd2, &st) < 0) -+ error (EXIT_FAILURE, errno, _("stat(%s) failure"), workbuf); - - /* Read the ELF header. */ -+ PCHECK (sizeof (ehdr2), 0); - if (pread (fd2, &ehdr2, sizeof (ehdr2), 0) != sizeof (ehdr2)) - error (EXIT_FAILURE, errno, - _("reading of ELF header failed")); - - /* Map the section header. */ -- size_t size = ehdr2.e_shnum * sizeof (ElfW(Shdr)); -+ size_t size; -+ if (INT_MULTIPLY_WRAPV (ehdr2.e_shnum, sizeof (ElfW(Shdr)), &size)) -+ error (EXIT_FAILURE, errno, _("too many section headers")); -+ - ElfW(Shdr) *shdr2 = (ElfW(Shdr) *) alloca (size); -+ PCHECK (size, ehdr2.e_shoff); - if (pread (fd2, shdr2, size, ehdr2.e_shoff) != size) - error (EXIT_FAILURE, errno, - _("reading of section headers failed")); - - /* Get the section header string table. */ - shstrtab = (char *) alloca (shdr2[ehdr2.e_shstrndx].sh_size); -+ PCHECK (shdr2[ehdr2.e_shstrndx].sh_size, -+ shdr2[ehdr2.e_shstrndx].sh_offset); - if (pread (fd2, shstrtab, shdr2[ehdr2.e_shstrndx].sh_size, - shdr2[ehdr2.e_shstrndx].sh_offset) - != shdr2[ehdr2.e_shstrndx].sh_size) - -commit 2a0873aa81446149c6065237e1dc2511201bef88 -Author: Collin Funk -Date: Wed Oct 22 01:51:09 2025 -0700 - - sprof: fix -Wformat warnings on 32-bit hosts - - Reviewed-by: H.J. Lu - (cherry picked from commit 9681f645ba20fc3c18eb12ffebf94e3df1f888e3) - -diff --git a/elf/sprof.c b/elf/sprof.c -index e9d2a66a4f..513e0470b2 100644 ---- a/elf/sprof.c -+++ b/elf/sprof.c -@@ -570,8 +570,8 @@ load_shobj (const char *name) - || INT_ADD_WRAPV (sz, off, &end_off) \ - || end_off > st.st_size) \ - error (EXIT_FAILURE, ERANGE, \ -- _("read outside of file extents %zu + %zd > %zu"), \ -- sz, off, st.st_size); \ -+ _("read outside of file extents %zu + %jd > %jd"), \ -+ sz, (intmax_t) off, (intmax_t) st.st_size); \ - } - - /* Map the section header. */ - -commit 8dfb84ad4efbc39c7a7d9efdff6f6ac9017e0a53 -Author: Florian Weimer -Date: Thu Nov 6 14:33:22 2025 +0100 - - support: Fix FILE * leak in check_for_unshare_hints in test-container - - The file opened via fopen is never closed. - - (cherry picked from commit 20a2a756089eacd7e7f4c02e381e82b5d0e40a2c) - -diff --git a/support/test-container.c b/support/test-container.c -index 1c40ab377f..d78139622f 100644 ---- a/support/test-container.c -+++ b/support/test-container.c -@@ -705,6 +705,7 @@ check_for_unshare_hints (int require_pidns) - - val = -1; /* Sentinel. */ - int cnt = fscanf (f, "%d", &val); -+ fclose (f); - if (cnt == 1 && val != files[i].bad_value) - continue; - - -commit a1d3294a5bed821aece03994ab4e72c8b822a962 -Author: Florian Weimer -Date: Thu Nov 6 14:49:21 2025 +0100 - - support: Exit on consistency check failure in resolv_response_add_name - - Using TEST_VERIFY (crname_target != crname) instructs some analysis - tools that crname_target == crname might hold. Under this assumption, - they report a use-after-free for crname_target->offset below, caused - by the previous free (crname). - - Reviewed-by: Collin Funk - (cherry picked from commit b64335ff111c071fde61aec1c1a8460afb3d16d4) - -diff --git a/support/resolv_test.c b/support/resolv_test.c -index ab37d3d58c..29e59da958 100644 ---- a/support/resolv_test.c -+++ b/support/resolv_test.c -@@ -326,7 +326,7 @@ resolv_response_add_name (struct resolv_response_builder *b, - crname_target = *ptr; - else - crname_target = NULL; -- TEST_VERIFY (crname_target != crname); -+ TEST_VERIFY_EXIT (crname_target != crname); - /* Not added to the tree. */ - free (crname); - } - -commit f122d0b4d145814869bf10c56db1d971bcba55c5 -Author: Sunil K Pandey -Date: Tue Dec 9 08:57:44 2025 -0800 - - nptl: Optimize trylock for high cache contention workloads (BZ #33704) - - Check lock availability before acquisition to reduce cache line - bouncing. Significantly improves trylock throughput on multi-core - systems under heavy contention. - - Tested on x86_64. - - Fixes BZ #33704. - - Co-authored-by: Alex M Wells - Reviewed-by: Wilco Dijkstra - (cherry picked from commit 63716823dbad9482e09972907ae98e9cb00f9b86) - -diff --git a/nptl/pthread_mutex_trylock.c b/nptl/pthread_mutex_trylock.c -index dbb8fcc754..392619021b 100644 ---- a/nptl/pthread_mutex_trylock.c -+++ b/nptl/pthread_mutex_trylock.c -@@ -48,7 +48,8 @@ ___pthread_mutex_trylock (pthread_mutex_t *mutex) - return 0; - } - -- if (lll_trylock (mutex->__data.__lock) == 0) -+ if (atomic_load_relaxed (&(mutex->__data.__lock)) == 0 -+ && lll_trylock (mutex->__data.__lock) == 0) - { - /* Record the ownership. */ - mutex->__data.__owner = id; -@@ -71,7 +72,10 @@ ___pthread_mutex_trylock (pthread_mutex_t *mutex) - /*FALL THROUGH*/ - case PTHREAD_MUTEX_ADAPTIVE_NP: - case PTHREAD_MUTEX_ERRORCHECK_NP: -- if (lll_trylock (mutex->__data.__lock) != 0) -+ /* Mutex type is already loaded, lock check overhead should -+ be minimal. */ -+ if (atomic_load_relaxed (&(mutex->__data.__lock)) != 0 -+ || lll_trylock (mutex->__data.__lock) != 0) - break; - - /* Record the ownership. */ - -commit b0ec8fb689df862171f0f78994a3bdeb51313545 -Author: Siddhesh Poyarekar -Date: Thu Jan 15 06:06:40 2026 -0500 - - memalign: reinstate alignment overflow check (CVE-2026-0861) - - The change to cap valid sizes to PTRDIFF_MAX inadvertently dropped the - overflow check for alignment in memalign functions, _mid_memalign and - _int_memalign. Reinstate the overflow check in _int_memalign, aligned - with the PTRDIFF_MAX change since that is directly responsible for the - CVE. The missing _mid_memalign check is not relevant (and does not have - a security impact) and may need a different approach to fully resolve, - so it has been omitted. - - CVE-Id: CVE-2026-0861 - Vulnerable-Commit: 9bf8e29ca136094f73f69f725f15c51facc97206 - Reported-by: Igor Morgenstern, Aisle Research - Fixes: BZ #33796 - Reviewed-by: Wilco Dijkstra - Signed-off-by: Siddhesh Poyarekar - (cherry picked from commit c9188d333717d3ceb7e3020011651f424f749f93) - -diff --git a/malloc/malloc.c b/malloc/malloc.c -index 5f3e701fd1..1d5aa304d3 100644 ---- a/malloc/malloc.c -+++ b/malloc/malloc.c -@@ -5167,7 +5167,7 @@ _int_memalign (mstate av, size_t alignment, size_t bytes) - INTERNAL_SIZE_T size; - - nb = checked_request2size (bytes); -- if (nb == 0) -+ if (nb == 0 || alignment > PTRDIFF_MAX) - { - __set_errno (ENOMEM); - return NULL; -@@ -5183,7 +5183,10 @@ _int_memalign (mstate av, size_t alignment, size_t bytes) - we don't find anything in those bins, the common malloc code will - scan starting at 2x. */ - -- /* Call malloc with worst case padding to hit alignment. */ -+ /* Call malloc with worst case padding to hit alignment. ALIGNMENT is a -+ power of 2, so it tops out at (PTRDIFF_MAX >> 1) + 1, leaving plenty of -+ space to add MINSIZE and whatever checked_request2size adds to BYTES to -+ get NB. Consequently, total below also does not overflow. */ - m = (char *) (_int_malloc (av, nb + alignment + MINSIZE)); - - if (m == NULL) -diff --git a/malloc/tst-malloc-too-large.c b/malloc/tst-malloc-too-large.c -index a548a37b46..a1bda673a3 100644 ---- a/malloc/tst-malloc-too-large.c -+++ b/malloc/tst-malloc-too-large.c -@@ -152,7 +152,6 @@ test_large_allocations (size_t size) - } - - --static long pagesize; - - /* This function tests the following aligned memory allocation functions - using several valid alignments and precedes each allocation test with a -@@ -171,8 +170,8 @@ test_large_aligned_allocations (size_t size) - - /* All aligned memory allocation functions expect an alignment that is a - power of 2. Given this, we test each of them with every valid -- alignment from 1 thru PAGESIZE. */ -- for (align = 1; align <= pagesize; align *= 2) -+ alignment for the type of ALIGN, i.e. until it wraps to 0. */ -+ for (align = 1; align > 0; align <<= 1) - { - test_setup (); - #if __GNUC_PREREQ (7, 0) -@@ -265,11 +264,6 @@ do_test (void) - DIAG_IGNORE_NEEDS_COMMENT (7, "-Walloc-size-larger-than="); - #endif - -- /* Aligned memory allocation functions need to be tested up to alignment -- size equivalent to page size, which should be a power of 2. */ -- pagesize = sysconf (_SC_PAGESIZE); -- TEST_VERIFY_EXIT (powerof2 (pagesize)); -- - /* Loop 1: Ensure that all allocations with SIZE close to SIZE_MAX, i.e. - in the range (SIZE_MAX - 2^14, SIZE_MAX], fail. - - -commit 453e6b8dbab935257eb0802b0c97bca6b67ba30e -Author: Carlos O'Donell -Date: Thu Jan 15 15:09:38 2026 -0500 - - resolv: Fix NSS DNS backend for getnetbyaddr (CVE-2026-0915) - - The default network value of zero for net was never tested for and - results in a DNS query constructed from uninitialized stack bytes. - The solution is to provide a default query for the case where net - is zero. - - Adding a test case for this was straight forward given the existence of - tst-resolv-network and if the test is added without the fix you observe - this failure: - - FAIL: resolv/tst-resolv-network - original exit status 1 - error: tst-resolv-network.c:174: invalid QNAME: \146\218\129\128 - error: 1 test failures - - With a random QNAME resulting from the use of uninitialized stack bytes. - - After the fix the test passes. - - Additionally verified using wireshark before and after to ensure - on-the-wire bytes for the DNS query were as expected. - - No regressions on x86_64. - - Reviewed-by: Florian Weimer - (cherry picked from commit e56ff82d5034ec66c6a78f517af6faa427f65b0b) - -diff --git a/resolv/nss_dns/dns-network.c b/resolv/nss_dns/dns-network.c -index 519f8422ca..e14e959d7c 100644 ---- a/resolv/nss_dns/dns-network.c -+++ b/resolv/nss_dns/dns-network.c -@@ -207,6 +207,10 @@ _nss_dns_getnetbyaddr_r (uint32_t net, int type, struct netent *result, - sprintf (qbuf, "%u.%u.%u.%u.in-addr.arpa", net_bytes[3], net_bytes[2], - net_bytes[1], net_bytes[0]); - break; -+ default: -+ /* Default network (net is originally zero). */ -+ strcpy (qbuf, "0.0.0.0.in-addr.arpa"); -+ break; - } - - net_buffer.buf = orig_net_buffer = (querybuf *) alloca (1024); -diff --git a/resolv/tst-resolv-network.c b/resolv/tst-resolv-network.c -index d9f69649d0..181be80835 100644 ---- a/resolv/tst-resolv-network.c -+++ b/resolv/tst-resolv-network.c -@@ -46,6 +46,9 @@ handle_code (const struct resolv_response_context *ctx, - { - switch (code) - { -+ case 0: -+ send_ptr (b, qname, qclass, qtype, "0.in-addr.arpa"); -+ break; - case 1: - send_ptr (b, qname, qclass, qtype, "1.in-addr.arpa"); - break; -@@ -265,6 +268,9 @@ do_test (void) - "error: TRY_AGAIN\n"); - - /* Lookup by address, success cases. */ -+ check_reverse (0, -+ "name: 0.in-addr.arpa\n" -+ "net: 0x00000000\n"); - check_reverse (1, - "name: 1.in-addr.arpa\n" - "net: 0x00000001\n"); - -commit cbf39c26b25801e9bc88499b4fd361ac172d4125 -Author: Adhemerval Zanella -Date: Thu Jan 15 10:32:19 2026 -0300 - - posix: Reset wordexp_t fields with WRDE_REUSE (CVE-2025-15281 / BZ 33814) - - The wordexp fails to properly initialize the input wordexp_t when - WRDE_REUSE is used. The wordexp_t struct is properly freed, but - reuses the old wc_wordc value and updates the we_wordv in the - wrong position. A later wordfree will then call free with an - invalid pointer. - - Checked on x86_64-linux-gnu and i686-linux-gnu. - - Reviewed-by: Carlos O'Donell - (cherry picked from commit 80cc58ea2de214f85b0a1d902a3b668ad2ecb302) - -diff --git a/NEWS b/NEWS -index ed3c114c7a..7e7e1930dd 100644 ---- a/NEWS -+++ b/NEWS -@@ -16,6 +16,8 @@ The following bugs were resolved with this release: - [33356] nptl: creating thread stack with guardsize 0 can erroneously - conclude MADV_GUARD_INSTALL is available - [33361] nss: Group merge does not react to ERANGE during merge -+ [33814] glob: wordexp with WRDE_REUSE and WRDE_APPEND may return -+ uninitialized memory - - Version 2.42 - -diff --git a/posix/Makefile b/posix/Makefile -index a36e5decd3..1ea86efcc1 100644 ---- a/posix/Makefile -+++ b/posix/Makefile -@@ -327,6 +327,7 @@ tests := \ - tst-wait4 \ - tst-waitid \ - tst-wordexp-nocmd \ -+ tst-wordexp-reuse \ - tstgetopt \ - # tests - -@@ -457,6 +458,8 @@ generated += \ - tst-rxspencer-no-utf8.mtrace \ - tst-vfork3-mem.out \ - tst-vfork3.mtrace \ -+ tst-wordexp-reuse-mem.out \ -+ tst-wordexp-reuse.mtrace \ - # generated - endif - endif -@@ -492,6 +495,7 @@ tests-special += \ - $(objpfx)tst-pcre-mem.out \ - $(objpfx)tst-rxspencer-no-utf8-mem.out \ - $(objpfx)tst-vfork3-mem.out \ -+ $(objpfx)tst-wordexp-reuse.out \ - # tests-special - endif - endif -@@ -775,3 +779,10 @@ $(objpfx)posix-conf-vars-def.h: $(..)scripts/gen-posix-conf-vars.awk \ - $(make-target-directory) - $(AWK) -f $(filter-out Makefile, $^) > $@.tmp - mv -f $@.tmp $@ -+ -+tst-wordexp-reuse-ENV += MALLOC_TRACE=$(objpfx)tst-wordexp-reuse.mtrace \ -+ LD_PRELOAD=$(common-objpfx)/malloc/libc_malloc_debug.so -+ -+$(objpfx)tst-wordexp-reuse-mem.out: $(objpfx)tst-wordexp-reuse.out -+ $(common-objpfx)malloc/mtrace $(objpfx)tst-wordexp-reuse.mtrace > $@; \ -+ $(evaluate-test) -diff --git a/posix/tst-wordexp-reuse.c b/posix/tst-wordexp-reuse.c -new file mode 100644 -index 0000000000..3926b9f557 ---- /dev/null -+++ b/posix/tst-wordexp-reuse.c -@@ -0,0 +1,89 @@ -+/* Test for wordexp with WRDE_REUSE flag. -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+ -+#include -+ -+static int -+do_test (void) -+{ -+ mtrace (); -+ -+ { -+ wordexp_t p = { 0 }; -+ TEST_COMPARE (wordexp ("one", &p, 0), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[0], "one"); -+ TEST_COMPARE (wordexp ("two", &p, WRDE_REUSE), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[0], "two"); -+ wordfree (&p); -+ } -+ -+ { -+ wordexp_t p = { .we_offs = 2 }; -+ TEST_COMPARE (wordexp ("one", &p, 0), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[0], "one"); -+ TEST_COMPARE (wordexp ("two", &p, WRDE_REUSE | WRDE_DOOFFS), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[p.we_offs + 0], "two"); -+ wordfree (&p); -+ } -+ -+ { -+ wordexp_t p = { 0 }; -+ TEST_COMPARE (wordexp ("one", &p, 0), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[0], "one"); -+ TEST_COMPARE (wordexp ("two", &p, WRDE_REUSE | WRDE_APPEND), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[0], "two"); -+ wordfree (&p); -+ } -+ -+ { -+ wordexp_t p = { .we_offs = 2 }; -+ TEST_COMPARE (wordexp ("one", &p, WRDE_DOOFFS), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[p.we_offs + 0], "one"); -+ TEST_COMPARE (wordexp ("two", &p, WRDE_REUSE -+ | WRDE_DOOFFS), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[p.we_offs + 0], "two"); -+ wordfree (&p); -+ } -+ -+ { -+ wordexp_t p = { .we_offs = 2 }; -+ TEST_COMPARE (wordexp ("one", &p, WRDE_DOOFFS), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[p.we_offs + 0], "one"); -+ TEST_COMPARE (wordexp ("two", &p, WRDE_REUSE -+ | WRDE_DOOFFS | WRDE_APPEND), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[p.we_offs + 0], "two"); -+ wordfree (&p); -+ } -+ -+ return 0; -+} -+ -+#include -diff --git a/posix/wordexp.c b/posix/wordexp.c -index a69b732801..9df4bb7424 100644 ---- a/posix/wordexp.c -+++ b/posix/wordexp.c -@@ -2216,7 +2216,9 @@ wordexp (const char *words, wordexp_t *pwordexp, int flags) - { - /* Minimal implementation of WRDE_REUSE for now */ - wordfree (pwordexp); -+ old_word.we_wordc = 0; - old_word.we_wordv = NULL; -+ pwordexp->we_wordc = 0; - } - - if ((flags & WRDE_APPEND) == 0) - -commit 912d89a766847649a3857985a3b5e6065c51bfd4 -Author: Florian Weimer -Date: Thu Jan 8 12:35:08 2026 +0100 - - Switch currency symbol for the bg_BG locale to euro - - Bulgaria joined the eurozone on 2026-01-01. - - Suggested-by: Йордан Гигов - Reviewed-by: Collin Funk - (cherry picked from commit 78fdb2d6b1c34ea8e779fd48f9436dfbd50b6387) - -diff --git a/localedata/locales/bg_BG b/localedata/locales/bg_BG -index 159a6c3334..eda2a8d01b 100644 ---- a/localedata/locales/bg_BG -+++ b/localedata/locales/bg_BG -@@ -248,8 +248,8 @@ reorder-end - END LC_COLLATE - - LC_MONETARY --int_curr_symbol "BGN " --currency_symbol "лв." -+int_curr_symbol "EUR " -+currency_symbol "€" - mon_decimal_point "," - mon_thousands_sep " " - mon_grouping 3 - -commit 39897805917ab1c44dbf4452b9c4c2bbafc7117b -Author: Florian Weimer -Date: Fri Feb 13 09:02:07 2026 +0100 - - nss: Introduce dedicated struct nss_database_for_fork type - - The initialized field in struct nss_database_data is rather confusing - because it is not used by the regular NSS code, only by the fork - state synchronization code. Introduce a separate type and place - the initialized field there. - - Reviewed-by: Sam James - (cherry picked from commit 7bb859f4198d0be19c31a9937eae4f6c2c9a079e) - -diff --git a/nss/nss_database.c b/nss/nss_database.c -index a7ac32beb9..a6b7d5c956 100644 ---- a/nss/nss_database.c -+++ b/nss/nss_database.c -@@ -56,7 +56,6 @@ global_state_allocate (void *closure) - { - result->data.nsswitch_conf.size = -1; /* Force reload. */ - memset (result->data.services, 0, sizeof (result->data.services)); -- result->data.initialized = true; - result->data.reload_disabled = false; - __libc_lock_init (result->lock); - result->root_ino = 0; -@@ -451,8 +450,8 @@ nss_database_check_reload_and_get (struct nss_database_state *local, - /* Avoid overwriting the global configuration until we have loaded - everything successfully. Otherwise, if the file change - information changes back to what is in the global configuration, -- the lookups would use the partially-written configuration. */ -- struct nss_database_data staging = { .initialized = true, }; -+ the lookups would use the partially-written configuration. */ -+ struct nss_database_data staging = { }; - - bool ok = nss_database_reload (&staging, &initial); - -@@ -503,7 +502,7 @@ __nss_database_freeres (void) - } - - void --__nss_database_fork_prepare_parent (struct nss_database_data *data) -+__nss_database_fork_prepare_parent (struct nss_database_for_fork *data) - { - /* Do not use allocate_once to trigger loading unnecessarily. */ - struct nss_database_state *local = atomic_load_acquire (&global_database_state); -@@ -515,20 +514,21 @@ __nss_database_fork_prepare_parent (struct nss_database_data *data) - because it avoids acquiring the lock during the actual - fork. */ - __libc_lock_lock (local->lock); -- *data = local->data; -+ data->data = local->data; - __libc_lock_unlock (local->lock); -+ data->initialized = true; - } - } - - void --__nss_database_fork_subprocess (struct nss_database_data *data) -+__nss_database_fork_subprocess (struct nss_database_for_fork *data) - { - struct nss_database_state *local = atomic_load_acquire (&global_database_state); - if (data->initialized) - { - /* Restore the state at the point of the fork. */ - assert (local != NULL); -- local->data = *data; -+ local->data = data->data; - __libc_lock_init (local->lock); - } - else if (local != NULL) -diff --git a/nss/nss_database.h b/nss/nss_database.h -index 0eaea49685..c170da03f6 100644 ---- a/nss/nss_database.h -+++ b/nss/nss_database.h -@@ -70,15 +70,21 @@ struct nss_database_data - struct file_change_detection nsswitch_conf; - nss_action_list services[NSS_DATABASE_COUNT]; - int reload_disabled; /* Actually bool; int for atomic access. */ -- bool initialized; -+}; -+ -+/* Use to store a consistent state snapshot across fork. */ -+struct nss_database_for_fork -+{ -+ bool initialized; /* Set to true if the data field below is initialized. */ -+ struct nss_database_data data; - }; - - /* Called by fork in the parent process, before forking. */ --void __nss_database_fork_prepare_parent (struct nss_database_data *data) -+void __nss_database_fork_prepare_parent (struct nss_database_for_fork *) - attribute_hidden; - - /* Called by fork in the new subprocess, after forking. */ --void __nss_database_fork_subprocess (struct nss_database_data *data) -+void __nss_database_fork_subprocess (struct nss_database_for_fork *) - attribute_hidden; - - #endif /* _NSS_DATABASE_H */ -diff --git a/posix/fork.c b/posix/fork.c -index 011e92fc1d..7f2370f2eb 100644 ---- a/posix/fork.c -+++ b/posix/fork.c -@@ -50,7 +50,7 @@ __libc_fork (void) - - lastrun = __run_prefork_handlers (multiple_threads); - -- struct nss_database_data nss_database_data; -+ struct nss_database_for_fork nss_database_data; - - /* If we are not running multiple threads, we do not have to - preserve lock state. If fork runs from a signal handler, only - -commit 937ef7aaf3ce41038b3e12675a6298b86b389af2 -Author: Florian Weimer -Date: Fri Feb 13 09:02:07 2026 +0100 - - Linux: In getlogin_r, use utmp fallback only for specific errors - - Most importantly, if getwpuid_r fails, it does not make sense to retry - via utmp because the user ID obtained from there is less reliable than - the one from /proc/self/loginuid. - - Reviewed-by: Sam James - (cherry picked from commit 28660f4b45afa8921c2faebaec2846f95f670ba0) - -diff --git a/sysdeps/unix/sysv/linux/getlogin_r.c b/sysdeps/unix/sysv/linux/getlogin_r.c -index f03ecd4da9..0e66944570 100644 ---- a/sysdeps/unix/sysv/linux/getlogin_r.c -+++ b/sysdeps/unix/sysv/linux/getlogin_r.c -@@ -37,7 +37,12 @@ __getlogin_r_loginuid (char *name, size_t namesize) - { - int fd = __open_nocancel ("/proc/self/loginuid", O_RDONLY); - if (fd == -1) -- return -1; -+ { -+ if (errno == ENOENT) -+ /* Trigger utmp fallback. */ -+ return -1; -+ return errno; -+ } - - /* We are reading a 32-bit number. 12 bytes are enough for the text - representation. If not, something is wrong. */ -@@ -45,6 +50,8 @@ __getlogin_r_loginuid (char *name, size_t namesize) - ssize_t n = TEMP_FAILURE_RETRY (__read_nocancel (fd, uidbuf, - sizeof (uidbuf))); - __close_nocancel_nostatus (fd); -+ if (n < 0) -+ return errno; - - uid_t uid; - char *endp; -@@ -53,12 +60,13 @@ __getlogin_r_loginuid (char *name, size_t namesize) - || (uidbuf[n] = '\0', - uid = strtoul (uidbuf, &endp, 10), - endp == uidbuf || *endp != '\0')) -- return -1; -+ return EINVAL; - - /* If there is no login uid, linux sets /proc/self/loginid to the sentinel - value of, (uid_t) -1, so check if that value is set and return early to - avoid making unneeded nss lookups. */ - if (uid == (uid_t) -1) -+ /* Trigger utmp fallback. */ - return -1; - - struct passwd pwd; -@@ -78,9 +86,14 @@ __getlogin_r_loginuid (char *name, size_t namesize) - } - } - -- if (res != 0 || tpwd == NULL) -+ if (res != 0) -+ { -+ result = res; -+ goto out; -+ } -+ if (tpwd == NULL) - { -- result = -1; -+ result = ENOENT; - goto out; - } - - -commit ebd45473f5421e0fced5ba2cde0f1aaa36e79b61 -Author: Florian Weimer -Date: Fri Feb 13 09:02:07 2026 +0100 - - nss: Missing checks in __nss_configure_lookup, __nss_database_get (bug 28940) - - This avoids a null pointer dereference in the - nss_database_check_reload_and_get function, and assertion failures. - - Reviewed-by: Sam James - (cherry picked from commit 5b713b49443eb6a4e54e50e2f0147105f86dab02) - -diff --git a/nss/Makefile b/nss/Makefile -index 1991b7482a..f690c29b94 100644 ---- a/nss/Makefile -+++ b/nss/Makefile -@@ -326,6 +326,7 @@ tests := \ - tst-gshadow \ - tst-nss-getpwent \ - tst-nss-hash \ -+ tst-nss-malloc-failure-getlogin_r \ - tst-nss-test1 \ - tst-nss-test2 \ - tst-nss-test4 \ -diff --git a/nss/nss_database.c b/nss/nss_database.c -index a6b7d5c956..7aa460c7df 100644 ---- a/nss/nss_database.c -+++ b/nss/nss_database.c -@@ -250,9 +250,12 @@ __nss_configure_lookup (const char *dbname, const char *service_line) - - /* Force any load/cache/read whatever to happen, so we can override - it. */ -- __nss_database_get (db, &result); -+ if (!__nss_database_get (db, &result)) -+ return -1; - - local = nss_database_state_get (); -+ if (local == NULL) -+ return -1; - - result = __nss_action_parse (service_line); - if (result == NULL) -@@ -477,6 +480,8 @@ bool - __nss_database_get (enum nss_database db, nss_action_list *actions) - { - struct nss_database_state *local = nss_database_state_get (); -+ if (local == NULL) -+ return false; - return nss_database_check_reload_and_get (local, actions, db); - } - libc_hidden_def (__nss_database_get) -diff --git a/nss/tst-nss-malloc-failure-getlogin_r.c b/nss/tst-nss-malloc-failure-getlogin_r.c -new file mode 100644 -index 0000000000..0e2985ad57 ---- /dev/null -+++ b/nss/tst-nss-malloc-failure-getlogin_r.c -@@ -0,0 +1,345 @@ -+/* Test NSS/getlogin_r with injected allocation failures (bug 28940). -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+ -+/* This test calls getpwuid_r via getlogin_r (on Linux). -+ -+ This test uses the NSS system configuration to exercise that code -+ path. It means that it can fail (crash) if malloc failure is not -+ handled by NSS modules for the passwd database. */ -+ -+/* Data structure allocated via MAP_SHARED, so that writes from the -+ subprocess are visible. */ -+struct shared_data -+{ -+ /* Number of tracked allocations performed so far. */ -+ volatile unsigned int allocation_count; -+ -+ /* If this number is reached, one allocation fails. */ -+ volatile unsigned int failing_allocation; -+ -+ /* The number of allocations performed during initialization -+ (before the actual getlogin_r call). */ -+ volatile unsigned int init_allocation_count; -+ -+ /* Error code of an expected getlogin_r failure. */ -+ volatile int expected_failure; -+ -+ /* The subprocess stores the expected name here. */ -+ char name[100]; -+}; -+ -+/* Allocation count in shared mapping. */ -+static struct shared_data *shared; -+ -+/* Returns true if a failure should be injected for this allocation. */ -+static bool -+fail_this_allocation (void) -+{ -+ if (shared != NULL) -+ { -+ unsigned int count = shared->allocation_count; -+ shared->allocation_count = count + 1; -+ return count == shared->failing_allocation; -+ } -+ else -+ return false; -+} -+ -+/* Failure-injecting wrappers for allocation functions used by glibc. */ -+ -+void * -+malloc (size_t size) -+{ -+ if (fail_this_allocation ()) -+ { -+ errno = ENOMEM; -+ return NULL; -+ } -+ extern __typeof (malloc) __libc_malloc; -+ return __libc_malloc (size); -+} -+ -+void * -+calloc (size_t a, size_t b) -+{ -+ if (fail_this_allocation ()) -+ { -+ errno = ENOMEM; -+ return NULL; -+ } -+ extern __typeof (calloc) __libc_calloc; -+ return __libc_calloc (a, b); -+} -+ -+void * -+realloc (void *ptr, size_t size) -+{ -+ if (fail_this_allocation ()) -+ { -+ errno = ENOMEM; -+ return NULL; -+ } -+ extern __typeof (realloc) __libc_realloc; -+ return __libc_realloc (ptr, size); -+} -+ -+/* No-op subprocess to verify that support_isolate_in_subprocess does -+ not perform any heap allocations. */ -+static void -+no_op (void *ignored) -+{ -+} -+ -+/* Perform a getlogin_r call in a subprocess, to obtain the number of -+ allocations used and the expected result of a successful call. */ -+static void -+initialize (void *configure_lookup) -+{ -+ shared->init_allocation_count = 0; -+ if (configure_lookup != NULL) -+ { -+ TEST_COMPARE (__nss_configure_lookup ("passwd", configure_lookup), 0); -+ shared->init_allocation_count = shared->allocation_count; -+ } -+ -+ shared->name[0] = '\0'; -+ int ret = getlogin_r (shared->name, sizeof (shared->name)); -+ if (ret != 0) -+ { -+ printf ("info: getlogin_r failed: %s (%d)\n", -+ strerrorname_np (ret), ret); -+ shared->expected_failure = ret; -+ } -+ else -+ { -+ shared->expected_failure = 0; -+ if (shared->name[0] == '\0') -+ FAIL ("error: getlogin_r succeeded without result\n"); -+ else -+ printf ("info: getlogin_r: \"%s\"\n", shared->name); -+ } -+} -+ -+/* Perform getlogin_r in a subprocess with fault injection. */ -+static void -+test_in_subprocess (void *configure_lookup) -+{ -+ if (configure_lookup != NULL -+ && __nss_configure_lookup ("passwd", configure_lookup) < 0) -+ { -+ printf ("info: __nss_configure_lookup failed: %s (%d)\n", -+ strerrorname_np (errno), errno); -+ TEST_COMPARE (errno, ENOMEM); -+ TEST_VERIFY (shared->allocation_count <= shared->init_allocation_count); -+ return; -+ } -+ -+ unsigned int inject_at = shared->failing_allocation; -+ char name[sizeof (shared->name)] = "name not set"; -+ int ret = getlogin_r (name, sizeof (name)); -+ shared->failing_allocation = ~0U; -+ -+ if (ret == 0) -+ { -+ TEST_COMPARE (shared->expected_failure, 0); -+ TEST_COMPARE_STRING (name, shared->name); -+ } -+ else -+ { -+ printf ("info: allocation %u failure results in error %s (%d)\n", -+ inject_at, strerrorname_np (ret), ret); -+ -+ if (ret != ENOMEM) -+ { -+ if (shared->expected_failure != 0) -+ TEST_COMPARE (ret, shared->expected_failure); -+ else if (configure_lookup == NULL) -+ /* The ENOENT failure can happen due to an issue related -+ to bug 22041: dlopen failure does not result in ENOMEM. */ -+ TEST_COMPARE (ret, ENOENT); -+ else -+ FAIL ("unexpected getlogin_r error"); -+ } -+ } -+ -+ if (shared->expected_failure == 0) -+ { -+ /* The second call should succeed. */ -+ puts ("info: about to perform second getlogin_r call"); -+ ret = getlogin_r (name, sizeof (name)); -+ if (configure_lookup == NULL) -+ { -+ /* This check can fail due to bug 22041 if the malloc error -+ injection causes a failure internally in dlopen. */ -+ if (ret != 0) -+ { -+ printf ("warning: second getlogin_r call failed with %s (%d)\n", -+ strerrorname_np (ret), ret); -+ TEST_COMPARE (ret, ENOENT); -+ } -+ } -+ else -+ /* If __nss_configure_lookup has been called, the error caching -+ bug does not happen because nss_files is built-in, and the -+ second getlogin_r is expected to succeed. */ -+ TEST_COMPARE (ret, 0); -+ if (ret == 0) -+ TEST_COMPARE_STRING (name, shared->name); -+ } -+} -+ -+/* Set by the --failing-allocation command line option. Together with -+ --direct, this can be used to trigger an allocation failure in the -+ original process, which may help with debugging. */ -+static int option_failing_allocation = -1; -+ -+/* Set by --override, to be used with --failing-allocation. Turns on -+ the __nss_configure_lookup call for passwd/files, which is disabled -+ by default. */ -+static int option_override = 0; -+ -+static int -+do_test (void) -+{ -+ char files[] = "files"; -+ -+ if (option_failing_allocation >= 0) -+ { -+ /* The test was invoked with --failing-allocation. Perform just -+ one test, using the original nsswitch.conf. This is a -+ condensed version of the probing/testing loop below. */ -+ printf ("info: testing with failing allocation %d\n", -+ option_failing_allocation); -+ shared = support_shared_allocate (sizeof (*shared)); -+ shared->failing_allocation = ~0U; -+ char *configure_lookup = option_override ? files : NULL; -+ support_isolate_in_subprocess (initialize, configure_lookup); -+ shared->allocation_count = 0; -+ shared->failing_allocation = option_failing_allocation; -+ test_in_subprocess (configure_lookup); /* No subprocess. */ -+ support_shared_free (shared); -+ shared = NULL; -+ return 0; -+ } -+ -+ bool any_success = false; -+ -+ for (int do_configure_lookup = 0; do_configure_lookup < 2; -+ ++do_configure_lookup) -+ { -+ if (do_configure_lookup) -+ puts ("info: testing with nsswitch.conf override"); -+ else -+ puts ("info: testing with original nsswitch.conf"); -+ -+ char *configure_lookup = do_configure_lookup ? files : NULL; -+ -+ shared = support_shared_allocate (sizeof (*shared)); -+ -+ /* Disable fault injection. */ -+ shared->failing_allocation = ~0U; -+ -+ support_isolate_in_subprocess (no_op, NULL); -+ TEST_COMPARE (shared->allocation_count, 0); -+ -+ support_isolate_in_subprocess (initialize, configure_lookup); -+ -+ if (shared->name[0] != '\0') -+ any_success = true; -+ -+ /* The number of allocations in the successful case. Once the -+ number of expected allocations is exceeded, injecting further -+ failures does not make a difference (assuming that the number -+ of malloc calls is deterministic). */ -+ unsigned int maximum_allocation_count = shared->allocation_count; -+ printf ("info: initial getlogin_r performed %u allocations\n", -+ maximum_allocation_count); -+ -+ for (unsigned int inject_at = 0; inject_at <= maximum_allocation_count; -+ ++inject_at) -+ { -+ printf ("info: running fault injection at allocation %u\n", -+ inject_at); -+ shared->allocation_count = 0; -+ shared->failing_allocation = inject_at; -+ support_isolate_in_subprocess (test_in_subprocess, configure_lookup); -+ } -+ -+ support_shared_free (shared); -+ shared = NULL; -+ } -+ -+ { -+ FILE *fp = fopen (_PATH_NSSWITCH_CONF, "r"); -+ if (fp == NULL) -+ printf ("info: no %s file\n", _PATH_NSSWITCH_CONF); -+ else -+ { -+ printf ("info: %s contents follows\n", _PATH_NSSWITCH_CONF); -+ int last_ch = '\n'; -+ while (true) -+ { -+ int ch = fgetc (fp); -+ if (ch == EOF) -+ break; -+ putchar (ch); -+ last_ch = ch; -+ } -+ if (last_ch != '\n') -+ putchar ('\n'); -+ printf ("(end of %s contents)\n", _PATH_NSSWITCH_CONF); -+ xfclose (fp); -+ } -+ } -+ -+ support_record_failure_barrier (); -+ -+ if (!any_success) -+ FAIL_UNSUPPORTED ("no successful getlogin_r calls"); -+ -+ return 0; -+} -+ -+static void -+cmdline_process (int c) -+{ -+ if (c == 'F') -+ option_failing_allocation = atoi (optarg); -+} -+ -+#define CMDLINE_OPTIONS \ -+ { "failing-allocation", required_argument, NULL, 'F' }, \ -+ { "override", no_argument, &option_override, 1 }, -+ -+#define CMDLINE_PROCESS cmdline_process -+ -+#include - -commit 9cd9c9054409d192aab06bfea32624af9ffa8121 -Author: Florian Weimer -Date: Fri Nov 28 11:46:09 2025 +0100 - - iconvdata: Fix invalid pointer arithmetic in ANSI_X3.110 module - - The expression inptr + 1 can technically be invalid: if inptr == inend, - inptr may point one element past the end of an array. - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit e98bd0c54d5e296ad1be91b6fe35260c6b87e733) - -diff --git a/iconvdata/ansi_x3.110.c b/iconvdata/ansi_x3.110.c -index c5506b13b8..94e6e6b745 100644 ---- a/iconvdata/ansi_x3.110.c -+++ b/iconvdata/ansi_x3.110.c -@@ -407,7 +407,7 @@ static const char from_ucs4[][2] = - is also available. */ \ - uint32_t ch2; \ - \ -- if (inptr + 1 >= inend) \ -+ if (inend - inptr <= 1) \ - { \ - /* The second character is not available. */ \ - result = __GCONV_INCOMPLETE_INPUT; \ - -commit 1a19d5a507eb82a2cf1cf8bd1c14ca1758fb8a82 -Author: Florian Weimer -Date: Mon Jan 26 17:12:37 2026 +0100 - - posix: Run tst-wordexp-reuse-mem test - - The test was not properly scheduled for execution with a Makefile - dependency. - - Fixes commit 80cc58ea2de214f85b0a1d902a3b668ad2ecb302 ("posix: Reset - wordexp_t fields with WRDE_REUSE (CVE-2025-15281 / BZ 33814"). - - (cherry picked from commit bed2db02f3183e93f21d506786c5f884a1dec9e7) - -diff --git a/posix/Makefile b/posix/Makefile -index 1ea86efcc1..0b29c9aa4e 100644 ---- a/posix/Makefile -+++ b/posix/Makefile -@@ -495,7 +495,7 @@ tests-special += \ - $(objpfx)tst-pcre-mem.out \ - $(objpfx)tst-rxspencer-no-utf8-mem.out \ - $(objpfx)tst-vfork3-mem.out \ -- $(objpfx)tst-wordexp-reuse.out \ -+ $(objpfx)tst-wordexp-reuse-mem.out \ - # tests-special - endif - endif - -commit 8e863fb1c92360520704a69dc948be6bb4a17cb3 -Author: Carlos O'Donell -Date: Fri Mar 20 16:43:33 2026 -0400 - - resolv: Count records correctly (CVE-2026-4437) - - The answer section boundary was previously ignored, and the code in - getanswer_ptr would iterate past the last resource record, but not - beyond the end of the returned data. This could lead to subsequent data - being interpreted as answer records, thus violating the DNS - specification. Such resource records could be maliciously crafted and - hidden from other tooling, but processed by the glibc stub resolver and - acted upon by the application. While we trust the data returned by the - configured recursive resolvers, we should not trust its format and - should validate it as required. It is a security issue to incorrectly - process the DNS protocol. - - A regression test is added for response section crossing. - - No regressions on x86_64-linux-gnu. - - Reviewed-by: Collin Funk - (cherry picked from commit 9f5f18aab40ec6b61fa49a007615e6077e9a979b) - -diff --git a/resolv/Makefile b/resolv/Makefile -index 8fa3398d76..0ba5fba710 100644 ---- a/resolv/Makefile -+++ b/resolv/Makefile -@@ -104,6 +104,7 @@ tests += \ - tst-resolv-basic \ - tst-resolv-binary \ - tst-resolv-byaddr \ -+ tst-resolv-dns-section \ - tst-resolv-edns \ - tst-resolv-invalid-cname \ - tst-resolv-network \ -@@ -115,6 +116,7 @@ tests += \ - tst-resolv-semi-failure \ - tst-resolv-short-response \ - tst-resolv-trailing \ -+ # tests - - # This test calls __res_context_send directly, which is not exported - # from libresolv. -@@ -293,6 +295,8 @@ $(objpfx)tst-resolv-aliases: $(objpfx)libresolv.so $(shared-thread-library) - $(objpfx)tst-resolv-basic: $(objpfx)libresolv.so $(shared-thread-library) - $(objpfx)tst-resolv-binary: $(objpfx)libresolv.so $(shared-thread-library) - $(objpfx)tst-resolv-byaddr: $(objpfx)libresolv.so $(shared-thread-library) -+$(objpfx)tst-resolv-dns-section: $(objpfx)libresolv.so \ -+ $(shared-thread-library) - $(objpfx)tst-resolv-edns: $(objpfx)libresolv.so $(shared-thread-library) - $(objpfx)tst-resolv-network: $(objpfx)libresolv.so $(shared-thread-library) - $(objpfx)tst-resolv-res_init: $(objpfx)libresolv.so -diff --git a/resolv/nss_dns/dns-host.c b/resolv/nss_dns/dns-host.c -index 14da73ee1d..27096edad2 100644 ---- a/resolv/nss_dns/dns-host.c -+++ b/resolv/nss_dns/dns-host.c -@@ -820,7 +820,7 @@ getanswer_ptr (unsigned char *packet, size_t packetlen, - /* expected_name may be updated to point into this buffer. */ - unsigned char name_buffer[NS_MAXCDNAME]; - -- while (ancount > 0) -+ for (; ancount > 0; --ancount) - { - struct ns_rr_wire rr; - if (!__ns_rr_cursor_next (&c, &rr)) -diff --git a/resolv/tst-resolv-dns-section.c b/resolv/tst-resolv-dns-section.c -new file mode 100644 -index 0000000000..1171baef51 ---- /dev/null -+++ b/resolv/tst-resolv-dns-section.c -@@ -0,0 +1,162 @@ -+/* Test handling of invalid section transitions (bug 34014). -+ Copyright (C) 2022-2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+ -+/* Name of test, and the second section type. */ -+struct item { -+ const char *test; -+ int ns_section; -+}; -+ -+static const struct item test_items[] = -+ { -+ { "Test crossing from ns_s_an to ns_s_ar.", ns_s_ar }, -+ { "Test crossing from ns_s_an to ns_s_an.", ns_s_ns }, -+ -+ { NULL, 0 }, -+ }; -+ -+/* The response is designed to contain the following: -+ - An Answer section with one T_PTR record that is skipped. -+ - A second section with a semantically invalid T_PTR record. -+ The original defect is that the response parsing would cross -+ section boundaries and handle the additional section T_PTR -+ as if it were an answer. A conforming implementation would -+ stop as soon as it reaches the end of the section. */ -+static void -+response (const struct resolv_response_context *ctx, -+ struct resolv_response_builder *b, -+ const char *qname, uint16_t qclass, uint16_t qtype) -+{ -+ TEST_COMPARE (qclass, C_IN); -+ -+ /* We only test PTR. */ -+ TEST_COMPARE (qtype, T_PTR); -+ -+ unsigned int count; -+ char *tail = NULL; -+ -+ if (strstr (qname, "in-addr.arpa") != NULL -+ && sscanf (qname, "%u.%ms", &count, &tail) == 2) -+ TEST_COMPARE_STRING (tail, "0.168.192.in-addr.arpa"); -+ else if (sscanf (qname, "%x.%ms", &count, &tail) == 2) -+ { -+ TEST_COMPARE_STRING (tail, "\ -+0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa"); -+ } -+ else -+ FAIL_EXIT1 ("invalid QNAME: %s\n", qname); -+ free (tail); -+ -+ /* We have a bounded number of possible tests. */ -+ TEST_VERIFY (count >= 0); -+ TEST_VERIFY (count <= 15); -+ -+ struct resolv_response_flags flags = {}; -+ resolv_response_init (b, flags); -+ resolv_response_add_question (b, qname, qclass, qtype); -+ resolv_response_section (b, ns_s_an); -+ -+ /* Actual answer record, but the wrong name (skipped). */ -+ resolv_response_open_record (b, "1.0.0.10.in-addr.arpa", qclass, qtype, 60); -+ -+ /* Record the answer. */ -+ resolv_response_add_name (b, "test.ptr.example.net"); -+ resolv_response_close_record (b); -+ -+ /* Add a second section to test section boundary crossing. */ -+ resolv_response_section (b, test_items[count].ns_section); -+ /* Semantically incorrect, but hide a T_PTR entry. */ -+ resolv_response_open_record (b, qname, qclass, qtype, 60); -+ resolv_response_add_name (b, "wrong.ptr.example.net"); -+ resolv_response_close_record (b); -+} -+ -+ -+/* Perform one check using a reverse lookup. */ -+static void -+check_reverse (int af, int count) -+{ -+ TEST_VERIFY (af == AF_INET || af == AF_INET6); -+ TEST_VERIFY (count < array_length (test_items)); -+ -+ char addr[sizeof (struct in6_addr)] = { 0 }; -+ socklen_t addrlen; -+ if (af == AF_INET) -+ { -+ addr[0] = (char) 192; -+ addr[1] = (char) 168; -+ addr[2] = (char) 0; -+ addr[3] = (char) count; -+ addrlen = 4; -+ } -+ else -+ { -+ addr[0] = 0x20; -+ addr[1] = 0x01; -+ addr[2] = 0x0d; -+ addr[3] = 0xb8; -+ addr[4] = addr[5] = addr[6] = addr[7] = 0x0; -+ addr[8] = addr[9] = addr[10] = addr[11] = 0x0; -+ addr[12] = 0x0; -+ addr[13] = 0x0; -+ addr[14] = 0x0; -+ addr[15] = count; -+ addrlen = 16; -+ } -+ -+ h_errno = 0; -+ struct hostent *answer = gethostbyaddr (addr, addrlen, af); -+ TEST_VERIFY (answer == NULL); -+ TEST_VERIFY (h_errno == NO_RECOVERY); -+ if (answer != NULL) -+ printf ("error: unexpected success: %s\n", -+ support_format_hostent (answer)); -+} -+ -+static int -+do_test (void) -+{ -+ struct resolv_test *obj = resolv_test_start -+ ((struct resolv_redirect_config) -+ { -+ .response_callback = response -+ }); -+ -+ for (int i = 0; test_items[i].test != NULL; i++) -+ { -+ check_reverse (AF_INET, i); -+ check_reverse (AF_INET6, i); -+ } -+ -+ resolv_test_end (obj); -+ -+ return 0; -+} -+ -+#include - -commit 426378547e6ddead92f28f5558a124eb0821d2f9 -Author: Carlos O'Donell -Date: Fri Mar 20 17:14:33 2026 -0400 - - resolv: Check hostname for validity (CVE-2026-4438) - - The processed hostname in getanswer_ptr should be correctly checked to - avoid invalid characters from being allowed, including shell - metacharacters. It is a security issue to fail to check the returned - hostname for validity. - - A regression test is added for invalid metacharacters and other cases - of invalid or valid characters. - - No regressions on x86_64-linux-gnu. - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit e10977481f4db4b2a3ce34fa4c3a1e26651ae312) - -diff --git a/resolv/Makefile b/resolv/Makefile -index 0ba5fba710..088a22ea18 100644 ---- a/resolv/Makefile -+++ b/resolv/Makefile -@@ -107,6 +107,7 @@ tests += \ - tst-resolv-dns-section \ - tst-resolv-edns \ - tst-resolv-invalid-cname \ -+ tst-resolv-invalid-ptr \ - tst-resolv-network \ - tst-resolv-noaaaa \ - tst-resolv-noaaaa-vc \ -@@ -306,6 +307,8 @@ $(objpfx)tst-resolv-res_init-thread: $(objpfx)libresolv.so \ - $(shared-thread-library) - $(objpfx)tst-resolv-invalid-cname: $(objpfx)libresolv.so \ - $(shared-thread-library) -+$(objpfx)tst-resolv-invalid-ptr: $(objpfx)libresolv.so \ -+ $(shared-thread-library) - $(objpfx)tst-resolv-noaaaa: $(objpfx)libresolv.so $(shared-thread-library) - $(objpfx)tst-resolv-noaaaa-vc: $(objpfx)libresolv.so $(shared-thread-library) - $(objpfx)tst-resolv-nondecimal: $(objpfx)libresolv.so $(shared-thread-library) -diff --git a/resolv/nss_dns/dns-host.c b/resolv/nss_dns/dns-host.c -index 27096edad2..1bc2e1df95 100644 ---- a/resolv/nss_dns/dns-host.c -+++ b/resolv/nss_dns/dns-host.c -@@ -866,7 +866,7 @@ getanswer_ptr (unsigned char *packet, size_t packetlen, - char hname[MAXHOSTNAMELEN + 1]; - if (__ns_name_unpack (c.begin, c.end, rr.rdata, - name_buffer, sizeof (name_buffer)) < 0 -- || !__res_binary_hnok (expected_name) -+ || !__res_binary_hnok (name_buffer) - || __ns_name_ntop (name_buffer, hname, sizeof (hname)) < 0) - { - *h_errnop = NO_RECOVERY; -diff --git a/resolv/tst-resolv-invalid-ptr.c b/resolv/tst-resolv-invalid-ptr.c -new file mode 100644 -index 0000000000..0c802ab967 ---- /dev/null -+++ b/resolv/tst-resolv-invalid-ptr.c -@@ -0,0 +1,255 @@ -+/* Test handling of invalid T_PTR results (bug 34015). -+ Copyright (C) 2022-2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+ -+/* Name of test, the answer, the expected error return, and if we -+ expect the call to fail. */ -+struct item { -+ const char *test; -+ const char *answer; -+ int expected; -+ bool fail; -+}; -+ -+static const struct item test_items[] = -+ { -+ /* Test for invalid characters. */ -+ { "Invalid use of \"|\"", -+ "test.|.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"&\"", -+ "test.&.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \";\"", -+ "test.;.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"<\"", -+ "test.<.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \">\"", -+ "test.>.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"(\"", -+ "test.(.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \")\"", -+ "test.).ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"$\"", -+ "test.$.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"`\"", -+ "test.`.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"\\\"", -+ "test.\\.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"\'\"", -+ "test.'.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"\"\"", -+ "test.\".ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \" \"", -+ "test. .ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"\\t\"", -+ "test.\t.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"\\n\"", -+ "test.\n.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"\\r\"", -+ "test.\r.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"*\"", -+ "test.*.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"?\"", -+ "test.?.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"[\"", -+ "test.[.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"]\"", -+ "test.].ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \",\"", -+ "test.,.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"~\"", -+ "test.~.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \":\"", -+ "test.:.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"!\"", -+ "test.!.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"@\"", -+ "test.@.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"#\"", -+ "test.#.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"%\"", -+ "test.%%.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"^\"", -+ "test.^.ptr.example", NO_RECOVERY, true }, -+ -+ /* Test for invalid UTF-8 characters (2-byte, 4-byte, 6-byte). */ -+ { "Invalid use of UTF-8 (2-byte, U+00C0-U+00C2)", -+ "ÁÂÃ.test.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of UTF-8 (4-byte, U+0750-U+0752)", -+ "ݐݑݒ.test.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of UTF-8 (6-byte, U+0904-U+0906)", -+ "ऄअआ.test.ptr.example", NO_RECOVERY, true }, -+ -+ /* Test for "-" which may be valid depending on position. */ -+ { "Invalid leading \"-\"", -+ "-test.ptr.example", NO_RECOVERY, true }, -+ { "Valid trailing \"-\"", -+ "test-.ptr.example", 0, false }, -+ { "Valid mid-label use of \"-\"", -+ "te-st.ptr.example", 0, false }, -+ -+ /* Test for "_" which is always valid in any position. */ -+ { "Valid leading use of \"_\"", -+ "_test.ptr.example", 0, false }, -+ { "Valid mid-label use of \"_\"", -+ "te_st.ptr.example", 0, false }, -+ { "Valid trailing use of \"_\"", -+ "test_.ptr.example", 0, false }, -+ -+ /* Sanity test the broader set [A-Za-z0-9_-] of valid characters. */ -+ { "Valid \"[A-Z]\"", -+ "test.ABCDEFGHIJKLMNOPQRSTUVWXYZ.ptr.example", 0, false }, -+ { "Valid \"[a-z]\"", -+ "test.abcdefghijklmnopqrstuvwxyz.ptr.example", 0, false }, -+ { "Valid \"[0-9]\"", -+ "test.0123456789.ptr.example", 0, false }, -+ { "Valid mixed use of \"[A-Za-z0-9_-]\"", -+ "test.012abcABZ_-.ptr.example", 0, false }, -+ }; -+ -+static void -+response (const struct resolv_response_context *ctx, -+ struct resolv_response_builder *b, -+ const char *qname, uint16_t qclass, uint16_t qtype) -+{ -+ TEST_COMPARE (qclass, C_IN); -+ -+ /* We only test PTR. */ -+ TEST_COMPARE (qtype, T_PTR); -+ -+ unsigned int count, count1; -+ char *tail = NULL; -+ -+ /* The test implementation can handle up to 255 tests. */ -+ if (strstr (qname, "in-addr.arpa") != NULL -+ && sscanf (qname, "%u.%ms", &count, &tail) == 2) -+ TEST_COMPARE_STRING (tail, "0.168.192.in-addr.arpa"); -+ else if (sscanf (qname, "%x.%x.%ms", &count, &count1, &tail) == 3) -+ { -+ TEST_COMPARE_STRING (tail, "\ -+0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa"); -+ count |= count1 << 4; -+ } -+ else -+ FAIL_EXIT1 ("invalid QNAME: %s\n", qname); -+ free (tail); -+ -+ /* Cross check. Count has a fixed bound (soft limit). */ -+ TEST_VERIFY (count >= 0 && count <= 255); -+ -+ /* We have a fixed number of tests (hard limit). */ -+ TEST_VERIFY_EXIT (count < array_length (test_items)); -+ -+ struct resolv_response_flags flags = {}; -+ resolv_response_init (b, flags); -+ resolv_response_add_question (b, qname, qclass, qtype); -+ resolv_response_section (b, ns_s_an); -+ -+ /* Actual answer record. */ -+ resolv_response_open_record (b, qname, qclass, qtype, 60); -+ -+ /* Record the answer. */ -+ resolv_response_add_name (b, test_items[count].answer); -+ resolv_response_close_record (b); -+} -+ -+/* Perform one check using a reverse lookup. */ -+static void -+check_reverse (int af, int count) -+{ -+ TEST_VERIFY (af == AF_INET || af == AF_INET6); -+ TEST_VERIFY_EXIT (count < array_length (test_items)); -+ -+ /* Generate an address to query for each test. */ -+ char addr[sizeof (struct in6_addr)] = { 0 }; -+ socklen_t addrlen; -+ if (af == AF_INET) -+ { -+ addr[0] = (char) 192; -+ addr[1] = (char) 168; -+ addr[2] = (char) 0; -+ addr[3] = (char) count; -+ addrlen = 4; -+ } -+ else -+ { -+ addr[0] = 0x20; -+ addr[1] = 0x01; -+ addr[2] = 0x0d; -+ addr[3] = 0xb8; -+ addr[4] = addr[5] = addr[6] = addr[7] = 0x0; -+ addr[8] = addr[9] = addr[10] = addr[11] = 0x0; -+ addr[12] = 0x0; -+ addr[13] = 0x0; -+ addr[14] = 0x0; -+ addr[15] = (char) count; -+ addrlen = 16; -+ } -+ -+ h_errno = 0; -+ struct hostent *answer = gethostbyaddr (addr, addrlen, af); -+ -+ /* Verify h_errno is as expected. */ -+ TEST_COMPARE (h_errno, test_items[count].expected); -+ if (h_errno != test_items[count].expected) -+ /* And print more information if it's not. */ -+ printf ("INFO: %s\n", test_items[count].test); -+ -+ if (test_items[count].fail) -+ { -+ /* We expected a failure so verify answer is NULL. */ -+ TEST_VERIFY (answer == NULL); -+ /* If it's not NULL we should print out what we received. */ -+ if (answer != NULL) -+ printf ("error: unexpected success: %s\n", -+ support_format_hostent (answer)); -+ } -+ else -+ /* We don't expect a failure so answer must be valid. */ -+ TEST_COMPARE_STRING (answer->h_name, test_items[count].answer); -+} -+ -+static int -+do_test (void) -+{ -+ struct resolv_test *obj = resolv_test_start -+ ((struct resolv_redirect_config) -+ { -+ .response_callback = response -+ }); -+ -+ for (int i = 0; i < array_length (test_items); i++) -+ { -+ check_reverse (AF_INET, i); -+ check_reverse (AF_INET6, i); -+ } -+ resolv_test_end (obj); -+ -+ return 0; -+} -+ -+#include - -commit 68099ccc941664481386c62cba40bbc5dac8b00e -Author: Xi Ruoyao -Date: Tue Feb 3 16:20:12 2026 +0800 - - elf: parse /proc/self/maps as the last resort to find the gap for tst-link-map-contiguous-ldso - - The initialization process of libc.so calls mmap() several times and the - kernel may lay the maps into the gap. If all pages in the gap are - occupied, the test would not be able to find the gap with mmap() and the - test would fail. - - The failure reproduces most frequently on LoongArch because with the - commonly used page size (16 KiB) the gap only contains 4 pages and the - probability they are all occupied is not near to zero. - - With the changes in the patch, a test run may output: - - info: ld.so link map is not contiguous - info: object "/dev/zero" found at 0x7ffff1fe0000 - 0x7ffff1fe4000 - info: anonymous mapping found at 0x7ffff1fe4000 - 0x7ffff1fec000 - - Also take the chance to fix a mistake in the "object found at" message - which has puzzled me during the initial debug session. - - Signed-off-by: Xi Ruoyao - Reviewed-by: Adhemerval Zanella - (cherry picked from commit aed8390a6a22e5751fc12704c0c5f2a8271fc286) - -diff --git a/elf/tst-link-map-contiguous-ldso.c b/elf/tst-link-map-contiguous-ldso.c -index 04de808bb2..f0e26682f2 100644 ---- a/elf/tst-link-map-contiguous-ldso.c -+++ b/elf/tst-link-map-contiguous-ldso.c -@@ -18,15 +18,73 @@ - - #include - #include -+#include - #include - #include - #include - #include -+#include - #include - #include -+#include - #include - #include - -+/* Slow path in case we cannot find a gap with mmap (when the runtime has -+ mapped all the pages in the gap for some reason). */ -+static bool -+find_gap_with_proc_self_map (const struct link_map *l) -+{ -+ int pagesize = getpagesize (); -+ -+ support_need_proc ("Reads /proc/self/maps to find gap in ld.so mapping"); -+ -+ /* Parse /proc/self/maps and find all the mappings in the ld.so range -+ but not from ld.so. */ -+ FILE *f = xfopen ("/proc/self/maps", "r"); -+ char *line = NULL, *path_ldso = NULL; -+ size_t len; -+ bool found = false; -+ while (xgetline (&line, &len, f)) -+ { -+ uintptr_t from, to; -+ char *path = NULL; -+ int r = sscanf (line, "%" SCNxPTR "-%" SCNxPTR "%*s%*s%*s%*s%ms", -+ &from, &to, &path); -+ -+ TEST_VERIFY (r == 2 || r == 3); -+ TEST_COMPARE (from % pagesize, 0); -+ TEST_COMPARE (to % pagesize, 0); -+ -+ if (path_ldso == NULL && l->l_map_start == from) -+ { -+ TEST_COMPARE (r, 3); -+ path_ldso = path; -+ continue; -+ } -+ -+ if (from > l->l_map_start && to < l->l_map_end -+ && (r == 2 || (path_ldso != NULL && strcmp (path, path_ldso)))) -+ { -+ if (r == 2) -+ printf ("info: anonymous mapping found at 0x%" PRIxPTR " - 0x%" -+ PRIxPTR "\n", from, to); -+ else -+ printf ("info: object \"%s\" found at 0x%" PRIxPTR " - 0x%" -+ PRIxPTR "\n", path, from, to); -+ -+ found = true; -+ } -+ -+ free (path); -+ } -+ -+ free (path_ldso); -+ free (line); -+ xfclose (f); -+ return found; -+} -+ - static int - do_test (void) - { -@@ -64,16 +122,18 @@ do_test (void) - if ((void *) dlfo.dlfo_link_map != (void *) l) - { - printf ("info: object \"%s\" found at %p\n", -- dlfo.dlfo_link_map->l_name, ptr); -+ dlfo.dlfo_link_map->l_name, expected); - gap_found = true; - } - } - else - TEST_COMPARE (dlfo_ret, -1); -+ - xmunmap (ptr, 1); - addr += pagesize; - } -- if (!gap_found) -+ -+ if (!gap_found && !find_gap_with_proc_self_map (l)) - FAIL ("no ld.so gap found"); - } - else - -commit a56a2943d2ce541102c630142c2eae0fbfc5886b -Author: Michael Jeanson -Date: Fri Feb 20 11:01:00 2026 -0500 - - tests: fix tst-rseq with Linux 7.0 - - A sub-test of tst-rseq is to validate the return code and errno of the - rseq syscall when attempting to register the exact same rseq area as was - done in the dynamic loader. - - This involves finding the rseq area address by adding the - '__rseq_offset' to the thread pointer and calculating the area size from - the AT_RSEQ_FEATURE_SIZE auxiliary vector. However the test currently - calculates the size of the rseq area allocation in the TLS block which - must be a multiple of AT_RSEQ_ALIGN. - - Up until now that happened to be the same value since the feature size - and alignment exposed by the kernel were below the minimum ABI size of - 32. Starting with Linux 7.0 the feature size has reached 33 while the - alignment is now 64. - - This results in the test trying to re-register the rseq area with a - different size and thus not getting the expected errno value. - - Signed-off-by: Michael Jeanson - Reviewed-by: Mathieu Desnoyers - (cherry picked from commit 67f303b47dc584f204e3f2441b9832082415eebc) - -diff --git a/sysdeps/unix/sysv/linux/tst-rseq.c b/sysdeps/unix/sysv/linux/tst-rseq.c -index 00181cfefb..e83ea2b939 100644 ---- a/sysdeps/unix/sysv/linux/tst-rseq.c -+++ b/sysdeps/unix/sysv/linux/tst-rseq.c -@@ -48,8 +48,7 @@ do_rseq_main_test (void) - size_t rseq_align = MAX (getauxval (AT_RSEQ_ALIGN), RSEQ_MIN_ALIGN); - size_t rseq_feature_size = MAX (getauxval (AT_RSEQ_FEATURE_SIZE), - RSEQ_AREA_SIZE_INITIAL_USED); -- size_t rseq_alloc_size = roundup (MAX (rseq_feature_size, -- RSEQ_AREA_SIZE_INITIAL_USED), rseq_align); -+ size_t rseq_reg_size = MAX (rseq_feature_size, RSEQ_AREA_SIZE_INITIAL); - struct rseq *rseq_abi = __thread_pointer () + __rseq_offset; - - TEST_VERIFY_EXIT (rseq_thread_registered ()); -@@ -89,8 +88,8 @@ do_rseq_main_test (void) - /* Test a rseq registration with the same arguments as the internal - registration which should fail with errno == EBUSY. */ - TEST_VERIFY (((unsigned long) rseq_abi % rseq_align) == 0); -- TEST_VERIFY (__rseq_size <= rseq_alloc_size); -- int ret = syscall (__NR_rseq, rseq_abi, rseq_alloc_size, 0, RSEQ_SIG); -+ TEST_VERIFY (__rseq_size <= rseq_reg_size); -+ int ret = syscall (__NR_rseq, rseq_abi, rseq_reg_size, 0, RSEQ_SIG); - TEST_VERIFY (ret != 0); - TEST_COMPARE (errno, EBUSY); - } - -commit f13c1bb0f97fbc12a6ba1ab5669ce561ea32b80a -Author: Florian Weimer -Date: Thu Apr 16 19:13:43 2026 +0200 - - Use pending character state in IBM1390, IBM1399 character sets (CVE-2026-4046) - - Follow the example in iso-2022-jp-3.c and use the __count state - variable to store the pending character. This avoids restarting - the conversion if the output buffer ends between two 4-byte UCS-4 - code points, so that the assert reported in the bug can no longer - happen. - - Even though the fix is applied to ibm1364.c, the change is only - effective for the two HAS_COMBINED codecs for IBM1390, IBM1399. - - The test case was mostly auto-generated using - claude-4.6-opus-high-thinking, and composer-2-fast shows up in the - log as well. During review, gpt-5.4-xhigh flagged that the original - version of the test case was not exercising the new character - flush logic. - - This fixes bug 33980. - - Assisted-by: LLM - Reviewed-by: Carlos O'Donell - (cherry picked from commit d6f08d1cf027f4eb2ba289a6cc66853722d4badc) - -diff --git a/iconvdata/Makefile b/iconvdata/Makefile -index 5a2abeea24..cc689f63e9 100644 ---- a/iconvdata/Makefile -+++ b/iconvdata/Makefile -@@ -76,7 +76,7 @@ tests = bug-iconv1 bug-iconv2 tst-loading tst-e2big tst-iconv4 bug-iconv4 \ - tst-iconv6 bug-iconv5 bug-iconv6 tst-iconv7 bug-iconv8 bug-iconv9 \ - bug-iconv10 bug-iconv11 bug-iconv12 tst-iconv-big5-hkscs-to-2ucs4 \ - bug-iconv13 bug-iconv14 bug-iconv15 \ -- tst-iconv-iso-2022-cn-ext -+ tst-iconv-iso-2022-cn-ext tst-bug33980 - ifeq ($(have-thread-library),yes) - tests += bug-iconv3 - endif -@@ -333,6 +333,8 @@ $(objpfx)bug-iconv15.out: $(addprefix $(objpfx), $(gconv-modules)) \ - $(addprefix $(objpfx),$(modules.so)) - $(objpfx)tst-iconv-iso-2022-cn-ext.out: $(addprefix $(objpfx), $(gconv-modules)) \ - $(addprefix $(objpfx),$(modules.so)) -+$(objpfx)tst-bug33980.out: $(addprefix $(objpfx), $(gconv-modules)) \ -+ $(addprefix $(objpfx),$(modules.so)) - - $(objpfx)iconv-test.out: run-iconv-test.sh \ - $(addprefix $(objpfx), $(gconv-modules)) \ -diff --git a/iconvdata/ibm1364.c b/iconvdata/ibm1364.c -index 45c62acee5..244c61ad7a 100644 ---- a/iconvdata/ibm1364.c -+++ b/iconvdata/ibm1364.c -@@ -67,12 +67,29 @@ - - /* Since this is a stateful encoding we have to provide code which resets - the output state to the initial state. This has to be done during the -- flushing. */ -+ flushing. For the to-internal direction (FROM_DIRECTION is true), -+ there may be a pending character that needs flushing. */ - #define EMIT_SHIFT_TO_INIT \ - if ((data->__statep->__count & ~7) != sb) \ - { \ - if (FROM_DIRECTION) \ -- data->__statep->__count &= 7; \ -+ { \ -+ uint32_t ch = data->__statep->__count >> 7; \ -+ if (__glibc_unlikely (ch != 0)) \ -+ { \ -+ if (__glibc_unlikely (outend - outbuf < 4)) \ -+ status = __GCONV_FULL_OUTPUT; \ -+ else \ -+ { \ -+ put32 (outbuf, ch); \ -+ outbuf += 4; \ -+ /* Clear character and db bit. */ \ -+ data->__statep->__count &= 7; \ -+ } \ -+ } \ -+ else \ -+ data->__statep->__count &= 7; \ -+ } \ - else \ - { \ - /* We are not in the initial state. To switch back we have \ -@@ -99,11 +116,13 @@ - *curcsp = save_curcs - - --/* Current codeset type. */ -+/* Current codeset type. The bit is stored in the __count variable of -+ the conversion state. If the db bit is set, bit 7 and above store -+ a pending UCS-4 code point if non-zero. */ - enum - { -- sb = 0, -- db = 64 -+ sb = 0, /* Single byte mode. */ -+ db = 64 /* Double byte mode. */ - }; - - -@@ -119,21 +138,29 @@ enum - } \ - else \ - { \ -- /* This is a combined character. Make sure we have room. */ \ -- if (__glibc_unlikely (outptr + 8 > outend)) \ -- { \ -- result = __GCONV_FULL_OUTPUT; \ -- break; \ -- } \ -- \ - const struct divide *cmbp \ - = &DB_TO_UCS4_COMB[ch - __TO_UCS4_COMBINED_MIN]; \ - assert (cmbp->res1 != 0 && cmbp->res2 != 0); \ - \ - put32 (outptr, cmbp->res1); \ - outptr += 4; \ -- put32 (outptr, cmbp->res2); \ -- outptr += 4; \ -+ \ -+ /* See whether we have room for the second character. */ \ -+ if (outend - outptr >= 4) \ -+ { \ -+ put32 (outptr, cmbp->res2); \ -+ outptr += 4; \ -+ } \ -+ else \ -+ { \ -+ /* Otherwise store only the first character now, and \ -+ put the second one into the queue. */ \ -+ curcs |= cmbp->res2 << 7; \ -+ inptr += 2; \ -+ /* Tell the caller why we terminate the loop. */ \ -+ result = __GCONV_FULL_OUTPUT; \ -+ break; \ -+ } \ - } \ - } - #else -@@ -153,7 +180,20 @@ enum - #define LOOPFCT FROM_LOOP - #define BODY \ - { \ -- uint32_t ch = *inptr; \ -+ uint32_t ch; \ -+ \ -+ ch = curcs >> 7; \ -+ if (__glibc_unlikely (ch != 0)) \ -+ { \ -+ put32 (outptr, ch); \ -+ outptr += 4; \ -+ /* Remove the pending character, but preserve state bits. */ \ -+ curcs &= (1 << 7) - 1; \ -+ continue; \ -+ } \ -+ \ -+ /* Otherwise read the next input byte. */ \ -+ ch = *inptr; \ - \ - if (__builtin_expect (ch, 0) == SO) \ - { \ -diff --git a/iconvdata/tst-bug33980.c b/iconvdata/tst-bug33980.c -new file mode 100644 -index 0000000000..c9693e0efe ---- /dev/null -+++ b/iconvdata/tst-bug33980.c -@@ -0,0 +1,153 @@ -+/* Test for bug 33980: combining characters in IBM1390/IBM1399. -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+ -+#include -+#include -+#include -+ -+/* Run iconv in a loop with a small output buffer of OUTBUFSIZE bytes -+ starting at OUTBUF. OUTBUF should be right before an unmapped page -+ so that writing past the end will fault. Skip SHIFT bytes at the -+ start of the input and output, to exercise different buffer -+ alignment. TRUNCATE indicates skipped bytes at the end of -+ input (0 and 1 a valid). */ -+static void -+test_one (const char *encoding, unsigned int shift, unsigned int truncate, -+ char *outbuf, size_t outbufsize) -+{ -+ /* In IBM1390 and IBM1399, the DBCS code 0xECB5 expands to two -+ Unicode code points when translated. */ -+ static char input[] = -+ { -+ /* 8 letters X. */ -+ 0xe7, 0xe7, 0xe7, 0xe7, 0xe7, 0xe7, 0xe7, 0xe7, -+ /* SO, 0xECB5, SI: shift to DBCS, special character, shift back. */ -+ 0x0e, 0xec, 0xb5, 0x0f -+ }; -+ -+ /* Expected output after UTF-8 conversion. */ -+ static char expected[] = -+ { -+ 'X', 'X', 'X', 'X', 'X', 'X', 'X', 'X', -+ /* U+304B (HIRAGANA LETTER KA). */ -+ 0xe3, 0x81, 0x8b, -+ /* U+309A (COMBINING KATAKANA-HIRAGANA SEMI-VOICED SOUND MARK). */ -+ 0xe3, 0x82, 0x9a -+ }; -+ -+ iconv_t cd = iconv_open ("UTF-8", encoding); -+ TEST_VERIFY_EXIT (cd != (iconv_t) -1); -+ -+ char result_storage[64]; -+ struct alloc_buffer result_buf -+ = alloc_buffer_create (result_storage, sizeof (result_storage)); -+ -+ char *inptr = &input[shift]; -+ size_t inleft = sizeof (input) - shift - truncate; -+ -+ while (inleft > 0) -+ { -+ char *outptr = outbuf; -+ size_t outleft = outbufsize; -+ size_t inleft_before = inleft; -+ -+ size_t ret = iconv (cd, &inptr, &inleft, &outptr, &outleft); -+ size_t produced = outptr - outbuf; -+ alloc_buffer_copy_bytes (&result_buf, outbuf, produced); -+ -+ if (ret == (size_t) -1 && errno == E2BIG) -+ { -+ if (produced == 0 && inleft == inleft_before) -+ { -+ /* Output buffer too small to make progress. This is -+ expected for very small output buffer sizes. */ -+ TEST_VERIFY_EXIT (outbufsize < 3); -+ break; -+ } -+ continue; -+ } -+ if (ret == (size_t) -1) -+ FAIL_EXIT1 ("%s (outbufsize %zu): iconv: %m", encoding, outbufsize); -+ break; -+ } -+ -+ /* Flush any pending state (e.g. a buffered combined character). -+ With outbufsize < 3, we could not store the first character, so -+ the second character did not become pending, and there is nothing -+ to flush. */ -+ { -+ char *outptr = outbuf; -+ size_t outleft = outbufsize; -+ -+ size_t ret = iconv (cd, NULL, NULL, &outptr, &outleft); -+ TEST_VERIFY_EXIT (ret == 0); -+ size_t produced = outptr - outbuf; -+ alloc_buffer_copy_bytes (&result_buf, outbuf, produced); -+ -+ /* Second flush does not provide more data. */ -+ outptr = outbuf; -+ outleft = outbufsize; -+ ret = iconv (cd, NULL, NULL, &outptr, &outleft); -+ TEST_VERIFY_EXIT (ret == 0); -+ TEST_VERIFY (outptr == outbuf); -+ } -+ -+ TEST_VERIFY_EXIT (!alloc_buffer_has_failed (&result_buf)); -+ size_t result_used -+ = sizeof (result_storage) - alloc_buffer_size (&result_buf); -+ -+ if (outbufsize >= 3) -+ { -+ TEST_COMPARE (inleft, 0); -+ TEST_COMPARE (result_used, sizeof (expected) - shift); -+ TEST_COMPARE_BLOB (result_storage, result_used, -+ &expected[shift], sizeof (expected) - shift); -+ } -+ else -+ /* If the buffer is too small, only the leading X could be converted. */ -+ TEST_COMPARE (result_used, 8 - shift); -+ -+ TEST_VERIFY_EXIT (iconv_close (cd) == 0); -+} -+ -+static int -+do_test (void) -+{ -+ struct support_next_to_fault ntf -+ = support_next_to_fault_allocate (8); -+ -+ for (int shift = 0; shift <= 8; ++shift) -+ for (int truncate = 0; truncate < 2; ++truncate) -+ for (size_t outbufsize = 1; outbufsize <= 8; outbufsize++) -+ { -+ char *outbuf = ntf.buffer + ntf.length - outbufsize; -+ test_one ("IBM1390", shift, truncate, outbuf, outbufsize); -+ test_one ("IBM1399", shift, truncate, outbuf, outbufsize); -+ } -+ -+ support_next_to_fault_free (&ntf); -+ return 0; -+} -+ -+#include - -commit 12feedaf67e11c4618dc50c6aab4dbfd1e6d9531 -Author: DJ Delorie -Date: Mon Jan 26 22:24:42 2026 -0500 - - include: isolate __O_CLOEXEC flag for sys/mount.h and fcntl.h - - Including sys/mount.h should not implicitly include fcntl.h - as that causes namespace pollution and conflicts with kernel - headers. It only needs O_CLOEXEC for OPEN_TREE_CLOEXEC - (although it shouldn't need that, but it's defined that way) - so we provide that define (via a private version) separately. - - Reviewed-by: Adhemerval Zanella - Tested-by: Florian Weimer - (cherry picked from commit 419245719ccbc7dad6a97f24465e7f09c090327a) - -diff --git a/io/fcntl.c b/io/fcntl.c -index e88e28664c..b7dab1bb39 100644 ---- a/io/fcntl.c -+++ b/io/fcntl.c -@@ -18,6 +18,10 @@ - #include - #include - -+#ifndef __O_CLOEXEC -+# error __O_CLOEXEC not defined by fcntl.h/cloexec.h -+#endif -+ - /* Perform file control operations on FD. */ - int - __fcntl (int fd, int cmd, ...) -diff --git a/sysdeps/unix/sysv/linux/Makefile b/sysdeps/unix/sysv/linux/Makefile -index c47cbdf428..053041f256 100644 ---- a/sysdeps/unix/sysv/linux/Makefile -+++ b/sysdeps/unix/sysv/linux/Makefile -@@ -129,6 +129,7 @@ CFLAGS-test-errno-linux.c += $(no-fortify-source) - - sysdep_headers += \ - bits/a.out.h \ -+ bits/cloexec.h \ - bits/epoll.h \ - bits/eventfd.h \ - bits/inotify.h \ -diff --git a/sysdeps/unix/sysv/linux/alpha/bits/cloexec.h b/sysdeps/unix/sysv/linux/alpha/bits/cloexec.h -new file mode 100644 -index 0000000000..f381f28a53 ---- /dev/null -+++ b/sysdeps/unix/sysv/linux/alpha/bits/cloexec.h -@@ -0,0 +1 @@ -+#define __O_CLOEXEC 010000000 -diff --git a/sysdeps/unix/sysv/linux/bits/cloexec.h b/sysdeps/unix/sysv/linux/bits/cloexec.h -new file mode 100644 -index 0000000000..3059fb6473 ---- /dev/null -+++ b/sysdeps/unix/sysv/linux/bits/cloexec.h -@@ -0,0 +1 @@ -+#define __O_CLOEXEC 02000000 -diff --git a/sysdeps/unix/sysv/linux/bits/fcntl-linux.h b/sysdeps/unix/sysv/linux/bits/fcntl-linux.h -index f425a4bf22..98954feaca 100644 ---- a/sysdeps/unix/sysv/linux/bits/fcntl-linux.h -+++ b/sysdeps/unix/sysv/linux/bits/fcntl-linux.h -@@ -81,9 +81,7 @@ - #ifndef __O_NOFOLLOW - # define __O_NOFOLLOW 0400000 - #endif --#ifndef __O_CLOEXEC --# define __O_CLOEXEC 02000000 --#endif -+#include - #ifndef __O_DIRECT - # define __O_DIRECT 040000 - #endif -diff --git a/sysdeps/unix/sysv/linux/hppa/bits/cloexec.h b/sysdeps/unix/sysv/linux/hppa/bits/cloexec.h -new file mode 100644 -index 0000000000..f381f28a53 ---- /dev/null -+++ b/sysdeps/unix/sysv/linux/hppa/bits/cloexec.h -@@ -0,0 +1 @@ -+#define __O_CLOEXEC 010000000 -diff --git a/sysdeps/unix/sysv/linux/sparc/bits/cloexec.h b/sysdeps/unix/sysv/linux/sparc/bits/cloexec.h -new file mode 100644 -index 0000000000..6706eaa7d5 ---- /dev/null -+++ b/sysdeps/unix/sysv/linux/sparc/bits/cloexec.h -@@ -0,0 +1 @@ -+#define __O_CLOEXEC 0x400000 -diff --git a/sysdeps/unix/sysv/linux/sys/mount.h b/sysdeps/unix/sysv/linux/sys/mount.h -index b549e75148..365da1c296 100644 ---- a/sysdeps/unix/sysv/linux/sys/mount.h -+++ b/sysdeps/unix/sysv/linux/sys/mount.h -@@ -21,7 +21,6 @@ - #ifndef _SYS_MOUNT_H - #define _SYS_MOUNT_H 1 - --#include - #include - #include - #include -@@ -266,6 +265,11 @@ enum fsconfig_command - - /* open_tree flags. */ - #define OPEN_TREE_CLONE 1 /* Clone the target tree and attach the clone */ -+#ifndef O_CLOEXEC -+# include -+# define O_CLOEXEC __O_CLOEXEC -+#endif -+#undef OPEN_TREE_CLOEXEC - #define OPEN_TREE_CLOEXEC O_CLOEXEC /* Close the file on execve() */ - - -diff --git a/sysdeps/unix/sysv/linux/tst-mount.c b/sysdeps/unix/sysv/linux/tst-mount.c -index 40913c7082..78a2772b2f 100644 ---- a/sysdeps/unix/sysv/linux/tst-mount.c -+++ b/sysdeps/unix/sysv/linux/tst-mount.c -@@ -20,6 +20,7 @@ - #include - #include - #include -+#include /* For AT_ constants. */ - #include - - _Static_assert (sizeof (struct mount_attr) == MOUNT_ATTR_SIZE_VER0, - -commit 3ecfa68561d723564a1fb565366182eb4acb3e8f -Author: Florian Weimer -Date: Wed Mar 4 18:32:36 2026 +0100 - - Linux: Only define OPEN_TREE_* macros in if undefined (bug 33921) - - There is a conditional inclusion of earlier in the file. - If that defines the macros, do not redefine them. This addresses build - problems as the token sequence used by the UAPI macro definitions - changes between Linux versions. - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit d12b017cddfeb9fe9920ba054ae3dfcb8e9238b8) - -diff --git a/sysdeps/unix/sysv/linux/sys/mount.h b/sysdeps/unix/sysv/linux/sys/mount.h -index 365da1c296..30ba56c1e8 100644 ---- a/sysdeps/unix/sysv/linux/sys/mount.h -+++ b/sysdeps/unix/sysv/linux/sys/mount.h -@@ -264,14 +264,16 @@ enum fsconfig_command - #define FSOPEN_CLOEXEC 0x00000001 - - /* open_tree flags. */ --#define OPEN_TREE_CLONE 1 /* Clone the target tree and attach the clone */ -+#ifndef OPEN_TREE_CLONE -+# define OPEN_TREE_CLONE 1 /* Clone the target tree and attach the clone */ -+#endif - #ifndef O_CLOEXEC - # include - # define O_CLOEXEC __O_CLOEXEC - #endif --#undef OPEN_TREE_CLOEXEC --#define OPEN_TREE_CLOEXEC O_CLOEXEC /* Close the file on execve() */ -- -+#ifndef OPEN_TREE_CLOEXEC -+# define OPEN_TREE_CLOEXEC O_CLOEXEC /* Close the file on execve() */ -+#endif - - __BEGIN_DECLS - - -commit 3e87cf9be93acf19d685e8003fc649cdb052a891 -Author: H.J. Lu -Date: Mon Apr 13 10:46:42 2026 +0800 - - abilist.awk: Handle weak unversioned defined symbols - - After - - commit f685e3953f9a38a41bbd0a597f9882870cee13d5 - Author: H.J. Lu - Date: Wed Oct 29 09:49:57 2025 +0800 - - elf: Don't set its DT_VERSYM entry for unversioned symbol - - ld no longer assigns version index 1 to unversioned defined symbol. - For libmachuser.so, "objdump --dynamic-syms" reports: - - 0000dd30 w DF .text 000000f8 processor_start - - instead of - - 0000dd30 w DF .text 000000f8 (Base) processor_start - - Also allow NF == 6 for weak unversioned dynamic symbols. This fixes BZ - 33650. - - Signed-off-by: H.J. Lu - Reviewed-by: Sam James - (cherry picked from commit ee5d1db2a81468413fbf7c82779ffa782f429d1a) - -diff --git a/scripts/abilist.awk b/scripts/abilist.awk -index 6cc7af6ac8..7ea1edf8c0 100644 ---- a/scripts/abilist.awk -+++ b/scripts/abilist.awk -@@ -38,7 +38,7 @@ $4 == "*UND*" { next } - $2 == "l" { next } - - # If the target uses ST_OTHER, it will be output before the symbol name. --$2 == "g" || $2 == "w" && (NF == 7 || NF == 8) { -+$2 == "g" || $2 == "w" && (NF == 6 || NF == 7 || NF == 8) { - type = $3; - size = $5; - sub(/^0*/, "", size); - -commit b4bca35ab9e76890504c4dbdd5eaf15a93514580 -Author: Rocket Ma -Date: Fri May 1 20:39:07 2026 -0700 - - libio: Fix ungetwc operating on byte stream [BZ #33998] - - * libio/wgenops.c: When _IO_wdefault_pbackfail attempts to push back one - character, it accidently compare the wchar to push back with the last - char from byte stream, instead of wide stream. Under specific coding, - attacker may exploit this to leak information. This commit fix bug - 33998, or CVE-2026-5928. - - Signed-off-by: Rocket Ma - Reviewed-by: Carlos O'Donell - (cherry picked from commit ef3bfb5f910011f3780cb06aa47e730035f53285) - -diff --git a/libio/Makefile b/libio/Makefile -index f020f8ec4d..fa2b8ae791 100644 ---- a/libio/Makefile -+++ b/libio/Makefile -@@ -83,6 +83,7 @@ tests = \ - bug-ungetwc1 \ - bug-ungetwc2 \ - bug-wfflush \ -+ bug-wgenops-bz33998 \ - bug-wmemstream1 \ - bug-wsetpos \ - test-fmemopen \ -diff --git a/libio/bug-wgenops-bz33998.c b/libio/bug-wgenops-bz33998.c -new file mode 100644 -index 0000000000..cc4067da99 ---- /dev/null -+++ b/libio/bug-wgenops-bz33998.c -@@ -0,0 +1,54 @@ -+/* Regression test for ungetwc operating on byte stream (BZ #33998) -+ Copyright (C) 2026 The GNU Toolchain Authors. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include "support/temp_file.h" -+#include "support/xstdio.h" -+#include "support/xunistd.h" -+#include -+#include -+#include -+#include -+#include -+#include -+ -+static int -+do_test (void) -+{ -+ char *filename; -+ int fd = create_temp_file ("tst-bz33998-", &filename); -+ TEST_VERIFY (fd != -1); -+ xwrite (fd, "A", sizeof ("A")); // write "A\0" by design -+ xclose (fd); -+ -+ FILE *fp = xfopen (filename, "r+"); -+ TEST_COMPARE (getwc (fp), L'A'); -+ /* If the bug is fixed, then ungetwc should not touch byte stream. -+ If the bug is not fixed, ungetwc firstly match last read char, L'A', -+ failed, then the pbackfail branch, matching last read char in byte -+ stream, that is, '\0' (initialized when setup wide stream). */ -+ char *old_read_ptr = fp->_IO_read_ptr; -+ TEST_COMPARE (ungetwc (L'\0', fp), L'\0'); -+ TEST_VERIFY (fp->_IO_read_ptr == old_read_ptr); -+ -+ xfclose (fp); -+ free (filename); -+ -+ return 0; -+} -+ -+#include -diff --git a/libio/wgenops.c b/libio/wgenops.c -index 0a11d1b1de..9e0b2c00ea 100644 ---- a/libio/wgenops.c -+++ b/libio/wgenops.c -@@ -108,8 +108,8 @@ _IO_wdefault_pbackfail (FILE *fp, wint_t c) - { - if (fp->_wide_data->_IO_read_ptr > fp->_wide_data->_IO_read_base - && !_IO_in_backup (fp) -- && (wint_t) fp->_IO_read_ptr[-1] == c) -- --fp->_IO_read_ptr; -+ && (wint_t) fp->_wide_data->_IO_read_ptr[-1] == c) -+ --fp->_wide_data->_IO_read_ptr; - else - { - /* Need to handle a filebuf in write mode (switch to read mode). FIXME!*/ - -commit 4ebd33dd77eabe8d4c45232bed4b42a31d2f9edc -Author: Rocket Ma -Date: Fri Apr 17 23:48:41 2026 -0700 - - stdio-common: Fix buffer overflow in scanf %mc [BZ #34008] - - * stdio-common/vfscanf-internal.c: When enlarging allocated buffer with - format %mc or %mC, glibc allocates one byte less, leading to - user-controlled one byte overflow. This commit fixes BZ #34008, or - CVE-2026-5450. - - Reviewed-by: Carlos O'Donell - Signed-off-by: Rocket Ma - Reviewed-by: H.J. Lu - (cherry picked from commit 839898777226a3ed88c0859f25ffe712519b4ead) - -diff --git a/stdio-common/Makefile b/stdio-common/Makefile -index 64b3575acb..e52c333808 100644 ---- a/stdio-common/Makefile -+++ b/stdio-common/Makefile -@@ -347,6 +347,7 @@ tests := \ - tst-vfprintf-user-type \ - tst-vfprintf-width-i18n \ - tst-vfprintf-width-prec-alloc \ -+ tst-vfscanf-bz34008 \ - tst-wc-printf \ - tstdiomisc \ - tstgetln \ -@@ -562,6 +563,9 @@ tst-printf-bz18872-ENV = MALLOC_TRACE=$(objpfx)tst-printf-bz18872.mtrace \ - tst-vfprintf-width-prec-ENV = \ - MALLOC_TRACE=$(objpfx)tst-vfprintf-width-prec.mtrace \ - LD_PRELOAD=$(common-objpfx)/malloc/libc_malloc_debug.so -+tst-vfscanf-bz34008-ENV = \ -+ MALLOC_CHECK_=3 \ -+ LD_PRELOAD=$(common-objpfx)/malloc/libc_malloc_debug.so - tst-printf-bz25691-ENV = \ - MALLOC_TRACE=$(objpfx)tst-printf-bz25691.mtrace \ - LD_PRELOAD=$(common-objpfx)/malloc/libc_malloc_debug.so -diff --git a/stdio-common/tst-vfscanf-bz34008.c b/stdio-common/tst-vfscanf-bz34008.c -new file mode 100644 -index 0000000000..48371c8a3d ---- /dev/null -+++ b/stdio-common/tst-vfscanf-bz34008.c -@@ -0,0 +1,48 @@ -+/* Regression test for vfscanf %Nmc out-of-bound write (BZ #34008) -+ Copyright (C) 2026 The GNU Toolchain Authors. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include "malloc/mcheck.h" -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+ -+#define WIDTH 0x410 -+#define SCANFSTR "%1040mc" -+static int -+do_test (void) -+{ -+ mcheck_pedantic (NULL); -+ char *input = malloc (WIDTH + 1); -+ TEST_VERIFY (input != NULL); -+ memset (input, 'A', WIDTH); -+ input[WIDTH] = '\0'; -+ -+ char *buf = NULL; -+ TEST_VERIFY (sscanf (input, SCANFSTR, &buf) != -1); -+ TEST_VERIFY (buf != NULL); -+ -+ free (buf); -+ free (input); -+ return 0; -+} -+ -+#include -diff --git a/stdio-common/vfscanf-internal.c b/stdio-common/vfscanf-internal.c -index 86ae5019a6..17b5565d0f 100644 ---- a/stdio-common/vfscanf-internal.c -+++ b/stdio-common/vfscanf-internal.c -@@ -853,8 +853,7 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, - { - /* Enlarge the buffer. */ - size_t newsize -- = strsize -- + (strsize >= width ? width - 1 : strsize); -+ = strsize + (strsize >= width ? width : strsize); - - str = (char *) realloc (*strptr, newsize); - if (str == NULL) -@@ -925,7 +924,7 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, - && wstr == (wchar_t *) *strptr + strsize) - { - size_t newsize -- = strsize + (strsize > width ? width - 1 : strsize); -+ = strsize + (strsize >= width ? width : strsize); - /* Enlarge the buffer. */ - wstr = (wchar_t *) realloc (*strptr, - newsize * sizeof (wchar_t)); -@@ -980,7 +979,7 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, - && wstr == (wchar_t *) *strptr + strsize) - { - size_t newsize -- = strsize + (strsize > width ? width - 1 : strsize); -+ = strsize + (strsize >= width ? width : strsize); - /* Enlarge the buffer. */ - wstr = (wchar_t *) realloc (*strptr, - newsize * sizeof (wchar_t)); - -commit b866ef29773b22a1343ff9084374775114350b78 -Author: Maciej W. Rozycki -Date: Wed May 27 12:57:10 2026 -0400 - - support: Implement 'xfmemopen' for seamless 'fmemopen' use - - Add 'xfmemopen' wrapper for seamless 'fmemopen' use in tests, following - 'xfopen', 'xfclose', etc., and providing a standardized error reporting - facility. - - Reviewed-by: Florian Weimer - (cherry picked from commit fe709cc24578ecfd2ff5b07e10e3829fcb55075b) - - Reviewed-by: Carlos O'Donell - -diff --git a/support/Makefile b/support/Makefile -index d41278eeab..f67f38130a 100644 ---- a/support/Makefile -+++ b/support/Makefile -@@ -134,6 +134,7 @@ libsupport-routines = \ - xfclose \ - xfdopendir \ - xfgets \ -+ xfmemopen \ - xfopen \ - xfork \ - xfread \ -diff --git a/support/xfmemopen.c b/support/xfmemopen.c -new file mode 100644 -index 0000000000..f1dbc72c67 ---- /dev/null -+++ b/support/xfmemopen.c -@@ -0,0 +1,31 @@ -+/* fmemopen with error checking. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+ -+#include -+#include -+ -+FILE * -+xfmemopen (void *mem, size_t len, const char *mode) -+{ -+ FILE *fp = fmemopen (mem, len, mode); -+ if (fp == NULL) -+ FAIL_EXIT1 ("fmemopen (mode \"%s\"): %m", mode); -+ return fp; -+} -diff --git a/support/xstdio.h b/support/xstdio.h -index c3fdf9496f..70b83f11da 100644 ---- a/support/xstdio.h -+++ b/support/xstdio.h -@@ -27,6 +27,7 @@ __BEGIN_DECLS - FILE *xfopen (const char *path, const char *mode); - void xfclose (FILE *); - FILE *xfreopen (const char *path, const char *mode, FILE *stream); -+FILE *xfmemopen (void *mem, size_t len, const char *mode); - void xfread (void *ptr, size_t size, size_t nmemb, FILE *stream); - char *xfgets (char *s, int size, FILE *stream); - - -commit 97926e9017f3faeaacce9337f1288460f5e6ec7d -Author: Maciej W. Rozycki -Date: Wed May 27 12:57:10 2026 -0400 - - stdio-common: Reject insufficient character data in scanf [BZ #12701] - - Reject invalid formatted scanf character data with the 'c' conversion - where there is not enough input available to satisfy the field width - requested. It is required by ISO C that this conversion matches a - sequence of characters of exactly the number specified by the field - width and it is also already documented as such in our own manual: - - "It reads precisely the next N characters, and fails if it cannot get - that many." - - Currently a matching success is instead incorrectly produced where the - EOF condition is encountered before the required number of characters - has been retrieved, and the characters actually obtained are stored in - the buffer provided. - - Add test cases accordingly and remove placeholders from 'c' conversion - input data for the existing scanf tests. - - Reviewed-by: Adhemerval Zanella - - [This is a modified version of commit 2b16c76609, which tests for the - old behavior and only includes the test cases, for older branches - and downstream backports - DJ] - - Reviewed-by: Carlos O'Donell - -diff --git a/localedata/Makefile b/localedata/Makefile -index 4a23593cca..bff5c0bc71 100644 ---- a/localedata/Makefile -+++ b/localedata/Makefile -@@ -236,6 +236,7 @@ tests = \ - bug-iconv-trans \ - bug-setlocale1 \ - bug-usesetlocale \ -+ tst-bz12701-lc \ - tst-bz13988 \ - tst-c-utf8-consistency \ - tst-digits \ -diff --git a/localedata/tst-bz12701-lc.c b/localedata/tst-bz12701-lc.c -new file mode 100644 -index 0000000000..23c2ab7d2a ---- /dev/null -+++ b/localedata/tst-bz12701-lc.c -@@ -0,0 +1,218 @@ -+/* Verify scanf field width handling with the 'lc' conversion (BZ #12701). -+ Copyright (C) 2025-2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+ -+#include -+#include -+#include -+#include -+ -+/* Compare character-wise the initial part of the wide character object -+ pointed to by WS corresponding to wide characters obtained by the -+ conversion of first N bytes of the multibyte character object pointed -+ to by S. */ -+ -+static int -+tst_bz12701_lc_memcmp (const wchar_t *ds, const char *s, size_t n) -+{ -+ size_t nc = mbsnrtowcs (NULL, &s, n, 0, NULL); -+ -+ struct support_next_to_fault ntf; -+ ntf = support_next_to_fault_allocate (nc * sizeof (wchar_t)); -+ wchar_t *ss = (wchar_t *) ntf.buffer; -+ -+ mbsnrtowcs (ss, &s, n, nc, NULL); -+ int r = wmemcmp (ds, ss, nc); -+ -+ support_next_to_fault_free (&ntf); -+ -+ return r; -+} -+ -+/* Verify various aspects of field width handling, including the data -+ obtained, the number of bytes consumed, and the stream position. */ -+ -+static int -+do_test (void) -+{ -+ if (setlocale (LC_ALL, "pl_PL.UTF-8") == NULL) -+ FAIL_EXIT1 ("setlocale (LC_ALL, \"pl_PL.UTF-8\")"); -+ -+ /* Part of a tongue-twister in Polish, which says: -+ "On a rainy morning cuckoos and warblers, rather than starting -+ on earthworms, stuffed themselves fasted with the flesh of cress." */ -+ static const char s[126] = "Dżdżystym rankiem gżegżółki i piegże, " -+ "zamiast wziąć się za dżdżownice, " -+ "nażarły się na czczo miąższu rzeżuchy"; -+ -+ const char *sp = s; -+ size_t nc; -+ TEST_VERIFY_EXIT ((nc = mbsnrtowcs (NULL, &sp, sizeof (s), 0, NULL)) == 108); -+ -+ struct support_next_to_fault ntfo, ntfi; -+ ntfo = support_next_to_fault_allocate (nc * sizeof (wchar_t)); -+ ntfi = support_next_to_fault_allocate (sizeof (s)); -+ wchar_t *e = (wchar_t *) ntfo.buffer + nc; -+ char *b = ntfi.buffer; -+ -+ wchar_t *c; -+ FILE *f; -+ int ic; -+ int n; -+ int i; -+ -+ memcpy (ntfi.buffer, s, sizeof (s)); -+ -+ ic = i = 0; -+ f = xfmemopen (b, sizeof (s), "r"); -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ /* Avoid: "warning: zero width in gnu_scanf format [-Werror=format=]". */ -+ DIAG_PUSH_NEEDS_COMMENT; -+ DIAG_IGNORE_NEEDS_COMMENT (4.9, "-Wformat"); -+ TEST_VERIFY_EXIT (fscanf (f, "%0lc%n", c, &n) == 1); -+ DIAG_POP_NEEDS_COMMENT; -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 1; -+ i += n; -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 2); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 1; -+ i += n; -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%1lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 1; -+ i += n; -+ -+ c = e - 2; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 3); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 2; -+ i += n; -+ -+ c = e - 4; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%4lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 4); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 4; -+ i += n; -+ -+ c = e - 8; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%8lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 8); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 8; -+ i += n; -+ -+ c = e - 16; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%16lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 20); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 16; -+ i += n; -+ -+ c = e - 32; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%32lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 38); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 32; -+ i += n; -+ -+ c = e - (nc - ic); -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_COMPARE (fscanf (f, "%64lc%n", c, &n), 1); -+ TEST_COMPARE (n , 49); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, sizeof (s) - i) == 0); -+ -+ TEST_VERIFY_EXIT (ftell (f) == sizeof (s)); -+ TEST_VERIFY_EXIT (feof (f) != 0); -+ -+ xfclose (f); -+ -+ ic = i = 0; -+ f = xfmemopen (b, 3, "r"); -+ -+ c = e - 2; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 3); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 2; -+ i += n; -+ -+ c = e - (nc - ic); -+ TEST_VERIFY_EXIT (feof (f) == 0); -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2lc%n", c, &n) == EOF); -+ TEST_VERIFY_EXIT (n == 3); -+ -+ TEST_VERIFY_EXIT (ftell (f) == 3); -+ TEST_VERIFY_EXIT (feof (f) != 0); -+ -+ xfclose (f); -+ -+ ic = i = 0; -+ f = xfmemopen (b, 3, "r"); -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 1; -+ i += n; -+ -+ c = e - (nc - ic); -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 2); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, 3 - i) == 0); -+ -+ TEST_VERIFY_EXIT (ftell (f) == 3); -+ TEST_VERIFY_EXIT (feof (f) != 0); -+ -+ xfclose (f); -+ -+ support_next_to_fault_free (&ntfi); -+ support_next_to_fault_free (&ntfo); -+ -+ return 0; -+} -+ -+#include -diff --git a/stdio-common/Makefile b/stdio-common/Makefile -index e52c333808..fdb545242e 100644 ---- a/stdio-common/Makefile -+++ b/stdio-common/Makefile -@@ -260,6 +260,7 @@ tests := \ - tllformat \ - tst-bz11319 \ - tst-bz11319-fortify2 \ -+ tst-bz12701-c \ - tst-cookie \ - tst-dprintf-length \ - tst-fclose-devzero \ -diff --git a/stdio-common/tst-bz12701-c.c b/stdio-common/tst-bz12701-c.c -new file mode 100644 -index 0000000000..4f3616fbfd ---- /dev/null -+++ b/stdio-common/tst-bz12701-c.c -@@ -0,0 +1,169 @@ -+/* Verify scanf field width handling with the 'c' conversion (BZ #12701). -+ Copyright (C) 2025-2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+ -+#include -+#include -+#include -+#include -+ -+/* Verify various aspects of field width handling, including the data -+ obtained, the number of bytes consumed, and the stream position. */ -+ -+static int -+do_test (void) -+{ -+ static const char s[43] = "The quick brown fox jumps over the lazy dog"; -+ struct support_next_to_fault ntfo, ntfi; -+ ntfo = support_next_to_fault_allocate (sizeof (s)); -+ ntfi = support_next_to_fault_allocate (sizeof (s)); -+ char *e = ntfo.buffer + sizeof (s); -+ char *b = ntfi.buffer; -+ -+ char *c; -+ FILE *f; -+ int n; -+ int i; -+ -+ memcpy (ntfi.buffer, s, sizeof (s)); -+ -+ i = 0; -+ f = xfmemopen (b, sizeof (s), "r"); -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ /* Avoid: "warning: zero width in gnu_scanf format [-Werror=format=]". */ -+ DIAG_PUSH_NEEDS_COMMENT; -+ DIAG_IGNORE_NEEDS_COMMENT (4.9, "-Wformat"); -+ TEST_VERIFY_EXIT (fscanf (f, "%0c%n", c, &n) == 1); -+ DIAG_POP_NEEDS_COMMENT; -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%1c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - 2; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 2); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - 4; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%4c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 4); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - 8; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%8c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 8); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - 16; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%16c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 16); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - (sizeof (s) - i); -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%32c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 10); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, sizeof (s) - i) == 0); -+ -+ TEST_VERIFY_EXIT (ftell (f) == sizeof (s)); -+ TEST_VERIFY_EXIT (feof (f) != 0); -+ -+ xfclose (f); -+ -+ i = 0; -+ f = xfmemopen (b, 3, "r"); -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - 2; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 2); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - (3 - i); -+ TEST_VERIFY_EXIT (feof (f) == 0); -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2c%n", c, &n) == EOF); -+ TEST_VERIFY_EXIT (n == 2); -+ -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (feof (f) != 0); -+ -+ xfclose (f); -+ -+ i = 0; -+ f = xfmemopen (b, 3, "r"); -+ -+ c = e - 2; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 2); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - (3 - i); -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, 3 - i) == 0); -+ -+ TEST_VERIFY_EXIT (ftell (f) == 3); -+ TEST_VERIFY_EXIT (feof (f) != 0); -+ -+ xfclose (f); -+ -+ support_next_to_fault_free (&ntfi); -+ support_next_to_fault_free (&ntfo); -+ -+ return 0; -+} -+ -+#include - -commit 6cebb0b80fd783e442a8ad27c3f52cde52a9cac7 -Author: DJ Delorie -Date: Wed May 27 12:57:10 2026 -0400 - - stdio-common: Allow partially-filled %mc buffers [BZ #12701] - - This is a backwards-compatible alternative to the main solution to - the %mc part of 12701. The allocated buffer is expanded to the - requested size and NUL padded, but truncated reads are allowed. - - Reviewed-by: Carlos O'Donell - -diff --git a/localedata/Makefile b/localedata/Makefile -index bff5c0bc71..e212facef0 100644 ---- a/localedata/Makefile -+++ b/localedata/Makefile -@@ -237,6 +237,7 @@ tests = \ - bug-setlocale1 \ - bug-usesetlocale \ - tst-bz12701-lc \ -+ tst-bz12701-lc2 \ - tst-bz13988 \ - tst-c-utf8-consistency \ - tst-digits \ -diff --git a/localedata/tst-bz12701-lc2.c b/localedata/tst-bz12701-lc2.c -new file mode 100644 -index 0000000000..b24e86df0b ---- /dev/null -+++ b/localedata/tst-bz12701-lc2.c -@@ -0,0 +1,47 @@ -+/* Verify scanf memory handling with the 'c' conversion (BZ #12701). -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+ -+#include -+#include -+#include -+#include -+ -+static int -+do_test (void) -+{ -+ wchar_t *c = NULL; -+ int i; -+ -+ TEST_VERIFY (sscanf ("1234", "%30mlc", &c) == 1); -+ -+ TEST_VERIFY (c != NULL); -+ TEST_COMPARE_BLOB (c, 5 * sizeof (wchar_t), -+ L"1234\0", 5 * sizeof (wchar_t)); -+ for (i = 5; i < 30; i ++) -+ TEST_VERIFY (c[i] == L'\0'); -+ -+ TEST_VERIFY (malloc_usable_size (c) >= 30 * sizeof(wchar_t)); -+ -+ return 0; -+} -+ -+#include -diff --git a/stdio-common/Makefile b/stdio-common/Makefile -index fdb545242e..27e7ea20f0 100644 ---- a/stdio-common/Makefile -+++ b/stdio-common/Makefile -@@ -261,6 +261,7 @@ tests := \ - tst-bz11319 \ - tst-bz11319-fortify2 \ - tst-bz12701-c \ -+ tst-bz12701-c2 \ - tst-cookie \ - tst-dprintf-length \ - tst-fclose-devzero \ -diff --git a/stdio-common/tst-bz12701-c2.c b/stdio-common/tst-bz12701-c2.c -new file mode 100644 -index 0000000000..5f9ca7c592 ---- /dev/null -+++ b/stdio-common/tst-bz12701-c2.c -@@ -0,0 +1,46 @@ -+/* Verify scanf memory handling with the 'c' conversion (BZ #12701). -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+ -+#include -+#include -+#include -+#include -+ -+static int -+do_test (void) -+{ -+ char *c = NULL; -+ int i; -+ -+ TEST_VERIFY (sscanf ("1234", "%30mc", &c) == 1); -+ -+ TEST_VERIFY (c != NULL); -+ TEST_COMPARE_BLOB (c, 5, "1234\0", 5); -+ for (i = 5; i < 30; i ++) -+ TEST_VERIFY (c[i] == '\0'); -+ -+ TEST_VERIFY (malloc_usable_size (c) >= 30); -+ -+ return 0; -+} -+ -+#include -diff --git a/stdio-common/vfscanf-internal.c b/stdio-common/vfscanf-internal.c -index 17b5565d0f..90a1886951 100644 ---- a/stdio-common/vfscanf-internal.c -+++ b/stdio-common/vfscanf-internal.c -@@ -780,9 +780,9 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, - conv_error (); \ - } while (0) - #ifdef COMPILE_WSCANF -- STRING_ARG (str, char, 100); -+ STRING_ARG (str, char, (width > 0 ? width : 1)); - #else -- STRING_ARG (str, char, (width > 1024 ? 1024 : width)); -+ STRING_ARG (str, char, (width > 0 ? width : 1)); - #endif - - c = inchar (); -@@ -891,6 +891,11 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, - - if (!(flags & SUPPRESS)) - { -+ /* If the buffer isn't completely filled, pad it with NULs. */ -+ if (flags & MALLOC) -+ while (width-- > 0) -+ *str++ = '\0'; -+ - if ((flags & MALLOC) && str - *strptr != strsize) - { - char *cp = (char *) realloc (*strptr, str - *strptr); -@@ -908,7 +913,7 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, - if (width == -1) - width = 1; - -- STRING_ARG (wstr, wchar_t, (width > 1024 ? 1024 : width)); -+ STRING_ARG (wstr, wchar_t, (width > 0 ? width : 1)); - - c = inchar (); - if (__glibc_unlikely (c == EOF)) -@@ -1044,6 +1049,11 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, - - if (!(flags & SUPPRESS)) - { -+ /* If the buffer isn't completely filled, pad it with NULs. */ -+ if (flags & MALLOC) -+ while (width-- > 0) -+ *wstr++ = L'\0'; -+ - if ((flags & MALLOC) && wstr - (wchar_t *) *strptr != strsize) - { - wchar_t *cp = (wchar_t *) realloc (*strptr, - -commit 748699d9385fc298f7d3369af0a015a6d88b7e64 -Author: Sam James -Date: Sat Jun 6 20:32:27 2026 +0100 - - elf: don't clobber ld.so.conf in tst-glibc-hwcaps-prepend-cache [BZ #34210] - - dbe5065f2166be20e57a24f246a40d50e001a05d and ae589cb84df10825fc545a45c7007a5f79409bf1 - cater for setups where ld.so.conf{,.d} is required to find runtime support - libraries, but tst-glibc-hwcaps-prepend-cache clobbers the created ld.so.conf - with its own entry. - - Fix it to instead use the ld.so.conf.d created in ae589cb84df10825fc545a45c7007a5f79409bf1 - to co-exist with existing entries. - - Bug: https://bugs.gentoo.org/976773 - Bug: https://sourceware.org/bugzilla/show_bug.cgi?id=31901 - Bug: https://sourceware.org/bugzilla/show_bug.cgi?id=34210 - Tested-by: Andreas K. Hüttel - Reported-by: Eli Schwartz - Reviewed-by: Andreas K. Hüttel - (cherry picked from commit d0cc9bf859d0434e397530d75a6507f13db79fba) - -diff --git a/elf/tst-glibc-hwcaps-prepend-cache.c b/elf/tst-glibc-hwcaps-prepend-cache.c -index b7df3962b5..2d51c22328 100644 ---- a/elf/tst-glibc-hwcaps-prepend-cache.c -+++ b/elf/tst-glibc-hwcaps-prepend-cache.c -@@ -46,7 +46,7 @@ do_test (void) - - { - /* Install the default implementation of libmarkermod1.so. */ -- char *conf_path = xasprintf ("%s/ld.so.conf", support_sysconfdir_prefix); -+ char *conf_path = xasprintf ("%s/ld.so.conf.d/hwcaps.conf", support_sysconfdir_prefix); - xmkdirp (support_sysconfdir_prefix, 0777); - support_write_file_string (conf_path, "/glibc-test/lib\n"); - free (conf_path); - -commit f671746f6c3ae511432b5666953be668267159f8 -Author: Florian Weimer -Date: Tue Jun 9 07:28:02 2026 +0200 - - iconv: Suppress intermediate errors with //TRANSLIT (bug 34236) - - When tentatively converting characters on behalf of - __gconv_transliterate, do not create a persistent error. Just - produce a local error, and rely on __gconv_transliterate to - produce the error if all transliteration options are exhausted. - - This fixes transliteration of “½” to ASCII, which cannot use the - “ 1⁄2 ” alternative. Eventually, the “ 1/2 ” alternative is chosen, - but the error sticks. Therefore, iconv exited with status 1 before - this change. - - Adjust iconv/tst-iconv_prog.sh to test both C and en_US.UTF-8 locales. - This requires changing the way the ICONV template is defined, so that - run_program_env is evaluated multiple times. - - Fixes commit 9a4b0eaf726f5404c6683d5c7c5e86f61c3f3fbc ("iconv: do not - report error exit with transliteration [BZ #32448]"), - commit 6cbf845fcdc76131d0e674cee454fe738b69c69d ("iconv: Preserve - iconv -c error exit on invalid inputs (bug 32046)"), and bug 34236. - - Reviewed-by: Aurelien Jarno - (cherry picked from commit e9325bd7d04aacc45cf39505e279b1ca9de22c08) - -diff --git a/iconv/Makefile b/iconv/Makefile -index 9a94a41ba4..028d24ffc3 100644 ---- a/iconv/Makefile -+++ b/iconv/Makefile -@@ -138,7 +138,8 @@ $(objpfx)test-iconvconfig.out: $(objpfx)iconvconfig - rm -f $$tmp) > $@; \ - $(evaluate-test) - --$(objpfx)tst-iconv_prog.out: tst-iconv_prog.sh $(objpfx)iconv_prog -+$(objpfx)tst-iconv_prog.out: tst-iconv_prog.sh $(objpfx)iconv_prog \ -+ $(gen-locales) - $(BASH) $< $(common-objdir) '$(test-wrapper-env)' \ - '$(run-program-env)' > $@; \ - $(evaluate-test) -diff --git a/iconv/loop.c b/iconv/loop.c -index 1378d23147..74b2a3e26d 100644 ---- a/iconv/loop.c -+++ b/iconv/loop.c -@@ -144,8 +144,10 @@ - if (irreversible == NULL) \ - { \ - /* This means we are in call from __gconv_transliterate. In this \ -- case we are not doing any error recovery ourselves. */ \ -- result = __gconv_mark_illegal_input (step_data); \ -+ case we are not doing any error recovery ourselves. Do not create \ -+ a persistent error state. If __gconv_transliterate exhausts all \ -+ alternatives, it will call __gconv_mark_illegal_input itself. */ \ -+ result = __GCONV_ILLEGAL_INPUT; \ - break; \ - } \ - \ -diff --git a/iconv/tst-iconv_prog.sh b/iconv/tst-iconv_prog.sh -index e2a43280d2..7d7948b7aa 100644 ---- a/iconv/tst-iconv_prog.sh -+++ b/iconv/tst-iconv_prog.sh -@@ -27,10 +27,10 @@ LIBPATH=$codir:$codir/iconvdata - - # How the start the iconv(1) program. $from is not defined/expanded yet. - ICONV=' -+$test_wrapper_env $run_program_env - $codir/elf/ld.so --library-path $LIBPATH --inhibit-rpath ${from}.so - $codir/iconv/iconv_prog - ' --ICONV="$test_wrapper_env $run_program_env $ICONV" - - TIMEOUTFACTOR=${TIMEOUTFACTOR:-1} - -@@ -218,6 +218,7 @@ testarray=( - "\x00\x00;;INVALID;UTF-8;1" - "\x00\x00;;UTF-8;INVALID;1" - "\xc3\xa9;;UTF-8;ASCII//TRANSLIT;0" -+"X\xc2\xbdY;;UTF-8;ASCII//TRANSLIT;0" - ) - - # Requires $twobyte input, $c flag, $from, and $to to be set; sets $ret -@@ -278,12 +279,21 @@ check_errtest_result () - fi - } - --for testcommand in "${testarray[@]}"; do -- twobyte="$(echo "$testcommand" | cut -d";" -f 1)" -- c="$(echo "$testcommand" | cut -d";" -f 2)" -- from="$(echo "$testcommand" | cut -d";" -f 3)" -- to="$(echo "$testcommand" | cut -d";" -f 4)" -- eret="$(echo "$testcommand" | cut -d";" -f 5)" -- execute_test -- check_errtest_result --done -+run_test_array () -+{ -+ for testcommand in "${testarray[@]}"; do -+ twobyte="$(echo "$testcommand" | cut -d";" -f 1)" -+ c="$(echo "$testcommand" | cut -d";" -f 2)" -+ from="$(echo "$testcommand" | cut -d";" -f 3)" -+ to="$(echo "$testcommand" | cut -d";" -f 4)" -+ eret="$(echo "$testcommand" | cut -d";" -f 5)" -+ execute_test -+ check_errtest_result -+ done -+} -+ -+echo "info: testing C locale" -+run_test_array -+echo "info: testing en_US.UTF-8 locale" -+run_program_env="$run_program_env LC_ALL=en_US.UTF-8" -+run_test_array - -commit f6713070c6accac5c93d96c1d580833afacde3f5 -Author: Adhemerval Zanella -Date: Wed May 13 08:32:24 2026 -0300 - - arm: Save/restore VFP registers in PLT trampolines (BZ 34144, BZ 15792) - - _dl_runtime_resolve and _dl_runtime_profile only preserved the integer - argument registers (r0-r3) across the inner call to _dl_fixup / - _dl_profile_fixup. Two related ABI requirements demand more: - - * Under AAPCS-VFP, d0-d7 hold the caller's double arguments to the - function being resolved. Recent GCC emits VFP instructions inside - the fixup routines, clobbering them, so the resolved function sees - corrupted arguments (BZ 34144). - - * Per RTABI32, the __aeabi_mem* helpers (and similar runtime helpers - reachable through the dynamic linker) must only corrupt integer - core registers. IFUNC resolvers, audit modules, and interposed - malloc invoked during symbol resolution may also use VFP, even on - softfp ABI builds (BZ 15792). - - Save all call-clobbered VFP state -- d0-d15 unconditionally, d16-d31 - when HWCAP_ARM_VFPD32 is set, and fpscr -- around the inner fixup - call. Whether VFP is usable is a property of the hardware, not of - the ABI glibc was built with, so the decision is gated on AT_HWCAP at - runtime in both hardfp and softfp builds; hardfp builds will always - find HWCAP_ARM_VFP set, while softfp builds running on a non-VFP CPU - correctly skip the save. - - For _dl_runtime_profile the save area is slipped in just before the - bl to _dl_profile_fixup; the outgoing framesizep argument is - recomputed to account for the extra frame, and both the fast path - (no audit framesize) and the slow path (audit wraps with - pltenter/pltexit) traverse the restore before splitting. - - Checked on arm-linux-gnueabihf. - - Tested-by: Aurelien Jarno - Reviewed-by: Wilco Dijkstra - (cherry picked from commit 1111fbdd3e7ebed402800bc23e67055eaae0d972) - -diff --git a/sysdeps/arm/Makefile b/sysdeps/arm/Makefile -index 9c4fd6b236..be9e46aeeb 100644 ---- a/sysdeps/arm/Makefile -+++ b/sysdeps/arm/Makefile -@@ -30,6 +30,25 @@ $(objpfx)tst-armtlsdescloc: $(objpfx)tst-armtlsdesclocmod.so - $(objpfx)tst-armtlsdescextnow: $(objpfx)tst-armtlsdescextnowmod.so - $(objpfx)tst-armtlsdescextlazy: $(objpfx)tst-armtlsdescextlazymod.so - endif -+ -+tests += \ -+ tst-bz34144 \ -+ tst-bz34144-audit \ -+ # tests -+modules-names += \ -+ tst-bz34144-auditmod \ -+ tst-bz34144-mod \ -+ # modules-names -+$(objpfx)tst-bz34144: $(objpfx)tst-bz34144-mod.so -+$(objpfx)tst-bz34144-audit: $(objpfx)tst-bz34144-mod.so -+$(objpfx)tst-bz34144-audit.out: $(objpfx)tst-bz34144-auditmod.so -+# Use lazy binding to check if _dl_runtime_resolve correctly save/restore -+# the VFP state. -+LDFLAGS-tst-bz34144 = -Wl,-z,lazy -+# With LD_AUDIT, lazy resolution goes through _dl_runtime_profile, which -+# must also save/restore VFP state (BZ 34144). -+LDFLAGS-tst-bz34144-audit = -Wl,-z,lazy -+tst-bz34144-audit-ENV = LD_AUDIT=$(objpfx)tst-bz34144-auditmod.so - endif - endif - -diff --git a/sysdeps/arm/dl-trampoline.S b/sysdeps/arm/dl-trampoline.S -index fffac55050..ef358d48bc 100644 ---- a/sysdeps/arm/dl-trampoline.S -+++ b/sysdeps/arm/dl-trampoline.S -@@ -20,6 +20,7 @@ - #define NO_THUMB - #include - #include -+#include - - .text - .globl _dl_runtime_resolve -@@ -36,13 +37,40 @@ _dl_runtime_resolve: - @ ip contains &GOT[n+3] (pointer to function) - @ lr points to &GOT[2] - -- @ Save arguments. We save r4 to realign the stack. -+ @ Save arguments. We save r4 to realign the stack and to hold -+ @ the hwcap value used to decide whether to save VFP registers. - push {r0-r4} - cfi_adjust_cfa_offset (20) - cfi_rel_offset (r0, 0) - cfi_rel_offset (r1, 4) - cfi_rel_offset (r2, 8) - cfi_rel_offset (r3, 12) -+ cfi_rel_offset (r4, 16) -+ -+#ifdef SHARED -+ @ Preserve all call-clobbered VFP registers across _dl_fixup. -+ @ VFP may be used by IFUNC resolvers, audit modules, interposed -+ @ malloc, and the __aeabi_mem* helpers required by RTABI32, -+ @ which mandates that those helpers only corrupt integer core -+ @ registers. -+ LDR_GLOBAL (r4, r3, C_SYMBOL_NAME(_rtld_global_ro), \ -+ RTLD_GLOBAL_RO_DL_HWCAP_OFFSET) -+ -+ tst r4, #HWCAP_ARM_VFP -+ beq .Lno_vfp_save -+ -+# define VFP_STACK_REQ (32*8 + 8) -+ sub sp, sp, VFP_STACK_REQ -+ cfi_adjust_cfa_offset (VFP_STACK_REQ) -+ mov r3, sp -+ .inst 0xeca30b20 @ vstmia r3!, {d0-d15} -+ tst r4, #HWCAP_ARM_VFPD32 -+ beq 1f -+ .inst 0xece30b20 @ vstmia r3!, {d16-d31} -+1: .inst 0xeef12a10 @ vmrs r2, fpscr -+ str r2, [r3] -+.Lno_vfp_save: -+#endif /* SHARED */ - - @ get pointer to linker struct - ldr r0, [lr, #-4] -@@ -59,8 +87,23 @@ _dl_runtime_resolve: - @ save the return - mov ip, r0 - -- @ get arguments and return address back. We restore r4 -- @ only to realign the stack. -+#ifdef SHARED -+ tst r4, #HWCAP_ARM_VFP -+ beq .Lno_vfp_restore -+ mov r3, sp -+ .inst 0xecb30b20 @ vldmia r3!, {d0-d15} -+ tst r4, #HWCAP_ARM_VFPD32 -+ beq 2f -+ .inst 0xecf30b20 @ vldmia r3!, {d16-d31} -+2: ldr r2, [r3] -+ .inst 0xeee12a10 @ vmsr fpscr, r2 -+ add sp, sp, VFP_STACK_REQ -+ cfi_adjust_cfa_offset (-VFP_STACK_REQ) -+.Lno_vfp_restore: -+#endif /* SHARED */ -+ -+ @ get arguments and return address back. We restore r4 to -+ @ its original value as well. - pop {r0-r4,lr} - cfi_adjust_cfa_offset (-24) - -@@ -124,14 +167,71 @@ _dl_runtime_profile: - add r3, sp, #8 - stmia r3!, {r0,r1} - -+ @ Preserve all call-clobbered VFP registers across -+ @ _dl_profile_fixup. See the matching comment in -+ @ _dl_runtime_resolve above for the rationale (BZ 34144, -+ @ BZ 15792). -+ @ -+ @ Stack layout below the current sp (which becomes the new sp -+ @ after the sub): -+ @ sp + 0 .. 3: outgoing arg (framesizep) for _dl_profile_fixup -+ @ sp + 4 .. 7: saved hwcap (so we can test it after the call) -+ @ sp + 8 .. 11: saved r2 (used as scratch for LDR_GLOBAL) -+ @ sp + 12 .. 15: padding (for 8-byte alignment of the VFP area) -+ @ sp + 16 .. 16+VFP_STACK_REQ-1: VFP regs + fpscr -+#define VFP_PROFILE_STACK (16 + VFP_STACK_REQ) -+ sub sp, sp, #VFP_PROFILE_STACK -+ cfi_adjust_cfa_offset (VFP_PROFILE_STACK) -+ -+ @ r2 holds the retaddr (3rd arg to _dl_profile_fixup); spill -+ @ it so we can use it as the LDR_GLOBAL destination. -+ str r2, [sp, #8] -+ -+ LDR_GLOBAL (r2, ip, C_SYMBOL_NAME(_rtld_global_ro), \ -+ RTLD_GLOBAL_RO_DL_HWCAP_OFFSET) -+ str r2, [sp, #4] -+ -+ tst r2, #HWCAP_ARM_VFP -+ beq .Lprofile_no_vfp_save -+ add ip, sp, #16 -+ .inst 0xecac0b20 @ vstmia ip!, {d0-d15} -+ tst r2, #HWCAP_ARM_VFPD32 -+ beq 7f -+ .inst 0xecec0b20 @ vstmia ip!, {d16-d31} -+7: .inst 0xeef12a10 @ vmrs r2, fpscr -+ str r2, [ip] -+.Lprofile_no_vfp_save: -+ -+ @ Restore r2 (retaddr) for _dl_profile_fixup. -+ ldr r2, [sp, #8] -+ - @ Set up extra args for _dl_profile_fixup. -- @ r2 and r3 are already loaded. -- add ip, sp, #208 -+ @ The framesize slot is at the old sp+208, which is the new -+ @ sp + VFP_PROFILE_STACK + 208 -- compute in two steps because -+ @ the combined offset is not encodable as an ARM immediate. -+ add ip, sp, #VFP_PROFILE_STACK -+ add ip, ip, #208 - str ip, [sp, #0] - - @ call profiling fixup routine - bl _dl_profile_fixup - -+ @ Restore VFP registers. r0 holds the resolved function -+ @ address; r1/r2/ip are caller-saved by the call. -+ ldr r1, [sp, #4] -+ tst r1, #HWCAP_ARM_VFP -+ beq .Lprofile_no_vfp_restore -+ add ip, sp, #16 -+ .inst 0xecbc0b20 @ vldmia ip!, {d0-d15} -+ tst r1, #HWCAP_ARM_VFPD32 -+ beq 8f -+ .inst 0xecfc0b20 @ vldmia ip!, {d16-d31} -+8: ldr r2, [ip] -+ .inst 0xeee12a10 @ vmsr fpscr, r2 -+.Lprofile_no_vfp_restore: -+ add sp, sp, #VFP_PROFILE_STACK -+ cfi_adjust_cfa_offset (-VFP_PROFILE_STACK) -+ - @ The address to call is now in r0. - - @ Check whether we're wrapping this function. -diff --git a/sysdeps/arm/tst-bz34144-audit.c b/sysdeps/arm/tst-bz34144-audit.c -new file mode 100644 -index 0000000000..8f1084fa0a ---- /dev/null -+++ b/sysdeps/arm/tst-bz34144-audit.c -@@ -0,0 +1,32 @@ -+/* Test that lazy PLT resolution via _dl_runtime_profile preserves -+ caller-saved VFP registers used to pass double arguments (BZ 34144). -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+ -+extern void test_float_args (double a, double b, double c, double d, -+ double e, double f, double g, double h); -+ -+static int -+do_test (void) -+{ -+ test_float_args (2.0, 3.0, 4.0, 5.0, 6.0, 7.0, 8.0, 9.0); -+ return 0; -+} -+ -+#include -diff --git a/sysdeps/arm/tst-bz34144-auditmod.c b/sysdeps/arm/tst-bz34144-auditmod.c -new file mode 100644 -index 0000000000..ada9f126c2 ---- /dev/null -+++ b/sysdeps/arm/tst-bz34144-auditmod.c -@@ -0,0 +1,50 @@ -+/* Minimal audit module used by tst-bz34144-audit to force PLT calls -+ to go through _dl_runtime_profile instead of _dl_runtime_resolve. -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+ -+unsigned int -+la_version (unsigned int v) -+{ -+ return v; -+} -+ -+unsigned int -+la_objopen (struct link_map *l, Lmid_t lmid, uintptr_t *cookie) -+{ -+ return LA_FLG_BINDFROM | LA_FLG_BINDTO; -+} -+ -+uintptr_t -+la_symbind32 (Elf32_Sym *sym, unsigned int ndx, uintptr_t *refcook, -+ uintptr_t *defcook, unsigned int *flags, const char *symname) -+{ -+ return sym->st_value; -+} -+ -+Elf32_Addr -+la_arm_gnu_pltenter (Elf32_Sym *sym, unsigned int ndx, uintptr_t *refcook, -+ uintptr_t *defcook, La_arm_regs *regs, -+ unsigned int *flags, const char *symname, -+ long int *framesizep) -+{ -+ return sym->st_value; -+} -diff --git a/sysdeps/arm/tst-bz34144-mod.c b/sysdeps/arm/tst-bz34144-mod.c -new file mode 100644 -index 0000000000..be6b54bf91 ---- /dev/null -+++ b/sysdeps/arm/tst-bz34144-mod.c -@@ -0,0 +1,28 @@ -+/* DSO used by tst-bz34144. -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+ -+void -+test_float_args (double a, double b, double c, double d, -+ double e, double f, double g, double h) -+{ -+ if (a != 2.0 || b != 3.0 || c != 4.0 || d != 5.0 -+ || e != 6.0 || f != 7.0 || g != 8.0 || h != 9.0) -+ abort (); -+} -diff --git a/sysdeps/arm/tst-bz34144.c b/sysdeps/arm/tst-bz34144.c -new file mode 100644 -index 0000000000..61e41b3945 ---- /dev/null -+++ b/sysdeps/arm/tst-bz34144.c -@@ -0,0 +1,32 @@ -+/* Test that lazy PLT resolution preserves caller-saved VFP registers -+ used to pass double arguments (BZ 34144). -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+ -+extern void test_float_args (double a, double b, double c, double d, -+ double e, double f, double g, double h); -+ -+static int -+do_test (void) -+{ -+ test_float_args (2.0, 3.0, 4.0, 5.0, 6.0, 7.0, 8.0, 9.0); -+ return 0; -+} -+ -+#include - -commit 0be5a6a72a4a3132bc211720d2b6949a84f54dc3 -Author: John David Anglin -Date: Tue Jun 23 13:41:10 2026 -0400 - - hppa: Fix missing call to __feraiseexcept (BZ 34306) - - The feupdateenv function is supposed to raise exceptions after - installing the environment represented by its envp argument. - This was accidentally missed on hppa. - - The failure to raise exceptions was noticed by the failure of - the math/test-narrowing-trap test. - - Signed-off-by: John David Anglin - -diff --git a/sysdeps/hppa/fpu/feupdateenv.c b/sysdeps/hppa/fpu/feupdateenv.c -index 46b83cc7a0..a3d3de33e4 100644 ---- a/sysdeps/hppa/fpu/feupdateenv.c -+++ b/sysdeps/hppa/fpu/feupdateenv.c -@@ -24,6 +24,7 @@ __feupdateenv (const fenv_t *envp) - { - union { unsigned long long l; unsigned int sw[2]; } s; - fenv_t temp; -+ - /* Get the current exception status */ - __asm__ ("fstd %%fr0,0(%1) \n\t" - "fldd 0(%1),%%fr0 \n\t" -@@ -46,6 +47,10 @@ __feupdateenv (const fenv_t *envp) - - /* Install new environment. */ - __fesetenv (&temp); -+ -+ /* Raise exceptions. */ -+ __feraiseexcept (temp.