From b2d978f51eed07785b804593e3b28184dc56bef4 Mon Sep 17 00:00:00 2001 From: Tom Oostveen Date: Sun, 5 Jul 2026 17:31:35 +0200 Subject: [PATCH 01/48] nixos/readeck: copy config file to mutable place To prevent this failure: ``` ERROR: open /nix/store/...-readeck.toml: read-only file system ``` (cherry picked from commit af11c3d0c8cf6feca5003a595792163c60fd4446) --- nixos/modules/services/web-apps/readeck.nix | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/nixos/modules/services/web-apps/readeck.nix b/nixos/modules/services/web-apps/readeck.nix index 4c2c921b5a7c..45e1be487a08 100644 --- a/nixos/modules/services/web-apps/readeck.nix +++ b/nixos/modules/services/web-apps/readeck.nix @@ -66,7 +66,9 @@ in WorkingDirectory = "/var/lib/readeck"; EnvironmentFile = lib.optional (cfg.environmentFile != null) cfg.environmentFile; DynamicUser = true; - ExecStart = "${lib.getExe cfg.package} serve -config ${configFile}"; + # readeck opens config.toml as writable in case it needs to add a secret key... + ExecStartPre = "${lib.getExe' pkgs.coreutils "cp"} --no-preserve=all ${configFile} config.toml"; + ExecStart = "${lib.getExe cfg.package} serve -config config.toml"; ProtectSystem = "full"; SystemCallArchitectures = "native"; MemoryDenyWriteExecute = true; From 09397e19e96284faa883aec2d649d40fc57babe1 Mon Sep 17 00:00:00 2001 From: 4evy Date: Thu, 27 Aug 2026 21:10:00 +0300 Subject: [PATCH 02/48] hister: init at 0.17.0 (cherry picked from commit 3792e2049d37edaaf11d4e1cc3ea9e7273f9ba48) --- pkgs/by-name/hi/hister/package.nix | 101 +++++++++++++++++++++++++++++ 1 file changed, 101 insertions(+) create mode 100644 pkgs/by-name/hi/hister/package.nix diff --git a/pkgs/by-name/hi/hister/package.nix b/pkgs/by-name/hi/hister/package.nix new file mode 100644 index 000000000000..c9da331f7313 --- /dev/null +++ b/pkgs/by-name/hi/hister/package.nix @@ -0,0 +1,101 @@ +{ + lib, + buildGoModule, + buildNpmPackage, + fetchFromGitHub, + nodejs_22, + sqlite, + yt-dlp-light, + makeBinaryWrapper, + nix-update-script, + pkg-config, + versionCheckHook, +}: +buildGoModule (finalAttrs: { + pname = "hister"; + version = "0.17.0"; + + src = fetchFromGitHub { + owner = "asciimoo"; + repo = "hister"; + tag = "v${finalAttrs.version}"; + hash = "sha256-UIKQVs2hbzalDeRL1ILUgfMQnues5IFrzWn9Eg5sm30="; + }; + + __structuredAttrs = true; + strictDeps = true; + + vendorHash = "sha256-ozTULKnUrzBy+tK/eSq7exPVjXp43mSzg4EOWG+r1No="; + proxyVendor = true; + + nativeBuildInputs = [ + pkg-config + makeBinaryWrapper + ]; + buildInputs = [ sqlite ]; + + tags = [ "libsqlite3" ]; + + preBuild = '' + mkdir -p server/static/app + cp -r ${finalAttrs.passthru.frontend}/* server/static/app/ + ''; + + ldflags = [ + "-s" + ]; + + subPackages = [ "." ]; + + postInstall = '' + wrapProgram $out/bin/hister \ + --prefix PATH : ${lib.makeBinPath [ yt-dlp-light ]} + ''; + + nativeInstallCheckInputs = [ versionCheckHook ]; + doInstallCheck = true; + + passthru = { + frontend = (buildNpmPackage.override { nodejs = nodejs_22; }) { + pname = "${finalAttrs.pname}-frontend"; + inherit (finalAttrs) version src; + + strictDeps = true; + + npmWorkspace = "webui/app"; + npmDepsFetcherVersion = 2; + npmDepsHash = "sha256-ueGtZYMrmQeYsJXmA5RRV5GHCEH5Ui+6PDiQ/Nd1quM="; + + # vite 8's rolldown pipeline does a dns.lookup('localhost') during `vite build` + # which fails in darwin's relaxed sandbox without loopback access + __darwinAllowLocalNetworking = true; + + preBuild = '' + patchShebangs webui + ''; + + installPhase = '' + runHook preInstall + mkdir -p "$out" + cp -r webui/app/build/* "$out/" + runHook postInstall + ''; + }; + updateScript = nix-update-script { + extraArgs = [ + "--subpackage" + "frontend" + ]; + }; + }; + + meta = { + changelog = "https://github.com/asciimoo/hister/releases/tag/v${finalAttrs.version}"; + description = "Web history on steroids - blazing fast, content-based search for visited websites"; + homepage = "https://github.com/asciimoo/hister"; + license = lib.licenses.agpl3Plus; + mainProgram = "hister"; + maintainers = with lib.maintainers; [ _4evy ]; + platforms = lib.platforms.unix; + }; +}) From c262786b4342920fe8fc0dc52779210ca5ef46b7 Mon Sep 17 00:00:00 2001 From: 4evy Date: Thu, 27 Aug 2026 21:10:00 +0300 Subject: [PATCH 03/48] nixos/hister: init (cherry picked from commit dcb6fc8d1213d5a91e07c956b41f9240981d5a42) --- nixos/modules/module-list.nix | 1 + nixos/modules/services/web-apps/hister.nix | 224 +++++++++++++++++++++ 2 files changed, 225 insertions(+) create mode 100644 nixos/modules/services/web-apps/hister.nix diff --git a/nixos/modules/module-list.nix b/nixos/modules/module-list.nix index 4a2b951d915e..d5d571570a0e 100644 --- a/nixos/modules/module-list.nix +++ b/nixos/modules/module-list.nix @@ -1679,6 +1679,7 @@ ./services/web-apps/haven.nix ./services/web-apps/healthchecks.nix ./services/web-apps/hedgedoc.nix + ./services/web-apps/hister.nix ./services/web-apps/hledger-web.nix ./services/web-apps/homebox.nix ./services/web-apps/homer.nix diff --git a/nixos/modules/services/web-apps/hister.nix b/nixos/modules/services/web-apps/hister.nix new file mode 100644 index 000000000000..8b0ecab66a94 --- /dev/null +++ b/nixos/modules/services/web-apps/hister.nix @@ -0,0 +1,224 @@ +{ + config, + lib, + pkgs, + ... +}: + +let + cfg = config.services.hister; + + yamlFormat = pkgs.formats.yaml { }; + + dataDir = if cfg.dataDir != null then cfg.dataDir else "/var/lib/hister"; + generatedConfig = yamlFormat.generate "hister-config.yml" cfg.settings; + hasConfig = cfg.configPath != null || cfg.settings != { }; + runtimeConfigSource = if cfg.settings != { } then generatedConfig else cfg.configPath; + runtimeConfig = "/run/hister/config.yml"; + + histerEnv = + lib.optionalAttrs (cfg.port != null) { + HISTER_PORT = toString cfg.port; + } + // lib.optionalAttrs hasConfig { + HISTER_CONFIG = runtimeConfig; + } + // { + HISTER_DATA_DIR = dataDir; + }; + + privilegedPort = cfg.port != null && cfg.port < 1024; +in +{ + meta.maintainers = with lib.maintainers; [ _4evy ]; + + options.services.hister = { + enable = lib.mkEnableOption "Hister, a web history service with content-based search"; + + package = lib.mkPackageOption pkgs "hister" { }; + + user = lib.mkOption { + type = lib.types.str; + default = "hister"; + description = "User account under which Hister runs."; + }; + + group = lib.mkOption { + type = lib.types.str; + default = "hister"; + description = "Group under which Hister runs."; + }; + + dataDir = lib.mkOption { + type = lib.types.nullOr lib.types.path; + default = null; + example = "/var/lib/hister"; + description = '' + Directory where Hister stores its data. When `null` (the default), the + service is isolated under `/var/lib/hister` via systemd's + `StateDirectory=`. When set to an explicit path, that path is created + with `systemd-tmpfiles` and granted via `ReadWritePaths=` instead. + ''; + }; + + port = lib.mkOption { + type = lib.types.nullOr lib.types.port; + default = null; + example = 4433; + description = '' + Port on which Hister listens. When set, this overrides the port in + `server.address` from the configuration file via the `HISTER_PORT` + environment variable. + ''; + }; + + openFirewall = lib.mkOption { + type = lib.types.bool; + default = false; + description = '' + Whether to open {option}`services.hister.port` in the firewall. Has no + effect if `port` is `null`. + ''; + }; + + configPath = lib.mkOption { + type = lib.types.nullOr lib.types.path; + default = null; + example = "/etc/hister/config.yml"; + description = '' + Path to an existing Hister configuration file mounted read-only into + the service runtime directory and passed via `HISTER_CONFIG`. Mutually + exclusive with {option}`services.hister.settings`. + ''; + }; + + environmentFile = lib.mkOption { + type = lib.types.nullOr lib.types.path; + default = null; + example = "/run/secrets/hister.env"; + description = '' + Path to an environment file (read at service start) used to inject + secrets such as `HISTER__APP__ACCESS_TOKEN` without placing them in the + world-readable Nix store. + ''; + }; + + settings = lib.mkOption { + type = yamlFormat.type; + default = { }; + description = '' + Hister configuration rendered to YAML and passed via `HISTER_CONFIG`. + Accepts any structure the server accepts: see the `app`, `server`, + `indexer`, `crawler`, `hotkeys`, `extractors`, `semantic_search`, and + `sensitive_content_patterns` blocks documented upstream. + ''; + example = lib.literalExpression '' + { + app = { + search_url = "https://google.com/search?q={query}"; + log_level = "info"; + }; + server = { + address = "127.0.0.1:4433"; + database = "db.sqlite3"; + }; + hotkeys.web = { + "/" = "focus_search_input"; + "enter" = "open_result"; + }; + } + ''; + }; + }; + + config = lib.mkIf cfg.enable { + assertions = [ + { + assertion = !(cfg.configPath != null && cfg.settings != { }); + message = "Only one of services.hister.configPath and services.hister.settings can be set"; + } + ]; + + environment.systemPackages = [ cfg.package ]; + + users.users = lib.mkIf (cfg.user == "hister") { + hister = { + description = "Hister web history service"; + group = cfg.group; + isSystemUser = true; + }; + }; + + users.groups = lib.mkIf (cfg.group == "hister") { + hister = { }; + }; + + systemd.tmpfiles.settings."10-hister"."