Merge release-26.05 into staging-next-26.05

This commit is contained in:
nixpkgs-ci[bot]
2026-10-01 00:35:37 +00:00
committed by GitHub
31 changed files with 394 additions and 196 deletions

View File

@@ -45,6 +45,17 @@ in
default = null;
};
databaseEncryptionKeysFile = mkOption {
description = ''
Path to file containing encryption key(s) to encrypt target credentials stored in database.
Should be a env-like file: `WARPGATE_ENCRYPTION_KEY=$(openssl rand -base64 32)`.
If you are rotating key, move the old key to `WARPGATE_ENCRYPTION_KEY_OLD`.
See [Encrypting credentials at rest](https://warpgate.null.page/encryption/).
'';
type = nullOr str;
default = null;
};
settings = mkOption {
description = "Warpgate configuration.";
type = submodule {
@@ -120,18 +131,6 @@ in
]
'';
};
recordings = {
enable = mkOption {
description = "Whether to enable session recording.";
default = true;
type = bool;
};
path = mkOption {
description = "Path to store session recordings.";
default = "/var/lib/warpgate/recordings";
type = str;
};
};
external_host = mkOption {
description = ''
Configure the domain name of this Warpgate instance.
@@ -160,6 +159,11 @@ in
default = "[::]:2222";
type = str;
};
proxy_protocol = mkOption {
description = "Accept HAProxy PROXY protocol v1/v2 headers from upstream reverse proxy.";
default = false;
type = bool;
};
external_host = mkOption {
description = "The SSH listener is reachable via this domain name externally.";
default = null;
@@ -201,6 +205,11 @@ in
default = "[::]:8888";
type = str;
};
proxy_protocol = mkOption {
description = "Accept HAProxy PROXY protocol v1/v2 headers from upstream reverse proxy.";
default = false;
type = bool;
};
external_host = mkOption {
description = "The HTTP listener is reachable via this domain name externally.";
default = null;
@@ -270,6 +279,88 @@ in
type = str;
};
};
rdp = {
enable = mkOption {
description = "Whether to enable RDP listener.";
default = false;
type = bool;
};
listen = mkOption {
description = "Listen endpoint of RDP listener.";
default = "[::]:3389";
type = str;
};
proxy_protocol = mkOption {
description = "Accept HAProxy PROXY protocol v1/v2 headers from the listener's peer.";
default = false;
type = bool;
};
external_host = mkOption {
description = "The RDP listener is reachable via this domain name externally.";
default = null;
type = nullOr str;
};
external_port = mkOption {
description = "The RDP listener is reachable via this port externally.";
default = null;
type = nullOr str;
};
certificate = mkOption {
description = "Path to RDP listener certificate.";
default = "/var/lib/warpgate/tls.certificate.pem";
type = str;
};
key = mkOption {
description = "Path to RDP listener private key.";
default = "/var/lib/warpgate/tls.key.pem";
type = str;
};
};
vnc = {
enable = mkOption {
description = "Whether to enable VNC listener.";
default = false;
type = bool;
};
listen = mkOption {
description = "Listen endpoint of VNC listener.";
default = "[::]:5900";
type = str;
};
proxy_protocol = mkOption {
description = "Accept HAProxy PROXY protocol v1/v2 headers from the listener's peer.";
default = false;
type = bool;
};
external_host = mkOption {
description = "The VNC listener is reachable via this domain name externally.";
default = null;
type = nullOr str;
};
external_port = mkOption {
description = "The VNC listener is reachable via this port externally.";
default = null;
type = nullOr str;
};
certificate = mkOption {
description = "Path to VNC listener certificate.";
default = "/var/lib/warpgate/tls.certificate.pem";
type = str;
};
key = mkOption {
description = "Path to VNC listener private key.";
default = "/var/lib/warpgate/tls.key.pem";
type = str;
};
enable_ard_auth = mkOption {
description = ''
Enable Apple-DH (Apple Remote Desktop / type 30) auth, which is to ensure compatibility with Apple clients.
However [connections from macOS built-in VNC client with ARD auth is not supported](https://github.com/warp-tech/warpgate/blob/47e676969a0b1e0b8456f9a5f1474d6c58648c4f/warpgate-protocol-vnc/src/server/rfb.rs#L8-L10).
'';
default = false;
type = bool;
};
};
mysql = {
enable = mkOption {
description = "Whether to enable MySQL listener.";
@@ -281,6 +372,11 @@ in
default = "[::]:33306";
type = str;
};
proxy_protocol = mkOption {
description = "Accept HAProxy PROXY protocol v1/v2 headers from upstream reverse proxy.";
default = false;
type = bool;
};
external_host = mkOption {
description = "The MySQL listener is reachable via this domain name externally.";
default = null;
@@ -301,6 +397,14 @@ in
default = "/var/lib/warpgate/tls.key.pem";
type = str;
};
advertised_version = mkOption {
description = ''
The server version advertised to clients during the handshake.
Warpgate can't auto-match the target's version since the target is only known after the handshake, but Warpgate's clients use it to pick a protocol dialect.
'';
default = "8.0.3-Warpgate";
type = str;
};
};
postgres = {
enable = mkOption {
@@ -313,6 +417,11 @@ in
default = "[::]:55432";
type = str;
};
proxy_protocol = mkOption {
description = "Accept HAProxy PROXY protocol v1/v2 headers from upstream reverse proxy.";
default = false;
type = bool;
};
external_host = mkOption {
description = "The PostgreSQL listener is reachable via this domain name externally.";
default = null;
@@ -345,6 +454,11 @@ in
default = "[::]:8443";
type = str;
};
proxy_protocol = mkOption {
description = "Accept HAProxy PROXY protocol v1/v2 headers from upstream reverse proxy.";
default = false;
type = bool;
};
external_host = mkOption {
description = "The Kubernetes listener is reachable via this domain name externally.";
default = null;
@@ -420,36 +534,45 @@ in
any
map
head
optional
reverseList
;
inherit (lib.strings) splitString toIntBase10;
inherit (lib.strings)
optionalString
splitString
toIntBase10
;
preStartScript = pkgs.writers.writeBash "warpgate-init" ''
CFGFILE=/var/lib/warpgate/config.yaml
renderedYamlConfig = yaml.generate "warpgate-config" cfg.settings;
startupScript = pkgs.writeShellScript "warpgate-run" ''
CFGFILE=$STATE_DIRECTORY/config.yaml
if [ ! -O $CFGFILE ] || [ ! -s $CFGFILE ]; then
INITPWD=$(tr -dc 'A-Za-z0-9!?%=' </dev/urandom 2>/dev/null | head -c 16)
${lib.getExe cfg.package} \
--config $CFGFILE unattended-setup \
--data-path /var/lib/warpgate \
--data-path $STATE_DIRECTORY \
--http-port 8888 \
--admin-password $INITPWD
fi
${
if cfg.databaseUrlFile != null then
''
sed -e '/^database_url: null/d' ${yaml.generate "warpgate-config" cfg.settings} > $CFGFILE
cat /run/credentials/warpgate.service/databaseUrl >> $CFGFILE
''
else
"cp --no-preserve=ownership ${yaml.generate "warpgate-config" cfg.settings} $CFGFILE"
}
cp --no-preserve=ownership ${renderedYamlConfig} $CFGFILE
${optionalString (cfg.databaseUrlFile != null) ''
sed -e '/^database_url: null/d' ${renderedYamlConfig} > $CFGFILE
cat $CREDENTIALS_DIRECTORY/databaseUrl >> $CFGFILE
''}
${optionalString (cfg.databaseEncryptionKeysFile != null) ''
set -a
source $CREDENTIALS_DIRECTORY/dbEncryptionKeys
set +a
''}
${lib.getExe cfg.package} --config $CFGFILE run
'';
bindOnPrivilegedPorts = any (x: toIntBase10 x < 1025) (
map (x: head (reverseList (splitString ":" x))) (
[ cfg.settings.http.listen ]
++ lib.optional cfg.settings.ssh.enable cfg.settings.ssh.listen
++ lib.optional cfg.settings.mysql.enable cfg.settings.mysql.listen
++ lib.optional cfg.settings.postgres.enable cfg.settings.postgres.listen
++ optional cfg.settings.ssh.enable cfg.settings.ssh.listen
++ optional cfg.settings.mysql.enable cfg.settings.mysql.listen
++ optional cfg.settings.postgres.enable cfg.settings.postgres.listen
)
);
in
@@ -467,6 +590,10 @@ in
assertion = !(lib.hasAttr "config_provider" cfg.settings);
message = "`services.warpgate.settings.config_provider` is a legacy option that has been removed since 0.14.0. Please do not set this option.";
}
{
assertion = !(lib.hasAttr "recordings" cfg.settings);
message = "`services.warpgate.settings.recordings` has been deprecated by S3 recording storage support in 0.27.0. Please remove this section from your config and set it from admin UI.";
}
];
environment.systemPackages = [ cfg.package ];
@@ -474,14 +601,16 @@ in
systemd.services.warpgate = {
description = "Warpgate smart bastion";
wantedBy = [ "multi-user.target" ];
after = [ "network.target" ];
wants = [ "network-online.target" ];
after = [ "network-online.target" ];
startLimitBurst = 5;
serviceConfig = {
LoadCredential = "${
if cfg.databaseUrlFile != null then "databaseUrl:${cfg.databaseUrlFile}" else ""
}";
ExecStartPre = preStartScript;
ExecStart = "${lib.getExe cfg.package} --config /var/lib/warpgate/config.yaml run";
LoadCredential =
optional (cfg.databaseUrlFile != null) "databaseUrl:${cfg.databaseUrlFile}"
++ optional (
cfg.databaseEncryptionKeysFile != null
) "dbEncryptionKeys:${cfg.databaseEncryptionKeysFile}";
ExecStart = startupScript;
DynamicUser = true;
RestartSec = 3;
Restart = "on-failure";

