From 8ec2a8f100dcaf9b0f1541ba01dd58bc7ddc8153 Mon Sep 17 00:00:00 2001 From: Ben Siraphob Date: Thu, 24 Nov 2022 19:09:12 -0600 Subject: [PATCH 01/38] fq: 0.0.10 -> 0.1.0 (cherry picked from commit bb68fd92c9ebf60128441324582d822e29082ef9) --- pkgs/development/tools/fq/default.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/development/tools/fq/default.nix b/pkgs/development/tools/fq/default.nix index 8c76493430cc..293e16508276 100644 --- a/pkgs/development/tools/fq/default.nix +++ b/pkgs/development/tools/fq/default.nix @@ -7,16 +7,16 @@ buildGoModule rec { pname = "fq"; - version = "0.0.10"; + version = "0.1.0"; src = fetchFromGitHub { owner = "wader"; repo = "fq"; rev = "v${version}"; - sha256 = "sha256-0/5MjnBP7Aeczky5VQ1N1siX4/Qw4rjlrWp8+kKaiFo="; + sha256 = "sha256-ZUbeAZGHG7I4NwJZjI92isIMX8M675oI833v3uKZE7U="; }; - vendorSha256 = "sha256-GwHQvL1XxQLkW8jvsKXIpQI5zdlZurQ4PqNFahBpYDc="; + vendorSha256 = "sha256-GGbKoLj8CyfqB90QnOsomZBVd6KwJCTp/MeyKvRopSQ="; ldflags = [ "-s" From e5574ff8f6056e984cd21d8c987d8e8f4fd1d67a Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 13 Nov 2022 01:34:22 +0000 Subject: [PATCH 02/38] swtpm: 0.7.3 -> 0.8.0 (cherry picked from commit 4d6d188495c2bafe0ac0b609158b063a723a1ba5) --- pkgs/tools/security/swtpm/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/tools/security/swtpm/default.nix b/pkgs/tools/security/swtpm/default.nix index 5d20b65d5914..635fccc00632 100644 --- a/pkgs/tools/security/swtpm/default.nix +++ b/pkgs/tools/security/swtpm/default.nix @@ -16,13 +16,13 @@ stdenv.mkDerivation rec { pname = "swtpm"; - version = "0.7.3"; + version = "0.8.0"; src = fetchFromGitHub { owner = "stefanberger"; repo = "swtpm"; rev = "v${version}"; - sha256 = "sha256-YaNQgxk0uT8FLUIxF80jpgO/L9ygGRHaABEcs5ukq5E="; + sha256 = "sha256-O+sHkmQ47FbqsgWpaqAc/j2AJ5xzsvpBj/p0Zea1nSI="; }; nativeBuildInputs = [ From b413a1b89addd0368260888d541990f70f80d0f9 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 1 Nov 2022 00:42:52 +0000 Subject: [PATCH 03/38] ntfs3g: 2022.5.17 -> 2022.10.3 (cherry picked from commit 26a6ef7f17e1bd46661359af3751ce57511d9962) --- pkgs/tools/filesystems/ntfs-3g/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/tools/filesystems/ntfs-3g/default.nix b/pkgs/tools/filesystems/ntfs-3g/default.nix index 018621b8019a..56d6bdc7fba2 100644 --- a/pkgs/tools/filesystems/ntfs-3g/default.nix +++ b/pkgs/tools/filesystems/ntfs-3g/default.nix @@ -5,7 +5,7 @@ stdenv.mkDerivation rec { pname = "ntfs3g"; - version = "2022.5.17"; + version = "2022.10.3"; outputs = [ "out" "dev" "man" "doc" ]; @@ -13,7 +13,7 @@ stdenv.mkDerivation rec { owner = "tuxera"; repo = "ntfs-3g"; rev = version; - sha256 = "sha256-xh8cMNIHeJ1rtk5zwOsmcxeedgZ3+MSiWn2UC7y+gtQ="; + sha256 = "sha256-nuFTsGkm3zmSzpwmhyY7Ke0VZfZU0jHOzEWaLBbglQk="; }; buildInputs = [ gettext libuuid ] From 1095249f8b762420e554ea44d6de87ec57b90a6b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Vladim=C3=ADr=20=C4=8Cun=C3=A1t?= Date: Sun, 27 Nov 2022 18:00:41 +0100 Subject: [PATCH 04/38] patchelf_0_14: rename to patchelfStable It was 0.15.x already, and r-ryantm keeps suggesting updates. (cherry picked from commit ec045d118ac4997d537892155d48ceaefe690d01) --- pkgs/top-level/all-packages.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index ee05a707a32e..f576fe765c26 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -17500,11 +17500,11 @@ with pkgs; patchelf = if with stdenv.buildPlatform; isAarch64 && isMusl then patchelf_0_13 else - patchelf_0_14; + patchelfStable; patchelf_0_13 = callPackage ../development/tools/misc/patchelf/0.13.nix { - patchelf = patchelf_0_14; + patchelf = patchelfStable; }; - patchelf_0_14 = callPackage ../development/tools/misc/patchelf { }; + patchelfStable = callPackage ../development/tools/misc/patchelf { }; patchelfUnstable = lowPrio (callPackage ../development/tools/misc/patchelf/unstable.nix { }); From 98912623a7239647b7b7a32dd07dc0f63c5c134b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Sun, 27 Nov 2022 20:30:06 -0800 Subject: [PATCH 05/38] python310Packages.snowflake-connector-python: 2.8.0 -> 2.8.2 fixes CVE-2022-42965 https://github.com/snowflakedb/snowflake-connector-python/blob/v2.8.2/DESCRIPTION.md (cherry picked from commit 5aaa6f33d600b6d7b0087c0b14f837dade96f474) --- .../python-modules/snowflake-connector-python/default.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/development/python-modules/snowflake-connector-python/default.nix b/pkgs/development/python-modules/snowflake-connector-python/default.nix index dd2a4175d77f..89cccc5d8b1e 100644 --- a/pkgs/development/python-modules/snowflake-connector-python/default.nix +++ b/pkgs/development/python-modules/snowflake-connector-python/default.nix @@ -20,14 +20,14 @@ buildPythonPackage rec { pname = "snowflake-connector-python"; - version = "2.8.0"; + version = "2.8.2"; format = "setuptools"; disabled = pythonOlder "3.7"; src = fetchPypi { inherit pname version; - hash = "sha256-gvZ+Nuf+Ns1XIYpsBHdegzA9sjFxT9+Qm6kbsJR8JLY="; + hash = "sha256-JvPnxwi+xOsp+hhXIs0GyYx4oz6aovmvHsgHk9R6z8o="; }; propagatedBuildInputs = [ @@ -50,7 +50,6 @@ buildPythonPackage rec { postPatch = '' substituteInPlace setup.cfg \ --replace "pyOpenSSL>=16.2.0,<23.0.0" "pyOpenSSL" \ - --replace "cryptography>=3.1.0,<37.0.0" "cryptography" \ --replace "charset-normalizer~=2.0.0" "charset_normalizer>=2" ''; @@ -64,6 +63,7 @@ buildPythonPackage rec { ]; meta = with lib; { + changelog = "https://github.com/snowflakedb/snowflake-connector-python/blob/v${version}/DESCRIPTION.md"; description = "Snowflake Connector for Python"; homepage = "https://github.com/snowflakedb/snowflake-connector-python"; license = licenses.asl20; From 6c645b4cbe4595cb4f95f607584dfd53232eb28a Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Sun, 27 Nov 2022 20:32:37 -0800 Subject: [PATCH 06/38] python310Packages.snowflake-sqlalchemy: 1.4.3 -> 1.4.4 https://github.com/snowflakedb/snowflake-sqlalchemy/blob/v1.4.4/DESCRIPTION.md (cherry picked from commit c3a00241700de8c4c7bee20614a6f918346be66e) --- .../python-modules/snowflake-sqlalchemy/default.nix | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/snowflake-sqlalchemy/default.nix b/pkgs/development/python-modules/snowflake-sqlalchemy/default.nix index ed51eb73eaa7..d66a5128db52 100644 --- a/pkgs/development/python-modules/snowflake-sqlalchemy/default.nix +++ b/pkgs/development/python-modules/snowflake-sqlalchemy/default.nix @@ -9,14 +9,14 @@ buildPythonPackage rec { pname = "snowflake-sqlalchemy"; - version = "1.4.3"; + version = "1.4.4"; format = "setuptools"; disabled = pythonOlder "3.7"; src = fetchPypi { inherit pname version; - hash = "sha256-sBnkztxqTz7MQ0eYvkAvYWPojxBy6ek1qZxMppLTTM4="; + hash = "sha256-p1ryAD/rVvqGXV2Aev+e8A5Jvltgixg81LKcjbQwAic="; }; propagatedBuildInputs = [ @@ -33,6 +33,7 @@ buildPythonPackage rec { ]; meta = with lib; { + changelog = "https://github.com/snowflakedb/snowflake-sqlalchemy/blob/v${version}/DESCRIPTION.md"; description = "Snowflake SQLAlchemy Dialect"; homepage = "https://github.com/snowflakedb/snowflake-sqlalchemy"; license = licenses.asl20; From ac99db9a61d0f93d1c013358b3a4e189e9d163e2 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sandro=20J=C3=A4ckel?= Date: Fri, 25 Nov 2022 22:27:39 +0100 Subject: [PATCH 07/38] nixos/release-notes: add entry for #191713 (cherry picked from commit a4f053f0e4f5cfe53d8d3a4d9c7f5bf2630812c9) --- .../doc/manual/from_md/release-notes/rl-2211.section.xml | 9 +++++++++ nixos/doc/manual/release-notes/rl-2211.section.md | 2 ++ 2 files changed, 11 insertions(+) diff --git a/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml b/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml index 3061c27585fc..4e4b0923db6c 100644 --- a/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml +++ b/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml @@ -814,6 +814,15 @@ nix.checkConfig previously did. + + + nix.buildMachines got a new submodule + option protocol. An undocumented hack to + set the protocol via hostName is no longer + working and the protocol option should be + used instead. + + generateOptparseApplicativeCompletions and diff --git a/nixos/doc/manual/release-notes/rl-2211.section.md b/nixos/doc/manual/release-notes/rl-2211.section.md index f8442be4351d..fccb00ff0156 100644 --- a/nixos/doc/manual/release-notes/rl-2211.section.md +++ b/nixos/doc/manual/release-notes/rl-2211.section.md @@ -266,6 +266,8 @@ Available as [services.patroni](options.html#opt-services.patroni.enable). - The `nix.checkConfig` option now fully disables the config check. The new `nix.checkAllErrors` option behaves like `nix.checkConfig` previously did. +- `nix.buildMachines` got a new submodule option `protocol`. An undocumented hack to set the protocol via `hostName` is no longer working and the `protocol` option should be used instead. + - `generateOptparseApplicativeCompletions` and `generateOptparseApplicativeCompletion` from `haskell.lib.compose` (and `haskell.lib`) have been deprecated in favor of `generateOptparseApplicativeCompletions` (plural!) as provided by the haskell package sets (so `haskellPackages.generateOptparseApplicativeCompletions` etc.). From 43b3cb7aed55aa23034a0fc7eb1865ab928a9504 Mon Sep 17 00:00:00 2001 From: Vonfry Date: Sun, 27 Nov 2022 14:26:24 +0800 Subject: [PATCH 08/38] tdlib: 1.8.7 -> 1.8.8 (cherry picked from commit dde0ac4ca9227ffe33b754b3c83566c0f2fb1d70) --- pkgs/development/libraries/tdlib/default.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/development/libraries/tdlib/default.nix b/pkgs/development/libraries/tdlib/default.nix index afbdc374ce49..ca0f98acc2e5 100644 --- a/pkgs/development/libraries/tdlib/default.nix +++ b/pkgs/development/libraries/tdlib/default.nix @@ -2,7 +2,7 @@ stdenv.mkDerivation rec { pname = "tdlib"; - version = "1.8.7"; + version = "1.8.8"; src = fetchFromGitHub { owner = "tdlib"; @@ -11,8 +11,8 @@ stdenv.mkDerivation rec { # The tdlib authors do not set tags for minor versions, but # external programs depending on tdlib constrain the minor # version, hence we set a specific commit with a known version. - rev = "a7a17b34b3c8fd3f7f6295f152746beb68f34d83"; - sha256 = "sha256:0a5609knn7rmiiblz315yrvc9f2r207l2nl6brjy5bnhjdspmzs6"; + rev = "bbe37ee594d97f3c7820dd23ebcd9c9b8dac51a0"; + sha256 = "jLJglvq+7f+zCoanDRTFpUsH/M1Qf7PWJ1JjvmZsa24="; }; buildInputs = [ gperf openssl readline zlib ]; From afbae2b22db83472030b6e60ec612fb5bec39e22 Mon Sep 17 00:00:00 2001 From: Francesco Gazzetta Date: Sat, 26 Nov 2022 21:23:37 +0100 Subject: [PATCH 09/38] soundtracker: 1.0.2.1 -> 1.0.3 (cherry picked from commit ce571fce9f505981debcc7efda9432654b1135e0) --- pkgs/applications/audio/soundtracker/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/audio/soundtracker/default.nix b/pkgs/applications/audio/soundtracker/default.nix index 251725ea6b29..48acd5517179 100644 --- a/pkgs/applications/audio/soundtracker/default.nix +++ b/pkgs/applications/audio/soundtracker/default.nix @@ -12,7 +12,7 @@ stdenv.mkDerivation rec { pname = "soundtracker"; - version = "1.0.2.1"; + version = "1.0.3"; src = fetchurl { # Past releases get moved to the "old releases" directory. @@ -20,7 +20,7 @@ stdenv.mkDerivation rec { # Nonetheless, only the name of the file seems to affect which file is # downloaded, so this path should be fine both for old and current releases. url = "mirror://sourceforge/soundtracker/soundtracker-${version}.tar.xz"; - sha256 = "0nh0dwz8nldc040q6n06vlazhss8ms42r2dffhjcrqj3hbrvfx82"; + sha256 = "sha256-k+TB1DIauOIeQSCVV5uYu69wwRx7vCRAlSCTAtDguKo="; }; postPatch = lib.optionalString stdenv.hostPlatform.isDarwin '' From fd49c6417876440697fbe867ae925747ed103cf3 Mon Sep 17 00:00:00 2001 From: Amneesh Singh Date: Tue, 22 Nov 2022 17:52:03 +0530 Subject: [PATCH 10/38] yuzu-mainline: 1162 -> 1245 Signed-off-by: Amneesh Singh (cherry picked from commit 98cd1161b0ac02cb490904315470d4036c51f914) --- pkgs/applications/emulators/yuzu/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/emulators/yuzu/default.nix b/pkgs/applications/emulators/yuzu/default.nix index 7650ebad343d..8dae647b89d6 100644 --- a/pkgs/applications/emulators/yuzu/default.nix +++ b/pkgs/applications/emulators/yuzu/default.nix @@ -15,13 +15,13 @@ let in { mainline = libsForQt5.callPackage ./generic.nix rec { pname = "yuzu-mainline"; - version = "1162"; + version = "1245"; src = fetchFromGitHub { owner = "yuzu-emu"; repo = "yuzu-mainline"; rev = "mainline-0-${version}"; - sha256 = "sha256-1UNgB/3l6RN0OLRrmXqzwcEUgXlWGSE7PvHbZ8YSDro="; + sha256 = "sha256-lWXlY1KQC067MvCRUFhmr0c7KDrHDuwJOhIWMKw1f+A="; fetchSubmodules = true; }; From dbb36247db213acfd733b9d31903ac70a58455a2 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 28 Nov 2022 09:50:51 +0000 Subject: [PATCH 11/38] electron-mail: 5.0.1 -> 5.1.2 (cherry picked from commit 1a25877c44aa664ebba7c58a9d91c8873ef4f9d3) --- .../networking/mailreaders/electron-mail/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/networking/mailreaders/electron-mail/default.nix b/pkgs/applications/networking/mailreaders/electron-mail/default.nix index f454a8b43daf..3cce58258a8a 100644 --- a/pkgs/applications/networking/mailreaders/electron-mail/default.nix +++ b/pkgs/applications/networking/mailreaders/electron-mail/default.nix @@ -2,12 +2,12 @@ let pname = "electron-mail"; - version = "5.0.1"; + version = "5.1.2"; name = "ElectronMail-${version}"; src = fetchurl { url = "https://github.com/vladimiry/ElectronMail/releases/download/v${version}/electron-mail-${version}-linux-x86_64.AppImage"; - sha256 = "sha256-w6ZZPIJnAlA8WhNHtM9gsjr7U6wMYT21fGFmkDDAVJU="; + sha256 = "sha256-PLDzAtH7T7QMrLavvcF3zOVTayCqEA1IghIUAAxkbEE="; }; appimageContents = appimageTools.extract { inherit name src; }; From 70ef4eba89c23a2aae142c8cc59c4b8994e44702 Mon Sep 17 00:00:00 2001 From: K900 Date: Tue, 29 Nov 2022 17:02:49 +0300 Subject: [PATCH 12/38] plasma: 5.26.3 -> 5.26.4 Minor bug fixes all over the place. (cherry picked from commit 8b542d1f936ebea47560f4406066e54beb9fbb62) --- pkgs/desktops/plasma-5/fetch.sh | 2 +- pkgs/desktops/plasma-5/srcs.nix | 464 ++++++++++++++++---------------- 2 files changed, 233 insertions(+), 233 deletions(-) diff --git a/pkgs/desktops/plasma-5/fetch.sh b/pkgs/desktops/plasma-5/fetch.sh index eb91ba4838fb..da393659b7c4 100644 --- a/pkgs/desktops/plasma-5/fetch.sh +++ b/pkgs/desktops/plasma-5/fetch.sh @@ -1 +1 @@ -WGET_ARGS=( https://download.kde.org/stable/plasma/5.26.3/ -A '*.tar.xz' ) +WGET_ARGS=( https://download.kde.org/stable/plasma/5.26.4/ -A '*.tar.xz' ) diff --git a/pkgs/desktops/plasma-5/srcs.nix b/pkgs/desktops/plasma-5/srcs.nix index 0d5a6010e6fe..f0b263ae4cf4 100644 --- a/pkgs/desktops/plasma-5/srcs.nix +++ b/pkgs/desktops/plasma-5/srcs.nix @@ -4,467 +4,467 @@ { aura-browser = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/aura-browser-5.26.3.tar.xz"; - sha256 = "0103avsjplj6zmjql4gcgh2lrmmx87k3dx0wl371vqdf1prgbv2z"; - name = "aura-browser-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/aura-browser-5.26.4.tar.xz"; + sha256 = "1gpv2vb0xkjshkg2xyyg3s731kx6268rc5c10gm927129il1p9fs"; + name = "aura-browser-5.26.4.tar.xz"; }; }; bluedevil = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/bluedevil-5.26.3.tar.xz"; - sha256 = "1f2dh7d0ds5n8vcnrkx919yvf5g3yrl6zg2rfaiac9vff04afcpj"; - name = "bluedevil-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/bluedevil-5.26.4.tar.xz"; + sha256 = "1886nlxszraixsxyg7kn7qzqjwiwxnn6dgbrxw1797z1w4s6s7my"; + name = "bluedevil-5.26.4.tar.xz"; }; }; breeze = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/breeze-5.26.3.tar.xz"; - sha256 = "0wn5m8avs1ncvx70lrh5gafnq7sdfd18rvih95cpdbqqs4y222a5"; - name = "breeze-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/breeze-5.26.4.tar.xz"; + sha256 = "0sq0b2535d7d8p7ndi3i1k7ix3790mpkqmp1gcfs0a4jni43y2bc"; + name = "breeze-5.26.4.tar.xz"; }; }; breeze-grub = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/breeze-grub-5.26.3.tar.xz"; - sha256 = "0qnxcwina2m4imgm02yq2yn2ax2rwncp511gihx49h97cy9yx7i5"; - name = "breeze-grub-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/breeze-grub-5.26.4.tar.xz"; + sha256 = "1dl98dwz5l2vljfj41kigngdpfgkrbs09hdmr7dqj8qx1vkfdrp8"; + name = "breeze-grub-5.26.4.tar.xz"; }; }; breeze-gtk = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/breeze-gtk-5.26.3.tar.xz"; - sha256 = "0qrz7kkkv00rmaja6a1dmrldy6nfshdsx56k3vji00fwpi03nfja"; - name = "breeze-gtk-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/breeze-gtk-5.26.4.tar.xz"; + sha256 = "0kc1dxpp5n1rkik1amkdbci6kivqzzlh9bb53ikixbj3rp2h8g31"; + name = "breeze-gtk-5.26.4.tar.xz"; }; }; breeze-plymouth = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/breeze-plymouth-5.26.3.tar.xz"; - sha256 = "0n6skqay6c84411n2hi9sibyhiiqisl2kmd5lwbv748h4x311yz8"; - name = "breeze-plymouth-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/breeze-plymouth-5.26.4.tar.xz"; + sha256 = "0h96dcdqgdzqxcrzc4805l14p463ks5zjnvh3r1j73gs8cbrwsxd"; + name = "breeze-plymouth-5.26.4.tar.xz"; }; }; discover = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/discover-5.26.3.tar.xz"; - sha256 = "1p9l6q68kyzm40hg6nhp2jsqx6mjscixj1fkmibphj3ps10xsgqf"; - name = "discover-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/discover-5.26.4.tar.xz"; + sha256 = "1hl85770yq1bld0x085mqyznq5cjvr7csx9pj9q4783hrjhkvdwc"; + name = "discover-5.26.4.tar.xz"; }; }; drkonqi = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/drkonqi-5.26.3.tar.xz"; - sha256 = "0897fkxa3gd7hbvx4h5hhwnxwycgcciyp02aw5m2gmyylav97pb4"; - name = "drkonqi-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/drkonqi-5.26.4.tar.xz"; + sha256 = "0p8k9q5mglw4sq2ybi7yy1brjn3p6kkl09smh1fwvpkifg64mv3d"; + name = "drkonqi-5.26.4.tar.xz"; }; }; kactivitymanagerd = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/kactivitymanagerd-5.26.3.tar.xz"; - sha256 = "1wv6b5shm8741phhhfldrwzb8pm4jskd3sq242pg8230qh054vrc"; - name = "kactivitymanagerd-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/kactivitymanagerd-5.26.4.tar.xz"; + sha256 = "1k15cf0l3cji5y0xkh0sx2xwpc7v77zsj25c3yxydxg03mgq01l4"; + name = "kactivitymanagerd-5.26.4.tar.xz"; }; }; kde-cli-tools = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/kde-cli-tools-5.26.3.tar.xz"; - sha256 = "0h76w9nkcc4d15lh7yz260vfh3fv9apx5d7i5m75pb4z9mgcpgzv"; - name = "kde-cli-tools-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/kde-cli-tools-5.26.4.tar.xz"; + sha256 = "0kyq3jm3mr8wdcjamswp6hqfh7g7kry28v344y0r9v052d8nvj8z"; + name = "kde-cli-tools-5.26.4.tar.xz"; }; }; kde-gtk-config = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/kde-gtk-config-5.26.3.tar.xz"; - sha256 = "1fkiqf92222vsbrq15skn6cynni312r7clbr2xrsxnygwbvsqni7"; - name = "kde-gtk-config-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/kde-gtk-config-5.26.4.tar.xz"; + sha256 = "057kfkblngafipar0qpzz5psmq2cq0d8y9vg0451i84kpignggsk"; + name = "kde-gtk-config-5.26.4.tar.xz"; }; }; kdecoration = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/kdecoration-5.26.3.tar.xz"; - sha256 = "0ngcqfp0qy8dmd7df35xw5m2pz5azzvpsj0raby370j76s8l92wi"; - name = "kdecoration-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/kdecoration-5.26.4.tar.xz"; + sha256 = "0p988y6qw1xiccfcimrdqivc1h1vnfaj3208j157h1kfg40kpz48"; + name = "kdecoration-5.26.4.tar.xz"; }; }; kdeplasma-addons = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/kdeplasma-addons-5.26.3.tar.xz"; - sha256 = "13j79097j2x8cmssqikiwlxkkajaj8nnw4md6vl4f51qnrz7h7f4"; - name = "kdeplasma-addons-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/kdeplasma-addons-5.26.4.tar.xz"; + sha256 = "183xxr55j3s8nr9cgpdm34d7jm4ijrj6jf3r1mvkih992iryk11r"; + name = "kdeplasma-addons-5.26.4.tar.xz"; }; }; kgamma5 = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/kgamma5-5.26.3.tar.xz"; - sha256 = "0pjyqrily8in109ys2bawm3cr0vn4ig788h100l3953wg15alv47"; - name = "kgamma5-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/kgamma5-5.26.4.tar.xz"; + sha256 = "0my9jbd6iw1k0jmg2b05k31mv6my1yzqg6ks9kysmsr28d3kgsll"; + name = "kgamma5-5.26.4.tar.xz"; }; }; khotkeys = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/khotkeys-5.26.3.tar.xz"; - sha256 = "0pwmf35qfz2vrvc5gwwibxjwwpc5lvlihba77cj6lfw1hn9h203m"; - name = "khotkeys-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/khotkeys-5.26.4.tar.xz"; + sha256 = "1kr0bwjghs3a1ibjbd6sh3jjlmy573y4jhld88wdyi69smq28lzh"; + name = "khotkeys-5.26.4.tar.xz"; }; }; kinfocenter = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/kinfocenter-5.26.3.tar.xz"; - sha256 = "0fmc34n9yvkrfhgp0akjd9y7mkhjl8jfl485kfij5rrc14zyln65"; - name = "kinfocenter-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/kinfocenter-5.26.4.tar.xz"; + sha256 = "0hq5mzxlz3711k14bd5y99mcdipvy25himbzxqm09b5wpn0yihcr"; + name = "kinfocenter-5.26.4.tar.xz"; }; }; kmenuedit = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/kmenuedit-5.26.3.tar.xz"; - sha256 = "0bapsrfi9fhj8gw8qbs3f538l1kpawv3k2avkk87zy9cvi9kh1vw"; - name = "kmenuedit-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/kmenuedit-5.26.4.tar.xz"; + sha256 = "1869i7bv40di5axlr5xwmv3xnaja1r84h1f9xh8rqmhz1kv2d2y8"; + name = "kmenuedit-5.26.4.tar.xz"; }; }; kpipewire = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/kpipewire-5.26.3.tar.xz"; - sha256 = "193wrnz4v8zqi95laa9jpbnd2kmf1y40a57yyhfjhawfijinba5l"; - name = "kpipewire-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/kpipewire-5.26.4.tar.xz"; + sha256 = "0d7nlmq5h0kd0lrkv4lc673prchyips2j3jc6igbxyk3v1blw9s6"; + name = "kpipewire-5.26.4.tar.xz"; }; }; kscreen = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/kscreen-5.26.3.tar.xz"; - sha256 = "05dcff125vklawf3b8hirbp7fwhjqnpqrlkkaqsxf7w99p3s6bss"; - name = "kscreen-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/kscreen-5.26.4.tar.xz"; + sha256 = "1766yqbvm021i4g6fyrm9a2cxdkb6q3pr7igvj7bb8ga3y44ip6p"; + name = "kscreen-5.26.4.tar.xz"; }; }; kscreenlocker = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/kscreenlocker-5.26.3.tar.xz"; - sha256 = "0sa56dyxa7mg76z41dn5w7z1snsyqwyxh0nq32izi9bm20zd2f6f"; - name = "kscreenlocker-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/kscreenlocker-5.26.4.tar.xz"; + sha256 = "0mz8av4pccnpd7pj3l30isi31s8nram7ymn4hacsmwgzhmqfn9m1"; + name = "kscreenlocker-5.26.4.tar.xz"; }; }; ksshaskpass = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/ksshaskpass-5.26.3.tar.xz"; - sha256 = "05kwcwny6lx459p149nwgv09hzjb6w24jafqzxa6rk1k1fb0x5wi"; - name = "ksshaskpass-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/ksshaskpass-5.26.4.tar.xz"; + sha256 = "05rdqkr6iyfyxgb5dxwsbhb91ni9fp7ysm73wgj4f40azkk9j91i"; + name = "ksshaskpass-5.26.4.tar.xz"; }; }; ksystemstats = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/ksystemstats-5.26.3.tar.xz"; - sha256 = "0il22sx3clkksri9z0k41ssqhb07qvfipnymckja90m70npqb2a2"; - name = "ksystemstats-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/ksystemstats-5.26.4.tar.xz"; + sha256 = "0amzb79kba310myc18g6gdfakmzqmlzvmd3c42yz71vjfpywibr3"; + name = "ksystemstats-5.26.4.tar.xz"; }; }; kwallet-pam = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/kwallet-pam-5.26.3.tar.xz"; - sha256 = "03haxcdsjwydb1l27lzizk8bqqhyf313044p4f94ii8gdgg1w8l5"; - name = "kwallet-pam-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/kwallet-pam-5.26.4.tar.xz"; + sha256 = "0z661sa0bwd30c3jfq0n00jfrhb1mxm7107w23r2hyrdi4i8dsjb"; + name = "kwallet-pam-5.26.4.tar.xz"; }; }; kwayland-integration = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/kwayland-integration-5.26.3.tar.xz"; - sha256 = "0hy6xv1009vcmypqaga8mzfsh4nybsrvm107g261hww43qyx2wg5"; - name = "kwayland-integration-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/kwayland-integration-5.26.4.tar.xz"; + sha256 = "10p9i7vihigdj63m48lk6c9f56jz1y5sar5lqnr5f9ai7s6na6gh"; + name = "kwayland-integration-5.26.4.tar.xz"; }; }; kwin = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/kwin-5.26.3.tar.xz"; - sha256 = "050a5j0dm131a45lggiw47mllzzm4fxf2m1mv5csazzwjrbmz661"; - name = "kwin-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/kwin-5.26.4.tar.xz"; + sha256 = "1f80sfzaphcdq0dg1k8wyl6gnxap98yhiwcgski6x4gy0rhdnl16"; + name = "kwin-5.26.4.tar.xz"; }; }; kwrited = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/kwrited-5.26.3.tar.xz"; - sha256 = "0jznp1r92z22vk5zqwjh1fk6j5jzw4vygzjjlm4yv426izkw2xdj"; - name = "kwrited-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/kwrited-5.26.4.tar.xz"; + sha256 = "1w1yr8adpwx4m118x0w5890yph0n4gi0wdf99d5vhjd8yjcrb1s2"; + name = "kwrited-5.26.4.tar.xz"; }; }; layer-shell-qt = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/layer-shell-qt-5.26.3.tar.xz"; - sha256 = "10d4vi70z27n434d71n38m1l8dgdk33155yk97d7rsaicg7s1hq2"; - name = "layer-shell-qt-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/layer-shell-qt-5.26.4.tar.xz"; + sha256 = "1hb0fbj9lf3vdfq31y9b6cy4qpzmv30cf1jbvy55rgyhqnk8il7b"; + name = "layer-shell-qt-5.26.4.tar.xz"; }; }; libkscreen = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/libkscreen-5.26.3.tar.xz"; - sha256 = "1nfpa4h8yhrkfq39qzlbpfkxp1qvd5k11jv4sgdqv0fs99g8xhzf"; - name = "libkscreen-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/libkscreen-5.26.4.tar.xz"; + sha256 = "1w3qhg3q2g6b0dngcq5cm1jghbkqpcyzn9yicrhcllmcp3v540mv"; + name = "libkscreen-5.26.4.tar.xz"; }; }; libksysguard = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/libksysguard-5.26.3.tar.xz"; - sha256 = "1lbngciln6q66g2q48xcl7m1j7rb2yjrncpaidr6464a8vffwh69"; - name = "libksysguard-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/libksysguard-5.26.4.tar.xz"; + sha256 = "1s5mhnq4vinc2znw2fw45ydljwzy55shjf083s4lnvmj7smlp5gb"; + name = "libksysguard-5.26.4.tar.xz"; }; }; milou = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/milou-5.26.3.tar.xz"; - sha256 = "12wjbvw72033havjq91i2prcj4yjynh6h2lc2z6ba9zsp6rsgk41"; - name = "milou-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/milou-5.26.4.tar.xz"; + sha256 = "0scx0207jf11w1j8ja7sxfxnkjm5j3g23ip28gmf2q01py05rg00"; + name = "milou-5.26.4.tar.xz"; }; }; oxygen = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/oxygen-5.26.3.tar.xz"; - sha256 = "1hczm502afy9ps5qq6pq0zdzvdyn2gsr17072q530fi9mzljbdch"; - name = "oxygen-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/oxygen-5.26.4.tar.xz"; + sha256 = "1lj34gccgjqf327732wd5dlk4chpxpdl5w8ci86zd2js42d4gyhk"; + name = "oxygen-5.26.4.tar.xz"; }; }; oxygen-sounds = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/oxygen-sounds-5.26.3.tar.xz"; - sha256 = "015mn6smrc5ii5jq8yajqi0ndlaci48cy289ks8q5qspvfd99hrs"; - name = "oxygen-sounds-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/oxygen-sounds-5.26.4.tar.xz"; + sha256 = "0c2w5y77jrzmxkd8bv8b95y67i0kjm4kc84wla574s57lcjwyn12"; + name = "oxygen-sounds-5.26.4.tar.xz"; }; }; plank-player = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/plank-player-5.26.3.tar.xz"; - sha256 = "16lmsmg6d363giyfw0vwbyznx27fy8p4cvmpgqdzq23zhc20axnm"; - name = "plank-player-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/plank-player-5.26.4.tar.xz"; + sha256 = "0b2ss5fj85gf0gnw0xpwrkib1r68nmkvzakk3qgbc9dmgjfbi3wp"; + name = "plank-player-5.26.4.tar.xz"; }; }; plasma-bigscreen = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/plasma-bigscreen-5.26.3.tar.xz"; - sha256 = "13mr8xkmvq0lh6fc103nzirkgda3gpry1qwy3azvw65bxxakf7wq"; - name = "plasma-bigscreen-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/plasma-bigscreen-5.26.4.tar.xz"; + sha256 = "0kfnh7cy6v8qczvz4z6isy3bx3zrlkz32hwyy3idinpgqih6cm5s"; + name = "plasma-bigscreen-5.26.4.tar.xz"; }; }; plasma-browser-integration = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/plasma-browser-integration-5.26.3.tar.xz"; - sha256 = "1bwdl6dzz6cj9753cgivrz1ajxy6qn59g5la4icfp7kn945zw7zm"; - name = "plasma-browser-integration-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/plasma-browser-integration-5.26.4.tar.xz"; + sha256 = "0fcz8snq3i4q9bpyd9nw7a1n50bh1sw3qp1sgyz0vp13rcic7fph"; + name = "plasma-browser-integration-5.26.4.tar.xz"; }; }; plasma-desktop = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/plasma-desktop-5.26.3.tar.xz"; - sha256 = "1lsw17rkwb91v1kaqg627rg6i3a56q2izj66fcgfy9fl34sc4x31"; - name = "plasma-desktop-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/plasma-desktop-5.26.4.tar.xz"; + sha256 = "1llk8bjihjny52f5q9qanp5if3az3mz9slxbrn7882c0xghhr6ba"; + name = "plasma-desktop-5.26.4.tar.xz"; }; }; plasma-disks = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/plasma-disks-5.26.3.tar.xz"; - sha256 = "0gjbhnf74vnd1d1zfbdha9qx0jddx8621z80czyrn0b6yz28pmgm"; - name = "plasma-disks-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/plasma-disks-5.26.4.tar.xz"; + sha256 = "1mgmqvlwy7nml51l9siw900lg4j85a2djjjcr7bw3mbqnxny5wgj"; + name = "plasma-disks-5.26.4.tar.xz"; }; }; plasma-firewall = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/plasma-firewall-5.26.3.tar.xz"; - sha256 = "0ra23mv2n2bsq5hsyl9biiak2s1ii3fpxhbbmyzakp3dnln0vkwx"; - name = "plasma-firewall-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/plasma-firewall-5.26.4.tar.xz"; + sha256 = "1iz45gq322r1kb1hps51mjid2k1wqk4amxbv5xlcdlfdwqr7agc1"; + name = "plasma-firewall-5.26.4.tar.xz"; }; }; plasma-integration = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/plasma-integration-5.26.3.tar.xz"; - sha256 = "1vfs6hw9pswxgjln13kj5l7hqfh3m40vqrh0yz3zzs574bfj61y7"; - name = "plasma-integration-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/plasma-integration-5.26.4.tar.xz"; + sha256 = "0gdzkxscll22s2jj3q4wlz18zb3bm5xsxvikss5phdyw4ppc2qsy"; + name = "plasma-integration-5.26.4.tar.xz"; }; }; plasma-mobile = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/plasma-mobile-5.26.3.tar.xz"; - sha256 = "0l4m281bsilswvzhp849x6qnpvzc632p1mlarhwh40gak9ymjx0h"; - name = "plasma-mobile-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/plasma-mobile-5.26.4.tar.xz"; + sha256 = "15q6v8vnn45y84jnrkarr3v9x9hng2slxdp5nr1xsa80pvb1j23x"; + name = "plasma-mobile-5.26.4.tar.xz"; }; }; plasma-nano = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/plasma-nano-5.26.3.tar.xz"; - sha256 = "1n2nfl8s9vrsr919cpz2pji4f8fa6cmlp5qybib490mnwlw6vy7k"; - name = "plasma-nano-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/plasma-nano-5.26.4.tar.xz"; + sha256 = "15jxj90mg3jkx1jmf1dadss3nd9rvjqqr0vvfm5yyf0m45sb11xs"; + name = "plasma-nano-5.26.4.tar.xz"; }; }; plasma-nm = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/plasma-nm-5.26.3.tar.xz"; - sha256 = "1q21lnl5y3dm73pl7586bg7whc9fk540ajm3hy0x4p10q28y7yyc"; - name = "plasma-nm-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/plasma-nm-5.26.4.tar.xz"; + sha256 = "1x1xcf33jfl01cf1pmz3mbzyzbmchk780wwlij9wva9pbnxg97hy"; + name = "plasma-nm-5.26.4.tar.xz"; }; }; plasma-pa = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/plasma-pa-5.26.3.tar.xz"; - sha256 = "01q8jbbdi1hqa6wx8bhas7qzqg3v5mkqrj3lmaq56qvp9rjyg8ik"; - name = "plasma-pa-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/plasma-pa-5.26.4.tar.xz"; + sha256 = "0h0rbgcnh16m31wnfklmy2gks4njxy3rlx1kpn6a2q1zzgs3ri3a"; + name = "plasma-pa-5.26.4.tar.xz"; }; }; plasma-remotecontrollers = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/plasma-remotecontrollers-5.26.3.tar.xz"; - sha256 = "0hmacs0927pqhxmv89p96g5c71ic2wsn7byvbnp9w9gp4wbgkwc2"; - name = "plasma-remotecontrollers-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/plasma-remotecontrollers-5.26.4.tar.xz"; + sha256 = "1pkcwx1br4flga1xlj807aapq274522f2jcl96hlaz1i5w9c4ids"; + name = "plasma-remotecontrollers-5.26.4.tar.xz"; }; }; plasma-sdk = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/plasma-sdk-5.26.3.tar.xz"; - sha256 = "0s71clqpc9ncqcz6pjkv4r0zk4v2bl72i1s6mxr7z9qxmhhmi41f"; - name = "plasma-sdk-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/plasma-sdk-5.26.4.tar.xz"; + sha256 = "1pm8j2nz3a6icj1pm2lxidldyza4v3j5pq3xaf1pjs9n3vd8j8b5"; + name = "plasma-sdk-5.26.4.tar.xz"; }; }; plasma-systemmonitor = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/plasma-systemmonitor-5.26.3.tar.xz"; - sha256 = "11dvzjr083c3ds4cq2ws7d3365c3hdqdpw0r9sca94grs64jigwz"; - name = "plasma-systemmonitor-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/plasma-systemmonitor-5.26.4.tar.xz"; + sha256 = "1harn31ia6fsa6wq13mpxxnnw4w98vmspaqmss1a7187hafislf9"; + name = "plasma-systemmonitor-5.26.4.tar.xz"; }; }; plasma-tests = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/plasma-tests-5.26.3.tar.xz"; - sha256 = "1m71rhvfl1yls8vlyxpfs7z3aavf42a0lyg94rmb7awzp4qkf7zv"; - name = "plasma-tests-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/plasma-tests-5.26.4.tar.xz"; + sha256 = "0h6kk0h64v34vxwa5z466fz2a90sni2sn08rjcpavbhq3rrz16pb"; + name = "plasma-tests-5.26.4.tar.xz"; }; }; plasma-thunderbolt = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/plasma-thunderbolt-5.26.3.tar.xz"; - sha256 = "1w0b124xkh8g9kivlxwasb4iqpp5spm40y5hdz08r8faw065fn6g"; - name = "plasma-thunderbolt-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/plasma-thunderbolt-5.26.4.tar.xz"; + sha256 = "1g2ppkcp10yrvsy8hd9ylfvbajbj8ixv1y31810qbf8svbg6ihdv"; + name = "plasma-thunderbolt-5.26.4.tar.xz"; }; }; plasma-vault = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/plasma-vault-5.26.3.tar.xz"; - sha256 = "09mljjn7z8vbwzfhdxbjnkr8r4anplbb3di2vvfwcgn0yn2m4hmf"; - name = "plasma-vault-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/plasma-vault-5.26.4.tar.xz"; + sha256 = "14nf0il3mg23dsbxifnzxxs5lks7zmifnvrny240nvnfwmh58hz4"; + name = "plasma-vault-5.26.4.tar.xz"; }; }; plasma-workspace = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/plasma-workspace-5.26.3.tar.xz"; - sha256 = "0ly96nxdiw5sndb1ga2ngqr4s5sslg8gi9ikp0nq4h75wfc1wb0a"; - name = "plasma-workspace-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/plasma-workspace-5.26.4.tar.xz"; + sha256 = "06pbghl8gpq63gg9jj29jsizgfq7bcqj9kx48gkqcwvd9gd1q1f9"; + name = "plasma-workspace-5.26.4.tar.xz"; }; }; plasma-workspace-wallpapers = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/plasma-workspace-wallpapers-5.26.3.tar.xz"; - sha256 = "1qrwfn8r845giganv9gk7v75827q9js8sygc0dvijg2ilmr56d31"; - name = "plasma-workspace-wallpapers-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/plasma-workspace-wallpapers-5.26.4.tar.xz"; + sha256 = "1plw7hxcyl68gwcf2vh650lady4syz75sbhmj97a60nw2fwlxyvv"; + name = "plasma-workspace-wallpapers-5.26.4.tar.xz"; }; }; plymouth-kcm = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/plymouth-kcm-5.26.3.tar.xz"; - sha256 = "14np3wnca4nmcr74zbkrnysbfsrbrhxaf0hb96f4rn391kj5m635"; - name = "plymouth-kcm-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/plymouth-kcm-5.26.4.tar.xz"; + sha256 = "0kqv4kwsw7j7f1jf0nqr65rgzwd1ps5ax37m9ama1vrcvd87fsma"; + name = "plymouth-kcm-5.26.4.tar.xz"; }; }; polkit-kde-agent = { - version = "1-5.26.3"; + version = "1-5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/polkit-kde-agent-1-5.26.3.tar.xz"; - sha256 = "0wd6yjd1qgiqjvvdn575zaa4c3szigk91d5l7a4c4kg4x5yb161g"; - name = "polkit-kde-agent-1-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/polkit-kde-agent-1-5.26.4.tar.xz"; + sha256 = "1v07l94jnlcyslq0asy8p3g0wd459rbh1f68icn9r1kcfw8cc1as"; + name = "polkit-kde-agent-1-5.26.4.tar.xz"; }; }; powerdevil = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/powerdevil-5.26.3.tar.xz"; - sha256 = "0190rygc748av81iw2a3bl3zkawl0wjpx0761lagvrdj7hm3x35v"; - name = "powerdevil-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/powerdevil-5.26.4.tar.xz"; + sha256 = "1samnxv1qiqna2zgzl3pm3bf7br86nrpyvgbcvlsiv03aqbq77x3"; + name = "powerdevil-5.26.4.tar.xz"; }; }; qqc2-breeze-style = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/qqc2-breeze-style-5.26.3.tar.xz"; - sha256 = "04nx8519g6dwvacyp8x6n2av4wp65kshqbvbfy32f61lildhkg9c"; - name = "qqc2-breeze-style-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/qqc2-breeze-style-5.26.4.tar.xz"; + sha256 = "1q3vmp5g1qmmry5i4gbsfnqwc9287hf8jkmipk6ka5cf6pn0z0qa"; + name = "qqc2-breeze-style-5.26.4.tar.xz"; }; }; sddm-kcm = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/sddm-kcm-5.26.3.tar.xz"; - sha256 = "1xfkwqs0aljk1wdmgvw9vqm50d43svlzrkhh7cacy94z9jnaaxia"; - name = "sddm-kcm-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/sddm-kcm-5.26.4.tar.xz"; + sha256 = "1sqlwxhff538m6nsglxxkhnmngvfjhavmh6lqapvfsyzkyxxd8fb"; + name = "sddm-kcm-5.26.4.tar.xz"; }; }; systemsettings = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/systemsettings-5.26.3.tar.xz"; - sha256 = "1clqw087nk47gb7qbbmc0s9ks2k5ch5ssim2smz7j6gn3d9n3qy3"; - name = "systemsettings-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/systemsettings-5.26.4.tar.xz"; + sha256 = "1wl0krqq1865pndvlxs031ki123c3idnmhxrqffrwvk3d74lrn0m"; + name = "systemsettings-5.26.4.tar.xz"; }; }; xdg-desktop-portal-kde = { - version = "5.26.3"; + version = "5.26.4"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.3/xdg-desktop-portal-kde-5.26.3.tar.xz"; - sha256 = "1lx73k85ysyyscz1rpdrw3gq8vj16xsgbcz7gs36qcvzhwvg5pjp"; - name = "xdg-desktop-portal-kde-5.26.3.