From c9821d8e128ab7433a95e779afd6f06ef1a84f33 Mon Sep 17 00:00:00 2001 From: Marcin Serwin Date: Sun, 15 Feb 2026 20:35:40 +0100 Subject: [PATCH 001/134] libmodplug: use the configured includedir in pc file This should make no difference at the moment because pc file is patched in the fixup phase by the global hook which I'm intending to remove. Signed-off-by: Marcin Serwin --- pkgs/by-name/li/libmodplug/package.nix | 13 +++++++++---- 1 file changed, 9 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/li/libmodplug/package.nix b/pkgs/by-name/li/libmodplug/package.nix index f8ee283758bc..5c7a2279dc99 100644 --- a/pkgs/by-name/li/libmodplug/package.nix +++ b/pkgs/by-name/li/libmodplug/package.nix @@ -14,10 +14,15 @@ stdenv.mkDerivation (finalAttrs: { sha256 = "1pnri98a603xk47smnxr551svbmgbzcw018mq1k6srbrq6kaaz25"; }; - # Unfortunately, upstream appears inactive and the patches from the fork don’t apply cleanly. - # Modify `src/fastmix.cpp` to remove usage of the register storage class, which is - # not allowed in C++17 and is an error in clang 16. - prePatch = "substituteInPlace src/fastmix.cpp --replace 'register ' ''"; + postPatch = '' + # Unfortunately, upstream appears inactive and the patches from the fork don’t apply cleanly. + # Modify `src/fastmix.cpp` to remove usage of the register storage class, which is + # not allowed in C++17 and is an error in clang 16. + substituteInPlace src/fastmix.cpp --replace-fail 'register ' "" + + substituteInPlace libmodplug.pc.in \ + --replace-fail 'includedir=''${prefix}/include' 'includedir=@includedir@' + ''; outputs = [ "out" From b2b912fd5279a2b91affb6cfa5760e360ffc252b Mon Sep 17 00:00:00 2001 From: Aaron Andersen Date: Fri, 5 Jun 2026 16:32:32 -0400 Subject: [PATCH 002/134] polkit: replace systemdMinimal dependency with systemdLibs --- pkgs/by-name/po/polkit/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/po/polkit/package.nix b/pkgs/by-name/po/polkit/package.nix index 31231f32d736..723f80bcdc74 100644 --- a/pkgs/by-name/po/polkit/package.nix +++ b/pkgs/by-name/po/polkit/package.nix @@ -22,8 +22,8 @@ docbook_xml_dtd_412, gtk-doc, coreutils, - useSystemd ? lib.meta.availableOn stdenv.hostPlatform systemdMinimal, - systemdMinimal, + useSystemd ? lib.meta.availableOn stdenv.hostPlatform systemdLibs, + systemdLibs, elogind, buildPackages, withIntrospection ? @@ -97,7 +97,7 @@ stdenv.mkDerivation rec { ] ++ lib.optionals stdenv.hostPlatform.isLinux [ # On Linux, fall back to elogind when systemd support is off. - (if useSystemd then systemdMinimal else elogind) + (if useSystemd then systemdLibs else elogind) ]; propagatedBuildInputs = [ From 4b7c9730a83a36bd4ab0991f31d2304bc30c031a Mon Sep 17 00:00:00 2001 From: Alyssa Ross Date: Mon, 15 Jun 2026 18:17:42 +0200 Subject: [PATCH 003/134] gssdp_1_6: remove unused Python input MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit This doesn't seem to have done anything since it was introduced. I checked the original source tarball. Fixes: b30e56bddfc2 ("gssdp: 1.2.3 → 1.4.0.1") --- pkgs/by-name/gs/gssdp_1_6/package.nix | 1 - 1 file changed, 1 deletion(-) diff --git a/pkgs/by-name/gs/gssdp_1_6/package.nix b/pkgs/by-name/gs/gssdp_1_6/package.nix index b4d8daba12c1..e895dbe049d0 100644 --- a/pkgs/by-name/gs/gssdp_1_6/package.nix +++ b/pkgs/by-name/gs/gssdp_1_6/package.nix @@ -41,7 +41,6 @@ stdenv.mkDerivation (finalAttrs: { gobject-introspection vala gi-docgen - python3 ]; buildInputs = [ From 2d8e6e2b5097496aa2f2e380ce71716872e9f97b Mon Sep 17 00:00:00 2001 From: Alyssa Ross Date: Mon, 15 Jun 2026 18:21:10 +0200 Subject: [PATCH 004/134] gssdp_1_6: disable introspection if unavailable This is essentially just doing the same thing that was already done for the older gssdp, in 2be3d063cf58 ("gssdp: disable introspection if unavailable"). Fixes e.g. cross-compiling from Linux to FreeBSD, where we can't have gobject-introspection due to the lack of a user-mode emulator. --- pkgs/by-name/gs/gssdp_1_6/package.nix | 14 ++++++++++++-- 1 file changed, 12 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/gs/gssdp_1_6/package.nix b/pkgs/by-name/gs/gssdp_1_6/package.nix index b4d8daba12c1..069b3b8b6b20 100644 --- a/pkgs/by-name/gs/gssdp_1_6/package.nix +++ b/pkgs/by-name/gs/gssdp_1_6/package.nix @@ -13,6 +13,10 @@ glib, gnome, gssdp-tools, + withIntrospection ? + lib.meta.availableOn stdenv.hostPlatform gobject-introspection + && stdenv.hostPlatform.emulatorAvailable buildPackages, + buildPackages, }: stdenv.mkDerivation (finalAttrs: { @@ -22,6 +26,8 @@ stdenv.mkDerivation (finalAttrs: { outputs = [ "out" "dev" + ] + ++ lib.optionals withIntrospection [ "devdoc" ]; @@ -38,6 +44,9 @@ stdenv.mkDerivation (finalAttrs: { meson ninja pkg-config + glib + ] + ++ lib.optionals withIntrospection [ gobject-introspection vala gi-docgen @@ -53,16 +62,17 @@ stdenv.mkDerivation (finalAttrs: { ]; mesonFlags = [ - "-Dgtk_doc=true" "-Dsniffer=false" # This packages only has manpages for gssdp-device-sniffer, which we disabled above. "-Dmanpages=false" + (lib.mesonBool "gtk_doc" withIntrospection) + (lib.mesonBool "introspection" withIntrospection) ]; # On Darwin: Failed to bind socket, Operation not permitted doCheck = !stdenv.hostPlatform.isDarwin; - postFixup = '' + postFixup = lib.optionalString withIntrospection '' # Move developer documentation to devdoc output. # Cannot be in postInstall, otherwise _multioutDocs hook in preFixup will move right back. find -L "$out/share/doc" -type f -regex '.*\.devhelp2?' -print0 \ From 1148372a48bfa9f1ca0519d652276b2c59d2064a Mon Sep 17 00:00:00 2001 From: Marian Hammer Date: Tue, 23 Jun 2026 13:03:53 +0200 Subject: [PATCH 005/134] amf-headers: package build speedup use sparseCheckout to only download the needed headers files --- pkgs/by-name/am/amf-headers/package.nix | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/am/amf-headers/package.nix b/pkgs/by-name/am/amf-headers/package.nix index a03ba327914d..b0744966b877 100644 --- a/pkgs/by-name/am/amf-headers/package.nix +++ b/pkgs/by-name/am/amf-headers/package.nix @@ -12,7 +12,8 @@ stdenv.mkDerivation (finalAttrs: { owner = "GPUOpen-LibrariesAndSDKs"; repo = "AMF"; tag = "v${finalAttrs.version}"; - sha256 = "sha256-+jVYm/Zmt+1bzKnKTiClgoMRsyhqpuKZj79DvGHpPTM="; + sha256 = "sha256-ardO9GojOIQUnuSa2fGOCfFHI5PJYBsffCpNCh2dyRw="; + sparseCheckout = [ "amf/public/include" ]; }; installPhase = '' From 7e469caa382f9107aebad147946eeee4ff5062af Mon Sep 17 00:00:00 2001 From: Alexandre Esteves Date: Fri, 27 Feb 2026 08:27:25 +0000 Subject: [PATCH 006/134] darwin.adv_cmds: fix build with llvm 22 --- pkgs/os-specific/darwin/by-name/ad/adv_cmds/package.nix | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/darwin/by-name/ad/adv_cmds/package.nix b/pkgs/os-specific/darwin/by-name/ad/adv_cmds/package.nix index 3f0e13b38f2a..6ea659f142aa 100644 --- a/pkgs/os-specific/darwin/by-name/ad/adv_cmds/package.nix +++ b/pkgs/os-specific/darwin/by-name/ad/adv_cmds/package.nix @@ -74,8 +74,10 @@ mkAppleDerivation { --replace-fail '/usr/local' "$out" done ''; - - env.NIX_CFLAGS_COMPILE = "-I${privateHeaders}/include"; + env.NIX_CFLAGS_COMPILE = lib.join " " [ + "-I${privateHeaders}/include" + "-Wno-error=incompatible-pointer-types" + ]; buildInputs = [ libxo From 29d41a5e41eaeba9ae47b44ab5b7a84aff411841 Mon Sep 17 00:00:00 2001 From: Alexandre Esteves Date: Fri, 27 Feb 2026 08:26:38 +0000 Subject: [PATCH 007/134] dbus: fix build with llvm 22 --- pkgs/by-name/db/dbus/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/db/dbus/package.nix b/pkgs/by-name/db/dbus/package.nix index 264f6d944497..2e1f36b7831e 100644 --- a/pkgs/by-name/db/dbus/package.nix +++ b/pkgs/by-name/db/dbus/package.nix @@ -127,6 +127,7 @@ stdenv.mkDerivation (finalAttrs: { (lib.mesonEnable "launchd" stdenv.hostPlatform.isDarwin) (lib.mesonEnable "systemd" enableSystemd) "-Dselinux=disabled" + "-Dc_args=-Wno-error=incompatible-pointer-types" ] ++ lib.optionals stdenv.hostPlatform.isDarwin [ # D-Bus defaults to launchd-activation on Darwin, but that requires the launch agent be installed. It also breaks From e48514a021aac2255767c189ee4a4afbed0998a1 Mon Sep 17 00:00:00 2001 From: Alexandre Esteves Date: Fri, 27 Feb 2026 08:27:05 +0000 Subject: [PATCH 008/134] fontforge: fix build with llvm 22 --- pkgs/by-name/fo/fontforge/package.nix | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/fo/fontforge/package.nix b/pkgs/by-name/fo/fontforge/package.nix index 4cdcfacbb326..8197a82a0c25 100644 --- a/pkgs/by-name/fo/fontforge/package.nix +++ b/pkgs/by-name/fo/fontforge/package.nix @@ -82,7 +82,12 @@ stdenv.mkDerivation (finalAttrs: { ''; # do not use x87's 80-bit arithmetic, rounding errors result in very different font binaries - env.NIX_CFLAGS_COMPILE = lib.optionalString stdenv.hostPlatform.isi686 "-msse2 -mfpmath=sse"; + env.NIX_CFLAGS_COMPILE = lib.join " " ( + [ + "-Wno-error=incompatible-pointer-types" + ] + ++ lib.optional stdenv.hostPlatform.isi686 "-msse2 -mfpmath=sse" + ); strictDeps = true; From 1b539713f395098dcf597451cca1d779e32e7642 Mon Sep 17 00:00:00 2001 From: Alexandre Esteves Date: Fri, 27 Feb 2026 08:27:37 +0000 Subject: [PATCH 009/134] gbenchmark: fix build with llvm 22 --- pkgs/by-name/gb/gbenchmark/package.nix | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/gb/gbenchmark/package.nix b/pkgs/by-name/gb/gbenchmark/package.nix index a35f4781dba1..0c9e020871ed 100644 --- a/pkgs/by-name/gb/gbenchmark/package.nix +++ b/pkgs/by-name/gb/gbenchmark/package.nix @@ -52,7 +52,12 @@ stdenv.mkDerivation (finalAttrs: { # # This might be a problem with our Clang, as it does not reproduce # with Xcode, but we just work around it by silencing the warning. - NIX_CFLAGS_COMPILE = lib.optionalString stdenv.cc.isClang "-Wno-c++17-attribute-extensions"; + NIX_CFLAGS_COMPILE = lib.join " " ( + [ + "-Wno-error=c2y-extensions" + ] + ++ lib.optional stdenv.cc.isClang "-Wno-c++17-attribute-extensions" + ); } // lib.optionalAttrs stdenv.hostPlatform.isGnu { # For test:locale_impermeability_test From e6e7dc5e320073efd25558209e060a395523d7a4 Mon Sep 17 00:00:00 2001 From: whispers Date: Fri, 3 Jul 2026 00:17:21 -0400 Subject: [PATCH 010/134] protobufc: unpin standard version to fix build with gcc 16 protobufc pins a specific version of the C++ standard and does so using an ancient vendored macro from the autoconf archive. this causes a failure to build on gcc 16, as it defaults to C++20 and protobufc uses C++17. this particularly causes problems with abseil, which has headers which depend on the C++ standard to compile. accordingly, to avoid having to manually specify and update a version each time the default standard version updates, we unpin it completely and allow the compiler to choose what it uses by default. alternatively, we could override the abseil that ends up in protobufc by way of protobuf_33 to use the C++17 standard instead. this would work, but this seems more fragile and subject to compiler version churn. it is also our understanding that mixing and matching versions of standards in dependents can be messy, and using the default seems the least likely to cause problems. --- pkgs/by-name/pr/protobufc/package.nix | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/pkgs/by-name/pr/protobufc/package.nix b/pkgs/by-name/pr/protobufc/package.nix index c71242bd98dd..8e3537d9a224 100644 --- a/pkgs/by-name/pr/protobufc/package.nix +++ b/pkgs/by-name/pr/protobufc/package.nix @@ -36,6 +36,21 @@ stdenv.mkDerivation (finalAttrs: { zlib ]; + # The upstream macro is vendored from a very old autoconf archive: + # https://github.com/protobuf-c/protobuf-c/commit/42612b4ba4b11d48b76e3643fa6d42f617e661b6 + # and the build system appears to arbitrarily require C++17 specifically: + # https://github.com/protobuf-c/protobuf-c/blob/4719fdd7760624388c2c5b9d6759eb6a47490626/configure.ac#L72 + # However, the default standard version used by GCC continues to increase + # (e.g. C++20 for GCC 16), and so protobuf-c's dependencies do as well. In + # particular, abseil-cpp has headers that protobuf-c includes and are + # sensitive to the standard version. While we could override the standard + # version used by these dependents, it is simpler to drop the requirement and + # allow the compiler default standard to be used. + postPatch = '' + substituteInPlace configure.ac --replace-fail \ + "AX_CXX_COMPILE_STDCXX(17, noext, mandatory)" "" + ''; + env.PROTOC = lib.getExe buildPackages.protobuf_33; meta = { From c50cd7f5452db95eefc4d67a780009bc6e4ef2d8 Mon Sep 17 00:00:00 2001 From: Jan Tojnar Date: Sun, 12 Jul 2026 16:59:15 +0200 Subject: [PATCH 011/134] =?UTF-8?q?at-spi2-core:=202.60.4=20=E2=86=92=202.?= =?UTF-8?q?60.5?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit https://gitlab.gnome.org/GNOME/at-spi2-core/-/compare/2.60.4...2.60.5 --- pkgs/by-name/at/at-spi2-core/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/at/at-spi2-core/package.nix b/pkgs/by-name/at/at-spi2-core/package.nix index c20443184374..3f76500bed87 100644 --- a/pkgs/by-name/at/at-spi2-core/package.nix +++ b/pkgs/by-name/at/at-spi2-core/package.nix @@ -29,7 +29,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "at-spi2-core"; - version = "2.60.4"; + version = "2.60.5"; outputs = [ "out" @@ -39,7 +39,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "mirror://gnome/sources/at-spi2-core/${lib.versions.majorMinor finalAttrs.version}/at-spi2-core-${finalAttrs.version}.tar.xz"; - hash = "sha256-Gh9bqYBZF/QfxqpoI9z4h6KR1gekJ+LVr7a136ZQcMc="; + hash = "sha256-YFmnfVB0OP9sjW0GAl+Pn1d0+g+Oq+nJsFmxzEHhu8A="; }; nativeBuildInputs = [ From 21a2601472fc62edfea2a377d7163a1bdf5ba5c6 Mon Sep 17 00:00:00 2001 From: Jan Tojnar Date: Sun, 12 Jul 2026 17:45:40 +0200 Subject: [PATCH 012/134] at-spi2-core: Find `dbus-daemon` and `dbus-broker-launch` on `PATH` MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit This is needed to allow using `at-spi-bus-launcher` in Nix build sandbox where the `/run/current-system` does not exist (e.g. for testing Orca). As a side benefit, we will be able to run `at-spi-bus-launcher` on non-NixOS systems. Also, the comment introduced in f6260a3fe5b2844671eb5dc3ff9f010009c116d1 is slightly misleading. There is no fallback – `at-spi-bus-launcher` will always launch a new `dbus-daemon` instance (accessibility bus) to avoid clobbering the session bus. So I adjusted the text. Since `at-spi-dbus-bus.service` is a systemd user service, it will use `PATH` from user profile, which might prioritize e.g. `~/.local/bin`. This could, in theory, allow an injection of a malicious D-Bus daemon wrapper that would exfiltrate the accessibility bus traffic. But attacker could just as well override `at-spi-dbus-bus.service` so this should not affect security properties. But just to reduce the chance of user profile interference, I am prepending system directories to PATH in the launcher wrapper. --- pkgs/by-name/at/at-spi2-core/package.nix | 24 +++++++++++++++--------- 1 file changed, 15 insertions(+), 9 deletions(-) diff --git a/pkgs/by-name/at/at-spi2-core/package.nix b/pkgs/by-name/at/at-spi2-core/package.nix index 3f76500bed87..1094d8f7da80 100644 --- a/pkgs/by-name/at/at-spi2-core/package.nix +++ b/pkgs/by-name/at/at-spi2-core/package.nix @@ -79,15 +79,14 @@ stdenv.mkDerivation (finalAttrs: { doCheck = false; mesonFlags = [ - # Provide dbus-daemon fallback when it is not already running when - # at-spi2-bus-launcher is executed. This allows us to avoid - # including the entire dbus closure in libraries linked with - # the at-spi2-core libraries. - "-Ddbus_daemon=/run/current-system/sw/bin/dbus-daemon" + # Allows at-spi2-bus-launcher to use dbus-daemon from PATH. + # This allows us to avoid including the entire dbus closure in libraries + # linked with the at-spi2-core libraries. + "-Ddbus_daemon=dbus-daemon" ] ++ lib.optionals systemdSupport [ # Same as the above, but for dbus-broker - "-Ddbus_broker=/run/current-system/sw/bin/dbus-broker-launch" + "-Ddbus_broker=dbus-broker-launch" ] ++ lib.optionals (!systemdSupport) [ "-Duse_systemd=false" @@ -108,10 +107,17 @@ stdenv.mkDerivation (finalAttrs: { }; postFixup = '' - # Cannot use wrapGAppsHook'due to a dependency cycle - wrapProgram $out/libexec/at-spi-bus-launcher \ - ${lib.optionalString withDconf ''--prefix GIO_EXTRA_MODULES : "${lib.getLib dconf}/lib/gio/modules"''} \ + busLauncherWrapperArgs=( + # Prefer dbus-daemon and dbus-broker-launch from system locations. + --prefix PATH : "/run/current-system/sw/bin:/usr/bin" + + # Access to accessibility settings. + ${lib.optionalString withDconf ''--prefix GIO_EXTRA_MODULES : "${lib.getLib dconf}/lib/gio/modules"''} --prefix XDG_DATA_DIRS : ${gsettings-desktop-schemas}/share/gsettings-schemas/${gsettings-desktop-schemas.name} + ) + + # Cannot use wrapGAppsHook'due to a dependency cycle + wrapProgram "$out/libexec/at-spi-bus-launcher" "''${busLauncherWrapperArgs[@]}" ''; meta = { From 2559a0f30478b0906f3bc361a637c2c82bf2c0d7 Mon Sep 17 00:00:00 2001 From: Tom Hunze Date: Fri, 17 Jul 2026 21:14:14 +0000 Subject: [PATCH 013/134] gdk-pixbuf: 2.44.6 -> 2.44.7 https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/compare/2.44.6...2.44.7 --- pkgs/by-name/gd/gdk-pixbuf/package.nix | 12 ++---------- 1 file changed, 2 insertions(+), 10 deletions(-) diff --git a/pkgs/by-name/gd/gdk-pixbuf/package.nix b/pkgs/by-name/gd/gdk-pixbuf/package.nix index 0a1e32428806..a55bfa0909c6 100644 --- a/pkgs/by-name/gd/gdk-pixbuf/package.nix +++ b/pkgs/by-name/gd/gdk-pixbuf/package.nix @@ -1,7 +1,6 @@ { stdenv, fetchurl, - fetchpatch, nixosTests, fixDarwinDylibNames, meson, @@ -29,7 +28,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "gdk-pixbuf"; - version = "2.44.6"; + version = "2.44.7"; outputs = [ "out" @@ -41,19 +40,12 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "mirror://gnome/sources/gdk-pixbuf/${lib.versions.majorMinor finalAttrs.version}/gdk-pixbuf-${finalAttrs.version}.tar.xz"; - hash = "sha256-FAwtC4mfz4U+6SsmNzydwijbzeCCCkJGaT9DKKJ0Zvo="; + hash = "sha256-Fy+A42JuwxUgqXBADxo2lOBHGPbCzSiF91JQ+1pplaQ="; }; patches = [ # Move installed tests to a separate output ./installed-tests-path.patch - - # Fix loading of xpm module if built-in - # https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/merge_requests/267 - (fetchpatch { - url = "https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/commit/62b8f9fd0bb3b862823cd34afce4b389fbd27569.patch"; - hash = "sha256-ECEIt8lq/jBtDdBetErKpap2PWGav10vqCXKCpIQSyA="; - }) ]; # gdk-pixbuf-thumbnailer is not wrapped therefore strictDeps will work From 757b81a53b41e062290007938cf71af6c578da4f Mon Sep 17 00:00:00 2001 From: Tom Hunze Date: Fri, 17 Jul 2026 21:38:24 +0000 Subject: [PATCH 014/134] gjs: 1.88.0 -> 1.88.1 https://gitlab.gnome.org/GNOME/gjs/-/compare/1.88.0...1.88.1 --- pkgs/by-name/gj/gjs/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/gj/gjs/package.nix b/pkgs/by-name/gj/gjs/package.nix index 30b62ac129a9..08cfe8bd2db4 100644 --- a/pkgs/by-name/gj/gjs/package.nix +++ b/pkgs/by-name/gj/gjs/package.nix @@ -41,7 +41,7 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "gjs"; - version = "1.88.0"; + version = "1.88.1"; outputs = [ "out" @@ -51,7 +51,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "mirror://gnome/sources/gjs/${lib.versions.majorMinor finalAttrs.version}/gjs-${finalAttrs.version}.tar.xz"; - hash = "sha256-MKC58zF+jmCxiW2ykDxw6LDNM9+VPDKHVYA6dRkdxFM="; + hash = "sha256-dnurgOZl1nLLAFY8JfCzkqnsjCmW7R1EVMaYtMLwo9k="; }; patches = [ From 717c0b5b7da5d4f9b8f3359d4c53d49828ab5019 Mon Sep 17 00:00:00 2001 From: OPNA2608 Date: Sun, 26 Apr 2026 23:41:56 +0200 Subject: [PATCH 015/134] protobuf: Apply patch to fix BoolKeys test big-endian --- .../protobuf/fix-BoolKeys-test-on-be.patch | 32 +++++++++++++++++++ .../libraries/protobuf/generic.nix | 4 +++ 2 files changed, 36 insertions(+) create mode 100644 pkgs/development/libraries/protobuf/fix-BoolKeys-test-on-be.patch diff --git a/pkgs/development/libraries/protobuf/fix-BoolKeys-test-on-be.patch b/pkgs/development/libraries/protobuf/fix-BoolKeys-test-on-be.patch new file mode 100644 index 000000000000..b8eaa6e94d73 --- /dev/null +++ b/pkgs/development/libraries/protobuf/fix-BoolKeys-test-on-be.patch @@ -0,0 +1,32 @@ +From 02774a2aea957c552383cc6cae43076f5436d867 Mon Sep 17 00:00:00 2001 +From: Sai Sindhuri Avulamanda +Date: Wed, 11 Feb 2026 11:00:05 +0530 +Subject: [PATCH] Fix BoolKeys test to use integer-to-bool cast + +Signed-off-by: saisindhuri91 +--- + upb/hash/test.cc | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/upb/hash/test.cc b/upb/hash/test.cc +index 546df9d71c1f0..fcb7deaa8e4bc 100644 +--- a/upb/hash/test.cc ++++ b/upb/hash/test.cc +@@ -336,7 +336,7 @@ TEST(IntTableTest, BoolKeys) { + // First element. + EXPECT_TRUE(upb_inttable_next(&t, &key, &val, &iter)); + bool key_bool; +- memcpy(&key_bool, &key, sizeof(key_bool)); ++ key_bool = static_cast(key); + EXPECT_EQ(key_bool, false); + EXPECT_EQ(upb_inttable_iter_key(&t, iter), false); + EXPECT_EQ(val.val, true); +@@ -345,7 +345,7 @@ TEST(IntTableTest, BoolKeys) { + + // Second element. + EXPECT_TRUE(upb_inttable_next(&t, &key, &val, &iter)); +- memcpy(&key_bool, &key, sizeof(key_bool)); ++ key_bool = static_cast(key); + EXPECT_EQ(key_bool, true); + EXPECT_EQ(upb_inttable_iter_key(&t, iter), true); + EXPECT_EQ(val.val, false); diff --git a/pkgs/development/libraries/protobuf/generic.nix b/pkgs/development/libraries/protobuf/generic.nix index 59de3e5e7f76..3dbf28e70bea 100644 --- a/pkgs/development/libraries/protobuf/generic.nix +++ b/pkgs/development/libraries/protobuf/generic.nix @@ -83,6 +83,10 @@ stdenv.mkDerivation (finalAttrs: { # entries in `linkarr_upb_AllExts` during test builds. # Context: https://github.com/protocolbuffers/protobuf/issues/21021 ./fix-upb-linkarr-sentinel-init.patch + + # Fix BoolKeys test on big-endian + # https://github.com/protocolbuffers/protobuf/pull/25862 + ./fix-BoolKeys-test-on-be.patch ]; postPatch = From 654698b382a3785d381d3678a41ee098a1822072 Mon Sep 17 00:00:00 2001 From: OPNA2608 Date: Mon, 20 Jul 2026 10:50:03 +0200 Subject: [PATCH 016/134] protobuf_35: Add back fix-upb-packed-enum-be.patch Patch isn't in 35.x, still needed there. --- pkgs/development/libraries/protobuf/generic.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/development/libraries/protobuf/generic.nix b/pkgs/development/libraries/protobuf/generic.nix index 3dbf28e70bea..47149383a4e5 100644 --- a/pkgs/development/libraries/protobuf/generic.nix +++ b/pkgs/development/libraries/protobuf/generic.nix @@ -73,6 +73,8 @@ stdenv.mkDerivation (finalAttrs: { url = "https://github.com/protocolbuffers/protobuf/commit/8282f0f8ecf8b847e5964a308e041ba3b049811c.patch"; hash = "sha256-4c/yLuAd29Cxrz6I9F2Lj02lW2bazIcGb+86uxZY7qA="; }) + ] + ++ lib.optionals ((lib.versionAtLeast version "33") && (lib.versionOlder version "36")) [ # Fix packed enum decoding on big-endian platforms # https://github.com/protocolbuffers/protobuf/pull/25683 ./fix-upb-packed-enum-be.patch From 8c5838cc90ac30da3dce1fbdde6b021e7d48573f Mon Sep 17 00:00:00 2001 From: Willy Date: Tue, 21 Jul 2026 01:41:54 +0200 Subject: [PATCH 017/134] setup-hooks/strip: fix double space in printed output cosmetic change only the loop above prefixes each path with a space, including the first one. this "fix" looks odd in the echo, but beats using `${pathsNew:+ }` as a delimiter (which would be more correct, but also even more ugly) --- pkgs/build-support/setup-hooks/strip.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/build-support/setup-hooks/strip.sh b/pkgs/build-support/setup-hooks/strip.sh index f340ac49acd4..c0553c05ef99 100644 --- a/pkgs/build-support/setup-hooks/strip.sh +++ b/pkgs/build-support/setup-hooks/strip.sh @@ -71,7 +71,7 @@ stripDirs() { paths=${pathsNew} if [ -n "${paths}" ]; then - echo "stripping (with command $cmd and flags $stripFlags) in $paths" + echo "stripping (with command $cmd and flags $stripFlags) in$paths" local striperr striperr="$(mktemp --tmpdir="$TMPDIR" 'striperr.XXXXXX')" # Make sure we process files only once. `strip`ping the same file through different From a2dd9bb9ec2568505236149dce51beea5a76ae13 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 23 Jul 2026 15:46:38 +0000 Subject: [PATCH 018/134] libraqm: 0.10.5 -> 0.11.0 --- pkgs/by-name/li/libraqm/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/li/libraqm/package.nix b/pkgs/by-name/li/libraqm/package.nix index 3010acb5cde6..e2236249055e 100644 --- a/pkgs/by-name/li/libraqm/package.nix +++ b/pkgs/by-name/li/libraqm/package.nix @@ -12,13 +12,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "libraqm"; - version = "0.10.5"; + version = "0.11.0"; src = fetchFromGitHub { owner = "HOST-Oman"; repo = "libraqm"; rev = "v${finalAttrs.version}"; - sha256 = "sha256-6STgs9//BQRu1TTxf+L6+Jj0Z7rkaBFodXzQVRyybE4="; + sha256 = "sha256-3wE2Xr07kFMDw5j6cWwv1cutL2bg7Ia7CdkAx4ysa5A="; }; buildInputs = [ From 4b5231a6ba8324eeecc274c4e0aa27bf689dc3e1 Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Mon, 13 Apr 2026 22:39:55 +0200 Subject: [PATCH 019/134] python3Packages.python-pkcs11: 0.9.3 -> 0.9.4 Diff: https://github.com/danni/python-pkcs11/compare/v0.9.3...v0.9.4 Changelog: https://github.com/pyauth/python-pkcs11/releases/tag/v0.9.4 --- pkgs/development/python-modules/python-pkcs11/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/python-pkcs11/default.nix b/pkgs/development/python-modules/python-pkcs11/default.nix index cad6d6d32ca5..bca6d487117f 100644 --- a/pkgs/development/python-modules/python-pkcs11/default.nix +++ b/pkgs/development/python-modules/python-pkcs11/default.nix @@ -9,14 +9,14 @@ buildPythonPackage rec { pname = "python-pkcs11"; - version = "0.9.3"; + version = "0.9.4"; pyproject = true; src = fetchFromGitHub { owner = "danni"; repo = "python-pkcs11"; tag = "v${version}"; - sha256 = "sha256-ursQHwyTUz4kCg66+Rnvo8bI3fzA3k9FsmbnUvpq/aY="; + hash = "sha256-9RVUtUe+Af5nTDaMeipdijLK4Un/SGRAQIztVKQZZzQ="; }; build-system = [ From ab3a09c3d5c20398ecd9a928cd0ee21cf0ae8489 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 24 Jul 2026 13:43:44 +0000 Subject: [PATCH 020/134] wildmidi: 0.4.6 -> 0.5.0 --- pkgs/by-name/wi/wildmidi/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/wi/wildmidi/package.nix b/pkgs/by-name/wi/wildmidi/package.nix index 59d1aeaaaa64..ce30cdbb8dfa 100644 --- a/pkgs/by-name/wi/wildmidi/package.nix +++ b/pkgs/by-name/wi/wildmidi/package.nix @@ -13,13 +13,13 @@ let in stdenv.mkDerivation rec { pname = "wildmidi"; - version = "0.4.6"; + version = "0.5.0"; src = fetchFromGitHub { owner = "Mindwerks"; repo = "wildmidi"; rev = "${pname}-${version}"; - sha256 = "sha256-syjs8y75M2ul7whiZxnWMSskRJd0ixFqnep7qsTbiDE="; + sha256 = "sha256-KFJW2m7TJ0RExK/C0XHyOefKGFLUszl7Jh6l10NjeHM="; }; nativeBuildInputs = [ cmake ]; From eba134eca772f724793b48416ccc8528be743283 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 24 Jul 2026 21:50:48 +0000 Subject: [PATCH 021/134] duckdb: 1.5.4 -> 1.5.5 --- pkgs/by-name/du/duckdb/versions.json | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/du/duckdb/versions.json b/pkgs/by-name/du/duckdb/versions.json index 0f1ac213431c..09a078b65907 100644 --- a/pkgs/by-name/du/duckdb/versions.json +++ b/pkgs/by-name/du/duckdb/versions.json @@ -1,6 +1,6 @@ { - "version": "1.5.4", - "rev": "08e34c447bae34eaee3723cac61f2878b6bdf787", - "hash": "sha256-6xpKZKfH5/nwE2nU5kcpgITKFm3ilb1PYf9QEk+bKoM=", - "python_hash": "sha256-2TgMuaeAehJ5rvpfA57KTmHtTZnvfa/nl/Y9ASCwVs0=" + "version": "1.5.5", + "rev": "d8cdaa33fda8df955cc76ef58a280f68f4cd43fa", + "hash": "sha256-vFXrMcWF5KDYYRjWZb6iJdhGnCAb6SMlSgzlcr+FQ8Y=", + "python_hash": "sha256-O4tYdPz6H2By7WXT9GzfyBGNeJruCkzSmTYIbiEq2dQ=" } From d328bfb521b56b8fa7fe8d2cd3a0f11ba9114909 Mon Sep 17 00:00:00 2001 From: Dmitry Bogatov Date: Thu, 23 Jul 2026 21:54:16 +0000 Subject: [PATCH 022/134] pkgsStatic.lua.pkgs.libluv: fix build --- pkgs/development/lua-modules/luv/lib.nix | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/pkgs/development/lua-modules/luv/lib.nix b/pkgs/development/lua-modules/luv/lib.nix index d13961b8259e..7ff3f705ec70 100644 --- a/pkgs/development/lua-modules/luv/lib.nix +++ b/pkgs/development/lua-modules/luv/lib.nix @@ -13,7 +13,8 @@ stdenv.mkDerivation { inherit (lua.pkgs.luv) version src meta; cmakeFlags = [ - "-DBUILD_SHARED_LIBS=ON" + (lib.cmakeBool "BUILD_SHARED_LIBS" (!stdenv.hostPlatform.isStatic)) + (lib.cmakeBool "BUILD_STATIC_LIBS" stdenv.hostPlatform.isStatic) "-DBUILD_MODULE=OFF" "-DWITH_SHARED_LIBUV=ON" "-DLUA_BUILD_TYPE=System" From 6e4941d3acf19c831c9343d962ec527ada172b8c Mon Sep 17 00:00:00 2001 From: Dmitry Bogatov Date: Thu, 23 Jul 2026 21:54:16 +0000 Subject: [PATCH 023/134] pkgsStatic.lua.pkgs.luarocks_bootstrap: fix build --- pkgs/development/tools/misc/luarocks/default.nix | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/pkgs/development/tools/misc/luarocks/default.nix b/pkgs/development/tools/misc/luarocks/default.nix index 75327f83f184..4ccddabf2e30 100644 --- a/pkgs/development/tools/misc/luarocks/default.nix +++ b/pkgs/development/tools/misc/luarocks/default.nix @@ -47,6 +47,10 @@ stdenv.mkDerivation (finalAttrs: { # Error: Unknown flag: --build=x86_64-unknown-linux-gnu configurePlatforms = [ ]; + # ... nor the --enable-static/--disable-shared that pkgsStatic injects: + # Error: Unknown flag: --enable-static + dontAddStaticConfigureFlags = true; + preConfigure = '' lua -e "" || { luajit -e "" && { From 4c82c0d5e05ecf877deb5fb097ec6b4f3810731c Mon Sep 17 00:00:00 2001 From: Dmitry Bogatov Date: Thu, 23 Jul 2026 21:54:16 +0000 Subject: [PATCH 024/134] lua.pkgs.libluv: reformat with "nixfmt -s" --- pkgs/development/lua-modules/luv/lib.nix | 5 +---- 1 file changed, 1 insertion(+), 4 deletions(-) diff --git a/pkgs/development/lua-modules/luv/lib.nix b/pkgs/development/lua-modules/luv/lib.nix index 7ff3f705ec70..d6e6933d4817 100644 --- a/pkgs/development/lua-modules/luv/lib.nix +++ b/pkgs/development/lua-modules/luv/lib.nix @@ -31,10 +31,7 @@ stdenv.mkDerivation { lua ]; - nativeBuildInputs = [ - cmake - ] - ++ lib.optionals stdenv.hostPlatform.isDarwin [ fixDarwinDylibNames ]; + nativeBuildInputs = [ cmake ] ++ lib.optionals stdenv.hostPlatform.isDarwin [ fixDarwinDylibNames ]; passthru.tests = { # Test luv too From 289f209083df5078d6de228fe5f1f8c5fd5689d6 Mon Sep 17 00:00:00 2001 From: whispers Date: Fri, 3 Jul 2026 17:14:18 -0400 Subject: [PATCH 025/134] assimp: devendor pugixml, rapidjson, and utf8cpp assimp vendors a *lot* of its own libraries, which is generally an anti-pattern for distros as it leads to duplicate work, both for fixing any issues and build compute. unfortunately, assimp does not make it easy to pull in system libraries (there is an open issue for it, but little progress seems to have been made in a few years), so we patch the CMake declarations to use our own in the same way that Fedora and Debian already do. --- pkgs/by-name/as/assimp/package.nix | 14 +++ .../as/assimp/use-system-libraries.patch | 86 +++++++++++++++++++ 2 files changed, 100 insertions(+) create mode 100644 pkgs/by-name/as/assimp/use-system-libraries.patch diff --git a/pkgs/by-name/as/assimp/package.nix b/pkgs/by-name/as/assimp/package.nix index 24769c4a231c..1bdcf2093886 100644 --- a/pkgs/by-name/as/assimp/package.nix +++ b/pkgs/by-name/as/assimp/package.nix @@ -3,6 +3,9 @@ stdenv, fetchFromGitHub, cmake, + pugixml, + rapidjson, + utf8cpp, zlib, nix-update-script, }: @@ -23,6 +26,14 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-QWBi1pl5C76UtPhB6SmFipm9oEdnfhELMT3MqfV6oxg="; }; + # assimp vendors many libraries that we have available in Nixpkgs, and offers no good way of pulling them from non-vendored sources. + # We thus patch the CMake declarations to do so. + # https://github.com/assimp/assimp/issues/5286 + # also see: + # https://src.fedoraproject.org/rpms/assimp/blob/e0ca8c040bfd661b6d68551b6dc189ba33ffdac1/f/assimp-unbundle.patch + # https://salsa.debian.org/debian/assimp/-/tree/c60e93150d63590d671d9aab165cf259c71f5df9/debian/patches + patches = [ ./use-system-libraries.patch ]; + postPatch = '' # nix build sandbox does not set /var/tmp up: # https://github.com/assimp/assimp/issues/6270 @@ -33,6 +44,9 @@ stdenv.mkDerivation (finalAttrs: { nativeBuildInputs = [ cmake ]; buildInputs = [ + pugixml + rapidjson + utf8cpp zlib ]; diff --git a/pkgs/by-name/as/assimp/use-system-libraries.patch b/pkgs/by-name/as/assimp/use-system-libraries.patch new file mode 100644 index 000000000000..72db82300d46 --- /dev/null +++ b/pkgs/by-name/as/assimp/use-system-libraries.patch @@ -0,0 +1,86 @@ +diff --git a/code/CMakeLists.txt b/code/CMakeLists.txt +index b7b08de3b7..1c07aee928 100644 +--- a/code/CMakeLists.txt ++++ b/code/CMakeLists.txt +@@ -1117,13 +1117,7 @@ + hunter_add_package(pugixml) + find_package(pugixml CONFIG REQUIRED) + ELSEIF(NOT TARGET pugixml::pugixml) +- SET( Pugixml_SRCS +- ../contrib/pugixml/src/pugiconfig.hpp +- ../contrib/pugixml/src/pugixml.cpp +- ../contrib/pugixml/src/pugixml.hpp +- ) +- INCLUDE_DIRECTORIES("../contrib/pugixml/src") +- SOURCE_GROUP( Contrib\\Pugixml FILES ${Pugixml_SRCS}) ++ find_package(pugixml REQUIRED) + ENDIF() + + # utf8 +@@ -1131,7 +1125,7 @@ + hunter_add_package(utf8) + find_package(utf8cpp CONFIG REQUIRED) + ELSE() +- INCLUDE_DIRECTORIES("../contrib/utf8cpp/source") ++ find_package(utf8cpp REQUIRED) + ENDIF() + + # polyclipping +@@ -1287,7 +1281,8 @@ + hunter_add_package(RapidJSON) + find_package(RapidJSON CONFIG REQUIRED) + ELSE() +- INCLUDE_DIRECTORIES("../contrib/rapidjson/include") ++ find_package(RapidJSON CONFIG REQUIRED) ++ include_directories(${RapidJSON_INCLUDE_DIRS}) + ADD_DEFINITIONS( -DRAPIDJSON_HAS_STDSTRING=1) + option( ASSIMP_RAPIDJSON_NO_MEMBER_ITERATOR "Suppress rapidjson warning on MSVC (NOTE: breaks android build)" ON ) + if(ASSIMP_RAPIDJSON_NO_MEMBER_ITERATOR) +@@ -1353,7 +1348,7 @@ + ${ASSIMP_EXPORTER_SRCS} + + ${FBX_COMMON_SRCS} +- ++ + # Third-party libraries + ${unzip_compile_SRCS} + ${Poly2Tri_SRCS} +@@ -1497,13 +1492,11 @@ + target_link_libraries(assimp PRIVATE ${draco_LIBRARIES}) + endif() + ELSE() +- TARGET_LINK_LIBRARIES(assimp ${ZLIB_LIBRARIES} ${OPENDDL_PARSER_LIBRARIES}) ++ TARGET_LINK_LIBRARIES(assimp PRIVATE ${ZLIB_LIBRARIES} ${OPENDDL_PARSER_LIBRARIES}) + if (ASSIMP_BUILD_DRACO) + target_link_libraries(assimp ${draco_LIBRARIES}) + endif() +- if(TARGET pugixml::pugixml) +- target_link_libraries(assimp pugixml::pugixml) +- endif() ++ target_link_libraries(assimp PRIVATE pugixml utf8::cpp) + ENDIF() + + if(ASSIMP_ANDROID_JNIIOSYSTEM) +@@ -1608,7 +1601,7 @@ + + # Add RT-extension library for glTF importer with Open3DGC-compression. + IF (RT_FOUND AND ASSIMP_IMPORTER_GLTF_USE_OPEN3DGC) +- TARGET_LINK_LIBRARIES(assimp rt) ++ TARGET_LINK_LIBRARIES(assimp PRIVATE rt) + ENDIF () + + IF(ASSIMP_INSTALL) +diff --git a/test/CMakeLists.txt b/test/CMakeLists.txt +index 362a43be05..368b52b126 100644 +--- a/test/CMakeLists.txt ++++ b/test/CMakeLists.txt +@@ -263,7 +263,8 @@ + hunter_add_package(RapidJSON) + find_package(RapidJSON CONFIG REQUIRED) + ELSE() +- INCLUDE_DIRECTORIES("../contrib/rapidjson/include") ++ find_package(RapidJSON CONFIG REQUIRED) ++ include_directories(${RapidJSON_INCLUDE_DIRS}) + ADD_DEFINITIONS( -DRAPIDJSON_HAS_STDSTRING=1) + option( ASSIMP_RAPIDJSON_NO_MEMBER_ITERATOR "Suppress rapidjson warning on MSVC (NOTE: breaks android build)" ON ) + if(ASSIMP_RAPIDJSON_NO_MEMBER_ITERATOR) From 15b3e77a1d75a8d5c471dceb6967c3f6fb6f6e33 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Sat, 25 Jul 2026 13:01:49 -0700 Subject: [PATCH 026/134] lerc: 4.1.1 -> 4.2.0 Diff: https://github.com/esri/lerc/compare/v4.1.1...v4.2.0 Changelog: https://github.com/Esri/lerc/blob/v4.2.0/CHANGELOG.md --- pkgs/by-name/le/lerc/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/le/lerc/package.nix b/pkgs/by-name/le/lerc/package.nix index 7765b5e8b9a6..bb308c0ea2b8 100644 --- a/pkgs/by-name/le/lerc/package.nix +++ b/pkgs/by-name/le/lerc/package.nix @@ -10,7 +10,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "lerc"; - version = "4.1.1"; + version = "4.2.0"; outputs = [ "out" @@ -21,7 +21,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "esri"; repo = "lerc"; tag = "v${finalAttrs.version}"; - hash = "sha256-YTNIydQLCBzsuvPWA6qnOkOIPf9JlByJdNHkTevE7Z0="; + hash = "sha256-ysD+0B5yMOdNOKe9MS2T8o0KgqygdxLYiLMr8XeG4JE="; }; # Required to get the freebsd-ports patch to apply. From 3dea6a7bda151ba1b19a60de144afdccfeaf17ab Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jo=C3=A3o=20Santos=20Reis?= Date: Mon, 27 Jul 2026 11:52:39 +0100 Subject: [PATCH 027/134] imagemagick: replace hard-coded store path with $NIX_STORE fixes build issues on systems with a non-default nix store path --- pkgs/by-name/im/imagemagick/package.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/by-name/im/imagemagick/package.nix b/pkgs/by-name/im/imagemagick/package.nix index 918d97c640fa..70fa39d06dfa 100644 --- a/pkgs/by-name/im/imagemagick/package.nix +++ b/pkgs/by-name/im/imagemagick/package.nix @@ -177,7 +177,7 @@ stdenv.mkDerivation (finalAttrs: { moveToOutput "bin/*-config" "$dev" moveToOutput "lib/ImageMagick-*/config-Q16HDRI" "$dev" # includes configure params configDestination=($out/share/ImageMagick-*) - grep -v '/nix/store' $dev/lib/ImageMagick-*/config-Q16HDRI/configure.xml > $configDestination/configure.xml + grep -v "$NIX_STORE" $dev/lib/ImageMagick-*/config-Q16HDRI/configure.xml > $configDestination/configure.xml for file in "$dev"/bin/*-config; do substituteInPlace "$file" --replace-fail "$PKG_CONFIG" \ "PKG_CONFIG_PATH='$dev/lib/pkgconfig' '$(command -v $PKG_CONFIG)'" From 155c8dea99a81d5c65cd60c91550440a17be8f2f Mon Sep 17 00:00:00 2001 From: Cass Fridkin Date: Sat, 25 Jul 2026 09:01:06 -0600 Subject: [PATCH 028/134] pandoc-cli: test lua and server features are enabled by default The lua and server Cabal flags are expected to be on by default. Assert they actually made it into the built binary via a `pandoc --version` check in postInstall, so a future toolchain change can't silently drop them without failing the build. https://github.com/NixOS/nixpkgs/issues/540900 Co-authored-by: Lukas Epple Assisted-by: Claude Code --- pkgs/development/haskell-modules/configuration-nix.nix | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/pkgs/development/haskell-modules/configuration-nix.nix b/pkgs/development/haskell-modules/configuration-nix.nix index 870f2fac7cf2..399297c71260 100644 --- a/pkgs/development/haskell-modules/configuration-nix.nix +++ b/pkgs/development/haskell-modules/configuration-nix.nix @@ -404,6 +404,13 @@ builtins.intersectAttrs super { postInstall = '' ${drv.postInstall or ""} ln -s "''${!outputBin}/bin/pandoc" "''${!outputBin}/bin/pandoc-server" + '' + # Assert the lua and server features are enabled by default + # c.f. https://github.com/NixOS/nixpkgs/issues/540900 + # FIXME: overrideCabal does not allow configuring installCheckPhase, so use postInstall + + lib.optionalString canExecute '' + "''${!outputBin}/bin/pandoc" --version | grep -qF '+lua' + "''${!outputBin}/bin/pandoc" --version | grep -qF '+server' ''; }) super.pandoc-cli; From fbc1858e72e4894b902a09fb528cf22bdd1af877 Mon Sep 17 00:00:00 2001 From: Peder Bergebakken Sundt Date: Mon, 27 Jul 2026 14:41:50 +0200 Subject: [PATCH 029/134] python3Packages.pythonMetadataCheckHook: avoid leaking internal variables --- .../python/hooks/python-metadata-check-hook.sh | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/pkgs/development/interpreters/python/hooks/python-metadata-check-hook.sh b/pkgs/development/interpreters/python/hooks/python-metadata-check-hook.sh index f942e5bee76a..bdc26f6381c2 100644 --- a/pkgs/development/interpreters/python/hooks/python-metadata-check-hook.sh +++ b/pkgs/development/interpreters/python/hooks/python-metadata-check-hook.sh @@ -7,16 +7,17 @@ pythonMetadataCheckPhase() { echo "Executing pythonMetadataCheckPhase" # shellcheck disable=SC2154 - pythonMetadataCheckOutput="$out" + local pythonMetadataCheckOutput="$out" if [[ -n "${python-}" ]]; then echo "Using python specific output \$python for metadata check" pythonMetadataCheckOutput=$python fi # shellcheck disable=SC2154 - derivationPname="$pname" + local derivationPname="$pname" # shellcheck disable=SC2154 - derivationVersion="$version" + local derivationVersion="$version" # `python -P` avoids picking up egg-info dirs in $PWD + local metadataVersion metadataVersion="$(PYTHONPATH="$pythonMetadataCheckOutput/@pythonSitePackages@:$PYTHONPATH" \ @pythonInterpreter@ -P -c 'from importlib.metadata import version; import sys; print(version(sys.argv[1]))' "$derivationPname")" From 85141fe0eed89918e13a4f32f850055dfb85b541 Mon Sep 17 00:00:00 2001 From: Peder Bergebakken Sundt Date: Mon, 27 Jul 2026 14:36:14 +0200 Subject: [PATCH 030/134] python3Packages.pythonMetadataCheckHook: fix typo --- .../interpreters/python/hooks/python-metadata-check-hook.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/development/interpreters/python/hooks/python-metadata-check-hook.sh b/pkgs/development/interpreters/python/hooks/python-metadata-check-hook.sh index bdc26f6381c2..de61a8228940 100644 --- a/pkgs/development/interpreters/python/hooks/python-metadata-check-hook.sh +++ b/pkgs/development/interpreters/python/hooks/python-metadata-check-hook.sh @@ -21,7 +21,7 @@ pythonMetadataCheckPhase() { metadataVersion="$(PYTHONPATH="$pythonMetadataCheckOutput/@pythonSitePackages@:$PYTHONPATH" \ @pythonInterpreter@ -P -c 'from importlib.metadata import version; import sys; print(version(sys.argv[1]))' "$derivationPname")" - # chethat both versions can be parsed + # check that both versions can be parsed @pythonWithPackaging@ -c "from packaging.version import Version; from sys import argv; Version(argv[1]); Version(argv[2])" "$derivationVersion" "$metadataVersion" if @pythonWithPackaging@ -c "from packaging.version import Version; from sys import argv, exit; exit(Version(argv[1]) == Version(argv[2]))" "$derivationVersion" "$metadataVersion"; then From 945300a3251ade9b117a2a412f3d0ee759c80aa7 Mon Sep 17 00:00:00 2001 From: Aleksi Hannula Date: Thu, 9 Apr 2026 11:57:32 +0300 Subject: [PATCH 031/134] minimal-bootstrap.libgmp: init at 6.3.0 --- .../linux/minimal-bootstrap/default.nix | 7 ++ .../linux/minimal-bootstrap/gcc/gmp.nix | 83 +++++++++++++++++++ 2 files changed, 90 insertions(+) create mode 100644 pkgs/os-specific/linux/minimal-bootstrap/gcc/gmp.nix diff --git a/pkgs/os-specific/linux/minimal-bootstrap/default.nix b/pkgs/os-specific/linux/minimal-bootstrap/default.nix index ac31f89dfa66..6e0ff3eb8551 100644 --- a/pkgs/os-specific/linux/minimal-bootstrap/default.nix +++ b/pkgs/os-specific/linux/minimal-bootstrap/default.nix @@ -274,6 +274,13 @@ lib.makeScope heirloom-devtools = callPackage ./heirloom-devtools { tinycc = tinycc-mes; }; + libgmp = callPackage ./gcc/gmp.nix { + gcc-buildbuild = gcc-latest; + gcc = gcc-latest; + gnumake = gnumake-musl; + gnutar = gnutar-latest; + }; + linux-headers = callPackage ./linux-headers { gcc = gcc-latest; gnumake = gnumake-musl; diff --git a/pkgs/os-specific/linux/minimal-bootstrap/gcc/gmp.nix b/pkgs/os-specific/linux/minimal-bootstrap/gcc/gmp.nix new file mode 100644 index 000000000000..87f205ebe9af --- /dev/null +++ b/pkgs/os-specific/linux/minimal-bootstrap/gcc/gmp.nix @@ -0,0 +1,83 @@ +{ + lib, + buildPlatform, + hostPlatform, + fetchurl, + bash, + coreutils, + gcc-buildbuild, + gcc, + binutils, + gnumake, + gnused, + gnugrep, + gawk, + diffutils, + findutils, + gnutar, + gzip, + bzip2, + xz, +}: +let + pname = "gmp"; + version = "6.3.0"; + + src = fetchurl { + url = "mirror://gnu/gmp/gmp-${version}.tar.xz"; + hash = "sha256-o8K4AgG4nmhhb0rTC8Zq7kknw85Q4zkpyoGdXENTiJg="; + }; +in +bash.runCommand "${pname}-${version}" + { + inherit pname version; + + nativeBuildInputs = [ + gcc + gcc-buildbuild + binutils + gnumake + gnused + gnugrep + gawk + diffutils + findutils + gnutar + gzip + bzip2 + xz + ]; + + meta = { + description = "The GNU Multiple Precision Arithmetic Library, version ${version}"; + homepage = "https://gmplib.org/"; + license = with lib.licenses; [ + lgpl3Only + gpl2Only + ]; + teams = [ lib.teams.minimal-bootstrap ]; + platforms = lib.platforms.unix; + }; + } + '' + # Unpack + tar xf ${src} + cd gmp-${version} + + # Configure + bash ./configure \ + --prefix=$out \ + --build=${buildPlatform.config} \ + --host=${hostPlatform.config} \ + --disable-dependency-tracking \ + --with-pic \ + --disable-assembly \ + CFLAGS=-std=c99 \ + M4=false + + # Build + make -j $NIX_BUILD_CORES + + # Install + make -j $NIX_BUILD_CORES install-strip + '' From ab3dec4efda1008c8a09e264d0fcd949aa245b04 Mon Sep 17 00:00:00 2001 From: Aleksi Hannula Date: Thu, 9 Apr 2026 11:58:46 +0300 Subject: [PATCH 032/134] minimal-bootstrap.libmpfr: init at 4.2.2 --- .../linux/minimal-bootstrap/default.nix | 6 ++ .../linux/minimal-bootstrap/gcc/mpfr.nix | 71 +++++++++++++++++++ 2 files changed, 77 insertions(+) create mode 100644 pkgs/os-specific/linux/minimal-bootstrap/gcc/mpfr.nix diff --git a/pkgs/os-specific/linux/minimal-bootstrap/default.nix b/pkgs/os-specific/linux/minimal-bootstrap/default.nix index 6e0ff3eb8551..7f11a5add96f 100644 --- a/pkgs/os-specific/linux/minimal-bootstrap/default.nix +++ b/pkgs/os-specific/linux/minimal-bootstrap/default.nix @@ -281,6 +281,12 @@ lib.makeScope gnutar = gnutar-latest; }; + libmpfr = callPackage ./gcc/mpfr.nix { + gcc = gcc-latest; + gnumake = gnumake-musl; + gnutar = gnutar-latest; + }; + linux-headers = callPackage ./linux-headers { gcc = gcc-latest; gnumake = gnumake-musl; diff --git a/pkgs/os-specific/linux/minimal-bootstrap/gcc/mpfr.nix b/pkgs/os-specific/linux/minimal-bootstrap/gcc/mpfr.nix new file mode 100644 index 000000000000..11807a44350f --- /dev/null +++ b/pkgs/os-specific/linux/minimal-bootstrap/gcc/mpfr.nix @@ -0,0 +1,71 @@ +{ + lib, + buildPlatform, + hostPlatform, + fetchurl, + bash, + gcc, + binutils, + gnumake, + gnused, + gnugrep, + gawk, + diffutils, + findutils, + gnutar, + xz, + libgmp, +}: +let + pname = "mpfr"; + version = "4.2.2"; + + src = fetchurl { + url = "mirror://gnu/mpfr/mpfr-${version}.tar.xz"; + hash = "sha256-tnugOD736KhWNzTi6InvXsPDuJigHQD6CmhprYHGzgE="; + }; +in +bash.runCommand "${pname}-${version}" + { + inherit pname version; + + nativeBuildInputs = [ + gcc + binutils + gnumake + gnused + gnugrep + gawk + diffutils + findutils + gnutar + xz + ]; + + meta = { + description = "The GNU Multiple Precision Floating-Point Reliable Library, version ${version}"; + homepage = "https://www.mpfr.org/"; + license = lib.licenses.lgpl3Plus; + teams = [ lib.teams.minimal-bootstrap ]; + platforms = lib.platforms.unix; + }; + } + '' + # Unpack + tar xf ${src} + cd mpfr-${version} + + # Configure + bash ./configure \ + --prefix=$out \ + --build=${buildPlatform.config} \ + --host=${hostPlatform.config} \ + --disable-dependency-tracking \ + --with-gmp=${libgmp} + + # Build + make -j $NIX_BUILD_CORES + + # Install + make -j $NIX_BUILD_CORES install-strip + '' From da19a96b09793c6cce046dee4da939f2f519c889 Mon Sep 17 00:00:00 2001 From: Aleksi Hannula Date: Thu, 9 Apr 2026 11:59:24 +0300 Subject: [PATCH 033/134] minimal-bootstrap.libmpc: init at 1.3.1 --- .../linux/minimal-bootstrap/default.nix | 6 ++ .../linux/minimal-bootstrap/gcc/mpc.nix | 77 +++++++++++++++++++ 2 files changed, 83 insertions(+) create mode 100644 pkgs/os-specific/linux/minimal-bootstrap/gcc/mpc.nix diff --git a/pkgs/os-specific/linux/minimal-bootstrap/default.nix b/pkgs/os-specific/linux/minimal-bootstrap/default.nix index 7f11a5add96f..60242ac986c8 100644 --- a/pkgs/os-specific/linux/minimal-bootstrap/default.nix +++ b/pkgs/os-specific/linux/minimal-bootstrap/default.nix @@ -281,6 +281,12 @@ lib.makeScope gnutar = gnutar-latest; }; + libmpc = callPackage ./gcc/mpc.nix { + gcc = gcc-latest; + gnumake = gnumake-musl; + gnutar = gnutar-latest; + }; + libmpfr = callPackage ./gcc/mpfr.nix { gcc = gcc-latest; gnumake = gnumake-musl; diff --git a/pkgs/os-specific/linux/minimal-bootstrap/gcc/mpc.nix b/pkgs/os-specific/linux/minimal-bootstrap/gcc/mpc.nix new file mode 100644 index 000000000000..0bba4f4498f3 --- /dev/null +++ b/pkgs/os-specific/linux/minimal-bootstrap/gcc/mpc.nix @@ -0,0 +1,77 @@ +{ + lib, + buildPlatform, + hostPlatform, + fetchurl, + bash, + coreutils, + gcc, + binutils, + gnumake, + gnused, + gnugrep, + gawk, + diffutils, + findutils, + gnutar, + gzip, + bzip2, + xz, + libgmp, + libmpfr, +}: +let + pname = "mpc"; + version = "1.3.1"; + src = fetchurl { + url = "mirror://gnu/mpc/mpc-${version}.tar.gz"; + hash = "sha256-q2QkkvXPiCt0qgy3MM1BCoHtzb7IlRg86TDnBsHHWbg="; + }; +in +bash.runCommand "${pname}-${version}" + { + inherit pname version; + + nativeBuildInputs = [ + gcc + binutils + gnumake + gnused + gnugrep + gawk + diffutils + findutils + gnutar + gzip + bzip2 + xz + ]; + + meta = { + description = "GNU Multiple Precision Complex Library, version ${version}"; + homepage = "https://www.multiprecision.org/"; + license = lib.licenses.lgpl3Plus; + teams = [ lib.teams.minimal-bootstrap ]; + platforms = lib.platforms.unix; + }; + } + '' + # Unpack + tar xf ${src} + cd mpc-${version} + + # Configure + bash ./configure \ + --prefix=$out \ + --build=${buildPlatform.config} \ + --host=${hostPlatform.config} \ + --disable-dependency-tracking \ + --with-gmp=${libgmp} \ + --with-mpfr=${libmpfr} + + # Build + make -j $NIX_BUILD_CORES + + # Install + make -j $NIX_BUILD_CORES install-strip + '' From 12f89dcfe5da7c99d3859f8592b6ada42e81581a Mon Sep 17 00:00:00 2001 From: Aleksi Hannula Date: Thu, 9 Apr 2026 12:01:02 +0300 Subject: [PATCH 034/134] minimal-bootstrap.glibc-headers: init at 2.42 --- .../linux/minimal-bootstrap/default.nix | 7 ++ .../linux/minimal-bootstrap/glibc/headers.nix | 82 +++++++++++++++++++ 2 files changed, 89 insertions(+) create mode 100644 pkgs/os-specific/linux/minimal-bootstrap/glibc/headers.nix diff --git a/pkgs/os-specific/linux/minimal-bootstrap/default.nix b/pkgs/os-specific/linux/minimal-bootstrap/default.nix index 60242ac986c8..dfb48ddf3578 100644 --- a/pkgs/os-specific/linux/minimal-bootstrap/default.nix +++ b/pkgs/os-specific/linux/minimal-bootstrap/default.nix @@ -490,6 +490,13 @@ lib.makeScope gnutar = gnutar-latest; gnugrep = gnugrep-static; }; + + glibc-headers = callPackage ./glibc/headers.nix { + gcc = gcc-latest; + binutils-build = binutils; + gnumake = gnumake-musl; + gnutar = gnutar-latest; + }; } ) ) diff --git a/pkgs/os-specific/linux/minimal-bootstrap/glibc/headers.nix b/pkgs/os-specific/linux/minimal-bootstrap/glibc/headers.nix new file mode 100644 index 000000000000..2a4676231f2f --- /dev/null +++ b/pkgs/os-specific/linux/minimal-bootstrap/glibc/headers.nix @@ -0,0 +1,82 @@ +{ + lib, + buildPlatform, + hostPlatform, + fetchurl, + bash, + gcc, + binutils, + binutils-build, + linux-headers, + gnumake, + gnused, + gnugrep, + gawk, + diffutils, + findutils, + python, + bison, + gnutar, + xz, +}: +let + pname = "glibc-headers"; + version = "2.42"; + + src = fetchurl { + url = "mirror://gnu/libc/glibc-${version}.tar.xz"; + hash = "sha256-0XdeMuRijmTvkw9DW2e7Y691may2viszW58Z8WUJ8X8="; + }; +in +bash.runCommand "${pname}-${version}" + { + inherit pname version; + + nativeBuildInputs = [ + gcc + binutils + binutils-build + gnumake + gnused + gnugrep + gawk + diffutils + findutils + python + bison + gnutar + xz + ]; + + meta = { + description = "The GNU C Library"; + homepage = "https://www.gnu.org/software/libc/"; + license = lib.licenses.lgpl2Plus; + platforms = lib.platforms.linux; + teams = [ lib.teams.minimal-bootstrap ]; + }; + } + '' + # Unpack + tar xf ${src} + cd glibc-${version} + + # Configure + mkdir build + cd build + # libstdc++.so is built against musl and fails to link + export CXX=false + bash ../configure \ + --prefix=$out \ + --build=${buildPlatform.config} \ + --host=${hostPlatform.config} \ + --with-headers=${linux-headers}/include \ + --disable-dependency-tracking + + # Install + make -j $NIX_BUILD_CORES INSTALL_UNCOMPRESSED=yes install-headers install-bootstrap-headers=yes + ln -s $(ls -d ${linux-headers}/include/* | grep -v scsi\$) $out/include/ + + # https://sources.debian.org/patches/glibc/2.43-1/any/local-bootstrap-headers.diff/ + touch $out/include/gnu/stubs.h + '' From d48885dee82b8c4935d5307374142964724cdecb Mon Sep 17 00:00:00 2001 From: Aleksi Hannula Date: Thu, 9 Apr 2026 12:01:53 +0300 Subject: [PATCH 035/134] minimal-bootstrap.musl-headers: init at 1.2.6 --- .../linux/minimal-bootstrap/default.nix | 6 ++ .../linux/minimal-bootstrap/musl/headers.nix | 60 +++++++++++++++++++ 2 files changed, 66 insertions(+) create mode 100644 pkgs/os-specific/linux/minimal-bootstrap/musl/headers.nix diff --git a/pkgs/os-specific/linux/minimal-bootstrap/default.nix b/pkgs/os-specific/linux/minimal-bootstrap/default.nix index dfb48ddf3578..b0fad7145a70 100644 --- a/pkgs/os-specific/linux/minimal-bootstrap/default.nix +++ b/pkgs/os-specific/linux/minimal-bootstrap/default.nix @@ -322,6 +322,12 @@ lib.makeScope gnumake = gnumake-musl; }; + musl-headers = callPackage ./musl/headers.nix { + gcc = gcc46; + gnumake = gnumake-musl; + gnutar = gnutar-latest; + }; + musl-static = callPackage ./musl/static.nix { libgcc = gcc-latest-unwrapped; gcc = gcc-latest; diff --git a/pkgs/os-specific/linux/minimal-bootstrap/musl/headers.nix b/pkgs/os-specific/linux/minimal-bootstrap/musl/headers.nix new file mode 100644 index 000000000000..f356c3842508 --- /dev/null +++ b/pkgs/os-specific/linux/minimal-bootstrap/musl/headers.nix @@ -0,0 +1,60 @@ +{ + lib, + buildPlatform, + hostPlatform, + fetchurl, + bash, + gcc, + binutils, + gnumake, + gnugrep, + gnused, + gnutar, + gzip, +}: +let + inherit (import ./common.nix { inherit lib; }) pname meta; + version = "1.2.6"; + + src = fetchurl { + url = "https://musl.libc.org/releases/musl-${version}.tar.gz"; + hash = "sha256-1YX9O2E8ZhUfwySejtRPdwIMtebB5jWmFtP5+CRgUSo="; + }; +in +bash.runCommand "${pname}-${version}" + { + inherit pname version meta; + + nativeBuildInputs = [ + gcc + binutils + gnumake + gnused + gnugrep + gnutar + gzip + ]; + } + '' + # Unpack + tar xzf ${src} + cd musl-${version} + + # Patch + # https://github.com/ZilchOS/bootstrap-from-tcc/blob/2e0c68c36b3437386f786d619bc9a16177f2e149/using-nix/2a3-intermediate-musl.nix + sed -i 's|/bin/sh|${bash}/bin/bash|' \ + tools/*.sh + + # Configure + # Use build-gcc, since we won't be compiling anything + bash ./configure \ + --prefix=$out \ + --build=${buildPlatform.config} \ + --host=${hostPlatform.config} \ + --syslibdir=$out/lib \ + --enable-wrapper \ + CC=gcc + + # Install + make -j $NIX_BUILD_CORES install-headers + '' From 7bb72161e1de8ad847ab8e806e75f3488059be06 Mon Sep 17 00:00:00 2001 From: Sergei Zimmerman Date: Mon, 27 Jul 2026 22:37:12 +0300 Subject: [PATCH 036/134] boost: backport regression fixes for boost.context Applies the fixes for 1.88 regressions that have caused widespread breakage in Nix. Currently we are building with 1.89, so only 2 fixes are relevant [1,2], with the second patch being backported to avoid conflicts - the issue it addresses doesn't blow up in nix - but it does in userver and other stuff too probably. The third patch was authored by NaN-git to unbreak nix with 1.89, so we apply it to 1.88 (the initial version that had the fiber-specific exception state changes with fcontext and libstdc++). This is mostly for consistency and unbreak boost.context on that version. [1]: https://github.com/boostorg/context/pull/337 [2]: https://github.com/boostorg/context/pull/331 --- pkgs/development/libraries/boost/generic.nix | 29 ++++++++++++++++++++ 1 file changed, 29 insertions(+) diff --git a/pkgs/development/libraries/boost/generic.nix b/pkgs/development/libraries/boost/generic.nix index 2c5bcf0c7c0e..2b46a1b0410c 100644 --- a/pkgs/development/libraries/boost/generic.nix +++ b/pkgs/development/libraries/boost/generic.nix @@ -194,6 +194,35 @@ stdenv.mkDerivation { extraPrefix = "libs/context/"; sha256 = "sha256-bCfLL7bD1Rn4Ie/P3X+nIcgTkbXdCX6FW7B9lHsmVW8="; }) + # Backports https://github.com/boostorg/context/pull/331, which prevents + # an optimisation that breaks coroutine migration between threads. + # (mostly needed to avoid conflicts when applying the patch below, + # but it's a meaningful standalone fix too). + ++ + lib.optional (lib.versionAtLeast version "1.88.0" && lib.versionOlder version "1.92.0") + (fetchpatch { + url = "https://github.com/boostorg/context/commit/0921b9fd5c776aec7748475c6c10807e0d51bc6d.patch"; + relative = "include"; + hash = "sha256-nQYMd3HFsDLxijnGdyas0ZHs3ylQVMGQL14K7F6MkF0="; + }) + # Backports https://github.com/boostorg/context/pull/337 which fixes a regression that breaks + # std::uncaught_exceptions for abandoned coroutines under libstdc++ and fcontext implementation. + # This bug also caused subtle breakage in Nix. See https://github.com/NixOS/nix/issues/16174. + ++ + lib.optional (lib.versionAtLeast version "1.88.0" && lib.versionOlder version "1.93.0") + (fetchpatch { + url = "https://github.com/boostorg/context/commit/5883212311535a0046031d74d1568ae173c1e35b.patch"; + relative = "include"; + hash = "sha256-CytNLi2d0wjI/lY5lDv98mwwQaEt7qeIs4UkE6QgCBU="; + }) + ++ + # This also broke Nix https://github.com/NixOS/nix/issues/13145 and probably much more dependants too. + lib.optional (lib.versionAtLeast version "1.88.0" && lib.versionOlder version "1.89.0") + (fetchpatch { + url = "https://github.com/boostorg/context/commit/c79564d0de69422ed33f2fbc892908ad510e6a19.patch"; + relative = "include"; + hash = "sha256-5iZ+rSdtyOupBUYws6U8whd43XMkTlQlApW5xvE0ZB4="; + }) # This fixes another issue regarding ill-formed constant expressions, which is a default error # in clang 16 and will be a hard error in clang 17. ++ lib.optional (lib.versionOlder version "1.80") (fetchpatch { From c3ae1ea5ff1360be6d3e4fc2953767c302c96c1a Mon Sep 17 00:00:00 2001 From: whispers Date: Thu, 2 Jul 2026 22:10:13 -0400 Subject: [PATCH 037/134] webrtc-audio-processing: explicitly specify C++17 for abseil-cpp abseil exposes different interfaces depending on what is available in `std` in a given C++ standard. gcc 16 defaults to C++20, thus causing the default abseil-cpp to expose a different interface than the one webrtc-audio-processing (built with C++17) expects. this leads to a great deal of "error: 'partial_ordering' has not been declared in 'std'" and similar originating from abseil's types/compare.h. thus, we explicitly override abseil to specify the desired C++ standard. --- pkgs/by-name/we/webrtc-audio-processing/package.nix | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/we/webrtc-audio-processing/package.nix b/pkgs/by-name/we/webrtc-audio-processing/package.nix index 6dfea3582b92..4038bde5548f 100644 --- a/pkgs/by-name/we/webrtc-audio-processing/package.nix +++ b/pkgs/by-name/we/webrtc-audio-processing/package.nix @@ -46,7 +46,11 @@ stdenv.mkDerivation (finalAttrs: { ]; propagatedBuildInputs = [ - abseil-cpp + # webrtc-audio-processing specifies C++17, so abseil must match. Otherwise, + # abseil exposes a different (incompatible) interface based on the default + # C++ standard of the compiler. + # https://gitlab.freedesktop.org/pulseaudio/webrtc-audio-processing/-/blob/d0569cfa50c1858ee279d77b3fc8870be6902441/meson.build#L7 + (abseil-cpp.override { cxxStandard = "17"; }) ]; mesonFlags = From a12482ee8190257fe1d207c193b5880f7f6fec69 Mon Sep 17 00:00:00 2001 From: Brian McGillion Date: Tue, 28 Jul 2026 09:28:09 +0400 Subject: [PATCH 038/134] swtpm: fix cross-compilation configure.ac probes for the openssl CLI: AC_CHECK_PROG([OPENSSL_CLITOOL], [openssl], [yes], [no]) AS_IF([test "$OPENSSL_CLITOOL" != "yes"], [AC_MSG_ERROR("Could not find openssl tool. Is openssl installed?")]) swtpm gained this check when it switched its local CA from the gnutls certtool to the openssl CLI in 0.10.1-unstable-2026-05-21. openssl is currently only in buildInputs, for the library. Natively that happens to satisfy the probe as well, since build == host means the buildInputs bin dirs land on PATH anyway, but when cross-compiling they go to HOST_PATH instead and configure aborts: configure: error: "Could not find openssl tool. Is openssl installed?" Add openssl to nativeBuildInputs so the build-platform CLI is on PATH. The probe is only a presence test -- the path baked into swtpm_localca is already substituted to the host openssl via lib.getExe -- so this does not change what the built package runs. Tested with `nix build -f . pkgsCross.aarch64-multiplatform.swtpm`, which fails on master and succeeds with this change. Signed-off-by: Brian McGillion --- pkgs/by-name/sw/swtpm/package.