View File

@@ -1,3 +1,4 @@
{ pkgs, ... }:
{
name = "warpgate";
@@ -9,14 +10,29 @@
};
machine2 = {
environment.etc."warpgate-db-url".text = "database: sqlite:/var/lib/warpgate/db/";
environment.etc."warpgate-db-url".text =
"database_url: postgresql://warpgate:warpgate@localhost:5432/warpgate";
environment.etc."warpgate-db-enc".text =
"WARPGATE_ENCRYPTION_KEY=QVJBTkRPTTMyQ0hBUkFDVEVSU0VOQ1JZUFRJT05LRVk=";
services.warpgate = {
enable = true;
databaseUrlFile = "/etc/warpgate-db-url";
databaseEncryptionKeysFile = "/etc/warpgate-db-enc";
settings = {
database_url = null;
};
};
services.postgresql = {
enable = true;
initialScript = pkgs.writeText "psql-init" ''
CREATE ROLE warpgate WITH LOGIN PASSWORD 'warpgate';
CREATE DATABASE warpgate WITH OWNER warpgate;
'';
};
systemd.services.warpgate = {
after = [ "postgresql.target" ];
requires = [ "postgresql.target" ];
};
};
machine3 = {
@@ -24,6 +40,12 @@
enable = true;
settings = {
http.listen = "[::]:443";
ssh.enable = true;
rdp.enable = true;
vnc.enable = true;
mysql.enable = true;
postgres.enable = true;
kubernetes.enable = true;
};
};
};
@@ -43,6 +65,12 @@
machine3.wait_for_unit("warpgate.service")
machine3.wait_for_open_port(443)
machine3.wait_for_open_port(2222)
machine3.wait_for_open_port(3389)
machine3.wait_for_open_port(5900)
machine3.wait_for_open_port(33306)
machine3.wait_for_open_port(55432)
machine3.wait_for_open_port(8443)
machine3.succeed("curl -k --fail https://localhost/@warpgate")
machine3.shutdown()
'';