${dataDir}".d = lib.mkIf (cfg.dataDir != null) { + user = cfg.user; + group = cfg.group; + mode = "0750"; + }; + + systemd.services.hister = { + description = "Hister web history service"; + after = [ + "network.target" + "systemd-tmpfiles-setup.service" + "systemd-tmpfiles-resetup.service" + ]; + wantedBy = [ "multi-user.target" ]; + + environment = histerEnv; + + serviceConfig = { + ExecStart = "${lib.getExe cfg.package} listen"; + Restart = "on-failure"; + User = cfg.user; + Group = cfg.group; + RuntimeDirectory = lib.mkIf hasConfig "hister"; + RuntimeDirectoryMode = lib.mkIf hasConfig "0750"; + BindReadOnlyPaths = lib.mkIf hasConfig [ "${runtimeConfigSource}:${runtimeConfig}" ]; + StateDirectory = lib.mkIf (cfg.dataDir == null) "hister"; + StateDirectoryMode = lib.mkIf (cfg.dataDir == null) "0750"; + ReadWritePaths = lib.mkIf (cfg.dataDir != null) [ cfg.dataDir ]; + EnvironmentFile = lib.mkIf (cfg.environmentFile != null) cfg.environmentFile; + + AmbientCapabilities = lib.mkIf privilegedPort [ "CAP_NET_BIND_SERVICE" ]; + CapabilityBoundingSet = if privilegedPort then [ "CAP_NET_BIND_SERVICE" ] else [ "" ]; + + NoNewPrivileges = true; + ProtectSystem = "strict"; + ProtectHome = true; + PrivateTmp = true; + PrivateDevices = true; + ProtectKernelTunables = true; + ProtectKernelModules = true; + ProtectKernelLogs = true; + ProtectControlGroups = true; + ProtectClock = true; + ProtectHostname = true; + ProtectProc = "invisible"; + ProcSubset = "pid"; + LockPersonality = true; + RestrictNamespaces = true; + RestrictRealtime = true; + RestrictSUIDSGID = true; + RemoveIPC = true; + RestrictAddressFamilies = [ + "AF_INET" + "AF_INET6" + "AF_UNIX" + ]; + SystemCallArchitectures = "native"; + SystemCallFilter = [ + "@system-service" + "~@privileged" + ]; + MemoryDenyWriteExecute = true; + UMask = "0077"; + }; + }; + + networking.firewall.allowedTCPPorts = lib.mkIf (cfg.openFirewall && cfg.port != null) [ cfg.port ]; + }; +} From 7b127741465404d044245382fc4c9ac2d871b7b6 Mon Sep 17 00:00:00 2001 From: 4evy Date: Thu, 27 Aug 2026 21:10:00 +0300 Subject: [PATCH 04/48] nixosTests.hister: init (cherry picked from commit f5087b90fbe241ae40e35f9dd4c1f20e1bba215f) --- nixos/tests/all-tests.nix | 1 + nixos/tests/hister.nix | 146 +++++++++++++++++++++++++++++ pkgs/by-name/hi/hister/package.nix | 2 + 3 files changed, 149 insertions(+) create mode 100644 nixos/tests/hister.nix diff --git a/nixos/tests/all-tests.nix b/nixos/tests/all-tests.nix index 09eb2c1af7bc..c36088fe2d28 100644 --- a/nixos/tests/all-tests.nix +++ b/nixos/tests/all-tests.nix @@ -763,6 +763,7 @@ in hibernate-systemd-stage-1 = handleTestOn [ "x86_64-linux" ] ./hibernate.nix { systemdStage1 = true; }; + hister = runTest ./hister.nix; hitch = handleTest ./hitch { }; hledger-web = runTest ./hledger-web.nix; hockeypuck = runTest ./hockeypuck.nix; diff --git a/nixos/tests/hister.nix b/nixos/tests/hister.nix new file mode 100644 index 000000000000..9958581f180a --- /dev/null +++ b/nixos/tests/hister.nix @@ -0,0 +1,146 @@ +{ lib, pkgs, ... }: +let + configPathConfig = pkgs.writeText "hister-config.yml" '' + app: + title: NixOS Hister Config Path + search_url: https://config.example.invalid/?q={query} + hotkeys: + web: + alt+c: open_query_in_search_engine + ''; +in +{ + name = "hister"; + + meta = { + maintainers = with lib.maintainers; [ _4evy ]; + }; + + nodes.machine = { + environment.systemPackages = [ pkgs.jq ]; + + systemd.tmpfiles.settings."10-hister-env"."/run/hister.env"."f" = { + mode = "0600"; + user = "root"; + group = "root"; + argument = "HISTER__APP__ACCESS_TOKEN=test-token"; + }; + + specialisation = { + inline_settings.configuration.services.hister = { + enable = true; + port = 4433; + environmentFile = "/run/hister.env"; + settings = { + app = { + log_level = "debug"; + title = "NixOS Hister"; + search_url = "https://search.example.invalid/?q={query}"; + open_results_on_new_tab = true; + }; + hotkeys.web."alt+n" = "open_query_in_search_engine"; + }; + }; + + config_file.configuration.services.hister = { + enable = true; + port = 4434; + configPath = configPathConfig; + }; + + custom_data_dir.configuration.services.hister = { + enable = true; + port = 4435; + dataDir = "/srv/hister-data"; + settings.app.title = "NixOS Hister Custom Data"; + }; + }; + }; + + testScript = + { nodes, ... }: + let + switchTo = + name: + "${nodes.machine.system.build.toplevel}/specialisation/${name}/bin/switch-to-configuration test"; + in + '' + start_all() + + with subtest("inline settings"): + machine.succeed("${switchTo "inline_settings"}") + machine.systemctl("restart hister.service") + machine.wait_for_unit("hister.service") + machine.wait_for_open_port(4433) + machine.succeed("curl -fsS http://localhost:4433/ | grep -F 'Hister'") + machine.succeed("test $(stat -c %a /var/lib/hister) = 750") + machine.succeed("test $(stat -c %a /run/hister) = 750") + machine.succeed("test -s /run/hister/tui.yaml") + machine.succeed("test -s /var/lib/hister/db.sqlite3") + machine.succeed("test -s /var/lib/hister/.secret_key") + machine.succeed("test -s /var/lib/hister/rules.json") + machine.succeed( + "curl -fsS http://localhost:4433/api/config" + + " | jq -e " + + "'" + + '.baseUrl == "http://127.0.0.1:4433"' + + ' and .title == "NixOS Hister"' + + ' and .searchUrl == "https://search.example.invalid/?q={query}"' + + ' and .openResultsOnNewTab == true' + + ' and .hotkeys."alt+n" == "open_query_in_search_engine"' + + ' and .authMode == "token"' + + "'" + ) + machine.fail("journalctl -u hister.service | grep -F 'Failed to create tui.yaml'") + + with subtest("configPath"): + machine.succeed("${switchTo "config_file"}") + machine.systemctl("restart hister.service") + machine.wait_for_unit("hister.service") + machine.wait_for_open_port(4434) + machine.succeed("curl -fsS http://localhost:4434/ >/dev/null") + machine.succeed("test $(stat -c %a /run/hister) = 750") + machine.succeed("test -s /run/hister/tui.yaml") + machine.succeed("test -s /var/lib/hister/db.sqlite3") + machine.succeed("test -s /var/lib/hister/.secret_key") + machine.succeed("test -s /var/lib/hister/rules.json") + machine.succeed( + "curl -fsS http://localhost:4434/api/config" + + " | jq -e " + + "'" + + '.baseUrl == "http://127.0.0.1:4434"' + + ' and .title == "NixOS Hister Config Path"' + + ' and .searchUrl == "https://config.example.invalid/?q={query}"' + + ' and .hotkeys."alt+c" == "open_query_in_search_engine"' + + ' and .authMode == "none"' + + "'" + ) + machine.fail("journalctl -u hister.service | grep -F 'Failed to create tui.yaml'") + + with subtest("custom dataDir"): + machine.systemctl("stop hister.service") + machine.succeed("rm -rf /var/lib/hister") + machine.succeed("${switchTo "custom_data_dir"}") + machine.systemctl("restart hister.service") + machine.wait_for_unit("hister.service") + machine.wait_for_open_port(4435) + machine.succeed("curl -fsS http://localhost:4435/ >/dev/null") + machine.succeed("test $(stat -c %U:%G:%a /srv/hister-data) = hister:hister:750") + machine.succeed("test $(stat -c %a /run/hister) = 750") + machine.succeed("test -s /run/hister/tui.yaml") + machine.succeed("test -s /srv/hister-data/db.sqlite3") + machine.succeed("test -s /srv/hister-data/.secret_key") + machine.succeed("test -s /srv/hister-data/rules.json") + machine.succeed("test ! -e /var/lib/hister") + machine.succeed( + "curl -fsS http://localhost:4435/api/config" + + " | jq -e " + + "'" + + '.baseUrl == "http://127.0.0.1:4435"' + + ' and .title == "NixOS Hister Custom Data"' + + ' and .authMode == "none"' + + "'" + ) + machine.fail("journalctl -u hister.service | grep -F 'Failed to create tui.yaml'") + ''; +} diff --git a/pkgs/by-name/hi/hister/package.nix b/pkgs/by-name/hi/hister/package.nix index c9da331f7313..78d213c38f54 100644 --- a/pkgs/by-name/hi/hister/package.nix +++ b/pkgs/by-name/hi/hister/package.nix @@ -10,6 +10,7 @@ nix-update-script, pkg-config, versionCheckHook, + nixosTests, }: buildGoModule (finalAttrs: { pname = "hister"; @@ -87,6 +88,7 @@ buildGoModule (finalAttrs: { "frontend" ]; }; + tests = { inherit (nixosTests) hister; }; }; meta = { From 54b05d19486bad21bb8fe1a9029b9918590b2d3f Mon Sep 17 00:00:00 2001 From: Vincenzo Mantova <1962985+xworld21@users.noreply.github.com> Date: Thu, 27 Aug 2026 19:30:45 +0100 Subject: [PATCH 05/48] texlive.bin.pygmentex: fix typo in alias (cherry picked from commit 1c74733467142e147ea0649cae6145d965508c55) --- pkgs/tools/typesetting/tex/texlive/default.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/tools/typesetting/tex/texlive/default.nix b/pkgs/tools/typesetting/tex/texlive/default.nix index 379292358aae..113b78b27de5 100644 --- a/pkgs/tools/typesetting/tex/texlive/default.nix +++ b/pkgs/tools/typesetting/tex/texlive/default.nix @@ -670,7 +670,7 @@ allPkgLists // { # for backward compatibility latexindent = texlive.pkgs.latexindent; - pygmentex = texlive.pkgs.pigmentex; + pygmentex = texlive.pkgs.pygmentex; }; combine = From 247113f6bf775012707de3fc1b2a88b33d68e058 Mon Sep 17 00:00:00 2001 From: Tom Herbers Date: Fri, 28 Aug 2026 01:04:24 +0200 Subject: [PATCH 06/48] incus: 7.3.0 -> 7.4.0 Changelog: https://github.com/lxc/incus/releases/tag/v7.4.0 (cherry picked from commit 6d17f5d82aeac59462b0b2979a2d0fb79be3bb19) --- pkgs/by-name/in/incus/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/in/incus/package.nix b/pkgs/by-name/in/incus/package.nix index 74bcaf2fdc54..ba73221152a9 100644 --- a/pkgs/by-name/in/incus/package.nix +++ b/pkgs/by-name/in/incus/package.nix @@ -1,7 +1,7 @@ import ./generic.nix { - hash = "sha256-5XOpT+MnLcPrINHD9VAjDtXSeYAqIsejuOsOpQLMfwc="; - version = "7.3.0"; - vendorHash = "sha256-FZ9oVHrZNE/h1w/qWNTdN9/zfn9r6S3ox0W2YKf6hgI="; + hash = "sha256-9q4YrumeCb8u0O6e0Ftisb33s2dz/DOdUO3JD05W8K0="; + version = "7.4.0"; + vendorHash = "sha256-zplmn+JH/zEaQgo2xa5wzc6rCIb5tLIVlM1vYJpw9zQ="; patches = fetchpatch2: [ ]; nixUpdateExtraArgs = [ "--override-filename=pkgs/by-name/in/incus/package.nix" From 46dd8d8b99fa6f083c4c9996a904d6da7a0f2436 Mon Sep 17 00:00:00 2001 From: "Adam C. Stephens" Date: Thu, 27 Aug 2026 22:47:01 -0400 Subject: [PATCH 07/48] incus: loosen go requirement to 1.26.6 --- pkgs/by-name/in/incus/go_1_26_6.patch | 12 ++++++++++++ pkgs/by-name/in/incus/package.nix | 4 +++- 2 files changed, 15 insertions(+), 1 deletion(-) create mode 100644 pkgs/by-name/in/incus/go_1_26_6.patch diff --git a/pkgs/by-name/in/incus/go_1_26_6.patch b/pkgs/by-name/in/incus/go_1_26_6.patch new file mode 100644 index 000000000000..2544f77a1c3c --- /dev/null +++ b/pkgs/by-name/in/incus/go_1_26_6.patch @@ -0,0 +1,12 @@ +diff --git i/go.mod w/go.mod +index 0fd8ca7b49..9b7b05b433 