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/xdg-desktop-portal-kde-5.26.4.tar.xz"; + sha256 = "173z3i0jkm157imw4m25ip0gac325d25gjswc82dza3x2mmisdk3"; + name = "xdg-desktop-portal-kde-5.26.4.tar.xz"; }; }; } From d7a5a0bee5706d1cb70ffc138ee34dc2acfd03c7 Mon Sep 17 00:00:00 2001 From: Vincent Laporte Date: Wed, 23 Nov 2022 06:28:16 +0100 Subject: [PATCH 13/38] =?UTF-8?q?ocamlPackages.calendar:=202.5=20=E2=86=92?= =?UTF-8?q?=203.0?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit (cherry picked from commit 7d49f04d1c4fd83b25dfa8f8455c363588fd5c36) --- .../ocaml-modules/calendar/default.nix | 32 +++++++++---------- 1 file changed, 15 insertions(+), 17 deletions(-) diff --git a/pkgs/development/ocaml-modules/calendar/default.nix b/pkgs/development/ocaml-modules/calendar/default.nix index 4c089b76f3ed..cf349eeb8bb1 100644 --- a/pkgs/development/ocaml-modules/calendar/default.nix +++ b/pkgs/development/ocaml-modules/calendar/default.nix @@ -1,27 +1,25 @@ -{ stdenv, lib, fetchurl, ocaml, findlib }: +{ lib, buildDunePackage, fetchFromGitHub, re }: -stdenv.mkDerivation rec { - pname = "ocaml-calendar"; - version = "2.5"; +buildDunePackage rec { + pname = "calendar"; + version = "3.0.0"; + minimalOCamlVersion = "4.03"; - src = fetchurl { - url = "https://forge.ocamlcore.org/frs/download.php/915/calendar-${version}.tar.bz2"; - sha256 = "04pvhwb664g3s644c7v7419a3kvf5s3pynkhmk5j59dvlfm1yf0f"; + src = fetchFromGitHub { + owner = "ocaml-community"; + repo = pname; + rev = "v${version}"; + sha256 = "sha256-+VQzi6pEMqzV1ZR84Yjdu4jsJEWtx+7bd6PQGX7TiEs="; }; - nativeBuildInputs = [ ocaml findlib ]; + propagatedBuildInputs = [ re ]; strictDeps = true; - createFindlibDestdir = true; - meta = { - homepage = "https://forge.ocamlcore.org/projects/calendar/"; - description = "An Objective Caml library managing dates and times"; - license = "LGPL"; - platforms = ocaml.meta.platforms or [ ]; - maintainers = [ - lib.maintainers.gal_bolle - ]; + inherit (src.meta) homepage; + description = "A library for handling dates and times"; + license = lib.licenses.lgpl21Plus; + maintainers = [ lib.maintainers.gal_bolle ]; }; } From d94950082fe0340d5df48ae8f1355bc0f172d499 Mon Sep 17 00:00:00 2001 From: Peter Hoeg Date: Wed, 30 Nov 2022 11:59:38 +0800 Subject: [PATCH 14/38] plasma-workspace: 5.26.4 -> 5.26.4.1 (cherry picked from commit 16f1d25e44baa62cb16f74ad9515122d293d25ea) --- pkgs/desktops/plasma-5/srcs.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/desktops/plasma-5/srcs.nix b/pkgs/desktops/plasma-5/srcs.nix index f0b263ae4cf4..ae1dd2433625 100644 --- a/pkgs/desktops/plasma-5/srcs.nix +++ b/pkgs/desktops/plasma-5/srcs.nix @@ -396,11 +396,11 @@ }; }; plasma-workspace = { - version = "5.26.4"; + version = "5.26.4.1"; src = fetchurl { - url = "${mirror}/stable/plasma/5.26.4/plasma-workspace-5.26.4.tar.xz"; - sha256 = "06pbghl8gpq63gg9jj29jsizgfq7bcqj9kx48gkqcwvd9gd1q1f9"; - name = "plasma-workspace-5.26.4.tar.xz"; + url = "${mirror}/stable/plasma/5.26.4/plasma-workspace-5.26.4.1.tar.xz"; + sha256 = "7fcca23ff8de6f4aa2261f0180be54422f25047002b7ca6c648e7216459b80fc"; + name = "plasma-workspace-5.26.4.1.tar.xz"; }; }; plasma-workspace-wallpapers = { From 42a0bb2733af54e1d548eda170147d486cf9fa1f Mon Sep 17 00:00:00 2001 From: 06kellyjac Date: Wed, 23 Nov 2022 16:50:48 +0000 Subject: [PATCH 15/38] brave: fix commandLineArgs option also requiring vulkanSupport (cherry picked from commit 25551116a472c95aab5e01c120557f188383f69c) --- pkgs/applications/networking/browsers/brave/default.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/applications/networking/browsers/brave/default.nix b/pkgs/applications/networking/browsers/brave/default.nix index e9c5cf66d9de..c446a607f390 100644 --- a/pkgs/applications/networking/browsers/brave/default.nix +++ b/pkgs/applications/networking/browsers/brave/default.nix @@ -180,8 +180,8 @@ stdenv.mkDerivation rec { --add-flags "\''${NIXOS_OZONE_WL:+\''${WAYLAND_DISPLAY:+--ozone-platform-hint=auto --enable-features=WaylandWindowDecorations}}" ${optionalString vulkanSupport '' --prefix XDG_DATA_DIRS : "${addOpenGLRunpath.driverLink}/share" - --add-flags ${escapeShellArg commandLineArgs} ''} + --add-flags ${escapeShellArg commandLineArgs} ) ''; From 8fddf55c8fe89e184c412c76c0a6769007f4518f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Bj=C3=B8rn=20Forsman?= Date: Tue, 29 Nov 2022 15:27:47 +0100 Subject: [PATCH 16/38] smartmontools: add hostname to runtime closure This makes smartd notifications contain the hostname instead of "unknown". Total runtime closure size: Before: 46.1 MiB After: 46.7 MiB (cherry picked from commit c1e51d4b28e91eb74b62fa3a0386fde0b69a6683) --- pkgs/tools/system/smartmontools/default.nix | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/pkgs/tools/system/smartmontools/default.nix b/pkgs/tools/system/smartmontools/default.nix index d7bc0a2cb829..c1749030d6dd 100644 --- a/pkgs/tools/system/smartmontools/default.nix +++ b/pkgs/tools/system/smartmontools/default.nix @@ -4,6 +4,7 @@ , autoreconfHook , enableMail ? false , gnused +, hostname , mailutils , inetutils , IOKit @@ -18,7 +19,7 @@ let sha256 = "sha256-0dtLev4JjeHsS259+qOgg19rz4yjkeX4D3ooUgS4RTI="; name = "smartmontools-drivedb.h"; }; - scriptPath = lib.makeBinPath ([ gnused ] ++ lib.optionals enableMail [ inetutils mailutils ]); + scriptPath = lib.makeBinPath ([ gnused hostname ] ++ lib.optionals enableMail [ inetutils mailutils ]); in stdenv.mkDerivation rec { From 574d400589569e0390be8bf6083cd30952c24eb7 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Bj=C3=B8rn=20Forsman?= Date: Tue, 29 Nov 2022 15:33:02 +0100 Subject: [PATCH 17/38] smartmontools: remove unneeded inetutils It was only needed for 'hostname', which is now provided by the 'hostname' package, which has smaller storage footprint. (cherry picked from commit e01e2d3978046735926ba41088f038d7b7ad6552) --- pkgs/tools/system/smartmontools/default.nix | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/pkgs/tools/system/smartmontools/default.nix b/pkgs/tools/system/smartmontools/default.nix index c1749030d6dd..a54c85bdaf92 100644 --- a/pkgs/tools/system/smartmontools/default.nix +++ b/pkgs/tools/system/smartmontools/default.nix @@ -6,7 +6,6 @@ , gnused , hostname , mailutils -, inetutils , IOKit , ApplicationServices }: @@ -19,7 +18,7 @@ let sha256 = "sha256-0dtLev4JjeHsS259+qOgg19rz4yjkeX4D3ooUgS4RTI="; name = "smartmontools-drivedb.h"; }; - scriptPath = lib.makeBinPath ([ gnused hostname ] ++ lib.optionals enableMail [ inetutils mailutils ]); + scriptPath = lib.makeBinPath ([ gnused hostname ] ++ lib.optionals enableMail [ mailutils ]); in stdenv.mkDerivation rec { From d51bd551173928e67a842c930e20e30b6ec15dba Mon Sep 17 00:00:00 2001 From: Weijia Wang <9713184+wegank@users.noreply.github.com> Date: Tue, 29 Nov 2022 16:28:06 +0100 Subject: [PATCH 18/38] racket-minimal: fix build on aarch64-darwin This commit fixed a previous patch so that signatures are effectively removed and then added. (cherry picked from commit 8b868b5616c3406c8737c4dba50f394528475732) --- .../interpreters/racket/force-remove-codesign-then-add.patch | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/development/interpreters/racket/force-remove-codesign-then-add.patch b/pkgs/development/interpreters/racket/force-remove-codesign-then-add.patch index 38cd7f52e237..98e2cb102db9 100644 --- a/pkgs/development/interpreters/racket/force-remove-codesign-then-add.patch +++ b/pkgs/development/interpreters/racket/force-remove-codesign-then-add.patch @@ -5,6 +5,6 @@ (void - (if remove? -+ (if #t ++ (begin (remove-signature file) (add-ad-hoc-signature file))) From 3bd7152706ca651c5382e497debab3f2b643c0b6 Mon Sep 17 00:00:00 2001 From: sternenseemann Date: Tue, 29 Nov 2022 23:22:00 +0100 Subject: [PATCH 19/38] licensee: 9.15.1 -> 9.15.3 https://github.com/licensee/licensee/releases/tag/v9.15.2 https://github.com/licensee/licensee/releases/tag/v9.15.3 (cherry picked from commit 8db42896f1f22639d819188d7fa8184279f8f363) --- .../package-management/licensee/Gemfile.lock | 52 +++++++------- .../package-management/licensee/gemset.nix | 72 ++++++++----------- 2 files changed, 56 insertions(+), 68 deletions(-) diff --git a/pkgs/tools/package-management/licensee/Gemfile.lock b/pkgs/tools/package-management/licensee/Gemfile.lock index e631b63963c3..438ba3e8c6f3 100644 --- a/pkgs/tools/package-management/licensee/Gemfile.lock +++ b/pkgs/tools/package-management/licensee/Gemfile.lock @@ -1,38 +1,36 @@ GEM remote: https://rubygems.org/ specs: - addressable (2.7.0) - public_suffix (>= 2.0.2, < 5.0) - dotenv (2.7.6) - faraday (1.3.0) - faraday-net_http (~> 1.0) - multipart-post (>= 1.2, < 3) - ruby2_keywords - faraday-net_http (1.0.1) - licensee (9.15.1) + addressable (2.8.1) + public_suffix (>= 2.0.2, < 6.0) + dotenv (2.8.1) + faraday (2.7.1) + faraday-net_http (>= 2.0, < 3.1) + ruby2_keywords (>= 0.0.4) + faraday-net_http (3.0.2) + licensee (9.15.3) dotenv (~> 2.0) - octokit (~> 4.20) - reverse_markdown (~> 1.0) + octokit (>= 4.20, < 7.0) + reverse_markdown (>= 1, < 3) rugged (>= 0.24, < 2.0) thor (>= 0.19, < 2.0) - mini_portile2 (2.5.0) - multipart-post (2.1.1) - nokogiri (1.11.1) - mini_portile2 (~> 2.5.0) + mini_portile2 (2.8.0) + nokogiri (1.13.9) + mini_portile2 (~> 2.8.0) racc (~> 1.4) - octokit (4.20.0) - faraday (>= 0.9) - sawyer (~> 0.8.0, >= 0.5.3) - public_suffix (4.0.6) - racc (1.5.2) - reverse_markdown (1.4.0) + octokit (6.0.1) + faraday (>= 1, < 3) + sawyer (~> 0.9) + public_suffix (5.0.0) + racc (1.6.0) + reverse_markdown (2.1.1) nokogiri - ruby2_keywords (0.0.4) - rugged (1.1.0) - sawyer (0.8.2) + ruby2_keywords (0.0.5) + rugged (1.5.0.1) + sawyer (0.9.2) addressable (>= 2.3.5) - faraday (> 0.8, < 2.0) - thor (1.1.0) + faraday (>= 0.17.3, < 3) + thor (1.2.1) PLATFORMS ruby @@ -41,4 +39,4 @@ DEPENDENCIES licensee BUNDLED WITH - 2.1.4 + 2.3.25 diff --git a/pkgs/tools/package-management/licensee/gemset.nix b/pkgs/tools/package-management/licensee/gemset.nix index b9b11b465f69..656f67f3a270 100644 --- a/pkgs/tools/package-management/licensee/gemset.nix +++ b/pkgs/tools/package-management/licensee/gemset.nix @@ -5,41 +5,41 @@ platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "1fvchp2rhp2rmigx7qglf69xvjqvzq7x0g49naliw29r2bz656sy"; + sha256 = "1ypdmpdn20hxp5vwxz3zc04r5xcwqc25qszdlg41h8ghdqbllwmw"; type = "gem"; }; - version = "2.7.0"; + version = "2.8.1"; }; dotenv = { groups = ["default"]; platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "0iym172c5337sm1x2ykc2i3f961vj3wdclbyg1x6sxs3irgfsl94"; + sha256 = "1n0pi8x8ql5h1mijvm8lgn6bhq4xjb5a500p5r1krq4s6j9lg565"; type = "gem"; }; - version = "2.7.6"; + version = "2.8.1"; }; faraday = { - dependencies = ["faraday-net_http" "multipart-post" "ruby2_keywords"]; + dependencies = ["faraday-net_http" "ruby2_keywords"]; groups = ["default"]; platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "1hmssd8pj4n7yq4kz834ylkla8ryyvhaap6q9nzymp93m1xq21kz"; + sha256 = "1wyz9ab0mzi84gpf81fs19vrixglmmxi25k6n1mn9h141qmsp590"; type = "gem"; }; - version = "1.3.0"; + version = "2.7.1"; }; faraday-net_http = { groups = ["default"]; platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "1fi8sda5hc54v1w3mqfl5yz09nhx35kglyx72w7b8xxvdr0cwi9j"; + sha256 = "13byv3mp1gsjyv8k0ih4612y6vw5kqva6i03wcg4w2fqpsd950k8"; type = "gem"; }; - version = "1.0.1"; + version = "3.0.2"; }; licensee = { dependencies = ["dotenv" "octokit" "reverse_markdown" "rugged" "thor"]; @@ -47,30 +47,20 @@ platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "1pvrz9fjvxzk3aq85zgh8dkw98kz54jmwi10k3shc8dqbrlvragy"; + sha256 = "0n0l1c8kxhpdg6pgv1wgwpdfc7gqkygpd8h41shwc95rapdha9gg"; type = "gem"; }; - version = "9.15.1"; + version = "9.15.3"; }; mini_portile2 = { groups = ["default"]; platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "1hdbpmamx8js53yk3h8cqy12kgv6ca06k0c9n3pxh6b6cjfs19x7"; + sha256 = "0rapl1sfmfi3bfr68da4ca16yhc0pp93vjwkj7y3rdqrzy3b41hy"; type = "gem"; }; - version = "2.5.0"; - }; - multipart-post = { - groups = ["default"]; - platforms = []; - source = { - remotes = ["https://rubygems.org"]; - sha256 = "1zgw9zlwh2a6i1yvhhc4a84ry1hv824d6g2iw2chs3k5aylpmpfj"; - type = "gem"; - }; - version = "2.1.1"; + version = "2.8.0"; }; nokogiri = { dependencies = ["mini_portile2" "racc"]; @@ -78,10 +68,10 @@ platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "1ajwkqr28hwqbyl1l3czx4a34c88acxywyqp8cjyy0zgsd6sbhj2"; + sha256 = "0cam1455nmi3fzzpa9ixn2hsim10fbprmj62ajpd6d02mwdprwwn"; type = "gem"; }; - version = "1.11.1"; + version = "1.13.9"; }; octokit = { dependencies = ["faraday" "sawyer"]; @@ -89,30 +79,30 @@ platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "1fl517ld5vj0llyshp3f9kb7xyl9iqy28cbz3k999fkbwcxzhlyq"; + sha256 = "0a5iy1v1n8f5ggp6q601mn8dz1n08ffs4gv0zsh5ca68j8dfmpx5"; type = "gem"; }; - version = "4.20.0"; + version = "6.0.1"; }; public_suffix = { groups = ["default"]; platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "1xqcgkl7bwws1qrlnmxgh8g4g9m10vg60bhlw40fplninb3ng6d9"; + sha256 = "0sqw1zls6227bgq38sxb2hs8nkdz4hn1zivs27mjbniswfy4zvi6"; type = "gem"; }; - version = "4.0.6"; + version = "5.0.0"; }; racc = { groups = ["default"]; platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "178k7r0xn689spviqzhvazzvxfq6fyjldxb3ywjbgipbfi4s8j1g"; + sha256 = "0la56m0z26j3mfn1a9lf2l03qx1xifanndf9p3vx1azf6sqy7v9d"; type = "gem"; }; - version = "1.5.2"; + version = "1.6.0"; }; reverse_markdown = { dependencies = ["nokogiri"]; @@ -120,30 +110,30 @@ platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "0w786j869fjhjf72waj0hc9i4ghi45b78a2am27kij4sa2hmsc53"; + sha256 = "0087vhw5ik50lxvddicns01clkx800fk5v5qnrvi3b42nrk6885j"; type = "gem"; }; - version = "1.4.0"; + version = "2.1.1"; }; ruby2_keywords = { groups = ["default"]; platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "15wfcqxyfgka05v2a7kpg64x57gl1y4xzvnc9lh60bqx5sf1iqrs"; + sha256 = "1vz322p8n39hz3b4a9gkmz9y7a5jaz41zrm2ywf31dvkqm03glgz"; type = "gem"; }; - version = "0.0.4"; + version = "0.0.5"; }; rugged = { groups = ["default"]; platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "04aq913plcxjw71l5r62qgz3bx3466p0wvgyfqahg5n3nybmcwqy"; + sha256 = "02h1cv73znwfgy61mqmfylcfvwyyp3lddiz3njgivfx234mpz50x"; type = "gem"; }; - version = "1.1.0"; + version = "1.5.0.1"; }; sawyer = { dependencies = ["addressable" "faraday"]; @@ -151,19 +141,19 @@ platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "0yrdchs3psh583rjapkv33mljdivggqn99wkydkjdckcjn43j3cz"; + sha256 = "1jks1qjbmqm8f9kvwa81vqj39avaj9wdnzc531xm29a55bb74fps"; type = "gem"; }; - version = "0.8.2"; + version = "0.9.2"; }; thor = { groups = ["default"]; platforms = []; source = { remotes = ["https://rubygems.org"]; - sha256 = "18yhlvmfya23cs3pvhr1qy38y41b6mhr5q9vwv5lrgk16wmf3jna"; + sha256 = "0inl77jh4ia03jw3iqm5ipr76ghal3hyjrd6r8zqsswwvi9j2xdi"; type = "gem"; }; - version = "1.1.0"; + version = "1.2.1"; }; } From 76e1155823a8e6e937fc4240783204e5744787ee Mon Sep 17 00:00:00 2001 From: sternenseemann Date: Tue, 29 Nov 2022 23:25:42 +0100 Subject: [PATCH 20/38] bundlerUpdateScript: use Nix 2.3 The script assumes that nix(1) can be used without any flags which is no longer the case. We can easily use Nix 2.3 as a workaround until someone else musters the willpower to adjust this script for Nix 2.11. (cherry picked from commit 38ffd641e0da8f37b82858ebd7cd679fa4716b66) --- .../ruby-modules/bundler-update-script/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/ruby-modules/bundler-update-script/default.nix b/pkgs/development/ruby-modules/bundler-update-script/default.nix index 50d0364aa067..cf4942f6e58c 100644 --- a/pkgs/development/ruby-modules/bundler-update-script/default.nix +++ b/pkgs/development/ruby-modules/bundler-update-script/default.nix @@ -1,11 +1,11 @@ -{ runtimeShell, lib, writeScript, bundix, bundler, bundler-audit, coreutils, git, nix }: +{ runtimeShell, lib, writeScript, bundix, bundler, bundler-audit, coreutils, git, nix_2_3 }: attrPath: let updateScript = writeScript "bundler-update-script" '' #!${runtimeShell} - PATH=${lib.makeBinPath [ bundler bundler-audit bundix coreutils git nix ]} + PATH=${lib.makeBinPath [ bundler bundler-audit bundix coreutils git nix_2_3 ]} set -o errexit set -o nounset set -o pipefail From 1a16d716c9ee88b58be0f50f6a27703002c2a964 Mon Sep 17 00:00:00 2001 From: Thomas Gerbet Date: Tue, 29 Nov 2022 18:36:38 +0100 Subject: [PATCH 21/38] php8*: disable PCRE2 JIT SEAlloc to avoid crashes when forking This is a follow up to #200815 and #184634. The PCRE2 JIT SEAlloc does not support the `fork()` as announced in their README [0]: > If you are enabling JIT under SELinux environment you may also want to add > --enable-jit-sealloc, which enables the use of an executable memory allocator > that is compatible with SELinux. Warning: this allocator is experimental! > It does not support fork() operation and may crash when no disk space is > available. This option has no effect if JIT is disabled. As a result using it in PHP can break apps and tools, it can only be enabled under very specific context where you have a full picture of what the PHP code is doing. This contribution disables again the PCRE2 JIT SEAlloc and extends the existing PHP/PCRE2 tests to make sure we do not enable it again by mistake. [0] https://www.pcre.org/readme.txt (cherry picked from commit 622f4ee35426c6933b8a36ce5266f03884d1ed05) --- nixos/tests/php/pcre.nix | 16 +++++++++++++--- pkgs/top-level/all-packages.nix | 6 +++--- 2 files changed, 16 insertions(+), 6 deletions(-) diff --git a/nixos/tests/php/pcre.nix b/nixos/tests/php/pcre.nix index 57407477f4b8..8e37d5dcf97b 100644 --- a/nixos/tests/php/pcre.nix +++ b/nixos/tests/php/pcre.nix @@ -1,7 +1,7 @@ let testString = "can-use-subgroups"; in -import ../make-test-python.nix ({ lib, php, ... }: { +import ../make-test-python.nix ({ pkgs, lib, php, ... }: { name = "php-${php.version}-httpd-pcre-jit-test"; meta.maintainers = lib.teams.php.members; @@ -31,12 +31,22 @@ import ../make-test-python.nix ({ lib, php, ... }: { ''; }; }; - testScript = { ... }: - '' + testScript = let + # PCRE JIT SEAlloc feature does not play well with fork() + # The feature needs to either be disabled or PHP configured correctly + # More information in https://bugs.php.net/bug.php?id=78927 and https://bugs.php.net/bug.php?id=78630 + pcreJitSeallocForkIssue = pkgs.writeText "pcre-jit-sealloc-issue.php" '' + Date: Thu, 24 Nov 2022 21:05:35 +0100 Subject: [PATCH 22/38] git-credential-keepassxc: 0.10.1 -> 0.11.0 (cherry picked from commit 782c75a8f30eb5fe082f78b3f0e0f648fcddc461) --- .../git-and-tools/git-credential-keepassxc/default.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/applications/version-management/git-and-tools/git-credential-keepassxc/default.nix b/pkgs/applications/version-management/git-and-tools/git-credential-keepassxc/default.nix index 0e5ba28eebaa..27998f1c9c15 100644 --- a/pkgs/applications/version-management/git-and-tools/git-credential-keepassxc/default.nix +++ b/pkgs/applications/version-management/git-and-tools/git-credential-keepassxc/default.nix @@ -8,16 +8,16 @@ rustPlatform.buildRustPackage rec { pname = "git-credential-keepassxc"; - version = "0.10.1"; + version = "0.11.0"; src = fetchFromGitHub { owner = "Frederick888"; repo = "git-credential-keepassxc"; rev = "v${version}"; - hash = "sha256-zVE3RQlh0SEV4iavz40YhR+MP31oLCvG54H8gqXwL/k="; + hash = "sha256-ZpysJ+xs3IenqAdoswG0OkzxzuNPSKkqlutGxn4VRw8="; }; - cargoHash = "sha256-H75SGbT//02I+umttnPM5BwtFkDVNxEYLf84oULEuEk="; + cargoHash = "sha256-IPsMlVfgwoFEQlXmW4gnt16WNF5W6akobUVct/iF42E="; buildInputs = lib.optionals stdenv.isDarwin [ DiskArbitration Foundation ]; From 8b8d92ecec715dfb5e5a5d7f028a9540a7d30446 Mon Sep 17 00:00:00 2001 From: KFears Date: Wed, 30 Nov 2022 01:30:00 +0400 Subject: [PATCH 23/38] nixos/openrgb: fix linking in release notes (cherry picked from commit bb4cc151b6dfee792e98f53a30895b66cf7b4a48) --- nixos/doc/manual/from_md/release-notes/rl-2211.section.xml | 2 +- nixos/doc/manual/release-notes/rl-2211.section.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml b/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml index 4e4b0923db6c..bfc9dd658325 100644 --- a/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml +++ b/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml @@ -355,7 +355,7 @@ OpenRGB, a FOSS tool for controlling RGB lighting. Available as - services.hardware.openrgb.enable. + services.hardware.openrgb.enable. diff --git a/nixos/doc/manual/release-notes/rl-2211.section.md b/nixos/doc/manual/release-notes/rl-2211.section.md index fccb00ff0156..f939de1b078c 100644 --- a/nixos/doc/manual/release-notes/rl-2211.section.md +++ b/nixos/doc/manual/release-notes/rl-2211.section.md @@ -127,7 +127,7 @@ In addition to numerous new and upgraded packages, this release has the followin - [languagetool](https://languagetool.org/), a multilingual grammar, style, and spell checker. Available as [services.languagetool](options.html#opt-services.languagetool.enable). -- [OpenRGB](https://gitlab.com/CalcProgrammer1/OpenRGB/-/tree/master), a FOSS tool for controlling RGB lighting. Available as [services.hardware.openrgb.enable](options.html#opt-services-hardware-openrgb-enable). +- [OpenRGB](https://gitlab.com/CalcProgrammer1/OpenRGB/-/tree/master), a FOSS tool for controlling RGB lighting. Available as [services.hardware.openrgb.enable](options.html#opt-services.hardware.openrgb.enable). - [Outline](https://www.getoutline.com/), a wiki and knowledge base similar to Notion. Available as [services.outline](#opt-services.outline.enable). From 2e87d3dacf51361122a1fae9d96fac68ff140079 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Oto=20Pet=C5=99=C3=ADk?= Date: Sun, 24 Jul 2022 15:36:43 +0200 Subject: [PATCH 24/38] nixos/proxmox-image: allow building UEFI images Allow building other than Legacy-BIOS-only Proxmox images. Default is unchanged. To build UEFI proxmox image use: proxmox.qemuConf.bios = "ovmf"; (default is "seabios") To build image bootable using both "seabios" and "ovmf" use: partitionTableType = "hybrid"; BIOS can be switched in Proxmox between "seabios" and "ovmf" and VM still boots. (GRUB2-only, systemd-boot does not boot under "seabios") To build systemd-boot UEFI image: proxmox.qemuConf.bios = "ovmf"; boot.loader.systemd-boot.enable = true; (cherry picked from commit 4729d5d7f62a989c1518cac96a3a971da00a7d12) --- .../from_md/release-notes/rl-2211.section.xml | 20 +++++++ .../manual/release-notes/rl-2211.section.md | 2 + .../modules/virtualisation/proxmox-image.nix | 59 ++++++++++++++++++- 3 files changed, 80 insertions(+), 1 deletion(-) diff --git a/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml b/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml index bfc9dd658325..8b79b09a8b38 100644 --- a/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml +++ b/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml @@ -1462,6 +1462,26 @@ services.github-runner.serviceOverrides.SupplementaryGroups = [ if you intend to add packages to /bin. + + + The proxmox.qemuConf.bios option was added, + it corresponds to Hardware->BIOS field + in Proxmox web interface. Use + "ovmf" value to build UEFI image, + default value remains "bios". New + option proxmox.partitionTableType defaults + to either "legacy" or + "efi", depending on the + bios value. Setting + partitionTableType to + "hybrid" results in an image, + which supports both methods + ("bios" and + "ovmf"), thereby remaining + bootable after change to Proxmox + Hardware->BIOS field. + + memtest86+ was updated from 5.00-coreboot-002 to 6.00-beta2. diff --git a/nixos/doc/manual/release-notes/rl-2211.section.md b/nixos/doc/manual/release-notes/rl-2211.section.md index f939de1b078c..6d0bc1197768 100644 --- a/nixos/doc/manual/release-notes/rl-2211.section.md +++ b/nixos/doc/manual/release-notes/rl-2211.section.md @@ -475,6 +475,8 @@ Available as [services.patroni](options.html#opt-services.patroni.enable). - `dockerTools.buildImage` deprecates the misunderstood `contents` parameter, in favor of `copyToRoot`. Use `copyToRoot = buildEnv { ... };` or similar if you intend to add packages to `/bin`. +- The `proxmox.qemuConf.bios` option was added, it corresponds to `Hardware->BIOS` field in Proxmox web interface. Use `"ovmf"` value to build UEFI image, default value remains `"bios"`. New option `proxmox.partitionTableType` defaults to either `"legacy"` or `"efi"`, depending on the `bios` value. Setting `partitionTableType` to `"hybrid"` results in an image, which supports both methods (`"bios"` and `"ovmf"`), thereby remaining bootable after change to Proxmox `Hardware->BIOS` field. + - memtest86+ was updated from 5.00-coreboot-002 to 6.00-beta2. It is now the upstream version from https://www.memtest.org/, as coreboot's fork is no longer available. - Option descriptions, examples, and defaults writting in DocBook are now deprecated. Using CommonMark is preferred and will become the default in a future release. diff --git a/nixos/modules/virtualisation/proxmox-image.nix b/nixos/modules/virtualisation/proxmox-image.nix index 4fca8ce9e7eb..42c52c12edf0 100644 --- a/nixos/modules/virtualisation/proxmox-image.nix +++ b/nixos/modules/virtualisation/proxmox-image.nix @@ -53,6 +53,13 @@ with lib; Guest memory in MB ''; }; + bios = mkOption { + type = types.enum [ "seabios" "ovmf" ]; + default = "seabios"; + description = '' + Select BIOS implementation (seabios = Legacy BIOS, ovmf = UEFI). + ''; + }; # optional configs name = mkOption { @@ -99,6 +106,17 @@ with lib; Additional options appended to qemu-server.conf ''; }; + partitionTableType = mkOption { + type = types.enum [ "efi" "hybrid" "legacy" "legacy+gpt" ]; + description = '' + Partition table type to use. See make-disk-image.nix partitionTableType for details. + Defaults to 'legacy' for 'proxmox.qemuConf.bios="seabios"' (default), other bios values defaults to 'efi'. + Use 'hybrid' to build grub-based hybrid bios+efi images. + ''; + default = if config.proxmox.qemuConf.bios == "seabios" then "legacy" else "efi"; + defaultText = lib.literalExpression ''if config.proxmox.qemuConf.bios == "seabios" then "legacy" else "efi"''; + example = "hybrid"; + }; filenameSuffix = mkOption { type = types.str; default = config.proxmox.qemuConf.name; @@ -122,9 +140,33 @@ with lib; ${lib.concatStrings (lib.mapAttrsToList cfgLine properties)} #qmdump#map:virtio0:drive-virtio0:local-lvm:raw: ''; + inherit (cfg) partitionTableType; + supportEfi = partitionTableType == "efi" || partitionTableType == "hybrid"; + supportBios = partitionTableType == "legacy" || partitionTableType == "hybrid" || partitionTableType == "legacy+gpt"; + hasBootPartition = partitionTableType == "efi" || partitionTableType == "hybrid"; + hasNoFsPartition = partitionTableType == "hybrid" || partitionTableType == "legacy+gpt"; in { + assertions = [ + { + assertion = config.boot.loader.systemd-boot.enable -> config.proxmox.qemuConf.bios == "ovmf"; + message = "systemd-boot requires 'ovmf' bios"; + } + { + assertion = partitionTableType == "efi" -> config.proxmox.qemuConf.bios == "ovmf"; + message = "'efi' disk partitioning requires 'ovmf' bios"; + } + { + assertion = partitionTableType == "legacy" -> config.proxmox.qemuConf.bios == "seabios"; + message = "'legacy' disk partitioning requires 'seabios' bios"; + } + { + assertion = partitionTableType == "legacy+gpt" -> config.proxmox.qemuConf.bios == "seabios"; + message = "'legacy+gpt' disk partitioning requires 'seabios' bios"; + } + ]; system.build.VMA = import ../../lib/make-disk-image.nix { name = "proxmox-${cfg.filenameSuffix}"; + inherit partitionTableType; postVM = let # Build qemu with PVE's patch that adds support for the VMA format vma = (pkgs.qemu_kvm.override { @@ -181,7 +223,18 @@ with lib; boot = { growPartition = true; kernelParams = [ "console=ttyS0" ]; - loader.grub.device = lib.mkDefault "/dev/vda"; + loader.grub = { + device = lib.mkDefault (if (hasNoFsPartition || supportBios) then + # Even if there is a separate no-fs partition ("/dev/disk/by-partlabel/no-fs" i.e. "/dev/vda2"), + # which will be used the bootloader, do not set it as loader.grub.device. + # GRUB installation fails, unless the whole disk is selected. + "/dev/vda" + else + "nodev"); + efiSupport = lib.mkDefault supportEfi; + efiInstallAsRemovable = lib.mkDefault supportEfi; + }; + loader.timeout = 0; initrd.availableKernelModules = [ "uas" "virtio_blk" "virtio_pci" ]; }; @@ -191,6 +244,10 @@ with lib; autoResize = true; fsType = "ext4"; }; + fileSystems."/boot" = lib.mkIf hasBootPartition { + device = "/dev/disk/by-label/ESP"; + fsType = "vfat"; + }; services.qemuGuest.enable = lib.mkDefault true; }; From 7044fe36924e4b031a95629a66e3cc298a6fa5f8 Mon Sep 17 00:00:00 2001 From: Winter Date: Sun, 27 Nov 2022 22:16:03 -0500 Subject: [PATCH 25/38] nixos/doc/rl-2211: cleanup (cherry picked from commit e81b0cec91c35a427ed4d0fe2df3c74344a14c72) --- .../from_md/release-notes/rl-2211.section.xml | 2619 ++++++++--------- .../manual/release-notes/rl-2211.section.md | 803 +++-- 2 files changed, 1703 insertions(+), 1719 deletions(-) diff --git a/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml b/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml index 8b79b09a8b38..7a8ab3c00e3c 100644 --- a/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml +++ b/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml @@ -1,23 +1,179 @@
Release 22.11 (“Raccoon”, 2022.11/??) - Support is planned until the end of June 2023, handing over to - 23.05. + This release is supported until the end of June 2023, handing over + to NixOS 23.05.