View File

@@ -1,10 +1,10 @@
{
"chromium": {
"version": "154.0.8037.57",
"version": "154.0.8037.92",
"chromedriver": {
"version": "154.0.8037.58",
"hash_darwin": "sha256-oMomlVZiLv+QQGHNq0Ao5tq++wCt1wAQmmddj0ARUKU=",
"hash_darwin_aarch64": "sha256-9Yy5BKjSdTr44fZp15lHPgXV9nMynXjF6Srw6CoAlAY="
"version": "154.0.8037.93",
"hash_darwin": "sha256-98b3h7D4+HHaZ7sLsr8v4Uv0xc3TqJLI2DWd8jchMCY=",
"hash_darwin_aarch64": "sha256-RVAlxmcKbxi7VPYXOwJlup3CLwLE/YPpISWDlaYQdPI="
},
"deps": {
"depot_tools": {
@@ -21,8 +21,8 @@
"DEPS": {
"src": {
"url": "https://chromium.googlesource.com/chromium/src.git",
"rev": "73c14f6228d7cd537c855007e8f88678969cc0eb",
"hash": "sha256-LqS0Up2B1g7YWGx9N85hwMDQ2SktPjvxlJDfo8gxFOg=",
"rev": "334b65d254ccc35df4fca82706d1753227b01039",
"hash": "sha256-UtjuCxGPAHukLFqtwvyW7QRlOah4N1xJ5bHAT1hYUVA=",
"recompress": true
},
"src/third_party/clang-format/script": {
@@ -92,8 +92,8 @@
},
"src/third_party/angle": {
"url": "https://chromium.googlesource.com/angle/angle.git",
"rev": "1ff8799c596d4fc9acea28343610b1f33650a6fa",
"hash": "sha256-aNsNXGV9V3tE9Xj0eb80EdPGi4gYJzmgQk3BIo/wxmY="
"rev": "802a8704ca940b633b731493ee192e0661eb8cdd",
"hash": "sha256-HqMu7GkWXTyIj/a4SY6f8x1wS/ficMQYyI/g0zuTlvM="
},
"src/third_party/angle/third_party/glmark2/src": {
"url": "https://chromium.googlesource.com/external/github.com/glmark2/glmark2",
@@ -132,8 +132,8 @@
},
"src/third_party/dawn": {
"url": "https://dawn.googlesource.com/dawn.git",
"rev": "8597a1aaec546a7f19e8e662a49ebf03b2e91308",
"hash": "sha256-zCY7dE1C2PGb2pQ/H6oNGjpSHUhhRTfTFkAgdJm3efE="
"rev": "38bc7fb0b3a024d05212958ae843e4ddf8c44ff1",
"hash": "sha256-l1naz112kynSTtFsE0LrpLSzvdGLxJJ19UMNfHvUkmw="
},
"src/third_party/dawn/third_party/glfw3/src": {
"url": "https://chromium.googlesource.com/external/github.com/glfw/glfw",
@@ -847,8 +847,8 @@
},
"src/v8": {
"url": "https://chromium.googlesource.com/v8/v8.git",
"rev": "671f7c27ac0403ceb8074a8dfbcc02cdd7369c3f",
"hash": "sha256-0eEMZgbwW5edL4as79OibOVQidQL5rWYcGSdpq7ZPQo="
"rev": "31fac3bef58c3def36b0760e4ddc54ec77099596",
"hash": "sha256-hJfc8TsOIGi9pBXwDcxLoaO6RxczIn9mwYJAQoGBnI0="
},
"src/agents/shared": {
"url": "https://chromium.googlesource.com/chromium/agents.git",

View File

@@ -14,7 +14,7 @@
lzo,
lzop,
lz4,
openssl_3,
openssl_3_5,
pkg-config,
python3,
rustPlatform,
@@ -61,7 +61,7 @@ rustPlatform.buildRustPackage (finalAttrs: {
dtc
fontconfig
lzo
openssl_3
openssl_3_5
python3.pkgs.python-lzo
ucl
unzip

View File

@@ -37,6 +37,7 @@ let
libxcursor
libxdmcp
libxext
libxfixes
libxi
libxinerama
libxmu

View File

@@ -51,17 +51,18 @@
# passthru
testers,
nix-update-script,
xvfb-run,
}:
stdenv.mkDerivation (finalAttrs: {
pname = "dolphin-emu";
version = "2606a";
version = "2609"; # Please backport to stable for netplay compat
src = fetchFromGitHub {
owner = "dolphin-emu";
repo = "dolphin";
tag = finalAttrs.version;
hash = "sha256-TAIxBEGbbYvoOi+dukr2Hij0J/NL9Iy6pcgf2bhEgI8=";
hash = "sha256-mylUTwDBIOIdGKCdA64RSqioTVc9f6oTP5WHAVtkH9w=";
fetchSubmodules = true;
leaveDotGit = true;
postFetch = ''
@@ -184,7 +185,7 @@ stdenv.mkDerivation (finalAttrs: {
tests = {
version = testers.testVersion {
package = finalAttrs.finalPackage;
command = "dolphin-emu-nogui --version";
command = "${lib.getExe xvfb-run} dolphin-emu --version";
inherit (finalAttrs) version;
};
};

View File

@@ -95,6 +95,17 @@ rustPlatform.buildRustPackage rec {
binaryName = "firefoxpwa";
applicationName = "firefoxpwa";
inherit (firefoxRuntime) gtk3;
# Inherit all variables that related for wrapping, since this derivation is
# wrapped similarly to `firefoxRuntime`, and these passthru variables are
# read when `wrapFirefox` wraps this derivation too.
inherit (firefoxRuntime)
ffmpegSupport
gssSupport
alsaSupport
pipewireSupport
sndioSupport
jackSupport
;
};
meta = {

View File

@@ -31,13 +31,13 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "flaresolverr";
version = "3.5.0";
version = "3.5.2";
src = fetchFromGitHub {
owner = "FlareSolverr";
repo = "FlareSolverr";
rev = "v${finalAttrs.version}";
hash = "sha256-gOrfxFGNlxZWScfYEw7zfy7oVWhYEygYgP7mkO4cs/w=";
hash = "sha256-iTFoixNcEjhTCWpfDAJoLclspiyozZnQrRfkevLzd2o=";
};
nativeBuildInputs = [ makeWrapper ];