100644 +--- i/go.mod ++++ w/go.mod +@@ -1,6 +1,6 @@ + module github.com/lxc/incus/v7 + +-go 1.26.7 ++go 1.26.6 + + require ( + github.com/FuturFusion/vsock v0.0.0-20260219213046-d78a7104f821 diff --git a/pkgs/by-name/in/incus/package.nix b/pkgs/by-name/in/incus/package.nix index ba73221152a9..ed520180bcae 100644 --- a/pkgs/by-name/in/incus/package.nix +++ b/pkgs/by-name/in/incus/package.nix @@ -2,7 +2,9 @@ import ./generic.nix { hash = "sha256-9q4YrumeCb8u0O6e0Ftisb33s2dz/DOdUO3JD05W8K0="; version = "7.4.0"; vendorHash = "sha256-zplmn+JH/zEaQgo2xa5wzc6rCIb5tLIVlM1vYJpw9zQ="; - patches = fetchpatch2: [ ]; + patches = fetchpatch2: [ + ./go_1_26_6.patch + ]; nixUpdateExtraArgs = [ "--override-filename=pkgs/by-name/in/incus/package.nix" ]; From ce295f663f6dad79db4e20e0b7a8f2551448ec09 Mon Sep 17 00:00:00 2001 From: Lin Jian Date: Thu, 27 Aug 2026 17:52:57 +0800 Subject: [PATCH 08/48] emacs30, emacs30-macport: patch CVE-2026-79992 (cherry picked from commit ece60c611b9915bd6dcb62d6b17f0f323b203ac3) --- pkgs/applications/editors/emacs/sources.nix | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/pkgs/applications/editors/emacs/sources.nix b/pkgs/applications/editors/emacs/sources.nix index 58a60c59fe36..71f888a3aa73 100644 --- a/pkgs/applications/editors/emacs/sources.nix +++ b/pkgs/applications/editors/emacs/sources.nix @@ -136,6 +136,11 @@ in url = "https://cgit.git.savannah.gnu.org/cgit/emacs.git/patch/?id=8466eb44991707d128110bdc549fad14c8e1d61e"; hash = "sha256-SyRCay2MahCJovtzBHA9M1H9hXhtD5IG3ZFSEUwaWlg="; }) + (fetchpatch { + name = "CVE-2026-79992.patch"; + url = "https://gitweb.gentoo.org/proj/emacs-patches.git/plain/emacs/30.2/05_all_tramp.patch?id=2a6292f81affedcc468c594c60808e652ae87118"; + hash = "sha256-WMjTscIuOXakuTO2H+w/Hd61V61V6ZrLh9WPMd58l+M="; + }) ]; }); @@ -166,6 +171,11 @@ in url = "https://cgit.git.savannah.gnu.org/cgit/emacs.git/patch/?id=8466eb44991707d128110bdc549fad14c8e1d61e"; hash = "sha256-SyRCay2MahCJovtzBHA9M1H9hXhtD5IG3ZFSEUwaWlg="; }) + (fetchpatch { + name = "CVE-2026-79992.patch"; + url = "https://gitweb.gentoo.org/proj/emacs-patches.git/plain/emacs/30.2/05_all_tramp.patch?id=2a6292f81affedcc468c594c60808e652ae87118"; + hash = "sha256-WMjTscIuOXakuTO2H+w/Hd61V61V6ZrLh9WPMd58l+M="; + }) ]; }); } From 175b2b3840f3b34ad44e4c6f00230643e7891e32 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sandro=20J=C3=A4ckel?= Date: Fri, 28 Aug 2026 00:57:43 +0200 Subject: [PATCH 09/48] open-webui: 0.11.0 -> 0.11.1 Changelog: https://github.com/open-webui/open-webui/releases/tag/v0.11.1 Diff: https://github.com/open-webui/open-webui/compare/v0.11.0...v0.11.1 (cherry picked from commit 137bc0fbaf6dfb49755b58150565e5db209a3382) --- pkgs/by-name/op/open-webui/package.nix | 11 +++++------ 1 file changed, 5 insertions(+), 6 deletions(-) diff --git a/pkgs/by-name/op/open-webui/package.nix b/pkgs/by-name/op/open-webui/package.nix index 464544cc10f2..eb36683b4ea4 100644 --- a/pkgs/by-name/op/open-webui/package.nix +++ b/pkgs/by-name/op/open-webui/package.nix @@ -9,13 +9,13 @@ }: let pname = "open-webui"; - version = "0.11.0"; + version = "0.11.1"; src = fetchFromGitHub { owner = "open-webui"; repo = "open-webui"; tag = "v${version}"; - hash = "sha256-SP5Huefj35PHvVzqS8R/DGSBci/hCHoueEb5RupGVqY="; + hash = "sha256-W3RzBYUtI32Ft1Nw5JM7Z/mgYELNAlFCJmrNa2Wnhu4="; }; # we need datasets_3 for SpeechT5 embeddings @@ -36,7 +36,7 @@ let url = "https://github.com/pyodide/pyodide/releases/download/${pyodideVersion}/pyodide-${pyodideVersion}.tar.bz2"; }; - npmDepsHash = "sha256-9Wa6gP0asGPCoBJh8ufpweOg4zNf7onzBu08iQwgqis="; + npmDepsHash = "sha256-5W/IMa23b0afAlw5Md8KvJYQmRen8u1dfUG2RAKDOn0="; npmFlags = [ "--force" ]; @@ -173,6 +173,7 @@ python3Packages.buildPythonApplication (finalAttrs: { pymysql pypandoc pypdf + python-docx python-dotenv python-mimeparse python-multipart @@ -225,7 +226,6 @@ python3Packages.buildPythonApplication (finalAttrs: { azure-search-documents colbert-ai elasticsearch - moto oracledb pinecone-client playwright @@ -236,8 +236,7 @@ python3Packages.buildPythonApplication (finalAttrs: { ] ++ finalAttrs.passthru.optional-dependencies.mariadb ++ finalAttrs.passthru.optional-dependencies.postgres - ++ finalAttrs.passthru.optional-dependencies.unstructured - ++ moto.optional-dependencies.s3; + ++ finalAttrs.passthru.optional-dependencies.unstructured; }; pythonImportsCheck = [ "open_webui" ]; From 4fa4df87618bb4060675f2f1ce7c52e1bc40b34b Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 27 Aug 2026 13:57:21 +0000 Subject: [PATCH 10/48] javaPackages.compiler.openjdk25: 25.0.4+7 -> 25.0.4.1+1 (cherry picked from commit 964592c656015949d352e0939d404d3885667852) --- pkgs/development/compilers/openjdk/25/source.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/compilers/openjdk/25/source.json b/pkgs/development/compilers/openjdk/25/source.json index f1c94058b6c4..0fcde8a4e852 100644 --- a/pkgs/development/compilers/openjdk/25/source.json +++ b/pkgs/development/compilers/openjdk/25/source.json @@ -1,6 +1,6 @@ { - "hash": "sha256-/42TUyZnw8LVOuUnupVFBkqsT5IIeTw9/WNQ0eCfQRQ=", + "hash": "sha256-i5PZZbIcHviwOQ5I41LDJxjbS64AOXudk1cXXFUypUo=", "owner": "openjdk", "repo": "jdk25u", - "rev": "refs/tags/jdk-25.0.4+7" + "rev": "refs/tags/jdk-25.0.4.1+1" } From ccc46ecb92661c8cc650eec737d67ed5f280d313 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 27 Aug 2026 21:41:56 +0000 Subject: [PATCH 11/48] javaPackages.compiler.openjdk17: 17.0.20+8 -> 17.0.20.1+1 (cherry picked from commit c1a64735a5ee54b2ea3a55dc84a9742cf2ba2ee3) --- pkgs/development/compilers/openjdk/17/source.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/compilers/openjdk/17/source.json b/pkgs/development/compilers/openjdk/17/source.json index aaaa49a87972..0f6489796f65 100644 --- a/pkgs/development/compilers/openjdk/17/source.json +++ b/pkgs/development/compilers/openjdk/17/source.json @@ -1,6 +1,6 @@ { - "hash": "sha256-0cmzR5KZY6q+ZhoF90HkiIqHJsEdMeLOt4bmV8ID5so=", + "hash": "sha256-6cO7tfgUwMeDXjGBiGkKk7lODgxAGub/phS54URUfSI=", "owner": "openjdk", "repo": "jdk17u", - "rev": "refs/tags/jdk-17.0.20+8" + "rev": "refs/tags/jdk-17.0.20.1+1" } From 8b54d470a81c88561e098ce7830e01c6edafd1a3 Mon Sep 17 00:00:00 2001 From: Ihar Hrachyshka Date: Mon, 17 Aug 2026 21:17:20 -0400 Subject: [PATCH 12/48] ci/github-script/check-target-branch: extract review helpers Assisted-by: Codex gpt-5.6-sol medium (cherry picked from commit d003d54dc4ce21898316e4e5a2a87b0c4d760f07) --- ci/github-script/check-target-branch.ts | 157 ++++++++++++++---------- 1 file changed, 95 insertions(+), 62 deletions(-) diff --git a/ci/github-script/check-target-branch.ts b/ci/github-script/check-target-branch.ts index 1b1f2c4e8b03..0562cd09c183 100644 --- a/ci/github-script/check-target-branch.ts +++ b/ci/github-script/check-target-branch.ts @@ -40,6 +40,89 @@ type ChangedPaths = { rebuildsByPlatform: Record } +type TargetBranchReviewFacts = { + github: InstanceType + context: typeof actionsContext + core: typeof actionsCore + dry: boolean + base: string + maxRebuildCount: number +} + +async function postMassRebuildReview(facts: TargetBranchReviewFacts) { + const { github, context, core, dry, base, maxRebuildCount } = facts + const desiredBranch = + base === 'master' ? 'staging' : `staging-${split(base).version}` + const body = [ + `The PR's base branch is set to \`${base}\`, but this PR causes ${maxRebuildCount} rebuilds.`, + 'It is therefore considered a mass rebuild.', + `Please [change the base branch](https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/proposing-changes-to-your-work-with-pull-requests/changing-the-base-branch-of-a-pull-request) to [the right base branch for your changes](https://github.com/NixOS/nixpkgs/blob/master/CONTRIBUTING.md#branch-conventions) (probably \`${desiredBranch}\`).`, + ].join('\n') + + await postReview({ + github, + context, + core, + dry, + body, + event: 'REQUEST_CHANGES', + reviewKey, + }) +} + +async function postNixosRebuildReview(facts: TargetBranchReviewFacts) { + const { github, context, core, dry, base, maxRebuildCount } = facts + let branchText: string + if (base === 'master' && maxRebuildCount >= 500) { + branchText = '(probably either `staging-nixos` or `staging`)' + } else if (base === 'master') { + branchText = '(probably `staging-nixos`)' + } else if (maxRebuildCount >= 500) { + branchText = `(probably either \`staging-nixos-${split(base).version}\` or \`staging-${split(base).version}\`)` + } else { + branchText = `(probably \`staging-nixos-${split(base).version}\`)` + } + const body = [ + `The PR's base branch is set to \`${base}\`, but this PR rebuilds all NixOS tests.`, + base === 'master' && maxRebuildCount >= 500 + ? `Since this PR also causes ${maxRebuildCount} rebuilds, it may also be considered a mass rebuild.` + : '', + `Please [change the base branch](https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/proposing-changes-to-your-work-with-pull-requests/changing-the-base-branch-of-a-pull-request) to [the right base branch for your changes](https://github.com/NixOS/nixpkgs/blob/master/CONTRIBUTING.md#branch-conventions) ${branchText}.`, + ].join('\n') + + await postReview({ + github, + context, + core, + dry, + body, + event: 'REQUEST_CHANGES', + reviewKey, + }) +} + +async function postPossibleMassRebuildReview(facts: TargetBranchReviewFacts) { + const { github, context, core, dry, base, maxRebuildCount } = facts + const stagingBranch = + base === 'master' ? 'staging' : `staging-${split(base).version}` + const body = [ + `The PR's base branch is set to \`${base}\`, and this PR causes ${maxRebuildCount} rebuilds.`, + `Please consider whether this PR causes a mass rebuild according to [our conventions](https://github.com/NixOS/nixpkgs/blob/master/CONTRIBUTING.md#branch-conventions).