From 10a4220c8ac24529241c891f2190edc0b69946e2 Mon Sep 17 00:00:00 2001 From: Amaan Qureshi Date: Thu, 12 Mar 2026 00:26:05 -0400 Subject: [PATCH 001/423] spandsp: fix dead source URL, add mirror --- pkgs/development/libraries/spandsp/common.nix | 2 +- pkgs/development/libraries/spandsp/default.nix | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/libraries/spandsp/common.nix b/pkgs/development/libraries/spandsp/common.nix index 1aacb0f1123f..3c320cedd9dd 100644 --- a/pkgs/development/libraries/spandsp/common.nix +++ b/pkgs/development/libraries/spandsp/common.nix @@ -220,6 +220,6 @@ stdenv.mkDerivation (finalAttrs: { maintainers = with lib.maintainers; [ misuzu ]; teams = [ lib.teams.ngi ]; license = lib.licenses.gpl2; - downloadPage = "http://www.soft-switch.org/downloads/spandsp/"; + downloadPage = "https://github.com/freeswitch/spandsp"; }; }) diff --git a/pkgs/development/libraries/spandsp/default.nix b/pkgs/development/libraries/spandsp/default.nix index 0a06b112e4c2..df1b5639bc47 100644 --- a/pkgs/development/libraries/spandsp/default.nix +++ b/pkgs/development/libraries/spandsp/default.nix @@ -7,7 +7,7 @@ (callPackage ./common.nix { }) rec { version = "0.0.6"; src = fetchurl { - url = "https://www.soft-switch.org/downloads/spandsp/spandsp-${version}.tar.gz"; + url = "https://src.fedoraproject.org/lookaside/pkgs/spandsp/spandsp-${version}.tar.gz/897d839516a6d4edb20397d4757a7ca3/spandsp-${version}.tar.gz"; sha256 = "0rclrkyspzk575v8fslzjpgp4y2s4x7xk3r55ycvpi4agv33l1fc"; }; patches = [ From 7dbd6409f86e98c6aec7479231b61797705319c5 Mon Sep 17 00:00:00 2001 From: Amaan Qureshi Date: Thu, 12 Mar 2026 00:26:40 -0400 Subject: [PATCH 002/423] spandsp: fix bit_operations_tests UB on ppc64be --- pkgs/development/libraries/spandsp/common.nix | 3 ++ .../spandsp/fix-bit-operations-ub.patch | 53 +++++++++++++++++++ 2 files changed, 56 insertions(+) create mode 100644 pkgs/development/libraries/spandsp/fix-bit-operations-ub.patch diff --git a/pkgs/development/libraries/spandsp/common.nix b/pkgs/development/libraries/spandsp/common.nix index 3c320cedd9dd..c564d3da979e 100644 --- a/pkgs/development/libraries/spandsp/common.nix +++ b/pkgs/development/libraries/spandsp/common.nix @@ -40,6 +40,9 @@ stdenv.mkDerivation (finalAttrs: { # https://github.com/freeswitch/spandsp/pull/111 ./Fix-tests-pcap_parse-build-on-musl.patch + + # https://github.com/freeswitch/spandsp/pull/116 + ./fix-bit-operations-ub.patch ] ++ patches; diff --git a/pkgs/development/libraries/spandsp/fix-bit-operations-ub.patch b/pkgs/development/libraries/spandsp/fix-bit-operations-ub.patch new file mode 100644 index 000000000000..24562d6135d8 --- /dev/null +++ b/pkgs/development/libraries/spandsp/fix-bit-operations-ub.patch @@ -0,0 +1,53 @@ +From 6366823f4c6a1641543a0f3859afcafccf2e47af Mon Sep 17 00:00:00 2001 +From: Amaan Qureshi +Date: Wed, 11 Mar 2026 23:34:26 -0400 +Subject: [PATCH] tests: fix undefined behavior in `bit_operations_tests` + +The `most_significant_one32`/`least_significant_one32` test loop +started at `i = -1`, which produces a shift of `1U << -1`. This is +undefined behavior per the C standard, as the shift count must be in +`[0, bit_width)`. On x86 this happened to produce `0x80000000` due to +masking the shift count to 5 bits, but on ppc64be it produces `0`, +causing a spurious test failure. + +This commit starts the loop at `i = 0` instead. Testing the zero-input +case is not meaningful here since `most_significant_one32(0)` itself +invokes UB internally (`1 << top_bit(0)` where `top_bit` returns `-1`). +I've also fixed the printf format strings to use `1U` instead of `1` to +avoid signed overflow when `i = 31`. +--- + tests/bit_operations_tests.c | 6 +++--- + 1 file changed, 3 insertions(+), 3 deletions(-) + +diff --git a/tests/bit_operations_tests.c b/tests/bit_operations_tests.c +index 53cd997..53f7892 100644 +--- a/tests/bit_operations_tests.c ++++ b/tests/bit_operations_tests.c +@@ -257,22 +257,22 @@ int main(int argc, char *argv[]) + printf("Test failed: parity 8 - %x %x %x\n", i, ax, bx); + exit(2); + } + } + +- for (i = -1; i < 32; i++) ++ for (i = 0; i < 32; i++) + { + ax32 = most_significant_one32(1 << i); + if (ax32 != (1 << i)) + { +- printf("Test failed: most significant one 32 - %x %" PRIx32 " %x\n", i, ax32, (1 << i)); ++ printf("Test failed: most significant one 32 - %x %" PRIx32 " %x\n", i, ax32, (1U << i)); + exit(2); + } + ax32 = least_significant_one32(1 << i); + if (ax32 != (1 << i)) + { +- printf("Test failed: least significant one 32 - %x %" PRIx32 " %x\n", i, ax32, (1 << i)); ++ printf("Test failed: least significant one 32 - %x %" PRIx32 " %x\n", i, ax32, (1U << i)); + exit(2); + } + } + + for (i = 0x80000000; i < 0x800FFFFF; i++) +-- +2.53.0 From c4d7c303d311fe6ec7615a43671ae718bac019aa Mon Sep 17 00:00:00 2001 From: Amaan Qureshi Date: Thu, 12 Mar 2026 04:09:40 -0400 Subject: [PATCH 003/423] spandsp: disable `lpc10_tests` on ppc64 The LPC-10 test checks decoded audio against a reference WAV generated on x86. On POWER, small float rounding differences in the encoder accumulate over hundreds of frames and eventually produce different output, even though the codec itself works correctly. --- pkgs/development/libraries/spandsp/common.nix | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/pkgs/development/libraries/spandsp/common.nix b/pkgs/development/libraries/spandsp/common.nix index c564d3da979e..8ceab5257191 100644 --- a/pkgs/development/libraries/spandsp/common.nix +++ b/pkgs/development/libraries/spandsp/common.nix @@ -176,6 +176,10 @@ stdenv.mkDerivation (finalAttrs: { # Seemingly runs forever, with tons of output "v22bis_tests" + ] + ++ lib.optionals stdenv.hostPlatform.isPower64 [ + # Output differs from x86-generated reference due to float precision + "lpc10_tests" ]; checkPhase = '' From 7edc8b40063af44802398912b0b6836d44ba3a6b Mon Sep 17 00:00:00 2001 From: SandaruKasa Date: Fri, 5 Jun 2026 06:20:05 +0300 Subject: [PATCH 004/423] dconf: add `man` output out: 104K -> 92K man: 0K -> 12K --- pkgs/by-name/dc/dconf/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/dc/dconf/package.nix b/pkgs/by-name/dc/dconf/package.nix index 73dd2a3fee42..dcef677247bd 100644 --- a/pkgs/by-name/dc/dconf/package.nix +++ b/pkgs/by-name/dc/dconf/package.nix @@ -33,6 +33,7 @@ stdenv.mkDerivation (finalAttrs: { "out" "lib" "dev" + "man" ] ++ lib.optional withDocs "devdoc"; From 69e163e571b7726e0bbf29bc383eeca6f8d23675 Mon Sep 17 00:00:00 2001 From: SandaruKasa Date: Thu, 11 Jun 2026 02:12:55 +0300 Subject: [PATCH 005/423] dconf: `strictDeps` & `__structuredAttrs` `nix store make-content-addressed` gives the same output before and after this change --- pkgs/by-name/dc/dconf/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/dc/dconf/package.nix b/pkgs/by-name/dc/dconf/package.nix index dcef677247bd..1396fe83303a 100644 --- a/pkgs/by-name/dc/dconf/package.nix +++ b/pkgs/by-name/dc/dconf/package.nix @@ -29,6 +29,9 @@ stdenv.mkDerivation (finalAttrs: { pname = "dconf"; version = "0.49.0"; + __structuredAttrs = true; + strictDeps = true; + outputs = [ "out" "lib" From a734897cbe8f60b361c7b376e749a3727adcd70b Mon Sep 17 00:00:00 2001 From: Hythera <87016780+Hythera@users.noreply.github.com> Date: Fri, 12 Jun 2026 20:25:43 +0200 Subject: [PATCH 006/423] libqrtr-glib: 1.2.2 -> 1.4.0 diff: https://gitlab.freedesktop.org/mobile-broadband/libqrtr-glib/-/compare/1.2.2...1.4.0 --- pkgs/by-name/li/libqrtr-glib/package.nix | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/li/libqrtr-glib/package.nix b/pkgs/by-name/li/libqrtr-glib/package.nix index 16f5a7cb6301..0f8857b2d204 100644 --- a/pkgs/by-name/li/libqrtr-glib/package.nix +++ b/pkgs/by-name/li/libqrtr-glib/package.nix @@ -15,12 +15,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "libqrtr-glib"; - version = "1.2.2"; + version = "1.4.0"; outputs = [ "out" "dev" - "devdoc" ]; src = fetchFromGitLab { @@ -28,7 +27,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "mobile-broadband"; repo = "libqrtr-glib"; rev = finalAttrs.version; - sha256 = "kHLrOXN6wgBrHqipo2KfAM5YejS0/bp7ziBSpt0s1i0="; + sha256 = "sha256-1zsGwZogsI0QvIvvQy5FhcRSq2Q75/J724OcM+K/QBo="; }; strictDeps = true; From 9c06a6653d95e38ad3cd5bbecc7f0891963e137e Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 12 Jul 2026 06:27:58 +0000 Subject: [PATCH 007/423] memcached: 1.6.42 -> 1.6.45 --- pkgs/by-name/me/memcached/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/me/memcached/package.nix b/pkgs/by-name/me/memcached/package.nix index e0b63e959ece..60dbfce191c3 100644 --- a/pkgs/by-name/me/memcached/package.nix +++ b/pkgs/by-name/me/memcached/package.nix @@ -8,12 +8,12 @@ }: stdenv.mkDerivation (finalAttrs: { - version = "1.6.42"; + version = "1.6.45"; pname = "memcached"; src = fetchurl { url = "https://memcached.org/files/memcached-${finalAttrs.version}.tar.gz"; - sha256 = "sha256-UPCLh51PnTbeqdkF6eqt4Vxwjjjbfppz/CHci0U5Xec="; + sha256 = "sha256-02LGTm2NUocVNQHqv3yFtKdhQy+/U/XXsIXQuxZTwd0="; }; configureFlags = [ From 54c1571722d897a27a63907f2a28ab5bcdf2cab7 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 15 Jul 2026 04:27:21 +0000 Subject: [PATCH 008/423] nghttp3: 1.16.0 -> 1.17.0 --- pkgs/by-name/ng/nghttp3/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ng/nghttp3/package.nix b/pkgs/by-name/ng/nghttp3/package.nix index 852ebfce6194..138fd0a06113 100644 --- a/pkgs/by-name/ng/nghttp3/package.nix +++ b/pkgs/by-name/ng/nghttp3/package.nix @@ -8,11 +8,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "nghttp3"; - version = "1.16.0"; + version = "1.17.0"; src = fetchurl { url = "https://github.com/ngtcp2/nghttp3/releases/download/v${finalAttrs.version}/nghttp3-${finalAttrs.version}.tar.bz2"; - hash = "sha256-IsBpidVL0mbUpx817vGS1JuJBlWfFqQfO4gssCNhdGM="; + hash = "sha256-KobUa0Kx37XGLk/sO/5ugO5JVxXhiAqEaFdyiBDJgm0="; }; outputs = [ From 77e36bcb9d326eb05c9d25a2d8cdd9580450c5f9 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 15 Jul 2026 17:47:14 +0000 Subject: [PATCH 009/423] thrift: 0.22.0 -> 0.24.0 --- pkgs/by-name/th/thrift/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/th/thrift/package.nix b/pkgs/by-name/th/thrift/package.nix index 319c2413d96a..187720580203 100644 --- a/pkgs/by-name/th/thrift/package.nix +++ b/pkgs/by-name/th/thrift/package.nix @@ -17,13 +17,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "thrift"; - version = "0.22.0"; + version = "0.24.0"; src = fetchFromGitHub { owner = "apache"; repo = "thrift"; tag = "v${finalAttrs.version}"; - hash = "sha256-gGAO+D0A/hEoHMm6OvRBc1Mks9y52kfd0q/Sg96pdW4="; + hash = "sha256-+o/2exHsunjQBGjXrNQ1pQ5TKV53++qCxIMeVyOh5QY="; }; # Workaround to make the Python wrapper not drop this package: From a090aae6c103b8ab8d14c51d2fc8d79da27f97fb Mon Sep 17 00:00:00 2001 From: SandaruKasa Date: Sat, 18 Jul 2026 20:45:42 +0300 Subject: [PATCH 010/423] libaom: 3.12.1 -> 3.14.1 Changelog: https://aomedia.googlesource.com/aom/+/refs/tags/v3.14.1/CHANGELOG --- pkgs/by-name/li/libaom/outputs.patch | 25 +++++++++++++------------ pkgs/by-name/li/libaom/package.nix | 4 ++-- 2 files changed, 15 insertions(+), 14 deletions(-) diff --git a/pkgs/by-name/li/libaom/outputs.patch b/pkgs/by-name/li/libaom/outputs.patch index 7b34338403f2..d7a6cafba539 100644 --- a/pkgs/by-name/li/libaom/outputs.patch +++ b/pkgs/by-name/li/libaom/outputs.patch @@ -1,8 +1,8 @@ -diff --git a/build/cmake/aom_install.cmake b/build/cmake/aom_install.cmake -index 0bd2bf035..5cf5acea8 100644 ---- a/build/cmake/aom_install.cmake -+++ b/build/cmake/aom_install.cmake -@@ -42,8 +42,8 @@ macro(setup_aom_install_targets) +diff --git a/cmake/aom_install.cmake b/cmake/aom_install.cmake +index a8f6d64361..c5223462ed 100644 +--- a/cmake/aom_install.cmake ++++ b/cmake/aom_install.cmake +@@ -45,8 +45,8 @@ macro(setup_aom_install_targets) -DAOM_ROOT=${AOM_ROOT} -DCMAKE_INSTALL_PREFIX=${CMAKE_INSTALL_PREFIX} -DCMAKE_INSTALL_BINDIR=${CMAKE_INSTALL_BINDIR} @@ -11,9 +11,9 @@ index 0bd2bf035..5cf5acea8 100644 + -DCMAKE_INSTALL_FULL_INCLUDEDIR=${CMAKE_INSTALL_FULL_INCLUDEDIR} + -DCMAKE_INSTALL_FULL_LIBDIR=${CMAKE_INSTALL_FULL_LIBDIR} -DCMAKE_PROJECT_NAME=${CMAKE_PROJECT_NAME} + -DCMAKE_THREAD_LIBS_INIT=${CMAKE_THREAD_LIBS_INIT} -DCONFIG_MULTITHREAD=${CONFIG_MULTITHREAD} - -DCONFIG_TUNE_VMAF=${CONFIG_TUNE_VMAF} -@@ -84,12 +84,12 @@ macro(setup_aom_install_targets) +@@ -115,13 +115,13 @@ macro(setup_aom_install_targets) # Setup the install rules. install() will automatically prepend # CMAKE_INSTALL_PREFIX to relative paths install(FILES ${AOM_INSTALL_INCS} @@ -23,6 +23,7 @@ index 0bd2bf035..5cf5acea8 100644 - DESTINATION "${CMAKE_INSTALL_LIBDIR}/pkgconfig") + DESTINATION "${CMAKE_INSTALL_FULL_LIBDIR}/pkgconfig") install(TARGETS ${AOM_INSTALL_LIBS};${AOM_INSTALL_BINS} + EXPORT "${AOM_TARGETS_EXPORT_NAME}" - RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}" - LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" - ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}") @@ -31,12 +32,12 @@ index 0bd2bf035..5cf5acea8 100644 + ARCHIVE DESTINATION "${CMAKE_INSTALL_FULL_LIBDIR}") endif() endmacro() -diff --git a/build/cmake/pkg_config.cmake b/build/cmake/pkg_config.cmake -index e8fff2e77..b8a73aad4 100644 ---- a/build/cmake/pkg_config.cmake -+++ b/build/cmake/pkg_config.cmake +diff --git a/cmake/pkg_config.cmake b/cmake/pkg_config.cmake +index ad3cf77009..1b46040cd1 100644 +--- a/cmake/pkg_config.cmake ++++ b/cmake/pkg_config.cmake @@ -11,8 +11,8 @@ - cmake_minimum_required(VERSION 3.5) + cmake_minimum_required(VERSION 3.16) set(REQUIRED_ARGS "AOM_ROOT" "AOM_CONFIG_DIR" "CMAKE_INSTALL_PREFIX" - "CMAKE_INSTALL_BINDIR" "CMAKE_INSTALL_INCLUDEDIR" diff --git a/pkgs/by-name/li/libaom/package.nix b/pkgs/by-name/li/libaom/package.nix index c8296dd90fb8..739ac4320eaa 100644 --- a/pkgs/by-name/li/libaom/package.nix +++ b/pkgs/by-name/li/libaom/package.nix @@ -23,11 +23,11 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "libaom"; - version = "3.12.1"; + version = "3.14.1"; src = fetchzip { url = "https://aomedia.googlesource.com/aom/+archive/v${finalAttrs.version}.tar.gz"; - hash = "sha256-AAS6wfq4rZ4frm6+gwKoIS3+NVzPhhfW428WXJQ2tQ8="; + hash = "sha256-ddMrDkWV5jUbpPGKsMQl7s4r43205WbBtCEYtZNgwAM="; stripRoot = false; }; From c5898aaf4154cffe9fd936307c8c8b5911102ec5 Mon Sep 17 00:00:00 2001 From: SandaruKasa Date: Sat, 18 Jul 2026 20:50:26 +0300 Subject: [PATCH 011/423] libaom: strictDeps, __structuredAttrs --- pkgs/by-name/li/libaom/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/li/libaom/package.nix b/pkgs/by-name/li/libaom/package.nix index 739ac4320eaa..9dfe847d606a 100644 --- a/pkgs/by-name/li/libaom/package.nix +++ b/pkgs/by-name/li/libaom/package.nix @@ -96,6 +96,9 @@ stdenv.mkDerivation (finalAttrs: { ln -s $static $out ''; + __structuredAttrs = true; + strictDeps = true; + outputs = [ "out" "bin" From 5d03ccc350a44de5f97ffc5e560702809829f3d3 Mon Sep 17 00:00:00 2001 From: bitbloxhub <45184892+bitbloxhub@users.noreply.github.com> Date: Thu, 23 Jul 2026 00:35:41 +0000 Subject: [PATCH 012/423] gtk4: backport Wayland session cleanup null check --- pkgs/by-name/gt/gtk4/package.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkgs/by-name/gt/gtk4/package.nix b/pkgs/by-name/gt/gtk4/package.nix index 9b7807508a35..63e82f1fb982 100644 --- a/pkgs/by-name/gt/gtk4/package.nix +++ b/pkgs/by-name/gt/gtk4/package.nix @@ -101,6 +101,11 @@ stdenv.mkDerivation (finalAttrs: { url = "https://gitlab.gnome.org/GNOME/gtk/-/commit/10d43de8f4f942cb591ada3103474bd7213425f1.patch"; hash = "sha256-DJIL6M3XcsjBoMO77OxNi84d1DxAphAfot3N7Nq1QqQ="; }) + (fetchpatch { + name = "gtkapplication-wayland-null-check.patch"; + url = "https://gitlab.gnome.org/GNOME/gtk/-/commit/221cd8e1904f2ca35d89dff3c1068616c6ce588c.patch"; + hash = "sha256-SLMmWDZ2mLXW3/GJfFdoszthNg4Hd15yvZO2XOld4Uw="; + }) ]; depsBuildBuild = [ From 7eb51f62c763c580d4fdf70c01966099fda2bc40 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Sat, 25 Jul 2026 01:09:29 +0200 Subject: [PATCH 013/423] python3Packages.dirty-equals: fix tests The tests were not actually enabled with overrideAttrs instead of overridePythonAttrs. Enabling them exposed a failure. --- pkgs/development/python-modules/dirty-equals/default.nix | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/pkgs/development/python-modules/dirty-equals/default.nix b/pkgs/development/python-modules/dirty-equals/default.nix index 41281df75b36..ff085567ec7c 100644 --- a/pkgs/development/python-modules/dirty-equals/default.nix +++ b/pkgs/development/python-modules/dirty-equals/default.nix @@ -22,13 +22,19 @@ let hash = "sha256-JFKWrbMdxhvSBbjQ+S9HPW87CK+5ZZiXHg8Wltlv2YY="; }; + postPatch = '' + # Fix pytest.PytestRemovedIn10Warning: Passing a non-Collection iterable to parametrize is deprecated. + substituteInPlace tests/test_docs.py \ + --replace-fail "examples," "list(examples)," + ''; + build-system = [ hatchling ]; dependencies = [ pytz ]; doCheck = false; - passthru.tests.pytest = dirty-equals.overrideAttrs { doCheck = true; }; + passthru.tests.pytest = dirty-equals.overridePythonAttrs { doCheck = true; }; nativeCheckInputs = [ pydantic From ed5ca467b977ecd1133d3beae6699345fba82d5e Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Sat, 25 Jul 2026 01:10:19 +0200 Subject: [PATCH 014/423] python3Packages.dirty-equals: enable structuredAttrs, use finalAttrs --- .../python-modules/dirty-equals/default.nix | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/pkgs/development/python-modules/dirty-equals/default.nix b/pkgs/development/python-modules/dirty-equals/default.nix index ff085567ec7c..c1d5812ac9c2 100644 --- a/pkgs/development/python-modules/dirty-equals/default.nix +++ b/pkgs/development/python-modules/dirty-equals/default.nix @@ -10,7 +10,7 @@ }: let - dirty-equals = buildPythonPackage rec { + dirty-equals = buildPythonPackage (finalAttrs: { pname = "dirty-equals"; version = "0.11.0"; pyproject = true; @@ -18,7 +18,7 @@ let src = fetchFromGitHub { owner = "samuelcolvin"; repo = "dirty-equals"; - tag = "v${version}"; + tag = "v${finalAttrs.version}"; hash = "sha256-JFKWrbMdxhvSBbjQ+S9HPW87CK+5ZZiXHg8Wltlv2YY="; }; @@ -44,13 +44,15 @@ let pythonImportsCheck = [ "dirty_equals" ]; + __structuredAttrs = true; + meta = { description = "Module for doing dirty (but extremely useful) things with equals"; homepage = "https://github.com/samuelcolvin/dirty-equals"; - changelog = "https://github.com/samuelcolvin/dirty-equals/releases/tag/${src.tag}"; + changelog = "https://github.com/samuelcolvin/dirty-equals/releases/tag/${finalAttrs.src.tag}"; license = lib.licenses.mit; maintainers = with lib.maintainers; [ fab ]; }; - }; + }); in dirty-equals From d2cbb4ba810112c938f92645fa58d3fcd1d5ce18 Mon Sep 17 00:00:00 2001 From: Thomas Gerbet Date: Sun, 2 Aug 2026 16:58:01 +0200 Subject: [PATCH 015/423] makeBinaryWrapper: reject prefix/suffix with an empty path segment Preferred to reject explictly the value instead of silently sanitizing it. It's closer to what we do for the invalid env name and it will allow us to spot derivation that were impacted by the issue that has not yet been fixed. --- .../ma/makeBinaryWrapper/make-binary-wrapper.sh | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/pkgs/by-name/ma/makeBinaryWrapper/make-binary-wrapper.sh b/pkgs/by-name/ma/makeBinaryWrapper/make-binary-wrapper.sh index 232bc2b5c3cd..52933999922b 100644 --- a/pkgs/by-name/ma/makeBinaryWrapper/make-binary-wrapper.sh +++ b/pkgs/by-name/ma/makeBinaryWrapper/make-binary-wrapper.sh @@ -263,6 +263,7 @@ setEnvPrefix() { val=$(escapeStringLiteral "$3") printf '%s' "set_env_prefix(\"$env\", \"$sep\", \"$val\");" assertValidEnvName "$1" + assertNoEmptySegment "--prefix" "$1" "$2" "$3" } # suffix ENV SEP VAL @@ -273,6 +274,7 @@ setEnvSuffix() { val=$(escapeStringLiteral "$3") printf '%s' "set_env_suffix(\"$env\", \"$sep\", \"$val\");" assertValidEnvName "$1" + assertNoEmptySegment "--suffix" "$1" "$2" "$3" } # setEnv KEY VALUE @@ -325,6 +327,14 @@ assertValidEnvName() { esac } +assertNoEmptySegment() { + local flag="$1" env="$2" sep="$3" val="$4" + [ -n "$sep" ] || return 0 + if [[ "$sep$val$sep" == *"$sep$sep"* ]]; then + printf '\n%s\n' "#error $flag $env would introduce an empty PATH-like segment (empty, or a leading/trailing/doubled \`$sep\`). This is interpreted as \"search the current directory\" by shells, execvp() and the dynamic linker, see https://github.com/NixOS/nixpkgs/security/advisories/GHSA-p7v3-pr2c-8584. Guard the value with e.g. lib.optionalString (list != [])." + fi +} + setSepSurroundCheck() { printf '%s' "\ int is_surrounded_by_sep(char *env, char *ptr, unsigned long len, char *sep) { From 6d980c226487dabec0a6dbe795d13d17e99f6ec8 Mon Sep 17 00:00:00 2001 From: crumblingMizzle <77518303+crumblingMizzle@users.noreply.github.com> Date: Mon, 3 Aug 2026 18:33:25 -0400 Subject: [PATCH 016/423] swig: fix cross-compilation --- pkgs/by-name/sw/swig/package.nix | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/sw/swig/package.nix b/pkgs/by-name/sw/swig/package.nix index 7b7b7e01a8f3..8dc3f4af8125 100644 --- a/pkgs/by-name/sw/swig/package.nix +++ b/pkgs/by-name/sw/swig/package.nix @@ -20,13 +20,14 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-jsi83v9sg0n5kUfDACqdNAS2VuLSyxv+pe2LRcO4Khc="; }; + # It is necessary to pull in the target pcre2-config binary this way because including pcre2 in nativeBuildInputs can create linking failures with cross-compilation + env.PCRE2_CONFIG = "${pcre2.dev}/bin/pcre2-config"; strictDeps = true; nativeBuildInputs = [ autoconf automake libtool bison - pcre2 ]; buildInputs = [ pcre2 ]; From e59c1c0c42bd6f25c2b25e7c7430fba9f8883a32 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 11 Aug 2026 12:22:42 +0000 Subject: [PATCH 017/423] xdg-dbus-proxy: 0.1.7 -> 0.1.8 --- pkgs/by-name/xd/xdg-dbus-proxy/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/xd/xdg-dbus-proxy/package.nix b/pkgs/by-name/xd/xdg-dbus-proxy/package.nix index 098785d5556c..e580314238f5 100644 --- a/pkgs/by-name/xd/xdg-dbus-proxy/package.nix +++ b/pkgs/by-name/xd/xdg-dbus-proxy/package.nix @@ -14,11 +14,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "xdg-dbus-proxy"; - version = "0.1.7"; + version = "0.1.8"; src = fetchurl { url = "https://github.com/flatpak/xdg-dbus-proxy/releases/download/${finalAttrs.version}/xdg-dbus-proxy-${finalAttrs.version}.tar.xz"; - hash = "sha256-OtPSe6V04XisteTUOLo2rOJeNWT4mcNvMcVvgsetu+c="; + hash = "sha256-tmML0k+BYbDiVG0qy7AUo7Mkn1wNdfKoY63omLkDTT0="; }; nativeBuildInputs = [ From 0a9281fd8d8fab40d460932e3c201d390a481ee0 Mon Sep 17 00:00:00 2001 From: Aaron Jheng Date: Wed, 5 Aug 2026 10:21:44 +0800 Subject: [PATCH 018/423] lame: 3.100 -> 4.0 --- .../la/lame/export-hip-pinfo-symbols.patch | 18 ++ .../la/lame/fix-setlocale-without-iconv.patch | 18 ++ pkgs/by-name/la/lame/fix-utf8-id3-tag.patch | 156 ++++++++++++++++++ pkgs/by-name/la/lame/package.nix | 36 ++-- 4 files changed, 213 insertions(+), 15 deletions(-) create mode 100644 pkgs/by-name/la/lame/export-hip-pinfo-symbols.patch create mode 100644 pkgs/by-name/la/lame/fix-setlocale-without-iconv.patch create mode 100644 pkgs/by-name/la/lame/fix-utf8-id3-tag.patch diff --git a/pkgs/by-name/la/lame/export-hip-pinfo-symbols.patch b/pkgs/by-name/la/lame/export-hip-pinfo-symbols.patch new file mode 100644 index 000000000000..dad53822ee1a --- /dev/null +++ b/pkgs/by-name/la/lame/export-hip-pinfo-symbols.patch @@ -0,0 +1,18 @@ +Export hip_set_pinfo and hip_finish_pinfo. + +The frontend (get_audio.c) links against these symbols when built with +--enable-analyzer-hooks, but they were missing from the -export-symbols +list, so linking the lame binary failed. Fixed in upstream SVN trunk +after the 4.0 release. + +--- a/include/libmp3lame.sym ++++ b/include/libmp3lame.sym +@@ -188,6 +188,8 @@ hip_decode_exit + hip_set_errorf + hip_set_debugf + hip_set_msgf ++hip_set_pinfo ++hip_finish_pinfo + hip_decode + hip_decode_headers + hip_decode1 diff --git a/pkgs/by-name/la/lame/fix-setlocale-without-iconv.patch b/pkgs/by-name/la/lame/fix-setlocale-without-iconv.patch new file mode 100644 index 000000000000..dcdd1ecb7d6d --- /dev/null +++ b/pkgs/by-name/la/lame/fix-setlocale-without-iconv.patch @@ -0,0 +1,18 @@ +Guard setlocale() the same way as its header include. + +Upstream SVN r6590. parse.c includes only when both +HAVE_ICONV and HAVE_LANGINFO_H are defined, but the setlocale() call +was guarded on HAVE_LANGINFO_H alone, breaking the build on systems +that have langinfo.h but no working iconv (e.g. macOS). + +--- a/frontend/parse.c ++++ b/frontend/parse.c +@@ -1619,7 +1619,7 @@ + enum TextEncoding id3_tenc = TENC_LATIN1; + #endif + +-#ifdef HAVE_LANGINFO_H ++#if defined(HAVE_ICONV) && defined(HAVE_LANGINFO_H) + setlocale(LC_CTYPE, ""); + #endif + inPath[0] = '\0'; \ No newline at end of file diff --git a/pkgs/by-name/la/lame/fix-utf8-id3-tag.patch b/pkgs/by-name/la/lame/fix-utf8-id3-tag.patch new file mode 100644 index 000000000000..5b0b5db52caf --- /dev/null +++ b/pkgs/by-name/la/lame/fix-utf8-id3-tag.patch @@ -0,0 +1,156 @@ +frontend, libmp3lame: fix ID3v2 UTF-8 tag path (SF #524). + +Upstream SVN r6562. The ID3v2 tag writer routed both the UTF-8 and +UTF-16 command-line encodings through a single path typed for UTF-16. +For --id3v2-utf8 that mismatches the actual byte-oriented data and +reaches tag setters GCC 15 rejects as incompatible-pointer-types, +so LAME fails to build with GCC 15. + +Give each encoding its own path so the data and the setters it feeds +match. The test infrastructure changes are omitted as they do not +exist in the 4.0 release tarball. + +--- a/frontend/parse.c ++++ b/frontend/parse.c +@@ -402,41 +402,45 @@ + } + + #ifdef ID3TAGS_EXTENDED ++/* Set an ID3v2 tag field from UTF-16 data. The data pointer is genuinely ++ UTF-16 here, so the UTF-16 id3tag_* setters are used throughout. */ + static int +-set_id3v2tag(lame_global_flags* gfp, TextEncoding enc, int type, unsigned short const* str) ++set_id3v2tag_utf16(lame_global_flags* gfp, int type, unsigned short const* str) + { +- switch (enc) ++ switch (type) + { +- case TENC_UTF8: +- switch (type) +- { +- case 'a': return id3tag_set_textinfo_utf8(gfp, "TPE1", str); +- case 't': return id3tag_set_textinfo_utf8(gfp, "TIT2", str); +- case 'l': return id3tag_set_textinfo_utf8(gfp, "TALB", str); +- case 'g': return id3tag_set_textinfo_utf8(gfp, "TCON", str); +- case 'c': return id3tag_set_comment_ucs2(gfp, 0, 0, str); +- case 'n': return id3tag_set_textinfo_utf8(gfp, "TRCK", str); +- case 'y': return id3tag_set_textinfo_utf8(gfp, "TYER", str); +- case 'v': return id3tag_set_fieldvalue_ucs2(gfp, str); +- } +- ;; +- case TENC_UTF16: +- switch (type) +- { +- case 'a': return id3tag_set_textinfo_utf16(gfp, "TPE1", str); +- case 't': return id3tag_set_textinfo_utf16(gfp, "TIT2", str); +- case 'l': return id3tag_set_textinfo_utf16(gfp, "TALB", str); +- case 'g': return id3tag_set_textinfo_utf16(gfp, "TCON", str); +- case 'c': return id3tag_set_comment_utf16(gfp, 0, 0, str); +- case 'n': return id3tag_set_textinfo_utf16(gfp, "TRCK", str); +- case 'y': return id3tag_set_textinfo_utf16(gfp, "TYER", str); +- case 'v': return id3tag_set_fieldvalue_utf16(gfp, str); +- } +- ;; +- default: +- return -3; ++ case 'a': return id3tag_set_textinfo_utf16(gfp, "TPE1", str); ++ case 't': return id3tag_set_textinfo_utf16(gfp, "TIT2", str); ++ case 'l': return id3tag_set_textinfo_utf16(gfp, "TALB", str); ++ case 'g': return id3tag_set_textinfo_utf16(gfp, "TCON", str); ++ case 'c': return id3tag_set_comment_utf16(gfp, 0, 0, str); ++ case 'n': return id3tag_set_textinfo_utf16(gfp, "TRCK", str); ++ case 'y': return id3tag_set_textinfo_utf16(gfp, "TYER", str); ++ case 'v': return id3tag_set_fieldvalue_utf16(gfp, str); + } ++ return -3; + } ++ ++/* Set an ID3v2 tag field from UTF-8 data. The data pointer is a UTF-8 char ++ string (not UTF-16 as the old, mistyped single handler assumed), so the ++ UTF-8 id3tag_* setters are used - including id3tag_set_fieldvalue_utf8 for ++ 'v', which replaces the removed *_ucs2 calls the UTF-8 path used to make. */ ++static int ++set_id3v2tag_utf8(lame_global_flags* gfp, int type, char const* str) ++{ ++ switch (type) ++ { ++ case 'a': return id3tag_set_textinfo_utf8(gfp, "TPE1", str); ++ case 't': return id3tag_set_textinfo_utf8(gfp, "TIT2", str); ++ case 'l': return id3tag_set_textinfo_utf8(gfp, "TALB", str); ++ case 'g': return id3tag_set_textinfo_utf8(gfp, "TCON", str); ++ case 'c': return id3tag_set_comment_utf8(gfp, 0, 0, str); ++ case 'n': return id3tag_set_textinfo_utf8(gfp, "TRCK", str); ++ case 'y': return id3tag_set_textinfo_utf8(gfp, "TYER", str); ++ case 'v': return id3tag_set_fieldvalue_utf8(gfp, str); ++ } ++ return -3; ++} + #endif + + static int +@@ -480,8 +484,8 @@ + default: + #ifdef ID3TAGS_EXTENDED + case TENC_LATIN1: result = set_id3tag(gfp, type, x); break; +- case TENC_UTF16: result = set_id3v2tag(gfp, enc, type, x); break; +- case TENC_UTF8: result = set_id3v2tag(gfp, enc, type, x); break; ++ case TENC_UTF16: result = set_id3v2tag_utf16(gfp, type, x); break; ++ case TENC_UTF8: result = set_id3v2tag_utf8(gfp, type, x); break; + #else + case TENC_RAW: result = set_id3tag(gfp, type, x); break; + #endif +--- a/include/lame.h ++++ b/include/lame.h +@@ -1297,6 +1297,9 @@ + int CDECL id3tag_set_fieldvalue_utf16(lame_t gfp, const unsigned short *fieldvalue); + + /* experimental */ ++int CDECL id3tag_set_fieldvalue_utf8(lame_t gfp, const char *fieldvalue); ++ ++/* experimental */ + int CDECL id3tag_set_textinfo_utf16(lame_t gfp, char const *id, unsigned short const *text); + + /* experimental */ +--- a/include/lame.def ++++ b/include/lame.def +@@ -306,3 +306,6 @@ + ; two external functions for ID3v2.4 tag support + id3tag_add_v2_4_UTF8 @2029 + id3tag_v2_4_UTF8_only @2030 ++ ++; UTF-8 field-value setter (companion to id3tag_set_fieldvalue_utf16) ++id3tag_set_fieldvalue_utf8 @2031 +--- a/include/libmp3lame.sym ++++ b/include/libmp3lame.sym +@@ -229,6 +229,7 @@ + id3tag_set_comment_ucs2 + id3tag_set_fieldvalue_ucs2 + id3tag_set_fieldvalue_utf16 ++id3tag_set_fieldvalue_utf8 + id3tag_set_textinfo_utf16 + id3tag_set_comment_utf16 + id3tag_set_textinfo_utf8 +--- a/libmp3lame/id3tag.c ++++ b/libmp3lame/id3tag.c +@@ -1844,6 +1844,21 @@ + return id3tag_set_fieldvalue_utf16(gfp, fieldvalue); + } + ++int ++id3tag_set_fieldvalue_utf8(lame_t gfp, const char *fieldvalue) ++{ ++ if (is_lame_internal_flags_null(gfp)) { ++ return 0; ++ } ++ if (fieldvalue && *fieldvalue) { ++ if (strlen(fieldvalue) < 5 || fieldvalue[4] != '=') { ++ return -1; ++ } ++ return id3tag_set_textinfo_utf8(gfp, fieldvalue, &fieldvalue[5]); ++ } ++ return 0; ++} ++ + size_t + lame_get_id3v2_tag(lame_t gfp, unsigned char *buffer, size_t size) + { \ No newline at end of file diff --git a/pkgs/by-name/la/lame/package.nix b/pkgs/by-name/la/lame/package.nix index 7b557369e71f..3c4efc573f1f 100644 --- a/pkgs/by-name/la/lame/package.nix +++ b/pkgs/by-name/la/lame/package.nix @@ -2,6 +2,7 @@ lib, stdenv, fetchurl, + pkg-config, nasmSupport ? true, nasm, # Assembly optimizations cpmlSupport ? true, # Compaq's fast math library @@ -10,6 +11,7 @@ libsndfile, # Use libsndfile, instead of lame's internal routines analyzerHooksSupport ? true, # Use analyzer hooks decoderSupport ? true, # mpg123 decoder + libmpg123, frontendSupport ? true, # Build the lame executable #, mp3xSupport ? false, gtk1 # Build GTK frame analyzer mp3rtpSupport ? false, # Build mp3rtp @@ -18,11 +20,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "lame"; - version = "3.100"; + version = "4.0"; src = fetchurl { url = "mirror://sourceforge/lame/lame-${finalAttrs.version}.tar.gz"; - sha256 = "07nsn5sy3a8xbmw1bidxnsj5fj6kg9ai04icmqw40ybkp353dznx"; + hash = "sha256-PfUSTVrTqYMS/9e6aps2Iw5Pij5m084PQl4zbDLSFus="; }; outputs = [ @@ -32,13 +34,23 @@ stdenv.mkDerivation (finalAttrs: { ]; # a small single header outputMan = "out"; - nativeBuildInputs = [ ] ++ lib.optional nasmSupport nasm; + patches = [ + # fix ID3v2 UTF-8 tag path to avoid incompatible-pointer-types + # with GCC 15; upstream SVN r6562, SF bug #524 + ./fix-utf8-id3-tag.patch + # setlocale() is used under HAVE_LANGINFO_H, but was only + # included together with HAVE_ICONV, breaking the build on macOS; + # upstream SVN r6590 + ./fix-setlocale-without-iconv.patch + # hip_set_pinfo/hip_finish_pinfo are used by the frontend but were missing + # from the exported symbol list, breaking the link with analyzer hooks + # enabled; upstream SVN r6564, SF bug #515 + ./export-hip-pinfo-symbols.patch + ]; - buildInputs = - [ ] - #++ optional efenceSupport libefence - #++ optional mp3xSupport gtk1 - ++ lib.optional sndfileFileIOSupport libsndfile; + nativeBuildInputs = [ pkg-config ] ++ lib.optional nasmSupport nasm; + + buildInputs = lib.optional decoderSupport libmpg123 ++ lib.optional sndfileFileIOSupport libsndfile; configureFlags = [ (lib.enableFeature nasmSupport "nasm") @@ -54,15 +66,9 @@ stdenv.mkDerivation (finalAttrs: { (lib.optionalString debugSupport "--enable-debug=alot") ]; - preConfigure = '' - # Prevent a build failure for 3.100 due to using outdated symbol list - # https://hydrogenaud.io/index.php/topic,114777.msg946373.html#msg946373 - sed -i '/lame_init_old/d' include/libmp3lame.sym - ''; - meta = { description = "High quality MPEG Audio Layer III (MP3) encoder"; - homepage = "http://lame.sourceforge.net"; + homepage = "https://lame.sourceforge.io"; license = lib.licenses.lgpl2; maintainers = [ ]; platforms = lib.platforms.all; From 17e5e45040be2135c140951ca269f2a51e4f425f Mon Sep 17 00:00:00 2001 From: Sergei Trofimovich Date: Tue, 18 Aug 2026 21:28:58 +0100 Subject: [PATCH 019/423] lndir: 1.0.5 -> 1.0.6 Changes: https://www.mail-archive.com/xorg-announce@lists.x.org/msg01945.html --- pkgs/by-name/ln/lndir/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ln/lndir/package.nix b/pkgs/by-name/ln/lndir/package.nix index 9e18819a4947..fb1c82eb37f9 100644 --- a/pkgs/by-name/ln/lndir/package.nix +++ b/pkgs/by-name/ln/lndir/package.nix @@ -7,11 +7,11 @@ }: stdenv.mkDerivation (finalAttrs: { pname = "lndir"; - version = "1.0.5"; + version = "1.0.6"; src = fetchurl { url = "mirror://xorg/individual/util/lndir-${finalAttrs.version}.tar.xz"; - hash = "sha256-O2VXelV1zOCVZk9UkhZKlpQYAP5ikKEjcx1H8+cQTds="; + hash = "sha256-GPbWZOUolLfe4NL8mxceDlhWblCR5E+VNfEObZQZEqQ="; }; strictDeps = true; From 58d084bdd271bf4020f3471ebd67374cd5bab331 Mon Sep 17 00:00:00 2001 From: Aaron Andersen Date: Tue, 18 Aug 2026 20:34:56 -0400 Subject: [PATCH 020/423] modemmanager: replace systemd dependency with systemdLibs --- pkgs/by-name/mo/modemmanager/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/mo/modemmanager/package.nix b/pkgs/by-name/mo/modemmanager/package.nix index a7a73ee2c50f..a0bfff3f6468 100644 --- a/pkgs/by-name/mo/modemmanager/package.nix +++ b/pkgs/by-name/mo/modemmanager/package.nix @@ -26,8 +26,8 @@ && stdenv.hostPlatform.emulatorAvailable buildPackages, polkit, withPolkit ? lib.meta.availableOn stdenv.hostPlatform polkit, - systemd, - withSystemd ? lib.meta.availableOn stdenv.hostPlatform systemd, + systemdLibs, + withSystemd ? lib.meta.availableOn stdenv.hostPlatform systemdLibs, }: stdenv.mkDerivation rec { @@ -79,7 +79,7 @@ stdenv.mkDerivation rec { polkit ] ++ lib.optionals withSystemd [ - systemd + systemdLibs ]; nativeInstallCheckInputs = [ From 66b6f41fd3312c80f7b767a7b3ab33284bf97f88 Mon Sep 17 00:00:00 2001 From: Aaron Andersen Date: Tue, 18 Aug 2026 20:41:35 -0400 Subject: [PATCH 021/423] networkmanager: replace systemd dependency with systemdMinimal --- pkgs/by-name/ne/networkmanager/package.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/ne/networkmanager/package.nix b/pkgs/by-name/ne/networkmanager/package.nix index 3dfd4067399f..d4c31638aa8e 100644 --- a/pkgs/by-name/ne/networkmanager/package.nix +++ b/pkgs/by-name/ne/networkmanager/package.nix @@ -36,9 +36,9 @@ polkit, readline, slang, - systemd, + systemdMinimal, udev, - withSystemd ? lib.meta.availableOn stdenv.hostPlatform systemd, + withSystemd ? lib.meta.availableOn stdenv.hostPlatform systemdMinimal, # external deps bluez5, @@ -211,7 +211,7 @@ stdenv.mkDerivation (finalAttrs: { ppp readline slang - (if withSystemd then systemd else udev) + (if withSystemd then systemdMinimal else udev) ] ++ lib.optionals withNbft [ libnvme @@ -236,7 +236,7 @@ stdenv.mkDerivation (finalAttrs: { '' + lib.optionalString withSystemd '' substituteInPlace data/NetworkManager.service.in \ - --replace-fail /usr/bin/busctl ${lib.getExe' systemd "busctl"} + --replace-fail /usr/bin/busctl ${lib.getExe' systemdMinimal "busctl"} ''; preBuild = '' From 51044d203a8bab081284a88bf23a25de1fba5d32 Mon Sep 17 00:00:00 2001 From: Doron Behar Date: Wed, 19 Aug 2026 17:49:33 +0300 Subject: [PATCH 022/423] zlib: remove not needed anymore lld linker workaround Tested that with this change the packages `pkgsCross.x86_64-{freebsd,openbsd}.zlib` build from an `x86_64-linux` build platform, and that their hashes actually are changed due to this. --- pkgs/development/libraries/zlib/default.nix | 21 +++++++-------------- 1 file changed, 7 insertions(+), 14 deletions(-) diff --git a/pkgs/development/libraries/zlib/default.nix b/pkgs/development/libraries/zlib/default.nix index a400e4b60c63..2db92fe52920 100644 --- a/pkgs/development/libraries/zlib/default.nix +++ b/pkgs/development/libraries/zlib/default.nix @@ -108,20 +108,13 @@ stdenv.mkDerivation (finalAttrs: { ln -s zlib1.dll $out/bin/libz.dll ''; - env = - lib.optionalAttrs (!stdenv.hostPlatform.isDarwin) { - # As zlib takes part in the stdenv building, we don't want references - # to the bootstrap-tools libgcc (as uses to happen on arm/mips) - NIX_CFLAGS_COMPILE = toString ( - [ "-static-libgcc" ] ++ lib.optional stdenv.hostPlatform.isCygwin "-DHAVE_UNISTD_H" - ); - } - // lib.optionalAttrs (stdenv.hostPlatform.linker == "lld") { - # lld 16 enables --no-undefined-version by default - # This makes configure think it can't build dynamic libraries - # this may be removed when a version is packaged with https://github.com/madler/zlib/issues/960 fixed - NIX_LDFLAGS = "--undefined-version"; - }; + env = lib.optionalAttrs (!stdenv.hostPlatform.isDarwin) { + # As zlib takes part in the stdenv building, we don't want references + # to the bootstrap-tools libgcc (as uses to happen on arm/mips) + NIX_CFLAGS_COMPILE = toString ( + [ "-static-libgcc" ] ++ lib.optional stdenv.hostPlatform.isCygwin "-DHAVE_UNISTD_H" + ); + }; # We don't strip on static cross-compilation because of reports that native # stripping corrupted the target library; see commit 12e960f5 for the report. From 785ec6b49ad9b9448579828e32d46a8e0289c0c7 Mon Sep 17 00:00:00 2001 From: seth Date: Fri, 20 Dec 2024 15:00:03 -0500 Subject: [PATCH 023/423] zlib: use default configure script on windows This avoids the pitfalls of win32/Makefile.gcc (which prevents building on compilers other than gcc without patching and has non-standard installation behavior) and fixes cross compilation for ucrtAarch64 Putting the DLL's in `$out/bin` was given the approval of: John Ericson --- pkgs/development/libraries/zlib/default.nix | 20 +++---------------- .../libraries/zlib/mingw-shared.patch | 13 ++++++++++++ 2 files changed, 16 insertions(+), 17 deletions(-) create mode 100644 pkgs/development/libraries/zlib/mingw-shared.patch diff --git a/pkgs/development/libraries/zlib/default.nix b/pkgs/development/libraries/zlib/default.nix index 2db92fe52920..6d985093d9d3 100644 --- a/pkgs/development/libraries/zlib/default.nix +++ b/pkgs/development/libraries/zlib/default.nix @@ -49,6 +49,8 @@ stdenv.mkDerivation (finalAttrs: { # https://github.com/madler/zlib/pull/1171 patches = [ ./export-variable.patch + # https://github.com/madler/zlib/pull/1296 + ./mingw-shared.patch ]; postPatch = '' @@ -69,15 +71,13 @@ stdenv.mkDerivation (finalAttrs: { setOutputFlags = false; outputDoc = "dev"; # single tiny man3 page - dontConfigure = (stdenv.hostPlatform.isMinGW || stdenv.hostPlatform.isCygwin); - preConfigure = lib.optionalString (stdenv.hostPlatform != stdenv.buildPlatform) '' export CHOST=${stdenv.hostPlatform.config} ''; configureFlags = [ "--includedir=${placeholder "dev"}/include" - "--sharedlibdir=${placeholder "out"}/lib" + "--sharedlibdir=${placeholder "out"}/${if stdenv.hostPlatform.isWindows then "bin" else "lib"}" "--libdir=${placeholder (if splitStaticOutput then "static" else "out")}/lib" # See comment near splitStaticOutput argument (lib.enableFeature shared "shared") @@ -101,11 +101,6 @@ stdenv.mkDerivation (finalAttrs: { for file in $out/lib/*.so* $out/lib/*.dylib* ; do ${stdenv.cc.bintools.targetPrefix}install_name_tool -id "$file" $file done - '' - # Non-typical naming confuses libtool which then refuses to use zlib's DLL - # in some cases, e.g. when compiling libpng. - + lib.optionalString (stdenv.hostPlatform.isMinGW && shared) '' - ln -s zlib1.dll $out/bin/libz.dll ''; env = lib.optionalAttrs (!stdenv.hostPlatform.isDarwin) { @@ -134,18 +129,9 @@ stdenv.mkDerivation (finalAttrs: { "PREFIX=${stdenv.cc.targetPrefix}" "pkgconfigdir=${placeholder "dev"}/share/pkgconfig" ] - ++ lib.optionals (stdenv.hostPlatform.isMinGW || stdenv.hostPlatform.isCygwin) [ - "-f" - "win32/Makefile.gcc" - ] ++ lib.optionals stdenv.hostPlatform.isCygwin [ "SHAREDLIB=cygz.dll" "IMPLIB=libz.dll.a" - ] - ++ lib.optionals shared [ - # Note that as of writing (zlib 1.2.11), this flag only has an effect - # for Windows as it is specific to `win32/Makefile.gcc`. - "SHARED_MODE=1" ]; passthru.tests = { diff --git a/pkgs/development/libraries/zlib/mingw-shared.patch b/pkgs/development/libraries/zlib/mingw-shared.patch new file mode 100644 index 000000000000..9f08476a3a26 --- /dev/null +++ b/pkgs/development/libraries/zlib/mingw-shared.patch @@ -0,0 +1,13 @@ +diff --git a/configure b/configure +index c55098a..07f7c08 100755 +--- a/configure ++++ b/configure +@@ -243,6 +243,8 @@ if test "$gcc" -eq 1 && ($cc -c $test.c) >> configure.log 2>&1; then + echo "If this doesn't work for you, try win32/Makefile.gcc." | tee -a configure.log + LDSHARED=${LDSHARED-"$cc -shared"} + LDSHAREDLIBC="" ++ shared_ext='.dll' ++ SHAREDLIB='libz.dll' + EXE='.exe' ;; + QNX*) # This is for QNX6. I suppose that the QNX rule below is for QNX2,QNX4 + # (alain.bonnefoy@icbt.com) From b25306b0d49271e64705e6b7f5583f41284cc51e Mon Sep 17 00:00:00 2001 From: Aaron Andersen Date: Tue, 18 Aug 2026 20:09:15 -0400 Subject: [PATCH 024/423] ppp: replace systemd dependency with systemdLibs --- pkgs/by-name/pp/ppp/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/pp/ppp/package.nix b/pkgs/by-name/pp/ppp/package.nix index 547c7ee8f7dd..da17ab2a17e8 100644 --- a/pkgs/by-name/pp/ppp/package.nix +++ b/pkgs/by-name/pp/ppp/package.nix @@ -11,8 +11,8 @@ openssl, pkg-config, stdenv, - withSystemd ? lib.meta.availableOn stdenv.hostPlatform systemdMinimal, - systemdMinimal, + withSystemd ? lib.meta.availableOn stdenv.hostPlatform systemdLibs, + systemdLibs, }: stdenv.mkDerivation (finalAttrs: { @@ -55,7 +55,7 @@ stdenv.mkDerivation (finalAttrs: { openssl ] ++ lib.optionals withSystemd [ - systemdMinimal + systemdLibs ]; postPatch = '' From 5f16fc985c621df34e30cee1c56aee1f06a2b550 Mon Sep 17 00:00:00 2001 From: Sergei Trofimovich Date: Wed, 19 Aug 2026 22:01:58 +0100 Subject: [PATCH 025/423] libmicrohttpd: 1.0.6 -> 1.0.10 --- pkgs/development/libraries/libmicrohttpd/1.0.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/libraries/libmicrohttpd/1.0.nix b/pkgs/development/libraries/libmicrohttpd/1.0.nix index 9248819673c6..cf9879dccee9 100644 --- a/pkgs/development/libraries/libmicrohttpd/1.0.nix +++ b/pkgs/development/libraries/libmicrohttpd/1.0.nix @@ -1,10 +1,10 @@ { callPackage, fetchurl }: callPackage ./generic.nix rec { - version = "1.0.6"; + version = "1.0.10"; src = fetchurl { url = "mirror://gnu/libmicrohttpd/libmicrohttpd-${version}.tar.gz"; - hash = "sha256-u1z8rfxS29XrUS1uKZXgNhNRwz6XqHq6Qm06Snumz3A="; + hash = "sha256-BL/o73XbfWKaM952dZl2XOytxWJ0o5gi1dCBAw1XdoU="; }; } From 1e8e68e5a934df7f6591f969aae9918a59d0ff4b Mon Sep 17 00:00:00 2001 From: Oleksandr Usov Date: Sun, 16 Aug 2026 04:14:12 +0100 Subject: [PATCH 026/423] git: fix interpreter paths in contrib scripts --- pkgs/by-name/gi/git/package.nix | 14 +++++++++++++- 1 file changed, 13 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/gi/git/package.nix b/pkgs/by-name/gi/git/package.nix index 3aa66809b005..83cbffb070b2 100644 --- a/pkgs/by-name/gi/git/package.nix +++ b/pkgs/by-name/gi/git/package.nix @@ -86,6 +86,11 @@ let AuthenSASL DigestHMAC ]; + gitJumpBinPath = lib.makeBinPath [ + "$out" + perlPackages.perl + coreutils + ]; in stdenv.mkDerivation (finalAttrs: { @@ -197,6 +202,7 @@ stdenv.mkDerivation (finalAttrs: { (if stdenv.hostPlatform.isFreeBSD then libiconvReal else libiconv) bash ] + ++ lib.optionals pythonSupport [ python3 ] ++ lib.optionals perlSupport [ perlPackages.perl ] ++ lib.optionals guiSupport [ tcl @@ -383,9 +389,11 @@ stdenv.mkDerivation (finalAttrs: { # Also put git-http-backend into $PATH, so that we can use smart # HTTP(s) transports for pushing ln -s $out/libexec/git-core/git-http-backend${stdenv.hostPlatform.extensions.executable} $out/bin/git-http-backend - ln -s $out/share/git/contrib/git-jump/git-jump $out/bin/git-jump '' + lib.optionalString perlSupport '' + makeWrapper $out/share/git/contrib/git-jump/git-jump $out/bin/git-jump \ + --prefix PATH : "${gitJumpBinPath}" + # wrap perl commands makeWrapper "$out/share/git/contrib/credential/netrc/git-credential-netrc.perl" $out/libexec/git-core/git-credential-netrc \ --set PERL5LIB "$out/${perlPackages.perl.libPrefix}:${perlPackages.makePerlPath perlLibs}" @@ -412,6 +420,10 @@ stdenv.mkDerivation (finalAttrs: { done '' + + lib.optionalString pythonSupport '' + patchShebangs $out/share/git/contrib/fast-import/import-zips.py + '' + + ( if svnSupport then '' From 77e807267494e63bd8d256a4567c8c8d5ef14095 Mon Sep 17 00:00:00 2001 From: Sergei Trofimovich Date: Tue, 25 Aug 2026 21:34:09 +0100 Subject: [PATCH 027/423] gdk-pixbuf: 2.44.7 -> 2.44.8 Changes: https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/compare/2.44.7...2.44.8 --- pkgs/by-name/gd/gdk-pixbuf/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/gd/gdk-pixbuf/package.nix b/pkgs/by-name/gd/gdk-pixbuf/package.nix index a55bfa0909c6..618f24b74f4b 100644 --- a/pkgs/by-name/gd/gdk-pixbuf/package.nix +++ b/pkgs/by-name/gd/gdk-pixbuf/package.nix @@ -28,7 +28,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "gdk-pixbuf"; - version = "2.44.7"; + version = "2.44.8"; outputs = [ "out" @@ -40,7 +40,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "mirror://gnome/sources/gdk-pixbuf/${lib.versions.majorMinor finalAttrs.version}/gdk-pixbuf-${finalAttrs.version}.tar.xz"; - hash = "sha256-Fy+A42JuwxUgqXBADxo2lOBHGPbCzSiF91JQ+1pplaQ="; + hash = "sha256-kZ9SlRKWGhLoHNS0tGakjDkzRp5/mjEMZRPNT7JSujw="; }; patches = [ From 17a75aa77deb1a976d36c89efadae5ca11fad2bc Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 26 Aug 2026 00:45:19 +0000 Subject: [PATCH 028/423] libvpx: 1.16.0 -> 1.17.0 --- pkgs/by-name/li/libvpx/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/li/libvpx/package.nix b/pkgs/by-name/li/libvpx/package.nix index 5ecf5bf47fe2..684c5244da60 100644 --- a/pkgs/by-name/li/libvpx/package.nix +++ b/pkgs/by-name/li/libvpx/package.nix @@ -136,13 +136,13 @@ assert isCygwin -> unitTestsSupport && webmIOSupport && libyuvSupport; stdenv.mkDerivation (finalAttrs: { pname = "libvpx"; - version = "1.16.0"; + version = "1.17.0"; src = fetchFromGitHub { owner = "webmproject"; repo = "libvpx"; rev = "v${finalAttrs.version}"; - hash = "sha256-z1Ov3BHnAGuayeY4D86oTRiDfuZ2Wpc4ZD7pXGaakVI="; + hash = "sha256-1PBeHQSgBf5nT/IDL36VWBqiWLSHz/1XGM41gy49DsY="; }; postPatch = '' From 43bb5f368b3b8188af0109cb3f577054e4bcb117 Mon Sep 17 00:00:00 2001 From: liberodark Date: Wed, 26 Aug 2026 08:40:02 +0200 Subject: [PATCH 029/423] haskell.compiler: apply LLVM split sections fix unconditionally --- .../compilers/ghc/common-hadrian.nix | 23 +++++++------------ 1 file changed, 8 insertions(+), 15 deletions(-) diff --git a/pkgs/development/compilers/ghc/common-hadrian.nix b/pkgs/development/compilers/ghc/common-hadrian.nix index 51fc88540c9c..d3049455a1d6 100644 --- a/pkgs/development/compilers/ghc/common-hadrian.nix +++ b/pkgs/development/compilers/ghc/common-hadrian.nix @@ -254,21 +254,14 @@ "sha256-vtjT+TL/7sYPu4rcVV3xCqJQ+uqkyBbf9l0KIi97j/0="; }) ] - ++ - lib.optionals - ( - (stdenv.hostPlatform.isRiscV64 || stdenv.hostPlatform.isLoongArch64) - && lib.versionAtLeast version "9.10" - && lib.versionOlder version "9.12" - ) - [ - # Fix LLVM backend split sections causing bin/out reference cycles: https://gitlab.haskell.org/ghc/ghc/-/issues/26770 - (fetchpatch { - name = "ghc-llvm-fix-split-sections.patch"; - url = "https://gitlab.haskell.org/ghc/ghc/-/commit/b18b2c42c32488ad6d3480a56a1fcd753cad2023.patch"; - hash = "sha256-kEgZARwcdnWcvjuTfyqnn8V1zAUczZN0qiy/1WbCy1s="; - }) - ] + ++ lib.optionals (lib.versionAtLeast version "9.10" && lib.versionOlder version "9.12") [ + # Fix LLVM backend split sections causing bin/out reference cycles: https://gitlab.haskell.org/ghc/ghc/-/issues/26770 + (fetchpatch { + name = "ghc-llvm-fix-split-sections.patch"; + url = "https://gitlab.haskell.org/ghc/ghc/-/commit/b18b2c42c32488ad6d3480a56a1fcd753cad2023.patch"; + hash = "sha256-kEgZARwcdnWcvjuTfyqnn8V1zAUczZN0qiy/1WbCy1s="; + }) + ] ++ lib.optionals (lib.versionOlder version "9.12") [ (fetchpatch { name = "ghc-rts-Fix-compile-on-powerpc64-elf-v1.patch"; From 3117f84f1db370861f63bbf2448b71b87df3c0bb Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Thu, 27 Aug 2026 13:10:02 +0200 Subject: [PATCH 030/423] boehmgc: enable strictDeps, use tag --- pkgs/by-name/bo/boehmgc/package.nix | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/bo/boehmgc/package.nix b/pkgs/by-name/bo/boehmgc/package.nix index 41a6a88764a6..9a0d3c9d34d5 100644 --- a/pkgs/by-name/bo/boehmgc/package.nix +++ b/pkgs/by-name/bo/boehmgc/package.nix @@ -26,7 +26,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchFromGitHub { owner = "bdwgc"; repo = "bdwgc"; - rev = "v${finalAttrs.version}"; + tag = "v${finalAttrs.version}"; hash = "sha256-5yeAB5Y92YjOutwRXBJkMxoOLkmzmqIJs4PirKX89fE="; }; @@ -43,6 +43,8 @@ stdenv.mkDerivation (finalAttrs: { autoreconfHook ]; + strictDeps = true; + configureFlags = [ "--enable-cplusplus" "--with-libatomic-ops=none" From 191d65e9b08c650b35e21d3d4700fcce6e48e205 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Fri, 28 Aug 2026 11:38:44 +0200 Subject: [PATCH 031/423] db{4,5,6}: enable strictDeps --- pkgs/development/libraries/db/generic.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/development/libraries/db/generic.nix b/pkgs/development/libraries/db/generic.nix index 25dc5785f6e0..b9867a030a80 100644 --- a/pkgs/development/libraries/db/generic.nix +++ b/pkgs/development/libraries/db/generic.nix @@ -31,6 +31,8 @@ stdenv.mkDerivation ( # which causes configure checks to work incorrectly with clang 16. nativeBuildInputs = lib.optionals stdenv.cc.isClang [ autoconf269 ] ++ [ autoreconfHook ]; + strictDeps = true; + patches = [ (fetchpatch { name = "gcc15.patch"; From bcff0884c778cd8a167d94c4f042eb30b72757e7 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Fri, 28 Aug 2026 11:39:02 +0200 Subject: [PATCH 032/423] db{4,5,6}: enable structuredAttrs --- pkgs/development/libraries/db/generic.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/development/libraries/db/generic.nix b/pkgs/development/libraries/db/generic.nix index b9867a030a80..367a244cee1c 100644 --- a/pkgs/development/libraries/db/generic.nix +++ b/pkgs/development/libraries/db/generic.nix @@ -114,6 +114,8 @@ stdenv.mkDerivation ( make examples_c examples_cxx ''; + __structuredAttrs = true; + meta = { homepage = "https://www.oracle.com/database/technologies/related/berkeleydb.html"; description = "Berkeley DB"; From 107da3649cd032de86c3d720d7e7680e960fde4a Mon Sep 17 00:00:00 2001 From: Tom Hunze Date: Fri, 28 Aug 2026 00:34:53 +0200 Subject: [PATCH 033/423] nixosTests.installed-tests.gjs: fix build These tests require cairo and xlib typelibs. Hydra: https://hydra.nixos.org/build/343716867 --- pkgs/by-name/gj/gjs/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/gj/gjs/package.nix b/pkgs/by-name/gj/gjs/package.nix index 08cfe8bd2db4..8f6e794042aa 100644 --- a/pkgs/by-name/gj/gjs/package.nix +++ b/pkgs/by-name/gj/gjs/package.nix @@ -37,6 +37,7 @@ let gdk-pixbuf harfbuzz glib.out + gobject-introspection ]; in stdenv.mkDerivation (finalAttrs: { From cb288385c43f8f9ab93097e73a1c148fbb09b64a Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Sat, 29 Aug 2026 21:49:18 -0700 Subject: [PATCH 034/423] catch2_3: 3.15.3 -> 3.16.0 Diff: https://github.com/catchorg/Catch2/compare/v3.15.3...v3.16.0 Changelog: https://github.com/catchorg/Catch2/blob/v3.16.0/docs/release-notes.md --- .../catch2_3/clang-20-disable-broken-test.patch | 15 --------------- pkgs/by-name/ca/catch2_3/package.nix | 10 ++-------- 2 files changed, 2 insertions(+), 23 deletions(-) delete mode 100644 pkgs/by-name/ca/catch2_3/clang-20-disable-broken-test.patch diff --git a/pkgs/by-name/ca/catch2_3/clang-20-disable-broken-test.patch b/pkgs/by-name/ca/catch2_3/clang-20-disable-broken-test.patch deleted file mode 100644 index 372243455aed..000000000000 --- a/pkgs/by-name/ca/catch2_3/clang-20-disable-broken-test.patch +++ /dev/null @@ -1,15 +0,0 @@ -diff --git a/tests/SelfTest/UsageTests/Misc.tests.cpp b/tests/SelfTest/UsageTests/Misc.tests.cpp -index 3697f0695c..8c10aace7b 100644 ---- a/tests/SelfTest/UsageTests/Misc.tests.cpp -+++ b/tests/SelfTest/UsageTests/Misc.tests.cpp -@@ -384,10 +384,6 @@ - REQUIRE(x.size() > 0); - } - --TEMPLATE_PRODUCT_TEST_CASE("Product with differing arities", "[template][product]", std::tuple, (int, (int, double), (int, double, float))) { -- REQUIRE(std::tuple_size::value >= 1); --} -- - using MyTypes = std::tuple; - TEMPLATE_LIST_TEST_CASE("Template test case with test types specified inside std::tuple", "[template][list]", MyTypes) - { diff --git a/pkgs/by-name/ca/catch2_3/package.nix b/pkgs/by-name/ca/catch2_3/package.nix index 381fead86e88..1776477cbf56 100644 --- a/pkgs/by-name/ca/catch2_3/package.nix +++ b/pkgs/by-name/ca/catch2_3/package.nix @@ -9,21 +9,15 @@ stdenv.mkDerivation rec { pname = "catch2"; - version = "3.15.3"; + version = "3.16.0"; src = fetchFromGitHub { owner = "catchorg"; repo = "Catch2"; tag = "v${version}"; - hash = "sha256-ZuH3tUWNklq0bKp0Yu9w3L5FNsQwUxe6lyGBv4M6U1E="; + hash = "sha256-vvPZTQzLNGIcdDbuo0w6sQvxzLdKFCl2LNwcHu0d5I8="; }; - patches = lib.optionals stdenv.cc.isClang [ - # This test fails to compile with Clang 20 - # See: https://github.com/catchorg/Catch2/issues/2991 - ./clang-20-disable-broken-test.patch - ]; - postPatch = '' substituteInPlace CMake/*.pc.in \ --replace-fail "\''${prefix}/" "" From d801a11a6bf991f1036b0b55220fbba3c29c3aba Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Sat, 29 Aug 2026 21:51:49 -0700 Subject: [PATCH 035/423] catch2_3: use finalAttrs --- pkgs/by-name/ca/catch2_3/package.nix | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/pkgs/by-name/ca/catch2_3/package.nix b/pkgs/by-name/ca/catch2_3/package.nix index 1776477cbf56..29d15bd0bfc7 100644 --- a/pkgs/by-name/ca/catch2_3/package.nix +++ b/pkgs/by-name/ca/catch2_3/package.nix @@ -7,14 +7,14 @@ spdlog, }: -stdenv.mkDerivation rec { +stdenv.mkDerivation (finalAttrs: { pname = "catch2"; version = "3.16.0"; src = fetchFromGitHub { owner = "catchorg"; repo = "Catch2"; - tag = "v${version}"; + tag = "v${finalAttrs.version}"; hash = "sha256-vvPZTQzLNGIcdDbuo0w6sQvxzLdKFCl2LNwcHu0d5I8="; }; @@ -31,10 +31,10 @@ stdenv.mkDerivation rec { cmakeFlags = [ "-DCATCH_DEVELOPMENT_BUILD=ON" - "-DCATCH_BUILD_TESTING=${if doCheck then "ON" else "OFF"}" + "-DCATCH_BUILD_TESTING=${if finalAttrs.doCheck then "ON" else "OFF"}" "-DCATCH_ENABLE_WERROR=OFF" ] - ++ lib.optionals (stdenv.cc.isClang && doCheck) [ + ++ lib.optionals (stdenv.cc.isClang && finalAttrs.doCheck) [ # test has a faulty path normalization technique that won't work in # our darwin/LLVM build environment https://github.com/catchorg/Catch2/issues/1691 "-DCMAKE_CTEST_ARGUMENTS=-E;ApprovalTests" @@ -63,9 +63,9 @@ stdenv.mkDerivation rec { meta = { description = "Modern, C++-native, test framework for unit-tests"; homepage = "https://github.com/catchorg/Catch2"; - changelog = "https://github.com/catchorg/Catch2/blob/${src.tag}/docs/release-notes.md"; + changelog = "https://github.com/catchorg/Catch2/blob/${finalAttrs.src.tag}/docs/release-notes.md"; license = lib.licenses.boost; maintainers = with lib.maintainers; [ dotlambda ]; platforms = with lib.platforms; unix ++ windows; }; -} +}) From 7adb46d173764051df2a9bbf6cfc1f3e7aedd45b Mon Sep 17 00:00:00 2001 From: OPNA2608 Date: Sun, 30 Aug 2026 04:17:28 +0200 Subject: [PATCH 036/423] python3Packages.appnope: 0.1.4 -> 1.0.0 --- pkgs/development/python-modules/appnope/default.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/development/python-modules/appnope/default.nix b/pkgs/development/python-modules/appnope/default.nix index 12e720eb3618..f647b3834520 100644 --- a/pkgs/development/python-modules/appnope/default.nix +++ b/pkgs/development/python-modules/appnope/default.nix @@ -2,23 +2,23 @@ lib, buildPythonPackage, fetchFromGitHub, - setuptools, + hatchling, pytestCheckHook, }: buildPythonPackage (finalAttrs: { pname = "appnope"; - version = "0.1.4"; + version = "1.0.0"; pyproject = true; src = fetchFromGitHub { owner = "minrk"; repo = "appnope"; tag = finalAttrs.version; - hash = "sha256-We7sZKVbQFIMdZpS+VMdi0RH1O/qtFNrfJNg/98tO5A="; + hash = "sha256-saJ68R4zdquTWWT/QuWZk6oQhcx3R+AmVBYt/NmFtyM="; }; - build-system = [ setuptools ]; + build-system = [ hatchling ]; checkInputs = [ pytestCheckHook ]; From c55bf541fe64f586e2bf9bb1ec62e3f45dd2cf3e Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Mon, 31 Aug 2026 11:15:53 +0200 Subject: [PATCH 037/423] imath: enable strictDeps --- pkgs/by-name/im/imath/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/im/imath/package.nix b/pkgs/by-name/im/imath/package.nix index fe65e5274b95..836684b3da9d 100644 --- a/pkgs/by-name/im/imath/package.nix +++ b/pkgs/by-name/im/imath/package.nix @@ -18,6 +18,8 @@ stdenv.mkDerivation (finalAttrs: { nativeBuildInputs = [ cmake ]; + strictDeps = true; + meta = { description = "C++ and python library of 2D and 3D vector, matrix, and math operations for computer graphics"; homepage = "https://github.com/AcademySoftwareFoundation/Imath"; From 93a0568e389889c0f9013767096a26f32e1eddcf Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Mon, 31 Aug 2026 11:16:23 +0200 Subject: [PATCH 038/423] imath: enable structuredAttrs, use tag --- pkgs/by-name/im/imath/package.nix | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/im/imath/package.nix b/pkgs/by-name/im/imath/package.nix index 836684b3da9d..fe7e53260d6b 100644 --- a/pkgs/by-name/im/imath/package.nix +++ b/pkgs/by-name/im/imath/package.nix @@ -12,7 +12,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchFromGitHub { owner = "AcademySoftwareFoundation"; repo = "imath"; - rev = "v${finalAttrs.version}"; + tag = "v${finalAttrs.version}"; hash = "sha256-kmWj9g6PnvgEOojjiWYpJ9+lXwT1svpezYDsCns4NP0="; }; @@ -20,6 +20,8 @@ stdenv.mkDerivation (finalAttrs: { strictDeps = true; + __structuredAttrs = true; + meta = { description = "C++ and python library of 2D and 3D vector, matrix, and math operations for computer graphics"; homepage = "https://github.com/AcademySoftwareFoundation/Imath"; From 7e51d02b33ca751c1bd18211e7664745bca75f11 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Mon, 31 Aug 2026 11:17:58 +0200 Subject: [PATCH 039/423] jbig2dec: enable strictDeps --- pkgs/by-name/jb/jbig2dec/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/jb/jbig2dec/package.nix b/pkgs/by-name/jb/jbig2dec/package.nix index 7ccc8cc7f9b3..557c9885484e 100644 --- a/pkgs/by-name/jb/jbig2dec/package.nix +++ b/pkgs/by-name/jb/jbig2dec/package.nix @@ -37,6 +37,8 @@ stdenv.mkDerivation (finalAttrs: { libtool ]; + strictDeps = true; + # `autogen.sh` runs `configure`, and expects that any flags needed # by `configure` (like `--host`) are passed to `autogen.sh`. configureScript = "./autogen.sh"; From dceabcb721ce1b0c3b97507f2df33a3fda049ab5 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Mon, 31 Aug 2026 11:18:10 +0200 Subject: [PATCH 040/423] jbig2dec: enable structuredAttrs --- pkgs/by-name/jb/jbig2dec/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/jb/jbig2dec/package.nix b/pkgs/by-name/jb/jbig2dec/package.nix index 557c9885484e..097483c1bb7f 100644 --- a/pkgs/by-name/jb/jbig2dec/package.nix +++ b/pkgs/by-name/jb/jbig2dec/package.nix @@ -46,6 +46,8 @@ stdenv.mkDerivation (finalAttrs: { nativeCheckInputs = [ python3 ]; doCheck = true; + __structuredAttrs = true; + meta = { homepage = "https://www.jbig2dec.com/"; description = "Decoder implementation of the JBIG2 image compression format"; From 849f0cc9890d678087d8ced7a67a5cf1ccbe813b Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Mon, 31 Aug 2026 11:25:07 +0200 Subject: [PATCH 041/423] simdjson: enable strictDeps --- pkgs/by-name/si/simdjson/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/si/simdjson/package.nix b/pkgs/by-name/si/simdjson/package.nix index e2c225fa2906..0b2141e67443 100644 --- a/pkgs/by-name/si/simdjson/package.nix +++ b/pkgs/by-name/si/simdjson/package.nix @@ -18,6 +18,8 @@ stdenv.mkDerivation (finalAttrs: { nativeBuildInputs = [ cmake ]; + strictDeps = true; + cmakeFlags = [ (lib.cmakeBool "SIMDJSON_DEVELOPER_MODE" false) (lib.cmakeBool "BUILD_SHARED_LIBS" (!stdenv.hostPlatform.isStatic)) From fd5f39bb5c9f46d869a8ddd4c3236b3577d08617 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Mon, 31 Aug 2026 11:25:17 +0200 Subject: [PATCH 042/423] simdjson: enable structuredAttrs --- pkgs/by-name/si/simdjson/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/si/simdjson/package.nix b/pkgs/by-name/si/simdjson/package.nix index 0b2141e67443..83ec75356240 100644 --- a/pkgs/by-name/si/simdjson/package.nix +++ b/pkgs/by-name/si/simdjson/package.nix @@ -30,6 +30,8 @@ stdenv.mkDerivation (finalAttrs: { (lib.cmakeFeature "CMAKE_CXX_FLAGS" "-mpower8-vector") ]; + __structuredAttrs = true; + meta = { homepage = "https://simdjson.org/"; changelog = "https://github.com/simdjson/simdjson/releases/tag/${finalAttrs.src.tag}"; From f3dedf6799fb0175e74ed372e120b3221af51272 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Mon, 31 Aug 2026 11:29:40 +0200 Subject: [PATCH 043/423] srt: enable strictDeps --- pkgs/by-name/sr/srt/package.nix | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/pkgs/by-name/sr/srt/package.nix b/pkgs/by-name/sr/srt/package.nix index 6dc2f322e407..d8093826bbe9 100644 --- a/pkgs/by-name/sr/srt/package.nix +++ b/pkgs/by-name/sr/srt/package.nix @@ -3,6 +3,7 @@ stdenv, fetchFromGitHub, cmake, + bashNonInteractive, openssl, windows, }: @@ -21,12 +22,15 @@ stdenv.mkDerivation (finalAttrs: { nativeBuildInputs = [ cmake ]; buildInputs = [ + bashNonInteractive openssl ] ++ lib.optionals stdenv.hostPlatform.isMinGW [ windows.pthreads ]; + strictDeps = true; + patches = [ ] ++ lib.optionals stdenv.hostPlatform.isMinGW [ From a1c497ad0e8957248c81e2fae2581fd3b1e2faf0 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Mon, 31 Aug 2026 11:30:00 +0200 Subject: [PATCH 044/423] srt: enable structuredAttrs, use tag/hash --- pkgs/by-name/sr/srt/package.nix | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/sr/srt/package.nix b/pkgs/by-name/sr/srt/package.nix index d8093826bbe9..7021a2f3b6ab 100644 --- a/pkgs/by-name/sr/srt/package.nix +++ b/pkgs/by-name/sr/srt/package.nix @@ -15,8 +15,8 @@ stdenv.mkDerivation (finalAttrs: { src = fetchFromGitHub { owner = "Haivision"; repo = "srt"; - rev = "v${finalAttrs.version}"; - sha256 = "sha256-fdgj6URuMaem+ZVy7D8Hnf2Ev1HindevdvX0xyxCL4M="; + tag = "v${finalAttrs.version}"; + hash = "sha256-fdgj6URuMaem+ZVy7D8Hnf2Ev1HindevdvX0xyxCL4M="; }; nativeBuildInputs = [ cmake ]; @@ -49,6 +49,8 @@ stdenv.mkDerivation (finalAttrs: { "-UCMAKE_INSTALL_LIBDIR" ]; + __structuredAttrs = true; + meta = { description = "Secure, Reliable, Transport"; homepage = "https://github.com/Haivision/srt"; From 971823d346eb687113499c96b7f1140a233c996d Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Mon, 31 Aug 2026 12:06:49 +0200 Subject: [PATCH 045/423] libidn2: enable strictDeps and structuredAttrs for non-bootstrap build --- pkgs/development/libraries/libidn2/no-bootstrap-reference.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/development/libraries/libidn2/no-bootstrap-reference.nix b/pkgs/development/libraries/libidn2/no-bootstrap-reference.nix index 773dfb6efe0f..8e918e04ff0c 100644 --- a/pkgs/development/libraries/libidn2/no-bootstrap-reference.nix +++ b/pkgs/development/libraries/libidn2/no-bootstrap-reference.nix @@ -18,6 +18,9 @@ runCommandLocal "${libidn2.pname}-${libidn2.version}" inherit (libidn2) out info devdoc; # no need to touch these store paths }; inherit (libidn2) meta pname version; + + strictDeps = true; + __structuredAttrs = true; } '' cp -r '${libidn2.bin}' "$bin" From 6fd929011884f9f8494d5b03b986f92a20fbcc62 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Mon, 31 Aug 2026 12:06:57 +0200 Subject: [PATCH 046/423] libidn2: modernize non-bootstrap build, fix comment --- pkgs/development/libraries/libidn2/default.nix | 2 +- pkgs/development/libraries/libidn2/no-bootstrap-reference.nix | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/development/libraries/libidn2/default.nix b/pkgs/development/libraries/libidn2/default.nix index 8b34a2842082..ae1893635c7d 100644 --- a/pkgs/development/libraries/libidn2/default.nix +++ b/pkgs/development/libraries/libidn2/default.nix @@ -24,7 +24,7 @@ stdenv.mkDerivation (finalAttrs: { }; strictDeps = true; - # Beware: non-bootstrap libidn2 is overridden by ./hack.nix + # Beware: non-bootstrap libidn2 is overridden by ./no-bootstrap-reference.nix outputs = [ "bin" "dev" diff --git a/pkgs/development/libraries/libidn2/no-bootstrap-reference.nix b/pkgs/development/libraries/libidn2/no-bootstrap-reference.nix index 8e918e04ff0c..8bde788e1373 100644 --- a/pkgs/development/libraries/libidn2/no-bootstrap-reference.nix +++ b/pkgs/development/libraries/libidn2/no-bootstrap-reference.nix @@ -39,9 +39,9 @@ runCommandLocal "${libidn2.pname}-${libidn2.version}" cp -r '${libidn2.dev}' "$dev" chmod +w "$dev"/nix-support/propagated-build-inputs substituteInPlace "$dev"/nix-support/propagated-build-inputs \ - --replace '${libidn2.bin}' "$bin" + --replace-fail '${libidn2.bin}' "$bin" substituteInPlace "$dev"/lib/pkgconfig/libidn2.pc \ - --replace '${libidn2.dev}' "$dev" + --replace-fail '${libidn2.dev}' "$dev" ln -s '${libidn2.out}' "$out" # it's hard to be without any $out '' From aaef923e34ebee8b2f917810138ca271253cab27 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 31 Aug 2026 22:04:05 +0000 Subject: [PATCH 047/423] azurite: 3.35.0 -> 3.37.0 --- pkgs/by-name/az/azurite/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/az/azurite/package.nix b/pkgs/by-name/az/azurite/package.nix index a46a7c0b8f64..7bd89abea9c8 100644 --- a/pkgs/by-name/az/azurite/package.nix +++ b/pkgs/by-name/az/azurite/package.nix @@ -11,16 +11,16 @@ buildNpmPackage (finalAttrs: { pname = "azurite"; - version = "3.35.0"; + version = "3.37.0"; src = fetchFromGitHub { owner = "Azure"; repo = "Azurite"; rev = "v${finalAttrs.version}"; - hash = "sha256-sVYiHQJ3nR5vM+oPAHzr/MjuNBMY14afqCHpw32WCiQ="; + hash = "sha256-gqWwUpUKaMzc9TiIhgubak+NQCX9dvqLQDg6Eysaw14="; }; - npmDepsHash = "sha256-UBHjb65Ud7IANsR30DokbI/16+dVjDEtfhqRPAQhGUw="; + npmDepsHash = "sha256-ZgYGURSFc/4xx6QqJA5wMFzbWSaAH39ztcfBEqCfmVg="; nativeBuildInputs = [ pkg-config From 7fa51063dfc9d1f34999918d99ee3be4f7373efa Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Mon, 31 Aug 2026 16:04:38 -0700 Subject: [PATCH 048/423] gpgme: 2.1.2 -> 2.2.0 Changelog: https://github.com/gpg/gpgme/blob/gpgme-2.2.0/NEWS --- pkgs/by-name/gp/gpgme/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/gp/gpgme/package.nix b/pkgs/by-name/gp/gpgme/package.nix index eb406544e78e..d87c8e9e73b4 100644 --- a/pkgs/by-name/gp/gpgme/package.nix +++ b/pkgs/by-name/gp/gpgme/package.nix @@ -22,7 +22,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "gpgme"; - version = "2.1.2"; + version = "2.2.0"; outputs = [ "out" @@ -34,7 +34,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "mirror://gnupg/gpgme/gpgme-${finalAttrs.version}.tar.bz2"; - hash = "sha256-BoepWymYccQUH1B8D3QN5rQpyawGfQ+k4GLjJk31+3c="; + hash = "sha256-cWDoDoTa/QDZVshIkcUzu3qxampU++FXSy86zwSWl3s="; }; postPatch = '' From 44869a3612a4adb4af64ad982d5c642b6c34132e Mon Sep 17 00:00:00 2001 From: Jamie Magee Date: Tue, 1 Sep 2026 11:49:17 -0700 Subject: [PATCH 049/423] rust-bindgen: pass target triple when cross-compiling --- pkgs/build-support/rust/hooks/default.nix | 3 +++ pkgs/build-support/rust/hooks/rust-bindgen-hook.sh | 2 +- pkgs/development/tools/rust/bindgen/default.nix | 7 +++++++ pkgs/development/tools/rust/bindgen/wrapper.sh | 4 ++-- 4 files changed, 13 insertions(+), 3 deletions(-) diff --git a/pkgs/build-support/rust/hooks/default.nix b/pkgs/build-support/rust/hooks/default.nix index d57f1b09c40a..7c8c846e3109 100644 --- a/pkgs/build-support/rust/hooks/default.nix +++ b/pkgs/build-support/rust/hooks/default.nix @@ -132,6 +132,9 @@ substitutions = { libclang = (lib.getLib clang.cc); inherit clang; + targetFlag = lib.optionalString ( + stdenv.targetPlatform != stdenv.hostPlatform + ) "--target=${stdenv.targetPlatform.config}"; }; meta.license = lib.licenses.mit; } ./rust-bindgen-hook.sh; diff --git a/pkgs/build-support/rust/hooks/rust-bindgen-hook.sh b/pkgs/build-support/rust/hooks/rust-bindgen-hook.sh index 53624b124f2b..ba39686d3a1b 100644 --- a/pkgs/build-support/rust/hooks/rust-bindgen-hook.sh +++ b/pkgs/build-support/rust/hooks/rust-bindgen-hook.sh @@ -6,7 +6,7 @@ populateBindgenEnv () { export LIBCLANG_PATH=@libclang@/lib - BINDGEN_EXTRA_CLANG_ARGS="$(< @clang@/nix-support/cc-cflags) $(< @clang@/nix-support/libc-cflags) $(< @clang@/nix-support/libcxx-cxxflags) $NIX_CFLAGS_COMPILE" + BINDGEN_EXTRA_CLANG_ARGS="@targetFlag@ $(< @clang@/nix-support/cc-cflags) $(< @clang@/nix-support/libc-cflags) $(< @clang@/nix-support/libcxx-cxxflags) $NIX_CFLAGS_COMPILE" export BINDGEN_EXTRA_CLANG_ARGS } diff --git a/pkgs/development/tools/rust/bindgen/default.nix b/pkgs/development/tools/rust/bindgen/default.nix index 393b89a4acb4..fcd26a41c0a9 100644 --- a/pkgs/development/tools/rust/bindgen/default.nix +++ b/pkgs/development/tools/rust/bindgen/default.nix @@ -4,9 +4,15 @@ bash, runCommand, runCommandCC, + stdenv, }: let clang = rust-bindgen-unwrapped.clang; + targetFlag = + if stdenv.targetPlatform != stdenv.hostPlatform then + "--target=${stdenv.targetPlatform.config}" + else + ""; self = runCommand "rust-bindgen-${rust-bindgen-unwrapped.version}" { @@ -49,6 +55,7 @@ let --replace-fail "@bash@" "${bash}" \ --replace-fail "@cxxincludes@" "$cxxincludes" \ --replace-fail "@cincludes@" "$cincludes" \ + --replace-fail "@targetFlag@" "${targetFlag}" \ --replace-fail "@unwrapped@" "${rust-bindgen-unwrapped}" chmod +x $out/bin/bindgen ''; diff --git a/pkgs/development/tools/rust/bindgen/wrapper.sh b/pkgs/development/tools/rust/bindgen/wrapper.sh index 4311b9720aa8..cd4eff556cc1 100755 --- a/pkgs/development/tools/rust/bindgen/wrapper.sh +++ b/pkgs/development/tools/rust/bindgen/wrapper.sh @@ -28,7 +28,7 @@ if [[ -n "$NIX_DEBUG" ]]; then set -x; fi; # shellcheck disable=SC2086 -# cxxflags and NIX_CFLAGS_COMPILE should be word-split -exec -a "$0" @unwrapped@/bin/bindgen "$@" $sep $cxxflags @cincludes@ $NIX_CFLAGS_COMPILE +# targetFlag, cxxflags and NIX_CFLAGS_COMPILE should be word-split +exec -a "$0" @unwrapped@/bin/bindgen "$@" $sep @targetFlag@ $cxxflags @cincludes@ $NIX_CFLAGS_COMPILE # note that we add the flags after $@ which is incorrect. This is only for the sake # of simplicity. From 1163f773c6bd6918864b9346f3998bf696eac14b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Tue, 1 Sep 2026 15:03:01 -0700 Subject: [PATCH 050/423] gpgmepp: 2.1.0 -> 2.2.0 Changelog: https://dev.gnupg.org/source/gpgmepp/browse/master/NEWS;gpgmepp-2.2.0?as=remarkup --- pkgs/by-name/gp/gpgmepp/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/gp/gpgmepp/package.nix b/pkgs/by-name/gp/gpgmepp/package.nix index d82e0d1617ba..f2b62e35d84b 100644 --- a/pkgs/by-name/gp/gpgmepp/package.nix +++ b/pkgs/by-name/gp/gpgmepp/package.nix @@ -10,11 +10,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "gpgmepp"; - version = "2.1.0"; + version = "2.2.0"; src = fetchurl { url = "mirror://gnupg/gpgmepp/gpgmepp-${finalAttrs.version}.tar.xz"; - hash = "sha256-V/gERo8CBFBLFyxrE5ywUSS0JjvnrVFJMsfExQYqFuI="; + hash = "sha256-ZlHF9/gBVD1bZ2cZ35/sgFOwpvWrpAuYyg0r7hETbzA="; }; postPatch = '' From 2ad46cfb959555317d535df064dcdcf13674d02b Mon Sep 17 00:00:00 2001 From: Gaetan Lepage Date: Wed, 2 Sep 2026 12:36:50 +0000 Subject: [PATCH 051/423] abseil-cpp: 20260107.1 -> 20260817.0 Diff: https://github.com/abseil/abseil-cpp/compare/20260107.1...20260817.0 Changelogs: - https://github.com/abseil/abseil-cpp/releases/tag/20260526.0 - https://github.com/abseil/abseil-cpp/releases/tag/20260817.0 --- pkgs/by-name/ab/abseil-cpp/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ab/abseil-cpp/package.nix b/pkgs/by-name/ab/abseil-cpp/package.nix index 61e67450c68b..c5dd8cc0b6c6 100644 --- a/pkgs/by-name/ab/abseil-cpp/package.nix +++ b/pkgs/by-name/ab/abseil-cpp/package.nix @@ -6,7 +6,7 @@ # required LTS branch, leaving `abseil-cpp` as an alias. { - abseil-cpp_202601, + abseil-cpp_202608, cxxStandard ? null, }: -abseil-cpp_202601.override { inherit cxxStandard; } +abseil-cpp_202608.override { inherit cxxStandard; } From 54c6f0648c477d595312ad315cb99eb331aa343a Mon Sep 17 00:00:00 2001 From: whispers Date: Thu, 3 Sep 2026 17:59:02 -0400 Subject: [PATCH 052/423] go_1_26: 1.26.7 -> 1.26.8 changelog: https://go.dev/doc/devel/release#go1.26.minor diff: https://github.com/golang/go/compare/go1.26.7...go1.26.8 --- pkgs/development/compilers/go/1.26.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/compilers/go/1.26.nix b/pkgs/development/compilers/go/1.26.nix index ccb5b67f17af..0a2708bba8da 100644 --- a/pkgs/development/compilers/go/1.26.nix +++ b/pkgs/development/compilers/go/1.26.nix @@ -25,11 +25,11 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "go"; - version = "1.26.7"; + version = "1.26.8"; src = fetchurl { url = "https://go.dev/dl/go${finalAttrs.version}.src.tar.gz"; - hash = "sha256-DtJOrHVRBQhbif6cq8J0K5GgrXuUtZ0602SRjryJVq0="; + hash = "sha256-Tjm5jkL5RvoFrIvFtxh335fb23y7Gnd7VBZnrXEX/S4="; }; strictDeps = true; From 11c8783464bcd2fc3265f0dbc3c8380f03732a2c Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Fri, 4 Sep 2026 13:51:36 +0200 Subject: [PATCH 053/423] iana-etc: enable strictDeps --- pkgs/by-name/ia/iana-etc/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/ia/iana-etc/package.nix b/pkgs/by-name/ia/iana-etc/package.nix index da283674f11c..cb9b3dbe2583 100644 --- a/pkgs/by-name/ia/iana-etc/package.nix +++ b/pkgs/by-name/ia/iana-etc/package.nix @@ -14,6 +14,8 @@ stdenvNoCC.mkDerivation rec { sha256 = "sha256-BUGhVHvWSdFJdqaoPasLt87lTUFVF2B7X7sfigwrJss="; }; + strictDeps = true; + installPhase = '' install -D -m0644 -t $out/etc services protocols ''; From 0da45eb98e2fe3f965b0884bee94e315ff003d25 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Fri, 4 Sep 2026 13:51:56 +0200 Subject: [PATCH 054/423] iana-etc: enable structuredAttrs, use finalAttrs, use hash --- pkgs/by-name/ia/iana-etc/package.nix | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/ia/iana-etc/package.nix b/pkgs/by-name/ia/iana-etc/package.nix index cb9b3dbe2583..f2be62765784 100644 --- a/pkgs/by-name/ia/iana-etc/package.nix +++ b/pkgs/by-name/ia/iana-etc/package.nix @@ -5,13 +5,13 @@ writeText, }: -stdenvNoCC.mkDerivation rec { +stdenvNoCC.mkDerivation (finalAttrs: { pname = "iana-etc"; version = "20251215"; src = fetchzip { - url = "https://github.com/Mic92/iana-etc/releases/download/${version}/iana-etc-${version}.tar.gz"; - sha256 = "sha256-BUGhVHvWSdFJdqaoPasLt87lTUFVF2B7X7sfigwrJss="; + url = "https://github.com/Mic92/iana-etc/releases/download/${finalAttrs.version}/iana-etc-${finalAttrs.version}.tar.gz"; + hash = "sha256-BUGhVHvWSdFJdqaoPasLt87lTUFVF2B7X7sfigwrJss="; }; strictDeps = true; @@ -25,10 +25,12 @@ stdenvNoCC.mkDerivation rec { export NIX_ETC_SERVICES=@out@/etc/services ''; + __structuredAttrs = true; + meta = { homepage = "https://github.com/Mic92/iana-etc"; description = "IANA protocol and port number assignments (/etc/protocols and /etc/services)"; platforms = lib.platforms.unix; license = lib.licenses.mit; }; -} +}) From 0b1d179e293aab153d1142a475cc045a87c14b25 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Fri, 4 Sep 2026 15:27:04 +0200 Subject: [PATCH 055/423] rustPlatform.fetchCargoVendor: enable strictDeps, enable structuredAttrs --- pkgs/build-support/rust/fetch-cargo-vendor.nix | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/pkgs/build-support/rust/fetch-cargo-vendor.nix b/pkgs/build-support/rust/fetch-cargo-vendor.nix index 37a37f7b7bd2..98f21361199e 100644 --- a/pkgs/build-support/rust/fetch-cargo-vendor.nix +++ b/pkgs/build-support/rust/fetch-cargo-vendor.nix @@ -105,6 +105,8 @@ let outputHash = hash; outputHashAlgo = if hash == "" then "sha256" else null; outputHashMode = "recursive"; + + __structuredAttrs = true; } // removeAttrs args removedArgs ); @@ -117,6 +119,8 @@ runCommand "${name}-vendor" cargo replaceWorkspaceValues ]; + strictDeps = true; + __structuredAttrs = true; } '' fetch-cargo-vendor-util create-vendor "$vendorStaging" "$out" From 5975da64bbe7b7fb433a5e15518d885371bb8f70 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Fri, 4 Sep 2026 15:28:11 +0200 Subject: [PATCH 056/423] rustc: enable structuredAttrs in wrapper --- pkgs/build-support/rust/rustc-wrapper/default.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/build-support/rust/rustc-wrapper/default.nix b/pkgs/build-support/rust/rustc-wrapper/default.nix index 0ec66da5ab1a..3952e8b4cf26 100644 --- a/pkgs/build-support/rust/rustc-wrapper/default.nix +++ b/pkgs/build-support/rust/rustc-wrapper/default.nix @@ -49,6 +49,8 @@ runCommand "${rustc-unwrapped.pname}-wrapper-${rustc-unwrapped.version}" unwrapped = rustc-unwrapped; }; + __structuredAttrs = true; + meta = rustc-unwrapped.meta // { description = "${rustc-unwrapped.meta.description} (wrapper script)"; priority = 10; From d1c11f1d55fe2b487ac94e225c52b47d1ae07901 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Fri, 4 Sep 2026 15:30:27 +0200 Subject: [PATCH 057/423] rustc: enable strictDeps, enable structuredAttrs for binary derivation --- pkgs/development/compilers/rust/binary.nix | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/pkgs/development/compilers/rust/binary.nix b/pkgs/development/compilers/rust/binary.nix index 5dc36c54d3fb..f10e9a4ae8c8 100644 --- a/pkgs/development/compilers/rust/binary.nix +++ b/pkgs/development/compilers/rust/binary.nix @@ -48,6 +48,8 @@ rec { ++ lib.optional (!stdenv.hostPlatform.isDarwin && !stdenv.hostPlatform.isFreeBSD) gcc.cc.lib ++ lib.optional (!stdenv.hostPlatform.isDarwin) zlib; + strictDeps = true; + postPatch = '' patchShebangs . ''; @@ -90,6 +92,8 @@ rec { setupHooks = ./setup-hook.sh; + __structuredAttrs = true; + passthru = rec { targetPlatformsWithHostTools = [ # Platforms with host tools from From e9c36d6b0fc59c7cce8b8be1031e543c93aceb3c Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Fri, 4 Sep 2026 15:31:18 +0200 Subject: [PATCH 058/423] cargo: enable strictDeps, enabled structuredAttrs for binary derivation --- pkgs/development/compilers/rust/binary.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/development/compilers/rust/binary.nix b/pkgs/development/compilers/rust/binary.nix index f10e9a4ae8c8..ecbb2932eea9 100644 --- a/pkgs/development/compilers/rust/binary.nix +++ b/pkgs/development/compilers/rust/binary.nix @@ -176,6 +176,9 @@ rec { ] ++ lib.optional (!stdenv.hostPlatform.isDarwin && !stdenv.hostPlatform.isFreeBSD) gcc.cc.lib; + strictDeps = true; + __structuredAttrs = true; + postPatch = '' patchShebangs . ''; From 6749ed78c91b9a863dcf11ebd19a233a12316cd1 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Fri, 4 Sep 2026 15:32:29 +0200 Subject: [PATCH 059/423] cargo-auditable-cargo-wrapper: enable strictDeps, enable structuredAttrs --- .../compilers/rust/cargo-auditable-cargo-wrapper.nix | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/pkgs/development/compilers/rust/cargo-auditable-cargo-wrapper.nix b/pkgs/development/compilers/rust/cargo-auditable-cargo-wrapper.nix index 420b3bc82052..4878387dcb57 100644 --- a/pkgs/development/compilers/rust/cargo-auditable-cargo-wrapper.nix +++ b/pkgs/development/compilers/rust/cargo-auditable-cargo-wrapper.nix @@ -14,6 +14,8 @@ else { nativeBuildInputs = [ makeBinaryWrapper ]; + strictDeps = true; + passthru.tests = runCommand "rust-audit-info-test" { @@ -23,6 +25,8 @@ else rust-audit-info ${lib.getBin rust-audit-info}/bin/rust-audit-info > $out ''; + __structuredAttrs = true; + meta = cargo-auditable.meta // { mainProgram = "cargo"; }; From 05283c8449d1b6c613b7245fe5002aa52ea97d2a Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Fri, 4 Sep 2026 15:33:00 +0200 Subject: [PATCH 060/423] cargo: enable structuredAttrs --- pkgs/development/compilers/rust/cargo.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/development/compilers/rust/cargo.nix b/pkgs/development/compilers/rust/cargo.nix index 3fb4f948a223..64aa7d9cffd2 100644 --- a/pkgs/development/compilers/rust/cargo.nix +++ b/pkgs/development/compilers/rust/cargo.nix @@ -116,6 +116,8 @@ rustPlatform.buildRustPackage.override rustPlatform.rust.rustc.unwrapped ]; + __structuredAttrs = true; + meta = { homepage = "https://crates.io"; description = "Downloads your Rust project's dependencies and builds your project"; From 4cbf08b937916fc36793d080f5f318a868aa086c Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Fri, 4 Sep 2026 15:33:32 +0200 Subject: [PATCH 061/423] rustc: enable strictDeps --- pkgs/development/compilers/rust/rustc.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/development/compilers/rust/rustc.nix b/pkgs/development/compilers/rust/rustc.nix index f5c09e0740ba..ba1166e2dd60 100644 --- a/pkgs/development/compilers/rust/rustc.nix +++ b/pkgs/development/compilers/rust/rustc.nix @@ -411,6 +411,8 @@ stdenv.mkDerivation (finalAttrs: { ++ optional (!withBundledLLVM) llvmShared.lib ++ optional (useLLVM && !withBundledLLVM) llvmPackages.libunwind; + strictDeps = true; + outputs = [ "out" "man" From 00588fd9037c0f7550f9346ce697010c3cd98b77 Mon Sep 17 00:00:00 2001 From: hakan-demirli Date: Fri, 4 Sep 2026 23:59:34 +0200 Subject: [PATCH 062/423] python3Packages.inline-snapshot: skip documentation tests --- pkgs/development/python-modules/inline-snapshot/default.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/development/python-modules/inline-snapshot/default.nix b/pkgs/development/python-modules/inline-snapshot/default.nix index fd694d13f53d..4997f6756729 100644 --- a/pkgs/development/python-modules/inline-snapshot/default.nix +++ b/pkgs/development/python-modules/inline-snapshot/default.nix @@ -65,6 +65,8 @@ buildPythonPackage rec { disabledTestPaths = [ # Tests don't play nice with pytest-xdist "tests/test_typing.py" + # Sensitive to formatter versions + "tests/test_docs.py" ]; meta = { From 9a1444ff8a464364c34a2870e5fda1bbe9f6bc11 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sandro=20J=C3=A4ckel?= Date: Sat, 5 Sep 2026 18:07:22 +0200 Subject: [PATCH 063/423] go: drop GO111MODULE This defaults to on since go 1.16, see https://go.dev/ref/mod#mod-commands --- pkgs/build-support/go/module.nix | 1 - 1 file changed, 1 deletion(-) diff --git a/pkgs/build-support/go/module.nix b/pkgs/build-support/go/module.nix index b9722cc413a6..a11cd872c596 100644 --- a/pkgs/build-support/go/module.nix +++ b/pkgs/build-support/go/module.nix @@ -219,7 +219,6 @@ lib.extendMkDerivation { env = args.env or { } // { inherit (go) GOOS GOARCH; - GO111MODULE = "on"; GOTOOLCHAIN = "local"; CGO_ENABLED = args.env.CGO_ENABLED or go.CGO_ENABLED; From 704f32146a3f80dfc255ca477f144bc74ca945ed Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Sat, 5 Sep 2026 11:42:31 -0400 Subject: [PATCH 064/423] libmysofa: enable tests --- pkgs/by-name/li/libmysofa/package.nix | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/li/libmysofa/package.nix b/pkgs/by-name/li/libmysofa/package.nix index 360cff5d871d..dc7c0e1f9efd 100644 --- a/pkgs/by-name/li/libmysofa/package.nix +++ b/pkgs/by-name/li/libmysofa/package.nix @@ -3,6 +3,8 @@ stdenv, fetchFromGitHub, cmake, + cunit, + nodejs, zlib, }: @@ -26,10 +28,16 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ zlib ]; + nativeCheckInputs = [ nodejs ]; + + checkInputs = [ cunit ]; + cmakeFlags = [ - (lib.cmakeBool "BUILD_TESTS" false) + (lib.cmakeBool "BUILD_TESTS" finalAttrs.finalPackage.doCheck) ]; + doCheck = true; + __structuredAttrs = true; strictDeps = true; From 39632953ba1618678280b7aa498a07c8cd80acc7 Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Sat, 5 Sep 2026 15:12:28 -0400 Subject: [PATCH 065/423] cmake: 4.4.2 -> 4.4.3 Changelog: https://cmake.org/cmake/help/v4.4/release/4.4.html Diff: https://github.com/Kitware/CMake/compare/v4.4.2...v4.4.3 --- .../cm/cmake/add-nixpkgs-libc-paths.patch | 4 +- .../cm/cmake/darwin-binary-paths.patch | 22 +- .../cm/cmake/darwin-bsd-binary-paths.patch | 20 +- .../cm/cmake/nixpkgs-cmake-prefix-path.patch | 8 +- pkgs/by-name/cm/cmake/package.nix | 4 +- .../cm/cmake/remove-impure-search-paths.patch | 374 +++++++++--------- 6 files changed, 222 insertions(+), 210 deletions(-) diff --git a/pkgs/by-name/cm/cmake/add-nixpkgs-libc-paths.patch b/pkgs/by-name/cm/cmake/add-nixpkgs-libc-paths.patch index 3a1cbf0e11ac..00dda8b8038a 100644 --- a/pkgs/by-name/cm/cmake/add-nixpkgs-libc-paths.patch +++ b/pkgs/by-name/cm/cmake/add-nixpkgs-libc-paths.patch @@ -1,8 +1,8 @@ diff --git a/Modules/Platform/UnixPaths.cmake b/Modules/Platform/UnixPaths.cmake -index e95da44ea4..bdf4155232 100644 +index 9aa659e4fd..ba9974c316 100644 --- a/Modules/Platform/UnixPaths.cmake +++ b/Modules/Platform/UnixPaths.cmake -@@ -71,28 +71,38 @@ +@@ -81,28 +81,38 @@ list(APPEND CMAKE_PLATFORM_IMPLICIT_LINK_DIRECTORIES /lib /lib32 /lib64 /usr/lib /usr/lib32 /usr/lib64 ) diff --git a/pkgs/by-name/cm/cmake/darwin-binary-paths.patch b/pkgs/by-name/cm/cmake/darwin-binary-paths.patch index af9d5af2cfe1..cea6c95ed169 100644 --- a/pkgs/by-name/cm/cmake/darwin-binary-paths.patch +++ b/pkgs/by-name/cm/cmake/darwin-binary-paths.patch @@ -1,21 +1,21 @@ diff --git a/Modules/Platform/Darwin-Initialize.cmake b/Modules/Platform/Darwin-Initialize.cmake -index 196ab18b0b..31dd4346b1 100644 +index c9c88b36f5..0b1fda27d7 100644 --- a/Modules/Platform/Darwin-Initialize.cmake +++ b/Modules/Platform/Darwin-Initialize.cmake -@@ -16,7 +16,7 @@ - endif() +@@ -290,7 +290,7 @@ endif() + # CMAKE_OSX_DEPLOYMENT_TARGET if(NOT CMAKE_CROSSCOMPILING) - execute_process(COMMAND sw_vers -productVersion + execute_process(COMMAND @sw_vers@ -productVersion OUTPUT_VARIABLE _CMAKE_HOST_OSX_VERSION - OUTPUT_STRIP_TRAILING_WHITESPACE) - endif() + OUTPUT_STRIP_TRAILING_WHITESPACE + RESULT_VARIABLE _result) diff --git a/Source/kwsys/SystemInformation.cxx b/Source/kwsys/SystemInformation.cxx -index c65587edbe..0a7cc380c3 100644 +index 743c224437..173ceb0a64 100644 --- a/Source/kwsys/SystemInformation.cxx +++ b/Source/kwsys/SystemInformation.cxx -@@ -3833,7 +3833,7 @@ +@@ -3835,7 +3835,7 @@ long long SystemInformationImplementation::GetHostMemoryUsed() } char const* names[3] = { "Pages wired down:", "Pages active:", nullptr }; long long values[2] = { 0 }; @@ -24,7 +24,7 @@ index c65587edbe..0a7cc380c3 100644 if (ierr) { return -1; } -@@ -5586,7 +5586,7 @@ +@@ -5506,7 +5506,7 @@ int SystemInformationImplementation::CallSwVers(char const* arg, { #ifdef __APPLE__ std::vector args; @@ -34,10 +34,10 @@ index c65587edbe..0a7cc380c3 100644 args.push_back(nullptr); ver = this->RunProcess(args); diff --git a/Tests/CMakeLists.txt b/Tests/CMakeLists.txt -index 15a1e2c0c3..33bb304cf7 100644 +index 8020d96833..d32e6a6693 100644 --- a/Tests/CMakeLists.txt +++ b/Tests/CMakeLists.txt -@@ -1958,7 +1958,7 @@ +@@ -1977,7 +1977,7 @@ if(BUILD_TESTING) if(CMake_TEST_XCODE_VERSION AND NOT CMake_TEST_XCODE_VERSION VERSION_LESS 5) if(NOT CMake_TEST_XCTest_DEPLOYMENT_TARGET) execute_process( @@ -45,4 +45,4 @@ index 15a1e2c0c3..33bb304cf7 100644 + COMMAND @sw_vers@ -productVersion OUTPUT_VARIABLE OSX_VERSION OUTPUT_STRIP_TRAILING_WHITESPACE - ) + RESULT_VARIABLE _sw_vers_result diff --git a/pkgs/by-name/cm/cmake/darwin-bsd-binary-paths.patch b/pkgs/by-name/cm/cmake/darwin-bsd-binary-paths.patch index 8fe699ac2953..4c23425eb79d 100644 --- a/pkgs/by-name/cm/cmake/darwin-bsd-binary-paths.patch +++ b/pkgs/by-name/cm/cmake/darwin-bsd-binary-paths.patch @@ -1,8 +1,8 @@ diff --git a/Modules/CMakeDetermineSystem.cmake b/Modules/CMakeDetermineSystem.cmake -index dc26258eac..dd8d30e3d9 100644 +index c70fea184d..10b18675b0 100644 --- a/Modules/CMakeDetermineSystem.cmake +++ b/Modules/CMakeDetermineSystem.cmake -@@ -68,7 +68,7 @@ +@@ -74,7 +74,7 @@ if(CMAKE_HOST_UNIX) endif() if(_CMAKE_APPLE_SILICON_PROCESSOR) if(";${_CMAKE_APPLE_SILICON_PROCESSOR};" MATCHES "^;(arm64|x86_64);$") @@ -12,10 +12,10 @@ index dc26258eac..dd8d30e3d9 100644 ERROR_VARIABLE _sysctl_stderr RESULT_VARIABLE _sysctl_result diff --git a/Modules/Platform/Darwin-Initialize.cmake b/Modules/Platform/Darwin-Initialize.cmake -index 31dd4346b1..7c4f123a1d 100644 +index 0b1fda27d7..f5491ef048 100644 --- a/Modules/Platform/Darwin-Initialize.cmake +++ b/Modules/Platform/Darwin-Initialize.cmake -@@ -28,7 +28,7 @@ +@@ -22,7 +22,7 @@ set(CMAKE_OSX_ARCHITECTURES "$ENV{CMAKE_OSX_ARCHITECTURES}" CACHE STRING if(NOT CMAKE_CROSSCOMPILING AND CMAKE_SYSTEM_NAME STREQUAL "Darwin" AND CMAKE_HOST_SYSTEM_PROCESSOR MATCHES "^(arm64|x86_64)$") @@ -25,10 +25,10 @@ index 31dd4346b1..7c4f123a1d 100644 ERROR_VARIABLE _sysctl_stderr RESULT_VARIABLE _sysctl_result diff --git a/Modules/ProcessorCount.cmake b/Modules/ProcessorCount.cmake -index 260b6631c0..ffb8fcd8d2 100644 +index b8fa1fabc0..7c3112b817 100644 --- a/Modules/ProcessorCount.cmake +++ b/Modules/ProcessorCount.cmake -@@ -87,8 +87,7 @@ +@@ -87,8 +87,7 @@ function(ProcessorCount var) if(NOT count) # Mac, FreeBSD, OpenBSD (systems with sysctl): @@ -52,10 +52,10 @@ index 8c22b4e43a..6d9ccef5e7 100644 #elif defined(__sun) && (defined(__SVR4) || defined(__svr4__)) /* Solaris */ # define KWSYSPE_PS_COMMAND "ps -e -o pid,ppid" diff --git a/Source/kwsys/SystemInformation.cxx b/Source/kwsys/SystemInformation.cxx -index 0a7cc380c3..9923dc4ab9 100644 +index 173ceb0a64..7bddddf955 100644 --- a/Source/kwsys/SystemInformation.cxx +++ b/Source/kwsys/SystemInformation.cxx -@@ -3876,7 +3876,7 @@ +@@ -3878,7 +3878,7 @@ long long SystemInformationImplementation::GetProcMemoryUsed() long long memUsed = 0; pid_t pid = getpid(); std::ostringstream oss; @@ -65,10 +65,10 @@ index 0a7cc380c3..9923dc4ab9 100644 if (!file) { return -1; diff --git a/Tests/CMakeLists.txt b/Tests/CMakeLists.txt -index 33bb304cf7..7dbda40a81 100644 +index d32e6a6693..683e27ece7 100644 --- a/Tests/CMakeLists.txt +++ b/Tests/CMakeLists.txt -@@ -216,7 +216,7 @@ +@@ -249,7 +249,7 @@ if(BUILD_TESTING) endif() if(CMAKE_SYSTEM_NAME STREQUAL "Darwin" AND NOT DEFINED CMake_TEST_APPLE_SILICON) diff --git a/pkgs/by-name/cm/cmake/nixpkgs-cmake-prefix-path.patch b/pkgs/by-name/cm/cmake/nixpkgs-cmake-prefix-path.patch index 8a572fc08320..896e3aeffe57 100644 --- a/pkgs/by-name/cm/cmake/nixpkgs-cmake-prefix-path.patch +++ b/pkgs/by-name/cm/cmake/nixpkgs-cmake-prefix-path.patch @@ -1,8 +1,8 @@ diff --git a/Source/cmFindBase.cxx b/Source/cmFindBase.cxx -index b8d4765692..902c1e5290 100644 +index e9e8dfd4b9..d115cd1897 100644 --- a/Source/cmFindBase.cxx +++ b/Source/cmFindBase.cxx -@@ -312,6 +312,11 @@ void cmFindBase::FillCMakeEnvironmentPath() +@@ -308,6 +308,11 @@ void cmFindBase::FillCMakeEnvironmentPath() // Add CMAKE_*_PATH environment variables std::string var = cmStrCat("CMAKE_", this->CMakePathName, "_PATH"); paths.AddEnvPrefixPath("CMAKE_PREFIX_PATH"); @@ -15,10 +15,10 @@ index b8d4765692..902c1e5290 100644 if (this->CMakePathName == "PROGRAM") { diff --git a/Source/cmFindPackageCommand.cxx b/Source/cmFindPackageCommand.cxx -index 6201894fd1..9533862a2b 100644 +index 2f2c5c6662..4594afd0e7 100644 --- a/Source/cmFindPackageCommand.cxx +++ b/Source/cmFindPackageCommand.cxx -@@ -2467,6 +2467,7 @@ void cmFindPackageCommand::FillPrefixesCMakeEnvironment() +@@ -2520,6 +2520,7 @@ void cmFindPackageCommand::FillPrefixesCMakeEnvironment() // And now the general CMake environment variables paths.AddEnvPath("CMAKE_PREFIX_PATH"); diff --git a/pkgs/by-name/cm/cmake/package.nix b/pkgs/by-name/cm/cmake/package.nix index 94a68528777c..8d5908b8f5b8 100644 --- a/pkgs/by-name/cm/cmake/package.nix +++ b/pkgs/by-name/cm/cmake/package.nix @@ -52,11 +52,11 @@ stdenv.mkDerivation (finalAttrs: { + lib.optionalString isMinimalBuild "-minimal" + lib.optionalString cursesUI "-cursesUI" + lib.optionalString qt5UI "-qt5UI"; - version = "4.4.2"; + version = "4.4.3"; src = fetchurl { url = "https://cmake.org/files/v${lib.versions.majorMinor finalAttrs.version}/cmake-${finalAttrs.version}.tar.gz"; - hash = "sha256-HbnmHmC24IdMhjhjQLkQOC88XnW5+/tE0SIGMSmieJ0="; + hash = "sha256-xGQAYYtPHytDUH8k+yLzroMMNBbPI7d24W4dQTqokvA="; }; patches = [ diff --git a/pkgs/by-name/cm/cmake/remove-impure-search-paths.patch b/pkgs/by-name/cm/cmake/remove-impure-search-paths.patch index 0e396847f7c6..89d12e93aab1 100644 --- a/pkgs/by-name/cm/cmake/remove-impure-search-paths.patch +++ b/pkgs/by-name/cm/cmake/remove-impure-search-paths.patch @@ -1,8 +1,8 @@ diff --git a/Modules/CMakeDetermineJavaCompiler.cmake b/Modules/CMakeDetermineJavaCompiler.cmake -index b20a255621..bc67fdf4aa 100644 +index f66402e304..175b2235d2 100644 --- a/Modules/CMakeDetermineJavaCompiler.cmake +++ b/Modules/CMakeDetermineJavaCompiler.cmake -@@ -42,19 +42,6 @@ +@@ -42,19 +42,6 @@ if(NOT CMAKE_Java_COMPILER) "[HKEY_LOCAL_MACHINE\\SOFTWARE\\JavaSoft\\Java Development Kit\\1.4;JavaHome]/bin" "[HKEY_LOCAL_MACHINE\\SOFTWARE\\JavaSoft\\Java Development Kit\\1.3;JavaHome]/bin" $ENV{JAVA_HOME}/bin @@ -23,7 +23,7 @@ index b20a255621..bc67fdf4aa 100644 # if no compiler has been specified yet, then look for one if(CMAKE_Java_COMPILER_INIT) diff --git a/Modules/CMakeDetermineSystem.cmake b/Modules/CMakeDetermineSystem.cmake -index dd8d30e3d9..d500364ba5 100644 +index 10b18675b0..3f9b62f02f 100644 --- a/Modules/CMakeDetermineSystem.cmake +++ b/Modules/CMakeDetermineSystem.cmake @@ -9,7 +9,7 @@ @@ -39,7 +39,7 @@ diff --git a/Modules/CMakeFindFrameworks.cmake b/Modules/CMakeFindFrameworks.cma index 87ad38b46b..95f226be40 100644 --- a/Modules/CMakeFindFrameworks.cmake +++ b/Modules/CMakeFindFrameworks.cmake -@@ -39,22 +39,10 @@ +@@ -39,22 +39,10 @@ if(NOT CMAKE_FIND_FRAMEWORKS_INCLUDED) macro(CMAKE_FIND_FRAMEWORKS fwk) set(${fwk}_FRAMEWORKS) if(APPLE) @@ -63,7 +63,7 @@ index 87ad38b46b..95f226be40 100644 # For backwards compatibility reasons, diff --git a/Modules/CMakeFindJavaCommon.cmake b/Modules/CMakeFindJavaCommon.cmake -index 95ca9b57b6..616295e031 100644 +index f3e34936b4..cc4514c1e9 100644 --- a/Modules/CMakeFindJavaCommon.cmake +++ b/Modules/CMakeFindJavaCommon.cmake @@ -15,21 +15,6 @@ else() @@ -89,10 +89,10 @@ index 95ca9b57b6..616295e031 100644 unset(_ENV_JAVA_HOME) endif() diff --git a/Modules/CMakeFindPackageMode.cmake b/Modules/CMakeFindPackageMode.cmake -index 6e2762cf41..f88cf2f7c1 100644 +index 62e33e047f..c5253b9f66 100644 --- a/Modules/CMakeFindPackageMode.cmake +++ b/Modules/CMakeFindPackageMode.cmake -@@ -64,7 +64,7 @@ +@@ -64,7 +64,7 @@ if(UNIX) # from the outside if(NOT CMAKE_SIZEOF_VOID_P) set(CMAKE_SIZEOF_VOID_P 4) @@ -101,7 +101,7 @@ index 6e2762cf41..f88cf2f7c1 100644 set(CMAKE_SIZEOF_VOID_P 8) else() # use the file utility to check whether itself is 64 bit: -@@ -79,22 +79,6 @@ +@@ -81,22 +81,6 @@ if(UNIX) endif() endif() @@ -145,10 +145,10 @@ index fc0ec313b8..46d8418d2c 100644 if(CMAKE_SUBLIMETEXT_EXECUTABLE) diff --git a/Modules/CPackIFW.cmake b/Modules/CPackIFW.cmake -index 2a2f478fd7..f22281bdca 100644 +index 03427823e4..aa6f062581 100644 --- a/Modules/CPackIFW.cmake +++ b/Modules/CPackIFW.cmake -@@ -426,7 +426,7 @@ +@@ -432,7 +432,7 @@ if(WIN32) else() list(APPEND _CPACK_IFW_PATHS "$ENV{HOME}/Qt" @@ -183,10 +183,10 @@ index 9f986a78e7..5a6a9758ea 100644 list(GET _ACML_ROOT 0 _ACML_ROOT) list(GET _ACML_GPU_ROOT 0 _ACML_GPU_ROOT) diff --git a/Modules/FindCUDA.cmake b/Modules/FindCUDA.cmake -index bceb615ca0..2350b15655 100644 +index 96b16598ab..0827dbbd73 100644 --- a/Modules/FindCUDA.cmake +++ b/Modules/FindCUDA.cmake -@@ -854,7 +854,6 @@ +@@ -852,7 +852,6 @@ if(NOT CUDA_TOOLKIT_ROOT_DIR AND NOT CMAKE_CROSSCOMPILING) # Now search default paths find_program(CUDA_TOOLKIT_ROOT_DIR_NVCC NAMES nvcc nvcc.exe @@ -194,7 +194,7 @@ index bceb615ca0..2350b15655 100644 PATH_SUFFIXES cuda/bin DOC "Toolkit location." ) -@@ -1014,7 +1013,6 @@ +@@ -1012,7 +1011,6 @@ macro(cuda_find_library_local_first_with_path_ext _var _names _doc _path_ext ) # Search default search paths, after we search our own set of paths. find_library(${_var} NAMES ${_names} @@ -202,7 +202,7 @@ index bceb615ca0..2350b15655 100644 DOC ${_doc} ) endif() -@@ -1114,11 +1112,6 @@ +@@ -1112,11 +1110,6 @@ elseif(CUDA_USE_STATIC_CUDA_RUNTIME AND CUDA_cudart_static_LIBRARY) if (CUDA_rt_LIBRARY) list(APPEND CUDA_LIBRARIES ${CUDA_rt_LIBRARY}) endif() @@ -214,7 +214,7 @@ index bceb615ca0..2350b15655 100644 else() list(APPEND CUDA_LIBRARIES ${CUDA_CUDART_LIBRARY}) endif() -@@ -1223,8 +1216,6 @@ +@@ -1221,8 +1214,6 @@ find_path(CUDA_SDK_ROOT_DIR common/inc/cutil.h "$ENV{NVSDKCOMPUTE_ROOT}/C" ENV NVSDKCUDA_ROOT "[HKEY_LOCAL_MACHINE\\SOFTWARE\\NVIDIA Corporation\\Installed Products\\NVIDIA SDK 10\\Compute;InstallDir]" @@ -223,7 +223,7 @@ index bceb615ca0..2350b15655 100644 ) # Keep the CUDA_SDK_ROOT_DIR first in order to be able to override the -@@ -1236,7 +1227,6 @@ +@@ -1234,7 +1225,6 @@ set(CUDA_SDK_SEARCH_PATH "${CUDA_TOOLKIT_ROOT_DIR}/NV_CUDA_SDK" "$ENV{HOME}/NVIDIA_CUDA_SDK" "$ENV{HOME}/NVIDIA_CUDA_SDK_MACOSX" @@ -232,10 +232,10 @@ index bceb615ca0..2350b15655 100644 # Example of how to find an include file from the CUDA_SDK_ROOT_DIR diff --git a/Modules/FindCUDAToolkit.cmake b/Modules/FindCUDAToolkit.cmake -index df36f9a19b..825d1e7386 100644 +index 20ca4a47a2..4827c8b8d7 100644 --- a/Modules/FindCUDAToolkit.cmake +++ b/Modules/FindCUDAToolkit.cmake -@@ -830,18 +830,9 @@ else() +@@ -861,18 +861,9 @@ else() # We will also search the default symlink location /usr/local/cuda first since # if CUDAToolkit_ROOT is not specified, it is assumed that the symlinked # directory is the desired location. @@ -255,7 +255,7 @@ index df36f9a19b..825d1e7386 100644 # Iterate the glob results and create a descending list. set(versions) foreach(p ${possible_paths}) -@@ -857,14 +848,6 @@ else() +@@ -888,14 +879,6 @@ else() # With a descending list of versions, populate possible paths to search. set(search_paths) @@ -270,7 +270,7 @@ index df36f9a19b..825d1e7386 100644 # Now search for the toolkit again using the platform default search paths. _CUDAToolkit_find_root_dir(SEARCH_PATHS "${search_paths}" FIND_FLAGS PATH_SUFFIXES bin) -@@ -889,12 +872,6 @@ else() +@@ -920,12 +903,6 @@ else() elseif(CUDAToolkit_ROOT_DIR AND EXISTS "${CUDAToolkit_ROOT_DIR}/${vf}") set(${result_variable} "${CUDAToolkit_ROOT_DIR}/${vf}" PARENT_SCOPE) break() @@ -284,10 +284,10 @@ index df36f9a19b..825d1e7386 100644 endforeach() endfunction() diff --git a/Modules/FindCoin3D.cmake b/Modules/FindCoin3D.cmake -index 1d89c604e0..5b70e71a87 100644 +index 07cbb69e26..f54b31f204 100644 --- a/Modules/FindCoin3D.cmake +++ b/Modules/FindCoin3D.cmake -@@ -76,10 +76,8 @@ +@@ -106,10 +106,8 @@ if (WIN32) else () if(APPLE) find_path(COIN3D_INCLUDE_DIRS Inventor/So.h @@ -299,10 +299,10 @@ index 1d89c604e0..5b70e71a87 100644 set(COIN3D_LIBRARIES "-framework Coin3d" CACHE STRING "Coin3D library for OSX") else() diff --git a/Modules/FindCurses.cmake b/Modules/FindCurses.cmake -index 64600c6c64..de6af241a1 100644 +index c93cb8651a..edaf83b2ec 100644 --- a/Modules/FindCurses.cmake +++ b/Modules/FindCurses.cmake -@@ -136,15 +136,7 @@ +@@ -147,15 +147,7 @@ endif() # message. Cygwin is an ncurses package, so force ncurses on # cygwin if the curses.h is missing if(CURSES_NCURSES_LIBRARY AND CYGWIN) @@ -320,10 +320,10 @@ index 64600c6c64..de6af241a1 100644 diff --git a/Modules/FindDCMTK.cmake b/Modules/FindDCMTK.cmake -index 4e0ff47f52..6db26cb855 100644 +index 181142c4bb..1bff8ec1b5 100644 --- a/Modules/FindDCMTK.cmake +++ b/Modules/FindDCMTK.cmake -@@ -88,14 +88,7 @@ +@@ -158,14 +158,7 @@ files instead: set(_dcmtk_dir_description "The directory of DCMTK build or install tree.") @@ -340,10 +340,10 @@ index 4e0ff47f52..6db26cb855 100644 set(_SAVED_DCMTK_DIR ${DCMTK_DIR}) diff --git a/Modules/FindDart.cmake b/Modules/FindDart.cmake -index 96cce45590..245dffaf21 100644 +index 6d4b9a3e72..a23e33c1c5 100644 --- a/Modules/FindDart.cmake +++ b/Modules/FindDart.cmake -@@ -24,7 +24,6 @@ +@@ -46,7 +46,6 @@ find_path(DART_ROOT README.INSTALL ENV DART_ROOT PATHS ${PROJECT_SOURCE_DIR} @@ -352,10 +352,10 @@ index 96cce45590..245dffaf21 100644 "C:/Program Files" ${PROJECT_SOURCE_DIR}/.. diff --git a/Modules/FindDoxygen.cmake b/Modules/FindDoxygen.cmake -index 2d430994e8..335c733150 100644 +index 888fd2d83e..a84dd74d58 100644 --- a/Modules/FindDoxygen.cmake +++ b/Modules/FindDoxygen.cmake -@@ -755,10 +755,6 @@ +@@ -773,10 +773,6 @@ macro(_Doxygen_find_doxygen) NAMES doxygen PATHS "[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\doxygen_is1;Inno Setup: App Path]/bin" @@ -366,7 +366,7 @@ index 2d430994e8..335c733150 100644 DOC "Doxygen documentation generation tool (https://www.doxygen.nl)" VALIDATOR _Doxygen_version_validator ) -@@ -845,12 +841,6 @@ +@@ -864,12 +860,6 @@ macro(_Doxygen_find_dot) "$ENV{ProgramFiles}/ATT/Graphviz/bin" "C:/Program Files/ATT/Graphviz/bin" [HKEY_LOCAL_MACHINE\\SOFTWARE\\ATT\\Graphviz;InstallPath]/bin @@ -380,10 +380,10 @@ index 2d430994e8..335c733150 100644 ) mark_as_advanced(DOXYGEN_DOT_EXECUTABLE) diff --git a/Modules/FindFontconfig.cmake b/Modules/FindFontconfig.cmake -index 218ad2fbfa..94e6052564 100644 +index 1e37c7c4eb..5c24e9fb5e 100644 --- a/Modules/FindFontconfig.cmake +++ b/Modules/FindFontconfig.cmake -@@ -64,7 +64,6 @@ +@@ -68,7 +68,6 @@ find_path( Fontconfig_INCLUDE_DIR fontconfig/fontconfig.h HINTS ${PKG_FONTCONFIG_INCLUDE_DIRS} @@ -392,10 +392,10 @@ index 218ad2fbfa..94e6052564 100644 find_library( Fontconfig_LIBRARY diff --git a/Modules/FindGLUT.cmake b/Modules/FindGLUT.cmake -index e29758dc1c..d6255f98c2 100644 +index dcb0359f1c..b46b8ccb77 100644 --- a/Modules/FindGLUT.cmake +++ b/Modules/FindGLUT.cmake -@@ -120,12 +120,10 @@ +@@ -125,12 +125,10 @@ else() set(_GLUT_glut_LIB_DIR /boot/develop/lib/x86) else() find_library( GLUT_Xi_LIBRARY Xi @@ -408,7 +408,7 @@ index e29758dc1c..d6255f98c2 100644 ) mark_as_advanced(GLUT_Xmu_LIBRARY) -@@ -145,11 +143,6 @@ +@@ -150,11 +148,6 @@ else() find_path( GLUT_INCLUDE_DIR GL/glut.h PATHS @@ -420,7 +420,7 @@ index e29758dc1c..d6255f98c2 100644 ${_GLUT_INC_DIR} HINTS ${PC_GLUT_INCLUDE_DIRS} -@@ -158,7 +151,6 @@ +@@ -163,7 +156,6 @@ else() find_library( GLUT_glut_LIBRARY glut PATHS @@ -429,10 +429,10 @@ index e29758dc1c..d6255f98c2 100644 HINTS ${PC_GLUT_LIBRARY_DIRS} diff --git a/Modules/FindGTK.cmake b/Modules/FindGTK.cmake -index 6e39f5a989..df231de76e 100644 +index 87325e25b5..f07dc59787 100644 --- a/Modules/FindGTK.cmake +++ b/Modules/FindGTK.cmake -@@ -71,9 +71,6 @@ +@@ -75,9 +75,6 @@ if(UNIX) find_path( GTK_gtk_INCLUDE_PATH NAMES gtk/gtk.h PATH_SUFFIXES gtk-1.2 gtk12 PATHS @@ -442,7 +442,7 @@ index 6e39f5a989..df231de76e 100644 ) # Some Linux distributions (e.g. Red Hat) have glibconfig.h -@@ -84,26 +81,17 @@ +@@ -88,26 +85,17 @@ if(UNIX) find_path( GTK_glibconfig_INCLUDE_PATH NAMES glibconfig.h PATH_SUFFIXES glib/include lib/glib/include include/glib12 PATHS @@ -469,7 +469,7 @@ index 6e39f5a989..df231de76e 100644 ) # -@@ -112,38 +100,26 @@ +@@ -116,38 +104,26 @@ if(UNIX) find_library( GTK_gtk_LIBRARY NAMES gtk gtk12 @@ -509,10 +509,10 @@ index 6e39f5a989..df231de76e 100644 if(GTK_gtk_INCLUDE_PATH diff --git a/Modules/FindGTK2.cmake b/Modules/FindGTK2.cmake -index 9c5bc63272..87f8f81149 100644 +index 2cbb3a6075..68db0ef40b 100644 --- a/Modules/FindGTK2.cmake +++ b/Modules/FindGTK2.cmake -@@ -377,34 +377,12 @@ +@@ -382,34 +382,12 @@ function(_GTK2_FIND_INCLUDE_DIR _var _hdr) "include suffixes = ${_suffixes}") endif() @@ -547,7 +547,7 @@ index 9c5bc63272..87f8f81149 100644 $ENV{GTKMM_BASEPATH}/include $ENV{GTKMM_BASEPATH}/lib [HKEY_CURRENT_USER\\SOFTWARE\\gtkmm\\2.4;Path]/include -@@ -509,8 +487,6 @@ +@@ -514,8 +492,6 @@ function(_GTK2_FIND_LIBRARY _var _lib _expand_vc _append_version) find_library(GTK2_${_var}_LIBRARY_RELEASE NAMES ${_lib_list} PATHS @@ -557,10 +557,10 @@ index 9c5bc63272..87f8f81149 100644 [HKEY_CURRENT_USER\\SOFTWARE\\gtkmm\\2.4;Path]/lib [HKEY_LOCAL_MACHINE\\SOFTWARE\\gtkmm\\2.4;Path]/lib diff --git a/Modules/FindIce.cmake b/Modules/FindIce.cmake -index 82156747d3..cc3f2a64af 100644 +index f672ba86ee..cbe5595183 100644 --- a/Modules/FindIce.cmake +++ b/Modules/FindIce.cmake -@@ -629,11 +629,6 @@ +@@ -634,11 +634,6 @@ function(_Ice_FIND) list(APPEND ice_roots "${ice_location}") endif() endforeach() @@ -572,7 +572,7 @@ index 82156747d3..cc3f2a64af 100644 endif() # Find all Ice programs -@@ -689,7 +684,7 @@ +@@ -695,7 +690,7 @@ function(_Ice_FIND) # In common use on Linux, MacOS X (homebrew) and FreeBSD; prefer # version-specific dir list(APPEND ice_slice_paths @@ -582,10 +582,10 @@ index 82156747d3..cc3f2a64af 100644 "Ice-${Ice_VERSION_SLICE2CPP_FULL}/slice" "Ice-${Ice_VERSION_SLICE2CPP_SHORT}/slice" diff --git a/Modules/FindJNI.cmake b/Modules/FindJNI.cmake -index a70b00f330..1962b55d4a 100644 +index 5ad87279c2..d16db0806d 100644 --- a/Modules/FindJNI.cmake +++ b/Modules/FindJNI.cmake -@@ -367,56 +367,6 @@ if (WIN32) +@@ -367,68 +367,6 @@ if (WIN32) endif() set(_JNI_JAVA_DIRECTORIES_BASE @@ -639,14 +639,26 @@ index a70b00f330..1962b55d4a 100644 - # SuSE specific paths for default JVM - /usr/lib64/jvm/java - /usr/lib64/jvm/jre +- /usr/lib64/jvm/java-26-openjdk +- /usr/lib64/jvm/jre-26-openjdk +- /usr/lib64/jvm/java-25-openjdk +- /usr/lib64/jvm/jre-25-openjdk +- /usr/lib64/jvm/java-21-openjdk +- /usr/lib64/jvm/jre-21-openjdk +- /usr/lib64/jvm/java-17-openjdk +- /usr/lib64/jvm/jre-17-openjdk +- /usr/lib64/jvm/java-11-openjdk +- /usr/lib64/jvm/jre-11-openjdk +- /usr/lib64/jvm/java-1.8.0-openjdk +- /usr/lib64/jvm/jre-1.8.0-openjdk ) set(_JNI_JAVA_AWT_LIBRARY_TRIES) diff --git a/Modules/FindJava.cmake b/Modules/FindJava.cmake -index 1587ce648b..e92213cba7 100644 +index 09e9fd7a7a..dad434ec86 100644 --- a/Modules/FindJava.cmake +++ b/Modules/FindJava.cmake -@@ -199,17 +199,6 @@ +@@ -207,17 +207,6 @@ endif() # Hard-coded guesses should still go in PATHS. This ensures that the user # environment can always override hard guesses. set(_JAVA_PATHS @@ -665,10 +677,10 @@ index 1587ce648b..e92213cba7 100644 find_program(Java_JAVA_EXECUTABLE NAMES java diff --git a/Modules/FindKDE3.cmake b/Modules/FindKDE3.cmake -index ccfad5e7fb..265e99eb1a 100644 +index bc6b0e420e..3da4206065 100644 --- a/Modules/FindKDE3.cmake +++ b/Modules/FindKDE3.cmake -@@ -234,9 +234,6 @@ +@@ -240,9 +240,6 @@ find_package(X11 ${_REQ_STRING_KDE3}) find_program(KDECONFIG_EXECUTABLE NAMES kde-config HINTS $ENV{KDEDIR}/bin @@ -678,7 +690,7 @@ index ccfad5e7fb..265e99eb1a 100644 ) set(KDE3PREFIX) -@@ -261,9 +258,6 @@ +@@ -267,9 +264,6 @@ find_path(KDE3_INCLUDE_DIR kpassdlg.h HINTS $ENV{KDEDIR}/include ${KDE3PREFIX}/include @@ -688,7 +700,7 @@ index ccfad5e7fb..265e99eb1a 100644 PATH_SUFFIXES include/kde ) -@@ -272,9 +266,6 @@ +@@ -278,9 +272,6 @@ find_library(KDE3_KDECORE_LIBRARY NAMES kdecore HINTS $ENV{KDEDIR}/lib ${KDE3PREFIX}/lib @@ -698,7 +710,7 @@ index ccfad5e7fb..265e99eb1a 100644 ) set(QT_AND_KDECORE_LIBS ${QT_LIBRARIES} ${KDE3_KDECORE_LIBRARY}) -@@ -296,27 +287,18 @@ +@@ -302,27 +293,18 @@ find_program(KDE3_DCOPIDL_EXECUTABLE NAMES dcopidl HINTS $ENV{KDEDIR}/bin ${KDE3PREFIX}/bin @@ -727,10 +739,10 @@ index ccfad5e7fb..265e99eb1a 100644 diff --git a/Modules/FindKDE4.cmake b/Modules/FindKDE4.cmake -index 220906b2de..7eb7b692d8 100644 +index 04c76da73d..0b78a56867 100644 --- a/Modules/FindKDE4.cmake +++ b/Modules/FindKDE4.cmake -@@ -52,7 +52,6 @@ +@@ -248,7 +248,6 @@ find_program(KDE4_KDECONFIG_EXECUTABLE NAMES kde4-config HINTS ${CMAKE_INSTALL_PREFIX} ${_KDEDIRS} @@ -739,10 +751,10 @@ index 220906b2de..7eb7b692d8 100644 ) diff --git a/Modules/FindLATEX.cmake b/Modules/FindLATEX.cmake -index e272770af3..9f702c3f6d 100644 +index 7db4fc6805..66d92e9c42 100644 --- a/Modules/FindLATEX.cmake +++ b/Modules/FindLATEX.cmake -@@ -203,14 +203,12 @@ +@@ -209,14 +209,12 @@ endif () find_program(LATEX_COMPILER NAMES latex PATHS ${MIKTEX_BINARY_PATH} @@ -757,7 +769,7 @@ index e272770af3..9f702c3f6d 100644 ) if (PDFLATEX_COMPILER) set(LATEX_PDFLATEX_FOUND TRUE) -@@ -222,7 +220,6 @@ +@@ -228,7 +226,6 @@ endif() find_program(XELATEX_COMPILER NAMES xelatex PATHS ${MIKTEX_BINARY_PATH} @@ -765,7 +777,7 @@ index e272770af3..9f702c3f6d 100644 ) if (XELATEX_COMPILER) set(LATEX_XELATEX_FOUND TRUE) -@@ -234,7 +231,6 @@ +@@ -240,7 +237,6 @@ endif() find_program(LUALATEX_COMPILER NAMES lualatex PATHS ${MIKTEX_BINARY_PATH} @@ -773,7 +785,7 @@ index e272770af3..9f702c3f6d 100644 ) if (LUALATEX_COMPILER) set(LATEX_LUALATEX_FOUND TRUE) -@@ -246,7 +242,6 @@ +@@ -252,7 +248,6 @@ endif() find_program(BIBTEX_COMPILER NAMES bibtex PATHS ${MIKTEX_BINARY_PATH} @@ -781,7 +793,7 @@ index e272770af3..9f702c3f6d 100644 ) if (BIBTEX_COMPILER) set(LATEX_BIBTEX_FOUND TRUE) -@@ -258,7 +253,6 @@ +@@ -264,7 +259,6 @@ endif() find_program(BIBER_COMPILER NAMES biber PATHS ${MIKTEX_BINARY_PATH} @@ -789,7 +801,7 @@ index e272770af3..9f702c3f6d 100644 ) if (BIBER_COMPILER) set(LATEX_BIBER_FOUND TRUE) -@@ -270,7 +264,6 @@ +@@ -276,7 +270,6 @@ endif() find_program(MAKEINDEX_COMPILER NAMES makeindex PATHS ${MIKTEX_BINARY_PATH} @@ -797,7 +809,7 @@ index e272770af3..9f702c3f6d 100644 ) if (MAKEINDEX_COMPILER) set(LATEX_MAKEINDEX_FOUND TRUE) -@@ -282,7 +275,6 @@ +@@ -288,7 +281,6 @@ endif() find_program(XINDY_COMPILER NAMES xindy PATHS ${MIKTEX_BINARY_PATH} @@ -805,7 +817,7 @@ index e272770af3..9f702c3f6d 100644 ) if (XINDY_COMPILER) set(LATEX_XINDY_FOUND TRUE) -@@ -294,7 +286,6 @@ +@@ -300,7 +292,6 @@ endif() find_program(DVIPS_CONVERTER NAMES dvips PATHS ${MIKTEX_BINARY_PATH} @@ -813,7 +825,7 @@ index e272770af3..9f702c3f6d 100644 ) if (DVIPS_CONVERTER) set(LATEX_DVIPS_FOUND TRUE) -@@ -306,7 +297,6 @@ +@@ -312,7 +303,6 @@ endif() find_program(DVIPDF_CONVERTER NAMES dvipdfm dvipdft dvipdf PATHS ${MIKTEX_BINARY_PATH} @@ -821,7 +833,7 @@ index e272770af3..9f702c3f6d 100644 ) if (DVIPDF_CONVERTER) set(LATEX_DVIPDF_FOUND TRUE) -@@ -336,7 +326,6 @@ +@@ -342,7 +332,6 @@ endif() find_program(PDFTOPS_CONVERTER NAMES pdftops PATHS ${MIKTEX_BINARY_PATH} @@ -829,7 +841,7 @@ index e272770af3..9f702c3f6d 100644 ) if (PDFTOPS_CONVERTER) set(LATEX_PDFTOPS_FOUND TRUE) -@@ -348,7 +337,6 @@ +@@ -354,7 +343,6 @@ endif() find_program(LATEX2HTML_CONVERTER NAMES latex2html PATHS ${MIKTEX_BINARY_PATH} @@ -837,7 +849,7 @@ index e272770af3..9f702c3f6d 100644 ) if (LATEX2HTML_CONVERTER) set(LATEX_LATEX2HTML_FOUND TRUE) -@@ -360,7 +348,6 @@ +@@ -366,7 +354,6 @@ endif() find_program(HTLATEX_COMPILER NAMES htlatex PATHS ${MIKTEX_BINARY_PATH} @@ -846,10 +858,10 @@ index e272770af3..9f702c3f6d 100644 if (HTLATEX_COMPILER) set(LATEX_HTLATEX_FOUND TRUE) diff --git a/Modules/FindLua50.cmake b/Modules/FindLua50.cmake -index ac36c86640..fe5d2147e8 100644 +index 0651a56708..c3228777f9 100644 --- a/Modules/FindLua50.cmake +++ b/Modules/FindLua50.cmake -@@ -84,10 +84,6 @@ +@@ -102,10 +102,6 @@ find_path(LUA_INCLUDE_DIR lua.h HINTS ENV LUA_DIR PATH_SUFFIXES lua50 lua5.0 lua5 lua @@ -860,7 +872,7 @@ index ac36c86640..fe5d2147e8 100644 ) find_library(LUA_LIBRARY_lua -@@ -95,10 +91,6 @@ +@@ -113,10 +109,6 @@ find_library(LUA_LIBRARY_lua HINTS ENV LUA_DIR PATH_SUFFIXES lib @@ -871,7 +883,7 @@ index ac36c86640..fe5d2147e8 100644 ) # In an OS X framework, lualib is usually included as part of the framework -@@ -113,7 +105,6 @@ +@@ -131,7 +123,6 @@ else() ENV LUA_DIR PATH_SUFFIXES lib PATHS @@ -880,10 +892,10 @@ index ac36c86640..fe5d2147e8 100644 if(LUA_LIBRARY_lualib AND LUA_LIBRARY_lua) # include the math library for Unix diff --git a/Modules/FindLua51.cmake b/Modules/FindLua51.cmake -index cba30e4b58..21a95cb89f 100644 +index ad8a8ea373..9bc6dcb598 100644 --- a/Modules/FindLua51.cmake +++ b/Modules/FindLua51.cmake -@@ -87,10 +87,6 @@ +@@ -115,10 +115,6 @@ find_path(LUA_INCLUDE_DIR lua.h HINTS ENV LUA_DIR PATH_SUFFIXES lua51 lua5.1 lua-5.1 lua @@ -894,7 +906,7 @@ index cba30e4b58..21a95cb89f 100644 ) find_library(LUA_LIBRARY -@@ -98,10 +94,6 @@ +@@ -126,10 +122,6 @@ find_library(LUA_LIBRARY HINTS ENV LUA_DIR PATH_SUFFIXES lib @@ -906,10 +918,10 @@ index cba30e4b58..21a95cb89f 100644 if(LUA_LIBRARY) diff --git a/Modules/FindMPI.cmake b/Modules/FindMPI.cmake -index 78b1c5c915..741f86aaef 100644 +index ebfd79fe3e..4f22333eb1 100644 --- a/Modules/FindMPI.cmake +++ b/Modules/FindMPI.cmake -@@ -1349,15 +1349,6 @@ +@@ -1510,15 +1510,6 @@ macro(MPI_search_mpi_prefix_folder PREFIX_FOLDER) endmacro() set(MPI_HINT_DIRS ${MPI_HOME} $ENV{MPI_HOME} $ENV{I_MPI_ROOT}) @@ -926,10 +938,10 @@ index 78b1c5c915..741f86aaef 100644 # Most MPI distributions have some form of mpiexec or mpirun which gives us something we can look for. # The MPI standard does not mandate the existence of either, but instead only makes requirements if a distribution diff --git a/Modules/FindMatlab.cmake b/Modules/FindMatlab.cmake -index 8a7bd80957..74009fbebc 100644 +index 5f7c83bc51..5890068ba7 100644 --- a/Modules/FindMatlab.cmake +++ b/Modules/FindMatlab.cmake -@@ -1529,7 +1529,7 @@ +@@ -1749,7 +1749,7 @@ function(_Matlab_find_instances_macos matlab_roots) endif() foreach(_matlab_current_release IN LISTS _matlab_releases) @@ -939,10 +951,10 @@ index 8a7bd80957..74009fbebc 100644 string(REPLACE "." "" _matlab_current_version_without_dot "${_matlab_current_version}") set(_matlab_base_path "${_macos_app_base}/MATLAB_${_matlab_current_release}.app") diff --git a/Modules/FindMotif.cmake b/Modules/FindMotif.cmake -index d72b19309e..5753e5c3dc 100644 +index 1ce164c157..f700305dd6 100644 --- a/Modules/FindMotif.cmake +++ b/Modules/FindMotif.cmake -@@ -39,12 +39,10 @@ +@@ -69,12 +69,10 @@ project target: if(UNIX) find_path(MOTIF_INCLUDE_DIR Xm/Xm.h @@ -956,10 +968,10 @@ index d72b19309e..5753e5c3dc 100644 endif() diff --git a/Modules/FindOpenAL.cmake b/Modules/FindOpenAL.cmake -index dad9ada128..32d02db7c3 100644 +index 766c563824..4bc2a7c887 100644 --- a/Modules/FindOpenAL.cmake +++ b/Modules/FindOpenAL.cmake -@@ -95,9 +95,6 @@ +@@ -109,9 +109,6 @@ find_path(OPENAL_INCLUDE_DIR al.h HINTS ENV OPENALDIR PATHS @@ -969,7 +981,7 @@ index dad9ada128..32d02db7c3 100644 [HKEY_LOCAL_MACHINE\\SOFTWARE\\Creative\ Labs\\OpenAL\ 1.1\ Software\ Development\ Kit\\1.00.0000;InstallDir] PATH_SUFFIXES include/AL include/OpenAL include AL OpenAL ) -@@ -113,9 +110,6 @@ +@@ -127,9 +124,6 @@ find_library(OPENAL_LIBRARY HINTS ENV OPENALDIR PATHS @@ -980,10 +992,10 @@ index dad9ada128..32d02db7c3 100644 PATH_SUFFIXES libx32 lib64 lib libs64 libs ${_OpenAL_ARCH_DIR} ) diff --git a/Modules/FindOpenCL.cmake b/Modules/FindOpenCL.cmake -index 3be945ba1b..4086ebe2f2 100644 +index ff4e1d2c9d..b2893cc9cd 100644 --- a/Modules/FindOpenCL.cmake +++ b/Modules/FindOpenCL.cmake -@@ -113,8 +113,6 @@ +@@ -159,8 +159,6 @@ find_path(OpenCL_INCLUDE_DIR ENV CUDA_PATH ENV ATISTREAMSDKROOT ENV OCL_ROOT @@ -992,7 +1004,7 @@ index 3be945ba1b..4086ebe2f2 100644 PATH_SUFFIXES include OpenCL/common/inc -@@ -170,8 +168,6 @@ +@@ -216,8 +214,6 @@ else() PATHS ENV AMDAPPSDKROOT ENV CUDA_PATH @@ -1001,7 +1013,7 @@ index 3be945ba1b..4086ebe2f2 100644 PATH_SUFFIXES lib/x86 lib) -@@ -181,8 +177,6 @@ +@@ -227,8 +223,6 @@ else() PATHS ENV AMDAPPSDKROOT ENV CUDA_PATH @@ -1011,10 +1023,10 @@ index 3be945ba1b..4086ebe2f2 100644 lib/x86_64 lib/x64 diff --git a/Modules/FindOpenGL.cmake b/Modules/FindOpenGL.cmake -index a842756fcf..a02a66eb60 100644 +index 101dbad77e..4bcb5fe6bd 100644 --- a/Modules/FindOpenGL.cmake +++ b/Modules/FindOpenGL.cmake -@@ -271,12 +271,7 @@ +@@ -390,12 +390,7 @@ else() set(_OPENGL_INCLUDE_PATH /boot/develop/headers/os/opengl) elseif (CMAKE_SYSTEM_NAME STREQUAL "Linux") @@ -1028,7 +1040,7 @@ index a842756fcf..a02a66eb60 100644 endif() # The first line below is to make sure that the proper headers -@@ -287,9 +282,6 @@ +@@ -406,9 +401,6 @@ else() # Make sure the NVIDIA directory comes BEFORE the others. # - Atanas Georgiev find_path(OPENGL_INCLUDE_DIR GL/gl.h @@ -1038,7 +1050,7 @@ index a842756fcf..a02a66eb60 100644 ${_OPENGL_INCLUDE_PATH} ) find_path(OPENGL_GLX_INCLUDE_DIR GL/glx.h ${_OPENGL_INCLUDE_PATH}) -@@ -297,9 +289,6 @@ +@@ -416,9 +408,6 @@ else() find_path(OPENGL_GLES2_INCLUDE_DIR GLES2/gl2.h ${_OPENGL_INCLUDE_PATH}) find_path(OPENGL_GLES3_INCLUDE_DIR GLES3/gl3.h ${_OPENGL_INCLUDE_PATH}) find_path(OPENGL_xmesa_INCLUDE_DIR GL/xmesa.h @@ -1048,7 +1060,7 @@ index a842756fcf..a02a66eb60 100644 ) find_path(OPENGL_GLU_INCLUDE_DIR GL/glu.h ${_OPENGL_INCLUDE_PATH}) -@@ -347,9 +336,6 @@ +@@ -466,9 +455,6 @@ else() find_library(OPENGL_glu_LIBRARY NAMES GLU MesaGLU PATHS ${OPENGL_gl_LIBRARY} @@ -1058,7 +1070,7 @@ index a842756fcf..a02a66eb60 100644 ) list(APPEND _OpenGL_CACHE_VARS -@@ -401,10 +387,7 @@ +@@ -520,10 +506,7 @@ else() # Search for the legacy GL library. find_library(OPENGL_gl_LIBRARY NAMES GL MesaGL @@ -1070,7 +1082,7 @@ index a842756fcf..a02a66eb60 100644 PATH_SUFFIXES libglvnd ) list(APPEND _OpenGL_CACHE_VARS OPENGL_gl_LIBRARY) -@@ -513,9 +496,6 @@ +@@ -636,9 +619,6 @@ else() find_library(OPENGL_glu_LIBRARY NAMES GLU MesaGLU PATHS ${OPENGL_gl_LIBRARY} @@ -1081,10 +1093,10 @@ index a842756fcf..a02a66eb60 100644 endif () diff --git a/Modules/FindPHP4.cmake b/Modules/FindPHP4.cmake -index edef791cb8..5515f44710 100644 +index 46509fed52..c2ccc2fee1 100644 --- a/Modules/FindPHP4.cmake +++ b/Modules/FindPHP4.cmake -@@ -36,15 +36,9 @@ +@@ -48,15 +48,9 @@ Finding PHP: #]=======================================================================] set(PHP4_POSSIBLE_INCLUDE_PATHS @@ -1127,10 +1139,10 @@ index fbe1aade72..34562e7807 100644 endif () diff --git a/Modules/FindPhysFS.cmake b/Modules/FindPhysFS.cmake -index 1894498d9d..03c6e61853 100644 +index 6031d17bf9..2685d2017f 100644 --- a/Modules/FindPhysFS.cmake +++ b/Modules/FindPhysFS.cmake -@@ -52,10 +52,6 @@ +@@ -68,10 +68,6 @@ find_path(PHYSFS_INCLUDE_DIR physfs.h HINTS ENV PHYSFSDIR PATH_SUFFIXES include/physfs include @@ -1141,7 +1153,7 @@ index 1894498d9d..03c6e61853 100644 ) find_library(PHYSFS_LIBRARY -@@ -63,10 +59,6 @@ +@@ -79,10 +75,6 @@ find_library(PHYSFS_LIBRARY HINTS ENV PHYSFSDIR PATH_SUFFIXES lib @@ -1153,10 +1165,10 @@ index 1894498d9d..03c6e61853 100644 include(FindPackageHandleStandardArgs) diff --git a/Modules/FindPkgConfig.cmake b/Modules/FindPkgConfig.cmake -index b230eb5ef5..bf7b204406 100644 +index 924284a46e..75692d033e 100644 --- a/Modules/FindPkgConfig.cmake +++ b/Modules/FindPkgConfig.cmake -@@ -391,7 +391,7 @@ +@@ -845,7 +845,7 @@ macro(_pkg_set_path_internal) if(NOT DEFINED CMAKE_SYSTEM_NAME OR (CMAKE_SYSTEM_NAME MATCHES "^(Linux|GNU)$" AND NOT CMAKE_CROSSCOMPILING)) @@ -1166,10 +1178,10 @@ index b230eb5ef5..bf7b204406 100644 list(APPEND _lib_dirs "lib/${CMAKE_LIBRARY_ARCHITECTURE}/pkgconfig") endif() diff --git a/Modules/FindProducer.cmake b/Modules/FindProducer.cmake -index 1d034bc207..d176655f46 100644 +index 7fbd837344..a09978f7aa 100644 --- a/Modules/FindProducer.cmake +++ b/Modules/FindProducer.cmake -@@ -100,9 +100,6 @@ +@@ -116,9 +116,6 @@ find_path(PRODUCER_INCLUDE_DIR Producer/CameraGroup ENV OSGDIR PATH_SUFFIXES include PATHS @@ -1179,7 +1191,7 @@ index 1d034bc207..d176655f46 100644 [HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Session\ Manager\\Environment;OpenThreads_ROOT] [HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Session\ Manager\\Environment;OSG_ROOT] ) -@@ -114,8 +111,6 @@ +@@ -130,8 +127,6 @@ find_library(PRODUCER_LIBRARY ENV OSG_DIR ENV OSGDIR PATH_SUFFIXES lib @@ -1189,10 +1201,10 @@ index 1d034bc207..d176655f46 100644 include(FindPackageHandleStandardArgs) diff --git a/Modules/FindPython/Support.cmake b/Modules/FindPython/Support.cmake -index a9441646d1..28ba743f60 100644 +index de9fba3a76..96b70fdd72 100644 --- a/Modules/FindPython/Support.cmake +++ b/Modules/FindPython/Support.cmake -@@ -162,9 +162,6 @@ +@@ -162,9 +162,6 @@ macro (_PYTHON_FIND_FRAMEWORKS) file(TO_CMAKE_PATH "$ENV{CMAKE_FRAMEWORK_PATH}" _pff_CMAKE_FRAMEWORK_PATH) set (_pff_frameworks ${CMAKE_FRAMEWORK_PATH} ${_pff_CMAKE_FRAMEWORK_PATH} @@ -1203,10 +1215,10 @@ index a9441646d1..28ba743f60 100644 list (REMOVE_DUPLICATES _pff_frameworks) foreach (_pff_implementation IN LISTS _${_PYTHON_PREFIX}_FIND_IMPLEMENTATIONS) diff --git a/Modules/FindQt.cmake b/Modules/FindQt.cmake -index 98cd1e2abf..90ad88365d 100644 +index 9fc83e6279..6a140bac21 100644 --- a/Modules/FindQt.cmake +++ b/Modules/FindQt.cmake -@@ -63,44 +63,6 @@ +@@ -68,44 +68,6 @@ if(_findqt_testing) return() endif() @@ -1251,7 +1263,7 @@ index 98cd1e2abf..90ad88365d 100644 if (Qt_FIND_VERSION) if (Qt_FIND_VERSION MATCHES "^([34])(\\.[0-9]+.*)?$") set(DESIRED_QT_VERSION ${CMAKE_MATCH_1}) -@@ -135,9 +97,6 @@ +@@ -140,9 +102,6 @@ find_file( QT4_QGLOBAL_H_FILE qglobal.h "[HKEY_CURRENT_USER\\Software\\Trolltech\\Versions\\4.0.0;InstallDir]/include/Qt" ${qt_headers}/Qt $ENV{QTDIR}/include/Qt @@ -1261,7 +1273,7 @@ index 98cd1e2abf..90ad88365d 100644 C:/Progra~1/qt/include/Qt PATH_SUFFIXES qt/include/Qt include/Qt) -@@ -152,9 +111,6 @@ +@@ -157,9 +116,6 @@ find_file( QT3_QGLOBAL_H_FILE qglobal.h "[HKEY_CURRENT_USER\\Software\\Trolltech\\Qt3Versions\\3.1.0;InstallDir]/include/Qt" C:/Qt/3.3.3Educational/include $ENV{QTDIR}/include @@ -1272,10 +1284,10 @@ index 98cd1e2abf..90ad88365d 100644 PATH_SUFFIXES qt/include include/qt3) diff --git a/Modules/FindQt3.cmake b/Modules/FindQt3.cmake -index 2c62a5f17f..772a8d88f6 100644 +index f72261ea0e..7617702faa 100644 --- a/Modules/FindQt3.cmake +++ b/Modules/FindQt3.cmake -@@ -101,10 +101,6 @@ +@@ -125,10 +125,6 @@ if(Qt4_FOUND) endif() @@ -1286,7 +1298,7 @@ index 2c62a5f17f..772a8d88f6 100644 find_path(QT_INCLUDE_DIR NAMES qt.h PATHS -@@ -112,10 +108,7 @@ +@@ -136,10 +132,7 @@ find_path(QT_INCLUDE_DIR "[HKEY_CURRENT_USER\\Software\\Trolltech\\Qt3Versions\\3.2.0;InstallDir]/include/Qt" "[HKEY_CURRENT_USER\\Software\\Trolltech\\Qt3Versions\\3.1.0;InstallDir]/include/Qt" $ENV{QTDIR}/include @@ -1297,15 +1309,15 @@ index 2c62a5f17f..772a8d88f6 100644 PATH_SUFFIXES lib/qt/include lib/qt3/include include/qt include/qt3 qt/include qt3/include ) -@@ -137,7 +130,6 @@ - set(QT_VERSION_STRING "${qt_version_str}") +@@ -162,7 +155,6 @@ if(QT_INCLUDE_DIR) + set(QT_VERSION_STRING "${Qt3_VERSION}") endif() -file(GLOB GLOB_PATHS_LIB /usr/lib/qt-3*/lib/) if (QT_MT_REQUIRED) find_library(QT_QT_LIBRARY NAMES -@@ -148,8 +140,6 @@ +@@ -173,8 +165,6 @@ if (QT_MT_REQUIRED) "[HKEY_CURRENT_USER\\Software\\Trolltech\\Qt3Versions\\3.2.0;InstallDir]" "[HKEY_CURRENT_USER\\Software\\Trolltech\\Qt3Versions\\3.1.0;InstallDir]" ENV QTDIR @@ -1314,7 +1326,7 @@ index 2c62a5f17f..772a8d88f6 100644 C:/Progra~1/qt PATH_SUFFIXES lib lib/qt lib/qt3 qt qt3 qt/lib qt3/lib -@@ -166,8 +156,6 @@ +@@ -191,8 +181,6 @@ else () "[HKEY_CURRENT_USER\\Software\\Trolltech\\Qt3Versions\\3.2.0;InstallDir]" "[HKEY_CURRENT_USER\\Software\\Trolltech\\Qt3Versions\\3.1.0;InstallDir]" ENV QTDIR @@ -1323,7 +1335,7 @@ index 2c62a5f17f..772a8d88f6 100644 C:/Progra~1/qt/lib PATH_SUFFIXES lib lib/qt lib/qt3 qt qt3 qt/lib qt3/lib -@@ -182,8 +170,6 @@ +@@ -207,8 +195,6 @@ find_library(QT_QASSISTANTCLIENT_LIBRARY "[HKEY_CURRENT_USER\\Software\\Trolltech\\Qt3Versions\\3.2.0;InstallDir]" "[HKEY_CURRENT_USER\\Software\\Trolltech\\Qt3Versions\\3.1.0;InstallDir]" ENV QTDIR @@ -1332,7 +1344,7 @@ index 2c62a5f17f..772a8d88f6 100644 C:/Progra~1/qt PATH_SUFFIXES lib lib/qt lib/qt3 qt qt3 qt/lib qt3/lib -@@ -198,8 +184,6 @@ +@@ -223,8 +209,6 @@ find_program(QT_MOC_EXECUTABLE "[HKEY_CURRENT_USER\\Software\\Trolltech\\Qt3Versions\\3.2.1;InstallDir]/include/Qt" "[HKEY_CURRENT_USER\\Software\\Trolltech\\Qt3Versions\\3.2.0;InstallDir]/include/Qt" "[HKEY_CURRENT_USER\\Software\\Trolltech\\Qt3Versions\\3.1.0;InstallDir]/include/Qt" @@ -1341,7 +1353,7 @@ index 2c62a5f17f..772a8d88f6 100644 C:/Progra~1/qt PATH_SUFFIXES bin lib/qt lib/qt3 qt qt3 qt/bin qt3/bin lib/qt/bin lib/qt3/bin -@@ -218,8 +202,6 @@ +@@ -243,8 +227,6 @@ find_program(QT_UIC_EXECUTABLE "[HKEY_CURRENT_USER\\Software\\Trolltech\\Qt3Versions\\3.2.1;InstallDir]/include/Qt" "[HKEY_CURRENT_USER\\Software\\Trolltech\\Qt3Versions\\3.2.0;InstallDir]/include/Qt" "[HKEY_CURRENT_USER\\Software\\Trolltech\\Qt3Versions\\3.1.0;InstallDir]/include/Qt" @@ -1351,7 +1363,7 @@ index 2c62a5f17f..772a8d88f6 100644 PATH_SUFFIXES bin lib/qt lib/qt3 qt qt3 qt/bin qt3/bin lib/qt/bin lib/qt3/bin diff --git a/Modules/FindRuby.cmake b/Modules/FindRuby.cmake -index 863f70a7f2..17e3ac606a 100644 +index 6f865da129..831ca2251b 100644 --- a/Modules/FindRuby.cmake +++ b/Modules/FindRuby.cmake @@ -366,11 +366,6 @@ if (NOT Ruby_EXECUTABLE AND Ruby_FIND_VIRTUALENV MATCHES "^(FIRST|ONLY)$") @@ -1367,10 +1379,10 @@ index 863f70a7f2..17e3ac606a 100644 if (NOT Ruby_EXECUTABLE AND NOT Ruby_FIND_VIRTUALENV STREQUAL "ONLY") _RUBY_CHECK_SYSTEM() diff --git a/Modules/FindSDL.cmake b/Modules/FindSDL.cmake -index a720dcc3df..73e222a27c 100644 +index 5bd34bb642..7e53285860 100644 --- a/Modules/FindSDL.cmake +++ b/Modules/FindSDL.cmake -@@ -214,8 +214,6 @@ +@@ -220,8 +220,6 @@ if(NOT SDL_BUILDING_LIBRARY) HINTS ENV SDLDIR PATH_SUFFIXES lib ${VC_LIB_PATH_SUFFIX} @@ -1380,10 +1392,10 @@ index a720dcc3df..73e222a27c 100644 endif() endif() diff --git a/Modules/FindSDL_sound.cmake b/Modules/FindSDL_sound.cmake -index 954303f3d3..26a5781e2a 100644 +index 19fc2cd081..457a139414 100644 --- a/Modules/FindSDL_sound.cmake +++ b/Modules/FindSDL_sound.cmake -@@ -292,7 +292,6 @@ +@@ -317,7 +317,6 @@ if(SDL_FOUND AND SDL_SOUND_INCLUDE_DIR AND SDL_SOUND_LIBRARY) ENV MIKMODDIR ENV SDLSOUNDDIR ENV SDLDIR @@ -1391,7 +1403,7 @@ index 954303f3d3..26a5781e2a 100644 PATH_SUFFIXES lib ) -@@ -309,7 +308,6 @@ +@@ -334,7 +333,6 @@ if(SDL_FOUND AND SDL_SOUND_INCLUDE_DIR AND SDL_SOUND_LIBRARY) ENV MODPLUGDIR ENV SDLSOUNDDIR ENV SDLDIR @@ -1399,7 +1411,7 @@ index 954303f3d3..26a5781e2a 100644 PATH_SUFFIXES lib ) -@@ -328,7 +326,6 @@ +@@ -353,7 +351,6 @@ if(SDL_FOUND AND SDL_SOUND_INCLUDE_DIR AND SDL_SOUND_LIBRARY) ENV OGGDIR ENV SDLSOUNDDIR ENV SDLDIR @@ -1407,7 +1419,7 @@ index 954303f3d3..26a5781e2a 100644 PATH_SUFFIXES lib ) -@@ -343,7 +340,6 @@ +@@ -368,7 +365,6 @@ if(SDL_FOUND AND SDL_SOUND_INCLUDE_DIR AND SDL_SOUND_LIBRARY) ENV VORBISDIR ENV SDLSOUNDDIR ENV SDLDIR @@ -1415,7 +1427,7 @@ index 954303f3d3..26a5781e2a 100644 PATH_SUFFIXES lib ) -@@ -361,7 +357,6 @@ +@@ -386,7 +382,6 @@ if(SDL_FOUND AND SDL_SOUND_INCLUDE_DIR AND SDL_SOUND_LIBRARY) ENV SMPEGDIR ENV SDLSOUNDDIR ENV SDLDIR @@ -1423,7 +1435,7 @@ index 954303f3d3..26a5781e2a 100644 PATH_SUFFIXES lib ) -@@ -379,7 +374,6 @@ +@@ -404,7 +399,6 @@ if(SDL_FOUND AND SDL_SOUND_INCLUDE_DIR AND SDL_SOUND_LIBRARY) ENV FLACDIR ENV SDLSOUNDDIR ENV SDLDIR @@ -1431,7 +1443,7 @@ index 954303f3d3..26a5781e2a 100644 PATH_SUFFIXES lib ) -@@ -400,7 +394,6 @@ +@@ -425,7 +419,6 @@ if(SDL_FOUND AND SDL_SOUND_INCLUDE_DIR AND SDL_SOUND_LIBRARY) ENV SPEEXDIR ENV SDLSOUNDDIR ENV SDLDIR @@ -1439,7 +1451,7 @@ index 954303f3d3..26a5781e2a 100644 PATH_SUFFIXES lib ) -@@ -419,7 +412,6 @@ +@@ -444,7 +437,6 @@ if(SDL_FOUND AND SDL_SOUND_INCLUDE_DIR AND SDL_SOUND_LIBRARY) ENV SPEEXDIR ENV SDLSOUNDDIR ENV SDLDIR @@ -1448,10 +1460,10 @@ index 954303f3d3..26a5781e2a 100644 ) if(OGG_LIBRARY) diff --git a/Modules/FindX11.cmake b/Modules/FindX11.cmake -index b2f23bd1dd..9a94529589 100644 +index 93aa9329ea..20973713fb 100644 --- a/Modules/FindX11.cmake +++ b/Modules/FindX11.cmake -@@ -138,22 +138,9 @@ +@@ -151,22 +151,9 @@ if (UNIX) set(CMAKE_REQUIRED_QUIET_SAVE ${CMAKE_REQUIRED_QUIET}) set(CMAKE_REQUIRED_QUIET ${X11_FIND_QUIETLY}) set(X11_INC_SEARCH_PATH @@ -1475,10 +1487,10 @@ index b2f23bd1dd..9a94529589 100644 find_path(X11_X11_INCLUDE_PATH X11/X.h ${X11_INC_SEARCH_PATH}) diff --git a/Modules/GNUInstallDirs.cmake b/Modules/GNUInstallDirs.cmake -index ff9c11a9d7..706b34b087 100644 +index d626688c5f..8f87b5c129 100644 --- a/Modules/GNUInstallDirs.cmake +++ b/Modules/GNUInstallDirs.cmake -@@ -336,17 +336,6 @@ +@@ -363,17 +363,6 @@ function(_GNUInstallDirs_get_system_type_for_install out_var) set(${out_var} "conda") endif() endif() @@ -1497,10 +1509,10 @@ index ff9c11a9d7..706b34b087 100644 endfunction() diff --git a/Modules/GetPrerequisites.cmake b/Modules/GetPrerequisites.cmake -index f1f5db7b7b..9b4bdddb36 100644 +index 952e66c0d1..553810fd8c 100644 --- a/Modules/GetPrerequisites.cmake +++ b/Modules/GetPrerequisites.cmake -@@ -458,11 +458,9 @@ +@@ -506,11 +506,9 @@ function(gp_resolve_item context item exepath dirs resolved_item_var) if(NOT resolved) set(ri "ri-NOTFOUND") find_file(ri "${item}" ${exepath} ${dirs} NO_DEFAULT_PATH) @@ -1512,7 +1524,7 @@ index f1f5db7b7b..9b4bdddb36 100644 if(ri) #message(STATUS "info: 'find_file' in exepath/dirs (${ri})") -@@ -472,23 +470,6 @@ +@@ -520,23 +518,6 @@ function(gp_resolve_item context item exepath dirs resolved_item_var) endif() endif() @@ -1537,10 +1549,10 @@ index f1f5db7b7b..9b4bdddb36 100644 # (Converting simple file names into full path names if found.) # diff --git a/Modules/Internal/CMakeCUDAFindToolkit.cmake b/Modules/Internal/CMakeCUDAFindToolkit.cmake -index 8fd408994f..61894813a2 100644 +index ff67ef0755..586e28d8aa 100644 --- a/Modules/Internal/CMakeCUDAFindToolkit.cmake +++ b/Modules/Internal/CMakeCUDAFindToolkit.cmake -@@ -50,18 +50,8 @@ +@@ -50,18 +50,8 @@ macro(cmake_cuda_find_toolkit lang lang_var_) # if CUDAToolkit_ROOT is not specified, it is assumed that the symlinked # directory is the desired location. if(NOT _CUDA_NVCC_EXECUTABLE) @@ -1560,7 +1572,7 @@ index 8fd408994f..61894813a2 100644 # Iterate the glob results and create a descending list. set(versions) foreach(p ${possible_paths}) -@@ -77,14 +67,6 @@ +@@ -77,14 +67,6 @@ macro(cmake_cuda_find_toolkit lang lang_var_) # With a descending list of versions, populate possible paths to search. set(search_paths) @@ -1575,7 +1587,7 @@ index 8fd408994f..61894813a2 100644 # Now search for nvcc again using the platform default search paths. find_program(_CUDA_NVCC_EXECUTABLE -@@ -140,23 +122,13 @@ +@@ -141,23 +123,13 @@ macro(cmake_cuda_find_toolkit lang lang_var_) set(${lang_var_}LIBRARY_ROOT "${_CUDA_COMPILER_LIBRARY_ROOT_FROM_NVVMIR_LIBRARY_DIR}") elseif(EXISTS "${${lang_var_}TOOLKIT_ROOT}/nvvm/libdevice") set(${lang_var_}LIBRARY_ROOT "${${lang_var_}TOOLKIT_ROOT}") @@ -1601,10 +1613,10 @@ index 8fd408994f..61894813a2 100644 # For regular nvcc we the toolkit version is the same as the compiler version and we can parse it from the vendor test output. # For Clang we need to invoke nvcc to get version output. diff --git a/Modules/Internal/CPack/CPackRPM.cmake b/Modules/Internal/CPack/CPackRPM.cmake -index b733cfe964..90709f48e8 100644 +index 84665506d9..2b07f479f0 100644 --- a/Modules/Internal/CPack/CPackRPM.cmake +++ b/Modules/Internal/CPack/CPackRPM.cmake -@@ -640,7 +640,7 @@ +@@ -648,7 +648,7 @@ function(cpack_rpm_debugsymbol_check INSTALL_FILES WORKING_DIR) endif() # With debugedit we prepare source files list @@ -1617,7 +1629,7 @@ diff --git a/Modules/Platform/CYGWIN.cmake b/Modules/Platform/CYGWIN.cmake index cf5e732833..1bbbfeca54 100644 --- a/Modules/Platform/CYGWIN.cmake +++ b/Modules/Platform/CYGWIN.cmake -@@ -15,13 +15,3 @@ +@@ -15,13 +15,3 @@ set(CMAKE_FIND_LIBRARY_SUFFIXES ".dll.a" ".a") set(CMAKE_SHARED_LIBRARY_NAME_WITH_VERSION 1) include(Platform/UnixPaths) @@ -1632,7 +1644,7 @@ index cf5e732833..1bbbfeca54 100644 - /usr/lib/w32api - ) diff --git a/Modules/Platform/Darwin-Initialize.cmake b/Modules/Platform/Darwin-Initialize.cmake -index 7c4f123a1d..4cfd53de9f 100644 +index f5491ef048..1c44eb7fa0 100644 --- a/Modules/Platform/Darwin-Initialize.cmake +++ b/Modules/Platform/Darwin-Initialize.cmake @@ -1,19 +1,7 @@ @@ -1654,9 +1666,9 @@ index 7c4f123a1d..4cfd53de9f 100644 -endif() +set(OSX_DEVELOPER_ROOT "") - if(NOT CMAKE_CROSSCOMPILING) - execute_process(COMMAND @sw_vers@ -productVersion -@@ -277,13 +277,6 @@ if(NOT CMAKE_OSX_SYSROOT) + # Save CMAKE_OSX_ARCHITECTURES from the environment. + set(CMAKE_OSX_ARCHITECTURES "$ENV{CMAKE_OSX_ARCHITECTURES}" CACHE STRING +@@ -277,13 +265,6 @@ if(NOT CMAKE_OSX_SYSROOT) RESULT_VARIABLE _result ) unset(_sdk_macosx) @@ -1671,10 +1683,10 @@ index 7c4f123a1d..4cfd53de9f 100644 #---------------------------------------------------------------------------- diff --git a/Modules/Platform/Darwin.cmake b/Modules/Platform/Darwin.cmake -index 42c6b35424..f2985f3765 100644 +index bd4673248c..9cdbbb964a 100644 --- a/Modules/Platform/Darwin.cmake +++ b/Modules/Platform/Darwin.cmake -@@ -166,7 +166,6 @@ +@@ -156,7 +156,6 @@ endif() # set up the default search directories for frameworks set(CMAKE_SYSTEM_FRAMEWORK_PATH @@ -1682,7 +1694,7 @@ index 42c6b35424..f2985f3765 100644 ) if(_CMAKE_OSX_SYSROOT_PATH) list(APPEND CMAKE_SYSTEM_FRAMEWORK_PATH -@@ -201,10 +200,6 @@ +@@ -191,10 +190,6 @@ if (OSX_DEVELOPER_ROOT AND EXISTS "${OSX_DEVELOPER_ROOT}/Library/Frameworks") list(APPEND CMAKE_SYSTEM_FRAMEWORK_PATH ${OSX_DEVELOPER_ROOT}/Library/Frameworks) endif() @@ -1693,7 +1705,7 @@ index 42c6b35424..f2985f3765 100644 # Warn about known system misconfiguration case. if(CMAKE_OSX_SYSROOT) -@@ -230,10 +225,6 @@ +@@ -220,10 +215,6 @@ endif() # set up the default search directories for application bundles set(_apps_paths) foreach(_path @@ -1704,7 +1716,7 @@ index 42c6b35424..f2985f3765 100644 ) get_filename_component(_apps "${_path}" ABSOLUTE) if(EXISTS "${_apps}") -@@ -249,28 +240,6 @@ +@@ -239,28 +230,6 @@ unset(_apps_paths) include(Platform/UnixPaths) @@ -1733,7 +1745,7 @@ index 42c6b35424..f2985f3765 100644 if(_CMAKE_OSX_SYSROOT_PATH) if(EXISTS ${_CMAKE_OSX_SYSROOT_PATH}/usr/include) list(INSERT CMAKE_SYSTEM_PREFIX_PATH 0 ${_CMAKE_OSX_SYSROOT_PATH}/usr) -@@ -285,7 +254,3 @@ +@@ -275,7 +244,3 @@ if(_CMAKE_OSX_SYSROOT_PATH) endforeach() endif() endif() @@ -1745,7 +1757,7 @@ diff --git a/Modules/Platform/GNU.cmake b/Modules/Platform/GNU.cmake index 6a25b00b81..2430bdb7e4 100644 --- a/Modules/Platform/GNU.cmake +++ b/Modules/Platform/GNU.cmake -@@ -48,13 +48,8 @@ +@@ -48,13 +48,8 @@ else() # checking the platform every time. This option is advanced enough # that only package maintainers should need to adjust it. They are # capable of providing a setting on the command line. @@ -1765,7 +1777,7 @@ diff --git a/Modules/Platform/Linux.cmake b/Modules/Platform/Linux.cmake index 5b61dd6b61..d324b903ed 100644 --- a/Modules/Platform/Linux.cmake +++ b/Modules/Platform/Linux.cmake -@@ -45,25 +45,8 @@ +@@ -45,25 +45,8 @@ else() # checking the platform every time. This option is advanced enough # that only package maintainers should need to adjust it. They are # capable of providing a setting on the command line. @@ -1794,10 +1806,10 @@ index 5b61dd6b61..d324b903ed 100644 - endif() -endif() diff --git a/Modules/Platform/OpenBSD.cmake b/Modules/Platform/OpenBSD.cmake -index 97e2a6a83e..02c607618c 100644 +index 71bb99eb2f..01a1d04ffa 100644 --- a/Modules/Platform/OpenBSD.cmake +++ b/Modules/Platform/OpenBSD.cmake -@@ -31,13 +31,9 @@ +@@ -34,13 +34,9 @@ set(CMAKE_INSTALL_SO_NO_EXE 1) if($ENV{LOCALBASE}) set(OPENBSD_LOCALBASE $ENV{LOCALBASE}) @@ -1815,7 +1827,7 @@ diff --git a/Modules/Platform/SunOS.cmake b/Modules/Platform/SunOS.cmake index e01e892283..d044d81c88 100644 --- a/Modules/Platform/SunOS.cmake +++ b/Modules/Platform/SunOS.cmake -@@ -19,11 +19,6 @@ +@@ -19,11 +19,6 @@ endif() include(Platform/UnixPaths) @@ -1828,7 +1840,7 @@ index e01e892283..d044d81c88 100644 # in the -L path. set(CMAKE_LINK_DEPENDENT_LIBRARY_DIRS 1) diff --git a/Modules/Platform/UnixPaths.cmake b/Modules/Platform/UnixPaths.cmake -index bdf4155232..588064821d 100644 +index ba9974c316..f8f00b487a 100644 --- a/Modules/Platform/UnixPaths.cmake +++ b/Modules/Platform/UnixPaths.cmake @@ -35,10 +35,6 @@ unset(_cmake_running_in_build_tree) @@ -1842,7 +1854,7 @@ index bdf4155232..588064821d 100644 if(_CMAKE_INSTALL_DIR) list(APPEND CMAKE_SYSTEM_PREFIX_PATH # CMake install location -@@ -49,28 +46,6 @@ +@@ -59,28 +55,6 @@ if (NOT CMAKE_FIND_NO_INSTALL_PREFIX) endif() _cmake_record_install_prefix() @@ -1872,10 +1884,10 @@ index bdf4155232..588064821d 100644 if(DEFINED ENV{NIX_CC} AND IS_DIRECTORY "$ENV{NIX_CC}" diff --git a/Modules/Platform/WindowsPaths.cmake b/Modules/Platform/WindowsPaths.cmake -index c56dfaf9ac..4e0b250c1a 100644 +index 0f19b95e85..09143ef09f 100644 --- a/Modules/Platform/WindowsPaths.cmake +++ b/Modules/Platform/WindowsPaths.cmake -@@ -69,11 +69,6 @@ +@@ -79,11 +79,6 @@ if (NOT CMAKE_FIND_NO_INSTALL_PREFIX) endif() _cmake_record_install_prefix() @@ -1888,11 +1900,11 @@ index c56dfaf9ac..4e0b250c1a 100644 ) diff --git a/Modules/ProcessorCount.cmake b/Modules/ProcessorCount.cmake -index ffb8fcd8d2..6b8fcf87dc 100644 +index 7c3112b817..8464875df2 100644 --- a/Modules/ProcessorCount.cmake +++ b/Modules/ProcessorCount.cmake -@@ -128,7 +128,7 @@ - if(NOT count) +@@ -131,7 +131,7 @@ function(ProcessorCount var) + if(NOT (_count_ok EQUAL 0 AND count GREATER 0)) # HPUX (systems with machinfo): find_program(ProcessorCount_cmd_machinfo machinfo - PATHS /usr/contrib/bin) @@ -1900,8 +1912,8 @@ index ffb8fcd8d2..6b8fcf87dc 100644 mark_as_advanced(ProcessorCount_cmd_machinfo) if(ProcessorCount_cmd_machinfo) execute_process(COMMAND ${ProcessorCount_cmd_machinfo} -@@ -160,7 +160,7 @@ - if(NOT count) +@@ -166,7 +166,7 @@ function(ProcessorCount var) + if(NOT count GREATER 0) # AIX (systems with lsconf): find_program(ProcessorCount_cmd_lsconf lsconf - PATHS /usr/sbin) @@ -1909,9 +1921,9 @@ index ffb8fcd8d2..6b8fcf87dc 100644 mark_as_advanced(ProcessorCount_cmd_lsconf) if(ProcessorCount_cmd_lsconf) execute_process(COMMAND ${ProcessorCount_cmd_lsconf} -@@ -190,7 +190,7 @@ +@@ -202,7 +202,7 @@ function(ProcessorCount var) - if(NOT count) + if(NOT count GREATER 0) # Sun (systems where psrinfo tool is available) - find_program(ProcessorCount_cmd_psrinfo psrinfo PATHS /usr/sbin /sbin) + find_program(ProcessorCount_cmd_psrinfo psrinfo) @@ -1919,10 +1931,10 @@ index ffb8fcd8d2..6b8fcf87dc 100644 if (ProcessorCount_cmd_psrinfo) execute_process(COMMAND ${ProcessorCount_cmd_psrinfo} -p -v diff --git a/Modules/UseJava.cmake b/Modules/UseJava.cmake -index b977d955ca..5ff835298d 100644 +index 4192169e0e..b4ca13e363 100644 --- a/Modules/UseJava.cmake +++ b/Modules/UseJava.cmake -@@ -1125,8 +1125,6 @@ +@@ -1182,8 +1182,6 @@ function (find_jar VARIABLE) set(_jar_files) set(_jar_versions) set(_jar_paths @@ -1932,10 +1944,10 @@ index b977d955ca..5ff835298d 100644 set(_jar_doc "NOTSET") diff --git a/Utilities/cmcurl/CMakeLists.txt b/Utilities/cmcurl/CMakeLists.txt -index 2c6a6e6a19..3a43da619a 100644 +index 5b9cdcb217..ab9a0454fb 100644 --- a/Utilities/cmcurl/CMakeLists.txt +++ b/Utilities/cmcurl/CMakeLists.txt -@@ -1566,43 +1566,6 @@ if(_curl_ca_bundle_supported) +@@ -1649,43 +1649,6 @@ if(_curl_ca_bundle_supported) endif() mark_as_advanced(CURL_CA_PATH_SET) @@ -1980,7 +1992,7 @@ index 2c6a6e6a19..3a43da619a 100644 if(BUILD_CURL_EXE AND NOT CURL_CA_EMBED STREQUAL "") if(EXISTS "${CURL_CA_EMBED}") diff --git a/Utilities/cmlibarchive/CMakeLists.txt b/Utilities/cmlibarchive/CMakeLists.txt -index e6ab5de99b..158a407c3e 100644 +index d094dc3753..78cfe39a6b 100644 --- a/Utilities/cmlibarchive/CMakeLists.txt +++ b/Utilities/cmlibarchive/CMakeLists.txt @@ -44,11 +44,6 @@ ENDIF(NOT "${CMAKE_BUILD_TYPE_UPPER}" From da685c6c1671a59f2005d3b2b9757ad51ac01dcc Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Fri, 4 Sep 2026 13:54:03 +0200 Subject: [PATCH 066/423] go: enable strictDeps for bootstrap --- pkgs/development/compilers/go/binary.nix | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/pkgs/development/compilers/go/binary.nix b/pkgs/development/compilers/go/binary.nix index 2e02355dceec..2c8ae189b69c 100644 --- a/pkgs/development/compilers/go/binary.nix +++ b/pkgs/development/compilers/go/binary.nix @@ -4,6 +4,7 @@ fetchurl, version, hashes, + bashNonInteractive, }: let platform = with stdenv.hostPlatform.go; "${GOOS}-${if GOARCH == "arm" then "armv6l" else GOARCH}"; @@ -16,9 +17,15 @@ stdenv.mkDerivation { sha256 = hashes.${platform} or (throw "Missing Go bootstrap hash for platform ${platform}"); }; + buildInputs = [ + bashNonInteractive + ]; + # We must preserve the signature on Darwin dontStrip = stdenv.hostPlatform.isDarwin; + strictDeps = true; + installPhase = '' runHook preInstall mkdir -p $out/share/go $out/bin From e5a1f49564c288b03229ce3a8301cd82459b8e01 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Fri, 4 Sep 2026 13:54:20 +0200 Subject: [PATCH 067/423] go: enable structuredAttrs for bootstrap --- pkgs/development/compilers/go/binary.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/development/compilers/go/binary.nix b/pkgs/development/compilers/go/binary.nix index 2c8ae189b69c..1d52db4c0548 100644 --- a/pkgs/development/compilers/go/binary.nix +++ b/pkgs/development/compilers/go/binary.nix @@ -34,6 +34,8 @@ stdenv.mkDerivation { runHook postInstall ''; + __structuredAttrs = true; + meta = { sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ]; changelog = "https://go.dev/doc/devel/release#go${lib.versions.majorMinor version}"; From 0683ad8c01b660757cfdbe5f863288625b311186 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Fri, 4 Sep 2026 13:54:45 +0200 Subject: [PATCH 068/423] go: use stdenvNoCC for bootstrap --- pkgs/development/compilers/go/binary.nix | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/pkgs/development/compilers/go/binary.nix b/pkgs/development/compilers/go/binary.nix index 1d52db4c0548..b4cc4b59b36a 100644 --- a/pkgs/development/compilers/go/binary.nix +++ b/pkgs/development/compilers/go/binary.nix @@ -1,15 +1,17 @@ { lib, - stdenv, + stdenvNoCC, fetchurl, version, hashes, bashNonInteractive, }: let - platform = with stdenv.hostPlatform.go; "${GOOS}-${if GOARCH == "arm" then "armv6l" else GOARCH}"; + platform = + with stdenvNoCC.hostPlatform.go; + "${GOOS}-${if GOARCH == "arm" then "armv6l" else GOARCH}"; in -stdenv.mkDerivation { +stdenvNoCC.mkDerivation { name = "go-${version}-${platform}-bootstrap"; src = fetchurl { @@ -22,7 +24,7 @@ stdenv.mkDerivation { ]; # We must preserve the signature on Darwin - dontStrip = stdenv.hostPlatform.isDarwin; + dontStrip = stdenvNoCC.hostPlatform.isDarwin; strictDeps = true; From 7315bec4324e6e2ce9263c1e0f39d0fe1371ebd7 Mon Sep 17 00:00:00 2001 From: Hythera <87016780+Hythera@users.noreply.github.com> Date: Tue, 30 Jun 2026 14:11:38 +0200 Subject: [PATCH 069/423] shared-mime-info: 2.4 -> 2.5.1 changelog: https://gitlab.freedesktop.org/xdg/shared-mime-info/-/blob/2.5.1/NEWS diff: https://gitlab.freedesktop.org/xdg/shared-mime-info/-/compare/2.4...2.5.1 --- pkgs/by-name/sh/shared-mime-info/package.nix | 27 +++++++++++++++++--- 1 file changed, 23 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/sh/shared-mime-info/package.nix b/pkgs/by-name/sh/shared-mime-info/package.nix index 51521a613d37..a09f6f40c8d2 100644 --- a/pkgs/by-name/sh/shared-mime-info/package.nix +++ b/pkgs/by-name/sh/shared-mime-info/package.nix @@ -10,10 +10,20 @@ glib, shared-mime-info, }: - +let + # Upstream doesn't pin the version of `xdgmime` in their git repository, + # so it has to be fetched separately. + xdgmime = fetchFromGitLab { + domain = "gitlab.freedesktop.org"; + owner = "xdg"; + repo = "xdgmime"; + rev = "04ce4cd90cb3fa77d5348662de221a6f33b21b17"; + hash = "sha256-0sjH6qG0RYb1kCw4+veTpzv1zJCzoTd2LPa9pqsZrgY="; + }; +in stdenv.mkDerivation (finalAttrs: { pname = "shared-mime-info"; - version = "2.4"; + version = "2.5.1"; outputs = [ "out" @@ -24,10 +34,18 @@ stdenv.mkDerivation (finalAttrs: { domain = "gitlab.freedesktop.org"; owner = "xdg"; repo = "shared-mime-info"; - rev = finalAttrs.version; - hash = "sha256-5eyMkfSBUOD7p8woIYTgz5C/L8uQMXyr0fhL0l23VMA="; + tag = finalAttrs.version; + hash = "sha256-FZFrsCYRyLSFWSOlAt+f6jUEVNy52plhEytu+0tFFvU="; }; + # Disable fuzzing support for xdgmime: shared-mime-info doesn't use it, + # and it requires Linux-only APIs + postPatch = '' + cp -r --no-preserve=mode ${xdgmime} subprojects/xdgmime + substituteInPlace subprojects/xdgmime/meson.build \ + --replace-fail "subdir('fuzzing')" "" + ''; + nativeBuildInputs = [ meson ninja @@ -46,6 +64,7 @@ stdenv.mkDerivation (finalAttrs: { mesonFlags = [ "-Dupdate-mimedb=true" + "-Dbuild-spec=false" ]; meta = { From 0ce7459b96b32d416a608efdda21047bcfa8261b Mon Sep 17 00:00:00 2001 From: Hythera <87016780+Hythera@users.noreply.github.com> Date: Thu, 9 Apr 2026 18:03:24 +0200 Subject: [PATCH 070/423] unixodbcDrivers.mariadb: 3.2.6 -> 3.2.9 changelog: https://mariadb.com/docs/release-notes/connectors/odbc/3.2/3.2.9 diff: https://github.com/mariadb-corporation/mariadb-connector-odbc/compare/3.2.6...3.2.9 --- .../libraries/unixODBCDrivers/default.nix | 19 +-------- .../mariadb-connector-odbc-musl.patch | 41 ------------------- .../mariadb-connector-odbc-unistd.patch | 12 ------ 3 files changed, 2 insertions(+), 70 deletions(-) delete mode 100644 pkgs/development/libraries/unixODBCDrivers/mariadb-connector-odbc-musl.patch delete mode 100644 pkgs/development/libraries/unixODBCDrivers/mariadb-connector-odbc-unistd.patch diff --git a/pkgs/development/libraries/unixODBCDrivers/default.nix b/pkgs/development/libraries/unixODBCDrivers/default.nix index 5b1c363f26ea..1c283249f061 100644 --- a/pkgs/development/libraries/unixODBCDrivers/default.nix +++ b/pkgs/development/libraries/unixODBCDrivers/default.nix @@ -47,33 +47,18 @@ mariadb = stdenv.mkDerivation rec { pname = "mariadb-connector-odbc"; - version = "3.2.6"; + version = "3.2.9"; src = fetchFromGitHub { owner = "mariadb-corporation"; repo = "mariadb-connector-odbc"; rev = version; - hash = "sha256-FdnA3/xDxnk2910LCMPWQTcUUSYfUsnnZ3Hqj0uey5s="; + hash = "sha256-VPpQa17dj544G+kx8b93rErvRZxghvAbZN3povPKYrw="; # this driver only seems to build correctly when built against the mariadb-connect-c subrepo # (see https://github.com/NixOS/nixpkgs/issues/73258) fetchSubmodules = true; }; - patches = [ - # Fix `call to undeclared function 'sleep'` with clang 16 - ./mariadb-connector-odbc-unistd.patch - - ./mariadb-connector-odbc-musl.patch - - # Fix build with gcc15 - # https://github.com/mariadb-corporation/mariadb-connector-odbc/pull/63 - (fetchpatch { - name = "mariadb-connector-odbc-add-include-cstdint-gcc15.patch"; - url = "https://github.com/mariadb-corporation/mariadb-connector-odbc/commit/a3ced654db2ef93de0a818f2d66171f6084e5f2d.patch"; - hash = "sha256-GZITSryfRdAgNxZehasoBModGNZo575Dd5aokwNWzpY="; - }) - ]; - nativeBuildInputs = [ cmake ]; buildInputs = [ unixodbc diff --git a/pkgs/development/libraries/unixODBCDrivers/mariadb-connector-odbc-musl.patch b/pkgs/development/libraries/unixODBCDrivers/mariadb-connector-odbc-musl.patch deleted file mode 100644 index 67445813fb86..000000000000 --- a/pkgs/development/libraries/unixODBCDrivers/mariadb-connector-odbc-musl.patch +++ /dev/null @@ -1,41 +0,0 @@ -From fe6e6412ac0fb155843585647c045a1fba2ee3f2 Mon Sep 17 00:00:00 2001 -From: Alyssa Ross -Date: Sat, 20 Sep 2025 14:11:13 +0200 -Subject: [PATCH] Add missing includes - -These files use types from without including it. Without -the includes, the build fails for musl. ---- -Link: https://github.com/mariadb-corporation/mariadb-connector-odbc/pull/65 - - driver/interface/Exception.h | 1 + - driver/template/CArray.h | 1 + - 2 files changed, 2 insertions(+) - -diff --git a/driver/interface/Exception.h b/driver/interface/Exception.h -index 1b2eb847..82f06273 100644 ---- a/driver/interface/Exception.h -+++ b/driver/interface/Exception.h -@@ -21,6 +21,7 @@ - #ifndef _EXCEPTION_H_ - #define _EXCEPTION_H_ - -+#include - #include - #include "class/SQLString.h" - -diff --git a/driver/template/CArray.h b/driver/template/CArray.h -index 2c4be514..bd0e9912 100644 ---- a/driver/template/CArray.h -+++ b/driver/template/CArray.h -@@ -24,6 +24,7 @@ - #include - #include - #include -+#include - #include - #include - --- -2.51.0 - diff --git a/pkgs/development/libraries/unixODBCDrivers/mariadb-connector-odbc-unistd.patch b/pkgs/development/libraries/unixODBCDrivers/mariadb-connector-odbc-unistd.patch deleted file mode 100644 index 8c976885eb62..000000000000 --- a/pkgs/development/libraries/unixODBCDrivers/mariadb-connector-odbc-unistd.patch +++ /dev/null @@ -1,12 +0,0 @@ -diff -ur a/test/use_result.c b/test/use_result.c ---- a/test/use_result.c 1969-12-31 19:00:01.000000000 -0500 -+++ b/test/use_result.c 2023-09-05 00:08:12.979889343 -0400 -@@ -23,6 +23,8 @@ - 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA - */ - -+#include -+ - #include "tap.h" - - SQLINTEGER my_max_rows= 100; From d0c819d62ce3dcc71701ebb343d9d367b7a015ab Mon Sep 17 00:00:00 2001 From: Hythera <87016780+Hythera@users.noreply.github.com> Date: Sat, 8 Aug 2026 14:54:32 +0200 Subject: [PATCH 071/423] unixodbcDrivers.mariadb: modernize --- .../libraries/unixODBCDrivers/default.nix | 23 ++++++++----------- 1 file changed, 10 insertions(+), 13 deletions(-) diff --git a/pkgs/development/libraries/unixODBCDrivers/default.nix b/pkgs/development/libraries/unixODBCDrivers/default.nix index 1c283249f061..3e2bda487a73 100644 --- a/pkgs/development/libraries/unixODBCDrivers/default.nix +++ b/pkgs/development/libraries/unixODBCDrivers/default.nix @@ -45,14 +45,14 @@ duckdb = duckdb-odbc; - mariadb = stdenv.mkDerivation rec { + mariadb = stdenv.mkDerivation (finalAttrs: { pname = "mariadb-connector-odbc"; version = "3.2.9"; src = fetchFromGitHub { owner = "mariadb-corporation"; repo = "mariadb-connector-odbc"; - rev = version; + tag = finalAttrs.version; hash = "sha256-VPpQa17dj544G+kx8b93rErvRZxghvAbZN3povPKYrw="; # this driver only seems to build correctly when built against the mariadb-connect-c subrepo # (see https://github.com/NixOS/nixpkgs/issues/73258) @@ -60,6 +60,7 @@ }; nativeBuildInputs = [ cmake ]; + buildInputs = [ unixodbc openssl @@ -69,20 +70,16 @@ ++ lib.optionals stdenv.hostPlatform.isDarwin [ libkrb5 ]; cmakeFlags = [ - "-DWITH_EXTERNAL_ZLIB=ON" - "-DODBC_LIB_DIR=${lib.getLib unixodbc}/lib" - "-DODBC_INCLUDE_DIR=${lib.getDev unixodbc}/include" - "-DWITH_OPENSSL=ON" - # on darwin this defaults to ON but we want to build against unixodbc - "-DWITH_IODBC=OFF" + # On darwin this defaults to ON but we want to build against unixodbc + (lib.cmakeBool "WITH_IODBC" false) + (lib.cmakeBool "WITH_OPENSSL" true) + (lib.cmakeBool "WITH_EXTERNAL_ZLIB" true) + (lib.cmakeFeature "ODBC_LIB_DIR" "${lib.getLib unixodbc}/lib") + (lib.cmakeFeature "ODBC_INCLUDE_DIR" "${lib.getDev unixodbc}/include") ]; buildFlags = if stdenv.hostPlatform.isDarwin then [ "maodbc" ] else null; - env = lib.optionalAttrs stdenv.cc.isGNU { - NIX_CFLAGS_COMPILE = "-Wno-error=incompatible-pointer-types"; - }; - installTargets = if stdenv.hostPlatform.isDarwin then [ "install/fast" ] else null; # see the top of the file for an explanation @@ -97,7 +94,7 @@ license = lib.licenses.gpl2; platforms = lib.platforms.linux ++ lib.platforms.darwin; }; - }; + }); sqlite = stdenv.mkDerivation rec { pname = "sqlite-connector-odbc"; From 11737cb0a4307728a7d8ca4c40798020bef8415b Mon Sep 17 00:00:00 2001 From: Hythera <87016780+Hythera@users.noreply.github.com> Date: Thu, 9 Apr 2026 18:04:34 +0200 Subject: [PATCH 072/423] unixodbcDrivers.mariadb: add hythera as maintainer --- pkgs/development/libraries/unixODBCDrivers/default.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/development/libraries/unixODBCDrivers/default.nix b/pkgs/development/libraries/unixODBCDrivers/default.nix index 3e2bda487a73..80ce13b7d5fa 100644 --- a/pkgs/development/libraries/unixODBCDrivers/default.nix +++ b/pkgs/development/libraries/unixODBCDrivers/default.nix @@ -92,6 +92,7 @@ description = "MariaDB ODBC database driver"; homepage = "https://downloads.mariadb.org/connector-odbc/"; license = lib.licenses.gpl2; + maintainers = with lib.maintainers; [ hythera ]; platforms = lib.platforms.linux ++ lib.platforms.darwin; }; }); From 7f3ed9c6ace8613709cdadcf8103912a2655ed73 Mon Sep 17 00:00:00 2001 From: scraptux Date: Sun, 6 Sep 2026 10:38:04 +0200 Subject: [PATCH 073/423] grpc: 1.83.0 -> 1.83.1 --- pkgs/by-name/gr/grpc/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/gr/grpc/package.nix b/pkgs/by-name/gr/grpc/package.nix index 105e69cc23ee..c4b8a870a687 100644 --- a/pkgs/by-name/gr/grpc/package.nix +++ b/pkgs/by-name/gr/grpc/package.nix @@ -25,7 +25,7 @@ # nixpkgs-update: no auto update stdenv.mkDerivation (finalAttrs: { pname = "grpc"; - version = "1.83.0"; # N.B: if you change this, please update: + version = "1.83.1"; # N.B: if you change this, please update: # pythonPackages.grpcio # pythonPackages.grpcio-channelz # pythonPackages.grpcio-health-checking @@ -38,7 +38,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "grpc"; repo = "grpc"; tag = "v${finalAttrs.version}"; - hash = "sha256-A2QtLdsunMOulbpyaSOoAID9caK0tpuiyZJ5C5zrr+k="; + hash = "sha256-h2F+lKF9GH5CGjzS5326ovLUHbYwsPjoqmb8Ljgj2ao="; fetchSubmodules = true; }; From 201de3c1404586747ea7a0f7a9aac3ff6663425a Mon Sep 17 00:00:00 2001 From: scraptux Date: Sun, 6 Sep 2026 10:38:07 +0200 Subject: [PATCH 074/423] python3Packages.grpcio: 1.83.0 -> 1.83.1 --- pkgs/development/python-modules/grpcio/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/grpcio/default.nix b/pkgs/development/python-modules/grpcio/default.nix index 3f39101e34d8..0c4e6648a9c1 100644 --- a/pkgs/development/python-modules/grpcio/default.nix +++ b/pkgs/development/python-modules/grpcio/default.nix @@ -18,12 +18,12 @@ # nixpkgs-update: no auto update buildPythonPackage rec { pname = "grpcio"; - version = "1.83.0"; + version = "1.83.1"; pyproject = true; src = fetchPypi { inherit pname version; - hash = "sha256-dnRYckj7uyrG5O7Pg6ig89kako+UHeVxrP06LwB/vCQ="; + hash = "sha256-nO5vy/LrV8S0lFF4e/qHvo78HKAqCzJ91LVNRFAuNis="; }; postPatch = '' From 2bbce9fb11a4b1820f05b3d682ce6171ca52e471 Mon Sep 17 00:00:00 2001 From: scraptux Date: Sun, 6 Sep 2026 10:38:08 +0200 Subject: [PATCH 075/423] python3Packages.grpcio-channelz: 1.83.0 -> 1.83.1 --- pkgs/development/python-modules/grpcio-channelz/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/grpcio-channelz/default.nix b/pkgs/development/python-modules/grpcio-channelz/default.nix index 6741c9d8bc80..a37b04eb3395 100644 --- a/pkgs/development/python-modules/grpcio-channelz/default.nix +++ b/pkgs/development/python-modules/grpcio-channelz/default.nix @@ -12,13 +12,13 @@ # nixpkgs-update: no auto update buildPythonPackage rec { pname = "grpcio-channelz"; - version = "1.83.0"; + version = "1.83.1"; pyproject = true; src = fetchPypi { pname = "grpcio_channelz"; inherit version; - hash = "sha256-gaqgIn5UGWGvsnhNNcmWO9sPdmtGQ9JAODmBeKYc9lw="; + hash = "sha256-XrsLFMK8yBFJ4oSNHSZCQEJnYqBQsinTNzRruzfT4x8="; }; build-system = [ setuptools ]; From f6254e7328b04eedc3f2b8cc4ee9717f025194a3 Mon Sep 17 00:00:00 2001 From: scraptux Date: Sun, 6 Sep 2026 10:38:10 +0200 Subject: [PATCH 076/423] python3Packages.grpcio-health-checking: 1.83.0 -> 1.83.1 --- .../python-modules/grpcio-health-checking/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/grpcio-health-checking/default.nix b/pkgs/development/python-modules/grpcio-health-checking/default.nix index ef962e09a7a2..ff362fdff915 100644 --- a/pkgs/development/python-modules/grpcio-health-checking/default.nix +++ b/pkgs/development/python-modules/grpcio-health-checking/default.nix @@ -11,13 +11,13 @@ # nixpkgs-update: no auto update buildPythonPackage rec { pname = "grpcio-health-checking"; - version = "1.83.0"; + version = "1.83.1"; format = "setuptools"; src = fetchPypi { pname = "grpcio_health_checking"; inherit version; - hash = "sha256-rWvE1aEQOtcE0lzNgt7zAN+ieZaxhcqz5Mzu7yxoZ9Q="; + hash = "sha256-1gkk5vutOPNcNyd5vF62UaAORG1tJPHRxy8UKXodDlY="; }; propagatedBuildInputs = [ From 37869fcefab29ac585d890bfd060dd8f01127968 Mon Sep 17 00:00:00 2001 From: scraptux Date: Sun, 6 Sep 2026 10:38:12 +0200 Subject: [PATCH 077/423] python3Packages.grpcio-reflection: 1.83.0 -> 1.83.1 --- pkgs/development/python-modules/grpcio-reflection/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/grpcio-reflection/default.nix b/pkgs/development/python-modules/grpcio-reflection/default.nix index d697034b9bb0..0b640f0e32d1 100644 --- a/pkgs/development/python-modules/grpcio-reflection/default.nix +++ b/pkgs/development/python-modules/grpcio-reflection/default.nix @@ -12,13 +12,13 @@ # nixpkgs-update: no auto update buildPythonPackage rec { pname = "grpcio-reflection"; - version = "1.83.0"; + version = "1.83.1"; pyproject = true; src = fetchPypi { pname = "grpcio_reflection"; inherit version; - hash = "sha256-aiowpGKsLDxtFJc0qP5lX6dhfBf6LNqZSQBvO/B/Wz4="; + hash = "sha256-wzlT8urhMTqx0sK2oc7G3a6+Z2PaGyYxmAeS2XkuYjM="; }; build-system = [ setuptools ]; From 17b9bc2c15efaf6a17398bd3bfd8fb02c56faaaa Mon Sep 17 00:00:00 2001 From: scraptux Date: Sun, 6 Sep 2026 10:38:14 +0200 Subject: [PATCH 078/423] python3Packages.grpcio-status: 1.83.0 -> 1.83.1 --- pkgs/development/python-modules/grpcio-status/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/grpcio-status/default.nix b/pkgs/development/python-modules/grpcio-status/default.nix index 57e252eae475..91cad68190e6 100644 --- a/pkgs/development/python-modules/grpcio-status/default.nix +++ b/pkgs/development/python-modules/grpcio-status/default.nix @@ -12,13 +12,13 @@ # nixpkgs-update: no auto update buildPythonPackage rec { pname = "grpcio-status"; - version = "1.83.0"; + version = "1.83.1"; format = "setuptools"; src = fetchPypi { pname = "grpcio_status"; inherit version; - hash = "sha256-g3IZxt6a/cy29vcrNLxx4VGiAR7wQEDj+qynRqV+VK4="; + hash = "sha256-wIyNVT1quW7/rh2SODneIpJvWjFqlC9IpIBA4EfFF68="; }; postPatch = '' From 35678e2de564a3bfe8770d9715a61e5206224f32 Mon Sep 17 00:00:00 2001 From: scraptux Date: Sun, 6 Sep 2026 10:38:16 +0200 Subject: [PATCH 079/423] python3Packages.grpcio-testing: 1.83.0 -> 1.83.1 --- pkgs/development/python-modules/grpcio-testing/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/grpcio-testing/default.nix b/pkgs/development/python-modules/grpcio-testing/default.nix index 9f0f81ecb5b8..55cbb7b6d3c0 100644 --- a/pkgs/development/python-modules/grpcio-testing/default.nix +++ b/pkgs/development/python-modules/grpcio-testing/default.nix @@ -12,13 +12,13 @@ # nixpkgs-update: no auto update buildPythonPackage rec { pname = "grpcio-testing"; - version = "1.83.0"; + version = "1.83.1"; pyproject = true; src = fetchPypi { pname = "grpcio_testing"; inherit version; - hash = "sha256-/6p6o+ckGsNXDBePfNbpRYEUK1Eh60esk5g+1gfwa90="; + hash = "sha256-xye7371SOlXGMECLeX/43w89GEFyHV8+eOoV4C/39Vs="; }; postPatch = '' From 93880b986be616bc3235501a1015f25ab3cbd46c Mon Sep 17 00:00:00 2001 From: scraptux Date: Sun, 6 Sep 2026 10:38:19 +0200 Subject: [PATCH 080/423] python3Packages.grpcio-tools: 1.83.0 -> 1.83.1 --- pkgs/development/python-modules/grpcio-tools/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/grpcio-tools/default.nix b/pkgs/development/python-modules/grpcio-tools/default.nix index 0274dd2ead83..e391ab625f2d 100644 --- a/pkgs/development/python-modules/grpcio-tools/default.nix +++ b/pkgs/development/python-modules/grpcio-tools/default.nix @@ -13,13 +13,13 @@ # nixpkgs-update: no auto update buildPythonPackage rec { pname = "grpcio-tools"; - version = "1.83.0"; + version = "1.83.1"; pyproject = true; src = fetchPypi { pname = "grpcio_tools"; inherit version; - hash = "sha256-UVkHJl0U+pl10MdyP5Wp2gFGPXrGB1RqA/h0H4ahuwc="; + hash = "sha256-qBSO7OOW+KNJCXlYvADxSIIAMzHzt8KugHnBxjLRfW8="; }; postPatch = '' From a03d7c5196966f802fdbf650bc32e414e5af4c0e Mon Sep 17 00:00:00 2001 From: liberodark Date: Sun, 6 Sep 2026 14:32:40 +0200 Subject: [PATCH 081/423] python3Packages.httpcore2: fix riscv64-linux build --- pkgs/development/python-modules/httpcore2/default.nix | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/pkgs/development/python-modules/httpcore2/default.nix b/pkgs/development/python-modules/httpcore2/default.nix index f87ae1db2a26..badd6a951953 100644 --- a/pkgs/development/python-modules/httpcore2/default.nix +++ b/pkgs/development/python-modules/httpcore2/default.nix @@ -1,5 +1,6 @@ { lib, + stdenv, buildPythonPackage, fetchFromGitHub, @@ -78,6 +79,12 @@ buildPythonPackage (finalAttrs: { pytestFlags = [ "tests/httpcore2" ]; + # Skip tests does not pass: 10ms cancellation-timing test + disabledTests = lib.optionals stdenv.hostPlatform.isRiscV64 [ + "test_h2_timeout_during_request" + "test_h2_timeout_during_response" + ]; + passthru.tests = { inherit httpx2; }; From 311a15ebb5f6023b108e44113df3d9da6772bd65 Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Sun, 6 Sep 2026 10:24:07 -0400 Subject: [PATCH 082/423] Revert "unixodbcDrivers.mariadb: 3.2.6 -> 3.2.8, adopt" --- .../libraries/unixODBCDrivers/default.nix | 43 +++++++++++++------ .../mariadb-connector-odbc-musl.patch | 41 ++++++++++++++++++ .../mariadb-connector-odbc-unistd.patch | 12 ++++++ 3 files changed, 83 insertions(+), 13 deletions(-) create mode 100644 pkgs/development/libraries/unixODBCDrivers/mariadb-connector-odbc-musl.patch create mode 100644 pkgs/development/libraries/unixODBCDrivers/mariadb-connector-odbc-unistd.patch diff --git a/pkgs/development/libraries/unixODBCDrivers/default.nix b/pkgs/development/libraries/unixODBCDrivers/default.nix index 80ce13b7d5fa..5b1c363f26ea 100644 --- a/pkgs/development/libraries/unixODBCDrivers/default.nix +++ b/pkgs/development/libraries/unixODBCDrivers/default.nix @@ -45,22 +45,36 @@ duckdb = duckdb-odbc; - mariadb = stdenv.mkDerivation (finalAttrs: { + mariadb = stdenv.mkDerivation rec { pname = "mariadb-connector-odbc"; - version = "3.2.9"; + version = "3.2.6"; src = fetchFromGitHub { owner = "mariadb-corporation"; repo = "mariadb-connector-odbc"; - tag = finalAttrs.version; - hash = "sha256-VPpQa17dj544G+kx8b93rErvRZxghvAbZN3povPKYrw="; + rev = version; + hash = "sha256-FdnA3/xDxnk2910LCMPWQTcUUSYfUsnnZ3Hqj0uey5s="; # this driver only seems to build correctly when built against the mariadb-connect-c subrepo # (see https://github.com/NixOS/nixpkgs/issues/73258) fetchSubmodules = true; }; - nativeBuildInputs = [ cmake ]; + patches = [ + # Fix `call to undeclared function 'sleep'` with clang 16 + ./mariadb-connector-odbc-unistd.patch + ./mariadb-connector-odbc-musl.patch + + # Fix build with gcc15 + # https://github.com/mariadb-corporation/mariadb-connector-odbc/pull/63 + (fetchpatch { + name = "mariadb-connector-odbc-add-include-cstdint-gcc15.patch"; + url = "https://github.com/mariadb-corporation/mariadb-connector-odbc/commit/a3ced654db2ef93de0a818f2d66171f6084e5f2d.patch"; + hash = "sha256-GZITSryfRdAgNxZehasoBModGNZo575Dd5aokwNWzpY="; + }) + ]; + + nativeBuildInputs = [ cmake ]; buildInputs = [ unixodbc openssl @@ -70,16 +84,20 @@ ++ lib.optionals stdenv.hostPlatform.isDarwin [ libkrb5 ]; cmakeFlags = [ - # On darwin this defaults to ON but we want to build against unixodbc - (lib.cmakeBool "WITH_IODBC" false) - (lib.cmakeBool "WITH_OPENSSL" true) - (lib.cmakeBool "WITH_EXTERNAL_ZLIB" true) - (lib.cmakeFeature "ODBC_LIB_DIR" "${lib.getLib unixodbc}/lib") - (lib.cmakeFeature "ODBC_INCLUDE_DIR" "${lib.getDev unixodbc}/include") + "-DWITH_EXTERNAL_ZLIB=ON" + "-DODBC_LIB_DIR=${lib.getLib unixodbc}/lib" + "-DODBC_INCLUDE_DIR=${lib.getDev unixodbc}/include" + "-DWITH_OPENSSL=ON" + # on darwin this defaults to ON but we want to build against unixodbc + "-DWITH_IODBC=OFF" ]; buildFlags = if stdenv.hostPlatform.isDarwin then [ "maodbc" ] else null; + env = lib.optionalAttrs stdenv.cc.isGNU { + NIX_CFLAGS_COMPILE = "-Wno-error=incompatible-pointer-types"; + }; + installTargets = if stdenv.hostPlatform.isDarwin then [ "install/fast" ] else null; # see the top of the file for an explanation @@ -92,10 +110,9 @@ description = "MariaDB ODBC database driver"; homepage = "https://downloads.mariadb.org/connector-odbc/"; license = lib.licenses.gpl2; - maintainers = with lib.maintainers; [ hythera ]; platforms = lib.platforms.linux ++ lib.platforms.darwin; }; - }); + }; sqlite = stdenv.mkDerivation rec { pname = "sqlite-connector-odbc"; diff --git a/pkgs/development/libraries/unixODBCDrivers/mariadb-connector-odbc-musl.patch b/pkgs/development/libraries/unixODBCDrivers/mariadb-connector-odbc-musl.patch new file mode 100644 index 000000000000..67445813fb86 --- /dev/null +++ b/pkgs/development/libraries/unixODBCDrivers/mariadb-connector-odbc-musl.patch @@ -0,0 +1,41 @@ +From fe6e6412ac0fb155843585647c045a1fba2ee3f2 Mon Sep 17 00:00:00 2001 +From: Alyssa Ross +Date: Sat, 20 Sep 2025 14:11:13 +0200 +Subject: [PATCH] Add missing includes + +These files use types from without including it. Without +the includes, the build fails for musl. +--- +Link: https://github.com/mariadb-corporation/mariadb-connector-odbc/pull/65 + + driver/interface/Exception.h | 1 + + driver/template/CArray.h | 1 + + 2 files changed, 2 insertions(+) + +diff --git a/driver/interface/Exception.h b/driver/interface/Exception.h +index 1b2eb847..82f06273 100644 +--- a/driver/interface/Exception.h ++++ b/driver/interface/Exception.h +@@ -21,6 +21,7 @@ + #ifndef _EXCEPTION_H_ + #define _EXCEPTION_H_ + ++#include + #include + #include "class/SQLString.h" + +diff --git a/driver/template/CArray.h b/driver/template/CArray.h +index 2c4be514..bd0e9912 100644 +--- a/driver/template/CArray.h ++++ b/driver/template/CArray.h +@@ -24,6 +24,7 @@ + #include + #include + #include ++#include + #include + #include + +-- +2.51.0 + diff --git a/pkgs/development/libraries/unixODBCDrivers/mariadb-connector-odbc-unistd.patch b/pkgs/development/libraries/unixODBCDrivers/mariadb-connector-odbc-unistd.patch new file mode 100644 index 000000000000..8c976885eb62 --- /dev/null +++ b/pkgs/development/libraries/unixODBCDrivers/mariadb-connector-odbc-unistd.patch @@ -0,0 +1,12 @@ +diff -ur a/test/use_result.c b/test/use_result.c +--- a/test/use_result.c 1969-12-31 19:00:01.000000000 -0500 ++++ b/test/use_result.c 2023-09-05 00:08:12.979889343 -0400 +@@ -23,6 +23,8 @@ + 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA + */ + ++#include ++ + #include "tap.h" + + SQLINTEGER my_max_rows= 100; From fb3f389bc7dca0fdcf8380675531ba3f8615235f Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Sun, 6 Sep 2026 16:24:49 +0200 Subject: [PATCH 083/423] merve: enable `structuredAttrs`, `strictDeps`, and multiple outputs --- pkgs/by-name/me/merve/package.nix | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/pkgs/by-name/me/merve/package.nix b/pkgs/by-name/me/merve/package.nix index 066ac8fd351d..08a38426257f 100644 --- a/pkgs/by-name/me/merve/package.nix +++ b/pkgs/by-name/me/merve/package.nix @@ -15,6 +15,14 @@ stdenv.mkDerivation (finalAttrs: { pname = "merve"; version = "1.2.2"; + __structuredAttrs = true; + strictDeps = true; + + outputs = [ + "out" + "dev" + ]; + src = fetchFromGitHub { owner = "nodejs"; repo = "merve"; From 303384d3a0bb726b836e3ca6159252844bdd1d52 Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Sun, 6 Sep 2026 16:25:02 +0200 Subject: [PATCH 084/423] nbytes: enable `structuredAttrs`, `strictDeps`, and multiple outputs --- pkgs/by-name/nb/nbytes/package.nix | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/pkgs/by-name/nb/nbytes/package.nix b/pkgs/by-name/nb/nbytes/package.nix index b886e53522f1..145012080436 100644 --- a/pkgs/by-name/nb/nbytes/package.nix +++ b/pkgs/by-name/nb/nbytes/package.nix @@ -13,6 +13,9 @@ stdenv.mkDerivation (finalAttrs: { pname = "nbytes"; version = "0.1.4"; + __structuredAttrs = true; + strictDeps = true; + src = fetchFromGitHub { owner = "nodejs"; repo = "nbytes"; @@ -20,6 +23,11 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-etCRWjak7tKL6dKlQR7SD6HXx/mn/8gnR4l+CAjoQgA="; }; + outputs = [ + "out" + "dev" + ]; + nativeBuildInputs = [ cmake validatePkgConfig From bda34026b7a0d6df8cc4c26d189648424da3dda9 Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Sun, 6 Sep 2026 16:25:12 +0200 Subject: [PATCH 085/423] uvwasi: enable `structuredAttrs`, `strictDeps`, and multiple outputs --- pkgs/by-name/uv/uvwasi/package.nix | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/pkgs/by-name/uv/uvwasi/package.nix b/pkgs/by-name/uv/uvwasi/package.nix index 5194fdc7ab07..c3b85b5c8308 100644 --- a/pkgs/by-name/uv/uvwasi/package.nix +++ b/pkgs/by-name/uv/uvwasi/package.nix @@ -22,6 +22,9 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-+vz/qTMRRDHV1VE4nny9vYYtarZHk1xoM4EZiah3jnY="; }; + __structuredAttrs = true; + strictDeps = true; + patches = [ # FIXME: remove when included in a release (fetchpatch2 { @@ -38,6 +41,7 @@ stdenv.mkDerivation (finalAttrs: { outputs = [ "out" + "dev" ]; nativeBuildInputs = [ From 41d426db5b9b0e9f4157fbf433ecc0ec16ebf0aa Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Sun, 6 Sep 2026 19:10:58 +0200 Subject: [PATCH 086/423] protobuf: use separate outputs --- pkgs/development/libraries/protobuf/generic.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/pkgs/development/libraries/protobuf/generic.nix b/pkgs/development/libraries/protobuf/generic.nix index 45db4049d10a..08c2ac50cad5 100644 --- a/pkgs/development/libraries/protobuf/generic.nix +++ b/pkgs/development/libraries/protobuf/generic.nix @@ -37,6 +37,12 @@ stdenv.mkDerivation (finalAttrs: { inherit hash; }; + outputs = [ + "out" + "lib" + "dev" + ]; + patches = lib.optionals (lib.versionOlder version "22") [ # fix protobuf-targets.cmake installation paths, and allow for CMAKE_INSTALL_LIBDIR to be absolute From dc3cf5062f4c8449a7921a380fa87d7cde3ac8d8 Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Sun, 6 Sep 2026 19:11:31 +0200 Subject: [PATCH 087/423] protobuf: add `meta.pkgConfigModules` --- pkgs/development/libraries/protobuf/generic.nix | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/pkgs/development/libraries/protobuf/generic.nix b/pkgs/development/libraries/protobuf/generic.nix index 08c2ac50cad5..958ef2b7d19d 100644 --- a/pkgs/development/libraries/protobuf/generic.nix +++ b/pkgs/development/libraries/protobuf/generic.nix @@ -186,6 +186,10 @@ stdenv.mkDerivation (finalAttrs: { inherit (python3.pkgs) celery; version = testers.testVersion { package = protobuf; }; + + pkg-config = testers.hasPkgConfigModules { + package = protobuf; + }; }; inherit abseil-cpp; @@ -203,5 +207,15 @@ stdenv.mkDerivation (finalAttrs: { homepage = "https://protobuf.dev/"; maintainers = with lib.maintainers; [ GaetanLepage ]; mainProgram = "protoc"; + pkgConfigModules = [ + "protobuf" + "protobuf_lite" + ] + ++ lib.optionals (lib.versionAtLeast version "22") [ + "utf8_range" + ] + ++ lib.optionals (lib.versionAtLeast version "27") [ + "upb" + ]; }; }) From 003cd784470ca9593df86f72b407dc4ee4865fe2 Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Sat, 1 Aug 2026 10:23:13 -0400 Subject: [PATCH 088/423] meson: 1.10.2 -> 1.12.0 --- pkgs/by-name/me/meson/package.nix | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/me/meson/package.nix b/pkgs/by-name/me/meson/package.nix index edd39a451200..22a0e8ab6fc3 100644 --- a/pkgs/by-name/me/meson/package.nix +++ b/pkgs/by-name/me/meson/package.nix @@ -16,14 +16,14 @@ python3.pkgs.buildPythonApplication rec { pname = "meson"; - version = "1.10.2"; + version = "1.12.0"; format = "setuptools"; src = fetchFromGitHub { owner = "mesonbuild"; repo = "meson"; tag = version; - hash = "sha256-3Zeavn6aW6920gM7yE73Ms1RPCP2GjX9IUL9YGmISfY="; + hash = "sha256-lnuySM7aCojPU9bQI7LPKgod8otFa+Spo9yIDFbOJVs="; }; patches = [ @@ -129,6 +129,11 @@ python3.pkgs.buildPythonApplication rec { "test cases/linuxlike/14 static dynamic linkage" # Nixpkgs cctools does not have bitcode support. "test cases/osx/7 bitcode" + # This test tries to compile with flags `-D_FORTIFY_SOURCE=2 -U_FORTIFY_SOURCE -O0`. + # It fails because cc-wrapper adds `-U_FORTIFY_SOURCE -D_FORTIFY_SOURCE=3` + # after the provided args (to ensure that fortify cannot be disabled without + # being allowed by the package definition) + "test cases/common/282 -D_FORTIFY_SOURCE=2 and -O0" ] ++ lib.optionals stdenv.hostPlatform.isDarwin [ # requires llvmPackages.openmp, creating cyclic dependency From 8f7ca3386c65de59783f8ff3525e0f3bc9e5a8ec Mon Sep 17 00:00:00 2001 From: Dimitar Nestorov <8790386+dimitarnestorov@users.noreply.github.com> Date: Mon, 7 Sep 2026 10:18:47 +0300 Subject: [PATCH 089/423] yarn-berry: add `lockfileVersion` --- pkgs/by-name/ya/yarn-berry/package.nix | 29 ++++++++++++++++++++++++++ 1 file changed, 29 insertions(+) diff --git a/pkgs/by-name/ya/yarn-berry/package.nix b/pkgs/by-name/ya/yarn-berry/package.nix index 54d98e811b80..f0ab67d69512 100644 --- a/pkgs/by-name/ya/yarn-berry/package.nix +++ b/pkgs/by-name/ya/yarn-berry/package.nix @@ -6,6 +6,7 @@ stdenv, testers, yarn, + git, callPackage, berryVersion ? 4, }: @@ -15,11 +16,14 @@ let version_3 = "3.8.7"; hash_4 = "sha256-0UnU5jRSUFMw+WowvXqYqaaN1ZbZAdLLJ6LPyuK6iCc="; hash_3 = "sha256-vRrk+Fs/7dZha3h7yI5NpMfd1xezesnigpFgTRCACZo="; + lockfileVersion_4 = "9"; + lockfileVersion_3 = "6"; in stdenv.mkDerivation (finalAttrs: { pname = "yarn-berry"; version = if berryVersion == 4 then version_4 else version_3; + lockfileVersion = if berryVersion == 4 then lockfileVersion_4 else lockfileVersion_3; src = fetchFromGitHub { owner = "yarnpkg"; @@ -35,6 +39,7 @@ stdenv.mkDerivation (finalAttrs: { nativeBuildInputs = [ nodejs yarn + git ]; strictDeps = true; @@ -47,6 +52,28 @@ stdenv.mkDerivation (finalAttrs: { runHook postBuild ''; + # Confirms that lockfileVersion matches the one defined above + doCheck = true; + checkPhase = '' + runHook preCheck + + YARN_JS_PATH=$(pwd)/packages/yarnpkg-cli/bundles/yarn.js + TEST_DIR=$(mktemp -d) + export HOME=$(mktemp -d) + git config --global user.name nixbld + git config --global user.email nixbld@localhost + cd $TEST_DIR + + node $YARN_JS_PATH config set --home enableTelemetry 0 + node $YARN_JS_PATH init + node $YARN_JS_PATH install # Yarn 3 doesn't run install during init + grep -Pzq '\n__metadata:\n version: ${finalAttrs.lockfileVersion}\n' yarn.lock + + cd - + + runHook postCheck + ''; + installPhase = '' runHook preInstall install -Dm 755 ./packages/yarnpkg-cli/bundles/yarn.js "$out/bin/yarn" @@ -54,6 +81,8 @@ stdenv.mkDerivation (finalAttrs: { ''; passthru = { + lockfileVersion = finalAttrs.lockfileVersion; + updateScript = ./update.sh; tests = From d251914e23665531c568a85135afd314284e542a Mon Sep 17 00:00:00 2001 From: Dimitar Nestorov <8790386+dimitarnestorov@users.noreply.github.com> Date: Mon, 7 Sep 2026 10:30:30 +0300 Subject: [PATCH 090/423] yarn-berry_4: 4.14.1 -> 4.18.0 --- pkgs/by-name/af/affine/package.nix | 29 +++++++--- .../by-name/af/affine/yarn-4.14-support.patch | 23 -------- pkgs/by-name/af/affine/yarn-fix.patch | 58 +++++++++++++++++++ pkgs/by-name/an/anki/package.nix | 16 +++-- ...yarn-4.14-support.patch => yarn-fix.patch} | 2 +- pkgs/by-name/aw/aws-cdk-cli/package.nix | 8 --- .../by-name/bi/bitfocus-companion/package.nix | 23 ++++++-- .../bitfocus-companion/yarn-fix.patch} | 6 +- pkgs/by-name/co/cockpit-zfs/package.nix | 29 ++-------- pkgs/by-name/ea/eas-cli/package.nix | 29 +++++++--- ...yarn-4.14-support.patch => yarn-fix.patch} | 2 +- pkgs/by-name/el/electron-fiddle/package.nix | 25 ++++++-- .../by-name/el/electron-fiddle/yarn-fix.patch | 58 +++++++++++++++++++ pkgs/by-name/gi/gitbeaker-cli/package.nix | 29 +++++++--- ...yarn-4.14-support.patch => yarn-fix.patch} | 2 +- pkgs/by-name/he/hedgedoc/package.nix | 28 ++++++--- ...yarn-4.14-support.patch => yarn-fix.patch} | 2 +- pkgs/by-name/in/insulator2/package.nix | 27 ++++++--- ...yarn-4.14-support.patch => yarn-fix.patch} | 2 +- pkgs/by-name/jo/joplin-cli/package.nix | 28 +++++---- ...yarn-4.14-support.patch => yarn-fix.patch} | 2 +- pkgs/by-name/jo/joplin-desktop/package.nix | 6 +- .../jo/joplin-desktop/release-data.json | 4 +- pkgs/by-name/ko/koito/client.nix | 2 +- pkgs/by-name/ko/koito/package.nix | 21 ++++++- pkgs/by-name/ko/koito/yarn-fix.patch | 11 ++++ pkgs/by-name/le/learn6502/package.nix | 27 ++++++--- ...yarn-4.14-support.patch => yarn-fix.patch} | 2 +- pkgs/by-name/li/linkwarden/package.nix | 27 ++++++--- .../li/linkwarden/yarn-fix.patch} | 2 +- pkgs/by-name/lo/losslesscut/package.nix | 24 ++++++-- ...yarn-4.14-support.patch => yarn-fix.patch} | 2 +- .../ma/mastodon/yarn-4.14-support.patch | 21 ------- pkgs/by-name/ou/outline/package.nix | 29 +++++++--- ...yarn-4.14-support.patch => yarn-fix.patch} | 9 +-- pkgs/by-name/pe/peacock/package.nix | 29 +++++++--- ...yarn-4.14-support.patch => yarn-fix.patch} | 3 +- pkgs/by-name/pg/pgadmin4/package.nix | 28 ++++++--- ...yarn-4.14-support.patch => yarn-fix.patch} | 2 +- .../pr/proton-authenticator/package.nix | 2 +- .../by-name/pr/proton-authenticator/yarn.lock | 2 +- pkgs/by-name/r2/r2modman/package.nix | 27 ++++++--- ...yarn-4.14-support.patch => yarn-fix.patch} | 2 +- .../by-name/ro/rocketchat-desktop/package.nix | 29 +++++++--- ...yarn-4.14-support.patch => yarn-fix.patch} | 2 +- pkgs/by-name/sy/synapse-admin/package.nix | 27 ++++++--- .../sy/synapse-admin/yarn-4.14-support.patch | 20 ------- pkgs/by-name/sy/synapse-admin/yarn-fix.patch | 41 +++++++++++++ pkgs/by-name/ti/tilt/assets.nix | 13 +---- pkgs/by-name/ti/tilt/package.nix | 22 ++++++- pkgs/by-name/ti/tilt/yarn-4.14-support.patch | 23 -------- pkgs/by-name/ti/tilt/yarn-fix.patch | 58 +++++++++++++++++++ pkgs/by-name/up/uppy-companion/package.nix | 29 +++++++--- ...yarn-4.14-support.patch => yarn-fix.patch} | 2 +- pkgs/by-name/vu/vultisig-cli/package.nix | 29 +++++++--- ...yarn-4.14-support.patch => yarn-fix.patch} | 2 +- .../yarn-berry/fetcher/berry-4-offline.patch | 2 +- .../by-name/ya/yarn-berry/fetcher/default.nix | 1 + pkgs/by-name/ya/yarn-berry/package.nix | 12 ++-- pkgs/by-name/yt/ytmdesktop/package.nix | 24 +++++--- ...yarn-4.14-support.patch => yarn-fix.patch} | 2 +- .../python-modules/locust/default.nix | 22 ++++++- .../python-modules/locust/webui.nix | 15 +---- ...yarn-4.14-support.patch => yarn-fix.patch} | 2 +- pkgs/development/tools/electron/common.nix | 14 ++++- pkgs/development/tools/electron/info.json | 6 +- ...yarn-4.14-support.patch => yarn-fix.patch} | 2 +- .../advanced-camera-card/package.nix | 27 ++++++--- ...yarn-4.14-support.patch => yarn-fix.patch} | 2 +- .../horizon-card/package.nix | 27 ++++++--- .../horizon-card/yarn-fix.patch} | 2 +- 71 files changed, 791 insertions(+), 376 deletions(-) delete mode 100644 pkgs/by-name/af/affine/yarn-4.14-support.patch create mode 100644 pkgs/by-name/af/affine/yarn-fix.patch rename pkgs/by-name/an/anki/patches/{yarn-4.14-support.patch => yarn-fix.patch} (88%) rename pkgs/by-name/{el/electron-fiddle/yarn-metadata-version.patch => bi/bitfocus-companion/yarn-fix.patch} (62%) rename pkgs/by-name/ea/eas-cli/{yarn-4.14-support.patch => yarn-fix.patch} (89%) create mode 100644 pkgs/by-name/el/electron-fiddle/yarn-fix.patch rename pkgs/by-name/gi/gitbeaker-cli/{yarn-4.14-support.patch => yarn-fix.patch} (89%) rename pkgs/by-name/he/hedgedoc/{yarn-4.14-support.patch => yarn-fix.patch} (90%) rename pkgs/by-name/in/insulator2/{yarn-4.14-support.patch => yarn-fix.patch} (88%) rename pkgs/by-name/jo/joplin-cli/{yarn-4.14-support.patch => yarn-fix.patch} (91%) create mode 100644 pkgs/by-name/ko/koito/yarn-fix.patch rename pkgs/by-name/le/learn6502/{yarn-4.14-support.patch => yarn-fix.patch} (90%) rename pkgs/{servers/home-assistant/custom-lovelace-modules/horizon-card/yarn-4.14-support.patch => by-name/li/linkwarden/yarn-fix.patch} (89%) rename pkgs/by-name/lo/losslesscut/{yarn-4.14-support.patch => yarn-fix.patch} (84%) delete mode 100644 pkgs/by-name/ma/mastodon/yarn-4.14-support.patch rename pkgs/by-name/ou/outline/{yarn-4.14-support.patch => yarn-fix.patch} (76%) rename pkgs/by-name/pe/peacock/{yarn-4.14-support.patch => yarn-fix.patch} (81%) rename pkgs/by-name/pg/pgadmin4/{yarn-4.14-support.patch => yarn-fix.patch} (90%) rename pkgs/by-name/r2/r2modman/{yarn-4.14-support.patch => yarn-fix.patch} (88%) rename pkgs/by-name/ro/rocketchat-desktop/{yarn-4.14-support.patch => yarn-fix.patch} (90%) delete mode 100644 pkgs/by-name/sy/synapse-admin/yarn-4.14-support.patch create mode 100644 pkgs/by-name/sy/synapse-admin/yarn-fix.patch delete mode 100644 pkgs/by-name/ti/tilt/yarn-4.14-support.patch create mode 100644 pkgs/by-name/ti/tilt/yarn-fix.patch rename pkgs/by-name/up/uppy-companion/{yarn-4.14-support.patch => yarn-fix.patch} (89%) rename pkgs/by-name/vu/vultisig-cli/{yarn-4.14-support.patch => yarn-fix.patch} (89%) rename pkgs/by-name/yt/ytmdesktop/{yarn-4.14-support.patch => yarn-fix.patch} (89%) rename pkgs/development/python-modules/locust/{yarn-4.14-support.patch => yarn-fix.patch} (89%) rename pkgs/development/tools/electron/{yarn-4.14-support.patch => yarn-fix.patch} (89%) rename pkgs/servers/home-assistant/custom-lovelace-modules/advanced-camera-card/{yarn-4.14-support.patch => yarn-fix.patch} (88%) rename pkgs/{by-name/li/linkwarden/02-yarn-4.14-support.patch => servers/home-assistant/custom-lovelace-modules/horizon-card/yarn-fix.patch} (89%) diff --git a/pkgs/by-name/af/affine/package.nix b/pkgs/by-name/af/affine/package.nix index 43b532795f8c..dcdb19173fd6 100644 --- a/pkgs/by-name/af/affine/package.nix +++ b/pkgs/by-name/af/affine/package.nix @@ -3,6 +3,7 @@ stdenv, stdenvNoCC, fetchFromGitHub, + substitute, rustPlatform, electron, nodejs_22, @@ -51,14 +52,24 @@ stdenv.mkDerivation (finalAttrs: { owner = "toeverything"; repo = "AFFiNE"; tag = "v${finalAttrs.version}"; - hash = "sha256-gtdhWLNZRNY91j9wVVny1bRAjZAwIvNJr11ePQapWYQ="; - }; + hash = "sha256-RotC2mNtMig3QKcKo8zr15myAqkPDuBopvV9wLlr2tQ="; - patches = [ - # Remove after upstream updates to Yarn 4.14 - # https://github.com/toeverything/AFFiNE/blob/canary/package.json#L96 - ./yarn-4.14-support.patch - ]; + # Remove when updating since upstream has updated Yarn + # https://github.com/toeverything/AFFiNE/commit/6375f5ab8c389831327284f4795d8397de085153 + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry.lockfileVersion + ]; + }) + } + ''; + }; cargoDeps = rustPlatform.fetchCargoVendor { inherit (finalAttrs) pname version src; @@ -68,7 +79,7 @@ stdenv.mkDerivation (finalAttrs: { # keep yarnOfflineCache same output style with offlineCache = yarn-berry.fetchYarnBerryDeps { inherit (finalAttrs) src missingHashes; hash = "" }; yarnOfflineCache = stdenvNoCC.mkDerivation { name = "yarn-offline-cache"; - inherit (finalAttrs) src patches; + inherit (finalAttrs) src; nativeBuildInputs = [ yarn-berry cacert @@ -112,7 +123,7 @@ stdenv.mkDerivation (finalAttrs: { ''; dontInstall = true; outputHashMode = "recursive"; - outputHash = "sha256-mNvvKbj9mUioh5Jw4CcRt0CpX1IcQC8JOxUnyy0Lw9c="; + outputHash = "sha256-gje8iTCiy3N/zYRuf/CGUVfGw0RSVXTPu4SjnE9+OY8="; }; buildInputs = lib.optionals hostPlatform.isDarwin [ diff --git a/pkgs/by-name/af/affine/yarn-4.14-support.patch b/pkgs/by-name/af/affine/yarn-4.14-support.patch deleted file mode 100644 index 782730dc89af..000000000000 --- a/pkgs/by-name/af/affine/yarn-4.14-support.patch +++ /dev/null @@ -1,23 +0,0 @@ -diff --git a/.yarnrc.yml b/.yarnrc.yml ---- a/.yarnrc.yml -+++ b/.yarnrc.yml -@@ -12,4 +12,7 @@ npmPublishAccess: public - - npmRegistryServer: "https://registry.npmjs.org" - --yarnPath: .yarn/releases/yarn-4.12.0.cjs -+approvedGitRepositories: -+ - "**" -+ -+enableScripts: true -diff --git a/yarn.lock b/yarn.lock ---- a/yarn.lock -+++ b/yarn.lock -@@ -2,6 +2,6 @@ - # Manual changes might be lost - proceed with caution! - - __metadata: -- version: 8 -+ version: 9 - cacheKey: 10 - diff --git a/pkgs/by-name/af/affine/yarn-fix.patch b/pkgs/by-name/af/affine/yarn-fix.patch new file mode 100644 index 000000000000..00d7fda513dd --- /dev/null +++ b/pkgs/by-name/af/affine/yarn-fix.patch @@ -0,0 +1,58 @@ +diff --git a/.yarnrc.yml b/.yarnrc.yml +--- a/.yarnrc.yml ++++ b/.yarnrc.yml +@@ -12,4 +12,7 @@ npmPublishAccess: public + + npmRegistryServer: "https://registry.npmjs.org" + +-yarnPath: .yarn/releases/yarn-4.12.0.cjs ++approvedGitRepositories: ++ - "**" ++ ++enableScripts: true +diff --git a/yarn.lock b/yarn.lock +--- a/yarn.lock ++++ b/yarn.lock +@@ -2,6 +2,6 @@ + # Manual changes might be lost - proceed with caution! + + __metadata: +- version: 8 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER + cacheKey: 10 + +diff --git a/yarn.lock b/yarn.lock +--- a/yarn.lock ++++ b/yarn.lock +@@ -33250,27 +33250,27 @@ __metadata: + + "resolve@patch:resolve@npm%3A^1.1.6#optional!builtin, resolve@patch:resolve@npm%3A^1.10.0#optional!builtin, resolve@patch:resolve@npm%3A^1.19.0#optional!builtin, resolve@patch:resolve@npm%3A^1.20.0#optional!builtin, resolve@patch:resolve@npm%3A^1.22.1#optional!builtin, resolve@patch:resolve@npm%3A^1.22.8#optional!builtin": + version: 1.22.11 +- resolution: "resolve@patch:resolve@npm%3A1.22.11#optional!builtin::version=1.22.11&hash=c3c19d" ++ resolution: "resolve@patch:resolve@npm%3A1.22.11#optional!builtin::version=1.22.11&hash=9bd1a5" + dependencies: + is-core-module: "npm:^2.16.1" + path-parse: "npm:^1.0.7" + supports-preserve-symlinks-flag: "npm:^1.0.0" + bin: + resolve: bin/resolve +- checksum: 10/fd342cad25e52cd6f4f3d1716e189717f2522bfd6641109fe7aa372f32b5714a296ed7c238ddbe7ebb0c1ddfe0b7f71c9984171024c97cf1b2073e3e40ff71a8 ++ checksum: 10/c990146fed81dd7792c56c1d62c170a8c8330bee86ef5d2524f0b1db79cfd9a6e2b4ad3cd4742b2685e51117b67be5d6f8cfd6ffa9c57bd64a1c8c8c9ff4c965 + languageName: node + linkType: hard + + "resolve@patch:resolve@npm%3A^2.0.0-next.5#optional!builtin": + version: 2.0.0-next.5 +- resolution: "resolve@patch:resolve@npm%3A2.0.0-next.5#optional!builtin::version=2.0.0-next.5&hash=c3c19d" ++ resolution: "resolve@patch:resolve@npm%3A2.0.0-next.5#optional!builtin::version=2.0.0-next.5&hash=9bd1a5" + dependencies: + is-core-module: "npm:^2.13.0" + path-parse: "npm:^1.0.7" + supports-preserve-symlinks-flag: "npm:^1.0.0" + bin: + resolve: bin/resolve +- checksum: 10/05fa778de9d0347c8b889eb7a18f1f06bf0f801b0eb4610b4871a4b2f22e220900cf0ad525e94f990bb8d8921c07754ab2122c0c225ab4cdcea98f36e64fa4c2 ++ checksum: 10/76c221deb1d986c0a80cd576373b0ee09f42871e0085a1f76beda84f73ce04e0d21bab28dffd326eb006a7af83bbc582404566b384aa3b0baa217f56cf7e8618 + languageName: node + linkType: hard + diff --git a/pkgs/by-name/an/anki/package.nix b/pkgs/by-name/an/anki/package.nix index 5f5119b4d917..d53ca31f1ce4 100644 --- a/pkgs/by-name/an/anki/package.nix +++ b/pkgs/by-name/an/anki/package.nix @@ -24,6 +24,7 @@ yarn, yarn-berry_4, runCommand, + substitute, wrapGAppsHook3, @@ -42,7 +43,7 @@ let srcHash = "sha256-0sqtKiMqw7MLXVFSCT1sKX/VO7q5BY63pJP5OnCE2zo="; cargoHash = "sha256-LQ5uD86ZOKXy9vGbTqPBi3Q57PZEjwQkbHR94QAIVMg="; - yarnHash = "sha256-bOgiZImraPXR/gVk9MB3o9GScMGvLvdhc9mLAaCA4IE="; + yarnHash = "sha256-mpHGclmQxFqiIuZWFTOYBKQW24ugSVhQiYMTmyyk/n4="; pythonDeps = with python3Packages; [ @@ -155,9 +156,16 @@ python3Packages.buildPythonApplication (finalAttrs: { # Used in with-addons.nix ./patches/allow-setting-addons-folder.patch - # Remove after upstream updates to Yarn 4.14 - # https://github.com/ankitects/anki/blob/main/package.json#L99 - ./patches/yarn-4.14-support.patch + # Remove after upstream updates to Yarn 4.15 + # https://github.com/ankitects/anki/blob/main/package.json#L103 + (substitute { + src = ./patches/yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry.lockfileVersion + ]; + }) ]; inherit cargoDeps; diff --git a/pkgs/by-name/an/anki/patches/yarn-4.14-support.patch b/pkgs/by-name/an/anki/patches/yarn-fix.patch similarity index 88% rename from pkgs/by-name/an/anki/patches/yarn-4.14-support.patch rename to pkgs/by-name/an/anki/patches/yarn-fix.patch index c45ad0430e5e..1be64c531419 100644 --- a/pkgs/by-name/an/anki/patches/yarn-4.14-support.patch +++ b/pkgs/by-name/an/anki/patches/yarn-fix.patch @@ -14,6 +14,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10c0 diff --git a/pkgs/by-name/aw/aws-cdk-cli/package.nix b/pkgs/by-name/aw/aws-cdk-cli/package.nix index d83a5c101d78..1e49b63437f1 100644 --- a/pkgs/by-name/aw/aws-cdk-cli/package.nix +++ b/pkgs/by-name/aw/aws-cdk-cli/package.nix @@ -50,7 +50,6 @@ stdenv.mkDerivation (finalAttrs: { NX_VERBOSE_LOGGING = "true"; # Needed to properly embed version info CODEBUILD_RESOLVED_SOURCE_VERSION = finalAttrs.version; - YARN_LOCKFILE_VERSION_OVERRIDE = "8"; }; # Regular "build" is very heavy and does things we don't need. @@ -64,13 +63,6 @@ stdenv.mkDerivation (finalAttrs: { in '' echo '${cliVersionJson}' > packages/@aws-cdk/cloud-assembly-schema/cli-version.json - cat >> .yarnrc.yml <<'EOF' - approvedGitRepositories: - - "**" - enableScripts: true - enableNetwork: false - enableHardenedMode: false - EOF ''; preBuild = '' diff --git a/pkgs/by-name/bi/bitfocus-companion/package.nix b/pkgs/by-name/bi/bitfocus-companion/package.nix index 9bbdfd6c65be..d02ee3705a38 100644 --- a/pkgs/by-name/bi/bitfocus-companion/package.nix +++ b/pkgs/by-name/bi/bitfocus-companion/package.nix @@ -2,6 +2,7 @@ stdenv, lib, fetchFromGitHub, + substitute, fetchurl, nodejs, git, @@ -50,7 +51,23 @@ stdenv.mkDerivation rec { owner = "bitfocus"; repo = "companion"; tag = "v${version}"; - hash = "sha256-ojSXiWaRKFCjHmAMs/RtzNhgSNUy7RKTZ4CE/wCxEaI="; + hash = "sha256-01zW6IrUgubxDSiGffGajZnWlssNsh8kO5FljVcjyL0="; + + # Remove when updating since upstream updated Yarn + # https://github.com/bitfocus/companion/commit/d2ad585c510f328f4bf111b7e489225925882354 + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry.lockfileVersion + ]; + }) + } + ''; }; passthru.updateScript = nix-update-script { }; @@ -100,15 +117,13 @@ stdenv.mkDerivation rec { offlineCache = yarn-berry.fetchYarnBerryDeps { inherit src missingHashes; - hash = "sha256-XDXxv+LSr9fYhVhwkcvmd56fAL6gY9FK6kiQlXxTWXo="; + hash = "sha256-LKIDfngn7Yia9oRwb8Ze0FOiZqreUMa6vuolqSz2hWo="; }; env = { ELECTRON_SKIP_BINARY_DOWNLOAD = 1; SKIP_LAUNCH_CHECK = true; ELECTRON = 0; - # prevent yarn >= 4.14 from triggering a lockfile refresh for v8 lockfiles - YARN_LOCKFILE_VERSION_OVERRIDE = 8; }; # with dontConfigure it doesn't seem to retrieve node_modules, so empty configurePhase instead diff --git a/pkgs/by-name/el/electron-fiddle/yarn-metadata-version.patch b/pkgs/by-name/bi/bitfocus-companion/yarn-fix.patch similarity index 62% rename from pkgs/by-name/el/electron-fiddle/yarn-metadata-version.patch rename to pkgs/by-name/bi/bitfocus-companion/yarn-fix.patch index 780b7265824a..d1667e6e319f 100644 --- a/pkgs/by-name/el/electron-fiddle/yarn-metadata-version.patch +++ b/pkgs/by-name/bi/bitfocus-companion/yarn-fix.patch @@ -1,13 +1,11 @@ diff --git a/yarn.lock b/yarn.lock -index 365f8b4d..ffa89a3d 100644 --- a/yarn.lock +++ b/yarn.lock -@@ -2,7 +2,7 @@ +@@ -2,6 +2,6 @@ # Manual changes might be lost - proceed with caution! __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10c0 - "@aashutoshrathi/word-wrap@npm:^1.2.3": diff --git a/pkgs/by-name/co/cockpit-zfs/package.nix b/pkgs/by-name/co/cockpit-zfs/package.nix index 2ccadc3f3197..4599d759083e 100644 --- a/pkgs/by-name/co/cockpit-zfs/package.nix +++ b/pkgs/by-name/co/cockpit-zfs/package.nix @@ -1,7 +1,6 @@ { acl, bash, - buildPackages, cockpit, coreutils, fetchFromGitHub, @@ -15,7 +14,7 @@ mbuffer, msmtp, nix-update-script, - nodejs_22, + nodejs, openssh, samba, shadow, @@ -27,22 +26,6 @@ yarn-berry, zfs, }: -let - # Pin to Node <24.15.0: Yarn Berry's PnP linker breaks `require.cache` on - # newer Node, which crashes tailwindcss mid-build (and ESLint, per - # yarnpkg/berry#7106). See NixOS/nixpkgs#530137. - # - # `nodejs` is rebound here (rather than touched at every call site below) - # so the rest of this file is unaffected. - # - # yarn-berry's own `yarn` binary gets patchShebang'd against whatever - # `nodejs` *it* was built with, so overriding nativeBuildInputs alone does - # nothing - we have to rebuild yarn-berry itself against nodejs_22, for - # both the host and build-platform (cross-compilation) variants. - nodejs = nodejs_22; - yarnBerry = yarn-berry.override { inherit nodejs; }; - yarnBerryForBuild = buildPackages.yarn-berry.override { nodejs = buildPackages.nodejs_22; }; -in stdenv.mkDerivation (finalAttrs: { pname = "cockpit-zfs"; @@ -59,17 +42,17 @@ stdenv.mkDerivation (finalAttrs: { missingHashes = ./missing-hashes.json; # Use buildPackages for cross-compilation support - offlineCache = yarnBerryForBuild.fetchYarnBerryDeps { + offlineCache = yarn-berry.fetchYarnBerryDeps { inherit (finalAttrs) src missingHashes; hash = "sha256-nm3iHf9Rm5JFKzH0HAvglkQPFIV6Fl1e9WvNdqevTug="; }; nativeBuildInputs = [ makeWrapper - nodejs_22 + nodejs jq - yarnBerry - yarnBerryForBuild.yarnBerryConfigHook + yarn-berry + yarn-berry.yarnBerryConfigHook ]; disallowedRequisites = [ finalAttrs.offlineCache ]; @@ -86,7 +69,7 @@ stdenv.mkDerivation (finalAttrs: { lsscsi mbuffer msmtp - nodejs_22 + nodejs openssh samba shadow diff --git a/pkgs/by-name/ea/eas-cli/package.nix b/pkgs/by-name/ea/eas-cli/package.nix index 567372a7f135..3f61e5f469ea 100644 --- a/pkgs/by-name/ea/eas-cli/package.nix +++ b/pkgs/by-name/ea/eas-cli/package.nix @@ -2,6 +2,7 @@ lib, stdenv, fetchFromGitHub, + substitute, yarn-berry_4, nodejs, jq, @@ -15,14 +16,25 @@ let owner = "expo"; repo = "eas-cli"; rev = "v${version}"; - hash = "sha256-EMN54PR9lhrZcGMq2iNUsdyBP3wVk4G/isjsneIGslI="; + hash = "sha256-WfzCV304xgTqiKBCsZc5rnzaC+UHA6c155FG+HWBY7s="; + + # Remove after upstream updates to Yarn 4.15 + # https://github.com/expo/eas-cli/blob/main/package.json#L38 + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry_4.lockfileVersion + ]; + }) + } + ''; }; missingHashes = ./missing-hashes.json; - patches = [ - # Remove after upstream updates to Yarn 4.14 - # https://github.com/expo/eas-cli/blob/v18.7.0/package.json#L37 - ./yarn-4.14-support.patch - ]; in # cc is necessary because of building an npm package without a prebuilt binary # for ARM. See comment in nativeBuildInputs below. @@ -32,12 +44,11 @@ stdenv.mkDerivation (finalAttrs: { src version missingHashes - patches ; yarnOfflineCache = yarn-berry_4.fetchYarnBerryDeps { - inherit src missingHashes patches; - hash = "sha256-dOx4T009+FMFEvTZtlyJpAUo2UYBm1O1hIyBnSbqIgw="; + inherit src missingHashes; + hash = "sha256-Iqdk0MpXeiKm5hgF68XOKvl0a+5LpXsNNcelCcbfj3s="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/ea/eas-cli/yarn-4.14-support.patch b/pkgs/by-name/ea/eas-cli/yarn-fix.patch similarity index 89% rename from pkgs/by-name/ea/eas-cli/yarn-4.14-support.patch rename to pkgs/by-name/ea/eas-cli/yarn-fix.patch index 2591021c6269..a67bb75f0925 100644 --- a/pkgs/by-name/ea/eas-cli/yarn-4.14-support.patch +++ b/pkgs/by-name/ea/eas-cli/yarn-fix.patch @@ -15,6 +15,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10c0 diff --git a/pkgs/by-name/el/electron-fiddle/package.nix b/pkgs/by-name/el/electron-fiddle/package.nix index f083d5c1b88b..cfe7cf999881 100644 --- a/pkgs/by-name/el/electron-fiddle/package.nix +++ b/pkgs/by-name/el/electron-fiddle/package.nix @@ -1,7 +1,6 @@ { buildFHSEnv, fetchFromGitHub, - fetchYarnDeps, electron, git, lib, @@ -10,6 +9,7 @@ stdenvNoCC, util-linux, yarn-berry_4, + substitute, zip, }: @@ -22,7 +22,23 @@ let owner = "electron"; repo = "fiddle"; tag = "v${version}"; - hash = "sha256-nmmj1PvW9LOoEdwwWRRXe9q9J8z6Fp45Tt038BjWD+k="; + hash = "sha256-5Pw889lHRwWoTUVbLmToPF8/bDz382qFMO9mL/EKLo0="; + + # Remove after upstream updates to Yarn 4.15 + # https://github.com/electron/fiddle/blob/main/package.json#L163 + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry.lockfileVersion + ]; + }) + } + ''; }; patches = [ @@ -31,9 +47,6 @@ let # zip extraction fails on newer nodejs versions without this fix ./bump-yauzl.patch - - # https://github.com/nixos/nixpkgs/issues/542343 - ./yarn-metadata-version.patch ]; missingHashes = ./missing-hashes.json; @@ -49,7 +62,7 @@ let offlineCache = yarn-berry.fetchYarnBerryDeps { inherit src patches missingHashes; - hash = "sha256-xxguRiyZDGdVt3eYh+KUI/odLZZ/LeScRBfexMxAOVI="; + hash = "sha256-O9zaCL0W8JPYQz8EBWOz0qGjW57Js3oMosUbz72YBc4="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/el/electron-fiddle/yarn-fix.patch b/pkgs/by-name/el/electron-fiddle/yarn-fix.patch new file mode 100644 index 000000000000..cf10d3150a43 --- /dev/null +++ b/pkgs/by-name/el/electron-fiddle/yarn-fix.patch @@ -0,0 +1,58 @@ +diff --git a/.yarnrc.yml b/.yarnrc.yml +--- a/.yarnrc.yml ++++ b/.yarnrc.yml +@@ -1,7 +1,5 @@ + nodeLinker: node-modules + +-yarnPath: .yarn/releases/yarn-4.10.3.cjs +- + # see package.json for Electron postinstall + enableScripts: false + +diff --git a/yarn.lock b/yarn.lock +index 365f8b4d..ffa89a3d 100644 +--- a/yarn.lock ++++ b/yarn.lock +@@ -2,6 +2,6 @@ + # Manual changes might be lost - proceed with caution! + + __metadata: +- version: 8 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER + cacheKey: 10c0 + +diff --git a/yarn.lock b/yarn.lock +--- a/yarn.lock ++++ b/yarn.lock +@@ -11277,27 +11277,27 @@ __metadata: + + "resolve@patch:resolve@npm%3A^1.22.1#optional!builtin, resolve@patch:resolve@npm%3A~1.22.2#optional!builtin": + version: 1.22.11 +- resolution: "resolve@patch:resolve@npm%3A1.22.11#optional!builtin::version=1.22.11&hash=c3c19d" ++ resolution: "resolve@patch:resolve@npm%3A1.22.11#optional!builtin::version=1.22.11&hash=9bd1a5" + dependencies: + is-core-module: "npm:^2.16.1" + path-parse: "npm:^1.0.7" + supports-preserve-symlinks-flag: "npm:^1.0.0" + bin: + resolve: bin/resolve +- checksum: 10c0/ee5b182f2e37cb1165465e58c6abc797fec0a80b5ba3231607beb4677db0c9291ac010c47cf092b6daa2b7f518d69a0e21888e7e2b633f68d501a874212a8c63 ++ checksum: 10c0/55f7a298977b1aacf6dbec6dcfc81100ba98675bced193b57d3ac58ced65acc40c3a38927853cea86b7f75edb3c20e1f099a09d48b0d8ceccc25d466993eec47 + languageName: node + linkType: hard + + "resolve@patch:resolve@npm%3A^2.0.0-next.4#optional!builtin": + version: 2.0.0-next.4 +- resolution: "resolve@patch:resolve@npm%3A2.0.0-next.4#optional!builtin::version=2.0.0-next.4&hash=c3c19d" ++ resolution: "resolve@patch:resolve@npm%3A2.0.0-next.4#optional!builtin::version=2.0.0-next.4&hash=9bd1a5" + dependencies: + is-core-module: "npm:^2.9.0" + path-parse: "npm:^1.0.7" + supports-preserve-symlinks-flag: "npm:^1.0.0" + bin: + resolve: bin/resolve +- checksum: 10c0/ed2bb51d616b9cd30fe85cf49f7a2240094d9fa01a221d361918462be81f683d1855b7f192391d2ab5325245b42464ca59690db5bd5dad0a326fc0de5974dd10 ++ checksum: 10c0/c86731c5e95ceaa3bf7a0e5d451a9c5e50f7d8c545300de905cda347b5c6d7e23b500b365757673cc884f9be93c23b8aa4dc5c5350b7e6cdfec8149c4b257479 + languageName: node + linkType: hard + diff --git a/pkgs/by-name/gi/gitbeaker-cli/package.nix b/pkgs/by-name/gi/gitbeaker-cli/package.nix index 2fc7ec894a8d..58773ae02fa9 100644 --- a/pkgs/by-name/gi/gitbeaker-cli/package.nix +++ b/pkgs/by-name/gi/gitbeaker-cli/package.nix @@ -2,6 +2,7 @@ lib, stdenv, fetchFromGitHub, + substitute, nodejs, gnutar, makeBinaryWrapper, @@ -17,14 +18,24 @@ stdenv.mkDerivation (finalAttrs: { owner = "jdalrymple"; repo = "gitbeaker"; tag = finalAttrs.version; - hash = "sha256-EVxDUEuxCnMiqqsKFs9JpRVJ86d9hW22K4a4we8eoJA="; - }; + hash = "sha256-zGcSilIQUKn7iMGFkDZuvPZZM9UcZadczelB7JgVYb4="; - patches = [ - # Remove this when updating since upstream migrated to pnpm - # https://github.com/jdalrymple/gitbeaker/blob/main/package.json#L59 - ./yarn-4.14-support.patch - ]; + # Remove when updating since upstream migrated to pnpm + # https://github.com/jdalrymple/gitbeaker/blob/main/package.json#L61 + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry_4.lockfileVersion + ]; + }) + } + ''; + }; # Set for the `nodejsInstall` hooks npmWorkspace = "@gitbeaker/cli"; @@ -42,8 +53,8 @@ stdenv.mkDerivation (finalAttrs: { missingHashes = ./missing-hashes.json; offlineCache = yarn-berry_4.fetchYarnBerryDeps { - inherit (finalAttrs) src missingHashes patches; - hash = "sha256-RTgdHicbfbJbToif51TchLCfdIPZynvT0n/KwrydLYU="; + inherit (finalAttrs) src missingHashes; + hash = "sha256-OMsa/4pRyZVjgYPfYsaj1D+auKOHRAXKtEDYWenI33I="; }; buildPhase = '' diff --git a/pkgs/by-name/gi/gitbeaker-cli/yarn-4.14-support.patch b/pkgs/by-name/gi/gitbeaker-cli/yarn-fix.patch similarity index 89% rename from pkgs/by-name/gi/gitbeaker-cli/yarn-4.14-support.patch rename to pkgs/by-name/gi/gitbeaker-cli/yarn-fix.patch index aa1ac588934c..e55b7512d292 100644 --- a/pkgs/by-name/gi/gitbeaker-cli/yarn-4.14-support.patch +++ b/pkgs/by-name/gi/gitbeaker-cli/yarn-fix.patch @@ -17,6 +17,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10c0 diff --git a/pkgs/by-name/he/hedgedoc/package.nix b/pkgs/by-name/he/hedgedoc/package.nix index a0173a2f6fa9..fc5e594c8e95 100644 --- a/pkgs/by-name/he/hedgedoc/package.nix +++ b/pkgs/by-name/he/hedgedoc/package.nix @@ -2,6 +2,7 @@ lib, stdenv, fetchFromGitHub, + substitute, makeBinaryWrapper, nodejs, python3, @@ -17,22 +18,31 @@ stdenv.mkDerivation (finalAttrs: { owner = "hedgedoc"; repo = "hedgedoc"; tag = finalAttrs.version; - hash = "sha256-QYWDgQuSsMf8xElSK0MpthOMAB6EJXcxfOWcHrR4ODU="; - }; + hash = "sha256-sKmy80FO5cp2aKoirtzaPmf2IqTn5yLUkbakIZMa5aQ="; - patches = [ - # Remove after upstream updates to Yarn 4.14 - # https://github.com/hedgedoc/hedgedoc/blob/develop/package.json#L28 - ./yarn-4.14-support.patch - ]; + # Remove after https://github.com/hedgedoc/hedgedoc/commit/6e6536df1b7b8e1ad30a0929be5b851eef98029f is released + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry_4.lockfileVersion + ]; + }) + } + ''; + }; # Generate this file with: # nix run nixpkgs#yarn-berry_4.yarn-berry-fetcher missing-hashes yarn.lock missingHashes = ./missing-hashes.json; offlineCache = yarn-berry_4.fetchYarnBerryDeps { - inherit (finalAttrs) src missingHashes patches; - hash = "sha256-2qwTV9GRKnVIhK6dsSfis+JOTfjcdwW0RVdrJZa/uJc="; + inherit (finalAttrs) src missingHashes; + hash = "sha256-OywEJNs1DwUnPPjW2CzEYKhfHz03EcSEJ1PUWx8DGUI="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/he/hedgedoc/yarn-4.14-support.patch b/pkgs/by-name/he/hedgedoc/yarn-fix.patch similarity index 90% rename from pkgs/by-name/he/hedgedoc/yarn-4.14-support.patch rename to pkgs/by-name/he/hedgedoc/yarn-fix.patch index 965bede33cf7..c3f584b8e6dd 100644 --- a/pkgs/by-name/he/hedgedoc/yarn-4.14-support.patch +++ b/pkgs/by-name/he/hedgedoc/yarn-fix.patch @@ -18,6 +18,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10 diff --git a/pkgs/by-name/in/insulator2/package.nix b/pkgs/by-name/in/insulator2/package.nix index 5f42e73a124b..93275d2bb39a 100644 --- a/pkgs/by-name/in/insulator2/package.nix +++ b/pkgs/by-name/in/insulator2/package.nix @@ -3,6 +3,7 @@ stdenv, fetchFromGitHub, + substitute, yarn-berry_4, cargo, @@ -31,19 +32,29 @@ stdenv.mkDerivation (finalAttrs: { owner = "andrewinci"; repo = "insulator2"; rev = "v${finalAttrs.version}"; - hash = "sha256-3eDA+pwchnwWtweGeSDlf+Vt0Hoylmanf4hnvJ2YOGU="; - }; + hash = "sha256-QCoDiFEgVuF/+MqgzcMTXqjC/nDA+A2v3l01kZyviDs="; - patches = [ - # Remove after upstream updates to Yarn 4.14 + # Remove after upstream updates to Yarn 4.15 # https://github.com/andrewinci/insulator2/blob/main/package.json#L105 - ./yarn-4.14-support.patch - ]; + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry_4.lockfileVersion + ]; + }) + } + ''; + }; missingHashes = ./missing-hashes.json; offlineCache = yarn-berry_4.fetchYarnBerryDeps { - inherit (finalAttrs) src missingHashes patches; - hash = "sha256-IechRla3epfANBESCYgti5/8B3QaPCv6Gp2I4eZNiyI="; + inherit (finalAttrs) src missingHashes; + hash = "sha256-2w1fMVwQFClyrpNmJrjJoDqbU2nxRZh9NkBIcMUEjec="; }; cargoDeps = rustPlatform.fetchCargoVendor { diff --git a/pkgs/by-name/in/insulator2/yarn-4.14-support.patch b/pkgs/by-name/in/insulator2/yarn-fix.patch similarity index 88% rename from pkgs/by-name/in/insulator2/yarn-4.14-support.patch rename to pkgs/by-name/in/insulator2/yarn-fix.patch index 017f2d295ca9..868db25c8d32 100644 --- a/pkgs/by-name/in/insulator2/yarn-4.14-support.patch +++ b/pkgs/by-name/in/insulator2/yarn-fix.patch @@ -16,6 +16,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10c0 diff --git a/pkgs/by-name/jo/joplin-cli/package.nix b/pkgs/by-name/jo/joplin-cli/package.nix index d38bd270fe3f..bb8d7456ba79 100644 --- a/pkgs/by-name/jo/joplin-cli/package.nix +++ b/pkgs/by-name/jo/joplin-cli/package.nix @@ -3,6 +3,7 @@ stdenv, nodejs, fetchFromGitHub, + substitute, yarn-berry_4, python3, pkg-config, @@ -24,15 +25,23 @@ stdenv.mkDerivation (finalAttrs: { postFetch = '' # there's a file with a weird name that causes a hash mismatch on darwin rm $out/packages/app-cli/tests/support/photo* - ''; - hash = "sha256-nWMUvAseKoTOv5ui9uYDUiGlvO+8nNV4ux7JbsnrM5U="; - }; - patches = [ - # Remove after upstream updates to Yarn 4.14 - # https://github.com/laurent22/joplin/blob/dev/package.json#L103 - ./yarn-4.14-support.patch - ]; + # Remove when updating since upstream has updated Yarn + # https://github.com/laurent22/joplin/commit/071f205c44da8e2979dcf53a4105648bfa0e7f83 + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry_4.lockfileVersion + ]; + }) + } + ''; + hash = "sha256-LSkiW3Kwtjsk2LLM/MXo6ErR+G8b7IX3LkEtDJlc7ok="; + }; missingHashes = ./missing-hashes.json; @@ -40,10 +49,9 @@ stdenv.mkDerivation (finalAttrs: { inherit (finalAttrs) src missingHashes - patches postPatch ; - hash = "sha256-mdDVYLJ4ZN7zJJdf/2Wh+or+p1uJPTrMCyDYWwc04YM="; + hash = "sha256-EHHAB20syDakpN4TGuLCc1v2AGEJPc3y7uCpS+PVzzQ="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/jo/joplin-cli/yarn-4.14-support.patch b/pkgs/by-name/jo/joplin-cli/yarn-fix.patch similarity index 91% rename from pkgs/by-name/jo/joplin-cli/yarn-4.14-support.patch rename to pkgs/by-name/jo/joplin-cli/yarn-fix.patch index dfcc07f08841..c70079375f30 100644 --- a/pkgs/by-name/jo/joplin-cli/yarn-4.14-support.patch +++ b/pkgs/by-name/jo/joplin-cli/yarn-fix.patch @@ -21,6 +21,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10 diff --git a/pkgs/by-name/jo/joplin-desktop/package.nix b/pkgs/by-name/jo/joplin-desktop/package.nix index b003c063c6b2..e87bd4e32c33 100644 --- a/pkgs/by-name/jo/joplin-desktop/package.nix +++ b/pkgs/by-name/jo/joplin-desktop/package.nix @@ -45,9 +45,9 @@ stdenv.mkDerivation (finalAttrs: { # there's a file with a weird name that causes a hash mismatch on darwin rm $out/packages/app-cli/tests/support/photo* - # Remove after upstream updates to Yarn 4.14 - # https://github.com/laurent22/joplin/blob/dev/package.json#L103 - sed -i '/__metadata/{n;s/version: 8$/version: 9/;}' $out/yarn.lock + # Remove when updating since upstream updated Yarn + # https://github.com/laurent22/joplin/commit/071f205c44da8e2979dcf53a4105648bfa0e7f83 + sed -i '/__metadata/{n;s/version: 8$/version: ${yarn-berry.lockfileVersion}/;}' $out/yarn.lock ''; inherit (releaseData) hash; }; diff --git a/pkgs/by-name/jo/joplin-desktop/release-data.json b/pkgs/by-name/jo/joplin-desktop/release-data.json index cc2e899f0202..7f1937b80a66 100644 --- a/pkgs/by-name/jo/joplin-desktop/release-data.json +++ b/pkgs/by-name/jo/joplin-desktop/release-data.json @@ -1,6 +1,6 @@ { "version": "3.6.16", - "hash": "sha256-0W6xNcEMXIs8XsoY6NqSud9D5fEmc5GKFC8Uo6CEtec=", + "hash": "sha256-S1PIhotA0Y57ZeT9xBcbMInblwFK8LKwXlcnMs2TB3Q=", "plugins": { "io.github.jackgruber.backup": { "name": "joplin-plugin-backup", @@ -9,5 +9,5 @@ "npmDepsHash": "sha256-xZJ0Oir1A6sLe0ztIyBu39Yy3D6sNrVaciOYG0k85l0=" } }, - "deps_hash": "sha256-ejg0u9Dy3iaBusH248IbtJNpvd/zADyPJ9CplIK1A/w=" + "deps_hash": "sha256-mj9s97D/4UJqctl5NtyJRWYTc6fFAC0ueZE78KZVFsQ=" } diff --git a/pkgs/by-name/ko/koito/client.nix b/pkgs/by-name/ko/koito/client.nix index d696189f04a2..d611c8659143 100644 --- a/pkgs/by-name/ko/koito/client.nix +++ b/pkgs/by-name/ko/koito/client.nix @@ -17,7 +17,7 @@ stdenv.mkDerivation (finalAttrs: { missingHashes = ./missing-hashes.json; offlineCache = yarn.fetchYarnBerryDeps { inherit (finalAttrs) src sourceRoot missingHashes; - hash = "sha256-VIlWld21GScJ/2UUkKQISM9jyU9wCVwwDNKkge+K044="; + hash = "sha256-2kWRZBGm7pTpOwZ1Wp+pCU5WWFche1xqGyLL86eGEow="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/ko/koito/package.nix b/pkgs/by-name/ko/koito/package.nix index 1b088365b8f8..fd1dc293ed3f 100644 --- a/pkgs/by-name/ko/koito/package.nix +++ b/pkgs/by-name/ko/koito/package.nix @@ -2,6 +2,8 @@ lib, buildGoModule, fetchFromGitHub, + substitute, + yarn-berry_4, callPackage, pkg-config, vips, @@ -15,7 +17,23 @@ buildGoModule (finalAttrs: { owner = "gabehf"; repo = "koito"; rev = "v${finalAttrs.version}"; - hash = "sha256-68+Z4Alzu+4v/PxU1IOboqZkF1pO+y6gswuO+HPS7dk="; + hash = "sha256-z0HeuPYQwkyKkt8K7PKUYseECz2p1C/6UO5sUSxopBQ="; + + # Remove when upstream updates to Yarn 4.15 + # https://github.com/gabehf/Koito/blob/main/client/package.json#L44 + postFetch = '' + cd $out/client + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry_4.lockfileVersion + ]; + }) + } + ''; }; __structuredAttrs = true; @@ -47,6 +65,7 @@ buildGoModule (finalAttrs: { passthru = { client = callPackage ./client.nix { inherit (finalAttrs) src version; + inherit yarn-berry_4; }; tests = { diff --git a/pkgs/by-name/ko/koito/yarn-fix.patch b/pkgs/by-name/ko/koito/yarn-fix.patch new file mode 100644 index 000000000000..7b3deff55c1d --- /dev/null +++ b/pkgs/by-name/ko/koito/yarn-fix.patch @@ -0,0 +1,11 @@ +diff --git a/yarn.lock b/yarn.lock +--- a/yarn.lock ++++ b/yarn.lock +@@ -2,6 +2,6 @@ + # Manual changes might be lost - proceed with caution! + + __metadata: +- version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER + cacheKey: 10c0 + diff --git a/pkgs/by-name/le/learn6502/package.nix b/pkgs/by-name/le/learn6502/package.nix index 7f608f7533d9..4131bb10d0b5 100644 --- a/pkgs/by-name/le/learn6502/package.nix +++ b/pkgs/by-name/le/learn6502/package.nix @@ -2,6 +2,7 @@ lib, stdenv, fetchFromGitHub, + substitute, yarn-berry_4, nodejs, meson, @@ -30,22 +31,34 @@ stdenv.mkDerivation (finalAttrs: { owner = "JumpLink"; repo = "Learn6502"; tag = "v${finalAttrs.version}"; - hash = "sha256-wttNOF1ngEK70u+6bBZkFLzvJCQaL9KMfy7EG+mfHIg="; + hash = "sha256-b91b+H5avQDYknDaKUSPGG+Vq6sxSwuJgSiVzdqlbh8="; + + # Remove when updating since upstream migrated to gjsify + # https://github.com/JumpLink/Learn6502/commit/1ae86c179aede8c5785aeda66db334a29d02a7c0 + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry_4.lockfileVersion + ]; + }) + } + ''; }; patches = [ ./get-yarn-from-path.patch - - # Remove after upstream updates to Yarn 4.14 - # https://github.com/JumpLink/Learn6502/blob/main/package.json#L36 - ./yarn-4.14-support.patch ]; missingHashes = ./missing-hashes.json; offlineCache = yarn-berry.fetchYarnBerryDeps { - inherit (finalAttrs) src missingHashes patches; - hash = "sha256-fWx1zawU8pJQ3Q7PYWKmJh3Ko7b8wO0m3KS6XCSd9v8="; + inherit (finalAttrs) src missingHashes; + hash = "sha256-BIP2L6EQXKzpiYrA8qpqQEQ/NnjFrQSyHlmFg7vg1Xk="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/le/learn6502/yarn-4.14-support.patch b/pkgs/by-name/le/learn6502/yarn-fix.patch similarity index 90% rename from pkgs/by-name/le/learn6502/yarn-4.14-support.patch rename to pkgs/by-name/le/learn6502/yarn-fix.patch index 7cf0d4d94092..5a39ecd3f512 100644 --- a/pkgs/by-name/le/learn6502/yarn-4.14-support.patch +++ b/pkgs/by-name/le/learn6502/yarn-fix.patch @@ -18,6 +18,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10c0 diff --git a/pkgs/by-name/li/linkwarden/package.nix b/pkgs/by-name/li/linkwarden/package.nix index 7844371304c9..b1041ab8a87c 100644 --- a/pkgs/by-name/li/linkwarden/package.nix +++ b/pkgs/by-name/li/linkwarden/package.nix @@ -4,6 +4,7 @@ buildNpmPackage, fetchFromGitHub, yarn-berry, + substitute, makeBinaryWrapper, nixosTests, stdenv, @@ -75,7 +76,23 @@ stdenvNoCC.mkDerivation (finalAttrs: { owner = "linkwarden"; repo = "linkwarden"; tag = "v${finalAttrs.version}"; - hash = "sha256-4S2/TRZlMa3KHM+tmrWQsqGFk0TZjMbhdS2b1aNTVow="; + hash = "sha256-/Hnavo98+X0XAULkMKLVO2H4eK548I/d8l/b0NzM88I="; + + # Remove after upstream updates to Yarn 4.15 + # https://github.com/linkwarden/linkwarden/blob/main/package.json#L3 + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry.lockfileVersion + ]; + }) + } + ''; }; patches = [ @@ -89,16 +106,12 @@ stdenvNoCC.mkDerivation (finalAttrs: { pkgs/by-name/ne/nextjs-ollama-llm-ui/0002-use-local-google-fonts.patch */ ./01-localfont.patch - - # Remove after upstream updates to Yarn 4.14 - # https://github.com/linkwarden/linkwarden/blob/main/package.json#L3 - ./02-yarn-4.14-support.patch ]; missingHashes = ./missing-hashes.json; yarnOfflineCache = yarn-berry.fetchYarnBerryDeps { - inherit (finalAttrs) src missingHashes patches; - hash = "sha256-f7xIzxN+0JWZeGfeK/3XTiUbxrnnzErbFEukolMMv/s="; + inherit (finalAttrs) src missingHashes; + hash = "sha256-6NiA2gNBk3auIjYqv9TxsbUR/k7ygj6KejrWx+Gy0pg="; }; nativeBuildInputs = [ diff --git a/pkgs/servers/home-assistant/custom-lovelace-modules/horizon-card/yarn-4.14-support.patch b/pkgs/by-name/li/linkwarden/yarn-fix.patch similarity index 89% rename from pkgs/servers/home-assistant/custom-lovelace-modules/horizon-card/yarn-4.14-support.patch rename to pkgs/by-name/li/linkwarden/yarn-fix.patch index 75225db95b78..7a11f6399640 100644 --- a/pkgs/servers/home-assistant/custom-lovelace-modules/horizon-card/yarn-4.14-support.patch +++ b/pkgs/by-name/li/linkwarden/yarn-fix.patch @@ -15,6 +15,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10c0 diff --git a/pkgs/by-name/lo/losslesscut/package.nix b/pkgs/by-name/lo/losslesscut/package.nix index 3aba1df4368f..de14db04ca23 100644 --- a/pkgs/by-name/lo/losslesscut/package.nix +++ b/pkgs/by-name/lo/losslesscut/package.nix @@ -1,6 +1,7 @@ { lib, fetchFromGitHub, + substitute, stdenv, yarn-berry_4, nodejs_24, @@ -25,13 +26,28 @@ stdenv.mkDerivation (finalAttrs: { owner = "mifi"; repo = "lossless-cut"; tag = "v${finalAttrs.version}"; - hash = "sha256-LNh9F2aKxVegZTAPuEAqo2f78ynGMgnpwnDXEP1u2+M="; + hash = "sha256-E0Ds2Wpo+JUSfd+hBY7QdJM1cUlWgNWW4zEiB0rdh6w="; + + # Remove after upstream updates to Yarn 4.15 + # https://github.com/mifi/lossless-cut/blob/master/package.json#L492 + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry.lockfileVersion + ]; + }) + } + ''; }; patches = [ # fixes a few things that try to guess whether it's a dev build ./undev.patch - ./yarn-4.14-support.patch ./disable-update-check.patch # LosslessCut will retrieve a URL from mifi.no (the author's domain) and directly embed the HTML in the app. # This was previously used to show a Ukraine flag, which I don't have strong opinions on. @@ -121,8 +137,8 @@ stdenv.mkDerivation (finalAttrs: { missingHashes = ./missing-hashes.json; offlineCache = yarn-berry.fetchYarnBerryDeps { - inherit (finalAttrs) src missingHashes patches; - hash = "sha256-o0u9dAoo0sTEV+kjQg8TjRNAIcx8fqfk79HsDwAXriA="; + inherit (finalAttrs) src missingHashes; + hash = "sha256-81pebHUkVLEAe01a5olTP9zzQkTCrGMWUvNTYBsW+Bk="; }; postConfigure = '' diff --git a/pkgs/by-name/lo/losslesscut/yarn-4.14-support.patch b/pkgs/by-name/lo/losslesscut/yarn-fix.patch similarity index 84% rename from pkgs/by-name/lo/losslesscut/yarn-4.14-support.patch rename to pkgs/by-name/lo/losslesscut/yarn-fix.patch index d673b914d875..82a6782e429c 100644 --- a/pkgs/by-name/lo/losslesscut/yarn-4.14-support.patch +++ b/pkgs/by-name/lo/losslesscut/yarn-fix.patch @@ -7,7 +7,7 @@ index 1e4550e7..6a2e770c 100644 __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10 "7zip-bin@npm:~5.2.0": diff --git a/pkgs/by-name/ma/mastodon/yarn-4.14-support.patch b/pkgs/by-name/ma/mastodon/yarn-4.14-support.patch deleted file mode 100644 index 017f2d295ca9..000000000000 --- a/pkgs/by-name/ma/mastodon/yarn-4.14-support.patch +++ /dev/null @@ -1,21 +0,0 @@ -diff --git a/.yarnrc.yml b/.yarnrc.yml ---- a/.yarnrc.yml -+++ b/.yarnrc.yml -@@ -1 +1,6 @@ - nodeLinker: node-modules -+ -+approvedGitRepositories: -+ - "**" -+ -+enableScripts: true -diff --git a/yarn.lock b/yarn.lock ---- a/yarn.lock -+++ b/yarn.lock -@@ -2,6 +2,6 @@ - # Manual changes might be lost - proceed with caution! - - __metadata: -- version: 8 -+ version: 9 - cacheKey: 10c0 - diff --git a/pkgs/by-name/ou/outline/package.nix b/pkgs/by-name/ou/outline/package.nix index add6d2fc50a2..c9b7fefaf38e 100644 --- a/pkgs/by-name/ou/outline/package.nix +++ b/pkgs/by-name/ou/outline/package.nix @@ -2,6 +2,7 @@ stdenv, lib, fetchFromGitHub, + substitute, makeWrapper, nodejs, nixosTests, @@ -16,14 +17,24 @@ stdenv.mkDerivation (finalAttrs: { owner = "outline"; repo = "outline"; rev = "v${finalAttrs.version}"; - hash = "sha256-6w4Pso7I0ojbsbACEZrYuJsW9J2W38jY9uiErMQNeXE="; - }; + hash = "sha256-msFMfjNkpXaJisbTpJMQowyD0KZ5zfvSgTutEeLp9Vk="; - patches = [ - # Remove after upstream updates to Yarn 4.14 - # https://github.com/outline/outline/blob/main/package.json#L398 - ./yarn-4.14-support.patch - ]; + # Remove after upstream updates to Yarn 4.15 + # https://github.com/outline/outline/blob/main/package.json#L393 + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry_4.lockfileVersion + ]; + }) + } + ''; + }; missingHashes = ./missing-hashes.json; @@ -34,8 +45,8 @@ stdenv.mkDerivation (finalAttrs: { ]; offlineCache = yarn-berry_4.fetchYarnBerryDeps { - inherit (finalAttrs) src missingHashes patches; - hash = "sha256-7nREE+sGd6ZUGfZ+YSIIGUaysMSEdap189koFQcV+hs="; + inherit (finalAttrs) src missingHashes; + hash = "sha256-bEsnu4NL/Dgv6yPXXvV/4uMvQ7Sc9eDfeAD2fhFCB98="; }; buildPhase = '' diff --git a/pkgs/by-name/ou/outline/yarn-4.14-support.patch b/pkgs/by-name/ou/outline/yarn-fix.patch similarity index 76% rename from pkgs/by-name/ou/outline/yarn-4.14-support.patch rename to pkgs/by-name/ou/outline/yarn-fix.patch index 6c50d24297b0..8cf711edfe98 100644 --- a/pkgs/by-name/ou/outline/yarn-4.14-support.patch +++ b/pkgs/by-name/ou/outline/yarn-fix.patch @@ -1,22 +1,19 @@ --- a/.yarnrc.yml +++ b/.yarnrc.yml -@@ -12,3 +12,8 @@ npmPreapprovedPackages: +@@ -12,3 +12,6 @@ npmPreapprovedPackages: npmAuditIgnoreAdvisories: - "1113517" # GHSA-mw96-cpmx-2vgc rollup <2.80.0 path traversal (workbox-build, build-time) - "1113686" # GHSA-5c6j-r48x-rmvq serialize-javascript RCE (@rollup/plugin-terser, build-time) + +approvedGitRepositories: + - "**" -+ -+enableScripts: true --- a/yarn.lock +++ b/yarn.lock -@@ -2,7 +2,7 @@ +@@ -2,6 +2,6 @@ # Manual changes might be lost - proceed with caution! __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10c0 - "@antfu/install-pkg@npm:^1.1.0": diff --git a/pkgs/by-name/pe/peacock/package.nix b/pkgs/by-name/pe/peacock/package.nix index 144c875e3b16..7710b07f003b 100644 --- a/pkgs/by-name/pe/peacock/package.nix +++ b/pkgs/by-name/pe/peacock/package.nix @@ -1,6 +1,7 @@ { lib, fetchFromGitHub, + substitute, stdenv, nodejs, yarn-berry_4, @@ -19,14 +20,24 @@ stdenv.mkDerivation (finalAttrs: { owner = "thepeacockproject"; repo = "Peacock"; tag = "v${finalAttrs.version}"; - hash = "sha256-uVK9ABA5JoDU9Cmtjo2ZqIRwMvhZdDgdmkIpily/wk8="; - }; + hash = "sha256-8Z2UXz/4ecQruy20RykgSXBm3JjMqZH6KVBVCXRzAI4="; - patches = [ - # Remove after upstream updates to Yarn 4.14 - # https://github.com/thepeacockproject/Peacock/blob/master/package.json#L109 - ./yarn-4.14-support.patch - ]; + # Remove after upstream updates to Yarn 4.15 + # https://github.com/thepeacockproject/Peacock/blob/master/package.json#L107 + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry.lockfileVersion + ]; + }) + } + ''; + }; nativeBuildInputs = [ nodejs @@ -81,8 +92,8 @@ stdenv.mkDerivation (finalAttrs: { missingHashes = ./missing-hashes.json; offlineCache = yarn-berry.fetchYarnBerryDeps { - inherit (finalAttrs) src missingHashes patches; - hash = "sha256-9u/w/zy4f51uPFfkzf0fDZlsj8GFXAfw7RGR9owo5n8="; + inherit (finalAttrs) src missingHashes; + hash = "sha256-O1F/OaVipYyJOIIeNcOEghxTjGYNg8Ba0KMQMnW09EQ="; }; meta = { diff --git a/pkgs/by-name/pe/peacock/yarn-4.14-support.patch b/pkgs/by-name/pe/peacock/yarn-fix.patch similarity index 81% rename from pkgs/by-name/pe/peacock/yarn-4.14-support.patch rename to pkgs/by-name/pe/peacock/yarn-fix.patch index eb94dd5a821e..2d02497c0102 100644 --- a/pkgs/by-name/pe/peacock/yarn-4.14-support.patch +++ b/pkgs/by-name/pe/peacock/yarn-fix.patch @@ -1,5 +1,4 @@ diff --git a/yarn.lock b/yarn.lock -index 286ec90499..ee9a3a9fd3 100644 --- a/yarn.lock +++ b/yarn.lock @@ -2,7 +2,7 @@ @@ -7,7 +6,7 @@ index 286ec90499..ee9a3a9fd3 100644 __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10 "@aashutoshrathi/word-wrap@npm:^1.2.3": diff --git a/pkgs/by-name/pg/pgadmin4/package.nix b/pkgs/by-name/pg/pgadmin4/package.nix index 5c15cf400ab3..9a6676d096d4 100644 --- a/pkgs/by-name/pg/pgadmin4/package.nix +++ b/pkgs/by-name/pg/pgadmin4/package.nix @@ -2,6 +2,7 @@ lib, python3, fetchFromGitHub, + substitute, zlib, nixosTests, postgresqlTestHook, @@ -9,24 +10,36 @@ yarn-berry_4, nodejs, stdenv, - pkgsBuildHost, server-mode ? true, }: let pname = "pgadmin"; version = "9.14"; - yarnHash = "sha256-mJa5L8N40JWogQ8/LllSdX/uJHMzKULCow9+e5gFe/A="; + yarnHash = "sha256-uixmtWC588JD6DfM9INeh6LV5L2S9lc+GFNW62FVm+4="; src = fetchFromGitHub { owner = "pgadmin-org"; repo = "pgadmin4"; rev = "REL-${lib.versions.major version}_${lib.versions.minor version}"; - hash = "sha256-NQe1ZN8jQEJE5qSpL5MjgLwWLGrGXCIHaCd8zLpsx3s="; - }; + hash = "sha256-ZUJEwTRKG23ztLKAp+hDHKeKxPc6VmC8gnJe4x85R44="; - # Remove after https://github.com/pgadmin-org/pgadmin4/commit/79e490c5fa6031af7baa83f04f751bdc790dc408 is released - yarnPatch = ./yarn-4.14-support.patch; + # Remove when updating since upstream has updated Yarn + # https://github.com/pgadmin-org/pgadmin4/commit/aad2dfd7251f769ce73dd1bc3e17c76831a019ed#diff-b861012a5dd72b8a9f3281b7cf09f5a779c98569d040b1bbc1db50f1b15e7cceR183 + postFetch = '' + cd $out/web + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry_4.lockfileVersion + ]; + }) + } + ''; + }; # keep the scope, as it is used throughout the derivation and tests # this also makes potential future overrides easier @@ -53,7 +66,6 @@ pythonPackages.buildPythonApplication rec { inherit missingHashes; src = src + "/web"; hash = yarnHash; - patches = [ yarnPatch ]; }; # from Dockerfile @@ -115,8 +127,6 @@ pythonPackages.buildPythonApplication rec { echo Building the web frontend... cd web ( - PATH=$PATH:${lib.makeBinPath [ pkgsBuildHost.git ]} - git apply ${yarnPatch} export LD=$CC # https://github.com/imagemin/optipng-bin/issues/108 yarnBerryConfigHook ) diff --git a/pkgs/by-name/pg/pgadmin4/yarn-4.14-support.patch b/pkgs/by-name/pg/pgadmin4/yarn-fix.patch similarity index 90% rename from pkgs/by-name/pg/pgadmin4/yarn-4.14-support.patch rename to pkgs/by-name/pg/pgadmin4/yarn-fix.patch index 62b859642205..e689ae3dd496 100644 --- a/pkgs/by-name/pg/pgadmin4/yarn-4.14-support.patch +++ b/pkgs/by-name/pg/pgadmin4/yarn-fix.patch @@ -20,6 +20,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10c0 diff --git a/pkgs/by-name/pr/proton-authenticator/package.nix b/pkgs/by-name/pr/proton-authenticator/package.nix index 3762981974df..88b69429af53 100644 --- a/pkgs/by-name/pr/proton-authenticator/package.nix +++ b/pkgs/by-name/pr/proton-authenticator/package.nix @@ -74,7 +74,7 @@ rustPlatform.buildRustPackage (finalAttrs: { offlineCache = yarn-berry.fetchYarnBerryDeps { inherit (finalAttrs) src missingHashes yarnLock; - hash = "sha256-FiDuAwEj/AIH/lJRLyuNPvthcoynsFGcUYZyx7DMnFA="; + hash = "sha256-YNW6Hqk3WU0IRCbDQpNOTiIHT9T5zBMhNm5GxX1WqrM="; }; postUnpack = '' diff --git a/pkgs/by-name/pr/proton-authenticator/yarn.lock b/pkgs/by-name/pr/proton-authenticator/yarn.lock index e6f025b3dd50..5ce742161099 100644 --- a/pkgs/by-name/pr/proton-authenticator/yarn.lock +++ b/pkgs/by-name/pr/proton-authenticator/yarn.lock @@ -2,7 +2,7 @@ # Manual changes might be lost - proceed with caution! __metadata: - version: 9 + version: 10 cacheKey: 10 "@adobe/css-tools@npm:^4.4.0": diff --git a/pkgs/by-name/r2/r2modman/package.nix b/pkgs/by-name/r2/r2modman/package.nix index e059d255f8a6..8a131396e315 100644 --- a/pkgs/by-name/r2/r2modman/package.nix +++ b/pkgs/by-name/r2/r2modman/package.nix @@ -9,6 +9,7 @@ makeWrapper, nodejs, yarn-berry, + substitute, }: stdenv.mkDerivation (finalAttrs: { @@ -19,23 +20,35 @@ stdenv.mkDerivation (finalAttrs: { owner = "ebkr"; repo = "r2modmanPlus"; tag = "v${finalAttrs.version}"; - hash = "sha256-QGs3kF2GkHlISmRb0cIYOKts1b1RvBj5qkc2cUPawwE="; + hash = "sha256-6vSc3Gx0VZJoGSXm70T6rsOLhlv/7CnjK4HWkPOZv2s="; + + # Remove when updating since upstream migrated to pnpm + # https://github.com/ebkr/r2modmanPlus/commit/db41dfdf4e4b9059ce0d574a7fab0d2d344e633a + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry.lockfileVersion + ]; + }) + } + ''; }; missingHashes = ./missing-hashes.json; offlineCache = yarn-berry.fetchYarnBerryDeps { - inherit (finalAttrs) src patches missingHashes; - hash = "sha256-6CwayFhy0ZwdL1ZOZVtCJLlchCv5raX7WF1V4TvVpq4="; + inherit (finalAttrs) src missingHashes; + hash = "sha256-CAtDbWbl9u8tPdPQKxB2qcN7OhDomwO8EqDdRZppgQU="; }; patches = [ # Make it possible to launch Steam games from r2modman. ./steam-launch-fix.patch - # Remove after upstream updates to Yarn 4.14 - # https://github.com/ebkr/r2modmanPlus/blob/develop/package.json#L118 - ./yarn-4.14-support.patch - # Fix copying of wrapper files to game directory ./wrapper-fix.patch ]; diff --git a/pkgs/by-name/r2/r2modman/yarn-4.14-support.patch b/pkgs/by-name/r2/r2modman/yarn-fix.patch similarity index 88% rename from pkgs/by-name/r2/r2modman/yarn-4.14-support.patch rename to pkgs/by-name/r2/r2modman/yarn-fix.patch index 017f2d295ca9..868db25c8d32 100644 --- a/pkgs/by-name/r2/r2modman/yarn-4.14-support.patch +++ b/pkgs/by-name/r2/r2modman/yarn-fix.patch @@ -16,6 +16,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10c0 diff --git a/pkgs/by-name/ro/rocketchat-desktop/package.nix b/pkgs/by-name/ro/rocketchat-desktop/package.nix index 254ce5c2830f..c1ebd06b619c 100644 --- a/pkgs/by-name/ro/rocketchat-desktop/package.nix +++ b/pkgs/by-name/ro/rocketchat-desktop/package.nix @@ -2,6 +2,7 @@ lib, stdenv, fetchFromGitHub, + substitute, yarn-berry_4, nodejs, pkg-config, @@ -27,22 +28,32 @@ stdenv.mkDerivation (finalAttrs: { owner = "RocketChat"; repo = "Rocket.Chat.Electron"; tag = finalAttrs.version; - hash = "sha256-ToAez48+TBcPJUjrh8xYC84HLwbU+rCxGoor5o4gGgo="; - }; + hash = "sha256-Z9yTtlpud3nCMVnyCTd0eYM3G/9UjrPu2sfTVirDR0k="; - patches = [ - # Remove after upstream updates to Yarn 4.14 - # https://github.com/RocketChat/Rocket.Chat.Electron/blob/master/package.json#L182 - ./yarn-4.14-support.patch - ]; + # Remove after upstream updates to Yarn 4.15 + # https://github.com/RocketChat/Rocket.Chat.Electron/blob/master/package.json#L187 + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry.lockfileVersion + ]; + }) + } + ''; + }; # This might need to be updated between releases. # See https://nixos.org/manual/nixpkgs/stable/#javascript-yarnBerry-missing-hashes missingHashes = ./missing-hashes.json; offlineCache = yarn-berry.fetchYarnBerryDeps { - inherit (finalAttrs) src missingHashes patches; - hash = "sha256-7zPiu8kgZbp64ugf229hrjpwZujQHHDLwCxlGRVgH4E="; + inherit (finalAttrs) src missingHashes; + hash = "sha256-VMCLYLuNAZQzfglLS6ncFCLOcmGsuXPR2J+q+Gn/CP4="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/ro/rocketchat-desktop/yarn-4.14-support.patch b/pkgs/by-name/ro/rocketchat-desktop/yarn-fix.patch similarity index 90% rename from pkgs/by-name/ro/rocketchat-desktop/yarn-4.14-support.patch rename to pkgs/by-name/ro/rocketchat-desktop/yarn-fix.patch index 2977561bd557..ac0fc8f2f4dd 100644 --- a/pkgs/by-name/ro/rocketchat-desktop/yarn-4.14-support.patch +++ b/pkgs/by-name/ro/rocketchat-desktop/yarn-fix.patch @@ -18,6 +18,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10 diff --git a/pkgs/by-name/sy/synapse-admin/package.nix b/pkgs/by-name/sy/synapse-admin/package.nix index b65f92a92fae..bc35a9673281 100644 --- a/pkgs/by-name/sy/synapse-admin/package.nix +++ b/pkgs/by-name/sy/synapse-admin/package.nix @@ -2,6 +2,7 @@ lib, stdenv, fetchFromGitHub, + substitute, nodejs, yarn-berry, cacert, @@ -24,19 +25,29 @@ stdenv.mkDerivation (finalAttrs: { owner = "Awesome-Technologies"; repo = "synapse-admin"; tag = finalAttrs.version; - hash = "sha256-rK1Tc1K3wx6/1J8TEw5Lb9g09gbt/1HoZdDrEFzxTQQ="; - }; + hash = "sha256-D7MlFaI49KSNQ7DPj0iGKJqaQ4s5Y6EksB2U3Z5sJXY="; - patches = [ - # Remove after upstream updates to Yarn 4.14 + # Remove after upstream updates to Yarn 4.15 # https://github.com/Awesome-Technologies/synapse-admin/blob/master/package.json#L13 - ./yarn-4.14-support.patch - ]; + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry.lockfileVersion + ]; + }) + } + ''; + }; # we cannot use fetchYarnDeps because that doesn't support yarn 2/berry lockfiles yarnOfflineCache = stdenv.mkDerivation { pname = "yarn-deps"; - inherit (finalAttrs) version src patches; + inherit (finalAttrs) version src; nativeBuildInputs = [ yarn-berry ]; @@ -84,7 +95,7 @@ stdenv.mkDerivation (finalAttrs: { runHook postBuild ''; - outputHash = "sha256-IiViodAB1KAYsRRr8+zw3vrCbUYp7Mdtazi0Y6SEFNU="; + outputHash = "sha256-n5SkXCWOsqdyZkng5EU0HJDKJ0xorfi6SfNvwnuhFTg="; outputHashMode = "recursive"; }; diff --git a/pkgs/by-name/sy/synapse-admin/yarn-4.14-support.patch b/pkgs/by-name/sy/synapse-admin/yarn-4.14-support.patch deleted file mode 100644 index 7acf8fd001bc..000000000000 --- a/pkgs/by-name/sy/synapse-admin/yarn-4.14-support.patch +++ /dev/null @@ -1,20 +0,0 @@ -diff --git a/.yarnrc.yml b/.yarnrc.yml ---- a/.yarnrc.yml -+++ b/.yarnrc.yml -@@ -1 +1,4 @@ --yarnPath: .yarn/releases/yarn-4.4.1.cjs -+approvedGitRepositories: -+ - "**" -+ -+enableScripts: true -diff --git a/yarn.lock b/yarn.lock ---- a/yarn.lock -+++ b/yarn.lock -@@ -2,6 +2,6 @@ - # Manual changes might be lost - proceed with caution! - - __metadata: -- version: 8 -+ version: 9 - cacheKey: 10c0 - diff --git a/pkgs/by-name/sy/synapse-admin/yarn-fix.patch b/pkgs/by-name/sy/synapse-admin/yarn-fix.patch new file mode 100644 index 000000000000..b18faa94fbb0 --- /dev/null +++ b/pkgs/by-name/sy/synapse-admin/yarn-fix.patch @@ -0,0 +1,41 @@ +diff --git a/.yarnrc.yml b/.yarnrc.yml +--- a/.yarnrc.yml ++++ b/.yarnrc.yml +@@ -1 +1,4 @@ +-yarnPath: .yarn/releases/yarn-4.4.1.cjs ++approvedGitRepositories: ++ - "**" ++ ++enableScripts: true +diff --git a/yarn.lock b/yarn.lock +--- a/yarn.lock ++++ b/yarn.lock +@@ -2,6 +2,6 @@ + # Manual changes might be lost - proceed with caution! + + __metadata: +- version: 8 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER + cacheKey: 10c0 + +diff --git a/yarn.lock b/yarn.lock +index 7ecce1c508a4..6df14e5f4603 100644 +--- a/yarn.lock ++++ b/yarn.lock +@@ -7366,14 +7366,14 @@ __metadata: + + "resolve@patch:resolve@npm%3A^1.19.0#optional!builtin, resolve@patch:resolve@npm%3A^1.20.0#optional!builtin, resolve@patch:resolve@npm%3A^1.22.4#optional!builtin": + version: 1.22.8 +- resolution: "resolve@patch:resolve@npm%3A1.22.8#optional!builtin::version=1.22.8&hash=c3c19d" ++ resolution: "resolve@patch:resolve@npm%3A1.22.8#optional!builtin::version=1.22.8&hash=9bd1a5" + dependencies: + is-core-module: "npm:^2.13.0" + path-parse: "npm:^1.0.7" + supports-preserve-symlinks-flag: "npm:^1.0.0" + bin: + resolve: bin/resolve +- checksum: 10c0/0446f024439cd2e50c6c8fa8ba77eaa8370b4180f401a96abf3d1ebc770ac51c1955e12764cde449fde3fff480a61f84388e3505ecdbab778f4bef5f8212c729 ++ checksum: 10c0/4bc6de64a713422234e0e773bff296767d77d6e545b98042ff90a796d356f2b131853f4fa1d54e2c415aa6efa6dc2eed5b3f501f63164f834619fda900e33b8e + languageName: node + linkType: hard + diff --git a/pkgs/by-name/ti/tilt/assets.nix b/pkgs/by-name/ti/tilt/assets.nix index 12b145261390..d8fb770d939e 100644 --- a/pkgs/by-name/ti/tilt/assets.nix +++ b/pkgs/by-name/ti/tilt/assets.nix @@ -8,17 +8,10 @@ src, }: -let - patches = [ - # Remove after upstream updates to Yarn 4.14 - # https://github.com/tilt-dev/tilt/blob/master/web/package.json#L94 - ./yarn-4.14-support.patch - ]; -in stdenvNoCC.mkDerivation { pname = "tilt-assets"; src = "${src}/web"; - inherit version patches; + inherit version; nativeBuildInputs = [ nodejs @@ -29,8 +22,6 @@ stdenvNoCC.mkDerivation { name = "tilt-assets-deps"; src = "${src}/web"; - inherit patches; - nativeBuildInputs = [ yarn-berry ]; supportedArchitectures = builtins.toJSON { @@ -77,7 +68,7 @@ stdenvNoCC.mkDerivation { dontInstall = true; outputHashAlgo = "sha256"; - outputHash = "sha256-MOEf6LZuHoOMX6OWqTn9j7AKIyC2lzt4SUXKWfE8B5A="; + outputHash = "sha256-fJwBXemRFvT5pA0McrXMGeuaCLjyHXwTMf5/Rh+jPvs="; outputHashMode = "recursive"; }; diff --git a/pkgs/by-name/ti/tilt/package.nix b/pkgs/by-name/ti/tilt/package.nix index 1a126ed6927c..6f9692e8d387 100644 --- a/pkgs/by-name/ti/tilt/package.nix +++ b/pkgs/by-name/ti/tilt/package.nix @@ -1,6 +1,8 @@ { fetchFromGitHub, + substitute, callPackage, + yarn-berry, }: let args = rec { @@ -15,10 +17,26 @@ let owner = "tilt-dev"; repo = "tilt"; tag = "v${version}"; - hash = "sha256-tMP3EYgwulyqmuL3yE3CtCBIs2QhoWzW8PnYF+//bgs="; + hash = "sha256-ECECNXxO7fkX3eyNBWMlr9yqgiJKas0XpDA48lQNnr8="; + + # Remove after upstream updates to Yarn 4.15 + # https://github.com/tilt-dev/tilt/blob/master/web/package.json#L98 + postFetch = '' + cd $out/web + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry.lockfileVersion + ]; + }) + } + ''; }; }; - tilt-assets = callPackage ./assets.nix args; + tilt-assets = callPackage ./assets.nix (args // { inherit yarn-berry; }); in callPackage ./binary.nix (args // { inherit tilt-assets; }) diff --git a/pkgs/by-name/ti/tilt/yarn-4.14-support.patch b/pkgs/by-name/ti/tilt/yarn-4.14-support.patch deleted file mode 100644 index 44b7fd0a4008..000000000000 --- a/pkgs/by-name/ti/tilt/yarn-4.14-support.patch +++ /dev/null @@ -1,23 +0,0 @@ -diff --git a/.yarnrc.yml b/.yarnrc.yml ---- a/.yarnrc.yml -+++ b/.yarnrc.yml -@@ -6,4 +6,7 @@ enableGlobalCache: false - - nodeLinker: node-modules - --yarnPath: .yarn/releases/yarn-4.9.3.cjs -+approvedGitRepositories: -+ - "**" -+ -+enableScripts: true -diff --git a/yarn.lock b/yarn.lock ---- a/yarn.lock -+++ b/yarn.lock -@@ -2,6 +2,6 @@ - # Manual changes might be lost - proceed with caution! - - __metadata: -- version: 8 -+ version: 9 - cacheKey: 10 - diff --git a/pkgs/by-name/ti/tilt/yarn-fix.patch b/pkgs/by-name/ti/tilt/yarn-fix.patch new file mode 100644 index 000000000000..925ce855de11 --- /dev/null +++ b/pkgs/by-name/ti/tilt/yarn-fix.patch @@ -0,0 +1,58 @@ +diff --git a/.yarnrc.yml b/.yarnrc.yml +--- a/.yarnrc.yml ++++ b/.yarnrc.yml +@@ -6,4 +6,7 @@ enableGlobalCache: false + + nodeLinker: node-modules + +-yarnPath: .yarn/releases/yarn-4.9.3.cjs ++approvedGitRepositories: ++ - "**" ++ ++enableScripts: true +diff --git a/yarn.lock b/yarn.lock +--- a/yarn.lock ++++ b/yarn.lock +@@ -2,6 +2,6 @@ + # Manual changes might be lost - proceed with caution! + + __metadata: +- version: 8 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER + cacheKey: 10 + +diff --git a/yarn.lock b/yarn.lock +--- a/yarn.lock ++++ b/yarn.lock +@@ -18405,27 +18405,27 @@ __metadata: + + "resolve@patch:resolve@npm%3A^1.1.7#optional!builtin, resolve@patch:resolve@npm%3A^1.10.0#optional!builtin, resolve@patch:resolve@npm%3A^1.14.2#optional!builtin, resolve@patch:resolve@npm%3A^1.19.0#optional!builtin, resolve@patch:resolve@npm%3A^1.20.0#optional!builtin, resolve@patch:resolve@npm%3A^1.22.2#optional!builtin, resolve@patch:resolve@npm%3A^1.22.4#optional!builtin, resolve@patch:resolve@npm%3A^1.3.2#optional!builtin": + version: 1.22.8 +- resolution: "resolve@patch:resolve@npm%3A1.22.8#optional!builtin::version=1.22.8&hash=c3c19d" ++ resolution: "resolve@patch:resolve@npm%3A1.22.8#optional!builtin::version=1.22.8&hash=9bd1a5" + dependencies: + is-core-module: "npm:^2.13.0" + path-parse: "npm:^1.0.7" + supports-preserve-symlinks-flag: "npm:^1.0.0" + bin: + resolve: bin/resolve +- checksum: 10/f345cd37f56a2c0275e3fe062517c650bb673815d885e7507566df589375d165bbbf4bdb6aa95600a9bc55f4744b81f452b5a63f95b9f10a72787dba3c90890a ++ checksum: 10/b14c82cbce48701a1e963c60f196b91a289186e8b596334e09c881df8069cefcfb0ac9ce85ea768742b361a58005494bf2428a95dc5056d2ba441aa993731b1f + languageName: node + linkType: hard + + "resolve@patch:resolve@npm%3A^2.0.0-next.4#optional!builtin": + version: 2.0.0-next.5 +- resolution: "resolve@patch:resolve@npm%3A2.0.0-next.5#optional!builtin::version=2.0.0-next.5&hash=c3c19d" ++ resolution: "resolve@patch:resolve@npm%3A2.0.0-next.5#optional!builtin::version=2.0.0-next.5&hash=9bd1a5" + dependencies: + is-core-module: "npm:^2.13.0" + path-parse: "npm:^1.0.7" + supports-preserve-symlinks-flag: "npm:^1.0.0" + bin: + resolve: bin/resolve +- checksum: 10/05fa778de9d0347c8b889eb7a18f1f06bf0f801b0eb4610b4871a4b2f22e220900cf0ad525e94f990bb8d8921c07754ab2122c0c225ab4cdcea98f36e64fa4c2 ++ checksum: 10/76c221deb1d986c0a80cd576373b0ee09f42871e0085a1f76beda84f73ce04e0d21bab28dffd326eb006a7af83bbc582404566b384aa3b0baa217f56cf7e8618 + languageName: node + linkType: hard + diff --git a/pkgs/by-name/up/uppy-companion/package.nix b/pkgs/by-name/up/uppy-companion/package.nix index 30dea050c6e0..8cda711321d4 100644 --- a/pkgs/by-name/up/uppy-companion/package.nix +++ b/pkgs/by-name/up/uppy-companion/package.nix @@ -3,6 +3,7 @@ stdenv, nodejs, fetchFromGitHub, + substitute, yarn-berry_4, }: @@ -14,14 +15,24 @@ stdenv.mkDerivation (finalAttrs: { owner = "transloadit"; repo = "uppy"; tag = "@uppy/companion@${finalAttrs.version}"; - hash = "sha256-FF5I4D9obRVJqyjucemnxZiPcNHdQdo3S0z/h96Fe6c="; - }; + hash = "sha256-4Xbw4d0SaLPk4mmvG9QWkUuVX/SM1SmGtuaK85rLihU="; - patches = [ - # Remove after upstream updates to Yarn 4.14 - # https://github.com/transloadit/uppy/blob/main/package.json#L39 - ./yarn-4.14-support.patch - ]; + # Remove after upstream updates to Yarn 4.15 + # https://github.com/transloadit/uppy/blob/main/package.json#L38 + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry_4.lockfileVersion + ]; + }) + } + ''; + }; nativeBuildInputs = [ nodejs @@ -36,8 +47,8 @@ stdenv.mkDerivation (finalAttrs: { missingHashes = ./missing-hashes.json; offlineCache = yarn-berry_4.fetchYarnBerryDeps { - inherit (finalAttrs) src missingHashes patches; - hash = "sha256-vmya3c+ec93T8kNoooUu4risqScY0b4cwML7d2kYz88="; + inherit (finalAttrs) src missingHashes; + hash = "sha256-MQTaNbeJuvWDtRajJQYRtuxiMrLGKtlasyB6sKeOIgs="; }; buildPhase = '' diff --git a/pkgs/by-name/up/uppy-companion/yarn-4.14-support.patch b/pkgs/by-name/up/uppy-companion/yarn-fix.patch similarity index 89% rename from pkgs/by-name/up/uppy-companion/yarn-4.14-support.patch rename to pkgs/by-name/up/uppy-companion/yarn-fix.patch index 1cb3aa5b44da..10fddf10793a 100644 --- a/pkgs/by-name/up/uppy-companion/yarn-4.14-support.patch +++ b/pkgs/by-name/up/uppy-companion/yarn-fix.patch @@ -17,6 +17,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10 diff --git a/pkgs/by-name/vu/vultisig-cli/package.nix b/pkgs/by-name/vu/vultisig-cli/package.nix index d32fc0695366..8de1998919d2 100644 --- a/pkgs/by-name/vu/vultisig-cli/package.nix +++ b/pkgs/by-name/vu/vultisig-cli/package.nix @@ -4,6 +4,7 @@ fetchFromGitHub, nodejs, yarn-berry, + substitute, makeWrapper, }: @@ -15,20 +16,30 @@ stdenv.mkDerivation (finalAttrs: { owner = "vultisig"; repo = "vultisig-sdk"; tag = "v${finalAttrs.version}"; - hash = "sha256-4I+N9uKZBzw0AePjS8CiALye/fuykBtpAoYxp+5iTW8="; - }; + hash = "sha256-IFEses2Gs0HdgXVMpNYA6y7PtnMMDVLSoAuyi3a+ZgE="; - patches = [ - # Remove after upstream updates to Yarn 4.14 - # https://github.com/vultisig/vultisig-sdk/blob/main/package.json#L4 - ./yarn-4.14-support.patch - ]; + # Remove when updating since upstream has updated to Yarn 4.16 + # https://github.com/vultisig/vultisig-sdk/commit/45611297a55da72d3c56b1a2ffe6522da1b64d7b + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry.lockfileVersion + ]; + }) + } + ''; + }; missingHashes = ./missing-hashes.json; offlineCache = yarn-berry.fetchYarnBerryDeps { - inherit (finalAttrs) src missingHashes patches; - hash = "sha256-EW0Vc3502xoL4iDr2hPDXQ39McvvsiBWpMKgZRtF44M="; + inherit (finalAttrs) src missingHashes; + hash = "sha256-e5sNNDJVYY4PgbpYtrzxzOL+rtYq1ZwOYglJvZ6OKzo="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/vu/vultisig-cli/yarn-4.14-support.patch b/pkgs/by-name/vu/vultisig-cli/yarn-fix.patch similarity index 89% rename from pkgs/by-name/vu/vultisig-cli/yarn-4.14-support.patch rename to pkgs/by-name/vu/vultisig-cli/yarn-fix.patch index acf6feee69fe..99385ae64a32 100644 --- a/pkgs/by-name/vu/vultisig-cli/yarn-4.14-support.patch +++ b/pkgs/by-name/vu/vultisig-cli/yarn-fix.patch @@ -17,6 +17,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10c0 diff --git a/pkgs/by-name/ya/yarn-berry/fetcher/berry-4-offline.patch b/pkgs/by-name/ya/yarn-berry/fetcher/berry-4-offline.patch index 7ebf48b64233..4ba700157bd7 100644 --- a/pkgs/by-name/ya/yarn-berry/fetcher/berry-4-offline.patch +++ b/pkgs/by-name/ya/yarn-berry/fetcher/berry-4-offline.patch @@ -6,7 +6,7 @@ index 90ba55349..ef5368c1b 100644 for (const rule of LOCKFILE_MIGRATION_RULES) { if (rule.selector(lockfileLastVersion) && typeof configuration.sources.get(rule.name) === `undefined`) { -+ throw new Error(`Tried to use yarn-berry_4.yarnConfigHook (nixpkgs) which expects lockfile version 8, but found lockfile version ${lockfileLastVersion}`); ++ throw new Error(`Tried to use yarn-berry_4.yarnConfigHook (nixpkgs) which expects lockfile version @YARN_LOCKFILE_VERSION_PLACEHOLDER@, but found lockfile version ${lockfileLastVersion}`); configuration.use(``, {[rule.name]: rule.value}, project.cwd, {overwrite: true}); newSettings[rule.name] = rule.value; } diff --git a/pkgs/by-name/ya/yarn-berry/fetcher/default.nix b/pkgs/by-name/ya/yarn-berry/fetcher/default.nix index 5392c6450ccd..2aec5c4f356e 100644 --- a/pkgs/by-name/ya/yarn-berry/fetcher/default.nix +++ b/pkgs/by-name/ya/yarn-berry/fetcher/default.nix @@ -40,6 +40,7 @@ let berryOfflinePatches = [ (replaceVars ./berry-4-offline.patch { yarnv1 = lib.getExe yarn; + YARN_LOCKFILE_VERSION_PLACEHOLDER = yarn-berry.lockfileVersion; }) ]; diff --git a/pkgs/by-name/ya/yarn-berry/package.nix b/pkgs/by-name/ya/yarn-berry/package.nix index f0ab67d69512..b477c14608de 100644 --- a/pkgs/by-name/ya/yarn-berry/package.nix +++ b/pkgs/by-name/ya/yarn-berry/package.nix @@ -6,17 +6,17 @@ stdenv, testers, yarn, - git, + gitMinimal, callPackage, berryVersion ? 4, }: let - version_4 = "4.14.1"; + version_4 = "4.18.0"; version_3 = "3.8.7"; - hash_4 = "sha256-0UnU5jRSUFMw+WowvXqYqaaN1ZbZAdLLJ6LPyuK6iCc="; + hash_4 = "sha256-pO89wh17cW9/RGKjo70yiefr+9nlJAQs4ZEdUnzdgQM="; hash_3 = "sha256-vRrk+Fs/7dZha3h7yI5NpMfd1xezesnigpFgTRCACZo="; - lockfileVersion_4 = "9"; + lockfileVersion_4 = "10"; lockfileVersion_3 = "6"; in @@ -39,7 +39,7 @@ stdenv.mkDerivation (finalAttrs: { nativeBuildInputs = [ nodejs yarn - git + gitMinimal ]; strictDeps = true; @@ -81,8 +81,6 @@ stdenv.mkDerivation (finalAttrs: { ''; passthru = { - lockfileVersion = finalAttrs.lockfileVersion; - updateScript = ./update.sh; tests = diff --git a/pkgs/by-name/yt/ytmdesktop/package.nix b/pkgs/by-name/yt/ytmdesktop/package.nix index 87ed83644327..f5da9af9b9a7 100644 --- a/pkgs/by-name/yt/ytmdesktop/package.nix +++ b/pkgs/by-name/yt/ytmdesktop/package.nix @@ -9,6 +9,7 @@ makeWrapper, nodejs, yarn-berry_4, + substitute, zip, electron, @@ -34,9 +35,22 @@ stdenv.mkDerivation (finalAttrs: { cd $out git rev-parse HEAD > .COMMIT find -name .git -print0 | xargs -0 rm -rf + + # Remove after upstream updates to Yarn 4.14 + # https://github.com/ytmdesktop/ytmdesktop/blob/v2.0.11/package.json#L77 + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry.lockfileVersion + ]; + }) + } ''; - hash = "sha256-3gUEdkTFaO6WT13HyVssVX0qSmluOPm4AAy1dovHw6g="; + hash = "sha256-Frw4Bn9/koeRl6Wl6ykiIdb3+wIMhVRfgHhMZhzgqVc="; }; patches = [ @@ -44,10 +58,6 @@ stdenv.mkDerivation (finalAttrs: { # use the .COMMIT file generated in the fetcher FOD ./git-rev-parse.patch - # Remove after upstream updates to Yarn 4.14 - # https://github.com/ytmdesktop/ytmdesktop/blob/v2.0.11/package.json#L77 - ./yarn-4.14-support.patch - # zip extraction fails on newer nodejs versions without this fix # generated by running `yarn set resolution yauzl@npm:^2.10.0 npm:^3.3.1` ./bump-yauzl.patch @@ -64,8 +74,8 @@ stdenv.mkDerivation (finalAttrs: { missingHashes = ./missing-hashes.json; yarnOfflineCache = yarn-berry.fetchYarnBerryDeps { - inherit (finalAttrs) src missingHashes patches; - hash = "sha256-VpNK+44/FwHxZ+Hyx0QShpZ9fdP06VhhpoXxMFeLUzE="; + inherit (finalAttrs) src patches missingHashes; + hash = "sha256-YBZRfr6RU4f+9KXgKJcTF0P08er7eyiv8jVULVIYWXI="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/yt/ytmdesktop/yarn-4.14-support.patch b/pkgs/by-name/yt/ytmdesktop/yarn-fix.patch similarity index 89% rename from pkgs/by-name/yt/ytmdesktop/yarn-4.14-support.patch rename to pkgs/by-name/yt/ytmdesktop/yarn-fix.patch index 577c6d19d696..b7de21d69201 100644 --- a/pkgs/by-name/yt/ytmdesktop/yarn-4.14-support.patch +++ b/pkgs/by-name/yt/ytmdesktop/yarn-fix.patch @@ -17,6 +17,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10c0 diff --git a/pkgs/development/python-modules/locust/default.nix b/pkgs/development/python-modules/locust/default.nix index 1d8b5a5cf5a1..a55b41811bd2 100644 --- a/pkgs/development/python-modules/locust/default.nix +++ b/pkgs/development/python-modules/locust/default.nix @@ -4,6 +4,7 @@ python, callPackage, fetchFromGitHub, + substitute, hatchling, hatch-vcs, pytestCheckHook, @@ -24,6 +25,7 @@ retry, tomli, werkzeug, + yarn-berry, }: buildPythonPackage rec { @@ -35,7 +37,23 @@ buildPythonPackage rec { owner = "locustio"; repo = "locust"; tag = version; - hash = "sha256-Diz5fGcX8hXQSuNT20LUcjKJZEYNvN+6myrGi5F4Hss="; + hash = "sha256-IFKphE/RuGXsCmddXNppnHzayTSETaFLrOm26+6tyBI="; + + # Remove after upstream updates to Yarn 4.15 + # https://github.com/locustio/locust/blob/master/locust/webui/package.json#L89 + postFetch = '' + cd $out/locust/webui + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry.lockfileVersion + ]; + }) + } + ''; }; postPatch = '' @@ -47,7 +65,7 @@ buildPythonPackage rec { ''; webui = callPackage ./webui.nix { - inherit version; + inherit version yarn-berry; src = "${src}/locust/webui"; }; diff --git a/pkgs/development/python-modules/locust/webui.nix b/pkgs/development/python-modules/locust/webui.nix index 239e756fc745..cdb28354e674 100644 --- a/pkgs/development/python-modules/locust/webui.nix +++ b/pkgs/development/python-modules/locust/webui.nix @@ -1,28 +1,19 @@ { stdenv, - yarn-berry_4, + yarn-berry, nodejs, version, src, lib, }: -let - yarn-berry = yarn-berry_4; -in stdenv.mkDerivation (finalAttrs: { pname = "locust-ui"; inherit version src; - patches = [ - # Remove after upstream updates to Yarn 4.14 - # https://github.com/locustio/locust/blob/master/locust/webui/package.json#L89 - ./yarn-4.14-support.patch - ]; - missingHashes = ./missing-hashes.json; yarnOfflineCache = yarn-berry.fetchYarnBerryDeps { - inherit (finalAttrs) src missingHashes patches; - hash = "sha256-1pAoz/fkxrTCJZsSuAnm1Pfn5qjEbup8utEUoDvYJSE="; + inherit (finalAttrs) src missingHashes; + hash = "sha256-fjvgnXKenRxML1JkpxYIOnVuNZ7BpU9L/XgblcQV0vA="; }; nativeBuildInputs = [ diff --git a/pkgs/development/python-modules/locust/yarn-4.14-support.patch b/pkgs/development/python-modules/locust/yarn-fix.patch similarity index 89% rename from pkgs/development/python-modules/locust/yarn-4.14-support.patch rename to pkgs/development/python-modules/locust/yarn-fix.patch index c9aaabe0983b..69c087950139 100644 --- a/pkgs/development/python-modules/locust/yarn-4.14-support.patch +++ b/pkgs/development/python-modules/locust/yarn-fix.patch @@ -17,6 +17,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10c0 diff --git a/pkgs/development/tools/electron/common.nix b/pkgs/development/tools/electron/common.nix index 15b6c1d67e6f..b4a6424b5e38 100644 --- a/pkgs/development/tools/electron/common.nix +++ b/pkgs/development/tools/electron/common.nix @@ -12,6 +12,7 @@ yarn-berry_4, unzip, writers, + substitute, libnotify, libpulseaudio, @@ -26,9 +27,16 @@ let gclientDeps = gclient2nix.importGclientDeps info.deps; yarn-berry = yarn-berry_4; - # Only apply to old versions after upstream updates to Yarn 4.14 - # https://github.com/electron/electron/blob/main/package.json#L148 - yarnPatch = ./yarn-4.14-support.patch; + # Only apply to old versions after upstream updates to Yarn 4.15 + # https://github.com/electron/electron/blob/main/package.json#L152 + yarnPatch = substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry_4.lockfileVersion + ]; + }; in ((chromium.override { upstream-info = info.chromium; }).mkDerivation (base: { diff --git a/pkgs/development/tools/electron/info.json b/pkgs/development/tools/electron/info.json index 9a8eb309964b..3f2aa9e12082 100644 --- a/pkgs/development/tools/electron/info.json +++ b/pkgs/development/tools/electron/info.json @@ -1359,7 +1359,7 @@ } }, "electron_yarn_data": { - "hash": "sha256-KNbWANdqpF3rypdyGKgj9ykGXQ/+VtkE5L/XR1lqbps=", + "hash": "sha256-tliyfTfe+PwJ9WRxzbfKlSk9dja6U9Luoir+e0Vf0qc=", "missing_hashes": { "@oxfmt/binding-android-arm-eabi@npm:0.42.0": "42c08d87ce491086843070241f8777fa2cb968f4a08f67b3f6c33a8f67e0b3eac50eae146daede743e90e3bc32326951c5188814eea02e9c3e4a9764a4b492ba", "@oxfmt/binding-android-arm64@npm:0.42.0": "73e6609498d05c655c6a435af9f3e4f341137c260c7ae27fbb0377573574ca5200bd9f187aa90d442879733bbd0c4e91ae023c3b4579c9a57413a0b2922c023a", @@ -2773,7 +2773,7 @@ } }, "electron_yarn_data": { - "hash": "sha256-0DiQw6UGeZ7BLNvUJihE77Io72AUfgcLMMmV+GxhfVw=", + "hash": "sha256-NRMcHEijch3Z5dfBEF4vC5wYp86StZr+agu/YGfyFEo=", "missing_hashes": { "@oxfmt/binding-android-arm-eabi@npm:0.42.0": "42c08d87ce491086843070241f8777fa2cb968f4a08f67b3f6c33a8f67e0b3eac50eae146daede743e90e3bc32326951c5188814eea02e9c3e4a9764a4b492ba", "@oxfmt/binding-android-arm64@npm:0.42.0": "73e6609498d05c655c6a435af9f3e4f341137c260c7ae27fbb0377573574ca5200bd9f187aa90d442879733bbd0c4e91ae023c3b4579c9a57413a0b2922c023a", @@ -4203,7 +4203,7 @@ } }, "electron_yarn_data": { - "hash": "sha256-Y2TE5iMVUgXqqKojb90yzcCfFAhEy7STB53yYQQanPM=", + "hash": "sha256-ZJs1Fg7jsIvghxDXQ4LZfI0VaZPePdXhwasHof8y6f8=", "missing_hashes": { "@oxfmt/binding-android-arm-eabi@npm:0.42.0": "42c08d87ce491086843070241f8777fa2cb968f4a08f67b3f6c33a8f67e0b3eac50eae146daede743e90e3bc32326951c5188814eea02e9c3e4a9764a4b492ba", "@oxfmt/binding-android-arm64@npm:0.42.0": "73e6609498d05c655c6a435af9f3e4f341137c260c7ae27fbb0377573574ca5200bd9f187aa90d442879733bbd0c4e91ae023c3b4579c9a57413a0b2922c023a", diff --git a/pkgs/development/tools/electron/yarn-4.14-support.patch b/pkgs/development/tools/electron/yarn-fix.patch similarity index 89% rename from pkgs/development/tools/electron/yarn-4.14-support.patch rename to pkgs/development/tools/electron/yarn-fix.patch index 1bf5818747e2..2fa9032d3a0c 100644 --- a/pkgs/development/tools/electron/yarn-4.14-support.patch +++ b/pkgs/development/tools/electron/yarn-fix.patch @@ -15,6 +15,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10c0 diff --git a/pkgs/servers/home-assistant/custom-lovelace-modules/advanced-camera-card/package.nix b/pkgs/servers/home-assistant/custom-lovelace-modules/advanced-camera-card/package.nix index 042ccb0f8436..9bab016c15dc 100644 --- a/pkgs/servers/home-assistant/custom-lovelace-modules/advanced-camera-card/package.nix +++ b/pkgs/servers/home-assistant/custom-lovelace-modules/advanced-camera-card/package.nix @@ -2,6 +2,7 @@ lib, stdenv, fetchFromGitHub, + substitute, gitMinimal, yarn-berry_4, nodejs, @@ -16,14 +17,26 @@ stdenv.mkDerivation (finalAttrs: { owner = "dermotduffy"; repo = "advanced-camera-card"; tag = "v${finalAttrs.version}"; - hash = "sha256-NdWP2nYzDEzmO4DpwVUpn3/KsungKNOzOQf8FxZ4fGw="; + hash = "sha256-I1dm7TZMK/eRF2Uld3e+r4PQBaL9oJc+NI+/5cxaGUs="; + + # Remove after upstream updates to Yarn 4.15 + # https://github.com/dermotduffy/advanced-camera-card/blob/main/package.json#L201 + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry_4.lockfileVersion + ]; + }) + } + ''; }; patches = [ - # Remove after upstream updates to Yarn 4.14 - # https://github.com/dermotduffy/advanced-camera-card/blob/main/package.json#L201 - ./yarn-4.14-support.patch - # Drop hard dependency on .git repo during build ./gitinfo.patch ]; @@ -37,8 +50,8 @@ stdenv.mkDerivation (finalAttrs: { offlineCache = yarn-berry_4.fetchYarnBerryDeps { name = "${finalAttrs.pname}-yarn-deps"; - inherit (finalAttrs) src missingHashes patches; - hash = "sha256-4fdSeSxSjd8EjPmu7U3ftxB+OJJc2uuvM3Umr5iY/a8="; + inherit (finalAttrs) src missingHashes; + hash = "sha256-vbDX5TkUrNqqWLq465mLyGkQ4L8QWJtKv5aCR98P/SI="; }; nativeBuildInputs = [ diff --git a/pkgs/servers/home-assistant/custom-lovelace-modules/advanced-camera-card/yarn-4.14-support.patch b/pkgs/servers/home-assistant/custom-lovelace-modules/advanced-camera-card/yarn-fix.patch similarity index 88% rename from pkgs/servers/home-assistant/custom-lovelace-modules/advanced-camera-card/yarn-4.14-support.patch rename to pkgs/servers/home-assistant/custom-lovelace-modules/advanced-camera-card/yarn-fix.patch index 017f2d295ca9..868db25c8d32 100644 --- a/pkgs/servers/home-assistant/custom-lovelace-modules/advanced-camera-card/yarn-4.14-support.patch +++ b/pkgs/servers/home-assistant/custom-lovelace-modules/advanced-camera-card/yarn-fix.patch @@ -16,6 +16,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10c0 diff --git a/pkgs/servers/home-assistant/custom-lovelace-modules/horizon-card/package.nix b/pkgs/servers/home-assistant/custom-lovelace-modules/horizon-card/package.nix index bdc2ff905538..5cf5e506d029 100644 --- a/pkgs/servers/home-assistant/custom-lovelace-modules/horizon-card/package.nix +++ b/pkgs/servers/home-assistant/custom-lovelace-modules/horizon-card/package.nix @@ -3,6 +3,7 @@ fetchFromGitHub, stdenvNoCC, yarn-berry, + substitute, }: stdenvNoCC.mkDerivation (finalAttrs: { @@ -13,14 +14,24 @@ stdenvNoCC.mkDerivation (finalAttrs: { owner = "rejuvenate"; repo = "lovelace-horizon-card"; tag = "v${finalAttrs.version}"; - hash = "sha256-n8UNL5kSwLz1ncGranmbGyIC5mIKGIV2F3cEF0PSwnU="; - }; + hash = "sha256-p4GI4R5P1LjiXwzF1Hlk6Kk57i+YUcEEsm8bN+qIYdE="; - patches = [ - # Remove after upstream updates to Yarn 4.14 + # Remove after upstream updates to Yarn 4.15 # https://github.com/rejuvenate/lovelace-horizon-card/blob/main/package.json#L4 - ./yarn-4.14-support.patch - ]; + postFetch = '' + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry.lockfileVersion + ]; + }) + } + ''; + }; nativeBuildInputs = [ yarn-berry @@ -30,8 +41,8 @@ stdenvNoCC.mkDerivation (finalAttrs: { # nix run nixpkgs#yarn-berry_4.yarn-berry-fetcher missing-hashes yarn.lock missingHashes = ./missing-hashes.json; offlineCache = yarn-berry.fetchYarnBerryDeps { - inherit (finalAttrs) src missingHashes patches; - hash = "sha256-WrBUsho7GZI/Un2zvhqZ970psDeAiESiBGJikgX3E5Q="; + inherit (finalAttrs) src missingHashes; + hash = "sha256-iHMIcnCQEbDkAugB9FO4G++eDq3/ABfp0E7Q6893fVY="; }; buildPhase = '' diff --git a/pkgs/by-name/li/linkwarden/02-yarn-4.14-support.patch b/pkgs/servers/home-assistant/custom-lovelace-modules/horizon-card/yarn-fix.patch similarity index 89% rename from pkgs/by-name/li/linkwarden/02-yarn-4.14-support.patch rename to pkgs/servers/home-assistant/custom-lovelace-modules/horizon-card/yarn-fix.patch index 75225db95b78..7a11f6399640 100644 --- a/pkgs/by-name/li/linkwarden/02-yarn-4.14-support.patch +++ b/pkgs/servers/home-assistant/custom-lovelace-modules/horizon-card/yarn-fix.patch @@ -15,6 +15,6 @@ diff --git a/yarn.lock b/yarn.lock __metadata: - version: 8 -+ version: 9 ++ version: YARN_LOCKFILE_VERSION_PLACEHOLDER cacheKey: 10c0 From 77ad8ec37ee0677e21fb412f1ce1731998f8247e Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Mon, 7 Sep 2026 02:23:25 +0200 Subject: [PATCH 091/423] python3Packages.psycopg: 3.3.4 -> 3.3.5 https://github.com/psycopg/psycopg/blob/3.3.5/docs/news.rst#current-release --- pkgs/development/python-modules/psycopg/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/psycopg/default.nix b/pkgs/development/python-modules/psycopg/default.nix index 4e4200f9adba..120fc3ea0b77 100644 --- a/pkgs/development/python-modules/psycopg/default.nix +++ b/pkgs/development/python-modules/psycopg/default.nix @@ -34,14 +34,14 @@ let pname = "psycopg"; - version = "3.3.4"; + version = "3.3.5"; pyproject = true; src = fetchFromGitHub { owner = "psycopg"; repo = "psycopg"; tag = version; - hash = "sha256-hHgswbqaoQRQrUxhNFG6tfmlap1mVUo/OkNsWF686U4="; + hash = "sha256-yjfLoichILaKocoAP3IUwkGGJPq910r8qvpdif/oONA="; }; patches = [ From a5d4caecd546c47d1ffe69da50ff056d27f46e15 Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Tue, 4 Aug 2026 19:25:19 -0400 Subject: [PATCH 092/423] meson: use finalAttrs --- pkgs/by-name/me/meson/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/me/meson/package.nix b/pkgs/by-name/me/meson/package.nix index 22a0e8ab6fc3..b9f326bfb2c8 100644 --- a/pkgs/by-name/me/meson/package.nix +++ b/pkgs/by-name/me/meson/package.nix @@ -14,7 +14,7 @@ zlib, }: -python3.pkgs.buildPythonApplication rec { +python3.pkgs.buildPythonApplication (finalAttrs: { pname = "meson"; version = "1.12.0"; format = "setuptools"; @@ -22,7 +22,7 @@ python3.pkgs.buildPythonApplication rec { src = fetchFromGitHub { owner = "mesonbuild"; repo = "meson"; - tag = version; + tag = finalAttrs.version; hash = "sha256-lnuySM7aCojPU9bQI7LPKgod8otFa+Spo9yIDFbOJVs="; }; @@ -198,5 +198,5 @@ python3.pkgs.buildPythonApplication rec { maintainers = with lib.maintainers; [ qyliss ]; inherit (python3.meta) platforms; }; -} +}) # TODO: a more Nixpkgs-tailoired test suite From e375bc6272d599ce9dfa12705f6642d35c93b004 Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Tue, 4 Aug 2026 19:29:07 -0400 Subject: [PATCH 093/423] meson: set pyproject = true --- pkgs/by-name/me/meson/package.nix | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/me/meson/package.nix b/pkgs/by-name/me/meson/package.nix index b9f326bfb2c8..9b1cb25b2008 100644 --- a/pkgs/by-name/me/meson/package.nix +++ b/pkgs/by-name/me/meson/package.nix @@ -17,7 +17,7 @@ python3.pkgs.buildPythonApplication (finalAttrs: { pname = "meson"; version = "1.12.0"; - format = "setuptools"; + pyproject = true; src = fetchFromGitHub { owner = "mesonbuild"; @@ -85,6 +85,8 @@ python3.pkgs.buildPythonApplication (finalAttrs: { else null; + build-system = [ python3.pkgs.setuptools ]; + nativeBuildInputs = [ installShellFiles ]; nativeCheckInputs = [ From 57c2cd9c5f0922d002af6bdbf35361aa91fa751c Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Tue, 4 Aug 2026 19:33:30 -0400 Subject: [PATCH 094/423] meson: use writableTmpDirAsHomeHook --- pkgs/by-name/me/meson/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/me/meson/package.nix b/pkgs/by-name/me/meson/package.nix index 9b1cb25b2008..96b199f209b5 100644 --- a/pkgs/by-name/me/meson/package.nix +++ b/pkgs/by-name/me/meson/package.nix @@ -10,6 +10,7 @@ pkg-config, python3, replaceVars, + writableTmpDirAsHomeHook, writeShellScriptBin, zlib, }: @@ -92,6 +93,7 @@ python3.pkgs.buildPythonApplication (finalAttrs: { nativeCheckInputs = [ ninja pkg-config + writableTmpDirAsHomeHook ] ++ lib.optionals python3.isPyPy [ # Several tests hardcode python3. @@ -153,9 +155,7 @@ python3.pkgs.buildPythonApplication (finalAttrs: { ] )) ++ [ - ''HOME="$TMPDIR" ${ - if python3.isPyPy then python3.interpreter else "python" - } ./run_project_tests.py'' + "${if python3.isPyPy then python3.interpreter else "python"} ./run_project_tests.py" "runHook postCheck" ] ); From a3b310ec27e00cab967c8b587fff3b860dbedf5d Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Tue, 4 Aug 2026 19:36:24 -0400 Subject: [PATCH 095/423] meson: set __structuredAttrs = true --- pkgs/by-name/me/meson/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/me/meson/package.nix b/pkgs/by-name/me/meson/package.nix index 96b199f209b5..1d3af8d5ccaa 100644 --- a/pkgs/by-name/me/meson/package.nix +++ b/pkgs/by-name/me/meson/package.nix @@ -19,6 +19,7 @@ python3.pkgs.buildPythonApplication (finalAttrs: { pname = "meson"; version = "1.12.0"; pyproject = true; + __structuredAttrs = true; src = fetchFromGitHub { owner = "mesonbuild"; From e39541fd761f2d8a45f033d3c401d087b1b62cea Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Tue, 4 Aug 2026 19:38:21 -0400 Subject: [PATCH 096/423] meson: combine installShellCompletion calls --- pkgs/by-name/me/meson/package.nix | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/me/meson/package.nix b/pkgs/by-name/me/meson/package.nix index 1d3af8d5ccaa..978ef5872db9 100644 --- a/pkgs/by-name/me/meson/package.nix +++ b/pkgs/by-name/me/meson/package.nix @@ -162,8 +162,9 @@ python3.pkgs.buildPythonApplication (finalAttrs: { ); postInstall = '' - installShellCompletion --zsh data/shell-completions/zsh/_meson - installShellCompletion --bash data/shell-completions/bash/meson + installShellCompletion \ + --bash data/shell-completions/bash/meson \ + --zsh data/shell-completions/zsh/_meson ''; postFixup = '' From 52048f317597caa4a0936e22e3698da2ddc53bec Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Tue, 4 Aug 2026 19:46:20 -0400 Subject: [PATCH 097/423] meson: set optional-dependencies --- pkgs/by-name/me/meson/package.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/pkgs/by-name/me/meson/package.nix b/pkgs/by-name/me/meson/package.nix index 978ef5872db9..a1fb24f1c0db 100644 --- a/pkgs/by-name/me/meson/package.nix +++ b/pkgs/by-name/me/meson/package.nix @@ -91,6 +91,12 @@ python3.pkgs.buildPythonApplication (finalAttrs: { nativeBuildInputs = [ installShellFiles ]; + optional-dependencies = { + ninja = [ python3.pkgs.ninja ]; + progress = [ python3.pkgs.tqdm ]; + typing = [ python3.pkgs.mypy ]; + }; + nativeCheckInputs = [ ninja pkg-config From ef3d7e646a5c29ddfbbcadf7137f46977174c39f Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Tue, 4 Aug 2026 19:48:47 -0400 Subject: [PATCH 098/423] meson: don't set postPatch at all if not using PyPy I prefer this formatting, I think. --- pkgs/by-name/me/meson/package.nix | 28 ++++++++++++---------------- 1 file changed, 12 insertions(+), 16 deletions(-) diff --git a/pkgs/by-name/me/meson/package.nix b/pkgs/by-name/me/meson/package.nix index a1fb24f1c0db..7eeee851086e 100644 --- a/pkgs/by-name/me/meson/package.nix +++ b/pkgs/by-name/me/meson/package.nix @@ -70,22 +70,18 @@ python3.pkgs.buildPythonApplication (finalAttrs: { ./007-freebsd-pkgconfig-path.patch ]; - postPatch = - if python3.isPyPy then - '' - substituteInPlace mesonbuild/modules/python.py \ - --replace-fail "PythonExternalProgram('python3', mesonlib.python_command" \ - "PythonExternalProgram('${python3.meta.mainProgram}', mesonlib.python_command" - substituteInPlace mesonbuild/modules/python3.py \ - --replace-fail "state.environment.lookup_binary_entry(mesonlib.MachineChoice.HOST, 'python3'" \ - "state.environment.lookup_binary_entry(mesonlib.MachineChoice.HOST, '${python3.meta.mainProgram}'" - substituteInPlace "test cases"/*/*/*.py "test cases"/*/*/*/*.py \ - --replace-quiet '#!/usr/bin/env python3' '#!/usr/bin/env pypy3' \ - --replace-quiet '#! /usr/bin/env python3' '#!/usr/bin/env pypy3' - chmod +x "test cases"/*/*/*.py "test cases"/*/*/*/*.py - '' - else - null; + ${if python3.isPyPy then "postPatch" else null} = '' + substituteInPlace mesonbuild/modules/python.py \ + --replace-fail "PythonExternalProgram('python3', mesonlib.python_command" \ + "PythonExternalProgram('${python3.meta.mainProgram}', mesonlib.python_command" + substituteInPlace mesonbuild/modules/python3.py \ + --replace-fail "state.environment.lookup_binary_entry(mesonlib.MachineChoice.HOST, 'python3'" \ + "state.environment.lookup_binary_entry(mesonlib.MachineChoice.HOST, '${python3.meta.mainProgram}'" + substituteInPlace "test cases"/*/*/*.py "test cases"/*/*/*/*.py \ + --replace-quiet '#!