Merge master into staging-nixos

This commit is contained in:
nixpkgs-ci[bot]
2026-07-31 18:32:20 +00:00
committed by GitHub
65 changed files with 1671 additions and 1884 deletions

View File

@@ -1,6 +1,5 @@
{
config,
options,
pkgs,
lib,
...
@@ -20,7 +19,6 @@ let
;
cfg = config.services.aesmd;
opt = options.services.aesmd;
sgx-psw = cfg.package;
@@ -28,10 +26,10 @@ let
with cfg.settings;
pkgs.writeText "aesmd.conf" (
concatStringsSep "\n" (
optional (whitelistUrl != null) "whitelist url = ${whitelistUrl}"
optional (defaultQuotingType != null) "default quoting type = ${defaultQuotingType}"
++ optional (qplLogLevel != null) "qpl log level = ${qplLogLevel}"
++ optional (proxy != null) "aesm proxy = ${proxy}"
++ optional (proxyType != null) "proxy type = ${proxyType}"
++ optional (defaultQuotingType != null) "default quoting type = ${defaultQuotingType}"
++
# Newline at end of file
[ "" ]
@@ -45,6 +43,12 @@ in
services.aesmd.package = pkgs.sgx-psw.override { debug = true; };
'')
(mkRemovedOptionModule [
"services"
"aesmd"
"settings"
"whitelistUrl"
] "sgx-psw-v2.28 no longer supports Intel enclave signer cert whitelist management.")
];
options.services.aesmd = {
@@ -66,54 +70,50 @@ in
example = literalExpression "pkgs.sgx-azure-dcap-client";
description = "Custom quote provider library to use.";
};
settings = mkOption {
description = "AESM configuration";
default = { };
type = types.submodule {
options.whitelistUrl = mkOption {
type = with types; nullOr str;
default = null;
example = "http://whitelist.trustedservices.intel.com/SGX/LCWL/Linux/sgx_white_list_cert.bin";
description = "URL to retrieve authorized Intel SGX enclave signers.";
};
options.proxy = mkOption {
type = with types; nullOr str;
default = null;
example = "http://proxy_url:1234";
description = "HTTP network proxy.";
};
options.proxyType = mkOption {
type =
with types;
nullOr (enum [
"default"
"direct"
"manual"
]);
default = if (cfg.settings.proxy != null) then "manual" else null;
defaultText = literalExpression ''
if (config.${opt.settings}.proxy != null) then "manual" else null
'';
example = "default";
description = ''
Type of proxy to use. The `default` uses the system's default proxy.
If `direct` is given, uses no proxy.
A value of `manual` uses the proxy from
{option}`services.aesmd.settings.proxy`.
'';
};
options.defaultQuotingType = mkOption {
type =
with types;
nullOr (enum [
"ecdsa_256"
"epid_linkable"
"epid_unlinkable"
]);
default = null;
example = "ecdsa_256";
description = "Attestation quote type.";
};
settings = {
proxy = mkOption {
type = with types; nullOr str;
default = null;
example = "http://proxy_url:1234";
description = "HTTP network proxy.";
};
proxyType = mkOption {
type =
with types;
nullOr (enum [
"default"
"direct"
"manual"
]);
default = if (cfg.settings.proxy != null) then "manual" else null;
defaultText = literalExpression ''
if (cfg.settings.proxy != null) then "manual" else null
'';
example = "default";
description = ''
Type of proxy to use. The `default` uses the system's default proxy.
If `direct` is given, uses no proxy.
A value of `manual` uses the proxy from
{option}`services.aesmd.settings.proxy`.
'';
};
defaultQuotingType = mkOption {
# sgx-psw 2.28 removed EPID attestation
type = with types; nullOr (enum [ "ecdsa_256" ]);
default = null;
example = "ecdsa_256";
description = "Attestation quote type.";
};
qplLogLevel = mkOption {
type =
with types;
nullOr (enum [
"info"
"error"
]);
default = null;
example = "error";
description = "Log level for the default quote provider library.";
};
};
};
@@ -131,8 +131,6 @@ in
systemd.services.aesmd =
let
storeAesmFolder = "${sgx-psw}/aesm";
# Hardcoded path AESM_DATA_FOLDER in psw/ae/aesm_service/source/oal/linux/aesm_util.cpp
aesmDataFolder = "/var/opt/aesmd/data";
in
{
description = "Intel Architectural Enclave Service Manager";
@@ -154,13 +152,8 @@ in
unitConfig.AssertPathExists = [ "/dev/sgx_enclave" ];
serviceConfig = {
# Run with elevated privileges to create /var/opt/aesmd/... before
# dropping to DynamicUser.
ExecStartPre = ''
+${lib.getExe' pkgs.coreutils "install"} -m 644 -D \
"${storeAesmFolder}/data/white_list_cert_to_be_verify.bin" \
"${aesmDataFolder}/white_list_cert_to_be_verify.bin"
'';
# Hardcoded path AESM_DATA_FOLDER in psw/ae/aesm_service/source/oal/linux/aesm_util.cpp
ExecStartPre = "+${lib.getExe' pkgs.coreutils "mkdir"} -p -m 755 /var/opt/aesmd/data";
ExecStart = "${sgx-psw}/bin/aesm_service --no-daemon";
ExecReload = ''${pkgs.coreutils}/bin/kill -SIGHUP "$MAINPID"'';

View File

@@ -14,8 +14,8 @@
enable = true;
settings = {
defaultQuotingType = "ecdsa_256";
qplLogLevel = "info";
proxyType = "direct";
whitelistUrl = "http://nixos.org";
};
};
@@ -74,17 +74,17 @@
machine.succeed(f"sudo -u sgxtest test {op} {socket_path}")
machine.fail(f"sudo -u nosgxtest test {op} {socket_path}")
with subtest("Copies white_list_cert_to_be_verify.bin"):
whitelist_path = "/var/opt/aesmd/data/white_list_cert_to_be_verify.bin"
whitelist_perms = machine.succeed(
f"nsenter -m -t {main_pid} ${pkgs.coreutils}/bin/stat -c '%a' {whitelist_path}"
with subtest("Creates aesmd data directory"):
data_dir = "/var/opt/aesmd/data"
data_dir_perms = machine.succeed(
f"nsenter -m -t {main_pid} ${pkgs.coreutils}/bin/stat -c '%a' {data_dir}"
).strip()
assert "644" == whitelist_perms, f"white_list_cert_to_be_verify.bin has permissions {whitelist_perms}"
assert data_dir_perms == "755", f"{data_dir} has permissions {data_dir_perms}"
with subtest("Writes and binds aesm.conf in service namespace"):
aesmd_config = machine.succeed(f"nsenter -m -t {main_pid} ${pkgs.coreutils}/bin/cat /etc/aesmd.conf")
assert aesmd_config == "whitelist url = http://nixos.org\nproxy type = direct\ndefault quoting type = ecdsa_256\n", "aesmd.conf differs"
expected = "default quoting type = ecdsa_256\nqpl log level = info\nproxy type = direct\n"
assert aesmd_config == expected, f"aesmd.conf\n\nactual:\n{aesmd_config}\n---\n\nexpected:\n{expected}"
with subtest("aesmd.service without quote provider library has correct LD_LIBRARY_PATH"):
status, environment = machine.systemctl("show --property Environment --value aesmd.service")

View File

@@ -114,7 +114,7 @@ in
machine.succeed("run-goupile-test")
finally:
out_dir = os.environ.get("out", os.getcwd())
machine.copy_from_vm("/tmp/videos", out_dir)
machine.copy_from_machine("/tmp/videos", out_dir)
'';
# Debug interactively with:

View File

@@ -10,13 +10,13 @@
buildMozillaMach rec {
pname = "firefox-devedition";
binaryName = "firefox-devedition";
version = "153.0b13";
version = "154.0b4";
applicationName = "Firefox Developer Edition";
requireSigning = false;
branding = "browser/branding/aurora";
src = fetchurl {
url = "mirror://mozilla/devedition/releases/${version}/source/firefox-${version}.source.tar.xz";
sha512 = "ee1a699ab3f390031e7eb85b6cc394d3431cc2e2960e97cabc393cc4edad1bd1a2ba62e7d834e2ae52fa7fcf3a08c6194c1801ba7e62fa3ceb98ee08ac27981d";
sha512 = "1dae1edf7b97891224d186f469e31cfa0d2c4fbbdfd6d03f74c03b4421902739fee8d359c66b3c2c431318a4212b0e6221456a233fd6a141c96122f3c6e62bea";
};
# buildMozillaMach sets MOZ_APP_REMOTINGNAME during configuration, but

View File

@@ -41,7 +41,10 @@ let
service-identity
libtorrent-rasterbar.dev
libtorrent-rasterbar.python
setuptools
# pkg_resources was removed in setuptools>=82; deluge 2.2.0 still uses it
# standard-pkg-resources is an independent PyPI redistribution providing it
# TODO: remove once deluge migrates off pkg_resources
standard-pkg-resources
setproctitle
pillow
rencode

View File

@@ -8,13 +8,13 @@
}:
stdenv.mkDerivation {
pname = "airwindows";
version = "0-unstable-2026-05-02";
version = "0-unstable-2026-07-19";
src = fetchFromGitHub {
owner = "airwindows";
repo = "airwindows";
rev = "6df9b9832d0e4a1532040c0d4eba5b12bd795f79";
hash = "sha256-MOGVRIxlxyJk4LCW5iVtukV4fAnVoc+wORw2REGRyPc=";
rev = "51a71636fe38bc51cee54861689318ffb7d2e434";
hash = "sha256-DsY1Tto4M1/+tNVtAxdk1NvrEFxMgzZsiylmprSZtTM=";
};
# we patch helpers because honestly im spooked out by where those variables

View File

@@ -8,13 +8,13 @@
}:
stdenv.mkDerivation (finalAttrs: {
pname = "async-profiler";
version = "4.3";
version = "4.5";
src = fetchFromGitHub {
owner = "async-profiler";
repo = "async-profiler";
tag = "v${finalAttrs.version}";
hash = "sha256-wysOjirCfxm0SmwDW7GS+S73lAT8/0g4avu7T5+qy2Q=";
hash = "sha256-H3NBWyCjyuQkQ7HZ+B8ycBGIvQWdQDkx2SpQr+0gL08=";
};
nativeBuildInputs = [ makeWrapper ];

View File

@@ -10,16 +10,16 @@
buildGoModule (finalAttrs: {
pname = "betterleaks";
version = "1.6.1";
version = "1.7.2";
src = fetchFromGitHub {
owner = "betterleaks";
repo = "betterleaks";
tag = "v${finalAttrs.version}";
hash = "sha256-2VjvTS2qOUH8W+hFm4xA3xCGZZs+oP1KQOSq6FBLjaw=";
hash = "sha256-tJk63QED2J0XV893M57xekVJrT50Dbqs0BoK5urDsSc=";
};
vendorHash = "sha256-UBzobzZeIYzP+mU3+9GRF4lAs+cpqkIt+3mBpTN1BN8=";
vendorHash = "sha256-vwy3GJV7MPRxmM7ztwghKit5HZWnz+IyWNX5v/TKkfY=";
ldflags = [
"-s"

