Merge staging-next into staging

This commit is contained in:
nixpkgs-ci[bot]
2026-09-22 12:13:53 +00:00
committed by GitHub
71 changed files with 4919 additions and 338 deletions

View File

@@ -326,8 +326,8 @@ the packages with the version of the interpreter. Because this is irrelevant for
applications, the prefix is omitted.
When packaging a Python application with [`buildPythonApplication`](#buildpythonapplication-function), it should be
called with `callPackage` and passed `python3` or `python3Packages` (possibly
specifying an interpreter version), like this:
called with `callPackage` and passed `python3` or `python3Packages` (or possibly
specifying an interpreter version such as `python313Packages`), like this:
```nix
{

View File

@@ -435,8 +435,7 @@
"maintainers": {
"Aleksanaa": 42209822,
"Hythera": 87016780,
"getchoo": 48872998,
"michaelgrahamevans": 5932424
"getchoo": 48872998
},
"members": {},
"name": "GNOME Circle"

View File

@@ -98,6 +98,8 @@
- [ioquake3](https://ioquake3.org), a open-source port of the 3D action shooter Quake 3 Arena. Available as [programs.ioquake3](#opt-programs.ioquake3.enable).
- [Greenlight](https://github.com/bigbluebutton/greenlight), an end-user web interface for the virtual classroom software BigBlueButton. Available as [services.greenlight](#opt-services.greenlight.enable).
- [Matrix Authentication Service](https://github.com/element-hq/matrix-authentication-service) is an OAuth2.0 and OpenID Connect provider for Matrix homeservers (such as Synapse). It replaces standard password authentication with modern OpenID Connect flows, and can delegate authentication to upstream OIDC providers. Available as [services.matrix-authentication-service](#opt-services.matrix-authentication-service.enable).
- [Krill](https://nlnetlabs.nl/projects/krill/about), RPKI CA and Publication Server written in Rust. Available as [services.krill](#opt-services.krill.enable).

View File

@@ -1730,6 +1730,7 @@
./services/web-apps/gotosocial.nix
./services/web-apps/goupile.nix
./services/web-apps/grav.nix
./services/web-apps/greenlight.nix
./services/web-apps/grocy.nix
./services/web-apps/guacamole-client.nix
./services/web-apps/guacamole-server.nix

View File

@@ -1800,6 +1800,8 @@ in
Group = cfg.group;
Slice = "system-gitlab.slice";
ExecStart = "${gitlab-rake}/bin/gitlab-rake gitlab:backup:create";
Type = "oneshot";
RemainAfterExit = true;
};
};

View File

@@ -48,7 +48,7 @@ let
) "<VaapiDevice>${escapeXML cfg.hardwareAcceleration.device}</VaapiDevice>"}
${optionalString (
cfg.hardwareAcceleration.type == "qsv" && cfg.hardwareAcceleration.device != null
) "<OpenclDevice>${escapeXML cfg.hardwareAcceleration.device}</OpenclDevice>"}
) "<QsvDevice>${escapeXML cfg.hardwareAcceleration.device}</QsvDevice>"}
<EncodingThreadCount>${
if cfg.transcoding.threadCount != null then toString cfg.transcoding.threadCount else "-1"
}</EncodingThreadCount>

View File

@@ -0,0 +1,567 @@
{
lib,
config,
pkgs,
options,
...
}:
let
cfg = config.services.greenlight;
opt = options.services.greenlight;
dataDir = "/var/lib/greenlight";
listeningAddress = "${cfg.settings.BINDING}:${lib.toString cfg.settings.PORT}";
configEnv = lib.concatMapAttrs (
name: value:
lib.optionalAttrs (value != null) {
${name} = if lib.isBool value then lib.boolToString value else toString value;
}
) cfg.settings;
defaultSecretKeyBaseFile = "${dataDir}/secrets/secret-key-base";
needsGenCredentialsUnit = cfg.secretKeyBaseFile == null;
credentials = {
SECRET_KEY_BASE = lib.defaultTo defaultSecretKeyBaseFile cfg.secretKeyBaseFile;
}
// lib.optionalAttrs (cfg.database.passwordFile != null) {
DATABASE_PASSWORD = cfg.database.passwordFile;
};
loadCredentialsIntoEnv = lib.concatMapAttrsStringSep "\n" (
name: _: ''export ${name}="$(systemd-creds cat ${name})"''
) credentials;
loadCredentials = lib.mapAttrsToList (name: path: "${name}:${path}") credentials;
isRedisUnixSocket = lib.hasPrefix "/" cfg.redis.host;
isDatabaseUnixSocket = lib.hasPrefix "/" cfg.database.host;
databaseUrl = "postgresql://${lib.strings.escapeURL cfg.database.user}:$DATABASE_PASSWORD@${lib.strings.escapeURL cfg.database.host}${
lib.optionalString (
!isDatabaseUnixSocket && cfg.database.port != null
) ":${toString cfg.database.port}"
}/${lib.strings.escapeURL cfg.database.name}";
redisEnv =
if isRedisUnixSocket then
{
REDIS_URL = "unix://${cfg.redis.host}";
}
else
{
# Does not support passwords, but upstream does not provide an adequate env variable
# Perhaps patch or make a PR upstream in the future
REDIS_URL = "redis://${cfg.redis.host}:${toString cfg.redis.port}";
};
greenlight-rake = pkgs.writeShellApplication {
name = "greenlight-rake";
text =
let
command = pkgs.writeShellScript "greenlight-rake-unwrapped" ''
${loadCredentialsIntoEnv}
export DATABASE_PASSWORD="''${DATABASE_PASSWORD:-}"
export DATABASE_URL="${databaseUrl}"
exec ${lib.getExe' cfg.package.rubyEnv "rake"} "$@"
'';
env' = lib.filterAttrs (_: value: value != null) configEnv;
supplementaryGroups = lib.optionalString (cfg.redis.createLocally && isRedisUnixSocket) (
lib.escapeShellArg "--property=SupplementaryGroups=${config.services.redis.servers.greenlight.group}"
);
in
''
exec ${lib.getExe' config.systemd.package "systemd-run"} \
${
lib.escapeShellArgs (map (credential: "--property=LoadCredential=${credential}") loadCredentials)
} \
${
lib.escapeShellArgs (lib.mapAttrsToList (name: value: "--setenv=${name}=${toString value}") env')
} \
--uid=${lib.escapeShellArg cfg.user} \
--gid=${lib.escapeShellArg cfg.group} \
${supplementaryGroups} \
--working-directory=${lib.escapeShellArg cfg.package}/share/greenlight \
--property=PrivateTmp=yes \
--pty \
--wait \
--collect \
--service-type=exec \
--quiet \
-- \
${command} "$@"
'';
};
defaultServiceConfig = {
User = cfg.user;
Group = cfg.group;
WorkingDirectory = "${cfg.package}/share/greenlight";
StateDirectory = [
"greenlight"
"greenlight/secrets"
"greenlight/storage"
];
StateDirectoryMode = "0700";
LogsDirectory = "greenlight";
# Service hardening
ReadWritePaths = [
dataDir
"/var/log/greenlight"
];
CacheDirectory = "greenlight";
AmbientCapabilities = "";
CapabilityBoundingSet = "";
# ProtectClock adds DeviceAllow=char-rtc r
DeviceAllow = "";
DevicePolicy = "closed";
LockPersonality = true;
# Loosening setting, required by Ruby daemon
MemoryDenyWriteExecute = false;
NoNewPrivileges = true;
RemoveIPC = true;
PrivateDevices = true;
PrivateMounts = true;
PrivateTmp = true;
PrivateUsers = true;
ProtectClock = true;
ProtectHome = true;
ProtectHostname = true;
ProtectSystem = "strict";
ProtectControlGroups = true;
ProtectKernelLogs = true;
ProtectKernelModules = true;
ProtectKernelTunables = true;
ProtectProc = "invisible";
ProcSubset = "pid";
RestrictAddressFamilies = [
"AF_UNIX"
"AF_INET"
"AF_INET6"
];
RestrictNamespaces = true;
RestrictRealtime = true;
RestrictSUIDSGID = true;
SystemCallArchitectures = "native";
SystemCallFilter = [
"@system-service"
# Loosening setting, required by Ruby daemon
#"~@privileged @setuid @keyring"
];
UMask = "0077";
# ensure permissions to connect to the redis socket
SupplementaryGroups = lib.mkIf (cfg.redis.createLocally && isRedisUnixSocket) [
config.services.redis.servers.greenlight.group
];
};
in
{
meta = {
buildDocsInSandbox = false;
maintainers = [ lib.maintainers.onny ];
teams = [ lib.teams.ngi ];
};
options.services.greenlight = {
enable = lib.mkEnableOption "Greenlight web interface for BigBlueButton";
package = lib.mkPackageOption pkgs "greenlight" { };
database = {
createLocally = lib.mkOption {
description = ''
Whether to configure a local PostgreSQL server and database for Greenlight.
The connection is performed via Unix sockets.
'';
type = lib.types.bool;
default = true;
};
host = lib.mkOption {
type = lib.types.str;
default = "/run/postgresql";
example = "127.0.0.1";
description = "Hostname or address of the postgresql server. If an absolute path is given here, it will be interpreted as a unix socket path.";
};
port = lib.mkOption {
type = lib.types.nullOr lib.types.port;
default = 5432;
description = "Port of the postgresql server.";
};
name = lib.mkOption {
type = lib.types.str;
default = "greenlight";
description = "The name of the Greenlight database.";
};
user = lib.mkOption {
type = lib.types.str;
default = "greenlight";
description = "The database user for Greenlight.";
};
passwordFile = lib.mkOption {
type = lib.types.nullOr lib.types.path;
default = null;
example = "/run/keys/greenlight-db-password";
description = ''
A file containing the password corresponding to {option}`${opt.database.user}`.
'';
};
};
redis = {
createLocally = lib.mkOption {
description = ''
Whether to configure a local Redis server for Greenlight.
The connection is performed via Unix sockets by default,
but that can be changed by configuring {option}`${opt.redis.host}` and {option}`${opt.redis.port}`.
'';
type = lib.types.bool;
default = true;
};
host = lib.mkOption {
description = "The redis host Greenlight will connect to.";
type = lib.types.str;
default =
if cfg.redis.createLocally then config.services.redis.servers.greenlight.unixSocket else null;
defaultText = lib.literalExpression "config.services.redis.servers.greenlight.unixSocket";
};
port = lib.mkOption {
description = "The port of the redis server Greenlight will connect to. Set to zero to disable TCP and use Unix sockets instead.";
type = lib.types.port;
default = 0;
};
};
configureNginx = lib.mkOption {
description = ''
Configure nginx as a reverse proxy for Greenlight.
Alternatively you can configure a reverse-proxy of your choice to serve specific
paths. Take a look at Greenlight's provided reverse proxy configurations at
`https://github.com/bigbluebutton/greenlight/blob/master/greenlight-v3.nginx`.
'';
type = lib.types.bool;
default = true;
};
user = lib.mkOption {
description = ''
User under which Greenlight runs. If it is set to "greenlight",
that user will be created, otherwise it should be set to the
name of a user created elsewhere.
'';
type = lib.types.str;
default = "greenlight";
};
group = lib.mkOption {
description = ''
Group under which Greenlight runs.
'';
type = lib.types.str;
default = "greenlight";
};
settings = lib.mkOption {
type = lib.types.submodule {
freeformType = lib.types.attrsOf (
lib.types.nullOr (
lib.types.oneOf [
lib.types.str
lib.types.bool
lib.types.int
lib.types.port
lib.types.path
]
)
);
options = {
URL_HOST = lib.mkOption {
type = lib.types.str;
default = "localhost";
description = "Hostname to use";
};
PORT = lib.mkOption {
type = lib.types.port;
default = 6346;
description = "Port for the puma daemon to bind to.";
};
BINDING = lib.mkOption {
type = lib.types.str;
default = "127.0.0.1";
description = "Address for the puma daemon to bind to.";
};
};
};
default = { };
description = ''
Extra configuration options to append or override.
For available and default option values see
[upstream configuration file](https://github.com/bigbluebutton/greenlight/blob/master/sample.env).
'';
};
secretKeyBaseFile = lib.mkOption {
description = ''
Path to file containing the secret key base.
The content of the file will be sourced into {env}`SECRET_KEY_BASE` environment
variable. The secret has a minimum length requirement of 64 bytes.
One way to generate such a secret is to use `openssl rand -hex 64`.
This file is loaded using systemd credentials, and therefore does not need to be
owned by the greenlight user.
If this option is null, it will be created at ${defaultSecretKeyBaseFile}
with a new secret key base.
'';
default = null;
type = lib.types.nullOr lib.types.str;
};
};
config = lib.mkIf cfg.enable {
assertions = [
{
assertion = !isRedisUnixSocket -> cfg.redis.port != 0;
message = ''
`services.greenlight.redis.port` needs to be configured if `services.greenlight.redis.host` is not a unix socket.
'';
}
{
assertion = !isDatabaseUnixSocket -> cfg.database.port != null;
message = ''
`services.greenlight.database.port` needs to be configured if `services.greenlight.database.host` is not a unix socket.
'';
}
{
assertion = cfg.database.passwordFile == null || !isDatabaseUnixSocket;
message = ''
`services.greenlight.database.passwordFile` has no effect when `services.greenlight.database.host`
is a unix socket, since local socket connections normally authenticate via peer/ident, not a password.
Either point `database.host` at a TCP address, or drop `passwordFile`.
'';
}
{
assertion = !(cfg.database.createLocally && cfg.database.passwordFile != null);
message = ''
`services.greenlight.database.passwordFile` is set, but `database.createLocally` is also enabled.
The PostgreSQL role created via `ensureUsers` has no password configured, so authentication would
fail. Either disable `database.createLocally` and use an external database, or configure the local
role's password yourself (e.g. via `services.postgresql.initialScript`) and keep it in sync with
`passwordFile`.
'';
}
{
assertion = cfg.database.createLocally && isDatabaseUnixSocket -> cfg.database.user == cfg.user;
message = ''
services.greenlight.database.user must equal services.greenlight.user when
services.greenlight.database.createLocally is true and services.greenlight.database.host
is a unix socket, since the local PostgreSQL connection authenticates via peer auth
(OS user must match the Postgres role name).
'';
}
];
services.greenlight.settings = lib.mkMerge [
{
RAILS_ENV = lib.mkDefault "production";
RAILS_ROOT = "${cfg.package}/share/greenlight";
BUNDLE_WITHOUT = "development:test";
BUNDLE_USER_HOME = "/tmp/bundle"; # will use private tmp inside systemd unit
}
redisEnv
];
systemd.services.greenlight-init-credentials = lib.mkIf needsGenCredentialsUnit {
script = ''
if ! test -f ${defaultSecretKeyBaseFile}; then
${lib.getExe' cfg.package.rubyEnv "bundle"} exec rails secret > ${defaultSecretKeyBaseFile}
fi
'';
serviceConfig = {
Type = "oneshot";
SyslogIdentifier = "greenlight-init-dirs";
}
// defaultServiceConfig;
environment = configEnv;
after = [ "network.target" ];
};
systemd.services."greenlight-seeder" = {
script = ''
set -o pipefail -o nounset
shopt -s inherit_errexit
${loadCredentialsIntoEnv}
export DATABASE_PASSWORD="''${DATABASE_PASSWORD:-}"
export DATABASE_URL="${databaseUrl}"
# Auto-migrate on first run or if the package has changed
versionFile="${dataDir}/src-version"
version=$(cat "$versionFile" 2>/dev/null || echo 0)
if [[ $version == 0 ]]; then
echo "Initialising database and running seed..."