__status_word >> 27); -+ - /* Success. */ - return 0; - } - -commit 54929540335ef339ac66a8c28e3f4c22ebae2630 -Author: Fabian Rast -Date: Thu Jun 11 14:30:37 2026 +0200 - - rtld: cache cpuid results on the stack for intel - - dl_init_cacheinfo retrieves various information about cache - sizes, using the cpuid instruction on x86. - Previously, the same cpuid leaves were queried multiple times. - This behavior caused intel_check_word to prominently show up in - profiles of dynamic loader startup on the Intel(R) Xeon(R) Gold 6430. - The big performance impact could not be reproduced on other Intel cpus. - - This patch reduces the number of cpuid queries on startup - by caching their results on the stack for reuse when searching for a - different cache size value. - This approach does not change the overall design of - the cache enumeration code (repeated calls to handle_* functions). - The values are cached on the stack instead of globally (e.g. - in the cpu_features global) because they are never needed after - early initialization. - - The cache is only active for Intel cpus, because it has not yet - been shown through benchmarks that it meaningfully improves performance - for other processors. - - Signed-off-by: Fabian Rast - Reviewed-by: Sunil K Pandey - (cherry picked from commit df83fa8813eb53dcb232462a4f6dd00c873115f0) - -diff --git a/sysdeps/x86/dl-cacheinfo.h b/sysdeps/x86/dl-cacheinfo.h -index 6f9bb08a19..201d3ad278 100644 ---- a/sysdeps/x86/dl-cacheinfo.h -+++ b/sysdeps/x86/dl-cacheinfo.h -@@ -98,6 +98,15 @@ static const struct intel_02_cache_info - - #define nintel_02_known (sizeof (intel_02_known) / sizeof (intel_02_known [0])) - -+/* Cache for redundant cpuid queries in handle_intel, intel_check_word and -+ get_common_cache_info. Currently, this has only been shown to significantly -+ improve performance on a specific Intel CPU (Xeon 6430). */ -+struct intel_cpuid_cache -+{ -+ unsigned char leaf2_valid, leaf4_valid; /* Number of cached (sub)leaves. */ -+ unsigned int leaf2[4], leaf4[0x10][4]; -+}; -+ - static int - intel_02_known_compare (const void *p1, const void *p2) - { -@@ -118,7 +127,8 @@ static long int - __attribute__ ((noinline)) - intel_check_word (int name, unsigned int value, bool *has_level_2, - bool *no_level_2_or_3, -- const struct cpu_features *cpu_features) -+ const struct cpu_features *cpu_features, -+ struct intel_cpuid_cache *cache) - { - if ((value & 0x80000000) != 0) - /* The register value is reserved. */ -@@ -152,7 +162,21 @@ intel_check_word (int name, unsigned int value, bool *has_level_2, - unsigned int round = 0; - while (1) - { -- __cpuid_count (4, round, eax, ebx, ecx, edx); -+ if (round < cache->leaf4_valid) -+ /* Subleaf was queried before. Do not execute cpuid again. */ -+ eax = cache->leaf4[round][0], ebx = cache->leaf4[round][1], -+ ecx = cache->leaf4[round][2], edx = cache->leaf4[round][3]; -+ else if (round == cache->leaf4_valid -+ && round < sizeof(cache->leaf4)/sizeof(*cache->leaf4)) -+ { -+ /* Cache the cpuid result if we have space. */ -+ __cpuid_count (4, round, eax, ebx, ecx, edx); -+ cache->leaf4[round][0] = eax, cache->leaf4[round][1] = ebx; -+ cache->leaf4[round][2] = ecx, cache->leaf4[round][3] = edx; -+ cache->leaf4_valid++; -+ } -+ else -+ __cpuid_count (4, round, eax, ebx, ecx, edx); - - enum { null = 0, data = 1, inst = 2, uni = 3 } type = eax & 0x1f; - if (type == null) -@@ -247,7 +271,8 @@ intel_check_word (int name, unsigned int value, bool *has_level_2, - - - static long int __attribute__ ((noinline)) --handle_intel (int name, const struct cpu_features *cpu_features) -+handle_intel (int name, const struct cpu_features *cpu_features, -+ struct intel_cpuid_cache *cache) - { - unsigned int maxidx = cpu_features->basic.max_cpuid; - -@@ -260,41 +285,33 @@ handle_intel (int name, const struct cpu_features *cpu_features) - long int result = 0; - bool no_level_2_or_3 = false; - bool has_level_2 = false; -- unsigned int eax; -- unsigned int ebx; -- unsigned int ecx; -- unsigned int edx; -- __cpuid (2, eax, ebx, ecx, edx); -+ int i; -+ -+ if (!cache->leaf2_valid) -+ { -+ __cpuid (2, cache->leaf2[0], cache->leaf2[1], -+ cache->leaf2[2], cache->leaf2[3]); -+ cache->leaf2_valid = 1; -+ } - - /* The low byte of EAX of CPUID leaf 2 should always return 1 and it - should be ignored. If it isn't 1, use CPUID leaf 4 instead. */ -- if ((eax & 0xff) != 1) -+ if ((cache->leaf2[0] & 0xff) != 1) - return intel_check_word (name, 0xff, &has_level_2, &no_level_2_or_3, -- cpu_features); -- else -- { -- eax &= 0xffffff00; -- -- /* Process the individual registers' value. */ -- result = intel_check_word (name, eax, &has_level_2, -- &no_level_2_or_3, cpu_features); -- if (result != 0) -- return result; -+ cpu_features, cache); - -- result = intel_check_word (name, ebx, &has_level_2, -- &no_level_2_or_3, cpu_features); -- if (result != 0) -- return result; -- -- result = intel_check_word (name, ecx, &has_level_2, -- &no_level_2_or_3, cpu_features); -- if (result != 0) -- return result; -+ /* Process all descriptors in leaf 2. */ -+ result = intel_check_word (name, cache->leaf2[0]&0xffffff00, &has_level_2, -+ &no_level_2_or_3, cpu_features, cache); -+ if (result != 0) -+ return result; - -- result = intel_check_word (name, edx, &has_level_2, -- &no_level_2_or_3, cpu_features); -+ for (i = 1; i < 4; i++) -+ { -+ result = intel_check_word (name, cache->leaf2[i], &has_level_2, -+ &no_level_2_or_3, cpu_features, cache); - if (result != 0) -- return result; -+ return result; - } - - if (name >= _SC_LEVEL2_CACHE_SIZE && name <= _SC_LEVEL3_CACHE_LINESIZE -@@ -611,7 +628,7 @@ handle_hygon (int name) - - static void - get_common_cache_info (long int *shared_ptr, long int * shared_per_thread_ptr, unsigned int *threads_ptr, -- long int core) -+ long int core, struct intel_cpuid_cache *cache) - { - unsigned int eax; - unsigned int ebx; -@@ -669,7 +686,14 @@ get_common_cache_info (long int *shared_ptr, long int * shared_per_thread_ptr, u - int check = 0x1 | (threads_l3 == 0) << 1; - do - { -- __cpuid_count (4, i++, eax, ebx, ecx, edx); -+ if (cache != NULL && i < cache->leaf4_valid) -+ eax = cache->leaf4[i][0], ebx = cache->leaf4[i][1], -+ ecx = cache->leaf4[i][2], edx = cache->leaf4[i][3]; -+ else -+ /* Do not attempt to cache queries at this point, -+ because get_common_cache_info is called last. */ -+ __cpuid_count (4, i, eax, ebx, ecx, edx); -+ i++; - - /* There seems to be a bug in at least some Pentium Ds - which sometimes fail to iterate all cache parameters. -@@ -849,35 +873,38 @@ dl_init_cacheinfo (struct cpu_features *cpu_features) - - if (cpu_features->basic.kind == arch_kind_intel) - { -- data = handle_intel (_SC_LEVEL1_DCACHE_SIZE, cpu_features); -- shared = handle_intel (_SC_LEVEL3_CACHE_SIZE, cpu_features); -+ struct intel_cpuid_cache cache; -+ cache.leaf2_valid = cache.leaf4_valid = 0; -+ -+ data = handle_intel (_SC_LEVEL1_DCACHE_SIZE, cpu_features, &cache); -+ shared = handle_intel (_SC_LEVEL3_CACHE_SIZE, cpu_features, &cache); - shared_per_thread = shared; - - level1_icache_size -- = handle_intel (_SC_LEVEL1_ICACHE_SIZE, cpu_features); -+ = handle_intel (_SC_LEVEL1_ICACHE_SIZE, cpu_features, &cache); - level1_icache_linesize -- = handle_intel (_SC_LEVEL1_ICACHE_LINESIZE, cpu_features); -+ = handle_intel (_SC_LEVEL1_ICACHE_LINESIZE, cpu_features, &cache); - level1_dcache_size = data; - level1_dcache_assoc -- = handle_intel (_SC_LEVEL1_DCACHE_ASSOC, cpu_features); -+ = handle_intel (_SC_LEVEL1_DCACHE_ASSOC, cpu_features, &cache); - level1_dcache_linesize -- = handle_intel (_SC_LEVEL1_DCACHE_LINESIZE, cpu_features); -+ = handle_intel (_SC_LEVEL1_DCACHE_LINESIZE, cpu_features, &cache); - level2_cache_size -- = handle_intel (_SC_LEVEL2_CACHE_SIZE, cpu_features); -+ = handle_intel (_SC_LEVEL2_CACHE_SIZE, cpu_features, &cache); - level2_cache_assoc -- = handle_intel (_SC_LEVEL2_CACHE_ASSOC, cpu_features); -+ = handle_intel (_SC_LEVEL2_CACHE_ASSOC, cpu_features, &cache); - level2_cache_linesize -- = handle_intel (_SC_LEVEL2_CACHE_LINESIZE, cpu_features); -+ = handle_intel (_SC_LEVEL2_CACHE_LINESIZE, cpu_features, &cache); - level3_cache_size = shared; - level3_cache_assoc -- = handle_intel (_SC_LEVEL3_CACHE_ASSOC, cpu_features); -+ = handle_intel (_SC_LEVEL3_CACHE_ASSOC, cpu_features, &cache); - level3_cache_linesize -- = handle_intel (_SC_LEVEL3_CACHE_LINESIZE, cpu_features); -+ = handle_intel (_SC_LEVEL3_CACHE_LINESIZE, cpu_features, &cache); - level4_cache_size -- = handle_intel (_SC_LEVEL4_CACHE_SIZE, cpu_features); -+ = handle_intel (_SC_LEVEL4_CACHE_SIZE, cpu_features, &cache); - - get_common_cache_info (&shared, &shared_per_thread, &threads, -- level2_cache_size); -+ level2_cache_size, &cache); - } - else if (cpu_features->basic.kind == arch_kind_zhaoxin) - { -@@ -898,7 +925,7 @@ dl_init_cacheinfo (struct cpu_features *cpu_features) - level3_cache_linesize = handle_zhaoxin (_SC_LEVEL3_CACHE_LINESIZE); - - get_common_cache_info (&shared, &shared_per_thread, &threads, -- level2_cache_size); -+ level2_cache_size, NULL); - } - else if (cpu_features->basic.kind == arch_kind_amd) - { - -commit f2f55eac9e6f1167486f2694dea88adf87c77fdd -Author: Florian Weimer -Date: Fri Jun 19 18:22:20 2026 +0200 - - resolv: Declare __p_class_syms, __p_type_syms for internal use - - Reviewed-by: Carlos O'Donell - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 360f352c9a6da545d798ef3015e73ca114f0d230) - -diff --git a/include/resolv.h b/include/resolv.h -index 4dbbac3800..d5ad9994b9 100644 ---- a/include/resolv.h -+++ b/include/resolv.h -@@ -70,6 +70,11 @@ libc_hidden_proto (__libc_res_nameinquery) - extern __typeof (__res_queriesmatch) __libc_res_queriesmatch; - libc_hidden_proto (__libc_res_queriesmatch) - -+extern const struct res_sym __p_class_syms[]; -+libresolv_hidden_proto (__p_class_syms) -+extern const struct res_sym __p_type_syms[]; -+libresolv_hidden_proto (__p_type_syms) -+ - /* Variant of res_hnok which operates on binary (but uncompressed) names. */ - bool __res_binary_hnok (const unsigned char *dn) attribute_hidden; - -diff --git a/resolv/res_debug.c b/resolv/res_debug.c -index 73af0c72fe..6bf9962916 100644 ---- a/resolv/res_debug.c -+++ b/resolv/res_debug.c -@@ -390,8 +390,6 @@ p_fqname(const u_char *cp, const u_char *msg, FILE *file) { - * that C_ANY is a qclass but not a class. (You can ask for records of class - * C_ANY, but you can't have any records of that class in the database.) - */ --extern const struct res_sym __p_class_syms[]; --libresolv_hidden_proto (__p_class_syms) - const struct res_sym __p_class_syms[] = { - {C_IN, (char *) "IN"}, - {C_CHAOS, (char *) "CHAOS"}, -@@ -426,8 +424,6 @@ const struct res_sym __p_update_section_syms[] attribute_hidden = { - * Names of RR types and qtypes. The list is incomplete because its - * size is part of the ABI. - */ --extern const struct res_sym __p_type_syms[]; --libresolv_hidden_proto (__p_type_syms) - const struct res_sym __p_type_syms[] = { - {ns_t_a, (char *) "A", (char *) "address"}, - {ns_t_ns, (char *) "NS", (char *) "name server"}, - -commit 3c27e5170c456a69807348de8586c123f62a51f6 -Author: Florian Weimer -Date: Fri Jun 19 18:22:20 2026 +0200 - - resolv: Fix ns_sprintrrf formatting of class, type values (bug 34289) - - The p_class and p_type results could overwrite each other if both - were unknown. Format unknown values with CLASS and TYPE prefixes, - as in RFC 3597. Handle A6 separately because it cannot be added - to __p_type_syms for ABI reasons. - - Reviewed-by: Carlos O'Donell - Reviewed-by: Adhemerval Zanella - (cherry picked from commit f69b7f95e3694177546faec25d88bb266885c3b8) - -diff --git a/resolv/ns_print.c b/resolv/ns_print.c -index cef2212fd2..e75c39eaa8 100644 ---- a/resolv/ns_print.c -+++ b/resolv/ns_print.c -@@ -78,6 +78,24 @@ ns_sprintrr(const ns_msg *handle, const ns_rr *rr, - } - libresolv_hidden_def (ns_sprintrr) - -+/* Writes the class/type symbol NUMBER to *BUF, using the name from -+ *SYMS if possible. If NUMBER is not found in *SYMS, print the -+ number with PREFIX. */ -+static int -+addsym (const struct res_sym *syms, int number, const char *prefix, -+ char **buf, size_t *buflen) -+{ -+ for (; syms->name != NULL; syms++) -+ if (number == syms->number) -+ { -+ T (addstr (" ", 1, buf, buflen)); -+ return addstr (syms->name, strlen (syms->name), buf, buflen); -+ } -+ char tmp[20]; -+ int len = snprintf (tmp, sizeof (tmp), " %s%d", prefix, number); -+ return addstr (tmp, len, buf, buflen); -+} -+ - /*% - * Convert the fields of an RR into presentation format. - * -@@ -128,11 +146,21 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - /* - * TTL, Class, Type. - */ -- T(x = ns_format_ttl(ttl, buf, buflen)); -- addlen(x, &buf, &buflen); -- len = SPRINTF((tmp, " %s %s", p_class(class), p_type(type))); -- T(addstr(tmp, len, &buf, &buflen)); -- T(spaced = addtab(x + len, 16, spaced, &buf, &buflen)); -+ { -+ char *start = buf; -+ -+ T (x = ns_format_ttl (ttl, buf, buflen)); -+ addlen (x, &buf, &buflen); -+ T (addsym (__p_class_syms, class, "CLASS", &buf, &buflen)); -+ if (type == ns_t_a6) -+ /* A6 is not part of __p_type_syms, which is exported. -+ Adding A6 there would change its size. Handle it here. */ -+ T (addstr (" A6", 3, &buf, &buflen)); -+ else -+ T (addsym (__p_type_syms, type, "TYPE", &buf, &buflen)); -+ -+ T (spaced = addtab(buf - start, 16, spaced, &buf, &buflen)); -+ } - - /* - * RData. - -commit 509d819cea20f5d6c615eed1f869cc930effd9d2 -Author: Florian Weimer -Date: Fri Jun 19 18:22:20 2026 +0200 - - resolv: Improve formatting of unknown records in ns_sprintrrf - - Do not add the "unknown RR type" comment. After adding the TYPE - prefix, the number is largely redundant. - - Reviewed-by: Carlos O'Donell - Reviewed-by: Adhemerval Zanella - (cherry picked from commit d58415eb17d457a160af99f9e8ab164404ca151b) - -diff --git a/resolv/ns_print.c b/resolv/ns_print.c -index e75c39eaa8..3d38876483 100644 ---- a/resolv/ns_print.c -+++ b/resolv/ns_print.c -@@ -115,7 +115,6 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - - const char *comment; - char tmp[100]; -- char errbuf[40]; - int len, x; - - /* -@@ -590,20 +589,18 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - T(addstr(tmp, len, &buf, &buflen)); - break; - } -- - default: -- snprintf (errbuf, sizeof (errbuf), "unknown RR type %d", type); -- comment = errbuf; -+ comment = ""; - goto hexify; - } - return (buf - obuf); - formerr: -- comment = "RR format error"; -+ comment = " ; RR format error"; - hexify: { - int n, m; - char *p; - -- len = SPRINTF((tmp, "\\# %u%s\t; %s", (unsigned)(edata - rdata), -+ len = SPRINTF((tmp, "\\# %u%s%s", (unsigned)(edata - rdata), - rdlen != 0U ? " (" : "", comment)); - T(addstr(tmp, len, &buf, &buflen)); - while (rdata < edata) { - -commit 05dc6da0b4e12dbc60d3705e4961b823d3f7026d -Author: Florian Weimer -Date: Fri Jun 19 18:22:20 2026 +0200 - - resolv: Check for inet_ntop failure in ns_sprintrrf - - This makes the output more consistent (either failure or complete - output) and helps with systematic testing with varying buffer - sizes. - - Reviewed-by: Carlos O'Donell - Reviewed-by: Adhemerval Zanella - (cherry picked from commit cd0db208d56a2cecd528b8ae96df752ba5344d9a) - -diff --git a/resolv/ns_print.c b/resolv/ns_print.c -index 3d38876483..e58df5f35a 100644 ---- a/resolv/ns_print.c -+++ b/resolv/ns_print.c -@@ -167,8 +167,9 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - switch (type) { - case ns_t_a: - if (rdlen != (size_t)NS_INADDRSZ) -- goto formerr; -- (void) inet_ntop(AF_INET, rdata, buf, buflen); -+ goto formerr; -+ if (inet_ntop (AF_INET, rdata, buf, buflen) == NULL) -+ return -1; - addlen(strlen(buf), &buf, &buflen); - break; - -@@ -334,9 +335,10 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - } - - case ns_t_aaaa: -- if (rdlen != (size_t)NS_IN6ADDRSZ) -- goto formerr; -- (void) inet_ntop(AF_INET6, rdata, buf, buflen); -+ if (rdlen != (size_t)NS_IN6ADDRSZ) -+ goto formerr; -+ if (inet_ntop (AF_INET6, rdata, buf, buflen) == NULL) -+ return -1; - addlen(strlen(buf), &buf, &buflen); - break; - -@@ -427,7 +429,8 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - goto formerr; - - /* Address. */ -- (void) inet_ntop(AF_INET, rdata, buf, buflen); -+ if (inet_ntop (AF_INET, rdata, buf, buflen) == NULL) -+ return -1; - addlen(strlen(buf), &buf, &buflen); - rdata += NS_INADDRSZ; - -@@ -569,7 +572,8 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - if (rdata + pbyte >= edata) goto formerr; - memset(&a, 0, sizeof(a)); - memcpy(&a.s6_addr[pbyte], rdata, sizeof(a) - pbyte); -- (void) inet_ntop(AF_INET6, &a, buf, buflen); -+ if (inet_ntop (AF_INET6, &a, buf, buflen) == NULL) -+ return -1; - addlen(strlen(buf), &buf, &buflen); - rdata += sizeof(a) - pbyte; - } - -commit 299e1d25c32c5f9ef78ddd6cbfd0c6a09a1f4227 -Author: Florian Weimer -Date: Fri Jun 19 18:22:20 2026 +0200 - - resolv: More types as unknown in ns_sprintrrf (CVE-2026-5435) - - Specifically, CERT, TKEY, TSIG, OPT. This removes the buggy - implementations of TSIG, fixing bug 34033, and partially - fixing bug 34069. - - Reviewed-by: Carlos O'Donell - Reviewed-by: Adhemerval Zanella - (cherry picked from commit ca44a6609c29a683b03575fa035c6d17aa591e72) - -diff --git a/resolv/ns_print.c b/resolv/ns_print.c -index e58df5f35a..ab68bf2cb7 100644 ---- a/resolv/ns_print.c -+++ b/resolv/ns_print.c -@@ -464,96 +464,6 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - break; - } - -- case ns_t_cert: { -- u_int c_type, key_tag, alg; -- int n; -- unsigned int siz; -- char base64_cert[8192], tmp[40]; -- const char *leader; -- -- c_type = ns_get16(rdata); rdata += NS_INT16SZ; -- key_tag = ns_get16(rdata); rdata += NS_INT16SZ; -- alg = (u_int) *rdata++; -- -- len = SPRINTF((tmp, "%d %d %d ", c_type, key_tag, alg)); -- T(addstr(tmp, len, &buf, &buflen)); -- siz = (edata-rdata)*4/3 + 4; /* "+4" accounts for trailing \0 */ -- if (siz > sizeof(base64_cert) * 3/4) { -- const char *str = "record too long to print"; -- T(addstr(str, strlen(str), &buf, &buflen)); -- } -- else { -- len = b64_ntop(rdata, edata-rdata, base64_cert, siz); -- -- if (len < 0) -- goto formerr; -- else if (len > 15) { -- T(addstr(" (", 2, &buf, &buflen)); -- leader = "\n\t\t"; -- spaced = 0; -- } -- else -- leader = " "; -- -- for (n = 0; n < len; n += 48) { -- T(addstr(leader, strlen(leader), -- &buf, &buflen)); -- T(addstr(base64_cert + n, MIN(len - n, 48), -- &buf, &buflen)); -- } -- if (len > 15) -- T(addstr(" )", 2, &buf, &buflen)); -- } -- break; -- } -- -- case ns_t_tkey: { -- /* KJD - need to complete this */ -- u_long t; -- int mode, err, keysize; -- -- /* Algorithm name. */ -- T(addname(msg, msglen, &rdata, origin, &buf, &buflen)); -- T(addstr(" ", 1, &buf, &buflen)); -- -- /* Inception. */ -- t = ns_get32(rdata); rdata += NS_INT32SZ; -- len = SPRINTF((tmp, "%lu ", t)); -- T(addstr(tmp, len, &buf, &buflen)); -- -- /* Expiration. */ -- t = ns_get32(rdata); rdata += NS_INT32SZ; -- len = SPRINTF((tmp, "%lu ", t)); -- T(addstr(tmp, len, &buf, &buflen)); -- -- /* Mode , Error, Key Size. */ -- /* Priority, Weight, Port. */ -- mode = ns_get16(rdata); rdata += NS_INT16SZ; -- err = ns_get16(rdata); rdata += NS_INT16SZ; -- keysize = ns_get16(rdata); rdata += NS_INT16SZ; -- len = SPRINTF((tmp, "%u %u %u ", mode, err, keysize)); -- T(addstr(tmp, len, &buf, &buflen)); -- -- /* XXX need to dump key, print otherdata length & other data */ -- break; -- } -- -- case ns_t_tsig: { -- /* BEW - need to complete this */ -- int n; -- -- T(len = addname(msg, msglen, &rdata, origin, &buf, &buflen)); -- T(addstr(" ", 1, &buf, &buflen)); -- rdata += 8; /*%< time */ -- n = ns_get16(rdata); rdata += INT16SZ; -- rdata += n; /*%< sig */ -- n = ns_get16(rdata); rdata += INT16SZ; /*%< original id */ -- sprintf(buf, "%d", ns_get16(rdata)); -- rdata += INT16SZ; -- addlen(strlen(buf), &buf, &buflen); -- break; -- } -- - case ns_t_a6: { - struct in6_addr a; - int pbyte, pbit; -@@ -588,11 +498,6 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - break; - } - -- case ns_t_opt: { -- len = SPRINTF((tmp, "%u bytes", class)); -- T(addstr(tmp, len, &buf, &buflen)); -- break; -- } - default: - comment = ""; - goto hexify; - -commit cb4c62448047c043981deea84e5e01eccf8b36d4 -Author: Florian Weimer -Date: Fri Jun 19 18:22:20 2026 +0200 - - resolv: Fix buffer overreads in ns_sprintrrf (CVE-2026-6238) - - Check that the RDATA payload does not require more than RDATALEN - bytes while processing it. The fixes cover A6, LOC records. - (CERT, TKEY, TSIG were fixed before, by switching to the generic - formatter.) - - The vulnerable LOC record handling was first introduced before - glibc 2.0, in commit ee188d555b8c32ad9704a7440cab400af967292f. - - CERT, TSIG, TKEY handling came with commit - b43b13ac2544b11f35be301d1589b51a8473e32b, released with glibc 2.2. - - A6 record handling was introduced in commit - 91633816430e7ec5a19fe3ff510a7c4822a9557e ("* resolv/ns_print.c - (ns_sprintrrf): Handle ns_t_a6 and ns_t_opt."), which went into glibc - 2.7. - - This fixes bug 34069. - - Reviewed-by: Carlos O'Donell - Reviewed-by: Adhemerval Zanella - (cherry picked from commit a7b60d23bbb56eaef59f4962e4140062e552600a) - -diff --git a/resolv/ns_print.c b/resolv/ns_print.c -index ab68bf2cb7..f9dd086804 100644 ---- a/resolv/ns_print.c -+++ b/resolv/ns_print.c -@@ -345,7 +345,8 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - case ns_t_loc: { - char t[255]; - -- /* XXX protocol format checking? */ -+ if (rdlen != 16) -+ goto formerr; - (void) loc_ntoa(rdata, t); - T(addstr(t, strlen(t), &buf, &buflen)); - break; -@@ -479,13 +480,14 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - - /* address suffix: provided only when prefix len != 128 */ - if (pbit < 128) { -- if (rdata + pbyte >= edata) goto formerr; -+ unsigned int bytelen = sizeof(a) - pbyte; -+ if (edata - rdata < bytelen) goto formerr; - memset(&a, 0, sizeof(a)); -- memcpy(&a.s6_addr[pbyte], rdata, sizeof(a) - pbyte); -+ memcpy(&a.s6_addr[pbyte], rdata, bytelen); - if (inet_ntop (AF_INET6, &a, buf, buflen) == NULL) - return -1; - addlen(strlen(buf), &buf, &buflen); -- rdata += sizeof(a) - pbyte; -+ rdata += bytelen; - } - - /* prefix name: provided only when prefix len > 0 */ - -commit 296fb7f4a2b35db13efef52609f8efc00291b2a8 -Author: Florian Weimer -Date: Fri Jun 19 18:22:20 2026 +0200 - - resolv: Add test case tst-ns_sprintrr (bug 34033, bug 34069) - - This test case covers both input buffer overreads and output buffer - overflows. It should systematically cover these issues. - - I used code auto-generation for updating the test expectations for - truncated RDATA in TXT, ISDN records, after writing the rest - of the test by hand. - - Assisted-by: LLM - Reviewed-by: Carlos O'Donell - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 4ba0b79b9596e5a4951cc9eaa1546a55e543e083) - -diff --git a/resolv/Makefile b/resolv/Makefile -index 088a22ea18..c6d73b411c 100644 ---- a/resolv/Makefile -+++ b/resolv/Makefile -@@ -98,6 +98,7 @@ tests += \ - tst-ns_name \ - tst-ns_name_compress \ - tst-ns_name_pton \ -+ tst-ns_sprintrr \ - tst-res_hconf_reorder \ - tst-res_hnok \ - tst-resolv-aliases \ -@@ -331,5 +332,6 @@ $(objpfx)tst-ns_name: $(objpfx)libresolv.so - $(objpfx)tst-ns_name.out: tst-ns_name.data - $(objpfx)tst-ns_name_compress: $(objpfx)libresolv.so - $(objpfx)tst-ns_name_pton: $(objpfx)libresolv.so -+$(objpfx)tst-ns_sprintrr: $(objpfx)libresolv.so - $(objpfx)tst-res_hnok: $(objpfx)libresolv.so - $(objpfx)tst-p_secstodate: $(objpfx)libresolv.so -diff --git a/resolv/tst-ns_sprintrr.c b/resolv/tst-ns_sprintrr.c -new file mode 100644 -index 0000000000..34739b5924 ---- /dev/null -+++ b/resolv/tst-ns_sprintrr.c -@@ -0,0 +1,329 @@ -+/* Tests for the ns_sprintrr function. -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+ -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+ -+#include -+ -+/* Regions that test_one_record uses for input and output. */ -+static struct support_next_to_fault ntf_in; -+static struct support_next_to_fault ntf_out; -+ -+/* This is used by test_one_record to construct the packet. */ -+static const char packet_prefix[] = -+ /* DNS response with one question, one answer record. */ -+ "AA\x81\x80\0\1\0\1\0\0\0\0" -+ /* Question: www.example.org/IN/ANY. */ -+ "\3www\7example\3org\0\0\xff\0\1" -+ /* Response: compression reference. */ -+ "\xc0\x0c"; -+ -+/* Use ns_sprintrr to format a DNS record (starting with -+ packet_prefix) of type RTYPE, with a record payload of RDATALEN -+ bytes starting at RDATA. Check successful formatting against -+ EXPECTED. Try various truncated input and output buffers to catch -+ overreads and buffer overflows, using ntf_in and ntf_out above. */ -+static void -+test_one_record (uint16_t rtype, const char *rdata, size_t rdatalen, -+ const char *expected) -+{ -+ struct rr_header -+ { -+ uint16_t typ; -+ uint16_t cls; -+ uint32_t ttl; -+ uint16_t rdatalen; -+ uint16_t pad; -+ } hdr = -+ { -+ .typ = htons (rtype), -+ .cls = htons (ns_c_in), -+ .ttl = htonl (86400), /* One day. */ -+ .rdatalen = htons (rdatalen), -+ }; -+ enum { hdrlen = offsetof (struct rr_header, pad) }; -+ TEST_COMPARE (hdrlen, 10); -+ -+ /* Construct the packet from packet_prefix, hdr, and rdata. */ -+ unsigned char packet[512]; -+ size_t packetlen; -+ { -+ struct alloc_buffer buf = alloc_buffer_create (packet, sizeof (packet)); -+ alloc_buffer_copy_bytes (&buf, packet_prefix, sizeof (packet_prefix) - 1); -+ alloc_buffer_copy_bytes (&buf, &hdr, hdrlen); -+ alloc_buffer_copy_bytes (&buf, rdata, rdatalen); -+ packetlen = sizeof (packet) - alloc_buffer_size (&buf); -+ } -+ -+ /* Parse the record. */ -+ ns_msg msg; -+ TEST_COMPARE (ns_initparse (packet, packetlen, &msg), 0); -+ ns_rr rr; -+ TEST_COMPARE (ns_parserr (&msg, ns_s_an, 0, &rr), 0); -+ -+ /* Try sizes up to this limit. Go a bit beyond the expected size to -+ check for errors. */ -+ size_t max_result_size = strlen (expected) + 16; -+ -+ bool success = false; -+ for (size_t result_size = 1; result_size <= max_result_size; ++result_size) -+ { -+ char *result_start = ntf_out.buffer + ntf_out.length - result_size; -+ memset (result_start, 'X', result_size); -+ -+ /* ns_sprintrr was deprecated in 2.34. */ -+ DIAG_PUSH_NEEDS_COMMENT; -+ DIAG_IGNORE_NEEDS_COMMENT (4.9, "-Wdeprecated-declarations"); -+ int ret = ns_sprintrr (&msg, &rr, NULL, NULL, result_start, result_size); -+ DIAG_POP_NEEDS_COMMENT; -+ -+ if (ret > 0) -+ { -+ TEST_COMPARE_STRING (result_start, expected); -+ TEST_COMPARE (ret, strlen (expected)); -+ success = true; -+ } -+ else -+ { -+ TEST_VERIFY (!success); -+ TEST_COMPARE (ret, -1); -+ } -+ } -+ TEST_VERIFY (success); -+ -+ /* Test with truncated RDATA. */ -+ for (size_t rdata_size = 0; rdata_size <= rdatalen; ++rdata_size) -+ { -+ size_t truncated_packet_size = packetlen - rdatalen + rdata_size; -+ unsigned char *packet_start -+ = ((unsigned char *) ntf_in.buffer + ntf_in.length -+ - truncated_packet_size); -+ memcpy (packet_start, packet, truncated_packet_size); -+ /* Patch in the updated RDATA length field. */ -+ uint16_t new_rdatalen = htons (rdata_size); -+ memcpy (packet_start + truncated_packet_size - rdata_size - 2, -+ &new_rdatalen, 2); -+ -+ ns_msg msg; -+ TEST_COMPARE (ns_initparse (packet_start, truncated_packet_size, &msg), -+ 0); -+ ns_rr rr; -+ TEST_COMPARE (ns_parserr (&msg, ns_s_an, 0, &rr), 0); -+ -+ size_t result_size = strlen (expected) + 1; -+ char *result_start = ntf_out.buffer + ntf_out.length - result_size; -+ memset (result_start, 'X', result_size); -+ -+ /* ns_sprintrr was deprecated in 2.34. */ -+ DIAG_PUSH_NEEDS_COMMENT; -+ DIAG_IGNORE_NEEDS_COMMENT (4.9, "-Wdeprecated-declarations"); -+ int ret = ns_sprintrr (&msg, &rr, NULL, NULL, result_start, result_size); -+ DIAG_POP_NEEDS_COMMENT; -+ -+ /* This flag indicates whether the output is syntactically -+ correct. In some cases, truncation may still yield a valid -+ payload. */ -+ bool broken = rdata_size < rdatalen; -+ switch (rtype) -+ { -+ case ns_t_wks: -+ /* WKS records use all trailing bytes for the port bitmap. */ -+ broken = rdata_size < 5; -+ break; -+ case ns_t_nsap: -+ /* Uses all bytes that are available. */ -+ broken = false; -+ break; -+ case ns_t_txt: -+ /* Truncation produces a valid payload if it occurs right -+ after a complete string in the TXT payload. */ -+ broken = false; -+ for (size_t pos = 0; pos < rdata_size; ) -+ { -+ unsigned int slen = rdata[pos] & 0xff; -+ if (pos + 1 + slen > rdata_size) -+ { -+ broken = true; -+ break; -+ } -+ pos += 1 + slen; -+ } -+ break; -+ case ns_t_isdn: -+ /* The second field is optional. If it is present, it must -+ not be truncated. */ -+ broken = rdata_size < 6 || (rdata_size > 6 && rdata_size < rdatalen); -+ break; -+ case ns_t_a6: -+ /* The first A6 subtest contains a trailing domain name, -+ which is ignored and not formatted. */ -+ if (rdata_size > 0 && rdata[0] == 0) -+ broken = rdata_size < 17; -+ break; -+ case ns_t_cert: -+ case ns_t_tkey: -+ case ns_t_tsig: -+ /* Only generic printing, which does not validate anything. */ -+ broken = false; -+ break; -+ } -+ -+ if (broken) -+ { -+ if (strstr (result_start, "RR format error") != NULL) -+ /* No further checks if an error indicator has been added -+ to the output. */ -+ ; -+ else -+ TEST_COMPARE (ret, -1); -+ } -+ else -+ TEST_VERIFY (ret > 0); -+ } -+} -+ -+static int -+do_test (void) -+{ -+ ntf_in = support_next_to_fault_allocate (512); -+ ntf_out = support_next_to_fault_allocate (256); -+ -+#define T(rtype, rdata, expected) \ -+ test_one_record (rtype, rdata, sizeof (rdata) - 1, expected) -+ T (ns_t_a, "\xc0\0\2\1", "www.example.org.\t1D IN A\t\t192.0.2.1"); -+ T (ns_t_cname, "\4www1\4prod\xc0\x10", -+ "www.example.org.\t1D IN CNAME\twww1.prod.example.org."); -+ T (ns_t_hinfo, "\5first\6second", -+ "www.example.org.\t1D IN HINFO\t\"first\" \"second\""); -+ T (ns_t_isdn, "\5first\6second", -+ "www.example.org.\t1D IN ISDN\t\"first\" \"second\""); -+ /* Bug: Extra space at the end in the text representation of ISDN RRs. */ -+ T (ns_t_isdn, "\5first", "www.example.org.\t1D IN ISDN\t\"first\" "); -+ T (ns_t_soa, -+ "\2ns\xc0\x10\12hostmaster\xc0\x10" -+ "\0\0\0\1\0\0\0\2\0\0\0\3\0\0\0\4\0\0\0\5", -+ "www.example.org.\t1D IN SOA\tns.example.org. hostmaster.example.org. (\n" -+ "\t\t\t\t\t1\t\t; serial\n" -+ "\t\t\t\t\t2S\t\t; refresh\n" -+ "\t\t\t\t\t3S\t\t; retry\n" -+ "\t\t\t\t\t4S\t\t; expiry\n" -+ "\t\t\t\t\t5S )\t\t; minimum\n"); -+ T (ns_t_mx, "\0\xa\2mx\xc0\x10", -+ "www.example.org.\t1D IN MX\t10 mx.example.org."); -+ T (ns_t_px, "\0\xa\3px1\xc0\x10\3px2\xc0\x10", -+ "www.example.org.\t1D IN PX\t10 px1.example.org. px2.example.org."); -+ T (ns_t_x25, "\4X.25", -+ "www.example.org.\t1D IN X25\t\"X.25\""); -+ T (ns_t_txt, "\1A\2BC\3DEF", -+ "www.example.org.\t1D IN TXT\t\"A\" \"BC\" \"DEF\""); -+ T (ns_t_nsap, "", -+ "www.example.org.\t1D IN NSAP\t"); -+ T (ns_t_nsap, "\1", -+ "www.example.org.\t1D IN NSAP\t01"); -+ T (ns_t_nsap, "\1\2", -+ "www.example.org.\t1D IN NSAP\t01.02"); -+ T (ns_t_nsap, "\1\2\3", -+ "www.example.org.\t1D IN NSAP\t01.0203"); -+ T (ns_t_nsap, "\1\2\3\4", -+ "www.example.org.\t1D IN NSAP\t01.0203.04"); -+ T (ns_t_nsap, -+ "\1\2\3\4\5\6\7\10\11\12\13\14\15\16\17\20\21\22\23\24\25\26\27\30\31\32" -+ "\33\34\35\36\37\40\41\42\43\44\45\46\47\50\51\52\53\54\55\56\57\60\61" -+ "\62\63\64\65\66\67\70\71\72\73\74\75\76\77\100\101\102\103\104\105\106" -+ "\107\110\111\112\113\114\115\116\117\120\121\122\123\124\125\126\127" -+ "\130\131\132\133\134\135\136\137\140\141\142\143\144\145\146\147\150" -+ "\151\152\153\154\155\156\157\160\161\162\163\164\165\166\167\170\171" -+ "\172\173\174\175\176\177\200\201\202\203\204\205\206\207\210\211\212" -+ "\213\214\215\216\217\220\221\222\223\224\225\226\227\230\231\232\233" -+ "\234\235\236\237\240\241\242\243\244\245\246\247\250\251\252\253\254" -+ "\255\256\257\260\261\262\263\264\265\266\267\270\271\272\273\274\275" -+ "\276\277\300\301\302\303\304\305\306\307\310\311\312\313\314\315\316" -+ "\317\320\321\322\323\324\325\326\327\330\331\332\333\334\335\336\337" -+ "\340\341\342\343\344\345\346\347\350\351\352\353\354\355\356\357\360" -+ "\361\362\363\364\365\366\367\370\371\372\373\374\375\376\377", -+ "www.example.org.\t1D IN NSAP\t" -+ "01.0203.0405.0607.0809.0A0B.0C0D.0E0F.1011.1213.1415.1617.1819.1A1B" -+ ".1C1D.1E1F.2021.2223.2425.2627.2829.2A2B.2C2D.2E2F.3031.3233.3435.3637" -+ ".3839.3A3B.3C3D.3E3F.4041.4243.4445.4647.4849.4A4B.4C4D.4E4F.5051.5253" -+ ".5455.5657.5859.5A5B.5C5D.5E5F.6061.6263.6465.6667.6869.6A6B.6C6D.6E6F" -+ ".7071.7273.7475.7677.7879.7A7B.7C7D.7E7F.8081.8283.8485.8687.8889.8A8B" -+ ".8C8D.8E8F.9091.9293.9495.9697.9899.9A9B.9C9D.9E9F.A0A1.A2A3.A4A5.A6A7" -+ ".A8A9.AAAB.ACAD.AEAF.B0B1.B2B3.B4B5.B6B7.B8B9.BABB.BCBD.BEBF.C0C1.C2C3" -+ ".C4C5.C6C7.C8C9.CACB.CCCD.CECF.D0D1.D2D3.D4D5.D6D7.D8D9.DADB.DCDD.DEDF" -+ ".E0E1.E2E3.E4E5.E6E7.E8E9.EAEB.ECED.EEEF.F0F1.F2F3.F4F5.F6F7.F8F9.FAFB" -+ ".FCFD.FEFF"); -+ T (ns_t_aaaa, "\x20\x01\x0d\xb8\0\0\0\0\0\0\0\0\0\0\x12\x34", -+ "www.example.org.\t1D IN AAAA\t2001:db8::1234"); -+ /* Example from RFC 1876. The loc_ntoa format is different from the -+ official text representation. */ -+ T (ns_t_loc, -+ "\000\063\026\023\211\027\055\320\160\276\025\360\000\230\215\040", -+ "www.example.org.\t1D IN LOC" -+ "\t42 21 54.000 N 71 06 18.000 W -24.00m 30.00m 10000.00m 10.00m"); -+ T (ns_t_naptr, -+ "\0\1\0\2\5flags\7service\2.*\5naptr\xc0\x10", -+ "www.example.org.\t1D IN NAPTR\t1 2 \"flags\" \"service\" \".*\"" -+ " naptr.example.org."); -+ T (ns_t_srv, -+ "\0\1\0\2\0\x50\4www1\xc0\x10", -+ "www.example.org.\t1D IN SRV\t1 2 80 www1.example.org."); -+ T (ns_t_rp, "\3rp1\xc0\x10\3rp2\xc0\x10", -+ "www.example.org.\t1D IN RP\trp1.example.org. rp2.example.org."); -+ T (ns_t_wks, "\xc0\0\2\1\6\0\0\0\0\0\0\0\0\0\0\200", -+ "www.example.org.\t1D IN WKS\t192.0.2.1 6 ( \n\t\t\t\t80 )"); -+ T (ns_t_cert, "\0\1\x04\xd2\0blob", -+ "www.example.org.\t1D IN CERT\t\\# 9 (\n" -+ "\t00 01 04 d2 00 62 6c 6f 62 )\t\t\t; .....blob"); -+ T (ns_t_tkey, "\4algo\0\0\0\0\1\0\0\0\2\0\3\0\4" -+ "\0\5\xa1\xa2\xa3\xa4\xa5\0\3\xb1\xb2\xb3", -+ "www.example.org.\t1D IN TYPE249\t\\# 30 (\n" -+ "\t04 61 6c 67 6f 00 00 00 00 01 00 00 00 02 00 03 ; .algo...........\n" -+ "\t00 04 00 05 a1 a2 a3 a4 a5 00 03 b1 b2 b3 )\t; .............."); -+ T (ns_t_tsig, "\4algo\0" -+ "\0\20\xdd\xcd\x64\x10\xe9\x21\x34\x1a\x8e\xe0\xa1\x9a\x30\xfc\x3b\xd1" -+ "\0\2\0\3\0\5other", -+ "www.example.org.\t1D IN TSIG\t\\# 35 (\n" -+ "\t04 61 6c 67 6f 00 00 10 dd cd 64 10 e9 21 34 1a ; .algo.....d..!4.\n" -+ "\t8e e0 a1 9a 30 fc 3b d1 00 02 00 03 00 05 6f 74 ; ....0.;.......ot\n" -+ "\t68 65 72 )\t\t\t\t\t; her"); -+ T (ns_t_a6, -+ "\0\x20\x01\x0d\xb8\0\0\0\0\0\0\0\0\0\0\x12\x34\6prefix\xc0\x10", -+ "www.example.org.\t1D IN A6\t0 2001:db8::1234"); -+ T (ns_t_a6, -+ "\0\x20\x01\x0d\xb8\0\0\0\0\0\0\0\0\0\0\x12\x35", -+ "www.example.org.\t1D IN A6\t0 2001:db8::1235"); -+ T (ns_t_a6, "\200\6prefix\xc0\x10", -+ "www.example.org.\t1D IN A6\t128 prefix.example.org."); -+ T (ns_t_a6, "\x20\0\0\0\0\0\0\0\0\0\0\x12\x36\6prefix\xc0\x10", -+ "www.example.org.\t1D IN A6\t32 ::1236 prefix.example.org."); -+#undef T -+ -+ support_next_to_fault_free (&ntf_in); -+ support_next_to_fault_free (&ntf_out); -+ return 0; -+} -+ -+#include - -commit 7414631f8aec8b9cee1a8311506e1fdcd9b94c0d -Author: Adhemerval Zanella -Date: Tue Apr 14 10:50:37 2026 -0300 - - posix: Fix stack overflow in wordexp tilde expansion (BZ 34091, CVE-2026-6791) - - The parse_tilde function previously used strndupa to allocate memory - for the parsed username on the stack, and since the input is - user-defined, this can lead to a stack overflow. - - This patch fixes the issue by replacing strndupa with scratch_buffer, - by reusing the buffer used in the __getpwnam_r call. - - The new “tst-wordexp-tilde.c” test is a test-container to avoid using - system-defined NSS modules. - - Checked on x86_64-linux-gnu and i686-linux-gnu. - - (cherry picked from commit 07c24f35392b727e6100d33edfdf811a6c68c218) - -diff --git a/posix/Makefile b/posix/Makefile -index 0b29c9aa4e..595c6b3ec2 100644 ---- a/posix/Makefile -+++ b/posix/Makefile -@@ -356,6 +356,7 @@ tests-internal := \ - tests-container := \ - bug-ga2 \ - tst-vfork3 \ -+ tst-wordexp-tilde \ - # tests-container - - tests-time64 := \ -diff --git a/posix/tst-wordexp-tilde.c b/posix/tst-wordexp-tilde.c -new file mode 100644 -index 0000000000..1661603681 ---- /dev/null -+++ b/posix/tst-wordexp-tilde.c -@@ -0,0 +1,244 @@ -+/* Test wordexp tilde expansion with large usernames (BZ 34091). -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+#include -+ -+#include -+#include -+#include -+#include -+ -+typedef void (*func_callback_t)(void); -+ -+static void -+subprocess_small_stack (void *closure) -+{ -+ struct rlimit rl; -+ TEST_COMPARE (getrlimit (RLIMIT_STACK, &rl), 0); -+ rl.rlim_cur = 512 * 1024; -+ TEST_COMPARE (setrlimit (RLIMIT_STACK, &rl), 0); -+ -+ func_callback_t func_test = closure; -+ func_test (); -+} -+ -+/* Build a string "~/tail" where is LEN bytes of the -+ character CH. The caller must free the result. */ -+static char * -+make_tilde_input (char ch, size_t len, const char *tail) -+{ -+ /* ~ + len + / + tail + \0 */ -+ size_t taillen = tail != NULL ? strlen (tail) : 0; -+ size_t total = 1 + len + 1 + taillen + 1; -+ char *buf = xmalloc (total); -+ buf[0] = '~'; -+ memset (buf + 1, ch, len); -+ buf[1 + len] = '/'; -+ if (tail != NULL) -+ memcpy (buf + 1 + len + 1, tail, taillen); -+ buf[total - 1] = '\0'; -+ return buf; -+} -+ -+/* Test 1: A very long username must not crash. The username will not match -+ any real user, so wordexp returns ~/rest. */ -+static void -+test_long_username (void) -+{ -+ printf ("info: test_long_username_no_crash\n"); -+ -+ static const char REST[] = "rest"; -+ -+ /* 1 MiB username — well beyond any reasonable stack frame. */ -+ const size_t long_len = 1024 * 1024; -+ char *input = make_tilde_input ('A', long_len, REST); -+ -+ wordexp_t we = { 0 }; -+ int ret = wordexp (input, &we, 0); -+ /* The (non-existent) username is invalid, so wordexp falls back to -+ literal output: ~AAA…/rest. */ -+ TEST_COMPARE (ret, 0); -+ TEST_COMPARE (we.we_wordc, 1); -+ -+ /* Verify prefix: '~' followed by long_len 'A's. */ -+ const char *result = we.we_wordv[0]; -+ TEST_COMPARE (result[0], '~'); -+ TEST_COMPARE (strlen (result), -+ 1 /* ~ */ + long_len + sizeof (REST)); -+ for (size_t j = 1; j <= long_len; j++) -+ if (result[j] != 'A') -+ { -+ printf (" mismatch at position %zu: expected 'A', got '%c'\n", -+ j, result[j]); -+ support_record_failure (); -+ break; -+ } -+ /* Verify the tail after the username. */ -+ TEST_COMPARE_STRING (result + 1 + long_len, "/rest"); -+ -+ wordfree (&we); -+ free (input); -+} -+ -+/* Test 2: A username that just exceeds the default scratch_buffer inline -+ size (1024 bytes) exercises the scratch_buffer_set_array_size growth path -+ without being excessively large. */ -+static void -+test_scratch_buffer_growth (void) -+{ -+ printf ("info: test_scratch_buffer_growth\n"); -+ -+ const size_t len = 2048; -+ char *input = make_tilde_input ('x', len, NULL); -+ -+ wordexp_t we = { 0 }; -+ int ret = wordexp (input, &we, 0); -+ TEST_COMPARE (ret, 0); -+ TEST_COMPARE (we.we_wordc, 1); -+ -+ /* ~xxx…/ — the trailing slash makes a separate empty component, but -+ wordexp merges it into the single token ~xxx…/. */ -+ const char *result = we.we_wordv[0]; -+ TEST_COMPARE (result[0], '~'); -+ for (size_t j = 1; j <= len; j++) -+ if (result[j] != 'x') -+ { -+ printf (" mismatch at position %zu\n", j); -+ support_record_failure (); -+ break; -+ } -+ TEST_COMPARE (result[1 + len], '/'); -+ -+ wordfree (&we); -+ free (input); -+} -+ -+/* Test 3: ~root still resolves to the correct home directory through the -+ __getpwnam_r path. */ -+static void -+test_known_user (void) -+{ -+ printf ("info: test_known_user\n"); -+ -+ /* Look up root's home directory for comparison. */ -+ struct passwd *pw = getpwnam ("root"); -+ if (pw == NULL || pw->pw_dir == NULL) -+ { -+ printf (" SKIP: cannot look up root\n"); -+ return; -+ } -+ -+ char *expected = xasprintf ("%s/file", pw->pw_dir); -+ -+ wordexp_t we = { 0 }; -+ TEST_COMPARE (wordexp ("~root/file", &we, 0), 0); -+ TEST_COMPARE (we.we_wordc, 1); -+ TEST_COMPARE_STRING (we.we_wordv[0], expected); -+ -+ wordfree (&we); -+ free (expected); -+} -+ -+/* Test 4: Bare tilde expands to $HOME. */ -+static void -+test_bare_tilde (void) -+{ -+ printf ("info: test_bare_tilde\n"); -+ -+ const char *home = getenv ("HOME"); -+ if (home == NULL) -+ { -+ printf (" SKIP: HOME is not set\n"); -+ return; -+ } -+ -+ wordexp_t we = { 0 }; -+ TEST_COMPARE (wordexp ("~", &we, 0), 0); -+ TEST_COMPARE (we.we_wordc, 1); -+ TEST_COMPARE_STRING (we.we_wordv[0], home); -+ -+ wordfree (&we); -+} -+ -+/* Test 5: Short non-existent username falls back to literal ~username output, -+ exercising the invalid-login-name path. */ -+static void -+test_unknown_user (void) -+{ -+ printf ("info: test_unknown_user\n"); -+ -+ /* Pick a username that is extremely unlikely to exist. */ -+ wordexp_t we = { 0 }; -+ TEST_COMPARE (wordexp ("~no_such_user_xyzzy42", &we, 0), 0); -+ TEST_COMPARE (we.we_wordc, 1); -+ TEST_COMPARE_STRING (we.we_wordv[0], "~no_such_user_xyzzy42"); -+ -+ wordfree (&we); -+} -+ -+/* Test 6: Tilde with username and WRDE_APPEND — exercises parse_tilde's -+ interaction with the WRDE_APPEND word list. */ -+static void -+test_tilde_with_append (void) -+{ -+ printf ("info: test_tilde_with_append\n"); -+ -+ const char *home = getenv ("HOME"); -+ if (home == NULL) -+ { -+ printf (" SKIP: HOME is not set\n"); -+ return; -+ } -+ -+ wordexp_t we = { 0 }; -+ TEST_COMPARE (wordexp ("first", &we, 0), 0); -+ -+ TEST_COMPARE (wordexp ("~/path", &we, WRDE_APPEND), 0); -+ TEST_COMPARE (we.we_wordc, 2); -+ TEST_COMPARE_STRING (we.we_wordv[0], "first"); -+ -+ char *expected = xasprintf ("%s/path", home); -+ TEST_COMPARE_STRING (we.we_wordv[1], expected); -+ -+ wordfree (&we); -+ free (expected); -+} -+ -+static int -+do_test (void) -+{ -+ test_known_user (); -+ test_bare_tilde (); -+ test_unknown_user (); -+ test_tilde_with_append (); -+ -+ support_isolate_in_subprocess (subprocess_small_stack, -+ test_long_username); -+ -+ support_isolate_in_subprocess (subprocess_small_stack, -+ test_scratch_buffer_growth); -+ -+ return 0; -+} -+ -+#include -diff --git a/posix/tst-wordexp-tilde.root/etc/group b/posix/tst-wordexp-tilde.root/etc/group -new file mode 100644 -index 0000000000..1dbf9013ee ---- /dev/null -+++ b/posix/tst-wordexp-tilde.root/etc/group -@@ -0,0 +1 @@ -+root:x:0: -diff --git a/posix/tst-wordexp-tilde.root/etc/nsswitch.conf b/posix/tst-wordexp-tilde.root/etc/nsswitch.conf -new file mode 100644 -index 0000000000..098a8d5938 ---- /dev/null -+++ b/posix/tst-wordexp-tilde.root/etc/nsswitch.conf -@@ -0,0 +1,3 @@ -+passwd: files -+group: files -+shadow: files -diff --git a/posix/tst-wordexp-tilde.root/etc/passwd b/posix/tst-wordexp-tilde.root/etc/passwd -new file mode 100644 -index 0000000000..eb85a552ad ---- /dev/null -+++ b/posix/tst-wordexp-tilde.root/etc/passwd -@@ -0,0 +1 @@ -+root:x:0:0:root:/root:/bin/sh -diff --git a/posix/wordexp.c b/posix/wordexp.c -index 9df4bb7424..731d1650e9 100644 ---- a/posix/wordexp.c -+++ b/posix/wordexp.c -@@ -335,17 +335,29 @@ parse_tilde (char **word, size_t *word_length, size_t *max_length, - else - { - /* Look up user name in database to get home directory */ -- char *user = strndupa (&words[1 + *offset], i - (1 + *offset)); -- struct passwd pwd, *tpwd; -- int result; -+ size_t userlen = i - (1 + *offset); -+ /* tmpbuf contains both the user and the __getpwnam_r working area. */ - struct scratch_buffer tmpbuf; - scratch_buffer_init (&tmpbuf); -+ if (!scratch_buffer_set_array_size (&tmpbuf, userlen + 1, 1)) -+ return WRDE_NOSPACE; -+ char *user = tmpbuf.data; -+ memcpy (user, &words[1 + *offset], userlen); -+ user[userlen] = '\0'; - -- while ((result = __getpwnam_r (user, &pwd, tmpbuf.data, tmpbuf.length, -+ struct passwd pwd, *tpwd; -+ int result; -+ while ((result = __getpwnam_r (user, -+ &pwd, -+ tmpbuf.data + userlen + 1, -+ tmpbuf.length - userlen - 1, - &tpwd)) != 0 - && errno == ERANGE) -- if (!scratch_buffer_grow (&tmpbuf)) -- return WRDE_NOSPACE; -+ { -+ if (!scratch_buffer_grow_preserve (&tmpbuf)) -+ return WRDE_NOSPACE; -+ user = tmpbuf.data; -+ } - - if (result == 0 && tpwd != NULL && pwd.pw_dir) - *word = w_addstr (*word, word_length, max_length, pwd.pw_dir); - -commit 8be3551ccb4e17e93ad82152de56d2c90de21f97 -Author: Adhemerval Zanella -Date: Mon Apr 13 16:33:30 2026 -0300 - - posix: Fix wordexp WRDE_APPEND to preserve state on non-NOSPACE errors (BZ 34090, CVE-2026-6368) - - The previous implementation saved a copy of the wordexp_t struct at - entry and blindly restored it on error via (*pwordexp = old_word). - This is incorrect when WRDE_APPEND is set because w_addword may have - called realloc on we_wordv during partial processing before the error - was detected. If realloc relocated the buffer, the saved we_wordv - pointer is dangling; restoring it causes a use-after-free in the - caller (e.g. via wordfree), and the relocated buffer is leaked. - - Fix this by duplicating the we_wordv pointer array at entry when - WRDE_APPEND is set, so that all subsequent realloc calls inside - w_addword operate on the copy. - - This change also fixes a POSIX conformance issue: if the WRDE_APPEND - flag is specified, pwordexp->we_wordc and pwordexp->we_wordv shall - not be modified. - - Also fix two pre-existing error return paths in the '"' and '\'' cases - that returned directly from w_addword failures instead of going through - do_error, which would leak the saved array (and previously would also - skip the word cleanup). - - Checked on x86_64-linux-gnu and i686-linux-gnu. - - Reviewed-by: DJ Delorie - (cherry picked from commit e2cefe16c37a617df9f11407cb00a272a6098823) - -diff --git a/posix/Makefile b/posix/Makefile -index 595c6b3ec2..a12c49c0ed 100644 ---- a/posix/Makefile -+++ b/posix/Makefile -@@ -326,6 +326,7 @@ tests := \ - tst-wait3 \ - tst-wait4 \ - tst-waitid \ -+ tst-wordexp-append \ - tst-wordexp-nocmd \ - tst-wordexp-reuse \ - tstgetopt \ -diff --git a/posix/tst-wordexp-append.c b/posix/tst-wordexp-append.c -new file mode 100644 -index 0000000000..87f388f0a7 ---- /dev/null -+++ b/posix/tst-wordexp-append.c -@@ -0,0 +1,393 @@ -+/* Test for wordexp with WRDE_APPEND flag. -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+ -+#include -+#include -+ -+static unsigned int relocating_reallocs; -+ -+/* w_addword grows we_wordv with realloc, make every call guaranteed to -+ relocate the block. This makes BZ 34090 regression more deterministic. */ -+void * -+realloc (void *ptr, size_t size) -+{ -+ if (ptr == NULL) -+ return malloc (size); -+ if (size == 0) -+ { -+ free (ptr); -+ return NULL; -+ } -+ -+ void *new = malloc (size); -+ if (new == NULL) -+ return NULL; -+ -+ /* Copy only what is valid in the old block to avoid reading past it. */ -+ size_t old = malloc_usable_size (ptr); -+ memcpy (new, ptr, old < size ? old : size); -+ /* Clobber the old block so that a stale we_wordv pointer restored on the -+ error path reads garbage instead of the old contents, which might -+ otherwise survive intact and mask the bug. */ -+ memset (ptr, 0x5a, old); -+ free (ptr); -+ relocating_reallocs++; -+ return new; -+} -+ -+/* Verify that all words in we match the expected NULL-terminated -+ array. */ -+static void -+check_words (const wordexp_t *we, const char *const *expected) -+{ -+ size_t i; -+ for (i = 0; expected[i] != NULL; i++) -+ { -+ TEST_VERIFY (i < we->we_wordc); -+ TEST_COMPARE_STRING (we->we_wordv[we->we_offs + i], expected[i]); -+ } -+ TEST_COMPARE (we->we_wordc, i); -+} -+ -+#define CHECK_WORDS(we, ...) \ -+ do { \ -+ const char *const expected_[] = { __VA_ARGS__, NULL }; \ -+ check_words (we, expected_); \ -+ } while (0) -+ -+/* Test 1: WRDE_APPEND + WRDE_BADCHAR preserves we_wordc. */ -+static void -+test_append_badchar_preserves_count (void) -+{ -+ printf ("info: test_append_badchar_preserves_count\n"); -+ wordexp_t we = { 0 }; -+ -+ TEST_COMPARE (wordexp ("one two three", &we, 0), 0); -+ TEST_COMPARE (we.we_wordc, 3); -+ -+ size_t saved_count = we.we_wordc; -+ -+ /* ')' triggers WRDE_BADCHAR and "extra" would be a new word if the -+ expansion succeeded, exercising the w_addword path before the error -+ is detected. */ -+ TEST_COMPARE (wordexp ("extra )", &we, WRDE_APPEND), WRDE_BADCHAR); -+ TEST_COMPARE (we.we_wordc, saved_count); -+ -+ wordfree (&we); -+} -+ -+/* Test 2: WRDE_APPEND + WRDE_BADCHAR preserves the we_wordv pointer even -+ when internal realloc would move the buffer. */ -+static void -+test_append_badchar_preserves_pointer (void) -+{ -+ printf ("info: test_append_badchar_preserves_pointer\n"); -+ wordexp_t we = { 0 }; -+ -+ /* Use many words so that the initial we_wordv allocation is -+ non-trivial and a later realloc is more likely to move it. */ -+ TEST_COMPARE (wordexp ("a b c d e f g h", &we, 0), 0); -+ TEST_COMPARE (we.we_wordc, 8); -+ -+ char **saved_wordv = we.we_wordv; -+ size_t saved_count = we.we_wordc; -+ unsigned int saved_reallocs = relocating_reallocs; -+ -+ /* The interposed realloc guarantees the internal we_wordv buffer moves -+ during parsing, so the pointer-stability check below is meaningful. */ -+ TEST_COMPARE (wordexp ("append )", &we, WRDE_APPEND), WRDE_BADCHAR); -+ /* Verify that a relocating realloc actually happened during the failed -+ call, otherwise the pointer-stability check is vacuous. */ -+ TEST_VERIFY (relocating_reallocs > saved_reallocs); -+ TEST_COMPARE (we.we_wordc, saved_count); -+ TEST_VERIFY (we.we_wordv == saved_wordv); -+ -+ wordfree (&we); -+} -+ -+/* Test 3: After a failed WRDE_APPEND the original words are still accessible -+ and correct. */ -+static void -+test_append_badchar_words_intact (void) -+{ -+ printf ("info: test_append_badchar_words_intact\n"); -+ wordexp_t we = { 0 }; -+ -+ TEST_COMPARE (wordexp ("alpha beta gamma", &we, 0), 0); -+ CHECK_WORDS (&we, "alpha", "beta", "gamma"); -+ -+ TEST_COMPARE (wordexp ("delta )", &we, WRDE_APPEND), WRDE_BADCHAR); -+ -+ /* Words must still be intact. */ -+ CHECK_WORDS (&we, "alpha", "beta", "gamma"); -+ /* The NULL terminator must still be present. */ -+ TEST_VERIFY (we.we_wordv[we.we_offs + we.we_wordc] == NULL); -+ -+ wordfree (&we); -+} -+ -+/* Test 4: Successful WRDE_APPEND still works (regression test). */ -+static void -+test_append_success (void) -+{ -+ printf ("info: test_append_success\n"); -+ wordexp_t we = { 0 }; -+ -+ TEST_COMPARE (wordexp ("hello", &we, 0), 0); -+ TEST_COMPARE (we.we_wordc, 1); -+ -+ char **saved_wordv = we.we_wordv; -+ -+ TEST_COMPARE (wordexp ("world", &we, WRDE_APPEND), 0); -+ TEST_COMPARE (we.we_wordc, 2); -+ /* A successful append works on a fresh copy of the array, so the -+ caller-visible pointer must have changed. */ -+ TEST_VERIFY (we.we_wordv != saved_wordv); -+ CHECK_WORDS (&we, "hello", "world"); -+ -+ wordfree (&we); -+} -+ -+/* Test 5: Successful append after a failed append — the implementation must -+ recover and allow further use of the wordexp_t. */ -+static void -+test_append_success_after_failure (void) -+{ -+ printf ("info: test_append_success_after_failure\n"); -+ wordexp_t we = { 0 }; -+ -+ TEST_COMPARE (wordexp ("first", &we, 0), 0); -+ CHECK_WORDS (&we, "first"); -+ -+ TEST_COMPARE (wordexp ("bad |", &we, WRDE_APPEND), WRDE_BADCHAR); -+ -+ /* State must be exactly as before the failed call. */ -+ CHECK_WORDS (&we, "first"); -+ -+ /* A subsequent successful append must work. */ -+ TEST_COMPARE (wordexp ("second third", &we, WRDE_APPEND), 0); -+ CHECK_WORDS (&we, "first", "second", "third"); -+ -+ wordfree (&we); -+} -+ -+/* Test 6: Multiple consecutive failed appends do not corrupt state. */ -+static void -+test_append_multiple_failures (void) -+{ -+ printf ("info: test_append_multiple_failures\n"); -+ wordexp_t we = { 0 }; -+ -+ TEST_COMPARE (wordexp ("keep this", &we, 0), 0); -+ CHECK_WORDS (&we, "keep", "this"); -+ -+ size_t saved_count = we.we_wordc; -+ char **saved_wordv = we.we_wordv; -+ -+ /* Each of these bad characters must leave the state unchanged. */ -+ TEST_COMPARE (wordexp ("x )", &we, WRDE_APPEND), WRDE_BADCHAR); -+ TEST_COMPARE (wordexp ("x |", &we, WRDE_APPEND), WRDE_BADCHAR); -+ TEST_COMPARE (wordexp ("x ;", &we, WRDE_APPEND), WRDE_BADCHAR); -+ TEST_COMPARE (wordexp ("x &", &we, WRDE_APPEND), WRDE_BADCHAR); -+ TEST_COMPARE (wordexp ("x <", &we, WRDE_APPEND), WRDE_BADCHAR); -+ TEST_COMPARE (wordexp ("x >", &we, WRDE_APPEND), WRDE_BADCHAR); -+ -+ TEST_COMPARE (we.we_wordc, saved_count); -+ TEST_VERIFY (we.we_wordv == saved_wordv); -+ CHECK_WORDS (&we, "keep", "this"); -+ -+ wordfree (&we); -+} -+ -+/* Test 7: WRDE_APPEND with WRDE_SYNTAX error (unterminated quote) also -+ preserves state. */ -+static void -+test_append_syntax_error (void) -+{ -+ printf ("info: test_append_syntax_error\n"); -+ wordexp_t we = { 0 }; -+ -+ TEST_COMPARE (wordexp ("original", &we, 0), 0); -+ CHECK_WORDS (&we, "original"); -+ -+ char **saved_wordv = we.we_wordv; -+ size_t saved_count = we.we_wordc; -+ -+ /* Unterminated double quote triggers WRDE_SYNTAX. */ -+ TEST_COMPARE (wordexp ("\"unterminated", &we, WRDE_APPEND), WRDE_SYNTAX); -+ -+ TEST_COMPARE (we.we_wordc, saved_count); -+ TEST_VERIFY (we.we_wordv == saved_wordv); -+ CHECK_WORDS (&we, "original"); -+ -+ wordfree (&we); -+} -+ -+/* Test 8: Error without WRDE_APPEND still works (regression test for the -+ non-APPEND code path in do_error). */ -+static void -+test_no_append_error (void) -+{ -+ printf ("info: test_no_append_error\n"); -+ wordexp_t we = { 0 }; -+ -+ /* Simple failure without WRDE_APPEND. */ -+ TEST_COMPARE (wordexp ("bad |", &we, 0), WRDE_BADCHAR); -+ -+ /* After failure without WRDE_APPEND the struct should be safe to -+ reuse — start fresh. */ -+ TEST_COMPARE (wordexp ("ok", &we, 0), 0); -+ CHECK_WORDS (&we, "ok"); -+ -+ wordfree (&we); -+} -+ -+/* Test 9: WRDE_BADCHAR on the very first character (no partial words added -+ before the error). */ -+static void -+test_append_badchar_immediate (void) -+{ -+ printf ("info: test_append_badchar_immediate\n"); -+ wordexp_t we = { 0 }; -+ -+ TEST_COMPARE (wordexp ("hello world", &we, 0), 0); -+ CHECK_WORDS (&we, "hello", "world"); -+ -+ char **saved_wordv = we.we_wordv; -+ size_t saved_count = we.we_wordc; -+ -+ /* The bad character is the very first byte — no w_addword call happens -+ before the error. */ -+ TEST_COMPARE (wordexp ("|", &we, WRDE_APPEND), WRDE_BADCHAR); -+ TEST_COMPARE (we.we_wordc, saved_count); -+ TEST_VERIFY (we.we_wordv == saved_wordv); -+ -+ wordfree (&we); -+} -+ -+/* Test 10: WRDE_APPEND into an empty wordexp_t (initial call uses WRDE_APPEND -+ with a zeroed struct — unusual but allowed). */ -+static void -+test_append_into_empty (void) -+{ -+ printf ("info: test_append_into_empty\n"); -+ wordexp_t we = { 0 }; -+ -+ /* First call with WRDE_APPEND on a zeroed struct. The implementation -+ must handle we_wordv == NULL gracefully. */ -+ TEST_COMPARE (wordexp ("solo", &we, WRDE_APPEND), 0); -+ TEST_COMPARE (we.we_wordc, 1); -+ CHECK_WORDS (&we, "solo"); -+ -+ wordfree (&we); -+} -+ -+/* Verify that the leading we_offs slots are all NULL. */ -+static void -+check_offs_null (const wordexp_t *we) -+{ -+ for (size_t i = 0; i < we->we_offs; i++) -+ TEST_VERIFY (we->we_wordv[i] == NULL); -+} -+ -+/* Test 11: successful WRDE_APPEND with WRDE_DOOFFS and a non-zero we_offs. -+ The leading offset slots must stay NULL and words must land at -+ we_wordv[we_offs + i] across both the initial and the appended call. */ -+static void -+test_dooffs_append_success (void) -+{ -+ printf ("info: test_dooffs_append_success\n"); -+ wordexp_t we = { 0 }; -+ we.we_offs = 2; -+ -+ TEST_COMPARE (wordexp ("one two", &we, WRDE_DOOFFS), 0); -+ TEST_COMPARE (we.we_offs, 2); -+ check_offs_null (&we); -+ CHECK_WORDS (&we, "one", "two"); -+ -+ TEST_COMPARE (wordexp ("three", &we, WRDE_APPEND | WRDE_DOOFFS), 0); -+ TEST_COMPARE (we.we_offs, 2); -+ check_offs_null (&we); -+ CHECK_WORDS (&we, "one", "two", "three"); -+ /* The NULL terminator must sit right after the last word. */ -+ TEST_VERIFY (we.we_wordv[we.we_offs + we.we_wordc] == NULL); -+ -+ wordfree (&we); -+} -+ -+/* Test 12: failed WRDE_APPEND with WRDE_DOOFFS preserves we_wordc, the -+ we_wordv pointer, the words and the leading NULL offset slots. This -+ exercises the we_offs arithmetic in the array duplication and in the -+ error-path cleanup (we_wordv[we_offs + --we_wordc]). */ -+static void -+test_dooffs_append_error_preserves_state (void) -+{ -+ printf ("info: test_dooffs_append_error_preserves_state\n"); -+ wordexp_t we = { 0 }; -+ we.we_offs = 3; -+ -+ TEST_COMPARE (wordexp ("alpha beta", &we, WRDE_DOOFFS), 0); -+ check_offs_null (&we); -+ CHECK_WORDS (&we, "alpha", "beta"); -+ -+ char **saved_wordv = we.we_wordv; -+ size_t saved_count = we.we_wordc; -+ unsigned int saved_reallocs = relocating_reallocs; -+ -+ /* "gamma" is a partial word added via w_addword (forcing a relocating -+ realloc of we_wordv) before ')' triggers WRDE_BADCHAR. */ -+ TEST_COMPARE (wordexp ("gamma )", &we, WRDE_APPEND | WRDE_DOOFFS), -+ WRDE_BADCHAR); -+ TEST_VERIFY (relocating_reallocs > saved_reallocs); -+ -+ TEST_COMPARE (we.we_offs, 3); -+ TEST_COMPARE (we.we_wordc, saved_count); -+ TEST_VERIFY (we.we_wordv == saved_wordv); -+ check_offs_null (&we); -+ CHECK_WORDS (&we, "alpha", "beta"); -+ TEST_VERIFY (we.we_wordv[we.we_offs + we.we_wordc] == NULL); -+ -+ wordfree (&we); -+} -+ -+static int -+do_test (void) -+{ -+ test_append_badchar_preserves_count (); -+ test_append_badchar_preserves_pointer (); -+ test_append_badchar_words_intact (); -+ test_append_success (); -+ test_append_success_after_failure (); -+ test_append_multiple_failures (); -+ test_append_syntax_error (); -+ test_no_append_error (); -+ test_append_badchar_immediate (); -+ test_append_into_empty (); -+ test_dooffs_append_success (); -+ test_dooffs_append_error_preserves_state (); -+ -+ return 0; -+} -+ -+#include -diff --git a/posix/wordexp.c b/posix/wordexp.c -index 731d1650e9..50b0d7a256 100644 ---- a/posix/wordexp.c -+++ b/posix/wordexp.c -@@ -35,6 +35,7 @@ - #include - #include <_itoa.h> - #include -+#include - - /* - * This is a recursive-descent-style word expansion routine. -@@ -2224,6 +2225,12 @@ wordexp (const char *words, wordexp_t *pwordexp, int flags) - char ifs_white[4]; - wordexp_t old_word = *pwordexp; - -+ /* When WRDE_APPEND is set we work on a copy of the we_wordv array so that -+ the caller's original pointer is never invalidated by realloc inside -+ w_addword. The saved_wordv keeps the original; on success we free it, -+ on non-NOSPACE error we free the working copy and restore the original. */ -+ char **saved_wordv = NULL; -+ - if (flags & WRDE_REUSE) - { - /* Minimal implementation of WRDE_REUSE for now */ -@@ -2258,6 +2265,23 @@ wordexp (const char *words, wordexp_t *pwordexp, int flags) - pwordexp->we_offs = 0; - } - } -+ else if (pwordexp->we_wordv != NULL) -+ { -+ /* WRDE_APPEND with an existing word list: duplicate the array so that -+ realloc during parsing does not invalidate the caller's pointer. The -+ strings themselves are shared. */ -+ size_t num_p; -+ char **dup; -+ if (INT_ADD_WRAPV (pwordexp->we_offs, pwordexp->we_wordc, &num_p) -+ || INT_ADD_WRAPV (num_p, 1, &num_p)) -+ return WRDE_NOSPACE; -+ dup = __libc_reallocarray (NULL, num_p, sizeof *dup); -+ if (dup == NULL) -+ return WRDE_NOSPACE; -+ memcpy (dup, pwordexp->we_wordv, num_p * sizeof *dup); -+ saved_wordv = pwordexp->we_wordv; -+ pwordexp->we_wordv = dup; -+ } - - /* Find out what the field separators are. - * There are two types: whitespace and non-whitespace. -@@ -2338,7 +2362,7 @@ wordexp (const char *words, wordexp_t *pwordexp, int flags) - error = w_addword (pwordexp, NULL); - - if (error) -- return error; -+ goto do_error; - } - - break; -@@ -2356,7 +2380,7 @@ wordexp (const char *words, wordexp_t *pwordexp, int flags) - error = w_addword (pwordexp, NULL); - - if (error) -- return error; -+ goto do_error; - } - - break; -@@ -2422,10 +2446,18 @@ wordexp (const char *words, wordexp_t *pwordexp, int flags) - - /* There was a word separator at the end */ - if (word == NULL) /* i.e. w_newword */ -- return 0; -+ { -+ free (saved_wordv); -+ return 0; -+ } - -- /* There was no field separator at the end */ -- return w_addword (pwordexp, word); -+ /* There was no field separator at the end. The only possible error -+ from w_addword is WRDE_NOSPACE. */ -+ error = w_addword (pwordexp, word); -+ if (error != 0) -+ goto do_error; -+ free (saved_wordv); -+ return 0; - - do_error: - /* Error: -@@ -2436,11 +2468,30 @@ do_error: - free (word); - - if (error == WRDE_NOSPACE) -- return WRDE_NOSPACE; -+ { -+ /* we_wordc and we_wordv are updated to reflect any words that were -+ successfully expanded. The old array is obsolete. */ -+ free (saved_wordv); -+ return WRDE_NOSPACE; -+ } - -- if ((flags & WRDE_APPEND) == 0) -- wordfree (pwordexp); -+ if (flags & WRDE_APPEND) -+ { -+ /* POSIX 2024 states that for in other error cases, if the WRDE_APPEND -+ flag was specified, we_wordc and we_wordv shall not be modified. -+ -+ Free strings appended during this call, discard the working copy of -+ we_wordv, and restore the caller's original pointer. */ -+ while (pwordexp->we_wordc > old_word.we_wordc) -+ free (pwordexp->we_wordv[pwordexp->we_offs + --pwordexp->we_wordc]); -+ free (pwordexp->we_wordv); -+ pwordexp->we_wordv = saved_wordv; -+ } -+ else -+ { -+ wordfree (pwordexp); -+ *pwordexp = old_word; -+ } - -- *pwordexp = old_word; - return error; - } diff --git a/pkgs/development/libraries/glibc/2.44-master.patch b/pkgs/development/libraries/glibc/2.44-master.patch new file mode 100644 index 000000000000..08c0e1da3143 --- /dev/null +++ b/pkgs/development/libraries/glibc/2.44-master.patch @@ -0,0 +1,4138 @@ +commit 5e5ddf57987ae4b37da5ca2fa039c8803b0be735 +Author: Andreas K. Hüttel +Date: Sat Jul 25 09:20:26 2026 +0900 + + advisories: replace with ADVISORIES text file + + Signed-off-by: Andreas K. Hüttel + +diff --git a/advisories/GLIBC-SA-2023-0001 b/advisories/GLIBC-SA-2023-0001 +deleted file mode 100644 +index 3d19c91b6a..0000000000 +--- a/advisories/GLIBC-SA-2023-0001 ++++ /dev/null +@@ -1,14 +0,0 @@ +-printf: incorrect output for integers with thousands separator and width field +- +-When the printf family of functions is called with a format specifier +-that uses an (enable grouping) and a minimum width +-specifier, the resulting output could be larger than reasonably expected +-by a caller that computed a tight bound on the buffer size. The +-resulting larger than expected output could result in a buffer overflow +-in the printf family of functions. +- +-CVE-Id: CVE-2023-25139 +-Public-Date: 2023-02-02 +-Vulnerable-Commit: e88b9f0e5cc50cab57a299dc7efe1a4eb385161d (2.37) +-Fix-Commit: c980549cc6a1c03c23cc2fe3e7b0fe626a0364b0 (2.38) +-Fix-Commit: 07b9521fc6369d000216b96562ff7c0ed32a16c4 (2.37-4) +diff --git a/advisories/GLIBC-SA-2023-0002 b/advisories/GLIBC-SA-2023-0002 +deleted file mode 100644 +index 5122669a64..0000000000 +--- a/advisories/GLIBC-SA-2023-0002 ++++ /dev/null +@@ -1,15 +0,0 @@ +-getaddrinfo: Stack read overflow in no-aaaa mode +- +-If the system is configured in no-aaaa mode via /etc/resolv.conf, +-getaddrinfo is called for the AF_UNSPEC address family, and a DNS +-response is received over TCP that is larger than 2048 bytes, +-getaddrinfo may potentially disclose stack contents via the returned +-address data, or crash. +- +-CVE-Id: CVE-2023-4527 +-Public-Date: 2023-09-12 +-Vulnerable-Commit: f282cdbe7f436c75864e5640a409a10485e9abb2 (2.36) +-Fix-Commit: bd77dd7e73e3530203be1c52c8a29d08270cb25d (2.39) +-Fix-Commit: 4ea972b7edd7e36610e8cde18bf7a8149d7bac4f (2.36-113) +-Fix-Commit: b7529346025a130fee483d42178b5c118da971bb (2.37-38) +-Fix-Commit: b25508dd774b617f99419bdc3cf2ace4560cd2d6 (2.38-19) +diff --git a/advisories/GLIBC-SA-2023-0003 b/advisories/GLIBC-SA-2023-0003 +deleted file mode 100644 +index d3aef80348..0000000000 +--- a/advisories/GLIBC-SA-2023-0003 ++++ /dev/null +@@ -1,15 +0,0 @@ +-getaddrinfo: Potential use-after-free +- +-When an NSS plugin only implements the _gethostbyname2_r and +-_getcanonname_r callbacks, getaddrinfo could use memory that was freed +-during buffer resizing, potentially causing a crash or read or write to +-arbitrary memory. +- +-CVE-Id: CVE-2023-4806 +-Public-Date: 2023-09-12 +-Fix-Commit: 973fe93a5675c42798b2161c6f29c01b0e243994 (2.39) +-Fix-Commit: e09ee267c03e3150c2c9ba28625ab130705a485e (2.34-420) +-Fix-Commit: e3ccb230a961b4797510e6a1f5f21fd9021853e7 (2.35-270) +-Fix-Commit: a9728f798ec7f05454c95637ee6581afaa9b487d (2.36-115) +-Fix-Commit: 6529a7466c935f36e9006b854d6f4e1d4876f942 (2.37-39) +-Fix-Commit: 00ae4f10b504bc4564e9f22f00907093f1ab9338 (2.38-20) +diff --git a/advisories/GLIBC-SA-2023-0004 b/advisories/GLIBC-SA-2023-0004 +deleted file mode 100644 +index 5286a7aa54..0000000000 +--- a/advisories/GLIBC-SA-2023-0004 ++++ /dev/null +@@ -1,16 +0,0 @@ +-tunables: local privilege escalation through buffer overflow +- +-If a tunable of the form NAME=NAME=VAL is passed in the environment of a +-setuid program and NAME is valid, it may result in a buffer overflow, +-which could be exploited to achieve escalated privileges. This flaw was +-introduced in glibc 2.34. +- +-CVE-Id: CVE-2023-4911 +-Public-Date: 2023-10-03 +-Vulnerable-Commit: 2ed18c5b534d9e92fc006202a5af0df6b72e7aca (2.34) +-Fix-Commit: 1056e5b4c3f2d90ed2b4a55f96add28da2f4c8fa (2.39) +-Fix-Commit: dcc367f148bc92e7f3778a125f7a416b093964d9 (2.34-423) +-Fix-Commit: c84018a05aec80f5ee6f682db0da1130b0196aef (2.35-274) +-Fix-Commit: 22955ad85186ee05834e47e665056148ca07699c (2.36-118) +-Fix-Commit: b4e23c75aea756b4bddc4abcf27a1c6dca8b6bd3 (2.37-45) +-Fix-Commit: 750a45a783906a19591fb8ff6b7841470f1f5701 (2.38-27) +diff --git a/advisories/GLIBC-SA-2023-0005 b/advisories/GLIBC-SA-2023-0005 +deleted file mode 100644 +index cc4eb90b82..0000000000 +--- a/advisories/GLIBC-SA-2023-0005 ++++ /dev/null +@@ -1,18 +0,0 @@ +-getaddrinfo: DoS due to memory leak +- +-The fix for CVE-2023-4806 introduced a memory leak when an application +-calls getaddrinfo for AF_INET6 with AI_CANONNAME, AI_ALL and AI_V4MAPPED +-flags set. +- +-CVE-Id: CVE-2023-5156 +-Public-Date: 2023-09-25 +-Vulnerable-Commit: e09ee267c03e3150c2c9ba28625ab130705a485e (2.34-420) +-Vulnerable-Commit: e3ccb230a961b4797510e6a1f5f21fd9021853e7 (2.35-270) +-Vulnerable-Commit: a9728f798ec7f05454c95637ee6581afaa9b487d (2.36-115) +-Vulnerable-Commit: 6529a7466c935f36e9006b854d6f4e1d4876f942 (2.37-39) +-Vulnerable-Commit: 00ae4f10b504bc4564e9f22f00907093f1ab9338 (2.38-20) +-Fix-Commit: 8006457ab7e1cd556b919f477348a96fe88f2e49 (2.34-421) +-Fix-Commit: 17092c0311f954e6f3c010f73ce3a78c24ac279a (2.35-272) +-Fix-Commit: 856bac55f98dc840e7c27cfa82262b933385de90 (2.36-116) +-Fix-Commit: 4473d1b87d04b25cdd0e0354814eeaa421328268 (2.37-42) +-Fix-Commit: 5ee59ca371b99984232d7584fe2b1a758b4421d3 (2.38-24) +diff --git a/advisories/GLIBC-SA-2024-0001 b/advisories/GLIBC-SA-2024-0001 +deleted file mode 100644 +index 28931c75ae..0000000000 +--- a/advisories/GLIBC-SA-2024-0001 ++++ /dev/null +@@ -1,15 +0,0 @@ +-syslog: Heap buffer overflow in __vsyslog_internal +- +-__vsyslog_internal did not handle a case where printing a SYSLOG_HEADER +-containing a long program name failed to update the required buffer +-size, leading to the allocation and overflow of a too-small buffer on +-the heap. +- +-CVE-Id: CVE-2023-6246 +-Public-Date: 2024-01-30 +-Vulnerable-Commit: 52a5be0df411ef3ff45c10c7c308cb92993d15b1 (2.37) +-Fix-Commit: 6bd0e4efcc78f3c0115e5ea9739a1642807450da (2.39) +-Fix-Commit: 23514c72b780f3da097ecf33a793b7ba9c2070d2 (2.38-42) +-Fix-Commit: 97a4292aa4a2642e251472b878d0ec4c46a0e59a (2.37-57) +-Vulnerable-Commit: b0e7888d1fa2dbd2d9e1645ec8c796abf78880b9 (2.36-16) +-Fix-Commit: d1a83b6767f68b3cb5b4b4ea2617254acd040c82 (2.36-126) +diff --git a/advisories/GLIBC-SA-2024-0002 b/advisories/GLIBC-SA-2024-0002 +deleted file mode 100644 +index 940bfcf2fc..0000000000 +--- a/advisories/GLIBC-SA-2024-0002 ++++ /dev/null +@@ -1,15 +0,0 @@ +-syslog: Heap buffer overflow in __vsyslog_internal +- +-__vsyslog_internal used the return value of snprintf/vsnprintf to +-calculate buffer sizes for memory allocation. If these functions (for +-any reason) failed and returned -1, the resulting buffer would be too +-small to hold output. +- +-CVE-Id: CVE-2023-6779 +-Public-Date: 2024-01-30 +-Vulnerable-Commit: 52a5be0df411ef3ff45c10c7c308cb92993d15b1 (2.37) +-Fix-Commit: 7e5a0c286da33159d47d0122007aac016f3e02cd (2.39) +-Fix-Commit: d0338312aace5bbfef85e03055e1212dd0e49578 (2.38-43) +-Fix-Commit: 67062eccd9a65d7fda9976a56aeaaf6c25a80214 (2.37-58) +-Vulnerable-Commit: b0e7888d1fa2dbd2d9e1645ec8c796abf78880b9 (2.36-16) +-Fix-Commit: 2bc9d7c002bdac38b5c2a3f11b78e309d7765b83 (2.36-127) +diff --git a/advisories/GLIBC-SA-2024-0003 b/advisories/GLIBC-SA-2024-0003 +deleted file mode 100644 +index b43a5150ab..0000000000 +--- a/advisories/GLIBC-SA-2024-0003 ++++ /dev/null +@@ -1,13 +0,0 @@ +-syslog: Integer overflow in __vsyslog_internal +- +-__vsyslog_internal calculated a buffer size by adding two integers, but +-did not first check if the addition would overflow. +- +-CVE-Id: CVE-2023-6780 +-Public-Date: 2024-01-30 +-Vulnerable-Commit: 52a5be0df411ef3ff45c10c7c308cb92993d15b1 (2.37) +-Fix-Commit: ddf542da94caf97ff43cc2875c88749880b7259b (2.39) +-Fix-Commit: d37c2b20a4787463d192b32041c3406c2bd91de0 (2.38-44) +-Fix-Commit: 2b58cba076e912961ceaa5fa58588e4b10f791c0 (2.37-59) +-Vulnerable-Commit: b0e7888d1fa2dbd2d9e1645ec8c796abf78880b9 (2.36-16) +-Fix-Commit: b9b7d6a27aa0632f334352fa400771115b3c69b7 (2.36-128) +diff --git a/advisories/GLIBC-SA-2024-0004 b/advisories/GLIBC-SA-2024-0004 +deleted file mode 100644 +index 08df2b3118..0000000000 +--- a/advisories/GLIBC-SA-2024-0004 ++++ /dev/null +@@ -1,28 +0,0 @@ +-ISO-2022-CN-EXT: fix out-of-bound writes when writing escape sequence +- +-The iconv() function in the GNU C Library versions 2.39 and older may +-overflow the output buffer passed to it by up to 4 bytes when converting +-strings to the ISO-2022-CN-EXT character set, which may be used to +-crash an application or overwrite a neighbouring variable. +- +-ISO-2022-CN-EXT uses escape sequences to indicate character set changes +-(as specified by RFC 1922). While the SOdesignation has the expected +-bounds checks, neither SS2designation nor SS3designation have its; +-allowing a write overflow of 1, 2, or 3 bytes with fixed values: +-'$+I', '$+J', '$+K', '$+L', '$+M', or '$*H'. +- +-CVE-Id: CVE-2024-2961 +-Public-Date: 2024-04-17 +-Vulnerable-Commit: 755104edc75c53f4a0e7440334e944ad3c6b32fc (2.1.93-169) +-Fix-Commit: f9dc609e06b1136bb0408be9605ce7973a767ada (2.40) +-Fix-Commit: 31da30f23cddd36db29d5b6a1c7619361b271fb4 (2.39-31) +-Fix-Commit: e1135387deded5d73924f6ca20c72a35dc8e1bda (2.38-66) +-Fix-Commit: 89ce64b269a897a7780e4c73a7412016381c6ecf (2.37-89) +-Fix-Commit: 4ed98540a7fd19f458287e783ae59c41e64df7b5 (2.36-164) +-Fix-Commit: 36280d1ce5e245aabefb877fe4d3c6cff95dabfa (2.35-315) +-Fix-Commit: a8b0561db4b9847ebfbfec20075697d5492a363c (2.34-459) +-Fix-Commit: ed4f16ff6bed3037266f1fa682ebd32a18fce29c (2.33-263) +-Fix-Commit: 682ad4c8623e611a971839990ceef00346289cc9 (2.32-140) +-Fix-Commit: 3703c32a8d304c1ee12126134ce69be965f38000 (2.31-154) +- +-Reported-By: Charles Fol +diff --git a/advisories/GLIBC-SA-2024-0005 b/advisories/GLIBC-SA-2024-0005 +deleted file mode 100644 +index a59596610a..0000000000 +--- a/advisories/GLIBC-SA-2024-0005 ++++ /dev/null +@@ -1,22 +0,0 @@ +-nscd: Stack-based buffer overflow in netgroup cache +- +-If the Name Service Cache Daemon's (nscd) fixed size cache is exhausted +-by client requests then a subsequent client request for netgroup data +-may result in a stack-based buffer overflow. This flaw was introduced +-in glibc 2.15 when the cache was added to nscd. +- +-This vulnerability is only present in the nscd binary. +- +-CVE-Id: CVE-2024-33599 +-Public-Date: 2024-04-23 +-Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) +-Fix-Commit: 69c58d5ef9f584ea198bd00f7964d364d0e6b921 (2.31-155) +-Fix-Commit: a77064893bfe8a701770e2f53a4d33805bc47a5a (2.32-141) +-Fix-Commit: 5c75001a96abcd50cbdb74df24c3f013188d076e (2.33-264) +-Fix-Commit: 52f73e5c4e29b14e79167272297977f360ae1e97 (2.34-460) +-Fix-Commit: 7a95873543ce225376faf13bb71c43dea6d24f86 (2.35-316) +-Fix-Commit: caa3151ca460bdd9330adeedd68c3112d97bffe4 (2.36-165) +-Fix-Commit: f75c298e747b2b8b41b1c2f551c011a52c41bfd1 (2.37-91) +-Fix-Commit: 5968aebb86164034b8f8421b4abab2f837a5bdaf (2.38-72) +-Fix-Commit: 1263d583d2e28afb8be53f8d6922f0842036f35d (2.39-35) +-Fix-Commit: 87801a8fd06db1d654eea3e4f7626ff476a9bdaa (2.40) +diff --git a/advisories/GLIBC-SA-2024-0006 b/advisories/GLIBC-SA-2024-0006 +deleted file mode 100644 +index d44148d3d9..0000000000 +--- a/advisories/GLIBC-SA-2024-0006 ++++ /dev/null +@@ -1,32 +0,0 @@ +-nscd: Null pointer crash after notfound response +- +-If the Name Service Cache Daemon's (nscd) cache fails to add a not-found +-netgroup response to the cache, the client request can result in a null +-pointer dereference. This flaw was introduced in glibc 2.15 when the +-cache was added to nscd. +- +-This vulnerability is only present in the nscd binary. +- +-CVE-Id: CVE-2024-33600 +-Public-Date: 2024-04-24 +-Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) +-Fix-Commit: b048a482f088e53144d26a61c390bed0210f49f2 (2.40) +-Fix-Commit: 7835b00dbce53c3c87bbbb1754a95fb5e58187aa (2.40) +-Fix-Commit: c99f886de54446cd4447db6b44be93dabbdc2f8b (2.39-37) +-Fix-Commit: 5a508e0b508c8ad53bd0d2fb48fd71b242626341 (2.39-36) +-Fix-Commit: 2ae9446c1b7a3064743b4a51c0bbae668ee43e4c (2.38-74) +-Fix-Commit: 541ea5172aa658c4bd5c6c6d6fd13903c3d5bb0a (2.38-73) +-Fix-Commit: a8070b31043c7585c36ba68a74298c4f7af075c3 (2.37-93) +-Fix-Commit: 5eea50c4402e39588de98aa1d4469a79774703d4 (2.37-92) +-Fix-Commit: f205b3af56740e3b014915b1bd3b162afe3407ef (2.36-167) +-Fix-Commit: c34f470a615b136170abd16142da5dd0c024f7d1 (2.36-166) +-Fix-Commit: bafadc589fbe21ae330e8c2af74db9da44a17660 (2.35-318) +-Fix-Commit: 4370bef52b0f3f3652c6aa13d7a9bb3ac079746d (2.35-317) +-Fix-Commit: 1f94122289a9bf7dba573f5d60327aaa2b85cf2e (2.34-462) +-Fix-Commit: 966d6ac9e40222b84bb21674cc4f83c8d72a5a26 (2.34-461) +-Fix-Commit: e3eef1b8fbdd3a7917af466ca9c4b7477251ca79 (2.33-266) +-Fix-Commit: f20a8d696b13c6261b52a6434899121f8b19d5a7 (2.33-265) +-Fix-Commit: be602180146de37582a3da3a0caa4b719645de9c (2.32-143) +-Fix-Commit: 394eae338199078b7961b051c191539870742d7b (2.32-142) +-Fix-Commit: 8d7949183760170c61e55def723c1d8050187874 (2.31-157) +-Fix-Commit: 304ce5fe466c4762b21b36c26926a4657b59b53e (2.31-156) +diff --git a/advisories/GLIBC-SA-2024-0007 b/advisories/GLIBC-SA-2024-0007 +deleted file mode 100644 +index b6928fa27a..0000000000 +--- a/advisories/GLIBC-SA-2024-0007 ++++ /dev/null +@@ -1,28 +0,0 @@ +-nscd: netgroup cache may terminate daemon on memory allocation failure +- +-The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or +-xrealloc and these functions may terminate the process due to a memory +-allocation failure resulting in a denial of service to the clients. The +-flaw was introduced in glibc 2.15 when the cache was added to nscd. +- +-This vulnerability is only present in the nscd binary. +- +-Subsequent refactoring of the netgroup cache only added more uses of +-xmalloc and xrealloc. Uses of xmalloc and xrealloc in other parts of +-nscd only occur during startup of the daemon and so are not affected by +-client requests that could trigger an out of memory followed by +-termination. +- +-CVE-Id: CVE-2024-33601 +-Public-Date: 2024-04-24 +-Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) +-Fix-Commit: c04a21e050d64a1193a6daab872bca2528bda44b (2.40) +-Fix-Commit: a9a8d3eebb145779a18d90e3966009a1daa63cd8 (2.39-38) +-Fix-Commit: 71af8ca864345d39b746d5cee84b94b430fad5db (2.38-75) +-Fix-Commit: 6e106dc214d6a033a4e945d1c6cf58061f1c5f1f (2.37-94) +-Fix-Commit: b6742463694b1dfdd5120b91ee21cf05d15ec2e2 (2.36-168) +-Fix-Commit: 7a5864cac60e06000394128a5a2817b03542f5a3 (2.35-319) +-Fix-Commit: 86f1d5f4129c373ac6fb6df5bcf38273838843cb (2.34-463) +-Fix-Commit: 4d27d4b9a188786fc6a56745506cec2acfc51f83 (2.33-267) +-Fix-Commit: 3ed195a8ec89da281e3c4bf887a13d281b72d8f4 (2.32-144) +-Fix-Commit: bbf5a58ccb55679217f94de706164d15372fbbc0 (2.31-158) +diff --git a/advisories/GLIBC-SA-2024-0008 b/advisories/GLIBC-SA-2024-0008 +deleted file mode 100644 +index d93e2a6f0b..0000000000 +--- a/advisories/GLIBC-SA-2024-0008 ++++ /dev/null +@@ -1,26 +0,0 @@ +-nscd: netgroup cache assumes NSS callback uses in-buffer strings +- +-The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory +-when the NSS callback does not store all strings in the provided buffer. +-The flaw was introduced in glibc 2.15 when the cache was added to nscd. +- +-This vulnerability is only present in the nscd binary. +- +-There is no guarantee from the NSS callback API that the returned +-strings are all within the buffer. However, the netgroup cache code +-assumes that the NSS callback uses in-buffer strings and if it doesn't +-the buffer resizing logic could lead to potential memory corruption. +- +-CVE-Id: CVE-2024-33602 +-Public-Date: 2024-04-24 +-Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) +-Fix-Commit: c04a21e050d64a1193a6daab872bca2528bda44b (2.40) +-Fix-Commit: a9a8d3eebb145779a18d90e3966009a1daa63cd8 (2.39-38) +-Fix-Commit: 71af8ca864345d39b746d5cee84b94b430fad5db (2.38-75) +-Fix-Commit: 6e106dc214d6a033a4e945d1c6cf58061f1c5f1f (2.37-94) +-Fix-Commit: b6742463694b1dfdd5120b91ee21cf05d15ec2e2 (2.36-168) +-Fix-Commit: 7a5864cac60e06000394128a5a2817b03542f5a3 (2.35-319) +-Fix-Commit: 86f1d5f4129c373ac6fb6df5bcf38273838843cb (2.34-463) +-Fix-Commit: 4d27d4b9a188786fc6a56745506cec2acfc51f83 (2.33-267) +-Fix-Commit: 3ed195a8ec89da281e3c4bf887a13d281b72d8f4 (2.32-144) +-Fix-Commit: bbf5a58ccb55679217f94de706164d15372fbbc0 (2.31-158) +diff --git a/advisories/GLIBC-SA-2025-0001 b/advisories/GLIBC-SA-2025-0001 +deleted file mode 100644 +index b053d32e91..0000000000 +--- a/advisories/GLIBC-SA-2025-0001 ++++ /dev/null +@@ -1,40 +0,0 @@ +-assert: Buffer overflow when printing assertion failure message +- +-When the assert() function fails, it does not allocate enough space for the +-assertion failure message string and size information, which may lead to a +-buffer overflow if the message string size aligns to page size. +- +-This bug can be triggered when an assertion in a program fails. The assertion +-failure message is allocated to allow developers to see this failure in core +-dumps and it typically includes, in addition to the invariant assertion +-string and function name, the name of the program. If the name of the failing +-program is user controlled, for example on a local system, this could allow an +-attacker to control the assertion failure to trigger this buffer overflow. +- +-The only viable vector for exploitation of this bug is local, if a setuid +-program exists that has an existing bug that results in an assertion failure. +-No such program has been discovered at the time of publishing this advisory, +-but the presence of custom setuid programs, although strongly discouraged as a +-security practice, cannot be discounted. +- +-CVE-Id: CVE-2025-0395 +-Public-Date: 2025-01-22 +-Vulnerable-Commit: f8a3b5bf8fa1d0c43d2458e03cc109a04fdef194 (2.13-175) +-Fix-Commit: 68ee0f704cb81e9ad0a78c644a83e1e9cd2ee578 (2.41) +-Fix-Commit: cdb9ba84191ce72e86346fb8b1d906e7cd930ea2 (2.42) +-Fix-Commit: 69fda28279b497bd405fdd442a6d8e4d3d5f681b (2.41-7) +-Fix-Commit: 7d4b6bcae91f29d7b4daf15bab06b66cf1d2217c (2.40-66) +-Fix-Commit: d6c156c326999f144cb5b73d29982108d549ad8a (2.40-71) +-Fix-Commit: 808a84a8b81468b517a4d721fdc62069cb8c211f (2.39-146) +-Fix-Commit: f6d48470aef9264d2d56f4c4533eb76db7f9c2e4 (2.39-150) +-Fix-Commit: c32fd59314c343db88c3ea4a203870481d33c3d2 (2.38-122) +-Fix-Commit: f984e2d7e8299726891a1a497a3c36cd5542a0bf (2.38-124) +-Fix-Commit: a3d7865b098a3a67c44f7812208d9ce4718873ba (2.37-143) +-Fix-Commit: b989519fe1683c204ac24ec92830e3fe3bfaccad (2.37-146) +-Fix-Commit: 7971add7ee4171fdd8dfd17e7c04c4ed77a18845 (2.36-216) +-Fix-Commit: 0487893d5c5bc6710d83d7c3152d888a0339559e (2.36-219) +-Fix-Commit: 8b5d4be762419c4f6176261c6fea40ac559b88dc (2.35-370) +-Fix-Commit: 8b3d09dc0d350191985f9d291cc30ce96f034b49 (2.35-373) +-Fix-Commit: df4e1f4a5096b385c9bcc94424cf2eaa227b3761 (2.34-500) +-Fix-Commit: 31eb872cb21449832ab47ad5db83281d240e1d03 (2.34-503) +-Reported-By: Qualys Security Advisory +diff --git a/advisories/GLIBC-SA-2025-0002 b/advisories/GLIBC-SA-2025-0002 +deleted file mode 100644 +index 161da13dd4..0000000000 +--- a/advisories/GLIBC-SA-2025-0002 ++++ /dev/null +@@ -1,23 +0,0 @@ +-elf: static setuid binary dlopen may incorrectly search LD_LIBRARY_PATH +- +-A statically linked setuid binary that calls dlopen (including internal +-dlopen calls after setlocale or calls to NSS functions such as getaddrinfo) +-may incorrectly search LD_LIBRARY_PATH to determine which library to load, +-leading to the execution of library code that is attacker controlled. +- +-The only viable vector for exploitation of this bug is local, if a static +-setuid program exists, and that program calls dlopen, then it may search +-LD_LIBRARY_PATH to locate the SONAME to load. No such program has been +-discovered at the time of publishing this advisory, but the presence of +-custom setuid programs, although strongly discouraged as a security +-practice, cannot be discounted. +- +-CVE-Id: CVE-2025-4802 +-Public-Date: 2025-05-16 +-Vulnerable-Commit: 10e93d968716ab82931d593bada121c17c0a4b93 (2.27) +-Fix-Commit: 5451fa962cd0a90a0e2ec1d8910a559ace02bba0 (2.39) +-Fix-Commit: 3be3728df2f1912c80abd3288bc6e3a25ad679e4 (2.38-132) +-Fix-Commit: 7403ede2d7752e59e0c47d5d33d73c2bf850e7be (2.37-154) +-Fix-Commit: 2ef7850279b2931caf6d6d6743ebaa91839e1cf7 (2.36-227) +-Fix-Commit: 621c65ccf12ddd415ceeb2234423bd1acd0fabb3 (2.35-387) +-Fix-Commit: 35018c0fd20eac9ceaf60060fed2745b3177359d (2.34-517) +diff --git a/advisories/GLIBC-SA-2025-0003 b/advisories/GLIBC-SA-2025-0003 +deleted file mode 100644 +index 2adeb3ce00..0000000000 +--- a/advisories/GLIBC-SA-2025-0003 ++++ /dev/null +@@ -1,30 +0,0 @@ +-power10: strcmp fails to save and restore nonvolatile vector registers +- +-The Power 10 implementation of strcmp in +-sysdeps/powerpc/powerpc64/le/power10/strcmp.S failed to save/restore +-nonvolatile vector registers in the 32-byte aligned loop path. This +-results in callers reading content from those registers in a different +-context, potentially altering program logic. +- +-There could be a program context where a user controlled string could +-leak through strcmp into program code, thus altering its logic. There +-is also a potential for sensitive strings passed into strcmp leaking +-through the clobbered registers into parts of the calling program that +-should otherwise not have had access to those strings. +- +-The impact of this flaw is limited to applications running on Power 10 +-hardware that use the nonvolatile vector registers, i.e. v20 to v31 +-assuming that they have been treated in accordance with the OpenPower +-psABI. It is possible to work around the issue for those specific +-applications by setting the glibc.cpu.hwcaps tunable to "-arch_3_1" like +-so: +- +- export GLIBC_TUNABLES=glibc.cpu.hwcaps=-arch_3_1 +- +-CVE-Id: CVE-2025-5702 +-Public-Date: 2025-06-04 +-Vulnerable-Commit: 3367d8e180848030d1646f088759f02b8dfe0d6f (2.39) +-Fix-Commit: 15808c77b35319e67ee0dc8f984a9a1a434701bc (2.42) +-Fix-Commit: 0c76c951620f9e12df2a89b2c684878b55bb6795 (2.41-60) +-Fix-Commit: 7e12550b8e3a11764a4a9090ce6bd3fc23fc8a8e (2.40-139) +-Fix-Commit: 06a70769fd0b2e1f2a3085ad50ab620282bd77b3 (2.39-209) +diff --git a/advisories/GLIBC-SA-2025-0004 b/advisories/GLIBC-SA-2025-0004 +deleted file mode 100644 +index 9409ca27c4..0000000000 +--- a/advisories/GLIBC-SA-2025-0004 ++++ /dev/null +@@ -1,29 +0,0 @@ +-power10: strncmp fails to save and restore nonvolatile vector registers +- +-The Power 10 implementation of strncmp in +-sysdeps/powerpc/powerpc64/le/power10/strncmp.S failed to save/restore +-nonvolatile vector registers in the 32-byte aligned loop path. This +-results in callers reading content from those registers in a different +-context, potentially altering program logic. +- +-There could be a program context where a user controlled string could +-leak through strncmp into program code, thus altering its logic. There +-is also a potential for sensitive strings passed into strncmp leaking +-through the clobbered registers into parts of the calling program that +-should otherwise not have had access to those strings. +- +-The impact of this flaw is limited to applications running on Power 10 +-hardware that use the nonvolatile vector registers, i.e. v20 to v31 +-assuming that they have been treated in accordance with the OpenPower +-psABI. It is possible to work around the issue for those specific +-applications by setting the glibc.cpu.hwcaps tunable to "-arch_3_1" like +-so: +- +- export GLIBC_TUNABLES=glibc.cpu.hwcaps=-arch_3_1 +- +-CVE-Id: CVE-2025-5745 +-Public-Date: 2025-06-05 +-Vulnerable-Commit: 23f0d81608d0ca6379894ef81670cf30af7fd081 (2.40) +-Fix-Commit: 63c60101ce7c5eac42be90f698ba02099b41b965 (2.42) +-Fix-Commit: 84bdbf8a6f2fdafd3661489dbb7f79835a52da82 (2.41-57) +-Fix-Commit: 42a5a940c974d02540c8da26d6374c744d148cb9 (2.40-136) +diff --git a/advisories/GLIBC-SA-2025-0005 b/advisories/GLIBC-SA-2025-0005 +deleted file mode 100644 +index 8bcccc59a5..0000000000 +--- a/advisories/GLIBC-SA-2025-0005 ++++ /dev/null +@@ -1,14 +0,0 @@ +-posix: Fix double-free after allocation failure in regcomp +- +-The regcomp function in the GNU C library version from 2.4 to 2.41 is +-subject to a double free if some previous allocation fails. It can be +-accomplished either by a malloc failure or by using an interposed +-malloc that injects random malloc failures. The double free can allow +-buffer manipulation depending of how the regex is constructed. +-This issue affects all architectures and ABIs supported by the GNU C +-library. +- +-CVE-Id: CVE-2025-8058 +-Public-Date: 2025-07-22 +-Vulnerable-Commit: 963d8d782fc98fb6dc3a66f0068795f9920c269d (2.3.3-1596) +-Fix-Commit: 7ea06e994093fa0bcca0d0ee2c1db271d8d7885d (2.42) +diff --git a/advisories/GLIBC-SA-2026-0001 b/advisories/GLIBC-SA-2026-0001 +deleted file mode 100644 +index 3e0ee3b3f4..0000000000 +--- a/advisories/GLIBC-SA-2026-0001 ++++ /dev/null +@@ -1,41 +0,0 @@ +-Integer overflow in memalign leads to heap corruption +- +-Passing too large an alignment to the memalign suite of functions +-(memalign, posix_memalign, aligned_alloc) in the GNU C Library version +-2.30 to 2.42 may result in an integer overflow, which could consequently +-result in a heap corruption. +- +-Note that the attacker must have control over both, the size as well as +-the alignment arguments of the memalign function to be able to exploit +-this. The size parameter must be close enough to PTRDIFF_MAX so as to +-overflow size_t along with the large alignment argument. This limits +-the malicious inputs for the alignment for memalign to the range [1<<62 +-+ 1, 1<<63] and exactly 1<<63 for posix_memalign and aligned_alloc. +- +-Typically the alignment argument passed to such functions is a known +-constrained quantity (e.g. page size, block size, struct sizes) and is +-not attacker controlled, because of which this may not be easily +-exploitable in practice. An application bug could potentially result in +-the input alignment being too large, e.g. due to a different buffer +-overflow or integer overflow in the application or its dependent +-libraries, but that is again an uncommon usage pattern given typical +-sources of alignments. +- +-CVE-Id: CVE-2026-0861 +-Public-Date: 2026-01-14 +-Vulnerable-Commit: 9bf8e29ca136094f73f69f725f15c51facc97206 (2.30) +-Fix-Commit: c9188d333717d3ceb7e3020011651f424f749f93 (2.43) +-Fix-Commit: 7f19ef14fbce095d4c77395e258320cad2ea2b28 (2.30-153) +-Fix-Commit: f18446d7b4a423090ee5e328c36b3c2a0f26041c (2.31-166) +-Fix-Commit: 8aef9e7a7af9565c0324b4ecb38b30dfa3782fd8 (2.32-151) +-Fix-Commit: 011293b4fd748cdd6f95874ba2b6aba9a3df8bff (2.33-275) +-Fix-Commit: 2c77e52108a58956c9f674b36e1f59a4e3fdcf4d (2.34-525) +-Fix-Commit: 499d1ccafccfe64df1b88deea2fa84d8180e8e8f (2.35-399) +-Fix-Commit: fb6b8822175769b5794fb6ea04f2895483a29b61 (2.36-244) +-Fix-Commit: 7b913d41a07836def826f2164c52541a9835f324 (2.37-172) +-Fix-Commit: 744b63026a29f7eedbbc8e3a01a7f48a6eb0a085 (2.38-212) +-Fix-Commit: fb22fd3f5b415dd4cd6f7b5741c2f0412374e242 (2.39-286) +-Fix-Commit: bfc4dd9e526eacf3017dd8864ba0848e9d045dd4 (2.40-216) +-Fix-Commit: 1e2c1ea4307197ccece0cda574bcfebf9080894c (2.41-121) +-Fix-Commit: b0ec8fb689df862171f0f78994a3bdeb51313545 (2.42-49) +-Reported-by: Igor Morgenstern, Aisle Research +diff --git a/advisories/GLIBC-SA-2026-0002 b/advisories/GLIBC-SA-2026-0002 +deleted file mode 100644 +index f10d8362f6..0000000000 +--- a/advisories/GLIBC-SA-2026-0002 ++++ /dev/null +@@ -1,36 +0,0 @@ +-getnetbyaddr and getnetbyaddr_r leak stack contents to DNS resovler +- +-Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf +-that specifies the library's DNS backend for networks and queries for a +-zero-valued network in the GNU C Library version 2.0 to version 2.42 +-can leak stack contents to the configured DNS resolver. +- +-A defect in the _nss_dns_getnetbyaddr_r function which implements +-getnetbyaddr and getnetbyaddr_r in the dns-based network database can +-pass stack contents unmodified to the configured DNS resolver as part of +-the network DNS query when the network queried is the default network +-i.e. net == 0x0. This stack contents leaking in the query is considered +-a loss of confidentiality for the host making the query. Typically it +-is rare to call these APIs with a net value of zero, and if an attacker +-can control the net value it can only leak adjacent stack, and so loss +-of confidentiality is spatially limited. The leak might be used to +-accelerate an ASLR bypass by knowing pointer values, but also requires +-network adjacent access to snoop between the application and the +-DNS server; making the attack complexity higher. +- +-CVE-Id: CVE-2026-0915 +-Public-Date: 2026-01-15 +-Vulnerable-Commit: 5f0e6fc702296840d2daa39f83f6cb1e40073d58 (1.92-1) +-Fix-Commit: e56ff82d5034ec66c6a78f517af6faa427f65b0b (2.43) +-Fix-Commit: 453e6b8dbab935257eb0802b0c97bca6b67ba30e (2.42-50) +-Fix-Commit: 15c9839a0b853f552b4ed9047841b6223f3c104d (2.41-122) +-Fix-Commit: 329c775788b2c9ff3da774ccf59fba7b6b8ff08e (2.40-217) +-Fix-Commit: 831f63b94ceb92fb14c0d1a7ddad35a0d1404c71 (2.39-287) +-Fix-Commit: 49125ffc8e1674dc2a100dfdc5b78796f22e16f2 (2.38-213) +-Fix-Commit: ddcaed5dfb05b2c1a6ea842fd6b643501365450a (2.37-173) +-Fix-Commit: a6bf47887f24b2b394acb301a3189fda04bd4d4d (2.36-245) +-Fix-Commit: 66f0cb057c9b4fb1249a5fec6ef4a63511a37899 (2.35-400) +-Fix-Commit: 96863dee262225cfb79f9fe45e06fd188319c7b8 (2.34-526) +-Fix-Commit: d210011f1536c8322157cbb4fe4229b35c834c08 (2.33-276) +-Fix-Commit: 1bc1832cfc74c2a601220969f36e789a5e9f0ebe (2.32-152) +-Reported-by: Igor Morgenstern, Aisle Research +diff --git a/advisories/GLIBC-SA-2026-0003 b/advisories/GLIBC-SA-2026-0003 +deleted file mode 100644 +index b7a6e83a10..0000000000 +--- a/advisories/GLIBC-SA-2026-0003 ++++ /dev/null +@@ -1,36 +0,0 @@ +-wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory +- +-Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the +-GNU C Library version 2.0 to version 2.42 may cause the interface to +-return uninitialized memory in the we_wordv member, which on subsequent +-calls to wordfree may abort the process. +- +-The implementation of WRDE_REUSE in conjunction with WRDE_APPEND fails +-to clear the we_wordc member of the structure, and as such, when new +-words are added internally, a leading we_wordc count number of entries +-are skipped since they are assumed initialized. These skipped entries +-are not initialized, but are the contents of a realloc-expanded array of +-pointers. If the caller inspects the we_wordv array, it will +-dereference invalid pointers and crash. If the caller calls wordfree, +-the malloc implementation may detect the invalid pointers and abort the +-process. Calls to wordexp using WRDE_REUSE and WRDE_APPEND have never +-worked correctly and thus the existence of applications that make use of +-this feature is unlikely. +- +-CVE-Id: CVE-2025-15281 +-Public-Date: 2026-01-20 +-Vulnerable-Commit: 8f2ece695d8822e9ecc63ecd157e90bf17a6fe65 (1.93-260) +-Fix-Commit: 80cc58ea2de214f85b0a1d902a3b668ad2ecb302 (2.43) +-Fix-Commit: cbf39c26b25801e9bc88499b4fd361ac172d4125 (2.42-51) +-Fix-Commit: fb4db64a04ad6c96cd1fbb7e02eb59323b1f2ac2 (2.41-123) +-Fix-Commit: 9fe8576664d43b87ca19401fb6a975e217e47623 (2.40-218) +-Fix-Commit: ce65d944e38a20cb70af2a48a4b8aa5d8fabe1cc (2.39-288) +-Fix-Commit: d5409a1be010699794264162c551ba60f05ee6c3 (2.38-214) +-Fix-Commit: ff2b172803f6bbd897755d2ce83ec4323a1a15b3 (2.37-174) +-Fix-Commit: e97cfe2293ed097eb3d0b4c18274d22855e65130 (2.36-246) +-Fix-Commit: bb59339d02faebac534a87eea50c83c948f35b77 (2.35-401) +-Fix-Commit: 2b656ff94d72f93c84d8da2e7c76456c1994f02e (2.34-527) +-Fix-Commit: 1d8ed2067a8a5d162a07670d0d063429679f17a0 (2.33-277) +-Fix-Commit: 3a56c4ee4ea49b8f2391a2d8d6220013c4160a79 (2.32-153) +-Fix-Commit: 28eb5caf895ced5d895cb02757e109004a2d33e5 (2.31-167) +-Reported-by: Vitaly Simonovich +diff --git a/advisories/GLIBC-SA-2026-0004 b/advisories/GLIBC-SA-2026-0004 +deleted file mode 100644 +index fd630dc591..0000000000 +--- a/advisories/GLIBC-SA-2026-0004 ++++ /dev/null +@@ -1,30 +0,0 @@ +-nscd client crash on x86_64 under high nscd load +- +-Calling NSS-backed functions that support caching via nscd may call the +-nscd client side code and in the GNU C Library version 2.36 under high +-load on x86_64 systems, the client may call memcmp on inputs that are +-concurrently modified by other processes or threads and crash. +- +-The nscd client in the GNU C Library uses the memcmp function with +-inputs that may be concurrently modified by another thread, potentially +-resulting in spurious cache misses, which in itself is not a security +-issue. However in the GNU C Library version 2.36 an optimized +-implementation of memcmp was introduced for x86_64 which could crash +-when invoked with such undefined behaviour, turning this into a +-potential crash of the nscd client and the application that uses it. +-This implementation was backported to the 2.35 branch, making the nscd +-client in that branch vulnerable as well. Subsequently, the fix for +-this issue was backported to all vulnerable branches in the GNU C +-Library repository. +- +-It is advised that distributions that may have cherry-picked the memcpy +-SSE2 optimization in their copy of the GNU C Library, also apply the fix +-to avoid the potential crash in the nscd client. +- +-CVE-Id: CVE-2026-3904 +-Public-Date: 2026-03-11 +-Vulnerable-Commit: 8804157ad9da39631703b92315460808eac86b0c (2.36) +-Vulnerable-Commit: 5a8df6485c584e2b0e957ec6b9070437a724911a (2.35-89) +-Fix-Commit: b712be52645282c706a5faa038242504feb06db5 (2.37) +-Fix-Commit: 93967a2a7bbdcedb73e0b246713580c7c84d001e (2.36-84) +-Fix-Commit: 6bcd5d8e3668d52388a6e0580611749f93e6871f (2.35-230) +diff --git a/advisories/GLIBC-SA-2026-0005 b/advisories/GLIBC-SA-2026-0005 +deleted file mode 100644 +index 7a50a43263..0000000000 +--- a/advisories/GLIBC-SA-2026-0005 ++++ /dev/null +@@ -1,37 +0,0 @@ +-gethostbyaddr and gethostbyaddr_r may incorrectly handle DNS response +- +-Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf +-that specifies the library's DNS backend in the GNU C Library version +-2.34 to version 2.43 could, with a crafted response from the configured +-DNS server, result in a violation of the DNS specification that causes +-the application to treat a non-answer section of the DNS response as a +-valid answer. +- +-A defect in the getanswer_ptr function, which implements the iteration +-and extraction of the answer from the DNS response, can cause it to +-incorrectly transition from the answer section to the next section while +-still treating it as an answer to the question. This can happen when +-the answer contains only skipped records, and the subsequent section +-contains a semantically invalid T_PTR record. This is considered a +-security issue because it is a violation of the DNS specification that +-leads to incorrect behaviour that could result in the wrong hostname +-being returned to the caller. At the time of publication, no known +-affected DNS server returns results that would be incorrectly +-interpreted by the library. An attacker would either need to be network +-adjacent or have compromised the DNS server to use this defect to hide +-returned reverse DNS results from intrusion detection systems. Even +-then, the inbound connection from the attacker, or the outbound +-connection from the application, would be visible to the intrusion +-detection system. At best, the defect can be used to obfuscate and +-delay analysis of the evolving threat. +- +-CVE-Id: CVE-2026-4437 +-Public-Date: 2026-03-20 +-Vulnerable-Commit: 32e5db37684ffcbc6ae34fcc6cdcf28670506baa (2.34-323) +-Vulnerable-Commit: def97e7f71a07517810f7263213d607e08ad21f1 (2.35-188) +-Vulnerable-Commit: 77f523c473878ec0051582ef15161c6982879095 (2.36-30) +-Vulnerable-Commit: e32547d661a43da63368e488b6cfa9c53b4dcf92 (2.37) +-Fix-Commit: 5c6fca0c62ce5bd6e68e259f138097756cbafd4d (2.43-16) +-Fix-Commit: 9f5f18aab40ec6b61fa49a007615e6077e9a979b (2.44) +-Reported-by: Antonio Maini (0rbitingZer0) - 0rbitingZer0@proton.me +-Reported-by: Kevin Farrell +diff --git a/advisories/GLIBC-SA-2026-0006 b/advisories/GLIBC-SA-2026-0006 +deleted file mode 100644 +index 1ac70de4d9..0000000000 +--- a/advisories/GLIBC-SA-2026-0006 ++++ /dev/null +@@ -1,27 +0,0 @@ +-gethostbyaddr and gethostbyaddr_r return invalid DNS hostnames +- +-Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf +-that specifies the library's DNS backend in the GNU C library version +-2.34 to version 2.43 could result in an invalid DNS hostname being +-returned to the caller in violation of the DNS specification. +- +-A defect in the getanswer_ptr function, which implements the iteration +-and extraction of the answer from a DNS response, can cause it to accept +-an invalid DNS hostname that can contain shell metacharacters. An +-application that uses the returned hostname in a shell, without guarding +-for shell expansion, may be subject to shell injection attacks. At the +-time of publication, no known affected DNS server returns results with +-shell metacharacters in the results. An attacker would either need to +-be network adjacent or have compromised the DNS server to use this +-defect for shell injection. No known vulnerable application has been +-identified. +- +-CVE-Id: CVE-2026-4438 +-Public-Date: 2026-03-20 +-Vulnerable-Commit: 32e5db37684ffcbc6ae34fcc6cdcf28670506baa (2.34-323) +-Vulnerable-Commit: def97e7f71a07517810f7263213d607e08ad21f1 (2.35-188) +-Vulnerable-Commit: 77f523c473878ec0051582ef15161c6982879095 (2.36-30) +-Vulnerable-Commit: e32547d661a43da63368e488b6cfa9c53b4dcf92 (2.37) +-Fix-Commit: dd9945c0ba40d2dbc9eb7c99291ba6b69bd66718 (2.43-17) +-Fix-Commit: e10977481f4db4b2a3ce34fa4c3a1e26651ae312 (2.44) +-Reported-by: Antonio Maini (0rbitingZer0) - 0rbitingZer0@proton.me +diff --git a/advisories/GLIBC-SA-2026-0007 b/advisories/GLIBC-SA-2026-0007 +deleted file mode 100644 +index b880fb5544..0000000000 +--- a/advisories/GLIBC-SA-2026-0007 ++++ /dev/null +@@ -1,15 +0,0 @@ +-iconv crash due to assertion failure with untrusted input +- +-The iconv() function in the GNU C Library versions 2.43 and earlier may +-crash due to an assertion failure when converting inputs from the +-IBM1390 or IBM1399 character sets, which may be used to remotely crash +-an application. +- +-This vulnerability can be trivially mitigated by removing the IBM1390 +-and IBM1399 character sets from systems that do not need them. +- +-CVE-Id: CVE-2026-4046 +-Public-Date: 2026-03-12 +-Vulnerable-Commit: 0ecb606cb6cf65de1d9fc8a919bceb4be476c602 (2.3.3-1501) +-Fix-Commit: d6f08d1cf027f4eb2ba289a6cc66853722d4badc (2.44) +-Reported-by: Rocket Ma +diff --git a/advisories/GLIBC-SA-2026-0008 b/advisories/GLIBC-SA-2026-0008 +deleted file mode 100644 +index 43b38ce38a..0000000000 +--- a/advisories/GLIBC-SA-2026-0008 ++++ /dev/null +@@ -1,22 +0,0 @@ +-REJECTED: Static buffer overflow in deprecated nis_local_principal +- +-REJECTED: CVE-2026-5358 is rejected for two reasons. Firstly it has been +-discovered that no NIS+ client or server was ever released for any +-Linux-based OS distributions and as such this makes the API provisional +-and unused. Secondly it has been discovered that the NIS+ cold start +-cache (/var/nis/NIS_COLD_START) cannot be bypassed and as such the API +-can only be called with a trusted server from the pre-populated cache. +-The use of a trusted server means no trust boundary is crossed and this +-is therefore considered a normal bug. +- +-NIS+ support in the GNU C Library was never officially supported even +-though an incomplete implementation of the APIs was made pulibc. To the +-best knowledge of the glibc security team no open-source NIS+ server +-implementations were ever released for use with this API. Applications +-should not use any of the NIS+ APIs and should move to modern identity +-and access management services. +- +-CVE-Id: CVE-2026-5358 +-Public-Date: 2026-04-10 +-Rejected-Date: 2026-04-33 +-Reported-by: Rahul Hoysala +diff --git a/advisories/GLIBC-SA-2026-0009 b/advisories/GLIBC-SA-2026-0009 +deleted file mode 100644 +index 3c297fdc80..0000000000 +--- a/advisories/GLIBC-SA-2026-0009 ++++ /dev/null +@@ -1,23 +0,0 @@ +-scanf %mc off-by-one heap buffer overflow +- +-Calling the scanf family of functions with a %mc (malloc'd character +-match) in the GNU C Library version 2.7 to version 2.43 with a format +-width specifier with an explicit width greater than 1024 could result in +-a one byte heap buffer overflow. +- +-The bug is in the buffer growth formula in __vfscanf_internal, which +-under-allocates by one byte during realloc expansion, allowing a +-controlled single-byte overwrite past the end of the heap buffer. +- +-The impact is limited by the fact that to execute the overwrite you need +-both user controlled input data and a specific choice of maximum width +-that yields a smaller than needed allocation. The latter point has to +-take into account malloc's particular chunk size rounding process. The +-"%[width]mc" format specifier does not appear to have notable use in +-major Linux-based OS distributions, due to which the real world impact +-may be limited to bespoke use cases. +- +-CVE-Id: CVE-2026-5450 +-Public-Date: 2026-03-19 +-Vulnerable-Commit: 874aa52349cc111d1f6ea5dff24bb14c306714e0 (2.7) +-Reported-by: Rocket Ma +diff --git a/advisories/GLIBC-SA-2026-0010 b/advisories/GLIBC-SA-2026-0010 +deleted file mode 100644 +index ae9953fb71..0000000000 +--- a/advisories/GLIBC-SA-2026-0010 ++++ /dev/null +@@ -1,24 +0,0 @@ +-Potential buffer under-read in ungetwc +- +-Calling the ungetwc function on a FILE stream with wide characters +-encoded in a character set that has overlaps between its single byte and +-multi-byte character encodings, in the GNU C Library version 2.43 or +-earlier, may result in an attempt to read bytes before an allocated +-buffer, potentially resulting in unintentional disclosure of neighboring +-data in the heap, or a program crash. +- +-A bug in the wide character pushback implementation +-(_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate +-on the regular character buffer (fp->_IO_read_ptr) instead of the actual +-wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program +-crash may happen in cases where fp->_IO_read_ptr is not initialized and +-hence points to NULL. The buffer under-read requires a special situation +-where the input character encoding is such that there are overlaps +-between single byte representations and multibyte representations in +-that encoding, resulting in spurious matches. The spurious match case +-is not possible in the standard Unicode character sets. +- +-CVE-Id: CVE-2026-5928 +-Public-Date: 2026-03-17 +-Reported-by: Rocket Ma +-Vulnerable-Commit: d64b6ad07585b8a37e5fecc9a47fcee766d52ede (2.1.1-89) +diff --git a/advisories/GLIBC-SA-2026-0011 b/advisories/GLIBC-SA-2026-0011 +deleted file mode 100644 +index e492fa5507..0000000000 +--- a/advisories/GLIBC-SA-2026-0011 ++++ /dev/null +@@ -1,24 +0,0 @@ +-Potential buffer overflow in ns_sprintrrf TSIG handling path +- +-The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the +-GNU C Library version 2.2 and newer fail to enforce the caller-supplied +-buffer length, and can result in an out-of-bounds write when printing +-TSIG records. +- +-A defect in the TSIG case handling within ns_sprintrrf performs a +-formatted write using sprintf without checking the remaining buffer +-length, and may write up to 6 bytes past the end of the buffer. If the +-library is compiled with assertions, and the out-of-bounds write doesn't +-terminate the process, then a subsequent check for "len <= *buflen" will +-trigger an assertion failure. +- +-These functions are for application debugging only and hence not in the +-path of code executed by the DNS resolver. Further, they have been +-deprecated since version 2.34 (2021-08-02) and should not be used by any +-new applications. Applications should consider porting away from these +-interfaces since they may be removed in future versions. +- +-CVE-Id: CVE-2026-5435 +-Public-Date: 2026-04-02 +-Vulnerable-Commit: b43b13ac2544b11f35be301d1589b51a8473e32b (2.2) +-Reported-by: shinobu +diff --git a/advisories/GLIBC-SA-2026-0012 b/advisories/GLIBC-SA-2026-0012 +deleted file mode 100644 +index 22071d97a6..0000000000 +--- a/advisories/GLIBC-SA-2026-0012 ++++ /dev/null +@@ -1,18 +0,0 @@ +-Buffer overread in ns_printrrf with corrupted RDATA field +- +-The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the +-GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA +-content against the RDATA length in a DNS response when processing A6, +-CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a +-DNS response, causing a target application to crash or read +-uninitialized memory. +- +-These functions are for application debugging only and hence not in the +-path of code executed by the DNS resolver. Further, they have been +-deprecated since version 2.34 and should not be used by any new +-applications. Applications should consider porting away from these +-interfaces since they may be removed in future versions. +- +-CVE-Id: CVE-2026-6238 +-Public-Date: 2026-04-11 +-Vulnerable-Commit: ee188d555b8c32ad9704a7440cab400af967292f (1.90) +diff --git a/advisories/GLIBC-SA-2026-0013 b/advisories/GLIBC-SA-2026-0013 +deleted file mode 100644 +index 085a853434..0000000000 +--- a/advisories/GLIBC-SA-2026-0013 ++++ /dev/null +@@ -1,20 +0,0 @@ +-Potential stack-based buffer clash during tilde expansion in wordexp +- +-Calling wordexp with a tilde (~) followed by an overly long username +-in the GNU C Library version 2.2.3 to 2.43 may lead to a stack buffer +-clash. +- +-When expanding paths that begin with a tilde (~) followed by a username, the +-internal parse_tilde function extracts the username to determine the user's +-home directory. The implementation allocates memory for this username directly +-on the stack using the strndupa macro. Because the size of this allocation +-was determined by the length of the user-supplied input without any bounds +-checks, passing an excessively long username e.g. thousands of characters, +-forces the thread to exhaust its stack space. Thus if an application passes +-untrusted, attacker-controlled input to the wordexp function, an attacker +-can trigger a stack clash. +- +-CVE-Id: CVE-2026-6791 +-Public-Date: 2026-06-22 +-Vulnerable-Commit: 344af000e1d6e9c7882b9bc48e71cb3f1b5fc03c (2.2.3-114) +-Reported-by: storm +diff --git a/advisories/GLIBC-SA-2026-0014 b/advisories/GLIBC-SA-2026-0014 +deleted file mode 100644 +index 1e9a0039f0..0000000000 +--- a/advisories/GLIBC-SA-2026-0014 ++++ /dev/null +@@ -1,19 +0,0 @@ +-wordexp with WRDE_APPEND may result in an invalid call to free() +- +-Calling wordexp with WRDE_APPEND in conjunction with an invalid expansion +-(where an error like WRDE_BADCHAR would be returned) can create a stale +-address in the wordexp_t that can cause an invalid free from wordfree. +-This affects the GNU C Library version 2.0 to version 2.43. +- +-In WRDE_APPEND mode, wordexp saves the caller-visible wordexp_t state +-before appending the processing input. If the word expansion grows +-we_wordv via realloc, and realloc requires moving we_wordv to a new memory +-location (instead of expanding in-place), and the expansion later fails, +-the rollback fails to properly restore all previous we_wordv values and +-may add stale pointers into the caller-visible state. A subsequent +-wordfree may then issue an invalid call to free(). +- +-CVE-Id: CVE-2026-6368 +-Public-Date: 2026-07-14 +-Vulnerable-Commit: 8f2ece695d8822e9ecc63ecd157e90bf17a6fe65 (1.93-260) +-Reported-by: shinobu +diff --git a/advisories/README b/advisories/README +deleted file mode 100644 +index 330a31dff3..0000000000 +--- a/advisories/README ++++ /dev/null +@@ -1,92 +0,0 @@ +-GNU C Library Security Advisory Format +-====================================== +- +-Security advisories in this directory follow a simple git commit log +-format, with a heading and free-format description augmented with tags +-to allow parsing key information. References to code changes are +-specific to the glibc repository and follow a specific format: +- +- Tag-name: (release-version) +- +-The indicates a specific commit in the repository. The +-release-version indicates the publicly consumable release in which this +-commit is known to exist. The release-version is derived from the +-git-describe format, (i.e. stripped out from glibc-2.34.NNN-gxxxx) and +-is of the form 2.34-NNN. If the -NNN suffix is absent, it means that +-the change is in that release tarball, otherwise the change is on the +-release/2.YY/master branch and not in any released tarball. +- +-The following tags are currently being used: +- +-CVE-Id: +-This is the CVE-Id assigned under the CVE Program +-(https://www.cve.org/). +- +-Public-Date: +-The date this issue became publicly known. +- +-Rejected-Date: +-The most recent date the assigned advisory was rejected. If the advisory +-is ever published again the Rejected-Date tag should be removed. +- +-Vulnerable-Commit: +-The commit that introduced this vulnerability. There could be multiple +-entries, one for each release branch in the glibc repository; the +-release-version portion of this tag should tell you which branch this is +-on. +- +-Fix-Commit: +-The commit that fixed this vulnerability. There could be multiple +-entries for each release branch in the glibc repository, indicating that +-all of those commits contributed to fixing that issue in each of those +-branches. +- +-Reported-By: +-The entity that reported this issue. There could be multiple entries, one for +-each reporter. +- +-Adding an Advisory +------------------- +- +-An advisory for a CVE needs to be added on the master branch in two steps: +- +-1. Add the text of the advisory without any Fix-Commit tags along with +- the fix for the CVE. Add the Vulnerable-Commit tag, if applicable. +- The advisories directory does not exist in release branches, so keep +- the advisory text commit distinct from the code changes, to ease +- backports. Ask for the GLIBC-SA advisory number from the security +- team. +- +-2. Finish all backports on release branches and then back on the msater +- branch, add all commit refs to the advisory using the Fix-Commit +- tags. Don't bother adding the release-version subscript since the +- next step will overwrite it. +- +-3. Run the process-advisories.sh script in the scripts directory on the +- advisory: +- +- scripts/process-advisories.sh update GLIBC-SA-YYYY-NNNN +- +- (replace YYYY-NNNN with the actual advisory number). +- +-4. Verify the updated advisory and push the result. +- +-Rejecting an Advisory +---------------------- +- +-Rejecting an advisory on the master branch can be done in one step: +- +-1. Mark the advisory as rejected. Add the text "REJECTED: " as a prefix +- to any short-form description. Add a new paragraph that starts with +- "REJECTED: " and explains the reason for the rejection including +- justification for why it no longer has security impact. Lastly add +- a Rejected-Date tag to the advisory. +- +-Getting a NEWS snippet from advisories +--------------------------------------- +- +-Run: +- +- scripts/process-advisories.sh news +- +-and copy the content into the NEWS file. + +commit 1bd79651065b27c02c6502b9423124e54882058d +Author: Andreas K. Hüttel +Date: Sat Jul 25 09:21:33 2026 +0900 + + NEWS: start 2.44.1 section + + Signed-off-by: Andreas K. Hüttel + +diff --git a/NEWS b/NEWS +index ee28fadf49..1043343d70 100644 +--- a/NEWS ++++ b/NEWS +@@ -5,6 +5,10 @@ See the end for copying conditions. + Please send GNU C library bug reports via + using `glibc' in the "product" field. + ++Version 2.44.1 ++ ++The following bugs are resolved with this release: ++ + Version 2.44 + + Major new features: + +commit 0b05bc142249ac47e72be5cad5c37f33f4bb68d4 +Author: Samuel Thibault +Date: Fri Jul 24 23:10:02 2026 +0200 + + hurd: Make the readlink __fstatat64 references optional + + They may show up or not depending on the toolchain in use. + +diff --git a/sysdeps/mach/hurd/i386/localplt.data b/sysdeps/mach/hurd/i386/localplt.data +index 2befcd3748..5b9413422d 100644 +--- a/sysdeps/mach/hurd/i386/localplt.data ++++ b/sysdeps/mach/hurd/i386/localplt.data +@@ -25,14 +25,14 @@ ld.so: __writev + ld.so: __libc_lseek64 + ld.so: __mmap + ld.so: __fstat64 +-ld.so: __fstatat64 ++ld.so: __fstatat64 ? + ld.so: __stat64 + ld.so: __access + ld.so: __getpid + ld.so: __getcwd + ld.so: _exit ? + ld.so: abort +-ld.so: readlink ++ld.so: readlink ? + ld.so: _hurd_intr_rpc_mach_msg + ld.so: __errno_location + ld.so: _dl_init_first +diff --git a/sysdeps/mach/hurd/x86_64/localplt.data b/sysdeps/mach/hurd/x86_64/localplt.data +index fda28cd983..cc39118d12 100644 +--- a/sysdeps/mach/hurd/x86_64/localplt.data ++++ b/sysdeps/mach/hurd/x86_64/localplt.data +@@ -24,14 +24,14 @@ ld.so: __writev + ld.so: __libc_lseek64 + ld.so: __mmap + ld.so: __fstat64 +-ld.so: __fstatat64 ++ld.so: __fstatat64 ? + ld.so: __stat64 + ld.so: __access + ld.so: __getpid + ld.so: __getcwd + ld.so: _exit ? + ld.so: abort +-ld.so: readlink ++ld.so: readlink ? + ld.so: _hurd_intr_rpc_mach_msg + ld.so: __errno_location + ld.so: _dl_init_first + +commit c045fc61e8435c103ebfe06d01fec7f56503e2b4 +Author: Samuel Thibault +Date: Mon Jul 27 00:59:36 2026 +0200 + + hurd: fix fork's longjmp demangling on i386 + + i386's setjmp does not actually mangle ebp. + +diff --git a/sysdeps/mach/hurd/i386/longjmp-ts.c b/sysdeps/mach/hurd/i386/longjmp-ts.c +index 93450e86b4..340104b832 100644 +--- a/sysdeps/mach/hurd/i386/longjmp-ts.c ++++ b/sysdeps/mach/hurd/i386/longjmp-ts.c +@@ -38,7 +38,6 @@ _hurd_longjmp_thread_state (void *state, jmp_buf env, int val) + ts->eip = env[0].