View File

@@ -1,11 +1,11 @@
{
version = "3.11.0";
version = "3.12.0";
x86_64-linux = {
url = "https://download.breitbandmessung.de/bbm/Breitbandmessung-3.11.0-linux.deb";
sha256 = "sha256-kNuR+zcKEdZ9p0HEajmFQ3TIUz1z2Ao098QNCK6x5lg=";
url = "https://download.breitbandmessung.de/bbm/Breitbandmessung-3.12.0-linux.deb";
sha256 = "sha256-3wQVUNTjFgoFBpy0Gl1r/FEdgqRrdjM3SFqPpl6z6O4=";
};
aarch64-darwin = {
url = "https://download.breitbandmessung.de/bbm/Breitbandmessung-3.11.0-mac.dmg";
sha256 = "sha256-pKI4Kg4ngXYzyZnzmlijIxmzoCKshdQao1v9JWaAV50=";
url = "https://download.breitbandmessung.de/bbm/Breitbandmessung-3.12.0-mac.dmg";
sha256 = "sha256-QuJaNTyBAVQb3SCHNjnhd5klxTrH/9/J56Mxl6l/sKs=";
};
}

View File

@@ -8,16 +8,16 @@
buildNpmPackage (finalAttrs: {
pname = "claude-agent-acp";
version = "0.60.0";
version = "0.64.0";
src = fetchFromGitHub {
owner = "agentclientprotocol";
repo = "claude-agent-acp";
tag = "v${finalAttrs.version}";
hash = "sha256-idyZcd8KD+bhAlKqqaTS6X8DcNjAzluln8it1V0vyUk=";
hash = "sha256-DBWsdGNbjkC1CzGwCpySOr07ruGkDdybfjkXI+3HXtA=";
};
npmDepsHash = "sha256-dJeUPTcGN616YVKLcsiGgSn8wb7NhJZuZmPRHeUxR4U=";
npmDepsHash = "sha256-qx6IQzrndzPIcPhMZUOrZE8S3amfhoeMhg+gadZmHdk=";
nativeBuildInputs = [ makeWrapper ];

View File

@@ -18,13 +18,13 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "context7-mcp";
version = "3.2.4";
version = "3.2.5";
src = fetchFromGitHub {
owner = "upstash";
repo = "context7";
tag = "${tag-prefix}@${finalAttrs.version}";
hash = "sha256-Ea281W/CT/TfFNFMKV7xQzXnMo/25mCAB/Gs9ofyUU4=";
hash = "sha256-BqssEX4AcqOJJRe4H0ChbpCJE2Zw1TsOdL7sqc8kv2s=";
};
nativeBuildInputs = [
@@ -38,7 +38,7 @@ stdenv.mkDerivation (finalAttrs: {
inherit (finalAttrs) pname version src;
inherit pnpm;
fetcherVersion = 3;
hash = "sha256-F1A0y4uZczVqzce0FfugCaU5Y2qqMZQXy7T6oqlgkbA=";
hash = "sha256-yFppXHv3sBcS8YYERYLTuRPw2jmhi1G+taiPVH1Vix4=";
};
buildPhase = ''

View File

@@ -7,14 +7,14 @@
python3.pkgs.buildPythonApplication (finalAttrs: {
pname = "ffsubsync";
version = "0.4.31";
version = "0.5.1";
pyproject = true;
src = fetchFromGitHub {
owner = "smacke";
repo = "ffsubsync";
tag = finalAttrs.version;
hash = "sha256-j9E4h2de2EOtYpuxKFbPOxZ5FBRO0EkbZhJdx5RiPn8=";
hash = "sha256-n9bYQgbBHGRJl79EiK7pTMDCcbI4ALudZUNc2SU0Wgg=";
};
build-system = with python3.pkgs; [ setuptools ];
@@ -36,6 +36,9 @@ python3.pkgs.buildPythonApplication (finalAttrs: {
webrtcvad
];
# webrtcvad provides the same import as upstream's wheel-only dependency.
pythonRemoveDeps = [ "webrtcvad-wheels" ];
nativeCheckInputs = with python3.pkgs; [ pytestCheckHook ];
pythonImportsCheck = [ "ffsubsync" ];
@@ -51,7 +54,9 @@ python3.pkgs.buildPythonApplication (finalAttrs: {
homepage = "https://github.com/smacke/ffsubsync";
description = "Automagically synchronize subtitles with video";
license = lib.licenses.mit;
maintainers = [ ];
maintainers = with lib.maintainers; [
davinci42
];
mainProgram = "ffsubsync";
};
})

View File

@@ -0,0 +1,6 @@
{ callPackage }:
callPackage ./generic.nix {
version = "3.12.9";
hash = "sha256-iSMxBrJ+M3/I+X3dxBOUHmcEQ0VqLjq38mUJuII3hUY=";
}

View File

@@ -0,0 +1,6 @@
{ callPackage }:
callPackage ./generic.nix {
version = "3.13.8";
hash = "sha256-7/S+SuXItnBabW0e5h/n9tezhW5sV/Ix8CmEOdx9EYA=";
}

View File

@@ -0,0 +1,6 @@
{ callPackage }:
callPackage ./generic.nix {
version = "3.14.2";
hash = "sha256-OuM96W9++2QKD2O2IwkzDjmBaC9Ej/6ReHY/Rwujuno=";
}

View File

@@ -0,0 +1,71 @@
{
fetchurl,
nix-update-script,
hash,
lib,
nixosTests,
stdenvNoCC,
version,
}:
stdenvNoCC.mkDerivation (finalAttrs: {
pname = "gerrit";
inherit version;
strictDeps = true;
__structuredAttrs = true;
src = fetchurl {
url = "https://gerrit-releases.storage.googleapis.com/gerrit-${finalAttrs.version}.war";
inherit hash;
};
buildCommand = ''
mkdir -p "$out"/webapps/
ln -s ${finalAttrs.src} "$out"/webapps/gerrit-${finalAttrs.version}.war
'';
passthru = {
updateScript = nix-update-script {
extraArgs = [
"--url=https://github.com/GerritCodeReview/gerrit"
"--version-regex=v(${lib.versions.majorMinor finalAttrs.version}\\.[0-9]+)"
"--override-filename=pkgs/by-name/ge/gerrit/${lib.versions.major finalAttrs.version}_${lib.versions.minor finalAttrs.version}.nix"
];
};
# A list of plugins that are part of the gerrit.war file.
# Use `java -jar gerrit.war ls | grep plugins/` to generate that list.
plugins = [
"codemirror-editor"
"commit-message-length-validator"
"delete-project"
"download-commands"
"gitiles"
"hooks"
"plugin-manager"
"replication"
"reviewnotes"
"singleusergroup"
"webhooks"
];
tests.gerrit = nixosTests.gerrit.extendNixOS {
module = {
services.gerrit.package = finalAttrs.finalPackage;
};
};
};
meta = {
homepage = "https://www.gerritcodereview.com/index.md";
license = lib.licenses.asl20;
description = "Web based code review and repository management for the git version control system";
changelog = "https://www.gerritcodereview.com/${lib.versions.majorMinor finalAttrs.version}.html";
sourceProvenance = with lib.sourceTypes; [ binaryBytecode ];
maintainers = with lib.maintainers; [
flokli
zimbatm
felixsinger
];
platforms = lib.platforms.unix;
};
})

View File

@@ -1,62 +1,3 @@
{
lib,
stdenvNoCC,
fetchurl,
gitUpdater,
nixosTests,
}:
{ callPackage }:
stdenvNoCC.mkDerivation (finalAttrs: {
pname = "gerrit";
version = "3.14.2";
src = fetchurl {
url = "https://gerrit-releases.storage.googleapis.com/gerrit-${finalAttrs.version}.war";
hash = "sha256-OuM96W9++2QKD2O2IwkzDjmBaC9Ej/6ReHY/Rwujuno=";
};
buildCommand = ''
mkdir -p "$out"/webapps/
ln -s ${finalAttrs.src} "$out"/webapps/gerrit-${finalAttrs.version}.war
'';
passthru = {
updateScript = gitUpdater {
url = "https://gerrit.googlesource.com/gerrit";
rev-prefix = "v";
allowedVersions = "^[0-9\\.]+$";
};
# A list of plugins that are part of the gerrit.war file.
# Use `java -jar gerrit.war ls | grep plugins/` to generate that list.
plugins = [
"codemirror-editor"
"commit-message-length-validator"
"delete-project"
"download-commands"
"gitiles"
"hooks"
"plugin-manager"
"replication"
"reviewnotes"
"singleusergroup"
"webhooks"
];
tests = {
inherit (nixosTests) gerrit;
};
};
meta = {
homepage = "https://www.gerritcodereview.com/index.md";
license = lib.licenses.asl20;
description = "Web based code review and repository management for the git version control system";
changelog = "https://www.gerritcodereview.com/${lib.versions.majorMinor finalAttrs.version}.html";
sourceProvenance = with lib.sourceTypes; [ binaryBytecode ];
maintainers = with lib.maintainers; [
flokli
zimbatm
felixsinger
];
platforms = lib.platforms.unix;
};
})
callPackage ./3_14.nix { }

View File

@@ -6,13 +6,14 @@
makeWrapper,
}:
stdenv.mkDerivation rec {
stdenv.mkDerivation (finalAttrs: {
pname = "google-java-format";
version = "1.36.0";
__structuredAttrs = true;
src = fetchurl {
url = "https://github.com/google/google-java-format/releases/download/v${version}/google-java-format-${version}-all-deps.jar";
sha256 = "sha256-I2lt4F3SDYXBRJyN6fJBkDB5lQj1NWVw6Xn3+W5Z2NY=";
url = "https://github.com/google/google-java-format/releases/download/v${finalAttrs.version}/google-java-format-${finalAttrs.version}-all-deps.jar";
};
dontUnpack = true;
@@ -23,17 +24,17 @@ stdenv.mkDerivation rec {
installPhase = ''
runHook preInstall
mkdir -p $out/{bin,share/${pname}}
install -D ${src} $out/share/${pname}/google-java-format-${version}-all-deps.jar
mkdir -p $out/{bin,share/${finalAttrs.pname}}
install -D ${finalAttrs.src} $out/share/${finalAttrs.pname}/google-java-format-${finalAttrs.version}-all-deps.jar
makeWrapper ${jre}/bin/java $out/bin/${pname} \
--argv0 ${pname} \
makeWrapper ${jre}/bin/java $out/bin/${finalAttrs.pname} \
--argv0 ${finalAttrs.pname} \
--add-flags "--add-exports jdk.compiler/com.sun.tools.javac.api=ALL-UNNAMED" \
--add-flags "--add-exports jdk.compiler/com.sun.tools.javac.file=ALL-UNNAMED" \
--add-flags "--add-exports jdk.compiler/com.sun.tools.javac.parser=ALL-UNNAMED" \
--add-flags "--add-exports jdk.compiler/com.sun.tools.javac.tree=ALL-UNNAMED" \
--add-flags "--add-exports jdk.compiler/com.sun.tools.javac.util=ALL-UNNAMED" \
--add-flags "-jar $out/share/${pname}/google-java-format-${version}-all-deps.jar"
--add-flags "-jar $out/share/${finalAttrs.pname}/google-java-format-${finalAttrs.version}-all-deps.jar"
runHook postInstall
'';
@@ -50,4 +51,4 @@ stdenv.mkDerivation rec {
platforms = lib.platforms.all;
mainProgram = "google-java-format";
};
}
})