DISABLE_DATABASE_ENVIRONMENT_CHECK=1 rails db:migrate db:migrate:with_data
echo ${cfg.package.version} > "$versionFile"
elif [[ $version != ${cfg.package.version} ]]; then
echo "Executing database migration and database seed..."
rails db:migrate db:migrate:with_data
echo ${cfg.package.version} > "$versionFile"
fi
'';
serviceConfig = {
Type = "oneshot";
RemainAfterExit = true;
LoadCredential = loadCredentials;
}
// defaultServiceConfig;
path = [ cfg.package.rubyEnv ];
environment = configEnv;
wants = lib.optional cfg.database.createLocally "postgresql.target";
after = [
"network.target"
]
++ lib.optional cfg.database.createLocally "postgresql.target"
++ lib.optional needsGenCredentialsUnit "greenlight-init-credentials.service"
++ lib.optional cfg.redis.createLocally "redis-greenlight.service";
requires =
lib.optional needsGenCredentialsUnit "greenlight-init-credentials.service"
++ lib.optional cfg.database.createLocally "postgresql.target"
++ lib.optional cfg.redis.createLocally "redis-greenlight.service";
};
systemd.services."greenlight-web" = {
script = ''
${loadCredentialsIntoEnv}
export DATABASE_PASSWORD="''${DATABASE_PASSWORD:-}"
export DATABASE_URL="${databaseUrl}"
${lib.getExe' cfg.package.rubyEnv "bundle"} exec rails server -u puma
'';
serviceConfig = {
LoadCredential = loadCredentials;
}
// defaultServiceConfig;
environment = configEnv;
bindsTo = [ "greenlight-seeder.service" ];
after = [
"greenlight-seeder.service"
]
++ lib.optional needsGenCredentialsUnit "greenlight-init-credentials.service"
++ lib.optional cfg.database.createLocally "postgresql.target"
++ lib.optional cfg.redis.createLocally "redis-greenlight.service";
requires =
lib.optional needsGenCredentialsUnit "greenlight-init-credentials.service"
++ lib.optional cfg.database.createLocally "postgresql.target"
++ lib.optional cfg.redis.createLocally "redis-greenlight.service";
wantedBy = [ "multi-user.target" ];
};
services.redis.servers = lib.mkIf cfg.redis.createLocally {
greenlight = {
enable = true;
port = cfg.redis.port;
bind = lib.mkIf (!isRedisUnixSocket) cfg.redis.host;
};
};
services.postgresql = lib.mkIf cfg.database.createLocally {
enable = true;
ensureUsers = [
{
name = cfg.database.user;
ensureDBOwnership = true;
}
];
ensureDatabases = [ cfg.database.name ];
};
services.nginx = lib.mkIf cfg.configureNginx {
enable = true;
# See https://github.com/bigbluebutton/greenlight/blob/master/greenlight-v3.nginx
virtualHosts."${cfg.settings.URL_HOST}" =
let
bbbProxyHeaders = ''
proxy_redirect off;
proxy_http_version 1.1;
proxy_set_header Host "${cfg.settings.URL_HOST}";
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
'';
in
{
root = "${cfg.package}/share/greenlight/public";
locations."/" = {
tryFiles = "$uri @greenlight";
};
locations."@greenlight" = {
proxyPass = "http://${listeningAddress}";
extraConfig = bbbProxyHeaders;
};
locations."/cable" = {
proxyPass = "http://${listeningAddress}";
extraConfig = bbbProxyHeaders + ''
proxy_set_header Connection "upgrade";
proxy_set_header Upgrade $http_upgrade;
'';
};
locations."@bbb-fe" = {
proxyPass = "http://${listeningAddress}";
extraConfig = bbbProxyHeaders + ''
proxy_set_header Connection "";
proxy_buffer_size 128k;
proxy_buffers 4 256k;
proxy_busy_buffers_size 256k;
'';
};
locations."~ '/api/v1/rooms/\\w{3}-\\w{3}-\\w{3}-\\w{3}\\.json$'" = {
proxyPass = "http://${listeningAddress}";
extraConfig = bbbProxyHeaders + ''
proxy_set_header Connection "";
client_max_body_size 31m;
'';
};
locations."~ '/api/v1/users/\\w{8}-\\w{4}-\\w{4}-\\w{4}-\\w{12}\\.json$'" = {
proxyPass = "http://${listeningAddress}";
extraConfig = bbbProxyHeaders + ''
proxy_set_header Connection "";
client_max_body_size 4m;
'';
};
locations."~ /api/v1/admin/site_settings/BrandingImage\\.json$" = {
proxyPass = "http://${listeningAddress}";
extraConfig = bbbProxyHeaders + ''
proxy_set_header Connection "";
client_max_body_size 4m;
'';
};
};
};
users.users = lib.mkIf (cfg.user == "greenlight") {
greenlight = {
isSystemUser = true;
home = cfg.package;
inherit (cfg) group;
};
};
users.groups = lib.mkIf (cfg.group == "greenlight") { ${cfg.group} = { }; };
environment.systemPackages = [ greenlight-rake ];
};
}

View File

@@ -996,15 +996,51 @@ in
assertions =
let
# Host Nix config info
inherit
(rec {
disabledOpts = filter (x: !x.value) [
options.nix.enable
options.nix.daemon.enable
];
hostNixSocketEnabled = disabledOpts == [ ];
hostNixSocketIsDisabled =
if lib.length disabledOpts == 1 then
"host option ${lib.head disabledOpts} is disabled"
else
"host options ${lib.concatStringsSep " and " disabledOpts} are disabled";
})
hostNixSocketEnabled
hostNixSocketIsDisabled
;
# Tested in: nixos/tests/containers-eval.nix
mapper =
name: cfg:
name:
{ cfg, opt }:
optional (cfg.networkNamespace != null && (cfg.privateNetwork || cfg.interfaces != [ ]))
"containers.${name}.networkNamespace is mutally exclusive to containers.${name}.privateNetwork and containers.${name}.interfaces."
++
optional (cfg.config.nix.enable && cfg.config.nix.daemon.enable && !config.nix.daemon.enable)
"${options.containers}.${strings.escapeNixIdentifier name} requires a Nix daemon but the host does not provided it, as option ${options.nix.daemon.enable} is disabled";
optional (cfg.flake != null && !config.nix.enable)
"${options.containers}.${strings.escapeNixIdentifier name}.flake is defined, so the container is built with nix on the host, but ${options.nix.enable} is disabled"
++
optional
(
!hostNixSocketEnabled
&& opt.config.isDefined
&& cfg.config.nix.enable
&& cfg.config.nix.daemon.enable
)
"${options.containers}.${strings.escapeNixIdentifier name} has nix.daemon.enable = true, but the host does not provide a nix daemon socket, as ${hostNixSocketIsDisabled}. Disable nix.daemon.enable in the container, or enable the daemon on the host.";
in
mkMerge (mapAttrsToList mapper config.containers);
(lib.concatMap
# This could be done in mapper but causes a reformat
(map (msg: {
assertion = false;
message = msg;
}))
(lib.attrValues (lib.modules.mapAttrsOfSubmodule mapper options.containers))
);
}
(mkIf (config.boot.enableContainers) (

View File

@@ -292,6 +292,7 @@ in
aria2 = runTest ./aria2.nix;
armagetronad = runTest ./armagetronad.nix;
artalk = runTest ./artalk.nix;
asynch = runTest ./asynch.nix;
atd = runTest ./atd.nix;
atop = import ./atop.nix { inherit pkgs runTest; };
atticd = runTest ./atticd.nix;
@@ -467,10 +468,12 @@ in
containers-bridge = runTest ./containers-bridge.nix;
containers-custom-pkgs = runTest ./containers-custom-pkgs.nix;
containers-ephemeral = runTest ./containers-ephemeral.nix;
containers-eval = import ./containers-eval.nix { inherit pkgs; };
containers-extra_veth = runTest ./containers-extra_veth.nix;
containers-gateway = runTest ./containers-gateway.nix;
containers-hosts = runTest ./containers-hosts.nix;
containers-imperative = runTest ./containers-imperative.nix;
containers-imperative-no-daemon = runTest ./containers-imperative-no-daemon.nix;
containers-ip = runTest ./containers-ip.nix;
containers-ipv6-slaac = runTest ./containers-ipv6-slaac.nix;
containers-macvlans = runTest ./containers-macvlans.nix;
@@ -803,6 +806,7 @@ in
graphite = runTest ./graphite.nix;
grav = runTest ./web-apps/grav.nix;
graylog = runTest ./graylog.nix;
greenlight = runTest ./greenlight.nix;
greetd-no-shadow = runTest ./greetd-no-shadow.nix;
grocy = runTest ./grocy.nix;
grow-partition = runTest ./grow-partition.nix;

37
nixos/tests/asynch.nix Normal file
View File

@@ -0,0 +1,37 @@
{ lib, pkgs, ... }:
let
pythonEnv = pkgs.python3.withPackages (p: [
p.asynch
p.pytest
p.pytest-asyncio
p.pytest-random-order
p.pytest-mock
p.pytest-xdist
]);
in
{
name = "asynch";
meta.maintainers = [ lib.maintainers.joaosreis ];
nodes.machine =
{ ... }:
{
environment.systemPackages = [ pythonEnv ];
services.clickhouse.enable = true;
};
testScript = ''
start_all()
machine.wait_for_unit("multi-user.target")
machine.succeed("mkdir -p /build/source")
machine.succeed("cp ${pkgs.python3Packages.asynch.src}/pyproject.toml /build/source && cp -r ${pkgs.python3Packages.asynch.src}/tests /build/source/tests")
machine.wait_for_unit("clickhouse.service")
machine.succeed("cd /build/source && systemd-cat -t asynch-test ${pythonEnv.interpreter} -m pytest");
'';
}

View File

@@ -151,6 +151,8 @@
};
testScript = ''
from datetime import timedelta
start_all()
authelia.wait_for_unit("simplehttp.service")
@@ -159,14 +161,28 @@
authelia.wait_for_open_port(443)
authelia.wait_for_unit("multi-user.target")
# FIXME: Authelia currently does not notify systemd of its readiness.
# Set the service with Type=notify and remove this when the following PR is merged
# and available in a release: https://github.com/authelia/authelia/pull/12772
authelia.wait_until_succeeds(
"curl --insecure -sSf -H Host:auth.example.com https://authelia:443/",
timeout=timedelta(seconds=10)
)
with subtest("Check for authelia"):
# expect the login page
assert "Login - Authelia", "could not reach authelia" in \
authelia.succeed("curl --insecure -sSf -H Host:auth.example.com https://authelia:443/")
t.assertIn(
"<noscript>You need to enable JavaScript to run this app.</noscript>",
authelia.succeed("curl --insecure -sSf -H Host:auth.example.com https://authelia:443/"),
"Login - Authelia"
)
with subtest("Check contacting basic http server via traefik with https works"):
assert "hello", "could not reach raw static site" in \
authelia.succeed("curl --insecure -sSf -H Host:static.example.com https://authelia:443/")
t.assertIn(
"hello",
authelia.succeed("curl --insecure -sSf -H Host:static.example.com https://authelia:443/"),
"could not reach raw static site"
)
with subtest("Test traefik and authelia"):
with subtest("No details fail"):
@@ -175,7 +191,10 @@
authelia.fail("curl --insecure -sSf -u 'bob:wordpass' -H Host:static-basic-auth.example.com https://authelia:443/")
authelia.fail("curl --insecure -sSf -u 'alice:password' -H Host:static-basic-auth.example.com https://authelia:443/")
with subtest("Correct details pass"):
assert "hello", "could not reach authed static site with valid credentials" in \
authelia.succeed("curl --insecure -sSf -u 'bob:password' -H Host:static-basic-auth.example.com https://authelia:443/")
t.assertIn(
"hello",
authelia.succeed("curl --insecure -sSf -u 'bob:password' -H Host:static-basic-auth.example.com https://authelia:443/"),
"could not reach authed static site with valid credentials"
)
'';
}

View File

@@ -0,0 +1,81 @@
# Given a Nixpkgs, `assert` relevant properties of NixOS container evaluation
# that aren't exercised by the test framework, such as checking the `assertions`,
# which makes `toplevel` invalid.
#
# Run tests with:
# nix-build -A nixosTests.containers-eval
{
pkgs,
lib ? pkgs.lib,
}:
let
inherit (lib) concatMap optionals;
test = rec {
nixos =
m:
pkgs.nixos {
imports = [ m ];
boot.loader.grub.enable = false;
fileSystems."/".device = "bogus";
fileSystems."/".fsType = "bogusfs";
system.stateVersion = lib.trivial.release;
};
# we'd rather have all messages ready for display than show thunks and length mismatch
deepSeqId = a: builtins.deepSeq a a;
assertionMessages =
configuration:
deepSeqId (
concatMap (ass: optionals (!ass.assertion) [ ass.message ]) configuration.config.assertions
);
flakeContainerOnHostWithoutNix = nixos {
nix.enable = false;
containers.foo.flake = "github:NixOS/fake-repo";
# - Does not need nix for startup like flake.
# - We can't know whether it needs a socket, so we just let this pass.
# So via_path should eval without assertions.
containers.via_path.path = "/nix/var/nix/profiles/per-container/foo";
};
flakeContainerOnHostWithoutNixDaemon = nixos {
nix.daemon.enable = false;
# This should eval fine. The host needs nix, but we can't know now whether
# the specified container needs a nix daemon socket.
containers.foo.flake = "github:NixOS/fake-repo";
# This container does not disable its daemon socket, so this could be a
# problem and we should report it.
containers.bar.config = {
};
};
conflictingNetwork = nixos {
containers.foo.networkNamespace = "/foons";
containers.foo.interfaces = [ "veth67" ];
containers.foo.config = { };
};
result =
assert
assertionMessages flakeContainerOnHostWithoutNix == [
"containers.foo.flake is defined, so the container is built with nix on the host, but nix.enable is disabled"
];
assert
assertionMessages flakeContainerOnHostWithoutNixDaemon == [
"containers.bar has nix.daemon.enable = true, but the host does not provide a nix daemon socket, as host option nix.daemon.enable is disabled. Disable nix.daemon.enable in the container, or enable the daemon on the host."
];
assert
assertionMessages conflictingNetwork == [
"containers.foo.networkNamespace is mutally exclusive to containers.foo.privateNetwork and containers.foo.interfaces."
];
pkgs.emptyFile // { details = test; };
};
in
test.result

View File

@@ -0,0 +1,17 @@
{ lib, ... }: {
imports = [ ./containers-imperative.nix ];
name = lib.mkForce "containers-imperative-no-daemon";
test-nix-in-container = false;
nodes.machine =
{ config, ... }:
{
nix.daemon.enable = false;
assertions = [
# no mkForce trickery
{
assertion = !config.nix.daemon.enable;
message = "test failed: nix.daemon.enable has override";
}
];
};
}

View File

@@ -1,4 +1,9 @@
{ pkgs, lib, ... }:
test@{
config,
pkgs,
lib,
...