Highlights In addition to numerous new and upgraded packages, this release - has the following highlights: + includes the following highlights: - GNOME has been upgraded to 43. Please take a look at their - Release + GNOME has been upgraded to version 43. Please take a look at + their Release Notes for details. + + + KDE Plasma has been upgraded from v5.24 to v5.26. Please see + the release notes for + v5.25 + and + v5.26 + for more details on the included changes. + + + + + Cinnamon has been updated to 5.4, and the Cinnamon module now + defaults to Blueman as the Bluetooth manager and slick-greeter + as the LightDM greeter, to match upstream. + + + + + OpenSSL now defaults to OpenSSL 3, updated from 1.1.1. + + + + + PHP now defaults to PHP 8.1, updated from 8.0. + + + + + PHP is now built in NTS (Non-Thread Safe) + mode by default. + + + + + For Apache and mod_php usage, we enable + ZTS (Zend Thread Safe) mode. This has + been a common practice for a long time in other + distributions. + + + + + + + Perl has been updated to 5.36, and its core module + HTTP::Tiny was patched to verify SSL/TLS + certificates by default. + + + + + nscd functionality, necessary to provide + non-glibc-builtin NSS modules (such as + nss_systemd or nss_ldap) + can now be provided by nsncd, by setting + services.nscd.enableNsncd to + true. + + + The nscd daemon provided by glibc, which is + currently used by NixOS isn’t very reliable. For example, it’s + not + fully possible to disable caching functionality, + causing various issues and failed lookups. + + + In contrast to nscd’s behavior of caching module responses on + its own, nsncd merely forwards requests to NSS modules, which + might cache or not. + + + We plan to use nsncd by default in NixOS + 23.05. + + + + + The emacs package now makes use of native + compilation which means: + + + + + Emacs packages from Nixpkgs, builtin or not, will do + native compilation ahead of time so you can enjoy the + benefit of native compilation without compiling them on + you machine; + + + + + Emacs packages from somewhere else, e.g. + package-install, will perform + asynchronously deferred native compilation. If you do not + want this, maybe to avoid CPU consumption for compilation, + you can use + (setq native-comp-deferred-compilation nil) + to disable it while still benefiting from native + compilation for packages from Nixpkgs. + + + + + + + nixos-generate-config now generates + configurations that can be built in pure mode. This is + achieved by setting the new + nixpkgs.hostPlatform option. + + + You may have to unset the system parameter + in lib.nixosSystem, or similarly remove + definitions of the + nixpkgs.{system,localSystem,crossSystem} + options. + + + Alternatively, you can remove the + hostPlatform line and use NixOS like you + would in NixOS 22.05 and earlier. + + + + + It is now possible to generate NixOS images for the Linode + cloud provider, via + system.build.linodeImage. + + + + + hardware.nvidia has a new option, + hardware.nvidia.open, that can be used to + enable the usage of NVIDIA’s open-source kernel driver. Note + that the driver’s support for GeForce and Workstation GPUs is + still alpha quality, see + the + release announcement for more information. + + + +
+
+ Internal changes + + + + Improved performances of + lib.closePropagation which was previously + quadratic. This is used in e.g. + ghcWithPackages. Please see backward + incompatibilities notes below. + + During cross-compilation, tests are now executed if the test @@ -77,97 +233,998 @@ with any supported NixOS release. + +
+
+ Backward Incompatibilities + - nscd functionality, necessary to provide - non-glibc-builtin NSS modules (such as - nss_systemd or nss_ldap) - can now be provided by nsncd, by setting - services.nscd.enableNsncd to - true. - - - The nscd daemon provided by glibc, which is - currently used by NixOS isn’t very reliable. For example, it’s - not - fully possible to disable caching functionality, - causing various issues and failed lookups. - - - In contrast to nscd’s behavior of caching module responses on - its own, nsncd merely forwards requests to NSS modules, which - might cache or not. - - - We plan to use nsncd by default in NixOS - 23.05. + Nixpkgs now requires Nix 2.3 or newer. - emacs enables native compilation which - means: + The isCompatible predicate checking CPU + compatibility is no longer exposed by the platform sets + generated using lib.systems.elaborate. In + most cases you will want to use the new + canExecute predicate instead which also + considers the kernel / syscall interface. It is briefly + described in the release’s + highlights + section. + lib.systems.parse.isCompatible still + exists, but has changed semantically: Architectures with + differing endianness modes are no longer considered + compatible. + + + + + ngrok has been upgraded from 2.3.40 to + 3.0.4. Please see + the + upgrade guide and + changelog. + Notably, breaking changes are that the config file format has + changed and support for single hyphen arguments was dropped. + + + + + i18n.supportedLocales is now only generated + with the locales set in i18n.defaultLocale + and i18n.extraLocaleSettings. - emacs packages from nixpkgs, builtin or not, will do - native compilation ahead of time so you can enjoy the - benefit of native compilation without compiling them on - you machine; + This reduces the final system closure size by up to 200MB. - emacs packages from somewhere else, e.g. - package-install, will do asynchronously - deferred native compilation. If you do not want this, - maybe to avoid CPU consumption for compilation, you can - use - (setq native-comp-deferred-compilation nil) - to disable it while still enjoy the benefit of native - compilation for packages from nixpkgs. + If you require all locales installed, set the option to + [ "all" ]. - nixos-generate-config now generates - configurations that can be built in pure mode. This is - achieved by setting the new - nixpkgs.hostPlatform option. - - - You may have to unset the system parameter - in lib.nixosSystem, or similarly remove - definitions of the - nixpkgs.{system,localSystem,crossSystem} - options. - - - Alternatively, you can remove the - hostPlatform line and use NixOS like you - would in NixOS 22.05 and earlier. + Deprecated settings logrotate.paths and + logrotate.extraConfig have been removed. + Please convert any uses to + services.logrotate.settings + instead. - PHP now defaults to PHP 8.1, updated from 8.0. + The isPowerPC predicate, found on + platform attrsets + (hostPlatform, + buildPlatform, + targetPlatform, etc) has been removed in + order to reduce confusion. The predicate was was defined such + that it matches only the 32-bit big-endian members of the + POWER/PowerPC family, despite having a name which would imply + a broader set of systems. If you were using this predicate, + you can replace foo.isPowerPC with + (with foo; isPower && is32bit && isBigEndian). - PHP is now built NTS (Non-Thread Safe) - style by default, for Apache and mod_php - usage we still enable ZTS (Zend Thread - Safe). This has been a common practice for a long time in - other distributions. + The fetchgit fetcher now uses + cone + mode by default for sparse checkouts. + Non-cone + mode can be enabled by passing + nonConeMode = true, but note that non-cone + mode is deprecated and this option may be removed alongside a + future Git update without notice. - PHP 8.2.0 RC 7 is available. + The fetchgit fetcher supports sparse + checkouts via the sparseCheckout option. + This used to accept a multi-line string with + directories/patterns to check out, but now requires a list of + strings + + + + + openssh was updated to version 9.1, + disabling the generation of DSA keys when using + ssh-keygen -A as they are insecure. Also, + SetEnv directives in + ssh_config and + sshd_config are now first-match-wins + + + + + bsp-layout no longer uses the command + cycle to switch to other window layouts, as + it got replaced by the commands previous + and next. + + + + + The Barco ClickShare driver/client package + pkgs.clickshare-csc1 and the option + programs.clickshare-csc1.enable have been + removed, as it requires qt4, which reached + its end-of-life 2015 and will no longer be supported by + nixpkgs. + According + to Barco many of their base unit models can be used + with Google Chrome and the Google Cast extension. + + + + + services.hbase has been renamed to + services.hbase-standalone. For production + HBase clusters, use services.hadoop.hbase + instead. + + + + + The p4 package now only includes the + open-source Perforce Helix Core command-line client and APIs. + It no longer installs the unfree Helix Core Server binaries + p4d, p4broker, and + p4p. To install the Helix Core Server + binaries, use the p4d package instead. + + + + + The OpenSSL extension for the PHP interpreter used by + Nextcloud is built against OpenSSL 1.1 if + is below + 22.11. This is to make sure that people + using + server-side + encryption don’t lose access to their files. + + + In any other case, it’s safe to use OpenSSL 3 for PHP’s + OpenSSL extension. This can be done by setting + + to false. + + + + + The coq package and versioned variants + starting at coq_8_14 no longer include + CoqIDE, which is now available through + coqPackages.coqide. It is still possible to + get CoqIDE as part of the coq package by + overriding the buildIde argument of the + derivation. + + + + + PHP 7.4 is no longer supported due to upstream not supporting + this version for the entire lifecycle of the 22.11 release. + + + + + The ipfs package and module were renamed to kubo. The kubo + module now uses an RFC42-style settings + option instead of extraConfig and the + gatewayAddress, + apiAddress and + swarmAddress options were renamed. Using + the old names will print a warning but still work. + + + + + pkgs.cosign does not provide the + cosigned binary anymore. The + sget binary has been moved into its own + package. + + + + + Emacs now uses the Lucid toolkit by default instead of GTK + because of stability and compatibility issues. Users who still + wish to remain using GTK can do so by using + emacs-gtk. + + + + + kanidm has been updated to 1.1.0-alpha.10 + and now requires a TLS certificate and key. It will always + start https and-–-if enabled-–-an LDAPS + server and no HTTP and LDAP server anymore + + + + + riak package removed along with + services.riak module, due to lack of + maintainer to update the package. + + + + + ppd files in pkgs.cups-drv-rastertosag-gdi + are now gzipped. If you refer to such a ppd file with its path + (e.g. via + hardware.printers.ensurePrinters) + you will need to append .gz to the path. + + + + + xow package removed along with the + hardware.xow module, due to the project + being deprecated in favor of xone, which is + available via the hardware.xone module. + + + + + dd-agent package removed along with the + services.dd-agent module, due to the + project being deprecated in favor of + datadog-agent, which is available via the + services.datadog-agent module. + + + + + teleport has been upgraded to major version + 10. Please see upstream + upgrade + instructions and + release + notes. + + + + + lib.closePropagation now needs that all + gathered sets have an outPath attribute. + + + + + lemmy module option + services.lemmy.settings.database.createLocally + moved to + services.lemmy.database.createLocally. + + + + + virtlyst package and services.virtlyst + module removed, due to lack of maintainers. + + + + + The nix.checkConfig option now fully + disables the config check. The new + nix.checkAllErrors option behaves like + nix.checkConfig previously did. + + + + + generateOptparseApplicativeCompletions and + generateOptparseApplicativeCompletion from + haskell.lib.compose (and + haskell.lib) have been deprecated in favor + of generateOptparseApplicativeCompletions + (plural!) as provided by the haskell package sets (so + haskellPackages.generateOptparseApplicativeCompletions + etc.). The latter allows for cross-compilation (by + automatically disabling generation of completion in the cross + case). For it to work properly you need to make sure that the + function comes from the same context as the package you are + trying to override, i.e. always use the same package set as + your package is coming from or – even better – use + self.generateOptparseApplicativeCompletions + if you are overriding a haskell package set. The old functions + are retained for backwards compatibility, but yield are + warning. + + + + + The services.graphite.api and + services.graphite.beacon NixOS options, and + the python3.pkgs.graphite_api, + python3.pkgs.graphite_beacon and + python3.pkgs.influxgraph packages, have + been removed due to lack of upstream maintenance. + + + + + The trace binary from + perf-linux package has been removed, due to + being a duplicate of the perf binary. + + + + + The aws package has been removed due to + being abandoned by the upstream. It is recommended to use + awscli or awscli2 + instead. + + + + + The + CEmu + TI-84 Plus CE emulator package has been renamed to + cemu-ti. The + Cemu Wii U + emulator is now packaged as cemu. + + + + + systemd-networkd v250 deprecated, renamed, + and moved some sections and settings which leads to the + following breaking module changes: + + + + + systemd.network.networks.<name>.dhcpV6PrefixDelegationConfig + is renamed to + systemd.network.networks.<name>.dhcpPrefixDelegationConfig. + + + + + systemd.network.networks.<name>.dhcpV6Config + no longer accepts the + ForceDHCPv6PDOtherInformation= setting. + Please use the WithoutRA= and + UseDelegatedPrefix= settings in your + systemd.network.networks.<name>.dhcpV6Config + and the DHCPv6Client= setting in your + systemd.network.networks.<name>.ipv6AcceptRAConfig + to control when the DHCPv6 client is started and how the + delegated prefixes are handled by the DHCPv6 client. + + + + + systemd.network.networks.<name>.networkConfig + no longer accepts the IPv6Token= + setting. Use the Token= setting in your + systemd.network.networks.<name>.ipv6AcceptRAConfig + instead. The + systemd.network.networks.<name>.ipv6Prefixes.*.ipv6PrefixConfig + now also accepts the Token= setting. + + + + + + + arangodb versions 3.3, 3.4, and 3.5 have + been removed because they are at EOL upstream. The default is + now 3.10.0. Support for aarch64-linux has been removed since + the target cannot be built reproducibly. By default + arangodb is now built for the + haswell architecture. If you wish to build + for a different architecture, you may override the + targetArchitecture argument with a value + from + this + list supported upstream. Some architecture specific + optimizations are also conditionally enabled. You may alter + this behavior by overriding the + asmOptimizations parameter. You may also + add additional architecture support by adding more + -DHAS_XYZ flags to + cmakeFlags via + overrideAttrs. + + + + + The meta.mainProgram attribute of packages + in wineWowPackages now defaults to + "wine64". + + + + + The paperless module now defaults + PAPERLESS_TIME_ZONE to your configured + system timezone. + + + + + The top-level termonad-with-packages alias + for termonad has been removed. + + + + + Linux 4.9 has been removed because it will reach its end of + life within the lifespan of 22.11. + + + + + (Neo)Vim can not be configured with + configure.pathogen anymore to reduce + maintainance burden. Use configure.packages + instead. + + + + + Neovim can not be configured with plug anymore (still works + for vim). + + + + + The adguardhome module no longer uses + host and port options, + use settings.bind_host and + settings.bind_port instead. + + + + + The default kops version is now 1.25.1 and + support for 1.22 and older has been dropped. + + + + + The zrepl package has been updated from + 0.5.0 to 0.6.0. See the + changelog + for details. + + + + + k3s no longer supports Docker as runtime + due to upstream dropping support. + + + + + cassandra_2_1 and + cassandra_2_2 have been removed. Please + update to cassandra_3_11 or + cassandra_3_0. See the + changelog + for more information about the upgrade process. + + + + + mysql57 has been removed. Please update to + mysql80 or mariadb. See + the + upgrade + guide for more information. + + + + + Consequently, cqrlog and + amorok now use mariadb + instead of mysql57 for their embedded + databases. Running mysql_upgrade may be + neccesary. + + + + + k3s supports clusterInit + option, and it is enabled by default, for servers. + + + + + percona-server56 has been removed. Please + migrate to mysql or + mariadb if possible. + + + + + obs-studio hase been updated to version 28. + If you have packaged custom plugins, check if they are + compatible. obs-websocket has been + integrated into obs-studio. + + + + + signald has been bumped to + 0.23.0. For the upgrade, a migration + process is necessary. It can be done by running a command like + this before starting signald.service: + + +signald -d /var/lib/signald/db \ + --database sqlite:/var/lib/signald/db \ + --migrate-data + + + For further information, please read the upstream changelogs. + + + + + stylua no longer accepts + lua52Support and + luauSupport overrides. Use + features instead, which defaults to + [ "lua54" "luau" ]. + + + + + ocamlPackages.ocaml_extlib has been renamed + to ocamlPackages.extlib. + + + + + pkgs.fetchNextcloudApp has been rewritten + to circumvent impurities in e.g. tarballs from GitHub and to + make it easier to apply patches. This means that your hashes + are out-of-date and the (previously required) attributes + name and version are no + longer accepted. + + + + + The Syncthing service now only allows absolute paths—starting + with / or ~/—for + services.syncthing.folders.<name>.path. + In a future release other paths will be allowed again and + interpreted relative to + services.syncthing.dataDir. + + + + + services.github-runner and + services.github-runners.<name> gained + the option serviceOverrides which allows + overriding the systemd serviceConfig. If + you have been overriding the systemd service configuration + (i.e., by defining + systemd.services.github-runner.serviceConfig), + you have to use the serviceOverrides option + now. Example: + + +services.github-runner.serviceOverrides.SupplementaryGroups = [ + "docker" +]; + + + +
+
+ Other Notable Changes + + + + firefox, thunderbird and + librewolf now come with Wayland support by + default. The firefox-wayland, + firefox-esr-wayland, + thunderbird-wayland and + librewolf-wayland attributes are obsolete + and have been aliased to their generic attribute. + + + + + The xplr package has been updated from + 0.18.0 to 0.19.0, which brings some breaking changes. See the + upstream + release notes for more details. + + + + + Configuring multiple GitHub runners is now possible through + services.github-runners.<name>. The + options under services.github-runner + remain, to configure a single runner. + + + + + github-runner gained support for ephemeral + runners and registrations using a personal access token (PAT) + instead of a registration token. See + services.github-runner.ephemeral and + services.github-runner.tokenFile for + details. + + + + + A new module was added to provide hardware support for the + Saleae Logic device family, providing the options + hardware.saleae-logic.enable and + hardware.saleae-logic.package. + + + + + ZFS module will no longer allow hibernation by default. + + + + + This is a safety measure to prevent data loss cases like + the ones described at + OpenZFS/260 + and + OpenZFS/12842. + + + + + Use the boot.zfs.allowHibernation + option to configure this behaviour. + + + + + + + Mastodon now automatically removes remote media attachments + older than 30 days. This is configurable through + services.mastodon.mediaAutoRemove. + + + + + The Redis module now disables RDB persistence when + services.redis.servers.<name>.save = [] + instead of using the Redis default. + + + + + Neo4j was updated from version 3 to version 4. See upstream’s + migration + guide for information on how to migrate your instance. + + + + + The networking.wireguard module now can set + the mtu on interfaces and tag its packets with an fwmark. + + + + + The option overrideStrategy was added to + the different systemd unit options + (systemd.services.<name>, + systemd.sockets.<name>, …) to allow + enforcing the creation of a dropin file, rather than the main + unit file, by setting it to asDropin. This + is useful in cases where the existence of the main unit file + is not known to Nix at evaluation time, for example when the + main unit file is provided by adding a package to + systemd.packages. See the fix proposed in + NixOS’s + systemd abstraction doesn’t work with systemd template + units for an example. + + + + + The polymc package has been removed due to + a rogue maintainer. It has been replaced by + prismlauncher, a fork by the rest of the + maintainers. For more details, see + the + PR that made this change and + the + issue detailing the vulnerability. Users with existing + installations should rename + ~/.local/share/polymc to + ~/.local/share/PrismLauncher. The main + config file’s path has also moved from + ~/.local/share/polymc/polymc.cfg to + ~/.local/share/PrismLauncher/prismlauncher.cfg. + + + + + The bloat package has been updated from + unstable-2022-03-31 to unstable-2022-10-25, which brings a + breaking change. See + this + upstream commit message for details. + + + + + Synapse’s systemd unit has been hardened. + + + + + The module services.grafana was refactored + to be compliant with + RFC + 0042. To be precise, this means that the following + things have changed: + + + + + The newly introduced option + is an + attribute-set that will be converted into Grafana’s INI + format. This means that the configuration from + Grafana’s + configuration reference can be directly written as + attribute-set in Nix within this option. + + + + + The option + services.grafana.extraOptions has been + removed. This option was an association of environment + variables for Grafana. If you had an expression like + + +{ + services.grafana.extraOptions.SECURITY_ADMIN_USER = "foobar"; +} + + + your Grafana instance was running with + GF_SECURITY_ADMIN_USER=foobar in its + environment. + + + For the migration, it is recommended to turn it into the + INI format, i.e. to declare + + +{ + services.grafana.settings.security.admin_user = "foobar"; +} + + + instead. + + + The keys in + services.grafana.extraOptions have the + format + <INI section name>_<Key Name>. + Further details are outlined in the + configuration + reference. + + + Alternatively you can also set all your values from + extraOptions to + systemd.services.grafana.environment, + make sure you don’t forget to add the + GF_ prefix though! + + + + + Previously, the options + + and + + expected lists of datasources or dashboards for the + declarative + provisioning. + + + To declare lists of + + + + + datasources, please + rename your declarations to + . + + + + + dashboards, please + rename your declarations to + . + + + + + This change was made to support more features for that: + + + + + It’s possible to declare the + apiVersion of your dashboards and + datasources by + + (or + ). + + + + + Instead of declaring datasources and dashboards in + pure Nix, it’s also possible to specify configuration + files (or directories) with YAML instead using + + (or + . + This is useful when having provisioning files from + non-NixOS Grafana instances that you also want to + deploy to NixOS. + + + Note: secrets from + these files will be leaked into the store unless you + use a + file-provider + or env-var for secrets! + + + + + + is not affected by this change because this feature is + deprecated by Grafana and will probably removed in + Grafana 10. It’s recommended to use + services.grafana.provision.alerting.contactPoints + instead. + + + + + + + + + The services.grafana.provision.alerting + option was added. It includes suboptions for every + alerting-related objects (with the exception of + notifiers), which means it’s now possible + to configure modern Grafana alerting declaratively. + + + + + Synapse now requires entries in the + state_group_edges table to be unique, in + order to prevent accidentally introducing duplicate + information (for example, because a database backup was + restored multiple times). If your Synapse database already has + duplicate rows in this table, this could fail with an error + and require manual remediation. + + + + + The diamond package has been update from + 0.8.36 to 2.0.15. See the + upstream + release notes for more details. + + + + + The guake package has been updated from + 3.6.3 to 3.9.0, see the + changelog + for more details. + + + + + The netlify-cli package has been updated + from 6.13.2 to 12.2.4, see the + changelog + for more details. + + + + + dockerTools.buildImage’s + contents parameter has been deprecated in + favor of copyToRoot. Use + copyToRoot = buildEnv { ... }; or similar + if you intend to add packages to /bin. + + + + + The proxmox.qemuConf.bios option was added, + it corresponds to Hardware->BIOS field + in Proxmox web interface. Use + "ovmf" value to build UEFI image, + default value remains "bios". New + option proxmox.partitionTableType defaults + to either "legacy" or + "efi", depending on the + bios value. Setting + partitionTableType to + "hybrid" results in an image, + which supports both methods + ("bios" and + "ovmf"), thereby remaining + bootable after change to Proxmox + Hardware->BIOS field. + + + + + memtest86+ was updated from 5.00-coreboot-002 to 6.00-beta2. + It is now the upstream version from https://www.memtest.org/, + as coreboot’s fork is no longer available. + + + + + Option descriptions, examples, and defaults writting in + DocBook are now deprecated. Using CommonMark is preferred and + will become the default in a future release. + + + + + The + documentation.nixos.options.allowDocBook + option was added to ease the transition to CommonMark option + documentation. Setting this option to false + causes an error for every option included in the manual that + uses DocBook documentation; it defaults to + true to preserve the previous behavior and + will be removed once the transition to CommonMark is complete. + + + + + The Redis module now persists each instance’s configuration + file in the state directory, in order to support some more + advanced use cases like Sentinel. @@ -179,49 +1236,214 @@ - Perl has been updated to 5.36, and its core module - HTTP::Tiny was patched to verify SSL/TLS - certificates by default. + The udisks2 service, available at + services.udisks2.enable, is now disabled by + default. It will automatically be enabled through services and + desktop environments as needed. This also means that polkit + will now actually be disabled by default. The default for + security.polkit.enable was already flipped + in the previous release, but udisks2 being enabled by default + re-enabled it. - Improved performances of - lib.closePropagation which was previously - quadratic. This is used in e.g. - ghcWithPackages. Please see backward - incompatibilities notes below. + Nextcloud has been updated to version + 25. Additionally the + following things have changed for Nextcloud in NixOS: + + + + + For Nextcloud >=24, + the default PHP version is 8.1. + + + + + Nextcloud 23 has been + removed since it will reach its + end + of life in December 2022. + + + + + If system.stateVersion is + >=22.11, Nextcloud + 25 will be installed by default. For older versions, + Nextcloud 24 will be installed. + + + + + Please ensure that you only upgrade one major release at a + time! Nextcloud doesn’t support upgrades across multiple + versions, i.e. an upgrade from + 23 to + 25 is only possible + when upgrading to 24 + first. + + + + + + + systemd-oomd is enabled by default. Depending on which systemd + units have ManagedOOMSwap=kill or + ManagedOOMMemoryPressure=kill, systemd-oomd + will SIGKILL all the processes under the appropriate + descendant cgroups when the configured limits are exceeded. + NixOS does currently not configure cgroups with oomd by + default, this can be enabled using + systemd.oomd.enableRootSlice, + systemd.oomd.enableSystemSlice, + and + systemd.oomd.enableUserServices. - Cinnamon has been updated to 5.4. While at it, the cinnamon - module now defaults to blueman as bluetooth manager and - slick-greeter as lightdm greeter to match upstream. + The tt-rss service performs two database + migrations when you first use its web UI after upgrade. + Consider backing up its database before updating. - OpenSSL now defaults to OpenSSL 3, updated from 1.1.1. + The pass-secret-service package now + includes systemd units from upstream, so adding it to the + NixOS services.dbus.packages option will + make it start automatically as a systemd user service when an + application tries to talk to the libsecret D-Bus API. - An image configuration and generator has been added for Linode - images, largely based on the present GCE configuration and - image. + The Wordpress module now has support for installing language + packs through a new option, + services.wordpress.sites.<site>.languages. - hardware.nvidia has a new option - open that can be used to opt in the - opensource version of NVIDIA kernel driver. Note that the - driver’s support for GeForce and Workstation GPUs is still - alpha quality, see - NVIDIA - Releases Open-Source GPU Kernel Modules for the - official announcement. + The default package for + services.mullvad-vpn.package was changed to + pkgs.mullvad, allowing cross-platform usage + of Mullvad. pkgs.mullvad only contains the + Mullvad CLI tool, so users who rely on the Mullvad GUI will + want to change it back to pkgs.mullvad-vpn, + or add pkgs.mullvad-vpn to their + environment. + + + + + PowerDNS has been updated from v4.6.2 to v4.7.2. Please be + sure to review the + Upgrade + Notes provided by upstream before upgrading. Worth + specifically noting is that the new Catalog Zones feature + comes with a mandatory schema change for the GSQL database + backends, which has to be manually applied. + + + + + There is a new module for the thunar + program (the Xfce file manager), which depends on the + xfconf dbus service, and also has a dbus + service and a systemd unit. The option + services.xserver.desktopManager.xfce.thunarPlugins + has been renamed to + programs.thunar.plugins, and may be removed + in a future release. + + + + + There is a new module for xfconf (the Xfce + configuration storage system), which has a dbus service. + + + + + The Mastodon package has been upgraded to v4.0.0. See the + v4.0.0 + release notes for a list of changes. On standard + setups, no manual migration steps are required. Nevertheless, + a database backup is recommended. + + + + + The nomad package now defaults to v1.3, + which no longer has a downgrade path to v1.2 or older. + + + + + The nodePackages package set now defaults + to the LTS release in the nodejs package + again, instead of being pinned to + nodejs-14_x. Several updates to node2nix + have been made for compatibility with newer Node.js and npm + versions and a new postRebuild hook has + been added for packages to perform extra build steps before + the npm install step prunes dev dependencies. + + + + + boot.kernel.sysctl is defined as a + freeformType and adds a custom merge option for + net.core.rmem_max (taking the highest value + defined to avoid conflicts between 2 services trying to set + that value). + + + + + The mame package does not ship with its + tools anymore in the default output. They were moved to a + separate tools output instead. For + convenience, mame-tools package was added + for those who want to use it. + + + + + A NixOS module for Firefox has been added which allows + preferences and + policies + to be set. This also allows extensions to be installed via the + ExtensionSettings policy. The new options + are under programs.firefox. + + + + + The option + services.picom.experimentalBackends was + removed since it is now the default and the option will cause + picom to quit instead. + + + + + haskellPackage.callHackage is not always + invalidated if all-cabal-hashes changes, + leading to less rebuilds of haskell dependencies. + + + + + haskellPackages.callHackage and + haskellPackages.callCabal2nix (and related + functions) no longer keep a reference to the + cabal2nix call used to generate them. As a + result, they will be garbage collected more often. @@ -532,1227 +1754,4 @@
-