View File

@@ -21,16 +21,16 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "halloy";
version = "2026.7.2";
version = "2026.8";
src = fetchFromGitHub {
owner = "squidowl";
repo = "halloy";
tag = finalAttrs.version;
hash = "sha256-+qFHwlwRxVN4W9DG+gY5N6um+JARD+3EiLlsD7R9Tpc=";
hash = "sha256-OPSitjgfiBbqCNa3dIBHrFCP7097vsF78H5aCbtvPAI=";
};
cargoHash = "sha256-/nFtOJXpusIlc7orGv013qzad8fdfQr32c8DAlccHIA=";
cargoHash = "sha256-LBJmiUxCHUZM1nzF7rCapKPELqdSLNdz2am7ivHSK98=";
nativeBuildInputs = [
copyDesktopItems

View File

@@ -16,7 +16,7 @@
mpv-unwrapped,
}:
let
version = "0.3.22";
version = "0.3.32";
url_base = "https://github.com/alexmercerind2/harmonoid-releases/releases/download/v${version}";
url =
{
@@ -28,9 +28,9 @@ let
or (throw "${stdenv.hostPlatform.system} is an unsupported platform");
hash =
{
x86_64-linux = "sha256-+fEx30uu0rZiORrtE00xG2piJzpFbfxSZw3OjrhLJyg=";
aarch64-linux = "sha256-jXN5i+LudsODNZUzb5SXClqgQxYzanrbZCqB8X0pJRQ=";
aarch64-darwin = "sha256-YYMKrb7ZilfEztL2JTxSdeoDd8xQMrHFtN9N9fmsm3w=";
x86_64-linux = "sha256-ICnghYC25CLf5kzB6tUC/ocKI+J5HA7zyK9dEkLOWWE=";
aarch64-linux = "sha256-j9Pveq7iULBUVF7ochHWS9VynlJlk14m3KLRyAcNKiA=";
aarch64-darwin = "sha256-BrhumTPD7SjK9LRUp5giy5h7LdSrhQyVUXE1Crr0LXI=";
}
.${stdenv.hostPlatform.system};
in

View File

@@ -9,16 +9,16 @@
buildGoModule rec {
pname = "jx";
version = "3.17.17";
version = "3.17.61";
src = fetchFromGitHub {
owner = "jenkins-x";
repo = "jx";
rev = "v${version}";
sha256 = "sha256-Fu8qBiRWLZBK2Qn+fVPi7TVeqK+/ZD5a/c5yvPnypWo=";
sha256 = "sha256-4iDzS4ONDbCzXun2cB+t2c276VmKzIyB6OdeXEb3E6M=";
};
vendorHash = "sha256-tGvreLuxaRswjCGzroCRRDZR4QadQKLrX9Hz3u22VZ0=";
vendorHash = "sha256-Rupnzj1kw0den6O0RZ5Fg5pZWRsfLuor3ntAiQjfIn8=";
subPackages = [ "cmd" ];

View File

@@ -3,7 +3,7 @@
"description": "KeePassXC integration with native messaging support",
"path": "@out@/bin/keepassxc-proxy",
"type": "stdio",
"allowed_extensions": [
"allowed_origins": [
"chrome-extension://iopaggbpplllidnfmcghoonnokmjoicf/",
"chrome-extension://oboonakemofpalcgghocfoadofidjkkk/",
"chrome-extension://pdffhmdngciaglkoonimfcmckehcpafo/"

View File

@@ -50,7 +50,7 @@ in
# check if following issue is still valid
# https://github.com/mudler/LocalAI/issues/2207
machine.succeed("${jq}/bin/jq --exit-status '.[] | select(.name == \"api_call\").metrics | debug | any(.labels.path == \"/metricsls\" and .count == \"1\")' metrics.json")
machine.copy_from_vm("metrics.json")
machine.copy_from_machine("metrics.json")
'';
};
@@ -101,11 +101,11 @@ in
machine.succeed("${jq}/bin/jq --exit-status 'debug | .data[].id == \"${model}\"' models.json")
machine.succeed("curl -f http://localhost:${port}/embeddings --json @${writers.writeJSON "request.json" requests.request} --output embeddings.json")
machine.copy_from_vm("embeddings.json")
machine.copy_from_machine("embeddings.json")
machine.succeed("${jq}/bin/jq --exit-status 'debug | .model == \"${model}\"' embeddings.json")
machine.succeed("${prom2json}/bin/prom2json http://localhost:${port}/metrics > metrics.json")
machine.copy_from_vm("metrics.json")
machine.copy_from_machine("metrics.json")
'';
};
@@ -206,21 +206,21 @@ in
machine.succeed("${jq}/bin/jq --exit-status 'debug | .data[].id == \"${model}\"' models.json")
machine.succeed("curl -f http://localhost:${port}/v1/chat/completions --json @${writers.writeJSON "request-chat-completions.json" requests.chat-completions} --output chat-completions.json")
machine.copy_from_vm("chat-completions.json")
machine.copy_from_machine("chat-completions.json")
machine.succeed("${jq}/bin/jq --exit-status 'debug | .object == \"chat.completion\"' chat-completions.json")
machine.succeed("${jq}/bin/jq --exit-status 'debug | .choices | first.message.content | split(\" \") | last | tonumber == 3' chat-completions.json")
machine.succeed("curl -f http://localhost:${port}/v1/edits --json @${writers.writeJSON "request-edit-completions.json" requests.edit-completions} --output edit-completions.json")
machine.copy_from_vm("edit-completions.json")
machine.copy_from_machine("edit-completions.json")
machine.succeed("${jq}/bin/jq --exit-status 'debug | .object == \"edit\"' edit-completions.json")
machine.succeed("${jq}/bin/jq --exit-status '.usage.completion_tokens | debug == ${toString requests.edit-completions.max_tokens}' edit-completions.json")
machine.succeed("curl -f http://localhost:${port}/v1/completions --json @${writers.writeJSON "request-completions.json" requests.completions} --output completions.json")
machine.copy_from_vm("completions.json")
machine.copy_from_machine("completions.json")
machine.succeed("${jq}/bin/jq --exit-status 'debug | .object ==\"text_completion\"' completions.json")
machine.succeed("${prom2json}/bin/prom2json http://localhost:${port}/metrics > metrics.json")
machine.copy_from_vm("metrics.json")
machine.copy_from_machine("metrics.json")
'';
};
@@ -289,14 +289,14 @@ in
machine.succeed("${jq}/bin/jq --exit-status 'debug' models.json")
machine.succeed("curl -f http://localhost:${port}/tts --json @${writers.writeJSON "request.json" requests.request} --output out.wav")
machine.copy_from_vm("out.wav")
machine.copy_from_machine("out.wav")
machine.succeed("curl -f http://localhost:${port}/v1/audio/transcriptions --header 'Content-Type: multipart/form-data' --form file=@out.wav --form model=${model-stt} --output transcription.json")
machine.copy_from_vm("transcription.json")
machine.copy_from_machine("transcription.json")
machine.succeed("${jq}/bin/jq --exit-status 'debug | .segments | first.text == \"${requests.request.input}\"' transcription.json")
machine.succeed("${prom2json}/bin/prom2json http://localhost:${port}/metrics > metrics.json")
machine.copy_from_vm("metrics.json")
machine.copy_from_machine("metrics.json")
'';
};
}

View File

@@ -3,8 +3,8 @@
stdenv,
fetchFromGitHub,
alsa-lib,
SDL2,
SDL2_ttf,
sdl3,
sdl3-ttf,
copyDesktopItems,
expat,
fetchurl,
@@ -55,6 +55,7 @@ stdenv.mkDerivation (finalAttrs: {
"CC=${stdenv.cc.targetPrefix}cc"
"CXX=${stdenv.cc.targetPrefix}c++"
"TOOLS=1"
"OSD=sdl3"
"USE_LIBSDL=1"
# "USE_SYSTEM_LIB_ASIO=1"
"USE_SYSTEM_LIB_EXPAT=1"
@@ -84,8 +85,8 @@ stdenv.mkDerivation (finalAttrs: {
rapidjson
pugixml
glm
SDL2
SDL2_ttf
sdl3
sdl3-ttf
sqlite
libsForQt5.qtbase
]
@@ -135,11 +136,9 @@ stdenv.mkDerivation (finalAttrs: {
# This replaces the `sw_vers` call with the macOS version actually being
# targeted, so everything gets linked correctly.
+ lib.optionalString stdenv.hostPlatform.isDarwin ''
for file in scripts/src/osd/{mac,sdl}.lua; do
substituteInPlace "$file" --replace-fail \
'backtick("sw_vers -productVersion")' \
"os.getenv('MACOSX_DEPLOYMENT_TARGET') or '$darwinMinVersion'"
done
substituteInPlace scripts/src/osd/sdl3.lua --replace-fail \
'backtick("sw_vers -productVersion")' \
"os.getenv('MACOSX_DEPLOYMENT_TARGET') or '$darwinMinVersion'"
'';
desktopItems = [

View File

@@ -7,16 +7,16 @@
maven.buildMavenPackage rec {
pname = "mariadb-connector-java";
version = "3.5.7";
version = "3.5.10";
src = fetchFromGitHub {
owner = "mariadb-corporation";
repo = "mariadb-connector-j";
tag = version;
hash = "sha256-ScdrBSJKbVyD/omPrxiZvuaa5uOo2d3SqX/ozalMWHk=";
hash = "sha256-6xdqlk+B7h19M2BxtH00u+No/znlN4qNAP0ozxy8+W8=";
};
mvnHash = "sha256-CiUXHrabVX+ragocKbd4erIWr7J4kuWYcKYCDycpIrs=";
mvnHash = "sha256-dX3SqMSSgk6aOtjzC/e3418KMllbD+7V/vFeaZ9fE5s=";
doCheck = false; # Requires networking

View File

@@ -17,17 +17,17 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "matrix-continuwuity";
version = "26.7.1";
version = "26.7.2";
src = fetchFromGitea {
domain = "forgejo.ellis.link";
owner = "continuwuation";
repo = "continuwuity";
tag = "v${finalAttrs.version}";
hash = "sha256-gdTj7y1fwTG0CNWeK/0An6WM8YEeiw7TOuTjh1Zbe50=";
hash = "sha256-uE38tYYgze2q4hgW1mzk5CLTD3ezAwCnj+RQOmZtCdw=";
};
cargoHash = "sha256-nhL4GRmw49n+UlHUKHcEJPoT/BNm+6eatqz/m+zjahg=";
cargoHash = "sha256-DZsRr0Xt/7HnlNCZfXK4dUILK/uEOnSD+r26OxvycD0=";
nativeBuildInputs = [
pkg-config

View File

@@ -40,7 +40,7 @@ assert
pythonPackages.buildPythonApplication (finalAttrs: {
pname = "music-assistant";
version = "2.9.9";
version = "2.9.10";
pyproject = true;
__structuredAttrs = true;
@@ -48,7 +48,7 @@ pythonPackages.buildPythonApplication (finalAttrs: {
owner = "music-assistant";
repo = "server";
tag = finalAttrs.version;
hash = "sha256-ooe+QW+7S5LCgpin5/2g4L8+UDtr4TGZRpeR5F/tqZo=";
hash = "sha256-v9xFW83/v8CjKa04oql1yGQKB58VQtFmXZTN/KMN/gM=";
};
patches = [
@@ -195,6 +195,7 @@ pythonPackages.buildPythonApplication (finalAttrs: {
"dlna"
"fastmcp_server"
"jellyfin"
"heos"
"mpd"
"msx_bridge"
"opensubsonic"

View File

@@ -1,7 +1,7 @@
# Do not edit manually, run ./update-providers.py
{
version = "2.9.9";
version = "2.9.10";
builtins = [
"builtin"
"coverartarchive"
@@ -148,8 +148,6 @@
];
lrclib = ps: [
];
motherearthradio = ps: [
];
mpd =
ps: with ps; [
python-mpd2