}:
{
name = "containers-imperative";
meta = {
@@ -6,6 +11,19 @@
aszlig
];
};
imports = [
{
options.test-nix-in-container = lib.mkOption {
type = lib.types.bool;
description = ''
Whether to test nix inside the container.
We also run this test without daemon, in which case that won't work.
Activated by `./containers-imperative-no-daemon.nix`.
'';
default = true;
};
}
];
nodes.machine =
{
@@ -131,11 +149,13 @@
with subtest("Execute commands via the root shell"):
assert "Linux" in machine.succeed(f"nixos-container run {id1} -- uname")
with subtest("Execute a nix command via the root shell. (regression test for #40355)"):
machine.succeed(
f"nixos-container run {id1} -- nix-instantiate -E "
+ '\'derivation { name = "empty"; builder = "false"; system = "false"; }\' '
)
${lib.optionalString test.config.test-nix-in-container ''
with subtest("Execute a nix command via the root shell. (regression test for #40355)"):
machine.succeed(
f"nixos-container run {id1} -- nix-instantiate -E "
+ '\'derivation { name = "empty"; builder = "false"; system = "false"; }\' '
)
''}
with subtest("Stop and start (regression test for #4989)"):
machine.succeed(f"nixos-container stop {id1}")

View File

@@ -0,0 +1,56 @@
{
lib,
pkgs,
...
}:
{
name = "greenlight";
meta = {
maintainers = [ lib.maintainers.onny ];
teams = [ lib.teams.ngi ];
};
nodes = {
greenlight = {
services.greenlight = {
enable = true;
# For local testing without SSL
settings = {
RAILS_ENV = "development";
RAILS_DUMP_SCHEMA = false;
};
};
};
};
testScript = ''
greenlight.start
greenlight.wait_for_unit("greenlight-web.service")
greenlight.wait_for_open_port(80)
greenlight.wait_for_open_port(6346)
greenlight.succeed("curl -sSfL http://greenlight:80 | grep 'BigBlueButton open source conferencing system'")
greenlight.succeed(
"greenlight-rake admin:create",
)
# grab session cookie + CSRF token
greenlight.succeed("curl -sS -c /tmp/cookies.txt http://localhost/ -o /tmp/page.html")
csrf_token = greenlight.succeed(
"grep -o 'name=\"csrf-token\" content=\"[^\"]*\"' /tmp/page.html "
"| sed 's/.*content=\"//;s/\"$//'"
).strip()
# log in with default credentials
login_result = greenlight.succeed(
f"curl -sSf -c /tmp/cookies.txt -b /tmp/cookies.txt "
f"-X POST http://localhost/api/v1/sessions.json "
f"-H 'Content-Type: application/json' -H 'Accept: application/json' "
f"-H 'X-CSRF-Token: {csrf_token}' "
f"-d '{{\"session\":{{\"email\":\"admin@example.com\",\"password\":\"Administrator1!\"}}}}'"
)
assert '"signed_in":true' in login_result, f"login failed: {login_result}"
'';
}

View File

@@ -48,6 +48,19 @@
virtualisation.diskSize = 3 * 1024;
};
machineWithQsvTranscoding = {
services.jellyfin = {
enable = true;
hardwareAcceleration = {
enable = true;
type = "qsv";
device = "/dev/dri/renderD128";
};
};
environment.systemPackages = with pkgs; [ ffmpeg ];
virtualisation.diskSize = 3 * 1024;
};
machineWithForceConfig = {
services.jellyfin = {
enable = true;
@@ -186,6 +199,31 @@
assert "hevc" in decoding_codecs, f"hevc should be in HardwareDecodingCodecs, got {decoding_codecs}"
assert "vp9" in decoding_codecs, f"vp9 should be in HardwareDecodingCodecs, got {decoding_codecs}"
# Regression test: the qsv branch used to write the device path to a
# nonexistent <OpenclDevice> XML element, which Jellyfin silently
# ignores, instead of <QsvDevice> (see MediaBrowser.Model/Configuration/
# EncodingOptions.cs upstream, which has no OpenclDevice property).
with subtest("QSV hardware acceleration configuration"):
wait_for_jellyfin(machineWithQsvTranscoding)
machineWithQsvTranscoding.succeed("systemctl show jellyfin.service --property=DeviceAllow | grep '/dev/dri/renderD128 rw'")
machineWithQsvTranscoding.wait_until_succeeds(api_get("/Startup/Configuration"))
machineWithQsvTranscoding.succeed(api_get("/Startup/FirstUser"))
machineWithQsvTranscoding.succeed(api_post("/Startup/Complete"))
qsv_auth_result = json.loads(machineWithQsvTranscoding.succeed(
api_post("/Users/AuthenticateByName", "${payloads.auth}")
))
qsv_token = qsv_auth_result["AccessToken"]
qsv_config = json.loads(machineWithQsvTranscoding.succeed(
f"curl --fail 'http://localhost:8096/System/Configuration/encoding' -H 'Authorization:MediaBrowser Client=\"Test\", DeviceId=\"test\", Token={qsv_token}'"
))
assert qsv_config.get("HardwareAccelerationType") == "qsv", f"Hardware acceleration type: expected 'qsv', got '{qsv_config.get('HardwareAccelerationType')}'"
assert qsv_config.get("QsvDevice") == "/dev/dri/renderD128", f"QSV device: expected '/dev/dri/renderD128', got '{qsv_config.get('QsvDevice')}'"
with machine.nested("Wizard completes"):
machine.wait_until_succeeds(api_get("/Startup/Configuration"))

View File

@@ -742,11 +742,11 @@
"vendorHash": null
},
"ibm-cloud_ibm": {
"hash": "sha256-pTwgU5uf44MHAMOZ/vEWp4rKv6tfVca7U6B0dQRsjCc=",
"hash": "sha256-pY89jjLeGTRmF9IGRckr3HmMXvXrzdGNWqmXI2bMoxU=",
"homepage": "https://registry.terraform.io/providers/IBM-Cloud/ibm",
"owner": "IBM-Cloud",
"repo": "terraform-provider-ibm",
"rev": "v2.6.1",
"rev": "v2.6.2",
"spdx": "MPL-2.0",
"vendorHash": "sha256-+M87BX2FBbqL1AGCIE9uk5E6ySjYLIIxc+E5GYYDODo="
},

View File

@@ -8,18 +8,18 @@
}:
buildGoModule (finalAttrs: {
pname = "asdf-vm";
version = "0.20.0";
version = "0.20.1";
src = fetchFromGitHub {
owner = "asdf-vm";
repo = "asdf";
tag = "v${finalAttrs.version}";
hash = "sha256-qq1HJidVBqHyfk2OZ439fnkJKRq1xglqOrF3GVvWeXY=";
hash = "sha256-UbD8z5jIZTLfQLEruprLqJx4eoTJi4fFCMWUvIPDjOs=";
};
vendorHash = "sha256-Rv5p63opBTlyRlRDisgYX5fVJFny1clDn7b/zumV83M=";
vendorHash = "sha256-ompvvNzfJetcKCRueJxXALiN0rOQwSiytTHJcVXFEOo=";
nativeBuildInputs = [
makeWrapper

View File

@@ -4,7 +4,7 @@
nodejs,
fetchPnpmDeps,
pnpmConfigHook,
pnpm_11,
pnpm_12,
fetchFromGitHub,
buildGo127Module,
installShellFiles,
@@ -15,7 +15,7 @@
nodejs
fetchPnpmDeps
pnpmConfigHook
pnpm_11
pnpm_12
fetchFromGitHub
;
},

View File

@@ -1,14 +1,14 @@
{ fetchFromGitHub }:
rec {
pname = "authelia";
version = "4.39.22";
version = "4.39.27";
src = fetchFromGitHub {
owner = "authelia";
repo = "authelia";
rev = "v${version}";
hash = "sha256-6mKS+U0Leac2vcHRTMIAKfqr78NQUCMBiW76z4H/STw=";
hash = "sha256-lN8KH3JvL1s1q6crlHzGt43v278VUpvuUF+IVfW5m60=";
};
vendorHash = "sha256-8ftsYIEMkoM3emW0d6E3cOv3hUQDLZcSBDEy8NvwNcY=";
pnpmDepsHash = "sha256-ngHVlFIQuUY+D54CDZ7FIlu13UjGr3zcdTvKryntVhQ=";
vendorHash = "sha256-Bi3cAkcVP1ZWFBuy0RfpqW7yqyV5DxSsa6gmtfLgxEA=";
pnpmDepsHash = "sha256-uX7+TtZSiVheK7JoZ3mhX2/vcddPezgQ0vY22NF7gNI=";
}

View File

@@ -3,12 +3,12 @@
nodejs,
fetchPnpmDeps,
pnpmConfigHook,
pnpm_11,
pnpm_12,
fetchFromGitHub,
}:
let
pnpm = pnpm_11;
pnpm = pnpm_12;
inherit (import ./sources.nix { inherit fetchFromGitHub; })
pname

View File

@@ -31,14 +31,14 @@
}:
stdenv.mkDerivation (finalAttrs: {
version = "4.10.0";
version = "4.11.0";
pname = "baresip";
src = fetchFromGitHub {
owner = "baresip";
repo = "baresip";
rev = "v${finalAttrs.version}";
hash = "sha256-EUnMcRvSvQoCgVmDVPjtfeppUiheVU2xD49D9hZbGb4=";
hash = "sha256-GMR1XteY8IjbebRzD4FxCRqbrwP3kPbV8oW/+L85eLs=";
};
patches = [

View File

@@ -6,16 +6,16 @@
buildGoModule (finalAttrs: {
pname = "bazel-buildtools";
version = "8.5.1";
version = "10.0.1";
src = fetchFromGitHub {
owner = "bazelbuild";
repo = "buildtools";
rev = "v${finalAttrs.version}";
hash = "sha256-ykfdajj9KpP9+j0uePYCRf7TDpb1GbGAiR6bI++jslg=";
hash = "sha256-SX/QeVsAn3yqovmjAo6NDFyfetNpRxb/C72zqWwCbaE=";
};
vendorHash = "sha256-sYZ7ogQY0dWOwJMvLljOjaKeYGYdLrF5AnetregdlYY=";
vendorHash = "sha256-bUvWtQ0DCdAQRETyPJ6gp4qlaPowlpO5l3GHFaEcH94=";
preBuild = ''
rm -r warn/docs

View File

@@ -6,11 +6,11 @@
stdenvNoCC.mkDerivation (finalAttrs: {
pname = "chromium-hsts-preload-list";
version = "155.0.8053.3";
version = "156.0.8068.1";
src = fetchurl {
url = "https://raw.github.com/chromium/chromium/${finalAttrs.version}/net/http/transport_security_state_static.json";
hash = "sha256-GIC2O/GOHi7MpYKiLYlmiLHwh1nzvdCHcUSb3fC18I4=";
hash = "sha256-IqKm5y6lcbqA7EeP2pDGX8+tVLHSs/gBUAi8PIuIydY=";
};
dontUnpack = true;

View File

@@ -10,22 +10,22 @@ let
inherit (stdenv) hostPlatform;
sources = {
x86_64-linux = fetchurl {
url = "https://downloads.cursor.com/lab/2026.08.31-4057e58/linux/x64/agent-cli-package.tar.gz";
hash = "sha256-fjBttXUCGamcAO1Rf+iyNdPFTkyl934v8WDMl85wd5g=";
url = "https://downloads.cursor.com/lab/2026.09.10-fd3934a/linux/x64/agent-cli-package.tar.gz";
hash = "sha256-J5l8g5GthTpacysYRduO+CqLpq+w94KcxzlGT4lm6W4=";
};
aarch64-linux = fetchurl {
url = "https://downloads.cursor.com/lab/2026.08.31-4057e58/linux/arm64/agent-cli-package.tar.gz";
hash = "sha256-z122tQR7MoDYpJRxz9Qb6x1eR1d0F3313yhRhXq2UUo=";
url = "https://downloads.cursor.com/lab/2026.09.10-fd3934a/linux/arm64/agent-cli-package.tar.gz";
hash = "sha256-4ElEOLAcN7w0hISR0fNHjvRpSUxWyvAg3hF5bRRttko=";
};
aarch64-darwin = fetchurl {
url = "https://downloads.cursor.com/lab/2026.08.31-4057e58/darwin/arm64/agent-cli-package.tar.gz";
hash = "sha256-qUSDz1oWB7/hLLNCFr4Mj5WJnw9pj7heUAuijXMy+7A=";
url = "https://downloads.cursor.com/lab/2026.09.10-fd3934a/darwin/arm64/agent-cli-package.tar.gz";
hash = "sha256-rsCwGuBW3kigL+MV+/BYDrkTd3UtmTMHSZmIy+AoVCM=";
};
};
in
stdenv.mkDerivation {
pname = "cursor-cli";
version = "0-unstable-2026-08-31";
version = "0-unstable-2026-09-10";
src = sources.${hostPlatform.system};

View File

@@ -2,7 +2,6 @@
lib,
buildNpmPackage,
fetchFromGitHub,
fetchpatch2,
jre_headless,
protobuf_30,
xmlstarlet,
@@ -13,7 +12,7 @@
nixosTests,
}:
let
version = "4.14.2";
version = "4.14.4";
frontend = buildNpmPackage {
pname = "dependency-track-frontend";
@@ -23,7 +22,7 @@ let
owner = "DependencyTrack";
repo = "frontend";
tag = version;
hash = "sha256-/MH1YjEJdRjYjenkzOcp7oytudsJcinPbc9OAGFnI/Q=";
hash = "sha256-Zt6KBqR3CstS/RqqJAVJaGkgpzf835UcblrE/8gzUWE=";
};
installPhase = ''
@@ -31,14 +30,7 @@ let
cp -R ./dist $out/
'';
patches = [
(fetchpatch2 {
url = "https://github.com/DependencyTrack/frontend/pull/1575.patch?full_index=1";
hash = "sha256-Wo+6yXa/8jB/pph0DTNsFz6lK3sedvro+7yvLSKes9c=";
})
];
npmDepsHash = "sha256-md+PGEC1/Kl2MQhhYldSErcsDSefbPvwVDsw0Yklq1E=";
npmDepsHash = "sha256-NQY3bg3cwyIt/ing8RBOFNd3+02hzVwYcj0RXi350xk=";
forceGitDeps = true;
makeCacheWritable = true;
@@ -55,7 +47,7 @@ maven.buildMavenPackage rec {
owner = "DependencyTrack";
repo = "dependency-track";
tag = version;
hash = "sha256-9EPjIm2VOmt1FEiPoJtwNHoKZcewO0kJgBSc9fnUXeI=";