/usr/bin/env python3' '#!/usr/bin/env pypy3' \ + --replace-quiet '#! /usr/bin/env python3' '#!/usr/bin/env pypy3' + chmod +x "test cases"/*/*/*.py "test cases"/*/*/*/*.py + ''; build-system = [ python3.pkgs.setuptools ]; From fdb2910f214e3b40eea96f9ca6e04e7e84ad52f0 Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Tue, 4 Aug 2026 19:54:39 -0400 Subject: [PATCH 099/423] meson: use --replace-fail, lib.getExe' --- pkgs/by-name/me/meson/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/me/meson/package.nix b/pkgs/by-name/me/meson/package.nix index 7eeee851086e..700d7949f386 100644 --- a/pkgs/by-name/me/meson/package.nix +++ b/pkgs/by-name/me/meson/package.nix @@ -121,7 +121,7 @@ python3.pkgs.buildPythonApplication (finalAttrs: { substituteInPlace \ 'test cases/native/8 external program shebang parsing/script.int.in' \ 'test cases/common/274 customtarget exe for test/generate.py' \ - --replace /usr/bin/env ${coreutils}/bin/env + --replace-fail /usr/bin/env ${lib.getExe' coreutils "env"} '' ] # Remove problematic tests @@ -181,7 +181,7 @@ python3.pkgs.buildPythonApplication (finalAttrs: { rm $out/nix-support/propagated-build-inputs substituteInPlace "$out/share/bash-completion/completions/meson" \ - --replace "python3 -c " "${python3.interpreter} -c " + --replace-fail "python3 -c " "${python3.interpreter} -c " ''; setupHook = ./setup-hook.sh; From 9bdf09b40d0fbc77ee4f56a21e68eef898307319 Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Tue, 4 Aug 2026 19:56:07 -0400 Subject: [PATCH 100/423] meson: respect NIX_BUILD_CORES in tests --- pkgs/by-name/me/meson/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/me/meson/package.nix b/pkgs/by-name/me/meson/package.nix index 700d7949f386..30727c12b71b 100644 --- a/pkgs/by-name/me/meson/package.nix +++ b/pkgs/by-name/me/meson/package.nix @@ -122,6 +122,8 @@ python3.pkgs.buildPythonApplication (finalAttrs: { 'test cases/native/8 external program shebang parsing/script.int.in' \ 'test cases/common/274 customtarget exe for test/generate.py' \ --replace-fail /usr/bin/env ${lib.getExe' coreutils "env"} + substituteInPlace run_project_tests.py \ + --replace-fail "multiprocessing.cpu_count()" "int(os.environ['NIX_BUILD_CORES'])" '' ] # Remove problematic tests From 55c902a0a0524a2bedc6105f3d8997605638f95a Mon Sep 17 00:00:00 2001 From: sh0uv1 Date: Mon, 7 Sep 2026 15:40:57 +0000 Subject: [PATCH 101/423] perlPackages.AuthenSASL: 2.1900 -> 2.2100 --- pkgs/top-level/perl-packages.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index 1c9b0036b06c..c2abbfc935fd 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -2096,10 +2096,10 @@ with self; AuthenSASL = buildPerlPackage { pname = "Authen-SASL"; - version = "2.1900"; + version = "2.2100"; src = fetchurl { - url = "mirror://cpan/authors/id/E/EH/EHUELS/Authen-SASL-2.1900.tar.gz"; - hash = "sha256-vjUzpokbLmdxULR5waDUvxHIu+6+0+e466NAU+k5I7A="; + url = "mirror://cpan/authors/id/E/EH/EHUELS/Authen-SASL-2.2100.tar.gz"; + hash = "sha256-Tw8QCu7TS1KXepS335c+fwuPktFnsJ8rJJurgehZDlc="; }; propagatedBuildInputs = [ CryptURandom From 73714887c90c590810da1359f11771503e39f28b Mon Sep 17 00:00:00 2001 From: Tiebe Groosman Date: Mon, 7 Sep 2026 18:00:07 +0200 Subject: [PATCH 102/423] bitfocus-companion: 4.3.4 -> 5.0.5 --- .../bi/bitfocus-companion/missing-hashes.json | 259 ++++++++++-------- .../by-name/bi/bitfocus-companion/package.nix | 58 ++-- .../bi/bitfocus-companion/yarn-fix.patch | 11 - 3 files changed, 169 insertions(+), 159 deletions(-) delete mode 100644 pkgs/by-name/bi/bitfocus-companion/yarn-fix.patch diff --git a/pkgs/by-name/bi/bitfocus-companion/missing-hashes.json b/pkgs/by-name/bi/bitfocus-companion/missing-hashes.json index 0b9886723171..93c04cebef0a 100644 --- a/pkgs/by-name/bi/bitfocus-companion/missing-hashes.json +++ b/pkgs/by-name/bi/bitfocus-companion/missing-hashes.json @@ -1,41 +1,91 @@ { - "@esbuild/aix-ppc64@npm:0.27.4": "ba2c14b9cd901d9e7ea99b7de8ac259b146bf978c69866328d1765f277b11105cd16ed4df82107593b5c9b667bba5fbcde73cb7a9f511d98caca9e26778f64a5", - "@esbuild/android-arm64@npm:0.27.4": "d5a06758f91f0cf795d3a77198fc26fefbd78c3ddfce682df8d8ddb96b31ee65549ead1f6040a496dad2a1fc0fa345fab90692eff3410663bd0f39ed670ac727", - "@esbuild/android-arm@npm:0.27.4": "faeac957ba9eaff1c79871151dea2101d03691cb3772ffd5b4475551f54bf7962e1313346b6c06527e5dce09c63391b6b987b06070a544c4b8aaf91652ffbb84", - "@esbuild/android-x64@npm:0.27.4": "7e294ba0331704c4c455763a7132efff4484066b1a522d64c3068c9017749b9b2c59dbb04bfa6491d78fb65da826109af0ea6a7517b06c8a7d7a64e706390e59", - "@esbuild/darwin-arm64@npm:0.27.4": "57f495c8302bfb58852915195e3066166239de00ea84f91f4cc84b7f46dcd126bdbef0ceb22581e643d0c3a2ca34936dd72a96b40291362c2716d3edb6e051ee", - "@esbuild/darwin-x64@npm:0.27.4": "8b0af048b1b03a2145484fa02283b5c0c9b528fb857d510d9a02150854a2df3a08ee93a4ed269b7e1da54c9009273dac2ce75a419c32fd2f516550bfc534fe11", - "@esbuild/freebsd-arm64@npm:0.27.4": "67a551695f67acdbe7ada9dfa0d97d30ba9065cf79fa96d4e8b75c892200ea25ad8187fb108811b0af1e1ba559fb2b7d4ec572a002916bed70bca654e2888c14", - "@esbuild/freebsd-x64@npm:0.27.4": "a3b0ce4ce0f6e3614b49fded87a7c5989e34a4b81876450650f372cb119d835e627c325039c9ec93cb5fbb098a14dd0e8cfda8a24e8be670ec7900a27e9b90f3", - "@esbuild/linux-arm64@npm:0.27.4": "f3467a2e4f7db00b73df8e074d6c4d7b685d90965d7db8bf1a041460027b61cd9e9f258cca66dc26e0a1b5d8cb84263cd7bec81d7513e27f0ea9dc86253e69da", - "@esbuild/linux-arm@npm:0.27.4": "b30c834aca19a68de625214e912e3e5e2b040a32c82acba0c66a70af741b43f5a02ab07fd1e2f42f2bd7d336e0cf25333993dd070e23c70ea6470170a3ad90a1", - "@esbuild/linux-ia32@npm:0.27.4": "51d5d31a222490225f78802cda61d4ba618a3b5b35f3ea57675725f2cf7af32740c8be078fd5bb42952719b81de4e5b692ea1961d0618d827cbd5bc3b8298a94", - "@esbuild/linux-loong64@npm:0.27.4": "225d208ce874ec7bac4b9028933872aacc1b3d7be886f90741efa1cdf853ad51a064c176bd76ff24f0ce1b21946865b72c69a68bbabdf0653873d0f95398a4c8", - "@esbuild/linux-mips64el@npm:0.27.4": "ca438a7ada46810bc1b24ebfcccf0e2c2cc3098e0690b6d2f4dd031bf33160fb5dde07d5644d5a60bdf3768d89667da7c0df30debee684efc47f0ed5b876c6da", - "@esbuild/linux-ppc64@npm:0.27.4": "da0bb5332234921f746da98765b9a20421a5334bbca2abf8fa0f149929a94c5e1a42319b62aaf9711918d42bc0e397e7dbdbda7389ff64c63f843d451378eb0c", - "@esbuild/linux-riscv64@npm:0.27.4": "b6942603508353c956f804e8c037d9d7092b7885f78c88882753e21e978f5aace82c0aaa42a4100edf2fce3be76ce582ff4e550a7a87079446a4b6228918100c", - "@esbuild/linux-s390x@npm:0.27.4": "719d52323400ce16ee69314886ca17a97d7ed6a9886387b7e4e70fae7133721eecb65a44b521d79d9b6a4f9a3c5fd78bfe65a3b0c5315f11e68847d012344d97", - "@esbuild/linux-x64@npm:0.27.4": "2281d03477bd82fecd14fbbe2c6ee385bc196fef87a2dee9be9eae69429af9972b53f869741db3fdfd404d936f38f3aaf237194f506f8113b79aa9978c26ffba", - "@esbuild/netbsd-arm64@npm:0.27.4": "ca68d9ba6054eb15e7de67283073a82b6492871bec6d9b67cee0785c6d4b9a3391f7c286dfe093206a659a05bf27dc2b58c1e730c0d7ddcb997b7643684cd734", - "@esbuild/netbsd-x64@npm:0.27.4": "9ca4d720a2b681d1a01b50005bd00eb6ac182055585adc845fee4312ff87c55a678d19bbcbaad9f4211e9d409c7d03121748524978aa5404143e375e22d2f900", - "@esbuild/openbsd-arm64@npm:0.27.4": "1459bc44aabc838255cae80e33b32eb22fd375d924ca3eed9e0987e33a1ddae6e59ac61e529564ed9ab7ce9ad108db0f9eb4c5558eb8bc63b952d4ff3692f4a6", - "@esbuild/openbsd-x64@npm:0.27.4": "809917a83bb809d51d11d59ebc1bf9f44b6a94fb1f82bd5d52ac642a7dfaf55c90a71351d263d2c164b2d38700aa0dca69afec4840f929ce56daf90a696eadc9", - "@esbuild/openharmony-arm64@npm:0.27.4": "0f9f7dd181d505e0bedae25a73ac26ad9acd099f7b7c49e2ecf12998b59e49c64331616f22cba6b0da9bd7ea6f5b7fc59f7860014dda5e6673d25661042f4237", - "@esbuild/sunos-x64@npm:0.27.4": "16c38ba94b9b2ed6a2ce17e6b5071459f24e7f1df51e4b6555de7310ff1696743089462585c8c49103ea468b8b1b4ee47913d759c5b44b45c15963795c731150", - "@esbuild/win32-arm64@npm:0.27.4": "6e7361fc9a6d12896443f5b59897e5539d642514b9ba440a2d245f84d82b4589744905b6144d6d345a25cb5b1d80dcbc8a87109f4c9d9e88533919587d76c8bf", - "@esbuild/win32-ia32@npm:0.27.4": "36b0fdfeed7263f87a86c93a47d45c07b5e5502dd31c4a3244f058a0ccfa08c206c8d450eac1cc1e0ab98dc1edeb601b60d3b673cec28015d4ed2fd3a0592da5", - "@esbuild/win32-x64@npm:0.27.4": "70e6d04df925717d37f64cf9945a2ce9d5265169df6a9f5d75e60079023d8f0de7ca9f6ac8826a947c313116990562fc6f92c635f0a185bdb6d02e94e967fe77", - "@napi-rs/canvas-android-arm64@npm:0.1.97": "e36688d7201e7c2f60e3e1691aa4be52059a57d1a076b0fd922ebcb032665d0cfa522f17686d6fa619ab948f22ddf5c454b2695263edad66c0684f22373f22ef", - "@napi-rs/canvas-darwin-arm64@npm:0.1.97": "ec8ff5246e437209e4d2c6ef3cfcacba95cb1f73e1f54734ea3df26cd861761d724342072367b68e377ea5780646384a420f5654711b5afe97704bfde1dc7439", - "@napi-rs/canvas-darwin-x64@npm:0.1.97": "706510e1bbdb5d0d7cd90477714326f420788f6869bdbbf009e46061d23abb043d655ea64d71d6f1332c7fd267acf7250119d2356760743d6243ad0ed08e18fc", - "@napi-rs/canvas-linux-arm-gnueabihf@npm:0.1.97": "f0615e165f53f67aae5eb109763376647c80870d696e3d50a85396816e909088ec4f5a3d5c200a2d87514fb870700362f334034c2e629d1dd377c91f8d566f8a", - "@napi-rs/canvas-linux-arm64-gnu@npm:0.1.97": "972083576ede6a0bbd7698775cfa954bc109ca863cda19dc29b4c7b479ca3d6a8e6e3ff3c2fd25f4b9d5ac140885a469a5f99e9c5fe8ccb8d2f714360cb0522f", - "@napi-rs/canvas-linux-arm64-musl@npm:0.1.97": "ed6f85095031d58d649d094bd4de9d61b81bc33df753711eca284e2f01778eb9a0ffe9259a18e7e3245862ac6299425099a85823322caf691436a60c63396d3e", - "@napi-rs/canvas-linux-riscv64-gnu@npm:0.1.97": "cbe5940f9f0cbf88161aedef662791475b0d7abc43a6c0698a6e35ebc8c0d74630cabc491b484ffcd83f5bc3abea07876b781ca93d369d13acc277f1f5de379b", - "@napi-rs/canvas-linux-x64-gnu@npm:0.1.97": "a3484db20c9db146b16a17697e99929611edd973222ab6afff45f8d76bd56551942d9cf250e11206d9a708cfc14958a93941531eb63ed6a95b4925ae1902bff4", - "@napi-rs/canvas-linux-x64-musl@npm:0.1.97": "2ea96191a243930371271cc34d3ad53d12bc19718e6eeadd5f98e64e6a9c6cb682fc9cc76eacda8daf7a197d7edde56aa3a8171abfd1b47d2dbc358edac21b3f", - "@napi-rs/canvas-win32-arm64-msvc@npm:0.1.97": "67bf5d16e364ac882d3a626c426fb5a46147809ee78e4184839e2b600b72668a5c45143d79e712ae3c6662e54a9c9b2b4f36b03482086f5ac46c25c84dad8771", - "@napi-rs/canvas-win32-x64-msvc@npm:0.1.97": "3435d19347f23ec93eed8adecfbca6c14db368e916298edf1adbe80dfdd9e7679effe3f64ec9ad8c4f683b56528328508fa6e1fad46230c5ce96f2db704cf5c2", + "@esbuild/aix-ppc64@npm:0.28.1": "9b01eaa9c57542436436de762466b9a348b4596aa53dffa6e7034e4180691e1948d33fe34ec302239ab04c280e5166248880f24531011ff419fbec6986a265f3", + "@esbuild/android-arm64@npm:0.28.1": "7c977c8d4cea5126df4b298d5c31c3df8d14aa05d7477aa11c4147ec7baff17d25542234eea0134f279191b59cb1af18fee49c6916afda554484464129e4f9c3", + "@esbuild/android-arm@npm:0.28.1": "44baed9765216202f71b6aae8d9ddb930efa671d34f63f4220d980662b3df4da7972e965c0a0f12922147aa8428083686f6cb23cd9a4f140eaf922ae0b59c2a0", + "@esbuild/android-x64@npm:0.28.1": "1b8183640bef23f41a91598d898a04a6a8e3ca31d0100207c7e75928ee885878c04e3bcf31f27ed9c655d6d8a7c08e35e3afef035aee649488cb2d68e51abf1e", + "@esbuild/darwin-arm64@npm:0.28.1": "8ed80a99836df196c2b7996448eabb2d503ec8c71d0a8be59af4eed457b858fa5fd9292528b1967f0e106d2a045387e375207a2cc262cd45f89596681e94e7fd", + "@esbuild/darwin-x64@npm:0.28.1": "952b23f33c24aea13f5a78fd41731e06e8c7fa732e10995327fa1289115da6b4123899ca0cdb0cf0a56add29efcb9f7891ad6fda0bfb94541347275537a71e77", + "@esbuild/freebsd-arm64@npm:0.28.1": "cc2c4f1f13230607807c3f128680d789e85d4b93309501c4f8d84ed0674f4a2a3e60e279e3b997ee9f797047c1c5b906b25e4fe37de62d19634e4470bcb16f32", + "@esbuild/freebsd-x64@npm:0.28.1": "5b99b980599567ee931520a019beaeea4c7ae2874d0bfab79ee4bd6373a869251d2175946478c527490ce155d10a5bcc795e8c986dceb4a36fb6e813513fc54c", + "@esbuild/linux-arm64@npm:0.28.1": "9348c6bfc2d878e6213cffe482d4455d817b9e56b3c581a9f68b94aac720cddea5733d963dec57ca273039f3a7ca1714f1ac8e39e2e0f85f1af42f5d05e3ed00", + "@esbuild/linux-arm@npm:0.28.1": "654d7af59b4be40f585455e42ecb389657c6f11b1f2be2d5ab04caeac0514574d8b2a28b9f0f9805d92e266a44a5627c5acc8151b0d0379f75ac1490fecc013d", + "@esbuild/linux-ia32@npm:0.28.1": "cce27fbd8d74f34bb5507a5db8c0119aa377c7a070fd0be3881a8efddcdb8adeebe24dc97d55784d74a8bf4a60fb55b48899f41b5e931acaa3eb9f90ecc94a01", + "@esbuild/linux-loong64@npm:0.28.1": "47c3215d378f5da750300694b273b83db26d3e9ed36553696a1769da6d467e7557e289b46d211c93ab7a2978348b7415b66c7fec31658622f5bd356332b9d5b0", + "@esbuild/linux-mips64el@npm:0.28.1": "166d8888e731bdeba0c657382d429c0a979af2136100ee2491ec47b2e2ec55f6924fe2045880b48a6cdaeb3dcc44fc495f3f4b9a5aa3bb8c418d1f53f86b2ba1", + "@esbuild/linux-ppc64@npm:0.28.1": "a8eecb9e43a26dcb70a9805e685dec9f0caff0a8bac691b06a6db7c14ba0a69980ef0c01cb3fc1377ad63e2c4945f396fbbeaf008588bb232e9c0c37dcdb557b", + "@esbuild/linux-riscv64@npm:0.28.1": "cfde883f336e1811fee019a1df402000c7a8e6dc5a2b3577679fd0d9711d1a774c1faa194cc8954b18ca11f3a380ef32905ea90c241803831b61017d8a667c3b", + "@esbuild/linux-s390x@npm:0.28.1": "ea121d2fb6c8f6161312e0239258b584c431b4d23f320ace7cbc18da77034aac5ed383658d2a48fdfa32e38be07126a14aa26802b8e04d0e958e82646fb87f41", + "@esbuild/linux-x64@npm:0.28.1": "9b5458cf012247e31c6bf465e37553f2fc5aef3fccc6593bb30fee0c547958f9f00fbedd44e5bc076cf68d6791a4af2ce8714260fe341cb16843a78643773e3d", + "@esbuild/netbsd-arm64@npm:0.28.1": "86b5cf33fbad27ea5e7345601e711a26717bdf5ad119efa0b1bb9ad6a75f7cb2658c57ffb80f19491e3c7105f4698e76358ee2b6d57f48c9a230de9f588589c7", + "@esbuild/netbsd-x64@npm:0.28.1": "ff24c209715f7f122c711d3c51af099de27659837d3f7bd4cbea9a8868fa99a10b7af785058d18a1e32b2132989d1d1d82b8768df77ff25ab6cf19d58be3697d", + "@esbuild/openbsd-arm64@npm:0.28.1": "fe6590621116132baa0a2b9c2dc95c6342f146170ec1ffb343c29936580c369a69061676bef4e654ee27bad6491f531af3ba985aed7133eb16b758fffae6a445", + "@esbuild/openbsd-x64@npm:0.28.1": "2600c51c394945654f99b096fccba95e1d34fa3ecf4e78f40a7aee4573bf21dd955c274e0586768e9ebef3bff145ffe30231f1cb281ef5e679f7aa78dcc86687", + "@esbuild/openharmony-arm64@npm:0.28.1": "be9e1d1e4af478778ce847e28809fba0b754340a699e37ec03bc1a3cd4e84e4fde30ffea62099757877229b024d50331efd6270580492aa6be38eb2353ef5646", + "@esbuild/sunos-x64@npm:0.28.1": "349b9c7d879496456b2eb28f7bb3decc12a906007bb7fb24cb2b269f6b3e5138af109045b216bd0396762e63b802f0233408cc3dce802be5fcf242d4835b6bc8", + "@esbuild/win32-arm64@npm:0.28.1": "551ada5396e1f10e3d3592dd60a148a7257af1ab2317bba09e9ed18a6d7ee7e5961c68eb1fbaee4e8c1961b504807493e1b8f5c700dd1fb990f0cb36b240ad57", + "@esbuild/win32-ia32@npm:0.28.1": "2676ace6b4d63721da34873974152e869aed9fc8bd9fdff4b8df14a3a3e68b78a9b4566e643b90b948b4e85773cbf288a33a59d13979caaadd43b5adad68312c", + "@esbuild/win32-x64@npm:0.28.1": "8d658b74ed9b7494b3799093551d4c928a7916865ed42d00a135156cbd08612b53072e9e424f0687c10a93a444d30d6b0294b6a1d5fdba78078d706646ba558f", + "@napi-rs/canvas-android-arm64@npm:1.0.1": "1cc67a6e714b9e6cb194709b04a3994ec70679734608244b56aaf2cdd08a451cfc489957ffbaae6d11df2a3ffa9783d27704e14f479720b8ca0002d152f11098", + "@napi-rs/canvas-darwin-arm64@npm:1.0.1": "670bb1e83207a3b100f21c9e46a9539a8c7435264aa83faa7db47697dcefc52ae3c890a3f3f3df4f0e48ae2a0a684ab2e150a917977fa5291e7909bda485dc6e", + "@napi-rs/canvas-darwin-x64@npm:1.0.1": "ad09f3cd6a77b2fce80797ed25dd234906a523d7b7eb3e1a7f282b2d2a5778b2524166a9fb3964211869acb7bdf0bac664f9fb23e3e5301e37f7dc3eee445943", + "@napi-rs/canvas-linux-arm-gnueabihf@npm:1.0.1": "a204cc876f337011d1f04fdb7030af306c52612d8ed62e9fa2d9355f862de52fe56585c08a409b08e8d117200170c368cc6c9a60771f3763532c0ee900ec8e8f", + "@napi-rs/canvas-linux-arm64-gnu@npm:1.0.1": "84847d67398ba2a03b6eb77a3d71fa5ca17a0155483fbd8662a2fed106e3a5cfa7724149b571cc324beea3ebedfe1a5ba74c92254e2db1944c312750e9597349", + "@napi-rs/canvas-linux-arm64-musl@npm:1.0.1": "0f952496e5b22698580182862784ad4ab6afea1822a0398eea66e659f1c548e669a1fc9d805c9bc2e8e784d2ac1e8ca1fddf1584a0abc5abad9a017d5c2213f2", + "@napi-rs/canvas-linux-riscv64-gnu@npm:1.0.1": "2a10b4a1fc89e6dfa152f70de041e5c81ed4f7129ec5ab8ec54d155652540ffde5468b3b536f451c439e1b3b07c77bb3609c486cc9ad4a164267c781cad13a53", + "@napi-rs/canvas-linux-x64-gnu@npm:1.0.1": "41a577d9024e6c01fd47eb44f35514a558d63ce8f71384ad237857613911d667cd22caa3bea8ff470de771987cc293acf2433a5758307dfcfecafb4d2d1598ab", + "@napi-rs/canvas-linux-x64-musl@npm:1.0.1": "2c46a2475e59718f1562639bba501cef507cfbfbbeb15aa92dc5ca9839df781d698d152e3d5e56b258343aff03403b18d984e49a27f48df24013258f9ac9b554", + "@napi-rs/canvas-win32-arm64-msvc@npm:1.0.1": "8ef07e51204c8fb38b5bcd2e94f3dcb731b4456a8a56b3fb4eae3f7c92cc7020e1a7b94b0e566d6432783050d8a1737d40dfb37b06863d5064fdf1519aa11d15", + "@napi-rs/canvas-win32-x64-msvc@npm:1.0.1": "ee22f54b18f16ee09711b63ef67f2d2c6302574ea0140181664d1efcf508875d69c0d8948c2e5be0cc6078bd6f5781e0cb85c1af81e7443251a2983f7f030acd", + "@node-usb/usb-darwin-arm64@npm:3.0.1": "a47f20202b48f309a91aa726b0e5a8ccb3d19d8615988cc90b4e3ef3557f5bceb3da98a8495c6a59d22cd486db2faf78cec69cffc4d6285ac239392ed8be07d5", + "@node-usb/usb-darwin-x64@npm:3.0.1": "a6f0010a97bb3756956b2a14234350fe06cfea03feb087bffe0d9bb5f5b571e3ebe93c6ce0ad4a486bb4d0bb880eabf6fa50f1bc2d273f16e4811905b70e3313", + "@node-usb/usb-linux-arm-gnueabihf@npm:3.0.1": "3caf6677834fae131ed1566aab62eba1da1f9d12da17fb789bf48c142b5ab5fde7eb8fceef59a8b1543a73846bb8bf368a4029ca8bbf9b1c35d30e93cde3ccc8", + "@node-usb/usb-linux-arm64-gnu@npm:3.0.1": "194dbc3d0e594c023efee4c060c61d2523d96e686f74181f06df9747b9b6dd31daa2a757dc0bfa26ea819f68ab10edcd64e12faf052ead2af31ace1e1494a94d", + "@node-usb/usb-linux-arm64-musl@npm:3.0.1": "1bf85e9d653f3418f66e06d7df9da879fa8dc10ef11a1eedac66116d8f9eb459f59e83d033471886a556ea35805bb4bda07070b698d6fdbbb817929e8acd78a6", + "@node-usb/usb-linux-x64-gnu@npm:3.0.1": "0c2e117a42697717fa2c7a72865aabeb148a5c3f2b29d9b06d614282f3da2a536afef0151ea5fe6e826de3f4af4f0be745b30fbc614a82dc2a54ad5a087b14eb", + "@node-usb/usb-linux-x64-musl@npm:3.0.1": "fc8d8ca0efb54b88020ae9fba342f76ee6b5be4faa0ff4bf95b85f35ebaa3a7a52cbf98b9c432c18145a5a199c2a276793308276eb76c6177ba7bbe13545904a", + "@node-usb/usb-win32-arm64-msvc@npm:3.0.1": "0f793ce63cb210b8afe545acb61056941023694ab28c6f98a1153b7f82199efcabecfba5fbc5312e431f7473ef49ee0a2c32ef3e210edbda7e86503cd62f146a", + "@node-usb/usb-win32-ia32-msvc@npm:3.0.1": "2d8aae1e5694e046dfa2bbdcf18265c7b3ede1c17b71b1120efd7c43be30c187133289c6e2495d39c04ac5eb0cb37d8954339eea177024a8cd87ae2cff5557a1", + "@node-usb/usb-win32-x64-msvc@npm:3.0.1": "d3b0ec8570dcccc0e47eb5633bd8bad6276a98134fa1f1d87cfb35f66fb3a9cccbb54efad0842e8f1491d5d40b0620358ba87d247bcbdbdb4307db3d3a41168d", + "@oxc-parser/binding-android-arm-eabi@npm:0.127.0": "945e01f64f415992639081a3dc19aa5919f45e69c38298e20cda23c1e8bba26f79bad55e6dd6190a43866f363dd275970b71843ecf8a51a360cc8768f5900da0", + "@oxc-parser/binding-android-arm64@npm:0.127.0": "f28a90adca64bdabb7e5991941ace223559acaf5ec134fc6fd4f983979a660eafe97b1b03139c6608640e3b37d5a0225684fb49efc38b97486acaac2ebf9f3ef", + "@oxc-parser/binding-darwin-arm64@npm:0.127.0": "490d39689bb179a1f21b6e2230fe877fe6d62520e84d5a673f4d7c704c9a95bf63826bce15208ebacba172bdef0d5fd189b87eb5556de1b9fbf12944be183c8a", + "@oxc-parser/binding-darwin-x64@npm:0.127.0": "8e1ad7af46356aca1d43627e94c9a72d35328a5f66dc184a33bc3e28a086f4ad2b70bd44f097eff6a6b52ab94bafe0e15de396f6eed01d0beee7bd1a45e98541", + "@oxc-parser/binding-freebsd-x64@npm:0.127.0": "7eabf352fd03452bb8f853c7d92581705ddc207a31797b2649f364715b5818d3fb86512bca5a1dd6b3092f0690303f92c240d6ca1738b7a5e27992c08f648cfb", + "@oxc-parser/binding-linux-arm-gnueabihf@npm:0.127.0": "98edb854fd3c30e489237fec6cda7c1e46f0961d1b738369fec357b694989d95ff5ca20b576c835b7af7084ff703888751c877d46862e5745ccaf9e6ac226a0d", + "@oxc-parser/binding-linux-arm-musleabihf@npm:0.127.0": "d4a19c2d8f943c341e452e7ba8adf844998f87ed4ab501b473a05719fca52282bd133973f26e07fee28812963d39cd199702faf424a42300d4e317149079e84d", + "@oxc-parser/binding-linux-arm64-gnu@npm:0.127.0": "d818144ea9a661d54474001e750a501cb5e12460e22d4fb3f1c46506282ee9689a682761e07f4b925d2349fcee2734fa50b6655ca7f519c4ad9a055b0c4dac89", + "@oxc-parser/binding-linux-arm64-musl@npm:0.127.0": "f62825639af42d6be5e4c7a16576f1e23f4386b7db222dec59e320c0c2ccfdcb6efe45903a2969024f14c15f173b174d969473af9a0773cf25c07fdd3bfa4e31", + "@oxc-parser/binding-linux-ppc64-gnu@npm:0.127.0": "e635b0adb9e26bfce5209a87f2b55137ccb1e0d95208e1fd36bc1f0735fc3df95f8a99e11ad9d9ae621031ce21dffe583aa01c40080a9f57b466945306878e83", + "@oxc-parser/binding-linux-riscv64-gnu@npm:0.127.0": "bd16bb323eaf46ed519a583dba0a4b1a5984f65ba19d3773133476a7bec6985e6490efffcfd4d5f711c5acb7e201ffc5898b56ad7fa619cf884990514264bede", + "@oxc-parser/binding-linux-riscv64-musl@npm:0.127.0": "dc38d5b6c6ebe40c2f45ba59c1fa175f9bf148c274c41b0fea39311756e7390fbc25ad1f2399bbb9a2a12f1c2a8d4e284055a12042b6ec90b08d79e579afad33", + "@oxc-parser/binding-linux-s390x-gnu@npm:0.127.0": "a6e6f9c0de7b62087e3950a16b8c6f74b0995e0599a74eff0044b770dc1509e7f390c837f58ef349812036c2cec145cff5ff29800707123813688cbb632b3565", + "@oxc-parser/binding-linux-x64-gnu@npm:0.127.0": "2eea74fcd38d5c2cfdece401e9e8d2099f660266a2efd01603f85abd464aed1f28f77af8951655b2173bde8446da99a0657e7f531af93c941d6e2c851cef093f", + "@oxc-parser/binding-linux-x64-musl@npm:0.127.0": "e746466aaa1f7826130337d83e6b976736d780c59c12c43b5ca4710ad6a24439341e9d5aa58d705d6f6e0618296daf7f422f24e260b3e5c52f7cd0d916bd7ddb", + "@oxc-parser/binding-openharmony-arm64@npm:0.127.0": "5a00e6fcea62d4cfa3993e8d1f4a7f1bc2d70a80f8ac5bcff204eaf820124529194517e94937a3a6d0c28844cf713e7629c0a57cdddd87e0670c786c1890aa74", + "@oxc-parser/binding-wasm32-wasi@npm:0.127.0": "0679729f6bb75538acfda31258110ba0c7c60b195ebf8f0461c1f412fe8cf8a423c35eb107f184e67f3160c44efa32c705581a4014be050feac652a814eb9376", + "@oxc-parser/binding-win32-arm64-msvc@npm:0.127.0": "410ccb3fedde21efef8713198be39e7ba6526509d1328801b52c76e911af3412d1f214aea3609aa828bf30ec8a05e811c82e383da8e6cc3d670415cf17497db8", + "@oxc-parser/binding-win32-ia32-msvc@npm:0.127.0": "86b35f2feea4b23654bafe27b9bbe77194d4923f73f4254f813bcf14de5f12a09ce67e7fdb93b73944c9b859a0433128f3df2ef3fbc56f4c486e99d393508f0b", + "@oxc-parser/binding-win32-x64-msvc@npm:0.127.0": "6993c90d54ecfca7b5fd5a2a6f07909d53ce553b14e55dda739550e8dbc1a593c49f23792063cce95bf286bcae4f67624d0d9f014e28eaa700a31da185f2127b", + "@oxc-resolver/binding-android-arm-eabi@npm:11.19.1": "7fe35b00927acc6b1e9abd7cbf001cc4855f697b1a6604f245cf80ecb09628195d724545680b11ee58c462482247017e6d25d3b6074437ac61842ebb2200e925", + "@oxc-resolver/binding-android-arm64@npm:11.19.1": "2074f0f614aac0178d8c879f0a3897aebbe9cce66241bb8db8dd0400bf30db8a322fbcfb3dffd90e4a9f08eb52f32026155094c3515901f9e50f8c8115508bc2", + "@oxc-resolver/binding-darwin-arm64@npm:11.19.1": "43f0ebd467387f508dd13749b67a1b21b81902dfec7c7fdee24df1976942a78171e29e4ef09390dae88181dcdc4ccf08f43ade727c101572fff961b925f79834", + "@oxc-resolver/binding-darwin-x64@npm:11.19.1": "efad8b905d7cab94ddb749a7b486e7606d21a71ba3f2c8bb117e4a7648aa22499663c96819196e0f38830bb87885f147f517147f3117f805f908274086de01f9", + "@oxc-resolver/binding-freebsd-x64@npm:11.19.1": "750c57d8291f8ab8759f68f16b10aa5967879b7f6f432aed838d3e4b3ea25857c3f5dc1fd4677e79de890e79cc5bdf8bc845ab403bc7d9b7d7827c6af11404a3", + "@oxc-resolver/binding-linux-arm-gnueabihf@npm:11.19.1": "d1a71513000f2d7c300c45ac6b0900831e37759fd0df7c92a6cd2c66b87a724a303da7df94ed16fcbba72ccda45766923212c9711edd228b9f97dfa8da38e08a", + "@oxc-resolver/binding-linux-arm-musleabihf@npm:11.19.1": "4f1b757e8e86fbfdb7f8fd43e9684f3fe339e46606d836b509241c9217ae608397c5c4383b45ba9eabc3b6b4664842839037d41a9e49e726e4ef6e75d871904c", + "@oxc-resolver/binding-linux-arm64-gnu@npm:11.19.1": "6b1342772f5f347fe2a25582a8cd60f3814a7a6e4d2bc8e4a140355409df550858b961ce93932e3ce01fd440e7d4b2dd144978cd6372af325a6e2d85e496b4e8", + "@oxc-resolver/binding-linux-arm64-musl@npm:11.19.1": "40b99fcf1401d0f09a701572927bae4305a15705d2bb44003773ca5bb3ea8f28037e1e64fef5525eef314bd6ef348997b36cd521b4023053e0e0873b6700d52f", + "@oxc-resolver/binding-linux-ppc64-gnu@npm:11.19.1": "3581288514ce58eb79c927a03a43667e7e51b67b20be1f2c8343bce07f1fa848b9802f2d12990af73e8dae790d1ac6200611699c5350bd28a06abe3115a98002", + "@oxc-resolver/binding-linux-riscv64-gnu@npm:11.19.1": "1a8e43df91d8e7fec21c3cf816f20f98a0237b202e99d3768e1a9c49d9ddfbf0acea962991c4ae67dea936f3d2031d77bcacd3af615eecacf7828246be79becc", + "@oxc-resolver/binding-linux-riscv64-musl@npm:11.19.1": "a71fd4c5a13d7cb588d341318811d2728d64111878757988b15c2be3199d0e3f9dacb867ca990ec3cc38ff9eeaf9dfdee7aeb23738028031e6303903f0e501c4", + "@oxc-resolver/binding-linux-s390x-gnu@npm:11.19.1": "f4fc6a75967235ab88550b30891eb17a490e5bcfa8e9b2eaad33b3a4e7fd52ca60e6e0df3dbed5ab9bf4cab51bf05725e86e6d3172a46a1a95a928012a2d52bc", + "@oxc-resolver/binding-linux-x64-gnu@npm:11.19.1": "090f364639f4c6c021f345dc182c37c0d8370bc7b7ce5d93c546a49a3188d400a9c030106cba27a8c02dd7044384efc51187cee4f2e617109593e3c237a65509", + "@oxc-resolver/binding-linux-x64-musl@npm:11.19.1": "653779d9f6b78df664667e5f8693741727cd7c3e74831e0642a3ecd84fbfb36d302c1ae38a53cf33cc9516aef7d7f5ff66dacbb5f3701805baefc5785a5d7669", + "@oxc-resolver/binding-openharmony-arm64@npm:11.19.1": "4d88027b1ad55ab8b4820e8ee24c3a23b6ab6731c14da0da3c6b27394657bb54dd09d01085a64884e8f7219f719b48ea2221f0d7c8f10d2e7288c8a5e0b68287", + "@oxc-resolver/binding-wasm32-wasi@npm:11.19.1": "53be10977b68276a5e72be2a6b56361ff5548243aac269b93178a6058b0cf4dc14484a73ee5d0b68be1582982d96d434d97838515d1a9034a901080aef9d1b75", + "@oxc-resolver/binding-win32-arm64-msvc@npm:11.19.1": "f7671ed2e4f73d9f5ec386355fc9d93940c32bccdfbb7a7fb16bdc51e3cc42ed920cf9cd2f72d77c56e4a4a2c9357e53df3ae88b36106fcb363771e47f50e19e", + "@oxc-resolver/binding-win32-ia32-msvc@npm:11.19.1": "d60ccab0778023eb6977636c32d05c2369b54390aa8bdba4da1809323149548359bc546bccd9e5e717310c46e2a742ccd4dbc3f4750789aa97b5f9cef10ddcf7", + "@oxc-resolver/binding-win32-x64-msvc@npm:11.19.1": "bd84616bb214bd3f63531299f5576538f3f63411f95f1fb470fc8d7434c409fa1922bcbe535c4137673ceb3517e61b102e739a06b1963df600b717a954d22b16", "@parcel/watcher-android-arm64@npm:2.5.1": "f99d569e4f6cf78a1b0097fb9d4682cb201a74370ae440c531da4e1d5021e46141bfcdf8ef708b51a5b9cb1c30f78eea933ce75216d5eeb7b969a2ad27c68e4a", "@parcel/watcher-darwin-arm64@npm:2.5.1": "973c7ef3c94608da9cd1b20b18b9a7de2fb46fe44553731fe372b640de524491976150d0845f3d5953b74ed8ea469cb8d18a48651d0e5fb82f549a6b46b54f79", "@parcel/watcher-darwin-x64@npm:2.5.1": "848c5516aed9c36e14751200dbbf57e83c0bd46cdab0932df33db120e66b9596de18eeb98980e319efde84014f67d9e7924d7555383d8ffcefe35c501166b84b", @@ -49,46 +99,21 @@ "@parcel/watcher-win32-arm64@npm:2.5.1": "e015314d6b9b727cbe25eedf963ca8b23bf6d4e78d3c28008bd0d2657940ad54a271330486df3a93a5f1a30f2b8d052d14415b85cc7e7b747c6c73b5dc055628", "@parcel/watcher-win32-ia32@npm:2.5.1": "920b6ad6a2095aeb9c2d329c5118472a3c14669fa93eaa99aa8050c76c5c2d3d76d92677167ed748c2ac5487c568d5df16d5d94f4bc7c354094fccd8e0d6350c", "@parcel/watcher-win32-x64@npm:2.5.1": "8f1c8e41ec9f86e4dcd0d4db0a077742d5dcc853f15ea888387183e34e2efcff09fd1cc9ec46fc1121b9ad4ddc0e221283f2ffb23cfd7dbcbb8b03060b461963", - "@rolldown/binding-android-arm64@npm:1.0.0-rc.15": "0c78d6321d2dedc0c6ed4b5541328f6c04e8530a3c294b477cd9741e2af7c8377a51474f0171c85ecf63bff5c8bb31ee586f40f13fa265a869247ec3d6293204", - "@rolldown/binding-darwin-arm64@npm:1.0.0-rc.15": "598b8cb87d8ba8df4e880e0d6903f7f4f32b3e7b2804429cb3ccc47a69b8e7b852b2e3115a8c3a882d14979909f9464e8da55c2c52a52cb18a81df7e8a1aa654", - "@rolldown/binding-darwin-x64@npm:1.0.0-rc.15": "92fdfa58a8d9edaec4c1766c38c34f657715d2c8faec141590812d11ba6a6ce52530e55a6a2515fcd2ec6287e50187a458f06ca3c6813130cb9869a99c9f6f29", - "@rolldown/binding-freebsd-x64@npm:1.0.0-rc.15": "04e8288accf007c82e8bbe75af62d4ed570bddd7b25a178506fcf97daa0907cf6f85ea095be5826095242ac1a4923196059f53a9e8fdd0e3c34d9ed1c00d64ae", - "@rolldown/binding-linux-arm-gnueabihf@npm:1.0.0-rc.15": "4cd7452e4fe4433b730585bcbaf210efc50621bca5906204179ffe80748bea187398d4091dae64079f0c7ebfea1987f0b1c045ff60209ab0f60be9e04eccbef7", - "@rolldown/binding-linux-arm64-gnu@npm:1.0.0-rc.15": "fbddea791134b45a94aa5aea640a177d6feacd81a44f9ee3615da3daa824dc2a193ced6e8f2a0bb0676fca7b224525513b451cd8f78b379d7b1983fe6a0360ff", - "@rolldown/binding-linux-arm64-musl@npm:1.0.0-rc.15": "b325fa98753bf41100c5d95145f30ce92b5f69f6989973306344b1644fb21633454aa216f28355c74d0e7bd5885bb6d2c80d0f96dcc2b869ca7e63d8b22dbe91", - "@rolldown/binding-linux-ppc64-gnu@npm:1.0.0-rc.15": "0bff0d2724912079dcedfbc0a86dbad8e3e376d2d619cf36917964701b9ae5a39afa5ff49d3cb5b2c3e17437c559314cf8e17433ad3bfb4b64229d9c8bf1ebca", - "@rolldown/binding-linux-s390x-gnu@npm:1.0.0-rc.15": "6718fd91ead389f3bdefe22fd0344b490d3f9350697e4aa35a0fb55957aa1b127d26aaecf9bc2d49f1dfde62d9d4717cf5dfb7d93ce3b871372ef9c6cb7a1b1a", - "@rolldown/binding-linux-x64-gnu@npm:1.0.0-rc.15": "cb7628e1a7398ab5fd07dc79a38c73a27524d45adc989b5d906ea37e23b7692123d607d07fb9fda35485d6caba545ae41c561b9632aefa0bff76997208f83eae", - "@rolldown/binding-linux-x64-musl@npm:1.0.0-rc.15": "f59fb354b8cac55d123f6f3fe7bf8210402f97ed4be3f3a883c6c544ce1b825e36154f479d45f6e9f23c1fcd8861e9f3873dc24278631db871d263db3bea5580", - "@rolldown/binding-openharmony-arm64@npm:1.0.0-rc.15": "b6c220a48ace9c381d238dce2caaa8453da1d3fe9312bab7babf127a500bdec2bbe30bd381f9945af79c30fe9ca0185108b86ef311fc83ecb83ef24f7a587902", - "@rolldown/binding-wasm32-wasi@npm:1.0.0-rc.15": "9cd39e02ad5f43fc45901d074df10c0e3532d9077a6e334e431de60f90555c15e5445d1b5156c10df49d28839f9f15d5d808666bc8e70ab065bb9af3b8567e7a", - "@rolldown/binding-win32-arm64-msvc@npm:1.0.0-rc.15": "cfc32a72e8a3900f356b0b359520df3f18ac79379a273a4c53b00b1555123dcfd8204cf9976762664898b0c6c949c0edd4be850ae254d2e84a40fcb8352858eb", - "@rolldown/binding-win32-x64-msvc@npm:1.0.0-rc.15": "f0bd2876247f0834f135c1ae150b7d5626d54ff399b4a6193626dc46a0eca22374a43c64afdf3eff8e8e9cf1f20df826bcd9fd4219df3fece03972b8ae080e20", - "@rollup/rollup-android-arm-eabi@npm:4.60.0": "9a4292f59c64fadb8583a1cb20aa76ad07cb14213abcf705a25f21102f618d2c0c225caaa1730d77da3a472ba1660c987f709f364a60ceaf31199ecb2c7bd82e", - "@rollup/rollup-android-arm64@npm:4.60.0": "59f4cffa6b8245a3570479ac30834d18a63bc18d0eef706eec41800fa3256ccf3d5da1d9b0eecd360b8dff4df6c50adf7935b300e5443c72c2348f37307f828d", - "@rollup/rollup-darwin-arm64@npm:4.60.0": "5bdfee08ea0c0c49dd9877773c8a7361628b4274d7ae03925aa83e38dbda0f985d3bf128ee5bba99e50754034e109b8b3faddd47b776e503374fbebec6e98dd4", - "@rollup/rollup-darwin-x64@npm:4.60.0": "eb7bcb4655e1c31eca74ee96bc8c1de3ab3a511de3e5f433d59c14d4075ab6c32f6770722f5faded1cf8b6b64e3cf9378ac50b0722a928f972abb5e9e8b79096", - "@rollup/rollup-freebsd-arm64@npm:4.60.0": "510dc460350a81125c86db154c152af573e97fc77658924ddc126c98fae1b4e7e96274b1943d0c90f6246fc821aa0f90401f8982e18cdc06b5d0d62b0dd8791e", - "@rollup/rollup-freebsd-x64@npm:4.60.0": "5d8f2e66a1d62ddaec83fccce64a407e63174deb6fb4e492a8719c879f18e77baf2b1068b044f5fe0b67a41a80b72ac418f9aeb4baf5d9d9433c7701202d8a06", - "@rollup/rollup-linux-arm-gnueabihf@npm:4.60.0": "ab1f4fcc86f5d25867f84b00dc546f067f2a53ca631452407c03e70c341b554b03d2f77086533f55be20d36d9382a8ec339901bf789482c73dbe59d768adfdc8", - "@rollup/rollup-linux-arm-musleabihf@npm:4.60.0": "e08b56f8e3d7773e5b685100d22b4b0a8a562ea56524817528d214a6aff2319234da462e228d4842d04f5e1b711ceb77f4b041a4d2b69d446b959c1ce5cc603d", - "@rollup/rollup-linux-arm64-gnu@npm:4.60.0": "1cbf82bc9acca2ae204155d38c890faf88c4b02060b3ff4c96993379e48c08e6541aee3adf4e6a6dba986c0accc554eb21f9c23bbfb0257773e607a5d40eb6d1", - "@rollup/rollup-linux-arm64-musl@npm:4.60.0": "94fbd42c786baf0178adb6309c8d2c9fb5daa97cf2db8cd2cbcd88999c80b9de3089240e804f4287545eda3b509aaa67a41a8711ac5799f74261e11469d64dca", - "@rollup/rollup-linux-loong64-gnu@npm:4.60.0": "e840acd88f492be16732c7b365c680e03109702c7e6a33fdae04992abe333378180e713f9d536585348aac09e50dc11fad23d946df7338d13d95913010232bf9", - "@rollup/rollup-linux-loong64-musl@npm:4.60.0": "9775b8fbd12743f82230f4cb42f69c5fa2a96ca132a87d5a141115f8f879e96d37f8f9ee42fa5d9323a9c0e2ff7e5aba4e7ac99fab5aac044e0d47ed4e6dc2b4", - "@rollup/rollup-linux-ppc64-gnu@npm:4.60.0": "343870a783702e938933f8161c9a55abc5899cf52bc4bf44a97c0fe93ede9622f52488d56c33b67ccc18da1f3b369db984a6930d0a005de87221d8d997a827c7", - "@rollup/rollup-linux-ppc64-musl@npm:4.60.0": "3e8bcd82cc55f01a62e900877a56eb307824dc20edc22b0d51f3b21851f873f2da0dd146eaebf4423a7bf1d8ba377e58abf66194deb280d1fae54fb9de3b9d63", - "@rollup/rollup-linux-riscv64-gnu@npm:4.60.0": "3fdef46fa6ec90106db05d313048d970e86a80ed5ac6463b1f6060e1796a9f1c2287787ef47705032e0df704250046b271c9a52e691df727613421953bcb2bb8", - "@rollup/rollup-linux-riscv64-musl@npm:4.60.0": "50fe34aeb87c03f2c5a356884902242d4ddd3b0eec43b946c89ef1323dbab485a504638d024353f6b3aa7fdb1a4ddc979b8b034be22278ced4b0a9595d6ec7b6", - "@rollup/rollup-linux-s390x-gnu@npm:4.60.0": "af9d7f6f876af243960262868146f4f1ebaea0dbf9adeb14ea85b07c60df0e1d4241ddac1008509ee80ef47cac8b924f85099f7076f8c25e807cf87f048f435f", - "@rollup/rollup-linux-x64-gnu@npm:4.60.0": "3ce88bf8a93ab7f732139b3015249c5b8af5f0ceba8058e05f21c3e51144661be844b9a9ab20503b0f420579d930d37e55575dd544d303a0efcc09d979f537b8", - "@rollup/rollup-linux-x64-musl@npm:4.60.0": "893569365547e7fcea9fa83dc5f7824316ba959ee546606df70633576e6223fc5f33db3da89caf18815f2d671e87fd549886bbe7795facb68de9da941680c335", - "@rollup/rollup-openbsd-x64@npm:4.60.0": "ec522dccd3807237927afd6680ba7096041b477d4ebef6142e6a390fcc975fbd6d43d1a0d6e53cf8e97b6d90e528bb51a8ba1029383bbf086f5380fdf90ec6bd", - "@rollup/rollup-openharmony-arm64@npm:4.60.0": "aacd3b633618c1933f413e0ec2c588e75c3dd7830c34e2bc947915a307f97c570d08d103c5b4f30fd6b60a77dc6c81eb9ab4041205ba19414f55ed644a74f180", - "@rollup/rollup-win32-arm64-msvc@npm:4.60.0": "d8ecd24616112de473344717e07481081c0652f0a0d40dcc645ae2ac05e60fc962e2b0f86dcca7ab40b07625886050214403fd125e53297ba3003c877430f71a", - "@rollup/rollup-win32-ia32-msvc@npm:4.60.0": "0362713f7cfeb0b3deeedc11fabd551ec309cf21952735c2e2b76caf083331aef6701a11d2ad7a3824c439a9ff0d0c305aa12ef62f4f0a540eba2e952a18b00c", - "@rollup/rollup-win32-x64-gnu@npm:4.60.0": "1400b3aace00dc90638bfd39d68275bb5f16143d240b9c36eb70f242ed2080c26fe14192fd3375120308ff94a7da1e169a8e0e56efbe41483f59731602d3be84", - "@rollup/rollup-win32-x64-msvc@npm:4.60.0": "c948b3a8ed6e73f2382dc41ffab3e9928f95c4a0e3481272b26ad04a5f73084ca13fd5c253887f9077c37cb1c91bd8494b4a45a7764c874aa105684e8424289a", + "@rolldown/binding-android-arm64@npm:1.1.4": "d59f76669aaf18426811b5e35321cb5598e69bf57c1fe52c384ec157417c2cce95b34af5c41c085eb1098d92b3129ad3f5211df48efc759361ea8df5011efcbc", + "@rolldown/binding-darwin-arm64@npm:1.1.4": "0a1b74f273e25911b0110d289fe517f6273e39b5a08972231ccb74b76035d6229d51ca3a92eb1b0dc774e7377d373404d1c2736493271f576a266c0080a34206", + "@rolldown/binding-darwin-x64@npm:1.1.4": "736b7ee7d9ca8524466c329361c64929fcde7ca98ab99f279383b4e2e8df5824a1cce08bc5b6b0ff5c6753385bb4438b057c0afb7326b568d020848d950b2924", + "@rolldown/binding-freebsd-x64@npm:1.1.4": "d18f28b53889c03a99822f1666684533074329be5519ed79428d0f180d8748a21a1af00cb1de895a4a2e2c4981219d67ffbf894f37b5d45d287402644e4c6c3a", + "@rolldown/binding-linux-arm-gnueabihf@npm:1.1.4": "0229d25aafebcb76beb377ccfa2e4d55ff632563ad1ff8b061e71f5f98408924cd69c7b826265d957f8f392d77503d0acb7b297944915df44718a57ac83c7efb", + "@rolldown/binding-linux-arm64-gnu@npm:1.1.4": "0941dd2d18304ecb46cb08d8be7dfa22f34ed7a6c63632c6a274ff3035987fea4d672ade92d5a4ee5c31113ef66373978a3c9cab598c0b128ab1b2c9e5cee5e1", + "@rolldown/binding-linux-arm64-musl@npm:1.1.4": "a655f61bb3695a470deee665d3b1b6bf1d08e89b71d96e6362de6675dfa058352cb4ae360a4716aa1887cd97163b61411851780b84a2847ccf4cbdbf1dc36565", + "@rolldown/binding-linux-ppc64-gnu@npm:1.1.4": "7af64514357ba55256c6d2c62e1a2f0fc0a807f303353cd5b2703f64f04d1140f0edaa3eea9a94cfb120cb6e4c71a447c30041ecb86983e9a001455de5a1430d", + "@rolldown/binding-linux-s390x-gnu@npm:1.1.4": "abc61c30e8993fec98a17bba70398150b5b1a2a637e869ef767150906e43622ec2dd7cba4d5ec44f2f3aea193c95b75a9b67438e6cf2cb1f2b7e19569821fd80", + "@rolldown/binding-linux-x64-gnu@npm:1.1.4": "a7f99f45df86abb32d0d95023cae3e9923b47f04bad48e276355b9ceda9c9b9c0f70966557d48006bd0d673e7b4b622dd9af4ae3e605f2e7b717fc63f1c43878", + "@rolldown/binding-linux-x64-musl@npm:1.1.4": "1ac0921cfcd2ce3a5fbc70bb8bbc17e7a138a39413cce6a151a943be870d2c91b5679ad6a85ccadc383100f795f52d6fa47a47652a5c217a8bcb1302defddc91", + "@rolldown/binding-openharmony-arm64@npm:1.1.4": "f61e8562d59b91f4c238cfc815d5b43fa170f6a2795f0de6fd18425e155c8a75486f5a1ca53785bc81b4b9fc3b1967d7803b5be89fe50957e823746f6a35484e", + "@rolldown/binding-wasm32-wasi@npm:1.1.4": "e248421de5a5d30667deb15274101b73562e0ccb25de708eb7c1e463d825dfbf42e0a498f70093d8c22bf640d21f660c5d9e158001ecbb0e02c8c2be8db4009a", + "@rolldown/binding-win32-arm64-msvc@npm:1.1.4": "d2893af2319711c04eaab03e248d0f96b320942b7f843267b7d62d829eddd5c47808f0b2534fcce4c79db53da4d4cb57a7912f6ddc2e39ca72f09263d397d87a", + "@rolldown/binding-win32-x64-msvc@npm:1.1.4": "1566f653b56c576927cbe33d6c8aafccc82046ab04bfc6ac1907c58b48d902033610a6db23bfaa3376b2bdcbda1ef1c5c9437367b8bd3df4e247c9469e8beb1f", "@sentry/cli-darwin@npm:2.58.5": "8bb8a01ab9ba6862304d2efbb40a397cc52859665be38c238b75a3c82c0e6b795513a8e018c591da6b992e9531e8e485ba0ca46c60f2beca7690b0693ac5a771", "@sentry/cli-linux-arm64@npm:2.58.5": "1755aea6fe1808306fcc51e2d88f1c161118ea9f40d47f97570d121300da083fe405fb64b8fbbe753930c8ebaadb30da24c951e5e38ae5ed39bc97e02d712d73", "@sentry/cli-linux-arm@npm:2.58.5": "4fa8047b1bfa13969093ab25a643ae8b3e1f65fa3e1c6b2287efb1c6ca086b44e39ed8e7a5dfdac0d71efd7d985eaa12fa9034dfaa0b65e904d0ee082fca0e31", @@ -107,18 +132,38 @@ "@socketsecurity/socket-patch-win32-arm64@npm:2.0.0": "65418168f7f68cd2373000893d96251ea7ee8216a9730f0d51efe24402d67a5126f5255d6eb2d5ccfc4726e685a3ca17fcf7ed0b0d5feab631136902d5f959cc", "@socketsecurity/socket-patch-win32-ia32@npm:2.0.0": "b48b42604530d283c2e1230c5d7604fc5c87f97d0d50ca305a89ddc16c24eec6d833cba39a94fe4e6cc3bb85d3a5e1f47fe1013f1bcc0c0906563b823fc8405f", "@socketsecurity/socket-patch-win32-x64@npm:2.0.0": "8057bbfb19b4601bb1eb4af272fbab315af92c9b870731cdf8cfa7520bfe7b0e4b96c9ad6b1c1959490f97054bc64cc7e3c7dade054a46801b61ddb69e369253", - "@tailwindcss/oxide-android-arm64@npm:4.2.2": "11f6e9bd3c1eb998725a89210a74ec2253e7387e451fad4c9ac171d9299cfd4ca1ce24e687856ff7887a2fd60cfabb267f8bf77e392e3069b2ccb1d22007aac3", - "@tailwindcss/oxide-darwin-arm64@npm:4.2.2": "ddd2d7844ef9be81dfe043b393a4eb7d971d72c53eef241456c132f7c38d5acaf569311dd565d23a345484f0dcc16a3967eb3ed74ad08e672310919f1a0d8502", - "@tailwindcss/oxide-darwin-x64@npm:4.2.2": "29b54e88665e7cb6b08ec143336d56e7bc100f6c621a414ae1c96c5a913de43859d8b5fd197dc9b257c95530dc949d259d841f1b657cc7a037e74b61aee85de9", - "@tailwindcss/oxide-freebsd-x64@npm:4.2.2": "7e89193701c6239dd007eab2e48e4fca0b88337b50bdabd341bbab3660fdc5a151131ae28a24c5a9bb59ee491fd8acc4583018b93dd545e4889da28dc6a445f3", - "@tailwindcss/oxide-linux-arm-gnueabihf@npm:4.2.2": "6bc2f863e02da37c9ce2807ee2fe1f1d00f391d5608fd9092630faefc0902f3982917d9dfb6df38e6e2ae4e3e83d5587db02a178c78a4b896085f3dfe72fa931", - "@tailwindcss/oxide-linux-arm64-gnu@npm:4.2.2": "a8962da367468c8b28b4d0afec55e55dcff3c4c0f885b60ed4ad825b6f3b40c7c7350a646f72cfe502f247d5b3c4c0c1f03b56d96b3867c034e839379e91a78f", - "@tailwindcss/oxide-linux-arm64-musl@npm:4.2.2": "cbab9ca951ccf818c9ccdfa6a9450a18a022fe67ae86c75c30ad325fb2a3e0821362954dc76d188746d3d54cee93b0b1b286bdc3540d6e79a3d504aad8f135ce", - "@tailwindcss/oxide-linux-x64-gnu@npm:4.2.2": "0b6e47b461b9e1168033edb2c72b6405c24e944c5caf867858bd1e5dcdc68dcb5175edc8bbbffc472d00444dc1dfd45d510073fb619cad2887ebb996e485bcbd", - "@tailwindcss/oxide-linux-x64-musl@npm:4.2.2": "c1e258d6d954b0c3fa3c8214478c2b46e5581f60aa1049c11f60a1836668157b023325c691b8ddfabe39b36d8df9ff32e9237d06dc1e8e0beff103324730537d", - "@tailwindcss/oxide-wasm32-wasi@npm:4.2.2": "83ae560e1503cefc9854d5d54b9222d81287a8bd7fc29015f42d032c262cf0ba5ac88f6707219092bb0ec7d8f569a3440e585a9dc084aa07ef7dcfb4dba3defd", - "@tailwindcss/oxide-win32-arm64-msvc@npm:4.2.2": "674ba83bdf03338878cb7839d4a081934404f9fe8771df3c55f6c2f0c09cdf4ab871ec2e821f23eda245c7b0a9b9fdbe32c0d038f887e4958d97c37f9cfe5b3d", - "@tailwindcss/oxide-win32-x64-msvc@npm:4.2.2": "8fd2254df241f2d17417c8a3ecf9ddc51dc23f415a7cd1e7661930296de1a9f4128ae9f3912050f8e9dde4ea0f0f2b2452031b913451aecf12d453f131703c79", + "@tailwindcss/oxide-android-arm64@npm:4.3.2": "d71f84cf523d0b7e617640b2ef6930f8c78321076cca1d0266a531a12f0d1165a0f4b434a1527b3b43640dc19b2ed86c9db8b20de3e2adeb55a63dfbcfa096a8", + "@tailwindcss/oxide-darwin-arm64@npm:4.3.2": "57ee616c3c64a55da3e7a756e7ca82af89a3948646cf4b5117884ab60d922193cb003dc74837b11671f2c888ae28e6c3be69bba898fe7eecdb92cc5e8b6457a7", + "@tailwindcss/oxide-darwin-x64@npm:4.3.2": "30e477d48d3ee6c195583108f70ae861d47eebb35139dce00e57bcde5d58d387918b1ee4b1b1dd320f915a22965faa8caace579cde10707070ca25fdb754a9c3", + "@tailwindcss/oxide-freebsd-x64@npm:4.3.2": "c47f0a698c2e6f13780916468b70de9d13662851ddf085c3a4bc1b481335b4b01028e2446a0f88fe1846c9b325b7cf3c28844b4b5e6c399b768a3481e943637c", + "@tailwindcss/oxide-linux-arm-gnueabihf@npm:4.3.2": "79270082658f16b905cb1861070c87f02a2cf11f24f34b5a543d7da5197c7a7f117847a68f11cc8f39abe1d40a93cd7da9f605f828b2f45eb9fa75e294bbb91c", + "@tailwindcss/oxide-linux-arm64-gnu@npm:4.3.2": "a2a9a54d3a9204585e7af11b17b0f3748d4924364606276938a13a423ae27341dfea6317c35fbaadc436a493a60675851b45ce61c30021d7a4c2cd3c3c839e86", + "@tailwindcss/oxide-linux-arm64-musl@npm:4.3.2": "5abfb9e78a6946f90c1ca2e57b0ac1be87cd5f0dbabb34d9de2e2d652cbfce35d264cc9fd98d0560800f7e000495ab25c45c630916fd621aee7dd20fd3771de8", + "@tailwindcss/oxide-linux-x64-gnu@npm:4.3.2": "5cdd5aaa678665b024d16d557e344d564810e78525be3bde0b86b6b924bcff1e81e2b7e0da88c7f0868c26669955129960c215044a2fd47cb63d2002c6c7e96d", + "@tailwindcss/oxide-linux-x64-musl@npm:4.3.2": "61d39503d79726cae3c497432bf18840c170f198d7ee65b40108e546a24cd661d6f6587adf023254410f11bd6d143a88d09399342f43f4cbcfc017b0aa853d66", + "@tailwindcss/oxide-wasm32-wasi@npm:4.3.2": "6afddcfaf232ac6290ea3368ee3c878bddf8b3c842f3cb71583ef387009de12988067545e9dd4de423f3bca3f93498c4fa46ad105bd9c63582946fbef98e8628", + "@tailwindcss/oxide-win32-arm64-msvc@npm:4.3.2": "68130dff13d07c88b5a59ca1b27acfde384d2c246db910c5a4f98e3fe5ab27ce538e4aca31aa70a68bd5e5a59b50a1875fe9908aeba7b394289c377089753053", + "@tailwindcss/oxide-win32-x64-msvc@npm:4.3.2": "0240e7ab3cb5418d5f655a1b356eb21819c56be193a469b8670a3a89b1f9e66c8cda3120849cffd57c8167ad0098d0e0cfc69ff24577111d5689711f7a13879b", + "@typescript/typescript-aix-ppc64@npm:7.0.2": "6135266f6e9c5928a8efd220b2ec972ecd6fa8c771dea432d2b8ffcec606aedd57b949db98ccb2a216e3fb87d4c6d42fd449258e0ee4cbda3d5994c69c5e84d2", + "@typescript/typescript-darwin-arm64@npm:7.0.2": "c859259821baf9d7a8c1811bc1d0c0cb67b0d7fa9f99f1a3b50aa0e656a2df35c6142f77a9d2b1cd200874fd33bc3bf7ffb5cb5491d57be8e0522319ee3453f8", + "@typescript/typescript-darwin-x64@npm:7.0.2": "4c689effd4a83b881b993903901f58d13aded3c61b2a9b6a0f8f591eeab595dbfab82930b1b2af3b1595829ead0e86c9278ea7b7f8fad47c8c76dd6b0e7fec4c", + "@typescript/typescript-freebsd-arm64@npm:7.0.2": "3339e5cbf127f689cdd977133f903e9549afbf1c85fd12d2b61944bc8cb9cca2c18f45070066476273cb8af992591e340e9b661cbbe62c5bd4882615c2a62892", + "@typescript/typescript-freebsd-x64@npm:7.0.2": "52b1180545def7206ac4a944b3a4bf38809b22b3816e9b0f553e87a4ecbf8e61a6039bb6bcc3a353ad0c16f90195e7ff86f25874ada409dcbbf4c4a587e40c2d", + "@typescript/typescript-linux-arm64@npm:7.0.2": "b3873b9c64ff950230eb1d087eb2f46f7102cbf0f483b5280cb76221626833a1065e4e4dfdd99777151d03c0abde157fde73b605829343a022f3fcc6862490dc", + "@typescript/typescript-linux-arm@npm:7.0.2": "ff6a5f61931a97dd4555c2055001c4720cd0c44e3f102ecb79998799cdf156f39884c87f096036c7a57a09a132b4b545b3830c0ca952292661170a7c10c7ae73", + "@typescript/typescript-linux-loong64@npm:7.0.2": "7cdf90b48bf0792e6cd6f9c151bbfd1963980e50f20e73f75c27fa210ba8de65c8b69092b1dd4c6db5d86396cbe8fb5473ca2986ad45be0afc42e7dc863e5ac6", + "@typescript/typescript-linux-mips64el@npm:7.0.2": "6c669e865878a186249631ac720126ea9a71637170cf14cf6d0aef3dfa0f496cdf8fc1a71db1ed24064b1aa612e9b902c64e53689995a0671e6b6146cc68d156", + "@typescript/typescript-linux-ppc64@npm:7.0.2": "702ac3a57ed2e9932185b2b6a3aaeb12d50152d78b453ced55f936d442d9fd7669a5c8a81c76b44ec60201f96533aa38ad2ca80f70ea8b3e6dcbc5cc4a200208", + "@typescript/typescript-linux-riscv64@npm:7.0.2": "ea92265112cf9320f09fcaef847c8612421cc0a907b50bbc8aa928de1a6306cdf7f4d0c1426c3e475923c99f490dc4469042b2edab3c2eff3afef8c14456650d", + "@typescript/typescript-linux-s390x@npm:7.0.2": "dc6b678125ee4c1b81a91c64076490ec985b84e9dde9c017fbc50ec34808aefe45bf90e04c57bf9d0146ea453d71cd1543ac7c47f7a7ef77635758317d0b2173", + "@typescript/typescript-linux-x64@npm:7.0.2": "93d1142b9099dce38f9f2b25a7c4800289c72699e93e695aba5a6923f3661720b336cdd437f4cb3d49324226b7288c606f24f32a85c8e4be5f97c523f5b27b0a", + "@typescript/typescript-netbsd-arm64@npm:7.0.2": "b3274f1c526a20f4436b0f1167dc0e60dac5606f31491429c61439519a3f6a68fcee3a3f7f26f2fafb6557d918af75795b37d2fb6ede7b857bab772eb529140d", + "@typescript/typescript-netbsd-x64@npm:7.0.2": "d3c15af4176791e21927d35afe4935c8a98d21509db7ecb4dd7769a02c2f983500ef6d0f1646ad614a59a748269d517604af98cbd7c3c0450bb57a12cccd7270", + "@typescript/typescript-openbsd-arm64@npm:7.0.2": "09feda2dcbe2e3f9d31f2e98b09477158da1bb9509fe42dda2ce0b12a33b43bd31bb0caee24c6bde4c735c9d33662bcf65593ee762a2a5fee225798b5d674692", + "@typescript/typescript-openbsd-x64@npm:7.0.2": "e29ffc0538c2843b1e731b90626b5d2855345627fbb6b2ad7ee40b8f88ed1df6f91b03cf5c227645c4fc35a18fb6ff1612de98a9b449da25042f66478e671875", + "@typescript/typescript-sunos-x64@npm:7.0.2": "1647e487c452504c646c01e9e4a504e41c180bc09c9af7ccd2a6db23b6fedad436861de2681674793baccbbfc8970dccc85fce59a4da3d802dd67966774fc188", + "@typescript/typescript-win32-arm64@npm:7.0.2": "26cf8934a58378a2e8467914407f2d06028ca0e211bd68403994f9b27353439d8b0935ebeb7b9a03d8768a64e444285f87756a77ce72211efeecf5239af52bc5", + "@typescript/typescript-win32-x64@npm:7.0.2": "7f8408c4b3a58a2ef8851103c0575b97654e34c5aa0658e32be5584030f395f8a8e8a7fa87eb3afe2c794a01a0eb2e77db743c6025af57ed2915605b8e0a7c82", "dmg-license@npm:1.0.11": "feef35cfb45270a72daadcca9584be5cb840f924448b9d4e543fcd61f1b6d471151049f277c91de1d8b003fad6203d0176066a5f427a01df5fb073402cb8c8b7", "iconv-corefoundation@npm:1.1.7": "bc6f08ac421e5e92ed20f3825f123fd705e036612b2b6aa687958de753c06f32e54f0203ef55540869e3ee189eaea15e43a2757f3a90e555c4dd512c9422da43", "lightningcss-android-arm64@npm:1.32.0": "1cb326ad39dcb02cf9f45025c167b6900e3a04b08f5149d3c5ee26054b00d08db3736fb69183a6c3ed1cb32dddd148608c784b6631b4777623f7dd0c032c392d", @@ -132,22 +177,22 @@ "lightningcss-linux-x64-musl@npm:1.32.0": "a6f48ccc30a73d30563c7b61856d1fd6a8812ce62b1bee797f227e06612df70aab4ccd1908552952f77ca7ff2a51019f62d14ae5310ca67311635eeec55d3a9e", "lightningcss-win32-arm64-msvc@npm:1.32.0": "a919be7fb298c1102bccf18b6f83d54946adfac70ab2ac9c95e4ae38ded76d8f530215b0bcda4d38df4ffc40a70abe3afd91d01d35fd122e7d119ed0e46972d0", "lightningcss-win32-x64-msvc@npm:1.32.0": "5b8d3431aadbdc40a0a7eae32f2415e4f28b547af1a1cd5b35a35d67f772a89492c7fa03e9fc88ce804b14f5f88e412e49fff40d1b0aad67177de815c434207e", - "sass-embedded-all-unknown@npm:1.98.0": "36a9126decd90bb1e7cdb6e5a6ec9913ca644e1ba16748b179daf0b78c87bab1905647b3e4221dcd6dfb8bed9211830ed853d4fab257057f1678a557b4982ec7", - "sass-embedded-android-arm64@npm:1.98.0": "83bcb98adb64adcf01d1bfd0d5726cd28942e3a276b1cf2b8ed426fcb6de4345539b9cde44b6cc3593fd7643f6ac4138ccc5107bccc195438fefe63140f0cecf", - "sass-embedded-android-arm@npm:1.98.0": "7083ddf06fb3685351cef3d95c78044d25b6798f6c9db2898d75ac6f61a140344d591888f8760445e952dfdb6610934b97edab3c323431edc49655ef47d3d3a8", - "sass-embedded-android-riscv64@npm:1.98.0": "dedb467cf1b72c100409268889131ac85f08b517c76ba1fff2a05d829c1f38e14acde11a3081b4ae7063c8a7ee0fda5cdd880cde0d43c3f5bb616419209eb85e", - "sass-embedded-android-x64@npm:1.98.0": "9030281251fa16600de1c90ab8a8995d022fbbb2c7d7a6447ee262f3b3fcd4cbe772c1c9067b7296b8dd6a3311ef5655246ca9c03051b838b978cced82515896", - "sass-embedded-darwin-arm64@npm:1.98.0": "0955f52140dbcd6cc2a35592cbe147e271f988a8d9e2807e28e3c4ba49e950e8d9fbbca00e2187c36530d28de2916e9e79f3ad9ec5c0f214449e3f3d10b15a1b", - "sass-embedded-darwin-x64@npm:1.98.0": "aba47e0c1b61a64f9e0a3899bb84725dfb2b45fb4b3a38e7c2e5d767d0b0ca429ce49dba98699298a2491f4ef2e2e40f2dd32905bf268ec4ef7acaa1ca3730da", - "sass-embedded-linux-arm64@npm:1.98.0": "766a5f93c80ba64f3f1733dbf01ee71e0f0a5a56bf75227f0455bd5151ec0348b85501fb4ee09da6393655638b4c34cfcff420ea96645fb25ba7e6afe5a1a1f9", - "sass-embedded-linux-arm@npm:1.98.0": "109131a0d1173f6b34c987192607d148721f980396f8288df29bd407dbc160142e088320ac95a63fdfda464a07953e6092f00a5d3f1e56540cf2553ad21e2b68", - "sass-embedded-linux-musl-arm64@npm:1.98.0": "bcddf4d567b1e335bb5bdad25469d773d3a965cf9c9972e8c43cf943016d010a79ea441df0c1f47a7c67e7330f4f88fc2d13d07d4fe720138f44e8837f660468", - "sass-embedded-linux-musl-arm@npm:1.98.0": "e1572282ac95d9b20afe7053c9415b21490aebb49d276838d256189387df3cc5804f6ba21794ad43dce0531e925f89722a5bea139f327bd51ff4bcf754a84589", - "sass-embedded-linux-musl-riscv64@npm:1.98.0": "6f0f51d3daac10c8a6ca79f0627304f191ab0db1e9dc120084c23231cc7c60929b51e75d64b6afb77abf5054cea89c2d0b129e40ed552489bfb1662a152017e9", - "sass-embedded-linux-musl-x64@npm:1.98.0": "51e55184d36b60a8777dd89f84354fbc4e0e5c09d8b0a2bd842138bb6a766c7e42bf7817cab5784416541a8e31c5a872121b24ec8d945768ced9e0074e648c1f", - "sass-embedded-linux-riscv64@npm:1.98.0": "6dc8669e8e23f8079a1d29073b8c3947314b4dae7c88db86b7dc6642a86e3aebf1a4f7cf38903423552aa9388fa4aef5c137f332aba5fa37b8447ca11640dcd4", - "sass-embedded-linux-x64@npm:1.98.0": "67dc506dd51e139173539008c07e2a7a397a3d47c7192039a3bc1c9af578a8c19c91fa03768851af653002b850098340e401de7af9041fafc7bb49162848e63b", - "sass-embedded-unknown-all@npm:1.98.0": "c6bc5bc3828d9091e7b669379f7248771ff0b5bae78c5f52d4cc193a387ef0ff30b7a7f17ccb576fcf18502134727a2433ebc5470f67f0b6f5cababdda52a9e4", - "sass-embedded-win32-arm64@npm:1.98.0": "b799485e7afb87d08901bbbb419217ae94e57c60a38ab1ffa74c0f521b1e5f77cb30769807a8403dc0ee27003fbaec402cec2add8ce8bc8d625f48c7afbd5a0d", - "sass-embedded-win32-x64@npm:1.98.0": "c8cb13fafca66b403e829c166ddb57fbecbe7433f515b90841ad49deeb6641b5f8db2238fcfb11a03df094f16ff7e63c0454f4ecdba314a7d7cf7408abfd3658" + "sass-embedded-all-unknown@npm:1.100.0": "ed802ec849fb09307294e942382bd19d72c79f53dd348db51fd431f18354876f50e47bef586a27fa1546fe68c1df638e05d9eace5925074b3e117419f1bd486f", + "sass-embedded-android-arm64@npm:1.100.0": "0a219201304c6e3b37e7099092730e978e1e77bb5ab1b0ecb84d72bb4f78b4703552d7f2937ba29250fa67032a23b0417e47ddbe497ce3abd8386d492fbcbdfb", + "sass-embedded-android-arm@npm:1.100.0": "460f04093b37d7bb0a2b6b689622e084795a0c0b820327ce57b7905e6495de777d669b6ac663bf728fb9f62c99e1ad3a6dfe7cc15aca5005037a217130aeac95", + "sass-embedded-android-riscv64@npm:1.100.0": "5b84b0b8a00197571f7d82977af81c0d88053cda91cc1c283f80821a4d8e45532fc8bc974b2c53a3ff869f49f60b2c8f412c90694fb9fa1e5f7396fb3ca7dc8a", + "sass-embedded-android-x64@npm:1.100.0": "d225b29000a7ff1e0aa2a64e5d60ee63679630eaf717311b20e972326ac31711928c2deb2f78d6a5ad2d3b9ef0bfa918d40940dea01e75232db7146624e66323", + "sass-embedded-darwin-arm64@npm:1.100.0": "ae3b9b1ef84b5cc53f2c364295070b8ef8fe7c8cbde6ea278d34d3fa0e1636168f13abe074155549587300c1c91d90d07b2fba25f1f765f62aa26729a0f2d37c", + "sass-embedded-darwin-x64@npm:1.100.0": "85b6aecb66dfe00a3600eac244b1611c04e608f42fc64720519d0996a5a59692b619176ea726647aa031b496c6a147b3f1b2dc8aef43c61c9cecec63bfe1d138", + "sass-embedded-linux-arm64@npm:1.100.0": "9ea709b02c24242bcbae8cc299913b1b28ea85c95c3a4a14b645b59f7cebe283c199b2e823edf8cb76255216c160c5642b0ff02d63cd9649ed2fc67aec900adf", + "sass-embedded-linux-arm@npm:1.100.0": "1f673e52323446f60d069182dc3488e957df3b7e4b17a6973c39bd1922d073521e665371a64d76f527287a0b1c3e47825b4252c51de0817d02c069c4b3839252", + "sass-embedded-linux-musl-arm64@npm:1.100.0": "f87777a45b855531b990c2969b2a7c8dae02b5a3e80e712e093b61632384db5c176cb776507f886791cc378b504e936da30e4bf97d105454ee7d520f662c25d9", + "sass-embedded-linux-musl-arm@npm:1.100.0": "66887ed9ce2f552942a463f2276c4d93dc2ef6ad55797507e667580f8b1911c5b471a941c3a1a999516fd4802cc833a4f39a738d2e65bb2a2d76172bc56f280b", + "sass-embedded-linux-musl-riscv64@npm:1.100.0": "ceb308bd10e2176e6885303e8f64a414eec5d6db4badf1517069c744fedc4fd05f0d34abae2f71dfa9db4b73b2269e7f1d793a600ff4610f165abda35b06c4a2", + "sass-embedded-linux-musl-x64@npm:1.100.0": "64b02ea419edea470f485b87631f065b891adca5cb555b3089c6922200dc2cd6982ff51dcdf2bd44cb7aa3b6e81590346f672f1f64481609734176536cce6e47", + "sass-embedded-linux-riscv64@npm:1.100.0": "9f443b08cf057d1577b5178608b2fa34963a614e9fe06b132d77065650536f1013dc567f8754e3d059f036e39a4f58013c512cb94bd7497ca839f5d5febce25d", + "sass-embedded-linux-x64@npm:1.100.0": "85307c181232f792bf6b7ed3c4849d043802d4b0a2988cf589efcbf83e4c49099f0a599084d08dea160723ff21a931c5f4cb4eded7d300765c77dd13efd7f1ea", + "sass-embedded-unknown-all@npm:1.100.0": "576eea8f7e866bc5aee12995e219f65c2ddc9da3c848950740c2568e1dd4433a782be6a8b6a87e1c9fb27a03e6e06982efa3da04df8a2dec8cdb685f72f56a63", + "sass-embedded-win32-arm64@npm:1.100.0": "bfd7231a5965a4f9c31cf9778c664a6917ead537742beeacb7042c4e7f40301cc305c409620643bfa255a31efec69bad637ae359e8573376891b41ba9f4eb450", + "sass-embedded-win32-x64@npm:1.100.0": "d78da6f82e616e5ecfc8221648029343320ac2cff8357152ecb582ab5ac5dbd20a838cce78d29a8c9986310e2a097c263dbab93c105affc5c009c71fdb1de5fc" } diff --git a/pkgs/by-name/bi/bitfocus-companion/package.nix b/pkgs/by-name/bi/bitfocus-companion/package.nix index d02ee3705a38..2b2a208dfa49 100644 --- a/pkgs/by-name/bi/bitfocus-companion/package.nix +++ b/pkgs/by-name/bi/bitfocus-companion/package.nix @@ -2,9 +2,8 @@ stdenv, lib, fetchFromGitHub, - substitute, fetchurl, - nodejs, + nodejs_26, git, python3, udev, @@ -21,8 +20,8 @@ let builtinSurfaces = { elgato-stream-deck = fetchurl { - url = "https://s4.bitfocus.io/developer-module-builds/surface/elgato-stream-deck/v1.4.3-70e2c01d15a0f58c52a8e80d7d6f4977f157d58e/elgato-stream-deck-v1.4.3.tgz"; - hash = "sha256-bZnXvkyfllzHZTAJtH/hSYIv+J5ZOYWZycUHdz9srGI="; + url = "https://s4.bitfocus.io/developer-module-builds/surface/elgato-stream-deck/v1.4.6-c7ea9961c73fc6bf184b563d03c64b5607312d8d/elgato-stream-deck-v1.4.6.tgz"; + hash = "sha256-0zYgn2ao2yhy3CSlHbdqfV9YWWwUiQ5kibDjT4uqOn8="; }; xkeys = fetchurl { url = "https://s4.bitfocus.io/developer-module-builds/surface/xkeys/v1.0.2-876f00ee194faa57ec14468b7019bbaa516a9e6d/xkeys-v1.0.2.tgz"; @@ -42,7 +41,7 @@ in stdenv.mkDerivation rec { pname = "bitfocus-companion"; - version = "4.3.4"; + version = "5.0.5"; __structuredAttrs = true; strictDeps = true; @@ -51,23 +50,7 @@ stdenv.mkDerivation rec { owner = "bitfocus"; repo = "companion"; tag = "v${version}"; - hash = "sha256-01zW6IrUgubxDSiGffGajZnWlssNsh8kO5FljVcjyL0="; - - # Remove when updating since upstream updated Yarn - # https://github.com/bitfocus/companion/commit/d2ad585c510f328f4bf111b7e489225925882354 - postFetch = '' - cd $out - patch -p1 < ${ - (substitute { - src = ./yarn-fix.patch; - substitutions = [ - "--replace-fail" - "YARN_LOCKFILE_VERSION_PLACEHOLDER" - yarn-berry.lockfileVersion - ]; - }) - } - ''; + hash = "sha256-Q5XQ/r4YYYqLk6YaSlBZqcqEH8nFmpqyzMf7/fMWX74="; }; passthru.updateScript = nix-update-script { }; @@ -76,15 +59,10 @@ stdenv.mkDerivation rec { # patch out git calls to generate version strings. substituteInPlace tools/lib.mts --replace-fail "return await fcn()" "return \"v${version}\" as unknown as T" - # remove unsupported yarn config options (npmMinimalAgeGate, npmPreapprovedPackages removed in newer yarn) - # approvedGitRepositories and compressionLevel required by yarn >= 4.14 for lockfile version < 9 - printf "nodeLinker: node-modules\nenableScripts: false\ncompressionLevel: 0\napprovedGitRepositories:\n - '**'\n" > .yarnrc.yml + # remove yarn config options which require network access at install time + printf "nodeLinker: node-modules\nenableScripts: false\n" > .yarnrc.yml # remove the yarn install during the build, since there is no internet connection, and everything has already been installed by yarnBerryConfigHook - substituteInPlace tools/build/dist.mts \ - --replace-fail 'await $`yarn --cwd node_modules/better-sqlite3 prebuild-install --arch=''${platformInfo.nodeArch} --platform=''${platformInfo.nodePlatform}`' "" \ - --replace-fail 'await $`yarn --cwd node_modules/better-sqlite3 prebuild-install`' "" - substituteInPlace tools/build/package.mts --replace-fail "await $\`yarn install --no-immutable\`" "" # remove node download, since we'll use the nix version @@ -93,11 +71,16 @@ stdenv.mkDerivation rec { --replace-fail "await fs.createSymlink(latestRuntimeDir, path.join(runtimesDir, 'main'), 'dir')" "" substituteInPlace companion/lib/Instance/NodePath.ts \ - --replace-fail "if (!(await fs.pathExists(nodePath))) return null" "return '${lib.getExe nodejs}'" \ + --replace-fail "if (!(await fs.pathExists(nodePath))) return null" "return '${lib.getExe nodejs_26}'" + + # allow all surface modules (builtin and user-downloaded) to find libudev, by adding + # LD_LIBRARY_PATH to the env whitelist companion uses when spawning module child processes + substituteInPlace companion/lib/Instance/Environment.ts \ + --replace-fail "'DISABLE_IPV6'," "'DISABLE_IPV6', 'LD_LIBRARY_PATH'," ''; nativeBuildInputs = [ - nodejs + nodejs_26 yarn-berry.yarnBerryConfigHook git python3 @@ -108,7 +91,7 @@ stdenv.mkDerivation rec { buildInputs = [ libusb1 dart-sass - nodejs + nodejs_26 electron udev ]; @@ -117,7 +100,7 @@ stdenv.mkDerivation rec { offlineCache = yarn-berry.fetchYarnBerryDeps { inherit src missingHashes; - hash = "sha256-LKIDfngn7Yia9oRwb8Ze0FOiZqreUMa6vuolqSz2hWo="; + hash = "sha256-Fuh/D3FVtm08h7pW+LHgrEiyN9vmCjy+WekfpIz/Xc4="; }; env = { @@ -157,20 +140,13 @@ stdenv.mkDerivation rec { rm -rf dist/node-runtimes ''; - postInstall = '' - # patch the env whitelist companion uses when spawning module child processes to include - # LD_LIBRARY_PATH, so all surface modules (builtin and user-downloaded) can find libudev - substituteInPlace $out/share/bitfocus-companion/dist/main.js \ - --replace-fail '"DISABLE_IPV6"],t={}' '"DISABLE_IPV6","LD_LIBRARY_PATH"],t={}' - ''; - installPhase = '' runHook preInstall mkdir -p $out/share/bitfocus-companion cp -r * $out/share/bitfocus-companion/ - makeWrapper ${lib.getExe nodejs} $out/bin/bitfocus-companion \ + makeWrapper ${lib.getExe nodejs_26} $out/bin/bitfocus-companion \ --add-flags $out/share/bitfocus-companion/dist/main.js \ --set LD_LIBRARY_PATH "${ lib.makeLibraryPath [ diff --git a/pkgs/by-name/bi/bitfocus-companion/yarn-fix.patch b/pkgs/by-name/bi/bitfocus-companion/yarn-fix.patch deleted file mode 100644 index d1667e6e319f..000000000000 --- a/pkgs/by-name/bi/bitfocus-companion/yarn-fix.patch +++ /dev/null @@ -1,11 +0,0 @@ -diff --git a/yarn.lock b/yarn.lock ---- a/yarn.lock -+++ b/yarn.lock -@@ -2,6 +2,6 @@ - # Manual changes might be lost - proceed with caution! - - __metadata: -- version: 8 -+ version: YARN_LOCKFILE_VERSION_PLACEHOLDER - cacheKey: 10c0 - From be981eb0186597fd2d52f4d53925439768d8e1fc Mon Sep 17 00:00:00 2001 From: Sergei Trofimovich Date: Mon, 7 Sep 2026 22:56:22 +0100 Subject: [PATCH 103/423] libheif: 1.23.3 -> 1.23.4 Changes: https://github.com/strukturag/libheif/releases/tag/v1.23.4 --- pkgs/by-name/li/libheif/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/li/libheif/package.nix b/pkgs/by-name/li/libheif/package.nix index edee50ffcab4..e8febed52bae 100644 --- a/pkgs/by-name/li/libheif/package.nix +++ b/pkgs/by-name/li/libheif/package.nix @@ -24,7 +24,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "libheif"; - version = "1.23.3"; + version = "1.23.4"; outputs = [ "bin" @@ -38,7 +38,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "strukturag"; repo = "libheif"; rev = "v${finalAttrs.version}"; - hash = "sha256-cFEEauwgMekd4/xUpyPGqpJh82W4LRyl6PdMvOFWoLA="; + hash = "sha256-bxN3YB/nKjrsHa/dM3sTAnWR+wOHk5a6ku6NF+8moQ0="; }; nativeBuildInputs = [ From 6d5884d31c62a22a4b529e41ea3da9788889cd24 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Tue, 8 Sep 2026 00:00:05 +0200 Subject: [PATCH 104/423] libpaper: enable strictDeps --- pkgs/by-name/li/libpaper/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/li/libpaper/package.nix b/pkgs/by-name/li/libpaper/package.nix index 71c6f5326aeb..025602807463 100644 --- a/pkgs/by-name/li/libpaper/package.nix +++ b/pkgs/by-name/li/libpaper/package.nix @@ -16,6 +16,8 @@ stdenv.mkDerivation (finalAttrs: { nativeBuildInputs = [ autoreconfHook ]; + strictDeps = true; + # The configure script of libpaper is buggy: it uses AC_SUBST on a headerfile # to compile sysconfdir into the library. Autoconf however defines sysconfdir # as "${prefix}/etc", which is not expanded by AC_SUBST so libpaper will look From f7bb6dd755f42a5e89b287d5cef7d713f4a9d550 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Tue, 8 Sep 2026 00:00:20 +0200 Subject: [PATCH 105/423] libpaper: enable structuredAttrs --- pkgs/by-name/li/libpaper/package.nix | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/by-name/li/libpaper/package.nix b/pkgs/by-name/li/libpaper/package.nix index 025602807463..08be8cc12196 100644 --- a/pkgs/by-name/li/libpaper/package.nix +++ b/pkgs/by-name/li/libpaper/package.nix @@ -23,11 +23,9 @@ stdenv.mkDerivation (finalAttrs: { # as "${prefix}/etc", which is not expanded by AC_SUBST so libpaper will look # for config files in (literally, without expansion) '${prefix}/etc'. Manually # setting sysconfdir fixes this issue. - preConfigure = '' - configureFlagsArray+=( - "--sysconfdir=$out/etc" - ) - ''; + configureFlags = [ + "--sysconfdir=${placeholder "out"}/etc" + ]; # Set the default paper to letter (this is what libpaper uses as default as well, # if you call getdefaultpapername()). @@ -37,6 +35,8 @@ stdenv.mkDerivation (finalAttrs: { echo letter > $out/etc/papersize ''; + __structuredAttrs = true; + meta = { changelog = "https://github.com/rrthomas/libpaper/releases/tag/v${finalAttrs.version}"; description = "Library for handling paper characteristics"; From b76aeb3d38deba3dfbfd79e4f078045dabad89ab Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Tue, 8 Sep 2026 00:09:03 +0200 Subject: [PATCH 106/423] ada: enable `structuredAttrs` --- pkgs/by-name/ad/ada/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/ad/ada/package.nix b/pkgs/by-name/ad/ada/package.nix index 4afbdecb59de..afe87ef939df 100644 --- a/pkgs/by-name/ad/ada/package.nix +++ b/pkgs/by-name/ad/ada/package.nix @@ -54,6 +54,8 @@ stdenv.mkDerivation (finalAttrs: { }; }; + __structuredAttrs = true; + meta = { description = "WHATWG-compliant and fast URL parser written in modern C"; homepage = "https://github.com/ada-url/ada"; From 1b3d9fa3af81b0c27d56077fcf2a5ea346e606e0 Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Tue, 8 Sep 2026 00:09:24 +0200 Subject: [PATCH 107/423] ada: enable `strictDeps` --- pkgs/by-name/ad/ada/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/ad/ada/package.nix b/pkgs/by-name/ad/ada/package.nix index afe87ef939df..1c1b459b94ed 100644 --- a/pkgs/by-name/ad/ada/package.nix +++ b/pkgs/by-name/ad/ada/package.nix @@ -23,6 +23,7 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-TvjoLUKO2+YgS1mlyglLb+rBLTO/SWSBVA2S34Z6kMI="; }; + strictDeps = true; nativeBuildInputs = [ cmake validatePkgConfig From 6fb5cdb9a3eaccf11de971f250b41d5e02e5276c Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Tue, 8 Sep 2026 00:09:36 +0200 Subject: [PATCH 108/423] ada: split in two outputs --- pkgs/by-name/ad/ada/package.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkgs/by-name/ad/ada/package.nix b/pkgs/by-name/ad/ada/package.nix index 1c1b459b94ed..1b94fac3cef7 100644 --- a/pkgs/by-name/ad/ada/package.nix +++ b/pkgs/by-name/ad/ada/package.nix @@ -23,6 +23,11 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-TvjoLUKO2+YgS1mlyglLb+rBLTO/SWSBVA2S34Z6kMI="; }; + outputs = [ + "out" + "dev" + ]; + strictDeps = true; nativeBuildInputs = [ cmake From 59391f774ddca746b6a4bdcab5cd8f81c598d299 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Tue, 8 Sep 2026 00:41:20 +0200 Subject: [PATCH 109/423] libsoup_3: enable strictDeps --- pkgs/by-name/li/libsoup_3/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/li/libsoup_3/package.nix b/pkgs/by-name/li/libsoup_3/package.nix index 30a203e84343..7e77196bd4c4 100644 --- a/pkgs/by-name/li/libsoup_3/package.nix +++ b/pkgs/by-name/li/libsoup_3/package.nix @@ -148,6 +148,8 @@ stdenv.mkDerivation rec { glib ]; + strictDeps = true; + mesonFlags = [ "-Dtls_check=false" # glib-networking is a runtime dependency, not a compile-time dependency "-Dgssapi=disabled" From 171d4b6f9872980543ffa963f351622002b2e58b Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Tue, 8 Sep 2026 00:41:48 +0200 Subject: [PATCH 110/423] libsoup_3: enable structuredAttrs --- pkgs/by-name/li/libsoup_3/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/li/libsoup_3/package.nix b/pkgs/by-name/li/libsoup_3/package.nix index 7e77196bd4c4..db43835562b1 100644 --- a/pkgs/by-name/li/libsoup_3/package.nix +++ b/pkgs/by-name/li/libsoup_3/package.nix @@ -189,6 +189,8 @@ stdenv.mkDerivation rec { }; }; + __structuredAttrs = true; + meta = { description = "HTTP client/server library for GNOME"; homepage = "https://gitlab.gnome.org/GNOME/libsoup"; From bd30f1ebbf22a1ad8c1f06aea3428989b1816c15 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Tue, 8 Sep 2026 00:41:58 +0200 Subject: [PATCH 111/423] libsoup_3: modernize --- pkgs/by-name/li/libsoup_3/package.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/li/libsoup_3/package.nix b/pkgs/by-name/li/libsoup_3/package.nix index db43835562b1..872dfff315aa 100644 --- a/pkgs/by-name/li/libsoup_3/package.nix +++ b/pkgs/by-name/li/libsoup_3/package.nix @@ -23,7 +23,7 @@ libnghttp2, }: -stdenv.mkDerivation rec { +stdenv.mkDerivation (finalAttrs: { pname = "libsoup"; version = "3.6.6"; @@ -34,7 +34,7 @@ stdenv.mkDerivation rec { ++ lib.optional withIntrospection "devdoc"; src = fetchurl { - url = "mirror://gnome/sources/${pname}/${lib.versions.majorMinor version}/${pname}-${version}.tar.xz"; + url = "mirror://gnome/sources/libsoup/${lib.versions.majorMinor finalAttrs.version}/libsoup-${finalAttrs.version}.tar.xz"; hash = "sha256-Ue0K4G+dWkD0Af9Fni5fZS+aUQt3MOE1nuZtFNSHJ0A="; }; @@ -195,7 +195,7 @@ stdenv.mkDerivation rec { description = "HTTP client/server library for GNOME"; homepage = "https://gitlab.gnome.org/GNOME/libsoup"; license = lib.licenses.lgpl2Plus; - changelog = "https://gitlab.gnome.org/GNOME/libsoup/-/blob/${version}/NEWS"; + changelog = "https://gitlab.gnome.org/GNOME/libsoup/-/blob/${finalAttrs.version}/NEWS"; inherit (glib.meta) maintainers platforms teams; }; -} +}) From a086377e58251f336df3473d7456960e99f12652 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Tue, 8 Sep 2026 00:48:13 +0200 Subject: [PATCH 112/423] libmad: enable strictDeps --- pkgs/by-name/li/libmad/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/li/libmad/package.nix b/pkgs/by-name/li/libmad/package.nix index e2f1cf59cc2e..5daac1a367f8 100644 --- a/pkgs/by-name/li/libmad/package.nix +++ b/pkgs/by-name/li/libmad/package.nix @@ -70,6 +70,8 @@ stdenv.mkDerivation (finalAttrs: { nativeBuildInputs = [ autoconf ]; + strictDeps = true; + preConfigure = "autoconf"; passthru.tests = { From c34953c17f4c0979cf7acce8ce6f22af049880fe Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Tue, 8 Sep 2026 00:48:10 +0200 Subject: [PATCH 113/423] simdjson: split in multiple outputs --- pkgs/by-name/si/simdjson/package.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkgs/by-name/si/simdjson/package.nix b/pkgs/by-name/si/simdjson/package.nix index 8695dcb4c665..2763d1d331bf 100644 --- a/pkgs/by-name/si/simdjson/package.nix +++ b/pkgs/by-name/si/simdjson/package.nix @@ -18,6 +18,11 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-ZMYYjwyeqqlklwY4UWBgT5sJ0Ojkg38Xcxg6CO461Ec="; }; + outputs = [ + "out" + "dev" + ]; + nativeBuildInputs = [ cmake ]; cmakeFlags = [ From 437e4699e0c4f437e9897c8c9902778ef534407d Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Tue, 8 Sep 2026 00:48:41 +0200 Subject: [PATCH 114/423] libmad: enable structuredAttrs --- pkgs/by-name/li/libmad/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/li/libmad/package.nix b/pkgs/by-name/li/libmad/package.nix index 5daac1a367f8..e2054f281db0 100644 --- a/pkgs/by-name/li/libmad/package.nix +++ b/pkgs/by-name/li/libmad/package.nix @@ -85,6 +85,8 @@ stdenv.mkDerivation (finalAttrs: { ocaml-mad = ocamlPackages.mad; }; + __structuredAttrs = true; + meta = { homepage = "https://sourceforge.net/projects/mad/"; description = "High-quality, fixed-point MPEG audio decoder supporting MPEG-1 and MPEG-2"; From 6c3c849e117639aa38cfac3ba646edac53612d33 Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Tue, 8 Sep 2026 00:50:57 +0200 Subject: [PATCH 115/423] simdutf: split in multiple outputs --- pkgs/by-name/si/simdutf/package.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkgs/by-name/si/simdutf/package.nix b/pkgs/by-name/si/simdutf/package.nix index 6157622c3450..6e8bc1c87d9e 100644 --- a/pkgs/by-name/si/simdutf/package.nix +++ b/pkgs/by-name/si/simdutf/package.nix @@ -21,6 +21,11 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-PKL495sfkRKjHfN4RroW1dwudJV2JWN7ogB8hyDxj5Y="; }; + outputs = [ + "out" + "dev" + ]; + # https://github.com/simdutf/simdutf/issues/1032 # FIXME: remove in next release patches = lib.optionals stdenv.hostPlatform.isLoongArch64 [ From 24e4fd53413b4bc1a3294da4d1a7d66af9614452 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 8 Sep 2026 01:02:28 +0000 Subject: [PATCH 116/423] cryptsetup: 2.8.7 -> 2.8.8 --- pkgs/by-name/cr/cryptsetup/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/cr/cryptsetup/package.nix b/pkgs/by-name/cr/cryptsetup/package.nix index 0ff0e32e1742..3cb9df938375 100644 --- a/pkgs/by-name/cr/cryptsetup/package.nix +++ b/pkgs/by-name/cr/cryptsetup/package.nix @@ -25,7 +25,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "cryptsetup"; - version = "2.8.7"; + version = "2.8.8"; outputs = [ "bin" @@ -39,7 +39,7 @@ stdenv.mkDerivation (finalAttrs: { url = "mirror://kernel/linux/utils/cryptsetup/v${lib.versions.majorMinor finalAttrs.version}/" + "cryptsetup-${finalAttrs.version}.tar.xz"; - hash = "sha256-53bw04HobKYQQsRXBpSR/o4KwoZ4DHw7Hk+ZIavJYdo="; + hash = "sha256-Os+mhfLdf8yDLgt3vHCTqn2lVKUc6Nr7tBOOqoVO7jU="; }; patches = [ From 2906d09f241ca75ca37f4f72ac41c83d40a8fee0 Mon Sep 17 00:00:00 2001 From: Weijia Wang <9713184+wegank@users.noreply.github.com> Date: Tue, 8 Sep 2026 18:12:36 +0200 Subject: [PATCH 117/423] simdutf: 9.1.0 -> 9.1.1 --- pkgs/by-name/si/simdutf/package.nix | 14 ++------------ 1 file changed, 2 insertions(+), 12 deletions(-) diff --git a/pkgs/by-name/si/simdutf/package.nix b/pkgs/by-name/si/simdutf/package.nix index 6350a7902af0..da23a40d43db 100644 --- a/pkgs/by-name/si/simdutf/package.nix +++ b/pkgs/by-name/si/simdutf/package.nix @@ -2,7 +2,6 @@ lib, stdenv, fetchFromGitHub, - fetchpatch2, cmake, libiconv, nix-update-script, @@ -12,13 +11,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "simdutf"; - version = "9.1.0"; + version = "9.1.1"; src = fetchFromGitHub { owner = "simdutf"; repo = "simdutf"; tag = "v${finalAttrs.version}"; - hash = "sha256-PKL495sfkRKjHfN4RroW1dwudJV2JWN7ogB8hyDxj5Y="; + hash = "sha256-u0Ur/o2TRLqYisS7xQHBxN/742BzmbElNUeqgEzpw/I="; }; outputs = [ @@ -26,15 +25,6 @@ stdenv.mkDerivation (finalAttrs: { "dev" ]; - # https://github.com/simdutf/simdutf/issues/1032 - # FIXME: remove in next release - patches = lib.optionals (stdenv.hostPlatform.isLoongArch64 && finalAttrs.version == "9.1.0") [ - (fetchpatch2 { - url = "https://github.com/simdutf/simdutf/commit/1f8ef080486c31cbd70db21a05a008700eb03aae.patch?full_index=1"; - hash = "sha256-p1qJFUQ4KhSSLSBIiC9se/TxrWFqywdVKNgh78TkMyE="; - }) - ]; - cmakeFlags = [ (lib.cmakeBool "BUILD_SHARED_LIBS" (!stdenv.hostPlatform.isStatic)) From c50450401156ae9d5d8afc2e0c726472dc4c9447 Mon Sep 17 00:00:00 2001 From: whoomee Date: Tue, 8 Sep 2026 18:26:49 +0200 Subject: [PATCH 118/423] libnice: 0.1.23 -> 0.1.24 --- pkgs/by-name/li/libnice/package.nix | 11 ++--------- 1 file changed, 2 insertions(+), 9 deletions(-) diff --git a/pkgs/by-name/li/libnice/package.nix b/pkgs/by-name/li/libnice/package.nix index 5a0590c209f5..663b0b07d080 100644 --- a/pkgs/by-name/li/libnice/package.nix +++ b/pkgs/by-name/li/libnice/package.nix @@ -3,7 +3,6 @@ stdenv, testers, fetchFromGitLab, - fetchpatch, nix-update-script, meson, ninja, @@ -27,7 +26,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "libnice"; - version = "0.1.23"; + version = "0.1.24"; outputs = [ "bin" @@ -41,7 +40,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "libnice"; repo = "libnice"; tag = finalAttrs.version; - hash = "sha256-UPppE5kBois0jJwsHKefBC8iTfSIkPZXV6XnUBnEFn8="; + hash = "sha256-7y+yTf/kp4uy9LZCbcMisA1892csBjdXQU5mOVnrxRY="; }; patches = [ @@ -51,12 +50,6 @@ stdenv.mkDerivation (finalAttrs: { ] # TODO: investigate what's wrong ++ lib.optionals (!stdenv.hostPlatform.isDarwin) [ - (fetchpatch { - name = "freebsd.patch"; - url = "https://gitlab.freedesktop.org/libnice/libnice/-/commit/479f0813a571ff035bf00de679db452a0441125b.patch"; - hash = "sha256-rr8pAb8TjU85jYWUjsMMKkLxxXVE3B+IjfAyOw9suo0="; - }) - # https://gitlab.freedesktop.org/libnice/libnice/-/merge_requests/353 ./musl.patch ]; From d3aad09b0f52b59e0d4187dc277712cd4c80b43a Mon Sep 17 00:00:00 2001 From: whoomee Date: Tue, 8 Sep 2026 20:23:50 +0200 Subject: [PATCH 119/423] gstreamer: 1.28.6 -> 1.28.7 --- pkgs/development/libraries/gstreamer/bad/default.nix | 4 ++-- pkgs/development/libraries/gstreamer/base/default.nix | 4 ++-- pkgs/development/libraries/gstreamer/core/default.nix | 4 ++-- pkgs/development/libraries/gstreamer/devtools/default.nix | 4 ++-- pkgs/development/libraries/gstreamer/ges/default.nix | 4 ++-- pkgs/development/libraries/gstreamer/good/default.nix | 4 ++-- pkgs/development/libraries/gstreamer/libav/default.nix | 4 ++-- pkgs/development/libraries/gstreamer/rtsp-server/default.nix | 4 ++-- pkgs/development/libraries/gstreamer/ugly/default.nix | 4 ++-- 9 files changed, 18 insertions(+), 18 deletions(-) diff --git a/pkgs/development/libraries/gstreamer/bad/default.nix b/pkgs/development/libraries/gstreamer/bad/default.nix index d91572296421..f38f309e6f58 100644 --- a/pkgs/development/libraries/gstreamer/bad/default.nix +++ b/pkgs/development/libraries/gstreamer/bad/default.nix @@ -116,7 +116,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "gst-plugins-bad"; - version = "1.28.6"; + version = "1.28.7"; outputs = [ "out" @@ -125,7 +125,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "https://gstreamer.freedesktop.org/src/gst-plugins-bad/gst-plugins-bad-${finalAttrs.version}.tar.xz"; - hash = "sha256-Zjbywiic7aUsSrqXEzjIHitXgNM4G9NnPBwRbsh1h8M="; + hash = "sha256-3FJTg8GLLCZbvmpD1JhlbNkYqqEwqk46vqvNqnQcP/4="; }; patches = [ diff --git a/pkgs/development/libraries/gstreamer/base/default.nix b/pkgs/development/libraries/gstreamer/base/default.nix index 087c8c50b3d1..9ec79ac45baa 100644 --- a/pkgs/development/libraries/gstreamer/base/default.nix +++ b/pkgs/development/libraries/gstreamer/base/default.nix @@ -50,7 +50,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "gst-plugins-base"; - version = "1.28.6"; + version = "1.28.7"; outputs = [ "out" @@ -61,7 +61,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "https://gstreamer.freedesktop.org/src/gst-plugins-base/gst-plugins-base-${finalAttrs.version}.tar.xz"; - hash = "sha256-C6aZx8bGb0umQL54yziiRxWt2Wg/PjoZn1Np3FpPBKw="; + hash = "sha256-7W5UEPSW0XGBh2OvImXnl3FUvH+bgn6YrPjFvtId1ac="; }; __structuredAttrs = true; diff --git a/pkgs/development/libraries/gstreamer/core/default.nix b/pkgs/development/libraries/gstreamer/core/default.nix index 0c959452333b..4daef59d417b 100644 --- a/pkgs/development/libraries/gstreamer/core/default.nix +++ b/pkgs/development/libraries/gstreamer/core/default.nix @@ -40,7 +40,7 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "gstreamer"; - version = "1.28.6"; + version = "1.28.7"; outputs = [ "bin" @@ -52,7 +52,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "https://gstreamer.freedesktop.org/src/gstreamer/gstreamer-${finalAttrs.version}.tar.xz"; - hash = "sha256-Yra58K0xR6bdZCCsZKkRgLFOmQaVvd01O5YEFhHQUso="; + hash = "sha256-eHMpssV1jiKKcdkmptz5YLzqrMo8rdY4dLpmXfzaAT4="; }; depsBuildBuild = [ diff --git a/pkgs/development/libraries/gstreamer/devtools/default.nix b/pkgs/development/libraries/gstreamer/devtools/default.nix index 12eafbc7e91a..d05888dac788 100644 --- a/pkgs/development/libraries/gstreamer/devtools/default.nix +++ b/pkgs/development/libraries/gstreamer/devtools/default.nix @@ -27,7 +27,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "gst-devtools"; - version = "1.28.6"; + version = "1.28.7"; outputs = [ "out" @@ -36,7 +36,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "https://gstreamer.freedesktop.org/src/gst-devtools/gst-devtools-${finalAttrs.version}.tar.xz"; - hash = "sha256-FNQfquA2GSUflZWdPVe/ZcYQaDiztUIY3JXHE14euhM="; + hash = "sha256-nzo4nWp++loY11ZHJKfzscP67P/Lj9E1HtDoEdGHOtU="; }; cargoDeps = rustPlatform.fetchCargoVendor { diff --git a/pkgs/development/libraries/gstreamer/ges/default.nix b/pkgs/development/libraries/gstreamer/ges/default.nix index 0bef33df0348..e827b33f2576 100644 --- a/pkgs/development/libraries/gstreamer/ges/default.nix +++ b/pkgs/development/libraries/gstreamer/ges/default.nix @@ -23,7 +23,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "gst-editing-services"; - version = "1.28.6"; + version = "1.28.7"; outputs = [ "out" @@ -32,7 +32,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "https://gstreamer.freedesktop.org/src/gst-editing-services/gst-editing-services-${finalAttrs.version}.tar.xz"; - hash = "sha256-PRUeUJfWhsWJCudvFMV+4ZU4/WHGz2NxcfkLMJyv1Tw="; + hash = "sha256-b/wOXM7JCq1gkdP8Aa0px5Y3UFXhO5N4r/a44cIkaKM="; }; separateDebugInfo = true; diff --git a/pkgs/development/libraries/gstreamer/good/default.nix b/pkgs/development/libraries/gstreamer/good/default.nix index 00b47201a47e..05373b788ba9 100644 --- a/pkgs/development/libraries/gstreamer/good/default.nix +++ b/pkgs/development/libraries/gstreamer/good/default.nix @@ -79,7 +79,7 @@ assert raspiCameraSupport -> hostSupportsRaspiCamera; stdenv.mkDerivation (finalAttrs: { pname = "gst-plugins-good"; - version = "1.28.6"; + version = "1.28.7"; outputs = [ "out" @@ -88,7 +88,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "https://gstreamer.freedesktop.org/src/gst-plugins-good/gst-plugins-good-${finalAttrs.version}.tar.xz"; - hash = "sha256-sMYgpLGLbukxtMQ7vxdg0whmbcN/cwp+fxrTJ+Wc4t8="; + hash = "sha256-hyVpacgs87yFdDAfPnBEqQ3grFAKWifYujjE3eiU3Ys="; }; patches = [ diff --git a/pkgs/development/libraries/gstreamer/libav/default.nix b/pkgs/development/libraries/gstreamer/libav/default.nix index 6dc5f3abd6e4..953623630d36 100644 --- a/pkgs/development/libraries/gstreamer/libav/default.nix +++ b/pkgs/development/libraries/gstreamer/libav/default.nix @@ -19,11 +19,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "gst-libav"; - version = "1.28.6"; + version = "1.28.7"; src = fetchurl { url = "https://gstreamer.freedesktop.org/src/gst-libav/gst-libav-${finalAttrs.version}.tar.xz"; - hash = "sha256-cebq+0//KmbRuwuo0HgiTf5+M5cwfYwLuj3CNgbgj1E="; + hash = "sha256-WNpR3Tns8c9vqt40zGQSABvi4uFFvKiuD0Uzb2CjarI="; }; separateDebugInfo = true; diff --git a/pkgs/development/libraries/gstreamer/rtsp-server/default.nix b/pkgs/development/libraries/gstreamer/rtsp-server/default.nix index 742fbc362821..ff7f3c4c0390 100644 --- a/pkgs/development/libraries/gstreamer/rtsp-server/default.nix +++ b/pkgs/development/libraries/gstreamer/rtsp-server/default.nix @@ -19,7 +19,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "gst-rtsp-server"; - version = "1.28.6"; + version = "1.28.7"; outputs = [ "out" @@ -28,7 +28,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "https://gstreamer.freedesktop.org/src/gst-rtsp-server/gst-rtsp-server-${finalAttrs.version}.tar.xz"; - hash = "sha256-DLclsTUfdeiIA8Vd3eofJ74JUj3c1/KasYJw4YKipGM="; + hash = "sha256-3kOlmgyJoU6xwUro6B5bRcTp17H5MLDrqtNg+bXgtcQ="; }; separateDebugInfo = true; diff --git a/pkgs/development/libraries/gstreamer/ugly/default.nix b/pkgs/development/libraries/gstreamer/ugly/default.nix index 4ad03256c94e..eb49d2bf1cf1 100644 --- a/pkgs/development/libraries/gstreamer/ugly/default.nix +++ b/pkgs/development/libraries/gstreamer/ugly/default.nix @@ -27,7 +27,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "gst-plugins-ugly"; - version = "1.28.6"; + version = "1.28.7"; outputs = [ "out" @@ -36,7 +36,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "https://gstreamer.freedesktop.org/src/gst-plugins-ugly/gst-plugins-ugly-${finalAttrs.version}.tar.xz"; - hash = "sha256-7iedoTp0D9fwYNYxpnMiP6O8yMM9NQyNAmS9Myok7Ng="; + hash = "sha256-K2gRcN3CK2soPK/u1I9CfDChcFaXSmqe0TfDVOD3cww="; }; separateDebugInfo = true; From 594199fa6d2a41770c717007f1f286d8f2873a9e Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 8 Sep 2026 18:43:03 +0000 Subject: [PATCH 120/423] ucc: 1.8.0 -> 1.9.0 --- pkgs/by-name/uc/ucc/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/uc/ucc/package.nix b/pkgs/by-name/uc/ucc/package.nix index ebc88215053a..4e55618df4b3 100644 --- a/pkgs/by-name/uc/ucc/package.nix +++ b/pkgs/by-name/uc/ucc/package.nix @@ -40,13 +40,13 @@ effectiveStdenv.mkDerivation (finalAttrs: { strictDeps = true; pname = "ucc"; - version = "1.8.0"; + version = "1.9.0"; src = fetchFromGitHub { owner = "openucx"; repo = "ucc"; tag = "v${finalAttrs.version}"; - hash = "sha256-rH/bG0pYO4VKfrnkXLXy/67hjaz6i3R0YoYdsGBqPsU="; + hash = "sha256-UiVbvT/9lWlfAcxXynzcVNjV5tLn6GRFqg2/SwcEQSg="; }; outputs = [ From c0e8f0697b4ca5bd6dab38cbb0bf6b923367b235 Mon Sep 17 00:00:00 2001 From: Tom Hunze Date: Sat, 29 Aug 2026 00:07:27 +0200 Subject: [PATCH 121/423] glibmm: rename to glibmm_2_4 Having the older ABI version as the default seems odd and the different glibmm packages appear to be fundamentally incompatible, so drop the unsuffixed version similar to webkitgtk and as discussed in [1]. [1] https://github.com/NixOS/nixpkgs/pull/543345#issuecomment-5199018730 --- pkgs/applications/graphics/inkscape/default.nix | 4 ++-- .../pidgin/pidgin-plugins/purple-mm-sms/default.nix | 4 ++-- pkgs/by-name/ar/ardour/package.nix | 4 ++-- pkgs/by-name/ar/ardour_8/package.nix | 4 ++-- pkgs/by-name/at/atkmm/package.nix | 4 ++-- pkgs/by-name/ca/cadabra2/package.nix | 4 ++-- pkgs/by-name/ch/chatty/package.nix | 4 ++-- pkgs/by-name/ff/ffado/package.nix | 4 ++-- pkgs/by-name/gl/{glibmm => glibmm_2_4}/package.nix | 1 + pkgs/by-name/gt/gtkmm3/package.nix | 4 ++-- pkgs/by-name/gt/gtksourceviewmm/package.nix | 4 ++-- pkgs/by-name/gt/gtksourceviewmm4/package.nix | 4 ++-- pkgs/by-name/gt/gtkspellmm/package.nix | 4 ++-- pkgs/by-name/gu/guitarix-vst/package.nix | 4 ++-- pkgs/by-name/gu/guitarix/package.nix | 4 ++-- pkgs/by-name/ja/jamesdsp/package.nix | 4 ++-- pkgs/by-name/li/libgdamm/package.nix | 4 ++-- pkgs/by-name/li/libsigrok-sipeed/package.nix | 4 ++-- pkgs/by-name/li/libsigrok/package.nix | 4 ++-- pkgs/by-name/li/libxmlxx5/package.nix | 4 ++-- pkgs/by-name/li/lightspark/package.nix | 4 ++-- pkgs/by-name/li/linthesia/package.nix | 4 ++-- pkgs/by-name/pa/paprefs/package.nix | 4 ++-- pkgs/by-name/pe/performous/package.nix | 4 ++-- pkgs/by-name/po/powermode-indicator/package.nix | 4 ++-- pkgs/by-name/pu/pulseeffects-legacy/package.nix | 4 ++-- pkgs/by-name/pu/pulseview/package.nix | 4 ++-- pkgs/by-name/ra/radiotray-ng/package.nix | 4 ++-- pkgs/by-name/rh/rhvoice/package.nix | 4 ++-- pkgs/by-name/sm/smuview/package.nix | 4 ++-- pkgs/by-name/sy/synfigstudio/package.nix | 6 +++--- pkgs/by-name/sy/syshud/package.nix | 4 ++-- pkgs/by-name/wo/workrave/package.nix | 4 ++-- .../development/libraries/gstreamer/gstreamermm/default.nix | 4 ++-- pkgs/development/libraries/libxmlxx/default.nix | 4 ++-- pkgs/development/libraries/libxmlxx/v3.nix | 4 ++-- pkgs/development/libraries/pangomm/2.42.nix | 4 ++-- pkgs/development/libraries/pangomm/default.nix | 4 ++-- pkgs/top-level/aliases.nix | 1 + 39 files changed, 77 insertions(+), 75 deletions(-) rename pkgs/by-name/gl/{glibmm => glibmm_2_4}/package.nix (97%) diff --git a/pkgs/applications/graphics/inkscape/default.nix b/pkgs/applications/graphics/inkscape/default.nix index ccea323f700b..ea217e686e2b 100644 --- a/pkgs/applications/graphics/inkscape/default.nix +++ b/pkgs/applications/graphics/inkscape/default.nix @@ -13,7 +13,7 @@ gettext, ghostscript, glib, - glibmm, + glibmm_2_4, gobject-introspection, gsl, gspell, @@ -153,7 +153,7 @@ stdenv.mkDerivation (finalAttrs: { boost gettext glib - glibmm + glibmm_2_4 gsl gtkmm3 gtksourceview4 diff --git a/pkgs/applications/networking/instant-messengers/pidgin/pidgin-plugins/purple-mm-sms/default.nix b/pkgs/applications/networking/instant-messengers/pidgin/pidgin-plugins/purple-mm-sms/default.nix index 28dd496ffdce..460b5a0963e8 100644 --- a/pkgs/applications/networking/instant-messengers/pidgin/pidgin-plugins/purple-mm-sms/default.nix +++ b/pkgs/applications/networking/instant-messengers/pidgin/pidgin-plugins/purple-mm-sms/default.nix @@ -1,7 +1,7 @@ { lib, stdenv, - glibmm, + glibmm_2_4, pidgin, pkg-config, modemmanager, @@ -27,7 +27,7 @@ stdenv.mkDerivation rec { nativeBuildInputs = [ pkg-config ]; buildInputs = [ - glibmm + glibmm_2_4 pidgin modemmanager ]; diff --git a/pkgs/by-name/ar/ardour/package.nix b/pkgs/by-name/ar/ardour/package.nix index 727bbfb74f85..6c959449fc11 100644 --- a/pkgs/by-name/ar/ardour/package.nix +++ b/pkgs/by-name/ar/ardour/package.nix @@ -21,7 +21,7 @@ flac, fluidsynth, glibc, - glibmm, + glibmm_2_4, graphviz, harvid, hidapi, @@ -142,7 +142,7 @@ let fftwSinglePrec flac fluidsynth - glibmm + glibmm_2_4 hidapi itstool kissfft diff --git a/pkgs/by-name/ar/ardour_8/package.nix b/pkgs/by-name/ar/ardour_8/package.nix index c2d57cfcdd91..f673a096dab8 100644 --- a/pkgs/by-name/ar/ardour_8/package.nix +++ b/pkgs/by-name/ar/ardour_8/package.nix @@ -17,7 +17,7 @@ flac, fluidsynth, glibc, - glibmm, + glibmm_2_4, graphviz, harvid, hidapi, @@ -129,7 +129,7 @@ stdenv.mkDerivation ( fftwSinglePrec flac fluidsynth - glibmm + glibmm_2_4 hidapi itstool kissfft diff --git a/pkgs/by-name/at/atkmm/package.nix b/pkgs/by-name/at/atkmm/package.nix index 40929610a2ce..b2eff2bbbde9 100644 --- a/pkgs/by-name/at/atkmm/package.nix +++ b/pkgs/by-name/at/atkmm/package.nix @@ -3,7 +3,7 @@ stdenv, fetchurl, atk, - glibmm, + glibmm_2_4, pkg-config, gnome, meson, @@ -27,7 +27,7 @@ stdenv.mkDerivation (finalAttrs: { propagatedBuildInputs = [ atk - glibmm + glibmm_2_4 ]; nativeBuildInputs = [ diff --git a/pkgs/by-name/ca/cadabra2/package.nix b/pkgs/by-name/ca/cadabra2/package.nix index d083edc8de9d..a3cc590a36d1 100644 --- a/pkgs/by-name/ca/cadabra2/package.nix +++ b/pkgs/by-name/ca/cadabra2/package.nix @@ -10,7 +10,7 @@ nix-update-script, boost, - glibmm, + glibmm_2_4, gmpxx, gtkmm3, jsoncpp, @@ -81,7 +81,7 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ boost - glibmm + glibmm_2_4 gmpxx jsoncpp onetbb diff --git a/pkgs/by-name/ch/chatty/package.nix b/pkgs/by-name/ch/chatty/package.nix index 2b8c04700662..ef4893c0edb4 100644 --- a/pkgs/by-name/ch/chatty/package.nix +++ b/pkgs/by-name/ch/chatty/package.nix @@ -11,7 +11,7 @@ wrapGAppsHook4, evolution-data-server, feedbackd, - glibmm, + glibmm_2_4, libsecret, gnome-desktop, gspell, @@ -53,7 +53,7 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ evolution-data-server feedbackd - glibmm + glibmm_2_4 libsecret gnome-desktop gspell diff --git a/pkgs/by-name/ff/ffado/package.nix b/pkgs/by-name/ff/ffado/package.nix index 0258e15639d6..64842a377e6e 100644 --- a/pkgs/by-name/ff/ffado/package.nix +++ b/pkgs/by-name/ff/ffado/package.nix @@ -5,7 +5,7 @@ dbus, dbus_cplusplus, fetchurl, - glibmm, + glibmm_2_4, libavc1394, libconfig, libiec61883, @@ -98,7 +98,7 @@ stdenv.mkDerivation rec { buildInputs = [ dbus dbus_cplusplus - glibmm + glibmm_2_4 libavc1394 libconfig libiec61883 diff --git a/pkgs/by-name/gl/glibmm/package.nix b/pkgs/by-name/gl/glibmm_2_4/package.nix similarity index 97% rename from pkgs/by-name/gl/glibmm/package.nix rename to pkgs/by-name/gl/glibmm_2_4/package.nix index d5c50259eddb..3a564605f7fa 100644 --- a/pkgs/by-name/gl/glibmm/package.nix +++ b/pkgs/by-name/gl/glibmm_2_4/package.nix @@ -42,6 +42,7 @@ stdenv.mkDerivation (finalAttrs: { passthru = { updateScript = gnome.updateScript { packageName = "glibmm"; + attrPath = "glibmm_2_4"; versionPolicy = "odd-unstable"; freeze = true; }; diff --git a/pkgs/by-name/gt/gtkmm3/package.nix b/pkgs/by-name/gt/gtkmm3/package.nix index e753218ed3a3..da4d45b84b79 100644 --- a/pkgs/by-name/gt/gtkmm3/package.nix +++ b/pkgs/by-name/gt/gtkmm3/package.nix @@ -7,7 +7,7 @@ ninja, python3, gtk3, - glibmm, + glibmm_2_4, cairomm_1_0, pangomm, atkmm, @@ -42,7 +42,7 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ libepoxy ]; propagatedBuildInputs = [ - glibmm + glibmm_2_4 gtk3 atkmm cairomm_1_0 diff --git a/pkgs/by-name/gt/gtksourceviewmm/package.nix b/pkgs/by-name/gt/gtksourceviewmm/package.nix index 01909520007a..09337fb3c6f7 100644 --- a/pkgs/by-name/gt/gtksourceviewmm/package.nix +++ b/pkgs/by-name/gt/gtksourceviewmm/package.nix @@ -4,7 +4,7 @@ fetchurl, pkg-config, gtkmm3, - glibmm, + glibmm_2_4, gtksourceview3, gnome, }: @@ -28,7 +28,7 @@ stdenv.mkDerivation (finalAttrs: { nativeBuildInputs = [ pkg-config ]; buildInputs = [ - glibmm + glibmm_2_4 gtkmm3 gtksourceview3 ]; diff --git a/pkgs/by-name/gt/gtksourceviewmm4/package.nix b/pkgs/by-name/gt/gtksourceviewmm4/package.nix index 4e3bb4784f96..51f141a8a388 100644 --- a/pkgs/by-name/gt/gtksourceviewmm4/package.nix +++ b/pkgs/by-name/gt/gtksourceviewmm4/package.nix @@ -4,7 +4,7 @@ fetchurl, pkg-config, gtkmm3, - glibmm, + glibmm_2_4, gtksourceview4, gnome, }: @@ -28,7 +28,7 @@ stdenv.mkDerivation (finalAttrs: { nativeBuildInputs = [ pkg-config ]; propagatedBuildInputs = [ - glibmm + glibmm_2_4 gtkmm3 gtksourceview4 ]; diff --git a/pkgs/by-name/gt/gtkspellmm/package.nix b/pkgs/by-name/gt/gtkspellmm/package.nix index d05aa85f177f..c1143c5ba920 100644 --- a/pkgs/by-name/gt/gtkspellmm/package.nix +++ b/pkgs/by-name/gt/gtkspellmm/package.nix @@ -5,7 +5,7 @@ pkg-config, gtk3, glib, - glibmm, + glibmm_2_4, gtkmm3, gtkspell3, }: @@ -27,7 +27,7 @@ stdenv.mkDerivation rec { buildInputs = [ gtk3 glib - glibmm + glibmm_2_4 gtkmm3 ]; diff --git a/pkgs/by-name/gu/guitarix-vst/package.nix b/pkgs/by-name/gu/guitarix-vst/package.nix index 27eb994a4f8a..a131aefeb3ab 100644 --- a/pkgs/by-name/gu/guitarix-vst/package.nix +++ b/pkgs/by-name/gu/guitarix-vst/package.nix @@ -7,7 +7,7 @@ fftwFloat, freetype, glib, - glibmm, + glibmm_2_4, lib, libsndfile, libx11, @@ -54,7 +54,7 @@ stdenv.mkDerivation (finalAttrs: { fftwFloat freetype glib - glibmm + glibmm_2_4 libx11 libxcursor libxext diff --git a/pkgs/by-name/gu/guitarix/package.nix b/pkgs/by-name/gu/guitarix/package.nix index fa60d2efc584..a6c9018d5bff 100644 --- a/pkgs/by-name/gu/guitarix/package.nix +++ b/pkgs/by-name/gu/guitarix/package.nix @@ -13,7 +13,7 @@ gettext, glib, glib-networking, - glibmm, + glibmm_2_4, gperf, gtk3, gtkmm3, @@ -94,7 +94,7 @@ stdenv.mkDerivation (finalAttrs: { gettext glib glib-networking.out - glibmm + glibmm_2_4 gtk3 gtkmm3 ladspa-header diff --git a/pkgs/by-name/ja/jamesdsp/package.nix b/pkgs/by-name/ja/jamesdsp/package.nix index da668c36f11d..e62bd1b98e3e 100644 --- a/pkgs/by-name/ja/jamesdsp/package.nix +++ b/pkgs/by-name/ja/jamesdsp/package.nix @@ -2,7 +2,7 @@ copyDesktopItems, fetchFromGitHub, fetchpatch, - glibmm, + glibmm_2_4, gst_all_1, lib, libarchive, @@ -49,7 +49,7 @@ stdenv.mkDerivation (finalAttrs: { ]; buildInputs = [ - glibmm + glibmm_2_4 libarchive kdePackages.qtbase kdePackages.qtsvg diff --git a/pkgs/by-name/li/libgdamm/package.nix b/pkgs/by-name/li/libgdamm/package.nix index 2ac44bd39ced..f9fc5dcda735 100644 --- a/pkgs/by-name/li/libgdamm/package.nix +++ b/pkgs/by-name/li/libgdamm/package.nix @@ -3,7 +3,7 @@ stdenv, fetchurl, pkg-config, - glibmm, + glibmm_2_4, libgda5, libxml2, gnome, @@ -32,7 +32,7 @@ stdenv.mkDerivation rec { nativeBuildInputs = [ pkg-config ]; buildInputs = [ - glibmm + glibmm_2_4 libxml2 ]; propagatedBuildInputs = [ gda ]; diff --git a/pkgs/by-name/li/libsigrok-sipeed/package.nix b/pkgs/by-name/li/libsigrok-sipeed/package.nix index 43874dfe8b13..12eddd96e509 100644 --- a/pkgs/by-name/li/libsigrok-sipeed/package.nix +++ b/pkgs/by-name/li/libsigrok-sipeed/package.nix @@ -11,7 +11,7 @@ check, libserialport, doxygen, - glibmm, + glibmm_2_4, python3, hidapi, libieee1284, @@ -46,7 +46,7 @@ stdenv.mkDerivation { libftdi1 check libserialport - glibmm + glibmm_2_4 hidapi ] ++ lib.optionals stdenv.hostPlatform.isLinux [ diff --git a/pkgs/by-name/li/libsigrok/package.nix b/pkgs/by-name/li/libsigrok/package.nix index 5b8a9dbf62e9..8eafebf76d23 100644 --- a/pkgs/by-name/li/libsigrok/package.nix +++ b/pkgs/by-name/li/libsigrok/package.nix @@ -10,7 +10,7 @@ check, libserialport, doxygen, - glibmm, + glibmm_2_4, python3, hidapi, libieee1284, @@ -43,7 +43,7 @@ stdenv.mkDerivation { libftdi1 check libserialport - glibmm + glibmm_2_4 hidapi ] ++ lib.optionals stdenv.hostPlatform.isLinux [ diff --git a/pkgs/by-name/li/libxmlxx5/package.nix b/pkgs/by-name/li/libxmlxx5/package.nix index 98d6077a7ed1..34d668e12259 100644 --- a/pkgs/by-name/li/libxmlxx5/package.nix +++ b/pkgs/by-name/li/libxmlxx5/package.nix @@ -4,7 +4,7 @@ fetchFromGitHub, pkg-config, libxml2, - glibmm, + glibmm_2_4, meson, ninja, }: @@ -26,7 +26,7 @@ stdenv.mkDerivation (finalAttrs: { ninja ]; - buildInputs = [ glibmm ]; + buildInputs = [ glibmm_2_4 ]; propagatedBuildInputs = [ libxml2 ]; diff --git a/pkgs/by-name/li/lightspark/package.nix b/pkgs/by-name/li/lightspark/package.nix index 62539355e3e7..302141088b66 100644 --- a/pkgs/by-name/li/lightspark/package.nix +++ b/pkgs/by-name/li/lightspark/package.nix @@ -17,7 +17,7 @@ xz, nasm, llvm, - glibmm, + glibmm_2_4, }: stdenv.mkDerivation (finalAttrs: { @@ -54,7 +54,7 @@ stdenv.mkDerivation (finalAttrs: { xz nasm llvm - glibmm + glibmm_2_4 ]; meta = { diff --git a/pkgs/by-name/li/linthesia/package.nix b/pkgs/by-name/li/linthesia/package.nix index 013366e8ff40..96a05b8ebefe 100644 --- a/pkgs/by-name/li/linthesia/package.nix +++ b/pkgs/by-name/li/linthesia/package.nix @@ -5,7 +5,7 @@ SDL2_ttf, alsa-lib, fetchFromGitHub, - glibmm, + glibmm_2_4, gtk3, libGL, libGLU, @@ -44,7 +44,7 @@ stdenv.mkDerivation (finalAttrs: { libGL libGLU alsa-lib - glibmm + glibmm_2_4 sqlite SDL2 SDL2_ttf diff --git a/pkgs/by-name/pa/paprefs/package.nix b/pkgs/by-name/pa/paprefs/package.nix index 386212a8a820..2ba90eacc1c5 100644 --- a/pkgs/by-name/pa/paprefs/package.nix +++ b/pkgs/by-name/pa/paprefs/package.nix @@ -7,7 +7,7 @@ gettext, pkg-config, pulseaudioFull, - glibmm, + glibmm_2_4, gtkmm3, wrapGAppsHook3, }: @@ -31,7 +31,7 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ pulseaudioFull - glibmm + glibmm_2_4 gtkmm3 ]; diff --git a/pkgs/by-name/pe/performous/package.nix b/pkgs/by-name/pe/performous/package.nix index 71fc1b56f3bd..7593a83693a7 100644 --- a/pkgs/by-name/pe/performous/package.nix +++ b/pkgs/by-name/pe/performous/package.nix @@ -11,7 +11,7 @@ fmt, gettext, glew, - glibmm, + glibmm_2_4, glm, icu, libepoxy, @@ -95,7 +95,7 @@ stdenv.mkDerivation rec { ffmpeg fmt glew - glibmm + glibmm_2_4 glm icu libepoxy diff --git a/pkgs/by-name/po/powermode-indicator/package.nix b/pkgs/by-name/po/powermode-indicator/package.nix index e0da8dc9e444..d1dc193e9a6a 100644 --- a/pkgs/by-name/po/powermode-indicator/package.nix +++ b/pkgs/by-name/po/powermode-indicator/package.nix @@ -5,7 +5,7 @@ cmake, pkg-config, gtkmm3, - glibmm, + glibmm_2_4, libappindicator, }: stdenv.mkDerivation { @@ -26,7 +26,7 @@ stdenv.mkDerivation { buildInputs = [ libappindicator gtkmm3 - glibmm + glibmm_2_4 ]; meta = { diff --git a/pkgs/by-name/pu/pulseeffects-legacy/package.nix b/pkgs/by-name/pu/pulseeffects-legacy/package.nix index 2387c2176f17..d69c55e0aed0 100644 --- a/pkgs/by-name/pu/pulseeffects-legacy/package.nix +++ b/pkgs/by-name/pu/pulseeffects-legacy/package.nix @@ -14,7 +14,7 @@ pulseaudio, gtk3, glib, - glibmm, + glibmm_2_4, gtkmm3, lilv, lv2, @@ -71,7 +71,7 @@ stdenv.mkDerivation { buildInputs = [ pulseaudio glib - glibmm + glibmm_2_4 gtk3 gtkmm3 gst_all_1.gstreamer diff --git a/pkgs/by-name/pu/pulseview/package.nix b/pkgs/by-name/pu/pulseview/package.nix index 86c2f3705a08..dfe4833fcac0 100644 --- a/pkgs/by-name/pu/pulseview/package.nix +++ b/pkgs/by-name/pu/pulseview/package.nix @@ -12,7 +12,7 @@ libzip, libftdi1, hidapi, - glibmm, + glibmm_2_4, python3, bluez, libsForQt5, @@ -47,7 +47,7 @@ stdenv.mkDerivation { libzip libftdi1 hidapi - glibmm + glibmm_2_4 python3 libsForQt5.qtsvg ] diff --git a/pkgs/by-name/ra/radiotray-ng/package.nix b/pkgs/by-name/ra/radiotray-ng/package.nix index e1149c3c17c0..130d0637bbd5 100644 --- a/pkgs/by-name/ra/radiotray-ng/package.nix +++ b/pkgs/by-name/ra/radiotray-ng/package.nix @@ -12,7 +12,7 @@ libbsd, # GUI/Desktop dbus, - glibmm, + glibmm_2_4, gsettings-desktop-schemas, hicolor-icon-theme, libappindicator, @@ -71,7 +71,7 @@ stdenv.mkDerivation (finalAttrs: { boost jsoncpp libbsd - glibmm + glibmm_2_4 hicolor-icon-theme gsettings-desktop-schemas libappindicator diff --git a/pkgs/by-name/rh/rhvoice/package.nix b/pkgs/by-name/rh/rhvoice/package.nix index 039d8ea5fa98..eb611a14607a 100644 --- a/pkgs/by-name/rh/rhvoice/package.nix +++ b/pkgs/by-name/rh/rhvoice/package.nix @@ -5,7 +5,7 @@ ensureNewerSourcesForZipFilesHook, pkg-config, scons, - glibmm, + glibmm_2_4, libpulseaudio, libao, speechd-minimal, @@ -40,7 +40,7 @@ stdenv.mkDerivation (finalAttrs: { ]; buildInputs = [ - glibmm + glibmm_2_4 libpulseaudio libao speechd-minimal diff --git a/pkgs/by-name/sm/smuview/package.nix b/pkgs/by-name/sm/smuview/package.nix index 05a3dfd3afe0..b6a0ba50722f 100644 --- a/pkgs/by-name/sm/smuview/package.nix +++ b/pkgs/by-name/sm/smuview/package.nix @@ -11,7 +11,7 @@ libzip, libftdi1, hidapi, - glibmm, + glibmm_2_4, python3, bluez, pcre2, @@ -46,7 +46,7 @@ stdenv.mkDerivation { libzip libftdi1 hidapi - glibmm + glibmm_2_4 python3 pcre2 libsForQt5.qwt diff --git a/pkgs/by-name/sy/synfigstudio/package.nix b/pkgs/by-name/sy/synfigstudio/package.nix index 14b0d30d1d3f..48f43a2ce337 100644 --- a/pkgs/by-name/sy/synfigstudio/package.nix +++ b/pkgs/by-name/sy/synfigstudio/package.nix @@ -10,7 +10,7 @@ cairo, ffmpeg, gettext, - glibmm, + glibmm_2_4, libmng, gtk3, gtkmm3, @@ -79,7 +79,7 @@ let ]; buildInputs = [ ETL - glibmm + glibmm_2_4 mlt libsigcxx libxmlxx @@ -130,7 +130,7 @@ stdenv.mkDerivation (finalAttrs: { ETL synfig cairo - glibmm + glibmm_2_4 gtk3 gtkmm3 imagemagick diff --git a/pkgs/by-name/sy/syshud/package.nix b/pkgs/by-name/sy/syshud/package.nix index 0e3b3b852e0e..a32e4128a61d 100644 --- a/pkgs/by-name/sy/syshud/package.nix +++ b/pkgs/by-name/sy/syshud/package.nix @@ -2,7 +2,7 @@ lib, stdenv, fetchFromGitHub, - glibmm, + glibmm_2_4, gtk4-layer-shell, gtkmm4, libevdev, @@ -36,7 +36,7 @@ stdenv.mkDerivation (finalAttrs: { ]; buildInputs = [ - glibmm + glibmm_2_4 gtk4-layer-shell gtkmm4 libevdev diff --git a/pkgs/by-name/wo/workrave/package.nix b/pkgs/by-name/wo/workrave/package.nix index 3d805a12a088..d50183704ea5 100644 --- a/pkgs/by-name/wo/workrave/package.nix +++ b/pkgs/by-name/wo/workrave/package.nix @@ -16,7 +16,7 @@ libxtst, gobject-introspection, glib, - glibmm, + glibmm_2_4, gtkmm3, atk, pango, @@ -61,7 +61,7 @@ stdenv.mkDerivation (finalAttrs: { libxscrnsaver libxtst glib - glibmm + glibmm_2_4 gtkmm3 atk pango diff --git a/pkgs/development/libraries/gstreamer/gstreamermm/default.nix b/pkgs/development/libraries/gstreamer/gstreamermm/default.nix index 90da8d0df052..b8b75145f333 100644 --- a/pkgs/development/libraries/gstreamer/gstreamermm/default.nix +++ b/pkgs/development/libraries/gstreamer/gstreamermm/default.nix @@ -5,7 +5,7 @@ fetchpatch, pkg-config, file, - glibmm, + glibmm_2_4, gst_all_1, gnome, apple-sdk_gstreamer, @@ -43,7 +43,7 @@ stdenv.mkDerivation rec { ]; propagatedBuildInputs = [ - glibmm + glibmm_2_4 gst_all_1.gst-plugins-base ]; diff --git a/pkgs/development/libraries/libxmlxx/default.nix b/pkgs/development/libraries/libxmlxx/default.nix index 0ef02c177e12..1985f19245f6 100644 --- a/pkgs/development/libraries/libxmlxx/default.nix +++ b/pkgs/development/libraries/libxmlxx/default.nix @@ -4,7 +4,7 @@ fetchurl, pkg-config, libxml2, - glibmm, + glibmm_2_4, perl, gnome, }: @@ -35,7 +35,7 @@ stdenv.mkDerivation rec { propagatedBuildInputs = [ libxml2 - glibmm + glibmm_2_4 ]; passthru = { diff --git a/pkgs/development/libraries/libxmlxx/v3.nix b/pkgs/development/libraries/libxmlxx/v3.nix index 9794a16da5b0..0f7b5878e2fa 100644 --- a/pkgs/development/libraries/libxmlxx/v3.nix +++ b/pkgs/development/libraries/libxmlxx/v3.nix @@ -4,7 +4,7 @@ fetchurl, pkg-config, libxml2, - glibmm, + glibmm_2_4, perl, gnome, meson, @@ -61,7 +61,7 @@ stdenv.mkDerivation rec { dblatex ]; - buildInputs = [ glibmm ]; + buildInputs = [ glibmm_2_4 ]; propagatedBuildInputs = [ libxml2 ]; diff --git a/pkgs/development/libraries/pangomm/2.42.nix b/pkgs/development/libraries/pangomm/2.42.nix index 51d397cca17b..d2af4fc7a32e 100644 --- a/pkgs/development/libraries/pangomm/2.42.nix +++ b/pkgs/development/libraries/pangomm/2.42.nix @@ -7,7 +7,7 @@ ninja, python3, pango, - glibmm, + glibmm_2_4, cairomm_1_0, gnome, }: @@ -43,7 +43,7 @@ stdenv.mkDerivation rec { ]; propagatedBuildInputs = [ pango - glibmm + glibmm_2_4 cairomm_1_0 ]; diff --git a/pkgs/development/libraries/pangomm/default.nix b/pkgs/development/libraries/pangomm/default.nix index 8224b3a05f0f..bb264f81da8b 100644 --- a/pkgs/development/libraries/pangomm/default.nix +++ b/pkgs/development/libraries/pangomm/default.nix @@ -7,7 +7,7 @@ ninja, python3, pango, - glibmm, + glibmm_2_4, cairomm_1_0, gnome, }: @@ -34,7 +34,7 @@ stdenv.mkDerivation rec { ]; propagatedBuildInputs = [ pango - glibmm + glibmm_2_4 cairomm_1_0 ]; diff --git a/pkgs/top-level/aliases.nix b/pkgs/top-level/aliases.nix index f3b83d44a238..1acb89f12659 100644 --- a/pkgs/top-level/aliases.nix +++ b/pkgs/top-level/aliases.nix @@ -1001,6 +1001,7 @@ mapAliases { glew-egl = throw "'glew-egl' has been renamed to/replaced by 'glew'"; # Converted to throw 2025-10-27 glfw-wayland = throw "'glfw-wayland' has been renamed to/replaced by 'glfw'"; # Converted to throw 2025-10-27 glfw-wayland-minecraft = throw "'glfw-wayland-minecraft' has been renamed to/replaced by 'glfw3-minecraft'"; # Converted to throw 2025-10-27 + glibmm = throw "'glibmm' attribute has been removed from nixpkgs. Use a 'glibmm_*' attribute with an explicit ABI version instead."; # Added 2026-09-04 globalprotect-openconnect = throw "'globalprotect-openconnect' was removed because it was unmaintained in Nixpkgs and needed upgrading to the Tauri rewrite, as the old version depends on the removed Qt 5 WebEngine"; # Added 2026-04-26 glom = throw "'glom' has been removed as it was archived upstream and depended on libsoup 2.4"; # Added 2026-06-07 glxinfo = throw "'glxinfo' has been renamed to/replaced by 'mesa-demos'"; # Converted to throw 2025-10-27 From 0b8536ce9260b1380b5b08ca3226507bbc05ca91 Mon Sep 17 00:00:00 2001 From: Tom Hunze Date: Sat, 29 Aug 2026 00:10:08 +0200 Subject: [PATCH 122/423] glibmm_2_4: enable structuredAttrs and strictDeps --- pkgs/by-name/gl/glibmm_2_4/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/gl/glibmm_2_4/package.nix b/pkgs/by-name/gl/glibmm_2_4/package.nix index 3a564605f7fa..13cf5e5d141c 100644 --- a/pkgs/by-name/gl/glibmm_2_4/package.nix +++ b/pkgs/by-name/gl/glibmm_2_4/package.nix @@ -15,6 +15,9 @@ stdenv.mkDerivation (finalAttrs: { pname = "glibmm"; version = "2.66.8"; + __structuredAttrs = true; + strictDeps = true; + src = fetchurl { url = "mirror://gnome/sources/glibmm/${lib.versions.majorMinor finalAttrs.version}/glibmm-${finalAttrs.version}.tar.xz"; hash = "sha256-ZPEdO5WiTiqNQWbs/1GHMPeezCciLvQfr3x+A0D8kyk="; From 5be4a6998407cf694b41cf02a30a0d85c11420ef Mon Sep 17 00:00:00 2001 From: Tom Hunze Date: Sat, 29 Aug 2026 00:12:39 +0200 Subject: [PATCH 123/423] glibmm_2_68: enable structuredAttrs and strictDeps --- pkgs/by-name/gl/glibmm_2_68/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/gl/glibmm_2_68/package.nix b/pkgs/by-name/gl/glibmm_2_68/package.nix index e752e91f073a..50c31a228c78 100644 --- a/pkgs/by-name/gl/glibmm_2_68/package.nix +++ b/pkgs/by-name/gl/glibmm_2_68/package.nix @@ -15,6 +15,9 @@ stdenv.mkDerivation (finalAttrs: { pname = "glibmm"; version = "2.88.1"; + __structuredAttrs = true; + strictDeps = true; + outputs = [ "out" "dev" From 9ae024d50677789d71ac2ad959a4881805cf5093 Mon Sep 17 00:00:00 2001 From: Aaron Andersen Date: Tue, 8 Sep 2026 16:52:30 -0400 Subject: [PATCH 124/423] pulseaudio: replace systemd dependency with systemdLibs --- pkgs/by-name/pu/pulseaudio/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/pu/pulseaudio/package.nix b/pkgs/by-name/pu/pulseaudio/package.nix index d166190cffc6..a25d261b3a88 100644 --- a/pkgs/by-name/pu/pulseaudio/package.nix +++ b/pkgs/by-name/pu/pulseaudio/package.nix @@ -29,7 +29,7 @@ fftwFloat, soxr, speexdsp, - systemd, + systemdLibs, webrtc-audio-processing_1, gst_all_1, check, @@ -43,7 +43,7 @@ x11Support ? false, - useSystemd ? lib.meta.availableOn stdenv.hostPlatform systemd, + useSystemd ? lib.meta.availableOn stdenv.hostPlatform systemdLibs, # Whether to support the JACK sound system as a backend. jackaudioSupport ? false, @@ -150,7 +150,7 @@ stdenv.mkDerivation rec { libxi libxtst ] - ++ lib.optional useSystemd systemd + ++ lib.optional useSystemd systemdLibs ++ lib.optionals stdenv.hostPlatform.isLinux [ alsa-lib udev From e1459ab0f25d54f67b48c4fcba894cdc9ad48c12 Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Tue, 8 Sep 2026 23:52:38 +0200 Subject: [PATCH 125/423] nodejs_24: 24.20.0 -> 24.21.0 --- pkgs/development/web/nodejs/v24.nix | 10 ++-------- 1 file changed, 2 insertions(+), 8 deletions(-) diff --git a/pkgs/development/web/nodejs/v24.nix b/pkgs/development/web/nodejs/v24.nix index 44083fa48d15..5fee25ab2f17 100644 --- a/pkgs/development/web/nodejs/v24.nix +++ b/pkgs/development/web/nodejs/v24.nix @@ -29,8 +29,8 @@ let [ ]; in buildNodejs { - version = "24.20.0"; - sha256 = "2732fc3f588dd335cd6779c06864f7cd424bb1b5ff9a1743059a66c54f9ca4a1"; + version = "24.21.0"; + sha256 = "a6f54defb6fd7c84f41dba13d61e78e9b4e0961712cf61f29715c05f5ced94fc"; patches = (lib.optional (!(stdenv.hostPlatform.emulatorAvailable buildPackages)) (fetchpatch2 { url = "https://raw.githubusercontent.com/buildroot/buildroot/2f0c31bffdb59fb224387e35134a6d5e09a81d57/package/nodejs/nodejs-src/0003-include-obj-name-in-shared-intermediate.patch"; @@ -53,12 +53,6 @@ buildNodejs { ./use-correct-env-in-tests.patch ./bin-sh-node-run-v22.patch ./use-nix-codesign.patch - - # TODO: remove when support for OpenSSL 3.6.4 has landed upstream - (fetchpatch2 { - url = "https://github.com/nodejs/node/commit/a37601c99d7bde9abb3b3ae57b2fb2bacd81ec9d.patch?full_index=1"; - hash = "sha256-AdAPMs1RZgqJ0bzNZ6IvChjT97lbW+XV4cRWygzU1qc="; - }) ] ++ gypPatches ++ lib.optionals (!stdenv.buildPlatform.isDarwin) [ From e86865624d338b01ae1d35e1c85a81cff581e053 Mon Sep 17 00:00:00 2001 From: Jamie Magee Date: Tue, 8 Sep 2026 20:19:55 -0700 Subject: [PATCH 126/423] rust-bindgen: compare platforms with systems.equals --- pkgs/build-support/rust/hooks/default.nix | 2 +- pkgs/development/tools/rust/bindgen/default.nix | 3 ++- 2 files changed, 3 insertions(+), 2 deletions(-) diff --git a/pkgs/build-support/rust/hooks/default.nix b/pkgs/build-support/rust/hooks/default.nix index 7c8c846e3109..d17c6c0b4a12 100644 --- a/pkgs/build-support/rust/hooks/default.nix +++ b/pkgs/build-support/rust/hooks/default.nix @@ -133,7 +133,7 @@ libclang = (lib.getLib clang.cc); inherit clang; targetFlag = lib.optionalString ( - stdenv.targetPlatform != stdenv.hostPlatform + !lib.systems.equals stdenv.targetPlatform stdenv.hostPlatform ) "--target=${stdenv.targetPlatform.config}"; }; meta.license = lib.licenses.mit; diff --git a/pkgs/development/tools/rust/bindgen/default.nix b/pkgs/development/tools/rust/bindgen/default.nix index fcd26a41c0a9..6831e156dfa7 100644 --- a/pkgs/development/tools/rust/bindgen/default.nix +++ b/pkgs/development/tools/rust/bindgen/default.nix @@ -2,6 +2,7 @@ rust-bindgen-unwrapped, zlib, bash, + lib, runCommand, runCommandCC, stdenv, @@ -9,7 +10,7 @@ let clang = rust-bindgen-unwrapped.clang; targetFlag = - if stdenv.targetPlatform != stdenv.hostPlatform then + if (!lib.systems.equals stdenv.targetPlatform stdenv.hostPlatform) then "--target=${stdenv.targetPlatform.config}" else ""; From 9cd092bab4b6c55fe2ce0ee86d7964877b7bddd8 Mon Sep 17 00:00:00 2001 From: Jamie Magee Date: Tue, 8 Sep 2026 22:03:40 -0700 Subject: [PATCH 127/423] bcachefs-tools: remove RISC-V bindgen workaround --- pkgs/by-name/bc/bcachefs-tools/package.nix | 6 ------ 1 file changed, 6 deletions(-) diff --git a/pkgs/by-name/bc/bcachefs-tools/package.nix b/pkgs/by-name/bc/bcachefs-tools/package.nix index 6a0cf473f056..1f045ef5ca5c 100644 --- a/pkgs/by-name/bc/bcachefs-tools/package.nix +++ b/pkgs/by-name/bc/bcachefs-tools/package.nix @@ -106,12 +106,6 @@ stdenv.mkDerivation (finalAttrs: { PKG_CONFIG_SYSTEMD_SYSTEMDSYSTEMGENERATORDIR = "${placeholder "out"}/lib/systemd/system-generators"; }; - # Workaround for RISCV cross-compilation issue - # https://github.com/koverstreet/bcachefs-tools/issues/850 - preBuild = lib.optionalString stdenv.hostPlatform.isRiscV '' - export BINDGEN_EXTRA_CLANG_ARGS="$BINDGEN_EXTRA_CLANG_ARGS --target=riscv64-unknown-linux-gnu -march=rv64gc" - ''; - # FIXME: Try enabling this once the default linux kernel is at least 6.7 doCheck = false; # needs bcachefs module loaded on builder From 49054352ceaf424a72456dca741b7405c6d7267d Mon Sep 17 00:00:00 2001 From: Sergei Trofimovich Date: Wed, 9 Sep 2026 21:38:11 +0100 Subject: [PATCH 128/423] xz: 5.8.3 -> 5.8.4 Changes: https://github.com/tukaani-project/xz/releases/tag/v5.8.4 --- pkgs/by-name/xz/xz/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/xz/xz/package.nix b/pkgs/by-name/xz/xz/package.nix index 1313bc1779a2..83a1358cd2c1 100644 --- a/pkgs/by-name/xz/xz/package.nix +++ b/pkgs/by-name/xz/xz/package.nix @@ -15,13 +15,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "xz"; - version = "5.8.3"; + version = "5.8.4"; src = fetchurl { url = with finalAttrs; "https://github.com/tukaani-project/xz/releases/download/v${version}/xz-${version}.tar.xz"; - hash = "sha256-//H/zysNqE0wihTeUToaoj1OmqNGTRfmS5cUv90Lv7Y="; + hash = "sha256-TOJAOP1CIeDRO8Gi3npNtW6QuSs791Mh9sFL5z9l3ks="; }; strictDeps = true; From 6d4f039414867e315b19616213fe27baa08d0d31 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 10 Sep 2026 08:52:03 +0000 Subject: [PATCH 129/423] rdma-core: 64.0 -> 65.0 --- pkgs/by-name/rd/rdma-core/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/rd/rdma-core/package.nix b/pkgs/by-name/rd/rdma-core/package.nix index 256f8fcabc0c..044d8dd535fe 100644 --- a/pkgs/by-name/rd/rdma-core/package.nix +++ b/pkgs/by-name/rd/rdma-core/package.nix @@ -16,13 +16,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "rdma-core"; - version = "64.0"; + version = "65.0"; src = fetchFromGitHub { owner = "linux-rdma"; repo = "rdma-core"; rev = "v${finalAttrs.version}"; - hash = "sha256-Y0pCGkvCjZ1F9Ojouesozn2Lxj+x7/0ck6/9tJmdkWw="; + hash = "sha256-cAaWVE6/JU8ezjx+XrxNI6Su6VKxb2Jxl29sxU/yepI="; }; strictDeps = true; From ae25eb7f83967639b030b0c6e8cd59b8cb547f88 Mon Sep 17 00:00:00 2001 From: Tom Hunze Date: Sat, 5 Sep 2026 08:02:33 +0200 Subject: [PATCH 130/423] libsigcxx: rename to libsigcxx_2_0 Having the older ABI version as the default seems odd, so drop the unsuffixed version similar to webkitgtk and as discussed in [1]. [1] https://github.com/NixOS/nixpkgs/pull/543345#issuecomment-5199018730 --- pkgs/applications/graphics/inkscape/default.nix | 4 ++-- pkgs/by-name/ar/ardour/package.nix | 4 ++-- pkgs/by-name/ar/ardour_8/package.nix | 4 ++-- pkgs/by-name/ar/art/package.nix | 4 ++-- pkgs/by-name/as/asc/package.nix | 4 ++-- pkgs/by-name/ca/cairomm_1_0/package.nix | 4 ++-- pkgs/by-name/da/darkradiant/package.nix | 4 ++-- pkgs/by-name/fr/freqtweak/package.nix | 4 ++-- pkgs/by-name/gl/glibmm_2_4/package.nix | 4 ++-- pkgs/by-name/in/ingen/package.nix | 4 ++-- pkgs/by-name/js/jstest-gtk/package.nix | 4 ++-- pkgs/by-name/li/libpar2/package.nix | 4 ++-- pkgs/by-name/ma/mamba/package.nix | 4 ++-- pkgs/by-name/no/non/package.nix | 4 ++-- pkgs/by-name/nz/nzbget/package.nix | 4 ++-- pkgs/by-name/pa/pavucontrol/package.nix | 4 ++-- pkgs/by-name/pi/pingus/package.nix | 4 ++-- pkgs/by-name/pi/pioneer/package.nix | 4 ++-- pkgs/by-name/ra/rawtherapee/package.nix | 4 ++-- pkgs/by-name/sc/scopehal-apps/package.nix | 4 ++-- pkgs/by-name/so/sooperlooper/package.nix | 4 ++-- pkgs/by-name/su/subtitleeditor/package.nix | 4 ++-- pkgs/by-name/sv/svxlink/package.nix | 4 ++-- pkgs/by-name/sy/synfigstudio/package.nix | 6 +++--- pkgs/by-name/wa/waybar/package.nix | 4 ++-- pkgs/by-name/wo/workrave/package.nix | 4 ++-- pkgs/by-name/xk/xkb-switch-i3/package.nix | 4 ++-- pkgs/by-name/xt/xtuner/package.nix | 4 ++-- .../libraries/libsigcxx/{default.nix => 2.0.nix} | 2 +- pkgs/top-level/aliases.nix | 1 + pkgs/top-level/all-packages.nix | 2 +- 31 files changed, 60 insertions(+), 59 deletions(-) rename pkgs/development/libraries/libsigcxx/{default.nix => 2.0.nix} (96%) diff --git a/pkgs/applications/graphics/inkscape/default.nix b/pkgs/applications/graphics/inkscape/default.nix index ea217e686e2b..075e288bbb2e 100644 --- a/pkgs/applications/graphics/inkscape/default.nix +++ b/pkgs/applications/graphics/inkscape/default.nix @@ -29,7 +29,7 @@ libpng, librevenge, librsvg, - libsigcxx, + libsigcxx_2_0, libvisio, libwpg, libxft, @@ -165,7 +165,7 @@ stdenv.mkDerivation (finalAttrs: { libpng librevenge librsvg # for loading icons - libsigcxx + libsigcxx_2_0 libvisio libwpg libxft diff --git a/pkgs/by-name/ar/ardour/package.nix b/pkgs/by-name/ar/ardour/package.nix index 6c959449fc11..cd28884be1be 100644 --- a/pkgs/by-name/ar/ardour/package.nix +++ b/pkgs/by-name/ar/ardour/package.nix @@ -36,7 +36,7 @@ libpulseaudio, librdf_rasqal, libsamplerate, - libsigcxx, + libsigcxx_2_0, libsndfile, libusb1, libuv, @@ -154,7 +154,7 @@ let libogg librdf_rasqal libsamplerate - libsigcxx + libsigcxx_2_0 libsndfile libusb1 libuv diff --git a/pkgs/by-name/ar/ardour_8/package.nix b/pkgs/by-name/ar/ardour_8/package.nix index f673a096dab8..dbdbcb77d05f 100644 --- a/pkgs/by-name/ar/ardour_8/package.nix +++ b/pkgs/by-name/ar/ardour_8/package.nix @@ -31,7 +31,7 @@ libpulseaudio, librdf_rasqal, libsamplerate, - libsigcxx, + libsigcxx_2_0, libsndfile, libusb1, libuv, @@ -141,7 +141,7 @@ stdenv.mkDerivation ( libpulseaudio librdf_rasqal libsamplerate - libsigcxx + libsigcxx_2_0 libsndfile libusb1 libuv diff --git a/pkgs/by-name/ar/art/package.nix b/pkgs/by-name/ar/art/package.nix index 8afeb8325884..10e3d911dd0d 100644 --- a/pkgs/by-name/ar/art/package.nix +++ b/pkgs/by-name/ar/art/package.nix @@ -25,7 +25,7 @@ fftwSinglePrec, expat, pcre2, - libsigcxx, + libsigcxx_2_0, lensfun, librsvg, libcanberra-gtk3, @@ -83,7 +83,7 @@ stdenv.mkDerivation (finalAttrs: { fftwSinglePrec expat pcre2 - libsigcxx + libsigcxx_2_0 lensfun librsvg exiv2 diff --git a/pkgs/by-name/as/asc/package.nix b/pkgs/by-name/as/asc/package.nix index c28bd20cd0ef..2d1bc8b33a84 100644 --- a/pkgs/by-name/as/asc/package.nix +++ b/pkgs/by-name/as/asc/package.nix @@ -6,7 +6,7 @@ SDL_image, SDL_mixer, SDL_sound, - libsigcxx, + libsigcxx_2_0, physfs, boost, expat, @@ -64,7 +64,7 @@ stdenv.mkDerivation { flac libvorbis libogg - libsigcxx + libsigcxx_2_0 ]; meta = { diff --git a/pkgs/by-name/ca/cairomm_1_0/package.nix b/pkgs/by-name/ca/cairomm_1_0/package.nix index 7d48339c2704..ac957ad4ae54 100644 --- a/pkgs/by-name/ca/cairomm_1_0/package.nix +++ b/pkgs/by-name/ca/cairomm_1_0/package.nix @@ -6,7 +6,7 @@ boost, cairo, fontconfig, - libsigcxx, + libsigcxx_2_0, meson, ninja, }: @@ -41,7 +41,7 @@ stdenv.mkDerivation (finalAttrs: { propagatedBuildInputs = [ cairo - libsigcxx + libsigcxx_2_0 ]; mesonFlags = [ diff --git a/pkgs/by-name/da/darkradiant/package.nix b/pkgs/by-name/da/darkradiant/package.nix index 25f7f9f17809..e0983f0b28e0 100644 --- a/pkgs/by-name/da/darkradiant/package.nix +++ b/pkgs/by-name/da/darkradiant/package.nix @@ -8,7 +8,7 @@ libjpeg, wxwidgets_3_2, libxml2, - libsigcxx, + libsigcxx_2_0, libpng, openal, libvorbis, @@ -50,7 +50,7 @@ stdenv.mkDerivation (finalAttrs: { libjpeg wxwidgets_3_2 libxml2 - libsigcxx + libsigcxx_2_0 libpng openal libvorbis diff --git a/pkgs/by-name/fr/freqtweak/package.nix b/pkgs/by-name/fr/freqtweak/package.nix index 82565ad4ebaa..5d252b8ee4bf 100644 --- a/pkgs/by-name/fr/freqtweak/package.nix +++ b/pkgs/by-name/fr/freqtweak/package.nix @@ -6,7 +6,7 @@ pkg-config, fftwFloat, libjack2, - libsigcxx, + libsigcxx_2_0, libxml2, wxwidgets_3_2, @@ -32,7 +32,7 @@ stdenv.mkDerivation { buildInputs = [ fftwFloat libjack2 - libsigcxx + libsigcxx_2_0 libxml2 wxwidgets_3_2 ]; diff --git a/pkgs/by-name/gl/glibmm_2_4/package.nix b/pkgs/by-name/gl/glibmm_2_4/package.nix index 13cf5e5d141c..1bcc205b000b 100644 --- a/pkgs/by-name/gl/glibmm_2_4/package.nix +++ b/pkgs/by-name/gl/glibmm_2_4/package.nix @@ -5,7 +5,7 @@ pkg-config, gnum4, glib, - libsigcxx, + libsigcxx_2_0, gnome, meson, ninja, @@ -37,7 +37,7 @@ stdenv.mkDerivation (finalAttrs: { ]; propagatedBuildInputs = [ glib - libsigcxx + libsigcxx_2_0 ]; doCheck = false; # fails. one test needs the net, another /etc/fstab diff --git a/pkgs/by-name/in/ingen/package.nix b/pkgs/by-name/in/ingen/package.nix index 84d6abace175..d96c966a9676 100644 --- a/pkgs/by-name/in/ingen/package.nix +++ b/pkgs/by-name/in/ingen/package.nix @@ -5,7 +5,7 @@ portaudio, boost, libjack2, - libsigcxx, + libsigcxx_2_0, lilv, pkg-config, python3, @@ -39,7 +39,7 @@ stdenv.mkDerivation { buildInputs = [ boost libjack2 - libsigcxx + libsigcxx_2_0 lilv portaudio raul diff --git a/pkgs/by-name/js/jstest-gtk/package.nix b/pkgs/by-name/js/jstest-gtk/package.nix index ba476a2b6b81..b5ceca969b97 100644 --- a/pkgs/by-name/js/jstest-gtk/package.nix +++ b/pkgs/by-name/js/jstest-gtk/package.nix @@ -5,7 +5,7 @@ cmake, pkg-config, gtkmm3, - libsigcxx, + libsigcxx_2_0, libx11, }: @@ -26,7 +26,7 @@ stdenv.mkDerivation { ]; buildInputs = [ gtkmm3 - libsigcxx + libsigcxx_2_0 libx11 ]; diff --git a/pkgs/by-name/li/libpar2/package.nix b/pkgs/by-name/li/libpar2/package.nix index 2d29d4d81eb7..5b718cead6c8 100644 --- a/pkgs/by-name/li/libpar2/package.nix +++ b/pkgs/by-name/li/libpar2/package.nix @@ -3,7 +3,7 @@ stdenv, fetchurl, pkg-config, - libsigcxx, + libsigcxx_2_0, }: stdenv.mkDerivation (finalAttrs: { @@ -16,7 +16,7 @@ stdenv.mkDerivation (finalAttrs: { }; nativeBuildInputs = [ pkg-config ]; - buildInputs = [ libsigcxx ]; + buildInputs = [ libsigcxx_2_0 ]; patches = [ ./libpar2-0.4-external-verification.patch ]; diff --git a/pkgs/by-name/ma/mamba/package.nix b/pkgs/by-name/ma/mamba/package.nix index d12b7cb7f624..ff9a30389ce6 100644 --- a/pkgs/by-name/ma/mamba/package.nix +++ b/pkgs/by-name/ma/mamba/package.nix @@ -10,7 +10,7 @@ libjack2, alsa-lib, liblo, - libsigcxx, + libsigcxx_2_0, libsmf, }: @@ -37,7 +37,7 @@ stdenv.mkDerivation (finalAttrs: { libjack2 alsa-lib liblo - libsigcxx + libsigcxx_2_0 libsmf ]; diff --git a/pkgs/by-name/no/non/package.nix b/pkgs/by-name/no/non/package.nix index aad1eee48a15..9fa7a40848d5 100644 --- a/pkgs/by-name/no/non/package.nix +++ b/pkgs/by-name/no/non/package.nix @@ -11,7 +11,7 @@ libsndfile, ladspa-header, liblo, - libsigcxx, + libsigcxx_2_0, lrdf, waf, }: @@ -44,7 +44,7 @@ stdenv.mkDerivation { libsndfile ladspa-header liblo - libsigcxx + libsigcxx_2_0 lrdf ]; diff --git a/pkgs/by-name/nz/nzbget/package.nix b/pkgs/by-name/nz/nzbget/package.nix index bd8a64cc1cf3..5e13e2fd94b2 100644 --- a/pkgs/by-name/nz/nzbget/package.nix +++ b/pkgs/by-name/nz/nzbget/package.nix @@ -9,7 +9,7 @@ libgcrypt, libpar2, libcap, - libsigcxx, + libsigcxx_2_0, libxml2, ncurses, openssl, @@ -59,7 +59,7 @@ stdenv.mkDerivation (finalAttrs: { libgcrypt libpar2 libcap - libsigcxx + libsigcxx_2_0 libxml2 ncurses openssl diff --git a/pkgs/by-name/pa/pavucontrol/package.nix b/pkgs/by-name/pa/pavucontrol/package.nix index d2daf3b76af5..52c92d887482 100644 --- a/pkgs/by-name/pa/pavucontrol/package.nix +++ b/pkgs/by-name/pa/pavucontrol/package.nix @@ -6,7 +6,7 @@ intltool, libpulseaudio, gtkmm4, - libsigcxx, + libsigcxx_2_0, # Since version 6.1, libcanberra is optional withLibcanberra ? true, libcanberra-gtk3, @@ -32,7 +32,7 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ libpulseaudio gtkmm4 - libsigcxx + libsigcxx_2_0 (lib.optionals withLibcanberra libcanberra-gtk3) json-glib adwaita-icon-theme diff --git a/pkgs/by-name/pi/pingus/package.nix b/pkgs/by-name/pi/pingus/package.nix index f1795ee2a9aa..daa41c7aa6f0 100644 --- a/pkgs/by-name/pi/pingus/package.nix +++ b/pkgs/by-name/pi/pingus/package.nix @@ -12,7 +12,7 @@ fmt, gtest, libpng, - libsigcxx, + libsigcxx_2_0, argpp, geomcpp, logmich, @@ -50,7 +50,7 @@ stdenv.mkDerivation { fmt gtest libpng - libsigcxx + libsigcxx_2_0 argpp geomcpp logmich diff --git a/pkgs/by-name/pi/pioneer/package.nix b/pkgs/by-name/pi/pioneer/package.nix index 87a8dd2571e3..797f7d370d52 100644 --- a/pkgs/by-name/pi/pioneer/package.nix +++ b/pkgs/by-name/pi/pioneer/package.nix @@ -11,7 +11,7 @@ libGL, libGLU, libpng, - libsigcxx, + libsigcxx_2_0, libvorbis, libx11, lua5_2, @@ -50,7 +50,7 @@ stdenv.mkDerivation (finalAttrs: { libGL libGLU libpng - libsigcxx + libsigcxx_2_0 libvorbis libx11 lua5_2 diff --git a/pkgs/by-name/ra/rawtherapee/package.nix b/pkgs/by-name/ra/rawtherapee/package.nix index 572c6829e525..2e6dae849f91 100644 --- a/pkgs/by-name/ra/rawtherapee/package.nix +++ b/pkgs/by-name/ra/rawtherapee/package.nix @@ -25,7 +25,7 @@ fftwSinglePrec, expat, pcre2, - libsigcxx, + libsigcxx_2_0, lensfun, librsvg, libcanberra-gtk3, @@ -90,7 +90,7 @@ stdenv.mkDerivation (finalAttrs: { fftwSinglePrec expat pcre2 - libsigcxx + libsigcxx_2_0 lensfun librsvg exiv2 diff --git a/pkgs/by-name/sc/scopehal-apps/package.nix b/pkgs/by-name/sc/scopehal-apps/package.nix index f0d13037e83e..70c48c675e0d 100644 --- a/pkgs/by-name/sc/scopehal-apps/package.nix +++ b/pkgs/by-name/sc/scopehal-apps/package.nix @@ -10,7 +10,7 @@ libpng, libtirpc, liblxi, - libsigcxx, + libsigcxx_2_0, zlib, wrapGAppsHook3, makeBinaryWrapper, @@ -65,7 +65,7 @@ stdenv.mkDerivation { hidapi liblxi libpng - libsigcxx + libsigcxx_2_0 vulkan-headers vulkan-loader yaml-cpp diff --git a/pkgs/by-name/so/sooperlooper/package.nix b/pkgs/by-name/so/sooperlooper/package.nix index 78b2aa4baa32..22efae021550 100644 --- a/pkgs/by-name/so/sooperlooper/package.nix +++ b/pkgs/by-name/so/sooperlooper/package.nix @@ -11,7 +11,7 @@ libjack2, libsndfile, wxwidgets_3_2, - libsigcxx, + libsigcxx_2_0, libsamplerate, rubberband, gettext, @@ -49,7 +49,7 @@ stdenv.mkDerivation (finalAttrs: { libjack2 libsndfile wxwidgets_3_2 - libsigcxx + libsigcxx_2_0 libsamplerate rubberband gettext diff --git a/pkgs/by-name/su/subtitleeditor/package.nix b/pkgs/by-name/su/subtitleeditor/package.nix index ff0427899d63..e037a189158d 100644 --- a/pkgs/by-name/su/subtitleeditor/package.nix +++ b/pkgs/by-name/su/subtitleeditor/package.nix @@ -12,7 +12,7 @@ gtkmm3, gst_all_1, hicolor-icon-theme, - libsigcxx, + libsigcxx_2_0, libxmlxx, xdg-utils, isocodes, @@ -51,7 +51,7 @@ stdenv.mkDerivation (finalAttrs: { gst_all_1.gst-plugins-ugly gst_all_1.gst-libav hicolor-icon-theme - libsigcxx + libsigcxx_2_0 libxmlxx xdg-utils isocodes diff --git a/pkgs/by-name/sv/svxlink/package.nix b/pkgs/by-name/sv/svxlink/package.nix index 4a18d7a4ac85..9f16bf326f39 100644 --- a/pkgs/by-name/sv/svxlink/package.nix +++ b/pkgs/by-name/sv/svxlink/package.nix @@ -11,7 +11,7 @@ gsm, libgcrypt, libgpiod_1, - libsigcxx, + libsigcxx_2_0, popt, qt5, rtl-sdr, @@ -65,7 +65,7 @@ stdenv.mkDerivation (finalAttrs: { libgcrypt libgpiod_1 libopus - libsigcxx + libsigcxx_2_0 popt qt5.qtbase rtl-sdr diff --git a/pkgs/by-name/sy/synfigstudio/package.nix b/pkgs/by-name/sy/synfigstudio/package.nix index 48f43a2ce337..40451c3161ff 100644 --- a/pkgs/by-name/sy/synfigstudio/package.nix +++ b/pkgs/by-name/sy/synfigstudio/package.nix @@ -15,7 +15,7 @@ gtk3, gtkmm3, libjack2, - libsigcxx, + libsigcxx_2_0, libxmlxx, mlt, imagemagick, @@ -81,7 +81,7 @@ let ETL glibmm_2_4 mlt - libsigcxx + libsigcxx_2_0 libxmlxx imagemagick harfbuzz @@ -135,7 +135,7 @@ stdenv.mkDerivation (finalAttrs: { gtkmm3 imagemagick libjack2 - libsigcxx + libsigcxx_2_0 libxmlxx mlt fontconfig diff --git a/pkgs/by-name/wa/waybar/package.nix b/pkgs/by-name/wa/waybar/package.nix index c7f454a67efc..e1a58ed3d510 100644 --- a/pkgs/by-name/wa/waybar/package.nix +++ b/pkgs/by-name/wa/waybar/package.nix @@ -22,7 +22,7 @@ libmpdclient, libnl, libpulseaudio, - libsigcxx, + libsigcxx_2_0, libxkbcommon, meson, ncurses, @@ -123,7 +123,7 @@ stdenv.mkDerivation (finalAttrs: { gtk-layer-shell gtkmm3 jsoncpp - libsigcxx + libsigcxx_2_0 libxkbcommon spdlog wayland diff --git a/pkgs/by-name/wo/workrave/package.nix b/pkgs/by-name/wo/workrave/package.nix index d50183704ea5..cd895043cea1 100644 --- a/pkgs/by-name/wo/workrave/package.nix +++ b/pkgs/by-name/wo/workrave/package.nix @@ -26,7 +26,7 @@ dbus, dbus-glib, gst_all_1, - libsigcxx, + libsigcxx_2_0, boost, python3Packages, }: @@ -73,7 +73,7 @@ stdenv.mkDerivation (finalAttrs: { gst_all_1.gstreamer gst_all_1.gst-plugins-base gst_all_1.gst-plugins-good - libsigcxx + libsigcxx_2_0 boost ]; diff --git a/pkgs/by-name/xk/xkb-switch-i3/package.nix b/pkgs/by-name/xk/xkb-switch-i3/package.nix index 8c9c30807523..3965ddb59461 100644 --- a/pkgs/by-name/xk/xkb-switch-i3/package.nix +++ b/pkgs/by-name/xk/xkb-switch-i3/package.nix @@ -5,7 +5,7 @@ fetchFromGitHub, i3, jsoncpp, - libsigcxx, + libsigcxx_2_0, libx11, libxkbfile, pkg-config, @@ -45,7 +45,7 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ i3 jsoncpp - libsigcxx + libsigcxx_2_0 libx11 libxkbfile ]; diff --git a/pkgs/by-name/xt/xtuner/package.nix b/pkgs/by-name/xt/xtuner/package.nix index ed94f34e9a20..4375e8750231 100644 --- a/pkgs/by-name/xt/xtuner/package.nix +++ b/pkgs/by-name/xt/xtuner/package.nix @@ -8,7 +8,7 @@ libx11, libjack2, liblo, - libsigcxx, + libsigcxx_2_0, zita-resampler, fftwFloat, }: @@ -42,7 +42,7 @@ stdenv.mkDerivation (finalAttrs: { libx11 libjack2 liblo - libsigcxx + libsigcxx_2_0 zita-resampler fftwFloat ]; diff --git a/pkgs/development/libraries/libsigcxx/default.nix b/pkgs/development/libraries/libsigcxx/2.0.nix similarity index 96% rename from pkgs/development/libraries/libsigcxx/default.nix rename to pkgs/development/libraries/libsigcxx/2.0.nix index 95f040620245..0d72ebe9958e 100644 --- a/pkgs/development/libraries/libsigcxx/default.nix +++ b/pkgs/development/libraries/libsigcxx/2.0.nix @@ -33,7 +33,7 @@ stdenv.mkDerivation rec { passthru = { updateScript = gnome.updateScript { packageName = "libsigc++"; - attrPath = "libsigcxx"; + attrPath = "libsigcxx_2_0"; versionPolicy = "odd-unstable"; freeze = "2.99.1"; }; diff --git a/pkgs/top-level/aliases.nix b/pkgs/top-level/aliases.nix index 1de0a62e48b6..1c7b3ef456f3 100644 --- a/pkgs/top-level/aliases.nix +++ b/pkgs/top-level/aliases.nix @@ -1397,6 +1397,7 @@ mapAliases { librewolf-wayland = throw "'librewolf-wayland' has been renamed to/replaced by 'librewolf'"; # Converted to throw 2025-10-27 librtlsdr = throw "'librtlsdr' has been renamed to/replaced by 'rtl-sdr'"; # Converted to throw 2025-10-27 libsForQt515 = throw "'libsForQt515' has been renamed to/replaced by 'libsForQt5'"; # Converted to throw 2025-10-27 + libsigcxx = throw "'libsigcxx' attribute has been removed from nixpkgs. Use a 'libsigcxx_*' attribute with an explicit ABI version instead."; # Added 2026-09-05 libSM = libsm; # Added 2026-02-04 libsmartcols = warnAlias "'util-linux' should be used instead of 'libsmartcols'" util-linux; # Added 2025-09-03 libsoup = throw "'libsoup' has been renamed to/replaced by 'libsoup_2_4'"; # Converted to throw 2025-10-27 diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index c46a30843446..118df95e2d64 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -6047,7 +6047,7 @@ with pkgs; libprom ; - libsigcxx = callPackage ../development/libraries/libsigcxx { }; + libsigcxx_2_0 = callPackage ../development/libraries/libsigcxx/2.0.nix { }; libsigcxx30 = callPackage ../development/libraries/libsigcxx/3.0.nix { }; From 11900e5fb92eeeb0167b1b2463ef053309f5e97f Mon Sep 17 00:00:00 2001 From: Tom Hunze Date: Sat, 5 Sep 2026 08:11:02 +0200 Subject: [PATCH 131/423] libsigcxx30: rename to libsigcxx_3_0 That's more consistent with other GNOME-related package attributes with explicit ABI version suffixes. --- pkgs/by-name/ca/cairomm_1_16/package.nix | 4 ++-- pkgs/by-name/ea/easyeffects/package.nix | 4 ++-- pkgs/by-name/gl/glibmm_2_68/package.nix | 4 ++-- pkgs/development/libraries/libsigcxx/3.0.nix | 2 +- pkgs/top-level/aliases.nix | 1 + pkgs/top-level/all-packages.nix | 3 +-- 6 files changed, 9 insertions(+), 9 deletions(-) diff --git a/pkgs/by-name/ca/cairomm_1_16/package.nix b/pkgs/by-name/ca/cairomm_1_16/package.nix index 4bb542e104dd..3a4b66a57030 100644 --- a/pkgs/by-name/ca/cairomm_1_16/package.nix +++ b/pkgs/by-name/ca/cairomm_1_16/package.nix @@ -8,7 +8,7 @@ pkg-config, cairo, fontconfig, - libsigcxx30, + libsigcxx_3_0, }: stdenv.mkDerivation (finalAttrs: { @@ -41,7 +41,7 @@ stdenv.mkDerivation (finalAttrs: { propagatedBuildInputs = [ cairo - libsigcxx30 + libsigcxx_3_0 ]; mesonFlags = [ diff --git a/pkgs/by-name/ea/easyeffects/package.nix b/pkgs/by-name/ea/easyeffects/package.nix index 871930bd2ddf..6173179118dc 100644 --- a/pkgs/by-name/ea/easyeffects/package.nix +++ b/pkgs/by-name/ea/easyeffects/package.nix @@ -15,7 +15,7 @@ libbs2b, libebur128, libmysofa, - libsigcxx30, + libsigcxx_3_0, libsndfile, lilv, lsp-plugins, @@ -100,7 +100,7 @@ stdenv.mkDerivation (finalAttrs: { libbs2b libebur128 libmysofa - libsigcxx30 + libsigcxx_3_0 libsndfile lilv lv2 diff --git a/pkgs/by-name/gl/glibmm_2_68/package.nix b/pkgs/by-name/gl/glibmm_2_68/package.nix index 50c31a228c78..9745652e0e76 100644 --- a/pkgs/by-name/gl/glibmm_2_68/package.nix +++ b/pkgs/by-name/gl/glibmm_2_68/package.nix @@ -5,7 +5,7 @@ pkg-config, gnum4, glib, - libsigcxx30, + libsigcxx_3_0, gnome, meson, ninja, @@ -38,7 +38,7 @@ stdenv.mkDerivation (finalAttrs: { propagatedBuildInputs = [ glib - libsigcxx30 + libsigcxx_3_0 ]; doCheck = false; # fails. one test needs the net, another /etc/fstab diff --git a/pkgs/development/libraries/libsigcxx/3.0.nix b/pkgs/development/libraries/libsigcxx/3.0.nix index 8162e731e3da..5f8d78897419 100644 --- a/pkgs/development/libraries/libsigcxx/3.0.nix +++ b/pkgs/development/libraries/libsigcxx/3.0.nix @@ -35,7 +35,7 @@ stdenv.mkDerivation (finalAttrs: { passthru = { updateScript = gnome.updateScript { packageName = "libsigc++"; - attrPath = "libsigcxx30"; + attrPath = "libsigcxx_3_0"; versionPolicy = "odd-unstable"; }; }; diff --git a/pkgs/top-level/aliases.nix b/pkgs/top-level/aliases.nix index 1c7b3ef456f3..81e2fc06e840 100644 --- a/pkgs/top-level/aliases.nix +++ b/pkgs/top-level/aliases.nix @@ -1397,6 +1397,7 @@ mapAliases { librewolf-wayland = throw "'librewolf-wayland' has been renamed to/replaced by 'librewolf'"; # Converted to throw 2025-10-27 librtlsdr = throw "'librtlsdr' has been renamed to/replaced by 'rtl-sdr'"; # Converted to throw 2025-10-27 libsForQt515 = throw "'libsForQt515' has been renamed to/replaced by 'libsForQt5'"; # Converted to throw 2025-10-27 + libsigcxx30 = throw "'libsigcxx30' has been renamed to 'libsigcxx_3_0'"; # Added 2026-09-05 libsigcxx = throw "'libsigcxx' attribute has been removed from nixpkgs. Use a 'libsigcxx_*' attribute with an explicit ABI version instead."; # Added 2026-09-05 libSM = libsm; # Added 2026-02-04 libsmartcols = warnAlias "'util-linux' should be used instead of 'libsmartcols'" util-linux; # Added 2025-09-03 diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 118df95e2d64..96c9f9e8de6e 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -6048,8 +6048,7 @@ with pkgs; ; libsigcxx_2_0 = callPackage ../development/libraries/libsigcxx/2.0.nix { }; - - libsigcxx30 = callPackage ../development/libraries/libsigcxx/3.0.nix { }; + libsigcxx_3_0 = callPackage ../development/libraries/libsigcxx/3.0.nix { }; libtorrent-rasterbar = libtorrent-rasterbar-2_0_x; From 07387e61cb97c937899c8f9d0b75fdfad13c9b52 Mon Sep 17 00:00:00 2001 From: Tom Hunze Date: Sat, 5 Sep 2026 08:14:35 +0200 Subject: [PATCH 132/423] libsigcxx_2_0: enable structuredAttrs and strictDeps --- pkgs/development/libraries/libsigcxx/2.0.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/development/libraries/libsigcxx/2.0.nix b/pkgs/development/libraries/libsigcxx/2.0.nix index 0d72ebe9958e..260e21855ee3 100644 --- a/pkgs/development/libraries/libsigcxx/2.0.nix +++ b/pkgs/development/libraries/libsigcxx/2.0.nix @@ -12,6 +12,9 @@ stdenv.mkDerivation rec { pname = "libsigc++"; version = "2.12.1"; + __structuredAttrs = true; + strictDeps = true; + src = fetchurl { url = "mirror://gnome/sources/libsigc++/${lib.versions.majorMinor version}/libsigc++-${version}.tar.xz"; sha256 = "sha256-qdvuMjNR0Qm3ruB0qcuJyj57z4rY7e8YUfTPNZvVCEM="; From b0c699eea14eb1197f63f54beb5471da72d5a0ac Mon Sep 17 00:00:00 2001 From: Tom Hunze Date: Sat, 5 Sep 2026 08:14:43 +0200 Subject: [PATCH 133/423] libsigcxx_3_0: enable structuredAttrs and strictDeps --- pkgs/development/libraries/libsigcxx/3.0.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/development/libraries/libsigcxx/3.0.nix b/pkgs/development/libraries/libsigcxx/3.0.nix index 5f8d78897419..5a1c82cfe251 100644 --- a/pkgs/development/libraries/libsigcxx/3.0.nix +++ b/pkgs/development/libraries/libsigcxx/3.0.nix @@ -12,6 +12,9 @@ stdenv.mkDerivation (finalAttrs: { pname = "libsigc++"; version = "3.8.1"; + __structuredAttrs = true; + strictDeps = true; + src = fetchFromGitHub { owner = "libsigcplusplus"; repo = "libsigcplusplus"; From 2af6f8803af9c38cfcac7569603ad789f6cb9928 Mon Sep 17 00:00:00 2001 From: Tom Hunze Date: Sat, 5 Sep 2026 08:26:39 +0200 Subject: [PATCH 134/423] libsigcxx_{2,3}_0: move to pkgs/by-name --- .../libraries/libsigcxx => by-name/li/libsigcxx_3_0}/2.0.nix | 0 .../libsigcxx/3.0.nix => by-name/li/libsigcxx_3_0/package.nix} | 0 pkgs/top-level/all-packages.nix | 3 +-- 3 files changed, 1 insertion(+), 2 deletions(-) rename pkgs/{development/libraries/libsigcxx => by-name/li/libsigcxx_3_0}/2.0.nix (100%) rename pkgs/{development/libraries/libsigcxx/3.0.nix => by-name/li/libsigcxx_3_0/package.nix} (100%) diff --git a/pkgs/development/libraries/libsigcxx/2.0.nix b/pkgs/by-name/li/libsigcxx_3_0/2.0.nix similarity index 100% rename from pkgs/development/libraries/libsigcxx/2.0.nix rename to pkgs/by-name/li/libsigcxx_3_0/2.0.nix diff --git a/pkgs/development/libraries/libsigcxx/3.0.nix b/pkgs/by-name/li/libsigcxx_3_0/package.nix similarity index 100% rename from pkgs/development/libraries/libsigcxx/3.0.nix rename to pkgs/by-name/li/libsigcxx_3_0/package.nix diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 96c9f9e8de6e..03ed03bc3c46 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -6047,8 +6047,7 @@ with pkgs; libprom ; - libsigcxx_2_0 = callPackage ../development/libraries/libsigcxx/2.0.nix { }; - libsigcxx_3_0 = callPackage ../development/libraries/libsigcxx/3.0.nix { }; + libsigcxx_2_0 = callPackage ../by-name/li/libsigcxx_3_0/2.0.nix { }; libtorrent-rasterbar = libtorrent-rasterbar-2_0_x; From 562727f5bf955de11c65f95feff703d2f2aa378a Mon Sep 17 00:00:00 2001 From: Tom Hunze Date: Sun, 6 Sep 2026 02:14:26 +0200 Subject: [PATCH 135/423] libsigcxx_2_0: modernize --- pkgs/by-name/li/libsigcxx_3_0/2.0.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/li/libsigcxx_3_0/2.0.nix b/pkgs/by-name/li/libsigcxx_3_0/2.0.nix index 260e21855ee3..dbd05819626c 100644 --- a/pkgs/by-name/li/libsigcxx_3_0/2.0.nix +++ b/pkgs/by-name/li/libsigcxx_3_0/2.0.nix @@ -8,7 +8,7 @@ gnome, }: -stdenv.mkDerivation rec { +stdenv.mkDerivation (finalAttrs: { pname = "libsigc++"; version = "2.12.1"; @@ -16,8 +16,8 @@ stdenv.mkDerivation rec { strictDeps = true; src = fetchurl { - url = "mirror://gnome/sources/libsigc++/${lib.versions.majorMinor version}/libsigc++-${version}.tar.xz"; - sha256 = "sha256-qdvuMjNR0Qm3ruB0qcuJyj57z4rY7e8YUfTPNZvVCEM="; + url = "mirror://gnome/sources/libsigc++/${lib.versions.majorMinor finalAttrs.version}/libsigc++-${finalAttrs.version}.tar.xz"; + hash = "sha256-qdvuMjNR0Qm3ruB0qcuJyj57z4rY7e8YUfTPNZvVCEM="; }; outputs = [ @@ -48,4 +48,4 @@ stdenv.mkDerivation rec { license = lib.licenses.lgpl21Plus; platforms = lib.platforms.all; }; -} +}) From 3113b9085a18f6748d1781ecb303e53f3210fd20 Mon Sep 17 00:00:00 2001 From: whoomee Date: Sat, 29 Aug 2026 14:57:04 +0200 Subject: [PATCH 136/423] orc: 0.4.42 -> 0.4.44 --- pkgs/by-name/or/orc/package.nix | 13 ++++++++----- 1 file changed, 8 insertions(+), 5 deletions(-) diff --git a/pkgs/by-name/or/orc/package.nix b/pkgs/by-name/or/orc/package.nix index 4373c742ec9c..9e25575c2862 100644 --- a/pkgs/by-name/or/orc/package.nix +++ b/pkgs/by-name/or/orc/package.nix @@ -1,7 +1,7 @@ { lib, stdenv, - fetchurl, + fetchFromGitLab, meson, ninja, # FIXME: hotdoc errors out due to issues discovering libclang paths @@ -18,7 +18,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "orc"; - version = "0.4.42"; + version = "0.4.44"; outputs = [ "out" @@ -27,9 +27,12 @@ stdenv.mkDerivation (finalAttrs: { ++ lib.optional buildDevDoc "devdoc"; outputBin = "dev"; # compilation tools - src = fetchurl { - url = "https://gstreamer.freedesktop.org/src/orc/orc-${finalAttrs.version}.tar.xz"; - hash = "sha256-fskSq1mvPMl4dMRWpWqK4e7FIMOF7ER+ihArK9EiyQw="; + src = fetchFromGitLab { + domain = "gitlab.freedesktop.org"; + owner = "gstreamer"; + repo = "orc"; + tag = finalAttrs.version; + hash = "sha256-/fWXR9LuINXwVMXCAGVm4H6I+Lut1u43rz+xmV+5cVs="; }; postPatch = lib.optionalString (stdenv.hostPlatform.isDarwin && stdenv.hostPlatform.isx86_64) '' From f6f7fa5fb7ed2091d9cc2dbe075f9b9590b9993d Mon Sep 17 00:00:00 2001 From: whoomee Date: Sat, 29 Aug 2026 15:03:32 +0200 Subject: [PATCH 137/423] orc: set updateScript --- pkgs/by-name/or/orc/package.nix | 13 +++++++++---- 1 file changed, 9 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/or/orc/package.nix b/pkgs/by-name/or/orc/package.nix index 9e25575c2862..060c153d02f8 100644 --- a/pkgs/by-name/or/orc/package.nix +++ b/pkgs/by-name/or/orc/package.nix @@ -1,6 +1,7 @@ { lib, stdenv, + nix-update-script, fetchFromGitLab, meson, ninja, @@ -64,10 +65,14 @@ stdenv.mkDerivation (finalAttrs: { && lib.versionAtLeast stdenv.cc.version "12" ); - passthru.tests = { - inherit (gst_all_1) gst-plugins-good gst-plugins-bad gst-plugins-ugly; - inherit gnuradio vips; - qt6-qtmultimedia = qt6.qtmultimedia; + passthru = { + tests = { + inherit (gst_all_1) gst-plugins-good gst-plugins-bad gst-plugins-ugly; + inherit gnuradio vips; + qt6-qtmultimedia = qt6.qtmultimedia; + }; + + updateScript = nix-update-script { }; }; meta = { From 87a9c3a077ee82fe512268d9f1ffa7210298add1 Mon Sep 17 00:00:00 2001 From: whoomee Date: Sat, 29 Aug 2026 15:05:08 +0200 Subject: [PATCH 138/423] orc: specify and test meta.pkgConfigModules --- pkgs/by-name/or/orc/package.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/pkgs/by-name/or/orc/package.nix b/pkgs/by-name/or/orc/package.nix index 060c153d02f8..56099e52dcba 100644 --- a/pkgs/by-name/or/orc/package.nix +++ b/pkgs/by-name/or/orc/package.nix @@ -1,6 +1,7 @@ { lib, stdenv, + testers, nix-update-script, fetchFromGitLab, meson, @@ -70,6 +71,7 @@ stdenv.mkDerivation (finalAttrs: { inherit (gst_all_1) gst-plugins-good gst-plugins-bad gst-plugins-ugly; inherit gnuradio vips; qt6-qtmultimedia = qt6.qtmultimedia; + pkg-config = testers.testMetaPkgConfig finalAttrs.finalPackage; }; updateScript = nix-update-script { }; @@ -79,6 +81,10 @@ stdenv.mkDerivation (finalAttrs: { description = "Oil Runtime Compiler"; homepage = "https://gstreamer.freedesktop.org/projects/orc.html"; changelog = "https://gitlab.freedesktop.org/gstreamer/orc/-/blob/${finalAttrs.version}/RELEASE"; + pkgConfigModules = map (name: "${name}-${lib.versions.majorMinor finalAttrs.version}") [ + "orc" + "orc-test" + ]; # The source code implementing the Marsenne Twister algorithm is licensed # under the 3-clause BSD license. The rest is 2-clause BSD license. license = with lib.licenses; [ From f95cc368a1d2c05a2d0a9c76910f3ae638546012 Mon Sep 17 00:00:00 2001 From: whoomee Date: Sat, 29 Aug 2026 15:05:52 +0200 Subject: [PATCH 139/423] orc: re-enable buildDevDoc --- pkgs/by-name/or/orc/package.nix | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/or/orc/package.nix b/pkgs/by-name/or/orc/package.nix index 56099e52dcba..5468b74b990a 100644 --- a/pkgs/by-name/or/orc/package.nix +++ b/pkgs/by-name/or/orc/package.nix @@ -6,10 +6,8 @@ fetchFromGitLab, meson, ninja, - # FIXME: hotdoc errors out due to issues discovering libclang paths - # See https://github.com/NixOS/nixpkgs/issues/514723 hotdoc, - buildDevDoc ? false, + buildDevDoc ? true, # for passthru.tests gnuradio, @@ -28,6 +26,7 @@ stdenv.mkDerivation (finalAttrs: { ] ++ lib.optional buildDevDoc "devdoc"; outputBin = "dev"; # compilation tools + outputDoc = lib.optionalString buildDevDoc "devdoc"; src = fetchFromGitLab { domain = "gitlab.freedesktop.org"; From 075f08ee5b796bd910c11ee50cacbbe55779ce72 Mon Sep 17 00:00:00 2001 From: whoomee Date: Sat, 29 Aug 2026 15:06:03 +0200 Subject: [PATCH 140/423] orc: refactor mesonFlags --- pkgs/by-name/or/orc/package.nix | 13 +++++++------ 1 file changed, 7 insertions(+), 6 deletions(-) diff --git a/pkgs/by-name/or/orc/package.nix b/pkgs/by-name/or/orc/package.nix index 5468b74b990a..3b051a42f506 100644 --- a/pkgs/by-name/or/orc/package.nix +++ b/pkgs/by-name/or/orc/package.nix @@ -41,12 +41,13 @@ stdenv.mkDerivation (finalAttrs: { sed -i '/memcpy_speed/d' testsuite/meson.build ''; - mesonFlags = [ - (lib.mesonEnable "examples" false) - (lib.mesonEnable "benchmarks" false) - (lib.mesonEnable "tests" finalAttrs.finalPackage.doCheck) - (lib.mesonEnable "hotdoc" buildDevDoc) - ]; + mesonFlags = lib.mapAttrsToList lib.mesonEnable { + examples = false; + benchmarks = false; + tests = finalAttrs.finalPackage.doCheck; + hotdoc = buildDevDoc; + tools = true; + }; nativeBuildInputs = [ meson From 06674513521628b353a33c697cb9cd5d708fd91b Mon Sep 17 00:00:00 2001 From: whoomee Date: Mon, 31 Aug 2026 16:57:50 +0200 Subject: [PATCH 141/423] orc: specify meta.identifiers.cpeParts --- pkgs/by-name/or/orc/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/or/orc/package.nix b/pkgs/by-name/or/orc/package.nix index 3b051a42f506..65ce5974e3c4 100644 --- a/pkgs/by-name/or/orc/package.nix +++ b/pkgs/by-name/or/orc/package.nix @@ -91,6 +91,7 @@ stdenv.mkDerivation (finalAttrs: { bsd3 bsd2 ]; + identifiers.cpeParts = lib.meta.cpeFullVersionWithVendor "gstreamer" finalAttrs.version; platforms = lib.platforms.unix; maintainers = with lib.maintainers; [ tmarkus ]; }; From 86b171da65ed22dccd71f0bccc021270d9029ea7 Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Thu, 10 Sep 2026 19:26:18 -0400 Subject: [PATCH 142/423] Revert "meson: don't set postPatch at all if not using PyPy" This reverts commit ef3d7e646a5c29ddfbbcadf7137f46977174c39f. --- pkgs/by-name/me/meson/package.nix | 28 ++++++++++++++++------------ 1 file changed, 16 insertions(+), 12 deletions(-) diff --git a/pkgs/by-name/me/meson/package.nix b/pkgs/by-name/me/meson/package.nix index 30727c12b71b..f0d0dd59e535 100644 --- a/pkgs/by-name/me/meson/package.nix +++ b/pkgs/by-name/me/meson/package.nix @@ -70,18 +70,22 @@ python3.pkgs.buildPythonApplication (finalAttrs: { ./007-freebsd-pkgconfig-path.patch ]; - ${if python3.isPyPy then "postPatch" else null} = '' - substituteInPlace mesonbuild/modules/python.py \ - --replace-fail "PythonExternalProgram('python3', mesonlib.python_command" \ - "PythonExternalProgram('${python3.meta.mainProgram}', mesonlib.python_command" - substituteInPlace mesonbuild/modules/python3.py \ - --replace-fail "state.environment.lookup_binary_entry(mesonlib.MachineChoice.HOST, 'python3'" \ - "state.environment.lookup_binary_entry(mesonlib.MachineChoice.HOST, '${python3.meta.mainProgram}'" - substituteInPlace "test cases"/*/*/*.py "test cases"/*/*/*/*.py \ - --replace-quiet '#!/usr/bin/env python3' '#!/usr/bin/env pypy3' \ - --replace-quiet '#! /usr/bin/env python3' '#!/usr/bin/env pypy3' - chmod +x "test cases"/*/*/*.py "test cases"/*/*/*/*.py - ''; + postPatch = + if python3.isPyPy then + '' + substituteInPlace mesonbuild/modules/python.py \ + --replace-fail "PythonExternalProgram('python3', mesonlib.python_command" \ + "PythonExternalProgram('${python3.meta.mainProgram}', mesonlib.python_command" + substituteInPlace mesonbuild/modules/python3.py \ + --replace-fail "state.environment.lookup_binary_entry(mesonlib.MachineChoice.HOST, 'python3'" \ + "state.environment.lookup_binary_entry(mesonlib.MachineChoice.HOST, '${python3.meta.mainProgram}'" + substituteInPlace "test cases"/*/*/*.py "test cases"/*/*/*/*.py \ + --replace-quiet '#!/usr/bin/env python3' '#!/usr/bin/env pypy3' \ + --replace-quiet '#! /usr/bin/env python3' '#!/usr/bin/env pypy3' + chmod +x "test cases"/*/*/*.py "test cases"/*/*/*/*.py + '' + else + null; build-system = [ python3.pkgs.setuptools ]; From 53b813b1660e8ae9f62a5334a7bd89b42c7ea752 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 143/423] lldb: backport export trie fixes to LLDB 22 and older MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Older versions of LLDB crash on macOS 27 when starting a debugging session on macOS 27 due to a stack overflow in `ParseExportTries`. The fixes from LLVM 23 can’t be cherry-picked due to other changes. They have been manually backported and squashed into a single patch. --- .../backport-ParseTrieEntries-fixes.patch | 124 +++++++++++++++++ .../backport-ParseTrieEntries-fixes.patch | 125 ++++++++++++++++++ .../compilers/llvm/common/lldb/default.nix | 5 + .../compilers/llvm/common/patches.nix | 11 ++ 4 files changed, 265 insertions(+) create mode 100644 pkgs/development/compilers/llvm/18/lldb/backport-ParseTrieEntries-fixes.patch create mode 100644 pkgs/development/compilers/llvm/22/lldb/backport-ParseTrieEntries-fixes.patch diff --git a/pkgs/development/compilers/llvm/18/lldb/backport-ParseTrieEntries-fixes.patch b/pkgs/development/compilers/llvm/18/lldb/backport-ParseTrieEntries-fixes.patch new file mode 100644 index 000000000000..f165c7e9ebbe --- /dev/null +++ b/pkgs/development/compilers/llvm/18/lldb/backport-ParseTrieEntries-fixes.patch @@ -0,0 +1,124 @@ +diff --git a/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp b/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp +index 2c7005449f..e0c426afa0 100644 +--- a/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp ++++ b/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp +@@ -137,6 +137,14 @@ + using namespace lldb_private; + using namespace llvm::MachO; + ++/// Upper bound on the length of a symbol name assembled from export-trie edge ++/// labels. A corrupt trie can encode an edge label whose terminator is far ++/// away in the trie data, so a single label is many megabytes long; appending ++/// it to the running name would otherwise request an unbounded allocation. No ++/// legitimate symbol name comes close to this size. Also 1 MiB is the ++/// symbol length limit in ld. ++static constexpr size_t kMaxTrieSymbolNameLength = 1 << 20; // 1 MiB ++ + LLDB_PLUGIN_DEFINE(ObjectFileMachO) + + static void PrintRegisterValue(RegisterContext *reg_ctx, const char *name, +@@ -2050,15 +2058,21 @@ + } + }; + +-static bool ParseTrieEntries(DataExtractor &data, lldb::offset_t offset, +- const bool is_arm, addr_t text_seg_base_addr, +- std::vector &nameSlices, +- std::set &resolver_addresses, +- std::vector &reexports, +- std::vector &ext_symbols) { ++static bool ParseTrieEntriesImpl(DataExtractor &data, lldb::offset_t offset, ++ const bool is_arm, addr_t text_seg_base_addr, ++ std::string &prefix, ++ std::set &resolver_addresses, ++ std::vector &reexports, ++ std::vector &ext_symbols, ++ std::set &visited_nodes) { + if (!data.ValidOffset(offset)) + return true; + ++ // Every node in a well-formed trie is reached by exactly one path, so a node ++ // offset seen twice means the trie is corrupt. ++ if (!visited_nodes.insert(offset).second) ++ return false; ++ + // Terminal node -- end of a branch, possibly add this to + // the symbol table or resolver table. + const uint64_t terminalSize = data.GetULEB128(&offset); +@@ -2098,14 +2112,9 @@ + add_this_entry = true; + } + if (add_this_entry) { +- std::string name; +- if (!nameSlices.empty()) { +- for (auto name_slice : nameSlices) +- name.append(name_slice.data(), name_slice.size()); +- } +- if (name.size() > 1) { ++ if (prefix.size() > 1) { + // Skip the leading '_' +- e.entry.name.SetCStringWithLength(name.c_str() + 1, name.size() - 1); ++ e.entry.name.SetString(llvm::StringRef(prefix).drop_front()); + } + if (import_name) { + // Skip the leading '_' +@@ -2126,23 +2135,36 @@ + const uint8_t childrenCount = data.GetU8(&children_offset); + for (uint8_t i = 0; i < childrenCount; ++i) { + const char *cstr = data.GetCStr(&children_offset); +- if (cstr) +- nameSlices.push_back(llvm::StringRef(cstr)); +- else ++ if (!cstr) + return false; // Corrupt data ++ if (prefix.size() + llvm::StringRef(cstr).size() > kMaxTrieSymbolNameLength) ++ return false; // Corrupt data: implausibly long symbol name. ++ const size_t prevSize = prefix.size(); ++ prefix.append(cstr); + lldb::offset_t childNodeOffset = data.GetULEB128(&children_offset); +- if (childNodeOffset) { +- if (!ParseTrieEntries(data, childNodeOffset, is_arm, text_seg_base_addr, +- nameSlices, resolver_addresses, reexports, +- ext_symbols)) { +- return false; +- } +- } +- nameSlices.pop_back(); ++ // A child offset of 0 points back at the root; like any other repeated ++ // offset it is a cycle, which ParseTrieEntriesImpl rejects as corrupt. ++ if (!ParseTrieEntriesImpl(data, childNodeOffset, is_arm, text_seg_base_addr, ++ prefix, resolver_addresses, reexports, ++ ext_symbols, visited_nodes)) ++ return false; ++ prefix.resize(prevSize); + } + return true; + } + ++static bool ParseTrieEntries( ++ DataExtractor &data, const bool is_arm, lldb::addr_t text_seg_base_addr, ++ std::set &resolver_addresses, ++ std::vector &reexports, ++ std::vector &ext_symbols) { ++ lldb::offset_t offset = 0; ++ std::set visited_nodes; ++ std::string prefix; ++ return ParseTrieEntriesImpl(data, offset, is_arm, text_seg_base_addr, prefix, ++ resolver_addresses, reexports, ext_symbols, ++ visited_nodes); ++} + static SymbolType GetSymbolType(const char *&symbol_name, + bool &demangled_is_synthesized, + const SectionSP &text_section_sp, +@@ -2666,9 +2688,8 @@ + lldb::addr_t text_segment_file_addr = LLDB_INVALID_ADDRESS; + if (text_segment_sp) + text_segment_file_addr = text_segment_sp->GetFileAddress(); +- std::vector nameSlices; +- ParseTrieEntries(dyld_trie_data, 0, is_arm, text_segment_file_addr, +- nameSlices, resolver_addresses, reexport_trie_entries, ++ ParseTrieEntries(dyld_trie_data, is_arm, text_segment_file_addr, ++ resolver_addresses, reexport_trie_entries, + external_sym_trie_entries); + } + diff --git a/pkgs/development/compilers/llvm/22/lldb/backport-ParseTrieEntries-fixes.patch b/pkgs/development/compilers/llvm/22/lldb/backport-ParseTrieEntries-fixes.patch new file mode 100644 index 000000000000..312be42ec2fb --- /dev/null +++ b/pkgs/development/compilers/llvm/22/lldb/backport-ParseTrieEntries-fixes.patch @@ -0,0 +1,125 @@ +diff --git a/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp b/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp +index 0be7b4c6f8..f9d9a05920 100644 +--- a/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp ++++ b/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp +@@ -137,6 +137,14 @@ + static constexpr llvm::StringLiteral g_loader_path = "@loader_path"; + static constexpr llvm::StringLiteral g_executable_path = "@executable_path"; + ++/// Upper bound on the length of a symbol name assembled from export-trie edge ++/// labels. A corrupt trie can encode an edge label whose terminator is far ++/// away in the trie data, so a single label is many megabytes long; appending ++/// it to the running name would otherwise request an unbounded allocation. No ++/// legitimate symbol name comes close to this size. Also 1 MiB is the ++/// symbol length limit in ld. ++static constexpr size_t kMaxTrieSymbolNameLength = 1 << 20; // 1 MiB ++ + LLDB_PLUGIN_DEFINE(ObjectFileMachO) + + static void PrintRegisterValue(RegisterContext *reg_ctx, const char *name, +@@ -1994,15 +2002,21 @@ + } + }; + +-static bool ParseTrieEntries(DataExtractor &data, lldb::offset_t offset, +- const bool is_arm, addr_t text_seg_base_addr, +- std::vector &nameSlices, +- std::set &resolver_addresses, +- std::vector &reexports, +- std::vector &ext_symbols) { ++static bool ParseTrieEntriesImpl(DataExtractor &data, lldb::offset_t offset, ++ const bool is_arm, addr_t text_seg_base_addr, ++ std::string &prefix, ++ std::set &resolver_addresses, ++ std::vector &reexports, ++ std::vector &ext_symbols, ++ std::set &visited_nodes) { + if (!data.ValidOffset(offset)) + return true; + ++ // Every node in a well-formed trie is reached by exactly one path, so a node ++ // offset seen twice means the trie is corrupt. ++ if (!visited_nodes.insert(offset).second) ++ return false; ++ + // Terminal node -- end of a branch, possibly add this to + // the symbol table or resolver table. + const uint64_t terminalSize = data.GetULEB128(&offset); +@@ -2042,14 +2056,9 @@ + add_this_entry = true; + } + if (add_this_entry) { +- std::string name; +- if (!nameSlices.empty()) { +- for (auto name_slice : nameSlices) +- name.append(name_slice.data(), name_slice.size()); +- } +- if (name.size() > 1) { ++ if (prefix.size() > 1) { + // Skip the leading '_' +- e.entry.name.SetCStringWithLength(name.c_str() + 1, name.size() - 1); ++ e.entry.name.SetString(llvm::StringRef(prefix).drop_front()); + } + if (import_name) { + // Skip the leading '_' +@@ -2070,23 +2079,37 @@ + const uint8_t childrenCount = data.GetU8(&children_offset); + for (uint8_t i = 0; i < childrenCount; ++i) { + const char *cstr = data.GetCStr(&children_offset); +- if (cstr) +- nameSlices.push_back(llvm::StringRef(cstr)); +- else ++ if (!cstr) + return false; // Corrupt data ++ if (prefix.size() + llvm::StringRef(cstr).size() > kMaxTrieSymbolNameLength) ++ return false; // Corrupt data: implausibly long symbol name. ++ const size_t prevSize = prefix.size(); ++ prefix.append(cstr); + lldb::offset_t childNodeOffset = data.GetULEB128(&children_offset); +- if (childNodeOffset) { +- if (!ParseTrieEntries(data, childNodeOffset, is_arm, text_seg_base_addr, +- nameSlices, resolver_addresses, reexports, +- ext_symbols)) { +- return false; +- } +- } +- nameSlices.pop_back(); ++ // A child offset of 0 points back at the root; like any other repeated ++ // offset it is a cycle, which ParseTrieEntriesImpl rejects as corrupt. ++ if (!ParseTrieEntriesImpl(data, childNodeOffset, is_arm, text_seg_base_addr, ++ prefix, resolver_addresses, reexports, ++ ext_symbols, visited_nodes)) ++ return false; ++ prefix.resize(prevSize); + } + return true; + } + ++static bool ParseTrieEntries( ++ DataExtractor &data, const bool is_arm, lldb::addr_t text_seg_base_addr, ++ std::set &resolver_addresses, ++ std::vector &reexports, ++ std::vector &ext_symbols) { ++ lldb::offset_t offset = 0; ++ std::set visited_nodes; ++ std::string prefix; ++ return ParseTrieEntriesImpl(data, offset, is_arm, text_seg_base_addr, prefix, ++ resolver_addresses, reexports, ext_symbols, ++ visited_nodes); ++} ++ + static bool + TryParseV2ObjCMetadataSymbol(const char *&symbol_name, + const char *&symbol_name_non_abi_mangled, +@@ -2659,9 +2682,8 @@ + lldb::addr_t text_segment_file_addr = LLDB_INVALID_ADDRESS; + if (text_segment_sp) + text_segment_file_addr = text_segment_sp->GetFileAddress(); +- std::vector nameSlices; +- ParseTrieEntries(dyld_trie_data, 0, is_arm, text_segment_file_addr, +- nameSlices, resolver_addresses, reexport_trie_entries, ++ ParseTrieEntries(dyld_trie_data, is_arm, text_segment_file_addr, ++ resolver_addresses, reexport_trie_entries, + external_sym_trie_entries); + } + diff --git a/pkgs/development/compilers/llvm/common/lldb/default.nix b/pkgs/development/compilers/llvm/common/lldb/default.nix index ee927ae46601..49b9b07a4aa5 100644 --- a/pkgs/development/compilers/llvm/common/lldb/default.nix +++ b/pkgs/development/compilers/llvm/common/lldb/default.nix @@ -24,6 +24,7 @@ monorepoSrc ? null, enableManpages ? false, devExtraCmakeFlags ? [ ], + getVersionFile, versionCheckHook, }: @@ -81,6 +82,10 @@ stdenv.mkDerivation ( # Fix build with gcc15 # https://github.com/llvm/llvm-project/commit/bb59f04e7e75dcbe39f1bf952304a157f0035314 ./lldb-add-include-cstdint.patch + ] + ++ lib.optionals (lib.versionOlder (lib.versions.major release_version) "23") [ + # Backports several fixes to export trie parsing. Otherwise, LLDB crashes when starting a debugging session on macOS 27. + (getVersionFile "lldb/backport-ParseTrieEntries-fixes.patch") ]; nativeBuildInputs = [ diff --git a/pkgs/development/compilers/llvm/common/patches.nix b/pkgs/development/compilers/llvm/common/patches.nix index 1fb61da6b7bf..5eed9b45570c 100644 --- a/pkgs/development/compilers/llvm/common/patches.nix +++ b/pkgs/development/compilers/llvm/common/patches.nix @@ -20,6 +20,17 @@ path = ../18; } ]; + "lldb/backport-ParseTrieEntries-fixes.patch" = [ + { + before = "22"; + path = ../18; + } + { + after = "22"; + before = "23"; + path = ../22; + } + ]; "llvm/backport-darwin-triple-parsing.patch" = [ { after = "18"; From 913c7c9d08665de2619ffbbb2168cec0310400e4 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 11 Sep 2026 01:16:42 +0000 Subject: [PATCH 144/423] unixodbcDrivers.psql: 18.00.0002 -> 18.00.0003 --- pkgs/by-name/ps/psqlodbc/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ps/psqlodbc/package.nix b/pkgs/by-name/ps/psqlodbc/package.nix index b38c756eee66..47522cace89a 100644 --- a/pkgs/by-name/ps/psqlodbc/package.nix +++ b/pkgs/by-name/ps/psqlodbc/package.nix @@ -18,13 +18,13 @@ assert lib.xor withLibiodbc withUnixODBC; stdenv.mkDerivation (finalAttrs: { pname = "psqlodbc"; - version = "18.00.0002"; + version = "18.00.0003"; src = fetchFromGitHub { owner = "postgresql-interfaces"; repo = "psqlodbc"; tag = "REL-${lib.replaceString "." "_" finalAttrs.version}"; - hash = "sha256-qzbyo9P/o784Ux3KDA8NDMbcm0EbnfG8LiBLRk6n698="; + hash = "sha256-U3ZipJFvmhIEtaSCsTQw6BrH7QG02HlJnGOVVKMF3lk="; }; buildInputs = [ From b1a505fe964264c673a3c00f926383ec7494aa7a Mon Sep 17 00:00:00 2001 From: whispers Date: Thu, 10 Sep 2026 15:45:58 -0400 Subject: [PATCH 145/423] util-linux: do not run unnecessary autoreconf since #402852 (and made unconditional in 41205c0e6c894e01be1958b323eb015f95076caf), we run autoreconf for util-linux. this is because we needed to patch configure.ac. this is no longer the case, as the patch for which we did this was accepted upstream and we've had it since v2.42: https://lore.kernel.org/util-linux/20250501075806.88759-1-hi@alyssa.is/. accordingly, we can now remove this if we still want to autoreconf for some reason, despite it not being needed, we should at least unpin automake116x, as we have no reason to require an old automake anymore. --- pkgs/by-name/ut/util-linux/package.nix | 4 ---- 1 file changed, 4 deletions(-) diff --git a/pkgs/by-name/ut/util-linux/package.nix b/pkgs/by-name/ut/util-linux/package.nix index 56ada6d03da3..6daa0d3f3ca6 100644 --- a/pkgs/by-name/ut/util-linux/package.nix +++ b/pkgs/by-name/ut/util-linux/package.nix @@ -3,8 +3,6 @@ stdenv, fetchurl, pkg-config, - autoconf, - automake116x, zlib, shadow, capabilitiesSupport ? stdenv.hostPlatform.isLinux, @@ -160,8 +158,6 @@ stdenv.mkDerivation (finalAttrs: { ]; nativeBuildInputs = [ - autoconf - automake116x installShellFiles pkg-config ] From 9e8378652d9fbaaa5238a6d782eeb0d78ad57700 Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Fri, 11 Sep 2026 09:59:01 +0200 Subject: [PATCH 146/423] protobuf: fix typo in `pkgConfigModules` --- pkgs/development/libraries/protobuf/generic.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/development/libraries/protobuf/generic.nix b/pkgs/development/libraries/protobuf/generic.nix index 958ef2b7d19d..3e3d91a90b38 100644 --- a/pkgs/development/libraries/protobuf/generic.nix +++ b/pkgs/development/libraries/protobuf/generic.nix @@ -209,7 +209,7 @@ stdenv.mkDerivation (finalAttrs: { mainProgram = "protoc"; pkgConfigModules = [ "protobuf" - "protobuf_lite" + "protobuf-lite" ] ++ lib.optionals (lib.versionAtLeast version "22") [ "utf8_range" From 723f7f655bd96e076550e3ae1832e414a3e14141 Mon Sep 17 00:00:00 2001 From: teutat3s <10206665+teutat3s@users.noreply.github.com> Date: Thu, 10 Sep 2026 10:26:42 +0200 Subject: [PATCH 147/423] electron: fix update script https://github.com/NixOS/nixpkgs/pull/555729 changed yarn hashes but didn't apply the changes to the electron update script. --- pkgs/development/tools/electron/update.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/tools/electron/update.py b/pkgs/development/tools/electron/update.py index ad6124847afb..9f8d3cadae36 100755 --- a/pkgs/development/tools/electron/update.py +++ b/pkgs/development/tools/electron/update.py @@ -118,9 +118,9 @@ def get_chromium_gn_source(chromium_tag: str) -> dict: def get_electron_yarn_data(electron_tag: str) -> dict: print(f"yarn-berry-fetcher prefetch", file=sys.stderr) with tempfile.TemporaryDirectory() as tmp_dir: - print(f"Patching yarn.lock for yarn 4.14 support", file=sys.stderr) + print(f"Patching yarn.lock for yarn 4.18 support", file=sys.stderr) yarn_lock_file=get_electron_file(electron_tag, "yarn.lock") - patched_yarn_lock_file=yarn_lock_file.replace('version: 8', 'version: 9', count=1) + patched_yarn_lock_file=yarn_lock_file.replace('version: 8', 'version: 10', count=1) with open(tmp_dir + "/yarn.lock", "w") as f: f.write(patched_yarn_lock_file) missing_hashes_str = ( From 31e7b77199bbdd2d5a8fbfad9d8cef585422acfb Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Fri, 11 Sep 2026 11:13:41 +0200 Subject: [PATCH 148/423] protobuf: add `proto` output to fix `protobufc` build --- .../libraries/protobuf/generic.nix | 33 +++++++++++++++++++ 1 file changed, 33 insertions(+) diff --git a/pkgs/development/libraries/protobuf/generic.nix b/pkgs/development/libraries/protobuf/generic.nix index 958ef2b7d19d..d299f43ba9ce 100644 --- a/pkgs/development/libraries/protobuf/generic.nix +++ b/pkgs/development/libraries/protobuf/generic.nix @@ -41,8 +41,24 @@ stdenv.mkDerivation (finalAttrs: { "out" "lib" "dev" + "proto" ]; + outputChecks = { + out.disallowedReferences = [ + "dev" + ]; + lib.disallowedReferences = [ + "out" + "dev" + ]; + proto.disallowedReferences = [ + "out" + "lib" + "dev" + ]; + }; + patches = lib.optionals (lib.versionOlder version "22") [ # fix protobuf-targets.cmake installation paths, and allow for CMAKE_INSTALL_LIBDIR to be absolute @@ -179,6 +195,23 @@ stdenv.mkDerivation (finalAttrs: { GTEST_DEATH_TEST_STYLE = "threadsafe"; }; + # protoc expects to find `.proto` files relative to itself, so we put those to a separate output and add symlinks. + postFixup = '' + pushd "$dev" > /dev/null + + find include -name '*.proto' -print0 | while IFS= read -r -d ''' FILE; do + mkdir -p "$proto/$(dirname "$FILE")" + mkdir -p "$out/$(dirname "$FILE")" + + mv "$FILE" "$proto/$FILE" + + ln -s "$proto/$FILE" "$out/$FILE" + ln -s "$proto/$FILE" "$dev/$FILE" + done + + popd > /dev/null + ''; + passthru = { tests = { pythonProtobuf = python3.pkgs.protobuf; From d9d2e944dc2da2cab78f40b9759bb9b9327a202b Mon Sep 17 00:00:00 2001 From: K900 Date: Fri, 11 Sep 2026 13:07:17 +0300 Subject: [PATCH 149/423] qt6.qtdeclarative: backport change recommended by KDE --- .../libraries/qt-6/modules/qtdeclarative/default.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/pkgs/development/libraries/qt-6/modules/qtdeclarative/default.nix b/pkgs/development/libraries/qt-6/modules/qtdeclarative/default.nix index 786229c5651b..36089460fc4e 100644 --- a/pkgs/development/libraries/qt-6/modules/qtdeclarative/default.nix +++ b/pkgs/development/libraries/qt-6/modules/qtdeclarative/default.nix @@ -43,6 +43,12 @@ qtModule { hash = "sha256-ESy35OlmsvI4yFQ/rFT8oelOUBCwCmlcbQJvwcTrCig="; revert = true; }) + + # backport fix recommended by KDE + (fetchpatch { + url = "https://codereview.qt-project.org/changes/qt%2Fqtdeclarative~768697/revisions/4/patch?download&raw"; + hash = "sha256-HiHAWbLr2MaZpw+yaA+JIveYory5cWkL2ZNf3zveYX4="; + }) ]; cmakeFlags = [ From ae02526138c4334d86b87255fc20b722708ec341 Mon Sep 17 00:00:00 2001 From: whispers Date: Fri, 28 Aug 2026 17:15:50 -0400 Subject: [PATCH 150/423] libgcrypt: 1.12.2 -> 1.12.4 https://lists.gnu.org/archive/html/info-gnu/2026-08/msg00007.html https://lists.gnu.org/archive/html/info-gnu/2026-09/msg00002.html --- pkgs/by-name/li/libgcrypt/package.nix | 15 ++------------- 1 file changed, 2 insertions(+), 13 deletions(-) diff --git a/pkgs/by-name/li/libgcrypt/package.nix b/pkgs/by-name/li/libgcrypt/package.nix index 0e23409dcd67..940b1d861da7 100644 --- a/pkgs/by-name/li/libgcrypt/package.nix +++ b/pkgs/by-name/li/libgcrypt/package.nix @@ -2,7 +2,6 @@ lib, stdenv, fetchurl, - fetchpatch, gettext, libgpg-error, enableCapabilities ? false, @@ -18,23 +17,13 @@ assert enableCapabilities -> stdenv.hostPlatform.isLinux; stdenv.mkDerivation (finalAttrs: { pname = "libgcrypt"; - version = "1.12.2"; + version = "1.12.4"; src = fetchurl { url = "mirror://gnupg/libgcrypt/libgcrypt-${finalAttrs.version}.tar.bz2"; - hash = "sha256-fOM8JJIiGgQ2+WqFACFenz49y1/SanV81BXnqEO6vV4="; + hash = "sha256-139o9Ih5UQ55ovZZd8zGiYF4HqCSPlvf+sKhk+o9Zg4="; }; - patches = lib.optionals stdenv.hostPlatform.isRiscV64 [ - # Remove in next release - # https://github.com/gpg/libgcrypt/commit/3f684fc6ab3ac98320e245a06b3563ad37ec56f5 - # zvkned AES corrupts CBC/CFB/CTR/OCB/XTS output on VLEN>128 hardware - (fetchpatch { - url = "https://github.com/gpg/libgcrypt/commit/3f684fc6ab3ac98320e245a06b3563ad37ec56f5.patch"; - hash = "sha256-1LSrIwsN0n5IBRDZ+9MJTEjzY+/T6LQO6hX1ke8hSuc="; - }) - ]; - outputs = [ "bin" "lib" From 70a62b6872a488804d7f63ff8e310f56d9a0b8ad Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Fri, 11 Sep 2026 08:51:50 -0700 Subject: [PATCH 151/423] python3Packages.pyjwt: 2.13.0 -> 2.14.0 Diff: https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0 Changelog: https://github.com/jpadilla/pyjwt/blob/2.14.0/CHANGELOG.rst --- pkgs/development/python-modules/pyjwt/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/pyjwt/default.nix b/pkgs/development/python-modules/pyjwt/default.nix index 74754630a145..ae8a5353a84d 100644 --- a/pkgs/development/python-modules/pyjwt/default.nix +++ b/pkgs/development/python-modules/pyjwt/default.nix @@ -13,14 +13,14 @@ buildPythonPackage rec { pname = "pyjwt"; - version = "2.13.0"; + version = "2.14.0"; pyproject = true; src = fetchFromGitHub { owner = "jpadilla"; repo = "pyjwt"; tag = version; - hash = "sha256-q4ynXCJVDsyZh70439dloyWgRTLVm+elDOahUVOT5vA="; + hash = "sha256-SxJ2GQt1pfm8iAeTB2RmH2kliGeQ6whkM5nuesI1s/U="; }; outputs = [ From 409bbcafb75e03c239eea5364254d736ed1bac5b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Fri, 11 Sep 2026 08:54:39 -0700 Subject: [PATCH 152/423] python3Packages.pyjwt: use finalAttrs --- pkgs/development/python-modules/pyjwt/default.nix | 13 ++++++++----- 1 file changed, 8 insertions(+), 5 deletions(-) diff --git a/pkgs/development/python-modules/pyjwt/default.nix b/pkgs/development/python-modules/pyjwt/default.nix index ae8a5353a84d..d1267cf08628 100644 --- a/pkgs/development/python-modules/pyjwt/default.nix +++ b/pkgs/development/python-modules/pyjwt/default.nix @@ -11,7 +11,7 @@ oauthlib, }: -buildPythonPackage rec { +buildPythonPackage (finalAttrs: { pname = "pyjwt"; version = "2.14.0"; pyproject = true; @@ -19,7 +19,7 @@ buildPythonPackage rec { src = fetchFromGitHub { owner = "jpadilla"; repo = "pyjwt"; - tag = version; + tag = finalAttrs.version; hash = "sha256-SxJ2GQt1pfm8iAeTB2RmH2kliGeQ6whkM5nuesI1s/U="; }; @@ -38,7 +38,10 @@ buildPythonPackage rec { optional-dependencies.crypto = [ cryptography ]; - nativeCheckInputs = [ pytestCheckHook ] ++ (lib.concatAttrValues optional-dependencies); + nativeCheckInputs = [ + pytestCheckHook + ] + ++ (lib.concatAttrValues finalAttrs.passthru.optional-dependencies); disabledTests = [ # requires internet connection @@ -52,10 +55,10 @@ buildPythonPackage rec { }; meta = { - changelog = "https://github.com/jpadilla/pyjwt/blob/${version}/CHANGELOG.rst"; + changelog = "https://github.com/jpadilla/pyjwt/blob/${finalAttrs.src.tag}/CHANGELOG.rst"; description = "JSON Web Token implementation in Python"; homepage = "https://github.com/jpadilla/pyjwt"; license = lib.licenses.mit; maintainers = with lib.maintainers; [ prikhi ]; }; -} +}) From 387081f737e96db3794ca8459ba5e73930a7efbb Mon Sep 17 00:00:00 2001 From: ajs124 Date: Sat, 12 Sep 2026 08:08:30 +0200 Subject: [PATCH 153/423] tzdata: 2026c -> 2026d https://lists.iana.org/hyperkitty/list/tz-announce@iana.org/thread/L4IGHJRBUQR53F7RTEHM5IS7ZMBR3YXP/ --- pkgs/by-name/tz/tzdata/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/tz/tzdata/package.nix b/pkgs/by-name/tz/tzdata/package.nix index 7e3f8f38535d..3cab180bbc02 100644 --- a/pkgs/by-name/tz/tzdata/package.nix +++ b/pkgs/by-name/tz/tzdata/package.nix @@ -8,16 +8,16 @@ stdenv.mkDerivation (finalAttrs: { pname = "tzdata"; - version = "2026c"; + version = "2026d"; srcs = [ (fetchurl { url = "https://data.iana.org/time-zones/releases/tzdata${finalAttrs.version}.tar.gz"; - hash = "sha256-5KF4pEd/PQ6nfMMYKP9yqjj+/41hqhPn6Z4ULp2QK+Q="; + hash = "sha256-DLKqjjM8PcBJutxCoMYfIZh7jNROEH+pALrXZKrMd2c="; }) (fetchurl { url = "https://data.iana.org/time-zones/releases/tzcode${finalAttrs.version}.tar.gz"; - hash = "sha256-sc/8Os5MTHzQ77ovet2G7D0LedpIvPA1gmcf08j+rOg="; + hash = "sha256-L1yff+Kea4y4Y1g2Z4hLjOF7CkhTVaBUtZHGvfzYF5E="; }) ]; From 6d7da008fe3a3e5be1c3bb991c05bbc03dd0d648 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 12 Sep 2026 12:34:32 +0000 Subject: [PATCH 154/423] mpi: 5.0.10 -> 5.0.11 --- pkgs/by-name/op/openmpi/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/op/openmpi/package.nix b/pkgs/by-name/op/openmpi/package.nix index 66f58919896c..4f809f56094f 100644 --- a/pkgs/by-name/op/openmpi/package.nix +++ b/pkgs/by-name/op/openmpi/package.nix @@ -45,11 +45,11 @@ assert cudaSupport -> !rocmSupport; stdenv.mkDerivation (finalAttrs: { pname = "openmpi"; - version = "5.0.10"; + version = "5.0.11"; src = fetchurl { url = "https://www.open-mpi.org/software/ompi/v${lib.versions.majorMinor finalAttrs.version}/downloads/openmpi-${finalAttrs.version}.tar.bz2"; - sha256 = "sha256-Cs7MT8IY5d69vLikHRgsaw8dKTkwFe12OyqR1dc3TMY="; + sha256 = "sha256-cfQk150IotqRWeOrK9xGcgRXVgLCdE1E0aqYJ7xVvY4="; }; postPatch = '' From 70f533105ebe9315ad64afdbee10a1ff1bcc8dd1 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Sat, 12 Sep 2026 21:40:26 +0200 Subject: [PATCH 155/423] luit: enable structuredAttrs --- pkgs/by-name/lu/luit/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/lu/luit/package.nix b/pkgs/by-name/lu/luit/package.nix index 86cc09527242..765a34ecf46f 100644 --- a/pkgs/by-name/lu/luit/package.nix +++ b/pkgs/by-name/lu/luit/package.nix @@ -31,6 +31,8 @@ stdenv.mkDerivation (finalAttrs: { update-source-version luit "$version" ''; + __structuredAttrs = true; + meta = { description = "Filter between an arbitrary application and a UTF-8 terminal emulator converting the output and input between the locale's encoding and UTF-8"; homepage = "https://invisible-island.net/luit/"; From 52487795dfe2801fb3050b82e77fe172d509c955 Mon Sep 17 00:00:00 2001 From: Harinn Date: Thu, 13 Aug 2026 22:47:03 +0700 Subject: [PATCH 156/423] python3Packages.defcon: migrate to pyproject As part of https://github.com/NixOS/nixpkgs/issues/515974 --- pkgs/development/python-modules/defcon/default.nix | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/pkgs/development/python-modules/defcon/default.nix b/pkgs/development/python-modules/defcon/default.nix index 422f479ed4b4..f7ba5f176b0e 100644 --- a/pkgs/development/python-modules/defcon/default.nix +++ b/pkgs/development/python-modules/defcon/default.nix @@ -2,6 +2,7 @@ lib, buildPythonPackage, fetchPypi, + setuptools, setuptools-scm, fonttools, fontpens, @@ -11,16 +12,19 @@ buildPythonPackage rec { pname = "defcon"; version = "0.12.2"; - format = "setuptools"; + pyproject = true; src = fetchPypi { inherit pname version; hash = "sha256-Jd/n/QFSzPKSyxkNGSikfViImcILBGhUKT4DnhyT5eA="; }; - nativeBuildInputs = [ setuptools-scm ]; + build-system = [ + setuptools + setuptools-scm + ]; - propagatedBuildInputs = [ + dependencies = [ fonttools ] ++ fonttools.optional-dependencies.ufo From b58a7212341b9850876b9647f191028791d1b522 Mon Sep 17 00:00:00 2001 From: Harinn Date: Thu, 13 Aug 2026 22:49:28 +0700 Subject: [PATCH 157/423] python3Packages.defcon: modernize --- pkgs/development/python-modules/defcon/default.nix | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/pkgs/development/python-modules/defcon/default.nix b/pkgs/development/python-modules/defcon/default.nix index f7ba5f176b0e..94776ee4149d 100644 --- a/pkgs/development/python-modules/defcon/default.nix +++ b/pkgs/development/python-modules/defcon/default.nix @@ -9,13 +9,15 @@ pytestCheckHook, }: -buildPythonPackage rec { +buildPythonPackage (finalAttrs: { pname = "defcon"; version = "0.12.2"; pyproject = true; + __structuredAttrs = true; + src = fetchPypi { - inherit pname version; + inherit (finalAttrs) pname version; hash = "sha256-Jd/n/QFSzPKSyxkNGSikfViImcILBGhUKT4DnhyT5eA="; }; @@ -42,8 +44,8 @@ buildPythonPackage rec { meta = { description = "Set of UFO based objects for use in font editing applications"; homepage = "https://github.com/robotools/defcon"; - changelog = "https://github.com/robotools/defcon/releases/tag/${version}"; + changelog = "https://github.com/robotools/defcon/releases/tag/${finalAttrs.version}"; license = lib.licenses.mit; maintainers = with lib.maintainers; [ sternenseemann ]; }; -} +}) From 2fbdf98fbc09900ecc2526e8c0aa134e43745de2 Mon Sep 17 00:00:00 2001 From: Tom Hunze Date: Sat, 12 Sep 2026 02:55:32 +0200 Subject: [PATCH 158/423] ibus: fix crashes with latest gtk GTK issue: https://gitlab.gnome.org/GNOME/gtk/-/work_items/8341 Upstream PR: https://github.com/ibus/ibus/pull/2929 --- pkgs/by-name/ib/ibus/package.nix | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/pkgs/by-name/ib/ibus/package.nix b/pkgs/by-name/ib/ibus/package.nix index b164f6ead3a7..97f2cb2b2188 100644 --- a/pkgs/by-name/ib/ibus/package.nix +++ b/pkgs/by-name/ib/ibus/package.nix @@ -3,6 +3,7 @@ stdenv, replaceVars, fetchFromGitHub, + fetchpatch, autoreconfHook, gettext, makeWrapper, @@ -88,6 +89,15 @@ stdenv.mkDerivation (finalAttrs: { PYTHON = null; }) ./build-without-dbus-launch.patch + + # Fix crashes in `gtk_im_multicontext_set_delegate` with latest GTK + # GTK issue: https://gitlab.gnome.org/GNOME/gtk/-/work_items/8341 + # Upstream PR: https://github.com/ibus/ibus/pull/2929 + (fetchpatch { + name = "fix-gtk-crashes.patch"; + url = "https://github.com/ibus/ibus/commit/c534999a9dbea2666864250d74e058ecfb46e76f.patch"; + hash = "sha256-1h48hvdrDh2Qh4+SufL147CxlfiwvP/Jv509X0WnbrA="; + }) ]; outputs = [ From 6e699d9302bdc7b59cc1159ced8e6366afe3a702 Mon Sep 17 00:00:00 2001 From: Hythera <87016780+Hythera@users.noreply.github.com> Date: Sat, 1 Aug 2026 18:28:05 +0200 Subject: [PATCH 159/423] poppler: 26.06.0 -> 26.09.0 changelog: https://gitlab.freedesktop.org/poppler/poppler/-/raw/poppler-26.09.0/NEWS diff: https://gitlab.freedesktop.org/poppler/poppler/-/compare/poppler-26.06.0...poppler-26.09.0 --- .../development/libraries/poppler/default.nix | 27 +++++++++---------- 1 file changed, 12 insertions(+), 15 deletions(-) diff --git a/pkgs/development/libraries/poppler/default.nix b/pkgs/development/libraries/poppler/default.nix index 580d1fbfb73e..7313f9c8eda0 100644 --- a/pkgs/development/libraries/poppler/default.nix +++ b/pkgs/development/libraries/poppler/default.nix @@ -3,7 +3,6 @@ stdenv, fetchurl, fetchFromGitLab, - fetchpatch, cairo, clang-tools, cmake, @@ -12,12 +11,14 @@ fontconfig, freetype, glib, + harfbuzz, lcms, libiconv, libintl, libjpeg, libtiff, ninja, + noto-fonts-cjk-sans, openjpeg, pkg-config, python3, @@ -58,13 +59,13 @@ let domain = "gitlab.freedesktop.org"; owner = "poppler"; repo = "test"; - rev = "f0068e9c530017ad811d1f28b95f9b7f59264e37"; - hash = "sha256-Xf8duSh0r1o09b5BKB7mBvzrMfXYlzTuTOuK2ZCeItc="; + rev = "48b6219b84fc0a708040cb279d51095cc4e1c603"; + hash = "sha256-2eH4dZs2J0CeTWrXOYEHb0Xnpfa7tX8mi7AX2E9D41U="; }; in stdenv.mkDerivation (finalAttrs: { pname = "poppler-${suffix}"; - version = "26.06.0"; + version = "26.09.0"; outputs = [ "out" @@ -73,19 +74,9 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "https://poppler.freedesktop.org/poppler-${finalAttrs.version}.tar.xz"; - hash = "sha256-TLTlo9yMte7HUciiPIuhn2H5be3AzQfSruawyOLPa6Q="; + hash = "sha256-gFnq22gFNAdo8TjEZbV/gWTJK0oHc8N+8DHqbA2Yey4="; }; - patches = [ - # Backports Darwin crash fix from upstream - # https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1743 - (fetchpatch { - name = "darwin-mutex-lock-crash.patch"; - url = "https://gitlab.freedesktop.org/poppler/poppler/-/commit/08f4bca6a669f9fce75dbab743db559a86591738.patch"; - hash = "sha256-+eWqVK/v3Ys9k2+z/dCoS2o82m039UER1StMUW4PIgM="; - }) - ]; - nativeBuildInputs = [ cmake ninja @@ -105,6 +96,7 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ boost + harfbuzz libiconv libintl ] @@ -137,6 +129,11 @@ stdenv.mkDerivation (finalAttrs: { gpgme ]; + # Test `fontsubsetting-basic-test` needs a font that supports cjk. + nativeCheckInputs = [ + noto-fonts-cjk-sans + ]; + cmakeFlags = [ (mkFlag true "UNSTABLE_API_ABI_HEADERS") # previously "XPDF_HEADERS" (mkFlag (!minimal) "GLIB") From 4077f6f4f36d9a409dca4808a9359d07843e2beb Mon Sep 17 00:00:00 2001 From: Hythera <87016780+Hythera@users.noreply.github.com> Date: Sat, 1 Aug 2026 18:48:05 +0200 Subject: [PATCH 160/423] inkscape: fix build with poppler 26.07.0 --- .../graphics/inkscape/default.nix | 2 + .../inkscape/fix-build-poppler-26.07.0.patch | 331 ++++++++++++++++++ 2 files changed, 333 insertions(+) create mode 100644 pkgs/applications/graphics/inkscape/fix-build-poppler-26.07.0.patch diff --git a/pkgs/applications/graphics/inkscape/default.nix b/pkgs/applications/graphics/inkscape/default.nix index ccea323f700b..473a01ed58ae 100644 --- a/pkgs/applications/graphics/inkscape/default.nix +++ b/pkgs/applications/graphics/inkscape/default.nix @@ -111,6 +111,8 @@ stdenv.mkDerivation (finalAttrs: { }) # https://gitlab.com/inkscape/inkscape/-/merge_requests/7968 ./fix-build-poppler-26.06.0.patch + # https://gitlab.com/inkscape/inkscape/-/merge_requests/8034 + ./fix-build-poppler-26.07.0.patch ]; postPatch = '' diff --git a/pkgs/applications/graphics/inkscape/fix-build-poppler-26.07.0.patch b/pkgs/applications/graphics/inkscape/fix-build-poppler-26.07.0.patch new file mode 100644 index 000000000000..ddcc4dbb386c --- /dev/null +++ b/pkgs/applications/graphics/inkscape/fix-build-poppler-26.07.0.patch @@ -0,0 +1,331 @@ +From fc52525f8d8d7d3e772c5bfa1bdfe9b33c7f9709 Mon Sep 17 00:00:00 2001 +From: KrIr17 +Date: Sat, 4 Jul 2026 14:07:44 +0200 +Subject: [PATCH] Fix building with Poppler 26.07.0 + +1. `arrayGetfoo()` to `getArray()->getFoo()` [1] +2. `streamGetFoo()` to `getStream()->getFoo()` [2] +3. indextolabel now requires an `std::string *` and not `GooString *` + introduced _POPPLER_STRING_26_7 that changes accordingly. + +Relevant poppler commits: + +[1] [Remove Object::arrayGetNF](https://gitlab.freedesktop.org/poppler/poppler/-/commit/d9ffc4c29d1975a5c81d6bac9d8a1b6dc5aa1f50): Technically only arrayGetNF was removed, but perusing the commit shows that all `arrayGetFoo` are being changed. I assume they are slated for removal in future releases. + +[2] [Remove Object::streamGetDict](gitlab.freedesktop.org/poppler/poppler/-/commit/87edb5a5c40e67e782e54a14a2251547b4acdfb5) + +[3] [Use std::string instead of GooString for label](https://gitlab.freedesktop.org/poppler/poppler/-/commit/9e34004aae04064f1b798b5e711e13d0dddacf9e) +--- + src/extension/internal/pdfinput/pdf-input.cpp | 5 +- + .../internal/pdfinput/pdf-parser.cpp | 54 +++++++++---------- + .../pdfinput/poppler-transition-api.h | 6 +++ + .../internal/pdfinput/poppler-utils.cpp | 29 +++++----- + .../internal/pdfinput/poppler-utils.h | 1 + + 5 files changed, 54 insertions(+), 41 deletions(-) + +diff --git a/src/extension/internal/pdfinput/pdf-input.cpp b/src/extension/internal/pdfinput/pdf-input.cpp +index 4030a95882..0d46a0577f 100644 +--- a/src/extension/internal/pdfinput/pdf-input.cpp ++++ b/src/extension/internal/pdfinput/pdf-input.cpp +@@ -891,9 +891,10 @@ PdfInput::add_builder_page(std::shared_ptrpdf_doc, SvgBuilder *builder, + + // Parse the annotations + if (auto annots = page->getAnnotsObject(); annots.isArray()) { +- auto const size = annots.arrayGetLength(); ++ auto* annotsArray = annots.getArray(); ++ auto const size = annotsArray->getLength(); + for (int i = 0; i < size; i++) { +- pdf_parser.build_annots(annots.arrayGet(i), page_num); ++ pdf_parser.build_annots(annotsArray->get(i), page_num); + } + } + } +diff --git a/src/extension/internal/pdfinput/pdf-parser.cpp b/src/extension/internal/pdfinput/pdf-parser.cpp +index 86fc51b1f2..fac5326988 100644 +--- a/src/extension/internal/pdfinput/pdf-parser.cpp ++++ b/src/extension/internal/pdfinput/pdf-parser.cpp +@@ -289,8 +289,8 @@ PdfParser::PdfParser(std::shared_ptr pdf_doc, Inkscape::Extension::Inter + if (page) { + // Increment the page building here and set page label + Catalog *catalog = pdf_doc->getCatalog(); +- GooString *label = new GooString(""); +- catalog->indexToLabel(page->getNum() - 1, label); ++ _POPPLER_STRING_26_7 label; ++ catalog->indexToLabel(page->getNum() - 1, &label); + builder->pushPage(getString(label), state); + } + +@@ -374,8 +374,8 @@ void PdfParser::parse(Object *obj, GBool topLevel) { + Object obj2; + + if (obj->isArray()) { +- for (int i = 0; i < obj->arrayGetLength(); ++i) { +- _POPPLER_CALL_ARGS(obj2, obj->arrayGet, i); ++ for (int i = 0; i < obj->getArray()->getLength(); ++i) { ++ _POPPLER_CALL_ARGS(obj2, obj->getArray()->get, i); + if (!obj2.isStream()) { + error(errInternal, -1, "Weird page contents"); + _POPPLER_FREE(obj2); +@@ -782,8 +782,8 @@ void PdfParser::opSetExtGState(Object args[], int /*numArgs*/) + for (int &i : backdropColor.c) { + i = 0; + } +- for (int i = 0; i < obj3.arrayGetLength() && i < gfxColorMaxComps; ++i) { +- _POPPLER_CALL_ARGS(obj4, obj3.arrayGet, i); ++ for (int i = 0; i < obj3.getArray()->getLength() && i < gfxColorMaxComps; ++i) { ++ _POPPLER_CALL_ARGS(obj4, obj3.getArray()->get, i); + if (obj4.isNum()) { + backdropColor.c[i] = dblToCol(obj4.getNum()); + } +@@ -792,7 +792,7 @@ void PdfParser::opSetExtGState(Object args[], int /*numArgs*/) + } + _POPPLER_FREE(obj3); + if (_POPPLER_CALL_ARGS_DEREF(obj3, obj2.dictLookup, "G").isStream()) { +- if (_POPPLER_CALL_ARGS_DEREF(obj4, obj3.streamGetDict()->lookup, "Group").isDict()) { ++ if (_POPPLER_CALL_ARGS_DEREF(obj4, obj3.getStream()->getDict()->lookup, "Group").isDict()) { + std::unique_ptr blendingColorSpace; + GBool isolated = gFalse; + GBool knockout = gFalse; +@@ -855,7 +855,7 @@ void PdfParser::doSoftMask(Object *str, GBool alpha, + } + + // get stream dict +- dict = str->streamGetDict(); ++ dict = str->getStream()->getDict(); + + // check form type + _POPPLER_CALL_ARGS(obj1, dict->lookup, "FormType"); +@@ -872,7 +872,7 @@ void PdfParser::doSoftMask(Object *str, GBool alpha, + return; + } + for (i = 0; i < 4; ++i) { +- _POPPLER_CALL_ARGS(obj2, obj1.arrayGet, i); ++ _POPPLER_CALL_ARGS(obj2, obj1.getArray()->get, i); + bbox[i] = obj2.getNum(); + _POPPLER_FREE(obj2); + } +@@ -882,7 +882,7 @@ void PdfParser::doSoftMask(Object *str, GBool alpha, + _POPPLER_CALL_ARGS(obj1, dict->lookup, "Matrix"); + if (obj1.isArray()) { + for (i = 0; i < 6; ++i) { +- _POPPLER_CALL_ARGS(obj2, obj1.arrayGet, i); ++ _POPPLER_CALL_ARGS(obj2, obj1.getArray()->get, i); + m[i] = obj2.getNum(); + _POPPLER_FREE(obj2); + } +@@ -2396,7 +2396,7 @@ void PdfParser::opXObject(Object args[], int /*numArgs*/) + } + + //add layer at root if xObject has type OCG +- _POPPLER_CALL_ARGS(obj2, obj1.streamGetDict()->lookup, "OC"); ++ _POPPLER_CALL_ARGS(obj2, obj1.getStream()->getDict()->lookup, "OC"); + if(obj2.isDict()){ + auto type_dict = obj2.getDict(); + if (type_dict->lookup("Type").isName("OCG")) { +@@ -2406,7 +2406,7 @@ void PdfParser::opXObject(Object args[], int /*numArgs*/) + } + } + +- _POPPLER_CALL_ARGS(obj2, obj1.streamGetDict()->lookup, "Subtype"); ++ _POPPLER_CALL_ARGS(obj2, obj1.getStream()->getDict()->lookup, "Subtype"); + if (obj2.isName(const_cast("Image"))) { + _POPPLER_CALL_ARGS(refObj, res->lookupXObjectNF, name); + doImage(&refObj, obj1.getStream(), gFalse); +@@ -2414,7 +2414,7 @@ void PdfParser::opXObject(Object args[], int /*numArgs*/) + } else if (obj2.isName(const_cast("Form"))) { + doForm(&obj1); + } else if (obj2.isName(const_cast("PS"))) { +- _POPPLER_CALL_ARGS(obj3, obj1.streamGetDict()->lookup, "Level1"); ++ _POPPLER_CALL_ARGS(obj3, obj1.getStream()->getDict()->lookup, "Level1"); + } else if (obj2.isName()) { + error(errSyntaxError, getPos(), "Unknown XObject subtype '{0:s}'", obj2.getName()); + } else { +@@ -2545,7 +2545,7 @@ void PdfParser::doImage(Object * /*ref*/, Stream *str, GBool inlineImg) + _POPPLER_CALL_ARGS(obj1, dict->lookup, "D"); + } + if (obj1.isArray()) { +- _POPPLER_CALL_ARGS(obj2, obj1.arrayGet, 0); ++ _POPPLER_CALL_ARGS(obj2, obj1.getArray()->get, 0); + if (obj2.isInt() && obj2.getInt() == 1) { + invert = gTrue; + } +@@ -2607,7 +2607,7 @@ void PdfParser::doImage(Object * /*ref*/, Stream *str, GBool inlineImg) + goto err1; + } + maskStr = smaskObj.getStream(); +- maskDict = smaskObj.streamGetDict(); ++ maskDict = smaskObj.getStream()->getDict(); + _POPPLER_CALL_ARGS(obj1, maskDict->lookup, "Width"); + if (obj1.isNull()) { + _POPPLER_FREE(obj1); +@@ -2673,8 +2673,8 @@ void PdfParser::doImage(Object * /*ref*/, Stream *str, GBool inlineImg) + } else if (maskObj.isArray()) { + // color key mask + int i; +- for (i = 0; i < maskObj.arrayGetLength() && i < 2*gfxColorMaxComps; ++i) { +- _POPPLER_CALL_ARGS(obj1, maskObj.arrayGet, i); ++ for (i = 0; i < maskObj.getArray()->getLength() && i < 2*gfxColorMaxComps; ++i) { ++ _POPPLER_CALL_ARGS(obj1, maskObj.getArray()->get, i); + maskColors[i] = obj1.getInt(); + _POPPLER_FREE(obj1); + } +@@ -2685,7 +2685,7 @@ void PdfParser::doImage(Object * /*ref*/, Stream *str, GBool inlineImg) + goto err1; + } + maskStr = maskObj.getStream(); +- maskDict = maskObj.streamGetDict(); ++ maskDict = maskObj.getStream()->getDict(); + _POPPLER_CALL_ARGS(obj1, maskDict->lookup, "Width"); + if (obj1.isNull()) { + _POPPLER_FREE(obj1); +@@ -2732,7 +2732,7 @@ void PdfParser::doImage(Object * /*ref*/, Stream *str, GBool inlineImg) + _POPPLER_CALL_ARGS(obj1, maskDict->lookup, "D"); + } + if (obj1.isArray()) { +- _POPPLER_CALL_ARGS(obj2, obj1.arrayGet, 0); ++ _POPPLER_CALL_ARGS(obj2, obj1.getArray()->get, 0); + if (obj2.isInt() && obj2.getInt() == 1) { + maskInvert = gTrue; + } +@@ -2785,7 +2785,7 @@ void PdfParser::doForm(Object *str, double *offset) + } + + // get stream dict +- dict = str->streamGetDict(); ++ dict = str->getStream()->getDict(); + + // check form type + _POPPLER_CALL_ARGS(obj1, dict->lookup, "FormType"); +@@ -2802,7 +2802,7 @@ void PdfParser::doForm(Object *str, double *offset) + return; + } + for (i = 0; i < 4; ++i) { +- _POPPLER_CALL_ARGS(obj1, bboxObj.arrayGet, i); ++ _POPPLER_CALL_ARGS(obj1, bboxObj.getArray()->get, i); + bbox[i] = obj1.getNum(); + _POPPLER_FREE(obj1); + } +@@ -2812,7 +2812,7 @@ void PdfParser::doForm(Object *str, double *offset) + _POPPLER_CALL_ARGS(matrixObj, dict->lookup, "Matrix"); + if (matrixObj.isArray()) { + for (i = 0; i < 6; ++i) { +- _POPPLER_CALL_ARGS(obj1, matrixObj.arrayGet, i); ++ _POPPLER_CALL_ARGS(obj1, matrixObj.getArray()->get, i); + m[i] = obj1.getNum(); + _POPPLER_FREE(obj1); + } +@@ -3248,10 +3248,10 @@ void PdfParser::loadColorProfile() + return; + + Object outputIntents = catDict.dictLookup("OutputIntents"); +- if (!outputIntents.isArray() || outputIntents.arrayGetLength() != 1) ++ if (!outputIntents.isArray() || outputIntents.getArray()->getLength() != 1) + return; + +- Object firstElement = outputIntents.arrayGet(0); ++ Object firstElement = outputIntents.getArray()->get(0); + if (!firstElement.isDict()) + return; + +@@ -3300,7 +3300,7 @@ void PdfParser::build_annots(const Object &annot, int page_num) + _POPPLER_CALL_ARGS(Rect_obj, annot_dict->lookup, "Rect"); + if (Rect_obj.isArray()) { + for (int i = 0; i < 2; i++) { +- _POPPLER_CALL_ARGS(xy_obj, Rect_obj.arrayGet, i); ++ _POPPLER_CALL_ARGS(xy_obj, Rect_obj.getArray()->get, i); + offset[i] = xy_obj.getNum(); + } + doForm(&first_state_obj, offset); +diff --git a/src/extension/internal/pdfinput/poppler-transition-api.h b/src/extension/internal/pdfinput/poppler-transition-api.h +index 23550a3068..22bc8d223d 100644 +--- a/src/extension/internal/pdfinput/poppler-transition-api.h ++++ b/src/extension/internal/pdfinput/poppler-transition-api.h +@@ -15,6 +15,12 @@ + #include + #include + ++#if POPPLER_CHECK_VERSION(26, 7, 0) ++#define _POPPLER_STRING_26_7 std::string ++#else ++#define _POPPLER_STRING_26_7 GooString ++#endif ++ + #if POPPLER_CHECK_VERSION(26, 6, 0) + #define _POPPLER_GET_GRAY(color, gray) getGray(color, gray) + #define _POPPLER_GET_RGB(color, rgb) getRGB(color, rgb) +diff --git a/src/extension/internal/pdfinput/poppler-utils.cpp b/src/extension/internal/pdfinput/poppler-utils.cpp +index 66dcf85e1d..0a82574209 100644 +--- a/src/extension/internal/pdfinput/poppler-utils.cpp ++++ b/src/extension/internal/pdfinput/poppler-utils.cpp +@@ -187,15 +187,16 @@ void InkFontDict::hashFontObject1(const Object *obj, FNVHash *h) + case objNull: + h->hash('z'); + break; +- case objArray: +- h->hash('a'); +- n = obj->arrayGetLength(); +- h->hash((char *)&n, sizeof(int)); +- for (i = 0; i < n; ++i) { +- const Object &obj2 = obj->arrayGetNF(i); +- hashFontObject1(&obj2, h); +- } +- break; ++ case objArray: { ++ h->hash('a'); ++ Array * objArray = obj->getArray(); ++ n = objArray->getLength(); ++ h->hash((char *)&n, sizeof(int)); ++ for (i = 0; i < n; ++i) { ++ const Object &obj2 = objArray->getNF(i); ++ hashFontObject1(&obj2, h); ++ } ++ } break; + case objDict: { + h->hash('d'); + auto objdict = obj->getDict(); +@@ -207,8 +208,7 @@ void InkFontDict::hashFontObject1(const Object *obj, FNVHash *h) + const Object &obj2 = objdict->getValNF(i); + hashFontObject1(&obj2, h); + } +- } +- break; ++ } break; + case objStream: + // this should never happen - streams must be indirect refs + break; +@@ -546,7 +546,7 @@ void _getFontsRecursive(std::shared_ptr pdf_doc, Dict *resources, const + continue; + + Ref resourcesRef; +- const Object resObj = obj2.streamGetDict()->lookup("Resources", &resourcesRef); ++ const Object resObj = obj2.getStream()->getDict()->lookup("Resources", &resourcesRef); + if (resourcesRef != Ref::INVALID() && !visitedObjects.insert(resourcesRef.num).second) + continue; + +@@ -661,6 +661,11 @@ std::string getString(const GooString *value) + return ""; + } + ++std::string getString(const GooString &value) ++{ ++ return getString(value.toStr()); ++} ++ + /** + * Convert PDF strings, which can be formatted as UTF8, UTF16BE or UTF16LE into + * a predictable UTF8 string consistant with svg requirements. +diff --git a/src/extension/internal/pdfinput/poppler-utils.h b/src/extension/internal/pdfinput/poppler-utils.h +index b11ecd11e5..27675b758e 100644 +--- a/src/extension/internal/pdfinput/poppler-utils.h ++++ b/src/extension/internal/pdfinput/poppler-utils.h +@@ -86,6 +86,7 @@ std::string getDictString(Dict *dict, const char *key); + std::string getString(const std::string &value); + std::string getString(const std::unique_ptr &value); + std::string getString(const GooString *value); ++std::string getString(const GooString &value); + std::string validateString(std::string const &in); + std::string sanitizeId(std::string const &in); + +-- +GitLab + From 57c499f656c725793a2f89ab429e02253f72a15c Mon Sep 17 00:00:00 2001 From: Hythera <87016780+Hythera@users.noreply.github.com> Date: Sat, 1 Aug 2026 19:08:00 +0200 Subject: [PATCH 161/423] scribus: fix build with poppler 26.07.0 --- pkgs/by-name/sc/scribus/package.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkgs/by-name/sc/scribus/package.nix b/pkgs/by-name/sc/scribus/package.nix index 54637d7c1332..2746fe4d217a 100644 --- a/pkgs/by-name/sc/scribus/package.nix +++ b/pkgs/by-name/sc/scribus/package.nix @@ -114,6 +114,11 @@ stdenv.mkDerivation (finalAttrs: { url = "https://github.com/scribusproject/scribus/commit/2b9405a00a96a09e0183190ddc9f83d44963d4e0.patch"; hash = "sha256-4v+Ba+JODwNg4YLmwpFeBfIxk1j+RcZdtznPFeQ+H+w="; }) + (fetchpatch { + name = "fix-build-with-poppler-26.07.0.patch"; + url = "https://github.com/scribusproject/scribus/commit/ba246c3a2dd086b4e84517723beab159736ba9ba.patch"; + hash = "sha256-nfJ3eKBhuWC4IO2+IbqNOz0UWTD4UOKtfZXz5ch6NVE="; + }) ]; postPatch = '' From ff4e29c8ac1c51ca22c5ca8df29753810bebdfaf Mon Sep 17 00:00:00 2001 From: Stig Palmquist Date: Sun, 13 Sep 2026 07:12:00 +0200 Subject: [PATCH 162/423] gnupg: update freepg patches to source-2.4.9-freepg-1 Assisted-by: Claude Code (Claude Fable 5.1) --- pkgs/tools/security/gnupg/24.nix | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) diff --git a/pkgs/tools/security/gnupg/24.nix b/pkgs/tools/security/gnupg/24.nix index cdfbae4d9966..6625b8278484 100644 --- a/pkgs/tools/security/gnupg/24.nix +++ b/pkgs/tools/security/gnupg/24.nix @@ -90,8 +90,8 @@ stdenv.mkDerivation (finalAttrs: { freepgPatches = fetchFromGitLab { owner = "freepg"; repo = "gnupg"; - tag = "source-2.4.9-freepg"; - hash = "sha256-wF+iR0OgnU8VI90NlFOXtN5aCRC0YY/X7sPiDXjJm5M="; + tag = "source-2.4.9-freepg-1"; + hash = "sha256-hoSuIrq7Epco1LLlc77tGr/YZdp2w04Eq0rGbBCurWU="; }; patches = [ @@ -132,6 +132,15 @@ stdenv.mkDerivation (finalAttrs: { "0033-Support-large-RSA-keygen-in-non-batch-mode.patch" "0034-gpg-Verify-Text-mode-Signatures-over-binary-Literal-.patch" "0039-gpg-Do-not-use-a-default-when-asking-for-another-out.patch" + "0040-Add-missing-test-files-to-EXTRA_DIST.patch" + "0045-gpg-Fix-edge-case-in-refresh-keys.patch" + "0046-gpgsm-Require-a-minimum-tag-length-for-GCM-decryptio.patch" + "0047-gpg-Fix-handling-with-no-CRC-armor.patch" + "0048-gpg-Fix-armored-input-parsing.patch" + "0049-gpg-Fix-armor-parsing-when-no-CRC-is-found.patch" + "0050-tpm-Fix-possible-buffer-overflow-in-PKDECRYPT.patch" + "0051-agent-Fix-the-regression-in-pkdecrypt-with-TPM-RSA.patch" + "0052-dirmngr-Fix-a-call-of-calloc.patch" ]; postPatch = From e99a8832555408778f7c175f18e29ad3c1d0fc5b Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Sun, 13 Sep 2026 23:39:13 +0200 Subject: [PATCH 163/423] apache-orc: fix build --- pkgs/by-name/ap/apache-orc/package.nix | 2 +- pkgs/development/libraries/protobuf/generic.nix | 6 ++++++ 2 files changed, 7 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/ap/apache-orc/package.nix b/pkgs/by-name/ap/apache-orc/package.nix index 0034206b1d3d..417dbc034790 100644 --- a/pkgs/by-name/ap/apache-orc/package.nix +++ b/pkgs/by-name/ap/apache-orc/package.nix @@ -75,7 +75,7 @@ stdenv.mkDerivation (finalAttrs: { GTEST_HOME = gtest.dev; LZ4_HOME = lz4; ORC_FORMAT_URL = orc-format; - PROTOBUF_HOME = protobuf; + PROTOBUF_HOME = protobuf.full; # Configure script expects to find both executables and headers at this path. SNAPPY_HOME = snappy.dev; ZLIB_HOME = zlib.dev; ZSTD_HOME = zstd.dev; diff --git a/pkgs/development/libraries/protobuf/generic.nix b/pkgs/development/libraries/protobuf/generic.nix index 45db4049d10a..824156bcb44b 100644 --- a/pkgs/development/libraries/protobuf/generic.nix +++ b/pkgs/development/libraries/protobuf/generic.nix @@ -14,6 +14,7 @@ version, hash, versionCheckHook, + symlinkJoin, # downstream dependencies python3, @@ -183,6 +184,11 @@ stdenv.mkDerivation (finalAttrs: { }; inherit abseil-cpp; + + full = symlinkJoin { + inherit (finalAttrs.finalPackage) name; + paths = finalAttrs.finalPackage.all; + }; }; meta = { From 721870b2a6b45718df1c52ae2b4fb8595d3a394a Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Sun, 13 Sep 2026 17:01:00 -0700 Subject: [PATCH 164/423] cups: patch CVE-2026-87875 and CVE-2026-87876 --- pkgs/by-name/cu/cups/package.nix | 24 ++++++++++++++++++++++++ 1 file changed, 24 insertions(+) diff --git a/pkgs/by-name/cu/cups/package.nix b/pkgs/by-name/cu/cups/package.nix index dd12a5dcef57..bc7e13d02f1f 100644 --- a/pkgs/by-name/cu/cups/package.nix +++ b/pkgs/by-name/cu/cups/package.nix @@ -2,6 +2,7 @@ lib, stdenv, fetchurl, + fetchpatch, pkg-config, removeReferencesTo, zlib, @@ -42,6 +43,29 @@ stdenv.mkDerivation (finalAttrs: { "man" ]; + patches = [ + (fetchpatch { + name = "CVE-2026-87875.patch"; + url = "https://github.com/OpenPrinting/cups/commit/2b1dc178a2d2325135b855142e384f4e8c42d8e4.patch"; + excludes = [ "CHANGES.md" ]; + hash = "sha256-WHw/UWyUuYEBC6TRADpw+BBCaCts9Nd0jS9qsQHTBMo="; + }) + (fetchpatch { + url = "https://github.com/OpenPrinting/cups/commit/76b515154ce6264dae6d7cc44915d85e0e5fa0f4.patch"; + hash = "sha256-KtwcB4KrFmsLbtAz6u593qxbnozW2Vb/I9yX36gZTd0="; + }) + (fetchpatch { + url = "https://github.com/OpenPrinting/cups/commit/526adb34fe87f7f0cf5f63ae26751c1afa36a5d6.patch"; + hash = "sha256-Pg2xbCXalbvDvv5iI19MrjpOTW03XLKfEHN+lhImG1U="; + }) + (fetchpatch { + name = "CVE-2026-87876.patch"; + url = "https://github.com/OpenPrinting/cups/commit/88e67c00c130a45f3a1edf36686f7a0b2982fef8.patch"; + excludes = [ "CHANGES.md" ]; + hash = "sha256-gohcRO93JE2ldF5uPbR0re9NYxb13AeVn4b/qYsQGaE="; + }) + ]; + postPatch = '' substituteInPlace cups/testfile.c \ --replace 'cupsFileFind("cat", "/bin' 'cupsFileFind("cat", "${coreutils}/bin' From 5fc894118b338a35662667003c65d818b463abaa Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Sun, 13 Sep 2026 14:06:43 -0400 Subject: [PATCH 165/423] dtc: 1.7.2 -> 1.8.1 Diff: https://github.com/dgibson/dtc/compare/v1.7.2...v1.8.1 --- pkgs/by-name/dt/dtc/package.nix | 52 ++++++----- pkgs/by-name/dt/dtc/static.patch | 150 ------------------------------- 2 files changed, 28 insertions(+), 174 deletions(-) delete mode 100644 pkgs/by-name/dt/dtc/static.patch diff --git a/pkgs/by-name/dt/dtc/package.nix b/pkgs/by-name/dt/dtc/package.nix index 17fe8f5653e3..c05cd70b2b4a 100644 --- a/pkgs/by-name/dt/dtc/package.nix +++ b/pkgs/by-name/dt/dtc/package.nix @@ -14,40 +14,43 @@ replaceVars, swig, libyaml, + gitUpdater, }: stdenv.mkDerivation (finalAttrs: { pname = "dtc"; - version = "1.7.2"; + version = "1.8.1"; src = fetchzip { url = "https://git.kernel.org/pub/scm/utils/dtc/dtc.git/snapshot/dtc-v${finalAttrs.version}.tar.gz"; - hash = "sha256-KZCzrvdWd6zfQHppjyp4XzqNCfH2UnuRneu+BNIRVAY="; + hash = "sha256-l32ZGygimwSB2xmwQEvS+C2c5n86OMH92jQZ/tPI+YI="; }; patches = [ - # backport of https://github.com/dgibson/dtc/pull/141 - # to 1.7.2, to drop in 1.8. - ./static.patch - # backport fix for SWIG 4.3 + # These 4 patches fix build failures on x86_64-linux for tests/dumptrees by replacing it. (fetchpatch2 { - url = "https://github.com/dgibson/dtc/commit/9a969f3b70b07bbf1c9df44a38d7f8d1d3a6e2a5.patch"; - hash = "sha256-YrRzc3ATNmU6LYNHEQeU8wtjt1Ap7/gNFvtRR14PQEE="; + url = "https://github.com/dgibson/dtc/commit/9b53b9a4c2f953a37d8f68d72f5910b20cf5aee0.patch?full_index=1"; + hash = "sha256-HHX3zg1uwD3ZFHbHcANX85gNDpeEMVbkG7zMhyc/87k="; }) - # glibc-2.41 support (fetchpatch2 { - url = "https://github.com/dgibson/dtc/commit/ce1d8588880aecd7af264e422a16a8b33617cef7.patch"; - hash = "sha256-t1CxKnbCXUArtVcniAIdNvahOGXPbYhPCZiTynGLvfo="; + url = "https://github.com/dgibson/dtc/commit/f116f4800edce6cd58f680a36fbaed656018d528.patch?full_index=1"; + hash = "sha256-XcLzfruD3DGs4girNxsqrhBW3Ct/+vAltn8OzIRyU6w="; + }) + (fetchpatch2 { + url = "https://github.com/dgibson/dtc/commit/4df9ca4c8ddb83c40900bf13916b42914a25caf4.patch?full_index=1"; + hash = "sha256-ap3D2DxHxLYOSJPhWAUP/nooi/n2/wLc65NfbjlYl2M="; + }) + (fetchpatch2 { + url = "https://github.com/dgibson/dtc/commit/214372a27398121f8266cf9bb9592561508c4c0f.patch?full_index=1"; + hash = "sha256-Fk0dA1J14NsIfd5qSknOMkB769TEwvWem8e+uEleM84="; }) ] - ++ - lib.optional pythonSupport - # Make Meson use our Python version, not the one it was built with itself - ( - replaceVars ./python-path.patch { - python_bin = lib.getExe python; - } - ); + ++ lib.optionals pythonSupport [ + # Make Meson use our Python version, not the one it was built with itself + (replaceVars ./python-path.patch { + python_bin = lib.getExe python; + }) + ]; nativeBuildInputs = [ meson @@ -55,21 +58,17 @@ stdenv.mkDerivation (finalAttrs: { flex bison pkg-config - which ] ++ lib.optionals pythonSupport [ python - python.pkgs.setuptools-scm swig ]; buildInputs = [ libyaml ]; postPatch = '' - patchShebangs setup.py - # Align the name with pypi - sed -i "s/name='libfdt',/name='pylibfdt',/" setup.py + substituteInPlace pyproject.toml --replace-fail "name = 'libfdt'" "name = 'pylibfdt'" ''; # Required for installation of Python library and is innocuous otherwise. @@ -97,6 +96,11 @@ stdenv.mkDerivation (finalAttrs: { # hostPlatform binaries during the configurePhase. (with stdenv; buildPlatform.canExecute hostPlatform); + passthru.updateScript = gitUpdater { + url = "https://git.kernel.org/pub/scm/utils/dtc/dtc.git"; + rev-prefix = "v"; + }; + meta = { description = "Device Tree Compiler"; homepage = "https://git.kernel.org/pub/scm/utils/dtc/dtc.git"; diff --git a/pkgs/by-name/dt/dtc/static.patch b/pkgs/by-name/dt/dtc/static.patch deleted file mode 100644 index 5b368e07243a..000000000000 --- a/pkgs/by-name/dt/dtc/static.patch +++ /dev/null @@ -1,150 +0,0 @@ -commit a881a5b110d2f23a11924604bff64ab3c2755bc6 -Author: Brandon Maier -Date: Thu Mar 6 20:30:47 2025 -0600 - - meson: support building libfdt without static library - - Some packaging systems like NixOS don't support compiling static - libraries. However libfdt's meson.build uses `both_library()` which - forces the build to always compile shared and static libraries. Removing - `both_library()` will make packaging easier. - - libfdt uses `both_libraries()` to support the 'static-build' option. - But we do not need the 'static-build' option as Meson can natively - build static using - - > meson setup builddir/ -Dc_link_args='-static' --prefer-static --default-library=static - - So drop 'static-build' and then replace `both_libraries()` with - `library()`. - - Signed-off-by: Brandon Maier - Signed-off-by: David Gibson - -diff --git a/libfdt/meson.build b/libfdt/meson.build -index bf8343f..c2f4bd6 100644 ---- a/libfdt/meson.build -+++ b/libfdt/meson.build -@@ -26,7 +26,7 @@ else - endif - - link_args += version_script --libfdt = both_libraries( -+libfdt = library( - 'fdt', sources, - version: meson.project_version(), - link_args: link_args, -@@ -34,17 +34,11 @@ libfdt = both_libraries( - install: true, - ) - --if static_build -- link_with = libfdt.get_static_lib() --else -- link_with = libfdt.get_shared_lib() --endif -- - libfdt_inc = include_directories('.') - - libfdt_dep = declare_dependency( - include_directories: libfdt_inc, -- link_with: link_with, -+ link_with: libfdt, - ) - - install_headers( -diff --git a/meson.build b/meson.build -index 310699f..603ffaa 100644 ---- a/meson.build -+++ b/meson.build -@@ -1,7 +1,7 @@ - project('dtc', 'c', - version: files('VERSION.txt'), - license: ['GPL2+', 'BSD-2'], -- default_options: 'werror=true', -+ default_options: ['werror=true', 'default_library=both'], - meson_version: '>=0.57.0' - ) - -@@ -27,16 +27,8 @@ add_project_arguments( - language: 'c' - ) - --if get_option('static-build') -- static_build = true -- extra_link_args = ['-static'] --else -- static_build = false -- extra_link_args = [] --endif -- - yamltree = 'yamltree.c' --yaml = dependency('yaml-0.1', version: '>=0.2.3', required: get_option('yaml'), static: static_build) -+yaml = dependency('yaml-0.1', version: '>=0.2.3', required: get_option('yaml')) - if not yaml.found() - add_project_arguments('-DNO_YAML', language: 'c') - yamltree = [] -@@ -92,7 +84,6 @@ if get_option('tools') - ], - dependencies: util_dep, - install: true, -- link_args: extra_link_args, - ) - endif - -@@ -113,11 +104,10 @@ if get_option('tools') - ], - dependencies: [util_dep, yaml], - install: true, -- link_args: extra_link_args, - ) - - foreach e: ['fdtdump', 'fdtget', 'fdtput', 'fdtoverlay'] -- dtc_tools += executable(e, files(e + '.c'), dependencies: util_dep, install: true, link_args: extra_link_args) -+ dtc_tools += executable(e, files(e + '.c'), dependencies: util_dep, install: true) - endforeach - - install_data( -diff --git a/meson_options.txt b/meson_options.txt -index 36f391a..62b31b3 100644 ---- a/meson_options.txt -+++ b/meson_options.txt -@@ -8,7 +8,5 @@ option('valgrind', type: 'feature', value: 'auto', - description: 'Valgrind support') - option('python', type: 'feature', value: 'auto', - description: 'Build pylibfdt Python library') --option('static-build', type: 'boolean', value: false, -- description: 'Build static binaries') - option('tests', type: 'boolean', value: true, - description: 'Build tests') -diff --git a/tests/meson.build b/tests/meson.build -index 9cf6e3d..baed174 100644 ---- a/tests/meson.build -+++ b/tests/meson.build -@@ -96,22 +96,20 @@ tests += [ - 'truncated_string', - ] - -+test_deps = [testutil_dep, util_dep, libfdt_dep] -+ - dl = cc.find_library('dl', required: false) --if dl.found() and not static_build -+if dl.found() - tests += [ - 'asm_tree_dump', - 'value-labels', - ] --endif -- --test_deps = [testutil_dep, util_dep, libfdt_dep] --if not static_build - test_deps += [dl] - endif - - tests_exe = [] - foreach t: tests -- tests_exe += executable(t, files(t + '.c'), dependencies: test_deps, link_args: extra_link_args) -+ tests_exe += executable(t, files(t + '.c'), dependencies: test_deps) - endforeach - - run_tests = find_program('run_tests.sh') From b19adca6885eb98903f9a8d04a8ae3e822283de1 Mon Sep 17 00:00:00 2001 From: Grimmauld Date: Mon, 14 Sep 2026 13:36:15 +0200 Subject: [PATCH 166/423] libcap_ng: 0.9.5 -> 0.9.6 --- pkgs/by-name/li/libcap_ng/package.nix | 19 +++++++++++++++++-- 1 file changed, 17 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/li/libcap_ng/package.nix b/pkgs/by-name/li/libcap_ng/package.nix index c9aaca668faa..3876bebaa1e7 100644 --- a/pkgs/by-name/li/libcap_ng/package.nix +++ b/pkgs/by-name/li/libcap_ng/package.nix @@ -2,6 +2,7 @@ lib, stdenv, fetchFromGitHub, + fetchpatch, autoreconfHook, pkg-config, swig, @@ -14,15 +15,29 @@ stdenv.mkDerivation (finalAttrs: { pname = "libcap-ng"; - version = "0.9.5"; + version = "0.9.6"; src = fetchFromGitHub { owner = "stevegrubb"; repo = "libcap-ng"; tag = "v${finalAttrs.version}"; - hash = "sha256-HYVbPoFSlkmNuL5EsEQVAekE4fwidgL+biTBBS1BdPM="; + hash = "sha256-+2u3clE04++YfHbTCQAIY9uKmfks9fsPZnVQNE/CmvY="; }; + patches = [ + # https://github.com/stevegrubb/libcap-ng/issues/85 + (fetchpatch { + # static musl has tests failing to compile + url = "https://github.com/stevegrubb/libcap-ng/commit/ef1b34928455fa31ff5427d6ad4166406d5a1df1.patch"; + hash = "sha256-7EZC87RoVH2Dkg859rRXt2A+GhRJVajn/DpmYBUuEBI="; + }) + (fetchpatch { + # tests fail when building on a host with alpine kernel + url = "https://github.com/stevegrubb/libcap-ng/commit/b346f998af31febfb7d0915d0cf5e633a5262e88.patch"; + hash = "sha256-b+OOY4XFXxK7sAH8/PUJ8oDPVtH84LYrzcEvhPfB9QI="; + }) + ]; + # NEWS needs to exist or else the build fails postPatch = '' touch NEWS From 8eb0079666578b45efbb34dfc87681c0c7b1813b Mon Sep 17 00:00:00 2001 From: Grimmauld Date: Mon, 14 Sep 2026 13:37:04 +0200 Subject: [PATCH 167/423] Revert "libcap_ng: disable tests on static" This reverts commit 18219b32ad562755274e15f7c1797391931c3e30. --- pkgs/by-name/li/libcap_ng/package.nix | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/pkgs/by-name/li/libcap_ng/package.nix b/pkgs/by-name/li/libcap_ng/package.nix index 3876bebaa1e7..a7d3b1ddb757 100644 --- a/pkgs/by-name/li/libcap_ng/package.nix +++ b/pkgs/by-name/li/libcap_ng/package.nix @@ -101,9 +101,7 @@ stdenv.mkDerivation (finalAttrs: { # assumption: build machine runs linux kernel 5.0 or newer # see https://github.com/stevegrubb/libcap-ng?tab=readme-ov-file#note-to-distributions - # disabled on static due to symbol collision in test file compilation - # see https://github.com/stevegrubb/libcap-ng/issues/85 - doCheck = !stdenv.hostPlatform.isStatic; + doCheck = true; pythonImportsCheck = [ "capng" From 1344a818f64213c087176eba36fcee64b01170f5 Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Mon, 14 Sep 2026 17:08:41 -0400 Subject: [PATCH 168/423] various: fix hashes --- pkgs/by-name/jo/joplin-cli/package.nix | 16 ++++++++++++++-- pkgs/by-name/yt/ytmdesktop/package.nix | 4 ++-- pkgs/development/tools/electron/info.json | 6 +++--- 3 files changed, 19 insertions(+), 7 deletions(-) diff --git a/pkgs/by-name/jo/joplin-cli/package.nix b/pkgs/by-name/jo/joplin-cli/package.nix index 5acbdc708985..0c07ab58aee8 100644 --- a/pkgs/by-name/jo/joplin-cli/package.nix +++ b/pkgs/by-name/jo/joplin-cli/package.nix @@ -3,6 +3,7 @@ stdenv, nodejs, fetchFromGitHub, + substitute, yarn-berry_4, python3, pkg-config, @@ -24,8 +25,19 @@ stdenv.mkDerivation (finalAttrs: { postFetch = '' # there's a file with a weird name that causes a hash mismatch on darwin rm $out/packages/app-cli/tests/support/photo* + cd $out + patch -p1 < ${ + (substitute { + src = ./yarn-fix.patch; + substitutions = [ + "--replace-fail" + "YARN_LOCKFILE_VERSION_PLACEHOLDER" + yarn-berry_4.lockfileVersion + ]; + }) + } ''; - hash = "sha256-4o8mao7wAqDzwQgJ4QY+DPs9rtsnga6LLnq744l7HVM="; + hash = "sha256-g5b1DwSG0JgzGeL17q50CaTU0mG6u/v5IUwoVBcoMsM="; }; missingHashes = ./missing-hashes.json; @@ -36,7 +48,7 @@ stdenv.mkDerivation (finalAttrs: { missingHashes postPatch ; - hash = "sha256-CHjvFu6r5zak19dqtRkcGkPhPoKgt1nkBVa71ZcvdgE="; + hash = "sha256-IyOnSB21bOYiPnYUorne8/11zxUItIqMtT88ExCoEmU="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/yt/ytmdesktop/package.nix b/pkgs/by-name/yt/ytmdesktop/package.nix index d1bd5cb537b3..6b8fdec4fb50 100644 --- a/pkgs/by-name/yt/ytmdesktop/package.nix +++ b/pkgs/by-name/yt/ytmdesktop/package.nix @@ -50,7 +50,7 @@ stdenv.mkDerivation (finalAttrs: { } ''; - hash = "sha256-fT5UdJ9YYK3hXC8GkEeJ/LK1bCyXofcKA0aCJUnjZdk="; + hash = "sha256-48PeFM6azfPJBc3c6gNRE6mQnfYWMkMI9WQOcnFQCuA="; }; patches = [ @@ -75,7 +75,7 @@ stdenv.mkDerivation (finalAttrs: { yarnOfflineCache = yarn-berry.fetchYarnBerryDeps { inherit (finalAttrs) src missingHashes patches; - hash = "sha256-fpvBE4QZcDaWGgqU3jQlOe+bOLtnDEVNR4IuKBo35BQ="; + hash = "sha256-oDouMkHjvENQrGBHfgGC/+ZBRJSAdXR+f2Fb0fkM9Sw="; }; nativeBuildInputs = [ diff --git a/pkgs/development/tools/electron/info.json b/pkgs/development/tools/electron/info.json index fcd80946d3a7..022de72aa9b6 100644 --- a/pkgs/development/tools/electron/info.json +++ b/pkgs/development/tools/electron/info.json @@ -1367,7 +1367,7 @@ } }, "electron_yarn_data": { - "hash": "sha256-KNbWANdqpF3rypdyGKgj9ykGXQ/+VtkE5L/XR1lqbps=", + "hash": "sha256-3djOSYb8lSTWbtclB23O1I/Aw3n6auInUAtzOYrMth4=", "missing_hashes": { "@oxfmt/binding-android-arm-eabi@npm:0.42.0": "42c08d87ce491086843070241f8777fa2cb968f4a08f67b3f6c33a8f67e0b3eac50eae146daede743e90e3bc32326951c5188814eea02e9c3e4a9764a4b492ba", "@oxfmt/binding-android-arm64@npm:0.42.0": "73e6609498d05c655c6a435af9f3e4f341137c260c7ae27fbb0377573574ca5200bd9f187aa90d442879733bbd0c4e91ae023c3b4579c9a57413a0b2922c023a", @@ -2797,7 +2797,7 @@ } }, "electron_yarn_data": { - "hash": "sha256-0DiQw6UGeZ7BLNvUJihE77Io72AUfgcLMMmV+GxhfVw=", + "hash": "sha256-D3Tmxc2tzpUfKlWq4RXy6hYpqJ0Dsw7J4aQPp1rSZVs=", "missing_hashes": { "@oxfmt/binding-android-arm-eabi@npm:0.42.0": "42c08d87ce491086843070241f8777fa2cb968f4a08f67b3f6c33a8f67e0b3eac50eae146daede743e90e3bc32326951c5188814eea02e9c3e4a9764a4b492ba", "@oxfmt/binding-android-arm64@npm:0.42.0": "73e6609498d05c655c6a435af9f3e4f341137c260c7ae27fbb0377573574ca5200bd9f187aa90d442879733bbd0c4e91ae023c3b4579c9a57413a0b2922c023a", @@ -4251,7 +4251,7 @@ } }, "electron_yarn_data": { - "hash": "sha256-Y2TE5iMVUgXqqKojb90yzcCfFAhEy7STB53yYQQanPM=", + "hash": "sha256-/Se92a1Gw8vT3J1IkAcQmd4wYb3zwh+2LdrA5MwWHy8=", "missing_hashes": { "@oxfmt/binding-android-arm-eabi@npm:0.42.0": "42c08d87ce491086843070241f8777fa2cb968f4a08f67b3f6c33a8f67e0b3eac50eae146daede743e90e3bc32326951c5188814eea02e9c3e4a9764a4b492ba", "@oxfmt/binding-android-arm64@npm:0.42.0": "73e6609498d05c655c6a435af9f3e4f341137c260c7ae27fbb0377573574ca5200bd9f187aa90d442879733bbd0c4e91ae023c3b4579c9a57413a0b2922c023a", From 015a2211019236dc6eda9255a352773774bec6d1 Mon Sep 17 00:00:00 2001 From: Sergei Trofimovich Date: Mon, 14 Sep 2026 22:45:29 +0100 Subject: [PATCH 169/423] liburcu: 0.15.6 -> 0.15.7 Changes: https://raw.githubusercontent.com/urcu/userspace-rcu/v0.15.7/ChangeLog --- pkgs/by-name/li/liburcu/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/li/liburcu/package.nix b/pkgs/by-name/li/liburcu/package.nix index a983e5e99f9a..948b99b893af 100644 --- a/pkgs/by-name/li/liburcu/package.nix +++ b/pkgs/by-name/li/liburcu/package.nix @@ -7,12 +7,12 @@ }: stdenv.mkDerivation (finalAttrs: { - version = "0.15.6"; + version = "0.15.7"; pname = "liburcu"; src = fetchurl { url = "https://lttng.org/files/urcu/userspace-rcu-${finalAttrs.version}.tar.bz2"; - hash = "sha256-hQsZIJbrEevyxw6Pl7x9p0ee5B2hvr60TjmGkIusQU8="; + hash = "sha256-JVa4OtwPmzrIAk5hPhfQFNBMTEkRBgTOVfyxTq4y7dM="; }; outputs = [ From 844baee10f5fd6db76c57c505c656ad2f2424888 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Tue, 15 Sep 2026 02:02:45 +0200 Subject: [PATCH 170/423] liburcu: enable strictDeps --- pkgs/by-name/li/liburcu/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/li/liburcu/package.nix b/pkgs/by-name/li/liburcu/package.nix index a983e5e99f9a..79a07263be18 100644 --- a/pkgs/by-name/li/liburcu/package.nix +++ b/pkgs/by-name/li/liburcu/package.nix @@ -23,6 +23,8 @@ stdenv.mkDerivation (finalAttrs: { nativeCheckInputs = [ perl ]; + strictDeps = true; + enableParallelBuilding = true; preCheck = "patchShebangs tests/unit"; From 857ac80f17ad9e45dc3d6cc1397b659282173651 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Tue, 15 Sep 2026 02:03:00 +0200 Subject: [PATCH 171/423] liburcu: enable structuredAttrs --- pkgs/by-name/li/liburcu/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/li/liburcu/package.nix b/pkgs/by-name/li/liburcu/package.nix index 79a07263be18..2ce6f62bf58f 100644 --- a/pkgs/by-name/li/liburcu/package.nix +++ b/pkgs/by-name/li/liburcu/package.nix @@ -35,6 +35,8 @@ stdenv.mkDerivation (finalAttrs: { rev-prefix = "v"; }; + __structuredAttrs = true; + meta = { description = "Userspace RCU (read-copy-update) library"; homepage = "https://lttng.org/urcu"; From 2ad722223913f5813a540baa825b4cd49c9cc2a5 Mon Sep 17 00:00:00 2001 From: ajs124 Date: Tue, 15 Sep 2026 08:17:13 +0200 Subject: [PATCH 172/423] nss: 3.128 -> 3.129 https://github.com/mozilla/nss/blob/master/doc/src/releases/nss_3_129.md --- pkgs/development/libraries/nss/generic.nix | 3 +++ pkgs/development/libraries/nss/latest.nix | 4 ++-- 2 files changed, 5 insertions(+), 2 deletions(-) diff --git a/pkgs/development/libraries/nss/generic.nix b/pkgs/development/libraries/nss/generic.nix index c72fb989532f..ac0f11d02d85 100644 --- a/pkgs/development/libraries/nss/generic.nix +++ b/pkgs/development/libraries/nss/generic.nix @@ -76,6 +76,9 @@ stdenv.mkDerivation rec { substituteInPlace coreconf/config.gypi --replace "/usr/bin/grep" "${buildPackages.coreutils}/bin/env grep" '' + + lib.optionalString (lib.versionAtLeast version "3.129") '' + substituteInPlace build.sh --replace "\$obj_dir/lib/pkgconfig/nspr.pc" "${nspr.dev}/lib/pkgconfig/nspr.pc" + '' + lib.optionalString stdenv.hostPlatform.isDarwin '' substituteInPlace coreconf/Darwin.mk --replace '@executable_path/$(notdir $@)' "$out/lib/\$(notdir \$@)" substituteInPlace coreconf/config.gypi --replace "'DYLIB_INSTALL_NAME_BASE': '@executable_path'" "'DYLIB_INSTALL_NAME_BASE': '$out/lib'" diff --git a/pkgs/development/libraries/nss/latest.nix b/pkgs/development/libraries/nss/latest.nix index 6c003b433214..020d9330c51e 100644 --- a/pkgs/development/libraries/nss/latest.nix +++ b/pkgs/development/libraries/nss/latest.nix @@ -5,8 +5,8 @@ # Example: nix-shell ./maintainers/scripts/update.nix --argstr package cacert import ./generic.nix { - version = "3.128"; - hash = "sha256-C9SGEyoxR16F6j7zOUsudS0aH/qIHc7DgV5FbBbz90Q="; + version = "3.129"; + hash = "sha256-cy7+nCVtogr1onk8/8OQcQZUm2AH2azNsUmVFg4ym7k="; filename = "latest.nix"; versionRegex = "NSS_(\\d+)_(\\d+)(?:_(\\d+))?_RTM"; } From 2ba30f5255bd73a82ce609a6efbdda5a278c5838 Mon Sep 17 00:00:00 2001 From: whoomee Date: Tue, 8 Sep 2026 18:31:27 +0200 Subject: [PATCH 173/423] libnice: enable tests --- pkgs/by-name/li/libnice/package.nix | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/li/libnice/package.nix b/pkgs/by-name/li/libnice/package.nix index 663b0b07d080..3bb3672769a2 100644 --- a/pkgs/by-name/li/libnice/package.nix +++ b/pkgs/by-name/li/libnice/package.nix @@ -58,6 +58,13 @@ stdenv.mkDerivation (finalAttrs: { postPatch = '' substituteInPlace docs/reference/libnice/meson.build \ --replace-fail "version: '<1.30', " "" + '' + # Manually remove failing tests until we have disabledTests for meson + # The failures are due to the sandbox restricting network sockets + + '' + substituteInPlace tests/meson.build \ + --replace-fail "'test-slow-resolving'," "" \ + --replace-fail "'test-set-port-range'," "" ''; nativeBuildInputs = [ @@ -100,9 +107,7 @@ stdenv.mkDerivation (finalAttrs: { glib_debug = false; }; - # Tests are flaky - # see https://github.com/NixOS/nixpkgs/pull/53293#issuecomment-453739295 - doCheck = false; + doCheck = !stdenv.hostPlatform.isDarwin; passthru = { updateScript = nix-update-script { }; From 78643f203e77c1c93cd7355b5b0b8e2f0edafb48 Mon Sep 17 00:00:00 2001 From: whispers Date: Tue, 15 Sep 2026 18:48:47 -0400 Subject: [PATCH 174/423] tpm2-tss: drop unused libgcrypt dependency this was removed back in July 2020 with https://github.com/tpm2-software/tpm2-tss/commit/ebfe77b41e677de6cd808e3155fe43d606951143. diffoscoping the outputs yields no differences besides self-references in store paths. --- pkgs/development/libraries/tpm2-tss/default.nix | 2 -- 1 file changed, 2 deletions(-) diff --git a/pkgs/development/libraries/tpm2-tss/default.nix b/pkgs/development/libraries/tpm2-tss/default.nix index e910c11533bd..874c339b626d 100644 --- a/pkgs/development/libraries/tpm2-tss/default.nix +++ b/pkgs/development/libraries/tpm2-tss/default.nix @@ -10,7 +10,6 @@ openssl, json_c, curl, - libgcrypt, cmocka, uthash, swtpm, @@ -58,7 +57,6 @@ stdenv.mkDerivation (finalAttrs: { openssl json_c curl - libgcrypt uthash libuuid libtpms From b755abea8fdaa142fb21e5145f46d20cf2045870 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E5=A4=9C=E5=9D=82=E9=9B=85?= <23130178+ShadowRZ@users.noreply.github.com> Date: Wed, 16 Sep 2026 08:22:58 +0800 Subject: [PATCH 175/423] libmicrohttpd: drop libgcrypt --- pkgs/development/libraries/libmicrohttpd/generic.nix | 2 -- 1 file changed, 2 deletions(-) diff --git a/pkgs/development/libraries/libmicrohttpd/generic.nix b/pkgs/development/libraries/libmicrohttpd/generic.nix index fd1fa25ee207..d248810f6701 100644 --- a/pkgs/development/libraries/libmicrohttpd/generic.nix +++ b/pkgs/development/libraries/libmicrohttpd/generic.nix @@ -1,7 +1,6 @@ { lib, stdenv, - libgcrypt, curl, gnutls, pkg-config, @@ -24,7 +23,6 @@ stdenv.mkDerivation (finalAttrs: { ]; nativeBuildInputs = [ pkg-config ]; buildInputs = [ - libgcrypt curl gnutls libiconv From a9955997b6aa0669c328e297538f4554811ba9ea Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 176/423] lib.systems.elaborate: add Swift platform Move the definition of the Swift arch, platform, and triple out of the Swift compiler derivation; which should make it easier to handle target-specific differences once Swift cross-compilation is supported. --- lib/systems/default.nix | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+) diff --git a/lib/systems/default.nix b/lib/systems/default.nix index 2bd3f8927277..5b37eb20a874 100644 --- a/lib/systems/default.nix +++ b/lib/systems/default.nix @@ -719,6 +719,26 @@ let else null; }; + swift = { + arch = final.uname.processor; + platform = + if final.isMacOS then + "macosx" + else if final.isiOS then + "iphoneos" + else if final.isLinux then + "linux" + else if final.isWindows then + "windows" + else + null; + triple = + if final.isDarwin then + # FIXME: Can this be done a better way? + "${final.swift.arch}-${final.parsed.vendor.name}-${final.swift.platform}${final.darwinMinVersion}" + else + final.config; + }; }; in # Platforms elaborated by pre-26.11 Nixpkgs will include the `linux-kernel` attr, From 5776a35d7a795f54ed224886cc291c80cfcd5533 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 177/423] darwin.ICU: add Linux as a supported platform MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Swift Foundation uses a vendored copy of Apple’s ICU fork in the implementation of `FoundationInternationalization`. Instead of maintaining yet another build of ICU, update our existing packaging to build on Linux to faclitate devendoring swift-corelibs-icu. --- .../darwin/by-name/ic/ICU/package.nix | 46 ++++++++++++------- 1 file changed, 29 insertions(+), 17 deletions(-) diff --git a/pkgs/os-specific/darwin/by-name/ic/ICU/package.nix b/pkgs/os-specific/darwin/by-name/ic/ICU/package.nix index 935dfd277a8d..c25fbbc03b78 100644 --- a/pkgs/os-specific/darwin/by-name/ic/ICU/package.nix +++ b/pkgs/os-specific/darwin/by-name/ic/ICU/package.nix @@ -87,7 +87,7 @@ let description = "Unicode and globalization support library with Apple customizations"; license = lib.licenses.icu; teams = [ lib.teams.darwin ]; - platforms = lib.platforms.darwin; + platforms = lib.platforms.darwin ++ lib.platforms.linux; pkgConfigModules = [ "icu-i18n" "icu-io" @@ -169,8 +169,7 @@ let substituteInPlace "$dev/bin/icu-config" \ ${lib.concatMapStringsSep " " (r: "--replace-fail '${r.from}' '${r.to}'") replacements} '' - # Create library with everything reexported to provide the same ABI as the system ICU. - + lib.optionalString stdenv.hostPlatform.isDarwin ( + + ( if stdenv.hostPlatform.isStatic then '' ${stdenv.cc.targetPrefix}ar qL "$out/lib/libicucore.a" \ @@ -180,20 +179,33 @@ let "$out/lib/libicuio.a" '' else - '' - icuVersion=$(basename "$out/share/icu/"*) - ${stdenv.cc.targetPrefix}clang -dynamiclib \ - -L "$out/lib" \ - -Wl,-reexport-licuuc \ - -Wl,-reexport-licudata \ - -Wl,-reexport-licui18n \ - -Wl,-reexport-licuio \ - -compatibility_version 1 \ - -current_version "$icuVersion" \ - -install_name "$out/lib/libicucore.A.dylib" \ - -o "$out/lib/libicucore.A.dylib" - ln -s libicucore.A.dylib "$out/lib/libicucore.dylib" - '' + ( + lib.optionalString stdenv.hostPlatform.isDarwin '' + icuVersion=$(basename "$out/share/icu/"*) + ${stdenv.cc.targetPrefix}clang -dynamiclib \ + -L "$out/lib" \ + -Wl,-reexport-licuuc \ + -Wl,-reexport-licudata \ + -Wl,-reexport-licui18n \ + -Wl,-reexport-licuio \ + -compatibility_version 1 \ + -current_version "$icuVersion" \ + -install_name "$out/lib/libicucore.A.dylib" \ + -o "$out/lib/libicucore.A.dylib" + ln -s libicucore.A.dylib "$out/lib/libicucore.dylib" + '' + + lib.optionalString stdenv.hostPlatform.isLinux '' + ${stdenv.cc.targetPrefix}cc -shared \ + -L "$out/lib" \ + -Wl,--no-as-needed \ + -licuuc \ + -licudata \ + -licui18n \ + -licuio \ + -o "$out/lib/libicucore.so.A" + ln -s libicucore.so.A "$out/lib/libicucore.so" + '' + ) ) ); From f26a0bb1ebc7c23cfb3b576ea4ebf43455da1861 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 178/423] swiftPackages_ng: init package set Establish a parallel package set while the new Swift packaging is set up. The primary purpose is to allow packages to be added incrementally while still allowing `git bisect` to work. Otherwise, `swift` would be broken until this series was done (or it would have to be a single, large commit). This approach seems like the least bad one. --- pkgs/top-level/all-packages.nix | 1 + pkgs/top-level/swift-packages.nix | 15 +++++++++++++++ 2 files changed, 16 insertions(+) create mode 100644 pkgs/top-level/swift-packages.nix diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index ac01df0d1580..62735cba83b1 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -4103,6 +4103,7 @@ with pkgs; }; swiftPackages = recurseIntoAttrs (callPackage ../development/compilers/swift { }); + swiftPackages_ng = recurseIntoAttrs (callPackage ./swift-packages.nix { }); inherit (swiftPackages) swift swiftpm diff --git a/pkgs/top-level/swift-packages.nix b/pkgs/top-level/swift-packages.nix new file mode 100644 index 000000000000..42f30babff2d --- /dev/null +++ b/pkgs/top-level/swift-packages.nix @@ -0,0 +1,15 @@ +{ + lib, + clangStdenv, + generateSplicesForMkScope, + makeScopeWithSplicing', + otherSplices ? generateSplicesForMkScope "swiftPackages_ng", +}: + +makeScopeWithSplicing' { + inherit otherSplices; + extra = self: { }; + f = self: { + stdenv = clangStdenv; + }; +} From cf87abba340a849b0c0986e213babaa37a8af04f Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 179/423] swiftPackages.swift_release: init at 6.2.4 The Swift toolchain contains libraries and tools that are versioned together. Building a toolchain containing mixed versions of these is not supported by upstream and may not even build at all. However, we want to build these separately when possible, so introduce `swift_release` and `swift_sources` to capture this toolchain requirement. Note that there is an exception to this versioning scheme. The Swift toolchain depends on packages that are developed independently of the toolchain (such as Swift Argument Parser and Swift Collections). These can (and will be) updated independently of the toolchain. --- pkgs/development/compilers/swift_ng/sources-6.2.json | 2 ++ pkgs/top-level/swift-packages.nix | 11 ++++++++++- 2 files changed, 12 insertions(+), 1 deletion(-) create mode 100644 pkgs/development/compilers/swift_ng/sources-6.2.json diff --git a/pkgs/development/compilers/swift_ng/sources-6.2.json b/pkgs/development/compilers/swift_ng/sources-6.2.json new file mode 100644 index 000000000000..2c63c0851048 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/sources-6.2.json @@ -0,0 +1,2 @@ +{ +} diff --git a/pkgs/top-level/swift-packages.nix b/pkgs/top-level/swift-packages.nix index 42f30babff2d..889db69e582d 100644 --- a/pkgs/top-level/swift-packages.nix +++ b/pkgs/top-level/swift-packages.nix @@ -1,3 +1,9 @@ +let + swift_sources_6_2 = builtins.fromJSON ( + builtins.readFile ../development/compilers/swift_ng/sources-6.2.json + ); +in + { lib, clangStdenv, @@ -8,8 +14,11 @@ makeScopeWithSplicing' { inherit otherSplices; - extra = self: { }; + extra = self: { + swift_sources = swift_sources_6_2; + }; f = self: { stdenv = clangStdenv; + swift_release = "6.2.4"; }; } From 3c3b7f1cbfca77aff5cd8771e7375c91016c9159 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 180/423] swiftPackages_ng.llvmPackages: init at 17.0.0 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Swift requires using Apple’s fork of LLVM. The fork contains APIs that have not been upstreamed into LLVM and may never be upstreamed. It also contains changes required to support compling Swift. LLDB in particular has been modified heavily to depend on Swift compiler internals. --- .../by-name/ll/llvmPackages/package.nix | 86 +++++++++++++++++ .../patches/clang/gnu-install-dirs.patch | 95 +++++++++++++++++++ .../llvm/backport-darwin-triple-parsing.patch | 19 ++++ .../patches/llvm/module-cache.patch | 35 +++++++ .../compilers/swift_ng/sources-6.2.json | 3 + pkgs/top-level/swift-packages.nix | 6 +- 6 files changed, 242 insertions(+), 2 deletions(-) create mode 100644 pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/package.nix create mode 100644 pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/clang/gnu-install-dirs.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/llvm/backport-darwin-triple-parsing.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/llvm/module-cache.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/package.nix b/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/package.nix new file mode 100644 index 000000000000..5e5970f53190 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/package.nix @@ -0,0 +1,86 @@ +# Swift needs to be built against the matching tag from the LLVM fork in the swiftlang repo. +# Ideally, it would build against upstream LLVM, but it depends on APIs that have not been upstreamed. +# For example: https://github.com/swiftlang/llvm-project/blob/901f89886dcd5d1eaf07c8504d58c90f37b0cfdf/clang/include/clang/AST/StableHash.h + +{ + lib, + fetchFromGitHub, + generateSplicesForMkScope, + llvmPackages_19, # Needs to match the `llvmVersion` of the fork. + stdenv, + swift_release, + swift_sources, +}: + +let + swiftLlvmVersion = "17.0.0"; # From https://github.com/swiftlang/swift/blob/swift-$swiftVersion-RELEASE/utils/build_swift/build_swift/defaults.py#L51 + llvmVersion = "19.1.5"; # From https://github.com/swiftlang/llvm-project/blob/swift-$swiftVersion-RELEASE/cmake/Modules/LLVMVersion.cmake +in + +(llvmPackages_19.override { + officialRelease.version = llvmVersion; + + monorepoSrc = fetchFromGitHub { + owner = "swiftlang"; + repo = "llvm-project"; + tag = "swift-${swift_release}-RELEASE"; + inherit (swift_sources.llvm-project) hash; + }; + + otherSplices = generateSplicesForMkScope [ + "swiftPackages_ng" + "llvmPackages" + ]; + + patchesFn = + patches: + patches + // { + # Updated patch that also prevents Clang from trying to copy `clang-deps-launcher.py` to `${llvm}/bin`. + "clang/gnu-install-dirs.patch" = [ { path = ./patches; } ]; + # Update backport of the Darwin triple changes for macOS 27. + "llvm/backport-darwin-triple-parsing.patch" = [ { path = ./patches; } ]; + }; +}).overrideScope + ( + final: prev: { + version = swiftLlvmVersion; + release_version = llvmVersion; + + libclang = + let + clangWithLauncher = prev.libclang.overrideAttrs (old: { + postInstall = (old.postInstall or "") + '' + moveToOutput bin/clang-deps-launcher.py "$python" + ''; + }); + in + final.callPackage clangWithLauncher.override { inherit stdenv; }; + + libllvm = + let + # The Swift build system expects to link statically against LLVM. Trying to link to the `libLLVM` shared + # library causes `swift-frontend` to crash during the build on Linux. + staticLibllvm = final.callPackage prev.libllvm.override { + inherit stdenv; + enableSharedLibraries = false; + }; + in + staticLibllvm.overrideAttrs ( + old: + # Don’t apply the following changes when manpages are built, + # which nulls out these attrs and sets `doCheck` to false. + lib.optionalAttrs (old.pname != "llvm-manpages") { + patches = (old.patches or [ ]) ++ [ + # Ensure the LLVM module cache is in a writable location during builds. + ./patches/llvm/module-cache.patch + ]; + doCheck = false; # TODO: fix fork-specific tests that fail due to, e.g., not finding `libLLVM.dylib` during the test + # Swift relies on LLVM’s private `config.h` for feature checks (e.g., for `unistd.h`). + postInstall = (old.postInstall or "") + '' + cp include/llvm/Config/config.h "$dev/include/llvm/Config/config.h" + ''; + } + ); + } + ) diff --git a/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/clang/gnu-install-dirs.patch b/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/clang/gnu-install-dirs.patch new file mode 100644 index 000000000000..56fe048df79d --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/clang/gnu-install-dirs.patch @@ -0,0 +1,95 @@ +diff --git a/cmake/modules/AddClang.cmake b/cmake/modules/AddClang.cmake +index 75b0080f6..c895b884c 100644 +--- a/cmake/modules/AddClang.cmake ++++ b/cmake/modules/AddClang.cmake +@@ -119,8 +119,8 @@ macro(add_clang_library name) + install(TARGETS ${lib} + COMPONENT ${lib} + ${export_to_clangtargets} +- LIBRARY DESTINATION lib${LLVM_LIBDIR_SUFFIX} +- ARCHIVE DESTINATION lib${LLVM_LIBDIR_SUFFIX} ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}${LLVM_LIBDIR_SUFFIX}" ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}${LLVM_LIBDIR_SUFFIX}" + RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") + + if (NOT LLVM_ENABLE_IDE) +diff --git a/lib/Headers/CMakeLists.txt b/lib/Headers/CMakeLists.txt +index e6ae4e19e..5ef01aea2 100644 +--- a/lib/Headers/CMakeLists.txt ++++ b/lib/Headers/CMakeLists.txt +@@ -337,6 +337,7 @@ set(llvm_libc_wrapper_files + + include(GetClangResourceDir) + get_clang_resource_dir(output_dir PREFIX ${LLVM_LIBRARY_OUTPUT_INTDIR}/.. SUBDIR include) ++set(header_install_dir ${CMAKE_INSTALL_LIBDIR}${LLVM_LIBDIR_SUFFIX}/clang/${CLANG_VERSION_MAJOR}/include) + set(out_files) + set(generated_files) + +diff --git a/tools/libclang/CMakeLists.txt b/tools/libclang/CMakeLists.txt +index b5b6d2807..6b592d255 100644 +--- a/tools/libclang/CMakeLists.txt ++++ b/tools/libclang/CMakeLists.txt +@@ -246,7 +246,7 @@ foreach(PythonVersion ${CLANG_PYTHON_BINDINGS_VERSIONS}) + COMPONENT + libclang-python-bindings + DESTINATION +- "lib${LLVM_LIBDIR_SUFFIX}/python${PythonVersion}/site-packages") ++ "${CMAKE_INSTALL_LIBDIR}${LLVM_LIBDIR_SUFFIX}/python${PythonVersion}/site-packages") + endforeach() + if(NOT LLVM_ENABLE_IDE) + add_custom_target(libclang-python-bindings) +diff --git a/tools/scan-build-py/CMakeLists.txt b/tools/scan-build-py/CMakeLists.txt +index 3aca22c0b..3115353e3 100644 +--- a/tools/scan-build-py/CMakeLists.txt ++++ b/tools/scan-build-py/CMakeLists.txt +@@ -88,7 +88,7 @@ foreach(lib ${LibScanbuild}) + DEPENDS ${CMAKE_CURRENT_SOURCE_DIR}/lib/libscanbuild/${lib}) + list(APPEND Depends ${CMAKE_BINARY_DIR}/lib/libscanbuild/${lib}) + install(FILES lib/libscanbuild/${lib} +- DESTINATION lib/libscanbuild ++ DESTINATION "${CMAKE_INSTALL_LIBDIR}/libscanbuild" + COMPONENT scan-build-py) + endforeach() + +@@ -106,7 +106,7 @@ foreach(resource ${LibScanbuildResources}) + DEPENDS ${CMAKE_CURRENT_SOURCE_DIR}/lib/libscanbuild/resources/${resource}) + list(APPEND Depends ${CMAKE_BINARY_DIR}/lib/libscanbuild/resources/${resource}) + install(FILES lib/libscanbuild/resources/${resource} +- DESTINATION lib/libscanbuild/resources ++ DESTINATION "${CMAKE_INSTALL_LIBDIR}/libscanbuild/resources" + COMPONENT scan-build-py) + endforeach() + +@@ -122,7 +122,7 @@ foreach(lib ${LibEar}) + DEPENDS ${CMAKE_CURRENT_SOURCE_DIR}/lib/libear/${lib}) + list(APPEND Depends ${CMAKE_BINARY_DIR}/lib/libear/${lib}) + install(FILES lib/libear/${lib} +- DESTINATION lib/libear ++ DESTINATION "${CMAKE_INSTALL_LIBDIR}/libear" + COMPONENT scan-build-py) + endforeach() + +diff --git a/clang/tools/clang-scan-deps/CMakeLists.txt b/clang/tools/clang-scan-deps/CMakeLists.txt +index d0ab60b890..7cec331b68 100644 +--- a/tools/clang-scan-deps/CMakeLists.txt ++++ b/tools/clang-scan-deps/CMakeLists.txt +@@ -36,17 +36,9 @@ + ${CLANG_SCAN_DEPS_LIB_DEPS} + ) + +-add_custom_command(OUTPUT ${LLVM_TOOLS_BINARY_DIR}/clang-deps-launcher.py +- DEPENDS ${CMAKE_CURRENT_SOURCE_DIR}/clang-deps-launcher.py +- COMMAND ${CMAKE_COMMAND} -E copy_if_different +- "${CMAKE_CURRENT_SOURCE_DIR}/clang-deps-launcher.py" +- "${LLVM_TOOLS_BINARY_DIR}/clang-deps-launcher.py" +- COMMENT "Copy clang-deps-launcher.py..." +- ) +- +-add_custom_target(clang-deps-launcher ALL DEPENDS ${LLVM_TOOLS_BINARY_DIR}/clang-deps-launcher.py) ++add_custom_target(clang-deps-launcher ALL DEPENDS ${CMAKE_CURRENT_SOURCE_DIR}/clang-deps-launcher.py) + install( +- FILES ${LLVM_TOOLS_BINARY_DIR}/clang-deps-launcher.py ++ FILES ${CMAKE_CURRENT_SOURCE_DIR}/clang-deps-launcher.py + DESTINATION bin + PERMISSIONS OWNER_READ OWNER_WRITE OWNER_EXECUTE GROUP_READ GROUP_EXECUTE WORLD_READ WORLD_EXECUTE + COMPONENT clang-deps-launcher) diff --git a/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/llvm/backport-darwin-triple-parsing.patch b/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/llvm/backport-darwin-triple-parsing.patch new file mode 100644 index 000000000000..e8965369cc56 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/llvm/backport-darwin-triple-parsing.patch @@ -0,0 +1,19 @@ +diff --git a/lib/TargetParser/Triple.cpp b/lib/TargetParser/Triple.cpp +index 53922e7586..665e1e1d62 100644 +--- a/lib/TargetParser/Triple.cpp ++++ b/lib/TargetParser/Triple.cpp +@@ -1398,9 +1398,12 @@ + } else if (Version.getMajor() < 25) { + // darwin20-24 corresponds to macOS 11-15. + Version = VersionTuple(11 + Version.getMajor() - 20); +- } else { +- // darwin25 corresponds with macOS26+. ++ } else if ((Version.getMajor() == 25) || (Version.getMajor() == 26)) { ++ // darwin25-26 corresponds to macOS 26-27. + Version = VersionTuple(Version.getMajor() + 1); ++ } else { ++ // Starting with darwin27, it naturally corresponds to the same macOS ++ // version. + } + break; + case MacOSX: diff --git a/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/llvm/module-cache.patch b/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/llvm/module-cache.patch new file mode 100644 index 000000000000..d140f1eb5587 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/llvm/module-cache.patch @@ -0,0 +1,35 @@ +The compiler fails if LLVM modules are enabled and it cannot write its module +cache. This patch detects and rejects the fake, non-existant $HOME used in Nix +builds. + +We could simply return false in `cache_directory`, but that completely disables +module caching, and may unnecessarily slow down builds. Instead, let it use a +a `module-cache` folder at the top of the build. + +diff --git a/lib/Support/Unix/Path.inc b/lib/Support/Unix/Path.inc +index 660b3a6a3fe0..92fad8a72534 100644 +--- a/lib/Support/Unix/Path.inc ++++ b/lib/Support/Unix/Path.inc +@@ -1431,6 +1431,9 @@ bool user_config_directory(SmallVectorImpl &result) { + if (!home_directory(result)) { + return false; + } ++ if (std::equal(result.begin(), result.end(), "/homeless-shelter")) { ++ return false; ++ } + append(result, ".config"); + return true; + } +@@ -1452,6 +1455,12 @@ bool cache_directory(SmallVectorImpl &result) { + if (!home_directory(result)) { + return false; + } ++ if (const char *NixBuildTop = getenv("NIX_BUILD_TOP")) { ++ result.clear(); ++ result.append(NixBuildTop, NixBuildTop + strlen(NixBuildTop)); ++ append(result, "module-cache"); ++ return true; ++ } + append(result, ".cache"); + return true; + } diff --git a/pkgs/development/compilers/swift_ng/sources-6.2.json b/pkgs/development/compilers/swift_ng/sources-6.2.json index 2c63c0851048..5ba460c73672 100644 --- a/pkgs/development/compilers/swift_ng/sources-6.2.json +++ b/pkgs/development/compilers/swift_ng/sources-6.2.json @@ -1,2 +1,5 @@ { + "llvm-project": { + "hash": "sha256-5Nb8rQmk6onrc4wKW/kT38FsYsWTqMBWtsHYZLA/0Po=" + } } diff --git a/pkgs/top-level/swift-packages.nix b/pkgs/top-level/swift-packages.nix index 889db69e582d..b19baadfd093 100644 --- a/pkgs/top-level/swift-packages.nix +++ b/pkgs/top-level/swift-packages.nix @@ -1,4 +1,6 @@ let + autoCalledPackages = import ./by-name-overlay.nix ../development/compilers/swift_ng/by-name; + swift_sources_6_2 = builtins.fromJSON ( builtins.readFile ../development/compilers/swift_ng/sources-6.2.json ); @@ -17,8 +19,8 @@ makeScopeWithSplicing' { extra = self: { swift_sources = swift_sources_6_2; }; - f = self: { + f = lib.extends autoCalledPackages (self: { stdenv = clangStdenv; swift_release = "6.2.4"; - }; + }); } From b2f39c4a7e6235fb737be40be8c74351a988bbf7 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 181/423] swiftPackages_ng.swift-cmark: init at 0.8.0 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Swift requires its own fork of cmark. It doesn’t need a Swift compiler, so it can be introduced separately from the commit that adds it. --- .../by-name/sw/swift-cmark/package.nix | 44 +++++++++++++++++++ 1 file changed, 44 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-cmark/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-cmark/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift-cmark/package.nix new file mode 100644 index 000000000000..c6464db67e6b --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-cmark/package.nix @@ -0,0 +1,44 @@ +{ + lib, + cmake, + fetchFromGitHub, + gitUpdater, + ninja, + stdenv, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "swift-cmark"; + version = "0.8.0"; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-cmark"; + tag = finalAttrs.version; + hash = "sha256-0pyZ5yQRsbiKwz2XT8N6dMwCLcmM28qQOrxHcV6uH7g="; + }; + + strictDeps = true; + + nativeBuildInputs = [ + cmake + ninja + ]; + + doCheck = stdenv.buildPlatform.canExecute stdenv.hostPlatform; + + passthru.updateScript = gitUpdater { }; + + __structuredAttrs = true; + + meta = { + description = "CommonMark parsing and rendering library"; + homepage = "https://github.com/swiftlang/swift-cmark"; + platforms = lib.platforms.unix ++ lib.platforms.windows ++ lib.platforms.wasi; + license = [ + lib.licenses.bsd2 + lib.licenses.mit + ]; + teams = [ lib.teams.swift ]; + }; +}) From cf5da7e5b8ba07a40187cbefd3359aed49cb255e Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 182/423] swiftPackages_ng.swift-corelibs-libdispatch: init at 6.2.4 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit This could probably be done as a drop-in replacement for the existing `swiftPackages.Dispatch` package, but it’s easier to keep it separate. One key change from this package is that the Swift overlay uses the same shared libraries as the non-Swift build of the package, which makes bootstrapping easier because everything can link the same libdispatch. --- .../files/dispatchConfig.cmake | 20 ++++ .../sw/swift-corelibs-libdispatch/package.nix | 94 +++++++++++++++++++ .../patches/0001-gnu-install-dirs.patch | 60 ++++++++++++ ...0002-Don-t-include-sys-cdefs-on-Musl.patch | 32 +++++++ .../compilers/swift_ng/sources-6.2.json | 3 + 5 files changed, 209 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-libdispatch/files/dispatchConfig.cmake create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-libdispatch/package.nix create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-libdispatch/patches/0001-gnu-install-dirs.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-libdispatch/patches/0002-Don-t-include-sys-cdefs-on-Musl.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-libdispatch/files/dispatchConfig.cmake b/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-libdispatch/files/dispatchConfig.cmake new file mode 100644 index 000000000000..514017631268 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-libdispatch/files/dispatchConfig.cmake @@ -0,0 +1,20 @@ +add_library(BlocksRuntime @buildType@ IMPORTED) +set_target_properties(BlocksRuntime PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}BlocksRuntime${CMAKE_@buildType@_LIBRARY_SUFFIX}" +) + +add_library(dispatch @buildType@ IMPORTED) +set_target_properties(dispatch PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}dispatch${CMAKE_@buildType@_LIBRARY_SUFFIX}" +) + +set_target_properties(dispatch PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES "@dev@/include" + INTERFACE_LINK_LIBRARIES "BlocksRuntime" +) + +add_library(swiftDispatch @buildType@ IMPORTED) +set_target_properties(swiftDispatch PROPERTIES + IMPORTED_LOCATION "@out-swift@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}swiftDispatch${CMAKE_@buildType@_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@dev-swift@/lib/swift;@dev-swift@/lib/swift/@swiftPlatform@" +) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-libdispatch/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-libdispatch/package.nix new file mode 100644 index 000000000000..dbb318a4e9b7 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-libdispatch/package.nix @@ -0,0 +1,94 @@ +{ + lib, + cmake, + fetchFromGitHub, + fetchpatch2, + lld, + ninja, + stdenv, + swift-corelibs-libdispatch, + swift_release, + swift_sources, +}: + +let + swift-corelibs-libdispatch-no-overlay-lib = placeholder "out"; + swift-corelibs-libdispatch-no-overlay-dev = placeholder "dev"; +in + +stdenv.mkDerivation (finalAttrs: { + pname = "swift-corelibs-libdispatch"; + version = swift_release; + + outputs = [ + "out" + "dev" + "man" + ]; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-corelibs-libdispatch"; + tag = "swift-${finalAttrs.version}-RELEASE"; + inherit (swift_sources.swift-corelibs-libdispatch) hash; + }; + + patches = [ + ./patches/0001-gnu-install-dirs.patch + # Nixpkgs includes `sys/cdefs.h` from Alpine, which breaks the build due to `-Werror`. + ./patches/0002-Don-t-include-sys-cdefs-on-Musl.patch + # Fixes `implicit conversion changes signedness` error. + (fetchpatch2 { + url = "https://github.com/swiftlang/swift-corelibs-libdispatch/commit/38872e2d44d66d2fb94186988509defc734888a5.patch?full_index=1"; + hash = "sha256-BXTv79ej93CBrHtEzHDu+3WkIfzEctwyqBoPkNQQkAA="; + }) + ]; + + strictDeps = true; + + cmakeFlags = [ + # The Swift overlay is built separately using the no-overlay derivation as a base. + (lib.cmakeBool "ENABLE_SWIFT" false) + ] + ++ lib.optionals stdenv.hostPlatform.isMusl [ + # Musl requires _GNU_SOURCE or the getprogname shim fails to build. + (lib.cmakeFeature "CMAKE_C_FLAGS" "-D_GNU_SOURCE=1") + ] + ++ lib.optionals stdenv.hostPlatform.isWindows [ + # Linking for Windows requires using LLD. + (lib.cmakeFeature "CMAKE_LINKER_TYPE" "LLD") + ]; + + nativeBuildInputs = [ + cmake + ninja + ] + ++ lib.optionals stdenv.hostPlatform.isWindows [ lld ]; + + postInstall = '' + libExt=${stdenv.hostPlatform.extensions.library} + + # Provide a CMake module. This is primarily used to glue together parts of + # the Swift toolchain. Modifying the CMake config to do this for us is + # otherwise more trouble. + mkdir -p "''${!outputDev}/lib/cmake/dispatch" + substitute ${./files/dispatchConfig.cmake} "''${!outputDev}/lib/cmake/dispatch/dispatchConfig.cmake" \ + --replace-fail '@buildType@' ${if stdenv.hostPlatform.isStatic then "STATIC" else "SHARED"} \ + --replace-fail '@swiftPlatform@' ${stdenv.hostPlatform.swift.platform} \ + --replace-fail '@lib@' ${swift-corelibs-libdispatch-no-overlay-lib} \ + --replace-fail '@dev@' ${swift-corelibs-libdispatch-no-overlay-dev} \ + --replace-fail '@out-swift@' "$out" \ + --replace-fail '@dev-swift@' "''${!outputDev}" + ''; + + __structuredAttrs = true; + + meta = { + description = "Grand Central Dispatch"; + homepage = "https://github.com/swiftlang/swift-corelibs-libdispatch"; + platforms = lib.platforms.freebsd ++ lib.platforms.linux ++ lib.platforms.windows; + license = lib.licenses.asl20; + maintainers = with lib.maintainers; [ cmm ]; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-libdispatch/patches/0001-gnu-install-dirs.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-libdispatch/patches/0001-gnu-install-dirs.patch new file mode 100644 index 000000000000..c6abc42dc584 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-libdispatch/patches/0001-gnu-install-dirs.patch @@ -0,0 +1,60 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 4 Jul 2026 15:19:17 -0400 +Subject: [PATCH 1/2] gnu-install-dirs + +--- + src/BlocksRuntime/CMakeLists.txt | 4 ++-- + src/CMakeLists.txt | 4 ++-- + src/swift/CMakeLists.txt | 6 +++--- + 3 files changed, 7 insertions(+), 7 deletions(-) + +diff --git a/src/BlocksRuntime/CMakeLists.txt b/src/BlocksRuntime/CMakeLists.txt +index f6fde93..189131e 100644 +--- a/src/BlocksRuntime/CMakeLists.txt ++++ b/src/BlocksRuntime/CMakeLists.txt +@@ -34,6 +34,6 @@ endif() + set_property(GLOBAL APPEND PROPERTY DISPATCH_EXPORTS BlocksRuntime) + install(TARGETS BlocksRuntime + EXPORT dispatchExports +- ARCHIVE DESTINATION ${INSTALL_TARGET_DIR} +- LIBRARY DESTINATION ${INSTALL_TARGET_DIR} ++ ARCHIVE DESTINATION ${CMAKE_INSTALL_LIBDIR} ++ LIBRARY DESTINATION ${CMAKE_INSTALL_LIBDIR} + RUNTIME DESTINATION ${CMAKE_INSTALL_BINDIR}) +diff --git a/src/CMakeLists.txt b/src/CMakeLists.txt +index 846fb39..d09a5aa 100644 +--- a/src/CMakeLists.txt ++++ b/src/CMakeLists.txt +@@ -182,6 +182,6 @@ endif() + set_property(GLOBAL APPEND PROPERTY DISPATCH_EXPORTS dispatch) + install(TARGETS dispatch + EXPORT dispatchExports +- ARCHIVE DESTINATION ${INSTALL_TARGET_DIR} +- LIBRARY DESTINATION ${INSTALL_TARGET_DIR} ++ ARCHIVE DESTINATION ${CMAKE_INSTALL_LIBDIR} ++ LIBRARY DESTINATION ${CMAKE_INSTALL_LIBDIR} + RUNTIME DESTINATION ${CMAKE_INSTALL_BINDIR}) +diff --git a/src/swift/CMakeLists.txt b/src/swift/CMakeLists.txt +index 38bef37..3326735 100644 +--- a/src/swift/CMakeLists.txt ++++ b/src/swift/CMakeLists.txt +@@ -40,12 +40,12 @@ get_swift_host_arch(swift_arch) + install(FILES + ${CMAKE_CURRENT_BINARY_DIR}/swift/Dispatch.swiftmodule + ${CMAKE_CURRENT_BINARY_DIR}/swift/Dispatch.swiftdoc +- DESTINATION ${INSTALL_TARGET_DIR}/${swift_arch}) ++ DESTINATION "${CMAKE_INSTALL_INCLUDEDIR}/../lib/swift$<$>:_static>/${SWIFT_SYSTEM_NAME}") + set_property(GLOBAL APPEND PROPERTY DISPATCH_EXPORTS swiftDispatch) + install(TARGETS swiftDispatch + EXPORT dispatchExports +- ARCHIVE DESTINATION ${INSTALL_TARGET_DIR} +- LIBRARY DESTINATION ${INSTALL_TARGET_DIR} ++ ARCHIVE DESTINATION ${CMAKE_INSTALL_LIBDIR} ++ LIBRARY DESTINATION ${CMAKE_INSTALL_LIBDIR} + RUNTIME DESTINATION ${CMAKE_INSTALL_BINDIR}) + if(HAVE_OBJC AND NOT BUILD_SHARED_LIBS) + set_property(GLOBAL APPEND PROPERTY DISPATCH_EXPORTS DispatchStubs) +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-libdispatch/patches/0002-Don-t-include-sys-cdefs-on-Musl.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-libdispatch/patches/0002-Don-t-include-sys-cdefs-on-Musl.patch new file mode 100644 index 000000000000..9ef0c0462ba9 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-libdispatch/patches/0002-Don-t-include-sys-cdefs-on-Musl.patch @@ -0,0 +1,32 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Thu, 13 Aug 2026 20:26:09 -0400 +Subject: [PATCH 2/2] =?UTF-8?q?Don=E2=80=99t=20include=20=20on?= + =?UTF-8?q?=20Musl?= +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Nixpkgs includes `sys/cdefs.h` from Alpine, which causes the +`__has_header` check to pass. This would be harmless, but the `#warning` +at the top of `sys/cdefs.h` is turned into an error by `-Werror`. +--- + os/generic_unix_base.h | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/os/generic_unix_base.h b/os/generic_unix_base.h +index b77d2ad..95ffd80 100644 +--- a/os/generic_unix_base.h ++++ b/os/generic_unix_base.h +@@ -25,7 +25,7 @@ + #endif + #include + +-#if __has_include() ++#if __has_include() && (!defined(__linux__) || defined(__GLIBC__)) + #include + #endif + +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/sources-6.2.json b/pkgs/development/compilers/swift_ng/sources-6.2.json index 5ba460c73672..46e9a46b54d8 100644 --- a/pkgs/development/compilers/swift_ng/sources-6.2.json +++ b/pkgs/development/compilers/swift_ng/sources-6.2.json @@ -1,5 +1,8 @@ { "llvm-project": { "hash": "sha256-5Nb8rQmk6onrc4wKW/kT38FsYsWTqMBWtsHYZLA/0Po=" + }, + "swift-corelibs-libdispatch": { + "hash": "sha256-Tu2G9FAP4q1xgM1n9q17T6VrqJ3tv8RezyUex38yNds=" } } From f15734cf5461166518497224b3b3df56daa2d025 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 183/423] swiftPackages_ng: add private alias for upstream LLVM MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit While Swift requires its own fork for libclang and libLLVM, it can work with upstream LLVM tools. When possible, we want to use them. This alias facilitates that. The name was chosen to avoid clashing with the name of the Swift LLVM fork’s package set. --- pkgs/top-level/swift-packages.nix | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/pkgs/top-level/swift-packages.nix b/pkgs/top-level/swift-packages.nix index b19baadfd093..92af07ef9448 100644 --- a/pkgs/top-level/swift-packages.nix +++ b/pkgs/top-level/swift-packages.nix @@ -10,6 +10,7 @@ in lib, clangStdenv, generateSplicesForMkScope, + llvmPackages, makeScopeWithSplicing', otherSplices ? generateSplicesForMkScope "swiftPackages_ng", }: @@ -17,8 +18,10 @@ in makeScopeWithSplicing' { inherit otherSplices; extra = self: { - swift_sources = swift_sources_6_2; - }; + llvmPackages_upstream = llvmPackages; + + swift_sources = swift_sources_6_2; + }; f = lib.extends autoCalledPackages (self: { stdenv = clangStdenv; swift_release = "6.2.4"; From 3b1f177f71c81218b4e2d4c81772fc88e6636f8e Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 184/423] swiftPackages_ng: add private libtool helper package Many Swift packages on Darwin require using its `libtool` to link libraries. The upstream LLVM version is compatible enough for our needs, so we use that one instead of the one from cctools, which should help with future work to enable Linux to Darwin cross-compilation. --- pkgs/top-level/swift-packages.nix | 18 +++++++++++++++++- 1 file changed, 17 insertions(+), 1 deletion(-) diff --git a/pkgs/top-level/swift-packages.nix b/pkgs/top-level/swift-packages.nix index 92af07ef9448..f6d3cbd235d8 100644 --- a/pkgs/top-level/swift-packages.nix +++ b/pkgs/top-level/swift-packages.nix @@ -12,12 +12,28 @@ in generateSplicesForMkScope, llvmPackages, makeScopeWithSplicing', + stdenvNoCC, otherSplices ? generateSplicesForMkScope "swiftPackages_ng", }: makeScopeWithSplicing' { inherit otherSplices; - extra = self: { + extra = + self: + let + llvm_libtool = stdenvNoCC.mkDerivation { + pname = "libtool"; + version = lib.getVersion llvmPackages.llvm; + + buildCommand = '' + mkdir -p "$out/bin" + ln -s ${lib.getExe' llvmPackages.llvm "llvm-libtool-darwin"} "$out/bin/libtool" + ''; + }; + in + { + inherit llvm_libtool; + llvmPackages_upstream = llvmPackages; swift_sources = swift_sources_6_2; From 0dfc837eb437c8271f9fc32948864359139b82b9 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 185/423] swiftPackages_ng.swiftc: init stage 0 at 6.2.4 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The stage 0 Swift compiler is the legacy, C++-based compiler. Its primary purpose is to build a Swift-based compiler that can be used to build the stdlib and final Swift compiler. It’s buggy, but there are patches to work around its limitations. --- .../swift_ng/by-name/sw/swiftc/package.nix | 285 +++++ ...dlib-flags-from-the-wrapped-compiler.patch | 196 ++++ ...-and-C-stdlib-paths-in-ClangImporter.patch | 62 ++ .../patches/0003-cmark-build-revamp.patch | 58 ++ .../patches/0004-sil-missing-headers.patch | 29 + .../patches/0005-specify-liblto-path.patch | 44 + .../0006-use-nixpkgs-libdispatch.patch | 70 ++ ...ind-the-separate-stdlib-and-framewor.patch | 49 + .../0008-revert-optimizer-changes.patch | 981 ++++++++++++++++++ ...09-siloptimizer-bootstrap-workaround.patch | 34 + .../compilers/swift_ng/sources-6.2.json | 3 + pkgs/top-level/swift-packages.nix | 5 + 12 files changed, 1816 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftc/package.nix create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0001-Read-C-and-C-stdlib-flags-from-the-wrapped-compiler.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0002-Use-Nixpkgs-C-and-C-stdlib-paths-in-ClangImporter.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0003-cmark-build-revamp.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0004-sil-missing-headers.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0005-specify-liblto-path.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0006-use-nixpkgs-libdispatch.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0007-Help-Swift-JIT-find-the-separate-stdlib-and-framewor.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0008-revert-optimizer-changes.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0009-siloptimizer-bootstrap-workaround.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/package.nix new file mode 100644 index 000000000000..f5e04b7f479f --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/package.nix @@ -0,0 +1,285 @@ +{ + lib, + apple-sdk_14, + bootstrapStage, + buildSwiftPackages, + cmake, + darwin, + fetchFromGitHub, + fetchpatch2, + libedit, + libffi, + libuuid, + libxml2, + llvmPackages, + llvm_libtool, + ninja, + perl, + python3, + replaceVars, + stdenv, + swift-cmark, + swift-corelibs-libdispatch, + xcbuild, + xz, + zlib, + zstd, + swift_release, + swift_sources, + # This matches _SWIFT_DEFAULT_COMPONENTS, with specific components disabled. + swiftComponents ? [ + "autolink-driver" + # "clang-builtin-headers" + # "clang-resource-dir-symlink" + "compiler" + "compiler-swift-syntax-lib" + # "dev" + "editor-integration" + # "llvm-toolchain-dev-tools" + "license" + "sdk-overlay" + (if stdenv.hostPlatform.isDarwin then "sourcekit-xpc-service" else "sourcekit-inproc") + # "stdlib-experimental" + "swift-syntax-lib" + # "testsuite-tools" + "toolchain-dev-tools" + "toolchain-tools" + # "tools" + "back-deployment" + "sdk-overlay" + "static-mirror-lib" + "stdlib" + "swift-remote-mirror" + "swift-remote-mirror-headers" + ], +}: + +let + build-sdk = apple-sdk_14; + + swift = buildSwiftPackages.swift; + + inherit (llvmPackages) + clang + clang-unwrapped + llvm + + libclang + libllvm + ; + + inherit (darwin) sigtool; + + dylibExt = stdenv.hostPlatform.extensions.sharedLibrary; + + swiftComponents' = swiftComponents; +in + +stdenv.mkDerivation (finalAttrs: { + pname = "swiftc" + lib.optionalString (bootstrapStage == 0) "-cxx_bootstrap"; + version = swift_release; + + outputs = [ + "out" + "dev" + "doc" + "man" + ]; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift"; + tag = "swift-${swift_release}-RELEASE"; + inherit (swift_sources.swift) hash; + }; + + patches = [ + # ClangImporter needs help finding the location of libc and libc++ (and using it). + ./patches/0001-Read-C-and-C-stdlib-flags-from-the-wrapped-compiler.patch + ./patches/0002-Use-Nixpkgs-C-and-C-stdlib-paths-in-ClangImporter.patch + # Backport linking against an external swift-cmark. + # From https://github.com/swiftlang/swift/pull/70791. + ./patches/0003-cmark-build-revamp.patch + # Fix compilation errors when building the SIL module during bootstrap. + # error: field has incomplete type 'clang::DeclContext::all_lookups_iterator' + # error: field has incomplete type 'clang::DeclContext::ddiag_iterator' + ./patches/0004-sil-missing-headers.patch + # Use libLTO.dylib from the LLVM built for Swift + (replaceVars ./patches/0005-specify-liblto-path.patch { + libllvm_path = lib.getLib libllvm; + }) + # Use libdispatch from nixpkgs instead of building it in-tree + ./patches/0006-use-nixpkgs-libdispatch.patch + # The Swift JIT needs help finding dylibs when they are linked into the toolchain at `$out/lib`. + (replaceVars ./patches/0007-Help-Swift-JIT-find-the-separate-stdlib-and-framewor.patch { + swiftPlatform = stdenv.hostPlatform.swift.platform; + }) + # Fix missing when building against libstdc++ 15 + (fetchpatch2 { + url = "https://github.com/swiftlang/swift/commit/a5c727125e952839c373fe47e9f9e359db3d4d38.patch?full_index=1"; + hash = "sha256-OoTcPyqTzAhkxaRAMeu+hab3yoIDRPq6YzK5hrLk4Jg="; + }) + # Fix missing null-terminator on Linux, which results in a crash in `swift repl`. + (fetchpatch2 { + url = "https://github.com/swiftlang/swift/commit/cfbe70db5d1e65bed2388f97ee52f65719c812b3.patch?full_index=1"; + hash = "sha256-XxdP3Qs2YfT20d5E216cOQy+fUgYQpwMDWSyl77NQHw="; + }) + # Revert optimizer changes that cause the C++-based bootstrap compiler to be unable to compile functions with + # infinite loops that return from the loop. This doesn’t affect the later stages, so it’s applied conditionally. + # https://github.com/swiftlang/swift/pull/79186 + ./patches/0008-revert-optimizer-changes.patch + # Work around a compiler crash by partially reverting https://github.com/swiftlang/swift/pull/80920. + ./patches/0009-siloptimizer-bootstrap-workaround.patch + ]; + + postPatch = '' + # Swift doesn’t really _need_ LLVM’s build folder. It only needs to find a built LLVM, which we can provide. + substituteInPlace cmake/modules/SwiftSharedCMakeConfig.cmake \ + --replace-fail "precondition_translate_flag(LLVM_BUILD_LIBRARY_DIR LLVM_LIBRARY_DIR)" "" + + # Fix the path to LLVM’s CMake modules. + substituteInPlace lib/Basic/CMakeLists.txt \ + --replace-fail \''${LLVM_MAIN_SRC_DIR}/cmake/modules ${lib.escapeShellArg (lib.getDev libllvm)}/lib/cmake/llvm + + # Find `features.json` in Clang’s $out not LLVM’s. + substituteInPlace lib/Option/CMakeLists.txt \ + --replace-fail \''${LLVM_BINARY_DIR} ${lib.escapeShellArg (lib.getBin clang-unwrapped)} + + # Make sure Swift can find Clang’s resource dir during the build. + substituteInPlace stdlib/public/SwiftShims/swift/shims/CMakeLists.txt \ + --replace-fail \ + 'set(clang_headers_location "''${LLVM_LIBRARY_OUTPUT_INTDIR}/clang/''${CLANG_VERSION${lib.optionalString (lib.versionAtLeast finalAttrs.version "6.0") "_MAJOR"}}")' \ + 'set(clang_headers_location "${lib.getBin clang}/resource-root")' + + # Use absolute path references for `dlopen`. + substituteInPlace stdlib/public/RuntimeModule/Compression.swift \ + --replace-fail liblzma${dylibExt} ${lib.escapeShellArg (lib.getLib xz)}/lib/liblzma${dylibExt} \ + --replace-fail libz${dylibExt} ${lib.escapeShellArg (lib.getLib zlib)}/lib/libz${dylibExt} \ + --replace-fail libzstd${dylibExt} ${lib.escapeShellArg (lib.getLib zstd)}/lib/libzstd${dylibExt} + + # Make sure Swift uses the external macro plugin server built with the compiler. + substituteInPlace lib/Driver/DarwinToolChains.cpp \ + --replace-fail 'basePath, "usr", "bin", "swift-plugin-server"' "\"$out/bin/swift-plugin-server\"" + + # Only build the runtime for aarch64-darwin. Universal builds aren’t really supported in nixpkgs, + # and the dylibs in the SDK aren’t built as universal. Use `grep` to assert the change was made. + sed -i cmake/modules/SwiftConfigureSDK.cmake \ + -e 's/^\( *\)remove_sdk_unsupported_archs(.