__jmpbuf[JB_PC]; + ts->eax = val ?: 1; + +- PTR_DEMANGLE (ts->ebp); + PTR_DEMANGLE (ts->uesp); + PTR_DEMANGLE (ts->eip); + } + +commit 7cba77790f3279bec3ac20e9c7632b021cd53f95 +Author: Adhemerval Zanella +Date: Mon Jul 27 13:37:19 2026 -0300 + + math: Fix sinh worst-case results for |x| > 36.736801 [BZ 34441] + + The CORE-MATH import mistranslated the accurate path result scaling + 'th *= sp.f' as 'th *= asuint64 (sp)' (commit 106f8c2ed68), and two of + the 51 exceptional-case table entries were dropped when the table was + moved to e_sinh_data.c (commit f05c4907a27). + + Checked on x86_64-linux-gnu and aarch64-linux-gnu. + + (cherry picked from commit fdc90dbb52b092f68cd5a4fac7a4cbd854c91bc3) + +diff --git a/NEWS b/NEWS +index 1043343d70..fe2b1d7f79 100644 +--- a/NEWS ++++ b/NEWS +@@ -8,6 +8,9 @@ using `glibc' in the "product" field. + Version 2.44.1 + + The following bugs are resolved with this release: ++ ++ [34441] math: math: sinh() returns wrong results for some inputs with ++ |x| > 36.736801 + + Version 2.44 + +diff --git a/math/auto-libm-test-in b/math/auto-libm-test-in +index ca670768a2..5c4d486af4 100644 +--- a/math/auto-libm-test-in ++++ b/math/auto-libm-test-in +@@ -9661,6 +9661,14 @@ sinh 0x2.c5d37700c6bb03a6c24b6c9b494cp+12 + sinh 0x2.c5d37700c6bb03a6c24b6c9b494ep+12 + # the next value generates larger error bounds on x86_64 (binary64) + sinh -0x1.633c62890fa14p+9 ++sinh 0x1.2b4f4e0bb49c9p+5 ++sinh -0x1.2b4f4e0bb49c9p+5 ++sinh 0x1.2ac43fb6d3abap+5 ++sinh -0x1.2ac43fb6d3abap+5 ++sinh 0x1.b7efa91915c95p-2 ++sinh -0x1.b7efa91915c95p-2 ++sinh 0x1.92a5c27afbe82p+4 ++sinh -0x1.92a5c27afbe82p+4 + + sinpi 0 + sinpi -0 +diff --git a/math/auto-libm-test-out-sinh b/math/auto-libm-test-out-sinh +index f96252b91c..91ab5c19fa 100644 +--- a/math/auto-libm-test-out-sinh ++++ b/math/auto-libm-test-out-sinh +@@ -6466,3 +6466,555 @@ sinh -0x1.633c62890fa14p+9 + = sinh tonearest ibm128 -0x2.c678c5121f428p+8 : -0xf.ef3a7e711d2c75a66ea3ca1c4p+1020 : inexact-ok + = sinh towardzero ibm128 -0x2.c678c5121f428p+8 : -0xf.ef3a7e711d2c75a66ea3ca1c4p+1020 : inexact-ok + = sinh upward ibm128 -0x2.c678c5121f428p+8 : -0xf.ef3a7e711d2c75a66ea3ca1c4p+1020 : inexact-ok ++sinh 0x1.2b4f4e0bb49c9p+5 ++= sinh downward binary32 0x2.569eap+4 : 0x1.f7c30ap+52 : inexact-ok ++= sinh tonearest binary32 0x2.569eap+4 : 0x1.f7c30ap+52 : inexact-ok ++= sinh towardzero binary32 0x2.569eap+4 : 0x1.f7c30ap+52 : inexact-ok ++= sinh upward binary32 0x2.569eap+4 : 0x1.f7c30cp+52 : inexact-ok ++= sinh downward binary64 0x2.569eap+4 : 0x1.f7c30a155eea3p+52 : inexact-ok ++= sinh tonearest binary64 0x2.569eap+4 : 0x1.f7c30a155eea4p+52 : inexact-ok ++= sinh towardzero binary64 0x2.569eap+4 : 0x1.f7c30a155eea3p+52 : inexact-ok ++= sinh upward binary64 0x2.569eap+4 : 0x1.f7c30a155eea4p+52 : inexact-ok ++= sinh downward intel96 0x2.569eap+4 : 0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh tonearest intel96 0x2.569eap+4 : 0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh towardzero intel96 0x2.569eap+4 : 0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh upward intel96 0x2.569eap+4 : 0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh downward m68k96 0x2.569eap+4 : 0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh tonearest m68k96 0x2.569eap+4 : 0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh towardzero m68k96 0x2.569eap+4 : 0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh upward m68k96 0x2.569eap+4 : 0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh downward binary128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84f52p+52 : inexact-ok ++= sinh tonearest binary128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84f52p+52 : inexact-ok ++= sinh towardzero binary128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84f52p+52 : inexact-ok ++= sinh upward binary128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84f53p+52 : inexact-ok ++= sinh downward ibm128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84fp+52 : inexact-ok ++= sinh tonearest ibm128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84f8p+52 : inexact-ok ++= sinh towardzero ibm128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84fp+52 : inexact-ok ++= sinh upward ibm128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84f8p+52 : inexact-ok ++= sinh downward binary32 0x2.569e9cp+4 : 0x1.f7c28cp+52 : inexact-ok ++= sinh tonearest binary32 0x2.569e9cp+4 : 0x1.f7c28cp+52 : inexact-ok ++= sinh towardzero binary32 0x2.569e9cp+4 : 0x1.f7c28cp+52 : inexact-ok ++= sinh upward binary32 0x2.569e9cp+4 : 0x1.f7c28ep+52 : inexact-ok ++= sinh downward binary64 0x2.569e9cp+4 : 0x1.f7c28c24ac22fp+52 : inexact-ok ++= sinh tonearest binary64 0x2.569e9cp+4 : 0x1.f7c28c24ac23p+52 : inexact-ok ++= sinh towardzero binary64 0x2.569e9cp+4 : 0x1.f7c28c24ac22fp+52 : inexact-ok ++= sinh upward binary64 0x2.569e9cp+4 : 0x1.f7c28c24ac23p+52 : inexact-ok ++= sinh downward intel96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh tonearest intel96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh towardzero intel96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh upward intel96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbcp+52 : inexact-ok ++= sinh downward m68k96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh tonearest m68k96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh towardzero m68k96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh upward m68k96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbcp+52 : inexact-ok ++= sinh downward binary128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd1ebp+52 : inexact-ok ++= sinh tonearest binary128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd1ebp+52 : inexact-ok ++= sinh towardzero binary128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd1ebp+52 : inexact-ok ++= sinh upward binary128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd1ecp+52 : inexact-ok ++= sinh downward ibm128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd18p+52 : inexact-ok ++= sinh tonearest ibm128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd2p+52 : inexact-ok ++= sinh towardzero ibm128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd18p+52 : inexact-ok ++= sinh upward ibm128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd2p+52 : inexact-ok ++= sinh downward binary64 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1dp+52 : inexact-ok ++= sinh tonearest binary64 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1ep+52 : inexact-ok ++= sinh towardzero binary64 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1dp+52 : inexact-ok ++= sinh upward binary64 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1ep+52 : inexact-ok ++= sinh downward intel96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh tonearest intel96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh towardzero intel96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh upward intel96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d802p+52 : inexact-ok ++= sinh downward m68k96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh tonearest m68k96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh towardzero m68k96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh upward m68k96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d802p+52 : inexact-ok ++= sinh downward binary128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000008f84p+52 : inexact-ok ++= sinh tonearest binary128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000008f85p+52 : inexact-ok ++= sinh towardzero binary128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000008f84p+52 : inexact-ok ++= sinh upward binary128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000008f85p+52 : inexact-ok ++= sinh downward ibm128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000008f8p+52 : inexact-ok ++= sinh tonearest ibm128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000008f8p+52 : inexact-ok ++= sinh towardzero ibm128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000008f8p+52 : inexact-ok ++= sinh upward ibm128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000009p+52 : inexact-ok ++sinh -0x1.2b4f4e0bb49c9p+5 ++= sinh downward binary32 -0x2.569e9cp+4 : -0x1.f7c28ep+52 : inexact-ok ++= sinh tonearest binary32 -0x2.569e9cp+4 : -0x1.f7c28cp+52 : inexact-ok ++= sinh towardzero binary32 -0x2.569e9cp+4 : -0x1.f7c28cp+52 : inexact-ok ++= sinh upward binary32 -0x2.569e9cp+4 : -0x1.f7c28cp+52 : inexact-ok ++= sinh downward binary64 -0x2.569e9cp+4 : -0x1.f7c28c24ac23p+52 : inexact-ok ++= sinh tonearest binary64 -0x2.569e9cp+4 : -0x1.f7c28c24ac23p+52 : inexact-ok ++= sinh towardzero binary64 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fp+52 : inexact-ok ++= sinh upward binary64 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fp+52 : inexact-ok ++= sinh downward intel96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbcp+52 : inexact-ok ++= sinh tonearest intel96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh towardzero intel96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh upward intel96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh downward m68k96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbcp+52 : inexact-ok ++= sinh tonearest m68k96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh towardzero m68k96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh upward m68k96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh downward binary128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd1ecp+52 : inexact-ok ++= sinh tonearest binary128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd1ebp+52 : inexact-ok ++= sinh towardzero binary128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd1ebp+52 : inexact-ok ++= sinh upward binary128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd1ebp+52 : inexact-ok ++= sinh downward ibm128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd2p+52 : inexact-ok ++= sinh tonearest ibm128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd2p+52 : inexact-ok ++= sinh towardzero ibm128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd18p+52 : inexact-ok ++= sinh upward ibm128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd18p+52 : inexact-ok ++= sinh downward binary32 -0x2.569eap+4 : -0x1.f7c30cp+52 : inexact-ok ++= sinh tonearest binary32 -0x2.569eap+4 : -0x1.f7c30ap+52 : inexact-ok ++= sinh towardzero binary32 -0x2.569eap+4 : -0x1.f7c30ap+52 : inexact-ok ++= sinh upward binary32 -0x2.569eap+4 : -0x1.f7c30ap+52 : inexact-ok ++= sinh downward binary64 -0x2.569eap+4 : -0x1.f7c30a155eea4p+52 : inexact-ok ++= sinh tonearest binary64 -0x2.569eap+4 : -0x1.f7c30a155eea4p+52 : inexact-ok ++= sinh towardzero binary64 -0x2.569eap+4 : -0x1.f7c30a155eea3p+52 : inexact-ok ++= sinh upward binary64 -0x2.569eap+4 : -0x1.f7c30a155eea3p+52 : inexact-ok ++= sinh downward intel96 -0x2.569eap+4 : -0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh tonearest intel96 -0x2.569eap+4 : -0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh towardzero intel96 -0x2.569eap+4 : -0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh upward intel96 -0x2.569eap+4 : -0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh downward m68k96 -0x2.569eap+4 : -0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh tonearest m68k96 -0x2.569eap+4 : -0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh towardzero m68k96 -0x2.569eap+4 : -0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh upward m68k96 -0x2.569eap+4 : -0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh downward binary128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84f53p+52 : inexact-ok ++= sinh tonearest binary128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84f52p+52 : inexact-ok ++= sinh towardzero binary128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84f52p+52 : inexact-ok ++= sinh upward binary128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84f52p+52 : inexact-ok ++= sinh downward ibm128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84f8p+52 : inexact-ok ++= sinh tonearest ibm128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84f8p+52 : inexact-ok ++= sinh towardzero ibm128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84fp+52 : inexact-ok ++= sinh upward ibm128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84fp+52 : inexact-ok ++= sinh downward binary64 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1ep+52 : inexact-ok ++= sinh tonearest binary64 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1ep+52 : inexact-ok ++= sinh towardzero binary64 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1dp+52 : inexact-ok ++= sinh upward binary64 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1dp+52 : inexact-ok ++= sinh downward intel96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d802p+52 : inexact-ok ++= sinh tonearest intel96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh towardzero intel96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh upward intel96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh downward m68k96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d802p+52 : inexact-ok ++= sinh tonearest m68k96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh towardzero m68k96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh upward m68k96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh downward binary128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000008f85p+52 : inexact-ok ++= sinh tonearest binary128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000008f85p+52 : inexact-ok ++= sinh towardzero binary128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000008f84p+52 : inexact-ok ++= sinh upward binary128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000008f84p+52 : inexact-ok ++= sinh downward ibm128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000009p+52 : inexact-ok ++= sinh tonearest ibm128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000008f8p+52 : inexact-ok ++= sinh towardzero ibm128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000008f8p+52 : inexact-ok ++= sinh upward ibm128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000008f8p+52 : inexact-ok ++sinh 0x1.2ac43fb6d3abap+5 ++= sinh downward binary32 0x2.55888p+4 : 0x1.d6b0ecp+52 : inexact-ok ++= sinh tonearest binary32 0x2.55888p+4 : 0x1.d6b0ecp+52 : inexact-ok ++= sinh towardzero binary32 0x2.55888p+4 : 0x1.d6b0ecp+52 : inexact-ok ++= sinh upward binary32 0x2.55888p+4 : 0x1.d6b0eep+52 : inexact-ok ++= sinh downward binary64 0x2.55888p+4 : 0x1.d6b0ecda100c2p+52 : inexact-ok ++= sinh tonearest binary64 0x2.55888p+4 : 0x1.d6b0ecda100c2p+52 : inexact-ok ++= sinh towardzero binary64 0x2.55888p+4 : 0x1.d6b0ecda100c2p+52 : inexact-ok ++= sinh upward binary64 0x2.55888p+4 : 0x1.d6b0ecda100c3p+52 : inexact-ok ++= sinh downward intel96 0x2.55888p+4 : 0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh tonearest intel96 0x2.55888p+4 : 0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh towardzero intel96 0x2.55888p+4 : 0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh upward intel96 0x2.55888p+4 : 0x1.d6b0ecda100c254p+52 : inexact-ok ++= sinh downward m68k96 0x2.55888p+4 : 0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh tonearest m68k96 0x2.55888p+4 : 0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh towardzero m68k96 0x2.55888p+4 : 0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh upward m68k96 0x2.55888p+4 : 0x1.d6b0ecda100c254p+52 : inexact-ok ++= sinh downward binary128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed6d8p+52 : inexact-ok ++= sinh tonearest binary128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed6d8p+52 : inexact-ok ++= sinh towardzero binary128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed6d8p+52 : inexact-ok ++= sinh upward binary128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed6d9p+52 : inexact-ok ++= sinh downward ibm128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed68p+52 : inexact-ok ++= sinh tonearest ibm128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed7p+52 : inexact-ok ++= sinh towardzero ibm128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed68p+52 : inexact-ok ++= sinh upward ibm128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed7p+52 : inexact-ok ++= sinh downward binary32 0x2.55887cp+4 : 0x1.d6b076p+52 : inexact-ok ++= sinh tonearest binary32 0x2.55887cp+4 : 0x1.d6b078p+52 : inexact-ok ++= sinh towardzero binary32 0x2.55887cp+4 : 0x1.d6b076p+52 : inexact-ok ++= sinh upward binary32 0x2.55887cp+4 : 0x1.d6b078p+52 : inexact-ok ++= sinh downward binary64 0x2.55887cp+4 : 0x1.d6b0772de38b2p+52 : inexact-ok ++= sinh tonearest binary64 0x2.55887cp+4 : 0x1.d6b0772de38b2p+52 : inexact-ok ++= sinh towardzero binary64 0x2.55887cp+4 : 0x1.d6b0772de38b2p+52 : inexact-ok ++= sinh upward binary64 0x2.55887cp+4 : 0x1.d6b0772de38b3p+52 : inexact-ok ++= sinh downward intel96 0x2.55887cp+4 : 0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh tonearest intel96 0x2.55887cp+4 : 0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh towardzero intel96 0x2.55887cp+4 : 0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh upward intel96 0x2.55887cp+4 : 0x1.d6b0772de38b276ap+52 : inexact-ok ++= sinh downward m68k96 0x2.55887cp+4 : 0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh tonearest m68k96 0x2.55887cp+4 : 0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh towardzero m68k96 0x2.55887cp+4 : 0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh upward m68k96 0x2.55887cp+4 : 0x1.d6b0772de38b276ap+52 : inexact-ok ++= sinh downward binary128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c261p+52 : inexact-ok ++= sinh tonearest binary128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c261p+52 : inexact-ok ++= sinh towardzero binary128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c261p+52 : inexact-ok ++= sinh upward binary128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c262p+52 : inexact-ok ++= sinh downward ibm128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c2p+52 : inexact-ok ++= sinh tonearest ibm128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c28p+52 : inexact-ok ++= sinh towardzero ibm128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c2p+52 : inexact-ok ++= sinh upward ibm128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c28p+52 : inexact-ok ++= sinh downward binary64 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65p+52 : inexact-ok ++= sinh tonearest binary64 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh towardzero binary64 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65p+52 : inexact-ok ++= sinh upward binary64 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh downward intel96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh tonearest intel96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh towardzero intel96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh upward intel96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh downward m68k96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh tonearest m68k96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh towardzero m68k96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh upward m68k96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh downward binary128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff289ep+52 : inexact-ok ++= sinh tonearest binary128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff289ep+52 : inexact-ok ++= sinh towardzero binary128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff289ep+52 : inexact-ok ++= sinh upward binary128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff289fp+52 : inexact-ok ++= sinh downward ibm128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff288p+52 : inexact-ok ++= sinh tonearest ibm128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff288p+52 : inexact-ok ++= sinh towardzero ibm128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff288p+52 : inexact-ok ++= sinh upward ibm128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff29p+52 : inexact-ok ++sinh -0x1.2ac43fb6d3abap+5 ++= sinh downward binary32 -0x2.55887cp+4 : -0x1.d6b078p+52 : inexact-ok ++= sinh tonearest binary32 -0x2.55887cp+4 : -0x1.d6b078p+52 : inexact-ok ++= sinh towardzero binary32 -0x2.55887cp+4 : -0x1.d6b076p+52 : inexact-ok ++= sinh upward binary32 -0x2.55887cp+4 : -0x1.d6b076p+52 : inexact-ok ++= sinh downward binary64 -0x2.55887cp+4 : -0x1.d6b0772de38b3p+52 : inexact-ok ++= sinh tonearest binary64 -0x2.55887cp+4 : -0x1.d6b0772de38b2p+52 : inexact-ok ++= sinh towardzero binary64 -0x2.55887cp+4 : -0x1.d6b0772de38b2p+52 : inexact-ok ++= sinh upward binary64 -0x2.55887cp+4 : -0x1.d6b0772de38b2p+52 : inexact-ok ++= sinh downward intel96 -0x2.55887cp+4 : -0x1.d6b0772de38b276ap+52 : inexact-ok ++= sinh tonearest intel96 -0x2.55887cp+4 : -0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh towardzero intel96 -0x2.55887cp+4 : -0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh upward intel96 -0x2.55887cp+4 : -0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh downward m68k96 -0x2.55887cp+4 : -0x1.d6b0772de38b276ap+52 : inexact-ok ++= sinh tonearest m68k96 -0x2.55887cp+4 : -0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh towardzero m68k96 -0x2.55887cp+4 : -0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh upward m68k96 -0x2.55887cp+4 : -0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh downward binary128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c262p+52 : inexact-ok ++= sinh tonearest binary128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c261p+52 : inexact-ok ++= sinh towardzero binary128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c261p+52 : inexact-ok ++= sinh upward binary128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c261p+52 : inexact-ok ++= sinh downward ibm128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c28p+52 : inexact-ok ++= sinh tonearest ibm128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c28p+52 : inexact-ok ++= sinh towardzero ibm128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c2p+52 : inexact-ok ++= sinh upward ibm128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c2p+52 : inexact-ok ++= sinh downward binary32 -0x2.55888p+4 : -0x1.d6b0eep+52 : inexact-ok ++= sinh tonearest binary32 -0x2.55888p+4 : -0x1.d6b0ecp+52 : inexact-ok ++= sinh towardzero binary32 -0x2.55888p+4 : -0x1.d6b0ecp+52 : inexact-ok ++= sinh upward binary32 -0x2.55888p+4 : -0x1.d6b0ecp+52 : inexact-ok ++= sinh downward binary64 -0x2.55888p+4 : -0x1.d6b0ecda100c3p+52 : inexact-ok ++= sinh tonearest binary64 -0x2.55888p+4 : -0x1.d6b0ecda100c2p+52 : inexact-ok ++= sinh towardzero binary64 -0x2.55888p+4 : -0x1.d6b0ecda100c2p+52 : inexact-ok ++= sinh upward binary64 -0x2.55888p+4 : -0x1.d6b0ecda100c2p+52 : inexact-ok ++= sinh downward intel96 -0x2.55888p+4 : -0x1.d6b0ecda100c254p+52 : inexact-ok ++= sinh tonearest intel96 -0x2.55888p+4 : -0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh towardzero intel96 -0x2.55888p+4 : -0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh upward intel96 -0x2.55888p+4 : -0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh downward m68k96 -0x2.55888p+4 : -0x1.d6b0ecda100c254p+52 : inexact-ok ++= sinh tonearest m68k96 -0x2.55888p+4 : -0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh towardzero m68k96 -0x2.55888p+4 : -0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh upward m68k96 -0x2.55888p+4 : -0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh downward binary128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed6d9p+52 : inexact-ok ++= sinh tonearest binary128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed6d8p+52 : inexact-ok ++= sinh towardzero binary128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed6d8p+52 : inexact-ok ++= sinh upward binary128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed6d8p+52 : inexact-ok ++= sinh downward ibm128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed7p+52 : inexact-ok ++= sinh tonearest ibm128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed7p+52 : inexact-ok ++= sinh towardzero ibm128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed68p+52 : inexact-ok ++= sinh upward ibm128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed68p+52 : inexact-ok ++= sinh downward binary64 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh tonearest binary64 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh towardzero binary64 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65p+52 : inexact-ok ++= sinh upward binary64 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65p+52 : inexact-ok ++= sinh downward intel96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh tonearest intel96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh towardzero intel96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh upward intel96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh downward m68k96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh tonearest m68k96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh towardzero m68k96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh upward m68k96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh downward binary128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff289fp+52 : inexact-ok ++= sinh tonearest binary128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff289ep+52 : inexact-ok ++= sinh towardzero binary128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff289ep+52 : inexact-ok ++= sinh upward binary128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff289ep+52 : inexact-ok ++= sinh downward ibm128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff29p+52 : inexact-ok ++= sinh tonearest ibm128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff288p+52 : inexact-ok ++= sinh towardzero ibm128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff288p+52 : inexact-ok ++= sinh upward ibm128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff288p+52 : inexact-ok ++sinh 0x1.b7efa91915c95p-2 ++= sinh downward binary32 0x6.dfbea8p-4 : 0x7.1661a8p-4 : inexact-ok ++= sinh tonearest binary32 0x6.dfbea8p-4 : 0x7.1661a8p-4 : inexact-ok ++= sinh towardzero binary32 0x6.dfbea8p-4 : 0x7.1661a8p-4 : inexact-ok ++= sinh upward binary32 0x6.dfbea8p-4 : 0x7.1661bp-4 : inexact-ok ++= sinh downward binary64 0x6.dfbea8p-4 : 0x7.1661abb8260e4p-4 : inexact-ok ++= sinh tonearest binary64 0x6.dfbea8p-4 : 0x7.1661abb8260e8p-4 : inexact-ok ++= sinh towardzero binary64 0x6.dfbea8p-4 : 0x7.1661abb8260e4p-4 : inexact-ok ++= sinh upward binary64 0x6.dfbea8p-4 : 0x7.1661abb8260e8p-4 : inexact-ok ++= sinh downward intel96 0x6.dfbea8p-4 : 0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh tonearest intel96 0x6.dfbea8p-4 : 0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh towardzero intel96 0x6.dfbea8p-4 : 0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh upward intel96 0x6.dfbea8p-4 : 0x7.1661abb8260e76bp-4 : inexact-ok ++= sinh downward m68k96 0x6.dfbea8p-4 : 0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh tonearest m68k96 0x6.dfbea8p-4 : 0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh towardzero m68k96 0x6.dfbea8p-4 : 0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh upward m68k96 0x6.dfbea8p-4 : 0x7.1661abb8260e76bp-4 : inexact-ok ++= sinh downward binary128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ebed4p-4 : inexact-ok ++= sinh tonearest binary128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ebed8p-4 : inexact-ok ++= sinh towardzero binary128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ebed4p-4 : inexact-ok ++= sinh upward binary128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ebed8p-4 : inexact-ok ++= sinh downward ibm128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ebep-4 : inexact-ok ++= sinh tonearest ibm128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ebep-4 : inexact-ok ++= sinh towardzero ibm128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ebep-4 : inexact-ok ++= sinh upward ibm128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ecp-4 : inexact-ok ++= sinh downward binary32 0x6.dfbeap-4 : 0x7.1661ap-4 : inexact-ok ++= sinh tonearest binary32 0x6.dfbeap-4 : 0x7.1661ap-4 : inexact-ok ++= sinh towardzero binary32 0x6.dfbeap-4 : 0x7.1661ap-4 : inexact-ok ++= sinh upward binary32 0x6.dfbeap-4 : 0x7.1661a8p-4 : inexact-ok ++= sinh downward binary64 0x6.dfbeap-4 : 0x7.1661a2f837414p-4 : inexact-ok ++= sinh tonearest binary64 0x6.dfbeap-4 : 0x7.1661a2f837418p-4 : inexact-ok ++= sinh towardzero binary64 0x6.dfbeap-4 : 0x7.1661a2f837414p-4 : inexact-ok ++= sinh upward binary64 0x6.dfbeap-4 : 0x7.1661a2f837418p-4 : inexact-ok ++= sinh downward intel96 0x6.dfbeap-4 : 0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh tonearest intel96 0x6.dfbeap-4 : 0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh towardzero intel96 0x6.dfbeap-4 : 0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh upward intel96 0x6.dfbeap-4 : 0x7.1661a2f837416e98p-4 : inexact-ok ++= sinh downward m68k96 0x6.dfbeap-4 : 0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh tonearest m68k96 0x6.dfbeap-4 : 0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh towardzero m68k96 0x6.dfbeap-4 : 0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh upward m68k96 0x6.dfbeap-4 : 0x7.1661a2f837416e98p-4 : inexact-ok ++= sinh downward binary128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d4c8p-4 : inexact-ok ++= sinh tonearest binary128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d4c8p-4 : inexact-ok ++= sinh towardzero binary128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d4c8p-4 : inexact-ok ++= sinh upward binary128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d4ccp-4 : inexact-ok ++= sinh downward ibm128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d4p-4 : inexact-ok ++= sinh tonearest ibm128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d4p-4 : inexact-ok ++= sinh towardzero ibm128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d4p-4 : inexact-ok ++= sinh upward ibm128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d6p-4 : inexact-ok ++= sinh downward binary64 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed208p-4 : inexact-ok ++= sinh tonearest binary64 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh towardzero binary64 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed208p-4 : inexact-ok ++= sinh upward binary64 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh downward intel96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh tonearest intel96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh towardzero intel96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh upward intel96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh downward m68k96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh tonearest m68k96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh towardzero m68k96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh upward m68k96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh downward binary128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffeb44p-4 : inexact-ok ++= sinh tonearest binary128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffeb48p-4 : inexact-ok ++= sinh towardzero binary128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffeb44p-4 : inexact-ok ++= sinh upward binary128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffeb48p-4 : inexact-ok ++= sinh downward ibm128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffeap-4 : inexact-ok ++= sinh tonearest ibm128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffecp-4 : inexact-ok ++= sinh towardzero ibm128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffeap-4 : inexact-ok ++= sinh upward ibm128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffecp-4 : inexact-ok ++sinh -0x1.b7efa91915c95p-2 ++= sinh downward binary32 -0x6.dfbeap-4 : -0x7.1661a8p-4 : inexact-ok ++= sinh tonearest binary32 -0x6.dfbeap-4 : -0x7.1661ap-4 : inexact-ok ++= sinh towardzero binary32 -0x6.dfbeap-4 : -0x7.1661ap-4 : inexact-ok ++= sinh upward binary32 -0x6.dfbeap-4 : -0x7.1661ap-4 : inexact-ok ++= sinh downward binary64 -0x6.dfbeap-4 : -0x7.1661a2f837418p-4 : inexact-ok ++= sinh tonearest binary64 -0x6.dfbeap-4 : -0x7.1661a2f837418p-4 : inexact-ok ++= sinh towardzero binary64 -0x6.dfbeap-4 : -0x7.1661a2f837414p-4 : inexact-ok ++= sinh upward binary64 -0x6.dfbeap-4 : -0x7.1661a2f837414p-4 : inexact-ok ++= sinh downward intel96 -0x6.dfbeap-4 : -0x7.1661a2f837416e98p-4 : inexact-ok ++= sinh tonearest intel96 -0x6.dfbeap-4 : -0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh towardzero intel96 -0x6.dfbeap-4 : -0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh upward intel96 -0x6.dfbeap-4 : -0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh downward m68k96 -0x6.dfbeap-4 : -0x7.1661a2f837416e98p-4 : inexact-ok ++= sinh tonearest m68k96 -0x6.dfbeap-4 : -0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh towardzero m68k96 -0x6.dfbeap-4 : -0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh upward m68k96 -0x6.dfbeap-4 : -0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh downward binary128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d4ccp-4 : inexact-ok ++= sinh tonearest binary128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d4c8p-4 : inexact-ok ++= sinh towardzero binary128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d4c8p-4 : inexact-ok ++= sinh upward binary128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d4c8p-4 : inexact-ok ++= sinh downward ibm128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d6p-4 : inexact-ok ++= sinh tonearest ibm128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d4p-4 : inexact-ok ++= sinh towardzero ibm128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d4p-4 : inexact-ok ++= sinh upward ibm128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d4p-4 : inexact-ok ++= sinh downward binary32 -0x6.dfbea8p-4 : -0x7.1661bp-4 : inexact-ok ++= sinh tonearest binary32 -0x6.dfbea8p-4 : -0x7.1661a8p-4 : inexact-ok ++= sinh towardzero binary32 -0x6.dfbea8p-4 : -0x7.1661a8p-4 : inexact-ok ++= sinh upward binary32 -0x6.dfbea8p-4 : -0x7.1661a8p-4 : inexact-ok ++= sinh downward binary64 -0x6.dfbea8p-4 : -0x7.1661abb8260e8p-4 : inexact-ok ++= sinh tonearest binary64 -0x6.dfbea8p-4 : -0x7.1661abb8260e8p-4 : inexact-ok ++= sinh towardzero binary64 -0x6.dfbea8p-4 : -0x7.1661abb8260e4p-4 : inexact-ok ++= sinh upward binary64 -0x6.dfbea8p-4 : -0x7.1661abb8260e4p-4 : inexact-ok ++= sinh downward intel96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76bp-4 : inexact-ok ++= sinh tonearest intel96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh towardzero intel96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh upward intel96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh downward m68k96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76bp-4 : inexact-ok ++= sinh tonearest m68k96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh towardzero m68k96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh upward m68k96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh downward binary128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ebed8p-4 : inexact-ok ++= sinh tonearest binary128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ebed8p-4 : inexact-ok ++= sinh towardzero binary128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ebed4p-4 : inexact-ok ++= sinh upward binary128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ebed4p-4 : inexact-ok ++= sinh downward ibm128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ecp-4 : inexact-ok ++= sinh tonearest ibm128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ebep-4 : inexact-ok ++= sinh towardzero ibm128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ebep-4 : inexact-ok ++= sinh upward ibm128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ebep-4 : inexact-ok ++= sinh downward binary64 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh tonearest binary64 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh towardzero binary64 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed208p-4 : inexact-ok ++= sinh upward binary64 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed208p-4 : inexact-ok ++= sinh downward intel96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh tonearest intel96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh towardzero intel96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh upward intel96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh downward m68k96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh tonearest m68k96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh towardzero m68k96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh upward m68k96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh downward binary128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffeb48p-4 : inexact-ok ++= sinh tonearest binary128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffeb48p-4 : inexact-ok ++= sinh towardzero binary128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffeb44p-4 : inexact-ok ++= sinh upward binary128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffeb44p-4 : inexact-ok ++= sinh downward ibm128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffecp-4 : inexact-ok ++= sinh tonearest ibm128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffecp-4 : inexact-ok ++= sinh towardzero ibm128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffeap-4 : inexact-ok ++= sinh upward ibm128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffeap-4 : inexact-ok ++sinh 0x1.92a5c27afbe82p+4 ++= sinh downward binary32 0x1.92a5c4p+4 : 0x9.e410bp+32 : inexact-ok ++= sinh tonearest binary32 0x1.92a5c4p+4 : 0x9.e410cp+32 : inexact-ok ++= sinh towardzero binary32 0x1.92a5c4p+4 : 0x9.e410bp+32 : inexact-ok ++= sinh upward binary32 0x1.92a5c4p+4 : 0x9.e410cp+32 : inexact-ok ++= sinh downward binary64 0x1.92a5c4p+4 : 0x9.e410bd8d8c85p+32 : inexact-ok ++= sinh tonearest binary64 0x1.92a5c4p+4 : 0x9.e410bd8d8c85p+32 : inexact-ok ++= sinh towardzero binary64 0x1.92a5c4p+4 : 0x9.e410bd8d8c85p+32 : inexact-ok ++= sinh upward binary64 0x1.92a5c4p+4 : 0x9.e410bd8d8c858p+32 : inexact-ok ++= sinh downward intel96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh tonearest intel96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh towardzero intel96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh upward intel96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh downward m68k96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh tonearest m68k96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh towardzero m68k96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh upward m68k96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh downward binary128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60e85p+32 : inexact-ok ++= sinh tonearest binary128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60e858p+32 : inexact-ok ++= sinh towardzero binary128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60e85p+32 : inexact-ok ++= sinh upward binary128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60e858p+32 : inexact-ok ++= sinh downward ibm128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60e8p+32 : inexact-ok ++= sinh tonearest ibm128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60e8p+32 : inexact-ok ++= sinh towardzero ibm128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60e8p+32 : inexact-ok ++= sinh upward ibm128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60ecp+32 : inexact-ok ++= sinh downward binary32 0x1.92a5c2p+4 : 0x9.e40f8p+32 : inexact-ok ++= sinh tonearest binary32 0x1.92a5c2p+4 : 0x9.e40f8p+32 : inexact-ok ++= sinh towardzero binary32 0x1.92a5c2p+4 : 0x9.e40f8p+32 : inexact-ok ++= sinh upward binary32 0x1.92a5c2p+4 : 0x9.e40f9p+32 : inexact-ok ++= sinh downward binary64 0x1.92a5c2p+4 : 0x9.e40f810b889bp+32 : inexact-ok ++= sinh tonearest binary64 0x1.92a5c2p+4 : 0x9.e40f810b889b8p+32 : inexact-ok ++= sinh towardzero binary64 0x1.92a5c2p+4 : 0x9.e40f810b889bp+32 : inexact-ok ++= sinh upward binary64 0x1.92a5c2p+4 : 0x9.e40f810b889b8p+32 : inexact-ok ++= sinh downward intel96 0x1.92a5c2p+4 : 0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh tonearest intel96 0x1.92a5c2p+4 : 0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh towardzero intel96 0x1.92a5c2p+4 : 0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh upward intel96 0x1.92a5c2p+4 : 0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh downward m68k96 0x1.92a5c2p+4 : 0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh tonearest m68k96 0x1.92a5c2p+4 : 0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh towardzero m68k96 0x1.92a5c2p+4 : 0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh upward m68k96 0x1.92a5c2p+4 : 0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh downward binary128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa46p+32 : inexact-ok ++= sinh tonearest binary128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa46p+32 : inexact-ok ++= sinh towardzero binary128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa46p+32 : inexact-ok ++= sinh upward binary128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa468p+32 : inexact-ok ++= sinh downward ibm128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa4p+32 : inexact-ok ++= sinh tonearest ibm128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa4p+32 : inexact-ok ++= sinh towardzero ibm128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa4p+32 : inexact-ok ++= sinh upward ibm128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa8p+32 : inexact-ok ++= sinh downward binary64 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh tonearest binary64 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh towardzero binary64 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh upward binary64 0x1.92a5c27afbe82p+4 : 0x9.e40fcd12392ap+32 : inexact-ok ++= sinh downward intel96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh tonearest intel96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh towardzero intel96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh upward intel96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd123929801p+32 : inexact-ok ++= sinh downward m68k96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh tonearest m68k96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh towardzero m68k96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh upward m68k96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd123929801p+32 : inexact-ok ++= sinh downward binary128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298000000000002118p+32 : inexact-ok ++= sinh tonearest binary128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd123929800000000000212p+32 : inexact-ok ++= sinh towardzero binary128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298000000000002118p+32 : inexact-ok ++= sinh upward binary128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd123929800000000000212p+32 : inexact-ok ++= sinh downward ibm128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298000000000002p+32 : inexact-ok ++= sinh tonearest ibm128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298000000000002p+32 : inexact-ok ++= sinh towardzero ibm128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298000000000002p+32 : inexact-ok ++= sinh upward ibm128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd12392980000000000024p+32 : inexact-ok ++sinh -0x1.92a5c27afbe82p+4 ++= sinh downward binary32 -0x1.92a5c2p+4 : -0x9.e40f9p+32 : inexact-ok ++= sinh tonearest binary32 -0x1.92a5c2p+4 : -0x9.e40f8p+32 : inexact-ok ++= sinh towardzero binary32 -0x1.92a5c2p+4 : -0x9.e40f8p+32 : inexact-ok ++= sinh upward binary32 -0x1.92a5c2p+4 : -0x9.e40f8p+32 : inexact-ok ++= sinh downward binary64 -0x1.92a5c2p+4 : -0x9.e40f810b889b8p+32 : inexact-ok ++= sinh tonearest binary64 -0x1.92a5c2p+4 : -0x9.e40f810b889b8p+32 : inexact-ok ++= sinh towardzero binary64 -0x1.92a5c2p+4 : -0x9.e40f810b889bp+32 : inexact-ok ++= sinh upward binary64 -0x1.92a5c2p+4 : -0x9.e40f810b889bp+32 : inexact-ok ++= sinh downward intel96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh tonearest intel96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh towardzero intel96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh upward intel96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh downward m68k96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh tonearest m68k96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh towardzero m68k96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh upward m68k96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh downward binary128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa468p+32 : inexact-ok ++= sinh tonearest binary128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa46p+32 : inexact-ok ++= sinh towardzero binary128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa46p+32 : inexact-ok ++= sinh upward binary128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa46p+32 : inexact-ok ++= sinh downward ibm128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa8p+32 : inexact-ok ++= sinh tonearest ibm128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa4p+32 : inexact-ok ++= sinh towardzero ibm128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa4p+32 : inexact-ok ++= sinh upward ibm128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa4p+32 : inexact-ok ++= sinh downward binary32 -0x1.92a5c4p+4 : -0x9.e410cp+32 : inexact-ok ++= sinh tonearest binary32 -0x1.92a5c4p+4 : -0x9.e410cp+32 : inexact-ok ++= sinh towardzero binary32 -0x1.92a5c4p+4 : -0x9.e410bp+32 : inexact-ok ++= sinh upward binary32 -0x1.92a5c4p+4 : -0x9.e410bp+32 : inexact-ok ++= sinh downward binary64 -0x1.92a5c4p+4 : -0x9.e410bd8d8c858p+32 : inexact-ok ++= sinh tonearest binary64 -0x1.92a5c4p+4 : -0x9.e410bd8d8c85p+32 : inexact-ok ++= sinh towardzero binary64 -0x1.92a5c4p+4 : -0x9.e410bd8d8c85p+32 : inexact-ok ++= sinh upward binary64 -0x1.92a5c4p+4 : -0x9.e410bd8d8c85p+32 : inexact-ok ++= sinh downward intel96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh tonearest intel96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh towardzero intel96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh upward intel96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh downward m68k96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh tonearest m68k96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh towardzero m68k96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh upward m68k96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh downward binary128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60e858p+32 : inexact-ok ++= sinh tonearest binary128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60e858p+32 : inexact-ok ++= sinh towardzero binary128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60e85p+32 : inexact-ok ++= sinh upward binary128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60e85p+32 : inexact-ok ++= sinh downward ibm128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60ecp+32 : inexact-ok ++= sinh tonearest ibm128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60e8p+32 : inexact-ok ++= sinh towardzero ibm128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60e8p+32 : inexact-ok ++= sinh upward ibm128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60e8p+32 : inexact-ok ++= sinh downward binary64 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd12392ap+32 : inexact-ok ++= sinh tonearest binary64 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh towardzero binary64 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh upward binary64 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh downward intel96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd123929801p+32 : inexact-ok ++= sinh tonearest intel96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh towardzero intel96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh upward intel96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh downward m68k96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd123929801p+32 : inexact-ok ++= sinh tonearest m68k96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh towardzero m68k96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh upward m68k96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh downward binary128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd123929800000000000212p+32 : inexact-ok ++= sinh tonearest binary128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd123929800000000000212p+32 : inexact-ok ++= sinh towardzero binary128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298000000000002118p+32 : inexact-ok ++= sinh upward binary128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298000000000002118p+32 : inexact-ok ++= sinh downward ibm128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd12392980000000000024p+32 : inexact-ok ++= sinh tonearest ibm128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298000000000002p+32 : inexact-ok ++= sinh towardzero ibm128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298000000000002p+32 : inexact-ok ++= sinh upward ibm128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298000000000002p+32 : inexact-ok +diff --git a/sysdeps/ieee754/dbl-64/e_sinh.c b/sysdeps/ieee754/dbl-64/e_sinh.c +index 1643f3f504..638e3d6a6d 100644 +--- a/sysdeps/ieee754/dbl-64/e_sinh.c ++++ b/sysdeps/ieee754/dbl-64/e_sinh.c +@@ -213,7 +213,7 @@ __sinh (double x) + ml = (ul + 8) & MANTISSA_MASK; + th += tl; + th *= 2; +- th *= asuint64 (sp); ++ th *= sp; + if (ml <= 16 || eh - el > 103) + return as_sinh_database (x, th); + return th; +diff --git a/sysdeps/ieee754/dbl-64/e_sinh_data.c b/sysdeps/ieee754/dbl-64/e_sinh_data.c +index ca61e311f1..d4fd41d934 100644 +--- a/sysdeps/ieee754/dbl-64/e_sinh_data.c ++++ b/sysdeps/ieee754/dbl-64/e_sinh_data.c +@@ -35,12 +35,13 @@ const double __sinh_data_ch[][2] = + { 0x1.ae64567f54482p-26, -0x1.defcf17a6ab79p-81 } + }; + +-const double __sinh_data_db[49][3] = ++const double __sinh_data_db[51][3] = + { + { 0x1.364303e1ad8f6p-2, 0x1.3b07e0c779ddap-2, -0x1.bcp-106 }, + { 0x1.4169f234f23b9p-2, 0x1.46b7b3b358f99p-2, -0x1p-56 }, + { 0x1.616cc75d49226p-2, 0x1.687bd068c1c1ep-2, 0x1.ap-111 }, + { 0x1.ae3773250e7d2p-2, 0x1.bafc3479fc9ccp-2, -0x1p-105 }, ++ { 0x1.b7efa91915c95p-2, 0x1.c59869f17b483p-2, -0x1p-104 }, + { 0x1.d68039861ab53p-2, 0x1.e73b46abb01e1p-2, -0x1.2p-109 }, + { 0x1.e90f16eb88c09p-2, 0x1.fbdd4a37760b7p-2, -0x1.f8p-108 }, + { 0x1.a3fc7e4dd47d1p-1, 0x1.d4b21ebf542fp-1, 0x1.ep-107 }, +@@ -62,6 +63,7 @@ const double __sinh_data_db[49][3] = + { 0x1.43a81752eabe7p+3, 0x1.81d364845ecfap+13, -0x1p-90 }, + { 0x1.16369cd53bb69p+4, 0x1.0fbc6c02b1c9p+24, -0x1.9p-81 }, + { 0x1.20e29ea8b51e2p+4, 0x1.08b8abba28abcp+25, 0x1.9bp-79 }, ++ { 0x1.92a5c27afbe82p+4, 0x1.3c81f9a247253p+35, 0x1p-67 }, + { 0x1.a1e4f11b513d7p+4, 0x1.9a65b6c2e2185p+36, -0x1.bcp-70 }, + { 0x1.c089fcf166171p+4, 0x1.5c452e0e37569p+39, 0x1.4p-69 }, + { 0x1.e42a98b3a0be5p+4, 0x1.938768ca4f8aap+42, 0x1.6dp-62 }, +diff --git a/sysdeps/ieee754/dbl-64/e_sinh_data.h b/sysdeps/ieee754/dbl-64/e_sinh_data.h +index 16f7e0da5a..c34848fd54 100644 +--- a/sysdeps/ieee754/dbl-64/e_sinh_data.h ++++ b/sysdeps/ieee754/dbl-64/e_sinh_data.h +@@ -29,7 +29,7 @@ SOFTWARE. + + extern const double __sinh_data_ch[][2] attribute_hidden; + #define CH __sinh_data_ch +-extern const double __sinh_data_db[49][3] attribute_hidden; ++extern const double __sinh_data_db[51][3] attribute_hidden; + #define DB __sinh_data_db + + #endif + +commit 0b58f5d80d24cf83cfde9d8381aafb11fef0e152 +Author: Adhemerval Zanella +Date: Thu Jul 30 08:55:54 2026 -0300 + + math: Fix x86_64 tanh _FloatN aliases binding to the FMA variant [BZ 34465] + + The generic implementation emits libm_alias_double unconditionally, so + tanhf32x and tanhf64 bind directly to __tanh_fma. + + Guard the alias with '#ifndef __tanh' and emit it from the dispatcher, + as sin. Also remove the stale __expm1 defines, unused since tanh moved + to CORE-MATH. + + Checked on x86_64-linux-gnu, and with 'qemu-x86_64 -cpu Nehalem'. + + Reported-by: Michael Brunnbauer + + (cherry picked from commit b01abba04a954cbd6b2834c0643a08685a915fe5) + +diff --git a/NEWS b/NEWS +index fe2b1d7f79..43667c1963 100644 +--- a/NEWS ++++ b/NEWS +@@ -11,6 +11,7 @@ The following bugs are resolved with this release: + + [34441] math: math: sinh() returns wrong results for some inputs with + |x| > 36.736801 ++ [34465] math: math: x86_64 tanh ifunc selection wrong + + Version 2.44 + +diff --git a/sysdeps/ieee754/dbl-64/s_tanh.c b/sysdeps/ieee754/dbl-64/s_tanh.c +index 2029de8fa5..ef80b9edb6 100644 +--- a/sysdeps/ieee754/dbl-64/s_tanh.c ++++ b/sysdeps/ieee754/dbl-64/s_tanh.c +@@ -283,4 +283,6 @@ __tanh (double x) + return as_tanh_database (x, res); + return res; + } ++#ifndef __tanh + libm_alias_double (__tanh, tanh) ++#endif +diff --git a/sysdeps/x86_64/fpu/multiarch/s_tanh-fma.c b/sysdeps/x86_64/fpu/multiarch/s_tanh-fma.c +index 1b808b1227..1e6b33740a 100644 +--- a/sysdeps/x86_64/fpu/multiarch/s_tanh-fma.c ++++ b/sysdeps/x86_64/fpu/multiarch/s_tanh-fma.c +@@ -1,10 +1,4 @@ + #define __tanh __tanh_fma +-#define __expm1 __expm1_fma +- +-/* NB: __expm1 may be expanded to __expm1_fma in the following +- prototypes. */ +-extern long double __expm1l (long double); +-extern long double __expm1f128 (long double); + + #define SECTION __attribute__ ((section (".text.fma"))) + +diff --git a/sysdeps/x86_64/fpu/multiarch/s_tanh.c b/sysdeps/x86_64/fpu/multiarch/s_tanh.c +index ec8826f634..9048c977c1 100644 +--- a/sysdeps/x86_64/fpu/multiarch/s_tanh.c ++++ b/sysdeps/x86_64/fpu/multiarch/s_tanh.c +@@ -25,10 +25,9 @@ extern double __redirect_tanh (double); + # define SYMBOL_NAME tanh + # include "ifunc-fma.h" + +-libc_ifunc_redirected (__redirect_tanh, tanh, IFUNC_SELECTOR ()); ++libc_ifunc_redirected (__redirect_tanh, __tanh, IFUNC_SELECTOR ()); ++libm_alias_double (__tanh, tanh) + + # define __tanh __tanh_sse2 +-# undef libm_alias_double +-# define libm_alias_double(a, b) + #endif + #include + +commit 9bcb85688e58847191deb42bfc68d60802078df4 +Author: Xi Ruoyao +Date: Wed Jul 22 19:26:10 2026 +0800 + + io: fix ftw ABI on MIPS n64 + + On MIPS n64 off_t is same as off64_t, but struct stat is not same as + struct stat64 (very peculiar but see the "as tempting as it..." comment + in linux/mips/kernel_stat.h). As the ftw/ftw64 callback accepts a + pointer to a function who accepts struct stat/stat64, for MIPS n64 we + must use different implementations for ftw and ftw64. + + Thus for testing if ftw64 can be aliased to ftw, we should check + XSTAT_IS_XSTAT64 instead of __OFF_T_MATCHES_OFF64_T. + + This resolves the io/tst-ftw-lnk failure observed on MIPS n64. + + Link: https://sourceware.org/glibc/wiki/Testing/Tests/io/tst-ftw-lnk + Signed-off-by: Xi Ruoyao + Reviewed-by: Adhemerval Zanella + + (cherry picked from commit 6758def717175e679cb49b5051b6b5ec54ddfb2c) + +diff --git a/io/ftw.c b/io/ftw.c +index ed0eeb3904..a9368a706e 100644 +--- a/io/ftw.c ++++ b/io/ftw.c +@@ -18,7 +18,9 @@ + + #include + +-#ifndef __OFF_T_MATCHES_OFF64_T ++#include ++ ++#if !XSTAT_IS_XSTAT64 + # include "ftw-common.c" + + versioned_symbol (libc, __new_nftw, nftw, GLIBC_2_3_3); +diff --git a/io/ftw64.c b/io/ftw64.c +index d3cd14c21a..fa7b05df22 100644 +--- a/io/ftw64.c ++++ b/io/ftw64.c +@@ -31,6 +31,9 @@ + #define ftw __rename_ftw + #define nftw __rename_nftw + ++#include ++ ++#include + #include + #include "ftw-common.c" + +@@ -44,7 +47,7 @@ versioned_symbol (libc, __new_nftw64, nftw64, GLIBC_2_3_3); + compat_symbol (libc, __old_nftw64, nftw64, GLIBC_2_1); + #endif + +-#ifdef __OFF_T_MATCHES_OFF64_T ++#if XSTAT_IS_XSTAT64 + weak_alias (__ftw64, ftw) + versioned_symbol (libc, __new_nftw64, nftw, GLIBC_2_3_3); + # if SHLIB_COMPAT(libc, GLIBC_2_1, GLIBC_2_3_3) + +commit 58da792d8a2d8f2fe711318836e853fcddfd7cd8 +Author: Adhemerval Zanella +Date: Tue Aug 4 14:25:48 2026 +0000 + + hurd: Fix build after the ftw kernel_stat.h inclusion + + Commit 6758def7171 changed the generic ftw{64}.c to include + kernel_stat.h, which is Linux specific. + + Add a Hurd version of kernel_stat.h defining XSTAT_IS_XSTAT64 to 0, + since struct stat and struct stat64 never share a layout on Hurd: on + 32-bit ABIs st_ino, st_size, and st_blocks are narrower in struct stat, + and on 64-bit ABIs the two structures still differ in size because + _SPARE_SIZE in bits/stat.h reserves three more ints of spare space in + struct stat than in struct stat64. + + This keeps the ftw/ftw64 symbols exactly as before the change, where + the aliasing check on __OFF_T_MATCHES_OFF64_T was always false because + the Hurd bits/typesizes.h does not define it. + + Checked with a full build for i686-gnu and x86_64-gnu. + + (cherry picked from commit d6031665c3a59faf75cf6bc55e041611da21d0e6) + +diff --git a/sysdeps/mach/hurd/kernel_stat.h b/sysdeps/mach/hurd/kernel_stat.h +new file mode 100644 +index 0000000000..aa8c26b1d9 +--- /dev/null ++++ b/sysdeps/mach/hurd/kernel_stat.h +@@ -0,0 +1,23 @@ ++/* Internal definitions for stat functions. Hurd version. ++ Copyright (C) 2026 Free Software Foundation, Inc. ++ This file is part of the GNU C Library. ++ ++ The GNU C Library is free software; you can redistribute it and/or ++ modify it under the terms of the GNU Lesser General Public ++ License as published by the Free Software Foundation; either ++ version 2.1 of the License, or (at your option) any later version. ++ ++ The GNU C Library is distributed in the hope that it will be useful, ++ but WITHOUT ANY WARRANTY; without even the implied warranty of ++ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU ++ Lesser General Public License for more details. ++ ++ You should have received a copy of the GNU Lesser General Public ++ License along with the GNU C Library; if not, see ++ . */ ++ ++/* struct stat and struct stat64 never have the same layout: on 32-bit ++ ABIs st_ino, st_size, and st_blocks are narrower in struct stat, and ++ on 64-bit ABIs the two structures still differ in the amount of ++ trailing spare space (see _SPARE_SIZE in bits/stat.h). */ ++#define XSTAT_IS_XSTAT64 0 + +commit fec2a9c6765b548f9d738e3a1c63a63ad7061d40 +Author: Adhemerval Zanella +Date: Fri Mar 21 14:03:00 2025 +0000 + + linux: Inline syscall cancellation to keep wrapper frames observable (BZ 34338) + + The cancellable syscall wrappers end with a tail call to __syscall_cancel, + the wrapper frame is then elided, so when the syscall executes the wrapper + is no longer present on the stack. Tools that unwind from CFI alone, such + as valgrind, perf and sampling profilers, cannot observe it. On gdb, it + only recovers it from DWARF call site information, which reduced-debuginfo + libc builds usually omit. + + The behaviour is target dependent: for a shared (PIC) the tail call is + emitted on aarch64, arc, loongarch and riscv. It is not emitted on i386, + x86_64, arm, s390x, sparc and alpha, where the seventh argument is passed + on the stack or fewer argument registers are available, nor on powerpc + and mips, where the TOC/GOT pointer must be restored after the call. + This is why the problem was originally reported as aarch64 specific while + x86_64 was unaffected. + + Rather than only inhibiting the tail call [1] (which keeps the wrapper frame + but still leaves the __syscall_cancel and __internal_syscall_cancel + frames), move the cancellation logic back into the wrappers. In the + single-threaded case the syscall is now issued directly from the wrapper; + only the multi-threaded path still calls the out-of-line __syscall_cancel_arch. + + This keeps the wrapper observable and removes the extra frames, mimicking + how cancellation was handled before 89b53077d2a58f00e7debdfe58afabe953dac60d. + + The result is a small libc.so .text increase (size, first column): + + ABI master patched diff increase + aarch64 1635880 1647424 11544 0.71% + x86_64 1981081 1992257 11176 0.56% + powerpc64le 2364336 2376964 12628 0.53% + riscv64 1368386 1376704 8318 0.61% + loongarch64 1741385 1755601 14216 0.82% + + The tst-backtrace5 was suppose to track this issue, but due wrong + loop variable check it does not take this in account. This patch also fixes + it. + + Checked on aarch64-linux-gnu, x86_64-linux-gnu, i686-linux-gnu, + arm-linux-gnueabihf, and powerpc64le-linux-gnu. + + [1] https://sourceware.org/pipermail/libc-alpha/2025-March/165395.html + + (cherry picked from commit 1b5ff009fa5bf01ad26e6cc330a1df5a0c84135e) + +diff --git a/NEWS b/NEWS +index 43667c1963..28fbd9bcd8 100644 +--- a/NEWS ++++ b/NEWS +@@ -9,6 +9,8 @@ Version 2.44.1 + + The following bugs are resolved with this release: + ++ [34338] libc: Cancellable syscall wrappers are missing from backtraces ++ because they tail-call __syscall_cancel + [34441] math: math: sinh() returns wrong results for some inputs with + |x| > 36.736801 + [34465] math: math: x86_64 tanh ifunc selection wrong +diff --git a/debug/tst-backtrace5.c b/debug/tst-backtrace5.c +index 4c5784c060..6538da9ab5 100644 +--- a/debug/tst-backtrace5.c ++++ b/debug/tst-backtrace5.c +@@ -36,10 +36,15 @@ + trampoline, read, 3 * fn, and do_test. */ + #define NUM_FUNCTIONS 7 + ++/* Avoid the read wrapper frame truncation on targets that add extra frames ++ between it and handle_signal (the cancellable syscall wrappers ++ __syscall_cancel*, or the i686 __kernel_vsyscall entry). */ ++#define MAX_FUNCTIONS 64 ++ + void + handle_signal (int signum) + { +- void *addresses[NUM_FUNCTIONS]; ++ void *addresses[MAX_FUNCTIONS]; + char **symbols; + int n; + int i; +@@ -70,23 +75,28 @@ handle_signal (int signum) + return; + } + +- /* Do not check name for signal trampoline or cancellable syscall +- wrappers (__syscall_cancel*). */ +- for (; i < n - 1; i++) ++ /* Skip the signal trampoline and any cancellable syscall wrapper frames ++ (__syscall_cancel*) and require the read syscall wrapper to be ++ present. */ ++ for (i = 1; i < n; i++) + if (match (symbols[i], "read")) + break; +- if (i == n - 1) ++ if (i == n) + { + FAIL (); + return; + } + +- for (; i < n - 1; i++) +- if (!match (symbols[i], "fn")) +- { +- FAIL (); +- return; +- } ++ /* The read wrapper must be followed by the three fn recursion frames. */ ++ for (int j = 0; j < 3; j++) ++ { ++ i++; ++ if (i == n || !match (symbols[i], "fn")) ++ { ++ FAIL (); ++ return; ++ } ++ } + /* Symbol names are not available for static functions, so we do not + check do_test. */ + +diff --git a/elf/Makefile b/elf/Makefile +index 94c5b7e6ed..8b063e1bba 100644 +--- a/elf/Makefile ++++ b/elf/Makefile +@@ -1574,7 +1574,9 @@ $(objpfx)dl-allobjs.os: $(all-rtld-routines:%=$(objpfx)%.os) + # when compiled for libc. + rtld-stubbed-symbols = \ + __libc_assert_fail \ +- __syscall_cancel \ ++ __libc_single_threaded_internal \ ++ __syscall_cancel_arch \ ++ __syscall_do_cancel \ + calloc \ + free \ + malloc \ +diff --git a/nptl/cancellation.c b/nptl/cancellation.c +index 4368cb7231..63f09840ff 100644 +--- a/nptl/cancellation.c ++++ b/nptl/cancellation.c +@@ -19,66 +19,6 @@ + #include + #include "pthreadP.h" + +-/* Called by the INTERNAL_SYSCALL_CANCEL macro, check for cancellation and +- returns the syscall value or its negative error code. */ +-long int +-__internal_syscall_cancel (__syscall_arg_t a1, __syscall_arg_t a2, +- __syscall_arg_t a3, __syscall_arg_t a4, +- __syscall_arg_t a5, __syscall_arg_t a6, +- __SYSCALL_CANCEL7_ARG_DEF +- __syscall_arg_t nr) +-{ +- long int result; +- struct pthread *pd = THREAD_SELF; +- +- /* If cancellation is not enabled, call the syscall directly and also +- for thread terminatation to avoid call __syscall_do_cancel while +- executing cleanup handlers. */ +- int ch = atomic_load_relaxed (&pd->cancelhandling); +- if (SINGLE_THREAD_P || !cancel_enabled (ch) || cancel_exiting (ch)) +- { +- result = INTERNAL_SYSCALL_NCS_CALL (nr, a1, a2, a3, a4, a5, a6 +- __SYSCALL_CANCEL7_ARCH_ARG7); +- if (INTERNAL_SYSCALL_ERROR_P (result)) +- return -INTERNAL_SYSCALL_ERRNO (result); +- return result; +- } +- +- /* Call the arch-specific entry points that contains the globals markers +- to be checked by SIGCANCEL handler. */ +- result = __syscall_cancel_arch (&pd->cancelhandling, nr, a1, a2, a3, a4, a5, +- a6 __SYSCALL_CANCEL7_ARCH_ARG7); +- +- /* If the cancellable syscall was interrupted by SIGCANCEL and it has no +- side-effect, cancel the thread if cancellation is enabled. */ +- ch = atomic_load_relaxed (&pd->cancelhandling); +- /* The behaviour here assumes that EINTR is returned only if there are no +- visible side effects. POSIX Issue 7 has not yet provided any stronger +- language for close, and in theory the close syscall could return EINTR +- and leave the file descriptor open (conforming and leaks). It expects +- that no such kernel is used with glibc. */ +- if (result == -EINTR && cancel_enabled_and_canceled (ch)) +- __syscall_do_cancel (); +- +- return result; +-} +- +-/* Called by the SYSCALL_CANCEL macro, check for cancellation and return the +- syscall expected success value (usually 0) or, in case of failure, -1 and +- sets errno to syscall return value. */ +-long int +-__syscall_cancel (__syscall_arg_t a1, __syscall_arg_t a2, +- __syscall_arg_t a3, __syscall_arg_t a4, +- __syscall_arg_t a5, __syscall_arg_t a6, +- __SYSCALL_CANCEL7_ARG_DEF __syscall_arg_t nr) +-{ +- long int r = __internal_syscall_cancel (a1, a2, a3, a4, a5, a6, +- __SYSCALL_CANCEL7_ARG nr); +- return __glibc_unlikely (INTERNAL_SYSCALL_ERROR_P (r)) +- ? SYSCALL_ERROR_LABEL (INTERNAL_SYSCALL_ERRNO (r)) +- : r; +-} +- + /* Called by __syscall_cancel_arch or function above start the thread + cancellation. */ + _Noreturn void +diff --git a/nptl/futex-internal.c b/nptl/futex-internal.c +index fc6b11c8ad..07f1462abe 100644 +--- a/nptl/futex-internal.c ++++ b/nptl/futex-internal.c +@@ -17,7 +17,7 @@ + . */ + + #include +-#include ++#include + #include + #include + #include +diff --git a/nptl/sem_waitcommon.c b/nptl/sem_waitcommon.c +index b0cbe5cebf..82c686f020 100644 +--- a/nptl/sem_waitcommon.c ++++ b/nptl/sem_waitcommon.c +@@ -18,7 +18,7 @@ + + #include + #include +-#include ++#include + #include + #include + #include +diff --git a/sysdeps/unix/sysdep.h b/sysdeps/unix/sysdep.h +index a6ce5348ec..f0f271ec02 100644 +--- a/sysdeps/unix/sysdep.h ++++ b/sysdeps/unix/sysdep.h +@@ -154,42 +154,31 @@ + # define __SYSCALL_CANCEL7_ARG7 + # define __SYSCALL_CANCEL7_ARCH_ARG7 + #endif +-long int __internal_syscall_cancel (__syscall_arg_t a1, __syscall_arg_t a2, +- __syscall_arg_t a3, __syscall_arg_t a4, +- __syscall_arg_t a5, __syscall_arg_t a6, +- __SYSCALL_CANCEL7_ARG_DEF +- __syscall_arg_t nr) attribute_hidden; +- +-long int __syscall_cancel (__syscall_arg_t arg1, __syscall_arg_t arg2, +- __syscall_arg_t arg3, __syscall_arg_t arg4, +- __syscall_arg_t arg5, __syscall_arg_t arg6, +- __SYSCALL_CANCEL7_ARG_DEF +- __syscall_arg_t nr) attribute_hidden; + + #define __SYSCALL_CANCEL0(name) \ +- __syscall_cancel (0, 0, 0, 0, 0, 0, __SYSCALL_CANCEL7_ARG __NR_##name) ++ syscall_cancel (0, 0, 0, 0, 0, 0, __SYSCALL_CANCEL7_ARG __NR_##name) + #define __SYSCALL_CANCEL1(name, a1) \ +- __syscall_cancel (__SSC (a1), 0, 0, 0, 0, 0, \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ syscall_cancel (__SSC (a1), 0, 0, 0, 0, 0, \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __SYSCALL_CANCEL2(name, a1, a2) \ +- __syscall_cancel (__SSC (a1), __SSC (a2), 0, 0, 0, 0, \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ syscall_cancel (__SSC (a1), __SSC (a2), 0, 0, 0, 0, \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __SYSCALL_CANCEL3(name, a1, a2, a3) \ +- __syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), 0, 0, 0, \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), 0, 0, 0, \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __SYSCALL_CANCEL4(name, a1, a2, a3, a4) \ +- __syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ +- __SSC(a4), 0, 0, __SYSCALL_CANCEL7_ARG __NR_##name) ++ syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ ++ __SSC(a4), 0, 0, __SYSCALL_CANCEL7_ARG __NR_##name) + #define __SYSCALL_CANCEL5(name, a1, a2, a3, a4, a5) \ +- __syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), __SSC(a4), \ +- __SSC (a5), 0, __SYSCALL_CANCEL7_ARG __NR_##name) ++ syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), __SSC(a4), \ ++ __SSC (a5), 0, __SYSCALL_CANCEL7_ARG __NR_##name) + #define __SYSCALL_CANCEL6(name, a1, a2, a3, a4, a5, a6) \ +- __syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), __SSC (a4), \ +- __SSC (a5), __SSC (a6), __SYSCALL_CANCEL7_ARG \ +- __NR_##name) ++ syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), __SSC (a4), \ ++ __SSC (a5), __SSC (a6), __SYSCALL_CANCEL7_ARG \ ++ __NR_##name) + #define __SYSCALL_CANCEL7(name, a1, a2, a3, a4, a5, a6, a7) \ +- __syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), __SSC (a4), \ +- __SSC (a5), __SSC (a6), __SSC (a7), __NR_##name) ++ syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), __SSC (a4), \ ++ __SSC (a5), __SSC (a6), __SSC (a7), __NR_##name) + + #define __SYSCALL_CANCEL_NARGS_X(a,b,c,d,e,f,g,h,n,...) n + #define __SYSCALL_CANCEL_NARGS(...) \ +@@ -206,33 +195,33 @@ long int __syscall_cancel (__syscall_arg_t arg1, __syscall_arg_t arg2, + __SYSCALL_CANCEL_DISP (__SYSCALL_CANCEL, __VA_ARGS__) + + #define __INTERNAL_SYSCALL_CANCEL0(name) \ +- __internal_syscall_cancel (0, 0, 0, 0, 0, 0, __SYSCALL_CANCEL7_ARG \ ++ internal_syscall_cancel (0, 0, 0, 0, 0, 0, __SYSCALL_CANCEL7_ARG \ + __NR_##name) + #define __INTERNAL_SYSCALL_CANCEL1(name, a1) \ +- __internal_syscall_cancel (__SSC (a1), 0, 0, 0, 0, 0, \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ internal_syscall_cancel (__SSC (a1), 0, 0, 0, 0, 0, \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __INTERNAL_SYSCALL_CANCEL2(name, a1, a2) \ +- __internal_syscall_cancel (__SSC (a1), __SSC (a2), 0, 0, 0, 0, \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ internal_syscall_cancel (__SSC (a1), __SSC (a2), 0, 0, 0, 0, \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __INTERNAL_SYSCALL_CANCEL3(name, a1, a2, a3) \ +- __internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), 0, \ +- 0, 0, __SYSCALL_CANCEL7_ARG __NR_##name) ++ internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), 0, \ ++ 0, 0, __SYSCALL_CANCEL7_ARG __NR_##name) + #define __INTERNAL_SYSCALL_CANCEL4(name, a1, a2, a3, a4) \ +- __internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ +- __SSC(a4), 0, 0, \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ ++ __SSC(a4), 0, 0, \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __INTERNAL_SYSCALL_CANCEL5(name, a1, a2, a3, a4, a5) \ +- __internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ +- __SSC(a4), __SSC (a5), 0, \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ ++ __SSC(a4), __SSC (a5), 0, \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __INTERNAL_SYSCALL_CANCEL6(name, a1, a2, a3, a4, a5, a6) \ +- __internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ +- __SSC (a4), __SSC (a5), __SSC (a6), \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ ++ __SSC (a4), __SSC (a5), __SSC (a6), \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __INTERNAL_SYSCALL_CANCEL7(name, a1, a2, a3, a4, a5, a6, a7) \ +- __internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ +- __SSC (a4), __SSC (a5), __SSC (a6), \ +- __SSC (a7), __NR_##name) ++ internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ ++ __SSC (a4), __SSC (a5), __SSC (a6), \ ++ __SSC (a7), __NR_##name) + + /* Issue a cancellable syscall defined by syscall number NAME plus any other + argument required. If an error occurs its value is returned as an negative +diff --git a/sysdeps/unix/sysv/linux/epoll_pwait2.c b/sysdeps/unix/sysv/linux/epoll_pwait2.c +index 4da03e3e69..76ec1f8a71 100644 +--- a/sysdeps/unix/sysv/linux/epoll_pwait2.c ++++ b/sysdeps/unix/sysv/linux/epoll_pwait2.c +@@ -17,7 +17,7 @@ + . */ + + #include +-#include ++#include + + int + __epoll_pwait2_time64 (int fd, struct epoll_event *ev, int maxev, +diff --git a/sysdeps/unix/sysv/linux/recvmmsg.c b/sysdeps/unix/sysv/linux/recvmmsg.c +index 6fbe4b80aa..6a89f914c2 100644 +--- a/sysdeps/unix/sysv/linux/recvmmsg.c ++++ b/sysdeps/unix/sysv/linux/recvmmsg.c +@@ -16,7 +16,7 @@ + . */ + + #include +-#include ++#include + #include + + static int +diff --git a/sysdeps/unix/sysv/linux/sigtimedwait.c b/sysdeps/unix/sysv/linux/sigtimedwait.c +index a4fa8e9e8e..c2c5e2c0f2 100644 +--- a/sysdeps/unix/sysv/linux/sigtimedwait.c ++++ b/sysdeps/unix/sysv/linux/sigtimedwait.c +@@ -16,7 +16,7 @@ + . */ + + #include +-#include ++#include + + int + __sigtimedwait64 (const sigset_t *set, siginfo_t *info, +diff --git a/sysdeps/unix/sysv/linux/sysdep-cancel.h b/sysdeps/unix/sysv/linux/sysdep-cancel.h +index 7fd8258ba5..4b7278915a 100644 +--- a/sysdeps/unix/sysv/linux/sysdep-cancel.h ++++ b/sysdeps/unix/sysv/linux/sysdep-cancel.h +@@ -21,5 +21,66 @@ + #define _SYSDEP_CANCEL_H + + #include ++#include "pthreadP.h" ++ ++/* Called by the INTERNAL_SYSCALL_CANCEL macro, check for cancellation and ++ returns the syscall value or its negative error code. */ ++static __always_inline long int ++internal_syscall_cancel (__syscall_arg_t a1, __syscall_arg_t a2, ++ __syscall_arg_t a3, __syscall_arg_t a4, ++ __syscall_arg_t a5, __syscall_arg_t a6, ++ __SYSCALL_CANCEL7_ARG_DEF ++ __syscall_arg_t nr) ++{ ++ long int result; ++ struct pthread *pd = THREAD_SELF; ++ ++ /* If cancellation is not enabled, call the syscall directly and also ++ for thread terminatation to avoid call __syscall_do_cancel while ++ executing cleanup handlers. */ ++ int ch = atomic_load_relaxed (&pd->cancelhandling); ++ if (SINGLE_THREAD_P || !cancel_enabled (ch) || cancel_exiting (ch)) ++ { ++ result = INTERNAL_SYSCALL_NCS_CALL (nr, a1, a2, a3, a4, a5, a6 ++ __SYSCALL_CANCEL7_ARCH_ARG7); ++ if (INTERNAL_SYSCALL_ERROR_P (result)) ++ return -INTERNAL_SYSCALL_ERRNO (result); ++ return result; ++ } ++ ++ /* Call the arch-specific entry points that contains the globals markers ++ to be checked by SIGCANCEL handler. */ ++ result = __syscall_cancel_arch (&pd->cancelhandling, nr, a1, a2, a3, a4, a5, ++ a6 __SYSCALL_CANCEL7_ARCH_ARG7); ++ ++ /* If the cancellable syscall was interrupted by SIGCANCEL and it has no ++ side-effect, cancel the thread if cancellation is enabled. */ ++ ch = atomic_load_relaxed (&pd->cancelhandling); ++ /* The behaviour here assumes that EINTR is returned only if there are no ++ visible side effects. POSIX Issue 7 has not yet provided any stronger ++ language for close, and in theory the close syscall could return EINTR ++ and leave the file descriptor open (conforming and leaks). It expects ++ that no such kernel is used with glibc. */ ++ if (result == -EINTR && cancel_enabled_and_canceled (ch)) ++ __syscall_do_cancel (); ++ ++ return result; ++} ++ ++/* Called by the SYSCALL_CANCEL macro, check for cancellation and return the ++ syscall expected success value (usually 0) or, in case of failure, -1 and ++ sets errno to syscall return value. */ ++static __always_inline long int ++syscall_cancel (__syscall_arg_t a1, __syscall_arg_t a2, ++ __syscall_arg_t a3, __syscall_arg_t a4, ++ __syscall_arg_t a5, __syscall_arg_t a6, ++ __SYSCALL_CANCEL7_ARG_DEF __syscall_arg_t nr) ++{ ++ long int r = internal_syscall_cancel (a1, a2, a3, a4, a5, a6, ++ __SYSCALL_CANCEL7_ARG nr); ++ return __glibc_unlikely (INTERNAL_SYSCALL_ERROR_P (r)) ++ ? SYSCALL_ERROR_LABEL (INTERNAL_SYSCALL_ERRNO (r)) ++ : r; ++} + + #endif + +commit 5d1e923ed79185668ac62d19fc37e7e23a3642b6 +Author: Adhemerval Zanella +Date: Thu Aug 6 14:07:55 2026 -0300 + + Fix gen-as-const-headers races with the parallel subdir recursion (BZ 34438) + + The parallel subdirectory recursion (commit 7cac99621e96) only orders + csu (and mach/hurd on Hurd) before the parallel fan-out plus the edges + the Depend files request. A header generated from gen-as-const-headers + is only ordered before the compilations of the subdirectory that + adds the .sym (through before-compile), so a header consumed by a + different subdirectory may not exist yet when its consumer is + compiled. + + That is the case for : it is generated when + building misc, while its only consumer, ____longjmp_chk.S (x86_64 and + sh), is built in debug. The serial recursion always ran misc before + debug in the sorted order, hiding the missing dependency. + + Move the generate the header to 'debug' instead. + + The same class of problem exists on Hurd: jmp_buf-ssp.h that is used + by ____longjmp_chk.S in debug, and signal-defines.h that is sued + by debug and setjmp. + + Deterministically reproduced with 'make debug/subdir_lib' from a clean + build tree (which orders only csu before debug), and verified with + builds for x86_64-linux-gnu, sh4-linux-gnu, i686-gnu, and x86_64-gnu. + Reviewed-by: Sam James + + (cherry picked from commit 60c9ed0e6b9cce07e85ee56fc39b9afe36919e45) + +diff --git a/Makerules b/Makerules +index 6bef57ece9..cef30974f1 100644 +--- a/Makerules ++++ b/Makerules +@@ -259,7 +259,17 @@ endif # gen-py-const-headers + ifdef gen-as-const-headers + # Generating headers for assembly constants. + # We need this defined early to get into before-compile before +-# it's used in sysd-rules, below. ++# it's used in sysd-rules, below. The gen-as-const-headers is evaluated ++# per subdirectory, so the before-compile dependency below only orders ++# the generated header before the compiles of the subdirectory whose ++# Makefile adds the .sym directive. ++# The parallel subdirectory recursion does not order sibling subdirectories, ++# so a .sym must be added in the subdirectory that compiles its consumers, ++# or in csu (which runs before the parallel) when it has consumers in ++# several subdirectories. ++# It must not add the same .sym in several subdirectories though: their ++# concurrent sub-makes would race generating the header through the fixed ++# temporary files below. + # Define GEN_AS_CONST_HEADERS to avoid circular dependency [BZ #22792]. + # NB: is generated from tcb-offsets.sym to define + # offsets and sizes of types in and maybe which +diff --git a/NEWS b/NEWS +index 28fbd9bcd8..ee292ff6c9 100644 +--- a/NEWS ++++ b/NEWS +@@ -11,6 +11,8 @@ The following bugs are resolved with this release: + + [34338] libc: Cancellable syscall wrappers are missing from backtraces + because they tail-call __syscall_cancel ++ [34438] build: non reproducible build failure: sigaltstack-offsets.h: ++ No such file or directory + [34441] math: math: sinh() returns wrong results for some inputs with + |x| > 36.736801 + [34465] math: math: x86_64 tanh ifunc selection wrong +diff --git a/sysdeps/mach/hurd/x86/Makefile b/sysdeps/mach/hurd/x86/Makefile +index 97e3287c87..1d94f3a1c1 100644 +--- a/sysdeps/mach/hurd/x86/Makefile ++++ b/sysdeps/mach/hurd/x86/Makefile +@@ -3,11 +3,7 @@ sysdep_routines += ioperm + sysdep_headers += sys/io.h + endif + +-ifeq ($(subdir),debug) +-gen-as-const-headers += signal-defines.sym +-endif +- +-ifeq ($(subdir),setjmp) ++ifeq ($(subdir),csu) + gen-as-const-headers += signal-defines.sym + endif + +diff --git a/sysdeps/unix/sysv/linux/sh/Makefile b/sysdeps/unix/sysv/linux/sh/Makefile +index dd3b382ac1..8c4cb73824 100644 +--- a/sysdeps/unix/sysv/linux/sh/Makefile ++++ b/sysdeps/unix/sysv/linux/sh/Makefile +@@ -6,7 +6,9 @@ ifeq ($(subdir),stdlib) + gen-as-const-headers += ucontext_i.sym + endif + +-ifeq ($(subdir),misc) ++# is only used by ____longjmp_chk.S, which is ++# built in the debug subdirectory. ++ifeq ($(subdir),debug) + gen-as-const-headers += sigaltstack-offsets.sym + endif + +diff --git a/sysdeps/unix/sysv/linux/x86_64/Makefile b/sysdeps/unix/sysv/linux/x86_64/Makefile +index 6938382801..528fd951b2 100644 +--- a/sysdeps/unix/sysv/linux/x86_64/Makefile ++++ b/sysdeps/unix/sysv/linux/x86_64/Makefile +@@ -10,7 +10,9 @@ ifeq ($(subdir),csu) + gen-as-const-headers += ucontext_i.sym + endif + +-ifeq ($(subdir),misc) ++# is only used by ____longjmp_chk.S, which is ++# built in the debug subdirectory. ++ifeq ($(subdir),debug) + gen-as-const-headers += sigaltstack-offsets.sym + endif + +diff --git a/sysdeps/x86/Makefile b/sysdeps/x86/Makefile +index 232e388d32..b4434deb0c 100644 +--- a/sysdeps/x86/Makefile ++++ b/sysdeps/x86/Makefile +@@ -1,5 +1,12 @@ + ifeq ($(subdir),csu) +-gen-as-const-headers += cpu-features-offsets.sym features-offsets.sym ++# is used by the setjmp/longjmp implementations in the ++# setjmp subdirectory and also by ____longjmp_chk.S in the debug ++# subdirectory. ++gen-as-const-headers += \ ++ cpu-features-offsets.sym \ ++ features-offsets.sym \ ++ jmp_buf-ssp.sym \ ++ # gen-as-const-headers + endif + + ifeq ($(subdir),elf) +@@ -171,7 +178,6 @@ tests += \ + endif # $(subdir) == math + + ifeq ($(subdir),setjmp) +-gen-as-const-headers += jmp_buf-ssp.sym + sysdep_routines += __longjmp_cancel + endif + + +commit 45b8a13c48da92bc5dd6fe102011391dd6847862 +Author: Rudi Heitbaum +Date: Thu Aug 6 14:07:56 2026 -0300 + + Makerules: Only install the ABI lib-names header from the top level (BZ 34439) + + The $(inst_includedir)/%.h install rules exist only where $(headers) is + non-empty, so in a subdir without headers (e.g. csu) the prerequisite + added on install-others-nosubdir has no rule. + + It only worked because .NOTPARALLEL made the top level install the header + first, which the parallel subdir recursion no longer guarantees. + Reviewed-by: Sam James + + (cherry picked from commit 82c0a96b8e63005a49ba52ddb21993811030613f) + +diff --git a/Makerules b/Makerules +index cef30974f1..dfe66b7fa6 100644 +--- a/Makerules ++++ b/Makerules +@@ -312,7 +312,12 @@ lib-names-h-abi = gnu/lib-names-$(default-abi).h + lib-names-stmp-abi = gnu/lib-names-$(default-abi).stmp + before-compile += $(common-objpfx)$(lib-names-h-abi) + common-generated += gnu/lib-names.h ++# The $(inst_includedir)/%.h install rules are defined only where $(headers) ++# is non-empty, and with parallel subdir recursion a subdir without headers ++# (e.g. csu) may run before the top level has installed the header. ++ifndef subdir + install-others-nosubdir: $(inst_includedir)/$(lib-names-h-abi) ++endif + $(common-objpfx)gnu/lib-names.h: + $(make-target-directory) + { \ +diff --git a/NEWS b/NEWS +index ee292ff6c9..d0ef2d3e9a 100644 +--- a/NEWS ++++ b/NEWS +@@ -13,6 +13,8 @@ The following bugs are resolved with this release: + because they tail-call __syscall_cancel + [34438] build: non reproducible build failure: sigaltstack-offsets.h: + No such file or directory ++ [34439] build: parallel make install fails on multi-ABI targets: no ++ rule to make $(inst_includedir)/gnu/lib-names-$(abi).h in csu + [34441] math: math: sinh() returns wrong results for some inputs with + |x| > 36.736801 + [34465] math: math: x86_64 tanh ifunc selection wrong + +commit f7beb24f3ad5dbf8e84a5b75d5b2428a262e9ab9 +Author: Adhemerval Zanella +Date: Thu Aug 6 14:07:57 2026 -0300 + + Makefile: Only print the test summary in the second pass of 'make check' + + The build-only first pass of the two-pass 'make check' still runs the + static checks (abi, conformtest, installed headers, etc.), and the + top-level tests recipe merged and summarized their results. + + An unexpected FAIL there (e.g. check-abi) aborted 'check' before the + second pass ran any built test, and even a clean run printed a misleading + partial summary. + + Pass tests-summary=no in the first pass to skip the merge and summary; + the .test-result files persist, so the second pass folds those results + into the one complete summary at the end, restoring the single-pass + reporting behavior. + Reviewed-by: Sam James + + (cherry picked from commit 96a9a09d7d5527462a823c247569e65feeca8ddb) + +diff --git a/Makefile b/Makefile +index a6aabca691..b9fac6f47c 100644 +--- a/Makefile ++++ b/Makefile +@@ -869,7 +869,11 @@ endif + touch $(objpfx)testroot.pristine/install.stamp + + tests-special-notdir = $(patsubst $(objpfx)%, %, $(tests-special)) ++# The build-only first pass of the two-pass 'make check' (see Makerules) ++# passes tests-summary=no: the merge and summary are left to the second ++# pass, which folds in this pass's $(tests-special) results. + tests: $(tests-special) ++ifneq ($(tests-summary),no) + $(..)scripts/merge-test-results.sh -s $(objpfx) "" \ + $(sort $(tests-special-notdir:.out=)) \ + > $(objpfx)subdir-tests.sum +@@ -877,11 +881,14 @@ tests: $(tests-special) + $(sort $(subdirs) .) \ + > $(objpfx)tests.sum + $(call summarize-tests,tests.sum) ++endif + xtests: ++ifneq ($(tests-summary),no) + $(..)scripts/merge-test-results.sh -t $(objpfx) subdir-xtests.sum \ + $(sort $(subdirs)) \ + > $(objpfx)xtests.sum + $(call summarize-tests,xtests.sum, for extra tests) ++endif + + # The realclean target is just like distclean for the parent, but we want + # the subdirs to know the difference in case they care. +diff --git a/Makerules b/Makerules +index dfe66b7fa6..5f65f3ab9e 100644 +--- a/Makerules ++++ b/Makerules +@@ -1211,6 +1211,13 @@ ALL_BUILD_CFLAGS = $(BUILD_CFLAGS) $(BUILD_CPPFLAGS) -D_GNU_SOURCE \ + # therefore builds the test programs (run-built-tests=no, recursion fully + # parallel) and then runs them (run-built-tests=yes). 'make tests' and a + # subdirectory's own 'check' stay single-pass. ++# The first pass still runs the static checks ($(tests-special): abi, ++# conformtest, installed headers, ...), so tests-summary=no makes it skip ++# the results merge and summary: an unexpected FAIL there would otherwise ++# abort 'check' before the second pass runs any built test, and even a ++# clean run would print a misleading partial summary. The .test-result ++# files persist, so the second pass folds those results into the one ++# complete summary at the end. + check-twopass := + ifndef subdir + ifeq (yes,$(run-built-tests)) +@@ -1219,10 +1226,10 @@ endif + endif + ifeq (yes,$(check-twopass)) + check: +- $(MAKE) run-built-tests=no tests ++ $(MAKE) run-built-tests=no tests-summary=no tests + $(MAKE) run-built-tests=yes tests + xcheck: +- $(MAKE) run-built-tests=no xtests ++ $(MAKE) run-built-tests=no tests-summary=no xtests + $(MAKE) run-built-tests=yes xtests + else + check: tests + +commit fc3641194619c7c327ef398c88c07b3069878ed3 +Author: Adhemerval Zanella +Date: Thu Aug 6 14:07:58 2026 -0300 + + Makerules: Make the .dt to .d conversion safe against concurrent sub-makes + + The %.d: %.dt rule seds its input into a fixed temporary name, renames + it into place and removes the input. Two makes converting the same + file trip over each other: + + mv: cannot stat '.../test-double-libmvec-sincos-avx512f.o.T': No such file or directory + sed: can't read .../test-float-libmvec-acosf-avx512f.o.dt: No such file or directory + + That happens because the elf rtld-Rules recursion runs a sub-make over + every $(rtld-subdirs) directory, which converts that directory's .dt + files, and the parallel subdirectory recursion (commit 7cac99621e96) + runs it concurrently with those subdirectories' own sub-makes. + + Add the PID of the shell to the temporary name and claim the input with + a rename: only the run that wins converts and installs the target. + Reviewed-by: Sam James + + (cherry picked from commit ba8c8801be7674cc12406914184516a811ac22a8) + +diff --git a/Makerules b/Makerules +index 5f65f3ab9e..be51154bae 100644 +--- a/Makerules ++++ b/Makerules +@@ -758,10 +758,20 @@ all-dt-files := $(foreach o,$(object-suffixes-for-libc),$(+depfiles:.d=$o.dt)) + $(wildcard $(all-dt-files:.dt=.d)) + + # This is a funny rule in that it removes its input file. ++# ++# More than one make can convert the .dt files of a single object ++# directory: the elf rtld-Rules recursion runs a sub-make over every ++# $(rtld-subdirs) directory, concurrently with that directory's own ++# sub-make under the parallel subdir recursion. Add the PID of the ++# shell to the temporary name and claim the input with a rename: only ++# the run that wins converts and installs the target. + %.d: %.dt +- @sed $(sed-remove-objpfx) $< > $(@:.d=.T) && \ +- mv -f $(@:.d=.T) $@ && \ +- rm -f $< ++ @dt=$(@:.d=.T)$$$$; \ ++ if mv -f $< $$dt 2>/dev/null; then \ ++ sed $(sed-remove-objpfx) $$dt > $$dt.new && \ ++ mv -f $$dt.new $@ && \ ++ rm -f $$dt; \ ++ fi + + # Avoid the .h.d files for any .sym files whose .h files don't exist yet. + # They will be generated when they're needed, and trying too early won't work. +@@ -1433,7 +1443,7 @@ endef + # Also remove the dependencies and generated source files. + common-clean: common-mostlyclean + -rm -f $(addprefix $(objpfx),$(generated)) +- -rm -f $(objpfx)*.d $(objpfx)*.dt ++ -rm -f $(objpfx)*.d $(objpfx)*.dt $(objpfx)*.T[0-9]* + -rm -fr $(addprefix $(objpfx),$(generated-dirs)) + -rm -f $(addprefix $(common-objpfx),$(common-generated)) + -rm -f $(gen-as-const-headers:%.sym=$(common-objpfx)%.h) + +commit f34027b27fefbc94aab04bff613ba5c24fb909b1 +Author: Adhemerval Zanella +Date: Thu Aug 6 14:07:59 2026 -0300 + + Makefile: Order the top-level stamp files before the subdirectory fan-out + + The archive rules in Makerules list every stamp file as a prerequisite, + including the top level's own, and the elf sub-make evaluates them to + build libc_pic.a for the librtld.map link. A sub-make can only create + the stamp files of its own directory, so when the top-level ones do not + exist yet it fails with: + + make[2]: *** No rule to make target '.../stamp.os', needed by + '.../libc_pic.a'. Stop. + + The serial recursion created them before the subdirectories through the + prerequisite order of subdir_lib; the parallel recursion (commit + 7cac99621e96) does not. Add them as prerequisites of the object-building + per-subdirectory targets. + Reviewed-by: Sam James + + (cherry picked from commit 25c42d04c45fc5fdb1481a7f968782791b21fd3e) + +diff --git a/Makefile b/Makefile +index b9fac6f47c..d559c42873 100644 +--- a/Makefile ++++ b/Makefile +@@ -575,6 +575,14 @@ $(foreach t,$(+elf_last_subdir_targets),$(eval \ + elf/$(t): $(addsuffix /$(t),$(filter-out elf,$(subdirs))))) + endif + ++# The archive rules in Makerules list every stamp file as a ++# prerequisite of libc_pic.a, which the elf sub-make evaluates for the ++# librtld.map link, but a sub-make can only create its own directory's ++# stamps. Create the top-level ones before the fan-out. ++$(foreach t,$(+elf_last_subdir_targets),$(eval \ ++ $(addsuffix /$(t),$(subdirs)): \ ++ $(foreach o,$(object-suffixes-for-libc),$(common-objpfx)stamp$(o)))) ++ + # Pass barriers: a subdirectory 'others' build links programs against + # the libraries, so the 'lib' pass (including the top-level libc.so + # link) must have completed. + +commit 10e3ce8a57e134c13dd28772de68542b0e3d4e86 +Author: Adhemerval Zanella +Date: Thu Aug 6 14:08:00 2026 -0300 + + arm: Order the rtld link after libgcc-stubs.a + + The librtld.map and librtld.os link recipes use $(gnulib), which on arm + contains libgcc-stubs.a through gnulib-arch. But the archive is only a + prerequisite of lib-noranlib so the rtld link can run before the archive + exists: + + ld.bfd: cannot find .../elf/libgcc-stubs.a: No such file or directory + + The race seems to predates the parallel subdirectory recursion, which + only made it observable. + + Add the order-only dependency in sysdeps/arm/Makefile rather than in + elf/Makefile. Theprerequisite lists expand when the rule is parsed, + and gnulib-arch is only defined once Makerules includes the sysdeps + makefiles. + + Verified with a build for arm-linux-gnueabihf. + Reviewed-by: Sam James + + (cherry picked from commit a33ceb6e96dc8de8d36de1b1f3ec06ceb524d012) + +diff --git a/sysdeps/arm/Makefile b/sysdeps/arm/Makefile +index 0bb1b6e05b..9042315492 100644 +--- a/sysdeps/arm/Makefile ++++ b/sysdeps/arm/Makefile +@@ -10,6 +10,11 @@ shared-only-routines += aeabi_unwind_cpp_pr1 + $(objpfx)libgcc-stubs.a: $(objpfx)aeabi_unwind_cpp_pr1.os + $(build-extra-lib) + ++# The rtld link recipes in elf/Makefile use $(gnulib), which here ++# includes libgcc-stubs.a, but they cannot name it as a prerequisite: ++# gnulib-arch is only defined once this file is included from Makerules. ++$(objpfx)librtld.map $(objpfx)librtld.os: | $(objpfx)libgcc-stubs.a ++ + lib-noranlib: $(objpfx)libgcc-stubs.a + + ifeq ($(build-shared),yes) + +commit 26b9cc42a051f78233fcecd2a3b83f98ec9862b9 +Author: Adhemerval Zanella +Date: Tue Jul 28 11:27:33 2026 -0300 + + benchtests: Create objdir in the bench-%.c generation rule + + The $(objpfx)bench-%.c rule writes its output into $(objpfx) without + ensuring that directory exists. Serial builds happened to satisfy + that ordering, with parallel builds the generation recipe can + run before the directory is created, failing with: + + cannot create .../benchtests/bench-xxx.c-tmp: Directory nonexistent + + Add the standard $(make-target-directory). + + Reviewed-by: Florian Weimer + (cherry picked from commit 26f0f2aa7d6ea63f85b5186349c41de2c91b4dd7) + +diff --git a/benchtests/Makefile b/benchtests/Makefile +index f407e492cb..16cc951d19 100644 +--- a/benchtests/Makefile ++++ b/benchtests/Makefile +@@ -622,6 +622,7 @@ $(bench-link-targets): %: %.o $(objpfx)json-lib.o \ + $(bench-link-targets): LDFLAGS += $(link-bench-bind-now) + + $(objpfx)bench-%.c: %-inputs $(bench-deps) ++ $(make-target-directory) + { if [ -n "$($*-INCLUDE)" ]; then \ + cat $($*-INCLUDE); \ + fi; \ + +commit 4662c4675d7f3ba87637c61730f06071f305c5cb +Author: Xi Ruoyao +Date: Sun Jul 26 00:11:44 2026 +0800 + + elf: test: handle different rootsbindir in tst-ldconfig-cache + + When compiling a glibc for a merged-/usr distro people may set + rootsbindir=/usr/sbin. But tst-ldconfig-cache has hard-coded + /sbin/ldconfig path and so it fails with a different rootsbindir. + + Fix it by using support_install_rootsbindir like run_ldconfig in + test-container.c. + + Signed-off-by: Xi Ruoyao + Reviewed-by: Florian Weimer + (cherry picked from commit 02ea17b5add83a205d8b204dce28f38fe0498ea3) + +diff --git a/elf/tst-ldconfig-cache.c b/elf/tst-ldconfig-cache.c +index 9f71418b3a..f4820a1822 100644 +--- a/elf/tst-ldconfig-cache.c ++++ b/elf/tst-ldconfig-cache.c +@@ -85,7 +85,10 @@ corrupt (void) + static void + ldconfig (void) + { +- xsystem ("/sbin/ldconfig -X"); ++ char *cmd = xasprintf("%s/ldconfig -X", support_install_rootsbindir); ++ xsystem (cmd); ++ ++ free(cmd); + } + + /* Change ld.so.conf to refer to the new directory, and generate a new + +commit 9e1b1ef77c7b1cc58f625500e9ea74fb3cafdf12 +Author: Matt Turner +Date: Sun Jul 26 00:27:37 2026 -0400 + + ldbl-opt: Fix -mlong-double-128 configure test for Clang + + The check for -mlong-double-128 support wrapped its test code in + AC_LANG_PROGRAM, which places the body inside main(). The body defines + a function, so it became a nested function definition -- a GCC extension + that Clang does not implement, making the test fail (and thus the whole + build error out) with Clang even though it supports -mlong-double-128. + + Use AC_LANG_SOURCE so the function is defined at file scope, matching the + pattern already used by the powerpc64le compiler checks, and regenerate + configure. + + Reviewed-by: Sam James + (cherry picked from commit e7a14f03b8d5e34e8ac46db6c377da5c66a3ec2a) + +diff --git a/sysdeps/ieee754/ldbl-opt/configure b/sysdeps/ieee754/ldbl-opt/configure +old mode 100644 +new mode 100755 +index bc6552da0b..7769cc9781 +--- a/sysdeps/ieee754/ldbl-opt/configure ++++ b/sysdeps/ieee754/ldbl-opt/configure +@@ -13,17 +13,10 @@ CFLAGS="$CFLAGS -mlong-double-128" + cat confdefs.h - <<_ACEOF >conftest.$ac_ext + /* end confdefs.h. */ + +-int +-main (void) +-{ +- + #ifndef __LONG_DOUBLE_128__ + # error "compiler did not predefine __LONG_DOUBLE_128__ as expected" + #endif + long double foobar (long double x) { return x; } +- ; +- return 0; +-} + _ACEOF + if ac_fn_c_try_compile "$LINENO" + then : +diff --git a/sysdeps/ieee754/ldbl-opt/configure.ac b/sysdeps/ieee754/ldbl-opt/configure.ac +index 70e3b32dc6..1c500ad581 100644 +--- a/sysdeps/ieee754/ldbl-opt/configure.ac ++++ b/sysdeps/ieee754/ldbl-opt/configure.ac +@@ -6,7 +6,7 @@ AC_CACHE_CHECK(whether $CC $CFLAGS supports -mlong-double-128, + libc_cv_mlong_double_128, [dnl + save_CFLAGS="$CFLAGS" + CFLAGS="$CFLAGS -mlong-double-128" +-AC_COMPILE_IFELSE([AC_LANG_PROGRAM([[]], [[ ++AC_COMPILE_IFELSE([AC_LANG_SOURCE([[ + #ifndef __LONG_DOUBLE_128__ + # error "compiler did not predefine __LONG_DOUBLE_128__ as expected" + #endif + +commit eacd9cced93498e671c7e7f758aaf52593847e01 +Author: Matt Turner +Date: Sun Jul 26 14:43:11 2026 -0400 + + powerpc: Fix -mlong-double-128 IBM format configure test for Clang + + The check for -mlong-double-128 IBM extended format support wrapped its + test code in AC_LANG_PROGRAM, which places the body inside main(). The + body defines a function, so it became a nested function definition -- a + GCC extension that Clang does not implement, making the test fail with + Clang. + + Use AC_LANG_SOURCE so the function is defined at file scope, and + regenerate configure. + + Reviewed-by: Sam James + (cherry picked from commit 559d0f77f3ee1000cf8a2d0baba7a59a1ec45f50) + +diff --git a/sysdeps/unix/sysv/linux/powerpc/configure b/sysdeps/unix/sysv/linux/powerpc/configure +index ef2055db92..eb8578404f 100644 +--- a/sysdeps/unix/sysv/linux/powerpc/configure ++++ b/sysdeps/unix/sysv/linux/powerpc/configure +@@ -12,18 +12,12 @@ else case e in #( + CFLAGS="$CFLAGS -mlong-double-128" + cat confdefs.h - <<_ACEOF >conftest.$ac_ext + /* end confdefs.h. */ +-#include +-int +-main (void) +-{ + ++#include + #if LDBL_MANT_DIG != 106 + # error "compiler doesn't implement IBM extended format of long double" + #endif + long double foobar (long double x) { return x; } +- ; +- return 0; +-} + _ACEOF + if ac_fn_c_try_compile "$LINENO" + then : +diff --git a/sysdeps/unix/sysv/linux/powerpc/configure.ac b/sysdeps/unix/sysv/linux/powerpc/configure.ac +index 42347a66fc..ca0f82da08 100644 +--- a/sysdeps/unix/sysv/linux/powerpc/configure.ac ++++ b/sysdeps/unix/sysv/linux/powerpc/configure.ac +@@ -6,7 +6,8 @@ AC_CACHE_CHECK(whether $CC $CFLAGS -mlong-double-128 uses IBM extended format, + libc_cv_mlong_double_128ibm, [dnl + save_CFLAGS="$CFLAGS" + CFLAGS="$CFLAGS -mlong-double-128" +-AC_COMPILE_IFELSE([AC_LANG_PROGRAM([[#include ]], [[ ++AC_COMPILE_IFELSE([AC_LANG_SOURCE([[ ++#include + #if LDBL_MANT_DIG != 106 + # error "compiler doesn't implement IBM extended format of long double" + #endif + +commit 89da37bb6e4a631f375b5fe48783e5c023441b0c +Author: Matt Turner +Date: Tue Aug 4 10:17:20 2026 -0400 + + stdio-common: run AWK in the C locale in the printf format tests + + The program under test runs in the C locale, through the test program + prefix, but AWK inherits whatever locale the build was started in. They + agree today only because the locale in use shares its decimal point with + the C locale. + + It is also faster. gawk takes a single byte path in its regular + expression engine when MB_CUR_MAX is 1, and the script matches several + expressions against every line. For the %f conversion for double, the + largest of these tests, as the median of five runs: + + x86_64, gawk 5.4.1 1.482s -> 1.248s + x86_64, gawk 5.3.2 0.911s -> 0.703s + alpha, gawk 5.4.60 30.9s -> 26.6s + + Worth noting that gawk 5.4 is a good deal slower here than 5.3 was, at + 1.248s against 0.703s for the same input in the C locale, so these tests + have become more expensive than they used to be. + + Reviewed-by: Adhemerval Zanella + (cherry picked from commit 866a70167b85903a02d4ccacb91afb8922702c14) + +diff --git a/stdio-common/tst-printf-format-c.sh b/stdio-common/tst-printf-format-c.sh +index 825c50ec42..73d28c5607 100644 +--- a/stdio-common/tst-printf-format-c.sh ++++ b/stdio-common/tst-printf-format-c.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + echo Verifying c + (set -o pipefail +diff --git a/stdio-common/tst-printf-format-char.sh b/stdio-common/tst-printf-format-char.sh +index 7867bdd62f..aa4d211126 100644 +--- a/stdio-common/tst-printf-format-char.sh ++++ b/stdio-common/tst-printf-format-char.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=0 + +diff --git a/stdio-common/tst-printf-format-double.sh b/stdio-common/tst-printf-format-double.sh +index 8157092dc4..051e4716c5 100644 +--- a/stdio-common/tst-printf-format-double.sh ++++ b/stdio-common/tst-printf-format-double.sh +@@ -29,7 +29,7 @@ test_program_prefix=$1; shift + # internally to process the conversion requested, so any bug in our code + # would then be verified against itself, defeating the objective of doing + # the verification against an independent implementation. +-AWK="${AWK:-awk} -M" ++AWK="env LC_ALL=C ${AWK:-awk} -M" + + status=77 + +diff --git a/stdio-common/tst-printf-format-int.sh b/stdio-common/tst-printf-format-int.sh +index 8542ff4150..e9dcbedc04 100644 +--- a/stdio-common/tst-printf-format-int.sh ++++ b/stdio-common/tst-printf-format-int.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=77 + +diff --git a/stdio-common/tst-printf-format-ldouble.sh b/stdio-common/tst-printf-format-ldouble.sh +index dbf78a98c6..7ee097ac0a 100644 +--- a/stdio-common/tst-printf-format-ldouble.sh ++++ b/stdio-common/tst-printf-format-ldouble.sh +@@ -29,7 +29,7 @@ test_program_prefix=$1; shift + # internally to process the conversion requested, so any bug in our code + # would then be verified against itself, defeating the objective of doing + # the verification against an independent implementation. +-AWK="${AWK:-awk} -M" ++AWK="env LC_ALL=C ${AWK:-awk} -M" + + status=77 + +diff --git a/stdio-common/tst-printf-format-llong.sh b/stdio-common/tst-printf-format-llong.sh +index e1f5252c9a..98a79660cc 100644 +--- a/stdio-common/tst-printf-format-llong.sh ++++ b/stdio-common/tst-printf-format-llong.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=77 + +diff --git a/stdio-common/tst-printf-format-long.sh b/stdio-common/tst-printf-format-long.sh +index 4b68ab1e04..89ac3302b8 100644 +--- a/stdio-common/tst-printf-format-long.sh ++++ b/stdio-common/tst-printf-format-long.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=77 + +diff --git a/stdio-common/tst-printf-format-s.sh b/stdio-common/tst-printf-format-s.sh +index 65aa0cb675..015c730609 100644 +--- a/stdio-common/tst-printf-format-s.sh ++++ b/stdio-common/tst-printf-format-s.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + echo Verifying s + (set -o pipefail +diff --git a/stdio-common/tst-printf-format-short.sh b/stdio-common/tst-printf-format-short.sh +index 30357baa02..a7df8b8e6d 100644 +--- a/stdio-common/tst-printf-format-short.sh ++++ b/stdio-common/tst-printf-format-short.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=0 + +diff --git a/stdio-common/tst-printf-format-uchar.sh b/stdio-common/tst-printf-format-uchar.sh +index 08a6914b88..356de4217d 100644 +--- a/stdio-common/tst-printf-format-uchar.sh ++++ b/stdio-common/tst-printf-format-uchar.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=0 + +diff --git a/stdio-common/tst-printf-format-uint.sh b/stdio-common/tst-printf-format-uint.sh +index 0ba203ccda..b496047a49 100644 +--- a/stdio-common/tst-printf-format-uint.sh ++++ b/stdio-common/tst-printf-format-uint.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=77 + +diff --git a/stdio-common/tst-printf-format-ullong.sh b/stdio-common/tst-printf-format-ullong.sh +index 5b881ab924..f030f66a24 100644 +--- a/stdio-common/tst-printf-format-ullong.sh ++++ b/stdio-common/tst-printf-format-ullong.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=77 + +diff --git a/stdio-common/tst-printf-format-ulong.sh b/stdio-common/tst-printf-format-ulong.sh +index f6aeb8e3c0..7102575ed2 100644 +--- a/stdio-common/tst-printf-format-ulong.sh ++++ b/stdio-common/tst-printf-format-ulong.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=77 + +diff --git a/stdio-common/tst-printf-format-ushort.sh b/stdio-common/tst-printf-format-ushort.sh +index 07609128ab..5f612b5398 100644 +--- a/stdio-common/tst-printf-format-ushort.sh ++++ b/stdio-common/tst-printf-format-ushort.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=0 + + +commit 7cc7a3a4fbf15c8a7d61a69452f754f9c352cd62 +Author: Matt Turner +Date: Mon Aug 3 21:59:44 2026 -0400 + + stdio-common: avoid repeated regexp matches in tst-printf-format.awk + + Whether the value is an infinity, a NaN or zero does not change between + the conversions applied to it, but was determined again for each one. + Determine it where the value is read. + + Also look for the '#' flag with index() before matching the expressions + that need it, and test the value first where both have to hold. + + For the %f conversion for double, in the C locale, as the median of five + runs: + + x86_64, gawk 5.4.1 1.248s -> 1.184s + x86_64, gawk 5.3.2 0.703s -> 0.708s + alpha, gawk 5.4.60 26.6s -> 25.8s + + So this only helps with the regular expression engine that gawk 5.4 + brought in; under 5.3.2 it is lost in the noise. Output and exit status + are unchanged for the e, f and g conversions for double under both + gawk versions and both locales. + + Reviewed-by: Adhemerval Zanella + (cherry picked from commit 0cc3f9b3f3f2950844bd41cc8923215cd5d97269) + +diff --git a/stdio-common/tst-printf-format.awk b/stdio-common/tst-printf-format.awk +index 5d0324c551..57bea12621 100644 +--- a/stdio-common/tst-printf-format.awk ++++ b/stdio-common/tst-printf-format.awk +@@ -32,6 +32,9 @@ BEGIN { + # non-bignum mode unless a sign has been explicitly given. Keep + # original 'val' for reporting. + value = gensub(/^(INF|NAN|inf|nan)/, "+\\1", 1, val) ++ # Neither changes between the conversions applied to this value. ++ value_infnan = value ~ /(INF|NAN|inf|nan)/ ++ value_zero = value == 0 + next + } + +@@ -52,7 +55,7 @@ BEGIN { + # Discard the '#' flag with the octal conversion if output starts with + # 0 in the absence of this flag. In that case no extra 0 is supposed + # to be produced, but gawk prepends it anyway. +- if (format ~ /#.*o/) ++ if (index(format, "#") && format ~ /#.*o/) + { + tmpfmt = gensub(/#/, "", "g", format) + tmpout = sprintf(tmpfmt, value) +@@ -62,7 +65,7 @@ BEGIN { + # Likewise with the hexadecimal conversion where zero value with the + # precision of zero is supposed to produce no characters, but gawk + # outputs 0 instead. +- else if (format ~ /#.*[Xx]/) ++ else if (index(format, "#") && format ~ /#.*[Xx]/) + { + tmpfmt = gensub(/#/, "", "g", format) + tmpout = sprintf(tmpfmt, value) +@@ -78,7 +81,7 @@ BEGIN { + # values and reprint the output produced using the string conversion, + # with the field width carried over and the relevant flags handled by + # hand. +- if (format ~ /[EFGefg]/ && value ~ /(INF|NAN|inf|nan)/) ++ if (value_infnan && format ~ /[EFGefg]/) + { + minus = format ~ /-/ ? "-" : "" + sign = value ~ /-/ ? "-" : format ~ /\+/ ? "+" : format ~ / / ? " " : "" +@@ -94,7 +97,7 @@ BEGIN { + # In that case "+" is always supposed to be produced, but with the + # precision of zero gawk in the non-bignum mode produces any padding + # requested only. +- else if (format ~ /\+.*[di]/ && value == 0) ++ else if (value_zero && format ~ /\+.*[di]/) + { + output = gensub(/^( *) $/, format ~ /-/ ? "+\\1" : "\\1+", 1, output) + output = gensub(/^$/, "+", 1, output) +@@ -103,7 +106,7 @@ BEGIN { + # conversion for zero value. In that case at least one " " is + # supposed to be produced, but with the precision of zero gawk in the + # non-bignum mode produces nothing. +- else if (format ~ / .*[di]/ && value == 0) ++ else if (value_zero && format ~ / .*[di]/) + { + output = gensub(/^$/, " ", 1, output) + } + +commit 65d35639a9d055e423345c8748908c8aa48b19b9 +Author: Magnus Lindholm +Date: Wed Aug 5 23:14:58 2026 +0200 + + string: Speed up strcmp test data initialization + + The strcmp and strncmp tests repeatedly initialize large buffers for + many combinations of lengths and alignments. The existing loops + perform a remainder operation and two individual stores for every + element. + + Generate at most max_char elements using an additive recurrence. The + recurrence produces the same sequence as the existing multiplication + and remainder expression. Expand this initial pattern using bulk + copies, and then copy the completed first buffer to the second buffer. + + This preserves the generated test data while substantially reducing + the initialization cost on slower systems. + + The change also applies to the wcscmp and wcsncmp tests, which include + the same test sources. + + Signed-off-by: Magnus Lindholm + Reviewed-by: Adhemerval Zanella + (cherry picked from commit 9b323b95567dff46b34157ac4455734633921abb) + +diff --git a/string/test-strcmp.c b/string/test-strcmp.c +index 76ccff46e2..ca52827b11 100644 +--- a/string/test-strcmp.c ++++ b/string/test-strcmp.c +@@ -156,6 +156,10 @@ do_test (size_t align1, size_t align2, size_t len, int max_char, + int exp_result) + { + size_t i; ++ size_t value = 0; ++ size_t pattern_len; ++ size_t step ++ = (23U << ((CHARBYTES - 1) * 8)) % (size_t) max_char; + + CHAR *s1, *s2; + +@@ -179,8 +183,28 @@ do_test (size_t align1, size_t align2, size_t len, int max_char, + i = align2 + CHARBYTES * (len + 2); + s2 = (CHAR *)(buf2 + ((page_size - i) / 16 * 16) + align2); + +- for (i = 0; i < len; i++) +- s1[i] = s2[i] = 1 + (23 << ((CHARBYTES - 1) * 8)) * i % max_char; ++ /* The generated sequence repeats after at most max_char elements. */ ++ pattern_len ++ = len < (size_t) max_char ? len : (size_t) max_char; ++ ++ for (i = 0; i < pattern_len; i++) ++ { ++ s1[i] = 1 + value; ++ ++ value += step; ++ if (value >= (size_t) max_char) ++ value -= max_char; ++ } ++ ++ while (i < len) ++ { ++ size_t copy = i < len - i ? i : len - i; ++ ++ MEMCPY (s1 + i, s1, copy); ++ i += copy; ++ } ++ ++ MEMCPY (s2, s1, len); + + s1[len] = s2[len] = 0; + s1[len + 1] = 23; +diff --git a/string/test-strncmp.c b/string/test-strncmp.c +index 54ada39eb2..9da0f21f60 100644 +--- a/string/test-strncmp.c ++++ b/string/test-strncmp.c +@@ -190,6 +190,9 @@ do_test_n (size_t align1, size_t align2, size_t len, size_t n, int n_in_bounds, + { + size_t i, buf_bound; + CHAR *s1, *s2, *s1_end, *s2_end; ++ size_t value = 0; ++ size_t pattern_len; ++ size_t step = (23U << ((CHARBYTES - 1) * 8)) % (size_t) max_char; + + align1 &= ~(CHARBYTES - 1); + align2 &= ~(CHARBYTES - 1); +@@ -216,8 +219,29 @@ do_test_n (size_t align1, size_t align2, size_t len, size_t n, int n_in_bounds, + s2[n] = 23; + } + +- for (i = 0; i < buf_bound; i++) +- s1[i] = s2[i] = 1 + (23 << ((CHARBYTES - 1) * 8)) * i % max_char; ++ /* The generated sequence repeats after at most max_char elements. */ ++ pattern_len ++ = buf_bound < (size_t) max_char ++ ? buf_bound : (size_t) max_char; ++ ++ for (i = 0; i < pattern_len; i++) ++ { ++ s1[i] = 1 + value; ++ ++ value += step; ++ if (value >= (size_t) max_char) ++ value -= max_char; ++ } ++ ++ while (i < buf_bound) ++ { ++ size_t copy = i < buf_bound - i ? i : buf_bound - i; ++ ++ MEMCPY (s1 + i, s1, copy); ++ i += copy; ++ } ++ ++ MEMCPY (s2, s1, buf_bound); + + s1[len] = 0; + s2[len] = 0; + +commit 11ac3d78fc5e4f7f2846002e099f773ad8ff82fc +Author: Magnus Lindholm +Date: Wed Aug 5 23:14:59 2026 +0200 + + string: Speed up strcasecmp test data initialization + + The strcasecmp and strncasecmp tests repeatedly initialize large + buffers for many combinations of lengths and alignments. The existing + loops perform a remainder operation and call toupper and tolower for + every element. + + Generate at most max_char elements using an additive recurrence and + apply the case conversions while creating this initial pattern. The + recurrence produces the same sequence as the existing multiplication + and remainder expression. Expand the completed pattern using bulk + copies. + + This preserves the generated test data and locale-dependent case + conversion while substantially reducing the initialization cost on + slower systems. + + Signed-off-by: Magnus Lindholm + Reviewed-by: Adhemerval Zanella + (cherry picked from commit c1fb5d0e6b8d292ac526974d05c5adb4c3827fb0) + +diff --git a/string/test-strcasecmp.c b/string/test-strcasecmp.c +index a5235fa1bb..d090dcbf36 100644 +--- a/string/test-strcasecmp.c ++++ b/string/test-strcasecmp.c +@@ -63,6 +63,9 @@ do_test (size_t align1, size_t align2, size_t len, int max_char, + int exp_result) + { + size_t i; ++ size_t value = 0; ++ size_t step = 23U % (size_t) max_char; ++ size_t pattern_len; + char *s1, *s2; + + if (len == 0) +@@ -80,10 +83,25 @@ do_test (size_t align1, size_t align2, size_t len, int max_char, + s1 = (char *) (buf1 + align1); + s2 = (char *) (buf2 + align2); + +- for (i = 0; i < len; i++) ++ pattern_len ++ = len < (size_t) max_char ? len : (size_t) max_char; ++ ++ for (i = 0; i < pattern_len; i++) + { +- s1[i] = toupper (1 + 23 * i % max_char); ++ s1[i] = toupper (1 + value); + s2[i] = tolower (s1[i]); ++ value += step; ++ if (value >= (size_t) max_char) ++ value -= max_char; ++ } ++ ++ while (i < len) ++ { ++ size_t copy = i < len - i ? i : len - i; ++ ++ memcpy (s1 + i, s1, copy); ++ memcpy (s2 + i, s2, copy); ++ i += copy; + } + + s1[len] = s2[len] = 0; +diff --git a/string/test-strncasecmp.c b/string/test-strncasecmp.c +index 035c680532..6b00113e66 100644 +--- a/string/test-strncasecmp.c ++++ b/string/test-strncasecmp.c +@@ -83,6 +83,9 @@ do_test (size_t align1, size_t align2, size_t n, size_t len, int max_char, + int exp_result) + { + size_t i; ++ size_t value = 0; ++ size_t step = 23U % (size_t) max_char; ++ size_t pattern_len; + char *s1, *s2; + + if (len == 0) +@@ -100,10 +103,26 @@ do_test (size_t align1, size_t align2, size_t n, size_t len, int max_char, + s1 = (char *) (buf1 + align1); + s2 = (char *) (buf2 + align2); + +- for (i = 0; i < len; i++) ++ pattern_len ++ = len < (size_t) max_char ? len : (size_t) max_char; ++ ++ for (i = 0; i < pattern_len; i++) + { +- s1[i] = toupper (1 + 23 * i % max_char); ++ s1[i] = toupper (1 + value); + s2[i] = tolower (s1[i]); ++ ++ value += step; ++ if (value >= (size_t) max_char) ++ value -= max_char; ++ } ++ ++ while (i < len) ++ { ++ size_t copy = i < len - i ? i : len - i; ++ ++ memcpy (s1 + i, s1, copy); ++ memcpy (s2 + i, s2, copy); ++ i += copy; + } + + s1[len] = s2[len] = 0; + +commit 16be1518495f1fa05481b0182c4e4c24927c62df +Author: Adhemerval Zanella +Date: Mon Aug 3 11:02:53 2026 -0300 + + elf: Honour skip_ifunc for cross-object IFUNC relocations [BZ #34428] + + Commit 63b31c05a8a ("elf: Defer all IRELATIVE relocations until after PLT + setup") dropped the skip_ifunc argument from elf_dynamic_do_Rel, assuming + the new deferred elf_dynamic_do_Rel_irelative pass handles every relocation + that may run an IFUNC resolver. That only holds for IFUNC symbols defined + in the object being relocated: a reference to an IFUNC in another object is + an ordinary JMP_SLOT or GLOB_DAT against an undefined symbol, and its IFUNC + nature is only known after symbol resolution inside elf_machine_rel. Those + relocations stay in the regular pass, which no longer propagated + skip_ifunc, so __RTLD_NOIFUNC was ignored for them. + + ldd -u forces non-lazy binding (GLRO(dl_lazy) = 0 for DL_DEBUG_UNUSED), so + the resolver was called and the diagnostic emitted: + + $ ldd -u /bin/ls + /bin/ls: Relink `' with `/usr/lib64/libc.so.6' for IFUNC symbol `__mempcpy_chk' + + ldd -r with LD_BIND_NOW is affected in the same way. + + Restore the skip_ifunc parameter and thread it through _ELF_DYNAMIC_DO_RELOC. + + This new semantic shows that ELF_DYNAMIC_RELOCATE_NOIFUNC naming is misleading + (it reads as "do not process IFUNC", yet it takes a skip_ifunc + argument). Replace it to: + + DL_RELOC_BOTH -> DL_RELOC_ALL + DL_RELOC_NOIFUNC -> DL_RELOC_NORMAL + DL_RELOC_IFUNC -> DL_RELOC_IRELATIVE + + ELF_DYNAMIC_RELOCATE_NOIFUNC and ELF_DYNAMIC_RELOCATE_IFUNC become a single + ELF_DYNAMIC_RELOCATE_PASS taking the pass as its first argument, and + ELF_DYNAMIC_DO_REL/ELF_DYNAMIC_DO_RELA take the pass instead of having three + near-identical variants each. + + Checked on x86_64-linux-gnu, and built for all supported architectures. + + Reviewed-by: Sam James + + (cherry picked from commit 2f2e9bae4093e1c3ba61250e340d3c3b99788f68) + +diff --git a/elf/Makefile b/elf/Makefile +index 8b063e1bba..d279a5135c 100644 +--- a/elf/Makefile ++++ b/elf/Makefile +@@ -1396,6 +1396,13 @@ modules-names += \ + tst-ifunc-tls-write-lib \ + tst-tls-tdata-reloc-lib \ + # modules-names ++ifeq (yes,$(have-gcc-ifunc)) ++tests += \ ++ tst-ifunc-fault-dep-bindnow \ ++ tst-ifunc-fault-dep-lazy \ ++ # tests ++modules-names += tst-ifunc-fault-mod ++endif + ifneq (no,$(have-test-mtls-descriptor)) + tests += tst-ifunc-tls-init-tlsdesc + modules-names += tst-ifunc-tls-init-tlsdesc-lib +@@ -2547,6 +2554,27 @@ $(objpfx)tst-ifunc-fault-bindnow.out: $(objpfx)tst-ifunc-fault-bindnow \ + $(objpfx)ld.so + $(tst-ifunc-fault-script) + ++LDFLAGS-tst-ifunc-fault-dep-lazy = -Wl,-z,lazy ++LDFLAGS-tst-ifunc-fault-dep-bindnow = -Wl,-z,now ++define tst-ifunc-fault-dep-script ++( $(test-wrapper) $(rtld-prefix) --verify $< \ ++ && $(test-wrapper-env) LD_TRACE_LOADED_OBJECTS=1 $(rtld-prefix) $< \ ++ && $(test-wrapper-env) LD_TRACE_LOADED_OBJECTS=1 LD_DEBUG=unused \ ++ $(rtld-prefix) $< \ ++ && $(test-wrapper-env) LD_TRACE_LOADED_OBJECTS=1 LD_WARN=yes LD_BIND_NOW=1 \ ++ $(rtld-prefix) $< \ ++) > $@; $(evaluate-test) ++endef ++$(objpfx)tst-ifunc-fault-dep-lazy: $(objpfx)tst-ifunc-fault-mod.so ++$(objpfx)tst-ifunc-fault-dep-bindnow: $(objpfx)tst-ifunc-fault-mod.so ++$(objpfx)tst-ifunc-fault-dep-lazy.out: $(objpfx)tst-ifunc-fault-dep-lazy \ ++ $(objpfx)tst-ifunc-fault-mod.so $(objpfx)ld.so ++ $(tst-ifunc-fault-dep-script) ++$(objpfx)tst-ifunc-fault-dep-bindnow.out: \ ++ $(objpfx)tst-ifunc-fault-dep-bindnow \ ++ $(objpfx)tst-ifunc-fault-mod.so $(objpfx)ld.so ++ $(tst-ifunc-fault-dep-script) ++ + LDFLAGS-tst-ifunc-plt-lib.so = -Wl,-z,lazy + + tst-ifunc-plt-bindnow-ENV = LD_BIND_NOW=1 +diff --git a/elf/dl-reloc-static-pie.c b/elf/dl-reloc-static-pie.c +index 8463e46147..5dc5a545a8 100644 +--- a/elf/dl-reloc-static-pie.c ++++ b/elf/dl-reloc-static-pie.c +@@ -80,7 +80,7 @@ _dl_relocate_static_pie (void) + + /* Relocate ourselves so we can do normal function calls and data access + using the global offset table. IRELATIVE entries are deferred. */ +- ELF_DYNAMIC_RELOCATE_NOIFUNC (main_map, NULL, 0, 0); ++ ELF_DYNAMIC_RELOCATE_PASS (DL_RELOC_NORMAL, main_map, NULL, 0, 0, 0); + + /* Initialize _r_debug_extended. */ + struct r_debug *r = _dl_debug_initialize (0, LM_ID_BASE); +@@ -98,7 +98,7 @@ void + _dl_relocate_static_pie_ifunc (void) + { + struct link_map *main_map = _dl_get_dl_main_map (); +- ELF_DYNAMIC_RELOCATE_IFUNC (main_map, NULL, 0, 0); ++ ELF_DYNAMIC_RELOCATE_PASS (DL_RELOC_IRELATIVE, main_map, NULL, 0, 0, 0); + main_map->l_relocated = 1; + } + #endif +diff --git a/elf/dl-reloc.c b/elf/dl-reloc.c +index 15a6a4cffe..fa2f41ac44 100644 +--- a/elf/dl-reloc.c ++++ b/elf/dl-reloc.c +@@ -278,7 +278,8 @@ _dl_relocate_object_no_relro (struct link_map *l, struct r_scope_elem *scope[], + IFUNC resolvers. Without this, a resolver would see the unrelocated + initialiser bytes that were placed into the slot by the early + _dl_allocate_tls_init. */ +- ELF_DYNAMIC_RELOCATE_NOIFUNC (l, scope, lazy, consider_profiling); ++ ELF_DYNAMIC_RELOCATE_PASS (DL_RELOC_NORMAL, l, scope, lazy, ++ consider_profiling, skip_ifunc); + + #ifdef SHARED + /* Re-initialise the static TLS slot with the .tdata so the IRELATIVE +@@ -291,7 +292,8 @@ _dl_relocate_object_no_relro (struct link_map *l, struct r_scope_elem *scope[], + _dl_init_static_tls (l); + #endif + +- ELF_DYNAMIC_RELOCATE_IFUNC (l, scope, lazy, skip_ifunc); ++ ELF_DYNAMIC_RELOCATE_PASS (DL_RELOC_IRELATIVE, l, scope, lazy, ++ 0, skip_ifunc); + + if ((consider_profiling || consider_symbind) + && l->l_info[DT_PLTRELSZ] != NULL) +diff --git a/elf/do-rel.h b/elf/do-rel.h +index 7702244734..c610d12dbe 100644 +--- a/elf/do-rel.h ++++ b/elf/do-rel.h +@@ -79,17 +79,23 @@ elf_dynamic_Rel_audit_symbind (struct link_map *map, + /* Perform the relocations in MAP on the running program image as specified + by RELTAG, SZTAG. If LAZY is nonzero, this is the first pass on PLT + relocations; they should be set up to call _dl_runtime_resolve, rather +- than fully resolved now. ++ than fully resolved now. If SKIP_IFUNC is nonzero no IFUNC resolver is ++ called; this is required for the trace modes (ldd -u / ldd -r), which ++ relocate objects. + +- IRELATIVE entries are always skipped (non-bootstrap); they are handled ++ IRELATIVE entries and relocations against an STT_GNU_IFUNC symbol defined ++ in MAP itself are always skipped (non-bootstrap); they are handled + separately by elf_dynamic_do_Rel_irelative after all other relocations +- for both .rel.dyn and .rel.plt have been processed. */ ++ for both .rel.dyn and .rel.plt have been processed. Relocations against ++ an IFUNC symbol defined in *another* object are not deferred, since the ++ IFUNC symbol is only known after symbol resolution, and the defining object ++ has already been relocated at this point. */ + + static inline void __attribute__ ((always_inline)) + elf_dynamic_do_Rel (struct link_map *map, struct r_scope_elem *scope[], + ElfW(Addr) reladdr, ElfW(Addr) relsize, + __typeof (((ElfW(Dyn) *) 0)->d_un.d_val) nrelative, +- int lazy) ++ int lazy, int skip_ifunc) + { + const ElfW(Rel) *relative = (const void *) reladdr; + const ElfW(Rel) *r = relative + nrelative; +@@ -111,7 +117,7 @@ elf_dynamic_do_Rel (struct link_map *map, struct r_scope_elem *scope[], + void *const r_addr_arg = (void *) (l_addr + r->r_offset); + const struct r_found_version *rversion = &map->l_versions[ndx]; + +- elf_machine_rel (map, scope, r, sym, rversion, r_addr_arg, 0); ++ elf_machine_rel (map, scope, r, sym, rversion, r_addr_arg, skip_ifunc); + } + #else /* !RTLD_BOOTSTRAP */ + #if !defined DO_RELA || !defined ELF_MACHINE_PLT_REL +@@ -126,7 +132,7 @@ elf_dynamic_do_Rel (struct link_map *map, struct r_scope_elem *scope[], + const ElfW (Sym) *sym = &symtab[ELFW (R_SYM) (r->r_info)]; + if (elf_dynamic_is_Rel_irelative (r, sym)) + continue; +- elf_machine_lazy_rel (map, scope, l_addr, r, 0); ++ elf_machine_lazy_rel (map, scope, l_addr, r, skip_ifunc); + } + } + else +@@ -158,7 +164,8 @@ elf_dynamic_do_Rel (struct link_map *map, struct r_scope_elem *scope[], + + if (elf_dynamic_is_Rel_irelative (r, sym)) + continue; +- elf_machine_rel (map, scope, r, sym, rversion, r_addr_arg, 0); ++ elf_machine_rel (map, scope, r, sym, rversion, r_addr_arg, ++ skip_ifunc); + elf_dynamic_Rel_audit_symbind (map, scope, r, sym, rversion, + r_addr_arg); + } +@@ -172,7 +179,8 @@ elf_dynamic_do_Rel (struct link_map *map, struct r_scope_elem *scope[], + + if (elf_dynamic_is_Rel_irelative (r, sym)) + continue; +- elf_machine_rel (map, scope, r, sym, NULL, r_addr_arg, 0); ++ elf_machine_rel (map, scope, r, sym, NULL, r_addr_arg, ++ skip_ifunc); + elf_dynamic_Rel_audit_symbind (map, scope, r, sym, NULL, + r_addr_arg); + } +diff --git a/elf/dynamic-link.h b/elf/dynamic-link.h +index 35141acec4..0130c63feb 100644 +--- a/elf/dynamic-link.h ++++ b/elf/dynamic-link.h +@@ -78,18 +78,23 @@ elf_machine_lazy_rel (struct link_map *map, struct r_scope_elem *scope[], + consumes precisely the very end of the DT_REL*, or DT_JMPREL and DT_REL* + are completely separate and there is a gap between them. */ + +-/* This controls which sub-passes _ELF_DYNAMIC_DO_RELOC runs. Used to +- interleave TLS / stack-protector setup between the two passes so IFUNC +- resolvers see a fully-initialised TCB. */ +-enum elf_dynamic_reloc_phase ++/* Selects which relocations a pass processes. Splitting them allows the ++ caller to interleave TLS / stack-protector setup between the two passes, ++ so IFUNC resolvers see a fully-initialised TCB. ++ ++ This is orthogonal to the skip_ifunc argument, which says whether an IFUNC ++ resolver may be run at all and is honoured by every pass. In particular ++ DL_RELOC_NORMAL also runs IFUNC resolvers, for relocations against an ++ IFUNC symbol defined in another object. */ ++enum elf_dynamic_reloc_pass + { +- DL_RELOC_BOTH = 0, /* Non-IRELATIVE pass then IRELATIVE pass. */ +- DL_RELOC_NOIFUNC = 1, /* Non-IRELATIVE pass only. */ +- DL_RELOC_IFUNC = 2, /* IRELATIVE pass only. */ ++ DL_RELOC_ALL = 0, /* Non-IRELATIVE relocations, then IRELATIVE. */ ++ DL_RELOC_NORMAL = 1, /* Non-IRELATIVE relocations only. */ ++ DL_RELOC_IRELATIVE = 2, /* IRELATIVE relocations only. */ + }; + + # define _ELF_DYNAMIC_DO_RELOC(RELOC, reloc, map, scope, do_lazy, skip_ifunc, \ +- test_rel, phase) \ ++ test_rel, pass) \ + do { \ + struct { ElfW(Addr) start, size; \ + __typeof (((ElfW(Dyn) *) 0)->d_un.d_val) nrelative; int lazy; } \ +@@ -136,14 +141,15 @@ enum elf_dynamic_reloc_phase + by the linker. */ \ + if (!DO_RTLD_BOOTSTRAP) \ + { \ +- if ((phase) != DL_RELOC_IFUNC) \ ++ if ((pass) != DL_RELOC_IRELATIVE) \ + for (int ranges_index = 0; ranges_index < 2; ++ranges_index) \ + elf_dynamic_do_##reloc ((map), scope, \ + ranges[ranges_index].start, \ + ranges[ranges_index].size, \ + ranges[ranges_index].nrelative, \ +- ranges[ranges_index].lazy); \ +- if ((phase) != DL_RELOC_NOIFUNC) \ ++ ranges[ranges_index].lazy, \ ++ skip_ifunc); \ ++ if ((pass) != DL_RELOC_NORMAL) \ + for (int ranges_index = 0; ranges_index < 2; ++ranges_index) \ + elf_dynamic_do_##reloc##_irelative ((map), scope, \ + ranges[ranges_index].start, \ +@@ -158,7 +164,8 @@ enum elf_dynamic_reloc_phase + ranges[ranges_index].start, \ + ranges[ranges_index].size, \ + ranges[ranges_index].nrelative, \ +- ranges[ranges_index].lazy); \ ++ ranges[ranges_index].lazy, \ ++ skip_ifunc); \ + } while (0) + + # if ELF_MACHINE_NO_REL || ELF_MACHINE_NO_RELA +@@ -169,37 +176,21 @@ enum elf_dynamic_reloc_phase + + # if ! ELF_MACHINE_NO_REL + # include "do-rel.h" +-# define ELF_DYNAMIC_DO_REL(map, scope, lazy, skip_ifunc) \ +- _ELF_DYNAMIC_DO_RELOC (REL, Rel, map, scope, lazy, skip_ifunc, \ +- _ELF_CHECK_REL, DL_RELOC_BOTH) +-# define ELF_DYNAMIC_DO_REL_NOIFUNC(map, scope, lazy) \ +- _ELF_DYNAMIC_DO_RELOC (REL, Rel, map, scope, lazy, 0, \ +- _ELF_CHECK_REL, DL_RELOC_NOIFUNC) +-# define ELF_DYNAMIC_DO_REL_IFUNCONLY(map, scope, lazy, skip_ifunc) \ ++# define ELF_DYNAMIC_DO_REL(map, scope, lazy, skip_ifunc, pass) \ + _ELF_DYNAMIC_DO_RELOC (REL, Rel, map, scope, lazy, skip_ifunc, \ +- _ELF_CHECK_REL, DL_RELOC_IFUNC) ++ _ELF_CHECK_REL, pass) + # else +-# define ELF_DYNAMIC_DO_REL(map, scope, lazy, skip_ifunc) /* Nothing to do. */ +-# define ELF_DYNAMIC_DO_REL_NOIFUNC(map, scope, lazy) /* Nothing to do. */ +-# define ELF_DYNAMIC_DO_REL_IFUNCONLY(map, scope, lazy, skip_ifunc) /* Nothing. */ ++# define ELF_DYNAMIC_DO_REL(map, scope, lazy, skip_ifunc, pass) /* Nothing. */ + # endif + + # if ! ELF_MACHINE_NO_RELA + # define DO_RELA + # include "do-rel.h" +-# define ELF_DYNAMIC_DO_RELA(map, scope, lazy, skip_ifunc) \ +- _ELF_DYNAMIC_DO_RELOC (RELA, Rela, map, scope, lazy, skip_ifunc, \ +- _ELF_CHECK_REL, DL_RELOC_BOTH) +-# define ELF_DYNAMIC_DO_RELA_NOIFUNC(map, scope, lazy) \ +- _ELF_DYNAMIC_DO_RELOC (RELA, Rela, map, scope, lazy, 0, \ +- _ELF_CHECK_REL, DL_RELOC_NOIFUNC) +-# define ELF_DYNAMIC_DO_RELA_IFUNCONLY(map, scope, lazy, skip_ifunc) \ ++# define ELF_DYNAMIC_DO_RELA(map, scope, lazy, skip_ifunc, pass) \ + _ELF_DYNAMIC_DO_RELOC (RELA, Rela, map, scope, lazy, skip_ifunc, \ +- _ELF_CHECK_REL, DL_RELOC_IFUNC) ++ _ELF_CHECK_REL, pass) + # else +-# define ELF_DYNAMIC_DO_RELA(map, scope, lazy, skip_ifunc) /* Nothing to do. */ +-# define ELF_DYNAMIC_DO_RELA_NOIFUNC(map, scope, lazy) /* Nothing to do. */ +-# define ELF_DYNAMIC_DO_RELA_IFUNCONLY(map, scope, lazy, skip_ifunc) /* Nothing. */ ++# define ELF_DYNAMIC_DO_RELA(map, scope, lazy, skip_ifunc, pass) /* Nothing. */ + # endif + + # define ELF_DYNAMIC_DO_RELR(map) \ +@@ -240,37 +231,33 @@ enum elf_dynamic_reloc_phase + # else + # define DO_RTLD_BOOTSTRAP 0 + # endif +-# define ELF_DYNAMIC_RELOCATE(map, scope, lazy, consider_profile, skip_ifunc) \ +- do { \ +- int edr_lazy = elf_machine_runtime_setup ((map), (scope), (lazy), \ +- (consider_profile)); \ +- if (!is_rtld_link_map (map) || DO_RTLD_BOOTSTRAP) \ +- ELF_DYNAMIC_DO_RELR (map); \ +- ELF_DYNAMIC_DO_REL ((map), (scope), edr_lazy, skip_ifunc); \ +- ELF_DYNAMIC_DO_RELA ((map), (scope), edr_lazy, skip_ifunc); \ +- ELF_DYNAMIC_AFTER_RELOC ((map), (edr_lazy)); \ +- } while (0) ++/* Perform one relocation pass over MAP. PASS selects which relocations are ++ processed. It is orthogonal to SKIP_IFUNC, which suppresses running IFUNC ++ resolvers in whichever pass is selected. + +-/* Like ELF_DYNAMIC_RELOCATE but only processes the non-IRELATIVE pass. +- The IRELATIVE pass must be completed later via ELF_DYNAMIC_RELOCATE_IFUNC. +- Used by the static-pie startup so the TCB and stack-protector canary can +- be initialised between the two passes. */ +-# define ELF_DYNAMIC_RELOCATE_NOIFUNC(map, scope, lazy, consider_profile) \ ++ Unless PASS is DL_RELOC_IRELATIVE, this also performs the machine-specific ++ PLT/GOT setup, the DT_RELR relocations, and the ELF_DYNAMIC_AFTER_RELOC ++ hook. */ ++# define ELF_DYNAMIC_RELOCATE_PASS(pass, map, scope, lazy, consider_profile, \ ++ skip_ifunc) \ + do { \ +- int edr_lazy = elf_machine_runtime_setup ((map), (scope), (lazy), \ ++ int edr_lazy = (lazy); \ ++ if ((pass) != DL_RELOC_IRELATIVE) \ ++ { \ ++ edr_lazy = elf_machine_runtime_setup ((map), (scope), (lazy), \ + (consider_profile)); \ +- if (!is_rtld_link_map (map) || DO_RTLD_BOOTSTRAP) \ +- ELF_DYNAMIC_DO_RELR (map); \ +- ELF_DYNAMIC_DO_REL_NOIFUNC ((map), (scope), edr_lazy); \ +- ELF_DYNAMIC_DO_RELA_NOIFUNC ((map), (scope), edr_lazy); \ +- ELF_DYNAMIC_AFTER_RELOC ((map), (edr_lazy)); \ ++ if (!is_rtld_link_map (map) || DO_RTLD_BOOTSTRAP) \ ++ ELF_DYNAMIC_DO_RELR (map); \ ++ } \ ++ ELF_DYNAMIC_DO_REL ((map), (scope), edr_lazy, skip_ifunc, (pass)); \ ++ ELF_DYNAMIC_DO_RELA ((map), (scope), edr_lazy, skip_ifunc, (pass)); \ ++ if ((pass) != DL_RELOC_IRELATIVE) \ ++ ELF_DYNAMIC_AFTER_RELOC ((map), edr_lazy); \ + } while (0) + +-/* IRELATIVE-only companion to ELF_DYNAMIC_RELOCATE_NOIFUNC. */ +-# define ELF_DYNAMIC_RELOCATE_IFUNC(map, scope, lazy, skip_ifunc) \ +- do { \ +- ELF_DYNAMIC_DO_REL_IFUNCONLY ((map), (scope), (lazy), skip_ifunc); \ +- ELF_DYNAMIC_DO_RELA_IFUNCONLY ((map), (scope), (lazy), skip_ifunc); \ +- } while (0) ++/* Run both passes back to back, for callers with nothing to interleave. */ ++# define ELF_DYNAMIC_RELOCATE(map, scope, lazy, consider_profile, skip_ifunc) \ ++ ELF_DYNAMIC_RELOCATE_PASS (DL_RELOC_ALL, (map), (scope), (lazy), \ ++ (consider_profile), skip_ifunc) + + #endif +diff --git a/elf/tst-ifunc-fault-dep-bindnow.c b/elf/tst-ifunc-fault-dep-bindnow.c +new file mode 100644 +index 0000000000..60d97dcaa4 +--- /dev/null ++++ b/elf/tst-ifunc-fault-dep-bindnow.c +@@ -0,0 +1,19 @@ ++/* Program calling an IFUNC defined in a dependency. BIND_NOW variant. ++ Copyright (C) 2026 Free Software Foundation, Inc. ++ This file is part of the GNU C Library. ++ ++ The GNU C Library is free software; you can redistribute it and/or ++ modify it under the terms of the GNU Lesser General Public ++ License as published by the Free Software Foundation; either ++ version 2.1 of the License, or (at your option) any later version. ++ ++ The GNU C Library is distributed in the hope that it will be useful, ++ but WITHOUT ANY WARRANTY; without even the implied warranty of ++ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU ++ Lesser General Public License for more details. ++ ++ You should have received a copy of the GNU Lesser General Public ++ License along with the GNU C Library; if not, see ++ . */ ++ ++#include "tst-ifunc-fault-dep-lazy.c" +diff --git a/elf/tst-ifunc-fault-dep-lazy.c b/elf/tst-ifunc-fault-dep-lazy.c +new file mode 100644 +index 0000000000..122d33f391 +--- /dev/null ++++ b/elf/tst-ifunc-fault-dep-lazy.c +@@ -0,0 +1,27 @@ ++/* Program calling an IFUNC defined in a dependency (BZ 34428). ++ Copyright (C) 2026 Free Software Foundation, Inc. ++ This file is part of the GNU C Library. ++ ++ The GNU C Library is free software; you can redistribute it and/or ++ modify it under the terms of the GNU Lesser General Public ++ License as published by the Free Software Foundation; either ++ version 2.1 of the License, or (at your option) any later version. ++ ++ The GNU C Library is distributed in the hope that it will be useful, ++ but WITHOUT ANY WARRANTY; without even the implied warranty of ++ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU ++ Lesser General Public License for more details. ++ ++ You should have received a copy of the GNU Lesser General Public ++ License along with the GNU C Library; if not, see ++ . */ ++ ++extern void magic (void); ++ ++int ++main (void) ++{ ++ /* JMP_SLOT relocation against an undefined symbol. */ ++ magic (); ++ return 1; ++} +diff --git a/elf/tst-ifunc-fault-mod.c b/elf/tst-ifunc-fault-mod.c +new file mode 100644 +index 0000000000..11c21b48ac +--- /dev/null ++++ b/elf/tst-ifunc-fault-mod.c +@@ -0,0 +1,38 @@ ++/* Shared object exporting an IFUNC symbol with a resolver which crashes. ++ Copyright (C) 2026 Free Software Foundation, Inc. ++ This file is part of the GNU C Library. ++ ++ The GNU C Library is free software; you can redistribute it and/or ++ modify it under the terms of the GNU Lesser General Public ++ License as published by the Free Software Foundation; either ++ version 2.1 of the License, or (at your option) any later version. ++ ++ The GNU C Library is distributed in the hope that it will be useful, ++ but WITHOUT ANY WARRANTY; without even the implied warranty of ++ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU ++ Lesser General Public License for more details. ++ ++ You should have received a copy of the GNU Lesser General Public ++ License along with the GNU C Library; if not, see ++ . */ ++ ++#include ++ ++static void ++implementation (void) ++{ ++ /* Produce a crash, without depending on any relocations. */ ++ volatile char *volatile p = NULL; ++ *p = 0; ++} ++ ++static __typeof__ (implementation) * ++resolver (void) ++{ ++ /* Produce a crash, without depending on any relocations. */ ++ volatile char *volatile p = NULL; ++ *p = 0; ++ return implementation; ++} ++ ++void magic (void) __attribute__ ((ifunc ("resolver"))); + +commit afd131806b25715a7617ab757db43f0bb610acbf +Author: Adhemerval Zanella +Date: Wed Aug 12 09:03:17 2026 -0300 + + m68k: Fix fmod/fmodf infinite recursion (BZ 34508) + + Commits 6deadd4eb6a and ade9f30ce27 changed m68k fmod to call + __m81_u(fmod), instead of the mathimpl.h inline + __m81_u(__ieee754_fmod) (that wraps the m68k fmod instruction). + This leads to infinite recursion. + + Tested-by: John Paul Adrian Glaubitz + + (cherry picked from commit bb213471bedc177b8efd3178584137fb81cc976a) + +diff --git a/NEWS b/NEWS +index d0ef2d3e9a..697049efd1 100644 +--- a/NEWS ++++ b/NEWS +@@ -18,6 +18,8 @@ The following bugs are resolved with this release: + [34441] math: math: sinh() returns wrong results for some inputs with + |x| > 36.736801 + [34465] math: math: x86_64 tanh ifunc selection wrong ++ [34509] libc: [m68k] Regression: Perl locks up after upgrading glibc ++ to 2.43 + + Version 2.44 + +diff --git a/sysdeps/m68k/m680x0/fpu/e_fmod.c b/sysdeps/m68k/m680x0/fpu/e_fmod.c +index 9ad6924422..faac7c79e3 100644 +--- a/sysdeps/m68k/m680x0/fpu/e_fmod.c ++++ b/sysdeps/m68k/m680x0/fpu/e_fmod.c +@@ -33,7 +33,7 @@ __fmod (double x, double y) + && !is_nan (hx))) + return __math_invalid (x); + +- return __m81_u(fmod)(x, y); ++ return __m81_u(__ieee754_fmod)(x, y); + } + strong_alias (__fmod, __ieee754_fmod) + libm_alias_finite (__ieee754_fmod, __fmod) +diff --git a/sysdeps/m68k/m680x0/fpu/e_fmodf.c b/sysdeps/m68k/m680x0/fpu/e_fmodf.c +index a3bd24b71f..98797e0887 100644 +--- a/sysdeps/m68k/m680x0/fpu/e_fmodf.c ++++ b/sysdeps/m68k/m680x0/fpu/e_fmodf.c +@@ -34,7 +34,7 @@ __fmodf (float x, float y) + && !is_nan (hx))) + return __math_invalidf (x); + +- return __m81_u(fmodf)(x, y); ++ return __m81_u(__ieee754_fmodf)(x, y); + } + strong_alias (__fmodf, __ieee754_fmodf) + versioned_symbol (libm, __fmodf, fmodf, GLIBC_2_43); diff --git a/pkgs/development/libraries/glibc/common.nix b/pkgs/development/libraries/glibc/common.nix index 4db1dac187ed..ab415d5b932f 100644 --- a/pkgs/development/libraries/glibc/common.nix +++ b/pkgs/development/libraries/glibc/common.nix @@ -50,9 +50,9 @@ }@args: let - version = "2.42"; - patchSuffix = "-84"; - sha256 = "sha256-0XdeMuRijmTvkw9DW2e7Y691may2viszW58Z8WUJ8X8="; + version = "2.44"; + patchSuffix = "-25"; + sha256 = "sha256-N/YA8r7zxegwAUcFlWiyouQKetbMxlzpQlVtSUKcxmc="; in assert withLinuxHeaders -> linuxHeaders != null; @@ -69,17 +69,17 @@ stdenv.mkDerivation ( /* No tarballs for stable upstream branch, only https://sourceware.org/git/glibc.git and using git would complicate bootstrapping. $ git fetch --all -p && git checkout origin/release/2.42/master && git describe - glibc-2.42-67-g4ebd33dd77 - $ git show --minimal --reverse glibc-2.42.. ':!ADVISORIES' > 2.42-master.patch + glibc-2.44-25-gafd131806b + $ git show --minimal --reverse glibc-2.44.. ':!ADVISORIES' > 2.44-master.patch To compare the archive contents zdiff can be used. - $ diff -u 2.42-master.patch ../nixpkgs/pkgs/development/libraries/glibc/2.42-master.patch + $ diff -u 2.44-master.patch ../nixpkgs/pkgs/development/libraries/glibc/2.44-master.patch Please note that each commit has changes to the file ADVISORIES excluded since that conflicts with the directory advisories/ making cross-builds from hosts with case-insensitive file-systems impossible. */ - ./2.42-master.patch + ./2.44-master.patch # Allow NixOS and Nix to handle the locale-archive. ./nix-locale-archive.patch diff --git a/pkgs/development/libraries/glibc/dont-use-system-ld-so-cache.patch b/pkgs/development/libraries/glibc/dont-use-system-ld-so-cache.patch index 0e0315aca270..f9f3f815bbad 100644 --- a/pkgs/development/libraries/glibc/dont-use-system-ld-so-cache.patch +++ b/pkgs/development/libraries/glibc/dont-use-system-ld-so-cache.patch @@ -1,8 +1,8 @@ diff --git a/elf/Makefile b/elf/Makefile -index 5d666b1b..a5017e9c 100644 +index dc39ccea60..3230939376 100644 --- a/elf/Makefile +++ b/elf/Makefile -@@ -669,14 +669,14 @@ $(objpfx)sln: $(sln-modules:%=$(objpfx)%.o) +@@ -1745,14 +1745,14 @@ $(objpfx)sln: $(sln-modules:%=$(objpfx)%.o) $(objpfx)ldconfig: $(ldconfig-modules:%=$(objpfx)%.o) @@ -21,36 +21,41 @@ index 5d666b1b..a5017e9c 100644 +CFLAGS-rtld.c += $(PREFIX-FLAGS) +CFLAGS-dl-usage.c += $(PREFIX-FLAGS) \ -D'RTLD="$(rtlddir)/$(rtld-installed-name)"' - - cpp-srcs-left := $(all-rtld-routines:=.os) + CFLAGS-dl-diagnostics.c += $(SYSCONF-FLAGS) \ + -D'PREFIX="$(prefix)"' \ diff --git a/elf/dl-diagnostics.c b/elf/dl-diagnostics.c -index bef224b3..8e166b12 100644 +index 21311178c7..719e02f8e6 100644 --- a/elf/dl-diagnostics.c +++ b/elf/dl-diagnostics.c -@@ -205,7 +205,7 @@ print_paths (void) +@@ -204,7 +204,7 @@ print_paths (void) { _dl_diagnostics_print_labeled_string ("path.prefix", PREFIX); _dl_diagnostics_print_labeled_string ("path.rtld", RTLD); - _dl_diagnostics_print_labeled_string ("path.sysconfdir", SYSCONFDIR); + _dl_diagnostics_print_labeled_string ("path.sysconfdir", PREFIX "/etc"); - + unsigned int index = 0; static const char *system_dirs = SYSTEM_DIRS "\0"; diff --git a/elf/ldconfig.c b/elf/ldconfig.c -index 28ed637a..6f07b79a 100644 +index a39f3ecfcd..b5f12d0760 100644 --- a/elf/ldconfig.c +++ b/elf/ldconfig.c -@@ -57,7 +57,7 @@ - #define TLS_HWCAP_BIT 63 +@@ -48,11 +48,11 @@ + #ifndef LD_SO_CONF -# define LD_SO_CONF SYSCONFDIR "/ld.so.conf" +# define LD_SO_CONF PREFIX "/etc/ld.so.conf" #endif + #ifndef TUNABLES_CONF +-# define TUNABLES_CONF SYSCONFDIR "/tunables.conf" ++# define TUNABLES_CONF PREFIX "/etc/tunables.conf" + #endif + /* Get libc version number. */ diff --git a/sysdeps/generic/dl-cache.h b/sysdeps/generic/dl-cache.h -index 964d50a4..2224d651 100644 +index 972ab32b86..a0e0775506 100644 --- a/sysdeps/generic/dl-cache.h +++ b/sysdeps/generic/dl-cache.h @@ -35,7 +35,7 @@ diff --git a/pkgs/development/libraries/gstreamer/bad/default.nix b/pkgs/development/libraries/gstreamer/bad/default.nix index e607d95bb631..d0ecc9ffb662 100644 --- a/pkgs/development/libraries/gstreamer/bad/default.nix +++ b/pkgs/development/libraries/gstreamer/bad/default.nix @@ -116,7 +116,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "gst-plugins-bad"; - version = "1.28.6"; + version = "1.28.7"; outputs = [ "out" @@ -125,7 +125,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "https://gstreamer.freedesktop.org/src/gst-plugins-bad/gst-plugins-bad-${finalAttrs.version}.tar.xz"; - hash = "sha256-Zjbywiic7aUsSrqXEzjIHitXgNM4G9NnPBwRbsh1h8M="; + hash = "sha256-3FJTg8GLLCZbvmpD1JhlbNkYqqEwqk46vqvNqnQcP/4="; }; patches = [ diff --git a/pkgs/development/libraries/gstreamer/base/default.nix b/pkgs/development/libraries/gstreamer/base/default.nix index b1a4029028fd..47ac2203b31b 100644 --- a/pkgs/development/libraries/gstreamer/base/default.nix +++ b/pkgs/development/libraries/gstreamer/base/default.nix @@ -50,7 +50,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "gst-plugins-base"; - version = "1.28.6"; + version = "1.28.7"; outputs = [ "out" @@ -61,7 +61,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "https://gstreamer.freedesktop.org/src/gst-plugins-base/gst-plugins-base-${finalAttrs.version}.tar.xz"; - hash = "sha256-C6aZx8bGb0umQL54yziiRxWt2Wg/PjoZn1Np3FpPBKw="; + hash = "sha256-7W5UEPSW0XGBh2OvImXnl3FUvH+bgn6YrPjFvtId1ac="; }; __structuredAttrs = true; diff --git a/pkgs/development/libraries/gstreamer/core/default.nix b/pkgs/development/libraries/gstreamer/core/default.nix index 354dd05ddf7c..84b116a58495 100644 --- a/pkgs/development/libraries/gstreamer/core/default.nix +++ b/pkgs/development/libraries/gstreamer/core/default.nix @@ -40,7 +40,7 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "gstreamer"; - version = "1.28.6"; + version = "1.28.7"; outputs = [ "bin" @@ -52,7 +52,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "https://gstreamer.freedesktop.org/src/gstreamer/gstreamer-${finalAttrs.version}.tar.xz"; - hash = "sha256-Yra58K0xR6bdZCCsZKkRgLFOmQaVvd01O5YEFhHQUso="; + hash = "sha256-eHMpssV1jiKKcdkmptz5YLzqrMo8rdY4dLpmXfzaAT4="; }; depsBuildBuild = [ diff --git a/pkgs/development/libraries/gstreamer/devtools/default.nix b/pkgs/development/libraries/gstreamer/devtools/default.nix index 892fe6e84af6..c4a1c36560be 100644 --- a/pkgs/development/libraries/gstreamer/devtools/default.nix +++ b/pkgs/development/libraries/gstreamer/devtools/default.nix @@ -27,7 +27,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "gst-devtools"; - version = "1.28.6"; + version = "1.28.7"; outputs = [ "out" @@ -36,7 +36,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "https://gstreamer.freedesktop.org/src/gst-devtools/gst-devtools-${finalAttrs.version}.tar.xz"; - hash = "sha256-FNQfquA2GSUflZWdPVe/ZcYQaDiztUIY3JXHE14euhM="; + hash = "sha256-nzo4nWp++loY11ZHJKfzscP67P/Lj9E1HtDoEdGHOtU="; }; cargoDeps = rustPlatform.fetchCargoVendor { diff --git a/pkgs/development/libraries/gstreamer/ges/default.nix b/pkgs/development/libraries/gstreamer/ges/default.nix index 7b0130b4c977..a4e38b3672d3 100644 --- a/pkgs/development/libraries/gstreamer/ges/default.nix +++ b/pkgs/development/libraries/gstreamer/ges/default.nix @@ -25,7 +25,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "gst-editing-services"; - version = "1.28.6"; + version = "1.28.7"; outputs = [ "out" @@ -34,7 +34,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "https://gstreamer.freedesktop.org/src/gst-editing-services/gst-editing-services-${finalAttrs.version}.tar.xz"; - hash = "sha256-PRUeUJfWhsWJCudvFMV+4ZU4/WHGz2NxcfkLMJyv1Tw="; + hash = "sha256-b/wOXM7JCq1gkdP8Aa0px5Y3UFXhO5N4r/a44cIkaKM="; }; separateDebugInfo = true; diff --git a/pkgs/development/libraries/gstreamer/good/default.nix b/pkgs/development/libraries/gstreamer/good/default.nix index f149568a0f86..0ebab99bc829 100644 --- a/pkgs/development/libraries/gstreamer/good/default.nix +++ b/pkgs/development/libraries/gstreamer/good/default.nix @@ -81,7 +81,7 @@ assert raspiCameraSupport -> hostSupportsRaspiCamera; stdenv.mkDerivation (finalAttrs: { pname = "gst-plugins-good"; - version = "1.28.6"; + version = "1.28.7"; outputs = [ "out" @@ -90,7 +90,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "https://gstreamer.freedesktop.org/src/gst-plugins-good/gst-plugins-good-${finalAttrs.version}.tar.xz"; - hash = "sha256-sMYgpLGLbukxtMQ7vxdg0whmbcN/cwp+fxrTJ+Wc4t8="; + hash = "sha256-hyVpacgs87yFdDAfPnBEqQ3grFAKWifYujjE3eiU3Ys="; }; patches = [ diff --git a/pkgs/development/libraries/gstreamer/gstreamermm/default.nix b/pkgs/development/libraries/gstreamer/gstreamermm/default.nix index 90da8d0df052..b8b75145f333 100644 --- a/pkgs/development/libraries/gstreamer/gstreamermm/default.nix +++ b/pkgs/development/libraries/gstreamer/gstreamermm/default.nix @@ -5,7 +5,7 @@ fetchpatch, pkg-config, file, - glibmm, + glibmm_2_4, gst_all_1, gnome, apple-sdk_gstreamer, @@ -43,7 +43,7 @@ stdenv.mkDerivation rec { ]; propagatedBuildInputs = [ - glibmm + glibmm_2_4 gst_all_1.gst-plugins-base ]; diff --git a/pkgs/development/libraries/gstreamer/libav/default.nix b/pkgs/development/libraries/gstreamer/libav/default.nix index 4d0d96121fb9..fae41c00adf0 100644 --- a/pkgs/development/libraries/gstreamer/libav/default.nix +++ b/pkgs/development/libraries/gstreamer/libav/default.nix @@ -19,11 +19,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "gst-libav"; - version = "1.28.6"; + version = "1.28.7"; src = fetchurl { url = "https://gstreamer.freedesktop.org/src/gst-libav/gst-libav-${finalAttrs.version}.tar.xz"; - hash = "sha256-cebq+0//KmbRuwuo0HgiTf5+M5cwfYwLuj3CNgbgj1E="; + hash = "sha256-WNpR3Tns8c9vqt40zGQSABvi4uFFvKiuD0Uzb2CjarI="; }; separateDebugInfo = true; diff --git a/pkgs/development/libraries/gstreamer/rtsp-server/default.nix b/pkgs/development/libraries/gstreamer/rtsp-server/default.nix index bb02d891686e..0d283e516fb2 100644 --- a/pkgs/development/libraries/gstreamer/rtsp-server/default.nix +++ b/pkgs/development/libraries/gstreamer/rtsp-server/default.nix @@ -21,7 +21,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "gst-rtsp-server"; - version = "1.28.6"; + version = "1.28.7"; outputs = [ "out" @@ -30,7 +30,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "https://gstreamer.freedesktop.org/src/gst-rtsp-server/gst-rtsp-server-${finalAttrs.version}.tar.xz"; - hash = "sha256-DLclsTUfdeiIA8Vd3eofJ74JUj3c1/KasYJw4YKipGM="; + hash = "sha256-3kOlmgyJoU6xwUro6B5bRcTp17H5MLDrqtNg+bXgtcQ="; }; separateDebugInfo = true; diff --git a/pkgs/development/libraries/gstreamer/ugly/default.nix b/pkgs/development/libraries/gstreamer/ugly/default.nix index bb5a84bb7873..b362bf92c47f 100644 --- a/pkgs/development/libraries/gstreamer/ugly/default.nix +++ b/pkgs/development/libraries/gstreamer/ugly/default.nix @@ -29,7 +29,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "gst-plugins-ugly"; - version = "1.28.6"; + version = "1.28.7"; outputs = [ "out" @@ -38,7 +38,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "https://gstreamer.freedesktop.org/src/gst-plugins-ugly/gst-plugins-ugly-${finalAttrs.version}.tar.xz"; - hash = "sha256-7iedoTp0D9fwYNYxpnMiP6O8yMM9NQyNAmS9Myok7Ng="; + hash = "sha256-K2gRcN3CK2soPK/u1I9CfDChcFaXSmqe0TfDVOD3cww="; }; separateDebugInfo = true; diff --git a/pkgs/development/libraries/libidn2/default.nix b/pkgs/development/libraries/libidn2/default.nix index 8b34a2842082..ae1893635c7d 100644 --- a/pkgs/development/libraries/libidn2/default.nix +++ b/pkgs/development/libraries/libidn2/default.nix @@ -24,7 +24,7 @@ stdenv.mkDerivation (finalAttrs: { }; strictDeps = true; - # Beware: non-bootstrap libidn2 is overridden by ./hack.nix + # Beware: non-bootstrap libidn2 is overridden by ./no-bootstrap-reference.nix outputs = [ "bin" "dev" diff --git a/pkgs/development/libraries/libidn2/no-bootstrap-reference.nix b/pkgs/development/libraries/libidn2/no-bootstrap-reference.nix index 773dfb6efe0f..8bde788e1373 100644 --- a/pkgs/development/libraries/libidn2/no-bootstrap-reference.nix +++ b/pkgs/development/libraries/libidn2/no-bootstrap-reference.nix @@ -18,6 +18,9 @@ runCommandLocal "${libidn2.pname}-${libidn2.version}" inherit (libidn2) out info devdoc; # no need to touch these store paths }; inherit (libidn2) meta pname version; + + strictDeps = true; + __structuredAttrs = true; } '' cp -r '${libidn2.bin}' "$bin" @@ -36,9 +39,9 @@ runCommandLocal "${libidn2.pname}-${libidn2.version}" cp -r '${libidn2.dev}' "$dev" chmod +w "$dev"/nix-support/propagated-build-inputs substituteInPlace "$dev"/nix-support/propagated-build-inputs \ - --replace '${libidn2.bin}' "$bin" + --replace-fail '${libidn2.bin}' "$bin" substituteInPlace "$dev"/lib/pkgconfig/libidn2.pc \ - --replace '${libidn2.dev}' "$dev" + --replace-fail '${libidn2.dev}' "$dev" ln -s '${libidn2.out}' "$out" # it's hard to be without any $out '' diff --git a/pkgs/development/libraries/libmicrohttpd/1.0.nix b/pkgs/development/libraries/libmicrohttpd/1.0.nix index 9248819673c6..cf9879dccee9 100644 --- a/pkgs/development/libraries/libmicrohttpd/1.0.nix +++ b/pkgs/development/libraries/libmicrohttpd/1.0.nix @@ -1,10 +1,10 @@ { callPackage, fetchurl }: callPackage ./generic.nix rec { - version = "1.0.6"; + version = "1.0.10"; src = fetchurl { url = "mirror://gnu/libmicrohttpd/libmicrohttpd-${version}.tar.gz"; - hash = "sha256-u1z8rfxS29XrUS1uKZXgNhNRwz6XqHq6Qm06Snumz3A="; + hash = "sha256-BL/o73XbfWKaM952dZl2XOytxWJ0o5gi1dCBAw1XdoU="; }; } diff --git a/pkgs/development/libraries/libmicrohttpd/generic.nix b/pkgs/development/libraries/libmicrohttpd/generic.nix index fd1fa25ee207..d248810f6701 100644 --- a/pkgs/development/libraries/libmicrohttpd/generic.nix +++ b/pkgs/development/libraries/libmicrohttpd/generic.nix @@ -1,7 +1,6 @@ { lib, stdenv, - libgcrypt, curl, gnutls, pkg-config, @@ -24,7 +23,6 @@ stdenv.mkDerivation (finalAttrs: { ]; nativeBuildInputs = [ pkg-config ]; buildInputs = [ - libgcrypt curl gnutls libiconv diff --git a/pkgs/development/libraries/libxmlxx/default.nix b/pkgs/development/libraries/libxmlxx/default.nix index 0ef02c177e12..1985f19245f6 100644 --- a/pkgs/development/libraries/libxmlxx/default.nix +++ b/pkgs/development/libraries/libxmlxx/default.nix @@ -4,7 +4,7 @@ fetchurl, pkg-config, libxml2, - glibmm, + glibmm_2_4, perl, gnome, }: @@ -35,7 +35,7 @@ stdenv.mkDerivation rec { propagatedBuildInputs = [ libxml2 - glibmm + glibmm_2_4 ]; passthru = { diff --git a/pkgs/development/libraries/libxmlxx/v3.nix b/pkgs/development/libraries/libxmlxx/v3.nix index aac2d74fc326..1fef754a27ce 100644 --- a/pkgs/development/libraries/libxmlxx/v3.nix +++ b/pkgs/development/libraries/libxmlxx/v3.nix @@ -4,7 +4,7 @@ fetchurl, pkg-config, libxml2, - glibmm, + glibmm_2_4, perl, gnome, meson, @@ -61,7 +61,7 @@ stdenv.mkDerivation rec { dblatex ]; - buildInputs = [ glibmm ]; + buildInputs = [ glibmm_2_4 ]; propagatedBuildInputs = [ libxml2 ]; diff --git a/pkgs/development/libraries/nss/generic.nix b/pkgs/development/libraries/nss/generic.nix index c72fb989532f..ac0f11d02d85 100644 --- a/pkgs/development/libraries/nss/generic.nix +++ b/pkgs/development/libraries/nss/generic.nix @@ -76,6 +76,9 @@ stdenv.mkDerivation rec { substituteInPlace coreconf/config.gypi --replace "/usr/bin/grep" "${buildPackages.coreutils}/bin/env grep" '' + + lib.optionalString (lib.versionAtLeast version "3.129") '' + substituteInPlace build.sh --replace "\$obj_dir/lib/pkgconfig/nspr.pc" "${nspr.dev}/lib/pkgconfig/nspr.pc" + '' + lib.optionalString stdenv.hostPlatform.isDarwin '' substituteInPlace coreconf/Darwin.mk --replace '@executable_path/$(notdir $@)' "$out/lib/\$(notdir \$@)" substituteInPlace coreconf/config.gypi --replace "'DYLIB_INSTALL_NAME_BASE': '@executable_path'" "'DYLIB_INSTALL_NAME_BASE': '$out/lib'" diff --git a/pkgs/development/libraries/nss/latest.nix b/pkgs/development/libraries/nss/latest.nix index 6c003b433214..020d9330c51e 100644 --- a/pkgs/development/libraries/nss/latest.nix +++ b/pkgs/development/libraries/nss/latest.nix @@ -5,8 +5,8 @@ # Example: nix-shell ./maintainers/scripts/update.nix --argstr package cacert import ./generic.nix { - version = "3.128"; - hash = "sha256-C9SGEyoxR16F6j7zOUsudS0aH/qIHc7DgV5FbBbz90Q="; + version = "3.129"; + hash = "sha256-cy7+nCVtogr1onk8/8OQcQZUm2AH2azNsUmVFg4ym7k="; filename = "latest.nix"; versionRegex = "NSS_(\\d+)_(\\d+)(?:_(\\d+))?_RTM"; } diff --git a/pkgs/development/libraries/poppler/default.nix b/pkgs/development/libraries/poppler/default.nix index 580d1fbfb73e..7313f9c8eda0 100644 --- a/pkgs/development/libraries/poppler/default.nix +++ b/pkgs/development/libraries/poppler/default.nix @@ -3,7 +3,6 @@ stdenv, fetchurl, fetchFromGitLab, - fetchpatch, cairo, clang-tools, cmake, @@ -12,12 +11,14 @@ fontconfig, freetype, glib, + harfbuzz, lcms, libiconv, libintl, libjpeg, libtiff, ninja, + noto-fonts-cjk-sans, openjpeg, pkg-config, python3, @@ -58,13 +59,13 @@ let domain = "gitlab.freedesktop.org"; owner = "poppler"; repo = "test"; - rev = "f0068e9c530017ad811d1f28b95f9b7f59264e37"; - hash = "sha256-Xf8duSh0r1o09b5BKB7mBvzrMfXYlzTuTOuK2ZCeItc="; + rev = "48b6219b84fc0a708040cb279d51095cc4e1c603"; + hash = "sha256-2eH4dZs2J0CeTWrXOYEHb0Xnpfa7tX8mi7AX2E9D41U="; }; in stdenv.mkDerivation (finalAttrs: { pname = "poppler-${suffix}"; - version = "26.06.0"; + version = "26.09.0"; outputs = [ "out" @@ -73,19 +74,9 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "https://poppler.freedesktop.org/poppler-${finalAttrs.version}.tar.xz"; - hash = "sha256-TLTlo9yMte7HUciiPIuhn2H5be3AzQfSruawyOLPa6Q="; + hash = "sha256-gFnq22gFNAdo8TjEZbV/gWTJK0oHc8N+8DHqbA2Yey4="; }; - patches = [ - # Backports Darwin crash fix from upstream - # https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1743 - (fetchpatch { - name = "darwin-mutex-lock-crash.patch"; - url = "https://gitlab.freedesktop.org/poppler/poppler/-/commit/08f4bca6a669f9fce75dbab743db559a86591738.patch"; - hash = "sha256-+eWqVK/v3Ys9k2+z/dCoS2o82m039UER1StMUW4PIgM="; - }) - ]; - nativeBuildInputs = [ cmake ninja @@ -105,6 +96,7 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ boost + harfbuzz libiconv libintl ] @@ -137,6 +129,11 @@ stdenv.mkDerivation (finalAttrs: { gpgme ]; + # Test `fontsubsetting-basic-test` needs a font that supports cjk. + nativeCheckInputs = [ + noto-fonts-cjk-sans + ]; + cmakeFlags = [ (mkFlag true "UNSTABLE_API_ABI_HEADERS") # previously "XPDF_HEADERS" (mkFlag (!minimal) "GLIB") diff --git a/pkgs/development/libraries/protobuf/36.nix b/pkgs/development/libraries/protobuf/36.nix index 0be0c9a8404e..0648e9656537 100644 --- a/pkgs/development/libraries/protobuf/36.nix +++ b/pkgs/development/libraries/protobuf/36.nix @@ -2,8 +2,8 @@ callPackage ./generic.nix ( { - version = "36.1"; - hash = "sha256-SB17YwMdkCp4jPcX5Csf13IUGVNLaqwH5YJXugAeqMY="; + version = "36.2"; + hash = "sha256-sY9Pmy6KMJ5k/GdQSAF7vsviLJYPaArMKJ3deb++0wM="; } // args ) diff --git a/pkgs/development/libraries/protobuf/generic.nix b/pkgs/development/libraries/protobuf/generic.nix index 45db4049d10a..a7f0fed672b0 100644 --- a/pkgs/development/libraries/protobuf/generic.nix +++ b/pkgs/development/libraries/protobuf/generic.nix @@ -14,6 +14,7 @@ version, hash, versionCheckHook, + symlinkJoin, # downstream dependencies python3, @@ -37,6 +38,28 @@ stdenv.mkDerivation (finalAttrs: { inherit hash; }; + outputs = [ + "out" + "lib" + "dev" + "proto" + ]; + + outputChecks = { + out.disallowedReferences = [ + "dev" + ]; + lib.disallowedReferences = [ + "out" + "dev" + ]; + proto.disallowedReferences = [ + "out" + "lib" + "dev" + ]; + }; + patches = lib.optionals (lib.versionOlder version "22") [ # fix protobuf-targets.cmake installation paths, and allow for CMAKE_INSTALL_LIBDIR to be absolute @@ -173,6 +196,23 @@ stdenv.mkDerivation (finalAttrs: { GTEST_DEATH_TEST_STYLE = "threadsafe"; }; + # protoc expects to find `.proto` files relative to itself, so we put those to a separate output and add symlinks. + postFixup = '' + pushd "$dev" > /dev/null + + find include -name '*.proto' -print0 | while IFS= read -r -d ''' FILE; do + mkdir -p "$proto/$(dirname "$FILE")" + mkdir -p "$out/$(dirname "$FILE")" + + mv "$FILE" "$proto/$FILE" + + ln -s "$proto/$FILE" "$out/$FILE" + ln -s "$proto/$FILE" "$dev/$FILE" + done + + popd > /dev/null + ''; + passthru = { tests = { pythonProtobuf = python3.pkgs.protobuf; @@ -180,9 +220,18 @@ stdenv.mkDerivation (finalAttrs: { inherit (python3.pkgs) celery; version = testers.testVersion { package = protobuf; }; + + pkg-config = testers.hasPkgConfigModules { + package = protobuf; + }; }; inherit abseil-cpp; + + full = symlinkJoin { + inherit (finalAttrs.finalPackage) name; + paths = finalAttrs.finalPackage.all; + }; }; meta = { @@ -197,5 +246,15 @@ stdenv.mkDerivation (finalAttrs: { homepage = "https://protobuf.dev/"; maintainers = with lib.maintainers; [ GaetanLepage ]; mainProgram = "protoc"; + pkgConfigModules = [ + "protobuf" + "protobuf-lite" + ] + ++ lib.optionals (lib.versionAtLeast version "22") [ + "utf8_range" + ] + ++ lib.optionals (lib.versionAtLeast version "27") [ + "upb" + ]; }; }) diff --git a/pkgs/development/libraries/qt-6/modules/qtdeclarative/default.nix b/pkgs/development/libraries/qt-6/modules/qtdeclarative/default.nix index 786229c5651b..36089460fc4e 100644 --- a/pkgs/development/libraries/qt-6/modules/qtdeclarative/default.nix +++ b/pkgs/development/libraries/qt-6/modules/qtdeclarative/default.nix @@ -43,6 +43,12 @@ qtModule { hash = "sha256-ESy35OlmsvI4yFQ/rFT8oelOUBCwCmlcbQJvwcTrCig="; revert = true; }) + + # backport fix recommended by KDE + (fetchpatch { + url = "https://codereview.qt-project.org/changes/qt%2Fqtdeclarative~768697/revisions/4/patch?download&raw"; + hash = "sha256-HiHAWbLr2MaZpw+yaA+JIveYory5cWkL2ZNf3zveYX4="; + }) ]; cmakeFlags = [ diff --git a/pkgs/development/libraries/spandsp/common.nix b/pkgs/development/libraries/spandsp/common.nix index 1aacb0f1123f..8ceab5257191 100644 --- a/pkgs/development/libraries/spandsp/common.nix +++ b/pkgs/development/libraries/spandsp/common.nix @@ -40,6 +40,9 @@ stdenv.mkDerivation (finalAttrs: { # https://github.com/freeswitch/spandsp/pull/111 ./Fix-tests-pcap_parse-build-on-musl.patch + + # https://github.com/freeswitch/spandsp/pull/116 + ./fix-bit-operations-ub.patch ] ++ patches; @@ -173,6 +176,10 @@ stdenv.mkDerivation (finalAttrs: { # Seemingly runs forever, with tons of output "v22bis_tests" + ] + ++ lib.optionals stdenv.hostPlatform.isPower64 [ + # Output differs from x86-generated reference due to float precision + "lpc10_tests" ]; checkPhase = '' @@ -220,6 +227,6 @@ stdenv.mkDerivation (finalAttrs: { maintainers = with lib.maintainers; [ misuzu ]; teams = [ lib.teams.ngi ]; license = lib.licenses.gpl2; - downloadPage = "http://www.soft-switch.org/downloads/spandsp/"; + downloadPage = "https://github.com/freeswitch/spandsp"; }; }) diff --git a/pkgs/development/libraries/spandsp/default.nix b/pkgs/development/libraries/spandsp/default.nix index 0a06b112e4c2..df1b5639bc47 100644 --- a/pkgs/development/libraries/spandsp/default.nix +++ b/pkgs/development/libraries/spandsp/default.nix @@ -7,7 +7,7 @@ (callPackage ./common.nix { }) rec { version = "0.0.6"; src = fetchurl { - url = "https://www.soft-switch.org/downloads/spandsp/spandsp-${version}.tar.gz"; + url = "https://src.fedoraproject.org/lookaside/pkgs/spandsp/spandsp-${version}.tar.gz/897d839516a6d4edb20397d4757a7ca3/spandsp-${version}.tar.gz"; sha256 = "0rclrkyspzk575v8fslzjpgp4y2s4x7xk3r55ycvpi4agv33l1fc"; }; patches = [ diff --git a/pkgs/development/libraries/spandsp/fix-bit-operations-ub.patch b/pkgs/development/libraries/spandsp/fix-bit-operations-ub.patch new file mode 100644 index 000000000000..24562d6135d8 --- /dev/null +++ b/pkgs/development/libraries/spandsp/fix-bit-operations-ub.patch @@ -0,0 +1,53 @@ +From 6366823f4c6a1641543a0f3859afcafccf2e47af Mon Sep 17 00:00:00 2001 +From: Amaan Qureshi +Date: Wed, 11 Mar 2026 23:34:26 -0400 +Subject: [PATCH] tests: fix undefined behavior in `bit_operations_tests` + +The `most_significant_one32`/`least_significant_one32` test loop +started at `i = -1`, which produces a shift of `1U << -1`. This is +undefined behavior per the C standard, as the shift count must be in +`[0, bit_width)`. On x86 this happened to produce `0x80000000` due to +masking the shift count to 5 bits, but on ppc64be it produces `0`, +causing a spurious test failure. + +This commit starts the loop at `i = 0` instead. Testing the zero-input +case is not meaningful here since `most_significant_one32(0)` itself +invokes UB internally (`1 << top_bit(0)` where `top_bit` returns `-1`). +I've also fixed the printf format strings to use `1U` instead of `1` to +avoid signed overflow when `i = 31`. +--- + tests/bit_operations_tests.c | 6 +++--- + 1 file changed, 3 insertions(+), 3 deletions(-) + +diff --git a/tests/bit_operations_tests.c b/tests/bit_operations_tests.c +index 53cd997..53f7892 100644 +--- a/tests/bit_operations_tests.c ++++ b/tests/bit_operations_tests.c +@@ -257,22 +257,22 @@ int main(int argc, char *argv[]) + printf("Test failed: parity 8 - %x %x %x\n", i, ax, bx); + exit(2); + } + } + +- for (i = -1; i < 32; i++) ++ for (i = 0; i < 32; i++) + { + ax32 = most_significant_one32(1 << i); + if (ax32 != (1 << i)) + { +- printf("Test failed: most significant one 32 - %x %" PRIx32 " %x\n", i, ax32, (1 << i)); ++ printf("Test failed: most significant one 32 - %x %" PRIx32 " %x\n", i, ax32, (1U << i)); + exit(2); + } + ax32 = least_significant_one32(1 << i); + if (ax32 != (1 << i)) + { +- printf("Test failed: least significant one 32 - %x %" PRIx32 " %x\n", i, ax32, (1 << i)); ++ printf("Test failed: least significant one 32 - %x %" PRIx32 " %x\n", i, ax32, (1U << i)); + exit(2); + } + } + + for (i = 0x80000000; i < 0x800FFFFF; i++) +-- +2.53.0 diff --git a/pkgs/development/libraries/tk/generic.nix b/pkgs/development/libraries/tk/generic.nix index dae3651d64be..eab95e8e5f3a 100644 --- a/pkgs/development/libraries/tk/generic.nix +++ b/pkgs/development/libraries/tk/generic.nix @@ -100,6 +100,7 @@ tcl.mkTclDerivation { homepage = "https://www.tcl.tk/"; license = lib.licenses.tcltk; platforms = lib.platforms.all; + mainProgram = "wish"; maintainers = [ ]; }; } diff --git a/pkgs/development/libraries/tpm2-tss/default.nix b/pkgs/development/libraries/tpm2-tss/default.nix index e910c11533bd..874c339b626d 100644 --- a/pkgs/development/libraries/tpm2-tss/default.nix +++ b/pkgs/development/libraries/tpm2-tss/default.nix @@ -10,7 +10,6 @@ openssl, json_c, curl, - libgcrypt, cmocka, uthash, swtpm, @@ -58,7 +57,6 @@ stdenv.mkDerivation (finalAttrs: { openssl json_c curl - libgcrypt uthash libuuid libtpms diff --git a/pkgs/development/libraries/zlib/default.nix b/pkgs/development/libraries/zlib/default.nix index a400e4b60c63..6d985093d9d3 100644 --- a/pkgs/development/libraries/zlib/default.nix +++ b/pkgs/development/libraries/zlib/default.nix @@ -49,6 +49,8 @@ stdenv.mkDerivation (finalAttrs: { # https://github.com/madler/zlib/pull/1171 patches = [ ./export-variable.patch + # https://github.com/madler/zlib/pull/1296 + ./mingw-shared.patch ]; postPatch = '' @@ -69,15 +71,13 @@ stdenv.mkDerivation (finalAttrs: { setOutputFlags = false; outputDoc = "dev"; # single tiny man3 page - dontConfigure = (stdenv.hostPlatform.isMinGW || stdenv.hostPlatform.isCygwin); - preConfigure = lib.optionalString (stdenv.hostPlatform != stdenv.buildPlatform) '' export CHOST=${stdenv.hostPlatform.config} ''; configureFlags = [ "--includedir=${placeholder "dev"}/include" - "--sharedlibdir=${placeholder "out"}/lib" + "--sharedlibdir=${placeholder "out"}/${if stdenv.hostPlatform.isWindows then "bin" else "lib"}" "--libdir=${placeholder (if splitStaticOutput then "static" else "out")}/lib" # See comment near splitStaticOutput argument (lib.enableFeature shared "shared") @@ -101,27 +101,15 @@ stdenv.mkDerivation (finalAttrs: { for file in $out/lib/*.so* $out/lib/*.dylib* ; do ${stdenv.cc.bintools.targetPrefix}install_name_tool -id "$file" $file done - '' - # Non-typical naming confuses libtool which then refuses to use zlib's DLL - # in some cases, e.g. when compiling libpng. - + lib.optionalString (stdenv.hostPlatform.isMinGW && shared) '' - ln -s zlib1.dll $out/bin/libz.dll ''; - env = - lib.optionalAttrs (!stdenv.hostPlatform.isDarwin) { - # As zlib takes part in the stdenv building, we don't want references - # to the bootstrap-tools libgcc (as uses to happen on arm/mips) - NIX_CFLAGS_COMPILE = toString ( - [ "-static-libgcc" ] ++ lib.optional stdenv.hostPlatform.isCygwin "-DHAVE_UNISTD_H" - ); - } - // lib.optionalAttrs (stdenv.hostPlatform.linker == "lld") { - # lld 16 enables --no-undefined-version by default - # This makes configure think it can't build dynamic libraries - # this may be removed when a version is packaged with https://github.com/madler/zlib/issues/960 fixed - NIX_LDFLAGS = "--undefined-version"; - }; + env = lib.optionalAttrs (!stdenv.hostPlatform.isDarwin) { + # As zlib takes part in the stdenv building, we don't want references + # to the bootstrap-tools libgcc (as uses to happen on arm/mips) + NIX_CFLAGS_COMPILE = toString ( + [ "-static-libgcc" ] ++ lib.optional stdenv.hostPlatform.isCygwin "-DHAVE_UNISTD_H" + ); + }; # We don't strip on static cross-compilation because of reports that native # stripping corrupted the target library; see commit 12e960f5 for the report. @@ -141,18 +129,9 @@ stdenv.mkDerivation (finalAttrs: { "PREFIX=${stdenv.cc.targetPrefix}" "pkgconfigdir=${placeholder "dev"}/share/pkgconfig" ] - ++ lib.optionals (stdenv.hostPlatform.isMinGW || stdenv.hostPlatform.isCygwin) [ - "-f" - "win32/Makefile.gcc" - ] ++ lib.optionals stdenv.hostPlatform.isCygwin [ "SHAREDLIB=cygz.dll" "IMPLIB=libz.dll.a" - ] - ++ lib.optionals shared [ - # Note that as of writing (zlib 1.2.11), this flag only has an effect - # for Windows as it is specific to `win32/Makefile.gcc`. - "SHARED_MODE=1" ]; passthru.tests = { diff --git a/pkgs/development/libraries/zlib/mingw-shared.patch b/pkgs/development/libraries/zlib/mingw-shared.patch new file mode 100644 index 000000000000..9f08476a3a26 --- /dev/null +++ b/pkgs/development/libraries/zlib/mingw-shared.patch @@ -0,0 +1,13 @@ +diff --git a/configure b/configure +index c55098a..07f7c08 100755 +--- a/configure ++++ b/configure +@@ -243,6 +243,8 @@ if test "$gcc" -eq 1 && ($cc -c $test.c) >> configure.log 2>&1; then + echo "If this doesn't work for you, try win32/Makefile.gcc." | tee -a configure.log + LDSHARED=${LDSHARED-"$cc -shared"} + LDSHAREDLIBC="" ++ shared_ext='.dll' ++ SHAREDLIB='libz.dll' + EXE='.exe' ;; + QNX*) # This is for QNX6. I suppose that the QNX rule below is for QNX2,QNX4 + # (alain.bonnefoy@icbt.com) diff --git a/pkgs/development/python-modules/appnope/default.nix b/pkgs/development/python-modules/appnope/default.nix index 12e720eb3618..f647b3834520 100644 --- a/pkgs/development/python-modules/appnope/default.nix +++ b/pkgs/development/python-modules/appnope/default.nix @@ -2,23 +2,23 @@ lib, buildPythonPackage, fetchFromGitHub, - setuptools, + hatchling, pytestCheckHook, }: buildPythonPackage (finalAttrs: { pname = "appnope"; - version = "0.1.4"; + version = "1.0.0"; pyproject = true; src = fetchFromGitHub { owner = "minrk"; repo = "appnope"; tag = finalAttrs.version; - hash = "sha256-We7sZKVbQFIMdZpS+VMdi0RH1O/qtFNrfJNg/98tO5A="; + hash = "sha256-saJ68R4zdquTWWT/QuWZk6oQhcx3R+AmVBYt/NmFtyM="; }; - build-system = [ setuptools ]; + build-system = [ hatchling ]; checkInputs = [ pytestCheckHook ]; diff --git a/pkgs/development/python-modules/dask-glm/default.nix b/pkgs/development/python-modules/dask-glm/default.nix index 3801ae817917..9c4045be8fc4 100644 --- a/pkgs/development/python-modules/dask-glm/default.nix +++ b/pkgs/development/python-modules/dask-glm/default.nix @@ -1,50 +1,60 @@ { lib, - stdenv, buildPythonPackage, fetchFromGitHub, # build-system + setuptools, setuptools-scm, # dependencies cloudpickle, + dask, distributed, multipledispatch, + numba, + numpy, scikit-learn, scipy, sparse, - dask, # tests pytest-xdist, pytestCheckHook, }: -buildPythonPackage rec { +buildPythonPackage (finalAttrs: { pname = "dask-glm"; - version = "0.3.2"; + version = "0.4.0"; pyproject = true; + __structuredAttrs = true; src = fetchFromGitHub { owner = "dask"; repo = "dask-glm"; - tag = version; - hash = "sha256-q98QMmw1toashimS16of54cgZgIPqkua3xGD1FZ1nTc="; + tag = finalAttrs.version; + hash = "sha256-u3KASmBamc7qU/GxGT0QBqWJ1HDk81xI0MOoRng8BzA="; }; - # ValueError: The truth value of an empty array is ambiguous. Use `array.size > 0` to check that an array is not empty. + # The iprint parameter of `scipy.optimize.fmin_l_bfgs_b` was removed in 1.18.0 + # https://github.com/scipy/scipy/blob/b881cb179463e85a74f3368f6242986d713adbdc/doc/source/release/1.18.0-notes.rst?plain=1#L291-L292 postPatch = '' - substituteInPlace dask_glm/utils.py \ - --replace-fail "if arr:" "if (arr is not None) and (arr.size > 0):" + substituteInPlace dask_glm/algorithms.py \ + --replace-fail "iprint=(verbose > 0) - 1," "" ''; - build-system = [ setuptools-scm ]; + build-system = [ + setuptools + setuptools-scm + ]; dependencies = [ cloudpickle + dask distributed multipledispatch + numba + numpy scikit-learn scipy sparse @@ -58,23 +68,11 @@ buildPythonPackage rec { pythonImportsCheck = [ "dask_glm" ]; - disabledTests = [ - # ValueError: can be computed for one-element arrays only. - "test_dot_with_sparse" - - # ValueError: `shape` was not provided. - "test_sparse" - ]; - - # On darwin, tests saturate the entire system, even when constrained to run single-threaded - # Removing pytest-xdist AND setting --cores to one does not prevent the load from exploding - doCheck = !stdenv.hostPlatform.isDarwin; - meta = { description = "Generalized Linear Models with Dask"; homepage = "https://github.com/dask/dask-glm/"; - changelog = "https://github.com/dask/dask-glm/releases/tag/${version}"; + changelog = "https://github.com/dask/dask-glm/releases/tag/${finalAttrs.src.tag}"; license = lib.licenses.bsd3; maintainers = with lib.maintainers; [ GaetanLepage ]; }; -} +}) diff --git a/pkgs/development/python-modules/dask-ml/default.nix b/pkgs/development/python-modules/dask-ml/default.nix index 4153970a052e..842cbad62466 100644 --- a/pkgs/development/python-modules/dask-ml/default.nix +++ b/pkgs/development/python-modules/dask-ml/default.nix @@ -24,22 +24,24 @@ pytestCheckHook, }: -buildPythonPackage rec { +buildPythonPackage (finalAttrs: { pname = "dask-ml"; version = "2025.1.0"; pyproject = true; + __structuredAttrs = true; src = fetchFromGitHub { owner = "dask"; repo = "dask-ml"; - tag = "v${version}"; + tag = "v${finalAttrs.version}"; hash = "sha256-DHxx0LFuJmGWYuG/WGHj+a5XHAEekBmlHUUb90rl2IY="; }; postPatch = '' substituteInPlace pyproject.toml \ - --replace-fail 'addopts = "-rsx -v --durations=10 --color=yes"' \ - 'addopts = ["-rsx", "-v", "--durations=10", "--color=yes"]' + --replace-fail \ + 'addopts = "-rsx -v --durations=10 --color=yes"' \ + 'addopts = ["-rsx", "-v", "--durations=10", "--color=yes"]' ''; build-system = [ @@ -73,6 +75,18 @@ buildPythonPackage rec { pytestCheckHook ]; + pytestFlags = [ + # Skipping check check_array_api_input for KMeans because it raised SkipTest: + # SCIPY_ARRAY_API is not set: not checking array_api input + "-Wignore::sklearn.exceptions.SkipTestWarning" + + # pandas.errors.Pandas4Warning: For backward compatibility, 'str' dtypes are included by select_dtypes when 'object' dtype is specified. + # This behavior is deprecated and will be removed in a future version. + # Explicitly pass 'str' to `include` to select them, or to `exclude` to remove them and silence this warning. + # See https://pandas.pydata.org/docs/user_guide/migration-3-strings.html#string-migration-select-dtypes for details on how to write code that works with pandas 2 and 3. + "-Wignore::pandas.errors.Pandas4Warning" + ]; + disabledTestPaths = [ # RuntimeError: Attempting to use an asynchronous Client in a synchronous context of `dask.compute` # https://github.com/dask/dask-ml/issues/1016 @@ -131,4 +145,4 @@ buildPythonPackage rec { license = lib.licenses.bsd3; maintainers = with lib.maintainers; [ GaetanLepage ]; }; -} +}) diff --git a/pkgs/development/python-modules/dask/default.nix b/pkgs/development/python-modules/dask/default.nix index 3c83bd0e6eda..691504cc6a98 100644 --- a/pkgs/development/python-modules/dask/default.nix +++ b/pkgs/development/python-modules/dask/default.nix @@ -44,7 +44,7 @@ buildPythonPackage (finalAttrs: { pname = "dask"; - version = "2026.7.1"; + version = "2026.8.0"; pyproject = true; __structuredAttrs = true; @@ -52,7 +52,7 @@ buildPythonPackage (finalAttrs: { owner = "dask"; repo = "dask"; tag = finalAttrs.version; - hash = "sha256-Hh3QMSLMn7xCbwoiu4gjjF590YXZfiG5rp20kWX+Kms="; + hash = "sha256-DFPd46cBirwztmZJvRKS8u5qvYMEIWfy90QR2AeBu3c="; }; postPatch = lib.optionalString stdenv.hostPlatform.isLinux '' diff --git a/pkgs/development/python-modules/defcon/default.nix b/pkgs/development/python-modules/defcon/default.nix index 422f479ed4b4..94776ee4149d 100644 --- a/pkgs/development/python-modules/defcon/default.nix +++ b/pkgs/development/python-modules/defcon/default.nix @@ -2,25 +2,31 @@ lib, buildPythonPackage, fetchPypi, + setuptools, setuptools-scm, fonttools, fontpens, pytestCheckHook, }: -buildPythonPackage rec { +buildPythonPackage (finalAttrs: { pname = "defcon"; version = "0.12.2"; - format = "setuptools"; + pyproject = true; + + __structuredAttrs = true; src = fetchPypi { - inherit pname version; + inherit (finalAttrs) pname version; hash = "sha256-Jd/n/QFSzPKSyxkNGSikfViImcILBGhUKT4DnhyT5eA="; }; - nativeBuildInputs = [ setuptools-scm ]; + build-system = [ + setuptools + setuptools-scm + ]; - propagatedBuildInputs = [ + dependencies = [ fonttools ] ++ fonttools.optional-dependencies.ufo @@ -38,8 +44,8 @@ buildPythonPackage rec { meta = { description = "Set of UFO based objects for use in font editing applications"; homepage = "https://github.com/robotools/defcon"; - changelog = "https://github.com/robotools/defcon/releases/tag/${version}"; + changelog = "https://github.com/robotools/defcon/releases/tag/${finalAttrs.version}"; license = lib.licenses.mit; maintainers = with lib.maintainers; [ sternenseemann ]; }; -} +}) diff --git a/pkgs/development/python-modules/dirty-equals/default.nix b/pkgs/development/python-modules/dirty-equals/default.nix index 41281df75b36..c1d5812ac9c2 100644 --- a/pkgs/development/python-modules/dirty-equals/default.nix +++ b/pkgs/development/python-modules/dirty-equals/default.nix @@ -10,7 +10,7 @@ }: let - dirty-equals = buildPythonPackage rec { + dirty-equals = buildPythonPackage (finalAttrs: { pname = "dirty-equals"; version = "0.11.0"; pyproject = true; @@ -18,17 +18,23 @@ let src = fetchFromGitHub { owner = "samuelcolvin"; repo = "dirty-equals"; - tag = "v${version}"; + tag = "v${finalAttrs.version}"; hash = "sha256-JFKWrbMdxhvSBbjQ+S9HPW87CK+5ZZiXHg8Wltlv2YY="; }; + postPatch = '' + # Fix pytest.PytestRemovedIn10Warning: Passing a non-Collection iterable to parametrize is deprecated. + substituteInPlace tests/test_docs.py \ + --replace-fail "examples," "list(examples)," + ''; + build-system = [ hatchling ]; dependencies = [ pytz ]; doCheck = false; - passthru.tests.pytest = dirty-equals.overrideAttrs { doCheck = true; }; + passthru.tests.pytest = dirty-equals.overridePythonAttrs { doCheck = true; }; nativeCheckInputs = [ pydantic @@ -38,13 +44,15 @@ let pythonImportsCheck = [ "dirty_equals" ]; + __structuredAttrs = true; + meta = { description = "Module for doing dirty (but extremely useful) things with equals"; homepage = "https://github.com/samuelcolvin/dirty-equals"; - changelog = "https://github.com/samuelcolvin/dirty-equals/releases/tag/${src.tag}"; + changelog = "https://github.com/samuelcolvin/dirty-equals/releases/tag/${finalAttrs.src.tag}"; license = lib.licenses.mit; maintainers = with lib.maintainers; [ fab ]; }; - }; + }); in dirty-equals diff --git a/pkgs/development/python-modules/distributed/default.nix b/pkgs/development/python-modules/distributed/default.nix index 9f2fb7ebe6c3..a01910fa3853 100644 --- a/pkgs/development/python-modules/distributed/default.nix +++ b/pkgs/development/python-modules/distributed/default.nix @@ -26,7 +26,7 @@ buildPythonPackage (finalAttrs: { pname = "distributed"; - version = "2026.7.1"; + version = "2026.8.0"; pyproject = true; __structuredAttrs = true; @@ -34,7 +34,7 @@ buildPythonPackage (finalAttrs: { owner = "dask"; repo = "distributed"; tag = finalAttrs.version; - hash = "sha256-9QZb7PpPhdJEc4Kgoc3PE6TU7LHmiw58jkgfaoSNSg4="; + hash = "sha256-Z7T/ik8GDnFESDl2OuvSGFo+SBcEY7gpVx31CoTTvao="; }; build-system = [ diff --git a/pkgs/development/python-modules/django/5.nix b/pkgs/development/python-modules/django/5.nix index d9ec648838c7..202233c29318 100644 --- a/pkgs/development/python-modules/django/5.nix +++ b/pkgs/development/python-modules/django/5.nix @@ -59,6 +59,7 @@ buildPythonPackage rec { ./5.2/pythonpath.patch # disable test that expects timezone issues ./5.2/disable-failing-test.patch + ./6.x/skip-flaky-tests.patch ] ++ lib.optionals withGdal [ (replaceVars ./5.2/gdal.patch { diff --git a/pkgs/development/python-modules/filterpy/default.nix b/pkgs/development/python-modules/filterpy/default.nix index 110d3b136b0d..c5417046b1f6 100644 --- a/pkgs/development/python-modules/filterpy/default.nix +++ b/pkgs/development/python-modules/filterpy/default.nix @@ -24,7 +24,12 @@ buildPythonPackage { hash = "sha256-KuuVu0tqrmQuNKYmDmdy+TU6BnnhDxh4G8n9BGzjGag="; }; - patches = [ ./numpy-2.4-compat.patch ]; + patches = [ + ./numpy-2.4-compat.patch + + # https://github.com/rlabbe/filterpy/pull/331 + ./scipy-1.12-deprecation.patch + ]; build-system = [ setuptools ]; diff --git a/pkgs/development/python-modules/filterpy/scipy-1.12-deprecation.patch b/pkgs/development/python-modules/filterpy/scipy-1.12-deprecation.patch new file mode 100644 index 000000000000..ef26dbefafa2 --- /dev/null +++ b/pkgs/development/python-modules/filterpy/scipy-1.12-deprecation.patch @@ -0,0 +1,14 @@ +diff --git a/filterpy/discrete_bayes/discrete_bayes.py b/filterpy/discrete_bayes/discrete_bayes.py +index 084ba8c..c465835 100644 +--- a/filterpy/discrete_bayes/discrete_bayes.py ++++ b/filterpy/discrete_bayes/discrete_bayes.py +@@ -19,8 +19,7 @@ from __future__ import (absolute_import, division, print_function, + unicode_literals) + + import numpy as np +-from scipy.ndimage.filters import convolve +-from scipy.ndimage.interpolation import shift ++from scipy.ndimage import convolve, shift + + + def normalize(pdf): diff --git a/pkgs/development/python-modules/grpcio-channelz/default.nix b/pkgs/development/python-modules/grpcio-channelz/default.nix index 6741c9d8bc80..a37b04eb3395 100644 --- a/pkgs/development/python-modules/grpcio-channelz/default.nix +++ b/pkgs/development/python-modules/grpcio-channelz/default.nix @@ -12,13 +12,13 @@ # nixpkgs-update: no auto update buildPythonPackage rec { pname = "grpcio-channelz"; - version = "1.83.0"; + version = "1.83.1"; pyproject = true; src = fetchPypi { pname = "grpcio_channelz"; inherit version; - hash = "sha256-gaqgIn5UGWGvsnhNNcmWO9sPdmtGQ9JAODmBeKYc9lw="; + hash = "sha256-XrsLFMK8yBFJ4oSNHSZCQEJnYqBQsinTNzRruzfT4x8="; }; build-system = [ setuptools ]; diff --git a/pkgs/development/python-modules/grpcio-health-checking/default.nix b/pkgs/development/python-modules/grpcio-health-checking/default.nix index ef962e09a7a2..ff362fdff915 100644 --- a/pkgs/development/python-modules/grpcio-health-checking/default.nix +++ b/pkgs/development/python-modules/grpcio-health-checking/default.nix @@ -11,13 +11,13 @@ # nixpkgs-update: no auto update buildPythonPackage rec { pname = "grpcio-health-checking"; - version = "1.83.0"; + version = "1.83.1"; format = "setuptools"; src = fetchPypi { pname = "grpcio_health_checking"; inherit version; - hash = "sha256-rWvE1aEQOtcE0lzNgt7zAN+ieZaxhcqz5Mzu7yxoZ9Q="; + hash = "sha256-1gkk5vutOPNcNyd5vF62UaAORG1tJPHRxy8UKXodDlY="; }; propagatedBuildInputs = [ diff --git a/pkgs/development/python-modules/grpcio-reflection/default.nix b/pkgs/development/python-modules/grpcio-reflection/default.nix index d697034b9bb0..0b640f0e32d1 100644 --- a/pkgs/development/python-modules/grpcio-reflection/default.nix +++ b/pkgs/development/python-modules/grpcio-reflection/default.nix @@ -12,13 +12,13 @@ # nixpkgs-update: no auto update buildPythonPackage rec { pname = "grpcio-reflection"; - version = "1.83.0"; + version = "1.83.1"; pyproject = true; src = fetchPypi { pname = "grpcio_reflection"; inherit version; - hash = "sha256-aiowpGKsLDxtFJc0qP5lX6dhfBf6LNqZSQBvO/B/Wz4="; + hash = "sha256-wzlT8urhMTqx0sK2oc7G3a6+Z2PaGyYxmAeS2XkuYjM="; }; build-system = [ setuptools ]; diff --git a/pkgs/development/python-modules/grpcio-status/default.nix b/pkgs/development/python-modules/grpcio-status/default.nix index 57e252eae475..91cad68190e6 100644 --- a/pkgs/development/python-modules/grpcio-status/default.nix +++ b/pkgs/development/python-modules/grpcio-status/default.nix @@ -12,13 +12,13 @@ # nixpkgs-update: no auto update buildPythonPackage rec { pname = "grpcio-status"; - version = "1.83.0"; + version = "1.83.1"; format = "setuptools"; src = fetchPypi { pname = "grpcio_status"; inherit version; - hash = "sha256-g3IZxt6a/cy29vcrNLxx4VGiAR7wQEDj+qynRqV+VK4="; + hash = "sha256-wIyNVT1quW7/rh2SODneIpJvWjFqlC9IpIBA4EfFF68="; }; postPatch = '' diff --git a/pkgs/development/python-modules/grpcio-testing/default.nix b/pkgs/development/python-modules/grpcio-testing/default.nix index 