Merge staging-next into staging

This commit is contained in:
nixpkgs-ci[bot]
2026-09-08 00:25:33 +00:00
committed by GitHub
208 changed files with 4327 additions and 1046 deletions

View File

@@ -73,7 +73,7 @@ Controls the flags passed to `cargo tauri build`.
#### `tauriBundleType` {#tauri-bundle-type}
The [bundle type](https://tauri.app/v1/guides/building/) to build.
The [bundle type](https://tauri.app/reference/javascript/api/namespaceapp/#bundletype) to build.
#### `dontTauriBuild` {#dont-tauri-build}

View File

@@ -4474,6 +4474,14 @@
githubId = 510553;
name = "Jos van Bakel";
};
c2fc2f = {
name = "c2fc2f";
github = "c2fc2f";
githubId = 59392138;
email = "contact@c2fc2f.com";
matrix = "@c2fc2f:sagbot.com";
keys = [ { fingerprint = "6EF1 8507 76B5 ABCE 5BF0 C0F8 42E0 E1D1 0B61 1208"; } ];
};
c31io = {
email = "celiogrand@outlook.com";
github = "c31io";
@@ -19342,6 +19350,12 @@
githubId = 708570;
name = "Manuel Mendez";
};
mmulqueen = {
email = "michael@mulqueen.me.uk";
github = "mmulqueen";
githubId = 6616321;
name = "Michael Mulqueen";
};
mmusnjak = {
email = "marko.musnjak@gmail.com";
github = "mmusnjak";

View File

@@ -92,6 +92,10 @@ cd /my/git/clone/of/nixpkgs
nix-build -A nixosTests.hostname
```
In-tree tests run with a few changes to defaults, notably
- The `pkgs.*` are read only by default. You can opt out with `node.pkgsReadOnly = false;` at the test level.
- `nix.enable` defaults to `false` to reduce build closure size; in particular the reverse build closure of `nix` and its dependencies.
### Testing outside the NixOS project {#sec-call-nixos-test-outside-nixos}
Outside the `nixpkgs` repository, you can use the `runNixOSTest` function from
@@ -110,6 +114,8 @@ pkgs.testers.runNixOSTest {
`runNixOSTest` returns a derivation that runs the test.
Out-of-tree tests evaluate with a set of defaults that balances the principle of least surprise in the general case, but has a few differences from in-tree NixOS tests. See [Testing within NixOS](#sec-call-nixos-test-in-nixos).
## Test machines {#ssec-nixos-test-machines}
A NixOS test usually consists of one or more test machines. Each machine is either a

View File

@@ -207,6 +207,8 @@
- `fail2ban` has been updated to 1.1.1, which has a few breaking changes compared to 1.1.0 ([changelog](https://github.com/fail2ban/fail2ban/blob/1.1.1/ChangeLog))
- `services.neo4j.tls.<policy_name>`: This policy is no longer enabled by default. If you rely on this policy, you must now explicitly opt-in by setting `services.neo4j.tls.<policy_name>.enable = true;`.
- `systemd.user.extraConfig` has been removed in favor of the structured [](#opt-systemd.user.settings.Manager) option. Use `systemd.user.settings.Manager` to set any `systemd-user.conf(5)` option directly. For example, replace `systemd.user.extraConfig = "DefaultTimeoutStartSec=60";` with `systemd.user.settings.Manager.DefaultTimeoutStartSec = 60;`.
- `matrix-appservice-discord` was removed from nixpkgs along with its NixOS module (`services.matrix-appservice-discord`) as it is no longer actively maintained upstream. Use the actively-maintained puppeting bridge [`mautrix-discord`](#opt-services.mautrix-discord.enable) instead.

View File

@@ -80,17 +80,18 @@ class JunitXMLLogger(AbstractLogger):
self.failure = False
def __init__(self, outfile: Path) -> None:
self.tests: dict[str, JunitXMLLogger.TestCaseState] = {
"main": self.TestCaseState()
}
self.currentSubtest = "main"
self.testsuite = JunitXMLLogger.TestCaseState()
self.tests: dict[str, JunitXMLLogger.TestCaseState] = {}
self.currentSubtest = None
self.outfile: Path = outfile
self._print_serial_logs = True
self._log_level = LogLevel.INFO
atexit.register(self.close)
def log(self, message: str, attributes: dict[str, str] = {}) -> None:
self.tests[self.currentSubtest].stdout += message + os.linesep
self.testsuite.stdout += message + os.linesep
if self.currentSubtest:
self.tests[self.currentSubtest].stdout += message + os.linesep
@contextmanager
def subtest(self, name: str, attributes: dict[str, str] = {}) -> Iterator[None]:
@@ -109,19 +110,28 @@ class JunitXMLLogger(AbstractLogger):
def debug(self, *args, **kwargs) -> None:
if self._log_level <= LogLevel.DEBUG:
self.tests[self.currentSubtest].stdout += args[0] + os.linesep
self.testsuite.stdout += args[0] + os.linesep
if self.currentSubtest:
self.tests[self.currentSubtest].stdout += args[0] + os.linesep
def info(self, *args, **kwargs) -> None:
if self._log_level <= LogLevel.INFO:
self.tests[self.currentSubtest].stdout += args[0] + os.linesep
self.testsuite.stdout += args[0] + os.linesep
if self.currentSubtest:
self.tests[self.currentSubtest].stdout += args[0] + os.linesep
def warning(self, *args, **kwargs) -> None:
if self._log_level <= LogLevel.WARNING:
self.tests[self.currentSubtest].stdout += args[0] + os.linesep
self.testsuite.stdout += args[0] + os.linesep
if self.currentSubtest:
self.tests[self.currentSubtest].stdout += args[0] + os.linesep
def error(self, *args, **kwargs) -> None:
self.tests[self.currentSubtest].stderr += args[0] + os.linesep
self.tests[self.currentSubtest].failure = True
self.testsuite.stderr += args[0] + os.linesep
self.testsuite.failure = True
if self.currentSubtest:
self.tests[self.currentSubtest].stderr += args[0] + os.linesep
self.tests[self.currentSubtest].failure = True
def log_test_error(self, *args, **kwargs) -> None:
self.error(*args, **kwargs)
@@ -141,6 +151,9 @@ class JunitXMLLogger(AbstractLogger):
def close(self) -> None:
with open(self.outfile, "w") as f:
test_cases = []
if len(self.tests) == 0:
self.tests.setdefault("main", self.TestCaseState())
self.tests["main"].failure = self.testsuite.failure
for name, test_case_state in self.tests.items():
tc = TestCase(
name,
@@ -151,7 +164,12 @@ class JunitXMLLogger(AbstractLogger):
tc.add_failure_info("test case failed")
test_cases.append(tc)
ts = TestSuite("NixOS integration test", test_cases)
ts = TestSuite(
"NixOS integration test",
test_cases,
stdout=self.testsuite.stdout,
stderr=self.testsuite.stderr,
)
f.write(TestSuite.to_xml_string([ts]))

View File

@@ -1252,7 +1252,7 @@ let
name = "fscrypt";
enable = config.security.pam.enableFscrypt;
control = "optional";
modulePath = "${pkgs.fscrypt-experimental}/lib/security/pam_fscrypt.so";
modulePath = "${pkgs.fscrypt}/lib/security/pam_fscrypt.so";
}
{
name = "zfs_key";
@@ -1449,7 +1449,7 @@ let
name = "fscrypt";
enable = config.security.pam.enableFscrypt;
control = "optional";
modulePath = "${pkgs.fscrypt-experimental}/lib/security/pam_fscrypt.so";
modulePath = "${pkgs.fscrypt}/lib/security/pam_fscrypt.so";
}
{
name = "zfs_key";
@@ -1610,7 +1610,7 @@ let
name = "fscrypt";
enable = config.security.pam.enableFscrypt;
control = "optional";
modulePath = "${pkgs.fscrypt-experimental}/lib/security/pam_fscrypt.so";
modulePath = "${pkgs.fscrypt}/lib/security/pam_fscrypt.so";
}
{
name = "zfs_key-skip-systemd";
@@ -2663,7 +2663,7 @@ in
++ lib.optionals config.security.pam.enableOTPW [ pkgs.otpw ]
++ lib.optionals config.security.pam.oath.enable [ pkgs.oath-toolkit ]
++ lib.optionals config.security.pam.p11.enable [ pkgs.pam_p11 ]
++ lib.optionals config.security.pam.enableFscrypt [ pkgs.fscrypt-experimental ]
++ lib.optionals config.security.pam.enableFscrypt [ pkgs.fscrypt ]
++ lib.optionals config.security.pam.u2f.enable [ pkgs.pam_u2f ];
security.wrappers = {

View File

@@ -151,6 +151,17 @@ in
# ~/.config/Yubico/u2f_keys (the default key file location)
ProtectHome = "read-only";
})
(mkIf config.security.pam.yubico.enable {
# Override upstream PrivateDevices=yes to allow access to /dev/hidraw*
PrivateDevices = false;
DeviceAllow = [ "char-hidraw rw" ];
})
(mkIf config.services.fprintd.enable {
# Override upstream PrivateDevices=yes to allow access to /dev/bus/usb/**
PrivateDevices = false;
DeviceAllow = [ "char-usb_device rw" ];
RestrictAddressFamilies = [ "AF_NETLINK" ];
})
(mkIf config.security.pam.zfs.enable {
PrivateDevices = false;
DeviceAllow = [

View File

@@ -13,6 +13,7 @@ let
opt: lib.isOption opt && opt.type == lib.types.path && opt.highestPrio >= 1500;
sslPolicies = lib.mapAttrsToList (name: conf: ''
dbms.ssl.policy.${name}.enabled=${lib.boolToString conf.enable}
dbms.ssl.policy.${name}.allow_key_generation=${lib.boolToString conf.allowKeyGeneration}
dbms.ssl.policy.${name}.base_directory=${conf.baseDirectory}
${lib.optionalString (conf.ciphers != null) ''
@@ -35,7 +36,7 @@ let
dbms.ssl.policy.${name}.tls_versions=${lib.concatStringsSep "," conf.tlsVersions}
dbms.ssl.policy.${name}.trust_all=${lib.boolToString conf.trustAll}
dbms.ssl.policy.${name}.trusted_dir=${conf.trustedDir}
'') cfg.ssl.policies;
'') (lib.filterAttrs (_: v: v.enable) cfg.ssl.policies);
serverConfig = pkgs.writeText "neo4j.conf" ''
# General
@@ -467,6 +468,8 @@ in
}:
{
options = {
enable = lib.mkEnableOption "this policy";
allowKeyGeneration = lib.mkOption {
type = lib.types.bool;
default = false;
@@ -714,6 +717,6 @@ in
};
meta = {
maintainers = [ ];
maintainers = [ lib.maintainers.c2fc2f ];
};
}

View File

@@ -1,6 +1,7 @@
{
config,
lib,
options,
pkgs,
utils,
...