- Backward Incompatibilities - - - - Nixpkgs now requires Nix 2.3 or newer. - - - - - The isCompatible predicate checking CPU - compatibility is no longer exposed by the platform sets - generated using lib.systems.elaborate. In - most cases you will want to use the new - canExecute predicate instead which also - considers the kernel / syscall interface. It is briefly - described in the release’s - highlights - section. - lib.systems.parse.isCompatible still - exists, but has changed semantically: Architectures with - differing endianness modes are no longer considered - compatible. - - - - - ngrok has been upgraded from 2.3.40 to - 3.0.4. Please see - the - upgrade guide and - changelog. - Notably, breaking changes are that the config file format has - changed and support for single hypen arguments was dropped. - - - - - i18n.supportedLocales is now by default - only generated with the locales set in - i18n.defaultLocale and - i18n.extraLocaleSettings. This got - partially copied over from the minimal profile and reduces the - final system size by up to 200MB. If you require all locales - installed set the option to - [ "all" ]. - - - - - Deprecated settings logrotate.paths and - logrotate.extraConfig have been removed. - Please convert any uses to - services.logrotate.settings - instead. - - - - - The isPowerPC predicate, found on - platform attrsets - (hostPlatform, - buildPlatform, - targetPlatform, etc) has been removed in - order to reduce confusion. The predicate was was defined such - that it matches only the 32-bit big-endian members of the - POWER/PowerPC family, despite having a name which would imply - a broader set of systems. If you were using this predicate, - you can replace foo.isPowerPC with - (with foo; isPower && is32bit && isBigEndian). - - - - - The fetchgit fetcher now uses - cone - mode by default for sparse checkouts. - Non-cone - mode can be enabled by passing - nonConeMode = true, but note that non-cone - mode is deprecated and this option may be removed alongside a - future Git update without notice. - - - - - The fetchgit fetcher supports sparse - checkouts via the sparseCheckout option. - This used to accept a multi-line string with - directories/patterns to check out, but now requires a list of - strings. - - - - - openssh was updated to version 9.1, - disabling the generation of DSA keys when using - ssh-keygen -A as they are insecure. Also, - SetEnv directives in - ssh_config and - sshd_config are now first-match-wins - - - - - bsp-layout no longer uses the command - cycle to switch to other window layouts, as - it got replaced by the commands previous - and next. - - - - - The Barco ClickShare driver/client package - pkgs.clickshare-csc1 and the option - programs.clickshare-csc1.enable have been - removed, as it requires qt4, which reached - its end-of-life 2015 and will no longer be supported by - nixpkgs. - According - to Barco many of their base unit models can be used - with Google Chrome and the Google Cast extension. - - - - - services.hbase has been renamed to - services.hbase-standalone. For production - HBase clusters, use services.hadoop.hbase - instead. - - - - - The p4 package now only includes the - open-source Perforce Helix Core command-line client and APIs. - It no longer installs the unfree Helix Core Server binaries - p4d, p4broker, and - p4p. To install the Helix Core Server - binaries, use the p4d package instead. - - - - - The openssl-extension for the PHP - interpreter used by Nextcloud is built against OpenSSL 1.1 if - is below - 22.11. This is to make sure that people - using - server-side - encryption don’t lose access to their files. - - - In any other case it’s safe to use OpenSSL 3 for PHP’s openssl - extension. This can be done by setting - - to false. - - - - - The coq package and versioned variants - starting at coq_8_14 no longer include - CoqIDE, which is now available through - coqPackages.coqide. It is still possible to - get CoqIDE as part of the coq package by - overriding the buildIde argument of the - derivation. - - - - - PHP 7.4 is no longer supported due to upstream not supporting - this version for the entire lifecycle of the 22.11 release. - - - - - The ipfs package and module were renamed to kubo. The kubo - module now uses an RFC42-style settings - option instead of extraConfig and the - gatewayAddress, - apiAddress and - swarmAddress options were renamed. Using - the old names will print a warning but still work. - - - - - pkgs.cosign does not provide the - cosigned binary anymore. The - sget binary has been moved into its own - package. - - - - - Emacs now uses the Lucid toolkit by default instead of GTK - because of stability and compatibility issues. Users who still - wish to remain using GTK can do so by using - emacs-gtk. - - - - - kanidm has been updated to 1.1.0-alpha.10 - and now requires a tls certificate and key. It will always - start an https and – if enabled – an ldaps server and no http - and ldap server anymore. - - - - - riak package removed along with - services.riak module, due to lack of - maintainer to update the package. - - - - - ppd files in pkgs.cups-drv-rastertosag-gdi - are now gzipped. If you refer to such a ppd file with its path - (e.g. via - hardware.printers.ensurePrinters) - you will need to append .gz to the path. - - - - - xow package removed along with the - hardware.xow module, due to the project - being deprecated in favor of xone, which is - available via the hardware.xone module. - - - - - dd-agent package removed along with the - services.dd-agent module, due to the - project being deprecated in favor of - datadog-agent, which is available via the - services.datadog-agent module. - - - - - teleport has been upgraded to major version - 10. Please see upstream - upgrade - instructions and - release - notes. - - - - - lib.closePropagation now needs that all - gathered sets have an outPath attribute. - - - - - lemmy module option - services.lemmy.settings.database.createLocally - moved to - services.lemmy.database.createLocally. - - - - - virtlyst package and services.virtlyst - module removed, due to lack of maintainers. - - - - - The nix.checkConfig option now fully - disables the config check. The new - nix.checkAllErrors option behaves like - nix.checkConfig previously did. - - - - - nix.buildMachines got a new submodule - option protocol. An undocumented hack to - set the protocol via hostName is no longer - working and the protocol option should be - used instead. - - - - - generateOptparseApplicativeCompletions and - generateOptparseApplicativeCompletion from - haskell.lib.compose (and - haskell.lib) have been deprecated in favor - of generateOptparseApplicativeCompletions - (plural!) as provided by the haskell package sets (so - haskellPackages.generateOptparseApplicativeCompletions - etc.). The latter allows for cross-compilation (by - automatically disabling generation of completion in the cross - case). For it to work properly you need to make sure that the - function comes from the same context as the package you are - trying to override, i.e. always use the same package set as - your package is coming from or – even better – use - self.generateOptparseApplicativeCompletions - if you are overriding a haskell package set. The old functions - are retained for backwards compatibility, but yield are - warning. - - - - - The services.graphite.api and - services.graphite.beacon NixOS options, and - the python3.pkgs.graphite_api, - python3.pkgs.graphite_beacon and - python3.pkgs.influxgraph packages, have - been removed due to lack of upstream maintenance. - - - - - The trace binary from - perf-linux package has been removed, due to - being a duplicate of the perf binary. - - - - - The aws package has been removed due to - being abandoned by the upstream. It is recommended to use - awscli or awscli2 - instead. - - - - - The - CEmu - TI-84 Plus CE emulator package has been renamed to - cemu-ti. The - Cemu Wii U - emulator is now packaged as cemu. - - - - - systemd-networkd v250 deprecated, renamed, - and moved some sections and settings which leads to the - following breaking module changes: - - - - - systemd.network.networks.<name>.dhcpV6PrefixDelegationConfig - is renamed to - systemd.network.networks.<name>.dhcpPrefixDelegationConfig. - - - - - systemd.network.networks.<name>.dhcpV6Config - no longer accepts the - ForceDHCPv6PDOtherInformation= setting. - Please use the WithoutRA= and - UseDelegatedPrefix= settings in your - systemd.network.networks.<name>.dhcpV6Config - and the DHCPv6Client= setting in your - systemd.network.networks.<name>.ipv6AcceptRAConfig - to control when the DHCPv6 client is started and how the - delegated prefixes are handled by the DHCPv6 client. - - - - - systemd.network.networks.<name>.networkConfig - no longer accepts the IPv6Token= - setting. Use the Token= setting in your - systemd.network.networks.<name>.ipv6AcceptRAConfig - instead. The - systemd.network.networks.<name>.ipv6Prefixes.*.ipv6PrefixConfig - now also accepts the Token= setting. - - - - - - - arangodb versions 3.3, 3.4, and 3.5 have - been removed because they are at EOL upstream. The default is - now 3.10.0. Support for aarch64-linux has been removed since - the target cannot be built reproducibly. By default - arangodb is now built for the - haswell architecture. If you wish to build - for a different architecture, you may override the - targetArchitecture argument with a value - from - this - list supported upstream. Some architecture specific - optimizations are also conditionally enabled. You may alter - this behavior by overriding the - asmOptimizations parameter. You may also - add additional architecture support by adding more - -DHAS_XYZ flags to - cmakeFlags via - overrideAttrs. - - - - - The meta.mainProgram attribute of packages - in wineWowPackages now defaults to - "wine64". - - - - - The paperless module now defaults - PAPERLESS_TIME_ZONE to your configured - system timezone. - - - - - The top-level termonad-with-packages alias - for termonad has been removed. - - - - - Linux 4.9 has been removed because it will reach its end of - life within the lifespan of 22.11. - - - - - (Neo)Vim can not be configured with - configure.pathogen anymore to reduce - maintainance burden. Use configure.packages - instead. - - - - - Neovim can not be configured with plug anymore (still works - for vim). - - - - - The adguardhome module no longer uses - host and port options, - use settings.bind_host and - settings.bind_port instead. - - - - - The default kops version is now 1.25.1 and - support for 1.22 and older has been dropped. - - - - - The zrepl package has been updated from - 0.5.0 to 0.6.0. See the - changelog - for details. - - - - - k3s no longer supports docker as runtime - due to upstream dropping support. - - - - - cassandra_2_1 and - cassandra_2_2 have been removed. Please - update to cassandra_3_11 or - cassandra_3_0. See the - changelog - for more information about the upgrade process. - - - - - mysql57 has been removed. Please update to - mysql80 or mariadb. See - the - upgrade - guide for more information. - - - - - Consequently, cqrlog and - amorok now use mariadb - instead of mysql57 for their embedded - databases. Running mysql_upgrade may be - neccesary. - - - - - k3s supports clusterInit - option, and it is enabled by default, for servers. - - - - - percona-server56 has been removed. Please - migrate to mysql or - mariadb if possible. - - - - - obs-studio hase been updated to version 28. - If you have packaged custom plugins, check if they are - compatible. obs-websocket has been - integrated into obs-studio. - - - - - signald has been bumped to - 0.23.0. For the upgrade, a migration - process is necessary. It can be done by running a command like - this before starting signald.service: - - -signald -d /var/lib/signald/db \ - --database sqlite:/var/lib/signald/db \ - --migrate-data - - - For further information, please read the upstream changelogs. - - - - - stylua no longer accepts - lua52Support and - luauSupport overrides, use - features instead, which defaults to - [ "lua54" "luau" ]. - - - - - ocamlPackages.ocaml_extlib has been renamed - to ocamlPackages.extlib. - - - - - pkgs.fetchNextcloudApp has been rewritten - to circumvent impurities in e.g. tarballs from GitHub and to - make it easier to apply patches. This means that your hashes - are out-of-date and the (previously required) attributes - name and version are no - longer accepted. - - - - - The Syncthing service now only allows absolute paths—starting - with / or ~/—for - services.syncthing.folders.<name>.path. - In a future release other paths will be allowed again and - interpreted relative to - services.syncthing.dataDir. - - - - - services.github-runner and - services.github-runners.<name> gained - the option serviceOverrides which allows - overriding the systemd serviceConfig. If - you have been overriding the systemd service configuration - (i.e., by defining - systemd.services.github-runner.serviceConfig), - you have to use the serviceOverrides option - now. Example: - - -services.github-runner.serviceOverrides.SupplementaryGroups = [ - "docker" -]; - - - -
-
- Other Notable Changes - - - - firefox, thunderbird and - librewolf come with enabled Wayland support - by default. The firefox-wayland, - firefox-esr-wayland, - thunderbird-wayland and - librewolf-wayland attributes are obsolete - and have been aliased to their generic attribute. - - - - - The xplr package has been updated from - 0.18.0 to 0.19.0, which brings some breaking changes. See the - upstream - release notes for more details. - - - - - Configuring multiple GitHub runners is now possible through - services.github-runners.<name>. The - option services.github-runner remains. - - - - - github-runner gained support for ephemeral - runners and registrations using a personal access token (PAT) - instead of a registration token. See - services.github-runner.ephemeral and - services.github-runner.tokenFile for - details. - - - - - A new module was added for the Saleae Logic device family, - providing the options - hardware.saleae-logic.enable and - hardware.saleae-logic.package. - - - - - ZFS module will not allow hibernation by default, this is a - safety measure to prevent data loss cases like the ones - described at - OpenZFS/260 - and - OpenZFS/12842. - Use the boot.zfs.allowHibernation option to - configure this behaviour. - - - - - mastodon now automatically removes remote - media attachments older than 30 days. This is configurable - through services.mastodon.mediaAutoRemove. - - - - - The Redis module now disables RDB persistence when - services.redis.servers.<name>.save = [] - instead of using the Redis default. - - - - - Neo4j was updated from version 3 to version 4. See this - migration - guide on how to migrate your Neo4j instance. - - - - - The networking.wireguard module now can set - the mtu on interfaces and tag its packets with an fwmark. - - - - - The option overrideStrategy was added to - the different systemd unit options - (systemd.services.<name>, - systemd.sockets.<name>, …) to allow - enforcing the creation of a dropin file, rather than the main - unit file, by setting it to asDropin. This - is useful in cases where the existence of the main unit file - is not known to Nix at evaluation time, for example when the - main unit file is provided by adding a package to - systemd.packages. See the fix proposed in - NixOS’s - systemd abstraction doesn’t work with systemd template - units for an example. - - - - - The polymc package has been removed due to - a rogue maintainer. It has been replaced by - prismlauncher, a fork by the rest of the - maintainers. For more details, see - the - pull request that made this change and - this - issue detailing the vulnerability. Users with existing - installations should rename - ~/.local/share/polymc to - ~/.local/share/PrismLauncher. The main - config file’s path has also moved from - ~/.local/share/polymc/polymc.cfg to - ~/.local/share/PrismLauncher/prismlauncher.cfg. - - - - - The bloat package has been updated from - unstable-2022-03-31 to unstable-2022-10-25, which brings a - breaking change. See - this - upstream commit message for details. - - - - - The services.matrix-synapse systemd unit - has been hardened. - - - - - The module services.grafana was refactored - to be compliant with - RFC - 0042. To be precise, this means that the following - things have changed: - - - - - The newly introduced option - is an - attribute-set that will be converted into Grafana’s INI - format. This means that the configuration from - Grafana’s - configuration reference can be directly written as - attribute-set in Nix within this option. - - - - - The option - services.grafana.extraOptions has been - removed. This option was an association of environment - variables for Grafana. If you had an expression like - - -{ - services.grafana.extraOptions.SECURITY_ADMIN_USER = "foobar"; -} - - - your Grafana instance was running with - GF_SECURITY_ADMIN_USER=foobar in its - environment. - - - For the migration, it is recommended to turn it into the - INI format, i.e. to declare - - -{ - services.grafana.settings.security.admin_user = "foobar"; -} - - - instead. - - - The keys in - services.grafana.extraOptions have the - format - <INI section name>_<Key Name>. - Further details are outlined in the - configuration - reference. - - - Alternatively you can also set all your values from - extraOptions to - systemd.services.grafana.environment, - make sure you don’t forget to add the - GF_ prefix though! - - - - - Previously, the options - - and - - expected lists of datasources or dashboards for the - declarative - provisioning. - - - To declare lists of - - - - - datasources, please - rename your declarations to - . - - - - - dashboards, please - rename your declarations to - . - - - - - This change was made to support more features for that: - - - - - It’s possible to declare the - apiVersion of your dashboards and - datasources by - - (or - ). - - - - - Instead of declaring datasources and dashboards in - pure Nix, it’s also possible to specify configuration - files (or directories) with YAML instead using - - (or - . - This is useful when having provisioning files from - non-NixOS Grafana instances that you also want to - deploy to NixOS. - - - Note: secrets from - these files will be leaked into the store unless you - use a - file-provider - or env-var for secrets! - - - - - - is not affected by this change because this feature is - deprecated by Grafana and will probably removed in - Grafana 10. It’s recommended to use - services.grafana.provision.alerting.contactPoints - instead. - - - - - - - - - The services.grafana.provision.alerting - option was added. It includes suboptions for every - alerting-related objects (with the exception of - notifiers), which means it’s now possible - to configure modern Grafana alerting declaratively. - - - - - Matrix Synapse now requires entries in the - state_group_edges table to be unique, in - order to prevent accidentally introducing duplicate - information (for example, because a database backup was - restored multiple times). If your Synapse database already has - duplicate rows in this table, this could fail with an error - and require manual remediation. - - - - - The diamond package has been update from - 0.8.36 to 2.0.15. See the - upstream - release notes for more details. - - - - - The guake package has been updated from - 3.6.3 to 3.9.0, see the - changelog - for more details. - - - - - The netlify-cli package has been updated - from 6.13.2 to 12.2.4, see the - changelog - for more details. - - - - - dockerTools.buildImage deprecates the - misunderstood contents parameter, in favor - of copyToRoot. Use - copyToRoot = buildEnv { ... }; or similar - if you intend to add packages to /bin. - - - - - The proxmox.qemuConf.bios option was added, - it corresponds to Hardware->BIOS field - in Proxmox web interface. Use - "ovmf" value to build UEFI image, - default value remains "bios". New - option proxmox.partitionTableType defaults - to either "legacy" or - "efi", depending on the - bios value. Setting - partitionTableType to - "hybrid" results in an image, - which supports both methods - ("bios" and - "ovmf"), thereby remaining - bootable after change to Proxmox - Hardware->BIOS field. - - - - - memtest86+ was updated from 5.00-coreboot-002 to 6.00-beta2. - It is now the upstream version from https://www.memtest.org/, - as coreboot’s fork is no longer available. - - - - - Option descriptions, examples, and defaults writting in - DocBook are now deprecated. Using CommonMark is preferred and - will become the default in a future release. - - - - - The - documentation.nixos.options.allowDocBook - option was added to ease the transition to CommonMark option - documentation. Setting this option to false - causes an error for every option included in the manual that - uses DocBook documentation; it defaults to - true to preserve the previous behavior and - will be removed once the transition to CommonMark is complete. - - - - - The redis module now persists each instance’s configuration - file in the state directory, in order to support some more - advanced use cases like sentinel. - - - - - The udisks2 service, available at - services.udisks2.enable, is now disabled by - default. It will automatically be enabled through services and - desktop environments as needed. This also means that polkit - will now actually be disabled by default. The default for - security.polkit.enable was already flipped - in the previous release, but udisks2 being enabled by default - re-enabled it. - - - - - Nextcloud has been updated to version - 25. Additionally the - following things have changed for Nextcloud in NixOS: - - - - - For Nextcloud >=24, - the default PHP version is 8.1. - - - - - Nextcloud 23 has been - removed since it will reach its - end - of life in December 2022. - - - - - For system.stateVersion being - >=22.11, Nextcloud - 25 will be installed by default. For older versions, - Nextcloud 24 will be installed. - - - - - Please ensure that you only upgrade on major release at a - time! Nextcloud doesn’t support upgrades across multiple - versions, i.e. an upgrade from - 23 to - 25 is only possible - when upgrading to 24 - first. - - - - - - - Add udev rules for the Teensy family of microcontrollers. - - - - - The Qt QML disk cache is now disabled by default. This fixes a - long-standing issue where updating Qt/KDE apps would sometimes - cause them to crash or behave strangely without explanation. - Those concerned about the small (~10%) performance hit to - application startup can re-enable the cache (and expose - themselves to gremlins) by setting the envrionment variable - QML_FORCE_DISK_CACHE to - 1 using e.g. the - environment.sessionVariables NixOS option. - - - - - systemd-oomd is enabled by default. Depending on which systemd - units have ManagedOOMSwap=kill or - ManagedOOMMemoryPressure=kill, systemd-oomd - will SIGKILL all the processes under the appropriate - descendant cgroups when the configured limits are exceeded. - NixOS does currently not configure cgroups with oomd by - default, this can be enabled using - systemd.oomd.enableRootSlice, - systemd.oomd.enableSystemSlice, - and - systemd.oomd.enableUserServices. - - - - - The tt-rss service performs two database - migrations when you first use its web UI after upgrade. - Consider backing up its database before updating. - - - - - The pass-secret-service package now - includes systemd units from upstream, so adding it to the - NixOS services.dbus.packages option will - make it start automatically as a systemd user service when an - application tries to talk to the libsecret D-Bus API. - - - - - There is a new module for AMD SEV CPU functionality, which - grants access to the hardware. - - - - - The Wordpress module got support for installing language packs - through - services.wordpress.sites.<site>.languages. - - - - - The default package for - services.mullvad-vpn.package was changed to - pkgs.mullvad, allowing cross-platform usage - of Mullvad. pkgs.mullvad only contains the - Mullvad CLI tool, so users who rely on the Mullvad GUI will - want to change it back to pkgs.mullvad-vpn, - or add pkgs.mullvad-vpn to their - environment. - - - - - PowerDNS has been updated from 4.6.x to - 4.7.x. Please be sure to review the - Upgrade - Notes provided by upstream before upgrading. Worth - specifically noting is that the new Catalog Zones feature - comes with a mandatory schema change for the gsql database - backends, which has to be manually applied. - - - - - There is a new module for the thunar - program (the Xfce file manager), which depends on the - xfconf dbus service, and also has a dbus - service and a systemd unit. The option - services.xserver.desktopManager.xfce.thunarPlugins - has been renamed to - programs.thunar.plugins, and in a future - release it may be removed. - - - - - There is a new module for the xfconf - program (the Xfce configuration storage system), which has a - dbus service. - - - - - The Mastodon package got upgraded from the major version 3 to - 4. See the - v4.0.0 - release notes for a list of changes. On standard - setups, no manual migration steps are required. Nevertheless, - a database backup is recommended. - - - - - The nomad package now defaults to 1.3, - which no longer has a downgrade path to releases 1.2 or older. - - - - - The nodePackages package set now defaults - to the LTS release in the nodejs package - again, instead of being pinned to - nodejs-14_x. Several updates to node2nix - have been made for compatibility with newer Node.js and npm - versions and a new postRebuild hook has - been added for packages to perform extra build steps before - the npm install step prunes dev dependencies. - - - - - boot.kernel.sysctl is defined as a - freeformType and adds a custom merge option for - net.core.rmem_max (taking the highest value - defined to avoid conflicts between 2 services trying to set - that value). - - - - - The mame package does not ship with its - tools anymore in the default output. They were moved to a - separate tools output instead. For - convenience, mame-tools package was added - for those who want to use it. - - - - - A NixOS module for Firefox has been added which allows - preferences and - policies - to be set. This also allows extensions to be installed via the - ExtensionSettings policy. The new options - are under programs.firefox. - - - - - The option - services.picom.experimentalBackends was - removed since it is now the default and the option will cause - picom to quit instead. - - - - - haskellPackage.callHackage is not always - invalidated if all-cabal-hashes changes, - leading to less rebuilds of haskell dependencies. - - - - - haskellPackages.callHackage and - haskellPackages.callCabal2nix (and related - functions) no longer keep a reference to the - cabal2nix call used to generate them. As a - result, they will be garbage collected more often. - - - -
diff --git a/nixos/doc/manual/release-notes/rl-2211.section.md b/nixos/doc/manual/release-notes/rl-2211.section.md index 6d0bc1197768..7a5e6ead8760 100644 --- a/nixos/doc/manual/release-notes/rl-2211.section.md +++ b/nixos/doc/manual/release-notes/rl-2211.section.md @@ -1,14 +1,62 @@ # Release 22.11 (“Raccoon”, 2022.11/??) {#sec-release-22.11} -Support is planned until the end of June 2023, handing over to 23.05. +This release is supported until the end of June 2023, handing over to NixOS 23.05. ## Highlights {#sec-release-22.11-highlights} -In addition to numerous new and upgraded packages, this release has the following highlights: +In addition to numerous new and upgraded packages, this release includes the following highlights: -- GNOME has been upgraded to 43. Please take a look at their [Release - Notes](https://release.gnome.org/43/) for details. +- GNOME has been upgraded to version 43. Please take a look at their [Release Notes](https://release.gnome.org/43/) for details. +- KDE Plasma has been upgraded from v5.24 to v5.26. Please see the release notes for [v5.25](https://kde.org/announcements/plasma/5/5.25.0/) and [v5.26](https://kde.org/announcements/plasma/5/5.26.0/) for more details on the included changes. + +- Cinnamon has been updated to 5.4, and the Cinnamon module now defaults to + Blueman as the Bluetooth manager and slick-greeter as the LightDM greeter, to match upstream. + +- OpenSSL now defaults to OpenSSL 3, updated from 1.1.1. + +- PHP now defaults to PHP 8.1, updated from 8.0. + +- PHP is now built in `NTS` (Non-Thread Safe) mode by default. + - For Apache and `mod_php` usage, we enable `ZTS` (Zend Thread Safe) mode. This has been a + common practice for a long time in other distributions. + +- Perl has been updated to 5.36, and its core module `HTTP::Tiny` was patched to verify SSL/TLS certificates by default. + +- `nscd` functionality, necessary to provide non-glibc-builtin NSS + modules (such as `nss_systemd` or `nss_ldap`) can now be provided by + `nsncd`, by setting `services.nscd.enableNsncd` to `true`. + + The `nscd` daemon provided by glibc, which is currently used by NixOS isn't + very reliable. For example, it's [not fully possible to disable caching + functionality](https://github.com/NixOS/nixpkgs/issues/135888), causing + various issues and failed lookups. + + In contrast to nscd's behavior of caching module responses on its own, + nsncd merely forwards requests to NSS modules, which might cache or not. + + We plan to use `nsncd` by default in NixOS 23.05. + +- The `emacs` package now makes use of native compilation which means: + - Emacs packages from Nixpkgs, builtin or not, will do native compilation ahead of time so you can enjoy the benefit of native compilation without compiling them on you machine; + - Emacs packages from somewhere else, e.g. `package-install`, will perform asynchronously deferred native compilation. If you do not want this, maybe to avoid CPU consumption for compilation, you can use `(setq native-comp-deferred-compilation nil)` to disable it while still benefiting from native compilation for packages from Nixpkgs. + +- `nixos-generate-config` now generates configurations that can be built in pure + mode. This is achieved by setting the new `nixpkgs.hostPlatform` option. + + You may have to unset the `system` parameter in `lib.nixosSystem`, or similarly + remove definitions of the `nixpkgs.{system,localSystem,crossSystem}` options. + + Alternatively, you can remove the `hostPlatform` line and use NixOS like you + would in NixOS 22.05 and earlier. + +- It is now possible to generate NixOS images for the Linode cloud provider, via `system.build.linodeImage`. + +- `hardware.nvidia` has a new option, `hardware.nvidia.open`, that can be used to enable the usage of NVIDIA's open-source kernel driver. Note that the driver's support for GeForce and Workstation GPUs is still alpha quality, see [the release announcement](https://developer.nvidia.com/blog/nvidia-releases-open-source-gpu-kernel-modules/) for more information. + +## Internal changes {#sec-release-22.11-internal} + +- Improved performances of `lib.closePropagation` which was previously quadratic. This is used in e.g. `ghcWithPackages`. Please see backward incompatibilities notes below. - During cross-compilation, tests are now executed if the test suite can be executed by the build platform. This is the case when doing “native” cross-compilation where the build and host platforms are largely the same, but the nixpkgs' cross @@ -38,55 +86,366 @@ In addition to numerous new and upgraded packages, this release has the followin for a transition period so that in time the ecosystem can switch without breaking compatibility with any supported NixOS release. -- `nscd` functionality, necessary to provide non-glibc-builtin NSS - modules (such as `nss_systemd` or `nss_ldap`) can now be provided by - `nsncd`, by setting `services.nscd.enableNsncd` to `true`. +## Backward Incompatibilities {#sec-release-22.11-incompatibilities} - The `nscd` daemon provided by glibc, which is currently used by NixOS isn't - very reliable. For example, it's [not fully possible to disable caching - functionality](https://github.com/NixOS/nixpkgs/issues/135888), causing - various issues and failed lookups. +- Nixpkgs now requires Nix 2.3 or newer. - In contrast to nscd's behavior of caching module responses on its own, - nsncd merely forwards requests to NSS modules, which might cache or not. +- The `isCompatible` predicate checking CPU compatibility is no longer exposed + by the platform sets generated using `lib.systems.elaborate`. In most cases + you will want to use the new `canExecute` predicate instead which also + considers the kernel / syscall interface. It is briefly described in the + release's [highlights section](#sec-release-22.11-highlights). + `lib.systems.parse.isCompatible` still exists, but has changed semantically: + Architectures with differing endianness modes are *no longer considered compatible*. - We plan to use `nsncd` by default in NixOS 23.05. +- `ngrok` has been upgraded from 2.3.40 to 3.0.4. Please see [the upgrade guide](https://ngrok.com/docs/guides/upgrade-v2-v3) + and [changelog](https://ngrok.com/docs/ngrok-agent/changelog). Notably, breaking changes are that the config file format has + changed and support for single hyphen arguments was dropped. -- `emacs` enables native compilation which means: - - emacs packages from nixpkgs, builtin or not, will do native compilation ahead of time so you can enjoy the benefit of native compilation without compiling them on you machine; - - emacs packages from somewhere else, e.g. `package-install`, will do asynchronously deferred native compilation. If you do not want this, maybe to avoid CPU consumption for compilation, you can use `(setq native-comp-deferred-compilation nil)` to disable it while still enjoy the benefit of native compilation for packages from nixpkgs. +- `i18n.supportedLocales` is now only generated with the locales set in `i18n.defaultLocale` and `i18n.extraLocaleSettings`. + - This reduces the final system closure size by up to 200MB. + - If you require all locales installed, set the option to ``[ "all" ]``. -- `nixos-generate-config` now generates configurations that can be built in pure - mode. This is achieved by setting the new `nixpkgs.hostPlatform` option. +- Deprecated settings `logrotate.paths` and `logrotate.extraConfig` have + been removed. Please convert any uses to + [services.logrotate.settings](#opt-services.logrotate.settings) instead. - You may have to unset the `system` parameter in `lib.nixosSystem`, or similarly - remove definitions of the `nixpkgs.