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkgs/by-name/sw/swtpm/package.nix b/pkgs/by-name/sw/swtpm/package.nix index ffa3d5760e31..6fce8b666fb0 100644 --- a/pkgs/by-name/sw/swtpm/package.nix +++ b/pkgs/by-name/sw/swtpm/package.nix @@ -46,6 +46,11 @@ stdenv.mkDerivation (finalAttrs: { python3 autoreconfHook makeWrapper + # configure.ac does AC_CHECK_PROG([OPENSSL_CLITOOL], [openssl], ...) and + # errors out when the tool is not on PATH. openssl is in buildInputs for + # the library, which puts its bin dir on PATH only when build == host, so + # the check fails when cross-compiling. + openssl ]; nativeCheckInputs = [ From 6d89c1789da4b13f29fc590e2a33e2979b1889ac Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 28 Jul 2026 07:53:55 +0000 Subject: [PATCH 039/134] publicsuffix-list: 0-unstable-2026-06-24 -> 0-unstable-2026-07-25 --- pkgs/by-name/pu/publicsuffix-list/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/pu/publicsuffix-list/package.nix b/pkgs/by-name/pu/publicsuffix-list/package.nix index 7dd02eb4f21d..d6c15745fa64 100644 --- a/pkgs/by-name/pu/publicsuffix-list/package.nix +++ b/pkgs/by-name/pu/publicsuffix-list/package.nix @@ -7,13 +7,13 @@ stdenvNoCC.mkDerivation { pname = "publicsuffix-list"; - version = "0-unstable-2026-06-24"; + version = "0-unstable-2026-07-25"; src = fetchFromGitHub { owner = "publicsuffix"; repo = "list"; - rev = "18ecca5d54471f21918798da451dd8d03a18f3c7"; - hash = "sha256-xvOAZpWhuOU3koEHgNfVK6aHy+VMYRoHj3fq9PxaAFo="; + rev = "e1b8015c3b2f0f4f8c18659c2480fc1a22c07b20"; + hash = "sha256-F+OmANpg7I4dBFL7PM3oJlhpDzfxrRTfo+50lQHdU2M="; }; dontBuild = true; From a00e12bc536bd4d8ec340f8c40ec036fdf1e2012 Mon Sep 17 00:00:00 2001 From: teto <886074+teto@users.noreply.github.com> Date: Tue, 28 Jul 2026 13:32:36 +0200 Subject: [PATCH 040/134] luajit: update deprecated `substituteInPlace --replace` --- pkgs/development/interpreters/luajit/default.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/development/interpreters/luajit/default.nix b/pkgs/development/interpreters/luajit/default.nix index 91c706e4efa8..fede20472a1e 100644 --- a/pkgs/development/interpreters/luajit/default.nix +++ b/pkgs/development/interpreters/luajit/default.nix @@ -72,7 +72,7 @@ stdenv.mkDerivation (finalAttrs: { luaversion = "5.1"; postPatch = '' - substituteInPlace Makefile --replace ldconfig : + substituteInPlace Makefile --replace-fail ldconfig : if test -n "''${dontStrip-}"; then # CCDEBUG must be non-empty or everything will be stripped, -g being # passed by nixpkgs CC wrapper is insufficient on its own From 7a41586b84fa1de64e88861a4e2116cf1f1fc6d8 Mon Sep 17 00:00:00 2001 From: Hraban Date: Tue, 28 Jul 2026 08:40:55 -0400 Subject: [PATCH 041/134] sbcl: 2.6.6 -> 2.6.7 --- pkgs/development/compilers/sbcl/default.nix | 2 +- pkgs/top-level/all-packages.nix | 18 +++++++++--------- 2 files changed, 10 insertions(+), 10 deletions(-) diff --git a/pkgs/development/compilers/sbcl/default.nix b/pkgs/development/compilers/sbcl/default.nix index 3289dd72f3ab..eb5de16a28c3 100644 --- a/pkgs/development/compilers/sbcl/default.nix +++ b/pkgs/development/compilers/sbcl/default.nix @@ -32,8 +32,8 @@ let "2.4.10".sha256 = "sha256-zus5a2nSkT7uBIQcKva+ylw0LOFGTD/j5FPy3hDF4vg="; # By unofficial and very loose convention we keep the latest version of # SBCL, and the previous one in case someone quickly needs to roll back. - "2.6.5".sha256 = "sha256-kex19kclLtbmrq6bGhP0fHxs/ZtoSI3Gnxpv6lrMtEA="; "2.6.6".sha256 = "sha256-plp6MIEqr1SSXRGSubnoEPUnx5kRxgALdUgQWu99o0s="; + "2.6.7".sha256 = "sha256-Hr3DXJ3I4nG4zRrESWXgC/JV+cAiFlD8t38Ps0wtOt4="; }; # Collection of pre-built SBCL binaries for platforms that need them for # bootstrapping. Ideally these are to be avoided. If ECL (or any other diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 6d45ae290b39..1029fdc8d85f 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -7049,14 +7049,6 @@ with pkgs; ]; }; - sbcl_2_6_5 = wrapLisp { - pkg = callPackage ../development/compilers/sbcl { version = "2.6.5"; }; - faslExt = "fasl"; - flags = [ - "--dynamic-space-size" - "3000" - ]; - }; sbcl_2_6_6 = wrapLisp { pkg = callPackage ../development/compilers/sbcl { version = "2.6.6"; }; faslExt = "fasl"; @@ -7065,7 +7057,15 @@ with pkgs; "3000" ]; }; - sbcl = sbcl_2_6_6; + sbcl_2_6_7 = wrapLisp { + pkg = callPackage ../development/compilers/sbcl { version = "2.6.7"; }; + faslExt = "fasl"; + flags = [ + "--dynamic-space-size" + "3000" + ]; + }; + sbcl = sbcl_2_6_7; sbclPackages = recurseIntoAttrs sbcl.pkgs; From d3bdeb580bfe78a74f875d923fef55d27cb3d11e Mon Sep 17 00:00:00 2001 From: Samuel Dionne-Riel Date: Tue, 28 Jul 2026 09:56:57 -0400 Subject: [PATCH 042/134] libssh: 0.12.1 -> 0.12.2 https://www.libssh.org/2026/07/28/libssh-0-12-2-security-release/ Fixes: CVE-2026-59843: Denial of service via zero advertised channel packet size --- pkgs/by-name/li/libssh/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/li/libssh/package.nix b/pkgs/by-name/li/libssh/package.nix index b8a4ef7a8f92..c98fe05e6f7c 100644 --- a/pkgs/by-name/li/libssh/package.nix +++ b/pkgs/by-name/li/libssh/package.nix @@ -19,11 +19,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "libssh"; - version = "0.12.1"; + version = "0.12.2"; src = fetchurl { url = "https://www.libssh.org/files/${lib.versions.majorMinor finalAttrs.version}/libssh-${finalAttrs.version}.tar.xz"; - hash = "sha256-05Qa8KLXjV2C7Xo2mI6RM5lDEvA1uWWabkP42zloeEw="; + hash = "sha256-SVYPZ32W43BqkErC3hEW4l82gJN9UeXJIZj8ukocHp8="; }; outputs = [ From d86aa340f233e954ebc0cd150ced7de1a6f273d9 Mon Sep 17 00:00:00 2001 From: scraptux Date: Tue, 28 Jul 2026 16:01:35 +0200 Subject: [PATCH 043/134] grpc: 1.82.1 -> 1.83.0 --- pkgs/by-name/gr/grpc/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/gr/grpc/package.nix b/pkgs/by-name/gr/grpc/package.nix index 7688baf9284e..105e69cc23ee 100644 --- a/pkgs/by-name/gr/grpc/package.nix +++ b/pkgs/by-name/gr/grpc/package.nix @@ -25,7 +25,7 @@ # nixpkgs-update: no auto update stdenv.mkDerivation (finalAttrs: { pname = "grpc"; - version = "1.82.1"; # N.B: if you change this, please update: + version = "1.83.0"; # N.B: if you change this, please update: # pythonPackages.grpcio # pythonPackages.grpcio-channelz # pythonPackages.grpcio-health-checking @@ -38,7 +38,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "grpc"; repo = "grpc"; tag = "v${finalAttrs.version}"; - hash = "sha256-w4tl1y1GITlfeHTsSAZm45d8HQVzqSBVEQXoEqO0h5g="; + hash = "sha256-A2QtLdsunMOulbpyaSOoAID9caK0tpuiyZJ5C5zrr+k="; fetchSubmodules = true; }; From 7f6f0d4fb21bd2481cd08c2b10f8673587247386 Mon Sep 17 00:00:00 2001 From: scraptux Date: Tue, 28 Jul 2026 16:01:38 +0200 Subject: [PATCH 044/134] python3Packages.grpcio: 1.82.1 -> 1.83.0 --- pkgs/development/python-modules/grpcio/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/grpcio/default.nix b/pkgs/development/python-modules/grpcio/default.nix index 9f22f9b94416..3f39101e34d8 100644 --- a/pkgs/development/python-modules/grpcio/default.nix +++ b/pkgs/development/python-modules/grpcio/default.nix @@ -18,12 +18,12 @@ # nixpkgs-update: no auto update buildPythonPackage rec { pname = "grpcio"; - version = "1.82.1"; + version = "1.83.0"; pyproject = true; src = fetchPypi { inherit pname version; - hash = "sha256-cHskq9kPyx5FvMCAV32h2/mXHRB0kFiblTmvjh53tLU="; + hash = "sha256-dnRYckj7uyrG5O7Pg6ig89kako+UHeVxrP06LwB/vCQ="; }; postPatch = '' From 43743d1d5c79566758035c6ad32697a5a5d5b50d Mon Sep 17 00:00:00 2001 From: scraptux Date: Tue, 28 Jul 2026 16:01:40 +0200 Subject: [PATCH 045/134] python3Packages.grpcio-channelz: 1.82.1 -> 1.83.0 --- pkgs/development/python-modules/grpcio-channelz/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/grpcio-channelz/default.nix b/pkgs/development/python-modules/grpcio-channelz/default.nix index a3f96b4f0b39..6741c9d8bc80 100644 --- a/pkgs/development/python-modules/grpcio-channelz/default.nix +++ b/pkgs/development/python-modules/grpcio-channelz/default.nix @@ -12,13 +12,13 @@ # nixpkgs-update: no auto update buildPythonPackage rec { pname = "grpcio-channelz"; - version = "1.82.1"; + version = "1.83.0"; pyproject = true; src = fetchPypi { pname = "grpcio_channelz"; inherit version; - hash = "sha256-/Q6lQDfasOu4BAaiqH6AmyTUEKLp209mL6IqKZ8AUOs="; + hash = "sha256-gaqgIn5UGWGvsnhNNcmWO9sPdmtGQ9JAODmBeKYc9lw="; }; build-system = [ setuptools ]; From 73ca237bedad38ef50af6189991050c5dc7d9bc9 Mon Sep 17 00:00:00 2001 From: scraptux Date: Tue, 28 Jul 2026 16:01:42 +0200 Subject: [PATCH 046/134] python3Packages.grpcio-health-checking: 1.82.1 -> 1.83.0 --- .../python-modules/grpcio-health-checking/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/grpcio-health-checking/default.nix b/pkgs/development/python-modules/grpcio-health-checking/default.nix index ab1c0bb04f81..ef962e09a7a2 100644 --- a/pkgs/development/python-modules/grpcio-health-checking/default.nix +++ b/pkgs/development/python-modules/grpcio-health-checking/default.nix @@ -11,13 +11,13 @@ # nixpkgs-update: no auto update buildPythonPackage rec { pname = "grpcio-health-checking"; - version = "1.82.1"; + version = "1.83.0"; format = "setuptools"; src = fetchPypi { pname = "grpcio_health_checking"; inherit version; - hash = "sha256-hiVeBOHTnxyXpmMtQbYySTUUCN5cWOhe7eh6/X2YKN0="; + hash = "sha256-rWvE1aEQOtcE0lzNgt7zAN+ieZaxhcqz5Mzu7yxoZ9Q="; }; propagatedBuildInputs = [ From 60c83f713528907479a02e24a4fb5fc094b12873 Mon Sep 17 00:00:00 2001 From: scraptux Date: Tue, 28 Jul 2026 16:01:44 +0200 Subject: [PATCH 047/134] python3Packages.grpcio-reflection: 1.82.1 -> 1.83.0 --- pkgs/development/python-modules/grpcio-reflection/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/grpcio-reflection/default.nix b/pkgs/development/python-modules/grpcio-reflection/default.nix index 7d28689e7ee0..d697034b9bb0 100644 --- a/pkgs/development/python-modules/grpcio-reflection/default.nix +++ b/pkgs/development/python-modules/grpcio-reflection/default.nix @@ -12,13 +12,13 @@ # nixpkgs-update: no auto update buildPythonPackage rec { pname = "grpcio-reflection"; - version = "1.82.1"; + version = "1.83.0"; pyproject = true; src = fetchPypi { pname = "grpcio_reflection"; inherit version; - hash = "sha256-LslD6tPhe0P44HR6XLQXs6ZDV/49m0p73Dmkwz6pgA0="; + hash = "sha256-aiowpGKsLDxtFJc0qP5lX6dhfBf6LNqZSQBvO/B/Wz4="; }; build-system = [ setuptools ]; From f2e24494800a7564a5c75c29965d159d3e0c8c9a Mon Sep 17 00:00:00 2001 From: scraptux Date: Tue, 28 Jul 2026 16:01:46 +0200 Subject: [PATCH 048/134] python3Packages.grpcio-status: 1.82.1 -> 1.83.0 --- pkgs/development/python-modules/grpcio-status/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/grpcio-status/default.nix b/pkgs/development/python-modules/grpcio-status/default.nix index 479a1e105efb..57e252eae475 100644 --- a/pkgs/development/python-modules/grpcio-status/default.nix +++ b/pkgs/development/python-modules/grpcio-status/default.nix @@ -12,13 +12,13 @@ # nixpkgs-update: no auto update buildPythonPackage rec { pname = "grpcio-status"; - version = "1.82.1"; + version = "1.83.0"; format = "setuptools"; src = fetchPypi { pname = "grpcio_status"; inherit version; - hash = "sha256-2d6Kw0djzUaBMP3SkjKUr3w9KNCUJvbEUiHSfCWTETA="; + hash = "sha256-g3IZxt6a/cy29vcrNLxx4VGiAR7wQEDj+qynRqV+VK4="; }; postPatch = '' From c36939b7e6413a580d6e42b59c016dea1f935cb2 Mon Sep 17 00:00:00 2001 From: scraptux Date: Tue, 28 Jul 2026 16:01:49 +0200 Subject: [PATCH 049/134] python3Packages.grpcio-testing: 1.82.1 -> 1.83.0 --- pkgs/development/python-modules/grpcio-testing/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/grpcio-testing/default.nix b/pkgs/development/python-modules/grpcio-testing/default.nix index 59f7e88b533e..9f0f81ecb5b8 100644 --- a/pkgs/development/python-modules/grpcio-testing/default.nix +++ b/pkgs/development/python-modules/grpcio-testing/default.nix @@ -12,13 +12,13 @@ # nixpkgs-update: no auto update buildPythonPackage rec { pname = "grpcio-testing"; - version = "1.82.1"; + version = "1.83.0"; pyproject = true; src = fetchPypi { pname = "grpcio_testing"; inherit version; - hash = "sha256-2fxmLSRf10IpLQOJkCQtDdDmkvAKAvIQvRI0FFzxM0E="; + hash = "sha256-/6p6o+ckGsNXDBePfNbpRYEUK1Eh60esk5g+1gfwa90="; }; postPatch = '' From 5e29faac702ca4010fc8288db38804c108fe6f71 Mon Sep 17 00:00:00 2001 From: scraptux Date: Tue, 28 Jul 2026 16:01:54 +0200 Subject: [PATCH 050/134] python3Packages.grpcio-tools: 1.82.1 -> 1.83.0 --- pkgs/development/python-modules/grpcio-tools/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/grpcio-tools/default.nix b/pkgs/development/python-modules/grpcio-tools/default.nix index 9d4d7f1bc435..0274dd2ead83 100644 --- a/pkgs/development/python-modules/grpcio-tools/default.nix +++ b/pkgs/development/python-modules/grpcio-tools/default.nix @@ -13,13 +13,13 @@ # nixpkgs-update: no auto update buildPythonPackage rec { pname = "grpcio-tools"; - version = "1.82.1"; + version = "1.83.0"; pyproject = true; src = fetchPypi { pname = "grpcio_tools"; inherit version; - hash = "sha256-K9MXbM2/fNH0Y+t1t7g1RMfWQp9cqKD394S3YJfayJE="; + hash = "sha256-UVkHJl0U+pl10MdyP5Wp2gFGPXrGB1RqA/h0H4ahuwc="; }; postPatch = '' From 385cbe4a35fd9414d543685ed342f351e98dad48 Mon Sep 17 00:00:00 2001 From: Grimmauld Date: Tue, 28 Jul 2026 22:54:39 +0200 Subject: [PATCH 051/134] gst_all_1.gst-plugins-base: build vorbis support with libvorbis instead of tremor --- pkgs/development/libraries/gstreamer/base/default.nix | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/pkgs/development/libraries/gstreamer/base/default.nix b/pkgs/development/libraries/gstreamer/base/default.nix index a2a478c76ff2..6f56679fa103 100644 --- a/pkgs/development/libraries/gstreamer/base/default.nix +++ b/pkgs/development/libraries/gstreamer/base/default.nix @@ -17,7 +17,7 @@ isocodes, libjpeg, libpng, - tremor, # provides 'virbisidec' + libvorbis, libGL, withIntrospection ? lib.meta.availableOn stdenv.hostPlatform gobject-introspection @@ -98,7 +98,7 @@ stdenv.mkDerivation (finalAttrs: { isocodes libpng libjpeg - tremor + libvorbis pango ] ++ lib.optionals (!stdenv.hostPlatform.isDarwin) [ @@ -143,6 +143,8 @@ stdenv.mkDerivation (finalAttrs: { (lib.mesonEnable "introspection" withIntrospection) (lib.mesonEnable "doc" enableDocumentation) (lib.mesonEnable "libvisual" false) + (lib.mesonEnable "tremor" false) # unmaintained in nixpkgs, just use regular libvorbis instead + (lib.mesonEnable "vorbis" true) ] ++ lib.optionals (stdenv.buildPlatform != stdenv.hostPlatform) [ "-Dtests=disabled" From 5dee3f9c812279771684f71f920631b7bf81f5e6 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 29 Jul 2026 06:43:03 +0000 Subject: [PATCH 052/134] libva-minimal: 2.24.0 -> 2.24.1 --- pkgs/development/libraries/libva/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/libraries/libva/default.nix b/pkgs/development/libraries/libva/default.nix index d8b9cb278773..f3e996ec48ae 100644 --- a/pkgs/development/libraries/libva/default.nix +++ b/pkgs/development/libraries/libva/default.nix @@ -27,13 +27,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "libva" + lib.optionalString minimal "-minimal"; - version = "2.24.0"; + version = "2.24.1"; src = fetchFromGitHub { owner = "intel"; repo = "libva"; rev = finalAttrs.version; - sha256 = "sha256-NDh8XI1JJPegDXO2nH2XKVywp25Su/ytgR1OHI7nvdI="; + sha256 = "sha256-kgFvqyUlBZApc8D2i3BX6bHkUVNon5bL4asZ9myhQEM="; }; outputs = [ From 86293d257ea2526d3ff57cf1e1cb2707d118b61f Mon Sep 17 00:00:00 2001 From: Markus Theil Date: Wed, 29 Jul 2026 11:34:29 +0200 Subject: [PATCH 053/134] tpm2-tss: 4.1.3 -> 4.2.0 Bump due to security fixes: https://github.com/tpm2-software/tpm2-tss/releases/tag/4.2.0 Adapted patches and removed already upstream ones. Signed-off-by: Markus Theil --- .../libraries/tpm2-tss/default.nix | 20 +- .../tpm2-tss/no-dynamic-loader-path.patch | 470 +++++++++--------- .../libraries/tpm2-tss/no-shadow.patch | 16 - 3 files changed, 225 insertions(+), 281 deletions(-) delete mode 100644 pkgs/development/libraries/tpm2-tss/no-shadow.patch diff --git a/pkgs/development/libraries/tpm2-tss/default.nix b/pkgs/development/libraries/tpm2-tss/default.nix index 6bf372a5dd92..e910c11533bd 100644 --- a/pkgs/development/libraries/tpm2-tss/default.nix +++ b/pkgs/development/libraries/tpm2-tss/default.nix @@ -31,13 +31,13 @@ in stdenv.mkDerivation (finalAttrs: { pname = "tpm2-tss"; - version = "4.1.3"; + version = "4.2.0"; src = fetchFromGitHub { owner = "tpm2-software"; repo = finalAttrs.pname; rev = finalAttrs.version; - hash = "sha256-BP28utEUI9g1VNv3lCXuiKrDtEImFQxxZfIjLiE3Wr8="; + hash = "sha256-MNrVKoA2sW3wKaQsq27UtakzdKmfirtDCoPWu0EEndw="; }; outputs = [ @@ -87,17 +87,6 @@ stdenv.mkDerivation (finalAttrs: { # Do not rely on dynamic loader path # TCTI loader relies on dlopen(), this patch prefixes all calls with the output directory ./no-dynamic-loader-path.patch - - # Configure script expects tools from shadow (e.g. useradd) but they are - # actually optional (and we can’t use them in Nix sandbox anyway). Make the - # check in configure.ac a warning instead of an error so that we can run - # configure phase on platforms that don’t have shadow package (e.g. macOS). - # Note that *on platforms* does not mean *for platform* i.e. this is for - # cross-compilation, tpm2-tss does not support macOS, see upstream issue: - # https://github.com/tpm2-software/tpm2-tss/issues/2629 - # See also - # https://github.com/tpm2-software/tpm2-tss/blob/6c46325b466f35d40c2ed1043bfdfcfb8a367a34/Makefile.am#L880-L898 - ./no-shadow.patch ]; postPatch = '' @@ -115,11 +104,6 @@ stdenv.mkDerivation (finalAttrs: { done substituteInPlace src/tss2-fapi/ifapi_config.c \ --replace-fail 'SYSCONFDIR' '"/etc"' - - # https://github.com/tpm2-software/tpm2-tss/pull/3041 - substituteInPlace test/unit/tcti-libtpms.c \ - --replace-fail 'check_expected_ptr(st);' 'check_expected(st);' \ - --replace-fail 'check_expected_ptr(buf_len);' 'check_expected(buf_len);' '' # tcti tests rely on mocking function calls, which appears not to be supported # on clang diff --git a/pkgs/development/libraries/tpm2-tss/no-dynamic-loader-path.patch b/pkgs/development/libraries/tpm2-tss/no-dynamic-loader-path.patch index fcbfaca299fd..a2eedd60a937 100644 --- a/pkgs/development/libraries/tpm2-tss/no-dynamic-loader-path.patch +++ b/pkgs/development/libraries/tpm2-tss/no-dynamic-loader-path.patch @@ -1,8 +1,6 @@ -diff --git a/src/tss2-tcti/tctildr-dl.c b/src/tss2-tcti/tctildr-dl.c -index d26219d2..92d2b6a3 100644 --- a/src/tss2-tcti/tctildr-dl.c +++ b/src/tss2-tcti/tctildr-dl.c -@@ -88,14 +88,24 @@ handle_from_name(const char *file, +@@ -84,14 +84,24 @@ const char *formats[] = { /* */ "%s", @@ -27,479 +25,457 @@ index d26219d2..92d2b6a3 100644 }; if (handle == NULL) { -diff --git a/test/unit/tctildr-dl.c b/test/unit/tctildr-dl.c -index 135e1b14..7d654d1f 100644 --- a/test/unit/tctildr-dl.c +++ b/test/unit/tctildr-dl.c -@@ -168,6 +168,10 @@ test_handle_from_name_second_dlopen_success (void **state) - expect_value(__wrap_dlopen, flags, RTLD_NOW); +@@ -153,6 +153,9 @@ + expect_string(__wrap_dlopen, filename, TEST_TCTI_TRY_A); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); - + expect_string(__wrap_dlopen, filename, "@PREFIX@" TEST_TCTI_TRY_A); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); -+ - expect_string(__wrap_dlopen, filename, TEST_TCTI_TRY_B); - expect_value(__wrap_dlopen, flags, RTLD_NOW); - will_return(__wrap_dlopen, TEST_HANDLE); -@@ -186,10 +190,18 @@ test_handle_from_name_third_dlopen_success (void **state) - expect_value(__wrap_dlopen, flags, RTLD_NOW); - will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, TEST_TCTI_TRY_B); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); +@@ -170,10 +173,16 @@ + expect_string(__wrap_dlopen, filename, TEST_TCTI_TRY_A); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" TEST_TCTI_TRY_A); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); -+ - expect_string(__wrap_dlopen, filename, TEST_TCTI_TRY_B); - expect_value(__wrap_dlopen, flags, RTLD_NOW); - will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, TEST_TCTI_TRY_B); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" TEST_TCTI_TRY_B); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); -+ - expect_string(__wrap_dlopen, filename, TEST_TCTI_TRY_C); - expect_value(__wrap_dlopen, flags, RTLD_NOW); - will_return(__wrap_dlopen, TEST_HANDLE); -@@ -208,14 +220,26 @@ test_handle_from_name_fourth_dlopen_success (void **state) - expect_value(__wrap_dlopen, flags, RTLD_NOW); - will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, TEST_TCTI_TRY_C); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); +@@ -191,14 +200,23 @@ + expect_string(__wrap_dlopen, filename, TEST_TCTI_TRY_A); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" TEST_TCTI_TRY_A); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); -+ + expect_string(__wrap_dlopen, filename, TEST_TCTI_TRY_B); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); - + expect_string(__wrap_dlopen, filename, "@PREFIX@" TEST_TCTI_TRY_B); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); -+ - expect_string(__wrap_dlopen, filename, TEST_TCTI_TRY_C); - expect_value(__wrap_dlopen, flags, RTLD_NOW); - will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, TEST_TCTI_TRY_C); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" TEST_TCTI_TRY_C); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); -+ - expect_string(__wrap_dlopen, filename, TEST_TCTI_TRY_D); - expect_value(__wrap_dlopen, flags, RTLD_NOW); - will_return(__wrap_dlopen, TEST_HANDLE); -@@ -234,18 +258,34 @@ test_handle_from_name_fifth_dlopen_success (void **state) - expect_value(__wrap_dlopen, flags, RTLD_NOW); - will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, TEST_TCTI_TRY_D); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); +@@ -216,18 +234,30 @@ + expect_string(__wrap_dlopen, filename, TEST_TCTI_TRY_A); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" TEST_TCTI_TRY_A); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); -+ + expect_string(__wrap_dlopen, filename, TEST_TCTI_TRY_B); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); - + expect_string(__wrap_dlopen, filename, "@PREFIX@" TEST_TCTI_TRY_B); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); -+ + expect_string(__wrap_dlopen, filename, TEST_TCTI_TRY_C); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); - + expect_string(__wrap_dlopen, filename, "@PREFIX@" TEST_TCTI_TRY_C); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); -+ - expect_string(__wrap_dlopen, filename, TEST_TCTI_TRY_D); - expect_value(__wrap_dlopen, flags, RTLD_NOW); - will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, TEST_TCTI_TRY_D); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" TEST_TCTI_TRY_D); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); -+ + expect_string(__wrap_dlopen, filename, TEST_TCTI_TRY_E); - expect_value(__wrap_dlopen, flags, RTLD_NOW); - will_return(__wrap_dlopen, TEST_HANDLE); -@@ -281,22 +321,42 @@ test_get_info_default_success (void **state) - expect_value(__wrap_dlopen, flags, RTLD_NOW); - will_return(__wrap_dlopen, NULL); - -+ expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-default.so"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); -+ will_return(__wrap_dlopen, NULL); -+ - expect_string(__wrap_dlopen, filename, "libtss2-tcti-libtss2-tcti-default.so.so.0"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); - will_return(__wrap_dlopen, NULL); - -+ expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-libtss2-tcti-default.so.so.0"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); -+ will_return(__wrap_dlopen, NULL); -+ - expect_string(__wrap_dlopen, filename, "libtss2-tcti-libtss2-tcti-default.so.so"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); - will_return(__wrap_dlopen, NULL); - -+ expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-libtss2-tcti-default.so.so"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); -+ will_return(__wrap_dlopen, NULL); -+ - expect_string(__wrap_dlopen, filename, "libtss2-libtss2-tcti-default.so.so.0"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); - will_return(__wrap_dlopen, NULL); - -+ expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-libtss2-tcti-default.so.so.0"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); -+ will_return(__wrap_dlopen, NULL); -+ - expect_string(__wrap_dlopen, filename, "libtss2-libtss2-tcti-default.so.so"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); - will_return(__wrap_dlopen, NULL); - -+ expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-libtss2-tcti-default.so.so"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); -+ will_return(__wrap_dlopen, NULL); -+ - expect_string(__wrap_dlopen, filename, "libtss2-tcti-tabrmd.so.0"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); - will_return(__wrap_dlopen, HANDLE); -@@ -321,22 +381,42 @@ test_get_info_default_info_fail (void **state) - expect_value(__wrap_dlopen, flags, RTLD_NOW); - will_return(__wrap_dlopen, NULL); - -+ expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-default.so"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); -+ will_return(__wrap_dlopen, NULL); -+ - expect_string(__wrap_dlopen, filename, "libtss2-tcti-libtss2-tcti-default.so.so.0"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); - will_return(__wrap_dlopen, NULL); - -+ expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-libtss2-tcti-default.so.so.0"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); -+ will_return(__wrap_dlopen, NULL); -+ - expect_string(__wrap_dlopen, filename, "libtss2-tcti-libtss2-tcti-default.so.so"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); - will_return(__wrap_dlopen, NULL); - -+ expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-libtss2-tcti-default.so.so"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); -+ will_return(__wrap_dlopen, NULL); -+ - expect_string(__wrap_dlopen, filename, "libtss2-libtss2-tcti-default.so.so.0"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); - will_return(__wrap_dlopen, NULL); - -+ expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-libtss2-tcti-default.so.so.0"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); -+ will_return(__wrap_dlopen, NULL); -+ - expect_string(__wrap_dlopen, filename, "libtss2-libtss2-tcti-default.so.so"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); - will_return(__wrap_dlopen, NULL); - -+ expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-libtss2-tcti-default.so.so"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); -+ will_return(__wrap_dlopen, NULL); -+ - expect_string(__wrap_dlopen, filename, "libtss2-tcti-tabrmd.so.0"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); - will_return(__wrap_dlopen, HANDLE); -@@ -483,120 +563,225 @@ test_tcti_fail_all (void **state) + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); +@@ -265,22 +295,37 @@ expect_string(__wrap_dlopen, filename, "libtss2-tcti-default.so"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-default.so"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "libtss2-tcti-libtss2-tcti-default.so.so.0"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-libtss2-tcti-default.so.so.0"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "libtss2-tcti-libtss2-tcti-default.so.so"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-libtss2-tcti-default.so.so"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "libtss2-libtss2-tcti-default.so.so.0"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-libtss2-tcti-default.so.so.0"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "libtss2-libtss2-tcti-default.so.so"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-libtss2-tcti-default.so.so"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); ++ will_return(__wrap_dlopen, NULL); + + expect_string(__wrap_dlopen, filename, "libtss2-tcti-tabrmd.so.0"); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); +@@ -306,22 +351,37 @@ + expect_string(__wrap_dlopen, filename, "libtss2-tcti-default.so"); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); ++ expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-default.so"); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); ++ will_return(__wrap_dlopen, NULL); + + expect_string(__wrap_dlopen, filename, "libtss2-tcti-libtss2-tcti-default.so.so.0"); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); ++ expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-libtss2-tcti-default.so.so.0"); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); ++ will_return(__wrap_dlopen, NULL); + + expect_string(__wrap_dlopen, filename, "libtss2-tcti-libtss2-tcti-default.so.so"); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); ++ expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-libtss2-tcti-default.so.so"); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); ++ will_return(__wrap_dlopen, NULL); + + expect_string(__wrap_dlopen, filename, "libtss2-libtss2-tcti-default.so.so.0"); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); ++ expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-libtss2-tcti-default.so.so.0"); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); ++ will_return(__wrap_dlopen, NULL); + + expect_string(__wrap_dlopen, filename, "libtss2-libtss2-tcti-default.so.so"); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); ++ expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-libtss2-tcti-default.so.so"); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); ++ will_return(__wrap_dlopen, NULL); + + expect_string(__wrap_dlopen, filename, "libtss2-tcti-tabrmd.so.0"); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); +@@ -463,120 +523,225 @@ + expect_string(__wrap_dlopen, filename, "libtss2-tcti-default.so"); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); ++ expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-default.so"); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); ++ will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "libtss2-tcti-libtss2-tcti-default.so.so.0"); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); ++ expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-libtss2-tcti-default.so.so.0"); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); ++ will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "libtss2-tcti-libtss2-tcti-default.so.so"); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); ++ expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-libtss2-tcti-default.so.so"); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); ++ will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "libtss2-libtss2-tcti-default.so.so.0"); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); ++ expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-libtss2-tcti-default.so.so.0"); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); ++ will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "libtss2-libtss2-tcti-default.so.so"); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); ++ expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-libtss2-tcti-default.so.so"); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); /* Skip over libtss2-tcti-tabrmd.so */ expect_string(__wrap_dlopen, filename, "libtss2-tcti-tabrmd.so.0"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-tabrmd.so.0"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-tcti-libtss2-tcti-tabrmd.so.0.so.0"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-libtss2-tcti-tabrmd.so.0.so.0"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-tcti-libtss2-tcti-tabrmd.so.0.so"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-libtss2-tcti-tabrmd.so.0.so"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-libtss2-tcti-tabrmd.so.0.so.0"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-libtss2-tcti-tabrmd.so.0.so.0"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-libtss2-tcti-tabrmd.so.0.so"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-libtss2-tcti-tabrmd.so.0.so"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); /* Skip over libtss2-tcti-device.so, /dev/tpmrm0 */ expect_string(__wrap_dlopen, filename, "libtss2-tcti-device.so.0"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-device.so.0"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-tcti-libtss2-tcti-device.so.0.so.0"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-libtss2-tcti-device.so.0.so.0"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-tcti-libtss2-tcti-device.so.0.so"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-libtss2-tcti-device.so.0.so"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-libtss2-tcti-device.so.0.so.0"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-libtss2-tcti-device.so.0.so.0"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-libtss2-tcti-device.so.0.so"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-libtss2-tcti-device.so.0.so"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); /* Skip over libtss2-tcti-device.so, /dev/tpm0 */ expect_string(__wrap_dlopen, filename, "libtss2-tcti-device.so.0"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-device.so.0"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-tcti-libtss2-tcti-device.so.0.so.0"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-libtss2-tcti-device.so.0.so.0"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-tcti-libtss2-tcti-device.so.0.so"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-libtss2-tcti-device.so.0.so"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-libtss2-tcti-device.so.0.so.0"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-libtss2-tcti-device.so.0.so.0"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-libtss2-tcti-device.so.0.so"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-libtss2-tcti-device.so.0.so"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); /* Skip over libtss2-tcti-device.so, /dev/tcm0 */ expect_string(__wrap_dlopen, filename, "libtss2-tcti-device.so.0"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-device.so.0"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-tcti-libtss2-tcti-device.so.0.so.0"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-libtss2-tcti-device.so.0.so.0"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-tcti-libtss2-tcti-device.so.0.so"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-libtss2-tcti-device.so.0.so"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-libtss2-tcti-device.so.0.so.0"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-libtss2-tcti-device.so.0.so.0"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-libtss2-tcti-device.so.0.so"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-libtss2-tcti-device.so.0.so"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); /* Skip over libtss2-tcti-swtpm.so */ expect_string(__wrap_dlopen, filename, "libtss2-tcti-swtpm.so.0"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-swtpm.so.0"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-tcti-libtss2-tcti-swtpm.so.0.so.0"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-libtss2-tcti-swtpm.so.0.so.0"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-tcti-libtss2-tcti-swtpm.so.0.so"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-libtss2-tcti-swtpm.so.0.so"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-libtss2-tcti-swtpm.so.0.so.0"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-libtss2-tcti-swtpm.so.0.so.0"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-libtss2-tcti-swtpm.so.0.so"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-libtss2-tcti-swtpm.so.0.so"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); /* Skip over libtss2-tcti-mssim.so */ expect_string(__wrap_dlopen, filename, "libtss2-tcti-mssim.so.0"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-mssim.so.0"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-tcti-libtss2-tcti-mssim.so.0.so.0"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-libtss2-tcti-mssim.so.0.so.0"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-tcti-libtss2-tcti-mssim.so.0.so"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-libtss2-tcti-mssim.so.0.so"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-libtss2-tcti-mssim.so.0.so.0"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-libtss2-tcti-mssim.so.0.so.0"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-libtss2-tcti-mssim.so.0.so"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-libtss2-tcti-mssim.so.0.so"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); - TSS2_RC r; + TSS2_RC r; TSS2_TCTI_CONTEXT *tcti; -@@ -619,18 +804,33 @@ test_info_from_name_handle_fail (void **state) +@@ -597,18 +762,33 @@ expect_string(__wrap_dlopen, filename, "foo"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "foo"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-tcti-foo.so.0"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-foo.so.0"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-tcti-foo.so"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-foo.so"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-foo.so.0"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-foo.so.0"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-foo.so"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-foo.so"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); - TSS2_RC rc = info_from_name ("foo", &info, &data); - assert_int_equal (rc, TSS2_TCTI_RC_NOT_SUPPORTED); -@@ -741,18 +941,33 @@ test_tctildr_get_info_from_name (void **state) + TSS2_RC rc = info_from_name("foo", &info, &data); + assert_int_equal(rc, TSS2_TCTI_RC_NOT_SUPPORTED); +@@ -719,18 +899,33 @@ expect_string(__wrap_dlopen, filename, "foo"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "foo"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-tcti-foo.so.0"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-foo.so.0"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-tcti-foo.so"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-tcti-foo.so"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-foo.so.0"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-foo.so.0"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); expect_string(__wrap_dlopen, filename, "libtss2-foo.so"); - expect_value(__wrap_dlopen, flags, RTLD_NOW); + expect_int_value(__wrap_dlopen, flags, RTLD_NOW); will_return(__wrap_dlopen, NULL); + expect_string(__wrap_dlopen, filename, "@PREFIX@" "libtss2-foo.so"); -+ expect_value(__wrap_dlopen, flags, RTLD_NOW); ++ expect_int_value(__wrap_dlopen, flags, RTLD_NOW); + will_return(__wrap_dlopen, NULL); - TSS2_RC rc = tctildr_get_info ("foo", &info, &data); - assert_int_equal (rc, TSS2_TCTI_RC_NOT_SUPPORTED); + TSS2_RC rc = tctildr_get_info("foo", &info, &data); + assert_int_equal(rc, TSS2_TCTI_RC_NOT_SUPPORTED); diff --git a/pkgs/development/libraries/tpm2-tss/no-shadow.patch b/pkgs/development/libraries/tpm2-tss/no-shadow.patch deleted file mode 100644 index a42bf06771d0..000000000000 --- a/pkgs/development/libraries/tpm2-tss/no-shadow.patch +++ /dev/null @@ -1,16 +0,0 @@ -diff --git a/configure.ac b/configure.ac -index e2d579b8..0eac4ff3 100644 ---- a/configure.ac -+++ b/configure.ac -@@ -672,9 +672,9 @@ AS_IF([test "$HOSTOS" = "Linux" && test "x$systemd_sysusers" != "xyes"], - AC_CHECK_PROG(adduser, adduser, yes) - AC_CHECK_PROG(addgroup, addgroup, yes) - AS_IF([test "x$addgroup" != "xyes" && test "x$groupadd" != "xyes" ], -- [AC_MSG_ERROR([addgroup or groupadd are needed.])]) -+ [AC_MSG_WARN([addgroup or groupadd are needed.])]) - AS_IF([test "x$adduser" != "xyes" && test "x$useradd" != "xyes" ], -- [AC_MSG_ERROR([adduser or useradd are needed.])])]) -+ [AC_MSG_WARN([adduser or useradd are needed.])])]) - - AC_SUBST([PATH]) - From 154b6af468667d7f84b4b465180f68b4cc441c63 Mon Sep 17 00:00:00 2001 From: Peder Bergebakken Sundt Date: Wed, 29 Jul 2026 18:04:10 +0200 Subject: [PATCH 054/134] python3Packages.unidiff: 0.7.5 -> 1.0.0 Changelog: https://github.com/matiasb/python-unidiff/raw/v1.0.0/HISTORY https://github.com/matiasb/python-unidiff/releases/tag/v1.0.0 they migrated to pyproject.toml, but no change is needed on our end ^^ --- pkgs/development/python-modules/unidiff/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/unidiff/default.nix b/pkgs/development/python-modules/unidiff/default.nix index f3babe48eb5c..f70534eed63f 100644 --- a/pkgs/development/python-modules/unidiff/default.nix +++ b/pkgs/development/python-modules/unidiff/default.nix @@ -8,12 +8,12 @@ buildPythonPackage (finalAttrs: { pname = "unidiff"; - version = "0.7.5"; + version = "1.0.0"; pyproject = true; src = fetchPypi { inherit (finalAttrs) pname version; - sha256 = "2e5f0162052248946b9f0970a40e9e124236bf86c82b70821143a6fc1dea2574"; + sha256 = "sha256-Xl1c+rLcmL6Bm3R0erfZ9a+GlTaeyHELk/mrDwrmpEk="; }; build-system = [ setuptools ]; From 19aff0b47dc7f35d7a520c9455a2363a98d4556d Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 29 Jul 2026 16:52:48 +0000 Subject: [PATCH 055/134] simdjson: 4.6.4 -> 4.6.5 --- pkgs/by-name/si/simdjson/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/si/simdjson/package.nix b/pkgs/by-name/si/simdjson/package.nix index 3cb507297c47..3c6396b93ade 100644 --- a/pkgs/by-name/si/simdjson/package.nix +++ b/pkgs/by-name/si/simdjson/package.nix @@ -7,13 +7,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "simdjson"; - version = "4.6.4"; + version = "4.6.5"; src = fetchFromGitHub { owner = "simdjson"; repo = "simdjson"; tag = "v${finalAttrs.version}"; - hash = "sha256-8oQzsR7DSaNTN9su1uI9tRQ9HvOwXShPwSrnQj8+lGM="; + hash = "sha256-mN8k98+vqhehDvTXoP1wB/V25oKnGQYCVXrvh/rVssw="; }; nativeBuildInputs = [ cmake ]; From 6a0e36fbba26b8f255290a9e484eb18575a6fc35 Mon Sep 17 00:00:00 2001 From: Grimmauld Date: Thu, 30 Jul 2026 00:26:38 +0200 Subject: [PATCH 056/134] nixos/tests/utmp: init --- nixos/tests/all-tests.nix | 1 + nixos/tests/utmp.nix | 65 +++++++++++++++++++++++++++++++ pkgs/by-name/au/audit/package.nix | 2 +- 3 files changed, 67 insertions(+), 1 deletion(-) create mode 100644 nixos/tests/utmp.nix diff --git a/nixos/tests/all-tests.nix b/nixos/tests/all-tests.nix index 93de2aeb2ded..a0641a70af20 100644 --- a/nixos/tests/all-tests.nix +++ b/nixos/tests/all-tests.nix @@ -1833,6 +1833,7 @@ in userborn-static = runTest ./userborn-static.nix; ustreamer = runTest ./ustreamer.nix; utils = import ./utils { inherit runTest; }; + utmp = runTest ./utmp.nix; uwsgi = runTest ./uwsgi.nix; v2ray = runTest ./v2ray.nix; varnish80 = runTest { diff --git a/nixos/tests/utmp.nix b/nixos/tests/utmp.nix new file mode 100644 index 000000000000..c2d80c17cb76 --- /dev/null +++ b/nixos/tests/utmp.nix @@ -0,0 +1,65 @@ +{ lib, ... }: +{ + + name = "utmp"; + + meta = { + maintainers = with lib.maintainers; [ grimmauld ]; + }; + + nodes = { + machine = { + imports = [ ./common/user-account.nix ]; + security.audit.enable = true; + security.auditd.enable = true; + }; + }; + + testScript = '' + import re + + def extract_utmp_fields(line: str) -> tuple[str, str] | None: + m = re.match(r"^\[\d*\]\s*\[\d*\]\s*\[([^\]\s]*)\s*]\s*\[([^\]\s]*)\s*]", line) + if not m: + return None + return m.group(1), m.group(2) + + machine.wait_for_unit("auditd.service") + machine.wait_for_unit("systemd-update-utmp.service") + machine.wait_for_file("/run/utmp") + + with subtest("systemd updated utmp"): + utmp = machine.succeed("utmpdump /run/utmp").strip().split("\n") + print(utmp) + assert extract_utmp_fields(utmp[0]) == ("~~", "reboot") # first entry is the reboot + + with subtest("Test utmp entries are created by logins"): + machine.wait_for_unit("multi-user.target") + machine.wait_until_tty_matches("1", "login: ") + machine.send_chars("alice\n") + machine.wait_until_tty_matches("1", "Password: ") + machine.send_chars("foobar\n") + machine.wait_until_succeeds("pgrep -u alice bash") + utmp = machine.succeed("utmpdump /run/utmp").strip().split("\n") + print(utmp) + assert extract_utmp_fields(utmp[1]) == ("tty1", "alice") # second entry is alice login + machine.send_chars("exit\n") + machine.wait_until_fails("pgrep -u alice bash") + + with subtest("Test utmp entries are cleaned after logout"): + utmp = machine.succeed("utmpdump /run/utmp").strip().split("\n") + print(utmp) + assert extract_utmp_fields(utmp[1]) in [("tty1", ""), ("tty1", "LOGIN")] # tty1 previously in use by alice is now clear + + with subtest("audit logs utmp system boot"): + audit_log = machine.succeed("ausearch -m SYSTEM_BOOT") + print(audit_log) + # audit 4.2.1 truncates too long comm entries, while systemd shortened the entry from `systemd-update-utmp` (truncated) to `update-utmp` + # see also: + # - systemd: https://github.com/systemd/systemd/pull/43144 + # - audit: https://github.com/linux-audit/audit-userspace/commit/d7ea98263ebdb974b383a4057856a5ec339776fc + # accept either fix in this test + assert 'comm="update-utmp"' in audit_log or f'comm="{"systemd-update-utmp"[:15]}"' in audit_log + ''; + +} diff --git a/pkgs/by-name/au/audit/package.nix b/pkgs/by-name/au/audit/package.nix index 657e74647d6f..21abe380fdd2 100644 --- a/pkgs/by-name/au/audit/package.nix +++ b/pkgs/by-name/au/audit/package.nix @@ -153,7 +153,7 @@ stdenv.mkDerivation (finalAttrs: { musl = pkgsMusl.audit or null; static = pkgsStatic.audit or null; pkg-config = testers.testMetaPkgConfig finalAttrs.finalPackage; - inherit (nixosTests) audit audit-testsuite; + inherit (nixosTests) audit audit-testsuite utmp; # Broken on a hardened kernel package = finalAttrs.finalPackage.overrideAttrs (previousAttrs: { pname = previousAttrs.pname + "-test"; From c391d0bec6e291bd4ea5f9856a0d0ec4b524fddb Mon Sep 17 00:00:00 2001 From: Grimmauld Date: Thu, 30 Jul 2026 00:26:51 +0200 Subject: [PATCH 057/134] audit: 4.2 -> 4.2.1 Diff: https://github.com/linux-audit/audit-userspace/compare/v4.2...v4.2.1 Changelog: https://github.com/linux-audit/audit-userspace/releases/tag/v4.2.1 --- pkgs/by-name/au/audit/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/au/audit/package.nix b/pkgs/by-name/au/audit/package.nix index 21abe380fdd2..722eb7039611 100644 --- a/pkgs/by-name/au/audit/package.nix +++ b/pkgs/by-name/au/audit/package.nix @@ -30,13 +30,13 @@ }: stdenv.mkDerivation (finalAttrs: { pname = "audit"; - version = "4.2"; + version = "4.2.1"; src = fetchFromGitHub { owner = "linux-audit"; repo = "audit-userspace"; tag = "v${finalAttrs.version}"; - hash = "sha256-poldhsF+ccutCxK7KE/gYpxa1x3wUQJWoCwU6pGFj6A="; + hash = "sha256-W8VyeOYQGPAvvmQUe3F22u5ldWwIuxrVJ/sXyu0Qrl4="; }; postPatch = '' From 4f3ddb83536cb471870f53827da249ba8dd138e1 Mon Sep 17 00:00:00 2001 From: Grimmauld Date: Thu, 30 Jul 2026 08:24:25 +0200 Subject: [PATCH 058/134] Revert "nixos/systemd: patch to avoid update-utmp failure with audit 4.2" This reverts commit 693e3bc4155787b03d2e36523b43da32b268305c. --- nixos/modules/system/boot/systemd.nix | 22 +--------------------- 1 file changed, 1 insertion(+), 21 deletions(-) diff --git a/nixos/modules/system/boot/systemd.nix b/nixos/modules/system/boot/systemd.nix index 10dd33eac8c2..acfb213b98e0 100644 --- a/nixos/modules/system/boot/systemd.nix +++ b/nixos/modules/system/boot/systemd.nix @@ -259,27 +259,7 @@ in options.systemd = { - package = mkPackageOption pkgs "systemd" { } // { - # audit 4.2 rejects overlong values (max 15 bytes) for the kernel comm. - # systemd attempts to send the full 19 bytes of "systemd-update-utmp", - # and the systemd-update-utmp service fails to start. this patch shortens - # the kernel comm entry to "update-utmp". - # TODO: revert on staging when updating to audit 4.2.1 - # original commit: https://github.com/linux-audit/audit-userspace/commit/d7ea98263ebdb974b383a4057856a5ec339776fc - # switch to truncate: https://github.com/linux-audit/audit-userspace/commit/d7ea98263ebdb974b383a4057856a5ec339776fc - # systemd pr: https://github.com/systemd/systemd/pull/43144 - apply = - pkg: - pkg.overrideAttrs (prevAttrs: { - patches = prevAttrs.patches or [ ] ++ [ - (pkgs.fetchpatch { - name = "systemd-update-utmp-shorten-comm.patch"; - url = "https://github.com/systemd/systemd/commit/b8968c492108506952ab2748c4a44ce32fc9477c.patch"; - hash = "sha256-d0rMssj1+cDw3+KOk8ecjqIIuBhjDixIH+7MJfC+I+M="; - }) - ]; - }); - }; + package = mkPackageOption pkgs "systemd" { }; enableStrictShellChecks = mkEnableOption "" // { description = '' From bf70bb3629afff1ee725b9ae2d985cf7c599f350 Mon Sep 17 00:00:00 2001 From: K900 Date: Thu, 30 Jul 2026 10:35:15 +0300 Subject: [PATCH 059/134] glslang: 16.3.0 -> 16.4.0 Diff: https://github.com/KhronosGroup/glslang/compare/16.3.0...16.4.0 Changelog: https://github.com/KhronosGroup/glslang/blob/16.4.0/CHANGES.md --- pkgs/by-name/gl/glslang/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/gl/glslang/package.nix b/pkgs/by-name/gl/glslang/package.nix index c8b19772c622..9e731fb4f47b 100644 --- a/pkgs/by-name/gl/glslang/package.nix +++ b/pkgs/by-name/gl/glslang/package.nix @@ -12,13 +12,13 @@ }: stdenv.mkDerivation (finalAttrs: { pname = "glslang"; - version = "16.3.0"; + version = "16.4.0"; src = fetchFromGitHub { owner = "KhronosGroup"; repo = "glslang"; tag = finalAttrs.version; - hash = "sha256-wclcJ0NfqFXSUHGVsxjn2I8XxWbrkzOB4WXqsN1XtmE="; + hash = "sha256-nPXwBROAj/zYccM5Lydwws13e/nW96gm+f4218sQhE8="; }; outputs = [ From 5bd2afb11519c502049497cd06e1419898182847 Mon Sep 17 00:00:00 2001 From: K900 Date: Thu, 30 Jul 2026 10:35:28 +0300 Subject: [PATCH 060/134] vulkan-headers: 1.4.350.0 -> 1.4.357.0 Diff: https://github.com/KhronosGroup/Vulkan-Headers/compare/vulkan-sdk-1.4.350.0...vulkan-sdk-1.4.357.0 --- pkgs/by-name/vu/vulkan-headers/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/vu/vulkan-headers/package.nix b/pkgs/by-name/vu/vulkan-headers/package.nix index 956a3725941a..7b1b5e59ebe7 100644 --- a/pkgs/by-name/vu/vulkan-headers/package.nix +++ b/pkgs/by-name/vu/vulkan-headers/package.nix @@ -7,7 +7,7 @@ }: stdenv.mkDerivation (finalAttrs: { pname = "vulkan-headers"; - version = "1.4.350.0"; + version = "1.4.357.0"; # Adding `ninja` here to enable Ninja backend. Otherwise on gcc-14 or # later the build fails as: @@ -24,7 +24,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "KhronosGroup"; repo = "Vulkan-Headers"; rev = "vulkan-sdk-${finalAttrs.version}"; - hash = "sha256-RcUVurC+Rc0MyWpQLaLVmdn7FZO1GWWzTZZAOwvKwb4="; + hash = "sha256-tAYvYx/Mqvf/I177xmx7oLZVc7S7GK3MArY3i+FCYuw="; }; passthru.updateScript = ./update.sh; From 707ceb31f5dcb085fceb0a22977673aba0917d7e Mon Sep 17 00:00:00 2001 From: K900 Date: Thu, 30 Jul 2026 10:35:42 +0300 Subject: [PATCH 061/134] vulkan-loader: 1.4.350.0 -> 1.4.357.0 Diff: https://github.com/KhronosGroup/Vulkan-Loader/compare/vulkan-sdk-1.4.350.0...vulkan-sdk-1.4.357.0 --- pkgs/by-name/vu/vulkan-loader/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/vu/vulkan-loader/package.nix b/pkgs/by-name/vu/vulkan-loader/package.nix index 3987debfef12..ceecfa9ea58f 100644 --- a/pkgs/by-name/vu/vulkan-loader/package.nix +++ b/pkgs/by-name/vu/vulkan-loader/package.nix @@ -17,13 +17,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "vulkan-loader"; - version = "1.4.350.0"; + version = "1.4.357.0"; src = fetchFromGitHub { owner = "KhronosGroup"; repo = "Vulkan-Loader"; rev = "vulkan-sdk-${finalAttrs.version}"; - hash = "sha256-jgibBetbMpqRJ+OJpJgNxgC6phECewNqtla9CCJj56U="; + hash = "sha256-sPv3pA/oclV75CuxsYeIAZ6zH3C6FPmhdI0+djxRExk="; }; patches = [ ./fix-pkgconfig.patch ]; From d72de8be91bef9449963aef09705c53c6b347f9c Mon Sep 17 00:00:00 2001 From: K900 Date: Thu, 30 Jul 2026 10:35:57 +0300 Subject: [PATCH 062/134] vulkan-validation-layers: 1.4.350.0 -> 1.4.357.0 Diff: https://github.com/KhronosGroup/Vulkan-ValidationLayers/compare/vulkan-sdk-1.4.350.0...vulkan-sdk-1.4.357.0 --- pkgs/by-name/vu/vulkan-validation-layers/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/vu/vulkan-validation-layers/package.nix b/pkgs/by-name/vu/vulkan-validation-layers/package.nix index 0ec1066690c0..9d77abaee8b3 100644 --- a/pkgs/by-name/vu/vulkan-validation-layers/package.nix +++ b/pkgs/by-name/vu/vulkan-validation-layers/package.nix @@ -26,13 +26,13 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "vulkan-validation-layers"; - version = "1.4.350.0"; + version = "1.4.357.0"; src = fetchFromGitHub { owner = "KhronosGroup"; repo = "Vulkan-ValidationLayers"; rev = "vulkan-sdk-${finalAttrs.version}"; - hash = "sha256-3qUZP/R29eqTR4IAWH6jBGgmRqE0d1ahcdKbxUOAmTY="; + hash = "sha256-AO1ci608M6CoCrPR6UI2ZjCRlyzOeN8lkimZZODazb0="; }; strictDeps = true; From 61b6744a6eb80c109f101e011490536378ee6153 Mon Sep 17 00:00:00 2001 From: K900 Date: Thu, 30 Jul 2026 10:36:09 +0300 Subject: [PATCH 063/134] vulkan-tools: 1.4.350.0 -> 1.4.357.0 Diff: https://github.com/KhronosGroup/Vulkan-Tools/compare/vulkan-sdk-1.4.350.0...vulkan-sdk-1.4.357.0 --- pkgs/by-name/vu/vulkan-tools/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/vu/vulkan-tools/package.nix b/pkgs/by-name/vu/vulkan-tools/package.nix index f6bbd8c69f5b..be038ba8db3a 100644 --- a/pkgs/by-name/vu/vulkan-tools/package.nix +++ b/pkgs/by-name/vu/vulkan-tools/package.nix @@ -24,13 +24,13 @@ stdenv.mkDerivation rec { pname = "vulkan-tools"; - version = "1.4.350.0"; + version = "1.4.357.0"; src = fetchFromGitHub { owner = "KhronosGroup"; repo = "Vulkan-Tools"; rev = "vulkan-sdk-${version}"; - hash = "sha256-qtEq1ZQT5JXE4bXzy8W053CRF/dOFVV7d7NE9uNYssI="; + hash = "sha256-kbySCu2c5nh6icnPQV6qplfg1gHFnGPEYOG6G6TG8EU="; }; patches = [ ./wayland-scanner.patch ]; From 12c22a4361bbfdf597192e0845160dde398b6f26 Mon Sep 17 00:00:00 2001 From: K900 Date: Thu, 30 Jul 2026 10:36:22 +0300 Subject: [PATCH 064/134] vulkan-tools-lunarg: 1.4.350.0 -> 1.4.357.0 Diff: https://github.com/LunarG/VulkanTools/compare/vulkan-sdk-1.4.350.0...vulkan-sdk-1.4.357.0 --- pkgs/by-name/vu/vulkan-tools-lunarg/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/vu/vulkan-tools-lunarg/package.nix b/pkgs/by-name/vu/vulkan-tools-lunarg/package.nix index 7ccc9cfa11cc..ee130c8cd015 100644 --- a/pkgs/by-name/vu/vulkan-tools-lunarg/package.nix +++ b/pkgs/by-name/vu/vulkan-tools-lunarg/package.nix @@ -27,13 +27,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "vulkan-tools-lunarg"; - version = "1.4.350.0"; + version = "1.4.357.0"; src = fetchFromGitHub { owner = "LunarG"; repo = "VulkanTools"; rev = "vulkan-sdk-${finalAttrs.version}"; - hash = "sha256-tKt/OrGIVfg2/aK9dYPuOB4+05ayUheP9T7Ny5MfWTk="; + hash = "sha256-7nrEXdt0c02D2Z270W45YBwbfzsTwt854tKx+HlTHYA="; }; nativeBuildInputs = [ From 3841ac0223e6388412f79e752bf685dfc4196d31 Mon Sep 17 00:00:00 2001 From: K900 Date: Thu, 30 Jul 2026 10:36:34 +0300 Subject: [PATCH 065/134] vulkan-extension-layer: 1.4.350.0 -> 1.4.357.0 Diff: https://github.com/KhronosGroup/Vulkan-ExtensionLayer/compare/vulkan-sdk-1.4.350.0...vulkan-sdk-1.4.357.0 --- pkgs/by-name/vu/vulkan-extension-layer/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/vu/vulkan-extension-layer/package.nix b/pkgs/by-name/vu/vulkan-extension-layer/package.nix index eb36c08cf7ce..4d4931f7a1cd 100644 --- a/pkgs/by-name/vu/vulkan-extension-layer/package.nix +++ b/pkgs/by-name/vu/vulkan-extension-layer/package.nix @@ -16,13 +16,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "vulkan-extension-layer"; - version = "1.4.350.0"; + version = "1.4.357.0"; src = fetchFromGitHub { owner = "KhronosGroup"; repo = "Vulkan-ExtensionLayer"; rev = "vulkan-sdk-${finalAttrs.version}"; - hash = "sha256-6ZtPp6OqzzppmijIU1/77qcUvwCck/eMZOUh5pSwVc8="; + hash = "sha256-R9hs69SvZeK0w7YF7rhhVp9mRQing3y8NffWfRlXBQI="; }; nativeBuildInputs = [ From d8853b97e78194bf600a4fb25e96d283eeb2702f Mon Sep 17 00:00:00 2001 From: K900 Date: Thu, 30 Jul 2026 10:36:47 +0300 Subject: [PATCH 066/134] vulkan-utility-libraries: 1.4.350.0 -> 1.4.357.0 Diff: https://github.com/KhronosGroup/Vulkan-Utility-Libraries/compare/vulkan-sdk-1.4.350.0...vulkan-sdk-1.4.357.0 --- pkgs/by-name/vu/vulkan-utility-libraries/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/vu/vulkan-utility-libraries/package.nix b/pkgs/by-name/vu/vulkan-utility-libraries/package.nix index 2ea2fc62a0be..7d42890bd2a1 100644 --- a/pkgs/by-name/vu/vulkan-utility-libraries/package.nix +++ b/pkgs/by-name/vu/vulkan-utility-libraries/package.nix @@ -9,13 +9,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "vulkan-utility-libraries"; - version = "1.4.350.0"; + version = "1.4.357.0"; src = fetchFromGitHub { owner = "KhronosGroup"; repo = "Vulkan-Utility-Libraries"; rev = "vulkan-sdk-${finalAttrs.version}"; - hash = "sha256-E0T5eSI30eDB7//6srjwlkX9HfUp1UiyCPWDyK+ZEi8="; + hash = "sha256-WcSiUe3vB7zUO0vpqcVJkKqhnZXz76ApWaoMO49efXg="; }; nativeBuildInputs = [ From a51c06d6804b1f173e75474ffcc81a3c1e6feef2 Mon Sep 17 00:00:00 2001 From: K900 Date: Thu, 30 Jul 2026 10:36:59 +0300 Subject: [PATCH 