@@ -201,8 +202,12 @@ let
--notify-ready=yes \
--kill-signal=SIGRTMIN+3 \
--bind-ro=/nix/store:/nix/store$NIX_BIND_OPT \
--bind-ro=/nix/var/nix/db:/nix/var/nix/db$NIX_BIND_OPT \
--bind-ro=/nix/var/nix/daemon-socket:/nix/var/nix/daemon-socket$NIX_BIND_OPT \
${optionalString config.nix.enable "--bind-ro=/nix/var/nix/db:/nix/var/nix/db$NIX_BIND_OPT"} \
${
optionalString (
config.nix.enable && config.nix.daemon.enable
) "--bind-ro=/nix/var/nix/daemon-socket:/nix/var/nix/daemon-socket$NIX_BIND_OPT"
} \
--bind="/nix/var/nix/profiles/per-container/$INSTANCE:/nix/var/nix/profiles$NIX_BIND_OPT" \
--bind="/nix/var/nix/gcroots/per-container/$INSTANCE:/nix/var/nix/gcroots$NIX_BIND_OPT" \
${optionalString (!cfg.ephemeral) "--link-journal=try-guest"} \
@@ -994,7 +999,10 @@ in
mapper =
name: cfg:
optional (cfg.networkNamespace != null && (cfg.privateNetwork || cfg.interfaces != [ ]))
"containers.${name}.networkNamespace is mutally exclusive to containers.${name}.privateNetwork and containers.${name}.interfaces.";
"containers.${name}.networkNamespace is mutally exclusive to containers.${name}.privateNetwork and containers.${name}.interfaces."
++
optional (cfg.config.nix.enable && cfg.config.nix.daemon.enable && !config.nix.daemon.enable)
"${options.containers}.${strings.escapeNixIdentifier name} requires a Nix daemon but the host does not provided it, as option ${options.nix.daemon.enable} is disabled";
in
mkMerge (mapAttrsToList mapper config.containers);
}

View File

@@ -7,6 +7,10 @@
meta.maintainers = with lib.maintainers; [ nikstur ];
nodes.machine = {
# - nix.enable gates nix.channel.enable behaviors
# - disabled by default. See all-tests.nix / tag(no-nix-by-default)
nix.enable = true;
nix.channel.enable = true;
};

View File

@@ -109,6 +109,34 @@ let
];
};
/**
The test framework as exposed through its [other entrypoints] has defaults
that are most suitable for external usage.
This module adjusts it for the particular, important use case of
NixOS *as packaged in the nixpkgs repo*.
[other entrypoints]: https://nixos.org/manual/nixos/stable/#sec-calling-nixos-tests
*/
localTestOverrides =
{ lib, ... }:
{
_class = "nixosTest";
# for error messages, pseudo-url in no particular format
_file = "nixpkgs/nixos/tests/all-tests.nix#localTestOverrides";
imports = [
./read-only-pkgs.nix
];
extraBaseModules = {
_file = "nixpkgs/nixos/tests/all-tests.nix#localTestOverrides-extraBaseModules";
# tag(no-nix-by-default): we exclude nix from the tests *here* to keep a
# small reverse closure for nix package updates among other things.
# Out-of-tree usages get nix by default as usual.
# See https://nixos.org/manual/nixos/unstable/#sec-call-nixos-test-outside-nixos
config.nix.enable = lib.mkDefault false;
};
};
inherit
(rec {
doRunTest =
@@ -116,7 +144,7 @@ let
((import ../lib/testing-python.nix { inherit system pkgs; }).evalTest {
imports = [
arg
./read-only-pkgs.nix
localTestOverrides
];
}).config.result;
findTests =
@@ -175,6 +203,16 @@ in
touch $out
'';
efivars = runTestOn [ "x86_64-linux" ] ./nixos-test-driver/efivars.nix;
junit =
pkgs.runCommand "junit-xml-has-correct-testcases"
{
test = runTest ./nixos-test-driver/junit.nix;
nativeBuildInputs = [ pkgs.yq-go ];
}
''
[[ 2 = $(yq '.testsuites.testsuite.+@tests' $test/junit.xml) ]]
touch $out
'';
};
# NixOS vm tests and non-vm unit tests
@@ -422,6 +460,10 @@ in
containers-macvlans = runTest ./containers-macvlans.nix;
containers-names = runTest ./containers-names.nix;
containers-nested = runTest ./containers-nested.nix;
containers-nested-nix = runTest {
imports = [ ./containers-nested.nix ];
params.nix = true;
};
containers-physical_interfaces = runTest ./containers-physical_interfaces.nix;
containers-portforward = runTest ./containers-portforward.nix;
containers-reloadable = runTest ./containers-reloadable.nix;

View File

@@ -15,6 +15,8 @@ in
nodes = {
local = {
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
services.atticd = {
enable = true;
@@ -27,6 +29,8 @@ in
};
s3 = {
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
services.atticd = {
enable = true;
settings = {

View File

@@ -7,6 +7,9 @@
{ pkgs, ... }:
{
imports = [ ../modules/installer/cd-dvd/channel.nix ];
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
environment.systemPackages = with pkgs; [
openssl
python3

View File

@@ -49,6 +49,7 @@ in
localAddress = containerIp;
localAddress6 = containerIp6;
config = {
nix.enable = false; # disabled by default on the host. See all-tests.nix / tag(no-nix-by-default)
services.httpd.enable = true;
services.httpd.adminAddr = "foo@example.org";
networking.firewall.allowedTCPPorts = [ 80 ];
@@ -60,6 +61,7 @@ in
privateNetwork = true;
hostBridge = "br0";
config = {
nix.enable = false; # disabled by default on the host. See all-tests.nix / tag(no-nix-by-default)
services.httpd.enable = true;
services.httpd.adminAddr = "foo@example.org";
networking.firewall.allowedTCPPorts = [ 80 ];

View File

@@ -37,6 +37,8 @@ in
{
nixpkgs.pkgs = customPkgs;
system.extraDependencies = [ pkgs.hello ];
nix.enable = false; # disabled by default on the test's host. See all-tests.nix / tag(no-nix-by-default)
};
};
};

View File

@@ -26,6 +26,7 @@
};
};
networking.firewall.allowedTCPPorts = [ 80 ];
nix.enable = false; # disabled by default on the test's host. See all-tests.nix / tag(no-nix-by-default)
};
};
};

View File

@@ -63,6 +63,7 @@
};
config = {
networking.firewall.allowedTCPPorts = [ 80 ];
nix.enable = false; # disabled by default on the test's host. See all-tests.nix / tag(no-nix-by-default)
};
};

View File

@@ -39,9 +39,12 @@ in
hostBridge = "br0";
localAddress = containerIp4;
localAddress6 = containerIp6;
config.networking = {
defaultGateway.address = hostIp4;
defaultGateway6.address = hostIp6;
config = {
networking = {
defaultGateway.address = hostIp4;
defaultGateway6.address = hostIp6;
};
nix.enable = false; # disabled by default on the test's host. See all-tests.nix / tag(no-nix-by-default)
};
};
};

View File

@@ -29,7 +29,9 @@
localAddress = "10.10.0.1";
hostAddress = "10.10.0.254";
config = { };
config = {
nix.enable = false; # disabled by default on the test's host. See all-tests.nix / tag(no-nix-by-default)
};
};
containers.netmask = {
@@ -38,7 +40,9 @@
hostBridge = "br0";
localAddress = "10.11.0.1/24";
config = { };
config = {
nix.enable = false; # disabled by default on the test's host. See all-tests.nix / tag(no-nix-by-default)
};
};
};

View File

@@ -19,6 +19,7 @@
boot.enableContainers = true;
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
# XXX: Sandbox setup fails while trying to hardlink files from the host's
# store file system into the prepared chroot directory.
nix.settings.sandbox = false;

View File

@@ -8,6 +8,8 @@ let
adminAddr = "foo@example.org";
};
networking.firewall.allowedTCPPorts = [ 80 ];
nix.enable = false; # disabled by default on the test's host. See all-tests.nix / tag(no-nix-by-default)
};
};

View File

@@ -104,6 +104,8 @@ in
services.httpd.enable = true;
networking.firewall.allowedTCPPorts = [ 80 ];
nix.enable = false; # disabled by default on the test's host. See all-tests.nix / tag(no-nix-by-default)
};
};
};

View File

@@ -47,6 +47,7 @@ in
}
];
};
nix.enable = false; # disabled by default on the test's host. See all-tests.nix / tag(no-nix-by-default)
};
};
@@ -63,6 +64,7 @@ in
}
];
};
nix.enable = false; # disabled by default on the test's host. See all-tests.nix / tag(no-nix-by-default)
};
};
};

View File

@@ -19,7 +19,9 @@
privateNetwork = true;
hostAddress = "192.168.${subnet}.1";
localAddress = "192.168.${subnet}.2";
config = { };
config = {
nix.enable = false; # disabled by default on the test's host. See all-tests.nix / tag(no-nix-by-default)
};
};
in

View File

@@ -1,27 +1,54 @@
# Test for NixOS' container nesting.
{ pkgs, ... }:
{
name = "nested";
lib,
pkgs,
config,
...
}:
let
system = config.nodes.machine.nixpkgs.hostPlatform.system;
in
{
options = {
params.nix = lib.mkOption {
description = "Whether to enable nix on host and containers - we test both variants";
type = lib.types.bool;
default = false; # In line with all-tests.nix / tag(no-nix-by-default)
};
};
config.name = "nested";
meta = with pkgs.lib.maintainers; {
config.meta = with pkgs.lib.maintainers; {
maintainers = [ sorki ];
};
nodes.machine =
config.nodes.machine =
{ lib, ... }:
let
makeNested = subConf: {
# NOTE: outer container is also called "nested"!
containers.nested = {
autoStart = true;
privateNetwork = true;
config = subConf;
config = {
imports = [ subConf ];
nix.enable = config.params.nix;
nix.settings.substitute = false;
};
};
# host or level 1
nix.enable = config.params.nix;
};
in
makeNested (makeNested { });
{
imports = [
(makeNested (makeNested { }))
];
nix.settings.substitute = false;
};
testScript = ''
config.testScript = ''
machine.start()
machine.wait_for_unit("container@nested.service")
machine.succeed("systemd-run --pty --machine=nested -- machinectl list | grep nested")
@@ -30,5 +57,62 @@
"systemd-run --pty --machine=nested -- systemd-run --pty --machine=nested -- systemctl status"
)
)
${lib.optionalString config.params.nix ''
def check_path(path):
# result is available on host
machine.succeed(f"""
stat {path}
""")
# result is available on container
# invocation by absolute path because systemd-run is quite minimal
machine.succeed(f"""
systemd-run --machine=nested --pipe --wait -- /run/current-system/sw/bin/stat {path}
""")
# result is available on nested container
machine.succeed(f"""
systemd-run --machine=nested --pipe --wait -- systemd-run --machine=nested --pipe --wait -- /run/current-system/sw/bin/stat {path}
""")
with subtest("nix store sharing"):
with subtest("built on host"):
build = machine.succeed("""
nix-build --expr 'derivation {
name = "buildprobe-0";
system = "${system}";
builder = "/bin/sh";
args = [ "-c" "echo ok 0 >$out" ];
}'
""")
check_path(build)
with subtest("built on container layer 1"):
build = machine.succeed("""
systemd-run --machine=nested --pipe --wait -- \
/bin/sh -l -c 'exec $0 "$@"' \
/run/current-system/sw/bin/nix-build --expr 'derivation {
name = "buildprobe-1";
system = "${system}";
builder = "/bin/sh";
args = [ "-c" "echo ok 1 >$out" ];
}'
""")
check_path(build)
with subtest("built on container layer 2"):
build = machine.succeed("""
systemd-run --machine=nested --pipe --wait -- \
systemd-run --machine=nested --pipe --wait -- \
/bin/sh -l -c 'exec $0 "$@"' \
/run/current-system/sw/bin/nix-build --expr 'derivation {
name = "buildprobe-2";
system = "${system}";
builder = "/bin/sh";
args = [ "-c" "echo ok 2 >$out" ];
}'
""")
check_path(build)
''}
'';
}

View File

@@ -22,6 +22,7 @@
}
];
networking.firewall.enable = false;
nix.enable = false; # disabled by default on the test's host. See all-tests.nix / tag(no-nix-by-default)
};
};
};
@@ -44,6 +45,7 @@
config = {
networking.firewall.enable = false;
nix.enable = false; # disabled by default on the test's host. See all-tests.nix / tag(no-nix-by-default)
};
};
};
@@ -65,6 +67,7 @@
}
];
networking.firewall.enable = false;
nix.enable = false; # disabled by default on the test's host. See all-tests.nix / tag(no-nix-by-default)
};
};
};
@@ -90,6 +93,7 @@
}
];
networking.firewall.enable = false;
nix.enable = false; # disabled by default on the test's host. See all-tests.nix / tag(no-nix-by-default)
};
};
};
@@ -116,6 +120,7 @@
}
];
networking.firewall.enable = false;
nix.enable = false; # disabled by default on the test's host. See all-tests.nix / tag(no-nix-by-default)
};
};
};

View File

@@ -36,6 +36,7 @@ in
services.httpd.enable = true;
services.httpd.adminAddr = "foo@example.org";
networking.firewall.allowedTCPPorts = [ 80 ];
nix.enable = false; # disabled by default on the test's host. See all-tests.nix / tag(no-nix-by-default)
};
};

View File

@@ -12,6 +12,7 @@
containers.test1 = {
autoStart = true;
config.environment.etc.check.text = "client_base";
config.nix.enable = false; # disabled by default on the test's host. See all-tests.nix / tag(no-nix-by-default)
};
# prevent make-test-python.nix to change IP
@@ -22,6 +23,7 @@
environment.etc.check.text = lib.mkForce "client_c1";
services.httpd.enable = true;
services.httpd.adminAddr = "nixos@example.com";
nix.enable = false; # disabled by default on the test's host. See all-tests.nix / tag(no-nix-by-default)
};
};
@@ -29,6 +31,7 @@
containers.test1.config = {
environment.etc.check.text = lib.mkForce "client_c2";
services.nginx.enable = true;
nix.enable = false; # disabled by default on the test's host. See all-tests.nix / tag(no-nix-by-default)
};
};
};

View File

@@ -8,7 +8,9 @@
bindMounts = {
"/srv/data" = { };
};
config = { };
config = {
nix.enable = false; # disabled by default on the test's host. See all-tests.nix / tag(no-nix-by-default)
};
};
virtualisation.fileSystems = {

View File

@@ -22,6 +22,7 @@
prefixLength = 24;
}
];
nix.enable = false; # disabled by default on the test's host. See all-tests.nix / tag(no-nix-by-default)
};
};

View File

@@ -23,7 +23,9 @@
# Add a tmpfs on a path that does not exist
"/some/random/path"
];
config = { };
config = {
nix.enable = false; # disabled by default on the test's host. See all-tests.nix / tag(no-nix-by-default)
};
};
virtualisation.additionalPaths = [ pkgs.stdenv ];

View File

@@ -11,7 +11,9 @@
containers = {
test-container = {
autoStart = true;
config = { };
config = {
nix.enable = false; # disabled by default on the test's host. See all-tests.nix / tag(no-nix-by-default)
};
};
};
};

View File

@@ -34,10 +34,10 @@
return status == 0 and int(output) == 1
def start_job():
machine.succeed("curl -X POST http://localhost:8156/api/jobs/Test%20job")
machine.succeed("curl -X POST http://localhost:8156/api/jobs/test-job")
def job_ran_successfully() -> bool:
output = machine.succeed("curl http://localhost:8156/api/runs/Test%20job | jq '.[0].status_id, .[0].logs.[2].message'")
output = machine.succeed("curl http://localhost:8156/api/runs/test-job | jq '.[0].status_id, .[0].logs.[2].message'")
split_output = output.split('\n')
ran_successfully = int(split_output[0]) == 3
log_message_as_expected = "Job runs not successfully" in split_output[1]

View File

@@ -18,6 +18,7 @@
# check that extra-allowed-users is effective for harmonia
nix.settings.allowed-users = [ ];
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
};
client01 = {
@@ -27,6 +28,7 @@
"cache.example.com-1:eIGQXcGQpc00x6/XFcyacLEUmC07u4RAEHt5Y8vdglo="
];
};
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
};
};

View File

@@ -44,5 +44,6 @@
};
services.postfix.enable = true;
nix.settings.substituters = [ ];
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
};
}

View File

@@ -14,6 +14,7 @@ makeInstalledTest {
with pkgs;
[ flatpak-builder ] ++ flatpak-builder.installedTestsDependencies;
virtualisation.diskSize = 2048;
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
};
testRunnerFlags = [

View File

@@ -684,6 +684,9 @@ let
nodes =
let
commonConfig = {
# disabled by default. See all-tests.nix / tag(no-nix-by-default)
nix.enable = true;
# builds stuff in the VM, needs more juice
virtualisation.diskSize = 12 * 1024;
virtualisation.cores = 8;

View File

@@ -108,6 +108,8 @@ in
system.extraDependencies = [ nodes.initiatorRootDisk.system.build.toplevel ];
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
nix.settings = {
substituters = lib.mkForce [ ];
hashed-mirrors = null;

View File

@@ -2,6 +2,8 @@
name = "lix";
nodes.machine = { pkgs, ... }: {
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
nix.package = pkgs.lix;
environment.etc."test.nix".text = ''

View File

@@ -29,6 +29,7 @@
ubuntu-classic
];
services.printing.enable = true;
services.upower.enable = true;
};
@@ -37,7 +38,7 @@
testScript =
let
settingsPages = [
# Base pages
# Network
{
name = "wifi";
type = "internal";
@@ -55,6 +56,8 @@
element = "Add|Manual|Configuration";
skipOCR = true;
}
# Personal
{
name = "appearance";
type = "internal";
@@ -85,6 +88,13 @@
type = "internal";
element = "Edge drag";
}
# System
{
name = "printing";
type = "internal";
element = "no printers configured";
}
{
name = "mouse";
type = "internal";
@@ -95,13 +105,10 @@
type = "internal";
element = "Time zone|Set the time and date";
}
# External plugins
{
name = "security-privacy";
type = "external";
type = "internal";
element = "Locking|unlocking|permissions";
elementLocalised = "Sperren|Entsperren|Berechtigungen";
}
];
in

View File

@@ -6,6 +6,8 @@
{
imports = [ ../../modules/profiles/minimal.nix ];
environment.systemPackages = [ pkgs.lorri ];
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
};
testScript = ''

View File

@@ -66,6 +66,7 @@ in
boot.kernel.sysctl."vm.swappiness" = 1;
boot.kernelParams = [ "vsyscall=emulate" ];
system.extraDependencies = [ foo ];
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
};
testScript = ''

View File

@@ -23,6 +23,8 @@
networking.firewall.allowedTCPPorts = [ 8383 ];
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
# virtualisation.diskSize = 2 * 1024;
};
};

View File

@@ -26,6 +26,8 @@
networking.firewall.allowedTCPPorts = [ 5000 ];
system.extraDependencies = [ pkgs.emptyFile ];
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
};
ncps = {
@@ -50,6 +52,8 @@
};
networking.firewall.allowedTCPPorts = [ 8501 ];
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
};
client = {
@@ -59,6 +63,7 @@
"ncps:UtiE6C+3Tx0kgpP34vjyX/BKK6QZ/D1OzDYX72aCPJg="
];
};
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
};
};

View File

@@ -116,8 +116,8 @@ runTest (
)
# Verify the local and remote copies of the file are identical.
client_hash = client.succeed("nix-hash testfile.bin").strip()
nextcloud_hash = nextcloud.succeed("nix-hash /var/lib/nextcloud-data/data/root/files/testfile.bin").strip()
client_hash = client.succeed("sha256sum <testfile.bin").strip()
nextcloud_hash = nextcloud.succeed("sha256sum </var/lib/nextcloud-data/data/root/files/testfile.bin").strip()
t.assertEqual(client_hash, nextcloud_hash)
with subtest("secrets"):

View File

@@ -9,6 +9,7 @@
extra-nix-path = [ "extra=/etc/value.nix" ];
};
environment.etc."value.nix".text = "42";
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
};
testScript = ''
start_all()

View File

@@ -100,6 +100,7 @@ let
# Gives us access inside the nix sandbox
extra-sandbox-paths = [ "${pkgs.pkgsStatic.busybox}" ];
};
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
# Easy way to get files to the system
environment.etc = {

View File

@@ -19,6 +19,7 @@
"auto-allocate-uids"
];
};
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
# Easiest way to get a file onto the machine
environment.etc."test.nix".text = ''

View File

@@ -7,6 +7,8 @@
experimental-features = [ "nix-command" ];
log-lines = 26;
};
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
# Easiest way to get a file onto the machine
environment.etc."test.nix".text = ''
derivation {

View File

@@ -16,6 +16,7 @@ in
nix.settings.substituters = lib.mkForce [ ];
nix.settings.system-features = [ "supported-feature" ];
nix.settings.experimental-features = [ "nix-command" ];
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
programs.nix-required-mounts.enable = true;
programs.nix-required-mounts.allowedPatterns.supported-feature = {
onFeatures = [ "supported-feature" ];

View File

@@ -12,6 +12,9 @@ in
{
name = "nix-ssh-serve";
meta.maintainers = [ lib.maintainers.shlevy ];
defaults = {
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
};
nodes = {
server.nix.sshServe = {
enable = true;

View File

@@ -8,6 +8,7 @@
environment.systemPackages = [
pkgs.hello
];
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
};
testScript =
let

View File

@@ -45,6 +45,8 @@ pkgs.testers.nixosTest {
imports = [ nixos-module ];
nix.package = nixVersions.stable;
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
system.extraDependencies = [
fallback-paths-external
];

View File

@@ -19,6 +19,8 @@
services.desktopManager.gnome.enable = true;
''
];
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
};
testScript = ''
start_all()

View File

@@ -20,6 +20,7 @@
hashed-mirrors = null;
connect-timeout = 1;
};
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
system.includeBuildDependencies = true;

View File

@@ -20,6 +20,7 @@
hashed-mirrors = null;
connect-timeout = 1;
};
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
system.includeBuildDependencies = true;

View File

@@ -5,7 +5,9 @@
# TODO: remove overlay from nixos/modules/profiles/installation-device.nix
# make it a _small package instead, then remove pkgsReadOnly = false;.
node.pkgsReadOnly = false;
defaults = {
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
};
nodes = {
deployer =
{ lib, pkgs, ... }:

View File