View File

@@ -12,12 +12,12 @@
}:
let
pname = "fleet";
version = "4.90.1";
version = "4.92.1";
src = fetchFromGitHub {
owner = "fleetdm";
repo = "fleet";
tag = "fleet-v${version}";
hash = "sha256-yD1snjDI5AAnHmnbpAUhtRx7ayPyqn9Tqv84p5W3SV4=";
hash = "sha256-O6BXxILefLY8zAUGsiAGixcD35+mpm/631s6711A5RE=";
};
frontend = stdenvNoCC.mkDerivation {
@@ -32,7 +32,7 @@ let
yarnOfflineCache = fetchYarnDeps {
yarnLock = src + "/yarn.lock";
hash = "sha256-OVXnPUQOr8KQYNthE8RzPV9IoQH8pxXHqjgTy7ymW/k=";
hash = "sha256-ZhkCkaX6mzavOAfSyK81s6wVN59VvBkRVBfgIfw17vE=";
};
NODE_ENV = "production";
@@ -54,7 +54,7 @@ in
buildGoModule (finalAttrs: {
inherit pname version src;
vendorHash = "sha256-1IGhOxzrQAyZu9a4HUvdN0MV5x8WnWMcFQejwy5WF1c=";
vendorHash = "sha256-PdJ6oCLC5CNLAXCS5KSrCTxUNcSxYLrx4myZ1e1TR58=";
subPackages = [
"cmd/fleet"

View File

@@ -3,7 +3,7 @@
fetchCrate,
rustPlatform,
pkg-config,
openssl_3,
openssl_3_5,
protobuf,
}:
rustPlatform.buildRustPackage (finalAttrs: {
@@ -13,7 +13,7 @@ rustPlatform.buildRustPackage (finalAttrs: {
pkg-config
protobuf
];
buildInputs = [ openssl_3 ];
buildInputs = [ openssl_3_5 ];
src = fetchCrate {
inherit (finalAttrs) pname version;
hash = "sha256-IVkmZs3imzj8uN8kqEzN/Oio3H+Nqzu8ORjARNx1TpQ=";

View File

@@ -10,7 +10,7 @@
buildGo127Module (finalAttrs: {
pname = "gh";
version = "2.101.0";
version = "2.102.0";
__structuredAttrs = true;
@@ -18,10 +18,10 @@ buildGo127Module (finalAttrs: {
owner = "cli";
repo = "cli";
tag = "v${finalAttrs.version}";
hash = "sha256-EoKF2m5sZP+uQ5AVOKkFqSCACfkeUc7vnH8PHWCO6FE=";
hash = "sha256-txjOmo46nwRxIutYR/lnFgYEWZpkbWC/ilrMAfTaFZc=";
};
vendorHash = "sha256-4KYQBgMNc/sI0mbcXSfJ7A/77VAS6NM8TOzQ3w7AlK8=";
vendorHash = "sha256-hsG6wc7AfgPZhkWwO8Xzu4yR54Rp5+Z6yeTjwnI9S+o=";
nativeBuildInputs = [
installShellFiles

View File

@@ -6,7 +6,7 @@
libuuid,
libx11,
curlMinimal,
openssl_3,
openssl_3_5,
libsecret,
webkitgtk_4_1,
libsoup_3,
@@ -22,18 +22,13 @@
dbus,
nixosTests,
}:
let
curlMinimal_openssl_3 = curlMinimal.override {
openssl = openssl_3;
};
in
stdenv.mkDerivation rec {
pname = "intune-portal";
version = "1.2603.31-noble";
version = "1.2607.4-resolute";
src = fetchurl {
url = "https://packages.microsoft.com/ubuntu/24.04/prod/pool/main/i/intune-portal/intune-portal_${version}_amd64.deb";
hash = "sha256-0braaXnRa04CUQdJx0ZFwe5qfjsJNzTtGqaKQV5Z6Yw=";
url = "https://packages.microsoft.com/ubuntu/26.04/prod/pool/main/i/intune-portal/intune-portal_${version}_amd64.deb";
hash = "sha256-WXgzLH7umvB75obzTGYW+EZ3eE1zxdIJNFNKcaNY04s=";
};
nativeBuildInputs = [ dpkg ];
@@ -45,8 +40,8 @@ stdenv.mkDerivation rec {
stdenv.cc.cc
libuuid
libx11
curlMinimal_openssl_3
openssl_3
curlMinimal
openssl_3_5
libsecret
webkitgtk_4_1
libsoup_3

View File

@@ -1,7 +1,7 @@
#! /usr/bin/env nix-shell
#! nix-shell -i bash -p curl gzip dpkg common-updater-scripts
index_file=$(curl -sL https://packages.microsoft.com/ubuntu/24.04/prod/dists/noble/main/binary-amd64/Packages.gz | gzip -dc)
index_file=$(curl -sL https://packages.microsoft.com/ubuntu/26.04/prod/dists/resolute/main/binary-amd64/Packages.gz | gzip -dc)
latest_version="0"

View File

@@ -20,16 +20,16 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "jay";
version = "1.14.0";
version = "1.15.0";
src = fetchFromGitHub {
owner = "mahkoh";
repo = "jay";
rev = "v${finalAttrs.version}";
sha256 = "sha256-bdvcGO1E9fkmKiXQxc3nvISwjIAegY8g37HmxXolsmU=";
sha256 = "sha256-QLwpRbedt5a0gq9Q0Dr3LBq2dxeJivNQQQaVJP5CEhw=";
};
cargoHash = "sha256-5yjMPDh7liaa9+KntfdCzUXz4vWzTcAhFmXrnVZ+pjM=";
cargoHash = "sha256-U4lK/J6WrGHzvGVdr/ZYEr0NOzVsZzS8e4ioLqLDdM4=";
nativeBuildInputs = [
autoPatchelfHook
@@ -53,12 +53,13 @@ rustPlatform.buildRustPackage (finalAttrs: {
];
checkFlags = [
# these 5 tests fail in the lix sandbox because they rely on io_uring
# these tests fail in the lix sandbox because they rely on io_uring
"--skip=cpu_worker::tests::cancel"
"--skip=cpu_worker::tests::complete"
"--skip=eventfd_cache::tests::test"
"--skip=io_uring::ops::read_write_no_cancel::tests::cancel_in_kernel"
"--skip=io_uring::ops::read_write_no_cancel::tests::cancel_in_userspace"
"--skip=io_uring::"
"--skip=utils::client_trace::"
"--skip=utils::cross_process_ring_buffer::"
];
postInstall = ''