{system,localSystem,crossSystem}` options. +- The `isPowerPC` predicate, found on `platform` attrsets (`hostPlatform`, `buildPlatform`, `targetPlatform`, etc) has been removed in order to reduce confusion. The predicate was was defined such that it matches only the 32-bit big-endian members of the POWER/PowerPC family, despite having a name which would imply a broader set of systems. If you were using this predicate, you can replace `foo.isPowerPC` with `(with foo; isPower && is32bit && isBigEndian)`. - Alternatively, you can remove the `hostPlatform` line and use NixOS like you - would in NixOS 22.05 and earlier. +- The `fetchgit` fetcher now uses [cone mode](https://www.git-scm.com/docs/git-sparse-checkout/2.37.0#_internalscone_mode_handling) by default for sparse checkouts. [Non-cone mode](https://www.git-scm.com/docs/git-sparse-checkout/2.37.0#_internalsnon_cone_problems) can be enabled by passing `nonConeMode = true`, but note that non-cone mode is deprecated and this option may be removed alongside a future Git update without notice. -- PHP now defaults to PHP 8.1, updated from 8.0. +- The `fetchgit` fetcher supports sparse checkouts via the `sparseCheckout` option. This used to accept a multi-line string with directories/patterns to check out, but now requires a list of strings -- PHP is now built `NTS` (Non-Thread Safe) style by default, for Apache and - `mod_php` usage we still enable `ZTS` (Zend Thread Safe). This has been a - common practice for a long time in other distributions. +- `openssh` was updated to version 9.1, disabling the generation of DSA keys when using `ssh-keygen -A` as they are insecure. Also, `SetEnv` directives in `ssh_config` and `sshd_config` are now first-match-wins -- PHP 8.2.0 RC 7 is available. +- `bsp-layout` no longer uses the command `cycle` to switch to other window layouts, as it got replaced by the commands `previous` and `next`. + +- The Barco ClickShare driver/client package `pkgs.clickshare-csc1` and the option `programs.clickshare-csc1.enable` have been removed, + as it requires `qt4`, which reached its end-of-life 2015 and will no longer be supported by nixpkgs. + [According to Barco](https://www.barco.com/de/support/knowledge-base/4380-can-i-use-linux-os-with-clickshare-base-units) many of their base unit models can be used with Google Chrome and the Google Cast extension. + +- `services.hbase` has been renamed to `services.hbase-standalone`. + For production HBase clusters, use `services.hadoop.hbase` instead. + +- The `p4` package now only includes the open-source Perforce Helix Core command-line client and APIs. It no longer installs the unfree Helix Core Server binaries `p4d`, `p4broker`, and `p4p`. To install the Helix Core Server binaries, use the `p4d` package instead. + +- The OpenSSL extension for the PHP interpreter used by Nextcloud is built against OpenSSL 1.1 if + [](#opt-system.stateVersion) is below `22.11`. This is to make sure that people using [server-side encryption](https://docs.nextcloud.com/server/latest/admin_manual/configuration_files/encryption_configuration.html) + don't lose access to their files. + + In any other case, it's safe to use OpenSSL 3 for PHP's OpenSSL extension. This can be done by setting + [](#opt-services.nextcloud.enableBrokenCiphersForSSE) to `false`. + +- The `coq` package and versioned variants starting at `coq_8_14` no + longer include CoqIDE, which is now available through + `coqPackages.coqide`. It is still possible to get CoqIDE as part of + the `coq` package by overriding the `buildIde` argument of the + derivation. + +- PHP 7.4 is no longer supported due to upstream not supporting this + version for the entire lifecycle of the 22.11 release. + +- The ipfs package and module were renamed to kubo. The kubo module now uses an RFC42-style `settings` option instead of `extraConfig` and the `gatewayAddress`, `apiAddress` and `swarmAddress` options were renamed. Using the old names will print a warning but still work. + +- `pkgs.cosign` does not provide the `cosigned` binary anymore. The `sget` binary has been moved into its own package. + +- Emacs now uses the Lucid toolkit by default instead of GTK because of stability and compatibility issues. + Users who still wish to remain using GTK can do so by using `emacs-gtk`. + +- `kanidm` has been updated to 1.1.0-alpha.10 and now requires a TLS certificate and key. It will always start `https` and-–-if enabled-–-an LDAPS server and no HTTP and LDAP server anymore + +- riak package removed along with `services.riak` module, due to lack of maintainer to update the package. + +- ppd files in `pkgs.cups-drv-rastertosag-gdi` are now gzipped. If you refer to such a ppd file with its path (e.g. via [hardware.printers.ensurePrinters](options.html#opt-hardware.printers.ensurePrinters)) you will need to append `.gz` to the path. + +- xow package removed along with the `hardware.xow` module, due to the project being deprecated in favor of `xone`, which is available via the `hardware.xone` module. + +- dd-agent package removed along with the `services.dd-agent` module, due to the project being deprecated in favor of `datadog-agent`, which is available via the `services.datadog-agent` module. + +- `teleport` has been upgraded to major version 10. Please see upstream [upgrade instructions](https://goteleport.com/docs/ver/10.0/management/operations/upgrading/) and [release notes](https://goteleport.com/docs/ver/10.0/changelog/#1000). + +- `lib.closePropagation` now needs that all gathered sets have an `outPath` attribute. + +- lemmy module option `services.lemmy.settings.database.createLocally` + moved to `services.lemmy.database.createLocally`. + +- virtlyst package and `services.virtlyst` module removed, due to lack of maintainers. + +- The `nix.checkConfig` option now fully disables the config check. The new `nix.checkAllErrors` option behaves like `nix.checkConfig` previously did. + +- `generateOptparseApplicativeCompletions` and `generateOptparseApplicativeCompletion` from `haskell.lib.compose` + (and `haskell.lib`) have been deprecated in favor of `generateOptparseApplicativeCompletions` (plural!) as + provided by the haskell package sets (so `haskellPackages.generateOptparseApplicativeCompletions` etc.). + The latter allows for cross-compilation (by automatically disabling generation of completion in the cross case). + For it to work properly you need to make sure that the function comes from the same context as the package + you are trying to override, i.e. always use the same package set as your package is coming from or – even + better – use `self.generateOptparseApplicativeCompletions` if you are overriding a haskell package set. + The old functions are retained for backwards compatibility, but yield are warning. + +- The `services.graphite.api` and `services.graphite.beacon` NixOS options, and + the `python3.pkgs.graphite_api`, `python3.pkgs.graphite_beacon` and + `python3.pkgs.influxgraph` packages, have been removed due to lack of upstream + maintenance. + +- The `trace` binary from `perf-linux` package has been removed, due to being a duplicate of the `perf` binary. + +- The `aws` package has been removed due to being abandoned by the upstream. It is recommended to use `awscli` or `awscli2` instead. + +- The [CEmu TI-84 Plus CE emulator](https://ce-programming.github.io/CEmu) package has been renamed to `cemu-ti`. The [Cemu Wii U emulator](https://cemu.info) is now packaged as `cemu`. + +- `systemd-networkd` v250 deprecated, renamed, and moved some sections and settings which leads to the following breaking module changes: + + * `systemd.network.networks..dhcpV6PrefixDelegationConfig` is renamed to `systemd.network.networks..dhcpPrefixDelegationConfig`. + * `systemd.network.networks..dhcpV6Config` no longer accepts the `ForceDHCPv6PDOtherInformation=` setting. Please use the `WithoutRA=` and `UseDelegatedPrefix=` settings in your `systemd.network.networks..dhcpV6Config` and the `DHCPv6Client=` setting in your `systemd.network.networks..ipv6AcceptRAConfig` to control when the DHCPv6 client is started and how the delegated prefixes are handled by the DHCPv6 client. + * `systemd.network.networks..networkConfig` no longer accepts the `IPv6Token=` setting. Use the `Token=` setting in your `systemd.network.networks..ipv6AcceptRAConfig` instead. The `systemd.network.networks..ipv6Prefixes.*.ipv6PrefixConfig` now also accepts the `Token=` setting. + +- `arangodb` versions 3.3, 3.4, and 3.5 have been removed because they are at EOL upstream. The default is now 3.10.0. Support for aarch64-linux has been removed since the target cannot be built reproducibly. By default `arangodb` is now built for the `haswell` architecture. If you wish to build for a different architecture, you may override the `targetArchitecture` argument with a value from [this list supported upstream](https://github.com/arangodb/arangodb/blob/207ec6937e41a46e10aea34953879341f0606841/cmake/OptimizeForArchitecture.cmake#L594). Some architecture specific optimizations are also conditionally enabled. You may alter this behavior by overriding the `asmOptimizations` parameter. You may also add additional architecture support by adding more `-DHAS_XYZ` flags to `cmakeFlags` via `overrideAttrs`. + +- The `meta.mainProgram` attribute of packages in `wineWowPackages` now defaults to `"wine64"`. + +- The `paperless` module now defaults `PAPERLESS_TIME_ZONE` to your configured system timezone. + +- The top-level `termonad-with-packages` alias for `termonad` has been removed. + +- Linux 4.9 has been removed because it will reach its end of life within the lifespan of 22.11. + +- (Neo)Vim can not be configured with `configure.pathogen` anymore to reduce maintainance burden. + Use `configure.packages` instead. +- Neovim can not be configured with plug anymore (still works for vim). + +- The `adguardhome` module no longer uses `host` and `port` options, use `settings.bind_host` and `settings.bind_port` instead. + +- The default `kops` version is now 1.25.1 and support for 1.22 and older has been dropped. + +- The `zrepl` package has been updated from 0.5.0 to 0.6.0. See the [changelog](https://zrepl.github.io/changelog.html) for details. + +- `k3s` no longer supports Docker as runtime due to upstream dropping support. + +- `cassandra_2_1` and `cassandra_2_2` have been removed. Please update to `cassandra_3_11` or `cassandra_3_0`. See the [changelog](https://github.com/apache/cassandra/blob/cassandra-3.11.14/NEWS.txt) for more information about the upgrade process. + +- `mysql57` has been removed. Please update to `mysql80` or `mariadb`. See the [upgrade guide](https://mariadb.com/kb/en/upgrading-from-mysql-to-mariadb/) for more information. + +- Consequently, `cqrlog` and `amorok` now use `mariadb` instead of `mysql57` for their embedded databases. Running `mysql_upgrade` may be neccesary. +- `k3s` supports `clusterInit` option, and it is enabled by default, for servers. + +- `percona-server56` has been removed. Please migrate to `mysql` or `mariadb` if possible. + +- `obs-studio` hase been updated to version 28. If you have packaged custom plugins, check if they are compatible. `obs-websocket` has been integrated into `obs-studio`. + +- `signald` has been bumped to `0.23.0`. For the upgrade, a migration process is necessary. It can be + done by running a command like this before starting `signald.service`: + + ``` + signald -d /var/lib/signald/db \ + --database sqlite:/var/lib/signald/db \ + --migrate-data + ``` + + For further information, please read the upstream changelogs. + +- `stylua` no longer accepts `lua52Support` and `luauSupport` overrides. Use `features` instead, which defaults to `[ "lua54" "luau" ]`. + +- `ocamlPackages.ocaml_extlib` has been renamed to `ocamlPackages.extlib`. + +- `pkgs.fetchNextcloudApp` has been rewritten to circumvent impurities in e.g. tarballs from GitHub and to make it easier to + apply patches. This means that your hashes are out-of-date and the (previously required) attributes `name` and `version` + are no longer accepted. + +- The Syncthing service now only allows absolute paths---starting with `/` or + `~/`---for `services.syncthing.folders..path`. + In a future release other paths will be allowed again and interpreted + relative to `services.syncthing.dataDir`. + +- `services.github-runner` and `services.github-runners.` gained the option `serviceOverrides` which allows overriding the systemd `serviceConfig`. If you have been overriding the systemd service configuration (i.e., by defining `systemd.services.github-runner.serviceConfig`), you have to use the `serviceOverrides` option now. Example: + + ``` + services.github-runner.serviceOverrides.SupplementaryGroups = [ + "docker" + ]; + ``` + + + +## Other Notable Changes {#sec-release-22.11-notable-changes} + +- `firefox`, `thunderbird` and `librewolf` now come with Wayland support by default. The `firefox-wayland`, `firefox-esr-wayland`, `thunderbird-wayland` and `librewolf-wayland` attributes are obsolete and have been aliased to their generic attribute. + +- The `xplr` package has been updated from 0.18.0 to 0.19.0, which brings some breaking changes. See the [upstream release notes](https://github.com/sayanarijit/xplr/releases/tag/v0.19.0) for more details. + +- Configuring multiple GitHub runners is now possible through `services.github-runners.`. The options under `services.github-runner` remain, to configure a single runner. + +- `github-runner` gained support for ephemeral runners and registrations using a personal access token (PAT) instead of a registration token. See `services.github-runner.ephemeral` and `services.github-runner.tokenFile` for details. + +- A new module was added to provide hardware support for the Saleae Logic device family, providing the options `hardware.saleae-logic.enable` and `hardware.saleae-logic.package`. + +- ZFS module will no longer allow hibernation by default. + - This is a safety measure to prevent data loss cases like the ones described at [OpenZFS/260](https://github.com/openzfs/zfs/issues/260) and [OpenZFS/12842](https://github.com/openzfs/zfs/issues/12842). + - Use the `boot.zfs.allowHibernation` option to configure this behaviour. + +- Mastodon now automatically removes remote media attachments older than 30 days. This is configurable through `services.mastodon.mediaAutoRemove`. + +- The Redis module now disables RDB persistence when `services.redis.servers..save = []` instead of using the Redis default. + +- Neo4j was updated from version 3 to version 4. See upstream's [migration guide](https://neo4j.com/docs/upgrade-migration-guide/current/) for information on how to migrate your instance. + +- The `networking.wireguard` module now can set the mtu on interfaces and tag its packets with an fwmark. + +- The option `overrideStrategy` was added to the different systemd unit options (`systemd.services.`, `systemd.sockets.`, …) to allow enforcing the creation of a dropin file, rather than the main unit file, by setting it to `asDropin`. + This is useful in cases where the existence of the main unit file is not known to Nix at evaluation time, for example when the main unit file is provided by adding a package to `systemd.packages`. + See the fix proposed in [NixOS's systemd abstraction doesn't work with systemd template units](https://github.com/NixOS/nixpkgs/issues/135557#issuecomment-1295392470) for an example. + +- The `polymc` package has been removed due to a rogue maintainer. It has been + replaced by `prismlauncher`, a fork by the rest of the maintainers. For more + details, see [the PR that made this change](https://github.com/NixOS/nixpkgs/pull/196624) and + [the issue detailing the vulnerability](https://github.com/NixOS/nixpkgs/issues/196460). + Users with existing installations should rename `~/.local/share/polymc` to + `~/.local/share/PrismLauncher`. The main config file's path has also moved + from `~/.local/share/polymc/polymc.cfg` to + `~/.local/share/PrismLauncher/prismlauncher.cfg`. + +- The `bloat` package has been updated from unstable-2022-03-31 to unstable-2022-10-25, which brings a breaking change. See [this upstream commit message](https://git.freesoftwareextremist.com/bloat/commit/?id=887ed241d64ba5db3fd3d87194fb5595e5ad7d73) for details. + +- Synapse's systemd unit has been hardened. + +- The module `services.grafana` was refactored to be compliant with [RFC 0042](https://github.com/NixOS/rfcs/blob/master/rfcs/0042-config-option.md). To be precise, this means that the following things have changed: + - The newly introduced option [](#opt-services.grafana.settings) is an attribute-set that + will be converted into Grafana's INI format. This means that the configuration from + [Grafana's configuration reference](https://grafana.com/docs/grafana/latest/setup-grafana/configure-grafana/) + can be directly written as attribute-set in Nix within this option. + - The option `services.grafana.extraOptions` has been removed. This option was an association + of environment variables for Grafana. If you had an expression like + + ```nix + { + services.grafana.extraOptions.SECURITY_ADMIN_USER = "foobar"; + } + ``` + + your Grafana instance was running with `GF_SECURITY_ADMIN_USER=foobar` in its environment. + + For the migration, it is recommended to turn it into the INI format, i.e. + to declare + + ```nix + { + services.grafana.settings.security.admin_user = "foobar"; + } + ``` + + instead. + + The keys in `services.grafana.extraOptions` have the format `_`. + Further details are outlined in the [configuration reference](https://grafana.com/docs/grafana/latest/setup-grafana/configure-grafana/#override-configuration-with-environment-variables). + + Alternatively you can also set all your values from `extraOptions` to + `systemd.services.grafana.environment`, make sure you don't forget to add + the `GF_` prefix though! + - Previously, the options [](#opt-services.grafana.provision.datasources) and + [](#opt-services.grafana.provision.dashboards) expected lists of datasources + or dashboards for the [declarative provisioning](https://grafana.com/docs/grafana/latest/administration/provisioning/). + + To declare lists of + - **datasources**, please rename your declarations to [](#opt-services.grafana.provision.datasources.settings.datasources). + - **dashboards**, please rename your declarations to [](#opt-services.grafana.provision.dashboards.settings.providers). + + This change was made to support more features for that: + + - It's possible to declare the `apiVersion` of your dashboards and datasources + by [](#opt-services.grafana.provision.datasources.settings.apiVersion) (or + [](#opt-services.grafana.provision.dashboards.settings.apiVersion)). + + - Instead of declaring datasources and dashboards in pure Nix, it's also possible + to specify configuration files (or directories) with YAML instead using + [](#opt-services.grafana.provision.datasources.path) (or + [](#opt-services.grafana.provision.dashboards.path). This is useful when having + provisioning files from non-NixOS Grafana instances that you also want to + deploy to NixOS. + + __Note:__ secrets from these files will be leaked into the store unless you use a + [**file**-provider or env-var](https://grafana.com/docs/grafana/latest/setup-grafana/configure-grafana/#file-provider) for secrets! + + - [](#opt-services.grafana.provision.notifiers) is not affected by this change because + this feature is deprecated by Grafana and will probably removed in Grafana 10. + It's recommended to use `services.grafana.provision.alerting.contactPoints` instead. + +- The `services.grafana.provision.alerting` option was added. It includes suboptions for every alerting-related objects (with the exception of `notifiers`), which means it's now possible to configure modern Grafana alerting declaratively. + +- Synapse now requires entries in the `state_group_edges` table to be unique, in order to prevent accidentally introducing duplicate information (for example, because a database backup was restored multiple times). If your Synapse database already has duplicate rows in this table, this could fail with an error and require manual remediation. + +- The `diamond` package has been update from 0.8.36 to 2.0.15. See the [upstream release notes](https://github.com/bbuchfink/diamond/releases) for more details. + +- The `guake` package has been updated from 3.6.3 to 3.9.0, see the [changelog](https://github.com/Guake/guake/releases) for more details. + +- The `netlify-cli` package has been updated from 6.13.2 to 12.2.4, see the [changelog](https://github.com/netlify/cli/releases) for more details. + +- `dockerTools.buildImage`'s `contents` parameter has been deprecated in favor of `copyToRoot`. + Use `copyToRoot = buildEnv { ... };` or similar if you intend to add packages to `/bin`. + +- The `proxmox.qemuConf.bios` option was added, it corresponds to `Hardware->BIOS` field in Proxmox web interface. Use `"ovmf"` value to build UEFI image, default value remains `"bios"`. New option `proxmox.partitionTableType` defaults to either `"legacy"` or `"efi"`, depending on the `bios` value. Setting `partitionTableType` to `"hybrid"` results in an image, which supports both methods (`"bios"` and `"ovmf"`), thereby remaining bootable after change to Proxmox `Hardware->BIOS` field. + +- memtest86+ was updated from 5.00-coreboot-002 to 6.00-beta2. It is now the upstream version from https://www.memtest.org/, as coreboot's fork is no longer available. + +- Option descriptions, examples, and defaults writting in DocBook are now deprecated. Using CommonMark is preferred and will become the default in a future release. + +- The `documentation.nixos.options.allowDocBook` option was added to ease the transition to CommonMark option documentation. Setting this option to `false` causes an error for every option included in the manual that uses DocBook documentation; it defaults to `true` to preserve the previous behavior and will be removed once the transition to CommonMark is complete. + +- The Redis module now persists each instance's configuration file in the state directory, in order to support some more advanced use cases like Sentinel. - `protonup` has been aliased to and replaced by `protonup-ng` due to upstream not maintaining it. -- Perl has been updated to 5.36, and its core module `HTTP::Tiny` was patched to verify SSL/TLS certificates by default. +- The udisks2 service, available at `services.udisks2.enable`, is now disabled by default. It will automatically be enabled through services and desktop environments as needed. + This also means that polkit will now actually be disabled by default. The default for `security.polkit.enable` was already flipped in the previous release, but udisks2 being enabled by default re-enabled it. -- Improved performances of `lib.closePropagation` which was previously quadratic. This is used in e.g. `ghcWithPackages`. Please see backward incompatibilities notes below. +- Nextcloud has been updated to version **25**. Additionally the following things have changed + for Nextcloud in NixOS: + - For Nextcloud **>=24**, the default PHP version is 8.1. + - Nextcloud **23** has been removed since it will reach its [end of life in December 2022](https://github.com/nextcloud/server/wiki/Maintenance-and-Release-Schedule/d76576a12a626d53305d480a6065b57cab705d3d). + - If `system.stateVersion` is **>=22.11**, Nextcloud 25 will be installed by default. For older versions, + Nextcloud 24 will be installed. + - Please ensure that you only upgrade one major release at a time! Nextcloud doesn't support + upgrades across multiple versions, i.e. an upgrade from **23** to **25** is only possible + when upgrading to **24** first. -- Cinnamon has been updated to 5.4. While at it, the cinnamon module now defaults to - blueman as bluetooth manager and slick-greeter as lightdm greeter to match upstream. +- systemd-oomd is enabled by default. Depending on which systemd units have + `ManagedOOMSwap=kill` or `ManagedOOMMemoryPressure=kill`, systemd-oomd will + SIGKILL all the processes under the appropriate descendant cgroups when the + configured limits are exceeded. NixOS does currently not configure cgroups + with oomd by default, this can be enabled using + [systemd.oomd.enableRootSlice](options.html#opt-systemd.oomd.enableRootSlice), + [systemd.oomd.enableSystemSlice](options.html#opt-systemd.oomd.enableSystemSlice), + and [systemd.oomd.enableUserServices](options.html#opt-systemd.oomd.enableUserServices). -- OpenSSL now defaults to OpenSSL 3, updated from 1.1.1. +- The `tt-rss` service performs two database migrations when you first use its web UI after upgrade. Consider backing up its database before updating. -- An image configuration and generator has been added for Linode images, largely based on the present GCE configuration and image. +- The `pass-secret-service` package now includes systemd units from upstream, so adding it to the NixOS `services.dbus.packages` option will make it start automatically as a systemd user service when an application tries to talk to the libsecret D-Bus API. -- `hardware.nvidia` has a new option `open` that can be used to opt in the opensource version of NVIDIA kernel driver. Note that the driver's support for GeForce and Workstation GPUs is still alpha quality, see [NVIDIA Releases Open-Source GPU Kernel Modules](https://developer.nvidia.com/blog/nvidia-releases-open-source-gpu-kernel-modules/) for the official announcement. +- The Wordpress module now has support for installing language packs through a new option, `services.wordpress.sites..languages`. + +- The default package for `services.mullvad-vpn.package` was changed to `pkgs.mullvad`, allowing cross-platform usage of Mullvad. `pkgs.mullvad` only contains the Mullvad CLI tool, so users who rely on the Mullvad GUI will want to change it back to `pkgs.mullvad-vpn`, or add `pkgs.mullvad-vpn` to their environment. + +- PowerDNS has been updated from v4.6.2 to v4.7.2. Please be sure to review the [Upgrade Notes](https://doc.powerdns.com/authoritative/upgrading.html#to-4-7-0-or-master) provided by upstream before upgrading. Worth specifically noting is that the new Catalog Zones feature comes with a mandatory schema change for the GSQL database backends, which has to be manually applied. + +- There is a new module for the `thunar` program (the Xfce file manager), which depends on the `xfconf` dbus service, and also has a dbus service and a systemd unit. The option `services.xserver.desktopManager.xfce.thunarPlugins` has been renamed to `programs.thunar.plugins`, and may be removed in a future release. + +- There is a new module for `xfconf` (the Xfce configuration storage system), which has a dbus service. + +- The Mastodon package has been upgraded to v4.0.0. See the [v4.0.0 release notes](https://github.com/mastodon/mastodon/releases/tag/v4.0.0) for a list of changes. On standard setups, no manual migration steps are required. Nevertheless, a database backup is recommended. + +- The `nomad` package now defaults to v1.3, which no longer has a downgrade path to v1.2 or older. + +- The `nodePackages` package set now defaults to the LTS release in the `nodejs` package again, instead of being pinned to `nodejs-14_x`. Several updates to node2nix have been made for compatibility with newer Node.js and npm versions and a new `postRebuild` hook has been added for packages to perform extra build steps before the npm install step prunes dev dependencies. + +- `boot.kernel.sysctl` is defined as a freeformType and adds a custom merge option for `net.core.rmem_max` (taking the highest value defined to avoid conflicts between 2 services trying to set that value). + +- The `mame` package does not ship with its tools anymore in the default output. They were moved to a separate `tools` output instead. For convenience, `mame-tools` package was added for those who want to use it. + +- A NixOS module for Firefox has been added which allows preferences and [policies](https://github.com/mozilla/policy-templates/blob/master/README.md) to be set. This also allows extensions to be installed via the `ExtensionSettings` policy. The new options are under `programs.firefox`. + +- The option `services.picom.experimentalBackends` was removed since it is now the default and the option will cause `picom` to quit instead. + +- `haskellPackage.callHackage` is not always invalidated if `all-cabal-hashes` changes, leading to less rebuilds of haskell dependencies. + +- `haskellPackages.callHackage` and `haskellPackages.callCabal2nix` (and related functions) no longer keep a reference to the `cabal2nix` call used to generate them. As a result, they will be garbage collected more often. @@ -178,377 +537,3 @@ Available as [services.patroni](options.html#opt-services.patroni.enable). - [Mepo](https://mepo.milesalan.com), a fast, simple, hackable OSM map viewer for mobile and desktop Linux. Available as [programs.mepo.enable](#opt-programs.mepo.enable). - -## Backward Incompatibilities {#sec-release-22.11-incompatibilities} - -- Nixpkgs now requires Nix 2.3 or newer. - -- The `isCompatible` predicate checking CPU compatibility is no longer exposed - by the platform sets generated using `lib.systems.elaborate`. In most cases - you will want to use the new `canExecute` predicate instead which also - considers the kernel / syscall interface. It is briefly described in the - release's [highlights section](#sec-release-22.11-highlights). - `lib.systems.parse.isCompatible` still exists, but has changed semantically: - Architectures with differing endianness modes are *no longer considered compatible*. - -- `ngrok` has been upgraded from 2.3.40 to 3.0.4. Please see [the upgrade guide](https://ngrok.com/docs/guides/upgrade-v2-v3) - and [changelog](https://ngrok.com/docs/ngrok-agent/changelog). Notably, breaking changes are that the config file format has - changed and support for single hypen arguments was dropped. - -- `i18n.supportedLocales` is now by default only generated with the locales set in `i18n.defaultLocale` and `i18n.extraLocaleSettings`. - This got partially copied over from the minimal profile and reduces the final system size by up to 200MB. - If you require all locales installed set the option to ``[ "all" ]``. - -- Deprecated settings `logrotate.paths` and `logrotate.extraConfig` have - been removed. Please convert any uses to - [services.logrotate.settings](#opt-services.logrotate.settings) instead. - -- The `isPowerPC` predicate, found on `platform` attrsets (`hostPlatform`, `buildPlatform`, `targetPlatform`, etc) has been removed in order to reduce confusion. The predicate was was defined such that it matches only the 32-bit big-endian members of the POWER/PowerPC family, despite having a name which would imply a broader set of systems. If you were using this predicate, you can replace `foo.isPowerPC` with `(with foo; isPower && is32bit && isBigEndian)`. - -- The `fetchgit` fetcher now uses [cone mode](https://www.git-scm.com/docs/git-sparse-checkout/2.37.0#_internalscone_mode_handling) by default for sparse checkouts. [Non-cone mode](https://www.git-scm.com/docs/git-sparse-checkout/2.37.0#_internalsnon_cone_problems) can be enabled by passing `nonConeMode = true`, but note that non-cone mode is deprecated and this option may be removed alongside a future Git update without notice. - -- The `fetchgit` fetcher supports sparse checkouts via the `sparseCheckout` option. This used to accept a multi-line string with directories/patterns to check out, but now requires a list of strings. - -- `openssh` was updated to version 9.1, disabling the generation of DSA keys when using `ssh-keygen -A` as they are insecure. Also, `SetEnv` directives in `ssh_config` and `sshd_config` are now first-match-wins - -- `bsp-layout` no longer uses the command `cycle` to switch to other window layouts, as it got replaced by the commands `previous` and `next`. - -- The Barco ClickShare driver/client package `pkgs.clickshare-csc1` and the option `programs.clickshare-csc1.enable` have been removed, - as it requires `qt4`, which reached its end-of-life 2015 and will no longer be supported by nixpkgs. - [According to Barco](https://www.barco.com/de/support/knowledge-base/4380-can-i-use-linux-os-with-clickshare-base-units) many of their base unit models can be used with Google Chrome and the Google Cast extension. - -- `services.hbase` has been renamed to `services.hbase-standalone`. - For production HBase clusters, use `services.hadoop.hbase` instead. - -- The `p4` package now only includes the open-source Perforce Helix Core command-line client and APIs. It no longer installs the unfree Helix Core Server binaries `p4d`, `p4broker`, and `p4p`. To install the Helix Core Server binaries, use the `p4d` package instead. - -- The `openssl`-extension for the PHP interpreter used by Nextcloud is built against OpenSSL 1.1 if - [](#opt-system.stateVersion) is below `22.11`. This is to make sure that people using [server-side encryption](https://docs.nextcloud.com/server/latest/admin_manual/configuration_files/encryption_configuration.html) - don't lose access to their files. - - In any other case it's safe to use OpenSSL 3 for PHP's openssl extension. This can be done by setting - [](#opt-services.nextcloud.enableBrokenCiphersForSSE) to `false`. - -- The `coq` package and versioned variants starting at `coq_8_14` no - longer include CoqIDE, which is now available through - `coqPackages.coqide`. It is still possible to get CoqIDE as part of - the `coq` package by overriding the `buildIde` argument of the - derivation. - -- PHP 7.4 is no longer supported due to upstream not supporting this - version for the entire lifecycle of the 22.11 release. - -- The ipfs package and module were renamed to kubo. The kubo module now uses an RFC42-style `settings` option instead of `extraConfig` and the `gatewayAddress`, `apiAddress` and `swarmAddress` options were renamed. Using the old names will print a warning but still work. - -- `pkgs.cosign` does not provide the `cosigned` binary anymore. The `sget` binary has been moved into its own package. - -- Emacs now uses the Lucid toolkit by default instead of GTK because of stability and compatibility issues. - Users who still wish to remain using GTK can do so by using `emacs-gtk`. - -- `kanidm` has been updated to 1.1.0-alpha.10 and now requires a tls certificate and key. It will always start an https and – if enabled – an ldaps server and no http and ldap server anymore. - -- riak package removed along with `services.riak` module, due to lack of maintainer to update the package. - -- ppd files in `pkgs.cups-drv-rastertosag-gdi` are now gzipped. If you refer to such a ppd file with its path (e.g. via [hardware.printers.ensurePrinters](options.html#opt-hardware.printers.ensurePrinters)) you will need to append `.gz` to the path. - -- xow package removed along with the `hardware.xow` module, due to the project being deprecated in favor of `xone`, which is available via the `hardware.xone` module. - -- dd-agent package removed along with the `services.dd-agent` module, due to the project being deprecated in favor of `datadog-agent`, which is available via the `services.datadog-agent` module. - -- `teleport` has been upgraded to major version 10. Please see upstream [upgrade instructions](https://goteleport.com/docs/ver/10.0/management/operations/upgrading/) and [release notes](https://goteleport.com/docs/ver/10.0/changelog/#1000). - -- `lib.closePropagation` now needs that all gathered sets have an `outPath` attribute. - -- lemmy module option `services.lemmy.settings.database.createLocally` - moved to `services.lemmy.database.createLocally`. - -- virtlyst package and `services.virtlyst` module removed, due to lack of maintainers. - -- The `nix.checkConfig` option now fully disables the config check. The new `nix.checkAllErrors` option behaves like `nix.checkConfig` previously did. - -- `nix.buildMachines` got a new submodule option `protocol`. An undocumented hack to set the protocol via `hostName` is no longer working and the `protocol` option should be used instead. - -- `generateOptparseApplicativeCompletions` and `generateOptparseApplicativeCompletion` from `haskell.lib.compose` - (and `haskell.lib`) have been deprecated in favor of `generateOptparseApplicativeCompletions` (plural!) as - provided by the haskell package sets (so `haskellPackages.generateOptparseApplicativeCompletions` etc.). - The latter allows for cross-compilation (by automatically disabling generation of completion in the cross case). - For it to work properly you need to make sure that the function comes from the same context as the package - you are trying to override, i.e. always use the same package set as your package is coming from or – even - better – use `self.generateOptparseApplicativeCompletions` if you are overriding a haskell package set. - The old functions are retained for backwards compatibility, but yield are warning. - -- The `services.graphite.api` and `services.graphite.beacon` NixOS options, and - the `python3.pkgs.graphite_api`, `python3.pkgs.graphite_beacon` and - `python3.pkgs.influxgraph` packages, have been removed due to lack of upstream - maintenance. - -- The `trace` binary from `perf-linux` package has been removed, due to being a duplicate of the `perf` binary. - -- The `aws` package has been removed due to being abandoned by the upstream. It is recommended to use `awscli` or `awscli2` instead. - -- The [CEmu TI-84 Plus CE emulator](https://ce-programming.github.io/CEmu) package has been renamed to `cemu-ti`. The [Cemu Wii U emulator](https://cemu.info) is now packaged as `cemu`. - -- `systemd-networkd` v250 deprecated, renamed, and moved some sections and settings which leads to the following breaking module changes: - - * `systemd.network.networks..dhcpV6PrefixDelegationConfig` is renamed to `systemd.network.networks..dhcpPrefixDelegationConfig`. - * `systemd.network.networks..dhcpV6Config` no longer accepts the `ForceDHCPv6PDOtherInformation=` setting. Please use the `WithoutRA=` and `UseDelegatedPrefix=` settings in your `systemd.network.networks..dhcpV6Config` and the `DHCPv6Client=` setting in your `systemd.network.networks..ipv6AcceptRAConfig` to control when the DHCPv6 client is started and how the delegated prefixes are handled by the DHCPv6 client. - * `systemd.network.networks..networkConfig` no longer accepts the `IPv6Token=` setting. Use the `Token=` setting in your `systemd.network.networks..ipv6AcceptRAConfig` instead. The `systemd.network.networks..ipv6Prefixes.