*$/\1set(SWIFT_SDK_''${prefix}_ARCHITECTURES "arm64")/' + grep -q 'set(SWIFT_SDK_''${prefix}_ARCHITECTURES "arm64")' cmake/modules/SwiftConfigureSDK.cmake + ''; + + dontFixCmake = true; + + cmakeFlags = [ + # The bootstrap is managed via Nix instead of upstream’s bootstrap-specific bootstrapping modes. + (lib.cmakeFeature "BOOTSTRAPPING_MODE" "HOSTTOOLS") + (lib.cmakeOptionType "list" "SWIFT_INSTALL_COMPONENTS" (lib.concatStringsSep ";" swiftComponents')) + # Needs to be disabled in stage 0 to enable the C++ bootstrap. + (lib.cmakeBool "SWIFT_ENABLE_SWIFT_IN_SWIFT" (bootstrapStage > 0)) + # Swift installs its dylibs to `$lib/lib/swift/host` instead of `$lib/lib`. + (lib.cmakeFeature "CMAKE_INSTALL_NAME_DIR" "${placeholder "out"}/lib/swift/host") + # Make Swift use Clang from nixpkgs instead of building its own. + (lib.cmakeBool "SWIFT_PREBUILT_CLANG" true) + (lib.cmakeFeature "SWIFT_NATIVE_CLANG_TOOLS_PATH" "${lib.getBin clang}/bin") + (lib.cmakeFeature "SWIFT_NATIVE_LLVM_TOOLS_PATH" "${lib.getBin llvm}/bin") + # Swift expects to find these relative to `$src`, but it only actually needs their final build products. + # Instead of being built in the Swift derivation, they’re built separately. This tells CMake how to find them. + (lib.cmakeFeature "Clang_DIR" "${lib.getDev libclang}/lib/cmake/clang") + (lib.cmakeFeature "LLVM_DIR" "${lib.getDev libllvm}/lib/cmake/llvm") + (lib.cmakeFeature "cmark-gfm_DIR" "${swift-cmark.out}/lib/cmake") + # Swift defaults to 10.13, which is too old. Set the deployment target to the minimum supported in nixpkgs. + (lib.cmakeFeature "SWIFT_DARWIN_DEPLOYMENT_VERSION_OSX" stdenv.hostPlatform.darwinMinVersion) + (lib.cmakeFeature "SWIFT_HOST_TRIPLE" stdenv.hostPlatform.swift.triple) + # Tests should only be built when building a regular compiler. The bootstrap compiler is not functional enough. + (lib.cmakeBool "SWIFT_INCLUDE_TESTS" false) + ]; + + env = { + # Swift uses `-apple.macosx` triples instead of `-apple-darwin`, which causes tons of warnings. + NIX_CC_WRAPPER_SUPPRESS_TARGET_WARNING = true; + NIX_CFLAGS_COMPILE = toString ( + # Swift compiles some of its stdlib for older deployment targets without using availability checks. + [ "-Wno-error=unguarded-availability" ] + ); + }; + + preConfigure = + # Swift 6.2 needs to weakly link against `swift_coroFrameAlloc`, which is only in the 26.0 SDK. + # Unfortunately, the 26.0 SDK uses unguarded macros, so the C++ bootstrap compiler has to use the 14.4 SDK. + lib.optionalString stdenv.hostPlatform.isDarwin '' + if [ $NIX_APPLE_SDK_VERSION -lt 260000 ]; then + NIX_LDFLAGS+=" -undefined dynamic_lookup" + fi + ''; + + postConfigure = + # Make sure `swift` can locate the C and C++ standard library relative to `swift` binary in `bin`. + '' + ln -s ${lib.escapeShellArg (lib.getExe' clang "clang")} bin/clang + ''; + + strictDeps = true; + + ninjaFlags = swiftComponents'; + + nativeBuildInputs = [ + cmake + ninja + perl # For pod2man + python3 + swift + ] + ++ lib.optionals stdenv.hostPlatform.isDarwin [ + llvm_libtool + sigtool + xcbuild + ]; + + buildInputs = [ + libedit + libffi + libllvm + libxml2 + swift-cmark.out + zlib + ] + ++ lib.optionals stdenv.hostPlatform.isDarwin [ build-sdk ] + ++ lib.optionals (!stdenv.hostPlatform.isDarwin) [ + libuuid + swift-corelibs-libdispatch + ]; + + postInstall = + # Swift 6 installs private Swift Syntax dylibs to $lib/lib/swift/host/compiler, which `CMAKE_INSTALL_NAME_DIR` + # mangles to the wrong paths. + # Fix up the install names of all the dylibs generated by the build process. fixupDarwinDylibNames doesn’t work. + '' + while IFS= read -d "" dylib; do + dylib_name=$(basename "$dylib") + echo "$dylib: fixing dylib" + install_name_tool "$dylib" -id "$dylib" + done < <(find "''${!outputLib}/lib/swift/host/compiler" -name '*.dylib' -print0) + readarray -t -d "" args < <( + find "''${!outputLib}/lib/swift/host/compiler" -name '*.dylib' \ + -printf "-change\0''${!outputLib}/lib/swift/host/%f\0%p\0" + ) + while IFS= read -d "" exe; do + if [[ "$exe" != *.a ]] && LC_ALL=C isMachO "$exe"; then + res=$(install_name_tool "$exe" "''${args[@]}" 2>&1) + if [[ "$res" =~ invalidate ]]; then codesign -s - -f "$exe"; fi + fi + done < <(find "$out" -type f -print0) + ''; + + __structuredAttrs = true; + + meta = { + description = "Swift Programming Language"; + homepage = "https://github.com/swiftlang/swift"; + mainProgram = "swiftc"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + badPlatforms = [ lib.systems.inspect.patterns.is32bit ]; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0001-Read-C-and-C-stdlib-flags-from-the-wrapped-compiler.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0001-Read-C-and-C-stdlib-flags-from-the-wrapped-compiler.patch new file mode 100644 index 000000000000..7f8aacde44a1 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0001-Read-C-and-C-stdlib-flags-from-the-wrapped-compiler.patch @@ -0,0 +1,196 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sun, 4 Jan 2026 14:37:05 -0500 +Subject: [PATCH 01/10] Read C and C++ stdlib flags from the wrapped compiler +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +On most platforms supported by Nixpkgs, the C and C++ standard libraries +are located separately and are not part of the sysroot, but Swift’s +ClangImporter assumes they are part of the sysroot by default. + +While it is possible to create a sysroot for use with Swift, this has +negative affects on every package that wants to use Swift and compile +C++ code. The C++ library must be removed from the standard platform +configuration, which makes adding Swift as a dependency too disruptive. +--- + include/swift/ClangImporter/ClangImporter.h | 3 +- + lib/ClangImporter/ClangImporter.cpp | 8 ++++ + lib/ClangImporter/ClangIncludePaths.cpp | 18 ++++++-- + lib/ClangImporter/ClangIncludePaths.h | 51 +++++++++++++++++++++ + lib/Frontend/CompilerInvocation.cpp | 2 +- + 5 files changed, 76 insertions(+), 6 deletions(-) + +diff --git a/include/swift/ClangImporter/ClangImporter.h b/include/swift/ClangImporter/ClangImporter.h +index 274c659d54c..d478fbbccec 100644 +--- a/include/swift/ClangImporter/ClangImporter.h ++++ b/include/swift/ClangImporter/ClangImporter.h +@@ -231,7 +231,8 @@ public: + static llvm::opt::InputArgList + createClangArgs(const ClangImporterOptions &ClangImporterOpts, + const SearchPathOptions &SearchPathOpts, +- clang::driver::Driver &clangDriver); ++ clang::driver::Driver &clangDriver, ++ bool enableCXXInterop); + + ClangImporter(const ClangImporter &) = delete; + ClangImporter(ClangImporter &&) = delete; +diff --git a/lib/ClangImporter/ClangImporter.cpp b/lib/ClangImporter/ClangImporter.cpp +index 47361b38a0f..1b50ea3ab44 100644 +--- a/lib/ClangImporter/ClangImporter.cpp ++++ b/lib/ClangImporter/ClangImporter.cpp +@@ -564,7 +564,15 @@ void importer::getNormalInvocationArguments( + }); + } + ++ // Ensure libc is available. The C standard library is separate from the sysroot ++ // on most platforms in Nixpkgs. (Darwin is a prominent exception.) ++ addFlagsFromNixCC(invocationArgStrs, "libc-cflags"); ++ + if (LangOpts.EnableCXXInterop) { ++ // Ensure the libc++ headers are available. The C++ standard library is separate ++ // from the sysroot on most platforms in Nixpkgs. ++ addFlagsFromNixCC(invocationArgStrs, "libcxx-cxxflags"); ++ + if (auto path = getCxxShimModuleMapPath(searchPathOpts, LangOpts, triple)) { + invocationArgStrs.push_back((Twine("-fmodule-map-file=") + *path).str()); + } +diff --git a/lib/ClangImporter/ClangIncludePaths.cpp b/lib/ClangImporter/ClangIncludePaths.cpp +index 948b99876f0..b46ec2980f0 100644 +--- a/lib/ClangImporter/ClangIncludePaths.cpp ++++ b/lib/ClangImporter/ClangIncludePaths.cpp +@@ -178,12 +178,22 @@ static std::optional findFirstIncludeDir( + llvm::opt::InputArgList + ClangImporter::createClangArgs(const ClangImporterOptions &ClangImporterOpts, + const SearchPathOptions &SearchPathOpts, +- clang::driver::Driver &clangDriver) { ++ clang::driver::Driver &clangDriver, ++ bool enableCXXInterop) { + // Flags passed to Swift with `-Xcc` might affect include paths. + std::vector clangArgs; + for (const auto &each : ClangImporterOpts.ExtraArgs) { + clangArgs.push_back(each.c_str()); + } ++ ++ // Ensure libc is available. The C standard library is separate from the sysroot ++ // on most platforms in Nixpkgs. (Darwin is a prominent exception.) ++ addFlagsFromNixCC(clangArgs, "libc-cflags"); ++ ++ if (enableCXXInterop) { ++ addFlagsFromNixCC(clangArgs, "libcxx-cxxflags"); ++ } ++ + llvm::opt::InputArgList clangDriverArgs = + parseClangDriverArgs(clangDriver, clangArgs); + // If an SDK path was explicitly passed to Swift, make sure to pass it to +@@ -207,7 +217,7 @@ getLibcFileMapping(const ASTContext &ctx, StringRef modulemapFileName, + auto [clangDriver, clangDiagEngine] = ClangImporter::createClangDriver( + ctx.LangOpts, ctx.ClangImporterOpts, vfs); + auto clangDriverArgs = ClangImporter::createClangArgs( +- ctx.ClangImporterOpts, ctx.SearchPathOpts, clangDriver); ++ ctx.ClangImporterOpts, ctx.SearchPathOpts, clangDriver, ctx.LangOpts.EnableCXXInterop); + + llvm::opt::ArgStringList includeArgStrings; + const auto &clangToolchain = +@@ -286,7 +296,7 @@ static void getLibStdCxxFileMapping( + auto [clangDriver, clangDiagEngine] = ClangImporter::createClangDriver( + ctx.LangOpts, ctx.ClangImporterOpts, vfs); + auto clangDriverArgs = ClangImporter::createClangArgs( +- ctx.ClangImporterOpts, ctx.SearchPathOpts, clangDriver); ++ ctx.ClangImporterOpts, ctx.SearchPathOpts, clangDriver, ctx.LangOpts.EnableCXXInterop); + + llvm::opt::ArgStringList stdlibArgStrings; + const auto &clangToolchain = +@@ -467,7 +477,7 @@ void GetWindowsFileMappings( + auto [Driver, clangDiagEngine] = ClangImporter::createClangDriver( + Context.LangOpts, Context.ClangImporterOpts, driverVFS); + const llvm::opt::InputArgList Args = ClangImporter::createClangArgs( +- Context.ClangImporterOpts, Context.SearchPathOpts, Driver); ++ Context.ClangImporterOpts, Context.SearchPathOpts, Driver, Context.LangOpts.EnableCXXInterop); + const clang::driver::ToolChain &ToolChain = Driver.getToolChain(Args, Triple); + llvm::vfs::FileSystem &VFS = ToolChain.getVFS(); + +diff --git a/lib/ClangImporter/ClangIncludePaths.h b/lib/ClangImporter/ClangIncludePaths.h +index 7f08397fa7d..69be98357d9 100644 +--- a/lib/ClangImporter/ClangIncludePaths.h ++++ b/lib/ClangImporter/ClangIncludePaths.h +@@ -14,6 +14,8 @@ + #define SWIFT_CLANG_INCLUDE_PATHS_H + + #include "swift/AST/ASTContext.h" ++#include "llvm/ADT/StringRef.h" ++#include "llvm/Support/CommandLine.h" + + namespace swift { + +@@ -23,4 +25,53 @@ getCxxShimModuleMapPath(SearchPathOptions &opts, const LangOptions &langOpts, + + } // namespace swift + ++template ++void addFlagsFromNixCC(std::vector &invocationArgStrs, const char* flagFile) { ++ auto swiftPath = llvm::sys::fs::getMainExecutable(nullptr, nullptr); ++ ++ if (swiftPath != "") { ++ llvm::BumpPtrAllocator allocator; ++ llvm::StringSaver saver(allocator); ++ ++ // Read `flagFile` from Clang’s `nix-support` folder by finding it relative to the store ++ // location of `clang`, which is expected to be adjacent to Swift in `$out/bin`. ++ llvm::SmallString<256> clangPath = llvm::StringRef(swiftPath); ++ llvm::sys::path::remove_filename(clangPath); ++ llvm::sys::path::append(clangPath, "clang"); ++ ++ llvm::SmallString<256> path; ++ ++ // This shouldn’t happen, but if `real_path` fails to resolve `clang`, give up. ++ if (llvm::sys::fs::real_path(clangPath, path, /*expand_tilde*/ true)) { return; } ++ ++ llvm::sys::path::remove_filename(path); ++ llvm::sys::path::remove_filename(path); ++ llvm::sys::path::append(path, "nix-support", flagFile); ++ ++ // Treat `flagFile` as a response file for Clang. Because Clang expects response ++ // files to be expanded already at this point, it has to be expanded manually. ++ if (auto buffer = llvm::vfs::getRealFileSystem()->getBufferForFile(path)) { ++ auto contents = (*buffer)->getMemBufferRef().getBuffer(); ++ llvm::SmallVector args; ++#if _WIN32 ++ llvm::cl::TokenizeWindowsCommandLineNoCopy(contents, saver, args); ++#else ++ llvm::cl::TokenizeGNUCommandLine(contents, saver, args); ++#endif ++ for (auto arg : args) { ++ auto arg_str = [&arg = arg]() constexpr { ++ if constexpr (std::is_same::value) { ++ // This leaks, but there doesn’t seem to be a better way. ++ auto len = std::strlen(arg) + 1; ++ return std::strncpy(new char[len], arg, len); ++ } else { ++ return arg; ++ } ++ }(); ++ invocationArgStrs.push_back(arg_str); ++ } ++ } ++ } ++} ++ + #endif // SWIFT_CLANG_INCLUDE_PATHS_H +diff --git a/lib/Frontend/CompilerInvocation.cpp b/lib/Frontend/CompilerInvocation.cpp +index ed413f2be91..f866b49ba3a 100644 +--- a/lib/Frontend/CompilerInvocation.cpp ++++ b/lib/Frontend/CompilerInvocation.cpp +@@ -401,7 +401,7 @@ void CompilerInvocation::computeCXXStdlibOptions() { + auto [clangDriver, clangDiagEngine] = + ClangImporter::createClangDriver(LangOpts, ClangImporterOpts); + auto clangDriverArgs = ClangImporter::createClangArgs( +- ClangImporterOpts, SearchPathOpts, clangDriver); ++ ClangImporterOpts, SearchPathOpts, clangDriver, LangOpts.EnableCXXInterop); + auto &clangToolchain = + clangDriver.getToolChain(clangDriverArgs, LangOpts.Target); + auto cxxStdlibKind = clangToolchain.GetCXXStdlibType(clangDriverArgs); +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0002-Use-Nixpkgs-C-and-C-stdlib-paths-in-ClangImporter.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0002-Use-Nixpkgs-C-and-C-stdlib-paths-in-ClangImporter.patch new file mode 100644 index 000000000000..65f9552f0a0f --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0002-Use-Nixpkgs-C-and-C-stdlib-paths-in-ClangImporter.patch @@ -0,0 +1,62 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sun, 4 Jan 2026 14:37:05 -0500 +Subject: [PATCH 02/10] Use Nixpkgs C and C++ stdlib paths in ClangImporter + +This code injects an LLVM modulemap for glibc and libstdc++ by +overriding specific VFS paths. In order to do that, it needs to know the +actual locations of glibc and libstdc++, but it only searches `-sysroot` +and fails. Here we patch it to also consider `-idirafter` and `-isystem` +as added by cc-wrapper. +--- + lib/ClangImporter/ClangIncludePaths.cpp | 13 +++++++++++-- + 1 file changed, 11 insertions(+), 2 deletions(-) + +diff --git a/lib/ClangImporter/ClangIncludePaths.cpp b/lib/ClangImporter/ClangIncludePaths.cpp +index b46ec2980f0..9099b3066ab 100644 +--- a/lib/ClangImporter/ClangIncludePaths.cpp ++++ b/lib/ClangImporter/ClangIncludePaths.cpp +@@ -144,6 +144,7 @@ ClangImporter::createClangDriver( + /// \return a path without dots (`../`, './'). + static std::optional findFirstIncludeDir( + const llvm::opt::InputArgList &args, ++ const llvm::opt::ArgList &DriverArgs, + const ArrayRef expectedFileNames, + const llvm::IntrusiveRefCntPtr &vfs) { + // C++ stdlib paths are added as `-internal-isystem`. +@@ -153,6 +154,14 @@ static std::optional findFirstIncludeDir( + llvm::append_range(includeDirs, + args.getAllArgValues( + clang::driver::options::OPT_internal_externc_isystem)); ++ // Nix adds the C stdlib include path using `-idirafter`. ++ llvm::append_range(includeDirs, ++ DriverArgs.getAllArgValues( ++ clang::driver::options::OPT_idirafter)); ++ // Nix adds the C++ stdlib include path using `-cxx-isystem`. ++ llvm::append_range(includeDirs, ++ DriverArgs.getAllArgValues( ++ clang::driver::options::OPT_cxx_isystem)); + + for (const auto &includeDir : includeDirs) { + Path dir(includeDir); +@@ -231,7 +240,7 @@ getLibcFileMapping(const ASTContext &ctx, StringRef modulemapFileName, + // modulemap are present. + Path libcDir; + if (auto dir = findFirstIncludeDir( +- parsedIncludeArgs, {"inttypes.h", "unistd.h", "stdint.h"}, vfs)) { ++ parsedIncludeArgs, clangDriverArgs, {"inttypes.h", "unistd.h", "stdint.h"}, vfs)) { + libcDir = dir.value(); + } else { + if (!suppressDiagnostic) +@@ -312,7 +321,7 @@ static void getLibStdCxxFileMapping( + return; + + Path cxxStdlibDir; +- if (auto dir = findFirstIncludeDir(parsedStdlibArgs, ++ if (auto dir = findFirstIncludeDir(parsedStdlibArgs, clangDriverArgs, + {"cstdlib", "string", "vector"}, vfs)) { + cxxStdlibDir = dir.value(); + } else { +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0003-cmark-build-revamp.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0003-cmark-build-revamp.patch new file mode 100644 index 000000000000..2d43885b8bdb --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0003-cmark-build-revamp.patch @@ -0,0 +1,58 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sun, 4 Jan 2026 14:38:01 -0500 +Subject: [PATCH 03/10] cmark-build-revamp + +--- + cmake/modules/SwiftSharedCMakeConfig.cmake | 28 ---------------------- + 1 file changed, 28 deletions(-) + +diff --git a/cmake/modules/SwiftSharedCMakeConfig.cmake b/cmake/modules/SwiftSharedCMakeConfig.cmake +index ff552d65a90..3bbd6a13262 100644 +--- a/cmake/modules/SwiftSharedCMakeConfig.cmake ++++ b/cmake/modules/SwiftSharedCMakeConfig.cmake +@@ -198,33 +198,6 @@ macro(swift_common_standalone_build_config_clang product) + include_directories(${CLANG_INCLUDE_DIRS}) + endmacro() + +-macro(swift_common_standalone_build_config_cmark product) +- set(${product}_PATH_TO_CMARK_SOURCE "${${product}_PATH_TO_CMARK_SOURCE}" +- CACHE PATH "Path to CMark source code.") +- set(${product}_PATH_TO_CMARK_BUILD "${${product}_PATH_TO_CMARK_BUILD}" +- CACHE PATH "Path to the directory where CMark was built.") +- set(${product}_CMARK_LIBRARY_DIR "${${product}_CMARK_LIBRARY_DIR}" CACHE PATH +- "Path to the directory where CMark was installed.") +- get_filename_component(PATH_TO_CMARK_BUILD "${${product}_PATH_TO_CMARK_BUILD}" +- ABSOLUTE) +- get_filename_component(CMARK_MAIN_SRC_DIR "${${product}_PATH_TO_CMARK_SOURCE}" +- ABSOLUTE) +- get_filename_component(CMARK_LIBRARY_DIR "${${product}_CMARK_LIBRARY_DIR}" +- ABSOLUTE) +- +- set(CMARK_MAIN_INCLUDE_DIR "${CMARK_MAIN_SRC_DIR}/src/include") +- set(CMARK_BUILD_INCLUDE_DIR "${PATH_TO_CMARK_BUILD}/src") +- +- file(TO_CMAKE_PATH "${CMARK_MAIN_INCLUDE_DIR}" CMARK_MAIN_INCLUDE_DIR) +- file(TO_CMAKE_PATH "${CMARK_BUILD_INCLUDE_DIR}" CMARK_BUILD_INCLUDE_DIR) +- +- include_directories("${CMARK_MAIN_INCLUDE_DIR}" +- "${CMARK_BUILD_INCLUDE_DIR}") +- +- include(${PATH_TO_CMARK_BUILD}/src/cmarkTargets.cmake) +- add_definitions(-DCMARK_STATIC_DEFINE) +-endmacro() +- + # Common cmake project config for standalone builds. + # + # Parameters: +@@ -235,7 +208,6 @@ macro(swift_common_standalone_build_config product) + swift_common_standalone_build_config_llvm(${product}) + if(SWIFT_INCLUDE_TOOLS) + swift_common_standalone_build_config_clang(${product}) +- swift_common_standalone_build_config_cmark(${product}) + endif() + + # Enable groups for IDE generators (Xcode and MSVC). +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0004-sil-missing-headers.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0004-sil-missing-headers.patch new file mode 100644 index 000000000000..12e9e1df17a9 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0004-sil-missing-headers.patch @@ -0,0 +1,29 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sun, 4 Jan 2026 14:46:08 -0500 +Subject: [PATCH 04/10] sil-missing-headers + +Fix compilation errors when building the SIL module during bootstrap. + + error: field has incomplete type 'clang::DeclContext::all_lookups_iterator' + error: field has incomplete type 'clang::DeclContext::ddiag_iterator' +--- + include/swift/AST/ASTBridging.h | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/include/swift/AST/ASTBridging.h b/include/swift/AST/ASTBridging.h +index 115d6849866..deeb500e3b3 100644 +--- a/include/swift/AST/ASTBridging.h ++++ b/include/swift/AST/ASTBridging.h +@@ -24,6 +24,8 @@ + #ifdef USED_IN_CPP_SOURCE + #include "swift/AST/Attr.h" + #include "swift/AST/Decl.h" ++#include "clang/AST/DeclLookups.h" ++#include "clang/AST/DependentDiagnostic.h" + #endif + + SWIFT_BEGIN_NULLABILITY_ANNOTATIONS +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0005-specify-liblto-path.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0005-specify-liblto-path.patch new file mode 100644 index 000000000000..fab4599628c1 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0005-specify-liblto-path.patch @@ -0,0 +1,44 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sun, 4 Jan 2026 14:47:06 -0500 +Subject: [PATCH 05/10] specify-liblto-path + +--- + cmake/modules/UnixCompileRules.cmake | 2 +- + lib/Driver/DarwinToolChains.cpp | 7 ++----- + 2 files changed, 3 insertions(+), 6 deletions(-) + +diff --git a/cmake/modules/UnixCompileRules.cmake b/cmake/modules/UnixCompileRules.cmake +index 06a597b5ebb..e9086801408 100644 +--- a/cmake/modules/UnixCompileRules.cmake ++++ b/cmake/modules/UnixCompileRules.cmake +@@ -18,7 +18,7 @@ set(CMAKE_CXX_ARCHIVE_FINISH "") + # just-built bitcode format. So let's instead ask ar/ranlib/libtool to use the + # just-built libLTO.dylib from the toolchain that we're using to build. + if(APPLE AND SWIFT_NATIVE_CLANG_TOOLS_PATH) +- set(liblto_path "${SWIFT_NATIVE_CLANG_TOOLS_PATH}/../lib/libLTO.dylib") ++ set(liblto_path "@libllvm_path@/lib/libLTO.dylib") + + set(CMAKE_C_ARCHIVE_CREATE "${CMAKE_COMMAND} -E env LIBLTO_PATH=${liblto_path} crs ") + set(CMAKE_C_ARCHIVE_APPEND "${CMAKE_COMMAND} -E env LIBLTO_PATH=${liblto_path} qs ") +diff --git a/lib/Driver/DarwinToolChains.cpp b/lib/Driver/DarwinToolChains.cpp +index 7d4d7d61071..832c2dffde3 100644 +--- a/lib/Driver/DarwinToolChains.cpp ++++ b/lib/Driver/DarwinToolChains.cpp +@@ -270,11 +270,8 @@ void toolchains::Darwin::addLTOLibArgs(ArgStringList &Arguments, + Arguments.push_back("-lto_library"); + Arguments.push_back(context.Args.MakeArgString(context.OI.LibLTOPath)); + } else { +- // Check for relative libLTO.dylib. This would be the expected behavior in an +- // Xcode toolchain. +- StringRef P = llvm::sys::path::parent_path(getDriver().getSwiftProgramPath()); +- llvm::SmallString<128> LibLTOPath(P); +- llvm::sys::path::remove_filename(LibLTOPath); // Remove '/bin' ++ // Use the LTO dylib from the LLVM built for Swift. ++ llvm::SmallString<128> LibLTOPath("@libllvm_path@"); + llvm::sys::path::append(LibLTOPath, "lib"); + llvm::sys::path::append(LibLTOPath, "libLTO.dylib"); + if (llvm::sys::fs::exists(LibLTOPath)) { +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0006-use-nixpkgs-libdispatch.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0006-use-nixpkgs-libdispatch.patch new file mode 100644 index 000000000000..60712b733a5d --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0006-use-nixpkgs-libdispatch.patch @@ -0,0 +1,70 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Fri, 13 Feb 2026 20:51:47 -0500 +Subject: [PATCH 06/10] use-nixpkgs-libdispatch + +--- + CMakeLists.txt | 10 ++-------- + stdlib/cmake/modules/StdlibOptions.cmake | 3 --- + stdlib/public/Concurrency/CMakeLists.txt | 3 --- + 3 files changed, 2 insertions(+), 14 deletions(-) + +diff --git a/CMakeLists.txt b/CMakeLists.txt +index e4cbfb844e0..c6ea0234823 100644 +--- a/CMakeLists.txt ++++ b/CMakeLists.txt +@@ -853,12 +853,6 @@ if(SWIFT_ENABLE_DISPATCH AND NOT CMAKE_SYSTEM_NAME STREQUAL "Darwin") + if(SWIFT_INCLUDE_TOOLS AND SWIFT_BUILD_SOURCEKIT) + set(SWIFT_BUILD_HOST_DISPATCH TRUE) + endif() +- +- if(SWIFT_BUILD_HOST_DISPATCH) +- if(NOT EXISTS "${SWIFT_PATH_TO_LIBDISPATCH_SOURCE}") +- message(SEND_ERROR "SourceKit requires libdispatch on non-Darwin hosts. Please specify SWIFT_PATH_TO_LIBDISPATCH_SOURCE") +- endif() +- endif() + endif() + + file(STRINGS "utils/availability-macros.def" SWIFT_STDLIB_AVAILABILITY_DEFINITIONS) +@@ -1492,8 +1486,8 @@ if (LLVM_ENABLE_DOXYGEN) + message(STATUS "Doxygen: enabled") + endif() + +-if(SWIFT_ENABLE_DISPATCH) +- include(Libdispatch) ++if(SWIFT_ENABLE_DISPATCH AND NOT CMAKE_SYSTEM_NAME STREQUAL "Darwin") ++ find_package(dispatch) + endif() + + # Add all of the subdirectories, where we actually do work. +diff --git a/stdlib/cmake/modules/StdlibOptions.cmake b/stdlib/cmake/modules/StdlibOptions.cmake +index 24d1b836211..b3a105180ce 100644 +--- a/stdlib/cmake/modules/StdlibOptions.cmake ++++ b/stdlib/cmake/modules/StdlibOptions.cmake +@@ -221,9 +221,6 @@ if (SWIFT_ENABLE_EXPERIMENTAL_CONCURRENCY) + + if (SWIFT_ENABLE_DISPATCH) + set(SWIFT_CONCURRENCY_USES_DISPATCH TRUE) +- if (NOT CMAKE_SYSTEM_NAME STREQUAL "Darwin" AND NOT EXISTS "${SWIFT_PATH_TO_LIBDISPATCH_SOURCE}") +- message(SEND_ERROR "Concurrency requires libdispatch on non-Darwin hosts. Please specify SWIFT_PATH_TO_LIBDISPATCH_SOURCE") +- endif() + endif() + + if(SWIFT_CONCURRENCY_USES_DISPATCH) +diff --git a/stdlib/public/Concurrency/CMakeLists.txt b/stdlib/public/Concurrency/CMakeLists.txt +index d3a5011058c..fb037e40bbb 100644 +--- a/stdlib/public/Concurrency/CMakeLists.txt ++++ b/stdlib/public/Concurrency/CMakeLists.txt +@@ -25,9 +25,6 @@ set(swift_concurrency_incorporate_object_libraries_so swiftThreading) + + if("${SWIFT_CONCURRENCY_GLOBAL_EXECUTOR}" STREQUAL "dispatch") + if(NOT CMAKE_SYSTEM_NAME STREQUAL "Darwin") +- include_directories(AFTER +- ${SWIFT_PATH_TO_LIBDISPATCH_SOURCE}) +- + # FIXME: we can't rely on libdispatch having been built for the + # target at this point in the process. Currently, we're relying + # on soft-linking. +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0007-Help-Swift-JIT-find-the-separate-stdlib-and-framewor.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0007-Help-Swift-JIT-find-the-separate-stdlib-and-framewor.patch new file mode 100644 index 000000000000..afc2e5b470a4 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0007-Help-Swift-JIT-find-the-separate-stdlib-and-framewor.patch @@ -0,0 +1,49 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Wed, 15 Jul 2026 00:02:16 -0400 +Subject: [PATCH 07/10] Help Swift JIT find the separate stdlib and frameworks + +This is needed because the stdlib and several frameworks are all built +separately then symlinked into the final Swift toolchain. +--- + lib/Immediate/Immediate.cpp | 17 +++++++++++++++++ + 1 file changed, 17 insertions(+) + +diff --git a/lib/Immediate/Immediate.cpp b/lib/Immediate/Immediate.cpp +index 7d24b0d473e..bfd8ae3a129 100644 +--- a/lib/Immediate/Immediate.cpp ++++ b/lib/Immediate/Immediate.cpp +@@ -45,6 +45,8 @@ + #include "llvm/Support/Path.h" + #include "llvm/Transforms/IPO.h" + ++#include ++ + // TODO: Replace pass manager + // Removed in: d623b2f95fd559901f008a0588dddd0949a8db01 + /* #include "llvm/Transforms/IPO/PassManagerBuilder.h" */ +@@ -83,6 +85,21 @@ static void *loadRuntimeLib(StringRef sharedLibName, + for (auto &runtimeLibPath : runtimeLibPaths) { + if (void *handle = loadRuntimeLibAtPath(sharedLibName, runtimeLibPath)) + return handle; ++ else { ++ // Runtime libraries may also be located in `lib` for `lib/swift/`. ++ std::filesystem::path libPath = runtimeLibPath; ++ ++ if (libPath.filename() != "@swiftPlatform@") ++ continue; ++ libPath = libPath.parent_path(); ++ ++ if (libPath.filename() != "swift") ++ continue; ++ libPath = libPath.parent_path(); ++ ++ if (void *handle = loadRuntimeLibAtPath(sharedLibName, libPath.string())) ++ return handle; ++ } + } + return nullptr; + } +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0008-revert-optimizer-changes.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0008-revert-optimizer-changes.patch new file mode 100644 index 000000000000..07000cf9ec55 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0008-revert-optimizer-changes.patch @@ -0,0 +1,981 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sun, 4 Jan 2026 14:40:44 -0500 +Subject: [PATCH 08/10] revert-optimizer-changes + +We need to restore several optimizations that were removed to Swift +because otherwise the C++-only bootstrap driver will crash when building +Swift Compiler Driver and its dependencies for early-swift-driver. +--- + .../swift/SILOptimizer/PassManager/Passes.def | 2 + + .../swift/SILOptimizer/Utils/InstOptUtils.h | 5 + + .../Mandatory/PredictableMemOpt.cpp | 820 ++++++++++++++++++ + lib/SILOptimizer/PassManager/PassPipeline.cpp | 2 +- + 4 files changed, 828 insertions(+), 1 deletion(-) + +diff --git a/include/swift/SILOptimizer/PassManager/Passes.def b/include/swift/SILOptimizer/PassManager/Passes.def +index c9a500bbb66..b97790ba1f3 100644 +--- a/include/swift/SILOptimizer/PassManager/Passes.def ++++ b/include/swift/SILOptimizer/PassManager/Passes.def +@@ -381,6 +381,8 @@ LEGACY_PASS(PerformanceConstantPropagation, "performance-constant-propagation", + "Constant Propagation for Performance without Diagnostics") + LEGACY_PASS(PerformanceDiagnostics, "performance-diagnostics", + "Constant Propagation for Performance without Diagnostics") ++LEGACY_PASS(PredictableMemoryAccessOptimizations, "predictable-memaccess-opts", ++ "Predictable Memory Access Optimizations for Diagnostics") + LEGACY_PASS(PredictableDeadAllocationElimination, "predictable-deadalloc-elim", + "Eliminate dead temporary allocations after diagnostics") + LEGACY_PASS(RedundantPhiElimination, "redundant-phi-elimination", +diff --git a/include/swift/SILOptimizer/Utils/InstOptUtils.h b/include/swift/SILOptimizer/Utils/InstOptUtils.h +index d48e78938da..71805e93abf 100644 +--- a/include/swift/SILOptimizer/Utils/InstOptUtils.h ++++ b/include/swift/SILOptimizer/Utils/InstOptUtils.h +@@ -592,6 +592,11 @@ bool tryEliminateOnlyOwnershipUsedForwardingInst( + IntegerLiteralInst *optimizeBuiltinCanBeObjCClass(BuiltinInst *bi, + SILBuilder &builder); + ++/// Performs "predictable" memory access optimizations. ++/// ++/// See the PredictableMemoryAccessOptimizations pass. ++bool optimizeMemoryAccesses(SILFunction *fn); ++ + /// Performs "predictable" dead allocation optimizations. + /// + /// See the PredictableDeadAllocationElimination pass. +diff --git a/lib/SILOptimizer/Mandatory/PredictableMemOpt.cpp b/lib/SILOptimizer/Mandatory/PredictableMemOpt.cpp +index 20e0211c91b..8f57ce653c0 100644 +--- a/lib/SILOptimizer/Mandatory/PredictableMemOpt.cpp ++++ b/lib/SILOptimizer/Mandatory/PredictableMemOpt.cpp +@@ -41,6 +41,7 @@ using namespace swift; + static llvm::cl::opt EnableAggressiveExpansionBlocking( + "enable-aggressive-expansion-blocking", llvm::cl::init(false)); + ++STATISTIC(NumLoadPromoted, "Number of loads promoted"); + STATISTIC(NumLoadTakePromoted, "Number of load takes promoted"); + STATISTIC(NumDestroyAddrPromoted, "Number of destroy_addrs promoted"); + STATISTIC(NumAllocRemoved, "Number of allocations completely removed"); +@@ -496,6 +497,12 @@ struct AvailableValueDataflowFixup: AvailableValueFixup { + // Clears insertedInsts. + void verifyOwnership(DeadEndBlocks &deBlocks); + ++ // Fix ownership of inserted instructions and delete dead instructions. ++ // ++ // Clears insertedInsts. ++ void fixupOwnership(InstructionDeleter &deleter, ++ DeadEndBlocks &deBlocks); ++ + // Deletes all insertedInsts without fixing ownership. + // Clears insertedInsts. + void deleteInsertedInsts(InstructionDeleter &deleter); +@@ -542,6 +549,32 @@ void AvailableValueDataflowFixup::verifyOwnership(DeadEndBlocks &deBlocks) { + insertedInsts.clear(); + } + ++// In OptimizationMode::PreserveAlloc, delete any inserted instructions that are ++// still dead and fix ownership of any live inserted copies or casts ++// (mark_dependence). ++void AvailableValueDataflowFixup::fixupOwnership(InstructionDeleter &deleter, ++ DeadEndBlocks &deBlocks) { ++ for (auto *inst : insertedInsts) { ++ if (inst->isDeleted()) ++ continue; ++ ++ deleter.deleteIfDead(inst); ++ } ++ auto *function = const_cast(deBlocks.getFunction()); ++ OSSALifetimeCompletion completion(function, /*DomInfo*/ nullptr, deBlocks); ++ for (auto *inst : insertedInsts) { ++ if (inst->isDeleted()) ++ continue; ++ ++ // If any inserted instruction was not removed, complete its lifetime. ++ for (auto result : inst->getResults()) { ++ completion.completeOSSALifetime( ++ result, OSSALifetimeCompletion::Boundary::Liveness); ++ } ++ } ++ insertedInsts.clear(); ++} ++ + void AvailableValueDataflowFixup:: + deleteInsertedInsts(InstructionDeleter &deleter) { + for (auto *inst : insertedInsts) { +@@ -561,6 +594,11 @@ struct AvailableValueAggregationFixup: AvailableValueFixup { + /// The list of phi nodes inserted by the SSA updater. + SmallVector insertedPhiNodes; + ++ /// A set of copy_values whose lifetime we balanced while inserting phi ++ /// nodes. This means that these copy_value must be skipped in ++ /// addMissingDestroysForCopiedValues. ++ SmallPtrSet copyValueProcessedWithPhiNodes; ++ + AvailableValueAggregationFixup(DeadEndBlocks &deadEndBlocks) + : deadEndBlocks(deadEndBlocks) {} + +@@ -572,12 +610,29 @@ struct AvailableValueAggregationFixup: AvailableValueFixup { + SILInstruction *availableAtInst, + bool isFullyAvailable); + ++ /// Call this after mergeSingleValueCopies() or mergeAggregateCopies(). ++ void fixupOwnership(SILInstruction *load, SILValue newVal) { ++ addHandOffCopyDestroysForPhis(load, newVal); ++ ++ // TODO: use OwnershipLifetimeCompletion instead. ++ addMissingDestroysForCopiedValues(load, newVal); ++ ++ insertedInsts.clear(); ++ insertedPhiNodes.clear(); ++ copyValueProcessedWithPhiNodes.clear(); ++ } ++ + private: + /// As a result of us using the SSA updater, insert hand off copy/destroys at + /// each phi and make sure that intermediate phis do not leak by inserting + /// destroys along paths that go through the intermediate phi that do not also + /// go through the. + void addHandOffCopyDestroysForPhis(SILInstruction *load, SILValue newVal); ++ ++ /// If as a result of us copying values, we may have unconsumed destroys, find ++ /// the appropriate location and place the values there. Only used when ++ /// ownership is enabled. ++ void addMissingDestroysForCopiedValues(SILInstruction *load, SILValue newVal); + }; + + // For OptimizationMode::PreserveAlloc, insert copies at the available value's +@@ -663,6 +718,406 @@ SILValue AvailableValueAggregationFixup::mergeCopies( + .emitCopyValueOperation(availableAtInst->getLoc(), result); + } + ++ ++namespace { ++ ++class PhiNodeCopyCleanupInserter { ++ llvm::SmallMapVector incomingValues; ++ ++ /// Map from index -> (incomingValueIndex, copy). ++ /// ++ /// We are going to stable_sort this array using the indices of ++ /// incomingValueIndex. This will ensure that we always visit in ++ /// insertion order our incoming values (since the indices we are ++ /// sorting by are the count of incoming values we have seen so far ++ /// when we see the incoming value) and maintain the internal ++ /// insertion sort within our range as well. This ensures that we ++ /// visit our incoming values in visitation order and that within ++ /// their own values, also visit them in visitation order with ++ /// respect to each other. ++ SmallFrozenMultiMap copiesToCleanup; ++ ++ /// The lifetime frontier that we use to compute lifetime endpoints ++ /// when emitting cleanups. ++ ValueLifetimeAnalysis::Frontier lifetimeFrontier; ++ ++public: ++ PhiNodeCopyCleanupInserter() = default; ++ ++ void trackNewCleanup(SILValue incomingValue, CopyValueInst *copy) { ++ auto entry = std::make_pair(incomingValue, incomingValues.size()); ++ auto iter = incomingValues.insert(entry); ++ // If we did not succeed, then iter.first.second is the index of ++ // incoming value. Otherwise, it will be nextIndex. ++ copiesToCleanup.insert(iter.first->second, copy); ++ } ++ ++ void emit(DeadEndBlocks &deadEndBlocks) &&; ++}; ++ ++} // end anonymous namespace ++ ++static SILInstruction * ++getNonPhiBlockIncomingValueDef(SILValue incomingValue, ++ SingleValueInstruction *phiCopy) { ++ assert(isa(phiCopy)); ++ auto *phiBlock = phiCopy->getParent(); ++ if (phiBlock == incomingValue->getParentBlock()) { ++ return nullptr; ++ } ++ ++ if (auto *cvi = dyn_cast(incomingValue)) { ++ return cvi; ++ } ++ ++ assert(isa(incomingValue)); ++ ++ // Otherwise, our copy_value may not be post-dominated by our phi. To ++ // work around that, we need to insert destroys along the other ++ // paths. So set base to the first instruction in our argument's block, ++ // so we can insert destroys for our base. ++ return &*incomingValue->getParentBlock()->begin(); ++} ++ ++static bool ++terminatorHasAnyKnownPhis(TermInst *ti, ++ ArrayRef insertedPhiNodesSorted) { ++ for (auto succArgList : ti->getSuccessorBlockArgumentLists()) { ++ if (llvm::any_of(succArgList, [&](SILArgument *arg) { ++ return binary_search(insertedPhiNodesSorted, ++ cast(arg)); ++ })) { ++ return true; ++ } ++ } ++ ++ return false; ++} ++ ++void PhiNodeCopyCleanupInserter::emit(DeadEndBlocks &deadEndBlocks) && { ++ // READ THIS: We are being very careful here to avoid allowing for ++ // non-determinism to enter here. ++ // ++ // 1. First we create a list of indices of our phi node data. Then we use a ++ // stable sort those indices into the order in which our phi node cleanups ++ // would be in if we compared just using incomingValues. We use a stable ++ // sort here to ensure that within the same "cohort" of values, our order ++ // is insertion order. ++ // ++ // 2. We go through the list of phiNodeCleanupStates in insertion order. We ++ // also maintain a set of already visited base values. When we visit the ++ // first phiNodeCleanupState for a specific phi, we process the phi ++ // then. This ensures that we always process the phis in insertion order as ++ // well. ++ copiesToCleanup.setFrozen(); ++ ++ for (auto keyValue : copiesToCleanup.getRange()) { ++ unsigned incomingValueIndex = keyValue.first; ++ auto copies = keyValue.second; ++ ++ SILValue incomingValue = ++ std::next(incomingValues.begin(), incomingValueIndex)->first; ++ SingleValueInstruction *phiCopy = copies.front(); ++ auto *insertPt = getNonPhiBlockIncomingValueDef(incomingValue, phiCopy); ++ auto loc = RegularLocation::getAutoGeneratedLocation(); ++ ++ // Before we do anything, see if we have a single cleanup state. In such a ++ // case, we could have that we have a phi node as an incoming value and a ++ // copy_value in that same block. In such a case, we want to just insert the ++ // copy and continue. This means that ++ // cleanupState.getNonPhiBlockIncomingValueDef() should always return a ++ // non-null value in the code below. ++ if (copies.size() == 1 && isa(incomingValue) && !insertPt) { ++ SILBasicBlock *phiBlock = phiCopy->getParent(); ++ SILBuilderWithScope builder(phiBlock->getTerminator()); ++ builder.createDestroyValue(loc, incomingValue); ++ continue; ++ } ++ ++ // Otherwise, we know that we have for this incomingValue, multiple ++ // potential insert pts that we need to handle at the same time with our ++ // lifetime query. Lifetime extend our base over these copy_value uses. ++ assert(lifetimeFrontier.empty()); ++ auto *def = getNonPhiBlockIncomingValueDef(incomingValue, phiCopy); ++ assert(def && "Should never have a nullptr here since we handled all of " ++ "the single block cases earlier"); ++ ValueLifetimeAnalysis analysis(def, copies); ++ bool foundCriticalEdges = !analysis.computeFrontier( ++ lifetimeFrontier, ValueLifetimeAnalysis::DontModifyCFG, &deadEndBlocks); ++ (void)foundCriticalEdges; ++ assert(!foundCriticalEdges); ++ ++ while (!lifetimeFrontier.empty()) { ++ auto *insertPoint = lifetimeFrontier.pop_back_val(); ++ SILBuilderWithScope builder(insertPoint); ++ builder.createDestroyValue(loc, incomingValue); ++ } ++ } ++} ++ ++void AvailableValueAggregationFixup::addHandOffCopyDestroysForPhis( ++ SILInstruction *load, SILValue newVal) { ++ assert(isa(load) || isa(load)); ++ ++ if (insertedPhiNodes.empty()) ++ return; ++ ++ SmallVector leakingBlocks; ++ SmallVector, 8> incomingValues; ++ auto loc = RegularLocation::getAutoGeneratedLocation(); ++ ++#ifndef NDEBUG ++ LLVM_DEBUG(llvm::dbgs() << "Inserted Phis!\n"); ++ for (auto *phi : insertedPhiNodes) { ++ LLVM_DEBUG(llvm::dbgs() << "Phi: " << *phi); ++ } ++#endif ++ ++ // Before we begin, identify the offset for all phis that are intermediate ++ // phis inserted by the SSA updater. We are taking advantage of the fact that ++ // the SSA updater just constructs the web without knowledge of ownership. So ++ // if a phi node is only used by another phi node that we inserted, then we ++ // have an intermediate phi node. ++ // ++ // TODO: There should be a better way of doing this than doing a copy + sort. ++ SmallVector insertedPhiNodesSorted; ++ llvm::copy(insertedPhiNodes, std::back_inserter(insertedPhiNodesSorted)); ++ llvm::sort(insertedPhiNodesSorted); ++ ++ SmallBitVector intermediatePhiOffsets(insertedPhiNodes.size()); ++ for (unsigned i : indices(insertedPhiNodes)) { ++ if (TermInst *termInst = ++ insertedPhiNodes[i]->getSingleUserOfType()) { ++ // Only set the value if we find termInst has a successor with a phi node ++ // in our insertedPhiNodes. ++ if (terminatorHasAnyKnownPhis(termInst, insertedPhiNodesSorted)) { ++ intermediatePhiOffsets.set(i); ++ } ++ } ++ } ++ ++ // First go through all of our phi nodes doing the following: ++ // ++ // 1. If any of the phi node have a copy_value as an operand, we know that the ++ // copy_value does not dominate our final definition since otherwise the ++ // SSA updater would not have inserted a phi node here. In such a case ++ // since we may not have that the copy_value is post-dominated by the phi, ++ // we need to insert a copy_value at the phi to allow for post-domination ++ // and then use the ValueLifetimeChecker to determine the rest of the ++ // frontier for the base value. ++ // ++ // 2. If our phi node is used by another phi node, we run into a similar ++ // problem where we could have that our original phi node does not dominate ++ // our final definition (since the SSA updater would not have inserted the ++ // phi) and may not be strongly control dependent on our phi. To work ++ // around this problem, we insert at the phi a copy_value to allow for the ++ // phi to post_dominate its copy and then extend the lifetime of the phied ++ // value over that copy. ++ // ++ // As an extra complication to this, when we insert compensating releases for ++ // any copy_values from (1), we need to insert the destroy_value on "base ++ // values" (either a copy_value or the first instruction of a phi argument's ++ // block) /after/ we have found all of the base_values to ensure that if the ++ // same base value is used by multiple phis, we do not insert too many destroy ++ // value. ++ // ++ // NOTE: At first glance one may think that such a problem could not occur ++ // with phi nodes as well. Sadly if we allow for double backedge loops, it is ++ // possible (there may be more cases). ++ PhiNodeCopyCleanupInserter cleanupInserter; ++ ++ for (unsigned i : indices(insertedPhiNodes)) { ++ auto *phi = insertedPhiNodes[i]; ++ ++ // If our phi is not owned, continue. No fixes are needed. ++ if (phi->getOwnershipKind() != OwnershipKind::Owned) ++ continue; ++ ++ LLVM_DEBUG(llvm::dbgs() << "Visiting inserted phi: " << *phi); ++ // Otherwise, we have a copy_value that may not be strongly control ++ // equivalent with our phi node. In such a case, we need to use ++ // ValueLifetimeAnalysis to lifetime extend the copy such that we can ++ // produce a new copy_value at the phi. We insert destroys along the ++ // frontier. ++ leakingBlocks.clear(); ++ incomingValues.clear(); ++ ++ phi->getIncomingPhiValues(incomingValues); ++ unsigned phiIndex = phi->getIndex(); ++ for (auto pair : incomingValues) { ++ SILValue value = pair.second; ++ ++ // If we had a non-trivial type with non-owned ownership, we will not see ++ // a copy_value, so skip them here. ++ if (value->getOwnershipKind() != OwnershipKind::Owned) ++ continue; ++ ++ // Otherwise, value should be from a copy_value or a phi node. ++ assert(isa(value) || isa(value)); ++ ++ // If we have a copy_value, remove it from the inserted insts set so we ++ // skip it when we start processing insertedInstrs. ++ if (auto *cvi = dyn_cast(value)) { ++ copyValueProcessedWithPhiNodes.insert(cvi); ++ ++ // Then check if our termInst is in the same block as our copy_value. In ++ // such a case, we can just use the copy_value as our phi's value ++ // without needing to worry about any issues around control equivalence. ++ if (pair.first == cvi->getParent()) ++ continue; ++ } else { ++ assert(isa(value)); ++ } ++ ++ // Otherwise, insert a copy_value instruction right before the phi. We use ++ // that for our actual phi. ++ auto *termInst = pair.first->getTerminator(); ++ SILBuilderWithScope builder(termInst); ++ CopyValueInst *phiCopy = builder.createCopyValue(loc, value); ++ termInst->setOperand(phiIndex, phiCopy); ++ ++ // Now that we know our base, phi, phiCopy for this specific incoming ++ // value, append it to the phiNodeCleanupState so we can insert ++ // destroy_values late after we visit all insertedPhiNodes. ++ cleanupInserter.trackNewCleanup(value, phiCopy); ++ } ++ ++ // Then see if our phi is an intermediate phi. If it is an intermediate phi, ++ // we know that this is not the phi node that is post-dominated by the ++ // load_borrow and that we will lifetime extend it via the child ++ // phi. Instead, we need to just ensure that our phi arg does not leak onto ++ // its set of post-dominating paths, subtracting from that set the path ++ // through our terminator use. ++ if (intermediatePhiOffsets[i]) { ++ continue; ++ } ++ ++ // If we reach this point, then we know that we are a phi node that actually ++ // dominates our user so we need to lifetime extend it over the ++ // load_borrow. Thus insert copy_value along the incoming edges and then ++ // lifetime extend the phi node over the load_borrow. ++ // ++ // The linear lifetime checker doesn't care if the passed in load is ++ // actually a user of our copy_value. What we care about is that the load is ++ // guaranteed to be in the block where we have reformed the tuple in a ++ // consuming manner. This means if we add it as the consuming use of the ++ // copy, we can find the leaking places if any exist. ++ // ++ // Then perform the linear lifetime check. If we succeed, continue. We have ++ // no further work to do. ++ auto *loadOperand = &load->getAllOperands()[0]; ++ LinearLifetimeChecker checker(&deadEndBlocks); ++ bool consumedInLoop = checker.completeConsumingUseSet( ++ phi, loadOperand, [&](SILBasicBlock::iterator iter) { ++ SILBuilderWithScope builder(iter); ++ builder.emitDestroyValueOperation(loc, phi); ++ }); ++ ++ // Ok, we found some leaking blocks and potentially that our load is ++ // "consumed" inside a different loop in the loop nest from cvi. If we are ++ // consumed in the loop, then our visit should have inserted all of the ++ // necessary destroys for us by inserting the destroys on the loop ++ // boundaries. So, continue. ++ // ++ // NOTE: This includes cases where due to an infinite loop, we did not ++ // insert /any/ destroys since the loop has no boundary in a certain sense. ++ if (consumedInLoop) { ++ continue; ++ } ++ ++ // Otherwise, we need to insert one last destroy after the load for our phi. ++ auto next = std::next(load->getIterator()); ++ SILBuilderWithScope builder(next); ++ builder.emitDestroyValueOperation( ++ RegularLocation::getAutoGeneratedLocation(), phi); ++ } ++ ++ // Alright! In summary, we just lifetime extended all of our phis, ++ // lifetime extended them to the load block, and inserted phi copies ++ // at all of our intermediate phi nodes. Now we need to cleanup and ++ // insert all of the compensating destroy_value that we need. ++ std::move(cleanupInserter).emit(deadEndBlocks); ++ ++ // Clear the phi node array now that we are done. ++ insertedPhiNodes.clear(); ++} ++ ++// TODO: use standard lifetime completion ++void AvailableValueAggregationFixup::addMissingDestroysForCopiedValues( ++ SILInstruction *load, SILValue newVal) { ++ assert(load->getFunction()->hasOwnership() && ++ "We assume this is only called if we have ownership"); ++ ++ SmallVector leakingBlocks; ++ auto loc = RegularLocation::getAutoGeneratedLocation(); ++ ++ for (auto *inst : insertedInsts) { ++ // Otherwise, see if this is a load [copy]. It if it a load [copy], then we ++ // know that the load [copy] must be in the load block meaning we can just ++ // put a destroy_value /after/ the load_borrow to ensure that the value ++ // lives long enough for us to copy_value it or a derived value for the ++ // begin_borrow. ++ if (auto *li = dyn_cast(inst)) { ++ if (li->getOwnershipQualifier() == LoadOwnershipQualifier::Copy) { ++ assert(li->getParent() == load->getParent()); ++ auto next = std::next(load->getIterator()); ++ SILBuilderWithScope builder(next); ++ builder.emitDestroyValueOperation( ++ RegularLocation::getAutoGeneratedLocation(), li); ++ continue; ++ } ++ } ++ ++ // Our copy_value may have been unset above if it was used by a phi ++ // (implying it does not dominate our final user). ++ auto *cvi = dyn_cast(inst); ++ if (!cvi) ++ continue; ++ ++ // If we already handled this copy_value above when handling phi nodes, just ++ // continue. ++ if (copyValueProcessedWithPhiNodes.count(cvi)) ++ continue; ++ ++ // Clear our state. ++ leakingBlocks.clear(); ++ ++ // The linear lifetime checker doesn't care if the passed in load is ++ // actually a user of our copy_value. What we care about is that the load is ++ // guaranteed to be in the block where we have reformed the tuple in a ++ // consuming manner. This means if we add it as the consuming use of the ++ // copy, we can find the leaking places if any exist. ++ // ++ // Then perform the linear lifetime check. If we succeed, continue. We have ++ // no further work to do. ++ auto *loadOperand = &load->getAllOperands()[0]; ++ LinearLifetimeChecker checker(&deadEndBlocks); ++ bool consumedInLoop = checker.completeConsumingUseSet( ++ cvi, loadOperand, [&](SILBasicBlock::iterator iter) { ++ SILBuilderWithScope builder(iter); ++ builder.emitDestroyValueOperation(loc, cvi); ++ }); ++ ++ // Ok, we found some leaking blocks and potentially that our load is ++ // "consumed" inside a different loop in the loop nest from cvi. If we are ++ // consumed in the loop, then our visit should have inserted all of the ++ // necessary destroys for us by inserting the destroys on the loop ++ // boundaries. So, continue. ++ // ++ // NOTE: This includes cases where due to an infinite loop, we did not ++ // insert /any/ destroys since the loop has no boundary in a certain sense. ++ if (consumedInLoop) { ++ continue; ++ } ++ ++ // Otherwise, we need to insert one last destroy after the load for our phi. ++ auto next = std::next(load->getIterator()); ++ SILBuilderWithScope builder(next); ++ builder.emitDestroyValueOperation( ++ RegularLocation::getAutoGeneratedLocation(), cvi); ++ } ++} ++ + //===----------------------------------------------------------------------===// + // Available Value Aggregation + //===----------------------------------------------------------------------===// +@@ -735,6 +1190,15 @@ public: + return expectedOwnership == AvailableValueExpectedOwnership::Copy; + } + ++ /// Given a load_borrow that we have aggregated a new value for, fixup the ++ /// reference counts of the intermediate copies and phis to ensure that all ++ /// forwarding operations in the CFG are strongly control equivalent (i.e. run ++ /// the same number of times). ++ void fixupOwnership(SILInstruction *load, SILValue newVal) { ++ assert(isa(load) || isa(load)); ++ ownershipFixup.fixupOwnership(load, newVal); ++ } ++ + private: + SILValue aggregateFullyAvailableValue(SILType loadTy, unsigned firstElt); + SILValue aggregateTupleSubElts(TupleType *tt, SILType loadTy, +@@ -1071,6 +1535,11 @@ public: + ownershipFixup.verifyOwnership(deBlocks); + } + ++ void fixupOwnership(InstructionDeleter &deleter, ++ DeadEndBlocks &deBlocks) { ++ ownershipFixup.fixupOwnership(deleter, deBlocks); ++ } ++ + void deleteInsertedInsts(InstructionDeleter &deleter) { + ownershipFixup.deleteInsertedInsts(deleter); + } +@@ -1788,6 +2257,10 @@ bool AvailableValueDataflowContext::hasEscapedAt(SILInstruction *I) { + return HasAnyEscape; + } + ++//===----------------------------------------------------------------------===// ++// Optimize loads ++//===----------------------------------------------------------------------===// ++ + static SILType getMemoryType(AllocationInst *memory) { + // Compute the type of the memory object. + if (auto *abi = dyn_cast(memory)) { +@@ -1801,6 +2274,286 @@ static SILType getMemoryType(AllocationInst *memory) { + return cast(memory)->getElementType(); + } + ++namespace { ++ ++/// This performs load promotion and deletes synthesized allocations if all ++/// loads can be removed. ++class OptimizeAllocLoads { ++ ++ SILModule &Module; ++ ++ /// This is either an alloc_box or alloc_stack instruction. ++ AllocationInst *TheMemory; ++ ++ /// This is the SILType of the memory object. ++ SILType MemoryType; ++ ++ /// The number of primitive subelements across all elements of this memory ++ /// value. ++ unsigned NumMemorySubElements; ++ ++ SmallVectorImpl &Uses; ++ ++ InstructionDeleter &deleter; ++ ++ DeadEndBlocks &deadEndBlocks; ++ ++ /// A structure that we use to compute our available values. ++ AvailableValueDataflowContext DataflowContext; ++ ++public: ++ OptimizeAllocLoads(AllocationInst *memory, ++ SmallVectorImpl &uses, ++ DeadEndBlocks &deadEndBlocks, ++ InstructionDeleter &deleter) ++ : Module(memory->getModule()), TheMemory(memory), ++ MemoryType(getMemoryType(memory)), ++ NumMemorySubElements(getNumSubElements( ++ MemoryType, *memory->getFunction(), ++ TypeExpansionContext(*memory->getFunction()))), ++ Uses(uses), deleter(deleter), deadEndBlocks(deadEndBlocks), ++ DataflowContext(TheMemory, NumMemorySubElements, ++ OptimizationMode::PreserveAlloc, uses, ++ deleter, deadEndBlocks) {} ++ ++ bool optimize(); ++ ++private: ++ bool optimizeLoadUse(SILInstruction *inst); ++ bool promoteLoadCopy(LoadInst *li); ++ bool promoteLoadBorrow(LoadBorrowInst *lbi); ++ bool promoteCopyAddr(CopyAddrInst *cai); ++}; ++ ++} // end anonymous namespace ++ ++/// If we are able to optimize \p Inst, return the source address that ++/// instruction is loading from. If we can not optimize \p Inst, then just ++/// return an empty SILValue. ++static SILValue tryFindSrcAddrForLoad(SILInstruction *i) { ++ // We can always promote a load_borrow. ++ if (auto *lbi = dyn_cast(i)) ++ return lbi->getOperand(); ++ ++ // We only handle load [copy], load [trivial], load and copy_addr right ++ // now. Notably we do not support load [take] when promoting loads. ++ if (auto *li = dyn_cast(i)) ++ if (li->getOwnershipQualifier() != LoadOwnershipQualifier::Take) ++ return li->getOperand(); ++ ++ // If this is a CopyAddr, verify that the element type is loadable. If not, ++ // we can't explode to a load. ++ auto *cai = dyn_cast(i); ++ if (!cai || !cai->getSrc()->getType().isLoadable(*cai->getFunction())) ++ return SILValue(); ++ return cai->getSrc(); ++} ++ ++/// At this point, we know that this element satisfies the definitive init ++/// requirements, so we can try to promote loads to enable SSA-based dataflow ++/// analysis. We know that accesses to this element only access this element, ++/// cross element accesses have been scalarized. ++/// ++/// This returns true if the load has been removed from the program. ++bool OptimizeAllocLoads::promoteLoadCopy(LoadInst *li) { ++ // Note that we intentionally don't support forwarding of weak pointers, ++ // because the underlying value may drop be deallocated at any time. We would ++ // have to prove that something in this function is holding the weak value ++ // live across the promoted region and that isn't desired for a stable ++ // diagnostics pass this like one. ++ ++ // First attempt to find a source addr for our "load" instruction. If we fail ++ // to find a valid value, just return. ++ SILValue srcAddr = tryFindSrcAddrForLoad(li); ++ if (!srcAddr) ++ return false; ++ ++ SmallVector availableValues; ++ auto loadInfo = DataflowContext.computeAvailableValues(srcAddr, li, availableValues); ++ if (!loadInfo.has_value()) ++ return false; ++ ++ // Aggregate together all of the subelements into something that has the same ++ // type as the load did, and emit smaller loads for any subelements that were ++ // not available. We are "propagating" a +1 available value from the store ++ // points. ++ AvailableValueAggregator agg(li, availableValues, Uses, deadEndBlocks, ++ AvailableValueExpectedOwnership::Copy); ++ SILValue newVal = agg.aggregateValues(loadInfo->loadType, li->getOperand(), ++ loadInfo->firstElt); ++ ++ LLVM_DEBUG(llvm::dbgs() << " *** Promoting load: " << *li); ++ LLVM_DEBUG(llvm::dbgs() << " To value: " << *newVal); ++ ++NumLoadPromoted; ++ ++ // If we inserted any copies, we created the copies at our stores. We know ++ // that in our load block, we will reform the aggregate as appropriate at the ++ // load implying that the value /must/ be fully consumed. If we promoted a +0 ++ // value, we created dominating destroys along those paths. Thus any leaking ++ // blocks that we may have can be found by performing a linear lifetime check ++ // over all copies that we found using the load as the "consuming uses" (just ++ // for the purposes of identifying the consuming block). ++ agg.fixupOwnership(li, newVal); ++ ++ // Now that we have fixed up all of our missing destroys, insert the copy ++ // value for our actual load, in case the load was in an inner loop, and RAUW. ++ newVal = SILBuilderWithScope(li).emitCopyValueOperation(li->getLoc(), newVal); ++ ++ li->replaceAllUsesWith(newVal); ++ ++ SILValue addr = li->getOperand(); ++ deleter.forceDelete(li); ++ if (auto *addrI = addr->getDefiningInstruction()) ++ deleter.deleteIfDead(addrI); ++ return true; ++} ++ ++bool OptimizeAllocLoads::promoteCopyAddr(CopyAddrInst *cai) { ++ // Note that we intentionally don't support forwarding of weak pointers, ++ // because the underlying value may drop be deallocated at any time. We would ++ // have to prove that something in this function is holding the weak value ++ // live across the promoted region and that isn't desired for a stable ++ // diagnostics pass this like one. ++ ++ // First attempt to find a source addr for our "load" instruction. If we fail ++ // to find a valid value, just return. ++ SILValue srcAddr = tryFindSrcAddrForLoad(cai); ++ if (!srcAddr) ++ return false; ++ ++ SmallVector availableValues; ++ auto result = DataflowContext.computeAvailableValues(srcAddr, cai, ++ availableValues); ++ if (!result.has_value()) ++ return false; ++ ++ // Ok, we have some available values. If we have a copy_addr, explode it now, ++ // exposing the load operation within it. Subsequent optimization passes will ++ // see the load and propagate the available values into it. ++ DataflowContext.explodeCopyAddr(cai); ++ ++ // This is removing the copy_addr, but explodeCopyAddr takes care of ++ // removing the instruction from Uses for us, so we return false. ++ return false; ++} ++ ++/// At this point, we know that this element satisfies the definitive init ++/// requirements, so we can try to promote loads to enable SSA-based dataflow ++/// analysis. We know that accesses to this element only access this element, ++/// cross element accesses have been scalarized. ++/// ++/// This returns true if the load has been removed from the program. ++bool OptimizeAllocLoads::promoteLoadBorrow(LoadBorrowInst *lbi) { ++ // Note that we intentionally don't support forwarding of weak pointers, ++ // because the underlying value may drop be deallocated at any time. We would ++ // have to prove that something in this function is holding the weak value ++ // live across the promoted region and that isn't desired for a stable ++ // diagnostics pass this like one. ++ ++ // First attempt to find a source addr for our "load" instruction. If we fail ++ // to find a valid value, just return. ++ SILValue srcAddr = tryFindSrcAddrForLoad(lbi); ++ if (!srcAddr) ++ return false; ++ ++ SmallVector availableValues; ++ auto loadInfo = DataflowContext.computeAvailableValues(srcAddr, lbi, ++ availableValues); ++ if (!loadInfo.has_value()) ++ return false; ++ ++ // Bail if the load_borrow has reborrows. In this case it's not so easy to ++ // find the insertion points for the destroys. ++ if (!lbi->getUsersOfType().empty()) { ++ return false; ++ } ++ ++ ++NumLoadPromoted; ++ ++ // Aggregate together all of the subelements into something that has the same ++ // type as the load did, and emit smaller loads for any subelements that were ++ // not available. We are "propagating" a +1 available value from the store ++ // points. ++ AvailableValueAggregator agg(lbi, availableValues, Uses, deadEndBlocks, ++ AvailableValueExpectedOwnership::Borrow); ++ SILValue newVal = agg.aggregateValues(loadInfo->loadType, lbi->getOperand(), ++ loadInfo->firstElt); ++ ++ LLVM_DEBUG(llvm::dbgs() << " *** Promoting load: " << *lbi); ++ LLVM_DEBUG(llvm::dbgs() << " To value: " << *newVal); ++ ++ // If we inserted any copies, we created the copies at our ++ // stores. We know that in our load block, we will reform the ++ // aggregate as appropriate, will borrow the value there and give us ++ // a whole pristine new value. Now in this routine, we go through ++ // all of the copies and phis that we inserted and ensure that: ++ // ++ // 1. Phis are always strongly control equivalent to the copies that ++ // produced their incoming values. ++ // ++ // 2. All intermediate copies are properly lifetime extended to the ++ // load block and all leaking blocks are filled in as appropriate ++ // with destroy_values. ++ agg.fixupOwnership(lbi, newVal); ++ ++ // Now that we have fixed up the lifetimes of all of our incoming copies so ++ // that they are alive over the load point, copy, borrow newVal and insert ++ // destroy_value after the end_borrow and then RAUW. ++ SILBuilderWithScope builder(lbi); ++ SILValue copiedVal = builder.emitCopyValueOperation(lbi->getLoc(), newVal); ++ newVal = builder.createBeginBorrow(lbi->getLoc(), copiedVal); ++ ++ for (auto *ebi : lbi->getUsersOfType()) { ++ auto next = std::next(ebi->getIterator()); ++ SILBuilderWithScope(next).emitDestroyValueOperation(ebi->getLoc(), ++ copiedVal); ++ } ++ ++ lbi->replaceAllUsesWith(newVal); ++ ++ SILValue addr = lbi->getOperand(); ++ deleter.forceDelete(lbi); ++ if (auto *addrI = addr->getDefiningInstruction()) ++ deleter.deleteIfDead(addrI); ++ return true; ++} ++ ++bool OptimizeAllocLoads::optimize() { ++ bool changed = false; ++ ++ // If we've successfully checked all of the definitive initialization ++ // requirements, try to promote loads. This can explode copy_addrs, so the ++ // use list may change size. ++ for (unsigned i = 0; i != Uses.size(); ++i) { ++ auto &use = Uses[i]; ++ // Ignore entries for instructions that got expanded along the way. ++ if (use.Inst && use.Kind == PMOUseKind::Load) { ++ if (optimizeLoadUse(use.Inst)) { ++ changed = true; ++ Uses[i].Inst = nullptr; // remove entry if load got deleted. ++ } ++ } ++ } ++ return changed; ++} ++ ++bool OptimizeAllocLoads::optimizeLoadUse(SILInstruction *inst) { ++ // After replacing load uses with promoted values, fixup ownership for copies ++ // or casts inserted during dataflow. ++ SWIFT_DEFER { DataflowContext.fixupOwnership(deleter, deadEndBlocks); }; ++ ++ if (auto *cai = dyn_cast(inst)) ++ return promoteCopyAddr(cai); ++ ++ if (auto *lbi = dyn_cast(inst)) ++ return promoteLoadBorrow(lbi); ++ ++ if (auto *li = dyn_cast(inst)) ++ return promoteLoadCopy(li); ++ ++ return false; ++} ++ + //===----------------------------------------------------------------------===// + // Optimize dead allocation: + // Fully promote each access +@@ -2453,6 +3206,49 @@ static AllocationInst *getOptimizableAllocation(SILInstruction *i) { + return alloc; + } + ++bool swift::optimizeMemoryAccesses(SILFunction *fn) { ++ if (!fn->hasOwnership()) { ++ return false; ++ } ++ ++ bool changed = false; ++ DeadEndBlocks deadEndBlocks(fn); ++ InstructionDeleter deleter; ++ for (auto &bb : *fn) { ++ for (SILInstruction &inst : bb.deletableInstructions()) { ++ // First see if i is an allocation that we can optimize. If not, skip it. ++ AllocationInst *alloc = getOptimizableAllocation(&inst); ++ if (!alloc) { ++ continue; ++ } ++ ++ LLVM_DEBUG(llvm::dbgs() ++ << "*** PMO Optimize Memory Accesses looking at: " << *alloc); ++ PMOMemoryObjectInfo memInfo(alloc); ++ ++ // Set up the datastructure used to collect the uses of the allocation. ++ SmallVector uses; ++ ++ // Walk the use list of the pointer, collecting them. If we are not able ++ // to optimize, skip this value. *NOTE* We may still scalarize values ++ // inside the value. ++ if (!collectPMOElementUsesFrom(memInfo, uses)) { ++ // Avoid advancing this iterator until after collectPMOElementUsesFrom() ++ // runs. It creates and deletes instructions other than alloc. ++ continue; ++ } ++ OptimizeAllocLoads optimizeAllocLoads(alloc, uses, deadEndBlocks, ++ deleter); ++ changed |= optimizeAllocLoads.optimize(); ++ ++ // Move onto the next instruction. We know this is safe since we do not ++ // eliminate allocations here. ++ } ++ } ++ ++ return changed; ++} ++ + bool swift::eliminateDeadAllocations(SILFunction *fn, DominanceInfo *domInfo) { + if (!fn->hasOwnership()) { + return false; +@@ -2498,6 +3294,26 @@ bool swift::eliminateDeadAllocations(SILFunction *fn, DominanceInfo *domInfo) { + + namespace { + ++class PredictableMemoryAccessOptimizations : public SILFunctionTransform { ++ /// The entry point to the transformation. ++ /// ++ /// FIXME: This pass should not need to rerun on deserialized ++ /// functions. Nothing should have changed in the upstream pipeline after ++ /// deserialization. However, rerunning does improve some benchmarks. This ++ /// either indicates that this pass missing some opportunities the first time, ++ /// or has a pass order dependency on other early passes. ++ void run() override { ++ auto *func = getFunction(); ++ if (!func->hasOwnership()) ++ return; ++ ++ LLVM_DEBUG(llvm::dbgs() << "Looking at: " << func->getName() << "\n"); ++ // TODO: Can we invalidate here just instructions? ++ if (optimizeMemoryAccesses(func)) ++ invalidateAnalysis(SILAnalysis::InvalidationKind::FunctionBody); ++ } ++}; ++ + class PredictableDeadAllocationElimination : public SILFunctionTransform { + void run() override { + auto *func = getFunction(); +@@ -2516,6 +3332,10 @@ class PredictableDeadAllocationElimination : public SILFunctionTransform { + + } // end anonymous namespace + ++SILTransform *swift::createPredictableMemoryAccessOptimizations() { ++ return new PredictableMemoryAccessOptimizations(); ++} ++ + SILTransform *swift::createPredictableDeadAllocationElimination() { + return new PredictableDeadAllocationElimination(); + } +diff --git a/lib/SILOptimizer/PassManager/PassPipeline.cpp b/lib/SILOptimizer/PassManager/PassPipeline.cpp +index 92a084c2df5..620718451e7 100644 +--- a/lib/SILOptimizer/PassManager/PassPipeline.cpp ++++ b/lib/SILOptimizer/PassManager/PassPipeline.cpp +@@ -206,7 +206,7 @@ static void addMandatoryDiagnosticOptPipeline(SILPassPipelinePlan &P) { + + // Promote loads as necessary to ensure we have enough SSA formation to emit + // SSA based diagnostics. +- P.addMandatoryRedundantLoadElimination(); ++ P.addPredictableMemoryAccessOptimizations(); + + // This phase performs optimizations necessary for correct interoperation of + // Swift os log APIs with C os_log ABIs. +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0009-siloptimizer-bootstrap-workaround.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0009-siloptimizer-bootstrap-workaround.patch new file mode 100644 index 000000000000..3b7f4705ff24 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0009-siloptimizer-bootstrap-workaround.patch @@ -0,0 +1,34 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sun, 4 Jan 2026 14:44:49 -0500 +Subject: [PATCH 09/10] siloptimizer-bootstrap-workaround +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Restore the SimplifyCFG optimization when bootstrapping. Even though +it’s buggy, it’s needed to build later stages of the bootstrap. +--- + lib/SILOptimizer/Transforms/SimplifyCFG.cpp | 6 ------ + 1 file changed, 6 deletions(-) + +diff --git a/lib/SILOptimizer/Transforms/SimplifyCFG.cpp b/lib/SILOptimizer/Transforms/SimplifyCFG.cpp +index f4781b4ca5c..ef99a41d864 100644 +--- a/lib/SILOptimizer/Transforms/SimplifyCFG.cpp ++++ b/lib/SILOptimizer/Transforms/SimplifyCFG.cpp +@@ -3322,12 +3322,6 @@ static bool splitBBArguments(SILFunction &Fn) { + } + + bool SimplifyCFG::run() { +-#ifndef SWIFT_ENABLE_SWIFT_IN_SWIFT +- // This pass results in verification failures when Swift sources are not +- // enabled. +- LLVM_DEBUG(llvm::dbgs() << "SimplifyCFG disabled in C++-only Swift compiler\n"); +- return false; +-#endif //!SWIFT_ENABLE_SWIFT_IN_SWIFT + LLVM_DEBUG(llvm::dbgs() << "### Run SimplifyCFG on " << Fn.getName() << '\n'); + + // Disable some expensive optimizations if the function is huge. +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/sources-6.2.json b/pkgs/development/compilers/swift_ng/sources-6.2.json index 46e9a46b54d8..1f9d1d5bca63 100644 --- a/pkgs/development/compilers/swift_ng/sources-6.2.json +++ b/pkgs/development/compilers/swift_ng/sources-6.2.json @@ -2,6 +2,9 @@ "llvm-project": { "hash": "sha256-5Nb8rQmk6onrc4wKW/kT38FsYsWTqMBWtsHYZLA/0Po=" }, + "swift": { + "hash": "sha256-apbBe/TMzq0+1XLkaTOj5NaYzLQ81i+vU+O7VSEJrKo=" + }, "swift-corelibs-libdispatch": { "hash": "sha256-Tu2G9FAP4q1xgM1n9q17T6VrqJ3tv8RezyUex38yNds=" } diff --git a/pkgs/top-level/swift-packages.nix b/pkgs/top-level/swift-packages.nix index f6d3cbd235d8..f719950fd84f 100644 --- a/pkgs/top-level/swift-packages.nix +++ b/pkgs/top-level/swift-packages.nix @@ -13,6 +13,7 @@ in llvmPackages, makeScopeWithSplicing', stdenvNoCC, + swiftPackages_ng, otherSplices ? generateSplicesForMkScope "swiftPackages_ng", }: @@ -32,6 +33,10 @@ makeScopeWithSplicing' { }; in { + bootstrapStage = 0; + + buildSwiftPackages = swiftPackages_ng.overrideScope (_: _: { swift = null; }); + inherit llvm_libtool; llvmPackages_upstream = llvmPackages; From cbda3182f1603e4b5422d8aefab154a4d85a73ac Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 186/423] swiftPackages_ng.swift: init MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The Swift compiler expects to find the stdlib, its modules, etc relative to its location. Building everything together in one derivation would be a terrible idea because it would take a very long time to build and require rebuilding things unnecessarily during the bootstrap. Fortunately, we can symlink most of what Swift expects together. Collectively, the contents of this package is called a toolchain. One should think of it as similar to the toolchains offered on swift.org except that it’s bootstrapped from source and is part of Nixpkgs. --- .../swift_ng/by-name/sw/swift/package.nix | 133 ++++++++++++++++++ 1 file changed, 133 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix new file mode 100644 index 000000000000..22c6a496eae9 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix @@ -0,0 +1,133 @@ +{ + lib, + apple-sdk_14, + llvmPackages_upstream, + stdenv, + swift-corelibs-libdispatch, + swiftc, + symlinkJoin, + swift_release, +}: + +let + propagated-sdk = apple-sdk_14; + + # `out` and `dev` are merged because that’s what Swift expects. + outLinks = symlinkJoin { + name = "swift" + lib.removePrefix "swiftc" (lib.getName swiftc) + "-${swift_release}-out"; + paths = [ + swiftc.out + swiftc.dev + ] + ++ lib.optionals (!stdenv.hostPlatform.isDarwin) ( + lib.optionals (swift-corelibs-libdispatch != null) [ + swift-corelibs-libdispatch.out + swift-corelibs-libdispatch.dev + ] + ); + }; + + docLinks = symlinkJoin { + name = "swift" + lib.removePrefix "swiftc" (lib.getName swiftc) + "-${swift_release}-doc"; + paths = [ + swiftc.doc + ]; + }; + + manLinks = symlinkJoin { + name = "swift" + lib.removePrefix "swiftc" (lib.getName swiftc) + "-${swift_release}-man"; + paths = [ + swiftc.man + ] + ++ lib.optionals (!stdenv.hostPlatform.isDarwin && swift-corelibs-libdispatch != null) [ + swift-corelibs-libdispatch.man + ]; + }; +in +stdenv.mkDerivation (finalAttrs: { + pname = "swift" + lib.removePrefix "swiftc" (lib.getName swiftc); + version = swift_release; + + outputs = [ + "out" + "doc" + "man" + ]; + + strictDeps = true; + + # Will effectively be `buildInputs` when swift is put in `nativeBuildInputs`. + depsTargetTargetPropagated = + lib.optionals stdenv.targetPlatform.isDarwin [ propagated-sdk ] + ++ lib.optionals (!stdenv.hostPlatform.isDarwin) ( + lib.optionals (swift-corelibs-libdispatch != null) [ + swift-corelibs-libdispatch.out + ] + ); + + buildCommand = '' + mkdir -p "$out" "$doc" "$man" + + cp -r ${lib.escapeShellArg outLinks}/* "$out" + cp -r ${lib.escapeShellArg docLinks}/* "$doc" + cp -r ${lib.escapeShellArg manLinks}/* "$man" + + # Make writable temporarily to allow for the fixups below to be made to the outputs. + chmod -R u+w "$out/bin" "$out/lib" "$out/nix-support" + + # Swift expects to find Clang next to it. + ln -s ${lib.escapeShellArg (lib.getExe' llvmPackages_upstream.clang "clang")} "$out/bin/clang" + ln -s ${lib.escapeShellArg (lib.getExe' llvmPackages_upstream.clang "clang++")} "$out/bin/clang++" + + # Swift has a separate resource root from Clang, but locates the Clang resource root via subdir or symlink. + # + # NOTE: We don’t symlink directly here, because that’d add a run-time dep on the full Clang compiler to every + # Swift executable. We instead symlink compiler-rt and copy the headers from Clang to keep the closure size down. + mkdir -p "$out/lib/swift/clang" + ln -s ${lib.escapeShellArg (lib.getBin llvmPackages.compiler-rt)}/{lib,share} "$out/lib/swift/clang/" + cp -rH ${lib.escapeShellArg (lib.getBin llvmPackages.clang)}/resource-root/include/ "$out/lib/swift/clang/" + + # `swift-frontend` expects to find everything relative to its location after resolving symlinks. + # Also copy `swift-driver` assuming it does similar. + for exe in swift-driver swift-frontend; do + if [ -e "$out/bin/$exe" ]; then + orig=$(readlink "$out/bin/$exe") + rm "$out/bin/$exe" + cp "$orig" "$out/bin/$exe" + fi + done + + # Propagated inputs in `$dev/nix-support` have to be substituted to use this derivation instead of swiftc. + for f in "$out/nix-support/"*; do + orig=$(readlink "$f") + rm "$f" + substitute "$orig" "$f" \ + --replace-quiet ${lib.escapeShellArg swiftc.out} "$out" + done + + # Don’t propagate CMake files for toolchain dependencies. These are an implementation detail of the package set. + rm -rf "$out/lib/cmake" + + recordPropagatedDependencies + + chmod -R u-w "$out/bin" "$out/lib" "$out/nix-support" + + # Have to invoke manually because of `buildCommand`. + noBrokenSymlinksInAllOutputs + ''; + + __structuredAttrs = true; + + passthru = { + inherit swiftc; + }; + + meta = { + mainProgram = "swift"; + description = "Swift Programming Language"; + homepage = "https://github.com/swiftlang/swift"; + inherit (swiftc.meta) platforms badPlatforms; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) From e04335ea4a157badf12b9dfa940b591f0110a981 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 187/423] swiftPackages_ng.swift-syntax: init at 6.2.4 --- .../files/SwiftSyntaxConfig.cmake | 24 +++++ .../by-name/sw/swift-syntax/package.nix | 93 +++++++++++++++++++ .../patches/0001-gnu-install-dirs.patch | 36 +++++++ .../compilers/swift_ng/sources-6.2.json | 3 + 4 files changed, 156 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-syntax/files/SwiftSyntaxConfig.cmake create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-syntax/package.nix create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-syntax/patches/0001-gnu-install-dirs.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-syntax/files/SwiftSyntaxConfig.cmake b/pkgs/development/compilers/swift_ng/by-name/sw/swift-syntax/files/SwiftSyntaxConfig.cmake new file mode 100644 index 000000000000..e388c685d3fe --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-syntax/files/SwiftSyntaxConfig.cmake @@ -0,0 +1,24 @@ +set(SyntaxModules + SwiftBasicFormat + SwiftCompilerPlugin + SwiftCompilerPluginMessageHandling + SwiftDiagnostics + SwiftIDEUtils + SwiftIfConfig + SwiftLexicalLookup + SwiftOperators + SwiftParser + SwiftParserDiagnostics + SwiftSyntax + SwiftSyntaxBuilder + SwiftSyntaxMacroExpansion + SwiftSyntaxMacros +) + +foreach(SyntaxModule ${SyntaxModules}) + add_library(SwiftSyntax::${SyntaxModule} @buildType@ IMPORTED) + set_target_properties(SwiftSyntax::${SyntaxModule} PROPERTIES + IMPORTED_LOCATION "@lib@/lib/swift/host/${CMAKE_@buildType@_LIBRARY_PREFIX}${SyntaxModule}${CMAKE_@buildType@_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@dev@/lib/swift/host" + ) +endforeach() diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-syntax/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift-syntax/package.nix new file mode 100644 index 000000000000..374874b08c7e --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-syntax/package.nix @@ -0,0 +1,93 @@ +{ + lib, + cmake, + fetchFromGitHub, + ninja, + stdenv, + swift, + swift_release, + swift_sources, + # Using toolchain libraries is intended for building macro library plugins included in the Swift toolchain. + # Everything else should use a non-toolchain build of Swift Syntax. + useToolchainLibraries ? true, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "swift-syntax"; + version = swift_release; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-syntax"; + tag = "swift-${finalAttrs.version}-RELEASE"; + inherit (swift_sources.swift-syntax) hash; + }; + + outputs = [ "out" ] ++ lib.optionals (!useToolchainLibraries) [ "dev" ]; + + patches = [ ./patches/0001-gnu-install-dirs.patch ]; + + strictDeps = true; + + cmakeFlags = lib.optionals (!useToolchainLibraries) [ + # Defaults to not building shared libs. + (lib.cmakeBool "BUILD_SHARED_LIBS" (!stdenv.hostPlatform.isStatic)) + # Build and install the modules. + (lib.cmakeBool "SWIFTSYNTAX_EMIT_MODULE" true) + ]; + + nativeBuildInputs = lib.optionals (!useToolchainLibraries) [ + cmake + ninja + swift + ]; + + dontConfigure = useToolchainLibraries; + + preConfigure = '' + appendToVar cmakeFlags -DCMAKE_Swift_COMPILER_TARGET=${stdenv.hostPlatform.swift.triple} + appendToVar cmakeFlags -DCMAKE_Swift_FLAGS=-module-cache-path\ "$NIX_BUILD_TOP/module-cache" + ''; + + dontBuild = useToolchainLibraries; + + postBuild = '' + # For some reason, this library doesn’t get built even though the install phase expects it to have been. + ninja -j''${NIX_BUILD_CORES:-1} libSwiftCompilerPlugin${stdenv.hostPlatform.extensions.library} + ''; + + postInstall = + # Different paths are needed depending on whether we’re providing CMake config for the Swift compiler’s build + # or for the stand-alone Swift Syntax build. + if useToolchainLibraries then + '' + # Install CMake config file for Swift Syntax in the toolchain. This is needed to build toolchain macros separately + # from the compiler. + mkdir -p "''${!outputDev}/lib/cmake/SwiftSyntax" + substitute ${./files/SwiftSyntaxConfig.cmake} "''${!outputDev}/lib/cmake/SwiftSyntax/SwiftSyntaxConfig.cmake" \ + --replace-fail '@buildType@' ${if stdenv.hostPlatform.isStatic then "STATIC" else "SHARED"} \ + --replace-fail '@dev@' ${lib.escapeShellArg swift.swiftc.out} \ + --replace-fail '@lib@' ${lib.escapeShellArg swift.swiftc.out} + '' + else + '' + moveToOutput lib/swift/host "''${!outputDev}" + + # Install CMake config file for Swift Syntax. + mkdir -p "''${!outputDev}/lib/cmake/SwiftSyntax" + substitute ${./files/SwiftSyntaxConfig.cmake} "''${!outputDev}/lib/cmake/SwiftSyntax/SwiftSyntaxConfig.cmake" \ + --replace-fail '@buildType@' ${if stdenv.hostPlatform.isStatic then "STATIC" else "SHARED"} \ + --replace-fail '@dev@' "''${!outputDev}" \ + --replace-fail '@lib@/lib/swift/host' "''${!outputLib}/lib" + ''; + + __structuredAttrs = true; + + meta = { + homepage = "https://github.com/swiftlang/swift-syntax"; + description = "Swift libraries for parsing Swift source code"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-syntax/patches/0001-gnu-install-dirs.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swift-syntax/patches/0001-gnu-install-dirs.patch new file mode 100644 index 000000000000..a57a008b3315 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-syntax/patches/0001-gnu-install-dirs.patch @@ -0,0 +1,36 @@ +From fa08f0527d1ec76369852dfe8d5d2fd9d3feee8d Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Fri, 26 Dec 2025 11:39:45 -0500 +Subject: [PATCH] gnu-install-dirs + +--- + cmake/modules/AddSwiftHostLibrary.cmake | 8 ++++---- + 1 file changed, 4 insertions(+), 4 deletions(-) + +diff --git a/cmake/modules/AddSwiftHostLibrary.cmake b/cmake/modules/AddSwiftHostLibrary.cmake +index d2f7bc69..4f89a61d 100644 +--- a/cmake/modules/AddSwiftHostLibrary.cmake ++++ b/cmake/modules/AddSwiftHostLibrary.cmake +@@ -184,15 +184,15 @@ function(add_swift_syntax_library name) + # Install this target + install(TARGETS ${target} + EXPORT SwiftSyntaxTargets +- ARCHIVE DESTINATION lib/${SWIFT_HOST_LIBRARIES_SUBDIRECTORY} +- LIBRARY DESTINATION lib/${SWIFT_HOST_LIBRARIES_SUBDIRECTORY} +- RUNTIME DESTINATION bin ++ ARCHIVE DESTINATION ${CMAKE_INSTALL_LIBDIR} ++ LIBRARY DESTINATION ${CMAKE_INSTALL_LIBDIR} ++ RUNTIME DESTINATION ${CMAKE_INSTALL_BINDIR} + ) + + # Install the module files. + install( + DIRECTORY ${module_base} +- DESTINATION lib/${SWIFT_HOST_LIBRARIES_SUBDIRECTORY} ++ DESTINATION ${CMAKE_INSTALL_INCLUDEDIR}/../lib/${SWIFT_HOST_LIBRARIES_SUBDIRECTORY} + FILES_MATCHING PATTERN "*.swiftinterface" + ) + else() +-- +2.51.2 + diff --git a/pkgs/development/compilers/swift_ng/sources-6.2.json b/pkgs/development/compilers/swift_ng/sources-6.2.json index 1f9d1d5bca63..47419f861fb2 100644 --- a/pkgs/development/compilers/swift_ng/sources-6.2.json +++ b/pkgs/development/compilers/swift_ng/sources-6.2.json @@ -7,5 +7,8 @@ }, "swift-corelibs-libdispatch": { "hash": "sha256-Tu2G9FAP4q1xgM1n9q17T6VrqJ3tv8RezyUex38yNds=" + }, + "swift-syntax": { + "hash": "sha256-DMMVJQj590RGGBkTgA89u01ZP2B8kbJTmfu+oxzYPds=" } } From ce1a8b6683b3470187d1aae7e0239ea005214a93 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 188/423] swiftPackages_ng: add bootstrap helper MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The Swift bootstrap process requires building the Swift compiler several times. Upstream Swift does this all in the the Swift build process, but we want to manage it with Nix instead. Doing it in Nix gives us more control over what it links against and will allow the stdlib to built separate from the compiler. It will also allow us to take the Swift 6.2 compiler and use it to bootstrap future versions of Swift. Additionally, the build crashes in `swift-frontend` on Darwin when using the bootstrapping mode, so it can’t be used anyway. Fortunately, the C++ compiler does work after some patching. It’s brittle, but it can build everything needed to build a more functional Swift bootstrap compiler. --- pkgs/top-level/swift-packages.nix | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) diff --git a/pkgs/top-level/swift-packages.nix b/pkgs/top-level/swift-packages.nix index f719950fd84f..172141aac597 100644 --- a/pkgs/top-level/swift-packages.nix +++ b/pkgs/top-level/swift-packages.nix @@ -4,6 +4,25 @@ let swift_sources_6_2 = builtins.fromJSON ( builtins.readFile ../development/compilers/swift_ng/sources-6.2.json ); + + mkBootstrapSwiftPackages = + { + lib, + bootstrapStage, + buildSwiftPackages, + swiftPackages, + swift_release ? null, + swift_sources ? null, + }: + swiftPackages.overrideScope ( + final: prev: + { + inherit bootstrapStage buildSwiftPackages; + swift = prev.swift.override { swift-corelibs-libdispatch = null; }; + } + // lib.optionalAttrs (swift_release != null) { inherit swift_release; } + // lib.optionalAttrs (swift_sources != null) { inherit swift_sources; } + ); in { From 40e846c2b0a8381cd90c0420c67230b5e3ca2efc Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 189/423] swiftPackages_ng.swift: init stage 1 at 6.2.4 The stage 1 compiler supports macros, which are needed by the 26.x SDK and to build Swift Foundation on Linux. --- .../swift_ng/by-name/sw/swiftc/package.nix | 63 ++++++++++++++++++- ...y-on-_StringProcessing-during-stage-.patch | 59 +++++++++++++++++ .../compilers/swift_ng/sources-6.2.json | 3 + pkgs/top-level/swift-packages.nix | 17 ++++- 4 files changed, 138 insertions(+), 4 deletions(-) create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0010-Remove-dependency-on-_StringProcessing-during-stage-.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/package.nix index f5e04b7f479f..88cc7853afd5 100644 --- a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/package.nix +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/package.nix @@ -17,9 +17,11 @@ perl, python3, replaceVars, + srcOnly, stdenv, swift-cmark, swift-corelibs-libdispatch, + swift-syntax, xcbuild, xz, zlib, @@ -72,11 +74,35 @@ let dylibExt = stdenv.hostPlatform.extensions.sharedLibrary; - swiftComponents' = swiftComponents; + isNotSwiftSyntax = if bootstrapStage == 0 then c: !lib.hasInfix "swift-syntax" c else _: true; + + swiftComponents' = lib.filter isNotSwiftSyntax swiftComponents; + + srcs = { + swift-experimental-string-processing = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-experimental-string-processing"; + tag = "swift-${swift_release}-RELEASE"; + inherit (swift_sources.swift-experimental-string-processing) hash; + }; + + swift-syntax = srcOnly { + inherit (swift-syntax) + name + version + src + patches + stdenv + ; + }; + }; in stdenv.mkDerivation (finalAttrs: { - pname = "swiftc" + lib.optionalString (bootstrapStage == 0) "-cxx_bootstrap"; + pname = + "swiftc" + + lib.optionalString (bootstrapStage == 0) "-cxx_bootstrap" + + lib.optionalString (bootstrapStage == 1) "-bootstrap"; version = swift_release; outputs = [ @@ -93,6 +119,11 @@ stdenv.mkDerivation (finalAttrs: { inherit (swift_sources.swift) hash; }; + postUnpack = lib.optionalString (bootstrapStage >= 1) '' + ln -s ${lib.escapeShellArg srcs.swift-experimental-string-processing} "$NIX_BUILD_TOP/swift-experimental-string-processing" + ln -s ${lib.escapeShellArg srcs.swift-syntax} "$NIX_BUILD_TOP/swift-syntax" + ''; + patches = [ # ClangImporter needs help finding the location of libc and libc++ (and using it). ./patches/0001-Read-C-and-C-stdlib-flags-from-the-wrapped-compiler.patch @@ -124,12 +155,19 @@ stdenv.mkDerivation (finalAttrs: { url = "https://github.com/swiftlang/swift/commit/cfbe70db5d1e65bed2388f97ee52f65719c812b3.patch?full_index=1"; hash = "sha256-XxdP3Qs2YfT20d5E216cOQy+fUgYQpwMDWSyl77NQHw="; }) + ] + ++ lib.optionals (bootstrapStage == 0) [ # Revert optimizer changes that cause the C++-based bootstrap compiler to be unable to compile functions with # infinite loops that return from the loop. This doesn’t affect the later stages, so it’s applied conditionally. # https://github.com/swiftlang/swift/pull/79186 ./patches/0008-revert-optimizer-changes.patch # Work around a compiler crash by partially reverting https://github.com/swiftlang/swift/pull/80920. ./patches/0009-siloptimizer-bootstrap-workaround.patch + ] + ++ lib.optionals (bootstrapStage == 1) [ + # Stage 1 doesn’t have a compiler that supports _StringProcessing. + # This isn’t a problem on Darwin, but it fails on Linux. + ./patches/0010-Remove-dependency-on-_StringProcessing-during-stage-.patch ]; postPatch = '' @@ -192,6 +230,21 @@ stdenv.mkDerivation (finalAttrs: { (lib.cmakeFeature "SWIFT_HOST_TRIPLE" stdenv.hostPlatform.swift.triple) # Tests should only be built when building a regular compiler. The bootstrap compiler is not functional enough. (lib.cmakeBool "SWIFT_INCLUDE_TESTS" false) + # Swift Concurrency is needed to build the stage 1 compiler on Linux. + (lib.cmakeBool "SWIFT_ENABLE_EXPERIMENTAL_CONCURRENCY" true) + ] + ++ lib.optionals (bootstrapStage == 1) [ + # Work around crashes in ownership verifier in the bootstrap compiler. + # See https://github.com/swiftlang/swift/issues/84552#issuecomment-3409245634 + "-DCMAKE_Swift_FLAGS=-Xfrontend -disable-sil-ownership-verifier" + ] + ++ lib.optionals (bootstrapStage >= 1) [ + # These features are needed for the final build due to using unguarded macros in the SDK required to build it. + (lib.cmakeBool "SWIFT_BUILD_SWIFT_SYNTAX" true) + (lib.cmakeBool "SWIFT_ENABLE_EXPERIMENTAL_OBSERVATION" true) + (lib.cmakeBool "SWIFT_ENABLE_EXPERIMENTAL_STRING_PROCESSING" true) + # Synchronization is required to build Foundation. + (lib.cmakeBool "SWIFT_ENABLE_SYNCHRONIZATION" true) ]; env = { @@ -210,6 +263,10 @@ stdenv.mkDerivation (finalAttrs: { if [ $NIX_APPLE_SDK_VERSION -lt 260000 ]; then NIX_LDFLAGS+=" -undefined dynamic_lookup" fi + '' + + lib.optionalString (bootstrapStage >= 1) '' + appendToVar cmakeFlags "-DSWIFT_PATH_TO_STRING_PROCESSING_SOURCE:PATH=$NIX_BUILD_TOP/swift-experimental-string-processing" + appendToVar cmakeFlags "-DSWIFT_PATH_TO_SWIFT_SYNTAX_SOURCE:PATH=$NIX_BUILD_TOP/swift-syntax" ''; postConfigure = @@ -271,6 +328,8 @@ stdenv.mkDerivation (finalAttrs: { done < <(find "$out" -type f -print0) ''; + passthru.supportsMacros = bootstrapStage >= 1; + __structuredAttrs = true; meta = { diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0010-Remove-dependency-on-_StringProcessing-during-stage-.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0010-Remove-dependency-on-_StringProcessing-during-stage-.patch new file mode 100644 index 000000000000..d1a1b7b4dd76 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0010-Remove-dependency-on-_StringProcessing-during-stage-.patch @@ -0,0 +1,59 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 4 Jul 2026 12:34:17 -0400 +Subject: [PATCH 10/10] Remove dependency on _StringProcessing during stage 1 + bootstrap + +--- + .../SwiftMacros/DebugDescriptionMacro.swift | 25 ++++++++----------- + 1 file changed, 10 insertions(+), 15 deletions(-) + +diff --git a/lib/Macros/Sources/SwiftMacros/DebugDescriptionMacro.swift b/lib/Macros/Sources/SwiftMacros/DebugDescriptionMacro.swift +index 4483bf7a0c9..7dbc301a1d0 100644 +--- a/lib/Macros/Sources/SwiftMacros/DebugDescriptionMacro.swift ++++ b/lib/Macros/Sources/SwiftMacros/DebugDescriptionMacro.swift +@@ -13,7 +13,6 @@ + import SwiftSyntax + import SwiftSyntaxMacros + import SwiftDiagnostics +-import _StringProcessing + + public enum DebugDescriptionMacro {} + public enum _DebugDescriptionPropertyMacro {} +@@ -515,23 +514,19 @@ extension String { + + extension String { + fileprivate func escapedForLLDB() -> String { +- guard #available(macOS 13, *) else { +- guard self.firstIndex(of: "$") != nil else { +- return self +- } ++ guard self.firstIndex(of: "$") != nil else { ++ return self ++ } + +- var result = "" +- for char in self { +- if char == "$" { +- result.append("\\$") +- } else { +- result.append(char) +- } ++ var result = "" ++ for char in self { ++ if char == "$" { ++ result.append("\\$") ++ } else { ++ result.append(char) + } +- return result + } +- +- return self.replacing("$", with: "\\$") ++ return result + } + } + +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/sources-6.2.json b/pkgs/development/compilers/swift_ng/sources-6.2.json index 47419f861fb2..416f3d9168e2 100644 --- a/pkgs/development/compilers/swift_ng/sources-6.2.json +++ b/pkgs/development/compilers/swift_ng/sources-6.2.json @@ -8,6 +8,9 @@ "swift-corelibs-libdispatch": { "hash": "sha256-Tu2G9FAP4q1xgM1n9q17T6VrqJ3tv8RezyUex38yNds=" }, + "swift-experimental-string-processing": { + "hash": "sha256-WtLLqdvYTmLWSS5q42b8yXFrJcC+dUy4uTuCeIflRFs=" + }, "swift-syntax": { "hash": "sha256-DMMVJQj590RGGBkTgA89u01ZP2B8kbJTmfu+oxzYPds=" } diff --git a/pkgs/top-level/swift-packages.nix b/pkgs/top-level/swift-packages.nix index 172141aac597..97098af645b0 100644 --- a/pkgs/top-level/swift-packages.nix +++ b/pkgs/top-level/swift-packages.nix @@ -36,6 +36,19 @@ in otherSplices ? generateSplicesForMkScope "swiftPackages_ng", }: +let + # Swift requires three bootstrap stages: + # - Stage 0 builds a minimal Swift compiler using only C++. + # - Stage 1 builds a Swift compiler using the stage 0 Swift compiler. Features needed to build macros are enabled. + # - Stage 2 builds a full Swift compiler and stdlib using the stage 1 compiler. + bootstrapStage0SwiftPackages = mkBootstrapSwiftPackages { + inherit lib; + swiftPackages = swiftPackages_ng; + bootstrapStage = 0; + buildSwiftPackages = swiftPackages_ng.overrideScope (_: _: { swift = null; }); + }; +in + makeScopeWithSplicing' { inherit otherSplices; extra = @@ -52,9 +65,9 @@ makeScopeWithSplicing' { }; in { - bootstrapStage = 0; + bootstrapStage = 1; - buildSwiftPackages = swiftPackages_ng.overrideScope (_: _: { swift = null; }); + buildSwiftPackages = bootstrapStage0SwiftPackages; inherit llvm_libtool; From 246541b9f75352d66ac8f32424bed4436a038017 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 190/423] swiftPackages_ng.swift: propagate 26.x SDK when macros are supported --- .../compilers/swift_ng/by-name/sw/swift/package.nix | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix index 22c6a496eae9..84bc5e36e17f 100644 --- a/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix @@ -1,6 +1,7 @@ { lib, apple-sdk_14, + apple-sdk_26, llvmPackages_upstream, stdenv, swift-corelibs-libdispatch, @@ -10,7 +11,8 @@ }: let - propagated-sdk = apple-sdk_14; + # Need to use an older SDK if `swiftc` does not support macros. + propagated-sdk = if swiftc.supportsMacros then apple-sdk_26 else apple-sdk_14; # `out` and `dev` are merged because that’s what Swift expects. outLinks = symlinkJoin { From ba32eefdc8acdd5e61bd2cdd63d279d0fe51848c Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 191/423] swiftPackages_ng.swift-minimal: init MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Every package in the Swift package set uses the Swift toolchain to build, but obviously they can’t use a toolchain that includes themselves. That would result in circular dependencies. Note: This is a private helper. Packages outside of the Swift package set should always use the full Swift toolchain when building. --- pkgs/top-level/swift-packages.nix | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/pkgs/top-level/swift-packages.nix b/pkgs/top-level/swift-packages.nix index 97098af645b0..9e1262f3d320 100644 --- a/pkgs/top-level/swift-packages.nix +++ b/pkgs/top-level/swift-packages.nix @@ -73,6 +73,10 @@ makeScopeWithSplicing' { llvmPackages_upstream = llvmPackages; + swift-minimal = self.swift.override { + swift-corelibs-libdispatch = null; + }; + swift_sources = swift_sources_6_2; }; f = lib.extends autoCalledPackages (self: { From f0edcf6f72e756d26af51cd213caa427b4b740a9 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 192/423] swiftPackages_ng.swift-corelibs-libdispatch: build the Swift overlay --- .../sw/swift-corelibs-libdispatch/package.nix | 44 ++++++++++++++++--- .../swift_ng/by-name/sw/swiftc/package.nix | 2 +- 2 files changed, 40 insertions(+), 6 deletions(-) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-libdispatch/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-libdispatch/package.nix index dbb318a4e9b7..e95f74521218 100644 --- a/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-libdispatch/package.nix +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-libdispatch/package.nix @@ -7,17 +7,30 @@ ninja, stdenv, swift-corelibs-libdispatch, + swift-minimal, swift_release, swift_sources, + useSwift ? true, # Where to build the Swift overlay and swiftDispatch shared library. }: let - swift-corelibs-libdispatch-no-overlay-lib = placeholder "out"; - swift-corelibs-libdispatch-no-overlay-dev = placeholder "dev"; + swift-corelibs-libdispatch-no-overlay = swift-corelibs-libdispatch.override { useSwift = false; }; + + swift-corelibs-libdispatch-no-overlay-lib = + if useSwift then + lib.escapeShellArg (lib.getLib swift-corelibs-libdispatch-no-overlay) + else + placeholder "out"; + + swift-corelibs-libdispatch-no-overlay-dev = + if useSwift then + lib.escapeShellArg (lib.getDev swift-corelibs-libdispatch-no-overlay) + else + placeholder "dev"; in stdenv.mkDerivation (finalAttrs: { - pname = "swift-corelibs-libdispatch"; + pname = "swift-corelibs-libdispatch${lib.optionalString useSwift "-swift-overlay"}"; version = swift_release; outputs = [ @@ -48,7 +61,7 @@ stdenv.mkDerivation (finalAttrs: { cmakeFlags = [ # The Swift overlay is built separately using the no-overlay derivation as a base. - (lib.cmakeBool "ENABLE_SWIFT" false) + (lib.cmakeBool "ENABLE_SWIFT" useSwift) ] ++ lib.optionals stdenv.hostPlatform.isMusl [ # Musl requires _GNU_SOURCE or the getprogname shim fails to build. @@ -63,6 +76,7 @@ stdenv.mkDerivation (finalAttrs: { cmake ninja ] + ++ lib.optionals useSwift [ swift-minimal ] ++ lib.optionals stdenv.hostPlatform.isWindows [ lld ]; postInstall = '' @@ -79,7 +93,27 @@ stdenv.mkDerivation (finalAttrs: { --replace-fail '@dev@' ${swift-corelibs-libdispatch-no-overlay-dev} \ --replace-fail '@out-swift@' "$out" \ --replace-fail '@dev-swift@' "''${!outputDev}" - ''; + '' + + lib.optionalString useSwift ( + '' + mkdir -p "$dev/nix-support" "$man" + + moveToOutput lib/swift "''${!outputDev}" + + # Rely on `propagated-build-inputs` to propagate the non-Swift shared libraries, + # so with or without overlay uses the same ones. + rm "''${!outputLib}/lib/libdispatch$libExt" "''${!outputLib}/lib/libBlocksRuntime$libExt" + + ln -s ${lib.escapeShellArg (lib.getMan swift-corelibs-libdispatch-no-overlay)}/* "$man" + + echo -n ${swift-corelibs-libdispatch-no-overlay-dev} >> "$dev/nix-support/propagated-build-inputs" + '' + # Clean up the rpaths to reference the non-overlay shared libraries. + + lib.optionalString stdenv.hostPlatform.isElf '' + dylib="''${!outputLib}/lib/libswiftDispatch${stdenv.hostPlatform.extensions.sharedLibrary}" + patchelf --add-rpath ${swift-corelibs-libdispatch-no-overlay-lib}/lib "$dylib" + '' + ); __structuredAttrs = true; diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/package.nix index 88cc7853afd5..3a2f7d325177 100644 --- a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/package.nix +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/package.nix @@ -303,7 +303,7 @@ stdenv.mkDerivation (finalAttrs: { ++ lib.optionals stdenv.hostPlatform.isDarwin [ build-sdk ] ++ lib.optionals (!stdenv.hostPlatform.isDarwin) [ libuuid - swift-corelibs-libdispatch + (swift-corelibs-libdispatch.override { useSwift = false; }) ]; postInstall = From 06be068d169cf0d7d02d10da92f5426d474a31d2 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 193/423] swiftPackages_ng.swift: correctly propagate libdispatch The Swift overlay for libdispatch does not include the non-Swift shared libraries. These need to be included in the toolchain in addition to the Swift overlay and its module. --- .../compilers/swift_ng/by-name/sw/swift/package.nix | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix index 84bc5e36e17f..b666adbec16e 100644 --- a/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix @@ -14,6 +14,10 @@ let # Need to use an older SDK if `swiftc` does not support macros. propagated-sdk = if swiftc.supportsMacros then apple-sdk_26 else apple-sdk_14; + # The toolchain needs to propagate libdispatch with and without the Swift overlay to make sure it propagates + # both the non-Swift shared libraries and the Swift overlay shared library. + swift-corelibs-libdispatch-no-overlay = swift-corelibs-libdispatch.override { useSwift = false; }; + # `out` and `dev` are merged because that’s what Swift expects. outLinks = symlinkJoin { name = "swift" + lib.removePrefix "swiftc" (lib.getName swiftc) + "-${swift_release}-out"; @@ -25,6 +29,8 @@ let lib.optionals (swift-corelibs-libdispatch != null) [ swift-corelibs-libdispatch.out swift-corelibs-libdispatch.dev + swift-corelibs-libdispatch-no-overlay.out + swift-corelibs-libdispatch-no-overlay.dev ] ); }; @@ -63,6 +69,7 @@ stdenv.mkDerivation (finalAttrs: { lib.optionals stdenv.targetPlatform.isDarwin [ propagated-sdk ] ++ lib.optionals (!stdenv.hostPlatform.isDarwin) ( lib.optionals (swift-corelibs-libdispatch != null) [ + swift-corelibs-libdispatch-no-overlay.out swift-corelibs-libdispatch.out ] ); From 602696312b3f12af43a0711496560a71274bb2e6 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 194/423] swiftPackages_ng.swift-collections: init at 1.6.0 --- .../files/SwiftCollectionsConfig.cmake | 21 ++++++ .../by-name/sw/swift-collections/package.nix | 75 +++++++++++++++++++ 2 files changed, 96 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-collections/files/SwiftCollectionsConfig.cmake create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-collections/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-collections/files/SwiftCollectionsConfig.cmake b/pkgs/development/compilers/swift_ng/by-name/sw/swift-collections/files/SwiftCollectionsConfig.cmake new file mode 100644 index 000000000000..6847ed976e5c --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-collections/files/SwiftCollectionsConfig.cmake @@ -0,0 +1,21 @@ +set(CollectionModules + _RopeModule + BasicContainers + BitCollections + Collections + ContainersPreview + DequeModule + HashTreeCollections + HeapModule + InternalCollectionsUtilities + OrderedCollections + TrailingElementsModule +) + +foreach(CollectionModule ${CollectionModules}) + add_library(SwiftCollections::${CollectionModule} @buildType@ IMPORTED) + set_target_properties(SwiftCollections::${CollectionModule} PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}${CollectionModule}${CMAKE_@buildType@_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@include@/lib/swift/@swiftPlatform@" + ) +endforeach() diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-collections/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift-collections/package.nix new file mode 100644 index 000000000000..b9ba08469736 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-collections/package.nix @@ -0,0 +1,75 @@ +{ + lib, + cmake, + fetchFromGitHub, + gitUpdater, + ninja, + stdenv, + swift-minimal, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "swift-collections"; + version = "1.6.0"; + + outputs = [ + "out" + "dev" + ]; + + src = fetchFromGitHub { + owner = "apple"; + repo = "swift-collections"; + tag = finalAttrs.version; + hash = "sha256-oLYfOxB4CGH5tTkNOi0IX3iHTO64YBoaFyu+/1I5HNE="; + }; + + postPatch = '' + substituteInPlace cmake/modules/SwiftSupport.cmake \ + --replace-fail ' DESTINATION lib' "DESTINATION ''${!outputDev}/lib" \ + --replace-fail 'lib/''${swift}/''${COLLECTIONS_PLATFORM}$<$:/''${COLLECTIONS_ARCH}>' \''${CMAKE_INSTALL_LIBDIR} + ''; + + strictDeps = true; + + cmakeFlags = [ + # Defaults to not building shared libs on Linux. + (lib.cmakeBool "BUILD_SHARED_LIBS" (!stdenv.hostPlatform.isStatic)) + ]; + + preConfigure = '' + appendToVar cmakeFlags -DCMAKE_Swift_COMPILER_TARGET=${stdenv.hostPlatform.swift.triple} + appendToVar cmakeFlags -DCMAKE_Swift_FLAGS=-module-cache-path\ "$NIX_BUILD_TOP/module-cache" + ''; + + nativeBuildInputs = [ + cmake + ninja + swift-minimal + ]; + + postInstall = '' + moveToOutput lib/swift "''${!outputDev}" + moveToOutput lib/swift_static "''${!outputDev}" + + # Install CMake config file for the Swift Collections library. + mkdir -p "''${!outputDev}/lib/cmake/SwiftCollections" + substitute ${./files/SwiftCollectionsConfig.cmake} "''${!outputDev}/lib/cmake/SwiftCollections/SwiftCollectionsConfig.cmake" \ + --replace-fail '@buildType@' ${if stdenv.hostPlatform.isStatic then "STATIC" else "SHARED"} \ + --replace-fail '@include@' "''${!outputDev}" \ + --replace-fail '@lib@' "''${!outputLib}" \ + --replace-fail '@swiftPlatform@' ${stdenv.hostPlatform.swift.platform} + ''; + + __structuredAttrs = true; + + passthru.updateScript = gitUpdater { }; + + meta = { + homepage = "https://github.com/apple/swift-collections"; + description = "Commonly used data structures for Swift"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) From 5e2ebf6050e97e5c057c37d6f3802b544c47dd15 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 195/423] swiftPackages_ng.swift-foundation-icu: init at 6.2.4 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The upstream package vendors Apple’s ICU fork, but we already build it as `darwin.ICU`. This package just provides the needed CMake files to allow it to work with the rest of the Swift build process. --- .../files/SwiftFoundationICUConfig.cmake | 5 ++ .../sw/swift-foundation-icu/package.nix | 54 +++++++++++++++++++ .../compilers/swift_ng/sources-6.2.json | 3 ++ 3 files changed, 62 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-foundation-icu/files/SwiftFoundationICUConfig.cmake create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-foundation-icu/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-foundation-icu/files/SwiftFoundationICUConfig.cmake b/pkgs/development/compilers/swift_ng/by-name/sw/swift-foundation-icu/files/SwiftFoundationICUConfig.cmake new file mode 100644 index 000000000000..83eef9ba0337 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-foundation-icu/files/SwiftFoundationICUConfig.cmake @@ -0,0 +1,5 @@ +add_library(_FoundationICU @buildType@ IMPORTED) +set_target_properties(_FoundationICU PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}icucore${CMAKE_@buildType@_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@dev@/lib/swift" +) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-foundation-icu/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift-foundation-icu/package.nix new file mode 100644 index 000000000000..5296a0e473f9 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-foundation-icu/package.nix @@ -0,0 +1,54 @@ +{ + lib, + fetchFromGitHub, + stdenvNoCC, + darwin, + swift_release, + swift_sources, +}: + +stdenvNoCC.mkDerivation { + pname = "swift-foundation-icu"; + version = lib.getVersion darwin.ICU; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-foundation-icu"; + tag = "swift-${swift_release}-RELEASE"; + inherit (swift_sources.swift-foundation-icu) hash; + }; + + propagatedBuildInputs = [ (lib.getLib darwin.ICU) ]; + + buildCommand = '' + runPhase unpackPhase + + # Provide a CMake module. This is primarily used to glue together parts of the Swift toolchain. + # Upstream provides a build that does this for us, but we want to reuse our existing ICU build. + mkdir -p "''${!outputDev}/lib/cmake/SwiftFoundationICU" + export dylibExt="${stdenvNoCC.hostPlatform.extensions.sharedLibrary}" + + substitute ${./files/SwiftFoundationICUConfig.cmake} "''${!outputDev}/lib/cmake/SwiftFoundationICU/SwiftFoundationICUConfig.cmake" \ + --replace-fail '@buildType@' ${if stdenvNoCC.hostPlatform.isStatic then "STATIC" else "SHARED"} \ + --replace-fail '@lib@' ${lib.escapeShellArg (lib.getLib darwin.ICU)} \ + --replace-fail '@dev@' "''${!outputDev}" + + # Copy headers to `_foundation_unicode`. The translation is needed to make sure they’re found in the tooclhain. + mkdir -p "$out/lib/swift/_foundation_unicode" + for header in ${lib.escapeShellArg (lib.getInclude darwin.ICU)}/include/unicode/*; do + # Not all files include other files, so these can’t be `--replace-fail`. Use both `"` and `<` to be thorough. + substitute "$header" "$out/lib/swift/_foundation_unicode/$(basename "$header")" \ + --replace-quiet 'include "unicode/' 'include "_foundation_unicode/' \ + --replace-quiet 'include +Date: Sat, 27 Jun 2026 22:02:03 -0400 +Subject: [PATCH 1/3] gnu-install-dirs + +--- + cmake/modules/SwiftFoundationSwiftSupport.cmake | 8 ++++---- + 1 file changed, 4 insertions(+), 4 deletions(-) + +diff --git a/cmake/modules/SwiftFoundationSwiftSupport.cmake b/cmake/modules/SwiftFoundationSwiftSupport.cmake +index cbdfc2a..9418500 100644 +--- a/cmake/modules/SwiftFoundationSwiftSupport.cmake ++++ b/cmake/modules/SwiftFoundationSwiftSupport.cmake +@@ -21,8 +21,8 @@ function(_swift_foundation_install_target module) + endif() + + install(TARGETS ${module} +- ARCHIVE DESTINATION lib/${swift}/${swift_os} +- LIBRARY DESTINATION lib/${swift}/${swift_os} ++ ARCHIVE DESTINATION ${CMAKE_INSTALL_LIBDIR} ++ LIBRARY DESTINATION ${CMAKE_INSTALL_LIBDIR} + RUNTIME DESTINATION ${CMAKE_INSTALL_BINDIR}) + if(type STREQUAL EXECUTABLE) + return() +@@ -45,10 +45,10 @@ function(_swift_foundation_install_target module) + endif() + + install(FILES $/${module_name}.swiftdoc +- DESTINATION lib/${swift}/${swift_os}/${module_name}.swiftmodule ++ DESTINATION ${CMAKE_INSTALL_INCLUDEDIR}/../lib/${swift}/${swift_os}/${module_name}.swiftmodule + RENAME ${SwiftFoundation_MODULE_TRIPLE}.swiftdoc) + install(FILES $/${module_name}.swiftmodule +- DESTINATION lib/${swift}/${swift_os}/${module_name}.swiftmodule ++ DESTINATION ${CMAKE_INSTALL_INCLUDEDIR}/../lib/${swift}/${swift_os}/${module_name}.swiftmodule + RENAME ${SwiftFoundation_MODULE_TRIPLE}.swiftmodule) + + endfunction() +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-foundation/patches/0002-Devendor-SwiftFoundationICU.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swift-foundation/patches/0002-Devendor-SwiftFoundationICU.patch new file mode 100644 index 000000000000..07bbb665bc3d --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-foundation/patches/0002-Devendor-SwiftFoundationICU.patch @@ -0,0 +1,48 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 27 Jun 2026 20:50:03 -0400 +Subject: [PATCH 2/3] Devendor SwiftFoundationICU +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Swift Collections is not devendored because its module needs to be in +the toolchain, and we don’t want to leak Swift Collections into it. +--- + CMakeLists.txt | 13 ++----------- + 1 file changed, 2 insertions(+), 11 deletions(-) + +diff --git a/CMakeLists.txt b/CMakeLists.txt +index 8b4f45e..f71be26 100644 +--- a/CMakeLists.txt ++++ b/CMakeLists.txt +@@ -67,16 +67,7 @@ set(SwiftFoundation_MACRO "" CACHE STRING "Path to Foundation macro plugin") + + # Make sure our dependencies exists + include(FetchContent) +-if (_SwiftFoundationICU_SourceDIR) +- message(STATUS "_SwiftFoundationICU_SourceDIR provided, using swift-foundation-icu checkout at ${_SwiftFoundationICU_SourceDIR}") +- FetchContent_Declare(SwiftFoundationICU +- SOURCE_DIR ${_SwiftFoundationICU_SourceDIR}) +-else() +- message(STATUS "_SwiftFoundationICU_SourceDIR not provided, checking out local copy of swift-foundation-icu") +- FetchContent_Declare(SwiftFoundationICU +- GIT_REPOSITORY https://github.com/apple/swift-foundation-icu.git +- GIT_TAG release/6.2) +-endif() ++find_package(SwiftFoundationICU) + + if (_SwiftCollections_SourceDIR) + message(STATUS "_SwiftCollections_SourceDIR provided, using swift-foundation-icu checkout at ${_SwiftCollections_SourceDIR}") +@@ -88,7 +79,7 @@ else() + GIT_REPOSITORY https://github.com/apple/swift-collections.git + GIT_TAG 1.1.2) + endif() +-FetchContent_MakeAvailable(SwiftFoundationICU SwiftCollections) ++FetchContent_MakeAvailable(SwiftCollections) + + list(APPEND CMAKE_MODULE_PATH ${SwiftFoundation_SOURCE_DIR}/cmake/modules) + +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/sources-6.2.json b/pkgs/development/compilers/swift_ng/sources-6.2.json index f5443d1abc95..cf15fde41571 100644 --- a/pkgs/development/compilers/swift_ng/sources-6.2.json +++ b/pkgs/development/compilers/swift_ng/sources-6.2.json @@ -11,6 +11,9 @@ "swift-experimental-string-processing": { "hash": "sha256-WtLLqdvYTmLWSS5q42b8yXFrJcC+dUy4uTuCeIflRFs=" }, + "swift-foundation": { + "hash": "sha256-otE5EGG53zadZVZ0P67rr+4h4x/c3rWWEdZyL23Mxio=" + }, "swift-foundation-icu": { "hash": "sha256-C2rq5Q0F1id89mTN4+B/fKSvX1SEAf3/Zgvb/3IdsJ8=" }, From 57fbb23103b963f9d8f5c0a6c8b2314d000b714c Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 197/423] swiftPackages_ng.swift-corelibs-foundation: init at 6.2.4 --- .../files/FoundationConfig.cmake | 25 ++++ .../sw/swift-corelibs-foundation/package.nix | 118 ++++++++++++++++++ .../patches/0001-gnu-install-dirs.patch | 40 ++++++ ...iftFoundation-and-SwiftFoundationICU.patch | 45 +++++++ .../compilers/swift_ng/sources-6.2.json | 3 + 5 files changed, 231 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-foundation/files/FoundationConfig.cmake create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-foundation/package.nix create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-foundation/patches/0001-gnu-install-dirs.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-foundation/patches/0002-Devendor-SwiftFoundation-and-SwiftFoundationICU.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-foundation/files/FoundationConfig.cmake b/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-foundation/files/FoundationConfig.cmake new file mode 100644 index 000000000000..159354b71c3e --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-foundation/files/FoundationConfig.cmake @@ -0,0 +1,25 @@ +if (NOT TARGET _FoundationICU) + find_package(_FoundationICU) +endif () + +if (NOT TARGET SwiftCollections::_RopeModule) + find_package(SwiftCollections) +endif () + +if (NOT TARGET FoundationEssentials) + find_package(SwiftFoundation) +endif () + +add_library(Foundation @buildType@ IMPORTED) +set_target_properties(Foundation PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}Foundation${CMAKE_@buildType@_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@dev@/lib/swift;@dev@/lib/swift/@swiftPlatform@" +) +target_link_libraries(FoundationEssentials INTERFACE + _FoundationICU + FoundationEssentials + FoundationInternationalization + SwiftCollections::_RopeModule + SwiftCollections::InternalCollectionsUtilities + SwiftCollections::OrderedCollections +) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-foundation/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-foundation/package.nix new file mode 100644 index 000000000000..3e544bb2cbcd --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-foundation/package.nix @@ -0,0 +1,118 @@ +{ + lib, + cmake, + curl, + fetchFromGitHub, + libxml2, + ninja, + stdenv, + swift-corelibs-libdispatch, + swift-foundation, + swift-foundation-icu, + swift-minimal, + swift_release, + swift_sources, +}: + +let + doInstallCheck = stdenv.buildPlatform.canExecute stdenv.hostPlatform; +in + +stdenv.mkDerivation (finalAttrs: { + pname = "swift-corelibs-foundation"; + version = swift_release; + + outputs = [ + "out" + "dev" + ]; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-corelibs-foundation"; + tag = "swift-${finalAttrs.version}-RELEASE"; + inherit (swift_sources.swift-corelibs-foundation) hash; + }; + + patches = [ + ./patches/0001-gnu-install-dirs.patch + ./patches/0002-Devendor-SwiftFoundation-and-SwiftFoundationICU.patch + ]; + + strictDeps = true; + + nativeBuildInputs = [ + cmake + ninja + swift-minimal + ]; + + buildInputs = [ + curl + libxml2 + swift-corelibs-libdispatch + swift-foundation + swift-foundation-icu + ]; + + postInstall = '' + moveToOutput lib/swift "''${!outputDev}" + + # Install CMake config file for the Swift Collections library. + mkdir -p "''${!outputDev}/lib/cmake/Foundation" + substitute ${./files/FoundationConfig.cmake} "''${!outputDev}/lib/cmake/Foundation/FoundationConfig.cmake" \ + --replace-fail '@buildType@' ${if stdenv.hostPlatform.isStatic then "STATIC" else "SHARED"} \ + --replace-fail '@dev@' "''${!outputDev}" \ + --replace-fail '@lib@' "''${!outputLib}" \ + --replace-fail '@swiftPlatform@' ${stdenv.hostPlatform.swift.platform} + '' + + lib.optionalString (stdenv.hostPlatform.isElf && !stdenv.hostPlatform.isStatic) '' + # Make sure swift-corelibs-foundation has an rpath pointing at the stdlib (since it is installed outside of it) + # as well as to Dispatch and Swift Foundation. Also do the same for `plutil`. + for f in "$out/bin/plutil" "$out/lib/libFoundation${stdenv.hostPlatform.extensions.sharedLibrary}"; do + patchelf --add-rpath ${ + lib.escapeShellArg ( + lib.makeSearchPathOutput "out" "lib/swift/${stdenv.hostPlatform.swift.platform}" [ swift-minimal ] + ) + } "$f" + patchelf --add-rpath ${ + lib.escapeShellArg ( + lib.makeLibraryPath [ + # Need both for the Swift and non-Swift shared libraries + swift-corelibs-libdispatch + (swift-corelibs-libdispatch.override { useSwift = false; }) + swift-foundation + ] + ) + } "$f" + done + patchelf --add-rpath ${ + lib.escapeShellArg (lib.makeLibraryPath [ curl ]) + } "$out/lib/libFoundationNetworking${stdenv.hostPlatform.extensions.sharedLibrary}" + patchelf --add-rpath ${ + lib.escapeShellArg (lib.makeLibraryPath [ libxml2 ]) + } "$out/lib/libFoundationXML${stdenv.hostPlatform.extensions.sharedLibrary}" + ''; + + inherit doInstallCheck; + + # Can’t use `versionCheckHook` because `plutil` does not have an option to print the version. + installCheckPhase = '' + runHook preInstallCheck + + "''${!outputBin}/bin/${finalAttrs.meta.mainProgram}" -help | grep "plutil:" + + runHook postInstallCheck + ''; + + __structuredAttrs = true; + + meta = { + description = "Core utilities, internationalization, and OS independence for Swift"; + mainProgram = "plutil"; + homepage = "https://github.com/swiftlang/swift-corelibs-foundation"; + platforms = lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-foundation/patches/0001-gnu-install-dirs.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-foundation/patches/0001-gnu-install-dirs.patch new file mode 100644 index 000000000000..f8f0351a201c --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-foundation/patches/0001-gnu-install-dirs.patch @@ -0,0 +1,40 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 4 Jul 2026 10:55:52 -0400 +Subject: [PATCH 1/2] gnu-install-dirs + +--- + cmake/modules/FoundationSwiftSupport.cmake | 8 ++++---- + 1 file changed, 4 insertions(+), 4 deletions(-) + +diff --git a/cmake/modules/FoundationSwiftSupport.cmake b/cmake/modules/FoundationSwiftSupport.cmake +index 85868392..706f4b19 100644 +--- a/cmake/modules/FoundationSwiftSupport.cmake ++++ b/cmake/modules/FoundationSwiftSupport.cmake +@@ -23,8 +23,8 @@ function(_foundation_install_target module) + endif() + + install(TARGETS ${module} +- ARCHIVE DESTINATION lib/${swift}/${swift_os} +- LIBRARY DESTINATION lib/${swift}/${swift_os} ++ ARCHIVE DESTINATION ${CMAKE_INSTALL_LIBDIR} ++ LIBRARY DESTINATION ${CMAKE_INSTALL_LIBDIR} + RUNTIME DESTINATION ${CMAKE_INSTALL_BINDIR}) + if(type STREQUAL EXECUTABLE) + return() +@@ -36,10 +36,10 @@ function(_foundation_install_target module) + endif() + + install(FILES $/${module_name}.swiftdoc +- DESTINATION lib/${swift}/${swift_os}/${module_name}.swiftmodule ++ DESTINATION ${CMAKE_INSTALL_INCLUDEDIR}/../lib/${swift}/${swift_os}/${module_name}.swiftmodule + RENAME ${SwiftFoundation_MODULE_TRIPLE}.swiftdoc) + install(FILES $/${module_name}.swiftmodule +- DESTINATION lib/${swift}/${swift_os}/${module_name}.swiftmodule ++ DESTINATION ${CMAKE_INSTALL_INCLUDEDIR}/../lib/${swift}/${swift_os}/${module_name}.swiftmodule + RENAME ${SwiftFoundation_MODULE_TRIPLE}.swiftmodule) + + endfunction() +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-foundation/patches/0002-Devendor-SwiftFoundation-and-SwiftFoundationICU.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-foundation/patches/0002-Devendor-SwiftFoundation-and-SwiftFoundationICU.patch new file mode 100644 index 000000000000..668f48fbe4da --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-foundation/patches/0002-Devendor-SwiftFoundation-and-SwiftFoundationICU.patch @@ -0,0 +1,45 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 4 Jul 2026 10:13:45 -0400 +Subject: [PATCH 2/2] Devendor SwiftFoundation and SwiftFoundationICU + +--- + CMakeLists.txt | 22 ++-------------------- + 1 file changed, 2 insertions(+), 20 deletions(-) + +diff --git a/CMakeLists.txt b/CMakeLists.txt +index 08f69905..540afe42 100644 +--- a/CMakeLists.txt ++++ b/CMakeLists.txt +@@ -81,26 +81,8 @@ option(FOUNDATION_BUILD_NETWORKING "build FoundationNetworking" + + set(CMAKE_POSITION_INDEPENDENT_CODE YES) + +-# Fetchable dependencies +-include(FetchContent) +-if (_SwiftFoundationICU_SourceDIR) +- FetchContent_Declare(SwiftFoundationICU +- SOURCE_DIR ${_SwiftFoundationICU_SourceDIR}) +-else() +- FetchContent_Declare(SwiftFoundationICU +- GIT_REPOSITORY https://github.com/apple/swift-foundation-icu.git +- GIT_TAG 0.0.9) +-endif() +- +-if (_SwiftFoundation_SourceDIR) +- FetchContent_Declare(SwiftFoundation +- SOURCE_DIR ${_SwiftFoundation_SourceDIR}) +-else() +- FetchContent_Declare(SwiftFoundation +- GIT_REPOSITORY https://github.com/apple/swift-foundation.git +- GIT_TAG main) +-endif() +-FetchContent_MakeAvailable(SwiftFoundationICU SwiftFoundation) ++find_package(SwiftFoundation) ++find_package(SwiftFoundationICU) + + include(CheckLinkerFlag) + include(CheckSymbolExists) +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/sources-6.2.json b/pkgs/development/compilers/swift_ng/sources-6.2.json index cf15fde41571..8099aa4ee4a5 100644 --- a/pkgs/development/compilers/swift_ng/sources-6.2.json +++ b/pkgs/development/compilers/swift_ng/sources-6.2.json @@ -5,6 +5,9 @@ "swift": { "hash": "sha256-apbBe/TMzq0+1XLkaTOj5NaYzLQ81i+vU+O7VSEJrKo=" }, + "swift-corelibs-foundation": { + "hash": "sha256-Ytxiu80su2jnF/xLcLVEaHXYvI4spLO8d+qEhDxqAdQ=" + }, "swift-corelibs-libdispatch": { "hash": "sha256-Tu2G9FAP4q1xgM1n9q17T6VrqJ3tv8RezyUex38yNds=" }, From 69368615c46be241983aeaba3022d046c0deb9c6 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 198/423] swiftPackages_ng.swift: include Foundation in the toolchain --- .../swift_ng/by-name/sw/swift/package.nix | 19 +++++++++++++++++++ pkgs/top-level/swift-packages.nix | 8 +++++++- 2 files changed, 26 insertions(+), 1 deletion(-) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix index b666adbec16e..1ab3aaf5676e 100644 --- a/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix @@ -4,7 +4,10 @@ apple-sdk_26, llvmPackages_upstream, stdenv, + swift-corelibs-foundation, swift-corelibs-libdispatch, + swift-foundation, + swift-foundation-icu, swiftc, symlinkJoin, swift_release, @@ -25,6 +28,10 @@ let swiftc.out swiftc.dev ] + ++ lib.optionals (stdenv.hostPlatform.isDarwin && swift-foundation != null) [ + # Needed for FoundationMacros, which is otherwise not part of the SDK on Darwin. + swift-foundation.out + ] ++ lib.optionals (!stdenv.hostPlatform.isDarwin) ( lib.optionals (swift-corelibs-libdispatch != null) [ swift-corelibs-libdispatch.out @@ -32,6 +39,13 @@ let swift-corelibs-libdispatch-no-overlay.out swift-corelibs-libdispatch-no-overlay.dev ] + ++ lib.optionals (swift-foundation != null) [ + swift-corelibs-foundation.out + swift-corelibs-foundation.dev + swift-foundation-icu.out + swift-foundation.dev + swift-foundation.out + ] ); }; @@ -72,6 +86,11 @@ stdenv.mkDerivation (finalAttrs: { swift-corelibs-libdispatch-no-overlay.out swift-corelibs-libdispatch.out ] + ++ lib.optionals (swift-foundation != null) [ + swift-corelibs-foundation.out + swift-foundation-icu.out + swift-foundation.out + ] ); buildCommand = '' diff --git a/pkgs/top-level/swift-packages.nix b/pkgs/top-level/swift-packages.nix index 9e1262f3d320..01e9da472dcb 100644 --- a/pkgs/top-level/swift-packages.nix +++ b/pkgs/top-level/swift-packages.nix @@ -18,7 +18,12 @@ let final: prev: { inherit bootstrapStage buildSwiftPackages; - swift = prev.swift.override { swift-corelibs-libdispatch = null; }; + swift = prev.swift.override ( + { + swift-corelibs-libdispatch = null; + swift-foundation = null; + } + ); } // lib.optionalAttrs (swift_release != null) { inherit swift_release; } // lib.optionalAttrs (swift_sources != null) { inherit swift_sources; } @@ -75,6 +80,7 @@ makeScopeWithSplicing' { swift-minimal = self.swift.override { swift-corelibs-libdispatch = null; + swift-foundation = null; }; swift_sources = swift_sources_6_2; From a4330ce7ce99a7ac0b8f60b894d4e3c10608828e Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 199/423] swiftPackages_ng.swift-argument-parser: init at 1.8.2 --- .../files/ArgumentParserConfig.cmake | 5 ++ .../sw/swift-argument-parser/package.nix | 79 +++++++++++++++++++ ...01-install-argument-parser-tool-info.patch | 22 ++++++ 3 files changed, 106 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-argument-parser/files/ArgumentParserConfig.cmake create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-argument-parser/package.nix create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-argument-parser/patches/0001-install-argument-parser-tool-info.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-argument-parser/files/ArgumentParserConfig.cmake b/pkgs/development/compilers/swift_ng/by-name/sw/swift-argument-parser/files/ArgumentParserConfig.cmake new file mode 100644 index 000000000000..d2fa30ba8493 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-argument-parser/files/ArgumentParserConfig.cmake @@ -0,0 +1,5 @@ +add_library(ArgumentParser @buildType@ IMPORTED) +set_target_properties(ArgumentParser PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}ArgumentParser${CMAKE_@buildType@_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@include@/lib/swift/@swiftPlatform@;@include@/lib/swift_static/@swiftPlatform@" +) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-argument-parser/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift-argument-parser/package.nix new file mode 100644 index 000000000000..3e1313d8e2ce --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-argument-parser/package.nix @@ -0,0 +1,79 @@ +{ + lib, + cmake, + fetchFromGitHub, + gitUpdater, + llvm_libtool, + ninja, + stdenv, + swift-foundation, + swift-minimal, +}: + +let + swiftPlatform = stdenv.hostPlatform.swift.platform; + swift = swift-minimal.override { inherit swift-foundation; }; # Swift Argument Parser requires Foundation. +in + +# Swift Argument Parser is a dependency to both Swift Compiler Driver and SwiftPM. +# It must be built with CMake and use Swift without swift-driver to avoid dependency cycles. +stdenv.mkDerivation (finalAttrs: { + pname = "swift-argument-parser"; + version = "1.8.2"; + + outputs = [ + "out" + "dev" + ]; + + src = fetchFromGitHub { + owner = "apple"; + repo = "swift-argument-parser"; + tag = finalAttrs.version; + hash = "sha256-BWm2ZbNIvlamNp8cxoicFlAcujjhH22VPzs67lEIXWU="; + }; + + patches = [ + # Install libSwiftArgumentParserToolInfo.a and its module as well. + ./patches/0001-install-argument-parser-tool-info.patch + ]; + + strictDeps = true; + + preConfigure = '' + appendToVar cmakeFlags -DCMAKE_Swift_COMPILER_TARGET=${stdenv.hostPlatform.swift.triple} + appendToVar cmakeFlags -DCMAKE_Swift_FLAGS=-module-cache-path\ "$NIX_BUILD_TOP/module-cache" + ''; + + nativeBuildInputs = [ + cmake + ninja + swift + ] + ++ lib.optionals stdenv.hostPlatform.isDarwin [ llvm_libtool ]; + + postInstall = '' + moveToOutput lib/swift "''${!outputDev}" + moveToOutput lib/swift_static "''${!outputDev}" + + # Install CMake config file for the Swift Argument Parser library. + mkdir -p "''${!outputDev}/lib/cmake/ArgumentParser" + substitute ${./files/ArgumentParserConfig.cmake} "''${!outputDev}/lib/cmake/ArgumentParser/ArgumentParserConfig.cmake" \ + --replace-fail '@buildType@' ${if stdenv.hostPlatform.isStatic then "STATIC" else "SHARED"} \ + --replace-fail '@include@' "''${!outputDev}" \ + --replace-fail '@lib@' "''${!outputLib}" \ + --replace-fail '@swiftPlatform@' ${swiftPlatform} + ''; + + passthru.updateScript = gitUpdater { }; + + __structuredAttrs = true; + + meta = { + homepage = "https://github.com/apple/swift-argument-parser"; + description = "Type-safe argument parsing for Swift"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-argument-parser/patches/0001-install-argument-parser-tool-info.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swift-argument-parser/patches/0001-install-argument-parser-tool-info.patch new file mode 100644 index 000000000000..d5e3859a79e9 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-argument-parser/patches/0001-install-argument-parser-tool-info.patch @@ -0,0 +1,22 @@ +From afdddf3098f0cd0a7340609950df4f9471a12c61 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 28 Feb 2026 13:32:37 -0500 +Subject: [PATCH] install-argument-parser-tool-info + +--- + Sources/ArgumentParserToolInfo/CMakeLists.txt | 1 + + 1 file changed, 1 insertion(+) + +diff --git a/Sources/ArgumentParserToolInfo/CMakeLists.txt b/Sources/ArgumentParserToolInfo/CMakeLists.txt +index b82adb7..478f89d 100644 +--- a/Sources/ArgumentParserToolInfo/CMakeLists.txt ++++ b/Sources/ArgumentParserToolInfo/CMakeLists.txt +@@ -7,4 +7,5 @@ target_compile_options(ArgumentParserToolInfo PRIVATE + $<$:-enable-testing>) + + ++_install_target(ArgumentParserToolInfo) + set_property(GLOBAL APPEND PROPERTY ArgumentParser_EXPORTS ArgumentParserToolInfo) +-- +2.51.2 + From 9d6002a9a156f9e683ba6001f4baa754bdb45d3c Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 200/423] swiftPackages_ng.swift-llbuild: init at 6.2.4 --- .../swift-llbuild/files/LLBuildConfig.cmake | 11 ++ .../by-name/sw/swift-llbuild/package.nix | 115 ++++++++++++++++++ .../patches/0001-gnu-install-dirs.patch | 61 ++++++++++ .../compilers/swift_ng/sources-6.2.json | 3 + 4 files changed, 190 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-llbuild/files/LLBuildConfig.cmake create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-llbuild/package.nix create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-llbuild/patches/0001-gnu-install-dirs.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-llbuild/files/LLBuildConfig.cmake b/pkgs/development/compilers/swift_ng/by-name/sw/swift-llbuild/files/LLBuildConfig.cmake new file mode 100644 index 000000000000..5b32819de214 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-llbuild/files/LLBuildConfig.cmake @@ -0,0 +1,11 @@ +add_library(llbuild STATIC IMPORTED) +set_target_properties(llbuild PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_STATIC_LIBRARY_PREFIX}llbuild${CMAKE_STATIC_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@dev@/include" +) + +add_library(llbuildSwift @buildType@ IMPORTED) +set_target_properties(llbuildSwift PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}llbuildSwift${CMAKE_@buildType@_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@dev@/include;@dev@/lib/swift/@swiftPlatform@" +) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-llbuild/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift-llbuild/package.nix new file mode 100644 index 000000000000..d53f28bb934d --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-llbuild/package.nix @@ -0,0 +1,115 @@ +{ + lib, + cmake, + fetchFromGitHub, + fixDarwinDylibNames, + ncurses, + ninja, + sqlite, + stdenv, + swift-corelibs-libdispatch, + swift-foundation, + swift-minimal, + swift_release, + swift_sources, +}: + +let + swiftPlatform = stdenv.hostPlatform.swift.platform; + # swift-llbuild requires Foundation and Dispatch. + swift = swift-minimal.override { inherit swift-corelibs-libdispatch swift-foundation; }; +in + +# LLBuild is a dependency to both Swift Compiler Driver and SwiftPM. +# It must be built with CMake and use Swift without swift-driver to avoid dependency cycles. +stdenv.mkDerivation (finalAttrs: { + pname = "swift-llbuild"; + version = swift_release; + + outputs = [ + "out" + "dev" + "lib" + ]; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-llbuild"; + tag = "swift-${finalAttrs.version}-RELEASE"; + inherit (swift_sources.swift-llbuild) hash; + }; + + patches = [ ./patches/0001-gnu-install-dirs.patch ]; + + postPatch = '' + # Disable performance tests, which require XCTest.framework. XCTest.framework is not available. + substituteInPlace CMakeLists.txt --replace-fail 'add_subdirectory(perftests)' "" + + # Disable building the framework on Darwin, which we don’t use. + substituteInPlace products/libllbuild/CMakeLists.txt \ + --replace-fail 'if(''${CMAKE_SYSTEM_NAME} MATCHES "Darwin")' "if(FALSE)" + + # Use ncurses instead of curses + grep -rl 'curses)' -Z | while IFS= read -d "" file; do + substituteInPlace "$file" --replace-fail 'curses)' 'ncurses)' + done + ''; + + strictDeps = true; + + cmakeFlags = [ + # Defaults to not building shared libs. + (lib.cmakeBool "BUILD_SHARED_LIBS" (!stdenv.hostPlatform.isStatic)) + # Swift bindings are needed to build swift-driver. + (lib.cmakeFeature "LLBUILD_SUPPORT_BINDINGS" "Swift") + ] + ++ lib.optionals stdenv.hostPlatform.isDarwin [ + # Defaults to the `buildPlatform` architecture if this is not set. + (lib.cmakeFeature "CMAKE_OSX_ARCHITECTURES" stdenv.hostPlatform.darwinArch) + ]; + + preConfigure = '' + appendToVar cmakeFlags -DCMAKE_Swift_COMPILER_TARGET=${stdenv.hostPlatform.swift.triple} + appendToVar cmakeFlags -DCMAKE_Swift_FLAGS=-module-cache-path\ "$NIX_BUILD_TOP/module-cache" + ''; + + nativeBuildInputs = [ + cmake + ninja + swift + ] + ++ lib.optionals stdenv.hostPlatform.isDarwin [ fixDarwinDylibNames ]; + + buildInputs = [ + ncurses + sqlite + ]; + + postInstall = '' + # Install the module map for the `llbuild` module. + mkdir -p "''${!outputDev}/include" + cp -v "$NIX_BUILD_TOP/$sourceRoot/products/libllbuild/include/module.modulemap" "''${!outputDev}/include" + + # Install the swiftmodule (needed to use `llbuildSwift`). + mkdir -p "''${!outputDev}/lib/swift/${swiftPlatform}" + cp -v products/llbuildSwift/llbuildSwift.swiftmodule "''${!outputDev}/lib/swift/${swiftPlatform}" + + # Install CMake config file for llbuild and llbuildSwift. + mkdir -p "''${!outputDev}/lib/cmake/LLBuild" + substitute ${./files/LLBuildConfig.cmake} "''${!outputDev}/lib/cmake/LLBuild/LLBuildConfig.cmake" \ + --replace-fail '@buildType@' ${if stdenv.hostPlatform.isStatic then "STATIC" else "SHARED"} \ + --replace-fail '@dev@' "''${!outputDev}" \ + --replace-fail '@lib@' "''${!outputLib}" \ + --replace-fail '@swiftPlatform@' ${swiftPlatform} + ''; + + __structuredAttrs = true; + + meta = { + homepage = "https://github.com/swiftlang/swift-llbuild"; + description = "Low-level build system used by SwiftPM and Xcode"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-llbuild/patches/0001-gnu-install-dirs.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swift-llbuild/patches/0001-gnu-install-dirs.patch new file mode 100644 index 000000000000..126c7a4ee6bd --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-llbuild/patches/0001-gnu-install-dirs.patch @@ -0,0 +1,61 @@ +From ff5456f94260823fb9c7f1af728123019b31dc3b Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 6 Dec 2025 20:09:51 -0500 +Subject: [PATCH] gnu-install-dirs + +--- + products/libllbuild/CMakeLists.txt | 10 +++++----- + products/llbuildSwift/CMakeLists.txt | 6 +++--- + 2 files changed, 8 insertions(+), 8 deletions(-) + +diff --git a/products/libllbuild/CMakeLists.txt b/products/libllbuild/CMakeLists.txt +index dcf5d40b..30db822d 100644 +--- a/products/libllbuild/CMakeLists.txt ++++ b/products/libllbuild/CMakeLists.txt +@@ -40,21 +40,21 @@ include_directories(BEFORE + ${CMAKE_CURRENT_SOURCE_DIR}/include) + + install(DIRECTORY include/ +- DESTINATION include ++ DESTINATION "${CMAKE_INSTALL_INCLUDEDIR}" + COMPONENT libllbuild + FILES_MATCHING + PATTERN "*.h") + + install(DIRECTORY ${CMAKE_CURRENT_BINARY_DIR}/include/ +- DESTINATION include ++ DESTINATION "${CMAKE_INSTALL_INCLUDEDIR}" + COMPONENT libllbuild + FILES_MATCHING + PATTERN "*.h") + + install(TARGETS libllbuild +- ARCHIVE DESTINATION lib${LLBUILD_LIBDIR_SUFFIX} +- LIBRARY DESTINATION lib${LLBUILD_LIBDIR_SUFFIX} +- RUNTIME DESTINATION bin ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}" + COMPONENT libllbuild) + set_property(GLOBAL APPEND PROPERTY LLBuild_EXPORTS libllbuild) + +diff --git a/products/llbuildSwift/CMakeLists.txt b/products/llbuildSwift/CMakeLists.txt +index fe12e7f3..cd0a4f64 100644 +--- a/products/llbuildSwift/CMakeLists.txt ++++ b/products/llbuildSwift/CMakeLists.txt +@@ -62,9 +62,9 @@ set_target_properties(llbuildSwift PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES "${CMAKE_CURRENT_BINARY_DIR};${PROJECT_SOURCE_DIR}/products/libllbuild/include") + + install(TARGETS llbuildSwift +- ARCHIVE DESTINATION lib/swift/pm/llbuild COMPONENT libllbuildSwift +- LIBRARY DESTINATION lib/swift/pm/llbuild COMPONENT libllbuildSwift +- RUNTIME DESTINATION bin COMPONENT libllbuildSwift) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" COMPONENT libllbuildSwift ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" COMPONENT libllbuildSwift ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}" COMPONENT libllbuildSwift) + set_property(GLOBAL APPEND PROPERTY LLBuild_EXPORTS llbuildSwift) + + # Add install target. +-- +2.51.2 + diff --git a/pkgs/development/compilers/swift_ng/sources-6.2.json b/pkgs/development/compilers/swift_ng/sources-6.2.json index 8099aa4ee4a5..d6a43456bf69 100644 --- a/pkgs/development/compilers/swift_ng/sources-6.2.json +++ b/pkgs/development/compilers/swift_ng/sources-6.2.json @@ -20,6 +20,9 @@ "swift-foundation-icu": { "hash": "sha256-C2rq5Q0F1id89mTN4+B/fKSvX1SEAf3/Zgvb/3IdsJ8=" }, + "swift-llbuild": { + "hash": "sha256-nZdiFXYrUiTSlSl6lxNFVpD2x8KGC4OVUUvJSOqH7gU=" + }, "swift-syntax": { "hash": "sha256-DMMVJQj590RGGBkTgA89u01ZP2B8kbJTmfu+oxzYPds=" } From e4bafb0eae15deda0ea02deac77f13a2597d888c Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 201/423] swiftPackages_ng.swift-tools-support-core: init at 6.2.4 --- .../files/TSCConfig.cmake | 11 ++ .../sw/swift-tools-support-core/package.nix | 100 ++++++++++++++++ .../0001-build-SwiftToolsSupport.patch | 108 ++++++++++++++++++ .../compilers/swift_ng/sources-6.2.json | 3 + 4 files changed, 222 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-tools-support-core/files/TSCConfig.cmake create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-tools-support-core/package.nix create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-tools-support-core/patches/0001-build-SwiftToolsSupport.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-tools-support-core/files/TSCConfig.cmake b/pkgs/development/compilers/swift_ng/by-name/sw/swift-tools-support-core/files/TSCConfig.cmake new file mode 100644 index 000000000000..aaf13a84c523 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-tools-support-core/files/TSCConfig.cmake @@ -0,0 +1,11 @@ +add_library(TSCBasic @buildType@ IMPORTED) +set_target_properties(TSCBasic PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}SwiftToolsSupport${CMAKE_@buildType@_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@dev@/include;@dev@/lib/swift/@swiftPlatform@" +) + +add_library(TSCUtility @buildType@ IMPORTED) +set_target_properties(TSCUtility PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}SwiftToolsSupport${CMAKE_@buildType@_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@dev@/include;@dev@/lib/swift/@swiftPlatform@" +) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-tools-support-core/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift-tools-support-core/package.nix new file mode 100644 index 000000000000..f1b7c717d239 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-tools-support-core/package.nix @@ -0,0 +1,100 @@ +{ + lib, + cmake, + fetchFromGitHub, + gitUpdater, + llvm_libtool, + ninja, + stdenv, + swift-corelibs-libdispatch, + swift-foundation, + swift-minimal, + swift_release, + swift_sources, +}: + +let + swiftPlatform = stdenv.hostPlatform.swift.platform; + # Swift Tools Support Core requires Dispatch and Foundation. + swift = swift-minimal.override { inherit swift-corelibs-libdispatch swift-foundation; }; +in + +stdenv.mkDerivation (finalAttrs: { + pname = "swift-tools-support-core"; + version = swift_release; + + outputs = [ + "out" + "dev" + ]; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-tools-support-core"; + tag = "swift-${finalAttrs.version}-RELEASE"; + inherit (swift_sources.swift-tools-support-core) hash; + }; + + patches = [ + # Match the dynamic library structure of the SwiftPM build when using CMake. + ./patches/0001-build-SwiftToolsSupport.patch + ]; + + postPatch = + # Disable using XCTest framework properties that aren’t provided by swift-corelibs-xctest. + '' + substituteInPlace "Sources/TSCTestSupport/XCTestCasePerf.swift" \ + --replace-fail '#if canImport(Darwin)' '#if false' + ''; + + strictDeps = true; + + preConfigure = '' + appendToVar cmakeFlags -DCMAKE_Swift_COMPILER_TARGET=${stdenv.hostPlatform.swift.triple} + appendToVar cmakeFlags -DCMAKE_Swift_FLAGS=-module-cache-path\ "$NIX_BUILD_TOP/module-cache" + ''; + + nativeBuildInputs = [ + cmake + ninja + swift + ] + ++ lib.optionals stdenv.hostPlatform.isDarwin [ llvm_libtool ]; + + postInstall = '' + # Install the swiftmodule. + mkdir -p "''${!outputDev}/lib/swift/${swiftPlatform}" + cp -v swift/*.swiftmodule "''${!outputDev}/lib/swift/${swiftPlatform}" + + # Install the C module + mkdir -p "''${!outputDev}/include" + cp -v ../Sources/TSCclibc/include/* "''${!outputDev}/include" + + # Install CMake config file for the SwiftSupportTools library. + mkdir -p "''${!outputDev}/lib/cmake/TSC" + substitute ${./files/TSCConfig.cmake} "''${!outputDev}/lib/cmake/TSC/TSCConfig.cmake" \ + --replace-fail '@buildType@' ${if stdenv.hostPlatform.isStatic then "STATIC" else "SHARED"} \ + --replace-fail '@dev@' "''${!outputDev}" \ + --replace-fail '@lib@' "''${!outputLib}" \ + --replace-fail '@swiftPlatform@' ${swiftPlatform} + '' + # These are not linked into the shared library and are linked separate only on Linux. + + lib.optionalString (!stdenv.hostPlatform.isDarwin) '' + libExt=${stdenv.hostPlatform.extensions.staticLibrary} + for libName in TSCBasic TSCLibc; do + cp -v lib/lib$libName$libExt "''${!outputLib}/lib/lib$libName$libExt" + done + ''; + + __structuredAttrs = true; + + passthru.updateScript = gitUpdater { }; + + meta = { + homepage = "https://github.com/swiftlang/swift-tools-support-core"; + description = "Common infrastructure code used by SwiftPM and llbuild"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-tools-support-core/patches/0001-build-SwiftToolsSupport.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swift-tools-support-core/patches/0001-build-SwiftToolsSupport.patch new file mode 100644 index 000000000000..e829a41f9263 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-tools-support-core/patches/0001-build-SwiftToolsSupport.patch @@ -0,0 +1,108 @@ +From 2e4200e2586b2389f2214506bfe5e06102060f15 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Mon, 8 Dec 2025 17:40:01 -0500 +Subject: [PATCH] build SwiftToolsSupport + +--- + Sources/TSCBasic/CMakeLists.txt | 7 +------ + Sources/TSCUtility/CMakeLists.txt | 25 +++++++++++++------------ + Sources/TSCclibc/CMakeLists.txt | 6 ++---- + 3 files changed, 16 insertions(+), 22 deletions(-) + +diff --git a/Sources/TSCBasic/CMakeLists.txt b/Sources/TSCBasic/CMakeLists.txt +index d8b85ea..ebb8cbe 100644 +--- a/Sources/TSCBasic/CMakeLists.txt ++++ b/Sources/TSCBasic/CMakeLists.txt +@@ -6,7 +6,7 @@ + # See http://swift.org/LICENSE.txt for license information + # See http://swift.org/CONTRIBUTORS.txt for Swift project authors + +-add_library(TSCBasic ++add_library(TSCBasic STATIC + Await.swift + ByteString.swift + CStringArray.swift +@@ -69,9 +69,4 @@ target_link_libraries(TSCBasic PRIVATE + set_target_properties(TSCBasic PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + +-install(TARGETS TSCBasic +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) +- + set_property(GLOBAL APPEND PROPERTY TSC_EXPORTS TSCBasic) +diff --git a/Sources/TSCUtility/CMakeLists.txt b/Sources/TSCUtility/CMakeLists.txt +index 8e0a232..78e4558 100644 +--- a/Sources/TSCUtility/CMakeLists.txt ++++ b/Sources/TSCUtility/CMakeLists.txt +@@ -6,7 +6,7 @@ + # See http://swift.org/LICENSE.txt for license information + # See http://swift.org/CONTRIBUTORS.txt for Swift project authors + +-add_library(TSCUtility ++add_library(SwiftToolsSupport + Archiver.swift + ArgumentParser.swift + ArgumentParserShellCompletion.swift +@@ -42,29 +42,30 @@ add_library(TSCUtility + dlopen.swift + misc.swift + ) +-target_link_libraries(TSCUtility PUBLIC +- TSCBasic) +-target_link_libraries(TSCUtility PRIVATE ++target_link_libraries(SwiftToolsSupport PUBLIC ++ $) ++target_link_libraries(SwiftToolsSupport PRIVATE + TSCclibc + ${CMAKE_DL_LIBS} + Threads::Threads) + + if(NOT CMAKE_SYSTEM_NAME STREQUAL Darwin) + if(CMAKE_SYSTEM_NAME STREQUAL OpenBSD OR CMAKE_SYSTEM_NAME STREQUAL FreeBSD) +- target_link_directories(TSCUtility PRIVATE /usr/local/lib) ++ target_link_directories(SwiftToolsSupport PRIVATE /usr/local/lib) + endif() + if(Foundation_FOUND) +- target_link_libraries(TSCUtility PUBLIC ++ target_link_libraries(SwiftToolsSupport PUBLIC + FoundationNetworking) + endif() + endif() + # NOTE(compnerd) workaround for CMake not setting up include flags yet +-set_target_properties(TSCUtility PROPERTIES ++set_target_properties(SwiftToolsSupport PROPERTIES ++ Swift_MODULE_NAME TSCUtility + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + +-install(TARGETS TSCUtility +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++install(TARGETS SwiftToolsSupport ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") + +-set_property(GLOBAL APPEND PROPERTY TSC_EXPORTS TSCUtility) ++set_property(GLOBAL APPEND PROPERTY TSC_EXPORTS SwiftToolsSupport) +diff --git a/Sources/TSCclibc/CMakeLists.txt b/Sources/TSCclibc/CMakeLists.txt +index e28860c..8048c24 100644 +--- a/Sources/TSCclibc/CMakeLists.txt ++++ b/Sources/TSCclibc/CMakeLists.txt +@@ -14,9 +14,7 @@ target_compile_definitions(TSCclibc PRIVATE + "$<$:_GNU_SOURCE>") + set_target_properties(TSCclibc PROPERTIES POSITION_INDEPENDENT_CODE YES) + +-if(NOT BUILD_SHARED_LIBS) +- install(TARGETS TSCclibc +- ARCHIVE DESTINATION lib) +-endif() ++install(TARGETS TSCclibc ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}") + + set_property(GLOBAL APPEND PROPERTY TSC_EXPORTS TSCclibc) +-- +2.51.2 + diff --git a/pkgs/development/compilers/swift_ng/sources-6.2.json b/pkgs/development/compilers/swift_ng/sources-6.2.json index d6a43456bf69..c913713fd7a3 100644 --- a/pkgs/development/compilers/swift_ng/sources-6.2.json +++ b/pkgs/development/compilers/swift_ng/sources-6.2.json @@ -25,5 +25,8 @@ }, "swift-syntax": { "hash": "sha256-DMMVJQj590RGGBkTgA89u01ZP2B8kbJTmfu+oxzYPds=" + }, + "swift-tools-support-core": { + "hash": "sha256-mV+z5sdG/maUzXUhK1vMtsnLCclcjqyXSMO6J2FjBEg=" } } From 3645468866661b9475edaad95de3d082428142e8 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 202/423] swiftPackages_ng.swift-driver: init at 6.2.4 --- .../files/SwiftDriverConfig.cmake | 5 + .../by-name/sw/swift-driver/package.nix | 125 ++++++++++++++++++ .../patches/0001-gnu-install-dirs.patch | 56 ++++++++ ...PM-products-when-building-with-CMake.patch | 59 +++++++++ .../0003-Search-PATH-for-subcommands.patch | 40 ++++++ ...-the-repl-find-the-stdlib-in-Nixpkgs.patch | 30 +++++ .../tests/not-in-toolchain/package.nix | 18 +++ .../tests/swift-not-on-path/package.nix | 10 ++ .../compilers/swift_ng/sources-6.2.json | 3 + 9 files changed, 346 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/files/SwiftDriverConfig.cmake create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/package.nix create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/patches/0001-gnu-install-dirs.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/patches/0002-Match-SwiftPM-products-when-building-with-CMake.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/patches/0003-Search-PATH-for-subcommands.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/patches/0004-Help-the-repl-find-the-stdlib-in-Nixpkgs.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/tests/not-in-toolchain/package.nix create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/tests/swift-not-on-path/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/files/SwiftDriverConfig.cmake b/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/files/SwiftDriverConfig.cmake new file mode 100644 index 000000000000..02cc584e3d9e --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/files/SwiftDriverConfig.cmake @@ -0,0 +1,5 @@ +add_library(SwiftDriver @buildType@ IMPORTED) +set_target_properties(SwiftDriver PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}SwiftDriver${CMAKE_@buildType@_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@dev@/lib/swift/@swiftPlatform@" +) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/package.nix new file mode 100644 index 000000000000..683e923f374d --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/package.nix @@ -0,0 +1,125 @@ +{ + lib, + callPackage, + cmake, + fetchFromGitHub, + llvm_libtool, + ninja, + stdenv, + swift-argument-parser, + swift-corelibs-libdispatch, + swift-foundation, + swift-llbuild, + swift-minimal, + swift-tools-support-core, + swift_release, + swift_sources, +}: + +let + swiftPlatform = stdenv.hostPlatform.swift.platform; + # Swift Driver requires Dispatch and Foundation. + swift = swift-minimal.override { inherit swift-corelibs-libdispatch swift-foundation; }; +in + +stdenv.mkDerivation (finalAttrs: { + pname = "swift-driver"; + version = swift_release; + + outputs = [ + "out" + "dev" + "lib" + ]; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-driver"; + tag = "swift-${finalAttrs.version}-RELEASE"; + inherit (swift_sources.swift-driver) hash; + }; + + patches = [ + ./patches/0001-gnu-install-dirs.patch + # Adjust the built libraries to match the way SwiftPM would build the Swift Compiler Driver. + ./patches/0002-Match-SwiftPM-products-when-building-with-CMake.patch + # Align Swift Driver’s subcommand lookup behavior with the legacy/C++ frontend. Nixpkgs needs this because it + # builds and installs SwiftPM separately from the rest of the Swift toolchain. Otherwise, `swift build` will fail. + ./patches/0003-Search-PATH-for-subcommands.patch + # The stdlib is located at the top-level `lib` folder in the toolchain in Nixpkgs. Help `swift repl` find it there. + ./patches/0004-Help-the-repl-find-the-stdlib-in-Nixpkgs.patch + ]; + + strictDeps = true; + + preConfigure = '' + appendToVar cmakeFlags -DCMAKE_Swift_COMPILER_TARGET=${stdenv.hostPlatform.swift.triple} + appendToVar cmakeFlags -DCMAKE_Swift_FLAGS=-module-cache-path\ "$NIX_BUILD_TOP/module-cache" + ''; + + nativeBuildInputs = [ + cmake + ninja + swift + ] + ++ lib.optionals stdenv.hostPlatform.isDarwin [ llvm_libtool ]; + + buildInputs = [ + swift-argument-parser + swift-llbuild + swift-tools-support-core + ]; + + env.NIX_LDFLAGS = lib.optionalString stdenv.hostPlatform.isDarwin "-headerpad_max_install_names"; + + postInstall = '' + mkdir -p "''${!outputDev}/lib/swift/${swiftPlatform}" "''${!outputLib}/lib" + + # Install the SwiftOptions static library (needed by Swift Build). + cp -v lib/libSwiftOptions.a "''${!outputLib}/lib" + + # Install the swiftmodule. + cp -v swift/*.swiftmodule "''${!outputDev}/lib/swift/${swiftPlatform}" + + # Install CMake config file for the Swift Compiler Driver library. + mkdir -p "''${!outputDev}/lib/cmake/SwiftDriver" + substitute ${./files/SwiftDriverConfig.cmake} "''${!outputDev}/lib/cmake/SwiftDriver/SwiftDriverConfig.cmake" \ + --replace-fail '@buildType@' ${if stdenv.hostPlatform.isStatic then "STATIC" else "SHARED"} \ + --replace-fail '@dev@' "''${!outputDev}" \ + --replace-fail '@lib@' "''${!outputLib}" \ + --replace-fail '@swiftPlatform@' ${swiftPlatform} + '' + # For some reason, these rpaths get dropped during installation phase on Linux. + + lib.optionalString stdenv.hostPlatform.isLinux '' + for f in "$out/bin/"* "$lib/lib/"*; do + if isELF "$f"; then + patchelf --add-rpath ${ + lib.escapeShellArg ( + lib.makeLibraryPath [ + swift-argument-parser + swift-tools-support-core + swift-llbuild + ] + ) + } "$f" + patchelf --force-rpath "$f" # Otherwise, libswiftSynchronization.so won’t be found. + fi + done + ''; + + __structuredAttrs = true; + + passthru.tests = lib.packagesFromDirectoryRecursive { + inherit callPackage; + directory = ./tests; + }; + + meta = { + mainProgram = "swift-driver"; + homepage = "https://github.com/swiftlang/swift-driver"; + description = "Swift compiler driver written in Swift"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/patches/0001-gnu-install-dirs.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/patches/0001-gnu-install-dirs.patch new file mode 100644 index 000000000000..c9dc0c73c8ac --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/patches/0001-gnu-install-dirs.patch @@ -0,0 +1,56 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Mon, 7 Sep 2026 19:24:07 -0400 +Subject: [PATCH 1/4] gnu-install-dirs + +--- + Sources/SwiftDriver/CMakeLists.txt | 6 +++--- + Sources/SwiftDriverExecution/CMakeLists.txt | 6 +++--- + Sources/SwiftOptions/CMakeLists.txt | 6 +++--- + 3 files changed, 9 insertions(+), 9 deletions(-) + +diff --git a/Sources/SwiftDriver/CMakeLists.txt b/Sources/SwiftDriver/CMakeLists.txt +index d6594845..fb30f2bf 100644 +--- a/Sources/SwiftDriver/CMakeLists.txt ++++ b/Sources/SwiftDriver/CMakeLists.txt +@@ -140,6 +140,6 @@ set_target_properties(SwiftDriver PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + + install(TARGETS SwiftDriver +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/SwiftDriverExecution/CMakeLists.txt b/Sources/SwiftDriverExecution/CMakeLists.txt +index c42a4dec..91c9bc12 100644 +--- a/Sources/SwiftDriverExecution/CMakeLists.txt ++++ b/Sources/SwiftDriverExecution/CMakeLists.txt +@@ -26,6 +26,6 @@ set_target_properties(SwiftDriverExecution PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + + install(TARGETS SwiftDriverExecution +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/SwiftOptions/CMakeLists.txt b/Sources/SwiftOptions/CMakeLists.txt +index c6262682..d4dbbcc3 100644 +--- a/Sources/SwiftOptions/CMakeLists.txt ++++ b/Sources/SwiftOptions/CMakeLists.txt +@@ -25,6 +25,6 @@ set_target_properties(SwiftOptions PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + + install(TARGETS SwiftOptions +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/patches/0002-Match-SwiftPM-products-when-building-with-CMake.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/patches/0002-Match-SwiftPM-products-when-building-with-CMake.patch new file mode 100644 index 000000000000..5260a2d00025 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/patches/0002-Match-SwiftPM-products-when-building-with-CMake.patch @@ -0,0 +1,59 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Mon, 7 Sep 2026 19:24:08 -0400 +Subject: [PATCH 2/4] Match SwiftPM products when building with CMake + +Adjust the built libraries to match the way SwiftPM would build the +Swift Compiler Driver. +--- + Sources/SwiftDriverExecution/CMakeLists.txt | 7 +------ + Sources/SwiftOptions/CMakeLists.txt | 7 +------ + 2 files changed, 2 insertions(+), 12 deletions(-) + +diff --git a/Sources/SwiftDriverExecution/CMakeLists.txt b/Sources/SwiftDriverExecution/CMakeLists.txt +index 91c9bc12..17adca61 100644 +--- a/Sources/SwiftDriverExecution/CMakeLists.txt ++++ b/Sources/SwiftDriverExecution/CMakeLists.txt +@@ -6,7 +6,7 @@ + # See http://swift.org/LICENSE.txt for license information + # See http://swift.org/CONTRIBUTORS.txt for Swift project authors + +-add_library(SwiftDriverExecution ++add_library(SwiftDriverExecution STATIC + llbuild.swift + MultiJobExecutor.swift + SwiftDriverExecutor.swift) +@@ -24,8 +24,3 @@ set_property(GLOBAL APPEND PROPERTY SWIFTDRIVER_EXPORTS SwiftDriverExecution) + # NOTE: workaround for CMake not setting up include flags yet + set_target_properties(SwiftDriverExecution PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) +- +-install(TARGETS SwiftDriverExecution +- ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" +- LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" +- RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/SwiftOptions/CMakeLists.txt b/Sources/SwiftOptions/CMakeLists.txt +index d4dbbcc3..4dea39d6 100644 +--- a/Sources/SwiftOptions/CMakeLists.txt ++++ b/Sources/SwiftOptions/CMakeLists.txt +@@ -6,7 +6,7 @@ + # See http://swift.org/LICENSE.txt for license information + # See http://swift.org/CONTRIBUTORS.txt for Swift project authors + +-add_library(SwiftOptions ++add_library(SwiftOptions STATIC + DriverKind.swift + Option.swift + OptionTable.swift +@@ -23,8 +23,3 @@ set_property(GLOBAL APPEND PROPERTY SWIFTDRIVER_EXPORTS SwiftOptions) + # NOTE: workaround for CMake not setting up include flags yet + set_target_properties(SwiftOptions PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) +- +-install(TARGETS SwiftOptions +- ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" +- LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" +- RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/patches/0003-Search-PATH-for-subcommands.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/patches/0003-Search-PATH-for-subcommands.patch new file mode 100644 index 000000000000..d2abcc88a979 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/patches/0003-Search-PATH-for-subcommands.patch @@ -0,0 +1,40 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Mon, 7 Sep 2026 19:24:08 -0400 +Subject: [PATCH 3/4] Search PATH for subcommands +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +This aligns Swift Driver with the legacy/C++ frontend’s behavior when +searching for subcommands. +--- + Sources/swift-driver/main.swift | 9 +++------ + 1 file changed, 3 insertions(+), 6 deletions(-) + +diff --git a/Sources/swift-driver/main.swift b/Sources/swift-driver/main.swift +index d34ee811..ea3f5607 100644 +--- a/Sources/swift-driver/main.swift ++++ b/Sources/swift-driver/main.swift +@@ -120,15 +120,12 @@ do { + if case .subcommand(let subcommand) = mode { + // We are running as a subcommand, try to find the subcommand adjacent to the executable we are running as. + // If we didn't find the tool there, let the OS search for it. +- let subcommandPath: AbsolutePath? +- if let executablePath = Process.findExecutable(CommandLine.arguments[0]) { ++ let executablePath = try Process.findExecutable(ProcessInfo.processInfo.arguments[0]).map { + // Attempt to resolve the executable symlink in order to be able to + // resolve compiler-adjacent library locations. +- subcommandPath = try TSCBasic.resolveSymlinks(executablePath).parentDirectory.appending(component: subcommand) +- } else { +- subcommandPath = Process.findExecutable(subcommand) ++ try TSCBasic.resolveSymlinks($0).parentDirectory + } +- ++ let subcommandPath = Process.findExecutable(subcommand, workingDirectory: executablePath) + guard let subcommandPath = subcommandPath, + localFileSystem.exists(subcommandPath) else { + throw Driver.Error.unknownOrMissingSubcommand(subcommand, nil) +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/patches/0004-Help-the-repl-find-the-stdlib-in-Nixpkgs.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/patches/0004-Help-the-repl-find-the-stdlib-in-Nixpkgs.patch new file mode 100644 index 000000000000..eab86d85e61d --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/patches/0004-Help-the-repl-find-the-stdlib-in-Nixpkgs.patch @@ -0,0 +1,30 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Mon, 7 Sep 2026 19:24:08 -0400 +Subject: [PATCH 4/4] Help the repl find the stdlib in Nixpkgs + +The stdlib is located at `lib` instead of `lib/swift/`, but +`swift repl` only searches the latter for it. +--- + Sources/SwiftDriver/Jobs/ReplJob.swift | 5 +++++ + 1 file changed, 5 insertions(+) + +diff --git a/Sources/SwiftDriver/Jobs/ReplJob.swift b/Sources/SwiftDriver/Jobs/ReplJob.swift +index e7ff7999..d3f75ff2 100644 +--- a/Sources/SwiftDriver/Jobs/ReplJob.swift ++++ b/Sources/SwiftDriver/Jobs/ReplJob.swift +@@ -25,6 +25,11 @@ extension Driver { + ) + try commandLine.appendAll(.framework, .L, from: &parsedOptions) + ++ // Nixpkgs puts Swift libraries in `lib` instead of `lib/swift/`. Help `swift repl` find the stdlib there. ++ let toolchainPath = try toolchain.resolvedTool(.swiftCompiler).path.parentDirectory.parentDirectory ++ let libPath = toolchainPath.appending(component: "lib") ++ commandLine.append(contentsOf: [.flag("-L"), .path(.absolute(libPath))]) ++ + // Squash important frontend options into a single argument for LLDB. + let lldbCommandLine: [Job.ArgTemplate] = [.squashedArgumentList(option: "--repl=", args: commandLine)] + return Job( +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/tests/not-in-toolchain/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/tests/not-in-toolchain/package.nix new file mode 100644 index 000000000000..8c90fc510197 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/tests/not-in-toolchain/package.nix @@ -0,0 +1,18 @@ +{ + runCommand, + swift, + swiftpm, + swift_release, +}: + +runCommand "swift-driver-test-not-in-toolchain" + { + nativeBuildInputs = [ + swift + swiftpm + ]; + } + '' + swift package --version | grep "Swift Package Manager - Swift ${swift_release}" + touch "$out" + '' diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/tests/swift-not-on-path/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/tests/swift-not-on-path/package.nix new file mode 100644 index 000000000000..bebce0932044 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/tests/swift-not-on-path/package.nix @@ -0,0 +1,10 @@ +{ + lib, + runCommand, + swift, +}: + +runCommand "swift-driver-test-swift-not-on-path" { } '' + PATH= ${lib.getExe swift} help --help | grep "USAGE: swift-help" + touch "$out" +'' diff --git a/pkgs/development/compilers/swift_ng/sources-6.2.json b/pkgs/development/compilers/swift_ng/sources-6.2.json index c913713fd7a3..87d0e53f4e5a 100644 --- a/pkgs/development/compilers/swift_ng/sources-6.2.json +++ b/pkgs/development/compilers/swift_ng/sources-6.2.json @@ -11,6 +11,9 @@ "swift-corelibs-libdispatch": { "hash": "sha256-Tu2G9FAP4q1xgM1n9q17T6VrqJ3tv8RezyUex38yNds=" }, + "swift-driver": { + "hash": "sha256-CZYqUadpAsAUnCTZElobZS9nlMfCuHiMnac3o0k7hnI=" + }, "swift-experimental-string-processing": { "hash": "sha256-WtLLqdvYTmLWSS5q42b8yXFrJcC+dUy4uTuCeIflRFs=" }, From ed25aa9d7cdb13c735054fc62b54c9856ab001e4 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 203/423] swiftPackages_ng.swift: include the Swift compiler driver in the toolchain --- .../swift_ng/by-name/sw/swift/package.nix | 16 +++++++++++++++- pkgs/top-level/swift-packages.nix | 11 +++++++++++ 2 files changed, 26 insertions(+), 1 deletion(-) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix index 1ab3aaf5676e..b090cfe4203f 100644 --- a/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix @@ -6,6 +6,7 @@ stdenv, swift-corelibs-foundation, swift-corelibs-libdispatch, + swift-driver, swift-foundation, swift-foundation-icu, swiftc, @@ -28,6 +29,11 @@ let swiftc.out swiftc.dev ] + ++ lib.optionals (swift-driver != null) [ + swift-driver.out + swift-driver.dev + swift-driver.lib + ] ++ lib.optionals (stdenv.hostPlatform.isDarwin && swift-foundation != null) [ # Needed for FoundationMacros, which is otherwise not part of the SDK on Darwin. swift-foundation.out @@ -125,6 +131,14 @@ stdenv.mkDerivation (finalAttrs: { fi done + # Make sure `swift` and `swiftc` point to `swift-driver` if present. + if [ -e "$out/bin/swift-driver" ]; then + for exe in swift swiftc; do + rm -f "$out/bin/$exe" + ln -s swift-driver "$out/bin/$exe" + done + fi + # Propagated inputs in `$dev/nix-support` have to be substituted to use this derivation instead of swiftc. for f in "$out/nix-support/"*; do orig=$(readlink "$f") @@ -147,7 +161,7 @@ stdenv.mkDerivation (finalAttrs: { __structuredAttrs = true; passthru = { - inherit swiftc; + inherit swiftc swift-driver; }; meta = { diff --git a/pkgs/top-level/swift-packages.nix b/pkgs/top-level/swift-packages.nix index 01e9da472dcb..5f053304fae6 100644 --- a/pkgs/top-level/swift-packages.nix +++ b/pkgs/top-level/swift-packages.nix @@ -23,8 +23,18 @@ let swift-corelibs-libdispatch = null; swift-foundation = null; } + # Swift Driver is required when building the compiler’s Swift Syntax in the final toolchain. + # Otherwise, symbols are stripped from it that are needed to build Swift Testing. + // lib.optionalAttrs (bootstrapStage == 0) { + swift-driver = null; + } ); } + // lib.optionalAttrs (bootstrapStage != 2) { + swift-driver = prev.swift-driver.overrideAttrs (old: { + pname = "early-${old.pname}"; + }); + } // lib.optionalAttrs (swift_release != null) { inherit swift_release; } // lib.optionalAttrs (swift_sources != null) { inherit swift_sources; } ); @@ -80,6 +90,7 @@ makeScopeWithSplicing' { swift-minimal = self.swift.override { swift-corelibs-libdispatch = null; + swift-driver = null; swift-foundation = null; }; From fc73c0ba797c16776d4de6917738a37c2689c745 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 204/423] swiftPackages_ng.stdlib: init at 6.2.4 The Swift stdlib is normally built with the compiler, but we build it separately to keep the closure size down of Swift-using programs and to support cross-compilation in the future. --- .../swift_ng/by-name/st/stdlib/package.nix | 114 ++++++++++++++++++ .../swift_ng/by-name/sw/swiftc/package.nix | 1 + 2 files changed, 115 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/st/stdlib/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/st/stdlib/package.nix b/pkgs/development/compilers/swift_ng/by-name/st/stdlib/package.nix new file mode 100644 index 000000000000..be9c1cf8fdd5 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/st/stdlib/package.nix @@ -0,0 +1,114 @@ +{ + lib, + llvmPackages_upstream, + stdenv, + swiftc, +}: + +let + swiftPlatform = stdenv.hostPlatform.swift.platform; + libraryExtension = stdenv.hostPlatform.extensions.library; + + toolLTO = lib.cmakeFeature "SWIFT_TOOLS_ENABLE_LTO" "thin"; +in +(swiftc.override { + stdlib = null; + swiftComponents = [ + "back-deployment" + "sdk-overlay" + "static-mirror-lib" + "swift-remote-mirror" + "swift-remote-mirror-headers" + "stdlib" + ]; +}).overrideAttrs + (old: { + pname = "stdlib"; + + outputs = [ + "out" + "dev" + ]; + + cmakeFlags = + # Only enable LTO for the stdlib. Remove it if it’s enabled for the tools. + (lib.filter (flag: flag != toolLTO) (old.cmakeFlags or [ ])) + # LTO is slow (and pointless due to using system libraries) on Darwin, so only enable it for other platforms. + ++ lib.optionals (!stdenv.hostPlatform.isDarwin) [ + (lib.cmakeFeature "SWIFT_STDLIB_ENABLE_LTO" "thin") + ]; + + postInstall = '' + moveToOutput "lib/swift/${swiftPlatform}" "''${!outputLib}" + + # Static libraries, Swift modules, and shims are only needed for development. + moveToOutput "lib/swift/${swiftPlatform}/*.swiftmodule" "''${!outputDev}" + moveToOutput "lib/swift/_InternalSwiftStaticMirror" "''${!outputDev}" + moveToOutput "lib/swift/embedded" "''${!outputDev}" + moveToOutput "lib/swift/module.modulemap" "''${!outputDev}" + moveToOutput "lib/swift/shims" "''${!outputDev}" + moveToOutput "lib/swift_static" "''${!outputDev}" + + # Move libraries out of `lib/swift/`, so ld-wrapper will find them automatically. + mv -v "''${!outputLib}/lib/swift/${swiftPlatform}"/*${libraryExtension} "''${!outputLib}/lib" + + # Install C++ interop libraries and headers + cp -v lib/swift/${swiftPlatform}/libswiftCxx*${stdenv.hostPlatform.extensions.staticLibrary} "''${!outputDev}/lib" + cp -rv lib/swift/${swiftPlatform}/Cxx*.swiftmodule "''${!outputDev}/lib/swift/${swiftPlatform}" + + mkdir -p "''${!outputDev}/include/swiftToCxx" + cp -v ../lib/PrintAsClang/{_SwiftCxxInteroperability.h,_SwiftStdlibCxxOverlay.h,experimental-interoperability-version.json} \ + "''${!outputDev}/include/swiftToCxx" + cp -v lib/swift/${swiftPlatform}/libcxx* "''${!outputDev}/lib/swift/${swiftPlatform}" + '' + # libstdc++ does not come with a modulemap. It needs one provided by Swift. + + lib.optionalString (stdenv.cc.libcxx == null) '' + moveToOutput "lib/swift/${swiftPlatform}/libstdcxx.*" "''${!outputDev}" + '' + # Linux has some extra development files that need moved to $dev + + lib.optionalString stdenv.hostPlatform.isLinux '' + moveToOutput lib/swift/${swiftPlatform}/${stdenv.hostPlatform.swift.arch} "''${!outputDev}" + '' + # Convert LLVM bitcode files into native code to avoid requiring LTO for C++ interop. + + lib.optionalString stdenv.hostPlatform.isElf '' + ${lib.escapeShellArg (lib.getExe' llvmPackages_upstream.llvm "llc")} stdlib/public/Cxx/${lib.toUpper stdenv.hostPlatform.swift.platform}/${stdenv.hostPlatform.swift.arch}/Cxx.o -o Cxx.o -filetype=obj + "$AR" Drs "''${!outputDev}/lib/libswiftCxx.a" Cxx.o + ${lib.escapeShellArg (lib.getExe' llvmPackages_upstream.llvm "llc")} stdlib/public/Cxx/std/${lib.toUpper stdenv.hostPlatform.swift.platform}/${stdenv.hostPlatform.swift.arch}/CxxStdlib.o -o CxxStdlib.o -filetype=obj + "$AR" Drs "''${!outputDev}/lib/libswiftCxxStdlib.a" CxxStdlib.o + '' + + lib.optionalString stdenv.hostPlatform.isDarwin '' + # Back-deployment libraries are installed as part of the compiler component, so install them manually. + cp -rv lib/swift/macosx/libswiftCompatibility*.a "''${!outputDev}/lib" + + # Install `Span`-compatibility back-deployment library. + mkdir -p "''${!outputLib}/lib/swift-6.2/macosx" + cp -v lib/swift-6.2/macosx/libswiftCompatibilitySpan.dylib "''${!outputLib}/lib/swift-6.2/macosx/libswiftCompatibilitySpan.dylib" + + # macOS 26.4 dropped the Swift Differentiation dylibs. Use the one in the store instead of `/usr/lib/swift`. + install_name_tool "''${!outputLib}/lib/libswift_Differentiation.dylib" -id "''${!outputLib}/lib/libswift_Differentiation.dylib" + + # Generate text-based stubs for the stdlib. Darwin links against the system library, so they aren’t necessary. + for dylib in "''${!outputLib}/lib/"*.dylib; do + dylibName=$(basename "$dylib" .dylib) + if [ "$dylibName" = "libswiftCompatibilitySpan" ]; then + # Follow the SDK, which symlinks `libswiftCompatibilitySpan.tbd` to `libswiftCore.tbd`. + ln -s libswiftCore.tbd "''${!outputDev}/lib/$dylibName.tbd" + else + ${lib.escapeShellArg (lib.getExe' llvmPackages_upstream.llvm "llvm-readtapi")} --filetype=tbd-v4 \ + "$dylib" -o "''${!outputDev}/lib/$dylibName.tbd" + fi + if [ "$dylibName" != "libswift_Differentiation" ]; then + rm "$dylib" + fi + done + + # The linker should be using the stubs in $dev, which will reference the dylibs in $lib. + # There’s no need to propagate it on Darwin. + rm -rf "''${!outputDev}/nix-support" + + # Clean up empty folders. + rmdir "''${!outputLib}/lib/swift/${swiftPlatform}" "''${!outputLib}/lib/swift" + ''; + + postFixup = null; + }) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/package.nix index 3a2f7d325177..d661cf71fa64 100644 --- a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/package.nix +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/package.nix @@ -19,6 +19,7 @@ replaceVars, srcOnly, stdenv, + stdlib, swift-cmark, swift-corelibs-libdispatch, swift-syntax, From 4eba26cb252829d19476d7fea04cb178e4963da6 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 205/423] swiftPackages_ng.swift: include the stdlib in the toolchain --- .../swift_ng/by-name/sw/swift/package.nix | 21 +++++++++++++ .../swift_ng/by-name/sw/swift/setup-hook.sh | 30 +++++++++++++++++++ pkgs/top-level/swift-packages.nix | 1 + 3 files changed, 52 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift/setup-hook.sh diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix index b090cfe4203f..5216918eec0f 100644 --- a/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix @@ -3,7 +3,9 @@ apple-sdk_14, apple-sdk_26, llvmPackages_upstream, + patchelf, stdenv, + stdlib, swift-corelibs-foundation, swift-corelibs-libdispatch, swift-driver, @@ -29,6 +31,11 @@ let swiftc.out swiftc.dev ] + ++ lib.optionals (stdlib != null) [ + stdlib.dev + stdlib.out + swiftc.dev + ] ++ lib.optionals (swift-driver != null) [ swift-driver.out swift-driver.dev @@ -87,6 +94,10 @@ stdenv.mkDerivation (finalAttrs: { # Will effectively be `buildInputs` when swift is put in `nativeBuildInputs`. depsTargetTargetPropagated = lib.optionals stdenv.targetPlatform.isDarwin [ propagated-sdk ] + ++ lib.optionals (stdlib != null) [ + # Propagate the stdlib to make sure the linker wrapper will pick up the dynamic and static libraries. + stdlib + ] ++ lib.optionals (!stdenv.hostPlatform.isDarwin) ( lib.optionals (swift-corelibs-libdispatch != null) [ swift-corelibs-libdispatch-no-overlay.out @@ -152,6 +163,16 @@ stdenv.mkDerivation (finalAttrs: { recordPropagatedDependencies + ${lib.optionalString (stdlib != null) '' + # Can’t use `replaceVars` because it needs to substitute $out. + substitute ${./setup-hook.sh} "$out/nix-support/setup-hook" \ + --replace-fail @patchelf@ ${lib.escapeShellArg (lib.getExe patchelf)} \ + --replace-fail @objdump@ ${lib.escapeShellArg (lib.getExe' llvmPackages_upstream.llvm "llvm-objdump")} \ + --replace-fail @install_name_tool@ ${lib.escapeShellArg (lib.getExe' llvmPackages_upstream.llvm "llvm-install-name-tool")} \ + --replace-fail @stdlibPath@ ${lib.escapeShellArg stdlib.out} \ + --replace-fail @swiftPath@ "$out" \ + --replace-fail @swiftPlatform@ ${stdenv.hostPlatform.swift.platform} + ''} chmod -R u-w "$out/bin" "$out/lib" "$out/nix-support" # Have to invoke manually because of `buildCommand`. diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/setup-hook.sh b/pkgs/development/compilers/swift_ng/by-name/sw/swift/setup-hook.sh new file mode 100644 index 000000000000..1d82805dab7b --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift/setup-hook.sh @@ -0,0 +1,30 @@ +fixSwiftRpathsIn() { + local dir=$1 + + local swiftPath=@swiftPath@/lib + local swiftPathForPlatform=@swiftPath@/lib/swift/@swiftPlatform@ + local stdlibPath=@stdlibPath@/lib + + local f + while IFS= read -d "" f; do + if LC_ALL=C isMachO "$f"; then + IFS= readarray -d $'\n' -t rpaths < <(@objdump@ --macho --rpaths "$f" | tail -n +2) + for oldPath in "${rpaths[@]}"; do + local newPath=${oldPath/$swiftPathForPlatform/$stdlibPath} + newPath=${newPath/$swiftPath/$stdlibPath} + if [ "$newPath" != "$oldPath" ]; then + @install_name_tool@ "$f" -rpath "$oldPath" "$newPath" + fi + done + elif isELF "$f"; then + local oldRpaths=$(@patchelf@ --print-rpath "$f") + local newRpaths=${oldRpaths/$swiftPathForPlatform/$stdlibPath} + newRpaths=${newRpaths/$swiftPath/$stdlibPath} + if [ "$newRpaths" != "$oldRpaths" ]; then + @patchelf@ --set-rpath "$newRpaths" "$f" + fi + fi + done < <(find "$dir" -type f -print0) +} + +fixupOutputHooks+=('fixSwiftRpathsIn $prefix') diff --git a/pkgs/top-level/swift-packages.nix b/pkgs/top-level/swift-packages.nix index 5f053304fae6..6a52a8b5fa7c 100644 --- a/pkgs/top-level/swift-packages.nix +++ b/pkgs/top-level/swift-packages.nix @@ -31,6 +31,7 @@ let ); } // lib.optionalAttrs (bootstrapStage != 2) { + stdlib = null; # Have the bootstrap compiler use its own build of the stdlib. swift-driver = prev.swift-driver.overrideAttrs (old: { pname = "early-${old.pname}"; }); From e904858c8d4f933d14866035ea5c02a15b1b54a0 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 206/423] swiftPackages_ng.swiftc: init stage 2 at 6.2.4 The stage 2 compiler is the full compiler with LTO optimizations and all features enabled. It is linked against the separate stdlib. --- .../swift_ng/by-name/sw/swiftc/package.nix | 84 ++++++++++++++++++- pkgs/top-level/swift-packages.nix | 11 ++- 2 files changed, 89 insertions(+), 6 deletions(-) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/package.nix index d661cf71fa64..6791d4a5a96d 100644 --- a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/package.nix +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/package.nix @@ -1,6 +1,7 @@ { lib, apple-sdk_14, + apple-sdk_26, bootstrapStage, buildSwiftPackages, cmake, @@ -48,6 +49,8 @@ "toolchain-dev-tools" "toolchain-tools" # "tools" + ] + ++ lib.optionals (stdlib == null) [ "back-deployment" "sdk-overlay" "static-mirror-lib" @@ -58,9 +61,19 @@ }: let - build-sdk = apple-sdk_14; + # SDK versions past 14.x don’t work with the c++-based bootstrap compiler due to unconditionally exposing macros. + build-sdk = if bootstrapStage == 2 then apple-sdk_26 else apple-sdk_14; - swift = buildSwiftPackages.swift; + # `buildSwiftPackages` is always the previous stage. Building the stage 2 compiler requires linking against the + # separately built stdlib because it does not build its own. Override the stage 1 compiler to use it. + # Otherwise, packages with macros will fail to build with missing symbols in Swift Syntax. + swift = + if bootstrapStage == 2 then + buildSwiftPackages.swift.override { inherit stdlib; } + else + buildSwiftPackages.swift; + + swift-driver = swift.swift-driver or null; inherit (llvmPackages) clang @@ -73,12 +86,16 @@ let inherit (darwin) sigtool; + doCheck = false; # TODO: Implement tests per https://github.com/swiftlang/swift/blob/main/docs/Testing.md. + dylibExt = stdenv.hostPlatform.extensions.sharedLibrary; isNotSwiftSyntax = if bootstrapStage == 0 then c: !lib.hasInfix "swift-syntax" c else _: true; swiftComponents' = lib.filter isNotSwiftSyntax swiftComponents; + swiftPlatform = stdenv.hostPlatform.swift.platform; + srcs = { swift-experimental-string-processing = fetchFromGitHub { owner = "swiftlang"; @@ -230,7 +247,7 @@ stdenv.mkDerivation (finalAttrs: { (lib.cmakeFeature "SWIFT_DARWIN_DEPLOYMENT_VERSION_OSX" stdenv.hostPlatform.darwinMinVersion) (lib.cmakeFeature "SWIFT_HOST_TRIPLE" stdenv.hostPlatform.swift.triple) # Tests should only be built when building a regular compiler. The bootstrap compiler is not functional enough. - (lib.cmakeBool "SWIFT_INCLUDE_TESTS" false) + (lib.cmakeBool "SWIFT_INCLUDE_TESTS" doCheck) # Swift Concurrency is needed to build the stage 1 compiler on Linux. (lib.cmakeBool "SWIFT_ENABLE_EXPERIMENTAL_CONCURRENCY" true) ] @@ -246,7 +263,36 @@ stdenv.mkDerivation (finalAttrs: { (lib.cmakeBool "SWIFT_ENABLE_EXPERIMENTAL_STRING_PROCESSING" true) # Synchronization is required to build Foundation. (lib.cmakeBool "SWIFT_ENABLE_SYNCHRONIZATION" true) - ]; + ] + ++ lib.optionals (bootstrapStage >= 2) ( + [ + # Build Swift with LTO for better performance. Only enable it for tools. The stdlib will enable it separately. + (lib.cmakeFeature "SWIFT_TOOLS_ENABLE_LTO" "thin") + # LTO is slow with ld64. Only use it for targets that benefit from LTO. + (lib.cmakeBool "SWIFT_TOOLS_LD64_LTO_CODEGEN_ONLY_FOR_SUPPORTING_TARGETS" stdenv.hostPlatform.isDarwin) + # Enable the remaining features. + (lib.cmakeBool "SWIFT_ENABLE_BACKTRACING" true) + (lib.cmakeBool "SWIFT_ENABLE_EXPERIMENTAL_CXX_INTEROP" true) + (lib.cmakeBool "SWIFT_ENABLE_EXPERIMENTAL_DIFFERENTIABLE_PROGRAMMING" true) + (lib.cmakeBool "SWIFT_ENABLE_EXPERIMENTAL_DISTRIBUTED" true) + (lib.cmakeBool "SWIFT_ENABLE_EXPERIMENTAL_PARSER_VALIDATION" true) + (lib.cmakeBool "SWIFT_ENABLE_EXPERIMENTAL_POINTER_BOUNDS" true) + (lib.cmakeBool "SWIFT_ENABLE_EXPERIMENTAL_RUNTIME_MODULE" true) + (lib.cmakeBool "SWIFT_ENABLE_VOLATILE" true) + (lib.cmakeBool "SWIFT_ENABLE_RUNTIME_MODULE" true) + (lib.cmakeBool "SWIFT_STDLIB_ENABLE_STRICT_AVAILABILITY" true) + ] + ++ lib.optionals stdenv.cc.bintools.isGNU [ + # Use `llvm-ar` and `llvm-ranlib` when LTO is enabled, or builds will fail due missing symbol tables in archives. + # e.g., `error: lib/libswiftDemangling.a: no archive symbol table (run ranlib)`. + (lib.cmakeFeature "CMAKE_AR" (lib.getExe' llvm "llvm-ar")) + (lib.cmakeFeature "CMAKE_RANLIB" (lib.getExe' llvm "llvm-ranlib")) + # Make sure Swift is built with a consistent toolchan version. This doesn’t matter for non-LTO builds, but it causes + # LTO builds to fail when objects built with a newer Clang are processed by the Swift Clang’s libLTO. + (lib.cmakeFeature "CMAKE_C_COMPILER" (lib.getExe' clang "clang")) + (lib.cmakeFeature "CMAKE_CXX_COMPILER" (lib.getExe' clang "clang++")) + ] + ); env = { # Swift uses `-apple.macosx` triples instead of `-apple-darwin`, which causes tons of warnings. @@ -254,6 +300,9 @@ stdenv.mkDerivation (finalAttrs: { NIX_CFLAGS_COMPILE = toString ( # Swift compiles some of its stdlib for older deployment targets without using availability checks. [ "-Wno-error=unguarded-availability" ] + # Enable fat LTO (ELF only). This allows the compiler and stdlib to built with LTO while not requiring + # dependent packages to require a linker plugin to read the LLVM bitcode. + ++ lib.optionals (bootstrapStage == 2 && stdenv.hostPlatform.isElf) [ "-ffat-lto-objects" ] ); }; @@ -265,6 +314,9 @@ stdenv.mkDerivation (finalAttrs: { NIX_LDFLAGS+=" -undefined dynamic_lookup" fi '' + + lib.optionalString (swift-driver != null) '' + appendToVar cmakeFlags "-DSWIFT_EARLY_SWIFT_DRIVER_BUILD:PATH=${lib.escapeShellArg (lib.getBin swift-driver)}/bin" + '' + lib.optionalString (bootstrapStage >= 1) '' appendToVar cmakeFlags "-DSWIFT_PATH_TO_STRING_PROCESSING_SOURCE:PATH=$NIX_BUILD_TOP/swift-experimental-string-processing" appendToVar cmakeFlags "-DSWIFT_PATH_TO_SWIFT_SYNTAX_SOURCE:PATH=$NIX_BUILD_TOP/swift-syntax" @@ -307,6 +359,8 @@ stdenv.mkDerivation (finalAttrs: { (swift-corelibs-libdispatch.override { useSwift = false; }) ]; + inherit doCheck; + postInstall = # Swift 6 installs private Swift Syntax dylibs to $lib/lib/swift/host/compiler, which `CMAKE_INSTALL_NAME_DIR` # mangles to the wrong paths. @@ -327,6 +381,28 @@ stdenv.mkDerivation (finalAttrs: { if [[ "$res" =~ invalidate ]]; then codesign -s - -f "$exe"; fi fi done < <(find "$out" -type f -print0) + '' + # Swift installs some back-deployment and stdlib components as part of the compiler component. Delete them. + + lib.optionalString (stdlib != null) '' + rm -rf "''${!outputLib}/lib/swift/${swiftPlatform}" + rm -rf "''${!outputLib}/lib/swift-6.2" + rm -rf "''${!outputLib}/lib/swift_static" + '' + # Remove early Swift Driver from `$out/bin`. It will be supplied by the `swift` derivation. + + lib.optionalString (swift-driver != null) '' + declare -a swiftDriverFiles=( + swift + swift-driver + swift-help + swift-legacy-driver + swiftc + swiftc-legacy-driver + ) + for file in "''${swiftDriverFiles[@]}"; do + rm "''${!outputBin}/bin/$file" + done + ln -s swift-frontend "''${!outputBin}/bin/swift" + ln -s swift-frontend "''${!outputBin}/bin/swiftc" ''; passthru.supportsMacros = bootstrapStage >= 1; diff --git a/pkgs/top-level/swift-packages.nix b/pkgs/top-level/swift-packages.nix index 6a52a8b5fa7c..dcb87adbced3 100644 --- a/pkgs/top-level/swift-packages.nix +++ b/pkgs/top-level/swift-packages.nix @@ -63,6 +63,13 @@ let bootstrapStage = 0; buildSwiftPackages = swiftPackages_ng.overrideScope (_: _: { swift = null; }); }; + + bootstrapStage1SwiftPackages = mkBootstrapSwiftPackages { + inherit lib; + swiftPackages = swiftPackages_ng; + bootstrapStage = 1; + buildSwiftPackages = bootstrapStage0SwiftPackages; + }; in makeScopeWithSplicing' { @@ -81,9 +88,9 @@ makeScopeWithSplicing' { }; in { - bootstrapStage = 1; + bootstrapStage = 2; - buildSwiftPackages = bootstrapStage0SwiftPackages; + buildSwiftPackages = bootstrapStage1SwiftPackages; inherit llvm_libtool; From b842ad4d1f81c45a6f9682f2d116547e37324f93 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 207/423] swiftPackages_ng.swiftc: add static output for LLDB MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The Swift REPL depends on a highly modified version of LLDB included in the Swift fork of LLVM. This build of LLDB depends on a number of internal headers and static libraries from the Swift compiler build. We don’t want to include these in the dev outputs because they would unnecessarily increase its size when building Swift programs. Instead, copy them to a separate output that LLDB will use when building. --- .../swift_ng/by-name/sw/swiftc/package.nix | 151 ++++++++++++++++++ 1 file changed, 151 insertions(+) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/package.nix index 6791d4a5a96d..3e237e12ae2d 100644 --- a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/package.nix +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/package.nix @@ -128,6 +128,10 @@ stdenv.mkDerivation (finalAttrs: { "dev" "doc" "man" + ] + ++ lib.optionals (bootstrapStage == 2) [ + # Static libs from the compiler build (needed to build LLDB). + "static" ]; src = fetchFromGitHub { @@ -403,6 +407,153 @@ stdenv.mkDerivation (finalAttrs: { done ln -s swift-frontend "''${!outputBin}/bin/swift" ln -s swift-frontend "''${!outputBin}/bin/swiftc" + '' + + lib.optionalString (bootstrapStage == 2) '' + mkdir -p "$static/lib" + + # Copy Swift compiler libraries needed by LLDB into $static. The following list should match the ones found at: + # - https://github.com/swiftlang/llvm-project/blob/swift-$swiftVersion-RELEASE/lldb/source/Plugins/ExpressionParser/Swift/CMakeLists.txt + # - https://github.com/swiftlang/llvm-project/blob/swift-$swiftVersion-RELEASE/lldb/source/Plugins/Language/Swift/CMakeLists.txt + # - https://github.com/swiftlang/llvm-project/blob/swift-$swiftVersion-RELEASE/lldb/source/Plugins/LanguageRuntime/Swift/CMakeLists.txt + # - https://github.com/swiftlang/llvm-project/blob/swift-$swiftVersion-RELEASE/lldb/source/Symbol/CMakeLists.txt + # - https://github.com/swiftlang/swift/blob/swift-$swiftVersion-RELEASE/SwiftCompilerSources/CMakeLists.txt + declare -a swiftLibs=( + libswiftAST + libswiftASTSectionImporter + libswiftBasic + libswiftClangImporter + libswiftFrontend + libswiftIDE + libswiftParse + libswiftRemoteAST + libswiftRemoteInspection + libswiftSIL + libswiftSILOptimizer + libswiftSerialization + ) + # These are dependencies of the above + declare -a swiftLibsDeps=( + lib_CompilerRegexParser + libswiftAPIDigester + libswiftASTGen + libswiftCompilerModules + libswiftConstExtract + libswiftDemangling + libswiftDriver + libswiftIDEUtilsBridging + libswiftIRGen + libswiftLLVMPasses + libswiftLocalization + libswiftMacroEvaluation + libswiftMarkup + libswiftOption + libswiftSILGen + libswiftSema + libswiftSymbolGraphGen + swift/host/compiler/lib_Compiler_SwiftLibraryPluginProviderCShims + swift/host/compiler/lib_Compiler_SwiftSyntaxCShims + swift/host/lib_SwiftLibraryPluginProviderCShims + swift/host/lib_SwiftSyntaxCShims + ) + for swiftLib in "''${swiftLibs[@]}" "''${swiftLibsDeps[@]}"; do + src=lib/$swiftLib${stdenv.hostPlatform.extensions.staticLibrary} + dest=$static/lib/$swiftLib${stdenv.hostPlatform.extensions.staticLibrary} + ninja "$(basename "$src")" # Make sure the static library was built. Some aren’t by default. + mkdir -p "$(dirname "$dest")" + cp -v "$src" "$dest" + done + # swiftCompilerStub is actually just an object file + cp SwiftCompilerSources/CMakeFiles/swiftCompilerStub.dir/stubs.cpp.o "$static/lib/stubs.cpp.o" + ''; + + postFixup = + # The Swift fork of LLDB needs several internal headers and build artifacts. These are copied in `postFixup` instead + # of in `postInstall` to prevent the multiple outputs hook from moving them to $dev. We don’t want them in + # $dev to keep the closure size down when using `swiftc` outside of buidling LLDB. + lib.optionalString (bootstrapStage == 2) '' + staticLibExt=${stdenv.hostPlatform.extensions.staticLibrary} + sharedLibExt=${stdenv.hostPlatform.extensions.sharedLibrary} + + stdlibLibPath=${lib.escapeShellArg (lib.getLib stdlib)} + stdlibDevPath=${lib.escapeShellArg (lib.getDev stdlib)} + stdlibIncPath=${lib.escapeShellArg (lib.getInclude stdlib)} + + swiftcLibPath=''${!outputLib} + swiftcDevPath=$static + swiftcIncPath=''${!outputInclude} + + swiftBinaryDir=''${!outputBin} + swiftIncludeDirs=$swiftcIncPath/include\;$stdlibIncPath/lib\;$stdlibIncPath/include\;$static/include + swiftLibraryDirs=$swiftcDevPath/lib\;$swiftcLibPath/lib\;$stdlibLibPath/lib\;$stdlibDevPath/lib + + swiftArch=${stdenv.hostPlatform.swift.arch} + swiftPlatform=${stdenv.hostPlatform.swift.platform} + + buildDir=$NIX_BUILD_TOP/$sourceRoot/build + buildType=''${cmakeBuildType:-Release} + + # Some headers reference headers from the source tree, so copy all of them. This has to be done in `postFixup` + # instead of `postInstall` to prevent the multiple outputs hook from moving them to $dev. + cp -rv include "$static" # For generated config headers. + + # When the store is on a case-insensitive filesystem, which is currently the default on Darwin for both the old + # and the new installers, this header will conflict with `$static/include/swift/Bridging`. + mv "$static/include/swift/bridging" "$static/include/swift/bridging.h" + + while IFS= read -d "" f; do + # Don’t copy build products. Only copy headers from the original source tree. + if [[ ! "$f" =~ \.\./build ]]; then + dest=$static/''${f#../} + mkdir -p "$(dirname "$dest")" + cp -v "$f" "$dest" + fi + done < <(find .. \( -name '*.def' -o -name '*.h' \) -print0) + + # Fix up any references to `swift/bridging`, which was renamed above. + while IFS= read -d "" f; do + substituteInPlace "$f" --replace-fail 'swift/bridging' 'swift/bridging.h' + done < <(grep -rlz 'include.*swift/bridging' "$static") + + # Copy the Swift CMake config but fix it up to point to the store instead of to the source folder. + # This also has to be done here to avoid having them moved to $dev. + mkdir -p "$static/lib/cmake/modules" + cp -rv lib/cmake/swift "$static/lib/cmake" + + # Clean up the config paths and drop the main source location (because it references the build folder). + # The `find_package` is because our Swift builds against an external swift-cmark, which dependents + # need to be able to find and use as well. Otherwise, they try to link liblibcmark-gfm, which is wrong. + sed -i "$static/lib/cmake/swift/SwiftConfig.cmake" \ + -e '1i find_package(cmark-gfm)' \ + -e "2i set(SWIFT_STDLIB_DIR \"$stdlibLibPath/lib\")" \ + -e '/SWIFT_MAIN_SRC_DIR/d' \ + -e "/SWIFT_BINARY_DIR /c set(SWIFT_BINARY_DIR \"$swiftBinaryDir\")" \ + -e "/SWIFT_INCLUDE_DIR /c set(SWIFT_INCLUDE_DIR \"$swiftIncludeDirs\")" \ + -e "/SWIFT_INCLUDE_DIRS /c set(SWIFT_INCLUDE_DIRS \"$swiftIncludeDirs\")" \ + -e "/SWIFT_LIBRARY_DIR /c set(SWIFT_LIBRARY_DIR \"$swiftLibraryDirs\")" \ + -e "/SWIFT_LIBRARY_DIRS /c set(SWIFT_LIBRARY_DIRS \"$swiftLibraryDirs\")" \ + -e "/SWIFT_CMAKE_DIR /c set(SWIFT_CMAKE_DIR \"$static/lib/cmake/modules\")" \ + -e "/include(\"''${NIX_BUILD_TOP//\//\\\/}/c include(\"$static/lib/cmake/swift/SwiftExports.cmake\")" + + # Change exports to point to the locations in the store. This is a ugly because the exports could be in + # one of several outputs belong to different derivations. + sed -i "$static/lib/cmake/swift/SwiftExports.cmake" \ + -e "s|IMPORTED_LOCATION_''${buildType^^} \"$buildDir/lib/swift/$swiftPlatform/$swiftArch/\(.*$sharedLibExt\)\"|IMPORTED_LOCATION_''${buildType^^} \"$stdlibLibPath/lib/\1\"|g" \ + -e "s|IMPORTED_LOCATION_''${buildType^^} \"$buildDir/lib/swift/$swiftPlatform/$swiftArch/\(.*$staticLibExt\)\"|IMPORTED_LOCATION_''${buildType^^} \"$stdlibDevPath/lib/\1\"|g" \ + -e "s|IMPORTED_LOCATION_''${buildType^^} \"$buildDir/lib/\(swift-[^/]*\)/$swiftPlatform/$swiftArch/\([^/\"]*\)\"|IMPORTED_LOCATION_''${buildType^^} \"$stdlibLibPath/lib/\1/\2\"|g" \ + -e "s|IMPORTED_LOCATION_''${buildType^^} \"$buildDir/lib/swift/host/\(.*$sharedLibExt\)\"|IMPORTED_LOCATION_''${buildType^^} \"$swiftcLibPath/lib/swift/host/\1\"|g" \ + -e "s|IMPORTED_LOCATION_''${buildType^^} \"$buildDir/lib/swift/host/\(.*$staticLibExt\)\"|IMPORTED_LOCATION_''${buildType^^} \"$swiftcDevPath/lib/swift/host/\1\"|g" \ + -e "s|IMPORTED_LOCATION_''${buildType^^} \"$buildDir/lib/\(lib_Internal[^/\"]*\)\"|IMPORTED_LOCATION_''${buildType^^} \"$swiftcLibPath/lib/swift/host/compiler/\1\"|g" \ + -e "s|IMPORTED_LOCATION_''${buildType^^} \"$buildDir/lib/\(.*$sharedLibExt\)\"|IMPORTED_LOCATION_''${buildType^^} \"$swiftcLibPath/lib/\1\"|g" \ + -e "s|IMPORTED_LOCATION_''${buildType^^} \"$buildDir/lib/\(.*.framework/[^\"]*\)\"|IMPORTED_LOCATION_''${buildType^^} \"$swiftcLibPath/lib/\1\"|g" \ + -e "s|IMPORTED_LOCATION_''${buildType^^} \"$buildDir/lib/\(.*$staticLibExt\)\"|IMPORTED_LOCATION_''${buildType^^} \"$swiftcDevPath/lib/\1\"|g" \ + -e "s|IMPORTED_LOCATION_''${buildType^^} \"$buildDir/bin/\([^/\"]*\)\"|IMPORTED_LOCATION_''${buildType^^} \"$swiftBinaryDir/bin/\1\"|g" \ + -e "s|IMPORTED_OBJECTS_''${buildType^^} \"$buildDir/.*/\([^/\"]*.o\)\"|IMPORTED_OBJECTS_''${buildType^^} \"$swiftcDevPath/lib\/\1\"|g" \ + -e "/INTERFACE_INCLUDE_DIRECTORIES/c INTERFACE_INCLUDE_DIRECTORIES \"$swiftIncludeDirs\"" \ + -e "/INTERFACE_LINK_DIRECTORIES/c INTERFACE_LINK_DIRECTORIES \"$swiftLibraryDirs\"" + + # Copy SwiftAddCustomCommandTarget and its required support module (SwiftUtils), which is needed by LLDB. + cp -v ../cmake/modules/SwiftUtils.cmake "$static/lib/cmake/modules/SwiftUtils.cmake" + cp -v ../cmake/modules/SwiftAddCustomCommandTarget.cmake "$static/lib/cmake/modules/SwiftAddCustomCommandTarget.cmake" ''; passthru.supportsMacros = bootstrapStage >= 1; From 34bbd8c8a90af9bc742be498cbe31328e3b3f3e4 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 208/423] swiftPackages_ng.llvmPackages.lldb: support Swift and the REPL Unlike the other LLVM packages used by Swift, LLDB requires several changes and patching to work and function with Swift in Nixpkgs. --- .../by-name/ll/llvmPackages/package.nix | 86 ++++++++++++ .../lldb/0001-Set-stdlib-path-on-Linux.patch | 30 +++++ .../0002-Link-lldb-server-to-swiftCore.patch | 28 ++++ ...follow-symlinks-when-finding-liblldb.patch | 92 +++++++++++++ ...B-executable-path-to-find-the-stdlib.patch | 33 +++++ .../backport-ParseTrieEntries-fixes.patch | 125 ++++++++++++++++++ 6 files changed, 394 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/lldb/0001-Set-stdlib-path-on-Linux.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/lldb/0002-Link-lldb-server-to-swiftCore.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/lldb/0003-Don-t-follow-symlinks-when-finding-liblldb.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/lldb/0004-Use-the-LLDB-executable-path-to-find-the-stdlib.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/lldb/backport-ParseTrieEntries-fixes.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/package.nix b/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/package.nix index 5e5970f53190..d9725fe5b4c5 100644 --- a/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/package.nix +++ b/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/package.nix @@ -4,10 +4,18 @@ { lib, + apple-sdk_26, + darwin, fetchFromGitHub, generateSplicesForMkScope, + libuuid, + lld, llvmPackages_19, # Needs to match the `llvmVersion` of the fork. + python3, stdenv, + stdlib, + swift-cmark, + swiftc, swift_release, swift_sources, }: @@ -38,6 +46,8 @@ in // { # Updated patch that also prevents Clang from trying to copy `clang-deps-launcher.py` to `${llvm}/bin`. "clang/gnu-install-dirs.patch" = [ { path = ./patches; } ]; + # The patch needs slightly tweaked to apply to Swift’s LLDB fork. + "lldb/backport-ParseTrieEntries-fixes.patch" = [ { path = ./patches; } ]; # Update backport of the Darwin triple changes for macOS 27. "llvm/backport-darwin-triple-parsing.patch" = [ { path = ./patches; } ]; }; @@ -82,5 +92,81 @@ in ''; } ); + + lldb = + let + python3-with-distutils = python3.withPackages (pkgs: [ pkgs.distutils ]); + + swiftLLDB = prev.lldb.overrideAttrs (old: { + patches = (old.patches or [ ]) ++ [ + # The LLDB build on Linux assumes the rpath is set relative to the toolchain and that `SWIFT_LIBRARY_DIR` + # consists of only one path (and is not a list). It needs to point to the stdlib. + ./patches/lldb/0001-Set-stdlib-path-on-Linux.patch + # Otherwise, linking `lldb-server` fails with a missing symbol error on Linux. + ./patches/lldb/0002-Link-lldb-server-to-swiftCore.patch + # Don’t resolve the liblldb symlink to help it find the Swift toolchain that it’s linked into. + ./patches/lldb/0003-Don-t-follow-symlinks-when-finding-liblldb.patch + # Darwin needs to find the path to LLDB via the main executable because dyld always resolves symlinks + # when loading dylibs from disk. + ./patches/lldb/0004-Use-the-LLDB-executable-path-to-find-the-stdlib.patch + ]; + buildInputs = + (old.buildInputs or [ ]) + ++ [ + stdlib # The LLDB build system expects the stdlib libraries to be available on the default linker path. + ] + # For `swift_coroFrameAlloc`, which needs an SDK with libswiftCore text-based stubs that have the symbol. + ++ lib.optionals stdenv.hostPlatform.isDarwin [ apple-sdk_26 ]; + # Swift’s fork of LLDB has extra requirements. + nativeBuildInputs = + (old.nativeBuildInputs or [ ]) + ++ [ + python3-with-distutils # distutils is needed for the bundled Python plugin. + ] + ++ lib.optionals stdenv.hostPlatform.isDarwin [ + darwin.sigtool # Required for code-signing. + lld # Otherwise results in `can't find ordinal for imported symbol '_objc_opt_self'` when linking. + ]; + # These aren’t set correctly otherwise. The LLDB build system needs an explicit Swift path regardless. + cmakeFlags = + (old.cmakeFlags or [ ]) + ++ [ + (lib.cmakeFeature "LLVM_DIR" "${lib.getDev final.libllvm}/lib/cmake/llvm") + (lib.cmakeFeature "Swift_DIR" "${lib.getOutput "static" swiftc}") + (lib.cmakeFeature "cmark-gfm_DIR" "${swift-cmark.out}/lib/cmake") + (lib.cmakeFeature "LLDB_SWIFT_LIBS" "${lib.getDev stdlib}/lib/swift") + # LLDB looks for Clang’s resource root in `${swiftc}/lib/swift/clang`. When it’s not there, which it’s + # not because it’s been moved to the `swift` package, LLDB falls back to `CLANG_RESOURCE_DIR`, + # but that’s `libclang.lib`, which also doesn’t have it. So use the wrapped Clang’s resource root. + (lib.cmakeFeature "CLANG_RESOURCE_DIR" "../../../../${lib.getBin final.clang}/resource-root") + ] + ++ lib.optionals stdenv.hostPlatform.isDarwin [ + (lib.cmakeFeature "CMAKE_LINKER_TYPE" "LLD") # Darwin fails to link correctly using ld64 (see above). + ]; + + # Make sure LLDB can find the Swift compiler shared libraries. + postInstall = + (old.postInstall or "") + + lib.optionalString stdenv.hostPlatform.isElf '' + for output in $(getAllOutputNames); do + while IFS= read -d "" f; do + if isELF "$f"; then + # Make sure all rpaths are present. Why is libuuid getting dropped? I have no idea. + patchelf --add-rpath ${ + lib.escapeShellArg (lib.makeSearchPathOutput "out" "lib/swift/host/compiler" [ swiftc ]) + } "$f" || true + patchelf --add-rpath ${lib.escapeShellArg (lib.makeLibraryPath [ libuuid ])} "$f" || true + fi + done < <(find "''${!output}" -type f -print0) + done + # Reduce LLDB closure size by symlinking `lib/swift` into LLDB instead of copying it. + rm -rf "''$out/lib/swift" + ln -s ${lib.escapeShellArg swiftc}/lib/swift "$out/lib/swift" + ''; + }); + in + # Linux tries to use a GCC stdenv to build LLDB, but the Swift headers aren’t compatible with GCC. + # The stdenv passed in from the package set arguments is the Clang-based stdenv from `swift-packages.nix`. + final.callPackage swiftLLDB.override { inherit stdenv; }; } ) diff --git a/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/lldb/0001-Set-stdlib-path-on-Linux.patch b/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/lldb/0001-Set-stdlib-path-on-Linux.patch new file mode 100644 index 000000000000..e2862a504d38 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/lldb/0001-Set-stdlib-path-on-Linux.patch @@ -0,0 +1,30 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Tue, 21 Jul 2026 23:04:32 -0400 +Subject: [PATCH 1/4] Set stdlib path on Linux + +--- + tools/repl/swift/CMakeLists.txt | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/tools/repl/swift/CMakeLists.txt b/tools/repl/swift/CMakeLists.txt +index 46989e7c25b5..4199b71f488d 100644 +--- a/tools/repl/swift/CMakeLists.txt ++++ b/tools/repl/swift/CMakeLists.txt +@@ -26,11 +26,11 @@ elseif(CMAKE_SYSTEM_NAME STREQUAL Linux) + BUILD_RPATH ${SWIFT_LIBRARY_DIR}/swift/linux/powerpc64le) + else() + set_target_properties(repl_swift PROPERTIES +- BUILD_RPATH ${SWIFT_LIBRARY_DIR}/swift/linux) ++ BUILD_RPATH ${SWIFT_STDLIB_DIR}) + endif() + set_target_properties(repl_swift PROPERTIES + BUILD_WITH_INSTALL_RPATH NO +- INSTALL_RPATH "$ORIGIN/../lib/swift/linux") ++ INSTALL_RPATH ${SWIFT_STDLIB_DIR}) + endif() + + # The dummy repl executable is a C program, but we always look for a mangled +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/lldb/0002-Link-lldb-server-to-swiftCore.patch b/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/lldb/0002-Link-lldb-server-to-swiftCore.patch new file mode 100644 index 000000000000..a058fb4b327e --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/lldb/0002-Link-lldb-server-to-swiftCore.patch @@ -0,0 +1,28 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Wed, 22 Jul 2026 21:02:05 -0400 +Subject: [PATCH 2/4] Link lldb-server to swiftCore + +Fixes a missing symbol error when linking lldb-server on Linux: + + ld.bfd: /lib/libswiftASTGen.a(LexicalLookup.swift.o): undefined reference to symbol '$ss10SetAlgebraP9formUnionyyxnFTq' + ld.bfd: /lib/libswiftCore.so: error adding symbols: DSO missing from command line +--- + tools/lldb-server/CMakeLists.txt | 1 + + 1 file changed, 1 insertion(+) + +diff --git a/tools/lldb-server/CMakeLists.txt b/tools/lldb-server/CMakeLists.txt +index 4ac3fddf2b53..6c2603626e44 100644 +--- a/tools/lldb-server/CMakeLists.txt ++++ b/tools/lldb-server/CMakeLists.txt +@@ -55,6 +55,7 @@ add_lldb_tool(lldb-server + lldbPluginInstructionMIPS64 + lldbPluginInstructionRISCV + ${LLDB_SYSTEM_LIBS} ++ swiftCore + + LINK_COMPONENTS + Option +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/lldb/0003-Don-t-follow-symlinks-when-finding-liblldb.patch b/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/lldb/0003-Don-t-follow-symlinks-when-finding-liblldb.patch new file mode 100644 index 000000000000..2bd1bb7172af --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/lldb/0003-Don-t-follow-symlinks-when-finding-liblldb.patch @@ -0,0 +1,92 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Wed, 5 Aug 2026 07:36:33 -0400 +Subject: [PATCH 3/4] =?UTF-8?q?Don=E2=80=99t=20follow=20symlinks=20when=20?= + =?UTF-8?q?finding=20liblldb?= +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Various dependencies are symlinked together into the Swift toolchain in +Nixpkgs. If LLDB resolves the location of liblldb, it will always find +it in the LLDB derivation’s output, which prevents finding the Swift +toolchain when running the Swift REPL. +--- + include/lldb/Host/Host.h | 2 +- + source/Host/common/Host.cpp | 6 ++++-- + source/Host/common/HostInfoBase.cpp | 6 +++++- + source/Host/windows/Host.cpp | 2 +- + 4 files changed, 11 insertions(+), 5 deletions(-) + +diff --git a/include/lldb/Host/Host.h b/include/lldb/Host/Host.h +index 23d5383163ff..4a17900be75d 100644 +--- a/include/lldb/Host/Host.h ++++ b/include/lldb/Host/Host.h +@@ -120,7 +120,7 @@ public: + /// \b A file spec with the module that contains \a host_addr, + /// which may be invalid if \a host_addr doesn't fall into + /// any valid module address range. +- static FileSpec GetModuleFileSpecForHostAddress(const void *host_addr); ++ static FileSpec GetModuleFileSpecForHostAddress(const void *host_addr, bool resolvePath = true); + + /// If you have an executable that is in a bundle and want to get back to + /// the bundle directory from the path itself, this function will change a +diff --git a/source/Host/common/Host.cpp b/source/Host/common/Host.cpp +index 04380c6255f1..2510f2d7b54e 100644 +--- a/source/Host/common/Host.cpp ++++ b/source/Host/common/Host.cpp +@@ -344,14 +344,16 @@ bool Host::ResolveExecutableInBundle(FileSpec &file) { return false; } + + #ifndef _WIN32 + +-FileSpec Host::GetModuleFileSpecForHostAddress(const void *host_addr) { ++FileSpec Host::GetModuleFileSpecForHostAddress(const void *host_addr, bool resolvePath) { + FileSpec module_filespec; + #if !defined(__ANDROID__) + Dl_info info; + if (::dladdr(host_addr, &info)) { + if (info.dli_fname) { + module_filespec.SetFile(info.dli_fname, FileSpec::Style::native); +- FileSystem::Instance().Resolve(module_filespec); ++ if (resolvePath) { ++ FileSystem::Instance().Resolve(module_filespec); ++ } + } + } + #endif +diff --git a/source/Host/common/HostInfoBase.cpp b/source/Host/common/HostInfoBase.cpp +index 5c44c2f38b28..cb10bded1470 100644 +--- a/source/Host/common/HostInfoBase.cpp ++++ b/source/Host/common/HostInfoBase.cpp +@@ -249,10 +249,14 @@ bool HostInfoBase::ComputeSharedLibraryDirectory(FileSpec &file_spec) { + // On other posix systems, we will get .../lib(64|32)?/liblldb.so. + + FileSpec lldb_file_spec(Host::GetModuleFileSpecForHostAddress( +- reinterpret_cast(HostInfoBase::ComputeSharedLibraryDirectory))); ++ reinterpret_cast(HostInfoBase::ComputeSharedLibraryDirectory), /* resolvePath */ false)); + ++// If g_shlib_dir_helper is set on Linux, it will resolve the symlink, which we don’t want. ++// Getting the shared library where it is saves ~280 MiB of toolchain closure size. ++#ifdef _WIN32 + if (g_shlib_dir_helper) + g_shlib_dir_helper(lldb_file_spec); ++#endif + + // Remove the filename so that this FileSpec only represents the directory. + file_spec.SetDirectory(lldb_file_spec.GetDirectory()); +diff --git a/source/Host/windows/Host.cpp b/source/Host/windows/Host.cpp +index e8973a3fb937..5955cf742059 100644 +--- a/source/Host/windows/Host.cpp ++++ b/source/Host/windows/Host.cpp +@@ -113,7 +113,7 @@ void Host::Kill(lldb::pid_t pid, int signo) { + + const char *Host::GetSignalAsCString(int signo) { return NULL; } + +-FileSpec Host::GetModuleFileSpecForHostAddress(const void *host_addr) { ++FileSpec Host::GetModuleFileSpecForHostAddress(const void *host_addr, bool resolvePath) { + FileSpec module_filespec; + + HMODULE hmodule = NULL; +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/lldb/0004-Use-the-LLDB-executable-path-to-find-the-stdlib.patch b/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/lldb/0004-Use-the-LLDB-executable-path-to-find-the-stdlib.patch new file mode 100644 index 000000000000..6e6d60cbbafb --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/lldb/0004-Use-the-LLDB-executable-path-to-find-the-stdlib.patch @@ -0,0 +1,33 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 5 Sep 2026 08:24:48 -0400 +Subject: [PATCH 4/4] Use the LLDB executable path to find the stdlib + +dyld always resolves symlinks when loading an image, which prevents +`GetModuleFileSpecForHostAddress` from returning the unresolved path to +`liblldb.dylib`. We could break the symlink by copying the dylib, but +that would make the closure much larger. Fortunately, we can use the +path of the LLDB executable, which will need to be copied into the +toolchain anyway for other reasons. +--- + source/Host/macosx/objcxx/HostInfoMacOSXSwift.cpp | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/source/Host/macosx/objcxx/HostInfoMacOSXSwift.cpp b/source/Host/macosx/objcxx/HostInfoMacOSXSwift.cpp +index 716d0fbb4f63..18ed6cf55ff7 100644 +--- a/source/Host/macosx/objcxx/HostInfoMacOSXSwift.cpp ++++ b/source/Host/macosx/objcxx/HostInfoMacOSXSwift.cpp +@@ -79,8 +79,8 @@ FileSpec HostInfoMacOSX::GetSwiftResourceDir() { + static std::once_flag g_once_flag; + static FileSpec g_swift_resource_dir; + std::call_once(g_once_flag, []() { +- FileSpec lldb_file_spec = HostInfo::GetShlibDir(); +- ComputeSwiftResourceDirectory(lldb_file_spec, g_swift_resource_dir, true); ++ auto exe_path = HostInfoMacOSX::GetProgramFileSpec().CopyByRemovingLastPathComponent(); ++ ComputeSwiftResourceDirectory(exe_path, g_swift_resource_dir, true); + Log *log = GetLog(LLDBLog::Host); + LLDB_LOG(log, "swift dir -> '{0}'", g_swift_resource_dir); + }); +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/lldb/backport-ParseTrieEntries-fixes.patch b/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/lldb/backport-ParseTrieEntries-fixes.patch new file mode 100644 index 000000000000..82961ad15398 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/lldb/backport-ParseTrieEntries-fixes.patch @@ -0,0 +1,125 @@ +diff --git a/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp b/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp +index 9fe3e27ca0..2040879a51 100644 +--- a/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp ++++ b/source/Plugins/ObjectFile/Mach-O/ObjectFileMachO.cpp +@@ -144,6 +144,14 @@ + static constexpr llvm::StringLiteral g_loader_path = "@loader_path"; + static constexpr llvm::StringLiteral g_executable_path = "@executable_path"; + ++/// Upper bound on the length of a symbol name assembled from export-trie edge ++/// labels. A corrupt trie can encode an edge label whose terminator is far ++/// away in the trie data, so a single label is many megabytes long; appending ++/// it to the running name would otherwise request an unbounded allocation. No ++/// legitimate symbol name comes close to this size. Also 1 MiB is the ++/// symbol length limit in ld. ++static constexpr size_t kMaxTrieSymbolNameLength = 1 << 20; // 1 MiB ++ + LLDB_PLUGIN_DEFINE(ObjectFileMachO) + + static void PrintRegisterValue(RegisterContext *reg_ctx, const char *name, +@@ -2213,15 +2221,21 @@ + } + }; + +-static bool ParseTrieEntries(DataExtractor &data, lldb::offset_t offset, +- const bool is_arm, addr_t text_seg_base_addr, +- std::vector &nameSlices, +- std::set &resolver_addresses, +- std::vector &reexports, +- std::vector &ext_symbols) { ++static bool ParseTrieEntriesImpl(DataExtractor &data, lldb::offset_t offset, ++ const bool is_arm, addr_t text_seg_base_addr, ++ std::string &prefix, ++ std::set &resolver_addresses, ++ std::vector &reexports, ++ std::vector &ext_symbols, ++ std::set &visited_nodes) { + if (!data.ValidOffset(offset)) + return true; + ++ // Every node in a well-formed trie is reached by exactly one path, so a node ++ // offset seen twice means the trie is corrupt. ++ if (!visited_nodes.insert(offset).second) ++ return false; ++ + // Terminal node -- end of a branch, possibly add this to + // the symbol table or resolver table. + const uint64_t terminalSize = data.GetULEB128(&offset); +@@ -2261,14 +2275,9 @@ + add_this_entry = true; + } + if (add_this_entry) { +- std::string name; +- if (!nameSlices.empty()) { +- for (auto name_slice : nameSlices) +- name.append(name_slice.data(), name_slice.size()); +- } +- if (name.size() > 1) { ++ if (prefix.size() > 1) { + // Skip the leading '_' +- e.entry.name.SetCStringWithLength(name.c_str() + 1, name.size() - 1); ++ e.entry.name.SetString(llvm::StringRef(prefix).drop_front()); + } + if (import_name) { + // Skip the leading '_' +@@ -2289,23 +2298,37 @@ + const uint8_t childrenCount = data.GetU8(&children_offset); + for (uint8_t i = 0; i < childrenCount; ++i) { + const char *cstr = data.GetCStr(&children_offset); +- if (cstr) +- nameSlices.push_back(llvm::StringRef(cstr)); +- else ++ if (!cstr) + return false; // Corrupt data ++ if (prefix.size() + llvm::StringRef(cstr).size() > kMaxTrieSymbolNameLength) ++ return false; // Corrupt data: implausibly long symbol name. ++ const size_t prevSize = prefix.size(); ++ prefix.append(cstr); + lldb::offset_t childNodeOffset = data.GetULEB128(&children_offset); +- if (childNodeOffset) { +- if (!ParseTrieEntries(data, childNodeOffset, is_arm, text_seg_base_addr, +- nameSlices, resolver_addresses, reexports, +- ext_symbols)) { +- return false; +- } +- } +- nameSlices.pop_back(); ++ // A child offset of 0 points back at the root; like any other repeated ++ // offset it is a cycle, which ParseTrieEntriesImpl rejects as corrupt. ++ if (!ParseTrieEntriesImpl(data, childNodeOffset, is_arm, text_seg_base_addr, ++ prefix, resolver_addresses, reexports, ++ ext_symbols, visited_nodes)) ++ return false; ++ prefix.resize(prevSize); + } + return true; + } + ++static bool ParseTrieEntries( ++ DataExtractor &data, const bool is_arm, lldb::addr_t text_seg_base_addr, ++ std::set &resolver_addresses, ++ std::vector &reexports, ++ std::vector &ext_symbols) { ++ lldb::offset_t offset = 0; ++ std::set visited_nodes; ++ std::string prefix; ++ return ParseTrieEntriesImpl(data, offset, is_arm, text_seg_base_addr, prefix, ++ resolver_addresses, reexports, ext_symbols, ++ visited_nodes); ++} ++ + static bool + TryParseV2ObjCMetadataSymbol(const char *&symbol_name, + const char *&symbol_name_non_abi_mangled, +@@ -2887,9 +2910,8 @@ + lldb::addr_t text_segment_file_addr = LLDB_INVALID_ADDRESS; + if (text_segment_sp) + text_segment_file_addr = text_segment_sp->GetFileAddress(); +- std::vector nameSlices; +- ParseTrieEntries(dyld_trie_data, 0, is_arm, text_segment_file_addr, +- nameSlices, resolver_addresses, reexport_trie_entries, ++ ParseTrieEntries(dyld_trie_data, is_arm, text_segment_file_addr, ++ resolver_addresses, reexport_trie_entries, + external_sym_trie_entries); + } + From eef51f196ca556156312ade5ef1fca063b632f5b Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 209/423] swiftPackages_ng.swift: enable the REPL LLDB needs to be symlinked into the toolchain for the REPL to work. It needs to be able to find both the Swift shared libraries and modules. --- .../swift_ng/by-name/sw/swift/package.nix | 25 +++++++++++++++++++ pkgs/top-level/swift-packages.nix | 2 ++ 2 files changed, 27 insertions(+) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix index 5216918eec0f..0a7167b77fc7 100644 --- a/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix @@ -2,6 +2,7 @@ lib, apple-sdk_14, apple-sdk_26, + llvmPackages, llvmPackages_upstream, patchelf, stdenv, @@ -14,6 +15,7 @@ swiftc, symlinkJoin, swift_release, + enableRepl ? true, # Whether to build and include LLDB for the Swift REPL. }: let @@ -31,6 +33,10 @@ let swiftc.out swiftc.dev ] + ++ lib.optionals enableRepl [ + # LLDB is used by `swift repl` to provide the REPL. + llvmPackages.lldb.out + ] ++ lib.optionals (stdlib != null) [ stdlib.dev stdlib.out @@ -173,6 +179,25 @@ stdenv.mkDerivation (finalAttrs: { --replace-fail @swiftPath@ "$out" \ --replace-fail @swiftPlatform@ ${stdenv.hostPlatform.swift.platform} ''} + ${lib.optionalString enableRepl '' + # LLDB expects to find Swift relative to its location. Both the wrapper and its binary need copied, + # and the wrapper needs updated to find the binary in the new location. + lldbBinPath=$(dirname $(readlink "$out/bin/lldb")) + for lldbExe in lldb .lldb-wrapped; do + rm "$out/bin/$lldbExe" + cp "$lldbBinPath/$lldbExe" "$out/bin/$lldbExe" + done + substituteInPlace "$out/bin/lldb" \ + --replace-fail "$lldbBinPath" "$out/bin" + ${lib.optionalString stdenv.hostPlatform.isElf '' + # LLDB tries to find the Swift resource folder relative to where it finds `liblldb.so` via RPATH. + oldRpaths=$(patchelf --print-rpath "$out/bin/.lldb-wrapped") + lldbRpath=${lib.escapeShellArg llvmPackages.lldb.out} + + chmod u+w "$out/bin/.lldb-wrapped" + patchelf --set-rpath "''${oldRpaths/$lldbRpath/$out}" "$out/bin/.lldb-wrapped" + ''} + ''} chmod -R u-w "$out/bin" "$out/lib" "$out/nix-support" # Have to invoke manually because of `buildCommand`. diff --git a/pkgs/top-level/swift-packages.nix b/pkgs/top-level/swift-packages.nix index dcb87adbced3..5d38c7082f20 100644 --- a/pkgs/top-level/swift-packages.nix +++ b/pkgs/top-level/swift-packages.nix @@ -22,6 +22,7 @@ let { swift-corelibs-libdispatch = null; swift-foundation = null; + enableRepl = false; } # Swift Driver is required when building the compiler’s Swift Syntax in the final toolchain. # Otherwise, symbols are stripped from it that are needed to build Swift Testing. @@ -100,6 +101,7 @@ makeScopeWithSplicing' { swift-corelibs-libdispatch = null; swift-driver = null; swift-foundation = null; + enableRepl = false; }; swift_sources = swift_sources_6_2; From 8cdee6caa0ce2292a644e609e6c0bf71fbb9b9fe Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 210/423] swiftPackages_ng.swift-corelibs-xctest: init at 6.2.4 --- .../sw/swift-corelibs-xctest/package.nix | 88 +++++++++++++++++++ .../compilers/swift_ng/sources-6.2.json | 3 + 2 files changed, 91 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-xctest/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-xctest/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-xctest/package.nix new file mode 100644 index 000000000000..7c5310b501cd --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-xctest/package.nix @@ -0,0 +1,88 @@ +{ + lib, + cmake, + fetchFromGitHub, + ninja, + stdenv, + swift-corelibs-foundation, + swift-corelibs-libdispatch, + swift-foundation, + swift-foundation-icu, + swift-minimal, + swift_release, + swift_sources, +}: + +let + # Our minimum deployment target is higher than 10.12, but we can target lower, and some dependants require it. + # This is harmless on non-Darwin. + minTriple = + lib.replaceString stdenv.hostPlatform.darwinMinVersion "10.12" + stdenv.hostPlatform.swift.triple; + + # swift-corelibs-xctest requires Dispatch and Foundation. + swift = swift-minimal.override { inherit swift-corelibs-libdispatch swift-foundation; }; +in + +stdenv.mkDerivation (finalAttrs: { + pname = "swift-corelibs-xctest"; + version = swift_release; + + outputs = [ + "out" + "dev" + ]; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-corelibs-xctest"; + tag = "swift-${finalAttrs.version}-RELEASE"; + inherit (swift_sources.swift-corelibs-xctest) hash; + }; + + strictDeps = true; + + cmakeFlags = [ (lib.cmakeBool "USE_FOUNDATION_FRAMEWORK" true) ]; + + preConfigure = '' + appendToVar cmakeFlags -DCMAKE_Swift_COMPILER_TARGET=${minTriple} + appendToVar cmakeFlags -DCMAKE_Swift_FLAGS=-module-cache-path\ "$NIX_BUILD_TOP/module-cache" + ''; + + nativeBuildInputs = [ + cmake + ninja + swift + ]; + + buildInputs = + # swift-corelibs-xctest expects to find these via CMake on non-Darwin platforms. + lib.optionals (!stdenv.hostPlatform.isDarwin) [ + swift-corelibs-foundation + swift-corelibs-libdispatch + swift-foundation + swift-foundation-icu + ]; + + postInstall = '' + dylib_name=libXCTest${stdenv.hostPlatform.extensions.library} + dylib_path="''${!outputLib}/lib/swift/${stdenv.hostPlatform.swift.platform}" + mv "$dylib_path/$dylib_name" "''${!outputLib}/lib/$dylib_name" + + moveToOutput lib/swift/${stdenv.hostPlatform.swift.platform} "''${!outputDev}" + '' + + lib.optionalString stdenv.hostPlatform.isDarwin '' + install_name_tool "''${!outputLib}/lib/$dylib_name" \ + -change "$dylib_path/$dylib_name" "''${!outputLib}/lib/$dylib_name" + ''; + + __structuredAttrs = true; + + meta = { + description = "Framework for writing unit tests in Swift"; + homepage = "https://github.com/swiftlang/swift-corelibs-xctest"; + platforms = lib.platforms.darwin ++ lib.platforms.linux ++ lib.platforms.windows; + license = lib.licenses.asl20; + maintainers = lib.teams.swift.members; + }; +}) diff --git a/pkgs/development/compilers/swift_ng/sources-6.2.json b/pkgs/development/compilers/swift_ng/sources-6.2.json index 87d0e53f4e5a..3ca74c79e30d 100644 --- a/pkgs/development/compilers/swift_ng/sources-6.2.json +++ b/pkgs/development/compilers/swift_ng/sources-6.2.json @@ -11,6 +11,9 @@ "swift-corelibs-libdispatch": { "hash": "sha256-Tu2G9FAP4q1xgM1n9q17T6VrqJ3tv8RezyUex38yNds=" }, + "swift-corelibs-xctest": { + "hash": "sha256-BbzY1kZUaHu7O29c8J7xDuelik6lhqmfSSskvvPZ7R4=" + }, "swift-driver": { "hash": "sha256-CZYqUadpAsAUnCTZElobZS9nlMfCuHiMnac3o0k7hnI=" }, From c1ab40a70a37398d048766a5c336e7b7f950ebd7 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 211/423] swiftPackages_ng.swift-testing: init at 6.2.4 --- .../by-name/sw/swift-testing/package.nix | 84 +++++++++++++++++++ .../patches/0001-gnu-install-dirs.patch | 27 ++++++ .../compilers/swift_ng/sources-6.2.json | 3 + 3 files changed, 114 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-testing/package.nix create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-testing/patches/0001-gnu-install-dirs.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-testing/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift-testing/package.nix new file mode 100644 index 000000000000..80b73625c6dd --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-testing/package.nix @@ -0,0 +1,84 @@ +{ + lib, + cmake, + fetchFromGitHub, + ninja, + stdenv, + swift, + swift-syntax, + swift_release, + swift_sources, +}: + +let + inherit (stdenv.hostPlatform.extensions) sharedLibrary; + buildSharedLibrary = stdenv.buildPlatform.extensions.sharedLibrary; +in + +stdenv.mkDerivation (finalAttrs: { + pname = "swift-testing"; + version = swift_release; + + outputs = [ + "out" + "dev" + ]; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-testing"; + tag = "swift-${finalAttrs.version}-RELEASE"; + inherit (swift_sources.swift-testing) hash; + }; + + patches = [ ./patches/0001-gnu-install-dirs.patch ]; + + postPatch = '' + # Need to reference $include, so this can’t be substituted by `replaceVars`. + substituteInPlace CMakeLists.txt --replace-fail '@include@' "''${!outputInclude}" + ''; + + strictDeps = true; + + cmakeFlags = [ (lib.cmakeBool "BUILD_SHARED_LIBS" (!stdenv.hostPlatform.isStatic)) ]; + + preConfigure = '' + appendToVar cmakeFlags -DCMAKE_Swift_COMPILER_TARGET=${stdenv.hostPlatform.swift.triple} + appendToVar cmakeFlags -DCMAKE_Swift_FLAGS=-module-cache-path\ "$NIX_BUILD_TOP/module-cache" + ''; + + nativeBuildInputs = [ + cmake + ninja + swift + ]; + + buildInputs = [ swift-syntax ]; + + postInstall = ( + if stdenv.hostPlatform.isDarwin then + '' + install -D -t "''${!outputDev}/lib/swift/host/plugins/testing" \ + lib/swift/host/plugins/testing/libTestingMacros${sharedLibrary} + install_name_tool "''${!outputLib}/lib/libTesting${sharedLibrary}" \ + -id "''${!outputLib}/lib/libTesting${sharedLibrary}" + install_name_tool "''${!outputDev}/lib/swift/host/plugins/testing/libTestingMacros${buildSharedLibrary}" \ + -id "''${!outputDev}/lib/swift/host/plugins/testing/libTestingMacros${buildSharedLibrary}" + '' + else + '' + install -D -t "''${!outputDev}/lib/swift/host/plugins/testing" \ + lib/swift/host/plugins/libTestingMacros${sharedLibrary} + '' + ); + + __structuredAttrs = true; + + meta = { + description = "Modern testing package for Swift"; + homepage = "https://github.com/swiftlang/swift-testing"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + maintainers = lib.teams.swift.members; + }; +}) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-testing/patches/0001-gnu-install-dirs.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swift-testing/patches/0001-gnu-install-dirs.patch new file mode 100644 index 000000000000..caa75758e8c8 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-testing/patches/0001-gnu-install-dirs.patch @@ -0,0 +1,27 @@ +From 6d92a130bca4f066211e405ee733ea22eed54e37 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Fri, 26 Dec 2025 21:20:40 -0500 +Subject: [PATCH] gnu-install-dirs + +--- + CMakeLists.txt | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/CMakeLists.txt b/CMakeLists.txt +index 38aeda61..2499a8db 100644 +--- a/CMakeLists.txt ++++ b/CMakeLists.txt +@@ -51,8 +51,8 @@ include(PlatformInfo) + include(SwiftModuleInstallation) + + option(SwiftTesting_INSTALL_NESTED_SUBDIR "Install libraries under a platform and architecture subdirectory" NO) +-set(SwiftTesting_INSTALL_LIBDIR "${CMAKE_INSTALL_LIBDIR}/swift$<$>:_static>/${SwiftTesting_PLATFORM_SUBDIR}$<$,$>>:/testing>$<$:/${SwiftTesting_ARCH_SUBDIR}>") +-set(SwiftTesting_INSTALL_SWIFTMODULEDIR "${CMAKE_INSTALL_LIBDIR}/swift$<$>:_static>/${SwiftTesting_PLATFORM_SUBDIR}$<$,$>>:/testing>") ++set(SwiftTesting_INSTALL_LIBDIR "${CMAKE_INSTALL_LIBDIR}") ++set(SwiftTesting_INSTALL_SWIFTMODULEDIR "@include@/lib/swift$<$>:_static>/${SwiftTesting_PLATFORM_SUBDIR}$<$,$>>:/testing>") + + add_compile_options($<$:-no-toolchain-stdlib-rpath>) + +-- +2.51.2 + diff --git a/pkgs/development/compilers/swift_ng/sources-6.2.json b/pkgs/development/compilers/swift_ng/sources-6.2.json index 3ca74c79e30d..afaff3263e39 100644 --- a/pkgs/development/compilers/swift_ng/sources-6.2.json +++ b/pkgs/development/compilers/swift_ng/sources-6.2.json @@ -32,6 +32,9 @@ "swift-syntax": { "hash": "sha256-DMMVJQj590RGGBkTgA89u01ZP2B8kbJTmfu+oxzYPds=" }, + "swift-testing": { + "hash": "sha256-HgvwoAbUeFTVnrOTNVIgFRLOpGyCQHRgQqulHQ1LYnQ=" + }, "swift-tools-support-core": { "hash": "sha256-mV+z5sdG/maUzXUhK1vMtsnLCclcjqyXSMO6J2FjBEg=" } From 0f4a90941a45554b30ca4ac415e4296bee5185ee Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 212/423] swiftPackages_ng.swift: include testing libraries in the toolchain --- .../swift_ng/by-name/sw/swift-testing/package.nix | 6 +++++- .../swift_ng/by-name/sw/swift/package.nix | 15 +++++++++++++++ pkgs/top-level/swift-packages.nix | 2 ++ 3 files changed, 22 insertions(+), 1 deletion(-) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-testing/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift-testing/package.nix index 80b73625c6dd..8b52585f905c 100644 --- a/pkgs/development/compilers/swift_ng/by-name/sw/swift-testing/package.nix +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-testing/package.nix @@ -13,6 +13,10 @@ let inherit (stdenv.hostPlatform.extensions) sharedLibrary; buildSharedLibrary = stdenv.buildPlatform.extensions.sharedLibrary; + + # Can’t use `swift-minimal`. Swift Testing fails to build using the classic Swift frontend. + # It requires the new Swift compiler driver. + swift' = swift.override { swift-testing = null; }; in stdenv.mkDerivation (finalAttrs: { @@ -50,7 +54,7 @@ stdenv.mkDerivation (finalAttrs: { nativeBuildInputs = [ cmake ninja - swift + swift' ]; buildInputs = [ swift-syntax ]; diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix index 0a7167b77fc7..8fdd03b0723e 100644 --- a/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix @@ -9,9 +9,11 @@ stdlib, swift-corelibs-foundation, swift-corelibs-libdispatch, + swift-corelibs-xctest, swift-driver, swift-foundation, swift-foundation-icu, + swift-testing, swiftc, symlinkJoin, swift_release, @@ -19,6 +21,8 @@ }: let + includeTesting = swiftc.supportsMacros && swift-testing != null; + # Need to use an older SDK if `swiftc` does not support macros. propagated-sdk = if swiftc.supportsMacros then apple-sdk_26 else apple-sdk_14; @@ -37,6 +41,12 @@ let # LLDB is used by `swift repl` to provide the REPL. llvmPackages.lldb.out ] + ++ lib.optionals includeTesting [ + swift-corelibs-xctest.dev + swift-corelibs-xctest.out + swift-testing.dev + swift-testing.out + ] ++ lib.optionals (stdlib != null) [ stdlib.dev stdlib.out @@ -85,6 +95,7 @@ let ]; }; in + stdenv.mkDerivation (finalAttrs: { pname = "swift" + lib.removePrefix "swiftc" (lib.getName swiftc); version = swift_release; @@ -104,6 +115,10 @@ stdenv.mkDerivation (finalAttrs: { # Propagate the stdlib to make sure the linker wrapper will pick up the dynamic and static libraries. stdlib ] + ++ lib.optionals includeTesting [ + swift-corelibs-xctest.out + swift-testing.out + ] ++ lib.optionals (!stdenv.hostPlatform.isDarwin) ( lib.optionals (swift-corelibs-libdispatch != null) [ swift-corelibs-libdispatch-no-overlay.out diff --git a/pkgs/top-level/swift-packages.nix b/pkgs/top-level/swift-packages.nix index 5d38c7082f20..7cbbb2492ac6 100644 --- a/pkgs/top-level/swift-packages.nix +++ b/pkgs/top-level/swift-packages.nix @@ -22,6 +22,7 @@ let { swift-corelibs-libdispatch = null; swift-foundation = null; + swift-testing = null; enableRepl = false; } # Swift Driver is required when building the compiler’s Swift Syntax in the final toolchain. @@ -101,6 +102,7 @@ makeScopeWithSplicing' { swift-corelibs-libdispatch = null; swift-driver = null; swift-foundation = null; + swift-testing = null; enableRepl = false; }; From a0ee52630e9a0293d9f1ceffc20425c16ab10e8d Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 213/423] swiftPackages_ng.swift-asn1: init at 1.7.1 --- .../sw/swift-asn1/files/SwiftASN1Config.cmake | 5 ++ .../by-name/sw/swift-asn1/package.nix | 72 +++++++++++++++++++ 2 files changed, 77 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-asn1/files/SwiftASN1Config.cmake create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-asn1/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-asn1/files/SwiftASN1Config.cmake b/pkgs/development/compilers/swift_ng/by-name/sw/swift-asn1/files/SwiftASN1Config.cmake new file mode 100644 index 000000000000..ddcb6b154d6d --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-asn1/files/SwiftASN1Config.cmake @@ -0,0 +1,5 @@ +add_library(SwiftASN1 @buildType@ IMPORTED) +set_target_properties(SwiftASN1 PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}SwiftASN1${CMAKE_@buildType@_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@include@/lib/swift/@swiftPlatform@" +) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-asn1/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift-asn1/package.nix new file mode 100644 index 000000000000..eddec9f79f3c --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-asn1/package.nix @@ -0,0 +1,72 @@ +{ + lib, + cmake, + fetchFromGitHub, + gitUpdater, + ninja, + stdenv, + swift, +}: + +# Swift-ASN1 is a dependency of SwiftPM. It must be built with CMake to avoid dependency cycles. +stdenv.mkDerivation (finalAttrs: { + pname = "swift-asn1"; + version = "1.7.1"; + + outputs = [ + "out" + "dev" + ]; + + src = fetchFromGitHub { + owner = "apple"; + repo = "swift-asn1"; + tag = finalAttrs.version; + hash = "sha256-hikWOlKKW0VplBuDgrt/Xyao3gsDS5IkxsMfbITHT2I="; + }; + + postPatch = '' + substituteInPlace cmake/modules/SwiftSupport.cmake \ + --replace-fail 'ARCHIVE DESTINATION lib/''${swift}/''${swift_os}' 'ARCHIVE DESTINATION ''${CMAKE_INSTALL_LIBDIR}' \ + --replace-fail 'LIBRARY DESTINATION lib/''${swift}/''${swift_os}' 'LIBRARY DESTINATION ''${CMAKE_INSTALL_LIBDIR}' \ + --replace-fail 'RUNTIME DESTINATION bin' 'RUNTIME DESTINATION ''${CMAKE_INSTALL_BINDIR}' + ''; + + strictDeps = true; + + preConfigure = '' + appendToVar cmakeFlags -DCMAKE_Swift_COMPILER_TARGET=${stdenv.hostPlatform.swift.triple} + appendToVar cmakeFlags -DCMAKE_Swift_FLAGS=-module-cache-path\ "$NIX_BUILD_TOP/module-cache" + ''; + + nativeBuildInputs = [ + cmake + ninja + swift + ]; + + postInstall = '' + moveToOutput lib/swift "''${!outputDev}" + moveToOutput lib/swift_static "''${!outputDev}" + + # Install CMake config file for the SwiftASN1 library. + mkdir -p "''${!outputDev}/lib/cmake/SwiftASN1" + substitute ${./files/SwiftASN1Config.cmake} "''${!outputDev}/lib/cmake/SwiftASN1/SwiftASN1Config.cmake" \ + --replace-fail '@buildType@' ${if stdenv.hostPlatform.isStatic then "STATIC" else "SHARED"} \ + --replace-fail '@include@' "''${!outputDev}" \ + --replace-fail '@lib@' "''${!outputLib}" \ + --replace-fail '@swiftPlatform@' ${stdenv.hostPlatform.swift.platform} + ''; + + passthru.updateScript = gitUpdater { }; + + __structuredAttrs = true; + + meta = { + homepage = "https://github.com/apple/swift-asn1"; + description = "An implementation of ASN.1 for Swift"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) From 5c233bad7c83ebf32b4307255c3617e93454520d Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 214/423] swiftPackages_ng.swift-crypto: init at 4.5.1 --- .../files/SwiftCryptoConfig.cmake | 5 ++ .../by-name/sw/swift-crypto/package.nix | 87 +++++++++++++++++++ .../0001-install-missing-modules.patch | 64 ++++++++++++++ 3 files changed, 156 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-crypto/files/SwiftCryptoConfig.cmake create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-crypto/package.nix create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-crypto/patches/0001-install-missing-modules.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-crypto/files/SwiftCryptoConfig.cmake b/pkgs/development/compilers/swift_ng/by-name/sw/swift-crypto/files/SwiftCryptoConfig.cmake new file mode 100644 index 000000000000..b7a7b36566f7 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-crypto/files/SwiftCryptoConfig.cmake @@ -0,0 +1,5 @@ +add_library(Crypto @buildType@ IMPORTED) +set_target_properties(Crypto PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}Crypto${CMAKE_@buildType@_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@include@/lib/swift/@swiftPlatform@;@include@/lib/swift_static/@swiftPlatform@" +) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-crypto/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift-crypto/package.nix new file mode 100644 index 000000000000..40478e348535 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-crypto/package.nix @@ -0,0 +1,87 @@ +{ + lib, + cmake, + fetchFromGitHub, + gitUpdater, + ninja, + stdenv, + swift, + swift-asn1, +}: + +let + swiftPlatform = stdenv.hostPlatform.swift.platform; +in + +stdenv.mkDerivation (finalAttrs: { + pname = "swift-crypto"; + version = "4.5.1"; + + outputs = [ + "out" + "dev" + ]; + + src = fetchFromGitHub { + owner = "apple"; + repo = "swift-crypto"; + tag = finalAttrs.version; + hash = "sha256-RLZmCrRmu6ZYre+VT4YzxpM8LgM7lLCbcMD/CVPiRTg="; + }; + + patches = [ + # Install _CryptoExtras and CryptoBoringWrapper + ./patches/0001-install-missing-modules.patch + ]; + + postPatch = '' + substituteInPlace CMakeLists.txt \ + --replace-fail '/usr/bin/ar' '$ENV{AR}' \ + --replace-fail '/usr/bin/ranlib' '$ENV{RANLIB}' + + substituteInPlace cmake/modules/SwiftSupport.cmake \ + --replace-fail 'ARCHIVE DESTINATION lib/''${swift}/''${swift_os}' 'ARCHIVE DESTINATION ''${CMAKE_INSTALL_LIBDIR}' \ + --replace-fail 'LIBRARY DESTINATION lib/''${swift}/''${swift_os}' 'LIBRARY DESTINATION ''${CMAKE_INSTALL_LIBDIR}' \ + --replace-fail 'RUNTIME DESTINATION bin' 'RUNTIME DESTINATION ''${CMAKE_INSTALL_BINDIR}' \ + ''; + + strictDeps = true; + + preConfigure = '' + appendToVar cmakeFlags -DCMAKE_Swift_COMPILER_TARGET=${stdenv.hostPlatform.swift.triple} + appendToVar cmakeFlags -DCMAKE_Swift_FLAGS=-module-cache-path\ "$NIX_BUILD_TOP/module-cache" + ''; + + nativeBuildInputs = [ + cmake + ninja + swift + ]; + + buildInputs = [ (lib.getInclude swift-asn1) ]; + + postInstall = '' + moveToOutput lib/swift "''${!outputDev}" + moveToOutput lib/swift_static "''${!outputDev}" + + # Install CMake config file for the Swift Crypto library. + mkdir -p "''${!outputDev}/lib/cmake/SwiftCrypto" + substitute ${./files/SwiftCryptoConfig.cmake} "''${!outputDev}/lib/cmake/SwiftCrypto/SwiftCryptoConfig.cmake" \ + --replace-fail '@buildType@' ${if stdenv.hostPlatform.isStatic then "STATIC" else "SHARED"} \ + --replace-fail '@include@' "''${!outputDev}" \ + --replace-fail '@lib@' "''${!outputLib}" \ + --replace-fail '@swiftPlatform@' ${swiftPlatform} + ''; + + __structuredAttrs = true; + + passthru.updateScript = gitUpdater { }; + + meta = { + homepage = "https://github.com/apple/swift-crypto"; + description = "Open-source implementation of most of CryptoKit for Swift"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-crypto/patches/0001-install-missing-modules.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swift-crypto/patches/0001-install-missing-modules.patch new file mode 100644 index 000000000000..d49beb69853b --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-crypto/patches/0001-install-missing-modules.patch @@ -0,0 +1,64 @@ +From fad5e514f44a546b9f41d68f8a99d1a9beab2066 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Thu, 18 Dec 2025 20:58:24 -0500 +Subject: [PATCH] install-missing-modules + +--- + Sources/CMakeLists.txt | 1 + + Sources/CryptoBoringWrapper/CMakeLists.txt | 1 + + Sources/CryptoExtras/CMakeLists.txt | 1 + + Sources/_CryptoExtras/CMakeLists.txt | 13 +++++++++++++ + 4 files changed, 16 insertions(+) + create mode 100644 Sources/_CryptoExtras/CMakeLists.txt + +diff --git a/Sources/CMakeLists.txt b/Sources/CMakeLists.txt +index 4616a1f..caf7440 100644 +--- a/Sources/CMakeLists.txt ++++ b/Sources/CMakeLists.txt +@@ -19,3 +19,4 @@ add_subdirectory(CXKCPShims) + add_subdirectory(CryptoBoringWrapper) + add_subdirectory(Crypto) + add_subdirectory(CryptoExtras) ++add_subdirectory(_CryptoExtras) +diff --git a/Sources/CryptoBoringWrapper/CMakeLists.txt b/Sources/CryptoBoringWrapper/CMakeLists.txt +index 980f33c..0c852bf 100644 +--- a/Sources/CryptoBoringWrapper/CMakeLists.txt ++++ b/Sources/CryptoBoringWrapper/CMakeLists.txt +@@ -36,4 +36,5 @@ target_compile_options(CryptoBoringWrapper PRIVATE ${SWIFT_CRYPTO_COMPILE_OPTION + set_target_properties(CryptoBoringWrapper PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + ++_install_target(CryptoBoringWrapper) + set_property(GLOBAL APPEND PROPERTY SWIFT_CRYPTO_EXPORTS CryptoBoringWrapper) +diff --git a/Sources/CryptoExtras/CMakeLists.txt b/Sources/CryptoExtras/CMakeLists.txt +index e081070..89ce053 100644 +--- a/Sources/CryptoExtras/CMakeLists.txt ++++ b/Sources/CryptoExtras/CMakeLists.txt +@@ -102,4 +102,5 @@ target_link_options(CryptoExtras PRIVATE + set_target_properties(CryptoExtras PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + ++_install_target(CryptoExtras) + set_property(GLOBAL APPEND PROPERTY SWIFT_CRYPTO_EXPORTS CryptoExtras) +diff --git a/Sources/_CryptoExtras/CMakeLists.txt b/Sources/_CryptoExtras/CMakeLists.txt +new file mode 100644 +index 0000000..5e6c283 +--- /dev/null ++++ b/Sources/_CryptoExtras/CMakeLists.txt +@@ -0,0 +1,13 @@ ++add_library(_CryptoExtras STATIC ++ Exports.swift ++) ++ ++target_link_libraries(_CryptoExtras PUBLIC ++ CryptoExtras) ++ ++ ++set_target_properties(_CryptoExtras PROPERTIES ++ INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) ++ ++_install_target(_CryptoExtras) ++set_property(GLOBAL APPEND PROPERTY SWIFT_CRYPTO_EXPORTS _CryptoExtras) +-- +2.50.1 + From 20370b91b693364a9f22e74cd635a3eac29a7f80 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 215/423] swiftPackages_ng.swift-certificates: init at 1.19.4 --- .../files/SwiftCertificatesConfig.cmake | 5 ++ .../by-name/sw/swift-certificates/package.nix | 76 +++++++++++++++++++ 2 files changed, 81 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-certificates/files/SwiftCertificatesConfig.cmake create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-certificates/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-certificates/files/SwiftCertificatesConfig.cmake b/pkgs/development/compilers/swift_ng/by-name/sw/swift-certificates/files/SwiftCertificatesConfig.cmake new file mode 100644 index 000000000000..702338ff038b --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-certificates/files/SwiftCertificatesConfig.cmake @@ -0,0 +1,5 @@ +add_library(X509 @buildType@ IMPORTED) +set_target_properties(X509 PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}X509${CMAKE_@buildType@_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@include@/lib/swift/@swiftPlatform@" +) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-certificates/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift-certificates/package.nix new file mode 100644 index 000000000000..7ea70f784983 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-certificates/package.nix @@ -0,0 +1,76 @@ +{ + lib, + cmake, + fetchFromGitHub, + gitUpdater, + ninja, + stdenv, + swift, + swift-asn1, + swift-crypto, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "swift-certificates"; + version = "1.19.4"; + + outputs = [ + "out" + "dev" + ]; + + src = fetchFromGitHub { + owner = "apple"; + repo = "swift-certificates"; + tag = finalAttrs.version; + hash = "sha256-8I7/JAcGYrk22DymtlM2aiFXlQc3OijBAGL3DtoJWTE="; + }; + + postPatch = '' + substituteInPlace cmake/modules/SwiftSupport.cmake \ + --replace-fail 'ARCHIVE DESTINATION lib/''${swift}/''${swift_os}' 'ARCHIVE DESTINATION ''${CMAKE_INSTALL_LIBDIR}' \ + --replace-fail 'LIBRARY DESTINATION lib/''${swift}/''${swift_os}' 'LIBRARY DESTINATION ''${CMAKE_INSTALL_LIBDIR}' \ + --replace-fail 'RUNTIME DESTINATION bin' 'RUNTIME DESTINATION ''${CMAKE_INSTALL_BINDIR}' \ + --replace-fail ' DESTINATION lib' "DESTINATION ''${!outputInclude}/lib" + ''; + + strictDeps = true; + + preConfigure = '' + appendToVar cmakeFlags -DCMAKE_Swift_COMPILER_TARGET=${stdenv.hostPlatform.swift.triple} + appendToVar cmakeFlags -DCMAKE_Swift_FLAGS=-module-cache-path\ "$NIX_BUILD_TOP/module-cache" + ''; + + nativeBuildInputs = [ + cmake + ninja + swift + ]; + + buildInputs = [ + swift-asn1 + swift-crypto + ]; + + postInstall = '' + # Install CMake config file for the Swift Certificates library. + mkdir -p "''${!outputDev}/lib/cmake/SwiftCertificates" + substitute ${./files/SwiftCertificatesConfig.cmake} "''${!outputDev}/lib/cmake/SwiftCertificates/SwiftCertificatesConfig.cmake" \ + --replace-fail '@buildType@' ${if stdenv.hostPlatform.isStatic then "STATIC" else "SHARED"} \ + --replace-fail '@include@' "''${!outputDev}" \ + --replace-fail '@lib@' "''${!outputLib}" \ + --replace-fail '@swiftPlatform@' ${stdenv.hostPlatform.swift.platform} + ''; + + passthru.updateScript = gitUpdater { }; + + __structuredAttrs = true; + + meta = { + homepage = "https://github.com/apple/swift-certificates"; + description = "An implementation of X.509 for Swift"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) From 272e07e6ee6b9ad37bc9ebd3791870831533cb78 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 216/423] swiftPackages_ng.swift-system: init at 1.8.1 --- .../files/SwiftSystemConfig.cmake | 11 +++ .../by-name/sw/swift-system/package.nix | 68 +++++++++++++++++++ .../patches/0001-gnu-install-dirs.patch | 23 +++++++ 3 files changed, 102 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-system/files/SwiftSystemConfig.cmake create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-system/package.nix create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-system/patches/0001-gnu-install-dirs.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-system/files/SwiftSystemConfig.cmake b/pkgs/development/compilers/swift_ng/by-name/sw/swift-system/files/SwiftSystemConfig.cmake new file mode 100644 index 000000000000..cbf2d99fe6f2 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-system/files/SwiftSystemConfig.cmake @@ -0,0 +1,11 @@ +add_library(CSystem STATIC IMPORTED) +set_target_properties(CSystem PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_STATIC_LIBRARY_PREFIX}CSystem${CMAKE_STATIC_LIBRARY_SUFFIX}" +) + +add_library(SwiftSystem::SystemPackage STATIC IMPORTED) +set_target_properties(SwiftSystem::SystemPackage PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_STATIC_LIBRARY_PREFIX}SystemPackage${CMAKE_STATIC_LIBRARY_SUFFIX}" + INTERFACE_LINK_LIBRARIES CSystem + INTERFACE_INCLUDE_DIRECTORIES "@dev@/include;@dev@/lib/swift_static/@swiftPlatform@" +) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-system/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift-system/package.nix new file mode 100644 index 000000000000..86b008c41746 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-system/package.nix @@ -0,0 +1,68 @@ +{ + lib, + cmake, + fetchFromGitHub, + gitUpdater, + ninja, + stdenv, + swift, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "swift-system"; + version = "1.8.1"; + + outputs = [ + "out" + "dev" + ]; + + src = fetchFromGitHub { + owner = "apple"; + repo = "swift-system"; + tag = finalAttrs.version; + hash = "sha256-mnQcCHYW0oCadmIE9ayjs3aZiCVQRuliQ0qWpQ22OFQ="; + }; + + patches = [ ./patches/0001-gnu-install-dirs.patch ]; + + strictDeps = true; + + preConfigure = '' + appendToVar cmakeFlags -DCMAKE_Swift_COMPILER_TARGET=${stdenv.hostPlatform.swift.triple} + appendToVar cmakeFlags -DCMAKE_Swift_FLAGS=-module-cache-path\ "$NIX_BUILD_TOP/module-cache" + ''; + + nativeBuildInputs = [ + cmake + ninja + swift + ]; + + postInstall = '' + moveToOutput lib/swift "''${!outputDev}" + moveToOutput lib/swift_static "''${!outputDev}" + + # This isn’t installed by the upstream CMake files, but it’s needed. + cp lib/libCSystem.a "$out/lib/libCSystem.a" + + # Install CMake config file for Swift System. + mkdir -p "''${!outputDev}/lib/cmake/SwiftSystem" + substitute ${./files/SwiftSystemConfig.cmake} "''${!outputDev}/lib/cmake/SwiftSystem/SwiftSystemConfig.cmake" \ + --replace-fail '@dev@' "''${!outputDev}" \ + --replace-fail '@lib@' "''${!outputLib}" \ + --replace-fail '@swiftPlatform@' ${stdenv.hostPlatform.swift.platform} + ''; + + __structuredAttrs = true; + + passthru.updateScript = gitUpdater { }; + + meta = { + homepage = "https://github.com/apple/swift-system"; + description = "Low-level APIs and types for Swift"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-system/patches/0001-gnu-install-dirs.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swift-system/patches/0001-gnu-install-dirs.patch new file mode 100644 index 000000000000..aa9bdeb78adc --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-system/patches/0001-gnu-install-dirs.patch @@ -0,0 +1,23 @@ +From ab44a593012e8092bd17c63aba77641993624f12 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Wed, 17 Dec 2025 20:59:10 -0500 +Subject: [PATCH] gnu-install-dirs + +--- + Sources/CSystem/CMakeLists.txt | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/Sources/CSystem/CMakeLists.txt b/Sources/CSystem/CMakeLists.txt +index faf730e..0860dbc 100644 +--- a/Sources/CSystem/CMakeLists.txt ++++ b/Sources/CSystem/CMakeLists.txt +@@ -16,5 +16,5 @@ install(FILES + include/CSystemLinux.h + include/CSystemWindows.h + include/module.modulemap +- DESTINATION include/CSystem) ++ DESTINATION "${CMAKE_INSTALL_INCLUDEDIR}") + set_property(GLOBAL APPEND PROPERTY SWIFT_SYSTEM_EXPORTS CSystem) +-- +2.50.1 + From 884c04f8ed82b888ceaf3fd29600a94e4d029a4b Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 217/423] swiftPackages_ng.swift-build: init at 6.2.4 --- .../by-name/sw/swift-build/extra-bins/copypng | 64 + .../sw/swift-build/extra-bins/tiffutil | 77 ++ .../swift-build/files/SwiftBuildConfig.cmake | 11 + .../by-name/sw/swift-build/package.nix | 166 +++ .../patches/0001-replace-impure-paths.patch | 1090 +++++++++++++++++ .../0002-treat-nixpkgs-sdk-as-xcode.patch | 49 + .../patches/0003-find-bundles-in-store.patch | 48 + .../compilers/swift_ng/sources-6.2.json | 3 + 8 files changed, 1508 insertions(+) create mode 100755 pkgs/development/compilers/swift_ng/by-name/sw/swift-build/extra-bins/copypng create mode 100755 pkgs/development/compilers/swift_ng/by-name/sw/swift-build/extra-bins/tiffutil create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-build/files/SwiftBuildConfig.cmake create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-build/package.nix create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-build/patches/0001-replace-impure-paths.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-build/patches/0002-treat-nixpkgs-sdk-as-xcode.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-build/patches/0003-find-bundles-in-store.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-build/extra-bins/copypng b/pkgs/development/compilers/swift_ng/by-name/sw/swift-build/extra-bins/copypng new file mode 100755 index 000000000000..634c339ef173 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-build/extra-bins/copypng @@ -0,0 +1,64 @@ +#!/usr/bin/env bash + +set -eu -o pipefail + +compress=false +optimize="" + +declare -a files=() + +echo "All args: $@" + +for arg in "${@}"; do + echo "Got arg: $arg" + test -n "$arg" && continue # Sometimes xcbuild passes empty arguments + case "$arg" in + -strip-PNG-text) + echo "Removing text chunks" + optimize="--strip tEXt,iTXt,zTXt" + ;; + -skip-PNGs) + echo "Not actually compressing" + compress=false + ;; + -compress) + echo "Actually in fact compressing" + compress=true + ;; + -*) + echo "warning: unrecognized option $1." >&2 + ;; + *) + echo "Adding $1 to files" + files+=("$(realpath "$1")") + ;; + esac +done + +echo "Got: ${files[@]} with length ${#files[@]}" + +case "${#files[@]}" in + 0) + echo "error: missing source and destination files" >&2 + exit 1 + ;; + 1) + echo "error: missing destination files" >&2 + exit 1 + ;; + 2) + source=${files[0]} + dest=${files[1]} + ;; + *) + echo "warning: ignoring extra files passed to \`copypng\`" + source=${files[0]} + dest=${files[1]} + ;; +esac + +if $compress; then + oxipng $optimize "$source" --force --out "$dest" +else + @coreutils@/bin/cp "$source" "$dest" +fi diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-build/extra-bins/tiffutil b/pkgs/development/compilers/swift_ng/by-name/sw/swift-build/extra-bins/tiffutil new file mode 100755 index 000000000000..b987913d59f1 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-build/extra-bins/tiffutil @@ -0,0 +1,77 @@ +#!/usr/bin/env bash + +set -eux -o pipefail + +compression="" +cmd=copy +outfile="" + +declare -a files=() + +while [ "$#" -gt 0 ]; do + test -z "$1" && continue # Sometimes xcbuild passes empty arguments + case "$1" in + -none) + compression="" + ;; + -lzw) + compression="-c lzw" + ;; + -packbits) + compression="-c packbits" + ;; + -cat) + cmd=cat + ;; + -catnosizecheck) + echo "warning: size checks are not implemented" >&2 + cmd=cat + ;; + -cathidpicheck) + echo "warning: DPI guidelines checks are not implemented" >&2 + cmd=cat + ;; + -extract) + shift + index=$1 + shift + file=$(realpath "$1") + files+=("$file,$index") + ;; + -info|-verboseinfo|-dump) + cmd=info + ;; + -out) + shift + outfile=$(realpath "$1") + ;; + *) + files+=("$(realpath "$1")") + ;; + esac + shift +done + +echo "Files: ${files[@]}" +case "${#files[@]},$cmd" in + 0,*) + echo "error: missing source and destination files" >&2 + exit 1 + ;; + 1,*) + echo "Got one file, yay" + ;; + *,copy|*,info) + echo "error: too many input files specified" + exit 1 + ;; +esac + +case $cmd in + cat|copy) + tiffcp $compression "${files[@]}" "$outfile" + ;; + info) + tiffinfo "${files[@]}" + ;; +esac diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-build/files/SwiftBuildConfig.cmake b/pkgs/development/compilers/swift_ng/by-name/sw/swift-build/files/SwiftBuildConfig.cmake new file mode 100644 index 000000000000..e3eccaa4f08b --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-build/files/SwiftBuildConfig.cmake @@ -0,0 +1,11 @@ +add_library(SwiftBuild::SwiftBuild @buildType@ IMPORTED) +set_target_properties(SwiftBuild::SwiftBuild PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}SwiftBuild${CMAKE_@buildType@_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@include@/include;@include@/lib/swift/@swiftPlatform@" +) + +add_library(SwiftBuild::SWBBuildService @buildType@ IMPORTED) +set_target_properties(SwiftBuild::SWBBuildService PROPERTIES + IMPORTED_LOCATION "@lib@/lib/${CMAKE_@buildType@_LIBRARY_PREFIX}SWBBuildService${CMAKE_@buildType@_LIBRARY_SUFFIX}" + INTERFACE_INCLUDE_DIRECTORIES "@include@/include;@include@/lib/swift/@swiftPlatform@" +) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-build/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift-build/package.nix new file mode 100644 index 000000000000..e13b8b65de2f --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-build/package.nix @@ -0,0 +1,166 @@ +{ + lib, + cmake, + coreutils, + darwin, + diffutils, + fetchFromGitHub, + gnused, + libiconv, + libtiff, + llvmPackages_upstream, + llvm_libtool, + ninja, + oxipng, + replaceVars, + sqlite, + stdenv, + stdenvNoCC, + swift, + swift-argument-parser, + swift-driver, + swift-llbuild, + swift-system, + swift-tools-support-core, + xcbuild, + swift_release, + swift_sources, +}: + +let + graphics_cmds = stdenvNoCC.mkDerivation { + pname = "graphics_cmds"; + version = "1"; + + # Note: These depend on oxipng and tools from libtiff, but we don’t want to pull them into the Swift Build + # closure unnecessarily. Packages using those commands will have to add them themselves. + buildCommand = '' + install -m755 -D ${replaceVars ./extra-bins/copypng { inherit coreutils; }} "$out/bin/copypng" + install -m755 -D ${replaceVars ./extra-bins/tiffutil { }} "$out/bin/tiffutil" + ''; + }; + + swiftPlatform = stdenv.hostPlatform.swift.platform; +in + +# Swift Build is a dependency of SwiftPM. It must be built with CMake to avoid dependency cycles. +stdenv.mkDerivation (finalAttrs: { + pname = "swift-build"; + version = swift_release; + + outputs = [ + "out" + "dev" + "lib" + ]; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-build"; + tag = "swift-${finalAttrs.version}-RELEASE"; + inherit (swift_sources.swift-build) hash; + }; + + patches = [ + # Remove as many impure paths as possible. + (replaceVars ./patches/0001-replace-impure-paths.patch { + xcrun = if stdenv.hostPlatform.isDarwin then xcbuild.xcrun else "/not-supported"; + inherit graphics_cmds; + coreutils = lib.getBin coreutils; + diffutils = lib.getBin diffutils; + gnused = lib.getBin gnused; + libiconv = lib.getBin libiconv; + libtool = lib.getBin llvm_libtool; + llvm = lib.getBin llvmPackages_upstream.llvm; + shell_cmds = + if stdenv.hostPlatform.isDarwin then lib.getBin darwin.shell_cmds else "/not-supported"; + sigtool = lib.getBin darwin.sigtool; + }) + # Swift Build checks whether the SDK is Xcode by looking at the `DEVELOPER_DIR` path for Xcode. + # Have it treat store paths as being Xcode SDKs so that the nixpkgs SDK is treated as a Darwin platform. + (replaceVars ./patches/0002-treat-nixpkgs-sdk-as-xcode.patch { + store-dir = builtins.storeDir; + }) + # Don’t look in the build directory for bundles. Look only in the store. + ./patches/0003-find-bundles-in-store.patch + ]; + + # FIXME: Make this a patch + postPatch = '' + # Allow Swift Build to find `SWBBuildServiceBundle` in `$out/libexec`. + substituteInPlace Sources/SwiftBuild/SWBBuildServiceConnection.swift \ + --replace-fail 'Bundle(for: SWBBuildServiceConnection.self).bundleURL.deletingLastPathComponent()' 'URL(filePath: "@lib@/libexec")' \ + --replace-fail 'Bundle.main.executableURL?.deletingLastPathComponent()' '.some(URL(filePath: "@lib@/libexec"))?' \ + --replace-fail '@lib@' "''${!outputLib}" + + # Use the path to `swift` to find the plugin server binary + substituteInPlace Sources/SWBCore/Settings/Settings.swift \ + --replace-fail '\(toolchain.path.str)/usr/bin/swift-plugin-server' ${lib.getExe' swift.swiftc "swift-plugin-server"} + ''; + + strictDeps = true; + + cmakeFlags = [ + # The CMake hook doesn’t set `${CMAKE_INSTALL_DATADIR}` to a store path, so it needs to be specified manually. + (lib.cmakeFeature "CMAKE_INSTALL_DATADIR" "${placeholder "lib"}/share") + ]; + + preConfigure = '' + appendToVar cmakeFlags -DCMAKE_Swift_COMPILER_TARGET=${stdenv.hostPlatform.swift.triple} + appendToVar cmakeFlags -DCMAKE_Swift_FLAGS=-module-cache-path\ "$NIX_BUILD_TOP/module-cache" + ''; + + nativeBuildInputs = [ + cmake + ninja + swift + ]; + + buildInputs = [ + sqlite + swift-argument-parser + swift-driver + swift-llbuild + swift-system + swift-tools-support-core + ]; + + # Needed for `fixDarwinDylibNames` to work. + env.NIX_LDFLAGS = lib.optionalString stdenv.hostPlatform.isDarwin "-headerpad_max_install_names"; + + postInstall = '' + mkdir -p "''${!outputLib}/libexec" + mv "''${!outputBin}/bin/SWBBuildServiceBundle" "''${!outputLib}/libexec/SWBBuildServiceBundle" + + # Install the swiftmodules. + mkdir -p "''${!outputDev}/lib/swift/${swiftPlatform}" + cp -v swift/*.swiftmodule "''${!outputDev}/lib/swift/${swiftPlatform}" + + # Install the C module + mkdir -p "''${!outputDev}/include" + cp -v "$NIX_BUILD_TOP/$sourceRoot/Sources/SWBCLibc/include"/*.h "''${!outputDev}/include" + cp -v "$NIX_BUILD_TOP/$sourceRoot/Sources/SWBCSupport"/*.h "''${!outputDev}/include" + cat \ + "$NIX_BUILD_TOP/$sourceRoot/Sources/SWBCLibc/include/module.modulemap" \ + "$NIX_BUILD_TOP/$sourceRoot/Sources/SWBCSupport/module.modulemap" \ + > "''${!outputDev}/include/module.modulemap" + + # Install CMake config file for the Swift Build library. + mkdir -p "''${!outputDev}/lib/cmake/SwiftBuild" + substitute ${./files/SwiftBuildConfig.cmake} "''${!outputDev}/lib/cmake/SwiftBuild/SwiftBuildConfig.cmake" \ + --replace-fail '@buildType@' ${if stdenv.hostPlatform.isStatic then "STATIC" else "SHARED"} \ + --replace-fail '@include@' "''${!outputDev}" \ + --replace-fail '@lib@' "''${!outputLib}" \ + --replace-fail '@swiftPlatform@' ${swiftPlatform} + ''; + + __structuredAttrs = true; + + meta = { + homepage = "https://github.com/swiftlang/swift-build"; + description = "High-level build system based on llbuild"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-build/patches/0001-replace-impure-paths.