View File

@@ -1,23 +1,23 @@
diff --git a/kitty/key_names.py b/kitty/key_names.py
index 1c4ce3487..00d767d45 100644
--- a/kitty/key_names.py
+++ b/kitty/key_names.py
@@ -59,17 +59,7 @@ if is_macos:
else:
diff --git i/kitty/key_names.py w/kitty/key_names.py
index d496339..2a1d9bc 100644
--- i/kitty/key_names.py
+++ w/kitty/key_names.py
@@ -67,17 +67,7 @@ def get_key_name_lookup() -> LookupFunc:
def load_libxkb_lookup() -> LookupFunc:
import ctypes
- for suffix in ('.0', ''):
- with suppress(Exception):
- lib = ctypes.CDLL(f'libxkbcommon.so{suffix}')
- break
- else:
- from ctypes.util import find_library
-
- lname = find_library('xkbcommon')
- if lname is None:
- raise RuntimeError('Failed to find libxkbcommon')
- lib = ctypes.CDLL(lname)
-
+ lib = ctypes.CDLL('@libxkbcommon@')
f = lib.xkb_keysym_from_name
f.argtypes = [ctypes.c_char_p, ctypes.c_int]
f.restype = ctypes.c_int

View File

@@ -46,26 +46,42 @@
makeBinaryWrapper,
darwin,
cairo,
shader-slang,
}:
let
shader-slang' = shader-slang.overrideAttrs (
finalAttrs: previousAttrs: {
version = "2026.18";
src = fetchFromGitHub {
owner = "shader-slang";
repo = "slang";
tag = "v${finalAttrs.version}";
hash = "sha256-GlXTDfC6BLENmrzBceJGZIP4FU5ItqtyoxmbnFZ5fdQ=";
fetchSubmodules = true;
};
cmakeFlags = previousAttrs.cmakeFlags ++ [ (lib.cmakeBool "SLANG_ENABLE_DXIL" false) ];
}
);
in
with python3Packages;
buildPythonApplication rec {
pname = "kitty";
version = "0.48.2";
version = "0.49.1";
pyproject = false;
src = fetchFromGitHub {
owner = "kovidgoyal";
repo = "kitty";
tag = "v${version}";
hash = "sha256-qNgVPpvMm8Y/nbBjVvWVuZ954ZXIuWmXhldP3w8MBhU=";
hash = "sha256-YVjTfJnsNEBjcHWQCq2nJBFPvLg7RqQcyWjgR4ijUqc=";
};
goModules =
(buildGo126Module {
pname = "kitty-go-modules";
inherit src version;
vendorHash = "sha256-BZudfNfREwNrgalaimC5Lp+UIdFS+jHFLl9mEXcHYMI=";
vendorHash = "sha256-urQMf5lGYPgS65VjGw0pi/ZM6CETtGWfi/kvVDAkIoc=";
}).goModules;
buildInputs = [
@@ -108,11 +124,13 @@ buildPythonApplication rec {
sphinx
furo
sphinx-copybutton
sphinx-design
sphinxext-opengraph
sphinx-inline-tabs
go_1_26
fontconfig
makeBinaryWrapper
shader-slang'
]
++ lib.optionals stdenv.hostPlatform.isDarwin [
imagemagick
@@ -294,6 +312,7 @@ buildPythonApplication rec {
lib.makeBinPath [
imagemagick
ncurses.dev
shader-slang'
]
}"

View File

@@ -186,11 +186,11 @@ let
linux = stdenvNoCC.mkDerivation (finalAttrs: {
inherit pname meta;
version = "154.0.4258.37";
version = "154.0.4258.48";
src = fetchurl {
url = "https://packages.microsoft.com/repos/edge/pool/main/m/microsoft-edge-stable/microsoft-edge-stable_${finalAttrs.version}-1_amd64.deb";
hash = "sha256-xvopdHM5kTIbRsQGS3hc3sWhTYzd0YK8X9oFfjfnYD0=";
hash = "sha256-uaC6R/AjO04yZuYWMLJRFAZ/olNh32MYLIiqqKQiuY4=";
};
# With strictDeps on, some shebangs were not being patched correctly
@@ -296,12 +296,12 @@ let
darwin = stdenvNoCC.mkDerivation (finalAttrs: {
inherit pname meta;
version = "154.0.4258.37";
uuid = "f7dec597-801d-4c4b-ae51-c8a53c78925c";
version = "154.0.4258.48";
uuid = "1522ce6b-7a1f-4297-b0c5-b4b4da1e237e";
src = fetchurl {
url = "https://msedge.sf.dl.delivery.mp.microsoft.com/filestreamingservice/files/${finalAttrs.uuid}/MicrosoftEdge-${finalAttrs.version}.dmg";
hash = "sha256-R385aGFby0WK64wxHGCbKnDymsUIG+lzTpQfVO2NBgA=";
hash = "sha256-ByDzUQVSqmPp+Nc3bp1KV+P0IUOESs+Be/fymxR1o4E=";
};
dontPatch = true;

View File

@@ -12,7 +12,7 @@
stdenvNoCC.mkDerivation (finalAttrs: {
pname = "msedgedriver";
version = "154.0.4258.37";
version = "154.0.4258.48";
src =
let
@@ -28,9 +28,9 @@ stdenvNoCC.mkDerivation (finalAttrs: {
url = "https://msedgedriver.microsoft.com/${finalAttrs.version}/edgedriver_${driverArch}.zip";
hash =
{
mac64_m1 = "sha256-6nwe/vRPh5MkQLTiZNXepfFsLtILwoK925mgLCUUVNg=";
mac64 = "sha256-p/cnNKQub6sSEWPz2fJ+FoU7rgzeoZQMkv3PphvvHLw=";
linux64 = "sha256-XbOQl9FyckF3Qybb+40474ImJDKahBkekPoydf/TxV0=";
mac64_m1 = "sha256-qY3DxrmrM1QlOJC+PLX8jDO6Y2OOGoKxtKHOFygQop0=";
mac64 = "sha256-Gwj0C+SLXnHFamG9iKYmBFgUtxzUmomcxuAW5G+O92Y=";
linux64 = "sha256-anRg15o6RDWikhxIZtHGP08qyqsXeBln9SHkdj10ARg=";
}
.${driverArch};
stripRoot = false;

View File

@@ -29,7 +29,7 @@ buildFHSEnv {
libz
krb5.lib
lttng-ust.out
openssl_3.out
openssl_3_5.out
icu76
# Transitive dependencies from the Debian package

View File

@@ -36,7 +36,7 @@ buildFHSEnv {
libgcc.lib
krb5.lib
lttng-ust.out
openssl_3.out
openssl_3_5.out
icu76
plasticscm-theme