View File

@@ -27,20 +27,20 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "n8n";
version = "2.31.4";
version = "2.32.6";
src = fetchFromGitHub {
owner = "n8n-io";
repo = "n8n";
tag = "n8n@${finalAttrs.version}";
hash = "sha256-lmkCT1o5LSC1ORd+Jozr9hkJu2znMpFO97jTWYOnga0=";
hash = "sha256-wWm6vGyJ2I2SBU38gRGaZG2FR5FBxH6V/sWQwn5B4Ac=";
};
pnpmDeps = fetchPnpmDeps {
inherit (finalAttrs) pname version src;
pnpm = pnpm_10;
fetcherVersion = 4;
hash = "sha256-ejJ0ihsLdIXbNllDtoi7Yd1u4x61Czxm6d8zJ9Fj7p8=";
hash = "sha256-D8CKJxU2RoMjNrqIgGDE3mFBjc0kqFLQzT/DdUpiNmY=";
};
nativeBuildInputs = [

View File

@@ -8,25 +8,41 @@
pkg-config,
wayland-scanner,
bashNonInteractive,
cairo,
fontconfig,
freetype,
glib,
gtk4,
libGL,
librsvg,
libwebp,
libxkbcommon,
nlohmann_json,
pango,
stb,
tomlplusplus,
wayland,
wayland-protocols,
wlroots_0_20,
nix-update-script,
}:
let
# nixpkgs stb doesn't have stb_image_resize2.h which noctalia-greeter needs
stb' = stb.overrideAttrs {
version = "0-unstable-2025-10-26";
src = fetchFromGitHub {
owner = "nothings";
repo = "stb";
rev = "f1c79c02822848a9bed4315b12c8c8f3761e1296";
hash = "sha256-BlyXJtAI7WqXCTT3ylww8zoG0hBxaojJnQDvdQOXJPE=";
};
};
in
stdenv.mkDerivation (finalAttrs: {
pname = "noctalia-greeter";
version = "1.0.0";
version = "1.1.0";
__structuredAttrs = true;
strictDeps = true;
@@ -34,8 +50,8 @@ stdenv.mkDerivation (finalAttrs: {
src = fetchFromGitHub {
owner = "noctalia-dev";
repo = "noctalia-greeter";
rev = "367ab83dcd9190010f093cfe0e123ba132a75b5a";
hash = "sha256-/jQ/lkgjaH5EOTZRXk4YZaFrjrKhq/fzZsU6nm7wPt0=";
tag = "v${finalAttrs.version}";
hash = "sha256-3t/+o8Cbve8z43IekUNBj7Ecn/T+v7+p4Ivgs3IEQtk=";
};
nativeBuildInputs = [
@@ -46,18 +62,22 @@ stdenv.mkDerivation (finalAttrs: {
];
buildInputs = [
bashNonInteractive
cairo
fontconfig
freetype
glib
gtk4
libGL
librsvg
libwebp
libxkbcommon
nlohmann_json
pango
stb'
tomlplusplus
wayland
wayland-protocols
wlroots_0_20
];
passthru.updateScript = nix-update-script { };
@@ -65,10 +85,10 @@ stdenv.mkDerivation (finalAttrs: {
meta = {
description = "`greetd` greeter for Noctalia";
homepage = "https://github.com/noctalia-dev/noctalia-greeter";
changelog = "https://github.com/noctalia-dev/noctalia-greeter/blob/${finalAttrs.src.rev}/CHANGELOG.md";
license = lib.licenses.mit;
maintainers = with lib.maintainers; [
dtomvan
samiser
spacedentist
];
mainProgram = "noctalia-greeter-session";

View File

@@ -16,18 +16,18 @@
buildGoModule (finalAttrs: {
pname = "olivetin";
version = "3000.17.3";
version = "3000.18.1";
src = fetchFromGitHub {
owner = "OliveTin";
repo = "OliveTin";
tag = finalAttrs.version;
hash = "sha256-fC+J1ejRDQDe3LfCNuZrt52mvXUxw8eMScCk1wsuQCo=";
hash = "sha256-74G/klFYD2dXBnTI6Pe1qArM3ZGFralsmGZJ2HlNN24=";
};
modRoot = "service";
vendorHash = "sha256-33tP6bZgwOTAXBgxfdbq1Dn73uVJE5dYR1drlxBe7eo=";
vendorHash = "sha256-QslY0UIdr0EXYxYfWe7URfEYroLEZ+Dm26Q4hpLxkJI=";
subPackages = [ "." ];
@@ -75,14 +75,14 @@ buildGoModule (finalAttrs: {
'';
outputHashMode = "recursive";
outputHash = "sha256-+Afw5Q+3u24+eDk6yxN3WiyKmLtodaq9uk/mAKAz/G4=";
outputHash = "sha256-+U6WTWVVZI5QBAquhpNwbJQDp5GlDNL9T0xYEssF0TM=";
};
webui = buildNpmPackage {
pname = "olivetin-webui";
inherit (finalAttrs) version src;
npmDepsHash = "sha256-c76uc+t/hRZKRGeOnqbjAK7KbaWncBkovtjMm7pgGUs=";
npmDepsHash = "sha256-uXbUAREi9jyKqLwrA5bNDpnJ41QUbwYrk9PJDhTqV7U=";
sourceRoot = "${finalAttrs.src.name}/frontend";

View File

@@ -7,17 +7,17 @@
}:
rustPlatform.buildRustPackage (finalAttrs: {
pname = "oniux";
version = "0.10.0";
version = "0.12.0";
src = fetchFromGitLab {
domain = "gitlab.torproject.org";
owner = "tpo/core";
repo = "oniux";
tag = "v${finalAttrs.version}";
hash = "sha256-ys6RjLyfhoAIiIlf8pv971txPubobY627jhk84HZhsw=";
hash = "sha256-04JywbJ//qgA56/5C4DZOliryZCnO0K3/0lyevFz7hk=";
};
cargoHash = "sha256-4sXCZ2P4HFsW3g/CSIB2gwBMSddNXzdIav1tSWWOO9A=";
cargoHash = "sha256-a0hV4q288IWFC1a1jTvgkXAVyKGm8OnsRHwShnQjywI=";
nativeBuildInputs = [
perl

View File

@@ -1,6 +1,7 @@
{
lib,
fetchFromGitHub,
fetchpatch,
crystal,
jq,
libxml2,
@@ -18,6 +19,13 @@ crystal.buildCrystalPackage rec {
sha256 = "sha256-AgUVHlk39J1V1Vv91FjglT4mSbP4IHiRlTrlfmrJxfY=";
};
patches = [
(fetchpatch {
url = "https://github.com/Blacksmoke16/oq/commit/151b5b1d60ed1cafa9fc2a1ec175dcd1732a3961.diff";
hash = "sha256-xWZ1U2A1ClwviSdGMvBeBgA16qKLuUzdBRmJblM7DAc=";
})
];
nativeBuildInputs = [ makeWrapper ];
buildInputs = [ libxml2 ];
nativeCheckInputs = [ jq ];

View File

@@ -1,29 +1,26 @@
# Generated by ./update.sh - do not update manually!
# Last updated: 2026-06-03
# Last updated: 2026-07-30
{ fetchurl }:
let
any-darwin = {
version = "6.9.96-2026-05-28";
{
aarch64-darwin = {
version = "6.9.98-2026-07-20";
src = fetchurl {
url = "https://qqdl.gtimg.cn/qqfile/QQNT/9.9.31/release/045f4292/QQ_6.9.96_260528_01.dmg";
hash = "sha256-cMgWMXfKtL4ZLBrjGhROpCMNAHtFIdnZRfyi9XtsIjI=";
url = "https://qqdl.gtimg.cn/qqfile/QQNT/9.9.32/release/7ee184e7/QQ_6.9.98_260710_01.dmg";
hash = "sha256-pDkK46kO5KxcGcDaQptKkgkH4XYEVUrUhxHvIXT1be4=";
};
};
in
{
aarch64-darwin = any-darwin;
aarch64-linux = {
version = "3.2.29-2026-05-28";
version = "3.2.31-2026-07-20";
src = fetchurl {
url = "https://qqdl.gtimg.cn/qqfile/QQNT/9.9.31/release/00e6a3e7/QQ_3.2.29_260528_arm64_01.deb";
hash = "sha256-W82MzaQB+/oYIafDx1j4SiU8MXVo8LnC10QmokdJ6aY=";
url = "https://qqdl.gtimg.cn/qqfile/QQNT/9.9.32/release/c390e792/QQ_3.2.31_260710_arm64_01.deb";
hash = "sha256-rGBDcfXEhqz2y/g91mfmIu4fSH0Mi9QlYn3m1o/jSXQ=";
};
};
x86_64-linux = {
version = "3.2.29-2026-05-28";
version = "3.2.31-2026-07-20";
src = fetchurl {
url = "https://qqdl.gtimg.cn/qqfile/QQNT/9.9.31/release/00e6a3e7/QQ_3.2.29_260528_amd64_01.deb";
hash = "sha256-HjgoB5ZzyUmUvA9HgNXYUoZHY5kgZZhi1J0cLyoZjiU=";
url = "https://qqdl.gtimg.cn/qqfile/QQNT/9.9.32/release/c390e792/QQ_3.2.31_260710_amd64_01.deb";
hash = "sha256-AvZ3/rHOAe0pOjx3YeXdhb15k29X3KpM21MXiuMOPW0=";
};
};
}

View File

@@ -15,7 +15,7 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "radicle-httpd";
version = "0.26.0";
version = "0.27.0";
env.RADICLE_VERSION = finalAttrs.version;
@@ -29,10 +29,10 @@ rustPlatform.buildRustPackage (finalAttrs: {
"/Cargo.toml"
"/Cargo.lock"
];
hash = "sha256-zSU8B5IwOEUS9d4Y/UWJ6eD0p3zvp0nWVgJmZ/kVB1Q=";
hash = "sha256-OJrHV5WdFNzoYrOkqpN1ctrJDB3JTJhH54q/C6IV9ZU=";
};
cargoHash = "sha256-rdW+WLkQ4UEn6hRZfgJhJkJWb7A26MayXVnVwAlLAG8=";
cargoHash = "sha256-FjYhw27pAX9Tilgm/Tg18Vkv4/K5kEFJAbhv1mDY0rg=";
nativeBuildInputs = [
asciidoctor

View File

@@ -14,16 +14,16 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "rattler-build";
version = "0.70.0";
version = "0.72.0";
src = fetchFromGitHub {
owner = "prefix-dev";
repo = "rattler-build";
tag = "v${finalAttrs.version}";
hash = "sha256-kvcxBrP6vzbhtzgFqMfTZwQlCJ6wnaAYbCNLotGQnK4=";
hash = "sha256-rekotcO5RMwCAlyqz9tsH3MrlLyr0sMxrW5sqXykV2c=";
};
cargoHash = "sha256-UoZqxpcLZqXxZYTfLIaqMa/1gkIn9Ntmk2qsnaTmV7s=";
cargoHash = "sha256-aipz3siZhSau3en7udAvuHp3egXFQa/+a8UVu5W/NKM=";
doCheck = false; # test requires network access