*.ipv6PrefixConfig` now also accepts the `Token=` setting. - -- `arangodb` versions 3.3, 3.4, and 3.5 have been removed because they are at EOL upstream. The default is now 3.10.0. Support for aarch64-linux has been removed since the target cannot be built reproducibly. By default `arangodb` is now built for the `haswell` architecture. If you wish to build for a different architecture, you may override the `targetArchitecture` argument with a value from [this list supported upstream](https://github.com/arangodb/arangodb/blob/207ec6937e41a46e10aea34953879341f0606841/cmake/OptimizeForArchitecture.cmake#L594). Some architecture specific optimizations are also conditionally enabled. You may alter this behavior by overriding the `asmOptimizations` parameter. You may also add additional architecture support by adding more `-DHAS_XYZ` flags to `cmakeFlags` via `overrideAttrs`. - -- The `meta.mainProgram` attribute of packages in `wineWowPackages` now defaults to `"wine64"`. - -- The `paperless` module now defaults `PAPERLESS_TIME_ZONE` to your configured system timezone. - -- The top-level `termonad-with-packages` alias for `termonad` has been removed. - -- Linux 4.9 has been removed because it will reach its end of life within the lifespan of 22.11. - -- (Neo)Vim can not be configured with `configure.pathogen` anymore to reduce maintainance burden. - Use `configure.packages` instead. -- Neovim can not be configured with plug anymore (still works for vim). - -- The `adguardhome` module no longer uses `host` and `port` options, use `settings.bind_host` and `settings.bind_port` instead. - -- The default `kops` version is now 1.25.1 and support for 1.22 and older has been dropped. - -- The `zrepl` package has been updated from 0.5.0 to 0.6.0. See the [changelog](https://zrepl.github.io/changelog.html) for details. - -- `k3s` no longer supports docker as runtime due to upstream dropping support. - -- `cassandra_2_1` and `cassandra_2_2` have been removed. Please update to `cassandra_3_11` or `cassandra_3_0`. See the [changelog](https://github.com/apache/cassandra/blob/cassandra-3.11.14/NEWS.txt) for more information about the upgrade process. - -- `mysql57` has been removed. Please update to `mysql80` or `mariadb`. See the [upgrade guide](https://mariadb.com/kb/en/upgrading-from-mysql-to-mariadb/) for more information. - -- Consequently, `cqrlog` and `amorok` now use `mariadb` instead of `mysql57` for their embedded databases. Running `mysql_upgrade` may be neccesary. -- `k3s` supports `clusterInit` option, and it is enabled by default, for servers. - -- `percona-server56` has been removed. Please migrate to `mysql` or `mariadb` if possible. - -- `obs-studio` hase been updated to version 28. If you have packaged custom plugins, check if they are compatible. `obs-websocket` has been integrated into `obs-studio`. - -- `signald` has been bumped to `0.23.0`. For the upgrade, a migration process is necessary. It can be - done by running a command like this before starting `signald.service`: - - ``` - signald -d /var/lib/signald/db \ - --database sqlite:/var/lib/signald/db \ - --migrate-data - ``` - - For further information, please read the upstream changelogs. - -- `stylua` no longer accepts `lua52Support` and `luauSupport` overrides, use `features` instead, which defaults to `[ "lua54" "luau" ]`. - -- `ocamlPackages.ocaml_extlib` has been renamed to `ocamlPackages.extlib`. - -- `pkgs.fetchNextcloudApp` has been rewritten to circumvent impurities in e.g. tarballs from GitHub and to make it easier to - apply patches. This means that your hashes are out-of-date and the (previously required) attributes `name` and `version` - are no longer accepted. - -- The Syncthing service now only allows absolute paths---starting with `/` or - `~/`---for `services.syncthing.folders..path`. - In a future release other paths will be allowed again and interpreted - relative to `services.syncthing.dataDir`. - -- `services.github-runner` and `services.github-runners.` gained the option `serviceOverrides` which allows overriding the systemd `serviceConfig`. If you have been overriding the systemd service configuration (i.e., by defining `systemd.services.github-runner.serviceConfig`), you have to use the `serviceOverrides` option now. Example: - - ``` - services.github-runner.serviceOverrides.SupplementaryGroups = [ - "docker" - ]; - ``` - - - -## Other Notable Changes {#sec-release-22.11-notable-changes} - -- `firefox`, `thunderbird` and `librewolf` come with enabled Wayland support by default. The `firefox-wayland`, `firefox-esr-wayland`, `thunderbird-wayland` and `librewolf-wayland` attributes are obsolete and have been aliased to their generic attribute. - -- The `xplr` package has been updated from 0.18.0 to 0.19.0, which brings some breaking changes. See the [upstream release notes](https://github.com/sayanarijit/xplr/releases/tag/v0.19.0) for more details. - -- Configuring multiple GitHub runners is now possible through `services.github-runners.`. The option `services.github-runner` remains. - -- `github-runner` gained support for ephemeral runners and registrations using a personal access token (PAT) instead of a registration token. See `services.github-runner.ephemeral` and `services.github-runner.tokenFile` for details. - -- A new module was added for the Saleae Logic device family, providing the options `hardware.saleae-logic.enable` and `hardware.saleae-logic.package`. - -- ZFS module will not allow hibernation by default, this is a safety measure to prevent data loss cases like the ones described at [OpenZFS/260](https://github.com/openzfs/zfs/issues/260) and [OpenZFS/12842](https://github.com/openzfs/zfs/issues/12842). Use the `boot.zfs.allowHibernation` option to configure this behaviour. - -- `mastodon` now automatically removes remote media attachments older than 30 days. This is configurable through `services.mastodon.mediaAutoRemove`. - -- The Redis module now disables RDB persistence when `services.redis.servers..save = []` instead of using the Redis default. - -- Neo4j was updated from version 3 to version 4. See this [migration guide](https://neo4j.com/docs/upgrade-migration-guide/current/) on how to migrate your Neo4j instance. - -- The `networking.wireguard` module now can set the mtu on interfaces and tag its packets with an fwmark. - -- The option `overrideStrategy` was added to the different systemd unit options (`systemd.services.`, `systemd.sockets.`, …) to allow enforcing the creation of a dropin file, rather than the main unit file, by setting it to `asDropin`. - This is useful in cases where the existence of the main unit file is not known to Nix at evaluation time, for example when the main unit file is provided by adding a package to `systemd.packages`. - See the fix proposed in [NixOS's systemd abstraction doesn't work with systemd template units](https://github.com/NixOS/nixpkgs/issues/135557#issuecomment-1295392470) for an example. - -- The `polymc` package has been removed due to a rogue maintainer. It has been - replaced by `prismlauncher`, a fork by the rest of the maintainers. For more - details, see [the pull request that made this - change](https://github.com/NixOS/nixpkgs/pull/196624) and [this issue - detailing the vulnerability](https://github.com/NixOS/nixpkgs/issues/196460). - Users with existing installations should rename `~/.local/share/polymc` to - `~/.local/share/PrismLauncher`. The main config file's path has also moved - from `~/.local/share/polymc/polymc.cfg` to - `~/.local/share/PrismLauncher/prismlauncher.cfg`. - -- The `bloat` package has been updated from unstable-2022-03-31 to unstable-2022-10-25, which brings a breaking change. See [this upstream commit message](https://git.freesoftwareextremist.com/bloat/commit/?id=887ed241d64ba5db3fd3d87194fb5595e5ad7d73) for details. - -- The `services.matrix-synapse` systemd unit has been hardened. - -- The module `services.grafana` was refactored to be compliant with [RFC 0042](https://github.com/NixOS/rfcs/blob/master/rfcs/0042-config-option.md). To be precise, this means that the following things have changed: - - The newly introduced option [](#opt-services.grafana.settings) is an attribute-set that - will be converted into Grafana's INI format. This means that the configuration from - [Grafana's configuration reference](https://grafana.com/docs/grafana/latest/setup-grafana/configure-grafana/) - can be directly written as attribute-set in Nix within this option. - - The option `services.grafana.extraOptions` has been removed. This option was an association - of environment variables for Grafana. If you had an expression like - - ```nix - { - services.grafana.extraOptions.SECURITY_ADMIN_USER = "foobar"; - } - ``` - - your Grafana instance was running with `GF_SECURITY_ADMIN_USER=foobar` in its environment. - - For the migration, it is recommended to turn it into the INI format, i.e. - to declare - - ```nix - { - services.grafana.settings.security.admin_user = "foobar"; - } - ``` - - instead. - - The keys in `services.grafana.extraOptions` have the format `_`. - Further details are outlined in the [configuration reference](https://grafana.com/docs/grafana/latest/setup-grafana/configure-grafana/#override-configuration-with-environment-variables). - - Alternatively you can also set all your values from `extraOptions` to - `systemd.services.grafana.environment`, make sure you don't forget to add - the `GF_` prefix though! - - Previously, the options [](#opt-services.grafana.provision.datasources) and - [](#opt-services.grafana.provision.dashboards) expected lists of datasources - or dashboards for the [declarative provisioning](https://grafana.com/docs/grafana/latest/administration/provisioning/). - - To declare lists of - - **datasources**, please rename your declarations to [](#opt-services.grafana.provision.datasources.settings.datasources). - - **dashboards**, please rename your declarations to [](#opt-services.grafana.provision.dashboards.settings.providers). - - This change was made to support more features for that: - - - It's possible to declare the `apiVersion` of your dashboards and datasources - by [](#opt-services.grafana.provision.datasources.settings.apiVersion) (or - [](#opt-services.grafana.provision.dashboards.settings.apiVersion)). - - - Instead of declaring datasources and dashboards in pure Nix, it's also possible - to specify configuration files (or directories) with YAML instead using - [](#opt-services.grafana.provision.datasources.path) (or - [](#opt-services.grafana.provision.dashboards.path). This is useful when having - provisioning files from non-NixOS Grafana instances that you also want to - deploy to NixOS. - - __Note:__ secrets from these files will be leaked into the store unless you use a - [**file**-provider or env-var](https://grafana.com/docs/grafana/latest/setup-grafana/configure-grafana/#file-provider) for secrets! - - - [](#opt-services.grafana.provision.notifiers) is not affected by this change because - this feature is deprecated by Grafana and will probably removed in Grafana 10. - It's recommended to use `services.grafana.provision.alerting.contactPoints` instead. - -- The `services.grafana.provision.alerting` option was added. It includes suboptions for every alerting-related objects (with the exception of `notifiers`), which means it's now possible to configure modern Grafana alerting declaratively. - -- Matrix Synapse now requires entries in the `state_group_edges` table to be unique, in order to prevent accidentally introducing duplicate information (for example, because a database backup was restored multiple times). If your Synapse database already has duplicate rows in this table, this could fail with an error and require manual remediation. - -- The `diamond` package has been update from 0.8.36 to 2.0.15. See the [upstream release notes](https://github.com/bbuchfink/diamond/releases) for more details. - -- The `guake` package has been updated from 3.6.3 to 3.9.0, see the [changelog](https://github.com/Guake/guake/releases) for more details. - -- The `netlify-cli` package has been updated from 6.13.2 to 12.2.4, see the [changelog](https://github.com/netlify/cli/releases) for more details. - -- `dockerTools.buildImage` deprecates the misunderstood `contents` parameter, in favor of `copyToRoot`. - Use `copyToRoot = buildEnv { ... };` or similar if you intend to add packages to `/bin`. - -- The `proxmox.qemuConf.bios` option was added, it corresponds to `Hardware->BIOS` field in Proxmox web interface. Use `"ovmf"` value to build UEFI image, default value remains `"bios"`. New option `proxmox.partitionTableType` defaults to either `"legacy"` or `"efi"`, depending on the `bios` value. Setting `partitionTableType` to `"hybrid"` results in an image, which supports both methods (`"bios"` and `"ovmf"`), thereby remaining bootable after change to Proxmox `Hardware->BIOS` field. - -- memtest86+ was updated from 5.00-coreboot-002 to 6.00-beta2. It is now the upstream version from https://www.memtest.org/, as coreboot's fork is no longer available. - -- Option descriptions, examples, and defaults writting in DocBook are now deprecated. Using CommonMark is preferred and will become the default in a future release. - -- The `documentation.nixos.options.allowDocBook` option was added to ease the transition to CommonMark option documentation. Setting this option to `false` causes an error for every option included in the manual that uses DocBook documentation; it defaults to `true` to preserve the previous behavior and will be removed once the transition to CommonMark is complete. - -- The redis module now persists each instance's configuration file in the state directory, in order to support some more advanced use cases like sentinel. - -- The udisks2 service, available at `services.udisks2.enable`, is now disabled by default. It will automatically be enabled through services and desktop environments as needed. - This also means that polkit will now actually be disabled by default. The default for `security.polkit.enable` was already flipped in the previous release, but udisks2 being enabled by default re-enabled it. - -- Nextcloud has been updated to version **25**. Additionally the following things have changed - for Nextcloud in NixOS: - - For Nextcloud **>=24**, the default PHP version is 8.1. - - Nextcloud **23** has been removed since it will reach its [end of life in December 2022](https://github.com/nextcloud/server/wiki/Maintenance-and-Release-Schedule/d76576a12a626d53305d480a6065b57cab705d3d). - - For `system.stateVersion` being **>=22.11**, Nextcloud 25 will be installed by default. For older versions, - Nextcloud 24 will be installed. - - Please ensure that you only upgrade on major release at a time! Nextcloud doesn't support - upgrades across multiple versions, i.e. an upgrade from **23** to **25** is only possible - when upgrading to **24** first. - -- Add udev rules for the Teensy family of microcontrollers. - -- The Qt QML disk cache is now disabled by default. This fixes a - long-standing issue where updating Qt/KDE apps would sometimes cause - them to crash or behave strangely without explanation. Those concerned - about the small (~10%) performance hit to application startup can - re-enable the cache (and expose themselves to gremlins) by setting the - envrionment variable `QML_FORCE_DISK_CACHE` to `1` using e.g. the - `environment.sessionVariables` NixOS option. - -- systemd-oomd is enabled by default. Depending on which systemd units have - `ManagedOOMSwap=kill` or `ManagedOOMMemoryPressure=kill`, systemd-oomd will - SIGKILL all the processes under the appropriate descendant cgroups when the - configured limits are exceeded. NixOS does currently not configure cgroups - with oomd by default, this can be enabled using - [systemd.oomd.enableRootSlice](options.html#opt-systemd.oomd.enableRootSlice), - [systemd.oomd.enableSystemSlice](options.html#opt-systemd.oomd.enableSystemSlice), - and [systemd.oomd.enableUserServices](options.html#opt-systemd.oomd.enableUserServices). - -- The `tt-rss` service performs two database migrations when you first use its web UI after upgrade. Consider backing up its database before updating. - -- The `pass-secret-service` package now includes systemd units from upstream, so adding it to the NixOS `services.dbus.packages` option will make it start automatically as a systemd user service when an application tries to talk to the libsecret D-Bus API. - -- There is a new module for AMD SEV CPU functionality, which grants access to the hardware. - -- The Wordpress module got support for installing language packs through `services.wordpress.sites..languages`. - -- The default package for `services.mullvad-vpn.package` was changed to `pkgs.mullvad`, allowing cross-platform usage of Mullvad. `pkgs.mullvad` only contains the Mullvad CLI tool, so users who rely on the Mullvad GUI will want to change it back to `pkgs.mullvad-vpn`, or add `pkgs.mullvad-vpn` to their environment. - -- PowerDNS has been updated from `4.6.x` to `4.7.x`. Please be sure to review the [Upgrade Notes](https://doc.powerdns.com/authoritative/upgrading.html#to-4-7-0-or-master) provided by upstream before upgrading. Worth specifically noting is that the new Catalog Zones feature comes with a mandatory schema change for the gsql database backends, which has to be manually applied. - -- There is a new module for the `thunar` program (the Xfce file manager), which depends on the `xfconf` dbus service, and also has a dbus service and a systemd unit. The option `services.xserver.desktopManager.xfce.thunarPlugins` has been renamed to `programs.thunar.plugins`, and in a future release it may be removed. - -- There is a new module for the `xfconf` program (the Xfce configuration storage system), which has a dbus service. - -- The Mastodon package got upgraded from the major version 3 to 4. See the [v4.0.0 release notes](https://github.com/mastodon/mastodon/releases/tag/v4.0.0) for a list of changes. On standard setups, no manual migration steps are required. Nevertheless, a database backup is recommended. - -- The `nomad` package now defaults to 1.3, which no longer has a downgrade path to releases 1.2 or older. - -- The `nodePackages` package set now defaults to the LTS release in the `nodejs` package again, instead of being pinned to `nodejs-14_x`. Several updates to node2nix have been made for compatibility with newer Node.js and npm versions and a new `postRebuild` hook has been added for packages to perform extra build steps before the npm install step prunes dev dependencies. - -- `boot.kernel.sysctl` is defined as a freeformType and adds a custom merge option for "net.core.rmem_max" (taking the highest value defined to avoid conflicts between 2 services trying to set that value). - -- The `mame` package does not ship with its tools anymore in the default output. They were moved to a separate `tools` output instead. For convenience, `mame-tools` package was added for those who want to use it. - -- A NixOS module for Firefox has been added which allows preferences and [policies](https://github.com/mozilla/policy-templates/blob/master/README.md) to be set. This also allows extensions to be installed via the `ExtensionSettings` policy. The new options are under `programs.firefox`. - -- The option `services.picom.experimentalBackends` was removed since it is now the default and the option will cause `picom` to quit instead. - -- `haskellPackage.callHackage` is not always invalidated if `all-cabal-hashes` changes, leading to less rebuilds of haskell dependencies. - -- `haskellPackages.callHackage` and `haskellPackages.callCabal2nix` (and related functions) no longer keep a reference to the `cabal2nix` call used to generate them. As a result, they will be garbage collected more often. - - From 479a6355447a4bce133fc3060101c11b3dd53f8c Mon Sep 17 00:00:00 2001 From: Winter Date: Tue, 29 Nov 2022 20:22:02 -0500 Subject: [PATCH 26/38] nixos/doc/rl-2211: add entry for libxcrypt migration (cherry picked from commit b937bf637f14efa210afc83f30736cb3487d3ad9) --- .../from_md/release-notes/rl-2211.section.xml | 56 +++++++++++++++++++ .../manual/release-notes/rl-2211.section.md | 7 +++ 2 files changed, 63 insertions(+) diff --git a/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml b/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml index 7a8ab3c00e3c..7e9b19beeb40 100644 --- a/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml +++ b/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml @@ -11,6 +11,62 @@ includes the following highlights:
+ + + Software that uses the crypt password + hashing API is now using the implementation provided by + libxcrypt + instead of glibc’s, which enables support for more secure + algorithms. + + + + + Support for algorithms that libxcrypt + does + not consider strong are + deprecated as of this + release, and will be removed in NixOS 23.05. + + + + + This includes system login passwords. Given this, we + strongly encourage all + users to update their system passwords, as you will be + unable to login if password hashes are not migrated by the + time their support is removed. + + + + + When using + users.users.<name>.hashedPassword + to configure user passwords, run + mkpasswd, and use the yescrypt hash + that is provided as the new value. + + + + + On the other hand, for interactively configured user + passwords, simply re-set the passwords for all users + with passwd. + + + + + This release introduces warnings for the use of + deprecated hash algorithms for both methods of + configuring passwords. To make sure you migrated + correctly, run + nixos-rebuild switch. + + + + + + GNOME has been upgraded to version 43. Please take a look at diff --git a/nixos/doc/manual/release-notes/rl-2211.section.md b/nixos/doc/manual/release-notes/rl-2211.section.md index 7a5e6ead8760..3229485e3282 100644 --- a/nixos/doc/manual/release-notes/rl-2211.section.md +++ b/nixos/doc/manual/release-notes/rl-2211.section.md @@ -6,6 +6,13 @@ This release is supported until the end of June 2023, handing over to NixOS 23.0 In addition to numerous new and upgraded packages, this release includes the following highlights: +- Software that uses the `crypt` password hashing API is now using the implementation provided by [`libxcrypt`](https://github.com/besser82/libxcrypt) instead of glibc's, which enables support for more secure algorithms. + - Support for algorithms that `libxcrypt` [does not consider strong](https://github.com/besser82/libxcrypt/blob/v4.4.28/lib/hashes.conf#L41) are **deprecated** as of this release, and will be removed in NixOS 23.05. + - This includes system login passwords. Given this, we **strongly encourage** all users to update their system passwords, as you will be unable to login if password hashes are not migrated by the time their support is removed. + - When using `users.users..hashedPassword` to configure user passwords, run `mkpasswd`, and use the yescrypt hash that is provided as the new value. + - On the other hand, for interactively configured user passwords, simply re-set the passwords for all users with `passwd`. + - This release introduces warnings for the use of deprecated hash algorithms for both methods of configuring passwords. To make sure you migrated correctly, run `nixos-rebuild switch`. + - GNOME has been upgraded to version 43. Please take a look at their [Release Notes](https://release.gnome.org/43/) for details. - KDE Plasma has been upgraded from v5.24 to v5.26. Please see the release notes for [v5.25](https://kde.org/announcements/plasma/5/5.25.0/) and [v5.26](https://kde.org/announcements/plasma/5/5.26.0/) for more details on the included changes. From e1b7ac3028ca77595d9fc564723d8fb1ca2927b0 Mon Sep 17 00:00:00 2001 From: Winter Date: Tue, 29 Nov 2022 20:51:29 -0500 Subject: [PATCH 27/38] nixos/doc/rl-2211: add entry for aarch64-linux jobset inclusion/images on homepage (cherry picked from commit 881f22670ee42c5e22135f21822447d8d8b486b1) --- .../from_md/release-notes/rl-2211.section.xml | 17 +++++++++++++++++ .../doc/manual/release-notes/rl-2211.section.md | 4 ++++ 2 files changed, 21 insertions(+) diff --git a/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml b/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml index 7e9b19beeb40..54e40a8fba78 100644 --- a/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml +++ b/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml @@ -216,6 +216,23 @@ release announcement for more information. + + + aarch64-linux is now included in the + nixos-22.11 and + nixos-22.11-small channels. This means that + x86_64-linux and + aarch64-linux will recieve updates at the + same time. + + + + + aarch64-linux ISOs are now available on the + downloads + page. + +
diff --git a/nixos/doc/manual/release-notes/rl-2211.section.md b/nixos/doc/manual/release-notes/rl-2211.section.md index 3229485e3282..941bd0521eaf 100644 --- a/nixos/doc/manual/release-notes/rl-2211.section.md +++ b/nixos/doc/manual/release-notes/rl-2211.section.md @@ -61,6 +61,10 @@ In addition to numerous new and upgraded packages, this release includes the fol - `hardware.nvidia` has a new option, `hardware.nvidia.open`, that can be used to enable the usage of NVIDIA's open-source kernel driver. Note that the driver's support for GeForce and Workstation GPUs is still alpha quality, see [the release announcement](https://developer.nvidia.com/blog/nvidia-releases-open-source-gpu-kernel-modules/) for more information. +- `aarch64-linux` is now included in the `nixos-22.11` and `nixos-22.11-small` channels. This means that `x86_64-linux` and `aarch64-linux` will recieve updates at the same time. + +- `aarch64-linux` ISOs are now available on the [downloads page](https://nixos.org/download.html). + ## Internal changes {#sec-release-22.11-internal} - Improved performances of `lib.closePropagation` which was previously quadratic. This is used in e.g. `ghcWithPackages`. Please see backward incompatibilities notes below. From 100793ae97f8e90796ce506b44b3d5cbe6c612c5 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?J=C3=B6rg=20Thalheim?= Date: Wed, 30 Nov 2022 17:34:42 +0100 Subject: [PATCH 28/38] nixos/doc/rl-2211: cleanup (cherry picked from commit 07fe1b987bb6c47dd43fb03c61cc0dea648145b7) --- .../from_md/release-notes/rl-2211.section.xml | 271 +++++++++--------- .../manual/release-notes/rl-2211.section.md | 96 +++---- 2 files changed, 180 insertions(+), 187 deletions(-) diff --git a/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml b/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml index 54e40a8fba78..6689d2389eb2 100644 --- a/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml +++ b/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml @@ -1,9 +1,18 @@
Release 22.11 (“Raccoon”, 2022.11/??) + + The NixOS release team is happy to announce a new version of NixOS + 22.11. NixOS is both a linux distribution, and a set of packages + usable on other Linux systems and macOS. + This release is supported until the end of June 2023, handing over to NixOS 23.05. + + To upgrade to the latest release follow the + upgrade chapter. +
Highlights @@ -69,87 +78,72 @@ - GNOME has been upgraded to version 43. Please take a look at - their Release - Notes for details. + The NixOS documentation is now generated from markdown. While + docbook is still part of the documentation build process, it’s + a big step towards the full migration. - KDE Plasma has been upgraded from v5.24 to v5.26. Please see - the release notes for - v5.25 - and - v5.26 - for more details on the included changes. + aarch64-linux is now included in the + nixos-22.11 and + nixos-22.11-small channels. This means that + when those channel update, both + x86_64-linux and + aarch64-linux will be available in the + binary cache. - Cinnamon has been updated to 5.4, and the Cinnamon module now - defaults to Blueman as the Bluetooth manager and slick-greeter - as the LightDM greeter, to match upstream. + aarch64-linux ISOs are now available on the + downloads + page. - OpenSSL now defaults to OpenSSL 3, updated from 1.1.1. + nsncd is now available as a replacement of + nscd. - - - PHP now defaults to PHP 8.1, updated from 8.0. + nscd is responsible for resolving + hostnames, users and more in NixOS and has been a long + standing source of bugs, such as sporadic network freezes. - - - PHP is now built in NTS (Non-Thread Safe) - mode by default. + More context in this + issue. - - - - For Apache and mod_php usage, we enable - ZTS (Zend Thread Safe) mode. This has - been a common practice for a long time in other - distributions. - - - - - - Perl has been updated to 5.36, and its core module - HTTP::Tiny was patched to verify SSL/TLS - certificates by default. - - - - - nscd functionality, necessary to provide - non-glibc-builtin NSS modules (such as - nss_systemd or nss_ldap) - can now be provided by nsncd, by setting + Help us test the new implementation by setting services.nscd.enableNsncd to true. - - The nscd daemon provided by glibc, which is - currently used by NixOS isn’t very reliable. For example, it’s - not - fully possible to disable caching functionality, - causing various issues and failed lookups. - - - In contrast to nscd’s behavior of caching module responses on - its own, nsncd merely forwards requests to NSS modules, which - might cache or not. - We plan to use nsncd by default in NixOS 23.05. + + + Linode cloud images are now supported by importing + ${modulesPath}/virtualisation/linode-image.nix + and accessing system.build.linodeImage on + the output. + + + + + hardware.nvidia has a new option, + hardware.nvidia.open, that can be used to + enable the usage of NVIDIA’s open-source kernel driver. Note + that the driver’s support for GeForce and Workstation GPUs is + still alpha quality, see + the + release announcement for more information. + + The emacs package now makes use of native @@ -178,61 +172,6 @@ - - - nixos-generate-config now generates - configurations that can be built in pure mode. This is - achieved by setting the new - nixpkgs.hostPlatform option. - - - You may have to unset the system parameter - in lib.nixosSystem, or similarly remove - definitions of the - nixpkgs.{system,localSystem,crossSystem} - options. - - - Alternatively, you can remove the - hostPlatform line and use NixOS like you - would in NixOS 22.05 and earlier. - - - - - It is now possible to generate NixOS images for the Linode - cloud provider, via - system.build.linodeImage. - - - - - hardware.nvidia has a new option, - hardware.nvidia.open, that can be used to - enable the usage of NVIDIA’s open-source kernel driver. Note - that the driver’s support for GeForce and Workstation GPUs is - still alpha quality, see - the - release announcement for more information. - - - - - aarch64-linux is now included in the - nixos-22.11 and - nixos-22.11-small channels. This means that - x86_64-linux and - aarch64-linux will recieve updates at the - same time. - - - - - aarch64-linux ISOs are now available on the - downloads - page. - -