hash = "sha256-tHtM5xqD7EG3CyZtaL6qsHEAa+5AstcIYRes+hIFyKk=";
};
postPatch = ''
@@ -88,15 +80,15 @@ maven.buildMavenPackage rec {
'';
mvnJdk = jre_headless;
mvnHash = "sha256-pshUDIPPGGGzxg5WJXC3mjnqGXn8HVowFCb2l5f6zjA=";
mvnHash = "sha256-903EuablhywF/2N8k8ISHOnSyZrSJ1LKC9Lx4USO0z8=";
manualMvnArtifacts = [
"com.coderplus.maven.plugins:copy-rename-maven-plugin:1.0.1"
# added to saticfy protobuf compiler plugin dependency resolving
"jakarta.el:jakarta.el-api:5.0.1"
"com.fasterxml.jackson.module:jackson-module-jakarta-xmlbind-annotations:2.19.1"
"com.fasterxml.jackson.dataformat:jackson-dataformat-xml:2.21.0"
"com.fasterxml.jackson.dataformat:jackson-dataformat-yaml:2.18.3"
"com.fasterxml.jackson.datatype:jackson-datatype-jsr310:2.21.2"
"com.fasterxml.jackson.dataformat:jackson-dataformat-xml:2.22.2"
"com.fasterxml.jackson.dataformat:jackson-dataformat-yaml:2.18.4"
"com.fasterxml.jackson.datatype:jackson-datatype-jsr310:2.22.1"
"io.micrometer:micrometer-core:1.16.0"
"io.micrometer:micrometer-observation:1.16.0"
];

View File

@@ -8,16 +8,16 @@
buildGoModule (finalAttrs: {
pname = "ejsonkms";
version = "0.3.3";
version = "0.3.4";
src = fetchFromGitHub {
owner = "envato";
repo = "ejsonkms";
rev = "v${finalAttrs.version}";
hash = "sha256-PoFRKnh9XMXOPn2kj9UCzO0ahom+c4bSvxszNQ941L0=";
hash = "sha256-uvTIyc3z8rpculfmiV8ojQ5K70R5cwP7IQPrM5teSQQ=";
};
vendorHash = "sha256-GHLS5fQo65vS0uEo0xTC9oiznmwW27wvu7TYl0BjqR4=";
vendorHash = "sha256-RXzZ+5CqVBcGAYB/IiPG8Mu4fUAgE0xr1UUVMqWTwEw=";
ldflags = [
"-X main.version=v${finalAttrs.version}"

View File

@@ -123,7 +123,6 @@ buildNpmPackage (finalAttrs: {
];
};
maintainers = with lib.maintainers; [
brantes
xiaoxiangmoe
caverav
];

View File

@@ -8,16 +8,16 @@
buildGoModule (finalAttrs: {
pname = "go-enum";
version = "0.9.4";
version = "0.9.5";
src = fetchFromGitHub {
owner = "abice";
repo = "go-enum";
tag = "v${finalAttrs.version}";
hash = "sha256-fFMTnbQ6RUGxvANHveB1YrXlppgUVTJIRB4v1sV3GH8=";
hash = "sha256-pEBx5292R8X06TLpv8kboNafiEfq9NWXvUoVVVQ0DVg=";
};
vendorHash = "sha256-hGfwb0GZCxc3EQWvxs7/fNVEVGGQE2I0B+MMaH7ecPM=";
vendorHash = "sha256-NK4IeOmpzioo7c9PrncgwhCsIyt31sMnkv7qjuJbREo=";
__structuredAttrs = true;

View File

@@ -10,13 +10,13 @@
buildGoModule (finalAttrs: {
pname = "gotify-server";
version = "3.1.0";
version = "3.1.1";
src = fetchFromGitHub {
owner = "gotify";
repo = "server";
tag = "v${finalAttrs.version}";
hash = "sha256-s3oU6mEvhbguLHcLUaavDlR44EX7sDnd0SxrtbMCeyI=";
hash = "sha256-x3LbIrw+co2sY+VQAT/0Q6oQd1i17d3z2bGdH8wVg70=";
};
vendorHash = "sha256-ERRPIRZFhJN+QKEwBbZVUKTaTOLrlC+cb8yQNGHgMxg=";

View File

@@ -16,7 +16,7 @@ stdenv.mkDerivation (finalAttrs: {
yarnOfflineCache = fetchYarnDeps {
yarnLock = "${finalAttrs.src}/yarn.lock";
hash = "sha256-PUO8HWTjtZfzWtLkDa827HoRx0LBxxO11My3mhito+I=";
hash = "sha256-zyPNIrTw5YUOZnuYuD1UTw7Pjy8nDWQwbH5IZXICF0I=";
};
nativeBuildInputs = [

View File

@@ -1,6 +1,7 @@
{
buildDotnetModule,
fetchFromGitLab,
fetchurl,
dotnetCorePackages,
lib,
ffmpeg,
@@ -44,18 +45,23 @@
_experimental-update-script-combinators,
grayjay-frontend,
grayjay-libcurlshim,
unzip,
}:
let
version = "17";
version = "18";
src = fetchFromGitLab {
domain = "gitlab.futo.org";
owner = "videostreaming";
repo = "Grayjay.Desktop";
tag = version;
hash = "sha256-/oeoLXKewjYkCO7naZNOzauWm1OYDKnsxXY9EkI7fTM=";
hash = "sha256-dhXUjj9x8v1bfHLPxNtcysj/eKeT3kkSeVuX6PKoykE=";
fetchSubmodules = true;
fetchLFS = true;
};
justcefNative = fetchurl {
url = "https://static.grayjay.app/justcef/1/JustCefNative-linux-x64.zip";
hash = "sha256-LXOp+QZZcWBd8eP+BpK++AMBo9303+aIDEEYNVWekhE=";
};
getLibrary =
pkg: libnm:
"${lib.getLib pkg}/lib/lib${libnm}${pkg.drvAttrs.stdenv.hostPlatform.extensions.sharedLibrary}";
@@ -88,6 +94,7 @@ buildDotnetModule (finalAttrs: {
autoPatchelfHook
wrapGAppsHook3
copyDesktopItems
unzip
];
dontWrapGApps = true;
@@ -108,7 +115,7 @@ buildDotnetModule (finalAttrs: {
"Grayjay.Engine/Grayjay.Engine/Grayjay.Engine.csproj"
"Grayjay.Desktop.CEF/Grayjay.Desktop.CEF.csproj"
"FUTO.MDNS/FUTO.MDNS/FUTO.MDNS.csproj"
"JustCef/DotCef.csproj"
"JustCef/JustCef.csproj"
];
testProjectFile = [
@@ -134,6 +141,10 @@ buildDotnetModule (finalAttrs: {
preBuild = ''
rm -r Grayjay.ClientServer/wwwroot/web
cp -r ${grayjay-frontend} Grayjay.ClientServer/wwwroot/web
mkdir -p JustCef/obj/justcef/net8.0/1/linux-x64
cp ${justcefNative} \
JustCef/obj/justcef/net8.0/1/linux-x64/JustCefNative-linux-x64.zip
'';
postInstall = ''
@@ -148,8 +159,8 @@ buildDotnetModule (finalAttrs: {
ln -s ${getLibrary libsodium "sodium"} $out/lib/grayjay/libsodium.so
ln -s ${getLibrary sqlite "sqlite3"} $out/lib/grayjay/libe_sqlite3.so
# CEF is still vendored for now
chmod +x $out/lib/grayjay/cef/dotcefnative
# Explicitly fetched and copied over in preBuild
chmod +x $out/lib/grayjay/cef/justcefnative
mkdir -p $out/share/icons/hicolor/scalable/apps
ln -s $out/lib/grayjay/grayjay.png $out/share/icons/hicolor/scalable/apps/grayjay.png

583
pkgs/by-name/gr/greenlight/Gemfile.lock generated Normal file
View File

@@ -0,0 +1,583 @@
GEM
remote: https://rubygems.org/
specs:
actioncable (7.2.3.1)
actionpack (= 7.2.3.1)
activesupport (= 7.2.3.1)
nio4r (~> 2.0)
websocket-driver (>= 0.6.1)
zeitwerk (~> 2.6)
actionmailbox (7.2.3.1)
actionpack (= 7.2.3.1)
activejob (= 7.2.3.1)
activerecord (= 7.2.3.1)
activestorage (= 7.2.3.1)
activesupport (= 7.2.3.1)
mail (>= 2.8.0)
actionmailer (7.2.3.1)
actionpack (= 7.2.3.1)
actionview (= 7.2.3.1)
activejob (= 7.2.3.1)
activesupport (= 7.2.3.1)
mail (>= 2.8.0)
rails-dom-testing (~> 2.2)
actionpack (7.2.3.1)
actionview (= 7.2.3.1)
activesupport (= 7.2.3.1)
cgi
nokogiri (>= 1.8.5)
racc
rack (>= 2.2.4, < 3.3)
rack-session (>= 1.0.1)
rack-test (>= 0.6.3)
rails-dom-testing (~> 2.2)
rails-html-sanitizer (~> 1.6)
useragent (~> 0.16)
actiontext (7.2.3.1)
actionpack (= 7.2.3.1)
activerecord (= 7.2.3.1)
activestorage (= 7.2.3.1)
activesupport (= 7.2.3.1)
globalid (>= 0.6.0)
nokogiri (>= 1.8.5)
actionview (7.2.3.1)
activesupport (= 7.2.3.1)
builder (~> 3.1)
cgi
erubi (~> 1.11)
rails-dom-testing (~> 2.2)
rails-html-sanitizer (~> 1.6)
active_model_serializers (0.10.15)
actionpack (>= 4.1)
activemodel (>= 4.1)
case_transform (>= 0.2)
jsonapi-renderer (>= 0.1.1.beta1, < 0.3)
active_storage_validations (3.0.2)
activejob (>= 6.1.4)
activemodel (>= 6.1.4)
activestorage (>= 6.1.4)
activesupport (>= 6.1.4)
marcel (>= 1.0.3)
activejob (7.2.3.1)
activesupport (= 7.2.3.1)
globalid (>= 0.3.6)
activemodel (7.2.3.1)
activesupport (= 7.2.3.1)
activerecord (7.2.3.1)
activemodel (= 7.2.3.1)
activesupport (= 7.2.3.1)
timeout (>= 0.4.0)
activestorage (7.2.3.1)
actionpack (= 7.2.3.1)
activejob (= 7.2.3.1)
activerecord (= 7.2.3.1)
activesupport (= 7.2.3.1)
marcel (~> 1.0)
activesupport (7.2.3.1)
base64
benchmark (>= 0.3)
bigdecimal
concurrent-ruby (~> 1.0, >= 1.3.1)
connection_pool (>= 2.2.5)
drb
i18n (>= 1.6, < 2)
logger (>= 1.4.2)
minitest (>= 5.1, < 6)
securerandom (>= 0.3)
tzinfo (~> 2.0, >= 2.0.5)
addressable (2.9.0)
public_suffix (>= 2.0.2, < 8.0)
aes_key_wrap (1.1.0)
ast (2.4.3)
attr_required (1.0.2)
aws-eventstream (1.4.0)
aws-partitions (1.1196.0)
aws-sdk-core (3.240.0)
aws-eventstream (~> 1, >= 1.3.0)
aws-partitions (~> 1, >= 1.992.0)
aws-sigv4 (~> 1.9)
base64
bigdecimal
jmespath (~> 1, >= 1.6.1)
logger
aws-sdk-kms (1.118.0)
aws-sdk-core (~> 3, >= 3.239.1)
aws-sigv4 (~> 1.5)
aws-sdk-s3 (1.208.0)
aws-sdk-core (~> 3, >= 3.234.0)
aws-sdk-kms (~> 1)
aws-sigv4 (~> 1.5)
aws-sigv4 (1.12.1)
aws-eventstream (~> 1, >= 1.0.2)
base64 (0.3.0)
bcrypt (3.1.22)
benchmark (0.5.0)
bigbluebutton-api-ruby (2.0.0)
base64 (>= 0.1.0)
xml-simple (~> 1.1)
bigdecimal (4.1.1)
bindata (2.5.1)
bindex (0.8.1)
bootsnap (1.16.0)
msgpack (~> 1.2)
builder (3.3.0)
capybara (3.40.0)
addressable
matrix
mini_mime (>= 0.1.3)
nokogiri (~> 1.11)
rack (>= 1.6.0)
rack-test (>= 0.6.3)
regexp_parser (>= 1.5, < 3.0)
xpath (~> 3.2)
case_transform (0.2)
activesupport
cgi (0.5.1)
clamby (1.6.10)
concurrent-ruby (1.3.7)
connection_pool (2.5.5)
crack (1.0.0)
bigdecimal
rexml
crass (1.0.6)
cssbundling-rails (1.4.3)
railties (>= 6.0.0)
data_migrate (11.3.1)
activerecord (>= 6.1)
railties (>= 6.1)
date (3.5.1)
debug (1.11.0)
irb (~> 1.10)
reline (>= 0.3.8)
declarative (0.0.20)
diff-lcs (1.6.2)
digest-crc (0.7.0)
rake (>= 12.0.0, < 14.0.0)
dotenv (3.2.0)
dotenv-rails (3.2.0)
dotenv (= 3.2.0)
railties (>= 6.1)
drb (2.2.3)
email_validator (2.2.4)
activemodel
erb (6.0.1.1)
erubi (1.13.1)
factory_bot (6.5.6)
activesupport (>= 6.1.0)
factory_bot_rails (6.5.1)
factory_bot (~> 6.5)
railties (>= 6.1.0)
faker (3.1.1)
i18n (>= 1.8.11, < 2)
faraday (2.14.3)
faraday-net_http (>= 2.0, < 3.5)
json
logger
faraday-follow_redirects (0.4.0)
faraday (>= 1, < 3)
faraday-net_http (3.4.4)
net-http (~> 0.5)
ffi (1.17.2)
globalid (1.3.0)
activesupport (>= 6.1)
google-apis-core (1.0.2)
addressable (~> 2.8, >= 2.8.7)
faraday (~> 2.13)
faraday-follow_redirects (~> 0.3)
googleauth (~> 1.14)
mini_mime (~> 1.1)
representable (~> 3.0)
retriable (~> 3.1)
google-apis-iamcredentials_v1 (0.26.0)
google-apis-core (>= 0.15.0, < 2.a)
google-apis-storage_v1 (0.60.0)
google-apis-core (>= 0.15.0, < 2.a)
google-cloud-core (1.8.0)
google-cloud-env (>= 1.0, < 3.a)
google-cloud-errors (~> 1.0)
google-cloud-env (2.3.1)
base64 (~> 0.2)
faraday (>= 1.0, < 3.a)
google-cloud-errors (1.5.0)
google-cloud-storage (1.58.0)
addressable (~> 2.8)
digest-crc (~> 0.4)
google-apis-core (>= 0.18, < 2)
google-apis-iamcredentials_v1 (~> 0.18)
google-apis-storage_v1 (>= 0.42)
google-cloud-core (~> 1.6)
googleauth (~> 1.9)
mini_mime (~> 1.0)
google-logging-utils (0.2.0)
googleauth (1.16.1)
faraday (>= 1.0, < 3.a)
google-cloud-env (~> 2.2)
google-logging-utils (~> 0.1)
jwt (>= 1.4, < 4.0)
multi_json (~> 1.11)
os (>= 0.9, < 2.0)
signet (>= 0.16, < 2.a)
hashdiff (1.1.2)
hashie (5.0.0)
hcaptcha (7.1.0)
json
i18n (1.14.8)
concurrent-ruby (~> 1.0)
i18n-language-mapping (0.1.3.1)
image_processing (1.12.2)
mini_magick (>= 4.9.5, < 5)
ruby-vips (>= 2.0.17, < 3)
io-console (0.8.1)
irb (1.15.3)
pp (>= 0.6.0)
rdoc (>= 4.0.0)
reline (>= 0.4.2)
jbuilder (2.13.0)
actionview (>= 5.0.0)
activesupport (>= 5.0.0)
jmespath (1.6.2)
jsbundling-rails (1.3.1)
railties (>= 6.0.0)
json (2.19.9)
json-jwt (1.17.0)
activesupport (>= 4.2)
aes_key_wrap
base64
bindata
faraday (~> 2.0)
faraday-follow_redirects
jsonapi-renderer (0.2.2)
jwt (3.2.0)
base64