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swift-build/patches/0001-replace-impure-paths.patch new file mode 100644 index 000000000000..8a22a52cebe8 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-build/patches/0001-replace-impure-paths.patch @@ -0,0 +1,1090 @@ +From 10f011cf8753c2175456a850b51c9968b2908081 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Tue, 9 Dec 2025 20:57:45 -0500 +Subject: [PATCH] replace-impure-paths + +--- + Plugins/run-xcodebuild/run-xcodebuild.swift | 2 +- + Sources/SWBAndroidPlatform/Plugin.swift | 2 +- + Sources/SWBBuildService/Messages.swift | 2 +- + .../CommandLineToolSpec.swift | 2 +- + .../SpecImplementations/Tools/CodeSign.swift | 2 +- + .../SpecImplementations/Tools/TouchTool.swift | 2 +- + Sources/SWBCore/Specs/CoreBuildSystem.xcspec | 2 +- + .../SWBCore/Specs/NativeBuildSystem.xcspec | 10 ++-- + Sources/SWBGenericUnixPlatform/Plugin.swift | 4 +- + .../SWBTaskExecution/BuildDescription.swift | 4 +- + .../TaskActions/CopyTiffTaskAction.swift | 2 +- + .../EmbedSwiftStdLibTaskAction.swift | 2 +- + Sources/SWBTestSupport/CoreBasedTests.swift | 6 +-- + Sources/SWBTestSupport/FSUtilities.swift | 4 +- + .../SWBTestSupport/LibraryGeneration.swift | 4 +- + Sources/SWBTestSupport/Xcode.swift | 2 +- + .../Specs/CodeSign.xcspec | 2 +- + Sources/SWBUtil/Signatures.swift | 2 +- + .../CoreQualificationTester.swift | 2 +- + Tests/SWBCoreTests/CommandLineSpecTests.swift | 2 +- + .../CodeSignTaskConstructionTests.swift | 48 +++++++++---------- + .../MergeableLibraryTests.swift | 10 ++-- + .../PlatformTaskConstructionTests.swift | 8 ++-- + .../PostprocessingTaskConstructionTests.swift | 4 +- + .../SwiftTaskConstructionTests.swift | 6 +-- + .../TaskConstructionTests.swift | 26 +++++----- + .../UnitTestTaskConstructionTests.swift | 12 ++--- + .../WatchTaskConstructionTests.swift | 12 ++--- + .../SignatureCollectionActionTests.swift | 4 +- + Tests/SWBUtilTests/MiscTests.swift | 2 +- + Tests/SWBUtilTests/SignaturesTests.swift | 4 +- + .../SwiftBuildTests/BuildOperationTests.swift | 16 +++---- + 32 files changed, 106 insertions(+), 106 deletions(-) + +diff --git a/Plugins/run-xcodebuild/run-xcodebuild.swift b/Plugins/run-xcodebuild/run-xcodebuild.swift +index 710a84a..c83982d 100644 +--- a/Plugins/run-xcodebuild/run-xcodebuild.swift ++++ b/Plugins/run-xcodebuild/run-xcodebuild.swift +@@ -39,7 +39,7 @@ struct RunXcodebuild: CommandPlugin { + } + + let process = Process() +- process.executableURL = URL(fileURLWithPath: "/usr/bin/xcrun") ++ process.executableURL = URL(fileURLWithPath: "@xcrun@/bin/xcrun") + process.arguments = ["xcodebuild"] + args.remainingArguments + process.environment = ProcessInfo.processInfo.environment.merging(["XCBBUILDSERVICE_PATH": buildServiceURL.path()]) { _, new in new } + try await process.run() +diff --git a/Sources/SWBAndroidPlatform/Plugin.swift b/Sources/SWBAndroidPlatform/Plugin.swift +index 117e7c6..6014cad 100644 +--- a/Sources/SWBAndroidPlatform/Plugin.swift ++++ b/Sources/SWBAndroidPlatform/Plugin.swift +@@ -118,7 +118,7 @@ struct AndroidPlatformExtension: PlatformInfoExtension { + "GENERATE_TEXT_BASED_STUBS": "NO", + "GENERATE_INTERMEDIATE_TEXT_BASED_STUBS": "NO", + +- "CHOWN": "/usr/bin/chown", ++ "CHOWN": "@coreutils@/bin/chown", + + "LIBTOOL": .plString(host.imageFormat.executableName(basename: "llvm-lib")), + "AR": .plString(host.imageFormat.executableName(basename: "llvm-ar")), +diff --git a/Sources/SWBBuildService/Messages.swift b/Sources/SWBBuildService/Messages.swift +index 070b5d3..47c7c3b 100644 +--- a/Sources/SWBBuildService/Messages.swift ++++ b/Sources/SWBBuildService/Messages.swift +@@ -192,7 +192,7 @@ extension SetSessionWorkspaceContainerPathRequest: PIFProvidingRequest { + try fs.createDirectory(dir, recursive: true) + let pifPath = dir.join(Foundation.UUID().description + ".json") + let argument = isProject ? "-project" : "-workspace" +- let result = try await Process.getOutput(url: URL(fileURLWithPath: "/usr/bin/xcrun"), arguments: ["xcodebuild", "-dumpPIF", pifPath.str, argument, path.str], currentDirectoryURL: URL(fileURLWithPath: containerPath.dirname.str, isDirectory: true), environment: Environment.current.addingContents(of: [.developerDir: session.core.developerPath.path.str])) ++ let result = try await Process.getOutput(url: URL(fileURLWithPath: "@xcrun@/bin/xcrun"), arguments: ["xcodebuild", "-dumpPIF", pifPath.str, argument, path.str], currentDirectoryURL: URL(fileURLWithPath: containerPath.dirname.str, isDirectory: true), environment: Environment.current.addingContents(of: [.developerDir: session.core.developerPath.path.str])) + if !result.exitStatus.isSuccess { + throw StubError.error("Could not dump PIF for '\(path.str)': \(String(decoding: result.stderr, as: UTF8.self))") + } +diff --git a/Sources/SWBCore/SpecImplementations/CommandLineToolSpec.swift b/Sources/SWBCore/SpecImplementations/CommandLineToolSpec.swift +index 116a390..66d030f 100644 +--- a/Sources/SWBCore/SpecImplementations/CommandLineToolSpec.swift ++++ b/Sources/SWBCore/SpecImplementations/CommandLineToolSpec.swift +@@ -246,7 +246,7 @@ extension DiscoveredCommandLineToolSpecInfo { + if !toolPath.isAbsolute { + throw StubError.error("\(toolPath.str) is not absolute") + } +- return try await producer.discoveredCommandLineToolSpecInfo(delegate, toolPath.basename, ["/usr/bin/what", "-q", toolPath.str]) { executionResult in ++ return try await producer.discoveredCommandLineToolSpecInfo(delegate, toolPath.basename, ["@shell_cmds@/bin/what", "-q", toolPath.str]) { executionResult in + let outputString = String(decoding: executionResult.stdout, as: UTF8.self).trimmingCharacters(in: .whitespacesAndNewlines) + let lines = Set(outputString.split(separator: "\n").map(String.init)) // version info is printed once per architecture slice, but we never expect them to differ + return try construct(AppleGenericVersionInfo(string: lines.only ?? outputString)) +diff --git a/Sources/SWBCore/SpecImplementations/Tools/CodeSign.swift b/Sources/SWBCore/SpecImplementations/Tools/CodeSign.swift +index d8d7ead..ea8fb21 100644 +--- a/Sources/SWBCore/SpecImplementations/Tools/CodeSign.swift ++++ b/Sources/SWBCore/SpecImplementations/Tools/CodeSign.swift +@@ -20,7 +20,7 @@ public final class CodesignToolSpec : CommandLineToolSpec, SpecIdentifierType, @ + public override func computeExecutablePath(_ cbc: CommandBuildContext) -> String { + var codesign = Path(cbc.scope.evaluate(BuiltinMacros.CODESIGN)) + if codesign.isEmpty { +- codesign = Path("/usr/bin/codesign") ++ codesign = Path("@sigtool@/bin/codesign") + } + if !codesign.isAbsolute { + codesign = resolveExecutablePath(cbc, codesign) +diff --git a/Sources/SWBCore/SpecImplementations/Tools/TouchTool.swift b/Sources/SWBCore/SpecImplementations/Tools/TouchTool.swift +index e6997b7..9644d09 100644 +--- a/Sources/SWBCore/SpecImplementations/Tools/TouchTool.swift ++++ b/Sources/SWBCore/SpecImplementations/Tools/TouchTool.swift +@@ -45,7 +45,7 @@ final class TouchToolSpec : CommandLineToolSpec, SpecIdentifierType, @unchecked + // FIXME: Need to properly quote the path here, or generally handle this better + commandLine = [commandShellPath, "/c", "copy /b \"\(input.absolutePath.str)\" +,,"] + } else { +- commandLine = ["/usr/bin/touch", "-c", input.absolutePath.str] ++ commandLine = ["@coreutils@/bin/touch", "-c", input.absolutePath.str] + } + + delegate.createTask(type: self, ruleInfo: ["Touch", input.absolutePath.str], commandLine: commandLine, environment: EnvironmentBindings(), workingDirectory: cbc.producer.defaultWorkingDirectory, inputs: [delegate.createNode(input.absolutePath)], outputs: outputs, mustPrecede: [], action: delegate.taskActionCreationDelegate.createDeferredExecutionTaskActionIfRequested(userPreferences: cbc.producer.userPreferences), execDescription: resolveExecutionDescription(cbc, delegate, lookup: outputFileOverride), enableSandboxing: enableSandboxing) +diff --git a/Sources/SWBCore/Specs/CoreBuildSystem.xcspec b/Sources/SWBCore/Specs/CoreBuildSystem.xcspec +index 467e061..cee7bd1 100644 +--- a/Sources/SWBCore/Specs/CoreBuildSystem.xcspec ++++ b/Sources/SWBCore/Specs/CoreBuildSystem.xcspec +@@ -3176,7 +3176,7 @@ For more information on mergeable libraries, see [Configuring your project to us + { + Name = "JAVA_COMPILER"; + Type = Path; +- DefaultValue = "/usr/bin/javac"; ++ DefaultValue = "javac"; + }, + { + Name = "JAVA_ARCHIVE_CLASSES"; +diff --git a/Sources/SWBCore/Specs/NativeBuildSystem.xcspec b/Sources/SWBCore/Specs/NativeBuildSystem.xcspec +index b4fcfa8..79f4b99 100644 +--- a/Sources/SWBCore/Specs/NativeBuildSystem.xcspec ++++ b/Sources/SWBCore/Specs/NativeBuildSystem.xcspec +@@ -823,23 +823,23 @@ When `GENERATE_INFOPLIST_FILE` is enabled, sets the value of the [CFBundleExecut + }, + { Name = ICONV; + Type = Path; +- DefaultValue = "/usr/bin/iconv"; ++ DefaultValue = "@libiconv@/bin/iconv"; + }, + { Name = SED; + Type = Path; +- DefaultValue = "/usr/bin/sed"; ++ DefaultValue = "@gnused@/bin/sed"; + }, + { Name = CHOWN; + Type = Path; +- DefaultValue = "/usr/sbin/chown"; ++ DefaultValue = "@coreutils@/bin/chown"; + }, + { Name = CHMOD; + Type = Path; +- DefaultValue = "/bin/chmod"; ++ DefaultValue = "@coreutils@/bin/chmod"; + }, + { Name = DIFF; + Type = Path; +- DefaultValue = "/usr/bin/diff"; ++ DefaultValue = "@diffutils@/bin/diff"; + }, + + // Utility settings +diff --git a/Sources/SWBGenericUnixPlatform/Plugin.swift b/Sources/SWBGenericUnixPlatform/Plugin.swift +index 632a4ca..5b18fc4 100644 +--- a/Sources/SWBGenericUnixPlatform/Plugin.swift ++++ b/Sources/SWBGenericUnixPlatform/Plugin.swift +@@ -120,8 +120,8 @@ struct GenericUnixSDKRegistryExtension: SDKRegistryExtension { + "GENERATE_TEXT_BASED_STUBS": "NO", + "GENERATE_INTERMEDIATE_TEXT_BASED_STUBS": "NO", + +- "CHOWN": "/usr/bin/chown", +- "AR": "llvm-ar", ++ "CHOWN": "@coreutils@/bin/chown", ++ "AR": "@llvm@/bin/llvm-ar", + ] + default: + defaultProperties = [:] +diff --git a/Sources/SWBTaskExecution/BuildDescription.swift b/Sources/SWBTaskExecution/BuildDescription.swift +index 53aae73..15fc1ea 100644 +--- a/Sources/SWBTaskExecution/BuildDescription.swift ++++ b/Sources/SWBTaskExecution/BuildDescription.swift +@@ -896,7 +896,7 @@ package final class BuildDescriptionBuilder { + + var commandLine = commandLine + if bypassActualTasks { +- commandLine = [ByteString(encodingAsUTF8: "/usr/bin/true")] + commandLine ++ commandLine = [ByteString(encodingAsUTF8: "@coreutils@/bin/true")] + commandLine + } + + // Add the command definition. +@@ -976,7 +976,7 @@ package final class BuildDescriptionBuilder { + func addCustomCommand(_ task: any PlannedTask, tool: String, inputs: [any PlannedNode], outputs: [any PlannedNode], deps: DependencyDataStyle? = nil, allowMissingInputs: Bool, alwaysOutOfDate: Bool, description: [String]) throws { + // Honor `bypassActualTasks`. + if bypassActualTasks { +- try addSubprocessCommand(task, inputs: inputs, outputs: outputs, description: description, commandLine: ["/usr/bin/true"], allowMissingInputs: allowMissingInputs, alwaysOutOfDate: alwaysOutOfDate, isUnsafeToInterrupt: false) ++ try addSubprocessCommand(task, inputs: inputs, outputs: outputs, description: description, commandLine: ["@coreutils@/bin/true"], allowMissingInputs: allowMissingInputs, alwaysOutOfDate: alwaysOutOfDate, isUnsafeToInterrupt: false) + return + } + +diff --git a/Sources/SWBTaskExecution/TaskActions/CopyTiffTaskAction.swift b/Sources/SWBTaskExecution/TaskActions/CopyTiffTaskAction.swift +index df1675a..9e4b37c 100644 +--- a/Sources/SWBTaskExecution/TaskActions/CopyTiffTaskAction.swift ++++ b/Sources/SWBTaskExecution/TaskActions/CopyTiffTaskAction.swift +@@ -141,7 +141,7 @@ public final class CopyTiffTaskAction: TaskAction { + + // If we have a compression argument, pass through tiffutil. + if let compression = options.compression { +- let tiffutilCommand = ["/usr/bin/tiffutil", "-\(compression)", input.str, "-out", output.str] ++ let tiffutilCommand = ["@graphics_cmds@/bin/tiffutil", "-\(compression)", input.str, "-out", output.str] + + let processDelegate = TaskProcessDelegate(outputDelegate: outputDelegate) + do { +diff --git a/Sources/SWBTaskExecution/TaskActions/EmbedSwiftStdLibTaskAction.swift b/Sources/SWBTaskExecution/TaskActions/EmbedSwiftStdLibTaskAction.swift +index 40509fc..e2a3ae6 100644 +--- a/Sources/SWBTaskExecution/TaskActions/EmbedSwiftStdLibTaskAction.swift ++++ b/Sources/SWBTaskExecution/TaskActions/EmbedSwiftStdLibTaskAction.swift +@@ -847,7 +847,7 @@ public final class EmbedSwiftStdLibTaskAction: TaskAction { + // Codesign the Swift libraries in $build_dir/$frameworks + // but not the libraries in $build_dir/$unsigned_frameworks. + if codeSignIdentity != nil && !swiftLibs.isEmpty { +- let codesign = Path(self.effectiveEnvironment["CODESIGN"] ?? "/usr/bin/codesign") ++ let codesign = Path(self.effectiveEnvironment["CODESIGN"] ?? "@sigtool@/bin/codesign") + + // Swift libraries that are up-to-date get codesigned anyway + // (in case options changed or a previous build was incomplete). +diff --git a/Sources/SWBTestSupport/CoreBasedTests.swift b/Sources/SWBTestSupport/CoreBasedTests.swift +index ff76cf5..4d3ea5c 100644 +--- a/Sources/SWBTestSupport/CoreBasedTests.swift ++++ b/Sources/SWBTestSupport/CoreBasedTests.swift +@@ -227,9 +227,9 @@ extension CoreBasedTests { + package var libtoolPath: Path { + get async throws { + let (core, defaultToolchain) = try await coreAndToolchain() +- let fallbacklibtool = Path("/usr/bin/libtool") ++ let fallbacklibtool = Path("@libtool@/bin/libtool") + return try #require(defaultToolchain.executableSearchPaths.findExecutable(operatingSystem: core.hostOperatingSystem, basename: "libtool") +- ?? defaultToolchain.executableSearchPaths.findExecutable(operatingSystem: core.hostOperatingSystem, basename: "llvm-ar") ++ ?? defaultToolchain.executableSearchPaths.findExecutable(operatingSystem: core.hostOperatingSystem, basename: "@llvm@/bin/llvm-ar") + ?? (localFS.exists(fallbacklibtool) ? fallbacklibtool : nil), "couldn't find libtool in default toolchain") + } + } +@@ -238,7 +238,7 @@ extension CoreBasedTests { + package var llvmlibPath: Path { + get async throws { + let (core, defaultToolchain) = try await coreAndToolchain() +- let fallbacklibtool = Path("/usr/bin/llvm-lib") ++ let fallbacklibtool = Path("@llvm@/bin/llvm-lib") + return try #require(defaultToolchain.executableSearchPaths.findExecutable(operatingSystem: core.hostOperatingSystem, basename: "llvm-lib") ?? (localFS.exists(fallbacklibtool) ? fallbacklibtool : nil), "couldn't find llvm-lib in default toolchain") + } + } +diff --git a/Sources/SWBTestSupport/FSUtilities.swift b/Sources/SWBTestSupport/FSUtilities.swift +index e95573a..972df55 100644 +--- a/Sources/SWBTestSupport/FSUtilities.swift ++++ b/Sources/SWBTestSupport/FSUtilities.swift +@@ -325,9 +325,9 @@ package extension FSProxy { + + if self === localFS { + if !shallow { +- _ = try await runProcess(["/usr/bin/codesign", "-s", "-", binary.join(path.basenameWithoutSuffix).str]) ++ _ = try await runProcess(["@sigtool@/bin/codesign", "-s", "-", binary.join(path.basenameWithoutSuffix).str]) + } +- _ = try await runProcess(["/usr/bin/codesign", "-s", "-", (shallow ? path : contents).str]) ++ _ = try await runProcess(["@sigtool@/bin/codesign", "-s", "-", (shallow ? path : contents).str]) + } else { + try await writeFileContents(contents.join("_CodeSignature/CodeSignature")) { $0 <<< "signature" } + } +diff --git a/Sources/SWBTestSupport/LibraryGeneration.swift b/Sources/SWBTestSupport/LibraryGeneration.swift +index 1a23807..3f750f3 100644 +--- a/Sources/SWBTestSupport/LibraryGeneration.swift ++++ b/Sources/SWBTestSupport/LibraryGeneration.swift +@@ -87,7 +87,7 @@ extension InstalledXcode { + let linkArgs = [["-sdk", platform.sdkName, "clang", "-dynamiclib", "-target", target], targetVariantArgs, linkerArgs, ["-L" + swiftRuntimeLibraryDirectoryPath(name: platform.sdkName), "-L/usr/lib/swift", "-o", machoPath.str, objectPath.str]].reduce([], +) + _ = try await xcrun(linkArgs, workingDirectory: workingDirectory) + if needSigned { +- _ = try await runProcessWithDeveloperDirectory(["/usr/bin/codesign", "-s", "-", machoPath.str]) ++ _ = try await runProcessWithDeveloperDirectory(["@sigtool@/bin/codesign", "-s", "-", machoPath.str]) + } + return machoPath + } +@@ -178,7 +178,7 @@ extension InstalledXcode { + } else { + _ = try await xcrun(["-sdk", platform.sdkName, "clang", "-dynamiclib", "-target", target] + targetVariantArgs + linkerArgs + ["-o", machoPath.str, objectPath.str]) + if needSigned { +- _ = try await runProcessWithDeveloperDirectory(["/usr/bin/codesign", "-s", "-", machoPath.str]) ++ _ = try await runProcessWithDeveloperDirectory(["@sigtool@/bin/codesign", "-s", "-", machoPath.str]) + } + machos.append(machoPath) + } +diff --git a/Sources/SWBTestSupport/Xcode.swift b/Sources/SWBTestSupport/Xcode.swift +index 969fc92..087816c 100644 +--- a/Sources/SWBTestSupport/Xcode.swift ++++ b/Sources/SWBTestSupport/Xcode.swift +@@ -32,7 +32,7 @@ package struct InstalledXcode: Sendable { + } + + package func xcrun(_ args: [String], workingDirectory: Path? = nil, redirectStderr: Bool = true) async throws -> String { +- return try await runProcessWithDeveloperDirectory(["/usr/bin/xcrun"] + args, workingDirectory: workingDirectory, overrideDeveloperDirectory: self.developerDirPath.str, redirectStderr: redirectStderr) ++ return try await runProcessWithDeveloperDirectory(["@xcrun@/bin/xcrun"] + args, workingDirectory: workingDirectory, overrideDeveloperDirectory: self.developerDirPath.str, redirectStderr: redirectStderr) + } + + package func productBuildVersion() throws -> ProductBuildVersion { +diff --git a/Sources/SWBUniversalPlatform/Specs/CodeSign.xcspec b/Sources/SWBUniversalPlatform/Specs/CodeSign.xcspec +index 02ec3dd..51629c9 100644 +--- a/Sources/SWBUniversalPlatform/Specs/CodeSign.xcspec ++++ b/Sources/SWBUniversalPlatform/Specs/CodeSign.xcspec +@@ -17,7 +17,7 @@ + Description = "Code-sign a framework, application, or other built target."; + ExecDescription = "Sign $(InputFileName)"; + ProgressDescription = "Signing product"; +- ExecPath = "/usr/bin/codesign"; ++ ExecPath = "@sigtool@/bin/codesign"; + // codesign is currently not safe to interrupt, tracked by 20712615. + IsUnsafeToInterrupt = YES; + CommandOutputParser = ( +diff --git a/Sources/SWBUtil/Signatures.swift b/Sources/SWBUtil/Signatures.swift +index eb3c1e2..180dcc6 100644 +--- a/Sources/SWBUtil/Signatures.swift ++++ b/Sources/SWBUtil/Signatures.swift +@@ -140,7 +140,7 @@ public struct CodeSignatureInfo: Codable, Sendable { + + static public func invokeCodesignVerification(for path: String, treatUnsignedAsError: Bool) async throws { + #if os(macOS) +- let executionResult = try await Process.getOutput(url: URL(filePath: "/usr/bin/codesign"), arguments: ["-vvvv", path]) ++ let executionResult = try await Process.getOutput(url: URL(filePath: "@sigtool@/bin/codesign"), arguments: ["-vvvv", path]) + let stdoutContent = String(data: executionResult.stdout, encoding: .utf8)?.trimmingCharacters(in: .whitespacesAndNewlines) ?? "" + let stderrContent = String(data: executionResult.stderr, encoding: .utf8)?.trimmingCharacters(in: .whitespacesAndNewlines) ?? "" + +diff --git a/Sources/SwiftBuildTestSupport/CoreQualificationTester.swift b/Sources/SwiftBuildTestSupport/CoreQualificationTester.swift +index 8495d9f..1e4dd60 100644 +--- a/Sources/SwiftBuildTestSupport/CoreQualificationTester.swift ++++ b/Sources/SwiftBuildTestSupport/CoreQualificationTester.swift +@@ -326,7 +326,7 @@ extension FileContentsCheckingResult { + let plist: PropertyListItem? + switch destination { + case .signed: +- let bytes = try await Array(xcode.xcrun(["/usr/bin/codesign", "-a", slice.arch, "-d", "--entitlements", ":-", binaryPath.str], redirectStderr: false).utf8) ++ let bytes = try await Array(xcode.xcrun(["@sigtool@/bin/codesign", "-a", slice.arch, "-d", "--entitlements", ":-", binaryPath.str], redirectStderr: false).utf8) + plist = try !bytes.isEmpty ? PropertyList.fromBytes(bytes) : nil + case .simulated: + // xcrun otool-classic [-arch arch] -X -s __TEXT __entitlements +diff --git a/Tests/SWBCoreTests/CommandLineSpecTests.swift b/Tests/SWBCoreTests/CommandLineSpecTests.swift +index 77813bc..03df67f 100644 +--- a/Tests/SWBCoreTests/CommandLineSpecTests.swift ++++ b/Tests/SWBCoreTests/CommandLineSpecTests.swift +@@ -1721,7 +1721,7 @@ import SWBMacro + let commandShellPath = try #require(getEnvironmentVariable("ComSpec"), "Can't determine path to cmd.exe because the ComSpec environment variable is not set") + task.checkCommandLine([commandShellPath, "/c", "copy /b \"\(Path.root.join("tmp/input").str)\" +,,"]) + } else { +- task.checkCommandLine(["/usr/bin/touch", "-c", Path.root.join("tmp/input").str]) ++ task.checkCommandLine(["@coreutils@/bin/touch", "-c", Path.root.join("tmp/input").str]) + } + #expect(task.execDescription == "Touch input") + } +diff --git a/Tests/SWBTaskConstructionTests/CodeSignTaskConstructionTests.swift b/Tests/SWBTaskConstructionTests/CodeSignTaskConstructionTests.swift +index 33972fe..838b3d0 100644 +--- a/Tests/SWBTaskConstructionTests/CodeSignTaskConstructionTests.swift ++++ b/Tests/SWBTaskConstructionTests/CodeSignTaskConstructionTests.swift +@@ -572,7 +572,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["ENABLE_LIBRARY_VALIDATION": "YES", "ENABLE_HARDENED_RUNTIME": "YES", "CODE_SIGN_RESTRICT": "YES"]), runDestination: .macOS) { results in + results.checkTarget("macOSFramework") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "-", "-o", "library,restrict,runtime", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "-", "-o", "library,restrict,runtime", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) + } + } + +@@ -583,7 +583,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["ENABLE_LIBRARY_VALIDATION": "NO", "ENABLE_HARDENED_RUNTIME": "NO", "CODE_SIGN_RESTRICT": "NO"]), runDestination: .macOS) { results in + results.checkTarget("macOSFramework") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) + } + } + +@@ -594,7 +594,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["ENABLE_LIBRARY_VALIDATION": "NO", "ENABLE_HARDENED_RUNTIME": "NO", "CODE_SIGN_RESTRICT": "YES", "OTHER_CODE_SIGN_FLAGS": "-o library,restrict"]), runDestination: .macOS) { results in + results.checkTarget("macOSFramework") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "-", "-o", "library,restrict", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "-", "-o", "library,restrict", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) + } + } + +@@ -605,7 +605,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["ENABLE_LIBRARY_VALIDATION": "NO", "ENABLE_HARDENED_RUNTIME": "NO", "CODE_SIGN_RESTRICT": "NO", "OTHER_CODE_SIGN_FLAGS": "-o library,restrict,runtime"]), runDestination: .macOS) { results in + results.checkTarget("macOSFramework") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "-", "-o", "library,restrict,runtime", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "-", "-o", "library,restrict,runtime", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) + } + } + +@@ -616,7 +616,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["ENABLE_LIBRARY_VALIDATION": "NO", "ENABLE_HARDENED_RUNTIME": "NO", "CODE_SIGN_RESTRICT": "NO", "OTHER_CODE_SIGN_FLAGS": "-o library,restrict,runtime", "DISABLE_FREEFORM_CODE_SIGN_OPTION_FLAGS": "YES"]), runDestination: .macOS) { results in + results.checkTarget("macOSFramework") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) + } + } + +@@ -630,7 +630,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["ENABLE_LIBRARY_VALIDATION": "YES", "ENABLE_HARDENED_RUNTIME": "YES", "CODE_SIGN_RESTRICT": "YES", "OTHER_CODE_SIGN_FLAGS": "--options kill,hard,host,expires,linker-signed"]), runDestination: .macOS) { results in // ignore-unacceptable-language; codesign tool option + results.checkTarget("macOSFramework") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "-", "--options", "expires,hard,host,kill,library,linker-signed,restrict,runtime", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) // ignore-unacceptable-language; codesign tool option ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--options", "expires,hard,host,kill,library,linker-signed,restrict,runtime", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) // ignore-unacceptable-language; codesign tool option + } + } + +@@ -641,7 +641,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["ENABLE_LIBRARY_VALIDATION": "NO", "ENABLE_HARDENED_RUNTIME": "NO", "CODE_SIGN_RESTRICT": "YES", "OTHER_CODE_SIGN_FLAGS": "--options kill,hard,host,expires,linker-signed"]), runDestination: .macOS) { results in // ignore-unacceptable-language; codesign tool option + results.checkTarget("macOSFramework") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "-", "--options", "expires,hard,host,kill,linker-signed,restrict", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) // ignore-unacceptable-language; codesign tool option ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--options", "expires,hard,host,kill,linker-signed,restrict", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) // ignore-unacceptable-language; codesign tool option + } + } + +@@ -892,7 +892,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["ENABLE_HARDENED_RUNTIME": "YES"]), runDestination: .macCatalyst, fs: fs) { results in + results.checkTarget("App") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "3ACDE4E702E4", "-o", "runtime", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "3ACDE4E702E4", "-o", "runtime", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) + } + results.checkNoDiagnostics() + } +@@ -900,7 +900,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["OTHER_CODE_SIGN_FLAGS": "-o library,restrict,runtime"]), runDestination: .macCatalyst, fs: fs) { results in + results.checkTarget("App") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "3ACDE4E702E4", "-o", "library,restrict,runtime", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "3ACDE4E702E4", "-o", "library,restrict,runtime", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) + } + results.checkNoDiagnostics() + } +@@ -908,7 +908,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["ENABLE_LIBRARY_VALIDATION": "YES", "ENABLE_HARDENED_RUNTIME": "YES", "CODE_SIGN_RESTRICT": "YES"]), runDestination: .iOS, fs: fs) { results in + results.checkTarget("App") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "-o", "library,restrict,runtime", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "-o", "library,restrict,runtime", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) + } + results.checkNoDiagnostics() + } +@@ -916,7 +916,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["ENABLE_HARDENED_RUNTIME": "YES"]), runDestination: .iOS, fs: fs) { results in + results.checkTarget("App") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "-o", "runtime", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "-o", "runtime", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) + } + results.checkNoDiagnostics() + } +@@ -924,7 +924,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["ENABLE_HARDENED_RUNTIME": "YES"]), runDestination: .macOS, fs: fs) { results in + results.checkTarget("macOSFramework") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "3ACDE4E702E4", "-o", "runtime", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "3ACDE4E702E4", "-o", "runtime", "--entitlements", .suffix("macOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/macOSFramework.framework/Versions/A"]) + } + results.checkNoDiagnostics() + } +@@ -932,7 +932,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["ENABLE_HARDENED_RUNTIME": "YES"]), runDestination: .watchOS, fs: fs) { results in + results.checkTarget("watchOSFramework") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "-o", "runtime", "--entitlements", .suffix("watchOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/watchOSFramework.framework"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "-o", "runtime", "--entitlements", .suffix("watchOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/watchOSFramework.framework"]) + } + results.checkNoDiagnostics() + } +@@ -942,7 +942,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["ENABLE_HARDENED_RUNTIME": "YES"]), runDestination: .iOSSimulator, fs: fs) { results in + results.checkTarget("App") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) + } + results.checkNoDiagnostics() + } +@@ -950,7 +950,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["ENABLE_LIBRARY_VALIDATION": "YES", "ENABLE_HARDENED_RUNTIME": "YES", "CODE_SIGN_RESTRICT": "YES"]), runDestination: .iOSSimulator, fs: fs) { results in + results.checkTarget("App") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "-o", "library,restrict", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "-o", "library,restrict", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) + } + results.checkNoDiagnostics() + } +@@ -958,7 +958,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["OTHER_CODE_SIGN_FLAGS": "-o runtime"]), runDestination: .iOSSimulator, fs: fs) { results in + results.checkTarget("App") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) + } + results.checkNoDiagnostics() + } +@@ -966,7 +966,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["OTHER_CODE_SIGN_FLAGS": "-o library,restrict,runtime"]), runDestination: .iOSSimulator, fs: fs) { results in + results.checkTarget("App") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "-o", "library,restrict", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "-o", "library,restrict", "--entitlements", .suffix("App.app.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Applications/App.app"]) + } + results.checkNoDiagnostics() + } +@@ -974,7 +974,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["ENABLE_HARDENED_RUNTIME": "YES"]), runDestination: .watchOSSimulator, fs: fs) { results in + results.checkTarget("watchOSFramework") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", .suffix("watchOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/watchOSFramework.framework"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", .suffix("watchOSFramework.framework.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/Library/Frameworks/watchOSFramework.framework"]) + } + results.checkNoDiagnostics() + } +@@ -1019,7 +1019,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["LAUNCH_CONSTRAINT_SELF": "/tmp/SelfLaunchConstraint.plist"]), runDestination: .macOS) { results in + results.checkTarget("Tool") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("Tool.xcent"), "--generate-entitlement-der", "--launch-constraint-self", .suffix("SelfLaunchConstraint.plist"), "/tmp/aProject.dst/usr/local/bin/Tool"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("Tool.xcent"), "--generate-entitlement-der", "--launch-constraint-self", .suffix("SelfLaunchConstraint.plist"), "/tmp/aProject.dst/usr/local/bin/Tool"]) + } + } + } +@@ -1028,7 +1028,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["LAUNCH_CONSTRAINT_PARENT": "/tmp/ParentLaunchConstraint.plist"]), runDestination: .macOS) { results in + results.checkTarget("Tool") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("Tool.xcent"), "--generate-entitlement-der", "--launch-constraint-parent", .suffix("ParentLaunchConstraint.plist"), "/tmp/aProject.dst/usr/local/bin/Tool"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("Tool.xcent"), "--generate-entitlement-der", "--launch-constraint-parent", .suffix("ParentLaunchConstraint.plist"), "/tmp/aProject.dst/usr/local/bin/Tool"]) + } + } + } +@@ -1038,7 +1038,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["LAUNCH_CONSTRAINT_RESPONSIBLE": "/tmp/ResponsibleLaunchConstraint.plist"]), runDestination: .macOS) { results in + results.checkTarget("Tool") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("Tool.xcent"), "--generate-entitlement-der", "--launch-constraint-responsible", .suffix("ResponsibleLaunchConstraint.plist"), "/tmp/aProject.dst/usr/local/bin/Tool"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("Tool.xcent"), "--generate-entitlement-der", "--launch-constraint-responsible", .suffix("ResponsibleLaunchConstraint.plist"), "/tmp/aProject.dst/usr/local/bin/Tool"]) + } + } + } +@@ -1047,7 +1047,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["LAUNCH_CONSTRAINT_SELF": "/tmp/SelfLaunchConstraint.plist", "LAUNCH_CONSTRAINT_PARENT": "/tmp/ParentLaunchConstraint.plist", "LAUNCH_CONSTRAINT_RESPONSIBLE": "/tmp/ResponsibleLaunchConstraint.plist"]), runDestination: .macOS) { results in + results.checkTarget("Tool") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("Tool.xcent"), "--generate-entitlement-der", "--launch-constraint-self", .suffix("SelfLaunchConstraint.plist"), "--launch-constraint-parent", .suffix("ParentLaunchConstraint.plist"), "--launch-constraint-responsible", .suffix("ResponsibleLaunchConstraint.plist"), "/tmp/aProject.dst/usr/local/bin/Tool"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("Tool.xcent"), "--generate-entitlement-der", "--launch-constraint-self", .suffix("SelfLaunchConstraint.plist"), "--launch-constraint-parent", .suffix("ParentLaunchConstraint.plist"), "--launch-constraint-responsible", .suffix("ResponsibleLaunchConstraint.plist"), "/tmp/aProject.dst/usr/local/bin/Tool"]) + } + } + } +@@ -1091,7 +1091,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["LIBRARY_LOAD_CONSTRAINT": "/tmp/LibraryLoadConstraint.plist"]), runDestination: .macOS, systemInfo: SystemInfo(operatingSystemVersion: Version(14), productBuildVersion: "99A98", nativeArchitecture: "arm64")) { results in + results.checkTarget("Tool") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("Tool.xcent"), "--generate-entitlement-der", "--library-constraint", .suffix("LibraryLoadConstraint.plist"), "/tmp/aProject.dst/usr/local/bin/Tool"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("Tool.xcent"), "--generate-entitlement-der", "--library-constraint", .suffix("LibraryLoadConstraint.plist"), "/tmp/aProject.dst/usr/local/bin/Tool"]) + } + } + } +@@ -1100,7 +1100,7 @@ fileprivate struct CodeSignTaskConstructionTests: CoreBasedTests { + await tester.checkBuild(BuildParameters(action: .install, configuration: "Release", overrides: ["LIBRARY_LOAD_CONSTRAINT": "/tmp/LibraryLoadConstraint.plist"]), runDestination: .macOS, systemInfo: SystemInfo(operatingSystemVersion: Version(13), productBuildVersion: "99A98", nativeArchitecture: "arm64")) { results in + results.checkTarget("Tool") { target in + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in +- task.checkCommandLineMatches(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("Tool.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/usr/local/bin/Tool"]) ++ task.checkCommandLineMatches(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", .suffix("Tool.xcent"), "--generate-entitlement-der", "/tmp/aProject.dst/usr/local/bin/Tool"]) + } + } + } +diff --git a/Tests/SWBTaskConstructionTests/MergeableLibraryTests.swift b/Tests/SWBTaskConstructionTests/MergeableLibraryTests.swift +index 4584f5d..edc83b1 100644 +--- a/Tests/SWBTaskConstructionTests/MergeableLibraryTests.swift ++++ b/Tests/SWBTaskConstructionTests/MergeableLibraryTests.swift +@@ -289,7 +289,7 @@ fileprivate struct MergeableLibraryTests: CoreBasedTests { + let signedDir = String("\(FWK_FULL_PRODUCT_NAME)/\(FWK_CONTENTS_DIR_SUBPATH)".dropLast()) // Chop off the trailing '/' + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemPattern(.suffix(signedDir))) { task in + task.checkRuleInfo(["CodeSign", "\(BUILT_PRODUCTS_DIR)/\(FULL_PRODUCT_NAME)/\(FWK_CONTENTS_DIR_SUBPATH)\(reexportedBinariesDirectoryName)/\(signedDir)"]) +- task.checkCommandLineContains(["/usr/bin/codesign", "--preserve-metadata=identifier,entitlements,flags", "\(BUILT_PRODUCTS_DIR)/\(FULL_PRODUCT_NAME)/\(FWK_CONTENTS_DIR_SUBPATH)\(reexportedBinariesDirectoryName)/\(signedDir)"]) ++ task.checkCommandLineContains(["@sigtool@/bin/codesign", "--preserve-metadata=identifier,entitlements,flags", "\(BUILT_PRODUCTS_DIR)/\(FULL_PRODUCT_NAME)/\(FWK_CONTENTS_DIR_SUBPATH)\(reexportedBinariesDirectoryName)/\(signedDir)"]) + results.checkTaskFollows(task, [.matchTarget(target), .matchRuleType("Copy"), .matchRuleItemBasename(FWK_FULL_PRODUCT_NAME)]) + } + } +@@ -303,7 +303,7 @@ fileprivate struct MergeableLibraryTests: CoreBasedTests { + } + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename(DYLIB_FULL_PRODUCT_NAME)) { task in + task.checkRuleInfo(["CodeSign", "\(BUILT_PRODUCTS_DIR)/\(FULL_PRODUCT_NAME)/\(FWK_CONTENTS_DIR_SUBPATH)\(reexportedBinariesDirectoryName)/\(DYLIB_FULL_PRODUCT_NAME)"]) +- task.checkCommandLineContains(["/usr/bin/codesign", "--preserve-metadata=identifier,entitlements,flags", "\(BUILT_PRODUCTS_DIR)/\(FULL_PRODUCT_NAME)/\(FWK_CONTENTS_DIR_SUBPATH)\(reexportedBinariesDirectoryName)/\(DYLIB_FULL_PRODUCT_NAME)"]) ++ task.checkCommandLineContains(["@sigtool@/bin/codesign", "--preserve-metadata=identifier,entitlements,flags", "\(BUILT_PRODUCTS_DIR)/\(FULL_PRODUCT_NAME)/\(FWK_CONTENTS_DIR_SUBPATH)\(reexportedBinariesDirectoryName)/\(DYLIB_FULL_PRODUCT_NAME)"]) + results.checkTaskFollows(task, [.matchTarget(target), .matchRuleType("Copy"), .matchRuleItemBasename(DYLIB_FULL_PRODUCT_NAME)]) + } + } +@@ -732,7 +732,7 @@ fileprivate struct MergeableLibraryTests: CoreBasedTests { + let signedDir = String("\(FWK_FULL_PRODUCT_NAME)/\(FWK_CONTENTS_DIR_SUBPATH)".dropLast()) // Chop off the trailing '/' + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemPattern(.suffix(signedDir))) { task in + task.checkRuleInfo(["CodeSign", "\(BUILT_PRODUCTS_DIR)/\(FULL_PRODUCT_NAME)/\(FWK_CONTENTS_DIR_SUBPATH)\(reexportedBinariesDirectoryName)/\(signedDir)"]) +- task.checkCommandLineContains(["/usr/bin/codesign", "--preserve-metadata=identifier,entitlements,flags", "\(BUILT_PRODUCTS_DIR)/\(FULL_PRODUCT_NAME)/\(FWK_CONTENTS_DIR_SUBPATH)\(reexportedBinariesDirectoryName)/\(signedDir)"]) ++ task.checkCommandLineContains(["@sigtool@/bin/codesign", "--preserve-metadata=identifier,entitlements,flags", "\(BUILT_PRODUCTS_DIR)/\(FULL_PRODUCT_NAME)/\(FWK_CONTENTS_DIR_SUBPATH)\(reexportedBinariesDirectoryName)/\(signedDir)"]) + results.checkTaskFollows(task, [.matchTarget(target), .matchRuleType("Copy"), .matchRuleItemBasename(FWK_FULL_PRODUCT_NAME)]) + } + } +@@ -1113,7 +1113,7 @@ fileprivate struct MergeableLibraryTests: CoreBasedTests { + } + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("FwkTarget.framework")) { task in + task.checkRuleInfo(["CodeSign", "\(SYMROOT)/Config-iphoneos/\(targetName).framework/\(reexportedBinariesDirectoryName)/FwkTarget.framework"]) +- task.checkCommandLineContains(["/usr/bin/codesign", "--preserve-metadata=identifier,entitlements,flags", "\(SYMROOT)/Config-iphoneos/\(targetName).framework/\(reexportedBinariesDirectoryName)/FwkTarget.framework"]) ++ task.checkCommandLineContains(["@sigtool@/bin/codesign", "--preserve-metadata=identifier,entitlements,flags", "\(SYMROOT)/Config-iphoneos/\(targetName).framework/\(reexportedBinariesDirectoryName)/FwkTarget.framework"]) + results.checkTaskFollows(task, [.matchTarget(target), .matchRuleType("Copy"), .matchRuleItemBasename("FwkTarget.framework")]) + } + +@@ -2242,7 +2242,7 @@ fileprivate struct MergeableLibraryTests: CoreBasedTests { + } + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemPattern(.suffix("\(reexportedBinariesDirectoryName)/\(fwkTargetName).framework"))) { task in + task.checkRuleInfo(["CodeSign", "\(SYMROOT)/Config-iphoneos/\(targetName).app/\(reexportedBinariesDirectoryName)/\(fwkTargetName).framework"]) +- task.checkCommandLineContains(["/usr/bin/codesign", "--preserve-metadata=identifier,entitlements,flags", "\(SYMROOT)/Config-iphoneos/\(targetName).app/\(reexportedBinariesDirectoryName)/\(fwkTargetName).framework"]) ++ task.checkCommandLineContains(["@sigtool@/bin/codesign", "--preserve-metadata=identifier,entitlements,flags", "\(SYMROOT)/Config-iphoneos/\(targetName).app/\(reexportedBinariesDirectoryName)/\(fwkTargetName).framework"]) + results.checkTaskFollows(task, [.matchTarget(target), .matchRuleType("Copy"), .matchRuleItemPattern(.suffix("\(reexportedBinariesDirectoryName)/\(fwkTargetName).framework"))]) + } + } +diff --git a/Tests/SWBTaskConstructionTests/PlatformTaskConstructionTests.swift b/Tests/SWBTaskConstructionTests/PlatformTaskConstructionTests.swift +index f2e561d..5a11f29 100644 +--- a/Tests/SWBTaskConstructionTests/PlatformTaskConstructionTests.swift ++++ b/Tests/SWBTaskConstructionTests/PlatformTaskConstructionTests.swift +@@ -191,7 +191,7 @@ fileprivate struct PlatformTaskConstructionTests: CoreBasedTests { + } + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("FwkTarget.framework")) { task in + task.checkRuleInfo(["CodeSign", "\(SRCROOT)/build/Debug-iphoneos/AppTarget.app/Frameworks/FwkTarget.framework"]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "--timestamp=none", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "\(SRCROOT)/build/Debug-iphoneos/AppTarget.app/Frameworks/FwkTarget.framework"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "--timestamp=none", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "\(SRCROOT)/build/Debug-iphoneos/AppTarget.app/Frameworks/FwkTarget.framework"]) + task.checkInputs([ + .path("\(SRCROOT)/build/Debug-iphoneos/AppTarget.app/Frameworks/FwkTarget.framework"), + .path("\(SRCROOT)/build/Debug-iphoneos/AppTarget.app/Frameworks/FwkTarget.framework"), +@@ -211,7 +211,7 @@ fileprivate struct PlatformTaskConstructionTests: CoreBasedTests { + // There should be a codesign task for the app. + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("AppTarget.app")) { task in + #expect(task.ruleInfo[1] == "\(SRCROOT)/build/Debug-iphoneos/AppTarget.app") +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-iphoneos/AppTarget.build/AppTarget.app.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug-iphoneos/AppTarget.app"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-iphoneos/AppTarget.build/AppTarget.app.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug-iphoneos/AppTarget.app"]) + task.checkEnvironment([ + "CODESIGN_ALLOCATE": .equal("codesign_allocate"), + ], exact: true) +@@ -322,7 +322,7 @@ fileprivate struct PlatformTaskConstructionTests: CoreBasedTests { + } + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("FwkTarget.framework")) { task in + task.checkRuleInfo(["CodeSign", "\(SRCROOT)/build/Debug-iphonesimulator/AppTarget.app/Frameworks/FwkTarget.framework"]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "--timestamp=none", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "\(SRCROOT)/build/Debug-iphonesimulator/AppTarget.app/Frameworks/FwkTarget.framework"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "--timestamp=none", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "\(SRCROOT)/build/Debug-iphonesimulator/AppTarget.app/Frameworks/FwkTarget.framework"]) + task.checkInputs([ + .path("\(SRCROOT)/build/Debug-iphonesimulator/AppTarget.app/Frameworks/FwkTarget.framework"), + .path("\(SRCROOT)/build/Debug-iphonesimulator/AppTarget.app/Frameworks/FwkTarget.framework"), +@@ -346,7 +346,7 @@ fileprivate struct PlatformTaskConstructionTests: CoreBasedTests { + // There should be a codesign task for the app. + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("AppTarget.app")) { task in + #expect(task.ruleInfo[1] == "\(SRCROOT)/build/Debug-iphonesimulator/AppTarget.app") +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-iphonesimulator/AppTarget.build/AppTarget.app.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug-iphonesimulator/AppTarget.app"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-iphonesimulator/AppTarget.build/AppTarget.app.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug-iphonesimulator/AppTarget.app"]) + } + + // There should be one product validation task. +diff --git a/Tests/SWBTaskConstructionTests/PostprocessingTaskConstructionTests.swift b/Tests/SWBTaskConstructionTests/PostprocessingTaskConstructionTests.swift +index 85fd06e..d5d7251 100644 +--- a/Tests/SWBTaskConstructionTests/PostprocessingTaskConstructionTests.swift ++++ b/Tests/SWBTaskConstructionTests/PostprocessingTaskConstructionTests.swift +@@ -75,7 +75,7 @@ fileprivate struct PostprocessingTaskConstructionTests: CoreBasedTests { + let suffix = buildVariant == "normal" ? "" : "_\(buildVariant)" + + task.checkRuleInfo(["SetOwnerAndGroup", "exampleUser:exampleGroup", "/tmp/aProject.dst/usr/local/lib/Library\(suffix).dylib"]) +- task.checkCommandLine(["/usr/sbin/chown", "-RH", "exampleUser:exampleGroup", "/tmp/aProject.dst/usr/local/lib/Library\(suffix).dylib"]) ++ task.checkCommandLine(["@coreutils@/bin/chown", "-RH", "exampleUser:exampleGroup", "/tmp/aProject.dst/usr/local/lib/Library\(suffix).dylib"]) + + task.checkInputs([ + .path("/tmp/aProject.dst/usr/local/lib/Library\(suffix).dylib"), +@@ -117,7 +117,7 @@ fileprivate struct PostprocessingTaskConstructionTests: CoreBasedTests { + results.checkTarget("Framework") { target in + results.checkTask(.matchTarget(target), .matchRuleType("SetOwnerAndGroup")) { task in + task.checkRuleInfo(["SetOwnerAndGroup", "exampleUser:exampleGroup", "/tmp/aProject.dst/Library/Frameworks/Framework.framework"]) +- task.checkCommandLine(["/usr/sbin/chown", "-RH", "exampleUser:exampleGroup", "/tmp/aProject.dst/Library/Frameworks/Framework.framework"]) ++ task.checkCommandLine(["@coreutils@/bin/chown", "-RH", "exampleUser:exampleGroup", "/tmp/aProject.dst/Library/Frameworks/Framework.framework"]) + + task.checkInputs([ + .path("/tmp/aProject.dst/Library/Frameworks/Framework.framework"), +diff --git a/Tests/SWBTaskConstructionTests/SwiftTaskConstructionTests.swift b/Tests/SWBTaskConstructionTests/SwiftTaskConstructionTests.swift +index 1d901c0..c184bd2 100644 +--- a/Tests/SWBTaskConstructionTests/SwiftTaskConstructionTests.swift ++++ b/Tests/SWBTaskConstructionTests/SwiftTaskConstructionTests.swift +@@ -181,7 +181,7 @@ fileprivate struct SwiftTaskConstructionTests: CoreBasedTests { + // Create a fake codesign_allocate tool so it can be found in the executable search paths. + let fs = PseudoFS() + try await fs.writeFileContents(swiftCompilerPath) { $0 <<< "binary" } +- try await fs.writeFileContents(core.developerPath.path.join("Toolchains/XcodeDefault.xctoolchain/usr/bin/codesign_allocate")) { $0 <<< "binary" } ++ try await fs.writeFileContents(core.developerPath.path.join("@sigtool@/bin/codesign_allocate")) { $0 <<< "binary" } + + // NOTE: The toolchain cannot be set normally and must be passed in as an override. + var overrides = ["TOOLCHAINS": toolchainIdentifier] +@@ -437,7 +437,7 @@ fileprivate struct SwiftTaskConstructionTests: CoreBasedTests { + .name("CopySwiftStdlib \(SRCROOT)/build/Debug/AppTarget.app"),]) + + task.checkEnvironment([ +- "CODESIGN_ALLOCATE": .equal(core.developerPath.path.join("Toolchains/XcodeDefault.xctoolchain/usr/bin/codesign_allocate").str), ++ "CODESIGN_ALLOCATE": .equal(core.developerPath.path.join("@sigtool@/bin/codesign_allocate").str), + "DEVELOPER_DIR": .equal(core.developerPath.path.str), + "SDKROOT": .equal(core.loadSDK(.macOS).path.str), + // This is coming from our overrides in unit test infrastructure. +@@ -448,7 +448,7 @@ fileprivate struct SwiftTaskConstructionTests: CoreBasedTests { + // There should be a product 'Touch' task. + results.checkTask(.matchTarget(target), .matchRuleType("Touch")) { task in + task.checkRuleInfo(["Touch", "\(SRCROOT)/build/Debug/AppTarget.app"]) +- task.checkCommandLine(["/usr/bin/touch", "-c", "\(SRCROOT)/build/Debug/AppTarget.app"]) ++ task.checkCommandLine(["@coreutils@/bin/touch", "-c", "\(SRCROOT)/build/Debug/AppTarget.app"]) + } + + results.checkTask(.matchTarget(target), .matchRuleType("RegisterExecutionPolicyException")) { task in +diff --git a/Tests/SWBTaskConstructionTests/TaskConstructionTests.swift b/Tests/SWBTaskConstructionTests/TaskConstructionTests.swift +index 4f9a3e5..ee50974 100644 +--- a/Tests/SWBTaskConstructionTests/TaskConstructionTests.swift ++++ b/Tests/SWBTaskConstructionTests/TaskConstructionTests.swift +@@ -960,7 +960,7 @@ fileprivate struct TaskConstructionTests: CoreBasedTests { + // There should be a chown and chmod task. + results.checkTask(.matchTarget(target), .matchRuleType("SetOwnerAndGroup")) { task in + task.checkRuleInfo(["SetOwnerAndGroup", "exampleUser:exampleGroup", "/tmp/aProject.dst/Applications/AppTarget.app"]) +- task.checkCommandLine(["/usr/sbin/chown", "-RH", "exampleUser:exampleGroup", "/tmp/aProject.dst/Applications/AppTarget.app"]) ++ task.checkCommandLine(["@coreutils@/bin/chown", "-RH", "exampleUser:exampleGroup", "/tmp/aProject.dst/Applications/AppTarget.app"]) + + task.checkInputs([ + .path("/tmp/aProject.dst/Applications/AppTarget.app"), +@@ -996,7 +996,7 @@ fileprivate struct TaskConstructionTests: CoreBasedTests { + // There should be a chown task targeting the file in the the ALTERNATE_PERMISSIONS_FILES build setting. + results.checkTask(.matchTarget(target), .matchRuleType("SetOwner")) { task in + task.checkRuleInfo(["SetOwner", "fooOwner", "/tmp/aProject.dst/Applications/AlternatePermissions.txt"]) +- task.checkCommandLine(["/usr/sbin/chown", "-RH", "fooOwner", "/tmp/aProject.dst/Applications/AlternatePermissions.txt"]) ++ task.checkCommandLine(["@coreutils@/bin/chown", "-RH", "fooOwner", "/tmp/aProject.dst/Applications/AlternatePermissions.txt"]) + + task.checkInputs([ + .path("/tmp/aProject.dst/Applications/AlternatePermissions.txt"), +@@ -1056,7 +1056,7 @@ fileprivate struct TaskConstructionTests: CoreBasedTests { + + // There should be three codesign tasks (one for the copied FW, one for the copied dylib, one for the app), two of which should be re-signing tasks. + results.checkTask(.matchTarget(target), .matchRule(["CodeSign", "/tmp/aProject.dst/Applications/AppTarget.app/Contents/Frameworks/FWToCopy.framework/Versions/A"])) { task in +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "/tmp/aProject.dst/Applications/AppTarget.app/Contents/Frameworks/FWToCopy.framework/Versions/A"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "/tmp/aProject.dst/Applications/AppTarget.app/Contents/Frameworks/FWToCopy.framework/Versions/A"]) + task.checkInputs([ + .path("/tmp/aProject.dst/Applications/AppTarget.app/Contents/Frameworks/FWToCopy.framework"), + .path("/tmp/aProject.dst/Applications/AppTarget.app/Contents/Frameworks/FWToCopy.framework/Versions/A"), +@@ -1077,7 +1077,7 @@ fileprivate struct TaskConstructionTests: CoreBasedTests { + ]) + } + results.checkTask(.matchTarget(target), .matchRule(["CodeSign", "/tmp/aProject.dst/Applications/AppTarget.app/Contents/Frameworks/libdynamic.dylib"])) { task in +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "/tmp/aProject.dst/Applications/AppTarget.app/Contents/Frameworks/libdynamic.dylib"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "/tmp/aProject.dst/Applications/AppTarget.app/Contents/Frameworks/libdynamic.dylib"]) + task.checkInputs([ + .path("/tmp/aProject.dst/Applications/AppTarget.app/Contents/Frameworks/libdynamic.dylib"), + .path("/tmp/aProject.dst/Applications/AppTarget.app/Contents/Frameworks/libdynamic.dylib"), +@@ -1095,7 +1095,7 @@ fileprivate struct TaskConstructionTests: CoreBasedTests { + ]) + } + results.checkTask(.matchTarget(target), .matchRule(["CodeSign", "/tmp/aProject.dst/Applications/AppTarget.app"])) { task in +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Release/AppTarget.build/AppTarget.app.xcent", "--generate-entitlement-der", "/tmp/aProject.dst/Applications/AppTarget.app"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Release/AppTarget.build/AppTarget.app.xcent", "--generate-entitlement-der", "/tmp/aProject.dst/Applications/AppTarget.app"]) + task.checkInputs([ + .path("/tmp/aProject.dst/Applications/AppTarget.app"), + .path("/tmp/aProject.dst/Applications/AppTarget.app"), +@@ -4167,7 +4167,7 @@ fileprivate struct TaskConstructionTests: CoreBasedTests { + // There should be two code signing tasks, one for the library and one for the product. + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("libclang_rt.asan_osx_dynamic.dylib")) { task in + task.checkRuleInfo([.equal("CodeSign"), .equal("\(SRCROOT)/build/Debug/\(targetName).app/Contents/Frameworks/libclang_rt.asan_osx_dynamic.dylib")]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--timestamp=none", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app/Contents/Frameworks/libclang_rt.asan_osx_dynamic.dylib"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--timestamp=none", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app/Contents/Frameworks/libclang_rt.asan_osx_dynamic.dylib"]) + task.checkInputs([ + .path("\(SRCROOT)/build/Debug/AppTarget.app/Contents/Frameworks/libclang_rt.asan_osx_dynamic.dylib"), + .path("\(SRCROOT)/build/Debug/AppTarget.app/Contents/Frameworks/libclang_rt.asan_osx_dynamic.dylib"), +@@ -4178,7 +4178,7 @@ fileprivate struct TaskConstructionTests: CoreBasedTests { + } + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("\(targetName).app")) { task in + task.checkRuleInfo([.equal("CodeSign"), .equal("\(SRCROOT)/build/Debug/\(targetName).app")]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/AppTarget.build/AppTarget.app.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/AppTarget.build/AppTarget.app.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app"]) + } + } + +@@ -4225,7 +4225,7 @@ fileprivate struct TaskConstructionTests: CoreBasedTests { + // There should be one code signing task for the ASan library. + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("libclang_rt.asan_osx_dynamic.dylib")) { task in + task.checkRuleInfo([.equal("CodeSign"), .equal("\(SRCROOT)/build/Debug/\(targetName).app/Contents/Frameworks/libclang_rt.asan_osx_dynamic.dylib")]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--timestamp=none", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app/Contents/Frameworks/libclang_rt.asan_osx_dynamic.dylib"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--timestamp=none", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app/Contents/Frameworks/libclang_rt.asan_osx_dynamic.dylib"]) + task.checkInputs([ + .path("\(SRCROOT)/build/Debug/AppTarget.app/Contents/Frameworks/libclang_rt.asan_osx_dynamic.dylib"), + .path("\(SRCROOT)/build/Debug/AppTarget.app/Contents/Frameworks/libclang_rt.asan_osx_dynamic.dylib"), +@@ -4238,7 +4238,7 @@ fileprivate struct TaskConstructionTests: CoreBasedTests { + // There should be one code signing task for the TSan library. + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("libclang_rt.tsan_osx_dynamic.dylib")) { task in + task.checkRuleInfo([.equal("CodeSign"), .equal("\(SRCROOT)/build/Debug/\(targetName).app/Contents/Frameworks/libclang_rt.tsan_osx_dynamic.dylib")]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--timestamp=none", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app/Contents/Frameworks/libclang_rt.tsan_osx_dynamic.dylib"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--timestamp=none", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app/Contents/Frameworks/libclang_rt.tsan_osx_dynamic.dylib"]) + task.checkInputs([ + .path("\(SRCROOT)/build/Debug/AppTarget.app/Contents/Frameworks/libclang_rt.tsan_osx_dynamic.dylib"), + .path("\(SRCROOT)/build/Debug/AppTarget.app/Contents/Frameworks/libclang_rt.tsan_osx_dynamic.dylib"), +@@ -4301,7 +4301,7 @@ fileprivate struct TaskConstructionTests: CoreBasedTests { + // There should be two code signing tasks, one for the library and one for the product. + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("libclang_rt.tsan_osx_dynamic.dylib")) { task in + task.checkRuleInfo([.equal("CodeSign"), .equal("\(SRCROOT)/build/Debug/\(targetName).app/Contents/Frameworks/libclang_rt.tsan_osx_dynamic.dylib")]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--timestamp=none", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app/Contents/Frameworks/libclang_rt.tsan_osx_dynamic.dylib"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--timestamp=none", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app/Contents/Frameworks/libclang_rt.tsan_osx_dynamic.dylib"]) + task.checkInputs([ + .path("\(SRCROOT)/build/Debug/AppTarget.app/Contents/Frameworks/libclang_rt.tsan_osx_dynamic.dylib"), + .path("\(SRCROOT)/build/Debug/AppTarget.app/Contents/Frameworks/libclang_rt.tsan_osx_dynamic.dylib"), +@@ -4312,7 +4312,7 @@ fileprivate struct TaskConstructionTests: CoreBasedTests { + } + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("\(targetName).app")) { task in + task.checkRuleInfo([.equal("CodeSign"), .equal("\(SRCROOT)/build/Debug/\(targetName).app")]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/AppTarget.build/AppTarget.app.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/AppTarget.build/AppTarget.app.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app"]) + } + } + +@@ -4356,7 +4356,7 @@ fileprivate struct TaskConstructionTests: CoreBasedTests { + // There should be two code signing tasks, one for the library and one for the product. + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("libclang_rt.ubsan_osx_dynamic.dylib")) { task in + task.checkRuleInfo([.equal("CodeSign"), .equal("\(SRCROOT)/build/Debug/\(targetName).app/Contents/Frameworks/libclang_rt.ubsan_osx_dynamic.dylib")]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--timestamp=none", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app/Contents/Frameworks/libclang_rt.ubsan_osx_dynamic.dylib"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--timestamp=none", "--preserve-metadata=identifier,entitlements,flags", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app/Contents/Frameworks/libclang_rt.ubsan_osx_dynamic.dylib"]) + task.checkInputs([ + .path("\(SRCROOT)/build/Debug/AppTarget.app/Contents/Frameworks/libclang_rt.ubsan_osx_dynamic.dylib"), + .path("\(SRCROOT)/build/Debug/AppTarget.app/Contents/Frameworks/libclang_rt.ubsan_osx_dynamic.dylib"), +@@ -4367,7 +4367,7 @@ fileprivate struct TaskConstructionTests: CoreBasedTests { + } + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("\(targetName).app")) { task in + task.checkRuleInfo([.equal("CodeSign"), .equal("\(SRCROOT)/build/Debug/\(targetName).app")]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/AppTarget.build/AppTarget.app.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/AppTarget.build/AppTarget.app.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/\(targetName).app"]) + } + } + +diff --git a/Tests/SWBTaskConstructionTests/UnitTestTaskConstructionTests.swift b/Tests/SWBTaskConstructionTests/UnitTestTaskConstructionTests.swift +index 761146f..95bfcb7 100644 +--- a/Tests/SWBTaskConstructionTests/UnitTestTaskConstructionTests.swift ++++ b/Tests/SWBTaskConstructionTests/UnitTestTaskConstructionTests.swift +@@ -657,7 +657,7 @@ fileprivate struct UnitTestTaskConstructionTests: CoreBasedTests { + } + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("UnitTestTargetOne.xctest")) { task in + task.checkRuleInfo(["CodeSign", "\(SRCROOT)/build/Debug/AppTarget.app/Contents/PlugIns/UnitTestTargetOne.xctest"]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/UnitTestTargetOne.build/UnitTestTargetOne.xctest.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/AppTarget.app/Contents/PlugIns/UnitTestTargetOne.xctest"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/UnitTestTargetOne.build/UnitTestTargetOne.xctest.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/AppTarget.app/Contents/PlugIns/UnitTestTargetOne.xctest"]) + task.checkInputs([ + .path("\(SRCROOT)/build/Debug/AppTarget.app/Contents/PlugIns/UnitTestTargetOne.xctest"), + .path("\(SRCROOT)/build/Debug/AppTarget.app/Contents/PlugIns/UnitTestTargetOne.xctest"), +@@ -843,7 +843,7 @@ fileprivate struct UnitTestTaskConstructionTests: CoreBasedTests { + results.checkTask(.matchTarget(target), .matchRuleType("ProcessProductPackagingDER")) { _ in } + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("UnitTestTargetOne.xctest")) { task in + task.checkRuleInfo(["CodeSign", "\(SRCROOT)/build/UninstalledProducts/macosx/UnitTestTargetOne.xctest"]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/UnitTestTargetOne.build/UnitTestTargetOne.xctest.xcent", "--generate-entitlement-der", "\(SRCROOT)/build/UninstalledProducts/macosx/UnitTestTargetOne.xctest"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/UnitTestTargetOne.build/UnitTestTargetOne.xctest.xcent", "--generate-entitlement-der", "\(SRCROOT)/build/UninstalledProducts/macosx/UnitTestTargetOne.xctest"]) + task.checkInputs([ + .path("\(SRCROOT)/build/UninstalledProducts/macosx/UnitTestTargetOne.xctest"), + .path("\(SRCROOT)/build/UninstalledProducts/macosx/UnitTestTargetOne.xctest"), +@@ -2515,7 +2515,7 @@ fileprivate struct UnitTestTaskConstructionTests: CoreBasedTests { + } + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("UITestTarget.xctest")) { task in + task.checkRuleInfo(["CodeSign", "\(SRCROOT)/build/Debug/UITestTarget-Runner.app/Contents/PlugIns/UITestTarget.xctest"]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/UITestTarget.build/UITestTarget.xctest.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/UITestTarget-Runner.app/Contents/PlugIns/UITestTarget.xctest"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/UITestTarget.build/UITestTarget.xctest.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/UITestTarget-Runner.app/Contents/PlugIns/UITestTarget.xctest"]) + task.checkInputs(contain: [ + .path("\(SRCROOT)/build/Debug/UITestTarget-Runner.app/Contents/PlugIns/UITestTarget.xctest"), + .path("\(SRCROOT)/build/Debug/UITestTarget-Runner.app/Contents/PlugIns/UITestTarget.xctest"), +@@ -2535,7 +2535,7 @@ fileprivate struct UnitTestTaskConstructionTests: CoreBasedTests { + } + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("UITestTarget-Runner.app")) { task in + task.checkRuleInfo(["CodeSign", "\(SRCROOT)/build/Debug/UITestTarget-Runner.app"]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/UITestTarget.build/UITestTarget.xctest.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/UITestTarget-Runner.app"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/UITestTarget.build/UITestTarget.xctest.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug/UITestTarget-Runner.app"]) + task.checkInputs(contain: ([[ + .path("\(SRCROOT)/build/Debug/UITestTarget-Runner.app/Contents/PlugIns/UITestTarget.xctest"), + .path("\(SRCROOT)/build/Debug/UITestTarget-Runner.app"), +@@ -2689,7 +2689,7 @@ fileprivate struct UnitTestTaskConstructionTests: CoreBasedTests { + results.checkTask(.matchTarget(target), .matchRuleType("ProcessProductPackagingDER"), .matchRuleItemPattern(.suffix(".xcent"))) { _ in } + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("UITestTarget.xctest")) { task in + task.checkRuleInfo(["CodeSign", "\(SRCROOT)/build/UninstalledProducts/macosx/UITestTarget-Runner.app/Contents/PlugIns/UITestTarget.xctest"]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/UITestTarget.build/UITestTarget.xctest.xcent", "--generate-entitlement-der", "\(SRCROOT)/build/UninstalledProducts/macosx/UITestTarget-Runner.app/Contents/PlugIns/UITestTarget.xctest"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/UITestTarget.build/UITestTarget.xctest.xcent", "--generate-entitlement-der", "\(SRCROOT)/build/UninstalledProducts/macosx/UITestTarget-Runner.app/Contents/PlugIns/UITestTarget.xctest"]) + task.checkInputs(contain: [ + .path("\(SRCROOT)/build/UninstalledProducts/macosx/UITestTarget-Runner.app/Contents/PlugIns/UITestTarget.xctest"), + .path("\(SRCROOT)/build/UninstalledProducts/macosx/UITestTarget-Runner.app/Contents/PlugIns/UITestTarget.xctest"), +@@ -2709,7 +2709,7 @@ fileprivate struct UnitTestTaskConstructionTests: CoreBasedTests { + } + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign"), .matchRuleItemBasename("UITestTarget-Runner.app")) { task in + task.checkRuleInfo(["CodeSign", "\(SRCROOT)/build/UninstalledProducts/macosx/UITestTarget-Runner.app"]) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/UITestTarget.build/UITestTarget.xctest.xcent", "--generate-entitlement-der", "\(SRCROOT)/build/UninstalledProducts/macosx/UITestTarget-Runner.app"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "-", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug/UITestTarget.build/UITestTarget.xctest.xcent", "--generate-entitlement-der", "\(SRCROOT)/build/UninstalledProducts/macosx/UITestTarget-Runner.app"]) + task.checkInputs(contain: ([[ + .path("\(SRCROOT)/build/UninstalledProducts/macosx/UITestTarget-Runner.app/Contents/PlugIns/UITestTarget.xctest"), + .path("\(SRCROOT)/build/UninstalledProducts/macosx/UITestTarget-Runner.app"), +diff --git a/Tests/SWBTaskConstructionTests/WatchTaskConstructionTests.swift b/Tests/SWBTaskConstructionTests/WatchTaskConstructionTests.swift +index db2a64f..7319fdd 100644 +--- a/Tests/SWBTaskConstructionTests/WatchTaskConstructionTests.swift ++++ b/Tests/SWBTaskConstructionTests/WatchTaskConstructionTests.swift +@@ -296,7 +296,7 @@ fileprivate struct WatchTaskConstructionTests: CoreBasedTests { + // There should be one codesign task. + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in + #expect(task.ruleInfo[1] == "\(SRCROOT)/build/Debug-watchos/Watchable WatchKit Extension.appex") +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-watchos/\(target.target.name).build/\(target.target.name).appex.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug-watchos/\(target.target.name).appex"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-watchos/\(target.target.name).build/\(target.target.name).appex.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug-watchos/\(target.target.name).appex"]) + task.checkEnvironment([ + "CODESIGN_ALLOCATE": .equal("codesign_allocate"), + ], exact: true) +@@ -384,7 +384,7 @@ fileprivate struct WatchTaskConstructionTests: CoreBasedTests { + // There should be one codesign task. + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in + #expect(task.ruleInfo[1] == builtWatchAppPath) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-watchos/Watchable WatchKit App.build/Watchable WatchKit App.app.xcent", "--timestamp=none", "--generate-entitlement-der", builtWatchAppPath]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-watchos/Watchable WatchKit App.build/Watchable WatchKit App.app.xcent", "--timestamp=none", "--generate-entitlement-der", builtWatchAppPath]) + task.checkEnvironment([ + "CODESIGN_ALLOCATE": .equal("codesign_allocate"), + ], exact: true) +@@ -490,7 +490,7 @@ fileprivate struct WatchTaskConstructionTests: CoreBasedTests { + // There should be one codesign task. + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in + #expect(task.ruleInfo[1] == builtHostIOSAppPath) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-iphoneos/Watchable.build/Watchable.app.xcent", "--timestamp=none", "--generate-entitlement-der", builtHostIOSAppPath]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-iphoneos/Watchable.build/Watchable.app.xcent", "--timestamp=none", "--generate-entitlement-der", builtHostIOSAppPath]) + task.checkEnvironment([ + "CODESIGN_ALLOCATE": .equal("codesign_allocate"), + ], exact: true) +@@ -599,7 +599,7 @@ fileprivate struct WatchTaskConstructionTests: CoreBasedTests { + // There should be one codesign task. + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in + #expect(task.ruleInfo[1] == "\(SRCROOT)/build/Debug-watchsimulator/Watchable WatchKit Extension.appex") +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-watchsimulator/Watchable WatchKit Extension.build/Watchable WatchKit Extension.appex.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug-watchsimulator/Watchable WatchKit Extension.appex"]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-watchsimulator/Watchable WatchKit Extension.build/Watchable WatchKit Extension.appex.xcent", "--timestamp=none", "--generate-entitlement-der", "\(SRCROOT)/build/Debug-watchsimulator/Watchable WatchKit Extension.appex"]) + task.checkEnvironment([ + "CODESIGN_ALLOCATE": .equal("codesign_allocate"), + ], exact: true) +@@ -667,7 +667,7 @@ fileprivate struct WatchTaskConstructionTests: CoreBasedTests { + // There should be one codesign task. + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in + #expect(task.ruleInfo[1] == builtWatchAppPath) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-watchsimulator/Watchable WatchKit App.build/Watchable WatchKit App.app.xcent", "--timestamp=none", "--generate-entitlement-der", builtWatchAppPath]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-watchsimulator/Watchable WatchKit App.build/Watchable WatchKit App.app.xcent", "--timestamp=none", "--generate-entitlement-der", builtWatchAppPath]) + task.checkEnvironment([ + "CODESIGN_ALLOCATE": .equal("codesign_allocate"), + ], exact: true) +@@ -768,7 +768,7 @@ fileprivate struct WatchTaskConstructionTests: CoreBasedTests { + // There should be one codesign task. + results.checkTask(.matchTarget(target), .matchRuleType("CodeSign")) { task in + #expect(task.ruleInfo[1] == builtHostIOSAppPath) +- task.checkCommandLine(["/usr/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-iphonesimulator/Watchable.build/Watchable.app.xcent", "--timestamp=none", "--generate-entitlement-der", builtHostIOSAppPath]) ++ task.checkCommandLine(["@sigtool@/bin/codesign", "--force", "--sign", "105DE4E702E4", "--entitlements", "\(SRCROOT)/build/aProject.build/Debug-iphonesimulator/Watchable.build/Watchable.app.xcent", "--timestamp=none", "--generate-entitlement-der", builtHostIOSAppPath]) + task.checkEnvironment([ + "CODESIGN_ALLOCATE": .equal("codesign_allocate"), + ], exact: true) +diff --git a/Tests/SWBTaskExecutionTests/SignatureCollectionActionTests.swift b/Tests/SWBTaskExecutionTests/SignatureCollectionActionTests.swift +index 3c11b2c..1842a9f 100644 +--- a/Tests/SWBTaskExecutionTests/SignatureCollectionActionTests.swift ++++ b/Tests/SWBTaskExecutionTests/SignatureCollectionActionTests.swift +@@ -107,7 +107,7 @@ fileprivate struct SignatureCollectionActionTests { + let bundlePath = rootPath.join("test.bundle") + try fs.copy(Path(Bundle.module.bundlePath), to: bundlePath) + +- let codesignTool = URL(fileURLWithPath: "/usr/bin/codesign") ++ let codesignTool = URL(fileURLWithPath: "@sigtool@/bin/codesign") + let codesignResult = try await Process.run(url: codesignTool, arguments: ["--remove-signature", bundlePath.str]) + #expect(codesignResult.isSuccess) + +@@ -162,7 +162,7 @@ fileprivate struct SignatureCollectionActionTests { + let bundlePath = rootPath.join("test.bundle") + try fs.copy(Path(Bundle.module.bundlePath), to: bundlePath) + +- let codesignTool = URL(fileURLWithPath: "/usr/bin/codesign") ++ let codesignTool = URL(fileURLWithPath: "@sigtool@/bin/codesign") + let codesignResult = try await Process.run(url: codesignTool, arguments: ["--remove-signature", bundlePath.str]) + #expect(codesignResult.isSuccess) + +diff --git a/Tests/SWBUtilTests/MiscTests.swift b/Tests/SWBUtilTests/MiscTests.swift +index f93094a..2ff6572 100644 +--- a/Tests/SWBUtilTests/MiscTests.swift ++++ b/Tests/SWBUtilTests/MiscTests.swift +@@ -62,7 +62,7 @@ import SWBUtil + let path = try await xcode.compileFramework(path: tmpDir, platform: .iOS, infoLookup: Lookup(), archs: ["arm64"], useSwift: false) + #expect(!pbxcp_path_is_code_signed(path), "binary was unexpectedly code signed") + +- _ = try await runProcess(["/usr/bin/codesign", "-s", "-", path.str]) ++ _ = try await runProcess(["@sigtool@/bin/codesign", "-s", "-", path.str]) + #expect(pbxcp_path_is_code_signed(path), "binary was unexpectedly NOT code signed") + } + } +diff --git a/Tests/SWBUtilTests/SignaturesTests.swift b/Tests/SWBUtilTests/SignaturesTests.swift +index ca93d8f..c853bd2 100644 +--- a/Tests/SWBUtilTests/SignaturesTests.swift ++++ b/Tests/SWBUtilTests/SignaturesTests.swift +@@ -28,7 +28,7 @@ fileprivate struct SignaturesTests { + try await fs.writePlist(bundlePath.join("Info.plist"), .plDict([:])) + try fs.write(bundlePath.join("test"), contents: "#!/bin/bash", atomically: true) + +- let codesignTool = URL(fileURLWithPath: "/usr/bin/codesign") ++ let codesignTool = URL(fileURLWithPath: "@sigtool@/bin/codesign") + + // Set-up the ad-hoc signed bundle for testing. + let codesignSigningResult = try await Process.run(url: codesignTool, arguments: ["-s", "-", "-i", "test-ident", bundlePath.str]) +@@ -48,7 +48,7 @@ fileprivate struct SignaturesTests { + try await fs.writePlist(bundlePath.join("Info.plist"), .plDict([:])) + try fs.write(bundlePath.join("test"), contents: "#!/bin/bash", atomically: true) + +- let codesignTool = URL(fileURLWithPath: "/usr/bin/codesign") ++ let codesignTool = URL(fileURLWithPath: "@sigtool@/bin/codesign") + + // Set-up the ad-hoc signed bundle for testing. + let codesignSigningResult = try await Process.run(url: codesignTool, arguments: ["-s", "-", bundlePath.str]) +diff --git a/Tests/SwiftBuildTests/BuildOperationTests.swift b/Tests/SwiftBuildTests/BuildOperationTests.swift +index 077da08..6a14464 100644 +--- a/Tests/SwiftBuildTests/BuildOperationTests.swift ++++ b/Tests/SwiftBuildTests/BuildOperationTests.swift +@@ -213,7 +213,7 @@ fileprivate struct BuildOperationTests: CoreBasedTests { + buildPhases: [ + TestShellScriptBuildPhase( + name: "A.Script", originalObjectID: "A.Script", contents: (OutputByteStream() +- <<< "/usr/bin/touch ${SCRIPT_OUTPUT_FILE_0}" ++ <<< "@coreutils@/bin/touch ${SCRIPT_OUTPUT_FILE_0}" + ).bytes.asString, inputs: [], outputs: ["$(DERIVED_FILE_DIR)/stamp"]) + ], + dependencies: ["B"] +@@ -228,7 +228,7 @@ fileprivate struct BuildOperationTests: CoreBasedTests { + // This task will be up-to-date after the first build + TestShellScriptBuildPhase( + name: "B.Once", originalObjectID: "B.Once", +- contents: "/usr/bin/touch ${SCRIPT_OUTPUT_FILE_0}", ++ contents: "@coreutils@/bin/touch ${SCRIPT_OUTPUT_FILE_0}", + inputs: [], outputs: ["$(DERIVED_FILE_DIR)/stamp"]), + // This task will always run. + TestShellScriptBuildPhase( +@@ -1260,7 +1260,7 @@ fileprivate struct BuildOperationTests: CoreBasedTests { + "PRODUCT_NAME": "$(TARGET_NAME)", + "USE_HEADERMAP": "NO", + // We run a task which will never finish. +- "CC": "/usr/bin/yes", ++ "CC": "@coreutils@/bin/yes", + ])], + buildPhases: [ + TestSourcesBuildPhase([TestBuildFile("foo.c")]), +@@ -1331,7 +1331,7 @@ fileprivate struct BuildOperationTests: CoreBasedTests { + "PRODUCT_NAME": "$(TARGET_NAME)", + "USE_HEADERMAP": "NO", + // We run a task which will never finish. +- "CC": "/usr/bin/yes", ++ "CC": "@coreutils@/bin/yes", + ])], + buildPhases: [ + TestSourcesBuildPhase([TestBuildFile("foo.c")]), +@@ -1403,7 +1403,7 @@ fileprivate struct BuildOperationTests: CoreBasedTests { + "PRODUCT_NAME": "$(TARGET_NAME)", + "USE_HEADERMAP": "NO", + // We run a task which will never finish. +- "CC": "/usr/bin/yes", ++ "CC": "@coreutils@/bin/yes", + ])], + buildPhases: [ + TestSourcesBuildPhase([TestBuildFile("foo.c")]), +@@ -1485,7 +1485,7 @@ fileprivate struct BuildOperationTests: CoreBasedTests { + "PRODUCT_NAME": "$(TARGET_NAME)", + "USE_HEADERMAP": "NO", + // We run a task which will never finish. +- "CC": "/usr/bin/yes", ++ "CC": "@coreutils@/bin/yes", + ])], + buildPhases: [ + TestSourcesBuildPhase([TestBuildFile("foo.c")]), +@@ -1565,7 +1565,7 @@ fileprivate struct BuildOperationTests: CoreBasedTests { + "PRODUCT_NAME": "$(TARGET_NAME)", + "USE_HEADERMAP": "NO", + // We run a task which will never finish. +- "CC": "/usr/bin/yes", ++ "CC": "@coreutils@/bin/yes", + ])], + buildPhases: [ + TestSourcesBuildPhase([TestBuildFile("foo.c")]), +@@ -1724,7 +1724,7 @@ fileprivate struct BuildOperationTests: CoreBasedTests { + "PRODUCT_NAME": "$(TARGET_NAME)", + "USE_HEADERMAP": "NO", + // We run a task which will never finish. +- "CC": "/usr/bin/yes", ++ "CC": "@coreutils@/bin/yes", + ])], + buildPhases: [ + TestSourcesBuildPhase([TestBuildFile("foo.c")]), +-- +2.51.2 + diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-build/patches/0002-treat-nixpkgs-sdk-as-xcode.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swift-build/patches/0002-treat-nixpkgs-sdk-as-xcode.patch new file mode 100644 index 000000000000..8e6a921ac3e5 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-build/patches/0002-treat-nixpkgs-sdk-as-xcode.patch @@ -0,0 +1,49 @@ +From 0e17f25cf6827dfa94ad37590964d4f7b1d23625 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Tue, 9 Dec 2025 21:03:16 -0500 +Subject: [PATCH] treat-nixpkgs-sdk-as-xcode + +--- + Sources/SWBCore/Core.swift | 4 ++-- + Sources/SWBTestSupport/SkippedTestSupport.swift | 3 ++- + 2 files changed, 4 insertions(+), 3 deletions(-) + +diff --git a/Sources/SWBCore/Core.swift b/Sources/SWBCore/Core.swift +index 8a19a5e..7ab64fd 100644 +--- a/Sources/SWBCore/Core.swift ++++ b/Sources/SWBCore/Core.swift +@@ -267,7 +267,7 @@ public final class Core: Sendable { + + switch developerPath { + case .xcode(let path): +- toolchainPaths.append((path.join("Toolchains"), strict: path.str.hasSuffix(".app/Contents/Developer"))) ++ toolchainPaths.append((path.join("Toolchains"), strict: path.str.hasSuffix(".app/Contents/Developer") || path.str.hasPrefix("@store-dir@"))) + case .swiftToolchain(let path, xcodeDeveloperPath: let xcodeDeveloperPath): + if hostOperatingSystem == .windows { + toolchainPaths.append((path.join("Toolchains"), strict: true)) +@@ -275,7 +275,7 @@ public final class Core: Sendable { + toolchainPaths.append((path, strict: true)) + } + if let xcodeDeveloperPath { +- toolchainPaths.append((xcodeDeveloperPath.join("Toolchains"), strict: xcodeDeveloperPath.str.hasSuffix(".app/Contents/Developer"))) ++ toolchainPaths.append((xcodeDeveloperPath.join("Toolchains"), strict: xcodeDeveloperPath.str.hasSuffix(".app/Contents/Developer") || path.str.hasPrefix("@store-dir@"))) + } + } + +diff --git a/Sources/SWBTestSupport/SkippedTestSupport.swift b/Sources/SWBTestSupport/SkippedTestSupport.swift +index 1db4090..08e3109 100644 +--- a/Sources/SWBTestSupport/SkippedTestSupport.swift ++++ b/Sources/SWBTestSupport/SkippedTestSupport.swift +@@ -148,7 +148,8 @@ extension Trait where Self == Testing.ConditionTrait { + /// Constructs a condition trait that causes a test to be disabled if the developer directory is pointing at an Xcode developer directory. + package static var skipXcodeToolchain: Self { + disabled("This test is incompatible with Xcode toolchains.", { +- try await ConditionTraitContext.shared.getCore().developerPath.path.str.contains(".app/Contents/Developer") ++ let core = try await ConditionTraitContext.shared.getCore() ++ return core.developerPath.path.str.contains(".app/Contents/Developer") || core.developerPath.path.str.hasPrefix("@store-dir@") + }) + } + +-- +2.51.2 + diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-build/patches/0003-find-bundles-in-store.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swift-build/patches/0003-find-bundles-in-store.patch new file mode 100644 index 000000000000..b2d8e2467e05 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-build/patches/0003-find-bundles-in-store.patch @@ -0,0 +1,48 @@ +From a60ea4fbf21654eac779eece5c6d304e0f7b64c8 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 13 Dec 2025 09:40:18 -0500 +Subject: [PATCH] find-bundles-in-store + +--- + Sources/CMakeLists.txt | 11 +++++------ + 1 file changed, 5 insertions(+), 6 deletions(-) + +diff --git a/Sources/CMakeLists.txt b/Sources/CMakeLists.txt +index c0d0304..9df123e 100644 +--- a/Sources/CMakeLists.txt ++++ b/Sources/CMakeLists.txt +@@ -24,18 +24,17 @@ function(SwiftBuild_Bundle) + ${CMAKE_COMMAND} -E copy_if_different ${BundleXCSpecs_FILES} "${CMAKE_BINARY_DIR}/share/pm/SwiftBuild_${BundleXCSpecs_MODULE}.resources/") + + +- file(TO_NATIVE_PATH "${CMAKE_BINARY_DIR}/share/pm/SwiftBuild_${BundleXCSpecs_MODULE}.resources" _SWIFT_BUILD_RESOURCE_BUNDLE_BUILD_PATH) ++ file(TO_NATIVE_PATH "${CMAKE_INSTALL_DATADIR}/pm/SwiftBuild_${BundleXCSpecs_MODULE}.resources" _SWIFT_BUILD_RESOURCE_BUNDLE_BUILD_PATH) + file(CONFIGURE + OUTPUT "${CMAKE_BINARY_DIR}/resource_accessors/SwiftBuild_${BundleXCSpecs_MODULE}_resource_bundle_accessor.swift" + CONTENT [[ + import Foundation + extension Foundation.Bundle { + static let module: Bundle = { +- let mainPath = Bundle.main.bundleURL.appendingPathComponent("SwiftBuild_@BundleXCSpecs_MODULE@.resources").path +- let buildPath = #"@_SWIFT_BUILD_RESOURCE_BUNDLE_BUILD_PATH@"# ++ let mainPath = #"@_SWIFT_BUILD_RESOURCE_BUNDLE_BUILD_PATH@"# + let preferredBundle = Bundle(path: mainPath) +- guard let bundle = preferredBundle ?? Bundle(path: buildPath) else { +- Swift.fatalError("could not load resource bundle: from \(mainPath) or \(buildPath)") ++ guard let bundle = preferredBundle else { ++ Swift.fatalError("could not load resource bundle: from \(mainPath)") + } + return bundle + }() +@@ -48,7 +47,7 @@ function(SwiftBuild_Bundle) + + install(DIRECTORY + "${CMAKE_BINARY_DIR}/share/pm/SwiftBuild_${BundleXCSpecs_MODULE}.resources/" +- DESTINATION share/pm/SwiftBuild_${BundleXCSpecs_MODULE}.resources/) ++ DESTINATION ${CMAKE_INSTALL_DATADIR}/pm/SwiftBuild_${BundleXCSpecs_MODULE}.resources/) + endfunction() + + add_subdirectory(SWBCSupport) +-- +2.51.2 + diff --git a/pkgs/development/compilers/swift_ng/sources-6.2.json b/pkgs/development/compilers/swift_ng/sources-6.2.json index afaff3263e39..fcd1710988d9 100644 --- a/pkgs/development/compilers/swift_ng/sources-6.2.json +++ b/pkgs/development/compilers/swift_ng/sources-6.2.json @@ -5,6 +5,9 @@ "swift": { "hash": "sha256-apbBe/TMzq0+1XLkaTOj5NaYzLQ81i+vU+O7VSEJrKo=" }, + "swift-build": { + "hash": "sha256-uwxnn9B/79mCyceKDIdM+iqxKoCHh8dgEijU4NM2MnM=" + }, "swift-corelibs-foundation": { "hash": "sha256-Ytxiu80su2jnF/xLcLVEaHXYvI4spLO8d+qEhDxqAdQ=" }, From 860cbce30dfe1a32fd00943cfbba97c7af7cb54d Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 218/423] swiftPackages_ng.swiftpm: init at 6.2.4 --- .../swift_ng/by-name/sw/swiftpm/package.nix | 174 +++++++++ .../patches/0001-gnu-install-dirs.patch | 362 ++++++++++++++++++ .../0002-darwin-swift-corelibs-xctest.patch | 102 +++++ .../patches/0003-disable-sandbox.patch | 47 +++ .../patches/0005-fix-manifest-path.patch | 31 ++ .../patches/0006-nix-build-caches.patch | 36 ++ .../patches/0007-nix-pkgconfig-vars.patch | 41 ++ .../patches/0008-set-compiler-vendor.patch | 30 ++ .../patches/0009-add-missing-libraries.patch | 45 +++ .../0010-Load-IndexStore-from-the-store.patch | 35 ++ ...1-Always-find-Clang-in-the-toolchain.patch | 40 ++ .../backdeploy-references-stdlib/package.nix | 53 +++ .../src/Package.swift | 14 + .../src/Sources/main.swift | 11 + .../compilers/swift_ng/sources-6.2.json | 3 + 15 files changed, 1024 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/package.nix create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0001-gnu-install-dirs.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0002-darwin-swift-corelibs-xctest.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0003-disable-sandbox.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0005-fix-manifest-path.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0006-nix-build-caches.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0007-nix-pkgconfig-vars.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0008-set-compiler-vendor.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0009-add-missing-libraries.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0010-Load-IndexStore-from-the-store.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0011-Always-find-Clang-in-the-toolchain.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/package.nix create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/src/Package.swift create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/src/Sources/main.swift diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/package.nix new file mode 100644 index 000000000000..e80082a64aef --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/package.nix @@ -0,0 +1,174 @@ +{ + lib, + callPackage, + cmake, + fetchFromGitHub, + fetchpatch2, + llvmPackages, + ninja, + replaceVars, + sqlite, + stdenv, + swift, + swift-argument-parser, + swift-asn1, + swift-build, + swift-certificates, + swift-collections, + swift-crypto, + swift-driver, + swift-llbuild, + swift-syntax, + swift-system, + swift-tools-support-core, + swift_release, + swift_sources, +}: + +let + swift-syntax-no-toolchain = swift-syntax.override { useToolchainLibraries = false; }; + + rpaths = lib.makeLibraryPath [ + sqlite + swift-argument-parser + swift-asn1 + swift-build + swift-certificates + swift-collections + swift-crypto + swift-driver + swift-llbuild + swift-syntax-no-toolchain + swift-system + swift-tools-support-core + ]; +in + +stdenv.mkDerivation (finalAttrs: { + pname = "swiftpm"; + version = swift_release; + + outputs = [ + "out" + "dev" + ]; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-package-manager"; + tag = "swift-${finalAttrs.version}-RELEASE"; + inherit (swift_sources.swift-package-manager) hash; + }; + + patches = [ + ./patches/0001-gnu-install-dirs.patch + # Use swift-corelibs-xctest even on Darwin (because XCTest.framework is not available in nixpkgs). + ./patches/0002-darwin-swift-corelibs-xctest.patch + # SwiftPM tries to use `sandbox-exec` for sandboxing, which will fail when it is run in the Nix sandbox. + ./patches/0003-disable-sandbox.patch + # SwiftPM falls back to looking for manifests and plugins in the Swift compiler location. Find them in $out. + ./patches/0005-fix-manifest-path.patch + # Silence warnings about not finding the cache folder when building packages by moving it to $NIX_BUILD_TOP. + ./patches/0006-nix-build-caches.patch + # SwiftPM does its own `.pc` parsing, so it avoids the `pkg-config` wrapper used in nixpkgs to support + # cross-compilation. This patch adds support for `"PKG_CONFIG_PATH_FOR_TARGET` to SwiftPM. + ./patches/0007-nix-pkgconfig-vars.patch + # SwiftPM assumes that you are using Apple Clang on macOS, but nixpkgs builds Clang from upstream LLVM. + # This effectively disables using `-index-store-path`, which isn’t supported by LLVM’s Clang. + ./patches/0008-set-compiler-vendor.patch + # A couple of required libraries are missing from the `CMakeLists.txt` files. + ./patches/0009-add-missing-libraries.patch + # SwiftPM tries to load IndexStoreDB from the toolchain, but load it from the store instead. + (replaceVars ./patches/0010-Load-IndexStore-from-the-store.patch { + libclang = lib.getLib llvmPackages.libclang; + }) + # SwiftPM tries to find Clang via `CC`, but that can be GCC on Linux, which doesn’t actually work with SwiftPM. + ./patches/0011-Always-find-Clang-in-the-toolchain.patch + # Build missing `swift-package-collection` and `swift-package-registry` binaries. + (fetchpatch2 { + url = "https://github.com/swiftlang/swift-package-manager/commit/e1910f814cc1be40c709c3987a29488b9bee2f92.patch?full_index=1"; + hash = "sha256-4Ew/cKlk+Zn8cIQvh0jQy4Fz+xGYBYwch4+SBu1nKpI="; + }) + ]; + + postPatch = '' + # Need to reference $out, so this can’t be substituted by `replaceVars`. + substituteInPlace Sources/PackageModel/UserToolchain.swift \ + --replace-fail '@out@' "$out" + + # Replace hardcoded references to `xcrun` with `PATH`-based references. + find Sources -name '*.swift' -exec sed -i '{}' -e 's|/usr/bin/xcrun|xcrun|g' \; + + # Set the deployment target when building package manifests to one supported in nixpkgs. + substituteInPlace Sources/PackageLoading/ManifestLoader.swift \ + --replace-fail '.tripleString(forPlatformVersion: version)' ".tripleString(forPlatformVersion: \"$MACOSX_DEPLOYMENT_TARGET\")" + ''; + + strictDeps = true; + + preConfigure = '' + appendToVar cmakeFlags -DCMAKE_Swift_COMPILER_TARGET=${stdenv.hostPlatform.swift.triple} + appendToVar cmakeFlags -DCMAKE_Swift_FLAGS=-module-cache-path\ "$NIX_BUILD_TOP/module-cache" + ''; + + nativeBuildInputs = [ + cmake + ninja + swift + ]; + + buildInputs = [ + sqlite + swift-argument-parser + swift-asn1 + swift-build + swift-certificates + swift-collections + swift-crypto + swift-driver + swift-llbuild + swift-syntax-no-toolchain + swift-system + swift-tools-support-core + ]; + + postInstall = + lib.optionalString stdenv.hostPlatform.isDarwin '' + # Replace `@rpath` with absolute paths on Darwin. For some reason, this isn’t always done during installation. + # `fixDarwinDylibNames` doesn’t work either. + IFS= readarray -d "" dylibs < <(find "$out" -type f -and -name '*.dylib' -print0) + declare -a mappings + + for dylib in "''${dylibs[@]}"; do + mappings+=(-change "@rpath/$(basename "$dylib")" "$dylib") + done + + for dylib in "''${dylibs[@]}"; do + install_name_tool "$dylib" ''${mappings[@]} + done + '' + + lib.optionalString stdenv.hostPlatform.isElf '' + for output in "''${outputs[@]}"; do + while IFS= read -d "" f; do + if isELF "$f"; then + patchelf --add-rpath ${lib.escapeShellArg rpaths} "$f" + fi + done < <(find "$output" -type f -print0) + done + ''; + + passthru.tests = lib.packagesFromDirectoryRecursive { + inherit callPackage; + directory = ./tests; + }; + + __structuredAttrs = true; + + meta = { + description = "Package Manager for the Swift Programming Language"; + homepage = "https://github.com/swiftlang/swift-package-manager"; + inherit (swift.meta) badPlatforms platforms; + license = lib.licenses.asl20; + maintainers = lib.teams.swift.members; + }; +}) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0001-gnu-install-dirs.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0001-gnu-install-dirs.patch new file mode 100644 index 000000000000..5851bb9b15a4 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0001-gnu-install-dirs.patch @@ -0,0 +1,362 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Fri, 19 Dec 2025 20:12:12 -0500 +Subject: [PATCH 01/11] gnu-install-dirs + +--- + Sources/Basics/CMakeLists.txt | 6 +++--- + Sources/Build/CMakeLists.txt | 6 +++--- + Sources/Commands/CMakeLists.txt | 6 +++--- + Sources/CoreCommands/CMakeLists.txt | 6 +++--- + Sources/DriverSupport/CMakeLists.txt | 6 +++--- + Sources/PackageCollections/CMakeLists.txt | 6 +++--- + Sources/PackageCollectionsModel/CMakeLists.txt | 6 +++--- + Sources/PackageCollectionsSigning/CMakeLists.txt | 6 +++--- + Sources/PackageGraph/CMakeLists.txt | 6 +++--- + Sources/PackageLoading/CMakeLists.txt | 6 +++--- + Sources/PackageModel/CMakeLists.txt | 6 +++--- + Sources/PackageModelSyntax/CMakeLists.txt | 6 +++--- + Sources/PackageRegistryCommand/CMakeLists.txt | 6 +++--- + Sources/QueryEngine/CMakeLists.txt | 6 +++--- + Sources/SPMBuildCore/CMakeLists.txt | 6 +++--- + Sources/SourceControl/CMakeLists.txt | 6 +++--- + Sources/SwiftSDKCommand/CMakeLists.txt | 6 +++--- + Sources/Workspace/CMakeLists.txt | 6 +++--- + Sources/_AsyncFileSystem/CMakeLists.txt | 6 +++--- + Sources/swift-experimental-sdk/CMakeLists.txt | 2 +- + Sources/swift-package/CMakeLists.txt | 2 +- + Sources/swift-run/CMakeLists.txt | 2 +- + Sources/swift-sdk/CMakeLists.txt | 2 +- + Sources/swift-test/CMakeLists.txt | 2 +- + 24 files changed, 62 insertions(+), 62 deletions(-) + +diff --git a/Sources/Basics/CMakeLists.txt b/Sources/Basics/CMakeLists.txt +index e2910d09b..2f523dedb 100644 +--- a/Sources/Basics/CMakeLists.txt ++++ b/Sources/Basics/CMakeLists.txt +@@ -97,7 +97,7 @@ target_link_options(Basics PRIVATE + "$<$:SHELL:-Xlinker -framework -Xlinker Security>") + + install(TARGETS Basics +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") + set_property(GLOBAL APPEND PROPERTY SwiftPM_EXPORTS Basics) +diff --git a/Sources/Build/CMakeLists.txt b/Sources/Build/CMakeLists.txt +index 495bd7a87..9b32067ff 100644 +--- a/Sources/Build/CMakeLists.txt ++++ b/Sources/Build/CMakeLists.txt +@@ -49,7 +49,7 @@ set_target_properties(Build PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + + install(TARGETS Build +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") + set_property(GLOBAL APPEND PROPERTY SwiftPM_EXPORTS Build) +diff --git a/Sources/Commands/CMakeLists.txt b/Sources/Commands/CMakeLists.txt +index c62c7424e..5efcc760d 100644 +--- a/Sources/Commands/CMakeLists.txt ++++ b/Sources/Commands/CMakeLists.txt +@@ -80,6 +80,6 @@ set_target_properties(Commands PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + + install(TARGETS Commands +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/CoreCommands/CMakeLists.txt b/Sources/CoreCommands/CMakeLists.txt +index 54bc10b2b..dbaadcb3f 100644 +--- a/Sources/CoreCommands/CMakeLists.txt ++++ b/Sources/CoreCommands/CMakeLists.txt +@@ -29,6 +29,6 @@ set_target_properties(CoreCommands PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + + install(TARGETS CoreCommands +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/DriverSupport/CMakeLists.txt b/Sources/DriverSupport/CMakeLists.txt +index 1044df0e9..29234574c 100644 +--- a/Sources/DriverSupport/CMakeLists.txt ++++ b/Sources/DriverSupport/CMakeLists.txt +@@ -18,7 +18,7 @@ target_link_libraries(DriverSupport PUBLIC + SwiftDriver) + + install(TARGETS DriverSupport +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") + set_property(GLOBAL APPEND PROPERTY SwiftPM_EXPORTS DriverSupport) +diff --git a/Sources/PackageCollections/CMakeLists.txt b/Sources/PackageCollections/CMakeLists.txt +index 63eb94c2f..4f3c183e4 100644 +--- a/Sources/PackageCollections/CMakeLists.txt ++++ b/Sources/PackageCollections/CMakeLists.txt +@@ -56,6 +56,6 @@ if(NOT APPLE) + endif() + + install(TARGETS PackageCollections +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/PackageCollectionsModel/CMakeLists.txt b/Sources/PackageCollectionsModel/CMakeLists.txt +index 9f98827a5..c99c5d81c 100644 +--- a/Sources/PackageCollectionsModel/CMakeLists.txt ++++ b/Sources/PackageCollectionsModel/CMakeLists.txt +@@ -20,6 +20,6 @@ if(NOT APPLE) + endif() + + install(TARGETS PackageCollectionsModel +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/PackageCollectionsSigning/CMakeLists.txt b/Sources/PackageCollectionsSigning/CMakeLists.txt +index 5f3d69abe..7390bb783 100644 +--- a/Sources/PackageCollectionsSigning/CMakeLists.txt ++++ b/Sources/PackageCollectionsSigning/CMakeLists.txt +@@ -36,6 +36,6 @@ if(NOT APPLE) + endif() + + install(TARGETS PackageCollectionsSigning +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/PackageGraph/CMakeLists.txt b/Sources/PackageGraph/CMakeLists.txt +index 46bd6580f..4e7a5e04d 100644 +--- a/Sources/PackageGraph/CMakeLists.txt ++++ b/Sources/PackageGraph/CMakeLists.txt +@@ -51,7 +51,7 @@ set_target_properties(PackageGraph PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + + install(TARGETS PackageGraph +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") + set_property(GLOBAL APPEND PROPERTY SwiftPM_EXPORTS PackageGraph) +diff --git a/Sources/PackageLoading/CMakeLists.txt b/Sources/PackageLoading/CMakeLists.txt +index 476588dbf..f363cd12d 100644 +--- a/Sources/PackageLoading/CMakeLists.txt ++++ b/Sources/PackageLoading/CMakeLists.txt +@@ -36,7 +36,7 @@ set_target_properties(PackageLoading PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + + install(TARGETS PackageLoading +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") + set_property(GLOBAL APPEND PROPERTY SwiftPM_EXPORTS PackageLoading) +diff --git a/Sources/PackageModel/CMakeLists.txt b/Sources/PackageModel/CMakeLists.txt +index 48ff3b9ba..3c2e305a9 100644 +--- a/Sources/PackageModel/CMakeLists.txt ++++ b/Sources/PackageModel/CMakeLists.txt +@@ -75,7 +75,7 @@ set_target_properties(PackageModel PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + + install(TARGETS PackageModel +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") + set_property(GLOBAL APPEND PROPERTY SwiftPM_EXPORTS PackageModel) +diff --git a/Sources/PackageModelSyntax/CMakeLists.txt b/Sources/PackageModelSyntax/CMakeLists.txt +index 02142c690..70dcf942c 100644 +--- a/Sources/PackageModelSyntax/CMakeLists.txt ++++ b/Sources/PackageModelSyntax/CMakeLists.txt +@@ -39,7 +39,7 @@ set_target_properties(PackageModelSyntax PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + + install(TARGETS PackageModelSyntax +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") + set_property(GLOBAL APPEND PROPERTY SwiftPM_EXPORTS PackageModelSyntax) +diff --git a/Sources/PackageRegistryCommand/CMakeLists.txt b/Sources/PackageRegistryCommand/CMakeLists.txt +index 92c7785ed..a62300a1a 100644 +--- a/Sources/PackageRegistryCommand/CMakeLists.txt ++++ b/Sources/PackageRegistryCommand/CMakeLists.txt +@@ -34,6 +34,6 @@ if(NOT APPLE) + endif() + + install(TARGETS PackageRegistryCommand +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/QueryEngine/CMakeLists.txt b/Sources/QueryEngine/CMakeLists.txt +index 869c52c45..36d71c89c 100644 +--- a/Sources/QueryEngine/CMakeLists.txt ++++ b/Sources/QueryEngine/CMakeLists.txt +@@ -27,6 +27,6 @@ if(NOT APPLE) + endif() + + install(TARGETS QueryEngine +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/SPMBuildCore/CMakeLists.txt b/Sources/SPMBuildCore/CMakeLists.txt +index eaf92ddd1..ed7f25ca9 100644 +--- a/Sources/SPMBuildCore/CMakeLists.txt ++++ b/Sources/SPMBuildCore/CMakeLists.txt +@@ -40,7 +40,7 @@ target_link_libraries(SPMBuildCore PUBLIC + + + install(TARGETS SPMBuildCore +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") + set_property(GLOBAL APPEND PROPERTY SwiftPM_EXPORTS SPMBuildCore) +diff --git a/Sources/SourceControl/CMakeLists.txt b/Sources/SourceControl/CMakeLists.txt +index 8e1377d9b..e660bae2d 100644 +--- a/Sources/SourceControl/CMakeLists.txt ++++ b/Sources/SourceControl/CMakeLists.txt +@@ -22,7 +22,7 @@ set_target_properties(SourceControl PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + + install(TARGETS SourceControl +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") + set_property(GLOBAL APPEND PROPERTY SwiftPM_EXPORTS SourceControl) +diff --git a/Sources/SwiftSDKCommand/CMakeLists.txt b/Sources/SwiftSDKCommand/CMakeLists.txt +index 4dcfa36a2..ccca0ac3b 100644 +--- a/Sources/SwiftSDKCommand/CMakeLists.txt ++++ b/Sources/SwiftSDKCommand/CMakeLists.txt +@@ -29,6 +29,6 @@ set_target_properties(SwiftSDKCommand PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + + install(TARGETS SwiftSDKCommand +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/Workspace/CMakeLists.txt b/Sources/Workspace/CMakeLists.txt +index cdc939112..78b79ac25 100644 +--- a/Sources/Workspace/CMakeLists.txt ++++ b/Sources/Workspace/CMakeLists.txt +@@ -62,6 +62,6 @@ set_target_properties(Workspace PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + + install(TARGETS Workspace +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/_AsyncFileSystem/CMakeLists.txt b/Sources/_AsyncFileSystem/CMakeLists.txt +index adf09b29c..ad2ce7c4a 100644 +--- a/Sources/_AsyncFileSystem/CMakeLists.txt ++++ b/Sources/_AsyncFileSystem/CMakeLists.txt +@@ -24,8 +24,8 @@ set_target_properties(_AsyncFileSystem PROPERTIES + INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) + + install(TARGETS _AsyncFileSystem +- ARCHIVE DESTINATION lib +- LIBRARY DESTINATION lib +- RUNTIME DESTINATION bin) ++ ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") + + set_property(GLOBAL APPEND PROPERTY SwiftPM_EXPORTS _AsyncFileSystem) +diff --git a/Sources/swift-experimental-sdk/CMakeLists.txt b/Sources/swift-experimental-sdk/CMakeLists.txt +index edad12be8..f07bd15a7 100644 +--- a/Sources/swift-experimental-sdk/CMakeLists.txt ++++ b/Sources/swift-experimental-sdk/CMakeLists.txt +@@ -15,4 +15,4 @@ target_compile_options(swift-experimental-sdk PRIVATE + -parse-as-library) + + install(TARGETS swift-experimental-sdk +- RUNTIME DESTINATION bin) ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/swift-package/CMakeLists.txt b/Sources/swift-package/CMakeLists.txt +index 3468bdefc..4b4a8d190 100644 +--- a/Sources/swift-package/CMakeLists.txt ++++ b/Sources/swift-package/CMakeLists.txt +@@ -16,4 +16,4 @@ target_compile_options(swift-package PRIVATE + -parse-as-library) + + install(TARGETS swift-package +- RUNTIME DESTINATION bin) ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/swift-run/CMakeLists.txt b/Sources/swift-run/CMakeLists.txt +index 9c609f84e..719a2228a 100644 +--- a/Sources/swift-run/CMakeLists.txt ++++ b/Sources/swift-run/CMakeLists.txt +@@ -15,4 +15,4 @@ target_compile_options(swift-run PRIVATE + -parse-as-library) + + install(TARGETS swift-run +- RUNTIME DESTINATION bin) ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/swift-sdk/CMakeLists.txt b/Sources/swift-sdk/CMakeLists.txt +index ee3be128b..4ed4a522a 100644 +--- a/Sources/swift-sdk/CMakeLists.txt ++++ b/Sources/swift-sdk/CMakeLists.txt +@@ -15,4 +15,4 @@ target_compile_options(swift-sdk PRIVATE + -parse-as-library) + + install(TARGETS swift-sdk +- RUNTIME DESTINATION bin) ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +diff --git a/Sources/swift-test/CMakeLists.txt b/Sources/swift-test/CMakeLists.txt +index 79c910294..ef2305587 100644 +--- a/Sources/swift-test/CMakeLists.txt ++++ b/Sources/swift-test/CMakeLists.txt +@@ -15,4 +15,4 @@ target_compile_options(swift-test PRIVATE + -parse-as-library) + + install(TARGETS swift-test +- RUNTIME DESTINATION bin) ++ RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}") +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0002-darwin-swift-corelibs-xctest.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0002-darwin-swift-corelibs-xctest.patch new file mode 100644 index 000000000000..475cb0b2c893 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0002-darwin-swift-corelibs-xctest.patch @@ -0,0 +1,102 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 13 Dec 2025 22:57:10 -0500 +Subject: [PATCH 02/11] darwin-swift-corelibs-xctest + +--- + .../Commands/Utilities/TestingSupport.swift | 65 ------------------- + 1 file changed, 65 deletions(-) + +diff --git a/Sources/Commands/Utilities/TestingSupport.swift b/Sources/Commands/Utilities/TestingSupport.swift +index 81b329613..536babca5 100644 +--- a/Sources/Commands/Utilities/TestingSupport.swift ++++ b/Sources/Commands/Utilities/TestingSupport.swift +@@ -29,46 +29,6 @@ import func TSCBasic.withTemporaryFile + /// Note: In the long term this should be factored into a reusable module that + /// can run and report results on tests from both CLI and libSwiftPM API. + enum TestingSupport { +- /// Locates XCTestHelper tool inside the libexec directory and bin directory. +- /// Note: It is a fatalError if we are not able to locate the tool. +- /// +- /// - Returns: Path to XCTestHelper tool. +- static func xctestHelperPath(swiftCommandState: SwiftCommandState) throws -> AbsolutePath { +- var triedPaths = [AbsolutePath]() +- +- func findXCTestHelper(swiftBuildPath: AbsolutePath) -> AbsolutePath? { +- // XCTestHelper tool is installed in libexec. +- let maybePath = swiftBuildPath.parentDirectory.parentDirectory.appending( +- components: "libexec", "swift", "pm", "swiftpm-xctest-helper" +- ) +- if swiftCommandState.fileSystem.isFile(maybePath) { +- return maybePath +- } else { +- triedPaths.append(maybePath) +- return nil +- } +- } +- +- if let firstCLIArgument = CommandLine.arguments.first { +- let runningSwiftBuildPath = try AbsolutePath(validating: firstCLIArgument, relativeTo: swiftCommandState.originalWorkingDirectory) +- if let xctestHelperPath = findXCTestHelper(swiftBuildPath: runningSwiftBuildPath) { +- return xctestHelperPath +- } +- } +- +- // This will be true during swiftpm development or when using swift.org toolchains. +- let xcodePath = try AsyncProcess.checkNonZeroExit(args: "/usr/bin/xcode-select", "--print-path").spm_chomp() +- let installedSwiftBuildPath = try AsyncProcess.checkNonZeroExit( +- args: "/usr/bin/xcrun", "--find", "swift-build", +- environment: ["DEVELOPER_DIR": xcodePath] +- ).spm_chomp() +- if let xctestHelperPath = findXCTestHelper(swiftBuildPath: try AbsolutePath(validating: installedSwiftBuildPath)) { +- return xctestHelperPath +- } +- +- throw InternalError("XCTestHelper binary not found, tried \(triedPaths.map { $0.pathString }.joined(separator: ", "))") +- } +- + static func getTestSuites( + in testProducts: [BuiltTestProduct], + swiftCommandState: SwiftCommandState, +@@ -112,30 +72,6 @@ enum TestingSupport { + ) throws -> [TestSuite] { + // Run the correct tool. + var args = [String]() +- #if os(macOS) +- let data: String = try withTemporaryFile { tempFile in +- args = [try Self.xctestHelperPath(swiftCommandState: swiftCommandState).pathString, path.pathString, tempFile.path.pathString] +- let env = try Self.constructTestEnvironment( +- toolchain: try swiftCommandState.getTargetToolchain(), +- destinationBuildParameters: swiftCommandState.buildParametersForTest( +- enableCodeCoverage: enableCodeCoverage, +- shouldSkipBuilding: shouldSkipBuilding, +- experimentalTestOutput: experimentalTestOutput +- ).productsBuildParameters, +- sanitizers: sanitizers, +- library: .xctest +- ) +- try Self.runProcessWithExistenceCheck( +- path: path, +- fileSystem: swiftCommandState.fileSystem, +- args: args, +- env: env +- ) +- +- // Read the temporary file's content. +- return try swiftCommandState.fileSystem.readFileContents(AbsolutePath(tempFile.path)) +- } +- #else + let env = try Self.constructTestEnvironment( + toolchain: try swiftCommandState.getTargetToolchain(), + destinationBuildParameters: swiftCommandState.buildParametersForTest( +@@ -152,7 +88,6 @@ enum TestingSupport { + args: args, + env: env + ) +- #endif + // Parse json and return TestSuites. + return try TestSuite.parse(jsonString: data, context: args.joined(separator: " ")) + } +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0003-disable-sandbox.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0003-disable-sandbox.patch new file mode 100644 index 000000000000..dd9952255e9d --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0003-disable-sandbox.patch @@ -0,0 +1,47 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 13 Dec 2025 22:57:33 -0500 +Subject: [PATCH 03/11] disable-sandbox + +--- + Sources/Basics/Sandbox.swift | 22 ++++++++++++---------- + 1 file changed, 12 insertions(+), 10 deletions(-) + +diff --git a/Sources/Basics/Sandbox.swift b/Sources/Basics/Sandbox.swift +index f24636cac..8b65b2489 100644 +--- a/Sources/Basics/Sandbox.swift ++++ b/Sources/Basics/Sandbox.swift +@@ -57,18 +57,20 @@ public enum Sandbox { + allowNetworkConnections: [SandboxNetworkPermission] = [] + ) throws -> [String] { + #if os(macOS) +- let profile = try macOSSandboxProfile( +- fileSystem: fileSystem, +- strictness: strictness, +- writableDirectories: writableDirectories, +- readOnlyDirectories: readOnlyDirectories, +- allowNetworkConnections: allowNetworkConnections +- ) +- return ["/usr/bin/sandbox-exec", "-p", profile] + command +- #else ++ let env = ProcessInfo.processInfo.environment ++ if env["NIX_BUILD_TOP"] == nil || env["IN_NIX_SHELL"] != nil { ++ let profile = try macOSSandboxProfile( ++ fileSystem: fileSystem, ++ strictness: strictness, ++ writableDirectories: writableDirectories, ++ readOnlyDirectories: readOnlyDirectories, ++ allowNetworkConnections: allowNetworkConnections ++ ) ++ return ["/usr/bin/sandbox-exec", "-p", profile] + command ++ } ++ #endif + // rdar://40235432, rdar://75636874 tracks implementing sandboxes for other platforms. + return command +- #endif + } + + /// Basic strictness level of a sandbox applied to a command line. +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0005-fix-manifest-path.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0005-fix-manifest-path.patch new file mode 100644 index 000000000000..a9ac3f1db1b0 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0005-fix-manifest-path.patch @@ -0,0 +1,31 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 13 Dec 2025 22:58:33 -0500 +Subject: [PATCH 05/11] fix-manifest-path + +--- + Sources/PackageModel/UserToolchain.swift | 8 ++++++++ + 1 file changed, 8 insertions(+) + +diff --git a/Sources/PackageModel/UserToolchain.swift b/Sources/PackageModel/UserToolchain.swift +index 7f21304c6..39d7333c5 100644 +--- a/Sources/PackageModel/UserToolchain.swift ++++ b/Sources/PackageModel/UserToolchain.swift +@@ -956,6 +956,14 @@ public final class UserToolchain: Toolchain { + } + } + ++ // The manifest and plugin paths should be in the store if they’re nowhere else. ++ if let storeLibraryPath = try? Basics.AbsolutePath(validating: "@out@/lib/swift/pm") { ++ return .init( ++ manifestLibraryPath: storeLibraryPath.appending("ManifestAPI"), ++ pluginLibraryPath: storeLibraryPath.appending("PluginAPI") ++ ) ++ } ++ + // we are using a SwiftPM outside a toolchain, use the compiler path to compute the location + return .init(swiftCompilerPath: swiftCompilerPath) + } +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0006-nix-build-caches.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0006-nix-build-caches.patch new file mode 100644 index 000000000000..aa72be9610f4 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0006-nix-build-caches.patch @@ -0,0 +1,36 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 13 Dec 2025 22:58:44 -0500 +Subject: [PATCH 06/11] nix-build-caches + +--- + Sources/Basics/FileSystem/FileSystem+Extensions.swift | 6 ++++++ + 1 file changed, 6 insertions(+) + +diff --git a/Sources/Basics/FileSystem/FileSystem+Extensions.swift b/Sources/Basics/FileSystem/FileSystem+Extensions.swift +index 5f9674b2e..49f83e175 100644 +--- a/Sources/Basics/FileSystem/FileSystem+Extensions.swift ++++ b/Sources/Basics/FileSystem/FileSystem+Extensions.swift +@@ -12,6 +12,7 @@ + + import struct Foundation.Data + import class Foundation.FileManager ++import class Foundation.ProcessInfo + import struct Foundation.UUID + + import struct TSCBasic.ByteString +@@ -245,6 +246,11 @@ extension FileSystem { + /// SwiftPM cache directory under user's caches directory (if exists) + public var swiftPMCacheDirectory: AbsolutePath { + get throws { ++ let env = ProcessInfo.processInfo.environment ++ // Set up the caches in the build environment for Nix-managed builds ++ if let nixBuildTop = env["NIX_BUILD_TOP"] { ++ return try! AbsolutePath(validating: nixBuildTop).appending("swiftpm-cache") ++ } + if let path = self.idiomaticUserCacheDirectory { + return path.appending("org.swift.swiftpm") + } else { +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0007-nix-pkgconfig-vars.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0007-nix-pkgconfig-vars.patch new file mode 100644 index 000000000000..5721c1c66f43 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0007-nix-pkgconfig-vars.patch @@ -0,0 +1,41 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 13 Dec 2025 22:59:18 -0500 +Subject: [PATCH 07/11] nix-pkgconfig-vars + +--- + Sources/PackageLoading/PkgConfig.swift | 17 ++++++++++------- + 1 file changed, 10 insertions(+), 7 deletions(-) + +diff --git a/Sources/PackageLoading/PkgConfig.swift b/Sources/PackageLoading/PkgConfig.swift +index 21e0c514e..eaf9c803c 100644 +--- a/Sources/PackageLoading/PkgConfig.swift ++++ b/Sources/PackageLoading/PkgConfig.swift +@@ -131,14 +131,17 @@ public struct PkgConfig { + + private static var envSearchPaths: [Basics.AbsolutePath] { + get throws { +- if let configPath = Environment.current["PKG_CONFIG_PATH"] { +- #if os(Windows) +- return try configPath.split(separator: ";").map({ try AbsolutePath(validating: String($0)) }) +- #else +- return try configPath.split(separator: ":").map({ try AbsolutePath(validating: String($0)) }) +- #endif ++ var result: [Basics.AbsolutePath] = [] ++ for envVar in ["PKG_CONFIG_PATH", "PKG_CONFIG_PATH_FOR_TARGET"] { ++ if let configPath = Environment.current[EnvironmentKey(envVar)] { ++ #if os(Windows) ++ result += try configPath.split(separator: ";").map({ try Basics.AbsolutePath(validating: String($0)) }) ++ #else ++ result += try configPath.split(separator: ":").map({ try Basics.AbsolutePath(validating: String($0)) }) ++ #endif ++ } + } +- return [] ++ return result + } + } + } +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0008-set-compiler-vendor.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0008-set-compiler-vendor.patch new file mode 100644 index 000000000000..ea210e2efb26 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0008-set-compiler-vendor.patch @@ -0,0 +1,30 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 13 Dec 2025 22:59:36 -0500 +Subject: [PATCH 08/11] set-compiler-vendor + +--- + Sources/PackageModel/UserToolchain.swift | 6 ------ + 1 file changed, 6 deletions(-) + +diff --git a/Sources/PackageModel/UserToolchain.swift b/Sources/PackageModel/UserToolchain.swift +index 39d7333c5..b63997bad 100644 +--- a/Sources/PackageModel/UserToolchain.swift ++++ b/Sources/PackageModel/UserToolchain.swift +@@ -409,13 +409,7 @@ public final class UserToolchain: Toolchain { + } + + public func _isClangCompilerVendorApple() throws -> Bool? { +- // Assume the vendor is Apple on macOS. +- // FIXME: This might not be the best way to determine this. +- #if os(macOS) +- return true +- #else + return false +- #endif + } + + /// Returns the path to lldb. +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0009-add-missing-libraries.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0009-add-missing-libraries.patch new file mode 100644 index 000000000000..0f6fb621536f --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0009-add-missing-libraries.patch @@ -0,0 +1,45 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 13 Dec 2025 22:59:57 -0500 +Subject: [PATCH 09/11] add-missing-libraries + +--- + Sources/PackageSigning/CMakeLists.txt | 1 + + Sources/SwiftBuildSupport/CMakeLists.txt | 2 ++ + 2 files changed, 3 insertions(+) + +diff --git a/Sources/PackageSigning/CMakeLists.txt b/Sources/PackageSigning/CMakeLists.txt +index 13a7b8cd5..d00c7d01e 100644 +--- a/Sources/PackageSigning/CMakeLists.txt ++++ b/Sources/PackageSigning/CMakeLists.txt +@@ -21,6 +21,7 @@ target_link_libraries(PackageSigning PUBLIC + Basics + Crypto + PackageModel ++ SwiftASN1 + TSCBasic + TSCUtility + X509) +diff --git a/Sources/SwiftBuildSupport/CMakeLists.txt b/Sources/SwiftBuildSupport/CMakeLists.txt +index 3bd426bbf..c926ab811 100644 +--- a/Sources/SwiftBuildSupport/CMakeLists.txt ++++ b/Sources/SwiftBuildSupport/CMakeLists.txt +@@ -19,6 +19,7 @@ add_library(SwiftBuildSupport STATIC + PIFBuilder.swift + SwiftBuildSystem.swift) + target_link_libraries(SwiftBuildSupport PUBLIC ++ ArgumentParser + Build + DriverSupport + TSCBasic +@@ -26,6 +27,7 @@ target_link_libraries(SwiftBuildSupport PUBLIC + PackageGraph + SwiftBuild::SwiftBuild + SwiftBuild::SWBBuildService ++ SwiftSystem::SystemPackage + ) + + set_target_properties(SwiftBuildSupport PROPERTIES +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0010-Load-IndexStore-from-the-store.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0010-Load-IndexStore-from-the-store.patch new file mode 100644 index 000000000000..8d4e7cbf3889 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0010-Load-IndexStore-from-the-store.patch @@ -0,0 +1,35 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 11 Jul 2026 14:43:47 -0400 +Subject: [PATCH 10/11] Load IndexStore from the store + +--- + Sources/Build/LLBuildProgressTracker.swift | 9 +++------ + 1 file changed, 3 insertions(+), 6 deletions(-) + +diff --git a/Sources/Build/LLBuildProgressTracker.swift b/Sources/Build/LLBuildProgressTracker.swift +index 63a6a6caa..ac9b63419 100644 +--- a/Sources/Build/LLBuildProgressTracker.swift ++++ b/Sources/Build/LLBuildProgressTracker.swift +@@ -114,15 +114,12 @@ public final class BuildExecutionContext { + // library is currently installed as `libIndexStore.dll` rather than + // `IndexStore.dll`. In the future, this may require a fallback + // search, preferring `IndexStore.dll` over `libIndexStore.dll`. +- let indexStoreLib = self.toolsBuildParameters.toolchain.swiftCompilerPath +- .parentDirectory +- .appending("libIndexStore.dll") ++ let indexStoreLib = TSCAbsolutePath("@libclang@").appending(components: "lib", "libIndexStore.dll") + #else + let ext = self.toolsBuildParameters.triple.dynamicLibraryExtension +- let indexStoreLib = try toolsBuildParameters.toolchain.toolchainLibDir +- .appending("libIndexStore" + ext) ++ let indexStoreLib = TSCAbsolutePath("@libclang@").appending(components: "lib", "libIndexStore" + ext) + #endif +- return try .success(IndexStoreAPI(dylib: TSCAbsolutePath(indexStoreLib))) ++ return try .success(IndexStoreAPI(dylib: indexStoreLib)) + } catch { + return .failure(error) + } +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0011-Always-find-Clang-in-the-toolchain.patch b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0011-Always-find-Clang-in-the-toolchain.patch new file mode 100644 index 000000000000..618822002a2f --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0011-Always-find-Clang-in-the-toolchain.patch @@ -0,0 +1,40 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sun, 23 Aug 2026 21:49:05 -0400 +Subject: [PATCH 11/11] Always find Clang in the toolchain +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +We want Swift to be usable in a default stdenv, which means `CC` is GCC +on Linux. Since SwiftPM doesn’t actually support GCC, use Clang from the +toolchain. This means you can’t override the Clang version, but that’s +probably not a good idea usually. +--- + Sources/PackageModel/UserToolchain.swift | 10 ---------- + 1 file changed, 10 deletions(-) + +diff --git a/Sources/PackageModel/UserToolchain.swift b/Sources/PackageModel/UserToolchain.swift +index b63997bad..903bdeba3 100644 +--- a/Sources/PackageModel/UserToolchain.swift ++++ b/Sources/PackageModel/UserToolchain.swift +@@ -377,16 +377,6 @@ public final class UserToolchain: Toolchain { + return clang + } + +- // Check in the environment variable first. +- if let toolPath = UserToolchain.lookup( +- variable: "CC", +- searchPaths: self.envSearchPaths, +- environment: environment +- ) { +- self._clangCompiler = toolPath +- return toolPath +- } +- + // Then, check the toolchain. + if let toolPath = try? UserToolchain.getTool( + "clang", +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/package.nix new file mode 100644 index 000000000000..ab218a518210 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/package.nix @@ -0,0 +1,53 @@ +{ + lib, + stdenv, + stdlib, + swift, + swiftpm, +}: + +stdenv.mkDerivation { + name = "test-swiftpm-backdeploy-references-stdlib"; + + src = ./src; + + strictDeps = true; + + nativeBuildInputs = [ + swift + swiftpm + ]; + + doCheck = true; + + checkPhase = '' + swift run -c release | grep 'x: 1;x: 2;x: 3;x: 4' + ''; + + postFixup = '' + # This check has to be done post-fixup to make sure the stdlib’s rpath hook has run. + foundStdlib=0 + foundSwift=0 + + IFS= readarray -d $'\n' -t rpaths < <(objdump --macho --rpaths $out/bin/backdeploy-references-stdlib | tail -n +2) + for rpath in "''${rpaths[@]}"; do + if [[ "$rpath" =~ ${lib.escapeShellArg (lib.getLib stdlib)} ]]; then + foundStdlib=1 + fi + if [[ "$rpath" =~ ${lib.escapeShellArg (lib.getLib swift)} ]]; then + foundSwift=1 + fi + done + rm -rf "$out" + if [[ "$foundStdlib" == 0 || "$foundSwift" == 1 ]]; then + exit 1 + else + touch "$out" + fi + ''; + + __structuredAttrs = true; + + # Backdeployment is only used on Darwin. + meta.platforms = lib.platforms.darwin; +} diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/src/Package.swift b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/src/Package.swift new file mode 100644 index 000000000000..d5d9308d9948 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/src/Package.swift @@ -0,0 +1,14 @@ +// swift-tools-version: 6.2 + +import PackageDescription + +let package = Package( + name: "backdeploy-references-stdlib", + platforms: [.macOS("11.0")], + products: [ + .executable(name: "backdeploy-references-stdlib", targets: ["backdeploy-references-stdlib"]) + ], + targets: [ + .executableTarget(name: "backdeploy-references-stdlib", path: "Sources") + ] +) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/src/Sources/main.swift b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/src/Sources/main.swift new file mode 100644 index 000000000000..6dbf25a4e06b --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/src/Sources/main.swift @@ -0,0 +1,11 @@ +// Array.span can’t be backdeployed, so we have to work with buffer pointers for the test. +// See: https://forums.swift.org/t/using-span-on-pre-26-apple-os-versions/80513/4 +let arr = [1, 2, 3, 4] + +// Avoid `error: lifetime-dependent value escapes its scope` by extending the lifetime of the span. +arr.withUnsafeBufferPointer { ptr in + let span = ptr.span + for idx in span.indices { + print("x: \(span[idx]);", terminator: "") + } +} diff --git a/pkgs/development/compilers/swift_ng/sources-6.2.json b/pkgs/development/compilers/swift_ng/sources-6.2.json index fcd1710988d9..3bf0499947c8 100644 --- a/pkgs/development/compilers/swift_ng/sources-6.2.json +++ b/pkgs/development/compilers/swift_ng/sources-6.2.json @@ -32,6 +32,9 @@ "swift-llbuild": { "hash": "sha256-nZdiFXYrUiTSlSl6lxNFVpD2x8KGC4OVUUvJSOqH7gU=" }, + "swift-package-manager": { + "hash": "sha256-RIJLOoyDWWseBdDbJ5fluoZVq11jOdlV1yjq+m5xIws=" + }, "swift-syntax": { "hash": "sha256-DMMVJQj590RGGBkTgA89u01ZP2B8kbJTmfu+oxzYPds=" }, From 8e806474c476ea588df5653c89b47a802a2e7436 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 219/423] swiftPackages_ng.fetchSwiftPMDeps: init `fetchSwiftPMDeps` is an alternative to `swiftpm2nix` that uses a FOD, which should greatly simplify packaging Swift dependencies. --- .../by-name/fe/fetchSwiftPMDeps/package.nix | 153 ++++++++++++++++++ 1 file changed, 153 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/fe/fetchSwiftPMDeps/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/fe/fetchSwiftPMDeps/package.nix b/pkgs/development/compilers/swift_ng/by-name/fe/fetchSwiftPMDeps/package.nix new file mode 100644 index 000000000000..945f7dea168e --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/fe/fetchSwiftPMDeps/package.nix @@ -0,0 +1,153 @@ +# Fetches a package based on its metadata from `Package.resolved` +{ + lib, + cacert, + jq, + nix, + nix-prefetch-git, + runCommand, + stdenvNoCC, +}: + +{ + name ? if args ? pname && args ? version then "${args.pname}-${args.version}" else "swiftpm-deps", + hash ? (throw "fetchSwiftPMDeps requires a `hash` value to be set for ${name}"), + nativeBuildInputs ? [ ], + ... +}@args: + +let + removedArgs = [ + "name" + "pname" + "version" + "nativeBuildInputs" + "hash" + ]; + + vendorStaging = stdenvNoCC.mkDerivation ( + { + name = "${name}-vendor-staging"; + + impureEnvVars = lib.fetchers.proxyImpureEnvVars; + + strictDeps = true; + + nativeBuildInputs = [ + cacert + jq + nix-prefetch-git + ] + ++ nativeBuildInputs; + + buildPhase = '' + runHook preBuild + + resolved=$PWD/Package.resolved + stagingResolved=$out/Package.resolved + + mkdir -p "$out" + + # Convert version 1 to version 2 because its pins `schema` differs. + # Version 3 has the same pins schema, so it is already compatible. + if [ "$(jq --raw-output '.version' < "$resolved")" = "1" ]; then + jq ' + { + pins: [ + .object.pins[] | { + identity: .package, + kind: "remoteSourceControl", + location: .repositoryURL, + state: .state + } + ], + version: 2 + } + ' < "$resolved" > "$stagingResolved" + else + cp "$resolved" "$stagingResolved" + fi + + if [ -n "$(jq --raw-output '.pins[] | select(.kind != "remoteSourceControl")' < "$stagingResolved")" ]; then + echo "Only Git-based dependencies are supported by fetchSwiftPMDeps" + exit 1 + fi + + jq --raw-output0 '.pins[] | select(.kind == "remoteSourceControl")' < "$stagingResolved" | while IFS= read -d "" pin; do + url=$(jq --raw-output '.location' <<< "$pin") + name=$(basename "$url" .git) + rev=$(jq --raw-output '.state.revision' <<< "$pin") + nix-prefetch-git --builder --quiet --fetch-submodules --url "$url" --rev "$rev" --out "$out/Packages/$name" + done + + runHook postBuild + ''; + + dontConfigure = true; + dontInstall = true; + dontFixup = true; + + outputHash = hash; + outputHashAlgo = if hash == "" then "sha256" else null; + outputHashMode = "recursive"; + + __structuredAttrs = true; + } + // builtins.removeAttrs args removedArgs + ); +in + +# `fetchSwiftPMDeps` splits the workspace-state generation into a separate, non-FOD derivation in case the format +# of the file ever changes or in case we have to do additional processing due to changes in SwiftPM. +runCommand "${name}-vendor" + { + inherit vendorStaging; + nativeBuildInputs = [ jq ]; + } + '' + mkdir -p "$out" + + # SwiftPM uses workspace-state.json to determine whether it needs to fetch dependencies. + # Generate it to prevent that from happening. + jq --compact-output --sort-keys ' + { + "object": { + "artifacts": [ ], + "dependencies": [ .pins[] | + { + "basedOn": { + "basedOn": null, + "packageRef": { + "identity": .identity, + "kind": .kind, + "location": .location, + "name": .location | sub("\\.git$"; "") | split("/")[-1] + }, + "state": { + "checkoutState": .state, + "name": "sourceControlCheckout" + }, + "subpath": .location | sub("\\.git$"; "") | split("/")[-1] + }, + "packageRef": { + "identity": .identity, + "kind": .kind, + "location": .location, + "name": .location | sub("\\.git$"; "") | split("/")[-1] + }, + "state": { + "name": "edited", + "path": null + }, + "subpath": .location | sub("\\.git$"; "") | split("/")[-1] + } + ], + "prebuilts": [ ] + }, + "version": 7 + } + ' < "$vendorStaging/Package.resolved" > "$out/workspace-state.json" + + # Symlink the packages from the staging area. There’s no reason to waste space copying them. + ln -s "$vendorStaging/Packages" "$out/Packages" + '' From deff8c14929d2fd48f3c18297195e660fc792125 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 220/423] swiftPackages_ng.swiftpmUnpackHook: init at 6.2.4 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Sets up the Swift package with its dependencies “vendored” from the FOD created by `fetchSwiftPMDeps`. Because SwiftPM does not support vendoring dependencies natively, this hook instead sets them up as if they are being “edited”, which causes SwiftPM to use what has been copied or symlinked into the top-level `Packages` folder of the build. --- .../by-name/sw/swiftpmUnpackHook/package.nix | 13 ++++++ .../sw/swiftpmUnpackHook/setup-hook.sh | 46 +++++++++++++++++++ 2 files changed, 59 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftpmUnpackHook/package.nix create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftpmUnpackHook/setup-hook.sh diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpmUnpackHook/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpmUnpackHook/package.nix new file mode 100644 index 000000000000..e3c19f343b7e --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpmUnpackHook/package.nix @@ -0,0 +1,13 @@ +{ + lib, + jq, + makeSetupHook, + swiftpm, +}: + +makeSetupHook { + name = "${lib.getName swiftpm}-unpack-hook-${lib.getVersion swiftpm}"; + substitutions = { + jq = lib.getExe jq; + }; +} ./setup-hook.sh diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpmUnpackHook/setup-hook.sh b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpmUnpackHook/setup-hook.sh new file mode 100644 index 000000000000..c991654efa92 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpmUnpackHook/setup-hook.sh @@ -0,0 +1,46 @@ +# shellcheck shell=bash + +swiftpmUnpackDeps() { + if [ -n "$swiftpmDeps" ]; then + echo "Unpacking SwiftPM dependencies" + + # Set up `workspace-state.json`. Local packages must be added now, or SwiftPM will try to fetch their dependencies. + mkdir -p "$NIX_BUILD_TOP/$sourceRoot/.build" + @jq@ -s --sort-keys ' + { + "object": { + "artifacts": [ ], + "dependencies": ( + (.[0] | .object.dependencies) + + [ .[1] | .dependencies[] | select(.fileSystem) | .[][] | + { + "basedOn": null, + "packageRef": { + "identity": .identity, + "kind": "fileSystem", + "location": .path, + "name": .path | sub("\\.git$"; "") | split("/")[-1] + }, + "state": { + "name": "fileSystem", + "path": .path + }, + "subpath": .identity + } + ] + ), + "prebuilts": [ ], + }, + "version": 7 + } + ' "$swiftpmDeps/workspace-state.json" <(swift package dump-package --package-path "$NIX_BUILD_TOP/$sourceRoot") \ + > "$NIX_BUILD_TOP/$sourceRoot/.build/workspace-state.json~" + mv "$NIX_BUILD_TOP/$sourceRoot/.build/workspace-state.json~" "$NIX_BUILD_TOP/$sourceRoot/.build/workspace-state.json" + + # The closest thing to vendoring SwiftPM supports is setting up a dependencies as edited at `Packages`. + ln -s "$swiftpmDeps/Packages" "$NIX_BUILD_TOP/$sourceRoot/Packages" + fi +} + +appendToVar postUnpackHooks swiftpmUnpackDeps + From e2408a353251f34358012934fce618762c37e300 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 221/423] swiftPackages_ng.swiftpmHook: init at 6.2.4 This hook is similar to the SwiftPM 5.10.1 hook already in Nixpkgs except it also includes an install phase. --- .../by-name/sw/swiftpmHook/package.nix | 43 +++++ .../by-name/sw/swiftpmHook/setup-hook.sh | 169 ++++++++++++++++++ 2 files changed, 212 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftpmHook/package.nix create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftpmHook/setup-hook.sh diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpmHook/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpmHook/package.nix new file mode 100644 index 000000000000..8b3a253e4308 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpmHook/package.nix @@ -0,0 +1,43 @@ +{ + lib, + cctools, + jq, + llvmPackages_upstream, + llvm_libtool, + makeSetupHook, + stdenv, + stdenvNoCC, + swiftpm, + swiftpmUnpackHook, +}: + +let + vtool = stdenvNoCC.mkDerivation { + pname = "cctools-vtool"; + version = lib.getVersion cctools; + + buildCommand = '' + mkdir -p "$out/bin" + ln -s ${lib.getExe' cctools "vtool"} "$out/bin/vtool" + ''; + }; +in + +makeSetupHook { + name = "${lib.getName swiftpm}-hook-${lib.getVersion swiftpm}"; + propagatedBuildInputs = [ + swiftpmUnpackHook + ] + ++ lib.optionals stdenvNoCC.hostPlatform.isDarwin [ + # SwiftPM requires these tools for builds on Darwin. + # It also requires xcrun, which is already part of the Darwin stdenv. + llvm_libtool + vtool + ]; + substitutions = { + inherit (stdenvNoCC.hostPlatform.extensions) sharedLibrary; + swiftPlatform = stdenv.hostPlatform.swift.platform; + install_name_tool = lib.getExe' llvmPackages_upstream.llvm "llvm-install-name-tool"; + jq = lib.getExe jq; + }; +} ./setup-hook.sh diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpmHook/setup-hook.sh b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpmHook/setup-hook.sh new file mode 100644 index 000000000000..2a76abd6a80e --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpmHook/setup-hook.sh @@ -0,0 +1,169 @@ +# shellcheck shell=bash + +swiftpm_addCVars() { + swiftLibDir='.*/lib/swift\(_static\)?/\(host\|@swiftPlatform@\)\(/plugins\|/plugins/testing\|/testing\)?$' + while IFS= read -d "" d; do + # Avoid adding paths that have already been added + if [[ "${swiftpmFlags-}" =~ \ $d\ ]]; then + continue + fi + # Only add the folder if it actually contains Swift modules. + if [ -n "$(ls "$d"/*.swiftmodule)" ]; then + appendToVar swiftpmFlags -Xswiftc -I -Xswiftc "$d" + fi + # Compiler plugins + if [[ "$d" =~ plugins(/testing)?$ && -n "$(ls "$d"/*@sharedLibrary@)" ]]; then + appendToVar swiftpmFlags -Xswiftc -plugin-path -Xswiftc "$d" + fi + done < <(find "$1" -type d -and -regex "$swiftLibDir" -print0) +} + +addEnvHooks "$targetOffset" swiftpm_addCVars + +# Build using 'swift build'. +swiftpmBuildPhase() { + runHook preBuild + + local buildCores=1 + if [ "${enableParallelBuilding-1}" ]; then + buildCores="$NIX_BUILD_CORES" + fi + + local flagsArray=( + -j "$buildCores" + -c "${swiftpmBuildConfig-release}" + -Xswiftc -module-cache-path -Xswiftc "$NIX_BUILD_TOP/module-cache" + ) + concatTo flagsArray swiftpmFlags swiftpmFlagsArray + + echoCmd 'SwiftPM flags' "${flagsArray[@]}" + TERM=dumb swift build --disable-sandbox "${flagsArray[@]}" + + runHook postBuild +} + +if [ -z "${dontUseSwiftpmBuild-}" ] && [ -z "${buildPhase-}" ]; then + buildPhase=swiftpmBuildPhase +fi + +# Check using 'swift test'. +swiftpmCheckPhase() { + runHook preCheck + + local buildCores=1 + if [ "${enableParallelBuilding-1}" ]; then + buildCores="$NIX_BUILD_CORES" + fi + + local flagsArray=( + -j "$buildCores" + -c "${swiftpmBuildConfig-release}" + ) + concatTo flagsArray swiftpmFlags swiftpmFlagsArray + + echoCmd 'check flags' "${flagsArray[@]}" + TERM=dumb swift test "${flagsArray[@]}" + + runHook postCheck +} + +if [ -z "${dontUseSwiftpmCheck-}" ] && [ -z "${checkPhase-}" ]; then + checkPhase=swiftpmCheckPhase +fi + +# Helper used to find the binary output path. +# Useful for performing the installPhase of swiftpm packages. +swiftpmBinPath() { + local flagsArray=( + -c "${swiftpmBuildConfig-release}" + ) + concatTo flagsArray swiftpmFlags swiftpmFlagsArray + + swift build --show-bin-path "${flagsArray[@]}" +} + +# TODO: Support static libraries. +swiftpmInstallPhase() { + runHook preInstall + + local products=$(swiftpmBinPath) + while IFS= read -d "" exe; do + install -D -m 755 "$products/$exe" "${!outputBin}/bin/$exe" + done < <(swift package dump-package | @jq@ --raw-output0 '.products[] | select(.type | has("executable")) | .name') + + local libsToInstall=() + local modulesToInstall=() + + while IFS= read -d "" library; do + if [ -e "$products/lib$library@sharedLibrary@" ]; then + if isMachO "$products/lib$library@sharedLibrary@"; then + @install_name_tool@ "$products/lib$library@sharedLibrary@" \ + -id "${!outputLib}/lib/lib$library@sharedLibrary@" + fi + appendToVar libsToInstall "$products/lib$library@sharedLibrary@" + fi + if [ -e "$products/$library.swiftmodule" ]; then + appendToVar modulesToInstall "$products/$library.swiftmodule" + fi + if [ -e "$products/Modules/$library.swiftmodule" ]; then + appendToVar modulesToInstall "$products/Modules/$library.swiftmodule" + fi + done < <(swift package dump-package | @jq@ --raw-output0 '.products[] | select(.type | has("library")) | .name') + + if [ -n "${libsToInstall}" ]; then + install -D -t "${!outputLib}/lib" "${libsToInstall[@]}" + # Only install modules if there are any library products. + if [ -n "${modulesToInstall}" ]; then + install -D -t "${!outputInclude}/lib/swift/@swiftPlatform@" "${modulesToInstall[@]}" + fi + fi + + runHook postInstall +} + +if [ -z "${dontUseSwiftpmInstall-}" ] && [ -z "${installPhase-}" ]; then + installPhase=swiftpmInstallPhase +fi + +# Based on CMake’s setup-hook +makeSwiftPMFindLibs() { + local -A swiftpmLibFlags + isystem_seen= + iframework_seen= + for flag in ${NIX_CFLAGS_COMPILE-}; do + if test -n "$isystem_seen" && test -d "$flag"; then + isystem_seen= + swiftpmLibFlags["${flag}"]="-Xcc -isystem -Xcc" + elif test -n "$iframework_seen" && test -d "$flag"; then + iframework_seen= + swiftpmLibFlags["${flag}"]="-Xcc -iframework -Xcc" + else + isystem_seen= + iframework_seen= + case $flag in + -I*) + swiftpmLibFlags["${flag:2}"]="-Xcc -I -Xcc" + ;; + -L*) + swiftpmLibFlags["${flag:2}"]="-Xlinker -L -Xlinker" + ;; + -F*) + swiftpmLibFlags["${flag:2}"]="-Xcc -F -Xcc" + ;; + -isystem) + isystem_seen=1 + ;; + -iframework) + iframework_seen=1 + ;; + esac + fi + done + for flag in "${!swiftpmLibFlags[@]}"; do + appendToVar swiftpmFlags ${swiftpmLibFlags["${flag}"]} "$flag" + done +} + +# not using setupHook, because it could be a setupHook adding additional +# include flags to NIX_CFLAGS_COMPILE +postHooks+=(makeSwiftPMFindLibs) From da05dc18ce586df60d69656cfbac6f1d912aa20a Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 222/423] swiftPackages_ng.swiftpm: propagate `swiftpmHook` Ideally, packages would opt into hook behavior by including the hook explicitly, but that would be a significantly breaking change. At least for now, propagate the hook for compatibility. --- .../compilers/swift_ng/by-name/sw/swiftpm/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/package.nix index e80082a64aef..3f879b94da5e 100644 --- a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/package.nix +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/package.nix @@ -21,6 +21,7 @@ swift-syntax, swift-system, swift-tools-support-core, + swiftpmHook, swift_release, swift_sources, }: @@ -117,6 +118,8 @@ stdenv.mkDerivation (finalAttrs: { swift ]; + propagatedBuildInputs = [ swiftpmHook ]; + buildInputs = [ sqlite swift-argument-parser From 3afe5aec32df5ac5e28c1b08dc7be41db4833995 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 223/423] swiftPackages_ng.swiftpm2nix: port to swiftpmUnpackHook swiftpm2nix includes everything (and a bit more, which can be ignored) needed by `swiftpm2UnpackHook` to unpack and setup dependencies. This allows swiftpm2nix to use the edit-based vendoring method and automatically gain any improvements made to that hook --- .../by-name/sw/swiftpm2nix/package.nix | 42 +++++++ .../by-name/sw/swiftpm2nix/support.nix | 109 ++++++++++++++++++ .../by-name/sw/swiftpm2nix/swiftpm2nix.sh | 45 ++++++++ 3 files changed, 196 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftpm2nix/package.nix create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftpm2nix/support.nix create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftpm2nix/swiftpm2nix.sh diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm2nix/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm2nix/package.nix new file mode 100644 index 000000000000..24d84ea51502 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm2nix/package.nix @@ -0,0 +1,42 @@ +{ + lib, + stdenv, + callPackage, + makeWrapper, + jq, + nurl, +}: + +stdenv.mkDerivation { + name = "swiftpm2nix"; + + strictDeps = true; + + nativeBuildInputs = [ makeWrapper ]; + + dontUnpack = true; + + installPhase = '' + install -vD ${./swiftpm2nix.sh} $out/bin/swiftpm2nix + wrapProgram $out/bin/$name \ + --prefix PATH : ${ + lib.makeBinPath [ + jq + nurl + ] + } + ''; + + preferLocalBuild = true; + + passthru = callPackage ./support.nix { }; + + __structuredAttrs = true; + + meta = { + description = "Generate a Nix expression to fetch swiftpm dependencies"; + mainProgram = "swiftpm2nix"; + teams = [ lib.teams.swift ]; + platforms = lib.platforms.all; + }; +} diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm2nix/support.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm2nix/support.nix new file mode 100644 index 000000000000..07525e1b656a --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm2nix/support.nix @@ -0,0 +1,109 @@ +{ + lib, + fetchgit, + formats, + jq, + swiftpmHook, + swiftpmUnpackHook, +}: +let + inherit (lib) + concatStrings + listToAttrs + makeOverridable + mapAttrsToList + nameValuePair + ; + json = formats.json { }; +in +rec { + + # Derive a pin file from workspace state. + mkPinFile = + workspaceState: + assert workspaceState.version >= 5 && workspaceState.version <= 6; + json.generate "Package.resolved" { + version = 1; + object.pins = map (dep: { + package = dep.packageRef.name; + repositoryURL = dep.packageRef.location; + state = dep.state.checkoutState; + }) workspaceState.object.dependencies; + }; + + # Make packaging helpers from swiftpm2nix generated output. + helpers = + generated: + let + inherit (import generated) workspaceStateFile hashes; + workspaceState = lib.importJSON workspaceStateFile; + pinFile = mkPinFile workspaceState; + in + rec { + + # Create fetch expressions for dependencies. + sources = listToAttrs ( + map ( + dep: + nameValuePair dep.subpath (fetchgit { + url = dep.packageRef.location; + rev = dep.state.checkoutState.revision; + sha256 = hashes.${dep.subpath}; + fetchSubmodules = true; + }) + ) workspaceState.object.dependencies + ); + + # Configure phase snippet for use in packaging. + configure = '' + swiftpmDeps=$NIX_BUILD_TOP/swiftpmDeps + mkdir -p "$swiftpmDeps/Packages" + + # Rewrite the workspace-state.json to put the packages in edit mode. This is needed for compatibility with + # `swiftpmUnpackDeps`, which uses edit mode for vendoring. + ${lib.getExe jq} ' + { + "object": { + "artifacts": .object.artifacts[] // [ ], + "dependencies": [ .object.dependencies[] | + { + "basedOn": .basedOn, + "packageRef": .packageRef, + "state": { + "name": "edited", + "path": null + }, + "subpath": .subpath, + } + ], + "prebuilts": [ ], + }, + "version": 7 + } + ' < ${workspaceStateFile} > "$swiftpmDeps/workspace-state.json" + '' + + concatStrings ( + mapAttrsToList (name: src: '' + ln -s '${src}' "$swiftpmDeps/Packages/${name}" + '') sources + ) + + '' + swiftpmUnpackDeps + + # Helper that makes a swiftpm dependency mutable by copying the source. + swiftpmMakeMutable() { + local checkoutDir=$NIX_BUILD_TOP/$sourceRoot/.build/checkouts + local orig=$(readlink -f "Packages/$1") + + mkdir -p "$checkoutDir" + cp -r "$orig" "$checkoutDir/$1" + chmod -R u+w "$checkoutDir/$1" + + rm "Packages/$1" + ln -s "$checkoutDir/$1" "Packages/$1" + } + ''; + + }; + +} diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm2nix/swiftpm2nix.sh b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm2nix/swiftpm2nix.sh new file mode 100644 index 000000000000..e5525c51b200 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm2nix/swiftpm2nix.sh @@ -0,0 +1,45 @@ +#!/usr/bin/env bash + +# Generates a Nix expression to fetch swiftpm dependencies, and a +# configurePhase snippet to prepare a working directory for swift build. + +set -eu -o pipefail +shopt -s lastpipe + +stateFile=".build/workspace-state.json" +if [[ ! -f "$stateFile" ]]; then + echo >&2 "Missing $stateFile. Run 'swift package resolve' first." + exit 1 +fi + +stateVersion="$(jq .version $stateFile)" +if [[ $stateVersion -lt 5 || $stateVersion -gt 7 ]]; then + echo >&2 "Unsupported $stateFile version" + exit 1 +fi + +# Iterate dependencies and prefetch. +hashes="" +jq -r '.object.dependencies[] | "\(.subpath) \(.packageRef.location) \(.state.checkoutState.revision)"' $stateFile \ +| while read -r name url rev; do + echo >&2 "-- Fetching $name" + hash="$(nurl "$url" "$rev" --json --submodules=true --fetcher=fetchgit | jq -r .args.hash)" +hashes+=" + \"$name\" = \"$hash\";" + echo >&2 +done +hashes+=$'\n'" " + +# Generate output. +mkdir -p nix +# Copy the workspace state, but clear 'artifacts'. +jq '.object.artifacts = []' < $stateFile > nix/workspace-state.json +# Build an expression for fetching sources, and preparing the working directory. +cat > nix/default.nix << EOF +# This file was generated by swiftpm2nix. +{ + workspaceStateFile = ./workspace-state.json; + hashes = {$hashes}; +} +EOF +echo >&2 "-- Generated ./nix" From 3a44ae2ba8a6d360a8b1502f3bd9a4d63b85095b Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 224/423] swiftPackages_ng.swift: add tests - Port over cxx-interop-test from the Swift 5.10.1 implementation and also add support for testing using Swift from C++; - Add tests for the repl and scripting; - Add tests for features that impact macOS such as Swift Differentiation (dropped from macOS 26.4) and Foundation Macros; and - Add tests for Swift Testing to confirm it works. --- .../swift_ng/by-name/sw/swift/package.nix | 5 +++ .../sw/swift/tests/cxx-interop/package.nix | 31 ++++++++++++++++++ .../sw/swift/tests/cxx-interop/src/Makefile | 11 +++++++ .../swift/tests/cxx-interop/src/Package.swift | 19 +++++++++++ .../cxx-interop/src/Sources/SwiftStruct.swift | 9 ++++++ .../tests/cxx-interop/src/Sources/main.swift | 3 ++ .../sw/swift/tests/cxx-interop/src/main.cpp | 8 +++++ .../swift/tests/differentiation/package.nix | 27 ++++++++++++++++ .../tests/differentiation/src/Package.swift | 13 ++++++++ .../differentiation/src/Sources/main.swift | 10 ++++++ .../swift/tests/foundation-macros/package.nix | 26 +++++++++++++++ .../tests/foundation-macros/src/Package.swift | 14 ++++++++ .../foundation-macros/src/Sources/main.swift | 14 ++++++++ .../by-name/sw/swift/tests/repl/package.nix | 23 +++++++++++++ .../sw/swift/tests/scripting/package.nix | 14 ++++++++ .../sw/swift/tests/scripting/script.swift | 17 ++++++++++ .../sw/swift/tests/swift-testing/package.nix | 32 +++++++++++++++++++ .../tests/swift-testing/src/Package.swift | 18 +++++++++++ .../swift-testing/src/Sources/Hello.swift | 5 +++ .../swift-testing/src/Tests/HelloTests.swift | 14 ++++++++ 20 files changed, 313 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/package.nix create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/src/Makefile create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/src/Package.swift create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/src/Sources/SwiftStruct.swift create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/src/Sources/main.swift create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/src/main.cpp create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/differentiation/package.nix create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/differentiation/src/Package.swift create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/differentiation/src/Sources/main.swift create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/foundation-macros/package.nix create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/foundation-macros/src/Package.swift create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/foundation-macros/src/Sources/main.swift create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/repl/package.nix create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/scripting/package.nix create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/scripting/script.swift create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/swift-testing/package.nix create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/swift-testing/src/Package.swift create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/swift-testing/src/Sources/Hello.swift create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/swift-testing/src/Tests/HelloTests.swift diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix index 8fdd03b0723e..a195f9429a4b 100644 --- a/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix @@ -2,6 +2,7 @@ lib, apple-sdk_14, apple-sdk_26, + callPackage, llvmPackages, llvmPackages_upstream, patchelf, @@ -223,6 +224,10 @@ stdenv.mkDerivation (finalAttrs: { passthru = { inherit swiftc swift-driver; + tests = lib.packagesFromDirectoryRecursive { + inherit callPackage; + directory = ./tests; + }; }; meta = { diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/package.nix new file mode 100644 index 000000000000..3a772f5ac7fa --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/package.nix @@ -0,0 +1,31 @@ +{ + stdenv, + swift, + swiftpm, +}: + +stdenv.mkDerivation { + name = "swift-test-cxx-interop"; + + src = ./src; + + strictDeps = true; + + nativeBuildInputs = [ + swift + swiftpm + ]; + + buildPhase = '' + swiftpmBuildPhase + make + ''; + + installPhase = '' + swift run -c release CxxInteropTest | grep 'Hello, Swift!' + ./SwiftToCxxInteropTest | grep 'Hello, C++!' + touch "$out" + ''; + + __structuredAttrs = true; +} diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/src/Makefile b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/src/Makefile new file mode 100644 index 000000000000..90139e6b3ef3 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/src/Makefile @@ -0,0 +1,11 @@ +.PHONY: all +all: SwiftToCxxInteropTest + +SwiftStruct.o Check-SwiftStruct.h: Sources/SwiftStruct.swift + swiftc -parse-as-library -emit-clang-header-path Check-SwiftStruct.h -module-name Check -cxx-interoperability-mode=default $^ -c -o SwiftStruct.o + +main.o: main.cpp Check-SwiftStruct.h + clang++ $< -c -o $@ + +SwiftToCxxInteropTest: main.o SwiftStruct.o + swiftc $^ -o $@ diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/src/Package.swift b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/src/Package.swift new file mode 100644 index 000000000000..2ec53f023be8 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/src/Package.swift @@ -0,0 +1,19 @@ +// swift-tools-version: 5.10 + +import PackageDescription + +let package = Package( + name: "CxxInteropTest", + products: [ + .executable(name: "CxxInteropTest", targets: ["CxxInteropTest"]) + ], + targets: [ + .executableTarget( + name: "CxxInteropTest", + path: "Sources", + swiftSettings: [ + .interoperabilityMode(.Cxx) + ] + ) + ] +) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/src/Sources/SwiftStruct.swift b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/src/Sources/SwiftStruct.swift new file mode 100644 index 000000000000..cdadd6b97f34 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/src/Sources/SwiftStruct.swift @@ -0,0 +1,9 @@ +import CxxStdlib + +public struct SwiftStruct { + public let hello: std.string + + public init(hello: std.string) { + self.hello = hello + } +} diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/src/Sources/main.swift b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/src/Sources/main.swift new file mode 100644 index 000000000000..1e89c7a14867 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/src/Sources/main.swift @@ -0,0 +1,3 @@ +let swiftStruct = SwiftStruct(hello: "Hello, Swift!") +let cxxHello = swiftStruct.hello +print(String(cxxHello)) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/src/main.cpp b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/src/main.cpp new file mode 100644 index 000000000000..24d12e48c9ca --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/src/main.cpp @@ -0,0 +1,8 @@ +#include + +#include "Check-SwiftStruct.h" + +int main() { + auto swiftStruct = Check::SwiftStruct::init("Hello, C++!"); + std::cout << swiftStruct.getHello() << std::endl; +} diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/differentiation/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/differentiation/package.nix new file mode 100644 index 000000000000..8b45cc36728f --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/differentiation/package.nix @@ -0,0 +1,27 @@ +{ + stdenv, + swift, + swiftpm, +}: + +# Test that Swift Differentiation works. This test is particularly important for Darwin because the +# Swift Differentiation dylib is no longer distributed with macOS (as of 26.4). +stdenv.mkDerivation { + name = "swift-test-differentiation"; + + src = ./src; + + strictDeps = true; + + nativeBuildInputs = [ + swift + swiftpm + ]; + + installPhase = '' + swift run -c release differentiation 4 | grep '8.0' + touch "$out" + ''; + + __structuredAttrs = true; +} diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/differentiation/src/Package.swift b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/differentiation/src/Package.swift new file mode 100644 index 000000000000..3c1ca846970f --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/differentiation/src/Package.swift @@ -0,0 +1,13 @@ +// swift-tools-version: 6.2 + +import PackageDescription + +let package = Package( + name: "differentiation", + products: [ + .executable(name: "differentiation", targets: ["differentiation"]) + ], + targets: [ + .executableTarget(name: "differentiation", path: "Sources") + ] +) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/differentiation/src/Sources/main.swift b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/differentiation/src/Sources/main.swift new file mode 100644 index 000000000000..74d86fe609cf --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/differentiation/src/Sources/main.swift @@ -0,0 +1,10 @@ +import _Differentiation + +@differentiable(reverse) +func f(x: Double) -> Double { + return x * x +} + +let m = gradient(at: Double(CommandLine.arguments[1])!, of: f) + +print(m) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/foundation-macros/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/foundation-macros/package.nix new file mode 100644 index 000000000000..0e22d74b2b2b --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/foundation-macros/package.nix @@ -0,0 +1,26 @@ +{ + stdenv, + swift, + swiftpm, +}: + +# The primary goal of this test is to confirm that the foundation macros built with the toolchain work on Darwin. +stdenv.mkDerivation { + name = "swift-test-foundation-macros"; + + src = ./src; + + strictDeps = true; + + nativeBuildInputs = [ + swift + swiftpm + ]; + + installPhase = '' + swift run -c release foundation-macros | grep 'Hello, foundation macros' + touch "$out" + ''; + + __structuredAttrs = true; +} diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/foundation-macros/src/Package.swift b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/foundation-macros/src/Package.swift new file mode 100644 index 000000000000..99cd2a9934cb --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/foundation-macros/src/Package.swift @@ -0,0 +1,14 @@ +// swift-tools-version: 6.2 + +import PackageDescription + +let package = Package( + name: "foundation-macros", + platforms: [.macOS("14.0")], + products: [ + .executable(name: "foundation-macros", targets: ["foundation-macros"]) + ], + targets: [ + .executableTarget(name: "foundation-macros", path: "Sources") + ] +) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/foundation-macros/src/Sources/main.swift b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/foundation-macros/src/Sources/main.swift new file mode 100644 index 000000000000..3e2a66c57b9a --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/foundation-macros/src/Sources/main.swift @@ -0,0 +1,14 @@ +import Foundation + +let wordPred = #Predicate { s in s == "foundation" || s == "macros" } + +let words = [ + "foo", + "foundation", + "macros", + "swift", + "world", +] +let filtered = try! words.filter(wordPred) + +print("Hello, \(filtered.joined(separator: " "))") diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/repl/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/repl/package.nix new file mode 100644 index 000000000000..09353c38fef2 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/repl/package.nix @@ -0,0 +1,23 @@ +{ + lib, + runCommand, + swift, +}: + +# Make sure the REPL works. It’s a bit finicky on Linux. +runCommand "swift-test-repl" + { + nativeBuildInputs = [ swift ]; + meta.badPlatforms = [ + # Darwin can’t run this test because it requires `debugserver`, which is non-free. + # Even if it could use `debugserver`, the build user would need debugging access, which it will not have. + lib.systems.inspect.patterns.isDarwin + ]; + } + '' + swift repl < Double { + return x * x +} + +let m = gradient(at: Double(CommandLine.arguments[1])!, of: f) + +let data = Data("Hello, \(m)".utf8) +let str = String(decoding: data, as: UTF8.self) + +print(str) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/swift-testing/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/swift-testing/package.nix new file mode 100644 index 000000000000..a320da544018 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/swift-testing/package.nix @@ -0,0 +1,32 @@ +{ + lib, + swift, + swiftpm, + stdenv, +}: + +stdenv.mkDerivation { + name = "swift-test-swift-testing"; + + src = ./src; + + strictDeps = true; + + nativeBuildInputs = [ + swift + swiftpm + ]; + + doCheck = true; + + installPhase = '' + touch "$out" + ''; + + __structuredAttrs = true; + + meta.badPlatforms = [ + # This test won’t work on Darwin until XCTest is modified to work on Darwin without requiring Xcode. + lib.systems.inspect.patterns.isDarwin + ]; +} diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/swift-testing/src/Package.swift b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/swift-testing/src/Package.swift new file mode 100644 index 000000000000..e707f58c6b29 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/swift-testing/src/Package.swift @@ -0,0 +1,18 @@ +// swift-tools-version: 6.2 + +import PackageDescription + +let package = Package( + name: "test-swift-testing", + products: [ + .library(name: "test-swift-testing", type: .dynamic, targets: ["test-swift-testing"]) + ], + targets: [ + .target(name: "test-swift-testing", path: "Sources"), + .testTarget( + name: "test-swift-testing-tests", + dependencies: ["test-swift-testing"], + path: "Tests" + ), + ] +) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/swift-testing/src/Sources/Hello.swift b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/swift-testing/src/Sources/Hello.swift new file mode 100644 index 000000000000..1fa85f9560f5 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/swift-testing/src/Sources/Hello.swift @@ -0,0 +1,5 @@ +struct HelloStruct { + let message: String + + func sayHello() -> String { "Hello, \(self.message)" } +} diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/swift-testing/src/Tests/HelloTests.swift b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/swift-testing/src/Tests/HelloTests.swift new file mode 100644 index 000000000000..c4fa23805b2c --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/swift-testing/src/Tests/HelloTests.swift @@ -0,0 +1,14 @@ +import Testing + +@testable import test_swift_testing + +@Suite struct HelloStructTests { + @Test func itSaysHello() { + let expected = "Hello, Nixpkgs!" + + let s = HelloStruct(message: "Nixpkgs!") + let result = s.sayHello() + + #expect(result == expected) + } +} From f7277f257282b82bfecb12424f2324df82b430f7 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 225/423] swiftPackages_ng.sourcekit-lsp: init at 6.2.4 --- .../by-name/so/sourcekit-lsp/Package.resolved | 195 ++++++++++++++++++ .../by-name/so/sourcekit-lsp/package.nix | 96 +++++++++ ...sing-swift-corelibs-xctest-on-Darwin.patch | 27 +++ .../0002-Load-IndexStore-from-the-store.patch | 48 +++++ .../compilers/swift_ng/sources-6.2.json | 6 + 5 files changed, 372 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/so/sourcekit-lsp/Package.resolved create mode 100644 pkgs/development/compilers/swift_ng/by-name/so/sourcekit-lsp/package.nix create mode 100644 pkgs/development/compilers/swift_ng/by-name/so/sourcekit-lsp/patches/0001-Fix-for-using-swift-corelibs-xctest-on-Darwin.patch create mode 100644 pkgs/development/compilers/swift_ng/by-name/so/sourcekit-lsp/patches/0002-Load-IndexStore-from-the-store.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/so/sourcekit-lsp/Package.resolved b/pkgs/development/compilers/swift_ng/by-name/so/sourcekit-lsp/Package.resolved new file mode 100644 index 000000000000..f084392f4564 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/so/sourcekit-lsp/Package.resolved @@ -0,0 +1,195 @@ +{ + "originHash" : "5f567b0c0cf4b1a211e9fb649f0b00e14f04b8ea55a3c96cc77462e3b6f933be", + "pins" : [ + { + "identity" : "indexstore-db", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/indexstore-db.git", + "state" : { + "branch" : "release/6.2", + "revision" : "cf29ef4e5e5243a3b6f518d72c6e527b5290375a" + } + }, + { + "identity" : "swift-argument-parser", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-argument-parser.git", + "state" : { + "revision" : "6a52f3251125d74daf04fcbd5e6f08a75d074382", + "version" : "1.8.2" + } + }, + { + "identity" : "swift-asn1", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-asn1.git", + "state" : { + "revision" : "a9a5efd40eaf558a2bcd48d64b1d1646be686008", + "version" : "1.7.1" + } + }, + { + "identity" : "swift-atomics", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-atomics.git", + "state" : { + "revision" : "0442cb5a3f98ab802acb777929fdb446bda11a34", + "version" : "1.3.1" + } + }, + { + "identity" : "swift-certificates", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-certificates.git", + "state" : { + "revision" : "2f797305c1b5b982acaa6005d8a9f970cc4e97ff", + "version" : "1.5.0" + } + }, + { + "identity" : "swift-cmark", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-cmark.git", + "state" : { + "branch" : "release/6.2", + "revision" : "5d9bdaa4228b381639fff09403e39a04926e2dbe" + } + }, + { + "identity" : "swift-collections", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-collections.git", + "state" : { + "revision" : "c11818f3cae0780656baa430b49e7f163f08dffd", + "version" : "1.1.6" + } + }, + { + "identity" : "swift-crypto", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-crypto.git", + "state" : { + "revision" : "629f0b679d0fd0a6ae823d7f750b9ab032c00b80", + "version" : "3.0.0" + } + }, + { + "identity" : "swift-docc", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-docc.git", + "state" : { + "branch" : "release/6.2", + "revision" : "4be8229cd268c2e4d036a848376b290ecbbc4d64" + } + }, + { + "identity" : "swift-docc-symbolkit", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-docc-symbolkit.git", + "state" : { + "branch" : "release/6.2", + "revision" : "467084cd380d352abcd128b27927ecdc8cb5bae8" + } + }, + { + "identity" : "swift-driver", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-driver.git", + "state" : { + "branch" : "release/6.2", + "revision" : "aedacc6c1583db4f2989a367e3c41968558a5b8e" + } + }, + { + "identity" : "swift-format", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-format.git", + "state" : { + "branch" : "release/6.2", + "revision" : "63687c7f450abe1fc96765e2caf173e82ebe780d" + } + }, + { + "identity" : "swift-llbuild", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-llbuild.git", + "state" : { + "branch" : "release/6.2", + "revision" : "073dff55529d7c4ecbd615ab5f5ac52ae5b380da" + } + }, + { + "identity" : "swift-lmdb", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-lmdb.git", + "state" : { + "branch" : "release/6.2", + "revision" : "1ad9a2d80b6fcde498c2242f509bd1be7d667ff8" + } + }, + { + "identity" : "swift-markdown", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-markdown.git", + "state" : { + "branch" : "release/6.2", + "revision" : "9063d10a2ac546227a0f08f3f7b4c6029d2757b1" + } + }, + { + "identity" : "swift-nio", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-nio.git", + "state" : { + "revision" : "cd3e1152083706d77b223fb29110e590efcc70c0", + "version" : "2.101.2" + } + }, + { + "identity" : "swift-package-manager", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-package-manager.git", + "state" : { + "branch" : "release/6.2", + "revision" : "215e9f91823d7e44c379fa17bf1eef189438fc24" + } + }, + { + "identity" : "swift-syntax", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-syntax.git", + "state" : { + "branch" : "release/6.2", + "revision" : "5a87516fc3dddbd23cb76358eb489915ee86b444" + } + }, + { + "identity" : "swift-system", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-system.git", + "state" : { + "revision" : "7502b711c92a17741fa625d722b0ccbd595d8ed1", + "version" : "1.7.2" + } + }, + { + "identity" : "swift-toolchain-sqlite", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-toolchain-sqlite", + "state" : { + "revision" : "05c9f4d17fae1eb586e716e11e5aa52bac464d00", + "version" : "1.0.10" + } + }, + { + "identity" : "swift-tools-support-core", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-tools-support-core.git", + "state" : { + "branch" : "release/6.2", + "revision" : "5a993c8848487c934d53ffceef8e1cad0a241dc1" + } + } + ], + "version" : 3 +} diff --git a/pkgs/development/compilers/swift_ng/by-name/so/sourcekit-lsp/package.nix b/pkgs/development/compilers/swift_ng/by-name/so/sourcekit-lsp/package.nix new file mode 100644 index 000000000000..3ceac0465b0a --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/so/sourcekit-lsp/package.nix @@ -0,0 +1,96 @@ +{ + lib, + fetchFromGitHub, + fetchSwiftPMDeps, + llvmPackages, + ncurses, + pkg-config, + replaceVars, + sqlite, + stdenv, + swift, + swift-corelibs-libdispatch, + swiftpm, + swift_release, + swift_sources, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "sourcekit-lsp"; + version = swift_release; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "sourcekit-lsp"; + tag = "swift-${finalAttrs.version}-RELEASE"; + inherit (swift_sources.sourcekit-lsp) hash; + }; + + patches = [ + # We can’t use the XCTest framework on Darwin and have to use swift-corelibs-xctest. Patch the `PerfTestCase` + # base class to build with it on Darwin. + ./patches/0001-Fix-for-using-swift-corelibs-xctest-on-Darwin.patch + # SourceKit-LSP tries to load IndexStore from the toolchain, but we want to load it from the store directly instead. + (replaceVars ./patches/0002-Load-IndexStore-from-the-store.patch { + libclang = lib.getLib llvmPackages.libclang; + }) + ]; + + # The SwiftPM patches can’t be included in the swiftpmDeps FOD because they reference store paths. + swiftpmPatches = swiftpm.patches; + + postPatch = '' + packagesPath=$(readlink -f Packages) + + rm Packages + cp -r "$packagesPath" Packages + chmod -R u+w Packages/swift-package-manager + + for p in "''${swiftpmPatches[@]}"; do + # Don’t apply the backdeploy patch because it creates a link to the Swift toolchain, + # which bloats up the SourceKit-LSP closure quite significantly. + if ! [[ $p =~ fix-backdeploy-rpath\.patch ]]; then + echo "applying patch $p" + patch -d Packages/swift-package-manager -p1 < "$p" + fi + done + ''; + + swiftpmDeps = fetchSwiftPMDeps { + inherit (finalAttrs) pname version src; + inherit (swift_sources.sourcekit-lsp.swiftpmDeps) hash; + + # Upstream doesn’t provide `Package.resolved`. + postPatch = '' + ln -s ${./Package.resolved} Package.resolved + ''; + }; + + strictDeps = true; + + nativeBuildInputs = [ + pkg-config + swift + swiftpm + ]; + + buildInputs = [ + ncurses + sqlite + ] + ++ lib.optionals (!stdenv.hostPlatform.isDarwin) [ swift-corelibs-libdispatch ]; + + # Tests crash with `*** bit out of range 0 - FD_SETSIZE on fd_set ***: terminated` + doCheck = false; # !stdenv.hostPlatform.isDarwin; + + __structuredAttrs = true; + + meta = { + description = "Language Server Protocol implementation for Swift and C-based languages"; + mainProgram = "sourcekit-lsp"; + homepage = "https://github.com/apple/sourcekit-lsp"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift_ng/by-name/so/sourcekit-lsp/patches/0001-Fix-for-using-swift-corelibs-xctest-on-Darwin.patch b/pkgs/development/compilers/swift_ng/by-name/so/sourcekit-lsp/patches/0001-Fix-for-using-swift-corelibs-xctest-on-Darwin.patch new file mode 100644 index 000000000000..c137baa63833 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/so/sourcekit-lsp/patches/0001-Fix-for-using-swift-corelibs-xctest-on-Darwin.patch @@ -0,0 +1,27 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 11 Jul 2026 15:55:24 -0400 +Subject: [PATCH 1/2] Fix for using swift-corelibs-xctest on Darwin + +Darwin in Nixpkgs also uses swift-corelibs-xctest, so we need to use the +logic as other platforms to define the base class for performance tests. +--- + Sources/SKTestSupport/PerfTestCase.swift | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/Sources/SKTestSupport/PerfTestCase.swift b/Sources/SKTestSupport/PerfTestCase.swift +index ba716c49..5b5cfccc 100644 +--- a/Sources/SKTestSupport/PerfTestCase.swift ++++ b/Sources/SKTestSupport/PerfTestCase.swift +@@ -23,7 +23,7 @@ open class PerfTestCase: XCTestCase { + + #if !ENABLE_PERF_TESTS + +- #if os(macOS) ++ #if false + open override func startMeasuring() {} + open override func stopMeasuring() {} + open override func measureMetrics( +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/by-name/so/sourcekit-lsp/patches/0002-Load-IndexStore-from-the-store.patch b/pkgs/development/compilers/swift_ng/by-name/so/sourcekit-lsp/patches/0002-Load-IndexStore-from-the-store.patch new file mode 100644 index 000000000000..657f3e2b5d18 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/so/sourcekit-lsp/patches/0002-Load-IndexStore-from-the-store.patch @@ -0,0 +1,48 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Randy Eckenrode +Date: Sat, 11 Jul 2026 16:07:13 -0400 +Subject: [PATCH 2/2] Load IndexStore from the store + +--- + Sources/ToolchainRegistry/Toolchain.swift | 7 ++----- + Tests/ToolchainRegistryTests/ToolchainRegistryTests.swift | 7 +------ + 2 files changed, 3 insertions(+), 11 deletions(-) + +diff --git a/Sources/ToolchainRegistry/Toolchain.swift b/Sources/ToolchainRegistry/Toolchain.swift +index 41d697bd..008a77af 100644 +--- a/Sources/ToolchainRegistry/Toolchain.swift ++++ b/Sources/ToolchainRegistry/Toolchain.swift +@@ -330,11 +330,8 @@ public final class Toolchain: Sendable { + foundAny = true + } + +- #if os(Windows) +- let libIndexStorePath = binPath.appendingPathComponent("libIndexStore\(dylibExtension)") +- #else +- let libIndexStorePath = libPath.appendingPathComponent("libIndexStore\(dylibExtension)") +- #endif ++ let libIndexStorePath = URL(filePath: "@libclang@").appending(components: "lib", "libIndexStore\(dylibExtension)") ++ + if FileManager.default.isFile(at: libIndexStorePath) { + libIndexStore = libIndexStorePath + foundAny = true +diff --git a/Tests/ToolchainRegistryTests/ToolchainRegistryTests.swift b/Tests/ToolchainRegistryTests/ToolchainRegistryTests.swift +index 60c4bf10..c8582c7a 100644 +--- a/Tests/ToolchainRegistryTests/ToolchainRegistryTests.swift ++++ b/Tests/ToolchainRegistryTests/ToolchainRegistryTests.swift +@@ -758,11 +758,6 @@ private func makeToolchain( + #endif + } + if libIndexStore { +- #if os(Windows) +- // Windows has a prefix of `lib` on this particular library ... +- try Data().write(to: binPath.appendingPathComponent("libIndexStore\(dylibSuffix)")) +- #else +- try Data().write(to: libPath.appendingPathComponent("libIndexStore\(dylibSuffix)")) +- #endif ++ try Data().write(to: URL(filePath: "@libclang@").appending(components: "lib", "libIndexStore\(dylibSuffix)")) + } + } +-- +2.54.0 + diff --git a/pkgs/development/compilers/swift_ng/sources-6.2.json b/pkgs/development/compilers/swift_ng/sources-6.2.json index 3bf0499947c8..9c84185e21fe 100644 --- a/pkgs/development/compilers/swift_ng/sources-6.2.json +++ b/pkgs/development/compilers/swift_ng/sources-6.2.json @@ -2,6 +2,12 @@ "llvm-project": { "hash": "sha256-5Nb8rQmk6onrc4wKW/kT38FsYsWTqMBWtsHYZLA/0Po=" }, + "sourcekit-lsp": { + "hash": "sha256-vDMZJSIeM+oIheeJCEfP0+FAJn+RyNYDDdWrHJDRcyE=", + "swiftpmDeps": { + "hash": "sha256-xpvXcm2qtCd2xhClbR6BLwmaupSHg1H25uJd7Thgd/4=" + } + }, "swift": { "hash": "sha256-apbBe/TMzq0+1XLkaTOj5NaYzLQ81i+vU+O7VSEJrKo=" }, From 6c12143ea5bdbc2cf668eaebf30521adf4151da8 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 10 Sep 2026 00:49:46 -0400 Subject: [PATCH 226/423] swiftPackages.swift-docc-render: init at 6.2.4-unstable-2025-09-16 We have to use an unstable version for compatibility with Node.js 22. Otherwise, it requires Node.js 20, which has been removed from Nixpkgs. --- .../by-name/sw/swift-docc-render/package.nix | 62 +++++++++++++++++++ .../compilers/swift_ng/sources-6.2.json | 7 +++ 2 files changed, 69 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-docc-render/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-docc-render/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift-docc-render/package.nix new file mode 100644 index 000000000000..8448446f8bec --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-docc-render/package.nix @@ -0,0 +1,62 @@ +{ + lib, + buildNpmPackage, + fetchFromGitHub, + fetchNpmDeps, + nodejs_22, + fetchpatch2, + swift_release, + swift_sources, +}: + +# swift-docc-render does not tag releases. Only the built artifacts are tagged. To build this from source: +# 1. Go to https://github.com/swiftlang/swift-docc-render-artifact and check the tagged release for the Swift release; +# 2. Note the parent commit. This will be needed to find the build in Swift’s CI; +# 3. Go to https://ci.swift.org and navigate to the builds for the Swift release being built (e.g., 6.2 for 6.2.4); +# 4. Find the successful build with the same commit for swiftlang/swift-docc-render-artifact as the parent commit for +# the tagged release. You have to check the parent because Jenkins is reporting the current state of the branch; +# 5. The githubweb link is the commit that was built and tagged in swiftlang/swift-docc-render-artifact. + +# For example, for Swift 6.2.4: +# - The parent commit for the pre-built artifact at https://github.com/swiftlang/swift-docc-render-artifact/tree/swift-6.2.4-RELEASE +# is b2bf4e5426851306760607d79b0bf9af2b6f479b. +# - The successful build with that parent commit is https://ci.swift.org/view/Swift%206.2/job/swift-6.2-docc-render-sync/21/. +# - The corresponding commit on GitHub is https://github.com/swiftlang/swift-docc-render/commit/451103e0f055db233467e4e6b67384cf0d4625a0. +# - The `rev` to use in `src` below is 451103e0f055db233467e4e6b67384cf0d4625a0. + +buildNpmPackage (finalAttrs: { + pname = "swift-docc-render"; + version = "${swift_release}-unstable-2025-09-16"; + + # Note! We don’t use the commit from Swift 6.2.4 but a later one that is compatible with Node.js 22. + # Otherwise, it would require Node.js 20, which is no longer supported in Nixpkgs. + # This comment can be dropped after the Swift 6.3 update, which includes this commit. + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-docc-render"; + inherit (swift_sources.swift-docc-render) rev hash; + }; + + nodejs = nodejs_22; + + npmDeps = fetchNpmDeps { + name = "${finalAttrs.pname}-${finalAttrs.version}-npm-deps"; + inherit (finalAttrs) src; + inherit (swift_sources.swift-docc-render.npmDeps) hash; + }; + + installPhase = '' + runHook preInstall + mkdir -p "$out" + cp -rv dist "$out/dist" + runHook postInstall + ''; + + meta = { + description = "Web renderer for Swift DocC documentation"; + homepage = "https://github.com/swiftlang/swift-docc-render"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift_ng/sources-6.2.json b/pkgs/development/compilers/swift_ng/sources-6.2.json index 9c84185e21fe..0e1af3664e57 100644 --- a/pkgs/development/compilers/swift_ng/sources-6.2.json +++ b/pkgs/development/compilers/swift_ng/sources-6.2.json @@ -23,6 +23,13 @@ "swift-corelibs-xctest": { "hash": "sha256-BbzY1kZUaHu7O29c8J7xDuelik6lhqmfSSskvvPZ7R4=" }, + "swift-docc-render": { + "hash": "sha256-uikFKvbjdU2BW3G0hCLah5Dt86DfAJ0etirX2nYVD+8=", + "npmDeps": { + "hash": "sha256-10RbVbf8lA4Glqw9NZGRCFmpE660UfbTBllIKJYQ+U8=" + }, + "rev": "1eb260c405bea1a57d843563e1085baa632262c6" + }, "swift-driver": { "hash": "sha256-CZYqUadpAsAUnCTZElobZS9nlMfCuHiMnac3o0k7hnI=" }, From 4914173e34c8a3bd46669f4eaffdd6209a170e57 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 227/423] swiftPackages_ng.swift-docc: init at 6.2.4 --- .../by-name/sw/swift-docc/package.nix | 66 +++++++++++++++++++ .../compilers/swift_ng/sources-6.2.json | 6 ++ 2 files changed, 72 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-docc/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-docc/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift-docc/package.nix new file mode 100644 index 000000000000..d2adb46a9e1f --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-docc/package.nix @@ -0,0 +1,66 @@ +{ + lib, + fetchFromGitHub, + fetchSwiftPMDeps, + stdenv, + swift, + swift-docc-render, + swiftpm, + swift_release, + swift_sources, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "swift-docc"; + version = swift_release; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-docc"; + tag = "swift-${finalAttrs.version}-RELEASE"; + inherit (swift_sources.swift-docc) hash; + }; + + postPatch = + # SignalTests.testTrappingSignal tries to access `/bin/bash`. Replace it with the shell in the stdenv. + '' + substituteInPlace Tests/SwiftDocCUtilitiesTests/SignalTests.swift \ + --replace-fail '/bin/bash' ${lib.escapeShellArg stdenv.shell} + ''; + + strictDeps = true; + + swiftpmDeps = fetchSwiftPMDeps { + inherit (finalAttrs) pname version src; + inherit (swift_sources.swift-docc.swiftpmDeps) hash; + }; + + swiftpmFlags = [ + # Otherwise fails to build with `error: module 'SwiftDocC' was not compiled for testing`. + "-Xswiftc" + "-enable-testing" + ]; + + nativeBuildInputs = [ + swift + swiftpm + ]; + + doCheck = !stdenv.hostPlatform.isDarwin; + + postInstall = '' + mkdir -p "$out/share/docc" + ln -s "${swift-docc-render}/dist" "$out/share/docc/render" + ''; + + __structuredAttrs = true; + + meta = { + description = "Documentation compiler for Swift"; + mainProgram = "docc"; + homepage = "https://github.com/swiftlang/swift-docc"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift_ng/sources-6.2.json b/pkgs/development/compilers/swift_ng/sources-6.2.json index 0e1af3664e57..9d1d2acb6835 100644 --- a/pkgs/development/compilers/swift_ng/sources-6.2.json +++ b/pkgs/development/compilers/swift_ng/sources-6.2.json @@ -23,6 +23,12 @@ "swift-corelibs-xctest": { "hash": "sha256-BbzY1kZUaHu7O29c8J7xDuelik6lhqmfSSskvvPZ7R4=" }, + "swift-docc": { + "hash": "sha256-zu70RyYvnfhW3DdovSeLFXTNmdHrhdnSYCN8RisSkt8=", + "swiftpmDeps": { + "hash": "sha256-kJFuNw/pRn2A4UMvGcX3j04Faz44mriSz90u8hLdaZc=" + } + }, "swift-docc-render": { "hash": "sha256-uikFKvbjdU2BW3G0hCLah5Dt86DfAJ0etirX2nYVD+8=", "npmDeps": { From f82fc8a2092b58b0911bec386a6fe17f0563e860 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 228/423] swiftPackages_ng.swift-format: init at 6.2.4 --- .../by-name/sw/swift-format/Package.resolved | 41 +++++++++++++++ .../by-name/sw/swift-format/package.nix | 52 +++++++++++++++++++ .../compilers/swift_ng/sources-6.2.json | 6 +++ 3 files changed, 99 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-format/Package.resolved create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swift-format/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-format/Package.resolved b/pkgs/development/compilers/swift_ng/by-name/sw/swift-format/Package.resolved new file mode 100644 index 000000000000..94c7fd80deef --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-format/Package.resolved @@ -0,0 +1,41 @@ +{ + "pins" : [ + { + "identity" : "swift-argument-parser", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-argument-parser.git", + "state" : { + "revision" : "6a52f3251125d74daf04fcbd5e6f08a75d074382", + "version" : "1.8.2" + } + }, + { + "identity" : "swift-cmark", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-cmark.git", + "state" : { + "revision" : "924936d0427cb25a61169739a7660230bffa6ea6", + "version" : "0.8.0" + } + }, + { + "identity" : "swift-markdown", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-markdown.git", + "state" : { + "revision" : "3c6f9523da3a1ec2fd829673e472d95b8097a3b8", + "version" : "0.8.0" + } + }, + { + "identity" : "swift-syntax", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-syntax.git", + "state" : { + "branch" : "release/6.2", + "revision" : "5a87516fc3dddbd23cb76358eb489915ee86b444" + } + } + ], + "version" : 2 +} diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-format/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift-format/package.nix new file mode 100644 index 000000000000..09d6b8c80e97 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift-format/package.nix @@ -0,0 +1,52 @@ +{ + lib, + fetchFromGitHub, + fetchSwiftPMDeps, + stdenv, + swift, + swiftpm, + swift_release, + swift_sources, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "swift-format"; + version = swift_release; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swift-format"; + tag = "swift-${finalAttrs.version}-RELEASE"; + inherit (swift_sources.swift-format) hash; + }; + + strictDeps = true; + + swiftpmDeps = fetchSwiftPMDeps { + inherit (finalAttrs) pname version src; + inherit (swift_sources.swift-format.swiftpmDeps) hash; + + # Upstream doesn’t provide `Package.resolved`. + postPatch = '' + ln -s ${./Package.resolved} Package.resolved + ''; + }; + + nativeBuildInputs = [ + swift + swiftpm + ]; + + doCheck = !stdenv.hostPlatform.isDarwin; + + __structuredAttrs = true; + + meta = { + mainProgram = "swift-format"; + homepage = "https://github.com/swiftlang/swift-format"; + description = "Swift code formatter"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) diff --git a/pkgs/development/compilers/swift_ng/sources-6.2.json b/pkgs/development/compilers/swift_ng/sources-6.2.json index 9d1d2acb6835..6d78b3718f52 100644 --- a/pkgs/development/compilers/swift_ng/sources-6.2.json +++ b/pkgs/development/compilers/swift_ng/sources-6.2.json @@ -42,6 +42,12 @@ "swift-experimental-string-processing": { "hash": "sha256-WtLLqdvYTmLWSS5q42b8yXFrJcC+dUy4uTuCeIflRFs=" }, + "swift-format": { + "hash": "sha256-01lnZFaFAcjWN9Hn0y60gEANz7RbYRvjESysYqB9iSo=", + "swiftpmDeps": { + "hash": "sha256-UAvKJKEN32FVILwdADqXAZ7opS3Tf3e7Qp+RhD4R4QE=" + } + }, "swift-foundation": { "hash": "sha256-otE5EGG53zadZVZ0P67rr+4h4x/c3rWWEdZyL23Mxio=" }, From e7b6ee399e0f3e3622dfb8e47bb2c237024fc620 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 229/423] swiftPackages_ng.swiftly: init at 1.1.3 While not especially useful in Nixpkgs, users may want to install static SDKs and toolchains using it. --- .../swift_ng/by-name/sw/swiftly/package.nix | 59 +++++++++++++++++++ 1 file changed, 59 insertions(+) create mode 100644 pkgs/development/compilers/swift_ng/by-name/sw/swiftly/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftly/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swiftly/package.nix new file mode 100644 index 000000000000..4afebbb30b05 --- /dev/null +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swiftly/package.nix @@ -0,0 +1,59 @@ +{ + lib, + fetchFromGitHub, + fetchSwiftPMDeps, + gitUpdater, + libarchive, + pkg-config, + stdenv, + swift, + swiftpm, + zlib, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "swiftly"; + version = "1.1.3"; + + src = fetchFromGitHub { + owner = "swiftlang"; + repo = "swiftly"; + tag = finalAttrs.version; + hash = "sha256-VFgmgo69Q4Y8Je0SMdB3jKGt9lNoVYAaUhSuK3RUkFE="; + }; + + swiftpmDeps = fetchSwiftPMDeps { + inherit (finalAttrs) pname version src; + hash = "sha256-1KfyrQXE1HaO9WsuskzgiiEZxM/oelp40Jwzr8xJEL4="; + }; + + strictDeps = true; + + nativeBuildInputs = [ + swift + swiftpm + ] + # Required for libarchive. + ++ lib.optionals stdenv.hostPlatform.isLinux [ pkg-config ]; + + buildInputs = [ + zlib + ] + # Swiftly requires libarchive on Linux but not Darwin. + ++ lib.optionals stdenv.hostPlatform.isLinux [ libarchive ]; + + doCheck = false; # Too many impure tests that fail. Need a mechanism to disable just those tests. + + __structuredAttrs = true; + + passthru.updateScript = gitUpdater { }; + + meta = { + description = "Swift toolchain installer and manager"; + mainProgram = "swiftly"; + homepage = "https://github.com/swiftlang/swiftly"; + platforms = lib.platforms.darwin ++ lib.platforms.linux; + license = lib.licenses.asl20; + teams = [ lib.teams.swift ]; + }; +}) From a1ba3b7654c1c4e4021d944f0ad13732784fef5a Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 230/423] swiftPackages_ng.swift: add passthru properties for compatibility --- .../swift_ng/by-name/sw/swift/package.nix | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix index a195f9429a4b..82be17612d68 100644 --- a/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix @@ -228,6 +228,20 @@ stdenv.mkDerivation (finalAttrs: { inherit callPackage; directory = ./tests; }; + + # Swift libraries are installed in `lib` to make it easier to use Nixpkgs tooling with them. + swiftLibSubdir = "lib"; + swiftStaticLibSubdir = "lib"; + + # Our toolchain builds install modules in `lib/swift/`, which matches what upstream toolchains do. + swiftModuleSubdir = "lib/swift/${stdenv.hostPlatform.swift.platform}"; + swiftStaticModuleSubdir = "lib/swift_static/${stdenv.hostPlatform.swift.platform}"; + + # Legacy aliases for the old Swift packaging. These should eventually be removed. + swift = finalAttrs.finalPackage; + swiftArch = stdenv.hostPlatform.swift.arch; + swiftDriver = lib.warn "'swiftDriver' has been renamed to 'swift-driver'" finalAttrs.passthru.swift-driver; + swiftOs = stdenv.hostPlatform.swift.platform; }; meta = { From f5d5cdf9e7ad8169f5eb635792d5ab2d482d87f6 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 231/423] swiftPackages_ng: add compatibility aliases for old package names --- pkgs/top-level/swift-packages.nix | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/pkgs/top-level/swift-packages.nix b/pkgs/top-level/swift-packages.nix index 7cbbb2492ac6..7ab1d3c41fd7 100644 --- a/pkgs/top-level/swift-packages.nix +++ b/pkgs/top-level/swift-packages.nix @@ -111,5 +111,12 @@ makeScopeWithSplicing' { f = lib.extends autoCalledPackages (self: { stdenv = clangStdenv; swift_release = "6.2.4"; + + # Compatibility aliases for the old Swift packaging. + swift-unwrapped = self.swift; + swiftNoSwiftDriver = self.swift.override { swift-driver = null; }; + Dispatch = self.swift-corelibs-libdispatch; + Foundation = self.swift-corelibs-foundation; + XCTest = self.swift-corelibs-xctest; }); } From abd5659830f25848e01d8ef50b2a0a36b1d4a51b Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 232/423] age-plugin-se: disable SwiftPM install phase age-plugin-se expects to rely on the install phase defined in its `Makefile`. --- pkgs/by-name/ag/age-plugin-se/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/ag/age-plugin-se/package.nix b/pkgs/by-name/ag/age-plugin-se/package.nix index f15699e2ddde..8022834d8b60 100644 --- a/pkgs/by-name/ag/age-plugin-se/package.nix +++ b/pkgs/by-name/ag/age-plugin-se/package.nix @@ -63,6 +63,8 @@ stdenv.mkDerivation (finalAttrs: { "RELEASE=1" ]; + dontUseSwiftpmInstall = true; + passthru.updateScript = nix-update-script { }; meta = { From fdccfa8b361abd0df80d094045a8d52d2e59b5be Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 233/423] airdrop-cli: disable SwiftPM install phase airdrop-cli expects to rely on the install phase defined in its `Makefile`. --- pkgs/by-name/ai/airdrop-cli/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/ai/airdrop-cli/package.nix b/pkgs/by-name/ai/airdrop-cli/package.nix index 0b60f966e5d6..880416260f1b 100644 --- a/pkgs/by-name/ai/airdrop-cli/package.nix +++ b/pkgs/by-name/ai/airdrop-cli/package.nix @@ -27,6 +27,8 @@ swiftPackages.stdenv.mkDerivation { "PREFIX=$(out)" ]; + dontUseSwiftpmInstall = true; + meta = { description = "Use Airdrop from the CLI on macOS written in Swift"; homepage = "https://github.com/vldmrkl/airdrop-cli"; From 8eb27d94e7755a89b440865b5f188f0b37827c94 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 234/423] apple-sdk: rely on our Swift stdlib package for stdlib stubs and modules --- .../metadata/disallowed-packages.json | 34 +++++++++++++++++++ 1 file changed, 34 insertions(+) diff --git a/pkgs/by-name/ap/apple-sdk/metadata/disallowed-packages.json b/pkgs/by-name/ap/apple-sdk/metadata/disallowed-packages.json index f407c114fe8e..c834efc16e83 100644 --- a/pkgs/by-name/ap/apple-sdk/metadata/disallowed-packages.json +++ b/pkgs/by-name/ap/apple-sdk/metadata/disallowed-packages.json @@ -482,6 +482,40 @@ { "package": "swift", "libraries": [ + "swift/Cxx.swiftmodule", + "swift/CxxStdlib.swiftmodule", + "swift/Distributed.swiftmodule", + "swift/Observation.swiftmodule", + "swift/RegexBuilder.swiftmodule", + "swift/Runtime.swiftmodule", + "swift/Swift.swiftmodule", + "swift/SwiftOnoneSupport.swiftmodule", + "swift/Synchronization.swiftmodule", + "swift/_Builtin_float.swiftmodule", + "swift/_Concurrency.swiftmodule", + "swift/_Differentiation.swiftmodule", + "swift/_RegexParser.swiftmodule", + "swift/_StringProcessing.swiftmodule", + "swift/_Volatile.swiftmodule", + "swift/lib_InternalSwiftStaticMirror.tbd", + "swift/libcxxshim.h", + "swift/libcxxshim.modulemap", + "swift/libcxxstdlibshim.h", + "swift/libswiftCompatibilitySpan.tbd", + "swift/libswiftCore.tbd", + "swift/libswiftDistributed.tbd", + "swift/libswiftObservation.tbd", + "swift/libswiftRegexBuilder.tbd", + "swift/libswiftRemoteMirror.tbd", + "swift/libswiftRuntime.tbd", + "swift/libswiftSwiftOnoneSupport.tbd", + "swift/libswiftSynchronization.tbd", + "swift/libswift_Builtin_float.tbd", + "swift/libswift_Concurrency.tbd", + "swift/libswift_Differentiation.tbd", + "swift/libswift_RegexParser.tbd", + "swift/libswift_StringProcessing.tbd", + "swift/libswift_Volatile.tbd", "swift/shims" ] }, From 6043f3856f66eac4b347bd4a77bf3df0d3956686 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 235/423] dark-mode-notify: disable SwiftPM install phase dark-mode-notify expects to rely on the install phase defined in its `Makefile`. --- pkgs/by-name/da/dark-mode-notify/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/da/dark-mode-notify/package.nix b/pkgs/by-name/da/dark-mode-notify/package.nix index 2b941f11b0ed..0b03eee45810 100644 --- a/pkgs/by-name/da/dark-mode-notify/package.nix +++ b/pkgs/by-name/da/dark-mode-notify/package.nix @@ -27,6 +27,8 @@ swiftPackages.stdenv.mkDerivation (finalAttrs: { makeFlags = [ "prefix=$(out)" ]; + dontUseSwiftpmInstall = true; + meta = { description = "Run a script whenever dark mode changes in macOS"; homepage = "https://github.com/bouk/dark-mode-notify"; From cb6636d66d53bdbec8e71850b3aa3cc5a3df61e3 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 236/423] handy: improve compatibility when using the 26.x SDK The Swift 6.2 packaging propagates the 26.x SDK, which will cause handy to fail to build due to required macros being unavailable. --- pkgs/by-name/ha/handy/package.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkgs/by-name/ha/handy/package.nix b/pkgs/by-name/ha/handy/package.nix index 64a06881d3dd..0ef3c933fec8 100644 --- a/pkgs/by-name/ha/handy/package.nix +++ b/pkgs/by-name/ha/handy/package.nix @@ -91,6 +91,10 @@ rustPlatform.buildRustPackage (finalAttrs: { # Strip cbindgen build steps find "$cargoDepsCopy" -path "*/ferrous-opencc-*/build.rs" \ -exec sed -i -e '/cbindgen::Builder::new/{:l;/write_to_file/!{N;bl};d}' {} + + + # FoundationModels requires macros that are only shipped with Xcode. The 26.x SDK in Nixpkgs does not have them. + substituteInPlace src-tauri/build.rs \ + --replace-fail 'has_foundation_models = framework_path.exists()' ' has_foundation_models = false' '' + lib.optionalString stdenv.hostPlatform.isLinux '' substituteInPlace "$cargoDepsCopy"/*/libappindicator-sys-*/src/lib.rs \ @@ -153,6 +157,7 @@ rustPlatform.buildRustPackage (finalAttrs: { ); } // lib.optionalAttrs stdenv.hostPlatform.isDarwin { + NIX_LDFLAGS = "-lclang_rt.osx"; # Make sure `__isPlatformVersionAtLeast` is available for runtime version checks. SWIFTC = lib.getExe' swift "swiftc"; # Explicit so the Handy build system can avoid xcrun }; From d0be72e769fd09b610e9c059a595e09128607b93 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 237/423] protoc-gen-swift: include submodules for building with Swift 6 swift-protobuf uses a different `Package.swift` when building with Swift 6. This one requires several submodules. These will be vendored in later versions of swift-protobuf, but the one currently packages requires them to be fetched. --- pkgs/by-name/pr/protoc-gen-swift/package.nix | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/pr/protoc-gen-swift/package.nix b/pkgs/by-name/pr/protoc-gen-swift/package.nix index 1c6b5dea7215..cecaf3f3844a 100644 --- a/pkgs/by-name/pr/protoc-gen-swift/package.nix +++ b/pkgs/by-name/pr/protoc-gen-swift/package.nix @@ -17,7 +17,8 @@ stdenv.mkDerivation (finalAttrs: { owner = "apple"; repo = "swift-protobuf"; rev = "${finalAttrs.version}"; - hash = "sha256-DnnDT4egw00tvy84PuyvSKINjVwueg7QRSQrwD81qbg="; + hash = "sha256-Kit/kQDNs0ohtaNC0xWxG6o0vNGUWWE++YK1JP2o8OM="; + fetchSubmodules = true; }; nativeBuildInputs = [ From 0333d2c6f73276c19f0859cbddd063a57a1e3d49 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 238/423] sentry-cli: disable SwiftPM install phase sentry-cli expects to rely on the install phase defined in its `Makefile`. --- pkgs/by-name/se/sentry-cli/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/se/sentry-cli/package.nix b/pkgs/by-name/se/sentry-cli/package.nix index 52a9b1f73252..04ae9f6a8bb3 100644 --- a/pkgs/by-name/se/sentry-cli/package.nix +++ b/pkgs/by-name/se/sentry-cli/package.nix @@ -37,6 +37,7 @@ rustPlatform.buildRustPackage (finalAttrs: { # By default including `swiftpm` in `nativeBuildInputs` will take over `buildPhase` dontUseSwiftpmBuild = true; dontUseSwiftpmCheck = true; + dontUseSwiftpmInstall = true; __darwinAllowLocalNetworking = true; From 4fe30679ab6e30e31ab8a7fbe8e045d619c5debe Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 239/423] swift: 5.10.1 -> 6.2.4 https://www.swift.org/blog/announcing-swift-6/ https://www.swift.org/blog/swift-6.1-released/ https://www.swift.org/blog/swift-6.2-released/ Switch the top-level Swift implementation to use the new packaging, which also upgrades the version from 5.10.1 to 6.2.4. --- pkgs/top-level/all-packages.nix | 9 ++++----- 1 file changed, 4 insertions(+), 5 deletions(-) diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 62735cba83b1..25139ddc4fcd 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -4104,11 +4104,12 @@ with pkgs; swiftPackages = recurseIntoAttrs (callPackage ../development/compilers/swift { }); swiftPackages_ng = recurseIntoAttrs (callPackage ./swift-packages.nix { }); - inherit (swiftPackages) - swift - swiftpm + inherit (swiftPackages_ng) sourcekit-lsp + swift + swift-corelibs-libdispatch swift-format + swiftpm swiftpm2nix ; @@ -10782,8 +10783,6 @@ with pkgs; sieveshell = with python3.pkgs; toPythonApplication managesieve; - swift-corelibs-libdispatch = swiftPackages.Dispatch; - duden = python3Packages.toPythonApplication python3Packages.duden; yaziPlugins = recurseIntoAttrs (callPackage ../by-name/ya/yazi/plugins { }); From 5c0c26530761be71c11d4d55a2a2d099b4013537 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 240/423] fetchSwiftPMDeps: add to the top-level --- pkgs/top-level/all-packages.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 25139ddc4fcd..06d11d13177f 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -4105,6 +4105,7 @@ with pkgs; swiftPackages = recurseIntoAttrs (callPackage ../development/compilers/swift { }); swiftPackages_ng = recurseIntoAttrs (callPackage ./swift-packages.nix { }); inherit (swiftPackages_ng) + fetchSwiftPMDeps sourcekit-lsp swift swift-corelibs-libdispatch From 0c5005508e9485d88d8461ea52ae36b45a8b2cf1 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 241/423] age-plugin-se: switch to fetchSwiftPMDeps MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The way age-plugin-se attempts to vendor Swift Crypto doesn’t work on Linux after switching to Swift 6.2.4. Using fetchSwiftPMDeps does work, so just use it. This simplifies the dependency vendoring logic. --- pkgs/by-name/ag/age-plugin-se/package.nix | 34 +++-------------------- 1 file changed, 4 insertions(+), 30 deletions(-) diff --git a/pkgs/by-name/ag/age-plugin-se/package.nix b/pkgs/by-name/ag/age-plugin-se/package.nix index 8022834d8b60..2e0261adfa32 100644 --- a/pkgs/by-name/ag/age-plugin-se/package.nix +++ b/pkgs/by-name/ag/age-plugin-se/package.nix @@ -3,6 +3,7 @@ fetchFromGitHub, llvmPackages, swiftPackages, + fetchSwiftPMDeps, swift, swiftpm, nix-update-script, @@ -26,38 +27,11 @@ stdenv.mkDerivation (finalAttrs: { swiftpm ]; - env = lib.optionalAttrs stdenv.hostPlatform.isLinux { - # Can't find libdispatch without this on NixOS. (swift 5.8) - LD_LIBRARY_PATH = "${swiftPackages.Dispatch}/lib"; + swiftpmDeps = fetchSwiftPMDeps { + inherit (finalAttrs) pname version src; + hash = "sha256-rGPaSlNmW4zn2bBhu3LnJvPUWBQhAfFmHnNFm9jKR+8="; }; - postPatch = - let - swift-crypto = fetchFromGitHub { - owner = "apple"; - repo = "swift-crypto"; - tag = "3.7.1"; - hash = "sha256-zxmHxTryAezgqU5qjXlFFThJlfUsPxb1KRBan4DSm9A="; - }; - in - '' - ${lib.optionalString (lib.versionAtLeast swift.version "6") '' - echo "age-plugin-se still applies patch-package-swift-legacy; remove or revisit this patch now that nixpkgs Swift is 6+." - exit 1 - ''} - make patch-package-swift-legacy - ln -s ${swift-crypto} swift-crypto - substituteInPlace Package.swift --replace-fail 'url: "https://github.com/apple/swift-crypto.git"' 'path: "./swift-crypto"), //' - ${lib.optionalString stdenv.hostPlatform.isLinux '' - # Swift 5.10.1's corelibs Foundation lacks Date.ISO8601Format(). - # Remove this substitution once the upstream fallback is released: - # https://github.com/remko/age-plugin-se/issues/20 - substituteInPlace Sources/Plugin.swift --replace-fail \ - 'let createdAt = now.ISO8601Format()' \ - 'let createdAt = ISO8601DateFormatter().string(from: now)' - ''} - ''; - makeFlags = [ "PREFIX=$(out)" "RELEASE=1" From 485fbb2716b27a72f4bf8fec72e5943c8a34db88 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 242/423] age-plugin-se: remove obsolete Swift constructs MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - The new Swift packaging no longer requires using a custom stdenv; and - It no longer requires handling of libdispatch. It’s bundled in the toolchain. --- pkgs/by-name/ag/age-plugin-se/package.nix | 7 ++----- 1 file changed, 2 insertions(+), 5 deletions(-) diff --git a/pkgs/by-name/ag/age-plugin-se/package.nix b/pkgs/by-name/ag/age-plugin-se/package.nix index 2e0261adfa32..cf49bdaeb314 100644 --- a/pkgs/by-name/ag/age-plugin-se/package.nix +++ b/pkgs/by-name/ag/age-plugin-se/package.nix @@ -1,16 +1,13 @@ { lib, fetchFromGitHub, - llvmPackages, - swiftPackages, fetchSwiftPMDeps, + stdenv, swift, swiftpm, nix-update-script, }: -let - inherit (llvmPackages) stdenv; -in + stdenv.mkDerivation (finalAttrs: { pname = "age-plugin-se"; version = "0.2.1"; From 6c20eef73b30d66f061c9f98789d9ded98a4fda1 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 243/423] airdrop-cli: remove obsolete Swift constructs The new Swift packaging no longer requires using a custom stdenv. --- pkgs/by-name/ai/airdrop-cli/package.nix | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ai/airdrop-cli/package.nix b/pkgs/by-name/ai/airdrop-cli/package.nix index 880416260f1b..98cdac894c5f 100644 --- a/pkgs/by-name/ai/airdrop-cli/package.nix +++ b/pkgs/by-name/ai/airdrop-cli/package.nix @@ -1,13 +1,12 @@ { lib, fetchFromGitHub, + stdenv, swift, - swiftPackages, swiftpm, }: -# Doesn't build without using the same stdenv (and Clang) to build swift -swiftPackages.stdenv.mkDerivation { +stdenv.mkDerivation { pname = "airdrop-cli"; version = "0-unstable-2025-07-14"; From b74a4c6ff6fae5e6ecb8e08e57b10e33df76adff Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 244/423] alt-tab-macos: fix compatibility building with the 26.x SDK MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit It’s not clear how upstream is able to build this using an upstream toolchain, but the header for this API in our SDK has marked it obsolete. This causes the build to fail even though it won’t be used on our default deployment target. Fortunately, that means the offending static method can just be deleted. --- .../0005-avoid-using-obsolete-api.patch | 53 +++++++++++++++++++ pkgs/by-name/al/alt-tab-macos/package.nix | 2 + 2 files changed, 55 insertions(+) create mode 100644 pkgs/by-name/al/alt-tab-macos/0005-avoid-using-obsolete-api.patch diff --git a/pkgs/by-name/al/alt-tab-macos/0005-avoid-using-obsolete-api.patch b/pkgs/by-name/al/alt-tab-macos/0005-avoid-using-obsolete-api.patch new file mode 100644 index 000000000000..e4658dd7bf27 --- /dev/null +++ b/pkgs/by-name/al/alt-tab-macos/0005-avoid-using-obsolete-api.patch @@ -0,0 +1,53 @@ +diff --git a/src/macos/SystemPermissions.swift b/src/macos/SystemPermissions.swift +index 4a98ef9461..ae983eb73a 100644 +--- a/src/macos/SystemPermissions.swift ++++ b/src/macos/SystemPermissions.swift +@@ -158,24 +158,7 @@ + // their return value is not updated during the app lifetime + // note: shows the system prompt if there's no permission + private static func isGrantedOnSomeDisplay() -> Bool { +- if #available(macOS 12.3, *) { +- return checkWithSCShareableContent() +- } else { +- let mainDisplayID = CGMainDisplayID() +- if checkWithCGDisplayStream(mainDisplayID) { +- return true +- } +- // maybe the main screen can't produce a CGDisplayStream, but another screen can +- // a positive on any screen must mean that the permission is granted; we try on the other screens +- for screen in NSScreen.screens { +- if let id = screen.number(), id != mainDisplayID { +- if checkWithCGDisplayStream(id) { +- return true +- } +- } +- } +- return false +- } ++ return checkWithSCShareableContent() + } + + @available(macOS 12.3, *) +@@ -193,22 +176,6 @@ + } + } + +- private static func checkWithCGDisplayStream(_ id: CGDirectDisplayID) -> Bool { +- return runWithTimeout { completion in +- // this initializer can actually block for a while +- // it's undocumented but has been proven by spindumps shared by AltTab users +- let displayStream = CGDisplayStream( +- dispatchQueueDisplay: id, +- outputWidth: 1, +- outputHeight: 1, +- pixelFormat: Int32(kCVPixelFormatType_32BGRA), +- properties: nil, +- queue: .global() +- ) { _, _, _, _ in } +- completion(displayStream != nil) +- } +- } +- + private static func runWithTimeout(_ block: @escaping (@escaping (Bool) -> Void) -> Void) -> Bool { + let semaphore = DispatchSemaphore(value: 0) + var result = false diff --git a/pkgs/by-name/al/alt-tab-macos/package.nix b/pkgs/by-name/al/alt-tab-macos/package.nix index a5c70709aaac..6309dc6675d0 100644 --- a/pkgs/by-name/al/alt-tab-macos/package.nix +++ b/pkgs/by-name/al/alt-tab-macos/package.nix @@ -288,6 +288,8 @@ stdenv.mkDerivation (finalAttrs: { ./0003-use-runtime-dispatch-for-Liquid-Glass-with-SDK-14.patch # Don't offer preferences for services disabled by the source-only stubs. ./0004-hide-settings-for-disabled-services.patch + # Avoids error about `CGDisplayStream` initializer being unavailable on macOS when using the 26.x SDK. + ./0005-avoid-using-obsolete-api.patch ]; # Remove trailing comma incompatible with Swift 5.10 From 4026f234bf1da59ecc9c0de43dd644e011bec444 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 245/423] alt-tab-macos: drop Swift 5.10.1 compatibility workarounds --- ...ere-with-filter-.count-for-Swift-5.1.patch | 39 ---- ...raLarge-with-.large-for-macOS-14-SDK.patch | 39 ---- ...ispatch-for-Liquid-Glass-with-SDK-14.patch | 193 ------------------ pkgs/by-name/al/alt-tab-macos/package.nix | 20 -- 4 files changed, 291 deletions(-) delete mode 100644 pkgs/by-name/al/alt-tab-macos/0001-replace-count-where-with-filter-.count-for-Swift-5.1.patch delete mode 100644 pkgs/by-name/al/alt-tab-macos/0002-replace-.extraLarge-with-.large-for-macOS-14-SDK.patch delete mode 100644 pkgs/by-name/al/alt-tab-macos/0003-use-runtime-dispatch-for-Liquid-Glass-with-SDK-14.patch diff --git a/pkgs/by-name/al/alt-tab-macos/0001-replace-count-where-with-filter-.count-for-Swift-5.1.patch b/pkgs/by-name/al/alt-tab-macos/0001-replace-count-where-with-filter-.count-for-Swift-5.1.patch deleted file mode 100644 index 3d26fdb7a744..000000000000 --- a/pkgs/by-name/al/alt-tab-macos/0001-replace-count-where-with-filter-.count-for-Swift-5.1.patch +++ /dev/null @@ -1,39 +0,0 @@ -From 85a2e0440f8af42ae02cf7fee1119255b2459016 Mon Sep 17 00:00:00 2001 -From: nixpkgs -Date: Fri, 10 Jul 2026 12:21:11 +0300 -Subject: [PATCH 1/4] replace count(where:) with filter{}.count for Swift 5.10 - ---- - src/events/TrackpadEvents.swift | 2 +- - src/switcher/main-window/StatusIconsView.swift | 2 +- - 2 files changed, 2 insertions(+), 2 deletions(-) - -diff --git a/src/events/TrackpadEvents.swift b/src/events/TrackpadEvents.swift -index 2f1909df..5e187064 100644 ---- a/src/events/TrackpadEvents.swift -+++ b/src/events/TrackpadEvents.swift -@@ -76,7 +76,7 @@ class TrackpadEvents { - // on macOS, the finger contact surface is not exposed in NSTouch, so we can't detect big contact == palm, for example - // the closest thing we can do to detect resting inputs is remove touches which have .phase == .stationary - let activeTouches = touches.filter { !$0.isResting && ($0.phase == .began || $0.phase == .moved) } -- let fingersDown = touches.count { $0.phase == .began || $0.phase == .moved || $0.phase == .stationary } -+ let fingersDown = touches.filter { $0.phase == .began || $0.phase == .moved || $0.phase == .stationary }.count - let requiredFingers = Preferences.nextWindowGesture.isThreeFinger() ? 3 : 4 - if SwitcherSession.isActive { - handleEventIfAppIsBeingUsed(fingersDown, activeTouches, requiredFingers) -diff --git a/src/switcher/main-window/StatusIconsView.swift b/src/switcher/main-window/StatusIconsView.swift -index beeb2a54..2f35bddc 100644 ---- a/src/switcher/main-window/StatusIconsView.swift -+++ b/src/switcher/main-window/StatusIconsView.swift -@@ -76,7 +76,7 @@ class StatusIconsView: FlippedView { - icons[Self.fullscreenIdx].visible = isFullscreen - icons[Self.minimizedIdx].visible = isMinimized - icons[Self.spaceIdx].visible = showSpace -- visibleCount = icons.count(where: { $0.visible }) -+ visibleCount = icons.filter { $0.visible }.count - } - - func setSpaceStar() { --- -2.55.0 - diff --git a/pkgs/by-name/al/alt-tab-macos/0002-replace-.extraLarge-with-.large-for-macOS-14-SDK.patch b/pkgs/by-name/al/alt-tab-macos/0002-replace-.extraLarge-with-.large-for-macOS-14-SDK.patch deleted file mode 100644 index 15e284d6611f..000000000000 --- a/pkgs/by-name/al/alt-tab-macos/0002-replace-.extraLarge-with-.large-for-macOS-14-SDK.patch +++ /dev/null @@ -1,39 +0,0 @@ -From 7313d220616e756c4bb4f2c8cc5cf6b6b2e4789c Mon Sep 17 00:00:00 2001 -From: nixpkgs -Date: Fri, 10 Jul 2026 12:21:11 +0300 -Subject: [PATCH 2/4] replace .extraLarge with .large for macOS 14 SDK - ---- - src/preferences/settings-window/SettingsWindow.swift | 2 +- - src/switcher/main-window/TilesView.swift | 2 +- - 2 files changed, 2 insertions(+), 2 deletions(-) - -diff --git a/src/preferences/settings-window/SettingsWindow.swift b/src/preferences/settings-window/SettingsWindow.swift -index 866329ea..44f1da76 100644 ---- a/src/preferences/settings-window/SettingsWindow.swift -+++ b/src/preferences/settings-window/SettingsWindow.swift -@@ -462,7 +462,7 @@ class SettingsWindow: NSWindow { - searchField.sendsWholeSearchString = true - searchField.bezelStyle = .roundedBezel - if #available(macOS 26.0, *) { -- searchField.controlSize = .extraLarge -+ searchField.controlSize = .large - } else if #available(macOS 13.0, *) { - searchField.controlSize = .large - } -diff --git a/src/switcher/main-window/TilesView.swift b/src/switcher/main-window/TilesView.swift -index d6c7fb69..b6f374c9 100644 ---- a/src/switcher/main-window/TilesView.swift -+++ b/src/switcher/main-window/TilesView.swift -@@ -142,7 +142,7 @@ class TilesView { - searchField.sendsWholeSearchString = true - searchField.bezelStyle = .roundedBezel - if #available(macOS 26.0, *) { -- searchField.controlSize = .extraLarge -+ searchField.controlSize = .large - } else if #available(macOS 13.0, *) { - searchField.controlSize = .large - } else { --- -2.55.0 - diff --git a/pkgs/by-name/al/alt-tab-macos/0003-use-runtime-dispatch-for-Liquid-Glass-with-SDK-14.patch b/pkgs/by-name/al/alt-tab-macos/0003-use-runtime-dispatch-for-Liquid-Glass-with-SDK-14.patch deleted file mode 100644 index ebd914a0bd0e..000000000000 --- a/pkgs/by-name/al/alt-tab-macos/0003-use-runtime-dispatch-for-Liquid-Glass-with-SDK-14.patch +++ /dev/null @@ -1,193 +0,0 @@ -From 727f4c5aed5960bb429c7df0bbc3a547e05db7dd Mon Sep 17 00:00:00 2001 -From: nixpkgs -Date: Fri, 10 Jul 2026 12:21:12 +0300 -Subject: [PATCH 3/4] use runtime dispatch for Liquid Glass with SDK 14 - ---- - src/switcher/Appearance.swift | 2 +- - .../TilesPanelBackgroundView.swift | 122 +++++++++++------- - 2 files changed, 77 insertions(+), 47 deletions(-) - -diff --git a/src/switcher/Appearance.swift b/src/switcher/Appearance.swift -index dd033fa4..efb70c77 100644 ---- a/src/switcher/Appearance.swift -+++ b/src/switcher/Appearance.swift -@@ -83,7 +83,7 @@ class Appearance { - lightTheme() - } - // for Liquid Glass, we don't want a shadow around the panel -- if #available(macOS 26.0, *), currentStyle == .appIcons && LiquidGlass.canUsePrivateLook { -+ if #available(macOS 26.0, *), currentStyle == .appIcons && LiquidGlassEffectView.canUsePrivateLook { - enablePanelShadow = false - } else { - enablePanelShadow = true -diff --git a/src/switcher/main-window/TilesPanelBackgroundView.swift b/src/switcher/main-window/TilesPanelBackgroundView.swift -index cea0819c..99d12b06 100644 ---- a/src/switcher/main-window/TilesPanelBackgroundView.swift -+++ b/src/switcher/main-window/TilesPanelBackgroundView.swift -@@ -7,12 +7,81 @@ protocol EffectView: NSView { - } - - @available(macOS 26.0, *) --extension NSGlassEffectView: EffectView { -- func updateAppearance() { -- cornerRadius = Appearance.windowCornerRadius -+class LiquidGlassEffectView: NSView, EffectView { -+ private typealias SetIntType = @convention(c) (AnyObject, Selector, Int) -> Void -+ private typealias SetCGFloatType = @convention(c) (AnyObject, Selector, CGFloat) -> Void -+ private typealias SetObjectType = @convention(c) (AnyObject, Selector, AnyObject) -> Void -+ private static let setVariantSelector = NSSelectorFromString("set_variant:") -+ private static let setStyleSelector = NSSelectorFromString("setStyle:") -+ private static let setCornerRadiusSelector = NSSelectorFromString("setCornerRadius:") -+ private static let setContentViewSelector = NSSelectorFromString("setContentView:") -+ private static let glassClass: AnyClass? = NSClassFromString("NSGlassEffectView") -+ -+ static let canUsePrivateLook: Bool = { -+ guard let cls = glassClass else { return false } -+ return class_getInstanceMethod(cls, setVariantSelector) != nil -+ }() -+ -+ private var glassView: NSView? -+ private var contentHost: NSView! -+ -+ var hostView: NSView { contentHost } -+ -+ convenience init(clear: Bool) { -+ self.init(frame: .zero) -+ wantsLayer = true -+ layer!.masksToBounds = true -+ -+ let glass: NSView -+ if let cls = Self.glassClass as? NSView.Type { -+ glass = cls.init(frame: .zero) -+ } else { -+ glass = NSView(frame: .zero) -+ } -+ glass.translatesAutoresizingMaskIntoConstraints = false -+ addSubview(glass) -+ NSLayoutConstraint.activate([ -+ glass.leadingAnchor.constraint(equalTo: leadingAnchor), -+ glass.trailingAnchor.constraint(equalTo: trailingAnchor), -+ glass.topAnchor.constraint(equalTo: topAnchor), -+ glass.bottomAnchor.constraint(equalTo: bottomAnchor), -+ ]) -+ glassView = glass -+ -+ // NSGlassEffectView.Style: regular = 0, clear = 1 -+ Self.invokeIntSetter(glass, Self.setStyleSelector, clear ? 1 : 0) -+ if clear { -+ Self.invokeIntSetter(glass, Self.setVariantSelector, 3) -+ } -+ contentHost = NSView(frame: .zero) -+ Self.invokeObjectSetter(glass, Self.setContentViewSelector, contentHost) -+ updateAppearance() -+ } -+ -+ private static func invokeIntSetter(_ target: AnyObject, _ selector: Selector, _ value: Int) { -+ guard let method = class_getInstanceMethod(object_getClass(target), selector) else { return } -+ let function = unsafeBitCast(method_getImplementation(method), to: SetIntType.self) -+ function(target, selector, value) - } - -- var hostView: NSView { contentView! } -+ private static func invokeCGFloatSetter(_ target: AnyObject, _ selector: Selector, _ value: CGFloat) { -+ guard let method = class_getInstanceMethod(object_getClass(target), selector) else { return } -+ let function = unsafeBitCast(method_getImplementation(method), to: SetCGFloatType.self) -+ function(target, selector, value) -+ } -+ -+ private static func invokeObjectSetter(_ target: AnyObject, _ selector: Selector, _ value: AnyObject) { -+ guard let method = class_getInstanceMethod(object_getClass(target), selector) else { return } -+ let function = unsafeBitCast(method_getImplementation(method), to: SetObjectType.self) -+ function(target, selector, value) -+ } -+ -+ func updateAppearance() { -+ let radius = Appearance.windowCornerRadius -+ layer?.cornerRadius = radius -+ guard let glass = glassView else { return } -+ Self.invokeCGFloatSetter(glass, Self.setCornerRadiusSelector, radius) -+ } - } - - class FrostedGlassEffectView: NSVisualEffectView, EffectView { -@@ -51,28 +120,6 @@ class FrostedGlassEffectView: NSVisualEffectView, EffectView { - } - } - --/// The App Icons style uses the private `set_variant:` on `NSGlassEffectView` to get the macOS --/// Cmd-Tab-like clear glass look. `style = .clear` alone renders nearly fully transparent, so the --/// variant is what makes the panel visible. Lives here as a free helper (no NSGlassEffectView subclass). --enum LiquidGlass { -- private static let setVariantSelector = NSSelectorFromString("set_variant:") -- private typealias SetVariantFn = @convention(c) (AnyObject, Selector, Int) -> Void -- -- static let canUsePrivateLook: Bool = { -- if #available(macOS 26.0, *) { -- return class_getInstanceMethod(object_getClass(NSGlassEffectView()), setVariantSelector) != nil -- } -- return false -- }() -- -- @available(macOS 26.0, *) -- static func applyClearVariant(_ view: NSGlassEffectView) { -- guard let method = class_getInstanceMethod(object_getClass(view), setVariantSelector) else { return } -- let f = unsafeBitCast(method_getImplementation(method), to: SetVariantFn.self) -- f(view, setVariantSelector, 3) -- } --} -- - enum EffectViewKind { - case frosted - case liquidGlassRegular -@@ -82,7 +129,7 @@ enum EffectViewKind { - func requiredEffectViewKind() -> EffectViewKind { - if #available(macOS 26.0, *) { - if Preferences.effectiveAppearanceStyle(SwitcherSession.activeShortcutIndex) == .appIcons, -- LiquidGlass.canUsePrivateLook { -+ LiquidGlassEffectView.canUsePrivateLook { - return .liquidGlassClear - } - return .liquidGlassRegular -@@ -90,28 +137,11 @@ func requiredEffectViewKind() -> EffectViewKind { - return .frosted - } - --@available(macOS 26.0, *) --private func makeGlassEffectView(clear: Bool) -> NSGlassEffectView { -- let glass = NSGlassEffectView() -- glass.style = clear ? .clear : .regular -- if clear { -- LiquidGlass.applyClearVariant(glass) -- } -- // NSGlassEffectView only renders views embedded in `contentView`; this single host holds the -- // scroll view, search field and empty-state label so they all sit inside the glass. -- glass.contentView = NSView() -- glass.updateAppearance() -- // without this, there are weird shadows around the corners (most visible with .regular glass) -- glass.wantsLayer = true -- glass.layer!.masksToBounds = true -- return glass --} -- - func makeEffectView(for kind: EffectViewKind) -> EffectView { - if #available(macOS 26.0, *) { - switch kind { - case .liquidGlassClear: -- return makeGlassEffectView(clear: true) -+ return LiquidGlassEffectView(clear: true) - case .liquidGlassRegular: - if Preferences.effectiveAppearanceStyle(SwitcherSession.activeShortcutIndex) == .appIcons { - Logger.error { -@@ -119,7 +149,7 @@ func makeEffectView(for kind: EffectViewKind) -> EffectView { - return "Private API set_variant is no longer available. macOS version: \(os.majorVersion).\(os.minorVersion).\(os.patchVersion)" - } - } -- return makeGlassEffectView(clear: false) -+ return LiquidGlassEffectView(clear: false) - case .frosted: - break - } --- -2.55.0 - diff --git a/pkgs/by-name/al/alt-tab-macos/package.nix b/pkgs/by-name/al/alt-tab-macos/package.nix index 6309dc6675d0..00fa011ba859 100644 --- a/pkgs/by-name/al/alt-tab-macos/package.nix +++ b/pkgs/by-name/al/alt-tab-macos/package.nix @@ -83,9 +83,6 @@ let allFrameworks = lib.catAttrs "name" frameworks; objcFrameworks = lib.filter (fw: fw ? objc) frameworks; - # apple-sdk_26 cannot be used here because swiftPackages compiles its own modules - # against apple-sdk_14; adding it to buildInputs redirects SDKROOT and breaks Swift's - # foundational modules commonSwiftFlags = [ "-O" "-swift-version" @@ -282,32 +279,15 @@ stdenv.mkDerivation (finalAttrs: { ]; patches = [ - # Swift 5.10 compatibility: count(where:), .extraLarge, Liquid Glass - ./0001-replace-count-where-with-filter-.count-for-Swift-5.1.patch - ./0002-replace-.extraLarge-with-.large-for-macOS-14-SDK.patch - ./0003-use-runtime-dispatch-for-Liquid-Glass-with-SDK-14.patch # Don't offer preferences for services disabled by the source-only stubs. ./0004-hide-settings-for-disabled-services.patch # Avoids error about `CGDisplayStream` initializer being unavailable on macOS when using the 26.x SDK. ./0005-avoid-using-obsolete-api.patch ]; - # Remove trailing comma incompatible with Swift 5.10 postPatch = '' substituteInPlace Info.plist \ ${substitutePlistVariables (infoPlistSubstitutions finalAttrs.version)} - - substituteInPlace src/secondary-windows/permission-window/PermissionsWindow.swift \ - --replace-fail \ - '"x-apple.systempreferences:com.apple.preference.security?Privacy_Accessibility",' \ - '"x-apple.systempreferences:com.apple.preference.security?Privacy_Accessibility"' - - # Swift 5.10 compat: additional call site using trailing-closure - # sugar for count(where:). See 0001-replace-count-where-...patch. - substituteInPlace src/util/UsageStats.swift \ - --replace-fail \ - 'getTimestamps(key).count { $0 >= threshold }' \ - 'getTimestamps(key).filter { $0 >= threshold }.count' ''; dontConfigure = true; From 18bb266cd8c0265d06fe854632ea98003e3a334e Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 246/423] alt-tab-macos: remove obsolete Swift constructs The new Swift packaging no longer requires using a custom stdenv. --- pkgs/by-name/al/alt-tab-macos/package.nix | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/al/alt-tab-macos/package.nix b/pkgs/by-name/al/alt-tab-macos/package.nix index 00fa011ba859..720cf73741e4 100644 --- a/pkgs/by-name/al/alt-tab-macos/package.nix +++ b/pkgs/by-name/al/alt-tab-macos/package.nix @@ -1,17 +1,16 @@ { lib, - swiftPackages, fetchFromGitHub, actool, lld, + stdenv, + swift, makeWrapper, nix-update-script, rcodesign, }: let - inherit (swiftPackages) stdenv swift; - toPlist = lib.generators.toPlist { escape = true; }; deploymentTarget = "14.0"; sdkVersion = "26.0"; From 06552da921ced88de7ab1a4df7eaaa2997e9d0b0 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 247/423] autokbisw: remove obsolete Swift constructs The new Swift packaging no longer requires using a custom stdenv. --- pkgs/by-name/au/autokbisw/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/au/autokbisw/package.nix b/pkgs/by-name/au/autokbisw/package.nix index 76b601b2ae24..d60467d568a9 100644 --- a/pkgs/by-name/au/autokbisw/package.nix +++ b/pkgs/by-name/au/autokbisw/package.nix @@ -1,8 +1,8 @@ { fetchFromGitHub, lib, + stdenv, swift, - swiftPackages, swiftpm, swiftpm2nix, }: @@ -10,7 +10,7 @@ let # Nix dir generated by running `swiftpm2nix` in the upstream project generated = swiftpm2nix.helpers ./nix; in -swiftPackages.stdenv.mkDerivation rec { +stdenv.mkDerivation rec { pname = "autokbisw"; version = "2.0.1"; src = fetchFromGitHub { From 567d6acb6ae7125d05597223576b97fa260eda52 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 248/423] cgtcalc: remove obsolete Swift constructs The new Swift packaging includes XCTest in the toolchain. --- pkgs/by-name/cg/cgtcalc/package.nix | 5 ----- 1 file changed, 5 deletions(-) diff --git a/pkgs/by-name/cg/cgtcalc/package.nix b/pkgs/by-name/cg/cgtcalc/package.nix index c3720fb38c9e..89265525de1b 100644 --- a/pkgs/by-name/cg/cgtcalc/package.nix +++ b/pkgs/by-name/cg/cgtcalc/package.nix @@ -4,7 +4,6 @@ nix-update-script, stdenv, swift, - swiftPackages, swiftpm, swiftpm2nix, }: @@ -37,10 +36,6 @@ stdenv.mkDerivation (finalAttrs: { runHook postInstall ''; - buildInputs = [ - swiftPackages.XCTest - ]; - # libIndexStore.so: cannot open shared object file: No such file or directory # https://github.com/NixOS/nixpkgs/issues/379859 doCheck = false; From ae64a01a39ceb06b140401ce8da1cce71f3d60dd Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 249/423] cgtcalc: enable tests on non-Darwin --- pkgs/by-name/cg/cgtcalc/package.nix | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/pkgs/by-name/cg/cgtcalc/package.nix b/pkgs/by-name/cg/cgtcalc/package.nix index 89265525de1b..d90747cd9308 100644 --- a/pkgs/by-name/cg/cgtcalc/package.nix +++ b/pkgs/by-name/cg/cgtcalc/package.nix @@ -36,9 +36,7 @@ stdenv.mkDerivation (finalAttrs: { runHook postInstall ''; - # libIndexStore.so: cannot open shared object file: No such file or directory - # https://github.com/NixOS/nixpkgs/issues/379859 - doCheck = false; + doCheck = !stdenv.hostPlatform.isDarwin; passthru.updateScript = nix-update-script { extraArgs = [ "--version=branch" ]; From be04f95ba255c08611688a9e790bf9b9a041c525 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 250/423] dark-mode-notify: remove obsolete Swift constructs The new Swift packaging no longer requires using a custom stdenv. --- pkgs/by-name/da/dark-mode-notify/package.nix | 5 +---- 1 file changed, 1 insertion(+), 4 deletions(-) diff --git a/pkgs/by-name/da/dark-mode-notify/package.nix b/pkgs/by-name/da/dark-mode-notify/package.nix index 0b03eee45810..c71283af5933 100644 --- a/pkgs/by-name/da/dark-mode-notify/package.nix +++ b/pkgs/by-name/da/dark-mode-notify/package.nix @@ -4,12 +4,9 @@ stdenv, swift, swiftpm, - swiftPackages, }: -# Use the same stdenv, including clang, as Swift itself -# Fixes build issues, see https://github.com/NixOS/nixpkgs/pull/296082 and https://github.com/NixOS/nixpkgs/issues/295322 -swiftPackages.stdenv.mkDerivation (finalAttrs: { +stdenv.mkDerivation (finalAttrs: { pname = "dark-mode-notify"; version = "0-unstable-2022-07-18"; From 7d50bf1b3287d0996fca3a4df0e8ec2b25655cae Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 251/423] dockutil: remove obsolete Swift constructs The new Swift packaging no longer requires using a custom stdenv. --- pkgs/by-name/do/dockutil/package.nix | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/pkgs/by-name/do/dockutil/package.nix b/pkgs/by-name/do/dockutil/package.nix index 9d770bc4bbac..e9ee0e77057f 100644 --- a/pkgs/by-name/do/dockutil/package.nix +++ b/pkgs/by-name/do/dockutil/package.nix @@ -7,7 +7,6 @@ swift, swiftpm, swiftpm2nix, - swiftPackages, libarchive, p7zip, # Building from source on x86_64 fails (among other things) due to: @@ -30,7 +29,7 @@ let platforms = lib.platforms.darwin; }; - buildFromSource = swiftPackages.stdenv.mkDerivation (finalAttrs: { + buildFromSource = stdenv.mkDerivation (finalAttrs: { inherit pname version meta; src = fetchFromGitHub { From f10061fbb2d866d9b39ce03b219420931b669ec5 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 252/423] dotnet/source/vmr.nix: remove obsolete Swift constructs The new Swift packaging no longer requires using a custom stdenv. --- pkgs/development/compilers/dotnet/source/vmr.nix | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/pkgs/development/compilers/dotnet/source/vmr.nix b/pkgs/development/compilers/dotnet/source/vmr.nix index 06f1174a6fe5..d303c8a0a3d6 100644 --- a/pkgs/development/compilers/dotnet/source/vmr.nix +++ b/pkgs/development/compilers/dotnet/source/vmr.nix @@ -16,8 +16,8 @@ glibcLocales, ensureNewerSourcesForZipFilesHook, darwin, + swift, xcbuild, - swiftPackages, openssl, getconf, python3, @@ -47,7 +47,6 @@ let targetPlatform ; inherit (stdenv.hostPlatform) isLinux isDarwin; - inherit (swiftPackages) swift; releaseManifest = lib.importJSON releaseManifestFile; inherit (releaseManifest) sourceRepository tag; From 33b37373bbcadf7ba487efd30a0519a58b4991a5 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 253/423] dotnet/wrapper.nix: remove obsolete Swift constructs The new Swift packaging no longer requires using a custom stdenv. --- pkgs/development/compilers/dotnet/wrapper.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/development/compilers/dotnet/wrapper.nix b/pkgs/development/compilers/dotnet/wrapper.nix index b81cc38e28df..9aad807a4d0e 100644 --- a/pkgs/development/compilers/dotnet/wrapper.nix +++ b/pkgs/development/compilers/dotnet/wrapper.nix @@ -12,7 +12,7 @@ installShellFiles, callPackage, zlib, - swiftPackages, + swift, icu, lndir, replaceVars, @@ -226,13 +226,13 @@ stdenvNoCC.mkDerivation (finalAttrs: { // lib.optionalAttrs finalAttrs.finalPackage.hasILCompiler { aot = mkConsoleTest { name = "aot"; - stdenv = if stdenv.hostPlatform.isDarwin then swiftPackages.stdenv else stdenv; + inherit stdenv; usePackageSource = true; buildInputs = [ zlib ] ++ lib.optionals stdenv.hostPlatform.isDarwin [ - swiftPackages.swift + swift darwin.ICU ]; build = '' From 09181faedcb144e6c64ed56db035c42b7784f96d Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 254/423] ethernet-connection-status: remove obsolete Swift constructs --- pkgs/by-name/et/ethernet-connection-status/package.nix | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/et/ethernet-connection-status/package.nix b/pkgs/by-name/et/ethernet-connection-status/package.nix index 5d37e06da8d5..feef09bc631a 100644 --- a/pkgs/by-name/et/ethernet-connection-status/package.nix +++ b/pkgs/by-name/et/ethernet-connection-status/package.nix @@ -4,12 +4,11 @@ fetchFromGitHub, lib, nix-update-script, - swiftPackages, + stdenv, + swift, }: let - inherit (swiftPackages) stdenv swift; - infoPlist = version: lib.generators.toPlist { escape = true; } { From c82350cedd10dc38863478fd7f22360405cdc9e1 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 255/423] mask: include Swift support --- pkgs/by-name/ma/mask/package.nix | 7 ++----- 1 file changed, 2 insertions(+), 5 deletions(-) diff --git a/pkgs/by-name/ma/mask/package.nix b/pkgs/by-name/ma/mask/package.nix index 6cd1458177c1..f3c9c26e77b9 100644 --- a/pkgs/by-name/ma/mask/package.nix +++ b/pkgs/by-name/ma/mask/package.nix @@ -12,6 +12,7 @@ php, python3, ruby, + swift, }: rustPlatform.buildRustPackage (finalAttrs: { @@ -37,11 +38,7 @@ rustPlatform.buildRustPackage (finalAttrs: { php python3 ruby - ]; - - checkFlags = [ - # requires swift which currently fails to build - "--skip=swift" + swift ]; nativeInstallCheckInputs = [ versionCheckHook ]; From 6ae3279a89496ff02507c38c7d3f961d92d91b49 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 256/423] mpv-unwrapped: remove obsolete Swift constructs - The Swift stdlib is now a seperate package, and there is a hook to fix up references to the toolchain to point to the stdlib. It should no longer be necessary to manually specify the path to the stdlib; and - Support for `NIX_SWIFTFLAGS_COMPILE` has been dropped from the new Swift packaging. --- pkgs/by-name/mp/mpv-unwrapped/package.nix | 13 ------------- 1 file changed, 13 deletions(-) diff --git a/pkgs/by-name/mp/mpv-unwrapped/package.nix b/pkgs/by-name/mp/mpv-unwrapped/package.nix index 90755a6f6392..51eeefb9a040 100644 --- a/pkgs/by-name/mp/mpv-unwrapped/package.nix +++ b/pkgs/by-name/mp/mpv-unwrapped/package.nix @@ -128,12 +128,6 @@ stdenv.mkDerivation (finalAttrs: { '' ]; - # Ensure we reference 'lib' (not 'out') of Swift. - # TODO: Remove this once the Swift wrapper doesn’t include these. - preConfigure = lib.optionalString stdenv.hostPlatform.isDarwin '' - export SWIFT_LIB_DYNAMIC="${lib.getLib swift.swift}/lib/swift/macosx" - ''; - mesonFlags = [ (lib.mesonOption "default_library" "shared") (lib.mesonOption "sysconfdir" "/etc") @@ -225,13 +219,6 @@ stdenv.mkDerivation (finalAttrs: { ++ lib.optionals zimgSupport [ zimg ] ++ lib.optionals stdenv.hostPlatform.isLinux [ nv-codec-headers-11 ]; - # https://github.com/mpv-player/mpv/issues/15591#issuecomment-2764797522 - # In file included from ../player/clipboard/clipboard-mac.m:19: - # ./osdep/mac/swift.h:270:9: fatal error: '.../app_bridge_objc-1.pch' file not found - env = lib.optionalAttrs (stdenv.hostPlatform.isDarwin) { - NIX_SWIFTFLAGS_COMPILE = "-disable-bridging-pch"; - }; - postBuild = lib.optionalString stdenv.hostPlatform.isDarwin '' pushd .. # Must be run from the source dir because it uses relative paths python3 TOOLS/osxbundle.py -s build/mpv From 7bb47adab9e671fcc91c48f1145247aa871e42f3 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 257/423] pam-watchid: remove obsolete Swift constructs The new Swift packaging no longer requires using a custom stdenv. --- pkgs/by-name/pa/pam-watchid/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/pa/pam-watchid/package.nix b/pkgs/by-name/pa/pam-watchid/package.nix index cd2da4fbd546..3a18b3574641 100644 --- a/pkgs/by-name/pa/pam-watchid/package.nix +++ b/pkgs/by-name/pa/pam-watchid/package.nix @@ -1,12 +1,12 @@ { lib, - swiftPackages, swift, swiftpm, fetchFromGitHub, + stdenv, }: -swiftPackages.stdenv.mkDerivation { +stdenv.mkDerivation { pname = "pam-watchid"; version = "2-unstable-2024-12-24"; From f5b380c3f4b356c78636b29ef4793221ef171cf6 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 258/423] protoc-gen-swift: remove obsolete Swift constructs - The new Swift packaging no longer requires using a custom stdenv; and - It also no longer requires special handling of libdispatch or manually adding Foundation to `buildInputs`. Both are bundled in the toolchain. --- pkgs/by-name/pr/protoc-gen-swift/package.nix | 19 ++----------------- 1 file changed, 2 insertions(+), 17 deletions(-) diff --git a/pkgs/by-name/pr/protoc-gen-swift/package.nix b/pkgs/by-name/pr/protoc-gen-swift/package.nix index cecaf3f3844a..39a5dc46f8a3 100644 --- a/pkgs/by-name/pr/protoc-gen-swift/package.nix +++ b/pkgs/by-name/pr/protoc-gen-swift/package.nix @@ -1,14 +1,12 @@ { lib, fetchFromGitHub, - swiftPackages, swift, swiftpm, nix-update-script, + stdenv, }: -let - stdenv = swiftPackages.stdenv; -in + stdenv.mkDerivation (finalAttrs: { pname = "protoc-gen-swift"; version = "1.34.1"; @@ -26,19 +24,6 @@ stdenv.mkDerivation (finalAttrs: { swiftpm ]; - # Not needed for darwin, as `apple-sdk` is implicit and part of the stdenv - buildInputs = lib.optionals stdenv.hostPlatform.isLinux [ - swiftPackages.Foundation - swiftPackages.Dispatch - ]; - - env = lib.optionalAttrs stdenv.hostPlatform.isLinux { - # swiftpm fails to found libdispatch.so on Linux - LD_LIBRARY_PATH = lib.makeLibraryPath [ - swiftPackages.Dispatch - ]; - }; - installPhase = '' runHook preInstall install -Dm755 .build/release/protoc-gen-swift $out/bin/protoc-gen-swift From ebcc3c55bf3c6605da571378fca17b6d9fdff861 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 259/423] rectangle: remove obsolete Swift constructs The new Swift packaging no longer requires using a custom stdenv. --- pkgs/by-name/re/rectangle/package.nix | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/re/rectangle/package.nix b/pkgs/by-name/re/rectangle/package.nix index 49a2fbc41be4..1f421204969c 100644 --- a/pkgs/by-name/re/rectangle/package.nix +++ b/pkgs/by-name/re/rectangle/package.nix @@ -1,17 +1,16 @@ { lib, - swiftPackages, fetchFromGitHub, darwin, actool, ibtool, makeWrapper, nix-update-script, + swift, + stdenv, }: let - inherit (swiftPackages) stdenv swift; - masShortcutSrc = fetchFromGitHub { owner = "rxhanson"; repo = "MASShortcut"; From 83b68a56b5a5f9c73dafc97c2cbbb3da8400e948 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 260/423] smc-fuzzer: remove unused swiftPackage argument --- pkgs/by-name/sm/smc-fuzzer/package.nix | 1 - 1 file changed, 1 deletion(-) diff --git a/pkgs/by-name/sm/smc-fuzzer/package.nix b/pkgs/by-name/sm/smc-fuzzer/package.nix index 255182141c8d..7a396e506efb 100644 --- a/pkgs/by-name/sm/smc-fuzzer/package.nix +++ b/pkgs/by-name/sm/smc-fuzzer/package.nix @@ -1,6 +1,5 @@ { lib, - swiftPackages, fetchFromGitHub, stdenv, }: From 08ca3e01479dcb3baeaa3a8e0c9a21642926604a Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 261/423] stats: remove obsolete Swift constructs The new Swift packaging no longer requires using a custom stdenv. --- pkgs/by-name/st/stats/package.nix | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/st/stats/package.nix b/pkgs/by-name/st/stats/package.nix index d951e6aff0e2..3636545894e5 100644 --- a/pkgs/by-name/st/stats/package.nix +++ b/pkgs/by-name/st/stats/package.nix @@ -1,9 +1,10 @@ { lib, - swiftPackages, fetchFromGitHub, leveldb, perl, + stdenv, + swift, actool, makeWrapper, rcodesign, @@ -11,8 +12,6 @@ }: let - inherit (swiftPackages) stdenv swift; - frameworks = [ "Kit" "CPU" From 1bd6df73005df1b9ce0985b36bf7cb3737058a23 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 262/423] swipeaerospace: update for new Swift packaging - Manually specify the path to BlueSocket. The new Swift packaging no longer wraps `swift`. Normally, the build system would handle this, but the SwipeAeroSpace packaging builds things manually; and - Move modules and libraries to the standard locations (lib/swift/macosx and lib, respectively). The latter helps ld-wrapper find the dylib when linking BlueSocket. --- pkgs/by-name/sw/swipeaerospace/package.nix | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/sw/swipeaerospace/package.nix b/pkgs/by-name/sw/swipeaerospace/package.nix index 9566311cf313..f6237185809f 100644 --- a/pkgs/by-name/sw/swipeaerospace/package.nix +++ b/pkgs/by-name/sw/swipeaerospace/package.nix @@ -44,7 +44,7 @@ let -emit-module \ -module-name Socket \ -emit-module-path "$buildDir/Socket.swiftmodule" \ - -Xlinker -install_name -Xlinker "$out/lib/swift/libSocket.dylib" \ + -Xlinker -install_name -Xlinker "$out/lib/libSocket.dylib" \ Sources/Socket/*.swift \ -o "$buildDir/libSocket.dylib" @@ -54,9 +54,9 @@ let installPhase = '' runHook preInstall - mkdir -p "$out/lib/swift" - cp build/libSocket.dylib "$out/lib/swift/" - cp build/Socket.* "$out/lib/swift/" + mkdir -p "$out/lib/swift/macosx" + cp build/libSocket.dylib "$out/lib" + cp build/Socket.* "$out/lib/swift/macosx" runHook postInstall ''; @@ -123,6 +123,7 @@ stdenv.mkDerivation (finalAttrs: { done < <(find SwipeAeroSpace -name '*.swift' -print0) swiftc \ + -I${lib.getDev blueSocket}/lib/swift/${stdenv.hostPlatform.swift.platform} \ -O \ -swift-version 5 \ -parse-as-library \ From 61ef2bbc09c862d2dd77b9376726ab95933e9ad1 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 263/423] swipeaerospace: drop settings window patch Swift 6.2 uses the 26.x SDK, which has the required APIs, making the patch no longer necessary. --- pkgs/by-name/sw/swipeaerospace/package.nix | 4 --- .../sw/swipeaerospace/settings-window.patch | 36 ------------------- 2 files changed, 40 deletions(-) delete mode 100644 pkgs/by-name/sw/swipeaerospace/settings-window.patch diff --git a/pkgs/by-name/sw/swipeaerospace/package.nix b/pkgs/by-name/sw/swipeaerospace/package.nix index f6237185809f..d4266145e591 100644 --- a/pkgs/by-name/sw/swipeaerospace/package.nix +++ b/pkgs/by-name/sw/swipeaerospace/package.nix @@ -97,10 +97,6 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-468QGWjbRtA9Fml6jjeJZBTCUEp227cQPckqwyLK0dM="; }; - # Keep SettingsView unchanged, but open it through a regular WindowGroup. - # @Environment(\.openSettings) does not compile with nixpkgs' SwiftUI SDK. - patches = [ ./settings-window.patch ]; - nativeBuildInputs = [ swift actool diff --git a/pkgs/by-name/sw/swipeaerospace/settings-window.patch b/pkgs/by-name/sw/swipeaerospace/settings-window.patch deleted file mode 100644 index a70bb1b31375..000000000000 --- a/pkgs/by-name/sw/swipeaerospace/settings-window.patch +++ /dev/null @@ -1,36 +0,0 @@ ---- a/SwipeAeroSpace/SwipeAeroSpaceApp.swift -+++ b/SwipeAeroSpace/SwipeAeroSpaceApp.swift -@@ -10,10 +10,0 @@ import SwiftUI --@available(macOS 14.0, *) --struct SettingsButton: View { -- @Environment(\.openSettings) private var openSettings -- -- var body: some View { -- Button("Settings") { -- openSettings() -- } -- } --} -@@ -64,16 +54,4 @@ struct SwipeAeroSpaceApp: App { -- if #available(macOS 14.0, *) { -- SettingsButton() -- } else { -- Button( -- action: { -- NSApp.sendAction( -- Selector(("showSettingsWindow:")), -- to: nil, -- from: nil -- ) -- }, -- label: { -- Text("Settings") -- } -- ) -+ Button("Settings") { -+ NSApp.activate(ignoringOtherApps: true) -+ openWindow(id: "settings") - } -@@ -92 +70 @@ struct SwipeAeroSpaceApp: App { -- Settings { -+ WindowGroup(id: "settings") { From a62b12e78d96eb8e9d6497cc8116c6bea09d9acd Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 264/423] swipeaerospace: remove obsolete Swift constructs The new Swift packaging no longer requires using a custom stdenv. --- pkgs/by-name/sw/swipeaerospace/package.nix | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/sw/swipeaerospace/package.nix b/pkgs/by-name/sw/swipeaerospace/package.nix index d4266145e591..f4cb8edd4a8c 100644 --- a/pkgs/by-name/sw/swipeaerospace/package.nix +++ b/pkgs/by-name/sw/swipeaerospace/package.nix @@ -4,12 +4,11 @@ fetchFromGitHub, lib, nix-update-script, - swiftPackages, + stdenv, + swift, }: let - inherit (swiftPackages) stdenv swift; - blueSocket = stdenv.mkDerivation (finalAttrs: { pname = "blue-socket"; version = "2.0.4"; From ddcccf79ca3c681735d99fdc259f639447107400 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 265/423] vzvm: remove obsolete Swift constructs The new Swift packaging no longer requires using a custom stdenv. --- pkgs/by-name/vz/vzvm/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/vz/vzvm/package.nix b/pkgs/by-name/vz/vzvm/package.nix index 1d977008a91d..0dd81712992d 100644 --- a/pkgs/by-name/vz/vzvm/package.nix +++ b/pkgs/by-name/vz/vzvm/package.nix @@ -2,12 +2,12 @@ lib, fetchFromGitHub, darwin, + stdenv, swift, - swiftPackages, nix-update-script, }: -swiftPackages.stdenv.mkDerivation (finalAttrs: { +stdenv.mkDerivation (finalAttrs: { pname = "vzvm"; version = "1.0.0"; From 82648095101fee4e7a90bebb3e215eb6a7ab6d18 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 266/423] xcodegen: remove obsolete Swift constructs The new Swift packaging no longer requires using a custom stdenv. --- pkgs/by-name/xc/xcodegen/package.nix | 8 ++------ 1 file changed, 2 insertions(+), 6 deletions(-) diff --git a/pkgs/by-name/xc/xcodegen/package.nix b/pkgs/by-name/xc/xcodegen/package.nix index 2cc6595d8361..7fa42c144709 100644 --- a/pkgs/by-name/xc/xcodegen/package.nix +++ b/pkgs/by-name/xc/xcodegen/package.nix @@ -1,12 +1,12 @@ { lib, - swiftPackages, swift, swiftpm, swiftpm2nix, fetchFromGitHub, versionCheckHook, nix-update-script, + stdenv, }: let @@ -14,7 +14,7 @@ let generated = swiftpm2nix.helpers ./nix; in -swiftPackages.stdenv.mkDerivation (finalAttrs: { +stdenv.mkDerivation (finalAttrs: { pname = "xcodegen"; version = "2.44.1"; @@ -33,10 +33,6 @@ swiftPackages.stdenv.mkDerivation (finalAttrs: { swiftpm ]; - buildInputs = [ - swiftPackages.XCTest - ]; - # The helper provides a configure snippet that will prepare all dependencies # in the correct place, where SwiftPM expects them. configurePhase = generated.configure + '' From 282292d48ec8f36feafd33ad69563e9594029735 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 267/423] xcodes: remove obsolete Swift constructs The new Swift packaging no longer requires using a custom stdenv. --- pkgs/by-name/xc/xcodes/package.nix | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/pkgs/by-name/xc/xcodes/package.nix b/pkgs/by-name/xc/xcodes/package.nix index 1fad5edafa02..9c8f30b64131 100644 --- a/pkgs/by-name/xc/xcodes/package.nix +++ b/pkgs/by-name/xc/xcodes/package.nix @@ -1,7 +1,7 @@ { lib, fetchFromGitHub, - swiftPackages, + stdenv, swift, swiftpm, swiftpm2nix, @@ -10,7 +10,6 @@ }: let generated = swiftpm2nix.helpers ./generated; - stdenv = swiftPackages.stdenv; in stdenv.mkDerivation (finalAttrs: { pname = "xcodes"; From b34706c1cfc026fb655f3adf92fab11c2119ce5d Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 268/423] swiftPackages_ng.swift: warn on use of deprecated aliases --- .../compilers/swift_ng/by-name/sw/swift/package.nix | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix b/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix index 82be17612d68..5d9d5eabcdc2 100644 --- a/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix +++ b/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix @@ -1,5 +1,6 @@ { lib, + config, apple-sdk_14, apple-sdk_26, callPackage, @@ -236,12 +237,13 @@ stdenv.mkDerivation (finalAttrs: { # Our toolchain builds install modules in `lib/swift/`, which matches what upstream toolchains do. swiftModuleSubdir = "lib/swift/${stdenv.hostPlatform.swift.platform}"; swiftStaticModuleSubdir = "lib/swift_static/${stdenv.hostPlatform.swift.platform}"; - + } + // lib.optionalAttrs config.allowAliases { # Legacy aliases for the old Swift packaging. These should eventually be removed. - swift = finalAttrs.finalPackage; - swiftArch = stdenv.hostPlatform.swift.arch; - swiftDriver = lib.warn "'swiftDriver' has been renamed to 'swift-driver'" finalAttrs.passthru.swift-driver; - swiftOs = stdenv.hostPlatform.swift.platform; + swift = lib.warnOnInstantiate "`swift` is an alias for this (`swift`) package. Just use it directly." finalAttrs.finalPackage; + swiftArch = lib.warnOnInstantiate "'swiftArch' is an alias for 'stdenv.hostPlatform.swift.arch'." stdenv.hostPlatform.swift.arch; + swiftDriver = lib.warnOnInstantiate "'swiftDriver' has been renamed to 'swift-driver'" finalAttrs.passthru.swift-driver; + swiftOs = lib.warnOnInstantiate "'swiftOs' is an alias for 'stdenv.hostPlatform.swift.platform'." stdenv.hostPlatform.swift.platform; }; meta = { From 447ed2aef2ee4836aed8ee1861f1b319ac59efb8 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 6 Aug 2026 19:56:05 -0400 Subject: [PATCH 269/423] swiftPackages_ng: warn on use of deprecated aliases --- pkgs/top-level/swift-packages.nix | 30 +++++++++++++++++++----------- 1 file changed, 19 insertions(+), 11 deletions(-) diff --git a/pkgs/top-level/swift-packages.nix b/pkgs/top-level/swift-packages.nix index 7ab1d3c41fd7..b5339f4f3826 100644 --- a/pkgs/top-level/swift-packages.nix +++ b/pkgs/top-level/swift-packages.nix @@ -45,6 +45,7 @@ in { lib, + config, clangStdenv, generateSplicesForMkScope, llvmPackages, @@ -108,15 +109,22 @@ makeScopeWithSplicing' { swift_sources = swift_sources_6_2; }; - f = lib.extends autoCalledPackages (self: { - stdenv = clangStdenv; - swift_release = "6.2.4"; - - # Compatibility aliases for the old Swift packaging. - swift-unwrapped = self.swift; - swiftNoSwiftDriver = self.swift.override { swift-driver = null; }; - Dispatch = self.swift-corelibs-libdispatch; - Foundation = self.swift-corelibs-foundation; - XCTest = self.swift-corelibs-xctest; - }); + f = lib.extends autoCalledPackages ( + self: + { + stdenv = clangStdenv; + swift_release = "6.2.4"; + } + // lib.optionalAttrs config.allowAliases { + # Compatibility aliases for the old Swift packaging. + swift-unwrapped = lib.warnOnInstantiate "Swift is no longer wrapped. Use `swift` directly." self.swift; + swiftNoSwiftDriver = + lib.warnOnInstantiate + "swiftNoSwiftDriver is an alias. Override `swift` and set `swift-driver` to `null` instead." + (self.swift.override { swift-driver = null; }); + Dispatch = lib.warnOnInstantiate "Dispatch has been renamed to swift-corelibs-libdispatch. It is also now included in the default Swift SDK and no longer needs referenced as a separate package." self.swift-corelibs-libdispatch; + Foundation = lib.warnOnInstantiate "Foundation has been renamed to swift-corelibs-foundation. It is also now included in the default Swift SDK and no longer needs referenced as a separate package." self.swift-corelibs-foundation; + XCTest = lib.warnOnInstantiate "XCTest has been renamed to swift-corelibs-xctest. It is also now included in the default Swift SDK and no longer needs referenced as a separate package." self.swift-corelibs-xctest; + } + ); } From 424cefcdb592dfcd8dc4c81ad705f8133190f99d Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 270/423] swiftPackages: delete Swift 5.10.1 package set The old package set will be replaced with the Swift 6.2 package set. Going forward, it is expected that updates will be done in that package set since it is hoped that another rewrite will not be required. --- .../compilers/swift/compiler/default.nix | 842 ------------------ .../swift/compiler/patches/clang-purity.patch | 21 - .../patches/clang-toolchain-dir.patch | 13 - .../swift/compiler/patches/clang-wrap.patch | 18 - ...vm-fix-X86MCTargetDesc-compile-error.patch | 34 - .../compiler/patches/llvm-module-cache.patch | 30 - ...-Fix-a-small-unique_ptr-array-access.patch | 35 - .../swift-darwin-plistbuddy-workaround.patch | 17 - .../patches/swift-linux-fix-libc-paths.patch | 48 - .../patches/swift-linux-fix-linking.patch | 17 - .../swift-prevent-sdk-dirs-warning.patch | 39 - .../compiler/patches/swift-separate-lib.patch | 26 - .../swift/compiler/patches/swift-wrap.patch | 46 - .../swift/cxx-interop-test/default.nix | 57 -- .../swift/cxx-interop-test/src/.gitignore | 9 - .../swift/cxx-interop-test/src/Package.swift | 16 - .../cxx-interop-test/src/Sources/main.swift | 3 - pkgs/development/compilers/swift/default.nix | 85 -- .../compilers/swift/foundation/default.nix | 71 -- .../compilers/swift/foundation/glue.cmake | 8 - .../compilers/swift/libdispatch/default.nix | 68 -- .../libdispatch/disable-swift-overlay.patch | 35 - .../compilers/swift/libdispatch/glue.cmake | 5 - .../compilers/swift/sourcekit-lsp/default.nix | 89 -- .../swift/sourcekit-lsp/generated/default.nix | 19 - .../generated/workspace-state.json | 229 ----- .../patches/indexstore-db-macos-target.patch | 12 - pkgs/development/compilers/swift/sources.nix | 39 - .../compilers/swift/swift-docc/default.nix | 73 -- .../swift/swift-docc/fix-swift-nio.patch | 13 - .../swift/swift-docc/generated/default.nix | 16 - .../swift-docc/generated/workspace-state.json | 178 ---- .../compilers/swift/swift-driver/default.nix | 82 -- .../swift/swift-driver/generated/default.nix | 11 - .../generated/workspace-state.json | 93 -- .../patches/disable-catalyst.patch | 17 - .../patches/linux-fix-linking.patch | 40 - .../patches/prevent-sdk-dirs-warnings.patch | 16 - .../compilers/swift/swift-format/default.nix | 62 -- .../swift/swift-format/generated/default.nix | 10 - .../generated/workspace-state.json | 76 -- .../compilers/swift/swiftpm/cmake-glue.nix | 107 --- .../compilers/swift/swiftpm/default.nix | 501 ----------- .../swift/swiftpm/generated/default.nix | 16 - .../swiftpm/generated/workspace-state.json | 178 ---- .../swiftpm/patches/cmake-disable-rpath.patch | 36 - .../swiftpm/patches/disable-index-store.patch | 23 - .../swiftpm/patches/disable-sandbox.patch | 27 - .../swiftpm/patches/disable-xctest.patch | 14 - .../swift/swiftpm/patches/fix-clang-cxx.patch | 126 --- .../swiftpm/patches/fix-stdlib-path.patch | 25 - .../patches/install-crypto-extras.patch | 10 - .../patches/llbuild-cmake-disable-rpath.patch | 14 - .../patches/llbuild-fix-missing-cstdint.patch | 12 - .../swiftpm/patches/nix-pkgconfig-vars.patch | 28 - .../compilers/swift/swiftpm/setup-hook.sh | 62 -- .../compilers/swift/swiftpm2nix/default.nix | 38 - .../compilers/swift/swiftpm2nix/support.nix | 77 -- .../swift/swiftpm2nix/swiftpm2nix.sh | 45 - .../compilers/swift/wrapper/default.nix | 119 --- .../compilers/swift/wrapper/setup-hook.sh | 28 - .../compilers/swift/wrapper/wrapper.sh | 313 ------- .../compilers/swift/xctest/default.nix | 61 -- pkgs/top-level/all-packages.nix | 1 - 64 files changed, 4479 deletions(-) delete mode 100644 pkgs/development/compilers/swift/compiler/default.nix delete mode 100644 pkgs/development/compilers/swift/compiler/patches/clang-purity.patch delete mode 100644 pkgs/development/compilers/swift/compiler/patches/clang-toolchain-dir.patch delete mode 100644 pkgs/development/compilers/swift/compiler/patches/clang-wrap.patch delete mode 100644 pkgs/development/compilers/swift/compiler/patches/llvm-fix-X86MCTargetDesc-compile-error.patch delete mode 100644 pkgs/development/compilers/swift/compiler/patches/llvm-module-cache.patch delete mode 100644 pkgs/development/compilers/swift/compiler/patches/swift-Frontend-Fix-a-small-unique_ptr-array-access.patch delete mode 100644 pkgs/development/compilers/swift/compiler/patches/swift-darwin-plistbuddy-workaround.patch delete mode 100644 pkgs/development/compilers/swift/compiler/patches/swift-linux-fix-libc-paths.patch delete mode 100644 pkgs/development/compilers/swift/compiler/patches/swift-linux-fix-linking.patch delete mode 100644 pkgs/development/compilers/swift/compiler/patches/swift-prevent-sdk-dirs-warning.patch delete mode 100644 pkgs/development/compilers/swift/compiler/patches/swift-separate-lib.patch delete mode 100644 pkgs/development/compilers/swift/compiler/patches/swift-wrap.patch delete mode 100644 pkgs/development/compilers/swift/cxx-interop-test/default.nix delete mode 100644 pkgs/development/compilers/swift/cxx-interop-test/src/.gitignore delete mode 100644 pkgs/development/compilers/swift/cxx-interop-test/src/Package.swift delete mode 100644 pkgs/development/compilers/swift/cxx-interop-test/src/Sources/main.swift delete mode 100644 pkgs/development/compilers/swift/default.nix delete mode 100644 pkgs/development/compilers/swift/foundation/default.nix delete mode 100644 pkgs/development/compilers/swift/foundation/glue.cmake delete mode 100644 pkgs/development/compilers/swift/libdispatch/default.nix delete mode 100644 pkgs/development/compilers/swift/libdispatch/disable-swift-overlay.patch delete mode 100644 pkgs/development/compilers/swift/libdispatch/glue.cmake delete mode 100644 pkgs/development/compilers/swift/sourcekit-lsp/default.nix delete mode 100644 pkgs/development/compilers/swift/sourcekit-lsp/generated/default.nix delete mode 100644 pkgs/development/compilers/swift/sourcekit-lsp/generated/workspace-state.json delete mode 100644 pkgs/development/compilers/swift/sourcekit-lsp/patches/indexstore-db-macos-target.patch delete mode 100644 pkgs/development/compilers/swift/sources.nix delete mode 100644 pkgs/development/compilers/swift/swift-docc/default.nix delete mode 100644 pkgs/development/compilers/swift/swift-docc/fix-swift-nio.patch delete mode 100644 pkgs/development/compilers/swift/swift-docc/generated/default.nix delete mode 100644 pkgs/development/compilers/swift/swift-docc/generated/workspace-state.json delete mode 100644 pkgs/development/compilers/swift/swift-driver/default.nix delete mode 100644 pkgs/development/compilers/swift/swift-driver/generated/default.nix delete mode 100644 pkgs/development/compilers/swift/swift-driver/generated/workspace-state.json delete mode 100644 pkgs/development/compilers/swift/swift-driver/patches/disable-catalyst.patch delete mode 100644 pkgs/development/compilers/swift/swift-driver/patches/linux-fix-linking.patch delete mode 100644 pkgs/development/compilers/swift/swift-driver/patches/prevent-sdk-dirs-warnings.patch delete mode 100644 pkgs/development/compilers/swift/swift-format/default.nix delete mode 100644 pkgs/development/compilers/swift/swift-format/generated/default.nix delete mode 100644 pkgs/development/compilers/swift/swift-format/generated/workspace-state.json delete mode 100644 pkgs/development/compilers/swift/swiftpm/cmake-glue.nix delete mode 100644 pkgs/development/compilers/swift/swiftpm/default.nix delete mode 100644 pkgs/development/compilers/swift/swiftpm/generated/default.nix delete mode 100644 pkgs/development/compilers/swift/swiftpm/generated/workspace-state.json delete mode 100644 pkgs/development/compilers/swift/swiftpm/patches/cmake-disable-rpath.patch delete mode 100644 pkgs/development/compilers/swift/swiftpm/patches/disable-index-store.patch delete mode 100644 pkgs/development/compilers/swift/swiftpm/patches/disable-sandbox.patch delete mode 100644 pkgs/development/compilers/swift/swiftpm/patches/disable-xctest.patch delete mode 100644 pkgs/development/compilers/swift/swiftpm/patches/fix-clang-cxx.patch delete mode 100644 pkgs/development/compilers/swift/swiftpm/patches/fix-stdlib-path.patch delete mode 100644 pkgs/development/compilers/swift/swiftpm/patches/install-crypto-extras.patch delete mode 100644 pkgs/development/compilers/swift/swiftpm/patches/llbuild-cmake-disable-rpath.patch delete mode 100644 pkgs/development/compilers/swift/swiftpm/patches/llbuild-fix-missing-cstdint.patch delete mode 100644 pkgs/development/compilers/swift/swiftpm/patches/nix-pkgconfig-vars.patch delete mode 100644 pkgs/development/compilers/swift/swiftpm/setup-hook.sh delete mode 100644 pkgs/development/compilers/swift/swiftpm2nix/default.nix delete mode 100644 pkgs/development/compilers/swift/swiftpm2nix/support.nix delete mode 100755 pkgs/development/compilers/swift/swiftpm2nix/swiftpm2nix.sh delete mode 100644 pkgs/development/compilers/swift/wrapper/default.nix delete mode 100644 pkgs/development/compilers/swift/wrapper/setup-hook.sh delete mode 100644 pkgs/development/compilers/swift/wrapper/wrapper.sh delete mode 100644 pkgs/development/compilers/swift/xctest/default.nix diff --git a/pkgs/development/compilers/swift/compiler/default.nix b/pkgs/development/compilers/swift/compiler/default.nix deleted file mode 100644 index 454bee2c49f7..000000000000 --- a/pkgs/development/compilers/swift/compiler/default.nix +++ /dev/null @@ -1,842 +0,0 @@ -{ - lib, - stdenv, - callPackage, - cmake, - bash, - coreutils, - gnugrep, - perl, - ninja_1_11, - pkg-config, - clang, - bintools, - python312Packages, - git, - fetchpatch, - fetchpatch2, - makeWrapper, - gnumake, - file, - runCommand, - writeShellScriptBin, - # For lldb - libedit, - ncurses, - swig, - libxml2, - # Linux-specific - glibc, - libuuid, - # Darwin-specific - replaceVars, - fixDarwinDylibNames, - xcbuild, - cctools, # libtool - sigtool, - DarwinTools, - apple-sdk_14, - darwinMinVersionHook, -}: - -let - apple-sdk_swift = apple-sdk_14; # Use the SDK that was available when Swift shipped. - - deploymentVersion = - if lib.versionOlder (targetPlatform.darwinMinVersion or "0") "10.15" then - "10.15" - else - targetPlatform.darwinMinVersion; - - # Use Python 3.12 for now because Swift 5.8 depends on Python's PyEval_ThreadsInitialized(), which was removed in 3.13. - python3 = python312Packages.python.withPackages (p: [ p.setuptools ]); # python 3.12 compat. - - inherit (stdenv) hostPlatform targetPlatform; - - sources = callPackage ../sources.nix { }; - - # There are apparently multiple naming conventions on Darwin. Swift uses the - # xcrun naming convention. See `configure_sdk_darwin` calls in CMake files. - swiftOs = - if targetPlatform.isDarwin then - { - "macos" = "macosx"; - "ios" = "iphoneos"; - #iphonesimulator - #appletvos - #appletvsimulator - #watchos - #watchsimulator - } - .${targetPlatform.darwinPlatform} - or (throw "Cannot build Swift for target Darwin platform '${targetPlatform.darwinPlatform}'") - else - targetPlatform.parsed.kernel.name; - - # This causes swiftPackages.XCTest to fail to build on aarch64-linux - # as I believe this is because Apple calls the architecture aarch64 - # on Linux rather than arm64 when used with macOS. - swiftArch = - if hostPlatform.isDarwin then hostPlatform.darwinArch else targetPlatform.parsed.cpu.name; - - # On Darwin, a `.swiftmodule` is a subdirectory in `lib/swift/`, - # containing binaries for supported archs. On other platforms, binaries are - # installed to `lib/swift//`. Note that our setup-hook also adds - # `lib/swift` for convenience. - swiftLibSubdir = "lib/swift/${swiftOs}"; - swiftModuleSubdir = - if hostPlatform.isDarwin then "lib/swift/${swiftOs}" else "lib/swift/${swiftOs}/${swiftArch}"; - - # And then there's also a separate subtree for statically linked modules. - toStaticSubdir = lib.replaceStrings [ "/swift/" ] [ "/swift_static/" ]; - swiftStaticLibSubdir = toStaticSubdir swiftLibSubdir; - swiftStaticModuleSubdir = toStaticSubdir swiftModuleSubdir; - - # This matches _SWIFT_DEFAULT_COMPONENTS, with specific components disabled. - swiftInstallComponents = [ - "autolink-driver" - "compiler" - # "clang-builtin-headers" - "stdlib" - "sdk-overlay" - "static-mirror-lib" - "editor-integration" - # "tools" - # "testsuite-tools" - "toolchain-tools" - "toolchain-dev-tools" - "license" - (if stdenv.hostPlatform.isDarwin then "sourcekit-xpc-service" else "sourcekit-inproc") - "swift-remote-mirror" - "swift-remote-mirror-headers" - ]; - - clangForWrappers = clang.override (prev: { - extraBuildCommands = - prev.extraBuildCommands - # We need to use the resource directory corresponding to Swift’s - # version of Clang instead of passing along the one from the - # `cc-wrapper` flags. - + '' - substituteInPlace $out/nix-support/cc-cflags \ - --replace-fail " -resource-dir=$out/resource-root" "" - '' - + - lib.optionalString - (targetPlatform.isLinux && targetPlatform.isx86 && lib.versionAtLeast (lib.getVersion clang) "19.1") - '' - # Swift bundles Clang 16, which predates -mtls-dialect=gnu2 - # support (added in Clang 19.1). The cc-wrapper adds it based - # on the system Clang version, so strip it here. - substituteInPlace $out/nix-support/add-local-cc-cflags-before.sh \ - --replace-fail "'-mtls-dialect=gnu2'" "" - ''; - }); - - # Build a tool used during the build to create a custom clang wrapper, with - # which we wrap the clang produced by the swift build. - # - # This is used in a `POST_BUILD` for the CMake target, so we rename the - # actual clang to clang-unwrapped, then put the wrapper in place. - # - # We replace the `exec ...` command with `exec -a "$0"` in order to - # preserve $0 for clang. This is because, unlike Nix, we don't have - # separate wrappers for clang/clang++, and clang uses $0 to detect C++. - # - # Similarly, the C++ detection in the wrapper itself also won't work for us, - # so we base it on $0 as well. - makeClangWrapper = writeShellScriptBin "nix-swift-make-clang-wrapper" '' - set -euo pipefail - - targetFile="$1" - unwrappedClang="$targetFile-unwrapped" - - mv "$targetFile" "$unwrappedClang" - sed < '${clangForWrappers}/bin/clang' > "$targetFile" \ - -e 's|^\s*exec|exec -a "$0"|g' \ - -e 's|^\[\[ "${clang.cc}/bin/clang" = \*++ ]]|[[ "$0" = *++ ]]|' \ - -e "s|${clang.cc}/bin/clang|$unwrappedClang|g" \ - -e "s|^\(\s*\)\($unwrappedClang\) \"@\\\$responseFile\"|\1argv0=\$0\n\1${bash}/bin/bash -c \"exec -a '\$argv0' \2 '@\$responseFile'\"|" \ - ${lib.optionalString (clang.libcxx != null) '' - -e 's|$NIX_CXXSTDLIB_COMPILE_${clang.suffixSalt}|-isystem '$SWIFT_BUILD_ROOT'/libcxx/include/c++/v1|g' - ''} - chmod a+x "$targetFile" - ''; - - # Create a tool used during the build to create a custom swift wrapper for - # each of the swift executables produced by the build. - # - # The build produces several `swift-frontend` executables during - # bootstrapping. Each of these has numerous aliases via symlinks, and the - # executable uses $0 to detect what tool is called. - wrapperParams = { - inherit bintools; - coreutils_bin = lib.getBin coreutils; - gnugrep_bin = gnugrep; - suffixSalt = lib.replaceStrings [ "-" "." ] [ "_" "_" ] targetPlatform.config; - use_response_file_by_default = 1; - swiftDriver = ""; - # NOTE: @cc_wrapper@ and @prog@ need to be filled elsewhere. - }; - swiftWrapper = runCommand "swift-wrapper.sh" wrapperParams '' - # Make empty to avoid adding the SDK’s modules in the bootstrap wrapper. Otherwise, the SDK conflicts with the - # shims the wrapper tries to build. - darwinMinVersion="" substituteAll '${../wrapper/wrapper.sh}' "$out" - ''; - makeSwiftcWrapper = writeShellScriptBin "nix-swift-make-swift-wrapper" '' - set -euo pipefail - - targetFile="$1" - unwrappedSwift="$targetFile-unwrapped" - - mv "$targetFile" "$unwrappedSwift" - sed < '${swiftWrapper}' > "$targetFile" \ - -e "s|@prog@|'$unwrappedSwift'|g" \ - -e 's|@cc_wrapper@|${clangForWrappers}|g' \ - -e 's|exec "$prog"|exec -a "$0" "$prog"|g' \ - ${lib.optionalString (clang.libcxx != null) '' - -e 's|$NIX_CXXSTDLIB_COMPILE_${clang.suffixSalt}|-isystem '$SWIFT_BUILD_ROOT'/libcxx/include/c++/v1|g' - ''} - chmod a+x "$targetFile" - ''; - - # On Darwin, we need to use BOOTSTRAPPING-WITH-HOSTLIBS because of ABI - # stability, and have to provide the definitions for the system stdlib. - appleSwiftCore = stdenv.mkDerivation { - name = "apple-swift-core"; - dontUnpack = true; - - buildInputs = [ apple-sdk_swift ]; - - installPhase = '' - mkdir -p $out/lib/swift - cp -r \ - "$SDKROOT/usr/lib/swift/Swift.swiftmodule" \ - "$SDKROOT/usr/lib/swift/CoreFoundation.swiftmodule" \ - "$SDKROOT/usr/lib/swift/Dispatch.swiftmodule" \ - "$SDKROOT/usr/lib/swift/ObjectiveC.swiftmodule" \ - "$SDKROOT/usr/lib/swift/libswiftCore.tbd" \ - "$SDKROOT/usr/lib/swift/libswiftCoreFoundation.tbd" \ - "$SDKROOT/usr/lib/swift/libswiftDispatch.tbd" \ - "$SDKROOT/usr/lib/swift/libswiftFoundation.tbd" \ - "$SDKROOT/usr/lib/swift/libswiftObjectiveC.tbd" \ - $out/lib/swift/ - ''; - }; - - # https://github.com/NixOS/nixpkgs/issues/327836 - # Fail to build with ninja 1.12 when NIX_BUILD_CORES is low (Hydra or Github Actions). - # Can reproduce using `nix --option cores 2 build -f . swiftPackages.swift-unwrapped`. - # Until we find out the exact cause, follow [swift upstream][1], pin ninja to version - # 1.11.1. - # [1]: https://github.com/swiftlang/swift/pull/72989 - ninja = ninja_1_11; - -in -stdenv.mkDerivation { - pname = "swift"; - inherit (sources) version; - - outputs = [ - "out" - "lib" - "dev" - "doc" - "man" - ]; - - nativeBuildInputs = [ - cmake - git - ninja - perl # pod2man - pkg-config - python3 - makeWrapper - makeClangWrapper - makeSwiftcWrapper - ] - ++ lib.optionals stdenv.hostPlatform.isDarwin [ - xcbuild - sigtool # codesign - DarwinTools # sw_vers - fixDarwinDylibNames - cctools.libtool - ]; - - buildInputs = [ - # For lldb - python3 - swig - libxml2 - ] - ++ lib.optionals stdenv.hostPlatform.isLinux [ - libuuid - ] - ++ lib.optionals stdenv.hostPlatform.isDarwin [ - apple-sdk_swift - ]; - - # Will effectively be `buildInputs` when swift is put in `nativeBuildInputs`. - depsTargetTargetPropagated = lib.optionals stdenv.targetPlatform.isDarwin [ - apple-sdk_swift - ]; - - # This is a partial reimplementation of our setup hook. Because we reuse - # the Swift wrapper for the Swift build itself, we need to do some of the - # same preparation. - postHook = '' - for pkg in "''${pkgsHostTarget[@]}" '${clang.libc}'; do - for subdir in ${swiftModuleSubdir} ${swiftStaticModuleSubdir} lib/swift; do - if [[ -d "$pkg/$subdir" ]]; then - export NIX_SWIFTFLAGS_COMPILE+=" -I $pkg/$subdir" - fi - done - for subdir in ${swiftLibSubdir} ${swiftStaticLibSubdir} lib/swift; do - if [[ -d "$pkg/$subdir" ]]; then - export NIX_LDFLAGS+=" -L $pkg/$subdir" - fi - done - done - ''; - - # We setup custom build directories. - dontUseCmakeBuildDir = true; - - unpackPhase = - let - copySource = repo: "cp -r ${sources.${repo}} ${repo}"; - in - '' - mkdir src - cd src - - ${copySource "swift-cmark"} - ${copySource "llvm-project"} - ${copySource "swift"} - ${copySource "swift-experimental-string-processing"} - ${copySource "swift-syntax"} - ${lib.optionalString (!stdenv.hostPlatform.isDarwin) (copySource "swift-corelibs-libdispatch")} - - chmod -R u+w . - ''; - - patchPhase = '' - # Just patch all the things for now, we can focus this later. - # TODO: eliminate use of env. - find -type f -print0 | xargs -0 sed -i \ - ${lib.optionalString stdenv.hostPlatform.isDarwin "-e 's|/usr/libexec/PlistBuddy|${xcbuild}/bin/PlistBuddy|g'"} \ - -e 's|/usr/bin/env|${coreutils}/bin/env|g' \ - -e 's|/usr/bin/make|${gnumake}/bin/make|g' \ - -e 's|/bin/mkdir|${coreutils}/bin/mkdir|g' \ - -e 's|/bin/cp|${coreutils}/bin/cp|g' \ - -e 's|/usr/bin/file|${file}/bin/file|g' - - patch -p1 -d swift -i ${./patches/swift-wrap.patch} - patch -p1 -d swift -i ${./patches/swift-linux-fix-libc-paths.patch} - patch -p1 -d swift -i ${ - replaceVars ./patches/swift-linux-fix-linking.patch { - inherit clang; - } - } - patch -p1 -d swift -i ${ - replaceVars ./patches/swift-darwin-plistbuddy-workaround.patch { - inherit swiftArch; - } - } - patch -p1 -d swift -i ${ - replaceVars ./patches/swift-prevent-sdk-dirs-warning.patch { - inherit (builtins) storeDir; - } - } - patch -p1 -d swift -i ${./patches/swift-Frontend-Fix-a-small-unique_ptr-array-access.patch} - - # This patch needs to know the lib output location, so must be substituted - # in the same derivation as the compiler. - storeDir="${builtins.storeDir}" \ - substituteAll ${./patches/swift-separate-lib.patch} $TMPDIR/swift-separate-lib.patch - patch -p1 -d swift -i $TMPDIR/swift-separate-lib.patch - - patch -p1 -d llvm-project/llvm -i ${./patches/llvm-module-cache.patch} - for root in llvm-project/llvm swift/stdlib; do - patch -p1 -d $root -i ${ - (fetchpatch { - name = "fix-SmallVector-compile-error.patch"; - url = "https://github.com/llvm/llvm-project/commit/7e44305041d96b064c197216b931ae3917a34ac1.patch"; - stripLen = 1; - hash = "sha256-1htuzsaPHbYgravGc1vrR8sqpQ/NSQ8PUZeAU8ucCFk="; - }) - } - done - patch -p2 -d llvm-project/llvm -i ${./patches/llvm-fix-X86MCTargetDesc-compile-error.patch} - - for lldbPatch in ${ - lib.escapeShellArgs [ - # Fix the build with modern libc++. - (fetchpatch { - name = "add-cstdio.patch"; - url = "https://github.com/llvm/llvm-project/commit/73e15b5edb4fa4a77e68c299a6e3b21e610d351f.patch"; - stripLen = 1; - hash = "sha256-eFcvxZaAuBsY/bda1h9212QevrXyvCHw8Cr9ngetDr0="; - }) - (fetchpatch { - url = "https://github.com/llvm/llvm-project/commit/68744ffbdd7daac41da274eef9ac0d191e11c16d.patch"; - stripLen = 1; - hash = "sha256-QCGhsL/mi7610ZNb5SqxjRGjwJeK2rwtsFVGeG3PUGc="; - }) - (fetchpatch { - name = "LLDB-Add-cstdint-to-AddressableBits-102110.patch"; - url = "https://github.com/llvm/llvm-project/commit/bb59f04e7e75dcbe39f1bf952304a157f0035314.patch"; - stripLen = 1; - hash = "sha256-+CcmZRxCaozFe1Kuf2HX+kGKuh/PDuoFBEFA/t7tL9A="; - }) - ] - }; do - patch -p1 -d llvm-project/lldb -i $lldbPatch - done - - patch -p1 -d llvm-project/clang -i ${./patches/clang-toolchain-dir.patch} - patch -p1 -d llvm-project/clang -i ${./patches/clang-wrap.patch} - patch -p1 -d llvm-project/clang -i ${./patches/clang-purity.patch} - - patch -p1 -d llvm-project/cmake -i ${ - fetchpatch2 { - name = "cmake-fix.patch"; - url = "https://github.com/llvm/llvm-project/commit/3676a86a4322e8c2b9c541f057b5d3704146b8f3.patch?full_index=1"; - stripLen = 1; - hash = "sha256-zP9dQOmWs7qrxkBRj70DyQBbRjH78B6tNJVy6ilA1xM="; - } - } - - ${lib.optionalString stdenv.hostPlatform.isLinux '' - substituteInPlace llvm-project/clang/lib/Driver/ToolChains/Linux.cpp \ - --replace-fail 'LibDir = "lib";' 'LibDir = "${glibc}/lib";' \ - --replace-fail 'LibDir = "lib64";' 'LibDir = "${glibc}/lib";' \ - --replace-fail 'LibDir = X32 ? "libx32" : "lib64";' 'LibDir = "${glibc}/lib";' - - # uuid.h is not part of glibc, but of libuuid. - sed -i 's|''${GLIBC_INCLUDE_PATH}/uuid/uuid.h|${libuuid.dev}/include/uuid/uuid.h|' \ - swift/stdlib/public/Platform/glibc.modulemap.gyb - ''} - - # Remove tests for cross compilation, which we don't currently support. - rm swift/test/Interop/Cxx/class/constructors-copy-irgen-*.swift - rm swift/test/Interop/Cxx/class/constructors-irgen-*.swift - - # TODO: consider fixing and re-adding. This test fails due to a non-standard "install_prefix". - rm swift/validation-test/Python/build_swift.swift - - # We cannot handle the SDK location being in "Weird Location" due to Nix isolation. - rm swift/test/DebugInfo/compiler-flags.swift - - # TODO: Fix issue with ld.gold invoked from script finding crtbeginS.o and crtendS.o. - rm swift/test/IRGen/ELF-remove-autolink-section.swift - - # The following two tests fail because we use don't use the bundled libicu: - # [SOURCE_DIR/utils/build-script] ERROR: can't find source directory for libicu (tried /build/src/icu) - rm swift/validation-test/BuildSystem/default_build_still_performs_epilogue_opts_after_split.test - rm swift/validation-test/BuildSystem/test_early_swift_driver_and_infer.swift - - # TODO: This test fails for some unknown reason - rm swift/test/Serialization/restrict-swiftmodule-to-revision.swift - - # This test was flaky in ofborg, see #186476 - rm swift/test/AutoDiff/compiler_crashers_fixed/issue-56649-missing-debug-scopes-in-pullback-trampoline.swift - - patchShebangs . - - ${lib.optionalString (!stdenv.hostPlatform.isDarwin) '' - patch -p1 -d swift-corelibs-libdispatch -i ${ - # Fix the build with modern Clang. - fetchpatch { - url = "https://github.com/swiftlang/swift-corelibs-libdispatch/commit/30bb8019ba79cdae0eb1dc0c967c17996dd5cc0a.patch"; - hash = "sha256-wPZQ4wtEWk8HaKMfzjamlU6p/IW5EFiTssY63rGM+ZA="; - } - } - patch -p1 -d swift-corelibs-libdispatch -i ${ - # Fix the build with modern Clang. - fetchpatch { - url = "https://github.com/swiftlang/swift-corelibs-libdispatch/commit/38872e2d44d66d2fb94186988509defc734888a5.patch"; - hash = "sha256-GABwDeTjciV36Sa0FS10mCfFCqRoBBstgW/OiKdPahA="; - } - } - ''} - ''; - - # > clang-15-unwrapped: error: unsupported option '-fzero-call-used-regs=used-gpr' for target 'arm64-apple-macosx10.9.0' - # > clang-15-unwrapped: error: argument unused during compilation: '-fstack-clash-protection' [-Werror,-Wunused-command-line-argument] - hardeningDisable = lib.optionals stdenv.hostPlatform.isAarch64 [ - "zerocallusedregs" - "stackclashprotection" - ]; - - configurePhase = '' - export SWIFT_SOURCE_ROOT="$PWD" - mkdir -p ../build - cd ../build - export SWIFT_BUILD_ROOT="$PWD" - ''; - - # These steps are derived from doing a normal build with. - # - # ./swift/utils/build-toolchain test --dry-run - # - # But dealing with the custom Python build system is far more trouble than - # simply invoking CMake directly. Few variables it passes to CMake are - # actually required or non-default. - # - # Using CMake directly also allows us to split up the already large build, - # and package Swift components separately. - # - # Besides `--dry-run`, another good way to compare build changes between - # Swift releases is to diff the scripts: - # - # git diff swift-5.6.3-RELEASE..swift-5.7-RELEASE -- utils/build* - # - buildPhase = '' - # Helper to build a subdirectory. - # - # Always reset cmakeFlags before calling this. The cmakeConfigurePhase - # amends flags and would otherwise keep expanding it. - function buildProject() { - mkdir -p $SWIFT_BUILD_ROOT/$1 - cd $SWIFT_BUILD_ROOT/$1 - - cmakeDir=$SWIFT_SOURCE_ROOT/''${2-$1} - cmakeConfigurePhase - - ninjaBuildPhase - } - - cmakeFlags="-GNinja" - buildProject swift-cmark - - ${lib.optionalString (clang.libcxx != null) '' - # Install the libc++ headers corresponding to the LLVM version of - # Swift’s Clang. - cmakeFlags=" - -GNinja - -DLLVM_ENABLE_RUNTIMES=libcxx;libcxxabi - -DLIBCXXABI_INSTALL_INCLUDE_DIR=$dev/include/c++/v1 - " - ninjaFlags="install-cxx-headers install-cxxabi-headers" - buildProject libcxx llvm-project/runtimes - unset ninjaFlags - ''} - - # Some notes: - # - The Swift build just needs Clang. - # - We can further reduce targets to just our targetPlatform. - cmakeFlags=" - -GNinja - -DLLVM_BUILD_TOOLS=NO - -DLLVM_ENABLE_PROJECTS=clang - -DLLVM_TARGETS_TO_BUILD=${ - { - "x86_64" = "X86"; - "aarch64" = "AArch64"; - } - .${targetPlatform.parsed.cpu.name} - or (throw "Unsupported CPU architecture: ${targetPlatform.parsed.cpu.name}") - } - " - buildProject llvm llvm-project/llvm - - # Ensure that the built Clang can find the runtime libraries by - # copying the symlinks from the main wrapper. - cp -P ${clang}/resource-root/{lib,share} $SWIFT_BUILD_ROOT/llvm/lib/clang/16.0.0/ - - '' - + lib.optionalString stdenv.hostPlatform.isDarwin '' - # Add appleSwiftCore to the search paths. Adding the whole SDK results in build failures. - OLD_NIX_SWIFTFLAGS_COMPILE="$NIX_SWIFTFLAGS_COMPILE" - OLD_NIX_LDFLAGS="$NIX_LDFLAGS" - OLD_NIX_CFLAGS_COMPILE="$NIX_CFLAGS_COMPILE" - export NIX_SWIFTFLAGS_COMPILE=" -I ${appleSwiftCore}/lib/swift" - export NIX_LDFLAGS+=" -L ${appleSwiftCore}/lib/swift" - export NIX_CFLAGS_COMPILE+=" -Wno-error=unguarded-availability" - '' - + '' - - # Some notes: - # - BOOTSTRAPPING_MODE defaults to OFF in CMake, but is enabled in standard - # builds, so we enable it as well. On Darwin, we have to use the system - # Swift libs because of ABI-stability, but this may be trouble if the - # builder is an older macOS. - # - Experimental features are OFF by default in CMake, but are enabled in - # official builds, so we do the same. (Concurrency is also required in - # the stdlib. StringProcessing is often implicitely imported, causing - # lots of warnings if missing.) - # - SWIFT_STDLIB_ENABLE_OBJC_INTEROP is set explicitely because its check - # is buggy. (Uses SWIFT_HOST_VARIANT_SDK before initialized.) - # Fixed in: https://github.com/apple/swift/commit/84083afef1de5931904d5c815d53856cdb3fb232 - cmakeFlags=" - -GNinja - -DBOOTSTRAPPING_MODE=BOOTSTRAPPING${lib.optionalString stdenv.hostPlatform.isDarwin "-WITH-HOSTLIBS"} - -DSWIFT_ENABLE_EXPERIMENTAL_DIFFERENTIABLE_PROGRAMMING=ON - -DSWIFT_ENABLE_EXPERIMENTAL_CONCURRENCY=ON - -DSWIFT_ENABLE_EXPERIMENTAL_CXX_INTEROP=ON - -DSWIFT_ENABLE_EXPERIMENTAL_DISTRIBUTED=ON - -DSWIFT_ENABLE_EXPERIMENTAL_STRING_PROCESSING=ON - -DSWIFT_ENABLE_BACKTRACING=ON - -DSWIFT_ENABLE_EXPERIMENTAL_OBSERVATION=ON - -DLLVM_DIR=$SWIFT_BUILD_ROOT/llvm/lib/cmake/llvm - -DClang_DIR=$SWIFT_BUILD_ROOT/llvm/lib/cmake/clang - -DSWIFT_PATH_TO_CMARK_SOURCE=$SWIFT_SOURCE_ROOT/swift-cmark - -DSWIFT_PATH_TO_CMARK_BUILD=$SWIFT_BUILD_ROOT/swift-cmark - -DSWIFT_PATH_TO_LIBDISPATCH_SOURCE=$SWIFT_SOURCE_ROOT/swift-corelibs-libdispatch - -DSWIFT_PATH_TO_SWIFT_SYNTAX_SOURCE=$SWIFT_SOURCE_ROOT/swift-syntax - -DSWIFT_PATH_TO_STRING_PROCESSING_SOURCE=$SWIFT_SOURCE_ROOT/swift-experimental-string-processing - -DSWIFT_INSTALL_COMPONENTS=${lib.concatStringsSep ";" swiftInstallComponents} - -DSWIFT_STDLIB_ENABLE_OBJC_INTEROP=${if stdenv.hostPlatform.isDarwin then "ON" else "OFF"} - -DSWIFT_DARWIN_DEPLOYMENT_VERSION_OSX=${deploymentVersion} - " - buildProject swift - - '' - + lib.optionalString stdenv.hostPlatform.isDarwin '' - # Restore search paths to remove appleSwiftCore. - export NIX_SWIFTFLAGS_COMPILE="$OLD_NIX_SWIFTFLAGS_COMPILE" - export NIX_LDFLAGS="$OLD_NIX_LDFLAGS" - export NIX_CFLAGS_COMPILE="$OLD_NIX_CFLAGS_COMPILE" - '' - + '' - - # These are based on flags in `utils/build-script-impl`. - # - # LLDB_USE_SYSTEM_DEBUGSERVER=ON disables the debugserver build on Darwin, - # which requires a special signature. - # - # CMAKE_BUILD_WITH_INSTALL_NAME_DIR ensures we don't use rpath on Darwin. - cmakeFlags=" - -GNinja - -DLLDB_SWIFTC=$SWIFT_BUILD_ROOT/swift/bin/swiftc - -DLLDB_SWIFT_LIBS=$SWIFT_BUILD_ROOT/swift/lib/swift - -DLLVM_DIR=$SWIFT_BUILD_ROOT/llvm/lib/cmake/llvm - -DClang_DIR=$SWIFT_BUILD_ROOT/llvm/lib/cmake/clang - -DSwift_DIR=$SWIFT_BUILD_ROOT/swift/lib/cmake/swift - -DLLDB_ENABLE_CURSES=ON - -DLLDB_ENABLE_LIBEDIT=ON - -DLLDB_ENABLE_PYTHON=ON - -DLLDB_ENABLE_LZMA=OFF - -DLLDB_ENABLE_LUA=OFF - -DLLDB_INCLUDE_TESTS=OFF - -DCMAKE_BUILD_WITH_INSTALL_NAME_DIR=ON - ${lib.optionalString stdenv.hostPlatform.isDarwin '' - -DLLDB_USE_SYSTEM_DEBUGSERVER=ON - ''} - -DLibEdit_INCLUDE_DIRS=${lib.getInclude libedit}/include - -DLibEdit_LIBRARIES=${lib.getLib libedit}/lib/libedit${stdenv.hostPlatform.extensions.sharedLibrary} - -DCURSES_INCLUDE_DIRS=${lib.getInclude ncurses}/include - -DCURSES_LIBRARIES=${lib.getLib ncurses}/lib/libncurses${stdenv.hostPlatform.extensions.sharedLibrary} - -DPANEL_LIBRARIES=${lib.getLib ncurses}/lib/libpanel${stdenv.hostPlatform.extensions.sharedLibrary} - "; - buildProject lldb llvm-project/lldb - - ${lib.optionalString stdenv.targetPlatform.isDarwin '' - # Need to do a standalone build of concurrency for Darwin back deployment. - # Based on: utils/swift_build_support/swift_build_support/products/backdeployconcurrency.py - cmakeFlags=" - -GNinja - -DCMAKE_Swift_COMPILER=$SWIFT_BUILD_ROOT/swift/bin/swiftc - -DSWIFT_PATH_TO_SWIFT_SYNTAX_SOURCE=$SWIFT_SOURCE_ROOT/swift-syntax - - -DTOOLCHAIN_DIR=/var/empty - -DSWIFT_NATIVE_LLVM_TOOLS_PATH=${stdenv.cc}/bin - -DSWIFT_NATIVE_CLANG_TOOLS_PATH=${stdenv.cc}/bin - -DSWIFT_NATIVE_SWIFT_TOOLS_PATH=$SWIFT_BUILD_ROOT/swift/bin - - -DCMAKE_CROSSCOMPILING=ON - - -DBUILD_SWIFT_CONCURRENCY_BACK_DEPLOYMENT_LIBRARIES=ON - -DSWIFT_INCLUDE_TOOLS=OFF - -DSWIFT_BUILD_STDLIB_EXTRA_TOOLCHAIN_CONTENT=OFF - -DSWIFT_BUILD_TEST_SUPPORT_MODULES=OFF - -DSWIFT_BUILD_STDLIB=OFF - -DSWIFT_BUILD_DYNAMIC_STDLIB=OFF - -DSWIFT_BUILD_STATIC_STDLIB=OFF - -DSWIFT_BUILD_REMOTE_MIRROR=OFF - -DSWIFT_BUILD_SDK_OVERLAY=OFF - -DSWIFT_BUILD_DYNAMIC_SDK_OVERLAY=OFF - -DSWIFT_BUILD_STATIC_SDK_OVERLAY=OFF - -DSWIFT_INCLUDE_TESTS=OFF - -DSWIFT_BUILD_PERF_TESTSUITE=OFF - - -DSWIFT_HOST_VARIANT_ARCH=${swiftArch} - -DBUILD_STANDALONE=ON - - -DSWIFT_INSTALL_COMPONENTS=back-deployment - - -DSWIFT_SDKS=${ - { - "macos" = "OSX"; - "ios" = "IOS"; - #IOS_SIMULATOR - #TVOS - #TVOS_SIMULATOR - #WATCHOS - #WATCHOS_SIMULATOR - } - .