@@ -240,38 +179,28 @@ - Improved performances of - lib.closePropagation which was previously - quadratic. This is used in e.g. - ghcWithPackages. Please see backward - incompatibilities notes below. + Haskell ghcWithPackages is now up to 15 + times faster to evaluate, thanks to changing + lib.closePropagation from a quadratic to + linear complexity. Please see backward incompatibilities notes + below. + https://github.com/NixOS/nixpkgs/pull/194391 - During cross-compilation, tests are now executed if the test - suite can be executed by the build platform. This is the case - when doing “native” cross-compilation where the build and host - platforms are largely the same, but the nixpkgs’ cross - compilation infrastructure is used, e.g. - pkgsStatic and pkgsLLVM. - Another possibility is that the build platform is a superset - of the host platform, e.g. when cross-compiling from - x86_64-unknown-linux to - i686-unknown-linux. The predicate gating - test suite execution is the newly added - canExecute predicate: You can e.g. check if - stdenv.buildPlatform can execute binaries - built for stdenv.hostPlatform (i.e. - produced by stdenv.cc) by evaluating - stdenv.buildPlatform.canExecute stdenv.hostPlatform. + For cross-compilation targets that can also run on the + building machine, we also enabled running tests now. This is + for example the case for the pkgsStatic and pkgsLLVm package + sets or i686 packages on x86_64 machine. - The nixpkgs.hostPlatform and - nixpkgs.buildPlatform options have been - added. These cover and override the + To simplify cross-compilation in NixOS, this release + introduces the nixpkgs.hostPlatform and + nixpkgs.buildPlatform options. These cover + and override the nixpkgs.{system,localSystem,crossSystem} options. @@ -308,6 +237,64 @@
+
+ Notable version updates + + + + Nix has been upgraded from + v2.8.1 + to v2.11.0 + + + + + OpenSSL now defaults to OpenSSL 3, updated from 1.1.1. + + + + + GNOME has been upgraded to version 43. Please take a look at + their Release + Notes for details. + + + + + KDE Plasma has been upgraded from v5.24 to v5.26. Please see + the release notes for + v5.25 + and + v5.26 + for more details on the included changes. + + + + + Cinnamon has been updated to 5.4, and the Cinnamon module now + defaults to Blueman as the Bluetooth manager and slick-greeter + as the LightDM greeter, to match upstream. + + + + + PHP now defaults to PHP 8.1, updated from 8.0. + + + + + Perl has been updated to 5.36, and its core module + HTTP::Tiny was patched to verify SSL/TLS + certificates by default. + + + + + Python now defalts to 3.10, updated from 3.9. + + + +
Backward Incompatibilities @@ -908,6 +895,22 @@ services.github-runner.serviceOverrides.SupplementaryGroups = [
Other Notable Changes + + + PHP is now built in NTS (Non-Thread Safe) + mode by default. + + + + + For Apache and mod_php usage, we enable + ZTS (Zend Thread Safe) mode. This has + been a common practice for a long time in other + distributions. + + + + firefox, thunderbird and diff --git a/nixos/doc/manual/release-notes/rl-2211.section.md b/nixos/doc/manual/release-notes/rl-2211.section.md index 941bd0521eaf..00e815fa66ac 100644 --- a/nixos/doc/manual/release-notes/rl-2211.section.md +++ b/nixos/doc/manual/release-notes/rl-2211.section.md @@ -1,7 +1,11 @@ # Release 22.11 (“Raccoon”, 2022.11/??) {#sec-release-22.11} +The NixOS release team is happy to announce a new version of NixOS 22.11. NixOS is both a linux distribution, and a set of packages usable on other Linux systems and macOS. + This release is supported until the end of June 2023, handing over to NixOS 23.05. +To upgrade to the latest release follow the [upgrade chapter](#sec-upgrading). + ## Highlights {#sec-release-22.11-highlights} In addition to numerous new and upgraded packages, this release includes the following highlights: @@ -13,74 +17,37 @@ In addition to numerous new and upgraded packages, this release includes the fol - On the other hand, for interactively configured user passwords, simply re-set the passwords for all users with `passwd`. - This release introduces warnings for the use of deprecated hash algorithms for both methods of configuring passwords. To make sure you migrated correctly, run `nixos-rebuild switch`. -- GNOME has been upgraded to version 43. Please take a look at their [Release Notes](https://release.gnome.org/43/) for details. +- The NixOS documentation is now generated from markdown. While docbook is still part of the documentation build process, it's a big step towards the full migration. -- KDE Plasma has been upgraded from v5.24 to v5.26. Please see the release notes for [v5.25](https://kde.org/announcements/plasma/5/5.25.0/) and [v5.26](https://kde.org/announcements/plasma/5/5.26.0/) for more details on the included changes. +- `aarch64-linux` is now included in the `nixos-22.11` and `nixos-22.11-small` channels. This means that when those channel update, both `x86_64-linux` and `aarch64-linux` will be available in the binary cache. -- Cinnamon has been updated to 5.4, and the Cinnamon module now defaults to - Blueman as the Bluetooth manager and slick-greeter as the LightDM greeter, to match upstream. +- `aarch64-linux` ISOs are now available on the [downloads page](https://nixos.org/download.html). -- OpenSSL now defaults to OpenSSL 3, updated from 1.1.1. +- `nsncd` is now available as a replacement of `nscd`. -- PHP now defaults to PHP 8.1, updated from 8.0. + `nscd` is responsible for resolving hostnames, users and more in NixOS and has been a long standing source of bugs, such as sporadic network freezes. + + More context in this [issue](https://github.com/NixOS/nixpkgs/issues/135888). + + Help us test the new implementation by setting `services.nscd.enableNsncd` to `true`. -- PHP is now built in `NTS` (Non-Thread Safe) mode by default. - - For Apache and `mod_php` usage, we enable `ZTS` (Zend Thread Safe) mode. This has been a - common practice for a long time in other distributions. + We plan to use `nsncd` by default in NixOS 23.05. -- Perl has been updated to 5.36, and its core module `HTTP::Tiny` was patched to verify SSL/TLS certificates by default. +- Linode cloud images are now supported by importing `${modulesPath}/virtualisation/linode-image.nix` and accessing `system.build.linodeImage` on the output. -- `nscd` functionality, necessary to provide non-glibc-builtin NSS - modules (such as `nss_systemd` or `nss_ldap`) can now be provided by - `nsncd`, by setting `services.nscd.enableNsncd` to `true`. - - The `nscd` daemon provided by glibc, which is currently used by NixOS isn't - very reliable. For example, it's [not fully possible to disable caching - functionality](https://github.com/NixOS/nixpkgs/issues/135888), causing - various issues and failed lookups. - - In contrast to nscd's behavior of caching module responses on its own, - nsncd merely forwards requests to NSS modules, which might cache or not. - - We plan to use `nsncd` by default in NixOS 23.05. +- `hardware.nvidia` has a new option, `hardware.nvidia.open`, that can be used to enable the usage of NVIDIA's open-source kernel driver. Note that the driver's support for GeForce and Workstation GPUs is still alpha quality, see [the release announcement](https://developer.nvidia.com/blog/nvidia-releases-open-source-gpu-kernel-modules/) for more information. - The `emacs` package now makes use of native compilation which means: - Emacs packages from Nixpkgs, builtin or not, will do native compilation ahead of time so you can enjoy the benefit of native compilation without compiling them on you machine; - Emacs packages from somewhere else, e.g. `package-install`, will perform asynchronously deferred native compilation. If you do not want this, maybe to avoid CPU consumption for compilation, you can use `(setq native-comp-deferred-compilation nil)` to disable it while still benefiting from native compilation for packages from Nixpkgs. -- `nixos-generate-config` now generates configurations that can be built in pure - mode. This is achieved by setting the new `nixpkgs.hostPlatform` option. - - You may have to unset the `system` parameter in `lib.nixosSystem`, or similarly - remove definitions of the `nixpkgs.{system,localSystem,crossSystem}` options. - - Alternatively, you can remove the `hostPlatform` line and use NixOS like you - would in NixOS 22.05 and earlier. - -- It is now possible to generate NixOS images for the Linode cloud provider, via `system.build.linodeImage`. - -- `hardware.nvidia` has a new option, `hardware.nvidia.open`, that can be used to enable the usage of NVIDIA's open-source kernel driver. Note that the driver's support for GeForce and Workstation GPUs is still alpha quality, see [the release announcement](https://developer.nvidia.com/blog/nvidia-releases-open-source-gpu-kernel-modules/) for more information. - -- `aarch64-linux` is now included in the `nixos-22.11` and `nixos-22.11-small` channels. This means that `x86_64-linux` and `aarch64-linux` will recieve updates at the same time. - -- `aarch64-linux` ISOs are now available on the [downloads page](https://nixos.org/download.html). - ## Internal changes {#sec-release-22.11-internal} -- Improved performances of `lib.closePropagation` which was previously quadratic. This is used in e.g. `ghcWithPackages`. Please see backward incompatibilities notes below. -- During cross-compilation, tests are now executed if the test suite can be executed - by the build platform. This is the case when doing “native” cross-compilation - where the build and host platforms are largely the same, but the nixpkgs' cross - compilation infrastructure is used, e.g. `pkgsStatic` and `pkgsLLVM`. Another - possibility is that the build platform is a superset of the host platform, e.g. when - cross-compiling from `x86_64-unknown-linux` to `i686-unknown-linux`. - The predicate gating test suite execution is the newly added `canExecute` - predicate: You can e.g. check if `stdenv.buildPlatform` can execute binaries - built for `stdenv.hostPlatform` (i.e. produced by `stdenv.cc`) by evaluating - `stdenv.buildPlatform.canExecute stdenv.hostPlatform`. +- Haskell `ghcWithPackages` is now up to 15 times faster to evaluate, thanks to changing `lib.closePropagation` from a quadratic to linear complexity. Please see backward incompatibilities notes below. -- The `nixpkgs.hostPlatform` and `nixpkgs.buildPlatform` options have been added. - These cover and override the `nixpkgs.{system,localSystem,crossSystem}` options. +- For cross-compilation targets that can also run on the building machine, we also enabled running tests now. This is for example the case for the pkgsStatic and pkgsLLVm package sets or i686 packages on `x86_64` machine. + +- To simplify cross-compilation in NixOS, this release introduces the `nixpkgs.hostPlatform` and `nixpkgs.buildPlatform` options. These cover and override the `nixpkgs.{system,localSystem,crossSystem}` options. - `hostPlatform` is the platform or "`system`" string of the NixOS system described by the configuration. @@ -97,6 +64,25 @@ In addition to numerous new and upgraded packages, this release includes the fol for a transition period so that in time the ecosystem can switch without breaking compatibility with any supported NixOS release. +## Notable version updates {#sec-release-22.11-version-updates} + +- Nix has been upgraded from [v2.8.1 to v2.11.0](https://github.com/NixOS/nix/compare/2.8.1...2.11.0) + +- OpenSSL now defaults to OpenSSL 3, updated from 1.1.1. + +- GNOME has been upgraded to version 43. Please take a look at their [Release Notes](https://release.gnome.org/43/) for details. + +- KDE Plasma has been upgraded from v5.24 to v5.26. Please see the release notes for [v5.25](https://kde.org/announcements/plasma/5/5.25.0/) and [v5.26](https://kde.org/announcements/plasma/5/5.26.0/) for more details on the included changes. + +- Cinnamon has been updated to 5.4, and the Cinnamon module now defaults to + Blueman as the Bluetooth manager and slick-greeter as the LightDM greeter, to match upstream. + +- PHP now defaults to PHP 8.1, updated from 8.0. + +- Perl has been updated to 5.36, and its core module `HTTP::Tiny` was patched to verify SSL/TLS certificates by default. + +- Python now defalts to 3.10, updated from 3.9. + ## Backward Incompatibilities {#sec-release-22.11-incompatibilities} - Nixpkgs now requires Nix 2.3 or newer. @@ -279,6 +265,10 @@ In addition to numerous new and upgraded packages, this release includes the fol ## Other Notable Changes {#sec-release-22.11-notable-changes} +- PHP is now built in `NTS` (Non-Thread Safe) mode by default. + - For Apache and `mod_php` usage, we enable `ZTS` (Zend Thread Safe) mode. This has been a + common practice for a long time in other distributions. + - `firefox`, `thunderbird` and `librewolf` now come with Wayland support by default. The `firefox-wayland`, `firefox-esr-wayland`, `thunderbird-wayland` and `librewolf-wayland` attributes are obsolete and have been aliased to their generic attribute. - The `xplr` package has been updated from 0.18.0 to 0.19.0, which brings some breaking changes. See the [upstream release notes](https://github.com/sayanarijit/xplr/releases/tag/v0.19.0) for more details. From 6bdce4215ebc79a4079e9807a4b629fb9c581788 Mon Sep 17 00:00:00 2001 From: maralorn Date: Wed, 30 Nov 2022 19:03:28 +0100 Subject: [PATCH 29/38] nixos/doc: Fix typo in 22.11 release manual (cherry picked from commit 6184f635b3c3d2794821bb31c04a4e7a99ee0fdb) --- nixos/doc/manual/release-notes/rl-2211.section.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/nixos/doc/manual/release-notes/rl-2211.section.md b/nixos/doc/manual/release-notes/rl-2211.section.md index fccb00ff0156..9473f2ba37f0 100644 --- a/nixos/doc/manual/release-notes/rl-2211.section.md +++ b/nixos/doc/manual/release-notes/rl-2211.section.md @@ -545,7 +545,7 @@ Available as [services.patroni](options.html#opt-services.patroni.enable). - The option `services.picom.experimentalBackends` was removed since it is now the default and the option will cause `picom` to quit instead. -- `haskellPackage.callHackage` is not always invalidated if `all-cabal-hashes` changes, leading to less rebuilds of haskell dependencies. +- `haskellPackages.callHackage` is not always invalidated if `all-cabal-hashes` changes, leading to less rebuilds of haskell dependencies. - `haskellPackages.callHackage` and `haskellPackages.callCabal2nix` (and related functions) no longer keep a reference to the `cabal2nix` call used to generate them. As a result, they will be garbage collected more often. From 32b91e1ed1b3f41389c27932d74c20e4834e74e8 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Wed, 30 Nov 2022 18:34:29 +0100 Subject: [PATCH 30/38] nixos/doc/rl-2211: more cleanup (cherry picked from commit 068f7348db86a08b108bcce5cb8320685534de17) --- .../from_md/release-notes/rl-2211.section.xml | 352 +++++++++--------- .../manual/release-notes/rl-2211.section.md | 121 +++--- 2 files changed, 236 insertions(+), 237 deletions(-) diff --git a/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml b/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml index 6689d2389eb2..2c64ea535c7e 100644 --- a/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml +++ b/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml @@ -2,7 +2,7 @@ Release 22.11 (“Raccoon”, 2022.11/??) The NixOS release team is happy to announce a new version of NixOS - 22.11. NixOS is both a linux distribution, and a set of packages + 22.11. NixOS is both a Linux distribution, and a set of packages usable on other Linux systems and macOS. @@ -190,9 +190,10 @@ For cross-compilation targets that can also run on the - building machine, we also enabled running tests now. This is - for example the case for the pkgsStatic and pkgsLLVm package - sets or i686 packages on x86_64 machine. + building machine, we now run tests. This, for example, is the + case for the pkgsStatic and + pkgsLLVM package sets or i686 packages on + x86_64 machines. @@ -242,9 +243,12 @@ - Nix has been upgraded from - v2.8.1 - to v2.11.0 + Nix has been upgraded from v2.8.1 to v2.11.0. For more + information, please see the release notes for + 2.9, + 2.10 + and + 2.11. @@ -254,9 +258,9 @@ - GNOME has been upgraded to version 43. Please take a look at - their Release - Notes for details. + GNOME has been upgraded to version 43. Please see the + release + notes for details. @@ -290,7 +294,7 @@ - Python now defalts to 3.10, updated from 3.9. + Python now defaults to 3.10, updated from 3.9. @@ -393,7 +397,7 @@ checkouts via the sparseCheckout option. This used to accept a multi-line string with directories/patterns to check out, but now requires a list of - strings + strings. @@ -403,7 +407,7 @@ ssh-keygen -A as they are insecure. Also, SetEnv directives in ssh_config and - sshd_config are now first-match-wins + sshd_config are now first-match-wins. @@ -511,7 +515,7 @@ kanidm has been updated to 1.1.0-alpha.10 and now requires a TLS certificate and key. It will always start https and-–-if enabled-–-an LDAPS - server and no HTTP and LDAP server anymore + server and no HTTP and LDAP server anymore. @@ -1527,6 +1531,13 @@ services.github-runner.serviceOverrides.SupplementaryGroups = [
New Services + + + alps, + a simple and extensible webmail. Available as + services.alps. + + appvm, @@ -1534,6 +1545,14 @@ services.github-runner.serviceOverrides.SupplementaryGroups = [ virtualisation.appvm. + + + AusweisApp2, + the authentication software for the German ID card. Available + as + programs.ausweisapp. + + automatic-timezoned. @@ -1544,18 +1563,10 @@ services.github-runner.serviceOverrides.SupplementaryGroups = [ - [xray] (https://github.com/XTLS/Xray-core), a fully compatible - v2ray-core replacement. Features XTLS, which when enabled on - server and client, brings UDP FullCone NAT to proxy setups. - Available as - services.xray. - - - - - syncstorage-rs, - a self-hostable sync server for Firefox. Available as - services.firefox-syncserver. + Dolibarr, + an enterprise resource planning and customer relationship + manager. Enable using + services.dolibarr. @@ -1567,39 +1578,16 @@ services.github-runner.serviceOverrides.SupplementaryGroups = [ - Komga, a free and - open source comics/mangas media server. Available as - services.komga. + endlessh-go, + an SSH tarpit that exposes Prometheus metrics. Available as + services.endlessh-go. - Tandoor Recipes, - a self-hosted multi-tenant recipe collection. Available as - services.tandoor-recipes. - - - - - HBase - cluster, a distributed, scalable, big data store. - Available as - services.hadoop.hbase. - - - - - Please, - a Sudo clone written in Rust. Available as - security.please - - - - - Sachet, - an SMS alerting tool for the Prometheus Alertmanager. - Available as - services.prometheus.sachet. + endlessh, + an SSH tarpit. Available as + services.endlessh. @@ -1614,17 +1602,53 @@ services.github-runner.serviceOverrides.SupplementaryGroups = [ - infnoise, - a hardware True Random Number Generator dongle. Available as - services.infnoise. + expressvpn, + the CLI client for ExpressVPN. Available as + services.expressvpn. - kthxbye, - an alert acknowledgement management daemon for Prometheus - Alertmanager. Available as - services.kthxbye + FreshRSS, a + free, self-hostable RSS feed aggregator. Available as + services.freshrss. + + + + + Garage, + a simple object storage server for geodistributed deployments, + alternative to MinIO. Available as + services.garage. + + + + + go-autoconfig, + IMAP/SMTP autodiscover server. Available as + services.go-autoconfig. + + + + + Grafana + Tempo, a distributed tracing store. Available as + services.tempo. + + + + + HBase + cluster, a distributed, scalable, big data store. + Available as + services.hadoop.hbase. + + + + + infnoise, + a hardware True Random Number Generator dongle. Available as + services.infnoise. @@ -1642,6 +1666,21 @@ services.github-runner.serviceOverrides.SupplementaryGroups = [ services.karma + + + Komga, a free and + open source comics/mangas media server. Available as + services.komga. + + + + + kthxbye, + an alert acknowledgement management daemon for Prometheus + Alertmanager. Available as + services.kthxbye + + languagetool, @@ -1649,6 +1688,42 @@ services.github-runner.serviceOverrides.SupplementaryGroups = [ services.languagetool. + + + Listmonk, a + self-hosted newsletter manager. Enable using + services.listmonk. + + + + + Mepo, a + fast, simple, hackable OSM map viewer for mobile and desktop + Linux. Available as + programs.mepo.enable. + + + + + merecat, + a small and easy HTTP server based on thttpd. Available as + services.merecat + + + + + netbird, a zero + configuration VPN. Available as + services.netbird. + + + + + ntfy.sh, a push + notification service. Available as + services.ntfy-sh + + OpenRGB, @@ -1665,45 +1740,10 @@ services.github-runner.serviceOverrides.SupplementaryGroups = [ - ntfy.sh, a push - notification service. Available as - services.ntfy-sh - - - - - alps, - a simple and extensible webmail. Available as - services.alps. - - - - - endlessh, - an SSH tarpit. Available as - services.endlessh. - - - - - endlessh-go, - an SSH tarpit that exposes Prometheus metrics. Available as - services.endlessh-go. - - - - - Garage, - a simple object storage server for geodistributed deployments, - alternative to MinIO. Available as - services.garage. - - - - - netbird, a zero - configuration VPN. Available as - services.netbird. + Patroni, + a template for PostgreSQL HA with ZooKeeper, etcd or Consul. + Available as + services.patroni. @@ -1715,6 +1755,29 @@ services.github-runner.serviceOverrides.SupplementaryGroups = [ services.persistent-evdev. + + + Please, + a Sudo clone written in Rust. Available as + security.please. + + + + + Prometheus + IPMI exporter, an IPMI exporter for Prometheus. + Available as + services.prometheus.exporters.ipmi. + + + + + Sachet, + an SMS alerting tool for the Prometheus Alertmanager. + Available as + services.prometheus.sachet. + + schleuder, a @@ -1724,38 +1787,16 @@ services.github-runner.serviceOverrides.SupplementaryGroups = [ - Dolibarr, - an enterprise resource planning and customer relationship - manager. Enable using - services.dolibarr. + syncstorage-rs, + a self-hostable sync server for Firefox. Available as + services.firefox-syncserver. - FreshRSS, a - free, self-hostable RSS feed aggregator. Available as - services.freshrss. - - - - - expressvpn, - the CLI client for ExpressVPN. Available as - services.expressvpn. - - - - - merecat, - a small and easy HTTP server based on thttpd. Available as - services.merecat - - - - - go-autoconfig, - IMAP/SMTP autodiscover server. Available as - services.go-autoconfig. + Tandoor Recipes, + a self-hosted multi-tenant recipe collection. Available as + services.tandoor-recipes. @@ -1769,33 +1810,9 @@ services.github-runner.serviceOverrides.SupplementaryGroups = [ - Grafana - Tempo, a distributed tracing store. Available as - services.tempo. - - - - - AusweisApp2, - the authentication software for the German ID card. Available - as - programs.ausweisapp. - - - - - Patroni, - a template for PostgreSQL HA with ZooKeeper, etcd or Consul. - Available as - services.patroni. - - - - - Prometheus - IPMI exporter, an IPMI exporter for Prometheus. - Available as - services.prometheus.exporters.ipmi. + Uptime + Kuma, a fancy self-hosted monitoring tool. Available as + services.uptime-kuma. @@ -1808,24 +1825,11 @@ services.github-runner.serviceOverrides.SupplementaryGroups = [ - Listmonk, a - self-hosted newsletter manager. Enable using - services.listmonk. - - - - - Uptime - Kuma, a fancy self-hosted monitoring tool. Available as - services.uptime-kuma. - - - - - Mepo, a - fast, simple, hackable OSM map viewer for mobile and desktop - Linux. Available as - programs.mepo.enable. + [xray] (https://github.com/XTLS/Xray-core), a fully compatible + v2ray-core replacement. Features XTLS, which when enabled on + server and client, brings UDP FullCone NAT to proxy setups. + Available as + services.xray. diff --git a/nixos/doc/manual/release-notes/rl-2211.section.md b/nixos/doc/manual/release-notes/rl-2211.section.md index 00e815fa66ac..b93235dd4dec 100644 --- a/nixos/doc/manual/release-notes/rl-2211.section.md +++ b/nixos/doc/manual/release-notes/rl-2211.section.md @@ -1,6 +1,6 @@ # Release 22.11 (“Raccoon”, 2022.11/??) {#sec-release-22.11} -The NixOS release team is happy to announce a new version of NixOS 22.11. NixOS is both a linux distribution, and a set of packages usable on other Linux systems and macOS. +The NixOS release team is happy to announce a new version of NixOS 22.11. NixOS is both a Linux distribution, and a set of packages usable on other Linux systems and macOS. This release is supported until the end of June 2023, handing over to NixOS 23.05. @@ -26,9 +26,9 @@ In addition to numerous new and upgraded packages, this release includes the fol - `nsncd` is now available as a replacement of `nscd`. `nscd` is responsible for resolving hostnames, users and more in NixOS and has been a long standing source of bugs, such as sporadic network freezes. - + More context in this [issue](https://github.com/NixOS/nixpkgs/issues/135888). - + Help us test the new implementation by setting `services.nscd.enableNsncd` to `true`. We plan to use `nsncd` by default in NixOS 23.05. @@ -45,7 +45,7 @@ In addition to numerous new and upgraded packages, this release includes the fol - Haskell `ghcWithPackages` is now up to 15 times faster to evaluate, thanks to changing `lib.closePropagation` from a quadratic to linear complexity. Please see backward incompatibilities notes below. -- For cross-compilation targets that can also run on the building machine, we also enabled running tests now. This is for example the case for the pkgsStatic and pkgsLLVm package sets or i686 packages on `x86_64` machine. +- For cross-compilation targets that can also run on the building machine, we now run tests. This, for example, is the case for the `pkgsStatic` and `pkgsLLVM` package sets or i686 packages on `x86_64` machines. - To simplify cross-compilation in NixOS, this release introduces the `nixpkgs.hostPlatform` and `nixpkgs.buildPlatform` options. These cover and override the `nixpkgs.{system,localSystem,crossSystem}` options. @@ -66,11 +66,11 @@ In addition to numerous new and upgraded packages, this release includes the fol ## Notable version updates {#sec-release-22.11-version-updates} -- Nix has been upgraded from [v2.8.1 to v2.11.0](https://github.com/NixOS/nix/compare/2.8.1...2.11.0) +- Nix has been upgraded from v2.8.1 to v2.11.0. For more information, please see the release notes for [2.9](https://nixos.org/manual/nix/stable/release-notes/rl-2.9.html), [2.10](https://nixos.org/manual/nix/stable/release-notes/rl-2.10.html) and [2.11](https://nixos.org/manual/nix/stable/release-notes/rl-2.11.html). - OpenSSL now defaults to OpenSSL 3, updated from 1.1.1. -- GNOME has been upgraded to version 43. Please take a look at their [Release Notes](https://release.gnome.org/43/) for details. +- GNOME has been upgraded to version 43. Please see the [release notes](https://release.gnome.org/43/) for details. - KDE Plasma has been upgraded from v5.24 to v5.26. Please see the release notes for [v5.25](https://kde.org/announcements/plasma/5/5.25.0/) and [v5.26](https://kde.org/announcements/plasma/5/5.26.0/) for more details on the included changes. @@ -81,7 +81,7 @@ In addition to numerous new and upgraded packages, this release includes the fol - Perl has been updated to 5.36, and its core module `HTTP::Tiny` was patched to verify SSL/TLS certificates by default. -- Python now defalts to 3.10, updated from 3.9. +- Python now defaults to 3.10, updated from 3.9. ## Backward Incompatibilities {#sec-release-22.11-incompatibilities} @@ -111,9 +111,9 @@ In addition to numerous new and upgraded packages, this release includes the fol - The `fetchgit` fetcher now uses [cone mode](https://www.git-scm.com/docs/git-sparse-checkout/2.37.0#_internalscone_mode_handling) by default for sparse checkouts. [Non-cone mode](https://www.git-scm.com/docs/git-sparse-checkout/2.37.0#_internalsnon_cone_problems) can be enabled by passing `nonConeMode = true`, but note that non-cone mode is deprecated and this option may be removed alongside a future Git update without notice. -- The `fetchgit` fetcher supports sparse checkouts via the `sparseCheckout` option. This used to accept a multi-line string with directories/patterns to check out, but now requires a list of strings +- The `fetchgit` fetcher supports sparse checkouts via the `sparseCheckout` option. This used to accept a multi-line string with directories/patterns to check out, but now requires a list of strings. -- `openssh` was updated to version 9.1, disabling the generation of DSA keys when using `ssh-keygen -A` as they are insecure. Also, `SetEnv` directives in `ssh_config` and `sshd_config` are now first-match-wins +- `openssh` was updated to version 9.1, disabling the generation of DSA keys when using `ssh-keygen -A` as they are insecure. Also, `SetEnv` directives in `ssh_config` and `sshd_config` are now first-match-wins. - `bsp-layout` no longer uses the command `cycle` to switch to other window layouts, as it got replaced by the commands `previous` and `next`. @@ -149,7 +149,7 @@ In addition to numerous new and upgraded packages, this release includes the fol - Emacs now uses the Lucid toolkit by default instead of GTK because of stability and compatibility issues. Users who still wish to remain using GTK can do so by using `emacs-gtk`. -- `kanidm` has been updated to 1.1.0-alpha.10 and now requires a TLS certificate and key. It will always start `https` and-–-if enabled-–-an LDAPS server and no HTTP and LDAP server anymore +- `kanidm` has been updated to 1.1.0-alpha.10 and now requires a TLS certificate and key. It will always start `https` and-–-if enabled-–-an LDAPS server and no HTTP and LDAP server anymore. - riak package removed along with `services.riak` module, due to lack of maintainer to update the package. @@ -452,89 +452,84 @@ In addition to numerous new and upgraded packages, this release includes the fol ## New Services {#sec-release-22.11-new-services} +- [alps](https://git.sr.ht/~migadu/alps), a simple and extensible webmail. Available as [services.alps](#opt-services.alps.enable). + - [appvm](https://github.com/jollheef/appvm), Nix based app VMs. Available as [virtualisation.appvm](options.html#opt-virtualisation.appvm.enable). +- [AusweisApp2](https://www.ausweisapp.bund.de/), the authentication software for the German ID card. Available as [programs.ausweisapp](#opt-programs.ausweisapp.enable). + - [automatic-timezoned](https://github.com/maxbrunet/automatic-timezoned). a Linux daemon to automatically update the system timezone based on location. Available as [services.automatic-timezoned](#opt-services.automatic-timezoned.enable). -- [xray] (https://github.com/XTLS/Xray-core), a fully compatible v2ray-core replacement. Features XTLS, which when enabled on server and client, brings UDP FullCone NAT to proxy setups. Available as [services.xray](options.html#opt-services.xray.enable). - -- [syncstorage-rs](https://github.com/mozilla-services/syncstorage-rs), a self-hostable sync server for Firefox. Available as [services.firefox-syncserver](options.html#opt-services.firefox-syncserver.enable). +- [Dolibarr](https://www.dolibarr.org/), an enterprise resource planning and customer relationship manager. Enable using [services.dolibarr](#opt-services.dolibarr.enable). - [dragonflydb](https://dragonflydb.io/), a modern replacement for Redis and Memcached. Available as [services.dragonflydb](#opt-services.dragonflydb.enable). -- [Komga](https://komga.org/), a free and open source comics/mangas media server. Available as [services.komga](#opt-services.komga.enable). +- [endlessh-go](https://github.com/shizunge/endlessh-go), an SSH tarpit that exposes Prometheus metrics. Available as [services.endlessh-go](#opt-services.endlessh-go.enable). -- [Tandoor Recipes](https://tandoor.dev), a self-hosted multi-tenant recipe collection. Available as [services.tandoor-recipes](options.html#opt-services.tandoor-recipes.enable). - -- [HBase cluster](https://hbase.apache.org/), a distributed, scalable, big data store. Available as [services.hadoop.hbase](options.html#opt-services.hadoop.hbase.enable). - -- [Please](https://github.com/edneville/please), a Sudo clone written in Rust. Available