language_server-protocol (3.17.0.5)
lint_roller (1.1.0)
logger (1.7.0)
lograge (0.14.0)
actionpack (>= 4)
activesupport (>= 4)
railties (>= 4)
request_store (~> 1.0)
loofah (2.25.1)
crass (~> 1.0.2)
nokogiri (>= 1.12.0)
mail (2.9.0)
logger
mini_mime (>= 0.1.1)
net-imap
net-pop
net-smtp
marcel (1.1.0)
matrix (0.4.3)
mini_magick (4.12.0)
mini_mime (1.1.5)
mini_portile2 (2.8.9)
minitest (5.27.0)
msgpack (1.6.0)
multi_json (1.19.1)
net-http (0.9.1)
uri (>= 0.11.1)
net-imap (0.5.15)
date
net-protocol
net-pop (0.1.2)
net-protocol
net-protocol (0.2.2)
timeout
net-smtp (0.5.1)
net-protocol
nio4r (2.7.5)
nkf (0.2.0)
nokogiri (1.19.4)
mini_portile2 (~> 2.8.2)
racc (~> 1.4)
omniauth (2.1.4)
hashie (>= 3.4.6)
logger
rack (>= 2.2.3)
rack-protection
omniauth-rails_csrf_protection (2.0.0)
actionpack (>= 4.2)
omniauth (~> 2.0)
omniauth_openid_connect (0.8.0)
omniauth (>= 1.9, < 3)
openid_connect (~> 2.2)
openid_connect (2.3.1)
activemodel
attr_required (>= 1.0.0)
email_validator
faraday (~> 2.0)
faraday-follow_redirects
json-jwt (>= 1.16)
mail
rack-oauth2 (~> 2.2)
swd (~> 2.0)
tzinfo
validate_url
webfinger (~> 2.0)
os (1.1.4)
pagy (6.0.4)
parallel (1.27.0)
parser (3.3.10.0)
ast (~> 2.4.1)
racc
pg (1.4.5)
pp (0.6.3)
prettyprint
prettyprint (0.2.0)
prism (1.6.0)
psych (5.2.6)
date
stringio
public_suffix (7.0.5)
puma (7.2.1)
nio4r (~> 2.0)
racc (1.8.1)
rack (3.2.6)
rack-oauth2 (2.3.0)
activesupport
attr_required
faraday (~> 2.0)
faraday-follow_redirects
json-jwt (>= 1.11.0)
rack (>= 2.1.0)
rack-protection (4.2.1)
base64 (>= 0.1.0)
logger (>= 1.6.0)
rack (>= 3.0.0, < 4)
rack-session (2.1.2)
base64 (>= 0.1.0)
rack (>= 3.0.0)
rack-test (2.2.0)
rack (>= 1.3)
rackup (2.2.1)
rack (>= 3)
rails (7.2.3.1)
actioncable (= 7.2.3.1)
actionmailbox (= 7.2.3.1)
actionmailer (= 7.2.3.1)
actionpack (= 7.2.3.1)
actiontext (= 7.2.3.1)
actionview (= 7.2.3.1)
activejob (= 7.2.3.1)
activemodel (= 7.2.3.1)
activerecord (= 7.2.3.1)
activestorage (= 7.2.3.1)
activesupport (= 7.2.3.1)
bundler (>= 1.15.0)
railties (= 7.2.3.1)
rails-dom-testing (2.3.0)
activesupport (>= 5.0.0)
minitest
nokogiri (>= 1.6)
rails-html-sanitizer (1.7.0)
loofah (~> 2.25)
nokogiri (>= 1.15.7, != 1.16.7, != 1.16.6, != 1.16.5, != 1.16.4, != 1.16.3, != 1.16.2, != 1.16.1, != 1.16.0.rc1, != 1.16.0)
railties (7.2.3.1)
actionpack (= 7.2.3.1)
activesupport (= 7.2.3.1)
cgi
irb (~> 1.13)
rackup (>= 1.0.0)
rake (>= 12.2)
thor (~> 1.0, >= 1.2.2)
tsort (>= 0.2)
zeitwerk (~> 2.6)
rainbow (3.1.1)
rake (13.3.1)
rdoc (6.16.1)
erb
psych (>= 4.0.0)
tsort
redis (4.8.0)
regexp_parser (2.11.3)
reline (0.6.3)
io-console (~> 0.5)
remote_syslog_logger (1.0.4)
syslog_protocol
representable (3.2.0)
declarative (< 0.1.0)
trailblazer-option (>= 0.1.1, < 0.2.0)
uber (< 0.2.0)
request_store (1.5.1)
rack (>= 1.4)
retriable (3.1.2)
rexml (3.4.4)
rspec-core (3.13.6)
rspec-support (~> 3.13.0)
rspec-expectations (3.13.5)
diff-lcs (>= 1.2.0, < 2.0)
rspec-support (~> 3.13.0)
rspec-mocks (3.13.7)
diff-lcs (>= 1.2.0, < 2.0)
rspec-support (~> 3.13.0)
rspec-rails (7.1.1)
actionpack (>= 7.0)
activesupport (>= 7.0)
railties (>= 7.0)
rspec-core (~> 3.13)
rspec-expectations (~> 3.13)
rspec-mocks (~> 3.13)
rspec-support (~> 3.13)
rspec-support (3.13.6)
rubocop (1.81.7)
json (~> 2.3)
language_server-protocol (~> 3.17.0.2)
lint_roller (~> 1.1.0)
parallel (~> 1.10)
parser (>= 3.3.0.2)
rainbow (>= 2.2.2, < 4.0)
regexp_parser (>= 2.9.3, < 3.0)
rubocop-ast (>= 1.47.1, < 2.0)
ruby-progressbar (~> 1.7)
unicode-display_width (>= 2.4.0, < 4.0)
rubocop-ast (1.48.0)
parser (>= 3.3.7.2)
prism (~> 1.4)
rubocop-capybara (2.19.0)
rubocop (~> 1.41)
rubocop-factory_bot (2.24.0)
rubocop (~> 1.33)
rubocop-performance (1.16.0)
rubocop (>= 1.7.0, < 2.0)
rubocop-ast (>= 0.4.0)
rubocop-rails (2.34.2)
activesupport (>= 4.2.0)
lint_roller (~> 1.1)
rack (>= 1.1)
rubocop (>= 1.75.0, < 2.0)
rubocop-ast (>= 1.44.0, < 2.0)
rubocop-rspec (2.9.0)
rubocop (~> 1.19)
ruby-progressbar (1.13.0)
ruby-vips (2.1.4)
ffi (~> 1.12)
rubyzip (2.4.1)
securerandom (0.4.1)
selenium-webdriver (4.8.0)
rexml (~> 3.2, >= 3.2.5)
rubyzip (>= 1.2.2, < 3.0)
websocket (~> 1.0)
shoulda-matchers (5.3.0)
activesupport (>= 5.2.0)
signet (0.21.0)
addressable (~> 2.8)
faraday (>= 0.17.5, < 3.a)
jwt (>= 1.5, < 4.0)
multi_json (~> 1.10)
sprockets (4.2.2)
concurrent-ruby (~> 1.0)
logger
rack (>= 2.2.4, < 4)
sprockets-rails (3.5.2)
actionpack (>= 6.1)
activesupport (>= 6.1)
sprockets (>= 3.0.0)
stringio (3.1.9)
swd (2.0.3)
activesupport (>= 3)
attr_required (>= 0.0.5)
faraday (~> 2.0)
faraday-follow_redirects
syslog_protocol (0.9.2)
thor (1.4.0)
timeout (0.6.1)
trailblazer-option (0.1.2)
tsort (0.2.0)
tzinfo (2.0.6)
concurrent-ruby (~> 1.0)
uber (0.1.0)
unicode-display_width (3.2.0)
unicode-emoji (~> 4.1)
unicode-emoji (4.1.0)
uri (1.1.1)
useragent (0.16.11)
validate_url (1.0.15)
activemodel (>= 3.0.0)
public_suffix
web-console (4.2.1)
actionview (>= 6.0.0)
activemodel (>= 6.0.0)
bindex (>= 0.4.0)
railties (>= 6.0.0)
webdrivers (5.2.0)
nokogiri (~> 1.6)
rubyzip (>= 1.3.0)
selenium-webdriver (~> 4.0)
webfinger (2.1.3)
activesupport
faraday (~> 2.0)
faraday-follow_redirects
webmock (3.24.0)
addressable (>= 2.8.0)
crack (>= 0.3.2)
hashdiff (>= 0.4.0, < 2.0.0)
websocket (1.2.9)
websocket-driver (0.8.1)
base64
websocket-extensions (>= 0.1.0)
websocket-extensions (0.1.5)
xml-simple (1.1.9)
rexml
xpath (3.2.0)
nokogiri (~> 1.8)
zeitwerk (2.7.3)
PLATFORMS
ruby
DEPENDENCIES
active_model_serializers (>= 0.10.15)
active_storage_validations (>= 1.4.0)
aws-sdk-s3
bcrypt (~> 3.1.22)
bigbluebutton-api-ruby (= 2.0.0)
bootsnap
capybara (>= 3.39.0)
clamby (~> 1.6.10)
connection_pool (~> 2.4)
cssbundling-rails (>= 1.4.0)
data_migrate (>= 11.3.0)
debug
dotenv-rails (>= 3.0.0)
factory_bot (>= 6.4.1)
factory_bot_rails (>= 6.4.4)
faker
google-cloud-storage (~> 1.45, >= 1.45.0)
hcaptcha
i18n-language-mapping
image_processing (~> 1.2)
jbuilder (>= 2.12)
jsbundling-rails (>= 1.3.0)
jwt
lograge (~> 0.14.0)
mini_magick (>= 4.9.5)
nkf (~> 0.2.0)
omniauth (~> 2.1.3)
omniauth-rails_csrf_protection (~> 2.0.0)
omniauth_openid_connect (>= 0.8.0)
pagy (~> 6.0, >= 6.0.0)
pg
puma (~> 7.2)
rails (~> 7.2.3)
redis (~> 4.8.0)
remote_syslog_logger
rspec-rails (~> 7.1, >= 7.1.1)
rubocop (~> 1.26)
rubocop-capybara (~> 2.19.0)
rubocop-factory_bot (~> 2.24.0)
rubocop-performance (~> 1.13)
rubocop-rails (~> 2.21, >= 2.21.0)
rubocop-rspec (~> 2.9.0)
selenium-webdriver
shoulda-matchers (~> 5.0)
sprockets-rails (>= 3.5.1)
tzinfo-data
web-console (>= 4.2.1)
webdrivers
webmock (>= 3.23.1)
RUBY VERSION
ruby 3.3.10p183
BUNDLED WITH
2.5.22

View File

@@ -0,0 +1,17 @@
diff --git a/config/environments/development.rb b/config/environments/development.rb
index c0cba740..a4a3f4d1 100644
--- a/config/environments/development.rb
+++ b/config/environments/development.rb
@@ -117,6 +117,12 @@ Rails.application.configure do
# Suppress logger output for asset requests.
config.assets.quiet = true
+ # Do not dump schema after migrations.
+ config.active_record.dump_schema_after_migration = Rails.env.development? && ENV["RAILS_DUMP_SCHEMA"] != "false"
+
+ # Ensure requests are considered secure if they come through a reverse proxy with the correct headers
+ config.action_controller.forgery_protection_origin_check = ENV['FORGERY_ORIGIN_CHECK'] != 'false'
+
# Raises error for missing translations.
# config.i18n.raise_on_missing_translations = true

2838
pkgs/by-name/gr/greenlight/gemset.nix generated Normal file

File diff suppressed because it is too large Load Diff

View File

@@ -0,0 +1,119 @@
{
lib,
stdenv,
fetchFromGitHub,
bundlerEnv,
fetchNpmDeps,
nodejs_26,
npmHooks,
ruby_3_3,
makeWrapper,
which,
nixosTests,
nix-update-script,
_experimental-update-script-combinators,
}:
let
ruby = ruby_3_3;
nodejs = nodejs_26;
in
stdenv.mkDerivation (finalAttrs: {
pname = "greenlight";
version = "3.8.2.4";
__structuredAttrs = true;
strictDeps = true;
src = fetchFromGitHub {
owner = "bigbluebutton";
repo = "greenlight";
tag = "release-${finalAttrs.version}";
hash = "sha256-GOgOEP6dx1E/rIe4HBR35TM294ad8ywcBXVea1xFOag=";
};
patches = [
# Expose further Rails development configurations as env vars
./expose_rails_dev_configs.patch
];
postPatch = ''
# jsbundling-rails dependency would executes yarn install but
# we'll stick with npm
rm -f yarn.lock
substituteInPlace "config/storage.yml" --replace-fail \
'root: <%= Rails.root.join("storage") %>' \
'root: "/var/lib/greenlight/storage"'
substituteInPlace "config/environments/development.rb" --replace-fail \
' config.hosts = nil' \
' config.hosts = nil; config.paths["log"] = ["/var/log/greenlight/development.log"]'
'';
nativeBuildInputs = [
makeWrapper
which
nodejs
npmHooks.npmConfigHook
finalAttrs.rubyEnv.wrappedRuby
];
npmDeps = fetchNpmDeps {
inherit (finalAttrs) src;
hash = "sha256-aTDd6+mc3DIE5FiaPVjjorJ0r8RfodhEVCs3o2zHbZk=";
};
rubyEnv = bundlerEnv {
name = "greenlight-env-${finalAttrs.version}";
inherit ruby;
gemfile = "${finalAttrs.src}/Gemfile";
# Manually need to remove platform not supported by bundix
# See https://github.com/bigbluebutton/greenlight/pull/6317
lockfile = ./Gemfile.lock;
gemset = ./gemset.nix;
groups = [ "production" ];
};
makeCacheWritable = true;
buildPhase = ''
runHook preBuild
export BUNDLE_WITHOUT=development:test
export SECRET_KEY_BASE=1
bundle exec rails assets:precompile
runHook postBuild
'';
installPhase = ''
runHook preInstall
mkdir -p $out/share/greenlight $out/bin
cp -r app bin config config.ru db lib public vendor Gemfile Gemfile.lock Rakefile $out/share/greenlight/
ln -s $out/share/greenlight/lib $out/lib
ln -s $out/share/greenlight/bin $out/bin
ln -sf /tmp $out/share/greenlight/tmp
runHook postInstall
'';
passthru = {
inherit (finalAttrs) rubyEnv;
tests = { inherit (nixosTests) greenlight; };
# run with: nix-shell ./maintainers/scripts/update.nix --argstr package greenlight
updateScript = _experimental-update-script-combinators.sequence [
(nix-update-script { })
./update.sh
];
};
meta = {
description = "End-user web interface for BigBlueButton server";
homepage = "https://github.com/bigbluebutton/greenlight";
platforms = lib.platforms.linux;
license = lib.licenses.lgpl3Only;
maintainers = [ lib.maintainers.onny ];
teams = [ lib.teams.ngi ];
};
})

View File

@@ -0,0 +1,20 @@
#!/usr/bin/env nix-shell
#!nix-shell -i bash -p bundix ruby_3_3 nixfmt
set -eu -o pipefail
set -x
dir="$(dirname "$(readlink -f "$0")")"
