libsecretspec: rename secretspec-ffi and update to 0.21.0

Follow the upstream native library rename, update cargo-c targets and pkg-config tests, and retain secretspec-ffi as a package alias. Document the native consumer migration in the 26.11 release notes.

https://github.com/cachix/secretspec/releases/tag/v0.21.0

Assisted-by: OpenAI Codex CLI 0.155.1 (gpt-6-sol)
This commit is contained in:
Domen Kožar
2026-09-23 16:18:28 -07:00
parent 22950f0aa4
commit 665bc767c3
3 changed files with 17 additions and 11 deletions

View File

@@ -184,6 +184,11 @@
- `librest` providing 0.7 ABI was removed. `librest_1_0` providing 1.0 ABI was renamed to `librest` and `librest_1_0` was kept as an alias.
- `secretspec-ffi` has been renamed to `libsecretspec` and updated to 0.21.0.
The old package attribute remains an alias, but native consumers must rebuild
against the new `libsecretspec` library and pkg-config module. The separate
`libsecretspec-resolver` package provides a C client for `secretspec serve`.
- `luaPackages.lrexlib-pcre` has been removed as part of the process to fully migrate from the end-of-life PRCE library to PCRE2. `luaPackages.lrexlib-pcre2` and multiple other versions of lrexlib can be used instead.
- `hostapd` was upgraded to version 2.12+, which moves move supported, basic, and beacon transmission rate configuration to be at BSS level instead of per-radio for all BSSs. Refer to the [upstream example config](https://git.w1.fi/cgit/hostap/plain/hostapd/hostapd.conf) for details.

View File

@@ -12,28 +12,28 @@
}:
rustPlatform.buildRustPackage (finalAttrs: {
pname = "secretspec-ffi";
version = "0.19.0";
pname = "libsecretspec";
version = "0.21.0";
__structuredAttrs = true;
src = fetchFromGitHub {
owner = "cachix";
repo = "secretspec";
tag = "v${finalAttrs.version}";
hash = "sha256-u6zfPsyLoktLQTE8OEDhK0GtiogOw/3ML4zpDVhSrX0=";
hash = "sha256-12jIhLZhtyQwkt2vKHqjGOuKSwwevcxzp8Ii02RTMLY=";
};
cargoHash = "sha256-ogeNTp94FJv7p+eZgrLUK1i63VCHiqHd7BsP+jDMHVc=";
cargoHash = "sha256-yqBAhnHBwKbSyH8sEDo6y0xGUdKJgHd3Gsr1sTS/bRc=";
nativeBuildInputs = [ cargo-c ];
# Keep the static archive intact while removing non-exported symbols from the shared library.
stripDebugFlags = if stdenv.hostPlatform.isDarwin then [ "-x" ] else [ "--strip-unneeded" ];
stripExclude = [ "lib/libsecretspec_ffi.a" ];
stripExclude = [ "lib/libsecretspec.a" ];
buildPhase = ''
runHook preBuild
${buildPackages.rust.envVars.setEnv} cargo cbuild -p secretspec-ffi -j $NIX_BUILD_CORES \
${buildPackages.rust.envVars.setEnv} cargo cbuild -p libsecretspec -j $NIX_BUILD_CORES \
--profile dist --frozen --prefix=${placeholder "out"} \
--target ${stdenv.hostPlatform.rust.rustcTarget}
runHook postBuild
@@ -41,7 +41,7 @@ rustPlatform.buildRustPackage (finalAttrs: {
installPhase = ''
runHook preInstall
${buildPackages.rust.envVars.setEnv} cargo cinstall -p secretspec-ffi -j $NIX_BUILD_CORES \
${buildPackages.rust.envVars.setEnv} cargo cinstall -p libsecretspec -j $NIX_BUILD_CORES \
--profile dist --frozen --prefix=${placeholder "out"} \
--target ${stdenv.hostPlatform.rust.rustcTarget}
runHook postInstall
@@ -49,7 +49,7 @@ rustPlatform.buildRustPackage (finalAttrs: {
checkPhase = ''
runHook preCheck
${buildPackages.rust.envVars.setEnv} cargo ctest -p secretspec-ffi -j $NIX_BUILD_CORES \
${buildPackages.rust.envVars.setEnv} cargo ctest -p libsecretspec -j $NIX_BUILD_CORES \
--profile dist --frozen --prefix=${placeholder "out"} \
--target ${stdenv.hostPlatform.rust.rustcTarget}
runHook postCheck
@@ -68,8 +68,8 @@ rustPlatform.buildRustPackage (finalAttrs: {
buildInputs = [ finalAttrs.finalPackage ];
}
''
$CC ${finalAttrs.src}/secretspec-ffi/tests/smoke.c \
$(pkg-config --cflags --libs secretspec_ffi) \
$CC ${finalAttrs.src}/libsecretspec/tests/smoke.c \
$(pkg-config --cflags --libs libsecretspec) \
-o smoke
./smoke
touch $out
@@ -86,6 +86,6 @@ rustPlatform.buildRustPackage (finalAttrs: {
domenkozar
sandydoo
];
pkgConfigModules = [ "secretspec_ffi" ];
pkgConfigModules = [ "libsecretspec" ];
};
})

View File

@@ -2309,6 +2309,7 @@ mapAliases {
sdnotify-wrapper = skawarePackages.sdnotify-wrapper;
seafile-server = throw "'seafile-server' has been removed as it is unmaintained"; # Added 2025-08-21
seahub = throw "'seahub' has been removed as it is unmaintained"; # Added 2025-08-21
secretspec-ffi = libsecretspec; # Added 2026-09-23
securefs = throw "'securefs' has been removed as it depends on fuse2"; # Added 2026-05-05
semantik = throw "'semantik' has been removed as it depended on EOL qt5 webengine"; # Added 2026-04-17
semiphemeral = throw "'semiphemeral' has been removed as it is archived upstream"; # Added 2025-11-06