as [security.please](#opt-security.please.enable) - -- [Sachet](https://github.com/messagebird/sachet/), an SMS alerting tool for the Prometheus Alertmanager. Available as [services.prometheus.sachet](#opt-services.prometheus.sachet.enable). +- [endlessh](https://github.com/skeeto/endlessh), an SSH tarpit. Available as [services.endlessh](#opt-services.endlessh.enable). - [EVCC](https://evcc.io) is an EV charge controller with PV integration. It supports a multitude of chargers, meters, vehicle APIs and more and ties that together with a well-tested backend and a lightweight web frontend. Available as [services.evcc](#opt-services.evcc.enable). -- [infnoise](https://github.com/leetronics/infnoise), a hardware True Random Number Generator dongle. - Available as [services.infnoise](options.html#opt-services.infnoise.enable). +- [expressvpn](https://www.expressvpn.com), the CLI client for ExpressVPN. Available as [services.expressvpn](#opt-services.expressvpn.enable). -- [kthxbye](https://github.com/prymitive/kthxbye), an alert acknowledgement management daemon for Prometheus Alertmanager. Available as [services.kthxbye](options.html#opt-services.kthxbye.enable) +- [FreshRSS](https://freshrss.org/), a free, self-hostable RSS feed aggregator. Available as [services.freshrss](#opt-services.freshrss.enable). -- [kanata](https://github.com/jtroo/kanata), a tool to improve keyboard comfort and usability with advanced customization. - Available as [services.kanata](options.html#opt-services.kanata.enable). +- [Garage](https://garagehq.deuxfleurs.fr/), a simple object storage server for geodistributed deployments, alternative to MinIO. Available as [services.garage](#opt-services.garage.enable). + +- [go-autoconfig](https://github.com/L11R/go-autoconfig), IMAP/SMTP autodiscover server. Available as [services.go-autoconfig](#opt-services.go-autoconfig.enable). + +- [Grafana Tempo](https://www.grafana.com/oss/tempo/), a distributed tracing store. Available as [services.tempo](#opt-services.tempo.enable). + +- [HBase cluster](https://hbase.apache.org/), a distributed, scalable, big data store. Available as [services.hadoop.hbase](options.html#opt-services.hadoop.hbase.enable). + +- [infnoise](https://github.com/leetronics/infnoise), a hardware True Random Number Generator dongle. Available as [services.infnoise](options.html#opt-services.infnoise.enable). + +- [kanata](https://github.com/jtroo/kanata), a tool to improve keyboard comfort and usability with advanced customization. Available as [services.kanata](options.html#opt-services.kanata.enable). - [karma](https://github.com/prymitive/karma), an alert dashboard for Prometheus Alertmanager. Available as [services.karma](options.html#opt-services.karma.enable) -- [languagetool](https://languagetool.org/), a multilingual grammar, style, and spell checker. - Available as [services.languagetool](options.html#opt-services.languagetool.enable). +- [Komga](https://komga.org/), a free and open source comics/mangas media server. Available as [services.komga](#opt-services.komga.enable). + +- [kthxbye](https://github.com/prymitive/kthxbye), an alert acknowledgement management daemon for Prometheus Alertmanager. Available as [services.kthxbye](options.html#opt-services.kthxbye.enable) + +- [languagetool](https://languagetool.org/), a multilingual grammar, style, and spell checker. Available as [services.languagetool](options.html#opt-services.languagetool.enable). + +- [Listmonk](https://listmonk.app), a self-hosted newsletter manager. Enable using [services.listmonk](options.html#opt-services.listmonk.enable). + +- [Mepo](https://mepo.milesalan.com), a fast, simple, hackable OSM map viewer for mobile and desktop Linux. Available as [programs.mepo.enable](#opt-programs.mepo.enable). + +- [merecat](https://troglobit.com/projects/merecat/), a small and easy HTTP server based on thttpd. Available as [services.merecat](#opt-services.merecat.enable) + +- [netbird](https://netbird.io), a zero configuration VPN. Available as [services.netbird](options.html#opt-services.netbird.enable). + +- [ntfy.sh](https://ntfy.sh), a push notification service. Available as [services.ntfy-sh](#opt-services.ntfy-sh.enable) - [OpenRGB](https://gitlab.com/CalcProgrammer1/OpenRGB/-/tree/master), a FOSS tool for controlling RGB lighting. Available as [services.hardware.openrgb.enable](options.html#opt-services.hardware.openrgb.enable). - [Outline](https://www.getoutline.com/), a wiki and knowledge base similar to Notion. Available as [services.outline](#opt-services.outline.enable). -- [ntfy.sh](https://ntfy.sh), a push notification service. Available as [services.ntfy-sh](#opt-services.ntfy-sh.enable) - -- [alps](https://git.sr.ht/~migadu/alps), a simple and extensible webmail. Available as [services.alps](#opt-services.alps.enable). - -- [endlessh](https://github.com/skeeto/endlessh), an SSH tarpit. Available as [services.endlessh](#opt-services.endlessh.enable). - -- [endlessh-go](https://github.com/shizunge/endlessh-go), an SSH tarpit that exposes Prometheus metrics. Available as [services.endlessh-go](#opt-services.endlessh-go.enable). - -- [Garage](https://garagehq.deuxfleurs.fr/), a simple object storage server for geodistributed deployments, alternative to MinIO. Available as [services.garage](#opt-services.garage.enable). - -- [netbird](https://netbird.io), a zero configuration VPN. - Available as [services.netbird](options.html#opt-services.netbird.enable). +- [Patroni](https://github.com/zalando/patroni), a template for PostgreSQL HA with ZooKeeper, etcd or Consul. Available as [services.patroni](options.html#opt-services.patroni.enable). - [persistent-evdev](https://github.com/aiberia/persistent-evdev), a daemon to add virtual proxy devices that mirror a physical input device but persist even if the underlying hardware is hot-plugged. Available as [services.persistent-evdev](#opt-services.persistent-evdev.enable). -- [schleuder](https://schleuder.org/), a mailing list manager with PGP support. Enable using [services.schleuder](#opt-services.schleuder.enable). - -- [Dolibarr](https://www.dolibarr.org/), an enterprise resource planning and customer relationship manager. Enable using [services.dolibarr](#opt-services.dolibarr.enable). - -- [FreshRSS](https://freshrss.org/), a free, self-hostable RSS feed aggregator. Available as [services.freshrss](#opt-services.freshrss.enable). - -- [expressvpn](https://www.expressvpn.com), the CLI client for ExpressVPN. Available as [services.expressvpn](#opt-services.expressvpn.enable). - -- [merecat](https://troglobit.com/projects/merecat/), a small and easy HTTP server based on thttpd. Available as [services.merecat](#opt-services.merecat.enable) - -- [go-autoconfig](https://github.com/L11R/go-autoconfig), IMAP/SMTP autodiscover server. Available as [services.go-autoconfig](#opt-services.go-autoconfig.enable). - -- [tmate-ssh-server](https://github.com/tmate-io/tmate-ssh-server), server side part of [tmate](https://tmate.io/). Available as [services.tmate-ssh-server](#opt-services.tmate-ssh-server.enable). - -- [Grafana Tempo](https://www.grafana.com/oss/tempo/), a distributed tracing store. Available as [services.tempo](#opt-services.tempo.enable). - -- [AusweisApp2](https://www.ausweisapp.bund.de/), the authentication software for the German ID card. Available as [programs.ausweisapp](#opt-programs.ausweisapp.enable). - -- [Patroni](https://github.com/zalando/patroni), a template for PostgreSQL HA with ZooKeeper, etcd or Consul. -Available as [services.patroni](options.html#opt-services.patroni.enable). +- [Please](https://github.com/edneville/please), a Sudo clone written in Rust. Available as [security.please](#opt-security.please.enable). - [Prometheus IPMI exporter](https://github.com/prometheus-community/ipmi_exporter), an IPMI exporter for Prometheus. Available as [services.prometheus.exporters.ipmi](#opt-services.prometheus.exporters.ipmi.enable). -- [WriteFreely](https://writefreely.org), a simple blogging platform with ActivityPub support. Available as [services.writefreely](options.html#opt-services.writefreely.enable). +- [Sachet](https://github.com/messagebird/sachet/), an SMS alerting tool for the Prometheus Alertmanager. Available as [services.prometheus.sachet](#opt-services.prometheus.sachet.enable). -- [Listmonk](https://listmonk.app), a self-hosted newsletter manager. Enable using [services.listmonk](options.html#opt-services.listmonk.enable). +- [schleuder](https://schleuder.org/), a mailing list manager with PGP support. Enable using [services.schleuder](#opt-services.schleuder.enable). + +- [syncstorage-rs](https://github.com/mozilla-services/syncstorage-rs), a self-hostable sync server for Firefox. Available as [services.firefox-syncserver](options.html#opt-services.firefox-syncserver.enable). + +- [Tandoor Recipes](https://tandoor.dev), a self-hosted multi-tenant recipe collection. Available as [services.tandoor-recipes](options.html#opt-services.tandoor-recipes.enable). + +- [tmate-ssh-server](https://github.com/tmate-io/tmate-ssh-server), server side part of [tmate](https://tmate.io/). Available as [services.tmate-ssh-server](#opt-services.tmate-ssh-server.enable). - [Uptime Kuma](https://uptime.kuma.pet/), a fancy self-hosted monitoring tool. Available as [services.uptime-kuma](#opt-services.uptime-kuma.enable). -- [Mepo](https://mepo.milesalan.com), a fast, simple, hackable OSM map viewer for mobile and desktop Linux. Available as [programs.mepo.enable](#opt-programs.mepo.enable). +- [WriteFreely](https://writefreely.org), a simple blogging platform with ActivityPub support. Available as [services.writefreely](options.html#opt-services.writefreely.enable). + +- [xray] (https://github.com/XTLS/Xray-core), a fully compatible v2ray-core replacement. Features XTLS, which when enabled on server and client, brings UDP FullCone NAT to proxy setups. Available as [services.xray](options.html#opt-services.xray.enable). From 3c89502dccf2f6f21c30ed4ca81719c73842b18e Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sandro=20J=C3=A4ckel?= Date: Wed, 30 Nov 2022 19:19:22 +0100 Subject: [PATCH 31/38] nixos/release-notes: fix link formatting (cherry picked from commit 29450f5d80c775d7f8b7a41b8f3e5edda5c97c18) --- .../manual/from_md/release-notes/rl-2211.section.xml | 10 +++++----- nixos/doc/manual/release-notes/rl-2211.section.md | 2 +- 2 files changed, 6 insertions(+), 6 deletions(-) diff --git a/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml b/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml index 2c64ea535c7e..3345ac134427 100644 --- a/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml +++ b/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml @@ -1512,7 +1512,7 @@ services.github-runner.serviceOverrides.SupplementaryGroups = [ - haskellPackage.callHackage is not always + haskellPackages.callHackage is not always invalidated if all-cabal-hashes changes, leading to less rebuilds of haskell dependencies. @@ -1825,10 +1825,10 @@ services.github-runner.serviceOverrides.SupplementaryGroups = [ - [xray] (https://github.com/XTLS/Xray-core), a fully compatible - v2ray-core replacement. Features XTLS, which when enabled on - server and client, brings UDP FullCone NAT to proxy setups. - Available as + xray, + a fully compatible v2ray-core replacement. Features XTLS, + which when enabled on server and client, brings UDP FullCone + NAT to proxy setups. Available as services.xray. diff --git a/nixos/doc/manual/release-notes/rl-2211.section.md b/nixos/doc/manual/release-notes/rl-2211.section.md index d52b27c1a840..6675d9c0c68c 100644 --- a/nixos/doc/manual/release-notes/rl-2211.section.md +++ b/nixos/doc/manual/release-notes/rl-2211.section.md @@ -530,6 +530,6 @@ In addition to numerous new and upgraded packages, this release includes the fol - [WriteFreely](https://writefreely.org), a simple blogging platform with ActivityPub support. Available as [services.writefreely](options.html#opt-services.writefreely.enable). -- [xray] (https://github.com/XTLS/Xray-core), a fully compatible v2ray-core replacement. Features XTLS, which when enabled on server and client, brings UDP FullCone NAT to proxy setups. Available as [services.xray](options.html#opt-services.xray.enable). +- [xray](https://github.com/XTLS/Xray-core), a fully compatible v2ray-core replacement. Features XTLS, which when enabled on server and client, brings UDP FullCone NAT to proxy setups. Available as [services.xray](options.html#opt-services.xray.enable). From 65aedb1b28d6040ba6ec35a0cc8fc2f2b79f1d50 Mon Sep 17 00:00:00 2001 From: David Morgan Date: Wed, 30 Nov 2022 16:09:35 +0000 Subject: [PATCH 32/38] vimpc: Support more platforms (cherry picked from commit b0f767da93e4f813fe25c4b876d013a3decda744) --- pkgs/applications/audio/vimpc/default.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/applications/audio/vimpc/default.nix b/pkgs/applications/audio/vimpc/default.nix index 5cc3c1099995..7e834efb9524 100644 --- a/pkgs/applications/audio/vimpc/default.nix +++ b/pkgs/applications/audio/vimpc/default.nix @@ -44,7 +44,7 @@ stdenv.mkDerivation rec { description = "A vi/vim inspired client for the Music Player Daemon (mpd)"; homepage = "https://github.com/boysetsfrog/vimpc"; license = licenses.gpl3; - platforms = platforms.linux; + platforms = platforms.unix; maintainers = with maintainers; [ pSub ]; }; } From 4d2b37a84fad1091b9de401eb450aae66f1a741e Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Wed, 30 Nov 2022 02:57:32 +0100 Subject: [PATCH 33/38] Release NixOS 22.11 (cherry picked from commit f1b9cc23aa8b1549dd7cb53dbe9fc950efc97646) --- .github/PULL_REQUEST_TEMPLATE.md | 2 +- CONTRIBUTING.md | 16 ++++++++-------- README.md | 4 ++-- .../from_md/installation/upgrading.chapter.xml | 16 ++++++++-------- .../from_md/release-notes/rl-2211.section.xml | 2 +- .../doc/manual/installation/upgrading.chapter.md | 16 ++++++++-------- .../doc/manual/release-notes/rl-2211.section.md | 2 +- 7 files changed, 29 insertions(+), 29 deletions(-) diff --git a/.github/PULL_REQUEST_TEMPLATE.md b/.github/PULL_REQUEST_TEMPLATE.md index 47857a8ca4c3..3d4bb049991f 100644 --- a/.github/PULL_REQUEST_TEMPLATE.md +++ b/.github/PULL_REQUEST_TEMPLATE.md @@ -22,7 +22,7 @@ For new packages please briefly describe the package or provide a link to its ho - made sure NixOS tests are [linked](https://nixos.org/manual/nixpkgs/unstable/#ssec-nixos-tests-linking) to the relevant packages - [ ] Tested compilation of all packages that depend on this change using `nix-shell -p nixpkgs-review --run "nixpkgs-review rev HEAD"`. Note: all changes have to be committed, also see [nixpkgs-review usage](https://github.com/Mic92/nixpkgs-review#usage) - [ ] Tested basic functionality of all binary files (usually in `./result/bin/`) -- [22.11 Release Notes (or backporting 22.05 Release notes)](https://github.com/NixOS/nixpkgs/blob/master/CONTRIBUTING.md#generating-2211-release-notes) +- [23.05 Release Notes (or backporting 22.11 Release notes)](https://github.com/NixOS/nixpkgs/blob/master/CONTRIBUTING.md#generating-2305-release-notes) - [ ] (Package updates) Added a release notes entry if the change is major or breaking - [ ] (Module updates) Added a release notes entry if the change is significant - [ ] (Module addition) Added a release notes entry if adding a new NixOS module diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index d8540782b91b..2d83222ee3a8 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -98,17 +98,17 @@ git push origin feature --force-with-lease Follow these steps to backport a change into a release branch in compliance with the [commit policy](https://nixos.org/nixpkgs/manual/#submitting-changes-stable-release-branches). -You can add a label such as `backport release-22.05` to a PR, so that merging it will +You can add a label such as `backport release-22.11` to a PR, so that merging it will automatically create a backport (via [a GitHub Action](.github/workflows/backport.yml)). This also works for PR's that have already been merged, and might take a couple of minutes to trigger. You can also create the backport manually: 1. Take note of the commits in which the change was introduced into `master` branch. -2. Check out the target _release branch_, e.g. `release-22.05`. Do not use a _channel branch_ like `nixos-22.05` or `nixpkgs-22.05-darwin`. +2. Check out the target _release branch_, e.g. `release-22.11`. Do not use a _channel branch_ like `nixos-22.11` or `nixpkgs-22.11-darwin`. 3. Create a branch for your change, e.g. `git checkout -b backport`. 4. When the reason to backport is not obvious from the original commit message, use `git cherry-pick -xe ` and add a reason. Otherwise use `git cherry-pick -x `. That's fine for minor version updates that only include security and bug fixes, commits that fixes an otherwise broken package or similar. Please also ensure the commits exists on the master branch; in the case of squashed or rebased merges, the commit hash will change and the new commits can be found in the merge message at the bottom of the master pull request. -5. Push to GitHub and open a backport pull request. Make sure to select the release branch (e.g. `release-22.05`) as the target branch of the pull request, and link to the pull request in which the original change was comitted to `master`. The pull request title should be the commit title with the release version as prefix, e.g. `[22.05]`. +5. Push to GitHub and open a backport pull request. Make sure to select the release branch (e.g. `release-22.11`) as the target branch of the pull request, and link to the pull request in which the original change was comitted to `master`. The pull request title should be the commit title with the release version as prefix, e.g. `[22.11]`. 6. When the backport pull request is merged and you have the necessary privileges you can also replace the label `9.needs: port to stable` with `8.has: port to stable` on the original pull request. This way maintainers can keep track of missing backports easier. ## Criteria for Backporting changes @@ -120,15 +120,15 @@ Anything that does not cause user or downstream dependency regressions can be ba - Services which require a client to be up-to-date regardless. (E.g. `spotify`, `steam`, or `discord`) - Security critical applications (E.g. `firefox`) -## Generating 22.11 Release Notes +## Generating 23.05 Release Notes Documentation in nixpkgs is transitioning to a markdown-centric workflow. Release notes now require a translation step to convert from markdown to a compatible docbook document. -Steps for updating 22.11 Release notes: +Steps for updating 23.05 Release notes: -1. Edit `nixos/doc/manual/release-notes/rl-2211.section.md` with the desired changes -2. Run `./nixos/doc/manual/md-to-db.sh` to render `nixos/doc/manual/from_md/release-notes/rl-2211.section.xml` -3. Include changes to `rl-2211.section.md` and `rl-2211.section.xml` in the same commit. +1. Edit `nixos/doc/manual/release-notes/rl-2305.section.md` with the desired changes +2. Run `./nixos/doc/manual/md-to-db.sh` to render `nixos/doc/manual/from_md/release-notes/rl-2305.section.xml` +3. Include changes to `rl-2305.section.md` and `rl-2305.section.xml` in the same commit. ## Reviewing contributions diff --git a/README.md b/README.md index c7e14f693495..4c6ad635164b 100644 --- a/README.md +++ b/README.md @@ -51,9 +51,9 @@ Nixpkgs and NixOS are built and tested by our continuous integration system, [Hydra](https://hydra.nixos.org/). * [Continuous package builds for unstable/master](https://hydra.nixos.org/jobset/nixos/trunk-combined) -* [Continuous package builds for the NixOS 22.05 release](https://hydra.nixos.org/jobset/nixos/release-22.05) +* [Continuous package builds for the NixOS 22.11 release](https://hydra.nixos.org/jobset/nixos/release-22.11) * [Tests for unstable/master](https://hydra.nixos.org/job/nixos/trunk-combined/tested#tabs-constituents) -* [Tests for the NixOS 22.05 release](https://hydra.nixos.org/job/nixos/release-22.05/tested#tabs-constituents) +* [Tests for the NixOS 22.11 release](https://hydra.nixos.org/job/nixos/release-22.11/tested#tabs-constituents) Artifacts successfully built with Hydra are published to cache at https://cache.nixos.org/. When successful build and test criteria are diff --git a/nixos/doc/manual/from_md/installation/upgrading.chapter.xml b/nixos/doc/manual/from_md/installation/upgrading.chapter.xml index 11fe1d317ccd..f6aedc800aca 100644 --- a/nixos/doc/manual/from_md/installation/upgrading.chapter.xml +++ b/nixos/doc/manual/from_md/installation/upgrading.chapter.xml @@ -12,7 +12,7 @@ Stable channels, such as - nixos-22.05. + nixos-22.11. These only get conservative bug fixes and package upgrades. For instance, a channel update may cause the Linux kernel on your system to be upgraded from 4.19.34 to 4.19.38 (a minor bug fix), @@ -33,7 +33,7 @@ Small channels, such as - nixos-22.05-small + nixos-22.11-small or nixos-unstable-small. These are identical to the stable and unstable channels @@ -60,8 +60,8 @@ When you first install NixOS, you’re automatically subscribed to the NixOS channel that corresponds to your installation source. For - instance, if you installed from a 22.05 ISO, you will be subscribed - to the nixos-22.05 channel. To see which NixOS + instance, if you installed from a 22.11 ISO, you will be subscribed + to the nixos-22.11 channel. To see which NixOS channel you’re subscribed to, run the following as root: @@ -76,17 +76,17 @@ nixos https://nixos.org/channels/nixos-unstable (Be sure to include the nixos parameter at the - end.) For instance, to use the NixOS 22.05 stable channel: + end.) For instance, to use the NixOS 22.11 stable channel: -# nix-channel --add https://nixos.org/channels/nixos-22.05 nixos +# nix-channel --add https://nixos.org/channels/nixos-22.11 nixos If you have a server, you may want to use the small channel instead: -# nix-channel --add https://nixos.org/channels/nixos-22.05-small nixos +# nix-channel --add https://nixos.org/channels/nixos-22.11-small nixos And if you want to live on the bleeding edge: @@ -146,7 +146,7 @@ system.autoUpgrade.allowReboot = true; also specify a channel explicitly, e.g. -system.autoUpgrade.channel = https://nixos.org/channels/nixos-22.05; +system.autoUpgrade.channel = https://nixos.org/channels/nixos-22.11;
diff --git a/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml b/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml index 3345ac134427..b72c4326004c 100644 --- a/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml +++ b/nixos/doc/manual/from_md/release-notes/rl-2211.section.xml @@ -1,5 +1,5 @@
- Release 22.11 (“Raccoon”, 2022.11/??) + Release 22.11 (“Raccoon”, 2022.11/30) The NixOS release team is happy to announce a new version of NixOS 22.11. NixOS is both a Linux distribution, and a set of packages diff --git a/nixos/doc/manual/installation/upgrading.chapter.md b/nixos/doc/manual/installation/upgrading.chapter.md index 2644979bc9db..249bcd97cec8 100644 --- a/nixos/doc/manual/installation/upgrading.chapter.md +++ b/nixos/doc/manual/installation/upgrading.chapter.md @@ -6,7 +6,7 @@ expressions and associated binaries. The NixOS channels are updated automatically from NixOS's Git repository after certain tests have passed and all packages have been built. These channels are: -- *Stable channels*, such as [`nixos-22.05`](https://nixos.org/channels/nixos-22.05). +- *Stable channels*, such as [`nixos-22.11`](https://nixos.org/channels/nixos-22.05). These only get conservative bug fixes and package upgrades. For instance, a channel update may cause the Linux kernel on your system to be upgraded from 4.19.34 to 4.19.38 (a minor bug fix), but not @@ -19,7 +19,7 @@ passed and all packages have been built. These channels are: radical changes between channel updates. It's not recommended for production systems. -- *Small channels*, such as [`nixos-22.05-small`](https://nixos.org/channels/nixos-22.05-small) +- *Small channels*, such as [`nixos-22.11-small`](https://nixos.org/channels/nixos-22.05-small) or [`nixos-unstable-small`](https://nixos.org/channels/nixos-unstable-small). These are identical to the stable and unstable channels described above, except that they contain fewer binary packages. This means they get updated @@ -38,8 +38,8 @@ newest supported stable release. When you first install NixOS, you're automatically subscribed to the NixOS channel that corresponds to your installation source. For -instance, if you installed from a 22.05 ISO, you will be subscribed to -the `nixos-22.05` channel. To see which NixOS channel you're subscribed +instance, if you installed from a 22.11 ISO, you will be subscribed to +the `nixos-22.11` channel. To see which NixOS channel you're subscribed to, run the following as root: ```ShellSession @@ -54,16 +54,16 @@ To switch to a different NixOS channel, do ``` (Be sure to include the `nixos` parameter at the end.) For instance, to -use the NixOS 22.05 stable channel: +use the NixOS 22.11 stable channel: ```ShellSession -# nix-channel --add https://nixos.org/channels/nixos-22.05 nixos +# nix-channel --add https://nixos.org/channels/nixos-22.11 nixos ``` If you have a server, you may want to use the "small" channel instead: ```ShellSession -# nix-channel --add https://nixos.org/channels/nixos-22.05-small nixos +# nix-channel --add https://nixos.org/channels/nixos-22.11-small nixos ``` And if you want to live on the bleeding edge: @@ -114,5 +114,5 @@ the new generation contains a different kernel, initrd or kernel modules. You can also specify a channel explicitly, e.g. ```nix -system.autoUpgrade.channel = https://nixos.org/channels/nixos-22.05; +system.autoUpgrade.channel = https://nixos.org/channels/nixos-22.11; ``` diff --git a/nixos/doc/manual/release-notes/rl-2211.section.md b/nixos/doc/manual/release-notes/rl-2211.section.md index 6675d9c0c68c..e0aef342c1ac 100644 --- a/nixos/doc/manual/release-notes/rl-2211.section.md +++ b/nixos/doc/manual/release-notes/rl-2211.section.md @@ -1,4 +1,4 @@ -# Release 22.11 (“Raccoon”, 2022.11/??) {#sec-release-22.11} +# Release 22.11 (“Raccoon”, 2022.11/30) {#sec-release-22.11} The NixOS release team is happy to announce a new version of NixOS 22.11. NixOS is both a Linux distribution, and a set of packages usable on other Linux systems and macOS. From 5b59a8b874d6805b810dc2d20cb810c20115c5b5 Mon Sep 17 00:00:00 2001 From: Michael Weiss Date: Sun, 20 Nov 2022 21:23:29 +0100 Subject: [PATCH 34/38] chromiumDev: 109.0.5410.0 -> 109.0.5414.10 (cherry picked from commit 6492d64628390ea421829b15e6f19626657df01d) --- .../networking/browsers/chromium/upstream-info.json | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/pkgs/applications/networking/browsers/chromium/upstream-info.json b/pkgs/applications/networking/browsers/chromium/upstream-info.json index c6ee9a3df01c..c7ee4b263dfb 100644 --- a/pkgs/applications/networking/browsers/chromium/upstream-info.json +++ b/pkgs/applications/networking/browsers/chromium/upstream-info.json @@ -32,15 +32,15 @@ } }, "dev": { - "version": "109.0.5410.0", - "sha256": "00g8q0qzl8kyc9j60nsvvjkr2x9js2xvbkmwp77p8b6gg0pyymjn", - "sha256bin64": "0ljhc5lqdy01apzyj96xzl931d904i37x62257s1h35w0j78mps0", + "version": "109.0.5414.10", + "sha256": "05yhfb5gznllh9rm6jhzaakj5kvdlxa8c4zqml10h297dbyr44bf", + "sha256bin64": "01fzjxrgzhccj75gvqj5w2xhqrphwzycdfqbsd6nc5p08jizpvy0", "deps": { "gn": { - "version": "2022-10-28", + "version": "2022-11-10", "url": "https://gn.googlesource.com/gn", - "rev": "a4d67be044b42963de801001e7146f9657c7fad4", - "sha256": "0wikkkx503ip5xr72bz6d6sh2k50h5wlz9y8vmasvnrz9kjmlv5b" + "rev": "1c4151ff5c1d6fbf7fa800b8d4bb34d3abc03a41", + "sha256": "02621c9nqpr4pwcapy31x36l5kbyd0vdgd0wdaxj5p8hrxk67d6b" } } }, From 9772484257d27206dbd96588677073e1267de2e1 Mon Sep 17 00:00:00 2001 From: Michael Weiss Date: Sun, 27 Nov 2022 18:52:22 +0100 Subject: [PATCH 35/38] chromiumBeta: Fix the configuration phase Upstream switched use_system_libwayland to false [0] and system_wayland_scanner_path will now only be declared if use_system_wayland_scanner is set to true (it defaults to use_system_libwayland) [1]. In Nixpkgs, we usually try to set use_system_* to true (i.e., we favor system libraries over bundled/vendored ones) but in the case of Chromium this can become difficult to maintain so we might eventually drop `use_system_libwayland = true` again (IIRC this only caused one incompatibility in the past though: b6b51374fc7; and f9d9864cb62 will become relevant again when we build with the bundled libwayland). [0]: https://source.chromium.org/chromium/chromium/src/+/b33bdfe2654df61dee900e7b85cc3fcaea6b65a3 [1]: https://source.chromium.org/chromium/chromium/src/+/272220cefa2cff8cf9273a02155454650e79e024 (cherry picked from commit 9d05d42f4d61f28207eef3492115168739cdc442) --- pkgs/applications/networking/browsers/chromium/common.nix | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/pkgs/applications/networking/browsers/chromium/common.nix b/pkgs/applications/networking/browsers/chromium/common.nix index 39a2f3d18369..523a9b251809 100644 --- a/pkgs/applications/networking/browsers/chromium/common.nix +++ b/pkgs/applications/networking/browsers/chromium/common.nix @@ -295,7 +295,14 @@ let chrome_pgo_phase = 0; clang_base_path = "${llvmPackages.clang}"; use_qt = false; + } // optionalAttrs (!chromiumVersionAtLeast "108") { use_system_libwayland_server = true; + } // optionalAttrs (chromiumVersionAtLeast "108") { + # The default has changed to false. We'll build with libwayland from + # Nixpkgs for now but might want to eventually use the bundled libwayland + # as well to avoid incompatibilities (if this continues to be a problem + # from time to time): + use_system_libwayland = true; } // optionalAttrs proprietaryCodecs { # enable support for the H.264 codec proprietary_codecs = true; From 6a93a3a2ed2b58da8e1b5606230e7676cab234c1 Mon Sep 17 00:00:00 2001 From: Michael Weiss Date: Mon, 28 Nov 2022 21:42:55 +0100 Subject: [PATCH 36/38] chromiumBeta: Fix the build We do already set `system_wayland_scanner_path` to `"${wayland}/bin/wayland-scanner"` but apparently wayland-scanner wasn't required (anymore?) as wayland-scanner is only in the `bin` output (I have a few ideas what could've changed but didn't bother to check as it isn't worth the time as long as it works now). This fixes the following build error: ``` ninja: error: '../../../../../../../../nix/store/l3y9k2x7cqzcjj9s18z7la9xqsjq6r52-wayland-1.21.0/bin/wayland-scanner', needed by 'gen/components/exo/wayland/protocol/aura-shell-protocol.c', missing and no known rule to make it ``` (cherry picked from commit 4024dedc4dc9980fc731d48be3ec67b642a9a838) --- pkgs/applications/networking/browsers/chromium/common.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/applications/networking/browsers/chromium/common.nix b/pkgs/applications/networking/browsers/chromium/common.nix index 523a9b251809..b67c3dba906c 100644 --- a/pkgs/applications/networking/browsers/chromium/common.nix +++ b/pkgs/applications/networking/browsers/chromium/common.nix @@ -303,6 +303,7 @@ let # as well to avoid incompatibilities (if this continues to be a problem # from time to time): use_system_libwayland = true; + system_wayland_scanner_path = "${wayland.bin}/bin/wayland-scanner"; } // optionalAttrs proprietaryCodecs { # enable support for the H.264 codec proprietary_codecs = true; From 96c0178fe5268e8f9c5e4f9cfc2d1ad4c9f81311 Mon Sep 17 00:00:00 2001 From: Michael Weiss Date: Wed, 30 Nov 2022 10:27:28 +0100 Subject: [PATCH 37/38] chromiumBeta: 108.0.5359.48 -> 108.0.5359.71 (#203681) * chromiumBeta: 108.0.5359.48 -> 108.0.5359.62 * chromiumBeta: 108.0.5359.62 -> 108.0.5359.71 (cherry picked from commit ed4a7faf43c35d35f144baede6644c1ae382729c) --- .../networking/browsers/chromium/upstream-info.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/applications/networking/browsers/chromium/upstream-info.json b/pkgs/applications/networking/browsers/chromium/upstream-info.json index c7ee4b263dfb..0dcd4c96c219 100644 --- a/pkgs/applications/networking/browsers/chromium/upstream-info.json +++ b/pkgs/applications/networking/browsers/chromium/upstream-info.json @@ -19,9 +19,9 @@ } }, "beta": { - "version": "108.0.5359.48", - "sha256": "0nk33rv4q22kgr9197y6a4w8yazgifsm5qvmmia41nnl24sqik57", - "sha256bin64": "062anw2i8rfi4v8zl0jdqxzn24xzl3ny24cbiyk8dyyf55r914v0", + "version": "108.0.5359.71", + "sha256": "0pgzf6xrd71is1dld1arhq366vjp8p54x75zyx6y7vcjqj0a0v6b", + "sha256bin64": "14sarqyw2pdcnkk2xnsdq58wg0s576fjvqfg0ishprm7ndks1z6m", "deps": { "gn": { "version": "2022-10-05", From d9449adefa6bf687441f6d5e5ba904dd331df44c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Na=C3=AFm=20Favier?= Date: Tue, 29 Nov 2022 14:09:41 +0100 Subject: [PATCH 38/38] nixos/nix-daemon: allow registry paths to be... paths Currently paths are handled by `types.package`, whose semantics are a bit of a mess. In particular, it converts path values to derivations using `toDerivation`, which will lead to problems when flake `outPath`s become paths in https://github.com/NixOS/nix/pull/6530. This change makes the "incompatible changes" section in the above PR obsolete: `nix.registry.nixpkgs.flake = nixpkgs;` works as expected (the flake is copied to the store). (cherry picked from commit bcb5f0decca13c2bd666ee0a2b306b162117bd71) --- nixos/modules/services/misc/nix-daemon.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/nixos/modules/services/misc/nix-daemon.nix b/nixos/modules/services/misc/nix-daemon.nix index 26e7cbfca733..8eb1ed53d0c7 100644 --- a/nixos/modules/services/misc/nix-daemon.nix +++ b/nixos/modules/services/misc/nix-daemon.nix @@ -414,6 +414,7 @@ in str int bool + path package ]); in