${targetPlatform.darwinPlatform} - } - - -DLLVM_DIR=$SWIFT_BUILD_ROOT/llvm/lib/cmake/llvm - - -DSWIFT_DEST_ROOT=$out - -DSWIFT_HOST_VARIANT_SDK=OSX - - -DSWIFT_DARWIN_DEPLOYMENT_VERSION_OSX=${deploymentVersion} - -DSWIFT_DARWIN_DEPLOYMENT_VERSION_IOS=13.0 - -DSWIFT_DARWIN_DEPLOYMENT_VERSION_MACCATALYST=13.0 - -DSWIFT_DARWIN_DEPLOYMENT_VERSION_TVOS=13.0 - -DSWIFT_DARWIN_DEPLOYMENT_VERSION_WATCHOS=6.0 - " - - # This depends on the special Clang build specific to the Swift branch. - # We also need to call a specific Ninja target. - export CC=$SWIFT_BUILD_ROOT/llvm/bin/clang - export CXX=$SWIFT_BUILD_ROOT/llvm/bin/clang++ - ninjaFlags="back-deployment" - - buildProject swift-concurrency-backdeploy swift - - export CC=$NIX_CC/bin/clang - export CXX=$NIX_CC/bin/clang++ - unset ninjaFlags - ''} - ''; - - # TODO: ~50 failing tests on x86_64-linux. Other platforms not checked. - doCheck = false; - nativeCheckInputs = [ file ]; - # TODO: consider using stress-tester and integration-test. - checkPhase = '' - cd $SWIFT_BUILD_ROOT/swift - checkTarget=check-swift-all - ninjaCheckPhase - unset checkTarget - ''; - - installPhase = '' - # Undo the clang and swift wrapping we did for the build. - # (This happened via patches to cmake files.) - cd $SWIFT_BUILD_ROOT - mv llvm/bin/clang-16{-unwrapped,} - mv swift/bin/swift-frontend{-unwrapped,} - - mkdir $lib - - # Install clang binaries only. We hide these with the wrapper, so they are - # for private use by Swift only. - cd $SWIFT_BUILD_ROOT/llvm - installTargets=install-clang - ninjaInstallPhase - unset installTargets - - # LLDB is also a private install. - cd $SWIFT_BUILD_ROOT/lldb - ninjaInstallPhase - - cd $SWIFT_BUILD_ROOT/swift - ninjaInstallPhase - - ${lib.optionalString stdenv.hostPlatform.isDarwin '' - cd $SWIFT_BUILD_ROOT/swift-concurrency-backdeploy - installTargets=install-back-deployment - ninjaInstallPhase - unset installTargets - ''} - - # Separate $lib output here, because specific logic follows. - # Only move the dynamic run-time parts, to keep $lib small. Every Swift - # build will depend on it. - moveToOutput "lib/swift" "$lib" - moveToOutput "lib/libswiftDemangle.*" "$lib" - - # This link is here because various tools (swiftpm) check for stdlib - # relative to the swift compiler. It's fine if this is for build-time - # stuff, but we should patch all cases were it would end up in an output. - ln -s $lib/lib/swift $out/lib/swift - - # Swift has a separate resource root from Clang, but locates the Clang - # resource root via subdir or symlink. - mv $SWIFT_BUILD_ROOT/llvm/lib/clang/16.0.0 $lib/lib/swift/clang - ''; - - preFixup = lib.optionalString stdenv.hostPlatform.isLinux '' - # This is cheesy, but helps the patchelf hook remove /build from RPATH. - cd $SWIFT_BUILD_ROOT/.. - mv build buildx - ''; - - postFixup = lib.optionalString stdenv.hostPlatform.isDarwin '' - # These libraries need to use the system install name. The official SDK - # does the same (as opposed to using rpath). Presumably, they are part of - # the stable ABI. Not using the system libraries at run-time is known to - # cause ObjC class conflicts and segfaults. - declare -A systemLibs=( - [libswiftCore.dylib]=1 - [libswiftDarwin.dylib]=1 - [libswiftSwiftOnoneSupport.dylib]=1 - [libswift_Concurrency.dylib]=1 - ) - - for systemLib in "''${!systemLibs[@]}"; do - install_name_tool -id /usr/lib/swift/$systemLib $lib/${swiftLibSubdir}/$systemLib - done - - for file in $out/bin/swift-frontend $lib/${swiftLibSubdir}/*.dylib; do - changeArgs="" - for dylib in $(otool -L $file | awk '{ print $1 }'); do - if [[ ''${systemLibs["$(basename $dylib)"]} ]]; then - changeArgs+=" -change $dylib /usr/lib/swift/$(basename $dylib)" - elif [[ "$dylib" = */bootstrapping1/* ]]; then - changeArgs+=" -change $dylib $lib/lib/swift/$(basename $dylib)" - fi - done - if [[ -n "$changeArgs" ]]; then - install_name_tool $changeArgs $file - fi - done - - wrapProgram $out/bin/swift-frontend \ - --prefix PATH : ${lib.makeBinPath [ cctools.libtool ]} - - # Needs to be propagated by the compiler not by its dev output. - moveToOutput nix-support/propagated-target-target-deps "$out" - ''; - - passthru = { - inherit - swiftOs - swiftArch - swiftModuleSubdir - swiftLibSubdir - swiftStaticModuleSubdir - swiftStaticLibSubdir - ; - - tests = { - cxx-interop-test = callPackage ../cxx-interop-test { }; - }; - - # Internal attr for the wrapper. - _wrapperParams = wrapperParams; - }; - - meta = { - description = "Swift Programming Language"; - homepage = "https://github.com/apple/swift"; - teams = [ lib.teams.swift ]; - license = lib.licenses.asl20; - platforms = [ - "x86_64-linux" - "aarch64-linux" - "x86_64-darwin" - "aarch64-darwin" - ]; - # Swift doesn't support 32-bit Linux, unknown on other platforms. - badPlatforms = lib.platforms.i686; - timeout = 86400; # 24 hours. - }; -} diff --git a/pkgs/development/compilers/swift/compiler/patches/clang-purity.patch b/pkgs/development/compilers/swift/compiler/patches/clang-purity.patch deleted file mode 100644 index dcb7771008d9..000000000000 --- a/pkgs/development/compilers/swift/compiler/patches/clang-purity.patch +++ /dev/null @@ -1,21 +0,0 @@ -From 4add81bba40dcec62c4ea4481be8e35ac53e89d8 Mon Sep 17 00:00:00 2001 -From: Will Dietz -Date: Thu, 18 May 2017 11:56:12 -0500 -Subject: [PATCH] "purity" patch for 5.0 - ---- clang/lib/Driver/ToolChains/Gnu.cpp -+++ clang/lib/Driver/ToolChains/Gnu.cpp -@@ -480,13 +480,6 @@ - } else { - if (Args.hasArg(options::OPT_rdynamic)) - CmdArgs.push_back("-export-dynamic"); -- -- if (!Args.hasArg(options::OPT_shared) && !IsStaticPIE && -- !Args.hasArg(options::OPT_r)) { -- CmdArgs.push_back("-dynamic-linker"); -- CmdArgs.push_back(Args.MakeArgString(Twine(D.DyldPrefix) + -- ToolChain.getDynamicLinker(Args))); -- } - } - - CmdArgs.push_back("-o"); diff --git a/pkgs/development/compilers/swift/compiler/patches/clang-toolchain-dir.patch b/pkgs/development/compilers/swift/compiler/patches/clang-toolchain-dir.patch deleted file mode 100644 index 40d7728cf788..000000000000 --- a/pkgs/development/compilers/swift/compiler/patches/clang-toolchain-dir.patch +++ /dev/null @@ -1,13 +0,0 @@ -Use the Nix include dirs and gcc runtime dir, when no sysroot is configured. - ---- a/lib/Driver/ToolChains/Linux.cpp -+++ b/lib/Driver/ToolChains/Linux.cpp -@@ -574,7 +574,7 @@ - - // Check for configure-time C include directories. - StringRef CIncludeDirs(C_INCLUDE_DIRS); -- if (CIncludeDirs != "") { -+ if (CIncludeDirs != "" && (SysRoot.empty() || SysRoot == "/")) { - SmallVector dirs; - CIncludeDirs.split(dirs, ":"); - for (StringRef dir : dirs) { diff --git a/pkgs/development/compilers/swift/compiler/patches/clang-wrap.patch b/pkgs/development/compilers/swift/compiler/patches/clang-wrap.patch deleted file mode 100644 index 9c6cafed3699..000000000000 --- a/pkgs/development/compilers/swift/compiler/patches/clang-wrap.patch +++ /dev/null @@ -1,18 +0,0 @@ -Wrap the clang produced during the build - ---- a/tools/driver/CMakeLists.txt -+++ b/tools/driver/CMakeLists.txt -@@ -59,6 +59,13 @@ endif() - - add_dependencies(clang clang-resource-headers) - -+# Nix: wrap the clang build. -+add_custom_command( -+ TARGET clang POST_BUILD -+ COMMAND nix-swift-make-clang-wrapper $ -+ VERBATIM -+) -+ - if(NOT CLANG_LINKS_TO_CREATE) - set(CLANG_LINKS_TO_CREATE clang++ clang-cl clang-cpp) - endif() diff --git a/pkgs/development/compilers/swift/compiler/patches/llvm-fix-X86MCTargetDesc-compile-error.patch b/pkgs/development/compilers/swift/compiler/patches/llvm-fix-X86MCTargetDesc-compile-error.patch deleted file mode 100644 index 3ced4d2c32b8..000000000000 --- a/pkgs/development/compilers/swift/compiler/patches/llvm-fix-X86MCTargetDesc-compile-error.patch +++ /dev/null @@ -1,34 +0,0 @@ -From f03ab75680385b1ea62af3ab15c423a3bc0f3588 Mon Sep 17 00:00:00 2001 -From: Stephan Hageboeck -Date: Mon, 20 Jan 2025 17:52:47 +0100 -Subject: [PATCH] Add missing include to X86MCTargetDesc.h (#123320) - -In gcc-15, explicit includes of `` are required when fixed-size -integers are used. In this file, this include only happened as a side -effect of including SmallVector.h - -Although llvm compiles fine, the root-project would benefit from -explicitly including it here, so we can backport the patch. - -Maybe interesting for @hahnjo and @vgvassilev - -(cherry picked from commit 7abf44069aec61eee147ca67a6333fc34583b524) ---- - llvm/lib/Target/X86/MCTargetDesc/X86MCTargetDesc.h | 1 + - 1 file changed, 1 insertion(+) - -diff --git a/llvm/lib/Target/X86/MCTargetDesc/X86MCTargetDesc.h b/llvm/lib/Target/X86/MCTargetDesc/X86MCTargetDesc.h -index d0530bd4d650..10b59462aebe 100644 ---- a/llvm/lib/Target/X86/MCTargetDesc/X86MCTargetDesc.h -+++ b/llvm/lib/Target/X86/MCTargetDesc/X86MCTargetDesc.h -@@ -13,6 +13,7 @@ - #ifndef LLVM_LIB_TARGET_X86_MCTARGETDESC_X86MCTARGETDESC_H - #define LLVM_LIB_TARGET_X86_MCTARGETDESC_X86MCTARGETDESC_H - -+#include - #include - #include - --- -2.52.0 - diff --git a/pkgs/development/compilers/swift/compiler/patches/llvm-module-cache.patch b/pkgs/development/compilers/swift/compiler/patches/llvm-module-cache.patch deleted file mode 100644 index 9a22d0482ea5..000000000000 --- a/pkgs/development/compilers/swift/compiler/patches/llvm-module-cache.patch +++ /dev/null @@ -1,30 +0,0 @@ -The compiler fails if LLVM modules are enabled and it cannot write its module -cache. This patch detects and rejects the fake, non-existant $HOME used in Nix -builds. - -We could simply return false in `cache_directory`, but that completely disables -module caching, and may unnecessarily slow down builds. Instead, let it use -'/tmp/.cache'. - ---- a/lib/Support/Unix/Path.inc -+++ b/lib/Support/Unix/Path.inc -@@ -1380,6 +1380,9 @@ bool user_config_directory(SmallVectorImpl &result) { - if (!home_directory(result)) { - return false; - } -+ if (std::equal(result.begin(), result.end(), "/homeless-shelter")) { -+ return false; -+ } - append(result, ".config"); - return true; - } -@@ -1401,6 +1404,9 @@ bool cache_directory(SmallVectorImpl &result) { - if (!home_directory(result)) { - return false; - } -+ if (std::equal(result.begin(), result.end(), "/homeless-shelter")) { -+ system_temp_directory(true/*ErasedOnReboot*/, result); -+ } - append(result, ".cache"); - return true; - } diff --git a/pkgs/development/compilers/swift/compiler/patches/swift-Frontend-Fix-a-small-unique_ptr-array-access.patch b/pkgs/development/compilers/swift/compiler/patches/swift-Frontend-Fix-a-small-unique_ptr-array-access.patch deleted file mode 100644 index 0059c7f7c9ee..000000000000 --- a/pkgs/development/compilers/swift/compiler/patches/swift-Frontend-Fix-a-small-unique_ptr-array-access.patch +++ /dev/null @@ -1,35 +0,0 @@ -From 1a2293c7593e4eeb3fbad74fa8d362abafb43b56 Mon Sep 17 00:00:00 2001 -From: Tony Allevato -Date: Wed, 9 Oct 2024 13:54:43 -0400 -Subject: [PATCH] [Frontend] Fix a small `unique_ptr` array access. - -When the size of the array accessed here is zero, retrieving the -address of the zero-th element here is undefined. When the frontend -is linked against a libc++ that has the `unique_ptr` hardening in -[this commit](https://github.com/llvm/llvm-project/commit/18df9d23ea390eaa50b41f3083a42f700a2b0e39) -enabled, it traps here. - -Instead, simply call `.get()` to retrieve the address of the -array, which works even when it is a zero-byte allocation. - -(cherry picked from commit bdf40184ab40eb59642cd825781d71d0711493eb) ---- - lib/FrontendTool/FrontendTool.cpp | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/lib/FrontendTool/FrontendTool.cpp b/lib/FrontendTool/FrontendTool.cpp -index afbc57cdf2f..ba64a306494 100644 ---- a/lib/FrontendTool/FrontendTool.cpp -+++ b/lib/FrontendTool/FrontendTool.cpp -@@ -2202,7 +2202,7 @@ int swift::performFrontend(ArrayRef Args, - std::make_unique[]>( - configurationFileBuffers.size()); - for_each(configurationFileBuffers.begin(), configurationFileBuffers.end(), -- &configurationFileStackTraces[0], -+ configurationFileStackTraces.get(), - [](const std::unique_ptr &buffer, - llvm::Optional &trace) { - trace.emplace(*buffer); --- -2.52.0 - diff --git a/pkgs/development/compilers/swift/compiler/patches/swift-darwin-plistbuddy-workaround.patch b/pkgs/development/compilers/swift/compiler/patches/swift-darwin-plistbuddy-workaround.patch deleted file mode 100644 index a3cf4f60675c..000000000000 --- a/pkgs/development/compilers/swift/compiler/patches/swift-darwin-plistbuddy-workaround.patch +++ /dev/null @@ -1,17 +0,0 @@ -CMake tries to read a list field from SDKSettings.plist, but the output of -facebook/xcbuild PlistBuddy is incompatible with Apple's. - -Simply set the supported architectures to the one target architecture we're -building for. - ---- a/cmake/modules/SwiftConfigureSDK.cmake -+++ b/cmake/modules/SwiftConfigureSDK.cmake -@@ -189,7 +189,7 @@ macro(configure_sdk_darwin - endif() - - # Remove any architectures not supported by the SDK. -- remove_sdk_unsupported_archs(${name} ${xcrun_name} ${SWIFT_SDK_${prefix}_PATH} SWIFT_SDK_${prefix}_ARCHITECTURES) -+ set(SWIFT_SDK_${prefix}_ARCHITECTURES "@swiftArch@") - - list_intersect( - "${SWIFT_DARWIN_MODULE_ARCHS}" # lhs diff --git a/pkgs/development/compilers/swift/compiler/patches/swift-linux-fix-libc-paths.patch b/pkgs/development/compilers/swift/compiler/patches/swift-linux-fix-libc-paths.patch deleted file mode 100644 index 61915c66f503..000000000000 --- a/pkgs/development/compilers/swift/compiler/patches/swift-linux-fix-libc-paths.patch +++ /dev/null @@ -1,48 +0,0 @@ -This code injects an LLVM modulemap for glibc and libstdc++ by overriding -specific VFS paths. In order to do that, it needs to know the actual locations -of glibc and libstdc++, but it only searches `-sysroot` and fails. Here we -patch it to also consider `-idirafter` and `-isystem` as added by cc-wrapper. - ---- a/lib/ClangImporter/ClangIncludePaths.cpp -+++ b/lib/ClangImporter/ClangIncludePaths.cpp -@@ -142,6 +142,7 @@ - /// \return a path without dots (`../`, './'). - static llvm::Optional findFirstIncludeDir( - const llvm::opt::InputArgList &args, -+ const llvm::opt::ArgList &DriverArgs, - const ArrayRef expectedFileNames, - const llvm::IntrusiveRefCntPtr &vfs) { - // C++ stdlib paths are added as `-internal-isystem`. -@@ -151,6 +152,14 @@ - llvm::append_range(includeDirs, - args.getAllArgValues( - clang::driver::options::OPT_internal_externc_isystem)); -+ // Nix adds the C stdlib include path using `-idirafter`. -+ llvm::append_range(includeDirs, -+ DriverArgs.getAllArgValues( -+ clang::driver::options::OPT_idirafter)); -+ // Nix adds the C++ stdlib include path using `-cxx-isystem`. -+ llvm::append_range(includeDirs, -+ DriverArgs.getAllArgValues( -+ clang::driver::options::OPT_cxx_isystem)); - - for (const auto &includeDir : includeDirs) { - Path dir(includeDir); -@@ -218,7 +227,7 @@ - // modulemap are present. - Path glibcDir; - if (auto dir = findFirstIncludeDir( -- parsedIncludeArgs, {"inttypes.h", "unistd.h", "stdint.h"}, vfs)) { -+ parsedIncludeArgs, clangDriverArgs, {"inttypes.h", "unistd.h", "stdint.h"}, vfs)) { - glibcDir = dir.value(); - } else { - ctx.Diags.diagnose(SourceLoc(), diag::glibc_not_found, triple.str()); -@@ -276,7 +285,7 @@ - auto parsedStdlibArgs = parseClangDriverArgs(clangDriver, stdlibArgStrings); - - Path cxxStdlibDir; -- if (auto dir = findFirstIncludeDir(parsedStdlibArgs, -+ if (auto dir = findFirstIncludeDir(parsedStdlibArgs, clangDriverArgs, - {"cstdlib", "string", "vector"}, vfs)) { - cxxStdlibDir = dir.value(); - } else { diff --git a/pkgs/development/compilers/swift/compiler/patches/swift-linux-fix-linking.patch b/pkgs/development/compilers/swift/compiler/patches/swift-linux-fix-linking.patch deleted file mode 100644 index c10b4038a9c4..000000000000 --- a/pkgs/development/compilers/swift/compiler/patches/swift-linux-fix-linking.patch +++ /dev/null @@ -1,17 +0,0 @@ -diff --git a/lib/Driver/ToolChains.cpp b/lib/Driver/ToolChains.cpp -index c0ee9217e8..bf7737d6fa 100644 ---- a/lib/Driver/ToolChains.cpp -+++ b/lib/Driver/ToolChains.cpp -@@ -1489,6 +1489,12 @@ - LinkerDriver = Args.MakeArgString(tool.get()); - } - -+ // For Nix, prefer linking using the wrapped Nixpkgs clang, instead of using -+ // the unwrapped clang packaged with swift. The latter is unable to link, but -+ // we still want to use it for other purposes (clang importer). -+ if (auto tool = llvm::sys::findProgramByName(LinkerDriver, {"@clang@/bin"})) -+ return Args.MakeArgString(tool.get()); -+ - return LinkerDriver; - } - diff --git a/pkgs/development/compilers/swift/compiler/patches/swift-prevent-sdk-dirs-warning.patch b/pkgs/development/compilers/swift/compiler/patches/swift-prevent-sdk-dirs-warning.patch deleted file mode 100644 index 987b99d74539..000000000000 --- a/pkgs/development/compilers/swift/compiler/patches/swift-prevent-sdk-dirs-warning.patch +++ /dev/null @@ -1,39 +0,0 @@ -Prevents a user-visible warning on every compilation: - - ld: warning: directory not found for option '-L.../MacOSX11.0.sdk/usr/lib/swift' - ---- a/lib/Driver/ToolChains.cpp -+++ b/lib/Driver/ToolChains.cpp -@@ -1455,9 +1455,11 @@ void ToolChain::getRuntimeLibraryPaths(SmallVectorImpl &runtimeLibP - runtimeLibPaths.push_back(std::string(scratchPath.str())); - } - -+ if (!SDKPath.startswith("@storeDir@")) { - scratchPath = SDKPath; - llvm::sys::path::append(scratchPath, "usr", "lib", "swift"); - runtimeLibPaths.push_back(std::string(scratchPath.str())); -+ } - } - } - ---- a/lib/Frontend/CompilerInvocation.cpp -+++ b/lib/Frontend/CompilerInvocation.cpp -@@ -185,7 +185,9 @@ static void updateRuntimeLibraryPaths(SearchPathOptions &SearchPathOpts, - RuntimeLibraryImportPaths.push_back(std::string(LibPath.str())); - } - -- LibPath = SearchPathOpts.getSDKPath(); -+ auto SDKPath = SearchPathOpts.getSDKPath(); -+ if (!SDKPath.startswith("@storeDir@")) { -+ LibPath = SDKPath; - llvm::sys::path::append(LibPath, "usr", "lib", "swift"); - if (!Triple.isOSDarwin()) { - // Use the non-architecture suffixed form with directory-layout -@@ -200,6 +202,7 @@ static void updateRuntimeLibraryPaths(SearchPathOptions &SearchPathOpts, - llvm::sys::path::append(LibPath, swift::getMajorArchitectureName(Triple)); - } - RuntimeLibraryImportPaths.push_back(std::string(LibPath.str())); -+ } - } - SearchPathOpts.setRuntimeLibraryImportPaths(RuntimeLibraryImportPaths); - } diff --git a/pkgs/development/compilers/swift/compiler/patches/swift-separate-lib.patch b/pkgs/development/compilers/swift/compiler/patches/swift-separate-lib.patch deleted file mode 100644 index 20d81a6e8296..000000000000 --- a/pkgs/development/compilers/swift/compiler/patches/swift-separate-lib.patch +++ /dev/null @@ -1,26 +0,0 @@ -Patch paths to use the separate 'lib' output. One of the things this patch -fixes is the output of `swift -frontend -print-target-info`, which swiftpm uses -to set rpath on Linux. - -The check if the executable path starts with 'out' is necessary for -bootstrapping, or the compiler will fail when run from the build directory. - ---- a/lib/Frontend/CompilerInvocation.cpp -+++ b/lib/Frontend/CompilerInvocation.cpp -@@ -49,11 +49,16 @@ swift::CompilerInvocation::CompilerInvocation() { - void CompilerInvocation::computeRuntimeResourcePathFromExecutablePath( - StringRef mainExecutablePath, bool shared, - llvm::SmallVectorImpl &runtimeResourcePath) { -+ if (mainExecutablePath.startswith("@storeDir@")) { -+ auto libPath = StringRef("@lib@"); -+ runtimeResourcePath.append(libPath.begin(), libPath.end()); -+ } else { - runtimeResourcePath.append(mainExecutablePath.begin(), - mainExecutablePath.end()); - - llvm::sys::path::remove_filename(runtimeResourcePath); // Remove /swift - llvm::sys::path::remove_filename(runtimeResourcePath); // Remove /bin -+ } - appendSwiftLibDir(runtimeResourcePath, shared); - } - diff --git a/pkgs/development/compilers/swift/compiler/patches/swift-wrap.patch b/pkgs/development/compilers/swift/compiler/patches/swift-wrap.patch deleted file mode 100644 index e4697f631e70..000000000000 --- a/pkgs/development/compilers/swift/compiler/patches/swift-wrap.patch +++ /dev/null @@ -1,46 +0,0 @@ -Wrap the swift compiler produced during the build - ---- a/tools/driver/CMakeLists.txt -+++ b/tools/driver/CMakeLists.txt -@@ -16,6 +16,13 @@ if(${LIBSWIFT_BUILD_MODE} MATCHES "BOOTSTRAPPING.*") - swiftDriverTool - libswiftStub) - -+ # Nix: wrap the swift build. -+ add_custom_command( -+ TARGET swift-frontend-bootstrapping0 POST_BUILD -+ COMMAND nix-swift-make-swift-wrapper $ -+ VERBATIM -+ ) -+ - swift_create_post_build_symlink(swift-frontend-bootstrapping0 - SOURCE "swift-frontend${CMAKE_EXECUTABLE_SUFFIX}" - DESTINATION "swiftc${CMAKE_EXECUTABLE_SUFFIX}" -@@ -34,6 +41,13 @@ if(${LIBSWIFT_BUILD_MODE} MATCHES "BOOTSTRAPPING.*") - swiftDriverTool - libswift-bootstrapping1) - -+ # Nix: wrap the swift build. -+ add_custom_command( -+ TARGET swift-frontend-bootstrapping1 POST_BUILD -+ COMMAND nix-swift-make-swift-wrapper $ -+ VERBATIM -+ ) -+ - swift_create_post_build_symlink(swift-frontend-bootstrapping1 - SOURCE "swift-frontend${CMAKE_EXECUTABLE_SUFFIX}" - DESTINATION "swiftc${CMAKE_EXECUTABLE_SUFFIX}" -@@ -50,6 +64,13 @@ target_link_libraries(swift-frontend - swiftDriverTool - libswift) - -+# Nix: wrap the swift build. -+add_custom_command( -+ TARGET swift-frontend POST_BUILD -+ COMMAND nix-swift-make-swift-wrapper $ -+ VERBATIM -+) -+ - # Create a `swift-driver` executable adjacent to the `swift-frontend` executable - # to ensure that `swiftc` forwards to the standalone driver when invoked. - swift_create_early_driver_copies(swift-frontend) diff --git a/pkgs/development/compilers/swift/cxx-interop-test/default.nix b/pkgs/development/compilers/swift/cxx-interop-test/default.nix deleted file mode 100644 index 12640750d622..000000000000 --- a/pkgs/development/compilers/swift/cxx-interop-test/default.nix +++ /dev/null @@ -1,57 +0,0 @@ -{ - lib, - stdenv, - swift, - swiftpm, - swiftPackages, -}: - -swiftPackages.stdenv.mkDerivation (finalAttrs: { - name = "swift-cxx-interop-test"; - - src = ./src; - - nativeBuildInputs = [ - swift - swiftpm - ]; - - installPhase = '' - runHook preInstall - - binPath="$(swiftpmBinPath)" - mkdir -p -- "$out/bin" - cp -- "$binPath/${finalAttrs.meta.mainProgram}" "$out/bin" - - runHook postInstall - ''; - - installCheckPhase = '' - runHook preInstallCheck - - "$out/bin/${finalAttrs.meta.mainProgram}" | grep 'Hello, world!' - - runHook postInstallCheck - ''; - - doInstallCheck = true; - - env = { - # Gross hack copied from `protoc-gen-swift` :( - LD_LIBRARY_PATH = lib.optionalString stdenv.hostPlatform.isLinux ( - lib.makeLibraryPath [ - swiftPackages.Dispatch - ] - ); - }; - - meta = { - inherit (swift.meta) - team - platforms - badPlatforms - ; - license = lib.licenses.mit; - mainProgram = "CxxInteropTest"; - }; -}) diff --git a/pkgs/development/compilers/swift/cxx-interop-test/src/.gitignore b/pkgs/development/compilers/swift/cxx-interop-test/src/.gitignore deleted file mode 100644 index 3b29812086f2..000000000000 --- a/pkgs/development/compilers/swift/cxx-interop-test/src/.gitignore +++ /dev/null @@ -1,9 +0,0 @@ -.DS_Store -/.build -/Packages -/*.xcodeproj -xcuserdata/ -DerivedData/ -.swiftpm/config/registries.json -.swiftpm/xcode/package.xcworkspace/contents.xcworkspacedata -.netrc diff --git a/pkgs/development/compilers/swift/cxx-interop-test/src/Package.swift b/pkgs/development/compilers/swift/cxx-interop-test/src/Package.swift deleted file mode 100644 index 4c664f22c467..000000000000 --- a/pkgs/development/compilers/swift/cxx-interop-test/src/Package.swift +++ /dev/null @@ -1,16 +0,0 @@ -// swift-tools-version: 5.10 - -import PackageDescription - -let package = Package( - name: "CxxInteropTest", - targets: [ - .executableTarget( - name: "CxxInteropTest", - path: "Sources", - swiftSettings: [ - .interoperabilityMode(.Cxx) - ] - ) - ] -) diff --git a/pkgs/development/compilers/swift/cxx-interop-test/src/Sources/main.swift b/pkgs/development/compilers/swift/cxx-interop-test/src/Sources/main.swift deleted file mode 100644 index abe1c879beba..000000000000 --- a/pkgs/development/compilers/swift/cxx-interop-test/src/Sources/main.swift +++ /dev/null @@ -1,3 +0,0 @@ -import CxxStdlib - -print(String(std.string("Hello, world!"))) diff --git a/pkgs/development/compilers/swift/default.nix b/pkgs/development/compilers/swift/default.nix deleted file mode 100644 index ad4fe81c46cb..000000000000 --- a/pkgs/development/compilers/swift/default.nix +++ /dev/null @@ -1,85 +0,0 @@ -{ - lib, - newScope, - stdenv, - llvmPackages, - darwin, -}: - -let - self = rec { - - callPackage = newScope self; - - # Provided for backwards compatibility. - inherit stdenv; - - swift-unwrapped = callPackage ./compiler { - inherit (llvmPackages) stdenv; - inherit (darwin) DarwinTools sigtool; - }; - - swiftNoSwiftDriver = callPackage ./wrapper { - swift = swift-unwrapped; - useSwiftDriver = false; - }; - - Dispatch = - if stdenv.hostPlatform.isDarwin then - null # part of apple-sdk - else - callPackage ./libdispatch { - inherit (llvmPackages) stdenv; - swift = swiftNoSwiftDriver; - }; - - Foundation = - if stdenv.hostPlatform.isDarwin then - null # part of apple-sdk - else - callPackage ./foundation { - inherit (llvmPackages) stdenv; - swift = swiftNoSwiftDriver; - }; - - # TODO: Apple distributes a binary XCTest with Xcode, but it is not part of - # CLTools (or SUS), so would have to figure out how to fetch it. The binary - # version has several extra features, like a test runner and ObjC support. - XCTest = callPackage ./xctest { - inherit (darwin) DarwinTools; - swift = swiftNoSwiftDriver; - }; - - swiftpm = callPackage ./swiftpm { - inherit (llvmPackages) stdenv; - inherit (darwin) DarwinTools; - swift = swiftNoSwiftDriver; - }; - - swift-driver = callPackage ./swift-driver { - inherit (llvmPackages) stdenv; - swift = swiftNoSwiftDriver; - }; - - swift = callPackage ./wrapper { - swift = swift-unwrapped; - }; - - sourcekit-lsp = callPackage ./sourcekit-lsp { - inherit (llvmPackages) stdenv; - }; - - swift-docc = callPackage ./swift-docc { - inherit (llvmPackages) stdenv; - }; - - swift-format = callPackage ./swift-format { - inherit (llvmPackages) stdenv; - }; - - swiftpm2nix = callPackage ./swiftpm2nix { }; - - }; - -in -self diff --git a/pkgs/development/compilers/swift/foundation/default.nix b/pkgs/development/compilers/swift/foundation/default.nix deleted file mode 100644 index 60d781ed7746..000000000000 --- a/pkgs/development/compilers/swift/foundation/default.nix +++ /dev/null @@ -1,71 +0,0 @@ -{ - lib, - stdenv, - fetchpatch, - callPackage, - cmake, - ninja, - swift, - Dispatch, - icu, - libxml2, - curl, -}: - -let - sources = callPackage ../sources.nix { }; -in -stdenv.mkDerivation { - pname = "swift-corelibs-foundation"; - - inherit (sources) version; - src = sources.swift-corelibs-foundation; - - outputs = [ - "out" - "dev" - ]; - - nativeBuildInputs = [ - cmake - ninja - swift - ]; - buildInputs = [ - icu - libxml2 - curl - ]; - propagatedBuildInputs = [ Dispatch ]; - - preConfigure = '' - # Fails to build with -D_FORTIFY_SOURCE. - NIX_HARDENING_ENABLE=''${NIX_HARDENING_ENABLE/fortify/} - ''; - - postInstall = '' - # Split up the output. - mkdir $dev - mv $out/lib/swift/${swift.swiftOs} $out/swiftlibs - mv $out/lib/swift $dev/include - mkdir $out/lib/swift - mv $out/swiftlibs $out/lib/swift/${swift.swiftOs} - - # Provide a CMake module. This is primarily used to glue together parts of - # the Swift toolchain. Modifying the CMake config to do this for us is - # otherwise more trouble. - mkdir -p $dev/lib/cmake/Foundation - export dylibExt="${stdenv.hostPlatform.extensions.sharedLibrary}" - export swiftOs="${swift.swiftOs}" - substituteAll ${./glue.cmake} $dev/lib/cmake/Foundation/FoundationConfig.cmake - ''; - - meta = { - description = "Core utilities, internationalization, and OS independence for Swift"; - mainProgram = "plutil"; - homepage = "https://github.com/apple/swift-corelibs-foundation"; - platforms = lib.platforms.linux; - license = lib.licenses.asl20; - teams = [ lib.teams.swift ]; - }; -} diff --git a/pkgs/development/compilers/swift/foundation/glue.cmake b/pkgs/development/compilers/swift/foundation/glue.cmake deleted file mode 100644 index a34984d19f04..000000000000 --- a/pkgs/development/compilers/swift/foundation/glue.cmake +++ /dev/null @@ -1,8 +0,0 @@ -add_library(Foundation SHARED IMPORTED) -set_property(TARGET Foundation PROPERTY IMPORTED_LOCATION "@out@/lib/swift/@swiftOs@/libFoundation@dylibExt@") - -add_library(FoundationNetworking SHARED IMPORTED) -set_property(TARGET FoundationNetworking PROPERTY IMPORTED_LOCATION "@out@/lib/swift/@swiftOs@/libFoundationNetworking@dylibExt@") - -add_library(FoundationXML SHARED IMPORTED) -set_property(TARGET FoundationXML PROPERTY IMPORTED_LOCATION "@out@/lib/swift/@swiftOs@/libFoundationXML@dylibExt@") diff --git a/pkgs/development/compilers/swift/libdispatch/default.nix b/pkgs/development/compilers/swift/libdispatch/default.nix deleted file mode 100644 index 3c99720ef75c..000000000000 --- a/pkgs/development/compilers/swift/libdispatch/default.nix +++ /dev/null @@ -1,68 +0,0 @@ -{ - lib, - stdenv, - callPackage, - fetchpatch, - cmake, - ninja, - useSwift ? true, - swift, -}: - -let - sources = callPackage ../sources.nix { }; -in -stdenv.mkDerivation { - pname = "swift-corelibs-libdispatch"; - - inherit (sources) version; - src = sources.swift-corelibs-libdispatch; - - outputs = [ - "out" - "dev" - "man" - ]; - - nativeBuildInputs = [ - cmake - ] - ++ lib.optionals useSwift [ - ninja - swift - ]; - - patches = [ - # Fix the build with modern Clang. - (fetchpatch { - url = "https://github.com/swiftlang/swift-corelibs-libdispatch/commit/30bb8019ba79cdae0eb1dc0c967c17996dd5cc0a.patch"; - hash = "sha256-wPZQ4wtEWk8HaKMfzjamlU6p/IW5EFiTssY63rGM+ZA="; - }) - (fetchpatch { - url = "https://github.com/swiftlang/swift-corelibs-libdispatch/commit/38872e2d44d66d2fb94186988509defc734888a5.patch"; - hash = "sha256-GABwDeTjciV36Sa0FS10mCfFCqRoBBstgW/OiKdPahA="; - }) - - ./disable-swift-overlay.patch - ]; - - cmakeFlags = lib.optional useSwift "-DENABLE_SWIFT=ON"; - - postInstall = '' - # Provide a CMake module. This is primarily used to glue together parts of - # the Swift toolchain. Modifying the CMake config to do this for us is - # otherwise more trouble. - mkdir -p $dev/lib/cmake/dispatch - export dylibExt="${stdenv.hostPlatform.extensions.sharedLibrary}" - substituteAll ${./glue.cmake} $dev/lib/cmake/dispatch/dispatchConfig.cmake - ''; - - meta = { - description = "Grand Central Dispatch"; - homepage = "https://github.com/swiftlang/swift-corelibs-libdispatch"; - platforms = lib.platforms.linux; - license = lib.licenses.asl20; - maintainers = with lib.maintainers; [ cmm ]; - teams = [ lib.teams.swift ]; - }; -} diff --git a/pkgs/development/compilers/swift/libdispatch/disable-swift-overlay.patch b/pkgs/development/compilers/swift/libdispatch/disable-swift-overlay.patch deleted file mode 100644 index 0ea1869d5528..000000000000 --- a/pkgs/development/compilers/swift/libdispatch/disable-swift-overlay.patch +++ /dev/null @@ -1,35 +0,0 @@ -Enabling Swift support is normally intended for building an overlay for a -Swift SDK, which changes the installation layout. Prevent this. - ---- a/CMakeLists.txt -+++ b/CMakeLists.txt -@@ -287,7 +287,7 @@ configure_file("${PROJECT_SOURCE_DIR}/cmake/config.h.in" - add_compile_definitions($<$,$>:HAVE_CONFIG_H>) - - --if(ENABLE_SWIFT) -+if(0) - set(INSTALL_TARGET_DIR "${CMAKE_INSTALL_LIBDIR}/swift$<$>:_static>/$" CACHE PATH "Path where the libraries will be installed") - set(INSTALL_DISPATCH_HEADERS_DIR "${CMAKE_INSTALL_LIBDIR}/swift$<$>:_static>/dispatch" CACHE PATH "Path where the headers will be installed for libdispatch") - set(INSTALL_BLOCK_HEADERS_DIR "${CMAKE_INSTALL_LIBDIR}/swift$<$>:_static>/Block" CACHE PATH "Path where the headers will be installed for the blocks runtime") ---- a/man/CMakeLists.txt -+++ b/man/CMakeLists.txt -@@ -1,6 +1,6 @@ - - # TODO(compnerd) add symlinks --if(NOT ENABLE_SWIFT) -+if(1) - install(FILES - dispatch.3 - dispatch_after.3 ---- a/src/swift/CMakeLists.txt -+++ b/src/swift/CMakeLists.txt -@@ -47,7 +47,7 @@ get_swift_host_arch(swift_arch) - install(FILES - ${CMAKE_CURRENT_BINARY_DIR}/swift/Dispatch.swiftmodule - ${CMAKE_CURRENT_BINARY_DIR}/swift/Dispatch.swiftdoc -- DESTINATION ${INSTALL_TARGET_DIR}/${swift_arch}) -+ DESTINATION ${INSTALL_TARGET_DIR}/swift) - set_property(GLOBAL APPEND PROPERTY DISPATCH_EXPORTS swiftDispatch) - install(TARGETS swiftDispatch - EXPORT dispatchExports diff --git a/pkgs/development/compilers/swift/libdispatch/glue.cmake b/pkgs/development/compilers/swift/libdispatch/glue.cmake deleted file mode 100644 index dd696dc61085..000000000000 --- a/pkgs/development/compilers/swift/libdispatch/glue.cmake +++ /dev/null @@ -1,5 +0,0 @@ -add_library(dispatch SHARED IMPORTED) -set_property(TARGET dispatch PROPERTY IMPORTED_LOCATION "@out@/lib/libdispatch@dylibExt@") - -add_library(swiftDispatch SHARED IMPORTED) -set_property(TARGET swiftDispatch PROPERTY IMPORTED_LOCATION "@out@/lib/libswiftDispatch@dylibExt@") diff --git a/pkgs/development/compilers/swift/sourcekit-lsp/default.nix b/pkgs/development/compilers/swift/sourcekit-lsp/default.nix deleted file mode 100644 index 7ad17d6624bb..000000000000 --- a/pkgs/development/compilers/swift/sourcekit-lsp/default.nix +++ /dev/null @@ -1,89 +0,0 @@ -{ - lib, - stdenv, - callPackage, - fetchpatch, - pkg-config, - swift, - swiftpm, - swiftpm2nix, - Dispatch, - Foundation, - XCTest, - sqlite, - ncurses, -}: -let - sources = callPackage ../sources.nix { }; - generated = swiftpm2nix.helpers ./generated; - - # On Darwin, we only want ncurses in the linker search path, because headers - # are part of libsystem. Adding its headers to the search path causes strange - # mixing and errors. - # TODO: Find a better way to prevent this conflict. - ncursesInput = if stdenv.hostPlatform.isDarwin then ncurses.out else ncurses; -in -stdenv.mkDerivation { - pname = "sourcekit-lsp"; - - inherit (sources) version; - src = sources.sourcekit-lsp; - - nativeBuildInputs = [ - pkg-config - swift - swiftpm - ]; - buildInputs = [ - Foundation - XCTest - sqlite - ncursesInput - ]; - - env.LD_LIBRARY_PATH = lib.optionalString stdenv.hostPlatform.isLinux ( - lib.makeLibraryPath [ Dispatch ] - ); - - configurePhase = generated.configure + '' - swiftpmMakeMutable indexstore-db - patch -p1 -d .build/checkouts/indexstore-db -i ${./patches/indexstore-db-macos-target.patch} - patch -p1 -d .build/checkouts/indexstore-db -i ${ - # Fix the build with modern Clang. - fetchpatch { - url = "https://github.com/swiftlang/indexstore-db/commit/6120b53b1e8774ef4e2ad83438d4d94961331e72.patch"; - hash = "sha256-tMAfTIa3RKiA/jDtP02mHcpPaF2s9a+3q/PLJxqn30M="; - } - } - - # This toggles a section specific to Xcode XCTest, which doesn't work on - # Darwin, where we also use swift-corelibs-xctest. - substituteInPlace Sources/LSPTestSupport/PerfTestCase.swift \ - --replace-fail '#if os(macOS)' '#if false' - - # Required to link with swift-corelibs-xctest on Darwin. - export SWIFTTSC_MACOS_DEPLOYMENT_TARGET=10.12 - ''; - - # TODO: BuildServerBuildSystemTests fails - #doCheck = true; - - installPhase = '' - binPath="$(swiftpmBinPath)" - mkdir -p $out/bin - cp $binPath/sourcekit-lsp $out/bin/ - ''; - - # Canary to verify output of our Swift toolchain does not depend on the Swift - # compiler itself. (Only its 'lib' output.) - disallowedRequisites = [ swift.swift ]; - - meta = { - description = "Language Server Protocol implementation for Swift and C-based languages"; - mainProgram = "sourcekit-lsp"; - homepage = "https://github.com/swiftlang/sourcekit-lsp"; - platforms = with lib.platforms; linux ++ darwin; - license = lib.licenses.asl20; - teams = [ lib.teams.swift ]; - }; -} diff --git a/pkgs/development/compilers/swift/sourcekit-lsp/generated/default.nix b/pkgs/development/compilers/swift/sourcekit-lsp/generated/default.nix deleted file mode 100644 index eb316fdf48c8..000000000000 --- a/pkgs/development/compilers/swift/sourcekit-lsp/generated/default.nix +++ /dev/null @@ -1,19 +0,0 @@ -# This file was generated by swiftpm2nix. -{ - workspaceStateFile = ./workspace-state.json; - hashes = { - "indexstore-db" = "sha256-2EIzEaVLHZ5vwO8skTaq9HoAaLuT9WFVLMgcgGYuVAk="; - "swift-argument-parser" = "sha256-qEJ329hqQyQVxtHScD7qPmWW9ZDf9bX+4xgpDlX0w5A="; - "swift-asn1" = "sha256-aN6BJOBvUCFn62mPv0nT4Z3edD1bQZ2zT5GubzdXZDw="; - "swift-certificates" = "sha256-34FcJfZgdufFehgjxgo8UbbFPnWnYsS6qR8SIba/WZg="; - "swift-collections" = "sha256-+f9Azcl+NbDvxlMsX0UbT3n87aYaBR1Kjp3rDqoLgkA="; - "swift-crypto" = "sha256-lcB497b/T1bHShPrjNjHthrs76pDFpU+4uN0uW4tz+4="; - "swift-driver" = "sha256-Xaz9gZuOspDb+PB67d6tXfpcs+kkDCPSkhu+eIfrb0A="; - "swift-llbuild" = "sha256-kUm8/+DWDBhuqU/kJBleqSl8/Vz478pMhx5QK2g7k0o="; - "swift-package-manager" = "sha256-7jkAum4nJj9ofVRF3RZDXAR6PyAjORPMnftTNnUrA+U="; - "swift-syntax" = "sha256-8XV2dlB3Vio5O+wFnS5EQeHyPCIgFyCjEYFGCWzOPwE="; - "swift-system" = "sha256-NpTzyppbOQR0Bg/0jrwdphZgbxyRrXy/4dnYcjFvY6w="; - "swift-tools-support-core" = "sha256-Pqy01AyDg7ZTyDM6lV69e6nhfhxwFTOhGFTfhcA1e9E="; - "Yams" = "sha256-AY/fIvB7THrl9GWzGJL8eDBbkcLw27tSRTGtUqmYw8k="; - }; -} diff --git a/pkgs/development/compilers/swift/sourcekit-lsp/generated/workspace-state.json b/pkgs/development/compilers/swift/sourcekit-lsp/generated/workspace-state.json deleted file mode 100644 index b0cf93cb193c..000000000000 --- a/pkgs/development/compilers/swift/sourcekit-lsp/generated/workspace-state.json +++ /dev/null @@ -1,229 +0,0 @@ -{ - "object": { - "artifacts": [], - "dependencies": [ - { - "basedOn": null, - "packageRef": { - "identity": "indexstore-db", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/indexstore-db.git", - "name": "IndexStoreDB" - }, - "state": { - "checkoutState": { - "branch": "release/5.10", - "revision": "89ec16c2ac1bb271614e734a2ee792224809eb20" - }, - "name": "sourceControlCheckout" - }, - "subpath": "indexstore-db" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-argument-parser", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-argument-parser.git", - "name": "swift-argument-parser" - }, - "state": { - "checkoutState": { - "revision": "8f4d2753f0e4778c76d5f05ad16c74f707390531", - "version": "1.2.3" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-argument-parser" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-asn1", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-asn1.git", - "name": "swift-asn1" - }, - "state": { - "checkoutState": { - "revision": "df5d2fcd22e3f480e3ef85bf23e277a4a0ef524d", - "version": "1.2.0" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-asn1" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-certificates", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-certificates.git", - "name": "swift-certificates" - }, - "state": { - "checkoutState": { - "revision": "83640c8097acaec17c9835a083e89678cb0f2b66", - "version": "1.3.0" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-certificates" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-collections", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-collections.git", - "name": "swift-collections" - }, - "state": { - "checkoutState": { - "revision": "c11818f3cae0780656baa430b49e7f163f08dffd", - "version": "1.1.6" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-collections" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-crypto", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-crypto.git", - "name": "swift-crypto" - }, - "state": { - "checkoutState": { - "revision": "629f0b679d0fd0a6ae823d7f750b9ab032c00b80", - "version": "3.0.0" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-crypto" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-driver", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-driver.git", - "name": "swift-driver" - }, - "state": { - "checkoutState": { - "branch": "release/5.10", - "revision": "b461fd4fc51be8e1f2a3f4a2184b664b8846b46f" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-driver" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-llbuild", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-llbuild.git", - "name": "llbuild" - }, - "state": { - "checkoutState": { - "branch": "release/5.10", - "revision": "fd7c2e0d9279edd023ced6b0a590f8407f5472f9" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-llbuild" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-package-manager", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-package-manager.git", - "name": "SwiftPM" - }, - "state": { - "checkoutState": { - "branch": "release/5.10", - "revision": "b5f8ad931b7a40b81f64765fa08c2751164759b4" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-package-manager" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-syntax", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-syntax.git", - "name": "swift-syntax" - }, - "state": { - "checkoutState": { - "branch": "release/5.10", - "revision": "cdd571f366a4298bb863a9dcfe1295bb595041d5" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-syntax" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-system", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-system.git", - "name": "swift-system" - }, - "state": { - "checkoutState": { - "revision": "d2ba781702a1d8285419c15ee62fd734a9437ff5", - "version": "1.3.2" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-system" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-tools-support-core", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-tools-support-core.git", - "name": "swift-tools-support-core" - }, - "state": { - "checkoutState": { - "branch": "release/5.10", - "revision": "90bdc2a157ebacc5d3de0c83e085d05d22ca5fa0" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-tools-support-core" - }, - { - "basedOn": null, - "packageRef": { - "identity": "yams", - "kind": "remoteSourceControl", - "location": "https://github.com/jpsim/Yams.git", - "name": "Yams" - }, - "state": { - "checkoutState": { - "revision": "0d9ee7ea8c4ebd4a489ad7a73d5c6cad55d6fed3", - "version": "5.0.6" - }, - "name": "sourceControlCheckout" - }, - "subpath": "Yams" - } - ] - }, - "version": 6 -} diff --git a/pkgs/development/compilers/swift/sourcekit-lsp/patches/indexstore-db-macos-target.patch b/pkgs/development/compilers/swift/sourcekit-lsp/patches/indexstore-db-macos-target.patch deleted file mode 100644 index 53e790874d5d..000000000000 --- a/pkgs/development/compilers/swift/sourcekit-lsp/patches/indexstore-db-macos-target.patch +++ /dev/null @@ -1,12 +0,0 @@ -Raise the deployment target of IndexStoreDB so it can link against our XCTest. - ---- a/Package.swift -+++ b/Package.swift -@@ -4,6 +4,7 @@ import PackageDescription - - let package = Package( - name: "IndexStoreDB", -+ platforms: [.macOS("10.12")], - products: [ - .library( - name: "IndexStoreDB", diff --git a/pkgs/development/compilers/swift/sources.nix b/pkgs/development/compilers/swift/sources.nix deleted file mode 100644 index 5b5c468a6d06..000000000000 --- a/pkgs/development/compilers/swift/sources.nix +++ /dev/null @@ -1,39 +0,0 @@ -{ lib, fetchFromGitHub }: - -let - - # These packages are all part of the Swift toolchain, and have a single - # upstream version that should match. We also list the hashes here so a basic - # version upgrade touches only this file. - version = "5.10.1"; - hashes = { - llvm-project = "sha256-D+zZjLgnAFy6zBuUQwRI0VmDrgr2TQeNUnDbDtvtRZ4="; - sourcekit-lsp = "sha256-mMZ8zPkyoht0aSSnStIULWbLjowahdza9DQXboT1D0o="; - swift = "sha256-UK8yPwHu/sCvcuKKmBMCP9rGRJCZE3ct0ckdNw2BVbE="; - swift-cmark = "sha256-GK2tFu49Sw8jJWJpxQerVFqsuUJwkAhRloa2/aUTYB8="; - swift-corelibs-foundation = "sha256-izYpdCZaf3ktgz/k3pjmHJHH5BebdG7nj8l6vbuk+o0="; - swift-corelibs-libdispatch = "sha256-pta3wJj2LJ/lsYAWQpw0wSGLDMO41mN8Zbl78LUCaQo="; - swift-corelibs-xctest = "sha256-HgnVFYUuefCZKsOjXgt98ebMsLdMl0oXFXy2Pb2iUdw="; - swift-docc = "sha256-zgGahAanYI95nQZ+3zAYrs0h4APNamPrZfwF81k1si0="; - swift-docc-render-artifact = "sha256-Ky9l6tzAxQOpcPFq2FeGnFUl8i59TifRBSHNaZg8wfw="; - swift-driver = "sha256-Xaz9gZuOspDb+PB67d6tXfpcs+kkDCPSkhu+eIfrb0A="; - swift-experimental-string-processing = "sha256-gv3xY9s6gdv0lpXH8RGfiLAvZWM7xVsUSLcqyb4rSeQ="; - swift-format = "sha256-oYf9Qt0b/6G3+uQaoExQRKzgpi1RPYSSpZLfwhuRmF8="; - swift-package-manager = "sha256-yL/cPCt7pZ0XqbbxEnrbzM2X3EkU9klon7SzO2Z13SA="; - swift-syntax = "sha256-OcrOdlnLYpMxH5CGWNGbs5XW3gJaGgKWQqB9YtwmZeY="; - }; - - # Create fetch derivations. - sources = lib.mapAttrs ( - repo: hash: - fetchFromGitHub { - owner = "apple"; - inherit repo; - rev = "swift-${version}-RELEASE"; - name = "${repo}-${version}-src"; - hash = hashes.${repo}; - } - ) hashes; - -in -sources // { inherit version; } diff --git a/pkgs/development/compilers/swift/swift-docc/default.nix b/pkgs/development/compilers/swift/swift-docc/default.nix deleted file mode 100644 index 2ec0b4c10746..000000000000 --- a/pkgs/development/compilers/swift/swift-docc/default.nix +++ /dev/null @@ -1,73 +0,0 @@ -{ - lib, - stdenv, - callPackage, - swift, - swiftpm, - swiftpm2nix, - Foundation, - XCTest, -}: -let - sources = callPackage ../sources.nix { }; - generated = swiftpm2nix.helpers ./generated; -in -stdenv.mkDerivation { - pname = "swift-docc"; - - inherit (sources) version; - src = sources.swift-docc; - # TODO: We could build this from `apple/swift-docc-render` source, but that - # repository is not tagged. - renderArtifact = sources.swift-docc-render-artifact; - - nativeBuildInputs = [ - swift - swiftpm - ]; - buildInputs = [ - Foundation - XCTest - ]; - - configurePhase = - generated.configure - # Fix the build with modern Clang. - # - # Based on the upstream fix for Musl: - # - + '' - swiftpmMakeMutable swift-nio - patch -p1 -d .build/checkouts/swift-nio -i ${./fix-swift-nio.patch} - ''; - - # We only install the docc binary, so don't need the other products. - # This works around a failure building generate-symbol-graph: - # Sources/generate-symbol-graph/main.swift:13:18: error: module 'SwiftDocC' was not compiled for testing - # TODO: Figure out the cause. It doesn't seem to happen outside Nixpkgs. - swiftpmFlags = [ "--product docc" ]; - - # TODO: Tests depend on indexstore-db being provided by an existing Swift - # toolchain. (ie. looks for `../lib/libIndexStore.so` relative to swiftc. - #doCheck = true; - - installPhase = '' - binPath="$(swiftpmBinPath)" - mkdir -p $out/bin $out/share/docc - cp $binPath/docc $out/bin/ - ln -s $renderArtifact/dist $out/share/docc/render - ''; - - # Canary to verify output of our Swift toolchain does not depend on the Swift - # compiler itself. (Only its 'lib' output.) - disallowedRequisites = [ swift.swift ]; - - meta = { - description = "Documentation compiler for Swift"; - mainProgram = "docc"; - homepage = "https://github.com/apple/swift-docc"; - platforms = with lib.platforms; linux ++ darwin; - license = lib.licenses.asl20; - teams = [ lib.teams.swift ]; - }; -} diff --git a/pkgs/development/compilers/swift/swift-docc/fix-swift-nio.patch b/pkgs/development/compilers/swift/swift-docc/fix-swift-nio.patch deleted file mode 100644 index ccab988906fa..000000000000 --- a/pkgs/development/compilers/swift/swift-docc/fix-swift-nio.patch +++ /dev/null @@ -1,13 +0,0 @@ -diff --git a/Package.swift b/Package.swift -index 39c6fb4b2f..02c08b898d 100644 ---- a/Package.swift -+++ b/Package.swift -@@ -26,7 +26,7 @@ - .target(name: "NIOFoundationCompat", dependencies: ["NIO"]), - .target(name: "CNIOAtomics", dependencies: []), - .target(name: "CNIOSHA1", dependencies: []), -- .target(name: "CNIOLinux", dependencies: []), -+ .target(name: "CNIOLinux", dependencies: [], cSettings: [.define("_GNU_SOURCE")]), - .target(name: "CNIODarwin", dependencies: [], cSettings: [.define("__APPLE_USE_RFC_3542")]), - .target(name: "CNIOWindows", dependencies: []), - .target(name: "NIOConcurrencyHelpers", diff --git a/pkgs/development/compilers/swift/swift-docc/generated/default.nix b/pkgs/development/compilers/swift/swift-docc/generated/default.nix deleted file mode 100644 index 22bec28c102f..000000000000 --- a/pkgs/development/compilers/swift/swift-docc/generated/default.nix +++ /dev/null @@ -1,16 +0,0 @@ -# This file was generated by swiftpm2nix. -{ - workspaceStateFile = ./workspace-state.json; - hashes = { - "swift-argument-parser" = "sha256-G4Tz/AdL5WbRq93aJnQhMjHLH7dEuhmXL3PPn+0H6vM="; - "swift-atomics" = "sha256-fjRGySMI7Mv52sCYejWI5YA+IcehOdz5XxK3p+hxwmU="; - "swift-cmark" = "sha256-1/LnvAggPkpfJZo9evfP+fCj6NXY9SMxwo7WJA2kXOM="; - "swift-collections" = "sha256-VtnHFWd5OUmRBnmIeOF8xn8PASLrHG/pfONWnEuX2sw="; - "swift-crypto" = "sha256-vBDjXtynl3HMq1RK/hMOu36b+0hX2SRRnwhPNjPUOsU="; - "swift-docc-plugin" = "sha256-r+cFtDTK6rRWDOOsgJNF6J2mfm/oKxoK7HIv6fpFW4o="; - "swift-docc-symbolkit" = "sha256-hAcoe57wE9gkPc1E/lXY41W+Eh3a7cUWfRv3Xi4rO2M="; - "swift-lmdb" = "sha256-dZDN2pBOE0ZPtneQvEjF+AE4PDwbcaTausR2W4lg9Ss="; - "swift-markdown" = "sha256-qb+mSS1A3WzLQdCB9lIz+UhSG9tf0hknitTfh6VIrHs="; - "swift-nio" = "sha256-KOvnE5VF6lw9hfTLHIlG+6EV/7kl8hL4IOIVoP2om3Q="; - }; -} diff --git a/pkgs/development/compilers/swift/swift-docc/generated/workspace-state.json b/pkgs/development/compilers/swift/swift-docc/generated/workspace-state.json deleted file mode 100644 index 76f5f228b274..000000000000 --- a/pkgs/development/compilers/swift/swift-docc/generated/workspace-state.json +++ /dev/null @@ -1,178 +0,0 @@ -{ - "object": { - "artifacts": [], - "dependencies": [ - { - "basedOn": null, - "packageRef": { - "identity": "swift-argument-parser", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-argument-parser", - "name": "swift-argument-parser" - }, - "state": { - "checkoutState": { - "revision": "fee6933f37fde9a5e12a1e4aeaa93fe60116ff2a", - "version": "1.2.2" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-argument-parser" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-atomics", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-atomics.git", - "name": "swift-atomics" - }, - "state": { - "checkoutState": { - "revision": "6c89474e62719ddcc1e9614989fff2f68208fe10", - "version": "1.1.0" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-atomics" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-cmark", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-cmark.git", - "name": "cmark-gfm" - }, - "state": { - "checkoutState": { - "branch": "gfm", - "revision": "eb9a6a357b6816c68f4b194eaa5b67f3cd1fa5c3" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-cmark" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-collections", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-collections.git", - "name": "swift-collections" - }, - "state": { - "checkoutState": { - "revision": "937e904258d22af6e447a0b72c0bc67583ef64a2", - "version": "1.0.4" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-collections" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-crypto", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-crypto.git", - "name": "swift-crypto" - }, - "state": { - "checkoutState": { - "revision": "33a20e650c33f6d72d822d558333f2085effa3dc", - "version": "2.5.0" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-crypto" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-docc-plugin", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-docc-plugin", - "name": "SwiftDocCPlugin" - }, - "state": { - "checkoutState": { - "revision": "9b1258905c21fc1b97bf03d1b4ca12c4ec4e5fda", - "version": "1.2.0" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-docc-plugin" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-docc-symbolkit", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-docc-symbolkit", - "name": "SymbolKit" - }, - "state": { - "checkoutState": { - "branch": "release/5.10", - "revision": "1d5aba8186fc648e17b30631b34043110ca8dd19" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-docc-symbolkit" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-lmdb", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-lmdb.git", - "name": "CLMDB" - }, - "state": { - "checkoutState": { - "branch": "release/5.10", - "revision": "584941b1236b15bad74d8163785d389c028b1ad8" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-lmdb" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-markdown", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-markdown.git", - "name": "swift-markdown" - }, - "state": { - "checkoutState": { - "branch": "release/5.10", - "revision": "636291555b65bd59b2b3279abc7d03a622aa7c55" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-markdown" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-nio", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-nio.git", - "name": "swift-nio" - }, - "state": { - "checkoutState": { - "revision": "2d8e6ca36fe3e8ed74b0883f593757a45463c34d", - "version": "2.53.0" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-nio" - } - ] - }, - "version": 6 -} diff --git a/pkgs/development/compilers/swift/swift-driver/default.nix b/pkgs/development/compilers/swift/swift-driver/default.nix deleted file mode 100644 index 04d41a663cd7..000000000000 --- a/pkgs/development/compilers/swift/swift-driver/default.nix +++ /dev/null @@ -1,82 +0,0 @@ -{ - lib, - stdenv, - callPackage, - fetchpatch, - swift, - swiftpm, - swiftpm2nix, - Foundation, - XCTest, - sqlite, - ncurses, - clang, - replaceVars, -}: -let - sources = callPackage ../sources.nix { }; - generated = swiftpm2nix.helpers ./generated; - - # On Darwin, we only want ncurses in the linker search path, because headers - # are part of libsystem. Adding its headers to the search path causes strange - # mixing and errors. - # TODO: Find a better way to prevent this conflict. - ncursesInput = if stdenv.hostPlatform.isDarwin then ncurses.out else ncurses; -in -stdenv.mkDerivation { - pname = "swift-driver"; - - inherit (sources) version; - src = sources.swift-driver; - - nativeBuildInputs = [ - swift - swiftpm - ]; - buildInputs = [ - Foundation - XCTest - sqlite - ncursesInput - ]; - - patches = [ - ./patches/disable-catalyst.patch - (replaceVars ./patches/linux-fix-linking.patch { - inherit clang; - }) - # TODO: Replace with branch patch once merged: - # https://github.com/apple/swift-driver/pull/1197 - (fetchpatch { - url = "https://github.com/apple/swift-driver/commit/d3ef9cdf4871a58eddec7ff0e28fe611130da3f9.patch"; - hash = "sha256-eVBaKN6uzj48ZnHtwGV0k5ChKjak1tDCyE+wTdyGq2c="; - }) - # Prevent a warning about SDK directories we don't have. - (replaceVars ./patches/prevent-sdk-dirs-warnings.patch { - inherit (builtins) storeDir; - }) - ]; - - configurePhase = generated.configure; - - # TODO: Tests depend on indexstore-db being provided by an existing Swift - # toolchain. (ie. looks for `../lib/libIndexStore.so` relative to swiftc. - #doCheck = true; - - # TODO: Darwin-specific installation includes more, but not sure why. - installPhase = '' - binPath="$(swiftpmBinPath)" - mkdir -p $out/bin - for executable in swift-driver swift-help swift-build-sdk-interfaces; do - cp $binPath/$executable $out/bin/ - done - ''; - - meta = { - description = "Swift compiler driver"; - homepage = "https://github.com/apple/swift-driver"; - platforms = with lib.platforms; linux ++ darwin; - license = lib.licenses.asl20; - teams = [ lib.teams.swift ]; - }; -} diff --git a/pkgs/development/compilers/swift/swift-driver/generated/default.nix b/pkgs/development/compilers/swift/swift-driver/generated/default.nix deleted file mode 100644 index 3651538c1a01..000000000000 --- a/pkgs/development/compilers/swift/swift-driver/generated/default.nix +++ /dev/null @@ -1,11 +0,0 @@ -# This file was generated by swiftpm2nix. -{ - workspaceStateFile = ./workspace-state.json; - hashes = { - "swift-argument-parser" = "sha256-G4Tz/AdL5WbRq93aJnQhMjHLH7dEuhmXL3PPn+0H6vM="; - "swift-llbuild" = "sha256-kUm8/+DWDBhuqU/kJBleqSl8/Vz478pMhx5QK2g7k0o="; - "swift-system" = "sha256-p18QHzO+NtoY/WQzOD+PfD+bjqrIWsbeEbsJLPqEAhA="; - "swift-tools-support-core" = "sha256-Pqy01AyDg7ZTyDM6lV69e6nhfhxwFTOhGFTfhcA1e9E="; - "Yams" = "sha256-5qxuCkmopm3uFcoYJKQA8ofW98f53H1gZaPiOh2DS4U="; - }; -} diff --git a/pkgs/development/compilers/swift/swift-driver/generated/workspace-state.json b/pkgs/development/compilers/swift/swift-driver/generated/workspace-state.json deleted file mode 100644 index 55bd4ea5fad1..000000000000 --- a/pkgs/development/compilers/swift/swift-driver/generated/workspace-state.json +++ /dev/null @@ -1,93 +0,0 @@ -{ - "object": { - "artifacts": [], - "dependencies": [ - { - "basedOn": null, - "packageRef": { - "identity": "swift-argument-parser", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-argument-parser.git", - "name": "swift-argument-parser" - }, - "state": { - "checkoutState": { - "revision": "fee6933f37fde9a5e12a1e4aeaa93fe60116ff2a", - "version": "1.2.2" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-argument-parser" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-llbuild", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-llbuild.git", - "name": "llbuild" - }, - "state": { - "checkoutState": { - "branch": "release/5.10", - "revision": "fd7c2e0d9279edd023ced6b0a590f8407f5472f9" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-llbuild" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-system", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-system.git", - "name": "swift-system" - }, - "state": { - "checkoutState": { - "revision": "836bc4557b74fe6d2660218d56e3ce96aff76574", - "version": "1.1.1" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-system" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-tools-support-core", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-tools-support-core.git", - "name": "swift-tools-support-core" - }, - "state": { - "checkoutState": { - "branch": "release/5.10", - "revision": "90bdc2a157ebacc5d3de0c83e085d05d22ca5fa0" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-tools-support-core" - }, - { - "basedOn": null, - "packageRef": { - "identity": "yams", - "kind": "remoteSourceControl", - "location": "https://github.com/jpsim/Yams.git", - "name": "Yams" - }, - "state": { - "checkoutState": { - "revision": "01835dc202670b5bb90d07f3eae41867e9ed29f6", - "version": "5.0.1" - }, - "name": "sourceControlCheckout" - }, - "subpath": "Yams" - } - ] - }, - "version": 6 -} diff --git a/pkgs/development/compilers/swift/swift-driver/patches/disable-catalyst.patch b/pkgs/development/compilers/swift/swift-driver/patches/disable-catalyst.patch deleted file mode 100644 index b9eb23f21061..000000000000 --- a/pkgs/development/compilers/swift/swift-driver/patches/disable-catalyst.patch +++ /dev/null @@ -1,17 +0,0 @@ -Tries to parse SDKSettings.plist looking for a Catalyst version map, but we -don't currently support this. - ---- a/Sources/SwiftDriver/Toolchains/DarwinToolchain.swift -+++ b/Sources/SwiftDriver/Toolchains/DarwinToolchain.swift -@@ -297,11 +297,7 @@ public final class DarwinToolchain: Toolchain { - debugDescription: "Malformed version string") - } - self.version = version -- if self.canonicalName.hasPrefix("macosx") { -- self.versionMap = try keyedContainer.decode(VersionMap.self, forKey: .versionMap) -- } else { - self.versionMap = VersionMap() -- } - } - - diff --git a/pkgs/development/compilers/swift/swift-driver/patches/linux-fix-linking.patch b/pkgs/development/compilers/swift/swift-driver/patches/linux-fix-linking.patch deleted file mode 100644 index dcdb5292687d..000000000000 --- a/pkgs/development/compilers/swift/swift-driver/patches/linux-fix-linking.patch +++ /dev/null @@ -1,40 +0,0 @@ -diff --git a/Sources/SwiftDriver/Jobs/GenericUnixToolchain+LinkerSupport.swift b/Sources/SwiftDriver/Jobs/GenericUnixToolchain+LinkerSupport.swift -index a4a735f498..381522cc1f 100644 ---- a/Sources/SwiftDriver/Jobs/GenericUnixToolchain+LinkerSupport.swift -+++ b/Sources/SwiftDriver/Jobs/GenericUnixToolchain+LinkerSupport.swift -@@ -10,6 +10,7 @@ - // - //===----------------------------------------------------------------------===// - -+import Foundation - import SwiftOptions - - import func TSCBasic.lookupExecutablePath -@@ -130,7 +131,18 @@ - } - - let clangTool: Tool = cxxCompatEnabled ? .clangxx : .clang -- var clangPath = try getToolPath(clangTool) -+ -+ // For Nix, prefer linking using the wrapped Nixpkgs clang, instead of using -+ // the unwrapped clang packaged with swift. The latter is unable to link, but -+ // we still want to use it for other purposes (clang importer). -+ var clangPath: AbsolutePath -+ if let binPath = try? AbsolutePath(validating: "@clang@/bin"), -+ let tool = lookupExecutablePath(filename: cxxCompatEnabled -+ ? "clang++" : "clang", -+ searchPaths: [binPath]) { -+ clangPath = tool -+ } else { -+ clangPath = try getToolPath(clangTool) - if let toolsDirPath = parsedOptions.getLastArgument(.toolsDirectory) { - // FIXME: What if this isn't an absolute path? - let toolsDir = try AbsolutePath(validating: toolsDirPath.asSingle) -@@ -146,6 +158,7 @@ - commandLine.appendFlag("-B") - commandLine.appendPath(toolsDir) - } -+ } // Nix - - // Executables on Linux get -pie - if targetTriple.os == .linux && linkerOutputType == .executable { diff --git a/pkgs/development/compilers/swift/swift-driver/patches/prevent-sdk-dirs-warnings.patch b/pkgs/development/compilers/swift/swift-driver/patches/prevent-sdk-dirs-warnings.patch deleted file mode 100644 index 6080865ebe37..000000000000 --- a/pkgs/development/compilers/swift/swift-driver/patches/prevent-sdk-dirs-warnings.patch +++ /dev/null @@ -1,16 +0,0 @@ -Prevents a user-visible warning on every compilation: - - ld: warning: directory not found for option '-L.../MacOSX11.0.sdk/usr/lib/swift' - ---- a/Sources/SwiftDriver/Jobs/Toolchain+LinkerSupport.swift -+++ b/Sources/SwiftDriver/Jobs/Toolchain+LinkerSupport.swift -@@ -50,7 +50,9 @@ extension Toolchain { - result.append(sdkPath.appending(components: "System", "iOSSupport", "usr", "lib", "swift")) - } - -+ if sdkPath.absolutePath?.pathString.starts(with: "@storeDir@") == false { - result.append(sdkPath.appending(components: "usr", "lib", "swift")) -+ } - } - - return result diff --git a/pkgs/development/compilers/swift/swift-format/default.nix b/pkgs/development/compilers/swift/swift-format/default.nix deleted file mode 100644 index 9f265bc4d6f1..000000000000 --- a/pkgs/development/compilers/swift/swift-format/default.nix +++ /dev/null @@ -1,62 +0,0 @@ -{ - lib, - stdenv, - callPackage, - swift, - swiftpm, - swiftpm2nix, - installShellFiles, - Dispatch, - Foundation, -}: -let - sources = callPackage ../sources.nix { }; - generated = swiftpm2nix.helpers ./generated; -in -stdenv.mkDerivation { - pname = "swift-format"; - - inherit (sources) version; - src = sources.swift-format; - - nativeBuildInputs = [ - swift - swiftpm - installShellFiles - ]; - buildInputs = [ Foundation ]; - - env.LD_LIBRARY_PATH = lib.optionalString stdenv.hostPlatform.isLinux ( - lib.makeLibraryPath [ Dispatch ] - ); - - configurePhase = generated.configure; - - # We only install the swift-format binary, so don't need the other products. - swiftpmFlags = [ "--product swift-format" ]; - - installPhase = '' - binPath="$(swiftpmBinPath)" - mkdir -p $out/bin - cp $binPath/swift-format $out/bin/ - - # Generate shell completions - for shell in bash zsh fish; do - $out/bin/swift-format --generate-completion-script $shell > swift-format.$shell - done - - installShellCompletion --cmd swift-format \ - --bash swift-format.bash \ - --zsh swift-format.zsh \ - --fish swift-format.fish - ''; - - meta = { - description = "Formatting technology for Swift source code"; - homepage = "https://github.com/swiftlang/swift-format"; - platforms = with lib.platforms; linux ++ darwin; - license = lib.licenses.asl20; - teams = [ lib.teams.swift ]; - mainProgram = "swift-format"; - }; -} diff --git a/pkgs/development/compilers/swift/swift-format/generated/default.nix b/pkgs/development/compilers/swift/swift-format/generated/default.nix deleted file mode 100644 index b01e3c6abf2d..000000000000 --- a/pkgs/development/compilers/swift/swift-format/generated/default.nix +++ /dev/null @@ -1,10 +0,0 @@ -# This file was generated by swiftpm2nix. -{ - workspaceStateFile = ./workspace-state.json; - hashes = { - "swift-argument-parser" = "sha256-JXNjFpLNaqzOGXlIgQtwzG2Yq1daOl4tmTAUcZL4thM="; - "swift-cmark" = "sha256-npLzvHtMmWZlqNIYOMAZfqyX2TOkICZNHCN1+laOBZA="; - "swift-markdown" = "sha256-F8xJYp8kf9IzLAe+HuKLFWJe3fdC2yewb+zaJgyeJ1U="; - "swift-syntax" = "sha256-8XV2dlB3Vio5O+wFnS5EQeHyPCIgFyCjEYFGCWzOPwE="; - }; -} diff --git a/pkgs/development/compilers/swift/swift-format/generated/workspace-state.json b/pkgs/development/compilers/swift/swift-format/generated/workspace-state.json deleted file mode 100644 index 388535f3770f..000000000000 --- a/pkgs/development/compilers/swift/swift-format/generated/workspace-state.json +++ /dev/null @@ -1,76 +0,0 @@ -{ - "object": { - "artifacts": [], - "dependencies": [ - { - "basedOn": null, - "packageRef": { - "identity": "swift-argument-parser", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-argument-parser.git", - "name": "swift-argument-parser" - }, - "state": { - "checkoutState": { - "revision": "309a47b2b1d9b5e991f36961c983ecec72275be3", - "version": "1.6.1" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-argument-parser" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-cmark", - "kind": "remoteSourceControl", - "location": "https://github.com/swiftlang/swift-cmark.git", - "name": "cmark-gfm" - }, - "state": { - "checkoutState": { - "revision": "b97d09472e847a416629f026eceae0e2afcfad65", - "version": "0.7.0" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-cmark" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-markdown", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-markdown.git", - "name": "swift-markdown" - }, - "state": { - "checkoutState": { - "revision": "d8cf111c276ed18cff82d3cad563d2ca5903b982", - "version": "0.7.1" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-markdown" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-syntax", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-syntax.git", - "name": "swift-syntax" - }, - "state": { - "checkoutState": { - "branch": "release/5.10", - "revision": "cdd571f366a4298bb863a9dcfe1295bb595041d5" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-syntax" - } - ] - }, - "version": 6 -} diff --git a/pkgs/development/compilers/swift/swiftpm/cmake-glue.nix b/pkgs/development/compilers/swift/swiftpm/cmake-glue.nix deleted file mode 100644 index 70af831142a9..000000000000 --- a/pkgs/development/compilers/swift/swiftpm/cmake-glue.nix +++ /dev/null @@ -1,107 +0,0 @@ -# SwiftPM dependencies are normally not installed using CMake, and only provide -# CMake modules to link them together in a build tree. We have separate -# derivations, so need a real install step. Here we provide our own minimal -# CMake modules to install along with the build products. -{ - lib, - stdenv, - swift, -}: -let - - inherit (stdenv.hostPlatform) extensions; - - # This file exports shell snippets for use in postInstall. - mkInstallScript = module: template: '' - mkdir -p $out/lib/cmake/${module} - ( - export staticLibExt="${extensions.staticLibrary}" - export sharedLibExt="${extensions.sharedLibrary}" - export swiftOs="${swift.swiftOs}" - substituteAll \ - ${builtins.toFile "${module}Config.cmake" template} \ - $out/lib/cmake/${module}/${module}Config.cmake - ) - ''; - -in -lib.mapAttrs mkInstallScript { - SwiftSystem = '' - add_library(SwiftSystem::SystemPackage STATIC IMPORTED) - set_property(TARGET SwiftSystem::SystemPackage PROPERTY IMPORTED_LOCATION "@out@/lib/swift_static/@swiftOs@/libSystemPackage@staticLibExt@") - ''; - - SwiftCollections = '' - add_library(SwiftCollections::Collections STATIC IMPORTED) - set_property(TARGET SwiftCollections::Collections PROPERTY IMPORTED_LOCATION "@out@/lib/swift_static/@swiftOs@/libCollections@staticLibExt@") - - add_library(SwiftCollections::DequeModule STATIC IMPORTED) - set_property(TARGET SwiftCollections::DequeModule PROPERTY IMPORTED_LOCATION "@out@/lib/swift_static/@swiftOs@/libDequeModule@staticLibExt@") - - add_library(SwiftCollections::OrderedCollections STATIC IMPORTED) - set_property(TARGET SwiftCollections::OrderedCollections PROPERTY IMPORTED_LOCATION "@out@/lib/swift_static/@swiftOs@/libOrderedCollections@staticLibExt@") - ''; - - TSC = '' - add_library(TSCLibc SHARED IMPORTED) - set_property(TARGET TSCLibc PROPERTY IMPORTED_LOCATION "@out@/lib/libTSCLibc@sharedLibExt@") - - add_library(TSCBasic SHARED IMPORTED) - set_property(TARGET TSCBasic PROPERTY IMPORTED_LOCATION "@out@/lib/libTSCBasic@sharedLibExt@") - - add_library(TSCUtility SHARED IMPORTED) - set_property(TARGET TSCUtility PROPERTY IMPORTED_LOCATION "@out@/lib/libTSCUtility@sharedLibExt@") - ''; - - ArgumentParser = '' - add_library(ArgumentParser SHARED IMPORTED) - set_property(TARGET ArgumentParser PROPERTY IMPORTED_LOCATION "@out@/lib/swift/@swiftOs@/libArgumentParser@sharedLibExt@") - - add_library(ArgumentParserToolInfo SHARED IMPORTED) - set_property(TARGET ArgumentParserToolInfo PROPERTY IMPORTED_LOCATION "@out@/lib/swift/@swiftOs@/libArgumentParserToolInfo@sharedLibExt@") - ''; - - Yams = '' - add_library(Yams SHARED IMPORTED) - set_property(TARGET Yams PROPERTY IMPORTED_LOCATION "@out@/lib/swift/@swiftOs@/libYams@sharedLibExt@") - ''; - - LLBuild = '' - add_library(libllbuild SHARED IMPORTED) - set_property(TARGET libllbuild PROPERTY IMPORTED_LOCATION "@out@/lib/libllbuild@sharedLibExt@") - - add_library(llbuildSwift SHARED IMPORTED) - set_property(TARGET llbuildSwift PROPERTY IMPORTED_LOCATION "@out@/lib/swift/pm/llbuild/libllbuildSwift@sharedLibExt@") - ''; - - SwiftDriver = '' - add_library(SwiftDriver SHARED IMPORTED) - set_property(TARGET SwiftDriver PROPERTY IMPORTED_LOCATION "@out@/lib/libSwiftDriver@sharedLibExt@") - - add_library(SwiftDriverExecution SHARED IMPORTED) - set_property(TARGET SwiftDriverExecution PROPERTY IMPORTED_LOCATION "@out@/lib/libSwiftDriverExecution@sharedLibExt@") - - add_library(SwiftOptions SHARED IMPORTED) - set_property(TARGET SwiftOptions PROPERTY IMPORTED_LOCATION "@out@/lib/libSwiftOptions@sharedLibExt@") - ''; - - SwiftCrypto = '' - add_library(Crypto SHARED IMPORTED) - set_property(TARGET Crypto PROPERTY IMPORTED_LOCATION "@out@/lib/swift/@swiftOs@/libCrypto@sharedLibExt@") - - add_library(_CryptoExtras SHARED IMPORTED) - # this can't possibly be right... I really think it should be `libCryptoExtras` - # swift-certificates did build with this though..... - set_property(TARGET _CryptoExtras PROPERTY IMPORTED_LOCATION "@out@/lib/swift/@swiftOs@/libCrypto@sharedLibExt@") - ''; - - SwiftASN1 = '' - add_library(SwiftASN1 SHARED IMPORTED) - set_property(TARGET SwiftASN1 PROPERTY IMPORTED_LOCATION "@out@/lib/swift/@swiftOs@/libSwiftASN1@sharedLibExt@") - ''; - - SwiftCertificates = '' - add_library(SwiftCertificates SHARED IMPORTED) - set_property(TARGET SwiftCertificates PROPERTY IMPORTED_LOCATION "@out@/lib/swift/@swiftOs@/libCertificates@sharedLibExt@") - ''; -} diff --git a/pkgs/development/compilers/swift/swiftpm/default.nix b/pkgs/development/compilers/swift/swiftpm/default.nix deleted file mode 100644 index e6858f08cf18..000000000000 --- a/pkgs/development/compilers/swift/swiftpm/default.nix +++ /dev/null @@ -1,501 +0,0 @@ -{ - lib, - stdenv, - callPackage, - fetchFromGitHub, - cmake, - ninja, - git, - swift, - swiftpm2nix, - Foundation, - XCTest, - pkg-config, - sqlite, - ncurses, - replaceVars, - runCommandLocal, - makeWrapper, - DarwinTools, # sw_vers - cctools, # vtool - xcbuild, -}: - -let - - inherit (swift) - swiftOs - swiftModuleSubdir - swiftStaticModuleSubdir - ; - sharedLibraryExt = stdenv.hostPlatform.extensions.sharedLibrary; - - sources = callPackage ../sources.nix { }; - generated = swiftpm2nix.helpers ./generated; - cmakeGlue = callPackage ./cmake-glue.nix { }; - - # Common attributes for the bootstrap swiftpm and the final swiftpm. - commonAttrs = { - inherit (sources) version; - src = sources.swift-package-manager; - nativeBuildInputs = [ makeWrapper ]; - # Required at run-time for the host platform to build package manifests. - propagatedBuildInputs = [ Foundation ]; - patches = [ - ./patches/cmake-disable-rpath.patch - ./patches/disable-index-store.patch - ./patches/disable-sandbox.patch - ./patches/disable-xctest.patch - ./patches/fix-clang-cxx.patch - ./patches/nix-pkgconfig-vars.patch - (replaceVars ./patches/fix-stdlib-path.patch { - inherit (builtins) storeDir; - swiftLib = swift.swift.lib; - }) - ]; - postPatch = '' - # The location of xcrun is hardcoded. We need PATH lookup instead. - find Sources -name '*.swift' | xargs sed -i -e 's|/usr/bin/xcrun|xcrun|g' - - # Patch the location where swiftpm looks for its API modules. - substituteInPlace Sources/PackageModel/UserToolchain.swift \ - --replace-fail \ - 'librariesPath = applicationPath.parentDirectory' \ - "librariesPath = try AbsolutePath(validating: \"$out\")" - ''; - }; - - # Tools invoked by swiftpm at run-time. - runtimeDeps = [ - git - ] - ++ lib.optionals stdenv.hostPlatform.isDarwin [ - xcbuild.xcrun - # These tools are part of cctools, but adding that as a build input puts - # an unwrapped linker in PATH, and breaks builds. This small derivation - # exposes just the tools we need: - # - vtool is used to determine a minimum deployment target. - # - libtool is used to build static libraries. - (runCommandLocal "swiftpm-cctools" { } '' - mkdir -p $out/bin - ln -s ${cctools}/bin/vtool $out/bin/vtool - ln -s ${cctools}/bin/libtool $out/bin/libtool - '') - ]; - - # Common attributes for the bootstrap derivations. - mkBootstrapDerivation = - attrs: - stdenv.mkDerivation ( - attrs - // { - nativeBuildInputs = - (attrs.nativeBuildInputs or [ ]) - ++ [ - cmake - ninja - swift - ] - ++ lib.optionals stdenv.hostPlatform.isDarwin [ DarwinTools ]; - - buildInputs = (attrs.buildInputs or [ ]) ++ [ Foundation ]; - - postPatch = - (attrs.postPatch or "") - + lib.optionalString stdenv.hostPlatform.isDarwin '' - # On Darwin only, Swift uses arm64 as cpu arch. - if [ -e cmake/modules/SwiftSupport.cmake ]; then - # At least in swift-asn1, this has been removed and the module uses the full target triple as the name - # (https://github.com/apple/swift-asn1/pull/103) - substituteInPlace cmake/modules/SwiftSupport.cmake \ - --replace '"aarch64" PARENT_SCOPE' '"arm64" PARENT_SCOPE' - fi - ''; - - postInstall = - (attrs.postInstall or "") - + lib.optionalString stdenv.hostPlatform.isDarwin '' - # The install name of libraries is incorrectly set to lib/ (via our - # CMake setup hook) instead of lib/swift/. This'd be easily fixed by - # fixDarwinDylibNames, but some builds create libraries that reference - # eachother, and we also have to fix those references. - dylibs="$(find $out/lib/swift* -name '*.dylib')" - changes="" - for dylib in $dylibs; do - changes+=" -change $(otool -D $dylib | tail -n 1) $dylib" - done - for dylib in $dylibs; do - install_name_tool -id $dylib $changes $dylib - done - ''; - - cmakeFlags = (attrs.cmakeFlags or [ ]) ++ [ - # Some builds link to libraries within the same build. Make sure these - # create references to $out. None of our builds run their own products, - # so we don't have to account for that scenario. - "-DCMAKE_BUILD_WITH_INSTALL_NAME_DIR=ON" - ]; - } - ); - - # On Darwin, we only want ncurses in the linker search path, because headers - # are part of libsystem. Adding its headers to the search path causes strange - # mixing and errors. - # TODO: Find a better way to prevent this conflict. - ncursesInput = if stdenv.hostPlatform.isDarwin then ncurses.out else ncurses; - - # Derivations for bootstrapping dependencies using CMake. - # This is based on the `swiftpm/Utilities/bootstrap` script. - # - # Some of the installation steps here are a bit hacky, because it seems like - # these packages were not really meant to be installed using CMake. The - # regular swiftpm bootstrap simply refers to the source and build - # directories. The advantage of separate builds is that we can more easily - # link libs together using existing Nixpkgs infra. - # - # In the end, we don't expose these derivations, and they only exist during - # the bootstrap phase. The final swiftpm derivation does not depend on them. - - swift-system = mkBootstrapDerivation { - name = "swift-system"; - src = generated.sources.swift-system; - - postInstall = - cmakeGlue.SwiftSystem - + lib.optionalString (!stdenv.hostPlatform.isDarwin) '' - # The cmake rules apparently only use the Darwin install convention. - # Fix up the installation so the module can be found on non-Darwin. - mkdir -p $out/${swiftStaticModuleSubdir} - mv $out/lib/swift_static/${swiftOs}/*.swiftmodule $out/${swiftStaticModuleSubdir}/ - ''; - }; - - swift-collections = mkBootstrapDerivation { - name = "swift-collections"; - src = generated.sources.swift-collections; - - postPatch = '' - # Only builds static libs on Linux, but this installation difference is a - # hassle. Because this installation is temporary for the bootstrap, may - # as well build static libs everywhere. - sed -i -e '/BUILD_SHARED_LIBS/d' CMakeLists.txt - ''; - - postInstall = - cmakeGlue.SwiftCollections - + lib.optionalString (!stdenv.hostPlatform.isDarwin) '' - # The cmake rules apparently only use the Darwin install convention. - # Fix up the installation so the module can be found on non-Darwin. - mkdir -p $out/${swiftStaticModuleSubdir} - mv $out/lib/swift_static/${swiftOs}/*.swiftmodule $out/${swiftStaticModuleSubdir}/ - ''; - }; - - swift-tools-support-core = mkBootstrapDerivation { - name = "swift-tools-support-core"; - src = generated.sources.swift-tools-support-core; - - buildInputs = [ - swift-system - sqlite - ]; - - postInstall = cmakeGlue.TSC + '' - # Swift modules are not installed. - mkdir -p $out/${swiftModuleSubdir} - cp swift/*.swift{module,doc} $out/${swiftModuleSubdir}/ - - # Static libs are not installed. - cp lib/*.a $out/lib/ - - # Headers are not installed. - mkdir -p $out/include - cp -r ../Sources/TSCclibc/include $out/include/TSC - ''; - }; - - swift-argument-parser = mkBootstrapDerivation { - name = "swift-argument-parser"; - src = generated.sources.swift-argument-parser; - - buildInputs = [ - ncursesInput - sqlite - ]; - - cmakeFlags = [ - "-DBUILD_TESTING=NO" - "-DBUILD_EXAMPLES=NO" - ]; - - postInstall = - cmakeGlue.ArgumentParser - + lib.optionalString stdenv.hostPlatform.isLinux '' - # Fix rpath so ArgumentParserToolInfo can be found. - patchelf --add-rpath "$out/lib/swift/${swiftOs}" \ - $out/lib/swift/${swiftOs}/libArgumentParser.so - ''; - }; - - Yams = mkBootstrapDerivation { - name = "Yams"; - src = generated.sources.Yams; - - # Conflicts with BUILD file on case-insensitive filesystems. - cmakeBuildDir = "_build"; - - postInstall = cmakeGlue.Yams; - }; - - llbuild = mkBootstrapDerivation { - name = "llbuild"; - src = generated.sources.swift-llbuild; - - nativeBuildInputs = lib.optional stdenv.hostPlatform.isDarwin xcbuild; - buildInputs = [ - ncursesInput - sqlite - ]; - - patches = [ - ./patches/llbuild-cmake-disable-rpath.patch - ./patches/llbuild-fix-missing-cstdint.patch - ]; - - postPatch = '' - # Substitute ncurses for curses. - find . -name CMakeLists.txt | xargs sed -i -e 's/curses/ncurses/' - - # Use absolute install names instead of rpath. - substituteInPlace \ - products/libllbuild/CMakeLists.txt \ - products/llbuildSwift/CMakeLists.txt \ - --replace-fail '@rpath' "$out/lib" - - # This subdirectory is enabled for Darwin only, but requires ObjC XCTest - # (and only Swift XCTest is open source). - substituteInPlace perftests/CMakeLists.txt \ - --replace-fail 'add_subdirectory(Xcode/' '#add_subdirectory(Xcode/' - ''; - - cmakeFlags = [ - "-DLLBUILD_SUPPORT_BINDINGS=Swift" - ]; - - postInstall = cmakeGlue.LLBuild + '' - # Install module map. - cp ../products/libllbuild/include/module.modulemap $out/include - - # Swift modules are not installed. - mkdir -p $out/${swiftModuleSubdir} - cp products/llbuildSwift/*.swift{module,doc} $out/${swiftModuleSubdir}/ - ''; - }; - - swift-driver = mkBootstrapDerivation { - name = "swift-driver"; - src = generated.sources.swift-driver; - - buildInputs = [ - Yams - llbuild - swift-system - swift-argument-parser - swift-tools-support-core - ]; - - postPatch = '' - # Tries to link against CYaml, but that's private. - substituteInPlace Sources/SwiftDriver/CMakeLists.txt \ - --replace-fail CYaml "" - ''; - - postInstall = cmakeGlue.SwiftDriver + '' - # Swift modules are not installed. - mkdir -p $out/${swiftModuleSubdir} - cp swift/*.swift{module,doc} $out/${swiftModuleSubdir}/ - ''; - }; - - swift-crypto = mkBootstrapDerivation { - name = "swift-crypto"; - src = fetchFromGitHub { - owner = "swiftlang"; - repo = "swift-crypto"; - rev = "95ba0316a9b733e92bb6b071255ff46263bbe7dc"; # 3.15.1, as opposed to the pinned version of 3.0.0 - sha256 = "sha256-RzoUBx4l12v0ZamSIAEpHHCRQXxJkXJCwVBEj7Qwg9I="; - fetchSubmodules = true; - }; - - buildInputs = [ - swift-asn1 - ]; - - patches = [ - ./patches/install-crypto-extras.patch - ]; - - postPatch = '' - # Fix use of hardcoded tool paths on Darwin. - substituteInPlace CMakeLists.txt \ - --replace-fail /usr/bin/ar $NIX_CC/bin/ar - substituteInPlace CMakeLists.txt \ - --replace-fail /usr/bin/ranlib $NIX_CC/bin/ranlib - ''; - - postInstall = cmakeGlue.SwiftCrypto + '' - # Static libs are not installed. - cp lib/*.a $out/lib/ - - # Headers are not installed. - cp -r ../Sources/CCryptoBoringSSL/include $out/include - - # Swift modules are put in the wrong place by default (and not all are linked) - mkdir -p $out/${swiftModuleSubdir} - rm -rf $out/${swiftModuleSubdir}/*.swift{module,doc} - # I assume we don't care about .swiftsourceinfo - cp swift/*.swift{module,doc} $out/${swiftModuleSubdir}/ - ''; - }; - - swift-asn1 = mkBootstrapDerivation { - name = "swift-asn1"; - src = generated.sources.swift-asn1; - - postInstall = - cmakeGlue.SwiftASN1 - + lib.optionalString (!stdenv.hostPlatform.isDarwin) '' - # SwiftASN1 uses the full target triple as the name of the swiftmodule - # (https://github.com/apple/swift-asn1/pull/103) - mkdir -p $out/${swiftModuleSubdir} - cp swift/*.swift{module,doc} $out/${swiftModuleSubdir}/ - ''; - }; - - swift-certificates = mkBootstrapDerivation { - name = "swift-certificates"; - src = generated.sources.swift-certificates; - - buildInputs = [ - swift-asn1 - swift-crypto - ]; - - postInstall = cmakeGlue.SwiftCertificates; - }; - - # Build a bootstrapping swiftpm using CMake. - swiftpm-bootstrap = mkBootstrapDerivation ( - commonAttrs - // { - pname = "swiftpm-bootstrap"; - - buildInputs = [ - llbuild - sqlite - swift-argument-parser - swift-asn1 - swift-certificates - swift-collections - swift-crypto - swift-driver - swift-system - swift-tools-support-core - ]; - - cmakeFlags = [ - "-DUSE_CMAKE_INSTALL=ON" - ]; - - postInstall = '' - for program in $out/bin/swift-*; do - wrapProgram $program --prefix PATH : ${lib.makeBinPath runtimeDeps} - done - ''; - } - ); - -in -# Build the final swiftpm with the bootstrapping swiftpm. -stdenv.mkDerivation ( - commonAttrs - // { - pname = "swiftpm"; - - nativeBuildInputs = commonAttrs.nativeBuildInputs ++ [ - pkg-config - swift - swiftpm-bootstrap - ]; - buildInputs = [ - ncursesInput - sqlite - XCTest - ]; - - configurePhase = generated.configure + '' - # Functionality provided by Xcode XCTest, but not available in - # swift-corelibs-xctest. - swiftpmMakeMutable swift-tools-support-core - substituteInPlace .build/checkouts/swift-tools-support-core/Sources/TSCTestSupport/XCTestCasePerf.swift \ - --replace-fail 'canImport(Darwin)' 'false' - - # Prevent a warning about SDK directories we don't have. - swiftpmMakeMutable swift-driver - patch -p1 -d .build/checkouts/swift-driver -i ${ - replaceVars ../swift-driver/patches/prevent-sdk-dirs-warnings.patch { - inherit (builtins) storeDir; - } - } - ''; - - buildPhase = '' - TERM=dumb swift-build -c release - ''; - - # TODO: Tests depend on indexstore-db being provided by an existing Swift - # toolchain. (ie. looks for `../lib/libIndexStore.so` relative to swiftc. - #doCheck = true; - #checkPhase = '' - # TERM=dumb swift-test -c release - #''; - - # The following is derived from Utilities/bootstrap, see install_swiftpm. - installPhase = '' - binPath="$(swift-build --show-bin-path -c release)" - - mkdir -p $out/bin $out/lib/swift - - cp $binPath/swift-package-manager $out/bin/swift-package - wrapProgram $out/bin/swift-package \ - --prefix PATH : ${lib.makeBinPath runtimeDeps} - for tool in swift-build swift-test swift-run swift-package-collection swift-experimental-destination; do - ln -s $out/bin/swift-package $out/bin/$tool - done - - installSwiftpmModule() { - mkdir -p $out/lib/swift/pm/$2 - cp $binPath/lib$1${sharedLibraryExt} $out/lib/swift/pm/$2/ - - if [[ -f $binPath/$1.swiftinterface ]]; then - cp $binPath/$1.swiftinterface $out/lib/swift/pm/$2/ - else - cp -r $binPath/$1.swiftmodule $out/lib/swift/pm/$2/ - fi - cp $binPath/$1.swiftdoc $out/lib/swift/pm/$2/ - } - installSwiftpmModule PackageDescription ManifestAPI - installSwiftpmModule PackagePlugin PluginAPI - ''; - - setupHook = ./setup-hook.sh; - - meta = { - description = "Package Manager for the Swift Programming Language"; - homepage = "https://github.com/swiftlang/swift-package-manager"; - platforms = with lib.platforms; linux ++ darwin; - license = lib.licenses.asl20; - teams = [ lib.teams.swift ]; - }; - } -) diff --git a/pkgs/development/compilers/swift/swiftpm/generated/default.nix b/pkgs/development/compilers/swift/swiftpm/generated/default.nix deleted file mode 100644 index 68e3f885d542..000000000000 --- a/pkgs/development/compilers/swift/swiftpm/generated/default.nix +++ /dev/null @@ -1,16 +0,0 @@ -# This file was generated by swiftpm2nix. -{ - workspaceStateFile = ./workspace-state.json; - hashes = { - "swift-argument-parser" = "sha256-qEJ329hqQyQVxtHScD7qPmWW9ZDf9bX+4xgpDlX0w5A="; - "swift-asn1" = "sha256-6NqPGUuM55YOXCMqNsqPm/3smKhSC2UIYHJSwtIiuoc="; - "swift-certificates" = "sha256-n5dE5J8f7PAVoJkIpiKrrDvB0xIil5VwtzC2mx6vz80="; - "swift-collections" = "sha256-WNj19mRvDSZNcDzZvmtS+jZxngBooiHekh3IsPZnKUQ="; - "swift-crypto" = "sha256-lcB497b/T1bHShPrjNjHthrs76pDFpU+4uN0uW4tz+4="; - "swift-driver" = "sha256-Xaz9gZuOspDb+PB67d6tXfpcs+kkDCPSkhu+eIfrb0A="; - "swift-llbuild" = "sha256-kUm8/+DWDBhuqU/kJBleqSl8/Vz478pMhx5QK2g7k0o="; - "swift-system" = "sha256-p18QHzO+NtoY/WQzOD+PfD+bjqrIWsbeEbsJLPqEAhA="; - "swift-tools-support-core" = "sha256-Pqy01AyDg7ZTyDM6lV69e6nhfhxwFTOhGFTfhcA1e9E="; - "Yams" = "sha256-AY/fIvB7THrl9GWzGJL8eDBbkcLw27tSRTGtUqmYw8k="; - }; -} diff --git a/pkgs/development/compilers/swift/swiftpm/generated/workspace-state.json b/pkgs/development/compilers/swift/swiftpm/generated/workspace-state.json deleted file mode 100644 index 4b9689d8ab30..000000000000 --- a/pkgs/development/compilers/swift/swiftpm/generated/workspace-state.json +++ /dev/null @@ -1,178 +0,0 @@ -{ - "object": { - "artifacts": [], - "dependencies": [ - { - "basedOn": null, - "packageRef": { - "identity": "swift-argument-parser", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-argument-parser.git", - "name": "swift-argument-parser" - }, - "state": { - "checkoutState": { - "revision": "8f4d2753f0e4778c76d5f05ad16c74f707390531", - "version": "1.2.3" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-argument-parser" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-asn1", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-asn1.git", - "name": "swift-asn1" - }, - "state": { - "checkoutState": { - "revision": "f70225981241859eb4aa1a18a75531d26637c8cc", - "version": "1.4.0" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-asn1" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-certificates", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-certificates.git", - "name": "swift-certificates" - }, - "state": { - "checkoutState": { - "revision": "01d7664523af5c169f26038f1e5d444ce47ae5ff", - "version": "1.0.1" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-certificates" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-collections", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-collections.git", - "name": "swift-collections" - }, - "state": { - "checkoutState": { - "revision": "d029d9d39c87bed85b1c50adee7c41795261a192", - "version": "1.0.6" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-collections" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-crypto", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-crypto.git", - "name": "swift-crypto" - }, - "state": { - "checkoutState": { - "revision": "629f0b679d0fd0a6ae823d7f750b9ab032c00b80", - "version": "3.0.0" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-crypto" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-driver", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-driver.git", - "name": "swift-driver" - }, - "state": { - "checkoutState": { - "branch": "release/5.10", - "revision": "b461fd4fc51be8e1f2a3f4a2184b664b8846b46f" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-driver" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-llbuild", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-llbuild.git", - "name": "llbuild" - }, - "state": { - "checkoutState": { - "branch": "release/5.10", - "revision": "fd7c2e0d9279edd023ced6b0a590f8407f5472f9" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-llbuild" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-system", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-system.git", - "name": "swift-system" - }, - "state": { - "checkoutState": { - "revision": "836bc4557b74fe6d2660218d56e3ce96aff76574", - "version": "1.1.1" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-system" - }, - { - "basedOn": null, - "packageRef": { - "identity": "swift-tools-support-core", - "kind": "remoteSourceControl", - "location": "https://github.com/apple/swift-tools-support-core.git", - "name": "swift-tools-support-core" - }, - "state": { - "checkoutState": { - "branch": "release/5.10", - "revision": "90bdc2a157ebacc5d3de0c83e085d05d22ca5fa0" - }, - "name": "sourceControlCheckout" - }, - "subpath": "swift-tools-support-core" - }, - { - "basedOn": null, - "packageRef": { - "identity": "yams", - "kind": "remoteSourceControl", - "location": "https://github.com/jpsim/Yams.git", - "name": "Yams" - }, - "state": { - "checkoutState": { - "revision": "0d9ee7ea8c4ebd4a489ad7a73d5c6cad55d6fed3", - "version": "5.0.6" - }, - "name": "sourceControlCheckout" - }, - "subpath": "Yams" - } - ] - }, - "version": 6 -} diff --git a/pkgs/development/compilers/swift/swiftpm/patches/cmake-disable-rpath.patch b/pkgs/development/compilers/swift/swiftpm/patches/cmake-disable-rpath.patch deleted file mode 100644 index f5997fa7ce5b..000000000000 --- a/pkgs/development/compilers/swift/swiftpm/patches/cmake-disable-rpath.patch +++ /dev/null @@ -1,36 +0,0 @@ -Disable rpath for the bootstrap build with CMake. - ---- a/Sources/PackageDescription/CMakeLists.txt -+++ b/Sources/PackageDescription/CMakeLists.txt -@@ -27,14 +27,11 @@ - $<$:-package-description-version$999.0>) - - if(CMAKE_HOST_SYSTEM_NAME STREQUAL Darwin) -- target_link_options(PackageDescription PRIVATE -- "SHELL:-Xlinker -install_name -Xlinker @rpath/libPackageDescription.dylib") - endif() - - set_target_properties(PackageDescription PROPERTIES - Swift_MODULE_NAME PackageDescription - Swift_MODULE_DIRECTORY ${CMAKE_BINARY_DIR}/pm/ManifestAPI -- INSTALL_NAME_DIR \\@rpath - OUTPUT_DIRECTORY ${CMAKE_BINARY_DIR}/pm/ManifestAPI - OUTPUT_NAME PackageDescription - ARCHIVE_OUTPUT_DIRECTORY ${CMAKE_BINARY_DIR}/pm/ManifestAPI ---- a/Sources/PackagePlugin/CMakeLists.txt -+++ b/Sources/PackagePlugin/CMakeLists.txt -@@ -29,14 +29,11 @@ if(CMAKE_HOST_SYSTEM_NAME STREQUAL Darwin) - set(SWIFT_INTERFACE_PATH ${CMAKE_BINARY_DIR}/pm/PluginAPI/PackagePlugin.swiftinterface) - target_compile_options(PackagePlugin PUBLIC - $<$:-emit-module-interface-path$${SWIFT_INTERFACE_PATH}>) -- target_link_options(PackagePlugin PRIVATE -- "SHELL:-Xlinker -install_name -Xlinker @rpath/libPackagePlugin.dylib") - endif() - - set_target_properties(PackagePlugin PROPERTIES - Swift_MODULE_NAME PackagePlugin - Swift_MODULE_DIRECTORY ${CMAKE_BINARY_DIR}/pm/PluginAPI -- INSTALL_NAME_DIR \\@rpath - OUTPUT_DIRECTORY ${CMAKE_BINARY_DIR}/pm/PluginAPI - OUTPUT_NAME PackagePlugin - ARCHIVE_OUTPUT_DIRECTORY ${CMAKE_BINARY_DIR}/pm/PluginAPI diff --git a/pkgs/development/compilers/swift/swiftpm/patches/disable-index-store.patch b/pkgs/development/compilers/swift/swiftpm/patches/disable-index-store.patch deleted file mode 100644 index ca701ae32543..000000000000 --- a/pkgs/development/compilers/swift/swiftpm/patches/disable-index-store.patch +++ /dev/null @@ -1,23 +0,0 @@ -The `-index-store-path` option is an Apple extension not available in our -Clang. Make it opt-in by default. - -(It is assumed the `target.type == test` check is for Xcode support, because -there is no evidence of it in swift-corelibs-xctest.) - ---- a/Sources/Build/BuildPlan/BuildPlan.swift -+++ b/Sources/Build/BuildPlan/BuildPlan.swift -@@ -111,14 +111,7 @@ - case .off: - addIndexStoreArguments = false - case .auto: -- if configuration == .debug { -- addIndexStoreArguments = true -- } else if target.type == .test { -- // Test discovery requires an index store for the test target to discover the tests -- addIndexStoreArguments = true -- } else { - addIndexStoreArguments = false -- } - } - - if addIndexStoreArguments { diff --git a/pkgs/development/compilers/swift/swiftpm/patches/disable-sandbox.patch b/pkgs/development/compilers/swift/swiftpm/patches/disable-sandbox.patch deleted file mode 100644 index b83e16e3c78f..000000000000 --- a/pkgs/development/compilers/swift/swiftpm/patches/disable-sandbox.patch +++ /dev/null @@ -1,27 +0,0 @@ -Nix may already sandbox the build, in which case sandbox_apply will fail. - ---- a/Sources/Basics/Sandbox.swift -+++ b/Sources/Basics/Sandbox.swift -@@ -57,6 +57,8 @@ - allowNetworkConnections: [SandboxNetworkPermission] = [] - ) throws -> [String] { - #if os(macOS) -+ let env = ProcessInfo.processInfo.environment -+ if env["NIX_BUILD_TOP"] == nil || env["IN_NIX_SHELL"] != nil { - let profile = try macOSSandboxProfile( - fileSystem: fileSystem, - strictness: strictness, -@@ -65,10 +67,10 @@ - allowNetworkConnections: allowNetworkConnections - ) - return ["/usr/bin/sandbox-exec", "-p", profile] + command -- #else -+ } -+ #endif - // rdar://40235432, rdar://75636874 tracks implementing sandboxes for other platforms. - return command -- #endif - } - - /// Basic strictness level of a sandbox applied to a command line. - diff --git a/pkgs/development/compilers/swift/swiftpm/patches/disable-xctest.patch b/pkgs/development/compilers/swift/swiftpm/patches/disable-xctest.patch deleted file mode 100644 index 71aca0071e83..000000000000 --- a/pkgs/development/compilers/swift/swiftpm/patches/disable-xctest.patch +++ /dev/null @@ -1,14 +0,0 @@ -XCTest is not fully open-source, only the Swift library parts. We don't have a -command-line runner available, so disable support. - ---- a/Sources/Commands/Utilities/TestingSupport.swift -+++ b/Sources/Commands/Utilities/TestingSupport.swift -@@ -105,7 +105,7 @@ - ) throws -> [TestSuite] { - // Run the correct tool. - var args = [String]() -- #if os(macOS) -+ #if false - let data: String = try withTemporaryFile { tempFile in - args = [try Self.xctestHelperPath(swiftTool: swiftTool).pathString, path.pathString, tempFile.path.pathString] - var env = try Self.constructTestEnvironment( diff --git a/pkgs/development/compilers/swift/swiftpm/patches/fix-clang-cxx.patch b/pkgs/development/compilers/swift/swiftpm/patches/fix-clang-cxx.patch deleted file mode 100644 index 877337924bbe..000000000000 --- a/pkgs/development/compilers/swift/swiftpm/patches/fix-clang-cxx.patch +++ /dev/null @@ -1,126 +0,0 @@ -Swiftpm may invoke clang, not clang++, to compile C++. Our cc-wrapper also -doesn't pick up the arguments that enable C++ compilation in this case. Patch -swiftpm to properly invoke clang++. - ---- a/Sources/Build/BuildPlan/BuildPlan+Product.swift -+++ b/Sources/Build/BuildPlan/BuildPlan+Product.swift -@@ -53,7 +53,7 @@ - for target in dependencies.staticTargets { - if case let target as ClangTarget = target.underlyingTarget, target.isCXX { - if buildParameters.targetTriple.isDarwin() { -- buildProduct.additionalFlags += ["-lc++"] -+ buildProduct.additionalFlags += ["-lc++", "-lc++abi"] - } else if buildParameters.targetTriple.isWindows() { - // Don't link any C++ library. - } else { ---- a/Sources/Build/BuildManifest/LLBuildManifestBuilder+Clang.swift -+++ b/Sources/Build/BuildManifest/LLBuildManifestBuilder+Clang.swift -@@ -97,7 +97,7 @@ - - args += ["-c", path.source.pathString, "-o", path.object.pathString] - -- let clangCompiler = try buildParameters.toolchain.getClangCompiler().pathString -+ let clangCompiler = try buildParameters.toolchain.getClangCompiler(isCXX: isCXX).pathString - args.insert(clangCompiler, at: 0) - - let objectFileNode: Node = .file(path.object) ---- a/Sources/PackageModel/Toolchain.swift -+++ b/Sources/PackageModel/Toolchain.swift -@@ -23,7 +23,7 @@ public protocol Toolchain { - var macosSwiftStdlib: AbsolutePath { get throws } - - /// Path of the `clang` compiler. -- func getClangCompiler() throws -> AbsolutePath -+ func getClangCompiler(isCXX: Bool) throws -> AbsolutePath - - // FIXME: This is a temporary API until index store is widely available in - // the OSS clang compiler. This API should not used for any other purpose. ---- a/Sources/PackageModel/UserToolchain.swift -+++ b/Sources/PackageModel/UserToolchain.swift -@@ -57,7 +57,7 @@ public final class UserToolchain: Toolchain { - /// Only use search paths, do not fall back to `xcrun`. - let useXcrun: Bool - -- private var _clangCompiler: AbsolutePath? -+ private var _clangCompiler: [Bool: AbsolutePath] = [:] - - private let environment: EnvironmentVariables - -@@ -262,33 +262,35 @@ - } - - /// Returns the path to clang compiler tool. -- public func getClangCompiler() throws -> AbsolutePath { -+ public func getClangCompiler(isCXX: Bool) throws -> AbsolutePath { - // Check if we already computed. -- if let clang = self._clangCompiler { -+ if let clang = self._clangCompiler[isCXX] { - return clang - } - - // Check in the environment variable first. -+ let envVar = isCXX ? "CXX" : "CC" - if let toolPath = UserToolchain.lookup( -- variable: "CC", -+ variable: envVar, - searchPaths: self.envSearchPaths, - environment: environment - ) { -- self._clangCompiler = toolPath -+ self._clangCompiler[isCXX] = toolPath - return toolPath - } - - // Then, check the toolchain. -+ let tool = isCXX ? "clang++" : "clang" - do { -- if let toolPath = try? UserToolchain.getTool("clang", binDirectories: self.swiftSDK.toolset.rootPaths) { -- self._clangCompiler = toolPath -+ if let toolPath = try? UserToolchain.getTool(tool, binDirectories: self.swiftSDK.toolset.rootPaths) { -+ self._clangCompiler[isCXX] = toolPath - return toolPath - } - } - - // Otherwise, lookup it up on the system. -- let toolPath = try UserToolchain.findTool("clang", envSearchPaths: self.envSearchPaths, useXcrun: useXcrun) -- self._clangCompiler = toolPath -+ let toolPath = try UserToolchain.findTool(tool, envSearchPaths: self.envSearchPaths, useXcrun: useXcrun) -+ self._clangCompiler[isCXX] = toolPath - return toolPath - } - - ---- a/Sources/SPMBuildCore/BuildParameters/BuildParameters.swift -+++ b/Sources/SPMBuildCore/BuildParameters/BuildParameters.swift -@@ -394,7 +394,7 @@ private struct _Toolchain: Encodable { - public func encode(to encoder: Encoder) throws { - var container = encoder.container(keyedBy: CodingKeys.self) - try container.encode(toolchain.swiftCompilerPath, forKey: .swiftCompiler) -- try container.encode(toolchain.getClangCompiler(), forKey: .clangCompiler) -+ try container.encode(toolchain.getClangCompiler(isCXX: false), forKey: .clangCompiler) - - try container.encode(toolchain.extraFlags.cCompilerFlags, forKey: .extraCCFlags) - // Maintaining `extraCPPFlags` key for compatibility with older encoding. ---- a/Sources/XCBuildSupport/XcodeBuildSystem.swift -+++ b/Sources/XCBuildSupport/XcodeBuildSystem.swift -@@ -182,7 +182,7 @@ public final class XcodeBuildSystem: SPMBuildCore.BuildSystem { - // Generate a table of any overriding build settings. - var settings: [String: String] = [:] - // An error with determining the override should not be fatal here. -- settings["CC"] = try? buildParameters.toolchain.getClangCompiler().pathString -+ settings["CC"] = try? buildParameters.toolchain.getClangCompiler(isCXX: false).pathString - // Always specify the path of the effective Swift compiler, which was determined in the same way as for the native build system. - settings["SWIFT_EXEC"] = buildParameters.toolchain.swiftCompilerPath.pathString - settings["LIBRARY_SEARCH_PATHS"] = "$(inherited) \(try buildParameters.toolchain.toolchainLibDir.pathString)" ---- a/Tests/BuildTests/MockBuildTestHelper.swift -+++ b/Tests/BuildTests/MockBuildTestHelper.swift -@@ -36,7 +36,7 @@ - let extraFlags = PackageModel.BuildFlags() - let installedSwiftPMConfiguration = InstalledSwiftPMConfiguration.default - -- func getClangCompiler() throws -> AbsolutePath { -+ func getClangCompiler(isCXX: Bool) throws -> AbsolutePath { - return "/fake/path/to/clang" - } - diff --git a/pkgs/development/compilers/swift/swiftpm/patches/fix-stdlib-path.patch b/pkgs/development/compilers/swift/swiftpm/patches/fix-stdlib-path.patch deleted file mode 100644 index 68698cafcdf6..000000000000 --- a/pkgs/development/compilers/swift/swiftpm/patches/fix-stdlib-path.patch +++ /dev/null @@ -1,25 +0,0 @@ -Swiftpm looks for the Swift stdlib relative to the swift compiler, but that's a -wrapper in our case. It wants to add the stdlib to the rpath, which is -necessary for back-deployment of some features. - ---- a/Sources/PackageModel/Toolchain.swift -+++ b/Sources/PackageModel/Toolchain.swift -@@ -53,12 +53,18 @@ extension Toolchain { - - public var macosSwiftStdlib: AbsolutePath { - get throws { -+ if swiftCompilerPath.pathString.starts(with: "@storeDir@") { -+ return try AbsolutePath(validating: "@swiftLib@/lib/swift/macosx") -+ } - return try AbsolutePath(validating: "../../lib/swift/macosx", relativeTo: resolveSymlinks(swiftCompilerPath)) - } - } - - public var toolchainLibDir: AbsolutePath { - get throws { -+ if swiftCompilerPath.pathString.starts(with: "@storeDir@") { -+ return try AbsolutePath(validating: "@swiftLib@/lib") -+ } - // FIXME: Not sure if it's better to base this off of Swift compiler or our own binary. - return try AbsolutePath(validating: "../../lib", relativeTo: resolveSymlinks(swiftCompilerPath)) - } diff --git a/pkgs/development/compilers/swift/swiftpm/patches/install-crypto-extras.patch b/pkgs/development/compilers/swift/swiftpm/patches/install-crypto-extras.patch deleted file mode 100644 index bdbd1c4d596e..000000000000 --- a/pkgs/development/compilers/swift/swiftpm/patches/install-crypto-extras.patch +++ /dev/null @@ -1,10 +0,0 @@ -Install _CryptoExtras target when building with CMake - ---- a/Sources/_CryptoExtras/CMakeLists.txt -+++ b/Sources/_CryptoExtras/CMakeLists.txt -@@ -42,4 +42,5 @@ target_link_options(_CryptoExtras PRIVATE - set_target_properties(_CryptoExtras PROPERTIES - INTERFACE_INCLUDE_DIRECTORIES ${CMAKE_Swift_MODULE_DIRECTORY}) - -+_install_target(_CryptoExtras) - set_property(GLOBAL APPEND PROPERTY SWIFT_CRYPTO_EXPORTS _CryptoExtras) diff --git a/pkgs/development/compilers/swift/swiftpm/patches/llbuild-cmake-disable-rpath.patch b/pkgs/development/compilers/swift/swiftpm/patches/llbuild-cmake-disable-rpath.patch deleted file mode 100644 index 785e82cc34b6..000000000000 --- a/pkgs/development/compilers/swift/swiftpm/patches/llbuild-cmake-disable-rpath.patch +++ /dev/null @@ -1,14 +0,0 @@ -Specifying `-platform_version` targeting macos before 10.15 causes cctools ld -to link with `@rpath`. This may have something to do with Swift ABI stability. - ---- a/products/llbuildSwift/CMakeLists.txt -+++ b/products/llbuildSwift/CMakeLists.txt -@@ -22,7 +17,7 @@ endif() - - # TODO(compnerd) move both of these outside of the CMake into the invocation - if(CMAKE_SYSTEM_NAME STREQUAL Darwin) -- add_compile_options(-target ${CMAKE_OSX_ARCHITECTURES}-apple-macosx10.10) -+ add_compile_options(-target ${CMAKE_OSX_ARCHITECTURES}-apple-macosx10.15) - if(NOT CMAKE_OSX_SYSROOT STREQUAL "") - add_compile_options(-sdk ${CMAKE_OSX_SYSROOT}) - endif() diff --git a/pkgs/development/compilers/swift/swiftpm/patches/llbuild-fix-missing-cstdint.patch b/pkgs/development/compilers/swift/swiftpm/patches/llbuild-fix-missing-cstdint.patch deleted file mode 100644 index 9dcbe6502356..000000000000 --- a/pkgs/development/compilers/swift/swiftpm/patches/llbuild-fix-missing-cstdint.patch +++ /dev/null @@ -1,12 +0,0 @@ -diff --git a/utils/unittest/googletest/src/gtest-death-test.cc b/utils/unittest/googletest/src/gtest-death-test.cc -index ede8378..bdef225 100644 ---- a/utils/unittest/googletest/src/gtest-death-test.cc -+++ b/utils/unittest/googletest/src/gtest-death-test.cc -@@ -33,6 +33,7 @@ - #include "gtest/gtest-death-test.h" - - #include -+#include - - #include "gtest/internal/gtest-port.h" - #include "gtest/internal/custom/gtest.h" diff --git a/pkgs/development/compilers/swift/swiftpm/patches/nix-pkgconfig-vars.patch b/pkgs/development/compilers/swift/swiftpm/patches/nix-pkgconfig-vars.patch deleted file mode 100644 index e032ce80bf90..000000000000 --- a/pkgs/development/compilers/swift/swiftpm/patches/nix-pkgconfig-vars.patch +++ /dev/null @@ -1,28 +0,0 @@ -Swift parses .pc files manually, but this means it bypasses our pkg-config -wrapper. That wrapper normally takes care of introducing the correct -PKG_CONFIG_PATH for cross compiling. - ---- a/Sources/PackageLoading/PkgConfig.swift -+++ b/Sources/PackageLoading/PkgConfig.swift -@@ -123,14 +123,17 @@ public struct PkgConfig { - - private static var envSearchPaths: [AbsolutePath] { - get throws { -- if let configPath = ProcessEnv.vars["PKG_CONFIG_PATH"] { -+ var result: [AbsolutePath] = [] -+ for envVar in ["PKG_CONFIG_PATH", "PKG_CONFIG_PATH_FOR_TARGET"] { -+ if let configPath = ProcessEnv.vars[envVar] { - #if os(Windows) -- return try configPath.split(separator: ";").map({ try AbsolutePath(validating: String($0)) }) -+ result += try configPath.split(separator: ";").map({ try AbsolutePath(validating: String($0)) }) - #else -- return try configPath.split(separator: ":").map({ try AbsolutePath(validating: String($0)) }) -+ result += try configPath.split(separator: ":").map({ try AbsolutePath(validating: String($0)) }) - #endif - } -- return [] -+ } -+ return result - } - } - } diff --git a/pkgs/development/compilers/swift/swiftpm/setup-hook.sh b/pkgs/development/compilers/swift/swiftpm/setup-hook.sh deleted file mode 100644 index 260d874ebfd7..000000000000 --- a/pkgs/development/compilers/swift/swiftpm/setup-hook.sh +++ /dev/null @@ -1,62 +0,0 @@ -# shellcheck shell=bash - -# Build using 'swift-build'. -swiftpmBuildPhase() { - runHook preBuild - - local buildCores=1 - if [ "${enableParallelBuilding-1}" ]; then - buildCores="$NIX_BUILD_CORES" - fi - - local flagsArray=( - -j "$buildCores" - -c "${swiftpmBuildConfig-release}" - ) - concatTo flagsArray swiftpmFlags swiftpmFlagsArray - - echoCmd 'build flags' "${flagsArray[@]}" - TERM=dumb swift-build "${flagsArray[@]}" - - runHook postBuild -} - -if [ -z "${dontUseSwiftpmBuild-}" ] && [ -z "${buildPhase-}" ]; then - buildPhase=swiftpmBuildPhase -fi - -# Check using 'swift-test'. -swiftpmCheckPhase() { - runHook preCheck - - local buildCores=1 - if [ "${enableParallelBuilding-1}" ]; then - buildCores="$NIX_BUILD_CORES" - fi - - local flagsArray=( - -j "$buildCores" - -c "${swiftpmBuildConfig-release}" - ) - concatTo flagsArray swiftpmFlags swiftpmFlagsArray - - echoCmd 'check flags' "${flagsArray[@]}" - TERM=dumb swift-test "${flagsArray[@]}" - - runHook postCheck -} - -if [ -z "${dontUseSwiftpmCheck-}" ] && [ -z "${checkPhase-}" ]; then - checkPhase=swiftpmCheckPhase -fi - -# Helper used to find the binary output path. -# Useful for performing the installPhase of swiftpm packages. -swiftpmBinPath() { - local flagsArray=( - -c "${swiftpmBuildConfig-release}" - ) - concatTo flagsArray swiftpmFlags swiftpmFlagsArray - - swift-build --show-bin-path "${flagsArray[@]}" -} diff --git a/pkgs/development/compilers/swift/swiftpm2nix/default.nix b/pkgs/development/compilers/swift/swiftpm2nix/default.nix deleted file mode 100644 index 208067014730..000000000000 --- a/pkgs/development/compilers/swift/swiftpm2nix/default.nix +++ /dev/null @@ -1,38 +0,0 @@ -{ - lib, - stdenv, - callPackage, - makeWrapper, - jq, - nurl, -}: - -stdenv.mkDerivation { - name = "swiftpm2nix"; - - nativeBuildInputs = [ makeWrapper ]; - - dontUnpack = true; - - installPhase = '' - install -vD ${./swiftpm2nix.sh} $out/bin/swiftpm2nix - wrapProgram $out/bin/$name \ - --prefix PATH : ${ - lib.makeBinPath [ - jq - nurl - ] - } - ''; - - preferLocalBuild = true; - - passthru = callPackage ./support.nix { }; - - meta = { - description = "Generate a Nix expression to fetch swiftpm dependencies"; - mainProgram = "swiftpm2nix"; - teams = [ lib.teams.swift ]; - platforms = lib.platforms.all; - }; -} diff --git a/pkgs/development/compilers/swift/swiftpm2nix/support.nix b/pkgs/development/compilers/swift/swiftpm2nix/support.nix deleted file mode 100644 index 0ddab549b98d..000000000000 --- a/pkgs/development/compilers/swift/swiftpm2nix/support.nix +++ /dev/null @@ -1,77 +0,0 @@ -{ - lib, - fetchgit, - formats, -}: -let - inherit (lib) - concatStrings - listToAttrs - makeOverridable - mapAttrsToList - nameValuePair - ; - json = formats.json { }; -in -rec { - - # Derive a pin file from workspace state. - mkPinFile = - workspaceState: - assert workspaceState.version >= 5 && workspaceState.version <= 6; - json.generate "Package.resolved" { - version = 1; - object.pins = map (dep: { - package = dep.packageRef.name; - repositoryURL = dep.packageRef.location; - state = dep.state.checkoutState; - }) workspaceState.object.dependencies; - }; - - # Make packaging helpers from swiftpm2nix generated output. - helpers = - generated: - let - inherit (import generated) workspaceStateFile hashes; - workspaceState = lib.importJSON workspaceStateFile; - pinFile = mkPinFile workspaceState; - in - rec { - - # Create fetch expressions for dependencies. - sources = listToAttrs ( - map ( - dep: - nameValuePair dep.subpath (fetchgit { - url = dep.packageRef.location; - rev = dep.state.checkoutState.revision; - sha256 = hashes.${dep.subpath}; - fetchSubmodules = true; - }) - ) workspaceState.object.dependencies - ); - - # Configure phase snippet for use in packaging. - configure = '' - mkdir -p .build/checkouts - ln -sf ${pinFile} ./Package.resolved - install -m 0600 ${workspaceStateFile} ./.build/workspace-state.json - '' - + concatStrings ( - mapAttrsToList (name: src: '' - ln -s '${src}' '.build/checkouts/${name}' - '') sources - ) - + '' - # Helper that makes a swiftpm dependency mutable by copying the source. - swiftpmMakeMutable() { - local orig="$(readlink .build/checkouts/$1)" - rm .build/checkouts/$1 - cp -r "$orig" .build/checkouts/$1 - chmod -R u+w .build/checkouts/$1 - } - ''; - - }; - -} diff --git a/pkgs/development/compilers/swift/swiftpm2nix/swiftpm2nix.sh b/pkgs/development/compilers/swift/swiftpm2nix/swiftpm2nix.sh deleted file mode 100755 index f5f9780aa95d..000000000000 --- a/pkgs/development/compilers/swift/swiftpm2nix/swiftpm2nix.sh +++ /dev/null @@ -1,45 +0,0 @@ -#!/usr/bin/env bash - -# Generates a Nix expression to fetch swiftpm dependencies, and a -# configurePhase snippet to prepare a working directory for swift-build. - -set -eu -o pipefail -shopt -s lastpipe - -stateFile=".build/workspace-state.json" -if [[ ! -f "$stateFile" ]]; then - echo >&2 "Missing $stateFile. Run 'swift package resolve' first." - exit 1 -fi - -stateVersion="$(jq .version $stateFile)" -if [[ $stateVersion -lt 5 || $stateVersion -gt 6 ]]; then - echo >&2 "Unsupported $stateFile version" - exit 1 -fi - -# Iterate dependencies and prefetch. -hashes="" -jq -r '.object.dependencies[] | "\(.subpath) \(.packageRef.location) \(.state.checkoutState.revision)"' $stateFile \ -| while read -r name url rev; do - echo >&2 "-- Fetching $name" - hash="$(nurl "$url" "$rev" --json --submodules=true --fetcher=fetchgit | jq -r .args.hash)" -hashes+=" - \"$name\" = \"$hash\";" - echo >&2 -done -hashes+=$'\n'" " - -# Generate output. -mkdir -p nix -# Copy the workspace state, but clear 'artifacts'. -jq '.object.artifacts = []' < $stateFile > nix/workspace-state.json -# Build an expression for fetching sources, and preparing the working directory. -cat > nix/default.nix << EOF -# This file was generated by swiftpm2nix. -{ - workspaceStateFile = ./workspace-state.json; - hashes = {$hashes}; -} -EOF -echo >&2 "-- Generated ./nix" diff --git a/pkgs/development/compilers/swift/wrapper/default.nix b/pkgs/development/compilers/swift/wrapper/default.nix deleted file mode 100644 index 9cd9cb347a23..000000000000 --- a/pkgs/development/compilers/swift/wrapper/default.nix +++ /dev/null @@ -1,119 +0,0 @@ -{ - lib, - stdenv, - swift, - useSwiftDriver ? true, - swift-driver, - clang, -}: - -stdenv.mkDerivation ( - swift._wrapperParams - // { - pname = "swift-wrapper"; - inherit (swift) version meta; - - outputs = [ - "out" - "man" - ]; - - # Wrapper and setup hook variables. - inherit swift; - inherit (swift) - swiftOs - swiftArch - swiftModuleSubdir - swiftLibSubdir - swiftStaticModuleSubdir - swiftStaticLibSubdir - ; - swiftDriver = lib.optionalString useSwiftDriver "${swift-driver}/bin/swift-driver"; - cc_wrapper = clang.override (prev: { - extraBuildCommands = - prev.extraBuildCommands - # We need to use the resource directory corresponding to Swift’s - # version of Clang instead of passing along the one from the - # `cc-wrapper` flags. - + '' - rm -r $out/resource-root - substituteInPlace $out/nix-support/cc-cflags \ - --replace-fail \ - "-resource-dir=$out/resource-root" \ - "-resource-dir=${lib.getLib swift}/lib/swift/clang" - '' - + - lib.optionalString - ( - stdenv.targetPlatform.isLinux - && stdenv.targetPlatform.isx86 - && lib.versionAtLeast (lib.getVersion clang) "19.1" - ) - '' - # Swift bundles Clang 16, which predates -mtls-dialect=gnu2 - # support (added in Clang 19.1). The cc-wrapper adds it based - # on the system Clang version, so strip it here. - substituteInPlace $out/nix-support/add-local-cc-cflags-before.sh \ - --replace-fail "'-mtls-dialect=gnu2'" "" - '' - # We need the libc++ headers corresponding to the LLVM version of - # Swift’s Clang. - + lib.optionalString (clang.libcxx != null) '' - include -isystem "${lib.getDev swift}/include/c++/v1" > $out/nix-support/libcxx-cxxflags - ''; - }); - - env.darwinMinVersion = lib.optionalString stdenv.targetPlatform.isDarwin ( - stdenv.targetPlatform.darwinMinVersion - ); - - buildCommand = '' - mkdir -p $out/bin $out/nix-support - - # Symlink all Swift binaries first. - # NOTE: This specifically omits clang binaries. We want to hide these for - # private use by Swift only. - ln -s -t $out/bin/ $swift/bin/swift* - - # Replace specific binaries with wrappers. - for executable in swift swiftc swift-frontend; do - export prog=$swift/bin/$executable - rm $out/bin/$executable - substituteAll '${./wrapper.sh}' $out/bin/$executable - chmod a+x $out/bin/$executable - done - - ${lib.optionalString useSwiftDriver '' - # Symlink swift-driver executables. - ln -s -t $out/bin/ ${swift-driver}/bin/* - ''} - - ln -s ${swift.man} $man - - # This link is here because various tools (swiftpm) check for stdlib - # relative to the swift compiler. It's fine if this is for build-time - # stuff, but we should patch all cases were it would end up in an output. - ln -s ${swift.lib}/lib $out/lib - - substituteAll ${./setup-hook.sh} $out/nix-support/setup-hook - - # Propagate any propagated inputs from the unwrapped Swift compiler, if any. - if [ -e "$swift/nix-support" ]; then - for input in "$swift/nix-support/"*propagated*; do - cp "$input" "$out/nix-support/$(basename "$input")" - done - fi - ''; - - passthru = { - inherit swift; - inherit (swift) - swiftOs - swiftArch - swiftModuleSubdir - swiftLibSubdir - tests - ; - }; - } -) diff --git a/pkgs/development/compilers/swift/wrapper/setup-hook.sh b/pkgs/development/compilers/swift/wrapper/setup-hook.sh deleted file mode 100644 index 398f19977f66..000000000000 --- a/pkgs/development/compilers/swift/wrapper/setup-hook.sh +++ /dev/null @@ -1,28 +0,0 @@ -# Add import paths for build inputs. -swiftWrapper_addImports () { - # Include subdirectories following both the Swift platform convention, and - # a simple `lib/swift` for Nix convenience. - for subdir in @swiftModuleSubdir@ @swiftStaticModuleSubdir@ lib/swift; do - if [[ -d "$1/$subdir" ]]; then - export NIX_SWIFTFLAGS_COMPILE+=" -I $1/$subdir" - fi - done - for subdir in @swiftLibSubdir@ @swiftStaticLibSubdir@ lib/swift; do - if [[ -d "$1/$subdir" ]]; then - export NIX_LDFLAGS+=" -L $1/$subdir" - fi - done -} - -addEnvHooks "$targetOffset" swiftWrapper_addImports - -# Use a postHook here because we rely on NIX_CC, which is set by the cc-wrapper -# setup hook, so delay until we're sure it was run. -swiftWrapper_postHook () { - # On Darwin, libc also contains Swift modules. - if [[ -e "$NIX_CC/nix-support/orig-libc" ]]; then - swiftWrapper_addImports "$(<$NIX_CC/nix-support/orig-libc)" - fi -} - -postHooks+=(swiftWrapper_postHook) diff --git a/pkgs/development/compilers/swift/wrapper/wrapper.sh b/pkgs/development/compilers/swift/wrapper/wrapper.sh deleted file mode 100644 index 77f7c31d6812..000000000000 --- a/pkgs/development/compilers/swift/wrapper/wrapper.sh +++ /dev/null @@ -1,313 +0,0 @@ -#! @shell@ -# NOTE: This wrapper is derived from cc-wrapper.sh, and is hopefully somewhat -# diffable with the original, so changes can be merged if necessary. -set -eu -o pipefail +o posix -shopt -s nullglob - -if (( "${NIX_DEBUG:-0}" >= 7 )); then - set -x -fi - -cc_wrapper="@cc_wrapper@" - -source $cc_wrapper/nix-support/utils.bash - -source $cc_wrapper/nix-support/darwin-sdk-setup.bash - -expandResponseParams "$@" - -# Check if we should wrap this Swift invocation at all, and how. Specifically, -# there are some internal tools we don't wrap, plus swift-frontend doesn't link -# and doesn't understand linker flags. This follows logic in -# `lib/DriverTool/driver.cpp`. -prog=@prog@ -progName="$(basename "$prog")" -firstArg="${params[0]:-}" -isFrontend=0 -isRepl=0 - -# These checks follow `shouldRunAsSubcommand`. -if [[ "$progName" == swift ]]; then - case "$firstArg" in - "" | -* | *.* | */* | repl) - ;; - *) - exec "swift-$firstArg" "${params[@]:1}" - ;; - esac -fi - -# These checks follow the first part of `run_driver`. -# -# NOTE: The original function short-circuits, but we can't here, because both -# paths must be wrapped. So we use an 'isFrontend' flag instead. -case "$firstArg" in - -frontend) - isFrontend=1 - # Ensure this stays the first argument. - params=( "${params[@]:1}" ) - extraBefore+=( "-frontend" ) - ;; - -modulewrap) - # Don't wrap this integrated tool. - exec "$prog" "${params[@]}" - ;; - repl) - isRepl=1 - params=( "${params[@]:1}" ) - ;; - --driver-mode=*) - ;; - *) - if [[ "$progName" == swift-frontend ]]; then - isFrontend=1 - fi - ;; -esac - -# For many tasks, Swift reinvokes swift-driver, the new driver implementation -# written in Swift. It needs some help finding the executable, though, and -# reimplementing the logic here is little effort. These checks follow -# `shouldDisallowNewDriver`. -if [[ - $isFrontend = 0 && - -n "@swiftDriver@" && - -z "${SWIFT_USE_OLD_DRIVER:-}" && - ( "$progName" == "swift" || "$progName" == "swiftc" ) -]]; then - prog=@swiftDriver@ - # Driver mode must be the very first argument. - extraBefore+=( "--driver-mode=$progName" ) - if [[ $isRepl = 1 ]]; then - extraBefore+=( "-repl" ) - fi - - # Ensure swift-driver invokes the unwrapped frontend (instead of finding - # the wrapped one via PATH), because we don't have to wrap a second time. - export SWIFT_DRIVER_SWIFT_FRONTEND_EXEC="@swift@/bin/swift-frontend" - - # Ensure swift-driver can find the LLDB with Swift support for the REPL. - export SWIFT_DRIVER_LLDB_EXEC="@swift@/bin/lldb" -fi - -path_backup="$PATH" - -# That @-vars are substituted separately from bash evaluation makes -# shellcheck think this, and others like it, are useless conditionals. -# shellcheck disable=SC2157 -if [[ -n "@coreutils_bin@" && -n "@gnugrep_bin@" ]]; then - PATH="@coreutils_bin@/bin:@gnugrep_bin@/bin" -fi - -# Parse command line options and set several variables. -# For instance, figure out if linker flags should be passed. -# GCC prints annoying warnings when they are not needed. -isCxx=0 -dontLink=$isFrontend - -for p in "${params[@]}"; do - case "$p" in - -cxx-interoperability-mode=default | -enable-cxx-interop | -enable-experimental-cxx-interop) - isCxx=1 ;; - esac -done - -# NOTE: We don't modify these for Swift, but sourced scripts may use them. -cxxInclude=1 -cxxLibrary=1 -cInclude=1 - -linkType=$(checkLinkType "${params[@]}") - -# Optionally filter out paths not refering to the store. -if [[ "${NIX_ENFORCE_PURITY:-}" = 1 && -n "$NIX_STORE" ]]; then - kept=() - nParams=${#params[@]} - declare -i n=0 - while (( "$n" < "$nParams" )); do - p=${params[n]} - p2=${params[n+1]:-} # handle `p` being last one - n+=1 - - skipNext=false - path="" - case "$p" in - -[IL]/*) path=${p:2} ;; - -[IL]) path=$p2 skipNext=true ;; - esac - - if [[ -n $path ]] && badPath "$path"; then - skip "$path" - $skipNext && n+=1 - continue - fi - - kept+=("$p") - done - # Old bash empty array hack - params=(${kept+"${kept[@]}"}) -fi - -# Flirting with a layer violation here. -if [ -z "${NIX_BINTOOLS_WRAPPER_FLAGS_SET_@suffixSalt@:-}" ]; then - source @bintools@/nix-support/add-flags.sh -fi - -# Put this one second so libc ldflags take priority. -if [ -z "${NIX_CC_WRAPPER_FLAGS_SET_@suffixSalt@:-}" ]; then - source $cc_wrapper/nix-support/add-flags.sh -fi - -# Only add darwin min version flag and set up `DEVELOPER_DIR` if a default darwin min version is set, -# which is a signal that we're targeting darwin. (Copied from add-flags in libc but tailored for Swift). -if [ "@darwinMinVersion@" ]; then - # Make sure the wrapped Swift compiler can find the overlays in the SDK. - NIX_SWIFTFLAGS_COMPILE+=" -I $SDKROOT/usr/lib/swift" - NIX_LDFLAGS_@suffixSalt@+=" -L $SDKROOT/usr/lib/swift" -fi - -if [[ "$isCxx" = 1 ]]; then - if [[ "$cxxInclude" = 1 ]]; then - NIX_CFLAGS_COMPILE_@suffixSalt@+=" $NIX_CXXSTDLIB_COMPILE_@suffixSalt@" - fi - if [[ "$cxxLibrary" = 1 ]]; then - NIX_CFLAGS_LINK_@suffixSalt@+=" $NIX_CXXSTDLIB_LINK_@suffixSalt@" - fi -fi - -source $cc_wrapper/nix-support/add-hardening.sh - -# Add the flags for the C compiler proper. -addCFlagsToList() { - declare -n list="$1" - shift - - for ((i = 1; i <= $#; i++)); do - local val="${!i}" - case "$val" in - # Pass through using -Xcc, but also convert to Swift -I. - # These have slightly different meaning for Clang, but Swift - # doesn't have exact equivalents. - -isystem | -cxx-isystem | -idirafter) - i=$((i + 1)) - list+=("-Xcc" "$val" "-Xcc" "${!i}" "-I" "${!i}") - ;; - # Simple rename. - -iframework) - i=$((i + 1)) - list+=("-Fsystem" "${!i}") - ;; - # Pass through verbatim. - -I | -Fsystem) - i=$((i + 1)) - list+=("${val}" "${!i}") - ;; - -I* | -L* | -F*) - list+=("${val}") - ;; - # Pass through using -Xcc. - *) - list+=("-Xcc" "$val") - ;; - esac - done -} -for i in ${NIX_SWIFTFLAGS_COMPILE:-}; do - extraAfter+=("$i") -done -for i in ${NIX_SWIFTFLAGS_COMPILE_BEFORE:-}; do - extraBefore+=("$i") -done -addCFlagsToList extraAfter $NIX_CFLAGS_COMPILE_@suffixSalt@ -addCFlagsToList extraBefore ${hardeningCFlags[@]+"${hardeningCFlags[@]}"} $NIX_CFLAGS_COMPILE_BEFORE_@suffixSalt@ - -if [ "$dontLink" != 1 ]; then - - # Add the flags that should only be passed to the compiler when - # linking. - addCFlagsToList extraAfter $(filterRpathFlags "$linkType" $NIX_CFLAGS_LINK_@suffixSalt@) - - # Add the flags that should be passed to the linker (and prevent - # `ld-wrapper' from adding NIX_LDFLAGS_@suffixSalt@ again). - for i in $(filterRpathFlags "$linkType" $NIX_LDFLAGS_BEFORE_@suffixSalt@); do - extraBefore+=("-Xlinker" "$i") - done - if [[ "$linkType" == dynamic && -n "$NIX_DYNAMIC_LINKER_@suffixSalt@" ]]; then - extraBefore+=("-Xlinker" "-dynamic-linker=$NIX_DYNAMIC_LINKER_@suffixSalt@") - fi - for i in $(filterRpathFlags "$linkType" $NIX_LDFLAGS_@suffixSalt@); do - if [ "${i:0:3}" = -L/ ]; then - extraAfter+=("$i") - else - extraAfter+=("-Xlinker" "$i") - fi - done - export NIX_LINK_TYPE_@suffixSalt@=$linkType -fi - -# TODO: If we ever need to expand functionality of this hook, it may no longer -# be compatible with Swift. Right now, it is only used on Darwin to force -# -target, which also happens to work with Swift. -# As of 369cc5c66b1efdbca2f136aa0055fedca1117304 (#445119), this hook also sets -# the -Werror=unguarded-availability flag, which Swift can't accept. We prefix -# that flag with -Xcc in the for loop below -if [[ -e $cc_wrapper/nix-support/add-local-cc-cflags-before.sh ]]; then - source $cc_wrapper/nix-support/add-local-cc-cflags-before.sh -fi - -for ((i=0; i < ${#extraBefore[@]}; i++));do - case "${extraBefore[i]}" in - -target) - i=$((i + 1)) - # On Darwin only, need to change 'aarch64' to 'arm64'. - extraBefore[i]="${extraBefore[i]/aarch64-apple-/arm64-apple-}" - # On Darwin, Swift requires the triple to be annotated with a version. - # TODO: Assumes macOS. - extraBefore[i]="${extraBefore[i]/-apple-darwin/-apple-macosx${MACOSX_DEPLOYMENT_TARGET:-11.0}}" - ;; - -march=*|-mcpu=*|-mfloat-abi=*|-mfpu=*|-mmode=*|-mthumb|-marm|-mtune=*|-Werror=*) - [[ i -gt 0 && ${extraBefore[i-1]} == -Xcc ]] && continue - extraBefore=( - "${extraBefore[@]:0:i}" - -Xcc - "${extraBefore[@]:i:${#extraBefore[@]}}" - ) - i=$((i + 1)) - ;; - esac -done - -# As a very special hack, if the arguments are just `-v', then don't -# add anything. This is to prevent `gcc -v' (which normally prints -# out the version number and returns exit code 0) from printing out -# `No input files specified' and returning exit code 1. -if [ "$*" = -v ]; then - extraAfter=() - extraBefore=() -fi - -# Optionally print debug info. -if (( "${NIX_DEBUG:-0}" >= 1 )); then - # Old bash workaround, see ld-wrapper for explanation. - echo "extra flags before to $prog:" >&2 - printf " %q\n" ${extraBefore+"${extraBefore[@]}"} >&2 - echo "original flags to $prog:" >&2 - printf " %q\n" ${params+"${params[@]}"} >&2 - echo "extra flags after to $prog:" >&2 - printf " %q\n" ${extraAfter+"${extraAfter[@]}"} >&2 -fi - -PATH="$path_backup" -# Old bash workaround, see above. - -if (( "${NIX_CC_USE_RESPONSE_FILE:-@use_response_file_by_default@}" >= 1 )); then - exec "$prog" @<(printf "%q\n" \ - ${extraBefore+"${extraBefore[@]}"} \ - ${params+"${params[@]}"} \ - ${extraAfter+"${extraAfter[@]}"}) -else - exec "$prog" \ - ${extraBefore+"${extraBefore[@]}"} \ - ${params+"${params[@]}"} \ - ${extraAfter+"${extraAfter[@]}"} -fi diff --git a/pkgs/development/compilers/swift/xctest/default.nix b/pkgs/development/compilers/swift/xctest/default.nix deleted file mode 100644 index 8b8128c206a6..000000000000 --- a/pkgs/development/compilers/swift/xctest/default.nix +++ /dev/null @@ -1,61 +0,0 @@ -{ - lib, - stdenv, - callPackage, - cmake, - ninja, - swift, - Foundation, - DarwinTools, -}: - -let - sources = callPackage ../sources.nix { }; -in -stdenv.mkDerivation { - pname = "swift-corelibs-xctest"; - - inherit (sources) version; - src = sources.swift-corelibs-xctest; - - outputs = [ "out" ]; - - nativeBuildInputs = [ - cmake - ninja - swift - ] - ++ lib.optional stdenv.hostPlatform.isDarwin DarwinTools; # sw_vers - buildInputs = [ Foundation ]; - - postPatch = lib.optionalString stdenv.hostPlatform.isDarwin '' - # On Darwin only, Swift uses arm64 as cpu arch. - substituteInPlace cmake/modules/SwiftSupport.cmake \ - --replace-fail '"aarch64" PARENT_SCOPE' '"arm64" PARENT_SCOPE' - ''; - - preConfigure = '' - # On aarch64-darwin, our minimum target is 11.0, but we can target lower, - # and some dependants require a lower target. Harmless on non-Darwin. - export MACOSX_DEPLOYMENT_TARGET=10.12 - ''; - - cmakeFlags = lib.optional stdenv.hostPlatform.isDarwin "-DUSE_FOUNDATION_FRAMEWORK=ON"; - - postInstall = lib.optionalString stdenv.hostPlatform.isDarwin '' - # Darwin normally uses the Xcode version of XCTest. Installing - # swift-corelibs-xctest is probably not officially supported, but we have - # no alternative. Fix up the installation here. - mv $out/lib/swift/darwin/${swift.swiftArch}/* $out/lib/swift/darwin - rmdir $out/lib/swift/darwin/${swift.swiftArch} - mv $out/lib/swift/darwin $out/lib/swift/${swift.swiftOs} - ''; - - meta = { - description = "Framework for writing unit tests in Swift"; - homepage = "https://github.com/apple/swift-corelibs-xctest"; - platforms = lib.platforms.all; - license = lib.licenses.asl20; - teams = [ lib.teams.swift ]; - }; -} diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 06d11d13177f..701005953e3e 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -4102,7 +4102,6 @@ with pkgs; ]; }; - swiftPackages = recurseIntoAttrs (callPackage ../development/compilers/swift { }); swiftPackages_ng = recurseIntoAttrs (callPackage ./swift-packages.nix { }); inherit (swiftPackages_ng) fetchSwiftPMDeps From aadf094af6121459c7491dd068e330fbaab8f556 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 271/423] swiftPackages_ng: rename to swiftPackages --- .../by-name/fe/fetchSwiftPMDeps/package.nix | 0 .../by-name/ll/llvmPackages/package.nix | 2 +- .../patches/clang/gnu-install-dirs.patch | 0 .../lldb/0001-Set-stdlib-path-on-Linux.patch | 0 .../0002-Link-lldb-server-to-swiftCore.patch | 0 ...-t-follow-symlinks-when-finding-liblldb.patch | 0 ...LLDB-executable-path-to-find-the-stdlib.patch | 0 .../lldb/backport-ParseTrieEntries-fixes.patch | 0 .../llvm/backport-darwin-triple-parsing.patch | 0 .../llvmPackages/patches/llvm/module-cache.patch | 0 .../by-name/so/sourcekit-lsp/Package.resolved | 0 .../by-name/so/sourcekit-lsp/package.nix | 0 ...r-using-swift-corelibs-xctest-on-Darwin.patch | 0 .../0002-Load-IndexStore-from-the-store.patch | 0 .../by-name/st/stdlib/package.nix | 0 .../files/ArgumentParserConfig.cmake | 0 .../by-name/sw/swift-argument-parser/package.nix | 0 .../0001-install-argument-parser-tool-info.patch | 0 .../sw/swift-asn1/files/SwiftASN1Config.cmake | 0 .../by-name/sw/swift-asn1/package.nix | 0 .../by-name/sw/swift-build/extra-bins/copypng | 0 .../by-name/sw/swift-build/extra-bins/tiffutil | 0 .../sw/swift-build/files/SwiftBuildConfig.cmake | 0 .../by-name/sw/swift-build/package.nix | 0 .../patches/0001-replace-impure-paths.patch | 0 .../0002-treat-nixpkgs-sdk-as-xcode.patch | 0 .../patches/0003-find-bundles-in-store.patch | 0 .../files/SwiftCertificatesConfig.cmake | 0 .../by-name/sw/swift-certificates/package.nix | 0 .../by-name/sw/swift-cmark/package.nix | 0 .../files/SwiftCollectionsConfig.cmake | 0 .../by-name/sw/swift-collections/package.nix | 0 .../files/FoundationConfig.cmake | 0 .../sw/swift-corelibs-foundation/package.nix | 0 .../patches/0001-gnu-install-dirs.patch | 0 ...-SwiftFoundation-and-SwiftFoundationICU.patch | 0 .../files/dispatchConfig.cmake | 0 .../sw/swift-corelibs-libdispatch/package.nix | 0 .../patches/0001-gnu-install-dirs.patch | 0 .../0002-Don-t-include-sys-cdefs-on-Musl.patch | 0 .../by-name/sw/swift-corelibs-xctest/package.nix | 0 .../swift-crypto/files/SwiftCryptoConfig.cmake | 0 .../by-name/sw/swift-crypto/package.nix | 0 .../patches/0001-install-missing-modules.patch | 0 .../by-name/sw/swift-docc-render/package.nix | 0 .../by-name/sw/swift-docc/package.nix | 0 .../swift-driver/files/SwiftDriverConfig.cmake | 0 .../by-name/sw/swift-driver/package.nix | 0 .../patches/0001-gnu-install-dirs.patch | 0 ...iftPM-products-when-building-with-CMake.patch | 0 .../0003-Search-PATH-for-subcommands.patch | 0 ...elp-the-repl-find-the-stdlib-in-Nixpkgs.patch | 0 .../tests/not-in-toolchain/package.nix | 0 .../tests/swift-not-on-path/package.nix | 0 .../by-name/sw/swift-format/Package.resolved | 0 .../by-name/sw/swift-format/package.nix | 0 .../files/SwiftFoundationICUConfig.cmake | 0 .../by-name/sw/swift-foundation-icu/package.nix | 0 .../files/SwiftFoundationConfig.cmake | 0 .../by-name/sw/swift-foundation/package.nix | 0 .../patches/0001-gnu-install-dirs.patch | 0 .../0002-Devendor-SwiftFoundationICU.patch | 0 .../sw/swift-llbuild/files/LLBuildConfig.cmake | 0 .../by-name/sw/swift-llbuild/package.nix | 0 .../patches/0001-gnu-install-dirs.patch | 0 .../swift-syntax/files/SwiftSyntaxConfig.cmake | 0 .../by-name/sw/swift-syntax/package.nix | 0 .../patches/0001-gnu-install-dirs.patch | 0 .../swift-system/files/SwiftSystemConfig.cmake | 0 .../by-name/sw/swift-system/package.nix | 0 .../patches/0001-gnu-install-dirs.patch | 0 .../by-name/sw/swift-testing/package.nix | 0 .../patches/0001-gnu-install-dirs.patch | 0 .../files/TSCConfig.cmake | 0 .../sw/swift-tools-support-core/package.nix | 0 .../patches/0001-build-SwiftToolsSupport.patch | 0 .../by-name/sw/swift/package.nix | 0 .../by-name/sw/swift/setup-hook.sh | 0 .../sw/swift/tests/cxx-interop/package.nix | 0 .../sw/swift/tests/cxx-interop/src/Makefile | 0 .../sw/swift/tests/cxx-interop/src/Package.swift | 0 .../cxx-interop/src/Sources/SwiftStruct.swift | 0 .../tests/cxx-interop/src/Sources/main.swift | 0 .../sw/swift/tests/cxx-interop/src/main.cpp | 0 .../sw/swift/tests/differentiation/package.nix | 0 .../tests/differentiation/src/Package.swift | 0 .../tests/differentiation/src/Sources/main.swift | 0 .../sw/swift/tests/foundation-macros/package.nix | 0 .../tests/foundation-macros/src/Package.swift | 0 .../foundation-macros/src/Sources/main.swift | 0 .../by-name/sw/swift/tests/repl/package.nix | 0 .../by-name/sw/swift/tests/scripting/package.nix | 0 .../sw/swift/tests/scripting/script.swift | 0 .../sw/swift/tests/swift-testing/package.nix | 0 .../swift/tests/swift-testing/src/Package.swift | 0 .../tests/swift-testing/src/Sources/Hello.swift | 0 .../swift-testing/src/Tests/HelloTests.swift | 0 .../by-name/sw/swiftc/package.nix | 0 ...-stdlib-flags-from-the-wrapped-compiler.patch | 0 ...s-C-and-C-stdlib-paths-in-ClangImporter.patch | 0 .../swiftc/patches/0003-cmark-build-revamp.patch | 0 .../patches/0004-sil-missing-headers.patch | 0 .../patches/0005-specify-liblto-path.patch | 0 .../patches/0006-use-nixpkgs-libdispatch.patch | 0 ...T-find-the-separate-stdlib-and-framewor.patch | 0 .../patches/0008-revert-optimizer-changes.patch | 0 .../0009-siloptimizer-bootstrap-workaround.patch | 0 ...ency-on-_StringProcessing-during-stage-.patch | 0 .../by-name/sw/swiftly/package.nix | 0 .../by-name/sw/swiftpm/package.nix | 0 .../swiftpm/patches/0001-gnu-install-dirs.patch | 0 .../0002-darwin-swift-corelibs-xctest.patch | 0 .../swiftpm/patches/0003-disable-sandbox.patch | 0 .../swiftpm/patches/0005-fix-manifest-path.patch | 0 .../swiftpm/patches/0006-nix-build-caches.patch | 0 .../patches/0007-nix-pkgconfig-vars.patch | 0 .../patches/0008-set-compiler-vendor.patch | 0 .../patches/0009-add-missing-libraries.patch | 0 .../0010-Load-IndexStore-from-the-store.patch | 0 ...0011-Always-find-Clang-in-the-toolchain.patch | 0 .../backdeploy-references-stdlib/package.nix | 0 .../src/Package.swift | 0 .../src/Sources/main.swift | 0 .../by-name/sw/swiftpm2nix/package.nix | 0 .../by-name/sw/swiftpm2nix/support.nix | 0 .../by-name/sw/swiftpm2nix/swiftpm2nix.sh | 0 .../by-name/sw/swiftpmHook/package.nix | 0 .../by-name/sw/swiftpmHook/setup-hook.sh | 0 .../by-name/sw/swiftpmUnpackHook/package.nix | 0 .../by-name/sw/swiftpmUnpackHook/setup-hook.sh | 0 .../{swift_ng => swift}/sources-6.2.json | 0 pkgs/top-level/all-packages.nix | 4 ++-- pkgs/top-level/swift-packages.nix | 16 +++++++--------- 133 files changed, 10 insertions(+), 12 deletions(-) rename pkgs/development/compilers/{swift_ng => swift}/by-name/fe/fetchSwiftPMDeps/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/ll/llvmPackages/package.nix (99%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/ll/llvmPackages/patches/clang/gnu-install-dirs.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/ll/llvmPackages/patches/lldb/0001-Set-stdlib-path-on-Linux.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/ll/llvmPackages/patches/lldb/0002-Link-lldb-server-to-swiftCore.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/ll/llvmPackages/patches/lldb/0003-Don-t-follow-symlinks-when-finding-liblldb.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/ll/llvmPackages/patches/lldb/0004-Use-the-LLDB-executable-path-to-find-the-stdlib.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/ll/llvmPackages/patches/lldb/backport-ParseTrieEntries-fixes.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/ll/llvmPackages/patches/llvm/backport-darwin-triple-parsing.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/ll/llvmPackages/patches/llvm/module-cache.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/so/sourcekit-lsp/Package.resolved (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/so/sourcekit-lsp/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/so/sourcekit-lsp/patches/0001-Fix-for-using-swift-corelibs-xctest-on-Darwin.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/so/sourcekit-lsp/patches/0002-Load-IndexStore-from-the-store.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/st/stdlib/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-argument-parser/files/ArgumentParserConfig.cmake (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-argument-parser/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-argument-parser/patches/0001-install-argument-parser-tool-info.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-asn1/files/SwiftASN1Config.cmake (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-asn1/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-build/extra-bins/copypng (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-build/extra-bins/tiffutil (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-build/files/SwiftBuildConfig.cmake (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-build/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-build/patches/0001-replace-impure-paths.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-build/patches/0002-treat-nixpkgs-sdk-as-xcode.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-build/patches/0003-find-bundles-in-store.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-certificates/files/SwiftCertificatesConfig.cmake (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-certificates/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-cmark/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-collections/files/SwiftCollectionsConfig.cmake (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-collections/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-corelibs-foundation/files/FoundationConfig.cmake (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-corelibs-foundation/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-corelibs-foundation/patches/0001-gnu-install-dirs.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-corelibs-foundation/patches/0002-Devendor-SwiftFoundation-and-SwiftFoundationICU.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-corelibs-libdispatch/files/dispatchConfig.cmake (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-corelibs-libdispatch/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-corelibs-libdispatch/patches/0001-gnu-install-dirs.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-corelibs-libdispatch/patches/0002-Don-t-include-sys-cdefs-on-Musl.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-corelibs-xctest/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-crypto/files/SwiftCryptoConfig.cmake (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-crypto/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-crypto/patches/0001-install-missing-modules.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-docc-render/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-docc/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-driver/files/SwiftDriverConfig.cmake (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-driver/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-driver/patches/0001-gnu-install-dirs.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-driver/patches/0002-Match-SwiftPM-products-when-building-with-CMake.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-driver/patches/0003-Search-PATH-for-subcommands.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-driver/patches/0004-Help-the-repl-find-the-stdlib-in-Nixpkgs.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-driver/tests/not-in-toolchain/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-driver/tests/swift-not-on-path/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-format/Package.resolved (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-format/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-foundation-icu/files/SwiftFoundationICUConfig.cmake (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-foundation-icu/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-foundation/files/SwiftFoundationConfig.cmake (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-foundation/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-foundation/patches/0001-gnu-install-dirs.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-foundation/patches/0002-Devendor-SwiftFoundationICU.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-llbuild/files/LLBuildConfig.cmake (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-llbuild/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-llbuild/patches/0001-gnu-install-dirs.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-syntax/files/SwiftSyntaxConfig.cmake (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-syntax/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-syntax/patches/0001-gnu-install-dirs.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-system/files/SwiftSystemConfig.cmake (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-system/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-system/patches/0001-gnu-install-dirs.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-testing/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-testing/patches/0001-gnu-install-dirs.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-tools-support-core/files/TSCConfig.cmake (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-tools-support-core/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift-tools-support-core/patches/0001-build-SwiftToolsSupport.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift/setup-hook.sh (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift/tests/cxx-interop/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift/tests/cxx-interop/src/Makefile (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift/tests/cxx-interop/src/Package.swift (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift/tests/cxx-interop/src/Sources/SwiftStruct.swift (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift/tests/cxx-interop/src/Sources/main.swift (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift/tests/cxx-interop/src/main.cpp (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift/tests/differentiation/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift/tests/differentiation/src/Package.swift (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift/tests/differentiation/src/Sources/main.swift (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift/tests/foundation-macros/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift/tests/foundation-macros/src/Package.swift (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift/tests/foundation-macros/src/Sources/main.swift (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift/tests/repl/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift/tests/scripting/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift/tests/scripting/script.swift (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift/tests/swift-testing/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift/tests/swift-testing/src/Package.swift (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift/tests/swift-testing/src/Sources/Hello.swift (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swift/tests/swift-testing/src/Tests/HelloTests.swift (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftc/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftc/patches/0001-Read-C-and-C-stdlib-flags-from-the-wrapped-compiler.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftc/patches/0002-Use-Nixpkgs-C-and-C-stdlib-paths-in-ClangImporter.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftc/patches/0003-cmark-build-revamp.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftc/patches/0004-sil-missing-headers.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftc/patches/0005-specify-liblto-path.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftc/patches/0006-use-nixpkgs-libdispatch.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftc/patches/0007-Help-Swift-JIT-find-the-separate-stdlib-and-framewor.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftc/patches/0008-revert-optimizer-changes.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftc/patches/0009-siloptimizer-bootstrap-workaround.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftc/patches/0010-Remove-dependency-on-_StringProcessing-during-stage-.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftly/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftpm/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftpm/patches/0001-gnu-install-dirs.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftpm/patches/0002-darwin-swift-corelibs-xctest.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftpm/patches/0003-disable-sandbox.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftpm/patches/0005-fix-manifest-path.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftpm/patches/0006-nix-build-caches.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftpm/patches/0007-nix-pkgconfig-vars.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftpm/patches/0008-set-compiler-vendor.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftpm/patches/0009-add-missing-libraries.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftpm/patches/0010-Load-IndexStore-from-the-store.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftpm/patches/0011-Always-find-Clang-in-the-toolchain.patch (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/src/Package.swift (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/src/Sources/main.swift (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftpm2nix/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftpm2nix/support.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftpm2nix/swiftpm2nix.sh (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftpmHook/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftpmHook/setup-hook.sh (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftpmUnpackHook/package.nix (100%) rename pkgs/development/compilers/{swift_ng => swift}/by-name/sw/swiftpmUnpackHook/setup-hook.sh (100%) rename pkgs/development/compilers/{swift_ng => swift}/sources-6.2.json (100%) diff --git a/pkgs/development/compilers/swift_ng/by-name/fe/fetchSwiftPMDeps/package.nix b/pkgs/development/compilers/swift/by-name/fe/fetchSwiftPMDeps/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/fe/fetchSwiftPMDeps/package.nix rename to pkgs/development/compilers/swift/by-name/fe/fetchSwiftPMDeps/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/package.nix b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/package.nix similarity index 99% rename from pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/package.nix rename to pkgs/development/compilers/swift/by-name/ll/llvmPackages/package.nix index d9725fe5b4c5..646756638d5e 100644 --- a/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/package.nix +++ b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/package.nix @@ -36,7 +36,7 @@ in }; otherSplices = generateSplicesForMkScope [ - "swiftPackages_ng" + "swiftPackages" "llvmPackages" ]; diff --git a/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/clang/gnu-install-dirs.patch b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/clang/gnu-install-dirs.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/clang/gnu-install-dirs.patch rename to pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/clang/gnu-install-dirs.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/lldb/0001-Set-stdlib-path-on-Linux.patch b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/lldb/0001-Set-stdlib-path-on-Linux.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/lldb/0001-Set-stdlib-path-on-Linux.patch rename to pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/lldb/0001-Set-stdlib-path-on-Linux.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/lldb/0002-Link-lldb-server-to-swiftCore.patch b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/lldb/0002-Link-lldb-server-to-swiftCore.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/lldb/0002-Link-lldb-server-to-swiftCore.patch rename to pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/lldb/0002-Link-lldb-server-to-swiftCore.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/lldb/0003-Don-t-follow-symlinks-when-finding-liblldb.patch b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/lldb/0003-Don-t-follow-symlinks-when-finding-liblldb.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/lldb/0003-Don-t-follow-symlinks-when-finding-liblldb.patch rename to pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/lldb/0003-Don-t-follow-symlinks-when-finding-liblldb.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/lldb/0004-Use-the-LLDB-executable-path-to-find-the-stdlib.patch b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/lldb/0004-Use-the-LLDB-executable-path-to-find-the-stdlib.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/lldb/0004-Use-the-LLDB-executable-path-to-find-the-stdlib.patch rename to pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/lldb/0004-Use-the-LLDB-executable-path-to-find-the-stdlib.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/lldb/backport-ParseTrieEntries-fixes.patch b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/lldb/backport-ParseTrieEntries-fixes.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/lldb/backport-ParseTrieEntries-fixes.patch rename to pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/lldb/backport-ParseTrieEntries-fixes.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/llvm/backport-darwin-triple-parsing.patch b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/llvm/backport-darwin-triple-parsing.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/llvm/backport-darwin-triple-parsing.patch rename to pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/llvm/backport-darwin-triple-parsing.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/llvm/module-cache.patch b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/llvm/module-cache.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/ll/llvmPackages/patches/llvm/module-cache.patch rename to pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/llvm/module-cache.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/so/sourcekit-lsp/Package.resolved b/pkgs/development/compilers/swift/by-name/so/sourcekit-lsp/Package.resolved similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/so/sourcekit-lsp/Package.resolved rename to pkgs/development/compilers/swift/by-name/so/sourcekit-lsp/Package.resolved diff --git a/pkgs/development/compilers/swift_ng/by-name/so/sourcekit-lsp/package.nix b/pkgs/development/compilers/swift/by-name/so/sourcekit-lsp/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/so/sourcekit-lsp/package.nix rename to pkgs/development/compilers/swift/by-name/so/sourcekit-lsp/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/so/sourcekit-lsp/patches/0001-Fix-for-using-swift-corelibs-xctest-on-Darwin.patch b/pkgs/development/compilers/swift/by-name/so/sourcekit-lsp/patches/0001-Fix-for-using-swift-corelibs-xctest-on-Darwin.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/so/sourcekit-lsp/patches/0001-Fix-for-using-swift-corelibs-xctest-on-Darwin.patch rename to pkgs/development/compilers/swift/by-name/so/sourcekit-lsp/patches/0001-Fix-for-using-swift-corelibs-xctest-on-Darwin.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/so/sourcekit-lsp/patches/0002-Load-IndexStore-from-the-store.patch b/pkgs/development/compilers/swift/by-name/so/sourcekit-lsp/patches/0002-Load-IndexStore-from-the-store.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/so/sourcekit-lsp/patches/0002-Load-IndexStore-from-the-store.patch rename to pkgs/development/compilers/swift/by-name/so/sourcekit-lsp/patches/0002-Load-IndexStore-from-the-store.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/st/stdlib/package.nix b/pkgs/development/compilers/swift/by-name/st/stdlib/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/st/stdlib/package.nix rename to pkgs/development/compilers/swift/by-name/st/stdlib/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-argument-parser/files/ArgumentParserConfig.cmake b/pkgs/development/compilers/swift/by-name/sw/swift-argument-parser/files/ArgumentParserConfig.cmake similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-argument-parser/files/ArgumentParserConfig.cmake rename to pkgs/development/compilers/swift/by-name/sw/swift-argument-parser/files/ArgumentParserConfig.cmake diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-argument-parser/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-argument-parser/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-argument-parser/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swift-argument-parser/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-argument-parser/patches/0001-install-argument-parser-tool-info.patch b/pkgs/development/compilers/swift/by-name/sw/swift-argument-parser/patches/0001-install-argument-parser-tool-info.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-argument-parser/patches/0001-install-argument-parser-tool-info.patch rename to pkgs/development/compilers/swift/by-name/sw/swift-argument-parser/patches/0001-install-argument-parser-tool-info.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-asn1/files/SwiftASN1Config.cmake b/pkgs/development/compilers/swift/by-name/sw/swift-asn1/files/SwiftASN1Config.cmake similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-asn1/files/SwiftASN1Config.cmake rename to pkgs/development/compilers/swift/by-name/sw/swift-asn1/files/SwiftASN1Config.cmake diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-asn1/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-asn1/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-asn1/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swift-asn1/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-build/extra-bins/copypng b/pkgs/development/compilers/swift/by-name/sw/swift-build/extra-bins/copypng similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-build/extra-bins/copypng rename to pkgs/development/compilers/swift/by-name/sw/swift-build/extra-bins/copypng diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-build/extra-bins/tiffutil b/pkgs/development/compilers/swift/by-name/sw/swift-build/extra-bins/tiffutil similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-build/extra-bins/tiffutil rename to pkgs/development/compilers/swift/by-name/sw/swift-build/extra-bins/tiffutil diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-build/files/SwiftBuildConfig.cmake b/pkgs/development/compilers/swift/by-name/sw/swift-build/files/SwiftBuildConfig.cmake similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-build/files/SwiftBuildConfig.cmake rename to pkgs/development/compilers/swift/by-name/sw/swift-build/files/SwiftBuildConfig.cmake diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-build/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-build/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-build/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swift-build/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-build/patches/0001-replace-impure-paths.patch b/pkgs/development/compilers/swift/by-name/sw/swift-build/patches/0001-replace-impure-paths.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-build/patches/0001-replace-impure-paths.patch rename to pkgs/development/compilers/swift/by-name/sw/swift-build/patches/0001-replace-impure-paths.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-build/patches/0002-treat-nixpkgs-sdk-as-xcode.patch b/pkgs/development/compilers/swift/by-name/sw/swift-build/patches/0002-treat-nixpkgs-sdk-as-xcode.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-build/patches/0002-treat-nixpkgs-sdk-as-xcode.patch rename to pkgs/development/compilers/swift/by-name/sw/swift-build/patches/0002-treat-nixpkgs-sdk-as-xcode.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-build/patches/0003-find-bundles-in-store.patch b/pkgs/development/compilers/swift/by-name/sw/swift-build/patches/0003-find-bundles-in-store.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-build/patches/0003-find-bundles-in-store.patch rename to pkgs/development/compilers/swift/by-name/sw/swift-build/patches/0003-find-bundles-in-store.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-certificates/files/SwiftCertificatesConfig.cmake b/pkgs/development/compilers/swift/by-name/sw/swift-certificates/files/SwiftCertificatesConfig.cmake similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-certificates/files/SwiftCertificatesConfig.cmake rename to pkgs/development/compilers/swift/by-name/sw/swift-certificates/files/SwiftCertificatesConfig.cmake diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-certificates/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-certificates/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-certificates/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swift-certificates/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-cmark/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-cmark/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-cmark/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swift-cmark/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-collections/files/SwiftCollectionsConfig.cmake b/pkgs/development/compilers/swift/by-name/sw/swift-collections/files/SwiftCollectionsConfig.cmake similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-collections/files/SwiftCollectionsConfig.cmake rename to pkgs/development/compilers/swift/by-name/sw/swift-collections/files/SwiftCollectionsConfig.cmake diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-collections/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-collections/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-collections/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swift-collections/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-foundation/files/FoundationConfig.cmake b/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-foundation/files/FoundationConfig.cmake similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-foundation/files/FoundationConfig.cmake rename to pkgs/development/compilers/swift/by-name/sw/swift-corelibs-foundation/files/FoundationConfig.cmake diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-foundation/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-foundation/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-foundation/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swift-corelibs-foundation/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-foundation/patches/0001-gnu-install-dirs.patch b/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-foundation/patches/0001-gnu-install-dirs.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-foundation/patches/0001-gnu-install-dirs.patch rename to pkgs/development/compilers/swift/by-name/sw/swift-corelibs-foundation/patches/0001-gnu-install-dirs.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-foundation/patches/0002-Devendor-SwiftFoundation-and-SwiftFoundationICU.patch b/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-foundation/patches/0002-Devendor-SwiftFoundation-and-SwiftFoundationICU.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-foundation/patches/0002-Devendor-SwiftFoundation-and-SwiftFoundationICU.patch rename to pkgs/development/compilers/swift/by-name/sw/swift-corelibs-foundation/patches/0002-Devendor-SwiftFoundation-and-SwiftFoundationICU.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-libdispatch/files/dispatchConfig.cmake b/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-libdispatch/files/dispatchConfig.cmake similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-libdispatch/files/dispatchConfig.cmake rename to pkgs/development/compilers/swift/by-name/sw/swift-corelibs-libdispatch/files/dispatchConfig.cmake diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-libdispatch/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-libdispatch/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-libdispatch/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swift-corelibs-libdispatch/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-libdispatch/patches/0001-gnu-install-dirs.patch b/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-libdispatch/patches/0001-gnu-install-dirs.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-libdispatch/patches/0001-gnu-install-dirs.patch rename to pkgs/development/compilers/swift/by-name/sw/swift-corelibs-libdispatch/patches/0001-gnu-install-dirs.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-libdispatch/patches/0002-Don-t-include-sys-cdefs-on-Musl.patch b/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-libdispatch/patches/0002-Don-t-include-sys-cdefs-on-Musl.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-libdispatch/patches/0002-Don-t-include-sys-cdefs-on-Musl.patch rename to pkgs/development/compilers/swift/by-name/sw/swift-corelibs-libdispatch/patches/0002-Don-t-include-sys-cdefs-on-Musl.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-xctest/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-corelibs-xctest/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-corelibs-xctest/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swift-corelibs-xctest/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-crypto/files/SwiftCryptoConfig.cmake b/pkgs/development/compilers/swift/by-name/sw/swift-crypto/files/SwiftCryptoConfig.cmake similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-crypto/files/SwiftCryptoConfig.cmake rename to pkgs/development/compilers/swift/by-name/sw/swift-crypto/files/SwiftCryptoConfig.cmake diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-crypto/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-crypto/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-crypto/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swift-crypto/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-crypto/patches/0001-install-missing-modules.patch b/pkgs/development/compilers/swift/by-name/sw/swift-crypto/patches/0001-install-missing-modules.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-crypto/patches/0001-install-missing-modules.patch rename to pkgs/development/compilers/swift/by-name/sw/swift-crypto/patches/0001-install-missing-modules.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-docc-render/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-docc-render/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-docc-render/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swift-docc-render/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-docc/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-docc/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-docc/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swift-docc/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/files/SwiftDriverConfig.cmake b/pkgs/development/compilers/swift/by-name/sw/swift-driver/files/SwiftDriverConfig.cmake similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/files/SwiftDriverConfig.cmake rename to pkgs/development/compilers/swift/by-name/sw/swift-driver/files/SwiftDriverConfig.cmake diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-driver/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swift-driver/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/patches/0001-gnu-install-dirs.patch b/pkgs/development/compilers/swift/by-name/sw/swift-driver/patches/0001-gnu-install-dirs.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/patches/0001-gnu-install-dirs.patch rename to pkgs/development/compilers/swift/by-name/sw/swift-driver/patches/0001-gnu-install-dirs.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/patches/0002-Match-SwiftPM-products-when-building-with-CMake.patch b/pkgs/development/compilers/swift/by-name/sw/swift-driver/patches/0002-Match-SwiftPM-products-when-building-with-CMake.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/patches/0002-Match-SwiftPM-products-when-building-with-CMake.patch rename to pkgs/development/compilers/swift/by-name/sw/swift-driver/patches/0002-Match-SwiftPM-products-when-building-with-CMake.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/patches/0003-Search-PATH-for-subcommands.patch b/pkgs/development/compilers/swift/by-name/sw/swift-driver/patches/0003-Search-PATH-for-subcommands.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/patches/0003-Search-PATH-for-subcommands.patch rename to pkgs/development/compilers/swift/by-name/sw/swift-driver/patches/0003-Search-PATH-for-subcommands.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/patches/0004-Help-the-repl-find-the-stdlib-in-Nixpkgs.patch b/pkgs/development/compilers/swift/by-name/sw/swift-driver/patches/0004-Help-the-repl-find-the-stdlib-in-Nixpkgs.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/patches/0004-Help-the-repl-find-the-stdlib-in-Nixpkgs.patch rename to pkgs/development/compilers/swift/by-name/sw/swift-driver/patches/0004-Help-the-repl-find-the-stdlib-in-Nixpkgs.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/tests/not-in-toolchain/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-driver/tests/not-in-toolchain/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/tests/not-in-toolchain/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swift-driver/tests/not-in-toolchain/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/tests/swift-not-on-path/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-driver/tests/swift-not-on-path/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-driver/tests/swift-not-on-path/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swift-driver/tests/swift-not-on-path/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-format/Package.resolved b/pkgs/development/compilers/swift/by-name/sw/swift-format/Package.resolved similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-format/Package.resolved rename to pkgs/development/compilers/swift/by-name/sw/swift-format/Package.resolved diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-format/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-format/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-format/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swift-format/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-foundation-icu/files/SwiftFoundationICUConfig.cmake b/pkgs/development/compilers/swift/by-name/sw/swift-foundation-icu/files/SwiftFoundationICUConfig.cmake similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-foundation-icu/files/SwiftFoundationICUConfig.cmake rename to pkgs/development/compilers/swift/by-name/sw/swift-foundation-icu/files/SwiftFoundationICUConfig.cmake diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-foundation-icu/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-foundation-icu/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-foundation-icu/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swift-foundation-icu/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-foundation/files/SwiftFoundationConfig.cmake b/pkgs/development/compilers/swift/by-name/sw/swift-foundation/files/SwiftFoundationConfig.cmake similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-foundation/files/SwiftFoundationConfig.cmake rename to pkgs/development/compilers/swift/by-name/sw/swift-foundation/files/SwiftFoundationConfig.cmake diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-foundation/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-foundation/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-foundation/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swift-foundation/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-foundation/patches/0001-gnu-install-dirs.patch b/pkgs/development/compilers/swift/by-name/sw/swift-foundation/patches/0001-gnu-install-dirs.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-foundation/patches/0001-gnu-install-dirs.patch rename to pkgs/development/compilers/swift/by-name/sw/swift-foundation/patches/0001-gnu-install-dirs.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-foundation/patches/0002-Devendor-SwiftFoundationICU.patch b/pkgs/development/compilers/swift/by-name/sw/swift-foundation/patches/0002-Devendor-SwiftFoundationICU.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-foundation/patches/0002-Devendor-SwiftFoundationICU.patch rename to pkgs/development/compilers/swift/by-name/sw/swift-foundation/patches/0002-Devendor-SwiftFoundationICU.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-llbuild/files/LLBuildConfig.cmake b/pkgs/development/compilers/swift/by-name/sw/swift-llbuild/files/LLBuildConfig.cmake similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-llbuild/files/LLBuildConfig.cmake rename to pkgs/development/compilers/swift/by-name/sw/swift-llbuild/files/LLBuildConfig.cmake diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-llbuild/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-llbuild/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-llbuild/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swift-llbuild/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-llbuild/patches/0001-gnu-install-dirs.patch b/pkgs/development/compilers/swift/by-name/sw/swift-llbuild/patches/0001-gnu-install-dirs.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-llbuild/patches/0001-gnu-install-dirs.patch rename to pkgs/development/compilers/swift/by-name/sw/swift-llbuild/patches/0001-gnu-install-dirs.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-syntax/files/SwiftSyntaxConfig.cmake b/pkgs/development/compilers/swift/by-name/sw/swift-syntax/files/SwiftSyntaxConfig.cmake similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-syntax/files/SwiftSyntaxConfig.cmake rename to pkgs/development/compilers/swift/by-name/sw/swift-syntax/files/SwiftSyntaxConfig.cmake diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-syntax/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-syntax/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-syntax/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swift-syntax/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-syntax/patches/0001-gnu-install-dirs.patch b/pkgs/development/compilers/swift/by-name/sw/swift-syntax/patches/0001-gnu-install-dirs.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-syntax/patches/0001-gnu-install-dirs.patch rename to pkgs/development/compilers/swift/by-name/sw/swift-syntax/patches/0001-gnu-install-dirs.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-system/files/SwiftSystemConfig.cmake b/pkgs/development/compilers/swift/by-name/sw/swift-system/files/SwiftSystemConfig.cmake similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-system/files/SwiftSystemConfig.cmake rename to pkgs/development/compilers/swift/by-name/sw/swift-system/files/SwiftSystemConfig.cmake diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-system/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-system/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-system/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swift-system/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-system/patches/0001-gnu-install-dirs.patch b/pkgs/development/compilers/swift/by-name/sw/swift-system/patches/0001-gnu-install-dirs.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-system/patches/0001-gnu-install-dirs.patch rename to pkgs/development/compilers/swift/by-name/sw/swift-system/patches/0001-gnu-install-dirs.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-testing/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-testing/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-testing/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swift-testing/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-testing/patches/0001-gnu-install-dirs.patch b/pkgs/development/compilers/swift/by-name/sw/swift-testing/patches/0001-gnu-install-dirs.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-testing/patches/0001-gnu-install-dirs.patch rename to pkgs/development/compilers/swift/by-name/sw/swift-testing/patches/0001-gnu-install-dirs.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-tools-support-core/files/TSCConfig.cmake b/pkgs/development/compilers/swift/by-name/sw/swift-tools-support-core/files/TSCConfig.cmake similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-tools-support-core/files/TSCConfig.cmake rename to pkgs/development/compilers/swift/by-name/sw/swift-tools-support-core/files/TSCConfig.cmake diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-tools-support-core/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift-tools-support-core/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-tools-support-core/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swift-tools-support-core/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift-tools-support-core/patches/0001-build-SwiftToolsSupport.patch b/pkgs/development/compilers/swift/by-name/sw/swift-tools-support-core/patches/0001-build-SwiftToolsSupport.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift-tools-support-core/patches/0001-build-SwiftToolsSupport.patch rename to pkgs/development/compilers/swift/by-name/sw/swift-tools-support-core/patches/0001-build-SwiftToolsSupport.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swift/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/setup-hook.sh b/pkgs/development/compilers/swift/by-name/sw/swift/setup-hook.sh similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift/setup-hook.sh rename to pkgs/development/compilers/swift/by-name/sw/swift/setup-hook.sh diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift/tests/cxx-interop/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swift/tests/cxx-interop/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/src/Makefile b/pkgs/development/compilers/swift/by-name/sw/swift/tests/cxx-interop/src/Makefile similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/src/Makefile rename to pkgs/development/compilers/swift/by-name/sw/swift/tests/cxx-interop/src/Makefile diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/src/Package.swift b/pkgs/development/compilers/swift/by-name/sw/swift/tests/cxx-interop/src/Package.swift similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/src/Package.swift rename to pkgs/development/compilers/swift/by-name/sw/swift/tests/cxx-interop/src/Package.swift diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/src/Sources/SwiftStruct.swift b/pkgs/development/compilers/swift/by-name/sw/swift/tests/cxx-interop/src/Sources/SwiftStruct.swift similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/src/Sources/SwiftStruct.swift rename to pkgs/development/compilers/swift/by-name/sw/swift/tests/cxx-interop/src/Sources/SwiftStruct.swift diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/src/Sources/main.swift b/pkgs/development/compilers/swift/by-name/sw/swift/tests/cxx-interop/src/Sources/main.swift similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/src/Sources/main.swift rename to pkgs/development/compilers/swift/by-name/sw/swift/tests/cxx-interop/src/Sources/main.swift diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/src/main.cpp b/pkgs/development/compilers/swift/by-name/sw/swift/tests/cxx-interop/src/main.cpp similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/cxx-interop/src/main.cpp rename to pkgs/development/compilers/swift/by-name/sw/swift/tests/cxx-interop/src/main.cpp diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/differentiation/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift/tests/differentiation/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/differentiation/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swift/tests/differentiation/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/differentiation/src/Package.swift b/pkgs/development/compilers/swift/by-name/sw/swift/tests/differentiation/src/Package.swift similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/differentiation/src/Package.swift rename to pkgs/development/compilers/swift/by-name/sw/swift/tests/differentiation/src/Package.swift diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/differentiation/src/Sources/main.swift b/pkgs/development/compilers/swift/by-name/sw/swift/tests/differentiation/src/Sources/main.swift similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/differentiation/src/Sources/main.swift rename to pkgs/development/compilers/swift/by-name/sw/swift/tests/differentiation/src/Sources/main.swift diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/foundation-macros/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift/tests/foundation-macros/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/foundation-macros/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swift/tests/foundation-macros/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/foundation-macros/src/Package.swift b/pkgs/development/compilers/swift/by-name/sw/swift/tests/foundation-macros/src/Package.swift similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/foundation-macros/src/Package.swift rename to pkgs/development/compilers/swift/by-name/sw/swift/tests/foundation-macros/src/Package.swift diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/foundation-macros/src/Sources/main.swift b/pkgs/development/compilers/swift/by-name/sw/swift/tests/foundation-macros/src/Sources/main.swift similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/foundation-macros/src/Sources/main.swift rename to pkgs/development/compilers/swift/by-name/sw/swift/tests/foundation-macros/src/Sources/main.swift diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/repl/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift/tests/repl/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/repl/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swift/tests/repl/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/scripting/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift/tests/scripting/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/scripting/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swift/tests/scripting/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/scripting/script.swift b/pkgs/development/compilers/swift/by-name/sw/swift/tests/scripting/script.swift similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/scripting/script.swift rename to pkgs/development/compilers/swift/by-name/sw/swift/tests/scripting/script.swift diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/swift-testing/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift/tests/swift-testing/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/swift-testing/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swift/tests/swift-testing/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/swift-testing/src/Package.swift b/pkgs/development/compilers/swift/by-name/sw/swift/tests/swift-testing/src/Package.swift similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/swift-testing/src/Package.swift rename to pkgs/development/compilers/swift/by-name/sw/swift/tests/swift-testing/src/Package.swift diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/swift-testing/src/Sources/Hello.swift b/pkgs/development/compilers/swift/by-name/sw/swift/tests/swift-testing/src/Sources/Hello.swift similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/swift-testing/src/Sources/Hello.swift rename to pkgs/development/compilers/swift/by-name/sw/swift/tests/swift-testing/src/Sources/Hello.swift diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/swift-testing/src/Tests/HelloTests.swift b/pkgs/development/compilers/swift/by-name/sw/swift/tests/swift-testing/src/Tests/HelloTests.swift similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swift/tests/swift-testing/src/Tests/HelloTests.swift rename to pkgs/development/compilers/swift/by-name/sw/swift/tests/swift-testing/src/Tests/HelloTests.swift diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/package.nix b/pkgs/development/compilers/swift/by-name/sw/swiftc/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftc/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swiftc/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0001-Read-C-and-C-stdlib-flags-from-the-wrapped-compiler.patch b/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0001-Read-C-and-C-stdlib-flags-from-the-wrapped-compiler.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0001-Read-C-and-C-stdlib-flags-from-the-wrapped-compiler.patch rename to pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0001-Read-C-and-C-stdlib-flags-from-the-wrapped-compiler.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0002-Use-Nixpkgs-C-and-C-stdlib-paths-in-ClangImporter.patch b/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0002-Use-Nixpkgs-C-and-C-stdlib-paths-in-ClangImporter.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0002-Use-Nixpkgs-C-and-C-stdlib-paths-in-ClangImporter.patch rename to pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0002-Use-Nixpkgs-C-and-C-stdlib-paths-in-ClangImporter.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0003-cmark-build-revamp.patch b/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0003-cmark-build-revamp.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0003-cmark-build-revamp.patch rename to pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0003-cmark-build-revamp.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0004-sil-missing-headers.patch b/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0004-sil-missing-headers.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0004-sil-missing-headers.patch rename to pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0004-sil-missing-headers.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0005-specify-liblto-path.patch b/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0005-specify-liblto-path.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0005-specify-liblto-path.patch rename to pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0005-specify-liblto-path.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0006-use-nixpkgs-libdispatch.patch b/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0006-use-nixpkgs-libdispatch.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0006-use-nixpkgs-libdispatch.patch rename to pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0006-use-nixpkgs-libdispatch.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0007-Help-Swift-JIT-find-the-separate-stdlib-and-framewor.patch b/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0007-Help-Swift-JIT-find-the-separate-stdlib-and-framewor.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0007-Help-Swift-JIT-find-the-separate-stdlib-and-framewor.patch rename to pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0007-Help-Swift-JIT-find-the-separate-stdlib-and-framewor.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0008-revert-optimizer-changes.patch b/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0008-revert-optimizer-changes.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0008-revert-optimizer-changes.patch rename to pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0008-revert-optimizer-changes.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0009-siloptimizer-bootstrap-workaround.patch b/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0009-siloptimizer-bootstrap-workaround.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0009-siloptimizer-bootstrap-workaround.patch rename to pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0009-siloptimizer-bootstrap-workaround.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0010-Remove-dependency-on-_StringProcessing-during-stage-.patch b/pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0010-Remove-dependency-on-_StringProcessing-during-stage-.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftc/patches/0010-Remove-dependency-on-_StringProcessing-during-stage-.patch rename to pkgs/development/compilers/swift/by-name/sw/swiftc/patches/0010-Remove-dependency-on-_StringProcessing-during-stage-.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftly/package.nix b/pkgs/development/compilers/swift/by-name/sw/swiftly/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftly/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swiftly/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/package.nix b/pkgs/development/compilers/swift/by-name/sw/swiftpm/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swiftpm/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0001-gnu-install-dirs.patch b/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0001-gnu-install-dirs.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0001-gnu-install-dirs.patch rename to pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0001-gnu-install-dirs.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0002-darwin-swift-corelibs-xctest.patch b/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0002-darwin-swift-corelibs-xctest.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0002-darwin-swift-corelibs-xctest.patch rename to pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0002-darwin-swift-corelibs-xctest.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0003-disable-sandbox.patch b/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0003-disable-sandbox.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0003-disable-sandbox.patch rename to pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0003-disable-sandbox.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0005-fix-manifest-path.patch b/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0005-fix-manifest-path.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0005-fix-manifest-path.patch rename to pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0005-fix-manifest-path.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0006-nix-build-caches.patch b/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0006-nix-build-caches.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0006-nix-build-caches.patch rename to pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0006-nix-build-caches.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0007-nix-pkgconfig-vars.patch b/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0007-nix-pkgconfig-vars.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0007-nix-pkgconfig-vars.patch rename to pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0007-nix-pkgconfig-vars.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0008-set-compiler-vendor.patch b/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0008-set-compiler-vendor.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0008-set-compiler-vendor.patch rename to pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0008-set-compiler-vendor.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0009-add-missing-libraries.patch b/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0009-add-missing-libraries.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0009-add-missing-libraries.patch rename to pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0009-add-missing-libraries.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0010-Load-IndexStore-from-the-store.patch b/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0010-Load-IndexStore-from-the-store.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0010-Load-IndexStore-from-the-store.patch rename to pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0010-Load-IndexStore-from-the-store.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0011-Always-find-Clang-in-the-toolchain.patch b/pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0011-Always-find-Clang-in-the-toolchain.patch similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/patches/0011-Always-find-Clang-in-the-toolchain.patch rename to pkgs/development/compilers/swift/by-name/sw/swiftpm/patches/0011-Always-find-Clang-in-the-toolchain.patch diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/package.nix b/pkgs/development/compilers/swift/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/src/Package.swift b/pkgs/development/compilers/swift/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/src/Package.swift similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/src/Package.swift rename to pkgs/development/compilers/swift/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/src/Package.swift diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/src/Sources/main.swift b/pkgs/development/compilers/swift/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/src/Sources/main.swift similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/src/Sources/main.swift rename to pkgs/development/compilers/swift/by-name/sw/swiftpm/tests/backdeploy-references-stdlib/src/Sources/main.swift diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm2nix/package.nix b/pkgs/development/compilers/swift/by-name/sw/swiftpm2nix/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftpm2nix/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swiftpm2nix/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm2nix/support.nix b/pkgs/development/compilers/swift/by-name/sw/swiftpm2nix/support.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftpm2nix/support.nix rename to pkgs/development/compilers/swift/by-name/sw/swiftpm2nix/support.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpm2nix/swiftpm2nix.sh b/pkgs/development/compilers/swift/by-name/sw/swiftpm2nix/swiftpm2nix.sh similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftpm2nix/swiftpm2nix.sh rename to pkgs/development/compilers/swift/by-name/sw/swiftpm2nix/swiftpm2nix.sh diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpmHook/package.nix b/pkgs/development/compilers/swift/by-name/sw/swiftpmHook/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftpmHook/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swiftpmHook/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpmHook/setup-hook.sh b/pkgs/development/compilers/swift/by-name/sw/swiftpmHook/setup-hook.sh similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftpmHook/setup-hook.sh rename to pkgs/development/compilers/swift/by-name/sw/swiftpmHook/setup-hook.sh diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpmUnpackHook/package.nix b/pkgs/development/compilers/swift/by-name/sw/swiftpmUnpackHook/package.nix similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftpmUnpackHook/package.nix rename to pkgs/development/compilers/swift/by-name/sw/swiftpmUnpackHook/package.nix diff --git a/pkgs/development/compilers/swift_ng/by-name/sw/swiftpmUnpackHook/setup-hook.sh b/pkgs/development/compilers/swift/by-name/sw/swiftpmUnpackHook/setup-hook.sh similarity index 100% rename from pkgs/development/compilers/swift_ng/by-name/sw/swiftpmUnpackHook/setup-hook.sh rename to pkgs/development/compilers/swift/by-name/sw/swiftpmUnpackHook/setup-hook.sh diff --git a/pkgs/development/compilers/swift_ng/sources-6.2.json b/pkgs/development/compilers/swift/sources-6.2.json similarity index 100% rename from pkgs/development/compilers/swift_ng/sources-6.2.json rename to pkgs/development/compilers/swift/sources-6.2.json diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 701005953e3e..9f40dbed0e69 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -4102,8 +4102,8 @@ with pkgs; ]; }; - swiftPackages_ng = recurseIntoAttrs (callPackage ./swift-packages.nix { }); - inherit (swiftPackages_ng) + swiftPackages = recurseIntoAttrs (callPackage ./swift-packages.nix { }); + inherit (swiftPackages) fetchSwiftPMDeps sourcekit-lsp swift diff --git a/pkgs/top-level/swift-packages.nix b/pkgs/top-level/swift-packages.nix index b5339f4f3826..5f3bab8c48ab 100644 --- a/pkgs/top-level/swift-packages.nix +++ b/pkgs/top-level/swift-packages.nix @@ -1,8 +1,8 @@ let - autoCalledPackages = import ./by-name-overlay.nix ../development/compilers/swift_ng/by-name; + autoCalledPackages = import ./by-name-overlay.nix ../development/compilers/swift/by-name; swift_sources_6_2 = builtins.fromJSON ( - builtins.readFile ../development/compilers/swift_ng/sources-6.2.json + builtins.readFile ../development/compilers/swift/sources-6.2.json ); mkBootstrapSwiftPackages = @@ -51,8 +51,8 @@ in llvmPackages, makeScopeWithSplicing', stdenvNoCC, - swiftPackages_ng, - otherSplices ? generateSplicesForMkScope "swiftPackages_ng", + swiftPackages, + otherSplices ? generateSplicesForMkScope "swiftPackages", }: let @@ -61,15 +61,13 @@ let # - Stage 1 builds a Swift compiler using the stage 0 Swift compiler. Features needed to build macros are enabled. # - Stage 2 builds a full Swift compiler and stdlib using the stage 1 compiler. bootstrapStage0SwiftPackages = mkBootstrapSwiftPackages { - inherit lib; - swiftPackages = swiftPackages_ng; + inherit lib swiftPackages; bootstrapStage = 0; - buildSwiftPackages = swiftPackages_ng.overrideScope (_: _: { swift = null; }); + buildSwiftPackages = swiftPackages.overrideScope (_: _: { swift = null; }); }; bootstrapStage1SwiftPackages = mkBootstrapSwiftPackages { - inherit lib; - swiftPackages = swiftPackages_ng; + inherit lib swiftPackages; bootstrapStage = 1; buildSwiftPackages = bootstrapStage0SwiftPackages; }; From bfd7c65db3d2982014075721742e407df47d405d Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 272/423] doc/stdenv/platform-notes: add note about missing macro libraries --- doc/redirects.json | 3 +++ doc/stdenv/platform-notes.chapter.md | 7 +++++++ 2 files changed, 10 insertions(+) diff --git a/doc/redirects.json b/doc/redirects.json index 23197cbdaee7..0bafda225709 100644 --- a/doc/redirects.json +++ b/doc/redirects.json @@ -1981,6 +1981,9 @@ "sec-darwin-troubleshooting-xcodebuild-absolute-paths": [ "index.html#sec-darwin-troubleshooting-xcodebuild-absolute-paths" ], + "sec-darwin-missing-macros": [ + "index.html#sec-darwin-missing-macros" + ], "sec-darwin-troubleshooting-libiconv": [ "index.html#sec-darwin-troubleshooting-libiconv" ], diff --git a/doc/stdenv/platform-notes.chapter.md b/doc/stdenv/platform-notes.chapter.md index 2aeee55ba2cd..fac864ad210b 100644 --- a/doc/stdenv/platform-notes.chapter.md +++ b/doc/stdenv/platform-notes.chapter.md @@ -192,6 +192,13 @@ stdenv.mkDerivation { } ``` +### Macro library not available {#sec-darwin-missing-macros} + +Some frameworks provide macros that are only shipped with Xcode. +For example, the AppleIntelligence framework, Swift Data, and SwiftUI (as of the 27.0 SDK). +A non-free package making these available will be added at a later date. +Until then, they are unfortunately not available in Nixpkgs. + #### How to use libiconv on Darwin {#sec-darwin-troubleshooting-libiconv} The libiconv package is included in the SDK by default along with libresolv and libsbuf. From be9fc8210149b5300e1d6fbe962176a8f15e0f51 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 273/423] doc: update Swift documentation for the new packaging --- doc/languages-frameworks/swift.section.md | 222 ++++++++++++++-------- doc/redirects.json | 19 +- 2 files changed, 159 insertions(+), 82 deletions(-) diff --git a/doc/languages-frameworks/swift.section.md b/doc/languages-frameworks/swift.section.md index 76e4962fe9e3..eb826246613f 100644 --- a/doc/languages-frameworks/swift.section.md +++ b/doc/languages-frameworks/swift.section.md @@ -11,47 +11,86 @@ nix-shell -p swift --run 'swiftc -' <<< 'print("Hello world!")' The `swift` package also provides the `swift` command, with some caveats: -- Swift Package Manager (SwiftPM) is packaged separately as `swiftpm`. If you - need functionality like `swift build`, `swift run`, `swift test`, you must - also add the `swiftpm` package to your closure. -- On Darwin, the `swift repl` command requires an Xcode installation. This is - because it uses the system LLDB debugserver, which has special entitlements. +- Swift Package Manager (SwiftPM) is packaged separately as `swiftpm`. + If you need functionality like `swift build`, `swift run`, `swift test`, you must also add the `swiftpm` package to your closure. +- On Darwin, the `swift repl` command requires an Xcode installation. + This is because it uses the system LLDB debugserver, which has special entitlements. ## Module search paths {#ssec-swift-module-search-paths} -Like other toolchains in Nixpkgs, the Swift compiler executables are wrapped -to help Swift find your application's dependencies in the Nix store. These -wrappers scan the `buildInputs` of your package derivation for specific -directories where Swift modules are placed by convention, and automatically -add those directories to the Swift compiler search paths. +The Swift compiler executables are patched to find the C and C++ standard libraries associated with its target platform, but they are not wrapped. +They will not find your application’s dependencies automatically in the Nix store. +Your build system is expected to handle this for you. -Swift follows different conventions depending on the platform. The wrappers -look for the following directories: +SwiftPM provides a hook that scans the `buildInputs` of your package derivation for specific directories where the Swift modules are placed by convention. +These directories are added automatically to `swiftpmFlags` when the hook runs. +Swift in Nixpkgs follows a few conventions when installing dependencies: -- On Darwin platforms: `lib/swift/macosx` - (If not targeting macOS, replace `macosx` with the Xcode platform name.) -- On other platforms: `lib/swift/linux/x86_64` - (Where `linux` and `x86_64` are from lowercase `uname -sm`.) -- For convenience, Nixpkgs also adds `lib/swift` to the search path. - This can save a bit of work packaging Swift modules, because many Nix builds - will produce output for just one target anyway. +- Libraries (both shared and static) are installed to `lib`. + This differs from upstream packaging, but it matches how other langauges are packaged in Nixpkgs. + This allows Swift packages to take advantage of existing tooling that expects libraries to be installed in this standard location. +- Modules are installed to `lib/swift/` where `` is the Swift platform for your host platform (e.g., `lib/swift/macosx` or `lib/swift/linux`). + Note that Linux modules may be installed in a directory specific to the target architecture(e.g., `lib/swift/linux/x86_64`), but this is uncommon. + Upstream Swift appears to be moving away from this convention. ## Core libraries {#ssec-swift-core-libraries} -In addition to the standard library, the Swift toolchain contains some -additional 'core libraries' that, on Apple platforms, are normally distributed -as part of the OS or Xcode. These are packaged separately in Nixpkgs and can -be found (for use in `buildInputs`) as: +The `swift` package contains a complete toolchain with the Swift stdlib, Dispatch, Foundation, XCTest, and Swift Testing. +These packages do not need to be added to `buildInputs` when packaging applications. +The Swift compiler will find them automatically in the `swift` toolchain. -- `swiftPackages.Dispatch` -- `swiftPackages.Foundation` -- `swiftPackages.XCTest` +If you do need to use these packages outside of the Swift toolchain, they are available in the following packages: + +- `swiftPackages.stdlib` contains the Swift stdlib and backdeployment dylibs. +- `swiftPackages.swift-corelibs-libdispatch` contains the Dispatch framework. +- `swiftPackages.swift-corelibs-foundation` contains the Foundation framework. +- `swiftPackages.swift-corelibs-xctest` and `swiftPackages.swift-testing` contain the XCTest and Swift Testing frameworks respectively. + +Note: On Darwin, the Swift stdlib has been removed from the SDK. +The Swift toolchain contains the stubs and modules required to build Swift applications with the following exceptions: + +- Swift Differentiation is shipped as a dylib in Nixpkgs because it is no longer shipped with the OS (as of macOS 26.4). + This allows packages using Swift Differentiation to work regardless of OS version. +- The Span back-deployment dylib is shipped with the stdlib. +- This is expected because back-deployment dylibs are normally shipped with the toolchain. +- FoundationMacros is built and shipped as a dylib in `swiftPackages.swift-foundation` and included in the toolchain. + Macros are actually compiler plugins executed at build time. + Without this, FoundationMacros would not work on Darwin. ## Packaging with SwiftPM {#ssec-swift-packaging-with-swiftpm} -Nixpkgs includes a small helper `swiftpm2nix` that can fetch your SwiftPM -dependencies for you, when you need to write a Nix expression to package your -application. +Nixpkgs includes two ways to package dependencies for Swift applications: `fetchSwiftPMDeps` and `swiftpm2nix`. +While `swiftpm2nix` is not deprecated, using `fetchSwiftPMDeps` is preferred because it is easier to use and does not (usually) require shipping extra files with your package. + +### Packaging with `fetchSwiftPMDeps` {#ssec-swift-packaging-with-fetch-swiftpm-deps} + +Swift provides a fetcher that will download all of your dependencies based on the `Package.resolved` shipped by your package. +If your package does not ship one, you will have to generate it yourself and provide it with your package. +Otherwise, set `swiftpmDeps` as follows: + +```nix +{ + swiftpmDeps = fetchSwiftPMDeps { + inherit src; + hash = "sha256-1KfyrQXE1HaO9WsuskzgiiEZxM/oelp40Jwzr8xJEL4="; + }; +} +``` + +The `src` attribute is required as is the `hash`. +The first time you build your package, you will need to set `hash` to an empty value by using `lib.fakeHash` to get the hash for your dependencies. +The following optional attributes can also be used: + +- `name`: Sets the name of the vendored dependencies fixed-output derivation. + You can also use `pname` and `version` to set the `name`. + This is often easier because you can inherit them from `finalAttrs`. +- `sourceRoot`: Sets the path where `Package.swift` and `Package.resolved` can be found if they are not in their default, top-level location. +- `patches`: Can be used to apply patches to your project before the dependencies are vendored. + This is useful to update `Package.swift` or `Package.resolved`. +- `postPatch`: Can be used to perform extra steps after patching. + You can copy a custom `Package.resolved` in `postPatch`. + +### Packaging with `swiftpm2nix` {#ssec-swift-packaging-with-swiftpm2nix} The first step is to run the generator: @@ -65,8 +104,8 @@ swift package resolve swiftpm2nix ``` -This produces some files in a directory `nix`, which will be part of your Nix -expression. The next step is to write that expression: +This produces some files in a directory `nix`, which will be part of your Nix expression. +The next step is to write that expression: ```nix { @@ -126,45 +165,13 @@ stdenv.mkDerivation (finalAttrs: { }) ``` -### Custom build flags {#ssec-swiftpm-custom-build-flags} +#### Patching dependencies {#ssec-swiftpm-patching-dependencies} -If you'd like to build a different configuration than `release`: +In some cases, it may be necessary to patch a SwiftPM dependency. +SwiftPM dependencies are located in `.build/checkouts`, but the `swiftpm2nix` helper provides these as symlinks to read-only `/nix/store` paths. +To patch them, we need to make them writable. -```nix -{ swiftpmBuildConfig = "debug"; } -``` - -It is also possible to provide additional flags to `swift build`: - -```nix -{ swiftpmFlags = [ "--disable-dead-strip" ]; } -``` - -The default `buildPhase` already passes `-j` for parallel building. - -If these two customization options are insufficient, provide your own -`buildPhase` that invokes `swift build`. - -### Running tests {#ssec-swiftpm-running-tests} - -Including `swiftpm` in your `nativeBuildInputs` also provides a default -`checkPhase`, but it must be enabled with: - -```nix -{ doCheck = true; } -``` - -This essentially runs: `swift test -c release` - -### Patching dependencies {#ssec-swiftpm-patching-dependencies} - -In some cases, it may be necessary to patch a SwiftPM dependency. SwiftPM -dependencies are located in `.build/checkouts`, but the `swiftpm2nix` helper -provides these as symlinks to read-only `/nix/store` paths. To patch -them, we need to make them writable. - -A special function `swiftpmMakeMutable` is available to replace the symlink -with a writable copy: +A special function `swiftpmMakeMutable` is available to replace the symlink with a writable copy: ```nix { @@ -183,21 +190,76 @@ with a writable copy: } ``` +### Custom build flags {#ssec-swiftpm-custom-build-flags} + +If you'd like to build a different configuration than `release`: + +```nix +{ swiftpmBuildConfig = "debug"; } +``` + +It is also possible to provide additional flags to `swift build`: + +```nix +{ swiftpmFlags = [ "--disable-dead-strip" ]; } +``` + +The default `buildPhase` already passes `-j` for parallel building. + +If these two customization options are insufficient, provide your own `buildPhase` that invokes `swift build`. + +### Running tests {#ssec-swiftpm-running-tests} + +Including `swiftpm` in your `nativeBuildInputs` also provides a default `checkPhase`, but it must be enabled with: + +```nix +{ doCheck = true; } +``` + +This essentially runs: `swift test -c release` + +### Installing packages {#ssec-swiftpm-install-phase} + +SwiftPM provides a default install phase that installs any products specified in your package’s `Package.swift`. +If your package does not specify any products, which is not uncommon, you will have to manually install them to `out`. +To disable the SwiftPM install phase, include the following in your derivation: + +```nix +{ dontUseSwiftpmInstall = true; } +``` + +## Hooks {#ssec-swift-hooks} + +Swift provides the following hooks to automate builds and unpack dependencies: + +- `swiftpmHook`: Propagated by `swiftpm`. + Also propagates `swiftpmUnpackHook`. + Provides build, install, and check phases. It also adds any dependencies found in `buildInputs` to `swiftpmFlags`. +- `swiftpmUnpackHook`: Sets up `workspace-state.json` and links vendored dependencies to the top-level `Packages` directory in the build environment. + +Swift also provides a hook with the toolchain to replace rpath references to the toolchain with references to the stdlib package. +This hook is used automatically by the `swift` package. +This avoids pulling the entire toolchain into the closure of your package. + ## Considerations for custom build tools {#ssec-swift-considerations-for-custom-build-tools} ### Linking the standard library {#ssec-swift-linking-the-standard-library} -The `swift` package has a separate `lib` output containing just the Swift -standard library, to prevent Swift applications needing a dependency on the -full Swift compiler at runtime. Linking with the Nixpkgs Swift toolchain -already ensures binaries correctly reference the `lib` output. +The Swift stdlib is packaged separately as `swiftPackages.stdlib`. +The shared and static libraries are installed to `lib`. +Most tooling in Nixpkgs should find them automatically when linking. +The stdlib provides a hook to change any rpaths pointing to the toolchain to point to the stdlib instead. -Sometimes, Swift is used only to compile part of a mixed codebase, and the -link step is manual. Custom build tools often locate the standard library -relative to the `swift` compiler executable, and while the result will work, -when this path ends up in the binary, it will have the Swift compiler as an -unintended dependency. +The stdlib modules are installed to `lib/swift/` in the `dev` output of the stdlib package. +These are symlinked together into the `swift` toolchain. +If your build tools locate the modules relative to the `swift` compiler executable, it should do the right thing automatically. -In this case, you should investigate how your build process discovers the -standard library, and override the path. The correct path will be something -like: `"${swift.swift.lib}/${swift.swiftModuleSubdir}"` +### Accessing properties of the Swift platform {#ssec-swift-platform-properties} + +The architecture, platform, and triple used by Swift is available as attributes on the build/host/targetPlatform for the `stdenv`. + +- `stdenv..swift.platform`: The Swift platform (e.g., `macosx` for macOS, `linux` for Linux, etc). +- `stdenv..swift.arch`: The Swift architecture (e.g., `arm64` for Darwin or `aarch64` for Linux, `x86_64`, etc). +- `stdenv..swift.triple`: The triple used by Swift. + This is the same as `stdenv..config` except on Darwin. + On Darwin, it uses the OS name instead of `darwin` and includes the deployment target (e.g., `arm64-apple-macosx14.0`). diff --git a/doc/redirects.json b/doc/redirects.json index 0bafda225709..ffcc105de889 100644 --- a/doc/redirects.json +++ b/doc/redirects.json @@ -4593,14 +4593,26 @@ "ssec-swift-packaging-with-swiftpm": [ "index.html#ssec-swift-packaging-with-swiftpm" ], + "ssec-swift-packaging-with-fetch-swiftpm-deps": [ + "index.html#ssec-swift-packaging-with-fetch-swiftpm-deps" + ], + "ssec-swift-packaging-with-swiftpm2nix": [ + "index.html#ssec-swift-packaging-with-swiftpm2nix" + ], + "ssec-swiftpm-patching-dependencies": [ + "index.html#ssec-swiftpm-patching-dependencies" + ], "ssec-swiftpm-custom-build-flags": [ "index.html#ssec-swiftpm-custom-build-flags" ], "ssec-swiftpm-running-tests": [ "index.html#ssec-swiftpm-running-tests" ], - "ssec-swiftpm-patching-dependencies": [ - "index.html#ssec-swiftpm-patching-dependencies" + "ssec-swiftpm-install-phase": [ + "index.html#ssec-swiftpm-install-phase" + ], + "ssec-swift-hooks": [ + "index.html#ssec-swift-hooks" ], "ssec-swift-considerations-for-custom-build-tools": [ "index.html#ssec-swift-considerations-for-custom-build-tools" @@ -4608,6 +4620,9 @@ "ssec-swift-linking-the-standard-library": [ "index.html#ssec-swift-linking-the-standard-library" ], + "ssec-swift-platform-properties": [ + "index.html#ssec-swift-platform-properties" + ], "sec-language-tcl": [ "index.html#sec-language-tcl" ], From 3a5030e3569b29ea63d33f78a39ee4639176f2b3 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 274/423] doc/rl-2611: add Swift 6.2 --- doc/release-notes/rl-2611.section.md | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/doc/release-notes/rl-2611.section.md b/doc/release-notes/rl-2611.section.md index 5bfa21291139..41071dfbbf61 100644 --- a/doc/release-notes/rl-2611.section.md +++ b/doc/release-notes/rl-2611.section.md @@ -205,6 +205,16 @@ - `nim-2_0` & `nim-2_2` and respective aliases have been removed; please migrate to `nim` or `nim-unwrapped` (nim 2.2.10). - `domoticz` has been updated from `2024.7` to `2026.x`, breaking third party applications and scripts using the old RType calls. Review the [release notes](https://github.com/domoticz/domoticz/blob/2026.2/History.txt#L398) for more information. +- `swift` is no longer wrapped. + The `NIX_SWIFTFLAGS_COMPILE` variable is no longer supported. + If you need to pass custom flags to the Swift compiler, you must add them via your package’s build system. + The default target version used by `swiftc` on Darwin is the operating system major version. + This value may be overridden by the build system (e.g., SwiftPM defaults to 10.13 instead). + See the Swift documentation in Nixpkgs for details. + +- `swiftpm` is no longer wrapped to include Git to fetch dependencies. + Users with Git-based dependencies will need to add `git` to their dev shells or include it in their environment if they weren’t already. + - `vimacs` has been removed, as it has not been maintained in 10 years and was built for an old version of vim (6.0). - The deprecated `appimageTools.extractType1`, `appimageTools.extractType2`, and `appimageTools.wrapType1` aliases now emit warnings. Use `appimageTools.extract` and `appimageTools.wrapType2` instead. @@ -249,6 +259,9 @@ - Firefox wrapper now accepts an optional `appDataDir` argument, which sets `MOZ_APP_DATA` to relocate Firefox application data. This is especially useful on macOS 27 and later, where wrapped Firefox applications may be denied access to profiles in traditional application data directory. +- Swift has been upgraded to Swift 6.2.4 from Swift 5.10.1. + The Swift packaging has been rewritten. + ## Nixpkgs Library {#sec-nixpkgs-release-26.11-lib} From 3c1176569d968525e30424020413f047159f1e9f Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 9 Aug 2026 08:38:12 -0400 Subject: [PATCH 275/423] teams/swift: add reckenrode --- maintainers/team-list.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/maintainers/team-list.nix b/maintainers/team-list.nix index ab85a7371cdd..aa636525d0d4 100644 --- a/maintainers/team-list.nix +++ b/maintainers/team-list.nix @@ -751,6 +751,7 @@ with lib.maintainers; swift = { members = [ + reckenrode samasaur stephank ]; From 6bb6dcae526a1df7b9a9643ef5d176e0406324a2 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E5=A4=9C=E5=9D=82=E9=9B=85?= <23130178+ShadowRZ@users.noreply.github.com> Date: Wed, 16 Sep 2026 18:27:02 +0800 Subject: [PATCH 276/423] libimobiledevice: drop unused libgcrypt dependency, modernize --- pkgs/by-name/li/libimobiledevice/package.nix | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) diff --git a/pkgs/by-name/li/libimobiledevice/package.nix b/pkgs/by-name/li/libimobiledevice/package.nix index 91fd4d468270..9320772113f8 100644 --- a/pkgs/by-name/li/libimobiledevice/package.nix +++ b/pkgs/by-name/li/libimobiledevice/package.nix @@ -15,19 +15,19 @@ unstableGitUpdater, }: -stdenv.mkDerivation rec { +stdenv.mkDerivation (finalAttrs: { pname = "libimobiledevice"; version = "1.4.0"; src = fetchFromGitHub { owner = "libimobiledevice"; repo = "libimobiledevice"; - tag = version; + tag = finalAttrs.version; hash = "sha256-SWWsa7asCXpcz80VNhxoePWr74QY8SP0byGSCp+nGG0="; }; preAutoreconf = '' - export RELEASE_VERSION=${version} + export RELEASE_VERSION=${finalAttrs.version} ''; configureFlags = [ "--without-cython" ]; @@ -39,7 +39,6 @@ stdenv.mkDerivation rec { propagatedBuildInputs = [ openssl - libgcrypt libplist libtasn1 libtatsu @@ -47,6 +46,9 @@ stdenv.mkDerivation rec { libimobiledevice-glue ]; + strictDeps = true; + __structuredAttrs = true; + outputs = [ "out" "dev" @@ -75,4 +77,4 @@ stdenv.mkDerivation rec { platforms = lib.platforms.unix; maintainers = with lib.maintainers; [ RossComputerGuy ]; }; -} +}) From a201dbdc72bcf84c8c5bc1d4253705bb50f02bc2 Mon Sep 17 00:00:00 2001 From: Gaetan Lepage Date: Tue, 1 Sep 2026 06:39:00 +0000 Subject: [PATCH 277/423] python3Packages.dask: 2026.7.1 -> 2026.8.0 Diff: https://github.com/dask/dask/compare/2026.7.1...2026.8.0 Changelog: https://docs.dask.org/en/latest/changelog.html --- pkgs/development/python-modules/dask/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/dask/default.nix b/pkgs/development/python-modules/dask/default.nix index 3c83bd0e6eda..691504cc6a98 100644 --- a/pkgs/development/python-modules/dask/default.nix +++ b/pkgs/development/python-modules/dask/default.nix @@ -44,7 +44,7 @@ buildPythonPackage (finalAttrs: { pname = "dask"; - version = "2026.7.1"; + version = "2026.8.0"; pyproject = true; __structuredAttrs = true; @@ -52,7 +52,7 @@ buildPythonPackage (finalAttrs: { owner = "dask"; repo = "dask"; tag = finalAttrs.version; - hash = "sha256-Hh3QMSLMn7xCbwoiu4gjjF590YXZfiG5rp20kWX+Kms="; + hash = "sha256-DFPd46cBirwztmZJvRKS8u5qvYMEIWfy90QR2AeBu3c="; }; postPatch = lib.optionalString stdenv.hostPlatform.isLinux '' From 06ff6a54d34928bcd21397d3beff62dd00039f52 Mon Sep 17 00:00:00 2001 From: Gaetan Lepage Date: Tue, 1 Sep 2026 06:39:58 +0000 Subject: [PATCH 278/423] python3Packages.distributed: 2026.7.1 -> 2026.8.0 Diff: https://github.com/dask/distributed/compare/2026.7.1...2026.8.0 Changelog: https://github.com/dask/distributed/releases/tag/2026.8.0 --- pkgs/development/python-modules/distributed/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/distributed/default.nix b/pkgs/development/python-modules/distributed/default.nix index 9f2fb7ebe6c3..a01910fa3853 100644 --- a/pkgs/development/python-modules/distributed/default.nix +++ b/pkgs/development/python-modules/distributed/default.nix @@ -26,7 +26,7 @@ buildPythonPackage (finalAttrs: { pname = "distributed"; - version = "2026.7.1"; + version = "2026.8.0"; pyproject = true; __structuredAttrs = true; @@ -34,7 +34,7 @@ buildPythonPackage (finalAttrs: { owner = "dask"; repo = "distributed"; tag = finalAttrs.version; - hash = "sha256-9QZb7PpPhdJEc4Kgoc3PE6TU7LHmiw58jkgfaoSNSg4="; + hash = "sha256-Z7T/ik8GDnFESDl2OuvSGFo+SBcEY7gpVx31CoTTvao="; }; build-system = [ From 13ec1d2a1af487c9afa23d8efcb831e6f7bc2516 Mon Sep 17 00:00:00 2001 From: Gaetan Lepage Date: Sun, 6 Sep 2026 20:57:48 +0000 Subject: [PATCH 279/423] python3Packages.dask-glm: 0.3.2 -> 0.4.0 Diff: https://github.com/dask/dask-glm/compare/0.3.2...0.4.0 Changelog: https://github.com/dask/dask-glm/releases/tag/0.4.0 --- .../python-modules/dask-glm/default.nix | 46 +++++++++---------- 1 file changed, 22 insertions(+), 24 deletions(-) diff --git a/pkgs/development/python-modules/dask-glm/default.nix b/pkgs/development/python-modules/dask-glm/default.nix index 3801ae817917..9c4045be8fc4 100644 --- a/pkgs/development/python-modules/dask-glm/default.nix +++ b/pkgs/development/python-modules/dask-glm/default.nix @@ -1,50 +1,60 @@ { lib, - stdenv, buildPythonPackage, fetchFromGitHub, # build-system + setuptools, setuptools-scm, # dependencies cloudpickle, + dask, distributed, multipledispatch, + numba, + numpy, scikit-learn, scipy, sparse, - dask, # tests pytest-xdist, pytestCheckHook, }: -buildPythonPackage rec { +buildPythonPackage (finalAttrs: { pname = "dask-glm"; - version = "0.3.2"; + version = "0.4.0"; pyproject = true; + __structuredAttrs = true; src = fetchFromGitHub { owner = "dask"; repo = "dask-glm"; - tag = version; - hash = "sha256-q98QMmw1toashimS16of54cgZgIPqkua3xGD1FZ1nTc="; + tag = finalAttrs.version; + hash = "sha256-u3KASmBamc7qU/GxGT0QBqWJ1HDk81xI0MOoRng8BzA="; }; - # ValueError: The truth value of an empty array is ambiguous. Use `array.size > 0` to check that an array is not empty. + # The iprint parameter of `scipy.optimize.fmin_l_bfgs_b` was removed in 1.18.0 + # https://github.com/scipy/scipy/blob/b881cb179463e85a74f3368f6242986d713adbdc/doc/source/release/1.18.0-notes.rst?plain=1#L291-L292 postPatch = '' - substituteInPlace dask_glm/utils.py \ - --replace-fail "if arr:" "if (arr is not None) and (arr.size > 0):" + substituteInPlace dask_glm/algorithms.py \ + --replace-fail "iprint=(verbose > 0) - 1," "" ''; - build-system = [ setuptools-scm ]; + build-system = [ + setuptools + setuptools-scm + ]; dependencies = [ cloudpickle + dask distributed multipledispatch + numba + numpy scikit-learn scipy sparse @@ -58,23 +68,11 @@ buildPythonPackage rec { pythonImportsCheck = [ "dask_glm" ]; - disabledTests = [ - # ValueError: can be computed for one-element arrays only. - "test_dot_with_sparse" - - # ValueError: `shape` was not provided. - "test_sparse" - ]; - - # On darwin, tests saturate the entire system, even when constrained to run single-threaded - # Removing pytest-xdist AND setting --cores to one does not prevent the load from exploding - doCheck = !stdenv.hostPlatform.isDarwin; - meta = { description = "Generalized Linear Models with Dask"; homepage = "https://github.com/dask/dask-glm/"; - changelog = "https://github.com/dask/dask-glm/releases/tag/${version}"; + changelog = "https://github.com/dask/dask-glm/releases/tag/${finalAttrs.src.tag}"; license = lib.licenses.bsd3; maintainers = with lib.maintainers; [ GaetanLepage ]; }; -} +}) From 6d8ee00de20b2aadc4fb392e5ce3b684b440e180 Mon Sep 17 00:00:00 2001 From: Gaetan Lepage Date: Mon, 7 Sep 2026 14:46:27 +0000 Subject: [PATCH 280/423] python3Packages.dask-ml: cleanup, fix --- .../python-modules/dask-ml/default.nix | 24 +++++++++++++++---- 1 file changed, 19 insertions(+), 5 deletions(-) diff --git a/pkgs/development/python-modules/dask-ml/default.nix b/pkgs/development/python-modules/dask-ml/default.nix index 4153970a052e..842cbad62466 100644 --- a/pkgs/development/python-modules/dask-ml/default.nix +++ b/pkgs/development/python-modules/dask-ml/default.nix @@ -24,22 +24,24 @@ pytestCheckHook, }: -buildPythonPackage rec { +buildPythonPackage (finalAttrs: { pname = "dask-ml"; version = "2025.1.0"; pyproject = true; + __structuredAttrs = true; src = fetchFromGitHub { owner = "dask"; repo = "dask-ml"; - tag = "v${version}"; + tag = "v${finalAttrs.version}"; hash = "sha256-DHxx0LFuJmGWYuG/WGHj+a5XHAEekBmlHUUb90rl2IY="; }; postPatch = '' substituteInPlace pyproject.toml \ - --replace-fail 'addopts = "-rsx -v --durations=10 --color=yes"' \ - 'addopts = ["-rsx", "-v", "--durations=10", "--color=yes"]' + --replace-fail \ + 'addopts = "-rsx -v --durations=10 --color=yes"' \ + 'addopts = ["-rsx", "-v", "--durations=10", "--color=yes"]' ''; build-system = [ @@ -73,6 +75,18 @@ buildPythonPackage rec { pytestCheckHook ]; + pytestFlags = [ + # Skipping check check_array_api_input for KMeans because it raised SkipTest: + # SCIPY_ARRAY_API is not set: not checking array_api input + "-Wignore::sklearn.exceptions.SkipTestWarning" + + # pandas.errors.Pandas4Warning: For backward compatibility, 'str' dtypes are included by select_dtypes when 'object' dtype is specified. + # This behavior is deprecated and will be removed in a future version. + # Explicitly pass 'str' to `include` to select them, or to `exclude` to remove them and silence this warning. + # See https://pandas.pydata.org/docs/user_guide/migration-3-strings.html#string-migration-select-dtypes for details on how to write code that works with pandas 2 and 3. + "-Wignore::pandas.errors.Pandas4Warning" + ]; + disabledTestPaths = [ # RuntimeError: Attempting to use an asynchronous Client in a synchronous context of `dask.compute` # https://github.com/dask/dask-ml/issues/1016 @@ -131,4 +145,4 @@ buildPythonPackage rec { license = lib.licenses.bsd3; maintainers = with lib.maintainers; [ GaetanLepage ]; }; -} +}) From 2b8a77bf809c3f25b30a50f4baa4c56d00b5a2ea Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Wed, 16 Sep 2026 21:56:29 -0400 Subject: [PATCH 281/423] nixVersions.nixComponents*.nix-store: fix compat with meson 1.12 Was broken by https://github.com/mesonbuild/meson/commit/7851563c0b6a1351d999e873618e0bd8e366fe53 --- .../package-management/nix/modular/src/libstore/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/tools/package-management/nix/modular/src/libstore/package.nix b/pkgs/tools/package-management/nix/modular/src/libstore/package.nix index 80f95ea3981d..e506383c2a09 100644 --- a/pkgs/tools/package-management/nix/modular/src/libstore/package.nix +++ b/pkgs/tools/package-management/nix/modular/src/libstore/package.nix @@ -73,6 +73,9 @@ mkMesonLibrary (finalAttrs: { nlohmann_json ]; + # Don't use the default name "build": that conflicts with an existing directory. + mesonBuildDir = "meson-build-dir"; + mesonFlags = [ (lib.mesonEnable "seccomp-sandboxing" stdenv.hostPlatform.isLinux) (lib.mesonBool "embedded-sandbox-shell" embeddedSandboxShell) From cd205bf477d4d2e0db45e6777467e9414b38cdbf Mon Sep 17 00:00:00 2001 From: K900 Date: Thu, 17 Sep 2026 14:55:29 +0300 Subject: [PATCH 282/423] pipewire: 1.6.8 -> 1.6.9 Diff: https://gitlab.freedesktop.org/pipewire/pipewire/-/compare/1.6.8...1.6.9 Changelog: https://gitlab.freedesktop.org/pipewire/pipewire/-/releases/1.6.9 --- pkgs/by-name/pi/pipewire/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/pi/pipewire/package.nix b/pkgs/by-name/pi/pipewire/package.nix index 981c7f867324..b1161e3c2642 100644 --- a/pkgs/by-name/pi/pipewire/package.nix +++ b/pkgs/by-name/pi/pipewire/package.nix @@ -88,7 +88,7 @@ in stdenv.mkDerivation (finalAttrs: { pname = "pipewire"; - version = "1.6.8"; + version = "1.6.9"; outputs = [ "out" @@ -104,7 +104,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "pipewire"; repo = "pipewire"; tag = finalAttrs.version; - hash = "sha256-sxS6+LtvpEWCKoKLDUSYkW4+rrcIXPjWPBglReIDh/k="; + hash = "sha256-YmICqzAHRuLoGuZ5UwvfLotOr04/usEPsRIKZXF4SLI="; }; patches = [ From ef4cbb9d840889307a394b453af9a88b3cde1669 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Thu, 17 Sep 2026 16:00:41 +0200 Subject: [PATCH 283/423] tzdata: fix unpatched shebang Regression after setting strictDeps = true; --- pkgs/by-name/tz/tzdata/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/tz/tzdata/package.nix b/pkgs/by-name/tz/tzdata/package.nix index 3cab180bbc02..1d6cb31e1d2b 100644 --- a/pkgs/by-name/tz/tzdata/package.nix +++ b/pkgs/by-name/tz/tzdata/package.nix @@ -3,6 +3,7 @@ stdenv, fetchurl, buildPackages, + bashNonInteractive, postgresql, }: @@ -35,6 +36,8 @@ stdenv.mkDerivation (finalAttrs: { ]; propagatedBuildOutputs = [ ]; + buildInputs = [ bashNonInteractive ]; # for 'tzselect' + strictDeps = true; makeFlags = [ From edee310e8fb533732098d92650a580a234a921ed Mon Sep 17 00:00:00 2001 From: "Adam C. Stephens" Date: Thu, 17 Sep 2026 11:26:15 -0400 Subject: [PATCH 284/423] openssl: downgrade default to 3.5 LTS 3.6.x will go out of support in November before branch off. I suggest this is a simpler change than trying to bring all of the tree up to 4.x. It's likely that some packages may need to manually specify such. --- pkgs/top-level/all-packages.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index ab861e43da02..3b364ebf6f4d 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -6327,7 +6327,7 @@ with pkgs; libressl_4_3 ; - openssl = openssl_3_6; + openssl = openssl_3_5; openssl_oqs = openssl.override { providers = [ From d3c88870e907402a78fe16ef299c72c539e7346f Mon Sep 17 00:00:00 2001 From: Thomas Gerbet Date: Thu, 17 Sep 2026 16:14:26 +0000 Subject: [PATCH 285/423] makeBinaryWrapper: ignore prefix/suffix empty segment check for LUA_PATH/LUA_CPATH These are not an issue with Lua, we can allowlist them. This should resolve the neovim build issue reported in https://github.com/NixOS/nixpkgs/pull/548442#issuecomment-5709248256 --- pkgs/by-name/ma/makeBinaryWrapper/make-binary-wrapper.sh | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/pkgs/by-name/ma/makeBinaryWrapper/make-binary-wrapper.sh b/pkgs/by-name/ma/makeBinaryWrapper/make-binary-wrapper.sh index 5788cde93651..2001f448264c 100644 --- a/pkgs/by-name/ma/makeBinaryWrapper/make-binary-wrapper.sh +++ b/pkgs/by-name/ma/makeBinaryWrapper/make-binary-wrapper.sh @@ -330,6 +330,12 @@ assertValidEnvName() { assertNoEmptySegment() { local flag="$1" env="$2" sep="$3" val="$4" [ -n "$sep" ] || return 0 + case "$env" in + # In Lua the loader will substitute the default paths or just ignore the empty segment + # https://github.com/lua/lua/blob/v5.5.1/loadlib.c#L274 + # https://github.com/lua/lua/blob/v5.5.1/loadlib.c#L475 + LUA_PATH|LUA_CPATH|LUA_PATH_*|LUA_CPATH_*) return 0 ;; + esac if [[ "$sep$val$sep" == *"$sep$sep"* ]]; then printf '\n%s\n' "#error $flag $env would introduce an empty PATH-like segment (empty, or a leading/trailing/doubled \`$sep\`). This is interpreted as \"search the current directory\" by shells, execvp() and the dynamic linker, see https://github.com/NixOS/nixpkgs/security/advisories/GHSA-p7v3-pr2c-8584. Guard the value with e.g. lib.optionalString (list != [])." fi From 1cb8cf0cd5cecf33965ce0a09f1e2816b99fabbc Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Thu, 17 Sep 2026 18:25:15 +0200 Subject: [PATCH 286/423] texinfo: update file path for 7.3 The whole tp directory was renamed to tta in https://cgit.git.savannah.gnu.org/cgit/texinfo.git/commit/?h=release/7.3&id=c692ff501fe7c346f548a9e61ecd13bb0ab5a3b7 --- pkgs/development/tools/misc/texinfo/common.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/development/tools/misc/texinfo/common.nix b/pkgs/development/tools/misc/texinfo/common.nix index 7b406eb8bf00..d010db80c808 100644 --- a/pkgs/development/tools/misc/texinfo/common.nix +++ b/pkgs/development/tools/misc/texinfo/common.nix @@ -61,7 +61,7 @@ stdenv.mkDerivation { ++ optional crossBuildTools ./cross-tools-flags.patch; postPatch = '' - patchShebangs tp/maintain/regenerate_commands_perl_info.pl + patchShebangs tta/maintain/regenerate_commands_perl_info.pl ''; env = { From 247f4425b9f11e5176be084b76f38ca7ca632870 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Thomas=20M=C3=BChlbacher?= Date: Tue, 15 Sep 2026 01:46:34 +0200 Subject: [PATCH 287/423] llvmPackages.clang-tools: ensure wrapper uses bash The wrapper script relies on features only available with bash, namely arithmetic evaluation as in `while (( $# )); do`. So let's ensure that the shebang is patched to use bash. (bash's POSIX `sh` evaluates this as intended.) A minimal reproducer with a project that generally ought to pass clang-tidy checking may look like so: ```nix { pkgs ? import { }, }: pkgs.fwupd.overrideAttrs ( final: prev: { nativeBuildInputs = prev.nativeBuildInputs ++ [ pkgs.clang-tools ]; preCheck = '' ninja clang-tidy ''; } ) ``` Before, you may see many errors about missing headers and some lines that suspiciously look like bash errors. ``` fwupd> >>> /nix/store/gf6qdh329rc8lbby710r9rzhwqkkgv3h-clang-tools-21.1.8/bin/clang-tidy --use-color -quiet -p /build/source/build /build/source/plugins/uf2/fu-self-test.c fwupd> /nix/store/gf6qdh329rc8lbby710r9rzhwqkkgv3h-clang-tools-21.1.8/bin/clang-tidy: line 5: 129: not found fwupd> /nix/store/gf6qdh329rc8lbby710r9rzhwqkkgv3h-clang-tools-21.1.8/bin/clang-tidy: line 23: 129: not found fwupd> 276 warnings and 1 error generated. fwupd> Error while processing /build/source/plugins/uf2/fu-self-test.c. fwupd> /nix/store/dm7fg33sqnjxkwdpirnnbnx7wyi89m82-glib-2.88.3-dev/include/glib-2.0/glib/gtypes.h:41:10: error: 'time.h' file not found [clang-diagnostic-error] fwupd> 41 | #include fwupd> | ^~~~~~~~ ``` With this change, these clang-tidy errors no longer appear. --- pkgs/development/compilers/llvm/common/clang-tools/default.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/development/compilers/llvm/common/clang-tools/default.nix b/pkgs/development/compilers/llvm/common/clang-tools/default.nix index 91daa95d07cf..74523db10b80 100644 --- a/pkgs/development/compilers/llvm/common/clang-tools/default.nix +++ b/pkgs/development/compilers/llvm/common/clang-tools/default.nix @@ -3,6 +3,7 @@ stdenv, runCommand, writeText, + bashNonInteractive, clang-unwrapped, clang, libcxxClang, @@ -20,6 +21,8 @@ stdenv.mkDerivation (finalAttrs: { strictDeps = true; __structuredAttrs = true; + buildInputs = [ bashNonInteractive ]; + installPhase = '' runHook preInstall From c37c7bbcdb0d1bb51bc497f85194f97be2bf859b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Thomas=20M=C3=BChlbacher?= Date: Thu, 17 Sep 2026 00:52:48 +0200 Subject: [PATCH 288/423] llvmPackages.clang-tools: use correct shell shebang This wrapper is factually a bash script and should therefore use the correct shebang instead of relying on the leniency of the bash POSIX mode. --- pkgs/development/compilers/llvm/common/clang-tools/wrapper | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/development/compilers/llvm/common/clang-tools/wrapper b/pkgs/development/compilers/llvm/common/clang-tools/wrapper index 6601d6875f8e..247d858b9488 100755 --- a/pkgs/development/compilers/llvm/common/clang-tools/wrapper +++ b/pkgs/development/compilers/llvm/common/clang-tools/wrapper @@ -1,4 +1,4 @@ -#!/bin/sh +#!/usr/bin/env bash buildcpath() { local path after From 5bf21ff317f377d7dd3e417e3b583d15852a3a4d Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Thomas=20M=C3=BChlbacher?= Date: Thu, 17 Sep 2026 00:55:02 +0200 Subject: [PATCH 289/423] llvmPackages.clang-tools: add test for clang-tidy While the wrapper's bash script was broken, clang-tidy would have failed to check a project with an include such as assert.h because it wouldn't have been able to find that header file. --- .../compilers/llvm/common/clang-tools/default.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/pkgs/development/compilers/llvm/common/clang-tools/default.nix b/pkgs/development/compilers/llvm/common/clang-tools/default.nix index 74523db10b80..4fab7f98164d 100644 --- a/pkgs/development/compilers/llvm/common/clang-tools/default.nix +++ b/pkgs/development/compilers/llvm/common/clang-tools/default.nix @@ -66,9 +66,11 @@ stdenv.mkDerivation (finalAttrs: { passthru.tests = let src = writeText "main.cpp" '' + #include #include int main() { + assert(true); std::cout << "Hi!"; } ''; @@ -79,6 +81,10 @@ stdenv.mkDerivation (finalAttrs: { ${finalAttrs.finalPackage}/bin/clangd --check=${src} touch $out ''; + smokeOkClangTidy = runCommand "clang-tidy-test-smoke-ok" { } '' + ${finalAttrs.finalPackage}/bin/clang-tidy ${src} + touch $out + ''; smokeErr = runCommand "clang-tools-test-smoke-err" { } '' (${finalAttrs.finalPackage}/bin/clangd --query-driver='**' --check=${src} 2>&1 || true) \ | grep 'use of undeclared identifier' From fb0f7b5e70246c59f7de0a401513549ed175a434 Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Thu, 17 Sep 2026 19:14:08 -0400 Subject: [PATCH 290/423] less: 704 -> 710 Changelog: https://www.greenwoodsoftware.com/less/news.710.html --- pkgs/by-name/le/less/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/le/less/package.nix b/pkgs/by-name/le/less/package.nix index 00823f701cde..7fa226c21f77 100644 --- a/pkgs/by-name/le/less/package.nix +++ b/pkgs/by-name/le/less/package.nix @@ -11,7 +11,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "less"; - version = "704"; + version = "710"; # `less` is provided by the following sources: # - meta.homepage @@ -20,7 +20,7 @@ stdenv.mkDerivation (finalAttrs: { # homepage, and only those not marked as beta. src = fetchurl { url = "https://www.greenwoodsoftware.com/less/less-${finalAttrs.version}.tar.gz"; - hash = "sha256-IKCworslJfpTx+7pvrhUtMnPFy6rsgmvcCB0NUe/6fs="; + hash = "sha256-0QCPt43K4TI92rZkvLNSph8CKxsTG9gBhUjgIdl17Ho="; }; buildInputs = [ From e43409680568e4e167cdcc88e63fd61243a4a459 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 18 Sep 2026 06:31:02 +0000 Subject: [PATCH 291/423] gn: 0-unstable-2026-07-23 -> 0-unstable-2026-08-14 --- pkgs/by-name/gn/gn/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/gn/gn/package.nix b/pkgs/by-name/gn/gn/package.nix index 461d2efb64ce..3cc315badcd7 100644 --- a/pkgs/by-name/gn/gn/package.nix +++ b/pkgs/by-name/gn/gn/package.nix @@ -11,11 +11,11 @@ version ? # This is a workaround for update-source-version to be able to update this let - _version = "0-unstable-2026-07-23"; + _version = "0-unstable-2026-08-14"; in _version, - rev ? "641ace93dd9560e75e7add0d08f77b446fbb3b78", - hash ? "sha256-ovLx6KaORdXqnWgbsGEty10k2CHuCmTk3yEqy5//ovk=", + rev ? "e8a8e0932a5e42a99e5896aa58e3b8290f4e5b8c", + hash ? "sha256-qvQ13Ws2tb4i2Hdu34kBHivYPAn8w06zjLdQgK4BIJg=", }: stdenv.mkDerivation { From bbf0d88475fe7a66538ad52a6b7eacf5e2f3f62f Mon Sep 17 00:00:00 2001 From: sempiternal-aurora <78790545+sempiternal-aurora@users.noreply.github.com> Date: Wed, 16 Sep 2026 23:54:17 +0200 Subject: [PATCH 292/423] llvmPackages.llvm: add support for arm64e.x1 subtype Apple added a new CPU subtype with the macOS 27 sdk, which describes CPUs with extra pointer authentication features. The apple A20 and M6 chips have this subtype, and code in the new macOS 27 sdk needs the compiler toolchain to be able to handle these architectures, so that it can be linked against. --- .../backport-minimal-arm64e_x1-support.patch | 205 ++++++++++++++++++ .../backport-minimal-arm64e_x1-support.patch | 205 ++++++++++++++++++ .../backport-minimal-arm64e_x1-support.patch | 205 ++++++++++++++++++ .../backport-minimal-arm64e_x1-support.patch | 205 ++++++++++++++++++ .../compilers/llvm/common/llvm/default.nix | 15 ++ .../compilers/llvm/common/patches.nix | 21 ++ .../swift/by-name/ll/llvmPackages/package.nix | 2 + .../backport-minimal-arm64e_x1-support.patch | 205 ++++++++++++++++++ 8 files changed, 1063 insertions(+) create mode 100644 pkgs/development/compilers/llvm/18/llvm/backport-minimal-arm64e_x1-support.patch create mode 100644 pkgs/development/compilers/llvm/19/llvm/backport-minimal-arm64e_x1-support.patch create mode 100644 pkgs/development/compilers/llvm/20/llvm/backport-minimal-arm64e_x1-support.patch create mode 100644 pkgs/development/compilers/llvm/22/llvm/backport-minimal-arm64e_x1-support.patch create mode 100644 pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/llvm/backport-minimal-arm64e_x1-support.patch diff --git a/pkgs/development/compilers/llvm/18/llvm/backport-minimal-arm64e_x1-support.patch b/pkgs/development/compilers/llvm/18/llvm/backport-minimal-arm64e_x1-support.patch new file mode 100644 index 000000000000..3547062520c5 --- /dev/null +++ b/pkgs/development/compilers/llvm/18/llvm/backport-minimal-arm64e_x1-support.patch @@ -0,0 +1,205 @@ +--- llvm/include/llvm/BinaryFormat/MachO.h ++++ llvm/include/llvm/BinaryFormat/MachO.h +@@ -1641,6 +1641,7 @@ + CPU_SUBTYPE_ARM64_ALL = 0, + CPU_SUBTYPE_ARM64_V8 = 1, + CPU_SUBTYPE_ARM64E = 2, ++ CPU_SUBTYPE_ARM64E_X1 = 12, + }; + + enum CPUSubTypeARM64_32 { CPU_SUBTYPE_ARM64_32_V8 = 1 }; +--- llvm/include/llvm/TargetParser/Triple.h ++++ llvm/include/llvm/TargetParser/Triple.h +@@ -147,6 +147,7 @@ + ARMSubArch_v4t, + + AArch64SubArch_arm64e, ++ AArch64SubArch_arm64e_x1, + AArch64SubArch_arm64ec, + + KalimbaSubArch_v3, +@@ -1008,6 +1009,11 @@ + getSubArch() == Triple::AArch64SubArch_arm64e; + } + ++ bool isArm64e_x1() const { ++ return getArch() == Triple::aarch64 && ++ getSubArch() == Triple::AArch64SubArch_arm64e_x1; ++ } ++ + /// Tests whether the target is X32. + bool isX32() const { + EnvironmentType Env = getEnvironment(); +--- llvm/include/llvm/TextAPI/Architecture.def ++++ llvm/include/llvm/TextAPI/Architecture.def +@@ -37,7 +37,7 @@ + /// + ARCHINFO(arm64, arm64, MachO::CPU_TYPE_ARM64, MachO::CPU_SUBTYPE_ARM64_ALL, 64) + ARCHINFO(arm64e, arm64e, MachO::CPU_TYPE_ARM64, MachO::CPU_SUBTYPE_ARM64E, 64) +- ++ARCHINFO(arm64e_x1, arm64e.x1, MachO::CPU_TYPE_ARM64, MachO::CPU_SUBTYPE_ARM64E_X1, 64) + + /// + /// ARM64_32 architectures sorted by cpu sub type id +--- llvm/lib/BinaryFormat/MachO.cpp ++++ llvm/lib/BinaryFormat/MachO.cpp +@@ -60,6 +60,8 @@ + return (MachO::CPUSubTypeARM64)MachO::CPU_SUBTYPE_ARM64_32_V8; + if (T.isArm64e()) + return MachO::CPU_SUBTYPE_ARM64E; ++ if (T.isArm64e_x1()) ++ return MachO::CPU_SUBTYPE_ARM64E_X1; + + return MachO::CPU_SUBTYPE_ARM64_ALL; + } +--- llvm/lib/Object/MachOObjectFile.cpp ++++ llvm/lib/Object/MachOObjectFile.cpp +@@ -2807,6 +2807,12 @@ + if (ArchFlag) + *ArchFlag = "arm64e"; + return Triple("arm64e-apple-darwin"); ++ case MachO::CPU_SUBTYPE_ARM64E_X1: ++ if (McpuDefault) ++ *McpuDefault = "apple-a20"; ++ if (ArchFlag) ++ *ArchFlag = "arm64e.x1"; ++ return Triple("arm64e.x1-apple-darwin"); + default: + return Triple(); + } +--- llvm/lib/TargetParser/Triple.cpp ++++ llvm/lib/TargetParser/Triple.cpp +@@ -114,6 +114,8 @@ + return "arm64ec"; + if (SubArch == AArch64SubArch_arm64e) + return "arm64e"; ++ if (SubArch == AArch64SubArch_arm64e_x1) ++ return "arm64e.x1"; + break; + default: + break; +@@ -515,6 +517,7 @@ + .Case("arm64", Triple::aarch64) + .Case("arm64_32", Triple::aarch64_32) + .Case("arm64e", Triple::aarch64) ++ .Case("arm64e.x1", Triple::aarch64) + .Case("arm64ec", Triple::aarch64) + .Case("arm", Triple::arm) + .Case("armeb", Triple::armeb) +@@ -720,6 +723,8 @@ + + if (SubArchName == "arm64e") + return Triple::AArch64SubArch_arm64e; ++ if (SubArchName == "arm64e.x1") ++ return Triple::AArch64SubArch_arm64e_x1; + + if (SubArchName == "arm64ec") + return Triple::AArch64SubArch_arm64ec; +--- llvm/test/tools/llvm-readobj/MachO/file-headers-arm64.test ++++ llvm/test/tools/llvm-readobj/MachO/file-headers-arm64.test +@@ -13,6 +13,11 @@ + # RUN: llvm-readobj -h %t.arm64e \ + # RUN: | FileCheck %s --strict-whitespace --match-full-lines -DFILE=%t.arm64e --check-prefix=ARM64 -DSUBTYPE="CPU_SUBTYPE_ARM64E (0x2)" + ++## Check subtype Arm64E.X1: ++# RUN: yaml2obj %s -o %t.arm64e.x1 -DSUBTYPE=0xC ++# RUN: llvm-readobj -h %t.arm64e.x1 \ ++# RUN: | FileCheck %s --strict-whitespace --match-full-lines -DFILE=%t.arm64e.x1 --check-prefix=ARM64 -DSUBTYPE="CPU_SUBTYPE_ARM64E_X1 (0xC)" ++ + # ARM64:File: [[FILE]] + # ARM64-NEXT:Format: Mach-O arm64 + # ARM64-NEXT:Arch: aarch64 +--- llvm/tools/llvm-objdump/MachODump.cpp ++++ llvm/tools/llvm-objdump/MachODump.cpp +@@ -2323,6 +2323,10 @@ + outs() << " cputype CPU_TYPE_ARM64\n"; + outs() << " cpusubtype CPU_SUBTYPE_ARM64E\n"; + break; ++ case MachO::CPU_SUBTYPE_ARM64E_X1: ++ outs() << " cputype CPU_TYPE_ARM64\n"; ++ outs() << " cpusubtype CPU_SUBTYPE_ARM64E_X1\n"; ++ break; + default: + printUnknownCPUType(cputype, cpusubtype); + break; +@@ -8213,6 +8217,9 @@ + case MachO::CPU_SUBTYPE_ARM64E: + outs() << " E"; + break; ++ case MachO::CPU_SUBTYPE_ARM64E_X1: ++ outs() << " E.X1"; ++ break; + default: + outs() << format(" %10d", cpusubtype & ~MachO::CPU_SUBTYPE_MASK); + break; +--- llvm/tools/llvm-readobj/MachODumper.cpp ++++ llvm/tools/llvm-readobj/MachODumper.cpp +@@ -170,6 +170,7 @@ + LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64_ALL), + LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64_V8), + LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64E), ++ LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64E_X1), + }; + + const EnumEntry MachOHeaderCpuSubtypesSPARC[] = { +--- llvm/unittests/BinaryFormat/MachOTest.cpp ++++ llvm/unittests/BinaryFormat/MachOTest.cpp +@@ -57,6 +57,7 @@ + CHECK_CPUTYPE("thumbv7-apple-darwin", MachO::CPU_TYPE_ARM); + CHECK_CPUTYPE("arm64-apple-darwin", MachO::CPU_TYPE_ARM64); + CHECK_CPUTYPE("arm64e-apple-darwin", MachO::CPU_TYPE_ARM64); ++ CHECK_CPUTYPE("arm64e.x1-apple-darwin", MachO::CPU_TYPE_ARM64); + CHECK_CPUTYPE("arm64_32-apple-darwin", MachO::CPU_TYPE_ARM64_32); + + { +@@ -98,6 +99,7 @@ + CHECK_CPUSUBTYPE("thumbv6-apple-darwin", MachO::CPU_SUBTYPE_ARM_V6); + CHECK_CPUSUBTYPE("arm64-apple-darwin", MachO::CPU_SUBTYPE_ARM64_ALL); + CHECK_CPUSUBTYPE("arm64e-apple-darwin", MachO::CPU_SUBTYPE_ARM64E); ++ CHECK_CPUSUBTYPE("arm64e.x1-apple-darwin", MachO::CPU_SUBTYPE_ARM64E_X1); + CHECK_CPUSUBTYPE("arm64_32-apple-darwin", MachO::CPU_SUBTYPE_ARM64_32_V8); + + { +--- /dev/null ++++ lld/test/MachO/arm64-x1.s +@@ -0,0 +1,20 @@ ++# REQUIRES: aarch64 ++ ++## Test that arm64.x1-macos is ignored instead of causing an error. ++## linked re-exported dylibs that only declare arm64e-macos targets, even if targeting arm64. ++# arm64 and arm64e are ABI compatible (same CPU type), and ld64 accepts this. ++ ++# RUN: rm -rf %t; split-file --no-leading-lines %s %t ++ ++# RUN: llvm-mc -filetype=obj -triple=arm64-apple-macos -o %t/test.o /dev/null ++ ++# RUN: %no-arg-lld -syslibroot %t/sdk -lSystem -dylib -arch arm64 \ ++# RUN: -platform_version macos 15 26 %t/test.o -o /dev/null ++ ++#--- sdk/usr/lib/libSystem.tbd ++--- !tapi-tbd ++tbd-version: 4 ++targets: [ arm64-macos, arm64e.x1-macos ] ++install-name: '/usr/lib/libSystem.dylib' ++current-version: 0001.001.1 ++... +--- /dev/null ++++ llvm/test/tools/llvm-readobj/macho-arm64e_x1.test +@@ -0,0 +1,17 @@ ++# RUN: yaml2obj %s -o %t.o ++# RUN: llvm-readobj -h %t.o | FileCheck %s ++ ++# CHECK: Magic: Magic64 (0xFEEDFACF) ++# CHECK: CpuType: Arm64 (0x100000C) ++# CHECK: CpuSubType: CPU_SUBTYPE_ARM64E_X1 (0xC) ++ ++--- !mach-o ++FileHeader: ++ magic: 0xFEEDFACF ++ cputype: 0x0100000C ++ cpusubtype: 0x0000000C ++ filetype: 0x00000001 ++ ncmds: 0 ++ sizeofcmds: 0 ++ flags: 0x00000000 ++ reserved: 0x00000000 diff --git a/pkgs/development/compilers/llvm/19/llvm/backport-minimal-arm64e_x1-support.patch b/pkgs/development/compilers/llvm/19/llvm/backport-minimal-arm64e_x1-support.patch new file mode 100644 index 000000000000..aed2b844a0b2 --- /dev/null +++ b/pkgs/development/compilers/llvm/19/llvm/backport-minimal-arm64e_x1-support.patch @@ -0,0 +1,205 @@ +--- llvm/include/llvm/BinaryFormat/MachO.h ++++ llvm/include/llvm/BinaryFormat/MachO.h +@@ -1641,6 +1641,7 @@ + CPU_SUBTYPE_ARM64_ALL = 0, + CPU_SUBTYPE_ARM64_V8 = 1, + CPU_SUBTYPE_ARM64E = 2, ++ CPU_SUBTYPE_ARM64E_X1 = 12, + }; + + enum CPUSubTypeARM64_32 { CPU_SUBTYPE_ARM64_32_V8 = 1 }; +--- llvm/include/llvm/TargetParser/Triple.h ++++ llvm/include/llvm/TargetParser/Triple.h +@@ -147,6 +147,7 @@ + ARMSubArch_v4t, + + AArch64SubArch_arm64e, ++ AArch64SubArch_arm64e_x1, + AArch64SubArch_arm64ec, + + KalimbaSubArch_v3, +@@ -1042,6 +1043,11 @@ + getSubArch() == Triple::AArch64SubArch_arm64e; + } + ++ bool isArm64e_x1() const { ++ return getArch() == Triple::aarch64 && ++ getSubArch() == Triple::AArch64SubArch_arm64e_x1; ++ } ++ + /// Tests whether the target is X32. + bool isX32() const { + EnvironmentType Env = getEnvironment(); +--- llvm/include/llvm/TextAPI/Architecture.def ++++ llvm/include/llvm/TextAPI/Architecture.def +@@ -37,7 +37,7 @@ + /// + ARCHINFO(arm64, arm64, MachO::CPU_TYPE_ARM64, MachO::CPU_SUBTYPE_ARM64_ALL, 64) + ARCHINFO(arm64e, arm64e, MachO::CPU_TYPE_ARM64, MachO::CPU_SUBTYPE_ARM64E, 64) +- ++ARCHINFO(arm64e_x1, arm64e.x1, MachO::CPU_TYPE_ARM64, MachO::CPU_SUBTYPE_ARM64E_X1, 64) + + /// + /// ARM64_32 architectures sorted by cpu sub type id +--- llvm/lib/BinaryFormat/MachO.cpp ++++ llvm/lib/BinaryFormat/MachO.cpp +@@ -60,6 +60,8 @@ + return (MachO::CPUSubTypeARM64)MachO::CPU_SUBTYPE_ARM64_32_V8; + if (T.isArm64e()) + return MachO::CPU_SUBTYPE_ARM64E; ++ if (T.isArm64e_x1()) ++ return MachO::CPU_SUBTYPE_ARM64E_X1; + + return MachO::CPU_SUBTYPE_ARM64_ALL; + } +--- llvm/lib/Object/MachOObjectFile.cpp ++++ llvm/lib/Object/MachOObjectFile.cpp +@@ -2807,6 +2807,12 @@ + if (ArchFlag) + *ArchFlag = "arm64e"; + return Triple("arm64e-apple-darwin"); ++ case MachO::CPU_SUBTYPE_ARM64E_X1: ++ if (McpuDefault) ++ *McpuDefault = "apple-a20"; ++ if (ArchFlag) ++ *ArchFlag = "arm64e.x1"; ++ return Triple("arm64e.x1-apple-darwin"); + default: + return Triple(); + } +--- llvm/lib/TargetParser/Triple.cpp ++++ llvm/lib/TargetParser/Triple.cpp +@@ -114,6 +114,8 @@ + return "arm64ec"; + if (SubArch == AArch64SubArch_arm64e) + return "arm64e"; ++ if (SubArch == AArch64SubArch_arm64e_x1) ++ return "arm64e.x1"; + break; + case Triple::dxil: + switch (SubArch) { +@@ -549,6 +551,7 @@ + .Case("arm64", Triple::aarch64) + .Case("arm64_32", Triple::aarch64_32) + .Case("arm64e", Triple::aarch64) ++ .Case("arm64e.x1", Triple::aarch64) + .Case("arm64ec", Triple::aarch64) + .Case("arm", Triple::arm) + .Case("armeb", Triple::armeb) +@@ -764,6 +767,8 @@ + + if (SubArchName == "arm64e") + return Triple::AArch64SubArch_arm64e; ++ if (SubArchName == "arm64e.x1") ++ return Triple::AArch64SubArch_arm64e_x1; + + if (SubArchName == "arm64ec") + return Triple::AArch64SubArch_arm64ec; +--- llvm/test/tools/llvm-readobj/MachO/file-headers-arm64.test ++++ llvm/test/tools/llvm-readobj/MachO/file-headers-arm64.test +@@ -13,6 +13,11 @@ + # RUN: llvm-readobj -h %t.arm64e \ + # RUN: | FileCheck %s --strict-whitespace --match-full-lines -DFILE=%t.arm64e --check-prefix=ARM64 -DSUBTYPE="CPU_SUBTYPE_ARM64E (0x2)" + ++## Check subtype Arm64E.X1: ++# RUN: yaml2obj %s -o %t.arm64e.x1 -DSUBTYPE=0xC ++# RUN: llvm-readobj -h %t.arm64e.x1 \ ++# RUN: | FileCheck %s --strict-whitespace --match-full-lines -DFILE=%t.arm64e.x1 --check-prefix=ARM64 -DSUBTYPE="CPU_SUBTYPE_ARM64E_X1 (0xC)" ++ + # ARM64:File: [[FILE]] + # ARM64-NEXT:Format: Mach-O arm64 + # ARM64-NEXT:Arch: aarch64 +--- llvm/tools/llvm-objdump/MachODump.cpp ++++ llvm/tools/llvm-objdump/MachODump.cpp +@@ -2323,6 +2323,10 @@ + outs() << " cputype CPU_TYPE_ARM64\n"; + outs() << " cpusubtype CPU_SUBTYPE_ARM64E\n"; + break; ++ case MachO::CPU_SUBTYPE_ARM64E_X1: ++ outs() << " cputype CPU_TYPE_ARM64\n"; ++ outs() << " cpusubtype CPU_SUBTYPE_ARM64E_X1\n"; ++ break; + default: + printUnknownCPUType(cputype, cpusubtype); + break; +@@ -8325,6 +8329,9 @@ + case MachO::CPU_SUBTYPE_ARM64E: + outs() << " E"; + break; ++ case MachO::CPU_SUBTYPE_ARM64E_X1: ++ outs() << " E.X1"; ++ break; + default: + outs() << format(" %10d", cpusubtype & ~MachO::CPU_SUBTYPE_MASK); + break; +--- llvm/tools/llvm-readobj/MachODumper.cpp ++++ llvm/tools/llvm-readobj/MachODumper.cpp +@@ -170,6 +170,7 @@ + LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64_ALL), + LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64_V8), + LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64E), ++ LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64E_X1), + }; + + const EnumEntry MachOHeaderCpuSubtypesSPARC[] = { +--- llvm/unittests/BinaryFormat/MachOTest.cpp ++++ llvm/unittests/BinaryFormat/MachOTest.cpp +@@ -66,6 +66,7 @@ + CHECK_CPUTYPE("thumbv7-apple-darwin", MachO::CPU_TYPE_ARM); + CHECK_CPUTYPE("arm64-apple-darwin", MachO::CPU_TYPE_ARM64); + CHECK_CPUTYPE("arm64e-apple-darwin", MachO::CPU_TYPE_ARM64); ++ CHECK_CPUTYPE("arm64e.x1-apple-darwin", MachO::CPU_TYPE_ARM64); + CHECK_CPUTYPE("arm64_32-apple-darwin", MachO::CPU_TYPE_ARM64_32); + + { +@@ -107,6 +108,7 @@ + CHECK_CPUSUBTYPE("thumbv6-apple-darwin", MachO::CPU_SUBTYPE_ARM_V6); + CHECK_CPUSUBTYPE("arm64-apple-darwin", MachO::CPU_SUBTYPE_ARM64_ALL); + CHECK_CPUSUBTYPE("arm64e-apple-darwin", MachO::CPU_SUBTYPE_ARM64E); ++ CHECK_CPUSUBTYPE("arm64e.x1-apple-darwin", MachO::CPU_SUBTYPE_ARM64E_X1); + CHECK_CPUSUBTYPE("arm64_32-apple-darwin", MachO::CPU_SUBTYPE_ARM64_32_V8); + + { +--- /dev/null ++++ lld/test/MachO/arm64-x1.s +@@ -0,0 +1,20 @@ ++# REQUIRES: aarch64 ++ ++## Test that arm64.x1-macos is ignored instead of causing an error. ++## linked re-exported dylibs that only declare arm64e-macos targets, even if targeting arm64. ++# arm64 and arm64e are ABI compatible (same CPU type), and ld64 accepts this. ++ ++# RUN: rm -rf %t; split-file --no-leading-lines %s %t ++ ++# RUN: llvm-mc -filetype=obj -triple=arm64-apple-macos -o %t/test.o /dev/null ++ ++# RUN: %no-arg-lld -syslibroot %t/sdk -lSystem -dylib -arch arm64 \ ++# RUN: -platform_version macos 15 26 %t/test.o -o /dev/null ++ ++#--- sdk/usr/lib/libSystem.tbd ++--- !tapi-tbd ++tbd-version: 4 ++targets: [ arm64-macos, arm64e.x1-macos ] ++install-name: '/usr/lib/libSystem.dylib' ++current-version: 0001.001.1 ++... +--- /dev/null ++++ llvm/test/tools/llvm-readobj/macho-arm64e_x1.test +@@ -0,0 +1,17 @@ ++# RUN: yaml2obj %s -o %t.o ++# RUN: llvm-readobj -h %t.o | FileCheck %s ++ ++# CHECK: Magic: Magic64 (0xFEEDFACF) ++# CHECK: CpuType: Arm64 (0x100000C) ++# CHECK: CpuSubType: CPU_SUBTYPE_ARM64E_X1 (0xC) ++ ++--- !mach-o ++FileHeader: ++ magic: 0xFEEDFACF ++ cputype: 0x0100000C ++ cpusubtype: 0x0000000C ++ filetype: 0x00000001 ++ ncmds: 0 ++ sizeofcmds: 0 ++ flags: 0x00000000 ++ reserved: 0x00000000 diff --git a/pkgs/development/compilers/llvm/20/llvm/backport-minimal-arm64e_x1-support.patch b/pkgs/development/compilers/llvm/20/llvm/backport-minimal-arm64e_x1-support.patch new file mode 100644 index 000000000000..a5b592d0f611 --- /dev/null +++ b/pkgs/development/compilers/llvm/20/llvm/backport-minimal-arm64e_x1-support.patch @@ -0,0 +1,205 @@ +--- llvm/include/llvm/BinaryFormat/MachO.h ++++ llvm/include/llvm/BinaryFormat/MachO.h +@@ -1641,6 +1641,7 @@ + CPU_SUBTYPE_ARM64_ALL = 0, + CPU_SUBTYPE_ARM64_V8 = 1, + CPU_SUBTYPE_ARM64E = 2, ++ CPU_SUBTYPE_ARM64E_X1 = 12, + + // arm64e uses the capability bits to encode ptrauth ABI information. + // Bit 63 marks the binary as Versioned. +--- llvm/include/llvm/TargetParser/Triple.h ++++ llvm/include/llvm/TargetParser/Triple.h +@@ -146,6 +146,7 @@ + ARMSubArch_v4t, + + AArch64SubArch_arm64e, ++ AArch64SubArch_arm64e_x1, + AArch64SubArch_arm64ec, + + KalimbaSubArch_v3, +@@ -1077,6 +1077,11 @@ + getSubArch() == Triple::AArch64SubArch_arm64e; + } + ++ bool isArm64e_x1() const { ++ return getArch() == Triple::aarch64 && ++ getSubArch() == Triple::AArch64SubArch_arm64e_x1; ++ } ++ + // Tests whether the target is N32. + bool isABIN32() const { + EnvironmentType Env = getEnvironment(); +--- llvm/include/llvm/TextAPI/Architecture.def ++++ llvm/include/llvm/TextAPI/Architecture.def +@@ -37,7 +37,7 @@ + /// + ARCHINFO(arm64, arm64, MachO::CPU_TYPE_ARM64, MachO::CPU_SUBTYPE_ARM64_ALL, 64) + ARCHINFO(arm64e, arm64e, MachO::CPU_TYPE_ARM64, MachO::CPU_SUBTYPE_ARM64E, 64) +- ++ARCHINFO(arm64e_x1, arm64e.x1, MachO::CPU_TYPE_ARM64, MachO::CPU_SUBTYPE_ARM64E_X1, 64) + + /// + /// ARM64_32 architectures sorted by cpu sub type id +--- llvm/lib/BinaryFormat/MachO.cpp ++++ llvm/lib/BinaryFormat/MachO.cpp +@@ -60,6 +60,8 @@ + return (MachO::CPUSubTypeARM64)MachO::CPU_SUBTYPE_ARM64_32_V8; + if (T.isArm64e()) + return MachO::CPU_SUBTYPE_ARM64E; ++ if (T.isArm64e_x1()) ++ return MachO::CPU_SUBTYPE_ARM64E_X1; + + return MachO::CPU_SUBTYPE_ARM64_ALL; + } +--- llvm/lib/Object/MachOObjectFile.cpp ++++ llvm/lib/Object/MachOObjectFile.cpp +@@ -2806,6 +2806,12 @@ + if (ArchFlag) + *ArchFlag = "arm64e"; + return Triple("arm64e-apple-darwin"); ++ case MachO::CPU_SUBTYPE_ARM64E_X1: ++ if (McpuDefault) ++ *McpuDefault = "apple-a20"; ++ if (ArchFlag) ++ *ArchFlag = "arm64e.x1"; ++ return Triple("arm64e.x1-apple-darwin"); + default: + return Triple(); + } +--- llvm/lib/TargetParser/Triple.cpp ++++ llvm/lib/TargetParser/Triple.cpp +@@ -114,6 +191,8 @@ + return "arm64ec"; + if (SubArch == AArch64SubArch_arm64e) + return "arm64e"; ++ if (SubArch == AArch64SubArch_arm64e_x1) ++ return "arm64e.x1"; + break; + case Triple::spirv: + switch (SubArch) { +@@ -574,6 +576,7 @@ + .Case("arm64", Triple::aarch64) + .Case("arm64_32", Triple::aarch64_32) + .Case("arm64e", Triple::aarch64) ++ .Case("arm64e.x1", Triple::aarch64) + .Case("arm64ec", Triple::aarch64) + .Case("arm", Triple::arm) + .Case("armeb", Triple::armeb) +@@ -793,6 +796,8 @@ + + if (SubArchName == "arm64e") + return Triple::AArch64SubArch_arm64e; ++ if (SubArchName == "arm64e.x1") ++ return Triple::AArch64SubArch_arm64e_x1; + + if (SubArchName == "arm64ec") + return Triple::AArch64SubArch_arm64ec; +--- llvm/test/tools/llvm-readobj/MachO/file-headers-arm64.test ++++ llvm/test/tools/llvm-readobj/MachO/file-headers-arm64.test +@@ -13,6 +13,11 @@ + # RUN: llvm-readobj -h %t.arm64e \ + # RUN: | FileCheck %s --strict-whitespace --match-full-lines -DFILE=%t.arm64e --check-prefix=ARM64 -DSUBTYPE="CPU_SUBTYPE_ARM64E (0x2)" + ++## Check subtype Arm64E.X1: ++# RUN: yaml2obj %s -o %t.arm64e.x1 -DSUBTYPE=0xC ++# RUN: llvm-readobj -h %t.arm64e.x1 \ ++# RUN: | FileCheck %s --strict-whitespace --match-full-lines -DFILE=%t.arm64e.x1 --check-prefix=ARM64 -DSUBTYPE="CPU_SUBTYPE_ARM64E_X1 (0xC)" ++ + # ARM64:File: [[FILE]] + # ARM64-NEXT:Format: Mach-O arm64 + # ARM64-NEXT:Arch: aarch64 +--- llvm/tools/llvm-objdump/MachODump.cpp ++++ llvm/tools/llvm-objdump/MachODump.cpp +@@ -2323,6 +2323,10 @@ + outs() << " cputype CPU_TYPE_ARM64\n"; + outs() << " cpusubtype CPU_SUBTYPE_ARM64E\n"; + break; ++ case MachO::CPU_SUBTYPE_ARM64E_X1: ++ outs() << " cputype CPU_TYPE_ARM64\n"; ++ outs() << " cpusubtype CPU_SUBTYPE_ARM64E_X1\n"; ++ break; + default: + printUnknownCPUType(cputype, cpusubtype); + break; +@@ -8337,6 +8341,9 @@ + case MachO::CPU_SUBTYPE_ARM64E: + outs() << " E"; + break; ++ case MachO::CPU_SUBTYPE_ARM64E_X1: ++ outs() << " E.X1"; ++ break; + default: + outs() << format(" %10d", cpusubtype & ~MachO::CPU_SUBTYPE_MASK); + break; +--- llvm/tools/llvm-readobj/MachODumper.cpp ++++ llvm/tools/llvm-readobj/MachODumper.cpp +@@ -170,6 +170,7 @@ + LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64_ALL), + LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64_V8), + LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64E), ++ LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64E_X1), + }; + + const EnumEntry MachOHeaderCpuSubtypesSPARC[] = { +--- llvm/unittests/BinaryFormat/MachOTest.cpp ++++ llvm/unittests/BinaryFormat/MachOTest.cpp +@@ -66,6 +66,7 @@ + CHECK_CPUTYPE("thumbv7-apple-darwin", MachO::CPU_TYPE_ARM); + CHECK_CPUTYPE("arm64-apple-darwin", MachO::CPU_TYPE_ARM64); + CHECK_CPUTYPE("arm64e-apple-darwin", MachO::CPU_TYPE_ARM64); ++ CHECK_CPUTYPE("arm64e.x1-apple-darwin", MachO::CPU_TYPE_ARM64); + CHECK_CPUTYPE("arm64_32-apple-darwin", MachO::CPU_TYPE_ARM64_32); + + { +@@ -107,6 +108,7 @@ + CHECK_CPUSUBTYPE("thumbv6-apple-darwin", MachO::CPU_SUBTYPE_ARM_V6); + CHECK_CPUSUBTYPE("arm64-apple-darwin", MachO::CPU_SUBTYPE_ARM64_ALL); + CHECK_CPUSUBTYPE("arm64e-apple-darwin", MachO::CPU_SUBTYPE_ARM64E); ++ CHECK_CPUSUBTYPE("arm64e.x1-apple-darwin", MachO::CPU_SUBTYPE_ARM64E_X1); + CHECK_CPUSUBTYPE("arm64_32-apple-darwin", MachO::CPU_SUBTYPE_ARM64_32_V8); + + { +--- /dev/null ++++ lld/test/MachO/arm64-x1.s +@@ -0,0 +1,20 @@ ++# REQUIRES: aarch64 ++ ++## Test that arm64.x1-macos is ignored instead of causing an error. ++## linked re-exported dylibs that only declare arm64e-macos targets, even if targeting arm64. ++# arm64 and arm64e are ABI compatible (same CPU type), and ld64 accepts this. ++ ++# RUN: rm -rf %t; split-file --no-leading-lines %s %t ++ ++# RUN: llvm-mc -filetype=obj -triple=arm64-apple-macos -o %t/test.o /dev/null ++ ++# RUN: %no-arg-lld -syslibroot %t/sdk -lSystem -dylib -arch arm64 \ ++# RUN: -platform_version macos 15 26 %t/test.o -o /dev/null ++ ++#--- sdk/usr/lib/libSystem.tbd ++--- !tapi-tbd ++tbd-version: 4 ++targets: [ arm64-macos, arm64e.x1-macos ] ++install-name: '/usr/lib/libSystem.dylib' ++current-version: 0001.001.1 ++... +--- /dev/null ++++ llvm/test/tools/llvm-readobj/macho-arm64e_x1.test +@@ -0,0 +1,17 @@ ++# RUN: yaml2obj %s -o %t.o ++# RUN: llvm-readobj -h %t.o | FileCheck %s ++ ++# CHECK: Magic: Magic64 (0xFEEDFACF) ++# CHECK: CpuType: Arm64 (0x100000C) ++# CHECK: CpuSubType: CPU_SUBTYPE_ARM64E_X1 (0xC) ++ ++--- !mach-o ++FileHeader: ++ magic: 0xFEEDFACF ++ cputype: 0x0100000C ++ cpusubtype: 0x0000000C ++ filetype: 0x00000001 ++ ncmds: 0 ++ sizeofcmds: 0 ++ flags: 0x00000000 ++ reserved: 0x00000000 diff --git a/pkgs/development/compilers/llvm/22/llvm/backport-minimal-arm64e_x1-support.patch b/pkgs/development/compilers/llvm/22/llvm/backport-minimal-arm64e_x1-support.patch new file mode 100644 index 000000000000..9aaa39d98eaa --- /dev/null +++ b/pkgs/development/compilers/llvm/22/llvm/backport-minimal-arm64e_x1-support.patch @@ -0,0 +1,205 @@ +--- llvm/include/llvm/BinaryFormat/MachO.h ++++ llvm/include/llvm/BinaryFormat/MachO.h +@@ -1715,6 +1715,7 @@ + CPU_SUBTYPE_ARM64_ALL = 0, + CPU_SUBTYPE_ARM64_V8 = 1, + CPU_SUBTYPE_ARM64E = 2, ++ CPU_SUBTYPE_ARM64E_X1 = 12, + + // arm64e uses the capability bits to encode ptrauth ABI information. + // Bit 63 marks the binary as Versioned. +--- llvm/include/llvm/TargetParser/Triple.h ++++ llvm/include/llvm/TargetParser/Triple.h +@@ -157,6 +157,7 @@ + ARMSubArch_v4t, + + AArch64SubArch_arm64e, ++ AArch64SubArch_arm64e_x1, + AArch64SubArch_arm64ec, + AArch64SubArch_lfi, + +@@ -1220,6 +1221,11 @@ + getSubArch() == Triple::AArch64SubArch_arm64e; + } + ++ bool isArm64e_x1() const { ++ return getArch() == Triple::aarch64 && ++ getSubArch() == Triple::AArch64SubArch_arm64e_x1; ++ } ++ + // Tests whether the target is N32. + bool isABIN32() const { + EnvironmentType Env = getEnvironment(); +--- llvm/include/llvm/TextAPI/Architecture.def ++++ llvm/include/llvm/TextAPI/Architecture.def +@@ -39,7 +39,7 @@ + /// + ARCHINFO(arm64, arm64, MachO::CPU_TYPE_ARM64, MachO::CPU_SUBTYPE_ARM64_ALL, 64) + ARCHINFO(arm64e, arm64e, MachO::CPU_TYPE_ARM64, MachO::CPU_SUBTYPE_ARM64E, 64) +- ++ARCHINFO(arm64e_x1, arm64e.x1, MachO::CPU_TYPE_ARM64, MachO::CPU_SUBTYPE_ARM64E_X1, 64) + + /// + /// ARM64_32 architectures sorted by cpu sub type id +--- llvm/lib/BinaryFormat/MachO.cpp ++++ llvm/lib/BinaryFormat/MachO.cpp +@@ -66,6 +66,8 @@ + return (MachO::CPUSubTypeARM64)MachO::CPU_SUBTYPE_ARM64_32_V8; + if (T.isArm64e()) + return MachO::CPU_SUBTYPE_ARM64E; ++ if (T.isArm64e_x1()) ++ return MachO::CPU_SUBTYPE_ARM64E_X1; + + return MachO::CPU_SUBTYPE_ARM64_ALL; + } +--- llvm/lib/Object/MachOObjectFile.cpp ++++ llvm/lib/Object/MachOObjectFile.cpp +@@ -2919,6 +2919,12 @@ + if (ArchFlag) + *ArchFlag = "arm64e"; + return Triple("arm64e-apple-darwin"); ++ case MachO::CPU_SUBTYPE_ARM64E_X1: ++ if (McpuDefault) ++ *McpuDefault = "apple-a20"; ++ if (ArchFlag) ++ *ArchFlag = "arm64e.x1"; ++ return Triple("arm64e.x1-apple-darwin"); + default: + return Triple(); + } +--- llvm/lib/TargetParser/Triple.cpp ++++ llvm/lib/TargetParser/Triple.cpp +@@ -191,6 +191,8 @@ + return "arm64ec"; + if (SubArch == AArch64SubArch_arm64e) + return "arm64e"; ++ if (SubArch == AArch64SubArch_arm64e_x1) ++ return "arm64e.x1"; + if (SubArch == AArch64SubArch_lfi) + return "aarch64_lfi"; + break; +@@ -612,6 +614,7 @@ + .Case("arm64", Triple::aarch64) + .Case("arm64_32", Triple::aarch64_32) + .Case("arm64e", Triple::aarch64) ++ .Case("arm64e.x1", Triple::aarch64) + .Case("arm64ec", Triple::aarch64) + .Case("arm", Triple::arm) + .Case("armeb", Triple::armeb) +@@ -739,6 +742,8 @@ + + if (SubArchName == "arm64e") + return Triple::AArch64SubArch_arm64e; ++ if (SubArchName == "arm64e.x1") ++ return Triple::AArch64SubArch_arm64e_x1; + + if (SubArchName == "arm64ec") + return Triple::AArch64SubArch_arm64ec; +--- llvm/test/tools/llvm-readobj/MachO/file-headers-arm64.test ++++ llvm/test/tools/llvm-readobj/MachO/file-headers-arm64.test +@@ -13,6 +13,11 @@ + # RUN: llvm-readobj -h %t.arm64e \ + # RUN: | FileCheck %s --strict-whitespace --match-full-lines -DFILE=%t.arm64e --check-prefix=ARM64 -DSUBTYPE="CPU_SUBTYPE_ARM64E (0x2)" + ++## Check subtype Arm64E.X1: ++# RUN: yaml2obj %s -o %t.arm64e.x1 -DSUBTYPE=0xC ++# RUN: llvm-readobj -h %t.arm64e.x1 \ ++# RUN: | FileCheck %s --strict-whitespace --match-full-lines -DFILE=%t.arm64e.x1 --check-prefix=ARM64 -DSUBTYPE="CPU_SUBTYPE_ARM64E_X1 (0xC)" ++ + # ARM64:File: [[FILE]] + # ARM64-NEXT:Format: Mach-O arm64 + # ARM64-NEXT:Arch: aarch64 +--- llvm/tools/llvm-objdump/MachODump.cpp ++++ llvm/tools/llvm-objdump/MachODump.cpp +@@ -2344,6 +2344,10 @@ + outs() << " cputype CPU_TYPE_ARM64\n"; + outs() << " cpusubtype CPU_SUBTYPE_ARM64E\n"; + break; ++ case MachO::CPU_SUBTYPE_ARM64E_X1: ++ outs() << " cputype CPU_TYPE_ARM64\n"; ++ outs() << " cpusubtype CPU_SUBTYPE_ARM64E_X1\n"; ++ break; + default: + printUnknownCPUType(cputype, cpusubtype); + break; +@@ -8472,6 +8476,9 @@ + case MachO::CPU_SUBTYPE_ARM64E: + outs() << " E"; + break; ++ case MachO::CPU_SUBTYPE_ARM64E_X1: ++ outs() << " E.X1"; ++ break; + default: + outs() << format(" %10d", cpusubtype & ~MachO::CPU_SUBTYPE_MASK); + break; +--- llvm/tools/llvm-readobj/MachODumper.cpp ++++ llvm/tools/llvm-readobj/MachODumper.cpp +@@ -190,6 +190,7 @@ + LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64_ALL), + LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64_V8), + LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64E), ++ LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64E_X1), + }; + constexpr auto MachOHeaderCpuSubtypesARM64 = + BUILD_ENUM_STRINGS(MachOHeaderCpuSubtypesARM64Defs); +--- llvm/unittests/BinaryFormat/MachOTest.cpp ++++ llvm/unittests/BinaryFormat/MachOTest.cpp +@@ -66,6 +66,7 @@ + CHECK_CPUTYPE("thumbv7-apple-darwin", MachO::CPU_TYPE_ARM); + CHECK_CPUTYPE("arm64-apple-darwin", MachO::CPU_TYPE_ARM64); + CHECK_CPUTYPE("arm64e-apple-darwin", MachO::CPU_TYPE_ARM64); ++ CHECK_CPUTYPE("arm64e.x1-apple-darwin", MachO::CPU_TYPE_ARM64); + CHECK_CPUTYPE("arm64_32-apple-darwin", MachO::CPU_TYPE_ARM64_32); + + { +@@ -107,6 +108,7 @@ + CHECK_CPUSUBTYPE("thumbv6-apple-darwin", MachO::CPU_SUBTYPE_ARM_V6); + CHECK_CPUSUBTYPE("arm64-apple-darwin", MachO::CPU_SUBTYPE_ARM64_ALL); + CHECK_CPUSUBTYPE("arm64e-apple-darwin", MachO::CPU_SUBTYPE_ARM64E); ++ CHECK_CPUSUBTYPE("arm64e.x1-apple-darwin", MachO::CPU_SUBTYPE_ARM64E_X1); + CHECK_CPUSUBTYPE("arm64_32-apple-darwin", MachO::CPU_SUBTYPE_ARM64_32_V8); + CHECK_CPUSUBTYPE("armv8m.main-apple-darwin", MachO::CPU_SUBTYPE_ARM_V8M_MAIN); + CHECK_CPUSUBTYPE("armv8m.base-apple-darwin", MachO::CPU_SUBTYPE_ARM_V8M_BASE); +--- /dev/null ++++ lld/test/MachO/arm64-x1.s +@@ -0,0 +1,20 @@ ++# REQUIRES: aarch64 ++ ++## Test that arm64.x1-macos is ignored instead of causing an error. ++## linked re-exported dylibs that only declare arm64e-macos targets, even if targeting arm64. ++# arm64 and arm64e are ABI compatible (same CPU type), and ld64 accepts this. ++ ++# RUN: rm -rf %t; split-file --no-leading-lines %s %t ++ ++# RUN: llvm-mc -filetype=obj -triple=arm64-apple-macos -o %t/test.o /dev/null ++ ++# RUN: %no-arg-lld -syslibroot %t/sdk -lSystem -dylib -arch arm64 \ ++# RUN: -platform_version macos 15 26 %t/test.o -o /dev/null ++ ++#--- sdk/usr/lib/libSystem.tbd ++--- !tapi-tbd ++tbd-version: 4 ++targets: [ arm64-macos, arm64e.x1-macos ] ++install-name: '/usr/lib/libSystem.dylib' ++current-version: 0001.001.1 ++... +--- /dev/null ++++ llvm/test/tools/llvm-readobj/macho-arm64e_x1.test +@@ -0,0 +1,17 @@ ++# RUN: yaml2obj %s -o %t.o ++# RUN: llvm-readobj -h %t.o | FileCheck %s ++ ++# CHECK: Magic: Magic64 (0xFEEDFACF) ++# CHECK: CpuType: Arm64 (0x100000C) ++# CHECK: CpuSubType: CPU_SUBTYPE_ARM64E_X1 (0xC) ++ ++--- !mach-o ++FileHeader: ++ magic: 0xFEEDFACF ++ cputype: 0x0100000C ++ cpusubtype: 0x0000000C ++ filetype: 0x00000001 ++ ncmds: 0 ++ sizeofcmds: 0 ++ flags: 0x00000000 ++ reserved: 0x00000000 diff --git a/pkgs/development/compilers/llvm/common/llvm/default.nix b/pkgs/development/compilers/llvm/common/llvm/default.nix index 98e7132b32af..20a541a48229 100644 --- a/pkgs/development/compilers/llvm/common/llvm/default.nix +++ b/pkgs/development/compilers/llvm/common/llvm/default.nix @@ -263,6 +263,21 @@ stdenv.mkDerivation ( # This patch is a backport of the target parsing changes in LLVM 23, which fixes the problem. # Hopefully, Apple does not change the version number scheme again any time soon. (getVersionFile "llvm/backport-darwin-triple-parsing.patch") + ] + ++ lib.optionals (lib.versionOlder release_version "22") [ + # Needed to add arm64e.x1 support, as the enum name differs from the architecture name + (fetchpatch { + name = "llvm-textapi-separate-arch-name-enum-label.patch"; + url = "https://github.com/llvm/llvm-project/commit/477a65a051ce151895193f8dede1262fdc251132.patch"; + stripLen = 1; + hash = "sha256-XXteX2zK5TzFQX+XhLzUtikY4PkCWF1f8l5MshelzX4="; + }) + ] + ++ lib.optionals (lib.versionOlder release_version "23") [ + # Needed to link with the macOS 27 sdk, as it has libraries linked for arm64e.x1 + # a new arm64 subtype that gives more pointer authentication machinery. + # Vendored backport of the patch for LLVM 23 + (getVersionFile "llvm/backport-minimal-arm64e_x1-support.patch") ]; nativeBuildInputs = [ diff --git a/pkgs/development/compilers/llvm/common/patches.nix b/pkgs/development/compilers/llvm/common/patches.nix index 22d0a695e253..6e4e8531605a 100644 --- a/pkgs/development/compilers/llvm/common/patches.nix +++ b/pkgs/development/compilers/llvm/common/patches.nix @@ -52,6 +52,27 @@ path = ../21; } ]; + "llvm/backport-minimal-arm64e_x1-support.patch" = [ + { + after = "18"; + before = "19"; + path = ../18; + } + { + after = "19"; + before = "20"; + path = ../19; + } + { + after = "20"; + before = "22"; + path = ../20; + } + { + after = "22"; + path = ../22; + } + ]; "llvm/gnu-install-dirs.patch" = [ { after = "23"; diff --git a/pkgs/development/compilers/swift/by-name/ll/llvmPackages/package.nix b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/package.nix index 646756638d5e..8818d083d358 100644 --- a/pkgs/development/compilers/swift/by-name/ll/llvmPackages/package.nix +++ b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/package.nix @@ -50,6 +50,8 @@ in "lldb/backport-ParseTrieEntries-fixes.patch" = [ { path = ./patches; } ]; # Update backport of the Darwin triple changes for macOS 27. "llvm/backport-darwin-triple-parsing.patch" = [ { path = ./patches; } ]; + # Backport support for arm64e.x1, the new cpu subtype for A20 and M6 + "llvm/backport-minimal-arm64e_x1-support.patch" = [ { path = ./patches; } ]; }; }).overrideScope ( diff --git a/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/llvm/backport-minimal-arm64e_x1-support.patch b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/llvm/backport-minimal-arm64e_x1-support.patch new file mode 100644 index 000000000000..78c93624c17a --- /dev/null +++ b/pkgs/development/compilers/swift/by-name/ll/llvmPackages/patches/llvm/backport-minimal-arm64e_x1-support.patch @@ -0,0 +1,205 @@ +--- llvm/include/llvm/BinaryFormat/MachO.h ++++ llvm/include/llvm/BinaryFormat/MachO.h +@@ -1643,6 +1643,7 @@ + CPU_SUBTYPE_ARM64_ALL = 0, + CPU_SUBTYPE_ARM64_V8 = 1, + CPU_SUBTYPE_ARM64E = 2, ++ CPU_SUBTYPE_ARM64E_X1 = 12, + + // arm64 reserves bits in the high byte for subtype-specific flags. + // On arm64e, the 6 low bits represent the ptrauth ABI version. +--- llvm/include/llvm/TargetParser/Triple.h ++++ llvm/include/llvm/TargetParser/Triple.h +@@ -147,6 +147,7 @@ + ARMSubArch_v4t, + + AArch64SubArch_arm64e, ++ AArch64SubArch_arm64e_x1, + AArch64SubArch_arm64ec, + + KalimbaSubArch_v3, +@@ -1048,6 +1049,11 @@ + getSubArch() == Triple::AArch64SubArch_arm64e; + } + ++ bool isArm64e_x1() const { ++ return getArch() == Triple::aarch64 && ++ getSubArch() == Triple::AArch64SubArch_arm64e_x1; ++ } ++ + /// Tests whether the target is X32. + bool isX32() const { + EnvironmentType Env = getEnvironment(); +--- llvm/include/llvm/TextAPI/Architecture.def ++++ llvm/include/llvm/TextAPI/Architecture.def +@@ -37,7 +37,7 @@ + /// + ARCHINFO(arm64, arm64, MachO::CPU_TYPE_ARM64, MachO::CPU_SUBTYPE_ARM64_ALL, 64) + ARCHINFO(arm64e, arm64e, MachO::CPU_TYPE_ARM64, MachO::CPU_SUBTYPE_ARM64E, 64) +- ++ARCHINFO(arm64e_x1, arm64e.x1, MachO::CPU_TYPE_ARM64, MachO::CPU_SUBTYPE_ARM64E_X1, 64) + + /// + /// ARM64_32 architectures sorted by cpu sub type id +--- llvm/lib/BinaryFormat/MachO.cpp ++++ llvm/lib/BinaryFormat/MachO.cpp +@@ -60,6 +60,8 @@ + return (MachO::CPUSubTypeARM64)MachO::CPU_SUBTYPE_ARM64_32_V8; + if (T.isArm64e()) + return MachO::CPU_SUBTYPE_ARM64E; ++ if (T.isArm64e_x1()) ++ return MachO::CPU_SUBTYPE_ARM64E_X1; + + return MachO::CPU_SUBTYPE_ARM64_ALL; + } +--- llvm/lib/Object/MachOObjectFile.cpp ++++ llvm/lib/Object/MachOObjectFile.cpp +@@ -2810,6 +2810,12 @@ + if (ArchFlag) + *ArchFlag = "arm64e"; + return Triple("arm64e-apple-darwin"); ++ case MachO::CPU_SUBTYPE_ARM64E_X1: ++ if (McpuDefault) ++ *McpuDefault = "apple-a20"; ++ if (ArchFlag) ++ *ArchFlag = "arm64e.x1"; ++ return Triple("arm64e.x1-apple-darwin"); + default: + return Triple(); + } +--- llvm/lib/TargetParser/Triple.cpp ++++ llvm/lib/TargetParser/Triple.cpp +@@ -114,6 +114,8 @@ + return "arm64ec"; + if (SubArch == AArch64SubArch_arm64e) + return "arm64e"; ++ if (SubArch == AArch64SubArch_arm64e_x1) ++ return "arm64e.x1"; + break; + case Triple::dxil: + switch (SubArch) { +@@ -550,6 +552,7 @@ + .Case("arm64", Triple::aarch64) + .Case("arm64_32", Triple::aarch64_32) + .Case("arm64e", Triple::aarch64) ++ .Case("arm64e.x1", Triple::aarch64) + .Case("arm64ec", Triple::aarch64) + .Case("arm", Triple::arm) + .Case("armeb", Triple::armeb) +@@ -766,6 +769,8 @@ + + if (SubArchName == "arm64e") + return Triple::AArch64SubArch_arm64e; ++ if (SubArchName == "arm64e.x1") ++ return Triple::AArch64SubArch_arm64e_x1; + + if (SubArchName == "arm64ec") + return Triple::AArch64SubArch_arm64ec; +--- llvm/test/tools/llvm-readobj/MachO/file-headers-arm64.test ++++ llvm/test/tools/llvm-readobj/MachO/file-headers-arm64.test +@@ -13,6 +13,11 @@ + # RUN: llvm-readobj -h %t.arm64e \ + # RUN: | FileCheck %s --strict-whitespace --match-full-lines -DFILE=%t.arm64e --check-prefix=ARM64 -DSUBTYPE="CPU_SUBTYPE_ARM64E (0x2)" + ++## Check subtype Arm64E.X1: ++# RUN: yaml2obj %s -o %t.arm64e.x1 -DSUBTYPE=0xC ++# RUN: llvm-readobj -h %t.arm64e.x1 \ ++# RUN: | FileCheck %s --strict-whitespace --match-full-lines -DFILE=%t.arm64e.x1 --check-prefix=ARM64 -DSUBTYPE="CPU_SUBTYPE_ARM64E_X1 (0xC)" ++ + # ARM64:File: [[FILE]] + # ARM64-NEXT:Format: Mach-O arm64{{e?