067/134] vulkan-volk: 1.4.350.0 -> 1.4.357.0 Diff: https://github.com/zeux/volk/compare/vulkan-sdk-1.4.350.0...vulkan-sdk-1.4.357.0 --- pkgs/by-name/vu/vulkan-volk/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/vu/vulkan-volk/package.nix b/pkgs/by-name/vu/vulkan-volk/package.nix index 613867ceee19..7a80de1c0cec 100644 --- a/pkgs/by-name/vu/vulkan-volk/package.nix +++ b/pkgs/by-name/vu/vulkan-volk/package.nix @@ -8,13 +8,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "volk"; - version = "1.4.350.0"; + version = "1.4.357.0"; src = fetchFromGitHub { owner = "zeux"; repo = "volk"; rev = "vulkan-sdk-${finalAttrs.version}"; - hash = "sha256-7JsOWhMTnxeJfsTVgnnHQt5gYJ8tqELT+s3VDHTPof8="; + hash = "sha256-iaKwjY4oJz4IdZ4JYuinOmWIFo6TkF7VikWZRhCWfNk="; }; nativeBuildInputs = [ cmake ]; From 9a925f11f2ac6b1d70a6e052b7669ef05bfa88cd Mon Sep 17 00:00:00 2001 From: K900 Date: Thu, 30 Jul 2026 10:37:11 +0300 Subject: [PATCH 068/134] spirv-headers: 1.4.350.0 -> 1.4.357.0 Diff: https://github.com/KhronosGroup/SPIRV-Headers/compare/vulkan-sdk-1.4.350.0...vulkan-sdk-1.4.357.0 --- pkgs/by-name/sp/spirv-headers/package.nix | 20 ++------------------ 1 file changed, 2 insertions(+), 18 deletions(-) diff --git a/pkgs/by-name/sp/spirv-headers/package.nix b/pkgs/by-name/sp/spirv-headers/package.nix index ddb49d7af092..49436e90d8e9 100644 --- a/pkgs/by-name/sp/spirv-headers/package.nix +++ b/pkgs/by-name/sp/spirv-headers/package.nix @@ -2,36 +2,20 @@ lib, stdenv, fetchFromGitHub, - fetchpatch, cmake, }: stdenv.mkDerivation (finalAttrs: { pname = "spirv-headers"; - version = "1.4.350.0"; + version = "1.4.357.0"; src = fetchFromGitHub { owner = "KhronosGroup"; repo = "SPIRV-Headers"; rev = "vulkan-sdk-${finalAttrs.version}"; - hash = "sha256-nwzhJlkdN8DaExHvnuVc5rZmlrkPYb7Qmj1fx3O5Zpw="; + hash = "sha256-tGY4H3+5p9M5LBK/xxRdMT9CX+qq3e7fPkaftnpjU9I="; }; - patches = [ - # backport to fix glslang tests - # FIXME: remove in next update - (fetchpatch { - url = "https://github.com/KhronosGroup/SPIRV-Headers/commit/1a22b167081842915a1c78a0b5b5a353a23284aa.diff"; - hash = "sha256-XUHfPHnk7bWK4vnozfW/84vaZN+rbFJUZSa6Og8GUAU="; - }) - # Backport new predicated load/store instructions, needed by spirv-llvm-translator - # Not in any tagged releases yet, should exist in the next release after 1.4.350.1. - (fetchpatch { - url = "https://github.com/KhronosGroup/SPIRV-Headers/commit/b8a32968473ce852a809b9de5f04f02a5a9dfa78.patch"; - hash = "sha256-59jmN28ifEhAxySXCpuGZ62jo1WVsRPnVosK8X4yrjM="; - }) - ]; - nativeBuildInputs = [ cmake ]; meta = { From 8b423b6cd2cd9f02d5caaf5c282171f1e21a6bf1 Mon Sep 17 00:00:00 2001 From: K900 Date: Thu, 30 Jul 2026 10:37:27 +0300 Subject: [PATCH 069/134] spirv-cross: 1.4.350.0 -> 1.4.357.0 Diff: https://github.com/KhronosGroup/SPIRV-Cross/compare/vulkan-sdk-1.4.350.0...vulkan-sdk-1.4.357.0 Changelog: https://github.com/KhronosGroup/SPIRV-Cross/releases/tag/vulkan-sdk-1.4.357.0 --- pkgs/by-name/sp/spirv-cross/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/sp/spirv-cross/package.nix b/pkgs/by-name/sp/spirv-cross/package.nix index ed353a8f884a..0ecc74bb557c 100644 --- a/pkgs/by-name/sp/spirv-cross/package.nix +++ b/pkgs/by-name/sp/spirv-cross/package.nix @@ -8,13 +8,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "spirv-cross"; - version = "1.4.350.0"; + version = "1.4.357.0"; src = fetchFromGitHub { owner = "KhronosGroup"; repo = "SPIRV-Cross"; rev = "vulkan-sdk-${finalAttrs.version}"; - hash = "sha256-JdVAS5uVSfe0mOGtyodkgmvgD4of9Amq8PbDSAtgaXc="; + hash = "sha256-HjAVP+yMeybM8VQQO3aKmuxpvjA03EGjKUPWVQKoRuc="; }; nativeBuildInputs = [ From 519130b3256d6a1d69af554de582f9135d1be4fc Mon Sep 17 00:00:00 2001 From: K900 Date: Thu, 30 Jul 2026 10:37:41 +0300 Subject: [PATCH 070/134] spirv-tools: 1.4.350.0 -> 1.4.357.0 Diff: https://github.com/KhronosGroup/SPIRV-Tools/compare/vulkan-sdk-1.4.350.0...vulkan-sdk-1.4.357.0 --- pkgs/by-name/sp/spirv-tools/package.nix | 17 ++--------------- 1 file changed, 2 insertions(+), 15 deletions(-) diff --git a/pkgs/by-name/sp/spirv-tools/package.nix b/pkgs/by-name/sp/spirv-tools/package.nix index 97b842561e42..241551253cc3 100644 --- a/pkgs/by-name/sp/spirv-tools/package.nix +++ b/pkgs/by-name/sp/spirv-tools/package.nix @@ -2,7 +2,6 @@ lib, stdenv, fetchFromGitHub, - fetchpatch, cmake, python3, spirv-headers, @@ -10,30 +9,18 @@ stdenv.mkDerivation (finalAttrs: { pname = "spirv-tools"; - version = "1.4.350.0"; + version = "1.4.357.0"; src = fetchFromGitHub { owner = "KhronosGroup"; repo = "SPIRV-Tools"; rev = "vulkan-sdk-${finalAttrs.version}"; - hash = "sha256-tR3POZH/LXaAljMUS9aHBBvIvlr6o7d6+YUtJCRMS1w="; + hash = "sha256-ne2JF68MJNriPIiA/fRCb6VYH3vWsoyov4S82QQY2AI="; }; patches = [ # https://github.com/KhronosGroup/SPIRV-Tools/pull/6483 ./0001-Fix-generated-pkg-config-modules-with-absolute-insta.patch - - # backport to fix glslang tests - # FIXME: remove in next update - (fetchpatch { - url = "https://github.com/KhronosGroup/SPIRV-Tools/commit/2ec8457ab33d539b6f1fecc998360c0b8b05ed4f.diff"; - hash = "sha256-YHbYBwXMm4rTKpmMW6I3LUafhA4RuNUdXqUBUAXwXpE="; - }) - - (fetchpatch { - url = "https://github.com/KhronosGroup/SPIRV-Tools/commit/0db9162641d9709c63c92a13e66fd88905180e89.diff"; - hash = "sha256-eoS35Zxb+frQTTTNCaZ4TV/QZjaK45mW1OzzIlXQ1C0="; - }) ] # The cmake options are sufficient for turning on static building, but not # for disabling shared building, just trim the shared lib from the CMake From 6877b48880a0791553908e90c6e2824023595b15 Mon Sep 17 00:00:00 2001 From: Sergei Trofimovich Date: Thu, 30 Jul 2026 17:31:07 +0100 Subject: [PATCH 071/134] gbenchmark: constrain `-Wno-error=c2y-extensions` to `clang MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Without the change `gbencmark` will fail the build on upcoming `gcc-17` as: cc1plus: error: ‘-Wno-error=c2y-extensions’: no option ‘-Wc2y-extensions’; did you mean ‘-Wc++20-extensions’? ninja: build stopped: subcommand failed. This happens because `gcc` never suported `-Wc2y-extensions` and `gcc-17` not fails on unrecognized `-W` flags. --- pkgs/by-name/gb/gbenchmark/package.nix | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/pkgs/by-name/gb/gbenchmark/package.nix b/pkgs/by-name/gb/gbenchmark/package.nix index 0c9e020871ed..fffc36fdfbbf 100644 --- a/pkgs/by-name/gb/gbenchmark/package.nix +++ b/pkgs/by-name/gb/gbenchmark/package.nix @@ -53,9 +53,7 @@ stdenv.mkDerivation (finalAttrs: { # This might be a problem with our Clang, as it does not reproduce # with Xcode, but we just work around it by silencing the warning. NIX_CFLAGS_COMPILE = lib.join " " ( - [ - "-Wno-error=c2y-extensions" - ] + lib.optional stdenv.cc.isClang "-Wno-error=c2y-extensions" ++ lib.optional stdenv.cc.isClang "-Wno-c++17-attribute-extensions" ); } From 8a969be9f44de55804cc28231d9a7258448f1f95 Mon Sep 17 00:00:00 2001 From: whispers Date: Thu, 30 Jul 2026 14:48:03 -0400 Subject: [PATCH 072/134] libssh2: apply debian patches for CVE-2026-6603[2345] Fixes: CVE-2026-66032, CVE-2026-66033, CVE-2026-66034, CVE-2026-66035 --- pkgs/by-name/li/libssh2/package.nix | 34 +++++++++++++++++++++++++++++ 1 file changed, 34 insertions(+) diff --git a/pkgs/by-name/li/libssh2/package.nix b/pkgs/by-name/li/libssh2/package.nix index 4237f6d421fa..b7c88dfc5eb7 100644 --- a/pkgs/by-name/li/libssh2/package.nix +++ b/pkgs/by-name/li/libssh2/package.nix @@ -27,18 +27,21 @@ stdenv.mkDerivation (finalAttrs: { # https://github.com/libssh2/libssh2/commit/256d04b60d80bf1190e96b0ad1e91b2174d744b1 ./CVE-2026-7598.patch + # backport of https://github.com/libssh2/libssh2/commit/2dae3024897e1898d389835151f4e9606227721d (fetchurl { name = "CVE-2025-15661.patch"; url = "https://salsa.debian.org/debian/libssh2/-/raw/1d4906e6ebe85a9da2931ba33677ead96a61f07f/debian/patches/CVE-2025-15661.patch"; hash = "sha256-Rz6i/881CbObUDcZbcPlgVPaKizSp6ZRTdmJNJ9HLHE="; }) + # backport of https://github.com/libssh2/libssh2/commit/17626857d20b3c9a1addfa45979dadcee1cd84a4 (fetchurl { name = "CVE-2026-55199.patch"; url = "https://salsa.debian.org/debian/libssh2/-/raw/1d4906e6ebe85a9da2931ba33677ead96a61f07f/debian/patches/CVE-2026-55199.patch"; hash = "sha256-AFZa5kohha62aE0if5ckmAdJ0TZNcjfP32yDznoEhNo="; }) + # backport of https://github.com/libssh2/libssh2/commit/97acf3dfda80c91c3a8c9f2372546301d4a1a7a8 (fetchurl { name = "CVE-2026-55200.patch"; url = "https://salsa.debian.org/debian/libssh2/-/raw/1d4906e6ebe85a9da2931ba33677ead96a61f07f/debian/patches/CVE-2026-55200.patch"; @@ -53,16 +56,47 @@ stdenv.mkDerivation (finalAttrs: { }) # https://github.com/libssh2/libssh2/issues/1925#issuecomment-4938515829 + # backport of https://github.com/libssh2/libssh2/commit/34497525929b9a47f03dfb81887ac896202b7e12 (fetchurl { name = "CVE-2026-58050.patch"; url = "https://raw.githubusercontent.com/JuliaPackaging/Yggdrasil/9404aa5dd96c945a790c425a5f49af19ed2a93b0/L/LibSSH2/LibSSH2%401.11/bundled/patches/CVE-2026-58050-3449752.patch"; hash = "sha256-BZ1ewZgrroev2gkJwdoHCMFJK4wiRmA/Y4tzwaQqBd8="; }) + + # backport of https://github.com/libssh2/libssh2/commit/a9758da45a52bc8c630ec9493804d0c6ea30b24a (fetchurl { name = "CVE-2026-58051.patch"; url = "https://github.com/JuliaPackaging/Yggdrasil/raw/9404aa5dd96c945a790c425a5f49af19ed2a93b0/L/LibSSH2/LibSSH2%401.11/bundled/patches/CVE-2026-58051-a9758da.patch"; hash = "sha256-fduXIH02uwzqWV2RDidZmaDBy51V8yuC4XKlGYacjxg="; }) + + # backport of https://github.com/libssh2/libssh2/commit/5e4776146552d898b9c0e1b313cd093fa8dc92d0 + (fetchurl { + name = "CVE-2026-66032.patch"; + url = "https://salsa.debian.org/debian/libssh2/-/raw/fe2e3c0848f8501bf729d61790360761a20c75f2/debian/patches/CVE-2026-66032.patch"; + hash = "sha256-H6VXhVc7uCFxj/k3Xouyg+8GYpsn/9IecXZrPkzsgks="; + }) + + # backport of https://github.com/libssh2/libssh2/commit/a2ed82d40964bbc0d64cd717aa0a5a892117d2e6 + (fetchurl { + name = "CVE-2026-66033.patch"; + url = "https://salsa.debian.org/debian/libssh2/-/raw/fe2e3c0848f8501bf729d61790360761a20c75f2/debian/patches/CVE-2026-66033.patch"; + hash = "sha256-To2ul9ibaAkn0BWNu7fUbpaqHqEX+juUsBbjA0BGF6s="; + }) + + # backport of https://github.com/libssh2/libssh2/commit/a13bb6c773f0d55ad1628cede57e99803cd898d9 + (fetchurl { + name = "CVE-2026-66034.patch"; + url = "https://salsa.debian.org/debian/libssh2/-/raw/fe2e3c0848f8501bf729d61790360761a20c75f2/debian/patches/CVE-2026-66034.patch"; + hash = "sha256-xYg9qh87KlExI38snAq5E5hF51mIoaJ1wOX9e1uEdmk="; + }) + + # backport of https://github.com/libssh2/libssh2/commit/42e33d81577ed4b95d4b4f6f845e5ee8efe5eeb4 + (fetchurl { + name = "CVE-2026-66035.patch"; + url = "https://salsa.debian.org/debian/libssh2/-/raw/fe2e3c0848f8501bf729d61790360761a20c75f2/debian/patches/CVE-2026-66035.patch"; + hash = "sha256-+Wr9dp+g347pgKaJYRNRx+EXHA3iOKgOO4tjxi7zkD8="; + }) ]; # this could be accomplished by updateAutotoolsGnuConfigScriptsHook, but that causes infinite recursion From f97de6d7cdb4765f43e60fdc7cc2e0e4fb0c02b3 Mon Sep 17 00:00:00 2001 From: Alyssa Ross Date: Thu, 30 Jul 2026 13:57:38 +0200 Subject: [PATCH 073/134] wrapGAppsHook: don't clobber XDG_DATA_DIRS default The wrapper is supposed to transparently add things to XDG_DATA_DIRS, not to take things out of it. But because XDG_DATA_DIRS has an implicit default if unset, and the wrapper set XDG_DATA_DIRS without preserving that default value if it was unset outside the wrapper, that's what it was doing in practice. I've tested that these default paths are not accidentally added if XDG_DATA_DIRS is set outside the wrapper, and that the other directories we want to add to XDG_DATA_DIRS are correctly included in both cases. --- .../setup-hooks/wrap-gapps-hook/wrap-gapps-hook.sh | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/pkgs/build-support/setup-hooks/wrap-gapps-hook/wrap-gapps-hook.sh b/pkgs/build-support/setup-hooks/wrap-gapps-hook/wrap-gapps-hook.sh index ef2c02dff02e..a9b8b393c8da 100644 --- a/pkgs/build-support/setup-hooks/wrap-gapps-hook/wrap-gapps-hook.sh +++ b/pkgs/build-support/setup-hooks/wrap-gapps-hook/wrap-gapps-hook.sh @@ -14,6 +14,16 @@ gappsWrapperArgsHook() { gappsWrapperArgs+=(--set GDK_PIXBUF_MODULE_FILE "$GDK_PIXBUF_MODULE_FILE") fi + # Per the XDG Base Directories Specification, XDG_DATA_DIRS + # defaults to /usr/local/share/:/usr/share/ if unset. To preserve + # the transparency of the wrapper, continue including these paths + # if XDG_DATA_DIRS is not set outside the wrapper. This is + # important for programs to work properly on non-NixOS systems + # where these paths exist. + if [ -n "$GSETTINGS_SCHEMAS_PATH" ] || [ -d "${prefix:?}/share" ]; then + gappsWrapperArgs+=(--set-default XDG_DATA_DIRS /usr/local/share/:/usr/share/) + fi + if [ -n "$GSETTINGS_SCHEMAS_PATH" ]; then gappsWrapperArgs+=(--prefix XDG_DATA_DIRS : "$GSETTINGS_SCHEMAS_PATH") fi From 80d419e9e4cda9900d34f2c23ace2d0388da6ef7 Mon Sep 17 00:00:00 2001 From: Sergei Trofimovich Date: Wed, 29 Jul 2026 22:46:17 +0100 Subject: [PATCH 074/134] shadow: 4.19.4 -> 4.20.0 Changes: https://github.com/shadow-maint/shadow/releases/tag/4.20.0 Co-authored-by: Michael Daniels --- nixos/tests/shadow/system.nix | 2 ++ pkgs/by-name/sh/shadow/package.nix | 35 ++---------------------------- 2 files changed, 4 insertions(+), 33 deletions(-) diff --git a/nixos/tests/shadow/system.nix b/nixos/tests/shadow/system.nix index fbed9be8beba..ddba233e3c5a 100644 --- a/nixos/tests/shadow/system.nix +++ b/nixos/tests/shadow/system.nix @@ -4,6 +4,7 @@ let controllerPython = pkgs.python3.withPackages (ps: [ ps.flaky ps.jc + ps.passlib ps.pytest ps.pytest-mh ps.pytest-ticket @@ -35,6 +36,7 @@ in environment.systemPackages = with pkgs; [ shadow expect + vim ]; users.defaultUserShell = "/bin/sh"; diff --git a/pkgs/by-name/sh/shadow/package.nix b/pkgs/by-name/sh/shadow/package.nix index 51a216b27684..f47476196c2a 100644 --- a/pkgs/by-name/sh/shadow/package.nix +++ b/pkgs/by-name/sh/shadow/package.nix @@ -20,7 +20,6 @@ withTcb ? lib.meta.availableOn stdenv.hostPlatform tcb, tcb, cmocka, - fetchpatch, }: let glibc' = @@ -34,13 +33,13 @@ in stdenv.mkDerivation (finalAttrs: { pname = "shadow"; - version = "4.19.4"; + version = "4.20.0"; src = fetchFromGitHub { owner = "shadow-maint"; repo = "shadow"; tag = finalAttrs.version; - hash = "sha256-vR6dwB3EttGY2DgQ20nOr9kNhF+nsAaBEyklcJAZ20Y="; + hash = "sha256-UafTyfK+pmW2wyAQnvHov9KIorf1HSc6haskfv7auHs="; }; outputs = [ @@ -150,36 +149,6 @@ stdenv.mkDerivation (finalAttrs: { cp -r . $out/ ''; dontBuild = true; - patches = [ - # tests: update useradd tests to expect ID 1001 - (fetchpatch { - name = "update-useradd-tests.patch"; - url = "https://github.com/shadow-maint/shadow/commit/59fbe8415dab17f1e702fbdee96956886c86c737.patch"; - hash = "sha256-U0+NSCd4AfTuHMddTx9+wNtpdJt9t8+D5ApW0OCNgsY="; - stripLen = 2; - }) - # tests: update usermod tests to expect ID 1001 - (fetchpatch { - name = "update-usermod-tests.patch"; - url = "https://github.com/shadow-maint/shadow/commit/91c2ad44ababca2e32cdb71152b0f7f2a7c546be.patch"; - hash = "sha256-v1EEvMfUYoE/ZnBM0k/+kUBK3W1dXr588OQzvFmnXLI="; - stripLen = 2; - }) - # tests: update groupadd tests to expect GID 1001 - (fetchpatch { - name = "update-groupadd-tests.patch"; - url = "https://github.com/shadow-maint/shadow/commit/60568eaec13d1e417f56f0e59ac9573c0e3b9a83.patch"; - hash = "sha256-tLmGeW4Y7UcZqMhW3IXgygKPhCmbZkkW5XTJ7CFz9vg="; - stripLen = 2; - }) - # tests: update newgrp tests to expect GID 1002 - (fetchpatch { - name = "update-newgrp-tests.patch"; - url = "https://github.com/shadow-maint/shadow/commit/49ff9bf33a7b6af57cb26688c3139f014302c9d9.patch"; - hash = "sha256-1760t4Ezd5Ke4PFZ70Njb+k+1kp17aT/7uqu1PswVss="; - stripLen = 2; - }) - ]; postPatch = '' # Replace the gshadow existence check in the test framework with a more NixOS-friendly one, since NixOS does not have /etc/gshadow as a regular file substituteInPlace framework/hosts/shadow.py \ From fd093df307236f3c2c9a4d4ab6d8a01d65bcbe26 Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Sun, 26 Jul 2026 12:23:30 -0400 Subject: [PATCH 075/134] coreutils: move to pkgs/by-name --- .../co}/coreutils/CVE-2026-56391.patch | 0 .../co}/coreutils/CVE-2026-56392.patch | 0 .../default.nix => by-name/co/coreutils/package.nix} | 0 pkgs/top-level/all-packages.nix | 11 +++++------ 4 files changed, 5 insertions(+), 6 deletions(-) rename pkgs/{tools/misc => by-name/co}/coreutils/CVE-2026-56391.patch (100%) rename pkgs/{tools/misc => by-name/co}/coreutils/CVE-2026-56392.patch (100%) rename pkgs/{tools/misc/coreutils/default.nix => by-name/co/coreutils/package.nix} (100%) diff --git a/pkgs/tools/misc/coreutils/CVE-2026-56391.patch b/pkgs/by-name/co/coreutils/CVE-2026-56391.patch similarity index 100% rename from pkgs/tools/misc/coreutils/CVE-2026-56391.patch rename to pkgs/by-name/co/coreutils/CVE-2026-56391.patch diff --git a/pkgs/tools/misc/coreutils/CVE-2026-56392.patch b/pkgs/by-name/co/coreutils/CVE-2026-56392.patch similarity index 100% rename from pkgs/tools/misc/coreutils/CVE-2026-56392.patch rename to pkgs/by-name/co/coreutils/CVE-2026-56392.patch diff --git a/pkgs/tools/misc/coreutils/default.nix b/pkgs/by-name/co/coreutils/package.nix similarity index 100% rename from pkgs/tools/misc/coreutils/default.nix rename to pkgs/by-name/co/coreutils/package.nix diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 6d1176e60ba4..b235d4e5aa23 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -1845,12 +1845,11 @@ with pkgs; comet-gog_heroic = callPackage ../by-name/co/comet-gog/package.nix { comet-gog_kind = "heroic"; }; - coreutils = callPackage ../tools/misc/coreutils { }; - - # The coreutils above are built with dependencies from - # bootstrapping. We cannot override it here, because that pulls in - # openssl from the previous stage as well. - coreutils-full = callPackage ../tools/misc/coreutils { minimal = false; }; + # The `coreutils` package (in pkgs/by-name) is built with dependencies from + # bootstrapping. We cannot override it for `coreutils-full`, because that + # pulls in openssl from the previous stage as well. + # `coreutils-prefixed` does not use openssl, though, so it can be overridden. + coreutils-full = callPackage ../by-name/co/coreutils/package.nix { minimal = false; }; coreutils-prefixed = coreutils.override { withPrefix = true; singleBinary = false; From f97f3da1e7ac8ee8f318569246fbbe9bd9eb84d5 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Thu, 30 Jul 2026 20:11:11 -0400 Subject: [PATCH 076/134] moltenvk: 1.4.1 -> 1.4.2 https://github.com/KhronosGroup/MoltenVK/releases/tag/v1.4.2 --- pkgs/by-name/mo/moltenvk/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/mo/moltenvk/package.nix b/pkgs/by-name/mo/moltenvk/package.nix index d39bb52b35e9..adc664b83fe8 100644 --- a/pkgs/by-name/mo/moltenvk/package.nix +++ b/pkgs/by-name/mo/moltenvk/package.nix @@ -21,7 +21,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "MoltenVK"; - version = "1.4.1"; + version = "1.4.2"; strictDeps = true; @@ -47,7 +47,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "KhronosGroup"; repo = "MoltenVK"; rev = "v${finalAttrs.version}"; - hash = "sha256-7S10p/XrQ/oMXuCnOU6gqnWMGMfP5vhimec1ThxmuIE="; + hash = "sha256-iyYxuWZZfk2W3DW9OX3m77RLk0e8GTTpEV3Th7mIrXY="; }; postPatch = '' @@ -55,7 +55,7 @@ stdenv.mkDerivation (finalAttrs: { while IFS= read -d "" proj; do echo "Updating deployment target to ${stdenv.hostPlatform.darwinMinVersion}: $proj" substituteInPlace "$proj" \ - --replace-fail 'MACOSX_DEPLOYMENT_TARGET = 11.0' "MACOSX_DEPLOYMENT_TARGET = $MACOSX_DEPLOYMENT_TARGET" + --replace-fail 'MACOSX_DEPLOYMENT_TARGET = 12.0' "MACOSX_DEPLOYMENT_TARGET = $MACOSX_DEPLOYMENT_TARGET" done < <(grep -Z -rl --include=project.pbxproj MACOSX_DEPLOYMENT_TARGET) # Move `mvkGitRevDerived.h` to a stable location From 23c0677f59016a07045685bd32470d40569c086b Mon Sep 17 00:00:00 2001 From: Dmitry Bogatov Date: Thu, 23 Jul 2026 18:44:19 +0000 Subject: [PATCH 077/134] pkgsStatic.libmpack: fix build --- pkgs/by-name/li/libmpack/package.nix | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/pkgs/by-name/li/libmpack/package.nix b/pkgs/by-name/li/libmpack/package.nix index 3e50880ecde5..ca0a865dd807 100644 --- a/pkgs/by-name/li/libmpack/package.nix +++ b/pkgs/by-name/li/libmpack/package.nix @@ -15,6 +15,10 @@ stdenv.mkDerivation (finalAttrs: { sha256 = "0rai5djdkjz7bsn025k5489in7r1amagw1pib0z4qns6b52kiar2"; }; + preBuild = lib.optionalString stdenv.hostPlatform.isStatic '' + mkdir -p build/release/src build/release/test/deps/tap + ''; + makeFlags = [ "LIBTOOL=${libtool}/bin/libtool" "PREFIX=$(out)" From f048aa98ac4b8aa747f7e4fe3bd87c3e13af4fda Mon Sep 17 00:00:00 2001 From: Marcin Serwin Date: Sat, 1 Aug 2026 10:44:48 +0200 Subject: [PATCH 078/134] gn: enable strictDeps and __structuredAttrs Signed-off-by: Marcin Serwin --- pkgs/by-name/gn/gn/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/gn/gn/package.nix b/pkgs/by-name/gn/gn/package.nix index f640662eedf4..7dbeec3a97fe 100644 --- a/pkgs/by-name/gn/gn/package.nix +++ b/pkgs/by-name/gn/gn/package.nix @@ -36,6 +36,9 @@ stdenv.mkDerivation { ''; }; + strictDeps = true; + __structuredAttrs = true; + nativeBuildInputs = [ ninja python3 From f49b48c48e3047f02a9d7cb9ad5577ca44b37014 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Gutyina=20Gerg=C5=91?= Date: Sat, 1 Aug 2026 19:23:19 +0200 Subject: [PATCH 079/134] zulu: enable __structuredAttrs and strictDeps --- pkgs/development/compilers/zulu/common.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/development/compilers/zulu/common.nix b/pkgs/development/compilers/zulu/common.nix index 46724ffea83c..88b0f98aa0f8 100644 --- a/pkgs/development/compilers/zulu/common.nix +++ b/pkgs/development/compilers/zulu/common.nix @@ -81,6 +81,9 @@ let pname = "zulu-${javaPackage}"; version = dist.jdkVersion; + __structuredAttrs = true; + strictDeps = true; + src = fetchurl { url = "https://cdn.azul.com/zulu/bin/zulu${dist.zuluVersion}-${javaPackage}${dist.jdkVersion}-${platform}_${arch}.tar.gz"; inherit (dist) hash; From d3ef7cf1b070cc195cc842abf86eae3ea4929b7c Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Sat, 1 Aug 2026 15:29:49 -0400 Subject: [PATCH 080/134] python3Packages.meson-python: rm outdated preCheck --- .../python-modules/meson-python/default.nix | 12 ------------ 1 file changed, 12 deletions(-) diff --git a/pkgs/development/python-modules/meson-python/default.nix b/pkgs/development/python-modules/meson-python/default.nix index 4ed430f34689..b618b5a5856a 100644 --- a/pkgs/development/python-modules/meson-python/default.nix +++ b/pkgs/development/python-modules/meson-python/default.nix @@ -51,18 +51,6 @@ buildPythonPackage rec { dontUseCmakeConfigure = true; - # meson-python respectes MACOSX_DEPLOYMENT_TARGET, but compares it with the - # actual platform version during tests, which mismatches. - # https://github.com/mesonbuild/meson-python/issues/760 - # FIXME: drop in 0.19.0 - preCheck = - if stdenv.hostPlatform.isDarwin then - '' - unset MACOSX_DEPLOYMENT_TARGET - '' - else - null; - setupHooks = [ ./add-build-flags.sh ]; meta = { From 8d9f27a18773794e07c89d56e442bde19da651a8 Mon Sep 17 00:00:00 2001 From: Sergei Trofimovich Date: Sat, 1 Aug 2026 22:05:03 +0100 Subject: [PATCH 081/134] llhttp: 9.4.2 -> 9.4.3 Changes: https://github.com/nodejs/llhttp/releases/tag/release%2Fv9.4.3 --- pkgs/by-name/ll/llhttp/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ll/llhttp/package.nix b/pkgs/by-name/ll/llhttp/package.nix index 4487a4518360..a1909b67b458 100644 --- a/pkgs/by-name/ll/llhttp/package.nix +++ b/pkgs/by-name/ll/llhttp/package.nix @@ -11,13 +11,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "llhttp"; - version = "9.4.2"; + version = "9.4.3"; src = fetchFromGitHub { owner = "nodejs"; repo = "llhttp"; tag = "release/v${finalAttrs.version}"; - hash = "sha256-LS8HS8CnXJ3X8WlIvtxBLc0h1wLL/HmTqZWHlvBjTEo="; + hash = "sha256-wz87FgdZn0vtdlTWOZL5/Ujhs/uzSwFMHzQ6D9S7dH8="; }; outputs = [ From 02309509a5ba66f1b76f9af721f0ea1e5252b866 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 2 Aug 2026 01:50:36 +0000 Subject: [PATCH 082/134] hwdata: 0.409 -> 0.410 --- pkgs/by-name/hw/hwdata/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/hw/hwdata/package.nix b/pkgs/by-name/hw/hwdata/package.nix index e88507d495f7..35e01d9db4ed 100644 --- a/pkgs/by-name/hw/hwdata/package.nix +++ b/pkgs/by-name/hw/hwdata/package.nix @@ -6,13 +6,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "hwdata"; - version = "0.409"; + version = "0.410"; src = fetchFromGitHub { owner = "vcrhonek"; repo = "hwdata"; rev = "v${finalAttrs.version}"; - hash = "sha256-WJ7oe94rTb+gzuawafpx7YyNTUzZe7ZWE0ZWWQKoyCA="; + hash = "sha256-9yw0z1fTcUjb2oWSFj91wY3W8GgPDqnqFMTpoR36mak="; }; doCheck = false; # this does build machine-specific checks (e.g. enumerates PCI bus) From b9d04fdfe732063e5d0b8395011cedb95a3b9741 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Sun, 2 Aug 2026 21:54:13 +0200 Subject: [PATCH 083/134] file: enable structuredAttrs --- pkgs/tools/misc/file/default.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/tools/misc/file/default.nix b/pkgs/tools/misc/file/default.nix index 0fae703c4c4a..99786b8e4dd7 100644 --- a/pkgs/tools/misc/file/default.nix +++ b/pkgs/tools/misc/file/default.nix @@ -58,6 +58,8 @@ stdenv.mkDerivation (finalAttrs: { passthru.tests.pkg-config = testers.testMetaPkgConfig finalAttrs.finalPackage; + __structuredAttrs = true; + meta = { homepage = "https://darwinsys.com/file"; description = "Program that shows the type of files"; From 50f56da2541d6ac0a9b304a237201d2ad256aa16 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Mon, 3 Aug 2026 01:05:42 +0200 Subject: [PATCH 084/134] libxcrypt: enable structuredAttrs --- pkgs/development/libraries/libxcrypt/default.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/development/libraries/libxcrypt/default.nix b/pkgs/development/libraries/libxcrypt/default.nix index 4387d24a61e4..c648cc46383a 100644 --- a/pkgs/development/libraries/libxcrypt/default.nix +++ b/pkgs/development/libraries/libxcrypt/default.nix @@ -97,6 +97,8 @@ stdenv.mkDerivation (finalAttrs: { ]; }; + __structuredAttrs = true; + meta = { changelog = "https://github.com/besser82/libxcrypt/blob/v${finalAttrs.version}/NEWS"; description = "Extended crypt library for descrypt, md5crypt, bcrypt, and others"; From 930c79a9b26f7412cb7ffe33206dad378b162992 Mon Sep 17 00:00:00 2001 From: Stefan Frijters Date: Mon, 3 Aug 2026 01:56:42 +0200 Subject: [PATCH 085/134] which: enable structuredAttrs --- pkgs/by-name/wh/which/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/wh/which/package.nix b/pkgs/by-name/wh/which/package.nix index 6c28c95eb844..51043d18ab47 100644 --- a/pkgs/by-name/wh/which/package.nix +++ b/pkgs/by-name/wh/which/package.nix @@ -31,6 +31,8 @@ stdenv.mkDerivation (finalAttrs: { "man" ]; + __structuredAttrs = true; + meta = { homepage = "https://www.gnu.org/software/which/"; description = "Shows the full path of (shell) commands"; From ab7bf6b39e5102291e0fece78b180cf0d48addaf Mon Sep 17 00:00:00 2001 From: Marie Ramlow Date: Mon, 3 Aug 2026 13:03:14 +0200 Subject: [PATCH 086/134] zxing-cpp: enable old and new writers See https://github.com/zxing-cpp/zxing-cpp/releases/tag/v3.0.1 > It is generally advised for package maintainers to use the BOTH config option during the 3.0 release cycle to allow client applications (like e.g. LibreOffice) to work until they switch to the new API. --- pkgs/by-name/zx/zxing-cpp/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/zx/zxing-cpp/package.nix b/pkgs/by-name/zx/zxing-cpp/package.nix index 182630f30259..144452f524bf 100644 --- a/pkgs/by-name/zx/zxing-cpp/package.nix +++ b/pkgs/by-name/zx/zxing-cpp/package.nix @@ -38,6 +38,7 @@ stdenv.mkDerivation (finalAttrs: { "-DZXING_DEPENDENCIES=LOCAL" "-DZXING_EXAMPLES=OFF" "-DZXING_USE_BUNDLED_ZINT=OFF" + (lib.cmakeFeature "ZXING_WRITERS" "BOTH") ]; passthru = { From 8d4e4d3de602b229ee27752bde89d228a9ba3916 Mon Sep 17 00:00:00 2001 From: Marie Ramlow Date: Mon, 3 Aug 2026 13:43:25 +0200 Subject: [PATCH 087/134] zxing-cpp: 3.0.2 -> 3.1.1 Diff: https://github.com/zxing-cpp/zxing-cpp/compare/v3.0.2...v3.1.1 Changelog: https://github.com/zxing-cpp/zxing-cpp/releases/tag/refs/tags/v3.1.1 --- pkgs/by-name/zx/zxing-cpp/package.nix | 4 +- .../python-modules/zxing-cpp/default.nix | 37 ++++++++++--------- 2 files changed, 21 insertions(+), 20 deletions(-) diff --git a/pkgs/by-name/zx/zxing-cpp/package.nix b/pkgs/by-name/zx/zxing-cpp/package.nix index 144452f524bf..8a6b3e6b0a3e 100644 --- a/pkgs/by-name/zx/zxing-cpp/package.nix +++ b/pkgs/by-name/zx/zxing-cpp/package.nix @@ -12,13 +12,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "zxing-cpp"; - version = "3.0.2"; + version = "3.1.1"; src = fetchFromGitHub { owner = "zxing-cpp"; repo = "zxing-cpp"; tag = "v${finalAttrs.version}"; - hash = "sha256-ZtjvHBnuPJkc9kU998jH7IPlX3jF/RGtLNWDzsb0v4A="; + hash = "sha256-dCqn2qYQGHY/nmwwkgd4uGoKp0YeQxWiHpS0Hhsm+UE="; }; strictDeps = true; diff --git a/pkgs/development/python-modules/zxing-cpp/default.nix b/pkgs/development/python-modules/zxing-cpp/default.nix index 47e30e3667a2..d12b3db74505 100644 --- a/pkgs/development/python-modules/zxing-cpp/default.nix +++ b/pkgs/development/python-modules/zxing-cpp/default.nix @@ -1,14 +1,16 @@ { + lib, buildPythonPackage, cmake, - setuptools-scm, + ninja, + scikit-build-core, numpy, pillow, - pybind11, + nanobind, libzxing-cpp, - pyprojectVersionPatchHook, pytestCheckHook, libzint, + python, }: buildPythonPackage { @@ -18,32 +20,31 @@ buildPythonPackage { sourceRoot = "${libzxing-cpp.src.name}/wrappers/python"; - # we don't need pybind11 in the root environment - # https://pybind11.readthedocs.io/en/stable/installing.html#include-with-pypi - postPatch = '' - substituteInPlace pyproject.toml \ - --replace-fail "pybind11[global]" "pybind11" - - substituteInPlace setup.py \ - --replace-fail "cfg = 'Debug' if self.debug else 'Release'" "cfg = 'Release'" \ - --replace-fail "f'-DPython_EXECUTABLE={sys.executable}'," "f'-DPython_EXECUTABLE={sys.executable}', '-DZXING_DEPENDENCIES=LOCAL', '-DZXING_USE_BUNDLED_ZINT=OFF'," - ''; - dontUseCmakeConfigure = true; + env = { + nanobind_DIR = "${nanobind}/${python.sitePackages}/nanobind/cmake"; + }; + + cmakeFlags = [ + (lib.cmakeBool "ZXING_USE_BUNDLED_ZINT" false) + ]; + build-system = [ - setuptools-scm - pybind11 + scikit-build-core + nanobind ]; dependencies = [ numpy ]; nativeBuildInputs = [ cmake - pyprojectVersionPatchHook + ninja ]; - buildInputs = [ libzint ]; + buildInputs = [ + libzint + ]; nativeCheckInputs = [ pillow From 9991ae9e257d42729e8fada9bdb26766e1da9e20 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 3 Aug 2026 12:35:11 +0000 Subject: [PATCH 088/134] ucx: 1.21.0 -> 1.22.0 --- pkgs/by-name/uc/ucx/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/uc/ucx/package.nix b/pkgs/by-name/uc/ucx/package.nix index 2cfb1d498aad..66a2e8e9f2f8 100644 --- a/pkgs/by-name/uc/ucx/package.nix +++ b/pkgs/by-name/uc/ucx/package.nix @@ -42,7 +42,7 @@ stdenv.mkDerivation (finalAttrs: { strictDeps = true; pname = "ucx"; - version = "1.21.0"; + version = "1.22.0"; src = fetchFromGitHub { owner = "openucx"; @@ -51,7 +51,7 @@ stdenv.mkDerivation (finalAttrs: { # Otherwise compilation fails with: # fatal error: gpunetio/common/doca_gpunetio_verbs_def.h: No such file or directory fetchSubmodules = true; - hash = "sha256-Td6L5wXDadIbHfk251bj6k9J3kIjqCYVx5lDso/u76M="; + hash = "sha256-R/uUjkYLPtY9c3vZWrkzKaSgK9Z/cppJCwQ1V1cuwPc="; }; postPatch = '' From d14174cf76b08f145215940c72af608cd8a956e3 Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Mon, 3 Aug 2026 15:49:45 +0200 Subject: [PATCH 089/134] nodejs_24: 24.18.1 -> 24.19.0 --- pkgs/development/web/nodejs/v24.nix | 21 ++++++--------------- 1 file changed, 6 insertions(+), 15 deletions(-) diff --git a/pkgs/development/web/nodejs/v24.nix b/pkgs/development/web/nodejs/v24.nix index 262990f1826e..578c94262c53 100644 --- a/pkgs/development/web/nodejs/v24.nix +++ b/pkgs/development/web/nodejs/v24.nix @@ -29,22 +29,13 @@ let [ ]; in buildNodejs { - version = "24.18.1"; - sha256 = "86d40d594bbdfcf69009a62fdf43cb19ae72b6cb5822d2bdd8349c5a1b2fa628"; + version = "24.19.0"; + sha256 = "f6d95e10a0431ee1067fc6aabe9f762908b4716dd35324e1ddb4b1466b76659f"; patches = - ( - if (stdenv.hostPlatform.emulatorAvailable buildPackages) then - [ - ./configure-emulator.patch - ] - else - [ - (fetchpatch2 { - url = "https://raw.githubusercontent.com/buildroot/buildroot/2f0c31bffdb59fb224387e35134a6d5e09a81d57/package/nodejs/nodejs-src/0003-include-obj-name-in-shared-intermediate.patch"; - hash = "sha256-3g4aS+NmmUYNOYRNc6UMJKYoaTlpP5Knt9UHegx+o0Y="; - }) - ] - ) + (lib.optional (!