@@ -0,0 +1,25 @@
# This tests the generation of junit files via the test driver.
{
name = "junit";
extraDriverArgs = [ "--junit=junit.xml" ];
nodes.machine = {
# Speeds up the boot significantly
networking.useNetworkd = true;
environment.etc."something".text = "nothing";
};
testScript = ''
machine.start()
machine.wait_for_unit("multi-user.target")
with subtest("systemd-networkd is started"):
machine.succeed("systemctl status systemd-networkd.service")
with subtest("/etc is populated correctly"):
output = machine.succeed("cat /etc/something")
t.assertEqual(output, "nothing")
'';
}

View File

@@ -1,6 +1,9 @@
{ pkgs, lib, ... }:
{
name = "nixseparatedebuginfod2";
defaults = {
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
};
# A binary cache with debug info and source for gnumake
nodes.cache =
{ pkgs, ... }:

View File

@@ -13,6 +13,7 @@
testScript = ''
machine.wait_for_unit("portunus.service")
machine.succeed("curl --fail -vvv http://localhost:8080/")
machine.wait_for_open_port(8080)
machine.wait_until_succeeds("curl --fail -vvv http://localhost:8080/")
'';
}

View File

@@ -5,6 +5,10 @@
meta.maintainers = with lib.maintainers; [ nikstur ];
defaults = {
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
};
nodes = {
sharedWritable = {
virtualisation.writableStore = true;

View File

@@ -8,6 +8,8 @@ import ../make-test-python.nix (
{ ... }:
{
nix.settings.experimental-features = [ "ca-derivations" ];
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
system.extraDependencies = [ pkgs.stdenvNoCC ];
};

View File

@@ -23,6 +23,7 @@
};
};
};
nix.enable = false; # disabled by default on the test's host. See all-tests.nix / tag(no-nix-by-default)
};
};
};

View File

@@ -25,6 +25,8 @@
};
};
};
# TODO: Remove dependency on nix. (Not needed, and I don't understand /nix/store above)
nix.enable = true;
};
in
{

View File

@@ -7,6 +7,10 @@ in
name = "rush";
meta = { inherit (pkgs.rush.meta) maintainers platforms; };
defaults = {
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
};
nodes = {
client =
{ ... }:

View File

@@ -41,6 +41,8 @@ let
boot.loader.efi.canTouchEfiVariables = true;
environment.systemPackages = [ pkgs.efibootmgr ];
system.switch.enable = true;
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
# Needed for machine-id to be persisted between reboots.
# Must be a valid (non-zero) ID, otherwise sd_id128_get_machine()
# returns -ENOMEDIUM and dbus-broker refuses to start.

View File

@@ -21,7 +21,9 @@
nodes.containerCheck = {
containers.c1 = {
autoStart = true;
config = { };
config = {
nix.enable = false; # disabled by default on the test's host. See all-tests.nix / tag(no-nix-by-default)
};
};
};

View File

@@ -23,6 +23,7 @@ in
services.nix-serve = {
enable = true;
};
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
services.varnish = {
inherit package;
@@ -86,6 +87,7 @@ in
require-sigs = false;
substituters = lib.mkForce [ "http://varnish" ];
};
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
};
};

View File

@@ -28,6 +28,7 @@ in
services.nix-serve = {
enable = true;
};
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
services.vinyl-cache = {
inherit package;
@@ -97,6 +98,7 @@ in
require-sigs = false;
substituters = lib.mkForce [ "http://vinyl" ];
};
nix.enable = true; # disabled by default. See all-tests.nix / tag(no-nix-by-default)
};
};

View File

@@ -138,6 +138,7 @@ in
services.httpd.enable = true;
services.httpd.adminAddr = "foo@example.org";
networking.firewall.allowedTCPPorts = [ 80 ];
nix.enable = false; # disabled by default on the test's host. See all-tests.nix / tag(no-nix-by-default)
};
};
};

View File

@@ -2155,6 +2155,20 @@ final: prev: {
meta.hydraPlatforms = [ ];
};
boolean-toggle-nvim = buildVimPlugin {
pname = "boolean-toggle.nvim";
version = "0.5.0-1";
src = fetchFromGitHub {
owner = "DrKJeff16";
repo = "boolean-toggle.nvim";
tag = "v0.5.0-1";
hash = "sha256-93ppL2JP2K+lfeCtJG0R8YW6cLk8JJrPa5RAGKnzOlE=";
};
meta.homepage = "https://github.com/DrKJeff16/boolean-toggle.nvim/";
meta.license = getLicenseFromSpdxId "GPL-2.0-only";
meta.hydraPlatforms = [ ];
};
bracey-vim = buildVimPlugin {
pname = "bracey.vim";
version = "0-unstable-2021-08-20";

View File

@@ -152,6 +152,7 @@ https://github.com/HampusHauffman/block.nvim/,,
https://github.com/uloco/bluloco.nvim/,,
https://github.com/rockerBOO/boo-colorscheme-nvim/,,
https://github.com/nat-418/boole.nvim/,,
https://github.com/DrKJeff16/boolean-toggle.nvim/,,
https://github.com/turbio/bracey.vim/,,
https://github.com/fruit-in/brainfuck-vim/,,
https://github.com/famiu/bufdelete.nvim/,,

View File

@@ -1,6 +1,5 @@
{
lib,
buildGo125Module,
buildGo126Module,
fetchFromGitHub,
nixosTests,
@@ -96,7 +95,7 @@ rec {
};
nomad_1_11 = generic {
buildGoModule = buildGo125Module;
buildGoModule = buildGo126Module;
version = "1.11.3";
hash = "sha256-J+w53HlMlrXX5yKjDYhf3rSGt1pmOyNcPlOqyUrkLWE=";
vendorHash = "sha256-67etQUjcPXz4VVpNXLVusQlEybxEqKfYQcNTNL4X8bA=";
@@ -108,7 +107,7 @@ rec {
};
nomad_1_10 = generic {
buildGoModule = buildGo125Module;
buildGoModule = buildGo126Module;
version = "1.10.5";
hash = "sha256-NFH++oYWb6vQN6cOPByscI/ZBWDNy4YbcLiBMO3/jVU=";
vendorHash = "sha256-QcTw9kKwoHIvXZoxfDohFG+sBs8OLvYPeygygDClsn8=";
@@ -120,7 +119,7 @@ rec {
};
nomad_1_9 = generic {
buildGoModule = buildGo125Module;
buildGoModule = buildGo126Module;
version = "1.9.7";
hash = "sha256-U02H6DPr1friQ9EwqD/wQnE2Fm20OE5xNccPDJfnsqI=";
vendorHash = "sha256-9GnwqkexJAxrhW9yJFaDTdSaZ+p+/dcMuhlusp4cmyw=";

View File

@@ -54,13 +54,13 @@
"vendorHash": "sha256-bJcVf4Yj70VwKn0p6RN+/dc5J+K6xFJcifVei9dK2bA="
},
"aminueza_minio": {
"hash": "sha256-2NbI/ANAuCogB4H31N2k5dPpg8jqRULFdWD0+NxQD5c=",
"hash": "sha256-pw8QgjdU0c4w6ZUJLCy3zTEk0UTML1Mymh+UsmBAdrQ=",
"homepage": "https://registry.terraform.io/providers/aminueza/minio",
"owner": "aminueza",
"repo": "terraform-provider-minio",
"rev": "v3.41.0",
"rev": "v3.41.1",
"spdx": "AGPL-3.0",
"vendorHash": "sha256-NplukDVIzE8OUBOUdi0NTEPYBIGTwIaXxd+j5FdJjf8="
"vendorHash": "sha256-V9yH/dGXZJ85XVQAksL4QCRbhS9yrXy2tY8Jr+kKQdk="
},
"archessmn_powerdns": {
"hash": "sha256-1bjQFu3k0ERBga94pQ8HZjbfu3qlxnMQLjSkDU6Vp/I=",
@@ -209,11 +209,11 @@
"vendorHash": "sha256-R3w7olc94QJuMk62bfvuM9aU+KlmNTUhojl/j9gmHjk="
},
"cloudamqp_cloudamqp": {
"hash": "sha256-UOEZK9zjHwUId86hawiWVtXAY3eGwbQIQLSmLHBbgCc=",
"hash": "sha256-GMfBdLUqw/3WEtZfP6ShCEwheHeUa/1EDMzIuYGalvA=",
"homepage": "https://registry.terraform.io/providers/cloudamqp/cloudamqp",
"owner": "cloudamqp",
"repo": "terraform-provider-cloudamqp",
"rev": "v1.47.0",
"rev": "v1.48.0",
"spdx": "MPL-2.0",
"vendorHash": "sha256-hgi4CyYMNBmxAUc93uFc4J13nlgVOQNLYyLYz+rnWlM="
},
@@ -292,13 +292,13 @@
"vendorHash": "sha256-3o6YRDrq4rQhNAFyqiGJrAoxuAykWw85OExRGSE3kGI="
},
"datadog_datadog": {
"hash": "sha256-ATKQBtgI4yfjZo09iMPlH7g14xc6bI9ebP64GTtNZwk=",
"hash": "sha256-Sq3gP01DrTm41fLTZvavNTNhMy7AfMcbxe+ac8omJIQ=",
"homepage": "https://registry.terraform.io/providers/DataDog/datadog",
"owner": "DataDog",
"repo": "terraform-provider-datadog",
"rev": "v4.19.0",
"rev": "v4.20.0",
"spdx": "MPL-2.0",
"vendorHash": "sha256-Uy798AsTpZNtaggIxUlf3WNIFTmvigtPp0yWygcyzJY="
"vendorHash": "sha256-PoM4C03Q8bAz1hqasx0SWYWEVW7dS7tCcI+tLE2MHLE="
},
"datadrivers_nexus": {
"hash": "sha256-t9hpZ4COmMPvs4TgcZLeuOA23oD5vvHw8UVK7SpzI0Y=",
@@ -382,13 +382,13 @@
"vendorHash": "sha256-uokHd4hDvWl6mrBa062F/uZmYPnW3TIZZKZwKBVq+Lo="
},
"e-breuninger_netbox": {
"hash": "sha256-qyzw5a35twJ5gsEe0ANv6a9MMD0UyV8hYbYt/2bBJ/k=",
"hash": "sha256-tbBCGOcbDhiOjdgyS9lSw6IbMgzZwnbM40/InvhUKCA=",
"homepage": "https://registry.terraform.io/providers/e-breuninger/netbox",
"owner": "e-breuninger",
"repo": "terraform-provider-netbox",
"rev": "v5.7.0",
"rev": "v5.8.0",
"spdx": "MPL-2.0",
"vendorHash": "sha256-y9GRTuoh1X6GfGkGZbPpO500y8DoJS1dnwZL3BCTUcY="
"vendorHash": "sha256-NbFksqqwwelhSig6+5kqoTuUsUab8we+sSp1izfpF10="
},
"equinix_equinix": {
"hash": "sha256-gPuRvWQiJZdyUGTNMCQSEFmbqC5ralxroBSbBprFe/8=",
@@ -517,13 +517,13 @@
"vendorHash": "sha256-ikBqIxD5aTOcwNHCMN6EaOwSHCAP5n/SULuqQXPLpOc="
},
"hashicorp_aws": {
"hash": "sha256-INQXP7BRW+QbcxYd6QmIKLzilmXlT2ntVMONcpk5Q4g=",
"hash": "sha256-qSGvtJqiViBdBZD6gMZSaUXbZNZmCBBb1kkKUjCK0YM=",
"homepage": "https://registry.terraform.io/providers/hashicorp/aws",
"owner": "hashicorp",
"repo": "terraform-provider-aws",
"rev": "v6.62.0",
"rev": "v6.63.0",
"spdx": "MPL-2.0",
"vendorHash": "sha256-e6ILWC7E2S9u+evH9OmS1hyn6WmYn9r0ch/zfJJ7xrg="
"vendorHash": "sha256-lrcDMPenGnTgKnrdL9oCk3Pg/WObKYqKxbLXqjWR7U4="
},
"hashicorp_awscc": {
"hash": "sha256-cVpZA8XK3d6RDjdo8KMbQ/J540ZRzUb79S2wq/Vzo6Y=",
@@ -1328,11 +1328,11 @@
"vendorHash": "sha256-kWwfjiWDm/voT95oxyNtCltRzeBJYR3gJo1USV0j/Uo="