View File

@@ -69,13 +69,13 @@ in
rustPlatform.buildRustPackage (finalAttrs: {
pname = "servo";
version = "0.5.0";
version = "0.6.0";
src = fetchFromGitHub {
owner = "servo";
repo = "servo";
tag = "v${finalAttrs.version}";
hash = "sha256-cJtmh/gzwno1gIqHPFgDsynGi//BvV9UyevuAbllRtg=";
hash = "sha256-inhpSzLQExTD5VT7hCzoycYMa2U4oZv8fz7NhZAlP2I=";
# Breaks reproducibility depending on whether the picked commit
# has other ref-names or not, which may change over time, i.e. with
# "ref-names: HEAD -> main" as long this commit is the branch HEAD
@@ -85,7 +85,23 @@ rustPlatform.buildRustPackage (finalAttrs: {
'';
};
cargoHash = "sha256-zZeHqxBvs5M0/TO/ifM1m5F0mSdT4cTJzoW2ja1+s28=";
cargoHash = "sha256-hjea0ze+GO3i+x1HZxSpWfXc57kvVVjmTWl2ytQYxco=";
postPatch = ''
# The mozjs crates all use cbindgen with `cargo metadata` invocations,
# which looks up the nearest cargo config.
# In our case, that's $cargoDepsCopy/.cargo/config.toml, which is the
# template of the config cargo-setup-hook creates in the build directory.
# The easiest workaround is to copy the final config back into $cargoDepsCopy,
# so `cargo metadata` invoked inside the mozjs crates finds the correct vendor path.
cp .cargo/config.toml $cargoDepsCopy/.cargo/config.toml
# We also need to make sure that `cargo metadata` knows what versions each of the
# mozjs crates' dependencies resolve to in our dependency cache, which can be achieved
# by copying our lockfile into the mozjs crate directories.
for mozjs_dir in $cargoDepsCopy/*/mozjs_*/; do
cp Cargo.lock $mozjs_dir
done
'';
# set `HOME` to a temp dir for write access
# Fix invalid option errors during linking (https://github.com/mozilla/nixpkgs-mozilla/commit/c72ff151a3e25f14182569679ed4cd22ef352328)
@@ -137,11 +153,6 @@ rustPlatform.buildRustPackage (finalAttrs: {
vulkan-loader
];
# Builds with additional features for aarch64, see https://github.com/servo/servo/issues/36819
buildFeatures = lib.optionals stdenv.hostPlatform.isAarch64 [
"servo-allocator/use-system-allocator"
];
env.NIX_CFLAGS_COMPILE = toString (
[
# mozjs-sys fails with:
@@ -176,7 +187,7 @@ rustPlatform.buildRustPackage (finalAttrs: {
homepage = "https://servo.org";
license = lib.licenses.mpl20;
maintainers = with lib.maintainers; [
hexa
niklaskorz
];
teams = with lib.teams; [ ngi ];
mainProgram = "servoshell";

View File

@@ -3,7 +3,7 @@
fetchCrate,
rustPlatform,
pkg-config,
openssl_3,
openssl_3_5,
protobuf,
}:
rustPlatform.buildRustPackage (finalAttrs: {
@@ -13,7 +13,7 @@ rustPlatform.buildRustPackage (finalAttrs: {
pkg-config
protobuf
];
buildInputs = [ openssl_3 ];
buildInputs = [ openssl_3_5 ];
src = fetchCrate {
inherit (finalAttrs) pname version;
hash = "sha256-vLbSjDULrYL8emQTha4fhEbr00OlhXNa00QhCKCnWDc=";

View File

@@ -1,20 +1,12 @@
diff --git a/warpgate-common/src/version.rs b/warpgate-common/src/version.rs
index 0e7985a..62c2b67 100644
index 31104706..ec201419 100644
--- a/warpgate-common/src/version.rs
+++ b/warpgate-common/src/version.rs
@@ -1,14 +1,3 @@
-use git_version::git_version;
-
pub const fn warpgate_version() -> &'static str {
- git_version!(
- args = [
- "--tags",
- "--always",
- "--dirty=-modified",
- "--match",
- "v[0-9]*"
- ],
@@ -9,6 +9,6 @@ pub const fn warpgate_version() -> &'static str {
"--match",
"v[0-9]*"
],
- fallback = "unknown"
- )
+ "v@version@"
+ fallback = "v@version@"
)
}

View File

@@ -7,20 +7,24 @@
openapi-generator-cli,
nixosTests,
nix-update-script,
perl,
withRDPLegacyTLSBackend ? false,
}:
rustPlatform.buildRustPackage (
finalAttrs:
let
warpgate-web = buildNpmPackage {
pname = "${finalAttrs.pname}-web";
webUi = buildNpmPackage {
pname = "warpgate-web";
version = finalAttrs.version;
src = finalAttrs.src;
sourceRoot = "${finalAttrs.src.name}/warpgate-web";
patches = [ ./web-ui-package-json.patch ];
patches = [
./web-ui-package-json.patch
];
npmDepsHash = "sha256-McQI5EmTfrbdcWnYRsoRHjhZphrZVaV/fN9i9MX8XF0=";
npmDepsHash = "sha256-BfmYRfsxdJZuS/c7bGccXXYktsjQ76mjwTFKLvNsGAg=";
nativeBuildInputs = [ openapi-generator-cli ];
@@ -35,45 +39,51 @@ rustPlatform.buildRustPackage (
in
{
pname = "warpgate";
version = "0.26.1";
version = "0.29.0";
src = fetchFromGitHub {
owner = "warp-tech";
repo = "warpgate";
tag = "v${finalAttrs.version}";
hash = "sha256-1Dg7bzhBQNe+u90Tw+kcmVaxV5IK0/t505HZr18qP5I=";
hash = "sha256-OXVFsscGU+euamUvgyisN2I3kH/SwSo+eag+S+3YW/w=";
};
cargoHash = "sha256-A5rRLrqlAZV/3ID8F+wUO8OP3Ocivg7vYrNDiMqRKik=";
cargoHash = "sha256-zlECC2p2hs5w1zkKc8ikoMyVFp/jie2HsqXGDLAEW7E=";
patches = [
(replaceVars ./hardcode-version.patch { inherit (finalAttrs) version; })
./remove-nightly-rustflags.patch
];
env.RUSTFLAGS = "--cfg tokio_unstable";
env = {
# uses nightly feature: gethostname, once_cell_try
RUSTC_BOOTSTRAP = true;
RUSTFLAGS = "--cfg tokio_unstable";
};
nativeBuildInputs = lib.optional withRDPLegacyTLSBackend perl;
buildFeatures = [
"postgres"
"mysql"
"sqlite"
];
]
++ lib.optional withRDPLegacyTLSBackend "rdp-openssl-tls";
preBuild = ''
rm -r .cargo/
ln -rs "${warpgate-web}" warpgate-web/dist
rm -rf .cargo/
ln -rs "${webUi}" warpgate-web/dist
'';
# skip check, project included tests require python stuff and docker
doCheck = false;
passthru = {
inherit warpgate-web;
inherit webUi;
tests = {
inherit (nixosTests) warpgate;
};
updateScript = nix-update-script {
extraArgs = [ "--subpackage=warpgate-web" ];
extraArgs = [ "--subpackage=webUi" ];
};
};