9f0f81ecb5b8..55cbb7b6d3c0 100644 --- a/pkgs/development/python-modules/grpcio-testing/default.nix +++ b/pkgs/development/python-modules/grpcio-testing/default.nix @@ -12,13 +12,13 @@ # nixpkgs-update: no auto update buildPythonPackage rec { pname = "grpcio-testing"; - version = "1.83.0"; + version = "1.83.1"; pyproject = true; src = fetchPypi { pname = "grpcio_testing"; inherit version; - hash = "sha256-/6p6o+ckGsNXDBePfNbpRYEUK1Eh60esk5g+1gfwa90="; + hash = "sha256-xye7371SOlXGMECLeX/43w89GEFyHV8+eOoV4C/39Vs="; }; postPatch = '' diff --git a/pkgs/development/python-modules/grpcio-tools/default.nix b/pkgs/development/python-modules/grpcio-tools/default.nix index 0274dd2ead83..e391ab625f2d 100644 --- a/pkgs/development/python-modules/grpcio-tools/default.nix +++ b/pkgs/development/python-modules/grpcio-tools/default.nix @@ -13,13 +13,13 @@ # nixpkgs-update: no auto update buildPythonPackage rec { pname = "grpcio-tools"; - version = "1.83.0"; + version = "1.83.1"; pyproject = true; src = fetchPypi { pname = "grpcio_tools"; inherit version; - hash = "sha256-UVkHJl0U+pl10MdyP5Wp2gFGPXrGB1RqA/h0H4ahuwc="; + hash = "sha256-qBSO7OOW+KNJCXlYvADxSIIAMzHzt8KugHnBxjLRfW8="; }; postPatch = '' diff --git a/pkgs/development/python-modules/grpcio/default.nix b/pkgs/development/python-modules/grpcio/default.nix index 3f39101e34d8..0c4e6648a9c1 100644 --- a/pkgs/development/python-modules/grpcio/default.nix +++ b/pkgs/development/python-modules/grpcio/default.nix @@ -18,12 +18,12 @@ # nixpkgs-update: no auto update buildPythonPackage rec { pname = "grpcio"; - version = "1.83.0"; + version = "1.83.1"; pyproject = true; src = fetchPypi { inherit pname version; - hash = "sha256-dnRYckj7uyrG5O7Pg6ig89kako+UHeVxrP06LwB/vCQ="; + hash = "sha256-nO5vy/LrV8S0lFF4e/qHvo78HKAqCzJ91LVNRFAuNis="; }; postPatch = '' diff --git a/pkgs/development/python-modules/httpcore2/default.nix b/pkgs/development/python-modules/httpcore2/default.nix index f87ae1db2a26..badd6a951953 100644 --- a/pkgs/development/python-modules/httpcore2/default.nix +++ b/pkgs/development/python-modules/httpcore2/default.nix @@ -1,5 +1,6 @@ { lib, + stdenv, buildPythonPackage, fetchFromGitHub, @@ -78,6 +79,12 @@ buildPythonPackage (finalAttrs: { pytestFlags = [ "tests/httpcore2" ]; + # Skip tests does not pass: 10ms cancellation-timing test + disabledTests = lib.optionals stdenv.hostPlatform.isRiscV64 [ + "test_h2_timeout_during_request" + "test_h2_timeout_during_response" + ]; + passthru.tests = { inherit httpx2; }; diff --git a/pkgs/development/python-modules/inline-snapshot/default.nix b/pkgs/development/python-modules/inline-snapshot/default.nix index fd694d13f53d..4997f6756729 100644 --- a/pkgs/development/python-modules/inline-snapshot/default.nix +++ b/pkgs/development/python-modules/inline-snapshot/default.nix @@ -65,6 +65,8 @@ buildPythonPackage rec { disabledTestPaths = [ # Tests don't play nice with pytest-xdist "tests/test_typing.py" + # Sensitive to formatter versions + "tests/test_docs.py" ]; meta = { diff --git a/pkgs/development/python-modules/libusb1/default.nix b/pkgs/development/python-modules/libusb1/default.nix index b655e14fd77a..ee82c5614d8d 100644 --- a/pkgs/development/python-modules/libusb1/default.nix +++ b/pkgs/development/python-modules/libusb1/default.nix @@ -11,14 +11,14 @@ buildPythonPackage rec { pname = "libusb1"; - version = "3.3.1"; + version = "3.4.0"; pyproject = true; src = fetchFromGitHub { owner = "vpelletier"; repo = "python-libusb1"; tag = version; - hash = "sha256-nytxew6KogpEpSnRtmY0UNH+07x0k0XLZ/MRC9NSpDg="; + hash = "sha256-w+Q00GWNobqQlvqryZlJl7SZPEMYgMtbuKpUSLneqNw="; }; patches = [ diff --git a/pkgs/development/python-modules/locust/default.nix b/pkgs/development/python-modules/locust/default.nix index 1d8b5a5cf5a1..a55b41811bd2 100644 --- a/pkgs/development/python-modules/locust/default.nix +++ b/pkgs/development/python-modules/locust/default.nix @@ -4,6 +4,7 @@ python, callPackage, fetchFromGitHub, + substitute, hatchling, hatch-vcs, pytestCheckHook, @@ -24,6 +25,7 @@ retry, tomli, werkzeug, + yarn-berry, }: buildPythonPackage rec { @@ -35,7 +37,23 @@ buildPythonPackage rec { owner = "locustio"; repo = "locust"; tag = version; - hash = "sha256-Diz5fGcX8hXQSuNT20LUcjKJZEYNvN+6myrGi5F4Hss="; + hash = "sha256-IFKphE/RuGXsCmddXNppnHzayTSETaFLrOm26+6tyBI="; + + # Remove after upstream updates to Yarn 4.15 + # https://github.com/locustio/locust/blob/master/locust/webui/package.json#L89 + postFetch = '' + cd $out/locust/webui + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry.lockfileVersion + ]; + }) + } + ''; }; postPatch = '' @@ -47,7 +65,7 @@ buildPythonPackage rec { ''; webui = callPackage ./webui.nix { - inherit version; + inherit version yarn-berry; src = "${src}/locust/webui"; }; diff --git a/pkgs/development/python-modules/locust/webui.nix b/pkgs/development/python-modules/locust/webui.nix index 239e756fc745..cdb28354e674 100644 --- a/pkgs/development/python-modules/locust/webui.nix +++ b/pkgs/development/python-modules/locust/webui.nix @@ -1,28 +1,19 @@ { stdenv, - yarn-berry_4, + yarn-berry, nodejs, version, src, lib, }: -let - yarn-berry = yarn-berry_4; -in stdenv.mkDerivation (finalAttrs: { pname = "locust-ui"; inherit version src; - patches = [ - # Remove after upstream updates to Yarn 4.14 - # https://github.com/locustio/locust/blob/master/locust/webui/package.json#L89 - ./yarn-4.14-support.patch - ]; - missingHashes = ./missing-hashes.json; yarnOfflineCache = yarn-berry.fetchYarnBerryDeps { - inherit (finalAttrs) src missingHashes patches; - hash = "sha256-1pAoz/fkxrTCJZsSuAnm1Pfn5qjEbup8utEUoDvYJSE="; + inherit (finalAttrs) src missingHashes; + hash = "sha256-fjvgnXKenRxML1JkpxYIOnVuNZ7BpU9L/XgblcQV0vA="; }; nativeBuildInputs = [ diff --git a/pkgs/development/python-modules/locust/yarn-4.14-support.patch b/pkgs/development/python-modules/locust/yarn-fix.patch similarity index 89% rename from pkgs/development/python-modules/locust/yarn-4.14-support.patch rename to pkgs/development/python-modules/locust/yarn-fix.patch index c9aaabe0983b..69c087950139 100644 --- a/pkgs/development/python-modules/locust/yarn-4.14-support.patch +++ b/pkgs/development/python-modules/locust/yarn-fix.patch @@ -17,6 +17,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10c0 diff --git a/pkgs/development/python-modules/mypy/default.nix b/pkgs/development/python-modules/mypy/default.nix index 68587c7c345f..a50eb9c32761 100644 --- a/pkgs/development/python-modules/mypy/default.nix +++ b/pkgs/development/python-modules/mypy/default.nix @@ -6,6 +6,7 @@ gitUpdater, pythonAtLeast, isPyPy, + fetchpatch, # build-system pathspec, @@ -49,6 +50,15 @@ buildPythonPackage rec { hash = "sha256-sm/pxQGxH5XuPH7B8i3fpp30KaFU9aSp6BT67UcDPvU="; }; + patches = [ + # fix build w/ glibc-2.44 + # If Python.h isn't included first, a const redefinition error now occurs otherwise. + (fetchpatch { + url = "https://github.com/python/mypy/commit/46acbe85c0e1703ebf2e6d4c699772edcdcf4652.patch"; + hash = "sha256-KslHiKqinvvXZoxvCnZXOhCm7i8577PbSdNGudCsjZE="; + }) + ]; + passthru.updateScript = gitUpdater { rev-prefix = "v"; }; diff --git a/pkgs/development/python-modules/protobuf/7.nix b/pkgs/development/python-modules/protobuf/7.nix index 7ba3647f3087..fd0a3a0d8796 100644 --- a/pkgs/development/python-modules/protobuf/7.nix +++ b/pkgs/development/python-modules/protobuf/7.nix @@ -9,13 +9,13 @@ buildPythonPackage (finalAttrs: { pname = "protobuf"; - version = "7.36.1"; + version = "7.36.2"; pyproject = true; __structuredAttrs = true; src = fetchPypi { inherit (finalAttrs) pname version; - hash = "sha256-0PZHDwziuE4/6uotS4FjeLN7pNSqCKJ0MFNz3pPi1SQ="; + hash = "sha256-SX0EY/8zFmgdpsC56NBstGXWGrzgC2E6tCImF1ZE0bs="; }; build-system = [ setuptools ]; diff --git a/pkgs/development/python-modules/psycopg/default.nix b/pkgs/development/python-modules/psycopg/default.nix index 4e4200f9adba..120fc3ea0b77 100644 --- a/pkgs/development/python-modules/psycopg/default.nix +++ b/pkgs/development/python-modules/psycopg/default.nix @@ -34,14 +34,14 @@ let pname = "psycopg"; - version = "3.3.4"; + version = "3.3.5"; pyproject = true; src = fetchFromGitHub { owner = "psycopg"; repo = "psycopg"; tag = version; - hash = "sha256-hHgswbqaoQRQrUxhNFG6tfmlap1mVUo/OkNsWF686U4="; + hash = "sha256-yjfLoichILaKocoAP3IUwkGGJPq910r8qvpdif/oONA="; }; patches = [ diff --git a/pkgs/development/python-modules/pyjwt/default.nix b/pkgs/development/python-modules/pyjwt/default.nix index 74754630a145..d1267cf08628 100644 --- a/pkgs/development/python-modules/pyjwt/default.nix +++ b/pkgs/development/python-modules/pyjwt/default.nix @@ -11,16 +11,16 @@ oauthlib, }: -buildPythonPackage rec { +buildPythonPackage (finalAttrs: { pname = "pyjwt"; - version = "2.13.0"; + version = "2.14.0"; pyproject = true; src = fetchFromGitHub { owner = "jpadilla"; repo = "pyjwt"; - tag = version; - hash = "sha256-q4ynXCJVDsyZh70439dloyWgRTLVm+elDOahUVOT5vA="; + tag = finalAttrs.version; + hash = "sha256-SxJ2GQt1pfm8iAeTB2RmH2kliGeQ6whkM5nuesI1s/U="; }; outputs = [ @@ -38,7 +38,10 @@ buildPythonPackage rec { optional-dependencies.crypto = [ cryptography ]; - nativeCheckInputs = [ pytestCheckHook ] ++ (lib.concatAttrValues optional-dependencies); + nativeCheckInputs = [ + pytestCheckHook + ] + ++ (lib.concatAttrValues finalAttrs.passthru.optional-dependencies); disabledTests = [ # requires internet connection @@ -52,10 +55,10 @@ buildPythonPackage rec { }; meta = { - changelog = "https://github.com/jpadilla/pyjwt/blob/${version}/CHANGELOG.rst"; + changelog = "https://github.com/jpadilla/pyjwt/blob/${finalAttrs.src.tag}/CHANGELOG.rst"; description = "JSON Web Token implementation in Python"; homepage = "https://github.com/jpadilla/pyjwt"; license = lib.licenses.mit; maintainers = with lib.maintainers; [ prikhi ]; }; -} +}) diff --git a/pkgs/development/tcl-modules/by-name/ex/expect/package.nix b/pkgs/development/tcl-modules/by-name/ex/expect/package.nix index 14526ebc3c1d..02dd152878c2 100644 --- a/pkgs/development/tcl-modules/by-name/ex/expect/package.nix +++ b/pkgs/development/tcl-modules/by-name/ex/expect/package.nix @@ -6,6 +6,7 @@ tcl, makeWrapper, autoreconfHook, + bashNonInteractive, replaceVars, dejagnu, }: @@ -38,6 +39,10 @@ tcl.mkTclDerivation (finalAttrs: { makeWrapper ]; + buildInputs = [ + bashNonInteractive + ]; + postInstall = '' tclWrapperArgs+=(--prefix PATH : ${lib.makeBinPath [ tcl ]}) ${lib.optionalString stdenv.hostPlatform.isDarwin "tclWrapperArgs+=(--prefix DYLD_LIBRARY_PATH : $out/lib/expect${finalAttrs.version})"} diff --git a/pkgs/development/tcl-modules/by-name/ex/expect_5/package.nix b/pkgs/development/tcl-modules/by-name/ex/expect_5/package.nix index 2cda3a33300c..14c2d259a0b2 100644 --- a/pkgs/development/tcl-modules/by-name/ex/expect_5/package.nix +++ b/pkgs/development/tcl-modules/by-name/ex/expect_5/package.nix @@ -6,16 +6,17 @@ tcl, makeWrapper, autoreconfHook, + bashNonInteractive, fetchpatch, replaceVars, }: -tcl.mkTclDerivation rec { +tcl.mkTclDerivation (finalAttrs: { pname = "expect"; version = "5.45.4"; src = fetchurl { - url = "mirror://sourceforge/expect/Expect/${version}/expect${version}.tar.gz"; + url = "mirror://sourceforge/expect/Expect/${finalAttrs.version}/expect${finalAttrs.version}.tar.gz"; hash = "sha256-Safag7C92fRtBKBN7sGcd2e7mjI+QMR4H4nK92C5LDQ="; }; @@ -49,7 +50,9 @@ tcl.mkTclDerivation rec { makeWrapper ]; - strictDeps = true; + buildInputs = [ + bashNonInteractive + ]; env = { NIX_CFLAGS_COMPILE = toString ( @@ -64,7 +67,7 @@ tcl.mkTclDerivation rec { postInstall = '' tclWrapperArgs+=(--prefix PATH : ${lib.makeBinPath [ tcl ]}) - ${lib.optionalString stdenv.hostPlatform.isDarwin "tclWrapperArgs+=(--prefix DYLD_LIBRARY_PATH : $out/lib/expect${version})"} + ${lib.optionalString stdenv.hostPlatform.isDarwin "tclWrapperArgs+=(--prefix DYLD_LIBRARY_PATH : $out/lib/expect${finalAttrs.version})"} ''; tclRequiresCheck = [ "Expect" ]; @@ -83,4 +86,4 @@ tcl.mkTclDerivation rec { maintainers = with lib.maintainers; [ fgaz ]; broken = tcl.isTcl9; }; -} +}) diff --git a/pkgs/development/tools/electron/common.nix b/pkgs/development/tools/electron/common.nix index 5b72914afc4c..99946bc1901a 100644 --- a/pkgs/development/tools/electron/common.nix +++ b/pkgs/development/tools/electron/common.nix @@ -12,6 +12,7 @@ yarn-berry_4, unzip, writers, + substitute, libnotify, libpulseaudio, @@ -26,9 +27,16 @@ let gclientDeps = gclient2nix.importGclientDeps info.deps; yarn-berry = yarn-berry_4; - # Only apply to old versions after upstream updates to Yarn 4.14 - # https://github.com/electron/electron/blob/main/package.json#L148 - yarnPatch = ./yarn-4.14-support.patch; + # Only apply to old versions after upstream updates to Yarn 4.15 + # https://github.com/electron/electron/blob/main/package.json#L152 + yarnPatch = substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry_4.lockfileVersion + ]; + }; in ((chromium.override { upstream-info = info.chromium; }).mkDerivation (base: { @@ -111,7 +119,8 @@ in ++ # Restore fake libGLESv2.so which is patchelf'd by the chromium derivation lib.optional (lib.versionAtLeast info.version "44") - ./0001-Revert-build-stop-shipping-dummy-ANGLE-libs-in-Linux.patch; + ./0001-Revert-build-stop-shipping-dummy-ANGLE-libs-in-Linux.patch + ++ lib.optional (lib.versionOlder info.version "43") ./fix-electron42-glibc-2.43.patch; postPatch = '' mkdir -p third_party/jdk/current/bin diff --git a/pkgs/development/tools/electron/fix-electron42-glibc-2.43.patch b/pkgs/development/tools/electron/fix-electron42-glibc-2.43.patch new file mode 100644 index 000000000000..27ca436c2b52 --- /dev/null +++ b/pkgs/development/tools/electron/fix-electron42-glibc-2.43.patch @@ -0,0 +1,67 @@ +From 83a9ccb1265dcdeeb8bf17205e00b751f86641d3 Mon Sep 17 00:00:00 2001 +From: Ho Cheung +Date: Tue, 21 Apr 2026 08:19:53 -0700 +Subject: [PATCH] [sandbox] Fix SYS_SECCOMP conflict with newer glibc + +glibc now exposes SYS_SECCOMP in signal headers, which conflicts with +Chromium's fallback macro in linux_seccomp.h. + +Stop defining SYS_SECCOMP in the public compat header and use a local +fallback in trap.cc instead. + +Test: Tested on an Ubuntu 26.04 container using use_sysroot = false. +Bug: 456218403 +Change-Id: I73ddfa85453dd9d524b64b4c1bca4f95b82c9f2b +Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7781604 +Reviewed-by: Elly +Commit-Queue: Aaron Teo +Cr-Commit-Position: refs/heads/main@{#1618207} +--- + +diff --git a/sandbox/linux/seccomp-bpf/trap.cc b/sandbox/linux/seccomp-bpf/trap.cc +index 1316786d..212e80e 100644 +--- a/sandbox/linux/seccomp-bpf/trap.cc ++++ b/sandbox/linux/seccomp-bpf/trap.cc +@@ -29,6 +29,12 @@ + + namespace { + ++#if defined(SYS_SECCOMP) ++constexpr int kSigsysSeccompCode = SYS_SECCOMP; ++#else ++constexpr int kSigsysSeccompCode = 1; ++#endif ++ + struct arch_sigsys { + // RAW_PTR_EXCLUSION: Points to a code address given to us by the kernel. + RAW_PTR_EXCLUSION void* ip; +@@ -151,7 +157,7 @@ + // Various sanity checks to make sure we actually received a signal + // triggered by a BPF filter. If something else triggered SIGSYS + // (e.g. kill()), there is really nothing we can do with this signal. +- if (nr != LINUX_SIGSYS || info->si_code != SYS_SECCOMP || !ctx || ++ if (nr != LINUX_SIGSYS || info->si_code != kSigsysSeccompCode || !ctx || + info->si_errno <= 0 || + static_cast(info->si_errno) > trap_array_size_) { + // ATI drivers seem to send SIGSYS, so this cannot be FATAL. +@@ -162,7 +168,6 @@ + return; + } + +- + // Obtain the siginfo information that is specific to SIGSYS. + struct arch_sigsys sigsys; + #if defined(si_call_addr) +diff --git a/sandbox/linux/system_headers/linux_seccomp.h b/sandbox/linux/system_headers/linux_seccomp.h +index 8690a96..8ebf4045 100644 +--- a/sandbox/linux/system_headers/linux_seccomp.h ++++ b/sandbox/linux/system_headers/linux_seccomp.h +@@ -214,8 +214,4 @@ + #define SECCOMP_RET_INVALID 0x00010000U // Illegal return value + #endif + +-#ifndef SYS_SECCOMP +-#define SYS_SECCOMP 1 +-#endif +- + #endif // SANDBOX_LINUX_SYSTEM_HEADERS_LINUX_SECCOMP_H_ diff --git a/pkgs/development/tools/electron/info.json b/pkgs/development/tools/electron/info.json index 76e2003d314f..022de72aa9b6 100644 --- a/pkgs/development/tools/electron/info.json +++ b/pkgs/development/tools/electron/info.json @@ -1367,7 +1367,7 @@ } }, "electron_yarn_data": { - "hash": "sha256-fVqQdwstENinc1XTRar5d4CnO5BLb9U2+Z6jOSzAIsk=", + "hash": "sha256-3djOSYb8lSTWbtclB23O1I/Aw3n6auInUAtzOYrMth4=", "missing_hashes": { "@oxfmt/binding-android-arm-eabi@npm:0.42.0": "42c08d87ce491086843070241f8777fa2cb968f4a08f67b3f6c33a8f67e0b3eac50eae146daede743e90e3bc32326951c5188814eea02e9c3e4a9764a4b492ba", "@oxfmt/binding-android-arm64@npm:0.42.0": "73e6609498d05c655c6a435af9f3e4f341137c260c7ae27fbb0377573574ca5200bd9f187aa90d442879733bbd0c4e91ae023c3b4579c9a57413a0b2922c023a", @@ -2797,7 +2797,7 @@ } }, "electron_yarn_data": { - "hash": "sha256-0ECf2IVgznQNlVMiHqAJCt8lBXXsFIJUekaFnVS+cJ4=", + "hash": "sha256-D3Tmxc2tzpUfKlWq4RXy6hYpqJ0Dsw7J4aQPp1rSZVs=", "missing_hashes": { "@oxfmt/binding-android-arm-eabi@npm:0.42.0": "42c08d87ce491086843070241f8777fa2cb968f4a08f67b3f6c33a8f67e0b3eac50eae146daede743e90e3bc32326951c5188814eea02e9c3e4a9764a4b492ba", "@oxfmt/binding-android-arm64@npm:0.42.0": "73e6609498d05c655c6a435af9f3e4f341137c260c7ae27fbb0377573574ca5200bd9f187aa90d442879733bbd0c4e91ae023c3b4579c9a57413a0b2922c023a", @@ -4251,7 +4251,7 @@ } }, "electron_yarn_data": { - "hash": "sha256-Qxv2r3kAYGwB0tVDoZeLqv2exBNdRCABFFrJXQ+X2jE=", + "hash": "sha256-/Se92a1Gw8vT3J1IkAcQmd4wYb3zwh+2LdrA5MwWHy8=", "missing_hashes": { "@oxfmt/binding-android-arm-eabi@npm:0.42.0": "42c08d87ce491086843070241f8777fa2cb968f4a08f67b3f6c33a8f67e0b3eac50eae146daede743e90e3bc32326951c5188814eea02e9c3e4a9764a4b492ba", "@oxfmt/binding-android-arm64@npm:0.42.0": "73e6609498d05c655c6a435af9f3e4f341137c260c7ae27fbb0377573574ca5200bd9f187aa90d442879733bbd0c4e91ae023c3b4579c9a57413a0b2922c023a", diff --git a/pkgs/development/tools/electron/update.py b/pkgs/development/tools/electron/update.py index ad6124847afb..9f8d3cadae36 100755 --- a/pkgs/development/tools/electron/update.py +++ b/pkgs/development/tools/electron/update.py @@ -118,9 +118,9 @@ def get_chromium_gn_source(chromium_tag: str) -> dict: def get_electron_yarn_data(electron_tag: str) -> dict: print(f"yarn-berry-fetcher prefetch", file=sys.stderr) with tempfile.TemporaryDirectory() as tmp_dir: - print(f"Patching yarn.lock for yarn 4.14 support", file=sys.stderr) + print(f"Patching yarn.lock for yarn 4.18 support", file=sys.stderr) yarn_lock_file=get_electron_file(electron_tag, "yarn.lock") - patched_yarn_lock_file=yarn_lock_file.replace('version: 8', 'version: 9', count=1) + patched_yarn_lock_file=yarn_lock_file.replace('version: 8', 'version: 10', count=1) with open(tmp_dir + "/yarn.lock", "w") as f: f.write(patched_yarn_lock_file) missing_hashes_str = ( diff --git a/pkgs/development/tools/electron/yarn-4.14-support.patch b/pkgs/development/tools/electron/yarn-fix.patch similarity index 89% rename from pkgs/development/tools/electron/yarn-4.14-support.patch rename to pkgs/development/tools/electron/yarn-fix.patch index 1bf5818747e2..2fa9032d3a0c 100644 --- a/pkgs/development/tools/electron/yarn-4.14-support.patch +++ b/pkgs/development/tools/electron/yarn-fix.patch @@ -15,6 +15,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10c0 diff --git a/pkgs/development/tools/misc/texinfo/common.nix b/pkgs/development/tools/misc/texinfo/common.nix index 7b406eb8bf00..d010db80c808 100644 --- a/pkgs/development/tools/misc/texinfo/common.nix +++ b/pkgs/development/tools/misc/texinfo/common.nix @@ -61,7 +61,7 @@ stdenv.mkDerivation { ++ optional crossBuildTools ./cross-tools-flags.patch; postPatch = '' - patchShebangs tp/maintain/regenerate_commands_perl_info.pl + patchShebangs tta/maintain/regenerate_commands_perl_info.pl ''; env = { diff --git a/pkgs/development/tools/mysql-shell/8.nix b/pkgs/development/tools/mysql-shell/8.nix index 238742bd3ebf..7c6b7680e282 100644 --- a/pkgs/development/tools/mysql-shell/8.nix +++ b/pkgs/development/tools/mysql-shell/8.nix @@ -29,6 +29,7 @@ cyrus_sasl, openldap, antlr, + fetchpatch, }: let @@ -66,6 +67,12 @@ stdenv.mkDerivation (finalAttrs: { # No openssl bundling on macOS. It's not working. # See https://github.com/mysql/mysql-shell/blob/5b84e0be59fc0e027ef3f4920df15f7be97624c1/cmake/ssl.cmake#L53 ./no-openssl-bundling.patch + + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/mysql/mysql-shell/commit/4ce8746d8a7eecf9ae66d4d500c84d57cc4fbdbb.patch"; + hash = "sha256-LUGC7gnNQ3zhmWUm2xogsOAmx8QSngQBHVJMWHFtWz0="; + }) ]; postPatch = '' diff --git a/pkgs/development/tools/mysql-shell/9.nix b/pkgs/development/tools/mysql-shell/9.nix index 14843a23f189..5f68b885640e 100644 --- a/pkgs/development/tools/mysql-shell/9.nix +++ b/pkgs/development/tools/mysql-shell/9.nix @@ -29,6 +29,7 @@ cyrus_sasl, openldap, antlr, + fetchpatch, }: let @@ -66,6 +67,12 @@ stdenv.mkDerivation (finalAttrs: { # No openssl bundling on macOS. It's not working. # See https://github.com/mysql/mysql-shell/blob/5b84e0be59fc0e027ef3f4920df15f7be97624c1/cmake/ssl.cmake#L53 ./no-openssl-bundling.patch + + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/mysql/mysql-shell/commit/4ce8746d8a7eecf9ae66d4d500c84d57cc4fbdbb.patch"; + hash = "sha256-LUGC7gnNQ3zhmWUm2xogsOAmx8QSngQBHVJMWHFtWz0="; + }) ]; postPatch = '' diff --git a/pkgs/development/tools/rust/bindgen/default.nix b/pkgs/development/tools/rust/bindgen/default.nix index 393b89a4acb4..6831e156dfa7 100644 --- a/pkgs/development/tools/rust/bindgen/default.nix +++ b/pkgs/development/tools/rust/bindgen/default.nix @@ -2,11 +2,18 @@ rust-bindgen-unwrapped, zlib, bash, + lib, runCommand, runCommandCC, + stdenv, }: let clang = rust-bindgen-unwrapped.clang; + targetFlag = + if (!lib.systems.equals stdenv.targetPlatform stdenv.hostPlatform) then + "--target=${stdenv.targetPlatform.config}" + else + ""; self = runCommand "rust-bindgen-${rust-bindgen-unwrapped.version}" { @@ -49,6 +56,7 @@ let --replace-fail "@bash@" "${bash}" \ --replace-fail "@cxxincludes@" "$cxxincludes" \ --replace-fail "@cincludes@" "$cincludes" \ + --replace-fail "@targetFlag@" "${targetFlag}" \ --replace-fail "@unwrapped@" "${rust-bindgen-unwrapped}" chmod +x $out/bin/bindgen ''; diff --git a/pkgs/development/tools/rust/bindgen/wrapper.sh b/pkgs/development/tools/rust/bindgen/wrapper.sh index 4311b9720aa8..cd4eff556cc1 100755 --- a/pkgs/development/tools/rust/bindgen/wrapper.sh +++ b/pkgs/development/tools/rust/bindgen/wrapper.sh @@ -28,7 +28,7 @@ if [[ -n "$NIX_DEBUG" ]]; then set -x; fi; # shellcheck disable=SC2086 -# cxxflags and NIX_CFLAGS_COMPILE should be word-split -exec -a "$0" @unwrapped@/bin/bindgen "$@" $sep $cxxflags @cincludes@ $NIX_CFLAGS_COMPILE +# targetFlag, cxxflags and NIX_CFLAGS_COMPILE should be word-split +exec -a "$0" @unwrapped@/bin/bindgen "$@" $sep @targetFlag@ $cxxflags @cincludes@ $NIX_CFLAGS_COMPILE # note that we add the flags after $@ which is incorrect. This is only for the sake # of simplicity. diff --git a/pkgs/development/web/nodejs/nodejs.nix b/pkgs/development/web/nodejs/nodejs.nix index a82a5e540eb5..5d5f8d45efd6 100644 --- a/pkgs/development/web/nodejs/nodejs.nix +++ b/pkgs/development/web/nodejs/nodejs.nix @@ -24,26 +24,6 @@ openssl, simdjson, simdutf, - simdutf_6 ? ( - simdutf.overrideAttrs ( - { - version = "6.5.0"; - - src = fetchFromGitHub { - owner = "simdutf"; - repo = "simdutf"; - rev = "v6.5.0"; - hash = "sha256-bZ4r62GMz2Dkd3fKTJhelitaA8jUBaDjG6jOysEg8Nk="; - }; - } - // (lib.optionalAttrs stdenv.buildPlatform.isDarwin { - # Fix build on darwin - postPatch = '' - substituteInPlace tools/CMakeLists.txt --replace-fail '-Wl,--gc-sections' "" - ''; - }) - ) - ), sqlite, temporal_capi, uvwasi, @@ -140,7 +120,8 @@ let # TODO: also handle MIPS flags (mips_arch, mips_fpu, mips_float_abi). useSharedAbseilAndHighway = lib.versionAtLeast version "26.9"; - useSharedAdaAndSimd = lib.versionAtLeast version "22.2"; + useSharedAdaAndSimdjson = lib.versionAtLeast version "22.2"; + useSharedSimdutf = lib.versionAtLeast version "26.10"; useSharedFFI = lib.versionAtLeast version "26.1"; useSharedGtestAndHistogram = lib.versionAtLeast version ( if majorVersion == "24" then "24.14.0" else "25.4" @@ -170,12 +151,14 @@ let abseil = abseil-cpp; highway = libhwy; }) - // (lib.optionalAttrs useSharedAdaAndSimd { + // (lib.optionalAttrs useSharedAdaAndSimdjson { inherit ada simdjson ; - simdutf = if lib.versionAtLeast version "25" then simdutf else simdutf_6; + }) + // (lib.optionalAttrs useSharedSimdutf { + inherit simdutf; }) // (lib.optionalAttrs useSharedSQLite { inherit sqlite; diff --git a/pkgs/development/web/nodejs/v24.nix b/pkgs/development/web/nodejs/v24.nix index 44083fa48d15..5fee25ab2f17 100644 --- a/pkgs/development/web/nodejs/v24.nix +++ b/pkgs/development/web/nodejs/v24.nix @@ -29,8 +29,8 @@ let [ ]; in buildNodejs { - version = "24.20.0"; - sha256 = "2732fc3f588dd335cd6779c06864f7cd424bb1b5ff9a1743059a66c54f9ca4a1"; + version = "24.21.0"; + sha256 = "a6f54defb6fd7c84f41dba13d61e78e9b4e0961712cf61f29715c05f5ced94fc"; patches = (lib.optional (!(stdenv.hostPlatform.emulatorAvailable buildPackages)) (fetchpatch2 { url = "https://raw.githubusercontent.com/buildroot/buildroot/2f0c31bffdb59fb224387e35134a6d5e09a81d57/package/nodejs/nodejs-src/0003-include-obj-name-in-shared-intermediate.patch"; @@ -53,12 +53,6 @@ buildNodejs { ./use-correct-env-in-tests.patch ./bin-sh-node-run-v22.patch ./use-nix-codesign.patch - - # TODO: remove when support for OpenSSL 3.6.4 has landed upstream - (fetchpatch2 { - url = "https://github.com/nodejs/node/commit/a37601c99d7bde9abb3b3ae57b2fb2bacd81ec9d.patch?full_index=1"; - hash = "sha256-AdAPMs1RZgqJ0bzNZ6IvChjT97lbW+XV4cRWygzU1qc="; - }) ] ++ gypPatches ++ lib.optionals (!stdenv.buildPlatform.isDarwin) [ diff --git a/pkgs/os-specific/darwin/by-name/ic/ICU/package.nix b/pkgs/os-specific/darwin/by-name/ic/ICU/package.nix index 935dfd277a8d..c25fbbc03b78 100644 --- a/pkgs/os-specific/darwin/by-name/ic/ICU/package.nix +++ b/pkgs/os-specific/darwin/by-name/ic/ICU/package.nix @@ -87,7 +87,7 @@ let description = "Unicode and globalization support library with Apple customizations"; license = lib.licenses.icu; teams = [ lib.teams.darwin ]; - platforms = lib.platforms.darwin; + platforms = lib.platforms.darwin ++ lib.platforms.linux; pkgConfigModules = [ "icu-i18n" "icu-io" @@ -169,8 +169,7 @@ let substituteInPlace "$dev/bin/icu-config" \ ${lib.concatMapStringsSep " " (r: "--replace-fail '${r.from}' '${r.to}'") replacements} '' - # Create library with everything reexported to provide the same ABI as the system ICU. - + lib.optionalString stdenv.hostPlatform.isDarwin ( + + ( if stdenv.hostPlatform.isStatic then '' ${stdenv.cc.targetPrefix}ar qL "$out/lib/libicucore.a" \ @@ -180,20 +179,33 @@ let "$out/lib/libicuio.a" '' else - '' - icuVersion=$(basename "$out/share/icu/"*) - ${stdenv.cc.targetPrefix}clang -dynamiclib \ - -L "$out/lib" \ - -Wl,-reexport-licuuc \ - -Wl,-reexport-licudata \ - -Wl,-reexport-licui18n \ - -Wl,-reexport-licuio \ - -compatibility_version 1 \ - -current_version "$icuVersion" \ - -install_name "$out/lib/libicucore.A.dylib" \ - -o "$out/lib/libicucore.A.dylib" - ln -s libicucore.A.dylib "$out/lib/libicucore.dylib" - '' + ( + lib.optionalString stdenv.hostPlatform.isDarwin '' + icuVersion=$(basename "$out/share/icu/"*) + ${stdenv.cc.targetPrefix}clang -dynamiclib \ + -L "$out/lib" \ + -Wl,-reexport-licuuc \ + -Wl,-reexport-licudata \ + -Wl,-reexport-licui18n \ + -Wl,-reexport-licuio \ + -compatibility_version 1 \ + -current_version "$icuVersion" \ + -install_name "$out/lib/libicucore.A.dylib" \ + -o "$out/lib/libicucore.A.dylib" + ln -s libicucore.A.dylib "$out/lib/libicucore.dylib" + '' + + lib.optionalString stdenv.hostPlatform.isLinux '' + ${stdenv.cc.targetPrefix}cc -shared \ + -L "$out/lib" \ + -Wl,--no-as-needed \ + -licuuc \ + -licudata \ + -licui18n \ + -licuio \ + -o "$out/lib/libicucore.so.A" + ln -s libicucore.so.A "$out/lib/libicucore.so" + '' + ) ) ); diff --git a/pkgs/os-specific/linux/kernel/C23-compat-6.1.patch b/pkgs/os-specific/linux/kernel/C23-compat-6.1.patch new file mode 100644 index 000000000000..73c268b8b615 --- /dev/null +++ b/pkgs/os-specific/linux/kernel/C23-compat-6.1.patch @@ -0,0 +1,13 @@ +diff --git a/tools/lib/bpf/libbpf.c b/tools/lib/bpf/libbpf.c +index 7bd6aff6e260..33b214a91338 100644 +--- a/tools/lib/bpf/libbpf.c ++++ b/tools/lib/bpf/libbpf.c +@@ -10748,7 +10748,7 @@ static int resolve_full_path(const char *file, char *result, size_t result_sz) + if (!search_paths[i]) + continue; + for (s = search_paths[i]; s != NULL; s = strchr(s, ':')) { +- char *next_path; ++ const char *next_path; + int seg_len; + + if (s[0] == ':') diff --git a/pkgs/os-specific/linux/kernel/patches.nix b/pkgs/os-specific/linux/kernel/patches.nix index db617c867064..12cf001b6503 100644 --- a/pkgs/os-specific/linux/kernel/patches.nix +++ b/pkgs/os-specific/linux/kernel/patches.nix @@ -27,4 +27,9 @@ name = "request-key-helper"; patch = ./request-key-helper.patch; }; + + libbpf_C23_compat = { + name = "c23-compat-libbpf"; + patch = ./C23-compat-6.1.patch; + }; } diff --git a/pkgs/os-specific/linux/libbpf/0.x.nix b/pkgs/os-specific/linux/libbpf/0.x.nix deleted file mode 100644 index 7d5676be8c0a..000000000000 --- a/pkgs/os-specific/linux/libbpf/0.x.nix +++ /dev/null @@ -1,70 +0,0 @@ -{ - fetchFromGitHub, - elfutils, - pkg-config, - stdenv, - zlib, - lib, - nixosTests, -}: - -# update bot does not seem to limit updates here to 0.8.x despite -# the all-packages derivation being libbpf_0 as the libbpf base alias -# is still present: just disable it for 0.x: -# nixpkgs-update: no auto update - -stdenv.mkDerivation rec { - pname = "libbpf"; - version = "0.8.3"; - - src = fetchFromGitHub { - owner = "libbpf"; - repo = "libbpf"; - rev = "v${version}"; - sha256 = "sha256-J5cUvfUYc+uLdkFa2jx/2bqBoZg/eSzc6SWlgKqcfIc="; - }; - - nativeBuildInputs = [ pkg-config ]; - buildInputs = [ - elfutils - zlib - ]; - - enableParallelBuilding = true; - makeFlags = [ - "PREFIX=$(out)" - "-C src" - ]; - - passthru.tests = { - bpf = nixosTests.bpf; - }; - - postInstall = '' - # install linux's libbpf-compatible linux/btf.h - install -Dm444 include/uapi/linux/*.h -t $out/include/linux - ''; - - # FIXME: Multi-output requires some fixes to the way the pkg-config file is - # constructed (it gets put in $out instead of $dev for some reason, with - # improper paths embedded). Don't enable it for now. - - # outputs = [ "out" "dev" ]; - - meta = { - description = "Upstream mirror of libbpf"; - homepage = "https://github.com/libbpf/libbpf"; - license = with lib.licenses; [ - lgpl21 # or - bsd2 - ]; - maintainers = with lib.maintainers; [ - thoughtpolice - vcunat - saschagrunert - martinetd - ]; - platforms = lib.platforms.linux; - identifiers.cpeParts = lib.meta.cpeFullVersionWithVendor "libbpf_project" version; - }; -} diff --git a/pkgs/os-specific/linux/minimal-bootstrap/gcc/glibc.nix b/pkgs/os-specific/linux/minimal-bootstrap/gcc/glibc.nix index 84429548ef45..9608b8d988e5 100644 --- a/pkgs/os-specific/linux/minimal-bootstrap/gcc/glibc.nix +++ b/pkgs/os-specific/linux/minimal-bootstrap/gcc/glibc.nix @@ -22,7 +22,7 @@ }: let pname = "gcc"; - version = "15.3.0"; + version = "16.2.0"; linkerName = { i686-linux = "ld-linux.so.2"; @@ -32,7 +32,7 @@ let src = fetchurl { url = "mirror://gnu/gcc/gcc-${version}/gcc-${version}.tar.xz"; - hash = "sha256-+lnBvu+JlfJ8TXHB3yJ1hxiTFdPm+v8btDBuYbDFMOs="; + hash = "sha256-5nOOKVl/czJwcxqpBgDzf/3ARQed/CfsfoGSzIEIXD4="; }; gmpVersion = "6.3.0"; @@ -155,6 +155,9 @@ bash.runCommand "${pname}-${version}" # Install make -j $NIX_BUILD_CORES install-strip + # Header installation tools retain build-time bash and sed unnecessarily. + rm -rf $out/libexec/gcc/*/*/install-tools $out/lib/gcc/*/*/install-tools + # libstdc++ gdb pretty-printers + man pages are unused downstream. rm -rf $out/share/gcc-*/python $out/share/man $out/share/info '' diff --git a/pkgs/os-specific/linux/minimal-bootstrap/gcc/latest.nix b/pkgs/os-specific/linux/minimal-bootstrap/gcc/latest.nix index 0489f9ceb125..8421ce2179a2 100644 --- a/pkgs/os-specific/linux/minimal-bootstrap/gcc/latest.nix +++ b/pkgs/os-specific/linux/minimal-bootstrap/gcc/latest.nix @@ -21,11 +21,11 @@ }: let pname = "gcc"; - version = "15.3.0"; + version = "16.2.0"; src = fetchurl { url = "mirror://gnu/gcc/gcc-${version}/gcc-${version}.tar.xz"; - hash = "sha256-+lnBvu+JlfJ8TXHB3yJ1hxiTFdPm+v8btDBuYbDFMOs="; + hash = "sha256-5nOOKVl/czJwcxqpBgDzf/3ARQed/CfsfoGSzIEIXD4="; }; gmpVersion = "6.3.0"; @@ -154,6 +154,9 @@ bash.runCommand "${pname}-${version}" # Install make -j $NIX_BUILD_CORES install-strip + # Header installation tools retain build-time bash and sed unnecessarily. + rm -rf $out/libexec/gcc/*/*/install-tools $out/lib/gcc/*/*/install-tools + # libstdc++ gdb pretty-printers + man pages are unused downstream. rm -rf $out/share/gcc-*/python $out/share/man $out/share/info diff --git a/pkgs/os-specific/linux/minimal-bootstrap/glibc/default.nix b/pkgs/os-specific/linux/minimal-bootstrap/glibc/default.nix index f156f862ecc0..cf71f17513f1 100644 --- a/pkgs/os-specific/linux/minimal-bootstrap/glibc/default.nix +++ b/pkgs/os-specific/linux/minimal-bootstrap/glibc/default.nix @@ -20,11 +20,11 @@ }: let pname = "glibc"; - version = "2.42"; + version = "2.44"; src = fetchurl { url = "mirror://gnu/libc/glibc-${version}.tar.xz"; - hash = "sha256-0XdeMuRijmTvkw9DW2e7Y691may2viszW58Z8WUJ8X8="; + hash = "sha256-N/YA8r7zxegwAUcFlWiyouQKetbMxlzpQlVtSUKcxmc="; }; linkerFile = diff --git a/pkgs/os-specific/linux/minimal-bootstrap/glibc/headers.nix b/pkgs/os-specific/linux/minimal-bootstrap/glibc/headers.nix index 2a4676231f2f..b636629bff8d 100644 --- a/pkgs/os-specific/linux/minimal-bootstrap/glibc/headers.nix +++ b/pkgs/os-specific/linux/minimal-bootstrap/glibc/headers.nix @@ -21,11 +21,11 @@ }: let pname = "glibc-headers"; - version = "2.42"; + version = "2.44"; src = fetchurl { url = "mirror://gnu/libc/glibc-${version}.tar.xz"; - hash = "sha256-0XdeMuRijmTvkw9DW2e7Y691may2viszW58Z8WUJ8X8="; + hash = "sha256-N/YA8r7zxegwAUcFlWiyouQKetbMxlzpQlVtSUKcxmc="; }; in bash.runCommand "${pname}-${version}" diff --git a/pkgs/os-specific/linux/minimal-bootstrap/musl/default.nix b/pkgs/os-specific/linux/minimal-bootstrap/musl/default.nix index d9a96dd6e5a6..1a715a0158fa 100644 --- a/pkgs/os-specific/linux/minimal-bootstrap/musl/default.nix +++ b/pkgs/os-specific/linux/minimal-bootstrap/musl/default.nix @@ -25,6 +25,11 @@ bash.runCommand "${pname}-${version}" { inherit pname version meta; + outputs = [ + "out" + "bin" + ]; + nativeBuildInputs = [ gcc binutils @@ -87,5 +92,9 @@ bash.runCommand "${pname}-${version}" # Install make -j $NIX_BUILD_CORES install sed -i 's|/bin/sh|${bash}/bin/bash|' $out/bin/* - ln -s ../lib/libc.so $out/bin/ldd + + # Don't retain bootstrap bash in libc closure in wrapper + mkdir -p $bin + mv $out/bin $bin/bin + ln -s $out/lib/libc.so $bin/bin/ldd '' diff --git a/pkgs/os-specific/linux/systemd/default.nix b/pkgs/os-specific/linux/systemd/default.nix index b187c1d4b54e..958c424ba30e 100644 --- a/pkgs/os-specific/linux/systemd/default.nix +++ b/pkgs/os-specific/linux/systemd/default.nix @@ -5,7 +5,6 @@ pkgsCross, testers, fetchFromGitHub, - fetchpatch, buildPackages, makeBinaryWrapper, ninja, @@ -204,13 +203,13 @@ let in stdenv.mkDerivation (finalAttrs: { inherit pname; - version = "261.2"; + version = "261.3"; src = fetchFromGitHub { owner = "systemd"; repo = "systemd"; tag = "v${finalAttrs.version}"; - hash = "sha256-w0Fxx+zYBs806whyaKBytGwSgn89ARdukAm6Hp+XlQQ="; + hash = "sha256-W3E6QUxr+x5jt4KJlHWbP4unyQCI7yA5oymgz6la1ng="; }; # PATCH POLICY @@ -240,13 +239,6 @@ stdenv.mkDerivation (finalAttrs: { ./0003-add-rootprefix-to-lookup-dir-paths.patch ./0004-path-util.h-add-placeholder-for-DEFAULT_PATH_NORMAL.patch ./0005-core-don-t-taint-on-unmerged-usr.patch - # Remove this with v262 - # Fixes an issue for switch-to-configuration - (fetchpatch { - name = "postpone-d-bus-queue-dispatch.patch"; - url = "https://github.com/systemd/systemd/commit/266b3e50218e2b27cd67d2371c165bf53ad3bf00.patch"; - hash = "sha256-dEEzZUqicnmgDuXVBV1y0BxzgKbb6Q47Dmxj+O71bFE="; - }) ] ++ lib.optionals (stdenv.hostPlatform.isLinux && stdenv.hostPlatform.isGnu) [ ./0006-timesyncd-disable-NSCD-when-DNSSEC-validation-is-dis.patch diff --git a/pkgs/servers/home-assistant/custom-lovelace-modules/advanced-camera-card/package.nix b/pkgs/servers/home-assistant/custom-lovelace-modules/advanced-camera-card/package.nix index 042ccb0f8436..9bab016c15dc 100644 --- a/pkgs/servers/home-assistant/custom-lovelace-modules/advanced-camera-card/package.nix +++ b/pkgs/servers/home-assistant/custom-lovelace-modules/advanced-camera-card/package.nix @@ -2,6 +2,7 @@ lib, stdenv, fetchFromGitHub, + substitute, gitMinimal, yarn-berry_4, nodejs, @@ -16,14 +17,26 @@ stdenv.mkDerivation (finalAttrs: { owner = "dermotduffy"; repo = "advanced-camera-card"; tag = "v${finalAttrs.version}"; - hash = "sha256-NdWP2nYzDEzmO4DpwVUpn3/KsungKNOzOQf8FxZ4fGw="; + hash = "sha256-I1dm7TZMK/eRF2Uld3e+r4PQBaL9oJc+NI+/5cxaGUs="; + + # Remove after upstream updates to Yarn 4.15 + # https://github.com/dermotduffy/advanced-camera-card/blob/main/package.json#L201 + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry_4.lockfileVersion + ]; + }) + } + ''; }; patches = [ - # Remove after upstream updates to Yarn 4.14 - # https://github.com/dermotduffy/advanced-camera-card/blob/main/package.json#L201 - ./yarn-4.14-support.patch - # Drop hard dependency on .git repo during build ./gitinfo.patch ]; @@ -37,8 +50,8 @@ stdenv.mkDerivation (finalAttrs: { offlineCache = yarn-berry_4.fetchYarnBerryDeps { name = "${finalAttrs.pname}-yarn-deps"; - inherit (finalAttrs) src missingHashes patches; - hash = "sha256-4fdSeSxSjd8EjPmu7U3ftxB+OJJc2uuvM3Umr5iY/a8="; + inherit (finalAttrs) src missingHashes; + hash = "sha256-vbDX5TkUrNqqWLq465mLyGkQ4L8QWJtKv5aCR98P/SI="; }; nativeBuildInputs = [ diff --git a/pkgs/servers/home-assistant/custom-lovelace-modules/advanced-camera-card/yarn-4.14-support.patch b/pkgs/servers/home-assistant/custom-lovelace-modules/advanced-camera-card/yarn-fix.patch similarity index 88% rename from pkgs/servers/home-assistant/custom-lovelace-modules/advanced-camera-card/yarn-4.14-support.patch rename to pkgs/servers/home-assistant/custom-lovelace-modules/advanced-camera-card/yarn-fix.patch index 017f2d295ca9..868db25c8d32 100644 --- a/pkgs/servers/home-assistant/custom-lovelace-modules/advanced-camera-card/yarn-4.14-support.patch +++ b/pkgs/servers/home-assistant/custom-lovelace-modules/advanced-camera-card/yarn-fix.patch @@ -16,6 +16,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10c0 diff --git a/pkgs/servers/home-assistant/custom-lovelace-modules/horizon-card/package.nix b/pkgs/servers/home-assistant/custom-lovelace-modules/horizon-card/package.nix index bdc2ff905538..5cf5e506d029 100644 --- a/pkgs/servers/home-assistant/custom-lovelace-modules/horizon-card/package.nix +++ b/pkgs/servers/home-assistant/custom-lovelace-modules/horizon-card/package.nix @@ -3,6 +3,7 @@ fetchFromGitHub, stdenvNoCC, yarn-berry, + substitute, }: stdenvNoCC.mkDerivation (finalAttrs: { @@ -13,14 +14,24 @@ stdenvNoCC.mkDerivation (finalAttrs: { owner = "rejuvenate"; repo = "lovelace-horizon-card"; tag = "v${finalAttrs.version}"; - hash = "sha256-n8UNL5kSwLz1ncGranmbGyIC5mIKGIV2F3cEF0PSwnU="; - }; + hash = "sha256-p4GI4R5P1LjiXwzF1Hlk6Kk57i+YUcEEsm8bN+qIYdE="; - patches = [ - # Remove after upstream updates to Yarn 4.14 + # Remove after upstream updates to Yarn 4.15 # https://github.com/rejuvenate/lovelace-horizon-card/blob/main/package.json#L4 - ./yarn-4.14-support.patch - ]; + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry.lockfileVersion + ]; + }) + } + ''; + }; nativeBuildInputs = [ yarn-berry @@ -30,8 +41,8 @@ stdenvNoCC.mkDerivation (finalAttrs: { # nix run nixpkgs#yarn-berry_4.yarn-berry-fetcher missing-hashes yarn.lock missingHashes = ./missing-hashes.json; offlineCache = yarn-berry.fetchYarnBerryDeps { - inherit (finalAttrs) src missingHashes patches; - hash = "sha256-WrBUsho7GZI/Un2zvhqZ970psDeAiESiBGJikgX3E5Q="; + inherit (finalAttrs) src missingHashes; + hash = "sha256-iHMIcnCQEbDkAugB9FO4G++eDq3/ABfp0E7Q6893fVY="; }; buildPhase = '' diff --git a/pkgs/by-name/li/linkwarden/02-yarn-4.14-support.patch b/pkgs/servers/home-assistant/custom-lovelace-modules/horizon-card/yarn-fix.patch similarity index 89% rename from pkgs/by-name/li/linkwarden/02-yarn-4.14-support.patch rename to pkgs/servers/home-assistant/custom-lovelace-modules/horizon-card/yarn-fix.patch index 75225db95b78..7a11f6399640 100644 --- a/pkgs/by-name/li/linkwarden/02-yarn-4.14-support.patch +++ b/pkgs/servers/home-assistant/custom-lovelace-modules/horizon-card/yarn-fix.patch @@ -15,6 +15,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10c0 diff --git a/pkgs/servers/mir/common.nix b/pkgs/servers/mir/common.nix index 28a2d5f566bf..8693a3027011 100644 --- a/pkgs/servers/mir/common.nix +++ b/pkgs/servers/mir/common.nix @@ -53,6 +53,7 @@ { version, pinned ? false, + broken ? false, hash, cargoHash ? null, patches ? [ ], @@ -298,6 +299,7 @@ stdenv.mkDerivation ( }; meta = { + inherit broken; description = "Display server and Wayland compositor developed by Canonical"; homepage = "https://mir-server.io"; changelog = "https://github.com/canonical/mir/releases/tag/v${finalAttrs.version}"; diff --git a/pkgs/servers/mir/default.nix b/pkgs/servers/mir/default.nix index 873dca525581..e3044d42d221 100644 --- a/pkgs/servers/mir/default.nix +++ b/pkgs/servers/mir/default.nix @@ -11,6 +11,7 @@ in }; mir_2_15 = common { + broken = true; # doesn't build with glibc 2.44 version = "2.15.0"; pinned = true; hash = "sha256-c1+gxzLEtNCjR/mx76O5QElQ8+AO4WsfcG7Wy1+nC6E="; diff --git a/pkgs/stdenv/linux/stdenv-bootstrap-tools.nix b/pkgs/stdenv/linux/stdenv-bootstrap-tools.nix index 35d9dfc37dc7..05318e777eb5 100644 --- a/pkgs/stdenv/linux/stdenv-bootstrap-tools.nix +++ b/pkgs/stdenv/linux/stdenv-bootstrap-tools.nix @@ -135,6 +135,9 @@ stdenv.mkDerivation (finalAttrs: { cp -d ${bootGCC.lib}/lib/libstdc++.so* $out/lib cp -d ${bootGCC.out}/lib/libssp.a* $out/lib cp -d ${bootGCC.out}/lib/libssp_nonshared.a $out/lib + cp -d ${bootGCC.lib}/lib/libgcc_s_asneeded.so $out/lib + cp -d ${bootGCC.lib}/lib/libatomic_asneeded.so $out/lib + cp -d ${bootGCC.out}/lib/libatomic.a* $out/lib cp -rd ${bootGCC.out}/lib/gcc $out/lib chmod -R u+w $out/lib rm -f $out/lib/gcc/*/*/include*/linux @@ -156,15 +159,6 @@ stdenv.mkDerivation (finalAttrs: { cp -d ${mpfr.out}/lib/libmpfr*.so* $out/lib cp -d ${libmpc.out}/lib/libmpc*.so* $out/lib cp -d ${zlib.out}/lib/libz.so* $out/lib - - '' - + lib.optionalString (stdenv.hostPlatform.isRiscV) '' - # libatomic is required on RiscV platform for C/C++ atomics and pthread - # even though they may be translated into native instructions. - cp -d ${bootGCC.out}/lib/libatomic.a* $out/lib - - '' - + '' cp -d ${bzip2.out}/lib/libbz2.so* $out/lib # Copy binutils. diff --git a/pkgs/tools/package-management/nix/modular/src/libstore/package.nix b/pkgs/tools/package-management/nix/modular/src/libstore/package.nix index 80f95ea3981d..e506383c2a09 100644 --- a/pkgs/tools/package-management/nix/modular/src/libstore/package.nix +++ b/pkgs/tools/package-management/nix/modular/src/libstore/package.nix @@ -73,6 +73,9 @@ mkMesonLibrary (finalAttrs: { nlohmann_json ]; + # Don't use the default name "build": that conflicts with an existing directory. + mesonBuildDir = "meson-build-dir"; + mesonFlags = [ (lib.mesonEnable "seccomp-sandboxing" stdenv.hostPlatform.isLinux) (lib.mesonBool "embedded-sandbox-shell" embeddedSandboxShell) diff --git a/pkgs/tools/security/gnupg/24.nix b/pkgs/tools/security/gnupg/24.nix index cdfbae4d9966..6625b8278484 100644 --- a/pkgs/tools/security/gnupg/24.nix +++ b/pkgs/tools/security/gnupg/24.nix @@ -90,8 +90,8 @@ stdenv.mkDerivation (finalAttrs: { freepgPatches = fetchFromGitLab { owner = "freepg"; repo = "gnupg"; - tag = "source-2.4.9-freepg"; - hash = "sha256-wF+iR0OgnU8VI90NlFOXtN5aCRC0YY/X7sPiDXjJm5M="; + tag = "source-2.4.9-freepg-1"; + hash = "sha256-hoSuIrq7Epco1LLlc77tGr/YZdp2w04Eq0rGbBCurWU="; }; patches = [ @@ -132,6 +132,15 @@ stdenv.mkDerivation (finalAttrs: { "0033-Support-large-RSA-keygen-in-non-batch-mode.patch" "0034-gpg-Verify-Text-mode-Signatures-over-binary-Literal-.patch" "0039-gpg-Do-not-use-a-default-when-asking-for-another-out.patch" + "0040-Add-missing-test-files-to-EXTRA_DIST.patch" + "0045-gpg-Fix-edge-case-in-refresh-keys.patch" + "0046-gpgsm-Require-a-minimum-tag-length-for-GCM-decryptio.patch" + "0047-gpg-Fix-handling-with-no-CRC-armor.patch" + "0048-gpg-Fix-armored-input-parsing.patch" + "0049-gpg-Fix-armor-parsing-when-no-CRC-is-found.patch" + "0050-tpm-Fix-possible-buffer-overflow-in-PKDECRYPT.patch" + "0051-agent-Fix-the-regression-in-pkdecrypt-with-TPM-RSA.patch" + "0052-dirmngr-Fix-a-call-of-calloc.patch" ]; postPatch = diff --git a/pkgs/top-level/aliases.nix b/pkgs/top-level/aliases.nix index da334bcb1dda..394caf7b563f 100644 --- a/pkgs/top-level/aliases.nix +++ b/pkgs/top-level/aliases.nix @@ -641,6 +641,7 @@ mapAliases { csslint = throw "'csslint' has been removed as upstream considers it abandoned."; # Added 2025-11-07 cstore_fdw = throw "'cstore_fdw' has been removed. Use 'postgresqlPackages.cstore_fdw' instead."; # Added 2025-07-19 ctpp2 = throw "'ctpp2' has been removed due to lack of maintenance."; # Added 2025-12-31 + ctx = throw "'ctx' was unmaintained and not updated for three years"; # Added 2026-09-08 cudaPackages_11 = throw "CUDA 11 has been removed from Nixpkgs, as it is unmaintained upstream and depends on unsupported compilers"; # Added 2025-08-08 cudaPackages_11_0 = throw "CUDA 11.0 has been removed from Nixpkgs, as it is unmaintained upstream and depends on unsupported compilers"; # Added 2025-08-08 cudaPackages_11_1 = throw "CUDA 11.1 has been removed from Nixpkgs, as it is unmaintained upstream and depends on unsupported compilers"; # Added 2025-08-08 @@ -724,6 +725,7 @@ mapAliases { dotnetfx40 = throw "'dotnetfx40' has been removed because it was unmaintained in Nixpkgs"; # Added 2026-01-27 dotty = throw "'dotty' has been renamed to/replaced by 'scala_3'"; # Converted to throw 2025-10-27 dovecot_fts_xapian = throw "'dovecot_fts_xapian' has been removed because it was unmaintained in Nixpkgs. Consider using dovecot-fts-flatcurve instead"; # Added 2025-08-16 + dragmap = throw "'dragmap' doesn't build with latest glibc anymore and upstream repo is archived"; # Added 2026-09-03 drone-runner-exec = throw "'drone-runner-exec' has been removed as it was deprecated and archived upstream."; # Added 2026-07-20 dsd = throw "dsd has been removed, as it was broken and lack of upstream maintenance"; # Added 2025-08-25 dtv-scan-tables_linuxtv = throw "'dtv-scan-tables_linuxtv' has been renamed to/replaced by 'dtv-scan-tables'"; # Converted to throw 2025-10-27 @@ -1009,6 +1011,7 @@ mapAliases { glew-egl = throw "'glew-egl' has been renamed to/replaced by 'glew'"; # Converted to throw 2025-10-27 glfw-wayland = throw "'glfw-wayland' has been renamed to/replaced by 'glfw'"; # Converted to throw 2025-10-27 glfw-wayland-minecraft = throw "'glfw-wayland-minecraft' has been renamed to/replaced by 'glfw3-minecraft'"; # Converted to throw 2025-10-27 + glibmm = throw "'glibmm' attribute has been removed from nixpkgs. Use a 'glibmm_*' attribute with an explicit ABI version instead."; # Added 2026-09-04 globalprotect-openconnect = throw "'globalprotect-openconnect' was removed because it was unmaintained in Nixpkgs and needed upgrading to the Tauri rewrite, as the old version depends on the removed Qt 5 WebEngine"; # Added 2026-04-26 glom = throw "'glom' has been removed as it was archived upstream and depended on libsoup 2.4"; # Added 2026-06-07 glxinfo = throw "'glxinfo' has been renamed to/replaced by 'mesa-demos'"; # Converted to throw 2025-10-27 @@ -1337,6 +1340,7 @@ mapAliases { libayatana-indicator-gtk3 = throw "'libayatana-indicator-gtk3' has been renamed to/replaced by 'libayatana-indicator'"; # Converted to throw 2025-10-27 libbaseencode = throw "'libbaseencode' has been removed because it was deprecated and archived upstream. Consider using 'libcotp' instead"; # Added 2026-01-15 libbencodetools = throw "'libbencodetools' has been renamed to/replaced by 'bencodetools'"; # Converted to throw 2025-10-27 + libbpf_0 = throw "'libbpf_0' has been removed since it's EOL for four years"; # Added 2026-09-03 libbpf_1 = throw "'libbpf_1' has been renamed to/replaced by 'libbpf'"; # Converted to throw 2025-10-27 libbson = throw "'libbson' has been renamed to/replaced by 'mongoc'"; # Converted to throw 2025-10-27 libcanberra-gtk2 = throw "'libcanberra-gtk2' has been removed as it depended on the deprecated GTK 2 engine. Consider using 'libcanberra-gtk3' instead."; # Added 2026-08-10 @@ -1416,6 +1420,8 @@ mapAliases { librewolf-wayland = throw "'librewolf-wayland' has been renamed to/replaced by 'librewolf'"; # Converted to throw 2025-10-27 librtlsdr = throw "'librtlsdr' has been renamed to/replaced by 'rtl-sdr'"; # Converted to throw 2025-10-27 libsForQt515 = throw "'libsForQt515' has been renamed to/replaced by 'libsForQt5'"; # Converted to throw 2025-10-27 + libsigcxx30 = throw "'libsigcxx30' has been renamed to 'libsigcxx_3_0'"; # Added 2026-09-05 + libsigcxx = throw "'libsigcxx' attribute has been removed from nixpkgs. Use a 'libsigcxx_*' attribute with an explicit ABI version instead."; # Added 2026-09-05 libSM = libsm; # Added 2026-02-04 libsmartcols = warnAlias "'util-linux' should be used instead of 'libsmartcols'" util-linux; # Added 2025-09-03 libsoup = throw "'libsoup' has been renamed to/replaced by 'libsoup_2_4'"; # Converted to throw 2025-10-27 @@ -1835,6 +1841,7 @@ mapAliases { nextcloud32Packages = throw "Nextcloud 32 is EOL!"; # Added 2026-09-19 nfstrace = throw "nfstrace has been removed, as it was broken"; # Added 2025-08-25 nginxQuic = throw "'nginxQuic' has been removed. QUIC support is now available in the default nginx builds."; + ngn-k = throw "'ngn-k' doesn't build with glibc 2.44 and upstream claims that the implementation is no longer supported"; # Added 2026-09-03 ngrid = throw "'ngrid' has been removed as it has been unmaintained upstream and broken"; # Added 2025-11-15 nightfox-gtk-theme = throw "'nightfox-gtk-theme' has been removed because it depended on 'gtk-engine-murrine', which was removed because it was unmaintained upstream and depended on GTK 2."; # Added 2026-07-22 nim1 = throw "'nim1' has reached EOL, please use 'nim'"; # Added 2026-03-06 diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 16da8d14a411..e6823acab098 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -3183,7 +3183,7 @@ with pkgs; gerbilPackages-unstable = pkgs.gerbil-support.gerbilPackages-unstable; # NB: don't recurseIntoAttrs for (unstable!) libraries glow-lang = pkgs.gerbilPackages-unstable.glow-lang; - default-gcc-version = 15; + default-gcc-version = 16; gcc = pkgs.${"gcc${toString default-gcc-version}"}; gccFun = callPackage ../development/compilers/gcc; gcc-unwrapped = gcc.cc; @@ -4069,12 +4069,14 @@ with pkgs; ]; }; - swiftPackages = recurseIntoAttrs (callPackage ../development/compilers/swift { }); + swiftPackages = recurseIntoAttrs (callPackage ./swift-packages.nix { }); inherit (swiftPackages) - swift - swiftpm + fetchSwiftPMDeps sourcekit-lsp + swift + swift-corelibs-libdispatch swift-format + swiftpm swiftpm2nix ; @@ -4882,7 +4884,6 @@ with pkgs; }; libbpf = callPackage ../os-specific/linux/libbpf { }; - libbpf_0 = callPackage ../os-specific/linux/libbpf/0.x.nix { }; bundlewrap = with python3.pkgs; toPythonApplication bundlewrap; @@ -6009,9 +6010,7 @@ with pkgs; libprom ; - libsigcxx = callPackage ../development/libraries/libsigcxx { }; - - libsigcxx30 = callPackage ../development/libraries/libsigcxx/3.0.nix { }; + libsigcxx_2_0 = callPackage ../by-name/li/libsigcxx_3_0/2.0.nix { }; libtorrent-rasterbar = libtorrent-rasterbar-2_0_x; @@ -6294,7 +6293,7 @@ with pkgs; libressl_4_3 ; - openssl = openssl_3_6; + openssl = openssl_3_5; openssl_oqs = openssl.override { providers = [ @@ -6738,9 +6737,10 @@ with pkgs; ### DEVELOPMENT / LIBRARIES / DARWIN SDKS - apple-sdk_14 = callPackage ../by-name/ap/apple-sdk/package.nix { darwinSdkMajorVersion = "14"; }; - apple-sdk_15 = callPackage ../by-name/ap/apple-sdk/package.nix { darwinSdkMajorVersion = "15"; }; - apple-sdk_26 = callPackage ../by-name/ap/apple-sdk/package.nix { darwinSdkMajorVersion = "26"; }; + apple-sdk_14 = apple-sdk.override { darwinSdkMajorVersion = "14"; }; + apple-sdk_15 = apple-sdk.override { darwinSdkMajorVersion = "15"; }; + apple-sdk_26 = apple-sdk.override { darwinSdkMajorVersion = "26"; }; + apple-sdk_27 = apple-sdk.override { darwinSdkMajorVersion = "27"; }; darwinMinVersionHook = deploymentTarget: @@ -10765,8 +10765,6 @@ with pkgs; sieveshell = with python3.pkgs; toPythonApplication managesieve; - swift-corelibs-libdispatch = swiftPackages.Dispatch; - duden = python3Packages.toPythonApplication python3Packages.duden; yaziPlugins = recurseIntoAttrs (callPackage ../by-name/ya/yazi/plugins { }); diff --git a/pkgs/top-level/linux-kernels.nix b/pkgs/top-level/linux-kernels.nix index d3fa965d9516..3baabf4a14b5 100644 --- a/pkgs/top-level/linux-kernels.nix +++ b/pkgs/top-level/linux-kernels.nix @@ -65,6 +65,7 @@ in kernelPatches = [ kernelPatches.bridge_stp_helper kernelPatches.request_key_helper + kernelPatches.libbpf_C23_compat ]; }; diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index efd3380a9fff..563390293462 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -2096,10 +2096,10 @@ with self; AuthenSASL = buildPerlPackage { pname = "Authen-SASL"; - version = "2.1900"; + version = "2.2100"; src = fetchurl { - url = "mirror://cpan/authors/id/E/EH/EHUELS/Authen-SASL-2.1900.tar.gz"; - hash = "sha256-vjUzpokbLmdxULR5waDUvxHIu+6+0+e466NAU+k5I7A="; + url = "mirror://cpan/authors/id/E/EH/EHUELS/Authen-SASL-2.2100.tar.gz"; + hash = "sha256-Tw8QCu7TS1KXepS335c+fwuPktFnsJ8rJJurgehZDlc="; }; propagatedBuildInputs = [ CryptURandom diff --git a/pkgs/top-level/swift-packages.nix b/pkgs/top-level/swift-packages.nix new file mode 100644 index 000000000000..5f3bab8c48ab --- /dev/null +++ b/pkgs/top-level/swift-packages.nix @@ -0,0 +1,128 @@ +let + autoCalledPackages = import ./by-name-overlay.nix ../development/compilers/swift/by-name; + + swift_sources_6_2 = builtins.fromJSON ( + builtins.readFile ../development/compilers/swift/sources-6.2.json + ); + + mkBootstrapSwiftPackages = + { + lib, + bootstrapStage, + buildSwiftPackages, + swiftPackages, + swift_release ? null, + swift_sources ? null, + }: + swiftPackages.overrideScope ( + final: prev: + { + inherit bootstrapStage buildSwiftPackages; + swift = prev.swift.override ( + { + swift-corelibs-libdispatch = null; + swift-foundation = null; + swift-testing = null; + enableRepl = false; + } + # Swift Driver is required when building the compiler’s Swift Syntax in the final toolchain. + # Otherwise, symbols are stripped from it that are needed to build Swift Testing. + // lib.optionalAttrs (bootstrapStage == 0) { + swift-driver = null; + } + ); + } + // lib.optionalAttrs (bootstrapStage != 2) { + stdlib = null; # Have the bootstrap compiler use its own build of the stdlib. + swift-driver = prev.swift-driver.overrideAttrs (old: { + pname = "early-${old.pname}"; + }); + } + // lib.optionalAttrs (swift_release != null) { inherit swift_release; } + // lib.optionalAttrs (swift_sources != null) { inherit swift_sources; } + ); +in + +{ + lib, + config, + clangStdenv, + generateSplicesForMkScope, + llvmPackages, + makeScopeWithSplicing', + stdenvNoCC, + swiftPackages, + otherSplices ? generateSplicesForMkScope "swiftPackages", +}: + +let + # Swift requires three bootstrap stages: + # - Stage 0 builds a minimal Swift compiler using only C++. + # - Stage 1 builds a Swift compiler using the stage 0 Swift compiler. Features needed to build macros are enabled. + # - Stage 2 builds a full Swift compiler and stdlib using the stage 1 compiler. + bootstrapStage0SwiftPackages = mkBootstrapSwiftPackages { + inherit lib swiftPackages; + bootstrapStage = 0; + buildSwiftPackages = swiftPackages.overrideScope (_: _: { swift = null; }); + }; + + bootstrapStage1SwiftPackages = mkBootstrapSwiftPackages { + inherit lib swiftPackages; + bootstrapStage = 1; + buildSwiftPackages = bootstrapStage0SwiftPackages; + }; +in + +makeScopeWithSplicing' { + inherit otherSplices; + extra = + self: + let + llvm_libtool = stdenvNoCC.mkDerivation { + pname = "libtool"; + version = lib.getVersion llvmPackages.llvm; + + buildCommand = '' + mkdir -p "$out/bin" + ln -s ${lib.getExe' llvmPackages.llvm "llvm-libtool-darwin"} "$out/bin/libtool" + ''; + }; + in + { + bootstrapStage = 2; + + buildSwiftPackages = bootstrapStage1SwiftPackages; + + inherit llvm_libtool; + + llvmPackages_upstream = llvmPackages; + + swift-minimal = self.swift.override { + swift-corelibs-libdispatch = null; + swift-driver = null; + swift-foundation = null; + swift-testing = null; + enableRepl = false; + }; + + swift_sources = swift_sources_6_2; + }; + f = lib.extends autoCalledPackages ( + self: + { + stdenv = clangStdenv; + swift_release = "6.2.4"; + } + // lib.optionalAttrs config.allowAliases { + # Compatibility aliases for the old Swift packaging. + swift-unwrapped = lib.warnOnInstantiate "Swift is no longer wrapped. Use `swift` directly." self.swift; + swiftNoSwiftDriver = + lib.warnOnInstantiate + "swiftNoSwiftDriver is an alias. Override `swift` and set `swift-driver` to `null` instead." + (self.swift.override { swift-driver = null; }); + Dispatch = lib.warnOnInstantiate "Dispatch has been renamed to swift-corelibs-libdispatch. It is also now included in the default Swift SDK and no longer needs referenced as a separate package." self.swift-corelibs-libdispatch; + Foundation = lib.warnOnInstantiate "Foundation has been renamed to swift-corelibs-foundation. It is also now included in the default Swift SDK and no longer needs referenced as a separate package." self.swift-corelibs-foundation; + XCTest = lib.warnOnInstantiate "XCTest has been renamed to swift-corelibs-xctest. It is also now included in the default Swift SDK and no longer needs referenced as a separate package." self.swift-corelibs-xctest; + } + ); +}