},
"tencentcloudstack_tencentcloud": {
"hash": "sha256-p8DBZ2NRC5Dswf+iRSg00zBi3+mA1Y3jNKS5ikpJ1Qo=",
"hash": "sha256-nuzKpMtJT0y4OuSvYTKbAs1+FYTpnXnWYI9oEzdt1BM=",
"homepage": "https://registry.terraform.io/providers/tencentcloudstack/tencentcloud",
"owner": "tencentcloudstack",
"repo": "terraform-provider-tencentcloud",
"rev": "v1.83.27",
"rev": "v1.83.29",
"spdx": "MPL-2.0",
"vendorHash": null
},

View File

@@ -285,7 +285,8 @@ stdenv.mkDerivation (finalAttrs: {
exec = binaryName;
icon = pname;
inherit desktopName;
genericName = meta.description;
comment = meta.description;
genericName = "Instant Messenger";
categories = [
"Network"
"InstantMessaging"

View File

@@ -1,159 +0,0 @@
{
autoPatchelfHook,
fetchurl,
lib,
copyDesktopItems,
makeDesktopItem,
makeWrapper,
stdenv,
wrapGAppsHook3,
at-spi2-core,
atk,
alsa-lib,
cairo,
cups,
dbus,
expat,
gcc-unwrapped,
gdk-pixbuf,
glib,
pango,
gtk3-x11,
libudev0-shim,
libuuid,
libgbm,
nss,
nspr,
libxtst,
libxscrnsaver,
libxrender,
libxrandr,
libxi,
libxfixes,
libxext,
libxdamage,
libxcursor,
libxcomposite,
libx11,
libxcb,
streamlink,
}:
let
basename = "streamlink-twitch-gui";
runtimeLibs = lib.makeLibraryPath [
gtk3-x11
libudev0-shim
];
runtimeBins = lib.makeBinPath [ streamlink ];
in
stdenv.mkDerivation rec {
pname = "${basename}-bin";
version = "2.5.3";
src =
{
x86_64-linux = fetchurl {
url = "https://github.com/streamlink/${basename}/releases/download/v${version}/${basename}-v${version}-linux64.tar.gz";
hash = "sha256-ue5Ehj/dLOIJNJVq0Pd6EbA1hkVPz5m+3chVvEXaH6U=";
};
i686-linux = fetchurl {
url = "https://github.com/streamlink/${basename}/releases/download/v${version}/${basename}-v${version}-linux32.tar.gz";
hash = "sha256-y252QhVsRakngdApOHgegMMhs61KTxL9gfPjBjaSKOI=";
};
}
.${stdenv.hostPlatform.system} or (throw "Unsupported system: ${stdenv.hostPlatform.system}");
nativeBuildInputs = [
at-spi2-core
atk
alsa-lib
autoPatchelfHook
cairo
copyDesktopItems
cups.lib
dbus.lib
expat
gcc-unwrapped
gdk-pixbuf
glib
pango
gtk3-x11
libgbm
nss
nspr
libuuid
libx11
libxcb
libxcomposite
libxcursor
libxdamage
libxext
libxfixes
libxi
libxrandr
libxrender
libxscrnsaver
libxtst
makeWrapper
wrapGAppsHook3
];
buildInputs = [ streamlink ];
dontBuild = true;
dontConfigure = true;
installPhase = ''
runHook preInstall
mkdir -p $out/{bin,opt/${basename},share}
# Install all files, remove unnecessary ones
cp -a . $out/opt/${basename}/
rm -r $out/opt/${basename}/{{add,remove}-menuitem.sh,credits.html,icons/}
ln -s $out/opt/${basename}/${basename} $out/bin/
for res in 16 32 48 64 128 256; do
install -Dm644 \
icons/icon-"$res".png \
$out/share/icons/hicolor/"$res"x"$res"/apps/${basename}.png
done
runHook postInstall
'';
preFixup = ''
gappsWrapperArgs+=(
--add-flags "--no-version-check" \
--prefix LD_LIBRARY_PATH : ${runtimeLibs} \
--prefix PATH : ${runtimeBins}
)
'';
desktopItems = [
(makeDesktopItem {
name = basename;
exec = basename;
icon = basename;
desktopName = "Streamlink Twitch GUI";
genericName = meta.description;
categories = [
"AudioVideo"
"Network"
];
})
];
meta = {
description = "Twitch.tv browser for Streamlink";
longDescription = "Browse Twitch.tv and watch streams in your videoplayer of choice";
homepage = "https://streamlink.github.io/streamlink-twitch-gui/";
downloadPage = "https://github.com/streamlink/streamlink-twitch-gui/releases";
sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ];
license = lib.licenses.mit;
mainProgram = "streamlink-twitch-gui";
maintainers = [ ];
platforms = [
"x86_64-linux"
"i686-linux"
];
};
}

View File

@@ -7,17 +7,17 @@
}:
buildGoModule (finalAttrs: {
pname = "docker-compose";
version = "5.5.0";
version = "5.5.1";
__structuredAttrs = true;
src = fetchFromGitHub {
owner = "docker";
repo = "compose";
tag = "v${finalAttrs.version}";
hash = "sha256-EUPf76jj4Wc287zZNiDzSljAnwl8adSkUAz8JJaT1es=";
hash = "sha256-f4lIO9zSONHSQoZy80NSg3pcXyDfT5GXRcB3RkXC9sw=";
};
vendorHash = "sha256-3Jlc/0g/IjH7hhnx70PgZ76Dl8nPzv9M2Gee3TXOGCg=";
vendorHash = "sha256-8I+gPz7gdNKjuqLi0AnW4NjaONKxoYIhHZR064QYt6g=";
nativeInstallCheckInputs = [ versionCheckHook ];

View File

@@ -71,9 +71,7 @@ let
# A user is required by nix
# https://github.com/NixOS/nix/blob/9348f9291e5d9e4ba3c4347ea1b235640f54fd79/src/libutil/util.cc#L478
export USER=nobody
${lib.getExe' buildPackages.nix "nix-store"} --load-db < ${
closureInfo { rootPaths = contentsList; }
}/registration
nix-store --load-db < ${closureInfo { rootPaths = contentsList; }}/registration
# Reset registration times to make the image reproducible
${lib.getExe buildPackages.sqlite} nix/var/nix/db/db.sqlite "UPDATE ValidPaths SET registrationTime = ''${SOURCE_DATE_EPOCH}"
@@ -430,6 +428,7 @@ rec {
keepContentsDirlinks ? false,
# Additional commands to run on the layer before it is tar'd up.
extraCommands ? "",
nativeBuildInputs ? [ ],
uid ? 0,
gid ? 0,
}:
@@ -441,7 +440,8 @@ rec {
jshon
rsync
tarsum
];
]
++ nativeBuildInputs;
}
''
mkdir layer
@@ -705,6 +705,7 @@ rec {
uid
gid
;
nativeBuildInputs = optionals includeNixDB [ nix ];
extraCommands = extraCommandsWithDB;
copyToRoot = rootContents;
}
@@ -1082,6 +1083,9 @@ rec {
]
++ optionals enableFakechroot [
proot
]
++ optionals includeNixDB [
nix
];
postBuild = ''
mv $out old_out

View File

@@ -50,5 +50,8 @@ python3.pkgs.buildPythonApplication (finalAttrs: {
mainProgram = "alertad";
license = lib.licenses.asl20;
maintainers = [ ];
knownVulnerabilities = [
"CVE-2026-34400: vulnerable to SQL injection via the Postgres query parser, which built WHERE clauses by interpolating user-supplied search terms directly into SQL strings via f-strings. This issue has been patched in version 9.1.0." # 505619 in nixpkgs
];
};
})

View File

@@ -8,11 +8,11 @@
stdenv.mkDerivation (finalAttrs: {
pname = "allure";
version = "2.46.0";
version = "2.46.1";
src = fetchurl {
url = "https://github.com/allure-framework/allure2/releases/download/${finalAttrs.version}/allure-${finalAttrs.version}.tgz";
hash = "sha256-KRyhI4t+Z9Vho1/N758shQyBHBxh9FsccNbX87sBpog=";
hash = "sha256-N0KBZPMQyNE3z90sOiXQSbIzJh3asT4b1N/XYntcv40=";
};
dontConfigure = true;

View File

@@ -9,7 +9,7 @@
buildGoModule (finalAttrs: {
pname = "andcli";
version = "2.8.1";
version = "2.9.0";
__structuredAttrs = true;
@@ -19,10 +19,10 @@ buildGoModule (finalAttrs: {
owner = "tjblackheart";
repo = "andcli";
tag = "v${finalAttrs.version}";
hash = "sha256-BVF+r8N+/PvARxANlL7nPf23ABbp+O1DNPblMyXroq8=";
hash = "sha256-ls/QWEAxxnsersk7L3AaRo5jo1Vsao61c2mgjt91sAQ=";
};
vendorHash = "sha256-aFOwfloqFPPMgCufwmDgfM9lDinkFvu4i+BiVUo+Iwk=";
vendorHash = "sha256-+qz2vIh4GTkdmhjGvYqJYZ9ZMI9f+yXObmyGHk/5Cyg=";
ldflags = [
"-s"

View File

@@ -0,0 +1,20 @@
diff --git a/buildscripts/cmake/SetupBuildEnvironment.cmake b/buildscripts/cmake/SetupBuildEnvironment.cmake
index d45a7728590..c4c77d48198 100644
--- a/buildscripts/cmake/SetupBuildEnvironment.cmake
+++ b/buildscripts/cmake/SetupBuildEnvironment.cmake
@@ -159,7 +159,13 @@
endif()
endif() #MUE_COMPILE_QT5_COMPAT
- set(MACOSX_DEPLOYMENT_TARGET 10.15)
- set(CMAKE_OSX_DEPLOYMENT_TARGET 10.15)
+ if (NOT CMAKE_OSX_DEPLOYMENT_TARGET)
+ if (NOT "$ENV{MACOSX_DEPLOYMENT_TARGET}" STREQUAL "")
+ set(CMAKE_OSX_DEPLOYMENT_TARGET "$ENV{MACOSX_DEPLOYMENT_TARGET}")
+ else()
+ set(CMAKE_OSX_DEPLOYMENT_TARGET 10.15)
+ endif()
+ endif()
+ set(MACOSX_DEPLOYMENT_TARGET "${CMAKE_OSX_DEPLOYMENT_TARGET}")
endif(OS_IS_MAC)

View File

@@ -0,0 +1,25 @@
diff --git a/CMakeLists.txt b/CMakeLists.txt
index 17e3e15e4de..49d869a6777 100644
--- a/CMakeLists.txt
+++ b/CMakeLists.txt
@@ -62,6 +62,8 @@
set(AU4_REVISION "" CACHE STRING "Build revision")
+set(AU4_MACDEPLOYQT_EXTRA_OPTIONS "" CACHE STRING "Semicolon-separated extra arguments for macdeployqt")
+
# Modules (alphabetical order please)
option(AU_BUILD_APPSHELL_MODULE "Build appshell module" ON)
option(AU_BUILD_APPSHELL_TESTS "Build appshell tests" ${MUSE_ENABLE_UNIT_TESTS})
diff --git a/src/app/CMakeLists.txt b/src/app/CMakeLists.txt
index a653a0b4cda..1ee5a5b31eb 100644
--- a/src/app/CMakeLists.txt
+++ b/src/app/CMakeLists.txt
@@ -418,6 +418,7 @@
DEPLOY_TOOL_OPTIONS
-qmldir=${PROJECT_SOURCE_DIR}/src
-qmldir=${PROJECT_SOURCE_DIR}/muse/framework
+ ${AU4_MACDEPLOYQT_EXTRA_OPTIONS}
)
install(SCRIPT ${deploy_script})

View File

@@ -0,0 +1,13 @@
diff --git a/muse_deps/recipes/wxwidgets/meta.cmake b/muse_deps/recipes/wxwidgets/meta.cmake
index b30de19..3d18391 100644
--- a/muse_deps/recipes/wxwidgets/meta.cmake
+++ b/muse_deps/recipes/wxwidgets/meta.cmake
@@ -35,6 +35,8 @@
endif()
separate_arguments(wx_cxx_list NATIVE_COMMAND "${wx_cxx}")
separate_arguments(wx_libs_list NATIVE_COMMAND "${wx_libs}")
+ # Keep framework flags and names together as a single CMake link item.