# nix-update-script already bumped src.tag/hash before this runs.
# Just regenerate the gem lockfiles for the current (already-updated) source.
repo=$(mktemp -d /tmp/greenlight-update.XXX)
rm -f "$dir/gemset.nix" "$dir/Gemfile.lock"
greenlight_storepath=$(nix build --no-link --print-out-paths -f . greenlight.src)
cp -r --no-preserve=mode,ownership "$greenlight_storepath/." "$repo/"
# remove binary platform otherwise building will fail
# see https://github.com/bigbluebutton/greenlight/pull/6317
BUNDLE_GEMFILE="$repo/Gemfile" bundler lock --remove-platform x86_64-linux --lockfile="$repo/Gemfile.lock"
bundix --lock --lockfile="$repo/Gemfile.lock" --gemfile="$repo/Gemfile" --gemset="$dir/gemset.nix"
cp "$repo/Gemfile.lock" "$dir/"
nixfmt "$dir/gemset.nix"

View File

@@ -15,7 +15,7 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "hk";
version = "1.57.0";
version = "1.58.1";
__structuredAttrs = true;
@@ -23,10 +23,10 @@ rustPlatform.buildRustPackage (finalAttrs: {
owner = "jdx";
repo = "hk";
tag = "v${finalAttrs.version}";
hash = "sha256-n2u//Gq0MTTAF02ed/ioINxSC/y0J0uC3M04fTudpi0=";
hash = "sha256-XSZy4dbKPDRkGc8BrVCz8H0STb64uJEoJBQ5lwiwsv4=";
};
cargoHash = "sha256-UyJUIrnnqPAI9Li5DgPgKYFzn+hYW0yRMar+1nTi8eQ=";
cargoHash = "sha256-WQ/ICFoRuZBEXGaLbScnwBv4s6AhdtgoUSxoYwmQT0c=";
nativeBuildInputs = [
installShellFiles

View File

@@ -49,19 +49,19 @@ let
llvmMajorVersion = "22";
version = "7.1.0";
version = "7.1.1";
src = fetchFromGitHub {
owner = "intel";
repo = "llvm";
tag = "v${self.version}";
hash = "sha256-dz/3oOzumEBq3FQgsPoxMLv4rxnw09orpbuc7kyvn6s=";
hash = "sha256-XVfLWx7lsjS1m+w/T2x0kGg2k51r7jCmKX2ZcR2aAHg=";
};
# The commit date of the release tag above, kept in sync by `updateScript`.
# If you override src, you'll probably also want to override this,
# as some packages check for this date to decide what features the compiler supports.
commitDate = "20260831";
commitDate = "20260915";
vc-intrinsics-src = fetchFromGitHub {
owner = "intel";

View File

@@ -2,33 +2,26 @@
lib,
stdenv,
fetchFromGitHub,
fetchpatch,
cmake,
pkg-config,
utf8cpp,
}:
stdenv.mkDerivation (finalAttrs: {
pname = "libebml";
version = "1.4.5";
version = "1.4.7";
src = fetchFromGitHub {
owner = "Matroska-Org";
repo = "libebml";
rev = "release-${finalAttrs.version}";
sha256 = "sha256-PIVBePTWceMgiENdaL9lvXIL/RQIrtg7l0OG2tO0SU8=";
sha256 = "sha256-myXqGGFfL+CuaOwwNuSZC4+fgqcQNRzhWN0jrY3k5r8=";
};
patches = [
(fetchpatch {
name = "libebml-fix-cmake-4.patch";
url = "https://github.com/Matroska-Org/libebml/commit/6725c5f0169981cb0bd2ee124fbf0d8ca30b762d.patch";
hash = "sha256-q62EWnJmQzBtra1xL0N7rC4RARJZQ/HAVyorzvB7XFY=";
})
];
nativeBuildInputs = [
cmake
pkg-config
utf8cpp
];
cmakeFlags = [

View File

@@ -8,13 +8,13 @@
}:
stdenv.mkDerivation (finalAttrs: {
version = "4.10.0";
version = "4.11.0";
pname = "libre";
src = fetchFromGitHub {
owner = "baresip";
repo = "re";
rev = "v${finalAttrs.version}";
sha256 = "sha256-1EI7Tjp5pwinP65vG+59jyHRXbNOBCP3vnRyC7zHUh4=";
sha256 = "sha256-cG7etDjpWdOhZ2dUhkXxlKpDpEoUG/7z8KkQXgSSVbw=";
};
buildInputs = [

View File

@@ -12,16 +12,16 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "mergiraf";
version = "0.19.0";
version = "0.19.1";
src = fetchFromCodeberg {
owner = "mergiraf";
repo = "mergiraf";
tag = "v${finalAttrs.version}";
hash = "sha256-eBq7xNuV0Z6DVdgaKVgk07WmGEgu7k14hkvVWwtplOo=";
hash = "sha256-belYegVxLLrXr3h+n1qjmF14+rJoadkXoNwL+S/2jZE=";
};
cargoHash = "sha256-dxTR5mvov5FvnkIZalDMnl99BH8sBx6EsqJyGRMiPfQ=";
cargoHash = "sha256-DioS90ecNOEryE7zVddu3ov2S3ylTRtLxe+Zmw2hkmM=";
nativeCheckInputs = [
git

View File

@@ -49,13 +49,13 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "mkvtoolnix";
version = "100.0";
version = "102.0";
src = fetchFromCodeberg {
owner = "mbunkus";
repo = "mkvtoolnix";
tag = "release-${finalAttrs.version}";
hash = "sha256-85mL3/x7SoTgOxU/YCFh58vcGzHLG3qPbbG4MD5dB9o=";
hash = "sha256-YsenzSOMwh+jDOgdYHQhiicdHEHIGzd3UqPyecdgJaI=";
};
passthru = {

View File

@@ -12,11 +12,11 @@
stdenv.mkDerivation (finalAttrs: {
pname = "neo4j";
version = "2026.07.0";
version = "2026.08.1";
src = fetchurl {
url = "https://neo4j.com/artifact.php?name=neo4j-community-${finalAttrs.version}-unix.tar.gz";
hash = "sha256-ANpBduUqBM+60704P34N/dfsBOtL0liPcRBVPxx5rgU=";
hash = "sha256-bkuxVaS9Aqinp+g6VqynDfHNXZD/TdlLVA8g9J8AAIQ=";
};
nativeBuildInputs = [ makeWrapper ];

View File

@@ -6,13 +6,13 @@
buildGoModule (finalAttrs: {
pname = "nvidia-mig-parted";
version = "0.15.0";
version = "0.15.1";
src = fetchFromGitHub {
owner = "NVIDIA";
repo = "mig-parted";
tag = "v${finalAttrs.version}";
hash = "sha256-IIMSLaHhLtA0Tf07a+DE52zIBlQnuGawlj0Z1wTivRs=";
hash = "sha256-ApqGjg5ARehMB9lP3Gv4i1j/f3p53Vd1ZNuwDznhIqw=";
};
vendorHash = null;

View File

@@ -9,13 +9,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "phpstan";
version = "2.2.13";
version = "2.2.14";
src = fetchFromGitHub {
owner = "phpstan";
repo = "phpstan";
tag = finalAttrs.version;
hash = "sha256-saY4OzbbN0VfyCJeGghlK3vFVEhAbKq+HJeplcG5Lm4=";
hash = "sha256-cxDHp8jN0aA0OQuDOpttIzFlp4JmUfKdxBxAPO9y/AM=";
};
nativeBuildInputs = [

View File

@@ -11,6 +11,8 @@
pango,
intltool,
wrapGAppsHook4,
webp-pixbuf-loader,
gnome,
nix-update-script,
# Darwin transitive deps
@@ -84,6 +86,17 @@ buildDotnetModule rec {
intltool-merge -d po/ xdg/com.github.PintaProject.Pinta.desktop.in xdg/com.github.PintaProject.Pinta.desktop
'';
postInstall = ''
# In postInstall to run before gappsWrapperArgsHook.
export GDK_PIXBUF_MODULE_FILE="${
gnome._gdkPixbufCacheBuilder_DO_NOT_USE {
extraLoaders = [
webp-pixbuf-loader
];
}
}"
'';
postFixup = ''
# Two-step rename needed on macOS: 'Pinta' is the same as 'pinta' on case-insensitive filesystems.
mv "$out/bin/Pinta" "$out/bin/pinta_tmp"

View File

@@ -15,7 +15,7 @@
stdenv.mkDerivation (finalAttrs: {
pname = "proton-pass-cli";
version = "2.3.3";
version = "2.4.1";
__structuredAttrs = true;
strictDeps = true;
@@ -57,15 +57,15 @@ stdenv.mkDerivation (finalAttrs: {
sources = {
"aarch64-darwin" = fetchurl {
url = "https://proton.me/download/pass-cli/${finalAttrs.version}/pass-cli-macos-aarch64";
hash = "sha256-MoFYesnFCuLxYEunXp0dObbeuyIbZabMVvZNYm7ePbw=";
hash = "sha256-Sx+OqpLUTM3d0rb3Fsjz4O04jLKHCAWbu8hhcPw5U5w=";
};
"aarch64-linux" = fetchurl {
url = "https://proton.me/download/pass-cli/${finalAttrs.version}/pass-cli-linux-aarch64";
hash = "sha256-nD6F4Q07tjH/43fwY9mWucyaVF0wlxvO31kQ4W0DVCs=";
hash = "sha256-ZVo/bG6/hrC8Z8yy4JmgkBo63xP4zAdNlliGv+cEA/o=";
};
"x86_64-linux" = fetchurl {
url = "https://proton.me/download/pass-cli/${finalAttrs.version}/pass-cli-linux-x86_64";
hash = "sha256-tbSaiz/Qr4gwwMGXnyjqDJDM7Oc/WQI6i8qCRdS2jak=";
hash = "sha256-9BiEMEZuCj1mi1Z5GotDAWLLIM6xCP7U/b/P530wgOY=";
};
};
updateScript = writeShellScript "update-proton-pass-cli" ''

View File

@@ -29,6 +29,8 @@ stdenv.mkDerivation {
makeFlags = [ "PREFIX=$(out)" ];
meta = {
# last successful hydra build on aarch64-linux was in 2022
broken = stdenv.hostPlatform.isLinux && stdenv.hostPlatform.isAarch64;
homepage = "https://www.umaxx.net/";
description = "Minimal utility to set display colour temperature";
maintainers = with lib.maintainers; [

View File

@@ -9,13 +9,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "sqlitecpp";
version = "3.3.3";
version = "3.4.0";
src = fetchFromGitHub {
owner = "SRombauts";
repo = "sqlitecpp";
rev = finalAttrs.version;
hash = "sha256-RSNJGfvIvNfk+/Awzh06tDi/TA5Wc35X8ya0X5mP9IE=";
hash = "sha256-lmXvh2z+6QLLUapsHouBuAxgBQwbC5XKq80sza6CaUI=";
};
nativeBuildInputs = [

View File

@@ -1,123 +0,0 @@
diff --git a/package.json b/package.json
index d0f7837..fbdcb92 100644
--- a/package.json
+++ b/package.json
@@ -55,5 +55,10 @@
"update-electron-app": "^3.1.1",
"utf-8-validate": "^6.0.5"
},
+ "pnpm": {
+ "overrides": {
+ "yauzl": "^3.3.1"
+ }
+ },
"packageManager": "pnpm@10.18.1+sha512.77a884a165cbba2d8d1c19e3b4880eee6d2fcabd0d879121e282196b80042351d5eb3ca0935fa599da1dc51265cc68816ad2bddd2a2de5ea9fdf92adbec7cd34"
-}
\ No newline at end of file
+}
diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml
index 9c7ff44..7e9007d 100644
--- a/pnpm-lock.yaml
+++ b/pnpm-lock.yaml
@@ -4,6 +4,9 @@ settings:
autoInstallPeers: true
excludeLinksFromLockfile: false
+overrides:
+ yauzl: ^3.3.1
+
importers:
.:
@@ -1086,9 +1089,6 @@ packages:
resolution: {integrity: sha512-yQbXgO/OSZVD2IsiLlro+7Hf6Q18EJrKSEsdoMzKePKXct3gvD8oLcOQdIzGupr5Fj+EDe8gO/lxc1BzfMpxvA==}
engines: {node: '>=8'}
- buffer-crc32@0.2.13:
- resolution: {integrity: sha512-VO9Ht/+p3SN7SKWqcrgEzjGbRSJYTx+Q1pTQC0wrWqHx0vpJraQ6GtHx8tvcg1rlK1byhU5gccxgOgj7B0TDkQ==}
-
buffer-from@1.1.2:
resolution: {integrity: sha512-E+XQCRwSbaaiChtv6k6Dwgc+bx+Bs6vuKJHHl5kox/BaKbhiXzqQOwK4cO22yElGp2OCmjwVhT3HmxgyPGnJfQ==}
@@ -1575,9 +1575,6 @@ packages:
fastq@1.19.1:
resolution: {integrity: sha512-GwLTyxkCXjXbxqIhTsMI2Nui8huMPtnxg7krajPJAjnEG/iiOS7i+zCtWGZR9G0NBKbXKh6X9m9UIsYX/N6vvQ==}
- fd-slicer@1.1.0:
- resolution: {integrity: sha512-cE1qsB/VwyQozZ+q1dGxR8LBYNZeofhEdUNGSMbQD3Gw2lAzX9Zb3uIU6Ebc/Fmyjo9AWWfnn0AUCHqtevs/8g==}
-
figures@2.0.0:
resolution: {integrity: sha512-Oa2M9atig69ZkfwiApY8F2Yy+tzMbazyvqv21R0NsSC8floSOC09BbT1ITWAdoMGQvJ/aZnR1KMwdx9tvHnTNA==}
engines: {node: '>=4'}
@@ -1722,7 +1719,7 @@ packages:
glob@7.2.3:
resolution: {integrity: sha512-nFR0zLpU2YCaRxwoCJvL6UvCH2JFyFVIvwTLsIf21AuHlMskA1hhTdk+LlYJtOlYt9v6dvszD2BGRqBL+iQK9Q==}
- deprecated: Old versions of glob are not supported, and contain widely publicized security vulnerabilities, which have been fixed in the current version. Please update. Support for old versions may be purchased (at exorbitant rates) by contacting i@izs.me
+ deprecated: Glob versions prior to v9 are no longer supported
glob@8.1.0:
resolution: {integrity: sha512-r8hpEjiQEYlF2QU0df3dS+nxxSIreXQS1qRhMJM0Q5NDdR386C7jb7Hwwod8Fgiuex+k0GFjgft18yvxm5XoCQ==}
@@ -2883,7 +2880,7 @@ packages:
tar@6.2.1:
resolution: {integrity: sha512-DZ4yORTwrbTj/7MZYq2w+/ZFdI6OZ/f9SFHR+71gIVUZhOQPHzVCLpvRnPgyaMpfWxxk/4ONva3GQSyNIKRv6A==}
engines: {node: '>=10'}
- deprecated: Old versions of tar are not supported, and contain widely publicized security vulnerabilities, which have been fixed in the current version. Please update. Support for old versions may be purchased (at exorbitant rates) by contacting i@izs.me
+ deprecated: Old versions of tar are not supported, and contain widely publicized security vulnerabilities, which have been fixed in the current version. Please update. Support for old versions may be purchased (at exhorbitant rates) by contacting i@izs.me
temp@0.9.4:
resolution: {integrity: sha512-yYrrsWnrXMcdsnu/7YMYAofM1ktpL5By7vZhf15CrXijWWrEYZks5AXBudalfSWJLlnen/QUJUB5aoB0kqZUGA==}
@@ -3174,8 +3171,9 @@ packages:
resolution: {integrity: sha512-7dSzzRQ++CKnNI/krKnYRV7JKKPUXMEh61soaHKg9mrWEhzFWhFnxPxGl+69cD1Ou63C13NUPCnmIcrvqCuM6w==}
engines: {node: '>=12'}
- yauzl@2.10.0:
- resolution: {integrity: sha512-p4a9I6X6nu6IhoGmBqAcbJy1mlC4j27vEPZX9F4L4/vZT3Lyq1VkFHw/V/PUcB9Buo+DG3iHkT0x3Qya58zc3g==}
+ yauzl@3.4.0:
+ resolution: {integrity: sha512-jIH9yLR9wqr0wOS0TpBvo/g/2UgZH5qePVbjgRliiF0BYvOZyaBknKsF+x9Iht0O6sqgnB93rCICdOZFecJuDw==}