`, + `If it does cause a mass rebuild, please [change the base branch](https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/proposing-changes-to-your-work-with-pull-requests/changing-the-base-branch-of-a-pull-request) to [the right base branch for your changes](https://github.com/NixOS/nixpkgs/blob/master/CONTRIBUTING.md#branch-conventions) (probably \`${stagingBranch}\`).`, + `If it does not cause a mass rebuild, this message can be ignored.`, + ].join('\n') + + await postReview({ + github, + context, + core, + dry, + body, + event: 'REQUEST_CHANGES', + reviewKey, + }) +} + async function checkTargetBranch({ github, context, @@ -142,79 +225,29 @@ async function checkTargetBranch({ ].join('\n'), ) + const reviewFacts: TargetBranchReviewFacts = { + github, + context, + core, + dry, + base, + maxRebuildCount, + } + if ( maxRebuildCount >= 1000 && !isExemptHomeAssistantUpdate && !isExemptKernelUpdate ) { - const desiredBranch = - base === 'master' ? 'staging' : `staging-${split(base).version}` - const body = [ - `The PR's base branch is set to \`${base}\`, but this PR causes ${maxRebuildCount} rebuilds.`, - 'It is therefore considered a mass rebuild.', - `Please [change the base branch](https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/proposing-changes-to-your-work-with-pull-requests/changing-the-base-branch-of-a-pull-request) to [the right base branch for your changes](https://github.com/NixOS/nixpkgs/blob/master/CONTRIBUTING.md#branch-conventions) (probably \`${desiredBranch}\`).`, - ].join('\n') - - await postReview({ - github, - context, - core, - dry, - body, - event: 'REQUEST_CHANGES', - reviewKey, - }) + await postMassRebuildReview(reviewFacts) } else if (rebuildsAllTests && !isExemptKernelUpdate) { - let branchText: string - if (base === 'master' && maxRebuildCount >= 500) { - branchText = '(probably either `staging-nixos` or `staging`)' - } else if (base === 'master') { - branchText = '(probably `staging-nixos`)' - } else if (maxRebuildCount >= 500) { - branchText = `(probably either \`staging-nixos-${split(base).version}\` or \`staging-${split(base).version}\`)` - } else { - branchText = `(probably \`staging-nixos-${split(base).version}\`)` - } - const body = [ - `The PR's base branch is set to \`${base}\`, but this PR rebuilds all NixOS tests.`, - base === 'master' && maxRebuildCount >= 500 - ? `Since this PR also causes ${maxRebuildCount} rebuilds, it may also be considered a mass rebuild.` - : '', - `Please [change the base branch](https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/proposing-changes-to-your-work-with-pull-requests/changing-the-base-branch-of-a-pull-request) to [the right base branch for your changes](https://github.com/NixOS/nixpkgs/blob/master/CONTRIBUTING.md#branch-conventions) ${branchText}.`, - ].join('\n') - - await postReview({ - github, - context, - core, - dry, - body, - event: 'REQUEST_CHANGES', - reviewKey, - }) + await postNixosRebuildReview(reviewFacts) } else if ( maxRebuildCount >= 500 && !isExemptKernelUpdate && !isExemptHomeAssistantUpdate ) { - const stagingBranch = - base === 'master' ? 'staging' : `staging-${split(base).version}` - const body = [ - `The PR's base branch is set to \`${base}\`, and this PR causes ${maxRebuildCount} rebuilds.`, - `Please consider whether this PR causes a mass rebuild according to [our conventions](https://github.com/NixOS/nixpkgs/blob/master/CONTRIBUTING.md#branch-conventions).`, - `If it does cause a mass rebuild, please [change the base branch](https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/proposing-changes-to-your-work-with-pull-requests/changing-the-base-branch-of-a-pull-request) to [the right base branch for your changes](https://github.com/NixOS/nixpkgs/blob/master/CONTRIBUTING.md#branch-conventions) (probably \`${stagingBranch}\`).`, - `If it does not cause a mass rebuild, this message can be ignored.`, - ].join('\n') - - await postReview({ - github, - context, - core, - dry, - body, - event: 'REQUEST_CHANGES', - reviewKey, - }) + await postPossibleMassRebuildReview(reviewFacts) } else { core.info('checkTargetBranch: this PR is against an appropriate branch.') From b2c2639af587bf104bd6910bd84dc6d895b53ade Mon Sep 17 00:00:00 2001 From: Ihar Hrachyshka Date: Mon, 17 Aug 2026 21:35:01 -0400 Subject: [PATCH 13/48] ci/github-script/check-target-branch: extract policy decision This is in preparation to test the extracted pure function in the next commit. Assisted-by: Codex gpt-5.6-sol medium (cherry picked from commit 3d17eabf1a6a9177f78e305677d86ac4efa5c6b2) --- .../check-target-branch-policy.ts | 67 +++++++++++++++++++ ci/github-script/check-target-branch.ts | 36 +++++----- 2 files changed, 87 insertions(+), 16 deletions(-) create mode 100644 ci/github-script/check-target-branch-policy.ts diff --git a/ci/github-script/check-target-branch-policy.ts b/ci/github-script/check-target-branch-policy.ts new file mode 100644 index 000000000000..57334a74cfbd --- /dev/null +++ b/ci/github-script/check-target-branch-policy.ts @@ -0,0 +1,67 @@ +const { classify } = require('../supportedBranches.js') + +type TargetBranchPolicyFacts = { + base: string + head: string + maxRebuildCount: number + rebuildsAllTests: boolean + isExemptKernelUpdate: boolean + isExemptHomeAssistantUpdate: boolean +} + +type TargetBranchReviewDecision = + | 'mass-rebuild' + | 'nixos-rebuild' + | 'possible-mass-rebuild' + | 'skip-development-merge' + | 'dismiss' + +function getTargetBranchPolicy({ base, head }: { base: string; head: string }) { + const baseClassification = classify(base) + const headClassification = classify(head) + + return { + shouldSkipDevelopmentMerge: headClassification.type.includes('development'), + shouldCheckMassRebuild: baseClassification.type.includes('primary'), + } +} + +function decideTargetBranchReview({ + base, + head, + maxRebuildCount, + rebuildsAllTests, + isExemptKernelUpdate, + isExemptHomeAssistantUpdate, +}: TargetBranchPolicyFacts): TargetBranchReviewDecision { + const baseClassification = classify(base) + const headClassification = classify(head) + + if (headClassification.type.includes('development')) { + return 'skip-development-merge' + } + + if (!baseClassification.type.includes('primary')) { + return 'dismiss' + } + + if ( + maxRebuildCount >= 1000 && + !isExemptHomeAssistantUpdate && + !isExemptKernelUpdate + ) { + return 'mass-rebuild' + } else if (rebuildsAllTests && !isExemptKernelUpdate) { + return 'nixos-rebuild' + } else if ( + maxRebuildCount >= 500 && + !isExemptKernelUpdate && + !isExemptHomeAssistantUpdate + ) { + return 'possible-mass-rebuild' + } else { + return 'dismiss' + } +} + +module.exports = { decideTargetBranchReview, getTargetBranchPolicy } diff --git a/ci/github-script/check-target-branch.ts b/ci/github-script/check-target-branch.ts index 0562cd09c183..bede591c4613 100644 --- a/ci/github-script/check-target-branch.ts +++ b/ci/github-script/check-target-branch.ts @@ -6,9 +6,13 @@ import type { GitHub } from '@actions/github/lib/utils' // They do seem quite similar, but this needs to run after eval, // and prepare.js obviously doesn't. -const { classify, split } = require('../supportedBranches.js') +const { split } = require('../supportedBranches.js') const { readFile } = require('node:fs/promises') const { postReview, dismissReviews } = require('./reviews.js') +const { + decideTargetBranchReview, + getTargetBranchPolicy, +} = require('./check-target-branch-policy.ts') const reviewKey = 'check-target-branch' @@ -152,11 +156,11 @@ async function checkTargetBranch({ ).data const base = prInfo.base.ref const head = prInfo.head.ref - const baseClassification = classify(base) - const headClassification = classify(head) + const { shouldSkipDevelopmentMerge, shouldCheckMassRebuild } = + getTargetBranchPolicy({ base, head }) // Don't run on, e.g., staging-nixos to master merges. - if (headClassification.type.includes('development')) { + if (shouldSkipDevelopmentMerge) { core.info( `Skipping checkTargetBranch: PR is from a development branch (${head})`, ) @@ -172,7 +176,7 @@ async function checkTargetBranch({ return } // Don't run on PRs against staging branches, wip branches, haskell-updates, etc. - if (!baseClassification.type.includes('primary')) { + if (!shouldCheckMassRebuild) { core.info( `Skipping checkTargetBranch: PR is against a non-primary base branch (${base})`, ) @@ -214,6 +218,14 @@ async function checkTargetBranch({ // https://github.com/NixOS/nixpkgs/pull/483194#issuecomment-3793393218 const isExemptHomeAssistantUpdate = maxRebuildCount <= 1500 && head === 'wip-home-assistant' + const decision = decideTargetBranchReview({ + base, + head, + maxRebuildCount, + rebuildsAllTests, + isExemptKernelUpdate, + isExemptHomeAssistantUpdate, + }) core.info( [ @@ -234,19 +246,11 @@ async function checkTargetBranch({ maxRebuildCount, } - if ( - maxRebuildCount >= 1000 && - !isExemptHomeAssistantUpdate && - !isExemptKernelUpdate - ) { + if (decision === 'mass-rebuild') { await postMassRebuildReview(reviewFacts) - } else if (rebuildsAllTests && !isExemptKernelUpdate) { + } else if (decision === 'nixos-rebuild') { await postNixosRebuildReview(reviewFacts) - } else if ( - maxRebuildCount >= 500 && - !isExemptKernelUpdate && - !isExemptHomeAssistantUpdate - ) { + } else if (decision === 'possible-mass-rebuild') { await postPossibleMassRebuildReview(reviewFacts) } else { core.info('checkTargetBranch: this PR is against an appropriate branch.') From 7c2242edbc45cbc68ba7158296cd4d3751988b19 Mon Sep 17 00:00:00 2001 From: Ihar Hrachyshka Date: Thu, 20 Aug 2026 17:33:22 -0400 Subject: [PATCH 14/48] ci/github-script: add npm scripts Allows running `npm run typecheck` or `npm test`. (cherry picked from commit 198d0cd4732c71bdf6baa76cbc9f4d9701fd6926) --- .github/workflows/check.yml | 4 ++-- ci/github-script/package.json | 4 ++++ 2 files changed, 6 insertions(+), 2 deletions(-) diff --git a/.github/workflows/check.yml b/.github/workflows/check.yml index a39d972d2990..e30e2f819e44 100644 --- a/.github/workflows/check.yml +++ b/.github/workflows/check.yml @@ -159,8 +159,8 @@ jobs: run: ln -s "$PWD/trusted/ci/github-script/node_modules" untrusted/ci/github-script/node_modules working-directory: nixpkgs - - name: Type-check ci/github-script - run: tsc --build + - name: Check ci/github-script + run: npm test working-directory: nixpkgs/untrusted/ci/github-script owners: diff --git a/ci/github-script/package.json b/ci/github-script/package.json index bba0431f80e2..e495941ca4cc 100644 --- a/ci/github-script/package.json +++ b/ci/github-script/package.json @@ -1,5 +1,9 @@ { "private": true, + "scripts": { + "typecheck": "tsc --build", + "test": "npm run typecheck" + }, "//": [ "Keep `@actions/core` and `@actions/github` in sync with", "https://github.com/actions/github-script/blob/main/package.json." From bec0b0629c343fb2f880f0b201ed024cd85d4f09 Mon Sep 17 00:00:00 2001 From: Ihar Hrachyshka Date: Mon, 17 Aug 2026 21:47:02 -0400 Subject: [PATCH 15/48] ci/github-script/check-target-branch: add policy tests Tests reflect status quo. They establish baseline for later policy changes. Some test cases are obvious bugs (e.g. mass rebuild checks are skipped on staging-nixos), others may also be questionable. Assisted-by: Codex gpt-5.6-sol medium (cherry picked from commit e1aa8c4d16e92029f39c3f92998f49cdf7be95cc) --- .../check-target-branch-policy.test.ts | 203 ++++++++++++++++++ ci/github-script/package.json | 3 +- 2 files changed, 205 insertions(+), 1 deletion(-) create mode 100644 ci/github-script/check-target-branch-policy.test.ts diff --git a/ci/github-script/check-target-branch-policy.test.ts b/ci/github-script/check-target-branch-policy.test.ts new file mode 100644 index 000000000000..7329fc3f6d3a --- /dev/null +++ b/ci/github-script/check-target-branch-policy.test.ts @@ -0,0 +1,203 @@ +const assert = require('node:assert/strict') +const test = require('node:test') +const { decideTargetBranchReview } = require('./check-target-branch-policy.ts') + +type DecisionFacts = { + base: string + head: string + maxRebuildCount: number + rebuildsAllTests: boolean + isExemptKernelUpdate: boolean + isExemptHomeAssistantUpdate: boolean +} + +type Decision = + | 'mass-rebuild' + | 'nixos-rebuild' + | 'possible-mass-rebuild' + | 'skip-development-merge' + | 'dismiss' + +const defaults: DecisionFacts = { + base: 'master', + head: 'topic-branch', + maxRebuildCount: 0, + rebuildsAllTests: false, + isExemptKernelUpdate: false, + isExemptHomeAssistantUpdate: false, +} + +const cases: Array<{ + name: string + facts: Partial + expected: Decision +}> = [ + { + name: 'allows fewer than 500 rebuilds on master', + facts: { maxRebuildCount: 499 }, + expected: 'dismiss', + }, + { + name: 'flags 500 rebuilds on master as a possible mass rebuild', + facts: { maxRebuildCount: 500 }, + expected: 'possible-mass-rebuild', + }, + { + name: 'flags 999 rebuilds on master as a possible mass rebuild', + facts: { maxRebuildCount: 999 }, + expected: 'possible-mass-rebuild', + }, + { + name: 'flags 1000 rebuilds on master as a mass rebuild', + facts: { maxRebuildCount: 1000 }, + expected: 'mass-rebuild', + }, + { + name: 'does not check mass rebuilds on staging-nixos', + facts: { base: 'staging-nixos', maxRebuildCount: 24_000 }, + expected: 'dismiss', + }, + { + name: 'does not check mass rebuilds on a release staging-nixos branch', + facts: { base: 'staging-nixos-26.05', maxRebuildCount: 1000 }, + expected: 'dismiss', + }, + { + name: 'allows mass rebuilds on staging', + facts: { base: 'staging', maxRebuildCount: 1000 }, + expected: 'dismiss', + }, + { + name: 'flags a mass rebuild on a release branch', + facts: { base: 'release-26.05', maxRebuildCount: 1000 }, + expected: 'mass-rebuild', + }, + { + name: 'flags NixOS test rebuilds on master', + facts: { rebuildsAllTests: true }, + expected: 'nixos-rebuild', + }, + { + name: 'flags NixOS test rebuilds on a release branch', + facts: { base: 'release-26.05', rebuildsAllTests: true }, + expected: 'nixos-rebuild', + }, + { + name: 'allows NixOS test rebuilds on staging-nixos', + facts: { base: 'staging-nixos', rebuildsAllTests: true }, + expected: 'dismiss', + }, + { + name: 'does not flag a possible mass rebuild when staging-nixos rebuilds all NixOS tests', + facts: { + base: 'staging-nixos', + maxRebuildCount: 500, + rebuildsAllTests: true, + }, + expected: 'dismiss', + }, + { + name: 'does not check possible mass rebuilds on staging-nixos', + facts: { base: 'staging-nixos', maxRebuildCount: 500 }, + expected: 'dismiss', + }, + { + name: 'skips staging into master', + facts: { + head: 'staging', + maxRebuildCount: 24_000, + }, + expected: 'skip-development-merge', + }, + { + name: 'skips staging-nixos into master', + facts: { + head: 'staging-nixos', + maxRebuildCount: 24_000, + }, + expected: 'skip-development-merge', + }, + { + name: 'skips master into staging-nixos', + facts: { + base: 'staging-nixos', + head: 'master', + maxRebuildCount: 24_000, + }, + expected: 'skip-development-merge', + }, + { + name: 'skips staging into staging-nixos', + facts: { + base: 'staging-nixos', + head: 'staging', + maxRebuildCount: 24_000, + }, + expected: 'skip-development-merge', + }, + { + name: 'skips release staging-nixos into its release branch', + facts: { + base: 'release-26.05', + head: 'staging-nixos-26.05', + maxRebuildCount: 24_000, + }, + expected: 'skip-development-merge', + }, + { + name: 'skips a release branch into its staging-nixos branch', + facts: { + base: 'staging-nixos-26.05', + head: 'release-26.05', + maxRebuildCount: 24_000, + }, + expected: 'skip-development-merge', + }, + { + name: 'skips release staging into its staging-nixos branch', + facts: { + base: 'staging-nixos-26.05', + head: 'staging-26.05', + maxRebuildCount: 24_000, + }, + expected: 'skip-development-merge', + }, + { + name: 'kernel exemption suppresses a possible mass rebuild', + facts: { maxRebuildCount: 999, isExemptKernelUpdate: true }, + expected: 'dismiss', + }, + { + name: 'kernel exemption suppresses a definite mass rebuild', + facts: { maxRebuildCount: 1000, isExemptKernelUpdate: true }, + expected: 'dismiss', + }, + { + name: 'kernel exemption suppresses a NixOS test rebuild', + facts: { rebuildsAllTests: true, isExemptKernelUpdate: true }, + expected: 'dismiss', + }, + { + name: 'Home Assistant exemption suppresses a mass rebuild', + facts: { + maxRebuildCount: 1500, + isExemptHomeAssistantUpdate: true, + }, + expected: 'dismiss', + }, + { + name: 'Home Assistant exemption does not suppress a NixOS test rebuild', + facts: { + maxRebuildCount: 1500, + rebuildsAllTests: true, + isExemptHomeAssistantUpdate: true, + }, + expected: 'nixos-rebuild', + }, +] + +for (const { name, facts, expected } of cases) { + test(name, () => { + assert.equal(decideTargetBranchReview({ ...defaults, ...facts }), expected) + }) +} diff --git a/ci/github-script/package.json b/ci/github-script/package.json index e495941ca4cc..84555f8dc372 100644 --- a/ci/github-script/package.json +++ b/ci/github-script/package.json @@ -2,7 +2,8 @@ "private": true, "scripts": { "typecheck": "tsc --build", - "test": "npm run typecheck" + "testsuite": "node --test", + "test": "npm run typecheck && npm run testsuite" }, "//": [ "Keep `@actions/core` and `@actions/github` in sync with", From eb9040e631e05689126cd15e984a97fb8a2cb95e Mon Sep 17 00:00:00 2001 From: Ihar Hrachyshka Date: Mon, 17 Aug 2026 21:36:37 -0400 Subject: [PATCH 16/48] ci/github-script/check-target-branch: simplify policy decisions This commit hopefully improves readability: encapsulates some intermediary decisions in variable, plus adopts early return decision tree. Assisted-by: Codex gpt-5.6-sol medium (cherry picked from commit 403d5922cf67fece1f3470ac773c930f839e12ca) --- .../check-target-branch-policy.ts | 56 ++++++++------- ci/github-script/check-target-branch.ts | 71 +++++++------------ 2 files changed, 55 insertions(+), 72 deletions(-) diff --git a/ci/github-script/check-target-branch-policy.ts b/ci/github-script/check-target-branch-policy.ts index 57334a74cfbd..7ef8865903e3 100644 --- a/ci/github-script/check-target-branch-policy.ts +++ b/ci/github-script/check-target-branch-policy.ts @@ -19,10 +19,14 @@ type TargetBranchReviewDecision = function getTargetBranchPolicy({ base, head }: { base: string; head: string }) { const baseClassification = classify(base) const headClassification = classify(head) + const isPrimaryBase = baseClassification.type.includes('primary') + const shouldSkipDevelopmentMerge = + headClassification.type.includes('development') return { - shouldSkipDevelopmentMerge: headClassification.type.includes('development'), - shouldCheckMassRebuild: baseClassification.type.includes('primary'), + shouldSkipDevelopmentMerge, + shouldCheckMassRebuild: !shouldSkipDevelopmentMerge && isPrimaryBase, + shouldCheckNixosRebuild: !shouldSkipDevelopmentMerge && isPrimaryBase, } } @@ -34,34 +38,34 @@ function decideTargetBranchReview({ isExemptKernelUpdate, isExemptHomeAssistantUpdate, }: TargetBranchPolicyFacts): TargetBranchReviewDecision { - const baseClassification = classify(base) - const headClassification = classify(head) - - if (headClassification.type.includes('development')) { - return 'skip-development-merge' - } - - if (!baseClassification.type.includes('primary')) { - return 'dismiss' - } - - if ( + const { + shouldSkipDevelopmentMerge, + shouldCheckMassRebuild, + shouldCheckNixosRebuild, + } = getTargetBranchPolicy({ base, head }) + const isMassRebuild = maxRebuildCount >= 1000 && - !isExemptHomeAssistantUpdate && - !isExemptKernelUpdate - ) { - return 'mass-rebuild' - } else if (rebuildsAllTests && !isExemptKernelUpdate) { - return 'nixos-rebuild' - } else if ( - maxRebuildCount >= 500 && !isExemptKernelUpdate && !isExemptHomeAssistantUpdate - ) { - return 'possible-mass-rebuild' - } else { - return 'dismiss' + + if (shouldCheckMassRebuild && isMassRebuild) { + return 'mass-rebuild' } + + if (shouldCheckNixosRebuild && rebuildsAllTests && !isExemptKernelUpdate) { + return 'nixos-rebuild' + } + + const isPossibleMassRebuild = + maxRebuildCount >= 500 && + !isMassRebuild && + !isExemptKernelUpdate && + !isExemptHomeAssistantUpdate + if (shouldCheckMassRebuild && isPossibleMassRebuild) { + return 'possible-mass-rebuild' + } + + return shouldSkipDevelopmentMerge ? 