+ string(REGEX REPLACE "-framework;([^;]+)" "-framework \\1" wx_libs_list "${wx_libs_list}")
set(incs "")
set(opts "")

View File

@@ -0,0 +1,21 @@
diff --git a/muse/buildscripts/cmake/SetupBuildEnvironment.cmake b/muse/buildscripts/cmake/SetupBuildEnvironment.cmake
index 994b4ab30a..71a910bcfa 100644
--- a/muse/buildscripts/cmake/SetupBuildEnvironment.cmake
+++ b/muse/buildscripts/cmake/SetupBuildEnvironment.cmake
@@ -63,8 +63,14 @@
# Mac-specific
if(OS_IS_MAC)
- set(MACOSX_DEPLOYMENT_TARGET 10.15.4)
- set(CMAKE_OSX_DEPLOYMENT_TARGET 10.15.4)
+ if(NOT CMAKE_OSX_DEPLOYMENT_TARGET)
+ if(NOT "$ENV{MACOSX_DEPLOYMENT_TARGET}" STREQUAL "")
+ set(CMAKE_OSX_DEPLOYMENT_TARGET "$ENV{MACOSX_DEPLOYMENT_TARGET}")
+ else()
+ set(CMAKE_OSX_DEPLOYMENT_TARGET 10.15.4)
+ endif()
+ endif()
+ set(MACOSX_DEPLOYMENT_TARGET "${CMAKE_OSX_DEPLOYMENT_TARGET}")
endif(OS_IS_MAC)
# MSVC-specific

View File

@@ -1,214 +1,193 @@
{
stdenv,
lib,
fetchFromGitHub,
stdenv,
fetchurl,
# nativeBuildInputs
cmake,
makeWrapper,
wrapGAppsHook3,
git,
linuxHeaders,
ninja,
pkg-config,
python3,
gettext,
file,
libvorbis,
libmad,
qt6,
wrapGAppsHook3,
# buildInputs
alsa-lib,
expat,
ffmpeg,
flac,
freetype,
harfbuzz,
lame,
libjack2,
lv2,
lilv,
libogg,
libopus,
libsndfile,
libvorbis,
mpg123,
opusfile,
rapidjson,
serd,
sord,
sqlite,
sratom,
suil,
libsndfile,
soxr,
flac,
lame,
twolame,
expat,
libid3tag,
libopus,
libuuid,
ffmpeg,
soundtouch,
portaudio, # given up fighting their portaudio.patch?
portmidi,
linuxHeaders,
alsa-lib,
at-spi2-core,
dbus,
libepoxy,
libxdmcp,
libxtst,
libpthread-stubs,
libsbsms_2_3_0,
libselinux,
libsepol,
libxkbcommon,
util-linux,
portaudio,
pugixml,
utf8cpp,
wavpack,
wxwidgets_3_2,
gtk3,
libpng,
libjpeg,
zlib,
}:
# TODO
# 1. detach sbsms
let
wxwidgets = wxwidgets_3_2.override { withWebKit = false; };
in
stdenv.mkDerivation (finalAttrs: {
pname = "audacity";
version = "3.7.9";
version = "4.0.0";
src = fetchFromGitHub {
owner = "audacity";
repo = "audacity";
rev = "Audacity-${finalAttrs.version}";
hash = "sha256-q/5LPL76GPEFGRxTZcuxmLuq15fwbw2Mak/q2RObghk=";
src = fetchurl {
url = "https://github.com/audacity/audacity/releases/download/Audacity-${finalAttrs.version}/audacity-sources-${finalAttrs.version}.tar.xz";
hash = "sha256-spB2+Z+l0vUi0AHbRyqJbbgfnv/v0VlIyUBXF1OFgFg=";
};
patches = [
# Introduced by https://github.com/Tencent/rapidjson/commit/b1c0c2843fcb2aca9ecc650fc035c57ffc13697c#diff-2f1bcf2729ff7c408adb0c2cc2cfa01602bd5646b05b3e4bc7e46b606035d249R21
./rapidjson.patch
# https://github.com/musescore/muse_deps/pull/47
./muse-deps-wxwidgets-frameworks.patch
# https://github.com/audacity/audacity/pull/12021
./audacity-deployment-target.patch
# https://github.com/musescore/muse_framework/pull/278
./muse-framework-deployment-target.patch
]
++ lib.optionals stdenv.hostPlatform.isDarwin [
# https://github.com/audacity/audacity/pull/12056
./macdeployqt-extra-options.patch
];
postPatch = ''
mkdir src/private
substituteInPlace scripts/build/macOS/fix_bundle.py \
--replace-fail "path.startswith('/usr/lib/')" "path.startswith('/usr/lib/') or path.startswith('${builtins.storeDir}')"
''
+ lib.optionalString stdenv.hostPlatform.isLinux ''
substituteInPlace libraries/lib-files/FileNames.cpp \
postPatch = lib.optionalString stdenv.hostPlatform.isLinux ''
substituteInPlace au3/libraries/au3-files/FileNames.cpp \
--replace-fail /usr/include/linux/magic.h ${linuxHeaders}/include/linux/magic.h
'';
nativeBuildInputs = [
cmake
gettext
git
ninja
pkg-config
python3
makeWrapper
wrapGAppsHook3
qt6.qttools
qt6.wrapQtAppsHook
wxwidgets
]
++ lib.optionals stdenv.hostPlatform.isLinux [
linuxHeaders
wrapGAppsHook3
];
buildInputs = [
expat
ffmpeg
file
flac
gtk3
freetype
harfbuzz
lame
libid3tag
libjack2
libmad
libogg
libopus
libsbsms_2_3_0
libsndfile
libvorbis
lilv
lv2
mpg123
opusfile
portmidi
rapidjson
serd
sord
soundtouch
soxr
sqlite
sratom
suil
twolame
portaudio
pugixml
qt6.qt5compat
qt6.qtbase
qt6.qtdeclarative
qt6.qtnetworkauth
qt6.qtshadertools
qt6.qtsvg
utf8cpp
wavpack
wxwidgets_3_2
wxwidgets
zlib
]
++ lib.optionals stdenv.hostPlatform.isLinux [
alsa-lib # for portaudio
at-spi2-core
dbus
libepoxy
libxdmcp
libxtst
libpthread-stubs
libxkbcommon
libselinux
libsepol
libuuid
util-linux
]
++ lib.optionals stdenv.hostPlatform.isDarwin [
libpng
libjpeg
alsa-lib
qt6.qtwayland
];
cmakeFlags = [
"-DAUDACITY_BUILD_LEVEL=2"
"-DAUDACITY_REV_LONG=nixpkgs"
"-DAUDACITY_REV_TIME=nixpkgs"
"-DDISABLE_DYNAMIC_LOADING_FFMPEG=ON"
"-Daudacity_conan_enabled=Off"
"-Daudacity_use_ffmpeg=loaded"
"-Daudacity_has_vst3=Off"
"-Daudacity_has_crashreports=Off"
# RPATH of binary /nix/store/.../bin/... contains a forbidden reference to /build/
"-DCMAKE_SKIP_BUILD_RPATH=ON"
# Fix duplicate store paths
"-DCMAKE_INSTALL_LIBDIR=lib"
(lib.cmakeFeature "AU4_BUILD_MODE" "release")
(lib.cmakeFeature "EXTDEPS_OVERRIDE_ALL" "SYSTEM")
(lib.cmakeBool "MUSE_COMPILE_USE_CCACHE" false)
(lib.cmakeBool "MUSE_ENABLE_UNIT_TESTS" finalAttrs.finalPackage.doCheck)
(lib.cmakeBool "MUSE_MODULE_DIAGNOSTICS_CRASHPAD_CLIENT" false)
]
++ lib.optionals stdenv.hostPlatform.isDarwin [
(lib.cmakeFeature "CMAKE_OSX_ARCHITECTURES" stdenv.hostPlatform.darwinArch)
(lib.cmakeFeature "CMAKE_OSX_DEPLOYMENT_TARGET" stdenv.hostPlatform.darwinMinVersion)
# Nix performs stripping after deployment.
(lib.cmakeFeature "AU4_MACDEPLOYQT_EXTRA_OPTIONS" "-no-strip")
];