View File

@@ -69,13 +69,13 @@ in
rustPlatform.buildRustPackage (finalAttrs: {
pname = "servo";
version = "0.3.0";
version = "0.4.0";
src = fetchFromGitHub {
owner = "servo";
repo = "servo";
tag = "v${finalAttrs.version}";
hash = "sha256-DfUjByBtDcOShExuBBLSHmgP9CPMSdkovw9QeGRDYaA=";
tag = finalAttrs.version;
hash = "sha256-oA6fFvSajUHFxyu5kgT3BZ8oxWNMdkdaov6tVkxgNrE=";
# Breaks reproducibility depending on whether the picked commit
# has other ref-names or not, which may change over time, i.e. with
# "ref-names: HEAD -> main" as long this commit is the branch HEAD
@@ -85,7 +85,7 @@ rustPlatform.buildRustPackage (finalAttrs: {
'';
};
cargoHash = "sha256-N0MUtL0HslJHEQUCB0iMbXGdD9hA6GRqcmdSjjhsu8E=";
cargoHash = "sha256-kFuW2RoE37ClYAEcEcRudQoUsRsjbUeEBbz/6d96FPU=";
# set `HOME` to a temp dir for write access
# Fix invalid option errors during linking (https://github.com/mozilla/nixpkgs-mozilla/commit/c72ff151a3e25f14182569679ed4cd22ef352328)

View File

@@ -29,7 +29,7 @@
enableVST2 ? false,
}:
let
version = "1.1.5";
version = "1.1.7";
in
stdenv.mkDerivation {
pname = "socalabs-sn76489";
@@ -39,7 +39,7 @@ stdenv.mkDerivation {
owner = "FigBug";
repo = "SN76489";
tag = "v${version}";
hash = "sha256-dQ697B0mhdIC0ltdY2EnErLNAGRKA6ARONX/kR3OLyI=";
hash = "sha256-gTFQ4Aibj2uesx0NRTM7H7diEzlic33Tl6gAzWUikxQ=";
fetchSubmodules = true;
preFetch = ''
# can't clone using ssh

View File

@@ -30,13 +30,13 @@
}:
stdenv.mkDerivation (finalAttrs: {
pname = "socalabs-voc";
version = "1.1.5";
version = "1.1.7";
src = fetchFromGitHub {
owner = "FigBug";
repo = "Voc";
tag = "v${finalAttrs.version}";
hash = "sha256-t9z+qnboGfHUcOp9WmfWXG7ss8VTkz8cv5qUMy//3AE=";
hash = "sha256-k+0oU157bXtwmGSccl2E4GUaRw9UYhQJ0dfQSdrK6GI=";
fetchSubmodules = true;
preFetch = ''
# can't clone using ssh

View File

@@ -22,13 +22,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "solarus";
version = "2.0.4";
version = "2.1.0";
src = fetchFromGitLab {
owner = "solarus-games";
repo = "solarus";
tag = "v${finalAttrs.version}";
hash = "sha256-dgsRxP0tZQjwlQhgEd8RwPtO/oU62xyy8WrHECBRMjQ=";
hash = "sha256-Uq5KRgPzwga7inEVNZ1ObtgtUy+Ld6xzYTNVX6k2nks=";
};
outputs = [

View File

@@ -6,13 +6,13 @@
buildGoModule (finalAttrs: {
pname = "spruce";
version = "1.35.13";
version = "1.35.14";
src = fetchFromGitHub {
owner = "geofffranks";
repo = "spruce";
rev = "v${finalAttrs.version}";
hash = "sha256-A1B9xFXqjxV34aPdg7tHOZIzQQR6boHTTO0ao2osiTY=";
hash = "sha256-EKhspLsuovnzJVFyp8+0cUSA+kRzPwJ0YHN5iUe5NRM=";
};
vendorHash = null;

View File

@@ -6,16 +6,16 @@
}:
rustPlatform.buildRustPackage (finalAttrs: {
pname = "proxy";
version = "1.0.0";
version = "1.0.1";
src = fetchFromGitHub {
owner = "stalwartlabs";
repo = "proxy";
tag = "v${finalAttrs.version}";
hash = "sha256-CAT05X9z8VBoDyZhVdMCUgpMtUe4wJvvROQc/sYHROs=";
hash = "sha256-hLVxno+1hsCoMQK5HfTswIbUZkytjcO8Sgddfga/kDA=";
};
__structuredAttrs = true;
__darwinAllowLocalNetworking = true;
cargoHash = "sha256-JXKqLM9rosaeCQP+UnY49FI6dpTEfd//jUhTEHoeKqU=";
cargoHash = "sha256-8TiWM3kqCsqtkTBh4cl4CeLEeM2PZq+FZNw0omcb7ME=";
# `Result::unwrap()` on an `Err` value: Tls("platform verifier: unexpected error: No CA certificates were loaded from the system")
nativeCheckInputs = [
cacert

File diff suppressed because it is too large Load Diff

View File

@@ -1,33 +0,0 @@
diff --git a/frontend/src-tauri/Cargo.lock b/frontend/src-tauri/Cargo.lock
index 87d5531..39b03ed 100644
--- a/frontend/src-tauri/Cargo.lock
+++ b/frontend/src-tauri/Cargo.lock
@@ -1966,7 +1966,7 @@ dependencies = [
"js-sys",
"log",
"wasm-bindgen",
- "windows-core 0.61.2",
+ "windows-core 0.62.2",
]
[[package]]
@@ -6041,6 +6041,19 @@ dependencies = [
"windows-core 0.61.2",
]
+[[package]]
+name = "windows-core"
+version = "0.61.2"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "c0fdd3ddb90610c7638aa2b3a3ab2904fb9e5cdbecc643ddb3647212781c4ae3"
+dependencies = [
+ "windows-implement",
+ "windows-interface",
+ "windows-link 0.1.3",
+ "windows-result 0.3.4",
+ "windows-strings 0.4.2",
+]
+
[[package]]
name = "windows-core"
version = "0.62.2"

View File

@@ -12,8 +12,11 @@
makeBinaryWrapper,
nodejs,
npmHooks,
pax-utils,
pkg-config,
unzip,
wrapGAppsHook3,
zip,
glib-networking,
jdk25,
@@ -25,7 +28,7 @@
nixosTests,
isDesktopVariant ? false,
withAdditionalFeatures ? true,
withAdditionalFeatures ? !isDesktopVariant,
buildWithFrontend ? !isDesktopVariant,
}:
@@ -35,36 +38,83 @@ assert isDesktopVariant -> !buildWithFrontend;
let
gradle = gradle_8;
jre = jdk25;
# jpdfium 1.0.2's bundled x86_64 libicudata.so.74 has an erroneous executable
# PT_GNU_STACK; the arm64 archive was checked and already has a non-executable stack.
# Fixed upstream for the next natives release; remove when Stirling-PDF updates jpdfium.
# https://github.com/Stirling-Tools/Stirling-PDF/issues/6869
# https://github.com/Stirling-Tools/JPDFium/pull/19
patchJpdfium = lib.optionalString (stdenv.hostPlatform.isLinux && stdenv.hostPlatform.isx86_64) ''
nativeJars=(
"$GRADLE_USER_HOME"/caches/modules-2/files-2.1/com.stirling/jpdfium-natives-linux-x64/*/*/jpdfium-natives-linux-x64-*.jar
)
if (( ''${#nativeJars[@]} != 1 )); then
echo "expected exactly one jpdfium native JAR, found ''${#nativeJars[@]}" >&2
exit 1
fi
nativeJar="''${nativeJars[0]}"
patchDir="$(mktemp -d)"
unzip -q "$nativeJar" natives/linux-x64/libicudata.so.74 -d "$patchDir"
scanelf -X -e "$patchDir/natives/linux-x64/libicudata.so.74"
touch --date=@315532800 "$patchDir/natives/linux-x64/libicudata.so.74"
chmod u+w "$nativeJar"
(cd "$patchDir" && zip -q -X "$nativeJar" natives/linux-x64/libicudata.so.74)
bootJars=( ./app/core/build/libs/stirling-pdf-*.jar )
if (( ''${#bootJars[@]} != 1 )); then
echo "expected exactly one Stirling-PDF JAR, found ''${#bootJars[@]}" >&2
exit 1
fi
bootJar="$(realpath "''${bootJars[0]}")"
nestedJar="BOOT-INF/lib/$(basename "$nativeJar")"
mkdir -p "$patchDir/$(dirname "$nestedJar")"
cp "$nativeJar" "$patchDir/$nestedJar"
touch --date=@315532800 "$patchDir/$nestedJar"
chmod u+w "$bootJar"
(cd "$patchDir" && zip -q -X -0 "$bootJar" "$nestedJar")
rm -rf "$patchDir"
'';
in
stdenv.mkDerivation (finalAttrs: {
__structuredAttrs = true;
pname = "stirling-pdf" + lib.optionalString isDesktopVariant "-desktop";
version = "2.10.1";
version = "2.14.2";
src = fetchFromGitHub {
owner = "Stirling-Tools";
repo = "Stirling-PDF";
tag = "v${finalAttrs.version}";
hash = "sha256-Qod8x8aB6qDxbRTE5rWUoqVka5kizfXJAWkKo5lhnFQ=";
hash = "sha256-2u4d9K4OEuOw9qE4YgpGXDvVLExVGUKAeXYNCySqy1c=";
};
patches = [
# remove timestamp from the header of a generated .properties file
./remove-props-file-timestamp.patch
# upstream probably forgot to commit the lockfile after a bump
./fix-cargo-lock.patch
# tests require network facilities intentionally unavailable in the Nix sandbox
./skip-sandbox-incompatible-tests.patch
];
postPatch = lib.optionalString isDesktopVariant ''
# Nixpkgs does not produce artifacts for Stirling-PDF's upstream updater
# and does not have access to upstream's private signing key.
substituteInPlace frontend/editor/src-tauri/tauri.conf.json \
--replace-fail '"createUpdaterArtifacts": true' '"createUpdaterArtifacts": false'
'';
npmRoot = "frontend";
npmDeps = fetchNpmDeps {
name = "${finalAttrs.pname}-${finalAttrs.version}-npm-deps";
inherit (finalAttrs) src patches;
postPatch = "cd ${finalAttrs.npmRoot}";
hash = "sha256-y+mviHatwhdIGCOKir1nnG/0Zm8oSoLKW345tU9upls=";
hash = "sha256-ujvSzang7n6DJZbNU/lDlG0x1265N5LJ6prkPbBYEic=";
};
cargoRoot = "frontend/src-tauri";
cargoRoot = "frontend/editor/src-tauri";
buildAndTestSubdir = finalAttrs.cargoRoot;
cargoDeps = rustPlatform.fetchCargoVendor {
@@ -75,7 +125,7 @@ stdenv.mkDerivation (finalAttrs: {
patches
cargoRoot
;
hash = "sha256-Tx6twcyFupNOzuXbW8uUulMJFObyPg/i2U0QnvyhIRQ=";
hash = "sha256-YhDFSmx6XK7x5wzQaPslyuaRbiX8W/X8y/Z0fxjbGwk=";
};
mitmCache = gradle.fetchDeps {
@@ -102,6 +152,9 @@ stdenv.mkDerivation (finalAttrs: {
gradle
jre # one of the tests also require that the `java` command is available on the command line
makeBinaryWrapper
pax-utils
unzip
zip
]
++ lib.optionals (buildWithFrontend || isDesktopVariant) [
nodejs
@@ -132,15 +185,18 @@ stdenv.mkDerivation (finalAttrs: {
# this simulates what the desktop:jlink:jar would do
gradle bootJar
install -Dm644 ./app/core/build/libs/stirling-pdf-*.jar -t ./frontend/src-tauri/libs
${patchJpdfium}
install -Dm644 ./app/core/build/libs/stirling-pdf-*.jar -t ./frontend/editor/src-tauri/libs
# creates as minimal jre via jlink
task desktop:jlink:runtime
substituteInPlace frontend/src-tauri/stirling-pdf.desktop \
substituteInPlace frontend/editor/src-tauri/stirling-pdf.desktop \
--replace-fail 'MimeType=application/pdf;' 'MimeType=application/pdf;x-scheme-handler/stirlingpdf;'
'';
postBuild = lib.optionalString (!isDesktopVariant) patchJpdfium;
# we use the installPhase from cargo-tauri-hook when we're building the desktop variant
installPhase = lib.optionalString (!isDesktopVariant) ''
runHook preInstall
@@ -177,6 +233,7 @@ stdenv.mkDerivation (finalAttrs: {
sourceProvenance = with lib.sourceTypes; [
fromSource
binaryBytecode # java deps
binaryNativeCode # bundled jpdfium inside jar
];
};
})