'skip-development-merge' : 'dismiss' } module.exports = { decideTargetBranchReview, getTargetBranchPolicy } diff --git a/ci/github-script/check-target-branch.ts b/ci/github-script/check-target-branch.ts index bede591c4613..4b190df67033 100644 --- a/ci/github-script/check-target-branch.ts +++ b/ci/github-script/check-target-branch.ts @@ -156,41 +156,7 @@ async function checkTargetBranch({ ).data const base = prInfo.base.ref const head = prInfo.head.ref - const { shouldSkipDevelopmentMerge, shouldCheckMassRebuild } = - getTargetBranchPolicy({ base, head }) - - // Don't run on, e.g., staging-nixos to master merges. - if (shouldSkipDevelopmentMerge) { - core.info( - `Skipping checkTargetBranch: PR is from a development branch (${head})`, - ) - - await dismissReviews({ - github, - context, - core, - dry, - reviewKey, - }) - - return - } - // Don't run on PRs against staging branches, wip branches, haskell-updates, etc. - if (!shouldCheckMassRebuild) { - core.info( - `Skipping checkTargetBranch: PR is against a non-primary base branch (${base})`, - ) - - await dismissReviews({ - github, - context, - core, - dry, - reviewKey, - }) - - return - } + const { shouldCheckMassRebuild } = getTargetBranchPolicy({ base, head }) const maxRebuildCount = Math.max( ...Object.values(changed.rebuildCountByKernel), @@ -202,7 +168,7 @@ async function checkTargetBranch({ // https://github.com/NixOS/nixpkgs/pull/521157 // These should go to master and release-xx.xx when backported let isExemptKernelUpdate = false - if (prInfo.changed_files === 1) { + if (shouldCheckMassRebuild && prInfo.changed_files === 1) { const changedFiles = ( await github.rest.pulls.listFiles({ ...context.repo, @@ -248,21 +214,34 @@ async function checkTargetBranch({ if (decision === 'mass-rebuild') { await postMassRebuildReview(reviewFacts) - } else if (decision === 'nixos-rebuild') { + return + } + + if (decision === 'nixos-rebuild') { await postNixosRebuildReview(reviewFacts) - } else if (decision === 'possible-mass-rebuild') { + return + } + + if (decision === 'possible-mass-rebuild') { await postPossibleMassRebuildReview(reviewFacts) + return + } + + if (decision === 'skip-development-merge') { + core.info( + `Skipping checkTargetBranch: PR merges the development branch ${head} into ${base}`, + ) } else { core.info('checkTargetBranch: this PR is against an appropriate branch.') - - await dismissReviews({ - github, - context, - core, - dry, - reviewKey, - }) } + + await dismissReviews({ + github, + context, + core, + dry, + reviewKey, + }) } module.exports = checkTargetBranch From 63708917552a4331e26e0873625d3d6827fb70fc Mon Sep 17 00:00:00 2001 From: Ihar Hrachyshka Date: Mon, 17 Aug 2026 21:08:16 -0400 Subject: [PATCH 17/48] ci/github-script/check-target-branch: check staging-nixos mass rebuilds Assisted-by: Codex gpt-5.6-sol medium (cherry picked from commit 221930c60ceb6f5eedefbd83cc94371279d83337) --- .../check-target-branch-policy.test.ts | 20 +++++++++---------- .../check-target-branch-policy.ts | 18 +++++++++++++---- ci/github-script/check-target-branch.ts | 11 ++++++---- 3 files changed, 31 insertions(+), 18 deletions(-) diff --git a/ci/github-script/check-target-branch-policy.test.ts b/ci/github-script/check-target-branch-policy.test.ts index 7329fc3f6d3a..f272379f37d6 100644 --- a/ci/github-script/check-target-branch-policy.test.ts +++ b/ci/github-script/check-target-branch-policy.test.ts @@ -53,14 +53,14 @@ const cases: Array<{ expected: 'mass-rebuild', }, { - name: 'does not check mass rebuilds on staging-nixos', + name: 'flags a mass rebuild on staging-nixos', facts: { base: 'staging-nixos', maxRebuildCount: 24_000 }, - expected: 'dismiss', + expected: 'mass-rebuild', }, { - name: 'does not check mass rebuilds on a release staging-nixos branch', + name: 'flags a mass rebuild on a release staging-nixos branch', facts: { base: 'staging-nixos-26.05', maxRebuildCount: 1000 }, - expected: 'dismiss', + expected: 'mass-rebuild', }, { name: 'allows mass rebuilds on staging', @@ -97,9 +97,9 @@ const cases: Array<{ expected: 'dismiss', }, { - name: 'does not check possible mass rebuilds on staging-nixos', + name: 'flags other possible mass rebuilds on staging-nixos', facts: { base: 'staging-nixos', maxRebuildCount: 500 }, - expected: 'dismiss', + expected: 'possible-mass-rebuild', }, { name: 'skips staging into master', @@ -127,13 +127,13 @@ const cases: Array<{ expected: 'skip-development-merge', }, { - name: 'skips staging into staging-nixos', + name: 'checks staging into staging-nixos', facts: { base: 'staging-nixos', head: 'staging', maxRebuildCount: 24_000, }, - expected: 'skip-development-merge', + expected: 'mass-rebuild', }, { name: 'skips release staging-nixos into its release branch', @@ -154,13 +154,13 @@ const cases: Array<{ expected: 'skip-development-merge', }, { - name: 'skips release staging into its staging-nixos branch', + name: 'checks release staging into its staging-nixos branch', facts: { base: 'staging-nixos-26.05', head: 'staging-26.05', maxRebuildCount: 24_000, }, - expected: 'skip-development-merge', + expected: 'mass-rebuild', }, { name: 'kernel exemption suppresses a possible mass rebuild', diff --git a/ci/github-script/check-target-branch-policy.ts b/ci/github-script/check-target-branch-policy.ts index 7ef8865903e3..c3671929373d 100644 --- a/ci/github-script/check-target-branch-policy.ts +++ b/ci/github-script/check-target-branch-policy.ts @@ -1,4 +1,4 @@ -const { classify } = require('../supportedBranches.js') +const { classify, split } = require('../supportedBranches.js') type TargetBranchPolicyFacts = { base: string @@ -20,12 +20,17 @@ function getTargetBranchPolicy({ base, head }: { base: string; head: string }) { const baseClassification = classify(base) const headClassification = classify(head) const isPrimaryBase = baseClassification.type.includes('primary') + const isPrimaryHead = headClassification.type.includes('primary') + const isStagingNixosBase = split(base).prefix === 'staging-nixos' + const isDevelopmentHead = headClassification.type.includes('development') const shouldSkipDevelopmentMerge = - headClassification.type.includes('development') + isDevelopmentHead && (!isStagingNixosBase || isPrimaryHead) return { + isStagingNixosBase, shouldSkipDevelopmentMerge, - shouldCheckMassRebuild: !shouldSkipDevelopmentMerge && isPrimaryBase, + shouldCheckMassRebuild: + !shouldSkipDevelopmentMerge && (isPrimaryBase || isStagingNixosBase), shouldCheckNixosRebuild: !shouldSkipDevelopmentMerge && isPrimaryBase, } } @@ -39,6 +44,7 @@ function decideTargetBranchReview({ isExemptHomeAssistantUpdate, }: TargetBranchPolicyFacts): TargetBranchReviewDecision { const { + isStagingNixosBase, shouldSkipDevelopmentMerge, shouldCheckMassRebuild, shouldCheckNixosRebuild, @@ -61,7 +67,11 @@ function decideTargetBranchReview({ !isMassRebuild && !isExemptKernelUpdate && !isExemptHomeAssistantUpdate - if (shouldCheckMassRebuild && isPossibleMassRebuild) { + if ( + shouldCheckMassRebuild && + isPossibleMassRebuild && + !(rebuildsAllTests && isStagingNixosBase) + ) { return 'possible-mass-rebuild' } diff --git a/ci/github-script/check-target-branch.ts b/ci/github-script/check-target-branch.ts index 4b190df67033..e8fc51e178b2 100644 --- a/ci/github-script/check-target-branch.ts +++ b/ci/github-script/check-target-branch.ts @@ -53,10 +53,14 @@ type TargetBranchReviewFacts = { maxRebuildCount: number } +function getStagingBranch(base: string) { + const version = split(base).version + return version ? `staging-${version}` : 'staging' +} + async function postMassRebuildReview(facts: TargetBranchReviewFacts) { const { github, context, core, dry, base, maxRebuildCount } = facts - const desiredBranch = - base === 'master' ? 'staging' : `staging-${split(base).version}` + const desiredBranch = getStagingBranch(base) const body = [ `The PR's base branch is set to \`${base}\`, but this PR causes ${maxRebuildCount} rebuilds.`, 'It is therefore considered a mass rebuild.', @@ -107,8 +111,7 @@ async function postNixosRebuildReview(facts: TargetBranchReviewFacts) { async function postPossibleMassRebuildReview(facts: TargetBranchReviewFacts) { const { github, context, core, dry, base, maxRebuildCount } = facts - const stagingBranch = - base === 'master' ? 'staging' : `staging-${split(base).version}` + const stagingBranch = getStagingBranch(base) const body = [ `The PR's base branch is set to \`${base}\`, and this PR causes ${maxRebuildCount} rebuilds.`, `Please consider whether this PR causes a mass rebuild according to [our conventions](https://github.com/NixOS/nixpkgs/blob/master/CONTRIBUTING.md#branch-conventions).