# [ 57%] Generating LightThemeAsCeeCode.h...
# ../../utils/image-compiler: error while loading shared libraries:
# lib-theme.so: cannot open shared object file: No such file or directory
preBuild = ''
export LD_LIBRARY_PATH=$PWD/Release/lib/audacity
preConfigure = ''
cmakeFlagsArray+=("-DEXTDEPS_CACHE=$PWD/offline-deps")
'';
doCheck = false; # Test fails
preInstall = lib.optionalString stdenv.hostPlatform.isDarwin ''
export NIX_QMLIMPORTSCANNER=${lib.getBin qt6.qtdeclarative}/libexec/qmlimportscanner
export QML2_IMPORT_PATH=
for input in ${lib.escapeShellArgs finalAttrs.buildInputs}; do
addToSearchPath QML2_IMPORT_PATH "$input/${qt6.qtbase.qtQmlPrefix}"
done
'';
postInstall = lib.optionalString stdenv.hostPlatform.isDarwin ''
mkdir -p "$out/Applications"
mv "$out/audacity.app" "$out/Applications/"
'';
qtWrapperArgs = [
"--prefix"
"${lib.optionalString stdenv.hostPlatform.isDarwin "DY"}LD_LIBRARY_PATH"
":"
(lib.makeLibraryPath [
ffmpeg
libjack2
])
];
preFixup = lib.optionalString stdenv.hostPlatform.isLinux ''
qtWrapperArgs+=("''${gappsWrapperArgs[@]}")
'';
postFixup = lib.optionalString stdenv.hostPlatform.isDarwin ''
# Use bundled Qt plugins, not a second Qt installation from the store.
wrapProgram "$out/Applications/audacity.app/Contents/MacOS/audacity" \
${lib.escapeShellArgs finalAttrs.qtWrapperArgs} \
--unset QT_PLUGIN_PATH \
--unset NIXPKGS_QT6_QML_IMPORT_PATH \
--unset QML2_IMPORT_PATH \
--unset QML_IMPORT_PATH
mkdir -p "$out/bin"
makeWrapper "$out/Applications/audacity.app/Contents/MacOS/audacity" "$out/bin/audacity"
'';
dontWrapGApps = true;
# Automatic scanning would wrap bundled framework libraries as executables.
dontWrapQtApps = stdenv.hostPlatform.isDarwin;
# Replace audacity's wrapper, to:
# - Put it in the right place; it shouldn't be in "$out/audacity"
# - Add the ffmpeg dynamic dependency
# - Use Xwayland by default on Wayland. See https://github.com/audacity/audacity/pull/5977
postFixup =
lib.optionalString stdenv.hostPlatform.isLinux ''
wrapProgram "$out/bin/audacity" \
"''${gappsWrapperArgs[@]}" \
--prefix LD_LIBRARY_PATH : "$out/lib/audacity":${lib.makeLibraryPath [ ffmpeg ]} \
--suffix AUDACITY_MODULES_PATH : "$out/lib/audacity/modules" \
--suffix AUDACITY_PATH : "$out/share/audacity" \
--set-default GDK_BACKEND x11
''
+ lib.optionalString stdenv.hostPlatform.isDarwin ''
mkdir -p $out/{Applications,bin}
mv $out/Audacity.app $out/Applications/
makeWrapper $out/Applications/Audacity.app/Contents/MacOS/Audacity $out/bin/audacity
'';
strictDeps = true;
__structuredAttrs = true;
meta = {
description = "Sound editor with graphical UI";
mainProgram = "audacity";
homepage = "https://www.audacityteam.org";
changelog = "https://github.com/audacity/audacity/releases";
license = with lib.licenses; [
gpl2Plus
# Must be GPL3 when building with "technologies that require it,
# such as the VST3 audio plugin interface".
# https://github.com/audacity/audacity/discussions/2142.
gpl3
# Documentation.
cc-by-30
changelog = "https://github.com/audacity/audacity/releases/tag/Audacity-${finalAttrs.version}";
license = lib.licenses.AND [
lib.licenses.gpl2Plus
lib.licenses.gpl3Only
lib.licenses.cc-by-30
];
maintainers = with lib.maintainers; [
johnrichardrinehart
veprbl
wegank
];

View File

@@ -0,0 +1,221 @@
{
stdenv,
lib,
fetchFromGitHub,
cmake,
makeWrapper,
wrapGAppsHook3,
pkg-config,
python3,
gettext,
file,
libvorbis,
libmad,
libjack2,
lv2,
lilv,
mpg123,
opusfile,
rapidjson,
serd,
sord,
sqlite,
sratom,
suil,
libsndfile,
soxr,
flac,
lame,
twolame,
expat,
libid3tag,
libopus,
libuuid,
ffmpeg,
soundtouch,
portaudio, # given up fighting their portaudio.patch?
portmidi,
linuxHeaders,
alsa-lib,
at-spi2-core,
dbus,
libepoxy,
libxdmcp,
libxtst,
libpthread-stubs,
libsbsms_2_3_0,
libselinux,
libsepol,
libxkbcommon,
util-linux,
wavpack,
wxwidgets_3_2,
gtk3,
libpng,
libjpeg,
}:
# TODO
# 1. detach sbsms
stdenv.mkDerivation (finalAttrs: {
pname = "audacity";
version = "3.7.9";
src = fetchFromGitHub {
owner = "audacity";
repo = "audacity";
rev = "Audacity-${finalAttrs.version}";
hash = "sha256-q/5LPL76GPEFGRxTZcuxmLuq15fwbw2Mak/q2RObghk=";
};
patches = [
# Introduced by https://github.com/Tencent/rapidjson/commit/b1c0c2843fcb2aca9ecc650fc035c57ffc13697c#diff-2f1bcf2729ff7c408adb0c2cc2cfa01602bd5646b05b3e4bc7e46b606035d249R21
./rapidjson.patch
];
postPatch = ''
mkdir src/private
substituteInPlace scripts/build/macOS/fix_bundle.py \
--replace-fail "path.startswith('/usr/lib/')" "path.startswith('/usr/lib/') or path.startswith('${builtins.storeDir}')"
''
+ lib.optionalString stdenv.hostPlatform.isLinux ''
substituteInPlace libraries/lib-files/FileNames.cpp \
--replace-fail /usr/include/linux/magic.h ${linuxHeaders}/include/linux/magic.h
'';
nativeBuildInputs = [
cmake
gettext
pkg-config
python3
makeWrapper
wrapGAppsHook3
wxwidgets_3_2
]
++ lib.optionals stdenv.hostPlatform.isLinux [
linuxHeaders
];
buildInputs = [
expat
ffmpeg
file
flac
gtk3
lame
libid3tag
libjack2
libmad
libopus
libsbsms_2_3_0
libsndfile
libvorbis
lilv
lv2
mpg123
opusfile
portmidi
rapidjson
serd
sord
soundtouch
soxr
sqlite
sratom
suil
twolame
portaudio
wavpack
wxwidgets_3_2
]
++ lib.optionals stdenv.hostPlatform.isLinux [
alsa-lib # for portaudio
at-spi2-core
dbus
libepoxy
libxdmcp
libxtst
libpthread-stubs
libxkbcommon
libselinux
libsepol
libuuid
util-linux
]
++ lib.optionals stdenv.hostPlatform.isDarwin [
libpng
libjpeg
];
cmakeFlags = [
"-DAUDACITY_BUILD_LEVEL=2"
"-DAUDACITY_REV_LONG=nixpkgs"
"-DAUDACITY_REV_TIME=nixpkgs"
"-DDISABLE_DYNAMIC_LOADING_FFMPEG=ON"
"-Daudacity_conan_enabled=Off"
"-Daudacity_use_ffmpeg=loaded"
"-Daudacity_has_vst3=Off"
"-Daudacity_has_crashreports=Off"
# RPATH of binary /nix/store/.../bin/... contains a forbidden reference to /build/
"-DCMAKE_SKIP_BUILD_RPATH=ON"
# Fix duplicate store paths
"-DCMAKE_INSTALL_LIBDIR=lib"
];
# [ 57%] Generating LightThemeAsCeeCode.h...
# ../../utils/image-compiler: error while loading shared libraries:
# lib-theme.so: cannot open shared object file: No such file or directory
preBuild = ''
export LD_LIBRARY_PATH=$PWD/Release/lib/audacity
'';
doCheck = false; # Test fails
dontWrapGApps = true;
strictDeps = true;
__structuredAttrs = true;
# Replace audacity's wrapper, to:
# - Put it in the right place; it shouldn't be in "$out/audacity"
# - Add the ffmpeg dynamic dependency
# - Use Xwayland by default on Wayland. See https://github.com/audacity/audacity/pull/5977
postFixup =
lib.optionalString stdenv.hostPlatform.isLinux ''
wrapProgram "$out/bin/audacity" \
"''${gappsWrapperArgs[@]}" \
--prefix LD_LIBRARY_PATH : "$out/lib/audacity":${lib.makeLibraryPath [ ffmpeg ]} \
--suffix AUDACITY_MODULES_PATH : "$out/lib/audacity/modules" \
--suffix AUDACITY_PATH : "$out/share/audacity" \
--set-default GDK_BACKEND x11
''
+ lib.optionalString stdenv.hostPlatform.isDarwin ''
mkdir -p $out/{Applications,bin}
mv $out/Audacity.app $out/Applications/
makeWrapper $out/Applications/Audacity.app/Contents/MacOS/Audacity $out/bin/audacity
'';
meta = {
description = "Sound editor with graphical UI";
mainProgram = "audacity";
homepage = "https://www.audacityteam.org";
changelog = "https://github.com/audacity/audacity/releases";
license = with lib.licenses; [
gpl2Plus
# Must be GPL3 when building with "technologies that require it,
# such as the VST3 audio plugin interface".
# https://github.com/audacity/audacity/discussions/2142.
gpl3
# Documentation.
cc-by-30
];
maintainers = with lib.maintainers; [
veprbl
wegank
];
platforms = lib.platforms.unix;
};
})

View File

@@ -16,7 +16,7 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "bookorbit";
version = "2.8.1";
version = "2.9.0";
__structuredAttrs = true;
strictDeps = true;
@@ -24,7 +24,7 @@ stdenv.mkDerivation (finalAttrs: {
owner = "bookorbit";
repo = "bookorbit";
tag = "v${finalAttrs.version}";
hash = "sha256-Un30txjsp+sdEPX9DTQ4f0ht7klDhbDptizUzQMP5AA=";
hash = "sha256-Dj/H7HWzxscl+uSMGDRgAwLeHDzcZEOM0RsiWrPJjUs=";
};
pnpmWorkspaces = [
@@ -41,7 +41,7 @@ stdenv.mkDerivation (finalAttrs: {
;
inherit pnpm;
fetcherVersion = 4;
hash = "sha256-y/cdgAjv8ZWlF4IikKb0pPqrlakMfTo9nY1Bb9AnxlM=";
hash = "sha256-NVI9R6n9HIE2VufTcqe4cjZbTK30R/i6dZy39TGH8qs=";
};
nativeBuildInputs = [

View File

@@ -4,6 +4,7 @@
fetchFromGitHub,
google-fonts,
nodejs,
stdenv,
nix-update-script,
nixosTests,
}:
@@ -67,6 +68,12 @@ buildNpmPackage (finalAttrs: {
runHook postInstall
'';
postInstall = ''