}} + # ARM64-NEXT:Arch: aarch64 +--- llvm/tools/llvm-objdump/MachODump.cpp ++++ llvm/tools/llvm-objdump/MachODump.cpp +@@ -2323,6 +2323,10 @@ + outs() << " cputype CPU_TYPE_ARM64\n"; + outs() << " cpusubtype CPU_SUBTYPE_ARM64E\n"; + break; ++ case MachO::CPU_SUBTYPE_ARM64E_X1: ++ outs() << " cputype CPU_TYPE_ARM64\n"; ++ outs() << " cpusubtype CPU_SUBTYPE_ARM64E_X1\n"; ++ break; + default: + printUnknownCPUType(cputype, cpusubtype); + break; +@@ -8333,6 +8337,9 @@ + case MachO::CPU_SUBTYPE_ARM64E: + outs() << " E"; + break; ++ case MachO::CPU_SUBTYPE_ARM64E_X1: ++ outs() << " E.X1"; ++ break; + default: + outs() << format(" %10d", cpusubtype & ~MachO::CPU_SUBTYPE_MASK); + break; +--- llvm/tools/llvm-readobj/MachODumper.cpp ++++ llvm/tools/llvm-readobj/MachODumper.cpp +@@ -170,6 +170,7 @@ + LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64_ALL), + LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64_V8), + LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64E), ++ LLVM_READOBJ_ENUM_ENT(MachO, CPU_SUBTYPE_ARM64E_X1), + }; + + const EnumEntry MachOHeaderCpuSubtypesSPARC[] = { +--- llvm/unittests/BinaryFormat/MachOTest.cpp ++++ llvm/unittests/BinaryFormat/MachOTest.cpp +@@ -66,6 +66,7 @@ + CHECK_CPUTYPE("thumbv7-apple-darwin", MachO::CPU_TYPE_ARM); + CHECK_CPUTYPE("arm64-apple-darwin", MachO::CPU_TYPE_ARM64); + CHECK_CPUTYPE("arm64e-apple-darwin", MachO::CPU_TYPE_ARM64); ++ CHECK_CPUTYPE("arm64e.x1-apple-darwin", MachO::CPU_TYPE_ARM64); + CHECK_CPUTYPE("arm64_32-apple-darwin", MachO::CPU_TYPE_ARM64_32); + + { +@@ -107,6 +108,7 @@ + CHECK_CPUSUBTYPE("thumbv6-apple-darwin", MachO::CPU_SUBTYPE_ARM_V6); + CHECK_CPUSUBTYPE("arm64-apple-darwin", MachO::CPU_SUBTYPE_ARM64_ALL); + CHECK_CPUSUBTYPE("arm64e-apple-darwin", MachO::CPU_SUBTYPE_ARM64E); ++ CHECK_CPUSUBTYPE("arm64e.x1-apple-darwin", MachO::CPU_SUBTYPE_ARM64E_X1); + CHECK_CPUSUBTYPE("arm64_32-apple-darwin", MachO::CPU_SUBTYPE_ARM64_32_V8); + + { +--- /dev/null ++++ lld/test/MachO/arm64-x1.s +@@ -0,0 +1,20 @@ ++# REQUIRES: aarch64 ++ ++## Test that arm64.x1-macos is ignored instead of causing an error. ++## linked re-exported dylibs that only declare arm64e-macos targets, even if targeting arm64. ++# arm64 and arm64e are ABI compatible (same CPU type), and ld64 accepts this. ++ ++# RUN: rm -rf %t; split-file --no-leading-lines %s %t ++ ++# RUN: llvm-mc -filetype=obj -triple=arm64-apple-macos -o %t/test.o /dev/null ++ ++# RUN: %no-arg-lld -syslibroot %t/sdk -lSystem -dylib -arch arm64 \ ++# RUN: -platform_version macos 15 26 %t/test.o -o /dev/null ++ ++#--- sdk/usr/lib/libSystem.tbd ++--- !tapi-tbd ++tbd-version: 4 ++targets: [ arm64-macos, arm64e.x1-macos ] ++install-name: '/usr/lib/libSystem.dylib' ++current-version: 0001.001.1 ++... +--- /dev/null ++++ llvm/test/tools/llvm-readobj/macho-arm64e_x1.test +@@ -0,0 +1,17 @@ ++# RUN: yaml2obj %s -o %t.o ++# RUN: llvm-readobj -h %t.o | FileCheck %s ++ ++# CHECK: Magic: Magic64 (0xFEEDFACF) ++# CHECK: CpuType: Arm64 (0x100000C) ++# CHECK: CpuSubType: CPU_SUBTYPE_ARM64E_X1 (0xC) ++ ++--- !mach-o ++FileHeader: ++ magic: 0xFEEDFACF ++ cputype: 0x0100000C ++ cpusubtype: 0x0000000C ++ filetype: 0x00000001 ++ ncmds: 0 ++ sizeofcmds: 0 ++ flags: 0x00000000 ++ reserved: 0x00000000 From 4b9403aca7fdb3ebee789cb7f1a09c15ae4d75f1 Mon Sep 17 00:00:00 2001 From: sempiternal-aurora <78790545+sempiternal-aurora@users.noreply.github.com> Date: Thu, 17 Sep 2026 00:47:32 +0200 Subject: [PATCH 293/423] apple-sdk_{14,15,26}: remove callPackage to by-name in all-packages A nice to do clean-up that brings things into a style I've done before. Does cause the sdks to be built with an earlier stage, but otherwise doesn't seem to cause any breakages. --- pkgs/top-level/all-packages.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 4ef980f80f6a..df927440ac02 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -6771,9 +6771,9 @@ with pkgs; ### DEVELOPMENT / LIBRARIES / DARWIN SDKS - apple-sdk_14 = callPackage ../by-name/ap/apple-sdk/package.nix { darwinSdkMajorVersion = "14"; }; - apple-sdk_15 = callPackage ../by-name/ap/apple-sdk/package.nix { darwinSdkMajorVersion = "15"; }; - apple-sdk_26 = callPackage ../by-name/ap/apple-sdk/package.nix { darwinSdkMajorVersion = "26"; }; + apple-sdk_14 = apple-sdk.override { darwinSdkMajorVersion = "14"; }; + apple-sdk_15 = apple-sdk.override { darwinSdkMajorVersion = "15"; }; + apple-sdk_26 = apple-sdk.override { darwinSdkMajorVersion = "26"; }; darwinMinVersionHook = deploymentTarget: From 041da8cd789202a4ba02c5e02416bd91b4c31c81 Mon Sep 17 00:00:00 2001 From: sempiternal-aurora <78790545+sempiternal-aurora@users.noreply.github.com> Date: Thu, 17 Sep 2026 00:03:09 +0200 Subject: [PATCH 294/423] apple-sdk_27: init at 27.0 --- doc/stdenv/platform-notes.chapter.md | 3 ++- pkgs/by-name/ap/apple-sdk/metadata/versions.json | 8 ++++++++ pkgs/top-level/all-packages.nix | 1 + 3 files changed, 11 insertions(+), 1 deletion(-) diff --git a/doc/stdenv/platform-notes.chapter.md b/doc/stdenv/platform-notes.chapter.md index fac864ad210b..7b18ef044745 100644 --- a/doc/stdenv/platform-notes.chapter.md +++ b/doc/stdenv/platform-notes.chapter.md @@ -121,7 +121,8 @@ Generally, only the last SDK release for a major version is packaged. |---------------|-------------|------------------------------| | 15.0–15.4 | 14.4 | `apple-sdk_14` / `apple-sdk` | | 16.0 | 15.0 | `apple-sdk_15` | -| 26.0+ | 26.0+ | `apple-sdk_26`, etc | +| 26.0 | 26.0 | `apple-sdk_26` | +| 27.0+ | 27.0+ | `apple-sdk_27`, etc | #### Darwin Default SDK versions {#sec-darwin-troubleshooting-darwin-defaults} diff --git a/pkgs/by-name/ap/apple-sdk/metadata/versions.json b/pkgs/by-name/ap/apple-sdk/metadata/versions.json index d655c7ebada9..d589cc6940cf 100644 --- a/pkgs/by-name/ap/apple-sdk/metadata/versions.json +++ b/pkgs/by-name/ap/apple-sdk/metadata/versions.json @@ -22,5 +22,13 @@ ], "version": "26.5", "hash": "sha256-IkDNtiO7PP4GI6OszCNWE1Xb4iepCUKwQHYUyc9NgNA=" + }, + "27": { + "urls": [ + "https://swcdn.apple.com/content/downloads/58/48/082-83364-A_KCEBOO2NJS/0d2rj4y5ucjlkgcvqt6f6a4pergug5tu2b/CLTools_macOSNMOS_SDK.pkg", + "https://web.archive.org/web/20260910221111/https://swcdn.apple.com/content/downloads/58/48/082-83364-A_KCEBOO2NJS/0d2rj4y5ucjlkgcvqt6f6a4pergug5tu2b/CLTools_macOSNMOS_SDK.pkg" + ], + "version": "27.0", + "hash": "sha256-qTDE8wu3pfk21WtgboKHYH/MiJnC8gKpDeMyrRJZaP8=" } } diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index df927440ac02..c98ea37d5d42 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -6774,6 +6774,7 @@ with pkgs; apple-sdk_14 = apple-sdk.override { darwinSdkMajorVersion = "14"; }; apple-sdk_15 = apple-sdk.override { darwinSdkMajorVersion = "15"; }; apple-sdk_26 = apple-sdk.override { darwinSdkMajorVersion = "26"; }; + apple-sdk_27 = apple-sdk.override { darwinSdkMajorVersion = "27"; }; darwinMinVersionHook = deploymentTarget: From 927856c7c3b95fe8d111e3676ce8a8e7037220d9 Mon Sep 17 00:00:00 2001 From: sempiternal-aurora <78790545+sempiternal-aurora@users.noreply.github.com> Date: Thu, 17 Sep 2026 00:03:43 +0200 Subject: [PATCH 295/423] apple-sdk: add tests for different versions --- pkgs/by-name/ap/apple-sdk/package.nix | 1 + .../ap/apple-sdk/tests/15/apple-sdk_15-test.m | 10 +++ .../by-name/ap/apple-sdk/tests/15/meson.build | 2 + .../ap/apple-sdk/tests/26/apple-sdk_26-test.m | 21 +++++++ .../by-name/ap/apple-sdk/tests/26/meson.build | 2 + .../ap/apple-sdk/tests/27/apple-sdk_27-test.m | 15 +++++ .../by-name/ap/apple-sdk/tests/27/meson.build | 2 + pkgs/by-name/ap/apple-sdk/tests/default.nix | 61 +++++++++++++++++++ 8 files changed, 114 insertions(+) create mode 100644 pkgs/by-name/ap/apple-sdk/tests/15/apple-sdk_15-test.m create mode 100644 pkgs/by-name/ap/apple-sdk/tests/15/meson.build create mode 100644 pkgs/by-name/ap/apple-sdk/tests/26/apple-sdk_26-test.m create mode 100644 pkgs/by-name/ap/apple-sdk/tests/26/meson.build create mode 100644 pkgs/by-name/ap/apple-sdk/tests/27/apple-sdk_27-test.m create mode 100644 pkgs/by-name/ap/apple-sdk/tests/27/meson.build create mode 100644 pkgs/by-name/ap/apple-sdk/tests/default.nix diff --git a/pkgs/by-name/ap/apple-sdk/package.nix b/pkgs/by-name/ap/apple-sdk/package.nix index 761ebb903e8f..04a0fdee1e0a 100644 --- a/pkgs/by-name/ap/apple-sdk/package.nix +++ b/pkgs/by-name/ap/apple-sdk/package.nix @@ -100,6 +100,7 @@ stdenvNoCC.mkDerivation ( passthru = { sdkroot = finalAttrs.finalPackage + "/Platforms/MacOSX.platform/Developer/SDKs/MacOSX.sdk"; + tests = callPackage ./tests { }; }; __structuredAttrs = true; diff --git a/pkgs/by-name/ap/apple-sdk/tests/15/apple-sdk_15-test.m b/pkgs/by-name/ap/apple-sdk/tests/15/apple-sdk_15-test.m new file mode 100644 index 000000000000..f2e55a76e92f --- /dev/null +++ b/pkgs/by-name/ap/apple-sdk/tests/15/apple-sdk_15-test.m @@ -0,0 +1,10 @@ +#include +#include + +int main() { + if (@available(macOS 15, *)) { + printf("%f\n", (double) __sqrtf16(2)); + } else { + printf(":(\n"); + } +} diff --git a/pkgs/by-name/ap/apple-sdk/tests/15/meson.build b/pkgs/by-name/ap/apple-sdk/tests/15/meson.build new file mode 100644 index 000000000000..c2d56fd595d2 --- /dev/null +++ b/pkgs/by-name/ap/apple-sdk/tests/15/meson.build @@ -0,0 +1,2 @@ +project('apple-sdk_15-test', 'objc') +executable('apple-sdk_15-test', 'apple-sdk_15-test.m', install : true) diff --git a/pkgs/by-name/ap/apple-sdk/tests/26/apple-sdk_26-test.m b/pkgs/by-name/ap/apple-sdk/tests/26/apple-sdk_26-test.m new file mode 100644 index 000000000000..21fc3af5253a --- /dev/null +++ b/pkgs/by-name/ap/apple-sdk/tests/26/apple-sdk_26-test.m @@ -0,0 +1,21 @@ +#include +#include + +int main(int argc, char** argv, char** env) { + if (@available(macOS 26, *)) { + int ret; + pid_t pid; + posix_spawn_file_actions_t actions; + if ((ret = posix_spawn_file_actions_init(&actions))) { + printf("cannot create file_actions\n"); + } + if ((ret = posix_spawn_file_actions_addchdir(&actions, "/tmp"))) { + printf("cannot add_chdir\n"); + } + if ((ret = posix_spawnp(&pid, "pwd", &actions, NULL, argv, env))) { + printf("cannot spawn\n"); + } + } else { + printf(":(\n"); + } +} diff --git a/pkgs/by-name/ap/apple-sdk/tests/26/meson.build b/pkgs/by-name/ap/apple-sdk/tests/26/meson.build new file mode 100644 index 000000000000..ef3a4c6179aa --- /dev/null +++ b/pkgs/by-name/ap/apple-sdk/tests/26/meson.build @@ -0,0 +1,2 @@ +project('apple-sdk_26-test', 'objc') +executable('apple-sdk_26-test', 'apple-sdk_26-test.m', install : true) diff --git a/pkgs/by-name/ap/apple-sdk/tests/27/apple-sdk_27-test.m b/pkgs/by-name/ap/apple-sdk/tests/27/apple-sdk_27-test.m new file mode 100644 index 000000000000..6ae05bc7bc69 --- /dev/null +++ b/pkgs/by-name/ap/apple-sdk/tests/27/apple-sdk_27-test.m @@ -0,0 +1,15 @@ +#include +#include + +int main() { + if (@available(macOS 27, *)) { + int ret = dup3(1, 3, 0); + if (ret < 0) { + printf("dup3(1,3,0) failed with error\n"); + return -1; + } + dprintf(3, ":)\n"); + } else { + printf(":(\n"); + } +} diff --git a/pkgs/by-name/ap/apple-sdk/tests/27/meson.build b/pkgs/by-name/ap/apple-sdk/tests/27/meson.build new file mode 100644 index 000000000000..9169cd8d251b --- /dev/null +++ b/pkgs/by-name/ap/apple-sdk/tests/27/meson.build @@ -0,0 +1,2 @@ +project('apple-sdk_27-test', 'objc') +executable('apple-sdk_27-test', 'apple-sdk_27-test.m', install : true) diff --git a/pkgs/by-name/ap/apple-sdk/tests/default.nix b/pkgs/by-name/ap/apple-sdk/tests/default.nix new file mode 100644 index 000000000000..5cb2f5cf7c99 --- /dev/null +++ b/pkgs/by-name/ap/apple-sdk/tests/default.nix @@ -0,0 +1,61 @@ +{ + lib, + stdenv, + ninja, + meson, + apple-sdk_15, + apple-sdk_26, + apple-sdk_27, +}: +{ + apple-sdk_15 = stdenv.mkDerivation { + name = "apple-sdk_15-test"; + + src = ./15; + + nativeBuildInputs = [ + meson + ninja + ]; + + buildInputs = [ + apple-sdk_15 + ]; + + meta.mainProgram = "apple-sdk_15-test"; + }; + + apple-sdk_26 = stdenv.mkDerivation { + name = "apple-sdk_26-test"; + + src = ./26; + + nativeBuildInputs = [ + meson + ninja + ]; + + buildInputs = [ + apple-sdk_26 + ]; + + meta.mainProgram = "apple-sdk_26-test"; + }; + + apple-sdk_27 = stdenv.mkDerivation { + name = "apple-sdk_27-test"; + + src = ./27; + + nativeBuildInputs = [ + meson + ninja + ]; + + buildInputs = [ + apple-sdk_27 + ]; + + meta.mainProgram = "apple-sdk_27-test"; + }; +} From 913b78ec5caf32ddd6ddee30f12bdbb5c8656a84 Mon Sep 17 00:00:00 2001 From: Gaetan Lepage Date: Fri, 18 Sep 2026 08:11:40 +0000 Subject: [PATCH 296/423] protobuf: 36.1 -> 36.2 Diff: https://github.com/protocolbuffers/protobuf/compare/v36.1...v36.2 Changelog: https://github.com/protocolbuffers/protobuf/releases/tag/v36.2 --- pkgs/development/libraries/protobuf/36.nix | 4 ++-- pkgs/development/python-modules/protobuf/7.nix | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/development/libraries/protobuf/36.nix b/pkgs/development/libraries/protobuf/36.nix index 0be0c9a8404e..0648e9656537 100644 --- a/pkgs/development/libraries/protobuf/36.nix +++ b/pkgs/development/libraries/protobuf/36.nix @@ -2,8 +2,8 @@ callPackage ./generic.nix ( { - version = "36.1"; - hash = "sha256-SB17YwMdkCp4jPcX5Csf13IUGVNLaqwH5YJXugAeqMY="; + version = "36.2"; + hash = "sha256-sY9Pmy6KMJ5k/GdQSAF7vsviLJYPaArMKJ3deb++0wM="; } // args ) diff --git a/pkgs/development/python-modules/protobuf/7.nix b/pkgs/development/python-modules/protobuf/7.nix index 7ba3647f3087..fd0a3a0d8796 100644 --- a/pkgs/development/python-modules/protobuf/7.nix +++ b/pkgs/development/python-modules/protobuf/7.nix @@ -9,13 +9,13 @@ buildPythonPackage (finalAttrs: { pname = "protobuf"; - version = "7.36.1"; + version = "7.36.2"; pyproject = true; __structuredAttrs = true; src = fetchPypi { inherit (finalAttrs) pname version; - hash = "sha256-0PZHDwziuE4/6uotS4FjeLN7pNSqCKJ0MFNz3pPi1SQ="; + hash = "sha256-SX0EY/8zFmgdpsC56NBstGXWGrzgC2E6tCImF1ZE0bs="; }; build-system = [ setuptools ]; From a244bf2117b993b1de7aca00277e43e147beef49 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Fri, 18 Sep 2026 13:21:15 +0200 Subject: [PATCH 297/423] gtk-doc: patch interpreter line for gtkdocize --- pkgs/by-name/gt/gtk-doc/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/gt/gtk-doc/package.nix b/pkgs/by-name/gt/gtk-doc/package.nix index 475149609a7b..67f54759ee1a 100644 --- a/pkgs/by-name/gt/gtk-doc/package.nix +++ b/pkgs/by-name/gt/gtk-doc/package.nix @@ -5,6 +5,7 @@ ninja, pkg-config, python3, + bashNonInteractive, docbook_xml_dtd_43, docbook-xsl-nons, libxslt, @@ -51,6 +52,7 @@ python3.pkgs.buildPythonApplication (finalAttrs: { ]; buildInputs = [ + bashNonInteractive docbook_xml_dtd_43 docbook-xsl-nons libxslt From 26c3ff7b213a477c483a890db8c46b841f5da690 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Fri, 18 Sep 2026 13:21:27 +0200 Subject: [PATCH 298/423] gtk-doc: modernize Explicit strictDeps is not needed, this is set by buildPythonApplication. --- pkgs/by-name/gt/gtk-doc/package.nix | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/gt/gtk-doc/package.nix b/pkgs/by-name/gt/gtk-doc/package.nix index 67f54759ee1a..97117f61992b 100644 --- a/pkgs/by-name/gt/gtk-doc/package.nix +++ b/pkgs/by-name/gt/gtk-doc/package.nix @@ -33,11 +33,9 @@ python3.pkgs.buildPythonApplication (finalAttrs: { postPatch = '' substituteInPlace meson.build \ - --replace "pkg-config" "$PKG_CONFIG" + --replace-fail "pkg-config" "$PKG_CONFIG" ''; - strictDeps = true; - depsBuildBuild = [ python3 pkg-config @@ -77,7 +75,7 @@ python3.pkgs.buildPythonApplication (finalAttrs: { postFixup = '' # Do not propagate Python substituteInPlace $out/nix-support/propagated-build-inputs \ - --replace "${python3}" "" + --replace-fail "${python3}" "" ''; passthru = { From 060acb0434ca6ab8164d0a97dd11c00d72b241f3 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Fri, 18 Sep 2026 11:07:50 +0200 Subject: [PATCH 299/423] tclModules.expect: fix unpatched bash scripts --- pkgs/development/tcl-modules/by-name/ex/expect/package.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkgs/development/tcl-modules/by-name/ex/expect/package.nix b/pkgs/development/tcl-modules/by-name/ex/expect/package.nix index 14526ebc3c1d..02dd152878c2 100644 --- a/pkgs/development/tcl-modules/by-name/ex/expect/package.nix +++ b/pkgs/development/tcl-modules/by-name/ex/expect/package.nix @@ -6,6 +6,7 @@ tcl, makeWrapper, autoreconfHook, + bashNonInteractive, replaceVars, dejagnu, }: @@ -38,6 +39,10 @@ tcl.mkTclDerivation (finalAttrs: { makeWrapper ]; + buildInputs = [ + bashNonInteractive + ]; + postInstall = '' tclWrapperArgs+=(--prefix PATH : ${lib.makeBinPath [ tcl ]}) ${lib.optionalString stdenv.hostPlatform.isDarwin "tclWrapperArgs+=(--prefix DYLD_LIBRARY_PATH : $out/lib/expect${finalAttrs.version})"} From 8291cd3378f5a510dd82a5dd9cbfca5a3892a607 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Fri, 18 Sep 2026 11:07:56 +0200 Subject: [PATCH 300/423] tclModules.expect_5: fix unpatched bash scripts --- pkgs/development/tcl-modules/by-name/ex/expect_5/package.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkgs/development/tcl-modules/by-name/ex/expect_5/package.nix b/pkgs/development/tcl-modules/by-name/ex/expect_5/package.nix index 2cda3a33300c..6c0a44a5fae9 100644 --- a/pkgs/development/tcl-modules/by-name/ex/expect_5/package.nix +++ b/pkgs/development/tcl-modules/by-name/ex/expect_5/package.nix @@ -6,6 +6,7 @@ tcl, makeWrapper, autoreconfHook, + bashNonInteractive, fetchpatch, replaceVars, }: @@ -49,6 +50,10 @@ tcl.mkTclDerivation rec { makeWrapper ]; + buildInputs = [ + bashNonInteractive + ]; + strictDeps = true; env = { From 72bbb59dc983e9c682a121662089cb71bea13c64 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Fri, 18 Sep 2026 14:42:47 +0200 Subject: [PATCH 301/423] tclPackages.expect_5: modernize We don't need explicit strictDeps, mkTclDerivation takes care of that. --- .../tcl-modules/by-name/ex/expect_5/package.nix | 10 ++++------ 1 file changed, 4 insertions(+), 6 deletions(-) diff --git a/pkgs/development/tcl-modules/by-name/ex/expect_5/package.nix b/pkgs/development/tcl-modules/by-name/ex/expect_5/package.nix index 6c0a44a5fae9..14c2d259a0b2 100644 --- a/pkgs/development/tcl-modules/by-name/ex/expect_5/package.nix +++ b/pkgs/development/tcl-modules/by-name/ex/expect_5/package.nix @@ -11,12 +11,12 @@ replaceVars, }: -tcl.mkTclDerivation rec { +tcl.mkTclDerivation (finalAttrs: { pname = "expect"; version = "5.45.4"; src = fetchurl { - url = "mirror://sourceforge/expect/Expect/${version}/expect${version}.tar.gz"; + url = "mirror://sourceforge/expect/Expect/${finalAttrs.version}/expect${finalAttrs.version}.tar.gz"; hash = "sha256-Safag7C92fRtBKBN7sGcd2e7mjI+QMR4H4nK92C5LDQ="; }; @@ -54,8 +54,6 @@ tcl.mkTclDerivation rec { bashNonInteractive ]; - strictDeps = true; - env = { NIX_CFLAGS_COMPILE = toString ( # Needed to avoid errors when building with GCC 15. @@ -69,7 +67,7 @@ tcl.mkTclDerivation rec { postInstall = '' tclWrapperArgs+=(--prefix PATH : ${lib.makeBinPath [ tcl ]}) - ${lib.optionalString stdenv.hostPlatform.isDarwin "tclWrapperArgs+=(--prefix DYLD_LIBRARY_PATH : $out/lib/expect${version})"} + ${lib.optionalString stdenv.hostPlatform.isDarwin "tclWrapperArgs+=(--prefix DYLD_LIBRARY_PATH : $out/lib/expect${finalAttrs.version})"} ''; tclRequiresCheck = [ "Expect" ]; @@ -88,4 +86,4 @@ tcl.mkTclDerivation rec { maintainers = with lib.maintainers; [ fgaz ]; broken = tcl.isTcl9; }; -} +}) From 55b4fee88a78a85d7168e4766049b0149f708f67 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Mon, 24 Aug 2026 01:15:40 +0200 Subject: [PATCH 302/423] minimal-bootstrap: glibc 2.42 -> 2.44 --- pkgs/os-specific/linux/minimal-bootstrap/glibc/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/minimal-bootstrap/glibc/default.nix b/pkgs/os-specific/linux/minimal-bootstrap/glibc/default.nix index f156f862ecc0..cf71f17513f1 100644 --- a/pkgs/os-specific/linux/minimal-bootstrap/glibc/default.nix +++ b/pkgs/os-specific/linux/minimal-bootstrap/glibc/default.nix @@ -20,11 +20,11 @@ }: let pname = "glibc"; - version = "2.42"; + version = "2.44"; src = fetchurl { url = "mirror://gnu/libc/glibc-${version}.tar.xz"; - hash = "sha256-0XdeMuRijmTvkw9DW2e7Y691may2viszW58Z8WUJ8X8="; + hash = "sha256-N/YA8r7zxegwAUcFlWiyouQKetbMxlzpQlVtSUKcxmc="; }; linkerFile = From eaed4506c4606187e46c8779897a8c6fd9b10d14 Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Fri, 18 Sep 2026 18:54:10 +0200 Subject: [PATCH 303/423] nodejs: use shared simdutf only on versions that do not force-use the vendored one --- pkgs/development/web/nodejs/nodejs.nix | 29 ++++++-------------------- 1 file changed, 6 insertions(+), 23 deletions(-) diff --git a/pkgs/development/web/nodejs/nodejs.nix b/pkgs/development/web/nodejs/nodejs.nix index a4db0dbca592..c604603382dd 100644 --- a/pkgs/development/web/nodejs/nodejs.nix +++ b/pkgs/development/web/nodejs/nodejs.nix @@ -24,26 +24,6 @@ openssl, simdjson, simdutf, - simdutf_6 ? ( - simdutf.overrideAttrs ( - { - version = "6.5.0"; - - src = fetchFromGitHub { - owner = "simdutf"; - repo = "simdutf"; - rev = "v6.5.0"; - hash = "sha256-bZ4r62GMz2Dkd3fKTJhelitaA8jUBaDjG6jOysEg8Nk="; - }; - } - // (lib.optionalAttrs stdenv.buildPlatform.isDarwin { - # Fix build on darwin - postPatch = '' - substituteInPlace tools/CMakeLists.txt --replace-fail '-Wl,--gc-sections' "" - ''; - }) - ) - ), sqlite, temporal_capi, uvwasi, @@ -140,7 +120,8 @@ let # TODO: also handle MIPS flags (mips_arch, mips_fpu, mips_float_abi). useSharedAbseilAndHighway = lib.versionAtLeast version "26.9"; - useSharedAdaAndSimd = lib.versionAtLeast version "22.2"; + useSharedAdaAndSimdjson = lib.versionAtLeast version "22.2"; + useSharedSimdutf = lib.versionAtLeast version "26.10"; useSharedFFI = lib.versionAtLeast version "26.1"; useSharedGtestAndHistogram = lib.versionAtLeast version ( if majorVersion == "24" then "24.14.0" else "25.4" @@ -170,12 +151,14 @@ let abseil = abseil-cpp; highway = libhwy; }) - // (lib.optionalAttrs useSharedAdaAndSimd { + // (lib.optionalAttrs useSharedAdaAndSimdjson { inherit ada simdjson ; - simdutf = if lib.versionAtLeast version "25" then simdutf else simdutf_6; + }) + // (lib.optionalAttrs useSharedSimdutf { + inherit simdutf; }) // (lib.optionalAttrs useSharedSQLite { inherit sqlite; From 81c20cfd8c45a52e66f4782c326634c1517ccfbb Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Sat, 19 Sep 2026 00:01:15 +0200 Subject: [PATCH 304/423] rustc: fix unpatched shebangs --- pkgs/development/compilers/rust/rustc.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/development/compilers/rust/rustc.nix b/pkgs/development/compilers/rust/rustc.nix index ba1166e2dd60..a2cfbe1b4a9f 100644 --- a/pkgs/development/compilers/rust/rustc.nix +++ b/pkgs/development/compilers/rust/rustc.nix @@ -20,6 +20,7 @@ rustc, rustfmt, pkg-config, + bashNonInteractive, openssl, xz, zlib, @@ -402,6 +403,7 @@ stdenv.mkDerivation (finalAttrs: { ]; buildInputs = [ + bashNonInteractive openssl rust-jemalloc-sys ] From b8fa6d27a505ba601ea671f97ecc5c4fcb75f6f8 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 19 Sep 2026 03:52:35 +0000 Subject: [PATCH 305/423] pahole: 1.31 -> 1.32 --- pkgs/by-name/pa/pahole/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/pa/pahole/package.nix b/pkgs/by-name/pa/pahole/package.nix index ad58df1572a6..27a388203532 100644 --- a/pkgs/by-name/pa/pahole/package.nix +++ b/pkgs/by-name/pa/pahole/package.nix @@ -14,10 +14,10 @@ stdenv.mkDerivation (finalAttrs: { pname = "pahole"; - version = "1.31"; + version = "1.32"; src = fetchzip { url = "https://git.kernel.org/pub/scm/devel/pahole/pahole.git/snapshot/pahole-${finalAttrs.version}.tar.gz"; - hash = "sha256-Afy0SysuDbTOa8H3m4hexy12Rmuv2NZL2wHfO4JtKL0="; + hash = "sha256-+vydbVzkM+VUROo3Zo+XJeJMkvwtwEIS/4GgxmqvAZE="; }; nativeBuildInputs = [ From 102ab2b7932aa494ccacd0e7be28741641f8486d Mon Sep 17 00:00:00 2001 From: Xesxen Date: Sat, 19 Sep 2026 00:05:29 +0200 Subject: [PATCH 306/423] unbound: 1.26.0 -> 1.26.1 --- pkgs/by-name/un/unbound/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/un/unbound/package.nix b/pkgs/by-name/un/unbound/package.nix index 842382c59adc..35add0725258 100644 --- a/pkgs/by-name/un/unbound/package.nix +++ b/pkgs/by-name/un/unbound/package.nix @@ -64,13 +64,13 @@ assert lib.assertMsg ( ) "unbound: withDoQ requires OpenSSL with QUIC support (OpenSSL >= 3.5)"; stdenv.mkDerivation (finalAttrs: { pname = "unbound"; - version = "1.26.0"; + version = "1.26.1"; src = fetchFromGitHub { owner = "NLnetLabs"; repo = "unbound"; tag = "release-${finalAttrs.version}"; - hash = "sha256-ESRboc5vwsNZ/Yynl2JGRWhH1QEYZumoTzgSvN3NbSU="; + hash = "sha256-gf4vASdB6XzSGhJ2GKbUhgs0wpR32Du2ARx4bBQ+vJA="; }; outputs = [ From 9149e326c565f95aa2cc0ddc027064ae11dd9830 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Sat, 19 Sep 2026 16:43:13 +0200 Subject: [PATCH 307/423] minimal-bootstrap.glibc-headers: 2.42 -> 2.44 --- pkgs/os-specific/linux/minimal-bootstrap/glibc/headers.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/minimal-bootstrap/glibc/headers.nix b/pkgs/os-specific/linux/minimal-bootstrap/glibc/headers.nix index 2a4676231f2f..b636629bff8d 100644 --- a/pkgs/os-specific/linux/minimal-bootstrap/glibc/headers.nix +++ b/pkgs/os-specific/linux/minimal-bootstrap/glibc/headers.nix @@ -21,11 +21,11 @@ }: let pname = "glibc-headers"; - version = "2.42"; + version = "2.44"; src = fetchurl { url = "mirror://gnu/libc/glibc-${version}.tar.xz"; - hash = "sha256-0XdeMuRijmTvkw9DW2e7Y691may2viszW58Z8WUJ8X8="; + hash = "sha256-N/YA8r7zxegwAUcFlWiyouQKetbMxlzpQlVtSUKcxmc="; }; in bash.runCommand "${pname}-${version}" From 03290f63705e155c994e8e6dadcf501f59b0e343 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Mon, 24 Aug 2026 01:18:58 +0200 Subject: [PATCH 308/423] grub2: fix build w/ glibc-2.44 Co-authored-by: Philip Taron --- pkgs/by-name/gr/grub2/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/gr/grub2/package.nix b/pkgs/by-name/gr/grub2/package.nix index 392a6ed6e794..6ab78b82c4eb 100644 --- a/pkgs/by-name/gr/grub2/package.nix +++ b/pkgs/by-name/gr/grub2/package.nix @@ -223,6 +223,9 @@ stdenv.mkDerivation rec { strictDeps = true; + # glibc 2.43 C23 const-preserving strchr/strstr macros + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + hardeningDisable = [ "all" ]; separateDebugInfo = !xenSupport; From 00b73f98545dd811cffb259767de46b09478339c Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Mon, 24 Aug 2026 01:19:36 +0200 Subject: [PATCH 309/423] dtc: fix build w/ glibc-2.44 Co-authored-by: Philip Taron --- pkgs/by-name/dt/dtc/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/dt/dtc/package.nix b/pkgs/by-name/dt/dtc/package.nix index 17fe8f5653e3..a65192ee8daa 100644 --- a/pkgs/by-name/dt/dtc/package.nix +++ b/pkgs/by-name/dt/dtc/package.nix @@ -74,6 +74,8 @@ stdenv.mkDerivation (finalAttrs: { # Required for installation of Python library and is innocuous otherwise. env.DESTDIR = "/"; + # glibc 2.43 C23 const-preserving strchr/strstr macros + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; mesonAutoFeatures = "auto"; mesonFlags = [ From db8336f9f1335fef75c570f1408655d1511941ef Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Mon, 24 Aug 2026 01:19:55 +0200 Subject: [PATCH 310/423] librist: fix build w/ glibc-2.44 Co-authored-by: Philip Taron --- pkgs/by-name/li/librist/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/li/librist/package.nix b/pkgs/by-name/li/librist/package.nix index 606b5f6a5acb..21d163f974d5 100644 --- a/pkgs/by-name/li/librist/package.nix +++ b/pkgs/by-name/li/librist/package.nix @@ -34,6 +34,9 @@ stdenv.mkDerivation (finalAttrs: { pkg-config ]; + # glibc 2.43 C23 const-preserving strchr/strstr macros + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + buildInputs = [ cjson cmocka From 1a0a983791e26f2ee69a42373f88ca65fb7417f8 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Mon, 24 Aug 2026 01:20:13 +0200 Subject: [PATCH 311/423] krb5: fix build w/ glibc-2.44 Co-authored-by: Philip Taron --- pkgs/by-name/kr/krb5/package.nix | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/kr/krb5/package.nix b/pkgs/by-name/kr/krb5/package.nix index 4e97e9867190..9b5b2cc2d628 100644 --- a/pkgs/by-name/kr/krb5/package.nix +++ b/pkgs/by-name/kr/krb5/package.nix @@ -75,7 +75,9 @@ stdenv.mkDerivation (finalAttrs: { # void foo(); # # declaration. - NIX_CFLAGS_COMPILE = "-std=gnu17" + lib.optionalString stdenv.hostPlatform.isStatic " -fcommon"; + NIX_CFLAGS_COMPILE = + "-std=gnu17 -Wno-error=discarded-qualifiers" + + lib.optionalString stdenv.hostPlatform.isStatic " -fcommon"; }; configureFlags = [ From efa476934e14f8ad69fce1f76e61a5c790d7ce88 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Mon, 24 Aug 2026 01:20:25 +0200 Subject: [PATCH 312/423] kvmtool: fix build w/ glibc-2.44 --- pkgs/by-name/kv/kvmtool/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/kv/kvmtool/package.nix b/pkgs/by-name/kv/kvmtool/package.nix index adfbd884d0e0..f89324a5909d 100644 --- a/pkgs/by-name/kv/kvmtool/package.nix +++ b/pkgs/by-name/kv/kvmtool/package.nix @@ -19,6 +19,9 @@ stdenv.mkDerivation { buildInputs = lib.optionals stdenv.hostPlatform.isAarch64 [ dtc ]; + # glibc 2.43 C23 const-preserving strchr/strstr macros + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + enableParallelBuilding = true; makeFlags = [ From abc74b463f2ac4bd0e1870c2c5b368a228437be6 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Mon, 24 Aug 2026 01:22:03 +0200 Subject: [PATCH 313/423] efivar: fix build w/ glibc-2.44 --- pkgs/by-name/ef/efivar/package.nix | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/pkgs/by-name/ef/efivar/package.nix b/pkgs/by-name/ef/efivar/package.nix index bdc7a06b9503..12ebaf4a7500 100644 --- a/pkgs/by-name/ef/efivar/package.nix +++ b/pkgs/by-name/ef/efivar/package.nix @@ -6,6 +6,7 @@ pkg-config, popt, mandoc, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -33,6 +34,14 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ popt ]; depsBuildBuild = [ buildPackages.stdenv.cc ]; + patches = [ + # fix build with glibc-2.44 + (fetchpatch { + url = "https://github.com/rhboot/efivar/commit/f521cd7f584c95d8308659ab9d89d750e2bd76da.patch"; + hash = "sha256-I19UIS0tNTsEipuoMQPlTEwih1RrYPz9Q4Wy98u1z0Q="; + }) + ]; + makeFlags = [ "prefix=$(out)" "libdir=$(out)/lib" From 53c393eb115c6f5db389bf033ee134b92c17e288 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Mon, 24 Aug 2026 01:22:59 +0200 Subject: [PATCH 314/423] ldb: fix build w/ glibc-2.44 Co-authored-by: Philip Taron --- pkgs/by-name/ld/ldb/package.nix | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/pkgs/by-name/ld/ldb/package.nix b/pkgs/by-name/ld/ldb/package.nix index 04d9e7d645bd..45e3f142befb 100644 --- a/pkgs/by-name/ld/ldb/package.nix +++ b/pkgs/by-name/ld/ldb/package.nix @@ -17,6 +17,7 @@ buildPackages, libxcrypt, testers, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -33,6 +34,16 @@ stdenv.mkDerivation (finalAttrs: { "dev" ]; + patches = [ + # Fix rep_memset_s calling C23 memset_explicit with wrong arg count (4 instead of 3). + # Upstream samba commit 04e0fb9b2d; later reworked more broadly in ef08be24e9 and 3e81b73a05 + # which replace memset_s with memset_explicit entirely, but those don't apply to ldb 2.9.2. + (fetchpatch { + url = "https://gitlab.com/samba-team/samba/-/commit/04e0fb9b2d1d87516f1331096c78e8355b4fa9f3.patch"; + hash = "sha256-sBqtVwGBXseCAMlv3QaiSYQmOw7H4cAJwc0Ey5yD6Os="; + }) + ]; + nativeBuildInputs = [ pkg-config python3 From 9c912cb79757cc1a0f0723589e36e68780596056 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Mon, 24 Aug 2026 01:23:25 +0200 Subject: [PATCH 315/423] sane-backends: fix build w/ glibc-2.44 Co-authored-by: Philip Taron --- pkgs/applications/graphics/sane/backends/default.nix | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/pkgs/applications/graphics/sane/backends/default.nix b/pkgs/applications/graphics/sane/backends/default.nix index 02dd36e23d7e..05f67e51cd2a 100644 --- a/pkgs/applications/graphics/sane/backends/default.nix +++ b/pkgs/applications/graphics/sane/backends/default.nix @@ -66,6 +66,16 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-9KKTr7p1vCgvGr6hFY83K5gbL7Ilm4Uzc86JIxv+ahI="; revert = true; }) + + # Fix gphoto2 backend build with glibc 2.43 C23 const-preserving strchr + (fetchpatch { + url = "https://gitlab.com/sane-project/backends/-/commit/d04d17b456d9847021b6df6eb08a3419a75172cf.patch"; + hash = "sha256-4iAzwA+uh8W+xSpUkZgvShQ71kq/OVJ26pKsD1NwiXs="; + }) + (fetchpatch { + url = "https://gitlab.com/sane-project/backends/-/commit/ebd4d82bd7a6b8c57870dbfb492e4c186cf584d8.patch"; + hash = "sha256-vHtv+OMA0f9JR1ReshTg8IOgcZf7cnV7chitRBBCAg4="; + }) ]; postPatch = '' From 31bb833ca2b358a8d557e1a8cfae13f2214e4b60 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Mon, 24 Aug 2026 01:24:00 +0200 Subject: [PATCH 316/423] python3Packages.mypy: fix build w/ glibc-2.44 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Otherwiwse a bunch of tests break with "warning: ‘_POSIX_C_SOURCE’ redefined". Apparently this now happens, if software doesn't adhere to the rule of `Python.h` having to be included first[1]. The applied patch focuses on Python 3.15 support, but also happens to fix that. [1] https://bugzilla.redhat.com/show_bug.cgi?id=2416110 --- pkgs/development/python-modules/mypy/default.nix | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/pkgs/development/python-modules/mypy/default.nix b/pkgs/development/python-modules/mypy/default.nix index 68587c7c345f..a50eb9c32761 100644 --- a/pkgs/development/python-modules/mypy/default.nix +++ b/pkgs/development/python-modules/mypy/default.nix @@ -6,6 +6,7 @@ gitUpdater, pythonAtLeast, isPyPy, + fetchpatch, # build-system pathspec, @@ -49,6 +50,15 @@ buildPythonPackage rec { hash = "sha256-sm/pxQGxH5XuPH7B8i3fpp30KaFU9aSp6BT67UcDPvU="; }; + patches = [ + # fix build w/ glibc-2.44 + # If Python.h isn't included first, a const redefinition error now occurs otherwise. + (fetchpatch { + url = "https://github.com/python/mypy/commit/46acbe85c0e1703ebf2e6d4c699772edcdcf4652.patch"; + hash = "sha256-KslHiKqinvvXZoxvCnZXOhCm7i8577PbSdNGudCsjZE="; + }) + ]; + passthru.updateScript = gitUpdater { rev-prefix = "v"; }; From 1e23b1be785ea5d625c65aff6de3333831a842fb Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Mon, 24 Aug 2026 01:28:45 +0200 Subject: [PATCH 317/423] glibc: 2.42-84 -> 2.44-25 Announcements: * https://inbox.sourceware.org/libc-announce/13932477.uLZWGnKmhe@pinacolada/T/#u * https://inbox.sourceware.org/libc-announce/teaVXxrfQH2qv0xBul7sXg@gentoo.org/T/#u Closes #502924 --- ...l-usage-of-BASH-or-BASH-in-installed.patch | 36 +- .../libraries/glibc/2.42-master.patch | 11174 ---------------- .../libraries/glibc/2.44-master.patch | 4138 ++++++ pkgs/development/libraries/glibc/common.nix | 14 +- .../glibc/dont-use-system-ld-so-cache.patch | 27 +- 5 files changed, 4179 insertions(+), 11210 deletions(-) delete mode 100644 pkgs/development/libraries/glibc/2.42-master.patch create mode 100644 pkgs/development/libraries/glibc/2.44-master.patch diff --git a/pkgs/development/libraries/glibc/0001-Revert-Remove-all-usage-of-BASH-or-BASH-in-installed.patch b/pkgs/development/libraries/glibc/0001-Revert-Remove-all-usage-of-BASH-or-BASH-in-installed.patch index 25cb329e086e..d1ea3ad0cdd2 100644 --- a/pkgs/development/libraries/glibc/0001-Revert-Remove-all-usage-of-BASH-or-BASH-in-installed.patch +++ b/pkgs/development/libraries/glibc/0001-Revert-Remove-all-usage-of-BASH-or-BASH-in-installed.patch @@ -1,4 +1,4 @@ -From c1c36f73aa3085a856c7cf36d69c21d18d3ef5ac Mon Sep 17 00:00:00 2001 +From 0ea28d2f38500559734cb0fe99eae40c04783730 Mon Sep 17 00:00:00 2001 From: Bernardo Meurer Date: Fri, 22 Jul 2022 22:11:07 -0700 Subject: [PATCH] Revert "Remove all usage of @BASH@ or ${BASH} in installed @@ -22,10 +22,10 @@ Co-authored-by: Maximilian Bosch 8 files changed, 15 insertions(+), 10 deletions(-) diff --git a/debug/Makefile b/debug/Makefile -index 6a05205ce6..dd63b16ae8 100644 +index c6c1069b40..ccecf6b70b 100644 --- a/debug/Makefile +++ b/debug/Makefile -@@ -345,8 +345,9 @@ $(objpfx)pcprofiledump: $(objpfx)pcprofiledump.o +@@ -407,8 +407,9 @@ $(objpfx)pcprofiledump: $(objpfx)pcprofiledump.o $(objpfx)xtrace: xtrace.sh rm -f $@.new @@ -38,17 +38,17 @@ index 6a05205ce6..dd63b16ae8 100644 && rm -f $@ && mv $@.new $@ && chmod +x $@ diff --git a/debug/xtrace.sh b/debug/xtrace.sh -index 00bafd33db..d0f9fca9a9 100755 +index a1bb50eeaf..01383c7c79 100755 --- a/debug/xtrace.sh +++ b/debug/xtrace.sh @@ -1,4 +1,4 @@ -#!/bin/bash +#! @BASH@ - # Copyright (C) 1999-2025 Free Software Foundation, Inc. + # Copyright (C) 1999-2026 Free Software Foundation, Inc. # This file is part of the GNU C Library. diff --git a/elf/Makefile b/elf/Makefile -index 4b1d0d8741..bbcf688c99 100644 +index d279a5135c..dc39ccea60 100644 --- a/elf/Makefile +++ b/elf/Makefile @@ -250,7 +250,8 @@ $(objpfx)sotruss-lib.so: $(common-objpfx)libc.so $(objpfx)ld.so \ @@ -61,7 +61,7 @@ index 4b1d0d8741..bbcf688c99 100644 -e 's%@TEXTDOMAINDIR@%$(localedir)%g' \ -e 's%@PREFIX@%$(prefix)%g' \ -e 's|@PKGVERSION@|$(PKGVERSION)|g' \ -@@ -1556,6 +1557,7 @@ ldd-rewrite = -e 's%@RTLD@%$(rtlddir)/$(rtld-installed-name)%g' \ +@@ -1720,6 +1721,7 @@ ldd-rewrite = -e 's%@RTLD@%$(rtlddir)/$(rtld-installed-name)%g' \ -e 's%@VERSION@%$(version)%g' \ -e 's|@PKGVERSION@|$(PKGVERSION)|g' \ -e 's|@REPORT_BUGS_TO@|$(REPORT_BUGS_TO)|g' \ @@ -70,30 +70,30 @@ index 4b1d0d8741..bbcf688c99 100644 ifeq ($(ldd-rewrite-script),no) diff --git a/elf/ldd.bash.in b/elf/ldd.bash.in -index 2d3df6e57e..0faf83dc86 100644 +index bfc40f6505..59ca54e2d9 100644 --- a/elf/ldd.bash.in +++ b/elf/ldd.bash.in @@ -1,4 +1,4 @@ -#!/bin/bash +#! @BASH@ - # Copyright (C) 1996-2025 Free Software Foundation, Inc. + # Copyright (C) 1996-2026 Free Software Foundation, Inc. # This file is part of the GNU C Library. diff --git a/elf/sotruss.sh b/elf/sotruss.sh -index 8944645df9..1c36981b22 100755 +index c90abaaed9..03cb25bc57 100755 --- a/elf/sotruss.sh +++ b/elf/sotruss.sh @@ -1,4 +1,4 @@ -#!/bin/bash +#! @BASH@ - # Copyright (C) 2011-2025 Free Software Foundation, Inc. + # Copyright (C) 2011-2026 Free Software Foundation, Inc. # This file is part of the GNU C Library. diff --git a/malloc/Makefile b/malloc/Makefile -index e2b2c1ae1b..67a399f1dd 100644 +index 72aa77af20..e148b6480a 100644 --- a/malloc/Makefile +++ b/malloc/Makefile -@@ -359,8 +359,9 @@ $(objpfx)mtrace: mtrace.pl +@@ -484,8 +484,9 @@ $(objpfx)mtrace: mtrace.pl $(objpfx)memusage: memusage.sh rm -f $@.new @@ -106,20 +106,20 @@ index e2b2c1ae1b..67a399f1dd 100644 && rm -f $@ && mv $@.new $@ && chmod +x $@ diff --git a/malloc/memusage.sh b/malloc/memusage.sh -index 8ae435d2f8..c929d16af7 100755 +index 309991a7c9..28117c4561 100755 --- a/malloc/memusage.sh +++ b/malloc/memusage.sh @@ -1,4 +1,4 @@ -#!/bin/bash +#! @BASH@ - # Copyright (C) 1999-2025 Free Software Foundation, Inc. + # Copyright (C) 1999-2026 Free Software Foundation, Inc. # This file is part of the GNU C Library. diff --git a/timezone/Makefile b/timezone/Makefile -index ebe5cf73a1..e9cf92861c 100644 +index ce9abe6cb2..3ee1eed54a 100644 --- a/timezone/Makefile +++ b/timezone/Makefile -@@ -139,7 +139,8 @@ $(testdata)/XT5: testdata/gen-XT5.sh +@@ -136,7 +136,8 @@ $(testdata)/XT5: testdata/gen-XT5.sh mv $@.tmp $@ $(objpfx)tzselect: tzselect.ksh $(common-objpfx)config.make @@ -130,5 +130,5 @@ index ebe5cf73a1..e9cf92861c 100644 -e '/PKGVERSION=/s|=.*|="$(PKGVERSION)"|' \ -e '/REPORT_BUGS_TO=/s|=.*|="$(REPORT_BUGS_TO)"|' \ -- -2.47.2 +2.54.0 diff --git a/pkgs/development/libraries/glibc/2.42-master.patch b/pkgs/development/libraries/glibc/2.42-master.patch deleted file mode 100644 index 8abd567ee32b..000000000000 --- a/pkgs/development/libraries/glibc/2.42-master.patch +++ /dev/null @@ -1,11174 +0,0 @@ -commit bdea6c37197a3c9bd976911cce5f580dea1c28dd -Author: Andreas K. Hüttel -Date: Mon Jul 28 20:35:38 2025 +0200 - - Replace advisories directory with pointer file - - Signed-off-by: Andreas K. Hüttel - -diff --git a/advisories/GLIBC-SA-2023-0001 b/advisories/GLIBC-SA-2023-0001 -deleted file mode 100644 -index 3d19c91b6a..0000000000 ---- a/advisories/GLIBC-SA-2023-0001 -+++ /dev/null -@@ -1,14 +0,0 @@ --printf: incorrect output for integers with thousands separator and width field -- --When the printf family of functions is called with a format specifier --that uses an (enable grouping) and a minimum width --specifier, the resulting output could be larger than reasonably expected --by a caller that computed a tight bound on the buffer size. The --resulting larger than expected output could result in a buffer overflow --in the printf family of functions. -- --CVE-Id: CVE-2023-25139 --Public-Date: 2023-02-02 --Vulnerable-Commit: e88b9f0e5cc50cab57a299dc7efe1a4eb385161d (2.37) --Fix-Commit: c980549cc6a1c03c23cc2fe3e7b0fe626a0364b0 (2.38) --Fix-Commit: 07b9521fc6369d000216b96562ff7c0ed32a16c4 (2.37-4) -diff --git a/advisories/GLIBC-SA-2023-0002 b/advisories/GLIBC-SA-2023-0002 -deleted file mode 100644 -index 5122669a64..0000000000 ---- a/advisories/GLIBC-SA-2023-0002 -+++ /dev/null -@@ -1,15 +0,0 @@ --getaddrinfo: Stack read overflow in no-aaaa mode -- --If the system is configured in no-aaaa mode via /etc/resolv.conf, --getaddrinfo is called for the AF_UNSPEC address family, and a DNS --response is received over TCP that is larger than 2048 bytes, --getaddrinfo may potentially disclose stack contents via the returned --address data, or crash. -- --CVE-Id: CVE-2023-4527 --Public-Date: 2023-09-12 --Vulnerable-Commit: f282cdbe7f436c75864e5640a409a10485e9abb2 (2.36) --Fix-Commit: bd77dd7e73e3530203be1c52c8a29d08270cb25d (2.39) --Fix-Commit: 4ea972b7edd7e36610e8cde18bf7a8149d7bac4f (2.36-113) --Fix-Commit: b7529346025a130fee483d42178b5c118da971bb (2.37-38) --Fix-Commit: b25508dd774b617f99419bdc3cf2ace4560cd2d6 (2.38-19) -diff --git a/advisories/GLIBC-SA-2023-0003 b/advisories/GLIBC-SA-2023-0003 -deleted file mode 100644 -index d3aef80348..0000000000 ---- a/advisories/GLIBC-SA-2023-0003 -+++ /dev/null -@@ -1,15 +0,0 @@ --getaddrinfo: Potential use-after-free -- --When an NSS plugin only implements the _gethostbyname2_r and --_getcanonname_r callbacks, getaddrinfo could use memory that was freed --during buffer resizing, potentially causing a crash or read or write to --arbitrary memory. -- --CVE-Id: CVE-2023-4806 --Public-Date: 2023-09-12 --Fix-Commit: 973fe93a5675c42798b2161c6f29c01b0e243994 (2.39) --Fix-Commit: e09ee267c03e3150c2c9ba28625ab130705a485e (2.34-420) --Fix-Commit: e3ccb230a961b4797510e6a1f5f21fd9021853e7 (2.35-270) --Fix-Commit: a9728f798ec7f05454c95637ee6581afaa9b487d (2.36-115) --Fix-Commit: 6529a7466c935f36e9006b854d6f4e1d4876f942 (2.37-39) --Fix-Commit: 00ae4f10b504bc4564e9f22f00907093f1ab9338 (2.38-20) -diff --git a/advisories/GLIBC-SA-2023-0004 b/advisories/GLIBC-SA-2023-0004 -deleted file mode 100644 -index 5286a7aa54..0000000000 ---- a/advisories/GLIBC-SA-2023-0004 -+++ /dev/null -@@ -1,16 +0,0 @@ --tunables: local privilege escalation through buffer overflow -- --If a tunable of the form NAME=NAME=VAL is passed in the environment of a --setuid program and NAME is valid, it may result in a buffer overflow, --which could be exploited to achieve escalated privileges. This flaw was --introduced in glibc 2.34. -- --CVE-Id: CVE-2023-4911 --Public-Date: 2023-10-03 --Vulnerable-Commit: 2ed18c5b534d9e92fc006202a5af0df6b72e7aca (2.34) --Fix-Commit: 1056e5b4c3f2d90ed2b4a55f96add28da2f4c8fa (2.39) --Fix-Commit: dcc367f148bc92e7f3778a125f7a416b093964d9 (2.34-423) --Fix-Commit: c84018a05aec80f5ee6f682db0da1130b0196aef (2.35-274) --Fix-Commit: 22955ad85186ee05834e47e665056148ca07699c (2.36-118) --Fix-Commit: b4e23c75aea756b4bddc4abcf27a1c6dca8b6bd3 (2.37-45) --Fix-Commit: 750a45a783906a19591fb8ff6b7841470f1f5701 (2.38-27) -diff --git a/advisories/GLIBC-SA-2023-0005 b/advisories/GLIBC-SA-2023-0005 -deleted file mode 100644 -index cc4eb90b82..0000000000 ---- a/advisories/GLIBC-SA-2023-0005 -+++ /dev/null -@@ -1,18 +0,0 @@ --getaddrinfo: DoS due to memory leak -- --The fix for CVE-2023-4806 introduced a memory leak when an application --calls getaddrinfo for AF_INET6 with AI_CANONNAME, AI_ALL and AI_V4MAPPED --flags set. -- --CVE-Id: CVE-2023-5156 --Public-Date: 2023-09-25 --Vulnerable-Commit: e09ee267c03e3150c2c9ba28625ab130705a485e (2.34-420) --Vulnerable-Commit: e3ccb230a961b4797510e6a1f5f21fd9021853e7 (2.35-270) --Vulnerable-Commit: a9728f798ec7f05454c95637ee6581afaa9b487d (2.36-115) --Vulnerable-Commit: 6529a7466c935f36e9006b854d6f4e1d4876f942 (2.37-39) --Vulnerable-Commit: 00ae4f10b504bc4564e9f22f00907093f1ab9338 (2.38-20) --Fix-Commit: 8006457ab7e1cd556b919f477348a96fe88f2e49 (2.34-421) --Fix-Commit: 17092c0311f954e6f3c010f73ce3a78c24ac279a (2.35-272) --Fix-Commit: 856bac55f98dc840e7c27cfa82262b933385de90 (2.36-116) --Fix-Commit: 4473d1b87d04b25cdd0e0354814eeaa421328268 (2.37-42) --Fix-Commit: 5ee59ca371b99984232d7584fe2b1a758b4421d3 (2.38-24) -diff --git a/advisories/GLIBC-SA-2024-0001 b/advisories/GLIBC-SA-2024-0001 -deleted file mode 100644 -index 28931c75ae..0000000000 ---- a/advisories/GLIBC-SA-2024-0001 -+++ /dev/null -@@ -1,15 +0,0 @@ --syslog: Heap buffer overflow in __vsyslog_internal -- --__vsyslog_internal did not handle a case where printing a SYSLOG_HEADER --containing a long program name failed to update the required buffer --size, leading to the allocation and overflow of a too-small buffer on --the heap. -- --CVE-Id: CVE-2023-6246 --Public-Date: 2024-01-30 --Vulnerable-Commit: 52a5be0df411ef3ff45c10c7c308cb92993d15b1 (2.37) --Fix-Commit: 6bd0e4efcc78f3c0115e5ea9739a1642807450da (2.39) --Fix-Commit: 23514c72b780f3da097ecf33a793b7ba9c2070d2 (2.38-42) --Fix-Commit: 97a4292aa4a2642e251472b878d0ec4c46a0e59a (2.37-57) --Vulnerable-Commit: b0e7888d1fa2dbd2d9e1645ec8c796abf78880b9 (2.36-16) --Fix-Commit: d1a83b6767f68b3cb5b4b4ea2617254acd040c82 (2.36-126) -diff --git a/advisories/GLIBC-SA-2024-0002 b/advisories/GLIBC-SA-2024-0002 -deleted file mode 100644 -index 940bfcf2fc..0000000000 ---- a/advisories/GLIBC-SA-2024-0002 -+++ /dev/null -@@ -1,15 +0,0 @@ --syslog: Heap buffer overflow in __vsyslog_internal -- --__vsyslog_internal used the return value of snprintf/vsnprintf to --calculate buffer sizes for memory allocation. If these functions (for --any reason) failed and returned -1, the resulting buffer would be too --small to hold output. -- --CVE-Id: CVE-2023-6779 --Public-Date: 2024-01-30 --Vulnerable-Commit: 52a5be0df411ef3ff45c10c7c308cb92993d15b1 (2.37) --Fix-Commit: 7e5a0c286da33159d47d0122007aac016f3e02cd (2.39) --Fix-Commit: d0338312aace5bbfef85e03055e1212dd0e49578 (2.38-43) --Fix-Commit: 67062eccd9a65d7fda9976a56aeaaf6c25a80214 (2.37-58) --Vulnerable-Commit: b0e7888d1fa2dbd2d9e1645ec8c796abf78880b9 (2.36-16) --Fix-Commit: 2bc9d7c002bdac38b5c2a3f11b78e309d7765b83 (2.36-127) -diff --git a/advisories/GLIBC-SA-2024-0003 b/advisories/GLIBC-SA-2024-0003 -deleted file mode 100644 -index b43a5150ab..0000000000 ---- a/advisories/GLIBC-SA-2024-0003 -+++ /dev/null -@@ -1,13 +0,0 @@ --syslog: Integer overflow in __vsyslog_internal -- --__vsyslog_internal calculated a buffer size by adding two integers, but --did not first check if the addition would overflow. -- --CVE-Id: CVE-2023-6780 --Public-Date: 2024-01-30 --Vulnerable-Commit: 52a5be0df411ef3ff45c10c7c308cb92993d15b1 (2.37) --Fix-Commit: ddf542da94caf97ff43cc2875c88749880b7259b (2.39) --Fix-Commit: d37c2b20a4787463d192b32041c3406c2bd91de0 (2.38-44) --Fix-Commit: 2b58cba076e912961ceaa5fa58588e4b10f791c0 (2.37-59) --Vulnerable-Commit: b0e7888d1fa2dbd2d9e1645ec8c796abf78880b9 (2.36-16) --Fix-Commit: b9b7d6a27aa0632f334352fa400771115b3c69b7 (2.36-128) -diff --git a/advisories/GLIBC-SA-2024-0004 b/advisories/GLIBC-SA-2024-0004 -deleted file mode 100644 -index 08df2b3118..0000000000 ---- a/advisories/GLIBC-SA-2024-0004 -+++ /dev/null -@@ -1,28 +0,0 @@ --ISO-2022-CN-EXT: fix out-of-bound writes when writing escape sequence -- --The iconv() function in the GNU C Library versions 2.39 and older may --overflow the output buffer passed to it by up to 4 bytes when converting --strings to the ISO-2022-CN-EXT character set, which may be used to --crash an application or overwrite a neighbouring variable. -- --ISO-2022-CN-EXT uses escape sequences to indicate character set changes --(as specified by RFC 1922). While the SOdesignation has the expected --bounds checks, neither SS2designation nor SS3designation have its; --allowing a write overflow of 1, 2, or 3 bytes with fixed values: --'$+I', '$+J', '$+K', '$+L', '$+M', or '$*H'. -- --CVE-Id: CVE-2024-2961 --Public-Date: 2024-04-17 --Vulnerable-Commit: 755104edc75c53f4a0e7440334e944ad3c6b32fc (2.1.93-169) --Fix-Commit: f9dc609e06b1136bb0408be9605ce7973a767ada (2.40) --Fix-Commit: 31da30f23cddd36db29d5b6a1c7619361b271fb4 (2.39-31) --Fix-Commit: e1135387deded5d73924f6ca20c72a35dc8e1bda (2.38-66) --Fix-Commit: 89ce64b269a897a7780e4c73a7412016381c6ecf (2.37-89) --Fix-Commit: 4ed98540a7fd19f458287e783ae59c41e64df7b5 (2.36-164) --Fix-Commit: 36280d1ce5e245aabefb877fe4d3c6cff95dabfa (2.35-315) --Fix-Commit: a8b0561db4b9847ebfbfec20075697d5492a363c (2.34-459) --Fix-Commit: ed4f16ff6bed3037266f1fa682ebd32a18fce29c (2.33-263) --Fix-Commit: 682ad4c8623e611a971839990ceef00346289cc9 (2.32-140) --Fix-Commit: 3703c32a8d304c1ee12126134ce69be965f38000 (2.31-154) -- --Reported-By: Charles Fol -diff --git a/advisories/GLIBC-SA-2024-0005 b/advisories/GLIBC-SA-2024-0005 -deleted file mode 100644 -index a59596610a..0000000000 ---- a/advisories/GLIBC-SA-2024-0005 -+++ /dev/null -@@ -1,22 +0,0 @@ --nscd: Stack-based buffer overflow in netgroup cache -- --If the Name Service Cache Daemon's (nscd) fixed size cache is exhausted --by client requests then a subsequent client request for netgroup data --may result in a stack-based buffer overflow. This flaw was introduced --in glibc 2.15 when the cache was added to nscd. -- --This vulnerability is only present in the nscd binary. -- --CVE-Id: CVE-2024-33599 --Public-Date: 2024-04-23 --Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) --Fix-Commit: 69c58d5ef9f584ea198bd00f7964d364d0e6b921 (2.31-155) --Fix-Commit: a77064893bfe8a701770e2f53a4d33805bc47a5a (2.32-141) --Fix-Commit: 5c75001a96abcd50cbdb74df24c3f013188d076e (2.33-264) --Fix-Commit: 52f73e5c4e29b14e79167272297977f360ae1e97 (2.34-460) --Fix-Commit: 7a95873543ce225376faf13bb71c43dea6d24f86 (2.35-316) --Fix-Commit: caa3151ca460bdd9330adeedd68c3112d97bffe4 (2.36-165) --Fix-Commit: f75c298e747b2b8b41b1c2f551c011a52c41bfd1 (2.37-91) --Fix-Commit: 5968aebb86164034b8f8421b4abab2f837a5bdaf (2.38-72) --Fix-Commit: 1263d583d2e28afb8be53f8d6922f0842036f35d (2.39-35) --Fix-Commit: 87801a8fd06db1d654eea3e4f7626ff476a9bdaa (2.40) -diff --git a/advisories/GLIBC-SA-2024-0006 b/advisories/GLIBC-SA-2024-0006 -deleted file mode 100644 -index d44148d3d9..0000000000 ---- a/advisories/GLIBC-SA-2024-0006 -+++ /dev/null -@@ -1,32 +0,0 @@ --nscd: Null pointer crash after notfound response -- --If the Name Service Cache Daemon's (nscd) cache fails to add a not-found --netgroup response to the cache, the client request can result in a null --pointer dereference. This flaw was introduced in glibc 2.15 when the --cache was added to nscd. -- --This vulnerability is only present in the nscd binary. -- --CVE-Id: CVE-2024-33600 --Public-Date: 2024-04-24 --Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) --Fix-Commit: b048a482f088e53144d26a61c390bed0210f49f2 (2.40) --Fix-Commit: 7835b00dbce53c3c87bbbb1754a95fb5e58187aa (2.40) --Fix-Commit: c99f886de54446cd4447db6b44be93dabbdc2f8b (2.39-37) --Fix-Commit: 5a508e0b508c8ad53bd0d2fb48fd71b242626341 (2.39-36) --Fix-Commit: 2ae9446c1b7a3064743b4a51c0bbae668ee43e4c (2.38-74) --Fix-Commit: 541ea5172aa658c4bd5c6c6d6fd13903c3d5bb0a (2.38-73) --Fix-Commit: a8070b31043c7585c36ba68a74298c4f7af075c3 (2.37-93) --Fix-Commit: 5eea50c4402e39588de98aa1d4469a79774703d4 (2.37-92) --Fix-Commit: f205b3af56740e3b014915b1bd3b162afe3407ef (2.36-167) --Fix-Commit: c34f470a615b136170abd16142da5dd0c024f7d1 (2.36-166) --Fix-Commit: bafadc589fbe21ae330e8c2af74db9da44a17660 (2.35-318) --Fix-Commit: 4370bef52b0f3f3652c6aa13d7a9bb3ac079746d (2.35-317) --Fix-Commit: 1f94122289a9bf7dba573f5d60327aaa2b85cf2e (2.34-462) --Fix-Commit: 966d6ac9e40222b84bb21674cc4f83c8d72a5a26 (2.34-461) --Fix-Commit: e3eef1b8fbdd3a7917af466ca9c4b7477251ca79 (2.33-266) --Fix-Commit: f20a8d696b13c6261b52a6434899121f8b19d5a7 (2.33-265) --Fix-Commit: be602180146de37582a3da3a0caa4b719645de9c (2.32-143) --Fix-Commit: 394eae338199078b7961b051c191539870742d7b (2.32-142) --Fix-Commit: 8d7949183760170c61e55def723c1d8050187874 (2.31-157) --Fix-Commit: 304ce5fe466c4762b21b36c26926a4657b59b53e (2.31-156) -diff --git a/advisories/GLIBC-SA-2024-0007 b/advisories/GLIBC-SA-2024-0007 -deleted file mode 100644 -index b6928fa27a..0000000000 ---- a/advisories/GLIBC-SA-2024-0007 -+++ /dev/null -@@ -1,28 +0,0 @@ --nscd: netgroup cache may terminate daemon on memory allocation failure -- --The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or --xrealloc and these functions may terminate the process due to a memory --allocation failure resulting in a denial of service to the clients. The --flaw was introduced in glibc 2.15 when the cache was added to nscd. -- --This vulnerability is only present in the nscd binary. -- --Subsequent refactoring of the netgroup cache only added more uses of --xmalloc and xrealloc. Uses of xmalloc and xrealloc in other parts of --nscd only occur during startup of the daemon and so are not affected by --client requests that could trigger an out of memory followed by --termination. -- --CVE-Id: CVE-2024-33601 --Public-Date: 2024-04-24 --Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) --Fix-Commit: c04a21e050d64a1193a6daab872bca2528bda44b (2.40) --Fix-Commit: a9a8d3eebb145779a18d90e3966009a1daa63cd8 (2.39-38) --Fix-Commit: 71af8ca864345d39b746d5cee84b94b430fad5db (2.38-75) --Fix-Commit: 6e106dc214d6a033a4e945d1c6cf58061f1c5f1f (2.37-94) --Fix-Commit: b6742463694b1dfdd5120b91ee21cf05d15ec2e2 (2.36-168) --Fix-Commit: 7a5864cac60e06000394128a5a2817b03542f5a3 (2.35-319) --Fix-Commit: 86f1d5f4129c373ac6fb6df5bcf38273838843cb (2.34-463) --Fix-Commit: 4d27d4b9a188786fc6a56745506cec2acfc51f83 (2.33-267) --Fix-Commit: 3ed195a8ec89da281e3c4bf887a13d281b72d8f4 (2.32-144) --Fix-Commit: bbf5a58ccb55679217f94de706164d15372fbbc0 (2.31-158) -diff --git a/advisories/GLIBC-SA-2024-0008 b/advisories/GLIBC-SA-2024-0008 -deleted file mode 100644 -index d93e2a6f0b..0000000000 ---- a/advisories/GLIBC-SA-2024-0008 -+++ /dev/null -@@ -1,26 +0,0 @@ --nscd: netgroup cache assumes NSS callback uses in-buffer strings -- --The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory --when the NSS callback does not store all strings in the provided buffer. --The flaw was introduced in glibc 2.15 when the cache was added to nscd. -- --This vulnerability is only present in the nscd binary. -- --There is no guarantee from the NSS callback API that the returned --strings are all within the buffer. However, the netgroup cache code --assumes that the NSS callback uses in-buffer strings and if it doesn't --the buffer resizing logic could lead to potential memory corruption. -- --CVE-Id: CVE-2024-33602 --Public-Date: 2024-04-24 --Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) --Fix-Commit: c04a21e050d64a1193a6daab872bca2528bda44b (2.40) --Fix-Commit: a9a8d3eebb145779a18d90e3966009a1daa63cd8 (2.39-38) --Fix-Commit: 71af8ca864345d39b746d5cee84b94b430fad5db (2.38-75) --Fix-Commit: 6e106dc214d6a033a4e945d1c6cf58061f1c5f1f (2.37-94) --Fix-Commit: b6742463694b1dfdd5120b91ee21cf05d15ec2e2 (2.36-168) --Fix-Commit: 7a5864cac60e06000394128a5a2817b03542f5a3 (2.35-319) --Fix-Commit: 86f1d5f4129c373ac6fb6df5bcf38273838843cb (2.34-463) --Fix-Commit: 4d27d4b9a188786fc6a56745506cec2acfc51f83 (2.33-267) --Fix-Commit: 3ed195a8ec89da281e3c4bf887a13d281b72d8f4 (2.32-144) --Fix-Commit: bbf5a58ccb55679217f94de706164d15372fbbc0 (2.31-158) -diff --git a/advisories/GLIBC-SA-2025-0001 b/advisories/GLIBC-SA-2025-0001 -deleted file mode 100644 -index b053d32e91..0000000000 ---- a/advisories/GLIBC-SA-2025-0001 -+++ /dev/null -@@ -1,40 +0,0 @@ --assert: Buffer overflow when printing assertion failure message -- --When the assert() function fails, it does not allocate enough space for the --assertion failure message string and size information, which may lead to a --buffer overflow if the message string size aligns to page size. -- --This bug can be triggered when an assertion in a program fails. The assertion --failure message is allocated to allow developers to see this failure in core --dumps and it typically includes, in addition to the invariant assertion --string and function name, the name of the program. If the name of the failing --program is user controlled, for example on a local system, this could allow an --attacker to control the assertion failure to trigger this buffer overflow. -- --The only viable vector for exploitation of this bug is local, if a setuid --program exists that has an existing bug that results in an assertion failure. --No such program has been discovered at the time of publishing this advisory, --but the presence of custom setuid programs, although strongly discouraged as a --security practice, cannot be discounted. -- --CVE-Id: CVE-2025-0395 --Public-Date: 2025-01-22 --Vulnerable-Commit: f8a3b5bf8fa1d0c43d2458e03cc109a04fdef194 (2.13-175) --Fix-Commit: 68ee0f704cb81e9ad0a78c644a83e1e9cd2ee578 (2.41) --Fix-Commit: cdb9ba84191ce72e86346fb8b1d906e7cd930ea2 (2.42) --Fix-Commit: 69fda28279b497bd405fdd442a6d8e4d3d5f681b (2.41-7) --Fix-Commit: 7d4b6bcae91f29d7b4daf15bab06b66cf1d2217c (2.40-66) --Fix-Commit: d6c156c326999f144cb5b73d29982108d549ad8a (2.40-71) --Fix-Commit: 808a84a8b81468b517a4d721fdc62069cb8c211f (2.39-146) --Fix-Commit: f6d48470aef9264d2d56f4c4533eb76db7f9c2e4 (2.39-150) --Fix-Commit: c32fd59314c343db88c3ea4a203870481d33c3d2 (2.38-122) --Fix-Commit: f984e2d7e8299726891a1a497a3c36cd5542a0bf (2.38-124) --Fix-Commit: a3d7865b098a3a67c44f7812208d9ce4718873ba (2.37-143) --Fix-Commit: b989519fe1683c204ac24ec92830e3fe3bfaccad (2.37-146) --Fix-Commit: 7971add7ee4171fdd8dfd17e7c04c4ed77a18845 (2.36-216) --Fix-Commit: 0487893d5c5bc6710d83d7c3152d888a0339559e (2.36-219) --Fix-Commit: 8b5d4be762419c4f6176261c6fea40ac559b88dc (2.35-370) --Fix-Commit: 8b3d09dc0d350191985f9d291cc30ce96f034b49 (2.35-373) --Fix-Commit: df4e1f4a5096b385c9bcc94424cf2eaa227b3761 (2.34-500) --Fix-Commit: 31eb872cb21449832ab47ad5db83281d240e1d03 (2.34-503) --Reported-By: Qualys Security Advisory -diff --git a/advisories/GLIBC-SA-2025-0002 b/advisories/GLIBC-SA-2025-0002 -deleted file mode 100644 -index 161da13dd4..0000000000 ---- a/advisories/GLIBC-SA-2025-0002 -+++ /dev/null -@@ -1,23 +0,0 @@ --elf: static setuid binary dlopen may incorrectly search LD_LIBRARY_PATH -- --A statically linked setuid binary that calls dlopen (including internal --dlopen calls after setlocale or calls to NSS functions such as getaddrinfo) --may incorrectly search LD_LIBRARY_PATH to determine which library to load, --leading to the execution of library code that is attacker controlled. -- --The only viable vector for exploitation of this bug is local, if a static --setuid program exists, and that program calls dlopen, then it may search --LD_LIBRARY_PATH to locate the SONAME to load. No such program has been --discovered at the time of publishing this advisory, but the presence of --custom setuid programs, although strongly discouraged as a security --practice, cannot be discounted. -- --CVE-Id: CVE-2025-4802 --Public-Date: 2025-05-16 --Vulnerable-Commit: 10e93d968716ab82931d593bada121c17c0a4b93 (2.27) --Fix-Commit: 5451fa962cd0a90a0e2ec1d8910a559ace02bba0 (2.39) --Fix-Commit: 3be3728df2f1912c80abd3288bc6e3a25ad679e4 (2.38-132) --Fix-Commit: 7403ede2d7752e59e0c47d5d33d73c2bf850e7be (2.37-154) --Fix-Commit: 2ef7850279b2931caf6d6d6743ebaa91839e1cf7 (2.36-227) --Fix-Commit: 621c65ccf12ddd415ceeb2234423bd1acd0fabb3 (2.35-387) --Fix-Commit: 35018c0fd20eac9ceaf60060fed2745b3177359d (2.34-517) -diff --git a/advisories/GLIBC-SA-2025-0003 b/advisories/GLIBC-SA-2025-0003 -deleted file mode 100644 -index 2adeb3ce00..0000000000 ---- a/advisories/GLIBC-SA-2025-0003 -+++ /dev/null -@@ -1,30 +0,0 @@ --power10: strcmp fails to save and restore nonvolatile vector registers -- --The Power 10 implementation of strcmp in --sysdeps/powerpc/powerpc64/le/power10/strcmp.S failed to save/restore --nonvolatile vector registers in the 32-byte aligned loop path. This --results in callers reading content from those registers in a different --context, potentially altering program logic. -- --There could be a program context where a user controlled string could --leak through strcmp into program code, thus altering its logic. There --is also a potential for sensitive strings passed into strcmp leaking --through the clobbered registers into parts of the calling program that --should otherwise not have had access to those strings. -- --The impact of this flaw is limited to applications running on Power 10 --hardware that use the nonvolatile vector registers, i.e. v20 to v31 --assuming that they have been treated in accordance with the OpenPower --psABI. It is possible to work around the issue for those specific --applications by setting the glibc.cpu.hwcaps tunable to "-arch_3_1" like --so: -- -- export GLIBC_TUNABLES=glibc.cpu.hwcaps=-arch_3_1 -- --CVE-Id: CVE-2025-5702 --Public-Date: 2025-06-04 --Vulnerable-Commit: 3367d8e180848030d1646f088759f02b8dfe0d6f (2.39) --Fix-Commit: 15808c77b35319e67ee0dc8f984a9a1a434701bc (2.42) --Fix-Commit: 0c76c951620f9e12df2a89b2c684878b55bb6795 (2.41-60) --Fix-Commit: 7e12550b8e3a11764a4a9090ce6bd3fc23fc8a8e (2.40-139) --Fix-Commit: 06a70769fd0b2e1f2a3085ad50ab620282bd77b3 (2.39-209) -diff --git a/advisories/GLIBC-SA-2025-0004 b/advisories/GLIBC-SA-2025-0004 -deleted file mode 100644 -index 9409ca27c4..0000000000 ---- a/advisories/GLIBC-SA-2025-0004 -+++ /dev/null -@@ -1,29 +0,0 @@ --power10: strncmp fails to save and restore nonvolatile vector registers -- --The Power 10 implementation of strncmp in --sysdeps/powerpc/powerpc64/le/power10/strncmp.S failed to save/restore --nonvolatile vector registers in the 32-byte aligned loop path. This --results in callers reading content from those registers in a different --context, potentially altering program logic. -- --There could be a program context where a user controlled string could --leak through strncmp into program code, thus altering its logic. There --is also a potential for sensitive strings passed into strncmp leaking --through the clobbered registers into parts of the calling program that --should otherwise not have had access to those strings. -- --The impact of this flaw is limited to applications running on Power 10 --hardware that use the nonvolatile vector registers, i.e. v20 to v31 --assuming that they have been treated in accordance with the OpenPower --psABI. It is possible to work around the issue for those specific --applications by setting the glibc.cpu.hwcaps tunable to "-arch_3_1" like --so: -- -- export GLIBC_TUNABLES=glibc.cpu.hwcaps=-arch_3_1 -- --CVE-Id: CVE-2025-5745 --Public-Date: 2025-06-05 --Vulnerable-Commit: 23f0d81608d0ca6379894ef81670cf30af7fd081 (2.40) --Fix-Commit: 63c60101ce7c5eac42be90f698ba02099b41b965 (2.42) --Fix-Commit: 84bdbf8a6f2fdafd3661489dbb7f79835a52da82 (2.41-57) --Fix-Commit: 42a5a940c974d02540c8da26d6374c744d148cb9 (2.40-136) -diff --git a/advisories/GLIBC-SA-2025-0005 b/advisories/GLIBC-SA-2025-0005 -deleted file mode 100644 -index 8bcccc59a5..0000000000 ---- a/advisories/GLIBC-SA-2025-0005 -+++ /dev/null -@@ -1,14 +0,0 @@ --posix: Fix double-free after allocation failure in regcomp -- --The regcomp function in the GNU C library version from 2.4 to 2.41 is --subject to a double free if some previous allocation fails. It can be --accomplished either by a malloc failure or by using an interposed --malloc that injects random malloc failures. The double free can allow --buffer manipulation depending of how the regex is constructed. --This issue affects all architectures and ABIs supported by the GNU C --library. -- --CVE-Id: CVE-2025-8058 --Public-Date: 2025-07-22 --Vulnerable-Commit: 963d8d782fc98fb6dc3a66f0068795f9920c269d (2.3.3-1596) --Fix-Commit: 7ea06e994093fa0bcca0d0ee2c1db271d8d7885d (2.42) -diff --git a/advisories/README b/advisories/README -deleted file mode 100644 -index b8f8a829ca..0000000000 ---- a/advisories/README -+++ /dev/null -@@ -1,77 +0,0 @@ --GNU C Library Security Advisory Format --====================================== -- --Security advisories in this directory follow a simple git commit log --format, with a heading and free-format description augmented with tags --to allow parsing key information. References to code changes are --specific to the glibc repository and follow a specific format: -- -- Tag-name: (release-version) -- --The indicates a specific commit in the repository. The --release-version indicates the publicly consumable release in which this --commit is known to exist. The release-version is derived from the --git-describe format, (i.e. stripped out from glibc-2.34.NNN-gxxxx) and --is of the form 2.34-NNN. If the -NNN suffix is absent, it means that --the change is in that release tarball, otherwise the change is on the --release/2.YY/master branch and not in any released tarball. -- --The following tags are currently being used: -- --CVE-Id: --This is the CVE-Id assigned under the CVE Program --(https://www.cve.org/). -- --Public-Date: --The date this issue became publicly known. -- --Vulnerable-Commit: --The commit that introduced this vulnerability. There could be multiple --entries, one for each release branch in the glibc repository; the --release-version portion of this tag should tell you which branch this is --on. -- --Fix-Commit: --The commit that fixed this vulnerability. There could be multiple --entries for each release branch in the glibc repository, indicating that --all of those commits contributed to fixing that issue in each of those --branches. -- --Reported-By: --The entity that reported this issue. There could be multiple entries, one for --each reporter. -- --Adding an Advisory -------------------- -- --An advisory for a CVE needs to be added on the master branch in two steps: -- --1. Add the text of the advisory without any Fix-Commit tags along with -- the fix for the CVE. Add the Vulnerable-Commit tag, if applicable. -- The advisories directory does not exist in release branches, so keep -- the advisory text commit distinct from the code changes, to ease -- backports. Ask for the GLIBC-SA advisory number from the security -- team. -- --2. Finish all backports on release branches and then back on the msater -- branch, add all commit refs to the advisory using the Fix-Commit -- tags. Don't bother adding the release-version subscript since the -- next step will overwrite it. -- --3. Run the process-advisories.sh script in the scripts directory on the -- advisory: -- -- scripts/process-advisories.sh update GLIBC-SA-YYYY-NNNN -- -- (replace YYYY-NNNN with the actual advisory number). -- --4. Verify the updated advisory and push the result. -- --Getting a NEWS snippet from advisories ---------------------------------------- -- --Run: -- -- scripts/process-advisories.sh news -- --and copy the content into the NEWS file. - -commit 3ec4dd77f648da031bba4d3fa14825e057b5a40d -Author: Andreas K. Hüttel -Date: Mon Jul 28 23:39:48 2025 +0200 - - NEWS: add new section - - Signed-off-by: Andreas K. Hüttel - -diff --git a/NEWS b/NEWS -index f0b0e924a4..9cb8de11f9 100644 ---- a/NEWS -+++ b/NEWS -@@ -5,6 +5,12 @@ See the end for copying conditions. - Please send GNU C library bug reports via - using `glibc' in the "product" field. - -+Version 2.42.1 -+ -+The following bugs were resolved with this release: -+ -+ [insert bugs here] -+ - Version 2.42 - - Major new features: - -commit bc13db73937730401d592b33092db6df806d193e -Author: Sam James -Date: Mon Jul 28 21:55:30 2025 +0100 - - inet-fortified: fix namespace violation (bug 33227) - - We need to use __sz, not sz, as we do elsewhere. - - Reviewed-by: Florian Weimer - (cherry picked from commit 87afbd7a1ad9c1dd116921817fa97198171045db) - -diff --git a/inet/bits/inet-fortified.h b/inet/bits/inet-fortified.h -index 6738221a54..cc476ebcfd 100644 ---- a/inet/bits/inet-fortified.h -+++ b/inet/bits/inet-fortified.h -@@ -45,15 +45,15 @@ __NTH (inet_pton (int __af, - __fortify_clang_warning_only_if_bos0_lt - (4, __dst, "inet_pton called with destination buffer size less than 4") - { -- size_t sz = 0; -+ size_t __sz = 0; - if (__af == AF_INET) -- sz = sizeof (struct in_addr); -+ __sz = sizeof (struct in_addr); - else if (__af == AF_INET6) -- sz = sizeof (struct in6_addr); -+ __sz = sizeof (struct in6_addr); - else - return __inet_pton_alias (__af, __src, __dst); - -- return __glibc_fortify (inet_pton, sz, sizeof (char), -+ return __glibc_fortify (inet_pton, __sz, sizeof (char), - __glibc_objsize (__dst), - __af, __src, __dst); - }; - -commit fd18059c0fcf5568db3688da47403b663cf91c5e -Author: Davide Cavalca -Date: Thu Jul 31 17:32:58 2025 +0200 - - stdlib: resolve a double lock init issue after fork [BZ #32994] - - The __abort_fork_reset_child (introduced in - d40ac01cbbc66e6d9dbd8e3485605c63b2178251) call resets the lock after the - fork. This causes a DRD regression in valgrind - (https://bugs.kde.org/show_bug.cgi?id=503668), as it's effectively a - double initialization, despite it being actually ok in this case. As - suggested in https://sourceware.org/bugzilla/show_bug.cgi?id=32994#c2 - we replace it here with a memcpy of another initialized lock instead, - which makes valgrind happy. - - Reviewed-by: Florian Weimer - (cherry picked from commit d9a348d0927c7a1aec5caf3df3fcd36956b3eb23) - -diff --git a/NEWS b/NEWS -index 9cb8de11f9..4610b8bbc6 100644 ---- a/NEWS -+++ b/NEWS -@@ -9,7 +9,7 @@ Version 2.42.1 - - The following bugs were resolved with this release: - -- [insert bugs here] -+ [32994] stdlib: resolve a double lock init issue after fork - - Version 2.42 - -diff --git a/stdlib/abort.c b/stdlib/abort.c -index caa9e6dc04..904244a2fb 100644 ---- a/stdlib/abort.c -+++ b/stdlib/abort.c -@@ -19,6 +19,7 @@ - #include - #include - #include -+#include - #include - - /* Try to get a machine dependent instruction which will make the -@@ -42,7 +43,10 @@ __libc_rwlock_define_initialized (static, lock); - void - __abort_fork_reset_child (void) - { -- __libc_rwlock_init (lock); -+ /* Reinitialize lock without calling pthread_rwlock_init, to -+ avoid a valgrind DRD false positive. */ -+ __libc_rwlock_define_initialized (, reset_lock); -+ memcpy (&lock, &reset_lock, sizeof (lock)); - } - - void - -commit 2fadee530155bae6682ab2965d6ff3a2fc9eced6 -Author: Florian Weimer -Date: Fri Aug 1 19:27:04 2025 +0200 - - elf: Extract rtld_setup_phdr function from dl_main - - Remove historic binutils reference from comment and update - how this data is used by applications. - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 2cac9559e06044ba520e785c151fbbd25011865f) - -diff --git a/elf/rtld.c b/elf/rtld.c -index 493f9696ea..6fb900fb31 100644 ---- a/elf/rtld.c -+++ b/elf/rtld.c -@@ -1239,6 +1239,37 @@ rtld_setup_main_map (struct link_map *main_map) - return has_interp; - } - -+/* Set up the program header information for the dynamic linker -+ itself. It can be accessed via _r_debug and dl_iterate_phdr -+ callbacks. */ -+static void -+rtld_setup_phdr (void) -+{ -+ /* Starting from binutils-2.23, the linker will define the magic -+ symbol __ehdr_start to point to our own ELF header if it is -+ visible in a segment that also includes the phdrs. */ -+ -+ const ElfW(Ehdr) *rtld_ehdr = &__ehdr_start; -+ assert (rtld_ehdr->e_ehsize == sizeof *rtld_ehdr); -+ assert (rtld_ehdr->e_phentsize == sizeof (ElfW(Phdr))); -+ -+ const ElfW(Phdr) *rtld_phdr = (const void *) rtld_ehdr + rtld_ehdr->e_phoff; -+ -+ _dl_rtld_map.l_phdr = rtld_phdr; -+ _dl_rtld_map.l_phnum = rtld_ehdr->e_phnum; -+ -+ -+ /* PT_GNU_RELRO is usually the last phdr. */ -+ size_t cnt = rtld_ehdr->e_phnum; -+ while (cnt-- > 0) -+ if (rtld_phdr[cnt].p_type == PT_GNU_RELRO) -+ { -+ _dl_rtld_map.l_relro_addr = rtld_phdr[cnt].p_vaddr; -+ _dl_rtld_map.l_relro_size = rtld_phdr[cnt].p_memsz; -+ break; -+ } -+} -+ - /* Adjusts the contents of the stack and related globals for the user - entry point. The ld.so processed skip_args arguments and bumped - _dl_argv and _dl_argc accordingly. Those arguments are removed from -@@ -1705,33 +1736,7 @@ dl_main (const ElfW(Phdr) *phdr, - ++GL(dl_ns)[LM_ID_BASE]._ns_nloaded; - ++GL(dl_load_adds); - -- /* Starting from binutils-2.23, the linker will define the magic symbol -- __ehdr_start to point to our own ELF header if it is visible in a -- segment that also includes the phdrs. If that's not available, we use -- the old method that assumes the beginning of the file is part of the -- lowest-addressed PT_LOAD segment. */ -- -- /* Set up the program header information for the dynamic linker -- itself. It is needed in the dl_iterate_phdr callbacks. */ -- const ElfW(Ehdr) *rtld_ehdr = &__ehdr_start; -- assert (rtld_ehdr->e_ehsize == sizeof *rtld_ehdr); -- assert (rtld_ehdr->e_phentsize == sizeof (ElfW(Phdr))); -- -- const ElfW(Phdr) *rtld_phdr = (const void *) rtld_ehdr + rtld_ehdr->e_phoff; -- -- _dl_rtld_map.l_phdr = rtld_phdr; -- _dl_rtld_map.l_phnum = rtld_ehdr->e_phnum; -- -- -- /* PT_GNU_RELRO is usually the last phdr. */ -- size_t cnt = rtld_ehdr->e_phnum; -- while (cnt-- > 0) -- if (rtld_phdr[cnt].p_type == PT_GNU_RELRO) -- { -- _dl_rtld_map.l_relro_addr = rtld_phdr[cnt].p_vaddr; -- _dl_rtld_map.l_relro_size = rtld_phdr[cnt].p_memsz; -- break; -- } -+ rtld_setup_phdr (); - - /* Add the dynamic linker to the TLS list if it also uses TLS. */ - if (_dl_rtld_map.l_tls_blocksize != 0) - -commit 5e298d2d937b6da06500478be956abeb24357e05 -Author: Florian Weimer -Date: Fri Aug 1 19:27:35 2025 +0200 - - elf: Handle ld.so with LOAD segment gaps in _dl_find_object (bug 31943) - - Detect if ld.so not contiguous and handle that case in _dl_find_object. - Set l_find_object_processed even for initially loaded link maps, - otherwise dlopen of an initially loaded object adds it to - _dlfo_loaded_mappings (where maps are expected to be contiguous), - in addition to _dlfo_nodelete_mappings. - - Test elf/tst-link-map-contiguous-ldso iterates over the loader - image, reading every word to make sure memory is actually mapped. - It only does that if the l_contiguous flag is set for the link map. - Otherwise, it finds gaps with mmap and checks that _dl_find_object - does not return the ld.so mapping for them. - - The test elf/tst-link-map-contiguous-main does the same thing for - the libc.so shared object. This only works if the kernel loaded - the main program because the glibc dynamic loader may fill - the gaps with PROT_NONE mappings in some cases, making it contiguous, - but accesses to individual words may still fault. - - Test elf/tst-link-map-contiguous-libc is again slightly different - because the dynamic loader always fills the gaps with PROT_NONE - mappings, so a different form of probing has to be used. - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 20681be149b9eb1b6c1f4246bf4bd801221c86cd) - -diff --git a/NEWS b/NEWS -index 4610b8bbc6..cbe11ac95b 100644 ---- a/NEWS -+++ b/NEWS -@@ -9,6 +9,7 @@ Version 2.42.1 - - The following bugs were resolved with this release: - -+ [31943] _dl_find_object can fail if ld.so contains gaps between load segments - [32994] stdlib: resolve a double lock init issue after fork - - Version 2.42 -diff --git a/elf/Makefile b/elf/Makefile -index 48aa0b57e5..3a5596e2bb 100644 ---- a/elf/Makefile -+++ b/elf/Makefile -@@ -543,6 +543,8 @@ tests-internal += \ - tst-dl_find_object-threads \ - tst-dlmopen2 \ - tst-hash-collision3 \ -+ tst-link-map-contiguous-ldso \ -+ tst-link-map-contiguous-libc \ - tst-ptrguard1 \ - tst-stackguard1 \ - tst-tls-surplus \ -@@ -554,6 +556,10 @@ tests-internal += \ - unload2 \ - # tests-internal - -+ifeq ($(build-hardcoded-path-in-tests),yes) -+tests-internal += tst-link-map-contiguous-main -+endif -+ - tests-container += \ - tst-dlopen-self-container \ - tst-dlopen-tlsmodid-container \ -diff --git a/elf/dl-find_object.c b/elf/dl-find_object.c -index 1e76373292..c9f4c1c8d1 100644 ---- a/elf/dl-find_object.c -+++ b/elf/dl-find_object.c -@@ -465,6 +465,37 @@ _dl_find_object (void *pc1, struct dl_find_object *result) - } - rtld_hidden_def (_dl_find_object) - -+/* Subroutine of _dlfo_process_initial to split out noncontigous link -+ maps. NODELETE is the number of used _dlfo_nodelete_mappings -+ elements. It is incremented as needed, and the new NODELETE value -+ is returned. */ -+static size_t -+_dlfo_process_initial_noncontiguous_map (struct link_map *map, -+ size_t nodelete) -+{ -+ struct dl_find_object_internal dlfo; -+ _dl_find_object_from_map (map, &dlfo); -+ -+ /* PT_LOAD segments for a non-contiguous link map are added to the -+ non-closeable mappings. */ -+ const ElfW(Phdr) *ph = map->l_phdr; -+ const ElfW(Phdr) *ph_end = map->l_phdr + map->l_phnum; -+ for (; ph < ph_end; ++ph) -+ if (ph->p_type == PT_LOAD) -+ { -+ if (_dlfo_nodelete_mappings != NULL) -+ { -+ /* Second pass only. */ -+ _dlfo_nodelete_mappings[nodelete] = dlfo; -+ ElfW(Addr) start = ph->p_vaddr + map->l_addr; -+ _dlfo_nodelete_mappings[nodelete].map_start = start; -+ _dlfo_nodelete_mappings[nodelete].map_end = start + ph->p_memsz; -+ } -+ ++nodelete; -+ } -+ return nodelete; -+} -+ - /* _dlfo_process_initial is called twice. First to compute the array - sizes from the initial loaded mappings. Second to fill in the - bases and infos arrays with the (still unsorted) data. Returns the -@@ -476,29 +507,8 @@ _dlfo_process_initial (void) - - size_t nodelete = 0; - if (!main_map->l_contiguous) -- { -- struct dl_find_object_internal dlfo; -- _dl_find_object_from_map (main_map, &dlfo); -- -- /* PT_LOAD segments for a non-contiguous are added to the -- non-closeable mappings. */ -- for (const ElfW(Phdr) *ph = main_map->l_phdr, -- *ph_end = main_map->l_phdr + main_map->l_phnum; -- ph < ph_end; ++ph) -- if (ph->p_type == PT_LOAD) -- { -- if (_dlfo_nodelete_mappings != NULL) -- { -- /* Second pass only. */ -- _dlfo_nodelete_mappings[nodelete] = dlfo; -- _dlfo_nodelete_mappings[nodelete].map_start -- = ph->p_vaddr + main_map->l_addr; -- _dlfo_nodelete_mappings[nodelete].map_end -- = _dlfo_nodelete_mappings[nodelete].map_start + ph->p_memsz; -- } -- ++nodelete; -- } -- } -+ /* Contiguous case already handled in _dl_find_object_init. */ -+ nodelete = _dlfo_process_initial_noncontiguous_map (main_map, nodelete); - - size_t loaded = 0; - for (Lmid_t ns = 0; ns < GL(dl_nns); ++ns) -@@ -510,11 +520,18 @@ _dlfo_process_initial (void) - /* lt_library link maps are implicitly NODELETE. */ - if (l->l_type == lt_library || l->l_nodelete_active) - { -- if (_dlfo_nodelete_mappings != NULL) -- /* Second pass only. */ -- _dl_find_object_from_map -- (l, _dlfo_nodelete_mappings + nodelete); -- ++nodelete; -+ /* The kernel may have loaded ld.so with gaps. */ -+ if (!l->l_contiguous && is_rtld_link_map (l)) -+ nodelete -+ = _dlfo_process_initial_noncontiguous_map (l, nodelete); -+ else -+ { -+ if (_dlfo_nodelete_mappings != NULL) -+ /* Second pass only. */ -+ _dl_find_object_from_map -+ (l, _dlfo_nodelete_mappings + nodelete); -+ ++nodelete; -+ } - } - else if (l->l_type == lt_loaded) - { -@@ -764,7 +781,6 @@ _dl_find_object_update_1 (struct link_map **loaded, size_t count) - /* Prefer newly loaded link map. */ - assert (loaded_index1 > 0); - _dl_find_object_from_map (loaded[loaded_index1 - 1], dlfo); -- loaded[loaded_index1 - 1]->l_find_object_processed = 1; - --loaded_index1; - } - -diff --git a/elf/dl-find_object.h b/elf/dl-find_object.h -index 9aa2439eaa..d9d75c4ad9 100644 ---- a/elf/dl-find_object.h -+++ b/elf/dl-find_object.h -@@ -94,7 +94,7 @@ _dl_find_object_to_external (struct dl_find_object_internal *internal, - } - - /* Extract the object location data from a link map and writes it to -- *RESULT using relaxed MO stores. */ -+ *RESULT using relaxed MO stores. Set L->l_find_object_processed. */ - static void __attribute__ ((unused)) - _dl_find_object_from_map (struct link_map *l, - struct dl_find_object_internal *result) -@@ -141,8 +141,11 @@ _dl_find_object_from_map (struct link_map *l, - break; - } - if (read_seg == 3) -- return; -+ goto done; - } -+ -+ done: -+ l->l_find_object_processed = 1; - } - - /* Called by the dynamic linker to set up the data structures for the -diff --git a/elf/rtld.c b/elf/rtld.c -index 6fb900fb31..ef4d96c053 100644 ---- a/elf/rtld.c -+++ b/elf/rtld.c -@@ -1241,7 +1241,7 @@ rtld_setup_main_map (struct link_map *main_map) - - /* Set up the program header information for the dynamic linker - itself. It can be accessed via _r_debug and dl_iterate_phdr -- callbacks. */ -+ callbacks, and it is used by _dl_find_object. */ - static void - rtld_setup_phdr (void) - { -@@ -1259,6 +1259,29 @@ rtld_setup_phdr (void) - _dl_rtld_map.l_phnum = rtld_ehdr->e_phnum; - - -+ _dl_rtld_map.l_contiguous = 1; -+ /* The linker may not have produced a contiguous object. The kernel -+ will load the object with actual gaps (unlike the glibc loader -+ for shared objects, which always produces a contiguous mapping). -+ See similar logic in rtld_setup_main_map above. */ -+ { -+ ElfW(Addr) expected_load_address = 0; -+ for (const ElfW(Phdr) *ph = rtld_phdr; ph < &rtld_phdr[rtld_ehdr->e_phnum]; -+ ++ph) -+ if (ph->p_type == PT_LOAD) -+ { -+ ElfW(Addr) mapstart = ph->p_vaddr & ~(GLRO(dl_pagesize) - 1); -+ if (_dl_rtld_map.l_contiguous && expected_load_address != 0 -+ && expected_load_address != mapstart) -+ _dl_rtld_map.l_contiguous = 0; -+ ElfW(Addr) allocend = ph->p_vaddr + ph->p_memsz; -+ /* The next expected address is the page following this load -+ segment. */ -+ expected_load_address = ((allocend + GLRO(dl_pagesize) - 1) -+ & ~(GLRO(dl_pagesize) - 1)); -+ } -+ } -+ - /* PT_GNU_RELRO is usually the last phdr. */ - size_t cnt = rtld_ehdr->e_phnum; - while (cnt-- > 0) -diff --git a/elf/tst-link-map-contiguous-ldso.c b/elf/tst-link-map-contiguous-ldso.c -new file mode 100644 -index 0000000000..04de808bb2 ---- /dev/null -+++ b/elf/tst-link-map-contiguous-ldso.c -@@ -0,0 +1,98 @@ -+/* Check that _dl_find_object behavior matches up with gaps. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+ -+static int -+do_test (void) -+{ -+ struct link_map *l = xdlopen (LD_SO, RTLD_NOW); -+ if (!l->l_contiguous) -+ { -+ puts ("info: ld.so link map is not contiguous"); -+ -+ /* Try to find holes by probing with mmap. */ -+ int pagesize = getpagesize (); -+ bool gap_found = false; -+ ElfW(Addr) addr = l->l_map_start; -+ TEST_COMPARE (addr % pagesize, 0); -+ while (addr < l->l_map_end) -+ { -+ void *expected = (void *) addr; -+ void *ptr = xmmap (expected, 1, PROT_READ | PROT_WRITE, -+ MAP_PRIVATE | MAP_ANONYMOUS, -1); -+ struct dl_find_object dlfo; -+ int dlfo_ret = _dl_find_object (expected, &dlfo); -+ if (ptr == expected) -+ { -+ if (dlfo_ret < 0) -+ { -+ TEST_COMPARE (dlfo_ret, -1); -+ printf ("info: hole without mapping data found at %p\n", ptr); -+ } -+ else -+ FAIL ("object \"%s\" found in gap at %p", -+ dlfo.dlfo_link_map->l_name, ptr); -+ gap_found = true; -+ } -+ else if (dlfo_ret == 0) -+ { -+ if ((void *) dlfo.dlfo_link_map != (void *) l) -+ { -+ printf ("info: object \"%s\" found at %p\n", -+ dlfo.dlfo_link_map->l_name, ptr); -+ gap_found = true; -+ } -+ } -+ else -+ TEST_COMPARE (dlfo_ret, -1); -+ xmunmap (ptr, 1); -+ addr += pagesize; -+ } -+ if (!gap_found) -+ FAIL ("no ld.so gap found"); -+ } -+ else -+ { -+ puts ("info: ld.so link map is contiguous"); -+ -+ /* Assert that ld.so is truly contiguous in memory. */ -+ volatile long int *p = (volatile long int *) l->l_map_start; -+ volatile long int *end = (volatile long int *) l->l_map_end; -+ while (p < end) -+ { -+ *p; -+ ++p; -+ } -+ } -+ -+ xdlclose (l); -+ -+ return 0; -+} -+ -+#include -diff --git a/elf/tst-link-map-contiguous-libc.c b/elf/tst-link-map-contiguous-libc.c -new file mode 100644 -index 0000000000..eb5728c765 ---- /dev/null -+++ b/elf/tst-link-map-contiguous-libc.c -@@ -0,0 +1,57 @@ -+/* Check that the entire libc.so program image is readable if contiguous. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+ -+static int -+do_test (void) -+{ -+ struct link_map *l = xdlopen (LIBC_SO, RTLD_NOW); -+ -+ /* The dynamic loader fills holes with PROT_NONE mappings. */ -+ if (!l->l_contiguous) -+ FAIL_EXIT1 ("libc.so link map is not contiguous"); -+ -+ /* Direct probing does not work because not everything is readable -+ due to PROT_NONE mappings. */ -+ int pagesize = getpagesize (); -+ ElfW(Addr) addr = l->l_map_start; -+ TEST_COMPARE (addr % pagesize, 0); -+ while (addr < l->l_map_end) -+ { -+ void *expected = (void *) addr; -+ void *ptr = xmmap (expected, 1, PROT_READ | PROT_WRITE, -+ MAP_PRIVATE | MAP_ANONYMOUS, -1); -+ if (ptr == expected) -+ FAIL ("hole in libc.so memory image after %lu bytes", -+ (unsigned long int) (addr - l->l_map_start)); -+ xmunmap (ptr, 1); -+ addr += pagesize; -+ } -+ -+ xdlclose (l); -+ -+ return 0; -+} -+#include -diff --git a/elf/tst-link-map-contiguous-main.c b/elf/tst-link-map-contiguous-main.c -new file mode 100644 -index 0000000000..2d1a054f0f ---- /dev/null -+++ b/elf/tst-link-map-contiguous-main.c -@@ -0,0 +1,45 @@ -+/* Check that the entire main program image is readable if contiguous. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+ -+static int -+do_test (void) -+{ -+ struct link_map *l = xdlopen ("", RTLD_NOW); -+ if (!l->l_contiguous) -+ FAIL_UNSUPPORTED ("main link map is not contiguous"); -+ -+ /* This check only works if the kernel loaded the main program. The -+ dynamic loader replaces gaps with PROT_NONE mappings, resulting -+ in faults. */ -+ volatile long int *p = (volatile long int *) l->l_map_start; -+ volatile long int *end = (volatile long int *) l->l_map_end; -+ while (p < end) -+ { -+ *p; -+ ++p; -+ } -+ -+ xdlclose (l); -+ -+ return 0; -+} -+#include - -commit b38f3f60d5b157edcf4d8bd1fd3ed02d417889e0 -Author: Adhemerval Zanella -Date: Fri Aug 1 15:00:25 2025 -0300 - - nptl: Fix SYSCALL_CANCEL for return values larger than INT_MAX (BZ 33245) - - The SYSCALL_CANCEL calls __syscall_cancel, which in turn - calls __internal_syscall_cancel with an 'int' return instead of the - expected 'long int'. This causes issues with syscalls that return - values larger than INT_MAX, such as copy_file_range [1]. - - Checked on x86_64-linux-gnu. - - [1] https://debbugs.gnu.org/cgi/bugreport.cgi?bug=79139 - - Reviewed-by: Andreas K. Huettel - (cherry picked from commit 7107bebf19286f42dcb0a97581137a5893c16206) - -diff --git a/NEWS b/NEWS -index cbe11ac95b..1d04bdfef8 100644 ---- a/NEWS -+++ b/NEWS -@@ -11,6 +11,7 @@ The following bugs were resolved with this release: - - [31943] _dl_find_object can fail if ld.so contains gaps between load segments - [32994] stdlib: resolve a double lock init issue after fork -+ [33245] nptl: nptl: error in internal cancellation syscall handling - - Version 2.42 - -diff --git a/nptl/cancellation.c b/nptl/cancellation.c -index 156e63dcf0..bed0383a23 100644 ---- a/nptl/cancellation.c -+++ b/nptl/cancellation.c -@@ -72,8 +72,8 @@ __syscall_cancel (__syscall_arg_t a1, __syscall_arg_t a2, - __syscall_arg_t a5, __syscall_arg_t a6, - __SYSCALL_CANCEL7_ARG_DEF __syscall_arg_t nr) - { -- int r = __internal_syscall_cancel (a1, a2, a3, a4, a5, a6, -- __SYSCALL_CANCEL7_ARG nr); -+ long int r = __internal_syscall_cancel (a1, a2, a3, a4, a5, a6, -+ __SYSCALL_CANCEL7_ARG nr); - return __glibc_unlikely (INTERNAL_SYSCALL_ERROR_P (r)) - ? SYSCALL_ERROR_LABEL (INTERNAL_SYSCALL_ERRNO (r)) - : r; - -commit 9d5bf9c17db0f35268cd798660c8bbeea1f4071d -Author: H.J. Lu -Date: Sat Jul 19 07:43:26 2025 -0700 - - Delete temporary files in support_subprocess - - Call support_delete_temp_files to delete temporary files before exit in - support_subprocess. - - This partially fixes BZ #33182. - - Signed-off-by: H.J. Lu - Reviewed-by: Adhemerval Zanella - (cherry picked from commit d27b1a71cd424710813bd3d81afb32a36470d643) - -diff --git a/support/support_subprocess.c b/support/support_subprocess.c -index be00dde3a7..8bf9a33ea2 100644 ---- a/support/support_subprocess.c -+++ b/support/support_subprocess.c -@@ -25,6 +25,7 @@ - #include - #include - #include -+#include - - static struct support_subprocess - support_subprocess_init (void) -@@ -60,6 +61,8 @@ support_subprocess (void (*callback) (void *), void *closure) - xclose (result.stdout_pipe[1]); - xclose (result.stderr_pipe[1]); - callback (closure); -+ /* Make sure that temporary files are deleted. */ -+ support_delete_temp_files (); - _exit (0); - } - xclose (result.stdout_pipe[1]); - -commit 9ec7a532ffdb9a6e0a4b220d7a694d6120701035 -Author: H.J. Lu -Date: Sat Jul 19 07:43:27 2025 -0700 - - tst-fopen-threaded.c: Delete temporary file - - Update tst-fopen-threaded.c to call support_create_temp_directory to - create a temporary directory and open "file" in the temporary directory, - instead of using /tmp/openclosetest and leaving it behind. - - This partially fixes BZ #33182. - - Signed-off-by: H.J. Lu - Reviewed-by: Adhemerval Zanella - (cherry picked from commit e7db5150603bb2224a2bfd9628cae04ddcbe49e3) - -diff --git a/sysdeps/pthread/tst-fopen-threaded.c b/sysdeps/pthread/tst-fopen-threaded.c -index ade58ad19e..c17f1eaa13 100644 ---- a/sysdeps/pthread/tst-fopen-threaded.c -+++ b/sysdeps/pthread/tst-fopen-threaded.c -@@ -34,11 +34,13 @@ - #include - #include - #include -+#include - - #include - #include - #include - #include -+#include - - #define NUM_THREADS 100 - #define ITERS 10 -@@ -111,7 +113,8 @@ threadOpenCloseRoutine (void *argv) - /* Wait for all threads to be ready to call fopen and fclose. */ - xpthread_barrier_wait (&barrier); - -- FILE *fd = xfopen ("/tmp/openclosetest", "w+"); -+ char *file = (char *) argv; -+ FILE *fd = xfopen (file, "w+"); - xfclose (fd); - return NULL; - } -@@ -235,6 +238,10 @@ do_test (void) - xfclose (fd_file); - } - -+ char *tempdir = support_create_temp_directory ("openclosetest-"); -+ char *file = xasprintf ("%s/file", tempdir); -+ add_temp_file (file); -+ - /* Test 3: Concurrent open/close. */ - for (int reps = 1; reps <= ITERS; reps++) - { -@@ -243,7 +250,7 @@ do_test (void) - { - threads[i] = - xpthread_create (support_small_stack_thread_attribute (), -- threadOpenCloseRoutine, NULL); -+ threadOpenCloseRoutine, file); - } - for (int i = 0; i < NUM_THREADS; i++) - { -@@ -252,6 +259,9 @@ do_test (void) - xpthread_barrier_destroy (&barrier); - } - -+ free (file); -+ free (tempdir); -+ - return 0; - } - - -commit 41a77b78cff821007e3dd874619ebec7ce708c3d -Author: H.J. Lu -Date: Sat Jul 19 07:43:28 2025 -0700 - - tst-freopen4-main.c: Call support_capture_subprocess with chroot - - Update tst-freopen4-main.c to call support_capture_subprocess with chroot, - which makes temporary files inaccessible, so that temporary files can be - deleted. - - This partially fixes BZ #33182. - - Signed-off-by: H.J. Lu - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 6463d4a7b28e5ee3891c34a8a1f0a59c24dfa9de) - -diff --git a/stdio-common/tst-freopen4-main.c b/stdio-common/tst-freopen4-main.c -index 3336f5327d..436da4d203 100644 ---- a/stdio-common/tst-freopen4-main.c -+++ b/stdio-common/tst-freopen4-main.c -@@ -28,25 +28,15 @@ - #include - #include - #include -+#include - --int --do_test (void) -+static void -+do_test_chroot (void *data) - { -- mtrace (); -- char *temp_dir; -+ char *temp_dir = (char *) data; - FILE *fp; - int ret; - -- /* These chroot tests verify that either reopening a renamed or -- deleted file works even in the absence of /proc, or that it fails -- (without memory leaks); thus, for example, such reopening does -- not crash in the absence of /proc. */ -- -- support_become_root (); -- if (!support_can_chroot ()) -- return EXIT_UNSUPPORTED; -- -- temp_dir = support_create_temp_directory ("tst-freopen4"); - xchroot (temp_dir); - - /* Test freopen with NULL, renamed file. This verifies that -@@ -96,6 +86,32 @@ do_test (void) - puts ("freopen of deleted file failed (OK)"); - - free (temp_dir); -+} -+ -+int -+do_test (void) -+{ -+ mtrace (); -+ char *temp_dir; -+ -+ /* These chroot tests verify that either reopening a renamed or -+ deleted file works even in the absence of /proc, or that it fails -+ (without memory leaks); thus, for example, such reopening does -+ not crash in the absence of /proc. */ -+ -+ support_become_root (); -+ if (!support_can_chroot ()) -+ return EXIT_UNSUPPORTED; -+ -+ temp_dir = support_create_temp_directory ("tst-freopen4"); -+ -+ struct support_capture_subprocess result; -+ result = support_capture_subprocess (do_test_chroot, temp_dir); -+ support_capture_subprocess_check (&result, "freopen4", 0, -+ sc_allow_stdout); -+ fputs (result.out.buffer, stdout); -+ support_capture_subprocess_free (&result); -+ - return 0; - } - - -commit c090b0cb1cde74aaeec01663dd55d6681dc92075 -Author: H.J. Lu -Date: Sat Jul 19 07:43:29 2025 -0700 - - tst-env-setuid: Delete LD_DEBUG_OUTPUT output - - Update tst-env-setuid.c to delete LD_DEBUG_OUTPUT output, instead of - leaving it behind. - - This partially fixes BZ #33182. - - Signed-off-by: H.J. Lu - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 5d23dfb289174d73b8907b86d2bef7a3ca889840) - -diff --git a/elf/tst-env-setuid.c b/elf/tst-env-setuid.c -index 7209acd616..ff3eda7f91 100644 ---- a/elf/tst-env-setuid.c -+++ b/elf/tst-env-setuid.c -@@ -40,6 +40,8 @@ static char SETGID_CHILD[] = "setgid-child"; - # define PROFILE_LIB "tst-sonamemove-runmod2.so" - #endif - -+#define LD_DEBUG_OUTPUT "/tmp/some-file" -+ - struct envvar_t - { - const char *env; -@@ -61,7 +63,7 @@ static const struct envvar_t filtered_envvars[] = - { "MALLOC_TRIM_THRESHOLD_", FILTERED_VALUE }, - { "RES_OPTIONS", FILTERED_VALUE }, - { "LD_DEBUG", "all" }, -- { "LD_DEBUG_OUTPUT", "/tmp/some-file" }, -+ { "LD_DEBUG_OUTPUT", LD_DEBUG_OUTPUT }, - { "LD_WARN", FILTERED_VALUE }, - { "LD_VERBOSE", FILTERED_VALUE }, - { "LD_BIND_NOW", "0" }, -@@ -74,6 +76,14 @@ static const struct envvar_t unfiltered_envvars[] = - { "LD_ASSUME_KERNEL", UNFILTERED_VALUE }, - }; - -+static void -+unlink_ld_debug_output (pid_t pid) -+{ -+ char *output = xasprintf ("%s.%d", LD_DEBUG_OUTPUT, pid); -+ unlink (output); -+ free (output); -+} -+ - static int - test_child (void) - { -@@ -138,13 +148,21 @@ do_test (int argc, char **argv) - /* Setgid child process. */ - if (argc == 2 && strcmp (argv[1], SETGID_CHILD) == 0) - { -+ pid_t ppid = getppid (); -+ - if (getgid () == getegid ()) -- /* This can happen if the file system is mounted nosuid. */ -- FAIL_UNSUPPORTED ("SGID failed: GID and EGID match (%jd)\n", -- (intmax_t) getgid ()); -+ { -+ /* This can happen if the file system is mounted nosuid. */ -+ unlink_ld_debug_output (ppid); -+ -+ FAIL_UNSUPPORTED ("SGID failed: GID and EGID match (%jd)\n", -+ (intmax_t) getgid ()); -+ } - - int ret = test_child (); - -+ unlink_ld_debug_output (ppid); -+ - if (ret != 0) - exit (1); - return 0; - -commit e5754399b542640f3f69c5e2513c57a307656032 -Author: H.J. Lu -Date: Tue Aug 5 09:16:14 2025 -0700 - - Revert "tst-freopen4-main.c: Call support_capture_subprocess with chroot" - - Revert commit 6463d4a7b28e5ee3891c34a8a1f0a59c24dfa9de to fix - - FAIL: stdio-common/tst-freopen4-mem - FAIL: stdio-common/tst-freopen64-4-mem - - This fixes BZ #33254. - - Reviewed-by: Sam James - (cherry picked from commit adec0bf05bc23ec35573c7a5b96440089b69265e) - -diff --git a/stdio-common/tst-freopen4-main.c b/stdio-common/tst-freopen4-main.c -index 436da4d203..3336f5327d 100644 ---- a/stdio-common/tst-freopen4-main.c -+++ b/stdio-common/tst-freopen4-main.c -@@ -28,15 +28,25 @@ - #include - #include - #include --#include - --static void --do_test_chroot (void *data) -+int -+do_test (void) - { -- char *temp_dir = (char *) data; -+ mtrace (); -+ char *temp_dir; - FILE *fp; - int ret; - -+ /* These chroot tests verify that either reopening a renamed or -+ deleted file works even in the absence of /proc, or that it fails -+ (without memory leaks); thus, for example, such reopening does -+ not crash in the absence of /proc. */ -+ -+ support_become_root (); -+ if (!support_can_chroot ()) -+ return EXIT_UNSUPPORTED; -+ -+ temp_dir = support_create_temp_directory ("tst-freopen4"); - xchroot (temp_dir); - - /* Test freopen with NULL, renamed file. This verifies that -@@ -86,32 +96,6 @@ do_test_chroot (void *data) - puts ("freopen of deleted file failed (OK)"); - - free (temp_dir); --} -- --int --do_test (void) --{ -- mtrace (); -- char *temp_dir; -- -- /* These chroot tests verify that either reopening a renamed or -- deleted file works even in the absence of /proc, or that it fails -- (without memory leaks); thus, for example, such reopening does -- not crash in the absence of /proc. */ -- -- support_become_root (); -- if (!support_can_chroot ()) -- return EXIT_UNSUPPORTED; -- -- temp_dir = support_create_temp_directory ("tst-freopen4"); -- -- struct support_capture_subprocess result; -- result = support_capture_subprocess (do_test_chroot, temp_dir); -- support_capture_subprocess_check (&result, "freopen4", 0, -- sc_allow_stdout); -- fputs (result.out.buffer, stdout); -- support_capture_subprocess_free (&result); -- - return 0; - } - - -commit c5476b7907d01207ede6bf57b26cef151b601f35 -Author: Samuel Thibault -Date: Fri Jul 18 23:14:40 2025 +0200 - - hurd: support: Fix running SGID tests - - Secure mode is enabled only if SGID actually provides a new privilege, - so we have to drop it before gaining it again. - - Fixes commit 3a3fb2ed83f79100c116c824454095ecfb335ad7 - ("Fix error reporting (false negatives) in SGID tests") - - (cherry picked from commit ad4589e2d834c80a042a8c354fb00cf33e06802c) - -diff --git a/support/support_capture_subprocess.c b/support/support_capture_subprocess.c -index b4e4bf9502..c89e65b534 100644 ---- a/support/support_capture_subprocess.c -+++ b/support/support_capture_subprocess.c -@@ -133,6 +133,27 @@ copy_and_spawn_sgid (const char *child_id, gid_t gid) - if (chmod (execname, 02750) != 0) - FAIL_UNSUPPORTED ("cannot make \"%s\" SGID: %m ", execname); - -+ /* Now we can drop the privilege of that group. */ -+ const int count = 64; -+ gid_t groups[count]; -+ int ngroups = getgroups(count, groups); -+ -+ if (ngroups < 0) -+ FAIL_UNSUPPORTED ("Could not get group list again for user %jd\n", -+ (intmax_t) getuid ()); -+ -+ int n = 0; -+ for (int i = 0; i < ngroups; i++) -+ { -+ if (groups[i] != gid) -+ { -+ if (n != i) -+ groups[n] = groups[i]; -+ n++; -+ } -+ } -+ setgroups (n, groups); -+ - /* We have the binary, now spawn the subprocess. Avoid using - support_subprogram because we only want the program exit status, not the - contents. */ - -commit 8a726b63047241c6dd4b55bf85eacd02244362a2 -Author: Wilco Dijkstra -Date: Thu Jul 10 15:49:14 2025 +0000 - - malloc: Remove redundant NULL check - - Remove a redundant NULL check from tcache_get_n. - - Reviewed-by: Cupertino Miranda - (cherry picked from commit 089b4fb90fac8ed53039bc4c465c4d333c6b4048) - -diff --git a/malloc/malloc.c b/malloc/malloc.c -index 5ca390cc22..cf5c02ff64 100644 ---- a/malloc/malloc.c -+++ b/malloc/malloc.c -@@ -3208,11 +3208,10 @@ tcache_get_n (size_t tc_idx, tcache_entry **ep, bool mangled) - if (__glibc_unlikely (misaligned_mem (e))) - malloc_printerr ("malloc(): unaligned tcache chunk detected"); - -- void *ne = e == NULL ? NULL : REVEAL_PTR (e->next); - if (!mangled) -- *ep = ne; -+ *ep = REVEAL_PTR (e->next); - else -- *ep = PROTECT_PTR (ep, ne); -+ *ep = PROTECT_PTR (ep, REVEAL_PTR (e->next)); - - ++(tcache->num_slots[tc_idx]); - e->key = 0; -@@ -3229,7 +3228,7 @@ tcache_put (mchunkptr chunk, size_t tc_idx) - static __always_inline void * - tcache_get (size_t tc_idx) - { -- return tcache_get_n (tc_idx, & tcache->entries[tc_idx], false); -+ return tcache_get_n (tc_idx, &tcache->entries[tc_idx], false); - } - - static __always_inline tcache_entry ** - -commit c491dabd8a3de090d1ccb4589421a44e79c5b185 -Author: Wilco Dijkstra -Date: Thu Jul 17 14:31:06 2025 +0000 - - malloc: Fix MAX_TCACHE_SMALL_SIZE - - MAX_TCACHE_SMALL_SIZE should use chunk size since it is used after - checked_request2size. Increase limit of tcache_max_bytes by 1 since all - comparisons use '<'. As a result, the last tcache entry is now used as - expected. - - Reviewed-by: DJ Delorie - (cherry picked from commit ad4caba4146583fc543cd434221dec7113c03e09) - -diff --git a/malloc/malloc.c b/malloc/malloc.c -index cf5c02ff64..b89b654f17 100644 ---- a/malloc/malloc.c -+++ b/malloc/malloc.c -@@ -294,9 +294,9 @@ - # define TCACHE_SMALL_BINS 64 - # define TCACHE_LARGE_BINS 12 /* Up to 4M chunks */ - # define TCACHE_MAX_BINS (TCACHE_SMALL_BINS + TCACHE_LARGE_BINS) --# define MAX_TCACHE_SMALL_SIZE tidx2usize (TCACHE_SMALL_BINS-1) -+# define MAX_TCACHE_SMALL_SIZE tidx2csize (TCACHE_SMALL_BINS-1) - --/* Only used to pre-fill the tunables. */ -+# define tidx2csize(idx) (((size_t) idx) * MALLOC_ALIGNMENT + MINSIZE) - # define tidx2usize(idx) (((size_t) idx) * MALLOC_ALIGNMENT + MINSIZE - SIZE_SZ) - - /* When "x" is from chunksize(). */ -@@ -1932,7 +1932,7 @@ static struct malloc_par mp_ = - , - .tcache_count = TCACHE_FILL_COUNT, - .tcache_small_bins = TCACHE_SMALL_BINS, -- .tcache_max_bytes = MAX_TCACHE_SMALL_SIZE, -+ .tcache_max_bytes = MAX_TCACHE_SMALL_SIZE + 1, - .tcache_unsorted_limit = 0 /* No limit. */ - #endif - }; -@@ -5586,15 +5586,13 @@ do_set_arena_max (size_t value) - static __always_inline int - do_set_tcache_max (size_t value) - { -+ if (value > PTRDIFF_MAX) -+ return 0; -+ - size_t nb = request2size (value); - size_t tc_idx = csize2tidx (nb); - -- /* To check that value is not too big and request2size does not return an -- overflown value. */ -- if (value > nb) -- return 0; -- -- if (nb > MAX_TCACHE_SMALL_SIZE) -+ if (tc_idx >= TCACHE_SMALL_BINS) - tc_idx = large_csize2tidx (nb); - - LIBC_PROBE (memory_tunable_tcache_max_bytes, 2, value, mp_.tcache_max_bytes); -@@ -5603,7 +5601,7 @@ do_set_tcache_max (size_t value) - { - if (tc_idx < TCACHE_SMALL_BINS) - mp_.tcache_small_bins = tc_idx + 1; -- mp_.tcache_max_bytes = nb; -+ mp_.tcache_max_bytes = nb + 1; - return 1; - } - - -commit a96a82c4a5efd3139e75cd11fd2a5554164dd5a0 -Author: Samuel Thibault -Date: Wed Jul 30 01:55:22 2025 +0200 - - malloc: Make sure tcache_key is odd enough - - We want tcache_key not to be a commonly-occurring value in memory, so ensure - a minimum amount of one and zero bits. - - And we need it non-zero, otherwise even if tcache_double_free_verify sets - e->key to 0 before calling __libc_free, it gets called again by __libc_free, - thus looping indefinitely. - - Fixes: c968fe50628db74b52124d863cd828225a1d305c ("malloc: Use tailcalls in __libc_free") - (cherry picked from commit 2536c4f8584082a1ac4c5e0a2a6222e290d43983) - -diff --git a/malloc/malloc.c b/malloc/malloc.c -index b89b654f17..e4e2f03600 100644 ---- a/malloc/malloc.c -+++ b/malloc/malloc.c -@@ -230,6 +230,9 @@ - /* For uintptr_t. */ - #include - -+/* For stdc_count_ones. */ -+#include -+ - /* For va_arg, va_start, va_end. */ - #include - -@@ -3152,6 +3155,19 @@ tcache_key_initialize (void) - if (__getrandom_nocancel_nostatus_direct (&tcache_key, sizeof(tcache_key), - GRND_NONBLOCK) - != sizeof (tcache_key)) -+ tcache_key = 0; -+ -+ /* We need tcache_key to be non-zero (otherwise tcache_double_free_verify's -+ clearing of e->key would go unnoticed and it would loop getting called -+ through __libc_free), and we want tcache_key not to be a -+ commonly-occurring value in memory, so ensure a minimum amount of one and -+ zero bits. */ -+ int minimum_bits = __WORDSIZE / 4; -+ int maximum_bits = __WORDSIZE - minimum_bits; -+ -+ while (labs (tcache_key) <= 0x1000000 -+ || stdc_count_ones (tcache_key) < minimum_bits -+ || stdc_count_ones (tcache_key) > maximum_bits) - { - tcache_key = random_bits (); - #if __WORDSIZE == 64 - -commit d7274d718e6f3655eabe311d4eb70fabb5ffa7ef -Author: Samuel Thibault -Date: Sun Aug 10 23:43:37 2025 +0200 - - malloc: Fix checking for small negative values of tcache_key - - tcache_key is unsigned so we should turn it explicitly to signed before - taking its absolute value. - - (cherry picked from commit 8543577b04ded6d979ffcc5a818930e4d74d0645) - -diff --git a/malloc/malloc.c b/malloc/malloc.c -index e4e2f03600..5f3e701fd1 100644 ---- a/malloc/malloc.c -+++ b/malloc/malloc.c -@@ -3165,7 +3165,7 @@ tcache_key_initialize (void) - int minimum_bits = __WORDSIZE / 4; - int maximum_bits = __WORDSIZE - minimum_bits; - -- while (labs (tcache_key) <= 0x1000000 -+ while (labs ((intptr_t) tcache_key) <= 0x1000000 - || stdc_count_ones (tcache_key) < minimum_bits - || stdc_count_ones (tcache_key) > maximum_bits) - { - -commit 8dbaecbe92ac7ab73b7d0aae84626af59131e41b -Author: Jens Remus -Date: Fri Jul 25 15:40:03 2025 +0200 - - Use TLS initial-exec model for __libc_tsd_CTYPE_* thread variables [BZ #33234] - - Commit 10a66a8e421b ("Remove ") removed the TLS initial-exec - (IE) model attribute from the __libc_tsd_CTYPE_* thread variable declarations - and definitions. Commit a894f04d8776 ("Optimize __libc_tsd_* thread - variable access") restored it on declarations. - - Restore the TLS initial-exec model attribute on __libc_tsd_CTYPE_* thread - variable definitions. - - This resolves test tst-locale1 failure on s390 32-bit, when using a - GNU linker without the fix from GNU binutils commit aefebe82dc89 - ("IBM zSystems: Fix offset relative to static TLS"). - - Reviewed-by: Florian Weimer - (cherry picked from commit e5363e6f460c2d58809bf10fc96d70fd1ef8b5b2) - -diff --git a/NEWS b/NEWS -index 1d04bdfef8..69aa600c6d 100644 ---- a/NEWS -+++ b/NEWS -@@ -11,6 +11,7 @@ The following bugs were resolved with this release: - - [31943] _dl_find_object can fail if ld.so contains gaps between load segments - [32994] stdlib: resolve a double lock init issue after fork -+ [33234] Use TLS initial-exec model for __libc_tsd_CTYPE_* thread variables - [33245] nptl: nptl: error in internal cancellation syscall handling - - Version 2.42 -diff --git a/ctype/ctype-info.c b/ctype/ctype-info.c -index b7d3422726..fb5acf9419 100644 ---- a/ctype/ctype-info.c -+++ b/ctype/ctype-info.c -@@ -24,11 +24,11 @@ - __ctype_init before user code runs, but this does not happen for - threads in secondary namespaces. With the initializers, secondary - namespaces at least get locale data from the C locale. */ --__thread const uint16_t * __libc_tsd_CTYPE_B -+__thread const uint16_t * __libc_tsd_CTYPE_B attribute_tls_model_ie - = (const uint16_t *) _nl_C_LC_CTYPE_class + 128; --__thread const int32_t * __libc_tsd_CTYPE_TOLOWER -+__thread const int32_t * __libc_tsd_CTYPE_TOLOWER attribute_tls_model_ie - = (const int32_t *) _nl_C_LC_CTYPE_tolower + 128; --__thread const int32_t * __libc_tsd_CTYPE_TOUPPER -+__thread const int32_t * __libc_tsd_CTYPE_TOUPPER attribute_tls_model_ie - = (const int32_t *) _nl_C_LC_CTYPE_toupper + 128; - - - -commit d0f72b96f2e91e1aa93f7e826c71f74078ada7d0 -Author: H.J. Lu -Date: Mon Jul 28 12:16:11 2025 -0700 - - i386: Add GLIBC_ABI_GNU_TLS version [BZ #33221] - - On i386, programs and shared libraries with __thread usage may fail - silently at run-time against glibc without the TLS run-time fix for: - - https://sourceware.org/bugzilla/show_bug.cgi?id=32996 - - Add GLIBC_ABI_GNU_TLS version to indicate that glibc has the working - GNU TLS run-time. Linker can add the GLIBC_ABI_GNU_TLS version to - binaries which depend on the working TLS run-time so that such programs - and shared libraries will fail to load and run at run-time against - libc.so without the GLIBC_ABI_GNU_TLS version, instead of fail silently - at random. - - This fixes BZ #33221. - - Signed-off-by: H.J. Lu - Reviewed-by: Sam James - (cherry picked from commit ed1b7a5a489ab555a27fad9c101ebe2e1c1ba881) - -diff --git a/sysdeps/i386/Makefile b/sysdeps/i386/Makefile -index ee6470d78e..c0c017b899 100644 ---- a/sysdeps/i386/Makefile -+++ b/sysdeps/i386/Makefile -@@ -60,6 +60,15 @@ $(objpfx)tst-ld-sse-use.out: ../sysdeps/i386/tst-ld-sse-use.sh $(objpfx)ld.so - @echo "Checking ld.so for SSE register use. This will take a few seconds..." - $(BASH) $< $(objpfx) '$(NM)' '$(OBJDUMP)' '$(READELF)' > $@; \ - $(evaluate-test) -+ -+tests-special += $(objpfx)check-gnu-tls.out -+ -+$(objpfx)check-gnu-tls.out: $(common-objpfx)libc.so -+ LC_ALL=C $(READELF) -V -W $< \ -+ | sed -ne '/.gnu.version_d/, /.gnu.version_r/ p' \ -+ | grep GLIBC_ABI_GNU_TLS > $@; \ -+ $(evaluate-test) -+generated += check-gnu-tls.out - else - CFLAGS-.os += $(if $(filter rtld-%.os,$(@F)), $(rtld-CFLAGS)) - endif -diff --git a/sysdeps/i386/Versions b/sysdeps/i386/Versions -index 36e23b466a..9c84c8ef04 100644 ---- a/sysdeps/i386/Versions -+++ b/sysdeps/i386/Versions -@@ -28,6 +28,11 @@ libc { - GLIBC_2.13 { - __fentry__; - } -+ GLIBC_ABI_GNU_TLS { -+ # This symbol is used only for empty version map and will be removed -+ # by scripts/versions.awk. -+ __placeholder_only_for_empty_version_map; -+ } - } - libm { - GLIBC_2.1 { - -commit 3970785bebcc3f1de4460072f3a041d178f64846 -Author: H.J. Lu -Date: Mon Jul 28 12:18:22 2025 -0700 - - x86-64: Add GLIBC_ABI_GNU2_TLS version [BZ #33129] - - Programs and shared libraries compiled with -mtls-dialect=gnu2 may fail - silently at run-time against glibc without the GNU2 TLS run-time fix - for: - - https://sourceware.org/bugzilla/show_bug.cgi?id=31372 - - Add GLIBC_ABI_GNU2_TLS version to indicate that glibc has the working - GNU2 TLS run-time. Linker can add the GLIBC_ABI_GNU2_TLS version to - binaries which depend on the working GNU2 TLS run-time: - - https://sourceware.org/bugzilla/show_bug.cgi?id=33130 - - so that such programs and shared libraries will fail to load and run at - run-time against libc.so without the GLIBC_ABI_GNU2_TLS version, instead - of fail silently at random. - - This fixes BZ #33129. - - Signed-off-by: H.J. Lu - Reviewed-by: Sam James - (cherry picked from commit 9df8fa397d515dc86ff5565f6c45625e672d539e) - -diff --git a/sysdeps/x86_64/Makefile b/sysdeps/x86_64/Makefile -index c3e1065c81..3ab8c1ed0f 100644 ---- a/sysdeps/x86_64/Makefile -+++ b/sysdeps/x86_64/Makefile -@@ -212,6 +212,15 @@ LDFLAGS-tst-plt-rewrite2 = -Wl,-z,now - LDFLAGS-tst-plt-rewritemod2.so = -Wl,-z,now,-z,undefs - tst-plt-rewrite2-ENV = GLIBC_TUNABLES=glibc.cpu.plt_rewrite=2 - $(objpfx)tst-plt-rewrite2: $(objpfx)tst-plt-rewritemod2.so -+ -+tests-special += $(objpfx)check-gnu2-tls.out -+ -+$(objpfx)check-gnu2-tls.out: $(common-objpfx)libc.so -+ LC_ALL=C $(READELF) -V -W $< \ -+ | sed -ne '/.gnu.version_d/, /.gnu.version_r/ p' \ -+ | grep GLIBC_ABI_GNU2_TLS > $@; \ -+ $(evaluate-test) -+generated += check-gnu2-tls.out - endif - - test-internal-extras += tst-gnu2-tls2mod1 -diff --git a/sysdeps/x86_64/Versions b/sysdeps/x86_64/Versions -index e94758b236..a63c11bcb2 100644 ---- a/sysdeps/x86_64/Versions -+++ b/sysdeps/x86_64/Versions -@@ -5,6 +5,11 @@ libc { - GLIBC_2.13 { - __fentry__; - } -+ GLIBC_ABI_GNU2_TLS { -+ # This symbol is used only for empty version map and will be removed -+ # by scripts/versions.awk. -+ __placeholder_only_for_empty_version_map; -+ } - } - libm { - GLIBC_2.1 { - -commit 7a8f3c6ee4b565a02da4ba0dad9aaeaeed4639ce -Author: H.J. Lu -Date: Thu Aug 14 07:03:20 2025 -0700 - - x86-64: Add GLIBC_ABI_DT_X86_64_PLT [BZ #33212] - - When the linker -z mark-plt option is used to add DT_X86_64_PLT, - DT_X86_64_PLTSZ and DT_X86_64_PLTENT, the r_addend field of the - R_X86_64_JUMP_SLOT relocation stores the offset of the indirect - branch instruction. However, glibc versions without the commit: - - commit f8587a61892cbafd98ce599131bf4f103466f084 - Author: H.J. Lu - Date: Fri May 20 19:21:48 2022 -0700 - - x86-64: Ignore r_addend for R_X86_64_GLOB_DAT/R_X86_64_JUMP_SLOT - - According to x86-64 psABI, r_addend should be ignored for R_X86_64_GLOB_DAT - and R_X86_64_JUMP_SLOT. Since linkers always set their r_addends to 0, we - can ignore their r_addends. - - Reviewed-by: Fangrui Song - - won't ignore the r_addend value in the R_X86_64_JUMP_SLOT relocation. - Such programs and shared libraries will fail at run-time randomly. - - Add GLIBC_ABI_DT_X86_64_PLT version to indicate that glibc is compatible - with DT_X86_64_PLT. - - The linker can add the glibc GLIBC_ABI_DT_X86_64_PLT version dependency - whenever -z mark-plt is passed to the linker. The resulting programs and - shared libraries will fail to load at run-time against libc.so without the - GLIBC_ABI_DT_X86_64_PLT version, instead of fail randomly. - - This fixes BZ #33212. - - Signed-off-by: H.J. Lu - Reviewed-by: Sam James - (cherry picked from commit 399384e0c8193e31aea014220ccfa24300ae5938) - -diff --git a/sysdeps/x86_64/Makefile b/sysdeps/x86_64/Makefile -index 3ab8c1ed0f..01100597a8 100644 ---- a/sysdeps/x86_64/Makefile -+++ b/sysdeps/x86_64/Makefile -@@ -213,6 +213,15 @@ LDFLAGS-tst-plt-rewritemod2.so = -Wl,-z,now,-z,undefs - tst-plt-rewrite2-ENV = GLIBC_TUNABLES=glibc.cpu.plt_rewrite=2 - $(objpfx)tst-plt-rewrite2: $(objpfx)tst-plt-rewritemod2.so - -+tests-special += $(objpfx)check-dt-x86-64-plt.out -+ -+$(objpfx)check-dt-x86-64-plt.out: $(common-objpfx)libc.so -+ LC_ALL=C $(READELF) -V -W $< \ -+ | sed -ne '/.gnu.version_d/, /.gnu.version_r/ p' \ -+ | grep GLIBC_ABI_DT_X86_64_PLT > $@; \ -+ $(evaluate-test) -+generated += check-dt-x86-64-plt.out -+ - tests-special += $(objpfx)check-gnu2-tls.out - - $(objpfx)check-gnu2-tls.out: $(common-objpfx)libc.so -diff --git a/sysdeps/x86_64/Versions b/sysdeps/x86_64/Versions -index a63c11bcb2..0a759029e5 100644 ---- a/sysdeps/x86_64/Versions -+++ b/sysdeps/x86_64/Versions -@@ -10,6 +10,11 @@ libc { - # by scripts/versions.awk. - __placeholder_only_for_empty_version_map; - } -+ GLIBC_ABI_DT_X86_64_PLT { -+ # This symbol is used only for empty version map and will be removed -+ # by scripts/versions.awk. -+ __placeholder_only_for_empty_version_map; -+ } - } - libm { - GLIBC_2.1 { - -commit e87844ec42b77363a499ea4da6c4a6ab85eba310 -Author: H.J. Lu -Date: Mon Aug 18 09:06:48 2025 -0700 - - i386: Also add GLIBC_ABI_GNU2_TLS version [BZ #33129] - - Since the GNU2 TLS run-time bug: - - https://sourceware.org/bugzilla/show_bug.cgi?id=31372 - - affects both i386 and x86-64, also add GLIBC_ABI_GNU2_TLS version to i386 - to indicate the working GNU2 TLS run-time. For x86-64, the additional - GNU2 TLS run-time bug fix is needed for - - https://sourceware.org/bugzilla/show_bug.cgi?id=31501 - - Signed-off-by: H.J. Lu - Reviewed-by: Sam James - (cherry picked from commit bd4628f3f18ac312408782eea450429c6f044860) - -diff --git a/sysdeps/x86/Makefile b/sysdeps/x86/Makefile -index 4fbd48e1c8..9e1c8cce85 100644 ---- a/sysdeps/x86/Makefile -+++ b/sysdeps/x86/Makefile -@@ -135,6 +135,15 @@ LDFLAGS-tst-tls23 += -rdynamic - tst-tls23-mod.so-no-z-defs = yes - - $(objpfx)tst-tls23-mod.so: $(libsupport) -+ -+tests-special += $(objpfx)check-gnu2-tls.out -+ -+$(objpfx)check-gnu2-tls.out: $(common-objpfx)libc.so -+ LC_ALL=C $(READELF) -V -W $< \ -+ | sed -ne '/.gnu.version_d/, /.gnu.version_r/ p' \ -+ | grep GLIBC_ABI_GNU2_TLS > $@; \ -+ $(evaluate-test) -+generated += check-gnu2-tls.out - endif - - ifeq ($(subdir),gmon) -diff --git a/sysdeps/x86/Versions b/sysdeps/x86/Versions -index 4b10c4b5d7..e8dcfccbe4 100644 ---- a/sysdeps/x86/Versions -+++ b/sysdeps/x86/Versions -@@ -7,4 +7,9 @@ libc { - GLIBC_2.33 { - __x86_get_cpuid_feature_leaf; - } -+ GLIBC_ABI_GNU2_TLS { -+ # This symbol is used only for empty version map and will be removed -+ # by scripts/versions.awk. -+ __placeholder_only_for_empty_version_map; -+ } - } -diff --git a/sysdeps/x86_64/Makefile b/sysdeps/x86_64/Makefile -index 01100597a8..fe9f1cdddb 100644 ---- a/sysdeps/x86_64/Makefile -+++ b/sysdeps/x86_64/Makefile -@@ -221,15 +221,6 @@ $(objpfx)check-dt-x86-64-plt.out: $(common-objpfx)libc.so - | grep GLIBC_ABI_DT_X86_64_PLT > $@; \ - $(evaluate-test) - generated += check-dt-x86-64-plt.out -- --tests-special += $(objpfx)check-gnu2-tls.out -- --$(objpfx)check-gnu2-tls.out: $(common-objpfx)libc.so -- LC_ALL=C $(READELF) -V -W $< \ -- | sed -ne '/.gnu.version_d/, /.gnu.version_r/ p' \ -- | grep GLIBC_ABI_GNU2_TLS > $@; \ -- $(evaluate-test) --generated += check-gnu2-tls.out - endif - - test-internal-extras += tst-gnu2-tls2mod1 -diff --git a/sysdeps/x86_64/Versions b/sysdeps/x86_64/Versions -index 0a759029e5..6a989ad3b3 100644 ---- a/sysdeps/x86_64/Versions -+++ b/sysdeps/x86_64/Versions -@@ -5,11 +5,6 @@ libc { - GLIBC_2.13 { - __fentry__; - } -- GLIBC_ABI_GNU2_TLS { -- # This symbol is used only for empty version map and will be removed -- # by scripts/versions.awk. -- __placeholder_only_for_empty_version_map; -- } - GLIBC_ABI_DT_X86_64_PLT { - # This symbol is used only for empty version map and will be removed - # by scripts/versions.awk. - -commit e34453cd6a8c592c325756ff3c7ac0afd3975cb4 -Author: Pierre Blanchard -Date: Wed Aug 20 17:41:50 2025 +0000 - - AArch64: Fix SVE powf routine [BZ #33299] - - Fix a bug in predicate logic introduced in last change. - A slight performance improvement from relying on all true - predicates during conversion from single to double. - This fixes BZ #33299. - - Reviewed-by: Wilco Dijkstra - (cherry picked from commit aac077645a645bba0d67f3250e82017c539d0f4b) - -diff --git a/sysdeps/aarch64/fpu/powf_sve.c b/sysdeps/aarch64/fpu/powf_sve.c -index 7046990aa1..65e9bd29d9 100644 ---- a/sysdeps/aarch64/fpu/powf_sve.c -+++ b/sysdeps/aarch64/fpu/powf_sve.c -@@ -223,15 +223,15 @@ sv_powf_core (const svbool_t pg, svuint32_t i, svuint32_t iz, svint32_t k, - const svbool_t ptrue = svptrue_b64 (); - - /* Unpack and promote input vectors (pg, y, z, i, k and sign_bias) into two -- * in order to perform core computation in double precision. */ -+ in order to perform core computation in double precision. */ - const svbool_t pg_lo = svunpklo (pg); - const svbool_t pg_hi = svunpkhi (pg); -- svfloat64_t y_lo -- = svcvt_f64_x (pg, svreinterpret_f32 (svunpklo (svreinterpret_u32 (y)))); -- svfloat64_t y_hi -- = svcvt_f64_x (pg, svreinterpret_f32 (svunpkhi (svreinterpret_u32 (y)))); -- svfloat64_t z_lo = svcvt_f64_x (pg, svreinterpret_f32 (svunpklo (iz))); -- svfloat64_t z_hi = svcvt_f64_x (pg, svreinterpret_f32 (svunpkhi (iz))); -+ svfloat64_t y_lo = svcvt_f64_x ( -+ ptrue, svreinterpret_f32 (svunpklo (svreinterpret_u32 (y)))); -+ svfloat64_t y_hi = svcvt_f64_x ( -+ ptrue, svreinterpret_f32 (svunpkhi (svreinterpret_u32 (y)))); -+ svfloat64_t z_lo = svcvt_f64_x (ptrue, svreinterpret_f32 (svunpklo (iz))); -+ svfloat64_t z_hi = svcvt_f64_x (ptrue, svreinterpret_f32 (svunpkhi (iz))); - svuint64_t i_lo = svunpklo (i); - svuint64_t i_hi = svunpkhi (i); - svint64_t k_lo = svunpklo (k); -@@ -312,7 +312,7 @@ svfloat32_t SV_NAME_F2 (pow) (svfloat32_t x, svfloat32_t y, const svbool_t pg) - (23 - V_POWF_EXP2_TABLE_BITS)); - - /* Compute core in extended precision and return intermediate ylogx results -- * to handle cases of underflow and underflow in exp. */ -+ to handle cases of underflow and overflow in exp. */ - svfloat32_t ylogx; - svfloat32_t ret - = sv_powf_core (yint_or_xpos, i, iz, k, y, sign_bias, &ylogx, d); - -commit 1166170d95863e5a6f8121a5ca9d97713f524f49 -Author: Florian Weimer -Date: Fri Sep 5 19:02:57 2025 +0200 - - libio: Define AT_RENAME_* with the same tokens as Linux - - Linux uses different expressions for the RENAME_* and AT_RENAME_* - constants. Mirror that in , so that the macro redefinitions - do not result in preprocessor warnings. - - Reviewed-by: Collin Funk - (cherry picked from commit b173557da978a04ac3bdfc0bd3b0e7ac583b44d5) - -diff --git a/libio/stdio.h b/libio/stdio.h -index d042b36618..e0e70945fa 100644 ---- a/libio/stdio.h -+++ b/libio/stdio.h -@@ -168,11 +168,11 @@ extern int renameat (int __oldfd, const char *__old, int __newfd, - #ifdef __USE_GNU - /* Flags for renameat2. */ - # define RENAME_NOREPLACE (1 << 0) --# define AT_RENAME_NOREPLACE RENAME_NOREPLACE -+# define AT_RENAME_NOREPLACE 0x0001 - # define RENAME_EXCHANGE (1 << 1) --# define AT_RENAME_EXCHANGE RENAME_EXCHANGE -+# define AT_RENAME_EXCHANGE 0x0002 - # define RENAME_WHITEOUT (1 << 2) --# define AT_RENAME_WHITEOUT RENAME_WHITEOUT -+# define AT_RENAME_WHITEOUT 0x0004 - - /* Rename file OLD relative to OLDFD to NEW relative to NEWFD, with - additional flags. */ -diff --git a/stdio-common/tst-renameat2.c b/stdio-common/tst-renameat2.c -index 12aa0f8b0f..6213e1376d 100644 ---- a/stdio-common/tst-renameat2.c -+++ b/stdio-common/tst-renameat2.c -@@ -28,6 +28,12 @@ - #include - #include - -+/* These constants are defined with different token sequences, -+ matching the Linux definitions, to avoid preprocessor warnings. */ -+_Static_assert (RENAME_NOREPLACE == AT_RENAME_NOREPLACE, "RENAME_NOREPLACE"); -+_Static_assert (RENAME_EXCHANGE == AT_RENAME_EXCHANGE, "RENAME_EXCHANGE"); -+_Static_assert (RENAME_WHITEOUT == AT_RENAME_WHITEOUT, "RENAME_WHITEOUT"); -+ - /* Directory with the temporary files. */ - static char *directory; - static int directory_fd; - -commit 46b4e37c9e0619d0cf065ba207c29996b326a06f -Author: Florian Weimer -Date: Fri Sep 12 21:33:34 2025 +0200 - - nss: Group merge does not react to ERANGE during merge (bug 33361) - - The break statement in CHECK_MERGE is expected to exit the surrounding - while loop, not the do-while loop with in the macro. Remove the - do-while loop from the macro. It is not needed to turn the macro - expansion into a single statement due to the way CHECK_MERGE is used - (and the statement expression would cover this anyway). - - Reviewed-by: Collin Funk - (cherry picked from commit 0fceed254559836b57ee05188deac649bc505d05) - -diff --git a/NEWS b/NEWS -index 69aa600c6d..06c27a8e17 100644 ---- a/NEWS -+++ b/NEWS -@@ -13,6 +13,7 @@ The following bugs were resolved with this release: - [32994] stdlib: resolve a double lock init issue after fork - [33234] Use TLS initial-exec model for __libc_tsd_CTYPE_* thread variables - [33245] nptl: nptl: error in internal cancellation syscall handling -+ [33361] nss: Group merge does not react to ERANGE during merge - - Version 2.42 - -diff --git a/nss/getXXbyYY_r.c b/nss/getXXbyYY_r.c -index eae6c3480e..2b0735fb6a 100644 ---- a/nss/getXXbyYY_r.c -+++ b/nss/getXXbyYY_r.c -@@ -157,19 +157,15 @@ __merge_einval (LOOKUP_TYPE *a, - - #define CHECK_MERGE(err, status) \ - ({ \ -- do \ -+ if (err) \ - { \ -- if (err) \ -- { \ -- __set_errno (err); \ -- if (err == ERANGE) \ -- status = NSS_STATUS_TRYAGAIN; \ -- else \ -- status = NSS_STATUS_UNAVAIL; \ -- break; \ -- } \ -+ __set_errno (err); \ -+ if (err == ERANGE) \ -+ status = NSS_STATUS_TRYAGAIN; \ -+ else \ -+ status = NSS_STATUS_UNAVAIL; \ -+ break; \ - } \ -- while (0); \ - }) - - /* Type of the lookup function we need here. */ - -commit 18fd689cdced8348e42991964557cddea0ba2dc5 -Author: Adhemerval Zanella -Date: Mon Sep 8 13:06:13 2025 -0300 - - nptl: Fix MADV_GUARD_INSTALL logic for thread without guard page (BZ 33356) - - The main issue is that setup_stack_prot fails to account for cases where - the cached thread stack lacks a guard page, which can cause madvise to - fail. Update the logic to also handle whether MADV_GUARD_INSTALL is - supported when resizing the guard page. - - Checked on x86_64-linux-gnu with 6.8.0 and 6.15 kernels. - - Reviewed-by: Florian Weimer - (cherry picked from commit 855bfa2566bbefefa27c516b344df58a75824a5c) - -diff --git a/NEWS b/NEWS -index 06c27a8e17..ed3c114c7a 100644 ---- a/NEWS -+++ b/NEWS -@@ -13,6 +13,8 @@ The following bugs were resolved with this release: - [32994] stdlib: resolve a double lock init issue after fork - [33234] Use TLS initial-exec model for __libc_tsd_CTYPE_* thread variables - [33245] nptl: nptl: error in internal cancellation syscall handling -+ [33356] nptl: creating thread stack with guardsize 0 can erroneously -+ conclude MADV_GUARD_INSTALL is available - [33361] nss: Group merge does not react to ERANGE during merge - - Version 2.42 -diff --git a/nptl/allocatestack.c b/nptl/allocatestack.c -index 800ca89720..fb8a60a21d 100644 ---- a/nptl/allocatestack.c -+++ b/nptl/allocatestack.c -@@ -240,7 +240,7 @@ setup_stack_prot (char *mem, size_t size, struct pthread *pd, - /* Update the guard area of the thread stack MEM of size SIZE with the new - GUARDISZE. It uses the method defined by PD stack_mode. */ - static inline bool --adjust_stack_prot (char *mem, size_t size, const struct pthread *pd, -+adjust_stack_prot (char *mem, size_t size, struct pthread *pd, - size_t guardsize, size_t pagesize_m1) - { - /* The required guard area is larger than the current one. For -@@ -258,11 +258,23 @@ adjust_stack_prot (char *mem, size_t size, const struct pthread *pd, - so use the new guard placement with the new size. */ - if (guardsize > pd->guardsize) - { -+ /* There was no need to previously setup a guard page, so we need -+ to check whether the kernel supports guard advise. */ - char *guard = guard_position (mem, size, guardsize, pd, pagesize_m1); -- if (pd->stack_mode == ALLOCATE_GUARD_MADV_GUARD) -- return __madvise (guard, guardsize, MADV_GUARD_INSTALL) == 0; -- else if (pd->stack_mode == ALLOCATE_GUARD_PROT_NONE) -- return __mprotect (guard, guardsize, PROT_NONE) == 0; -+ if (atomic_load_relaxed (&allocate_stack_mode) -+ == ALLOCATE_GUARD_MADV_GUARD) -+ { -+ if (__madvise (guard, guardsize, MADV_GUARD_INSTALL) == 0) -+ { -+ pd->stack_mode = ALLOCATE_GUARD_MADV_GUARD; -+ return true; -+ } -+ atomic_store_relaxed (&allocate_stack_mode, -+ ALLOCATE_GUARD_PROT_NONE); -+ } -+ -+ pd->stack_mode = ALLOCATE_GUARD_PROT_NONE; -+ return __mprotect (guard, guardsize, PROT_NONE) == 0; - } - /* The current guard area is larger than the required one. For - _STACK_GROWS_DOWN is means change the guard as: -diff --git a/nptl/tst-guard1.c b/nptl/tst-guard1.c -index e3e06df0fc..1c73d3fc93 100644 ---- a/nptl/tst-guard1.c -+++ b/nptl/tst-guard1.c -@@ -21,6 +21,7 @@ - #include - #include - #include -+#include - #include - #include - #include -@@ -202,7 +203,7 @@ tf (void *closure) - - /* Test 1: caller provided stack without guard. */ - static void --do_test1 (void) -+do_test1 (void *closure) - { - pthread_attr_t attr; - xpthread_attr_init (&attr); -@@ -227,7 +228,7 @@ do_test1 (void) - - /* Test 2: same as 1., but with a guard area. */ - static void --do_test2 (void) -+do_test2 (void *closure) - { - pthread_attr_t attr; - xpthread_attr_init (&attr); -@@ -250,18 +251,9 @@ do_test2 (void) - xmunmap (stack, stacksize); - } - --/* Test 3: pthread_create with default values. */ -+/* Test 3: pthread_create without a guard area. */ - static void --do_test3 (void) --{ -- pthread_t t = xpthread_create (NULL, tf, NULL); -- void *status = xpthread_join (t); -- TEST_VERIFY (status == 0); --} -- --/* Test 4: pthread_create without a guard area. */ --static void --do_test4 (void) -+do_test3 (void *closure) - { - pthread_attr_t attr; - xpthread_attr_init (&attr); -@@ -277,9 +269,18 @@ do_test4 (void) - xpthread_attr_destroy (&attr); - } - -+/* Test 4: pthread_create with default values. */ -+static void -+do_test4 (void *closure) -+{ -+ pthread_t t = xpthread_create (NULL, tf, NULL); -+ void *status = xpthread_join (t); -+ TEST_VERIFY (status == 0); -+} -+ - /* Test 5: pthread_create with non default stack and guard size value. */ - static void --do_test5 (void) -+do_test5 (void *closure) - { - pthread_attr_t attr; - xpthread_attr_init (&attr); -@@ -299,7 +300,7 @@ do_test5 (void) - test 3, but with a larger guard area. The pthread_create will need to - increase the guard area. */ - static void --do_test6 (void) -+do_test6 (void *closure) - { - pthread_attr_t attr; - xpthread_attr_init (&attr); -@@ -320,7 +321,7 @@ do_test6 (void) - pthread_create should use the cached stack from previous tests, but it - would require to reduce the guard area. */ - static void --do_test7 (void) -+do_test7 (void *closure) - { - pthread_t t = xpthread_create (NULL, tf, NULL); - void *status = xpthread_join (t); -@@ -346,21 +347,40 @@ do_test (void) - - static const struct { - const char *descr; -- void (*test)(void); -+ void (*test) (void *); - } tests[] = { - { "user provided stack without guard", do_test1 }, - { "user provided stack with guard", do_test2 }, -- { "default attribute", do_test3 }, -- { "default attribute without guard", do_test4 }, -+ /* N.B: do_test3 should be before do_test4 to check if a new thread -+ that uses the thread stack previously allocated without a guard -+ page correctly sets up the guard pages even on a kernel without -+ MADV_GUARD_INSTALL support (BZ 33356). */ -+ { "default attribute without guard", do_test3 }, -+ { "default attribute", do_test4 }, -+ /* Also checks if the guard is correctly removed from the cache thread -+ stack. */ -+ { "default attribute without guard", do_test3 }, - { "non default stack and guard sizes", do_test5 }, - { "reused stack with larger guard", do_test6 }, - { "reused stack with smaller guard", do_test7 }, - }; - -+ /* Run each test with a clean state. */ -+ for (int i = 0; i < array_length (tests); i++) -+ { -+ printf ("debug: fork: test%01d: %s\n", i, tests[i].descr); -+ struct support_capture_subprocess result = -+ support_capture_subprocess (tests[i].test, NULL); -+ support_capture_subprocess_check (&result, tests[i].descr, 0, -+ sc_allow_none); -+ support_capture_subprocess_free (&result); -+ } -+ -+ /* And now run the same tests along with the thread stack cache. */ - for (int i = 0; i < array_length (tests); i++) - { - printf ("debug: test%01d: %s\n", i, tests[i].descr); -- tests[i].test(); -+ tests[i].test ( NULL); - } - - return 0; - -commit bf48b17a28066a54f172e0d63da9fc5dc60c6355 -Author: Sunil K Pandey -Date: Mon Oct 6 18:13:04 2025 -0700 - - x86: Detect Intel Wildcat Lake Processor - - Detect Intel Wildcat Lake Processor and tune it similar to Intel Panther - Lake. https://cdrdv2.intel.com/v1/dl/getContent/671368 Section 1.2. - - Reviewed-by: H.J. Lu - (cherry picked from commit f8dd52901b72805a831d5a4cb7d971e4a3c9970b) - -diff --git a/sysdeps/x86/cpu-features.c b/sysdeps/x86/cpu-features.c -index b7d1506135..4bdade883e 100644 ---- a/sysdeps/x86/cpu-features.c -+++ b/sysdeps/x86/cpu-features.c -@@ -543,6 +543,7 @@ enum intel_microarch - INTEL_BIGCORE_PANTHERLAKE, - INTEL_BIGCORE_GRANITERAPIDS, - INTEL_BIGCORE_DIAMONDRAPIDS, -+ INTEL_BIGCORE_WILDCATLAKE, - - /* Mixed (bigcore + atom SOC). */ - INTEL_MIXED_LAKEFIELD, -@@ -702,6 +703,8 @@ intel_get_fam6_microarch (unsigned int model, - return INTEL_BIGCORE_ARROWLAKE; - case 0xCC: - return INTEL_BIGCORE_PANTHERLAKE; -+ case 0xD5: -+ return INTEL_BIGCORE_WILDCATLAKE; - case 0xAD: - case 0xAE: - return INTEL_BIGCORE_GRANITERAPIDS; -@@ -934,6 +937,7 @@ disable_tsx: - case INTEL_BIGCORE_LUNARLAKE: - case INTEL_BIGCORE_ARROWLAKE: - case INTEL_BIGCORE_PANTHERLAKE: -+ case INTEL_BIGCORE_WILDCATLAKE: - case INTEL_BIGCORE_SAPPHIRERAPIDS: - case INTEL_BIGCORE_EMERALDRAPIDS: - case INTEL_BIGCORE_GRANITERAPIDS: - -commit ab8c1b5d62d7be2c3c23f535bea3d7fff19c53ae -Author: Sunil K Pandey -Date: Wed Sep 24 09:38:17 2025 -0700 - - x86: Detect Intel Nova Lake Processor - - Detect Intel Nova Lake Processor and tune it similar to Intel Panther - Lake. https://cdrdv2.intel.com/v1/dl/getContent/671368 Section 1.2. - - Reviewed-by: H.J. Lu - (cherry picked from commit a114e29ddd530962d2b44aa9d89f1f6075abe7fa) - -diff --git a/sysdeps/x86/cpu-features.c b/sysdeps/x86/cpu-features.c -index 4bdade883e..b67ef541dd 100644 ---- a/sysdeps/x86/cpu-features.c -+++ b/sysdeps/x86/cpu-features.c -@@ -544,6 +544,7 @@ enum intel_microarch - INTEL_BIGCORE_GRANITERAPIDS, - INTEL_BIGCORE_DIAMONDRAPIDS, - INTEL_BIGCORE_WILDCATLAKE, -+ INTEL_BIGCORE_NOVALAKE, - - /* Mixed (bigcore + atom SOC). */ - INTEL_MIXED_LAKEFIELD, -@@ -821,6 +822,17 @@ disable_tsx: - break; - } - } -+ else if (family == 18) -+ switch (model) -+ { -+ case 0x01: -+ case 0x03: -+ microarch = INTEL_BIGCORE_NOVALAKE; -+ break; -+ -+ default: -+ break; -+ } - else if (family == 19) - switch (model) - { -@@ -938,6 +950,7 @@ disable_tsx: - case INTEL_BIGCORE_ARROWLAKE: - case INTEL_BIGCORE_PANTHERLAKE: - case INTEL_BIGCORE_WILDCATLAKE: -+ case INTEL_BIGCORE_NOVALAKE: - case INTEL_BIGCORE_SAPPHIRERAPIDS: - case INTEL_BIGCORE_EMERALDRAPIDS: - case INTEL_BIGCORE_GRANITERAPIDS: - -commit 6de12fc9ad56bc19fa6fcbd8ee502f29b5170d47 -Author: Yury Khrustalev -Date: Thu Sep 25 15:51:30 2025 +0100 - - aarch64: define macro for calling __libc_arm_za_disable - - A common sequence of instructions is used in several places - in assembly files, so define it in one place as an assembly - macro. - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit b4b713bd8921aff04773557da94fabb5fb9dd705) - -diff --git a/sysdeps/aarch64/__longjmp.S b/sysdeps/aarch64/__longjmp.S -index 70ac02c44b..53b42e1bdc 100644 ---- a/sysdeps/aarch64/__longjmp.S -+++ b/sysdeps/aarch64/__longjmp.S -@@ -26,16 +26,8 @@ - ENTRY (__longjmp) - - #if IS_IN(libc) -- /* Disable ZA state of SME in libc.a and libc.so, but not in ld.so. -- The calling convention of __libc_arm_za_disable allows to do -- this thus allowing to avoid saving to and reading from stack. -- As a result we also don't need to sign the return address and -- check it after returning because it is not stored to stack. */ -- mov x13, x30 -- cfi_register (x30, x13) -- bl __libc_arm_za_disable -- mov x30, x13 -- cfi_register (x13, x30) -+ /* Disable ZA state of SME in libc.a and libc.so, but not in ld.so. */ -+ CALL_LIBC_ARM_ZA_DISABLE - #endif - - cfi_def_cfa (x0, 0) -diff --git a/sysdeps/aarch64/setjmp.S b/sysdeps/aarch64/setjmp.S -index 53c5e7d8cc..92cedfad83 100644 ---- a/sysdeps/aarch64/setjmp.S -+++ b/sysdeps/aarch64/setjmp.S -@@ -37,16 +37,8 @@ ENTRY_ALIGN (__sigsetjmp, 2) - 1: - - #if IS_IN(libc) -- /* Disable ZA state of SME in libc.a and libc.so, but not in ld.so. -- The calling convention of __libc_arm_za_disable allows to do -- this thus allowing to avoid saving to and reading from stack. -- As a result we also don't need to sign the return address and -- check it after returning because it is not stored to stack. */ -- mov x13, x30 -- cfi_register (x30, x13) -- bl __libc_arm_za_disable -- mov x30, x13 -- cfi_register (x13, x30) -+ /* Disable ZA state of SME in libc.a and libc.so, but not in ld.so. */ -+ CALL_LIBC_ARM_ZA_DISABLE - #endif - - stp x19, x20, [x0, #JB_X19<<3] -diff --git a/sysdeps/unix/sysv/linux/aarch64/setcontext.S b/sysdeps/unix/sysv/linux/aarch64/setcontext.S -index d9716f012e..8e98594663 100644 ---- a/sysdeps/unix/sysv/linux/aarch64/setcontext.S -+++ b/sysdeps/unix/sysv/linux/aarch64/setcontext.S -@@ -49,15 +49,7 @@ ENTRY (__setcontext) - b C_SYMBOL_NAME (__syscall_error) - 1: - /* Clear ZA state of SME. */ -- /* The calling convention of __libc_arm_za_disable allows to do -- this thus allowing to avoid saving to and reading from stack. -- As a result we also don't need to sign the return address and -- check it after returning because it is not stored to stack. */ -- mov x13, x30 -- cfi_register (x30, x13) -- bl __libc_arm_za_disable -- mov x30, x13 -- cfi_register (x13, x30) -+ CALL_LIBC_ARM_ZA_DISABLE - /* Restore the general purpose registers. */ - mov x0, x9 - cfi_def_cfa (x0, 0) -diff --git a/sysdeps/unix/sysv/linux/aarch64/sysdep.h b/sysdeps/unix/sysv/linux/aarch64/sysdep.h -index f0e8d64eef..fa01386b25 100644 ---- a/sysdeps/unix/sysv/linux/aarch64/sysdep.h -+++ b/sysdeps/unix/sysv/linux/aarch64/sysdep.h -@@ -150,6 +150,18 @@ - mov x8, SYS_ify (syscall_name); \ - svc 0 - -+/* Clear ZA state of SME (ASM version). */ -+/* The __libc_arm_za_disable function has special calling convention -+ that allows to call it without stack manipulation and preserving -+ most of the registers. */ -+ .macro CALL_LIBC_ARM_ZA_DISABLE -+ mov x13, x30 -+ .cfi_register x30, x13 -+ bl __libc_arm_za_disable -+ mov x30, x13 -+ .cfi_register x13, x30 -+ .endm -+ - #else /* not __ASSEMBLER__ */ - - # define VDSO_NAME "LINUX_2.6.39" - -commit 256030b9842a10b1f22851b1de0c119761417544 -Author: Yury Khrustalev -Date: Thu Sep 25 15:54:36 2025 +0100 - - aarch64: clear ZA state of SME before clone and clone3 syscalls - - This change adds a call to the __arm_za_disable() function immediately - before the SVC instruction inside clone() and clone3() wrappers. It also - adds a macro for inline clone() used in fork() and adds the same call to - the vfork implementation. This sets the ZA state of SME to "off" on return - from these functions (for both the child and the parent). - - The __arm_za_disable() function is described in [1] (8.1.3). Note that - the internal Glibc name for this function is __libc_arm_za_disable(). - - When this change was originally proposed [2,3], it generated a long - discussion where several questions and concerns were raised. Here we - will address these concerns and explain why this change is useful and, - in fact, necessary. - - In a nutshell, a C library that conforms to the AAPCS64 spec [1] (pertinent - to this change, mainly, the chapters 6.2 and 6.6), should have a call to the - __arm_za_disable() function in clone() and clone3() wrappers. The following - explains in detail why this is the case. - - When we consider using the __arm_za_disable() function inside the clone() - and clone3() libc wrappers, we talk about the C library subroutines clone() - and clone3() rather than the syscalls with similar names. In the current - version of Glibc, clone() is public and clone3() is private, but it being - private is not pertinent to this discussion. - - We will begin with stating that this change is NOT a bug fix for something - in the kernel. The requirement to call __arm_za_disable() does NOT come from - the kernel. It also is NOT needed to satisfy a contract between the kernel - and userspace. This is why it is not for the kernel documentation to describe - this requirement. This requirement is instead needed to satisfy a pure userspace - scheme outlined in [1] and to make sure that software that uses Glibc (or any - other C library that has correct handling of SME states (see below)) conforms - to [1] without having to unnecessarily become SME-aware thus losing portability. - - To recap (see [1] (6.2)), SME extension defines SME state which is part of - processor state. Part of this SME state is ZA state that is necessary to - manage ZA storage register in the context of the ZA lazy saving scheme [1] - (6.6). This scheme exists because it would be challenging to handle ZA - storage of SME in either callee-saved or caller-saved manner. - - There are 3 kinds of ZA state that are defined in terms of the PSTATE.ZA - bit and the TPIDR2_EL0 register (see [1] (6.6.3)): - - - "off":       PSTATE.ZA == 0 - - "active":    PSTATE.ZA == 1 TPIDR2_EL0 == null - - "dormant":   PSTATE.ZA == 1 TPIDR2_EL0 != null - - As [1] (6.7.2) outlines, every subroutine has exactly one SME-interface - depending on the permitted ZA-states on entry and on normal return from - a call to this subroutine. Callers of a subroutine must know and respect - the ZA-interface of the subroutines they are using. Using a subroutine - in a way that is not permitted by its ZA-interface is undefined behaviour. - - In particular, clone() and clone3() (the C library functions) have the - ZA-private interface. This means that the permitted ZA-states on entry - are "off" and "dormant" and that the permitted states on return are "off" - or "dormant" (but if and only if it was "dormant" on entry). - - This means that both functions in question should correctly handle both - "off" and "dormant" ZA-states on entry. The conforming states on return - are "off" and "dormant" (if inbound state was already "dormant"). - - This change ensures that the ZA-state on return is always "off". Note, - that, in the context of clone() and clone3(), "on return" means a point - when execution resumes at certain address after transferring from clone() - or clone3(). For the caller (we may refer to it as "parent") this is the - return address in the link register where the RET instruction jumps. For - the "child", this is the target branch address. - - So, the "off" state on return is permitted and conformant. Why can't we - retain the "dormant" state? In theory, we can, but we shouldn't, here is - why. - - Every subroutine with a private-ZA interface, including clone() and clone3(), - must comply with the lazy saving scheme [1] (6.7.2). This puts additional - responsibility on a subroutine if ZA-state on return is "dormant" because - this state has special meaning. The "caller" (that is the place in code - where execution is transferred to, so this include both "parent" and "child") - may check the ZA-state and use it as per the spec of the "dormant" state that - is outlined in [1] (6.6.6 and 6.6.7). - - Conforming to this would require more code inside of clone() and clone3() - which hardly is desirable. - - For the return to "parent" this could be achieved in theory, but given that - neither clone() nor clone3() are supposed to be used in the middle of an - SME operation, if wouldn't be useful. For the "return" to "child" this - would be particularly difficult to achieve given the complexity of these - functions and their interfaces. Most importantly, it would be illegal - and somewhat meaningless to allow a "child" to start execution in the - "dormant" ZA-state because the very essence of the "dormant" state implies - that there is a place to return and that there is some outer context that - we are allowed to interact with. - - To sum up, calling __arm_za_disable() to ensure the "off" ZA-state when the - execution resumes after a call to clone() or clone3() is correct and also - the most simple way to conform to [1]. - - Can there be situations when we can avoid calling __arm_za_disable()? - - Calling __arm_za_disable() implies certain (sufficiently small) overhead, - so one might rightly ponder avoiding making a call to this function when - we can afford not to. The most trivial cases like this (e.g. when the - calling thread doesn't have access to SME or to the TPIDR2_EL0 register) - are already handled by this function (see [1] (8.1.3 and 8.1.2)). Reasoning - about other possible use cases would require making code inside clone() and - clone3() more complicated and it would defeat the point of trying to make - an optimisation of not calling __arm_za_disable(). - - Why can't the kernel do this instead? - - The handling of SME state by the kernel is described in [4]. In short, - kernel must not impose a specific ZA-interface onto a userspace function. - Interaction with the kernel happens (among other thing) via system calls. - In Glibc many of the system calls (notably, including SYS_clone and - SYS_clone3) are used via wrappers, and the kernel has no control of them - and, moreover, it cannot dictate how these wrappers should behave because - it is simply outside of the kernel's remit. - - However, in certain cases, the kernel may ensure that a "child" doesn't - start in an incorrect state. This is what is done by the recent change - included in 6.16 kernel [5]. This is not enough to ensure that code that - uses clone() and clone3() function conforms to [1] when it runs on a - system that provides SME, hence this change. - - [1]: https://github.com/ARM-software/abi-aa/blob/main/aapcs64/aapcs64.rst - [2]: https://inbox.sourceware.org/libc-alpha/20250522114828.2291047-1-yury.khrustalev@arm.com - [3]: https://inbox.sourceware.org/libc-alpha/20250609121407.3316070-1-yury.khrustalev@arm.com - [4]: https://www.kernel.org/doc/html/v6.16/arch/arm64/sme.html - [5]: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=cde5c32db55740659fca6d56c09b88800d88fd29 - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 27effb3d50424fb9634be77a2acd614b0386ff25) - -diff --git a/sysdeps/unix/sysv/linux/aarch64/clone.S b/sysdeps/unix/sysv/linux/aarch64/clone.S -index 40015c6933..53f1efd728 100644 ---- a/sysdeps/unix/sysv/linux/aarch64/clone.S -+++ b/sysdeps/unix/sysv/linux/aarch64/clone.S -@@ -45,6 +45,9 @@ ENTRY(__clone) - and x1, x1, -16 - cbz x1, .Lsyscall_error - -+ /* Clear ZA state of SME. */ -+ CALL_LIBC_ARM_ZA_DISABLE -+ - /* Do the system call. */ - /* X0:flags, x1:newsp, x2:parenttidptr, x3:newtls, x4:childtid. */ - mov x0, x2 /* flags */ -diff --git a/sysdeps/unix/sysv/linux/aarch64/clone3.S b/sysdeps/unix/sysv/linux/aarch64/clone3.S -index c9ca845ef2..bc978b7e10 100644 ---- a/sysdeps/unix/sysv/linux/aarch64/clone3.S -+++ b/sysdeps/unix/sysv/linux/aarch64/clone3.S -@@ -46,6 +46,9 @@ ENTRY(__clone3) - cbz x10, .Lsyscall_error /* No NULL cl_args pointer. */ - cbz x2, .Lsyscall_error /* No NULL function pointer. */ - -+ /* Clear ZA state of SME. */ -+ CALL_LIBC_ARM_ZA_DISABLE -+ - /* Do the system call, the kernel expects: - x8: system call number - x0: cl_args -diff --git a/sysdeps/unix/sysv/linux/aarch64/sysdep.h b/sysdeps/unix/sysv/linux/aarch64/sysdep.h -index fa01386b25..30003c0145 100644 ---- a/sysdeps/unix/sysv/linux/aarch64/sysdep.h -+++ b/sysdeps/unix/sysv/linux/aarch64/sysdep.h -@@ -242,6 +242,31 @@ - #undef HAVE_INTERNAL_BRK_ADDR_SYMBOL - #define HAVE_INTERNAL_BRK_ADDR_SYMBOL 1 - -+/* Clear ZA state of SME (C version). */ -+/* The __libc_arm_za_disable function has special calling convention -+ that allows to call it without stack manipulation and preserving -+ most of the registers. */ -+#define CALL_LIBC_ARM_ZA_DISABLE() \ -+({ \ -+ unsigned long int __tmp; \ -+ asm volatile ( \ -+ " mov %0, x30\n" \ -+ " .cfi_register x30, %0\n" \ -+ " bl __libc_arm_za_disable\n" \ -+ " mov x30, %0\n" \ -+ " .cfi_register %0, x30\n" \ -+ : "=r" (__tmp) \ -+ : \ -+ : "x14", "x15", "x16", "x17", "x18", "memory" ); \ -+}) -+ -+/* Do clear ZA state of SME before making normal clone syscall. */ -+#define INLINE_CLONE_SYSCALL(a0, a1, a2, a3, a4) \ -+({ \ -+ CALL_LIBC_ARM_ZA_DISABLE (); \ -+ INLINE_SYSCALL_CALL (clone, a0, a1, a2, a3, a4); \ -+}) -+ - #endif /* __ASSEMBLER__ */ - - #endif /* linux/aarch64/sysdep.h */ -diff --git a/sysdeps/unix/sysv/linux/aarch64/vfork.S b/sysdeps/unix/sysv/linux/aarch64/vfork.S -index d5943a7485..2600bc9be3 100644 ---- a/sysdeps/unix/sysv/linux/aarch64/vfork.S -+++ b/sysdeps/unix/sysv/linux/aarch64/vfork.S -@@ -27,6 +27,9 @@ - - ENTRY (__vfork) - -+ /* Clear ZA state of SME. */ -+ CALL_LIBC_ARM_ZA_DISABLE -+ - mov x0, #0x4111 /* CLONE_VM | CLONE_VFORK | SIGCHLD */ - mov x1, sp - DO_CALL (clone, 2) - -commit 71874f167aa5bb1538ff7e394beaacee28ebe65f -Author: Yury Khrustalev -Date: Fri Sep 26 10:03:45 2025 +0100 - - aarch64: tests for SME - - This commit adds tests for the following use cases relevant to handing of - the SME state: - - - fork() and vfork() - - clone() and clone3() - - signal handler - - While most cases are trivial, the case of clone3() is more complicated since - the clone3() symbol is not public in Glibc. - - To avoid having to check all possible ways clone3() may be called via other - public functions (e.g. vfork() or pthread_create()), we put together a test - that links directly with clone3.o. All the existing functions that have calls - to clone3() may not actually use it, in which case the outcome of such tests - would be unexpected. Having a direct call to the clone3() symbol in the test - allows to check precisely what we need to test: that the __arm_za_disable() - function is indeed called and has the desired effect. - - Linking to clone3.o also requires linking to __arm_za_disable.o that in - turn requires the _dl_hwcap2 hidden symbol which to provide in the test - and initialise it before using. - - Co-authored-by: Adhemerval Zanella Netto - Reviewed-by: Adhemerval Zanella - (cherry picked from commit ecb0fc2f0f839f36cd2a106283142c9df8ea8214) - -diff --git a/sysdeps/aarch64/Makefile b/sysdeps/aarch64/Makefile -index bb97d31355..9479fb9679 100644 ---- a/sysdeps/aarch64/Makefile -+++ b/sysdeps/aarch64/Makefile -@@ -79,8 +79,18 @@ sysdep_routines += \ - - tests += \ - tst-sme-jmp \ -+ tst-sme-signal \ - tst-sme-za-state \ - # tests -+tests-internal += \ -+ tst-sme-clone \ -+ tst-sme-clone3 \ -+ tst-sme-fork \ -+ tst-sme-vfork \ -+ # tests-internal -+ -+$(objpfx)tst-sme-clone3: $(objpfx)clone3.o $(objpfx)__arm_za_disable.o -+ - endif - - ifeq ($(subdir),malloc) -diff --git a/sysdeps/aarch64/tst-sme-clone.c b/sysdeps/aarch64/tst-sme-clone.c -new file mode 100644 -index 0000000000..7106ec7926 ---- /dev/null -+++ b/sysdeps/aarch64/tst-sme-clone.c -@@ -0,0 +1,53 @@ -+/* Test that ZA state of SME is cleared in both parent and child -+ when clone() syscall is used. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include "tst-sme-skeleton.c" -+ -+#include -+ -+static int -+fun (void * const arg) -+{ -+ printf ("in child: %s\n", (const char *)arg); -+ /* Check that ZA state of SME was disabled in child. */ -+ check_sme_za_state ("after clone in child", /* Clear. */ true); -+ return 0; -+} -+ -+static char __attribute__((aligned(16))) -+stack[1024 * 1024]; -+ -+static void -+run (struct blk *ptr) -+{ -+ char *syscall_name = (char *)"clone"; -+ printf ("in parent: before %s\n", syscall_name); -+ -+ /* Enabled ZA state so that effect of disabling be observable. */ -+ enable_sme_za_state (ptr); -+ check_sme_za_state ("before clone", /* Clear. */ false); -+ -+ pid_t pid = xclone (fun, syscall_name, stack, sizeof (stack), -+ CLONE_NEWUSER | CLONE_NEWNS | SIGCHLD); -+ -+ /* Check that ZA state of SME was disabled in parent. */ -+ check_sme_za_state ("after clone in parent", /* Clear. */ true); -+ -+ TEST_VERIFY (xwaitpid (pid, NULL, 0) == pid); -+} -diff --git a/sysdeps/aarch64/tst-sme-clone3.c b/sysdeps/aarch64/tst-sme-clone3.c -new file mode 100644 -index 0000000000..402b040cfd ---- /dev/null -+++ b/sysdeps/aarch64/tst-sme-clone3.c -@@ -0,0 +1,84 @@ -+/* Test that ZA state of SME is cleared in both parent and child -+ when clone3() syscall is used. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include "tst-sme-skeleton.c" -+ -+#include -+ -+#include -+#include -+#include -+ -+/* Since clone3 is not a public symbol, we link this test explicitly -+ with clone3.o and have to provide this declaration. */ -+int __clone3 (struct clone_args *cl_args, size_t size, -+ int (*func)(void *arg), void *arg); -+ -+static int -+fun (void * const arg) -+{ -+ printf ("in child: %s\n", (const char *)arg); -+ /* Check that ZA state of SME was disabled in child. */ -+ check_sme_za_state ("after clone3 in child", /* Clear. */ true); -+ return 0; -+} -+ -+static char __attribute__((aligned(16))) -+stack[1024 * 1024]; -+ -+/* Required by __arm_za_disable.o and provided by the startup code -+ as a hidden symbol. */ -+uint64_t _dl_hwcap2; -+ -+static void -+run (struct blk *ptr) -+{ -+ _dl_hwcap2 = getauxval (AT_HWCAP2); -+ -+ char *syscall_name = (char *)"clone3"; -+ struct clone_args args = { -+ .flags = CLONE_VM | CLONE_VFORK, -+ .exit_signal = SIGCHLD, -+ .stack = (uintptr_t) stack, -+ .stack_size = sizeof (stack), -+ }; -+ printf ("in parent: before %s\n", syscall_name); -+ -+ /* Enabled ZA state so that effect of disabling be observable. */ -+ enable_sme_za_state (ptr); -+ check_sme_za_state ("before clone3", /* Clear. */ false); -+ -+ pid_t pid = __clone3 (&args, sizeof (args), fun, syscall_name); -+ -+ /* Check that ZA state of SME was disabled in parent. */ -+ check_sme_za_state ("after clone3 in parent", /* Clear. */ true); -+ -+ printf ("%s child pid: %d\n", syscall_name, pid); -+ -+ xwaitpid (pid, NULL, 0); -+ printf ("in parent: after %s\n", syscall_name); -+} -+ -+/* Workaround to simplify linking with clone3.o. */ -+void __syscall_error(int code) -+{ -+ int err = -code; -+ fprintf (stderr, "syscall error %d (%s)\n", err, strerror (err)); -+ exit (err); -+} -diff --git a/sysdeps/aarch64/tst-sme-fork.c b/sysdeps/aarch64/tst-sme-fork.c -new file mode 100644 -index 0000000000..b003b08884 ---- /dev/null -+++ b/sysdeps/aarch64/tst-sme-fork.c -@@ -0,0 +1,43 @@ -+/* Test that ZA state of SME is cleared in both parent and child -+ when fork() function is used. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include "tst-sme-skeleton.c" -+ -+static void -+run (struct blk *blk) -+{ -+ /* Enabled ZA state so that effect of disabling be observable. */ -+ enable_sme_za_state (blk); -+ check_sme_za_state ("before fork", /* Clear. */ false); -+ fflush (stdout); -+ -+ pid_t pid = xfork (); -+ -+ if (pid == 0) -+ { -+ /* Check that ZA state of SME was disabled in child. */ -+ check_sme_za_state ("after fork in child", /* Clear. */ true); -+ exit (0); -+ } -+ -+ /* Check that ZA state of SME was disabled in parent. */ -+ check_sme_za_state ("after fork in parent", /* Clear. */ true); -+ -+ TEST_VERIFY (xwaitpid (pid, NULL, 0) == pid); -+} -diff --git a/sysdeps/aarch64/tst-sme-helper.h b/sysdeps/aarch64/tst-sme-helper.h -index f049416c2b..ab9c503e45 100644 ---- a/sysdeps/aarch64/tst-sme-helper.h -+++ b/sysdeps/aarch64/tst-sme-helper.h -@@ -16,9 +16,6 @@ - License along with the GNU C Library; if not, see - . */ - --/* Streaming SVE vector register size. */ --static unsigned long svl; -- - struct blk { - void *za_save_buffer; - uint16_t num_za_save_slices; -@@ -68,10 +65,10 @@ start_za (void) - - /* Load data into ZA byte by byte from p. */ - static void __attribute__ ((noinline)) --load_za (const void *p) -+load_za (const void *buf, unsigned long svl) - { - register unsigned long x15 asm ("x15") = 0; -- register unsigned long x16 asm ("x16") = (unsigned long)p; -+ register unsigned long x16 asm ("x16") = (unsigned long)buf; - register unsigned long x17 asm ("x17") = svl; - - asm volatile ( -diff --git a/sysdeps/aarch64/tst-sme-jmp.c b/sysdeps/aarch64/tst-sme-jmp.c -index 103897ad36..b2d21c6e1a 100644 ---- a/sysdeps/aarch64/tst-sme-jmp.c -+++ b/sysdeps/aarch64/tst-sme-jmp.c -@@ -29,6 +29,9 @@ - - #include "tst-sme-helper.h" - -+/* Streaming SVE vector register size. */ -+static unsigned long svl; -+ - static uint8_t *za_orig; - static uint8_t *za_dump; - static uint8_t *za_save; -@@ -82,7 +85,7 @@ longjmp_test (void) - FAIL_EXIT1 ("svcr != 0: %lu", svcr); - set_tpidr2 (&blk); - start_za (); -- load_za (za_orig); -+ load_za (za_orig, svl); - - print_data ("za save space", za_save); - p = get_tpidr2 (); -@@ -131,7 +134,7 @@ setcontext_test (void) - FAIL_EXIT1 ("svcr != 0: %lu", svcr); - set_tpidr2 (&blk); - start_za (); -- load_za (za_orig); -+ load_za (za_orig, svl); - - print_data ("za save space", za_save); - p = get_tpidr2 (); -diff --git a/sysdeps/aarch64/tst-sme-signal.c b/sysdeps/aarch64/tst-sme-signal.c -new file mode 100644 -index 0000000000..b4b07bcc44 ---- /dev/null -+++ b/sysdeps/aarch64/tst-sme-signal.c -@@ -0,0 +1,115 @@ -+/* Test handling of SME state in a signal handler. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include "tst-sme-skeleton.c" -+ -+#include -+ -+static struct _aarch64_ctx * -+extension (void *p) -+{ -+ return p; -+} -+ -+#ifndef TPIDR2_MAGIC -+#define TPIDR2_MAGIC 0x54504902 -+#endif -+ -+#ifndef ZA_MAGIC -+#define ZA_MAGIC 0x54366345 -+#endif -+ -+#ifndef ZT_MAGIC -+#define ZT_MAGIC 0x5a544e01 -+#endif -+ -+#ifndef EXTRA_MAGIC -+#define EXTRA_MAGIC 0x45585401 -+#endif -+ -+/* We use a pipe to make sure that the final check of the SME state -+ happens after signal handler finished. */ -+static int pipefd[2]; -+ -+#define WRITE(msg) xwrite (1, msg, sizeof (msg)); -+ -+static void -+handler (int signo, siginfo_t *si, void *ctx) -+{ -+ TEST_VERIFY (signo == SIGUSR1); -+ WRITE ("in the handler\n"); -+ check_sme_za_state ("during signal", true /* State is clear. */); -+ ucontext_t *uc = ctx; -+ void *p = uc->uc_mcontext.__reserved; -+ unsigned int found = 0; -+ uint32_t m; -+ while ((m = extension (p)->magic)) -+ { -+ if (m == TPIDR2_MAGIC) -+ { -+ WRITE ("found TPIDR2_MAGIC\n"); -+ found += 1; -+ } -+ if (m == ZA_MAGIC) -+ { -+ WRITE ("found ZA_MAGIC\n"); -+ found += 1; -+ } -+ if (m == ZT_MAGIC) -+ { -+ WRITE ("found ZT_MAGIC\n"); -+ found += 1; -+ } -+ if (m == EXTRA_MAGIC) -+ { -+ WRITE ("found EXTRA_MAGIC\n"); -+ struct { struct _aarch64_ctx h; uint64_t data; } *e = p; -+ p = (char *)e->data; -+ continue; -+ } -+ p = (char *)p + extension (p)->size; -+ } -+ TEST_COMPARE (found, 3); -+ -+ /* Signal that the wait is over (see below). */ -+ char message = '\0'; -+ xwrite (pipefd[1], &message, 1); -+} -+ -+static void -+run (struct blk *blk) -+{ -+ xpipe (pipefd); -+ -+ struct sigaction sigact; -+ sigemptyset (&sigact.sa_mask); -+ sigact.sa_flags = 0; -+ sigact.sa_flags |= SA_SIGINFO; -+ sigact.sa_sigaction = handler; -+ xsigaction (SIGUSR1, &sigact, NULL); -+ -+ enable_sme_za_state (blk); -+ check_sme_za_state ("before signal", false /* State is not clear. */); -+ xraise (SIGUSR1); -+ -+ /* Wait for signal handler to complete. */ -+ char response; -+ xread (pipefd[0], &response, 1); -+ -+ check_sme_za_state ("after signal", false /* State is not clear. */); -+} -diff --git a/sysdeps/aarch64/tst-sme-skeleton.c b/sysdeps/aarch64/tst-sme-skeleton.c -new file mode 100644 -index 0000000000..ba84dda1cb ---- /dev/null -+++ b/sysdeps/aarch64/tst-sme-skeleton.c -@@ -0,0 +1,101 @@ -+/* Template for SME tests. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+ -+#include -+#include -+#include -+#include -+#include -+ -+#include "tst-sme-helper.h" -+ -+/* Streaming SVE vector register size. */ -+static unsigned long svl; -+ -+static uint8_t *state; -+ -+static void -+enable_sme_za_state (struct blk *blk) -+{ -+ start_za (); -+ set_tpidr2 (blk); -+ load_za (blk, svl); -+} -+ -+/* Check if SME state is disabled (when CLEAR is true) or -+ enabled (when CLEAR is false). */ -+static void -+check_sme_za_state (const char msg[], bool clear) -+{ -+ unsigned long svcr = get_svcr (); -+ void *tpidr2 = get_tpidr2 (); -+ printf ("[%s]\n", msg); -+ printf ("svcr = %016lx\n", svcr); -+ printf ("tpidr2 = %016lx\n", (unsigned long)tpidr2); -+ if (clear) -+ { -+ TEST_VERIFY (svcr == 0); -+ TEST_VERIFY (tpidr2 == NULL); -+ } -+ else -+ { -+ TEST_VERIFY (svcr != 0); -+ TEST_VERIFY (tpidr2 != NULL); -+ } -+} -+ -+/* Should be defined in actual test that includes this -+ skeleton file. */ -+static void -+run (struct blk *ptr); -+ -+static int -+do_test (void) -+{ -+ unsigned long hwcap2 = getauxval (AT_HWCAP2); -+ if ((hwcap2 & HWCAP2_SME) == 0) -+ return EXIT_UNSUPPORTED; -+ -+ /* Get current streaming SVE vector length in bytes. */ -+ svl = get_svl (); -+ printf ("svl: %lu\n", svl); -+ -+ TEST_VERIFY_EXIT (!(svl < 16 || svl % 16 != 0 || svl >= (1 << 16))); -+ -+ /* Initialise buffer for ZA state of SME. */ -+ state = xmalloc (svl * svl); -+ memset (state, 1, svl * svl); -+ struct blk blk = { -+ .za_save_buffer = state, -+ .num_za_save_slices = svl, -+ .__reserved = {0}, -+ }; -+ -+ run (&blk); -+ -+ free (state); -+ return 0; -+} -+ -+#include -diff --git a/sysdeps/aarch64/tst-sme-vfork.c b/sysdeps/aarch64/tst-sme-vfork.c -new file mode 100644 -index 0000000000..3feea065e5 ---- /dev/null -+++ b/sysdeps/aarch64/tst-sme-vfork.c -@@ -0,0 +1,43 @@ -+/* Test that ZA state of SME is cleared in both parent and child -+ when vfork() function is used. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include "tst-sme-skeleton.c" -+ -+static void -+run (struct blk *blk) -+{ -+ /* Enabled ZA state so that effect of disabling be observable. */ -+ enable_sme_za_state (blk); -+ check_sme_za_state ("before vfork", /* Clear. */ false); -+ fflush (stdout); -+ -+ pid_t pid = vfork (); -+ -+ if (pid == 0) -+ { -+ /* Check that ZA state of SME was disabled in child. */ -+ check_sme_za_state ("after vfork in child", /* Clear. */ true); -+ _exit (0); -+ } -+ -+ /* Check that ZA state of SME was disabled in parent. */ -+ check_sme_za_state ("after vfork in parent", /* Clear. */ true); -+ -+ TEST_VERIFY (xwaitpid (pid, NULL, 0) == pid); -+} -diff --git a/sysdeps/aarch64/tst-sme-za-state.c b/sysdeps/aarch64/tst-sme-za-state.c -index 63f6eebeb4..00118ef506 100644 ---- a/sysdeps/aarch64/tst-sme-za-state.c -+++ b/sysdeps/aarch64/tst-sme-za-state.c -@@ -16,47 +16,9 @@ - License along with the GNU C Library; if not, see - . */ - --#include --#include --#include --#include --#include -- --#include --#include --#include -- --#include "tst-sme-helper.h" -- --static uint8_t *state; -- --static void --enable_sme_za_state (struct blk *ptr) --{ -- set_tpidr2 (ptr); -- start_za (); -- load_za (state); --} -+#include "tst-sme-skeleton.c" - --static void --check_sme_za_state (const char msg[], bool clear) --{ -- unsigned long svcr = get_svcr (); -- void *tpidr2 = get_tpidr2 (); -- printf ("[%s]\n", msg); -- printf ("svcr = %016lx\n", svcr); -- printf ("tpidr2 = %016lx\n", (unsigned long)tpidr2); -- if (clear) -- { -- TEST_VERIFY (svcr == 0); -- TEST_VERIFY (tpidr2 == NULL); -- } -- else -- { -- TEST_VERIFY (svcr != 0); -- TEST_VERIFY (tpidr2 != NULL); -- } --} -+#include - - static void - run (struct blk *ptr) -@@ -88,32 +50,3 @@ run (struct blk *ptr) - TEST_COMPARE (ret, 42); - check_sme_za_state ("after longjmp", /* Clear. */ true); - } -- --static int --do_test (void) --{ -- unsigned long hwcap2 = getauxval (AT_HWCAP2); -- if ((hwcap2 & HWCAP2_SME) == 0) -- return EXIT_UNSUPPORTED; -- -- /* Get current streaming SVE vector register size. */ -- svl = get_svl (); -- printf ("svl: %lu\n", svl); -- TEST_VERIFY_EXIT (!(svl < 16 || svl % 16 != 0 || svl >= (1 << 16))); -- -- /* Initialise buffer for ZA state of SME. */ -- state = xmalloc (svl * svl); -- memset (state, 1, svl * svl); -- struct blk blk = { -- .za_save_buffer = state, -- .num_za_save_slices = svl, -- .__reserved = {0}, -- }; -- -- run (&blk); -- -- free (state); -- return 0; --} -- --#include - -commit bf499c2a4964bddc25a006ec1402f8996d78c6ff -Author: Jiamei Xie -Date: Tue Oct 14 20:14:11 2025 +0800 - - x86: fix wmemset ifunc stray '!' (bug 33542) - - The ifunc selector for wmemset had a stray '!' in the - X86_ISA_CPU_FEATURES_ARCH_P(...) check: - - if (X86_ISA_CPU_FEATURE_USABLE_P (cpu_features, AVX2) - && X86_ISA_CPU_FEATURES_ARCH_P (cpu_features, - AVX_Fast_Unaligned_Load, !)) - - This effectively negated the predicate and caused the AVX2/AVX512 - paths to be skipped, making the dispatcher fall back to the SSE2 - implementation even on CPUs where AVX2/AVX512 are available. The - regression leads to noticeable throughput loss for wmemset. - - Remove the stray '!' so the AVX_Fast_Unaligned_Load capability is - tested as intended and the correct AVX2/EVEX variants are selected. - - Impact: - - On AVX2/AVX512-capable x86_64, wmemset no longer incorrectly - falls back to SSE2; perf now shows __wmemset_evex/avx2 variants. - - Testing: - - benchtests/bench-wmemset shows improved bandwidth across sizes. - - perf confirm the selected symbol is no longer SSE2. - - Signed-off-by: xiejiamei - Signed-off-by: Li jing - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 4d86b6cdd8132e0410347e07262239750f86dfb4) - -diff --git a/sysdeps/x86_64/multiarch/ifunc-wmemset.h b/sysdeps/x86_64/multiarch/ifunc-wmemset.h -index f95cca6ae5..50af138230 100644 ---- a/sysdeps/x86_64/multiarch/ifunc-wmemset.h -+++ b/sysdeps/x86_64/multiarch/ifunc-wmemset.h -@@ -35,7 +35,7 @@ IFUNC_SELECTOR (void) - - if (X86_ISA_CPU_FEATURE_USABLE_P (cpu_features, AVX2) - && X86_ISA_CPU_FEATURES_ARCH_P (cpu_features, -- AVX_Fast_Unaligned_Load, !)) -+ AVX_Fast_Unaligned_Load,)) - { - if (X86_ISA_CPU_FEATURE_USABLE_P (cpu_features, AVX512VL)) - { - -commit de1fe81f471496366580ad728b8986a3424b2fd7 -Author: Yury Khrustalev -Date: Tue Oct 28 11:01:50 2025 +0000 - - aarch64: fix cfi directives around __libc_arm_za_disable - - Incorrect CFI directive corrupted call stack information - and prevented debuggers from correctly displaying call - stack information. - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 2f77aec043f61e8533487850b11941a640ae2dea) - -diff --git a/sysdeps/unix/sysv/linux/aarch64/sysdep.h b/sysdeps/unix/sysv/linux/aarch64/sysdep.h -index 30003c0145..8a7690d4a8 100644 ---- a/sysdeps/unix/sysv/linux/aarch64/sysdep.h -+++ b/sysdeps/unix/sysv/linux/aarch64/sysdep.h -@@ -155,11 +155,12 @@ - that allows to call it without stack manipulation and preserving - most of the registers. */ - .macro CALL_LIBC_ARM_ZA_DISABLE -+ cfi_remember_state - mov x13, x30 -- .cfi_register x30, x13 -+ cfi_register(x30, x13) - bl __libc_arm_za_disable - mov x30, x13 -- .cfi_register x13, x30 -+ cfi_restore_state - .endm - - #else /* not __ASSEMBLER__ */ -@@ -250,11 +251,12 @@ - ({ \ - unsigned long int __tmp; \ - asm volatile ( \ -+ " .cfi_remember_state\n" \ - " mov %0, x30\n" \ -- " .cfi_register x30, %0\n" \ -+ " .cfi_register x30, %0\n" \ - " bl __libc_arm_za_disable\n" \ - " mov x30, %0\n" \ -- " .cfi_register %0, x30\n" \ -+ " .cfi_restore_state\n" \ - : "=r" (__tmp) \ - : \ - : "x14", "x15", "x16", "x17", "x18", "memory" ); \ - -commit 17c3eab387c3ceb6972e57888a89b1480793f81a -Author: Yury Khrustalev -Date: Tue Nov 11 11:40:25 2025 +0000 - - aarch64: fix includes in SME tests - - Use the correct include for the SIGCHLD macro: signal.h - - Reviewed-by: Wilco Dijkstra - (cherry picked from commit a9c426bcca59a9e228c4fbe75e75154217ec4ada) - -diff --git a/sysdeps/aarch64/tst-sme-clone.c b/sysdeps/aarch64/tst-sme-clone.c -index 7106ec7926..b6ad54fa37 100644 ---- a/sysdeps/aarch64/tst-sme-clone.c -+++ b/sysdeps/aarch64/tst-sme-clone.c -@@ -19,6 +19,7 @@ - - #include "tst-sme-skeleton.c" - -+#include - #include - - static int -diff --git a/sysdeps/aarch64/tst-sme-clone3.c b/sysdeps/aarch64/tst-sme-clone3.c -index 402b040cfd..f420d5984d 100644 ---- a/sysdeps/aarch64/tst-sme-clone3.c -+++ b/sysdeps/aarch64/tst-sme-clone3.c -@@ -22,7 +22,7 @@ - #include - - #include --#include -+#include - #include - - /* Since clone3 is not a public symbol, we link this test explicitly - -commit 97297120ce04f0edd16ed0357a11ef8731c5bd1e -Author: Joe Ramsay -Date: Thu Nov 6 15:36:03 2025 +0000 - - AArch64: Optimise SVE scalar callbacks - - Instead of using SVE instructions to marshall special results into the - correct lane, just write the entire vector (and the predicate) to - memory, then use cheaper scalar operations. - - Geomean speedup of 16% in special intervals on Neoverse with GCC 14. - - Reviewed-by: Wilco Dijkstra - (cherry picked from commit 5b82fb18827e962af9f080fdf3c1a69802783f67) - -diff --git a/sysdeps/aarch64/fpu/sv_math.h b/sysdeps/aarch64/fpu/sv_math.h -index 3d576df4cc..65d7f0ff20 100644 ---- a/sysdeps/aarch64/fpu/sv_math.h -+++ b/sysdeps/aarch64/fpu/sv_math.h -@@ -24,11 +24,29 @@ - - #include "vecmath_config.h" - -+#if !defined(__ARM_FEATURE_SVE_BITS) || __ARM_FEATURE_SVE_BITS == 0 -+/* If not specified by -msve-vector-bits, assume maximum vector length. */ -+# define SVE_VECTOR_BYTES 256 -+#else -+# define SVE_VECTOR_BYTES (__ARM_FEATURE_SVE_BITS / 8) -+#endif -+#define SVE_NUM_FLTS (SVE_VECTOR_BYTES / sizeof (float)) -+#define SVE_NUM_DBLS (SVE_VECTOR_BYTES / sizeof (double)) -+/* Predicate is stored as one bit per byte of VL so requires VL / 64 bytes. */ -+#define SVE_NUM_PG_BYTES (SVE_VECTOR_BYTES / sizeof (uint64_t)) -+ - #define SV_NAME_F1(fun) _ZGVsMxv_##fun##f - #define SV_NAME_D1(fun) _ZGVsMxv_##fun - #define SV_NAME_F2(fun) _ZGVsMxvv_##fun##f - #define SV_NAME_D2(fun) _ZGVsMxvv_##fun - -+static inline void -+svstr_p (uint8_t *dst, svbool_t p) -+{ -+ /* Predicate STR does not currently have an intrinsic. */ -+ __asm__("str %0, [%x1]\n" : : "Upa"(p), "r"(dst) : "memory"); -+} -+ - /* Double precision. */ - static inline svint64_t - sv_s64 (int64_t x) -@@ -51,33 +69,35 @@ sv_f64 (double x) - static inline svfloat64_t - sv_call_f64 (double (*f) (double), svfloat64_t x, svfloat64_t y, svbool_t cmp) - { -- svbool_t p = svpfirst (cmp, svpfalse ()); -- while (svptest_any (cmp, p)) -+ double tmp[SVE_NUM_DBLS]; -+ uint8_t pg_bits[SVE_NUM_PG_BYTES]; -+ svstr_p (pg_bits, cmp); -+ svst1 (svptrue_b64 (), tmp, svsel (cmp, x, y)); -+ -+ for (int i = 0; i < svcntd (); i++) - { -- double elem = svclastb_n_f64 (p, 0, x); -- elem = (*f) (elem); -- svfloat64_t y2 = svdup_n_f64 (elem); -- y = svsel_f64 (p, y2, y); -- p = svpnext_b64 (cmp, p); -+ if (pg_bits[i] & 1) -+ tmp[i] = f (tmp[i]); - } -- return y; -+ return svld1 (svptrue_b64 (), tmp); - } - - static inline svfloat64_t - sv_call2_f64 (double (*f) (double, double), svfloat64_t x1, svfloat64_t x2, - svfloat64_t y, svbool_t cmp) - { -- svbool_t p = svpfirst (cmp, svpfalse ()); -- while (svptest_any (cmp, p)) -+ double tmp1[SVE_NUM_DBLS], tmp2[SVE_NUM_DBLS]; -+ uint8_t pg_bits[SVE_NUM_PG_BYTES]; -+ svstr_p (pg_bits, cmp); -+ svst1 (svptrue_b64 (), tmp1, svsel (cmp, x1, y)); -+ svst1 (cmp, tmp2, x2); -+ -+ for (int i = 0; i < svcntd (); i++) - { -- double elem1 = svclastb_n_f64 (p, 0, x1); -- double elem2 = svclastb_n_f64 (p, 0, x2); -- double ret = (*f) (elem1, elem2); -- svfloat64_t y2 = svdup_n_f64 (ret); -- y = svsel_f64 (p, y2, y); -- p = svpnext_b64 (cmp, p); -+ if (pg_bits[i] & 1) -+ tmp1[i] = f (tmp1[i], tmp2[i]); - } -- return y; -+ return svld1 (svptrue_b64 (), tmp1); - } - - static inline svuint64_t -@@ -109,33 +129,40 @@ sv_f32 (float x) - static inline svfloat32_t - sv_call_f32 (float (*f) (float), svfloat32_t x, svfloat32_t y, svbool_t cmp) - { -- svbool_t p = svpfirst (cmp, svpfalse ()); -- while (svptest_any (cmp, p)) -+ float tmp[SVE_NUM_FLTS]; -+ uint8_t pg_bits[SVE_NUM_PG_BYTES]; -+ svstr_p (pg_bits, cmp); -+ svst1 (svptrue_b32 (), tmp, svsel (cmp, x, y)); -+ -+ for (int i = 0; i < svcntd (); i++) - { -- float elem = svclastb_n_f32 (p, 0, x); -- elem = f (elem); -- svfloat32_t y2 = svdup_n_f32 (elem); -- y = svsel_f32 (p, y2, y); -- p = svpnext_b32 (cmp, p); -+ uint8_t p = pg_bits[i]; -+ if (p & 1) -+ tmp[i * 2] = f (tmp[i * 2]); -+ if (p & (1 << 4)) -+ tmp[i * 2 + 1] = f (tmp[i * 2 + 1]); - } -- return y; -+ return svld1 (svptrue_b32 (), tmp); - } - - static inline svfloat32_t - sv_call2_f32 (float (*f) (float, float), svfloat32_t x1, svfloat32_t x2, - svfloat32_t y, svbool_t cmp) - { -- svbool_t p = svpfirst (cmp, svpfalse ()); -- while (svptest_any (cmp, p)) -+ float tmp1[SVE_NUM_FLTS], tmp2[SVE_NUM_FLTS]; -+ uint8_t pg_bits[SVE_NUM_PG_BYTES]; -+ svstr_p (pg_bits, cmp); -+ svst1 (svptrue_b32 (), tmp1, svsel (cmp, x1, y)); -+ svst1 (cmp, tmp2, x2); -+ -+ for (int i = 0; i < svcntd (); i++) - { -- float elem1 = svclastb_n_f32 (p, 0, x1); -- float elem2 = svclastb_n_f32 (p, 0, x2); -- float ret = f (elem1, elem2); -- svfloat32_t y2 = svdup_n_f32 (ret); -- y = svsel_f32 (p, y2, y); -- p = svpnext_b32 (cmp, p); -+ uint8_t p = pg_bits[i]; -+ if (p & 1) -+ tmp1[i * 2] = f (tmp1[i * 2], tmp2[i * 2]); -+ if (p & (1 << 4)) -+ tmp1[i * 2 + 1] = f (tmp1[i * 2 + 1], tmp2[i * 2 + 1]); - } -- return y; -+ return svld1 (svptrue_b32 (), tmp1); - } -- - #endif - -commit ec041b1f53bf1fd29d94ee147fac69da66437dc6 -Author: Joe Ramsay -Date: Thu Nov 6 18:26:54 2025 +0000 - - AArch64: Fix instability in AdvSIMD tan - - Previously presence of special-cases in one lane could affect the - results in other lanes due to unconditional scalar fallback. The old - WANT_SIMD_EXCEPT option (which has never been enabled in libmvec) has - been removed from AOR, making it easier to spot and fix this. 4% - improvement in throughput with GCC 14 on Neoverse V1. This bug is - present as far back as 2.39 (where tan was first introduced). - - Reviewed-by: Wilco Dijkstra - (cherry picked from commit 6c22823da57aa5218f717f569c04c9573c0448c5) - -diff --git a/sysdeps/aarch64/fpu/tan_advsimd.c b/sysdeps/aarch64/fpu/tan_advsimd.c -index 825c9754b3..d391a003d8 100644 ---- a/sysdeps/aarch64/fpu/tan_advsimd.c -+++ b/sysdeps/aarch64/fpu/tan_advsimd.c -@@ -25,9 +25,7 @@ static const struct data - float64x2_t poly[9]; - double half_pi[2]; - float64x2_t two_over_pi, shift; --#if !WANT_SIMD_EXCEPT - float64x2_t range_val; --#endif - } data = { - /* Coefficients generated using FPMinimax. */ - .poly = { V2 (0x1.5555555555556p-2), V2 (0x1.1111111110a63p-3), -@@ -38,20 +36,17 @@ static const struct data - .half_pi = { 0x1.921fb54442d18p0, 0x1.1a62633145c07p-54 }, - .two_over_pi = V2 (0x1.45f306dc9c883p-1), - .shift = V2 (0x1.8p52), --#if !WANT_SIMD_EXCEPT - .range_val = V2 (0x1p23), --#endif - }; - - #define RangeVal 0x4160000000000000 /* asuint64(0x1p23). */ - #define TinyBound 0x3e50000000000000 /* asuint64(2^-26). */ --#define Thresh 0x310000000000000 /* RangeVal - TinyBound. */ - - /* Special cases (fall back to scalar calls). */ - static float64x2_t VPCS_ATTR NOINLINE --special_case (float64x2_t x) -+special_case (float64x2_t x, float64x2_t n, float64x2_t d, uint64x2_t special) - { -- return v_call_f64 (tan, x, x, v_u64 (-1)); -+ return v_call_f64 (tan, x, vdivq_f64 (n, d), special); - } - - /* Vector approximation for double-precision tan. -@@ -65,14 +60,6 @@ float64x2_t VPCS_ATTR V_NAME_D1 (tan) (float64x2_t x) - very large inputs. Fall back to scalar routine for all lanes if any are - too large, or Inf/NaN. If fenv exceptions are expected, also fall back for - tiny input to avoid underflow. */ --#if WANT_SIMD_EXCEPT -- uint64x2_t iax = vreinterpretq_u64_f64 (vabsq_f64 (x)); -- /* iax - tiny_bound > range_val - tiny_bound. */ -- uint64x2_t special -- = vcgtq_u64 (vsubq_u64 (iax, v_u64 (TinyBound)), v_u64 (Thresh)); -- if (__glibc_unlikely (v_any_u64 (special))) -- return special_case (x); --#endif - - /* q = nearest integer to 2 * x / pi. */ - float64x2_t q -@@ -81,9 +68,8 @@ float64x2_t VPCS_ATTR V_NAME_D1 (tan) (float64x2_t x) - - /* Use q to reduce x to r in [-pi/4, pi/4], by: - r = x - q * pi/2, in extended precision. */ -- float64x2_t r = x; - float64x2_t half_pi = vld1q_f64 (dat->half_pi); -- r = vfmsq_laneq_f64 (r, q, half_pi, 0); -+ float64x2_t r = vfmsq_laneq_f64 (x, q, half_pi, 0); - r = vfmsq_laneq_f64 (r, q, half_pi, 1); - /* Further reduce r to [-pi/8, pi/8], to be reconstructed using double angle - formula. */ -@@ -114,12 +100,13 @@ float64x2_t VPCS_ATTR V_NAME_D1 (tan) (float64x2_t x) - - uint64x2_t no_recip = vtstq_u64 (vreinterpretq_u64_s64 (qi), v_u64 (1)); - --#if !WANT_SIMD_EXCEPT - uint64x2_t special = vcageq_f64 (x, dat->range_val); -+ float64x2_t swap = vbslq_f64 (no_recip, n, vnegq_f64 (d)); -+ d = vbslq_f64 (no_recip, d, n); -+ n = swap; -+ - if (__glibc_unlikely (v_any_u64 (special))) -- return special_case (x); --#endif -+ return special_case (x, n, d, special); - -- return vdivq_f64 (vbslq_f64 (no_recip, n, vnegq_f64 (d)), -- vbslq_f64 (no_recip, d, n)); -+ return vdivq_f64 (n, d); - } - -commit 0c9430ed976b961343dd29b752091f3c4771cf30 -Author: Joe Ramsay -Date: Thu Nov 6 18:29:33 2025 +0000 - - AArch64: Fix instability in AdvSIMD sinh - - Previously presence of special-cases in one lane could affect the - results in other lanes due to unconditional scalar fallback. The old - WANT_SIMD_EXCEPT option (which has never been enabled in libmvec) has - been removed from AOR, making it easier to spot and fix - this. No measured change in performance. This patch applies cleanly as - far back as 2.41, however there are conflicts with 2.40 where sinh was - first introduced. - - Reviewed-by: Wilco Dijkstra - (cherry picked from commit e45af510bc816e860c8e2e1d4a652b4fe15c4b34) - -diff --git a/sysdeps/aarch64/fpu/sinh_advsimd.c b/sysdeps/aarch64/fpu/sinh_advsimd.c -index 0d6a4856f8..b6b60262c6 100644 ---- a/sysdeps/aarch64/fpu/sinh_advsimd.c -+++ b/sysdeps/aarch64/fpu/sinh_advsimd.c -@@ -24,36 +24,26 @@ static const struct data - { - struct v_expm1_data d; - uint64x2_t halff; --#if WANT_SIMD_EXCEPT -- uint64x2_t tiny_bound, thresh; --#else - float64x2_t large_bound; --#endif - } data = { - .d = V_EXPM1_DATA, - .halff = V2 (0x3fe0000000000000), --#if WANT_SIMD_EXCEPT -- /* 2^-26, below which sinh(x) rounds to x. */ -- .tiny_bound = V2 (0x3e50000000000000), -- /* asuint(large_bound) - asuint(tiny_bound). */ -- .thresh = V2 (0x0230000000000000), --#else - /* 2^9. expm1 helper overflows for large input. */ - .large_bound = V2 (0x1p+9), --#endif - }; - - static float64x2_t NOINLINE VPCS_ATTR --special_case (float64x2_t x) -+special_case (float64x2_t x, float64x2_t t, float64x2_t halfsign, -+ uint64x2_t special) - { -- return v_call_f64 (sinh, x, x, v_u64 (-1)); -+ return v_call_f64 (sinh, x, vmulq_f64 (t, halfsign), special); - } - - /* Approximation for vector double-precision sinh(x) using expm1. - sinh(x) = (exp(x) - exp(-x)) / 2. - The greatest observed error is 2.52 ULP: -- _ZGVnN2v_sinh(-0x1.a098a2177a2b9p-2) got -0x1.ac2f05bb66fccp-2 -- want -0x1.ac2f05bb66fc9p-2. */ -+ _ZGVnN2v_sinh(0x1.9f6ff2ab6fb19p-2) got 0x1.aaed83a3153ccp-2 -+ want 0x1.aaed83a3153c9p-2. */ - float64x2_t VPCS_ATTR V_NAME_D1 (sinh) (float64x2_t x) - { - const struct data *d = ptr_barrier (&data); -@@ -63,21 +53,16 @@ float64x2_t VPCS_ATTR V_NAME_D1 (sinh) (float64x2_t x) - float64x2_t halfsign = vreinterpretq_f64_u64 ( - vbslq_u64 (v_u64 (0x8000000000000000), ix, d->halff)); - --#if WANT_SIMD_EXCEPT -- uint64x2_t special = vcgeq_u64 ( -- vsubq_u64 (vreinterpretq_u64_f64 (ax), d->tiny_bound), d->thresh); --#else - uint64x2_t special = vcageq_f64 (x, d->large_bound); --#endif -- -- /* Fall back to scalar variant for all lanes if any of them are special. */ -- if (__glibc_unlikely (v_any_u64 (special))) -- return special_case (x); - - /* Up to the point that expm1 overflows, we can use it to calculate sinh - using a slight rearrangement of the definition of sinh. This allows us to - retain acceptable accuracy for very small inputs. */ - float64x2_t t = expm1_inline (ax, &d->d); - t = vaddq_f64 (t, vdivq_f64 (t, vaddq_f64 (t, v_f64 (1.0)))); -+ -+ if (__glibc_unlikely (v_any_u64 (special))) -+ return special_case (x, t, halfsign, special); -+ - return vmulq_f64 (t, halfsign); - } - -commit 710d7a2e8374cf09280a0db170a6c813b70b59e5 -Author: Pierre Blanchard -Date: Tue Nov 18 15:03:10 2025 +0000 - - AArch64: fix SVE tanpi(f) [BZ #33642] - - Fixed svld1rq using incorrect predicates (BZ #33642). - Next to no performance variations (tested on V1). - - Reviewed-by: Wilco Dijkstra  - (cherry picked from commit e889160273a4c2b68870c9adf341955867d76a7d) - -diff --git a/sysdeps/aarch64/fpu/tanpi_sve.c b/sysdeps/aarch64/fpu/tanpi_sve.c -index 57c643ae29..bfe6828e1f 100644 ---- a/sysdeps/aarch64/fpu/tanpi_sve.c -+++ b/sysdeps/aarch64/fpu/tanpi_sve.c -@@ -1,6 +1,6 @@ - /* Double-precision (SVE) tanpi function - -- Copyright (C) 2024 Free Software Foundation, Inc. -+ Copyright (C) 2024-2025 Free Software Foundation, Inc. - This file is part of the GNU C Library. - - The GNU C Library is free software; you can redistribute it and/or -@@ -58,10 +58,10 @@ svfloat64_t SV_NAME_D1 (tanpi) (svfloat64_t x, const svbool_t pg) - svfloat64_t r2 = svmul_x (pg, r, r); - svfloat64_t r4 = svmul_x (pg, r2, r2); - -- svfloat64_t c_1_3 = svld1rq (pg, &d->c1); -- svfloat64_t c_5_7 = svld1rq (pg, &d->c5); -- svfloat64_t c_9_11 = svld1rq (pg, &d->c9); -- svfloat64_t c_13_14 = svld1rq (pg, &d->c13); -+ svfloat64_t c_1_3 = svld1rq (svptrue_b64 (), &d->c1); -+ svfloat64_t c_5_7 = svld1rq (svptrue_b64 (), &d->c5); -+ svfloat64_t c_9_11 = svld1rq (svptrue_b64 (), &d->c9); -+ svfloat64_t c_13_14 = svld1rq (svptrue_b64 (), &d->c13); - svfloat64_t p01 = svmla_lane (sv_f64 (d->c0), r2, c_1_3, 0); - svfloat64_t p23 = svmla_lane (sv_f64 (d->c2), r2, c_1_3, 1); - svfloat64_t p45 = svmla_lane (sv_f64 (d->c4), r2, c_5_7, 0); -diff --git a/sysdeps/aarch64/fpu/tanpif_sve.c b/sysdeps/aarch64/fpu/tanpif_sve.c -index 0285f56f34..6894379564 100644 ---- a/sysdeps/aarch64/fpu/tanpif_sve.c -+++ b/sysdeps/aarch64/fpu/tanpif_sve.c -@@ -1,6 +1,6 @@ - /* Single-precision (SVE) tanpi function - -- Copyright (C) 2024 Free Software Foundation, Inc. -+ Copyright (C) 2024-2025 Free Software Foundation, Inc. - This file is part of the GNU C Library. - - The GNU C Library is free software; you can redistribute it and/or -@@ -37,7 +37,7 @@ const static struct v_tanpif_data - svfloat32_t SV_NAME_F1 (tanpi) (svfloat32_t x, const svbool_t pg) - { - const struct v_tanpif_data *d = ptr_barrier (&tanpif_data); -- svfloat32_t odd_coeffs = svld1rq (pg, &d->c1); -+ svfloat32_t odd_coeffs = svld1rq (svptrue_b32 (), &d->c1); - svfloat32_t n = svrintn_x (pg, x); - - /* inf produces nan that propagates. */ - -commit 828b8d23f3fa05234d35032a61a746918accf91d -Author: Pierre Blanchard -Date: Tue Nov 18 15:09:05 2025 +0000 - - AArch64: Fix and improve SVE pow(f) special cases - - powf: - - Update scalar special case function to best use new interface. - - pow: - - Make specialcase NOINLINE to prevent str/ldr leaking in fast path. - Remove depency in sv_call2, as new callback impl is not a - performance gain. - Replace with vectorised specialcase since structure of scalar - routine is fairly simple. - - Throughput gain of about 5-10% on V1 for large values and 25% for subnormal `x`. - - Reviewed-by: Wilco Dijkstra  - (cherry picked from commit bb6519de1e6fe73d79bc71588ec4e5668907f080) - -diff --git a/sysdeps/aarch64/fpu/pow_sve.c b/sysdeps/aarch64/fpu/pow_sve.c -index b8c1b39dca..becf1a8410 100644 ---- a/sysdeps/aarch64/fpu/pow_sve.c -+++ b/sysdeps/aarch64/fpu/pow_sve.c -@@ -31,8 +31,8 @@ - The SVE algorithm drops the tail in the exp computation at the price of - a lower accuracy, slightly above 1ULP. - The SVE algorithm also drops the special treatement of small (< 2^-65) and -- large (> 2^63) finite values of |y|, as they only affect non-round to nearest -- modes. -+ large (> 2^63) finite values of |y|, as they only affect non-round to -+ nearest modes. - - Maximum measured error is 1.04 ULPs: - SV_NAME_D2 (pow) (0x1.3d2d45bc848acp+63, -0x1.a48a38b40cd43p-12) -@@ -156,42 +156,22 @@ sv_zeroinfnan (svbool_t pg, svuint64_t i) - a double. (int32_t)KI is the k used in the argument reduction and exponent - adjustment of scale, positive k here means the result may overflow and - negative k means the result may underflow. */ --static inline double --specialcase (double tmp, uint64_t sbits, uint64_t ki) --{ -- double scale; -- if ((ki & 0x80000000) == 0) -- { -- /* k > 0, the exponent of scale might have overflowed by <= 460. */ -- sbits -= 1009ull << 52; -- scale = asdouble (sbits); -- return 0x1p1009 * (scale + scale * tmp); -- } -- /* k < 0, need special care in the subnormal range. */ -- sbits += 1022ull << 52; -- /* Note: sbits is signed scale. */ -- scale = asdouble (sbits); -- double y = scale + scale * tmp; -- return 0x1p-1022 * y; --} -- --/* Scalar fallback for special cases of SVE pow's exp. */ - static inline svfloat64_t --sv_call_specialcase (svfloat64_t x1, svuint64_t u1, svuint64_t u2, -- svfloat64_t y, svbool_t cmp) -+specialcase (svfloat64_t tmp, svuint64_t sbits, svuint64_t ki, svbool_t cmp) - { -- svbool_t p = svpfirst (cmp, svpfalse ()); -- while (svptest_any (cmp, p)) -- { -- double sx1 = svclastb (p, 0, x1); -- uint64_t su1 = svclastb (p, 0, u1); -- uint64_t su2 = svclastb (p, 0, u2); -- double elem = specialcase (sx1, su1, su2); -- svfloat64_t y2 = sv_f64 (elem); -- y = svsel (p, y2, y); -- p = svpnext_b64 (cmp, p); -- } -- return y; -+ svbool_t p_pos = svcmpge_n_f64 (cmp, svreinterpret_f64_u64 (ki), 0.0); -+ -+ /* Scale up or down depending on sign of k. */ -+ svint64_t offset -+ = svsel_s64 (p_pos, sv_s64 (1009ull << 52), sv_s64 (-1022ull << 52)); -+ svfloat64_t factor -+ = svsel_f64 (p_pos, sv_f64 (0x1p1009), sv_f64 (0x1p-1022)); -+ -+ svuint64_t offset_sbits -+ = svsub_u64_x (cmp, sbits, svreinterpret_u64_s64 (offset)); -+ svfloat64_t scale = svreinterpret_f64_u64 (offset_sbits); -+ svfloat64_t res = svmad_f64_x (cmp, scale, tmp, scale); -+ return svmul_f64_x (cmp, res, factor); - } - - /* Compute y+TAIL = log(x) where the rounded result is y and TAIL has about -@@ -214,8 +194,8 @@ sv_log_inline (svbool_t pg, svuint64_t ix, svfloat64_t *tail, - - /* log(x) = k*Ln2 + log(c) + log1p(z/c-1). */ - /* SVE lookup requires 3 separate lookup tables, as opposed to scalar version -- that uses array of structures. We also do the lookup earlier in the code to -- make sure it finishes as early as possible. */ -+ that uses array of structures. We also do the lookup earlier in the code -+ to make sure it finishes as early as possible. */ - svfloat64_t invc = svld1_gather_index (pg, __v_pow_log_data.invc, i); - svfloat64_t logc = svld1_gather_index (pg, __v_pow_log_data.logc, i); - svfloat64_t logctail = svld1_gather_index (pg, __v_pow_log_data.logctail, i); -@@ -325,14 +305,14 @@ sv_exp_inline (svbool_t pg, svfloat64_t x, svfloat64_t xtail, - svbool_t oflow = svcmpge (pg, abstop, HugeExp); - oflow = svand_z (pg, uoflow, svbic_z (pg, oflow, uflow)); - -- /* For large |x| values (512 < |x| < 1024) scale * (1 + TMP) can overflow -- or underflow. */ -+ /* Handle underflow and overlow in scale. -+ For large |x| values (512 < |x| < 1024), scale * (1 + TMP) can -+ overflow or underflow. */ - svbool_t special = svbic_z (pg, uoflow, svorr_z (pg, uflow, oflow)); -+ if (__glibc_unlikely (svptest_any (pg, special))) -+ z = svsel (special, specialcase (tmp, sbits, ki, special), z); - -- /* Update result with special and large cases. */ -- z = sv_call_specialcase (tmp, sbits, ki, z, special); -- -- /* Handle underflow and overflow. */ -+ /* Handle underflow and overflow in exp. */ - svbool_t x_is_neg = svcmplt (pg, x, 0); - svuint64_t sign_mask - = svlsl_x (pg, sign_bias, 52 - V_POW_EXP_TABLE_BITS); -@@ -353,7 +333,7 @@ sv_exp_inline (svbool_t pg, svfloat64_t x, svfloat64_t xtail, - } - - static inline double --pow_sc (double x, double y) -+pow_specialcase (double x, double y) - { - uint64_t ix = asuint64 (x); - uint64_t iy = asuint64 (y); -@@ -382,6 +362,14 @@ pow_sc (double x, double y) - return x; - } - -+/* Scalar fallback for special case routines with custom signature. */ -+static svfloat64_t NOINLINE -+sv_pow_specialcase (svfloat64_t x1, svfloat64_t x2, svfloat64_t y, -+ svbool_t cmp) -+{ -+ return sv_call2_f64 (pow_specialcase, x1, x2, y, cmp); -+} -+ - svfloat64_t SV_NAME_D2 (pow) (svfloat64_t x, svfloat64_t y, const svbool_t pg) - { - const struct data *d = ptr_barrier (&data); -@@ -444,7 +432,7 @@ svfloat64_t SV_NAME_D2 (pow) (svfloat64_t x, svfloat64_t y, const svbool_t pg) - - /* Cases of zero/inf/nan x or y. */ - if (__glibc_unlikely (svptest_any (svptrue_b64 (), special))) -- vz = sv_call2_f64 (pow_sc, x, y, vz, special); -+ vz = sv_pow_specialcase (x, y, vz, special); - - return vz; - } -diff --git a/sysdeps/aarch64/fpu/powf_sve.c b/sysdeps/aarch64/fpu/powf_sve.c -index 65e9bd29d9..76f54b3522 100644 ---- a/sysdeps/aarch64/fpu/powf_sve.c -+++ b/sysdeps/aarch64/fpu/powf_sve.c -@@ -116,11 +116,10 @@ zeroinfnan (uint32_t ix) - preamble of scalar powf except that we do not update ix and sign_bias. This - is done in the preamble of the SVE powf. */ - static inline float --powf_specialcase (float x, float y, float z) -+powf_specialcase (float x, float y) - { - uint32_t ix = asuint (x); - uint32_t iy = asuint (y); -- /* Either (x < 0x1p-126 or inf or nan) or (y is 0 or inf or nan). */ - if (__glibc_unlikely (zeroinfnan (iy))) - { - if (2 * iy == 0) -@@ -142,32 +141,15 @@ powf_specialcase (float x, float y, float z) - x2 = -x2; - return iy & 0x80000000 ? 1 / x2 : x2; - } -- /* We need a return here in case x<0 and y is integer, but all other tests -- need to be run. */ -- return z; -+ /* Return x for convenience, but make sure result is never used. */ -+ return x; - } - - /* Scalar fallback for special case routines with custom signature. */ - static svfloat32_t NOINLINE --sv_call_powf_sc (svfloat32_t x1, svfloat32_t x2, svfloat32_t y) -+sv_call_powf_sc (svfloat32_t x1, svfloat32_t x2, svfloat32_t y, svbool_t cmp) - { -- /* Special cases of x or y: zero, inf and nan. */ -- svbool_t xspecial = sv_zeroinfnan (svptrue_b32 (), svreinterpret_u32 (x1)); -- svbool_t yspecial = sv_zeroinfnan (svptrue_b32 (), svreinterpret_u32 (x2)); -- svbool_t cmp = svorr_z (svptrue_b32 (), xspecial, yspecial); -- -- svbool_t p = svpfirst (cmp, svpfalse ()); -- while (svptest_any (cmp, p)) -- { -- float sx1 = svclastb (p, 0, x1); -- float sx2 = svclastb (p, 0, x2); -- float elem = svclastb (p, 0, y); -- elem = powf_specialcase (sx1, sx2, elem); -- svfloat32_t y2 = sv_f32 (elem); -- y = svsel (p, y2, y); -- p = svpnext_b32 (cmp, p); -- } -- return y; -+ return sv_call2_f32 (powf_specialcase, x1, x2, y, cmp); - } - - /* Compute core for half of the lanes in double precision. */ -@@ -330,7 +312,7 @@ svfloat32_t SV_NAME_F2 (pow) (svfloat32_t x, svfloat32_t y, const svbool_t pg) - ret = svsel (yint_or_xpos, ret, sv_f32 (__builtin_nanf (""))); - - if (__glibc_unlikely (svptest_any (cmp, cmp))) -- return sv_call_powf_sc (x, y, ret); -+ return sv_call_powf_sc (x, y, ret, cmp); - - return ret; - } - -commit 6b2957cfe8ad1e02c03a28abfc5a251c05e4005e -Author: Sachin Monga -Date: Fri Nov 21 00:30:04 2025 -0500 - - ppc64le: Restore optimized strcmp for power10 - - This patch addresses the actual cause of CVE-2025-5702 - - The vector non-volatile registers are not used anymore for - 32 byte load and comparison operation - - Additionally, the assembler workaround used earlier for the - instruction lxvp is replaced with actual instruction. - - Signed-off-by: Sachin Monga - Co-authored-by: Paul Murphy - (cherry picked from commit 9a40b1cda519cc4f532acb6d020390829df3d81b) - -diff --git a/sysdeps/powerpc/powerpc64/le/power10/strcmp.S b/sysdeps/powerpc/powerpc64/le/power10/strcmp.S -new file mode 100644 -index 0000000000..0d4a53317c ---- /dev/null -+++ b/sysdeps/powerpc/powerpc64/le/power10/strcmp.S -@@ -0,0 +1,185 @@ -+/* Optimized strcmp implementation for PowerPC64/POWER10. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+#include -+ -+#ifndef STRCMP -+# define STRCMP strcmp -+#endif -+ -+/* Implements the function -+ int [r3] strcmp (const char *s1 [r3], const char *s2 [r4]). */ -+ -+ -+#define COMPARE_16(vreg1,vreg2,offset) \ -+ lxv vreg1+32,offset(r3); \ -+ lxv vreg2+32,offset(r4); \ -+ vcmpnezb. v7,vreg1,vreg2; \ -+ bne cr6,L(different); \ -+ -+#define COMPARE_32(vreg1,vreg2,offset,label1,label2) \ -+ lxvp vreg1+32,offset(r3); \ -+ lxvp vreg2+32,offset(r4); \ -+ vcmpnezb. v7,vreg1+1,vreg2+1; \ -+ bne cr6,L(label1); \ -+ vcmpnezb. v7,vreg1,vreg2; \ -+ bne cr6,L(label2); \ -+ -+#define TAIL(vreg1,vreg2) \ -+ vctzlsbb r6,v7; \ -+ vextubrx r5,r6,vreg1; \ -+ vextubrx r4,r6,vreg2; \ -+ subf r3,r4,r5; \ -+ blr; \ -+ -+#define CHECK_N_BYTES(reg1,reg2,len_reg) \ -+ sldi r0,len_reg,56; \ -+ lxvl 32+v4,reg1,r0; \ -+ lxvl 32+v5,reg2,r0; \ -+ add reg1,reg1,len_reg; \ -+ add reg2,reg2,len_reg; \ -+ vcmpnezb. v7,v4,v5; \ -+ vctzlsbb r6,v7; \ -+ cmpld cr7,r6,len_reg; \ -+ blt cr7,L(different); \ -+ -+ -+ .machine power10 -+ENTRY_TOCLESS (STRCMP, 4) -+ li r11,16 -+ /* eq bit of cr1 used as swap status flag to indicate if -+ source pointers were swapped. */ -+ crclr 4*cr1+eq -+ andi. r7,r3,15 -+ sub r7,r11,r7 /* r7(nalign1) = 16 - (str1 & 15). */ -+ andi. r9,r4,15 -+ sub r5,r11,r9 /* r5(nalign2) = 16 - (str2 & 15). */ -+ cmpld cr7,r7,r5 -+ beq cr7,L(same_aligned) -+ blt cr7,L(nalign1_min) -+ /* Swap r3 and r4, and r7 and r5 such that r3 and r7 hold the -+ pointer which is closer to the next 16B boundary so that only -+ one CHECK_N_BYTES is needed before entering the loop below. */ -+ mr r8,r4 -+ mr r4,r3 -+ mr r3,r8 -+ mr r12,r7 -+ mr r7,r5 -+ mr r5,r12 -+ crset 4*cr1+eq /* Set bit on swapping source pointers. */ -+ -+ .p2align 5 -+L(nalign1_min): -+ CHECK_N_BYTES(r3,r4,r7) -+ -+ .p2align 5 -+L(s1_aligned): -+ /* r9 and r5 is number of bytes to be read after and before -+ page boundary correspondingly. */ -+ sub r5,r5,r7 -+ subfic r9,r5,16 -+ /* Now let r7 hold the count of quadwords which can be -+ checked without crossing a page boundary. quadword offset is -+ (str2>>4)&0xFF. */ -+ rlwinm r7,r4,28,0xFF -+ /* Below check is required only for first iteration. For second -+ iteration and beyond, the new loop counter is always 255. */ -+ cmpldi r7,255 -+ beq L(L3) -+ /* Get the initial loop count by 255-((str2>>4)&0xFF). */ -+ subfic r11,r7,255 -+ -+ .p2align 5 -+L(L1): -+ mtctr r11 -+ -+ .p2align 5 -+L(L2): -+ COMPARE_16(v4,v5,0) /* Load 16B blocks using lxv. */ -+ addi r3,r3,16 -+ addi r4,r4,16 -+ bdnz L(L2) -+ /* Cross the page boundary of s2, carefully. */ -+ -+ .p2align 5 -+L(L3): -+ CHECK_N_BYTES(r3,r4,r5) -+ CHECK_N_BYTES(r3,r4,r9) -+ li r11,255 /* Load the new loop counter. */ -+ b L(L1) -+ -+ .p2align 5 -+L(same_aligned): -+ CHECK_N_BYTES(r3,r4,r7) -+ /* Align s1 to 32B and adjust s2 address. -+ Use lxvp only if both s1 and s2 are 32B aligned. */ -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ COMPARE_16(v4,v5,32) -+ COMPARE_16(v4,v5,48) -+ addi r3,r3,64 -+ addi r4,r4,64 -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ -+ clrldi r6,r3,59 -+ subfic r5,r6,32 -+ add r3,r3,r5 -+ add r4,r4,r5 -+ andi. r5,r4,0x1F -+ beq cr0,L(32B_aligned_loop) -+ -+ .p2align 5 -+L(16B_aligned_loop): -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ COMPARE_16(v4,v5,32) -+ COMPARE_16(v4,v5,48) -+ addi r3,r3,64 -+ addi r4,r4,64 -+ b L(16B_aligned_loop) -+ -+ /* Calculate and return the difference. */ -+L(different): -+ vctzlsbb r6,v7 -+ vextubrx r5,r6,v4 -+ vextubrx r4,r6,v5 -+ bt 4*cr1+eq,L(swapped) -+ subf r3,r4,r5 -+ blr -+ -+ /* If src pointers were swapped, then swap the -+ indices and calculate the return value. */ -+L(swapped): -+ subf r3,r5,r4 -+ blr -+ -+ .p2align 5 -+L(32B_aligned_loop): -+ COMPARE_32(v14,v16,0,tail1,tail2) -+ COMPARE_32(v14,v16,32,tail1,tail2) -+ COMPARE_32(v14,v16,64,tail1,tail2) -+ COMPARE_32(v14,v16,96,tail1,tail2) -+ addi r3,r3,128 -+ addi r4,r4,128 -+ b L(32B_aligned_loop) -+ -+L(tail1): TAIL(v15,v17) -+L(tail2): TAIL(v14,v16) -+ -+END (STRCMP) -+libc_hidden_builtin_def (strcmp) -diff --git a/sysdeps/powerpc/powerpc64/multiarch/Makefile b/sysdeps/powerpc/powerpc64/multiarch/Makefile -index e321ce54e0..818f287925 100644 ---- a/sysdeps/powerpc/powerpc64/multiarch/Makefile -+++ b/sysdeps/powerpc/powerpc64/multiarch/Makefile -@@ -32,7 +32,7 @@ sysdep_routines += memcpy-power8-cached memcpy-power7 memcpy-a2 memcpy-power6 \ - ifneq (,$(filter %le,$(config-machine))) - sysdep_routines += memcmp-power10 memcpy-power10 memmove-power10 memset-power10 \ - rawmemchr-power9 rawmemchr-power10 \ -- strcmp-power9 strncmp-power9 \ -+ strcmp-power9 strcmp-power10 strncmp-power9 \ - strcpy-power9 strcat-power10 stpcpy-power9 \ - strlen-power9 strncpy-power9 stpncpy-power9 strlen-power10 - endif -diff --git a/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c b/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c -index 016d05fd16..dde3bec709 100644 ---- a/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c -+++ b/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c -@@ -366,6 +366,10 @@ __libc_ifunc_impl_list (const char *name, struct libc_ifunc_impl *array, - /* Support sysdeps/powerpc/powerpc64/multiarch/strcmp.c. */ - IFUNC_IMPL (i, name, strcmp, - #ifdef __LITTLE_ENDIAN__ -+ IFUNC_IMPL_ADD (array, i, strcmp, -+ (hwcap2 & PPC_FEATURE2_ARCH_3_1) -+ && (hwcap & PPC_FEATURE_HAS_VSX), -+ __strcmp_power10) - IFUNC_IMPL_ADD (array, i, strcmp, - hwcap2 & PPC_FEATURE2_ARCH_3_00 - && hwcap & PPC_FEATURE_HAS_ALTIVEC, -diff --git a/sysdeps/powerpc/powerpc64/multiarch/strcmp-power10.S b/sysdeps/powerpc/powerpc64/multiarch/strcmp-power10.S -new file mode 100644 -index 0000000000..a4ee7fb53c ---- /dev/null -+++ b/sysdeps/powerpc/powerpc64/multiarch/strcmp-power10.S -@@ -0,0 +1,26 @@ -+/* Optimized strcmp implementation for POWER10/PPC64. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#if defined __LITTLE_ENDIAN__ && IS_IN (libc) -+#define STRCMP __strcmp_power10 -+ -+#undef libc_hidden_builtin_def -+#define libc_hidden_builtin_def(name) -+ -+#include -+#endif /* __LITTLE_ENDIAN__ && IS_IN (libc) */ -diff --git a/sysdeps/powerpc/powerpc64/multiarch/strcmp.c b/sysdeps/powerpc/powerpc64/multiarch/strcmp.c -index 7c77c084a7..3c636e3bbc 100644 ---- a/sysdeps/powerpc/powerpc64/multiarch/strcmp.c -+++ b/sysdeps/powerpc/powerpc64/multiarch/strcmp.c -@@ -29,12 +29,16 @@ extern __typeof (strcmp) __strcmp_power7 attribute_hidden; - extern __typeof (strcmp) __strcmp_power8 attribute_hidden; - # ifdef __LITTLE_ENDIAN__ - extern __typeof (strcmp) __strcmp_power9 attribute_hidden; -+extern __typeof (strcmp) __strcmp_power10 attribute_hidden; - # endif - - # undef strcmp - - libc_ifunc_redirected (__redirect_strcmp, strcmp, - # ifdef __LITTLE_ENDIAN__ -+ (hwcap2 & PPC_FEATURE2_ARCH_3_1 -+ && hwcap & PPC_FEATURE_HAS_VSX) -+ ? __strcmp_power10 : - (hwcap2 & PPC_FEATURE2_ARCH_3_00 - && hwcap & PPC_FEATURE_HAS_ALTIVEC) - ? __strcmp_power9 : - -commit 2dbf973fe03f9b8fd5a4740ee0af0d47afdd7bbd -Author: Sachin Monga -Date: Fri Nov 21 00:30:52 2025 -0500 - - ppc64le: Restore optimized strncmp for power10 - - This patch addresses the actual cause of CVE-2025-5745 - - The vector non-volatile registers are not used anymore for - 32 byte load and comparison operation - - Additionally, the assembler workaround used earlier for the - instruction lxvp is replaced with actual instruction. - - Signed-off-by: Sachin Monga - Co-authored-by: Paul Murphy - (cherry picked from commit 2ea943f7d487d6a4166658b32af7c5365889fc34) - -diff --git a/sysdeps/powerpc/powerpc64/le/power10/strncmp.S b/sysdeps/powerpc/powerpc64/le/power10/strncmp.S -new file mode 100644 -index 0000000000..6e09fcb7f2 ---- /dev/null -+++ b/sysdeps/powerpc/powerpc64/le/power10/strncmp.S -@@ -0,0 +1,252 @@ -+/* Optimized strncmp implementation for PowerPC64/POWER10. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+ -+/* Implements the function -+ -+ int [r3] strncmp (const char *s1 [r3], const char *s2 [r4], size_t [r5] n) -+ -+ The implementation uses unaligned doubleword access to avoid specialized -+ code paths depending of data alignment for first 32 bytes and uses -+ vectorised loops after that. */ -+ -+#ifndef STRNCMP -+# define STRNCMP strncmp -+#endif -+ -+#define COMPARE_16(vreg1,vreg2,offset) \ -+ lxv vreg1+32,offset(r3); \ -+ lxv vreg2+32,offset(r4); \ -+ vcmpnezb. v7,vreg1,vreg2; \ -+ bne cr6,L(different); \ -+ cmpldi cr7,r5,16; \ -+ ble cr7,L(ret0); \ -+ addi r5,r5,-16; -+ -+#define COMPARE_32(vreg1,vreg2,offset,label1,label2) \ -+ lxvp vreg1+32,offset(r3); \ -+ lxvp vreg2+32,offset(r4); \ -+ vcmpnezb. v7,vreg1+1,vreg2+1; \ -+ bne cr6,L(label1); \ -+ vcmpnezb. v7,vreg1,vreg2; \ -+ bne cr6,L(label2); \ -+ cmpldi cr7,r5,32; \ -+ ble cr7,L(ret0); \ -+ addi r5,r5,-32; -+ -+#define TAIL_FIRST_16B(vreg1,vreg2) \ -+ vctzlsbb r6,v7; \ -+ cmpld cr7,r5,r6; \ -+ ble cr7,L(ret0); \ -+ vextubrx r5,r6,vreg1; \ -+ vextubrx r4,r6,vreg2; \ -+ subf r3,r4,r5; \ -+ blr; -+ -+#define TAIL_SECOND_16B(vreg1,vreg2) \ -+ vctzlsbb r6,v7; \ -+ addi r0,r6,16; \ -+ cmpld cr7,r5,r0; \ -+ ble cr7,L(ret0); \ -+ vextubrx r5,r6,vreg1; \ -+ vextubrx r4,r6,vreg2; \ -+ subf r3,r4,r5; \ -+ blr; -+ -+#define CHECK_N_BYTES(reg1,reg2,len_reg) \ -+ sldi r6,len_reg,56; \ -+ lxvl 32+v4,reg1,r6; \ -+ lxvl 32+v5,reg2,r6; \ -+ add reg1,reg1,len_reg; \ -+ add reg2,reg2,len_reg; \ -+ vcmpnezb v7,v4,v5; \ -+ vctzlsbb r6,v7; \ -+ cmpld cr7,r6,len_reg; \ -+ blt cr7,L(different); \ -+ cmpld cr7,r5,len_reg; \ -+ ble cr7,L(ret0); \ -+ sub r5,r5,len_reg; \ -+ -+ .machine power10 -+ENTRY_TOCLESS (STRNCMP, 4) -+ /* Check if size is 0. */ -+ cmpdi cr0,r5,0 -+ beq cr0,L(ret0) -+ andi. r7,r3,4095 -+ andi. r8,r4,4095 -+ cmpldi cr0,r7,4096-16 -+ cmpldi cr1,r8,4096-16 -+ bgt cr0,L(crosses) -+ bgt cr1,L(crosses) -+ COMPARE_16(v4,v5,0) -+ addi r3,r3,16 -+ addi r4,r4,16 -+ -+L(crosses): -+ andi. r7,r3,15 -+ subfic r7,r7,16 /* r7(nalign1) = 16 - (str1 & 15). */ -+ andi. r9,r4,15 -+ subfic r8,r9,16 /* r8(nalign2) = 16 - (str2 & 15). */ -+ cmpld cr7,r7,r8 -+ beq cr7,L(same_aligned) -+ blt cr7,L(nalign1_min) -+ -+ /* nalign2 is minimum and s2 pointer is aligned. */ -+ CHECK_N_BYTES(r3,r4,r8) -+ /* Are we on the 64B hunk which crosses a page? */ -+ andi. r10,r3,63 /* Determine offset into 64B hunk. */ -+ andi. r8,r3,15 /* The offset into the 16B hunk. */ -+ neg r7,r3 -+ andi. r9,r7,15 /* Number of bytes after a 16B cross. */ -+ rlwinm. r7,r7,26,0x3F /* ((r4-4096))>>6&63. */ -+ beq L(compare_64_pagecross) -+ mtctr r7 -+ b L(compare_64B_unaligned) -+ -+ /* nalign1 is minimum and s1 pointer is aligned. */ -+L(nalign1_min): -+ CHECK_N_BYTES(r3,r4,r7) -+ /* Are we on the 64B hunk which crosses a page? */ -+ andi. r10,r4,63 /* Determine offset into 64B hunk. */ -+ andi. r8,r4,15 /* The offset into the 16B hunk. */ -+ neg r7,r4 -+ andi. r9,r7,15 /* Number of bytes after a 16B cross. */ -+ rlwinm. r7,r7,26,0x3F /* ((r4-4096))>>6&63. */ -+ beq L(compare_64_pagecross) -+ mtctr r7 -+ -+ .p2align 5 -+L(compare_64B_unaligned): -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ COMPARE_16(v4,v5,32) -+ COMPARE_16(v4,v5,48) -+ addi r3,r3,64 -+ addi r4,r4,64 -+ bdnz L(compare_64B_unaligned) -+ -+ /* Cross the page boundary of s2, carefully. Only for first -+ iteration we have to get the count of 64B blocks to be checked. -+ From second iteration and beyond, loop counter is always 63. */ -+L(compare_64_pagecross): -+ li r11, 63 -+ mtctr r11 -+ cmpldi r10,16 -+ ble L(cross_4) -+ cmpldi r10,32 -+ ble L(cross_3) -+ cmpldi r10,48 -+ ble L(cross_2) -+L(cross_1): -+ CHECK_N_BYTES(r3,r4,r9) -+ CHECK_N_BYTES(r3,r4,r8) -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ COMPARE_16(v4,v5,32) -+ addi r3,r3,48 -+ addi r4,r4,48 -+ b L(compare_64B_unaligned) -+L(cross_2): -+ COMPARE_16(v4,v5,0) -+ addi r3,r3,16 -+ addi r4,r4,16 -+ CHECK_N_BYTES(r3,r4,r9) -+ CHECK_N_BYTES(r3,r4,r8) -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ addi r3,r3,32 -+ addi r4,r4,32 -+ b L(compare_64B_unaligned) -+L(cross_3): -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ addi r3,r3,32 -+ addi r4,r4,32 -+ CHECK_N_BYTES(r3,r4,r9) -+ CHECK_N_BYTES(r3,r4,r8) -+ COMPARE_16(v4,v5,0) -+ addi r3,r3,16 -+ addi r4,r4,16 -+ b L(compare_64B_unaligned) -+L(cross_4): -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ COMPARE_16(v4,v5,32) -+ addi r3,r3,48 -+ addi r4,r4,48 -+ CHECK_N_BYTES(r3,r4,r9) -+ CHECK_N_BYTES(r3,r4,r8) -+ b L(compare_64B_unaligned) -+ -+L(same_aligned): -+ CHECK_N_BYTES(r3,r4,r7) -+ /* Align s1 to 32B and adjust s2 address. -+ Use lxvp only if both s1 and s2 are 32B aligned. */ -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ COMPARE_16(v4,v5,32) -+ COMPARE_16(v4,v5,48) -+ addi r3,r3,64 -+ addi r4,r4,64 -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ addi r5,r5,32 -+ -+ clrldi r6,r3,59 -+ subfic r7,r6,32 -+ add r3,r3,r7 -+ add r4,r4,r7 -+ subf r5,r7,r5 -+ andi. r7,r4,0x1F -+ beq cr0,L(32B_aligned_loop) -+ -+ .p2align 5 -+L(16B_aligned_loop): -+ COMPARE_16(v4,v5,0) -+ COMPARE_16(v4,v5,16) -+ COMPARE_16(v4,v5,32) -+ COMPARE_16(v4,v5,48) -+ addi r3,r3,64 -+ addi r4,r4,64 -+ b L(16B_aligned_loop) -+ -+ /* Calculate and return the difference. */ -+L(different): -+ TAIL_FIRST_16B(v4,v5) -+ -+ .p2align 5 -+L(32B_aligned_loop): -+ COMPARE_32(v14,v16,0,tail1,tail2) -+ COMPARE_32(v14,v16,32,tail1,tail2) -+ COMPARE_32(v14,v16,64,tail1,tail2) -+ COMPARE_32(v14,v16,96,tail1,tail2) -+ addi r3,r3,128 -+ addi r4,r4,128 -+ b L(32B_aligned_loop) -+ -+L(tail1): TAIL_FIRST_16B(v15,v17) -+L(tail2): TAIL_SECOND_16B(v14,v16) -+ -+ .p2align 5 -+L(ret0): -+ li r3,0 -+ blr -+ -+END(STRNCMP) -+libc_hidden_builtin_def(strncmp) -diff --git a/sysdeps/powerpc/powerpc64/multiarch/Makefile b/sysdeps/powerpc/powerpc64/multiarch/Makefile -index 818f287925..c9178223a8 100644 ---- a/sysdeps/powerpc/powerpc64/multiarch/Makefile -+++ b/sysdeps/powerpc/powerpc64/multiarch/Makefile -@@ -32,7 +32,7 @@ sysdep_routines += memcpy-power8-cached memcpy-power7 memcpy-a2 memcpy-power6 \ - ifneq (,$(filter %le,$(config-machine))) - sysdep_routines += memcmp-power10 memcpy-power10 memmove-power10 memset-power10 \ - rawmemchr-power9 rawmemchr-power10 \ -- strcmp-power9 strcmp-power10 strncmp-power9 \ -+ strcmp-power9 strcmp-power10 strncmp-power9 strncmp-power10 \ - strcpy-power9 strcat-power10 stpcpy-power9 \ - strlen-power9 strncpy-power9 stpncpy-power9 strlen-power10 - endif -diff --git a/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c b/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c -index dde3bec709..f2b9cccde3 100644 ---- a/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c -+++ b/sysdeps/powerpc/powerpc64/multiarch/ifunc-impl-list.c -@@ -164,6 +164,9 @@ __libc_ifunc_impl_list (const char *name, struct libc_ifunc_impl *array, - /* Support sysdeps/powerpc/powerpc64/multiarch/strncmp.c. */ - IFUNC_IMPL (i, name, strncmp, - #ifdef __LITTLE_ENDIAN__ -+ IFUNC_IMPL_ADD (array, i, strncmp, hwcap2 & PPC_FEATURE2_ARCH_3_1 -+ && hwcap & PPC_FEATURE_HAS_VSX, -+ __strncmp_power10) - IFUNC_IMPL_ADD (array, i, strncmp, hwcap2 & PPC_FEATURE2_ARCH_3_00 - && hwcap & PPC_FEATURE_HAS_ALTIVEC, - __strncmp_power9) -diff --git a/sysdeps/powerpc/powerpc64/multiarch/strncmp-power10.S b/sysdeps/powerpc/powerpc64/multiarch/strncmp-power10.S -new file mode 100644 -index 0000000000..bb25bc75b8 ---- /dev/null -+++ b/sysdeps/powerpc/powerpc64/multiarch/strncmp-power10.S -@@ -0,0 +1,25 @@ -+/* Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#if defined __LITTLE_ENDIAN__ && IS_IN (libc) -+#define STRNCMP __strncmp_power10 -+ -+#undef libc_hidden_builtin_def -+#define libc_hidden_builtin_def(name) -+ -+#include -+#endif -diff --git a/sysdeps/powerpc/powerpc64/multiarch/strncmp.c b/sysdeps/powerpc/powerpc64/multiarch/strncmp.c -index 4cfe27fa45..0a664a620d 100644 ---- a/sysdeps/powerpc/powerpc64/multiarch/strncmp.c -+++ b/sysdeps/powerpc/powerpc64/multiarch/strncmp.c -@@ -29,6 +29,7 @@ extern __typeof (strncmp) __strncmp_ppc attribute_hidden; - extern __typeof (strncmp) __strncmp_power8 attribute_hidden; - # ifdef __LITTLE_ENDIAN__ - extern __typeof (strncmp) __strncmp_power9 attribute_hidden; -+extern __typeof (strncmp) __strncmp_power10 attribute_hidden; - # endif - # undef strncmp - -@@ -36,6 +37,9 @@ extern __typeof (strncmp) __strncmp_power9 attribute_hidden; - ifunc symbol properly. */ - libc_ifunc_redirected (__redirect_strncmp, strncmp, - # ifdef __LITTLE_ENDIAN__ -+ (hwcap2 & PPC_FEATURE2_ARCH_3_1 -+ && hwcap & PPC_FEATURE_HAS_VSX) -+ ? __strncmp_power10 : - (hwcap2 & PPC_FEATURE2_ARCH_3_00 - && hwcap & PPC_FEATURE_HAS_ALTIVEC) - ? __strncmp_power9 : - -commit 8aaf4b732d7650c2db3beb4dc8bb70eab5b022c3 -Author: Sachin Monga -Date: Thu Nov 27 03:28:17 2025 -0500 - - ppc64le: Power 10 rawmemchr clobbers v20 (bug #33091) - - Replace non-volatile(v20) by volatile(v17) - since v20 is not restored - - Reviewed-by: Peter Bergner - (cherry picked from commit b59799f14f97f697c3a36b4380bd4ce2fbe65f11) - -diff --git a/sysdeps/powerpc/powerpc64/le/power10/strlen.S b/sysdeps/powerpc/powerpc64/le/power10/strlen.S -index ec644d5bff..29a5a7d960 100644 ---- a/sysdeps/powerpc/powerpc64/le/power10/strlen.S -+++ b/sysdeps/powerpc/powerpc64/le/power10/strlen.S -@@ -31,7 +31,7 @@ - # define FUNCNAME RAWMEMCHR - # endif - # define MCOUNT_NARGS 2 --# define VREG_ZERO v20 -+# define VREG_ZERO v17 - # define OFF_START_LOOP 256 - # define RAWMEMCHR_SUBTRACT_VECTORS \ - vsububm v4,v4,v18; \ - -commit b11411fe2ee7a8f3c3a2c1ee99c1729adb9a0efe -Author: Yury Khrustalev -Date: Thu Nov 6 12:57:58 2025 +0000 - - posix: Fix invalid flags test for p{write,read}v2 - - Two tests fail from time to time when a new flag is added for the - p{write,read}v2 functions in a new Linux kernel: - - - misc/tst-preadvwritev2 - - misc/tst-preadvwritev64v2 - - This disrupts when testing Glibc on a system with a newer kernel - and it seems we can try improve testing for invalid flags setting - all the bits that are not supposed to be supported (rather than - setting only the next unsupported bit). - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 58a31b4316f1f687184eb147ffa1c676bc6a190e) - -diff --git a/misc/tst-preadvwritev2-common.c b/misc/tst-preadvwritev2-common.c -index ff1007d6d2..5182fcdce0 100644 ---- a/misc/tst-preadvwritev2-common.c -+++ b/misc/tst-preadvwritev2-common.c -@@ -109,9 +109,8 @@ do_test_with_invalid_iov (void) - static void - do_test_with_invalid_flags (void) - { -- /* Set the next bit from the mask of all supported flags. */ -- int invalid_flag = RWF_SUPPORTED != 0 ? __builtin_clz (RWF_SUPPORTED) : 2; -- invalid_flag = 0x1 << ((sizeof (int) * CHAR_BIT) - invalid_flag); -+ /* Set all the bits that are not used by the supported flags. */ -+ int invalid_flag = ~RWF_SUPPORTED; - - char buf[32]; - const struct iovec vec = { .iov_base = buf, .iov_len = sizeof (buf) }; - -commit efdf4c0c879590109778244046f84a80a4bf8fee -Author: DJ Delorie -Date: Wed Oct 15 21:37:56 2025 -0400 - - sprof: check pread size and offset for overflow - - Add a bit of descriptive paranoia to the values we read from - the ELF headers and use to access data. - - Reviewed-by: Collin Funk - (cherry picked from commit 324084649b2da2f6840e3a1b84159a4e9a9e9a74) - -diff --git a/elf/sprof.c b/elf/sprof.c -index c82c7c9db6..e9d2a66a4f 100644 ---- a/elf/sprof.c -+++ b/elf/sprof.c -@@ -38,6 +38,7 @@ - #include - #include - #include -+#include - - /* Get libc version number. */ - #include "../version.h" -@@ -410,6 +411,7 @@ load_shobj (const char *name) - int fd; - ElfW(Shdr) *shdr; - size_t pagesize = getpagesize (); -+ struct stat st; - - /* Since we use dlopen() we must be prepared to work around the sometimes - strange lookup rules for the shared objects. If we have a file foo.so -@@ -550,14 +552,39 @@ load_shobj (const char *name) - error (EXIT_FAILURE, errno, _("Reopening shared object `%s' failed"), - map->l_name); - -+ if (fstat (fd, &st) < 0) -+ error (EXIT_FAILURE, errno, _("stat(%s) failure"), map->l_name); -+ -+ /* We're depending on data that's being read from the file, so be a -+ bit paranoid here and make sure the requests are reasonable - -+ i.e. both size and offset are nonnegative and smaller than the -+ file size, as well as the offset of the end of the data. PREAD -+ would have failed anyway, but this is more robust and explains -+ what happened better. Note that SZ must be unsigned and OFF may -+ be signed or unsigned. */ -+#define PCHECK(sz1,off1) { \ -+ size_t sz = sz1, end_off; \ -+ off_t off = off1; \ -+ if (sz > st.st_size \ -+ || off < 0 || off > st.st_size \ -+ || INT_ADD_WRAPV (sz, off, &end_off) \ -+ || end_off > st.st_size) \ -+ error (EXIT_FAILURE, ERANGE, \ -+ _("read outside of file extents %zu + %zd > %zu"), \ -+ sz, off, st.st_size); \ -+ } -+ - /* Map the section header. */ - size_t size = ehdr->e_shnum * sizeof (ElfW(Shdr)); - shdr = (ElfW(Shdr) *) alloca (size); -+ PCHECK (size, ehdr->e_shoff); - if (pread (fd, shdr, size, ehdr->e_shoff) != size) - error (EXIT_FAILURE, errno, _("reading of section headers failed")); - - /* Get the section header string table. */ - char *shstrtab = (char *) alloca (shdr[ehdr->e_shstrndx].sh_size); -+ PCHECK (shdr[ehdr->e_shstrndx].sh_size, -+ shdr[ehdr->e_shstrndx].sh_offset); - if (pread (fd, shstrtab, shdr[ehdr->e_shstrndx].sh_size, - shdr[ehdr->e_shstrndx].sh_offset) - != shdr[ehdr->e_shstrndx].sh_size) -@@ -585,6 +612,7 @@ load_shobj (const char *name) - size_t size = debuglink_entry->sh_size; - char *debuginfo_fname = (char *) alloca (size + 1); - debuginfo_fname[size] = '\0'; -+ PCHECK (size, debuglink_entry->sh_offset); - if (pread (fd, debuginfo_fname, size, debuglink_entry->sh_offset) - != size) - { -@@ -638,21 +666,32 @@ load_shobj (const char *name) - if (fd2 != -1) - { - ElfW(Ehdr) ehdr2; -+ struct stat st; -+ -+ if (fstat (fd2, &st) < 0) -+ error (EXIT_FAILURE, errno, _("stat(%s) failure"), workbuf); - - /* Read the ELF header. */ -+ PCHECK (sizeof (ehdr2), 0); - if (pread (fd2, &ehdr2, sizeof (ehdr2), 0) != sizeof (ehdr2)) - error (EXIT_FAILURE, errno, - _("reading of ELF header failed")); - - /* Map the section header. */ -- size_t size = ehdr2.e_shnum * sizeof (ElfW(Shdr)); -+ size_t size; -+ if (INT_MULTIPLY_WRAPV (ehdr2.e_shnum, sizeof (ElfW(Shdr)), &size)) -+ error (EXIT_FAILURE, errno, _("too many section headers")); -+ - ElfW(Shdr) *shdr2 = (ElfW(Shdr) *) alloca (size); -+ PCHECK (size, ehdr2.e_shoff); - if (pread (fd2, shdr2, size, ehdr2.e_shoff) != size) - error (EXIT_FAILURE, errno, - _("reading of section headers failed")); - - /* Get the section header string table. */ - shstrtab = (char *) alloca (shdr2[ehdr2.e_shstrndx].sh_size); -+ PCHECK (shdr2[ehdr2.e_shstrndx].sh_size, -+ shdr2[ehdr2.e_shstrndx].sh_offset); - if (pread (fd2, shstrtab, shdr2[ehdr2.e_shstrndx].sh_size, - shdr2[ehdr2.e_shstrndx].sh_offset) - != shdr2[ehdr2.e_shstrndx].sh_size) - -commit 2a0873aa81446149c6065237e1dc2511201bef88 -Author: Collin Funk -Date: Wed Oct 22 01:51:09 2025 -0700 - - sprof: fix -Wformat warnings on 32-bit hosts - - Reviewed-by: H.J. Lu - (cherry picked from commit 9681f645ba20fc3c18eb12ffebf94e3df1f888e3) - -diff --git a/elf/sprof.c b/elf/sprof.c -index e9d2a66a4f..513e0470b2 100644 ---- a/elf/sprof.c -+++ b/elf/sprof.c -@@ -570,8 +570,8 @@ load_shobj (const char *name) - || INT_ADD_WRAPV (sz, off, &end_off) \ - || end_off > st.st_size) \ - error (EXIT_FAILURE, ERANGE, \ -- _("read outside of file extents %zu + %zd > %zu"), \ -- sz, off, st.st_size); \ -+ _("read outside of file extents %zu + %jd > %jd"), \ -+ sz, (intmax_t) off, (intmax_t) st.st_size); \ - } - - /* Map the section header. */ - -commit 8dfb84ad4efbc39c7a7d9efdff6f6ac9017e0a53 -Author: Florian Weimer -Date: Thu Nov 6 14:33:22 2025 +0100 - - support: Fix FILE * leak in check_for_unshare_hints in test-container - - The file opened via fopen is never closed. - - (cherry picked from commit 20a2a756089eacd7e7f4c02e381e82b5d0e40a2c) - -diff --git a/support/test-container.c b/support/test-container.c -index 1c40ab377f..d78139622f 100644 ---- a/support/test-container.c -+++ b/support/test-container.c -@@ -705,6 +705,7 @@ check_for_unshare_hints (int require_pidns) - - val = -1; /* Sentinel. */ - int cnt = fscanf (f, "%d", &val); -+ fclose (f); - if (cnt == 1 && val != files[i].bad_value) - continue; - - -commit a1d3294a5bed821aece03994ab4e72c8b822a962 -Author: Florian Weimer -Date: Thu Nov 6 14:49:21 2025 +0100 - - support: Exit on consistency check failure in resolv_response_add_name - - Using TEST_VERIFY (crname_target != crname) instructs some analysis - tools that crname_target == crname might hold. Under this assumption, - they report a use-after-free for crname_target->offset below, caused - by the previous free (crname). - - Reviewed-by: Collin Funk - (cherry picked from commit b64335ff111c071fde61aec1c1a8460afb3d16d4) - -diff --git a/support/resolv_test.c b/support/resolv_test.c -index ab37d3d58c..29e59da958 100644 ---- a/support/resolv_test.c -+++ b/support/resolv_test.c -@@ -326,7 +326,7 @@ resolv_response_add_name (struct resolv_response_builder *b, - crname_target = *ptr; - else - crname_target = NULL; -- TEST_VERIFY (crname_target != crname); -+ TEST_VERIFY_EXIT (crname_target != crname); - /* Not added to the tree. */ - free (crname); - } - -commit f122d0b4d145814869bf10c56db1d971bcba55c5 -Author: Sunil K Pandey -Date: Tue Dec 9 08:57:44 2025 -0800 - - nptl: Optimize trylock for high cache contention workloads (BZ #33704) - - Check lock availability before acquisition to reduce cache line - bouncing. Significantly improves trylock throughput on multi-core - systems under heavy contention. - - Tested on x86_64. - - Fixes BZ #33704. - - Co-authored-by: Alex M Wells - Reviewed-by: Wilco Dijkstra - (cherry picked from commit 63716823dbad9482e09972907ae98e9cb00f9b86) - -diff --git a/nptl/pthread_mutex_trylock.c b/nptl/pthread_mutex_trylock.c -index dbb8fcc754..392619021b 100644 ---- a/nptl/pthread_mutex_trylock.c -+++ b/nptl/pthread_mutex_trylock.c -@@ -48,7 +48,8 @@ ___pthread_mutex_trylock (pthread_mutex_t *mutex) - return 0; - } - -- if (lll_trylock (mutex->__data.__lock) == 0) -+ if (atomic_load_relaxed (&(mutex->__data.__lock)) == 0 -+ && lll_trylock (mutex->__data.__lock) == 0) - { - /* Record the ownership. */ - mutex->__data.__owner = id; -@@ -71,7 +72,10 @@ ___pthread_mutex_trylock (pthread_mutex_t *mutex) - /*FALL THROUGH*/ - case PTHREAD_MUTEX_ADAPTIVE_NP: - case PTHREAD_MUTEX_ERRORCHECK_NP: -- if (lll_trylock (mutex->__data.__lock) != 0) -+ /* Mutex type is already loaded, lock check overhead should -+ be minimal. */ -+ if (atomic_load_relaxed (&(mutex->__data.__lock)) != 0 -+ || lll_trylock (mutex->__data.__lock) != 0) - break; - - /* Record the ownership. */ - -commit b0ec8fb689df862171f0f78994a3bdeb51313545 -Author: Siddhesh Poyarekar -Date: Thu Jan 15 06:06:40 2026 -0500 - - memalign: reinstate alignment overflow check (CVE-2026-0861) - - The change to cap valid sizes to PTRDIFF_MAX inadvertently dropped the - overflow check for alignment in memalign functions, _mid_memalign and - _int_memalign. Reinstate the overflow check in _int_memalign, aligned - with the PTRDIFF_MAX change since that is directly responsible for the - CVE. The missing _mid_memalign check is not relevant (and does not have - a security impact) and may need a different approach to fully resolve, - so it has been omitted. - - CVE-Id: CVE-2026-0861 - Vulnerable-Commit: 9bf8e29ca136094f73f69f725f15c51facc97206 - Reported-by: Igor Morgenstern, Aisle Research - Fixes: BZ #33796 - Reviewed-by: Wilco Dijkstra - Signed-off-by: Siddhesh Poyarekar - (cherry picked from commit c9188d333717d3ceb7e3020011651f424f749f93) - -diff --git a/malloc/malloc.c b/malloc/malloc.c -index 5f3e701fd1..1d5aa304d3 100644 ---- a/malloc/malloc.c -+++ b/malloc/malloc.c -@@ -5167,7 +5167,7 @@ _int_memalign (mstate av, size_t alignment, size_t bytes) - INTERNAL_SIZE_T size; - - nb = checked_request2size (bytes); -- if (nb == 0) -+ if (nb == 0 || alignment > PTRDIFF_MAX) - { - __set_errno (ENOMEM); - return NULL; -@@ -5183,7 +5183,10 @@ _int_memalign (mstate av, size_t alignment, size_t bytes) - we don't find anything in those bins, the common malloc code will - scan starting at 2x. */ - -- /* Call malloc with worst case padding to hit alignment. */ -+ /* Call malloc with worst case padding to hit alignment. ALIGNMENT is a -+ power of 2, so it tops out at (PTRDIFF_MAX >> 1) + 1, leaving plenty of -+ space to add MINSIZE and whatever checked_request2size adds to BYTES to -+ get NB. Consequently, total below also does not overflow. */ - m = (char *) (_int_malloc (av, nb + alignment + MINSIZE)); - - if (m == NULL) -diff --git a/malloc/tst-malloc-too-large.c b/malloc/tst-malloc-too-large.c -index a548a37b46..a1bda673a3 100644 ---- a/malloc/tst-malloc-too-large.c -+++ b/malloc/tst-malloc-too-large.c -@@ -152,7 +152,6 @@ test_large_allocations (size_t size) - } - - --static long pagesize; - - /* This function tests the following aligned memory allocation functions - using several valid alignments and precedes each allocation test with a -@@ -171,8 +170,8 @@ test_large_aligned_allocations (size_t size) - - /* All aligned memory allocation functions expect an alignment that is a - power of 2. Given this, we test each of them with every valid -- alignment from 1 thru PAGESIZE. */ -- for (align = 1; align <= pagesize; align *= 2) -+ alignment for the type of ALIGN, i.e. until it wraps to 0. */ -+ for (align = 1; align > 0; align <<= 1) - { - test_setup (); - #if __GNUC_PREREQ (7, 0) -@@ -265,11 +264,6 @@ do_test (void) - DIAG_IGNORE_NEEDS_COMMENT (7, "-Walloc-size-larger-than="); - #endif - -- /* Aligned memory allocation functions need to be tested up to alignment -- size equivalent to page size, which should be a power of 2. */ -- pagesize = sysconf (_SC_PAGESIZE); -- TEST_VERIFY_EXIT (powerof2 (pagesize)); -- - /* Loop 1: Ensure that all allocations with SIZE close to SIZE_MAX, i.e. - in the range (SIZE_MAX - 2^14, SIZE_MAX], fail. - - -commit 453e6b8dbab935257eb0802b0c97bca6b67ba30e -Author: Carlos O'Donell -Date: Thu Jan 15 15:09:38 2026 -0500 - - resolv: Fix NSS DNS backend for getnetbyaddr (CVE-2026-0915) - - The default network value of zero for net was never tested for and - results in a DNS query constructed from uninitialized stack bytes. - The solution is to provide a default query for the case where net - is zero. - - Adding a test case for this was straight forward given the existence of - tst-resolv-network and if the test is added without the fix you observe - this failure: - - FAIL: resolv/tst-resolv-network - original exit status 1 - error: tst-resolv-network.c:174: invalid QNAME: \146\218\129\128 - error: 1 test failures - - With a random QNAME resulting from the use of uninitialized stack bytes. - - After the fix the test passes. - - Additionally verified using wireshark before and after to ensure - on-the-wire bytes for the DNS query were as expected. - - No regressions on x86_64. - - Reviewed-by: Florian Weimer - (cherry picked from commit e56ff82d5034ec66c6a78f517af6faa427f65b0b) - -diff --git a/resolv/nss_dns/dns-network.c b/resolv/nss_dns/dns-network.c -index 519f8422ca..e14e959d7c 100644 ---- a/resolv/nss_dns/dns-network.c -+++ b/resolv/nss_dns/dns-network.c -@@ -207,6 +207,10 @@ _nss_dns_getnetbyaddr_r (uint32_t net, int type, struct netent *result, - sprintf (qbuf, "%u.%u.%u.%u.in-addr.arpa", net_bytes[3], net_bytes[2], - net_bytes[1], net_bytes[0]); - break; -+ default: -+ /* Default network (net is originally zero). */ -+ strcpy (qbuf, "0.0.0.0.in-addr.arpa"); -+ break; - } - - net_buffer.buf = orig_net_buffer = (querybuf *) alloca (1024); -diff --git a/resolv/tst-resolv-network.c b/resolv/tst-resolv-network.c -index d9f69649d0..181be80835 100644 ---- a/resolv/tst-resolv-network.c -+++ b/resolv/tst-resolv-network.c -@@ -46,6 +46,9 @@ handle_code (const struct resolv_response_context *ctx, - { - switch (code) - { -+ case 0: -+ send_ptr (b, qname, qclass, qtype, "0.in-addr.arpa"); -+ break; - case 1: - send_ptr (b, qname, qclass, qtype, "1.in-addr.arpa"); - break; -@@ -265,6 +268,9 @@ do_test (void) - "error: TRY_AGAIN\n"); - - /* Lookup by address, success cases. */ -+ check_reverse (0, -+ "name: 0.in-addr.arpa\n" -+ "net: 0x00000000\n"); - check_reverse (1, - "name: 1.in-addr.arpa\n" - "net: 0x00000001\n"); - -commit cbf39c26b25801e9bc88499b4fd361ac172d4125 -Author: Adhemerval Zanella -Date: Thu Jan 15 10:32:19 2026 -0300 - - posix: Reset wordexp_t fields with WRDE_REUSE (CVE-2025-15281 / BZ 33814) - - The wordexp fails to properly initialize the input wordexp_t when - WRDE_REUSE is used. The wordexp_t struct is properly freed, but - reuses the old wc_wordc value and updates the we_wordv in the - wrong position. A later wordfree will then call free with an - invalid pointer. - - Checked on x86_64-linux-gnu and i686-linux-gnu. - - Reviewed-by: Carlos O'Donell - (cherry picked from commit 80cc58ea2de214f85b0a1d902a3b668ad2ecb302) - -diff --git a/NEWS b/NEWS -index ed3c114c7a..7e7e1930dd 100644 ---- a/NEWS -+++ b/NEWS -@@ -16,6 +16,8 @@ The following bugs were resolved with this release: - [33356] nptl: creating thread stack with guardsize 0 can erroneously - conclude MADV_GUARD_INSTALL is available - [33361] nss: Group merge does not react to ERANGE during merge -+ [33814] glob: wordexp with WRDE_REUSE and WRDE_APPEND may return -+ uninitialized memory - - Version 2.42 - -diff --git a/posix/Makefile b/posix/Makefile -index a36e5decd3..1ea86efcc1 100644 ---- a/posix/Makefile -+++ b/posix/Makefile -@@ -327,6 +327,7 @@ tests := \ - tst-wait4 \ - tst-waitid \ - tst-wordexp-nocmd \ -+ tst-wordexp-reuse \ - tstgetopt \ - # tests - -@@ -457,6 +458,8 @@ generated += \ - tst-rxspencer-no-utf8.mtrace \ - tst-vfork3-mem.out \ - tst-vfork3.mtrace \ -+ tst-wordexp-reuse-mem.out \ -+ tst-wordexp-reuse.mtrace \ - # generated - endif - endif -@@ -492,6 +495,7 @@ tests-special += \ - $(objpfx)tst-pcre-mem.out \ - $(objpfx)tst-rxspencer-no-utf8-mem.out \ - $(objpfx)tst-vfork3-mem.out \ -+ $(objpfx)tst-wordexp-reuse.out \ - # tests-special - endif - endif -@@ -775,3 +779,10 @@ $(objpfx)posix-conf-vars-def.h: $(..)scripts/gen-posix-conf-vars.awk \ - $(make-target-directory) - $(AWK) -f $(filter-out Makefile, $^) > $@.tmp - mv -f $@.tmp $@ -+ -+tst-wordexp-reuse-ENV += MALLOC_TRACE=$(objpfx)tst-wordexp-reuse.mtrace \ -+ LD_PRELOAD=$(common-objpfx)/malloc/libc_malloc_debug.so -+ -+$(objpfx)tst-wordexp-reuse-mem.out: $(objpfx)tst-wordexp-reuse.out -+ $(common-objpfx)malloc/mtrace $(objpfx)tst-wordexp-reuse.mtrace > $@; \ -+ $(evaluate-test) -diff --git a/posix/tst-wordexp-reuse.c b/posix/tst-wordexp-reuse.c -new file mode 100644 -index 0000000000..3926b9f557 ---- /dev/null -+++ b/posix/tst-wordexp-reuse.c -@@ -0,0 +1,89 @@ -+/* Test for wordexp with WRDE_REUSE flag. -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+ -+#include -+ -+static int -+do_test (void) -+{ -+ mtrace (); -+ -+ { -+ wordexp_t p = { 0 }; -+ TEST_COMPARE (wordexp ("one", &p, 0), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[0], "one"); -+ TEST_COMPARE (wordexp ("two", &p, WRDE_REUSE), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[0], "two"); -+ wordfree (&p); -+ } -+ -+ { -+ wordexp_t p = { .we_offs = 2 }; -+ TEST_COMPARE (wordexp ("one", &p, 0), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[0], "one"); -+ TEST_COMPARE (wordexp ("two", &p, WRDE_REUSE | WRDE_DOOFFS), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[p.we_offs + 0], "two"); -+ wordfree (&p); -+ } -+ -+ { -+ wordexp_t p = { 0 }; -+ TEST_COMPARE (wordexp ("one", &p, 0), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[0], "one"); -+ TEST_COMPARE (wordexp ("two", &p, WRDE_REUSE | WRDE_APPEND), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[0], "two"); -+ wordfree (&p); -+ } -+ -+ { -+ wordexp_t p = { .we_offs = 2 }; -+ TEST_COMPARE (wordexp ("one", &p, WRDE_DOOFFS), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[p.we_offs + 0], "one"); -+ TEST_COMPARE (wordexp ("two", &p, WRDE_REUSE -+ | WRDE_DOOFFS), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[p.we_offs + 0], "two"); -+ wordfree (&p); -+ } -+ -+ { -+ wordexp_t p = { .we_offs = 2 }; -+ TEST_COMPARE (wordexp ("one", &p, WRDE_DOOFFS), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[p.we_offs + 0], "one"); -+ TEST_COMPARE (wordexp ("two", &p, WRDE_REUSE -+ | WRDE_DOOFFS | WRDE_APPEND), 0); -+ TEST_COMPARE (p.we_wordc, 1); -+ TEST_COMPARE_STRING (p.we_wordv[p.we_offs + 0], "two"); -+ wordfree (&p); -+ } -+ -+ return 0; -+} -+ -+#include -diff --git a/posix/wordexp.c b/posix/wordexp.c -index a69b732801..9df4bb7424 100644 ---- a/posix/wordexp.c -+++ b/posix/wordexp.c -@@ -2216,7 +2216,9 @@ wordexp (const char *words, wordexp_t *pwordexp, int flags) - { - /* Minimal implementation of WRDE_REUSE for now */ - wordfree (pwordexp); -+ old_word.we_wordc = 0; - old_word.we_wordv = NULL; -+ pwordexp->we_wordc = 0; - } - - if ((flags & WRDE_APPEND) == 0) - -commit 912d89a766847649a3857985a3b5e6065c51bfd4 -Author: Florian Weimer -Date: Thu Jan 8 12:35:08 2026 +0100 - - Switch currency symbol for the bg_BG locale to euro - - Bulgaria joined the eurozone on 2026-01-01. - - Suggested-by: Йордан Гигов - Reviewed-by: Collin Funk - (cherry picked from commit 78fdb2d6b1c34ea8e779fd48f9436dfbd50b6387) - -diff --git a/localedata/locales/bg_BG b/localedata/locales/bg_BG -index 159a6c3334..eda2a8d01b 100644 ---- a/localedata/locales/bg_BG -+++ b/localedata/locales/bg_BG -@@ -248,8 +248,8 @@ reorder-end - END LC_COLLATE - - LC_MONETARY --int_curr_symbol "BGN " --currency_symbol "лв." -+int_curr_symbol "EUR " -+currency_symbol "€" - mon_decimal_point "," - mon_thousands_sep " " - mon_grouping 3 - -commit 39897805917ab1c44dbf4452b9c4c2bbafc7117b -Author: Florian Weimer -Date: Fri Feb 13 09:02:07 2026 +0100 - - nss: Introduce dedicated struct nss_database_for_fork type - - The initialized field in struct nss_database_data is rather confusing - because it is not used by the regular NSS code, only by the fork - state synchronization code. Introduce a separate type and place - the initialized field there. - - Reviewed-by: Sam James - (cherry picked from commit 7bb859f4198d0be19c31a9937eae4f6c2c9a079e) - -diff --git a/nss/nss_database.c b/nss/nss_database.c -index a7ac32beb9..a6b7d5c956 100644 ---- a/nss/nss_database.c -+++ b/nss/nss_database.c -@@ -56,7 +56,6 @@ global_state_allocate (void *closure) - { - result->data.nsswitch_conf.size = -1; /* Force reload. */ - memset (result->data.services, 0, sizeof (result->data.services)); -- result->data.initialized = true; - result->data.reload_disabled = false; - __libc_lock_init (result->lock); - result->root_ino = 0; -@@ -451,8 +450,8 @@ nss_database_check_reload_and_get (struct nss_database_state *local, - /* Avoid overwriting the global configuration until we have loaded - everything successfully. Otherwise, if the file change - information changes back to what is in the global configuration, -- the lookups would use the partially-written configuration. */ -- struct nss_database_data staging = { .initialized = true, }; -+ the lookups would use the partially-written configuration. */ -+ struct nss_database_data staging = { }; - - bool ok = nss_database_reload (&staging, &initial); - -@@ -503,7 +502,7 @@ __nss_database_freeres (void) - } - - void --__nss_database_fork_prepare_parent (struct nss_database_data *data) -+__nss_database_fork_prepare_parent (struct nss_database_for_fork *data) - { - /* Do not use allocate_once to trigger loading unnecessarily. */ - struct nss_database_state *local = atomic_load_acquire (&global_database_state); -@@ -515,20 +514,21 @@ __nss_database_fork_prepare_parent (struct nss_database_data *data) - because it avoids acquiring the lock during the actual - fork. */ - __libc_lock_lock (local->lock); -- *data = local->data; -+ data->data = local->data; - __libc_lock_unlock (local->lock); -+ data->initialized = true; - } - } - - void --__nss_database_fork_subprocess (struct nss_database_data *data) -+__nss_database_fork_subprocess (struct nss_database_for_fork *data) - { - struct nss_database_state *local = atomic_load_acquire (&global_database_state); - if (data->initialized) - { - /* Restore the state at the point of the fork. */ - assert (local != NULL); -- local->data = *data; -+ local->data = data->data; - __libc_lock_init (local->lock); - } - else if (local != NULL) -diff --git a/nss/nss_database.h b/nss/nss_database.h -index 0eaea49685..c170da03f6 100644 ---- a/nss/nss_database.h -+++ b/nss/nss_database.h -@@ -70,15 +70,21 @@ struct nss_database_data - struct file_change_detection nsswitch_conf; - nss_action_list services[NSS_DATABASE_COUNT]; - int reload_disabled; /* Actually bool; int for atomic access. */ -- bool initialized; -+}; -+ -+/* Use to store a consistent state snapshot across fork. */ -+struct nss_database_for_fork -+{ -+ bool initialized; /* Set to true if the data field below is initialized. */ -+ struct nss_database_data data; - }; - - /* Called by fork in the parent process, before forking. */ --void __nss_database_fork_prepare_parent (struct nss_database_data *data) -+void __nss_database_fork_prepare_parent (struct nss_database_for_fork *) - attribute_hidden; - - /* Called by fork in the new subprocess, after forking. */ --void __nss_database_fork_subprocess (struct nss_database_data *data) -+void __nss_database_fork_subprocess (struct nss_database_for_fork *) - attribute_hidden; - - #endif /* _NSS_DATABASE_H */ -diff --git a/posix/fork.c b/posix/fork.c -index 011e92fc1d..7f2370f2eb 100644 ---- a/posix/fork.c -+++ b/posix/fork.c -@@ -50,7 +50,7 @@ __libc_fork (void) - - lastrun = __run_prefork_handlers (multiple_threads); - -- struct nss_database_data nss_database_data; -+ struct nss_database_for_fork nss_database_data; - - /* If we are not running multiple threads, we do not have to - preserve lock state. If fork runs from a signal handler, only - -commit 937ef7aaf3ce41038b3e12675a6298b86b389af2 -Author: Florian Weimer -Date: Fri Feb 13 09:02:07 2026 +0100 - - Linux: In getlogin_r, use utmp fallback only for specific errors - - Most importantly, if getwpuid_r fails, it does not make sense to retry - via utmp because the user ID obtained from there is less reliable than - the one from /proc/self/loginuid. - - Reviewed-by: Sam James - (cherry picked from commit 28660f4b45afa8921c2faebaec2846f95f670ba0) - -diff --git a/sysdeps/unix/sysv/linux/getlogin_r.c b/sysdeps/unix/sysv/linux/getlogin_r.c -index f03ecd4da9..0e66944570 100644 ---- a/sysdeps/unix/sysv/linux/getlogin_r.c -+++ b/sysdeps/unix/sysv/linux/getlogin_r.c -@@ -37,7 +37,12 @@ __getlogin_r_loginuid (char *name, size_t namesize) - { - int fd = __open_nocancel ("/proc/self/loginuid", O_RDONLY); - if (fd == -1) -- return -1; -+ { -+ if (errno == ENOENT) -+ /* Trigger utmp fallback. */ -+ return -1; -+ return errno; -+ } - - /* We are reading a 32-bit number. 12 bytes are enough for the text - representation. If not, something is wrong. */ -@@ -45,6 +50,8 @@ __getlogin_r_loginuid (char *name, size_t namesize) - ssize_t n = TEMP_FAILURE_RETRY (__read_nocancel (fd, uidbuf, - sizeof (uidbuf))); - __close_nocancel_nostatus (fd); -+ if (n < 0) -+ return errno; - - uid_t uid; - char *endp; -@@ -53,12 +60,13 @@ __getlogin_r_loginuid (char *name, size_t namesize) - || (uidbuf[n] = '\0', - uid = strtoul (uidbuf, &endp, 10), - endp == uidbuf || *endp != '\0')) -- return -1; -+ return EINVAL; - - /* If there is no login uid, linux sets /proc/self/loginid to the sentinel - value of, (uid_t) -1, so check if that value is set and return early to - avoid making unneeded nss lookups. */ - if (uid == (uid_t) -1) -+ /* Trigger utmp fallback. */ - return -1; - - struct passwd pwd; -@@ -78,9 +86,14 @@ __getlogin_r_loginuid (char *name, size_t namesize) - } - } - -- if (res != 0 || tpwd == NULL) -+ if (res != 0) -+ { -+ result = res; -+ goto out; -+ } -+ if (tpwd == NULL) - { -- result = -1; -+ result = ENOENT; - goto out; - } - - -commit ebd45473f5421e0fced5ba2cde0f1aaa36e79b61 -Author: Florian Weimer -Date: Fri Feb 13 09:02:07 2026 +0100 - - nss: Missing checks in __nss_configure_lookup, __nss_database_get (bug 28940) - - This avoids a null pointer dereference in the - nss_database_check_reload_and_get function, and assertion failures. - - Reviewed-by: Sam James - (cherry picked from commit 5b713b49443eb6a4e54e50e2f0147105f86dab02) - -diff --git a/nss/Makefile b/nss/Makefile -index 1991b7482a..f690c29b94 100644 ---- a/nss/Makefile -+++ b/nss/Makefile -@@ -326,6 +326,7 @@ tests := \ - tst-gshadow \ - tst-nss-getpwent \ - tst-nss-hash \ -+ tst-nss-malloc-failure-getlogin_r \ - tst-nss-test1 \ - tst-nss-test2 \ - tst-nss-test4 \ -diff --git a/nss/nss_database.c b/nss/nss_database.c -index a6b7d5c956..7aa460c7df 100644 ---- a/nss/nss_database.c -+++ b/nss/nss_database.c -@@ -250,9 +250,12 @@ __nss_configure_lookup (const char *dbname, const char *service_line) - - /* Force any load/cache/read whatever to happen, so we can override - it. */ -- __nss_database_get (db, &result); -+ if (!__nss_database_get (db, &result)) -+ return -1; - - local = nss_database_state_get (); -+ if (local == NULL) -+ return -1; - - result = __nss_action_parse (service_line); - if (result == NULL) -@@ -477,6 +480,8 @@ bool - __nss_database_get (enum nss_database db, nss_action_list *actions) - { - struct nss_database_state *local = nss_database_state_get (); -+ if (local == NULL) -+ return false; - return nss_database_check_reload_and_get (local, actions, db); - } - libc_hidden_def (__nss_database_get) -diff --git a/nss/tst-nss-malloc-failure-getlogin_r.c b/nss/tst-nss-malloc-failure-getlogin_r.c -new file mode 100644 -index 0000000000..0e2985ad57 ---- /dev/null -+++ b/nss/tst-nss-malloc-failure-getlogin_r.c -@@ -0,0 +1,345 @@ -+/* Test NSS/getlogin_r with injected allocation failures (bug 28940). -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+ -+/* This test calls getpwuid_r via getlogin_r (on Linux). -+ -+ This test uses the NSS system configuration to exercise that code -+ path. It means that it can fail (crash) if malloc failure is not -+ handled by NSS modules for the passwd database. */ -+ -+/* Data structure allocated via MAP_SHARED, so that writes from the -+ subprocess are visible. */ -+struct shared_data -+{ -+ /* Number of tracked allocations performed so far. */ -+ volatile unsigned int allocation_count; -+ -+ /* If this number is reached, one allocation fails. */ -+ volatile unsigned int failing_allocation; -+ -+ /* The number of allocations performed during initialization -+ (before the actual getlogin_r call). */ -+ volatile unsigned int init_allocation_count; -+ -+ /* Error code of an expected getlogin_r failure. */ -+ volatile int expected_failure; -+ -+ /* The subprocess stores the expected name here. */ -+ char name[100]; -+}; -+ -+/* Allocation count in shared mapping. */ -+static struct shared_data *shared; -+ -+/* Returns true if a failure should be injected for this allocation. */ -+static bool -+fail_this_allocation (void) -+{ -+ if (shared != NULL) -+ { -+ unsigned int count = shared->allocation_count; -+ shared->allocation_count = count + 1; -+ return count == shared->failing_allocation; -+ } -+ else -+ return false; -+} -+ -+/* Failure-injecting wrappers for allocation functions used by glibc. */ -+ -+void * -+malloc (size_t size) -+{ -+ if (fail_this_allocation ()) -+ { -+ errno = ENOMEM; -+ return NULL; -+ } -+ extern __typeof (malloc) __libc_malloc; -+ return __libc_malloc (size); -+} -+ -+void * -+calloc (size_t a, size_t b) -+{ -+ if (fail_this_allocation ()) -+ { -+ errno = ENOMEM; -+ return NULL; -+ } -+ extern __typeof (calloc) __libc_calloc; -+ return __libc_calloc (a, b); -+} -+ -+void * -+realloc (void *ptr, size_t size) -+{ -+ if (fail_this_allocation ()) -+ { -+ errno = ENOMEM; -+ return NULL; -+ } -+ extern __typeof (realloc) __libc_realloc; -+ return __libc_realloc (ptr, size); -+} -+ -+/* No-op subprocess to verify that support_isolate_in_subprocess does -+ not perform any heap allocations. */ -+static void -+no_op (void *ignored) -+{ -+} -+ -+/* Perform a getlogin_r call in a subprocess, to obtain the number of -+ allocations used and the expected result of a successful call. */ -+static void -+initialize (void *configure_lookup) -+{ -+ shared->init_allocation_count = 0; -+ if (configure_lookup != NULL) -+ { -+ TEST_COMPARE (__nss_configure_lookup ("passwd", configure_lookup), 0); -+ shared->init_allocation_count = shared->allocation_count; -+ } -+ -+ shared->name[0] = '\0'; -+ int ret = getlogin_r (shared->name, sizeof (shared->name)); -+ if (ret != 0) -+ { -+ printf ("info: getlogin_r failed: %s (%d)\n", -+ strerrorname_np (ret), ret); -+ shared->expected_failure = ret; -+ } -+ else -+ { -+ shared->expected_failure = 0; -+ if (shared->name[0] == '\0') -+ FAIL ("error: getlogin_r succeeded without result\n"); -+ else -+ printf ("info: getlogin_r: \"%s\"\n", shared->name); -+ } -+} -+ -+/* Perform getlogin_r in a subprocess with fault injection. */ -+static void -+test_in_subprocess (void *configure_lookup) -+{ -+ if (configure_lookup != NULL -+ && __nss_configure_lookup ("passwd", configure_lookup) < 0) -+ { -+ printf ("info: __nss_configure_lookup failed: %s (%d)\n", -+ strerrorname_np (errno), errno); -+ TEST_COMPARE (errno, ENOMEM); -+ TEST_VERIFY (shared->allocation_count <= shared->init_allocation_count); -+ return; -+ } -+ -+ unsigned int inject_at = shared->failing_allocation; -+ char name[sizeof (shared->name)] = "name not set"; -+ int ret = getlogin_r (name, sizeof (name)); -+ shared->failing_allocation = ~0U; -+ -+ if (ret == 0) -+ { -+ TEST_COMPARE (shared->expected_failure, 0); -+ TEST_COMPARE_STRING (name, shared->name); -+ } -+ else -+ { -+ printf ("info: allocation %u failure results in error %s (%d)\n", -+ inject_at, strerrorname_np (ret), ret); -+ -+ if (ret != ENOMEM) -+ { -+ if (shared->expected_failure != 0) -+ TEST_COMPARE (ret, shared->expected_failure); -+ else if (configure_lookup == NULL) -+ /* The ENOENT failure can happen due to an issue related -+ to bug 22041: dlopen failure does not result in ENOMEM. */ -+ TEST_COMPARE (ret, ENOENT); -+ else -+ FAIL ("unexpected getlogin_r error"); -+ } -+ } -+ -+ if (shared->expected_failure == 0) -+ { -+ /* The second call should succeed. */ -+ puts ("info: about to perform second getlogin_r call"); -+ ret = getlogin_r (name, sizeof (name)); -+ if (configure_lookup == NULL) -+ { -+ /* This check can fail due to bug 22041 if the malloc error -+ injection causes a failure internally in dlopen. */ -+ if (ret != 0) -+ { -+ printf ("warning: second getlogin_r call failed with %s (%d)\n", -+ strerrorname_np (ret), ret); -+ TEST_COMPARE (ret, ENOENT); -+ } -+ } -+ else -+ /* If __nss_configure_lookup has been called, the error caching -+ bug does not happen because nss_files is built-in, and the -+ second getlogin_r is expected to succeed. */ -+ TEST_COMPARE (ret, 0); -+ if (ret == 0) -+ TEST_COMPARE_STRING (name, shared->name); -+ } -+} -+ -+/* Set by the --failing-allocation command line option. Together with -+ --direct, this can be used to trigger an allocation failure in the -+ original process, which may help with debugging. */ -+static int option_failing_allocation = -1; -+ -+/* Set by --override, to be used with --failing-allocation. Turns on -+ the __nss_configure_lookup call for passwd/files, which is disabled -+ by default. */ -+static int option_override = 0; -+ -+static int -+do_test (void) -+{ -+ char files[] = "files"; -+ -+ if (option_failing_allocation >= 0) -+ { -+ /* The test was invoked with --failing-allocation. Perform just -+ one test, using the original nsswitch.conf. This is a -+ condensed version of the probing/testing loop below. */ -+ printf ("info: testing with failing allocation %d\n", -+ option_failing_allocation); -+ shared = support_shared_allocate (sizeof (*shared)); -+ shared->failing_allocation = ~0U; -+ char *configure_lookup = option_override ? files : NULL; -+ support_isolate_in_subprocess (initialize, configure_lookup); -+ shared->allocation_count = 0; -+ shared->failing_allocation = option_failing_allocation; -+ test_in_subprocess (configure_lookup); /* No subprocess. */ -+ support_shared_free (shared); -+ shared = NULL; -+ return 0; -+ } -+ -+ bool any_success = false; -+ -+ for (int do_configure_lookup = 0; do_configure_lookup < 2; -+ ++do_configure_lookup) -+ { -+ if (do_configure_lookup) -+ puts ("info: testing with nsswitch.conf override"); -+ else -+ puts ("info: testing with original nsswitch.conf"); -+ -+ char *configure_lookup = do_configure_lookup ? files : NULL; -+ -+ shared = support_shared_allocate (sizeof (*shared)); -+ -+ /* Disable fault injection. */ -+ shared->failing_allocation = ~0U; -+ -+ support_isolate_in_subprocess (no_op, NULL); -+ TEST_COMPARE (shared->allocation_count, 0); -+ -+ support_isolate_in_subprocess (initialize, configure_lookup); -+ -+ if (shared->name[0] != '\0') -+ any_success = true; -+ -+ /* The number of allocations in the successful case. Once the -+ number of expected allocations is exceeded, injecting further -+ failures does not make a difference (assuming that the number -+ of malloc calls is deterministic). */ -+ unsigned int maximum_allocation_count = shared->allocation_count; -+ printf ("info: initial getlogin_r performed %u allocations\n", -+ maximum_allocation_count); -+ -+ for (unsigned int inject_at = 0; inject_at <= maximum_allocation_count; -+ ++inject_at) -+ { -+ printf ("info: running fault injection at allocation %u\n", -+ inject_at); -+ shared->allocation_count = 0; -+ shared->failing_allocation = inject_at; -+ support_isolate_in_subprocess (test_in_subprocess, configure_lookup); -+ } -+ -+ support_shared_free (shared); -+ shared = NULL; -+ } -+ -+ { -+ FILE *fp = fopen (_PATH_NSSWITCH_CONF, "r"); -+ if (fp == NULL) -+ printf ("info: no %s file\n", _PATH_NSSWITCH_CONF); -+ else -+ { -+ printf ("info: %s contents follows\n", _PATH_NSSWITCH_CONF); -+ int last_ch = '\n'; -+ while (true) -+ { -+ int ch = fgetc (fp); -+ if (ch == EOF) -+ break; -+ putchar (ch); -+ last_ch = ch; -+ } -+ if (last_ch != '\n') -+ putchar ('\n'); -+ printf ("(end of %s contents)\n", _PATH_NSSWITCH_CONF); -+ xfclose (fp); -+ } -+ } -+ -+ support_record_failure_barrier (); -+ -+ if (!any_success) -+ FAIL_UNSUPPORTED ("no successful getlogin_r calls"); -+ -+ return 0; -+} -+ -+static void -+cmdline_process (int c) -+{ -+ if (c == 'F') -+ option_failing_allocation = atoi (optarg); -+} -+ -+#define CMDLINE_OPTIONS \ -+ { "failing-allocation", required_argument, NULL, 'F' }, \ -+ { "override", no_argument, &option_override, 1 }, -+ -+#define CMDLINE_PROCESS cmdline_process -+ -+#include - -commit 9cd9c9054409d192aab06bfea32624af9ffa8121 -Author: Florian Weimer -Date: Fri Nov 28 11:46:09 2025 +0100 - - iconvdata: Fix invalid pointer arithmetic in ANSI_X3.110 module - - The expression inptr + 1 can technically be invalid: if inptr == inend, - inptr may point one element past the end of an array. - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit e98bd0c54d5e296ad1be91b6fe35260c6b87e733) - -diff --git a/iconvdata/ansi_x3.110.c b/iconvdata/ansi_x3.110.c -index c5506b13b8..94e6e6b745 100644 ---- a/iconvdata/ansi_x3.110.c -+++ b/iconvdata/ansi_x3.110.c -@@ -407,7 +407,7 @@ static const char from_ucs4[][2] = - is also available. */ \ - uint32_t ch2; \ - \ -- if (inptr + 1 >= inend) \ -+ if (inend - inptr <= 1) \ - { \ - /* The second character is not available. */ \ - result = __GCONV_INCOMPLETE_INPUT; \ - -commit 1a19d5a507eb82a2cf1cf8bd1c14ca1758fb8a82 -Author: Florian Weimer -Date: Mon Jan 26 17:12:37 2026 +0100 - - posix: Run tst-wordexp-reuse-mem test - - The test was not properly scheduled for execution with a Makefile - dependency. - - Fixes commit 80cc58ea2de214f85b0a1d902a3b668ad2ecb302 ("posix: Reset - wordexp_t fields with WRDE_REUSE (CVE-2025-15281 / BZ 33814"). - - (cherry picked from commit bed2db02f3183e93f21d506786c5f884a1dec9e7) - -diff --git a/posix/Makefile b/posix/Makefile -index 1ea86efcc1..0b29c9aa4e 100644 ---- a/posix/Makefile -+++ b/posix/Makefile -@@ -495,7 +495,7 @@ tests-special += \ - $(objpfx)tst-pcre-mem.out \ - $(objpfx)tst-rxspencer-no-utf8-mem.out \ - $(objpfx)tst-vfork3-mem.out \ -- $(objpfx)tst-wordexp-reuse.out \ -+ $(objpfx)tst-wordexp-reuse-mem.out \ - # tests-special - endif - endif - -commit 8e863fb1c92360520704a69dc948be6bb4a17cb3 -Author: Carlos O'Donell -Date: Fri Mar 20 16:43:33 2026 -0400 - - resolv: Count records correctly (CVE-2026-4437) - - The answer section boundary was previously ignored, and the code in - getanswer_ptr would iterate past the last resource record, but not - beyond the end of the returned data. This could lead to subsequent data - being interpreted as answer records, thus violating the DNS - specification. Such resource records could be maliciously crafted and - hidden from other tooling, but processed by the glibc stub resolver and - acted upon by the application. While we trust the data returned by the - configured recursive resolvers, we should not trust its format and - should validate it as required. It is a security issue to incorrectly - process the DNS protocol. - - A regression test is added for response section crossing. - - No regressions on x86_64-linux-gnu. - - Reviewed-by: Collin Funk - (cherry picked from commit 9f5f18aab40ec6b61fa49a007615e6077e9a979b) - -diff --git a/resolv/Makefile b/resolv/Makefile -index 8fa3398d76..0ba5fba710 100644 ---- a/resolv/Makefile -+++ b/resolv/Makefile -@@ -104,6 +104,7 @@ tests += \ - tst-resolv-basic \ - tst-resolv-binary \ - tst-resolv-byaddr \ -+ tst-resolv-dns-section \ - tst-resolv-edns \ - tst-resolv-invalid-cname \ - tst-resolv-network \ -@@ -115,6 +116,7 @@ tests += \ - tst-resolv-semi-failure \ - tst-resolv-short-response \ - tst-resolv-trailing \ -+ # tests - - # This test calls __res_context_send directly, which is not exported - # from libresolv. -@@ -293,6 +295,8 @@ $(objpfx)tst-resolv-aliases: $(objpfx)libresolv.so $(shared-thread-library) - $(objpfx)tst-resolv-basic: $(objpfx)libresolv.so $(shared-thread-library) - $(objpfx)tst-resolv-binary: $(objpfx)libresolv.so $(shared-thread-library) - $(objpfx)tst-resolv-byaddr: $(objpfx)libresolv.so $(shared-thread-library) -+$(objpfx)tst-resolv-dns-section: $(objpfx)libresolv.so \ -+ $(shared-thread-library) - $(objpfx)tst-resolv-edns: $(objpfx)libresolv.so $(shared-thread-library) - $(objpfx)tst-resolv-network: $(objpfx)libresolv.so $(shared-thread-library) - $(objpfx)tst-resolv-res_init: $(objpfx)libresolv.so -diff --git a/resolv/nss_dns/dns-host.c b/resolv/nss_dns/dns-host.c -index 14da73ee1d..27096edad2 100644 ---- a/resolv/nss_dns/dns-host.c -+++ b/resolv/nss_dns/dns-host.c -@@ -820,7 +820,7 @@ getanswer_ptr (unsigned char *packet, size_t packetlen, - /* expected_name may be updated to point into this buffer. */ - unsigned char name_buffer[NS_MAXCDNAME]; - -- while (ancount > 0) -+ for (; ancount > 0; --ancount) - { - struct ns_rr_wire rr; - if (!__ns_rr_cursor_next (&c, &rr)) -diff --git a/resolv/tst-resolv-dns-section.c b/resolv/tst-resolv-dns-section.c -new file mode 100644 -index 0000000000..1171baef51 ---- /dev/null -+++ b/resolv/tst-resolv-dns-section.c -@@ -0,0 +1,162 @@ -+/* Test handling of invalid section transitions (bug 34014). -+ Copyright (C) 2022-2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+ -+/* Name of test, and the second section type. */ -+struct item { -+ const char *test; -+ int ns_section; -+}; -+ -+static const struct item test_items[] = -+ { -+ { "Test crossing from ns_s_an to ns_s_ar.", ns_s_ar }, -+ { "Test crossing from ns_s_an to ns_s_an.", ns_s_ns }, -+ -+ { NULL, 0 }, -+ }; -+ -+/* The response is designed to contain the following: -+ - An Answer section with one T_PTR record that is skipped. -+ - A second section with a semantically invalid T_PTR record. -+ The original defect is that the response parsing would cross -+ section boundaries and handle the additional section T_PTR -+ as if it were an answer. A conforming implementation would -+ stop as soon as it reaches the end of the section. */ -+static void -+response (const struct resolv_response_context *ctx, -+ struct resolv_response_builder *b, -+ const char *qname, uint16_t qclass, uint16_t qtype) -+{ -+ TEST_COMPARE (qclass, C_IN); -+ -+ /* We only test PTR. */ -+ TEST_COMPARE (qtype, T_PTR); -+ -+ unsigned int count; -+ char *tail = NULL; -+ -+ if (strstr (qname, "in-addr.arpa") != NULL -+ && sscanf (qname, "%u.%ms", &count, &tail) == 2) -+ TEST_COMPARE_STRING (tail, "0.168.192.in-addr.arpa"); -+ else if (sscanf (qname, "%x.%ms", &count, &tail) == 2) -+ { -+ TEST_COMPARE_STRING (tail, "\ -+0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa"); -+ } -+ else -+ FAIL_EXIT1 ("invalid QNAME: %s\n", qname); -+ free (tail); -+ -+ /* We have a bounded number of possible tests. */ -+ TEST_VERIFY (count >= 0); -+ TEST_VERIFY (count <= 15); -+ -+ struct resolv_response_flags flags = {}; -+ resolv_response_init (b, flags); -+ resolv_response_add_question (b, qname, qclass, qtype); -+ resolv_response_section (b, ns_s_an); -+ -+ /* Actual answer record, but the wrong name (skipped). */ -+ resolv_response_open_record (b, "1.0.0.10.in-addr.arpa", qclass, qtype, 60); -+ -+ /* Record the answer. */ -+ resolv_response_add_name (b, "test.ptr.example.net"); -+ resolv_response_close_record (b); -+ -+ /* Add a second section to test section boundary crossing. */ -+ resolv_response_section (b, test_items[count].ns_section); -+ /* Semantically incorrect, but hide a T_PTR entry. */ -+ resolv_response_open_record (b, qname, qclass, qtype, 60); -+ resolv_response_add_name (b, "wrong.ptr.example.net"); -+ resolv_response_close_record (b); -+} -+ -+ -+/* Perform one check using a reverse lookup. */ -+static void -+check_reverse (int af, int count) -+{ -+ TEST_VERIFY (af == AF_INET || af == AF_INET6); -+ TEST_VERIFY (count < array_length (test_items)); -+ -+ char addr[sizeof (struct in6_addr)] = { 0 }; -+ socklen_t addrlen; -+ if (af == AF_INET) -+ { -+ addr[0] = (char) 192; -+ addr[1] = (char) 168; -+ addr[2] = (char) 0; -+ addr[3] = (char) count; -+ addrlen = 4; -+ } -+ else -+ { -+ addr[0] = 0x20; -+ addr[1] = 0x01; -+ addr[2] = 0x0d; -+ addr[3] = 0xb8; -+ addr[4] = addr[5] = addr[6] = addr[7] = 0x0; -+ addr[8] = addr[9] = addr[10] = addr[11] = 0x0; -+ addr[12] = 0x0; -+ addr[13] = 0x0; -+ addr[14] = 0x0; -+ addr[15] = count; -+ addrlen = 16; -+ } -+ -+ h_errno = 0; -+ struct hostent *answer = gethostbyaddr (addr, addrlen, af); -+ TEST_VERIFY (answer == NULL); -+ TEST_VERIFY (h_errno == NO_RECOVERY); -+ if (answer != NULL) -+ printf ("error: unexpected success: %s\n", -+ support_format_hostent (answer)); -+} -+ -+static int -+do_test (void) -+{ -+ struct resolv_test *obj = resolv_test_start -+ ((struct resolv_redirect_config) -+ { -+ .response_callback = response -+ }); -+ -+ for (int i = 0; test_items[i].test != NULL; i++) -+ { -+ check_reverse (AF_INET, i); -+ check_reverse (AF_INET6, i); -+ } -+ -+ resolv_test_end (obj); -+ -+ return 0; -+} -+ -+#include - -commit 426378547e6ddead92f28f5558a124eb0821d2f9 -Author: Carlos O'Donell -Date: Fri Mar 20 17:14:33 2026 -0400 - - resolv: Check hostname for validity (CVE-2026-4438) - - The processed hostname in getanswer_ptr should be correctly checked to - avoid invalid characters from being allowed, including shell - metacharacters. It is a security issue to fail to check the returned - hostname for validity. - - A regression test is added for invalid metacharacters and other cases - of invalid or valid characters. - - No regressions on x86_64-linux-gnu. - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit e10977481f4db4b2a3ce34fa4c3a1e26651ae312) - -diff --git a/resolv/Makefile b/resolv/Makefile -index 0ba5fba710..088a22ea18 100644 ---- a/resolv/Makefile -+++ b/resolv/Makefile -@@ -107,6 +107,7 @@ tests += \ - tst-resolv-dns-section \ - tst-resolv-edns \ - tst-resolv-invalid-cname \ -+ tst-resolv-invalid-ptr \ - tst-resolv-network \ - tst-resolv-noaaaa \ - tst-resolv-noaaaa-vc \ -@@ -306,6 +307,8 @@ $(objpfx)tst-resolv-res_init-thread: $(objpfx)libresolv.so \ - $(shared-thread-library) - $(objpfx)tst-resolv-invalid-cname: $(objpfx)libresolv.so \ - $(shared-thread-library) -+$(objpfx)tst-resolv-invalid-ptr: $(objpfx)libresolv.so \ -+ $(shared-thread-library) - $(objpfx)tst-resolv-noaaaa: $(objpfx)libresolv.so $(shared-thread-library) - $(objpfx)tst-resolv-noaaaa-vc: $(objpfx)libresolv.so $(shared-thread-library) - $(objpfx)tst-resolv-nondecimal: $(objpfx)libresolv.so $(shared-thread-library) -diff --git a/resolv/nss_dns/dns-host.c b/resolv/nss_dns/dns-host.c -index 27096edad2..1bc2e1df95 100644 ---- a/resolv/nss_dns/dns-host.c -+++ b/resolv/nss_dns/dns-host.c -@@ -866,7 +866,7 @@ getanswer_ptr (unsigned char *packet, size_t packetlen, - char hname[MAXHOSTNAMELEN + 1]; - if (__ns_name_unpack (c.begin, c.end, rr.rdata, - name_buffer, sizeof (name_buffer)) < 0 -- || !