View File

@@ -1,31 +0,0 @@
diff --git a/Cargo.toml b/Cargo.toml
index 0e92acb..d187ebc 100644
--- a/Cargo.toml
+++ b/Cargo.toml
@@ -1,5 +1,3 @@
-cargo-features = ["profile-rustflags"]
-
[workspace]
members = [
"warpgate",
@@ -160,20 +158,2 @@
[profile.coverage]
inherits = "dev"
-
-[profile.dev.package.aws-sdk-ec2]
-hint-mostly-unused = true
-
-[profile.release.package.aws-sdk-ec2]
-hint-mostly-unused = true
-
-[profile.dev.package.aws-sdk-rds]
-hint-mostly-unused = true
-
-[profile.release.package.aws-sdk-rds]
-hint-mostly-unused = true
-
-[profile.dev.package.aws-sdk-eks]
-hint-mostly-unused = true
-
-[profile.release.package.aws-sdk-eks]
-hint-mostly-unused = true

View File

@@ -1,15 +1,15 @@
diff --git a/package.json b/package.json
index 54125c3..6942dfb 100644
index f3348729..b236aafd 100644
--- a/package.json
+++ b/package.json
@@ -12,8 +12,8 @@
"postinstall": "npm run openapi:client:gateway && npm run openapi:client:admin",
"openapi:schema:gateway": "cargo run -p warpgate-protocol-http > src/gateway/lib/openapi-schema.json",
"openapi:schema:admin": "cargo run -p warpgate-admin > src/admin/lib/openapi-schema.json",
- "openapi:client:gateway": "openapi-generator-cli generate -g typescript-fetch -i src/gateway/lib/openapi-schema.json -o src/gateway/lib/api-client -p npmName=warpgate-gateway-api-client -p useSingleRequestParameter=true && cd src/gateway/lib/api-client && npm i typescript@5 && npm i && npx tsc --target esnext --module esnext && rm -rf src tsconfig.json",
- "openapi:client:admin": "openapi-generator-cli generate -g typescript-fetch -i src/admin/lib/openapi-schema.json -o src/admin/lib/api-client -p npmName=warpgate-admin-api-client -p useSingleRequestParameter=true && cd src/admin/lib/api-client && npm i typescript@5 && npm i && npx tsc --target esnext --module esnext && rm -rf src tsconfig.json",
+ "openapi:client:gateway": "openapi-generator-cli generate -g typescript-fetch -i src/gateway/lib/openapi-schema.json -o src/gateway/lib/api-client -p npmName=warpgate-gateway-api-client -p useSingleRequestParameter=true && ln -sr node_modules src/gateway/lib/api-client/node_modules && cd src/gateway/lib/api-client && npx tsc --target esnext --module esnext && rm -rf src tsconfig.json",
+ "openapi:client:admin": "openapi-generator-cli generate -g typescript-fetch -i src/admin/lib/openapi-schema.json -o src/admin/lib/api-client -p npmName=warpgate-admin-api-client -p useSingleRequestParameter=true && ln -sr node_modules src/admin/lib/api-client/node_modules && cd src/admin/lib/api-client && npx tsc --target esnext --module esnext && rm -rf src tsconfig.json",
"openapi:tests-sdk": "openapi-generator-cli generate -g python -i src/admin/lib/openapi-schema.json -o ../tests/api_sdk",
"openapi": "npm run openapi:schema:admin && npm run openapi:schema:gateway && npm run openapi:client:admin && npm run openapi:client:gateway"
},
@@ -16,8 +16,8 @@
"postinstall": "npm run openapi:client:gateway && npm run openapi:client:admin",
"openapi:schema:gateway": "cargo run -p warpgate-protocol-http > src/gateway/lib/openapi-schema.json",
"openapi:schema:admin": "cargo run -p warpgate-admin > src/admin/lib/openapi-schema.json",
- "openapi:client:gateway": "openapi-generator-cli generate -g typescript-fetch -i src/gateway/lib/openapi-schema.json -o src/gateway/lib/api-client -p npmName=warpgate-gateway-api-client -p useSingleRequestParameter=true && cd src/gateway/lib/api-client && npm i typescript@5 && npm i && npx tsc --target esnext --module esnext && rm -rf src tsconfig.json",
- "openapi:client:admin": "openapi-generator-cli generate -g typescript-fetch -i src/admin/lib/openapi-schema.json -o src/admin/lib/api-client -p npmName=warpgate-admin-api-client -p useSingleRequestParameter=true && cd src/admin/lib/api-client && npm i typescript@5 && npm i && npx tsc --target esnext --module esnext && rm -rf src tsconfig.json",
+ "openapi:client:gateway": "openapi-generator-cli generate -g typescript-fetch -i src/gateway/lib/openapi-schema.json -o src/gateway/lib/api-client -p npmName=warpgate-gateway-api-client -p useSingleRequestParameter=true && ln -sr node_modules src/gateway/lib/api-client/node_modules && cd src/gateway/lib/api-client && npx tsc --target esnext --module esnext && rm -rf src tsconfig.json",
+ "openapi:client:admin": "openapi-generator-cli generate -g typescript-fetch -i src/admin/lib/openapi-schema.json -o src/admin/lib/api-client -p npmName=warpgate-admin-api-client -p useSingleRequestParameter=true && ln -sr node_modules src/admin/lib/api-client/node_modules && cd src/admin/lib/api-client && npx tsc --target esnext --module esnext && rm -rf src tsconfig.json",
"openapi:tests-sdk": "openapi-generator-cli generate -g python -i src/admin/lib/openapi-schema.json -o ../tests/api_sdk",
"openapi": "npm run openapi:schema:admin && npm run openapi:schema:gateway && npm run openapi:client:admin && npm run openapi:client:gateway"
},