View File

@@ -0,0 +1,26 @@
diff --git a/app/core/src/test/java/stirling/software/SPDF/controller/api/misc/ConfigControllerTest.java b/app/core/src/test/java/stirling/software/SPDF/controller/api/misc/ConfigControllerTest.java
index 2ed6bb29f..8c48c1da2 100644
--- a/app/core/src/test/java/stirling/software/SPDF/controller/api/misc/ConfigControllerTest.java
+++ b/app/core/src/test/java/stirling/software/SPDF/controller/api/misc/ConfigControllerTest.java
@@ -230,4 +230,5 @@ class ConfigControllerTest {
@Test
+ @org.junit.jupiter.api.Disabled("requires a non-loopback network interface")
void resolveFrontendUrl_fallsThroughOnLoopbackHost() {
System sys = mock(System.class);
when(applicationProperties.getSystem()).thenReturn(sys);
@@ -251,4 +252,5 @@ class ConfigControllerTest {
@Test
+ @org.junit.jupiter.api.Disabled("requires a non-loopback network interface")
void resolveFrontendUrl_usesActualPortWhenServerPortIsEphemeral() {
System sys = mock(System.class);
when(applicationProperties.getSystem()).thenReturn(sys);
diff --git a/app/proprietary/src/test/java/stirling/software/proprietary/cluster/s3/S3ClientsTest.java b/app/proprietary/src/test/java/stirling/software/proprietary/cluster/s3/S3ClientsTest.java
index 8f57e15bc..143155191 100644
--- a/app/proprietary/src/test/java/stirling/software/proprietary/cluster/s3/S3ClientsTest.java
+++ b/app/proprietary/src/test/java/stirling/software/proprietary/cluster/s3/S3ClientsTest.java
@@ -16,4 +16,5 @@ class S3ClientsTest {
@Test
+ @org.junit.jupiter.api.Disabled("requires DNS access")
void validateEndpointHost_publicAwsHost_passes() {
assertThatCode(
() ->

View File

@@ -17,13 +17,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "switchfin";
version = "0.9.2";
version = "0.9.3";
src = fetchFromGitHub {
owner = "dragonflylee";
repo = "switchfin";
rev = finalAttrs.version;
hash = "sha256-FSpzZSd4Yc/PoDv7DyZr2dNsXjl9mHChK+TKHKCbYBI=";
hash = "sha256-khfcFRRccWPYvxETgQC52BlLySKnhgSUdF4hv/8znEM=";
fetchSubmodules = true;
};

View File

@@ -6,19 +6,20 @@
qt6Packages,
borgbackup,
versionCheckHook,
nix-update-script,
makeFontsConf,
}:
python3Packages.buildPythonApplication (finalAttrs: {
pname = "vorta";
version = "0.11.0";
version = "0.11.5";
pyproject = true;
src = fetchFromGitHub {
owner = "borgbase";
repo = "vorta";
tag = "v${finalAttrs.version}";
hash = "sha256-/60KVJGKNz3aouv5jzubFlz+AxPEbRDSv4ZO9MEi3V0=";
hash = "sha256-6WY1UAB5Vr+5Az6UYq2DwXwjabcQr7A3QAEQ2/aIzfg=";
};
nativeBuildInputs = [
@@ -94,12 +95,17 @@ python3Packages.buildPythonApplication (finalAttrs: {
"tests/network_manager/test_darwin.py"
];
passthru.updateScript = nix-update-script { };
meta = {
changelog = "https://github.com/borgbase/vorta/releases/tag/v${finalAttrs.version}";
description = "Desktop Backup Client for Borg";
homepage = "https://vorta.borgbase.com/";
license = lib.licenses.gpl3Only;
maintainers = with lib.maintainers; [ ma27 ];
maintainers = with lib.maintainers; [
ma27
stephsi
];
platforms = lib.platforms.linux;
mainProgram = "vorta";
};

View File

@@ -9,16 +9,16 @@
buildGoModule (finalAttrs: {
pname = "wakatime-cli";
version = "2.22.2";
version = "2.23.0";
src = fetchFromGitHub {
owner = "wakatime";
repo = "wakatime-cli";
tag = "v${finalAttrs.version}";
hash = "sha256-9OeWTjWoda8Hbiaej+UuNSvWtgEEK2MKy3PUqguyZ0U=";
hash = "sha256-AGlcBeurQajel+RmhEgwXm7eSClrcPMoEpHgW+lZJ8E=";
};
vendorHash = "sha256-xrIvtUfOFOgcKJ+2VgUgOzF2Cwp3NPBf39yXgAHN/cQ=";
vendorHash = "sha256-XUvCcQMgFbtBLOB6DkD445SFDQ9rOdDFK8Lkd8d72ig=";
ldflags = [
"-s"

View File

@@ -27,6 +27,10 @@ buildPythonPackage rec {
hash = "sha256-/2qoXZ2f3un2cgJFAGMnQWBraJ7urkb0kHtcKKJsh6w=";
};
postPatch = ''
echo '__version__ = "${version}"' > psqlextra/_version.py
'';
build-system = [ setuptools ];
dependencies = [

View File

@@ -13,14 +13,14 @@
buildPythonPackage (finalAttrs: {
pname = "genai-prices";
version = "0.0.71";
version = "0.1.0";
pyproject = true;
src = fetchFromGitHub {
owner = "pydantic";
repo = "genai-prices";
tag = "v${finalAttrs.version}";
hash = "sha256-IFBdpXJ0AE3UNNqUlOrYMIgRGeB87BYbNqb4GvtJkl0=";
hash = "sha256-mljmeZ9Xga0E4NM4FVz5lHNE1th45lrFzqAA6nCqPmw=";
};
sourceRoot = "${finalAttrs.src.name}/packages/python";

View File

@@ -0,0 +1,67 @@
{
lib,
buildPythonPackage,
fetchFromGitHub,
setuptools,
setuptools-scm,
jaraco-text,
packaging,
platformdirs,
jaraco-envs,
jaraco-path,
pytestCheckHook,
writableTmpDirAsHomeHook,
}:
buildPythonPackage rec {
pname = "standard-pkg-resources";
version = "1.0.0";
pyproject = true;
src = fetchFromGitHub {
owner = "stephenfin";
repo = "standard-pkg_resources";
tag = "v${version}";
hash = "sha256-MdibVeBssPa/kiNAw7f4jTl4Y6JKFnDLshvrc/cFWXw=";
};
# This filter references the coverage module directly; drop it instead of pulling in coverage/pytest-cov as a dependency.
postPatch = ''
substituteInPlace pytest.ini \
--replace-fail " ignore:Couldn't import C tracer:coverage.exceptions.CoverageWarning" ""
'';
build-system = [
setuptools
setuptools-scm
];
dependencies = [
jaraco-text
packaging
platformdirs
];
nativeCheckInputs = [
jaraco-envs
jaraco-path
pytestCheckHook
writableTmpDirAsHomeHook
];
disabledTests = [
# Fails against current setuptools_scm: it warns when a distribution's version is already set before it tries to infer one, which this test doesn't expect.
"test_version_resolved_from_egg_info"
# Requires internet access, unavailable in the Nix build sandbox.
"test_interop_pkg_resources_iter_entry_points"
];
pythonImportsCheck = [ "pkg_resources" ];
meta = {
description = "Standalone redistribution of pkg_resources, extracted from setuptools";
homepage = "https://github.com/stephenfin/standard-pkg_resources";
license = lib.licenses.mit;
maintainers = with lib.maintainers; [ a-peirogon ];
};
}

View File

@@ -3,7 +3,7 @@
lib,
buildPythonPackage,
fetchPypi,
hatchling,
flit-core,
pytestCheckHook,
pytest-random-order,
# dependencies
@@ -30,15 +30,15 @@
buildPythonPackage rec {
pname = "trezor";
version = "0.20.0";
version = "0.20.2";
pyproject = true;
src = fetchPypi {
inherit pname version;
hash = "sha256-TAmOIDFbJxZnOr3vQCgi5xiRAVmMfAPyN0ndIBDuJQQ=";
hash = "sha256-CrPOu0T+y1Mrd9WitAG1AYeh1wtyUabMLfVJTlL/31c=";
};
build-system = [ hatchling ];
build-system = [ flit-core ];
dependencies = [
click

View File

@@ -1,87 +1,26 @@
diff --git a/external/CppMicroServices/CMakeLists.txt b/external/CppMicroServices/CMakeLists.txt
index 8d0aff3..44d45d9 100644
--- a/external/CppMicroServices/CMakeLists.txt
+++ b/external/CppMicroServices/CMakeLists.txt
@@ -1,7 +1,7 @@
# Extract the current version from the VERSION file
file(STRINGS VERSION _version LIMIT_COUNT 1)
-set(US_CMAKE_MINIMUM_REQUIRED_VERSION 3.2)
+set(US_CMAKE_MINIMUM_REQUIRED_VERSION 3.10)
cmake_minimum_required(VERSION ${US_CMAKE_MINIMUM_REQUIRED_VERSION})
diff --git a/external/CppMicroServices/framework/include/cppmicroservices/AnyMap.h b/external/CppMicroServices/framework/include/cppmicroservices/AnyMap.h
index 3f240f4..e8acef9 100644
index 3f240f4..e9d5880 100644
--- a/external/CppMicroServices/framework/include/cppmicroservices/AnyMap.h
+++ b/external/CppMicroServices/framework/include/cppmicroservices/AnyMap.h
@@ -25,6 +25,7 @@
@@ -25,6 +25,8 @@
#include "cppmicroservices/Any.h"
+#include <cstdint>
+
#include <string>
#include <unordered_map>
diff --git a/external/CppMicroServices/framework/include/cppmicroservices/BundleEvent.h b/external/CppMicroServices/framework/include/cppmicroservices/BundleEvent.h
index 9b36a9b..12894fa 100644
--- a/external/CppMicroServices/framework/include/cppmicroservices/BundleEvent.h
+++ b/external/CppMicroServices/framework/include/cppmicroservices/BundleEvent.h
@@ -25,6 +25,7 @@
#include "cppmicroservices/FrameworkExport.h"
+#include <cstdint>
#include <iostream>
#include <memory>
diff --git a/external/CppMicroServices/framework/include/cppmicroservices/Constants.h b/external/CppMicroServices/framework/include/cppmicroservices/Constants.h
index 590a890..cf60926 100644
--- a/external/CppMicroServices/framework/include/cppmicroservices/Constants.h
+++ b/external/CppMicroServices/framework/include/cppmicroservices/Constants.h
@@ -25,6 +25,7 @@
#include "cppmicroservices/FrameworkConfig.h"
+#include <cstdint>
#include <string>
namespace cppmicroservices {
diff --git a/external/CppMicroServices/framework/include/cppmicroservices/FrameworkEvent.h b/external/CppMicroServices/framework/include/cppmicroservices/FrameworkEvent.h
index 71caf1b..a29e87c 100644
--- a/external/CppMicroServices/framework/include/cppmicroservices/FrameworkEvent.h
+++ b/external/CppMicroServices/framework/include/cppmicroservices/FrameworkEvent.h
@@ -25,6 +25,7 @@
#include "cppmicroservices/FrameworkExport.h"
+#include <cstdint>
#include <iostream>
#include <memory>
diff --git a/external/CppMicroServices/framework/include/cppmicroservices/ServiceEvent.h b/external/CppMicroServices/framework/include/cppmicroservices/ServiceEvent.h
index 451cb82..da7c5f0 100644
--- a/external/CppMicroServices/framework/include/cppmicroservices/ServiceEvent.h
+++ b/external/CppMicroServices/framework/include/cppmicroservices/ServiceEvent.h
@@ -25,6 +25,8 @@
#include "cppmicroservices/ServiceReference.h"
+#include <cstdint>
+
US_MSVC_PUSH_DISABLE_WARNING(
4251) // 'identifier' : class 'type' needs to have dll-interface to be used by clients of class 'type2'
diff --git a/psw/ae/aesm_service/source/CMakeLists.txt b/psw/ae/aesm_service/source/CMakeLists.txt
index 5728e9b..0169263 100644
--- a/psw/ae/aesm_service/source/CMakeLists.txt
+++ b/psw/ae/aesm_service/source/CMakeLists.txt
@@ -30,7 +30,7 @@
#
# [proj-begin]
-cmake_minimum_required(VERSION 3.0.0)
+cmake_minimum_required(VERSION 3.10.0)
project(ModularAESM VERSION 0.1.0)