# sharp picks its native binary by libc (detect-libc), so the copies built
# for the other libc can never be loaded.
rm -rf $out/node_modules/@img/*-${if stdenv.hostPlatform.isMusl then "linux" else "linuxmusl"}-*
'';
__structuredAttrs = true;
passthru = {

View File

@@ -8,7 +8,7 @@
rustPlatform.buildRustPackage {
pname = "buzz-cli";
version = "0.1.0-unstable-2026-08-27";
version = "0.1.0-unstable-2026-09-02";
__structuredAttrs = true;
__darwinAllowLocalNetworking = true;
strictDeps = true;
@@ -16,11 +16,11 @@ rustPlatform.buildRustPackage {
src = fetchFromGitHub {
owner = "block";
repo = "buzz";
rev = "0808ab485c39c3c12ef02af2188c65a5145eb99d";
hash = "sha256-+vYRX6yZmyWxtpcaQj62ujmcG2uwo3fdaX5Oo6Q1jEE=";
rev = "47d068e2109d077414cbf2f4f1c927f6d051037a";
hash = "sha256-sLIyStOy330KzzVF9QnIn27loT5QXCRz0U4NN9bxU40=";
};
cargoHash = "sha256-y067FJWvsJAe6mvtnLPSW1YK0/gcBrKuZX45OCO8/2U=";
cargoHash = "sha256-q8FUmTHnPfy/Ub+TNs3UK3exOoX1GdZGwHkH5pDteKE=";
cargoBuildFlags = [ "--package=buzz-cli" ];
cargoTestFlags = [ "--package=buzz-cli" ];

View File

@@ -9,7 +9,7 @@
stdenv.mkDerivation (finalAttrs: {
pname = "bzip3";
version = "1.5.3";
version = "1.5.4";
outputs = [
"bin"
@@ -21,7 +21,7 @@ stdenv.mkDerivation (finalAttrs: {
owner = "iczelia";
repo = "bzip3";
tag = finalAttrs.version;
hash = "sha256-SOouMUctxsAJdkt84rJBaCbK23GKmXRH9nVgGdDodsk=";
hash = "sha256-uLL87HbohLNTm+Pq96iNlN+zqjG/bxCV7BJk1H7DvgY=";
};
postPatch = ''

View File

@@ -9,16 +9,16 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "cargo-typify";
version = "0.6.2";
version = "0.7.0";
src = fetchFromGitHub {
owner = "oxidecomputer";
repo = "typify";
tag = "v${finalAttrs.version}";
hash = "sha256-Ym3xPMn36+Y8dnImmuegjwrARPzozhwI+qhDCXmFsHg=";
hash = "sha256-1JnNNapIg0uholQkgnqU+KQ1q1SCF0MJmrO8XybxBzw=";
};
cargoHash = "sha256-3hh4M5cqwLDHcHI+YGKXQOeTXGcVTec+xk+mZcVp0IU=";
cargoHash = "sha256-tH6Unl9mFUmpIiDoHp7ZUwaKAK8QEWGf2ldKbcyBET0=";
nativeBuildInputs = [
rustfmt
@@ -46,6 +46,8 @@ rustPlatform.buildRustPackage (finalAttrs: {
--set RUSTFMT "${lib.getExe rustfmt}"
'';
passthru.updateScript = gitUpdater { rev-prefix = "v"; };
meta = {
description = "JSON Schema to Rust type converter";
homepage = "https://github.com/oxidecomputer/typify";

View File

@@ -8,7 +8,6 @@
wrapGAppsHook3,
gtkmm3,
gtksourceview4,
gtksourceviewmm,
gspell,
libxmlxx,
sqlite,
@@ -40,7 +39,6 @@ stdenv.mkDerivation (finalAttrs: {
buildInputs = [
gtkmm3
gtksourceview4
gtksourceviewmm
gspell
libxmlxx
sqlite

View File

@@ -0,0 +1,55 @@
{
lib,
buildGoModule,
fetchFromGitHub,
nix-update-script,
versionCheckHook,
}:
buildGoModule (finalAttrs: {
pname = "cpak";
version = "2.12.7";
src = fetchFromGitHub {
owner = "Containerpak";
repo = "cpak";
tag = "v${finalAttrs.version}";
hash = "sha256-bISKyH1+Yr1EBzZYIK0xpe0jmBiWtCnByz4Ng01QJCI=";
};
vendorHash = "sha256-cgqb2AY06Ru+JJIK7vyaLSPyjJqiLvNytvSQCgDOASc=";
subPackages = [
"."
"cmd/cpak-storaged"
"cmd/cpak-sign"
];
tags = [ "cpak_ui_builtin" ];
__structuredAttrs = true;
env.CGO_ENABLED = 0;
ldflags = [
"-s"
"-w"
"-X main.version=${finalAttrs.version}"
"-X main.selfUpdateMode=disabled"
];
nativeInstallCheckInputs = [ versionCheckHook ];
doInstallCheck = true;
passthru.updateScript = nix-update-script { };
meta = {
description = "Decentralized, portable, low-overhead containerized application format for Linux";
homepage = "https://cpak.it";
changelog = "https://github.com/Containerpak/cpak/releases/tag/v${finalAttrs.version}";
license = lib.licenses.lgpl21Only;
maintainers = with lib.maintainers; [ rachalaraj ];
mainProgram = "cpak";
platforms = lib.platforms.linux;
};
})

View File

@@ -0,0 +1,73 @@
{
lib,
stdenvNoCC,
fetchurl,
unzip,
writeShellScript,
curl,
gnugrep,
gnused,
coreutils,
common-updater-scripts,
}:
stdenvNoCC.mkDerivation (finalAttrs: {
pname = "crossover";
version = "26.3.0";
__structuredAttrs = true;
strictDeps = true;
src = fetchurl {
url = "https://media.codeweavers.com/pub/crossover/cxmac/demo/crossover-${finalAttrs.version}.zip";
hash = "sha256-hojghIxOX3nxzDUctS0yRH2gDGwAz9O0uy0WTURYmiY=";
};
sourceRoot = ".";
nativeBuildInputs = [ unzip ];
installPhase = ''
runHook preInstall
mkdir -p $out/Applications
cp -R CrossOver.app $out/Applications/
runHook postInstall
'';
passthru.updateScript = writeShellScript "crossover-update-script" ''
set -euo pipefail
export PATH="${
lib.makeBinPath [
curl
gnugrep
gnused
coreutils
common-updater-scripts
]
}"
new_version=$(curl -s "https://www.codeweavers.com/xml/versions/cxmac.xml" \
| grep -oE 'crossover-[0-9]+\.[0-9]+\.[0-9]+\.zip' \
| sed -E 's/crossover-(.*)\.zip/\1/' \
| sort -V \
| tail -n1)
if [[ "${finalAttrs.version}" = "$new_version" ]]; then
echo "crossover is already at the latest version $new_version."
exit 0
fi
update-source-version "crossover" "$new_version" \
--ignore-same-version
'';
meta = {
description = "Run Windows applications on macOS without a Windows license";
homepage = "https://www.codeweavers.com/crossover";
license = lib.licenses.unfree;
maintainers = [ lib.maintainers.delafthi ];
platforms = lib.platforms.darwin;
sourceProvenance = [ lib.sourceTypes.binaryNativeCode ];
};
})

View File

@@ -9,22 +9,16 @@
}:
buildGoModule (finalAttrs: {
pname = "databricks-cli";
version = "1.11.0";
version = "1.14.0";
src = fetchFromGitHub {
owner = "databricks";
repo = "cli";
rev = "v${finalAttrs.version}";
hash = "sha256-ViMRqQ9lfek1ETCW30NDmIlG5dtPDmNv4F1EeDwlk6k=";
hash = "sha256-iR7fvhLHUVUBpVC2TlAkFcuTe0l+HJmLnmxhOYp8O7U=";
};
# Otherwise these tests fail asserting that the version is 0.0.0-dev
postPatch = ''
substituteInPlace bundle/deploy/terraform/init_test.go \
--replace-fail "cli/0.0.0-dev" "cli/${finalAttrs.version}"
'';
vendorHash = "sha256-LjU4cWFiCrmNwRFt9rAFDQhRw1fN2lLK03/z7wTr+E4=";
vendorHash = "sha256-xKv7EYwyEeuxlM+fMa+FpIygWxswQSkuwGzQYWHHvy0=";
subPackages = [ "." ];

View File

@@ -0,0 +1,55 @@
{
lib,
stdenv,
fetchgit,
wafHook,
python3,
gitMinimal,
pkg-config,
openssl,
boost,
}:
stdenv.mkDerivation (finalAttrs: {
pname = "asdcplib";
version = "1.0.11";
src = fetchgit {
url = "https://git.carlh.net/git/asdcplib";
tag = "v${finalAttrs.version}";
hash = "sha256-VkXDiNYPXU4eOgOfhZB3RMoSp1ujL2jMdAYwjdyIei0=";
};
# for some reason the version is not set properly upstream
postPatch = ''
substituteInPlace wscript \
--replace-fail \
"VERSION = open('VERSION').read().strip()" \
"VERSION = '${finalAttrs.version}'"
'';
nativeBuildInputs = [
wafHook
python3
gitMinimal
pkg-config
];
buildInputs = [
openssl
boost
];
__structuredAttrs = true;
strictDeps = true;
meta = {
description = "asdcplib library for low-level DCP handling";
homepage = "https://git.carlh.net/cgit/asdcplib";
downloadPage = "https://git.carlh.net/cgit/asdcplib";
license = lib.licenses.bsd3;
platforms = lib.platforms.linux;
maintainers = with lib.maintainers; [ logn ];
};
})

View File

@@ -0,0 +1,12 @@
diff --git a/src/wscript b/src/wscript
index cbea215..62b0a06 100644
--- a/src/wscript
+++ b/src/wscript
@@ -6,6 +6,7 @@ def build(bld):
obj.source = 'leqm_nrt.cc'
if bld.env.WITH_LIBSNDFILE:
+ obj.uselib = 'SNDFILE'
obj = bld(features='cxx cxxprogram')
obj.name = 'leqm_nrt_cli'
obj.target = 'leqm_nrt'

View File

@@ -0,0 +1,48 @@
{
stdenv,
lib,
fetchgit,
wafHook,
python3,
gitMinimal,
pkg-config,
libsndfile,
}:
stdenv.mkDerivation (finalAttrs: {
pname = "leqm-nrt";
version = "0.0.2";
src = fetchgit {
url = "https://git.carlh.net/git/leqm-nrt";
tag = "v${finalAttrs.version}";
hash = "sha256-rynqxvh2FT03Fs5XOV5ZBLzB6lJlop793cMv0FB3s1g=";
};
patches = [
./leqm-nrt-libsndfile-linking.patch
];
nativeBuildInputs = [
wafHook
python3
gitMinimal
pkg-config
];
buildInputs = [
libsndfile
];
__structuredAttrs = true;
strictDeps = true;
meta = {
description = "a non-real-time implementation of Leq(M) measurement";
homepage = "https://git.carlh.net/cgit/leqm-nrt";
downloadPage = "https://git.carlh.net/cgit/leqm-nrt";
license = lib.licenses.gpl3Plus;
platforms = lib.platforms.linux;
maintainers = with lib.maintainers; [ logn ];
};
})

Some files were not shown because too many files have changed in this diff Show More