__res_binary_hnok (expected_name) -+ || !__res_binary_hnok (name_buffer) - || __ns_name_ntop (name_buffer, hname, sizeof (hname)) < 0) - { - *h_errnop = NO_RECOVERY; -diff --git a/resolv/tst-resolv-invalid-ptr.c b/resolv/tst-resolv-invalid-ptr.c -new file mode 100644 -index 0000000000..0c802ab967 ---- /dev/null -+++ b/resolv/tst-resolv-invalid-ptr.c -@@ -0,0 +1,255 @@ -+/* Test handling of invalid T_PTR results (bug 34015). -+ Copyright (C) 2022-2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+ -+/* Name of test, the answer, the expected error return, and if we -+ expect the call to fail. */ -+struct item { -+ const char *test; -+ const char *answer; -+ int expected; -+ bool fail; -+}; -+ -+static const struct item test_items[] = -+ { -+ /* Test for invalid characters. */ -+ { "Invalid use of \"|\"", -+ "test.|.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"&\"", -+ "test.&.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \";\"", -+ "test.;.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"<\"", -+ "test.<.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \">\"", -+ "test.>.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"(\"", -+ "test.(.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \")\"", -+ "test.).ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"$\"", -+ "test.$.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"`\"", -+ "test.`.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"\\\"", -+ "test.\\.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"\'\"", -+ "test.'.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"\"\"", -+ "test.\".ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \" \"", -+ "test. .ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"\\t\"", -+ "test.\t.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"\\n\"", -+ "test.\n.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"\\r\"", -+ "test.\r.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"*\"", -+ "test.*.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"?\"", -+ "test.?.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"[\"", -+ "test.[.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"]\"", -+ "test.].ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \",\"", -+ "test.,.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"~\"", -+ "test.~.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \":\"", -+ "test.:.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"!\"", -+ "test.!.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"@\"", -+ "test.@.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"#\"", -+ "test.#.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"%\"", -+ "test.%%.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of \"^\"", -+ "test.^.ptr.example", NO_RECOVERY, true }, -+ -+ /* Test for invalid UTF-8 characters (2-byte, 4-byte, 6-byte). */ -+ { "Invalid use of UTF-8 (2-byte, U+00C0-U+00C2)", -+ "ÁÂÃ.test.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of UTF-8 (4-byte, U+0750-U+0752)", -+ "ݐݑݒ.test.ptr.example", NO_RECOVERY, true }, -+ { "Invalid use of UTF-8 (6-byte, U+0904-U+0906)", -+ "ऄअआ.test.ptr.example", NO_RECOVERY, true }, -+ -+ /* Test for "-" which may be valid depending on position. */ -+ { "Invalid leading \"-\"", -+ "-test.ptr.example", NO_RECOVERY, true }, -+ { "Valid trailing \"-\"", -+ "test-.ptr.example", 0, false }, -+ { "Valid mid-label use of \"-\"", -+ "te-st.ptr.example", 0, false }, -+ -+ /* Test for "_" which is always valid in any position. */ -+ { "Valid leading use of \"_\"", -+ "_test.ptr.example", 0, false }, -+ { "Valid mid-label use of \"_\"", -+ "te_st.ptr.example", 0, false }, -+ { "Valid trailing use of \"_\"", -+ "test_.ptr.example", 0, false }, -+ -+ /* Sanity test the broader set [A-Za-z0-9_-] of valid characters. */ -+ { "Valid \"[A-Z]\"", -+ "test.ABCDEFGHIJKLMNOPQRSTUVWXYZ.ptr.example", 0, false }, -+ { "Valid \"[a-z]\"", -+ "test.abcdefghijklmnopqrstuvwxyz.ptr.example", 0, false }, -+ { "Valid \"[0-9]\"", -+ "test.0123456789.ptr.example", 0, false }, -+ { "Valid mixed use of \"[A-Za-z0-9_-]\"", -+ "test.012abcABZ_-.ptr.example", 0, false }, -+ }; -+ -+static void -+response (const struct resolv_response_context *ctx, -+ struct resolv_response_builder *b, -+ const char *qname, uint16_t qclass, uint16_t qtype) -+{ -+ TEST_COMPARE (qclass, C_IN); -+ -+ /* We only test PTR. */ -+ TEST_COMPARE (qtype, T_PTR); -+ -+ unsigned int count, count1; -+ char *tail = NULL; -+ -+ /* The test implementation can handle up to 255 tests. */ -+ if (strstr (qname, "in-addr.arpa") != NULL -+ && sscanf (qname, "%u.%ms", &count, &tail) == 2) -+ TEST_COMPARE_STRING (tail, "0.168.192.in-addr.arpa"); -+ else if (sscanf (qname, "%x.%x.%ms", &count, &count1, &tail) == 3) -+ { -+ TEST_COMPARE_STRING (tail, "\ -+0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa"); -+ count |= count1 << 4; -+ } -+ else -+ FAIL_EXIT1 ("invalid QNAME: %s\n", qname); -+ free (tail); -+ -+ /* Cross check. Count has a fixed bound (soft limit). */ -+ TEST_VERIFY (count >= 0 && count <= 255); -+ -+ /* We have a fixed number of tests (hard limit). */ -+ TEST_VERIFY_EXIT (count < array_length (test_items)); -+ -+ struct resolv_response_flags flags = {}; -+ resolv_response_init (b, flags); -+ resolv_response_add_question (b, qname, qclass, qtype); -+ resolv_response_section (b, ns_s_an); -+ -+ /* Actual answer record. */ -+ resolv_response_open_record (b, qname, qclass, qtype, 60); -+ -+ /* Record the answer. */ -+ resolv_response_add_name (b, test_items[count].answer); -+ resolv_response_close_record (b); -+} -+ -+/* Perform one check using a reverse lookup. */ -+static void -+check_reverse (int af, int count) -+{ -+ TEST_VERIFY (af == AF_INET || af == AF_INET6); -+ TEST_VERIFY_EXIT (count < array_length (test_items)); -+ -+ /* Generate an address to query for each test. */ -+ char addr[sizeof (struct in6_addr)] = { 0 }; -+ socklen_t addrlen; -+ if (af == AF_INET) -+ { -+ addr[0] = (char) 192; -+ addr[1] = (char) 168; -+ addr[2] = (char) 0; -+ addr[3] = (char) count; -+ addrlen = 4; -+ } -+ else -+ { -+ addr[0] = 0x20; -+ addr[1] = 0x01; -+ addr[2] = 0x0d; -+ addr[3] = 0xb8; -+ addr[4] = addr[5] = addr[6] = addr[7] = 0x0; -+ addr[8] = addr[9] = addr[10] = addr[11] = 0x0; -+ addr[12] = 0x0; -+ addr[13] = 0x0; -+ addr[14] = 0x0; -+ addr[15] = (char) count; -+ addrlen = 16; -+ } -+ -+ h_errno = 0; -+ struct hostent *answer = gethostbyaddr (addr, addrlen, af); -+ -+ /* Verify h_errno is as expected. */ -+ TEST_COMPARE (h_errno, test_items[count].expected); -+ if (h_errno != test_items[count].expected) -+ /* And print more information if it's not. */ -+ printf ("INFO: %s\n", test_items[count].test); -+ -+ if (test_items[count].fail) -+ { -+ /* We expected a failure so verify answer is NULL. */ -+ TEST_VERIFY (answer == NULL); -+ /* If it's not NULL we should print out what we received. */ -+ if (answer != NULL) -+ printf ("error: unexpected success: %s\n", -+ support_format_hostent (answer)); -+ } -+ else -+ /* We don't expect a failure so answer must be valid. */ -+ TEST_COMPARE_STRING (answer->h_name, test_items[count].answer); -+} -+ -+static int -+do_test (void) -+{ -+ struct resolv_test *obj = resolv_test_start -+ ((struct resolv_redirect_config) -+ { -+ .response_callback = response -+ }); -+ -+ for (int i = 0; i < array_length (test_items); i++) -+ { -+ check_reverse (AF_INET, i); -+ check_reverse (AF_INET6, i); -+ } -+ resolv_test_end (obj); -+ -+ return 0; -+} -+ -+#include - -commit 68099ccc941664481386c62cba40bbc5dac8b00e -Author: Xi Ruoyao -Date: Tue Feb 3 16:20:12 2026 +0800 - - elf: parse /proc/self/maps as the last resort to find the gap for tst-link-map-contiguous-ldso - - The initialization process of libc.so calls mmap() several times and the - kernel may lay the maps into the gap. If all pages in the gap are - occupied, the test would not be able to find the gap with mmap() and the - test would fail. - - The failure reproduces most frequently on LoongArch because with the - commonly used page size (16 KiB) the gap only contains 4 pages and the - probability they are all occupied is not near to zero. - - With the changes in the patch, a test run may output: - - info: ld.so link map is not contiguous - info: object "/dev/zero" found at 0x7ffff1fe0000 - 0x7ffff1fe4000 - info: anonymous mapping found at 0x7ffff1fe4000 - 0x7ffff1fec000 - - Also take the chance to fix a mistake in the "object found at" message - which has puzzled me during the initial debug session. - - Signed-off-by: Xi Ruoyao - Reviewed-by: Adhemerval Zanella - (cherry picked from commit aed8390a6a22e5751fc12704c0c5f2a8271fc286) - -diff --git a/elf/tst-link-map-contiguous-ldso.c b/elf/tst-link-map-contiguous-ldso.c -index 04de808bb2..f0e26682f2 100644 ---- a/elf/tst-link-map-contiguous-ldso.c -+++ b/elf/tst-link-map-contiguous-ldso.c -@@ -18,15 +18,73 @@ - - #include - #include -+#include - #include - #include - #include - #include -+#include - #include - #include -+#include - #include - #include - -+/* Slow path in case we cannot find a gap with mmap (when the runtime has -+ mapped all the pages in the gap for some reason). */ -+static bool -+find_gap_with_proc_self_map (const struct link_map *l) -+{ -+ int pagesize = getpagesize (); -+ -+ support_need_proc ("Reads /proc/self/maps to find gap in ld.so mapping"); -+ -+ /* Parse /proc/self/maps and find all the mappings in the ld.so range -+ but not from ld.so. */ -+ FILE *f = xfopen ("/proc/self/maps", "r"); -+ char *line = NULL, *path_ldso = NULL; -+ size_t len; -+ bool found = false; -+ while (xgetline (&line, &len, f)) -+ { -+ uintptr_t from, to; -+ char *path = NULL; -+ int r = sscanf (line, "%" SCNxPTR "-%" SCNxPTR "%*s%*s%*s%*s%ms", -+ &from, &to, &path); -+ -+ TEST_VERIFY (r == 2 || r == 3); -+ TEST_COMPARE (from % pagesize, 0); -+ TEST_COMPARE (to % pagesize, 0); -+ -+ if (path_ldso == NULL && l->l_map_start == from) -+ { -+ TEST_COMPARE (r, 3); -+ path_ldso = path; -+ continue; -+ } -+ -+ if (from > l->l_map_start && to < l->l_map_end -+ && (r == 2 || (path_ldso != NULL && strcmp (path, path_ldso)))) -+ { -+ if (r == 2) -+ printf ("info: anonymous mapping found at 0x%" PRIxPTR " - 0x%" -+ PRIxPTR "\n", from, to); -+ else -+ printf ("info: object \"%s\" found at 0x%" PRIxPTR " - 0x%" -+ PRIxPTR "\n", path, from, to); -+ -+ found = true; -+ } -+ -+ free (path); -+ } -+ -+ free (path_ldso); -+ free (line); -+ xfclose (f); -+ return found; -+} -+ - static int - do_test (void) - { -@@ -64,16 +122,18 @@ do_test (void) - if ((void *) dlfo.dlfo_link_map != (void *) l) - { - printf ("info: object \"%s\" found at %p\n", -- dlfo.dlfo_link_map->l_name, ptr); -+ dlfo.dlfo_link_map->l_name, expected); - gap_found = true; - } - } - else - TEST_COMPARE (dlfo_ret, -1); -+ - xmunmap (ptr, 1); - addr += pagesize; - } -- if (!gap_found) -+ -+ if (!gap_found && !find_gap_with_proc_self_map (l)) - FAIL ("no ld.so gap found"); - } - else - -commit a56a2943d2ce541102c630142c2eae0fbfc5886b -Author: Michael Jeanson -Date: Fri Feb 20 11:01:00 2026 -0500 - - tests: fix tst-rseq with Linux 7.0 - - A sub-test of tst-rseq is to validate the return code and errno of the - rseq syscall when attempting to register the exact same rseq area as was - done in the dynamic loader. - - This involves finding the rseq area address by adding the - '__rseq_offset' to the thread pointer and calculating the area size from - the AT_RSEQ_FEATURE_SIZE auxiliary vector. However the test currently - calculates the size of the rseq area allocation in the TLS block which - must be a multiple of AT_RSEQ_ALIGN. - - Up until now that happened to be the same value since the feature size - and alignment exposed by the kernel were below the minimum ABI size of - 32. Starting with Linux 7.0 the feature size has reached 33 while the - alignment is now 64. - - This results in the test trying to re-register the rseq area with a - different size and thus not getting the expected errno value. - - Signed-off-by: Michael Jeanson - Reviewed-by: Mathieu Desnoyers - (cherry picked from commit 67f303b47dc584f204e3f2441b9832082415eebc) - -diff --git a/sysdeps/unix/sysv/linux/tst-rseq.c b/sysdeps/unix/sysv/linux/tst-rseq.c -index 00181cfefb..e83ea2b939 100644 ---- a/sysdeps/unix/sysv/linux/tst-rseq.c -+++ b/sysdeps/unix/sysv/linux/tst-rseq.c -@@ -48,8 +48,7 @@ do_rseq_main_test (void) - size_t rseq_align = MAX (getauxval (AT_RSEQ_ALIGN), RSEQ_MIN_ALIGN); - size_t rseq_feature_size = MAX (getauxval (AT_RSEQ_FEATURE_SIZE), - RSEQ_AREA_SIZE_INITIAL_USED); -- size_t rseq_alloc_size = roundup (MAX (rseq_feature_size, -- RSEQ_AREA_SIZE_INITIAL_USED), rseq_align); -+ size_t rseq_reg_size = MAX (rseq_feature_size, RSEQ_AREA_SIZE_INITIAL); - struct rseq *rseq_abi = __thread_pointer () + __rseq_offset; - - TEST_VERIFY_EXIT (rseq_thread_registered ()); -@@ -89,8 +88,8 @@ do_rseq_main_test (void) - /* Test a rseq registration with the same arguments as the internal - registration which should fail with errno == EBUSY. */ - TEST_VERIFY (((unsigned long) rseq_abi % rseq_align) == 0); -- TEST_VERIFY (__rseq_size <= rseq_alloc_size); -- int ret = syscall (__NR_rseq, rseq_abi, rseq_alloc_size, 0, RSEQ_SIG); -+ TEST_VERIFY (__rseq_size <= rseq_reg_size); -+ int ret = syscall (__NR_rseq, rseq_abi, rseq_reg_size, 0, RSEQ_SIG); - TEST_VERIFY (ret != 0); - TEST_COMPARE (errno, EBUSY); - } - -commit f13c1bb0f97fbc12a6ba1ab5669ce561ea32b80a -Author: Florian Weimer -Date: Thu Apr 16 19:13:43 2026 +0200 - - Use pending character state in IBM1390, IBM1399 character sets (CVE-2026-4046) - - Follow the example in iso-2022-jp-3.c and use the __count state - variable to store the pending character. This avoids restarting - the conversion if the output buffer ends between two 4-byte UCS-4 - code points, so that the assert reported in the bug can no longer - happen. - - Even though the fix is applied to ibm1364.c, the change is only - effective for the two HAS_COMBINED codecs for IBM1390, IBM1399. - - The test case was mostly auto-generated using - claude-4.6-opus-high-thinking, and composer-2-fast shows up in the - log as well. During review, gpt-5.4-xhigh flagged that the original - version of the test case was not exercising the new character - flush logic. - - This fixes bug 33980. - - Assisted-by: LLM - Reviewed-by: Carlos O'Donell - (cherry picked from commit d6f08d1cf027f4eb2ba289a6cc66853722d4badc) - -diff --git a/iconvdata/Makefile b/iconvdata/Makefile -index 5a2abeea24..cc689f63e9 100644 ---- a/iconvdata/Makefile -+++ b/iconvdata/Makefile -@@ -76,7 +76,7 @@ tests = bug-iconv1 bug-iconv2 tst-loading tst-e2big tst-iconv4 bug-iconv4 \ - tst-iconv6 bug-iconv5 bug-iconv6 tst-iconv7 bug-iconv8 bug-iconv9 \ - bug-iconv10 bug-iconv11 bug-iconv12 tst-iconv-big5-hkscs-to-2ucs4 \ - bug-iconv13 bug-iconv14 bug-iconv15 \ -- tst-iconv-iso-2022-cn-ext -+ tst-iconv-iso-2022-cn-ext tst-bug33980 - ifeq ($(have-thread-library),yes) - tests += bug-iconv3 - endif -@@ -333,6 +333,8 @@ $(objpfx)bug-iconv15.out: $(addprefix $(objpfx), $(gconv-modules)) \ - $(addprefix $(objpfx),$(modules.so)) - $(objpfx)tst-iconv-iso-2022-cn-ext.out: $(addprefix $(objpfx), $(gconv-modules)) \ - $(addprefix $(objpfx),$(modules.so)) -+$(objpfx)tst-bug33980.out: $(addprefix $(objpfx), $(gconv-modules)) \ -+ $(addprefix $(objpfx),$(modules.so)) - - $(objpfx)iconv-test.out: run-iconv-test.sh \ - $(addprefix $(objpfx), $(gconv-modules)) \ -diff --git a/iconvdata/ibm1364.c b/iconvdata/ibm1364.c -index 45c62acee5..244c61ad7a 100644 ---- a/iconvdata/ibm1364.c -+++ b/iconvdata/ibm1364.c -@@ -67,12 +67,29 @@ - - /* Since this is a stateful encoding we have to provide code which resets - the output state to the initial state. This has to be done during the -- flushing. */ -+ flushing. For the to-internal direction (FROM_DIRECTION is true), -+ there may be a pending character that needs flushing. */ - #define EMIT_SHIFT_TO_INIT \ - if ((data->__statep->__count & ~7) != sb) \ - { \ - if (FROM_DIRECTION) \ -- data->__statep->__count &= 7; \ -+ { \ -+ uint32_t ch = data->__statep->__count >> 7; \ -+ if (__glibc_unlikely (ch != 0)) \ -+ { \ -+ if (__glibc_unlikely (outend - outbuf < 4)) \ -+ status = __GCONV_FULL_OUTPUT; \ -+ else \ -+ { \ -+ put32 (outbuf, ch); \ -+ outbuf += 4; \ -+ /* Clear character and db bit. */ \ -+ data->__statep->__count &= 7; \ -+ } \ -+ } \ -+ else \ -+ data->__statep->__count &= 7; \ -+ } \ - else \ - { \ - /* We are not in the initial state. To switch back we have \ -@@ -99,11 +116,13 @@ - *curcsp = save_curcs - - --/* Current codeset type. */ -+/* Current codeset type. The bit is stored in the __count variable of -+ the conversion state. If the db bit is set, bit 7 and above store -+ a pending UCS-4 code point if non-zero. */ - enum - { -- sb = 0, -- db = 64 -+ sb = 0, /* Single byte mode. */ -+ db = 64 /* Double byte mode. */ - }; - - -@@ -119,21 +138,29 @@ enum - } \ - else \ - { \ -- /* This is a combined character. Make sure we have room. */ \ -- if (__glibc_unlikely (outptr + 8 > outend)) \ -- { \ -- result = __GCONV_FULL_OUTPUT; \ -- break; \ -- } \ -- \ - const struct divide *cmbp \ - = &DB_TO_UCS4_COMB[ch - __TO_UCS4_COMBINED_MIN]; \ - assert (cmbp->res1 != 0 && cmbp->res2 != 0); \ - \ - put32 (outptr, cmbp->res1); \ - outptr += 4; \ -- put32 (outptr, cmbp->res2); \ -- outptr += 4; \ -+ \ -+ /* See whether we have room for the second character. */ \ -+ if (outend - outptr >= 4) \ -+ { \ -+ put32 (outptr, cmbp->res2); \ -+ outptr += 4; \ -+ } \ -+ else \ -+ { \ -+ /* Otherwise store only the first character now, and \ -+ put the second one into the queue. */ \ -+ curcs |= cmbp->res2 << 7; \ -+ inptr += 2; \ -+ /* Tell the caller why we terminate the loop. */ \ -+ result = __GCONV_FULL_OUTPUT; \ -+ break; \ -+ } \ - } \ - } - #else -@@ -153,7 +180,20 @@ enum - #define LOOPFCT FROM_LOOP - #define BODY \ - { \ -- uint32_t ch = *inptr; \ -+ uint32_t ch; \ -+ \ -+ ch = curcs >> 7; \ -+ if (__glibc_unlikely (ch != 0)) \ -+ { \ -+ put32 (outptr, ch); \ -+ outptr += 4; \ -+ /* Remove the pending character, but preserve state bits. */ \ -+ curcs &= (1 << 7) - 1; \ -+ continue; \ -+ } \ -+ \ -+ /* Otherwise read the next input byte. */ \ -+ ch = *inptr; \ - \ - if (__builtin_expect (ch, 0) == SO) \ - { \ -diff --git a/iconvdata/tst-bug33980.c b/iconvdata/tst-bug33980.c -new file mode 100644 -index 0000000000..c9693e0efe ---- /dev/null -+++ b/iconvdata/tst-bug33980.c -@@ -0,0 +1,153 @@ -+/* Test for bug 33980: combining characters in IBM1390/IBM1399. -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+ -+#include -+#include -+#include -+ -+/* Run iconv in a loop with a small output buffer of OUTBUFSIZE bytes -+ starting at OUTBUF. OUTBUF should be right before an unmapped page -+ so that writing past the end will fault. Skip SHIFT bytes at the -+ start of the input and output, to exercise different buffer -+ alignment. TRUNCATE indicates skipped bytes at the end of -+ input (0 and 1 a valid). */ -+static void -+test_one (const char *encoding, unsigned int shift, unsigned int truncate, -+ char *outbuf, size_t outbufsize) -+{ -+ /* In IBM1390 and IBM1399, the DBCS code 0xECB5 expands to two -+ Unicode code points when translated. */ -+ static char input[] = -+ { -+ /* 8 letters X. */ -+ 0xe7, 0xe7, 0xe7, 0xe7, 0xe7, 0xe7, 0xe7, 0xe7, -+ /* SO, 0xECB5, SI: shift to DBCS, special character, shift back. */ -+ 0x0e, 0xec, 0xb5, 0x0f -+ }; -+ -+ /* Expected output after UTF-8 conversion. */ -+ static char expected[] = -+ { -+ 'X', 'X', 'X', 'X', 'X', 'X', 'X', 'X', -+ /* U+304B (HIRAGANA LETTER KA). */ -+ 0xe3, 0x81, 0x8b, -+ /* U+309A (COMBINING KATAKANA-HIRAGANA SEMI-VOICED SOUND MARK). */ -+ 0xe3, 0x82, 0x9a -+ }; -+ -+ iconv_t cd = iconv_open ("UTF-8", encoding); -+ TEST_VERIFY_EXIT (cd != (iconv_t) -1); -+ -+ char result_storage[64]; -+ struct alloc_buffer result_buf -+ = alloc_buffer_create (result_storage, sizeof (result_storage)); -+ -+ char *inptr = &input[shift]; -+ size_t inleft = sizeof (input) - shift - truncate; -+ -+ while (inleft > 0) -+ { -+ char *outptr = outbuf; -+ size_t outleft = outbufsize; -+ size_t inleft_before = inleft; -+ -+ size_t ret = iconv (cd, &inptr, &inleft, &outptr, &outleft); -+ size_t produced = outptr - outbuf; -+ alloc_buffer_copy_bytes (&result_buf, outbuf, produced); -+ -+ if (ret == (size_t) -1 && errno == E2BIG) -+ { -+ if (produced == 0 && inleft == inleft_before) -+ { -+ /* Output buffer too small to make progress. This is -+ expected for very small output buffer sizes. */ -+ TEST_VERIFY_EXIT (outbufsize < 3); -+ break; -+ } -+ continue; -+ } -+ if (ret == (size_t) -1) -+ FAIL_EXIT1 ("%s (outbufsize %zu): iconv: %m", encoding, outbufsize); -+ break; -+ } -+ -+ /* Flush any pending state (e.g. a buffered combined character). -+ With outbufsize < 3, we could not store the first character, so -+ the second character did not become pending, and there is nothing -+ to flush. */ -+ { -+ char *outptr = outbuf; -+ size_t outleft = outbufsize; -+ -+ size_t ret = iconv (cd, NULL, NULL, &outptr, &outleft); -+ TEST_VERIFY_EXIT (ret == 0); -+ size_t produced = outptr - outbuf; -+ alloc_buffer_copy_bytes (&result_buf, outbuf, produced); -+ -+ /* Second flush does not provide more data. */ -+ outptr = outbuf; -+ outleft = outbufsize; -+ ret = iconv (cd, NULL, NULL, &outptr, &outleft); -+ TEST_VERIFY_EXIT (ret == 0); -+ TEST_VERIFY (outptr == outbuf); -+ } -+ -+ TEST_VERIFY_EXIT (!alloc_buffer_has_failed (&result_buf)); -+ size_t result_used -+ = sizeof (result_storage) - alloc_buffer_size (&result_buf); -+ -+ if (outbufsize >= 3) -+ { -+ TEST_COMPARE (inleft, 0); -+ TEST_COMPARE (result_used, sizeof (expected) - shift); -+ TEST_COMPARE_BLOB (result_storage, result_used, -+ &expected[shift], sizeof (expected) - shift); -+ } -+ else -+ /* If the buffer is too small, only the leading X could be converted. */ -+ TEST_COMPARE (result_used, 8 - shift); -+ -+ TEST_VERIFY_EXIT (iconv_close (cd) == 0); -+} -+ -+static int -+do_test (void) -+{ -+ struct support_next_to_fault ntf -+ = support_next_to_fault_allocate (8); -+ -+ for (int shift = 0; shift <= 8; ++shift) -+ for (int truncate = 0; truncate < 2; ++truncate) -+ for (size_t outbufsize = 1; outbufsize <= 8; outbufsize++) -+ { -+ char *outbuf = ntf.buffer + ntf.length - outbufsize; -+ test_one ("IBM1390", shift, truncate, outbuf, outbufsize); -+ test_one ("IBM1399", shift, truncate, outbuf, outbufsize); -+ } -+ -+ support_next_to_fault_free (&ntf); -+ return 0; -+} -+ -+#include - -commit 12feedaf67e11c4618dc50c6aab4dbfd1e6d9531 -Author: DJ Delorie -Date: Mon Jan 26 22:24:42 2026 -0500 - - include: isolate __O_CLOEXEC flag for sys/mount.h and fcntl.h - - Including sys/mount.h should not implicitly include fcntl.h - as that causes namespace pollution and conflicts with kernel - headers. It only needs O_CLOEXEC for OPEN_TREE_CLOEXEC - (although it shouldn't need that, but it's defined that way) - so we provide that define (via a private version) separately. - - Reviewed-by: Adhemerval Zanella - Tested-by: Florian Weimer - (cherry picked from commit 419245719ccbc7dad6a97f24465e7f09c090327a) - -diff --git a/io/fcntl.c b/io/fcntl.c -index e88e28664c..b7dab1bb39 100644 ---- a/io/fcntl.c -+++ b/io/fcntl.c -@@ -18,6 +18,10 @@ - #include - #include - -+#ifndef __O_CLOEXEC -+# error __O_CLOEXEC not defined by fcntl.h/cloexec.h -+#endif -+ - /* Perform file control operations on FD. */ - int - __fcntl (int fd, int cmd, ...) -diff --git a/sysdeps/unix/sysv/linux/Makefile b/sysdeps/unix/sysv/linux/Makefile -index c47cbdf428..053041f256 100644 ---- a/sysdeps/unix/sysv/linux/Makefile -+++ b/sysdeps/unix/sysv/linux/Makefile -@@ -129,6 +129,7 @@ CFLAGS-test-errno-linux.c += $(no-fortify-source) - - sysdep_headers += \ - bits/a.out.h \ -+ bits/cloexec.h \ - bits/epoll.h \ - bits/eventfd.h \ - bits/inotify.h \ -diff --git a/sysdeps/unix/sysv/linux/alpha/bits/cloexec.h b/sysdeps/unix/sysv/linux/alpha/bits/cloexec.h -new file mode 100644 -index 0000000000..f381f28a53 ---- /dev/null -+++ b/sysdeps/unix/sysv/linux/alpha/bits/cloexec.h -@@ -0,0 +1 @@ -+#define __O_CLOEXEC 010000000 -diff --git a/sysdeps/unix/sysv/linux/bits/cloexec.h b/sysdeps/unix/sysv/linux/bits/cloexec.h -new file mode 100644 -index 0000000000..3059fb6473 ---- /dev/null -+++ b/sysdeps/unix/sysv/linux/bits/cloexec.h -@@ -0,0 +1 @@ -+#define __O_CLOEXEC 02000000 -diff --git a/sysdeps/unix/sysv/linux/bits/fcntl-linux.h b/sysdeps/unix/sysv/linux/bits/fcntl-linux.h -index f425a4bf22..98954feaca 100644 ---- a/sysdeps/unix/sysv/linux/bits/fcntl-linux.h -+++ b/sysdeps/unix/sysv/linux/bits/fcntl-linux.h -@@ -81,9 +81,7 @@ - #ifndef __O_NOFOLLOW - # define __O_NOFOLLOW 0400000 - #endif --#ifndef __O_CLOEXEC --# define __O_CLOEXEC 02000000 --#endif -+#include - #ifndef __O_DIRECT - # define __O_DIRECT 040000 - #endif -diff --git a/sysdeps/unix/sysv/linux/hppa/bits/cloexec.h b/sysdeps/unix/sysv/linux/hppa/bits/cloexec.h -new file mode 100644 -index 0000000000..f381f28a53 ---- /dev/null -+++ b/sysdeps/unix/sysv/linux/hppa/bits/cloexec.h -@@ -0,0 +1 @@ -+#define __O_CLOEXEC 010000000 -diff --git a/sysdeps/unix/sysv/linux/sparc/bits/cloexec.h b/sysdeps/unix/sysv/linux/sparc/bits/cloexec.h -new file mode 100644 -index 0000000000..6706eaa7d5 ---- /dev/null -+++ b/sysdeps/unix/sysv/linux/sparc/bits/cloexec.h -@@ -0,0 +1 @@ -+#define __O_CLOEXEC 0x400000 -diff --git a/sysdeps/unix/sysv/linux/sys/mount.h b/sysdeps/unix/sysv/linux/sys/mount.h -index b549e75148..365da1c296 100644 ---- a/sysdeps/unix/sysv/linux/sys/mount.h -+++ b/sysdeps/unix/sysv/linux/sys/mount.h -@@ -21,7 +21,6 @@ - #ifndef _SYS_MOUNT_H - #define _SYS_MOUNT_H 1 - --#include - #include - #include - #include -@@ -266,6 +265,11 @@ enum fsconfig_command - - /* open_tree flags. */ - #define OPEN_TREE_CLONE 1 /* Clone the target tree and attach the clone */ -+#ifndef O_CLOEXEC -+# include -+# define O_CLOEXEC __O_CLOEXEC -+#endif -+#undef OPEN_TREE_CLOEXEC - #define OPEN_TREE_CLOEXEC O_CLOEXEC /* Close the file on execve() */ - - -diff --git a/sysdeps/unix/sysv/linux/tst-mount.c b/sysdeps/unix/sysv/linux/tst-mount.c -index 40913c7082..78a2772b2f 100644 ---- a/sysdeps/unix/sysv/linux/tst-mount.c -+++ b/sysdeps/unix/sysv/linux/tst-mount.c -@@ -20,6 +20,7 @@ - #include - #include - #include -+#include /* For AT_ constants. */ - #include - - _Static_assert (sizeof (struct mount_attr) == MOUNT_ATTR_SIZE_VER0, - -commit 3ecfa68561d723564a1fb565366182eb4acb3e8f -Author: Florian Weimer -Date: Wed Mar 4 18:32:36 2026 +0100 - - Linux: Only define OPEN_TREE_* macros in if undefined (bug 33921) - - There is a conditional inclusion of earlier in the file. - If that defines the macros, do not redefine them. This addresses build - problems as the token sequence used by the UAPI macro definitions - changes between Linux versions. - - Reviewed-by: Adhemerval Zanella - (cherry picked from commit d12b017cddfeb9fe9920ba054ae3dfcb8e9238b8) - -diff --git a/sysdeps/unix/sysv/linux/sys/mount.h b/sysdeps/unix/sysv/linux/sys/mount.h -index 365da1c296..30ba56c1e8 100644 ---- a/sysdeps/unix/sysv/linux/sys/mount.h -+++ b/sysdeps/unix/sysv/linux/sys/mount.h -@@ -264,14 +264,16 @@ enum fsconfig_command - #define FSOPEN_CLOEXEC 0x00000001 - - /* open_tree flags. */ --#define OPEN_TREE_CLONE 1 /* Clone the target tree and attach the clone */ -+#ifndef OPEN_TREE_CLONE -+# define OPEN_TREE_CLONE 1 /* Clone the target tree and attach the clone */ -+#endif - #ifndef O_CLOEXEC - # include - # define O_CLOEXEC __O_CLOEXEC - #endif --#undef OPEN_TREE_CLOEXEC --#define OPEN_TREE_CLOEXEC O_CLOEXEC /* Close the file on execve() */ -- -+#ifndef OPEN_TREE_CLOEXEC -+# define OPEN_TREE_CLOEXEC O_CLOEXEC /* Close the file on execve() */ -+#endif - - __BEGIN_DECLS - - -commit 3e87cf9be93acf19d685e8003fc649cdb052a891 -Author: H.J. Lu -Date: Mon Apr 13 10:46:42 2026 +0800 - - abilist.awk: Handle weak unversioned defined symbols - - After - - commit f685e3953f9a38a41bbd0a597f9882870cee13d5 - Author: H.J. Lu - Date: Wed Oct 29 09:49:57 2025 +0800 - - elf: Don't set its DT_VERSYM entry for unversioned symbol - - ld no longer assigns version index 1 to unversioned defined symbol. - For libmachuser.so, "objdump --dynamic-syms" reports: - - 0000dd30 w DF .text 000000f8 processor_start - - instead of - - 0000dd30 w DF .text 000000f8 (Base) processor_start - - Also allow NF == 6 for weak unversioned dynamic symbols. This fixes BZ - 33650. - - Signed-off-by: H.J. Lu - Reviewed-by: Sam James - (cherry picked from commit ee5d1db2a81468413fbf7c82779ffa782f429d1a) - -diff --git a/scripts/abilist.awk b/scripts/abilist.awk -index 6cc7af6ac8..7ea1edf8c0 100644 ---- a/scripts/abilist.awk -+++ b/scripts/abilist.awk -@@ -38,7 +38,7 @@ $4 == "*UND*" { next } - $2 == "l" { next } - - # If the target uses ST_OTHER, it will be output before the symbol name. --$2 == "g" || $2 == "w" && (NF == 7 || NF == 8) { -+$2 == "g" || $2 == "w" && (NF == 6 || NF == 7 || NF == 8) { - type = $3; - size = $5; - sub(/^0*/, "", size); - -commit b4bca35ab9e76890504c4dbdd5eaf15a93514580 -Author: Rocket Ma -Date: Fri May 1 20:39:07 2026 -0700 - - libio: Fix ungetwc operating on byte stream [BZ #33998] - - * libio/wgenops.c: When _IO_wdefault_pbackfail attempts to push back one - character, it accidently compare the wchar to push back with the last - char from byte stream, instead of wide stream. Under specific coding, - attacker may exploit this to leak information. This commit fix bug - 33998, or CVE-2026-5928. - - Signed-off-by: Rocket Ma - Reviewed-by: Carlos O'Donell - (cherry picked from commit ef3bfb5f910011f3780cb06aa47e730035f53285) - -diff --git a/libio/Makefile b/libio/Makefile -index f020f8ec4d..fa2b8ae791 100644 ---- a/libio/Makefile -+++ b/libio/Makefile -@@ -83,6 +83,7 @@ tests = \ - bug-ungetwc1 \ - bug-ungetwc2 \ - bug-wfflush \ -+ bug-wgenops-bz33998 \ - bug-wmemstream1 \ - bug-wsetpos \ - test-fmemopen \ -diff --git a/libio/bug-wgenops-bz33998.c b/libio/bug-wgenops-bz33998.c -new file mode 100644 -index 0000000000..cc4067da99 ---- /dev/null -+++ b/libio/bug-wgenops-bz33998.c -@@ -0,0 +1,54 @@ -+/* Regression test for ungetwc operating on byte stream (BZ #33998) -+ Copyright (C) 2026 The GNU Toolchain Authors. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include "support/temp_file.h" -+#include "support/xstdio.h" -+#include "support/xunistd.h" -+#include -+#include -+#include -+#include -+#include -+#include -+ -+static int -+do_test (void) -+{ -+ char *filename; -+ int fd = create_temp_file ("tst-bz33998-", &filename); -+ TEST_VERIFY (fd != -1); -+ xwrite (fd, "A", sizeof ("A")); // write "A\0" by design -+ xclose (fd); -+ -+ FILE *fp = xfopen (filename, "r+"); -+ TEST_COMPARE (getwc (fp), L'A'); -+ /* If the bug is fixed, then ungetwc should not touch byte stream. -+ If the bug is not fixed, ungetwc firstly match last read char, L'A', -+ failed, then the pbackfail branch, matching last read char in byte -+ stream, that is, '\0' (initialized when setup wide stream). */ -+ char *old_read_ptr = fp->_IO_read_ptr; -+ TEST_COMPARE (ungetwc (L'\0', fp), L'\0'); -+ TEST_VERIFY (fp->_IO_read_ptr == old_read_ptr); -+ -+ xfclose (fp); -+ free (filename); -+ -+ return 0; -+} -+ -+#include -diff --git a/libio/wgenops.c b/libio/wgenops.c -index 0a11d1b1de..9e0b2c00ea 100644 ---- a/libio/wgenops.c -+++ b/libio/wgenops.c -@@ -108,8 +108,8 @@ _IO_wdefault_pbackfail (FILE *fp, wint_t c) - { - if (fp->_wide_data->_IO_read_ptr > fp->_wide_data->_IO_read_base - && !_IO_in_backup (fp) -- && (wint_t) fp->_IO_read_ptr[-1] == c) -- --fp->_IO_read_ptr; -+ && (wint_t) fp->_wide_data->_IO_read_ptr[-1] == c) -+ --fp->_wide_data->_IO_read_ptr; - else - { - /* Need to handle a filebuf in write mode (switch to read mode). FIXME!*/ - -commit 4ebd33dd77eabe8d4c45232bed4b42a31d2f9edc -Author: Rocket Ma -Date: Fri Apr 17 23:48:41 2026 -0700 - - stdio-common: Fix buffer overflow in scanf %mc [BZ #34008] - - * stdio-common/vfscanf-internal.c: When enlarging allocated buffer with - format %mc or %mC, glibc allocates one byte less, leading to - user-controlled one byte overflow. This commit fixes BZ #34008, or - CVE-2026-5450. - - Reviewed-by: Carlos O'Donell - Signed-off-by: Rocket Ma - Reviewed-by: H.J. Lu - (cherry picked from commit 839898777226a3ed88c0859f25ffe712519b4ead) - -diff --git a/stdio-common/Makefile b/stdio-common/Makefile -index 64b3575acb..e52c333808 100644 ---- a/stdio-common/Makefile -+++ b/stdio-common/Makefile -@@ -347,6 +347,7 @@ tests := \ - tst-vfprintf-user-type \ - tst-vfprintf-width-i18n \ - tst-vfprintf-width-prec-alloc \ -+ tst-vfscanf-bz34008 \ - tst-wc-printf \ - tstdiomisc \ - tstgetln \ -@@ -562,6 +563,9 @@ tst-printf-bz18872-ENV = MALLOC_TRACE=$(objpfx)tst-printf-bz18872.mtrace \ - tst-vfprintf-width-prec-ENV = \ - MALLOC_TRACE=$(objpfx)tst-vfprintf-width-prec.mtrace \ - LD_PRELOAD=$(common-objpfx)/malloc/libc_malloc_debug.so -+tst-vfscanf-bz34008-ENV = \ -+ MALLOC_CHECK_=3 \ -+ LD_PRELOAD=$(common-objpfx)/malloc/libc_malloc_debug.so - tst-printf-bz25691-ENV = \ - MALLOC_TRACE=$(objpfx)tst-printf-bz25691.mtrace \ - LD_PRELOAD=$(common-objpfx)/malloc/libc_malloc_debug.so -diff --git a/stdio-common/tst-vfscanf-bz34008.c b/stdio-common/tst-vfscanf-bz34008.c -new file mode 100644 -index 0000000000..48371c8a3d ---- /dev/null -+++ b/stdio-common/tst-vfscanf-bz34008.c -@@ -0,0 +1,48 @@ -+/* Regression test for vfscanf %Nmc out-of-bound write (BZ #34008) -+ Copyright (C) 2026 The GNU Toolchain Authors. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include "malloc/mcheck.h" -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+ -+#define WIDTH 0x410 -+#define SCANFSTR "%1040mc" -+static int -+do_test (void) -+{ -+ mcheck_pedantic (NULL); -+ char *input = malloc (WIDTH + 1); -+ TEST_VERIFY (input != NULL); -+ memset (input, 'A', WIDTH); -+ input[WIDTH] = '\0'; -+ -+ char *buf = NULL; -+ TEST_VERIFY (sscanf (input, SCANFSTR, &buf) != -1); -+ TEST_VERIFY (buf != NULL); -+ -+ free (buf); -+ free (input); -+ return 0; -+} -+ -+#include -diff --git a/stdio-common/vfscanf-internal.c b/stdio-common/vfscanf-internal.c -index 86ae5019a6..17b5565d0f 100644 ---- a/stdio-common/vfscanf-internal.c -+++ b/stdio-common/vfscanf-internal.c -@@ -853,8 +853,7 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, - { - /* Enlarge the buffer. */ - size_t newsize -- = strsize -- + (strsize >= width ? width - 1 : strsize); -+ = strsize + (strsize >= width ? width : strsize); - - str = (char *) realloc (*strptr, newsize); - if (str == NULL) -@@ -925,7 +924,7 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, - && wstr == (wchar_t *) *strptr + strsize) - { - size_t newsize -- = strsize + (strsize > width ? width - 1 : strsize); -+ = strsize + (strsize >= width ? width : strsize); - /* Enlarge the buffer. */ - wstr = (wchar_t *) realloc (*strptr, - newsize * sizeof (wchar_t)); -@@ -980,7 +979,7 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, - && wstr == (wchar_t *) *strptr + strsize) - { - size_t newsize -- = strsize + (strsize > width ? width - 1 : strsize); -+ = strsize + (strsize >= width ? width : strsize); - /* Enlarge the buffer. */ - wstr = (wchar_t *) realloc (*strptr, - newsize * sizeof (wchar_t)); - -commit b866ef29773b22a1343ff9084374775114350b78 -Author: Maciej W. Rozycki -Date: Wed May 27 12:57:10 2026 -0400 - - support: Implement 'xfmemopen' for seamless 'fmemopen' use - - Add 'xfmemopen' wrapper for seamless 'fmemopen' use in tests, following - 'xfopen', 'xfclose', etc., and providing a standardized error reporting - facility. - - Reviewed-by: Florian Weimer - (cherry picked from commit fe709cc24578ecfd2ff5b07e10e3829fcb55075b) - - Reviewed-by: Carlos O'Donell - -diff --git a/support/Makefile b/support/Makefile -index d41278eeab..f67f38130a 100644 ---- a/support/Makefile -+++ b/support/Makefile -@@ -134,6 +134,7 @@ libsupport-routines = \ - xfclose \ - xfdopendir \ - xfgets \ -+ xfmemopen \ - xfopen \ - xfork \ - xfread \ -diff --git a/support/xfmemopen.c b/support/xfmemopen.c -new file mode 100644 -index 0000000000..f1dbc72c67 ---- /dev/null -+++ b/support/xfmemopen.c -@@ -0,0 +1,31 @@ -+/* fmemopen with error checking. -+ Copyright (C) 2025 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+ -+#include -+#include -+ -+FILE * -+xfmemopen (void *mem, size_t len, const char *mode) -+{ -+ FILE *fp = fmemopen (mem, len, mode); -+ if (fp == NULL) -+ FAIL_EXIT1 ("fmemopen (mode \"%s\"): %m", mode); -+ return fp; -+} -diff --git a/support/xstdio.h b/support/xstdio.h -index c3fdf9496f..70b83f11da 100644 ---- a/support/xstdio.h -+++ b/support/xstdio.h -@@ -27,6 +27,7 @@ __BEGIN_DECLS - FILE *xfopen (const char *path, const char *mode); - void xfclose (FILE *); - FILE *xfreopen (const char *path, const char *mode, FILE *stream); -+FILE *xfmemopen (void *mem, size_t len, const char *mode); - void xfread (void *ptr, size_t size, size_t nmemb, FILE *stream); - char *xfgets (char *s, int size, FILE *stream); - - -commit 97926e9017f3faeaacce9337f1288460f5e6ec7d -Author: Maciej W. Rozycki -Date: Wed May 27 12:57:10 2026 -0400 - - stdio-common: Reject insufficient character data in scanf [BZ #12701] - - Reject invalid formatted scanf character data with the 'c' conversion - where there is not enough input available to satisfy the field width - requested. It is required by ISO C that this conversion matches a - sequence of characters of exactly the number specified by the field - width and it is also already documented as such in our own manual: - - "It reads precisely the next N characters, and fails if it cannot get - that many." - - Currently a matching success is instead incorrectly produced where the - EOF condition is encountered before the required number of characters - has been retrieved, and the characters actually obtained are stored in - the buffer provided. - - Add test cases accordingly and remove placeholders from 'c' conversion - input data for the existing scanf tests. - - Reviewed-by: Adhemerval Zanella - - [This is a modified version of commit 2b16c76609, which tests for the - old behavior and only includes the test cases, for older branches - and downstream backports - DJ] - - Reviewed-by: Carlos O'Donell - -diff --git a/localedata/Makefile b/localedata/Makefile -index 4a23593cca..bff5c0bc71 100644 ---- a/localedata/Makefile -+++ b/localedata/Makefile -@@ -236,6 +236,7 @@ tests = \ - bug-iconv-trans \ - bug-setlocale1 \ - bug-usesetlocale \ -+ tst-bz12701-lc \ - tst-bz13988 \ - tst-c-utf8-consistency \ - tst-digits \ -diff --git a/localedata/tst-bz12701-lc.c b/localedata/tst-bz12701-lc.c -new file mode 100644 -index 0000000000..23c2ab7d2a ---- /dev/null -+++ b/localedata/tst-bz12701-lc.c -@@ -0,0 +1,218 @@ -+/* Verify scanf field width handling with the 'lc' conversion (BZ #12701). -+ Copyright (C) 2025-2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+ -+#include -+#include -+#include -+#include -+ -+/* Compare character-wise the initial part of the wide character object -+ pointed to by WS corresponding to wide characters obtained by the -+ conversion of first N bytes of the multibyte character object pointed -+ to by S. */ -+ -+static int -+tst_bz12701_lc_memcmp (const wchar_t *ds, const char *s, size_t n) -+{ -+ size_t nc = mbsnrtowcs (NULL, &s, n, 0, NULL); -+ -+ struct support_next_to_fault ntf; -+ ntf = support_next_to_fault_allocate (nc * sizeof (wchar_t)); -+ wchar_t *ss = (wchar_t *) ntf.buffer; -+ -+ mbsnrtowcs (ss, &s, n, nc, NULL); -+ int r = wmemcmp (ds, ss, nc); -+ -+ support_next_to_fault_free (&ntf); -+ -+ return r; -+} -+ -+/* Verify various aspects of field width handling, including the data -+ obtained, the number of bytes consumed, and the stream position. */ -+ -+static int -+do_test (void) -+{ -+ if (setlocale (LC_ALL, "pl_PL.UTF-8") == NULL) -+ FAIL_EXIT1 ("setlocale (LC_ALL, \"pl_PL.UTF-8\")"); -+ -+ /* Part of a tongue-twister in Polish, which says: -+ "On a rainy morning cuckoos and warblers, rather than starting -+ on earthworms, stuffed themselves fasted with the flesh of cress." */ -+ static const char s[126] = "Dżdżystym rankiem gżegżółki i piegże, " -+ "zamiast wziąć się za dżdżownice, " -+ "nażarły się na czczo miąższu rzeżuchy"; -+ -+ const char *sp = s; -+ size_t nc; -+ TEST_VERIFY_EXIT ((nc = mbsnrtowcs (NULL, &sp, sizeof (s), 0, NULL)) == 108); -+ -+ struct support_next_to_fault ntfo, ntfi; -+ ntfo = support_next_to_fault_allocate (nc * sizeof (wchar_t)); -+ ntfi = support_next_to_fault_allocate (sizeof (s)); -+ wchar_t *e = (wchar_t *) ntfo.buffer + nc; -+ char *b = ntfi.buffer; -+ -+ wchar_t *c; -+ FILE *f; -+ int ic; -+ int n; -+ int i; -+ -+ memcpy (ntfi.buffer, s, sizeof (s)); -+ -+ ic = i = 0; -+ f = xfmemopen (b, sizeof (s), "r"); -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ /* Avoid: "warning: zero width in gnu_scanf format [-Werror=format=]". */ -+ DIAG_PUSH_NEEDS_COMMENT; -+ DIAG_IGNORE_NEEDS_COMMENT (4.9, "-Wformat"); -+ TEST_VERIFY_EXIT (fscanf (f, "%0lc%n", c, &n) == 1); -+ DIAG_POP_NEEDS_COMMENT; -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 1; -+ i += n; -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 2); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 1; -+ i += n; -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%1lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 1; -+ i += n; -+ -+ c = e - 2; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 3); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 2; -+ i += n; -+ -+ c = e - 4; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%4lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 4); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 4; -+ i += n; -+ -+ c = e - 8; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%8lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 8); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 8; -+ i += n; -+ -+ c = e - 16; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%16lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 20); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 16; -+ i += n; -+ -+ c = e - 32; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%32lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 38); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 32; -+ i += n; -+ -+ c = e - (nc - ic); -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_COMPARE (fscanf (f, "%64lc%n", c, &n), 1); -+ TEST_COMPARE (n , 49); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, sizeof (s) - i) == 0); -+ -+ TEST_VERIFY_EXIT (ftell (f) == sizeof (s)); -+ TEST_VERIFY_EXIT (feof (f) != 0); -+ -+ xfclose (f); -+ -+ ic = i = 0; -+ f = xfmemopen (b, 3, "r"); -+ -+ c = e - 2; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 3); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 2; -+ i += n; -+ -+ c = e - (nc - ic); -+ TEST_VERIFY_EXIT (feof (f) == 0); -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2lc%n", c, &n) == EOF); -+ TEST_VERIFY_EXIT (n == 3); -+ -+ TEST_VERIFY_EXIT (ftell (f) == 3); -+ TEST_VERIFY_EXIT (feof (f) != 0); -+ -+ xfclose (f); -+ -+ ic = i = 0; -+ f = xfmemopen (b, 3, "r"); -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, n) == 0); -+ ic += 1; -+ i += n; -+ -+ c = e - (nc - ic); -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2lc%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 2); -+ TEST_VERIFY_EXIT (tst_bz12701_lc_memcmp (c, s + i, 3 - i) == 0); -+ -+ TEST_VERIFY_EXIT (ftell (f) == 3); -+ TEST_VERIFY_EXIT (feof (f) != 0); -+ -+ xfclose (f); -+ -+ support_next_to_fault_free (&ntfi); -+ support_next_to_fault_free (&ntfo); -+ -+ return 0; -+} -+ -+#include -diff --git a/stdio-common/Makefile b/stdio-common/Makefile -index e52c333808..fdb545242e 100644 ---- a/stdio-common/Makefile -+++ b/stdio-common/Makefile -@@ -260,6 +260,7 @@ tests := \ - tllformat \ - tst-bz11319 \ - tst-bz11319-fortify2 \ -+ tst-bz12701-c \ - tst-cookie \ - tst-dprintf-length \ - tst-fclose-devzero \ -diff --git a/stdio-common/tst-bz12701-c.c b/stdio-common/tst-bz12701-c.c -new file mode 100644 -index 0000000000..4f3616fbfd ---- /dev/null -+++ b/stdio-common/tst-bz12701-c.c -@@ -0,0 +1,169 @@ -+/* Verify scanf field width handling with the 'c' conversion (BZ #12701). -+ Copyright (C) 2025-2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+ -+#include -+#include -+#include -+#include -+ -+/* Verify various aspects of field width handling, including the data -+ obtained, the number of bytes consumed, and the stream position. */ -+ -+static int -+do_test (void) -+{ -+ static const char s[43] = "The quick brown fox jumps over the lazy dog"; -+ struct support_next_to_fault ntfo, ntfi; -+ ntfo = support_next_to_fault_allocate (sizeof (s)); -+ ntfi = support_next_to_fault_allocate (sizeof (s)); -+ char *e = ntfo.buffer + sizeof (s); -+ char *b = ntfi.buffer; -+ -+ char *c; -+ FILE *f; -+ int n; -+ int i; -+ -+ memcpy (ntfi.buffer, s, sizeof (s)); -+ -+ i = 0; -+ f = xfmemopen (b, sizeof (s), "r"); -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ /* Avoid: "warning: zero width in gnu_scanf format [-Werror=format=]". */ -+ DIAG_PUSH_NEEDS_COMMENT; -+ DIAG_IGNORE_NEEDS_COMMENT (4.9, "-Wformat"); -+ TEST_VERIFY_EXIT (fscanf (f, "%0c%n", c, &n) == 1); -+ DIAG_POP_NEEDS_COMMENT; -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%1c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - 2; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 2); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - 4; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%4c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 4); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - 8; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%8c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 8); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - 16; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%16c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 16); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - (sizeof (s) - i); -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%32c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 10); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, sizeof (s) - i) == 0); -+ -+ TEST_VERIFY_EXIT (ftell (f) == sizeof (s)); -+ TEST_VERIFY_EXIT (feof (f) != 0); -+ -+ xfclose (f); -+ -+ i = 0; -+ f = xfmemopen (b, 3, "r"); -+ -+ c = e - 1; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - 2; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 2); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - (3 - i); -+ TEST_VERIFY_EXIT (feof (f) == 0); -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2c%n", c, &n) == EOF); -+ TEST_VERIFY_EXIT (n == 2); -+ -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (feof (f) != 0); -+ -+ xfclose (f); -+ -+ i = 0; -+ f = xfmemopen (b, 3, "r"); -+ -+ c = e - 2; -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 2); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, n) == 0); -+ i += n; -+ -+ c = e - (3 - i); -+ TEST_VERIFY_EXIT (ftell (f) == i); -+ TEST_VERIFY_EXIT (fscanf (f, "%2c%n", c, &n) == 1); -+ TEST_VERIFY_EXIT (n == 1); -+ TEST_VERIFY_EXIT (memcmp (c, s + i, 3 - i) == 0); -+ -+ TEST_VERIFY_EXIT (ftell (f) == 3); -+ TEST_VERIFY_EXIT (feof (f) != 0); -+ -+ xfclose (f); -+ -+ support_next_to_fault_free (&ntfi); -+ support_next_to_fault_free (&ntfo); -+ -+ return 0; -+} -+ -+#include - -commit 6cebb0b80fd783e442a8ad27c3f52cde52a9cac7 -Author: DJ Delorie -Date: Wed May 27 12:57:10 2026 -0400 - - stdio-common: Allow partially-filled %mc buffers [BZ #12701] - - This is a backwards-compatible alternative to the main solution to - the %mc part of 12701. The allocated buffer is expanded to the - requested size and NUL padded, but truncated reads are allowed. - - Reviewed-by: Carlos O'Donell - -diff --git a/localedata/Makefile b/localedata/Makefile -index bff5c0bc71..e212facef0 100644 ---- a/localedata/Makefile -+++ b/localedata/Makefile -@@ -237,6 +237,7 @@ tests = \ - bug-setlocale1 \ - bug-usesetlocale \ - tst-bz12701-lc \ -+ tst-bz12701-lc2 \ - tst-bz13988 \ - tst-c-utf8-consistency \ - tst-digits \ -diff --git a/localedata/tst-bz12701-lc2.c b/localedata/tst-bz12701-lc2.c -new file mode 100644 -index 0000000000..b24e86df0b ---- /dev/null -+++ b/localedata/tst-bz12701-lc2.c -@@ -0,0 +1,47 @@ -+/* Verify scanf memory handling with the 'c' conversion (BZ #12701). -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+ -+#include -+#include -+#include -+#include -+ -+static int -+do_test (void) -+{ -+ wchar_t *c = NULL; -+ int i; -+ -+ TEST_VERIFY (sscanf ("1234", "%30mlc", &c) == 1); -+ -+ TEST_VERIFY (c != NULL); -+ TEST_COMPARE_BLOB (c, 5 * sizeof (wchar_t), -+ L"1234\0", 5 * sizeof (wchar_t)); -+ for (i = 5; i < 30; i ++) -+ TEST_VERIFY (c[i] == L'\0'); -+ -+ TEST_VERIFY (malloc_usable_size (c) >= 30 * sizeof(wchar_t)); -+ -+ return 0; -+} -+ -+#include -diff --git a/stdio-common/Makefile b/stdio-common/Makefile -index fdb545242e..27e7ea20f0 100644 ---- a/stdio-common/Makefile -+++ b/stdio-common/Makefile -@@ -261,6 +261,7 @@ tests := \ - tst-bz11319 \ - tst-bz11319-fortify2 \ - tst-bz12701-c \ -+ tst-bz12701-c2 \ - tst-cookie \ - tst-dprintf-length \ - tst-fclose-devzero \ -diff --git a/stdio-common/tst-bz12701-c2.c b/stdio-common/tst-bz12701-c2.c -new file mode 100644 -index 0000000000..5f9ca7c592 ---- /dev/null -+++ b/stdio-common/tst-bz12701-c2.c -@@ -0,0 +1,46 @@ -+/* Verify scanf memory handling with the 'c' conversion (BZ #12701). -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+ -+#include -+#include -+#include -+#include -+ -+static int -+do_test (void) -+{ -+ char *c = NULL; -+ int i; -+ -+ TEST_VERIFY (sscanf ("1234", "%30mc", &c) == 1); -+ -+ TEST_VERIFY (c != NULL); -+ TEST_COMPARE_BLOB (c, 5, "1234\0", 5); -+ for (i = 5; i < 30; i ++) -+ TEST_VERIFY (c[i] == '\0'); -+ -+ TEST_VERIFY (malloc_usable_size (c) >= 30); -+ -+ return 0; -+} -+ -+#include -diff --git a/stdio-common/vfscanf-internal.c b/stdio-common/vfscanf-internal.c -index 17b5565d0f..90a1886951 100644 ---- a/stdio-common/vfscanf-internal.c -+++ b/stdio-common/vfscanf-internal.c -@@ -780,9 +780,9 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, - conv_error (); \ - } while (0) - #ifdef COMPILE_WSCANF -- STRING_ARG (str, char, 100); -+ STRING_ARG (str, char, (width > 0 ? width : 1)); - #else -- STRING_ARG (str, char, (width > 1024 ? 1024 : width)); -+ STRING_ARG (str, char, (width > 0 ? width : 1)); - #endif - - c = inchar (); -@@ -891,6 +891,11 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, - - if (!(flags & SUPPRESS)) - { -+ /* If the buffer isn't completely filled, pad it with NULs. */ -+ if (flags & MALLOC) -+ while (width-- > 0) -+ *str++ = '\0'; -+ - if ((flags & MALLOC) && str - *strptr != strsize) - { - char *cp = (char *) realloc (*strptr, str - *strptr); -@@ -908,7 +913,7 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, - if (width == -1) - width = 1; - -- STRING_ARG (wstr, wchar_t, (width > 1024 ? 1024 : width)); -+ STRING_ARG (wstr, wchar_t, (width > 0 ? width : 1)); - - c = inchar (); - if (__glibc_unlikely (c == EOF)) -@@ -1044,6 +1049,11 @@ __vfscanf_internal (FILE *s, const char *format, va_list argptr, - - if (!(flags & SUPPRESS)) - { -+ /* If the buffer isn't completely filled, pad it with NULs. */ -+ if (flags & MALLOC) -+ while (width-- > 0) -+ *wstr++ = L'\0'; -+ - if ((flags & MALLOC) && wstr - (wchar_t *) *strptr != strsize) - { - wchar_t *cp = (wchar_t *) realloc (*strptr, - -commit 748699d9385fc298f7d3369af0a015a6d88b7e64 -Author: Sam James -Date: Sat Jun 6 20:32:27 2026 +0100 - - elf: don't clobber ld.so.conf in tst-glibc-hwcaps-prepend-cache [BZ #34210] - - dbe5065f2166be20e57a24f246a40d50e001a05d and ae589cb84df10825fc545a45c7007a5f79409bf1 - cater for setups where ld.so.conf{,.d} is required to find runtime support - libraries, but tst-glibc-hwcaps-prepend-cache clobbers the created ld.so.conf - with its own entry. - - Fix it to instead use the ld.so.conf.d created in ae589cb84df10825fc545a45c7007a5f79409bf1 - to co-exist with existing entries. - - Bug: https://bugs.gentoo.org/976773 - Bug: https://sourceware.org/bugzilla/show_bug.cgi?id=31901 - Bug: https://sourceware.org/bugzilla/show_bug.cgi?id=34210 - Tested-by: Andreas K. Hüttel - Reported-by: Eli Schwartz - Reviewed-by: Andreas K. Hüttel - (cherry picked from commit d0cc9bf859d0434e397530d75a6507f13db79fba) - -diff --git a/elf/tst-glibc-hwcaps-prepend-cache.c b/elf/tst-glibc-hwcaps-prepend-cache.c -index b7df3962b5..2d51c22328 100644 ---- a/elf/tst-glibc-hwcaps-prepend-cache.c -+++ b/elf/tst-glibc-hwcaps-prepend-cache.c -@@ -46,7 +46,7 @@ do_test (void) - - { - /* Install the default implementation of libmarkermod1.so. */ -- char *conf_path = xasprintf ("%s/ld.so.conf", support_sysconfdir_prefix); -+ char *conf_path = xasprintf ("%s/ld.so.conf.d/hwcaps.conf", support_sysconfdir_prefix); - xmkdirp (support_sysconfdir_prefix, 0777); - support_write_file_string (conf_path, "/glibc-test/lib\n"); - free (conf_path); - -commit f671746f6c3ae511432b5666953be668267159f8 -Author: Florian Weimer -Date: Tue Jun 9 07:28:02 2026 +0200 - - iconv: Suppress intermediate errors with //TRANSLIT (bug 34236) - - When tentatively converting characters on behalf of - __gconv_transliterate, do not create a persistent error. Just - produce a local error, and rely on __gconv_transliterate to - produce the error if all transliteration options are exhausted. - - This fixes transliteration of “½” to ASCII, which cannot use the - “ 1⁄2 ” alternative. Eventually, the “ 1/2 ” alternative is chosen, - but the error sticks. Therefore, iconv exited with status 1 before - this change. - - Adjust iconv/tst-iconv_prog.sh to test both C and en_US.UTF-8 locales. - This requires changing the way the ICONV template is defined, so that - run_program_env is evaluated multiple times. - - Fixes commit 9a4b0eaf726f5404c6683d5c7c5e86f61c3f3fbc ("iconv: do not - report error exit with transliteration [BZ #32448]"), - commit 6cbf845fcdc76131d0e674cee454fe738b69c69d ("iconv: Preserve - iconv -c error exit on invalid inputs (bug 32046)"), and bug 34236. - - Reviewed-by: Aurelien Jarno - (cherry picked from commit e9325bd7d04aacc45cf39505e279b1ca9de22c08) - -diff --git a/iconv/Makefile b/iconv/Makefile -index 9a94a41ba4..028d24ffc3 100644 ---- a/iconv/Makefile -+++ b/iconv/Makefile -@@ -138,7 +138,8 @@ $(objpfx)test-iconvconfig.out: $(objpfx)iconvconfig - rm -f $$tmp) > $@; \ - $(evaluate-test) - --$(objpfx)tst-iconv_prog.out: tst-iconv_prog.sh $(objpfx)iconv_prog -+$(objpfx)tst-iconv_prog.out: tst-iconv_prog.sh $(objpfx)iconv_prog \ -+ $(gen-locales) - $(BASH) $< $(common-objdir) '$(test-wrapper-env)' \ - '$(run-program-env)' > $@; \ - $(evaluate-test) -diff --git a/iconv/loop.c b/iconv/loop.c -index 1378d23147..74b2a3e26d 100644 ---- a/iconv/loop.c -+++ b/iconv/loop.c -@@ -144,8 +144,10 @@ - if (irreversible == NULL) \ - { \ - /* This means we are in call from __gconv_transliterate. In this \ -- case we are not doing any error recovery ourselves. */ \ -- result = __gconv_mark_illegal_input (step_data); \ -+ case we are not doing any error recovery ourselves. Do not create \ -+ a persistent error state. If __gconv_transliterate exhausts all \ -+ alternatives, it will call __gconv_mark_illegal_input itself. */ \ -+ result = __GCONV_ILLEGAL_INPUT; \ - break; \ - } \ - \ -diff --git a/iconv/tst-iconv_prog.sh b/iconv/tst-iconv_prog.sh -index e2a43280d2..7d7948b7aa 100644 ---- a/iconv/tst-iconv_prog.sh -+++ b/iconv/tst-iconv_prog.sh -@@ -27,10 +27,10 @@ LIBPATH=$codir:$codir/iconvdata - - # How the start the iconv(1) program. $from is not defined/expanded yet. - ICONV=' -+$test_wrapper_env $run_program_env - $codir/elf/ld.so --library-path $LIBPATH --inhibit-rpath ${from}.so - $codir/iconv/iconv_prog - ' --ICONV="$test_wrapper_env $run_program_env $ICONV" - - TIMEOUTFACTOR=${TIMEOUTFACTOR:-1} - -@@ -218,6 +218,7 @@ testarray=( - "\x00\x00;;INVALID;UTF-8;1" - "\x00\x00;;UTF-8;INVALID;1" - "\xc3\xa9;;UTF-8;ASCII//TRANSLIT;0" -+"X\xc2\xbdY;;UTF-8;ASCII//TRANSLIT;0" - ) - - # Requires $twobyte input, $c flag, $from, and $to to be set; sets $ret -@@ -278,12 +279,21 @@ check_errtest_result () - fi - } - --for testcommand in "${testarray[@]}"; do -- twobyte="$(echo "$testcommand" | cut -d";" -f 1)" -- c="$(echo "$testcommand" | cut -d";" -f 2)" -- from="$(echo "$testcommand" | cut -d";" -f 3)" -- to="$(echo "$testcommand" | cut -d";" -f 4)" -- eret="$(echo "$testcommand" | cut -d";" -f 5)" -- execute_test -- check_errtest_result --done -+run_test_array () -+{ -+ for testcommand in "${testarray[@]}"; do -+ twobyte="$(echo "$testcommand" | cut -d";" -f 1)" -+ c="$(echo "$testcommand" | cut -d";" -f 2)" -+ from="$(echo "$testcommand" | cut -d";" -f 3)" -+ to="$(echo "$testcommand" | cut -d";" -f 4)" -+ eret="$(echo "$testcommand" | cut -d";" -f 5)" -+ execute_test -+ check_errtest_result -+ done -+} -+ -+echo "info: testing C locale" -+run_test_array -+echo "info: testing en_US.UTF-8 locale" -+run_program_env="$run_program_env LC_ALL=en_US.UTF-8" -+run_test_array - -commit f6713070c6accac5c93d96c1d580833afacde3f5 -Author: Adhemerval Zanella -Date: Wed May 13 08:32:24 2026 -0300 - - arm: Save/restore VFP registers in PLT trampolines (BZ 34144, BZ 15792) - - _dl_runtime_resolve and _dl_runtime_profile only preserved the integer - argument registers (r0-r3) across the inner call to _dl_fixup / - _dl_profile_fixup. Two related ABI requirements demand more: - - * Under AAPCS-VFP, d0-d7 hold the caller's double arguments to the - function being resolved. Recent GCC emits VFP instructions inside - the fixup routines, clobbering them, so the resolved function sees - corrupted arguments (BZ 34144). - - * Per RTABI32, the __aeabi_mem* helpers (and similar runtime helpers - reachable through the dynamic linker) must only corrupt integer - core registers. IFUNC resolvers, audit modules, and interposed - malloc invoked during symbol resolution may also use VFP, even on - softfp ABI builds (BZ 15792). - - Save all call-clobbered VFP state -- d0-d15 unconditionally, d16-d31 - when HWCAP_ARM_VFPD32 is set, and fpscr -- around the inner fixup - call. Whether VFP is usable is a property of the hardware, not of - the ABI glibc was built with, so the decision is gated on AT_HWCAP at - runtime in both hardfp and softfp builds; hardfp builds will always - find HWCAP_ARM_VFP set, while softfp builds running on a non-VFP CPU - correctly skip the save. - - For _dl_runtime_profile the save area is slipped in just before the - bl to _dl_profile_fixup; the outgoing framesizep argument is - recomputed to account for the extra frame, and both the fast path - (no audit framesize) and the slow path (audit wraps with - pltenter/pltexit) traverse the restore before splitting. - - Checked on arm-linux-gnueabihf. - - Tested-by: Aurelien Jarno - Reviewed-by: Wilco Dijkstra - (cherry picked from commit 1111fbdd3e7ebed402800bc23e67055eaae0d972) - -diff --git a/sysdeps/arm/Makefile b/sysdeps/arm/Makefile -index 9c4fd6b236..be9e46aeeb 100644 ---- a/sysdeps/arm/Makefile -+++ b/sysdeps/arm/Makefile -@@ -30,6 +30,25 @@ $(objpfx)tst-armtlsdescloc: $(objpfx)tst-armtlsdesclocmod.so - $(objpfx)tst-armtlsdescextnow: $(objpfx)tst-armtlsdescextnowmod.so - $(objpfx)tst-armtlsdescextlazy: $(objpfx)tst-armtlsdescextlazymod.so - endif -+ -+tests += \ -+ tst-bz34144 \ -+ tst-bz34144-audit \ -+ # tests -+modules-names += \ -+ tst-bz34144-auditmod \ -+ tst-bz34144-mod \ -+ # modules-names -+$(objpfx)tst-bz34144: $(objpfx)tst-bz34144-mod.so -+$(objpfx)tst-bz34144-audit: $(objpfx)tst-bz34144-mod.so -+$(objpfx)tst-bz34144-audit.out: $(objpfx)tst-bz34144-auditmod.so -+# Use lazy binding to check if _dl_runtime_resolve correctly save/restore -+# the VFP state. -+LDFLAGS-tst-bz34144 = -Wl,-z,lazy -+# With LD_AUDIT, lazy resolution goes through _dl_runtime_profile, which -+# must also save/restore VFP state (BZ 34144). -+LDFLAGS-tst-bz34144-audit = -Wl,-z,lazy -+tst-bz34144-audit-ENV = LD_AUDIT=$(objpfx)tst-bz34144-auditmod.so - endif - endif - -diff --git a/sysdeps/arm/dl-trampoline.S b/sysdeps/arm/dl-trampoline.S -index fffac55050..ef358d48bc 100644 ---- a/sysdeps/arm/dl-trampoline.S -+++ b/sysdeps/arm/dl-trampoline.S -@@ -20,6 +20,7 @@ - #define NO_THUMB - #include - #include -+#include - - .text - .globl _dl_runtime_resolve -@@ -36,13 +37,40 @@ _dl_runtime_resolve: - @ ip contains &GOT[n+3] (pointer to function) - @ lr points to &GOT[2] - -- @ Save arguments. We save r4 to realign the stack. -+ @ Save arguments. We save r4 to realign the stack and to hold -+ @ the hwcap value used to decide whether to save VFP registers. - push {r0-r4} - cfi_adjust_cfa_offset (20) - cfi_rel_offset (r0, 0) - cfi_rel_offset (r1, 4) - cfi_rel_offset (r2, 8) - cfi_rel_offset (r3, 12) -+ cfi_rel_offset (r4, 16) -+ -+#ifdef SHARED -+ @ Preserve all call-clobbered VFP registers across _dl_fixup. -+ @ VFP may be used by IFUNC resolvers, audit modules, interposed -+ @ malloc, and the __aeabi_mem* helpers required by RTABI32, -+ @ which mandates that those helpers only corrupt integer core -+ @ registers. -+ LDR_GLOBAL (r4, r3, C_SYMBOL_NAME(_rtld_global_ro), \ -+ RTLD_GLOBAL_RO_DL_HWCAP_OFFSET) -+ -+ tst r4, #HWCAP_ARM_VFP -+ beq .Lno_vfp_save -+ -+# define VFP_STACK_REQ (32*8 + 8) -+ sub sp, sp, VFP_STACK_REQ -+ cfi_adjust_cfa_offset (VFP_STACK_REQ) -+ mov r3, sp -+ .inst 0xeca30b20 @ vstmia r3!, {d0-d15} -+ tst r4, #HWCAP_ARM_VFPD32 -+ beq 1f -+ .inst 0xece30b20 @ vstmia r3!, {d16-d31} -+1: .inst 0xeef12a10 @ vmrs r2, fpscr -+ str r2, [r3] -+.Lno_vfp_save: -+#endif /* SHARED */ - - @ get pointer to linker struct - ldr r0, [lr, #-4] -@@ -59,8 +87,23 @@ _dl_runtime_resolve: - @ save the return - mov ip, r0 - -- @ get arguments and return address back. We restore r4 -- @ only to realign the stack. -+#ifdef SHARED -+ tst r4, #HWCAP_ARM_VFP -+ beq .Lno_vfp_restore -+ mov r3, sp -+ .inst 0xecb30b20 @ vldmia r3!, {d0-d15} -+ tst r4, #HWCAP_ARM_VFPD32 -+ beq 2f -+ .inst 0xecf30b20 @ vldmia r3!, {d16-d31} -+2: ldr r2, [r3] -+ .inst 0xeee12a10 @ vmsr fpscr, r2 -+ add sp, sp, VFP_STACK_REQ -+ cfi_adjust_cfa_offset (-VFP_STACK_REQ) -+.Lno_vfp_restore: -+#endif /* SHARED */ -+ -+ @ get arguments and return address back. We restore r4 to -+ @ its original value as well. - pop {r0-r4,lr} - cfi_adjust_cfa_offset (-24) - -@@ -124,14 +167,71 @@ _dl_runtime_profile: - add r3, sp, #8 - stmia r3!, {r0,r1} - -+ @ Preserve all call-clobbered VFP registers across -+ @ _dl_profile_fixup. See the matching comment in -+ @ _dl_runtime_resolve above for the rationale (BZ 34144, -+ @ BZ 15792). -+ @ -+ @ Stack layout below the current sp (which becomes the new sp -+ @ after the sub): -+ @ sp + 0 .. 3: outgoing arg (framesizep) for _dl_profile_fixup -+ @ sp + 4 .. 7: saved hwcap (so we can test it after the call) -+ @ sp + 8 .. 11: saved r2 (used as scratch for LDR_GLOBAL) -+ @ sp + 12 .. 15: padding (for 8-byte alignment of the VFP area) -+ @ sp + 16 .. 16+VFP_STACK_REQ-1: VFP regs + fpscr -+#define VFP_PROFILE_STACK (16 + VFP_STACK_REQ) -+ sub sp, sp, #VFP_PROFILE_STACK -+ cfi_adjust_cfa_offset (VFP_PROFILE_STACK) -+ -+ @ r2 holds the retaddr (3rd arg to _dl_profile_fixup); spill -+ @ it so we can use it as the LDR_GLOBAL destination. -+ str r2, [sp, #8] -+ -+ LDR_GLOBAL (r2, ip, C_SYMBOL_NAME(_rtld_global_ro), \ -+ RTLD_GLOBAL_RO_DL_HWCAP_OFFSET) -+ str r2, [sp, #4] -+ -+ tst r2, #HWCAP_ARM_VFP -+ beq .Lprofile_no_vfp_save -+ add ip, sp, #16 -+ .inst 0xecac0b20 @ vstmia ip!, {d0-d15} -+ tst r2, #HWCAP_ARM_VFPD32 -+ beq 7f -+ .inst 0xecec0b20 @ vstmia ip!, {d16-d31} -+7: .inst 0xeef12a10 @ vmrs r2, fpscr -+ str r2, [ip] -+.Lprofile_no_vfp_save: -+ -+ @ Restore r2 (retaddr) for _dl_profile_fixup. -+ ldr r2, [sp, #8] -+ - @ Set up extra args for _dl_profile_fixup. -- @ r2 and r3 are already loaded. -- add ip, sp, #208 -+ @ The framesize slot is at the old sp+208, which is the new -+ @ sp + VFP_PROFILE_STACK + 208 -- compute in two steps because -+ @ the combined offset is not encodable as an ARM immediate. -+ add ip, sp, #VFP_PROFILE_STACK -+ add ip, ip, #208 - str ip, [sp, #0] - - @ call profiling fixup routine - bl _dl_profile_fixup - -+ @ Restore VFP registers. r0 holds the resolved function -+ @ address; r1/r2/ip are caller-saved by the call. -+ ldr r1, [sp, #4] -+ tst r1, #HWCAP_ARM_VFP -+ beq .Lprofile_no_vfp_restore -+ add ip, sp, #16 -+ .inst 0xecbc0b20 @ vldmia ip!, {d0-d15} -+ tst r1, #HWCAP_ARM_VFPD32 -+ beq 8f -+ .inst 0xecfc0b20 @ vldmia ip!, {d16-d31} -+8: ldr r2, [ip] -+ .inst 0xeee12a10 @ vmsr fpscr, r2 -+.Lprofile_no_vfp_restore: -+ add sp, sp, #VFP_PROFILE_STACK -+ cfi_adjust_cfa_offset (-VFP_PROFILE_STACK) -+ - @ The address to call is now in r0. - - @ Check whether we're wrapping this function. -diff --git a/sysdeps/arm/tst-bz34144-audit.c b/sysdeps/arm/tst-bz34144-audit.c -new file mode 100644 -index 0000000000..8f1084fa0a ---- /dev/null -+++ b/sysdeps/arm/tst-bz34144-audit.c -@@ -0,0 +1,32 @@ -+/* Test that lazy PLT resolution via _dl_runtime_profile preserves -+ caller-saved VFP registers used to pass double arguments (BZ 34144). -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+ -+extern void test_float_args (double a, double b, double c, double d, -+ double e, double f, double g, double h); -+ -+static int -+do_test (void) -+{ -+ test_float_args (2.0, 3.0, 4.0, 5.0, 6.0, 7.0, 8.0, 9.0); -+ return 0; -+} -+ -+#include -diff --git a/sysdeps/arm/tst-bz34144-auditmod.c b/sysdeps/arm/tst-bz34144-auditmod.c -new file mode 100644 -index 0000000000..ada9f126c2 ---- /dev/null -+++ b/sysdeps/arm/tst-bz34144-auditmod.c -@@ -0,0 +1,50 @@ -+/* Minimal audit module used by tst-bz34144-audit to force PLT calls -+ to go through _dl_runtime_profile instead of _dl_runtime_resolve. -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+ -+unsigned int -+la_version (unsigned int v) -+{ -+ return v; -+} -+ -+unsigned int -+la_objopen (struct link_map *l, Lmid_t lmid, uintptr_t *cookie) -+{ -+ return LA_FLG_BINDFROM | LA_FLG_BINDTO; -+} -+ -+uintptr_t -+la_symbind32 (Elf32_Sym *sym, unsigned int ndx, uintptr_t *refcook, -+ uintptr_t *defcook, unsigned int *flags, const char *symname) -+{ -+ return sym->st_value; -+} -+ -+Elf32_Addr -+la_arm_gnu_pltenter (Elf32_Sym *sym, unsigned int ndx, uintptr_t *refcook, -+ uintptr_t *defcook, La_arm_regs *regs, -+ unsigned int *flags, const char *symname, -+ long int *framesizep) -+{ -+ return sym->st_value; -+} -diff --git a/sysdeps/arm/tst-bz34144-mod.c b/sysdeps/arm/tst-bz34144-mod.c -new file mode 100644 -index 0000000000..be6b54bf91 ---- /dev/null -+++ b/sysdeps/arm/tst-bz34144-mod.c -@@ -0,0 +1,28 @@ -+/* DSO used by tst-bz34144. -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+ -+void -+test_float_args (double a, double b, double c, double d, -+ double e, double f, double g, double h) -+{ -+ if (a != 2.0 || b != 3.0 || c != 4.0 || d != 5.0 -+ || e != 6.0 || f != 7.0 || g != 8.0 || h != 9.0) -+ abort (); -+} -diff --git a/sysdeps/arm/tst-bz34144.c b/sysdeps/arm/tst-bz34144.c -new file mode 100644 -index 0000000000..61e41b3945 ---- /dev/null -+++ b/sysdeps/arm/tst-bz34144.c -@@ -0,0 +1,32 @@ -+/* Test that lazy PLT resolution preserves caller-saved VFP registers -+ used to pass double arguments (BZ 34144). -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+ -+extern void test_float_args (double a, double b, double c, double d, -+ double e, double f, double g, double h); -+ -+static int -+do_test (void) -+{ -+ test_float_args (2.0, 3.0, 4.0, 5.0, 6.0, 7.0, 8.0, 9.0); -+ return 0; -+} -+ -+#include - -commit 0be5a6a72a4a3132bc211720d2b6949a84f54dc3 -Author: John David Anglin -Date: Tue Jun 23 13:41:10 2026 -0400 - - hppa: Fix missing call to __feraiseexcept (BZ 34306) - - The feupdateenv function is supposed to raise exceptions after - installing the environment represented by its envp argument. - This was accidentally missed on hppa. - - The failure to raise exceptions was noticed by the failure of - the math/test-narrowing-trap test. - - Signed-off-by: John David Anglin - -diff --git a/sysdeps/hppa/fpu/feupdateenv.c b/sysdeps/hppa/fpu/feupdateenv.c -index 46b83cc7a0..a3d3de33e4 100644 ---- a/sysdeps/hppa/fpu/feupdateenv.c -+++ b/sysdeps/hppa/fpu/feupdateenv.c -@@ -24,6 +24,7 @@ __feupdateenv (const fenv_t *envp) - { - union { unsigned long long l; unsigned int sw[2]; } s; - fenv_t temp; -+ - /* Get the current exception status */ - __asm__ ("fstd %%fr0,0(%1) \n\t" - "fldd 0(%1),%%fr0 \n\t" -@@ -46,6 +47,10 @@ __feupdateenv (const fenv_t *envp) - - /* Install new environment. */ - __fesetenv (&temp); -+ -+ /* Raise exceptions. */ -+ __feraiseexcept (temp.__status_word >> 27); -+ - /* Success. */ - return 0; - } - -commit 54929540335ef339ac66a8c28e3f4c22ebae2630 -Author: Fabian Rast -Date: Thu Jun 11 14:30:37 2026 +0200 - - rtld: cache cpuid results on the stack for intel - - dl_init_cacheinfo retrieves various information about cache - sizes, using the cpuid instruction on x86. - Previously, the same cpuid leaves were queried multiple times. - This behavior caused intel_check_word to prominently show up in - profiles of dynamic loader startup on the Intel(R) Xeon(R) Gold 6430. - The big performance impact could not be reproduced on other Intel cpus. - - This patch reduces the number of cpuid queries on startup - by caching their results on the stack for reuse when searching for a - different cache size value. - This approach does not change the overall design of - the cache enumeration code (repeated calls to handle_* functions). - The values are cached on the stack instead of globally (e.g. - in the cpu_features global) because they are never needed after - early initialization. - - The cache is only active for Intel cpus, because it has not yet - been shown through benchmarks that it meaningfully improves performance - for other processors. - - Signed-off-by: Fabian Rast - Reviewed-by: Sunil K Pandey - (cherry picked from commit df83fa8813eb53dcb232462a4f6dd00c873115f0) - -diff --git a/sysdeps/x86/dl-cacheinfo.h b/sysdeps/x86/dl-cacheinfo.h -index 6f9bb08a19..201d3ad278 100644 ---- a/sysdeps/x86/dl-cacheinfo.h -+++ b/sysdeps/x86/dl-cacheinfo.h -@@ -98,6 +98,15 @@ static const struct intel_02_cache_info - - #define nintel_02_known (sizeof (intel_02_known) / sizeof (intel_02_known [0])) - -+/* Cache for redundant cpuid queries in handle_intel, intel_check_word and -+ get_common_cache_info. Currently, this has only been shown to significantly -+ improve performance on a specific Intel CPU (Xeon 6430). */ -+struct intel_cpuid_cache -+{ -+ unsigned char leaf2_valid, leaf4_valid; /* Number of cached (sub)leaves. */ -+ unsigned int leaf2[4], leaf4[0x10][4]; -+}; -+ - static int - intel_02_known_compare (const void *p1, const void *p2) - { -@@ -118,7 +127,8 @@ static long int - __attribute__ ((noinline)) - intel_check_word (int name, unsigned int value, bool *has_level_2, - bool *no_level_2_or_3, -- const struct cpu_features *cpu_features) -+ const struct cpu_features *cpu_features, -+ struct intel_cpuid_cache *cache) - { - if ((value & 0x80000000) != 0) - /* The register value is reserved. */ -@@ -152,7 +162,21 @@ intel_check_word (int name, unsigned int value, bool *has_level_2, - unsigned int round = 0; - while (1) - { -- __cpuid_count (4, round, eax, ebx, ecx, edx); -+ if (round < cache->leaf4_valid) -+ /* Subleaf was queried before. Do not execute cpuid again. */ -+ eax = cache->leaf4[round][0], ebx = cache->leaf4[round][1], -+ ecx = cache->leaf4[round][2], edx = cache->leaf4[round][3]; -+ else if (round == cache->leaf4_valid -+ && round < sizeof(cache->leaf4)/sizeof(*cache->leaf4)) -+ { -+ /* Cache the cpuid result if we have space. */ -+ __cpuid_count (4, round, eax, ebx, ecx, edx); -+ cache->leaf4[round][0] = eax, cache->leaf4[round][1] = ebx; -+ cache->leaf4[round][2] = ecx, cache->leaf4[round][3] = edx; -+ cache->leaf4_valid++; -+ } -+ else -+ __cpuid_count (4, round, eax, ebx, ecx, edx); - - enum { null = 0, data = 1, inst = 2, uni = 3 } type = eax & 0x1f; - if (type == null) -@@ -247,7 +271,8 @@ intel_check_word (int name, unsigned int value, bool *has_level_2, - - - static long int __attribute__ ((noinline)) --handle_intel (int name, const struct cpu_features *cpu_features) -+handle_intel (int name, const struct cpu_features *cpu_features, -+ struct intel_cpuid_cache *cache) - { - unsigned int maxidx = cpu_features->basic.max_cpuid; - -@@ -260,41 +285,33 @@ handle_intel (int name, const struct cpu_features *cpu_features) - long int result = 0; - bool no_level_2_or_3 = false; - bool has_level_2 = false; -- unsigned int eax; -- unsigned int ebx; -- unsigned int ecx; -- unsigned int edx; -- __cpuid (2, eax, ebx, ecx, edx); -+ int i; -+ -+ if (!cache->leaf2_valid) -+ { -+ __cpuid (2, cache->leaf2[0], cache->leaf2[1], -+ cache->leaf2[2], cache->leaf2[3]); -+ cache->leaf2_valid = 1; -+ } - - /* The low byte of EAX of CPUID leaf 2 should always return 1 and it - should be ignored. If it isn't 1, use CPUID leaf 4 instead. */ -- if ((eax & 0xff) != 1) -+ if ((cache->leaf2[0] & 0xff) != 1) - return intel_check_word (name, 0xff, &has_level_2, &no_level_2_or_3, -- cpu_features); -- else -- { -- eax &= 0xffffff00; -- -- /* Process the individual registers' value. */ -- result = intel_check_word (name, eax, &has_level_2, -- &no_level_2_or_3, cpu_features); -- if (result != 0) -- return result; -+ cpu_features, cache); - -- result = intel_check_word (name, ebx, &has_level_2, -- &no_level_2_or_3, cpu_features); -- if (result != 0) -- return result; -- -- result = intel_check_word (name, ecx, &has_level_2, -- &no_level_2_or_3, cpu_features); -- if (result != 0) -- return result; -+ /* Process all descriptors in leaf 2. */ -+ result = intel_check_word (name, cache->leaf2[0]&0xffffff00, &has_level_2, -+ &no_level_2_or_3, cpu_features, cache); -+ if (result != 0) -+ return result; - -- result = intel_check_word (name, edx, &has_level_2, -- &no_level_2_or_3, cpu_features); -+ for (i = 1; i < 4; i++) -+ { -+ result = intel_check_word (name, cache->leaf2[i], &has_level_2, -+ &no_level_2_or_3, cpu_features, cache); - if (result != 0) -- return result; -+ return result; - } - - if (name >= _SC_LEVEL2_CACHE_SIZE && name <= _SC_LEVEL3_CACHE_LINESIZE -@@ -611,7 +628,7 @@ handle_hygon (int name) - - static void - get_common_cache_info (long int *shared_ptr, long int * shared_per_thread_ptr, unsigned int *threads_ptr, -- long int core) -+ long int core, struct intel_cpuid_cache *cache) - { - unsigned int eax; - unsigned int ebx; -@@ -669,7 +686,14 @@ get_common_cache_info (long int *shared_ptr, long int * shared_per_thread_ptr, u - int check = 0x1 | (threads_l3 == 0) << 1; - do - { -- __cpuid_count (4, i++, eax, ebx, ecx, edx); -+ if (cache != NULL && i < cache->leaf4_valid) -+ eax = cache->leaf4[i][0], ebx = cache->leaf4[i][1], -+ ecx = cache->leaf4[i][2], edx = cache->leaf4[i][3]; -+ else -+ /* Do not attempt to cache queries at this point, -+ because get_common_cache_info is called last. */ -+ __cpuid_count (4, i, eax, ebx, ecx, edx); -+ i++; - - /* There seems to be a bug in at least some Pentium Ds - which sometimes fail to iterate all cache parameters. -@@ -849,35 +873,38 @@ dl_init_cacheinfo (struct cpu_features *cpu_features) - - if (cpu_features->basic.kind == arch_kind_intel) - { -- data = handle_intel (_SC_LEVEL1_DCACHE_SIZE, cpu_features); -- shared = handle_intel (_SC_LEVEL3_CACHE_SIZE, cpu_features); -+ struct intel_cpuid_cache cache; -+ cache.leaf2_valid = cache.leaf4_valid = 0; -+ -+ data = handle_intel (_SC_LEVEL1_DCACHE_SIZE, cpu_features, &cache); -+ shared = handle_intel (_SC_LEVEL3_CACHE_SIZE, cpu_features, &cache); - shared_per_thread = shared; - - level1_icache_size -- = handle_intel (_SC_LEVEL1_ICACHE_SIZE, cpu_features); -+ = handle_intel (_SC_LEVEL1_ICACHE_SIZE, cpu_features, &cache); - level1_icache_linesize -- = handle_intel (_SC_LEVEL1_ICACHE_LINESIZE, cpu_features); -+ = handle_intel (_SC_LEVEL1_ICACHE_LINESIZE, cpu_features, &cache); - level1_dcache_size = data; - level1_dcache_assoc -- = handle_intel (_SC_LEVEL1_DCACHE_ASSOC, cpu_features); -+ = handle_intel (_SC_LEVEL1_DCACHE_ASSOC, cpu_features, &cache); - level1_dcache_linesize -- = handle_intel (_SC_LEVEL1_DCACHE_LINESIZE, cpu_features); -+ = handle_intel (_SC_LEVEL1_DCACHE_LINESIZE, cpu_features, &cache); - level2_cache_size -- = handle_intel (_SC_LEVEL2_CACHE_SIZE, cpu_features); -+ = handle_intel (_SC_LEVEL2_CACHE_SIZE, cpu_features, &cache); - level2_cache_assoc -- = handle_intel (_SC_LEVEL2_CACHE_ASSOC, cpu_features); -+ = handle_intel (_SC_LEVEL2_CACHE_ASSOC, cpu_features, &cache); - level2_cache_linesize -- = handle_intel (_SC_LEVEL2_CACHE_LINESIZE, cpu_features); -+ = handle_intel (_SC_LEVEL2_CACHE_LINESIZE, cpu_features, &cache); - level3_cache_size = shared; - level3_cache_assoc -- = handle_intel (_SC_LEVEL3_CACHE_ASSOC, cpu_features); -+ = handle_intel (_SC_LEVEL3_CACHE_ASSOC, cpu_features, &cache); - level3_cache_linesize -- = handle_intel (_SC_LEVEL3_CACHE_LINESIZE, cpu_features); -+ = handle_intel (_SC_LEVEL3_CACHE_LINESIZE, cpu_features, &cache); - level4_cache_size -- = handle_intel (_SC_LEVEL4_CACHE_SIZE, cpu_features); -+ = handle_intel (_SC_LEVEL4_CACHE_SIZE, cpu_features, &cache); - - get_common_cache_info (&shared, &shared_per_thread, &threads, -- level2_cache_size); -+ level2_cache_size, &cache); - } - else if (cpu_features->basic.kind == arch_kind_zhaoxin) - { -@@ -898,7 +925,7 @@ dl_init_cacheinfo (struct cpu_features *cpu_features) - level3_cache_linesize = handle_zhaoxin (_SC_LEVEL3_CACHE_LINESIZE); - - get_common_cache_info (&shared, &shared_per_thread, &threads, -- level2_cache_size); -+ level2_cache_size, NULL); - } - else if (cpu_features->basic.kind == arch_kind_amd) - { - -commit f2f55eac9e6f1167486f2694dea88adf87c77fdd -Author: Florian Weimer -Date: Fri Jun 19 18:22:20 2026 +0200 - - resolv: Declare __p_class_syms, __p_type_syms for internal use - - Reviewed-by: Carlos O'Donell - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 360f352c9a6da545d798ef3015e73ca114f0d230) - -diff --git a/include/resolv.h b/include/resolv.h -index 4dbbac3800..d5ad9994b9 100644 ---- a/include/resolv.h -+++ b/include/resolv.h -@@ -70,6 +70,11 @@ libc_hidden_proto (__libc_res_nameinquery) - extern __typeof (__res_queriesmatch) __libc_res_queriesmatch; - libc_hidden_proto (__libc_res_queriesmatch) - -+extern const struct res_sym __p_class_syms[]; -+libresolv_hidden_proto (__p_class_syms) -+extern const struct res_sym __p_type_syms[]; -+libresolv_hidden_proto (__p_type_syms) -+ - /* Variant of res_hnok which operates on binary (but uncompressed) names. */ - bool __res_binary_hnok (const unsigned char *dn) attribute_hidden; - -diff --git a/resolv/res_debug.c b/resolv/res_debug.c -index 73af0c72fe..6bf9962916 100644 ---- a/resolv/res_debug.c -+++ b/resolv/res_debug.c -@@ -390,8 +390,6 @@ p_fqname(const u_char *cp, const u_char *msg, FILE *file) { - * that C_ANY is a qclass but not a class. (You can ask for records of class - * C_ANY, but you can't have any records of that class in the database.) - */ --extern const struct res_sym __p_class_syms[]; --libresolv_hidden_proto (__p_class_syms) - const struct res_sym __p_class_syms[] = { - {C_IN, (char *) "IN"}, - {C_CHAOS, (char *) "CHAOS"}, -@@ -426,8 +424,6 @@ const struct res_sym __p_update_section_syms[] attribute_hidden = { - * Names of RR types and qtypes. The list is incomplete because its - * size is part of the ABI. - */ --extern const struct res_sym __p_type_syms[]; --libresolv_hidden_proto (__p_type_syms) - const struct res_sym __p_type_syms[] = { - {ns_t_a, (char *) "A", (char *) "address"}, - {ns_t_ns, (char *) "NS", (char *) "name server"}, - -commit 3c27e5170c456a69807348de8586c123f62a51f6 -Author: Florian Weimer -Date: Fri Jun 19 18:22:20 2026 +0200 - - resolv: Fix ns_sprintrrf formatting of class, type values (bug 34289) - - The p_class and p_type results could overwrite each other if both - were unknown. Format unknown values with CLASS and TYPE prefixes, - as in RFC 3597. Handle A6 separately because it cannot be added - to __p_type_syms for ABI reasons. - - Reviewed-by: Carlos O'Donell - Reviewed-by: Adhemerval Zanella - (cherry picked from commit f69b7f95e3694177546faec25d88bb266885c3b8) - -diff --git a/resolv/ns_print.c b/resolv/ns_print.c -index cef2212fd2..e75c39eaa8 100644 ---- a/resolv/ns_print.c -+++ b/resolv/ns_print.c -@@ -78,6 +78,24 @@ ns_sprintrr(const ns_msg *handle, const ns_rr *rr, - } - libresolv_hidden_def (ns_sprintrr) - -+/* Writes the class/type symbol NUMBER to *BUF, using the name from -+ *SYMS if possible. If NUMBER is not found in *SYMS, print the -+ number with PREFIX. */ -+static int -+addsym (const struct res_sym *syms, int number, const char *prefix, -+ char **buf, size_t *buflen) -+{ -+ for (; syms->name != NULL; syms++) -+ if (number == syms->number) -+ { -+ T (addstr (" ", 1, buf, buflen)); -+ return addstr (syms->name, strlen (syms->name), buf, buflen); -+ } -+ char tmp[20]; -+ int len = snprintf (tmp, sizeof (tmp), " %s%d", prefix, number); -+ return addstr (tmp, len, buf, buflen); -+} -+ - /*% - * Convert the fields of an RR into presentation format. - * -@@ -128,11 +146,21 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - /* - * TTL, Class, Type. - */ -- T(x = ns_format_ttl(ttl, buf, buflen)); -- addlen(x, &buf, &buflen); -- len = SPRINTF((tmp, " %s %s", p_class(class), p_type(type))); -- T(addstr(tmp, len, &buf, &buflen)); -- T(spaced = addtab(x + len, 16, spaced, &buf, &buflen)); -+ { -+ char *start = buf; -+ -+ T (x = ns_format_ttl (ttl, buf, buflen)); -+ addlen (x, &buf, &buflen); -+ T (addsym (__p_class_syms, class, "CLASS", &buf, &buflen)); -+ if (type == ns_t_a6) -+ /* A6 is not part of __p_type_syms, which is exported. -+ Adding A6 there would change its size. Handle it here. */ -+ T (addstr (" A6", 3, &buf, &buflen)); -+ else -+ T (addsym (__p_type_syms, type, "TYPE", &buf, &buflen)); -+ -+ T (spaced = addtab(buf - start, 16, spaced, &buf, &buflen)); -+ } - - /* - * RData. - -commit 509d819cea20f5d6c615eed1f869cc930effd9d2 -Author: Florian Weimer -Date: Fri Jun 19 18:22:20 2026 +0200 - - resolv: Improve formatting of unknown records in ns_sprintrrf - - Do not add the "unknown RR type" comment. After adding the TYPE - prefix, the number is largely redundant. - - Reviewed-by: Carlos O'Donell - Reviewed-by: Adhemerval Zanella - (cherry picked from commit d58415eb17d457a160af99f9e8ab164404ca151b) - -diff --git a/resolv/ns_print.c b/resolv/ns_print.c -index e75c39eaa8..3d38876483 100644 ---- a/resolv/ns_print.c -+++ b/resolv/ns_print.c -@@ -115,7 +115,6 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - - const char *comment; - char tmp[100]; -- char errbuf[40]; - int len, x; - - /* -@@ -590,20 +589,18 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - T(addstr(tmp, len, &buf, &buflen)); - break; - } -- - default: -- snprintf (errbuf, sizeof (errbuf), "unknown RR type %d", type); -- comment = errbuf; -+ comment = ""; - goto hexify; - } - return (buf - obuf); - formerr: -- comment = "RR format error"; -+ comment = " ; RR format error"; - hexify: { - int n, m; - char *p; - -- len = SPRINTF((tmp, "\\# %u%s\t; %s", (unsigned)(edata - rdata), -+ len = SPRINTF((tmp, "\\# %u%s%s", (unsigned)(edata - rdata), - rdlen != 0U ? " (" : "", comment)); - T(addstr(tmp, len, &buf, &buflen)); - while (rdata < edata) { - -commit 05dc6da0b4e12dbc60d3705e4961b823d3f7026d -Author: Florian Weimer -Date: Fri Jun 19 18:22:20 2026 +0200 - - resolv: Check for inet_ntop failure in ns_sprintrrf - - This makes the output more consistent (either failure or complete - output) and helps with systematic testing with varying buffer - sizes. - - Reviewed-by: Carlos O'Donell - Reviewed-by: Adhemerval Zanella - (cherry picked from commit cd0db208d56a2cecd528b8ae96df752ba5344d9a) - -diff --git a/resolv/ns_print.c b/resolv/ns_print.c -index 3d38876483..e58df5f35a 100644 ---- a/resolv/ns_print.c -+++ b/resolv/ns_print.c -@@ -167,8 +167,9 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - switch (type) { - case ns_t_a: - if (rdlen != (size_t)NS_INADDRSZ) -- goto formerr; -- (void) inet_ntop(AF_INET, rdata, buf, buflen); -+ goto formerr; -+ if (inet_ntop (AF_INET, rdata, buf, buflen) == NULL) -+ return -1; - addlen(strlen(buf), &buf, &buflen); - break; - -@@ -334,9 +335,10 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - } - - case ns_t_aaaa: -- if (rdlen != (size_t)NS_IN6ADDRSZ) -- goto formerr; -- (void) inet_ntop(AF_INET6, rdata, buf, buflen); -+ if (rdlen != (size_t)NS_IN6ADDRSZ) -+ goto formerr; -+ if (inet_ntop (AF_INET6, rdata, buf, buflen) == NULL) -+ return -1; - addlen(strlen(buf), &buf, &buflen); - break; - -@@ -427,7 +429,8 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - goto formerr; - - /* Address. */ -- (void) inet_ntop(AF_INET, rdata, buf, buflen); -+ if (inet_ntop (AF_INET, rdata, buf, buflen) == NULL) -+ return -1; - addlen(strlen(buf), &buf, &buflen); - rdata += NS_INADDRSZ; - -@@ -569,7 +572,8 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - if (rdata + pbyte >= edata) goto formerr; - memset(&a, 0, sizeof(a)); - memcpy(&a.s6_addr[pbyte], rdata, sizeof(a) - pbyte); -- (void) inet_ntop(AF_INET6, &a, buf, buflen); -+ if (inet_ntop (AF_INET6, &a, buf, buflen) == NULL) -+ return -1; - addlen(strlen(buf), &buf, &buflen); - rdata += sizeof(a) - pbyte; - } - -commit 299e1d25c32c5f9ef78ddd6cbfd0c6a09a1f4227 -Author: Florian Weimer -Date: Fri Jun 19 18:22:20 2026 +0200 - - resolv: More types as unknown in ns_sprintrrf (CVE-2026-5435) - - Specifically, CERT, TKEY, TSIG, OPT. This removes the buggy - implementations of TSIG, fixing bug 34033, and partially - fixing bug 34069. - - Reviewed-by: Carlos O'Donell - Reviewed-by: Adhemerval Zanella - (cherry picked from commit ca44a6609c29a683b03575fa035c6d17aa591e72) - -diff --git a/resolv/ns_print.c b/resolv/ns_print.c -index e58df5f35a..ab68bf2cb7 100644 ---- a/resolv/ns_print.c -+++ b/resolv/ns_print.c -@@ -464,96 +464,6 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - break; - } - -- case ns_t_cert: { -- u_int c_type, key_tag, alg; -- int n; -- unsigned int siz; -- char base64_cert[8192], tmp[40]; -- const char *leader; -- -- c_type = ns_get16(rdata); rdata += NS_INT16SZ; -- key_tag = ns_get16(rdata); rdata += NS_INT16SZ; -- alg = (u_int) *rdata++; -- -- len = SPRINTF((tmp, "%d %d %d ", c_type, key_tag, alg)); -- T(addstr(tmp, len, &buf, &buflen)); -- siz = (edata-rdata)*4/3 + 4; /* "+4" accounts for trailing \0 */ -- if (siz > sizeof(base64_cert) * 3/4) { -- const char *str = "record too long to print"; -- T(addstr(str, strlen(str), &buf, &buflen)); -- } -- else { -- len = b64_ntop(rdata, edata-rdata, base64_cert, siz); -- -- if (len < 0) -- goto formerr; -- else if (len > 15) { -- T(addstr(" (", 2, &buf, &buflen)); -- leader = "\n\t\t"; -- spaced = 0; -- } -- else -- leader = " "; -- -- for (n = 0; n < len; n += 48) { -- T(addstr(leader, strlen(leader), -- &buf, &buflen)); -- T(addstr(base64_cert + n, MIN(len - n, 48), -- &buf, &buflen)); -- } -- if (len > 15) -- T(addstr(" )", 2, &buf, &buflen)); -- } -- break; -- } -- -- case ns_t_tkey: { -- /* KJD - need to complete this */ -- u_long t; -- int mode, err, keysize; -- -- /* Algorithm name. */ -- T(addname(msg, msglen, &rdata, origin, &buf, &buflen)); -- T(addstr(" ", 1, &buf, &buflen)); -- -- /* Inception. */ -- t = ns_get32(rdata); rdata += NS_INT32SZ; -- len = SPRINTF((tmp, "%lu ", t)); -- T(addstr(tmp, len, &buf, &buflen)); -- -- /* Expiration. */ -- t = ns_get32(rdata); rdata += NS_INT32SZ; -- len = SPRINTF((tmp, "%lu ", t)); -- T(addstr(tmp, len, &buf, &buflen)); -- -- /* Mode , Error, Key Size. */ -- /* Priority, Weight, Port. */ -- mode = ns_get16(rdata); rdata += NS_INT16SZ; -- err = ns_get16(rdata); rdata += NS_INT16SZ; -- keysize = ns_get16(rdata); rdata += NS_INT16SZ; -- len = SPRINTF((tmp, "%u %u %u ", mode, err, keysize)); -- T(addstr(tmp, len, &buf, &buflen)); -- -- /* XXX need to dump key, print otherdata length & other data */ -- break; -- } -- -- case ns_t_tsig: { -- /* BEW - need to complete this */ -- int n; -- -- T(len = addname(msg, msglen, &rdata, origin, &buf, &buflen)); -- T(addstr(" ", 1, &buf, &buflen)); -- rdata += 8; /*%< time */ -- n = ns_get16(rdata); rdata += INT16SZ; -- rdata += n; /*%< sig */ -- n = ns_get16(rdata); rdata += INT16SZ; /*%< original id */ -- sprintf(buf, "%d", ns_get16(rdata)); -- rdata += INT16SZ; -- addlen(strlen(buf), &buf, &buflen); -- break; -- } -- - case ns_t_a6: { - struct in6_addr a; - int pbyte, pbit; -@@ -588,11 +498,6 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - break; - } - -- case ns_t_opt: { -- len = SPRINTF((tmp, "%u bytes", class)); -- T(addstr(tmp, len, &buf, &buflen)); -- break; -- } - default: - comment = ""; - goto hexify; - -commit cb4c62448047c043981deea84e5e01eccf8b36d4 -Author: Florian Weimer -Date: Fri Jun 19 18:22:20 2026 +0200 - - resolv: Fix buffer overreads in ns_sprintrrf (CVE-2026-6238) - - Check that the RDATA payload does not require more than RDATALEN - bytes while processing it. The fixes cover A6, LOC records. - (CERT, TKEY, TSIG were fixed before, by switching to the generic - formatter.) - - The vulnerable LOC record handling was first introduced before - glibc 2.0, in commit ee188d555b8c32ad9704a7440cab400af967292f. - - CERT, TSIG, TKEY handling came with commit - b43b13ac2544b11f35be301d1589b51a8473e32b, released with glibc 2.2. - - A6 record handling was introduced in commit - 91633816430e7ec5a19fe3ff510a7c4822a9557e ("* resolv/ns_print.c - (ns_sprintrrf): Handle ns_t_a6 and ns_t_opt."), which went into glibc - 2.7. - - This fixes bug 34069. - - Reviewed-by: Carlos O'Donell - Reviewed-by: Adhemerval Zanella - (cherry picked from commit a7b60d23bbb56eaef59f4962e4140062e552600a) - -diff --git a/resolv/ns_print.c b/resolv/ns_print.c -index ab68bf2cb7..f9dd086804 100644 ---- a/resolv/ns_print.c -+++ b/resolv/ns_print.c -@@ -345,7 +345,8 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - case ns_t_loc: { - char t[255]; - -- /* XXX protocol format checking? */ -+ if (rdlen != 16) -+ goto formerr; - (void) loc_ntoa(rdata, t); - T(addstr(t, strlen(t), &buf, &buflen)); - break; -@@ -479,13 +480,14 @@ ns_sprintrrf(const u_char *msg, size_t msglen, - - /* address suffix: provided only when prefix len != 128 */ - if (pbit < 128) { -- if (rdata + pbyte >= edata) goto formerr; -+ unsigned int bytelen = sizeof(a) - pbyte; -+ if (edata - rdata < bytelen) goto formerr; - memset(&a, 0, sizeof(a)); -- memcpy(&a.s6_addr[pbyte], rdata, sizeof(a) - pbyte); -+ memcpy(&a.s6_addr[pbyte], rdata, bytelen); - if (inet_ntop (AF_INET6, &a, buf, buflen) == NULL) - return -1; - addlen(strlen(buf), &buf, &buflen); -- rdata += sizeof(a) - pbyte; -+ rdata += bytelen; - } - - /* prefix name: provided only when prefix len > 0 */ - -commit 296fb7f4a2b35db13efef52609f8efc00291b2a8 -Author: Florian Weimer -Date: Fri Jun 19 18:22:20 2026 +0200 - - resolv: Add test case tst-ns_sprintrr (bug 34033, bug 34069) - - This test case covers both input buffer overreads and output buffer - overflows. It should systematically cover these issues. - - I used code auto-generation for updating the test expectations for - truncated RDATA in TXT, ISDN records, after writing the rest - of the test by hand. - - Assisted-by: LLM - Reviewed-by: Carlos O'Donell - Reviewed-by: Adhemerval Zanella - (cherry picked from commit 4ba0b79b9596e5a4951cc9eaa1546a55e543e083) - -diff --git a/resolv/Makefile b/resolv/Makefile -index 088a22ea18..c6d73b411c 100644 ---- a/resolv/Makefile -+++ b/resolv/Makefile -@@ -98,6 +98,7 @@ tests += \ - tst-ns_name \ - tst-ns_name_compress \ - tst-ns_name_pton \ -+ tst-ns_sprintrr \ - tst-res_hconf_reorder \ - tst-res_hnok \ - tst-resolv-aliases \ -@@ -331,5 +332,6 @@ $(objpfx)tst-ns_name: $(objpfx)libresolv.so - $(objpfx)tst-ns_name.out: tst-ns_name.data - $(objpfx)tst-ns_name_compress: $(objpfx)libresolv.so - $(objpfx)tst-ns_name_pton: $(objpfx)libresolv.so -+$(objpfx)tst-ns_sprintrr: $(objpfx)libresolv.so - $(objpfx)tst-res_hnok: $(objpfx)libresolv.so - $(objpfx)tst-p_secstodate: $(objpfx)libresolv.so -diff --git a/resolv/tst-ns_sprintrr.c b/resolv/tst-ns_sprintrr.c -new file mode 100644 -index 0000000000..34739b5924 ---- /dev/null -+++ b/resolv/tst-ns_sprintrr.c -@@ -0,0 +1,329 @@ -+/* Tests for the ns_sprintrr function. -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+ -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+ -+#include -+ -+/* Regions that test_one_record uses for input and output. */ -+static struct support_next_to_fault ntf_in; -+static struct support_next_to_fault ntf_out; -+ -+/* This is used by test_one_record to construct the packet. */ -+static const char packet_prefix[] = -+ /* DNS response with one question, one answer record. */ -+ "AA\x81\x80\0\1\0\1\0\0\0\0" -+ /* Question: www.example.org/IN/ANY. */ -+ "\3www\7example\3org\0\0\xff\0\1" -+ /* Response: compression reference. */ -+ "\xc0\x0c"; -+ -+/* Use ns_sprintrr to format a DNS record (starting with -+ packet_prefix) of type RTYPE, with a record payload of RDATALEN -+ bytes starting at RDATA. Check successful formatting against -+ EXPECTED. Try various truncated input and output buffers to catch -+ overreads and buffer overflows, using ntf_in and ntf_out above. */ -+static void -+test_one_record (uint16_t rtype, const char *rdata, size_t rdatalen, -+ const char *expected) -+{ -+ struct rr_header -+ { -+ uint16_t typ; -+ uint16_t cls; -+ uint32_t ttl; -+ uint16_t rdatalen; -+ uint16_t pad; -+ } hdr = -+ { -+ .typ = htons (rtype), -+ .cls = htons (ns_c_in), -+ .ttl = htonl (86400), /* One day. */ -+ .rdatalen = htons (rdatalen), -+ }; -+ enum { hdrlen = offsetof (struct rr_header, pad) }; -+ TEST_COMPARE (hdrlen, 10); -+ -+ /* Construct the packet from packet_prefix, hdr, and rdata. */ -+ unsigned char packet[512]; -+ size_t packetlen; -+ { -+ struct alloc_buffer buf = alloc_buffer_create (packet, sizeof (packet)); -+ alloc_buffer_copy_bytes (&buf, packet_prefix, sizeof (packet_prefix) - 1); -+ alloc_buffer_copy_bytes (&buf, &hdr, hdrlen); -+ alloc_buffer_copy_bytes (&buf, rdata, rdatalen); -+ packetlen = sizeof (packet) - alloc_buffer_size (&buf); -+ } -+ -+ /* Parse the record. */ -+ ns_msg msg; -+ TEST_COMPARE (ns_initparse (packet, packetlen, &msg), 0); -+ ns_rr rr; -+ TEST_COMPARE (ns_parserr (&msg, ns_s_an, 0, &rr), 0); -+ -+ /* Try sizes up to this limit. Go a bit beyond the expected size to -+ check for errors. */ -+ size_t max_result_size = strlen (expected) + 16; -+ -+ bool success = false; -+ for (size_t result_size = 1; result_size <= max_result_size; ++result_size) -+ { -+ char *result_start = ntf_out.buffer + ntf_out.length - result_size; -+ memset (result_start, 'X', result_size); -+ -+ /* ns_sprintrr was deprecated in 2.34. */ -+ DIAG_PUSH_NEEDS_COMMENT; -+ DIAG_IGNORE_NEEDS_COMMENT (4.9, "-Wdeprecated-declarations"); -+ int ret = ns_sprintrr (&msg, &rr, NULL, NULL, result_start, result_size); -+ DIAG_POP_NEEDS_COMMENT; -+ -+ if (ret > 0) -+ { -+ TEST_COMPARE_STRING (result_start, expected); -+ TEST_COMPARE (ret, strlen (expected)); -+ success = true; -+ } -+ else -+ { -+ TEST_VERIFY (!success); -+ TEST_COMPARE (ret, -1); -+ } -+ } -+ TEST_VERIFY (success); -+ -+ /* Test with truncated RDATA. */ -+ for (size_t rdata_size = 0; rdata_size <= rdatalen; ++rdata_size) -+ { -+ size_t truncated_packet_size = packetlen - rdatalen + rdata_size; -+ unsigned char *packet_start -+ = ((unsigned char *) ntf_in.buffer + ntf_in.length -+ - truncated_packet_size); -+ memcpy (packet_start, packet, truncated_packet_size); -+ /* Patch in the updated RDATA length field. */ -+ uint16_t new_rdatalen = htons (rdata_size); -+ memcpy (packet_start + truncated_packet_size - rdata_size - 2, -+ &new_rdatalen, 2); -+ -+ ns_msg msg; -+ TEST_COMPARE (ns_initparse (packet_start, truncated_packet_size, &msg), -+ 0); -+ ns_rr rr; -+ TEST_COMPARE (ns_parserr (&msg, ns_s_an, 0, &rr), 0); -+ -+ size_t result_size = strlen (expected) + 1; -+ char *result_start = ntf_out.buffer + ntf_out.length - result_size; -+ memset (result_start, 'X', result_size); -+ -+ /* ns_sprintrr was deprecated in 2.34. */ -+ DIAG_PUSH_NEEDS_COMMENT; -+ DIAG_IGNORE_NEEDS_COMMENT (4.9, "-Wdeprecated-declarations"); -+ int ret = ns_sprintrr (&msg, &rr, NULL, NULL, result_start, result_size); -+ DIAG_POP_NEEDS_COMMENT; -+ -+ /* This flag indicates whether the output is syntactically -+ correct. In some cases, truncation may still yield a valid -+ payload. */ -+ bool broken = rdata_size < rdatalen; -+ switch (rtype) -+ { -+ case ns_t_wks: -+ /* WKS records use all trailing bytes for the port bitmap. */ -+ broken = rdata_size < 5; -+ break; -+ case ns_t_nsap: -+ /* Uses all bytes that are available. */ -+ broken = false; -+ break; -+ case ns_t_txt: -+ /* Truncation produces a valid payload if it occurs right -+ after a complete string in the TXT payload. */ -+ broken = false; -+ for (size_t pos = 0; pos < rdata_size; ) -+ { -+ unsigned int slen = rdata[pos] & 0xff; -+ if (pos + 1 + slen > rdata_size) -+ { -+ broken = true; -+ break; -+ } -+ pos += 1 + slen; -+ } -+ break; -+ case ns_t_isdn: -+ /* The second field is optional. If it is present, it must -+ not be truncated. */ -+ broken = rdata_size < 6 || (rdata_size > 6 && rdata_size < rdatalen); -+ break; -+ case ns_t_a6: -+ /* The first A6 subtest contains a trailing domain name, -+ which is ignored and not formatted. */ -+ if (rdata_size > 0 && rdata[0] == 0) -+ broken = rdata_size < 17; -+ break; -+ case ns_t_cert: -+ case ns_t_tkey: -+ case ns_t_tsig: -+ /* Only generic printing, which does not validate anything. */ -+ broken = false; -+ break; -+ } -+ -+ if (broken) -+ { -+ if (strstr (result_start, "RR format error") != NULL) -+ /* No further checks if an error indicator has been added -+ to the output. */ -+ ; -+ else -+ TEST_COMPARE (ret, -1); -+ } -+ else -+ TEST_VERIFY (ret > 0); -+ } -+} -+ -+static int -+do_test (void) -+{ -+ ntf_in = support_next_to_fault_allocate (512); -+ ntf_out = support_next_to_fault_allocate (256); -+ -+#define T(rtype, rdata, expected) \ -+ test_one_record (rtype, rdata, sizeof (rdata) - 1, expected) -+ T (ns_t_a, "\xc0\0\2\1", "www.example.org.\t1D IN A\t\t192.0.2.1"); -+ T (ns_t_cname, "\4www1\4prod\xc0\x10", -+ "www.example.org.\t1D IN CNAME\twww1.prod.example.org."); -+ T (ns_t_hinfo, "\5first\6second", -+ "www.example.org.\t1D IN HINFO\t\"first\" \"second\""); -+ T (ns_t_isdn, "\5first\6second", -+ "www.example.org.\t1D IN ISDN\t\"first\" \"second\""); -+ /* Bug: Extra space at the end in the text representation of ISDN RRs. */ -+ T (ns_t_isdn, "\5first", "www.example.org.\t1D IN ISDN\t\"first\" "); -+ T (ns_t_soa, -+ "\2ns\xc0\x10\12hostmaster\xc0\x10" -+ "\0\0\0\1\0\0\0\2\0\0\0\3\0\0\0\4\0\0\0\5", -+ "www.example.org.\t1D IN SOA\tns.example.org. hostmaster.example.org. (\n" -+ "\t\t\t\t\t1\t\t; serial\n" -+ "\t\t\t\t\t2S\t\t; refresh\n" -+ "\t\t\t\t\t3S\t\t; retry\n" -+ "\t\t\t\t\t4S\t\t; expiry\n" -+ "\t\t\t\t\t5S )\t\t; minimum\n"); -+ T (ns_t_mx, "\0\xa\2mx\xc0\x10", -+ "www.example.org.\t1D IN MX\t10 mx.example.org."); -+ T (ns_t_px, "\0\xa\3px1\xc0\x10\3px2\xc0\x10", -+ "www.example.org.\t1D IN PX\t10 px1.example.org. px2.example.org."); -+ T (ns_t_x25, "\4X.25", -+ "www.example.org.\t1D IN X25\t\"X.25\""); -+ T (ns_t_txt, "\1A\2BC\3DEF", -+ "www.example.org.\t1D IN TXT\t\"A\" \"BC\" \"DEF\""); -+ T (ns_t_nsap, "", -+ "www.example.org.\t1D IN NSAP\t"); -+ T (ns_t_nsap, "\1", -+ "www.example.org.\t1D IN NSAP\t01"); -+ T (ns_t_nsap, "\1\2", -+ "www.example.org.\t1D IN NSAP\t01.02"); -+ T (ns_t_nsap, "\1\2\3", -+ "www.example.org.\t1D IN NSAP\t01.0203"); -+ T (ns_t_nsap, "\1\2\3\4", -+ "www.example.org.\t1D IN NSAP\t01.0203.04"); -+ T (ns_t_nsap, -+ "\1\2\3\4\5\6\7\10\11\12\13\14\15\16\17\20\21\22\23\24\25\26\27\30\31\32" -+ "\33\34\35\36\37\40\41\42\43\44\45\46\47\50\51\52\53\54\55\56\57\60\61" -+ "\62\63\64\65\66\67\70\71\72\73\74\75\76\77\100\101\102\103\104\105\106" -+ "\107\110\111\112\113\114\115\116\117\120\121\122\123\124\125\126\127" -+ "\130\131\132\133\134\135\136\137\140\141\142\143\144\145\146\147\150" -+ "\151\152\153\154\155\156\157\160\161\162\163\164\165\166\167\170\171" -+ "\172\173\174\175\176\177\200\201\202\203\204\205\206\207\210\211\212" -+ "\213\214\215\216\217\220\221\222\223\224\225\226\227\230\231\232\233" -+ "\234\235\236\237\240\241\242\243\244\245\246\247\250\251\252\253\254" -+ "\255\256\257\260\261\262\263\264\265\266\267\270\271\272\273\274\275" -+ "\276\277\300\301\302\303\304\305\306\307\310\311\312\313\314\315\316" -+ "\317\320\321\322\323\324\325\326\327\330\331\332\333\334\335\336\337" -+ "\340\341\342\343\344\345\346\347\350\351\352\353\354\355\356\357\360" -+ "\361\362\363\364\365\366\367\370\371\372\373\374\375\376\377", -+ "www.example.org.\t1D IN NSAP\t" -+ "01.0203.0405.0607.0809.0A0B.0C0D.0E0F.1011.1213.1415.1617.1819.1A1B" -+ ".1C1D.1E1F.2021.2223.2425.2627.2829.2A2B.2C2D.2E2F.3031.3233.3435.3637" -+ ".3839.3A3B.3C3D.3E3F.4041.4243.4445.4647.4849.4A4B.4C4D.4E4F.5051.5253" -+ ".5455.5657.5859.5A5B.5C5D.5E5F.6061.6263.6465.6667.6869.6A6B.6C6D.6E6F" -+ ".7071.7273.7475.7677.7879.7A7B.7C7D.7E7F.8081.8283.8485.8687.8889.8A8B" -+ ".8C8D.8E8F.9091.9293.9495.9697.9899.9A9B.9C9D.9E9F.A0A1.A2A3.A4A5.A6A7" -+ ".A8A9.AAAB.ACAD.AEAF.B0B1.B2B3.B4B5.B6B7.B8B9.BABB.BCBD.BEBF.C0C1.C2C3" -+ ".C4C5.C6C7.C8C9.CACB.CCCD.CECF.D0D1.D2D3.D4D5.D6D7.D8D9.DADB.DCDD.DEDF" -+ ".E0E1.E2E3.E4E5.E6E7.E8E9.EAEB.ECED.EEEF.F0F1.F2F3.F4F5.F6F7.F8F9.FAFB" -+ ".FCFD.FEFF"); -+ T (ns_t_aaaa, "\x20\x01\x0d\xb8\0\0\0\0\0\0\0\0\0\0\x12\x34", -+ "www.example.org.\t1D IN AAAA\t2001:db8::1234"); -+ /* Example from RFC 1876. The loc_ntoa format is different from the -+ official text representation. */ -+ T (ns_t_loc, -+ "\000\063\026\023\211\027\055\320\160\276\025\360\000\230\215\040", -+ "www.example.org.\t1D IN LOC" -+ "\t42 21 54.000 N 71 06 18.000 W -24.00m 30.00m 10000.00m 10.00m"); -+ T (ns_t_naptr, -+ "\0\1\0\2\5flags\7service\2.*\5naptr\xc0\x10", -+ "www.example.org.\t1D IN NAPTR\t1 2 \"flags\" \"service\" \".*\"" -+ " naptr.example.org."); -+ T (ns_t_srv, -+ "\0\1\0\2\0\x50\4www1\xc0\x10", -+ "www.example.org.\t1D IN SRV\t1 2 80 www1.example.org."); -+ T (ns_t_rp, "\3rp1\xc0\x10\3rp2\xc0\x10", -+ "www.example.org.\t1D IN RP\trp1.example.org. rp2.example.org."); -+ T (ns_t_wks, "\xc0\0\2\1\6\0\0\0\0\0\0\0\0\0\0\200", -+ "www.example.org.\t1D IN WKS\t192.0.2.1 6 ( \n\t\t\t\t80 )"); -+ T (ns_t_cert, "\0\1\x04\xd2\0blob", -+ "www.example.org.\t1D IN CERT\t\\# 9 (\n" -+ "\t00 01 04 d2 00 62 6c 6f 62 )\t\t\t; .....blob"); -+ T (ns_t_tkey, "\4algo\0\0\0\0\1\0\0\0\2\0\3\0\4" -+ "\0\5\xa1\xa2\xa3\xa4\xa5\0\3\xb1\xb2\xb3", -+ "www.example.org.\t1D IN TYPE249\t\\# 30 (\n" -+ "\t04 61 6c 67 6f 00 00 00 00 01 00 00 00 02 00 03 ; .algo...........\n" -+ "\t00 04 00 05 a1 a2 a3 a4 a5 00 03 b1 b2 b3 )\t; .............."); -+ T (ns_t_tsig, "\4algo\0" -+ "\0\20\xdd\xcd\x64\x10\xe9\x21\x34\x1a\x8e\xe0\xa1\x9a\x30\xfc\x3b\xd1" -+ "\0\2\0\3\0\5other", -+ "www.example.org.\t1D IN TSIG\t\\# 35 (\n" -+ "\t04 61 6c 67 6f 00 00 10 dd cd 64 10 e9 21 34 1a ; .algo.....d..!4.\n" -+ "\t8e e0 a1 9a 30 fc 3b d1 00 02 00 03 00 05 6f 74 ; ....0.;.......ot\n" -+ "\t68 65 72 )\t\t\t\t\t; her"); -+ T (ns_t_a6, -+ "\0\x20\x01\x0d\xb8\0\0\0\0\0\0\0\0\0\0\x12\x34\6prefix\xc0\x10", -+ "www.example.org.\t1D IN A6\t0 2001:db8::1234"); -+ T (ns_t_a6, -+ "\0\x20\x01\x0d\xb8\0\0\0\0\0\0\0\0\0\0\x12\x35", -+ "www.example.org.\t1D IN A6\t0 2001:db8::1235"); -+ T (ns_t_a6, "\200\6prefix\xc0\x10", -+ "www.example.org.\t1D IN A6\t128 prefix.example.org."); -+ T (ns_t_a6, "\x20\0\0\0\0\0\0\0\0\0\0\x12\x36\6prefix\xc0\x10", -+ "www.example.org.\t1D IN A6\t32 ::1236 prefix.example.org."); -+#undef T -+ -+ support_next_to_fault_free (&ntf_in); -+ support_next_to_fault_free (&ntf_out); -+ return 0; -+} -+ -+#include - -commit 7414631f8aec8b9cee1a8311506e1fdcd9b94c0d -Author: Adhemerval Zanella -Date: Tue Apr 14 10:50:37 2026 -0300 - - posix: Fix stack overflow in wordexp tilde expansion (BZ 34091, CVE-2026-6791) - - The parse_tilde function previously used strndupa to allocate memory - for the parsed username on the stack, and since the input is - user-defined, this can lead to a stack overflow. - - This patch fixes the issue by replacing strndupa with scratch_buffer, - by reusing the buffer used in the __getpwnam_r call. - - The new “tst-wordexp-tilde.c” test is a test-container to avoid using - system-defined NSS modules. - - Checked on x86_64-linux-gnu and i686-linux-gnu. - - (cherry picked from commit 07c24f35392b727e6100d33edfdf811a6c68c218) - -diff --git a/posix/Makefile b/posix/Makefile -index 0b29c9aa4e..595c6b3ec2 100644 ---- a/posix/Makefile -+++ b/posix/Makefile -@@ -356,6 +356,7 @@ tests-internal := \ - tests-container := \ - bug-ga2 \ - tst-vfork3 \ -+ tst-wordexp-tilde \ - # tests-container - - tests-time64 := \ -diff --git a/posix/tst-wordexp-tilde.c b/posix/tst-wordexp-tilde.c -new file mode 100644 -index 0000000000..1661603681 ---- /dev/null -+++ b/posix/tst-wordexp-tilde.c -@@ -0,0 +1,244 @@ -+/* Test wordexp tilde expansion with large usernames (BZ 34091). -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+#include -+ -+#include -+#include -+#include -+#include -+ -+typedef void (*func_callback_t)(void); -+ -+static void -+subprocess_small_stack (void *closure) -+{ -+ struct rlimit rl; -+ TEST_COMPARE (getrlimit (RLIMIT_STACK, &rl), 0); -+ rl.rlim_cur = 512 * 1024; -+ TEST_COMPARE (setrlimit (RLIMIT_STACK, &rl), 0); -+ -+ func_callback_t func_test = closure; -+ func_test (); -+} -+ -+/* Build a string "~/tail" where is LEN bytes of the -+ character CH. The caller must free the result. */ -+static char * -+make_tilde_input (char ch, size_t len, const char *tail) -+{ -+ /* ~ + len + / + tail + \0 */ -+ size_t taillen = tail != NULL ? strlen (tail) : 0; -+ size_t total = 1 + len + 1 + taillen + 1; -+ char *buf = xmalloc (total); -+ buf[0] = '~'; -+ memset (buf + 1, ch, len); -+ buf[1 + len] = '/'; -+ if (tail != NULL) -+ memcpy (buf + 1 + len + 1, tail, taillen); -+ buf[total - 1] = '\0'; -+ return buf; -+} -+ -+/* Test 1: A very long username must not crash. The username will not match -+ any real user, so wordexp returns ~/rest. */ -+static void -+test_long_username (void) -+{ -+ printf ("info: test_long_username_no_crash\n"); -+ -+ static const char REST[] = "rest"; -+ -+ /* 1 MiB username — well beyond any reasonable stack frame. */ -+ const size_t long_len = 1024 * 1024; -+ char *input = make_tilde_input ('A', long_len, REST); -+ -+ wordexp_t we = { 0 }; -+ int ret = wordexp (input, &we, 0); -+ /* The (non-existent) username is invalid, so wordexp falls back to -+ literal output: ~AAA…/rest. */ -+ TEST_COMPARE (ret, 0); -+ TEST_COMPARE (we.we_wordc, 1); -+ -+ /* Verify prefix: '~' followed by long_len 'A's. */ -+ const char *result = we.we_wordv[0]; -+ TEST_COMPARE (result[0], '~'); -+ TEST_COMPARE (strlen (result), -+ 1 /* ~ */ + long_len + sizeof (REST)); -+ for (size_t j = 1; j <= long_len; j++) -+ if (result[j] != 'A') -+ { -+ printf (" mismatch at position %zu: expected 'A', got '%c'\n", -+ j, result[j]); -+ support_record_failure (); -+ break; -+ } -+ /* Verify the tail after the username. */ -+ TEST_COMPARE_STRING (result + 1 + long_len, "/rest"); -+ -+ wordfree (&we); -+ free (input); -+} -+ -+/* Test 2: A username that just exceeds the default scratch_buffer inline -+ size (1024 bytes) exercises the scratch_buffer_set_array_size growth path -+ without being excessively large. */ -+static void -+test_scratch_buffer_growth (void) -+{ -+ printf ("info: test_scratch_buffer_growth\n"); -+ -+ const size_t len = 2048; -+ char *input = make_tilde_input ('x', len, NULL); -+ -+ wordexp_t we = { 0 }; -+ int ret = wordexp (input, &we, 0); -+ TEST_COMPARE (ret, 0); -+ TEST_COMPARE (we.we_wordc, 1); -+ -+ /* ~xxx…/ — the trailing slash makes a separate empty component, but -+ wordexp merges it into the single token ~xxx…/. */ -+ const char *result = we.we_wordv[0]; -+ TEST_COMPARE (result[0], '~'); -+ for (size_t j = 1; j <= len; j++) -+ if (result[j] != 'x') -+ { -+ printf (" mismatch at position %zu\n", j); -+ support_record_failure (); -+ break; -+ } -+ TEST_COMPARE (result[1 + len], '/'); -+ -+ wordfree (&we); -+ free (input); -+} -+ -+/* Test 3: ~root still resolves to the correct home directory through the -+ __getpwnam_r path. */ -+static void -+test_known_user (void) -+{ -+ printf ("info: test_known_user\n"); -+ -+ /* Look up root's home directory for comparison. */ -+ struct passwd *pw = getpwnam ("root"); -+ if (pw == NULL || pw->pw_dir == NULL) -+ { -+ printf (" SKIP: cannot look up root\n"); -+ return; -+ } -+ -+ char *expected = xasprintf ("%s/file", pw->pw_dir); -+ -+ wordexp_t we = { 0 }; -+ TEST_COMPARE (wordexp ("~root/file", &we, 0), 0); -+ TEST_COMPARE (we.we_wordc, 1); -+ TEST_COMPARE_STRING (we.we_wordv[0], expected); -+ -+ wordfree (&we); -+ free (expected); -+} -+ -+/* Test 4: Bare tilde expands to $HOME. */ -+static void -+test_bare_tilde (void) -+{ -+ printf ("info: test_bare_tilde\n"); -+ -+ const char *home = getenv ("HOME"); -+ if (home == NULL) -+ { -+ printf (" SKIP: HOME is not set\n"); -+ return; -+ } -+ -+ wordexp_t we = { 0 }; -+ TEST_COMPARE (wordexp ("~", &we, 0), 0); -+ TEST_COMPARE (we.we_wordc, 1); -+ TEST_COMPARE_STRING (we.we_wordv[0], home); -+ -+ wordfree (&we); -+} -+ -+/* Test 5: Short non-existent username falls back to literal ~username output, -+ exercising the invalid-login-name path. */ -+static void -+test_unknown_user (void) -+{ -+ printf ("info: test_unknown_user\n"); -+ -+ /* Pick a username that is extremely unlikely to exist. */ -+ wordexp_t we = { 0 }; -+ TEST_COMPARE (wordexp ("~no_such_user_xyzzy42", &we, 0), 0); -+ TEST_COMPARE (we.we_wordc, 1); -+ TEST_COMPARE_STRING (we.we_wordv[0], "~no_such_user_xyzzy42"); -+ -+ wordfree (&we); -+} -+ -+/* Test 6: Tilde with username and WRDE_APPEND — exercises parse_tilde's -+ interaction with the WRDE_APPEND word list. */ -+static void -+test_tilde_with_append (void) -+{ -+ printf ("info: test_tilde_with_append\n"); -+ -+ const char *home = getenv ("HOME"); -+ if (home == NULL) -+ { -+ printf (" SKIP: HOME is not set\n"); -+ return; -+ } -+ -+ wordexp_t we = { 0 }; -+ TEST_COMPARE (wordexp ("first", &we, 0), 0); -+ -+ TEST_COMPARE (wordexp ("~/path", &we, WRDE_APPEND), 0); -+ TEST_COMPARE (we.we_wordc, 2); -+ TEST_COMPARE_STRING (we.we_wordv[0], "first"); -+ -+ char *expected = xasprintf ("%s/path", home); -+ TEST_COMPARE_STRING (we.we_wordv[1], expected); -+ -+ wordfree (&we); -+ free (expected); -+} -+ -+static int -+do_test (void) -+{ -+ test_known_user (); -+ test_bare_tilde (); -+ test_unknown_user (); -+ test_tilde_with_append (); -+ -+ support_isolate_in_subprocess (subprocess_small_stack, -+ test_long_username); -+ -+ support_isolate_in_subprocess (subprocess_small_stack, -+ test_scratch_buffer_growth); -+ -+ return 0; -+} -+ -+#include -diff --git a/posix/tst-wordexp-tilde.root/etc/group b/posix/tst-wordexp-tilde.root/etc/group -new file mode 100644 -index 0000000000..1dbf9013ee ---- /dev/null -+++ b/posix/tst-wordexp-tilde.root/etc/group -@@ -0,0 +1 @@ -+root:x:0: -diff --git a/posix/tst-wordexp-tilde.root/etc/nsswitch.conf b/posix/tst-wordexp-tilde.root/etc/nsswitch.conf -new file mode 100644 -index 0000000000..098a8d5938 ---- /dev/null -+++ b/posix/tst-wordexp-tilde.root/etc/nsswitch.conf -@@ -0,0 +1,3 @@ -+passwd: files -+group: files -+shadow: files -diff --git a/posix/tst-wordexp-tilde.root/etc/passwd b/posix/tst-wordexp-tilde.root/etc/passwd -new file mode 100644 -index 0000000000..eb85a552ad ---- /dev/null -+++ b/posix/tst-wordexp-tilde.root/etc/passwd -@@ -0,0 +1 @@ -+root:x:0:0:root:/root:/bin/sh -diff --git a/posix/wordexp.c b/posix/wordexp.c -index 9df4bb7424..731d1650e9 100644 ---- a/posix/wordexp.c -+++ b/posix/wordexp.c -@@ -335,17 +335,29 @@ parse_tilde (char **word, size_t *word_length, size_t *max_length, - else - { - /* Look up user name in database to get home directory */ -- char *user = strndupa (&words[1 + *offset], i - (1 + *offset)); -- struct passwd pwd, *tpwd; -- int result; -+ size_t userlen = i - (1 + *offset); -+ /* tmpbuf contains both the user and the __getpwnam_r working area. */ - struct scratch_buffer tmpbuf; - scratch_buffer_init (&tmpbuf); -+ if (!scratch_buffer_set_array_size (&tmpbuf, userlen + 1, 1)) -+ return WRDE_NOSPACE; -+ char *user = tmpbuf.data; -+ memcpy (user, &words[1 + *offset], userlen); -+ user[userlen] = '\0'; - -- while ((result = __getpwnam_r (user, &pwd, tmpbuf.data, tmpbuf.length, -+ struct passwd pwd, *tpwd; -+ int result; -+ while ((result = __getpwnam_r (user, -+ &pwd, -+ tmpbuf.data + userlen + 1, -+ tmpbuf.length - userlen - 1, - &tpwd)) != 0 - && errno == ERANGE) -- if (!scratch_buffer_grow (&tmpbuf)) -- return WRDE_NOSPACE; -+ { -+ if (!scratch_buffer_grow_preserve (&tmpbuf)) -+ return WRDE_NOSPACE; -+ user = tmpbuf.data; -+ } - - if (result == 0 && tpwd != NULL && pwd.pw_dir) - *word = w_addstr (*word, word_length, max_length, pwd.pw_dir); - -commit 8be3551ccb4e17e93ad82152de56d2c90de21f97 -Author: Adhemerval Zanella -Date: Mon Apr 13 16:33:30 2026 -0300 - - posix: Fix wordexp WRDE_APPEND to preserve state on non-NOSPACE errors (BZ 34090, CVE-2026-6368) - - The previous implementation saved a copy of the wordexp_t struct at - entry and blindly restored it on error via (*pwordexp = old_word). - This is incorrect when WRDE_APPEND is set because w_addword may have - called realloc on we_wordv during partial processing before the error - was detected. If realloc relocated the buffer, the saved we_wordv - pointer is dangling; restoring it causes a use-after-free in the - caller (e.g. via wordfree), and the relocated buffer is leaked. - - Fix this by duplicating the we_wordv pointer array at entry when - WRDE_APPEND is set, so that all subsequent realloc calls inside - w_addword operate on the copy. - - This change also fixes a POSIX conformance issue: if the WRDE_APPEND - flag is specified, pwordexp->we_wordc and pwordexp->we_wordv shall - not be modified. - - Also fix two pre-existing error return paths in the '"' and '\'' cases - that returned directly from w_addword failures instead of going through - do_error, which would leak the saved array (and previously would also - skip the word cleanup). - - Checked on x86_64-linux-gnu and i686-linux-gnu. - - Reviewed-by: DJ Delorie - (cherry picked from commit e2cefe16c37a617df9f11407cb00a272a6098823) - -diff --git a/posix/Makefile b/posix/Makefile -index 595c6b3ec2..a12c49c0ed 100644 ---- a/posix/Makefile -+++ b/posix/Makefile -@@ -326,6 +326,7 @@ tests := \ - tst-wait3 \ - tst-wait4 \ - tst-waitid \ -+ tst-wordexp-append \ - tst-wordexp-nocmd \ - tst-wordexp-reuse \ - tstgetopt \ -diff --git a/posix/tst-wordexp-append.c b/posix/tst-wordexp-append.c -new file mode 100644 -index 0000000000..87f388f0a7 ---- /dev/null -+++ b/posix/tst-wordexp-append.c -@@ -0,0 +1,393 @@ -+/* Test for wordexp with WRDE_APPEND flag. -+ Copyright (C) 2026 Free Software Foundation, Inc. -+ This file is part of the GNU C Library. -+ -+ The GNU C Library is free software; you can redistribute it and/or -+ modify it under the terms of the GNU Lesser General Public -+ License as published by the Free Software Foundation; either -+ version 2.1 of the License, or (at your option) any later version. -+ -+ The GNU C Library is distributed in the hope that it will be useful, -+ but WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ Lesser General Public License for more details. -+ -+ You should have received a copy of the GNU Lesser General Public -+ License along with the GNU C Library; if not, see -+ . */ -+ -+#include -+#include -+#include -+#include -+#include -+ -+#include -+#include -+ -+static unsigned int relocating_reallocs; -+ -+/* w_addword grows we_wordv with realloc, make every call guaranteed to -+ relocate the block. This makes BZ 34090 regression more deterministic. */ -+void * -+realloc (void *ptr, size_t size) -+{ -+ if (ptr == NULL) -+ return malloc (size); -+ if (size == 0) -+ { -+ free (ptr); -+ return NULL; -+ } -+ -+ void *new = malloc (size); -+ if (new == NULL) -+ return NULL; -+ -+ /* Copy only what is valid in the old block to avoid reading past it. */ -+ size_t old = malloc_usable_size (ptr); -+ memcpy (new, ptr, old < size ? old : size); -+ /* Clobber the old block so that a stale we_wordv pointer restored on the -+ error path reads garbage instead of the old contents, which might -+ otherwise survive intact and mask the bug. */ -+ memset (ptr, 0x5a, old); -+ free (ptr); -+ relocating_reallocs++; -+ return new; -+} -+ -+/* Verify that all words in we match the expected NULL-terminated -+ array. */ -+static void -+check_words (const wordexp_t *we, const char *const *expected) -+{ -+ size_t i; -+ for (i = 0; expected[i] != NULL; i++) -+ { -+ TEST_VERIFY (i < we->we_wordc); -+ TEST_COMPARE_STRING (we->we_wordv[we->we_offs + i], expected[i]); -+ } -+ TEST_COMPARE (we->we_wordc, i); -+} -+ -+#define CHECK_WORDS(we, ...) \ -+ do { \ -+ const char *const expected_[] = { __VA_ARGS__, NULL }; \ -+ check_words (we, expected_); \ -+ } while (0) -+ -+/* Test 1: WRDE_APPEND + WRDE_BADCHAR preserves we_wordc. */ -+static void -+test_append_badchar_preserves_count (void) -+{ -+ printf ("info: test_append_badchar_preserves_count\n"); -+ wordexp_t we = { 0 }; -+ -+ TEST_COMPARE (wordexp ("one two three", &we, 0), 0); -+ TEST_COMPARE (we.we_wordc, 3); -+ -+ size_t saved_count = we.we_wordc; -+ -+ /* ')' triggers WRDE_BADCHAR and "extra" would be a new word if the -+ expansion succeeded, exercising the w_addword path before the error -+ is detected. */ -+ TEST_COMPARE (wordexp ("extra )", &we, WRDE_APPEND), WRDE_BADCHAR); -+ TEST_COMPARE (we.we_wordc, saved_count); -+ -+ wordfree (&we); -+} -+ -+/* Test 2: WRDE_APPEND + WRDE_BADCHAR preserves the we_wordv pointer even -+ when internal realloc would move the buffer. */ -+static void -+test_append_badchar_preserves_pointer (void) -+{ -+ printf ("info: test_append_badchar_preserves_pointer\n"); -+ wordexp_t we = { 0 }; -+ -+ /* Use many words so that the initial we_wordv allocation is -+ non-trivial and a later realloc is more likely to move it. */ -+ TEST_COMPARE (wordexp ("a b c d e f g h", &we, 0), 0); -+ TEST_COMPARE (we.we_wordc, 8); -+ -+ char **saved_wordv = we.we_wordv; -+ size_t saved_count = we.we_wordc; -+ unsigned int saved_reallocs = relocating_reallocs; -+ -+ /* The interposed realloc guarantees the internal we_wordv buffer moves -+ during parsing, so the pointer-stability check below is meaningful. */ -+ TEST_COMPARE (wordexp ("append )", &we, WRDE_APPEND), WRDE_BADCHAR); -+ /* Verify that a relocating realloc actually happened during the failed -+ call, otherwise the pointer-stability check is vacuous. */ -+ TEST_VERIFY (relocating_reallocs > saved_reallocs); -+ TEST_COMPARE (we.we_wordc, saved_count); -+ TEST_VERIFY (we.we_wordv == saved_wordv); -+ -+ wordfree (&we); -+} -+ -+/* Test 3: After a failed WRDE_APPEND the original words are still accessible -+ and correct. */ -+static void -+test_append_badchar_words_intact (void) -+{ -+ printf ("info: test_append_badchar_words_intact\n"); -+ wordexp_t we = { 0 }; -+ -+ TEST_COMPARE (wordexp ("alpha beta gamma", &we, 0), 0); -+ CHECK_WORDS (&we, "alpha", "beta", "gamma"); -+ -+ TEST_COMPARE (wordexp ("delta )", &we, WRDE_APPEND), WRDE_BADCHAR); -+ -+ /* Words must still be intact. */ -+ CHECK_WORDS (&we, "alpha", "beta", "gamma"); -+ /* The NULL terminator must still be present. */ -+ TEST_VERIFY (we.we_wordv[we.we_offs + we.we_wordc] == NULL); -+ -+ wordfree (&we); -+} -+ -+/* Test 4: Successful WRDE_APPEND still works (regression test). */ -+static void -+test_append_success (void) -+{ -+ printf ("info: test_append_success\n"); -+ wordexp_t we = { 0 }; -+ -+ TEST_COMPARE (wordexp ("hello", &we, 0), 0); -+ TEST_COMPARE (we.we_wordc, 1); -+ -+ char **saved_wordv = we.we_wordv; -+ -+ TEST_COMPARE (wordexp ("world", &we, WRDE_APPEND), 0); -+ TEST_COMPARE (we.we_wordc, 2); -+ /* A successful append works on a fresh copy of the array, so the -+ caller-visible pointer must have changed. */ -+ TEST_VERIFY (we.we_wordv != saved_wordv); -+ CHECK_WORDS (&we, "hello", "world"); -+ -+ wordfree (&we); -+} -+ -+/* Test 5: Successful append after a failed append — the implementation must -+ recover and allow further use of the wordexp_t. */ -+static void -+test_append_success_after_failure (void) -+{ -+ printf ("info: test_append_success_after_failure\n"); -+ wordexp_t we = { 0 }; -+ -+ TEST_COMPARE (wordexp ("first", &we, 0), 0); -+ CHECK_WORDS (&we, "first"); -+ -+ TEST_COMPARE (wordexp ("bad |", &we, WRDE_APPEND), WRDE_BADCHAR); -+ -+ /* State must be exactly as before the failed call. */ -+ CHECK_WORDS (&we, "first"); -+ -+ /* A subsequent successful append must work. */ -+ TEST_COMPARE (wordexp ("second third", &we, WRDE_APPEND), 0); -+ CHECK_WORDS (&we, "first", "second", "third"); -+ -+ wordfree (&we); -+} -+ -+/* Test 6: Multiple consecutive failed appends do not corrupt state. */ -+static void -+test_append_multiple_failures (void) -+{ -+ printf ("info: test_append_multiple_failures\n"); -+ wordexp_t we = { 0 }; -+ -+ TEST_COMPARE (wordexp ("keep this", &we, 0), 0); -+ CHECK_WORDS (&we, "keep", "this"); -+ -+ size_t saved_count = we.we_wordc; -+ char **saved_wordv = we.we_wordv; -+ -+ /* Each of these bad characters must leave the state unchanged. */ -+ TEST_COMPARE (wordexp ("x )", &we, WRDE_APPEND), WRDE_BADCHAR); -+ TEST_COMPARE (wordexp ("x |", &we, WRDE_APPEND), WRDE_BADCHAR); -+ TEST_COMPARE (wordexp ("x ;", &we, WRDE_APPEND), WRDE_BADCHAR); -+ TEST_COMPARE (wordexp ("x &", &we, WRDE_APPEND), WRDE_BADCHAR); -+ TEST_COMPARE (wordexp ("x <", &we, WRDE_APPEND), WRDE_BADCHAR); -+ TEST_COMPARE (wordexp ("x >", &we, WRDE_APPEND), WRDE_BADCHAR); -+ -+ TEST_COMPARE (we.we_wordc, saved_count); -+ TEST_VERIFY (we.we_wordv == saved_wordv); -+ CHECK_WORDS (&we, "keep", "this"); -+ -+ wordfree (&we); -+} -+ -+/* Test 7: WRDE_APPEND with WRDE_SYNTAX error (unterminated quote) also -+ preserves state. */ -+static void -+test_append_syntax_error (void) -+{ -+ printf ("info: test_append_syntax_error\n"); -+ wordexp_t we = { 0 }; -+ -+ TEST_COMPARE (wordexp ("original", &we, 0), 0); -+ CHECK_WORDS (&we, "original"); -+ -+ char **saved_wordv = we.we_wordv; -+ size_t saved_count = we.we_wordc; -+ -+ /* Unterminated double quote triggers WRDE_SYNTAX. */ -+ TEST_COMPARE (wordexp ("\"unterminated", &we, WRDE_APPEND), WRDE_SYNTAX); -+ -+ TEST_COMPARE (we.we_wordc, saved_count); -+ TEST_VERIFY (we.we_wordv == saved_wordv); -+ CHECK_WORDS (&we, "original"); -+ -+ wordfree (&we); -+} -+ -+/* Test 8: Error without WRDE_APPEND still works (regression test for the -+ non-APPEND code path in do_error). */ -+static void -+test_no_append_error (void) -+{ -+ printf ("info: test_no_append_error\n"); -+ wordexp_t we = { 0 }; -+ -+ /* Simple failure without WRDE_APPEND. */ -+ TEST_COMPARE (wordexp ("bad |", &we, 0), WRDE_BADCHAR); -+ -+ /* After failure without WRDE_APPEND the struct should be safe to -+ reuse — start fresh. */ -+ TEST_COMPARE (wordexp ("ok", &we, 0), 0); -+ CHECK_WORDS (&we, "ok"); -+ -+ wordfree (&we); -+} -+ -+/* Test 9: WRDE_BADCHAR on the very first character (no partial words added -+ before the error). */ -+static void -+test_append_badchar_immediate (void) -+{ -+ printf ("info: test_append_badchar_immediate\n"); -+ wordexp_t we = { 0 }; -+ -+ TEST_COMPARE (wordexp ("hello world", &we, 0), 0); -+ CHECK_WORDS (&we, "hello", "world"); -+ -+ char **saved_wordv = we.we_wordv; -+ size_t saved_count = we.we_wordc; -+ -+ /* The bad character is the very first byte — no w_addword call happens -+ before the error. */ -+ TEST_COMPARE (wordexp ("|", &we, WRDE_APPEND), WRDE_BADCHAR); -+ TEST_COMPARE (we.we_wordc, saved_count); -+ TEST_VERIFY (we.we_wordv == saved_wordv); -+ -+ wordfree (&we); -+} -+ -+/* Test 10: WRDE_APPEND into an empty wordexp_t (initial call uses WRDE_APPEND -+ with a zeroed struct — unusual but allowed). */ -+static void -+test_append_into_empty (void) -+{ -+ printf ("info: test_append_into_empty\n"); -+ wordexp_t we = { 0 }; -+ -+ /* First call with WRDE_APPEND on a zeroed struct. The implementation -+ must handle we_wordv == NULL gracefully. */ -+ TEST_COMPARE (wordexp ("solo", &we, WRDE_APPEND), 0); -+ TEST_COMPARE (we.we_wordc, 1); -+ CHECK_WORDS (&we, "solo"); -+ -+ wordfree (&we); -+} -+ -+/* Verify that the leading we_offs slots are all NULL. */ -+static void -+check_offs_null (const wordexp_t *we) -+{ -+ for (size_t i = 0; i < we->we_offs; i++) -+ TEST_VERIFY (we->we_wordv[i] == NULL); -+} -+ -+/* Test 11: successful WRDE_APPEND with WRDE_DOOFFS and a non-zero we_offs. -+ The leading offset slots must stay NULL and words must land at -+ we_wordv[we_offs + i] across both the initial and the appended call. */ -+static void -+test_dooffs_append_success (void) -+{ -+ printf ("info: test_dooffs_append_success\n"); -+ wordexp_t we = { 0 }; -+ we.we_offs = 2; -+ -+ TEST_COMPARE (wordexp ("one two", &we, WRDE_DOOFFS), 0); -+ TEST_COMPARE (we.we_offs, 2); -+ check_offs_null (&we); -+ CHECK_WORDS (&we, "one", "two"); -+ -+ TEST_COMPARE (wordexp ("three", &we, WRDE_APPEND | WRDE_DOOFFS), 0); -+ TEST_COMPARE (we.we_offs, 2); -+ check_offs_null (&we); -+ CHECK_WORDS (&we, "one", "two", "three"); -+ /* The NULL terminator must sit right after the last word. */ -+ TEST_VERIFY (we.we_wordv[we.we_offs + we.we_wordc] == NULL); -+ -+ wordfree (&we); -+} -+ -+/* Test 12: failed WRDE_APPEND with WRDE_DOOFFS preserves we_wordc, the -+ we_wordv pointer, the words and the leading NULL offset slots. This -+ exercises the we_offs arithmetic in the array duplication and in the -+ error-path cleanup (we_wordv[we_offs + --we_wordc]). */ -+static void -+test_dooffs_append_error_preserves_state (void) -+{ -+ printf ("info: test_dooffs_append_error_preserves_state\n"); -+ wordexp_t we = { 0 }; -+ we.we_offs = 3; -+ -+ TEST_COMPARE (wordexp ("alpha beta", &we, WRDE_DOOFFS), 0); -+ check_offs_null (&we); -+ CHECK_WORDS (&we, "alpha", "beta"); -+ -+ char **saved_wordv = we.we_wordv; -+ size_t saved_count = we.we_wordc; -+ unsigned int saved_reallocs = relocating_reallocs; -+ -+ /* "gamma" is a partial word added via w_addword (forcing a relocating -+ realloc of we_wordv) before ')' triggers WRDE_BADCHAR. */ -+ TEST_COMPARE (wordexp ("gamma )", &we, WRDE_APPEND | WRDE_DOOFFS), -+ WRDE_BADCHAR); -+ TEST_VERIFY (relocating_reallocs > saved_reallocs); -+ -+ TEST_COMPARE (we.we_offs, 3); -+ TEST_COMPARE (we.we_wordc, saved_count); -+ TEST_VERIFY (we.we_wordv == saved_wordv); -+ check_offs_null (&we); -+ CHECK_WORDS (&we, "alpha", "beta"); -+ TEST_VERIFY (we.we_wordv[we.we_offs + we.we_wordc] == NULL); -+ -+ wordfree (&we); -+} -+ -+static int -+do_test (void) -+{ -+ test_append_badchar_preserves_count (); -+ test_append_badchar_preserves_pointer (); -+ test_append_badchar_words_intact (); -+ test_append_success (); -+ test_append_success_after_failure (); -+ test_append_multiple_failures (); -+ test_append_syntax_error (); -+ test_no_append_error (); -+ test_append_badchar_immediate (); -+ test_append_into_empty (); -+ test_dooffs_append_success (); -+ test_dooffs_append_error_preserves_state (); -+ -+ return 0; -+} -+ -+#include -diff --git a/posix/wordexp.c b/posix/wordexp.c -index 731d1650e9..50b0d7a256 100644 ---- a/posix/wordexp.c -+++ b/posix/wordexp.c -@@ -35,6 +35,7 @@ - #include - #include <_itoa.h> - #include -+#include - - /* - * This is a recursive-descent-style word expansion routine. -@@ -2224,6 +2225,12 @@ wordexp (const char *words, wordexp_t *pwordexp, int flags) - char ifs_white[4]; - wordexp_t old_word = *pwordexp; - -+ /* When WRDE_APPEND is set we work on a copy of the we_wordv array so that -+ the caller's original pointer is never invalidated by realloc inside -+ w_addword. The saved_wordv keeps the original; on success we free it, -+ on non-NOSPACE error we free the working copy and restore the original. */ -+ char **saved_wordv = NULL; -+ - if (flags & WRDE_REUSE) - { - /* Minimal implementation of WRDE_REUSE for now */ -@@ -2258,6 +2265,23 @@ wordexp (const char *words, wordexp_t *pwordexp, int flags) - pwordexp->we_offs = 0; - } - } -+ else if (pwordexp->we_wordv != NULL) -+ { -+ /* WRDE_APPEND with an existing word list: duplicate the array so that -+ realloc during parsing does not invalidate the caller's pointer. The -+ strings themselves are shared. */ -+ size_t num_p; -+ char **dup; -+ if (INT_ADD_WRAPV (pwordexp->we_offs, pwordexp->we_wordc, &num_p) -+ || INT_ADD_WRAPV (num_p, 1, &num_p)) -+ return WRDE_NOSPACE; -+ dup = __libc_reallocarray (NULL, num_p, sizeof *dup); -+ if (dup == NULL) -+ return WRDE_NOSPACE; -+ memcpy (dup, pwordexp->we_wordv, num_p * sizeof *dup); -+ saved_wordv = pwordexp->we_wordv; -+ pwordexp->we_wordv = dup; -+ } - - /* Find out what the field separators are. - * There are two types: whitespace and non-whitespace. -@@ -2338,7 +2362,7 @@ wordexp (const char *words, wordexp_t *pwordexp, int flags) - error = w_addword (pwordexp, NULL); - - if (error) -- return error; -+ goto do_error; - } - - break; -@@ -2356,7 +2380,7 @@ wordexp (const char *words, wordexp_t *pwordexp, int flags) - error = w_addword (pwordexp, NULL); - - if (error) -- return error; -+ goto do_error; - } - - break; -@@ -2422,10 +2446,18 @@ wordexp (const char *words, wordexp_t *pwordexp, int flags) - - /* There was a word separator at the end */ - if (word == NULL) /* i.e. w_newword */ -- return 0; -+ { -+ free (saved_wordv); -+ return 0; -+ } - -- /* There was no field separator at the end */ -- return w_addword (pwordexp, word); -+ /* There was no field separator at the end. The only possible error -+ from w_addword is WRDE_NOSPACE. */ -+ error = w_addword (pwordexp, word); -+ if (error != 0) -+ goto do_error; -+ free (saved_wordv); -+ return 0; - - do_error: - /* Error: -@@ -2436,11 +2468,30 @@ do_error: - free (word); - - if (error == WRDE_NOSPACE) -- return WRDE_NOSPACE; -+ { -+ /* we_wordc and we_wordv are updated to reflect any words that were -+ successfully expanded. The old array is obsolete. */ -+ free (saved_wordv); -+ return WRDE_NOSPACE; -+ } - -- if ((flags & WRDE_APPEND) == 0) -- wordfree (pwordexp); -+ if (flags & WRDE_APPEND) -+ { -+ /* POSIX 2024 states that for in other error cases, if the WRDE_APPEND -+ flag was specified, we_wordc and we_wordv shall not be modified. -+ -+ Free strings appended during this call, discard the working copy of -+ we_wordv, and restore the caller's original pointer. */ -+ while (pwordexp->we_wordc > old_word.we_wordc) -+ free (pwordexp->we_wordv[pwordexp->we_offs + --pwordexp->we_wordc]); -+ free (pwordexp->we_wordv); -+ pwordexp->we_wordv = saved_wordv; -+ } -+ else -+ { -+ wordfree (pwordexp); -+ *pwordexp = old_word; -+ } - -- *pwordexp = old_word; - return error; - } diff --git a/pkgs/development/libraries/glibc/2.44-master.patch b/pkgs/development/libraries/glibc/2.44-master.patch new file mode 100644 index 000000000000..08c0e1da3143 --- /dev/null +++ b/pkgs/development/libraries/glibc/2.44-master.patch @@ -0,0 +1,4138 @@ +commit 5e5ddf57987ae4b37da5ca2fa039c8803b0be735 +Author: Andreas K. Hüttel +Date: Sat Jul 25 09:20:26 2026 +0900 + + advisories: replace with ADVISORIES text file + + Signed-off-by: Andreas K. Hüttel + +diff --git a/advisories/GLIBC-SA-2023-0001 b/advisories/GLIBC-SA-2023-0001 +deleted file mode 100644 +index 3d19c91b6a..0000000000 +--- a/advisories/GLIBC-SA-2023-0001 ++++ /dev/null +@@ -1,14 +0,0 @@ +-printf: incorrect output for integers with thousands separator and width field +- +-When the printf family of functions is called with a format specifier +-that uses an (enable grouping) and a minimum width +-specifier, the resulting output could be larger than reasonably expected +-by a caller that computed a tight bound on the buffer size. The +-resulting larger than expected output could result in a buffer overflow +-in the printf family of functions. +- +-CVE-Id: CVE-2023-25139 +-Public-Date: 2023-02-02 +-Vulnerable-Commit: e88b9f0e5cc50cab57a299dc7efe1a4eb385161d (2.37) +-Fix-Commit: c980549cc6a1c03c23cc2fe3e7b0fe626a0364b0 (2.38) +-Fix-Commit: 07b9521fc6369d000216b96562ff7c0ed32a16c4 (2.37-4) +diff --git a/advisories/GLIBC-SA-2023-0002 b/advisories/GLIBC-SA-2023-0002 +deleted file mode 100644 +index 5122669a64..0000000000 +--- a/advisories/GLIBC-SA-2023-0002 ++++ /dev/null +@@ -1,15 +0,0 @@ +-getaddrinfo: Stack read overflow in no-aaaa mode +- +-If the system is configured in no-aaaa mode via /etc/resolv.conf, +-getaddrinfo is called for the AF_UNSPEC address family, and a DNS +-response is received over TCP that is larger than 2048 bytes, +-getaddrinfo may potentially disclose stack contents via the returned +-address data, or crash. +- +-CVE-Id: CVE-2023-4527 +-Public-Date: 2023-09-12 +-Vulnerable-Commit: f282cdbe7f436c75864e5640a409a10485e9abb2 (2.36) +-Fix-Commit: bd77dd7e73e3530203be1c52c8a29d08270cb25d (2.39) +-Fix-Commit: 4ea972b7edd7e36610e8cde18bf7a8149d7bac4f (2.36-113) +-Fix-Commit: b7529346025a130fee483d42178b5c118da971bb (2.37-38) +-Fix-Commit: b25508dd774b617f99419bdc3cf2ace4560cd2d6 (2.38-19) +diff --git a/advisories/GLIBC-SA-2023-0003 b/advisories/GLIBC-SA-2023-0003 +deleted file mode 100644 +index d3aef80348..0000000000 +--- a/advisories/GLIBC-SA-2023-0003 ++++ /dev/null +@@ -1,15 +0,0 @@ +-getaddrinfo: Potential use-after-free +- +-When an NSS plugin only implements the _gethostbyname2_r and +-_getcanonname_r callbacks, getaddrinfo could use memory that was freed +-during buffer resizing, potentially causing a crash or read or write to +-arbitrary memory. +- +-CVE-Id: CVE-2023-4806 +-Public-Date: 2023-09-12 +-Fix-Commit: 973fe93a5675c42798b2161c6f29c01b0e243994 (2.39) +-Fix-Commit: e09ee267c03e3150c2c9ba28625ab130705a485e (2.34-420) +-Fix-Commit: e3ccb230a961b4797510e6a1f5f21fd9021853e7 (2.35-270) +-Fix-Commit: a9728f798ec7f05454c95637ee6581afaa9b487d (2.36-115) +-Fix-Commit: 6529a7466c935f36e9006b854d6f4e1d4876f942 (2.37-39) +-Fix-Commit: 00ae4f10b504bc4564e9f22f00907093f1ab9338 (2.38-20) +diff --git a/advisories/GLIBC-SA-2023-0004 b/advisories/GLIBC-SA-2023-0004 +deleted file mode 100644 +index 5286a7aa54..0000000000 +--- a/advisories/GLIBC-SA-2023-0004 ++++ /dev/null +@@ -1,16 +0,0 @@ +-tunables: local privilege escalation through buffer overflow +- +-If a tunable of the form NAME=NAME=VAL is passed in the environment of a +-setuid program and NAME is valid, it may result in a buffer overflow, +-which could be exploited to achieve escalated privileges. This flaw was +-introduced in glibc 2.34. +- +-CVE-Id: CVE-2023-4911 +-Public-Date: 2023-10-03 +-Vulnerable-Commit: 2ed18c5b534d9e92fc006202a5af0df6b72e7aca (2.34) +-Fix-Commit: 1056e5b4c3f2d90ed2b4a55f96add28da2f4c8fa (2.39) +-Fix-Commit: dcc367f148bc92e7f3778a125f7a416b093964d9 (2.34-423) +-Fix-Commit: c84018a05aec80f5ee6f682db0da1130b0196aef (2.35-274) +-Fix-Commit: 22955ad85186ee05834e47e665056148ca07699c (2.36-118) +-Fix-Commit: b4e23c75aea756b4bddc4abcf27a1c6dca8b6bd3 (2.37-45) +-Fix-Commit: 750a45a783906a19591fb8ff6b7841470f1f5701 (2.38-27) +diff --git a/advisories/GLIBC-SA-2023-0005 b/advisories/GLIBC-SA-2023-0005 +deleted file mode 100644 +index cc4eb90b82..0000000000 +--- a/advisories/GLIBC-SA-2023-0005 ++++ /dev/null +@@ -1,18 +0,0 @@ +-getaddrinfo: DoS due to memory leak +- +-The fix for CVE-2023-4806 introduced a memory leak when an application +-calls getaddrinfo for AF_INET6 with AI_CANONNAME, AI_ALL and AI_V4MAPPED +-flags set. +- +-CVE-Id: CVE-2023-5156 +-Public-Date: 2023-09-25 +-Vulnerable-Commit: e09ee267c03e3150c2c9ba28625ab130705a485e (2.34-420) +-Vulnerable-Commit: e3ccb230a961b4797510e6a1f5f21fd9021853e7 (2.35-270) +-Vulnerable-Commit: a9728f798ec7f05454c95637ee6581afaa9b487d (2.36-115) +-Vulnerable-Commit: 6529a7466c935f36e9006b854d6f4e1d4876f942 (2.37-39) +-Vulnerable-Commit: 00ae4f10b504bc4564e9f22f00907093f1ab9338 (2.38-20) +-Fix-Commit: 8006457ab7e1cd556b919f477348a96fe88f2e49 (2.34-421) +-Fix-Commit: 17092c0311f954e6f3c010f73ce3a78c24ac279a (2.35-272) +-Fix-Commit: 856bac55f98dc840e7c27cfa82262b933385de90 (2.36-116) +-Fix-Commit: 4473d1b87d04b25cdd0e0354814eeaa421328268 (2.37-42) +-Fix-Commit: 5ee59ca371b99984232d7584fe2b1a758b4421d3 (2.38-24) +diff --git a/advisories/GLIBC-SA-2024-0001 b/advisories/GLIBC-SA-2024-0001 +deleted file mode 100644 +index 28931c75ae..0000000000 +--- a/advisories/GLIBC-SA-2024-0001 ++++ /dev/null +@@ -1,15 +0,0 @@ +-syslog: Heap buffer overflow in __vsyslog_internal +- +-__vsyslog_internal did not handle a case where printing a SYSLOG_HEADER +-containing a long program name failed to update the required buffer +-size, leading to the allocation and overflow of a too-small buffer on +-the heap. +- +-CVE-Id: CVE-2023-6246 +-Public-Date: 2024-01-30 +-Vulnerable-Commit: 52a5be0df411ef3ff45c10c7c308cb92993d15b1 (2.37) +-Fix-Commit: 6bd0e4efcc78f3c0115e5ea9739a1642807450da (2.39) +-Fix-Commit: 23514c72b780f3da097ecf33a793b7ba9c2070d2 (2.38-42) +-Fix-Commit: 97a4292aa4a2642e251472b878d0ec4c46a0e59a (2.37-57) +-Vulnerable-Commit: b0e7888d1fa2dbd2d9e1645ec8c796abf78880b9 (2.36-16) +-Fix-Commit: d1a83b6767f68b3cb5b4b4ea2617254acd040c82 (2.36-126) +diff --git a/advisories/GLIBC-SA-2024-0002 b/advisories/GLIBC-SA-2024-0002 +deleted file mode 100644 +index 940bfcf2fc..0000000000 +--- a/advisories/GLIBC-SA-2024-0002 ++++ /dev/null +@@ -1,15 +0,0 @@ +-syslog: Heap buffer overflow in __vsyslog_internal +- +-__vsyslog_internal used the return value of snprintf/vsnprintf to +-calculate buffer sizes for memory allocation. If these functions (for +-any reason) failed and returned -1, the resulting buffer would be too +-small to hold output. +- +-CVE-Id: CVE-2023-6779 +-Public-Date: 2024-01-30 +-Vulnerable-Commit: 52a5be0df411ef3ff45c10c7c308cb92993d15b1 (2.37) +-Fix-Commit: 7e5a0c286da33159d47d0122007aac016f3e02cd (2.39) +-Fix-Commit: d0338312aace5bbfef85e03055e1212dd0e49578 (2.38-43) +-Fix-Commit: 67062eccd9a65d7fda9976a56aeaaf6c25a80214 (2.37-58) +-Vulnerable-Commit: b0e7888d1fa2dbd2d9e1645ec8c796abf78880b9 (2.36-16) +-Fix-Commit: 2bc9d7c002bdac38b5c2a3f11b78e309d7765b83 (2.36-127) +diff --git a/advisories/GLIBC-SA-2024-0003 b/advisories/GLIBC-SA-2024-0003 +deleted file mode 100644 +index b43a5150ab..0000000000 +--- a/advisories/GLIBC-SA-2024-0003 ++++ /dev/null +@@ -1,13 +0,0 @@ +-syslog: Integer overflow in __vsyslog_internal +- +-__vsyslog_internal calculated a buffer size by adding two integers, but +-did not first check if the addition would overflow. +- +-CVE-Id: CVE-2023-6780 +-Public-Date: 2024-01-30 +-Vulnerable-Commit: 52a5be0df411ef3ff45c10c7c308cb92993d15b1 (2.37) +-Fix-Commit: ddf542da94caf97ff43cc2875c88749880b7259b (2.39) +-Fix-Commit: d37c2b20a4787463d192b32041c3406c2bd91de0 (2.38-44) +-Fix-Commit: 2b58cba076e912961ceaa5fa58588e4b10f791c0 (2.37-59) +-Vulnerable-Commit: b0e7888d1fa2dbd2d9e1645ec8c796abf78880b9 (2.36-16) +-Fix-Commit: b9b7d6a27aa0632f334352fa400771115b3c69b7 (2.36-128) +diff --git a/advisories/GLIBC-SA-2024-0004 b/advisories/GLIBC-SA-2024-0004 +deleted file mode 100644 +index 08df2b3118..0000000000 +--- a/advisories/GLIBC-SA-2024-0004 ++++ /dev/null +@@ -1,28 +0,0 @@ +-ISO-2022-CN-EXT: fix out-of-bound writes when writing escape sequence +- +-The iconv() function in the GNU C Library versions 2.39 and older may +-overflow the output buffer passed to it by up to 4 bytes when converting +-strings to the ISO-2022-CN-EXT character set, which may be used to +-crash an application or overwrite a neighbouring variable. +- +-ISO-2022-CN-EXT uses escape sequences to indicate character set changes +-(as specified by RFC 1922). While the SOdesignation has the expected +-bounds checks, neither SS2designation nor SS3designation have its; +-allowing a write overflow of 1, 2, or 3 bytes with fixed values: +-'$+I', '$+J', '$+K', '$+L', '$+M', or '$*H'. +- +-CVE-Id: CVE-2024-2961 +-Public-Date: 2024-04-17 +-Vulnerable-Commit: 755104edc75c53f4a0e7440334e944ad3c6b32fc (2.1.93-169) +-Fix-Commit: f9dc609e06b1136bb0408be9605ce7973a767ada (2.40) +-Fix-Commit: 31da30f23cddd36db29d5b6a1c7619361b271fb4 (2.39-31) +-Fix-Commit: e1135387deded5d73924f6ca20c72a35dc8e1bda (2.38-66) +-Fix-Commit: 89ce64b269a897a7780e4c73a7412016381c6ecf (2.37-89) +-Fix-Commit: 4ed98540a7fd19f458287e783ae59c41e64df7b5 (2.36-164) +-Fix-Commit: 36280d1ce5e245aabefb877fe4d3c6cff95dabfa (2.35-315) +-Fix-Commit: a8b0561db4b9847ebfbfec20075697d5492a363c (2.34-459) +-Fix-Commit: ed4f16ff6bed3037266f1fa682ebd32a18fce29c (2.33-263) +-Fix-Commit: 682ad4c8623e611a971839990ceef00346289cc9 (2.32-140) +-Fix-Commit: 3703c32a8d304c1ee12126134ce69be965f38000 (2.31-154) +- +-Reported-By: Charles Fol +diff --git a/advisories/GLIBC-SA-2024-0005 b/advisories/GLIBC-SA-2024-0005 +deleted file mode 100644 +index a59596610a..0000000000 +--- a/advisories/GLIBC-SA-2024-0005 ++++ /dev/null +@@ -1,22 +0,0 @@ +-nscd: Stack-based buffer overflow in netgroup cache +- +-If the Name Service Cache Daemon's (nscd) fixed size cache is exhausted +-by client requests then a subsequent client request for netgroup data +-may result in a stack-based buffer overflow. This flaw was introduced +-in glibc 2.15 when the cache was added to nscd. +- +-This vulnerability is only present in the nscd binary. +- +-CVE-Id: CVE-2024-33599 +-Public-Date: 2024-04-23 +-Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) +-Fix-Commit: 69c58d5ef9f584ea198bd00f7964d364d0e6b921 (2.31-155) +-Fix-Commit: a77064893bfe8a701770e2f53a4d33805bc47a5a (2.32-141) +-Fix-Commit: 5c75001a96abcd50cbdb74df24c3f013188d076e (2.33-264) +-Fix-Commit: 52f73e5c4e29b14e79167272297977f360ae1e97 (2.34-460) +-Fix-Commit: 7a95873543ce225376faf13bb71c43dea6d24f86 (2.35-316) +-Fix-Commit: caa3151ca460bdd9330adeedd68c3112d97bffe4 (2.36-165) +-Fix-Commit: f75c298e747b2b8b41b1c2f551c011a52c41bfd1 (2.37-91) +-Fix-Commit: 5968aebb86164034b8f8421b4abab2f837a5bdaf (2.38-72) +-Fix-Commit: 1263d583d2e28afb8be53f8d6922f0842036f35d (2.39-35) +-Fix-Commit: 87801a8fd06db1d654eea3e4f7626ff476a9bdaa (2.40) +diff --git a/advisories/GLIBC-SA-2024-0006 b/advisories/GLIBC-SA-2024-0006 +deleted file mode 100644 +index d44148d3d9..0000000000 +--- a/advisories/GLIBC-SA-2024-0006 ++++ /dev/null +@@ -1,32 +0,0 @@ +-nscd: Null pointer crash after notfound response +- +-If the Name Service Cache Daemon's (nscd) cache fails to add a not-found +-netgroup response to the cache, the client request can result in a null +-pointer dereference. This flaw was introduced in glibc 2.15 when the +-cache was added to nscd. +- +-This vulnerability is only present in the nscd binary. +- +-CVE-Id: CVE-2024-33600 +-Public-Date: 2024-04-24 +-Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) +-Fix-Commit: b048a482f088e53144d26a61c390bed0210f49f2 (2.40) +-Fix-Commit: 7835b00dbce53c3c87bbbb1754a95fb5e58187aa (2.40) +-Fix-Commit: c99f886de54446cd4447db6b44be93dabbdc2f8b (2.39-37) +-Fix-Commit: 5a508e0b508c8ad53bd0d2fb48fd71b242626341 (2.39-36) +-Fix-Commit: 2ae9446c1b7a3064743b4a51c0bbae668ee43e4c (2.38-74) +-Fix-Commit: 541ea5172aa658c4bd5c6c6d6fd13903c3d5bb0a (2.38-73) +-Fix-Commit: a8070b31043c7585c36ba68a74298c4f7af075c3 (2.37-93) +-Fix-Commit: 5eea50c4402e39588de98aa1d4469a79774703d4 (2.37-92) +-Fix-Commit: f205b3af56740e3b014915b1bd3b162afe3407ef (2.36-167) +-Fix-Commit: c34f470a615b136170abd16142da5dd0c024f7d1 (2.36-166) +-Fix-Commit: bafadc589fbe21ae330e8c2af74db9da44a17660 (2.35-318) +-Fix-Commit: 4370bef52b0f3f3652c6aa13d7a9bb3ac079746d (2.35-317) +-Fix-Commit: 1f94122289a9bf7dba573f5d60327aaa2b85cf2e (2.34-462) +-Fix-Commit: 966d6ac9e40222b84bb21674cc4f83c8d72a5a26 (2.34-461) +-Fix-Commit: e3eef1b8fbdd3a7917af466ca9c4b7477251ca79 (2.33-266) +-Fix-Commit: f20a8d696b13c6261b52a6434899121f8b19d5a7 (2.33-265) +-Fix-Commit: be602180146de37582a3da3a0caa4b719645de9c (2.32-143) +-Fix-Commit: 394eae338199078b7961b051c191539870742d7b (2.32-142) +-Fix-Commit: 8d7949183760170c61e55def723c1d8050187874 (2.31-157) +-Fix-Commit: 304ce5fe466c4762b21b36c26926a4657b59b53e (2.31-156) +diff --git a/advisories/GLIBC-SA-2024-0007 b/advisories/GLIBC-SA-2024-0007 +deleted file mode 100644 +index b6928fa27a..0000000000 +--- a/advisories/GLIBC-SA-2024-0007 ++++ /dev/null +@@ -1,28 +0,0 @@ +-nscd: netgroup cache may terminate daemon on memory allocation failure +- +-The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or +-xrealloc and these functions may terminate the process due to a memory +-allocation failure resulting in a denial of service to the clients. The +-flaw was introduced in glibc 2.15 when the cache was added to nscd. +- +-This vulnerability is only present in the nscd binary. +- +-Subsequent refactoring of the netgroup cache only added more uses of +-xmalloc and xrealloc. Uses of xmalloc and xrealloc in other parts of +-nscd only occur during startup of the daemon and so are not affected by +-client requests that could trigger an out of memory followed by +-termination. +- +-CVE-Id: CVE-2024-33601 +-Public-Date: 2024-04-24 +-Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) +-Fix-Commit: c04a21e050d64a1193a6daab872bca2528bda44b (2.40) +-Fix-Commit: a9a8d3eebb145779a18d90e3966009a1daa63cd8 (2.39-38) +-Fix-Commit: 71af8ca864345d39b746d5cee84b94b430fad5db (2.38-75) +-Fix-Commit: 6e106dc214d6a033a4e945d1c6cf58061f1c5f1f (2.37-94) +-Fix-Commit: b6742463694b1dfdd5120b91ee21cf05d15ec2e2 (2.36-168) +-Fix-Commit: 7a5864cac60e06000394128a5a2817b03542f5a3 (2.35-319) +-Fix-Commit: 86f1d5f4129c373ac6fb6df5bcf38273838843cb (2.34-463) +-Fix-Commit: 4d27d4b9a188786fc6a56745506cec2acfc51f83 (2.33-267) +-Fix-Commit: 3ed195a8ec89da281e3c4bf887a13d281b72d8f4 (2.32-144) +-Fix-Commit: bbf5a58ccb55679217f94de706164d15372fbbc0 (2.31-158) +diff --git a/advisories/GLIBC-SA-2024-0008 b/advisories/GLIBC-SA-2024-0008 +deleted file mode 100644 +index d93e2a6f0b..0000000000 +--- a/advisories/GLIBC-SA-2024-0008 ++++ /dev/null +@@ -1,26 +0,0 @@ +-nscd: netgroup cache assumes NSS callback uses in-buffer strings +- +-The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory +-when the NSS callback does not store all strings in the provided buffer. +-The flaw was introduced in glibc 2.15 when the cache was added to nscd. +- +-This vulnerability is only present in the nscd binary. +- +-There is no guarantee from the NSS callback API that the returned +-strings are all within the buffer. However, the netgroup cache code +-assumes that the NSS callback uses in-buffer strings and if it doesn't +-the buffer resizing logic could lead to potential memory corruption. +- +-CVE-Id: CVE-2024-33602 +-Public-Date: 2024-04-24 +-Vulnerable-Commit: 684ae515993269277448150a1ca70db3b94aa5bd (2.15) +-Fix-Commit: c04a21e050d64a1193a6daab872bca2528bda44b (2.40) +-Fix-Commit: a9a8d3eebb145779a18d90e3966009a1daa63cd8 (2.39-38) +-Fix-Commit: 71af8ca864345d39b746d5cee84b94b430fad5db (2.38-75) +-Fix-Commit: 6e106dc214d6a033a4e945d1c6cf58061f1c5f1f (2.37-94) +-Fix-Commit: b6742463694b1dfdd5120b91ee21cf05d15ec2e2 (2.36-168) +-Fix-Commit: 7a5864cac60e06000394128a5a2817b03542f5a3 (2.35-319) +-Fix-Commit: 86f1d5f4129c373ac6fb6df5bcf38273838843cb (2.34-463) +-Fix-Commit: 4d27d4b9a188786fc6a56745506cec2acfc51f83 (2.33-267) +-Fix-Commit: 3ed195a8ec89da281e3c4bf887a13d281b72d8f4 (2.32-144) +-Fix-Commit: bbf5a58ccb55679217f94de706164d15372fbbc0 (2.31-158) +diff --git a/advisories/GLIBC-SA-2025-0001 b/advisories/GLIBC-SA-2025-0001 +deleted file mode 100644 +index b053d32e91..0000000000 +--- a/advisories/GLIBC-SA-2025-0001 ++++ /dev/null +@@ -1,40 +0,0 @@ +-assert: Buffer overflow when printing assertion failure message +- +-When the assert() function fails, it does not allocate enough space for the +-assertion failure message string and size information, which may lead to a +-buffer overflow if the message string size aligns to page size. +- +-This bug can be triggered when an assertion in a program fails. The assertion +-failure message is allocated to allow developers to see this failure in core +-dumps and it typically includes, in addition to the invariant assertion +-string and function name, the name of the program. If the name of the failing +-program is user controlled, for example on a local system, this could allow an +-attacker to control the assertion failure to trigger this buffer overflow. +- +-The only viable vector for exploitation of this bug is local, if a setuid +-program exists that has an existing bug that results in an assertion failure. +-No such program has been discovered at the time of publishing this advisory, +-but the presence of custom setuid programs, although strongly discouraged as a +-security practice, cannot be discounted. +- +-CVE-Id: CVE-2025-0395 +-Public-Date: 2025-01-22 +-Vulnerable-Commit: f8a3b5bf8fa1d0c43d2458e03cc109a04fdef194 (2.13-175) +-Fix-Commit: 68ee0f704cb81e9ad0a78c644a83e1e9cd2ee578 (2.41) +-Fix-Commit: cdb9ba84191ce72e86346fb8b1d906e7cd930ea2 (2.42) +-Fix-Commit: 69fda28279b497bd405fdd442a6d8e4d3d5f681b (2.41-7) +-Fix-Commit: 7d4b6bcae91f29d7b4daf15bab06b66cf1d2217c (2.40-66) +-Fix-Commit: d6c156c326999f144cb5b73d29982108d549ad8a (2.40-71) +-Fix-Commit: 808a84a8b81468b517a4d721fdc62069cb8c211f (2.39-146) +-Fix-Commit: f6d48470aef9264d2d56f4c4533eb76db7f9c2e4 (2.39-150) +-Fix-Commit: c32fd59314c343db88c3ea4a203870481d33c3d2 (2.38-122) +-Fix-Commit: f984e2d7e8299726891a1a497a3c36cd5542a0bf (2.38-124) +-Fix-Commit: a3d7865b098a3a67c44f7812208d9ce4718873ba (2.37-143) +-Fix-Commit: b989519fe1683c204ac24ec92830e3fe3bfaccad (2.37-146) +-Fix-Commit: 7971add7ee4171fdd8dfd17e7c04c4ed77a18845 (2.36-216) +-Fix-Commit: 0487893d5c5bc6710d83d7c3152d888a0339559e (2.36-219) +-Fix-Commit: 8b5d4be762419c4f6176261c6fea40ac559b88dc (2.35-370) +-Fix-Commit: 8b3d09dc0d350191985f9d291cc30ce96f034b49 (2.35-373) +-Fix-Commit: df4e1f4a5096b385c9bcc94424cf2eaa227b3761 (2.34-500) +-Fix-Commit: 31eb872cb21449832ab47ad5db83281d240e1d03 (2.34-503) +-Reported-By: Qualys Security Advisory +diff --git a/advisories/GLIBC-SA-2025-0002 b/advisories/GLIBC-SA-2025-0002 +deleted file mode 100644 +index 161da13dd4..0000000000 +--- a/advisories/GLIBC-SA-2025-0002 ++++ /dev/null +@@ -1,23 +0,0 @@ +-elf: static setuid binary dlopen may incorrectly search LD_LIBRARY_PATH +- +-A statically linked setuid binary that calls dlopen (including internal +-dlopen calls after setlocale or calls to NSS functions such as getaddrinfo) +-may incorrectly search LD_LIBRARY_PATH to determine which library to load, +-leading to the execution of library code that is attacker controlled. +- +-The only viable vector for exploitation of this bug is local, if a static +-setuid program exists, and that program calls dlopen, then it may search +-LD_LIBRARY_PATH to locate the SONAME to load. No such program has been +-discovered at the time of publishing this advisory, but the presence of +-custom setuid programs, although strongly discouraged as a security +-practice, cannot be discounted. +- +-CVE-Id: CVE-2025-4802 +-Public-Date: 2025-05-16 +-Vulnerable-Commit: 10e93d968716ab82931d593bada121c17c0a4b93 (2.27) +-Fix-Commit: 5451fa962cd0a90a0e2ec1d8910a559ace02bba0 (2.39) +-Fix-Commit: 3be3728df2f1912c80abd3288bc6e3a25ad679e4 (2.38-132) +-Fix-Commit: 7403ede2d7752e59e0c47d5d33d73c2bf850e7be (2.37-154) +-Fix-Commit: 2ef7850279b2931caf6d6d6743ebaa91839e1cf7 (2.36-227) +-Fix-Commit: 621c65ccf12ddd415ceeb2234423bd1acd0fabb3 (2.35-387) +-Fix-Commit: 35018c0fd20eac9ceaf60060fed2745b3177359d (2.34-517) +diff --git a/advisories/GLIBC-SA-2025-0003 b/advisories/GLIBC-SA-2025-0003 +deleted file mode 100644 +index 2adeb3ce00..0000000000 +--- a/advisories/GLIBC-SA-2025-0003 ++++ /dev/null +@@ -1,30 +0,0 @@ +-power10: strcmp fails to save and restore nonvolatile vector registers +- +-The Power 10 implementation of strcmp in +-sysdeps/powerpc/powerpc64/le/power10/strcmp.S failed to save/restore +-nonvolatile vector registers in the 32-byte aligned loop path. This +-results in callers reading content from those registers in a different +-context, potentially altering program logic. +- +-There could be a program context where a user controlled string could +-leak through strcmp into program code, thus altering its logic. There +-is also a potential for sensitive strings passed into strcmp leaking +-through the clobbered registers into parts of the calling program that +-should otherwise not have had access to those strings. +- +-The impact of this flaw is limited to applications running on Power 10 +-hardware that use the nonvolatile vector registers, i.e. v20 to v31 +-assuming that they have been treated in accordance with the OpenPower +-psABI. It is possible to work around the issue for those specific +-applications by setting the glibc.cpu.hwcaps tunable to "-arch_3_1" like +-so: +- +- export GLIBC_TUNABLES=glibc.cpu.hwcaps=-arch_3_1 +- +-CVE-Id: CVE-2025-5702 +-Public-Date: 2025-06-04 +-Vulnerable-Commit: 3367d8e180848030d1646f088759f02b8dfe0d6f (2.39) +-Fix-Commit: 15808c77b35319e67ee0dc8f984a9a1a434701bc (2.42) +-Fix-Commit: 0c76c951620f9e12df2a89b2c684878b55bb6795 (2.41-60) +-Fix-Commit: 7e12550b8e3a11764a4a9090ce6bd3fc23fc8a8e (2.40-139) +-Fix-Commit: 06a70769fd0b2e1f2a3085ad50ab620282bd77b3 (2.39-209) +diff --git a/advisories/GLIBC-SA-2025-0004 b/advisories/GLIBC-SA-2025-0004 +deleted file mode 100644 +index 9409ca27c4..0000000000 +--- a/advisories/GLIBC-SA-2025-0004 ++++ /dev/null +@@ -1,29 +0,0 @@ +-power10: strncmp fails to save and restore nonvolatile vector registers +- +-The Power 10 implementation of strncmp in +-sysdeps/powerpc/powerpc64/le/power10/strncmp.S failed to save/restore +-nonvolatile vector registers in the 32-byte aligned loop path. This +-results in callers reading content from those registers in a different +-context, potentially altering program logic. +- +-There could be a program context where a user controlled string could +-leak through strncmp into program code, thus altering its logic. There +-is also a potential for sensitive strings passed into strncmp leaking +-through the clobbered registers into parts of the calling program that +-should otherwise not have had access to those strings. +- +-The impact of this flaw is limited to applications running on Power 10 +-hardware that use the nonvolatile vector registers, i.e. v20 to v31 +-assuming that they have been treated in accordance with the OpenPower +-psABI. It is possible to work around the issue for those specific +-applications by setting the glibc.cpu.hwcaps tunable to "-arch_3_1" like +-so: +- +- export GLIBC_TUNABLES=glibc.cpu.hwcaps=-arch_3_1 +- +-CVE-Id: CVE-2025-5745 +-Public-Date: 2025-06-05 +-Vulnerable-Commit: 23f0d81608d0ca6379894ef81670cf30af7fd081 (2.40) +-Fix-Commit: 63c60101ce7c5eac42be90f698ba02099b41b965 (2.42) +-Fix-Commit: 84bdbf8a6f2fdafd3661489dbb7f79835a52da82 (2.41-57) +-Fix-Commit: 42a5a940c974d02540c8da26d6374c744d148cb9 (2.40-136) +diff --git a/advisories/GLIBC-SA-2025-0005 b/advisories/GLIBC-SA-2025-0005 +deleted file mode 100644 +index 8bcccc59a5..0000000000 +--- a/advisories/GLIBC-SA-2025-0005 ++++ /dev/null +@@ -1,14 +0,0 @@ +-posix: Fix double-free after allocation failure in regcomp +- +-The regcomp function in the GNU C library version from 2.4 to 2.41 is +-subject to a double free if some previous allocation fails. It can be +-accomplished either by a malloc failure or by using an interposed +-malloc that injects random malloc failures. The double free can allow +-buffer manipulation depending of how the regex is constructed. +-This issue affects all architectures and ABIs supported by the GNU C +-library. +- +-CVE-Id: CVE-2025-8058 +-Public-Date: 2025-07-22 +-Vulnerable-Commit: 963d8d782fc98fb6dc3a66f0068795f9920c269d (2.3.3-1596) +-Fix-Commit: 7ea06e994093fa0bcca0d0ee2c1db271d8d7885d (2.42) +diff --git a/advisories/GLIBC-SA-2026-0001 b/advisories/GLIBC-SA-2026-0001 +deleted file mode 100644 +index 3e0ee3b3f4..0000000000 +--- a/advisories/GLIBC-SA-2026-0001 ++++ /dev/null +@@ -1,41 +0,0 @@ +-Integer overflow in memalign leads to heap corruption +- +-Passing too large an alignment to the memalign suite of functions +-(memalign, posix_memalign, aligned_alloc) in the GNU C Library version +-2.30 to 2.42 may result in an integer overflow, which could consequently +-result in a heap corruption. +- +-Note that the attacker must have control over both, the size as well as +-the alignment arguments of the memalign function to be able to exploit +-this. The size parameter must be close enough to PTRDIFF_MAX so as to +-overflow size_t along with the large alignment argument. This limits +-the malicious inputs for the alignment for memalign to the range [1<<62 +-+ 1, 1<<63] and exactly 1<<63 for posix_memalign and aligned_alloc. +- +-Typically the alignment argument passed to such functions is a known +-constrained quantity (e.g. page size, block size, struct sizes) and is +-not attacker controlled, because of which this may not be easily +-exploitable in practice. An application bug could potentially result in +-the input alignment being too large, e.g. due to a different buffer +-overflow or integer overflow in the application or its dependent +-libraries, but that is again an uncommon usage pattern given typical +-sources of alignments. +- +-CVE-Id: CVE-2026-0861 +-Public-Date: 2026-01-14 +-Vulnerable-Commit: 9bf8e29ca136094f73f69f725f15c51facc97206 (2.30) +-Fix-Commit: c9188d333717d3ceb7e3020011651f424f749f93 (2.43) +-Fix-Commit: 7f19ef14fbce095d4c77395e258320cad2ea2b28 (2.30-153) +-Fix-Commit: f18446d7b4a423090ee5e328c36b3c2a0f26041c (2.31-166) +-Fix-Commit: 8aef9e7a7af9565c0324b4ecb38b30dfa3782fd8 (2.32-151) +-Fix-Commit: 011293b4fd748cdd6f95874ba2b6aba9a3df8bff (2.33-275) +-Fix-Commit: 2c77e52108a58956c9f674b36e1f59a4e3fdcf4d (2.34-525) +-Fix-Commit: 499d1ccafccfe64df1b88deea2fa84d8180e8e8f (2.35-399) +-Fix-Commit: fb6b8822175769b5794fb6ea04f2895483a29b61 (2.36-244) +-Fix-Commit: 7b913d41a07836def826f2164c52541a9835f324 (2.37-172) +-Fix-Commit: 744b63026a29f7eedbbc8e3a01a7f48a6eb0a085 (2.38-212) +-Fix-Commit: fb22fd3f5b415dd4cd6f7b5741c2f0412374e242 (2.39-286) +-Fix-Commit: bfc4dd9e526eacf3017dd8864ba0848e9d045dd4 (2.40-216) +-Fix-Commit: 1e2c1ea4307197ccece0cda574bcfebf9080894c (2.41-121) +-Fix-Commit: b0ec8fb689df862171f0f78994a3bdeb51313545 (2.42-49) +-Reported-by: Igor Morgenstern, Aisle Research +diff --git a/advisories/GLIBC-SA-2026-0002 b/advisories/GLIBC-SA-2026-0002 +deleted file mode 100644 +index f10d8362f6..0000000000 +--- a/advisories/GLIBC-SA-2026-0002 ++++ /dev/null +@@ -1,36 +0,0 @@ +-getnetbyaddr and getnetbyaddr_r leak stack contents to DNS resovler +- +-Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf +-that specifies the library's DNS backend for networks and queries for a +-zero-valued network in the GNU C Library version 2.0 to version 2.42 +-can leak stack contents to the configured DNS resolver. +- +-A defect in the _nss_dns_getnetbyaddr_r function which implements +-getnetbyaddr and getnetbyaddr_r in the dns-based network database can +-pass stack contents unmodified to the configured DNS resolver as part of +-the network DNS query when the network queried is the default network +-i.e. net == 0x0. This stack contents leaking in the query is considered +-a loss of confidentiality for the host making the query. Typically it +-is rare to call these APIs with a net value of zero, and if an attacker +-can control the net value it can only leak adjacent stack, and so loss +-of confidentiality is spatially limited. The leak might be used to +-accelerate an ASLR bypass by knowing pointer values, but also requires +-network adjacent access to snoop between the application and the +-DNS server; making the attack complexity higher. +- +-CVE-Id: CVE-2026-0915 +-Public-Date: 2026-01-15 +-Vulnerable-Commit: 5f0e6fc702296840d2daa39f83f6cb1e40073d58 (1.92-1) +-Fix-Commit: e56ff82d5034ec66c6a78f517af6faa427f65b0b (2.43) +-Fix-Commit: 453e6b8dbab935257eb0802b0c97bca6b67ba30e (2.42-50) +-Fix-Commit: 15c9839a0b853f552b4ed9047841b6223f3c104d (2.41-122) +-Fix-Commit: 329c775788b2c9ff3da774ccf59fba7b6b8ff08e (2.40-217) +-Fix-Commit: 831f63b94ceb92fb14c0d1a7ddad35a0d1404c71 (2.39-287) +-Fix-Commit: 49125ffc8e1674dc2a100dfdc5b78796f22e16f2 (2.38-213) +-Fix-Commit: ddcaed5dfb05b2c1a6ea842fd6b643501365450a (2.37-173) +-Fix-Commit: a6bf47887f24b2b394acb301a3189fda04bd4d4d (2.36-245) +-Fix-Commit: 66f0cb057c9b4fb1249a5fec6ef4a63511a37899 (2.35-400) +-Fix-Commit: 96863dee262225cfb79f9fe45e06fd188319c7b8 (2.34-526) +-Fix-Commit: d210011f1536c8322157cbb4fe4229b35c834c08 (2.33-276) +-Fix-Commit: 1bc1832cfc74c2a601220969f36e789a5e9f0ebe (2.32-152) +-Reported-by: Igor Morgenstern, Aisle Research +diff --git a/advisories/GLIBC-SA-2026-0003 b/advisories/GLIBC-SA-2026-0003 +deleted file mode 100644 +index b7a6e83a10..0000000000 +--- a/advisories/GLIBC-SA-2026-0003 ++++ /dev/null +@@ -1,36 +0,0 @@ +-wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory +- +-Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the +-GNU C Library version 2.0 to version 2.42 may cause the interface to +-return uninitialized memory in the we_wordv member, which on subsequent +-calls to wordfree may abort the process. +- +-The implementation of WRDE_REUSE in conjunction with WRDE_APPEND fails +-to clear the we_wordc member of the structure, and as such, when new +-words are added internally, a leading we_wordc count number of entries +-are skipped since they are assumed initialized. These skipped entries +-are not initialized, but are the contents of a realloc-expanded array of +-pointers. If the caller inspects the we_wordv array, it will +-dereference invalid pointers and crash. If the caller calls wordfree, +-the malloc implementation may detect the invalid pointers and abort the +-process. Calls to wordexp using WRDE_REUSE and WRDE_APPEND have never +-worked correctly and thus the existence of applications that make use of +-this feature is unlikely. +- +-CVE-Id: CVE-2025-15281 +-Public-Date: 2026-01-20 +-Vulnerable-Commit: 8f2ece695d8822e9ecc63ecd157e90bf17a6fe65 (1.93-260) +-Fix-Commit: 80cc58ea2de214f85b0a1d902a3b668ad2ecb302 (2.43) +-Fix-Commit: cbf39c26b25801e9bc88499b4fd361ac172d4125 (2.42-51) +-Fix-Commit: fb4db64a04ad6c96cd1fbb7e02eb59323b1f2ac2 (2.41-123) +-Fix-Commit: 9fe8576664d43b87ca19401fb6a975e217e47623 (2.40-218) +-Fix-Commit: ce65d944e38a20cb70af2a48a4b8aa5d8fabe1cc (2.39-288) +-Fix-Commit: d5409a1be010699794264162c551ba60f05ee6c3 (2.38-214) +-Fix-Commit: ff2b172803f6bbd897755d2ce83ec4323a1a15b3 (2.37-174) +-Fix-Commit: e97cfe2293ed097eb3d0b4c18274d22855e65130 (2.36-246) +-Fix-Commit: bb59339d02faebac534a87eea50c83c948f35b77 (2.35-401) +-Fix-Commit: 2b656ff94d72f93c84d8da2e7c76456c1994f02e (2.34-527) +-Fix-Commit: 1d8ed2067a8a5d162a07670d0d063429679f17a0 (2.33-277) +-Fix-Commit: 3a56c4ee4ea49b8f2391a2d8d6220013c4160a79 (2.32-153) +-Fix-Commit: 28eb5caf895ced5d895cb02757e109004a2d33e5 (2.31-167) +-Reported-by: Vitaly Simonovich +diff --git a/advisories/GLIBC-SA-2026-0004 b/advisories/GLIBC-SA-2026-0004 +deleted file mode 100644 +index fd630dc591..0000000000 +--- a/advisories/GLIBC-SA-2026-0004 ++++ /dev/null +@@ -1,30 +0,0 @@ +-nscd client crash on x86_64 under high nscd load +- +-Calling NSS-backed functions that support caching via nscd may call the +-nscd client side code and in the GNU C Library version 2.36 under high +-load on x86_64 systems, the client may call memcmp on inputs that are +-concurrently modified by other processes or threads and crash. +- +-The nscd client in the GNU C Library uses the memcmp function with +-inputs that may be concurrently modified by another thread, potentially +-resulting in spurious cache misses, which in itself is not a security +-issue. However in the GNU C Library version 2.36 an optimized +-implementation of memcmp was introduced for x86_64 which could crash +-when invoked with such undefined behaviour, turning this into a +-potential crash of the nscd client and the application that uses it. +-This implementation was backported to the 2.35 branch, making the nscd +-client in that branch vulnerable as well. Subsequently, the fix for +-this issue was backported to all vulnerable branches in the GNU C +-Library repository. +- +-It is advised that distributions that may have cherry-picked the memcpy +-SSE2 optimization in their copy of the GNU C Library, also apply the fix +-to avoid the potential crash in the nscd client. +- +-CVE-Id: CVE-2026-3904 +-Public-Date: 2026-03-11 +-Vulnerable-Commit: 8804157ad9da39631703b92315460808eac86b0c (2.36) +-Vulnerable-Commit: 5a8df6485c584e2b0e957ec6b9070437a724911a (2.35-89) +-Fix-Commit: b712be52645282c706a5faa038242504feb06db5 (2.37) +-Fix-Commit: 93967a2a7bbdcedb73e0b246713580c7c84d001e (2.36-84) +-Fix-Commit: 6bcd5d8e3668d52388a6e0580611749f93e6871f (2.35-230) +diff --git a/advisories/GLIBC-SA-2026-0005 b/advisories/GLIBC-SA-2026-0005 +deleted file mode 100644 +index 7a50a43263..0000000000 +--- a/advisories/GLIBC-SA-2026-0005 ++++ /dev/null +@@ -1,37 +0,0 @@ +-gethostbyaddr and gethostbyaddr_r may incorrectly handle DNS response +- +-Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf +-that specifies the library's DNS backend in the GNU C Library version +-2.34 to version 2.43 could, with a crafted response from the configured +-DNS server, result in a violation of the DNS specification that causes +-the application to treat a non-answer section of the DNS response as a +-valid answer. +- +-A defect in the getanswer_ptr function, which implements the iteration +-and extraction of the answer from the DNS response, can cause it to +-incorrectly transition from the answer section to the next section while +-still treating it as an answer to the question. This can happen when +-the answer contains only skipped records, and the subsequent section +-contains a semantically invalid T_PTR record. This is considered a +-security issue because it is a violation of the DNS specification that +-leads to incorrect behaviour that could result in the wrong hostname +-being returned to the caller. At the time of publication, no known +-affected DNS server returns results that would be incorrectly +-interpreted by the library. An attacker would either need to be network +-adjacent or have compromised the DNS server to use this defect to hide +-returned reverse DNS results from intrusion detection systems. Even +-then, the inbound connection from the attacker, or the outbound +-connection from the application, would be visible to the intrusion +-detection system. At best, the defect can be used to obfuscate and +-delay analysis of the evolving threat. +- +-CVE-Id: CVE-2026-4437 +-Public-Date: 2026-03-20 +-Vulnerable-Commit: 32e5db37684ffcbc6ae34fcc6cdcf28670506baa (2.34-323) +-Vulnerable-Commit: def97e7f71a07517810f7263213d607e08ad21f1 (2.35-188) +-Vulnerable-Commit: 77f523c473878ec0051582ef15161c6982879095 (2.36-30) +-Vulnerable-Commit: e32547d661a43da63368e488b6cfa9c53b4dcf92 (2.37) +-Fix-Commit: 5c6fca0c62ce5bd6e68e259f138097756cbafd4d (2.43-16) +-Fix-Commit: 9f5f18aab40ec6b61fa49a007615e6077e9a979b (2.44) +-Reported-by: Antonio Maini (0rbitingZer0) - 0rbitingZer0@proton.me +-Reported-by: Kevin Farrell +diff --git a/advisories/GLIBC-SA-2026-0006 b/advisories/GLIBC-SA-2026-0006 +deleted file mode 100644 +index 1ac70de4d9..0000000000 +--- a/advisories/GLIBC-SA-2026-0006 ++++ /dev/null +@@ -1,27 +0,0 @@ +-gethostbyaddr and gethostbyaddr_r return invalid DNS hostnames +- +-Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf +-that specifies the library's DNS backend in the GNU C library version +-2.34 to version 2.43 could result in an invalid DNS hostname being +-returned to the caller in violation of the DNS specification. +- +-A defect in the getanswer_ptr function, which implements the iteration +-and extraction of the answer from a DNS response, can cause it to accept +-an invalid DNS hostname that can contain shell metacharacters. An +-application that uses the returned hostname in a shell, without guarding +-for shell expansion, may be subject to shell injection attacks. At the +-time of publication, no known affected DNS server returns results with +-shell metacharacters in the results. An attacker would either need to +-be network adjacent or have compromised the DNS server to use this +-defect for shell injection. No known vulnerable application has been +-identified. +- +-CVE-Id: CVE-2026-4438 +-Public-Date: 2026-03-20 +-Vulnerable-Commit: 32e5db37684ffcbc6ae34fcc6cdcf28670506baa (2.34-323) +-Vulnerable-Commit: def97e7f71a07517810f7263213d607e08ad21f1 (2.35-188) +-Vulnerable-Commit: 77f523c473878ec0051582ef15161c6982879095 (2.36-30) +-Vulnerable-Commit: e32547d661a43da63368e488b6cfa9c53b4dcf92 (2.37) +-Fix-Commit: dd9945c0ba40d2dbc9eb7c99291ba6b69bd66718 (2.43-17) +-Fix-Commit: e10977481f4db4b2a3ce34fa4c3a1e26651ae312 (2.44) +-Reported-by: Antonio Maini (0rbitingZer0) - 0rbitingZer0@proton.me +diff --git a/advisories/GLIBC-SA-2026-0007 b/advisories/GLIBC-SA-2026-0007 +deleted file mode 100644 +index b880fb5544..0000000000 +--- a/advisories/GLIBC-SA-2026-0007 ++++ /dev/null +@@ -1,15 +0,0 @@ +-iconv crash due to assertion failure with untrusted input +- +-The iconv() function in the GNU C Library versions 2.43 and earlier may +-crash due to an assertion failure when converting inputs from the +-IBM1390 or IBM1399 character sets, which may be used to remotely crash +-an application. +- +-This vulnerability can be trivially mitigated by removing the IBM1390 +-and IBM1399 character sets from systems that do not need them. +- +-CVE-Id: CVE-2026-4046 +-Public-Date: 2026-03-12 +-Vulnerable-Commit: 0ecb606cb6cf65de1d9fc8a919bceb4be476c602 (2.3.3-1501) +-Fix-Commit: d6f08d1cf027f4eb2ba289a6cc66853722d4badc (2.44) +-Reported-by: Rocket Ma +diff --git a/advisories/GLIBC-SA-2026-0008 b/advisories/GLIBC-SA-2026-0008 +deleted file mode 100644 +index 43b38ce38a..0000000000 +--- a/advisories/GLIBC-SA-2026-0008 ++++ /dev/null +@@ -1,22 +0,0 @@ +-REJECTED: Static buffer overflow in deprecated nis_local_principal +- +-REJECTED: CVE-2026-5358 is rejected for two reasons. Firstly it has been +-discovered that no NIS+ client or server was ever released for any +-Linux-based OS distributions and as such this makes the API provisional +-and unused. Secondly it has been discovered that the NIS+ cold start +-cache (/var/nis/NIS_COLD_START) cannot be bypassed and as such the API +-can only be called with a trusted server from the pre-populated cache. +-The use of a trusted server means no trust boundary is crossed and this +-is therefore considered a normal bug. +- +-NIS+ support in the GNU C Library was never officially supported even +-though an incomplete implementation of the APIs was made pulibc. To the +-best knowledge of the glibc security team no open-source NIS+ server +-implementations were ever released for use with this API. Applications +-should not use any of the NIS+ APIs and should move to modern identity +-and access management services. +- +-CVE-Id: CVE-2026-5358 +-Public-Date: 2026-04-10 +-Rejected-Date: 2026-04-33 +-Reported-by: Rahul Hoysala +diff --git a/advisories/GLIBC-SA-2026-0009 b/advisories/GLIBC-SA-2026-0009 +deleted file mode 100644 +index 3c297fdc80..0000000000 +--- a/advisories/GLIBC-SA-2026-0009 ++++ /dev/null +@@ -1,23 +0,0 @@ +-scanf %mc off-by-one heap buffer overflow +- +-Calling the scanf family of functions with a %mc (malloc'd character +-match) in the GNU C Library version 2.7 to version 2.43 with a format +-width specifier with an explicit width greater than 1024 could result in +-a one byte heap buffer overflow. +- +-The bug is in the buffer growth formula in __vfscanf_internal, which +-under-allocates by one byte during realloc expansion, allowing a +-controlled single-byte overwrite past the end of the heap buffer. +- +-The impact is limited by the fact that to execute the overwrite you need +-both user controlled input data and a specific choice of maximum width +-that yields a smaller than needed allocation. The latter point has to +-take into account malloc's particular chunk size rounding process. The +-"%[width]mc" format specifier does not appear to have notable use in +-major Linux-based OS distributions, due to which the real world impact +-may be limited to bespoke use cases. +- +-CVE-Id: CVE-2026-5450 +-Public-Date: 2026-03-19 +-Vulnerable-Commit: 874aa52349cc111d1f6ea5dff24bb14c306714e0 (2.7) +-Reported-by: Rocket Ma +diff --git a/advisories/GLIBC-SA-2026-0010 b/advisories/GLIBC-SA-2026-0010 +deleted file mode 100644 +index ae9953fb71..0000000000 +--- a/advisories/GLIBC-SA-2026-0010 ++++ /dev/null +@@ -1,24 +0,0 @@ +-Potential buffer under-read in ungetwc +- +-Calling the ungetwc function on a FILE stream with wide characters +-encoded in a character set that has overlaps between its single byte and +-multi-byte character encodings, in the GNU C Library version 2.43 or +-earlier, may result in an attempt to read bytes before an allocated +-buffer, potentially resulting in unintentional disclosure of neighboring +-data in the heap, or a program crash. +- +-A bug in the wide character pushback implementation +-(_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate +-on the regular character buffer (fp->_IO_read_ptr) instead of the actual +-wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program +-crash may happen in cases where fp->_IO_read_ptr is not initialized and +-hence points to NULL. The buffer under-read requires a special situation +-where the input character encoding is such that there are overlaps +-between single byte representations and multibyte representations in +-that encoding, resulting in spurious matches. The spurious match case +-is not possible in the standard Unicode character sets. +- +-CVE-Id: CVE-2026-5928 +-Public-Date: 2026-03-17 +-Reported-by: Rocket Ma +-Vulnerable-Commit: d64b6ad07585b8a37e5fecc9a47fcee766d52ede (2.1.1-89) +diff --git a/advisories/GLIBC-SA-2026-0011 b/advisories/GLIBC-SA-2026-0011 +deleted file mode 100644 +index e492fa5507..0000000000 +--- a/advisories/GLIBC-SA-2026-0011 ++++ /dev/null +@@ -1,24 +0,0 @@ +-Potential buffer overflow in ns_sprintrrf TSIG handling path +- +-The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the +-GNU C Library version 2.2 and newer fail to enforce the caller-supplied +-buffer length, and can result in an out-of-bounds write when printing +-TSIG records. +- +-A defect in the TSIG case handling within ns_sprintrrf performs a +-formatted write using sprintf without checking the remaining buffer +-length, and may write up to 6 bytes past the end of the buffer. If the +-library is compiled with assertions, and the out-of-bounds write doesn't +-terminate the process, then a subsequent check for "len <= *buflen" will +-trigger an assertion failure. +- +-These functions are for application debugging only and hence not in the +-path of code executed by the DNS resolver. Further, they have been +-deprecated since version 2.34 (2021-08-02) and should not be used by any +-new applications. Applications should consider porting away from these +-interfaces since they may be removed in future versions. +- +-CVE-Id: CVE-2026-5435 +-Public-Date: 2026-04-02 +-Vulnerable-Commit: b43b13ac2544b11f35be301d1589b51a8473e32b (2.2) +-Reported-by: shinobu +diff --git a/advisories/GLIBC-SA-2026-0012 b/advisories/GLIBC-SA-2026-0012 +deleted file mode 100644 +index 22071d97a6..0000000000 +--- a/advisories/GLIBC-SA-2026-0012 ++++ /dev/null +@@ -1,18 +0,0 @@ +-Buffer overread in ns_printrrf with corrupted RDATA field +- +-The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the +-GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA +-content against the RDATA length in a DNS response when processing A6, +-CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a +-DNS response, causing a target application to crash or read +-uninitialized memory. +- +-These functions are for application debugging only and hence not in the +-path of code executed by the DNS resolver. Further, they have been +-deprecated since version 2.34 and should not be used by any new +-applications. Applications should consider porting away from these +-interfaces since they may be removed in future versions. +- +-CVE-Id: CVE-2026-6238 +-Public-Date: 2026-04-11 +-Vulnerable-Commit: ee188d555b8c32ad9704a7440cab400af967292f (1.90) +diff --git a/advisories/GLIBC-SA-2026-0013 b/advisories/GLIBC-SA-2026-0013 +deleted file mode 100644 +index 085a853434..0000000000 +--- a/advisories/GLIBC-SA-2026-0013 ++++ /dev/null +@@ -1,20 +0,0 @@ +-Potential stack-based buffer clash during tilde expansion in wordexp +- +-Calling wordexp with a tilde (~) followed by an overly long username +-in the GNU C Library version 2.2.3 to 2.43 may lead to a stack buffer +-clash. +- +-When expanding paths that begin with a tilde (~) followed by a username, the +-internal parse_tilde function extracts the username to determine the user's +-home directory. The implementation allocates memory for this username directly +-on the stack using the strndupa macro. Because the size of this allocation +-was determined by the length of the user-supplied input without any bounds +-checks, passing an excessively long username e.g. thousands of characters, +-forces the thread to exhaust its stack space. Thus if an application passes +-untrusted, attacker-controlled input to the wordexp function, an attacker +-can trigger a stack clash. +- +-CVE-Id: CVE-2026-6791 +-Public-Date: 2026-06-22 +-Vulnerable-Commit: 344af000e1d6e9c7882b9bc48e71cb3f1b5fc03c (2.2.3-114) +-Reported-by: storm +diff --git a/advisories/GLIBC-SA-2026-0014 b/advisories/GLIBC-SA-2026-0014 +deleted file mode 100644 +index 1e9a0039f0..0000000000 +--- a/advisories/GLIBC-SA-2026-0014 ++++ /dev/null +@@ -1,19 +0,0 @@ +-wordexp with WRDE_APPEND may result in an invalid call to free() +- +-Calling wordexp with WRDE_APPEND in conjunction with an invalid expansion +-(where an error like WRDE_BADCHAR would be returned) can create a stale +-address in the wordexp_t that can cause an invalid free from wordfree. +-This affects the GNU C Library version 2.0 to version 2.43. +- +-In WRDE_APPEND mode, wordexp saves the caller-visible wordexp_t state +-before appending the processing input. If the word expansion grows +-we_wordv via realloc, and realloc requires moving we_wordv to a new memory +-location (instead of expanding in-place), and the expansion later fails, +-the rollback fails to properly restore all previous we_wordv values and +-may add stale pointers into the caller-visible state. A subsequent +-wordfree may then issue an invalid call to free(). +- +-CVE-Id: CVE-2026-6368 +-Public-Date: 2026-07-14 +-Vulnerable-Commit: 8f2ece695d8822e9ecc63ecd157e90bf17a6fe65 (1.93-260) +-Reported-by: shinobu +diff --git a/advisories/README b/advisories/README +deleted file mode 100644 +index 330a31dff3..0000000000 +--- a/advisories/README ++++ /dev/null +@@ -1,92 +0,0 @@ +-GNU C Library Security Advisory Format +-====================================== +- +-Security advisories in this directory follow a simple git commit log +-format, with a heading and free-format description augmented with tags +-to allow parsing key information. References to code changes are +-specific to the glibc repository and follow a specific format: +- +- Tag-name: (release-version) +- +-The indicates a specific commit in the repository. The +-release-version indicates the publicly consumable release in which this +-commit is known to exist. The release-version is derived from the +-git-describe format, (i.e. stripped out from glibc-2.34.NNN-gxxxx) and +-is of the form 2.34-NNN. If the -NNN suffix is absent, it means that +-the change is in that release tarball, otherwise the change is on the +-release/2.YY/master branch and not in any released tarball. +- +-The following tags are currently being used: +- +-CVE-Id: +-This is the CVE-Id assigned under the CVE Program +-(https://www.cve.org/). +- +-Public-Date: +-The date this issue became publicly known. +- +-Rejected-Date: +-The most recent date the assigned advisory was rejected. If the advisory +-is ever published again the Rejected-Date tag should be removed. +- +-Vulnerable-Commit: +-The commit that introduced this vulnerability. There could be multiple +-entries, one for each release branch in the glibc repository; the +-release-version portion of this tag should tell you which branch this is +-on. +- +-Fix-Commit: +-The commit that fixed this vulnerability. There could be multiple +-entries for each release branch in the glibc repository, indicating that +-all of those commits contributed to fixing that issue in each of those +-branches. +- +-Reported-By: +-The entity that reported this issue. There could be multiple entries, one for +-each reporter. +- +-Adding an Advisory +------------------- +- +-An advisory for a CVE needs to be added on the master branch in two steps: +- +-1. Add the text of the advisory without any Fix-Commit tags along with +- the fix for the CVE. Add the Vulnerable-Commit tag, if applicable. +- The advisories directory does not exist in release branches, so keep +- the advisory text commit distinct from the code changes, to ease +- backports. Ask for the GLIBC-SA advisory number from the security +- team. +- +-2. Finish all backports on release branches and then back on the msater +- branch, add all commit refs to the advisory using the Fix-Commit +- tags. Don't bother adding the release-version subscript since the +- next step will overwrite it. +- +-3. Run the process-advisories.sh script in the scripts directory on the +- advisory: +- +- scripts/process-advisories.sh update GLIBC-SA-YYYY-NNNN +- +- (replace YYYY-NNNN with the actual advisory number). +- +-4. Verify the updated advisory and push the result. +- +-Rejecting an Advisory +---------------------- +- +-Rejecting an advisory on the master branch can be done in one step: +- +-1. Mark the advisory as rejected. Add the text "REJECTED: " as a prefix +- to any short-form description. Add a new paragraph that starts with +- "REJECTED: " and explains the reason for the rejection including +- justification for why it no longer has security impact. Lastly add +- a Rejected-Date tag to the advisory. +- +-Getting a NEWS snippet from advisories +--------------------------------------- +- +-Run: +- +- scripts/process-advisories.sh news +- +-and copy the content into the NEWS file. + +commit 1bd79651065b27c02c6502b9423124e54882058d +Author: Andreas K. Hüttel +Date: Sat Jul 25 09:21:33 2026 +0900 + + NEWS: start 2.44.1 section + + Signed-off-by: Andreas K. Hüttel + +diff --git a/NEWS b/NEWS +index ee28fadf49..1043343d70 100644 +--- a/NEWS ++++ b/NEWS +@@ -5,6 +5,10 @@ See the end for copying conditions. + Please send GNU C library bug reports via + using `glibc' in the "product" field. + ++Version 2.44.1 ++ ++The following bugs are resolved with this release: ++ + Version 2.44 + + Major new features: + +commit 0b05bc142249ac47e72be5cad5c37f33f4bb68d4 +Author: Samuel Thibault +Date: Fri Jul 24 23:10:02 2026 +0200 + + hurd: Make the readlink __fstatat64 references optional + + They may show up or not depending on the toolchain in use. + +diff --git a/sysdeps/mach/hurd/i386/localplt.data b/sysdeps/mach/hurd/i386/localplt.data +index 2befcd3748..5b9413422d 100644 +--- a/sysdeps/mach/hurd/i386/localplt.data ++++ b/sysdeps/mach/hurd/i386/localplt.data +@@ -25,14 +25,14 @@ ld.so: __writev + ld.so: __libc_lseek64 + ld.so: __mmap + ld.so: __fstat64 +-ld.so: __fstatat64 ++ld.so: __fstatat64 ? + ld.so: __stat64 + ld.so: __access + ld.so: __getpid + ld.so: __getcwd + ld.so: _exit ? + ld.so: abort +-ld.so: readlink ++ld.so: readlink ? + ld.so: _hurd_intr_rpc_mach_msg + ld.so: __errno_location + ld.so: _dl_init_first +diff --git a/sysdeps/mach/hurd/x86_64/localplt.data b/sysdeps/mach/hurd/x86_64/localplt.data +index fda28cd983..cc39118d12 100644 +--- a/sysdeps/mach/hurd/x86_64/localplt.data ++++ b/sysdeps/mach/hurd/x86_64/localplt.data +@@ -24,14 +24,14 @@ ld.so: __writev + ld.so: __libc_lseek64 + ld.so: __mmap + ld.so: __fstat64 +-ld.so: __fstatat64 ++ld.so: __fstatat64 ? + ld.so: __stat64 + ld.so: __access + ld.so: __getpid + ld.so: __getcwd + ld.so: _exit ? + ld.so: abort +-ld.so: readlink ++ld.so: readlink ? + ld.so: _hurd_intr_rpc_mach_msg + ld.so: __errno_location + ld.so: _dl_init_first + +commit c045fc61e8435c103ebfe06d01fec7f56503e2b4 +Author: Samuel Thibault +Date: Mon Jul 27 00:59:36 2026 +0200 + + hurd: fix fork's longjmp demangling on i386 + + i386's setjmp does not actually mangle ebp. + +diff --git a/sysdeps/mach/hurd/i386/longjmp-ts.c b/sysdeps/mach/hurd/i386/longjmp-ts.c +index 93450e86b4..340104b832 100644 +--- a/sysdeps/mach/hurd/i386/longjmp-ts.c ++++ b/sysdeps/mach/hurd/i386/longjmp-ts.c +@@ -38,7 +38,6 @@ _hurd_longjmp_thread_state (void *state, jmp_buf env, int val) + ts->eip = env[0].__jmpbuf[JB_PC]; + ts->eax = val ?: 1; + +- PTR_DEMANGLE (ts->ebp); + PTR_DEMANGLE (ts->uesp); + PTR_DEMANGLE (ts->eip); + } + +commit 7cba77790f3279bec3ac20e9c7632b021cd53f95 +Author: Adhemerval Zanella +Date: Mon Jul 27 13:37:19 2026 -0300 + + math: Fix sinh worst-case results for |x| > 36.736801 [BZ 34441] + + The CORE-MATH import mistranslated the accurate path result scaling + 'th *= sp.f' as 'th *= asuint64 (sp)' (commit 106f8c2ed68), and two of + the 51 exceptional-case table entries were dropped when the table was + moved to e_sinh_data.c (commit f05c4907a27). + + Checked on x86_64-linux-gnu and aarch64-linux-gnu. + + (cherry picked from commit fdc90dbb52b092f68cd5a4fac7a4cbd854c91bc3) + +diff --git a/NEWS b/NEWS +index 1043343d70..fe2b1d7f79 100644 +--- a/NEWS ++++ b/NEWS +@@ -8,6 +8,9 @@ using `glibc' in the "product" field. + Version 2.44.1 + + The following bugs are resolved with this release: ++ ++ [34441] math: math: sinh() returns wrong results for some inputs with ++ |x| > 36.736801 + + Version 2.44 + +diff --git a/math/auto-libm-test-in b/math/auto-libm-test-in +index ca670768a2..5c4d486af4 100644 +--- a/math/auto-libm-test-in ++++ b/math/auto-libm-test-in +@@ -9661,6 +9661,14 @@ sinh 0x2.c5d37700c6bb03a6c24b6c9b494cp+12 + sinh 0x2.c5d37700c6bb03a6c24b6c9b494ep+12 + # the next value generates larger error bounds on x86_64 (binary64) + sinh -0x1.633c62890fa14p+9 ++sinh 0x1.2b4f4e0bb49c9p+5 ++sinh -0x1.2b4f4e0bb49c9p+5 ++sinh 0x1.2ac43fb6d3abap+5 ++sinh -0x1.2ac43fb6d3abap+5 ++sinh 0x1.b7efa91915c95p-2 ++sinh -0x1.b7efa91915c95p-2 ++sinh 0x1.92a5c27afbe82p+4 ++sinh -0x1.92a5c27afbe82p+4 + + sinpi 0 + sinpi -0 +diff --git a/math/auto-libm-test-out-sinh b/math/auto-libm-test-out-sinh +index f96252b91c..91ab5c19fa 100644 +--- a/math/auto-libm-test-out-sinh ++++ b/math/auto-libm-test-out-sinh +@@ -6466,3 +6466,555 @@ sinh -0x1.633c62890fa14p+9 + = sinh tonearest ibm128 -0x2.c678c5121f428p+8 : -0xf.ef3a7e711d2c75a66ea3ca1c4p+1020 : inexact-ok + = sinh towardzero ibm128 -0x2.c678c5121f428p+8 : -0xf.ef3a7e711d2c75a66ea3ca1c4p+1020 : inexact-ok + = sinh upward ibm128 -0x2.c678c5121f428p+8 : -0xf.ef3a7e711d2c75a66ea3ca1c4p+1020 : inexact-ok ++sinh 0x1.2b4f4e0bb49c9p+5 ++= sinh downward binary32 0x2.569eap+4 : 0x1.f7c30ap+52 : inexact-ok ++= sinh tonearest binary32 0x2.569eap+4 : 0x1.f7c30ap+52 : inexact-ok ++= sinh towardzero binary32 0x2.569eap+4 : 0x1.f7c30ap+52 : inexact-ok ++= sinh upward binary32 0x2.569eap+4 : 0x1.f7c30cp+52 : inexact-ok ++= sinh downward binary64 0x2.569eap+4 : 0x1.f7c30a155eea3p+52 : inexact-ok ++= sinh tonearest binary64 0x2.569eap+4 : 0x1.f7c30a155eea4p+52 : inexact-ok ++= sinh towardzero binary64 0x2.569eap+4 : 0x1.f7c30a155eea3p+52 : inexact-ok ++= sinh upward binary64 0x2.569eap+4 : 0x1.f7c30a155eea4p+52 : inexact-ok ++= sinh downward intel96 0x2.569eap+4 : 0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh tonearest intel96 0x2.569eap+4 : 0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh towardzero intel96 0x2.569eap+4 : 0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh upward intel96 0x2.569eap+4 : 0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh downward m68k96 0x2.569eap+4 : 0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh tonearest m68k96 0x2.569eap+4 : 0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh towardzero m68k96 0x2.569eap+4 : 0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh upward m68k96 0x2.569eap+4 : 0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh downward binary128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84f52p+52 : inexact-ok ++= sinh tonearest binary128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84f52p+52 : inexact-ok ++= sinh towardzero binary128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84f52p+52 : inexact-ok ++= sinh upward binary128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84f53p+52 : inexact-ok ++= sinh downward ibm128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84fp+52 : inexact-ok ++= sinh tonearest ibm128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84f8p+52 : inexact-ok ++= sinh towardzero ibm128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84fp+52 : inexact-ok ++= sinh upward ibm128 0x2.569eap+4 : 0x1.f7c30a155eea3c77d646a5f84f8p+52 : inexact-ok ++= sinh downward binary32 0x2.569e9cp+4 : 0x1.f7c28cp+52 : inexact-ok ++= sinh tonearest binary32 0x2.569e9cp+4 : 0x1.f7c28cp+52 : inexact-ok ++= sinh towardzero binary32 0x2.569e9cp+4 : 0x1.f7c28cp+52 : inexact-ok ++= sinh upward binary32 0x2.569e9cp+4 : 0x1.f7c28ep+52 : inexact-ok ++= sinh downward binary64 0x2.569e9cp+4 : 0x1.f7c28c24ac22fp+52 : inexact-ok ++= sinh tonearest binary64 0x2.569e9cp+4 : 0x1.f7c28c24ac23p+52 : inexact-ok ++= sinh towardzero binary64 0x2.569e9cp+4 : 0x1.f7c28c24ac22fp+52 : inexact-ok ++= sinh upward binary64 0x2.569e9cp+4 : 0x1.f7c28c24ac23p+52 : inexact-ok ++= sinh downward intel96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh tonearest intel96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh towardzero intel96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh upward intel96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbcp+52 : inexact-ok ++= sinh downward m68k96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh tonearest m68k96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh towardzero m68k96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh upward m68k96 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbcp+52 : inexact-ok ++= sinh downward binary128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd1ebp+52 : inexact-ok ++= sinh tonearest binary128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd1ebp+52 : inexact-ok ++= sinh towardzero binary128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd1ebp+52 : inexact-ok ++= sinh upward binary128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd1ecp+52 : inexact-ok ++= sinh downward ibm128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd18p+52 : inexact-ok ++= sinh tonearest ibm128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd2p+52 : inexact-ok ++= sinh towardzero ibm128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd18p+52 : inexact-ok ++= sinh upward ibm128 0x2.569e9cp+4 : 0x1.f7c28c24ac22fbbe1ad8f17fd2p+52 : inexact-ok ++= sinh downward binary64 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1dp+52 : inexact-ok ++= sinh tonearest binary64 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1ep+52 : inexact-ok ++= sinh towardzero binary64 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1dp+52 : inexact-ok ++= sinh upward binary64 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1ep+52 : inexact-ok ++= sinh downward intel96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh tonearest intel96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh towardzero intel96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh upward intel96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d802p+52 : inexact-ok ++= sinh downward m68k96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh tonearest m68k96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh towardzero m68k96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh upward m68k96 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d802p+52 : inexact-ok ++= sinh downward binary128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000008f84p+52 : inexact-ok ++= sinh tonearest binary128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000008f85p+52 : inexact-ok ++= sinh towardzero binary128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000008f84p+52 : inexact-ok ++= sinh upward binary128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000008f85p+52 : inexact-ok ++= sinh downward ibm128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000008f8p+52 : inexact-ok ++= sinh tonearest ibm128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000008f8p+52 : inexact-ok ++= sinh towardzero ibm128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000008f8p+52 : inexact-ok ++= sinh upward ibm128 0x2.569e9c1769392p+4 : 0x1.f7c28f05c4c1d800000000009p+52 : inexact-ok ++sinh -0x1.2b4f4e0bb49c9p+5 ++= sinh downward binary32 -0x2.569e9cp+4 : -0x1.f7c28ep+52 : inexact-ok ++= sinh tonearest binary32 -0x2.569e9cp+4 : -0x1.f7c28cp+52 : inexact-ok ++= sinh towardzero binary32 -0x2.569e9cp+4 : -0x1.f7c28cp+52 : inexact-ok ++= sinh upward binary32 -0x2.569e9cp+4 : -0x1.f7c28cp+52 : inexact-ok ++= sinh downward binary64 -0x2.569e9cp+4 : -0x1.f7c28c24ac23p+52 : inexact-ok ++= sinh tonearest binary64 -0x2.569e9cp+4 : -0x1.f7c28c24ac23p+52 : inexact-ok ++= sinh towardzero binary64 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fp+52 : inexact-ok ++= sinh upward binary64 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fp+52 : inexact-ok ++= sinh downward intel96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbcp+52 : inexact-ok ++= sinh tonearest intel96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh towardzero intel96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh upward intel96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh downward m68k96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbcp+52 : inexact-ok ++= sinh tonearest m68k96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh towardzero m68k96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh upward m68k96 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbep+52 : inexact-ok ++= sinh downward binary128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd1ecp+52 : inexact-ok ++= sinh tonearest binary128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd1ebp+52 : inexact-ok ++= sinh towardzero binary128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd1ebp+52 : inexact-ok ++= sinh upward binary128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd1ebp+52 : inexact-ok ++= sinh downward ibm128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd2p+52 : inexact-ok ++= sinh tonearest ibm128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd2p+52 : inexact-ok ++= sinh towardzero ibm128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd18p+52 : inexact-ok ++= sinh upward ibm128 -0x2.569e9cp+4 : -0x1.f7c28c24ac22fbbe1ad8f17fd18p+52 : inexact-ok ++= sinh downward binary32 -0x2.569eap+4 : -0x1.f7c30cp+52 : inexact-ok ++= sinh tonearest binary32 -0x2.569eap+4 : -0x1.f7c30ap+52 : inexact-ok ++= sinh towardzero binary32 -0x2.569eap+4 : -0x1.f7c30ap+52 : inexact-ok ++= sinh upward binary32 -0x2.569eap+4 : -0x1.f7c30ap+52 : inexact-ok ++= sinh downward binary64 -0x2.569eap+4 : -0x1.f7c30a155eea4p+52 : inexact-ok ++= sinh tonearest binary64 -0x2.569eap+4 : -0x1.f7c30a155eea4p+52 : inexact-ok ++= sinh towardzero binary64 -0x2.569eap+4 : -0x1.f7c30a155eea3p+52 : inexact-ok ++= sinh upward binary64 -0x2.569eap+4 : -0x1.f7c30a155eea3p+52 : inexact-ok ++= sinh downward intel96 -0x2.569eap+4 : -0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh tonearest intel96 -0x2.569eap+4 : -0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh towardzero intel96 -0x2.569eap+4 : -0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh upward intel96 -0x2.569eap+4 : -0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh downward m68k96 -0x2.569eap+4 : -0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh tonearest m68k96 -0x2.569eap+4 : -0x1.f7c30a155eea3c78p+52 : inexact-ok ++= sinh towardzero m68k96 -0x2.569eap+4 : -0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh upward m68k96 -0x2.569eap+4 : -0x1.f7c30a155eea3c76p+52 : inexact-ok ++= sinh downward binary128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84f53p+52 : inexact-ok ++= sinh tonearest binary128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84f52p+52 : inexact-ok ++= sinh towardzero binary128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84f52p+52 : inexact-ok ++= sinh upward binary128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84f52p+52 : inexact-ok ++= sinh downward ibm128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84f8p+52 : inexact-ok ++= sinh tonearest ibm128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84f8p+52 : inexact-ok ++= sinh towardzero ibm128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84fp+52 : inexact-ok ++= sinh upward ibm128 -0x2.569eap+4 : -0x1.f7c30a155eea3c77d646a5f84fp+52 : inexact-ok ++= sinh downward binary64 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1ep+52 : inexact-ok ++= sinh tonearest binary64 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1ep+52 : inexact-ok ++= sinh towardzero binary64 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1dp+52 : inexact-ok ++= sinh upward binary64 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1dp+52 : inexact-ok ++= sinh downward intel96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d802p+52 : inexact-ok ++= sinh tonearest intel96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh towardzero intel96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh upward intel96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh downward m68k96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d802p+52 : inexact-ok ++= sinh tonearest m68k96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh towardzero m68k96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh upward m68k96 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d8p+52 : inexact-ok ++= sinh downward binary128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000008f85p+52 : inexact-ok ++= sinh tonearest binary128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000008f85p+52 : inexact-ok ++= sinh towardzero binary128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000008f84p+52 : inexact-ok ++= sinh upward binary128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000008f84p+52 : inexact-ok ++= sinh downward ibm128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000009p+52 : inexact-ok ++= sinh tonearest ibm128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000008f8p+52 : inexact-ok ++= sinh towardzero ibm128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000008f8p+52 : inexact-ok ++= sinh upward ibm128 -0x2.569e9c1769392p+4 : -0x1.f7c28f05c4c1d800000000008f8p+52 : inexact-ok ++sinh 0x1.2ac43fb6d3abap+5 ++= sinh downward binary32 0x2.55888p+4 : 0x1.d6b0ecp+52 : inexact-ok ++= sinh tonearest binary32 0x2.55888p+4 : 0x1.d6b0ecp+52 : inexact-ok ++= sinh towardzero binary32 0x2.55888p+4 : 0x1.d6b0ecp+52 : inexact-ok ++= sinh upward binary32 0x2.55888p+4 : 0x1.d6b0eep+52 : inexact-ok ++= sinh downward binary64 0x2.55888p+4 : 0x1.d6b0ecda100c2p+52 : inexact-ok ++= sinh tonearest binary64 0x2.55888p+4 : 0x1.d6b0ecda100c2p+52 : inexact-ok ++= sinh towardzero binary64 0x2.55888p+4 : 0x1.d6b0ecda100c2p+52 : inexact-ok ++= sinh upward binary64 0x2.55888p+4 : 0x1.d6b0ecda100c3p+52 : inexact-ok ++= sinh downward intel96 0x2.55888p+4 : 0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh tonearest intel96 0x2.55888p+4 : 0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh towardzero intel96 0x2.55888p+4 : 0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh upward intel96 0x2.55888p+4 : 0x1.d6b0ecda100c254p+52 : inexact-ok ++= sinh downward m68k96 0x2.55888p+4 : 0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh tonearest m68k96 0x2.55888p+4 : 0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh towardzero m68k96 0x2.55888p+4 : 0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh upward m68k96 0x2.55888p+4 : 0x1.d6b0ecda100c254p+52 : inexact-ok ++= sinh downward binary128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed6d8p+52 : inexact-ok ++= sinh tonearest binary128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed6d8p+52 : inexact-ok ++= sinh towardzero binary128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed6d8p+52 : inexact-ok ++= sinh upward binary128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed6d9p+52 : inexact-ok ++= sinh downward ibm128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed68p+52 : inexact-ok ++= sinh tonearest ibm128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed7p+52 : inexact-ok ++= sinh towardzero ibm128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed68p+52 : inexact-ok ++= sinh upward ibm128 0x2.55888p+4 : 0x1.d6b0ecda100c253edb8a451ed7p+52 : inexact-ok ++= sinh downward binary32 0x2.55887cp+4 : 0x1.d6b076p+52 : inexact-ok ++= sinh tonearest binary32 0x2.55887cp+4 : 0x1.d6b078p+52 : inexact-ok ++= sinh towardzero binary32 0x2.55887cp+4 : 0x1.d6b076p+52 : inexact-ok ++= sinh upward binary32 0x2.55887cp+4 : 0x1.d6b078p+52 : inexact-ok ++= sinh downward binary64 0x2.55887cp+4 : 0x1.d6b0772de38b2p+52 : inexact-ok ++= sinh tonearest binary64 0x2.55887cp+4 : 0x1.d6b0772de38b2p+52 : inexact-ok ++= sinh towardzero binary64 0x2.55887cp+4 : 0x1.d6b0772de38b2p+52 : inexact-ok ++= sinh upward binary64 0x2.55887cp+4 : 0x1.d6b0772de38b3p+52 : inexact-ok ++= sinh downward intel96 0x2.55887cp+4 : 0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh tonearest intel96 0x2.55887cp+4 : 0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh towardzero intel96 0x2.55887cp+4 : 0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh upward intel96 0x2.55887cp+4 : 0x1.d6b0772de38b276ap+52 : inexact-ok ++= sinh downward m68k96 0x2.55887cp+4 : 0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh tonearest m68k96 0x2.55887cp+4 : 0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh towardzero m68k96 0x2.55887cp+4 : 0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh upward m68k96 0x2.55887cp+4 : 0x1.d6b0772de38b276ap+52 : inexact-ok ++= sinh downward binary128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c261p+52 : inexact-ok ++= sinh tonearest binary128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c261p+52 : inexact-ok ++= sinh towardzero binary128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c261p+52 : inexact-ok ++= sinh upward binary128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c262p+52 : inexact-ok ++= sinh downward ibm128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c2p+52 : inexact-ok ++= sinh tonearest ibm128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c28p+52 : inexact-ok ++= sinh towardzero ibm128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c2p+52 : inexact-ok ++= sinh upward ibm128 0x2.55887cp+4 : 0x1.d6b0772de38b2768d785fab9c28p+52 : inexact-ok ++= sinh downward binary64 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65p+52 : inexact-ok ++= sinh tonearest binary64 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh towardzero binary64 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65p+52 : inexact-ok ++= sinh upward binary64 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh downward intel96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh tonearest intel96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh towardzero intel96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh upward intel96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh downward m68k96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh tonearest m68k96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh towardzero m68k96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh upward m68k96 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh downward binary128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff289ep+52 : inexact-ok ++= sinh tonearest binary128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff289ep+52 : inexact-ok ++= sinh towardzero binary128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff289ep+52 : inexact-ok ++= sinh upward binary128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff289fp+52 : inexact-ok ++= sinh downward ibm128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff288p+52 : inexact-ok ++= sinh tonearest ibm128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff288p+52 : inexact-ok ++= sinh towardzero ibm128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff288p+52 : inexact-ok ++= sinh upward ibm128 0x2.55887f6da7574p+4 : 0x1.d6b0dc08d1b65fffffffffff29p+52 : inexact-ok ++sinh -0x1.2ac43fb6d3abap+5 ++= sinh downward binary32 -0x2.55887cp+4 : -0x1.d6b078p+52 : inexact-ok ++= sinh tonearest binary32 -0x2.55887cp+4 : -0x1.d6b078p+52 : inexact-ok ++= sinh towardzero binary32 -0x2.55887cp+4 : -0x1.d6b076p+52 : inexact-ok ++= sinh upward binary32 -0x2.55887cp+4 : -0x1.d6b076p+52 : inexact-ok ++= sinh downward binary64 -0x2.55887cp+4 : -0x1.d6b0772de38b3p+52 : inexact-ok ++= sinh tonearest binary64 -0x2.55887cp+4 : -0x1.d6b0772de38b2p+52 : inexact-ok ++= sinh towardzero binary64 -0x2.55887cp+4 : -0x1.d6b0772de38b2p+52 : inexact-ok ++= sinh upward binary64 -0x2.55887cp+4 : -0x1.d6b0772de38b2p+52 : inexact-ok ++= sinh downward intel96 -0x2.55887cp+4 : -0x1.d6b0772de38b276ap+52 : inexact-ok ++= sinh tonearest intel96 -0x2.55887cp+4 : -0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh towardzero intel96 -0x2.55887cp+4 : -0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh upward intel96 -0x2.55887cp+4 : -0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh downward m68k96 -0x2.55887cp+4 : -0x1.d6b0772de38b276ap+52 : inexact-ok ++= sinh tonearest m68k96 -0x2.55887cp+4 : -0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh towardzero m68k96 -0x2.55887cp+4 : -0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh upward m68k96 -0x2.55887cp+4 : -0x1.d6b0772de38b2768p+52 : inexact-ok ++= sinh downward binary128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c262p+52 : inexact-ok ++= sinh tonearest binary128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c261p+52 : inexact-ok ++= sinh towardzero binary128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c261p+52 : inexact-ok ++= sinh upward binary128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c261p+52 : inexact-ok ++= sinh downward ibm128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c28p+52 : inexact-ok ++= sinh tonearest ibm128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c28p+52 : inexact-ok ++= sinh towardzero ibm128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c2p+52 : inexact-ok ++= sinh upward ibm128 -0x2.55887cp+4 : -0x1.d6b0772de38b2768d785fab9c2p+52 : inexact-ok ++= sinh downward binary32 -0x2.55888p+4 : -0x1.d6b0eep+52 : inexact-ok ++= sinh tonearest binary32 -0x2.55888p+4 : -0x1.d6b0ecp+52 : inexact-ok ++= sinh towardzero binary32 -0x2.55888p+4 : -0x1.d6b0ecp+52 : inexact-ok ++= sinh upward binary32 -0x2.55888p+4 : -0x1.d6b0ecp+52 : inexact-ok ++= sinh downward binary64 -0x2.55888p+4 : -0x1.d6b0ecda100c3p+52 : inexact-ok ++= sinh tonearest binary64 -0x2.55888p+4 : -0x1.d6b0ecda100c2p+52 : inexact-ok ++= sinh towardzero binary64 -0x2.55888p+4 : -0x1.d6b0ecda100c2p+52 : inexact-ok ++= sinh upward binary64 -0x2.55888p+4 : -0x1.d6b0ecda100c2p+52 : inexact-ok ++= sinh downward intel96 -0x2.55888p+4 : -0x1.d6b0ecda100c254p+52 : inexact-ok ++= sinh tonearest intel96 -0x2.55888p+4 : -0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh towardzero intel96 -0x2.55888p+4 : -0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh upward intel96 -0x2.55888p+4 : -0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh downward m68k96 -0x2.55888p+4 : -0x1.d6b0ecda100c254p+52 : inexact-ok ++= sinh tonearest m68k96 -0x2.55888p+4 : -0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh towardzero m68k96 -0x2.55888p+4 : -0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh upward m68k96 -0x2.55888p+4 : -0x1.d6b0ecda100c253ep+52 : inexact-ok ++= sinh downward binary128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed6d9p+52 : inexact-ok ++= sinh tonearest binary128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed6d8p+52 : inexact-ok ++= sinh towardzero binary128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed6d8p+52 : inexact-ok ++= sinh upward binary128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed6d8p+52 : inexact-ok ++= sinh downward ibm128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed7p+52 : inexact-ok ++= sinh tonearest ibm128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed7p+52 : inexact-ok ++= sinh towardzero ibm128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed68p+52 : inexact-ok ++= sinh upward ibm128 -0x2.55888p+4 : -0x1.d6b0ecda100c253edb8a451ed68p+52 : inexact-ok ++= sinh downward binary64 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh tonearest binary64 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh towardzero binary64 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65p+52 : inexact-ok ++= sinh upward binary64 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65p+52 : inexact-ok ++= sinh downward intel96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh tonearest intel96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh towardzero intel96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh upward intel96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh downward m68k96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh tonearest m68k96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b66p+52 : inexact-ok ++= sinh towardzero m68k96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh upward m68k96 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65ffep+52 : inexact-ok ++= sinh downward binary128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff289fp+52 : inexact-ok ++= sinh tonearest binary128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff289ep+52 : inexact-ok ++= sinh towardzero binary128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff289ep+52 : inexact-ok ++= sinh upward binary128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff289ep+52 : inexact-ok ++= sinh downward ibm128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff29p+52 : inexact-ok ++= sinh tonearest ibm128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff288p+52 : inexact-ok ++= sinh towardzero ibm128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff288p+52 : inexact-ok ++= sinh upward ibm128 -0x2.55887f6da7574p+4 : -0x1.d6b0dc08d1b65fffffffffff288p+52 : inexact-ok ++sinh 0x1.b7efa91915c95p-2 ++= sinh downward binary32 0x6.dfbea8p-4 : 0x7.1661a8p-4 : inexact-ok ++= sinh tonearest binary32 0x6.dfbea8p-4 : 0x7.1661a8p-4 : inexact-ok ++= sinh towardzero binary32 0x6.dfbea8p-4 : 0x7.1661a8p-4 : inexact-ok ++= sinh upward binary32 0x6.dfbea8p-4 : 0x7.1661bp-4 : inexact-ok ++= sinh downward binary64 0x6.dfbea8p-4 : 0x7.1661abb8260e4p-4 : inexact-ok ++= sinh tonearest binary64 0x6.dfbea8p-4 : 0x7.1661abb8260e8p-4 : inexact-ok ++= sinh towardzero binary64 0x6.dfbea8p-4 : 0x7.1661abb8260e4p-4 : inexact-ok ++= sinh upward binary64 0x6.dfbea8p-4 : 0x7.1661abb8260e8p-4 : inexact-ok ++= sinh downward intel96 0x6.dfbea8p-4 : 0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh tonearest intel96 0x6.dfbea8p-4 : 0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh towardzero intel96 0x6.dfbea8p-4 : 0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh upward intel96 0x6.dfbea8p-4 : 0x7.1661abb8260e76bp-4 : inexact-ok ++= sinh downward m68k96 0x6.dfbea8p-4 : 0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh tonearest m68k96 0x6.dfbea8p-4 : 0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh towardzero m68k96 0x6.dfbea8p-4 : 0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh upward m68k96 0x6.dfbea8p-4 : 0x7.1661abb8260e76bp-4 : inexact-ok ++= sinh downward binary128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ebed4p-4 : inexact-ok ++= sinh tonearest binary128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ebed8p-4 : inexact-ok ++= sinh towardzero binary128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ebed4p-4 : inexact-ok ++= sinh upward binary128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ebed8p-4 : inexact-ok ++= sinh downward ibm128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ebep-4 : inexact-ok ++= sinh tonearest ibm128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ebep-4 : inexact-ok ++= sinh towardzero ibm128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ebep-4 : inexact-ok ++= sinh upward ibm128 0x6.dfbea8p-4 : 0x7.1661abb8260e76a92049555ecp-4 : inexact-ok ++= sinh downward binary32 0x6.dfbeap-4 : 0x7.1661ap-4 : inexact-ok ++= sinh tonearest binary32 0x6.dfbeap-4 : 0x7.1661ap-4 : inexact-ok ++= sinh towardzero binary32 0x6.dfbeap-4 : 0x7.1661ap-4 : inexact-ok ++= sinh upward binary32 0x6.dfbeap-4 : 0x7.1661a8p-4 : inexact-ok ++= sinh downward binary64 0x6.dfbeap-4 : 0x7.1661a2f837414p-4 : inexact-ok ++= sinh tonearest binary64 0x6.dfbeap-4 : 0x7.1661a2f837418p-4 : inexact-ok ++= sinh towardzero binary64 0x6.dfbeap-4 : 0x7.1661a2f837414p-4 : inexact-ok ++= sinh upward binary64 0x6.dfbeap-4 : 0x7.1661a2f837418p-4 : inexact-ok ++= sinh downward intel96 0x6.dfbeap-4 : 0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh tonearest intel96 0x6.dfbeap-4 : 0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh towardzero intel96 0x6.dfbeap-4 : 0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh upward intel96 0x6.dfbeap-4 : 0x7.1661a2f837416e98p-4 : inexact-ok ++= sinh downward m68k96 0x6.dfbeap-4 : 0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh tonearest m68k96 0x6.dfbeap-4 : 0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh towardzero m68k96 0x6.dfbeap-4 : 0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh upward m68k96 0x6.dfbeap-4 : 0x7.1661a2f837416e98p-4 : inexact-ok ++= sinh downward binary128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d4c8p-4 : inexact-ok ++= sinh tonearest binary128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d4c8p-4 : inexact-ok ++= sinh towardzero binary128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d4c8p-4 : inexact-ok ++= sinh upward binary128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d4ccp-4 : inexact-ok ++= sinh downward ibm128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d4p-4 : inexact-ok ++= sinh tonearest ibm128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d4p-4 : inexact-ok ++= sinh towardzero ibm128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d4p-4 : inexact-ok ++= sinh upward ibm128 0x6.dfbeap-4 : 0x7.1661a2f837416e909121ab55d6p-4 : inexact-ok ++= sinh downward binary64 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed208p-4 : inexact-ok ++= sinh tonearest binary64 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh towardzero binary64 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed208p-4 : inexact-ok ++= sinh upward binary64 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh downward intel96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh tonearest intel96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh towardzero intel96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh upward intel96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh downward m68k96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh tonearest m68k96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh towardzero m68k96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh upward m68k96 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh downward binary128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffeb44p-4 : inexact-ok ++= sinh tonearest binary128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffeb48p-4 : inexact-ok ++= sinh towardzero binary128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffeb44p-4 : inexact-ok ++= sinh upward binary128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffeb48p-4 : inexact-ok ++= sinh downward ibm128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffeap-4 : inexact-ok ++= sinh tonearest ibm128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffecp-4 : inexact-ok ++= sinh towardzero ibm128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffeap-4 : inexact-ok ++= sinh upward ibm128 0x6.dfbea46457254p-4 : 0x7.1661a7c5ed20bfffffffffffecp-4 : inexact-ok ++sinh -0x1.b7efa91915c95p-2 ++= sinh downward binary32 -0x6.dfbeap-4 : -0x7.1661a8p-4 : inexact-ok ++= sinh tonearest binary32 -0x6.dfbeap-4 : -0x7.1661ap-4 : inexact-ok ++= sinh towardzero binary32 -0x6.dfbeap-4 : -0x7.1661ap-4 : inexact-ok ++= sinh upward binary32 -0x6.dfbeap-4 : -0x7.1661ap-4 : inexact-ok ++= sinh downward binary64 -0x6.dfbeap-4 : -0x7.1661a2f837418p-4 : inexact-ok ++= sinh tonearest binary64 -0x6.dfbeap-4 : -0x7.1661a2f837418p-4 : inexact-ok ++= sinh towardzero binary64 -0x6.dfbeap-4 : -0x7.1661a2f837414p-4 : inexact-ok ++= sinh upward binary64 -0x6.dfbeap-4 : -0x7.1661a2f837414p-4 : inexact-ok ++= sinh downward intel96 -0x6.dfbeap-4 : -0x7.1661a2f837416e98p-4 : inexact-ok ++= sinh tonearest intel96 -0x6.dfbeap-4 : -0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh towardzero intel96 -0x6.dfbeap-4 : -0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh upward intel96 -0x6.dfbeap-4 : -0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh downward m68k96 -0x6.dfbeap-4 : -0x7.1661a2f837416e98p-4 : inexact-ok ++= sinh tonearest m68k96 -0x6.dfbeap-4 : -0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh towardzero m68k96 -0x6.dfbeap-4 : -0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh upward m68k96 -0x6.dfbeap-4 : -0x7.1661a2f837416e9p-4 : inexact-ok ++= sinh downward binary128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d4ccp-4 : inexact-ok ++= sinh tonearest binary128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d4c8p-4 : inexact-ok ++= sinh towardzero binary128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d4c8p-4 : inexact-ok ++= sinh upward binary128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d4c8p-4 : inexact-ok ++= sinh downward ibm128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d6p-4 : inexact-ok ++= sinh tonearest ibm128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d4p-4 : inexact-ok ++= sinh towardzero ibm128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d4p-4 : inexact-ok ++= sinh upward ibm128 -0x6.dfbeap-4 : -0x7.1661a2f837416e909121ab55d4p-4 : inexact-ok ++= sinh downward binary32 -0x6.dfbea8p-4 : -0x7.1661bp-4 : inexact-ok ++= sinh tonearest binary32 -0x6.dfbea8p-4 : -0x7.1661a8p-4 : inexact-ok ++= sinh towardzero binary32 -0x6.dfbea8p-4 : -0x7.1661a8p-4 : inexact-ok ++= sinh upward binary32 -0x6.dfbea8p-4 : -0x7.1661a8p-4 : inexact-ok ++= sinh downward binary64 -0x6.dfbea8p-4 : -0x7.1661abb8260e8p-4 : inexact-ok ++= sinh tonearest binary64 -0x6.dfbea8p-4 : -0x7.1661abb8260e8p-4 : inexact-ok ++= sinh towardzero binary64 -0x6.dfbea8p-4 : -0x7.1661abb8260e4p-4 : inexact-ok ++= sinh upward binary64 -0x6.dfbea8p-4 : -0x7.1661abb8260e4p-4 : inexact-ok ++= sinh downward intel96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76bp-4 : inexact-ok ++= sinh tonearest intel96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh towardzero intel96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh upward intel96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh downward m68k96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76bp-4 : inexact-ok ++= sinh tonearest m68k96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh towardzero m68k96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh upward m68k96 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a8p-4 : inexact-ok ++= sinh downward binary128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ebed8p-4 : inexact-ok ++= sinh tonearest binary128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ebed8p-4 : inexact-ok ++= sinh towardzero binary128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ebed4p-4 : inexact-ok ++= sinh upward binary128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ebed4p-4 : inexact-ok ++= sinh downward ibm128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ecp-4 : inexact-ok ++= sinh tonearest ibm128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ebep-4 : inexact-ok ++= sinh towardzero ibm128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ebep-4 : inexact-ok ++= sinh upward ibm128 -0x6.dfbea8p-4 : -0x7.1661abb8260e76a92049555ebep-4 : inexact-ok ++= sinh downward binary64 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh tonearest binary64 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh towardzero binary64 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed208p-4 : inexact-ok ++= sinh upward binary64 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed208p-4 : inexact-ok ++= sinh downward intel96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh tonearest intel96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh towardzero intel96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh upward intel96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh downward m68k96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh tonearest m68k96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20cp-4 : inexact-ok ++= sinh towardzero m68k96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh upward m68k96 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bff8p-4 : inexact-ok ++= sinh downward binary128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffeb48p-4 : inexact-ok ++= sinh tonearest binary128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffeb48p-4 : inexact-ok ++= sinh towardzero binary128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffeb44p-4 : inexact-ok ++= sinh upward binary128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffeb44p-4 : inexact-ok ++= sinh downward ibm128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffecp-4 : inexact-ok ++= sinh tonearest ibm128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffecp-4 : inexact-ok ++= sinh towardzero ibm128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffeap-4 : inexact-ok ++= sinh upward ibm128 -0x6.dfbea46457254p-4 : -0x7.1661a7c5ed20bfffffffffffeap-4 : inexact-ok ++sinh 0x1.92a5c27afbe82p+4 ++= sinh downward binary32 0x1.92a5c4p+4 : 0x9.e410bp+32 : inexact-ok ++= sinh tonearest binary32 0x1.92a5c4p+4 : 0x9.e410cp+32 : inexact-ok ++= sinh towardzero binary32 0x1.92a5c4p+4 : 0x9.e410bp+32 : inexact-ok ++= sinh upward binary32 0x1.92a5c4p+4 : 0x9.e410cp+32 : inexact-ok ++= sinh downward binary64 0x1.92a5c4p+4 : 0x9.e410bd8d8c85p+32 : inexact-ok ++= sinh tonearest binary64 0x1.92a5c4p+4 : 0x9.e410bd8d8c85p+32 : inexact-ok ++= sinh towardzero binary64 0x1.92a5c4p+4 : 0x9.e410bd8d8c85p+32 : inexact-ok ++= sinh upward binary64 0x1.92a5c4p+4 : 0x9.e410bd8d8c858p+32 : inexact-ok ++= sinh downward intel96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh tonearest intel96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh towardzero intel96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh upward intel96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh downward m68k96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh tonearest m68k96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh towardzero m68k96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh upward m68k96 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh downward binary128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60e85p+32 : inexact-ok ++= sinh tonearest binary128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60e858p+32 : inexact-ok ++= sinh towardzero binary128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60e85p+32 : inexact-ok ++= sinh upward binary128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60e858p+32 : inexact-ok ++= sinh downward ibm128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60e8p+32 : inexact-ok ++= sinh tonearest ibm128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60e8p+32 : inexact-ok ++= sinh towardzero ibm128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60e8p+32 : inexact-ok ++= sinh upward ibm128 0x1.92a5c4p+4 : 0x9.e410bd8d8c8507a830e34d60ecp+32 : inexact-ok ++= sinh downward binary32 0x1.92a5c2p+4 : 0x9.e40f8p+32 : inexact-ok ++= sinh tonearest binary32 0x1.92a5c2p+4 : 0x9.e40f8p+32 : inexact-ok ++= sinh towardzero binary32 0x1.92a5c2p+4 : 0x9.e40f8p+32 : inexact-ok ++= sinh upward binary32 0x1.92a5c2p+4 : 0x9.e40f9p+32 : inexact-ok ++= sinh downward binary64 0x1.92a5c2p+4 : 0x9.e40f810b889bp+32 : inexact-ok ++= sinh tonearest binary64 0x1.92a5c2p+4 : 0x9.e40f810b889b8p+32 : inexact-ok ++= sinh towardzero binary64 0x1.92a5c2p+4 : 0x9.e40f810b889bp+32 : inexact-ok ++= sinh upward binary64 0x1.92a5c2p+4 : 0x9.e40f810b889b8p+32 : inexact-ok ++= sinh downward intel96 0x1.92a5c2p+4 : 0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh tonearest intel96 0x1.92a5c2p+4 : 0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh towardzero intel96 0x1.92a5c2p+4 : 0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh upward intel96 0x1.92a5c2p+4 : 0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh downward m68k96 0x1.92a5c2p+4 : 0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh tonearest m68k96 0x1.92a5c2p+4 : 0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh towardzero m68k96 0x1.92a5c2p+4 : 0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh upward m68k96 0x1.92a5c2p+4 : 0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh downward binary128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa46p+32 : inexact-ok ++= sinh tonearest binary128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa46p+32 : inexact-ok ++= sinh towardzero binary128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa46p+32 : inexact-ok ++= sinh upward binary128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa468p+32 : inexact-ok ++= sinh downward ibm128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa4p+32 : inexact-ok ++= sinh tonearest ibm128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa4p+32 : inexact-ok ++= sinh towardzero ibm128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa4p+32 : inexact-ok ++= sinh upward ibm128 0x1.92a5c2p+4 : 0x9.e40f810b889b76bfa9a8c69fa8p+32 : inexact-ok ++= sinh downward binary64 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh tonearest binary64 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh towardzero binary64 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh upward binary64 0x1.92a5c27afbe82p+4 : 0x9.e40fcd12392ap+32 : inexact-ok ++= sinh downward intel96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh tonearest intel96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh towardzero intel96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh upward intel96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd123929801p+32 : inexact-ok ++= sinh downward m68k96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh tonearest m68k96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh towardzero m68k96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298p+32 : inexact-ok ++= sinh upward m68k96 0x1.92a5c27afbe82p+4 : 0x9.e40fcd123929801p+32 : inexact-ok ++= sinh downward binary128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298000000000002118p+32 : inexact-ok ++= sinh tonearest binary128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd123929800000000000212p+32 : inexact-ok ++= sinh towardzero binary128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298000000000002118p+32 : inexact-ok ++= sinh upward binary128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd123929800000000000212p+32 : inexact-ok ++= sinh downward ibm128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298000000000002p+32 : inexact-ok ++= sinh tonearest ibm128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298000000000002p+32 : inexact-ok ++= sinh towardzero ibm128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd1239298000000000002p+32 : inexact-ok ++= sinh upward ibm128 0x1.92a5c27afbe82p+4 : 0x9.e40fcd12392980000000000024p+32 : inexact-ok ++sinh -0x1.92a5c27afbe82p+4 ++= sinh downward binary32 -0x1.92a5c2p+4 : -0x9.e40f9p+32 : inexact-ok ++= sinh tonearest binary32 -0x1.92a5c2p+4 : -0x9.e40f8p+32 : inexact-ok ++= sinh towardzero binary32 -0x1.92a5c2p+4 : -0x9.e40f8p+32 : inexact-ok ++= sinh upward binary32 -0x1.92a5c2p+4 : -0x9.e40f8p+32 : inexact-ok ++= sinh downward binary64 -0x1.92a5c2p+4 : -0x9.e40f810b889b8p+32 : inexact-ok ++= sinh tonearest binary64 -0x1.92a5c2p+4 : -0x9.e40f810b889b8p+32 : inexact-ok ++= sinh towardzero binary64 -0x1.92a5c2p+4 : -0x9.e40f810b889bp+32 : inexact-ok ++= sinh upward binary64 -0x1.92a5c2p+4 : -0x9.e40f810b889bp+32 : inexact-ok ++= sinh downward intel96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh tonearest intel96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh towardzero intel96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh upward intel96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh downward m68k96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh tonearest m68k96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76cp+32 : inexact-ok ++= sinh towardzero m68k96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh upward m68k96 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bp+32 : inexact-ok ++= sinh downward binary128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa468p+32 : inexact-ok ++= sinh tonearest binary128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa46p+32 : inexact-ok ++= sinh towardzero binary128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa46p+32 : inexact-ok ++= sinh upward binary128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa46p+32 : inexact-ok ++= sinh downward ibm128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa8p+32 : inexact-ok ++= sinh tonearest ibm128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa4p+32 : inexact-ok ++= sinh towardzero ibm128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa4p+32 : inexact-ok ++= sinh upward ibm128 -0x1.92a5c2p+4 : -0x9.e40f810b889b76bfa9a8c69fa4p+32 : inexact-ok ++= sinh downward binary32 -0x1.92a5c4p+4 : -0x9.e410cp+32 : inexact-ok ++= sinh tonearest binary32 -0x1.92a5c4p+4 : -0x9.e410cp+32 : inexact-ok ++= sinh towardzero binary32 -0x1.92a5c4p+4 : -0x9.e410bp+32 : inexact-ok ++= sinh upward binary32 -0x1.92a5c4p+4 : -0x9.e410bp+32 : inexact-ok ++= sinh downward binary64 -0x1.92a5c4p+4 : -0x9.e410bd8d8c858p+32 : inexact-ok ++= sinh tonearest binary64 -0x1.92a5c4p+4 : -0x9.e410bd8d8c85p+32 : inexact-ok ++= sinh towardzero binary64 -0x1.92a5c4p+4 : -0x9.e410bd8d8c85p+32 : inexact-ok ++= sinh upward binary64 -0x1.92a5c4p+4 : -0x9.e410bd8d8c85p+32 : inexact-ok ++= sinh downward intel96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh tonearest intel96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh towardzero intel96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh upward intel96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh downward m68k96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh tonearest m68k96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507bp+32 : inexact-ok ++= sinh towardzero m68k96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh upward m68k96 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507ap+32 : inexact-ok ++= sinh downward binary128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60e858p+32 : inexact-ok ++= sinh tonearest binary128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60e858p+32 : inexact-ok ++= sinh towardzero binary128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60e85p+32 : inexact-ok ++= sinh upward binary128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60e85p+32 : inexact-ok ++= sinh downward ibm128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60ecp+32 : inexact-ok ++= sinh tonearest ibm128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60e8p+32 : inexact-ok ++= sinh towardzero ibm128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60e8p+32 : inexact-ok ++= sinh upward ibm128 -0x1.92a5c4p+4 : -0x9.e410bd8d8c8507a830e34d60e8p+32 : inexact-ok ++= sinh downward binary64 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd12392ap+32 : inexact-ok ++= sinh tonearest binary64 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh towardzero binary64 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh upward binary64 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh downward intel96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd123929801p+32 : inexact-ok ++= sinh tonearest intel96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh towardzero intel96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh upward intel96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh downward m68k96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd123929801p+32 : inexact-ok ++= sinh tonearest m68k96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh towardzero m68k96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh upward m68k96 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298p+32 : inexact-ok ++= sinh downward binary128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd123929800000000000212p+32 : inexact-ok ++= sinh tonearest binary128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd123929800000000000212p+32 : inexact-ok ++= sinh towardzero binary128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298000000000002118p+32 : inexact-ok ++= sinh upward binary128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298000000000002118p+32 : inexact-ok ++= sinh downward ibm128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd12392980000000000024p+32 : inexact-ok ++= sinh tonearest ibm128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298000000000002p+32 : inexact-ok ++= sinh towardzero ibm128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298000000000002p+32 : inexact-ok ++= sinh upward ibm128 -0x1.92a5c27afbe82p+4 : -0x9.e40fcd1239298000000000002p+32 : inexact-ok +diff --git a/sysdeps/ieee754/dbl-64/e_sinh.c b/sysdeps/ieee754/dbl-64/e_sinh.c +index 1643f3f504..638e3d6a6d 100644 +--- a/sysdeps/ieee754/dbl-64/e_sinh.c ++++ b/sysdeps/ieee754/dbl-64/e_sinh.c +@@ -213,7 +213,7 @@ __sinh (double x) + ml = (ul + 8) & MANTISSA_MASK; + th += tl; + th *= 2; +- th *= asuint64 (sp); ++ th *= sp; + if (ml <= 16 || eh - el > 103) + return as_sinh_database (x, th); + return th; +diff --git a/sysdeps/ieee754/dbl-64/e_sinh_data.c b/sysdeps/ieee754/dbl-64/e_sinh_data.c +index ca61e311f1..d4fd41d934 100644 +--- a/sysdeps/ieee754/dbl-64/e_sinh_data.c ++++ b/sysdeps/ieee754/dbl-64/e_sinh_data.c +@@ -35,12 +35,13 @@ const double __sinh_data_ch[][2] = + { 0x1.ae64567f54482p-26, -0x1.defcf17a6ab79p-81 } + }; + +-const double __sinh_data_db[49][3] = ++const double __sinh_data_db[51][3] = + { + { 0x1.364303e1ad8f6p-2, 0x1.3b07e0c779ddap-2, -0x1.bcp-106 }, + { 0x1.4169f234f23b9p-2, 0x1.46b7b3b358f99p-2, -0x1p-56 }, + { 0x1.616cc75d49226p-2, 0x1.687bd068c1c1ep-2, 0x1.ap-111 }, + { 0x1.ae3773250e7d2p-2, 0x1.bafc3479fc9ccp-2, -0x1p-105 }, ++ { 0x1.b7efa91915c95p-2, 0x1.c59869f17b483p-2, -0x1p-104 }, + { 0x1.d68039861ab53p-2, 0x1.e73b46abb01e1p-2, -0x1.2p-109 }, + { 0x1.e90f16eb88c09p-2, 0x1.fbdd4a37760b7p-2, -0x1.f8p-108 }, + { 0x1.a3fc7e4dd47d1p-1, 0x1.d4b21ebf542fp-1, 0x1.ep-107 }, +@@ -62,6 +63,7 @@ const double __sinh_data_db[49][3] = + { 0x1.43a81752eabe7p+3, 0x1.81d364845ecfap+13, -0x1p-90 }, + { 0x1.16369cd53bb69p+4, 0x1.0fbc6c02b1c9p+24, -0x1.9p-81 }, + { 0x1.20e29ea8b51e2p+4, 0x1.08b8abba28abcp+25, 0x1.9bp-79 }, ++ { 0x1.92a5c27afbe82p+4, 0x1.3c81f9a247253p+35, 0x1p-67 }, + { 0x1.a1e4f11b513d7p+4, 0x1.9a65b6c2e2185p+36, -0x1.bcp-70 }, + { 0x1.c089fcf166171p+4, 0x1.5c452e0e37569p+39, 0x1.4p-69 }, + { 0x1.e42a98b3a0be5p+4, 0x1.938768ca4f8aap+42, 0x1.6dp-62 }, +diff --git a/sysdeps/ieee754/dbl-64/e_sinh_data.h b/sysdeps/ieee754/dbl-64/e_sinh_data.h +index 16f7e0da5a..c34848fd54 100644 +--- a/sysdeps/ieee754/dbl-64/e_sinh_data.h ++++ b/sysdeps/ieee754/dbl-64/e_sinh_data.h +@@ -29,7 +29,7 @@ SOFTWARE. + + extern const double __sinh_data_ch[][2] attribute_hidden; + #define CH __sinh_data_ch +-extern const double __sinh_data_db[49][3] attribute_hidden; ++extern const double __sinh_data_db[51][3] attribute_hidden; + #define DB __sinh_data_db + + #endif + +commit 0b58f5d80d24cf83cfde9d8381aafb11fef0e152 +Author: Adhemerval Zanella +Date: Thu Jul 30 08:55:54 2026 -0300 + + math: Fix x86_64 tanh _FloatN aliases binding to the FMA variant [BZ 34465] + + The generic implementation emits libm_alias_double unconditionally, so + tanhf32x and tanhf64 bind directly to __tanh_fma. + + Guard the alias with '#ifndef __tanh' and emit it from the dispatcher, + as sin. Also remove the stale __expm1 defines, unused since tanh moved + to CORE-MATH. + + Checked on x86_64-linux-gnu, and with 'qemu-x86_64 -cpu Nehalem'. + + Reported-by: Michael Brunnbauer + + (cherry picked from commit b01abba04a954cbd6b2834c0643a08685a915fe5) + +diff --git a/NEWS b/NEWS +index fe2b1d7f79..43667c1963 100644 +--- a/NEWS ++++ b/NEWS +@@ -11,6 +11,7 @@ The following bugs are resolved with this release: + + [34441] math: math: sinh() returns wrong results for some inputs with + |x| > 36.736801 ++ [34465] math: math: x86_64 tanh ifunc selection wrong + + Version 2.44 + +diff --git a/sysdeps/ieee754/dbl-64/s_tanh.c b/sysdeps/ieee754/dbl-64/s_tanh.c +index 2029de8fa5..ef80b9edb6 100644 +--- a/sysdeps/ieee754/dbl-64/s_tanh.c ++++ b/sysdeps/ieee754/dbl-64/s_tanh.c +@@ -283,4 +283,6 @@ __tanh (double x) + return as_tanh_database (x, res); + return res; + } ++#ifndef __tanh + libm_alias_double (__tanh, tanh) ++#endif +diff --git a/sysdeps/x86_64/fpu/multiarch/s_tanh-fma.c b/sysdeps/x86_64/fpu/multiarch/s_tanh-fma.c +index 1b808b1227..1e6b33740a 100644 +--- a/sysdeps/x86_64/fpu/multiarch/s_tanh-fma.c ++++ b/sysdeps/x86_64/fpu/multiarch/s_tanh-fma.c +@@ -1,10 +1,4 @@ + #define __tanh __tanh_fma +-#define __expm1 __expm1_fma +- +-/* NB: __expm1 may be expanded to __expm1_fma in the following +- prototypes. */ +-extern long double __expm1l (long double); +-extern long double __expm1f128 (long double); + + #define SECTION __attribute__ ((section (".text.fma"))) + +diff --git a/sysdeps/x86_64/fpu/multiarch/s_tanh.c b/sysdeps/x86_64/fpu/multiarch/s_tanh.c +index ec8826f634..9048c977c1 100644 +--- a/sysdeps/x86_64/fpu/multiarch/s_tanh.c ++++ b/sysdeps/x86_64/fpu/multiarch/s_tanh.c +@@ -25,10 +25,9 @@ extern double __redirect_tanh (double); + # define SYMBOL_NAME tanh + # include "ifunc-fma.h" + +-libc_ifunc_redirected (__redirect_tanh, tanh, IFUNC_SELECTOR ()); ++libc_ifunc_redirected (__redirect_tanh, __tanh, IFUNC_SELECTOR ()); ++libm_alias_double (__tanh, tanh) + + # define __tanh __tanh_sse2 +-# undef libm_alias_double +-# define libm_alias_double(a, b) + #endif + #include + +commit 9bcb85688e58847191deb42bfc68d60802078df4 +Author: Xi Ruoyao +Date: Wed Jul 22 19:26:10 2026 +0800 + + io: fix ftw ABI on MIPS n64 + + On MIPS n64 off_t is same as off64_t, but struct stat is not same as + struct stat64 (very peculiar but see the "as tempting as it..." comment + in linux/mips/kernel_stat.h). As the ftw/ftw64 callback accepts a + pointer to a function who accepts struct stat/stat64, for MIPS n64 we + must use different implementations for ftw and ftw64. + + Thus for testing if ftw64 can be aliased to ftw, we should check + XSTAT_IS_XSTAT64 instead of __OFF_T_MATCHES_OFF64_T. + + This resolves the io/tst-ftw-lnk failure observed on MIPS n64. + + Link: https://sourceware.org/glibc/wiki/Testing/Tests/io/tst-ftw-lnk + Signed-off-by: Xi Ruoyao + Reviewed-by: Adhemerval Zanella + + (cherry picked from commit 6758def717175e679cb49b5051b6b5ec54ddfb2c) + +diff --git a/io/ftw.c b/io/ftw.c +index ed0eeb3904..a9368a706e 100644 +--- a/io/ftw.c ++++ b/io/ftw.c +@@ -18,7 +18,9 @@ + + #include + +-#ifndef __OFF_T_MATCHES_OFF64_T ++#include ++ ++#if !XSTAT_IS_XSTAT64 + # include "ftw-common.c" + + versioned_symbol (libc, __new_nftw, nftw, GLIBC_2_3_3); +diff --git a/io/ftw64.c b/io/ftw64.c +index d3cd14c21a..fa7b05df22 100644 +--- a/io/ftw64.c ++++ b/io/ftw64.c +@@ -31,6 +31,9 @@ + #define ftw __rename_ftw + #define nftw __rename_nftw + ++#include ++ ++#include + #include + #include "ftw-common.c" + +@@ -44,7 +47,7 @@ versioned_symbol (libc, __new_nftw64, nftw64, GLIBC_2_3_3); + compat_symbol (libc, __old_nftw64, nftw64, GLIBC_2_1); + #endif + +-#ifdef __OFF_T_MATCHES_OFF64_T ++#if XSTAT_IS_XSTAT64 + weak_alias (__ftw64, ftw) + versioned_symbol (libc, __new_nftw64, nftw, GLIBC_2_3_3); + # if SHLIB_COMPAT(libc, GLIBC_2_1, GLIBC_2_3_3) + +commit 58da792d8a2d8f2fe711318836e853fcddfd7cd8 +Author: Adhemerval Zanella +Date: Tue Aug 4 14:25:48 2026 +0000 + + hurd: Fix build after the ftw kernel_stat.h inclusion + + Commit 6758def7171 changed the generic ftw{64}.c to include + kernel_stat.h, which is Linux specific. + + Add a Hurd version of kernel_stat.h defining XSTAT_IS_XSTAT64 to 0, + since struct stat and struct stat64 never share a layout on Hurd: on + 32-bit ABIs st_ino, st_size, and st_blocks are narrower in struct stat, + and on 64-bit ABIs the two structures still differ in size because + _SPARE_SIZE in bits/stat.h reserves three more ints of spare space in + struct stat than in struct stat64. + + This keeps the ftw/ftw64 symbols exactly as before the change, where + the aliasing check on __OFF_T_MATCHES_OFF64_T was always false because + the Hurd bits/typesizes.h does not define it. + + Checked with a full build for i686-gnu and x86_64-gnu. + + (cherry picked from commit d6031665c3a59faf75cf6bc55e041611da21d0e6) + +diff --git a/sysdeps/mach/hurd/kernel_stat.h b/sysdeps/mach/hurd/kernel_stat.h +new file mode 100644 +index 0000000000..aa8c26b1d9 +--- /dev/null ++++ b/sysdeps/mach/hurd/kernel_stat.h +@@ -0,0 +1,23 @@ ++/* Internal definitions for stat functions. Hurd version. ++ Copyright (C) 2026 Free Software Foundation, Inc. ++ This file is part of the GNU C Library. ++ ++ The GNU C Library is free software; you can redistribute it and/or ++ modify it under the terms of the GNU Lesser General Public ++ License as published by the Free Software Foundation; either ++ version 2.1 of the License, or (at your option) any later version. ++ ++ The GNU C Library is distributed in the hope that it will be useful, ++ but WITHOUT ANY WARRANTY; without even the implied warranty of ++ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU ++ Lesser General Public License for more details. ++ ++ You should have received a copy of the GNU Lesser General Public ++ License along with the GNU C Library; if not, see ++ . */ ++ ++/* struct stat and struct stat64 never have the same layout: on 32-bit ++ ABIs st_ino, st_size, and st_blocks are narrower in struct stat, and ++ on 64-bit ABIs the two structures still differ in the amount of ++ trailing spare space (see _SPARE_SIZE in bits/stat.h). */ ++#define XSTAT_IS_XSTAT64 0 + +commit fec2a9c6765b548f9d738e3a1c63a63ad7061d40 +Author: Adhemerval Zanella +Date: Fri Mar 21 14:03:00 2025 +0000 + + linux: Inline syscall cancellation to keep wrapper frames observable (BZ 34338) + + The cancellable syscall wrappers end with a tail call to __syscall_cancel, + the wrapper frame is then elided, so when the syscall executes the wrapper + is no longer present on the stack. Tools that unwind from CFI alone, such + as valgrind, perf and sampling profilers, cannot observe it. On gdb, it + only recovers it from DWARF call site information, which reduced-debuginfo + libc builds usually omit. + + The behaviour is target dependent: for a shared (PIC) the tail call is + emitted on aarch64, arc, loongarch and riscv. It is not emitted on i386, + x86_64, arm, s390x, sparc and alpha, where the seventh argument is passed + on the stack or fewer argument registers are available, nor on powerpc + and mips, where the TOC/GOT pointer must be restored after the call. + This is why the problem was originally reported as aarch64 specific while + x86_64 was unaffected. + + Rather than only inhibiting the tail call [1] (which keeps the wrapper frame + but still leaves the __syscall_cancel and __internal_syscall_cancel + frames), move the cancellation logic back into the wrappers. In the + single-threaded case the syscall is now issued directly from the wrapper; + only the multi-threaded path still calls the out-of-line __syscall_cancel_arch. + + This keeps the wrapper observable and removes the extra frames, mimicking + how cancellation was handled before 89b53077d2a58f00e7debdfe58afabe953dac60d. + + The result is a small libc.so .text increase (size, first column): + + ABI master patched diff increase + aarch64 1635880 1647424 11544 0.71% + x86_64 1981081 1992257 11176 0.56% + powerpc64le 2364336 2376964 12628 0.53% + riscv64 1368386 1376704 8318 0.61% + loongarch64 1741385 1755601 14216 0.82% + + The tst-backtrace5 was suppose to track this issue, but due wrong + loop variable check it does not take this in account. This patch also fixes + it. + + Checked on aarch64-linux-gnu, x86_64-linux-gnu, i686-linux-gnu, + arm-linux-gnueabihf, and powerpc64le-linux-gnu. + + [1] https://sourceware.org/pipermail/libc-alpha/2025-March/165395.html + + (cherry picked from commit 1b5ff009fa5bf01ad26e6cc330a1df5a0c84135e) + +diff --git a/NEWS b/NEWS +index 43667c1963..28fbd9bcd8 100644 +--- a/NEWS ++++ b/NEWS +@@ -9,6 +9,8 @@ Version 2.44.1 + + The following bugs are resolved with this release: + ++ [34338] libc: Cancellable syscall wrappers are missing from backtraces ++ because they tail-call __syscall_cancel + [34441] math: math: sinh() returns wrong results for some inputs with + |x| > 36.736801 + [34465] math: math: x86_64 tanh ifunc selection wrong +diff --git a/debug/tst-backtrace5.c b/debug/tst-backtrace5.c +index 4c5784c060..6538da9ab5 100644 +--- a/debug/tst-backtrace5.c ++++ b/debug/tst-backtrace5.c +@@ -36,10 +36,15 @@ + trampoline, read, 3 * fn, and do_test. */ + #define NUM_FUNCTIONS 7 + ++/* Avoid the read wrapper frame truncation on targets that add extra frames ++ between it and handle_signal (the cancellable syscall wrappers ++ __syscall_cancel*, or the i686 __kernel_vsyscall entry). */ ++#define MAX_FUNCTIONS 64 ++ + void + handle_signal (int signum) + { +- void *addresses[NUM_FUNCTIONS]; ++ void *addresses[MAX_FUNCTIONS]; + char **symbols; + int n; + int i; +@@ -70,23 +75,28 @@ handle_signal (int signum) + return; + } + +- /* Do not check name for signal trampoline or cancellable syscall +- wrappers (__syscall_cancel*). */ +- for (; i < n - 1; i++) ++ /* Skip the signal trampoline and any cancellable syscall wrapper frames ++ (__syscall_cancel*) and require the read syscall wrapper to be ++ present. */ ++ for (i = 1; i < n; i++) + if (match (symbols[i], "read")) + break; +- if (i == n - 1) ++ if (i == n) + { + FAIL (); + return; + } + +- for (; i < n - 1; i++) +- if (!match (symbols[i], "fn")) +- { +- FAIL (); +- return; +- } ++ /* The read wrapper must be followed by the three fn recursion frames. */ ++ for (int j = 0; j < 3; j++) ++ { ++ i++; ++ if (i == n || !match (symbols[i], "fn")) ++ { ++ FAIL (); ++ return; ++ } ++ } + /* Symbol names are not available for static functions, so we do not + check do_test. */ + +diff --git a/elf/Makefile b/elf/Makefile +index 94c5b7e6ed..8b063e1bba 100644 +--- a/elf/Makefile ++++ b/elf/Makefile +@@ -1574,7 +1574,9 @@ $(objpfx)dl-allobjs.os: $(all-rtld-routines:%=$(objpfx)%.os) + # when compiled for libc. + rtld-stubbed-symbols = \ + __libc_assert_fail \ +- __syscall_cancel \ ++ __libc_single_threaded_internal \ ++ __syscall_cancel_arch \ ++ __syscall_do_cancel \ + calloc \ + free \ + malloc \ +diff --git a/nptl/cancellation.c b/nptl/cancellation.c +index 4368cb7231..63f09840ff 100644 +--- a/nptl/cancellation.c ++++ b/nptl/cancellation.c +@@ -19,66 +19,6 @@ + #include + #include "pthreadP.h" + +-/* Called by the INTERNAL_SYSCALL_CANCEL macro, check for cancellation and +- returns the syscall value or its negative error code. */ +-long int +-__internal_syscall_cancel (__syscall_arg_t a1, __syscall_arg_t a2, +- __syscall_arg_t a3, __syscall_arg_t a4, +- __syscall_arg_t a5, __syscall_arg_t a6, +- __SYSCALL_CANCEL7_ARG_DEF +- __syscall_arg_t nr) +-{ +- long int result; +- struct pthread *pd = THREAD_SELF; +- +- /* If cancellation is not enabled, call the syscall directly and also +- for thread terminatation to avoid call __syscall_do_cancel while +- executing cleanup handlers. */ +- int ch = atomic_load_relaxed (&pd->cancelhandling); +- if (SINGLE_THREAD_P || !cancel_enabled (ch) || cancel_exiting (ch)) +- { +- result = INTERNAL_SYSCALL_NCS_CALL (nr, a1, a2, a3, a4, a5, a6 +- __SYSCALL_CANCEL7_ARCH_ARG7); +- if (INTERNAL_SYSCALL_ERROR_P (result)) +- return -INTERNAL_SYSCALL_ERRNO (result); +- return result; +- } +- +- /* Call the arch-specific entry points that contains the globals markers +- to be checked by SIGCANCEL handler. */ +- result = __syscall_cancel_arch (&pd->cancelhandling, nr, a1, a2, a3, a4, a5, +- a6 __SYSCALL_CANCEL7_ARCH_ARG7); +- +- /* If the cancellable syscall was interrupted by SIGCANCEL and it has no +- side-effect, cancel the thread if cancellation is enabled. */ +- ch = atomic_load_relaxed (&pd->cancelhandling); +- /* The behaviour here assumes that EINTR is returned only if there are no +- visible side effects. POSIX Issue 7 has not yet provided any stronger +- language for close, and in theory the close syscall could return EINTR +- and leave the file descriptor open (conforming and leaks). It expects +- that no such kernel is used with glibc. */ +- if (result == -EINTR && cancel_enabled_and_canceled (ch)) +- __syscall_do_cancel (); +- +- return result; +-} +- +-/* Called by the SYSCALL_CANCEL macro, check for cancellation and return the +- syscall expected success value (usually 0) or, in case of failure, -1 and +- sets errno to syscall return value. */ +-long int +-__syscall_cancel (__syscall_arg_t a1, __syscall_arg_t a2, +- __syscall_arg_t a3, __syscall_arg_t a4, +- __syscall_arg_t a5, __syscall_arg_t a6, +- __SYSCALL_CANCEL7_ARG_DEF __syscall_arg_t nr) +-{ +- long int r = __internal_syscall_cancel (a1, a2, a3, a4, a5, a6, +- __SYSCALL_CANCEL7_ARG nr); +- return __glibc_unlikely (INTERNAL_SYSCALL_ERROR_P (r)) +- ? SYSCALL_ERROR_LABEL (INTERNAL_SYSCALL_ERRNO (r)) +- : r; +-} +- + /* Called by __syscall_cancel_arch or function above start the thread + cancellation. */ + _Noreturn void +diff --git a/nptl/futex-internal.c b/nptl/futex-internal.c +index fc6b11c8ad..07f1462abe 100644 +--- a/nptl/futex-internal.c ++++ b/nptl/futex-internal.c +@@ -17,7 +17,7 @@ + . */ + + #include +-#include ++#include + #include + #include + #include +diff --git a/nptl/sem_waitcommon.c b/nptl/sem_waitcommon.c +index b0cbe5cebf..82c686f020 100644 +--- a/nptl/sem_waitcommon.c ++++ b/nptl/sem_waitcommon.c +@@ -18,7 +18,7 @@ + + #include + #include +-#include ++#include + #include + #include + #include +diff --git a/sysdeps/unix/sysdep.h b/sysdeps/unix/sysdep.h +index a6ce5348ec..f0f271ec02 100644 +--- a/sysdeps/unix/sysdep.h ++++ b/sysdeps/unix/sysdep.h +@@ -154,42 +154,31 @@ + # define __SYSCALL_CANCEL7_ARG7 + # define __SYSCALL_CANCEL7_ARCH_ARG7 + #endif +-long int __internal_syscall_cancel (__syscall_arg_t a1, __syscall_arg_t a2, +- __syscall_arg_t a3, __syscall_arg_t a4, +- __syscall_arg_t a5, __syscall_arg_t a6, +- __SYSCALL_CANCEL7_ARG_DEF +- __syscall_arg_t nr) attribute_hidden; +- +-long int __syscall_cancel (__syscall_arg_t arg1, __syscall_arg_t arg2, +- __syscall_arg_t arg3, __syscall_arg_t arg4, +- __syscall_arg_t arg5, __syscall_arg_t arg6, +- __SYSCALL_CANCEL7_ARG_DEF +- __syscall_arg_t nr) attribute_hidden; + + #define __SYSCALL_CANCEL0(name) \ +- __syscall_cancel (0, 0, 0, 0, 0, 0, __SYSCALL_CANCEL7_ARG __NR_##name) ++ syscall_cancel (0, 0, 0, 0, 0, 0, __SYSCALL_CANCEL7_ARG __NR_##name) + #define __SYSCALL_CANCEL1(name, a1) \ +- __syscall_cancel (__SSC (a1), 0, 0, 0, 0, 0, \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ syscall_cancel (__SSC (a1), 0, 0, 0, 0, 0, \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __SYSCALL_CANCEL2(name, a1, a2) \ +- __syscall_cancel (__SSC (a1), __SSC (a2), 0, 0, 0, 0, \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ syscall_cancel (__SSC (a1), __SSC (a2), 0, 0, 0, 0, \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __SYSCALL_CANCEL3(name, a1, a2, a3) \ +- __syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), 0, 0, 0, \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), 0, 0, 0, \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __SYSCALL_CANCEL4(name, a1, a2, a3, a4) \ +- __syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ +- __SSC(a4), 0, 0, __SYSCALL_CANCEL7_ARG __NR_##name) ++ syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ ++ __SSC(a4), 0, 0, __SYSCALL_CANCEL7_ARG __NR_##name) + #define __SYSCALL_CANCEL5(name, a1, a2, a3, a4, a5) \ +- __syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), __SSC(a4), \ +- __SSC (a5), 0, __SYSCALL_CANCEL7_ARG __NR_##name) ++ syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), __SSC(a4), \ ++ __SSC (a5), 0, __SYSCALL_CANCEL7_ARG __NR_##name) + #define __SYSCALL_CANCEL6(name, a1, a2, a3, a4, a5, a6) \ +- __syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), __SSC (a4), \ +- __SSC (a5), __SSC (a6), __SYSCALL_CANCEL7_ARG \ +- __NR_##name) ++ syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), __SSC (a4), \ ++ __SSC (a5), __SSC (a6), __SYSCALL_CANCEL7_ARG \ ++ __NR_##name) + #define __SYSCALL_CANCEL7(name, a1, a2, a3, a4, a5, a6, a7) \ +- __syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), __SSC (a4), \ +- __SSC (a5), __SSC (a6), __SSC (a7), __NR_##name) ++ syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), __SSC (a4), \ ++ __SSC (a5), __SSC (a6), __SSC (a7), __NR_##name) + + #define __SYSCALL_CANCEL_NARGS_X(a,b,c,d,e,f,g,h,n,...) n + #define __SYSCALL_CANCEL_NARGS(...) \ +@@ -206,33 +195,33 @@ long int __syscall_cancel (__syscall_arg_t arg1, __syscall_arg_t arg2, + __SYSCALL_CANCEL_DISP (__SYSCALL_CANCEL, __VA_ARGS__) + + #define __INTERNAL_SYSCALL_CANCEL0(name) \ +- __internal_syscall_cancel (0, 0, 0, 0, 0, 0, __SYSCALL_CANCEL7_ARG \ ++ internal_syscall_cancel (0, 0, 0, 0, 0, 0, __SYSCALL_CANCEL7_ARG \ + __NR_##name) + #define __INTERNAL_SYSCALL_CANCEL1(name, a1) \ +- __internal_syscall_cancel (__SSC (a1), 0, 0, 0, 0, 0, \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ internal_syscall_cancel (__SSC (a1), 0, 0, 0, 0, 0, \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __INTERNAL_SYSCALL_CANCEL2(name, a1, a2) \ +- __internal_syscall_cancel (__SSC (a1), __SSC (a2), 0, 0, 0, 0, \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ internal_syscall_cancel (__SSC (a1), __SSC (a2), 0, 0, 0, 0, \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __INTERNAL_SYSCALL_CANCEL3(name, a1, a2, a3) \ +- __internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), 0, \ +- 0, 0, __SYSCALL_CANCEL7_ARG __NR_##name) ++ internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), 0, \ ++ 0, 0, __SYSCALL_CANCEL7_ARG __NR_##name) + #define __INTERNAL_SYSCALL_CANCEL4(name, a1, a2, a3, a4) \ +- __internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ +- __SSC(a4), 0, 0, \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ ++ __SSC(a4), 0, 0, \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __INTERNAL_SYSCALL_CANCEL5(name, a1, a2, a3, a4, a5) \ +- __internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ +- __SSC(a4), __SSC (a5), 0, \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ ++ __SSC(a4), __SSC (a5), 0, \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __INTERNAL_SYSCALL_CANCEL6(name, a1, a2, a3, a4, a5, a6) \ +- __internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ +- __SSC (a4), __SSC (a5), __SSC (a6), \ +- __SYSCALL_CANCEL7_ARG __NR_##name) ++ internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ ++ __SSC (a4), __SSC (a5), __SSC (a6), \ ++ __SYSCALL_CANCEL7_ARG __NR_##name) + #define __INTERNAL_SYSCALL_CANCEL7(name, a1, a2, a3, a4, a5, a6, a7) \ +- __internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ +- __SSC (a4), __SSC (a5), __SSC (a6), \ +- __SSC (a7), __NR_##name) ++ internal_syscall_cancel (__SSC (a1), __SSC (a2), __SSC (a3), \ ++ __SSC (a4), __SSC (a5), __SSC (a6), \ ++ __SSC (a7), __NR_##name) + + /* Issue a cancellable syscall defined by syscall number NAME plus any other + argument required. If an error occurs its value is returned as an negative +diff --git a/sysdeps/unix/sysv/linux/epoll_pwait2.c b/sysdeps/unix/sysv/linux/epoll_pwait2.c +index 4da03e3e69..76ec1f8a71 100644 +--- a/sysdeps/unix/sysv/linux/epoll_pwait2.c ++++ b/sysdeps/unix/sysv/linux/epoll_pwait2.c +@@ -17,7 +17,7 @@ + . */ + + #include +-#include ++#include + + int + __epoll_pwait2_time64 (int fd, struct epoll_event *ev, int maxev, +diff --git a/sysdeps/unix/sysv/linux/recvmmsg.c b/sysdeps/unix/sysv/linux/recvmmsg.c +index 6fbe4b80aa..6a89f914c2 100644 +--- a/sysdeps/unix/sysv/linux/recvmmsg.c ++++ b/sysdeps/unix/sysv/linux/recvmmsg.c +@@ -16,7 +16,7 @@ + . */ + + #include +-#include ++#include + #include + + static int +diff --git a/sysdeps/unix/sysv/linux/sigtimedwait.c b/sysdeps/unix/sysv/linux/sigtimedwait.c +index a4fa8e9e8e..c2c5e2c0f2 100644 +--- a/sysdeps/unix/sysv/linux/sigtimedwait.c ++++ b/sysdeps/unix/sysv/linux/sigtimedwait.c +@@ -16,7 +16,7 @@ + . */ + + #include +-#include ++#include + + int + __sigtimedwait64 (const sigset_t *set, siginfo_t *info, +diff --git a/sysdeps/unix/sysv/linux/sysdep-cancel.h b/sysdeps/unix/sysv/linux/sysdep-cancel.h +index 7fd8258ba5..4b7278915a 100644 +--- a/sysdeps/unix/sysv/linux/sysdep-cancel.h ++++ b/sysdeps/unix/sysv/linux/sysdep-cancel.h +@@ -21,5 +21,66 @@ + #define _SYSDEP_CANCEL_H + + #include ++#include "pthreadP.h" ++ ++/* Called by the INTERNAL_SYSCALL_CANCEL macro, check for cancellation and ++ returns the syscall value or its negative error code. */ ++static __always_inline long int ++internal_syscall_cancel (__syscall_arg_t a1, __syscall_arg_t a2, ++ __syscall_arg_t a3, __syscall_arg_t a4, ++ __syscall_arg_t a5, __syscall_arg_t a6, ++ __SYSCALL_CANCEL7_ARG_DEF ++ __syscall_arg_t nr) ++{ ++ long int result; ++ struct pthread *pd = THREAD_SELF; ++ ++ /* If cancellation is not enabled, call the syscall directly and also ++ for thread terminatation to avoid call __syscall_do_cancel while ++ executing cleanup handlers. */ ++ int ch = atomic_load_relaxed (&pd->cancelhandling); ++ if (SINGLE_THREAD_P || !cancel_enabled (ch) || cancel_exiting (ch)) ++ { ++ result = INTERNAL_SYSCALL_NCS_CALL (nr, a1, a2, a3, a4, a5, a6 ++ __SYSCALL_CANCEL7_ARCH_ARG7); ++ if (INTERNAL_SYSCALL_ERROR_P (result)) ++ return -INTERNAL_SYSCALL_ERRNO (result); ++ return result; ++ } ++ ++ /* Call the arch-specific entry points that contains the globals markers ++ to be checked by SIGCANCEL handler. */ ++ result = __syscall_cancel_arch (&pd->cancelhandling, nr, a1, a2, a3, a4, a5, ++ a6 __SYSCALL_CANCEL7_ARCH_ARG7); ++ ++ /* If the cancellable syscall was interrupted by SIGCANCEL and it has no ++ side-effect, cancel the thread if cancellation is enabled. */ ++ ch = atomic_load_relaxed (&pd->cancelhandling); ++ /* The behaviour here assumes that EINTR is returned only if there are no ++ visible side effects. POSIX Issue 7 has not yet provided any stronger ++ language for close, and in theory the close syscall could return EINTR ++ and leave the file descriptor open (conforming and leaks). It expects ++ that no such kernel is used with glibc. */ ++ if (result == -EINTR && cancel_enabled_and_canceled (ch)) ++ __syscall_do_cancel (); ++ ++ return result; ++} ++ ++/* Called by the SYSCALL_CANCEL macro, check for cancellation and return the ++ syscall expected success value (usually 0) or, in case of failure, -1 and ++ sets errno to syscall return value. */ ++static __always_inline long int ++syscall_cancel (__syscall_arg_t a1, __syscall_arg_t a2, ++ __syscall_arg_t a3, __syscall_arg_t a4, ++ __syscall_arg_t a5, __syscall_arg_t a6, ++ __SYSCALL_CANCEL7_ARG_DEF __syscall_arg_t nr) ++{ ++ long int r = internal_syscall_cancel (a1, a2, a3, a4, a5, a6, ++ __SYSCALL_CANCEL7_ARG nr); ++ return __glibc_unlikely (INTERNAL_SYSCALL_ERROR_P (r)) ++ ? SYSCALL_ERROR_LABEL (INTERNAL_SYSCALL_ERRNO (r)) ++ : r; ++} + + #endif + +commit 5d1e923ed79185668ac62d19fc37e7e23a3642b6 +Author: Adhemerval Zanella +Date: Thu Aug 6 14:07:55 2026 -0300 + + Fix gen-as-const-headers races with the parallel subdir recursion (BZ 34438) + + The parallel subdirectory recursion (commit 7cac99621e96) only orders + csu (and mach/hurd on Hurd) before the parallel fan-out plus the edges + the Depend files request. A header generated from gen-as-const-headers + is only ordered before the compilations of the subdirectory that + adds the .sym (through before-compile), so a header consumed by a + different subdirectory may not exist yet when its consumer is + compiled. + + That is the case for : it is generated when + building misc, while its only consumer, ____longjmp_chk.S (x86_64 and + sh), is built in debug. The serial recursion always ran misc before + debug in the sorted order, hiding the missing dependency. + + Move the generate the header to 'debug' instead. + + The same class of problem exists on Hurd: jmp_buf-ssp.h that is used + by ____longjmp_chk.S in debug, and signal-defines.h that is sued + by debug and setjmp. + + Deterministically reproduced with 'make debug/subdir_lib' from a clean + build tree (which orders only csu before debug), and verified with + builds for x86_64-linux-gnu, sh4-linux-gnu, i686-gnu, and x86_64-gnu. + Reviewed-by: Sam James + + (cherry picked from commit 60c9ed0e6b9cce07e85ee56fc39b9afe36919e45) + +diff --git a/Makerules b/Makerules +index 6bef57ece9..cef30974f1 100644 +--- a/Makerules ++++ b/Makerules +@@ -259,7 +259,17 @@ endif # gen-py-const-headers + ifdef gen-as-const-headers + # Generating headers for assembly constants. + # We need this defined early to get into before-compile before +-# it's used in sysd-rules, below. ++# it's used in sysd-rules, below. The gen-as-const-headers is evaluated ++# per subdirectory, so the before-compile dependency below only orders ++# the generated header before the compiles of the subdirectory whose ++# Makefile adds the .sym directive. ++# The parallel subdirectory recursion does not order sibling subdirectories, ++# so a .sym must be added in the subdirectory that compiles its consumers, ++# or in csu (which runs before the parallel) when it has consumers in ++# several subdirectories. ++# It must not add the same .sym in several subdirectories though: their ++# concurrent sub-makes would race generating the header through the fixed ++# temporary files below. + # Define GEN_AS_CONST_HEADERS to avoid circular dependency [BZ #22792]. + # NB: is generated from tcb-offsets.sym to define + # offsets and sizes of types in and maybe which +diff --git a/NEWS b/NEWS +index 28fbd9bcd8..ee292ff6c9 100644 +--- a/NEWS ++++ b/NEWS +@@ -11,6 +11,8 @@ The following bugs are resolved with this release: + + [34338] libc: Cancellable syscall wrappers are missing from backtraces + because they tail-call __syscall_cancel ++ [34438] build: non reproducible build failure: sigaltstack-offsets.h: ++ No such file or directory + [34441] math: math: sinh() returns wrong results for some inputs with + |x| > 36.736801 + [34465] math: math: x86_64 tanh ifunc selection wrong +diff --git a/sysdeps/mach/hurd/x86/Makefile b/sysdeps/mach/hurd/x86/Makefile +index 97e3287c87..1d94f3a1c1 100644 +--- a/sysdeps/mach/hurd/x86/Makefile ++++ b/sysdeps/mach/hurd/x86/Makefile +@@ -3,11 +3,7 @@ sysdep_routines += ioperm + sysdep_headers += sys/io.h + endif + +-ifeq ($(subdir),debug) +-gen-as-const-headers += signal-defines.sym +-endif +- +-ifeq ($(subdir),setjmp) ++ifeq ($(subdir),csu) + gen-as-const-headers += signal-defines.sym + endif + +diff --git a/sysdeps/unix/sysv/linux/sh/Makefile b/sysdeps/unix/sysv/linux/sh/Makefile +index dd3b382ac1..8c4cb73824 100644 +--- a/sysdeps/unix/sysv/linux/sh/Makefile ++++ b/sysdeps/unix/sysv/linux/sh/Makefile +@@ -6,7 +6,9 @@ ifeq ($(subdir),stdlib) + gen-as-const-headers += ucontext_i.sym + endif + +-ifeq ($(subdir),misc) ++# is only used by ____longjmp_chk.S, which is ++# built in the debug subdirectory. ++ifeq ($(subdir),debug) + gen-as-const-headers += sigaltstack-offsets.sym + endif + +diff --git a/sysdeps/unix/sysv/linux/x86_64/Makefile b/sysdeps/unix/sysv/linux/x86_64/Makefile +index 6938382801..528fd951b2 100644 +--- a/sysdeps/unix/sysv/linux/x86_64/Makefile ++++ b/sysdeps/unix/sysv/linux/x86_64/Makefile +@@ -10,7 +10,9 @@ ifeq ($(subdir),csu) + gen-as-const-headers += ucontext_i.sym + endif + +-ifeq ($(subdir),misc) ++# is only used by ____longjmp_chk.S, which is ++# built in the debug subdirectory. ++ifeq ($(subdir),debug) + gen-as-const-headers += sigaltstack-offsets.sym + endif + +diff --git a/sysdeps/x86/Makefile b/sysdeps/x86/Makefile +index 232e388d32..b4434deb0c 100644 +--- a/sysdeps/x86/Makefile ++++ b/sysdeps/x86/Makefile +@@ -1,5 +1,12 @@ + ifeq ($(subdir),csu) +-gen-as-const-headers += cpu-features-offsets.sym features-offsets.sym ++# is used by the setjmp/longjmp implementations in the ++# setjmp subdirectory and also by ____longjmp_chk.S in the debug ++# subdirectory. ++gen-as-const-headers += \ ++ cpu-features-offsets.sym \ ++ features-offsets.sym \ ++ jmp_buf-ssp.sym \ ++ # gen-as-const-headers + endif + + ifeq ($(subdir),elf) +@@ -171,7 +178,6 @@ tests += \ + endif # $(subdir) == math + + ifeq ($(subdir),setjmp) +-gen-as-const-headers += jmp_buf-ssp.sym + sysdep_routines += __longjmp_cancel + endif + + +commit 45b8a13c48da92bc5dd6fe102011391dd6847862 +Author: Rudi Heitbaum +Date: Thu Aug 6 14:07:56 2026 -0300 + + Makerules: Only install the ABI lib-names header from the top level (BZ 34439) + + The $(inst_includedir)/%.h install rules exist only where $(headers) is + non-empty, so in a subdir without headers (e.g. csu) the prerequisite + added on install-others-nosubdir has no rule. + + It only worked because .NOTPARALLEL made the top level install the header + first, which the parallel subdir recursion no longer guarantees. + Reviewed-by: Sam James + + (cherry picked from commit 82c0a96b8e63005a49ba52ddb21993811030613f) + +diff --git a/Makerules b/Makerules +index cef30974f1..dfe66b7fa6 100644 +--- a/Makerules ++++ b/Makerules +@@ -312,7 +312,12 @@ lib-names-h-abi = gnu/lib-names-$(default-abi).h + lib-names-stmp-abi = gnu/lib-names-$(default-abi).stmp + before-compile += $(common-objpfx)$(lib-names-h-abi) + common-generated += gnu/lib-names.h ++# The $(inst_includedir)/%.h install rules are defined only where $(headers) ++# is non-empty, and with parallel subdir recursion a subdir without headers ++# (e.g. csu) may run before the top level has installed the header. ++ifndef subdir + install-others-nosubdir: $(inst_includedir)/$(lib-names-h-abi) ++endif + $(common-objpfx)gnu/lib-names.h: + $(make-target-directory) + { \ +diff --git a/NEWS b/NEWS +index ee292ff6c9..d0ef2d3e9a 100644 +--- a/NEWS ++++ b/NEWS +@@ -13,6 +13,8 @@ The following bugs are resolved with this release: + because they tail-call __syscall_cancel + [34438] build: non reproducible build failure: sigaltstack-offsets.h: + No such file or directory ++ [34439] build: parallel make install fails on multi-ABI targets: no ++ rule to make $(inst_includedir)/gnu/lib-names-$(abi).h in csu + [34441] math: math: sinh() returns wrong results for some inputs with + |x| > 36.736801 + [34465] math: math: x86_64 tanh ifunc selection wrong + +commit f7beb24f3ad5dbf8e84a5b75d5b2428a262e9ab9 +Author: Adhemerval Zanella +Date: Thu Aug 6 14:07:57 2026 -0300 + + Makefile: Only print the test summary in the second pass of 'make check' + + The build-only first pass of the two-pass 'make check' still runs the + static checks (abi, conformtest, installed headers, etc.), and the + top-level tests recipe merged and summarized their results. + + An unexpected FAIL there (e.g. check-abi) aborted 'check' before the + second pass ran any built test, and even a clean run printed a misleading + partial summary. + + Pass tests-summary=no in the first pass to skip the merge and summary; + the .test-result files persist, so the second pass folds those results + into the one complete summary at the end, restoring the single-pass + reporting behavior. + Reviewed-by: Sam James + + (cherry picked from commit 96a9a09d7d5527462a823c247569e65feeca8ddb) + +diff --git a/Makefile b/Makefile +index a6aabca691..b9fac6f47c 100644 +--- a/Makefile ++++ b/Makefile +@@ -869,7 +869,11 @@ endif + touch $(objpfx)testroot.pristine/install.stamp + + tests-special-notdir = $(patsubst $(objpfx)%, %, $(tests-special)) ++# The build-only first pass of the two-pass 'make check' (see Makerules) ++# passes tests-summary=no: the merge and summary are left to the second ++# pass, which folds in this pass's $(tests-special) results. + tests: $(tests-special) ++ifneq ($(tests-summary),no) + $(..)scripts/merge-test-results.sh -s $(objpfx) "" \ + $(sort $(tests-special-notdir:.out=)) \ + > $(objpfx)subdir-tests.sum +@@ -877,11 +881,14 @@ tests: $(tests-special) + $(sort $(subdirs) .) \ + > $(objpfx)tests.sum + $(call summarize-tests,tests.sum) ++endif + xtests: ++ifneq ($(tests-summary),no) + $(..)scripts/merge-test-results.sh -t $(objpfx) subdir-xtests.sum \ + $(sort $(subdirs)) \ + > $(objpfx)xtests.sum + $(call summarize-tests,xtests.sum, for extra tests) ++endif + + # The realclean target is just like distclean for the parent, but we want + # the subdirs to know the difference in case they care. +diff --git a/Makerules b/Makerules +index dfe66b7fa6..5f65f3ab9e 100644 +--- a/Makerules ++++ b/Makerules +@@ -1211,6 +1211,13 @@ ALL_BUILD_CFLAGS = $(BUILD_CFLAGS) $(BUILD_CPPFLAGS) -D_GNU_SOURCE \ + # therefore builds the test programs (run-built-tests=no, recursion fully + # parallel) and then runs them (run-built-tests=yes). 