+ engines: {node: '>=12'}
yocto-queue@0.1.0:
resolution: {integrity: sha512-rVksvsnNCdJ/ohGc6xgPwyN8eheCxsiLM8mxuE/t/mOVqJewPuO1miLpTHQiRgTKCLexL4MeAFVagts7HmNZ2Q==}
@@ -4439,8 +4437,6 @@ snapshots:
dependencies:
fill-range: 7.1.1
- buffer-crc32@0.2.13: {}
-
buffer-from@1.1.2: {}
buffer@5.7.1:
@@ -5110,7 +5106,7 @@ snapshots:
dependencies:
debug: 4.4.3
get-stream: 5.2.0
- yauzl: 2.10.0
+ yauzl: 3.4.0
optionalDependencies:
'@types/yauzl': 2.10.3
transitivePeerDependencies:
@@ -5136,10 +5132,6 @@ snapshots:
dependencies:
reusify: 1.1.0
- fd-slicer@1.1.0:
- dependencies:
- pend: 1.2.0
-
figures@2.0.0:
dependencies:
escape-string-regexp: 1.0.5
@@ -6839,10 +6831,9 @@ snapshots:
y18n: 5.0.8
yargs-parser: 21.1.1
- yauzl@2.10.0:
+ yauzl@3.4.0:
dependencies:
- buffer-crc32: 0.2.13
- fd-slicer: 1.1.0
+ pend: 1.2.0
yocto-queue@0.1.0: {}

View File

@@ -9,33 +9,28 @@
makeWrapper,
removeReferencesTo,
copyDesktopItems,
pnpm_10,
pnpm_11,
nodejs,
electron_42,
electron_43,
zip,
nix-update-script,
}:
let
electron = electron_42;
electron = electron_43;
stdenv = stdenvNoCC;
in
stdenv.mkDerivation (finalAttrs: {
pname = "stoat-desktop";
version = "1.4.2";
version = "1.5.3";
src = fetchFromGitHub {
owner = "stoatchat";
repo = "for-desktop";
tag = "v${finalAttrs.version}";
fetchSubmodules = true;
hash = "sha256-Qfny57ZwSk19R4fnz+IQoEhbVG76yJhx06QPDpLM7fM=";
hash = "sha256-UKMuMtBTfiA31K2i1buCFOtL9lf9xbv6BXVD5m4TARo=";
};
patches = [
# zip extraction fails on newer nodejs versions without this fix
./bump-yauzl.patch
];
postPatch = ''
# Disable auto-updates
sed -i '/updateElectronApp([^)]*)/d' src/main.ts
@@ -51,7 +46,7 @@ stdenv.mkDerivation (finalAttrs: {
makeWrapper
copyDesktopItems
nodejs
pnpm_10
pnpm_11
zip
]
++ lib.optionals stdenv.hostPlatform.isDarwin [
@@ -63,11 +58,10 @@ stdenv.mkDerivation (finalAttrs: {
pname
version
src
patches
;
fetcherVersion = 3;
pnpm = pnpm_10;
hash = "sha256-0v+MHYFgnIN4FvzFkv5D3Bqc7538763yCIWu05XR+fA=";
fetcherVersion = 4;
pnpm = pnpm_11;
hash = "sha256-uiKTkXU0THzW46FiAfftqMWfrnFPCfgS/30ZuWmpHMI=";
};
env.ELECTRON_SKIP_BINARY_DOWNLOAD = "1";

View File

@@ -14,13 +14,13 @@
buildGoModule (finalAttrs: {
pname = "tektoncd-cli";
version = "0.46.0";
version = "0.46.1";
src = fetchFromGitHub {
owner = "tektoncd";
repo = "cli";
tag = "v${finalAttrs.version}";
sha256 = "sha256-BEYwvGi/Mt/DkHRR2TU42ItLC57CVKnb7ZBy3TKBoZs=";
sha256 = "sha256-YZN6Oprt9Rjg5EBRmaQR/N5wc4oVaK4Tr9Tx4d+UemY=";
};
vendorHash = null;

View File

@@ -0,0 +1,74 @@
{
lib,
stdenv,
fetchFromGitHub,
fetchPnpmDeps,
pnpmConfigHook,
pnpm_10,
nodejs,
textlint,
textlint-rule-preset-ai-words-ja,
nix-update-script,
}:
stdenv.mkDerivation (finalAttrs: {
pname = "textlint-rule-preset-ai-words-ja";
version = "1.2.1";
__structuredAttrs = true;
strictDeps = true;
src = fetchFromGitHub {
owner = "p1ass";
repo = "textlint-rule-preset-ai-words-ja";
tag = "v${finalAttrs.version}";
hash = "sha256-0QgNPVyheFdPLCLq6JJy5AFIJ5txr1TOvzJ2VFC2C0I=";
};
pnpmDeps = fetchPnpmDeps {
inherit (finalAttrs) pname version src;
pnpm = pnpm_10;
fetcherVersion = 4;
hash = "sha256-azyV6f7aha1dS0bTTNU5rwzKxRpYaARNVDVJKbMA2sM=";
};
nativeBuildInputs = [
nodejs
pnpmConfigHook
pnpm_10
];
buildPhase = ''
runHook preBuild
pnpm build
runHook postBuild
'';
installPhase = ''
runHook preInstall
pnpm install --offline --frozen-lockfile --ignore-scripts --prod
mkdir -p $out/lib/node_modules/textlint-rule-preset-ai-words-ja
cp -r lib node_modules package.json $out/lib/node_modules/textlint-rule-preset-ai-words-ja
runHook postInstall
'';
passthru = {
tests = textlint.testPackages {
rule = textlint-rule-preset-ai-words-ja;
testFile = ./test.md;
};
updateScript = nix-update-script { };
};
meta = {
description = "Textlint preset that detects words and phrases commonly found in AI-generated Japanese";
homepage = "https://github.com/p1ass/textlint-rule-preset-ai-words-ja";
changelog = "https://github.com/p1ass/textlint-rule-preset-ai-words-ja/releases/tag/${finalAttrs.src.tag}";
license = lib.licenses.mit;
maintainers = with lib.maintainers; [ airrnot ];
platforms = textlint.meta.platforms;
};
})

View File

@@ -0,0 +1 @@
変更した瞬間、静かに壊れます。

View File

@@ -19,6 +19,7 @@
textlint-rule-max-comma,
textlint-rule-no-start-duplicated-conjunction,
textlint-rule-period-in-list-item,
textlint-rule-preset-ai-words-ja,
textlint-rule-preset-ja-spacing,
textlint-rule-preset-ja-technical-writing,
textlint-rule-prh,
@@ -157,6 +158,7 @@ stdenv.mkDerivation (finalAttrs: {
textlint-rule-max-comma
textlint-rule-no-start-duplicated-conjunction
textlint-rule-period-in-list-item
textlint-rule-preset-ai-words-ja
textlint-rule-preset-ja-spacing
textlint-rule-preset-ja-technical-writing
textlint-rule-prh

View File

@@ -38,16 +38,16 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "tokenspeed-triton-llvm";
version = "23.0.0-unstable-2026-04-08"; # See cmake/Modules/LLVMVersion.cmake
version = "24.0.0-unstable-2026-08-03"; # See cmake/Modules/LLVMVersion.cmake
__structuredAttrs = true;
strictDeps = true;
# See https://github.com/lightseekorg/triton/blob/v3.7.10.post20260531/cmake/llvm-info.json
# See https://github.com/lightseekorg/triton/blob/v3.8.10.post20260920/cmake/llvm-info.json
src = fetchFromGitHub {
owner = "llvm";
repo = "llvm-project";
rev = "87717bf9f81f7b29466c5d9a30a3453bdfc93941";
hash = "sha256-8+Q19pOgovZgpN0it5TDrrQfXZFGiIRoP0Ha5dLQJp0=";
rev = "b010a18d2b648cab83c83967ff26b8fde11acdc6";
hash = "sha256-stgOKrTcZo6eq/oOkIRo89t/lIJ2ADFzh7XHuNdxeJs=";
};
nativeBuildInputs = [

View File

@@ -16,13 +16,13 @@
buildGoModule (finalAttrs: {
pname = "wails";
version = "2.15.0";
version = "2.16.0";
src = fetchFromGitHub {
owner = "wailsapp";
repo = "wails";
tag = "v${finalAttrs.version}";
hash = "sha256-/0GJ0RVBxuPTUqSuoZ8pLi1E2dR9n1n3aPlUKjpFVJw=";
hash = "sha256-TackU0WXVP2yoVUVnXCnLiXfBjlqNUKzvwlkBDrCo5Y=";
};
sourceRoot = "${finalAttrs.src.name}/v2";

View File

@@ -21,6 +21,7 @@
libGL,
libxcursor,
libxext,
libxi,
libxinerama,
libxrandr,
libepoxy,
@@ -44,7 +45,7 @@ assert lib.assertOneOf "simdTarget" simdTarget [
];
clangStdenv.mkDerivation (finalAttrs: {
pname = "zlequalizer";
version = "1.2.2";
version = "1.4.0";
__structuredAttrs = true;
strictDeps = true;
@@ -53,7 +54,7 @@ clangStdenv.mkDerivation (finalAttrs: {
owner = "ZL-Audio";
repo = "ZLEqualizer";
tag = finalAttrs.version;
hash = "sha256-fIcplXdRKtCqWBm2Vw/Nm8dVDOpKnsejo2irv1xehvk=";
hash = "sha256-Q1eyWLt+AIz0DZmytBpgKJ/NHcwenYPIIQF6gQzP78M=";
fetchSubmodules = true;
};
@@ -78,6 +79,7 @@ clangStdenv.mkDerivation (finalAttrs: {
libGL
libxcursor
libxext
libxi
libxinerama
libxrandr
libepoxy
@@ -87,9 +89,15 @@ clangStdenv.mkDerivation (finalAttrs: {
env = lib.optionalAttrs clangStdenv.hostPlatform.isLinux {
# JUCE dlopen's these at runtime, crashes without them
# -lXi is essential: JUCE requests the unversioned
# "libXi.so", which no host has already loaded, and when that dlopen fails
# JUCE still believes XInput2 is present (the stub for the missing
# XIQueryVersion returns 0, which equals Success), so it discards all core
# pointer events and the GUI stops responding to the mouse entirely.
NIX_LDFLAGS = toString [
"-lX11"
"-lXext"
"-lXi"
"-lXcursor"
"-lXinerama"
"-lXrandr"

View File

@@ -0,0 +1,79 @@
{
lib,
buildPythonPackage,
fetchFromGitHub,
pythonOlder,
poetry-core,
setuptools,
cython,
ciso8601,
tzdata,
lz4,
tzlocal,
zstd,
clickhouse-cityhash,
stdenv,
nix-update-script,
nixosTests,
}:
buildPythonPackage (finalAttrs: {
pname = "asynch";
version = "0.4.0";
pyproject = true;
__structuredAttrs = true;
src = fetchFromGitHub {
owner = "long2ice";
repo = "asynch";
tag = "v${finalAttrs.version}";
sha256 = "sha256-iLhhk7EiNHMVzxlw7HWjS00GwZ8cRXPz3jih1edWde4=";
};
disabled = pythonOlder "3.11";
build-system = [
poetry-core
setuptools
cython
];
dependencies = [
ciso8601
tzlocal
]
++ lib.optionals (stdenv.hostPlatform.isWindows) [
tzdata
];
optional-dependencies = {
compression = [
clickhouse-cityhash
lz4
]
++ lib.optionals (pythonOlder "3.14") [
zstd
];
};
pythonImportsCheck = [
"asynch"
];
passthru = {
updateScript = nix-update-script { };
tests = {
inherit (nixosTests) asynch;
};
};
meta = {
description = "Asyncio driver for ClickHouse with native TCP support";
homepage = "https://github.com/long2ice/asynch";
license = lib.licenses.asl20;
maintainers = with lib.maintainers; [
jlesquembre
joaosreis
];
};
})

View File

@@ -14,14 +14,14 @@
buildPythonPackage (finalAttrs: {
pname = "cookidoo-api";
version = "0.18.3";
version = "0.18.4";
pyproject = true;
src = fetchFromGitHub {
owner = "miaucl";
repo = "cookidoo-api";
tag = finalAttrs.version;
hash = "sha256-mMMtapn5LLdGyVhU7jdaKm/ulC3YUoRhM32xgsIQiqU=";
hash = "sha256-YZdJ5myaVS+Hcj5LpsHwpoAyTEY2KRgczzJdIp9Nuck=";
};
build-system = [ setuptools ];

View File

@@ -0,0 +1,88 @@
{
lib,
buildPythonPackage,
fetchFromGitHub,
boto3,
pytestCheckHook,
cmake,
hypothesis,
rustPackages,
setuptools-rust,
torch,
}:
let
inherit (rustPackages) rustPlatform rustc cargo;
in
buildPythonPackage rec {
pname = "s3torchconnectorclient";
version = "1.5.0";
format = "pyproject";
__structuredAttrs = true;
src = fetchFromGitHub {
owner = "awslabs";
repo = "s3-connector-for-pytorch";
rev = "v${version}";
hash = "sha256-ovy/VUWTYMQ3wbmLptqj6l+uVwl4Gbkt3OpPUPayuLI=";
};
sourceRoot = "${src.name}/s3torchconnectorclient";
cargoDeps = rustPlatform.fetchCargoVendor {
inherit src sourceRoot;
hash = "sha256-xYfBnyZM43FNxPnnP6a45ZLCCve/B3713RNmgG0LNBc=";
};
nativeBuildInputs = [
cargo
cmake
rustc
rustPlatform.cargoSetupHook
rustPlatform.bindgenHook
setuptools-rust
];
# Patch metrics-0.24.1 to fix E0521 borrow-checker error under newer rustc.
# Backport of the fix from metrics 0.24.2. See: https://github.com/rust-lang/rust/issues/141402
postPatch = ''
patch -d $cargoDepsCopy/*/metrics-0.24.1 -p1 < ${./fix-metrics-0.24.1-E0521.patch}
'';
# cmake is needed/used by the rust toolchain, we don't want Nix to run it directly
dontUseCmakeConfigure = true;
env = {
CFLAGS = "-Wno-stringop-overflow -Wno-array-bounds -Wno-restrict";
# pyo3-0.24.1 declares support only up to Python 3.13; use stable ABI for forward compat
PYO3_USE_ABI3_FORWARD_COMPATIBILITY = "1";
};
dependencies = [
boto3
torch
];
pythonImportsCheck = [ "s3torchconnectorclient" ];
nativeCheckInputs = [
pytestCheckHook
hypothesis
];
disabledTestPaths = [
# integration tests access S3
"python/tst/integration/"
# unit tests for S3 client creation require AWS credentials + TLS trust store
"python/tst/unit/test_mountpoint_s3_client.py"
];
meta = with lib; {
description = "Low-level S3 client for PyTorch data loading";
homepage = "https://github.com/awslabs/s3-connector-for-pytorch";
changelog = "https://github.com/awslabs/s3-connector-for-pytorch/releases/tag/v${version}";
license = licenses.bsd3;
maintainers = with maintainers; [ jherland ];
};
}

View File

@@ -0,0 +1,27 @@
--- a/src/recorder/mod.rs
+++ b/src/recorder/mod.rs
@@ -139,11 +139,19 @@
impl<'a> LocalRecorderGuard<'a> {
/// Creates a new `LocalRecorderGuard` and sets the thread-local recorder.