View File

@@ -2,6 +2,7 @@
lib,
python3,
fetchFromGitHub,
fetchpatch2,
gettext,
pango,
harfbuzz,
@@ -65,6 +66,15 @@ python3Packages.buildPythonApplication (finalAttrs: {
hash = "sha256-7dhEkU2sVIjMPPR/0U2sMFXG6bl8s5WDvw8MyZZhqNE=";
};
patches = [
(fetchpatch2 {
name = "CVE-2026-86035.patch";
url = "https://github.com/WeblateOrg/weblate/commit/f60a9759a6d851bd10ccdefe9b1b7f0cdb9e9bbd.patch";
hash = "sha256-MDzU6cp2SXQU+iS3/wxaPH01fbgRy1DXMMuLfpJn4y0=";
excludes = [ "docs/changes.rst" ];
})
];
postPatch = ''
sed -i 's|/bin/true|true|g' weblate/addons/example_pre.py

View File

@@ -60,7 +60,7 @@ in
stdenv.mkDerivation (finalAttrs: {
pname = "wireshark-${if withQt then "qt" else "cli"}";
version = "4.6.8";
version = "4.6.9";
outputs = [
"out"
@@ -71,7 +71,7 @@ stdenv.mkDerivation (finalAttrs: {
repo = "wireshark";
owner = "wireshark";
tag = "v${finalAttrs.version}";
hash = "sha256-qUC2k8LZQxmSu19jj1LHM+oQiF/ao+rV6wwRQhISuzk=";
hash = "sha256-AMI36rWrGCg7dnC+Qi1YQoMqW/uprFBAGX5krG56HNw=";
};
patches = [

View File

@@ -107,6 +107,17 @@ optionals noSysDirs (
## 2. Patches relevant on specific platforms ####################################
## AArch64
# Fix an ICE when a function type carries a C++11 attribute without a namespace.
# Fixed in GCC 15, never backported to the GCC 14 branch:
# https://gcc.gnu.org/bugzilla/show_bug.cgi?id=116598
++ optional (is14 && targetPlatform.isAarch64) (fetchpatch {
name = "aarch64-fix-ice-in-lookup-shared-state-flags.patch";
url = "https://github.com/gcc-mirror/gcc/commit/1247fa6e95cdf4a6422ec802f733f1f7ecaa3557.patch";
hash = "sha256-p8fyIcAx8CvLtQboXPevw/J3LsvkSZp36bHtGHjxsiQ=";
})
## Darwin
# Fix detection of bootstrap compiler Ada support (cctools as) on Nix Darwin

View File

@@ -470,12 +470,15 @@ in
extraMeta = {
license = lib.licenses.asl20;
knownVulnerabilities = [
"OpenSSL 3.0 reached its end of life on 2026/09/07"
];
};
};
openssl_3_5 = common {
version = "3.5.8";
hash = "sha256-qPhKOZGOxkFc52XZtCnTE7qXuBQxacFy5zS5UURk9bI=";
version = "3.5.9";
hash = "sha256-YD9WAuLu8A13+9Qp003NWCK7MBdXobyc2yTGcPHrhZo=";
patches = [
# Support for NIX_SSL_CERT_FILE, motivation:
@@ -535,8 +538,8 @@ in
};
openssl_4_0 = common {
version = "4.0.2";
hash = "sha256-c2tGdTD5FnN7cDExDMsh2CGMYinmHo4WDNHTRYzVQ6g=";
version = "4.0.3";
hash = "sha256-MltcgGFnwTtAsf/q3+AkgZfADszEzxI+weKNLS/SFtk=";
patches = [
# Support for NIX_SSL_CERT_FILE, motivation:

View File

@@ -28,7 +28,6 @@
libepoxy,
libjxl,
at-spi2-core,
cairo,
expat,
libxml2,
libsoup_3,
@@ -85,7 +84,7 @@ in
# https://webkitgtk.org/2024/10/04/webkitgtk-2.46.html recommends building with clang.
clangStdenv.mkDerivation (finalAttrs: {
pname = "webkitgtk";
version = "2.52.6";
version = "2.54.0";
name = "webkitgtk-${finalAttrs.version}+abi=${abiVersion}";
outputs = [
@@ -100,7 +99,7 @@ clangStdenv.mkDerivation (finalAttrs: {
src = fetchurl {
url = "https://webkitgtk.org/releases/webkitgtk-${finalAttrs.version}.tar.xz";
hash = "sha256-F5ouo/j27dS+fzH9xVr8V70HKfH7pkjGHUGBU5rBFvw=";
hash = "sha256-hG/RnM7brh2/6QTybb8taKgAozpQyvKtUiLI3LPyVoI=";
};
patches = lib.optionals clangStdenv.hostPlatform.isLinux [
@@ -117,6 +116,15 @@ clangStdenv.mkDerivation (finalAttrs: {
hash = "sha256-MgaSpXq9l6KCLQdQyel6bQFHG53l3GY277WePpYXdjA=";
name = "fix_ftbfs_riscv64.patch";
})
# Fix https://bugs.webkit.org/show_bug.cgi?id=322394
# Upstream PR: https://github.com/WebKit/WebKit/pull/74512
# Fetching the patch vendored by gnome-build-meta because the upstream
# patch doesn't apply.
(fetchpatch {
url = "https://gitlab.gnome.org/GNOME/gnome-build-meta/-/raw/7e4afe649fa1acbe9203004ad8fe1749c26e619d/patches/webkitgtk/main-thread.patch";
hash = "sha256-Dm6Yytt4mQy7qxSWiudGBqfQUVJRhNAc1n+o/NMR1cg=";
})
];
nativeBuildInputs = [
@@ -141,7 +149,6 @@ clangStdenv.mkDerivation (finalAttrs: {
buildInputs = [
at-spi2-core
cairo # required even when using skia
enchant
expat
flite