`, From f916f3f0069f4477eadbec087d97b97ce08a8bc1 Mon Sep 17 00:00:00 2001 From: Ihar Hrachyshka Date: Mon, 17 Aug 2026 22:02:53 -0400 Subject: [PATCH 18/48] ci/github-script/check-target-branch: evaluate exemptions in policy Assisted-by: Codex gpt-5.6-sol medium (cherry picked from commit 30a8636adf7edde499a1d3aa1c2c395058f8919c) --- .../check-target-branch-policy.test.ts | 39 +++++++++++---- .../check-target-branch-policy.ts | 50 +++++++++++++++---- ci/github-script/check-target-branch.ts | 23 ++++----- 3 files changed, 76 insertions(+), 36 deletions(-) diff --git a/ci/github-script/check-target-branch-policy.test.ts b/ci/github-script/check-target-branch-policy.test.ts index f272379f37d6..a9feca6aea7a 100644 --- a/ci/github-script/check-target-branch-policy.test.ts +++ b/ci/github-script/check-target-branch-policy.test.ts @@ -1,14 +1,15 @@ const assert = require('node:assert/strict') const test = require('node:test') -const { decideTargetBranchReview } = require('./check-target-branch-policy.ts') +const { + evaluateTargetBranchPolicy, +} = require('./check-target-branch-policy.ts') type DecisionFacts = { base: string head: string maxRebuildCount: number rebuildsAllTests: boolean - isExemptKernelUpdate: boolean - isExemptHomeAssistantUpdate: boolean + onlyChangedFile: string | null } type Decision = @@ -23,8 +24,7 @@ const defaults: DecisionFacts = { head: 'topic-branch', maxRebuildCount: 0, rebuildsAllTests: false, - isExemptKernelUpdate: false, - isExemptHomeAssistantUpdate: false, + onlyChangedFile: null, } const cases: Array<{ @@ -164,33 +164,47 @@ const cases: Array<{ }, { name: 'kernel exemption suppresses a possible mass rebuild', - facts: { maxRebuildCount: 999, isExemptKernelUpdate: true }, + facts: { + maxRebuildCount: 999, + onlyChangedFile: 'pkgs/os-specific/linux/kernel/xanmod-kernels.nix', + }, expected: 'dismiss', }, { name: 'kernel exemption suppresses a definite mass rebuild', - facts: { maxRebuildCount: 1000, isExemptKernelUpdate: true }, + facts: { + maxRebuildCount: 1000, + onlyChangedFile: 'pkgs/os-specific/linux/kernel/xanmod-kernels.nix', + }, expected: 'dismiss', }, { name: 'kernel exemption suppresses a NixOS test rebuild', - facts: { rebuildsAllTests: true, isExemptKernelUpdate: true }, + facts: { + rebuildsAllTests: true, + onlyChangedFile: 'pkgs/os-specific/linux/kernel/xanmod-kernels.nix', + }, expected: 'dismiss', }, { name: 'Home Assistant exemption suppresses a mass rebuild', facts: { + head: 'wip-home-assistant', maxRebuildCount: 1500, - isExemptHomeAssistantUpdate: true, }, expected: 'dismiss', }, + { + name: 'does not exempt a Home Assistant update above 1500 rebuilds', + facts: { head: 'wip-home-assistant', maxRebuildCount: 1501 }, + expected: 'mass-rebuild', + }, { name: 'Home Assistant exemption does not suppress a NixOS test rebuild', facts: { + head: 'wip-home-assistant', maxRebuildCount: 1500, rebuildsAllTests: true, - isExemptHomeAssistantUpdate: true, }, expected: 'nixos-rebuild', }, @@ -198,6 +212,9 @@ const cases: Array<{ for (const { name, facts, expected } of cases) { test(name, () => { - assert.equal(decideTargetBranchReview({ ...defaults, ...facts }), expected) + assert.equal( + evaluateTargetBranchPolicy({ ...defaults, ...facts }).decision, + expected, + ) }) } diff --git a/ci/github-script/check-target-branch-policy.ts b/ci/github-script/check-target-branch-policy.ts index c3671929373d..30879a6f7ac8 100644 --- a/ci/github-script/check-target-branch-policy.ts +++ b/ci/github-script/check-target-branch-policy.ts @@ -5,8 +5,7 @@ type TargetBranchPolicyFacts = { head: string maxRebuildCount: number rebuildsAllTests: boolean - isExemptKernelUpdate: boolean - isExemptHomeAssistantUpdate: boolean + onlyChangedFile: string | null } type TargetBranchReviewDecision = @@ -16,6 +15,14 @@ type TargetBranchReviewDecision = | 'skip-development-merge' | 'dismiss' +type TargetBranchPolicyResult = { + decision: TargetBranchReviewDecision + details: { + isExemptKernelUpdate: boolean + isExemptHomeAssistantUpdate: boolean + } +} + function getTargetBranchPolicy({ base, head }: { base: string; head: string }) { const baseClassification = classify(base) const headClassification = classify(head) @@ -35,31 +42,50 @@ function getTargetBranchPolicy({ base, head }: { base: string; head: string }) { } } -function decideTargetBranchReview({ +function evaluateTargetBranchPolicy({ base, head, maxRebuildCount, rebuildsAllTests, - isExemptKernelUpdate, - isExemptHomeAssistantUpdate, -}: TargetBranchPolicyFacts): TargetBranchReviewDecision { + onlyChangedFile, +}: TargetBranchPolicyFacts): TargetBranchPolicyResult { const { isStagingNixosBase, shouldSkipDevelopmentMerge, shouldCheckMassRebuild, shouldCheckNixosRebuild, } = getTargetBranchPolicy({ base, head }) + + // https://github.com/NixOS/nixpkgs/pull/521157 + // These should go to master and release-xx.xx when backported + const isExemptKernelUpdate = + onlyChangedFile === 'pkgs/os-specific/linux/kernel/xanmod-kernels.nix' + + // https://github.com/NixOS/nixpkgs/pull/483194#issuecomment-3793393218 + const isExemptHomeAssistantUpdate = + maxRebuildCount <= 1500 && head === 'wip-home-assistant' + + const details = { + isExemptKernelUpdate, + isExemptHomeAssistantUpdate, + } + + const result = (decision: TargetBranchReviewDecision) => ({ + decision, + details, + }) + const isMassRebuild = maxRebuildCount >= 1000 && !isExemptKernelUpdate && !isExemptHomeAssistantUpdate if (shouldCheckMassRebuild && isMassRebuild) { - return 'mass-rebuild' + return result('mass-rebuild') } if (shouldCheckNixosRebuild && rebuildsAllTests && !isExemptKernelUpdate) { - return 'nixos-rebuild' + return result('nixos-rebuild') } const isPossibleMassRebuild = @@ -72,10 +98,12 @@ function decideTargetBranchReview({ isPossibleMassRebuild && !(rebuildsAllTests && isStagingNixosBase) ) { - return 'possible-mass-rebuild' + return result('possible-mass-rebuild') } - return shouldSkipDevelopmentMerge ? 'skip-development-merge' : 'dismiss' + return result( + shouldSkipDevelopmentMerge ? 'skip-development-merge' : 'dismiss', + ) } -module.exports = { decideTargetBranchReview, getTargetBranchPolicy } +module.exports = { evaluateTargetBranchPolicy, getTargetBranchPolicy } diff --git a/ci/github-script/check-target-branch.ts b/ci/github-script/check-target-branch.ts index e8fc51e178b2..8d07482a9533 100644 --- a/ci/github-script/check-target-branch.ts +++ b/ci/github-script/check-target-branch.ts @@ -10,7 +10,7 @@ const { split } = require('../supportedBranches.js') const { readFile } = require('node:fs/promises') const { postReview, dismissReviews } = require('./reviews.js') const { - decideTargetBranchReview, + evaluateTargetBranchPolicy, getTargetBranchPolicy, } = require('./check-target-branch-policy.ts') @@ -168,9 +168,7 @@ async function checkTargetBranch({ changed.attrdiff.changed.includes('nixosTests.simple-container') || changed.attrdiff.changed.includes('nixosTests.simple-vm') - // https://github.com/NixOS/nixpkgs/pull/521157 - // These should go to master and release-xx.xx when backported - let isExemptKernelUpdate = false + let onlyChangedFile: string | null = null if (shouldCheckMassRebuild && prInfo.changed_files === 1) { const changedFiles = ( await github.rest.pulls.listFiles({ @@ -178,22 +176,19 @@ async function checkTargetBranch({ pull_number, }) ).data - isExemptKernelUpdate = - changedFiles.length === 1 && - changedFiles[0].filename === - 'pkgs/os-specific/linux/kernel/xanmod-kernels.nix' + onlyChangedFile = + changedFiles.length === 1 ? changedFiles[0].filename : null } - // https://github.com/NixOS/nixpkgs/pull/483194#issuecomment-3793393218 - const isExemptHomeAssistantUpdate = - maxRebuildCount <= 1500 && head === 'wip-home-assistant' - const decision = decideTargetBranchReview({ + const { + decision, + details: { isExemptKernelUpdate, isExemptHomeAssistantUpdate }, + } = evaluateTargetBranchPolicy({ base, head, maxRebuildCount, rebuildsAllTests, - isExemptKernelUpdate, - isExemptHomeAssistantUpdate, + onlyChangedFile, }) core.info( From c18e79a851d9b0720aa7d6cf2272046ff27150c5 Mon Sep 17 00:00:00 2001 From: fsagbuya Date: Fri, 28 Aug 2026 15:46:00 +0800 Subject: [PATCH 19/48] nixos/flarum: don't overwrite config.php on installs not managed by this module (cherry picked from commit fa850edc89d9a2e5757ce328be62c94cf4e72a90) --- nixos/modules/services/web-apps/flarum.nix | 47 ++++++++++++++++++---- nixos/tests/flarum.nix | 13 ++++++ 2 files changed, 53 insertions(+), 7 deletions(-) diff --git a/nixos/modules/services/web-apps/flarum.nix b/nixos/modules/services/web-apps/flarum.nix index 7fb9492713d8..7b89290bbbb9 100644 --- a/nixos/modules/services/web-apps/flarum.nix +++ b/nixos/modules/services/web-apps/flarum.nix @@ -195,6 +195,25 @@ in Only set this to true if you are certain you are working with a fresh, empty database. ''; }; + + adoptConfig = mkOption { + type = types.bool; + default = false; + description = '' + Whether to let this module manage a pre-existing config.php, + such as a hand-maintained one (typically with + {option}`createDatabaseLocally` = false). + + By default, a config.php this module didn't create is left alone: + {option}`baseUrl` and {option}`database` are not applied to it, so + real settings can't get silently overwritten by their defaults. + + Before enabling this, make sure {option}`baseUrl` and + {option}`database` already match the file's real values. Once + enabled, config.php is regenerated from these options on every + activation, and anything in the file not covered by them is lost. + ''; + }; }; config = mkIf cfg.enable { @@ -287,6 +306,16 @@ in cp -f ${cfg.package}/share/php/flarum/{extend.php,site.php,flarum} . ln -sf ${cfg.package}/share/php/flarum/vendor . ln -sf ${cfg.package}/share/php/flarum/public/index.php public/ + + ${optionalString cfg.adoptConfig "touch .flarum-installed"} + + # config.php with no marker means we didn't write it, so leave it alone. + # This check must come before the guard below: that guard also touches + # the marker, which would make this check pass for the wrong reason. + if [ ! -f .flarum-installed ] && [ -f config.php ]; then + echo "flarum-install: config.php exists but wasn't written by this module; leaving it untouched." >&2 + echo "flarum-install: set services.flarum.adoptConfig = true to adopt it." >&2 + else '' + optionalString (cfg.createDatabaseLocally && cfg.database.driver == "mysql") '' if [ ! -f .flarum-installed ]; then @@ -306,14 +335,18 @@ in fi '' + '' - install -m 0600 ${configPhpFile} config.php - ${optionalString (cfg.databasePasswordFile != null) '' - ${pkgs.replace-secret}/bin/replace-secret '@databasePassword@' \ - ${escapeShellArg cfg.databasePasswordFile} config.php - ''} + touch .flarum-installed + install -m 0600 ${configPhpFile} config.php + ${optionalString (cfg.databasePasswordFile != null) '' + ${pkgs.replace-secret}/bin/replace-secret '@databasePassword@' \ + ${escapeShellArg cfg.databasePasswordFile} config.php + ''} + fi - php flarum migrate - php flarum cache:clear + if [ -f config.php ]; then + php flarum migrate + php flarum cache:clear + fi ''; }; }; diff --git a/nixos/tests/flarum.nix b/nixos/tests/flarum.nix index e6d1fe7128a6..3157a0627577 100644 --- a/nixos/tests/flarum.nix +++ b/nixos/tests/flarum.nix @@ -81,5 +81,18 @@ "echo 'select id from nixos_test_marker;' | sudo -u flarum mysql -u flarum flarum -N | grep -q 1" ) machine.succeed("[ -f /var/lib/flarum/.flarum-installed ]") + + # A config.php present without the .flarum-installed marker (hand-maintained, + # or from before this module managed config.php) must be left untouched. + machine.succeed("rm /var/lib/flarum/.flarum-installed") + machine.succeed( + "echo ' \"http://localhost\", \"database\" => " + + "array (\"driver\" => \"mysql\", \"host\" => \"localhost\", \"database\" => " + + "\"flarum\", \"username\" => \"flarum\", \"password\" => \"flarum-db-password\"), " + + "\"nixos_test_marker\" => \"foreign-config\");' " + + "| sudo -u flarum tee /var/lib/flarum/config.php" + ) + machine.succeed("systemctl restart flarum-install.service") + machine.succeed("grep -q 'nixos_test_marker' /var/lib/flarum/config.php") ''; } From 6a0fc0f5c53d8a85eb2d5db870ab640dec9d7185 Mon Sep 17 00:00:00 2001 From: zowoq <59103226+zowoq@users.noreply.github.com> Date: Fri, 28 Aug 2026 08:11:55 +0000 Subject: [PATCH 20/48] linux_7_2: 7.2.1 -> 7.2.2 (cherry picked from commit d732e65166b51f8fc6f8d4157ff019b9b1fa6c9f) --- pkgs/os-specific/linux/kernel/kernels-org.