(stdenv.hostPlatform.emulatorAvailable buildPackages)) (fetchpatch2 { + url = "https://raw.githubusercontent.com/buildroot/buildroot/2f0c31bffdb59fb224387e35134a6d5e09a81d57/package/nodejs/nodejs-src/0003-include-obj-name-in-shared-intermediate.patch"; + hash = "sha256-3g4aS+NmmUYNOYRNc6UMJKYoaTlpP5Knt9UHegx+o0Y="; + })) ++ lib.optionals (stdenv.hostPlatform != stdenv.buildPlatform && stdenv.hostPlatform.isFreeBSD) [ # This patch is concerning. # https://github.com/nodejs/node/issues/54576 From 1371c6fc0f0c877b25a19d7ae1a35d95ebc7df27 Mon Sep 17 00:00:00 2001 From: Gerhard Schwanzer Date: Mon, 3 Aug 2026 15:57:31 +0200 Subject: [PATCH 090/134] python3Packages.gitpython: 3.1.51 -> 3.1.57 Includes the security fixes published in GitPython 3.1.52 through 3.1.57. https://redirect.github.com/gitpython-developers/GitPython/blob/3.1.57/doc/source/changes.rst Assisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol) --- pkgs/development/python-modules/gitpython/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/gitpython/default.nix b/pkgs/development/python-modules/gitpython/default.nix index d612c47d5830..a2a183f6e448 100644 --- a/pkgs/development/python-modules/gitpython/default.nix +++ b/pkgs/development/python-modules/gitpython/default.nix @@ -10,14 +10,14 @@ buildPythonPackage (finalAttrs: { pname = "gitpython"; - version = "3.1.51"; + version = "3.1.57"; pyproject = true; src = fetchFromGitHub { owner = "gitpython-developers"; repo = "GitPython"; tag = finalAttrs.version; - hash = "sha256-c8tjBvWjVR7krR59Tfx5jKoJc/fcLWVt5D4xk15DvP4="; + hash = "sha256-pCGDKwIefGqx/UJaVqrsofc0t+ntqZRPMhsdbK2XBB0="; }; postPatch = '' From 6c0c69ed62712c46c5eb5e58b6aa92b37e4e6885 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Mon, 3 Aug 2026 15:25:36 -0700 Subject: [PATCH 091/134] libadwaita: 1.9.2 -> 1.9.3 Diff: https://gitlab.gnome.org/GNOME/libadwaita/-/compare/1.9.2...1.9.3 Changelog: https://gitlab.gnome.org/GNOME/libadwaita/-/blob/1.9.3/NEWS --- pkgs/by-name/li/libadwaita/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/li/libadwaita/package.nix b/pkgs/by-name/li/libadwaita/package.nix index fdad6431655b..c158da4ee9af 100644 --- a/pkgs/by-name/li/libadwaita/package.nix +++ b/pkgs/by-name/li/libadwaita/package.nix @@ -23,7 +23,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "libadwaita"; - version = "1.9.2"; + version = "1.9.3"; outputs = [ "out" @@ -37,7 +37,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "GNOME"; repo = "libadwaita"; tag = finalAttrs.version; - hash = "sha256-XKKjnZz4CII6w9fKFptPK3aTNa5eMfyE7rcerbgaDco="; + hash = "sha256-1V3L10YgRnOoJud/lybfSj2AYOY0kRAJdfamJg+S1fo="; }; depsBuildBuild = [ From 2a0a9dff4087b0512562509ae01b37942fc75b99 Mon Sep 17 00:00:00 2001 From: Brian McGillion Date: Tue, 28 Jul 2026 13:14:30 +0400 Subject: [PATCH 092/134] graphify: 0.4.23 -> 0.9.28 The project moved from safishamsi/graphify to Graphify-Labs/graphify; repoint src and homepage at the new location. 0.9.x adds numpy and rapidfuzz as runtime dependencies, and four more tree-sitter grammars (bash, fortran, groovy, json). Four of the grammar bindings need pythonRelaxDeps because python3Packages.tree-sitter-grammars tracks the grammar repositories, whose versions drift from the pins declared upstream. The pdf extra swapped html2text for markdownify; anthropic, bedrock, chinese, openai and postgres extras are new and all resolvable in nixpkgs. falkordb has no nixpkgs package, so that extra is left out. Set dontCheckPythonMetadata: the attribute and the command are `graphify`, but upstream publishes the distribution as `graphifyy`, and pythonMetadataCheckPhase resolves the distribution by `pname`. The plain build does not run that phase, but any consumer does, e.g. nix-build -E 'with import ./. {}; python3.withPackages (_: [ (python3.pkgs.toPythonModule graphify) ])' => PackageNotFoundError: No package metadata was found for graphify Changelog: https://github.com/Graphify-Labs/graphify/blob/v0.9.28/CHANGELOG.md Signed-off-by: Brian McGillion --- pkgs/by-name/gr/graphify/package.nix | 55 +++++++++++++++++++++++++--- 1 file changed, 50 insertions(+), 5 deletions(-) diff --git a/pkgs/by-name/gr/graphify/package.nix b/pkgs/by-name/gr/graphify/package.nix index 8c06ea6fd493..4b6a64684572 100644 --- a/pkgs/by-name/gr/graphify/package.nix +++ b/pkgs/by-name/gr/graphify/package.nix @@ -8,34 +8,49 @@ python3Packages.buildPythonApplication rec { __structuredAttrs = true; pname = "graphify"; - version = "0.4.23"; + version = "0.9.28"; pyproject = true; src = fetchFromGitHub { owner = "Graphify-Labs"; repo = "graphify"; tag = "v${version}"; - hash = "sha256-QEzB1tFBqGhpmI7oudMRC1Ia0CDcm+GYt6AgxMA5zDo="; + hash = "sha256-iu/ARF1ylyrDUWke70kLpji4azfIeBSDSQ6uS+CKYiw="; }; build-system = [ python3.pkgs.setuptools ]; + # The bindings in python3Packages.tree-sitter-grammars track the grammar + # repos, whose versions drift from the pins upstream declares. + pythonRelaxDeps = [ + "tree-sitter-fortran" + "tree-sitter-groovy" + "tree-sitter-julia" + "tree-sitter-kotlin" + ]; + dependencies = with python3.pkgs; [ networkx + numpy + rapidfuzz tree-sitter ] ++ (with python3.pkgs.tree-sitter-grammars; [ + tree-sitter-bash tree-sitter-c tree-sitter-c-sharp tree-sitter-cpp tree-sitter-elixir + tree-sitter-fortran tree-sitter-go + tree-sitter-groovy tree-sitter-java tree-sitter-javascript + tree-sitter-json tree-sitter-julia tree-sitter-kotlin tree-sitter-lua @@ -53,11 +68,21 @@ python3Packages.buildPythonApplication rec { ]); optional-dependencies = with python3.pkgs; { + anthropic = [ + anthropic + ]; + bedrock = [ + boto3 + ]; + chinese = [ + jieba + ]; leiden = [ graspologic ]; mcp = [ mcp + starlette ]; neo4j = [ neo4j @@ -66,10 +91,17 @@ python3Packages.buildPythonApplication rec { openpyxl python-docx ]; + openai = [ + openai + tiktoken + ]; pdf = [ - html2text + markdownify pypdf ]; + postgres = [ + psycopg + ]; svg = [ matplotlib ]; @@ -82,11 +114,24 @@ python3Packages.buildPythonApplication rec { ]; }; + pythonImportsCheck = [ "graphify" ]; + + # The attribute and the command are `graphify`, but upstream publishes the + # distribution as `graphifyy`. pythonMetadataCheckPhase resolves the + # distribution by `pname`, so it cannot find it: + # nix-build -E 'with import ./. {}; + # python3.withPackages (_: [ (python3.pkgs.toPythonModule graphify) ])' + # => PackageNotFoundError: No package metadata was found for graphify + dontCheckPythonMetadata = true; + meta = { description = "AI coding assistant skill. Turn any folder of code, docs, papers, images, or videos into a queryable knowledge graph."; homepage = "https://github.com/Graphify-Labs/graphify"; - changelog = "https://github.com/Graphify-Labs/graphify/blob/${src.rev}/CHANGELOG.md"; - license = lib.licenses.mit; + changelog = "https://github.com/Graphify-Labs/graphify/blob/${src.tag}/CHANGELOG.md"; + license = with lib.licenses; [ + asl20 + mit + ]; maintainers = with lib.maintainers; [ stunkymonkey ]; mainProgram = "graphify"; }; From 98f1bcdc7d3fd51ada7d3a08d2e96886bb046a1e Mon Sep 17 00:00:00 2001 From: Evan Porter Date: Sun, 19 Jul 2026 15:15:26 -0700 Subject: [PATCH 093/134] fmt_12: bump version from 12.1.0 -> 12.2.0 --- pkgs/development/libraries/fmt/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/libraries/fmt/default.nix b/pkgs/development/libraries/fmt/default.nix index 538d53284787..60f3401a5c39 100644 --- a/pkgs/development/libraries/fmt/default.nix +++ b/pkgs/development/libraries/fmt/default.nix @@ -103,7 +103,7 @@ in }; fmt_12 = generic { - version = "12.1.0"; - hash = "sha256-ZmI1Dv0ZabPlxa02OpERI47jp7zFfjpeWCy1WyuPYZ0="; + version = "12.2.0"; + hash = "sha256-Tc7PmNxUv7ajw6GaHPGEEtrD/fl6is7RB8TPestJa1o="; }; } From 494f62228ce73e41ec022309eac731989b7c8528 Mon Sep 17 00:00:00 2001 From: highghlow Date: Mon, 29 Jun 2026 20:09:21 +0300 Subject: [PATCH 094/134] maintainers: add highghlow --- maintainers/maintainer-list.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/maintainers/maintainer-list.nix b/maintainers/maintainer-list.nix index f2ed390c0edb..54b7ab4c3069 100644 --- a/maintainers/maintainer-list.nix +++ b/maintainers/maintainer-list.nix @@ -11234,6 +11234,11 @@ github = "HigherOrderLogic"; githubId = 73709188; }; + highghlow = { + name = "Alex Kravchenko"; + github = "unhighghlow"; + githubId = 132668972; + }; hirenashah = { email = "hiren@hiren.io"; github = "hirenashah"; From 6d6d63aa5aa9d920462df6bcfea024c661bc8e87 Mon Sep 17 00:00:00 2001 From: highghlow Date: Tue, 4 Aug 2026 16:07:06 +0300 Subject: [PATCH 095/134] pipewire: fix build without systemd pipewire: change the maintainer of enableSystemd=false to myself --- pkgs/by-name/pi/pipewire/package.nix | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/pi/pipewire/package.nix b/pkgs/by-name/pi/pipewire/package.nix index f2dadfc6aa94..144def6c59a9 100644 --- a/pkgs/by-name/pi/pipewire/package.nix +++ b/pkgs/by-name/pi/pipewire/package.nix @@ -13,7 +13,7 @@ libinotify-kqueue, epoll-shim, systemd, - enableSystemd ? lib.meta.availableOn stdenv.hostPlatform systemd, # enableSystemd=false maintained by maintainers.qyliss. + enableSystemd ? lib.meta.availableOn stdenv.hostPlatform systemd, # enableSystemd=false maintained by maintainers.highghlow. pkg-config, docutils, doxygen, @@ -229,6 +229,7 @@ stdenv.mkDerivation (finalAttrs: { (lib.mesonEnable "pipewire-v4l2" stdenv.hostPlatform.isLinux) (lib.mesonEnable "libsystemd" enableSystemd) (lib.mesonEnable "systemd-system-service" enableSystemd) + (lib.mesonEnable "systemd-user-service" enableSystemd) (lib.mesonEnable "udev" stdenv.hostPlatform.isLinux) (lib.mesonEnable "ffmpeg" true) (lib.mesonEnable "pw-cat-ffmpeg" true) From a7e1a760ab81e9f3f07b628208c01635a88837ed Mon Sep 17 00:00:00 2001 From: Gerhard Schwanzer Date: Tue, 4 Aug 2026 17:59:00 +0200 Subject: [PATCH 096/134] python3Packages.cryptography: 49.0.0 -> 50.0.0 https://cryptography.io/en/latest/changelog/#v50-0-0 This release fixes CVE-2026-69247. Assisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol) --- .../python-modules/cryptography/default.nix | 16 +++------------- 1 file changed, 3 insertions(+), 13 deletions(-) diff --git a/pkgs/development/python-modules/cryptography/default.nix b/pkgs/development/python-modules/cryptography/default.nix index f0560b576078..2fedc1d11f32 100644 --- a/pkgs/development/python-modules/cryptography/default.nix +++ b/pkgs/development/python-modules/cryptography/default.nix @@ -1,7 +1,6 @@ { lib, stdenv, - fetchpatch, buildPythonPackage, callPackage, setuptools, @@ -22,30 +21,21 @@ buildPythonPackage rec { pname = "cryptography"; - version = "49.0.0"; + version = "50.0.0"; pyproject = true; src = fetchFromGitHub { owner = "pyca"; repo = "cryptography"; tag = version; - hash = "sha256-yHUIGauFZYnjcoROvocT1UqQ0B8ZuVTaJ0ZAfri6T1E="; + hash = "sha256-KHxEVSYr8yrODSVsGNgZowI/YnhG3qnFgae9877H+VE="; }; cargoDeps = rustPlatform.fetchCargoVendor { inherit pname version src; - hash = "sha256-yMCBu/RGRcEQST8tEWCNgVvlQsp2KamOqt60qvOYdt8="; + hash = "sha256-heJGLh0MgDPpksWyPLaIkZ5gVEWx8UnaJKv4GvclpmI="; }; - patches = [ - (fetchpatch { - # Add test marks where malloc failure is expected on systems with overcommit enabled - name = "malloc-overcommit-mark.patch"; - url = "https://github.com/pyca/cryptography/commit/2efeba9cc67809b67e659bea8eaea680df2135e8.patch"; - hash = "sha256-06Z+sk2JTJ50CCnPf2vXyPL5BZeI98oc43LpccenzNg="; - }) - ]; - postPatch = '' substituteInPlace pyproject.toml \ --replace-fail "--benchmark-disable" "" From 6cce7828fff3ad67b3384beb701a8ed5cd00d1d5 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Tue, 4 Aug 2026 18:41:08 +0200 Subject: [PATCH 097/134] python3Packages.django_5: 5.2.16 -> 5.2.17 https://docs.djangoproject.com/en/5.2/releases/5.2.17/ https://www.djangoproject.com/weblog/2026/aug/04/security-releases/ Fixes: CVE-2026-15307, CVE-2026-15337, CVE-2026-15830, CVE-2026-15920 --- pkgs/development/python-modules/django/5.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/django/5.nix b/pkgs/development/python-modules/django/5.nix index 74dff79704f1..d9ec648838c7 100644 --- a/pkgs/development/python-modules/django/5.nix +++ b/pkgs/development/python-modules/django/5.nix @@ -41,14 +41,14 @@ buildPythonPackage rec { pname = "django"; - version = "5.2.16"; + version = "5.2.17"; pyproject = true; src = fetchFromGitHub { owner = "django"; repo = "django"; tag = version; - hash = "sha256-DZa3OkqnrgXp1A/HerKYdUdanvi5jxHndo1DV4RVs0M="; + hash = "sha256-7it3opzsiN/hHhpipZz4ogmRKGz7E9/LmTF03/UYIB0="; }; patches = [ From 2740d7bc7806b77af282cb14fdc1a4993d414e63 Mon Sep 17 00:00:00 2001 From: Gerhard Schwanzer Date: Tue, 4 Aug 2026 23:22:55 +0200 Subject: [PATCH 098/134] python3Packages.gitpython: 3.1.57 -> 3.1.58 Includes the six security fixes published in GitPython 3.1.58. https://redirect.github.com/gitpython-developers/GitPython/blob/3.1.58/doc/source/changes.rst Assisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol) --- pkgs/development/python-modules/gitpython/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/gitpython/default.nix b/pkgs/development/python-modules/gitpython/default.nix index a2a183f6e448..2b5b14a297b5 100644 --- a/pkgs/development/python-modules/gitpython/default.nix +++ b/pkgs/development/python-modules/gitpython/default.nix @@ -10,14 +10,14 @@ buildPythonPackage (finalAttrs: { pname = "gitpython"; - version = "3.1.57"; + version = "3.1.58"; pyproject = true; src = fetchFromGitHub { owner = "gitpython-developers"; repo = "GitPython"; tag = finalAttrs.version; - hash = "sha256-pCGDKwIefGqx/UJaVqrsofc0t+ntqZRPMhsdbK2XBB0="; + hash = "sha256-C6hrN7SRWngwkD/NYvsoEVQUagdurkxzWbnn42EJOHE="; }; postPatch = '' From 9e51429113d08bca9d502cb45bd010eaa29483a3 Mon Sep 17 00:00:00 2001 From: Sergei Trofimovich Date: Tue, 4 Aug 2026 22:51:45 +0100 Subject: [PATCH 099/134] mpg123: 1.33.6 -> 1.33.7 Changes: https://www.mpg123.de/#2026-08-02 --- pkgs/by-name/mp/mpg123/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/mp/mpg123/package.nix b/pkgs/by-name/mp/mpg123/package.nix index 9bba89330c5c..538daa4a574d 100644 --- a/pkgs/by-name/mp/mpg123/package.nix +++ b/pkgs/by-name/mp/mpg123/package.nix @@ -21,11 +21,11 @@ assert withConplay -> !libOnly; stdenv.mkDerivation (finalAttrs: { pname = "${lib.optionalString libOnly "lib"}mpg123"; - version = "1.33.6"; + version = "1.33.7"; src = fetchurl { url = "mirror://sourceforge/mpg123/mpg123-${finalAttrs.version}.tar.bz2"; - hash = "sha256-kpp8GLpmK4knrtTeIprZroqytIBt0PMLkBE+sbTiGVo="; + hash = "sha256-MdDjWkylZ+ybXr2mwwYrtENdbT6s1u8NlcrdeFTcA+4="; }; outputs = [ From d75cae80fa4ab7b5f6f39ddcbbbfbaa1a9183d81 Mon Sep 17 00:00:00 2001 From: Archit Gupta Date: Tue, 9 Jun 2026 00:55:01 -0700 Subject: [PATCH 100/134] makeBinaryWrapper: fix read past NUL When setting a prefix for a path-like environment variable, the deduplication code in set_env_prefix reads past the NUL byte at the end of the env val and into the next entry. This corrupts the resultant env value with data from the next env var, or other data sitting after it. --- .../makeBinaryWrapper/make-binary-wrapper.sh | 4 +- .../combination/combination.c | 4 +- pkgs/test/make-binary-wrapper/default.nix | 1 + .../overlength-strings/overlength-strings.c | 4 +- .../prefix-dedup-last/prefix-dedup-last.c | 64 +++++++++++++++++++ .../prefix-dedup-last.cmdline | 2 + .../prefix-dedup-last/prefix-dedup-last.env | 3 + pkgs/test/make-binary-wrapper/prefix/prefix.c | 4 +- 8 files changed, 78 insertions(+), 8 deletions(-) create mode 100644 pkgs/test/make-binary-wrapper/prefix-dedup-last/prefix-dedup-last.c create mode 100644 pkgs/test/make-binary-wrapper/prefix-dedup-last/prefix-dedup-last.cmdline create mode 100644 pkgs/test/make-binary-wrapper/prefix-dedup-last/prefix-dedup-last.env diff --git a/pkgs/by-name/ma/makeBinaryWrapper/make-binary-wrapper.sh b/pkgs/by-name/ma/makeBinaryWrapper/make-binary-wrapper.sh index 232bc2b5c3cd..595574468ffa 100644 --- a/pkgs/by-name/ma/makeBinaryWrapper/make-binary-wrapper.sh +++ b/pkgs/by-name/ma/makeBinaryWrapper/make-binary-wrapper.sh @@ -366,10 +366,10 @@ void set_env_prefix(char *env, char *sep, char *prefix) { return; } unsigned long sep_len = strlen(sep); - int n_before = existing_prefix - existing_env; + int n_before = existing_prefix - existing_env - sep_len; assert_success(asprintf(&val, \"%s%s%.*s%s\", prefix, sep, n_before, existing_env, - existing_prefix + prefix_len + sep_len)); + existing_prefix + prefix_len)); } else { assert_success(asprintf(&val, \"%s%s%s\", prefix, sep, existing_env)); } diff --git a/pkgs/test/make-binary-wrapper/combination/combination.c b/pkgs/test/make-binary-wrapper/combination/combination.c index ae90263c45a5..33a003ca6a9a 100644 --- a/pkgs/test/make-binary-wrapper/combination/combination.c +++ b/pkgs/test/make-binary-wrapper/combination/combination.c @@ -42,10 +42,10 @@ void set_env_prefix(char *env, char *sep, char *prefix) { return; } unsigned long sep_len = strlen(sep); - int n_before = existing_prefix - existing_env; + int n_before = existing_prefix - existing_env - sep_len; assert_success(asprintf(&val, "%s%s%.*s%s", prefix, sep, n_before, existing_env, - existing_prefix + prefix_len + sep_len)); + existing_prefix + prefix_len)); } else { assert_success(asprintf(&val, "%s%s%s", prefix, sep, existing_env)); } diff --git a/pkgs/test/make-binary-wrapper/default.nix b/pkgs/test/make-binary-wrapper/default.nix index 715b28f912e4..7d2e4b1a7cd2 100644 --- a/pkgs/test/make-binary-wrapper/default.nix +++ b/pkgs/test/make-binary-wrapper/default.nix @@ -59,6 +59,7 @@ let "overlength-strings" "prefix" "suffix" + "prefix-dedup-last" ] makeGoldenTest // lib.optionalAttrs (!stdenv.hostPlatform.isDarwin) { cross = diff --git a/pkgs/test/make-binary-wrapper/overlength-strings/overlength-strings.c b/pkgs/test/make-binary-wrapper/overlength-strings/overlength-strings.c index 6a5107d5a4de..0dde8218c3bf 100644 --- a/pkgs/test/make-binary-wrapper/overlength-strings/overlength-strings.c +++ b/pkgs/test/make-binary-wrapper/overlength-strings/overlength-strings.c @@ -42,10 +42,10 @@ void set_env_prefix(char *env, char *sep, char *prefix) { return; } unsigned long sep_len = strlen(sep); - int n_before = existing_prefix - existing_env; + int n_before = existing_prefix - existing_env - sep_len; assert_success(asprintf(&val, "%s%s%.*s%s", prefix, sep, n_before, existing_env, - existing_prefix + prefix_len + sep_len)); + existing_prefix + prefix_len)); } else { assert_success(asprintf(&val, "%s%s%s", prefix, sep, existing_env)); } diff --git a/pkgs/test/make-binary-wrapper/prefix-dedup-last/prefix-dedup-last.c b/pkgs/test/make-binary-wrapper/prefix-dedup-last/prefix-dedup-last.c new file mode 100644 index 000000000000..8f13278a7537 --- /dev/null +++ b/pkgs/test/make-binary-wrapper/prefix-dedup-last/prefix-dedup-last.c @@ -0,0 +1,64 @@ +#define _GNU_SOURCE /* See feature_test_macros(7) */ +#include +#include +#include +#include +#include + +#define assert_success(e) do { if ((e) < 0) { perror(#e); abort(); } } while (0) + +int is_surrounded_by_sep(char *env, char *ptr, unsigned long len, char *sep) { + unsigned long sep_len = strlen(sep); + + // Check left side (if not at start) + if (env != ptr) { + if (ptr - env < sep_len) + return 0; + if (strncmp(sep, ptr - sep_len, sep_len) != 0) { + return 0; + } + } + // Check right side (if not at end) + char *end_ptr = ptr + len; + if (*end_ptr != '\0') { + if (strncmp(sep, ptr + len, sep_len) != 0) { + return 0; + } + } + + return 1; +} + +void set_env_prefix(char *env, char *sep, char *prefix) { + char *existing_env = getenv(env); + if (existing_env) { + char *val; + + char *existing_prefix = strstr(existing_env, prefix); + unsigned long prefix_len = strlen(prefix); + // If the prefix already exists, remove the original + if (existing_prefix && is_surrounded_by_sep(existing_env, existing_prefix, prefix_len, sep)) { + if (existing_env == existing_prefix) { + return; + } + unsigned long sep_len = strlen(sep); + int n_before = existing_prefix - existing_env - sep_len; + assert_success(asprintf(&val, "%s%s%.*s%s", prefix, sep, + n_before, existing_env, + existing_prefix + prefix_len)); + } else { + assert_success(asprintf(&val, "%s%s%s", prefix, sep, existing_env)); + } + assert_success(setenv(env, val, 1)); + free(val); + } else { + assert_success(setenv(env, prefix, 1)); + } +} + +int main(int argc, char **argv) { + putenv("PATH=/usr/bin:/usr/local/bin"); + set_env_prefix("PATH", ":", "/usr/local/bin"); + argv[0] = "/send/me/flags"; + return execv("/send/me/flags", argv); +} diff --git a/pkgs/test/make-binary-wrapper/prefix-dedup-last/prefix-dedup-last.cmdline b/pkgs/test/make-binary-wrapper/prefix-dedup-last/prefix-dedup-last.cmdline new file mode 100644 index 000000000000..ec2d43b44031 --- /dev/null +++ b/pkgs/test/make-binary-wrapper/prefix-dedup-last/prefix-dedup-last.cmdline @@ -0,0 +1,2 @@ +--set PATH /usr/bin:/usr/local/bin \ +--prefix PATH : /usr/local/bin diff --git a/pkgs/test/make-binary-wrapper/prefix-dedup-last/prefix-dedup-last.env b/pkgs/test/make-binary-wrapper/prefix-dedup-last/prefix-dedup-last.env new file mode 100644 index 000000000000..6f8f684af379 --- /dev/null +++ b/pkgs/test/make-binary-wrapper/prefix-dedup-last/prefix-dedup-last.env @@ -0,0 +1,3 @@ +PATH=/usr/local/bin:/usr/bin +CWD=SUBST_CWD +SUBST_ARGV0 diff --git a/pkgs/test/make-binary-wrapper/prefix/prefix.c b/pkgs/test/make-binary-wrapper/prefix/prefix.c index 205ecd0dcaef..a74cb49861ea 100644 --- a/pkgs/test/make-binary-wrapper/prefix/prefix.c +++ b/pkgs/test/make-binary-wrapper/prefix/prefix.c @@ -42,10 +42,10 @@ void set_env_prefix(char *env, char *sep, char *prefix) { return; } unsigned long sep_len = strlen(sep); - int n_before = existing_prefix - existing_env; + int n_before = existing_prefix - existing_env - sep_len; assert_success(asprintf(&val, "%s%s%.*s%s", prefix, sep, n_before, existing_env, - existing_prefix + prefix_len + sep_len)); + existing_prefix + prefix_len)); } else { assert_success(asprintf(&val, "%s%s%s", prefix, sep, existing_env)); } From 0be718d0159bb6eb386056d8402a0629715c6b3d Mon Sep 17 00:00:00 2001 From: z10bn <312809655+z10bn@users.noreply.github.com> Date: Wed, 5 Aug 2026 08:27:07 +0530 Subject: [PATCH 101/134] bluez-headers: 5.86 -> 5.87 --- pkgs/by-name/bl/bluez-headers/package.nix | 6 +++--- pkgs/by-name/bl/bluez/package.nix | 17 ----------------- 2 files changed, 3 insertions(+), 20 deletions(-) diff --git a/pkgs/by-name/bl/bluez-headers/package.nix b/pkgs/by-name/bl/bluez-headers/package.nix index 06e4aa0aae1e..47efbb311552 100644 --- a/pkgs/by-name/bl/bluez-headers/package.nix +++ b/pkgs/by-name/bl/bluez-headers/package.nix @@ -10,14 +10,14 @@ stdenv.mkDerivation (finalAttrs: { pname = "bluez-headers"; - version = "5.86"; + version = "5.87"; # This package has the source, because of the emulatorAvailable check in the # bluez function args, that causes an infinite recursion with Python on cross # builds. src = fetchurl { url = "mirror://kernel/linux/bluetooth/bluez-${finalAttrs.version}.tar.xz"; - hash = "sha256-mfFEVAxgcFkeTFO8uXfrQmZMYrezbLNaKc9y3tM5Yh0="; + hash = "sha256-Jr3PLOvXMQxvWYhQYGsDfvDFFf5mCOvFTSLFDEwys18="; }; dontConfigure = true; @@ -29,7 +29,7 @@ stdenv.mkDerivation (finalAttrs: { ''; meta = { - homepage = "https://www.bluez.org/"; + homepage = "https://bluez.github.io/"; description = "Official Linux Bluetooth protocol stack"; changelog = "https://git.kernel.org/pub/scm/bluetooth/bluez.git/tree/ChangeLog?h=${finalAttrs.version}"; license = with lib.licenses; [ diff --git a/pkgs/by-name/bl/bluez/package.nix b/pkgs/by-name/bl/bluez/package.nix index 81ec00b045ca..e18ccdd4bdcc 100644 --- a/pkgs/by-name/bl/bluez/package.nix +++ b/pkgs/by-name/bl/bluez/package.nix @@ -32,23 +32,6 @@ stdenv.mkDerivation (finalAttrs: { inherit (bluez-headers) version src; patches = [ - # https://github.com/bluez/bluez/issues/1896 - # Remove the following 2 in the next release - (fetchpatch2 { - name = "fix-btctl-noninteractive-regression"; - url = "https://git.kernel.org/pub/scm/bluetooth/bluez.git/patch/?id=b33e923b55e4d0e9d78a83cfcb541fd1f687ef54"; - hash = "sha256-q7eN4ktw7DtdwMHHi7GU7fbvHAdMttKF1kDSWzZqa6A="; - }) - (fetchpatch2 { - name = "fix-btctl-noninteractive-regression-2"; - url = "https://git.kernel.org/pub/scm/bluetooth/bluez.git/patch/?id=21e13976f2e375d701b8b7032ba5c1b2e56c305f"; - hash = "sha256-JrdmYiC+U0KeMP8oVg12Z8CvkMEKWBVgiiUACx0E7dY="; - }) - (fetchpatch2 { - name = "support-libical-4.0.patch"; - url = "https://git.kernel.org/pub/scm/bluetooth/bluez.git/patch/?id=e60d07255327db3fc4e3a28d7fcc792cd42c34d0"; - hash = "sha256-1uw+5nTjh+t1/L++fRNIlQWblwDwTJifH0EvAn3dym8="; - }) ./lreadline.patch ]; From e180992165f30201bf959c9d678e910785a46d71 Mon Sep 17 00:00:00 2001 From: Scott Stephens Date: Wed, 5 Aug 2026 12:06:26 -0400 Subject: [PATCH 102/134] python3Packages.tpm2-pytss: 2.3.0 -> 3.0.0-rc1 https://github.com/tpm2-software/tpm2-pytss/blob/3.0.0-rc1/CHANGELOG.md --- .../python-modules/tpm2-pytss/default.nix | 42 ++----------------- 1 file changed, 4 insertions(+), 38 deletions(-) diff --git a/pkgs/development/python-modules/tpm2-pytss/default.nix b/pkgs/development/python-modules/tpm2-pytss/default.nix index 9c1fa30570b7..a389da6bef3d 100644 --- a/pkgs/development/python-modules/tpm2-pytss/default.nix +++ b/pkgs/development/python-modules/tpm2-pytss/default.nix @@ -24,50 +24,16 @@ let in buildPythonPackage rec { pname = "tpm2-pytss"; - version = "2.3.0"; + version = "3.0.0rc1"; format = "setuptools"; src = fetchPypi { - inherit pname version; - hash = "sha256-IAcRKTeWVvXzw7wW02RhJnKxR9gRkftOufn/n77khBA="; + inherit version; + pname = "tpm2_pytss"; + hash = "sha256-9Wj7RKjcjCzPqlsA4PxgVGQBvqQKuANG2tMb/cI3ihE="; }; patches = [ - # libtpms (underneath swtpm) bumped the TPM revision - # https://github.com/tpm2-software/tpm2-pytss/pull/593 - (fetchpatch { - url = "https://github.com/tpm2-software/tpm2-pytss/pull/593.patch"; - hash = "sha256-CNJnSIvUQ0Yvy0o7GdVfFZ7kHJd2hBt5Zv1lqgOeoks="; - }) - # support cryptography >= 45.0.0 - # https://github.com/tpm2-software/tpm2-pytss/pull/643 - (fetchpatch { - url = "https://github.com/tpm2-software/tpm2-pytss/commit/6ab4c74e6fb3da7cd38e97c1f8e92532312f8439.patch"; - hash = "sha256-01Qe4qpD2IINc5Z120iVdPitiLBwdr8KNBjLFnGgE7E="; - }) - # support cryptography >= 47.0.0, which made __deepcopy__ an abstract - # method on the private-key base classes - # https://github.com/tpm2-software/tpm2-pytss/pull/689 - (fetchpatch { - url = "https://github.com/tpm2-software/tpm2-pytss/commit/5d15cad4bde28902a4becb8e2a8e915aba8abbd0.patch"; - hash = "sha256-b2zVD7KJGVzJ765HO8LFAe9MyQmjOTpERmEqUrIg3oM="; - }) - # Properly restore environment variables upon exit from - # FAPIConfig context. Accepted into upstream, not yet released. - (fetchpatch2 { - url = "https://github.com/tpm2-software/tpm2-pytss/commit/afdee627d0639eb05711a2191f2f76e460793da9.patch?full_index=1"; - hash = "sha256-Y6drcBg4gnbSvnCGw69b42Q/QfLI3u56BGRUEkpdB0M="; - }) - # Fix build with gcc15 by using c99 for preprocessing - # The first patch is needed to apply the second; it doesn't affect us - (fetchpatch { - url = "https://github.com/tpm2-software/tpm2-pytss/commit/55d28b259f1a68f60c937ea8be7815685d32757f.patch"; - hash = "sha256-sGxUyQ2W2Jl9ROSt1w0E0dVTgFPAmYWlNgcpHcTVv90="; - }) - (fetchpatch { - url = "https://github.com/tpm2-software/tpm2-pytss/commit/61d00b4dcca131b3f03f674ceabf4260bdbd6a61.patch"; - hash = "sha256-0dwfyW0Fi5FkzYnaMOb2ua9O6eyCnMgJqT09tTT56vY="; - }) ] ++ lib.optionals isCross [ # pytss will regenerate files from headers of tpm2-tss. From 0ef9e3a24027db909c89c6df6b14366dadd736e3 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Wed, 5 Aug 2026 17:12:43 +0200 Subject: [PATCH 103/134] python314: 3.14.6 -> 3.14.7 https://docs.python.org/release/3.14.7/whatsnew/changelog.html --- pkgs/development/interpreters/python/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/interpreters/python/default.nix b/pkgs/development/interpreters/python/default.nix index 03cc59038ff2..94464575569a 100644 --- a/pkgs/development/interpreters/python/default.nix +++ b/pkgs/development/interpreters/python/default.nix @@ -20,10 +20,10 @@ sourceVersion = { major = "3"; minor = "14"; - patch = "6"; + patch = "7"; suffix = ""; }; - hash = "sha256-FDsd3e+uw70uIeO4ObNKK3+5hCJyiDxXZCDWBenzDGM="; + hash = "sha256-O0jayPtZ9i6qZ6yDwesSvaG3oIQG3ShuJSwRpmvif4E="; }; }; From f392f19a940905d33402d498ed578ec0d6320694 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Wed, 5 Aug 2026 18:30:03 +0200 Subject: [PATCH 104/134] python313: 3.13.14 -> 3.13.15 https://docs.python.org/release/3.13.15/whatsnew/changelog.html --- pkgs/development/interpreters/python/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/interpreters/python/default.nix b/pkgs/development/interpreters/python/default.nix index 94464575569a..fc4cd0db1219 100644 --- a/pkgs/development/interpreters/python/default.nix +++ b/pkgs/development/interpreters/python/default.nix @@ -59,10 +59,10 @@ sourceVersion = { major = "3"; minor = "13"; - patch = "14"; + patch = "15"; suffix = ""; }; - hash = "sha256-Y55DJDxiCjCPloIT354A8vj2IzL3rbqnp+65eDBXxpA="; + hash = "sha256-HmanlFpIOQ7kwqQmig5BhYhAWaE8SqttFIqiCN7qSnY="; inherit passthruFun; }; From 96aae4540390bb8535ebbe47a478455be05e99c1 Mon Sep 17 00:00:00 2001 From: Ben Siraphob Date: Wed, 5 Aug 2026 10:45:45 -0700 Subject: [PATCH 105/134] minimal-bootstrap.binutils-static: restore static linking --- pkgs/os-specific/linux/minimal-bootstrap/binutils/static.