- fn new(recorder: &'a dyn Recorder) -> Self {
- // SAFETY: While we take a lifetime-less pointer to the given reference, the reference we derive _from_ the
- // pointer is given the same lifetime of the reference used to construct the guard -- captured in the guard type
- // itself -- and so derived references never outlive the source reference.
- let recorder_ptr = unsafe { NonNull::new_unchecked(recorder as *const _ as *mut _) };
+ fn new(recorder: &'a (dyn Recorder + 'a)) -> Self {
+ // SAFETY: We extend `'a` to `'static` to satisfy the signature of `LOCAL_RECORDER`, which
+ // has an implied `'static` bound on `dyn Recorder`. We enforce that all usages of `LOCAL_RECORDER`
+ // are limited to `'a` as we mediate its access entirely through `LocalRecorderGuard<'a>`.
+ let recorder_ptr = unsafe {
+ std::mem::transmute::<*const (dyn Recorder + 'a), *mut (dyn Recorder + 'static)>(
+ recorder as &'a (dyn Recorder + 'a),
+ )
+ };
+ // SAFETY: While we take a lifetime-less pointer to the given reference, the reference we derive _from_ the
+ // pointer is given the same lifetime of the reference used to construct the guard -- captured in the guard type
+ // itself -- and so derived references never outlive the source reference.
+ let recorder_ptr = unsafe { NonNull::new_unchecked(recorder_ptr) };
let prev_recorder =
LOCAL_RECORDER.with(|local_recorder| local_recorder.replace(Some(recorder_ptr)));

View File

@@ -2,34 +2,17 @@
lib,
buildPythonPackage,
fetchPypi,
python,
stdenv,
# nativeBuildInputs
autoPatchelfHook,
pypaInstallHook,
pythonRuntimeDepsCheckHook,
wheelUnpackHook,
# dependencies
apache-tvm-ffi,
nvidia-cutlass-dsl,
nvidia-cutlass-dsl-libs-base,
tokenspeed-triton,
torch,
}:
let
inherit (stdenv.hostPlatform) system;
hashes = {
aarch64-linux = "sha256-rD4rFrvtQXuICjBOkFfmzj3DaGRC4RHGX5EV4x/3T34=";
x86_64-linux = "sha256-1gW6k7nZT4Luj1LOLWaAs91AHBmPi0XCL11loqaCHqQ=";
};
in
buildPythonPackage (finalAttrs: {
pname = "tokenspeed-mla";
version = "0.1.5";
pyproject = false;
version = "0.2.10";
format = "wheel";
__structuredAttrs = true;
src = fetchPypi {
@@ -38,18 +21,12 @@ buildPythonPackage (finalAttrs: {
inherit (finalAttrs) version;
dist = "py3";
python = "py3";
abi = "none";
platform = "manylinux_2_28_${stdenv.hostPlatform.uname.processor}";
hash = hashes.${system} or (throw "Unsupported system: ${system}");
hash = "sha256-o5dwtxhoLiNVF0O2iizjb1FArCNR/oZBI0PMS0KqV9E=";
};
nativeBuildInputs = [
autoPatchelfHook
pypaInstallHook
pythonRuntimeDepsCheckHook
wheelUnpackHook
pythonRelaxDeps = [
"apache-tvm-ffi"
];
dependencies = [
apache-tvm-ffi
nvidia-cutlass-dsl
@@ -57,13 +34,6 @@ buildPythonPackage (finalAttrs: {
torch
];
preFixup = ''
# libtvm_ffi.so
addAutoPatchelfSearchPath "${apache-tvm-ffi}/${python.sitePackages}/tvm_ffi/lib"
# libcute_dsl_runtime.so
addAutoPatchelfSearchPath "${nvidia-cutlass-dsl-libs-base}/${python.sitePackages}/nvidia_cutlass_dsl"/cu*/lib
'';
pythonImportsCheck = [ "tokenspeed_mla" ];
meta = {
@@ -71,9 +41,7 @@ buildPythonPackage (finalAttrs: {
homepage = "https://github.com/lightseekorg/tokenspeed/tree/main/tokenspeed-mla";
downloadPage = "https://pypi.org/project/tokenspeed-mla/#files";
license = lib.licenses.mit;
sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ];
maintainers = with lib.maintainers; [ prince213 ];
platforms = lib.attrNames hashes;
broken = !torch.cudaSupport;
};
})

View File

@@ -14,15 +14,16 @@
}:
buildPythonPackage (finalAttrs: {
pname = "tokenspeed-mla";
version = "0.1.5";
version = "0.2.10";
pyproject = true;
__structuredAttrs = true;
# No git tags. Using the commits named 'Update tokenspeed-mla to XXX'
src = fetchFromGitHub {
owner = "lightseekorg";
repo = "tokenspeed";
rev = "a39b3854dfd9b08a410028dbe5260eda08ef6b63";
hash = "sha256-rl+cpZabmK24nMcam5Ud4GqnpLA3TqpVRznlX6lz6Xs=";
rev = "bf2e923bb422bbc3777fec11ad6b388d2576fde1";
hash = "sha256-UmcM+lALQoTbbbbp4D3woo5vsNICbY9m/MS3wjdyJeE=";
};
sourceRoot = "${finalAttrs.src.name}/tokenspeed-mla";
@@ -31,6 +32,9 @@ buildPythonPackage (finalAttrs: {
setuptools
];
pythonRelaxDeps = [
"apache-tvm-ffi"
];
dependencies = [
apache-tvm-ffi
nvidia-cutlass-dsl

View File

@@ -22,20 +22,20 @@ let
hashes = {
aarch64-linux = {
cp310 = "sha256-rRex0Y8vvOsLsJO+gxeZNkRF+iT/79IWQ5ShvwZJm3Y=";
cp311 = "sha256-Ds3Y1+o63Z19ckG4NcgMEthCZSvWsg3NhNsYojXhYIQ=";
abi3 = "sha256-Fs0KP8HP/rRYp+A+hohxT0n98LWhCL/KmZ9GWXw/qrs=";
cp310 = "sha256-fkYRq6wkAavw4BwOHOt8aybu+IfRLLvrD5oU6JFTHlw=";
cp311 = "sha256-tGfvQ4M7eOqfndLnC842WevPx6N1HjTzHI/+4g0S1+U=";
abi3 = "sha256-KZ9Ygd4Go0SNjk9L/s32/58UiWk7rxYwPehBa6gsFtY=";
};
x86_64-linux = {
cp310 = "sha256-GGrclq8qFWW1Z27JIvYSZdf+u5pK6KK/5ioTigYMJ7Y=";
cp311 = "sha256-Ur4JbdxSJcbyNF4NCQrStWRmqFu+uGbMEaIOD+Pd4b8=";
abi3 = "sha256-uQrEHn8VkzeXVF/xqegDqdi+tMqbpw9tQang/CZIT1w=";
cp310 = "sha256-vHTyzQZDGs5gt3dkBSaA3QGK5rDFpC0NPWk9dOTRmVw=";
cp311 = "sha256-9qMpxrtZSfKxTUdJ1ulwWUwxvTUniPtc7sjkmxffWbw=";
abi3 = "sha256-616ubE09sR4TtwWMibV+B1+n35BdQxac/bBm4WGIZCE=";
};
};
in
buildPythonPackage (finalAttrs: {
pname = "tokenspeed-triton";
version = "3.7.10.post20260531";
version = "3.8.10.post20260920";
pyproject = false;
__structuredAttrs = true;

View File

@@ -20,7 +20,7 @@
}:
buildPythonPackage (finalAttrs: {
pname = "tokenspeed-triton";
version = "3.7.10.post20260531";
version = "3.8.10.post20260920";
pyproject = true;
__structuredAttrs = true;
@@ -28,7 +28,7 @@ buildPythonPackage (finalAttrs: {
owner = "lightseekorg";
repo = "triton";
tag = "v${finalAttrs.version}";
hash = "sha256-xsV63z2NtB5BM0rF0J+cnMH2RYzoWkpsSXHQI2nIEdQ=";
hash = "sha256-IsPm9yrtTTAzjsrFAfZOLSthCHi8akUemv2jZI6SuVM=";
};
postPatch = ''
@@ -40,20 +40,6 @@ buildPythonPackage (finalAttrs: {
substituteInPlace pyproject.toml \
--replace-fail "cmake>=3.20,<4.0" "cmake>=3.20" \
--replace-fail "nanobind==2.10.2" "nanobind>=2.10.2"
''
# nanobind >= 2.13 also requires the `Python::Interpreter`
# target, which upstream's `find_package(Python3)` ->
# `find_package(Python)` bridge misses:
# https://github.com/wjakob/nanobind/commit/706131bef6771ad3634b1d772f029f65b7ea8bd2
+ ''
substituteInPlace CMakeLists.txt \
--replace-fail \
'if(NOT TARGET Python::Module)' \
'if(NOT TARGET Python::Interpreter)
add_executable(Python::Interpreter ALIAS Python3::Interpreter)
endif()
if(NOT TARGET Python::Module)'
'';
build-system = [
@@ -69,7 +55,7 @@ buildPythonPackage (finalAttrs: {
writableTmpDirAsHomeHook
];
# https://github.com/lightseekorg/triton/blob/v3.7.10.post20260531/.github/workflows/wheels.yml#L109-L117
# https://github.com/lightseekorg/triton/blob/v3.8.10.post20260920/.github/workflows/wheels.yml#L110-L118
env = {
TRITON_OFFLINE_BUILD = true;
TRITON_BUILD_RELEASE = true;
@@ -77,7 +63,13 @@ buildPythonPackage (finalAttrs: {
TRITON_STABLE_ABI = pythonAtLeast "3.12";
LLVM_SYSPATH = tokenspeed-triton-llvm;
JSON_SYSPATH = nlohmann_json;
NIX_CFLAGS_COMPILE = "-Wno-stringop-overflow";
# Skip building the AMD codegen library, which requires its own pinned LLVM (cmake/amd-llvm-info.json).
# It is only dlopen'ed at runtime by the AMD backend.
TRITON_AMD_CODEGEN_PATH = "/dev/null";
NIX_CFLAGS_COMPILE = toString [
"-Wno-stringop-overflow"
"-Wno-free-nonheap-object"
];
};
buildInputs = [

View File

@@ -12,13 +12,13 @@
mkTclDerivation (finalAttrs: {
pname = "tclreadline";
version = "2.4.1";
version = "2.5.0";
src = fetchFromGitHub {
owner = "flightaware";
repo = "tclreadline";
tag = "v${finalAttrs.version}";
hash = "sha256-6FIQJsAm28jPIfNG+7xsMlCJSLw9JStOVzDemw2P+EI=";
hash = "sha256-7b+d1fBENfTCdyeHSGAnPPAKf2DMiQbxDLXDvhGYQm4=";
};
nativeBuildInputs = [

View File

@@ -533,6 +533,7 @@ let
# Those are annoyingly flaky, but not enough to be marked as such upstream.
++ lib.optional (majorVersion == "22") "test-child-process-stdout-flush-exit"
++ lib.optional (majorVersion == "22" && stdenv.hostPlatform.isRiscV64) "test-worker-messaging"
++ lib.optional (majorVersion == "26" && !stdenv.buildPlatform.isDarwin) "test-net-boundsocket"
++ lib.optional (
majorVersion == "22" && stdenv.buildPlatform.isDarwin
) "test/sequential/test-http-server-request-timeouts-mixed.js"
@@ -542,10 +543,6 @@ let
# patch does not apply
++ lib.optional (!lib.versionAtLeast version "24") "test-tls-junk-server"
++ lib.optional (majorVersion == "22") "test-tls-alert-handling"
# https://github.com/NixOS/nixpkgs/issues/564449
++ lib.optional (
majorVersion == "26" && !stdenv.buildPlatform.isDarwin
) "test-fs-cp-async-file-modes"
)
}"
];

View File

@@ -23,8 +23,8 @@ let
[ ];
in
buildNodejs {
version = "26.9.0";
sha256 = "47b970d88511b429e587b740fa733176909d2a2005a29662f01b05205f58468b";
version = "26.10.0";
sha256 = "7b3a546d33cb7e15a43bdd7a57e0be5d5fd5ffc553e6e4c120033e66f0ba20c5";
patches =
(lib.optional (!(stdenv.hostPlatform.emulatorAvailable buildPackages)) (fetchpatch2 {
url = "https://raw.githubusercontent.com/buildroot/buildroot/2f0c31bffdb59fb224387e35134a6d5e09a81d57/package/nodejs/nodejs-src/0003-include-obj-name-in-shared-intermediate.patch";

View File

@@ -1499,6 +1499,8 @@ self: super: with self; {
asyncer = callPackage ../development/python-modules/asyncer { };
asynch = callPackage ../development/python-modules/asynch { };
asyncinotify = callPackage ../development/python-modules/asyncinotify { };
asyncio-dgram = callPackage ../development/python-modules/asyncio-dgram { };
@@ -18453,6 +18455,8 @@ self: super: with self; {
s3fs = callPackage ../development/python-modules/s3fs { };
s3torchconnectorclient = callPackage ../development/python-modules/s3torchconnectorclient { };
s3transfer = callPackage ../development/python-modules/s3transfer { };
sabctools = callPackage ../development/python-modules/sabctools { };