'make tests' and a + # subdirectory's own 'check' stay single-pass. ++# The first pass still runs the static checks ($(tests-special): abi, ++# conformtest, installed headers, ...), so tests-summary=no makes it skip ++# the results merge and summary: an unexpected FAIL there would otherwise ++# abort 'check' before the second pass runs any built test, and even a ++# clean run would print a misleading partial summary. The .test-result ++# files persist, so the second pass folds those results into the one ++# complete summary at the end. + check-twopass := + ifndef subdir + ifeq (yes,$(run-built-tests)) +@@ -1219,10 +1226,10 @@ endif + endif + ifeq (yes,$(check-twopass)) + check: +- $(MAKE) run-built-tests=no tests ++ $(MAKE) run-built-tests=no tests-summary=no tests + $(MAKE) run-built-tests=yes tests + xcheck: +- $(MAKE) run-built-tests=no xtests ++ $(MAKE) run-built-tests=no tests-summary=no xtests + $(MAKE) run-built-tests=yes xtests + else + check: tests + +commit fc3641194619c7c327ef398c88c07b3069878ed3 +Author: Adhemerval Zanella +Date: Thu Aug 6 14:07:58 2026 -0300 + + Makerules: Make the .dt to .d conversion safe against concurrent sub-makes + + The %.d: %.dt rule seds its input into a fixed temporary name, renames + it into place and removes the input. Two makes converting the same + file trip over each other: + + mv: cannot stat '.../test-double-libmvec-sincos-avx512f.o.T': No such file or directory + sed: can't read .../test-float-libmvec-acosf-avx512f.o.dt: No such file or directory + + That happens because the elf rtld-Rules recursion runs a sub-make over + every $(rtld-subdirs) directory, which converts that directory's .dt + files, and the parallel subdirectory recursion (commit 7cac99621e96) + runs it concurrently with those subdirectories' own sub-makes. + + Add the PID of the shell to the temporary name and claim the input with + a rename: only the run that wins converts and installs the target. + Reviewed-by: Sam James + + (cherry picked from commit ba8c8801be7674cc12406914184516a811ac22a8) + +diff --git a/Makerules b/Makerules +index 5f65f3ab9e..be51154bae 100644 +--- a/Makerules ++++ b/Makerules +@@ -758,10 +758,20 @@ all-dt-files := $(foreach o,$(object-suffixes-for-libc),$(+depfiles:.d=$o.dt)) + $(wildcard $(all-dt-files:.dt=.d)) + + # This is a funny rule in that it removes its input file. ++# ++# More than one make can convert the .dt files of a single object ++# directory: the elf rtld-Rules recursion runs a sub-make over every ++# $(rtld-subdirs) directory, concurrently with that directory's own ++# sub-make under the parallel subdir recursion. Add the PID of the ++# shell to the temporary name and claim the input with a rename: only ++# the run that wins converts and installs the target. + %.d: %.dt +- @sed $(sed-remove-objpfx) $< > $(@:.d=.T) && \ +- mv -f $(@:.d=.T) $@ && \ +- rm -f $< ++ @dt=$(@:.d=.T)$$$$; \ ++ if mv -f $< $$dt 2>/dev/null; then \ ++ sed $(sed-remove-objpfx) $$dt > $$dt.new && \ ++ mv -f $$dt.new $@ && \ ++ rm -f $$dt; \ ++ fi + + # Avoid the .h.d files for any .sym files whose .h files don't exist yet. + # They will be generated when they're needed, and trying too early won't work. +@@ -1433,7 +1443,7 @@ endef + # Also remove the dependencies and generated source files. + common-clean: common-mostlyclean + -rm -f $(addprefix $(objpfx),$(generated)) +- -rm -f $(objpfx)*.d $(objpfx)*.dt ++ -rm -f $(objpfx)*.d $(objpfx)*.dt $(objpfx)*.T[0-9]* + -rm -fr $(addprefix $(objpfx),$(generated-dirs)) + -rm -f $(addprefix $(common-objpfx),$(common-generated)) + -rm -f $(gen-as-const-headers:%.sym=$(common-objpfx)%.h) + +commit f34027b27fefbc94aab04bff613ba5c24fb909b1 +Author: Adhemerval Zanella +Date: Thu Aug 6 14:07:59 2026 -0300 + + Makefile: Order the top-level stamp files before the subdirectory fan-out + + The archive rules in Makerules list every stamp file as a prerequisite, + including the top level's own, and the elf sub-make evaluates them to + build libc_pic.a for the librtld.map link. A sub-make can only create + the stamp files of its own directory, so when the top-level ones do not + exist yet it fails with: + + make[2]: *** No rule to make target '.../stamp.os', needed by + '.../libc_pic.a'. Stop. + + The serial recursion created them before the subdirectories through the + prerequisite order of subdir_lib; the parallel recursion (commit + 7cac99621e96) does not. Add them as prerequisites of the object-building + per-subdirectory targets. + Reviewed-by: Sam James + + (cherry picked from commit 25c42d04c45fc5fdb1481a7f968782791b21fd3e) + +diff --git a/Makefile b/Makefile +index b9fac6f47c..d559c42873 100644 +--- a/Makefile ++++ b/Makefile +@@ -575,6 +575,14 @@ $(foreach t,$(+elf_last_subdir_targets),$(eval \ + elf/$(t): $(addsuffix /$(t),$(filter-out elf,$(subdirs))))) + endif + ++# The archive rules in Makerules list every stamp file as a ++# prerequisite of libc_pic.a, which the elf sub-make evaluates for the ++# librtld.map link, but a sub-make can only create its own directory's ++# stamps. Create the top-level ones before the fan-out. ++$(foreach t,$(+elf_last_subdir_targets),$(eval \ ++ $(addsuffix /$(t),$(subdirs)): \ ++ $(foreach o,$(object-suffixes-for-libc),$(common-objpfx)stamp$(o)))) ++ + # Pass barriers: a subdirectory 'others' build links programs against + # the libraries, so the 'lib' pass (including the top-level libc.so + # link) must have completed. + +commit 10e3ce8a57e134c13dd28772de68542b0e3d4e86 +Author: Adhemerval Zanella +Date: Thu Aug 6 14:08:00 2026 -0300 + + arm: Order the rtld link after libgcc-stubs.a + + The librtld.map and librtld.os link recipes use $(gnulib), which on arm + contains libgcc-stubs.a through gnulib-arch. But the archive is only a + prerequisite of lib-noranlib so the rtld link can run before the archive + exists: + + ld.bfd: cannot find .../elf/libgcc-stubs.a: No such file or directory + + The race seems to predates the parallel subdirectory recursion, which + only made it observable. + + Add the order-only dependency in sysdeps/arm/Makefile rather than in + elf/Makefile. Theprerequisite lists expand when the rule is parsed, + and gnulib-arch is only defined once Makerules includes the sysdeps + makefiles. + + Verified with a build for arm-linux-gnueabihf. + Reviewed-by: Sam James + + (cherry picked from commit a33ceb6e96dc8de8d36de1b1f3ec06ceb524d012) + +diff --git a/sysdeps/arm/Makefile b/sysdeps/arm/Makefile +index 0bb1b6e05b..9042315492 100644 +--- a/sysdeps/arm/Makefile ++++ b/sysdeps/arm/Makefile +@@ -10,6 +10,11 @@ shared-only-routines += aeabi_unwind_cpp_pr1 + $(objpfx)libgcc-stubs.a: $(objpfx)aeabi_unwind_cpp_pr1.os + $(build-extra-lib) + ++# The rtld link recipes in elf/Makefile use $(gnulib), which here ++# includes libgcc-stubs.a, but they cannot name it as a prerequisite: ++# gnulib-arch is only defined once this file is included from Makerules. ++$(objpfx)librtld.map $(objpfx)librtld.os: | $(objpfx)libgcc-stubs.a ++ + lib-noranlib: $(objpfx)libgcc-stubs.a + + ifeq ($(build-shared),yes) + +commit 26b9cc42a051f78233fcecd2a3b83f98ec9862b9 +Author: Adhemerval Zanella +Date: Tue Jul 28 11:27:33 2026 -0300 + + benchtests: Create objdir in the bench-%.c generation rule + + The $(objpfx)bench-%.c rule writes its output into $(objpfx) without + ensuring that directory exists. Serial builds happened to satisfy + that ordering, with parallel builds the generation recipe can + run before the directory is created, failing with: + + cannot create .../benchtests/bench-xxx.c-tmp: Directory nonexistent + + Add the standard $(make-target-directory). + + Reviewed-by: Florian Weimer + (cherry picked from commit 26f0f2aa7d6ea63f85b5186349c41de2c91b4dd7) + +diff --git a/benchtests/Makefile b/benchtests/Makefile +index f407e492cb..16cc951d19 100644 +--- a/benchtests/Makefile ++++ b/benchtests/Makefile +@@ -622,6 +622,7 @@ $(bench-link-targets): %: %.o $(objpfx)json-lib.o \ + $(bench-link-targets): LDFLAGS += $(link-bench-bind-now) + + $(objpfx)bench-%.c: %-inputs $(bench-deps) ++ $(make-target-directory) + { if [ -n "$($*-INCLUDE)" ]; then \ + cat $($*-INCLUDE); \ + fi; \ + +commit 4662c4675d7f3ba87637c61730f06071f305c5cb +Author: Xi Ruoyao +Date: Sun Jul 26 00:11:44 2026 +0800 + + elf: test: handle different rootsbindir in tst-ldconfig-cache + + When compiling a glibc for a merged-/usr distro people may set + rootsbindir=/usr/sbin. But tst-ldconfig-cache has hard-coded + /sbin/ldconfig path and so it fails with a different rootsbindir. + + Fix it by using support_install_rootsbindir like run_ldconfig in + test-container.c. + + Signed-off-by: Xi Ruoyao + Reviewed-by: Florian Weimer + (cherry picked from commit 02ea17b5add83a205d8b204dce28f38fe0498ea3) + +diff --git a/elf/tst-ldconfig-cache.c b/elf/tst-ldconfig-cache.c +index 9f71418b3a..f4820a1822 100644 +--- a/elf/tst-ldconfig-cache.c ++++ b/elf/tst-ldconfig-cache.c +@@ -85,7 +85,10 @@ corrupt (void) + static void + ldconfig (void) + { +- xsystem ("/sbin/ldconfig -X"); ++ char *cmd = xasprintf("%s/ldconfig -X", support_install_rootsbindir); ++ xsystem (cmd); ++ ++ free(cmd); + } + + /* Change ld.so.conf to refer to the new directory, and generate a new + +commit 9e1b1ef77c7b1cc58f625500e9ea74fb3cafdf12 +Author: Matt Turner +Date: Sun Jul 26 00:27:37 2026 -0400 + + ldbl-opt: Fix -mlong-double-128 configure test for Clang + + The check for -mlong-double-128 support wrapped its test code in + AC_LANG_PROGRAM, which places the body inside main(). The body defines + a function, so it became a nested function definition -- a GCC extension + that Clang does not implement, making the test fail (and thus the whole + build error out) with Clang even though it supports -mlong-double-128. + + Use AC_LANG_SOURCE so the function is defined at file scope, matching the + pattern already used by the powerpc64le compiler checks, and regenerate + configure. + + Reviewed-by: Sam James + (cherry picked from commit e7a14f03b8d5e34e8ac46db6c377da5c66a3ec2a) + +diff --git a/sysdeps/ieee754/ldbl-opt/configure b/sysdeps/ieee754/ldbl-opt/configure +old mode 100644 +new mode 100755 +index bc6552da0b..7769cc9781 +--- a/sysdeps/ieee754/ldbl-opt/configure ++++ b/sysdeps/ieee754/ldbl-opt/configure +@@ -13,17 +13,10 @@ CFLAGS="$CFLAGS -mlong-double-128" + cat confdefs.h - <<_ACEOF >conftest.$ac_ext + /* end confdefs.h. */ + +-int +-main (void) +-{ +- + #ifndef __LONG_DOUBLE_128__ + # error "compiler did not predefine __LONG_DOUBLE_128__ as expected" + #endif + long double foobar (long double x) { return x; } +- ; +- return 0; +-} + _ACEOF + if ac_fn_c_try_compile "$LINENO" + then : +diff --git a/sysdeps/ieee754/ldbl-opt/configure.ac b/sysdeps/ieee754/ldbl-opt/configure.ac +index 70e3b32dc6..1c500ad581 100644 +--- a/sysdeps/ieee754/ldbl-opt/configure.ac ++++ b/sysdeps/ieee754/ldbl-opt/configure.ac +@@ -6,7 +6,7 @@ AC_CACHE_CHECK(whether $CC $CFLAGS supports -mlong-double-128, + libc_cv_mlong_double_128, [dnl + save_CFLAGS="$CFLAGS" + CFLAGS="$CFLAGS -mlong-double-128" +-AC_COMPILE_IFELSE([AC_LANG_PROGRAM([[]], [[ ++AC_COMPILE_IFELSE([AC_LANG_SOURCE([[ + #ifndef __LONG_DOUBLE_128__ + # error "compiler did not predefine __LONG_DOUBLE_128__ as expected" + #endif + +commit eacd9cced93498e671c7e7f758aaf52593847e01 +Author: Matt Turner +Date: Sun Jul 26 14:43:11 2026 -0400 + + powerpc: Fix -mlong-double-128 IBM format configure test for Clang + + The check for -mlong-double-128 IBM extended format support wrapped its + test code in AC_LANG_PROGRAM, which places the body inside main(). The + body defines a function, so it became a nested function definition -- a + GCC extension that Clang does not implement, making the test fail with + Clang. + + Use AC_LANG_SOURCE so the function is defined at file scope, and + regenerate configure. + + Reviewed-by: Sam James + (cherry picked from commit 559d0f77f3ee1000cf8a2d0baba7a59a1ec45f50) + +diff --git a/sysdeps/unix/sysv/linux/powerpc/configure b/sysdeps/unix/sysv/linux/powerpc/configure +index ef2055db92..eb8578404f 100644 +--- a/sysdeps/unix/sysv/linux/powerpc/configure ++++ b/sysdeps/unix/sysv/linux/powerpc/configure +@@ -12,18 +12,12 @@ else case e in #( + CFLAGS="$CFLAGS -mlong-double-128" + cat confdefs.h - <<_ACEOF >conftest.$ac_ext + /* end confdefs.h. */ +-#include +-int +-main (void) +-{ + ++#include + #if LDBL_MANT_DIG != 106 + # error "compiler doesn't implement IBM extended format of long double" + #endif + long double foobar (long double x) { return x; } +- ; +- return 0; +-} + _ACEOF + if ac_fn_c_try_compile "$LINENO" + then : +diff --git a/sysdeps/unix/sysv/linux/powerpc/configure.ac b/sysdeps/unix/sysv/linux/powerpc/configure.ac +index 42347a66fc..ca0f82da08 100644 +--- a/sysdeps/unix/sysv/linux/powerpc/configure.ac ++++ b/sysdeps/unix/sysv/linux/powerpc/configure.ac +@@ -6,7 +6,8 @@ AC_CACHE_CHECK(whether $CC $CFLAGS -mlong-double-128 uses IBM extended format, + libc_cv_mlong_double_128ibm, [dnl + save_CFLAGS="$CFLAGS" + CFLAGS="$CFLAGS -mlong-double-128" +-AC_COMPILE_IFELSE([AC_LANG_PROGRAM([[#include ]], [[ ++AC_COMPILE_IFELSE([AC_LANG_SOURCE([[ ++#include + #if LDBL_MANT_DIG != 106 + # error "compiler doesn't implement IBM extended format of long double" + #endif + +commit 89da37bb6e4a631f375b5fe48783e5c023441b0c +Author: Matt Turner +Date: Tue Aug 4 10:17:20 2026 -0400 + + stdio-common: run AWK in the C locale in the printf format tests + + The program under test runs in the C locale, through the test program + prefix, but AWK inherits whatever locale the build was started in. They + agree today only because the locale in use shares its decimal point with + the C locale. + + It is also faster. gawk takes a single byte path in its regular + expression engine when MB_CUR_MAX is 1, and the script matches several + expressions against every line. For the %f conversion for double, the + largest of these tests, as the median of five runs: + + x86_64, gawk 5.4.1 1.482s -> 1.248s + x86_64, gawk 5.3.2 0.911s -> 0.703s + alpha, gawk 5.4.60 30.9s -> 26.6s + + Worth noting that gawk 5.4 is a good deal slower here than 5.3 was, at + 1.248s against 0.703s for the same input in the C locale, so these tests + have become more expensive than they used to be. + + Reviewed-by: Adhemerval Zanella + (cherry picked from commit 866a70167b85903a02d4ccacb91afb8922702c14) + +diff --git a/stdio-common/tst-printf-format-c.sh b/stdio-common/tst-printf-format-c.sh +index 825c50ec42..73d28c5607 100644 +--- a/stdio-common/tst-printf-format-c.sh ++++ b/stdio-common/tst-printf-format-c.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + echo Verifying c + (set -o pipefail +diff --git a/stdio-common/tst-printf-format-char.sh b/stdio-common/tst-printf-format-char.sh +index 7867bdd62f..aa4d211126 100644 +--- a/stdio-common/tst-printf-format-char.sh ++++ b/stdio-common/tst-printf-format-char.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=0 + +diff --git a/stdio-common/tst-printf-format-double.sh b/stdio-common/tst-printf-format-double.sh +index 8157092dc4..051e4716c5 100644 +--- a/stdio-common/tst-printf-format-double.sh ++++ b/stdio-common/tst-printf-format-double.sh +@@ -29,7 +29,7 @@ test_program_prefix=$1; shift + # internally to process the conversion requested, so any bug in our code + # would then be verified against itself, defeating the objective of doing + # the verification against an independent implementation. +-AWK="${AWK:-awk} -M" ++AWK="env LC_ALL=C ${AWK:-awk} -M" + + status=77 + +diff --git a/stdio-common/tst-printf-format-int.sh b/stdio-common/tst-printf-format-int.sh +index 8542ff4150..e9dcbedc04 100644 +--- a/stdio-common/tst-printf-format-int.sh ++++ b/stdio-common/tst-printf-format-int.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=77 + +diff --git a/stdio-common/tst-printf-format-ldouble.sh b/stdio-common/tst-printf-format-ldouble.sh +index dbf78a98c6..7ee097ac0a 100644 +--- a/stdio-common/tst-printf-format-ldouble.sh ++++ b/stdio-common/tst-printf-format-ldouble.sh +@@ -29,7 +29,7 @@ test_program_prefix=$1; shift + # internally to process the conversion requested, so any bug in our code + # would then be verified against itself, defeating the objective of doing + # the verification against an independent implementation. +-AWK="${AWK:-awk} -M" ++AWK="env LC_ALL=C ${AWK:-awk} -M" + + status=77 + +diff --git a/stdio-common/tst-printf-format-llong.sh b/stdio-common/tst-printf-format-llong.sh +index e1f5252c9a..98a79660cc 100644 +--- a/stdio-common/tst-printf-format-llong.sh ++++ b/stdio-common/tst-printf-format-llong.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=77 + +diff --git a/stdio-common/tst-printf-format-long.sh b/stdio-common/tst-printf-format-long.sh +index 4b68ab1e04..89ac3302b8 100644 +--- a/stdio-common/tst-printf-format-long.sh ++++ b/stdio-common/tst-printf-format-long.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=77 + +diff --git a/stdio-common/tst-printf-format-s.sh b/stdio-common/tst-printf-format-s.sh +index 65aa0cb675..015c730609 100644 +--- a/stdio-common/tst-printf-format-s.sh ++++ b/stdio-common/tst-printf-format-s.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + echo Verifying s + (set -o pipefail +diff --git a/stdio-common/tst-printf-format-short.sh b/stdio-common/tst-printf-format-short.sh +index 30357baa02..a7df8b8e6d 100644 +--- a/stdio-common/tst-printf-format-short.sh ++++ b/stdio-common/tst-printf-format-short.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=0 + +diff --git a/stdio-common/tst-printf-format-uchar.sh b/stdio-common/tst-printf-format-uchar.sh +index 08a6914b88..356de4217d 100644 +--- a/stdio-common/tst-printf-format-uchar.sh ++++ b/stdio-common/tst-printf-format-uchar.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=0 + +diff --git a/stdio-common/tst-printf-format-uint.sh b/stdio-common/tst-printf-format-uint.sh +index 0ba203ccda..b496047a49 100644 +--- a/stdio-common/tst-printf-format-uint.sh ++++ b/stdio-common/tst-printf-format-uint.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=77 + +diff --git a/stdio-common/tst-printf-format-ullong.sh b/stdio-common/tst-printf-format-ullong.sh +index 5b881ab924..f030f66a24 100644 +--- a/stdio-common/tst-printf-format-ullong.sh ++++ b/stdio-common/tst-printf-format-ullong.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=77 + +diff --git a/stdio-common/tst-printf-format-ulong.sh b/stdio-common/tst-printf-format-ulong.sh +index f6aeb8e3c0..7102575ed2 100644 +--- a/stdio-common/tst-printf-format-ulong.sh ++++ b/stdio-common/tst-printf-format-ulong.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=77 + +diff --git a/stdio-common/tst-printf-format-ushort.sh b/stdio-common/tst-printf-format-ushort.sh +index 07609128ab..5f612b5398 100644 +--- a/stdio-common/tst-printf-format-ushort.sh ++++ b/stdio-common/tst-printf-format-ushort.sh +@@ -23,7 +23,7 @@ xprintf=$1; shift + common_objpfx=$1; shift + test_program_prefix=$1; shift + +-AWK=${AWK:-awk} ++AWK="env LC_ALL=C ${AWK:-awk}" + + status=0 + + +commit 7cc7a3a4fbf15c8a7d61a69452f754f9c352cd62 +Author: Matt Turner +Date: Mon Aug 3 21:59:44 2026 -0400 + + stdio-common: avoid repeated regexp matches in tst-printf-format.awk + + Whether the value is an infinity, a NaN or zero does not change between + the conversions applied to it, but was determined again for each one. + Determine it where the value is read. + + Also look for the '#' flag with index() before matching the expressions + that need it, and test the value first where both have to hold. + + For the %f conversion for double, in the C locale, as the median of five + runs: + + x86_64, gawk 5.4.1 1.248s -> 1.184s + x86_64, gawk 5.3.2 0.703s -> 0.708s + alpha, gawk 5.4.60 26.6s -> 25.8s + + So this only helps with the regular expression engine that gawk 5.4 + brought in; under 5.3.2 it is lost in the noise. Output and exit status + are unchanged for the e, f and g conversions for double under both + gawk versions and both locales. + + Reviewed-by: Adhemerval Zanella + (cherry picked from commit 0cc3f9b3f3f2950844bd41cc8923215cd5d97269) + +diff --git a/stdio-common/tst-printf-format.awk b/stdio-common/tst-printf-format.awk +index 5d0324c551..57bea12621 100644 +--- a/stdio-common/tst-printf-format.awk ++++ b/stdio-common/tst-printf-format.awk +@@ -32,6 +32,9 @@ BEGIN { + # non-bignum mode unless a sign has been explicitly given. Keep + # original 'val' for reporting. + value = gensub(/^(INF|NAN|inf|nan)/, "+\\1", 1, val) ++ # Neither changes between the conversions applied to this value. ++ value_infnan = value ~ /(INF|NAN|inf|nan)/ ++ value_zero = value == 0 + next + } + +@@ -52,7 +55,7 @@ BEGIN { + # Discard the '#' flag with the octal conversion if output starts with + # 0 in the absence of this flag. In that case no extra 0 is supposed + # to be produced, but gawk prepends it anyway. +- if (format ~ /#.*o/) ++ if (index(format, "#") && format ~ /#.*o/) + { + tmpfmt = gensub(/#/, "", "g", format) + tmpout = sprintf(tmpfmt, value) +@@ -62,7 +65,7 @@ BEGIN { + # Likewise with the hexadecimal conversion where zero value with the + # precision of zero is supposed to produce no characters, but gawk + # outputs 0 instead. +- else if (format ~ /#.*[Xx]/) ++ else if (index(format, "#") && format ~ /#.*[Xx]/) + { + tmpfmt = gensub(/#/, "", "g", format) + tmpout = sprintf(tmpfmt, value) +@@ -78,7 +81,7 @@ BEGIN { + # values and reprint the output produced using the string conversion, + # with the field width carried over and the relevant flags handled by + # hand. +- if (format ~ /[EFGefg]/ && value ~ /(INF|NAN|inf|nan)/) ++ if (value_infnan && format ~ /[EFGefg]/) + { + minus = format ~ /-/ ? "-" : "" + sign = value ~ /-/ ? "-" : format ~ /\+/ ? "+" : format ~ / / ? " " : "" +@@ -94,7 +97,7 @@ BEGIN { + # In that case "+" is always supposed to be produced, but with the + # precision of zero gawk in the non-bignum mode produces any padding + # requested only. +- else if (format ~ /\+.*[di]/ && value == 0) ++ else if (value_zero && format ~ /\+.*[di]/) + { + output = gensub(/^( *) $/, format ~ /-/ ? "+\\1" : "\\1+", 1, output) + output = gensub(/^$/, "+", 1, output) +@@ -103,7 +106,7 @@ BEGIN { + # conversion for zero value. In that case at least one " " is + # supposed to be produced, but with the precision of zero gawk in the + # non-bignum mode produces nothing. +- else if (format ~ / .*[di]/ && value == 0) ++ else if (value_zero && format ~ / .*[di]/) + { + output = gensub(/^$/, " ", 1, output) + } + +commit 65d35639a9d055e423345c8748908c8aa48b19b9 +Author: Magnus Lindholm +Date: Wed Aug 5 23:14:58 2026 +0200 + + string: Speed up strcmp test data initialization + + The strcmp and strncmp tests repeatedly initialize large buffers for + many combinations of lengths and alignments. The existing loops + perform a remainder operation and two individual stores for every + element. + + Generate at most max_char elements using an additive recurrence. The + recurrence produces the same sequence as the existing multiplication + and remainder expression. Expand this initial pattern using bulk + copies, and then copy the completed first buffer to the second buffer. + + This preserves the generated test data while substantially reducing + the initialization cost on slower systems. + + The change also applies to the wcscmp and wcsncmp tests, which include + the same test sources. + + Signed-off-by: Magnus Lindholm + Reviewed-by: Adhemerval Zanella + (cherry picked from commit 9b323b95567dff46b34157ac4455734633921abb) + +diff --git a/string/test-strcmp.c b/string/test-strcmp.c +index 76ccff46e2..ca52827b11 100644 +--- a/string/test-strcmp.c ++++ b/string/test-strcmp.c +@@ -156,6 +156,10 @@ do_test (size_t align1, size_t align2, size_t len, int max_char, + int exp_result) + { + size_t i; ++ size_t value = 0; ++ size_t pattern_len; ++ size_t step ++ = (23U << ((CHARBYTES - 1) * 8)) % (size_t) max_char; + + CHAR *s1, *s2; + +@@ -179,8 +183,28 @@ do_test (size_t align1, size_t align2, size_t len, int max_char, + i = align2 + CHARBYTES * (len + 2); + s2 = (CHAR *)(buf2 + ((page_size - i) / 16 * 16) + align2); + +- for (i = 0; i < len; i++) +- s1[i] = s2[i] = 1 + (23 << ((CHARBYTES - 1) * 8)) * i % max_char; ++ /* The generated sequence repeats after at most max_char elements. */ ++ pattern_len ++ = len < (size_t) max_char ? len : (size_t) max_char; ++ ++ for (i = 0; i < pattern_len; i++) ++ { ++ s1[i] = 1 + value; ++ ++ value += step; ++ if (value >= (size_t) max_char) ++ value -= max_char; ++ } ++ ++ while (i < len) ++ { ++ size_t copy = i < len - i ? i : len - i; ++ ++ MEMCPY (s1 + i, s1, copy); ++ i += copy; ++ } ++ ++ MEMCPY (s2, s1, len); + + s1[len] = s2[len] = 0; + s1[len + 1] = 23; +diff --git a/string/test-strncmp.c b/string/test-strncmp.c +index 54ada39eb2..9da0f21f60 100644 +--- a/string/test-strncmp.c ++++ b/string/test-strncmp.c +@@ -190,6 +190,9 @@ do_test_n (size_t align1, size_t align2, size_t len, size_t n, int n_in_bounds, + { + size_t i, buf_bound; + CHAR *s1, *s2, *s1_end, *s2_end; ++ size_t value = 0; ++ size_t pattern_len; ++ size_t step = (23U << ((CHARBYTES - 1) * 8)) % (size_t) max_char; + + align1 &= ~(CHARBYTES - 1); + align2 &= ~(CHARBYTES - 1); +@@ -216,8 +219,29 @@ do_test_n (size_t align1, size_t align2, size_t len, size_t n, int n_in_bounds, + s2[n] = 23; + } + +- for (i = 0; i < buf_bound; i++) +- s1[i] = s2[i] = 1 + (23 << ((CHARBYTES - 1) * 8)) * i % max_char; ++ /* The generated sequence repeats after at most max_char elements. */ ++ pattern_len ++ = buf_bound < (size_t) max_char ++ ? buf_bound : (size_t) max_char; ++ ++ for (i = 0; i < pattern_len; i++) ++ { ++ s1[i] = 1 + value; ++ ++ value += step; ++ if (value >= (size_t) max_char) ++ value -= max_char; ++ } ++ ++ while (i < buf_bound) ++ { ++ size_t copy = i < buf_bound - i ? i : buf_bound - i; ++ ++ MEMCPY (s1 + i, s1, copy); ++ i += copy; ++ } ++ ++ MEMCPY (s2, s1, buf_bound); + + s1[len] = 0; + s2[len] = 0; + +commit 11ac3d78fc5e4f7f2846002e099f773ad8ff82fc +Author: Magnus Lindholm +Date: Wed Aug 5 23:14:59 2026 +0200 + + string: Speed up strcasecmp test data initialization + + The strcasecmp and strncasecmp tests repeatedly initialize large + buffers for many combinations of lengths and alignments. The existing + loops perform a remainder operation and call toupper and tolower for + every element. + + Generate at most max_char elements using an additive recurrence and + apply the case conversions while creating this initial pattern. The + recurrence produces the same sequence as the existing multiplication + and remainder expression. Expand the completed pattern using bulk + copies. + + This preserves the generated test data and locale-dependent case + conversion while substantially reducing the initialization cost on + slower systems. + + Signed-off-by: Magnus Lindholm + Reviewed-by: Adhemerval Zanella + (cherry picked from commit c1fb5d0e6b8d292ac526974d05c5adb4c3827fb0) + +diff --git a/string/test-strcasecmp.c b/string/test-strcasecmp.c +index a5235fa1bb..d090dcbf36 100644 +--- a/string/test-strcasecmp.c ++++ b/string/test-strcasecmp.c +@@ -63,6 +63,9 @@ do_test (size_t align1, size_t align2, size_t len, int max_char, + int exp_result) + { + size_t i; ++ size_t value = 0; ++ size_t step = 23U % (size_t) max_char; ++ size_t pattern_len; + char *s1, *s2; + + if (len == 0) +@@ -80,10 +83,25 @@ do_test (size_t align1, size_t align2, size_t len, int max_char, + s1 = (char *) (buf1 + align1); + s2 = (char *) (buf2 + align2); + +- for (i = 0; i < len; i++) ++ pattern_len ++ = len < (size_t) max_char ? len : (size_t) max_char; ++ ++ for (i = 0; i < pattern_len; i++) + { +- s1[i] = toupper (1 + 23 * i % max_char); ++ s1[i] = toupper (1 + value); + s2[i] = tolower (s1[i]); ++ value += step; ++ if (value >= (size_t) max_char) ++ value -= max_char; ++ } ++ ++ while (i < len) ++ { ++ size_t copy = i < len - i ? i : len - i; ++ ++ memcpy (s1 + i, s1, copy); ++ memcpy (s2 + i, s2, copy); ++ i += copy; + } + + s1[len] = s2[len] = 0; +diff --git a/string/test-strncasecmp.c b/string/test-strncasecmp.c +index 035c680532..6b00113e66 100644 +--- a/string/test-strncasecmp.c ++++ b/string/test-strncasecmp.c +@@ -83,6 +83,9 @@ do_test (size_t align1, size_t align2, size_t n, size_t len, int max_char, + int exp_result) + { + size_t i; ++ size_t value = 0; ++ size_t step = 23U % (size_t) max_char; ++ size_t pattern_len; + char *s1, *s2; + + if (len == 0) +@@ -100,10 +103,26 @@ do_test (size_t align1, size_t align2, size_t n, size_t len, int max_char, + s1 = (char *) (buf1 + align1); + s2 = (char *) (buf2 + align2); + +- for (i = 0; i < len; i++) ++ pattern_len ++ = len < (size_t) max_char ? len : (size_t) max_char; ++ ++ for (i = 0; i < pattern_len; i++) + { +- s1[i] = toupper (1 + 23 * i % max_char); ++ s1[i] = toupper (1 + value); + s2[i] = tolower (s1[i]); ++ ++ value += step; ++ if (value >= (size_t) max_char) ++ value -= max_char; ++ } ++ ++ while (i < len) ++ { ++ size_t copy = i < len - i ? i : len - i; ++ ++ memcpy (s1 + i, s1, copy); ++ memcpy (s2 + i, s2, copy); ++ i += copy; + } + + s1[len] = s2[len] = 0; + +commit 16be1518495f1fa05481b0182c4e4c24927c62df +Author: Adhemerval Zanella +Date: Mon Aug 3 11:02:53 2026 -0300 + + elf: Honour skip_ifunc for cross-object IFUNC relocations [BZ #34428] + + Commit 63b31c05a8a ("elf: Defer all IRELATIVE relocations until after PLT + setup") dropped the skip_ifunc argument from elf_dynamic_do_Rel, assuming + the new deferred elf_dynamic_do_Rel_irelative pass handles every relocation + that may run an IFUNC resolver. That only holds for IFUNC symbols defined + in the object being relocated: a reference to an IFUNC in another object is + an ordinary JMP_SLOT or GLOB_DAT against an undefined symbol, and its IFUNC + nature is only known after symbol resolution inside elf_machine_rel. Those + relocations stay in the regular pass, which no longer propagated + skip_ifunc, so __RTLD_NOIFUNC was ignored for them. + + ldd -u forces non-lazy binding (GLRO(dl_lazy) = 0 for DL_DEBUG_UNUSED), so + the resolver was called and the diagnostic emitted: + + $ ldd -u /bin/ls + /bin/ls: Relink `' with `/usr/lib64/libc.so.6' for IFUNC symbol `__mempcpy_chk' + + ldd -r with LD_BIND_NOW is affected in the same way. + + Restore the skip_ifunc parameter and thread it through _ELF_DYNAMIC_DO_RELOC. + + This new semantic shows that ELF_DYNAMIC_RELOCATE_NOIFUNC naming is misleading + (it reads as "do not process IFUNC", yet it takes a skip_ifunc + argument). Replace it to: + + DL_RELOC_BOTH -> DL_RELOC_ALL + DL_RELOC_NOIFUNC -> DL_RELOC_NORMAL + DL_RELOC_IFUNC -> DL_RELOC_IRELATIVE + + ELF_DYNAMIC_RELOCATE_NOIFUNC and ELF_DYNAMIC_RELOCATE_IFUNC become a single + ELF_DYNAMIC_RELOCATE_PASS taking the pass as its first argument, and + ELF_DYNAMIC_DO_REL/ELF_DYNAMIC_DO_RELA take the pass instead of having three + near-identical variants each. + + Checked on x86_64-linux-gnu, and built for all supported architectures. + + Reviewed-by: Sam James + + (cherry picked from commit 2f2e9bae4093e1c3ba61250e340d3c3b99788f68) + +diff --git a/elf/Makefile b/elf/Makefile +index 8b063e1bba..d279a5135c 100644 +--- a/elf/Makefile ++++ b/elf/Makefile +@@ -1396,6 +1396,13 @@ modules-names += \ + tst-ifunc-tls-write-lib \ + tst-tls-tdata-reloc-lib \ + # modules-names ++ifeq (yes,$(have-gcc-ifunc)) ++tests += \ ++ tst-ifunc-fault-dep-bindnow \ ++ tst-ifunc-fault-dep-lazy \ ++ # tests ++modules-names += tst-ifunc-fault-mod ++endif + ifneq (no,$(have-test-mtls-descriptor)) + tests += tst-ifunc-tls-init-tlsdesc + modules-names += tst-ifunc-tls-init-tlsdesc-lib +@@ -2547,6 +2554,27 @@ $(objpfx)tst-ifunc-fault-bindnow.out: $(objpfx)tst-ifunc-fault-bindnow \ + $(objpfx)ld.so + $(tst-ifunc-fault-script) + ++LDFLAGS-tst-ifunc-fault-dep-lazy = -Wl,-z,lazy ++LDFLAGS-tst-ifunc-fault-dep-bindnow = -Wl,-z,now ++define tst-ifunc-fault-dep-script ++( $(test-wrapper) $(rtld-prefix) --verify $< \ ++ && $(test-wrapper-env) LD_TRACE_LOADED_OBJECTS=1 $(rtld-prefix) $< \ ++ && $(test-wrapper-env) LD_TRACE_LOADED_OBJECTS=1 LD_DEBUG=unused \ ++ $(rtld-prefix) $< \ ++ && $(test-wrapper-env) LD_TRACE_LOADED_OBJECTS=1 LD_WARN=yes LD_BIND_NOW=1 \ ++ $(rtld-prefix) $< \ ++) > $@; $(evaluate-test) ++endef ++$(objpfx)tst-ifunc-fault-dep-lazy: $(objpfx)tst-ifunc-fault-mod.so ++$(objpfx)tst-ifunc-fault-dep-bindnow: $(objpfx)tst-ifunc-fault-mod.so ++$(objpfx)tst-ifunc-fault-dep-lazy.out: $(objpfx)tst-ifunc-fault-dep-lazy \ ++ $(objpfx)tst-ifunc-fault-mod.so $(objpfx)ld.so ++ $(tst-ifunc-fault-dep-script) ++$(objpfx)tst-ifunc-fault-dep-bindnow.out: \ ++ $(objpfx)tst-ifunc-fault-dep-bindnow \ ++ $(objpfx)tst-ifunc-fault-mod.so $(objpfx)ld.so ++ $(tst-ifunc-fault-dep-script) ++ + LDFLAGS-tst-ifunc-plt-lib.so = -Wl,-z,lazy + + tst-ifunc-plt-bindnow-ENV = LD_BIND_NOW=1 +diff --git a/elf/dl-reloc-static-pie.c b/elf/dl-reloc-static-pie.c +index 8463e46147..5dc5a545a8 100644 +--- a/elf/dl-reloc-static-pie.c ++++ b/elf/dl-reloc-static-pie.c +@@ -80,7 +80,7 @@ _dl_relocate_static_pie (void) + + /* Relocate ourselves so we can do normal function calls and data access + using the global offset table. IRELATIVE entries are deferred. */ +- ELF_DYNAMIC_RELOCATE_NOIFUNC (main_map, NULL, 0, 0); ++ ELF_DYNAMIC_RELOCATE_PASS (DL_RELOC_NORMAL, main_map, NULL, 0, 0, 0); + + /* Initialize _r_debug_extended. */ + struct r_debug *r = _dl_debug_initialize (0, LM_ID_BASE); +@@ -98,7 +98,7 @@ void + _dl_relocate_static_pie_ifunc (void) + { + struct link_map *main_map = _dl_get_dl_main_map (); +- ELF_DYNAMIC_RELOCATE_IFUNC (main_map, NULL, 0, 0); ++ ELF_DYNAMIC_RELOCATE_PASS (DL_RELOC_IRELATIVE, main_map, NULL, 0, 0, 0); + main_map->l_relocated = 1; + } + #endif +diff --git a/elf/dl-reloc.c b/elf/dl-reloc.c +index 15a6a4cffe..fa2f41ac44 100644 +--- a/elf/dl-reloc.c ++++ b/elf/dl-reloc.c +@@ -278,7 +278,8 @@ _dl_relocate_object_no_relro (struct link_map *l, struct r_scope_elem *scope[], + IFUNC resolvers. Without this, a resolver would see the unrelocated + initialiser bytes that were placed into the slot by the early + _dl_allocate_tls_init. */ +- ELF_DYNAMIC_RELOCATE_NOIFUNC (l, scope, lazy, consider_profiling); ++ ELF_DYNAMIC_RELOCATE_PASS (DL_RELOC_NORMAL, l, scope, lazy, ++ consider_profiling, skip_ifunc); + + #ifdef SHARED + /* Re-initialise the static TLS slot with the .tdata so the IRELATIVE +@@ -291,7 +292,8 @@ _dl_relocate_object_no_relro (struct link_map *l, struct r_scope_elem *scope[], + _dl_init_static_tls (l); + #endif + +- ELF_DYNAMIC_RELOCATE_IFUNC (l, scope, lazy, skip_ifunc); ++ ELF_DYNAMIC_RELOCATE_PASS (DL_RELOC_IRELATIVE, l, scope, lazy, ++ 0, skip_ifunc); + + if ((consider_profiling || consider_symbind) + && l->l_info[DT_PLTRELSZ] != NULL) +diff --git a/elf/do-rel.h b/elf/do-rel.h +index 7702244734..c610d12dbe 100644 +--- a/elf/do-rel.h ++++ b/elf/do-rel.h +@@ -79,17 +79,23 @@ elf_dynamic_Rel_audit_symbind (struct link_map *map, + /* Perform the relocations in MAP on the running program image as specified + by RELTAG, SZTAG. If LAZY is nonzero, this is the first pass on PLT + relocations; they should be set up to call _dl_runtime_resolve, rather +- than fully resolved now. ++ than fully resolved now. If SKIP_IFUNC is nonzero no IFUNC resolver is ++ called; this is required for the trace modes (ldd -u / ldd -r), which ++ relocate objects. + +- IRELATIVE entries are always skipped (non-bootstrap); they are handled ++ IRELATIVE entries and relocations against an STT_GNU_IFUNC symbol defined ++ in MAP itself are always skipped (non-bootstrap); they are handled + separately by elf_dynamic_do_Rel_irelative after all other relocations +- for both .rel.dyn and .rel.plt have been processed. */ ++ for both .rel.dyn and .rel.plt have been processed. Relocations against ++ an IFUNC symbol defined in *another* object are not deferred, since the ++ IFUNC symbol is only known after symbol resolution, and the defining object ++ has already been relocated at this point. */ + + static inline void __attribute__ ((always_inline)) + elf_dynamic_do_Rel (struct link_map *map, struct r_scope_elem *scope[], + ElfW(Addr) reladdr, ElfW(Addr) relsize, + __typeof (((ElfW(Dyn) *) 0)->d_un.d_val) nrelative, +- int lazy) ++ int lazy, int skip_ifunc) + { + const ElfW(Rel) *relative = (const void *) reladdr; + const ElfW(Rel) *r = relative + nrelative; +@@ -111,7 +117,7 @@ elf_dynamic_do_Rel (struct link_map *map, struct r_scope_elem *scope[], + void *const r_addr_arg = (void *) (l_addr + r->r_offset); + const struct r_found_version *rversion = &map->l_versions[ndx]; + +- elf_machine_rel (map, scope, r, sym, rversion, r_addr_arg, 0); ++ elf_machine_rel (map, scope, r, sym, rversion, r_addr_arg, skip_ifunc); + } + #else /* !RTLD_BOOTSTRAP */ + #if !defined DO_RELA || !defined ELF_MACHINE_PLT_REL +@@ -126,7 +132,7 @@ elf_dynamic_do_Rel (struct link_map *map, struct r_scope_elem *scope[], + const ElfW (Sym) *sym = &symtab[ELFW (R_SYM) (r->r_info)]; + if (elf_dynamic_is_Rel_irelative (r, sym)) + continue; +- elf_machine_lazy_rel (map, scope, l_addr, r, 0); ++ elf_machine_lazy_rel (map, scope, l_addr, r, skip_ifunc); + } + } + else +@@ -158,7 +164,8 @@ elf_dynamic_do_Rel (struct link_map *map, struct r_scope_elem *scope[], + + if (elf_dynamic_is_Rel_irelative (r, sym)) + continue; +- elf_machine_rel (map, scope, r, sym, rversion, r_addr_arg, 0); ++ elf_machine_rel (map, scope, r, sym, rversion, r_addr_arg, ++ skip_ifunc); + elf_dynamic_Rel_audit_symbind (map, scope, r, sym, rversion, + r_addr_arg); + } +@@ -172,7 +179,8 @@ elf_dynamic_do_Rel (struct link_map *map, struct r_scope_elem *scope[], + + if (elf_dynamic_is_Rel_irelative (r, sym)) + continue; +- elf_machine_rel (map, scope, r, sym, NULL, r_addr_arg, 0); ++ elf_machine_rel (map, scope, r, sym, NULL, r_addr_arg, ++ skip_ifunc); + elf_dynamic_Rel_audit_symbind (map, scope, r, sym, NULL, + r_addr_arg); + } +diff --git a/elf/dynamic-link.h b/elf/dynamic-link.h +index 35141acec4..0130c63feb 100644 +--- a/elf/dynamic-link.h ++++ b/elf/dynamic-link.h +@@ -78,18 +78,23 @@ elf_machine_lazy_rel (struct link_map *map, struct r_scope_elem *scope[], + consumes precisely the very end of the DT_REL*, or DT_JMPREL and DT_REL* + are completely separate and there is a gap between them. */ + +-/* This controls which sub-passes _ELF_DYNAMIC_DO_RELOC runs. Used to +- interleave TLS / stack-protector setup between the two passes so IFUNC +- resolvers see a fully-initialised TCB. */ +-enum elf_dynamic_reloc_phase ++/* Selects which relocations a pass processes. Splitting them allows the ++ caller to interleave TLS / stack-protector setup between the two passes, ++ so IFUNC resolvers see a fully-initialised TCB. ++ ++ This is orthogonal to the skip_ifunc argument, which says whether an IFUNC ++ resolver may be run at all and is honoured by every pass. In particular ++ DL_RELOC_NORMAL also runs IFUNC resolvers, for relocations against an ++ IFUNC symbol defined in another object. */ ++enum elf_dynamic_reloc_pass + { +- DL_RELOC_BOTH = 0, /* Non-IRELATIVE pass then IRELATIVE pass. */ +- DL_RELOC_NOIFUNC = 1, /* Non-IRELATIVE pass only. */ +- DL_RELOC_IFUNC = 2, /* IRELATIVE pass only. */ ++ DL_RELOC_ALL = 0, /* Non-IRELATIVE relocations, then IRELATIVE. */ ++ DL_RELOC_NORMAL = 1, /* Non-IRELATIVE relocations only. */ ++ DL_RELOC_IRELATIVE = 2, /* IRELATIVE relocations only. */ + }; + + # define _ELF_DYNAMIC_DO_RELOC(RELOC, reloc, map, scope, do_lazy, skip_ifunc, \ +- test_rel, phase) \ ++ test_rel, pass) \ + do { \ + struct { ElfW(Addr) start, size; \ + __typeof (((ElfW(Dyn) *) 0)->d_un.d_val) nrelative; int lazy; } \ +@@ -136,14 +141,15 @@ enum elf_dynamic_reloc_phase + by the linker. */ \ + if (!DO_RTLD_BOOTSTRAP) \ + { \ +- if ((phase) != DL_RELOC_IFUNC) \ ++ if ((pass) != DL_RELOC_IRELATIVE) \ + for (int ranges_index = 0; ranges_index < 2; ++ranges_index) \ + elf_dynamic_do_##reloc ((map), scope, \ + ranges[ranges_index].start, \ + ranges[ranges_index].size, \ + ranges[ranges_index].nrelative, \ +- ranges[ranges_index].lazy); \ +- if ((phase) != DL_RELOC_NOIFUNC) \ ++ ranges[ranges_index].lazy, \ ++ skip_ifunc); \ ++ if ((pass) != DL_RELOC_NORMAL) \ + for (int ranges_index = 0; ranges_index < 2; ++ranges_index) \ + elf_dynamic_do_##reloc##_irelative ((map), scope, \ + ranges[ranges_index].start, \ +@@ -158,7 +164,8 @@ enum elf_dynamic_reloc_phase + ranges[ranges_index].start, \ + ranges[ranges_index].size, \ + ranges[ranges_index].nrelative, \ +- ranges[ranges_index].lazy); \ ++ ranges[ranges_index].lazy, \ ++ skip_ifunc); \ + } while (0) + + # if ELF_MACHINE_NO_REL || ELF_MACHINE_NO_RELA +@@ -169,37 +176,21 @@ enum elf_dynamic_reloc_phase + + # if ! ELF_MACHINE_NO_REL + # include "do-rel.h" +-# define ELF_DYNAMIC_DO_REL(map, scope, lazy, skip_ifunc) \ +- _ELF_DYNAMIC_DO_RELOC (REL, Rel, map, scope, lazy, skip_ifunc, \ +- _ELF_CHECK_REL, DL_RELOC_BOTH) +-# define ELF_DYNAMIC_DO_REL_NOIFUNC(map, scope, lazy) \ +- _ELF_DYNAMIC_DO_RELOC (REL, Rel, map, scope, lazy, 0, \ +- _ELF_CHECK_REL, DL_RELOC_NOIFUNC) +-# define ELF_DYNAMIC_DO_REL_IFUNCONLY(map, scope, lazy, skip_ifunc) \ ++# define ELF_DYNAMIC_DO_REL(map, scope, lazy, skip_ifunc, pass) \ + _ELF_DYNAMIC_DO_RELOC (REL, Rel, map, scope, lazy, skip_ifunc, \ +- _ELF_CHECK_REL, DL_RELOC_IFUNC) ++ _ELF_CHECK_REL, pass) + # else +-# define ELF_DYNAMIC_DO_REL(map, scope, lazy, skip_ifunc) /* Nothing to do. */ +-# define ELF_DYNAMIC_DO_REL_NOIFUNC(map, scope, lazy) /* Nothing to do. */ +-# define ELF_DYNAMIC_DO_REL_IFUNCONLY(map, scope, lazy, skip_ifunc) /* Nothing. */ ++# define ELF_DYNAMIC_DO_REL(map, scope, lazy, skip_ifunc, pass) /* Nothing. */ + # endif + + # if ! ELF_MACHINE_NO_RELA + # define DO_RELA + # include "do-rel.h" +-# define ELF_DYNAMIC_DO_RELA(map, scope, lazy, skip_ifunc) \ +- _ELF_DYNAMIC_DO_RELOC (RELA, Rela, map, scope, lazy, skip_ifunc, \ +- _ELF_CHECK_REL, DL_RELOC_BOTH) +-# define ELF_DYNAMIC_DO_RELA_NOIFUNC(map, scope, lazy) \ +- _ELF_DYNAMIC_DO_RELOC (RELA, Rela, map, scope, lazy, 0, \ +- _ELF_CHECK_REL, DL_RELOC_NOIFUNC) +-# define ELF_DYNAMIC_DO_RELA_IFUNCONLY(map, scope, lazy, skip_ifunc) \ ++# define ELF_DYNAMIC_DO_RELA(map, scope, lazy, skip_ifunc, pass) \ + _ELF_DYNAMIC_DO_RELOC (RELA, Rela, map, scope, lazy, skip_ifunc, \ +- _ELF_CHECK_REL, DL_RELOC_IFUNC) ++ _ELF_CHECK_REL, pass) + # else +-# define ELF_DYNAMIC_DO_RELA(map, scope, lazy, skip_ifunc) /* Nothing to do. */ +-# define ELF_DYNAMIC_DO_RELA_NOIFUNC(map, scope, lazy) /* Nothing to do. */ +-# define ELF_DYNAMIC_DO_RELA_IFUNCONLY(map, scope, lazy, skip_ifunc) /* Nothing. */ ++# define ELF_DYNAMIC_DO_RELA(map, scope, lazy, skip_ifunc, pass) /* Nothing. */ + # endif + + # define ELF_DYNAMIC_DO_RELR(map) \ +@@ -240,37 +231,33 @@ enum elf_dynamic_reloc_phase + # else + # define DO_RTLD_BOOTSTRAP 0 + # endif +-# define ELF_DYNAMIC_RELOCATE(map, scope, lazy, consider_profile, skip_ifunc) \ +- do { \ +- int edr_lazy = elf_machine_runtime_setup ((map), (scope), (lazy), \ +- (consider_profile)); \ +- if (!is_rtld_link_map (map) || DO_RTLD_BOOTSTRAP) \ +- ELF_DYNAMIC_DO_RELR (map); \ +- ELF_DYNAMIC_DO_REL ((map), (scope), edr_lazy, skip_ifunc); \ +- ELF_DYNAMIC_DO_RELA ((map), (scope), edr_lazy, skip_ifunc); \ +- ELF_DYNAMIC_AFTER_RELOC ((map), (edr_lazy)); \ +- } while (0) ++/* Perform one relocation pass over MAP. PASS selects which relocations are ++ processed. It is orthogonal to SKIP_IFUNC, which suppresses running IFUNC ++ resolvers in whichever pass is selected. + +-/* Like ELF_DYNAMIC_RELOCATE but only processes the non-IRELATIVE pass. +- The IRELATIVE pass must be completed later via ELF_DYNAMIC_RELOCATE_IFUNC. +- Used by the static-pie startup so the TCB and stack-protector canary can +- be initialised between the two passes. */ +-# define ELF_DYNAMIC_RELOCATE_NOIFUNC(map, scope, lazy, consider_profile) \ ++ Unless PASS is DL_RELOC_IRELATIVE, this also performs the machine-specific ++ PLT/GOT setup, the DT_RELR relocations, and the ELF_DYNAMIC_AFTER_RELOC ++ hook. */ ++# define ELF_DYNAMIC_RELOCATE_PASS(pass, map, scope, lazy, consider_profile, \ ++ skip_ifunc) \ + do { \ +- int edr_lazy = elf_machine_runtime_setup ((map), (scope), (lazy), \ ++ int edr_lazy = (lazy); \ ++ if ((pass) != DL_RELOC_IRELATIVE) \ ++ { \ ++ edr_lazy = elf_machine_runtime_setup ((map), (scope), (lazy), \ + (consider_profile)); \ +- if (!is_rtld_link_map (map) || DO_RTLD_BOOTSTRAP) \ +- ELF_DYNAMIC_DO_RELR (map); \ +- ELF_DYNAMIC_DO_REL_NOIFUNC ((map), (scope), edr_lazy); \ +- ELF_DYNAMIC_DO_RELA_NOIFUNC ((map), (scope), edr_lazy); \ +- ELF_DYNAMIC_AFTER_RELOC ((map), (edr_lazy)); \ ++ if (!is_rtld_link_map (map) || DO_RTLD_BOOTSTRAP) \ ++ ELF_DYNAMIC_DO_RELR (map); \ ++ } \ ++ ELF_DYNAMIC_DO_REL ((map), (scope), edr_lazy, skip_ifunc, (pass)); \ ++ ELF_DYNAMIC_DO_RELA ((map), (scope), edr_lazy, skip_ifunc, (pass)); \ ++ if ((pass) != DL_RELOC_IRELATIVE) \ ++ ELF_DYNAMIC_AFTER_RELOC ((map), edr_lazy); \ + } while (0) + +-/* IRELATIVE-only companion to ELF_DYNAMIC_RELOCATE_NOIFUNC. */ +-# define ELF_DYNAMIC_RELOCATE_IFUNC(map, scope, lazy, skip_ifunc) \ +- do { \ +- ELF_DYNAMIC_DO_REL_IFUNCONLY ((map), (scope), (lazy), skip_ifunc); \ +- ELF_DYNAMIC_DO_RELA_IFUNCONLY ((map), (scope), (lazy), skip_ifunc); \ +- } while (0) ++/* Run both passes back to back, for callers with nothing to interleave. */ ++# define ELF_DYNAMIC_RELOCATE(map, scope, lazy, consider_profile, skip_ifunc) \ ++ ELF_DYNAMIC_RELOCATE_PASS (DL_RELOC_ALL, (map), (scope), (lazy), \ ++ (consider_profile), skip_ifunc) + + #endif +diff --git a/elf/tst-ifunc-fault-dep-bindnow.c b/elf/tst-ifunc-fault-dep-bindnow.c +new file mode 100644 +index 0000000000..60d97dcaa4 +--- /dev/null ++++ b/elf/tst-ifunc-fault-dep-bindnow.c +@@ -0,0 +1,19 @@ ++/* Program calling an IFUNC defined in a dependency. BIND_NOW variant. ++ Copyright (C) 2026 Free Software Foundation, Inc. ++ This file is part of the GNU C Library. ++ ++ The GNU C Library is free software; you can redistribute it and/or ++ modify it under the terms of the GNU Lesser General Public ++ License as published by the Free Software Foundation; either ++ version 2.1 of the License, or (at your option) any later version. ++ ++ The GNU C Library is distributed in the hope that it will be useful, ++ but WITHOUT ANY WARRANTY; without even the implied warranty of ++ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU ++ Lesser General Public License for more details. ++ ++ You should have received a copy of the GNU Lesser General Public ++ License along with the GNU C Library; if not, see ++ . */ ++ ++#include "tst-ifunc-fault-dep-lazy.c" +diff --git a/elf/tst-ifunc-fault-dep-lazy.c b/elf/tst-ifunc-fault-dep-lazy.c +new file mode 100644 +index 0000000000..122d33f391 +--- /dev/null ++++ b/elf/tst-ifunc-fault-dep-lazy.c +@@ -0,0 +1,27 @@ ++/* Program calling an IFUNC defined in a dependency (BZ 34428). ++ Copyright (C) 2026 Free Software Foundation, Inc. ++ This file is part of the GNU C Library. ++ ++ The GNU C Library is free software; you can redistribute it and/or ++ modify it under the terms of the GNU Lesser General Public ++ License as published by the Free Software Foundation; either ++ version 2.1 of the License, or (at your option) any later version. ++ ++ The GNU C Library is distributed in the hope that it will be useful, ++ but WITHOUT ANY WARRANTY; without even the implied warranty of ++ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU ++ Lesser General Public License for more details. ++ ++ You should have received a copy of the GNU Lesser General Public ++ License along with the GNU C Library; if not, see ++ . */ ++ ++extern void magic (void); ++ ++int ++main (void) ++{ ++ /* JMP_SLOT relocation against an undefined symbol. */ ++ magic (); ++ return 1; ++} +diff --git a/elf/tst-ifunc-fault-mod.c b/elf/tst-ifunc-fault-mod.c +new file mode 100644 +index 0000000000..11c21b48ac +--- /dev/null ++++ b/elf/tst-ifunc-fault-mod.c +@@ -0,0 +1,38 @@ ++/* Shared object exporting an IFUNC symbol with a resolver which crashes. ++ Copyright (C) 2026 Free Software Foundation, Inc. ++ This file is part of the GNU C Library. ++ ++ The GNU C Library is free software; you can redistribute it and/or ++ modify it under the terms of the GNU Lesser General Public ++ License as published by the Free Software Foundation; either ++ version 2.1 of the License, or (at your option) any later version. ++ ++ The GNU C Library is distributed in the hope that it will be useful, ++ but WITHOUT ANY WARRANTY; without even the implied warranty of ++ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU ++ Lesser General Public License for more details. ++ ++ You should have received a copy of the GNU Lesser General Public ++ License along with the GNU C Library; if not, see ++ . */ ++ ++#include ++ ++static void ++implementation (void) ++{ ++ /* Produce a crash, without depending on any relocations. */ ++ volatile char *volatile p = NULL; ++ *p = 0; ++} ++ ++static __typeof__ (implementation) * ++resolver (void) ++{ ++ /* Produce a crash, without depending on any relocations. */ ++ volatile char *volatile p = NULL; ++ *p = 0; ++ return implementation; ++} ++ ++void magic (void) __attribute__ ((ifunc ("resolver"))); + +commit afd131806b25715a7617ab757db43f0bb610acbf +Author: Adhemerval Zanella +Date: Wed Aug 12 09:03:17 2026 -0300 + + m68k: Fix fmod/fmodf infinite recursion (BZ 34508) + + Commits 6deadd4eb6a and ade9f30ce27 changed m68k fmod to call + __m81_u(fmod), instead of the mathimpl.h inline + __m81_u(__ieee754_fmod) (that wraps the m68k fmod instruction). + This leads to infinite recursion. + + Tested-by: John Paul Adrian Glaubitz + + (cherry picked from commit bb213471bedc177b8efd3178584137fb81cc976a) + +diff --git a/NEWS b/NEWS +index d0ef2d3e9a..697049efd1 100644 +--- a/NEWS ++++ b/NEWS +@@ -18,6 +18,8 @@ The following bugs are resolved with this release: + [34441] math: math: sinh() returns wrong results for some inputs with + |x| > 36.736801 + [34465] math: math: x86_64 tanh ifunc selection wrong ++ [34509] libc: [m68k] Regression: Perl locks up after upgrading glibc ++ to 2.43 + + Version 2.44 + +diff --git a/sysdeps/m68k/m680x0/fpu/e_fmod.c b/sysdeps/m68k/m680x0/fpu/e_fmod.c +index 9ad6924422..faac7c79e3 100644 +--- a/sysdeps/m68k/m680x0/fpu/e_fmod.c ++++ b/sysdeps/m68k/m680x0/fpu/e_fmod.c +@@ -33,7 +33,7 @@ __fmod (double x, double y) + && !is_nan (hx))) + return __math_invalid (x); + +- return __m81_u(fmod)(x, y); ++ return __m81_u(__ieee754_fmod)(x, y); + } + strong_alias (__fmod, __ieee754_fmod) + libm_alias_finite (__ieee754_fmod, __fmod) +diff --git a/sysdeps/m68k/m680x0/fpu/e_fmodf.c b/sysdeps/m68k/m680x0/fpu/e_fmodf.c +index a3bd24b71f..98797e0887 100644 +--- a/sysdeps/m68k/m680x0/fpu/e_fmodf.c ++++ b/sysdeps/m68k/m680x0/fpu/e_fmodf.c +@@ -34,7 +34,7 @@ __fmodf (float x, float y) + && !is_nan (hx))) + return __math_invalidf (x); + +- return __m81_u(fmodf)(x, y); ++ return __m81_u(__ieee754_fmodf)(x, y); + } + strong_alias (__fmodf, __ieee754_fmodf) + versioned_symbol (libm, __fmodf, fmodf, GLIBC_2_43); diff --git a/pkgs/development/libraries/glibc/common.nix b/pkgs/development/libraries/glibc/common.nix index 4db1dac187ed..ab415d5b932f 100644 --- a/pkgs/development/libraries/glibc/common.nix +++ b/pkgs/development/libraries/glibc/common.nix @@ -50,9 +50,9 @@ }@args: let - version = "2.42"; - patchSuffix = "-84"; - sha256 = "sha256-0XdeMuRijmTvkw9DW2e7Y691may2viszW58Z8WUJ8X8="; + version = "2.44"; + patchSuffix = "-25"; + sha256 = "sha256-N/YA8r7zxegwAUcFlWiyouQKetbMxlzpQlVtSUKcxmc="; in assert withLinuxHeaders -> linuxHeaders != null; @@ -69,17 +69,17 @@ stdenv.mkDerivation ( /* No tarballs for stable upstream branch, only https://sourceware.org/git/glibc.git and using git would complicate bootstrapping. $ git fetch --all -p && git checkout origin/release/2.42/master && git describe - glibc-2.42-67-g4ebd33dd77 - $ git show --minimal --reverse glibc-2.42.. ':!ADVISORIES' > 2.42-master.patch + glibc-2.44-25-gafd131806b + $ git show --minimal --reverse glibc-2.44.. ':!ADVISORIES' > 2.44-master.patch To compare the archive contents zdiff can be used. - $ diff -u 2.42-master.patch ../nixpkgs/pkgs/development/libraries/glibc/2.42-master.patch + $ diff -u 2.44-master.patch ../nixpkgs/pkgs/development/libraries/glibc/2.44-master.patch Please note that each commit has changes to the file ADVISORIES excluded since that conflicts with the directory advisories/ making cross-builds from hosts with case-insensitive file-systems impossible. */ - ./2.42-master.patch + ./2.44-master.patch # Allow NixOS and Nix to handle the locale-archive. ./nix-locale-archive.patch diff --git a/pkgs/development/libraries/glibc/dont-use-system-ld-so-cache.patch b/pkgs/development/libraries/glibc/dont-use-system-ld-so-cache.patch index 0e0315aca270..f9f3f815bbad 100644 --- a/pkgs/development/libraries/glibc/dont-use-system-ld-so-cache.patch +++ b/pkgs/development/libraries/glibc/dont-use-system-ld-so-cache.patch @@ -1,8 +1,8 @@ diff --git a/elf/Makefile b/elf/Makefile -index 5d666b1b..a5017e9c 100644 +index dc39ccea60..3230939376 100644 --- a/elf/Makefile +++ b/elf/Makefile -@@ -669,14 +669,14 @@ $(objpfx)sln: $(sln-modules:%=$(objpfx)%.o) +@@ -1745,14 +1745,14 @@ $(objpfx)sln: $(sln-modules:%=$(objpfx)%.o) $(objpfx)ldconfig: $(ldconfig-modules:%=$(objpfx)%.o) @@ -21,36 +21,41 @@ index 5d666b1b..a5017e9c 100644 +CFLAGS-rtld.c += $(PREFIX-FLAGS) +CFLAGS-dl-usage.c += $(PREFIX-FLAGS) \ -D'RTLD="$(rtlddir)/$(rtld-installed-name)"' - - cpp-srcs-left := $(all-rtld-routines:=.os) + CFLAGS-dl-diagnostics.c += $(SYSCONF-FLAGS) \ + -D'PREFIX="$(prefix)"' \ diff --git a/elf/dl-diagnostics.c b/elf/dl-diagnostics.c -index bef224b3..8e166b12 100644 +index 21311178c7..719e02f8e6 100644 --- a/elf/dl-diagnostics.c +++ b/elf/dl-diagnostics.c -@@ -205,7 +205,7 @@ print_paths (void) +@@ -204,7 +204,7 @@ print_paths (void) { _dl_diagnostics_print_labeled_string ("path.prefix", PREFIX); _dl_diagnostics_print_labeled_string ("path.rtld", RTLD); - _dl_diagnostics_print_labeled_string ("path.sysconfdir", SYSCONFDIR); + _dl_diagnostics_print_labeled_string ("path.sysconfdir", PREFIX "/etc"); - + unsigned int index = 0; static const char *system_dirs = SYSTEM_DIRS "\0"; diff --git a/elf/ldconfig.c b/elf/ldconfig.c -index 28ed637a..6f07b79a 100644 +index a39f3ecfcd..b5f12d0760 100644 --- a/elf/ldconfig.c +++ b/elf/ldconfig.c -@@ -57,7 +57,7 @@ - #define TLS_HWCAP_BIT 63 +@@ -48,11 +48,11 @@ + #ifndef LD_SO_CONF -# define LD_SO_CONF SYSCONFDIR "/ld.so.conf" +# define LD_SO_CONF PREFIX "/etc/ld.so.conf" #endif + #ifndef TUNABLES_CONF +-# define TUNABLES_CONF SYSCONFDIR "/tunables.conf" ++# define TUNABLES_CONF PREFIX "/etc/tunables.conf" + #endif + /* Get libc version number. */ diff --git a/sysdeps/generic/dl-cache.h b/sysdeps/generic/dl-cache.h -index 964d50a4..2224d651 100644 +index 972ab32b86..a0e0775506 100644 --- a/sysdeps/generic/dl-cache.h +++ b/sysdeps/generic/dl-cache.h @@ -35,7 +35,7 @@ From 67bbac951c1c9c08ae87b0c471f67d245eb68f7a Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Mon, 31 Aug 2026 21:19:31 +0200 Subject: [PATCH 318/423] libfaketime: fix build w/ glibc-2.44 Failing Hydra Build: https://hydra.nixos.org/build/344162647 I'm aware that there's a 0.9.13 containing this patch, but given the fallout according to the comment, i.e. > 0.9.10 break dict-db-wiktionary and quartus-prime-lite on linux, > and 0.9.11 break everything on darwin I'm not going to look into this and pick the easy route for now, i.e. fixing the fallout of glibc which is what I'm here for. --- pkgs/by-name/li/libfaketime/package.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkgs/by-name/li/libfaketime/package.nix b/pkgs/by-name/li/libfaketime/package.nix index 1e9667b83fba..7bc9995e09d8 100644 --- a/pkgs/by-name/li/libfaketime/package.nix +++ b/pkgs/by-name/li/libfaketime/package.nix @@ -34,6 +34,11 @@ stdenv.mkDerivation (finalAttrs: { patches = [ ./nix-store-date.patch + # Fixes build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/wolfcw/libfaketime/commit/dbe865dfdba0145d993d70b7fd4ec88b2f47554b.patch"; + hash = "sha256-pn9MInefa4ZKuOorGEpi/sDQOQamCakjdYOkFSNA2VQ="; + }) ] ++ lib.optionals (!stdenv.hostPlatform.isDarwin) [ # GCC 16's unused variable analysis is more advanced than previous From 342e877fdd502ef884fd6067d887162f410c883b Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 17:14:33 +0200 Subject: [PATCH 319/423] aerospike: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344139672 --- pkgs/by-name/ae/aerospike/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/ae/aerospike/package.nix b/pkgs/by-name/ae/aerospike/package.nix index b90753491800..1818ad0f0e60 100644 --- a/pkgs/by-name/ae/aerospike/package.nix +++ b/pkgs/by-name/ae/aerospike/package.nix @@ -33,6 +33,9 @@ stdenv.mkDerivation (finalAttrs: { zlib ]; + # glibc 2.43 C23 const-preserving strchr/strstr macros + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + dontUseCmakeConfigure = true; preBuild = '' From 4b4ab898550e64635ba64c5ad3cb5d8bacfa2029 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 17:17:23 +0200 Subject: [PATCH 320/423] tayga: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344210014 --- pkgs/by-name/ta/tayga/package.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/pkgs/by-name/ta/tayga/package.nix b/pkgs/by-name/ta/tayga/package.nix index c153319c1677..5efecdef4648 100644 --- a/pkgs/by-name/ta/tayga/package.nix +++ b/pkgs/by-name/ta/tayga/package.nix @@ -24,6 +24,12 @@ stdenv.mkDerivation (finalAttrs: { url = "https://github.com/apalrd/tayga/commit/b41bd030846451d72b277854678b58370b1d5c8f.patch?full_index=1"; hash = "sha256-vFQTlZs9ghxdx4k/iODDOUBAglyll1OxUdTjzDtcwB0="; }) + + # Fix build w/ glibc-2.44 + (fetchpatch2 { + url = "https://github.com/apalrd/tayga/commit/807fe4e4510e697fef6916cd76d393a8ab8e495e.patch?full_index=1"; + hash = "sha256-JqRKv5ZAlypQxYvhctBKPdWgC6Opxo1IV1niS5v2CfY="; + }) ]; makeFlags = [ From facdfe4daba09ebed4e4a3ae1eaad9915e119617 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 17:19:06 +0200 Subject: [PATCH 321/423] target-isns: fix build w/ glibc-2.44 ChangeLog: https://hydra.nixos.org/build/344209981 --- pkgs/by-name/ta/target-isns/package.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/pkgs/by-name/ta/target-isns/package.nix b/pkgs/by-name/ta/target-isns/package.nix index b7c9d8f9eba1..cedaf1f35604 100644 --- a/pkgs/by-name/ta/target-isns/package.nix +++ b/pkgs/by-name/ta/target-isns/package.nix @@ -32,6 +32,12 @@ stdenv.mkDerivation (finalAttrs: { url = "https://github.com/open-iscsi/target-isns/commit/e209821423f936d1cc9b946fb8f7a8979b8e751b.patch?full_index=1"; hash = "sha256-86nl8wTiI9WSZ+Hhw/a9VtgS8OLqoFwiot5iU5IK0f8="; }) + + # Fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/open-iscsi/target-isns/commit/d3645f0c357b2b14fb682fa2cd4ba3621efc4cea.patch"; + hash = "sha256-/ew+B4WDF2s5bjfPLZ7glHW+o/pRTI7zPHLTDh+n4lY="; + }) ]; cmakeFlags = [ "-DSUPPORT_SYSTEMD=ON" ]; From ce4117f12e8a0e343ca6181f3aeac2d3aad520e6 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 17:23:26 +0200 Subject: [PATCH 322/423] ucode: fix build w/ glibc-2.44 Also apply two more bugfixes to correctly apply the patch fixing the issue. Failing Hydra build: https://hydra.nixos.org/build/344213888 --- pkgs/by-name/uc/ucode/package.nix | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/pkgs/by-name/uc/ucode/package.nix b/pkgs/by-name/uc/ucode/package.nix index a8309fbc4e26..ed014133c91d 100644 --- a/pkgs/by-name/uc/ucode/package.nix +++ b/pkgs/by-name/uc/ucode/package.nix @@ -5,6 +5,7 @@ cmake, pkg-config, json_c, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -18,6 +19,22 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-V8WGd4rSuCtGIA5oTfnagp0Dmh5FNG87/MJSeILtbM4="; }; + patches = [ + (fetchpatch { + url = "https://github.com/jow-/ucode/commit/4d81e6c13506599261208786cfe4ee068f346dcd.patch"; + hash = "sha256-RZhD422ue00bqam4n7jAynPDJdOzOFJnf34YbT2wH/s="; + }) + (fetchpatch { + url = "https://github.com/jow-/ucode/commit/a7ead3169ebf355e66b399aca1dd3a5ce29e1e5b.patch"; + hash = "sha256-sc+jSAlix1jE9Cb4MMuqI7VHG6h+zpCL7UZ84awOL6M="; + }) + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/jow-/ucode/commit/beafcff845fcdbb46308ee54422661e80300079d.patch"; + hash = "sha256-JcBk8kJHDlHLRuVR2fmsSfWqVmbFZMPF16+nPp6QFf4="; + }) + ]; + buildInputs = [ json_c ]; From 52724515a3fd6a4c59ac4cd28698bcc67359292b Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 17:25:44 +0200 Subject: [PATCH 323/423] termpaint: fix build w/ glibc-2.44 ChangeLog: https://hydra.nixos.org/build/344210222 --- pkgs/by-name/te/termpaint/package.nix | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/te/termpaint/package.nix b/pkgs/by-name/te/termpaint/package.nix index b9cc6217119d..9656eb68d8e9 100644 --- a/pkgs/by-name/te/termpaint/package.nix +++ b/pkgs/by-name/te/termpaint/package.nix @@ -6,6 +6,7 @@ ninja, pkg-config, python3, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { pname = "termpaint"; @@ -18,7 +19,15 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-7mfGTC5vJ4806bDbrPMSVthtW05a+M3vgUlHGbtaI4Q="; }; - patches = [ ./0001-meson.build-use-prefix.patch ]; + patches = [ + ./0001-meson.build-use-prefix.patch + + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/termpaint/termpaint/commit/6164fb5ff17fd3d05bf44e942539082aa71a2ff3.patch"; + hash = "sha256-rTI0ZdJ6Q/a7M73igihd+4EZT9l6l+7oHGUnKmB5n0o="; + }) + ]; nativeBuildInputs = [ meson From 80c900a82e14162f93fc5f3326a68fd1bd5fd2a1 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 17:46:07 +0200 Subject: [PATCH 324/423] libbpf_0: drop Doesn't build with glibc 2.44 and hasn't seen a release in four years. Suricata builds fine with pkgs.libbpf. --- pkgs/by-name/su/suricata/package.nix | 4 +- pkgs/os-specific/linux/libbpf/0.x.nix | 70 --------------------------- pkgs/top-level/aliases.nix | 1 + pkgs/top-level/all-packages.nix | 1 - 4 files changed, 3 insertions(+), 73 deletions(-) delete mode 100644 pkgs/os-specific/linux/libbpf/0.x.nix diff --git a/pkgs/by-name/su/suricata/package.nix b/pkgs/by-name/su/suricata/package.nix index b4c2782e8eb2..5dac04bb6ed9 100644 --- a/pkgs/by-name/su/suricata/package.nix +++ b/pkgs/by-name/su/suricata/package.nix @@ -8,7 +8,7 @@ elfutils, file, jansson, - libbpf_0, + libbpf, libcap_ng, libevent, libmaxminddb, @@ -67,7 +67,7 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ elfutils jansson - libbpf_0 + libbpf libcap_ng libevent libmagic diff --git a/pkgs/os-specific/linux/libbpf/0.x.nix b/pkgs/os-specific/linux/libbpf/0.x.nix deleted file mode 100644 index 7d5676be8c0a..000000000000 --- a/pkgs/os-specific/linux/libbpf/0.x.nix +++ /dev/null @@ -1,70 +0,0 @@ -{ - fetchFromGitHub, - elfutils, - pkg-config, - stdenv, - zlib, - lib, - nixosTests, -}: - -# update bot does not seem to limit updates here to 0.8.x despite -# the all-packages derivation being libbpf_0 as the libbpf base alias -# is still present: just disable it for 0.x: -# nixpkgs-update: no auto update - -stdenv.mkDerivation rec { - pname = "libbpf"; - version = "0.8.3"; - - src = fetchFromGitHub { - owner = "libbpf"; - repo = "libbpf"; - rev = "v${version}"; - sha256 = "sha256-J5cUvfUYc+uLdkFa2jx/2bqBoZg/eSzc6SWlgKqcfIc="; - }; - - nativeBuildInputs = [ pkg-config ]; - buildInputs = [ - elfutils - zlib - ]; - - enableParallelBuilding = true; - makeFlags = [ - "PREFIX=$(out)" - "-C src" - ]; - - passthru.tests = { - bpf = nixosTests.bpf; - }; - - postInstall = '' - # install linux's libbpf-compatible linux/btf.h - install -Dm444 include/uapi/linux/*.h -t $out/include/linux - ''; - - # FIXME: Multi-output requires some fixes to the way the pkg-config file is - # constructed (it gets put in $out instead of $dev for some reason, with - # improper paths embedded). Don't enable it for now. - - # outputs = [ "out" "dev" ]; - - meta = { - description = "Upstream mirror of libbpf"; - homepage = "https://github.com/libbpf/libbpf"; - license = with lib.licenses; [ - lgpl21 # or - bsd2 - ]; - maintainers = with lib.maintainers; [ - thoughtpolice - vcunat - saschagrunert - martinetd - ]; - platforms = lib.platforms.linux; - identifiers.cpeParts = lib.meta.cpeFullVersionWithVendor "libbpf_project" version; - }; -} diff --git a/pkgs/top-level/aliases.nix b/pkgs/top-level/aliases.nix index e2eea662635f..79b886d1de47 100644 --- a/pkgs/top-level/aliases.nix +++ b/pkgs/top-level/aliases.nix @@ -1331,6 +1331,7 @@ mapAliases { libayatana-indicator-gtk3 = throw "'libayatana-indicator-gtk3' has been renamed to/replaced by 'libayatana-indicator'"; # Converted to throw 2025-10-27 libbaseencode = throw "'libbaseencode' has been removed because it was deprecated and archived upstream. Consider using 'libcotp' instead"; # Added 2026-01-15 libbencodetools = throw "'libbencodetools' has been renamed to/replaced by 'bencodetools'"; # Converted to throw 2025-10-27 + libbpf_0 = throw "'libbpf_0' has been removed since it's EOL for four years"; # Added 2026-09-03 libbpf_1 = throw "'libbpf_1' has been renamed to/replaced by 'libbpf'"; # Converted to throw 2025-10-27 libbson = throw "'libbson' has been renamed to/replaced by 'mongoc'"; # Converted to throw 2025-10-27 libcanberra-gtk2 = throw "'libcanberra-gtk2' has been removed as it depended on the deprecated GTK 2 engine. Consider using 'libcanberra-gtk3' instead."; # Added 2026-08-10 diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 7822c324636a..029cc1a77247 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -4909,7 +4909,6 @@ with pkgs; }; libbpf = callPackage ../os-specific/linux/libbpf { }; - libbpf_0 = callPackage ../os-specific/linux/libbpf/0.x.nix { }; bundlewrap = with python3.pkgs; toPythonApplication bundlewrap; From 2036e92086bb90fdc15c271ae3cb4f2b128c2025 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 18:10:52 +0200 Subject: [PATCH 325/423] mir_2_15: mark as broken It's deeply questionable that this exists in the first place, this release is three years old now. For the sake of not ripping out a full desktop environment[1], I'm leaving it in for now. Failing Hydra build: https://hydra.nixos.org/build/344169110 [1] Lomiri and the build fails with `pkgs.mir` --- pkgs/servers/mir/common.nix | 2 ++ pkgs/servers/mir/default.nix | 1 + 2 files changed, 3 insertions(+) diff --git a/pkgs/servers/mir/common.nix b/pkgs/servers/mir/common.nix index 28a2d5f566bf..8693a3027011 100644 --- a/pkgs/servers/mir/common.nix +++ b/pkgs/servers/mir/common.nix @@ -53,6 +53,7 @@ { version, pinned ? false, + broken ? false, hash, cargoHash ? null, patches ? [ ], @@ -298,6 +299,7 @@ stdenv.mkDerivation ( }; meta = { + inherit broken; description = "Display server and Wayland compositor developed by Canonical"; homepage = "https://mir-server.io"; changelog = "https://github.com/canonical/mir/releases/tag/v${finalAttrs.version}"; diff --git a/pkgs/servers/mir/default.nix b/pkgs/servers/mir/default.nix index 873dca525581..e3044d42d221 100644 --- a/pkgs/servers/mir/default.nix +++ b/pkgs/servers/mir/default.nix @@ -11,6 +11,7 @@ in }; mir_2_15 = common { + broken = true; # doesn't build with glibc 2.44 version = "2.15.0"; pinned = true; hash = "sha256-c1+gxzLEtNCjR/mx76O5QElQ8+AO4WsfcG7Wy1+nC6E="; From ac80cd0e95571b5427d70234a8e9ea4caa185498 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 18:18:28 +0200 Subject: [PATCH 326/423] trurl: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344213650 --- ...build-constify-strchr-memchr-results.patch | 146 ++++++++++++++++++ pkgs/by-name/tr/trurl/package.nix | 9 +- 2 files changed, 154 insertions(+), 1 deletion(-) create mode 100644 pkgs/by-name/tr/trurl/0001-build-constify-strchr-memchr-results.patch diff --git a/pkgs/by-name/tr/trurl/0001-build-constify-strchr-memchr-results.patch b/pkgs/by-name/tr/trurl/0001-build-constify-strchr-memchr-results.patch new file mode 100644 index 000000000000..eb43174b2f28 --- /dev/null +++ b/pkgs/by-name/tr/trurl/0001-build-constify-strchr-memchr-results.patch @@ -0,0 +1,146 @@ +From f081fc506e0e53f671f02ebac8b324f3fd421ee8 Mon Sep 17 00:00:00 2001 +From: Viktor Szakats +Date: Sun, 1 Mar 2026 11:39:41 +0100 +Subject: [PATCH] build: constify `strchr()`/`memchr()` results + +To fix building with glibc-2.43. +(also seen with gcc 16 on Fedora rawhide/f44) + +Also: +- scope a variable while there. +- fix altering the const format buffer on bad syntax. + +Reported-by: Gustavo Costa +Fixes #430 +Reported-by: Michael Ablassmeier +Fixes #431 + +Closes #432 +--- + trurl.c | 37 +++++++++++++++++++------------------ + 1 file changed, 19 insertions(+), 18 deletions(-) + +diff --git a/trurl.c b/trurl.c +index b5a716c..d150a93 100644 +--- a/trurl.c ++++ b/trurl.c +@@ -483,7 +483,7 @@ static void pathadd(struct option *o, const char *path) + + static char *encodeassign(const char *query) + { +- char *p = strchr(query, '='); ++ const char *p = strchr(query, '='); + char *urle; + if(p) { + /* URL encode the left and the right side of the '=' separately */ +@@ -600,7 +600,7 @@ static int getarg(struct option *o, + gap = false; + } + else if((flag[0] == '-') && (flag[1] == '-')) { +- char *equals = strchr(&flag[2], '='); ++ const char *equals = strchr(&flag[2], '='); + if(equals) { + arg = (char *)&equals[1]; + gap = false; +@@ -861,9 +861,10 @@ static void get(struct option *o, CURLU *uh) + else { + /* this is meant as a variable to output */ + const char *start = ptr; +- char *end; +- char *cl; ++ const char *end; ++ const char *cl; + size_t vlen; ++ size_t badlen = 0; + bool isquery = false; + bool queryall = false; + bool strict = false; /* strict mode, fail on URL decode problems */ +@@ -923,7 +924,7 @@ static void get(struct option *o, CURLU *uh) + else { + /* syntax error */ + vlen = 0; +- end[1] = '\0'; ++ badlen = end - start + 1; + } + break; + } +@@ -938,7 +939,7 @@ static void get(struct option *o, CURLU *uh) + queryall); + } + else if(!vlen) +- errorf(o, ERROR_GET, "Bad --get syntax: %s", start); ++ errorf(o, ERROR_GET, "Bad --get syntax: %.*s", (int)badlen, start); + else if(!strncmp(ptr, "url", vlen)) + showurl(stream, o, mods, uh); + else { +@@ -1022,7 +1023,7 @@ static void get(struct option *o, CURLU *uh) + static const struct var *setone(CURLU *uh, const char *setline, + struct option *o) + { +- char *ptr = strchr(setline, '='); ++ const char *ptr = strchr(setline, '='); + const struct var *v = NULL; + if(ptr && (ptr > setline)) { + size_t vlen = ptr - setline; +@@ -1269,9 +1270,9 @@ static bool trim(struct option *o) + inslen--; + } + +- for(i = 0 ; i < nqpairs; i++) { +- char *q = qpairs[i].str; +- char *sep = strchr(q, '='); ++ for(i = 0; i < nqpairs; i++) { ++ const char *q = qpairs[i].str; ++ const char *sep = strchr(q, '='); + size_t qlen; + if(sep) + qlen = sep - q; +@@ -1546,10 +1547,9 @@ static bool extractqpairs(CURLU *uh, struct option *o) + /* extract the query */ + if(!curl_url_get(uh, CURLUPART_QUERY, &q, 0)) { + char *p = q; +- char *amp; + while(*p) { + size_t len; +- amp = strchr(p, o->qsep[0]); ++ char *amp = strchr(p, o->qsep[0]); + if(!amp) + len = strlen(p); + else +@@ -1684,7 +1684,7 @@ static char *canonical_path(const char *path) + { + /* split the path per slash, URL decode + encode, then put together again */ + size_t len = strlen(path); +- char *sl; ++ const char *sl; + char *dupe = NULL; + + do { +@@ -1810,7 +1810,8 @@ static void singleurl(struct option *o, + size_t plen; + const char *w; + size_t wlen; +- char *sep; ++ const char *sep; ++ char *sepw; + bool urlencode = true; + const struct var *v; + +@@ -1852,10 +1853,10 @@ static void singleurl(struct option *o, + w = iinfo->ptr; + } + +- sep = strchr(w, ' '); +- if(sep) { +- wlen = sep - w; +- iinfo->ptr = sep + 1; /* next word is here */ ++ sepw = strchr(w, ' '); ++ if(sepw) { ++ wlen = sepw - w; ++ iinfo->ptr = sepw + 1; /* next word is here */ + } + else { + /* last word */ +-- +2.54.0 + diff --git a/pkgs/by-name/tr/trurl/package.nix b/pkgs/by-name/tr/trurl/package.nix index 5cddcd00a35e..bd2e932fd697 100644 --- a/pkgs/by-name/tr/trurl/package.nix +++ b/pkgs/by-name/tr/trurl/package.nix @@ -6,7 +6,6 @@ curl, python3, perl, - trurl, versionCheckHook, }: @@ -22,6 +21,14 @@ stdenv.mkDerivation rec { }; patches = [ + # fix build w/ glibc-2.44 + # https://github.com/curl/trurl/commit/6e1479cc3bdece8d9a7602e6f8f799305d5a5b7d, but rebased + ./0001-build-constify-strchr-memchr-results.patch + (fetchpatch { + url = "https://github.com/curl/trurl/commit/b3c2faf7ee519e4686248957ee079a2452741d61.patch"; + hash = "sha256-khA77XHPVF+2Vn492UuPrhVAEUijRBA2P8lvPlKYSQM="; + }) + (fetchpatch { url = "https://github.com/curl/trurl/commit/f22a2c45956f35702e437fb83ac05376f1956ec5.patch"; hash = "sha256-7CkUs5tMk77WKc7SlgE2NslHtU5cViKSGhHj3IBlpWo="; From 829921e643c27178cd565b76ef0e3df44f0e28af Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 18:21:11 +0200 Subject: [PATCH 327/423] dragmap: drop Failing Hydra build: https://hydra.nixos.org/build/344145730 Repo is archived as well. --- .../dr/dragmap/boost-iterator-range.patch | 12 --- pkgs/by-name/dr/dragmap/cstdint.patch | 73 ----------------- pkgs/by-name/dr/dragmap/getHostVersion.patch | 11 --- pkgs/by-name/dr/dragmap/package.nix | 82 ------------------- pkgs/by-name/dr/dragmap/stdio-pclose.patch | 12 --- pkgs/top-level/aliases.nix | 1 + 6 files changed, 1 insertion(+), 190 deletions(-) delete mode 100644 pkgs/by-name/dr/dragmap/boost-iterator-range.patch delete mode 100644 pkgs/by-name/dr/dragmap/cstdint.patch delete mode 100644 pkgs/by-name/dr/dragmap/getHostVersion.patch delete mode 100644 pkgs/by-name/dr/dragmap/package.nix delete mode 100644 pkgs/by-name/dr/dragmap/stdio-pclose.patch diff --git a/pkgs/by-name/dr/dragmap/boost-iterator-range.patch b/pkgs/by-name/dr/dragmap/boost-iterator-range.patch deleted file mode 100644 index bd70eab43f49..000000000000 --- a/pkgs/by-name/dr/dragmap/boost-iterator-range.patch +++ /dev/null @@ -1,12 +0,0 @@ -diff --git a/src/lib/map/Mapper.cpp b/src/lib/map/Mapper.cpp -index 6eaa2c5..781988c 100644 ---- a/src/lib/map/Mapper.cpp -+++ b/src/lib/map/Mapper.cpp -@@ -22,6 +22,7 @@ - //#include "common/Crc32Hw.hpp" - #include "common/DragenLogger.hpp" - #include "map/Mapper.hpp" -+#include - - namespace dragenos { - namespace map { diff --git a/pkgs/by-name/dr/dragmap/cstdint.patch b/pkgs/by-name/dr/dragmap/cstdint.patch deleted file mode 100644 index 6004510d2999..000000000000 --- a/pkgs/by-name/dr/dragmap/cstdint.patch +++ /dev/null @@ -1,73 +0,0 @@ -diff --git a/src/include/map/SeedPosition.hpp b/src/include/map/SeedPosition.hpp -index 30a7d47..c05af16 100644 ---- a/src/include/map/SeedPosition.hpp -+++ b/src/include/map/SeedPosition.hpp -@@ -16,6 +16,7 @@ - #define MAP_SEED_POSITION_HPP - - #include -+#include - - #include "sequences/Seed.hpp" - -diff --git a/src/include/sequences/Read.hpp b/src/include/sequences/Read.hpp -index 460c1cb..c7ff619 100644 ---- a/src/include/sequences/Read.hpp -+++ b/src/include/sequences/Read.hpp -@@ -16,6 +16,7 @@ - #define SEQUENCES_READ_HPP - - #include -+#include - #include - #include - -diff --git a/src/include/sequences/Seed.hpp b/src/include/sequences/Seed.hpp -index a242153..dd4d23b 100644 ---- a/src/include/sequences/Seed.hpp -+++ b/src/include/sequences/Seed.hpp -@@ -16,6 +16,7 @@ - #define SEQUENCES_SEED_HPP - - #include -+#include - #include - - #include "sequences/Read.hpp" -diff --git a/src/lib/sequences/tests/unit/CrcHasherMocks.hpp b/src/lib/sequences/tests/unit/CrcHasherMocks.hpp -index 1866be7..5d9b7d7 100644 ---- a/src/lib/sequences/tests/unit/CrcHasherMocks.hpp -+++ b/src/lib/sequences/tests/unit/CrcHasherMocks.hpp -@@ -2,6 +2,7 @@ - - #include - #include -+#include - #include - #include - -diff --git a/stubs/dragen/src/host/dragen_api/read_group_list.hpp b/stubs/dragen/src/host/dragen_api/read_group_list.hpp -index eefb9ae..623a77f 100644 ---- a/stubs/dragen/src/host/dragen_api/read_group_list.hpp -+++ b/stubs/dragen/src/host/dragen_api/read_group_list.hpp -@@ -14,6 +14,7 @@ - #define __READ_GROUP_LIST_HPP__ - - #include "dragen_exception.hpp" -+#include - class ReadGroupList { - public: - const std::string &getReadGroupName(const uint16_t idx) const { - -diff --git a/stubs/dragen/src/host/metrics/public/run_stats.hpp b/stubs/dragen/src/host/metrics/public/run_stats.hpp -index 998fe4e..9561b0b 100644 ---- a/stubs/dragen/src/host/metrics/public/run_stats.hpp -+++ b/stubs/dragen/src/host/metrics/public/run_stats.hpp -@@ -10,6 +10,7 @@ - #include - #include - #include -+#include - // - // RP: HA! HA! HA! That's what you get when you write code logging to cout all - // over the place! diff --git a/pkgs/by-name/dr/dragmap/getHostVersion.patch b/pkgs/by-name/dr/dragmap/getHostVersion.patch deleted file mode 100644 index ba769c9b09a3..000000000000 --- a/pkgs/by-name/dr/dragmap/getHostVersion.patch +++ /dev/null @@ -1,11 +0,0 @@ -diff --git a/thirdparty/dragen/src/common/hash_generation/gen_hash_table.c b/thirdparty/dragen/src/common/hash_generation/gen_hash_table.c -index cdca3df..5a55699 100644 ---- a/thirdparty/dragen/src/common/hash_generation/gen_hash_table.c -+++ b/thirdparty/dragen/src/common/hash_generation/gen_hash_table.c -@@ -249,7 +249,7 @@ void setDefaultHashParams(hashTableConfig_t* defConfig, const char* destDir, Has - free(dir); - } - -- defConfig->hostVersion = (char*)getHostVersion(0); -+ defConfig->hostVersion = (char*)getHostVersion(); - } diff --git a/pkgs/by-name/dr/dragmap/package.nix b/pkgs/by-name/dr/dragmap/package.nix deleted file mode 100644 index 8f554102db65..000000000000 --- a/pkgs/by-name/dr/dragmap/package.nix +++ /dev/null @@ -1,82 +0,0 @@ -{ - lib, - stdenv, - fetchFromGitHub, - boost, - gtest, - zlib, -}: - -stdenv.mkDerivation (finalAttrs: { - pname = "dragmap"; - version = "1.3.0"; - - src = fetchFromGitHub { - owner = "Illumina"; - repo = "DRAGMAP"; - tag = finalAttrs.version; - fetchSubmodules = true; - hash = "sha256-f1jsOErriS1I/iUS4CzJ3+Dz8SMUve/ccb3KaE+L7U8="; - }; - - nativeBuildInputs = [ boost ]; - buildInputs = [ - gtest - zlib - ]; - - # Latest boost do not need system as a linking flag - postPatch = '' - sed -i 's/system filesystem/filesystem/' config.mk - ''; - - patches = [ - # getHostVersion use an empty parameter list. This is now an error for GC - ./getHostVersion.patch - - # pclose is called on a NULL value. This is no longer allowed since - # https://github.com/bminor/glibc/commit/64b1a44183a3094672ed304532bedb9acc707554 - ./stdio-pclose.patch - - # Add missing include cstdint. Upstream does not accept PR. Issue opened at - # https://github.com/Illumina/DRAGMAP/issues/63 - ./cstdint.patch - - # Missing import in Mapper.cpp - # Issue opened upstream https://github.com/Illumina/DRAGMAP/pull/66 - ./boost-iterator-range.patch - ]; - - env = { - GTEST_INCLUDEDIR = "${gtest.dev}/include"; - CPPFLAGS = "-I ${boost.dev}/include"; - LDFLAGS = "-L ${boost.out}/lib"; - }; - - installPhase = '' - runHook preInstall - - mkdir -p $out/bin - cp build/release/dragen-os $out/bin/ - - runHook postInstall - ''; - - # Tests are launched by default from makefile - doCheck = false; - - meta = { - description = "Open Source version of Dragen mapper for genomics"; - mainProgram = "dragen-os"; - longDescription = '' - DRAGMAP is an open-source software implementation of the DRAGEN mapper, - which the Illumina team created to produce the same results as their - proprietary DRAGEN hardware. - ''; - homepage = "https://github.com/Illumina/DRAGMAP"; - changelog = "https://github.com/Illumina/DRAGMAP/releases/tag/${finalAttrs.version}"; - license = lib.licenses.gpl3; - platforms = [ "x86_64-linux" ]; - maintainers = with lib.maintainers; [ apraga ]; - }; -}) diff --git a/pkgs/by-name/dr/dragmap/stdio-pclose.patch b/pkgs/by-name/dr/dragmap/stdio-pclose.patch deleted file mode 100644 index 74e8d57e9fa5..000000000000 --- a/pkgs/by-name/dr/dragmap/stdio-pclose.patch +++ /dev/null @@ -1,12 +0,0 @@ -diff --git a/stubs/dragen/src/host/infra/linux/infra_linux_utils.cpp b/stubs/dragen/src/host/infra/linux/infra_linux_utils.cpp -index cd02cd4..c26e9cf 100644 ---- a/stubs/dragen/src/host/infra/linux/infra_linux_utils.cpp -+++ b/stubs/dragen/src/host/infra/linux/infra_linux_utils.cpp -@@ -57,7 +57,6 @@ int GetDmiValue(const std::string& label, std::string& value) - FILE* dmiOutput = popen("sudo /usr/sbin/dmidecode -t 2", "r"); - if (dmiOutput == NULL) { - perror("dmidecode popen"); -- pclose(dmiOutput); - return -1; - } - diff --git a/pkgs/top-level/aliases.nix b/pkgs/top-level/aliases.nix index 79b886d1de47..f6d9491bcce4 100644 --- a/pkgs/top-level/aliases.nix +++ b/pkgs/top-level/aliases.nix @@ -722,6 +722,7 @@ mapAliases { dotnetfx40 = throw "'dotnetfx40' has been removed because it was unmaintained in Nixpkgs"; # Added 2026-01-27 dotty = throw "'dotty' has been renamed to/replaced by 'scala_3'"; # Converted to throw 2025-10-27 dovecot_fts_xapian = throw "'dovecot_fts_xapian' has been removed because it was unmaintained in Nixpkgs. Consider using dovecot-fts-flatcurve instead"; # Added 2025-08-16 + dragmap = throw "'dragmap' doesn't build with latest glibc anymore and upstream repo is archived"; # Added 2026-09-03 drone-runner-exec = throw "'drone-runner-exec' has been removed as it was deprecated and archived upstream."; # Added 2026-07-20 dsd = throw "dsd has been removed, as it was broken and lack of upstream maintenance"; # Added 2025-08-25 dtv-scan-tables_linuxtv = throw "'dtv-scan-tables_linuxtv' has been renamed to/replaced by 'dtv-scan-tables'"; # Converted to throw 2025-10-27 From 6d100550410c87c302979c9ce0c632a61e15b8b6 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 18:24:04 +0200 Subject: [PATCH 328/423] cowsql: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344144419 --- pkgs/by-name/co/cowsql/package.nix | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/pkgs/by-name/co/cowsql/package.nix b/pkgs/by-name/co/cowsql/package.nix index d672b987265c..d524cd0a16db 100644 --- a/pkgs/by-name/co/cowsql/package.nix +++ b/pkgs/by-name/co/cowsql/package.nix @@ -9,6 +9,7 @@ sqlite, incus, nix-update-script, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -22,6 +23,14 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-7djVcozWklI/0KhDC20df+H3YQbodUZaXBnQT4Ug8oI="; }; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/cowsql/cowsql/commit/7c4d73151969ead4f81077ae243d81396ce67988.patch"; + hash = "sha256-aJkf3egKbF23KNC0feDkxh8gIEupsyDBY3PTKuT6lcQ="; + }) + ]; + nativeBuildInputs = [ autoreconfHook pkg-config From a0654321884be9a926fbb60f4ab128ed61fc2409 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 18:26:51 +0200 Subject: [PATCH 329/423] criu: fix build w/ glibc-2.44 ChangeLog: https://hydra.nixos.org/build/344144517 --- pkgs/by-name/cr/criu/package.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/pkgs/by-name/cr/criu/package.nix b/pkgs/by-name/cr/criu/package.nix index f96504b19735..f4e0b527fd66 100644 --- a/pkgs/by-name/cr/criu/package.nix +++ b/pkgs/by-name/cr/criu/package.nix @@ -45,6 +45,12 @@ stdenv.mkDerivation (finalAttrs: { url = "https://github.com/checkpoint-restore/criu/commit/3f3acc3200a23140abaa32a2017ae159d3c2d02c.patch?full_index=1"; hash = "sha256-J8n4TjqjzJLLULnpJdR/6YWa/8moFQMn+wNo4a0otgE="; }) + + # fix build w/ glibc-2.44 + (fetchpatch2 { + url = "https://github.com/checkpoint-restore/criu/commit/a810faba33f43d61372741ed196eafd485546f83.patch?full_index=1"; + hash = "sha256-UHSSC3qI6dvtUAiXNnKXTtuXZYGE0SXpUnQ917SXFaU="; + }) ]; enableParallelBuilding = true; From 6d1f6ca228cdde95ffbc4aa94109d4f62bcbdc43 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 18:32:19 +0200 Subject: [PATCH 330/423] links2: mark as broken MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Failing Hydra build: https://hydra.nixos.org/build/344163770 Code-golfing to do if (strchr(cast_const_char ud, POST_CHAR)) *strchr(cast_const_char ud, POST_CHAR) = 0; means we can't workaround the failure with -Wno-error=discarded-qualifiers like we did for every other package. Also, upstream doesn't use any forge, so I'm not going to bother patching this 🤷 --- pkgs/by-name/li/links2/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/li/links2/package.nix b/pkgs/by-name/li/links2/package.nix index d63aab7bc04b..885bfb3c1158 100644 --- a/pkgs/by-name/li/links2/package.nix +++ b/pkgs/by-name/li/links2/package.nix @@ -76,5 +76,6 @@ stdenv.mkDerivation (finalAttrs: { mainProgram = "links"; license = lib.licenses.gpl2Plus; platforms = lib.platforms.unix; + broken = true; }; }) From 58dc9df41cd7efe162629205a2f9dd4e4f9f0680 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 18:35:29 +0200 Subject: [PATCH 331/423] libbladeRF: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344162454 --- pkgs/by-name/li/libbladeRF/package.nix | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/pkgs/by-name/li/libbladeRF/package.nix b/pkgs/by-name/li/libbladeRF/package.nix index cb340b8bad73..c022cc7b3a34 100644 --- a/pkgs/by-name/li/libbladeRF/package.nix +++ b/pkgs/by-name/li/libbladeRF/package.nix @@ -12,6 +12,7 @@ libusb1, curl, udev, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -29,6 +30,12 @@ stdenv.mkDerivation (finalAttrs: { patches = [ # fix clang build: https://github.com/Nuand/bladeRF/pull/1045 ./clang-fix.patch + + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/Nuand/bladeRF/commit/87bdb1a4bbbc45b749bb90db504fe9cf8fe7a595.patch"; + hash = "sha256-/sB18hwBSIqMkjaC7J0rb4STUrq4BWlJKnyy0Szac9c="; + }) ]; nativeBuildInputs = [ From 852dab931ef1ff2223843e6cdc2921b7dd766280 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 18:40:34 +0200 Subject: [PATCH 332/423] convimg: mark as broken MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Failing Hydra build: https://hydra.nixos.org/build/344144152 The culprit is in a 10 years old git submodule 🫠 --- pkgs/by-name/co/convimg/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/co/convimg/package.nix b/pkgs/by-name/co/convimg/package.nix index 505ac4ff7dc7..f148bfc9d3d0 100644 --- a/pkgs/by-name/co/convimg/package.nix +++ b/pkgs/by-name/co/convimg/package.nix @@ -42,5 +42,6 @@ stdenv.mkDerivation (finalAttrs: { maintainers = [ ]; platforms = lib.platforms.linux; mainProgram = "convimg"; + broken = true; }; }) From f6b4893f16188cddc0d04225ef903c86d47e9d0a Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 18:43:33 +0200 Subject: [PATCH 333/423] urweb: fix build w/ glibc-2.44 ChangeLog: https://hydra.nixos.org/build/344214226 --- pkgs/by-name/ur/urweb/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/ur/urweb/package.nix b/pkgs/by-name/ur/urweb/package.nix index 445c01cec8f0..e79a09bfda7a 100644 --- a/pkgs/by-name/ur/urweb/package.nix +++ b/pkgs/by-name/ur/urweb/package.nix @@ -64,6 +64,7 @@ stdenv.mkDerivation rec { env.NIX_CFLAGS_COMPILE = toString [ # Needed with GCC 12 "-Wno-error=use-after-free" + "-Wno-error=discarded-qualifiers" ]; # Be sure to keep the statically linked libraries From 815ed5f9a7768cb1f34ab23d8c4b5c18f440b658 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 18:50:02 +0200 Subject: [PATCH 334/423] cdecl: mark as broken Failing Hydra build: https://hydra.nixos.org/build/344142755 --- pkgs/by-name/cd/cdecl/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/cd/cdecl/package.nix b/pkgs/by-name/cd/cdecl/package.nix index 8295f1653575..494604a65625 100644 --- a/pkgs/by-name/cd/cdecl/package.nix +++ b/pkgs/by-name/cd/cdecl/package.nix @@ -73,5 +73,6 @@ stdenv.mkDerivation (finalAttrs: { maintainers = with lib.maintainers; [ sigmanificient ]; platforms = lib.platforms.unix; mainProgram = "cdecl"; + broken = true; }; }) From d80776b6f10dad03d77cc94271399c0001cc8925 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 18:54:23 +0200 Subject: [PATCH 335/423] loudmouth: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344166707 --- pkgs/by-name/lo/loudmouth/package.nix | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/lo/loudmouth/package.nix b/pkgs/by-name/lo/loudmouth/package.nix index 91155e474d41..a64d6e61f16a 100644 --- a/pkgs/by-name/lo/loudmouth/package.nix +++ b/pkgs/by-name/lo/loudmouth/package.nix @@ -20,7 +20,10 @@ stdenv.mkDerivation (finalAttrs: { configureFlags = [ "--with-ssl=openssl" ]; - env.NIX_CFLAGS_COMPILE = "-Wno-error=deprecated-declarations"; + env.NIX_CFLAGS_COMPILE = toString [ + "-Wno-error=deprecated-declarations" + "-Wno-error=discarded-qualifiers" + ]; propagatedBuildInputs = [ openssl From cb312659e04d931243c55f630d37aef646547b5e Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 19:00:14 +0200 Subject: [PATCH 336/423] vboot-utils: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344214375 --- pkgs/by-name/vb/vboot-utils/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/vb/vboot-utils/package.nix b/pkgs/by-name/vb/vboot-utils/package.nix index 981202ea1fa0..d04f8a109aaf 100644 --- a/pkgs/by-name/vb/vboot-utils/package.nix +++ b/pkgs/by-name/vb/vboot-utils/package.nix @@ -36,6 +36,9 @@ stdenv.mkDerivation (finalAttrs: { ] ++ lib.optional withFlashrom finalAttrs.passthru.flashromChromeos; + # Fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + enableParallelBuilding = true; postPatch = '' From e82ce26603da9fa9051c1385fdd2c6cad8893c78 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Thu, 3 Sep 2026 19:04:11 +0200 Subject: [PATCH 337/423] ngn-k: drop Upstream's readme claims: > this k implementation is no longer supported Failing Hydra build: https://hydra.nixos.org/build/344170285 --- pkgs/by-name/ng/ngn-k/package.nix | 64 ------------------- pkgs/by-name/ng/ngn-k/repl-argv-1.patch | 13 ---- pkgs/by-name/ng/ngn-k/repl-license-path.patch | 13 ---- pkgs/top-level/aliases.nix | 1 + 4 files changed, 1 insertion(+), 90 deletions(-) delete mode 100644 pkgs/by-name/ng/ngn-k/package.nix delete mode 100644 pkgs/by-name/ng/ngn-k/repl-argv-1.patch delete mode 100644 pkgs/by-name/ng/ngn-k/repl-license-path.patch diff --git a/pkgs/by-name/ng/ngn-k/package.nix b/pkgs/by-name/ng/ngn-k/package.nix deleted file mode 100644 index 92ab2e867624..000000000000 --- a/pkgs/by-name/ng/ngn-k/package.nix +++ /dev/null @@ -1,64 +0,0 @@ -{ - lib, - stdenv, - fetchFromCodeberg, - runtimeShell, -}: - -stdenv.mkDerivation { - pname = "ngn-k"; - version = "0-unstable-2025-11-17"; - - src = fetchFromCodeberg { - owner = "ngn"; - repo = "k"; - rev = "717063f24921d5aff405a39cf7643efedb5bb365"; - hash = "sha256-rUMi+VetQc139PjbFJXlSkmYEuK5wtM6LpQ/f1tcB1s="; - }; - - patches = [ - ./repl-license-path.patch - ./repl-argv-1.patch - ]; - - postPatch = '' - # don't use hardcoded /bin/sh - for f in repl.k m.c;do - substituteInPlace "$f" --replace-fail "/bin/sh" "${runtimeShell}" - done - ''; - - makeFlags = [ "-e" ]; - buildFlags = [ - "k" - "libk.so" - ]; - checkTarget = "t"; - doCheck = true; - - outputs = [ - "out" - "dev" - "lib" - ]; - - # TODO(@sternenseemann): package bulgarian translation - installPhase = '' - runHook preInstall - install -Dm755 k "$out/bin/k" - install -Dm755 repl.k "$out/bin/k-repl" - install -Dm755 libk.so "$lib/lib/libk.so" - install -Dm644 k.h "$dev/include/k.h" - install -Dm644 LICENSE -t "$out/share/ngn-k" - substituteInPlace "$out/bin/k-repl" --replace-fail "#!k" "#!$out/bin/k" - runHook postInstall - ''; - - meta = { - description = "Simple fast vector programming language"; - homepage = "https://codeberg.org/ngn/k"; - license = lib.licenses.agpl3Only; - maintainers = [ lib.maintainers.sternenseemann ]; - platforms = lib.platforms.linux ++ lib.platforms.freebsd; - }; -} diff --git a/pkgs/by-name/ng/ngn-k/repl-argv-1.patch b/pkgs/by-name/ng/ngn-k/repl-argv-1.patch deleted file mode 100644 index 0e54a0845e4a..000000000000 --- a/pkgs/by-name/ng/ngn-k/repl-argv-1.patch +++ /dev/null @@ -1,13 +0,0 @@ -diff --git a/repl.k b/repl.k -index dc89832c..33780850 100755 ---- a/repl.k -+++ b/repl.k -@@ -28,7 +28,7 @@ joinpath:{$[x~,".";y;"/"~*|x;x,y;x,"/",y]} - line0:{c:{0x07~*-2#*x}{(l;r):x;(1:1;r,,(-2_l))}/(x;());"\n"/(*|c),,*c} - line1:{$[#x;;:0];x:-1_x;$[(3>#x)&("\\"=*x)&~^(!cmds)?x 1;cmds[x 1]x 1;.[`1:(fmt;fmtx)[" "~*x]@.:;,x;{`0:`err[]}]];`1:prompt;1} - line:line1@line0@ --$["repl.k"~basename`argv 1;{cmds::@[cmds;x[1]1;:;{y;`0:x}2_x]}'{(&x~\:80#"-")_x:(1+*&x~\:,"/")_-1_x}@0:`argv 1;]; -+$["k-repl"~basename`argv 1;{cmds::@[cmds;x[1]1;:;{y;`0:x}2_x]}'{(&x~\:80#"-")_x:(1+*&x~\:,"/")_-1_x}@0:`argv 1;]; - run:{`1:banner,prompt;{line@1:`}::/`;} - \d . - diff --git a/pkgs/by-name/ng/ngn-k/repl-license-path.patch b/pkgs/by-name/ng/ngn-k/repl-license-path.patch deleted file mode 100644 index d3cd8c781b6b..000000000000 --- a/pkgs/by-name/ng/ngn-k/repl-license-path.patch +++ /dev/null @@ -1,13 +0,0 @@ -diff --git a/repl.k b/repl.k -index dc89832c..7a6e0dcf 100755 ---- a/repl.k -+++ b/repl.k -@@ -21,7 +21,7 @@ tbl:{[w;u;x]h:`k'!x;d:`k''.x;W:(#'h)|/'#''d - r,par'dd[w-2]'sem/'+@[W;&~^`i`d?_@'.x;-:]$'d} - cell:{$[|/`i`d=@y;-x;x]$z} - par:{opn,x,cls} --cmds:(,"a")!{`1:1:joinpath[dirname`argv 0]"LICENSE";} -+cmds:(,"a")!{`1:1:joinpath[dirname`argv 0]"../share/ngn-k/LICENSE";} - basename:{*|"/"\x} - dirname:{$[#x:"/"/-1_"/"\x;x;,"."]} - joinpath:{$[x~,".";y;"/"~*|x;x,y;x,"/",y]} diff --git a/pkgs/top-level/aliases.nix b/pkgs/top-level/aliases.nix index f6d9491bcce4..e885c9b0bb95 100644 --- a/pkgs/top-level/aliases.nix +++ b/pkgs/top-level/aliases.nix @@ -1829,6 +1829,7 @@ mapAliases { nextcloud31Packages = throw "Nextcloud 31 is EOL!"; # Added 2026-02-20 nfstrace = throw "nfstrace has been removed, as it was broken"; # Added 2025-08-25 nginxQuic = throw "'nginxQuic' has been removed. QUIC support is now available in the default nginx builds."; + ngn-k = throw "'ngn-k' doesn't build with glibc 2.44 and upstream claims that the implementation is no longer supported"; # Added 2026-09-03 ngrid = throw "'ngrid' has been removed as it has been unmaintained upstream and broken"; # Added 2025-11-15 nightfox-gtk-theme = throw "'nightfox-gtk-theme' has been removed because it depended on 'gtk-engine-murrine', which was removed because it was unmaintained upstream and depended on GTK 2."; # Added 2026-07-22 nim1 = throw "'nim1' has reached EOL, please use 'nim'"; # Added 2026-03-06 From 2b9386ea4358dde808b9cbbb9c175a9da3cc1a98 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Fri, 4 Sep 2026 13:05:19 +0200 Subject: [PATCH 338/423] beanstalkd: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344141671 --- pkgs/by-name/be/beanstalkd/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/be/beanstalkd/package.nix b/pkgs/by-name/be/beanstalkd/package.nix index bca64619cf03..45228640a9ee 100644 --- a/pkgs/by-name/be/beanstalkd/package.nix +++ b/pkgs/by-name/be/beanstalkd/package.nix @@ -28,6 +28,9 @@ stdenv.mkDerivation (finalAttrs: { hardeningDisable = [ "fortify" ]; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + makeFlags = [ "PREFIX=${placeholder "out"}" ]; nativeBuildInputs = [ installShellFiles ]; From 5f33626ac66bc82c5c5455bed56c5bbc9f927759 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Fri, 4 Sep 2026 13:05:54 +0200 Subject: [PATCH 339/423] diod: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344145191 --- pkgs/by-name/di/diod/package.nix | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/pkgs/by-name/di/diod/package.nix b/pkgs/by-name/di/diod/package.nix index 32b3748bed52..a3127d32ab80 100644 --- a/pkgs/by-name/di/diod/package.nix +++ b/pkgs/by-name/di/diod/package.nix @@ -9,6 +9,7 @@ libcap, perl, ncurses, + fetchpatch, }: let lua = lua5_1; @@ -24,6 +25,14 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-Fz+qvgw5ipyAcZlWBGkmSHuGrZ95i5OorLN3dkdsYKU="; }; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/chaos/diod/commit/d56db0c55012c8a9ea2d3c72749022292c0f65b8.patch"; + hash = "sha256-wuPok3D3VKiao9NmHYLcccsL+91xVbhUeSDExw17X/E="; + }) + ]; + postPatch = '' sed -i configure.ac -e '/git describe/c ${finalAttrs.version})' ''; From 75cda6b87dfbf1e16d5f0fd0fde26ede030905f5 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Fri, 4 Sep 2026 13:06:14 +0200 Subject: [PATCH 340/423] fyi: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344147678 --- pkgs/by-name/fy/fyi/package.nix | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/pkgs/by-name/fy/fyi/package.nix b/pkgs/by-name/fy/fyi/package.nix index e1ea4eaed3e9..f30b86444430 100644 --- a/pkgs/by-name/fy/fyi/package.nix +++ b/pkgs/by-name/fy/fyi/package.nix @@ -7,6 +7,7 @@ ninja, dbus, scdoc, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -19,6 +20,15 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-UGkShHziREQTkQUlbFXT1144BiBApFVbCvu5A1DuoMI="; }; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://codeberg.org/dnkl/fyi/commit/0a663c5230f756d1161a11080d1a113664e79c21.patch"; + hash = "sha256-B4RkenK4pDAl0jYCgoZH27yUDt3evAHaYnassLaFvB4="; + excludes = [ "CHANGELOG.md" ]; + }) + ]; + depsBuildBuild = [ pkg-config ]; nativeBuildInputs = [ From b50f76ac403dad1ba3c171a1ca8fefe5cb32fbe9 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Fri, 4 Sep 2026 13:06:46 +0200 Subject: [PATCH 341/423] spice-vdagent: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344209099 --- pkgs/by-name/sp/spice-vdagent/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/sp/spice-vdagent/package.nix b/pkgs/by-name/sp/spice-vdagent/package.nix index 7c7633f86f2c..48ca54f12f46 100644 --- a/pkgs/by-name/sp/spice-vdagent/package.nix +++ b/pkgs/by-name/sp/spice-vdagent/package.nix @@ -56,6 +56,9 @@ stdenv.mkDerivation (finalAttrs: { systemd ]; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + meta = { description = "Enhanced SPICE integration for linux QEMU guest"; longDescription = '' From e78e07e06158e59963420353cf1a2e14be5952a5 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Fri, 4 Sep 2026 13:30:15 +0200 Subject: [PATCH 342/423] futility: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344147650 --- pkgs/by-name/fu/futility/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/fu/futility/package.nix b/pkgs/by-name/fu/futility/package.nix index 41416f226c2d..061c0ac54249 100644 --- a/pkgs/by-name/fu/futility/package.nix +++ b/pkgs/by-name/fu/futility/package.nix @@ -27,6 +27,8 @@ stdenv.mkDerivation { nss ]; + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + postPatch = '' patchShebangs ./scripts substituteInPlace ./scripts/getversion.sh \ From c90629a83180730f32b075fc371baa59bfb14ca5 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Fri, 4 Sep 2026 13:30:35 +0200 Subject: [PATCH 343/423] ocf-resource-agents: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344173775 --- pkgs/by-name/oc/ocf-resource-agents/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/oc/ocf-resource-agents/package.nix b/pkgs/by-name/oc/ocf-resource-agents/package.nix index 0807b266aafb..f86d1bb1e9d5 100644 --- a/pkgs/by-name/oc/ocf-resource-agents/package.nix +++ b/pkgs/by-name/oc/ocf-resource-agents/package.nix @@ -63,6 +63,9 @@ let # Needed with GCC 12 but breaks on darwin (with clang) or older gcc "-Wno-error=maybe-uninitialized" ] + ++ [ + "-Wno-error=discarded-qualifiers" + ] ); meta = { From 137f6183e14f6b2f47edb32a53c269605d2bee0a Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Fri, 4 Sep 2026 13:31:02 +0200 Subject: [PATCH 344/423] orcania: fix build w/ glibc-2.44 ChangeLog: https://hydra.nixos.org/build/344174427 --- pkgs/by-name/or/orcania/package.nix | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/pkgs/by-name/or/orcania/package.nix b/pkgs/by-name/or/orcania/package.nix index e034e574341f..be2bc176a70b 100644 --- a/pkgs/by-name/or/orcania/package.nix +++ b/pkgs/by-name/or/orcania/package.nix @@ -5,6 +5,7 @@ cmake, check, subunit, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { pname = "orcania"; @@ -17,6 +18,18 @@ stdenv.mkDerivation (finalAttrs: { sha256 = "sha256-Cz3IE5UrfoWjMxQ/+iR1bLsYxf5DVN+7aJqLBcPjduA="; }; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/babelouest/orcania/commit/ee2f45b5da8b7fb2c747419c17880ccdca14521d.patch"; + hash = "sha256-BNGL2Q5STrrAO8/OKMS4S5GqlikGnvg4hgBwKTMulgU="; + }) + (fetchpatch { + url = "https://github.com/babelouest/orcania/commit/f261393b4dd1b4f50aca389916407e0dfa5f2e55.patch"; + hash = "sha256-KyRedPj5gBFPZmefmjLL49OY8eJNmMyd5jsFsQByTUE="; + }) + ]; + nativeBuildInputs = [ cmake ]; nativeCheckInputs = [ From 758a42843e20d40120c5bbdc4aec9805fd248382 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Fri, 4 Sep 2026 13:31:24 +0200 Subject: [PATCH 345/423] x16-emulator: fix build w/ glibc-2.44 --- pkgs/by-name/x1/x16/package.nix | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/pkgs/by-name/x1/x16/package.nix b/pkgs/by-name/x1/x16/package.nix index b1114d51b5fe..f1226c2f2bc9 100644 --- a/pkgs/by-name/x1/x16/package.nix +++ b/pkgs/by-name/x1/x16/package.nix @@ -7,6 +7,7 @@ callPackage, zlib, nix-update-script, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -30,6 +31,9 @@ stdenv.mkDerivation (finalAttrs: { }) ]; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + postPatch = '' substituteInPlace Makefile \ --replace-fail '/bin/echo' 'echo' From cd8332cd8045e62ac2fad4fc9b27ce160cf1aa87 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Fri, 4 Sep 2026 13:31:35 +0200 Subject: [PATCH 346/423] pacemaker: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344174583 --- pkgs/by-name/pa/pacemaker/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/pa/pacemaker/package.nix b/pkgs/by-name/pa/pacemaker/package.nix index 7d670749fe05..ff6d8fc48a7b 100644 --- a/pkgs/by-name/pa/pacemaker/package.nix +++ b/pkgs/by-name/pa/pacemaker/package.nix @@ -111,6 +111,9 @@ stdenv.mkDerivation (finalAttrs: { "-Wno-error=strict-prototypes" "-Wno-error=deprecated-declarations" ] + ++ [ + "-Wno-error=discarded-qualifiers" + ] ); enableParallelBuilding = true; From e563ad1ecd70ea0818c6ad31272af6d9267d5df6 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Fri, 4 Sep 2026 13:31:59 +0200 Subject: [PATCH 347/423] surge-xt: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344209629 --- pkgs/by-name/su/surge-xt/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/su/surge-xt/package.nix b/pkgs/by-name/su/surge-xt/package.nix index bad3fc26ea66..f31724aed58d 100644 --- a/pkgs/by-name/su/surge-xt/package.nix +++ b/pkgs/by-name/su/surge-xt/package.nix @@ -39,6 +39,9 @@ stdenv.mkDerivation (finalAttrs: { ./clap-option.diff ]; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + postPatch = '' # see https://github.com/NixOS/nixpkgs/pull/149487#issuecomment-991747333 export XDG_DOCUMENTS_DIR=$(mktemp -d) From 8594a5e0d89f0c168872669ef00521b03f2912e1 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Fri, 4 Sep 2026 13:41:14 +0200 Subject: [PATCH 348/423] firefox-esr-140: mark as broken Failing Hydra build: https://hydra.nixos.org/build/344146962 Fixing that is a can of worms: * There's a patch for the original compiler error[1], however the source hashes in the source-tree must be updated manually since that's a one-line JSON and that part of the patch doesn't apply. * Only to discover that there's subsequent breakage. Given that this is EOL by the end of month[2], fixing that doesn't seem like well-invested time to me. [1] https://bugzilla.mozilla.org/show_bug.cgi?id=2030493 [2] https://endoflife.date/firefox --- .../networking/browsers/firefox/packages/firefox-esr-140.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/applications/networking/browsers/firefox/packages/firefox-esr-140.nix b/pkgs/applications/networking/browsers/firefox/packages/firefox-esr-140.nix index 3750111eba50..766225ea1da7 100644 --- a/pkgs/applications/networking/browsers/firefox/packages/firefox-esr-140.nix +++ b/pkgs/applications/networking/browsers/firefox/packages/firefox-esr-140.nix @@ -37,6 +37,7 @@ buildMozillaMach rec { spec = "firefox@${lib.removeSuffix "esr" version}"; }; }; + broken = true; # doesn't build on glibc 2.44 }; tests = { inherit (nixosTests) firefox-esr-140; From c6497b9e94849d4d1b3667fd60a9f3fcb7b18ae4 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Fri, 4 Sep 2026 13:43:18 +0200 Subject: [PATCH 349/423] bees: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344141697 --- pkgs/by-name/be/bees/package.nix | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/pkgs/by-name/be/bees/package.nix b/pkgs/by-name/be/bees/package.nix index c29b5c0545fa..88c237730baf 100644 --- a/pkgs/by-name/be/bees/package.nix +++ b/pkgs/by-name/be/bees/package.nix @@ -3,6 +3,7 @@ fetchFromGitHub, makeWrapper, nixosTests, + fetchpatch, stdenv, # Build inputs @@ -25,6 +26,14 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-qaiRWRd9+ElJ40QGOS3AxT2NvF3phQCyPnVz6RfTt8c="; }; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/Zygo/bees/commit/14c82dce8a7e9714d6f9cd03229e0fb55460aa25.patch"; + hash = "sha256-bAYacaS3u01XdlM/8+baD+sMuCOyYDtSis4NvTkx8jk="; + }) + ]; + buildInputs = [ btrfs-progs # for btrfs/ioctl.h util-linux # for uuid.h From 705c45b2125db9ef98b1b9d658acc0c44f66daee Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Fri, 4 Sep 2026 13:51:24 +0200 Subject: [PATCH 350/423] libmongocrypt: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344162914 --- pkgs/by-name/li/libmongocrypt/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/li/libmongocrypt/package.nix b/pkgs/by-name/li/libmongocrypt/package.nix index 98efd633bdee..808c8b4d97e7 100644 --- a/pkgs/by-name/li/libmongocrypt/package.nix +++ b/pkgs/by-name/li/libmongocrypt/package.nix @@ -29,6 +29,9 @@ stdenv.mkDerivation (finalAttrs: { }) ]; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + nativeBuildInputs = [ cmake pkg-config From 315030e076982e8dbd72db7ad8cd52d193c615ea Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Fri, 4 Sep 2026 13:53:25 +0200 Subject: [PATCH 351/423] vg: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344214471 --- pkgs/by-name/vg/vg/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/vg/vg/package.nix b/pkgs/by-name/vg/vg/package.nix index b0c38d6c3cd5..5cc0fb425efb 100644 --- a/pkgs/by-name/vg/vg/package.nix +++ b/pkgs/by-name/vg/vg/package.nix @@ -133,6 +133,7 @@ stdenv.mkDerivation (finalAttrs: { NIX_CFLAGS_COMPILE = toString [ "-Wno-error=stringop-overflow" "-Wno-error=unterminated-string-initialization" + "-Wno-error=discarded-qualifiers" ]; }; From 1eff3c1301963c0a1d32aae326093f1799e0e46c Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 14:03:10 +0200 Subject: [PATCH 352/423] thunderbird-140: mark as broken Failing Hydra build: https://hydra.nixos.org/build/344212797 Same issue as with Firefox 140 esr and likely equally painful to fix, however the new ESR 153 is out already and it's an ESR for 5 out of 12 weeks when 140 is likely being put EOL[1]. [1] https://support.mozilla.org/en-US/kb/thunderbird-esr --- .../networking/mailreaders/thunderbird/packages.nix | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pkgs/applications/networking/mailreaders/thunderbird/packages.nix b/pkgs/applications/networking/mailreaders/thunderbird/packages.nix index 8c2d5732e16f..83af3fbafeab 100644 --- a/pkgs/applications/networking/mailreaders/thunderbird/packages.nix +++ b/pkgs/applications/networking/mailreaders/thunderbird/packages.nix @@ -15,6 +15,7 @@ let sha512, updateScript, applicationName ? "Thunderbird", + broken ? stdenv.buildPlatform.is32bit, }: (buildMozillaMach rec { pname = "thunderbird"; @@ -49,6 +50,7 @@ let ''; meta = { + inherit broken; changelog = "https://www.thunderbird.net/en-US/thunderbird/${version}/releasenotes/"; description = "Full-featured e-mail client"; homepage = "https://www.thunderbird.net/"; @@ -61,7 +63,6 @@ let vcunat ]; platforms = lib.platforms.unix; - broken = stdenv.buildPlatform.is32bit; # since Firefox 60, build on 32-bit platforms fails with "out of memory". # not in `badPlatforms` because cross-compilation on 64-bit machine might work. license = lib.licenses.mpl20; @@ -120,6 +121,8 @@ rec { versionPrefix = "140"; versionSuffix = "esr"; }; + + broken = true; }; } // lib.optionalAttrs config.allowAliases { From d288e330d60018adb088a106009d4418d84e64ba Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 14:04:28 +0200 Subject: [PATCH 353/423] ipv6calc: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344160376 --- pkgs/by-name/ip/ipv6calc/package.nix | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/pkgs/by-name/ip/ipv6calc/package.nix b/pkgs/by-name/ip/ipv6calc/package.nix index fa460738f960..533ca9257a5d 100644 --- a/pkgs/by-name/ip/ipv6calc/package.nix +++ b/pkgs/by-name/ip/ipv6calc/package.nix @@ -6,6 +6,7 @@ ip2location-c, openssl, perl, + fetchpatch, libmaxminddb ? null, geolite-legacy ? null, }: @@ -30,6 +31,14 @@ stdenv.mkDerivation (finalAttrs: { perl ]; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/pbiering/ipv6calc/commit/9b6aebd3690d93b6c2f9efa9346ec72540b1a718.patch"; + hash = "sha256-Y/XBMWdG2/Pfr/vZ2+RGYGj2JS3mWJwQGkXnKvXHArg="; + }) + ]; + postPatch = '' patchShebangs *.sh */*.sh for i in {,databases/}lib/Makefile.in; do From d097fa8774f83326a877adcd6668907f741d5657 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 14:07:18 +0200 Subject: [PATCH 354/423] odhcp6c: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344173898 --- pkgs/by-name/od/odhcp6c/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/od/odhcp6c/package.nix b/pkgs/by-name/od/odhcp6c/package.nix index 2ddedb629ebb..a149d7597435 100644 --- a/pkgs/by-name/od/odhcp6c/package.nix +++ b/pkgs/by-name/od/odhcp6c/package.nix @@ -18,6 +18,9 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-IDBbVWs017JcrApJ3s8fjEQghWCwrK1d+E6Wp5eHNX4="; }; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + nativeBuildInputs = [ cmake ]; buildInputs = [ libubox ]; From 48484b56c78ce70e94bfad2efa56c8a94017d3df Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 14:28:21 +0200 Subject: [PATCH 355/423] tuxpaint: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344213768 While the same patch is also upstream[1], I didn't really get how to extract .patch files from sourceforge, so I used the Gentoo vendored patch instead, contents are the same. [1] https://sourceforge.net/p/tuxpaint/tuxpaint/ci/6271edececef2a3720e5a5b4e245407cf909f034/ --- pkgs/by-name/tu/tuxpaint/package.nix | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/pkgs/by-name/tu/tuxpaint/package.nix b/pkgs/by-name/tu/tuxpaint/package.nix index 3152be909715..5e81c3583ef4 100644 --- a/pkgs/by-name/tu/tuxpaint/package.nix +++ b/pkgs/by-name/tu/tuxpaint/package.nix @@ -23,6 +23,7 @@ SDL2_Pango, SDL2_ttf, netpbm, + fetchpatch, }: let @@ -50,6 +51,15 @@ stdenv.mkDerivation (finalAttrs: { strictDeps = true; + patches = [ + # Fix build w/ glibc-2.44 + # https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=51c28b814990551897631be7a222af2d922030a9 + (fetchpatch { + url = "https://gitweb.gentoo.org/repo/gentoo.git/plain/media-gfx/tuxpaint/files/tuxpaint-0.9.35-glibc-2.43.patch?id=51c28b814990551897631be7a222af2d922030a9"; + hash = "sha256-xkV73GoCd/epeyWfLHq2MNmRNfKaledoFsukwVKiZSI="; + }) + ]; + nativeBuildInputs = [ gettext gperf From ba0ad70bd449b73d8c9115efd525ede9d6dc3270 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 14:35:56 +0200 Subject: [PATCH 356/423] ntp: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344170903 --- pkgs/by-name/nt/ntp/package.nix | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/pkgs/by-name/nt/ntp/package.nix b/pkgs/by-name/nt/ntp/package.nix index e36dad33bf80..a5ec68840827 100644 --- a/pkgs/by-name/nt/ntp/package.nix +++ b/pkgs/by-name/nt/ntp/package.nix @@ -7,6 +7,7 @@ perl, pps-tools, libcap, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -18,6 +19,14 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-z4TF8/saKVKElCYk2CP/+mNBROCWz8T5lprJjvX0aOU="; }; + patches = [ + # Fix build w/ glibc-2.44 + (fetchpatch { + url = "https://gitlab.archlinux.org/archlinux/packaging/packages/ntp/-/raw/8513bf75be3c0425318475e30f5725a03d8fb067/ntp-4.2.8.p18-glib-2.43.patch"; + hash = "sha256-20ztNAnirijKt8rgaMz6FGoHubBOskNL5ynXte3NTvM="; + }) + ]; + # fix for gcc-14 compile failure postPatch = '' substituteInPlace sntp/m4/openldap-thread-check.m4 \ From e3d7bc3b834320fa7003edc746c56c2b074c1cc6 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 17:44:39 +0200 Subject: [PATCH 357/423] ctx: drop Unmaintained and not updated in three years. Also doesn't build with latest glibc anymore. Failing Hydra build: https://hydra.nixos.org/build/344144642 --- pkgs/by-name/ct/ctx/0001-fix-detections.diff | 67 ---------------- pkgs/by-name/ct/ctx/package.nix | 83 -------------------- pkgs/top-level/aliases.nix | 1 + 3 files changed, 1 insertion(+), 150 deletions(-) delete mode 100644 pkgs/by-name/ct/ctx/0001-fix-detections.diff delete mode 100644 pkgs/by-name/ct/ctx/package.nix diff --git a/pkgs/by-name/ct/ctx/0001-fix-detections.diff b/pkgs/by-name/ct/ctx/0001-fix-detections.diff deleted file mode 100644 index d2580d0fde1d..000000000000 --- a/pkgs/by-name/ct/ctx/0001-fix-detections.diff +++ /dev/null @@ -1,67 +0,0 @@ -diff -Naur --no-dereference ctx-source-old/configure.sh ctx-source-new/configure.sh ---- ctx-source-old/configure.sh 1969-12-31 21:00:01.000000000 -0300 -+++ ctx-source-new/configure.sh 2023-09-27 19:26:05.403569888 -0300 -@@ -42,15 +42,18 @@ - ENABLE_SWITCH_DISPATCH=1 - - pkg-config sdl2 && HAVE_SDL=1 --pkg-config babl && HAVE_BABL=1 -+ -+pkg-config babl-0.1 && { HAVE_BABL=1; BABL_NAME=babl-0.1; } -+if [ $HAVE_BABL != 1 ]; then -+ pkg-config babl && { HAVE_BABL=1; BABL_NAME=babl; } -+fi -+ - pkg-config libcurl && HAVE_LIBCURL=1 - pkg-config alsa && HAVE_ALSA=1 - pkg-config libdrm && HAVE_KMS=1 - #pkg-config harfbuzz && HAVE_HARFBUZZ=1 - -- -- --ARCH=`uname -m` -+: "${ARCH:="$(uname -m)"}" - - case "$ARCH" in - "x86_64") HAVE_SIMD=1 ;; -@@ -224,8 +227,8 @@ - if [ $HAVE_BABL = 1 ];then - echo "#define CTX_BABL 1 " >> local.conf - echo "#define CTX_ENABLE_CM 1 " >> local.conf -- echo "CTX_CFLAGS+= `pkg-config babl --cflags`" >> build.conf -- echo "CTX_LIBS+= `pkg-config babl --libs` " >> build.conf -+ echo "CTX_CFLAGS+= `pkg-config "${BABL_NAME}" --cflags`" >> build.conf -+ echo "CTX_LIBS+= `pkg-config "${BABL_NAME}" --libs` " >> build.conf - else - echo "#define CTX_BABL 0 " >> local.conf - echo "#define CTX_ENABLE_CM 0 " >> local.conf -@@ -335,7 +338,7 @@ - #echo "Generating build.deps" - #make build.deps 2>/dev/null - --echo -n "configuration summary, architecture $(arch)" -+echo -n "configuration summary, architecture $ARCH" - [ $HAVE_SIMD = 1 ] && echo " SIMD multi-pass" - echo "" - echo "Backends:" -diff -Naur --no-dereference ctx-source-old/Makefile ctx-source-new/Makefile ---- ctx-source-old/Makefile 1969-12-31 21:00:01.000000000 -0300 -+++ ctx-source-new/Makefile 2023-09-27 19:37:23.779830320 -0300 -@@ -206,8 +206,8 @@ - libctx.a: itk.o deps.o $(CTX_OBJS) build.conf Makefile - $(AR) rcs $@ $(CTX_OBJS) deps.o itk.o - libctx.so: $(CTX_OBJS) deps.o itk.o build.conf Makefile -- $(LD) -shared $(LIBS) $(CTX_OBJS) deps.o itk.o $(CTX_LIBS) -o $@ -- #$(LD) --retain-symbols-file=symbols -shared $(LIBS) $? $(CTX_LIBS) -o $@ -+ $(CCC) -shared $(LIBS) $(CTX_OBJS) deps.o itk.o $(CTX_LIBS) -o $@ -+ #$(CCC) --retain-symbols-file=symbols -shared $(LIBS) $? $(CTX_LIBS) -o $@ - - ctx: main.c ctx.h build.conf Makefile $(TERMINAL_OBJS) $(MEDIA_HANDLERS_OBJS) libctx.a - $(CCC) main.c $(TERMINAL_OBJS) $(MEDIA_HANDLERS_OBJS) -o $@ $(CFLAGS) libctx.a $(LIBS) $(CTX_CFLAGS) $(OFLAGS_LIGHT) -lpthread $(CTX_LIBS) -@@ -277,5 +277,5 @@ - for a in `cat itk/css.h | tr ';' ' ' | tr ',' ' ' | tr ')' ' '|tr ':' ' ' | tr '{' ' ' | tr ' ' '\n' | grep 'SQZ_[a-z][0-9a-zA-Z_]*'| sort | uniq`;do b=`echo $$a|tail -c+5|tr '_' '-'`;echo "#define $$a `./squoze/squoze -33 $$b`u // \"$$b\"";done \ - >> $@ - echo '#endif' >> $@ --static.inc: static/* static/*/* tools/gen_fs.sh -+static.inc: static/* tools/gen_fs.sh - ./tools/gen_fs.sh static > $@ diff --git a/pkgs/by-name/ct/ctx/package.nix b/pkgs/by-name/ct/ctx/package.nix deleted file mode 100644 index 37e3ac1582db..000000000000 --- a/pkgs/by-name/ct/ctx/package.nix +++ /dev/null @@ -1,83 +0,0 @@ -{ - lib, - stdenv, - fetchgit, - SDL2, - alsa-lib, - babl, - bash, - curl, - libdrm, # Not documented - pkg-config, - xxd, - enableFb ? false, - nixosTests, -}: - -stdenv.mkDerivation (finalAttrs: { - pname = "ctx"; - version = "0-unstable-2023-09-03"; - - src = fetchgit { - name = "ctx-source"; # because of a dash starting the directory - url = "https://ctx.graphics/.git/"; - rev = "1bac18c152eace3ca995b3c2b829a452085d46fb"; - hash = "sha256-fOcQJ2XCeomdtAUmy0A+vU7Vt325OSwrb1+ccW+gZ38="; - }; - - patches = [ - # Many problematic things fixed - it should be upstreamed somehow: - # - babl changed its name in pkg-config files - # - arch detection made optional - # - LD changed to CCC - # - remove inexistent reference to static/*/* - ./0001-fix-detections.diff - ]; - - postPatch = '' - patchShebangs ./tools/gen_fs.sh - ''; - - nativeBuildInputs = [ - pkg-config - xxd - ]; - - buildInputs = [ - SDL2 - alsa-lib - babl - bash # for ctx-audioplayer - curl - libdrm - ]; - - strictDeps = true; - - env.ARCH = stdenv.hostPlatform.parsed.cpu.arch or stdenv.hostPlatform.parsed.cpu.name; - - configureScript = "./configure.sh"; - configureFlags = lib.optional enableFb "--enable-fb"; - configurePlatforms = [ ]; - dontAddPrefix = true; - dontDisableStatic = true; - - installFlags = [ - "PREFIX=${placeholder "out"}" - ]; - - passthru.tests.test = nixosTests.terminal-emulators.ctx; - - meta = { - homepage = "https://ctx.graphics/"; - description = "Vector graphics terminal"; - longDescription = '' - ctx is an interactive 2D vector graphics, audio, text- canvas and - terminal, with escape sequences that enable a 2D vector drawing API using - a vector graphics protocol. - ''; - license = lib.licenses.gpl3Plus; - maintainers = [ ]; - platforms = lib.platforms.unix; - }; -}) diff --git a/pkgs/top-level/aliases.nix b/pkgs/top-level/aliases.nix index e885c9b0bb95..602a5a5cbf30 100644 --- a/pkgs/top-level/aliases.nix +++ b/pkgs/top-level/aliases.nix @@ -640,6 +640,7 @@ mapAliases { csslint = throw "'csslint' has been removed as upstream considers it abandoned."; # Added 2025-11-07 cstore_fdw = throw "'cstore_fdw' has been removed. Use 'postgresqlPackages.cstore_fdw' instead."; # Added 2025-07-19 ctpp2 = throw "'ctpp2' has been removed due to lack of maintenance."; # Added 2025-12-31 + ctx = throw "'ctx' was unmaintained and not updated for three years"; # Added 2026-09-08 cudaPackages_11 = throw "CUDA 11 has been removed from Nixpkgs, as it is unmaintained upstream and depends on unsupported compilers"; # Added 2025-08-08 cudaPackages_11_0 = throw "CUDA 11.0 has been removed from Nixpkgs, as it is unmaintained upstream and depends on unsupported compilers"; # Added 2025-08-08 cudaPackages_11_1 = throw "CUDA 11.1 has been removed from Nixpkgs, as it is unmaintained upstream and depends on unsupported compilers"; # Added 2025-08-08 From a71a62a7b09bdf38ae96eb1d85778d969e98b4ef Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 17:45:27 +0200 Subject: [PATCH 358/423] zookeeper_mt: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344217319 --- pkgs/by-name/zo/zookeeper_mt/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/zo/zookeeper_mt/package.nix b/pkgs/by-name/zo/zookeeper_mt/package.nix index 44dc1fdf8cd8..4d7d4eaf5986 100644 --- a/pkgs/by-name/zo/zookeeper_mt/package.nix +++ b/pkgs/by-name/zo/zookeeper_mt/package.nix @@ -21,6 +21,9 @@ stdenv.mkDerivation rec { sourceRoot = "apache-${zookeeper.pname}-${version}/zookeeper-client/zookeeper-client-c"; + # Fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + nativeBuildInputs = [ autoreconfHook pkg-config From f2926847c4af5b0ccab1665971717bdd9e31f48c Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 18:01:08 +0200 Subject: [PATCH 359/423] livegrep: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344166092 --- pkgs/by-name/li/livegrep/package.nix | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/li/livegrep/package.nix b/pkgs/by-name/li/livegrep/package.nix index f2b8d4a47463..3fc784850bae 100644 --- a/pkgs/by-name/li/livegrep/package.nix +++ b/pkgs/by-name/li/livegrep/package.nix @@ -94,7 +94,10 @@ buildBazelPackage { "file://${registry}" ]; - env = lib.optionalAttrs stdenv.hostPlatform.isDarwin { + env = { + NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + } + // lib.optionalAttrs stdenv.hostPlatform.isDarwin { LIBTOOL = "${cctools}/bin/libtool"; }; From 744a98d733a4d05e41bb92c5573d7c07f621631f Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 18:01:44 +0200 Subject: [PATCH 360/423] odyssey: fix build w/ glibc-2.44 --- pkgs/by-name/od/odyssey/package.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/pkgs/by-name/od/odyssey/package.nix b/pkgs/by-name/od/odyssey/package.nix index f776d973e23f..69cfacd289d9 100644 --- a/pkgs/by-name/od/odyssey/package.nix +++ b/pkgs/by-name/od/odyssey/package.nix @@ -25,6 +25,12 @@ stdenv.mkDerivation (finalAttrs: { url = "https://github.com/yandex/odyssey/commit/51c0e777aa45157f4f03fbd036113ce6d11ca41f.patch?full_index=1"; hash = "sha256-yytyA2K62v7XwJQ+WJnBGh87AVyeOv0cuzlQ7oYnhFg="; }) + + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/yandex/odyssey/commit/1edf6bfd05dc34324162fda1b4ca4bc38b1b581c.patch"; + hash = "sha256-Rd/dqmvpY2gJMqg3hX5rXMu3vRjOG5V3QXV/S1M625Q="; + }) ]; nativeBuildInputs = [ cmake ]; From 9a4883041bbf28b2fb2878d38a9f5145ab8ff053 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 18:01:56 +0200 Subject: [PATCH 361/423] virt-viewer: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344467073 --- pkgs/by-name/vi/virt-viewer/package.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/pkgs/by-name/vi/virt-viewer/package.nix b/pkgs/by-name/vi/virt-viewer/package.nix index 56a1962294ab..c599d66504ed 100644 --- a/pkgs/by-name/vi/virt-viewer/package.nix +++ b/pkgs/by-name/vi/virt-viewer/package.nix @@ -49,6 +49,12 @@ stdenv.mkDerivation (finalAttrs: { url = "https://gitlab.com/virt-viewer/virt-viewer/-/commit/98d9f202ef768f22ae21b5c43a080a1aa64a7107.patch"; sha256 = "sha256-3AbnkbhWOh0aNjUkmVoSV/9jFQtvTllOr7plnkntb2o="; }) + + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://gitlab.com/virt-viewer/virt-viewer/-/commit/a634fa8d9fbc59b093f2f07110b2c867f622599d.patch"; + hash = "sha256-xNwpuVwYajlfQUbT6aDrTBqwa61Je8EhD0C9+PL/qx0="; + }) ]; nativeBuildInputs = [ From 9266a746c18e231668883ff2baabd25be64df6be Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 18:12:11 +0200 Subject: [PATCH 362/423] xbps: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344216369 --- pkgs/by-name/xb/xbps/package.nix | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/pkgs/by-name/xb/xbps/package.nix b/pkgs/by-name/xb/xbps/package.nix index 6f3e1ef231ea..b343f27c4909 100644 --- a/pkgs/by-name/xb/xbps/package.nix +++ b/pkgs/by-name/xb/xbps/package.nix @@ -7,6 +7,7 @@ zlib, openssl, libarchive, + fetchpatch, }: stdenv.mkDerivation (finalAttrs: { @@ -33,6 +34,23 @@ stdenv.mkDerivation (finalAttrs: { patches = [ ./cert-paths.patch + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/void-linux/xbps/commit/7d02b79d3d7e0bf644adf8b412e76dba1b1fdce1.patch"; + hash = "sha256-iUNBmkkfR02/EFDkax/ZpE7oM+5IVDMmD0FYz7p0dQ4="; + }) + (fetchpatch { + url = "https://github.com/void-linux/xbps/commit/9a8002c5688c3cdda700b022bf432b4426d64042.patch"; + hash = "sha256-/94HKeyv9LaQv6QHE0CqmM1ajBOSNt9Sfh0XKV0RLMQ="; + }) + (fetchpatch { + url = "https://github.com/void-linux/xbps/commit/7f2f10300f235639c5880bea1e4b14245fd5fbda.patch"; + hash = "sha256-iZXiNYrSFaP55qyzefc3hqJ+SoIOsFILqnra6u5iGpM="; + }) + (fetchpatch { + url = "https://github.com/void-linux/xbps/commit/84f6a1be26348c265afedebe9cea958424b0aabf.patch"; + hash = "sha256-WDsGkI+3JnJskM+UKjI/UZP6ypMCd5+3rYtlQgQEr40="; + }) ]; env.NIX_CFLAGS_COMPILE = "-Wno-error=unused-result -Wno-error=deprecated-declarations"; From ceec2dc3b9154c655bbf0d204b36bc8be7db67ad Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 21:47:09 +0200 Subject: [PATCH 363/423] hexcurse: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344158921 --- pkgs/by-name/he/hexcurse/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/he/hexcurse/package.nix b/pkgs/by-name/he/hexcurse/package.nix index b8863337e7bf..7c72389a47e2 100644 --- a/pkgs/by-name/he/hexcurse/package.nix +++ b/pkgs/by-name/he/hexcurse/package.nix @@ -21,6 +21,7 @@ stdenv.mkDerivation (finalAttrs: { env.NIX_CFLAGS_COMPILE = toString [ "-Wno-error=stringop-overflow" "-Wno-error=stringop-truncation" + "-Wno-error=discarded-qualifiers" ]; patches = [ # gcc7 compat From 8929e07ea1a44ff09bc15858fe9a4dea9ac92b6a Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 21:47:47 +0200 Subject: [PATCH 364/423] pesign: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344178917 --- pkgs/by-name/pe/pesign/package.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/pkgs/by-name/pe/pesign/package.nix b/pkgs/by-name/pe/pesign/package.nix index 7fd597e164a8..989062b68f41 100644 --- a/pkgs/by-name/pe/pesign/package.nix +++ b/pkgs/by-name/pe/pesign/package.nix @@ -30,6 +30,12 @@ stdenv.mkDerivation (finalAttrs: { url = "https://github.com/rhboot/pesign/commit/1f9e2fa0b4d872fdd01ca3ba81b04dfb1211a187.patch?full_index=1"; hash = "sha256-viVM4Z0jAEAWC3EdJVHcWe21aQskH5XE85lOd6Xd/qU="; }) + + # fix build w/ glibc-2.44 + (fetchpatch2 { + url = "https://github.com/rhboot/pesign/commit/419d63a8b6434f94b57730bb8a58a32a0bb199aa.patch?full_index=1"; + hash = "sha256-/o0QknZ1IDFwmsQAt1IENx7tr8WRNJS3wl84cHzprzA="; + }) ]; # nss-util is missing because it is already contained in nss From 03a5c683bff81df17b50feed3ffc72e5570cd904 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 21:48:23 +0200 Subject: [PATCH 365/423] mysql-shell_{8,9}: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344169786 --- pkgs/development/tools/mysql-shell/8.nix | 7 +++++++ pkgs/development/tools/mysql-shell/9.nix | 7 +++++++ 2 files changed, 14 insertions(+) diff --git a/pkgs/development/tools/mysql-shell/8.nix b/pkgs/development/tools/mysql-shell/8.nix index 238742bd3ebf..7c6b7680e282 100644 --- a/pkgs/development/tools/mysql-shell/8.nix +++ b/pkgs/development/tools/mysql-shell/8.nix @@ -29,6 +29,7 @@ cyrus_sasl, openldap, antlr, + fetchpatch, }: let @@ -66,6 +67,12 @@ stdenv.mkDerivation (finalAttrs: { # No openssl bundling on macOS. It's not working. # See https://github.com/mysql/mysql-shell/blob/5b84e0be59fc0e027ef3f4920df15f7be97624c1/cmake/ssl.cmake#L53 ./no-openssl-bundling.patch + + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/mysql/mysql-shell/commit/4ce8746d8a7eecf9ae66d4d500c84d57cc4fbdbb.patch"; + hash = "sha256-LUGC7gnNQ3zhmWUm2xogsOAmx8QSngQBHVJMWHFtWz0="; + }) ]; postPatch = '' diff --git a/pkgs/development/tools/mysql-shell/9.nix b/pkgs/development/tools/mysql-shell/9.nix index 14843a23f189..5f68b885640e 100644 --- a/pkgs/development/tools/mysql-shell/9.nix +++ b/pkgs/development/tools/mysql-shell/9.nix @@ -29,6 +29,7 @@ cyrus_sasl, openldap, antlr, + fetchpatch, }: let @@ -66,6 +67,12 @@ stdenv.mkDerivation (finalAttrs: { # No openssl bundling on macOS. It's not working. # See https://github.com/mysql/mysql-shell/blob/5b84e0be59fc0e027ef3f4920df15f7be97624c1/cmake/ssl.cmake#L53 ./no-openssl-bundling.patch + + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/mysql/mysql-shell/commit/4ce8746d8a7eecf9ae66d4d500c84d57cc4fbdbb.patch"; + hash = "sha256-LUGC7gnNQ3zhmWUm2xogsOAmx8QSngQBHVJMWHFtWz0="; + }) ]; postPatch = '' From 0706a24d11d06f9536ae573f5159ca328253f077 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 21:51:41 +0200 Subject: [PATCH 366/423] mitscheme: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344290710 _POSIX_C_SOURCE is defined in an already imported glibc header. Since that's used to enable newer C extensions and the code is still building fine, we're just removing the definition from the package's source-code. --- pkgs/by-name/mi/mitscheme/package.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkgs/by-name/mi/mitscheme/package.nix b/pkgs/by-name/mi/mitscheme/package.nix index 8f311d6c15ce..b0be6a25077b 100644 --- a/pkgs/by-name/mi/mitscheme/package.nix +++ b/pkgs/by-name/mi/mitscheme/package.nix @@ -44,6 +44,11 @@ stdenv.mkDerivation { sha256 = "035f92vni0vqmgj9hq2i7vwasz7crx52wll4823vhfkm1qdv5ywc"; }; + postPatch = '' + substituteInPlace "src/microcode/chacha.i" \ + --replace-fail "#define _POSIX_C_SOURCE 200809L" "" + ''; + patches = [ (fetchDebianPatch { pname = "mit-scheme"; From bc0eb86a1aa62a8a893b3c40595d10be793c25e6 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 21:52:48 +0200 Subject: [PATCH 367/423] open-vm-tools: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344174037 This package builds fine on the base of this branch, so it's somehow related to the glibc change, I'm just not understanding how. Anyways, the issue is that `g_free` is a macro in glib (NOT glibc) and was expanded in here leading to a syntax error. Removing this line entirely fixes the issue for us. --- pkgs/by-name/op/open-vm-tools/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/op/open-vm-tools/package.nix b/pkgs/by-name/op/open-vm-tools/package.nix index 5835333ae557..06e87eeeb82c 100644 --- a/pkgs/by-name/op/open-vm-tools/package.nix +++ b/pkgs/by-name/op/open-vm-tools/package.nix @@ -150,6 +150,9 @@ stdenv.mkDerivation (finalAttrs: { substituteInPlace udev/99-vmware-scsi-udev.rules \ --replace-fail "/bin/sh" "${bash}/bin/sh" + + substituteInPlace lib/rpcChannel/glib_stubs.c \ + --replace-fail "void g_free(void *p) { free(p); }" "" ''; configureFlags = [ From 9e2084eb155f358cc02ab7b39caca755793a5412 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 21:54:11 +0200 Subject: [PATCH 368/423] xfstests: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344216601 --- pkgs/by-name/xf/xfstests/package.nix | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/xf/xfstests/package.nix b/pkgs/by-name/xf/xfstests/package.nix index 0ab3874adbed..3151f71d3387 100644 --- a/pkgs/by-name/xf/xfstests/package.nix +++ b/pkgs/by-name/xf/xfstests/package.nix @@ -10,6 +10,7 @@ coreutils, e2fsprogs, fetchzip, + fetchpatch, fio, gawk, keyutils, @@ -45,6 +46,14 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-b2bL8t1I+kOryAvq3pYTVhx+LwIDf26xdHl7Wdq+Mw8="; }; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://lore.kernel.org/fstests/20260813150846.280498-1-zlang@kernel.org/raw"; + hash = "sha256-NOPMo0cdKKoPMwG53BdTe+G+vDXb+2ICGYFRs4g+edQ="; + }) + ]; + nativeBuildInputs = [ autoconf automake @@ -65,7 +74,7 @@ stdenv.mkDerivation (finalAttrs: { hardeningDisable = [ "format" ]; enableParallelBuilding = true; - patchPhase = '' + postPatch = '' substituteInPlace Makefile \ --replace-fail "cp include/install-sh ." "cp -f include/install-sh ." From 3e6711e17867f8a8266951819d7845140a971b30 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 23:05:00 +0200 Subject: [PATCH 369/423] ats2: fix build w/ glibc-2.42 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Failing Hydra build: https://hydra.nixos.org/build/344140882 `bsearch` is a macro now, so the `extern`-definition leads to a syntax error. Not going to find out how to use sourceforge to send that though 🤷 --- .../at/ats2/fix-build-glibc-2.44.patch | 20 +++++++++++++++++++ pkgs/by-name/at/ats2/package.nix | 4 ++++ 2 files changed, 24 insertions(+) create mode 100644 pkgs/by-name/at/ats2/fix-build-glibc-2.44.patch diff --git a/pkgs/by-name/at/ats2/fix-build-glibc-2.44.patch b/pkgs/by-name/at/ats2/fix-build-glibc-2.44.patch new file mode 100644 index 000000000000..5cc48100c380 --- /dev/null +++ b/pkgs/by-name/at/ats2/fix-build-glibc-2.44.patch @@ -0,0 +1,20 @@ +diff --git a/prelude/CATS/array.cats b/prelude/CATS/array.cats +index 70c7e3e..cec3b1d 100644 +--- a/prelude/CATS/array.cats ++++ b/prelude/CATS/array.cats +@@ -56,6 +56,7 @@ void qsort + void *base, size_t nmemb, size_t size + , int(*compar)(const void *, const void *) + ) ; // end of [qsort] ++#ifndef bsearch + extern + void *bsearch + ( +@@ -64,6 +65,7 @@ void *bsearch + , size_t nmemb, size_t size + , int (*compar)(const void *, const void *) + ) ; // end of [bsearch] ++#endif + // + #define atspre_array_qsort qsort + #define atspre_array_bsearch bsearch diff --git a/pkgs/by-name/at/ats2/package.nix b/pkgs/by-name/at/ats2/package.nix index ea804a173894..4f1e7287ec16 100644 --- a/pkgs/by-name/at/ats2/package.nix +++ b/pkgs/by-name/at/ats2/package.nix @@ -49,6 +49,10 @@ stdenv.mkDerivation rec { sed -i 's/gcc/clang/g' utils/*/DATS/atscc_util.dats ''; + patches = [ + ./fix-build-glibc-2.44.patch + ]; + buildInputs = [ gmp ]; # Disable parallel build, errors: From 01aced593b61b75b6c9cc5a805e142e58ae429b4 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 23:09:06 +0200 Subject: [PATCH 370/423] j: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344160462 --- pkgs/by-name/j/j/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/j/j/package.nix b/pkgs/by-name/j/j/package.nix index dd4ed59c1fe4..72b5523589ba 100644 --- a/pkgs/by-name/j/j/package.nix +++ b/pkgs/by-name/j/j/package.nix @@ -40,6 +40,9 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-fW6Tc0UEPYFTgEFMUxZaVm2NU5LNFqszifqOqfdFJZY="; }; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + nativeBuildInputs = [ which ]; buildInputs = [ gmp ]; From bae8a721d98b1b4ede0f6c04cec505dcf6a691ac Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 23:09:25 +0200 Subject: [PATCH 371/423] ulfius: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344467071 --- pkgs/by-name/ul/ulfius/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/ul/ulfius/package.nix b/pkgs/by-name/ul/ulfius/package.nix index 21542df0d6ad..6db5cbc75f7d 100644 --- a/pkgs/by-name/ul/ulfius/package.nix +++ b/pkgs/by-name/ul/ulfius/package.nix @@ -40,6 +40,9 @@ stdenv.mkDerivation (finalAttrs: { cmake ]; + # Fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + propagatedBuildInputs = [ libmicrohttpd orcania From 09d8101a4f93956ee920a308c8dde6f11ca68764 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 23:09:45 +0200 Subject: [PATCH 372/423] pspp: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344181613 --- pkgs/by-name/ps/pspp/fix-glibc-2.42.patch | 29 +++++++++++++++++++++++ pkgs/by-name/ps/pspp/package.nix | 7 ++++++ 2 files changed, 36 insertions(+) create mode 100644 pkgs/by-name/ps/pspp/fix-glibc-2.42.patch diff --git a/pkgs/by-name/ps/pspp/fix-glibc-2.42.patch b/pkgs/by-name/ps/pspp/fix-glibc-2.42.patch new file mode 100644 index 000000000000..8bf84cc53a94 --- /dev/null +++ b/pkgs/by-name/ps/pspp/fix-glibc-2.42.patch @@ -0,0 +1,29 @@ +diff --git a/gl/stdlib.in.h b/gl/stdlib.in.h +index bef0aaa..b2e19c3 100644 +--- a/gl/stdlib.in.h ++++ b/gl/stdlib.in.h +@@ -223,7 +223,7 @@ _GL_INLINE_HEADER_BEGIN + + + /* Declarations for ISO C N3322. */ +-#if defined __GNUC__ && __GNUC__ >= 15 && !defined __clang__ ++#if defined __GNUC__ && __GNUC__ >= 15 && !defined __clang__ && !defined(bsearch) + _GL_EXTERN_C void *bsearch (const void *__key, + const void *__base, size_t __nmemb, size_t __size, + int (*__compare) (const void *, const void *)) +diff --git a/gl/wchar.in.h b/gl/wchar.in.h +index ab602a2..a2aa597 100644 +--- a/gl/wchar.in.h ++++ b/gl/wchar.in.h +@@ -301,9 +301,11 @@ _GL_EXTERN_C int wcsncmp (const wchar_t *__s1, const wchar_t *__s2, size_t __n) + _GL_ATTRIBUTE_NONNULL_IF_NONZERO (1, 3) + _GL_ATTRIBUTE_NONNULL_IF_NONZERO (2, 3); + # ifndef __cplusplus ++# if !defined(wmemchr) + _GL_EXTERN_C wchar_t *wmemchr (const wchar_t *__s, wchar_t __wc, size_t __n) + _GL_ATTRIBUTE_NONNULL_IF_NONZERO (1, 3); + # endif ++# endif + _GL_EXTERN_C wchar_t *wmemset (wchar_t *__s, wchar_t __wc, size_t __n) + # if __GLIBC__ + (__GLIBC_MINOR__ >= 2) > 2 + _GL_ATTRIBUTE_NOTHROW diff --git a/pkgs/by-name/ps/pspp/package.nix b/pkgs/by-name/ps/pspp/package.nix index 7585269dc3d5..0cfad65068fd 100644 --- a/pkgs/by-name/ps/pspp/package.nix +++ b/pkgs/by-name/ps/pspp/package.nix @@ -55,10 +55,17 @@ stdenv.mkDerivation rec { iconv ]; + patches = [ + ./fix-glibc-2.42.patch + ]; + env = { C_INCLUDE_PATH = "${libxml2.dev}/include/libxml2/:" + lib.makeSearchPathOutput "dev" "include" buildInputs; LIBRARY_PATH = lib.makeLibraryPath buildInputs; + + # fix build w/ glibc-2.44 + NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; }; doCheck = false; From ada787547fccec71df54d565ddb901c1a10b219d Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 23:10:08 +0200 Subject: [PATCH 373/423] picolibc: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344179652 --- pkgs/by-name/pi/picolibc/package.nix | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/pkgs/by-name/pi/picolibc/package.nix b/pkgs/by-name/pi/picolibc/package.nix index 0bffb8ddd2e9..d9bf1a174531 100644 --- a/pkgs/by-name/pi/picolibc/package.nix +++ b/pkgs/by-name/pi/picolibc/package.nix @@ -1,5 +1,6 @@ { stdenvNoLibc, + fetchpatch, buildPackages, fetchFromGitHub, lib, @@ -34,6 +35,14 @@ stdenvNoLibc.mkDerivation (finalAttrs: { hash = "sha256-FhTNgffsnHbzIXOOwCMe6O1FGkEtqWfw+e30RW+Y4K4="; }; + patches = [ + # fix build w/ glibc-2.44 + (fetchpatch { + url = "https://github.com/picolibc/picolibc/commit/11a46b6ed03c4dca64e0534435da9841e837b160.patch"; + hash = "sha256-i1dKW1L5si0gf0/Sn4sU/BuIof778tvHgCCCY1TxMME="; + }) + ]; + depsBuildBuild = lib.optionals canExecute [ buildPackages.stdenv.cc ]; From 743f1ebcddaac34f54040de298caa47637baf78c Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 23:13:33 +0200 Subject: [PATCH 374/423] helix.tree-sitter-grammars.tree-sitter-perl: fix build w/ glibc-2.44 `bsearch` being a macro causes a syntax error on compilation. I'm letting the maintainers do an upgrade, for now we remove the custom bsearch implementation and let it use the glibc-provided one. Failing Hydra build: https://hydra.nixos.org/build/344158900/step/91/log --- pkgs/by-name/he/helix/package.nix | 18 +++++++++++++++++- 1 file changed, 17 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/he/helix/package.nix b/pkgs/by-name/he/helix/package.nix index e301693489f6..dd0f7662cab0 100644 --- a/pkgs/by-name/he/helix/package.nix +++ b/pkgs/by-name/he/helix/package.nix @@ -68,7 +68,23 @@ let helixTreeSitterGrammars = lib.filterAttrs (drvName: _: lib.hasAttr (lib.removePrefix "tree-sitter-" drvName) lockedGrammars) - (tree-sitter-grammars.overrideScope (lib.composeExtensions lockedVersionsOverlay grammarsOverlay)); + ( + tree-sitter-grammars.overrideScope ( + lib.composeManyExtensions [ + lockedVersionsOverlay + grammarsOverlay + (self: super: { + tree-sitter-perl = super.tree-sitter-perl.overrideAttrs { + postPatch = '' + rm src/bsearch.c + substituteInPlace src/tsp_unicode.h \ + --replace-fail '#include "bsearch.c"' "" + ''; + }; + }) + ] + ) + ); # Dynamic libraries for the grammars always use the `.so` extension, also on Darwin (should use `.dylib`) # See here: https://github.com/helix-editor/helix/pull/14982 From 056088250265813c5ab0b0c30cc10ca52c3acd6a Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 23:43:52 +0200 Subject: [PATCH 375/423] alsa-scarlett-gui: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344140166 --- pkgs/by-name/al/alsa-scarlett-gui/package.nix | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/al/alsa-scarlett-gui/package.nix b/pkgs/by-name/al/alsa-scarlett-gui/package.nix index e96089a715c6..2215e090c31a 100644 --- a/pkgs/by-name/al/alsa-scarlett-gui/package.nix +++ b/pkgs/by-name/al/alsa-scarlett-gui/package.nix @@ -22,7 +22,10 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-DkfpMK0T67B4mnriignf4hx6Ifddls0rN0SxyfEsPZg="; }; - env.NIX_CFLAGS_COMPILE = toString [ "-Wno-error=deprecated-declarations" ]; + env.NIX_CFLAGS_COMPILE = toString [ + "-Wno-error=deprecated-declarations" + "-Wno-error=discarded-qualifiers" + ]; makeFlags = [ "DESTDIR=\${out}" From 26da0e8d57d830648f4c52435d48e89716a582ee Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 23:44:16 +0200 Subject: [PATCH 376/423] odp-dpdk: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344173889 --- pkgs/by-name/od/odp-dpdk/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/od/odp-dpdk/package.nix b/pkgs/by-name/od/odp-dpdk/package.nix index 76b5a869b4e4..c11143fa6c1f 100644 --- a/pkgs/by-name/od/odp-dpdk/package.nix +++ b/pkgs/by-name/od/odp-dpdk/package.nix @@ -34,6 +34,9 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-L6lF8VaycAz7PcFArAgLhI8+sc0jnAHY3gum/uDIYz4="; }; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + nativeBuildInputs = [ autoreconfHook pkg-config From b4cd20c95b4ef2105b515efd5de86dc80241d008 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 8 Sep 2026 23:45:04 +0200 Subject: [PATCH 377/423] openvas-scanner: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344174370 --- pkgs/by-name/op/openvas-scanner/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/op/openvas-scanner/package.nix b/pkgs/by-name/op/openvas-scanner/package.nix index 8868ea132e0d..72637f8f05f4 100644 --- a/pkgs/by-name/op/openvas-scanner/package.nix +++ b/pkgs/by-name/op/openvas-scanner/package.nix @@ -40,6 +40,9 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-ggmex/BmAVgdE1JNM3kybEmr/uKqrIl8JdSoBnsg+40="; }; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + nativeBuildInputs = [ cmake git From c3ff0d031367898743f6f7f2427c2f8f4fd43fba Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 9 Sep 2026 09:10:19 +0200 Subject: [PATCH 378/423] fnc: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344147213 --- pkgs/by-name/fn/fnc/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/fn/fnc/package.nix b/pkgs/by-name/fn/fnc/package.nix index 2e6b2abcde37..20fcea12bbca 100644 --- a/pkgs/by-name/fn/fnc/package.nix +++ b/pkgs/by-name/fn/fnc/package.nix @@ -28,6 +28,8 @@ stdenv.mkDerivation (finalAttrs: { lib.optionals stdenv.cc.isGNU [ # Needed with GCC 12 "-Wno-error=maybe-uninitialized" + # Fix build w/ glibc-2.44 + "-Wno-error=discarded-qualifiers" ] ); From b9cbf8617f196a3c4c44a55b564d9e7d44d84432 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 9 Sep 2026 09:10:42 +0200 Subject: [PATCH 379/423] orbuculum: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344174435 --- pkgs/by-name/or/orbuculum/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/or/orbuculum/package.nix b/pkgs/by-name/or/orbuculum/package.nix index 80ce39a2c83f..055a5051937e 100644 --- a/pkgs/by-name/or/orbuculum/package.nix +++ b/pkgs/by-name/or/orbuculum/package.nix @@ -39,6 +39,9 @@ stdenv.mkDerivation (finalAttrs: { popd ''; + # fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + nativeBuildInputs = [ meson ninja From 6e4c64d6deb09965e0c6994b605095222494467f Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 9 Sep 2026 09:11:23 +0200 Subject: [PATCH 380/423] liquidwar: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344166064 --- pkgs/by-name/li/liquidwar/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/li/liquidwar/package.nix b/pkgs/by-name/li/liquidwar/package.nix index 8da0022a3421..35761a6e8d8d 100644 --- a/pkgs/by-name/li/liquidwar/package.nix +++ b/pkgs/by-name/li/liquidwar/package.nix @@ -96,6 +96,8 @@ stdenv.mkDerivation (finalAttrs: { "-Wno-error=address" "-Wno-error=use-after-free" "-std=gnu17" + # Fix build w/ glibc-2.44 + "-Wno-error=discarded-qualifiers" ] ++ [ "-Wno-error=deprecated-declarations" From f5757270ac1ba0a30e1505128ab70c5c6747ac17 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 9 Sep 2026 09:11:47 +0200 Subject: [PATCH 381/423] papi: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344174835/log --- pkgs/by-name/pa/papi/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/pa/papi/package.nix b/pkgs/by-name/pa/papi/package.nix index 96c0ee99f1ab..164a7b46104a 100644 --- a/pkgs/by-name/pa/papi/package.nix +++ b/pkgs/by-name/pa/papi/package.nix @@ -13,6 +13,9 @@ stdenv.mkDerivation (finalAttrs: { sha256 = "sha256-qb/4nM85kV1yngiuCgxqcc4Ou+mEEemi6zyDyNsK85w="; }; + # Fix build w/ glibc-2.44 + env.NIX_CFLAGS_COMPILE = "-Wno-error=discarded-qualifiers"; + setSourceRoot = '' sourceRoot=$(echo */src) ''; From 19863a81d5d517028cdb38a091774ba3f366786d Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 9 Sep 2026 09:12:16 +0200 Subject: [PATCH 382/423] mimic: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344168963 --- pkgs/by-name/mi/mimic/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/mi/mimic/package.nix b/pkgs/by-name/mi/mimic/package.nix index 931460357fb8..5b158b89ee77 100644 --- a/pkgs/by-name/mi/mimic/package.nix +++ b/pkgs/by-name/mi/mimic/package.nix @@ -55,6 +55,8 @@ stdenv.mkDerivation (finalAttrs: { env.NIX_CFLAGS_COMPILE = toString [ # Needed with GCC 12 "-Wno-error=free-nonheap-object" + # Fix build w/ glibc-2.44 + "-Wno-error=discarded-qualifiers" ]; postInstall = '' From ee3cffdbb7e3d4bad12c32a6b6ff94e8700ec23e Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 9 Sep 2026 09:15:35 +0200 Subject: [PATCH 383/423] guacamole-server: 1.6.0-unstable-2025-06-29 -> 1.6.0-unstable-2026-08-16 Fixes build w/ glibc-2.44. Failing Hydra build: https://hydra.nixos.org/build/344150990 --- pkgs/by-name/gu/guacamole-server/package.nix | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/gu/guacamole-server/package.nix b/pkgs/by-name/gu/guacamole-server/package.nix index c79a68bdc5f7..89634c3bc25a 100644 --- a/pkgs/by-name/gu/guacamole-server/package.nix +++ b/pkgs/by-name/gu/guacamole-server/package.nix @@ -2,7 +2,6 @@ lib, stdenv, fetchFromGitHub, - fetchpatch2, pkg-config, autoPatchelfHook, autoreconfHook, @@ -28,13 +27,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "guacamole-server"; - version = "1.6.0-unstable-2025-06-29"; + version = "1.6.0-unstable-2026-08-16"; src = fetchFromGitHub { owner = "apache"; repo = "guacamole-server"; - rev = "f3f5b9d76649ccc24f551cb166c81078f4b5e236"; - hash = "sha256-OjTwAQzKUuXfwZXLsL9XjrJc/0be38CmAGG+CoCeNwk="; + rev = "d3b7828977c63a5b197158d6cbbdaf1846b579fb"; + hash = "sha256-sxZLzF6m35EtfLRHb1+aqR3RF+piOuvPT9w9Hs3cor0="; }; env.NIX_CFLAGS_COMPILE = toString [ From 256511bd011ccca65cb19d0509c560716cc71213 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 9 Sep 2026 11:50:57 +0200 Subject: [PATCH 384/423] clickhouse: fix build w/ glibc-2.44 `struct open_how` is actually defined now, even though the value is set to false. Failing Hydra build: https://hydra.nixos.org/build/344143757 --- pkgs/by-name/cl/clickhouse/generic.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/cl/clickhouse/generic.nix b/pkgs/by-name/cl/clickhouse/generic.nix index 4616222f3363..ec64d528972a 100644 --- a/pkgs/by-name/cl/clickhouse/generic.nix +++ b/pkgs/by-name/cl/clickhouse/generic.nix @@ -130,6 +130,9 @@ llvmStdenv.mkDerivation (finalAttrs: { postPatch = '' patchShebangs src/ utils/ + + substituteInPlace contrib/liburing-cmake/CMakeLists.txt \ + --replace-fail "set (LIBURING_CONFIG_HAS_OPEN_HOW FALSE)" "set (LIBURING_CONFIG_HAS_OPEN_HOW TRUE)" '' + lib.optionalString stdenv.hostPlatform.isDarwin '' substituteInPlace cmake/tools.cmake \ From 12773d25e799cb948d94f198392036ba41fafaf2 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Sat, 19 Sep 2026 15:27:54 +0200 Subject: [PATCH 385/423] linux_6_1: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344163800 The full commit[1] doesn't apply on 6.1, so I ported the only relevant portion to it. Backport is currently pending[2] (as I've noticed after hand-rolling this patch), so for now we're only applying what we actually need. [1] https://lore.kernel.org/r/20251206092825.1471385-1-mikhail.v.gavrilov@gmail.com [2] https://lore.kernel.org/all/2026051315-engorge-agreed-39cb@gregkh/ --- pkgs/os-specific/linux/kernel/C23-compat-6.1.patch | 13 +++++++++++++ pkgs/os-specific/linux/kernel/patches.nix | 5 +++++ pkgs/top-level/linux-kernels.nix | 1 + 3 files changed, 19 insertions(+) create mode 100644 pkgs/os-specific/linux/kernel/C23-compat-6.1.patch diff --git a/pkgs/os-specific/linux/kernel/C23-compat-6.1.patch b/pkgs/os-specific/linux/kernel/C23-compat-6.1.patch new file mode 100644 index 000000000000..73c268b8b615 --- /dev/null +++ b/pkgs/os-specific/linux/kernel/C23-compat-6.1.patch @@ -0,0 +1,13 @@ +diff --git a/tools/lib/bpf/libbpf.c b/tools/lib/bpf/libbpf.c +index 7bd6aff6e260..33b214a91338 100644 +--- a/tools/lib/bpf/libbpf.c ++++ b/tools/lib/bpf/libbpf.c +@@ -10748,7 +10748,7 @@ static int resolve_full_path(const char *file, char *result, size_t result_sz) + if (!search_paths[i]) + continue; + for (s = search_paths[i]; s != NULL; s = strchr(s, ':')) { +- char *next_path; ++ const char *next_path; + int seg_len; + + if (s[0] == ':') diff --git a/pkgs/os-specific/linux/kernel/patches.nix b/pkgs/os-specific/linux/kernel/patches.nix index db617c867064..12cf001b6503 100644 --- a/pkgs/os-specific/linux/kernel/patches.nix +++ b/pkgs/os-specific/linux/kernel/patches.nix @@ -27,4 +27,9 @@ name = "request-key-helper"; patch = ./request-key-helper.patch; }; + + libbpf_C23_compat = { + name = "c23-compat-libbpf"; + patch = ./C23-compat-6.1.patch; + }; } diff --git a/pkgs/top-level/linux-kernels.nix b/pkgs/top-level/linux-kernels.nix index d3fa965d9516..3baabf4a14b5 100644 --- a/pkgs/top-level/linux-kernels.nix +++ b/pkgs/top-level/linux-kernels.nix @@ -65,6 +65,7 @@ in kernelPatches = [ kernelPatches.bridge_stp_helper kernelPatches.request_key_helper + kernelPatches.libbpf_C23_compat ]; }; From 85f87c51d67caf1c13de83a949801efa6373ee63 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Sat, 19 Sep 2026 15:51:30 +0200 Subject: [PATCH 386/423] electron_42: fix build w/ glibc-2.44 Failing Hydra build: https://hydra.nixos.org/build/344146127 Electron 43+ have a Chromium codebase that is new enough to contain the patch in question. --- pkgs/development/tools/electron/common.nix | 3 +- .../electron/fix-electron42-glibc-2.43.patch | 67 +++++++++++++++++++ 2 files changed, 69 insertions(+), 1 deletion(-) create mode 100644 pkgs/development/tools/electron/fix-electron42-glibc-2.43.patch diff --git a/pkgs/development/tools/electron/common.nix b/pkgs/development/tools/electron/common.nix index 5b72914afc4c..1d63d94bb7c4 100644 --- a/pkgs/development/tools/electron/common.nix +++ b/pkgs/development/tools/electron/common.nix @@ -111,7 +111,8 @@ in ++ # Restore fake libGLESv2.so which is patchelf'd by the chromium derivation lib.optional (lib.versionAtLeast info.version "44") - ./0001-Revert-build-stop-shipping-dummy-ANGLE-libs-in-Linux.patch; + ./0001-Revert-build-stop-shipping-dummy-ANGLE-libs-in-Linux.patch + ++ lib.optional (lib.versionOlder info.version "43") ./fix-electron42-glibc-2.43.patch; postPatch = '' mkdir -p third_party/jdk/current/bin diff --git a/pkgs/development/tools/electron/fix-electron42-glibc-2.43.patch b/pkgs/development/tools/electron/fix-electron42-glibc-2.43.patch new file mode 100644 index 000000000000..27ca436c2b52 --- /dev/null +++ b/pkgs/development/tools/electron/fix-electron42-glibc-2.43.patch @@ -0,0 +1,67 @@ +From 83a9ccb1265dcdeeb8bf17205e00b751f86641d3 Mon Sep 17 00:00:00 2001 +From: Ho Cheung +Date: Tue, 21 Apr 2026 08:19:53 -0700 +Subject: [PATCH] [sandbox] Fix SYS_SECCOMP conflict with newer glibc + +glibc now exposes SYS_SECCOMP in signal headers, which conflicts with +Chromium's fallback macro in linux_seccomp.h. + +Stop defining SYS_SECCOMP in the public compat header and use a local +fallback in trap.cc instead. + +Test: Tested on an Ubuntu 26.04 container using use_sysroot = false. +Bug: 456218403 +Change-Id: I73ddfa85453dd9d524b64b4c1bca4f95b82c9f2b +Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7781604 +Reviewed-by: Elly +Commit-Queue: Aaron Teo +Cr-Commit-Position: refs/heads/main@{#1618207} +--- + +diff --git a/sandbox/linux/seccomp-bpf/trap.cc b/sandbox/linux/seccomp-bpf/trap.cc +index 1316786d..212e80e 100644 +--- a/sandbox/linux/seccomp-bpf/trap.cc ++++ b/sandbox/linux/seccomp-bpf/trap.cc +@@ -29,6 +29,12 @@ + + namespace { + ++#if defined(SYS_SECCOMP) ++constexpr int kSigsysSeccompCode = SYS_SECCOMP; ++#else ++constexpr int kSigsysSeccompCode = 1; ++#endif ++ + struct arch_sigsys { + // RAW_PTR_EXCLUSION: Points to a code address given to us by the kernel. + RAW_PTR_EXCLUSION void* ip; +@@ -151,7 +157,7 @@ + // Various sanity checks to make sure we actually received a signal + // triggered by a BPF filter. If something else triggered SIGSYS + // (e.g. kill()), there is really nothing we can do with this signal. +- if (nr != LINUX_SIGSYS || info->si_code != SYS_SECCOMP || !ctx || ++ if (nr != LINUX_SIGSYS || info->si_code != kSigsysSeccompCode || !ctx || + info->si_errno <= 0 || + static_cast(info->si_errno) > trap_array_size_) { + // ATI drivers seem to send SIGSYS, so this cannot be FATAL. +@@ -162,7 +168,6 @@ + return; + } + +- + // Obtain the siginfo information that is specific to SIGSYS. + struct arch_sigsys sigsys; + #if defined(si_call_addr) +diff --git a/sandbox/linux/system_headers/linux_seccomp.h b/sandbox/linux/system_headers/linux_seccomp.h +index 8690a96..8ebf4045 100644 +--- a/sandbox/linux/system_headers/linux_seccomp.h ++++ b/sandbox/linux/system_headers/linux_seccomp.h +@@ -214,8 +214,4 @@ + #define SECCOMP_RET_INVALID 0x00010000U // Illegal return value + #endif + +-#ifndef SYS_SECCOMP +-#define SYS_SECCOMP 1 +-#endif +- + #endif // SANDBOX_LINUX_SYSTEM_HEADERS_LINUX_SECCOMP_H_ From 91c3fb7d5a389a5a4b1b17a2dc30429046089d57 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Sat, 19 Sep 2026 16:06:45 +0200 Subject: [PATCH 387/423] zutty: mark as broken Failing Hydra build: https://hydra.nixos.org/build/344291345 No upstream fix available. --- pkgs/by-name/zu/zutty/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/zu/zutty/package.nix b/pkgs/by-name/zu/zutty/package.nix index 06f975b68420..5a6f7ebfb87d 100644 --- a/pkgs/by-name/zu/zutty/package.nix +++ b/pkgs/by-name/zu/zutty/package.nix @@ -57,5 +57,6 @@ stdenv.mkDerivation (finalAttrs: { license = lib.licenses.gpl3Plus; maintainers = [ lib.maintainers.rolfschr ]; platforms = lib.platforms.linux; + broken = true; # Added 2026-09-19, fails with latest glibc }; }) From ebb9ee0fef2b237d2f9572defa0ab840b9fcce0b Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Sat, 19 Sep 2026 10:42:09 -0400 Subject: [PATCH 388/423] file: add mdaniels5757 as co-maintainer --- pkgs/by-name/fi/file/package.nix | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/fi/file/package.nix b/pkgs/by-name/fi/file/package.nix index 37516e53fe1e..c2b339fbfbce 100644 --- a/pkgs/by-name/fi/file/package.nix +++ b/pkgs/by-name/fi/file/package.nix @@ -64,7 +64,10 @@ stdenv.mkDerivation (finalAttrs: { meta = { homepage = "https://darwinsys.com/file"; description = "Program that shows the type of files"; - maintainers = with lib.maintainers; [ doronbehar ]; + maintainers = with lib.maintainers; [ + doronbehar + mdaniels5757 + ]; license = lib.licenses.bsd2; pkgConfigModules = [ "libmagic" ]; platforms = lib.platforms.all; From dabf496cd0b3c5ebf92dc0a7468ff31b47ad720b Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 19 Sep 2026 23:03:53 +0000 Subject: [PATCH 389/423] mimalloc: 3.4.5 -> 3.5.3 --- pkgs/by-name/mi/mimalloc/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/mi/mimalloc/package.nix b/pkgs/by-name/mi/mimalloc/package.nix index 810596fdfe03..5bedb5faa044 100644 --- a/pkgs/by-name/mi/mimalloc/package.nix +++ b/pkgs/by-name/mi/mimalloc/package.nix @@ -12,13 +12,13 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "mimalloc"; - version = "3.4.5"; + version = "3.5.3"; src = fetchFromGitHub { owner = "microsoft"; repo = "mimalloc"; tag = "v${finalAttrs.version}"; - hash = "sha256-vNVZw2YsDkf0GcdFTNb/fXMQLQYvoc8P425LupPShpo="; + hash = "sha256-GmLMWdUR2/VXJY7A8dZtwoV9FJIx0sxj8KWI4kG8IrU="; }; doCheck = !stdenv.hostPlatform.isStatic; From e19b7d221ab55887ea6f755e3d54e730d6f52f9a Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Sat, 19 Sep 2026 16:59:40 +0200 Subject: [PATCH 390/423] onetbb: fix nullptr deref in hwloc probe This fixes OpenVINO CPU plugin initialization in the Nix sandbox. --- .../on/onetbb/fix-hwloc-nullptr-deref.patch | 15 +++++++++++++++ pkgs/by-name/on/onetbb/package.nix | 3 +++ 2 files changed, 18 insertions(+) create mode 100644 pkgs/by-name/on/onetbb/fix-hwloc-nullptr-deref.patch diff --git a/pkgs/by-name/on/onetbb/fix-hwloc-nullptr-deref.patch b/pkgs/by-name/on/onetbb/fix-hwloc-nullptr-deref.patch new file mode 100644 index 000000000000..65b69293e155 --- /dev/null +++ b/pkgs/by-name/on/onetbb/fix-hwloc-nullptr-deref.patch @@ -0,0 +1,15 @@ +diff --git a/src/tbbbind/tbb_bind.cpp b/src/tbbbind/tbb_bind.cpp +index 26fa6747..2adccea5 100644 +--- a/src/tbbbind/tbb_bind.cpp ++++ b/src/tbbbind/tbb_bind.cpp +@@ -268,7 +268,9 @@ private: + // this function calls the interface that is available in the HWLOC 2.5 only. + #if HWLOC_API_VERSION >= 0x20500 + auto some_core = hwloc_get_next_obj_by_type(topology, HWLOC_OBJ_CORE, nullptr); +- hwloc_get_obj_with_same_locality(topology, some_core, HWLOC_OBJ_CORE, nullptr, nullptr, 0); ++ if (some_core) { ++ hwloc_get_obj_with_same_locality(topology, some_core, HWLOC_OBJ_CORE, nullptr, nullptr, 0); ++ } + #endif + } + diff --git a/pkgs/by-name/on/onetbb/package.nix b/pkgs/by-name/on/onetbb/package.nix index 3ab06b8bc1f7..bf9ed333195e 100644 --- a/pkgs/by-name/on/onetbb/package.nix +++ b/pkgs/by-name/on/onetbb/package.nix @@ -44,6 +44,9 @@ stdenv.mkDerivation (finalAttrs: { # # ./fix-libtbbmalloc-dlopen.patch + + # + ./fix-hwloc-nullptr-deref.patch ]; nativeBuildInputs = [ From 780932049b42948653305433dd1edae27016a334 Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Sat, 19 Sep 2026 10:50:28 -0400 Subject: [PATCH 391/423] file: add musl build to passthru.tests --- pkgs/by-name/fi/file/package.nix | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/fi/file/package.nix b/pkgs/by-name/fi/file/package.nix index c2b339fbfbce..9e1f9ddb492b 100644 --- a/pkgs/by-name/fi/file/package.nix +++ b/pkgs/by-name/fi/file/package.nix @@ -8,6 +8,7 @@ libgnurx ? windows.libgnurx, updateAutotoolsGnuConfigScriptsHook, testers, + pkgsMusl ? { }, # default to empty set to avoid CI fails with allowVariants = false }: # Note: this package is used for bootstrapping fetchurl, and thus @@ -57,7 +58,10 @@ stdenv.mkDerivation (finalAttrs: { !lib.systems.equals stdenv.hostPlatform stdenv.buildPlatform ) "FILE_COMPILE=${lib.getExe buildPackages.file}"; - passthru.tests.pkg-config = testers.testMetaPkgConfig finalAttrs.finalPackage; + passthru.tests = { + musl = pkgsMusl.file or null; + pkg-config = testers.testMetaPkgConfig finalAttrs.finalPackage; + }; __structuredAttrs = true; From b41e03e2d523f86fb317ad2c174f238bb5e91724 Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Sat, 19 Sep 2026 10:50:42 -0400 Subject: [PATCH 392/423] file: always run tests --- pkgs/by-name/fi/file/package.nix | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/pkgs/by-name/fi/file/package.nix b/pkgs/by-name/fi/file/package.nix index 9e1f9ddb492b..c0f19cfe8b8c 100644 --- a/pkgs/by-name/fi/file/package.nix +++ b/pkgs/by-name/fi/file/package.nix @@ -50,8 +50,7 @@ stdenv.mkDerivation (finalAttrs: { ]; buildInputs = [ zlib ] ++ lib.optional stdenv.hostPlatform.isMinGW libgnurx; - # https://bugs.astron.com/view.php?id=382 - doCheck = !stdenv.buildPlatform.isMusl; + doCheck = true; # In native builds, it will use the newly-compiled file instead. makeFlags = lib.optional ( From 93fd013de3bd188c39e9c5d0263a0581629a550d Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Sat, 19 Sep 2026 14:07:37 -0400 Subject: [PATCH 393/423] file: use versionCheckHook --- pkgs/by-name/fi/file/package.nix | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/pkgs/by-name/fi/file/package.nix b/pkgs/by-name/fi/file/package.nix index c0f19cfe8b8c..39c185a8fb19 100644 --- a/pkgs/by-name/fi/file/package.nix +++ b/pkgs/by-name/fi/file/package.nix @@ -9,6 +9,7 @@ updateAutotoolsGnuConfigScriptsHook, testers, pkgsMusl ? { }, # default to empty set to avoid CI fails with allowVariants = false + versionCheckHook, }: # Note: this package is used for bootstrapping fetchurl, and thus @@ -52,6 +53,9 @@ stdenv.mkDerivation (finalAttrs: { doCheck = true; + nativeInstallCheckInputs = [ versionCheckHook ]; + doInstallCheck = true; + # In native builds, it will use the newly-compiled file instead. makeFlags = lib.optional ( !lib.systems.equals stdenv.hostPlatform stdenv.buildPlatform From 2bae9f4d18cd3253c31881e3fb6cadab050a9672 Mon Sep 17 00:00:00 2001 From: Will Fancher Date: Sat, 19 Sep 2026 22:53:08 -0400 Subject: [PATCH 394/423] systemd: 261.2 -> 261.3 --- pkgs/os-specific/linux/systemd/default.nix | 12 ++---------- 1 file changed, 2 insertions(+), 10 deletions(-) diff --git a/pkgs/os-specific/linux/systemd/default.nix b/pkgs/os-specific/linux/systemd/default.nix index b187c1d4b54e..958c424ba30e 100644 --- a/pkgs/os-specific/linux/systemd/default.nix +++ b/pkgs/os-specific/linux/systemd/default.nix @@ -5,7 +5,6 @@ pkgsCross, testers, fetchFromGitHub, - fetchpatch, buildPackages, makeBinaryWrapper, ninja, @@ -204,13 +203,13 @@ let in stdenv.mkDerivation (finalAttrs: { inherit pname; - version = "261.2"; + version = "261.3"; src = fetchFromGitHub { owner = "systemd"; repo = "systemd"; tag = "v${finalAttrs.version}"; - hash = "sha256-w0Fxx+zYBs806whyaKBytGwSgn89ARdukAm6Hp+XlQQ="; + hash = "sha256-W3E6QUxr+x5jt4KJlHWbP4unyQCI7yA5oymgz6la1ng="; }; # PATCH POLICY @@ -240,13 +239,6 @@ stdenv.mkDerivation (finalAttrs: { ./0003-add-rootprefix-to-lookup-dir-paths.patch ./0004-path-util.h-add-placeholder-for-DEFAULT_PATH_NORMAL.patch ./0005-core-don-t-taint-on-unmerged-usr.patch - # Remove this with v262 - # Fixes an issue for switch-to-configuration - (fetchpatch { - name = "postpone-d-bus-queue-dispatch.patch"; - url = "https://github.com/systemd/systemd/commit/266b3e50218e2b27cd67d2371c165bf53ad3bf00.patch"; - hash = "sha256-dEEzZUqicnmgDuXVBV1y0BxzgKbb6Q47Dmxj+O71bFE="; - }) ] ++ lib.optionals (stdenv.hostPlatform.isLinux && stdenv.hostPlatform.isGnu) [ ./0006-timesyncd-disable-NSCD-when-DNSSEC-validation-is-dis.patch From 188f6b434adf468f419c598c6ab3a99300c00e0f Mon Sep 17 00:00:00 2001 From: whispers Date: Mon, 6 Jul 2026 17:31:19 -0400 Subject: [PATCH 395/423] minimal-bootstrap.gcc-latest: 15.3.0 -> 16.2.0 https://gcc.gnu.org/gcc-16/changes.html --- pkgs/os-specific/linux/minimal-bootstrap/gcc/latest.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/minimal-bootstrap/gcc/latest.nix b/pkgs/os-specific/linux/minimal-bootstrap/gcc/latest.nix index 0489f9ceb125..568ca57936bd 100644 --- a/pkgs/os-specific/linux/minimal-bootstrap/gcc/latest.nix +++ b/pkgs/os-specific/linux/minimal-bootstrap/gcc/latest.nix @@ -21,11 +21,11 @@ }: let pname = "gcc"; - version = "15.3.0"; + version = "16.2.0"; src = fetchurl { url = "mirror://gnu/gcc/gcc-${version}/gcc-${version}.tar.xz"; - hash = "sha256-+lnBvu+JlfJ8TXHB3yJ1hxiTFdPm+v8btDBuYbDFMOs="; + hash = "sha256-5nOOKVl/czJwcxqpBgDzf/3ARQed/CfsfoGSzIEIXD4="; }; gmpVersion = "6.3.0"; From 4632343d624e8a1e4d51fca94d6d6f690918e27f Mon Sep 17 00:00:00 2001 From: whispers Date: Mon, 6 Jul 2026 17:31:19 -0400 Subject: [PATCH 396/423] minimal-bootstrap.gcc-glibc: 15.3.0 -> 16.2.0 https://gcc.gnu.org/gcc-16/changes.html --- pkgs/os-specific/linux/minimal-bootstrap/gcc/glibc.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/minimal-bootstrap/gcc/glibc.nix b/pkgs/os-specific/linux/minimal-bootstrap/gcc/glibc.nix index 84429548ef45..45c7f71c6fc2 100644 --- a/pkgs/os-specific/linux/minimal-bootstrap/gcc/glibc.nix +++ b/pkgs/os-specific/linux/minimal-bootstrap/gcc/glibc.nix @@ -22,7 +22,7 @@ }: let pname = "gcc"; - version = "15.3.0"; + version = "16.2.0"; linkerName = { i686-linux = "ld-linux.so.2"; @@ -32,7 +32,7 @@ let src = fetchurl { url = "mirror://gnu/gcc/gcc-${version}/gcc-${version}.tar.xz"; - hash = "sha256-+lnBvu+JlfJ8TXHB3yJ1hxiTFdPm+v8btDBuYbDFMOs="; + hash = "sha256-5nOOKVl/czJwcxqpBgDzf/3ARQed/CfsfoGSzIEIXD4="; }; gmpVersion = "6.3.0"; From a1eee2b35c78a577b7b58a7958385767d5993448 Mon Sep 17 00:00:00 2001 From: whispers Date: Tue, 30 Jun 2026 19:54:30 -0400 Subject: [PATCH 397/423] gcc: 15 -> 16 changes: https://gcc.gnu.org/gcc-16/changes.html porting guide: https://gcc.gnu.org/gcc-16/porting_to.html --- doc/release-notes/rl-2611.section.md | 2 ++ pkgs/top-level/all-packages.nix | 2 +- 2 files changed, 3 insertions(+), 1 deletion(-) diff --git a/doc/release-notes/rl-2611.section.md b/doc/release-notes/rl-2611.section.md index d0a2a1b0cd5b..f28e7a0bb08e 100644 --- a/doc/release-notes/rl-2611.section.md +++ b/doc/release-notes/rl-2611.section.md @@ -16,6 +16,8 @@ +nixpkgs.url = "https://channels.nixos.org/nixos-26.05/nixexprs.tar.zst"; ``` +- GCC has been updated from GCC 15 to GCC 16. This introduces some backwards-incompatible changes. Refer to the [upstream porting guide](https://gcc.gnu.org/gcc-16/porting_to.html) for details. + - Emacs has been updated to 31. This introduces some backwards‐incompatible changes; see the NEWS for details. NEWS can be viewed from Emacs by typing `C-h n`, or by clicking `Help->Emacs News` from the menu bar. diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 5a15b0d25fd7..ff41f52dba1b 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -3194,7 +3194,7 @@ with pkgs; gerbilPackages-unstable = pkgs.gerbil-support.gerbilPackages-unstable; # NB: don't recurseIntoAttrs for (unstable!) libraries glow-lang = pkgs.gerbilPackages-unstable.glow-lang; - default-gcc-version = 15; + default-gcc-version = 16; gcc = pkgs.${"gcc${toString default-gcc-version}"}; gccFun = callPackage ../development/compilers/gcc; gcc-unwrapped = gcc.cc; From 83a31a3822f71af2ff73f7694b7bbb09792dafcd Mon Sep 17 00:00:00 2001 From: dramforever Date: Sun, 26 Jul 2026 00:00:30 +0800 Subject: [PATCH 398/423] stdenv-bootstrap-tools: Fix lib*_asneeded problem on gcc16 GCC 16 added and starts using -latomic_asneeded and -lgcc_s_asneeded to pull in the corresponding libraries as if --as-needed. Add these linker scripts. After fixing this, gcc in turn wants libatomic, so reuse the existing line copying it for riscv, and use it for all platforms. See https://gcc.gnu.org/bugzilla/show_bug.cgi?id=123650 for why this was added. (cherry picked from commit cd01953447f1d35c6dcbb97451db1bd813c13cda) --- pkgs/stdenv/linux/stdenv-bootstrap-tools.nix | 12 +++--------- 1 file changed, 3 insertions(+), 9 deletions(-) diff --git a/pkgs/stdenv/linux/stdenv-bootstrap-tools.nix b/pkgs/stdenv/linux/stdenv-bootstrap-tools.nix index 35d9dfc37dc7..05318e777eb5 100644 --- a/pkgs/stdenv/linux/stdenv-bootstrap-tools.nix +++ b/pkgs/stdenv/linux/stdenv-bootstrap-tools.nix @@ -135,6 +135,9 @@ stdenv.mkDerivation (finalAttrs: { cp -d ${bootGCC.lib}/lib/libstdc++.so* $out/lib cp -d ${bootGCC.out}/lib/libssp.a* $out/lib cp -d ${bootGCC.out}/lib/libssp_nonshared.a $out/lib + cp -d ${bootGCC.lib}/lib/libgcc_s_asneeded.so $out/lib + cp -d ${bootGCC.lib}/lib/libatomic_asneeded.so $out/lib + cp -d ${bootGCC.out}/lib/libatomic.a* $out/lib cp -rd ${bootGCC.out}/lib/gcc $out/lib chmod -R u+w $out/lib rm -f $out/lib/gcc/*/*/include*/linux @@ -156,15 +159,6 @@ stdenv.mkDerivation (finalAttrs: { cp -d ${mpfr.out}/lib/libmpfr*.so* $out/lib cp -d ${libmpc.out}/lib/libmpc*.so* $out/lib cp -d ${zlib.out}/lib/libz.so* $out/lib - - '' - + lib.optionalString (stdenv.hostPlatform.isRiscV) '' - # libatomic is required on RiscV platform for C/C++ atomics and pthread - # even though they may be translated into native instructions. - cp -d ${bootGCC.out}/lib/libatomic.a* $out/lib - - '' - + '' cp -d ${bzip2.out}/lib/libbz2.so* $out/lib # Copy binutils. From db3241d439ad5710ce703fe6c20d44fa348f51a9 Mon Sep 17 00:00:00 2001 From: Ben Siraphob Date: Sun, 20 Sep 2026 10:33:01 -0700 Subject: [PATCH 399/423] minimal-bootstrap: separate musl tools from runtime --- .../linux/minimal-bootstrap/musl/default.nix | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/pkgs/os-specific/linux/minimal-bootstrap/musl/default.nix b/pkgs/os-specific/linux/minimal-bootstrap/musl/default.nix index d9a96dd6e5a6..1a715a0158fa 100644 --- a/pkgs/os-specific/linux/minimal-bootstrap/musl/default.nix +++ b/pkgs/os-specific/linux/minimal-bootstrap/musl/default.nix @@ -25,6 +25,11 @@ bash.runCommand "${pname}-${version}" { inherit pname version meta; + outputs = [ + "out" + "bin" + ]; + nativeBuildInputs = [ gcc binutils @@ -87,5 +92,9 @@ bash.runCommand "${pname}-${version}" # Install make -j $NIX_BUILD_CORES install sed -i 's|/bin/sh|${bash}/bin/bash|' $out/bin/* - ln -s ../lib/libc.so $out/bin/ldd + + # Don't retain bootstrap bash in libc closure in wrapper + mkdir -p $bin + mv $out/bin $bin/bin + ln -s $out/lib/libc.so $bin/bin/ldd '' From 005d5f2d18bb340b5f4d4380fe846e33969fdc2c Mon Sep 17 00:00:00 2001 From: Ben Siraphob Date: Sun, 20 Sep 2026 10:33:02 -0700 Subject: [PATCH 400/423] minimal-bootstrap: header installation should not retain build-time bash and sed --- pkgs/os-specific/linux/minimal-bootstrap/gcc/glibc.nix | 3 +++ pkgs/os-specific/linux/minimal-bootstrap/gcc/latest.nix | 3 +++ 2 files changed, 6 insertions(+) diff --git a/pkgs/os-specific/linux/minimal-bootstrap/gcc/glibc.nix b/pkgs/os-specific/linux/minimal-bootstrap/gcc/glibc.nix index 84429548ef45..d9d538af5ce1 100644 --- a/pkgs/os-specific/linux/minimal-bootstrap/gcc/glibc.nix +++ b/pkgs/os-specific/linux/minimal-bootstrap/gcc/glibc.nix @@ -155,6 +155,9 @@ bash.runCommand "${pname}-${version}" # Install make -j $NIX_BUILD_CORES install-strip + # Header installation tools retain build-time bash and sed unnecessarily. + rm -rf $out/libexec/gcc/*/*/install-tools $out/lib/gcc/*/*/install-tools + # libstdc++ gdb pretty-printers + man pages are unused downstream. rm -rf $out/share/gcc-*/python $out/share/man $out/share/info '' diff --git a/pkgs/os-specific/linux/minimal-bootstrap/gcc/latest.nix b/pkgs/os-specific/linux/minimal-bootstrap/gcc/latest.nix index 0489f9ceb125..54416459f508 100644 --- a/pkgs/os-specific/linux/minimal-bootstrap/gcc/latest.nix +++ b/pkgs/os-specific/linux/minimal-bootstrap/gcc/latest.nix @@ -154,6 +154,9 @@ bash.runCommand "${pname}-${version}" # Install make -j $NIX_BUILD_CORES install-strip + # Header installation tools retain build-time bash and sed unnecessarily. + rm -rf $out/libexec/gcc/*/*/install-tools $out/lib/gcc/*/*/install-tools + # libstdc++ gdb pretty-printers + man pages are unused downstream. rm -rf $out/share/gcc-*/python $out/share/man $out/share/info From bb0f35f8a06752ccce5b8d0c5733378cd6afc22f Mon Sep 17 00:00:00 2001 From: Sergei Trofimovich Date: Sun, 20 Sep 2026 20:47:59 +0100 Subject: [PATCH 401/423] swift.swiftArch, swift.swiftOs: fix the eval MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Without the chnage the eval fails as: $ nix eval 'nixpkgs/staging#swift.swiftArch' error: … in the left operand of the update (//) operator at «github:NixOS/nixpkgs/9cfde996e4f874e9b58a0e9efb5193d565b6daf3»/lib/derivations.nix:265:8: 264| drv 265| // mapAttrs (_: lib.warn msg) drvToWrap | ^ 266| // ( … while calling the 'mapAttrs' builtin at «github:NixOS/nixpkgs/9cfde996e4f874e9b58a0e9efb5193d565b6daf3»/lib/derivations.nix:265:8: 264| drv 265| // mapAttrs (_: lib.warn msg) drvToWrap | ^ 266| // ( (stack trace truncated; use '--show-trace' to show the full, detailed trace) error: expected a set but found a string: "x86_64" --- pkgs/development/compilers/swift/by-name/sw/swift/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/compilers/swift/by-name/sw/swift/package.nix b/pkgs/development/compilers/swift/by-name/sw/swift/package.nix index 5d9d5eabcdc2..bc96a9cd7f91 100644 --- a/pkgs/development/compilers/swift/by-name/sw/swift/package.nix +++ b/pkgs/development/compilers/swift/by-name/sw/swift/package.nix @@ -241,9 +241,9 @@ stdenv.mkDerivation (finalAttrs: { // lib.optionalAttrs config.allowAliases { # Legacy aliases for the old Swift packaging. These should eventually be removed. swift = lib.warnOnInstantiate "`swift` is an alias for this (`swift`) package. Just use it directly." finalAttrs.finalPackage; - swiftArch = lib.warnOnInstantiate "'swiftArch' is an alias for 'stdenv.hostPlatform.swift.arch'." stdenv.hostPlatform.swift.arch; + swiftArch = lib.warn "'swiftArch' is an alias for 'stdenv.hostPlatform.swift.arch'." stdenv.hostPlatform.swift.arch; swiftDriver = lib.warnOnInstantiate "'swiftDriver' has been renamed to 'swift-driver'" finalAttrs.passthru.swift-driver; - swiftOs = lib.warnOnInstantiate "'swiftOs' is an alias for 'stdenv.hostPlatform.swift.platform'." stdenv.hostPlatform.swift.platform; + swiftOs = lib.warn "'swiftOs' is an alias for 'stdenv.hostPlatform.swift.platform'." stdenv.hostPlatform.swift.platform; }; meta = { From 3c034ce44394077dabdf2bdcc351c4f881c4eaaf Mon Sep 17 00:00:00 2001 From: Sergei Trofimovich Date: Sun, 20 Sep 2026 21:00:45 +0100 Subject: [PATCH 402/423] utf8cpp: 4.2.0 -> 4.2.1 Changes: https://github.com/nemtrif/utfcpp/releases/tag/v4.2.1 --- pkgs/by-name/ut/utf8cpp/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ut/utf8cpp/package.nix b/pkgs/by-name/ut/utf8cpp/package.nix index e5ee3a2477d3..d0861d2a93bf 100644 --- a/pkgs/by-name/ut/utf8cpp/package.nix +++ b/pkgs/by-name/ut/utf8cpp/package.nix @@ -7,13 +7,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "utf8cpp"; - version = "4.2.0"; + version = "4.2.1"; src = fetchFromGitHub { owner = "nemtrif"; repo = "utfcpp"; tag = "v${finalAttrs.version}"; - hash = "sha256-vc7nKVVZ/h6q+dQUNiuXnkcqX7L2CkG6WUiybLNXAjU="; + hash = "sha256-/YpP2ZThfOL1O7aunjKYv5TCjVzMnXVGEefmBpRBIGY="; }; nativeBuildInputs = [ cmake ]; From 526ece09f456bccbeae84f9677f5a6c8e3e6b69c Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 21 Sep 2026 08:33:47 +0000 Subject: [PATCH 403/423] srtp: 2.8.0 -> 2.8.1 --- pkgs/by-name/sr/srtp/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/sr/srtp/package.nix b/pkgs/by-name/sr/srtp/package.nix index 84ec31998fad..e917d7b948ca 100644 --- a/pkgs/by-name/sr/srtp/package.nix +++ b/pkgs/by-name/sr/srtp/package.nix @@ -11,13 +11,13 @@ stdenv.mkDerivation rec { pname = "libsrtp"; - version = "2.8.0"; + version = "2.8.1"; src = fetchFromGitHub { owner = "cisco"; repo = "libsrtp"; rev = "v${version}"; - sha256 = "sha256-QHDcPFzDhlvgLPnXfFU6247OirscU41SzKStiTPU0oQ="; + sha256 = "sha256-kLuz3gPVDhm1fzcrXL4xky+hrTprJbcxgQCyb4nVThQ="; }; outputs = [ From a7da5b25d1b5582b5e8c207ed88bb4d6a3f928f3 Mon Sep 17 00:00:00 2001 From: Markus Kowalewski Date: Mon, 21 Sep 2026 13:16:00 +0200 Subject: [PATCH 404/423] openmpi: fix hash --- pkgs/by-name/op/openmpi/package.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/by-name/op/openmpi/package.nix b/pkgs/by-name/op/openmpi/package.nix index 4f809f56094f..b99dd9da3008 100644 --- a/pkgs/by-name/op/openmpi/package.nix +++ b/pkgs/by-name/op/openmpi/package.nix @@ -49,7 +49,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "https://www.open-mpi.org/software/ompi/v${lib.versions.majorMinor finalAttrs.version}/downloads/openmpi-${finalAttrs.version}.tar.bz2"; - sha256 = "sha256-cfQk150IotqRWeOrK9xGcgRXVgLCdE1E0aqYJ7xVvY4="; + sha256 = "sha256-5mijxKzVDEHcIEyKbdmKYR4PJq+Jz2d1d/qb6KJpgAM="; }; postPatch = '' From af9977e4c5208efe4f369383ae2e090fa27b3f7e Mon Sep 17 00:00:00 2001 From: Francesco Gazzetta Date: Sat, 12 Sep 2026 12:05:51 +0200 Subject: [PATCH 405/423] tcl.tclRequiresCheckHook: move tcl code from heredoc to a separate file A heredoc piped into tclsh makes tclsh run in interactive mode, which keeps running regardless of errors. This required us to `catch` the error and `exit` manually. By using a standalone script we avoid this hack and the error gets automatically printed out. With a standalone file we also get better editor support. --- pkgs/development/interpreters/tcl/generic.nix | 4 +++- .../tcl/tcl-requires-check-hook.sh | 23 ++----------------- .../tcl/tcl-requires-check-hook.tcl | 20 ++++++++++++++++ 3 files changed, 25 insertions(+), 22 deletions(-) create mode 100644 pkgs/development/interpreters/tcl/tcl-requires-check-hook.tcl diff --git a/pkgs/development/interpreters/tcl/generic.nix b/pkgs/development/interpreters/tcl/generic.nix index f5d3e863361d..d5c4b775473f 100644 --- a/pkgs/development/interpreters/tcl/generic.nix +++ b/pkgs/development/interpreters/tcl/generic.nix @@ -226,7 +226,9 @@ stdenv.mkDerivation (finalAttrs: { { buildPackages }: makeSetupHook { name = "tcl-requires-check-hook"; - propagatedBuildInputs = [ buildPackages.makeBinaryWrapper ]; + substitutions = { + tcl_hook = ./tcl-requires-check-hook.tcl; + }; meta = { inherit (finalAttrs.meta) maintainers platforms; license = lib.licenses.mit; diff --git a/pkgs/development/interpreters/tcl/tcl-requires-check-hook.sh b/pkgs/development/interpreters/tcl/tcl-requires-check-hook.sh index 76c5901f2a33..6e3066d03b48 100644 --- a/pkgs/development/interpreters/tcl/tcl-requires-check-hook.sh +++ b/pkgs/development/interpreters/tcl/tcl-requires-check-hook.sh @@ -6,27 +6,8 @@ tclRequiresCheckPhase () { if [ -n "$tclRequiresCheck" ]; then export TCLLIBPATH="$out/lib $TCLLIBPATH" # Redundant if tcl-package-hook is also used - tclsh <<'EOF' - if {[info exists env(NIX_ATTRS_JSON_FILE)]} { - set nix_attrs_json_file [open $env(NIX_ATTRS_JSON_FILE)] - set nix_attrs_json [read $nix_attrs_json_file] - close $nix_attrs_json_file - # Normally we'd use one of tcllib/tdom/rl_json/yajl-tcl to parse JSON, - # however we don't want to introduce a circular dependency, - # so we rely on the JSON capabilities of the builtin sqlite package - # https://wiki.tcl-lang.org/page/SQLite+extension+JSON1 - package require sqlite3 - sqlite3 db :memory: -readonly 1 - set packages_to_check [db eval { - select value from json_each(jsonb_extract($nix_attrs_json, '$.tclRequiresCheck')) - }] - db close - } else { - set packages_to_check $env(tclRequiresCheck) - } - puts "Check whether the following packages can be required: $packages_to_check" - exit [catch {foreach pkg $packages_to_check {package require $pkg}}] -EOF + # FIXME: For some reason the output gets swallowed unless we pipe it through cat‽ + tclsh @tcl_hook@ 2>&1 | cat fi } diff --git a/pkgs/development/interpreters/tcl/tcl-requires-check-hook.tcl b/pkgs/development/interpreters/tcl/tcl-requires-check-hook.tcl new file mode 100644 index 000000000000..ee373586144a --- /dev/null +++ b/pkgs/development/interpreters/tcl/tcl-requires-check-hook.tcl @@ -0,0 +1,20 @@ +#!/usr/bin/env tclsh +if {[info exists env(NIX_ATTRS_JSON_FILE)]} { + set nix_attrs_json_file [open $env(NIX_ATTRS_JSON_FILE)] + set nix_attrs_json [read $nix_attrs_json_file] + close $nix_attrs_json_file + # Normally we'd use one of tcllib/tdom/rl_json/yajl-tcl to parse JSON, + # however we don't want to introduce a circular dependency, + # so we rely on the JSON capabilities of the builtin sqlite package + # https://wiki.tcl-lang.org/page/SQLite+extension+JSON1 + package require sqlite3 + sqlite3 db :memory: -readonly 1 + set packages_to_check [db eval { + select value from json_each(jsonb_extract($nix_attrs_json, '$.tclRequiresCheck')) + }] + db close +} else { + set packages_to_check $env(tclRequiresCheck) +} +puts "Check whether the following packages can be required: $packages_to_check" +foreach pkg $packages_to_check {package require $pkg} From 009b2db5bb2a86efe729c805ce6ba455536b9bb7 Mon Sep 17 00:00:00 2001 From: sempiternal-aurora <78790545+sempiternal-aurora@users.noreply.github.com> Date: Wed, 19 Aug 2026 00:19:23 +1000 Subject: [PATCH 406/423] multiple-outputs.sh: fix with structuredAttrs The variable `propagatedBuildOutputs` was only allowed to be a string, so when `__structuredAttrs = true` was set, it was incorrectly detected, especially for empty arrays. Refactor the code to allow it to be either an array or string. Closes: #323126 --- .../setup-hooks/multiple-outputs.sh | 16 +++++++++------- 1 file changed, 9 insertions(+), 7 deletions(-) diff --git a/pkgs/build-support/setup-hooks/multiple-outputs.sh b/pkgs/build-support/setup-hooks/multiple-outputs.sh index cc3ab4816fa2..b744550ea350 100644 --- a/pkgs/build-support/setup-hooks/multiple-outputs.sh +++ b/pkgs/build-support/setup-hooks/multiple-outputs.sh @@ -192,23 +192,25 @@ _multioutPropagateDev() { propagaterOutput="$outputFirst" fi - # Default value: propagate binaries, includes and libraries - if [ -z "${propagatedBuildOutputs+1}" ]; then + local outputsToPropagate=() + if declare -p propagatedBuildOutputs &>/dev/null; then + concatTo outputsToPropagate propagatedBuildOutputs + else local po_dirty="$outputBin $outputInclude $outputLib" set +o pipefail - propagatedBuildOutputs=`echo "$po_dirty" \ + readarray -t outputsToPropagate < <(echo "$po_dirty" \ | tr -s ' ' '\n' | grep -v -F "$propagaterOutput" \ - | sort -u | tr '\n' ' ' ` + | sort -u ) set -o pipefail fi - # The variable was explicitly set to empty or we resolved it so - if [ -z "$propagatedBuildOutputs" ]; then + # Check whether we actually have any outputs to propagate + if [[ "${#outputsToPropagate[@]}" -eq 0 ]]; then return fi mkdir -p "${!propagaterOutput}"/nix-support - for output in $propagatedBuildOutputs; do + for output in "${outputsToPropagate[@]}"; do echo -n " ${!output}" >> "${!propagaterOutput}"/nix-support/propagated-build-inputs done } From 7d32cab9b4e9ece9070e901c3cae97681330a718 Mon Sep 17 00:00:00 2001 From: sempiternal-aurora <78790545+sempiternal-aurora@users.noreply.github.com> Date: Wed, 19 Aug 2026 00:24:12 +1000 Subject: [PATCH 407/423] gnucobol: enable __structuredAttrs --- pkgs/by-name/gn/gnucobol/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/gn/gnucobol/package.nix b/pkgs/by-name/gn/gnucobol/package.nix index 70931643a432..2e422c7e571b 100644 --- a/pkgs/by-name/gn/gnucobol/package.nix +++ b/pkgs/by-name/gn/gnucobol/package.nix @@ -32,6 +32,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "gnucobol"; version = "3.2"; + __structuredAttrs = true; strictDeps = true; src = fetchurl { From 85dcfcc36f2e76ad04252b9724a2377cb8712e69 Mon Sep 17 00:00:00 2001 From: rnhmjoj Date: Mon, 21 Sep 2026 18:15:45 +0200 Subject: [PATCH 408/423] python3Packages.libusb1: 3.3.1 -> 3.4.0 --- pkgs/development/python-modules/libusb1/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/libusb1/default.nix b/pkgs/development/python-modules/libusb1/default.nix index b655e14fd77a..ee82c5614d8d 100644 --- a/pkgs/development/python-modules/libusb1/default.nix +++ b/pkgs/development/python-modules/libusb1/default.nix @@ -11,14 +11,14 @@ buildPythonPackage rec { pname = "libusb1"; - version = "3.3.1"; + version = "3.4.0"; pyproject = true; src = fetchFromGitHub { owner = "vpelletier"; repo = "python-libusb1"; tag = version; - hash = "sha256-nytxew6KogpEpSnRtmY0UNH+07x0k0XLZ/MRC9NSpDg="; + hash = "sha256-w+Q00GWNobqQlvqryZlJl7SZPEMYgMtbuKpUSLneqNw="; }; patches = [ From e102e2a10bd06d1930e834c5ecad10314f615d3e Mon Sep 17 00:00:00 2001 From: Francesco Gazzetta Date: Mon, 21 Sep 2026 19:11:06 +0200 Subject: [PATCH 409/423] tcl: set mainProgram --- pkgs/development/interpreters/tcl/generic.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/development/interpreters/tcl/generic.nix b/pkgs/development/interpreters/tcl/generic.nix index f5d3e863361d..2a224f3fb30f 100644 --- a/pkgs/development/interpreters/tcl/generic.nix +++ b/pkgs/development/interpreters/tcl/generic.nix @@ -200,6 +200,7 @@ stdenv.mkDerivation (finalAttrs: { homepage = "https://www.tcl.tk/"; license = lib.licenses.tcltk; platforms = lib.platforms.all; + mainProgram = "tclsh"; maintainers = with lib.maintainers; [ agbrooks ]; }; From 7382f70aa31c47837e44551933e3bc80cad0b871 Mon Sep 17 00:00:00 2001 From: Francesco Gazzetta Date: Mon, 21 Sep 2026 19:11:23 +0200 Subject: [PATCH 410/423] tk: set mainProgram --- pkgs/development/libraries/tk/generic.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/development/libraries/tk/generic.nix b/pkgs/development/libraries/tk/generic.nix index dae3651d64be..eab95e8e5f3a 100644 --- a/pkgs/development/libraries/tk/generic.nix +++ b/pkgs/development/libraries/tk/generic.nix @@ -100,6 +100,7 @@ tcl.mkTclDerivation { homepage = "https://www.tcl.tk/"; license = lib.licenses.tcltk; platforms = lib.platforms.all; + mainProgram = "wish"; maintainers = [ ]; }; } From b3f4f11e7e411e0a7b34c9216360b3410f8e1f39 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Mon, 21 Sep 2026 19:16:40 +0200 Subject: [PATCH 411/423] python3Packages.django_5: skip flaky test The test checks performance and easily fails under cpu pressure. --- pkgs/development/python-modules/django/5.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/development/python-modules/django/5.nix b/pkgs/development/python-modules/django/5.nix index d9ec648838c7..202233c29318 100644 --- a/pkgs/development/python-modules/django/5.nix +++ b/pkgs/development/python-modules/django/5.nix @@ -59,6 +59,7 @@ buildPythonPackage rec { ./5.2/pythonpath.patch # disable test that expects timezone issues ./5.2/disable-failing-test.patch + ./6.x/skip-flaky-tests.patch ] ++ lib.optionals withGdal [ (replaceVars ./5.2/gdal.patch { From 71deb719ea6925bdcfff5b5d8709b8253d1a2a45 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Mon, 13 Jul 2026 14:26:01 +0200 Subject: [PATCH 412/423] frigate: 0.17.2 -> 0.18.0 --- nixos/modules/services/video/frigate.nix | 33 +- pkgs/by-name/fr/frigate/ai-edge-litert.patch | 100 --- pkgs/by-name/fr/frigate/ffmpeg.patch | 68 +- .../frigate/fix-tests-media-auth-paths.patch | 32 + pkgs/by-name/fr/frigate/package.nix | 212 +++-- pkgs/by-name/fr/frigate/pr23641.patch | 770 ++++++++++++++++++ .../fr/frigate/proc-cmdline-strip.patch | 22 - pkgs/by-name/fr/frigate/web.nix | 2 +- 8 files changed, 940 insertions(+), 299 deletions(-) delete mode 100644 pkgs/by-name/fr/frigate/ai-edge-litert.patch create mode 100644 pkgs/by-name/fr/frigate/fix-tests-media-auth-paths.patch create mode 100644 pkgs/by-name/fr/frigate/pr23641.patch delete mode 100644 pkgs/by-name/fr/frigate/proc-cmdline-strip.patch diff --git a/nixos/modules/services/video/frigate.nix b/nixos/modules/services/video/frigate.nix index 43941e64ac0d..c358f0cd63b2 100644 --- a/nixos/modules/services/video/frigate.nix +++ b/nixos/modules/services/video/frigate.nix @@ -405,7 +405,9 @@ in extraConfig = nginxAuthRequest + '' types { video/mp4 mp4; - image/jpeg jpg; + image/jpeg jpg jpeg; + image/png png; + image/webp webp; } expires 7d; @@ -493,19 +495,6 @@ in } ''; }; - # frontend uses this to fetch the version - "/api/go2rtc/api" = { - proxyPass = "http://frigate-go2rtc/api"; - recommendedProxySettings = true; - extraConfig = - nginxAuthRequest - + nginxProxySettings - + '' - limit_except GET { - deny all; - } - ''; - }; # integrationn uses this to add webrtc candidate "/api/go2rtc/webrtc" = { proxyPass = "http://frigate-go2rtc/api/webrtc"; @@ -541,6 +530,7 @@ in expires off; proxy_cache frigate_api_cache; + proxy_cache_key "$scheme$proxy_host$request_uri|$role|$groups|$user"; proxy_cache_lock on; proxy_cache_use_stale updating; proxy_cache_valid 200 5s; @@ -563,6 +553,13 @@ in ${nginxProxySettings} } + location /api/logout { + auth_request off; + rewrite ^/api(/.*)$ $1 break; + proxy_pass http://frigate-api; + ${nginxProxySettings} + } + location /api/auth/first_time_login { auth_request off; limit_except GET { @@ -747,7 +744,6 @@ in ] ++ optionals (!stdenv.hostPlatform.isAarch64) [ # not available on aarch64-linux - intel-gpu-tools rocmPackages.rocminfo ]; serviceConfig = { @@ -775,11 +771,10 @@ in Group = "frigate"; SupplementaryGroups = [ "render" ] ++ optionals withCoral [ "coral" ]; - AmbientCapabilities = optionals (elem cfg.vaapiDriver [ - "i965" - "iHD" - ]) [ "CAP_PERFMON" ]; # for intel_gpu_top + # No capabilities + CapabilityBoundingSet = [ "" ]; + # Allow delegating access UMask = "0027"; StateDirectory = "frigate"; diff --git a/pkgs/by-name/fr/frigate/ai-edge-litert.patch b/pkgs/by-name/fr/frigate/ai-edge-litert.patch deleted file mode 100644 index 3a8c3f8a566f..000000000000 --- a/pkgs/by-name/fr/frigate/ai-edge-litert.patch +++ /dev/null @@ -1,100 +0,0 @@ -diff --git a/frigate/data_processing/real_time/bird.py b/frigate/data_processing/real_time/bird.py -index 7851c0997..520440005 100644 ---- a/frigate/data_processing/real_time/bird.py -+++ b/frigate/data_processing/real_time/bird.py -@@ -22,7 +22,7 @@ from .api import RealTimeProcessorApi - try: - from tflite_runtime.interpreter import Interpreter - except ModuleNotFoundError: -- from tensorflow.lite.python.interpreter import Interpreter -+ from ai_edge_litert.interpreter import Interpreter - - logger = logging.getLogger(__name__) - -diff --git a/frigate/data_processing/real_time/custom_classification.py b/frigate/data_processing/real_time/custom_classification.py -index 229383d9f..2c74a6575 100644 ---- a/frigate/data_processing/real_time/custom_classification.py -+++ b/frigate/data_processing/real_time/custom_classification.py -@@ -32,7 +32,7 @@ from .api import RealTimeProcessorApi - try: - from tflite_runtime.interpreter import Interpreter - except ModuleNotFoundError: -- from tensorflow.lite.python.interpreter import Interpreter -+ from ai_edge_litert.interpreter import Interpreter - - logger = logging.getLogger(__name__) - -@@ -76,7 +76,7 @@ class CustomStateClassificationProcessor(RealTimeProcessorApi): - try: - from tflite_runtime.interpreter import Interpreter - except ModuleNotFoundError: -- from tensorflow.lite.python.interpreter import Interpreter -+ from ai_edge_litert.interpreter import Interpreter - - model_path = os.path.join(self.model_dir, "model.tflite") - labelmap_path = os.path.join(self.model_dir, "labelmap.txt") -diff --git a/frigate/detectors/detector_utils.py b/frigate/detectors/detector_utils.py -index d732de871..d8930b2ae 100644 ---- a/frigate/detectors/detector_utils.py -+++ b/frigate/detectors/detector_utils.py -@@ -6,7 +6,7 @@ import numpy as np - try: - from tflite_runtime.interpreter import Interpreter, load_delegate - except ModuleNotFoundError: -- from tensorflow.lite.python.interpreter import Interpreter, load_delegate -+ from ai_edge_litert.interpreter import Interpreter, load_delegate - - - logger = logging.getLogger(__name__) -diff --git a/frigate/detectors/plugins/cpu_tfl.py b/frigate/detectors/plugins/cpu_tfl.py -index 00351f519..6d336bb6b 100644 ---- a/frigate/detectors/plugins/cpu_tfl.py -+++ b/frigate/detectors/plugins/cpu_tfl.py -@@ -12,7 +12,7 @@ from ..detector_utils import tflite_detect_raw, tflite_init - try: - from tflite_runtime.interpreter import Interpreter - except ModuleNotFoundError: -- from tensorflow.lite.python.interpreter import Interpreter -+ from ai_edge_litert.interpreter import Interpreter - - - logger = logging.getLogger(__name__) -diff --git a/frigate/detectors/plugins/edgetpu_tfl.py b/frigate/detectors/plugins/edgetpu_tfl.py -index 2b94fde39..36c769b4b 100644 ---- a/frigate/detectors/plugins/edgetpu_tfl.py -+++ b/frigate/detectors/plugins/edgetpu_tfl.py -@@ -13,7 +13,7 @@ from frigate.detectors.detector_config import BaseDetectorConfig, ModelTypeEnum - try: - from tflite_runtime.interpreter import Interpreter, load_delegate - except ModuleNotFoundError: -- from tensorflow.lite.python.interpreter import Interpreter, load_delegate -+ from ai_edge_litert.interpreter import Interpreter, load_delegate - - logger = logging.getLogger(__name__) - -diff --git a/frigate/embeddings/onnx/face_embedding.py b/frigate/embeddings/onnx/face_embedding.py -index 04d756897..75dfedc94 100644 ---- a/frigate/embeddings/onnx/face_embedding.py -+++ b/frigate/embeddings/onnx/face_embedding.py -@@ -17,7 +17,7 @@ from .base_embedding import BaseEmbedding - try: - from tflite_runtime.interpreter import Interpreter - except ModuleNotFoundError: -- from tensorflow.lite.python.interpreter import Interpreter -+ from ai_edge_litert.interpreter import Interpreter - - logger = logging.getLogger(__name__) - -diff --git a/frigate/events/audio.py b/frigate/events/audio.py -index e88f2ae71..ad87d19c1 100644 ---- a/frigate/events/audio.py -+++ b/frigate/events/audio.py -@@ -43,7 +43,7 @@ from frigate.video import start_or_restart_ffmpeg, stop_ffmpeg - try: - from tflite_runtime.interpreter import Interpreter - except ModuleNotFoundError: -- from tensorflow.lite.python.interpreter import Interpreter -+ from ai_edge_litert.interpreter import Interpreter - - - logger = logging.getLogger(__name__) diff --git a/pkgs/by-name/fr/frigate/ffmpeg.patch b/pkgs/by-name/fr/frigate/ffmpeg.patch index 2b9d08cf2d06..d2b4a5eea85a 100644 --- a/pkgs/by-name/fr/frigate/ffmpeg.patch +++ b/pkgs/by-name/fr/frigate/ffmpeg.patch @@ -1,47 +1,23 @@ -diff --git a/frigate/config/camera/ffmpeg.py b/frigate/config/camera/ffmpeg.py -index 2c1e4cdca..d1a1f7065 100644 ---- a/frigate/config/camera/ffmpeg.py -+++ b/frigate/config/camera/ffmpeg.py -@@ -1,4 +1,5 @@ - from enum import Enum -+from os.path import join - from typing import Union +diff --git a/frigate/util/config.py b/frigate/util/config.py +index 3e093a978..c9a5d7462 100644 +--- a/frigate/util/config.py ++++ b/frigate/util/config.py +@@ -32,17 +32,7 @@ def resolve_ffmpeg_path(path: str, binary: str = "ffmpeg") -> str: + bundled version so existing configs keep working across an upgrade or a + revert. Custom install paths (anything absolute) are used as-is. + """ +- if path == "default" or ( +- not path.startswith("/") and path not in INCLUDED_FFMPEG_VERSIONS +- ): +- version = DEFAULT_FFMPEG_VERSION +- elif path in INCLUDED_FFMPEG_VERSIONS: +- version = path +- else: +- return f"{path}/bin/{binary}" +- +- return f"/usr/lib/ffmpeg/{version}/bin/{binary}" +- ++ return os.path.join(path, "bin", binary) - from pydantic import Field, field_validator -@@ -71,21 +72,11 @@ class FfmpegConfig(FrigateBaseModel): - - @property - def ffmpeg_path(self) -> str: -- if self.path == "default": -- return f"/usr/lib/ffmpeg/{DEFAULT_FFMPEG_VERSION}/bin/ffmpeg" -- elif self.path in INCLUDED_FFMPEG_VERSIONS: -- return f"/usr/lib/ffmpeg/{self.path}/bin/ffmpeg" -- else: -- return f"{self.path}/bin/ffmpeg" -+ return join(self.path, "bin/ffmpeg") - - @property - def ffprobe_path(self) -> str: -- if self.path == "default": -- return f"/usr/lib/ffmpeg/{DEFAULT_FFMPEG_VERSION}/bin/ffprobe" -- elif self.path in INCLUDED_FFMPEG_VERSIONS: -- return f"/usr/lib/ffmpeg/{self.path}/bin/ffprobe" -- else: -- return f"{self.path}/bin/ffprobe" -+ return join(self.path, "bin/ffprobe") - - - class CameraRoleEnum(str, Enum): -diff --git a/frigate/record/export.py b/frigate/record/export.py -index d4b49bb4b..bbcccff61 100644 ---- a/frigate/record/export.py -+++ b/frigate/record/export.py -@@ -127,7 +127,7 @@ class RecordingExporter(threading.Thread): - minutes = int(diff / 60) - seconds = int(diff % 60) - ffmpeg_cmd = [ -- "/usr/lib/ffmpeg/7.0/bin/ffmpeg", # hardcode path for exports thumbnail due to missing libwebp support -+ self.config.ffmpeg.ffmpeg_path, # hardcode path for exports thumbnail due to missing libwebp support - "-hide_banner", - "-loglevel", - "warning", + def redact_credential(obj: dict[str, Any], key: str) -> None: + """Replace obj[key] with the redaction sentinel if a value is saved, else drop. diff --git a/pkgs/by-name/fr/frigate/fix-tests-media-auth-paths.patch b/pkgs/by-name/fr/frigate/fix-tests-media-auth-paths.patch new file mode 100644 index 000000000000..ac0f75afda85 --- /dev/null +++ b/pkgs/by-name/fr/frigate/fix-tests-media-auth-paths.patch @@ -0,0 +1,32 @@ +From 91711507df5ad880bfcba1e11619441f7d0f9a58 Mon Sep 17 00:00:00 2001 +From: Martin Weinelt +Date: Mon, 13 Jul 2026 14:11:18 +0200 +Subject: [PATCH] Reuse constants in media auth tests + +--- + frigate/test/test_media_auth.py | 5 +++-- + 1 file changed, 3 insertions(+), 2 deletions(-) + +diff --git a/frigate/test/test_media_auth.py b/frigate/test/test_media_auth.py +index d025fea614..0b106047b2 100644 +--- a/frigate/test/test_media_auth.py ++++ b/frigate/test/test_media_auth.py +@@ -20,6 +20,7 @@ + resolve_media_uri, + ) + from frigate.config import FrigateConfig ++from frigate.const import EXPORT_DIR + from frigate.models import Event, Export, Recordings, ReviewSegment + from frigate.test.const import TEST_DB, TEST_DB_CLEANUPS + +@@ -231,8 +232,8 @@ def _insert_export(self, export_id, camera, filename): + camera=camera, + name=f"export-{export_id}", + date=int(datetime.datetime.now().timestamp()), +- video_path=f"/media/frigate/exports/{filename}", +- thumb_path=f"/media/frigate/exports/{filename}.jpg", ++ video_path=os.path.join(EXPORT_DIR, filename), ++ thumb_path=os.path.join(EXPORT_DIR, f"{filename}.jpg"), + in_progress=False, + ).execute() + diff --git a/pkgs/by-name/fr/frigate/package.nix b/pkgs/by-name/fr/frigate/package.nix index f395c2a74eb1..e60770f91fbc 100644 --- a/pkgs/by-name/fr/frigate/package.nix +++ b/pkgs/by-name/fr/frigate/package.nix @@ -12,36 +12,11 @@ sqlite-vec, frigate, nixosTests, - go2rtc, }: let - version = "0.17.2"; - - src = fetchFromGitHub { - name = "frigate-${version}-source"; - owner = "blakeblackshear"; - repo = "frigate"; - tag = "v${version}"; - hash = "sha256-8ujG5rVGqIJxM+IiQKvudrA0xqfz+3Uisl/zXwARPpY="; - }; - - frigate-web = callPackage ./web.nix { - inherit version src; - }; - python3Packages = python313Packages.overrideScope ( self: super: { - joserfc = super.joserfc.overridePythonAttrs (oldAttrs: { - version = "1.1.0"; - src = fetchFromGitHub { - owner = "authlib"; - repo = "joserfc"; - tag = version; - hash = "sha256-95xtUzzIxxvDtpHX/5uCHnTQTB8Fc08DZGUOR/SdKLs="; - }; - }); - # transformers 4.* is not compatible with the latest tokenizers tokenizers = super.tokenizers.overridePythonAttrs ( oldAttrs: @@ -114,12 +89,18 @@ let hash = "sha256-5Cj2vEiWR8Z9d2xBmVoLZuNRv4UOuxHSGZQWTJorXUQ="; }; in -python3Packages.buildPythonApplication rec { +python3Packages.buildPythonApplication (finalAttrs: { pname = "frigate"; - inherit version; + version = "0.18.0"; pyproject = false; - inherit src; + src = fetchFromGitHub { + name = "frigate-${finalAttrs.version}-source"; + owner = "blakeblackshear"; + repo = "frigate"; + tag = "v${finalAttrs.version}"; + hash = "sha256-2FJG7tEZCuCQ6VJga9BMiuLTeswmlG8oN1MO6t0eroM="; + }; patches = [ # Always lookup ffmpeg from config setting @@ -130,24 +111,27 @@ python3Packages.buildPythonApplication rec { inherit (addDriverRunpath) driverLink; }) - # Use ai-edge-litert as tensorflow interpreter - # https://github.com/blakeblackshear/frigate/pull/21876 - ./ai-edge-litert.patch - # Disable failing optimization in onnxruntime # https://github.com/microsoft/onnxruntime/issues/26717 + # https://github.com/microsoft/onnxruntime/pull/29196 ./onnxruntime-compat.patch - # Fix excessive trailing whitespaces in process commandlines - # https://github.com/blakeblackshear/frigate/pull/22089 - ./proc-cmdline-strip.patch + # Reuse EXPORT_DIR in tests + ./fix-tests-media-auth-paths.patch # Fix more granular dtype resolution in Pandas 3.0 ./pandas3-compat.patch + + # Various fixes for newer library packages, migrates to + # - FastAPI lifespan, + # - native tz-aware objects, + # - Pydantic TypeAdapter + # https://github.com/blakeblackshear/frigate/pull/23641 + ./pr23641.patch ]; postPatch = '' - echo 'VERSION = "${version}"' > frigate/version.py + echo 'VERSION = "${finalAttrs.version}"' > frigate/version.py substituteInPlace \ frigate/app.py \ @@ -189,75 +173,77 @@ python3Packages.buildPythonApplication rec { dontBuild = true; - dependencies = with python3Packages; [ - # docker/main/requirements-wheel.txt - # TODO: degirum (no source repo, binary wheels only) - ai-edge-litert - aiofiles - aiohttp - appdirs - argcomplete - click - contextlib2 - cryptography - distlib - fastapi - faster-whisper - filelock - google-genai - importlib-metadata - importlib-resources - joserfc - keras # via tensorflow.keras - librosa - markupsafe - memray - netaddr - netifaces - norfair - numpy - ollama - onnxruntime - onvif-zeep-async - openai - opencv4 - openvino - paho-mqtt - pandas - pathvalidate - peewee - peewee-migrate - prometheus-client - psutil - py3nvml - pyclipper - pydantic - python-multipart - pytz - py-vapid - pywebpush - pyzmq - rapidfuzz - requests - ruamel-yaml - scipy - setproctitle - shapely - sherpa-onnx - slowapi - soundfile - starlette - starlette-context - tensorflow - titlecase - transformers - tzlocal - unidecode - uvicorn - verboselogs - virtualenv - ws4py - ]; + dependencies = + with python3Packages; + [ + # docker/main/requirements-wheel.txt + ai-edge-litert + aiofiles + aiohttp + appdirs + argcomplete + click + contextlib2 + cryptography + distlib + fastapi + faster-whisper + filelock + google-genai + httpx + importlib-metadata + importlib-resources + joserfc + keras # via tensorflow.keras + librosa + markupsafe + memray + netaddr + netifaces + norfair + numpy + ollama + onnxruntime + onvif-zeep-async + openai + opencv4 + openvino + paho-mqtt + pandas + pathvalidate + peewee + peewee-migrate + prometheus-client + psutil + py3nvml + pyclipper + pydantic + python-multipart + py-vapid + pywebpush + pyzmq + rapidfuzz + requests + ruamel-yaml + scipy + setproctitle + shapely + sherpa-onnx + slowapi + soundfile + starlette + starlette-context + tensorflow + titlecase + transformers + tzlocal + unidecode + uvicorn + verboselogs + virtualenv + ws4py + ] + ++ httpx.optional-dependencies.http2; installPhase = '' runHook preInstall @@ -283,9 +269,9 @@ python3Packages.buildPythonApplication rec { ]; preCheck = '' - # Unavailable in the build sandbox + # FHS paths are unreachable in the build sandbox substituteInPlace frigate/const.py \ - --replace-fail "/var/lib/frigate" "$TMPDIR/" \ + --replace-fail "/var/lib/frigate" "$TMPDIR" \ --replace-fail "/var/cache/frigate" "$TMPDIR" ''; @@ -300,16 +286,20 @@ python3Packages.buildPythonApplication rec { ]; passthru = { - web = frigate-web; inherit python; - pythonPath = (python3Packages.makePythonPath dependencies) + ":${frigate}/${python.sitePackages}"; + pythonPath = + (python3Packages.makePythonPath finalAttrs.finalPackage.dependencies) + + ":${frigate}/${python.sitePackages}"; + web = callPackage ./web.nix { + inherit (finalAttrs) version src; + }; tests = { inherit (nixosTests) frigate; }; }; meta = { - changelog = "https://github.com/blakeblackshear/frigate/releases/tag/${src.tag}"; + changelog = "https://github.com/blakeblackshear/frigate/releases/tag/${finalAttrs.src.tag}"; description = "NVR with realtime local object detection for IP cameras"; longDescription = '' A complete and local NVR designed for Home Assistant with AI @@ -320,4 +310,4 @@ python3Packages.buildPythonApplication rec { license = lib.licenses.mit; maintainers = with lib.maintainers; [ hexa ]; }; -} +}) diff --git a/pkgs/by-name/fr/frigate/pr23641.patch b/pkgs/by-name/fr/frigate/pr23641.patch new file mode 100644 index 000000000000..281c651fcdde --- /dev/null +++ b/pkgs/by-name/fr/frigate/pr23641.patch @@ -0,0 +1,770 @@ +From e4bba6f9c03af6fe20c8bd090bb1bc94cbd9ef1f Mon Sep 17 00:00:00 2001 +From: Martin Weinelt +Date: Mon, 6 Jul 2026 13:14:54 +0200 +Subject: [PATCH 1/5] Migrate to fastapi lifespan for startup events + +The `on_event` style decorator is deprecated + +https://fastapi.tiangolo.com/advanced/events/ +--- + frigate/api/fastapi_app.py | 21 ++++++++++++--------- + 1 file changed, 12 insertions(+), 9 deletions(-) + +diff --git a/frigate/api/fastapi_app.py b/frigate/api/fastapi_app.py +index 387f0473fc..86058bfdaa 100644 +--- a/frigate/api/fastapi_app.py ++++ b/frigate/api/fastapi_app.py +@@ -1,6 +1,7 @@ + import asyncio + import logging + import re ++from contextlib import asynccontextmanager + + from fastapi import Depends, FastAPI, Request + from fastapi.responses import JSONResponse +@@ -77,9 +78,20 @@ def create_fastapi_app( + enforce_default_admin: bool = True, + config_holder: ConfigHolder | None = None, + ): ++ @asynccontextmanager ++ async def lifespan(app: FastAPI): ++ logger.info("FastAPI started") ++ asyncio.create_task( ++ debug_replay_auto_stop_watchdog( ++ replay_manager, frigate_config, config_publisher ++ ) ++ ) ++ yield ++ + logger.info("Starting FastAPI app") + app = FastAPI( + debug=False, ++ lifespan=lifespan, + swagger_ui_parameters={"apisSorter": "alpha", "operationsSorter": "alpha"}, + dependencies=[Depends(require_admin_by_default())] + if enforce_default_admin +@@ -115,15 +127,6 @@ async def frigate_middleware(request: Request, call_next): + database.close() + return response + +- @app.on_event("startup") +- async def startup(): +- logger.info("FastAPI started") +- asyncio.create_task( +- debug_replay_auto_stop_watchdog( +- replay_manager, frigate_config, config_publisher +- ) +- ) +- + # Rate limiter (used for login endpoint) + if frigate_config.auth.failed_login_rate_limit is None: + limiter.enabled = False + +From ef8fcf2328bd59b6d30c7ca523e39909a8b8c01e Mon Sep 17 00:00:00 2001 +From: Martin Weinelt +Date: Mon, 6 Jul 2026 13:16:58 +0200 +Subject: [PATCH 2/5] Migrate to pydantic TypeAdapter + +https://pydantic.dev/docs/validation/2.12/get-started/migration/#introduction-of-typeadapter +--- + frigate/test/test_object_detector.py | 18 ++++++++++++------ + 1 file changed, 12 insertions(+), 6 deletions(-) + +diff --git a/frigate/test/test_object_detector.py b/frigate/test/test_object_detector.py +index dc15b23516..33748c2807 100644 +--- a/frigate/test/test_object_detector.py ++++ b/frigate/test/test_object_detector.py +@@ -2,7 +2,7 @@ + from unittest.mock import Mock, patch + + import numpy as np +-from pydantic import parse_obj_as ++from pydantic import TypeAdapter + + import frigate.detectors as detectors + import frigate.object_detection.base +@@ -19,8 +19,8 @@ def test_localdetectorprocess_should_only_create_specified_detector_type(self): + "frigate.detectors.api_types", + {det_type: Mock() for det_type in DetectorTypeEnum}, + ): +- test_cfg = parse_obj_as( +- DetectorConfig, ({"type": det_type, "model": {}}) ++ test_cfg = TypeAdapter(DetectorConfig).validate_python( ++ {"type": det_type, "model": {}} + ) + test_cfg.model.path = "/test/modelpath" + test_obj = frigate.object_detection.base.LocalObjectDetector( +@@ -44,7 +44,9 @@ def test_detect_raw_given_tensor_input_should_return_api_detect_raw_result(self) + TEST_DATA = [0, 1, 2, 3, 4, 5, 6, 7, 8, 9] + TEST_DETECT_RESULT = np.ndarray([1, 2, 4, 8, 16, 32]) + test_obj_detect = frigate.object_detection.base.LocalObjectDetector( +- detector_config=parse_obj_as(DetectorConfig, {"type": "cpu", "model": {}}) ++ detector_config=TypeAdapter(DetectorConfig).validate_python( ++ {"type": "cpu", "model": {}} ++ ) + ) + + mock_det_api = mock_cputfl.return_value +@@ -67,7 +69,9 @@ def test_detect_raw_given_tensor_input_should_call_api_detect_raw_with_transpose + TEST_DATA = np.zeros((1, 32, 32, 3), np.uint8) + TEST_DETECT_RESULT = np.ndarray([1, 2, 4, 8, 16, 32]) + +- test_cfg = parse_obj_as(DetectorConfig, {"type": "cpu", "model": {}}) ++ test_cfg = TypeAdapter(DetectorConfig).validate_python( ++ {"type": "cpu", "model": {}} ++ ) + test_cfg.model.input_tensor = InputTensorEnum.nchw + + test_obj_detect = frigate.object_detection.base.LocalObjectDetector( +@@ -116,7 +120,9 @@ def test_detect_given_tensor_input_should_return_lfiltered_detections( + "label-5", + ] + +- test_cfg = parse_obj_as(DetectorConfig, {"type": "cpu", "model": {}}) ++ test_cfg = TypeAdapter(DetectorConfig).validate_python( ++ {"type": "cpu", "model": {}} ++ ) + test_cfg.model = ModelConfig() + test_obj_detect = frigate.object_detection.base.LocalObjectDetector( + detector_config=test_cfg, + +From e9f1435eeb337bf7e269af1b09a0b1b87de719d5 Mon Sep 17 00:00:00 2001 +From: Martin Weinelt +Date: Mon, 6 Jul 2026 13:17:16 +0200 +Subject: [PATCH 3/5] Replace pytz with native tz-aware objects and zoneinfo + library + +Supported from Python 3.9, see https://peps.python.org/pep-0615/. Also +https://blog.ganssle.io/articles/2019/11/utcnow.html. +--- + docker/main/requirements-wheels.txt | 1 - + docs/static/frigate-api.yaml | 14 +++---- + .../api/defs/query/app_query_parameters.py | 2 +- + .../api/defs/query/events_query_parameters.py | 6 +-- + .../defs/query/recordings_query_parameters.py | 2 +- + .../api/defs/query/review_query_parameters.py | 2 +- + frigate/api/media.py | 4 +- + frigate/api/preview.py | 4 +- + frigate/api/record.py | 2 +- + frigate/record/export.py | 10 ++--- + frigate/test/http_api/test_http_media.py | 39 +++++++++---------- + frigate/test/http_api/test_http_review.py | 2 +- + frigate/util/time.py | 17 ++++---- + 13 files changed, 50 insertions(+), 55 deletions(-) + +diff --git a/docker/main/requirements-wheels.txt b/docker/main/requirements-wheels.txt +index 5ed9664fc2..164ab3b853 100644 +--- a/docker/main/requirements-wheels.txt ++++ b/docker/main/requirements-wheels.txt +@@ -25,7 +25,6 @@ peewee_migrate == 1.14.* + psutil == 7.1.* + pydantic == 2.10.* + git+https://github.com/fbcotter/py3nvml#egg=py3nvml +-pytz == 2025.* + pyzmq == 26.2.* + ruamel.yaml == 0.18.* + tzlocal == 5.2 +diff --git a/docs/static/frigate-api.yaml b/docs/static/frigate-api.yaml +index fe467e0c62..3ce79e4ae6 100644 +--- a/docs/static/frigate-api.yaml ++++ b/docs/static/frigate-api.yaml +@@ -2087,7 +2087,7 @@ paths: + required: false + schema: + type: string +- default: utc ++ default: UTC + title: Timezone + responses: + '200': +@@ -3129,7 +3129,7 @@ paths: + anyOf: + - type: string + - type: 'null' +- default: utc ++ default: UTC + title: Timezone + responses: + '200': +@@ -4227,7 +4227,7 @@ paths: + anyOf: + - type: string + - type: 'null' +- default: utc ++ default: UTC + title: Timezone + responses: + '200': +@@ -4479,7 +4479,7 @@ paths: + anyOf: + - type: string + - type: 'null' +- default: utc ++ default: UTC + title: Timezone + - name: min_score + in: query +@@ -4559,7 +4559,7 @@ paths: + anyOf: + - type: string + - type: 'null' +- default: utc ++ default: UTC + title: Timezone + - name: has_clip + in: query +@@ -6854,7 +6854,7 @@ paths: + required: false + schema: + type: string +- default: utc ++ default: UTC + title: Timezone + - name: cameras + in: query +@@ -6904,7 +6904,7 @@ paths: + required: false + schema: + type: string +- default: utc ++ default: UTC + title: Timezone + responses: + '200': +diff --git a/frigate/api/defs/query/app_query_parameters.py b/frigate/api/defs/query/app_query_parameters.py +index 626d39679b..26974d59b9 100644 +--- a/frigate/api/defs/query/app_query_parameters.py ++++ b/frigate/api/defs/query/app_query_parameters.py +@@ -7,4 +7,4 @@ class AppTimelineHourlyQueryParameters(BaseModel): + after: float | None = None + before: float | None = None + limit: int | None = 200 +- timezone: str | None = "utc" ++ timezone: str | None = "UTC" +diff --git a/frigate/api/defs/query/events_query_parameters.py b/frigate/api/defs/query/events_query_parameters.py +index 06d0dfc3af..30d0fcac50 100644 +--- a/frigate/api/defs/query/events_query_parameters.py ++++ b/frigate/api/defs/query/events_query_parameters.py +@@ -39,7 +39,7 @@ class EventsQueryParams(BaseModel): + max_length: float | None = None + event_id: str | None = None + sort: str | None = None +- timezone: str | None = "utc" ++ timezone: str | None = "UTC" + + + class EventsSearchQueryParams(BaseModel): +@@ -66,7 +66,7 @@ class EventsSearchQueryParams(BaseModel): + has_clip: bool | None = None + has_snapshot: bool | None = None + is_submitted: bool | None = None +- timezone: str | None = "utc" ++ timezone: str | None = "UTC" + min_score: float | None = None + max_score: float | None = None + min_speed: float | None = None +@@ -76,6 +76,6 @@ class EventsSearchQueryParams(BaseModel): + + + class EventsSummaryQueryParams(BaseModel): +- timezone: str | None = "utc" ++ timezone: str | None = "UTC" + has_clip: int | None = None + has_snapshot: int | None = None +diff --git a/frigate/api/defs/query/recordings_query_parameters.py b/frigate/api/defs/query/recordings_query_parameters.py +index 770da96bb8..cd7b4221c2 100644 +--- a/frigate/api/defs/query/recordings_query_parameters.py ++++ b/frigate/api/defs/query/recordings_query_parameters.py +@@ -3,7 +3,7 @@ + + + class MediaRecordingsSummaryQueryParams(BaseModel): +- timezone: str = "utc" ++ timezone: str = "UTC" + cameras: str | None = "all" + + +diff --git a/frigate/api/defs/query/review_query_parameters.py b/frigate/api/defs/query/review_query_parameters.py +index b16146a9bc..16f759f42a 100644 +--- a/frigate/api/defs/query/review_query_parameters.py ++++ b/frigate/api/defs/query/review_query_parameters.py +@@ -19,7 +19,7 @@ class ReviewSummaryQueryParams(BaseModel): + cameras: str = "all" + labels: str = "all" + zones: str = "all" +- timezone: str = "utc" ++ timezone: str = "UTC" + + + class ReviewActivityMotionQueryParams(BaseModel): +diff --git a/frigate/api/media.py b/frigate/api/media.py +index c6fa90c068..a5f5e1bab8 100644 +--- a/frigate/api/media.py ++++ b/frigate/api/media.py +@@ -11,10 +11,10 @@ + from pathlib import Path as FilePath + from typing import Any + from urllib.parse import unquote ++from zoneinfo import ZoneInfo + + import cv2 + import numpy as np +-import pytz + from fastapi import APIRouter, Depends, Path, Query, Request, Response + from fastapi.responses import FileResponse, JSONResponse, StreamingResponse + from pathvalidate import sanitize_filename +@@ -714,7 +714,7 @@ async def vod_hour( + parts = year_month.split("-") + start_date = ( + datetime(int(parts[0]), int(parts[1]), day, hour, tzinfo=UTC) +- - datetime.now(pytz.timezone(tz_name.replace(",", "/"))).utcoffset() ++ - datetime.now(ZoneInfo(tz_name.replace(",", "/"))).utcoffset() + ) + end_date = start_date + timedelta(hours=1) - timedelta(milliseconds=1) + start_ts = start_date.timestamp() +diff --git a/frigate/api/preview.py b/frigate/api/preview.py +index 1047591434..af84117fd6 100644 +--- a/frigate/api/preview.py ++++ b/frigate/api/preview.py +@@ -5,8 +5,8 @@ + import os + import threading + from datetime import UTC, datetime, timedelta ++from zoneinfo import ZoneInfo + +-import pytz + from fastapi import APIRouter, Depends, HTTPException + from fastapi.responses import JSONResponse + +@@ -126,7 +126,7 @@ def preview_hour( + parts = year_month.split("-") + start_date = ( + datetime(int(parts[0]), int(parts[1]), int(day), int(hour), tzinfo=UTC) +- - datetime.now(pytz.timezone(tz_name.replace(",", "/"))).utcoffset() ++ - datetime.now(ZoneInfo(tz_name.replace(",", "/"))).utcoffset() + ) + end_date = start_date + timedelta(hours=1) - timedelta(milliseconds=1) + start_ts = start_date.timestamp() +diff --git a/frigate/api/record.py b/frigate/api/record.py +index 5db257f482..3352ec039b 100644 +--- a/frigate/api/record.py ++++ b/frigate/api/record.py +@@ -120,7 +120,7 @@ def all_recordings_summary( + @router.get( + "/{camera_name}/recordings/summary", dependencies=[Depends(require_camera_access)] + ) +-async def recordings_summary(camera_name: str, timezone: str = "utc"): ++async def recordings_summary(camera_name: str, timezone: str = "UTC"): + """Returns hourly summary for recordings of given camera""" + + time_range_query = ( +diff --git a/frigate/record/export.py b/frigate/record/export.py +index 5d307077c9..0564dee04b 100644 +--- a/frigate/record/export.py ++++ b/frigate/record/export.py +@@ -12,8 +12,8 @@ + from collections.abc import Callable + from enum import Enum + from pathlib import Path ++from zoneinfo import ZoneInfo, ZoneInfoNotFoundError + +-import pytz # type: ignore[import-untyped] + from peewee import DoesNotExist + + from frigate.config import FfmpegConfig, FrigateConfig +@@ -371,8 +371,8 @@ def get_datetime_from_timestamp(self, timestamp: int) -> str: + tz_name = self.config.ui.timezone + if tz_name: + try: +- tz = pytz.timezone(tz_name) +- except pytz.UnknownTimeZoneError: ++ tz = ZoneInfo(tz_name) ++ except (ValueError, ZoneInfoNotFoundError): + tz = None + if tz is not None: + return datetime.datetime.fromtimestamp(timestamp, tz=tz).strftime( +@@ -533,8 +533,8 @@ def _build_recording_segment_chapter_metadata_file( + tz: datetime.tzinfo | None = None + if tz_name: + try: +- tz = pytz.timezone(tz_name) +- except pytz.UnknownTimeZoneError: ++ tz = ZoneInfo(tz_name) ++ except (ValueError, ZoneInfoNotFoundError): + tz = None + if tz is None: + tz = datetime.UTC +diff --git a/frigate/test/http_api/test_http_media.py b/frigate/test/http_api/test_http_media.py +index b2d83cbc8a..8a3835c324 100644 +--- a/frigate/test/http_api/test_http_media.py ++++ b/frigate/test/http_api/test_http_media.py +@@ -1,8 +1,8 @@ + """Unit tests for recordings/media API endpoints.""" + + from datetime import UTC, datetime ++from zoneinfo import ZoneInfo + +-import pytz + from fastapi import Request + + from frigate.api.auth import get_allowed_cameras_for_filter, get_current_user +@@ -51,16 +51,16 @@ def test_recordings_summary_across_dst_spring_forward(self): + In 2024, DST in America/New_York transitions on March 10, 2024 at 2:00 AM + Clocks spring forward from 2:00 AM to 3:00 AM (EST to EDT) + """ +- tz = pytz.timezone("America/New_York") ++ tz = ZoneInfo("America/New_York") + + # March 9, 2024 at 12:00 PM EST (before DST) +- march_9_noon = tz.localize(datetime(2024, 3, 9, 12, 0, 0)).timestamp() ++ march_9_noon = datetime(2024, 3, 9, 12, 0, 0, tzinfo=tz).timestamp() + + # March 10, 2024 at 12:00 PM EDT (after DST transition) +- march_10_noon = tz.localize(datetime(2024, 3, 10, 12, 0, 0)).timestamp() ++ march_10_noon = datetime(2024, 3, 10, 12, 0, 0, tzinfo=tz).timestamp() + + # March 11, 2024 at 12:00 PM EDT (after DST) +- march_11_noon = tz.localize(datetime(2024, 3, 11, 12, 0, 0)).timestamp() ++ march_11_noon = datetime(2024, 3, 11, 12, 0, 0, tzinfo=tz).timestamp() + + with AuthTestClient(self.app) as client: + # Insert recordings for each day +@@ -124,19 +124,16 @@ def test_recordings_summary_across_dst_fall_back(self): + In 2024, DST in America/New_York transitions on November 3, 2024 at 2:00 AM + Clocks fall back from 2:00 AM to 1:00 AM (EDT to EST) + """ +- tz = pytz.timezone("America/New_York") ++ tz = ZoneInfo("America/New_York") + + # November 2, 2024 at 12:00 PM EDT (before DST transition) +- nov_2_noon = tz.localize(datetime(2024, 11, 2, 12, 0, 0)).timestamp() ++ nov_2_noon = datetime(2024, 11, 2, 12, 0, 0, tzinfo=tz).timestamp() + + # November 3, 2024 at 12:00 PM EST (after DST transition) +- # Need to specify is_dst=False to get the time after fall back +- nov_3_noon = tz.localize( +- datetime(2024, 11, 3, 12, 0, 0), is_dst=False +- ).timestamp() ++ nov_3_noon = datetime(2024, 11, 3, 12, 0, 0, tzinfo=tz).timestamp() + + # November 4, 2024 at 12:00 PM EST (after DST) +- nov_4_noon = tz.localize(datetime(2024, 11, 4, 12, 0, 0)).timestamp() ++ nov_4_noon = datetime(2024, 11, 4, 12, 0, 0, tzinfo=tz).timestamp() + + with AuthTestClient(self.app) as client: + # Insert recordings for each day +@@ -197,13 +194,13 @@ def test_recordings_summary_multiple_cameras_across_dst(self): + """ + Test recordings summary with multiple cameras across DST boundary. + """ +- tz = pytz.timezone("America/New_York") ++ tz = ZoneInfo("America/New_York") + + # March 9, 2024 at 10:00 AM EST (before DST) +- march_9_morning = tz.localize(datetime(2024, 3, 9, 10, 0, 0)).timestamp() ++ march_9_morning = datetime(2024, 3, 9, 10, 0, 0, tzinfo=tz).timestamp() + + # March 10, 2024 at 3:00 PM EDT (after DST transition) +- march_10_afternoon = tz.localize(datetime(2024, 3, 10, 15, 0, 0)).timestamp() ++ march_10_afternoon = datetime(2024, 3, 10, 15, 0, 0, tzinfo=tz).timestamp() + + with AuthTestClient(self.app) as client: + # Override allowed cameras for this test to include both +@@ -266,15 +263,15 @@ def test_recordings_summary_at_dst_transition_time(self): + """ + Test recordings that span the exact DST transition time. + """ +- tz = pytz.timezone("America/New_York") ++ tz = ZoneInfo("America/New_York") + + # March 10, 2024 at 1:00 AM EST (1 hour before DST transition) + # At 2:00 AM, clocks jump to 3:00 AM +- before_transition = tz.localize(datetime(2024, 3, 10, 1, 0, 0)).timestamp() ++ before_transition = datetime(2024, 3, 10, 1, 0, 0, tzinfo=tz).timestamp() + + # Recording that spans the transition (1:00 AM to 3:30 AM EDT) + # This is 1.5 hours of actual time but spans the "missing" hour +- after_transition = tz.localize(datetime(2024, 3, 10, 3, 30, 0)).timestamp() ++ after_transition = datetime(2024, 3, 10, 3, 30, 0, tzinfo=tz).timestamp() + + with AuthTestClient(self.app) as client: + Recordings.insert( +@@ -334,7 +331,7 @@ def test_recordings_summary_utc_timezone(self): + + # Test with UTC timezone + response = client.get( +- "/recordings/summary", params={"timezone": "utc", "cameras": "all"} ++ "/recordings/summary", params={"timezone": "UTC", "cameras": "all"} + ) + + assert response.status_code == 200 +@@ -365,8 +362,8 @@ def test_recordings_summary_single_camera_filter(self): + """ + Test recordings summary filtered to a single camera. + """ +- tz = pytz.timezone("America/New_York") +- march_10_noon = tz.localize(datetime(2024, 3, 10, 12, 0, 0)).timestamp() ++ tz = ZoneInfo("America/New_York") ++ march_10_noon = datetime(2024, 3, 10, 12, 0, 0, tzinfo=tz).timestamp() + + with AuthTestClient(self.app) as client: + # Insert recordings for both cameras +diff --git a/frigate/test/http_api/test_http_review.py b/frigate/test/http_api/test_http_review.py +index d13a7bd273..62d4f1608d 100644 +--- a/frigate/test/http_api/test_http_review.py ++++ b/frigate/test/http_api/test_http_review.py +@@ -250,7 +250,7 @@ def test_get_review_summary_all_filters(self): + "cameras": "front_door", + "labels": "all", + "zones": "all", +- "timezone": "utc", ++ "timezone": "UTC", + } + response = client.get("/review/summary", params=params) + assert response.status_code == 200 +diff --git a/frigate/util/time.py b/frigate/util/time.py +index 861bec17f6..777ae9cc11 100644 +--- a/frigate/util/time.py ++++ b/frigate/util/time.py +@@ -2,9 +2,8 @@ + + import datetime + import logging +-from zoneinfo import ZoneInfoNotFoundError ++from zoneinfo import ZoneInfo, ZoneInfoNotFoundError + +-import pytz + from tzlocal import get_localzone + + logger = logging.getLogger(__name__) +@@ -12,7 +11,7 @@ + + def get_tz_modifiers(tz_name: str) -> tuple[str, str, float]: + seconds_offset = ( +- datetime.datetime.now(pytz.timezone(tz_name)).utcoffset().total_seconds() ++ datetime.datetime.now(ZoneInfo(tz_name)).utcoffset().total_seconds() + ) + hours_offset = int(seconds_offset / 60 / 60) + minutes_offset = int(seconds_offset / 60 - hours_offset * 60) +@@ -25,7 +24,7 @@ def get_tomorrow_at_time(hour: int) -> datetime.datetime: + """Returns the datetime of the following day at 2am.""" + try: + tomorrow = datetime.datetime.now(get_localzone()) + datetime.timedelta(days=1) +- except ZoneInfoNotFoundError: ++ except (ValueError, ZoneInfoNotFoundError): + tomorrow = datetime.datetime.now(datetime.UTC) + datetime.timedelta(days=1) + logger.warning( + "Using utc for maintenance due to missing or incorrect timezone set" +@@ -45,7 +44,7 @@ def is_current_hour(timestamp: int) -> bool: + + def get_dst_transitions( + tz_name: str, start_time: float, end_time: float +-) -> list[tuple[float, float]]: ++) -> list[tuple[float, float, int]]: + """ + Find DST transition points and return time periods with consistent offsets. + +@@ -59,8 +58,8 @@ def get_dst_transitions( + continuous periods with the same UTC offset + """ + try: +- tz = pytz.timezone(tz_name) +- except pytz.UnknownTimeZoneError: ++ tz = ZoneInfo(tz_name) ++ except (ValueError, ZoneInfoNotFoundError): + # If timezone is invalid, return single period with no offset + return [(start_time, end_time, 0)] + +@@ -68,14 +67,14 @@ def get_dst_transitions( + current = start_time + + # Get initial offset +- dt = datetime.datetime.utcfromtimestamp(current).replace(tzinfo=pytz.UTC) ++ dt = datetime.datetime.fromtimestamp(current, tz=datetime.UTC) + local_dt = dt.astimezone(tz) + prev_offset = local_dt.utcoffset().total_seconds() + period_start = start_time + + # Check each day for offset changes + while current <= end_time: +- dt = datetime.datetime.utcfromtimestamp(current).replace(tzinfo=pytz.UTC) ++ dt = datetime.datetime.fromtimestamp(current, tz=datetime.UTC) + local_dt = dt.astimezone(tz) + current_offset = local_dt.utcoffset().total_seconds() + + +From af86312f3dd57c068c3f6b3ae68d8fa6f77c6e30 Mon Sep 17 00:00:00 2001 +From: Martin Weinelt +Date: Mon, 6 Jul 2026 16:21:01 +0200 +Subject: [PATCH 4/5] Provide lookup for normalized timezone names + +This provides a helper to look up the correct timezone name independent +of the casing of the given timezone name. +--- + frigate/api/media.py | 5 ++++- + frigate/api/preview.py | 5 ++++- + frigate/record/export.py | 6 +++--- + frigate/util/time.py | 22 +++++++++++++++++++--- + 4 files changed, 30 insertions(+), 8 deletions(-) + +diff --git a/frigate/api/media.py b/frigate/api/media.py +index a5f5e1bab8..14ae263053 100644 +--- a/frigate/api/media.py ++++ b/frigate/api/media.py +@@ -54,6 +54,7 @@ + from frigate.util.image import get_image_from_recording, get_image_quality_params + from frigate.util.media import get_keyframe_before + from frigate.util.object import create_empty_regions_grid ++from frigate.util.time import get_normalized_tz_name + + logger = logging.getLogger(__name__) + +@@ -714,7 +715,9 @@ async def vod_hour( + parts = year_month.split("-") + start_date = ( + datetime(int(parts[0]), int(parts[1]), day, hour, tzinfo=UTC) +- - datetime.now(ZoneInfo(tz_name.replace(",", "/"))).utcoffset() ++ - datetime.now( ++ ZoneInfo(get_normalized_tz_name(tz_name.replace(",", "/"))) ++ ).utcoffset() + ) + end_date = start_date + timedelta(hours=1) - timedelta(milliseconds=1) + start_ts = start_date.timestamp() +diff --git a/frigate/api/preview.py b/frigate/api/preview.py +index af84117fd6..81de23d003 100644 +--- a/frigate/api/preview.py ++++ b/frigate/api/preview.py +@@ -22,6 +22,7 @@ + from frigate.api.defs.tags import Tags + from frigate.const import BASE_DIR, CACHE_DIR, PREVIEW_FRAME_TYPE + from frigate.models import Previews ++from frigate.util.time import get_normalized_tz_name + + logger = logging.getLogger(__name__) + +@@ -126,7 +127,9 @@ def preview_hour( + parts = year_month.split("-") + start_date = ( + datetime(int(parts[0]), int(parts[1]), int(day), int(hour), tzinfo=UTC) +- - datetime.now(ZoneInfo(tz_name.replace(",", "/"))).utcoffset() ++ - datetime.now( ++ ZoneInfo(get_normalized_tz_name(tz_name.replace(",", "/"))) ++ ).utcoffset() + ) + end_date = start_date + timedelta(hours=1) - timedelta(milliseconds=1) + start_ts = start_date.timestamp() +diff --git a/frigate/record/export.py b/frigate/record/export.py +index 0564dee04b..ff33063bc3 100644 +--- a/frigate/record/export.py ++++ b/frigate/record/export.py +@@ -31,7 +31,7 @@ + ) + from frigate.models import Export, Previews, Recordings, ReviewSegment + from frigate.util.ffmpeg import run_ffmpeg_with_progress +-from frigate.util.time import is_current_hour ++from frigate.util.time import get_normalized_tz_name, is_current_hour + + logger = logging.getLogger(__name__) + +@@ -371,7 +371,7 @@ def get_datetime_from_timestamp(self, timestamp: int) -> str: + tz_name = self.config.ui.timezone + if tz_name: + try: +- tz = ZoneInfo(tz_name) ++ tz = ZoneInfo(get_normalized_tz_name(tz_name)) + except (ValueError, ZoneInfoNotFoundError): + tz = None + if tz is not None: +@@ -533,7 +533,7 @@ def _build_recording_segment_chapter_metadata_file( + tz: datetime.tzinfo | None = None + if tz_name: + try: +- tz = ZoneInfo(tz_name) ++ tz = ZoneInfo(get_normalized_tz_name(tz_name)) + except (ValueError, ZoneInfoNotFoundError): + tz = None + if tz is None: +diff --git a/frigate/util/time.py b/frigate/util/time.py +index 777ae9cc11..a4395c5d5d 100644 +--- a/frigate/util/time.py ++++ b/frigate/util/time.py +@@ -2,16 +2,32 @@ + + import datetime + import logging +-from zoneinfo import ZoneInfo, ZoneInfoNotFoundError ++from typing import Final ++from zoneinfo import ZoneInfo, ZoneInfoNotFoundError, available_timezones + + from tzlocal import get_localzone + + logger = logging.getLogger(__name__) + ++TIMEZONE_CASEFOLD_INDEX: Final = { ++ timezone.casefold(): timezone for timezone in available_timezones() ++} ++ ++ ++def get_normalized_tz_name(tz_name: str) -> str: ++ """Return the canonical name for a case-insensitive IANA timezone.""" ++ tz = TIMEZONE_CASEFOLD_INDEX.get(tz_name.casefold()) ++ if tz: ++ return tz ++ ++ raise ValueError(f"Unknown timezone: {tz_name}") ++ + + def get_tz_modifiers(tz_name: str) -> tuple[str, str, float]: + seconds_offset = ( +- datetime.datetime.now(ZoneInfo(tz_name)).utcoffset().total_seconds() ++ datetime.datetime.now(ZoneInfo(get_normalized_tz_name(tz_name))) ++ .utcoffset() ++ .total_seconds() + ) + hours_offset = int(seconds_offset / 60 / 60) + minutes_offset = int(seconds_offset / 60 - hours_offset * 60) +@@ -58,7 +74,7 @@ def get_dst_transitions( + continuous periods with the same UTC offset + """ + try: +- tz = ZoneInfo(tz_name) ++ tz = ZoneInfo(get_normalized_tz_name(tz_name)) + except (ValueError, ZoneInfoNotFoundError): + # If timezone is invalid, return single period with no offset + return [(start_time, end_time, 0)] + +From 490f1b93f8cc2aa450e74e882aa31516d6c1078c Mon Sep 17 00:00:00 2001 +From: Martin Weinelt +Date: Mon, 6 Jul 2026 18:12:37 +0200 +Subject: [PATCH 5/5] Test timezone naming normalization and error handling + +--- + frigate/test/test_tz.py | 19 +++++++++++++++++++ + 1 file changed, 19 insertions(+) + create mode 100644 frigate/test/test_tz.py + +diff --git a/frigate/test/test_tz.py b/frigate/test/test_tz.py +new file mode 100644 +index 0000000000..5be8010dda +--- /dev/null ++++ b/frigate/test/test_tz.py +@@ -0,0 +1,19 @@ ++import unittest ++ ++from frigate.util.time import get_normalized_tz_name ++ ++ ++class TestGetNormalizedTzName(unittest.TestCase): ++ def test_valid(self): ++ cases = [ ++ ("utc", "UTC"), ++ ("america/new_york", "America/New_York"), ++ ] ++ ++ for tz_name, expected in cases: ++ with self.subTest(tz_name=tz_name): ++ self.assertEqual(get_normalized_tz_name(tz_name), expected) ++ ++ def test_invalid(self): ++ with self.assertRaisesRegex(ValueError, r"Unknown timezone: foo/bar"): ++ get_normalized_tz_name("foo/bar") diff --git a/pkgs/by-name/fr/frigate/proc-cmdline-strip.patch b/pkgs/by-name/fr/frigate/proc-cmdline-strip.patch deleted file mode 100644 index 2dd131ebf419..000000000000 --- a/pkgs/by-name/fr/frigate/proc-cmdline-strip.patch +++ /dev/null @@ -1,22 +0,0 @@ -diff --git a/frigate/util/services.py b/frigate/util/services.py -index 64d83833d..912ce67bd 100644 ---- a/frigate/util/services.py -+++ b/frigate/util/services.py -@@ -121,7 +121,7 @@ def get_cpu_stats() -> dict[str, dict]: - pid = str(process.info["pid"]) - try: - cpu_percent = process.info["cpu_percent"] -- cmdline = process.info["cmdline"] -+ cmdline = " ".join(process.info["cmdline"]).rstrip() - - with open(f"/proc/{pid}/stat", "r") as f: - stats = f.readline().split() -@@ -155,7 +155,7 @@ def get_cpu_stats() -> dict[str, dict]: - "cpu": str(cpu_percent), - "cpu_average": str(round(cpu_average_usage, 2)), - "mem": f"{mem_pct}", -- "cmdline": clean_camera_user_pass(" ".join(cmdline)), -+ "cmdline": clean_camera_user_pass(cmdline), - } - except Exception: - continue diff --git a/pkgs/by-name/fr/frigate/web.nix b/pkgs/by-name/fr/frigate/web.nix index 7e284818b975..7ea2aecce45d 100644 --- a/pkgs/by-name/fr/frigate/web.nix +++ b/pkgs/by-name/fr/frigate/web.nix @@ -31,7 +31,7 @@ buildNpmPackage { --replace-fail "/tmp/cache" "/var/cache/frigate" ''; - npmDepsHash = "sha256-iIqP3pspkDbaXZkZ5MIT/GVGiKBJCkFXQ7Av5h1rWKk="; + npmDepsHash = "sha256-k21UBr4agbJDZD0PYVjylRcyuRCFeBE2YBqZzE8v+jU="; installPhase = '' cp -rv dist/ $out From aa1b83e8ead366758a13823065e5799d1e26a879 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Sat, 18 Jul 2026 23:53:47 +0200 Subject: [PATCH 413/423] frigate: extract models into models attribute tree This creates dedicated attributes per model and exposes a `model` and a optionally a `labelmap` attribute where useful. The idea is to collect model build plans to make them easily accessible and referencable in your configurations. The explicit idea is not to cache on cache.nixos.org, because they are usually readily availalbe as FODs or just require light conversions that everyone should be able to handle on their own machine or build pipeline. This now also packages the converted ssdlite mobilnet v2 model for OpenVINO based setups, though I would recommend looking into YOLO models at this time. --- .../package.nix | 14 ++++ .../ssdlite_mobilenet_v2_coco/package.nix | 64 ++++++++++++++ .../package.nix | 14 ++++ .../yamnet_classification_v1/package.nix | 32 +++++++ pkgs/by-name/fr/frigate/package.nix | 83 +++++++++---------- 5 files changed, 164 insertions(+), 43 deletions(-) create mode 100644 pkgs/by-name/fr/frigate/models/edgetpu/ssdlite_mobiledet_coco_qat_postprocess/package.nix create mode 100644 pkgs/by-name/fr/frigate/models/openvino/ssdlite_mobilenet_v2_coco/package.nix create mode 100644 pkgs/by-name/fr/frigate/models/tflite/ssdlite_mobiledet_coco_qat_postprocess/package.nix create mode 100644 pkgs/by-name/fr/frigate/models/tflite/yamnet_classification_v1/package.nix diff --git a/pkgs/by-name/fr/frigate/models/edgetpu/ssdlite_mobiledet_coco_qat_postprocess/package.nix b/pkgs/by-name/fr/frigate/models/edgetpu/ssdlite_mobiledet_coco_qat_postprocess/package.nix new file mode 100644 index 000000000000..925323b6fbcb --- /dev/null +++ b/pkgs/by-name/fr/frigate/models/edgetpu/ssdlite_mobiledet_coco_qat_postprocess/package.nix @@ -0,0 +1,14 @@ +{ + fetchurl, +}: + +let + model = fetchurl { + url = "https://github.com/google-coral/test_data/raw/release-frogfish/ssdlite_mobiledet_coco_qat_postprocess_edgetpu.tflite"; + hash = "sha256-Siviu7YU5XbVbcuRT6UnUr8PE0EVEnENNV2X+qGzVkE="; + }; +in + +model.overrideAttrs (_: { + passthru.model = model; +}) diff --git a/pkgs/by-name/fr/frigate/models/openvino/ssdlite_mobilenet_v2_coco/package.nix b/pkgs/by-name/fr/frigate/models/openvino/ssdlite_mobilenet_v2_coco/package.nix new file mode 100644 index 000000000000..c961d1291e8a --- /dev/null +++ b/pkgs/by-name/fr/frigate/models/openvino/ssdlite_mobilenet_v2_coco/package.nix @@ -0,0 +1,64 @@ +{ + fetchurl, + frigate, + lib, + stdenv, + ... +}: + +let + inherit (frigate) python3Packages; +in + +stdenv.mkDerivation (finalAttrs: { + pname = "ssdlite_mobilenet_v2_coco"; + version = "2018_05_09"; + + src = fetchurl { + url = "http://download.tensorflow.org/models/object_detection/ssdlite_mobilenet_v2_coco_2018_05_09.tar.gz"; + hash = "sha256-VCRFzOg02/u33xmRQl1HXoWi1+xoxgpPJiuxiqwQyLI="; + }; + + nativeBuildInputs = [ + python3Packages.openvino + ]; + + postPatch = '' + cp --no-preserve=mode ${frigate.src}/docker/main/build_ov_model.py . + substituteInPlace build_ov_model.py \ + --replace-fail "/models/${finalAttrs.pname}_${finalAttrs.version}" "./" \ + --replace-fail "/models/" "dist/" + ''; + + buildPhase = '' + runHook preBuild + mkdir dist + python3 build_ov_model.py + runHook postBuild + ''; + + installPhase = '' + runHook preInstall + mkdir -p $out + cp dist/*.{bin,xml} $out/ + runHook postInstall + ''; + + passthru = { + model = "${finalAttrs.finalPackage}/ssdlite_mobilnet_v2.xml"; + labelmap = fetchurl { + url = "https://github.com/openvinotoolkit/open_model_zoo/raw/master/data/dataset_classes/coco_91cl_bkgr.txt"; + hash = "sha256-cQBhlxYm2yS6s7rm/06c5uZmUFZZkBI/P4bxLThbN9E="; + # https://github.com/blakeblackshear/frigate/commit/8ac3114f9a014356272b8a44b752e82df342f245 + postFetch = '' + sed -i "s/truck/car/g" $out + ''; + }; + }; + + meta = { + description = "Object detection model trained on the COCO dataset."; + license = lib.licenses.asl20; + homepage = "https://www.kaggle.com/models/tensorflow/ssdlite-mobilenet-v2/"; + }; +}) diff --git a/pkgs/by-name/fr/frigate/models/tflite/ssdlite_mobiledet_coco_qat_postprocess/package.nix b/pkgs/by-name/fr/frigate/models/tflite/ssdlite_mobiledet_coco_qat_postprocess/package.nix new file mode 100644 index 000000000000..a9399e969a32 --- /dev/null +++ b/pkgs/by-name/fr/frigate/models/tflite/ssdlite_mobiledet_coco_qat_postprocess/package.nix @@ -0,0 +1,14 @@ +{ + fetchurl, +}: + +let + model = fetchurl { + url = "https://github.com/google-coral/test_data/raw/release-frogfish/ssdlite_mobiledet_coco_qat_postprocess.tflite"; + hash = "sha256-kLszpjTgQZFMwYGapd+ZgY5sOWxNLblSwP16nP/Eck8="; + }; +in + +model.overrideAttrs (_: { + passthru.model = model; +}) diff --git a/pkgs/by-name/fr/frigate/models/tflite/yamnet_classification_v1/package.nix b/pkgs/by-name/fr/frigate/models/tflite/yamnet_classification_v1/package.nix new file mode 100644 index 000000000000..255d8f4d1b2e --- /dev/null +++ b/pkgs/by-name/fr/frigate/models/tflite/yamnet_classification_v1/package.nix @@ -0,0 +1,32 @@ +{ + fetchzip, + lib, + stdenv, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "yamnet_classification_v1"; + version = "0-unstable"; + + src = fetchzip { + url = "https://www.kaggle.com/api/v1/models/google/yamnet/tfLite/classification-tflite/1/download"; + extension = "tar.gz"; + hash = "sha256-FRL0lpbjgAV7HlaZIR1Hf/hr1bcfSMSeYdeGzMYpDf0="; + }; + + dontBuild = true; + + installPhase = '' + runHook preInstall + mkdir $out + mv 1.tflite $out/yamnet_classification_v1.tflite + runHook postInstall + ''; + + passthru.model = "${finalAttrs.finalPackage}/${finalAttrs.pname}.tflite"; + + meta = { + homepage = "https://www.kaggle.com/models/google/yamnet/tfLite/classification-tflite"; + license = lib.licenses.asl20; + }; +}) diff --git a/pkgs/by-name/fr/frigate/package.nix b/pkgs/by-name/fr/frigate/package.nix index e60770f91fbc..bdf4fb1931d4 100644 --- a/pkgs/by-name/fr/frigate/package.nix +++ b/pkgs/by-name/fr/frigate/package.nix @@ -1,17 +1,16 @@ { - lib, - stdenv, - replaceVars, addDriverRunpath, callPackage, - python313Packages, fetchFromGitHub, rustPlatform, - fetchurl, ffmpeg-headless, - sqlite-vec, frigate, + lib, nixosTests, + python313Packages, + replaceVars, + sqlite-vec, + stdenv, }: let @@ -61,33 +60,6 @@ let ); inherit (python3Packages) python; - - # Tensorflow audio model - # https://github.com/blakeblackshear/frigate/blob/v0.15.0/docker/main/Dockerfile#L125 - tflite_audio_model = fetchurl { - url = "https://www.kaggle.com/api/v1/models/google/yamnet/tfLite/classification-tflite/1/download"; - hash = "sha256-G5cbITJ2AnOl+49dxQToZ4OyeFO7MTXVVa4G8eHjZfM="; - }; - - # Tensorflow Lite models - # https://github.com/blakeblackshear/frigate/blob/v0.15.0/docker/main/Dockerfile#L115-L117 - tflite_cpu_model = fetchurl { - url = "https://github.com/google-coral/test_data/raw/release-frogfish/ssdlite_mobiledet_coco_qat_postprocess.tflite"; - hash = "sha256-kLszpjTgQZFMwYGapd+ZgY5sOWxNLblSwP16nP/Eck8="; - }; - tflite_edgetpu_model = fetchurl { - url = "https://github.com/google-coral/test_data/raw/release-frogfish/ssdlite_mobiledet_coco_qat_postprocess_edgetpu.tflite"; - hash = "sha256-Siviu7YU5XbVbcuRT6UnUr8PE0EVEnENNV2X+qGzVkE="; - }; - - # TODO: OpenVino model - # https://github.com/blakeblackshear/frigate/blob/v0.15.0/docker/main/Dockerfile#L64-L77 - # https://github.com/blakeblackshear/frigate/blob/v0.15.0/docker/main/Dockerfile#L120-L123 - # Convert https://www.kaggle.com/models/tensorflow/ssdlite-mobilenet-v2 with https://github.com/blakeblackshear/frigate/blob/v0.15.0/docker/main/build_ov_model.py into OpenVino IR format - coco_91cl_bkgr = fetchurl { - url = "https://github.com/openvinotoolkit/open_model_zoo/raw/master/data/dataset_classes/coco_91cl_bkgr.txt"; - hash = "sha256-5Cj2vEiWR8Z9d2xBmVoLZuNRv4UOuxHSGZQWTJorXUQ="; - }; in python3Packages.buildPythonApplication (finalAttrs: { pname = "frigate"; @@ -158,16 +130,18 @@ python3Packages.buildPythonApplication (finalAttrs: { substituteInPlace frigate/db/sqlitevecq.py \ --replace-fail "/usr/local/lib/vec0" "${lib.getLib sqlite-vec}/lib/vec0${stdenv.hostPlatform.extensions.sharedLibrary}" - # provide default paths for models and maps that are shipped with frigate + # hardcoded default models shipped with Frigate substituteInPlace frigate/config/config.py \ - --replace-fail "/cpu_model.tflite" "${tflite_cpu_model}" \ - --replace-fail "/edgetpu_model.tflite" "${tflite_edgetpu_model}" + --replace-fail "/cpu_model.tflite" "${frigate.models.tflite.ssdlite_mobiledet_coco_qat_postprocess}" \ + --replace-fail "/edgetpu_model.tflite" "${frigate.models.edgetpu.ssdlite_mobiledet_coco_qat_postprocess}" \ + --replace-fail "/openvino-model/ssdlite_mobilenet_v2.xml" "${frigate.models.openvino.ssdlite_mobilenet_v2_coco.model}" \ + --replace-fail "/openvino-model/coco_91cl_bkgr.txt" "${frigate.models.openvino.ssdlite_mobilenet_v2_coco.labelmap}" substituteInPlace frigate/detectors/detector_config.py \ --replace-fail "/labelmap.txt" "${placeholder "out"}/share/frigate/labelmap.txt" substituteInPlace frigate/events/audio.py \ - --replace-fail "/cpu_audio_model.tflite" "${placeholder "out"}/share/frigate/cpu_audio_model.tflite" \ + --replace-fail "/cpu_audio_model.tflite" "${frigate.models.tflite.yamnet_classification_v1.model}" \ --replace-fail "/audio-labelmap.txt" "${placeholder "out"}/share/frigate/audio-labelmap.txt" ''; @@ -254,11 +228,7 @@ python3Packages.buildPythonApplication (finalAttrs: { mkdir -p $out/share/frigate cp -R {migrations,labelmap.txt,audio-labelmap.txt} $out/share/frigate/ - tar --extract --gzip --file ${tflite_audio_model} - cp --no-preserve=mode ./1.tflite $out/share/frigate/cpu_audio_model.tflite - - cp --no-preserve=mode ${coco_91cl_bkgr} $out/share/frigate/coco_91cl_bkgr.txt - sed -i 's/truck/car/g' $out/share/frigate/coco_91cl_bkgr.txt + ln -s ${frigate.models.tflite.yamnet_classification_v1.model} $out/share/frigate/cpu_audio_model.tflite runHook postInstall ''; @@ -286,13 +256,40 @@ python3Packages.buildPythonApplication (finalAttrs: { ]; passthru = { - inherit python; + inherit python python3Packages; pythonPath = (python3Packages.makePythonPath finalAttrs.finalPackage.dependencies) + ":${frigate}/${python.sitePackages}"; web = callPackage ./web.nix { inherit (finalAttrs) version src; }; + models = { + # Google Coral Accelerators as Tensorflow Delegate + # https://docs.frigate.video/configuration/object_detectors/#edge-tpu-detector + edgetpu = lib.recurseIntoAttrs ( + lib.packagesFromDirectoryRecursive { + inherit callPackage; + directory = ./models/edgetpu; + } + ); + # Intel OpenVINO for CPU/GPU/NPU + # https://docs.frigate.video/configuration/object_detectors/#openvino-detector + openvino = lib.recurseIntoAttrs ( + lib.packagesFromDirectoryRecursive { + inherit callPackage; + directory = ./models/openvino; + } + ); + # Tensorflow Lite CPU models + # https://docs.frigate.video/configuration/object_detectors/#cpu-detector-not-recommended + # https://docs.frigate.video/configuration/audio_detectors/ + tflite = lib.recurseIntoAttrs ( + lib.packagesFromDirectoryRecursive { + inherit callPackage; + directory = ./models/tflite; + } + ); + }; tests = { inherit (nixosTests) frigate; }; From b453b6ed6cfea9b0a2f3df740be00ee06a8f362c Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Sun, 19 Jul 2026 16:22:08 +0200 Subject: [PATCH 414/423] nixos/frigate: harden runtime execution environment --- nixos/modules/services/video/frigate.nix | 44 ++++++++++++++++++++++++ nixos/tests/frigate.nix | 2 ++ 2 files changed, 46 insertions(+) diff --git a/nixos/modules/services/video/frigate.nix b/nixos/modules/services/video/frigate.nix index c358f0cd63b2..6ee20f7cf582 100644 --- a/nixos/modules/services/video/frigate.nix +++ b/nixos/modules/services/video/frigate.nix @@ -792,9 +792,53 @@ in # Sockets/IPC RuntimeDirectory = "frigate"; + RemoveIPC = true; # Reduce visible process scope to cgroup ProtectProc = "invisible"; + + # Allow wide /proc inspection, e.g. for cpuinfo + ProcSubset = "all"; + + # Protect various system locations/interfaces + ProtectControlGroups = true; + ProtectHome = true; + ProtectHostname = true; + ProtectKernelLogs = true; + ProtectKernelModules = true; + ProtectKernelTunables = true; + ProtectSystem = "strict"; + + # No JIT compilation + MemoryDenyWriteExecute = true; + + # No ABI personality changes + LockPersonality = true; + + # Only IP/Unix sockets + RestrictAddressFamilies = [ + "AF_INET" + "AF_INET6" + "AF_UNIX" + ]; + + # Deny namespace creation + RestrictNamespaces = true; + + # No privilege escalation + NoNewPrivileges = true; + RestrictSUIDSGID = true; + + # No realtime schedulign + RestrictRealtime = true; + + # Restrict allowed syscalls + SystemCallFilter = [ + "@system-service" + "~@privileged" + ]; + SystemCallArchitectures = "native"; + SystemCallErrorNumber = "EPERM"; }; }; diff --git a/nixos/tests/frigate.nix b/nixos/tests/frigate.nix index 10712387f421..ca6fc5a5c621 100644 --- a/nixos/tests/frigate.nix +++ b/nixos/tests/frigate.nix @@ -77,5 +77,7 @@ # wait for a recording to appear machine.wait_for_file("/var/cache/frigate/test@*.mp4") + + machine.log(machine.execute("systemd-analyze security frigate.service | grep -v ✓")[1]) ''; } From 182e420eccd48bea2deb5d7ff9cb450b920a2b85 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Mon, 13 Jul 2026 15:01:44 +0200 Subject: [PATCH 415/423] python3Packages.filterpy: fix scipy 1.12 deprecation warnings --- .../python-modules/filterpy/default.nix | 7 ++++++- .../filterpy/scipy-1.12-deprecation.patch | 14 ++++++++++++++ 2 files changed, 20 insertions(+), 1 deletion(-) create mode 100644 pkgs/development/python-modules/filterpy/scipy-1.12-deprecation.patch diff --git a/pkgs/development/python-modules/filterpy/default.nix b/pkgs/development/python-modules/filterpy/default.nix index 110d3b136b0d..c5417046b1f6 100644 --- a/pkgs/development/python-modules/filterpy/default.nix +++ b/pkgs/development/python-modules/filterpy/default.nix @@ -24,7 +24,12 @@ buildPythonPackage { hash = "sha256-KuuVu0tqrmQuNKYmDmdy+TU6BnnhDxh4G8n9BGzjGag="; }; - patches = [ ./numpy-2.4-compat.patch ]; + patches = [ + ./numpy-2.4-compat.patch + + # https://github.com/rlabbe/filterpy/pull/331 + ./scipy-1.12-deprecation.patch + ]; build-system = [ setuptools ]; diff --git a/pkgs/development/python-modules/filterpy/scipy-1.12-deprecation.patch b/pkgs/development/python-modules/filterpy/scipy-1.12-deprecation.patch new file mode 100644 index 000000000000..ef26dbefafa2 --- /dev/null +++ b/pkgs/development/python-modules/filterpy/scipy-1.12-deprecation.patch @@ -0,0 +1,14 @@ +diff --git a/filterpy/discrete_bayes/discrete_bayes.py b/filterpy/discrete_bayes/discrete_bayes.py +index 084ba8c..c465835 100644 +--- a/filterpy/discrete_bayes/discrete_bayes.py ++++ b/filterpy/discrete_bayes/discrete_bayes.py +@@ -19,8 +19,7 @@ from __future__ import (absolute_import, division, print_function, + unicode_literals) + + import numpy as np +-from scipy.ndimage.filters import convolve +-from scipy.ndimage.interpolation import shift ++from scipy.ndimage import convolve, shift + + + def normalize(pdf): From 61d7bf9e9796a5c451dd8c7c53dd2f5c950aacad Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Fri, 18 Sep 2026 12:57:14 +0200 Subject: [PATCH 416/423] openvino: build cpu plugin on aarch64-linux We need to substitute the gcc-ar and gcc-ranlib path as otherwise the build scripts for ARM ComputeLibrary are finding the wrong ar/ranlib executables which breaks at link time. --- pkgs/by-name/op/openvino/package.nix | 13 ++++++++++++- 1 file changed, 12 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/op/openvino/package.nix b/pkgs/by-name/op/openvino/package.nix index 8946009c1340..65acf6a9453e 100644 --- a/pkgs/by-name/op/openvino/package.nix +++ b/pkgs/by-name/op/openvino/package.nix @@ -94,6 +94,17 @@ stdenv.mkDerivation (finalAttrs: { ./cmake-install-paths.patch ]; + # Fix arm computelib ar/ranlib toolchain paths for LTO awareness + postPatch = '' + substituteInPlace src/plugins/intel_cpu/thirdparty/ComputeLibrary/SConstruct \ + --replace-fail \ + "env['AR'] = toolchain_prefix + \"ar\"" \ + "env['AR'] = \"${lib.getExe' stdenv.cc.cc "gcc-ar"}\"" \ + --replace-fail \ + "env['RANLIB'] = toolchain_prefix + \"ranlib\"" \ + "env['RANLIB'] = \"${lib.getExe' stdenv.cc.cc "gcc-ranlib"}\"" + ''; + dontUseSconsCheck = true; dontUseSconsBuild = true; dontUseSconsInstall = true; @@ -127,7 +138,7 @@ stdenv.mkDerivation (finalAttrs: { (cmakeBool "ENABLE_SAMPLES" false) # features - (cmakeBool "ENABLE_INTEL_CPU" stdenv.hostPlatform.isx86_64) + (cmakeBool "ENABLE_INTEL_CPU" true) (cmakeBool "ENABLE_INTEL_GPU" true) (cmakeBool "ENABLE_INTEL_NPU" stdenv.hostPlatform.isx86_64) (cmakeBool "ENABLE_JS" false) From 302fc0370ddd6877990ba5639b0432637276a5ff Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 22 Sep 2026 08:27:55 +0000 Subject: [PATCH 417/423] openexr: 3.4.15 -> 3.5.0 --- pkgs/by-name/op/openexr/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/op/openexr/package.nix b/pkgs/by-name/op/openexr/package.nix index 1b39a5c662ca..4b6c998e710f 100644 --- a/pkgs/by-name/op/openexr/package.nix +++ b/pkgs/by-name/op/openexr/package.nix @@ -14,13 +14,13 @@ stdenv.mkDerivation rec { pname = "openexr"; - version = "3.4.15"; + version = "3.5.0"; src = fetchFromGitHub { owner = "AcademySoftwareFoundation"; repo = "openexr"; rev = "v${version}"; - hash = "sha256-Z2o2ooDqAof5rnR5lX3RfWnklyD/c98HuwWF6uZA+78="; + hash = "sha256-9gzGQPJIn3AaVp/4lNEcFWrxuersHimwrab6HjB7KfI="; }; outputs = [ From 9e15d22f16ef2e8c6db2a826517736cc11d8b2ed Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 6 Sep 2026 12:59:40 +0000 Subject: [PATCH 418/423] libpcap: 1.10.6 -> 1.10.7 Taken from history of PR #560539 --- pkgs/by-name/li/libpcap/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/li/libpcap/package.nix b/pkgs/by-name/li/libpcap/package.nix index 5abab91f1a89..cfd19f446756 100644 --- a/pkgs/by-name/li/libpcap/package.nix +++ b/pkgs/by-name/li/libpcap/package.nix @@ -28,13 +28,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "libpcap"; - version = "1.10.6"; + version = "1.10.7"; __structuredAttrs = true; src = fetchurl { url = "https://www.tcpdump.org/release/libpcap-${finalAttrs.version}.tar.gz"; - hash = "sha256-hy3REzf+GrAq2dT+4EfJ2iRNaVxt3zTi67cz79Ttiqk="; + hash = "sha256-CzlKyQ28Cpg4/5dGjgXJyaPoc97CUUzVjbZdhZ0pbjE="; }; outputs = [ From 2aef6e14b531d263160f63eb678c652da3c2db2c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Vladim=C3=ADr=20=C4=8Cun=C3=A1t?= Date: Tue, 22 Sep 2026 15:57:25 +0200 Subject: [PATCH 419/423] libaom: 3.14.1 -> 3.15.0 https://aomedia.googlesource.com/aom/+/refs/tags/v3.15.0 Fixes: CVE-2026-56209 CVE-2026-13906 --- pkgs/by-name/li/libaom/package.nix | 28 ++++++++++++---------------- 1 file changed, 12 insertions(+), 16 deletions(-) diff --git a/pkgs/by-name/li/libaom/package.nix b/pkgs/by-name/li/libaom/package.nix index 9dfe847d606a..6af569faf2b2 100644 --- a/pkgs/by-name/li/libaom/package.nix +++ b/pkgs/by-name/li/libaom/package.nix @@ -23,25 +23,16 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "libaom"; - version = "3.14.1"; + version = "3.15.0"; src = fetchzip { url = "https://aomedia.googlesource.com/aom/+archive/v${finalAttrs.version}.tar.gz"; - hash = "sha256-ddMrDkWV5jUbpPGKsMQl7s4r43205WbBtCEYtZNgwAM="; + hash = "sha256-TixZQP06TEZPtpHvWVOEagzHtXW9hqXWweO2yimBDG4="; stripRoot = false; }; patches = [ ./outputs.patch - ] - ++ lib.optionals (!stdenv.hostPlatform.isDarwin) [ - # This patch defines `_POSIX_C_SOURCE`, which breaks system headers - # on Darwin. - (fetchurl { - name = "musl.patch"; - url = "https://gitweb.gentoo.org/repo/gentoo.git/plain/media-libs/libaom/files/libaom-3.4.0-posix-c-source-ftello.patch?id=50c7c4021e347ee549164595280cf8a23c960959"; - hash = "sha256-6+u7GTxZcSNJgN7D+s+XAVwbMnULufkTcQ0s7l+Ydl0="; - }) ]; nativeBuildInputs = [ @@ -54,11 +45,16 @@ stdenv.mkDerivation (finalAttrs: { propagatedBuildInputs = lib.optional enableVmaf libvmaf; - env = lib.optionalAttrs stdenv.hostPlatform.isFreeBSD { - # This can be removed when we switch to libcxx from llvm 20 - # https://github.com/llvm/llvm-project/pull/122361 - NIX_CFLAGS_COMPILE = "-D_XOPEN_SOURCE=700"; - }; + env = + lib.optionalAttrs stdenv.hostPlatform.isFreeBSD { + # This can be removed when we switch to libcxx from llvm 20 + # https://github.com/llvm/llvm-project/pull/122361 + NIX_CFLAGS_COMPILE = "-D_XOPEN_SOURCE=700"; + } + // lib.optionalAttrs stdenv.hostPlatform.isLinux { + # _POSIX_C_SOURCE breaks system headers on Darwin; it's required on musl + NIX_CFLAGS_COMPILE = "-D_POSIX_C_SOURCE=200112L"; + }; preConfigure = '' # build uses `git describe` to set the build version From b2e5a7c32ef5cfda49a88303612c10e8babcbf74 Mon Sep 17 00:00:00 2001 From: K900 Date: Tue, 22 Sep 2026 17:22:26 +0300 Subject: [PATCH 420/423] expat: 2.8.4 -> 2.8.5 --- pkgs/by-name/ex/expat/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ex/expat/package.nix b/pkgs/by-name/ex/expat/package.nix index ec72f0835768..86590a2c5744 100644 --- a/pkgs/by-name/ex/expat/package.nix +++ b/pkgs/by-name/ex/expat/package.nix @@ -23,13 +23,13 @@ in stdenv.mkDerivation (finalAttrs: { pname = "expat"; - version = "2.8.4"; + version = "2.8.5"; src = fetchurl { url = with finalAttrs; "https://github.com/libexpat/libexpat/releases/download/${tagFor version}/${pname}-${version}.tar.xz"; - hash = "sha256-ZWrhzI2jtOpRO7TiVPM+YkOTgITA7GI52oczdrCZhac="; + hash = "sha256-HnJ7iTPsUad6mp2a/PjmiLzkXZB8E+Nqtzk/425wMYI="; }; strictDeps = true; From fb971edc63a705c30d8b642932723d6c515546b1 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Vladim=C3=ADr=20=C4=8Cun=C3=A1t?= Date: Tue, 22 Sep 2026 17:59:32 +0200 Subject: [PATCH 421/423] libheif: 1.23.4 -> 1.23.5 https://github.com/strukturag/libheif/releases/tag/v1.23.5 --- pkgs/by-name/li/libheif/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/li/libheif/package.nix b/pkgs/by-name/li/libheif/package.nix index e8febed52bae..e1a009bf666b 100644 --- a/pkgs/by-name/li/libheif/package.nix +++ b/pkgs/by-name/li/libheif/package.nix @@ -24,7 +24,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "libheif"; - version = "1.23.4"; + version = "1.23.5"; outputs = [ "bin" @@ -38,7 +38,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "strukturag"; repo = "libheif"; rev = "v${finalAttrs.version}"; - hash = "sha256-bxN3YB/nKjrsHa/dM3sTAnWR+wOHk5a6ku6NF+8moQ0="; + hash = "sha256-+nrUIAclVgkj4N5U3wQ1L6qpZuF3fuzHFDUT+X39h04="; }; nativeBuildInputs = [ From 45d94985cd942a0f3bffe3213beab362b010f827 Mon Sep 17 00:00:00 2001 From: whispers Date: Tue, 22 Sep 2026 17:59:34 -0400 Subject: [PATCH 422/423] meson: 1.12.0 -> 1.12.1 https://github.com/mesonbuild/meson/compare/1.12.0...1.12.1 https://github.com/mesonbuild/meson/milestone/139 --- pkgs/by-name/me/meson/004-gir-fallback-path.patch | 12 ++++++------ pkgs/by-name/me/meson/package.nix | 4 ++-- 2 files changed, 8 insertions(+), 8 deletions(-) diff --git a/pkgs/by-name/me/meson/004-gir-fallback-path.patch b/pkgs/by-name/me/meson/004-gir-fallback-path.patch index e6d740265277..f158bdce4872 100644 --- a/pkgs/by-name/me/meson/004-gir-fallback-path.patch +++ b/pkgs/by-name/me/meson/004-gir-fallback-path.patch @@ -1,9 +1,9 @@ diff --git a/mesonbuild/modules/gnome.py b/mesonbuild/modules/gnome.py -index 1c6952df7..9466a0b7d 100644 +index 7be632517b..683818b64c 100644 --- a/mesonbuild/modules/gnome.py +++ b/mesonbuild/modules/gnome.py -@@ -923,6 +923,16 @@ class GnomeModule(ExtensionModule): - if fatal_warnings: +@@ -1264,6 +1264,16 @@ + if kwargs['fatal_warnings']: scan_command.append('--warn-error') + if len(set(girtarget.get_custom_install_dir()[0] for girtarget in girtargets if girtarget.get_custom_install_dir())) > 1: @@ -16,6 +16,6 @@ index 1c6952df7..9466a0b7d 100644 + if fallback_libpath is not None and isinstance(fallback_libpath, str) and len(fallback_libpath) > 0 and fallback_libpath[0] == "/": + scan_command += ['--fallback-library-path=' + fallback_libpath] + - generated_files = [f for f in libsources if isinstance(f, (GeneratedList, CustomTarget, CustomTargetIndex))] - - scan_target = self._make_gir_target(state, girfile, scan_command, generated_files, depends, kwargs) + generated_files: list[build.GeneratedTypes] = [] + depend_files: list[mesonlib.File] = [] + for f in libsources: diff --git a/pkgs/by-name/me/meson/package.nix b/pkgs/by-name/me/meson/package.nix index f0d0dd59e535..f472a97583b4 100644 --- a/pkgs/by-name/me/meson/package.nix +++ b/pkgs/by-name/me/meson/package.nix @@ -17,7 +17,7 @@ python3.pkgs.buildPythonApplication (finalAttrs: { pname = "meson"; - version = "1.12.0"; + version = "1.12.1"; pyproject = true; __structuredAttrs = true; @@ -25,7 +25,7 @@ python3.pkgs.buildPythonApplication (finalAttrs: { owner = "mesonbuild"; repo = "meson"; tag = finalAttrs.version; - hash = "sha256-lnuySM7aCojPU9bQI7LPKgod8otFa+Spo9yIDFbOJVs="; + hash = "sha256-cQphgkEWNpjjs7DuV5+6KGDhsmQ4x09cH+FU0lfoB0Y="; }; patches = [ From 99db7938f54a64d95ce56a885082c507486db31c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Vladim=C3=ADr=20=C4=8Cun=C3=A1t?= Date: Wed, 23 Sep 2026 08:28:03 +0200 Subject: [PATCH 423/423] libaom: fixup outputs in *.cmake Now libheif builds for me with this atop nixpkgs master. --- pkgs/by-name/li/libaom/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/li/libaom/package.nix b/pkgs/by-name/li/libaom/package.nix index 6af569faf2b2..c8cf959b9bf0 100644 --- a/pkgs/by-name/li/libaom/package.nix +++ b/pkgs/by-name/li/libaom/package.nix @@ -87,6 +87,9 @@ stdenv.mkDerivation (finalAttrs: { postFixup = '' moveToOutput lib/libaom.a "$static" + substituteInPlace "$dev"/lib/cmake/*/*.cmake \ + --replace-quiet "$out/lib/libaom.a" "$static/lib/libaom.a" \ + --replace-quiet "$"'{_IMPORT_PREFIX}/include' "$dev/include" '' + lib.optionalString stdenv.hostPlatform.isStatic '' ln -s $static $out