View File

@@ -17,18 +17,18 @@
which,
debug ? false,
}:
stdenv.mkDerivation rec {
stdenv.mkDerivation (finalAttrs: {
pname = "sgx-psw";
# Version as given in se_version.h
version = "2.27.100.1";
version = "2.29.100.1";
# Version as used in the Git tag
versionTag = "2.27";
versionTag = "2.29";
src = fetchFromGitHub {
owner = "intel";
repo = "linux-sgx";
rev = "sgx_${versionTag}";
hash = "sha256-hNmh4IgNJDNqt2xF8zBnD/x+saMyMk5hZLA3aOqzqEA=";
repo = "confidential-computing.sgx";
rev = "sgx_${finalAttrs.versionTag}";
hash = "sha256-gi4aNXHMHuPmc36JalALAXjIdn4COuXOZzC6dQRB6nU=";
fetchSubmodules = true;
};
@@ -39,37 +39,38 @@ stdenv.mkDerivation rec {
# run user application enclaves, verify launch policies, produce remote
# attestation quotes, and do platform certification.
ae.prebuilt = fetchurl {
url = "https://download.01.org/intel-sgx/sgx-linux/${versionTag}/prebuilt_ae_${versionTag}.tar.gz";
url = "https://download.01.org/intel-sgx/sgx-linux/${finalAttrs.versionTag}/prebuilt_ae_${finalAttrs.versionTag}.tar.gz";
hash = "sha256-Hlh96rYOyml2y50d8ASKz6U97Fl0hbGYECeZiG9nMSQ=";
};
# Pre-built ipp-crypto with mitigations.
optlib.prebuilt = fetchurl {
url = "https://download.01.org/intel-sgx/sgx-linux/${versionTag}/optimized_libs_${versionTag}.tar.gz";
url = "https://download.01.org/intel-sgx/sgx-linux/${finalAttrs.versionTag}/optimized_libs_${finalAttrs.versionTag}.tar.gz";
hash = "sha256-7mDTaLtpOQLHQ6Fv+FWJ2k/veJZPXIcuj7kOdRtRqhg=";
};
# Fetch the Data Center Attestation Primitives (DCAP) platform enclaves
# and pre-built sgxssl.
dcap = rec {
version = "1.24";
version = "1.26";
filename = "prebuilt_dcap_${version}.tar.gz";
prebuilt = fetchurl {
url = "https://download.01.org/intel-sgx/sgx-dcap/${version}/linux/${filename}";
hash = "sha256-sc/eYIPdhwAyDk2Zh1HU6yuFlobqVy/4++m5OnQE3Bc=";
hash = "sha256-TXQ8xh0q9RKPyKqjMvxoQtIH2lxbhCiwpV+HvQxACaw=";
};
};
in
''
# Make sure this is the right version of linux-sgx
grep -q '"${version}"' "$src/common/inc/internal/se_version.h" \
|| (echo "Could not find expected version ${version} in linux-sgx source" >&2 && exit 1)
grep -q '"${finalAttrs.version}"' "$src/common/inc/internal/se_version.h" \
|| (echo "Could not find expected version ${finalAttrs.version} in linux-sgx source" >&2 && exit 1)
tar -xzvf ${ae.prebuilt} -C $sourceRoot/
tar -xzvf ${optlib.prebuilt} -C $sourceRoot/
# Make sure we use the correct version of prebuilt DCAP
grep -q 'ae_file_name=${dcap.filename}' "$src/external/dcap_source/QuoteGeneration/download_prebuilt.sh" \
grep -qE '(dcap_version=${dcap.version}|ae_file_name=${dcap.filename})' \
"$src/external/dcap_source/QuoteGeneration/download_prebuilt.sh" \
|| (echo "Could not find expected prebuilt DCAP ${dcap.filename} in linux-sgx source" >&2 && exit 1)
tar -xzvf ${dcap.prebuilt} -C $sourceRoot/external/dcap_source prebuilt/
@@ -91,11 +92,7 @@ stdenv.mkDerivation rec {
# build because the embedded zip file contents have different modified times.
./cppmicroservices-no-mtime.patch
# CppMicroServices is failing to build with CMake 4 and GCC 15
# PR: <https://github.com/intel/confidential-computing.sgx/pull/1098>
# - CMake 4 dropped support for <3.5 and warns on <3.10, so bump the
# `cmake_minimum_required` to 3.10
# - Various header files now need `#include <cstdint>` to compile
# Add `#include <cstdint>` to CppMicroServices headers that GCC 15 needs
./cppmicroservices-compat.patch
];
@@ -270,7 +267,7 @@ stdenv.mkDerivation rec {
meta = {
description = "Intel SGX Architectural Enclave Service Manager";
homepage = "https://github.com/intel/linux-sgx";
homepage = "https://github.com/intel/confidential-computing.sgx";
maintainers = with lib.maintainers; [
phlip9
veehaitch
@@ -279,4 +276,4 @@ stdenv.mkDerivation rec {
platforms = [ "x86_64-linux" ];
license = lib.licenses.bsd3;
};
}
})

View File

@@ -1,27 +1,44 @@
diff --git a/Makefile b/Makefile
index 144f4e4..834c23e 100644
index 597f167..f59bacc 100644
--- a/Makefile
+++ b/Makefile
@@ -50,22 +50,17 @@ tips:
@@ -25,12 +25,10 @@ tips:
preparation:
# As SDK build needs to clone and patch openmp, we cannot support the mode that download the source from github as zip.
# Only enable the download from git
- git submodule update --init --recursive
cd external/dcap_source/external/jwt-cpp && git apply ../0001-Add-a-macro-to-disable-time-support-in-jwt-for-SGX.patch >/dev/null 2>&1 || \
git apply ../0001-Add-a-macro-to-disable-time-support-in-jwt-for-SGX.patch -R --check
cd external/dcap_source/external/wasm-micro-runtime && git apply ../0001-wasm-micro-runtime.patch >/dev/null 2>&1 || \
git apply ../0001-wasm-micro-runtime.patch -R --check
- ./external/dcap_source/QuoteVerification/prepare_sgxssl.sh nobuild
cd external/openmp/openmp_code && git apply ../0001-Enable-OpenMP-in-SGX.patch >/dev/null 2>&1 || git apply ../0001-Enable-OpenMP-in-SGX.patch --check -R
cd external/protobuf/protobuf_code && git apply ../sgx_protobuf.patch >/dev/null 2>&1 || git apply ../sgx_protobuf.patch --check -R
cd external/protobuf/protobuf_code && git apply ../0001-bumped-protobuf-to-1.33.0.patch >/dev/null 2>&1 || git apply ../0001-bumped-protobuf-to-1.33.0.patch --check -R
- cd external/protobuf/protobuf_code && git submodule update --init --recursive && cd third_party/abseil-cpp && git apply ../../../sgx_abseil.patch>/dev/null 2>&1 || git apply ../../../sgx_abseil.patch --check -R
./external/sgx-emm/create_symlink.sh
cd external/cbor && cp -r libcbor sgx_libcbor
cd external/cbor/libcbor && git apply ../raw_cbor.patch >/dev/null 2>&1 || git apply ../raw_cbor.patch --check -R
# TODO refactor to remove duplication with the ./external/protobuf/Makefile.
@@ -38,8 +36,7 @@ preparation:
# If you are adding a new patch over this one, write your patch's name to .sgx_patched
@if ! grep -q "sgx_protobuf" external/protobuf/protobuf_code/.sgx_patched 2>/dev/null; then \
cd external/protobuf/protobuf_code && \
- git apply ../sgx_protobuf.patch >/dev/null 2>&1 || git apply ../sgx_protobuf.patch --check -R && \
- git submodule update --init --recursive; \
+ git apply ../sgx_protobuf.patch >/dev/null 2>&1 || git apply ../sgx_protobuf.patch --check -R; \
fi
# If you are adding a new patch over this one, write your patch's name to .sgx_patched
@if ! grep -q "sgx_abseil" external/protobuf/abseil-cpp/.sgx_patched 2>/dev/null; then \
@@ -52,8 +49,6 @@ preparation:
cd external/cbor/sgx_libcbor && git apply ../sgx_cbor.patch >/dev/null 2>&1 || git apply ../sgx_cbor.patch --check -R
cd external/ippcp_internal/ipp-crypto && git apply ../0001-IPP-crypto-for-SGX.patch > /dev/null 2>&1 || git apply ../0001-IPP-crypto-for-SGX.patch --check -R
cd external/ippcp_internal/ipp-crypto && mkdir -p build
- ./download_prebuilt.sh
- ./external/dcap_source/QuoteGeneration/download_prebuilt.sh
cd external/libcxxrt/libcxxrt_code && git apply ../sgx_libcxxrt.patch >/dev/null 2>&1 || git apply ../sgx_libcxxrt.patch --check -R
psw:
$(MAKE) -C psw/ USE_OPT_LIBS=$(USE_OPT_LIBS)
@@ -87,7 +82,6 @@ servtd_attest_preparation:
# Only enable the download from git
git submodule update --init --recursive external/dcap_source external/sgx-emm/emm_src external/libcxxrt/libcxxrt_code
./external/sgx-emm/create_symlink.sh
- ./external/dcap_source/QuoteVerification/prepare_sgxssl.sh nobuild
cd external/libcxxrt/libcxxrt_code && (git apply ../sgx_libcxxrt.patch >/dev/null 2>&1 || git apply ../sgx_libcxxrt.patch --check -R)
ipp:

View File

@@ -10,13 +10,13 @@
buildHomeAssistantComponent rec {
owner = "kongo09";
domain = "philips_airpurifier_coap";
version = "0.36.2";
version = "0.37";
src = fetchFromGitHub {
inherit owner;
repo = "philips-airpurifier-coap";
rev = "v${version}";
hash = "sha256-aVCfUuwPW+0L+OuOoLV0cPezZVKHtO39p/TK/gy2jdg=";
hash = "sha256-oPdjf6eOkkywFQMavbeBty5E5zb215qIBHWND5zaJBs=";
};
dependencies = [

View File

@@ -6,16 +6,16 @@
buildNpmPackage rec {
pname = "mushroom";
version = "5.2.0";
version = "5.2.1";
src = fetchFromGitHub {
owner = "piitaya";
repo = "lovelace-mushroom";
rev = "v${version}";
hash = "sha256-M6p3nEV+t8nn4epM3qcu/F3cvLwSBIZ1Dh11bNIcsMw=";
hash = "sha256-S3nC6p35xG3Q33/XHlDF/h4qDXlKuoyMEtn0AywP/ag=";
};
npmDepsHash = "sha256-GbU/qI63Ykwt1wnHVUnW1n54mhZsL/V+KxkEysZFGuM=";
npmDepsHash = "sha256-7bVJIo3N7y3v6ck//bHhMwTQRUqEsNqoavfMuZZwE50=";
installPhase = ''
runHook preInstall

View File

@@ -3,31 +3,86 @@
#include <stdlib.h>
#include <assert.h>
#include <stdio.h>
#include <string.h>
#define assert_success(e) do { if ((e) < 0) { perror(#e); abort(); } } while (0)
void set_env_prefix(char *env, char *sep, char *prefix) {
char *existing = getenv(env);
if (existing) {
char *val;
assert_success(asprintf(&val, "%s%s%s", prefix, sep, existing));
assert_success(setenv(env, val, 1));
free(val);
} else {
assert_success(setenv(env, prefix, 1));
int is_surrounded_by_sep(char *env, char *ptr, unsigned long len, char *sep) {
unsigned long sep_len = strlen(sep);
// Check left side (if not at start)
if (env != ptr) {
if (ptr - env < sep_len)
return 0;
if (strncmp(sep, ptr - sep_len, sep_len) != 0) {
return 0;
}
}
// Check right side (if not at end)
char *end_ptr = ptr + len;
if (*end_ptr != '\0') {
if (strncmp(sep, ptr + len, sep_len) != 0) {
return 0;
}
}
return 1;
}
void set_env_prefix(char *env, char *sep, char *prefix) {
char *existing_env = getenv(env);
if (existing_env) {
char *val;
char *existing_prefix = strstr(existing_env, prefix);
unsigned long prefix_len = strlen(prefix);
// If the prefix already exists, remove the original
if (existing_prefix && is_surrounded_by_sep(existing_env, existing_prefix, prefix_len, sep)) {
if (existing_env == existing_prefix) {
return;
}
unsigned long sep_len = strlen(sep);
int n_before = existing_prefix - existing_env;
assert_success(asprintf(&val, "%s%s%.*s%s", prefix, sep,
n_before, existing_env,
existing_prefix + prefix_len + sep_len));
} else {
assert_success(asprintf(&val, "%s%s%s", prefix, sep, existing_env));
}
assert_success(setenv(env, val, 1));
free(val);
} else {
assert_success(setenv(env, prefix, 1));
}
}
void set_env_suffix(char *env, char *sep, char *suffix) {
char *existing = getenv(env);
if (existing) {
char *val;
assert_success(asprintf(&val, "%s%s%s", existing, sep, suffix));
assert_success(setenv(env, val, 1));
free(val);
char *existing_env = getenv(env);
if (existing_env) {
char *val;
char *existing_suffix = strstr(existing_env, suffix);
unsigned long suffix_len = strlen(suffix);
// If the suffix already exists, remove the original
if (existing_suffix && is_surrounded_by_sep(existing_env, existing_suffix, suffix_len, sep)) {
char *end_ptr = existing_suffix + suffix_len;
if (*end_ptr == '\0') {
return;
}
unsigned long sep_len = strlen(sep);
int n_before = existing_suffix - existing_env;
assert_success(asprintf(&val, "%.*s%s%s%s",
n_before, existing_env,
existing_suffix + suffix_len + sep_len,
sep, suffix));
} else {
assert_success(setenv(env, suffix, 1));
assert_success(asprintf(&val, "%s%s%s", existing_env, sep, suffix));
}
assert_success(setenv(env, val, 1));
free(val);
} else {
assert_success(setenv(env, suffix, 1));
}
}
int main(int argc, char **argv) {

View File

@@ -3,19 +3,57 @@
#include <stdlib.h>
#include <assert.h>
#include <stdio.h>
#include <string.h>
#define assert_success(e) do { if ((e) < 0) { perror(#e); abort(); } } while (0)
void set_env_prefix(char *env, char *sep, char *prefix) {
char *existing = getenv(env);
if (existing) {
char *val;
assert_success(asprintf(&val, "%s%s%s", prefix, sep, existing));
assert_success(setenv(env, val, 1));
free(val);
} else {
assert_success(setenv(env, prefix, 1));
int is_surrounded_by_sep(char *env, char *ptr, unsigned long len, char *sep) {
unsigned long sep_len = strlen(sep);
// Check left side (if not at start)
if (env != ptr) {
if (ptr - env < sep_len)
return 0;
if (strncmp(sep, ptr - sep_len, sep_len) != 0) {
return 0;
}
}
// Check right side (if not at end)
char *end_ptr = ptr + len;
if (*end_ptr != '\0') {
if (strncmp(sep, ptr + len, sep_len) != 0) {
return 0;
}
}
return 1;
}
void set_env_prefix(char *env, char *sep, char *prefix) {
char *existing_env = getenv(env);
if (existing_env) {
char *val;
char *existing_prefix = strstr(existing_env, prefix);
unsigned long prefix_len = strlen(prefix);
// If the prefix already exists, remove the original
if (existing_prefix && is_surrounded_by_sep(existing_env, existing_prefix, prefix_len, sep)) {
if (existing_env == existing_prefix) {
return;
}
unsigned long sep_len = strlen(sep);
int n_before = existing_prefix - existing_env;
assert_success(asprintf(&val, "%s%s%.*s%s", prefix, sep,
n_before, existing_env,
existing_prefix + prefix_len + sep_len));
} else {
assert_success(asprintf(&val, "%s%s%s", prefix, sep, existing_env));
}
assert_success(setenv(env, val, 1));
free(val);
} else {
assert_success(setenv(env, prefix, 1));
}
}
int main(int argc, char **argv) {

View File

@@ -3,19 +3,57 @@
#include <stdlib.h>
#include <assert.h>
#include <stdio.h>
#include <string.h>
#define assert_success(e) do { if ((e) < 0) { perror(#e); abort(); } } while (0)
void set_env_prefix(char *env, char *sep, char *prefix) {
char *existing = getenv(env);
if (existing) {
char *val;
assert_success(asprintf(&val, "%s%s%s", prefix, sep, existing));
assert_success(setenv(env, val, 1));
free(val);
} else {
assert_success(setenv(env, prefix, 1));
int is_surrounded_by_sep(char *env, char *ptr, unsigned long len, char *sep) {
unsigned long sep_len = strlen(sep);
// Check left side (if not at start)
if (env != ptr) {
if (ptr - env < sep_len)
return 0;
if (strncmp(sep, ptr - sep_len, sep_len) != 0) {
return 0;
}
}
// Check right side (if not at end)
char *end_ptr = ptr + len;
if (*end_ptr != '\0') {
if (strncmp(sep, ptr + len, sep_len) != 0) {
return 0;
}
}
return 1;
}
void set_env_prefix(char *env, char *sep, char *prefix) {
char *existing_env = getenv(env);
if (existing_env) {
char *val;
char *existing_prefix = strstr(existing_env, prefix);
unsigned long prefix_len = strlen(prefix);
// If the prefix already exists, remove the original
if (existing_prefix && is_surrounded_by_sep(existing_env, existing_prefix, prefix_len, sep)) {
if (existing_env == existing_prefix) {
return;
}
unsigned long sep_len = strlen(sep);
int n_before = existing_prefix - existing_env;
assert_success(asprintf(&val, "%s%s%.*s%s", prefix, sep,
n_before, existing_env,
existing_prefix + prefix_len + sep_len));
} else {
assert_success(asprintf(&val, "%s%s%s", prefix, sep, existing_env));
}
assert_success(setenv(env, val, 1));
free(val);
} else {
assert_success(setenv(env, prefix, 1));
}
}
int main(int argc, char **argv) {

View File

@@ -3,19 +3,59 @@
#include <stdlib.h>
#include <assert.h>
#include <stdio.h>
#include <string.h>
#define assert_success(e) do { if ((e) < 0) { perror(#e); abort(); } } while (0)
void set_env_suffix(char *env, char *sep, char *suffix) {
char *existing = getenv(env);
if (existing) {
char *val;
assert_success(asprintf(&val, "%s%s%s", existing, sep, suffix));
assert_success(setenv(env, val, 1));
free(val);
} else {
assert_success(setenv(env, suffix, 1));
int is_surrounded_by_sep(char *env, char *ptr, unsigned long len, char *sep) {
unsigned long sep_len = strlen(sep);
// Check left side (if not at start)
if (env != ptr) {
if (ptr - env < sep_len)
return 0;
if (strncmp(sep, ptr - sep_len, sep_len) != 0) {
return 0;
}
}
// Check right side (if not at end)
char *end_ptr = ptr + len;
if (*end_ptr != '\0') {
if (strncmp(sep, ptr + len, sep_len) != 0) {
return 0;
}
}
return 1;
}
void set_env_suffix(char *env, char *sep, char *suffix) {
char *existing_env = getenv(env);
if (existing_env) {
char *val;
char *existing_suffix = strstr(existing_env, suffix);
unsigned long suffix_len = strlen(suffix);
// If the suffix already exists, remove the original
if (existing_suffix && is_surrounded_by_sep(existing_env, existing_suffix, suffix_len, sep)) {
char *end_ptr = existing_suffix + suffix_len;
if (*end_ptr == '\0') {
return;
}
unsigned long sep_len = strlen(sep);
int n_before = existing_suffix - existing_env;
assert_success(asprintf(&val, "%.*s%s%s%s",
n_before, existing_env,
existing_suffix + suffix_len + sep_len,
sep, suffix));
} else {
assert_success(asprintf(&val, "%s%s%s", existing_env, sep, suffix));
}
assert_success(setenv(env, val, 1));
free(val);
} else {
assert_success(setenv(env, suffix, 1));
}
}
int main(int argc, char **argv) {

View File

@@ -1080,6 +1080,12 @@ with pkgs;
forgejo-lts = callPackage ../by-name/fo/forgejo/lts.nix { };
gerrit_3_12 = callPackage ../by-name/ge/gerrit/3_12.nix { };
gerrit_3_13 = callPackage ../by-name/ge/gerrit/3_13.nix { };
gerrit_3_14 = callPackage ../by-name/ge/gerrit/3_14.nix { };
github-cli = gh;
git-credential-aol = callPackage ../by-name/gi/git-credential-email/git-credential-aol { };

View File

@@ -19474,6 +19474,8 @@ self: super: with self; {
standard-pipes =
if pythonAtLeast "3.13" then callPackage ../development/python-modules/standard-pipes { } else null;
standard-pkg-resources = callPackage ../development/python-modules/standard-pkg-resources { };
standard-sndhdr =
if pythonAtLeast "3.13" then
callPackage ../development/python-modules/standard-sndhdr { }