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/os-specific/linux/minimal-bootstrap/binutils/static.nix b/pkgs/os-specific/linux/minimal-bootstrap/binutils/static.nix index e29e884a2dfd..92f8e2dea338 100644 --- a/pkgs/os-specific/linux/minimal-bootstrap/binutils/static.nix +++ b/pkgs/os-specific/linux/minimal-bootstrap/binutils/static.nix @@ -33,6 +33,8 @@ let ]; configureFlags = [ + # otherwise the binary links dynamically and pulls gcc into the closure + "LDFLAGS=--static" "--prefix=${placeholder "out"}" "--build=${buildPlatform.config}" "--host=${hostPlatform.config}" From fd7f9ac6335fe56229a15962dc5e0a96eef257cd Mon Sep 17 00:00:00 2001 From: Ben Siraphob Date: Wed, 5 Aug 2026 11:23:36 -0700 Subject: [PATCH 106/134] minimal-bootstrap: drop dead libgcc rpath from the gcc wrapper --- pkgs/os-specific/linux/minimal-bootstrap/gcc/wrapper.sh | 2 +- pkgs/os-specific/linux/minimal-bootstrap/gcc/wrappercxx.sh | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/minimal-bootstrap/gcc/wrapper.sh b/pkgs/os-specific/linux/minimal-bootstrap/gcc/wrapper.sh index 45720ce02d4a..45c4d3e1245f 100644 --- a/pkgs/os-specific/linux/minimal-bootstrap/gcc/wrapper.sh +++ b/pkgs/os-specific/linux/minimal-bootstrap/gcc/wrapper.sh @@ -41,7 +41,7 @@ done exec -a "@origname@" @gcc@ -Wl,-dynamic-linker=@dynlinker@ \ @extraflags@ \ $extraRpath \ - -Wl,-rpath,@libc@,-rpath,@libgcc@ \ + -Wl,-rpath,@libc@ \ -B@libc@/.. \ -B@libgcc@ \ -B@libc@ \ diff --git a/pkgs/os-specific/linux/minimal-bootstrap/gcc/wrappercxx.sh b/pkgs/os-specific/linux/minimal-bootstrap/gcc/wrappercxx.sh index c567b0313f08..9007d4aa1604 100644 --- a/pkgs/os-specific/linux/minimal-bootstrap/gcc/wrappercxx.sh +++ b/pkgs/os-specific/linux/minimal-bootstrap/gcc/wrappercxx.sh @@ -43,7 +43,7 @@ done exec -a "@origname@" @gcc@ -Wl,-dynamic-linker=@dynlinker@ \ @extraflags@ \ $extraRpath \ - -Wl,-rpath,@libc@,-rpath,@libgcc@,-rpath,@libstdcxx@ \ + -Wl,-rpath,@libc@,-rpath,@libstdcxx@ \ -I @libstdcxxarchinc@ \ -I @libstdcxxinc@ \ -B@libc@/.. \ From 2b893e55b8dad54e975d03d03a6eef4cc9b10435 Mon Sep 17 00:00:00 2001 From: SandaruKasa Date: Tue, 4 Aug 2026 23:31:45 +0300 Subject: [PATCH 107/134] ffmpeg: 8.1.2 -> 9.0 --- pkgs/development/libraries/ffmpeg/default.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/development/libraries/ffmpeg/default.nix b/pkgs/development/libraries/ffmpeg/default.nix index 28e51a85d4dd..9a37a2d12637 100644 --- a/pkgs/development/libraries/ffmpeg/default.nix +++ b/pkgs/development/libraries/ffmpeg/default.nix @@ -75,7 +75,7 @@ rec { # unversioned aliases to allow for quicker migration to new releases, # but can pin one of the versioned variants if they do not work with # the current default version. - ffmpeg = ffmpeg_8; - ffmpeg-headless = ffmpeg_8-headless; - ffmpeg-full = ffmpeg_8-full; + ffmpeg = ffmpeg_9; + ffmpeg-headless = ffmpeg_9-headless; + ffmpeg-full = ffmpeg_9-full; } From b22907c0497433fa25e42250c303a3fbd85573c6 Mon Sep 17 00:00:00 2001 From: SandaruKasa Date: Wed, 5 Aug 2026 00:15:12 +0300 Subject: [PATCH 108/134] various: ffmpeg: enable `__structuredAttrs` for all versions Co-authored-by: dotlambda --- pkgs/development/libraries/ffmpeg/generic.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/development/libraries/ffmpeg/generic.nix b/pkgs/development/libraries/ffmpeg/generic.nix index 1fcc6d47ebf6..644c4348873d 100644 --- a/pkgs/development/libraries/ffmpeg/generic.nix +++ b/pkgs/development/libraries/ffmpeg/generic.nix @@ -838,7 +838,7 @@ stdenv.mkDerivation ( in "remove-references-to ${lib.concatMapStringsSep " " (o: "-t ${o}") toStrip} config.h"; - __structuredAttrs = versionAtLeast version "9"; + __structuredAttrs = true; strictDeps = true; nativeBuildInputs = [ From 8f4fcbf26bdaed9c7673cb8646c0ea7c2fd356be Mon Sep 17 00:00:00 2001 From: Tom Hunze Date: Sat, 18 Jul 2026 18:31:44 +0000 Subject: [PATCH 109/134] =?UTF-8?q?glib:=202.88.1=20=E2=86=92=202.88.3?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit https://gitlab.gnome.org/GNOME/glib/-/compare/2.88.1...2.88.2 https://gitlab.gnome.org/GNOME/glib/-/compare/2.88.2...2.88.3 --- pkgs/by-name/gl/glib/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/gl/glib/package.nix b/pkgs/by-name/gl/glib/package.nix index bda3d4a4a09c..2327e6be33fd 100644 --- a/pkgs/by-name/gl/glib/package.nix +++ b/pkgs/by-name/gl/glib/package.nix @@ -84,7 +84,7 @@ in stdenv.mkDerivation (finalAttrs: { pname = "glib"; - version = "2.88.1"; + version = "2.88.3"; outputs = [ "bin" @@ -97,7 +97,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "mirror://gnome/sources/glib/${lib.versions.majorMinor finalAttrs.version}/glib-${finalAttrs.version}.tar.xz"; - hash = "sha256-UauATFb26rPlBFx3TRKQrF5Mkj1Pmj2OMxI77kXBhA4="; + hash = "sha256-qyTSTmmN+h5Ai3vNtQj0qvyQYYWouM5y/febu9ybODs="; }; patches = From 59cd134da0474d5361ca9fa8486bc7a49b67d39f Mon Sep 17 00:00:00 2001 From: Jan Tojnar Date: Thu, 6 Aug 2026 00:15:10 +0000 Subject: [PATCH 110/134] =?UTF-8?q?at-spi2-core:=202.60.5=20=E2=86=92=202.?= =?UTF-8?q?60.6?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit https://gitlab.gnome.org/GNOME/at-spi2-core/-/compare/2.60.5...2.60.6 --- pkgs/by-name/at/at-spi2-core/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/at/at-spi2-core/package.nix b/pkgs/by-name/at/at-spi2-core/package.nix index 1094d8f7da80..5800590de57d 100644 --- a/pkgs/by-name/at/at-spi2-core/package.nix +++ b/pkgs/by-name/at/at-spi2-core/package.nix @@ -29,7 +29,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "at-spi2-core"; - version = "2.60.5"; + version = "2.60.6"; outputs = [ "out" @@ -39,7 +39,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "mirror://gnome/sources/at-spi2-core/${lib.versions.majorMinor finalAttrs.version}/at-spi2-core-${finalAttrs.version}.tar.xz"; - hash = "sha256-YFmnfVB0OP9sjW0GAl+Pn1d0+g+Oq+nJsFmxzEHhu8A="; + hash = "sha256-qJtkqLIXqAQr3w41y/q2Kc7uNWQNunXfV4r96ap4nVc="; }; nativeBuildInputs = [ From 548c156f109369c0f9334be3a9da4160d96db752 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Vladim=C3=ADr=20=C4=8Cun=C3=A1t?= Date: Thu, 6 Aug 2026 13:29:13 +0200 Subject: [PATCH 111/134] libxfont_2: 2.0.8 -> 2.0.9 Fixes: CVE-2026-59679 CVE-2026-44950 https://lists.x.org/archives/xorg-announce/2026-August/003734.html https://lists.x.org/archives/xorg-announce/2026-August/003735.html --- pkgs/by-name/li/libxfont_2/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/li/libxfont_2/package.nix b/pkgs/by-name/li/libxfont_2/package.nix index 0156515019d1..beb3abd0d329 100644 --- a/pkgs/by-name/li/libxfont_2/package.nix +++ b/pkgs/by-name/li/libxfont_2/package.nix @@ -15,7 +15,7 @@ }: stdenv.mkDerivation (finalAttrs: { pname = "libxfont_2"; - version = "2.0.8"; + version = "2.0.9"; outputs = [ "out" @@ -24,7 +24,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "mirror://xorg/individual/lib/libXfont2-${finalAttrs.version}.tar.xz"; - hash = "sha256-9VbA4Qk6TmkRzJC8SxBtIBkC7hh/10ryBv8WL35qJNU="; + hash = "sha256-8EKjcGZoFee5Qem3AZAkdVvRxsKVSvv6UVrzeCUXmeI="; }; strictDeps = true; From 922901b1b561e7074b842d54a61a5e6de7300cf3 Mon Sep 17 00:00:00 2001 From: K900 Date: Sat, 8 Aug 2026 13:42:17 +0300 Subject: [PATCH 112/134] python3Packages.tkinter: apply more hacks to fix tests again --- pkgs/development/python-modules/tkinter/default.nix | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/pkgs/development/python-modules/tkinter/default.nix b/pkgs/development/python-modules/tkinter/default.nix index 497a42e91c6c..78cf4fae1726 100644 --- a/pkgs/development/python-modules/tkinter/default.nix +++ b/pkgs/development/python-modules/tkinter/default.nix @@ -77,6 +77,10 @@ buildPythonPackage { preCheck = '' cd "$python_src"/Lib export HOME=$TMPDIR + + # fix test that ignores PYTHONPATH and can't find tkinter + substituteInPlace test/support/script_helper.py \ + --replace-fail "__cached_interp_requires_environment = None" "__cached_interp_requires_environment = True" '' + lib.optionalString (pythonAtLeast "3.13" && pythonOlder "3.15") '' # https://github.com/python/cpython/pull/143570 @@ -88,7 +92,7 @@ buildPythonPackage { test/test_tkinter/support.py \ --replace-fail \ "support.get_resource_value('wantobjects')" \ - "0" + "1" ''; checkPhase = From 1fa22668e478de634b1427a38964ce10c1a5072b Mon Sep 17 00:00:00 2001 From: K900 Date: Sat, 8 Aug 2026 13:57:01 +0300 Subject: [PATCH 113/134] opencv: pin ffmpeg 8 --- pkgs/development/libraries/opencv/4.x.nix | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/pkgs/development/libraries/opencv/4.x.nix b/pkgs/development/libraries/opencv/4.x.nix index 1c4a1b08f1fd..dcadbf7d405c 100644 --- a/pkgs/development/libraries/opencv/4.x.nix +++ b/pkgs/development/libraries/opencv/4.x.nix @@ -59,7 +59,8 @@ enableVtk ? false, vtk, enableFfmpeg ? true, - ffmpeg-headless, + # FIXME: unpin once upstream has ffmpeg 9 support + ffmpeg_8-headless, enableGStreamer ? true, elfutils, gst_all_1, @@ -386,7 +387,7 @@ effectiveStdenv.mkDerivation { openjpeg ] ++ optionals enableFfmpeg [ - ffmpeg-headless + ffmpeg_8-headless ] ++ optionals (enableGStreamer && effectiveStdenv.hostPlatform.isLinux) [ elfutils From bf3686205021724fa601041ac8205ceb4b23c293 Mon Sep 17 00:00:00 2001 From: K900 Date: Sat, 8 Aug 2026 13:57:53 +0300 Subject: [PATCH 114/134] gst_all_1.gst-libav: pin ffmpeg 8 --- pkgs/development/libraries/gstreamer/libav/default.nix | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/pkgs/development/libraries/gstreamer/libav/default.nix b/pkgs/development/libraries/gstreamer/libav/default.nix index 92c906d4c1a9..3714fb286d9c 100644 --- a/pkgs/development/libraries/gstreamer/libav/default.nix +++ b/pkgs/development/libraries/gstreamer/libav/default.nix @@ -9,7 +9,8 @@ gstreamer, gst-plugins-base, gettext, - ffmpeg-headless, + # FIXME: unpin when upstream supports ffmpeg 9 + ffmpeg_8-headless, # Checks meson.is_cross_build(), so even canExecute isn't enough. enableDocumentation ? stdenv.hostPlatform == stdenv.buildPlatform, hotdoc, @@ -50,7 +51,7 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ gstreamer gst-plugins-base - ffmpeg-headless + ffmpeg_8-headless ] ++ lib.optionals stdenv.hostPlatform.isDarwin [ apple-sdk_gstreamer From c1b7eab7a87dfb195ce35c0febb0927c2daba23f Mon Sep 17 00:00:00 2001 From: K900 Date: Sat, 8 Aug 2026 14:06:33 +0300 Subject: [PATCH 115/134] treewide: fix opencv ffmpeg overrides Oops. Also ew. --- pkgs/by-name/ml/mlt/package.nix | 11 ++++++----- pkgs/by-name/sh/shotcut/package.nix | 8 ++++---- 2 files changed, 10 insertions(+), 9 deletions(-) diff --git a/pkgs/by-name/ml/mlt/package.nix b/pkgs/by-name/ml/mlt/package.nix index ce23dccb8185..1f228e1e52d7 100644 --- a/pkgs/by-name/ml/mlt/package.nix +++ b/pkgs/by-name/ml/mlt/package.nix @@ -7,7 +7,8 @@ cmake, pkg-config, which, - ffmpeg, + # FIXME: unpin when opencv supports ffmpeg 9 + ffmpeg_8, fftw, fontconfig, frei0r, @@ -82,11 +83,11 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ gdk-pixbuf - (opencv4.override { ffmpeg-headless = ffmpeg; }) - ffmpeg + (opencv4.override { ffmpeg_8-headless = ffmpeg_8; }) + ffmpeg_8 fftw fontconfig - (frei0r.override { opencv = opencv4.override { ffmpeg-headless = ffmpeg; }; }) + (frei0r.override { opencv = opencv4.override { ffmpeg_8-headless = ffmpeg_8; }; }) libdv libebur128 libexif @@ -146,7 +147,7 @@ stdenv.mkDerivation (finalAttrs: { preFixup = '' wrapProgram $out/bin/melt \ --prefix FREI0R_PATH : ${ - (frei0r.override { opencv = opencv4.override { ffmpeg-headless = ffmpeg; }; }) + (frei0r.override { opencv = opencv4.override { ffmpeg_8-headless = ffmpeg_8; }; }) }/lib/frei0r-1 \ ${lib.optionalString enableJackrack "--prefix LADSPA_PATH : ${ladspaPlugins}/lib/ladspa"} \ ${lib.optionalString (qtbase != null) "\${qtWrapperArgs[@]}"} diff --git a/pkgs/by-name/sh/shotcut/package.nix b/pkgs/by-name/sh/shotcut/package.nix index 5054989f5f6c..bf20d32bfa21 100644 --- a/pkgs/by-name/sh/shotcut/package.nix +++ b/pkgs/by-name/sh/shotcut/package.nix @@ -15,7 +15,7 @@ qt6Packages, cmake, gitUpdater, - ffmpeg, + ffmpeg_8, wrapGAppsHook3, }: @@ -39,7 +39,7 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ SDL2 - (frei0r.override { opencv = opencv4.override { ffmpeg-headless = ffmpeg; }; }) + (frei0r.override { opencv = opencv4.override { ffmpeg_8-headless = ffmpeg_8; }; }) ladspaPlugins gettext qt6Packages.mlt @@ -60,7 +60,7 @@ stdenv.mkDerivation (finalAttrs: { patches = [ (replaceVars ./fix-mlt-ffmpeg-path.patch { - inherit ffmpeg; + ffmpeg = ffmpeg_8; mlt = qt6Packages.mlt; }) ]; @@ -69,7 +69,7 @@ stdenv.mkDerivation (finalAttrs: { qtWrapperArgs = [ "--set FREI0R_PATH ${ - (frei0r.override { opencv = opencv4.override { ffmpeg-headless = ffmpeg; }; }) + (frei0r.override { opencv = opencv4.override { ffmpeg_8-headless = ffmpeg_8; }; }) }/lib/frei0r-1" "--set LADSPA_PATH ${ladspaPlugins}/lib/ladspa" "--prefix LD_LIBRARY_PATH : ${ From 23a5fece5b4567cfd3cead096f330bc184fc8270 Mon Sep 17 00:00:00 2001 From: K900 Date: Sat, 8 Aug 2026 14:12:29 +0300 Subject: [PATCH 116/134] mlt: fix passthru --- pkgs/by-name/ml/mlt/package.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/by-name/ml/mlt/package.nix b/pkgs/by-name/ml/mlt/package.nix index 1f228e1e52d7..539f0b2acd07 100644 --- a/pkgs/by-name/ml/mlt/package.nix +++ b/pkgs/by-name/ml/mlt/package.nix @@ -160,7 +160,7 @@ stdenv.mkDerivation (finalAttrs: { ''; passthru = { - inherit ffmpeg; + ffmpeg = ffmpeg_8; }; passthru.updateScript = gitUpdater { From 42488c08e906ee31413792d933a1e3c53c41998b Mon Sep 17 00:00:00 2001 From: K900 Date: Sat, 8 Aug 2026 15:04:18 +0300 Subject: [PATCH 117/134] bluez: refresh patch --- pkgs/by-name/bl/bluez/lreadline.patch | 31 +++++++++++++-------------- 1 file changed, 15 insertions(+), 16 deletions(-) diff --git a/pkgs/by-name/bl/bluez/lreadline.patch b/pkgs/by-name/bl/bluez/lreadline.patch index 3e3b6a1818bc..43f000e3f3d8 100644 --- a/pkgs/by-name/bl/bluez/lreadline.patch +++ b/pkgs/by-name/bl/bluez/lreadline.patch @@ -1,10 +1,9 @@ -# Adjusted version of https://lore.kernel.org/linux-bluetooth/20250703182908.2370130-1-hi@alyssa.is/raw diff --git a/Makefile.tools b/Makefile.tools -index 2080f0978..885371de9 100644 +index 1a4e56608..a8bff6df3 100644 --- a/Makefile.tools +++ b/Makefile.tools -@@ -19,7 +19,7 @@ client_bluetoothctl_SOURCES = client/main.c \ - client/telephony.h client/telephony.c +@@ -20,7 +20,7 @@ client_bluetoothctl_SOURCES = client/main.c \ + client/cs.h client/cs.c client_bluetoothctl_LDADD = lib/libbluetooth-internal.la \ gdbus/libgdbus-internal.la src/libshared-glib.la \ - $(GLIB_LIBS) $(DBUS_LIBS) -lreadline @@ -12,16 +11,16 @@ index 2080f0978..885371de9 100644 endif if ZSH_COMPLETIONS -@@ -385,7 +385,7 @@ tools_meshctl_SOURCES = tools/meshctl.c \ +@@ -389,7 +389,7 @@ tools_meshctl_SOURCES = tools/meshctl.c \ tools/mesh-gatt/onoff-model.c tools_meshctl_LDADD = gdbus/libgdbus-internal.la src/libshared-glib.la \ lib/libbluetooth-internal.la \ - $(GLIB_LIBS) $(DBUS_LIBS) -ljson-c -lreadline + $(GLIB_LIBS) $(DBUS_LIBS) -ljson-c $(READLINE_LIBS) - - EXTRA_DIST += tools/mesh-gatt/local_node.json tools/mesh-gatt/prov_db.json endif -@@ -404,7 +404,7 @@ tools_mesh_cfgclient_SOURCES = tools/mesh-cfgclient.c \ + + bin_PROGRAMS += tools/mesh-cfgclient +@@ -406,7 +406,7 @@ tools_mesh_cfgclient_SOURCES = tools/mesh-cfgclient.c \ mesh/crypto.h mesh/crypto.c tools_mesh_cfgclient_LDADD = lib/libbluetooth-internal.la src/libshared-ell.la \ @@ -30,7 +29,7 @@ index 2080f0978..885371de9 100644 bin_PROGRAMS += tools/mesh-cfgtest -@@ -512,7 +512,7 @@ noinst_PROGRAMS += tools/btmgmt tools/obex-client-tool tools/obex-server-tool \ +@@ -489,7 +489,7 @@ noinst_PROGRAMS += tools/btmgmt tools/obex-client-tool tools/obex-server-tool \ tools_obex_client_tool_SOURCES = $(gobex_sources) $(btio_sources) \ tools/obex-client-tool.c tools_obex_client_tool_LDADD = lib/libbluetooth-internal.la \ @@ -39,7 +38,7 @@ index 2080f0978..885371de9 100644 tools_obex_server_tool_SOURCES = $(gobex_sources) $(btio_sources) \ tools/obex-server-tool.c -@@ -523,16 +523,16 @@ tools_bluetooth_player_SOURCES = tools/bluetooth-player.c client/print.c \ +@@ -500,16 +500,16 @@ tools_bluetooth_player_SOURCES = tools/bluetooth-player.c client/print.c \ client/player.c tools_bluetooth_player_LDADD = gdbus/libgdbus-internal.la \ src/libshared-glib.la \ @@ -59,7 +58,7 @@ index 2080f0978..885371de9 100644 if DEPRECATED noinst_PROGRAMS += attrib/gatttool -@@ -542,7 +542,7 @@ attrib_gatttool_SOURCES = attrib/gatttool.c attrib/att.c attrib/gatt.c \ +@@ -519,7 +519,7 @@ attrib_gatttool_SOURCES = attrib/gatttool.c attrib/att.c attrib/gatt.c \ attrib/utils.c src/log.c client/display.c \ client/display.h attrib_gatttool_LDADD = lib/libbluetooth-internal.la \ @@ -68,18 +67,18 @@ index 2080f0978..885371de9 100644 endif endif -@@ -592,5 +592,5 @@ tools/btpclient.$(OBJEXT): src/libshared-ell.la ell/internal +@@ -575,5 +575,5 @@ client/btpclient/btpclient.$(OBJEXT): src/libshared-ell.la ell/internal - tools_btpclientctl_SOURCES = tools/btpclientctl.c client/display.c - tools_btpclientctl_LDADD = src/libshared-mainloop.la src/libshared-glib.la \ + client_btpclient_btpclientctl_SOURCES = client/btpclient/btpclientctl.c client/display.c + client_btpclient_btpclientctl_LDADD = src/libshared-mainloop.la src/libshared-glib.la \ - lib/libbluetooth-internal.la -lreadline + lib/libbluetooth-internal.la $(READLINE_LIBS) endif diff --git a/configure.ac b/configure.ac -index 52de7d665..f110ab103 100644 +index b011e9b0a..10f1af4af 100644 --- a/configure.ac +++ b/configure.ac -@@ -338,8 +338,7 @@ AC_ARG_ENABLE(client, AS_HELP_STRING([--disable-client], +@@ -340,8 +340,7 @@ AC_ARG_ENABLE(client, AS_HELP_STRING([--disable-client], AM_CONDITIONAL(CLIENT, test "${enable_client}" != "no") if (test "${enable_client}" != "no" || test "${enable_mesh}" = "yes"); then From 4315f4c9982383148f98bcb2208a0bf68bc7b9e0 Mon Sep 17 00:00:00 2001 From: Jonas Heinrich Date: Sat, 8 Aug 2026 14:46:52 +0200 Subject: [PATCH 118/134] bcachefs-tools: fix riscv build --- pkgs/by-name/bc/bcachefs-tools/package.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/pkgs/by-name/bc/bcachefs-tools/package.nix b/pkgs/by-name/bc/bcachefs-tools/package.nix index 0c7bd211bd33..7d97108df4ea 100644 --- a/pkgs/by-name/bc/bcachefs-tools/package.nix +++ b/pkgs/by-name/bc/bcachefs-tools/package.nix @@ -113,6 +113,12 @@ stdenv.mkDerivation (finalAttrs: { "CARGO_TARGET_${stdenv.hostPlatform.rust.cargoEnvVarTarget}_LINKER" = "${stdenv.cc.targetPrefix}cc"; }; + # Workaround for RISCV cross-compilation issue + # https://github.com/koverstreet/bcachefs-tools/issues/850 + preBuild = lib.optionalString stdenv.hostPlatform.isRiscV '' + export BINDGEN_EXTRA_CLANG_ARGS="$BINDGEN_EXTRA_CLANG_ARGS --target=riscv64-unknown-linux-gnu -march=rv64gc" + ''; + # FIXME: Try enabling this once the default linux kernel is at least 6.7 doCheck = false; # needs bcachefs module loaded on builder From c2459f23f3b31af5d36618ec3d63dc4f735a8c5e Mon Sep 17 00:00:00 2001 From: K900 Date: Sat, 8 Aug 2026 16:12:01 +0300 Subject: [PATCH 119/134] fmt: backport 32-bit build fix --- pkgs/development/libraries/fmt/default.nix | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/pkgs/development/libraries/fmt/default.nix b/pkgs/development/libraries/fmt/default.nix index 60f3401a5c39..641a91d75629 100644 --- a/pkgs/development/libraries/fmt/default.nix +++ b/pkgs/development/libraries/fmt/default.nix @@ -105,5 +105,14 @@ in fmt_12 = generic { version = "12.2.0"; hash = "sha256-Tc7PmNxUv7ajw6GaHPGEEtrD/fl6is7RB8TPestJa1o="; + + patches = lib.optionals stdenv.is32bit [ + # fix build on 32-bit targets + # FIXME: remove in next update + (fetchpatch { + url = "https://github.com/fmtlib/fmt/commit/588b3a0f8f6a8bcf2a959cae882d5b2703e86737.patch"; + hash = "sha256-DiE3nwYrtNDJ6cqYreU499Y0auH6dsAW21TRPe16Tx8="; + }) + ]; }; } From 9b55d5e439568000afa4752ea11db12f7933661e Mon Sep 17 00:00:00 2001 From: K900 Date: Sat, 8 Aug 2026 16:47:15 +0300 Subject: [PATCH 120/134] python3Packages.typing-inspection: skip test broken by Python 3.14.7 --- .../python-modules/typing-inspection/default.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/pkgs/development/python-modules/typing-inspection/default.nix b/pkgs/development/python-modules/typing-inspection/default.nix index ce85c5b0d5b6..2da9cae3ad60 100644 --- a/pkgs/development/python-modules/typing-inspection/default.nix +++ b/pkgs/development/python-modules/typing-inspection/default.nix @@ -31,6 +31,12 @@ buildPythonPackage rec { pytestCheckHook ]; + disabledTests = [ + # broken by intentional 3.14.7 behavior change + # reported upstream: https://github.com/pydantic/typing-inspection/issues/55 + "test_literal_values_unhashable_type" + ]; + meta = { changelog = "https://github.com/pydantic/typing-inspection/blob/${src.tag}/HISTORY.md"; description = "Runtime typing introspection tools"; From 2f1cd27372337a592db2c6b8c814df76ed534d49 Mon Sep 17 00:00:00 2001 From: whispers Date: Sat, 8 Aug 2026 12:07:30 -0400 Subject: [PATCH 121/134] rocmPackages.rocprofiler-register: fix build with fmt 12.2.0 fmt 12.2.0 changes the meaning of fmt/core.h so it no longer includes fmt::format, so this upstream commit switches to the correct header. --- .../rocm-modules/rocprofiler-register/default.nix | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/pkgs/development/rocm-modules/rocprofiler-register/default.nix b/pkgs/development/rocm-modules/rocprofiler-register/default.nix index 0577493ae599..96b1ee7a90c9 100644 --- a/pkgs/development/rocm-modules/rocprofiler-register/default.nix +++ b/pkgs/development/rocm-modules/rocprofiler-register/default.nix @@ -44,6 +44,14 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-VloRKV6kUzIfIInltx/bV1EM0FUfeQZrVAx6qgdsLyg="; relative = "projects/rocprofiler-register"; }) + (fetchpatch { + # fix(rocprofiler-sdk): include fmt/format.h instead of fmt/core.h for fmt::format + # fmt 12.2.0 changes the meaning of fmt/core.h so it no longer includes + # fmt::format, so this upstream commit switches to the correct header. + url = "https://github.com/ROCm/rocm-systems/commit/e2f588592ecfb0653ed5b3078753186325adf70a.patch"; + hash = "sha256-ip/s7tmUptcXMen3fyQJYKiZKwoe3SH0XqTVb0YBA7k="; + relative = "projects/rocprofiler-register"; + }) ]; nativeBuildInputs = [ From 8ffc1507f5581b238c48b88a8025b310f40d3c12 Mon Sep 17 00:00:00 2001 From: K900 Date: Sat, 8 Aug 2026 23:42:30 +0300 Subject: [PATCH 122/134] eden: pin fmt_11 --- pkgs/by-name/ed/eden/package.nix | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ed/eden/package.nix b/pkgs/by-name/ed/eden/package.nix index 1566a8a4d7bc..81761e0787aa 100644 --- a/pkgs/by-name/ed/eden/package.nix +++ b/pkgs/by-name/ed/eden/package.nix @@ -13,7 +13,8 @@ fetchpatch, fetchurl, ffmpeg-headless, - fmt, + # FIXME: unpin when upstream supports fmt 12 + fmt_11, frozen-containers, gamemode, glslang, @@ -88,7 +89,7 @@ stdenv.mkDerivation (finalAttrs: { cubeb enet ffmpeg-headless - fmt + fmt_11 frozen-containers gamemode httplib From ecc6d7edeabbf88ec1c9b0e84470afdd14016be1 Mon Sep 17 00:00:00 2001 From: K900 Date: Sun, 9 Aug 2026 08:46:38 +0300 Subject: [PATCH 123/134] alsa-plugins: pin ffmpeg_8 --- pkgs/by-name/al/alsa-plugins/package.nix | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/al/alsa-plugins/package.nix b/pkgs/by-name/al/alsa-plugins/package.nix index e86e24ba25f7..cbc9b2a08a37 100644 --- a/pkgs/by-name/al/alsa-plugins/package.nix +++ b/pkgs/by-name/al/alsa-plugins/package.nix @@ -4,7 +4,8 @@ lib, pkg-config, alsa-lib, - ffmpeg, + # FIXME: unpin when upstream supports ffmpeg 9 + ffmpeg_8, libjack2, libogg, libpulseaudio, @@ -25,7 +26,7 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ alsa-lib - ffmpeg + ffmpeg_8 libjack2 libogg libpulseaudio From 3553fcac38b3a9e6cf8f85af4cb9294fdd5a1636 Mon Sep 17 00:00:00 2001 From: K900 Date: Sun, 9 Aug 2026 08:53:04 +0300 Subject: [PATCH 124/134] python3Packages.imap-tools: skip tests broken on Python 3.14.7 --- pkgs/development/python-modules/imap-tools/default.nix | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/pkgs/development/python-modules/imap-tools/default.nix b/pkgs/development/python-modules/imap-tools/default.nix index b0832e865eb5..2ba58d7446b5 100644 --- a/pkgs/development/python-modules/imap-tools/default.nix +++ b/pkgs/development/python-modules/imap-tools/default.nix @@ -30,6 +30,10 @@ buildPythonPackage (finalAttrs: { "test_folders" "test_idle" "test_live" + # broken on Python 3.14.7 + # reported upstream: https://github.com/ikvk/imap_tools/issues/271 + "test_login_quotes_plain_username" + "test_login_quotes_username_with_special_chars" ]; pythonImportsCheck = [ "imap_tools" ]; From ead992a288d3cef220fff76591ff7973f79d8565 Mon Sep 17 00:00:00 2001 From: K900 Date: Sun, 9 Aug 2026 09:13:43 +0300 Subject: [PATCH 125/134] python3Packages.torchcodec: pin ffmpeg_8 --- .../development/python-modules/torchcodec/default.nix | 11 ++++++----- 1 file changed, 6 insertions(+), 5 deletions(-) diff --git a/pkgs/development/python-modules/torchcodec/default.nix b/pkgs/development/python-modules/torchcodec/default.nix index 8523ebbe076c..4fad1e12ec0f 100644 --- a/pkgs/development/python-modules/torchcodec/default.nix +++ b/pkgs/development/python-modules/torchcodec/default.nix @@ -8,7 +8,8 @@ pkg-config, # buildInputs - ffmpeg, + # FIXME: unpin when upstream supports ffmpeg 9 + ffmpeg_8, # build-system cmake, @@ -45,17 +46,17 @@ buildPythonPackage.override { inherit (torch) stdenv; } (finalAttrs: { test/test_encoders.py \ --replace-fail \ '"ffprobe"' \ - '"${lib.getExe' ffmpeg "ffprobe"}"' + '"${lib.getExe' ffmpeg_8 "ffprobe"}"' substituteInPlace test/test_encoders.py \ --replace-fail \ '"ffmpeg"' \ - '"${lib.getExe ffmpeg}"' + '"${lib.getExe ffmpeg_8}"' substituteInPlace test/test_transform_ops.py \ --replace-fail \ 'ffmpeg_cli = "ffmpeg"' \ - 'ffmpeg_cli = "${lib.getExe ffmpeg}"' + 'ffmpeg_cli = "${lib.getExe ffmpeg_8}"' ''; nativeBuildInputs = [ @@ -69,7 +70,7 @@ buildPythonPackage.override { inherit (torch) stdenv; } (finalAttrs: { ]; buildInputs = [ - ffmpeg + ffmpeg_8 ] ++ lib.optionals cudaSupport ( with cudaPackages; From 6e4b044e85473744ee1031f6952080fb00c7323c Mon Sep 17 00:00:00 2001 From: Tom Hunze Date: Sun, 9 Aug 2026 11:35:55 +0200 Subject: [PATCH 126/134] sv-lang: fix build with fmt 12.2 From the fmt 12.2 changelog [1]: - Made the `` header equivalent to `` by default. Code that relied on `` pulling in `` must now either include `` directly or define `FMT_DEPRECATED_HEAVY_CORE` to opt back in. [1] https://github.com/fmtlib/fmt/blob/60ccad511fd680cb91d8b60a315759f71c67bef9/ChangeLog.md#1220---2026-06-16 --- pkgs/by-name/sv/sv-lang/package.nix | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/pkgs/by-name/sv/sv-lang/package.nix b/pkgs/by-name/sv/sv-lang/package.nix index 2f49a2bbbead..5740701c3f21 100644 --- a/pkgs/by-name/sv/sv-lang/package.nix +++ b/pkgs/by-name/sv/sv-lang/package.nix @@ -2,6 +2,7 @@ lib, stdenv, fetchFromGitHub, + fetchpatch, boost, catch2_3, cmake, @@ -22,6 +23,20 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-popHzwX0qwv2POAl7/qX3e//OwJRXGtSl9xogpSn2LI="; }; + patches = [ + (fetchpatch { + name = "fmt-12.2.patch"; + url = "https://github.com/MikePopoloski/slang/commit/5a898b4b9225d281902fcd59fe4732b1561677d2.patch"; + excludes = [ "tests/unittests/diagnostics/WaiverTests.cpp" ]; + hash = "sha256-Y+GG8UINWXh7eTXEweM42oPY8ByP4DQYgTjSLukz4I4="; + }) + ]; + + patchFlags = [ + "-p1" + "-F3" + ]; + cmakeFlags = [ # fix for https://github.com/NixOS/nixpkgs/issues/144170 "-DCMAKE_INSTALL_INCLUDEDIR=include" From 71b8bfefd1dd7850984ef12cf3c794ea2e8784b2 Mon Sep 17 00:00:00 2001 From: K900 Date: Sun, 9 Aug 2026 14:48:48 +0300 Subject: [PATCH 127/134] python3Packages.torchaudio: disable RAM intensive test This test alone baloons the memory usage of the pytest process to something like 20GB, which makes torchaudio effectively unbuildable on the kind of machines most people actually have, especially aarch64. With it skipped, the whole thing still peaks at something like 15GB, but that at least puts us under 16GB+zram which is a best-case potato system setup. --- pkgs/development/python-modules/torchaudio/default.nix | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/pkgs/development/python-modules/torchaudio/default.nix b/pkgs/development/python-modules/torchaudio/default.nix index 34595c98d830..d32064e0da90 100644 --- a/pkgs/development/python-modules/torchaudio/default.nix +++ b/pkgs/development/python-modules/torchaudio/default.nix @@ -117,10 +117,6 @@ buildPythonPackage.override { inherit (torch) stdenv; } (finalAttrs: { disabledTestPaths = [ # Require internet access "test/integration_tests" - ] - ++ lib.optionals stdenv.hostPlatform.isDarwin [ - # Passes, but hangs the build after Pytest completes - "test/torchaudio_unittest/models/models_test.py::TestConvTasNet" ]; disabledTests = [ @@ -140,6 +136,9 @@ buildPythonPackage.override { inherit (torch) stdenv; } (finalAttrs: { "AutogradCPUTest" "TestAutogradLfilterCPU" "TestWav2Vec2Model" + + # Massive RAM usage + "TestConvTasNet" ] ++ lib.optionals (hostPlatform.isLinux && hostPlatform.isAarch64) [ # AssertionError: Tensor-likes are not close! From 3bcc2b1b2778b62c59e30edc29bc78dbdeb67aa2 Mon Sep 17 00:00:00 2001 From: whispers Date: Mon, 10 Aug 2026 07:28:43 -0400 Subject: [PATCH 128/134] Revert "alsa-plugins: pin ffmpeg_8" This reverts commit ecc6d7edeabbf88ec1c9b0e84470afdd14016be1. --- pkgs/by-name/al/alsa-plugins/package.nix | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/al/alsa-plugins/package.nix b/pkgs/by-name/al/alsa-plugins/package.nix index cbc9b2a08a37..e86e24ba25f7 100644 --- a/pkgs/by-name/al/alsa-plugins/package.nix +++ b/pkgs/by-name/al/alsa-plugins/package.nix @@ -4,8 +4,7 @@ lib, pkg-config, alsa-lib, - # FIXME: unpin when upstream supports ffmpeg 9 - ffmpeg_8, + ffmpeg, libjack2, libogg, libpulseaudio, @@ -26,7 +25,7 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ alsa-lib - ffmpeg_8 + ffmpeg libjack2 libogg libpulseaudio From 99e5aff3f0c20e7fbe6904a7014ea236e33642f1 Mon Sep 17 00:00:00 2001 From: whispers Date: Sat, 8 Aug 2026 20:31:01 -0400 Subject: [PATCH 129/134] alsa-plugins: fix build with ffmpeg 9 failing build logs: https://hydra.nixos.org/build/341407667 --- pkgs/by-name/al/alsa-plugins/package.nix | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/pkgs/by-name/al/alsa-plugins/package.nix b/pkgs/by-name/al/alsa-plugins/package.nix index e86e24ba25f7..0cdecfd9b168 100644 --- a/pkgs/by-name/al/alsa-plugins/package.nix +++ b/pkgs/by-name/al/alsa-plugins/package.nix @@ -1,6 +1,7 @@ { stdenv, fetchurl, + fetchpatch, lib, pkg-config, alsa-lib, @@ -21,6 +22,14 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-e9ioPTBOji2GoliV2Nyw7wJFqN8y4nGVnNvcavObZvI="; }; + patches = [ + (fetchpatch { + name = "ffmpeg-9-compatibility.patch"; + url = "https://gitlab.archlinux.org/archlinux/packaging/packages/alsa-plugins/-/raw/7f250af93b76e9b3d552af509beb8ea1356114d1/ffmpeg9.patch"; + hash = "sha256-heAl6Ym3iYI8mhuuQpwBpc0FeFYsQZRHx4UUvqiVtBo="; + }) + ]; + nativeBuildInputs = [ pkg-config ]; buildInputs = [ From 3c17dd2ce95aa2ed557d64101cb2d41c20158865 Mon Sep 17 00:00:00 2001 From: whispers Date: Mon, 10 Aug 2026 09:05:11 -0400 Subject: [PATCH 130/134] rocmPackages.rocprofiler-sdk: fix build with fmt 12.2.0 fmt 12.2.0 changes the meaning of fmt/core.h so it no longer includes fmt::format, so this upstream commit switches to the correct header. this backports the relevant parts of an upstream commit as upstream has diverged significantly from 7.2.3: https://github.com/ROCm/rocm-systems/commit/e2f588592ecfb0653ed5b3078753186325adf70a --- .../0010-fmt-12.2.0-format.h.patch | 529 ++++++++++++++++++ .../rocm-modules/rocprofiler-sdk/default.nix | 6 + 2 files changed, 535 insertions(+) create mode 100644 pkgs/development/rocm-modules/rocprofiler-sdk/0010-fmt-12.2.0-format.h.patch diff --git a/pkgs/development/rocm-modules/rocprofiler-sdk/0010-fmt-12.2.0-format.h.patch b/pkgs/development/rocm-modules/rocprofiler-sdk/0010-fmt-12.2.0-format.h.patch new file mode 100644 index 000000000000..15d0b8e15ef9 --- /dev/null +++ b/pkgs/development/rocm-modules/rocprofiler-sdk/0010-fmt-12.2.0-format.h.patch @@ -0,0 +1,529 @@ +From 4a06d995696453b4c65217e0b11228112fb444be Mon Sep 17 00:00:00 2001 +From: Darren Lao +Date: Wed, 22 Jul 2026 11:46:17 -0400 +Subject: [PATCH] fix(rocprofiler-sdk): include fmt/format.h instead of + fmt/core.h for fmt::format (#8203) +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +## Motivation + +Since fmt v12.2.0, `` was made equivalent to `` +by default (fmtlib/fmt@0007426c). `base.h` is a lightweight subset that +no longer declares the `std::string`-returning `fmt::format` / +`fmt::vformat`, which now live only in ``. + +As a result, any source that does `#include ` and calls +`fmt::format(...)` fails to compile against system fmt 12.2.0: + +``` +error: 'format' is not a member of 'fmt' +``` + +Resolves ROCm/rocm-systems#8183. + +## Technical Details + +Replace `#include ` with `#include ` in the +files that call `fmt::format` / `fmt::vformat`, across +`rocprofiler-register`, `rocprofiler-sdk`, and `profiler-hub` (44 +files). + +- Only files that use the format.h-only symbols are changed; files that +use just `fmt::print` / `fmt::format_to` (satisfied by `base.h`) are +left on `core.h`. +- Where a file already included `` next to ``, +the redundant `core.h` line is dropped. +- The change is backward compatible: `` is a strict +superset of `` and has provided `fmt::format` in every fmt +version these components build against. Verified against the pinned +submodule (fmt 11.1.4) and system fmt 12.2.0. + +## Test Plan + +Built each affected component against a locally-installed fmt 12.2.0, +forcing the `find_package(fmt)` path (`*_BUILD_FMT=OFF`) that the report +hits: + +- `rocprofiler-register` — full library build +- `rocprofiler-sdk` — full object/shared libraries plus the changed test +targets (`counter-tests`, `aql-test`, `parser-test`) +- `profiler-hub` — full static + shared library build + +## Test Result + +- With the fix: all three components build cleanly against fmt 12.2.0 (0 +compile errors). + +## Submission Checklist + +- [x] Look over the contributing guidelines at +https://github.com/ROCm/ROCm/blob/develop/CONTRIBUTING.md#pull-requests. + +--------- +--- + source/lib/common/stringize_arg.hpp | 2 +- + source/lib/output/format_path.cpp | 2 +- + source/lib/output/generatePerfetto.cpp | 2 +- + source/lib/output/metadata.cpp | 1 - + source/lib/output/metadata.hpp | 2 +- + source/lib/output/output_stream.cpp | 1 - + source/lib/rocprofiler-sdk-rocpd/sql.cpp | 2 +- + source/lib/rocprofiler-sdk-tool/config.cpp | 2 +- + source/lib/rocprofiler-sdk-tool/tool.cpp | 2 +- + source/lib/rocprofiler-sdk/agent.cpp | 1 - + source/lib/rocprofiler-sdk/aql/helpers.cpp | 2 +- + source/lib/rocprofiler-sdk/aql/packet_construct.cpp | 2 +- + source/lib/rocprofiler-sdk/counters.cpp | 2 +- + source/lib/rocprofiler-sdk/counters/evaluate_ast.cpp | 2 +- + source/lib/rocprofiler-sdk/counters/metrics.hpp | 2 +- + source/lib/rocprofiler-sdk/counters/parser/raw_ast.hpp | 2 +- + source/lib/rocprofiler-sdk/counters/parser/scanner.cpp | 2 +- + source/lib/rocprofiler-sdk/counters/parser/scanner.l | 2 +- + source/lib/rocprofiler-sdk/counters/tests/core.cpp | 2 +- + source/lib/rocprofiler-sdk/counters/tests/device_counting.cpp | 2 +- + source/lib/rocprofiler-sdk/counters/tests/dimension.cpp | 2 +- + source/lib/rocprofiler-sdk/counters/tests/evaluate_ast_test.cpp | 2 +- + source/lib/rocprofiler-sdk/hip/utils.hpp | 2 +- + source/lib/rocprofiler-sdk/hsa/agent_cache.cpp | 2 +- + source/lib/rocprofiler-sdk/hsa/aql_packet.cpp | 2 +- + source/lib/rocprofiler-sdk/hsa/utils.hpp | 2 +- + source/lib/rocprofiler-sdk/kfd/kfd.cpp | 2 +- + source/lib/rocprofiler-sdk/marker/utils.hpp | 2 +- + source/lib/rocprofiler-sdk/ompt.cpp | 2 +- + source/lib/rocprofiler-sdk/ompt/utils.hpp | 2 +- + .../rocprofiler-sdk/pc_sampling/parser/pc_record_interface.hpp | 2 +- + source/lib/rocprofiler-sdk/rocdecode/utils.hpp | 2 +- + source/lib/rocprofiler-sdk/tests/agent.cpp | 2 +- + 33 files changed, 30 insertions(+), 33 deletions(-) + +diff --git a/source/lib/common/stringize_arg.hpp b/source/lib/common/stringize_arg.hpp +index d211fdd549..6b4b3ebdc5 100644 +--- a/source/lib/common/stringize_arg.hpp ++++ b/source/lib/common/stringize_arg.hpp +@@ -25,7 +25,7 @@ + #include "lib/common/container/small_vector.hpp" + #include "lib/common/mpl.hpp" + +-#include ++#include + #include + + #include +diff --git a/source/lib/output/format_path.cpp b/source/lib/output/format_path.cpp +index 19d6f14737..9e5816903f 100644 +--- a/source/lib/output/format_path.cpp ++++ b/source/lib/output/format_path.cpp +@@ -35,7 +35,7 @@ + + #include + +-#include ++#include + + #include + #include +diff --git a/source/lib/output/generatePerfetto.cpp b/source/lib/output/generatePerfetto.cpp +index 7935aae95a..998f05281f 100644 +--- a/source/lib/output/generatePerfetto.cpp ++++ b/source/lib/output/generatePerfetto.cpp +@@ -33,7 +33,7 @@ + #include + #include + +-#include ++#include + + #include + #include +diff --git a/source/lib/output/metadata.cpp b/source/lib/output/metadata.cpp +index abe9e00b50..f68d46de5b 100644 +--- a/source/lib/output/metadata.cpp ++++ b/source/lib/output/metadata.cpp +@@ -41,7 +41,6 @@ + #include + #include + +-#include + #include + + #include +diff --git a/source/lib/output/metadata.hpp b/source/lib/output/metadata.hpp +index 069401f962..a283896f29 100644 +--- a/source/lib/output/metadata.hpp ++++ b/source/lib/output/metadata.hpp +@@ -45,7 +45,7 @@ + #include + #include + +-#include ++#include + + #include + #include +diff --git a/source/lib/output/output_stream.cpp b/source/lib/output/output_stream.cpp +index 7c1307e5e7..fbfffe5014 100644 +--- a/source/lib/output/output_stream.cpp ++++ b/source/lib/output/output_stream.cpp +@@ -25,7 +25,6 @@ + #include "lib/common/filesystem.hpp" + #include "lib/common/logging.hpp" + +-#include + #include + + #include +diff --git a/source/lib/rocprofiler-sdk-rocpd/sql.cpp b/source/lib/rocprofiler-sdk-rocpd/sql.cpp +index b052ec51c3..7fd5421fe3 100644 +--- a/source/lib/rocprofiler-sdk-rocpd/sql.cpp ++++ b/source/lib/rocprofiler-sdk-rocpd/sql.cpp +@@ -35,7 +35,7 @@ + + #include + +-#include ++#include + #include + + #include +diff --git a/source/lib/rocprofiler-sdk-tool/config.cpp b/source/lib/rocprofiler-sdk-tool/config.cpp +index f172d74c1b..35fff5b170 100644 +--- a/source/lib/rocprofiler-sdk-tool/config.cpp ++++ b/source/lib/rocprofiler-sdk-tool/config.cpp +@@ -34,7 +34,7 @@ + + #include + +-#include ++#include + + #include + #include +diff --git a/source/lib/rocprofiler-sdk-tool/tool.cpp b/source/lib/rocprofiler-sdk-tool/tool.cpp +index e36582550d..6ddb2274e5 100644 +--- a/source/lib/rocprofiler-sdk-tool/tool.cpp ++++ b/source/lib/rocprofiler-sdk-tool/tool.cpp +@@ -78,7 +78,7 @@ + #include + #include + +-#include ++#include + #include + + #include +diff --git a/source/lib/rocprofiler-sdk/agent.cpp b/source/lib/rocprofiler-sdk/agent.cpp +index fe5af0c1d6..89b912b822 100644 +--- a/source/lib/rocprofiler-sdk/agent.cpp ++++ b/source/lib/rocprofiler-sdk/agent.cpp +@@ -34,7 +34,6 @@ + #include + #include + +-#include + #include + #include + #include +diff --git a/source/lib/rocprofiler-sdk/aql/helpers.cpp b/source/lib/rocprofiler-sdk/aql/helpers.cpp +index 35842b1233..eaf7f5dd2a 100644 +--- a/source/lib/rocprofiler-sdk/aql/helpers.cpp ++++ b/source/lib/rocprofiler-sdk/aql/helpers.cpp +@@ -30,7 +30,7 @@ + + #include + +-#include ++#include + + namespace rocprofiler + { +diff --git a/source/lib/rocprofiler-sdk/aql/packet_construct.cpp b/source/lib/rocprofiler-sdk/aql/packet_construct.cpp +index 3417bd090d..e51f103ff5 100644 +--- a/source/lib/rocprofiler-sdk/aql/packet_construct.cpp ++++ b/source/lib/rocprofiler-sdk/aql/packet_construct.cpp +@@ -24,7 +24,7 @@ + #include "lib/common/logging.hpp" + #include "lib/rocprofiler-sdk/hsa/details/fmt.hpp" + +-#include ++#include + #include + #include "glog/logging.h" + +diff --git a/source/lib/rocprofiler-sdk/counters.cpp b/source/lib/rocprofiler-sdk/counters.cpp +index 96667ee75e..026dcab909 100644 +--- a/source/lib/rocprofiler-sdk/counters.cpp ++++ b/source/lib/rocprofiler-sdk/counters.cpp +@@ -41,7 +41,7 @@ + #include + #include + +-#include ++#include + + namespace rocprofiler + { +diff --git a/source/lib/rocprofiler-sdk/counters/evaluate_ast.cpp b/source/lib/rocprofiler-sdk/counters/evaluate_ast.cpp +index bbc3ea1a95..61d9a6c492 100644 +--- a/source/lib/rocprofiler-sdk/counters/evaluate_ast.cpp ++++ b/source/lib/rocprofiler-sdk/counters/evaluate_ast.cpp +@@ -34,7 +34,7 @@ + #include + #include + +-#include ++#include + #include + + #include +diff --git a/source/lib/rocprofiler-sdk/counters/metrics.hpp b/source/lib/rocprofiler-sdk/counters/metrics.hpp +index 7915bc8805..a65b98f6ad 100644 +--- a/source/lib/rocprofiler-sdk/counters/metrics.hpp ++++ b/source/lib/rocprofiler-sdk/counters/metrics.hpp +@@ -25,7 +25,7 @@ + #include + #include + +-#include ++#include + #include + #include + +diff --git a/source/lib/rocprofiler-sdk/counters/parser/raw_ast.hpp b/source/lib/rocprofiler-sdk/counters/parser/raw_ast.hpp +index 2f1d6f4dd4..ff5ea7abd9 100644 +--- a/source/lib/rocprofiler-sdk/counters/parser/raw_ast.hpp ++++ b/source/lib/rocprofiler-sdk/counters/parser/raw_ast.hpp +@@ -26,7 +26,7 @@ + #include "lib/common/utility.hpp" + #include "lib/rocprofiler-sdk/counters/id_decode.hpp" + +-#include ++#include + #include + + #include +diff --git a/source/lib/rocprofiler-sdk/counters/parser/scanner.cpp b/source/lib/rocprofiler-sdk/counters/parser/scanner.cpp +index 57acd7186d..c08171e866 100644 +--- a/source/lib/rocprofiler-sdk/counters/parser/scanner.cpp ++++ b/source/lib/rocprofiler-sdk/counters/parser/scanner.cpp +@@ -470,7 +470,7 @@ int yy_flex_debug = 0; + char* yytext; + #line 1 "scanner.l" + #line 4 "scanner.l" +-#include ++#include + + #include "parser.h" + #include "raw_ast.hpp" +diff --git a/source/lib/rocprofiler-sdk/counters/parser/scanner.l b/source/lib/rocprofiler-sdk/counters/parser/scanner.l +index a1f7edf7ea..196bf2c3a1 100644 +--- a/source/lib/rocprofiler-sdk/counters/parser/scanner.l ++++ b/source/lib/rocprofiler-sdk/counters/parser/scanner.l +@@ -1,7 +1,7 @@ + %option noyywrap nodefault yylineno nounput + + %{ +-#include ++#include + + #include "raw_ast.hpp" + #include "parser.h" +diff --git a/source/lib/rocprofiler-sdk/counters/tests/core.cpp b/source/lib/rocprofiler-sdk/counters/tests/core.cpp +index 5ecbf5e3cc..61d2721c87 100644 +--- a/source/lib/rocprofiler-sdk/counters/tests/core.cpp ++++ b/source/lib/rocprofiler-sdk/counters/tests/core.cpp +@@ -41,7 +41,7 @@ + #include + #include + +-#include ++#include + #include + #include + #include +diff --git a/source/lib/rocprofiler-sdk/counters/tests/device_counting.cpp b/source/lib/rocprofiler-sdk/counters/tests/device_counting.cpp +index d82a6ec40b..514e129ad3 100644 +--- a/source/lib/rocprofiler-sdk/counters/tests/device_counting.cpp ++++ b/source/lib/rocprofiler-sdk/counters/tests/device_counting.cpp +@@ -38,7 +38,7 @@ + #include + #include + +-#include ++#include + #include + #include + #include +diff --git a/source/lib/rocprofiler-sdk/counters/tests/dimension.cpp b/source/lib/rocprofiler-sdk/counters/tests/dimension.cpp +index 22fcda9bf7..6583ae0897 100644 +--- a/source/lib/rocprofiler-sdk/counters/tests/dimension.cpp ++++ b/source/lib/rocprofiler-sdk/counters/tests/dimension.cpp +@@ -38,7 +38,7 @@ + #include + #include + +-#include ++#include + #include + #include + #include +diff --git a/source/lib/rocprofiler-sdk/counters/tests/evaluate_ast_test.cpp b/source/lib/rocprofiler-sdk/counters/tests/evaluate_ast_test.cpp +index b7aca0c638..40c4c88bbf 100644 +--- a/source/lib/rocprofiler-sdk/counters/tests/evaluate_ast_test.cpp ++++ b/source/lib/rocprofiler-sdk/counters/tests/evaluate_ast_test.cpp +@@ -28,7 +28,7 @@ + + #include + +-#include ++#include + #include + + #include +diff --git a/source/lib/rocprofiler-sdk/hip/utils.hpp b/source/lib/rocprofiler-sdk/hip/utils.hpp +index 53916cbb5d..360577a5e8 100644 +--- a/source/lib/rocprofiler-sdk/hip/utils.hpp ++++ b/source/lib/rocprofiler-sdk/hip/utils.hpp +@@ -29,7 +29,7 @@ + #include "lib/rocprofiler-sdk/hip/details/format.hpp" + #include "lib/rocprofiler-sdk/hip/details/ostream.hpp" + +-#include "fmt/core.h" ++#include "fmt/format.h" + #include "fmt/ranges.h" + + #include +diff --git a/source/lib/rocprofiler-sdk/hsa/agent_cache.cpp b/source/lib/rocprofiler-sdk/hsa/agent_cache.cpp +index 196a122abc..251ddaf75c 100644 +--- a/source/lib/rocprofiler-sdk/hsa/agent_cache.cpp ++++ b/source/lib/rocprofiler-sdk/hsa/agent_cache.cpp +@@ -24,7 +24,7 @@ + #include "lib/common/environment.hpp" + #include "lib/common/logging.hpp" + +-#include ++#include + #include + + #include "lib/rocprofiler-sdk/context/context.hpp" +diff --git a/source/lib/rocprofiler-sdk/hsa/aql_packet.cpp b/source/lib/rocprofiler-sdk/hsa/aql_packet.cpp +index f1c0c3a56e..389a182e9d 100644 +--- a/source/lib/rocprofiler-sdk/hsa/aql_packet.cpp ++++ b/source/lib/rocprofiler-sdk/hsa/aql_packet.cpp +@@ -21,7 +21,7 @@ + // THE SOFTWARE. + + #include "lib/rocprofiler-sdk/hsa/aql_packet.hpp" +-#include ++#include + #include + #include + #include "lib/common/logging.hpp" +diff --git a/source/lib/rocprofiler-sdk/hsa/utils.hpp b/source/lib/rocprofiler-sdk/hsa/utils.hpp +index 004cb466b9..1560ef6a9e 100644 +--- a/source/lib/rocprofiler-sdk/hsa/utils.hpp ++++ b/source/lib/rocprofiler-sdk/hsa/utils.hpp +@@ -27,7 +27,7 @@ + #include "lib/common/stringize_arg.hpp" + #include "lib/rocprofiler-sdk/hsa/details/fmt.hpp" + +-#include ++#include + #include + #include + #include +diff --git a/source/lib/rocprofiler-sdk/kfd/kfd.cpp b/source/lib/rocprofiler-sdk/kfd/kfd.cpp +index 83fef31bbc..fdeb6f9bd5 100644 +--- a/source/lib/rocprofiler-sdk/kfd/kfd.cpp ++++ b/source/lib/rocprofiler-sdk/kfd/kfd.cpp +@@ -40,7 +40,7 @@ + #include + #include + +-#include ++#include + + #include + #include +diff --git a/source/lib/rocprofiler-sdk/marker/utils.hpp b/source/lib/rocprofiler-sdk/marker/utils.hpp +index c0dd168575..4a50b91d83 100644 +--- a/source/lib/rocprofiler-sdk/marker/utils.hpp ++++ b/source/lib/rocprofiler-sdk/marker/utils.hpp +@@ -28,7 +28,7 @@ + #include "lib/common/mpl.hpp" + #include "lib/common/stringize_arg.hpp" + +-#include ++#include + #include + + #include +diff --git a/source/lib/rocprofiler-sdk/ompt.cpp b/source/lib/rocprofiler-sdk/ompt.cpp +index a9ccc571c8..0d7166465a 100644 +--- a/source/lib/rocprofiler-sdk/ompt.cpp ++++ b/source/lib/rocprofiler-sdk/ompt.cpp +@@ -31,7 +31,7 @@ + #include + #include + +-#include ++#include + #include + #include + +diff --git a/source/lib/rocprofiler-sdk/ompt/utils.hpp b/source/lib/rocprofiler-sdk/ompt/utils.hpp +index 32da94c011..29f3780448 100644 +--- a/source/lib/rocprofiler-sdk/ompt/utils.hpp ++++ b/source/lib/rocprofiler-sdk/ompt/utils.hpp +@@ -27,7 +27,7 @@ + + #include + +-#include ++#include + #include + + #include +diff --git a/source/lib/rocprofiler-sdk/pc_sampling/parser/pc_record_interface.hpp b/source/lib/rocprofiler-sdk/pc_sampling/parser/pc_record_interface.hpp +index 9652c8426c..736e6bc65f 100644 +--- a/source/lib/rocprofiler-sdk/pc_sampling/parser/pc_record_interface.hpp ++++ b/source/lib/rocprofiler-sdk/pc_sampling/parser/pc_record_interface.hpp +@@ -31,7 +31,7 @@ + #include + #include + +-#include ++#include + #include + #include + #include +diff --git a/source/lib/rocprofiler-sdk/rocdecode/utils.hpp b/source/lib/rocprofiler-sdk/rocdecode/utils.hpp +index 996419c015..42e5bbe0fc 100644 +--- a/source/lib/rocprofiler-sdk/rocdecode/utils.hpp ++++ b/source/lib/rocprofiler-sdk/rocdecode/utils.hpp +@@ -25,7 +25,7 @@ + #include "lib/common/stringize_arg.hpp" + #include "lib/rocprofiler-sdk/rocdecode/details/format.hpp" + +-#include "fmt/core.h" ++#include "fmt/format.h" + #include "fmt/ranges.h" + + #include +diff --git a/source/lib/rocprofiler-sdk/tests/agent.cpp b/source/lib/rocprofiler-sdk/tests/agent.cpp +index e951160899..7f6689b73f 100644 +--- a/source/lib/rocprofiler-sdk/tests/agent.cpp ++++ b/source/lib/rocprofiler-sdk/tests/agent.cpp +@@ -31,7 +31,7 @@ + #include + #include + +-#include ++#include + #include + #include + #include +-- +2.55.0 + diff --git a/pkgs/development/rocm-modules/rocprofiler-sdk/default.nix b/pkgs/development/rocm-modules/rocprofiler-sdk/default.nix index 5806bc23c40f..d5caa277fe46 100644 --- a/pkgs/development/rocm-modules/rocprofiler-sdk/default.nix +++ b/pkgs/development/rocm-modules/rocprofiler-sdk/default.nix @@ -142,6 +142,12 @@ stdenv.mkDerivation (finalAttrs: { # "[rocprofiler-sdk] Migrate from glog to Abseil Logging (#4668)", which # is too invasive (40 files + new abseil submodule) to backport. ./0009-rocprofiler-sdk-guard-ompt-auto-start.patch + + # fmt v12.2.0 changed the structure of fmt/core.h, so this switches uses of + # fmt/core.h to fmt/format.h. backport of the relevant parts of + # https://github.com/ROCm/rocm-systems/commit/e2f588592ecfb0653ed5b3078753186325adf70a + # as upstream has changed significantly since 7.2.3. + ./0010-fmt-12.2.0-format.h.patch ]; postPatch = '' From 71bf9686498744de6f0592596d86fc84b0227768 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sandro=20J=C3=A4ckel?= Date: Mon, 10 Aug 2026 15:54:10 +0200 Subject: [PATCH 131/134] python3Packages.oslo-log: 8.1.0 -> 8.3.0 Diff: https://github.com/openstack/oslo.log/compare/8.1.0...8.3.0 --- .../python-modules/oslo-log/default.nix | 18 ++++++++---------- 1 file changed, 8 insertions(+), 10 deletions(-) diff --git a/pkgs/development/python-modules/oslo-log/default.nix b/pkgs/development/python-modules/oslo-log/default.nix index c221fb175b4c..50bb52bcb7cb 100644 --- a/pkgs/development/python-modules/oslo-log/default.nix +++ b/pkgs/development/python-modules/oslo-log/default.nix @@ -1,6 +1,5 @@ { lib, - stdenv, buildPythonPackage, fetchFromGitHub, @@ -11,11 +10,11 @@ debtcollector, oslo-config, oslo-context, + oslo-i18n, oslo-serialization, oslo-utils, pbr, python-dateutil, - pyinotify, # tests eventlet, @@ -25,14 +24,14 @@ buildPythonPackage rec { pname = "oslo-log"; - version = "8.1.0"; + version = "8.3.0"; pyproject = true; src = fetchFromGitHub { owner = "openstack"; repo = "oslo.log"; tag = version; - hash = "sha256-ThRJ2rfVStnVOwcu8ZaKDjqb4jT6YE+n+iOFtmR8rwQ="; + hash = "sha256-teESuCQg8fxCWPMUWTTYyBIGSn9m916Uoy3UkWArVVs="; }; # Manually set version because prb wants to get it from the git upstream repository (and we are @@ -45,12 +44,12 @@ buildPythonPackage rec { debtcollector oslo-config oslo-context + oslo-i18n oslo-serialization oslo-utils pbr python-dateutil - ] - ++ lib.optionals stdenv.hostPlatform.isLinux [ pyinotify ]; + ]; nativeCheckInputs = [ eventlet @@ -59,11 +58,10 @@ buildPythonPackage rec { ]; disabledTests = [ - # not compatible with sandbox - "test_logging_handle_error" # Incompatible Exception Representation, displaying natively - "test_rate_limit" - "test_rate_limit_except_level" + "test_logging_handle_error" + "test_rotate_log" + "test_timed_rotate_log" ]; pythonImportsCheck = [ "oslo_log" ]; From 5a29530a22d30d3f04a97eb1187e50e88347dfc8 Mon Sep 17 00:00:00 2001 From: Ryan Omasta Date: Mon, 10 Aug 2026 18:23:24 -0600 Subject: [PATCH 132/134] python3Packages.mediapy: pin to ffmpeg_8-headless --- pkgs/development/python-modules/mediapy/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/mediapy/default.nix b/pkgs/development/python-modules/mediapy/default.nix index 1081b0cc331e..aca87a7276c9 100644 --- a/pkgs/development/python-modules/mediapy/default.nix +++ b/pkgs/development/python-modules/mediapy/default.nix @@ -9,7 +9,7 @@ numpy, pillow, absl-py, - ffmpeg-headless, + ffmpeg_8-headless, pytestCheckHook, }: @@ -41,7 +41,7 @@ buildPythonPackage (finalAttrs: { nativeCheckInputs = [ absl-py - ffmpeg-headless + ffmpeg_8-headless pytestCheckHook ]; From 8fc67396b3276bfdcfdc4db92cd3063f0728da69 Mon Sep 17 00:00:00 2001 From: Jost Alemann Date: Tue, 11 Aug 2026 09:42:17 +0200 Subject: [PATCH 133/134] ty: 0.0.69 -> 0.0.70 Changelog: https://github.com/astral-sh/ty/releases/tag/0.0.70 Diff: https://github.com/astral-sh/ty/compare/0.0.69...0.0.70 --- pkgs/by-name/ty/ty/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ty/ty/package.nix b/pkgs/by-name/ty/ty/package.nix index 0a57be97ee5f..d71e6974b5bb 100644 --- a/pkgs/by-name/ty/ty/package.nix +++ b/pkgs/by-name/ty/ty/package.nix @@ -17,7 +17,7 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "ty"; - version = "0.0.69"; + version = "0.0.70"; __structuredAttrs = true; src = fetchFromGitHub { @@ -25,7 +25,7 @@ rustPlatform.buildRustPackage (finalAttrs: { repo = "ty"; tag = finalAttrs.version; fetchSubmodules = true; - hash = "sha256-bu/2vHmhHYS/3EZM9Ibh8Y0v/aigriDwWu7Wn7gNvds="; + hash = "sha256-rlhU/987KaTAXukZDUDY0XyDUQiC6qHGIXS2epg6ziI="; }; # For Darwin platforms, remove the integration test for file notifications, @@ -39,7 +39,7 @@ rustPlatform.buildRustPackage (finalAttrs: { cargoBuildFlags = [ "--package=ty" ]; - cargoHash = "sha256-DUCTpqnzsGPH3OQkutduqrCZd7uuOgbZZmnXNCC8YdY="; + cargoHash = "sha256-eM+MdAxx6UqvFSTnUmCk7Nx1MuprrYrv/64Jy90nE0c="; nativeBuildInputs = [ installShellFiles ]; buildInputs = [ rust-jemalloc-sys ]; From a3f12504d299d8c35e2e1f9799fadb3b6e4d0c03 Mon Sep 17 00:00:00 2001 From: qubitnano <146656568+qubitnano@users.noreply.github.com> Date: Sun, 9 Aug 2026 20:43:08 -0400 Subject: [PATCH 134/134] bcachefs-tools: 1.38.8 -> 1.39.1 https://evilpiepirate.org/git/bcachefs-tools.git/tree/Changelog.mdwn --- pkgs/by-name/bc/bcachefs-tools/package.nix | 17 +++-------------- 1 file changed, 3 insertions(+), 14 deletions(-) diff --git a/pkgs/by-name/bc/bcachefs-tools/package.nix b/pkgs/by-name/bc/bcachefs-tools/package.nix index 0c7bd211bd33..0a794322e191 100644 --- a/pkgs/by-name/bc/bcachefs-tools/package.nix +++ b/pkgs/by-name/bc/bcachefs-tools/package.nix @@ -2,7 +2,6 @@ lib, stdenv, fetchFromGitHub, - fetchpatch, pkg-config, libuuid, libsodium, @@ -32,29 +31,20 @@ stdenv.mkDerivation (finalAttrs: { pname = "bcachefs-tools"; - version = "1.38.8"; + version = "1.39.1"; src = fetchFromGitHub { owner = "koverstreet"; repo = "bcachefs-tools"; tag = "v${finalAttrs.version}"; - hash = "sha256-9sDE7ua3WMCfV9ZbwQdAbpatv2IhvcwHzzPr+/l2au0="; + hash = "sha256-KJBzVbK5DL+ZK27Oyyn8vCWRQUHrIAelrex1oX+fWq4="; }; cargoDeps = rustPlatform.fetchCargoVendor { inherit (finalAttrs) src; - hash = "sha256-F1+FeAlYSqOxeWJI8vHShpXrOZqYXjNGvty/s6f6u8w="; + hash = "sha256-Yb2DaFLuhAkwYED+s9SRKsjxluWoES4RSvKPKfd/kyE="; }; - patches = [ - # Fix compile-time assertion failure on big-endian - (fetchpatch { - name = "0001-bcachefs-tools-debug-copy-packed-bkey-fields-before-asserting.patch"; - url = "https://evilpiepirate.org/git/bcachefs-tools.git/patch/?id=79f119c4cd6900ab9ea27b0aa671f68300d9d38e"; - hash = "sha256-ACrpad93wrZOXhc73otnXBNQvyoDeZSfgtwze5nKaUE="; - }) - ]; - postPatch = '' substituteInPlace Makefile \ --replace-fail "target/release/bcachefs" "target/${stdenv.hostPlatform.rust.rustcTargetSpec}/release/bcachefs" @@ -163,6 +153,5 @@ stdenv.mkDerivation (finalAttrs: { ]; platforms = lib.platforms.linux; mainProgram = "bcachefs"; - broken = stdenv.hostPlatform.isi686; # error: stack smashing detected }; })