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/kernels-org.json b/pkgs/os-specific/linux/kernel/kernels-org.json index 956e33771b40..be7f32f549b7 100644 --- a/pkgs/os-specific/linux/kernel/kernels-org.json +++ b/pkgs/os-specific/linux/kernel/kernels-org.json @@ -40,8 +40,8 @@ "lts": false }, "7.2": { - "version": "7.2.1", - "hash": "sha256:1csp8m7a5ws9j35x7bc2cb8067illqx5v1cc0sz8zsi8ia60jn21", + "version": "7.2.2", + "hash": "sha256:10qd3kllldrw6gbp0wfziy94bgjr98svzzqci3z3xi4q9zhpq3kx", "lts": false } } From cbaf3aba19c6b98e508dff913ad63e14c50ebc64 Mon Sep 17 00:00:00 2001 From: zowoq <59103226+zowoq@users.noreply.github.com> Date: Fri, 28 Aug 2026 08:11:57 +0000 Subject: [PATCH 21/48] linux_7_1: 7.1.11 -> 7.1.12 (cherry picked from commit 48bf22807482c4a1f5fb1d050bc62cb4132a2730) --- pkgs/os-specific/linux/kernel/kernels-org.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/kernels-org.json b/pkgs/os-specific/linux/kernel/kernels-org.json index be7f32f549b7..49e9ce3fb8dd 100644 --- a/pkgs/os-specific/linux/kernel/kernels-org.json +++ b/pkgs/os-specific/linux/kernel/kernels-org.json @@ -35,8 +35,8 @@ "lts": true }, "7.1": { - "version": "7.1.11", - "hash": "sha256:1z0s6pv34d5mk75jxj05s6hzy2x6vahc5dxxbkp5pirfiw6m8a9h", + "version": "7.1.12", + "hash": "sha256:1qaskd7g2pzh32lvfb18qh29hfy3mh2flglh1d9cvr17xnrid5rq", "lts": false }, "7.2": { From 3c1473457214c1435ecc92c2764f21afb56b6249 Mon Sep 17 00:00:00 2001 From: zowoq <59103226+zowoq@users.noreply.github.com> Date: Fri, 28 Aug 2026 08:12:00 +0000 Subject: [PATCH 22/48] linux_6_18: 6.18.47 -> 6.18.48 (cherry picked from commit d6adba09a4d1561d9d650643257dab37488546df) --- pkgs/os-specific/linux/kernel/kernels-org.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/kernels-org.json b/pkgs/os-specific/linux/kernel/kernels-org.json index 49e9ce3fb8dd..8c00bee53bae 100644 --- a/pkgs/os-specific/linux/kernel/kernels-org.json +++ b/pkgs/os-specific/linux/kernel/kernels-org.json @@ -30,8 +30,8 @@ "lts": true }, "6.18": { - "version": "6.18.47", - "hash": "sha256:0678vsivrr3qw2pdg2ch26a2kx365cm1gy3w21rm86k08gyvlgqv", + "version": "6.18.48", + "hash": "sha256:137wqvcfl8drb4n51hqc2pw4kg0hl5j7fi8wdgy0hmsb1aqsvgay", "lts": true }, "7.1": { From ad867589554aa57c9ce66e5a4d93028cf2c17420 Mon Sep 17 00:00:00 2001 From: zowoq <59103226+zowoq@users.noreply.github.com> Date: Fri, 28 Aug 2026 08:12:02 +0000 Subject: [PATCH 23/48] linux_6_12: 6.12.106 -> 6.12.107 (cherry picked from commit c8698ff816d9aba46ef5b394b04fe5ce6778de40) --- pkgs/os-specific/linux/kernel/kernels-org.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/kernels-org.json b/pkgs/os-specific/linux/kernel/kernels-org.json index 8c00bee53bae..493f9b40baba 100644 --- a/pkgs/os-specific/linux/kernel/kernels-org.json +++ b/pkgs/os-specific/linux/kernel/kernels-org.json @@ -25,8 +25,8 @@ "lts": true }, "6.12": { - "version": "6.12.106", - "hash": "sha256:11fpivj271143v8rdk4jifbpxxrd3saphq9za027d76rc5bmb4h3", + "version": "6.12.107", + "hash": "sha256:0yih5s4xbp1hlyfha49z2j3l9x7i5ij335jfl6f6sbfy7yzcby55", "lts": true }, "6.18": { From 661993a0e57ad646f06c09926bd54b8c457476e7 Mon Sep 17 00:00:00 2001 From: zowoq <59103226+zowoq@users.noreply.github.com> Date: Fri, 28 Aug 2026 08:12:28 +0000 Subject: [PATCH 24/48] linux_6_6: 6.6.154 -> 6.6.155 (cherry picked from commit 6ea73c1539a7f992801d16aaa7bd69f1b177bf74) --- pkgs/os-specific/linux/kernel/kernels-org.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/kernels-org.json b/pkgs/os-specific/linux/kernel/kernels-org.json index 493f9b40baba..c79cf208acd0 100644 --- a/pkgs/os-specific/linux/kernel/kernels-org.json +++ b/pkgs/os-specific/linux/kernel/kernels-org.json @@ -20,8 +20,8 @@ "lts": true }, "6.6": { - "version": "6.6.154", - "hash": "sha256:0d02xm0xglyhac9iyf01a01ab0kp0ghkar8qq6gj6l5h7pw01vpd", + "version": "6.6.155", + "hash": "sha256:10j9cm0jrjjwm8gy8h8nkyj8x3pfhaicj29125qb069c7wkajrsf", "lts": true }, "6.12": { From cbf2b58c49d71c2e3f71389aefdd5624608b6e97 Mon Sep 17 00:00:00 2001 From: zowoq <59103226+zowoq@users.noreply.github.com> Date: Fri, 28 Aug 2026 08:12:46 +0000 Subject: [PATCH 25/48] linux_6_1: 6.1.185 -> 6.1.186 (cherry picked from commit f650bd18c629680b54e2bb9b227092679e6ab8fc) --- pkgs/os-specific/linux/kernel/kernels-org.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/kernels-org.json b/pkgs/os-specific/linux/kernel/kernels-org.json index c79cf208acd0..9c8994cda3d1 100644 --- a/pkgs/os-specific/linux/kernel/kernels-org.json +++ b/pkgs/os-specific/linux/kernel/kernels-org.json @@ -5,8 +5,8 @@ "lts": false }, "6.1": { - "version": "6.1.185", - "hash": "sha256:0x1639znr91szyahgj2ni7ymcm46dmm41ispfx4jdikx2fhxjr1q", + "version": "6.1.186", + "hash": "sha256:0vi3yqvass80jgjw2yc2iz7p4wfqlih2gvjhzxd20j14pwmw7vgf", "lts": true }, "5.15": { From 51e33c08799bd196e62c1468ef0f771ad4922b7e Mon Sep 17 00:00:00 2001 From: zowoq <59103226+zowoq@users.noreply.github.com> Date: Fri, 28 Aug 2026 08:13:06 +0000 Subject: [PATCH 26/48] linux_5_15: 5.15.218 -> 5.15.219 (cherry picked from commit 90933664edd555e489aad4c110c8b509056392b0) --- pkgs/os-specific/linux/kernel/kernels-org.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/kernels-org.json b/pkgs/os-specific/linux/kernel/kernels-org.json index 9c8994cda3d1..514e0d4f41e3 100644 --- a/pkgs/os-specific/linux/kernel/kernels-org.json +++ b/pkgs/os-specific/linux/kernel/kernels-org.json @@ -10,8 +10,8 @@ "lts": true }, "5.15": { - "version": "5.15.218", - "hash": "sha256:0dpjimmxs648j9gri7h3flfimb1647a8629pgsvyxsgk6k8ip063", + "version": "5.15.219", + "hash": "sha256:192ws3mf4hvhawdl6amg7a7q7d68v2ijgjsy1cbq2vy2iiwlyjnh", "lts": true }, "5.10": { From 9b8a7debb7a44d57257fb6b6c22a4b8ca542827d Mon Sep 17 00:00:00 2001 From: zowoq <59103226+zowoq@users.noreply.github.com> Date: Fri, 28 Aug 2026 08:13:25 +0000 Subject: [PATCH 27/48] linux_5_10: 5.10.267 -> 5.10.268 (cherry picked from commit b641e1db3ecda03e1a9384dd89d57cd2f7b9d452) --- pkgs/os-specific/linux/kernel/kernels-org.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/kernels-org.json b/pkgs/os-specific/linux/kernel/kernels-org.json index 514e0d4f41e3..f9a122746387 100644 --- a/pkgs/os-specific/linux/kernel/kernels-org.json +++ b/pkgs/os-specific/linux/kernel/kernels-org.json @@ -15,8 +15,8 @@ "lts": true }, "5.10": { - "version": "5.10.267", - "hash": "sha256:01migk31fib50zgqf8rqmm71cff8s93msvy20sy8mj22mi80fi2v", + "version": "5.10.268", + "hash": "sha256:0fi6a8gbj60ankrx8gcjswv52k93xcjajcb6jihkwx63vfm4s5kv", "lts": true }, "6.6": { From ef85c42a8b245321c1976043981bd974ff5443b4 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 23 Aug 2026 17:39:57 +0000 Subject: [PATCH 28/48] firefox-beta-unwrapped: 154.0b10 -> 155.0b4 (cherry picked from commit ba89296176c6a0653c5f04f272b3b56093249160) --- .../networking/browsers/firefox/packages/firefox-beta.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/networking/browsers/firefox/packages/firefox-beta.nix b/pkgs/applications/networking/browsers/firefox/packages/firefox-beta.nix index 8935ef5e314f..cbea4f9af1ed 100644 --- a/pkgs/applications/networking/browsers/firefox/packages/firefox-beta.nix +++ b/pkgs/applications/networking/browsers/firefox/packages/firefox-beta.nix @@ -10,11 +10,11 @@ buildMozillaMach rec { pname = "firefox-beta"; binaryName = "firefox-beta"; - version = "154.0b10"; + version = "155.0b4"; applicationName = "Firefox Beta"; src = fetchurl { url = "mirror://mozilla/firefox/releases/${version}/source/firefox-${version}.source.tar.xz"; - sha512 = "ddbe3ff45217a16df9eecfac52fcb12425accae76457e7054b20bd085f5b22908940a20448f213c3dc62d1276bb1c81f38194432336ba97459b2c17393ebd3cd"; + sha512 = "6c1536924b955f856bc629cdf563ab9d4a87058fac7acf8db008bfe5a1f19defd004116bb3673fd23b62e1e00ca21acbcc7153d85dfa522eb3def6c85065b01b"; }; meta = { From 04840a0d9199445ecc9dab742ecc9d8017f926a3 Mon Sep 17 00:00:00 2001 From: jopejoe1 Date: Tue, 25 Aug 2026 19:56:20 +0000 Subject: [PATCH 29/48] firefox-devedition-unwrapped: 154.0b10 -> 155.0b4 (cherry picked from commit 4bee12d42c841c917d608899ad0e9f27826a7a38) --- .../browsers/firefox/packages/firefox-devedition.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/networking/browsers/firefox/packages/firefox-devedition.nix b/pkgs/applications/networking/browsers/firefox/packages/firefox-devedition.nix index d9918265f160..4b541f399eae 100644 --- a/pkgs/applications/networking/browsers/firefox/packages/firefox-devedition.nix +++ b/pkgs/applications/networking/browsers/firefox/packages/firefox-devedition.nix @@ -10,13 +10,13 @@ buildMozillaMach rec { pname = "firefox-devedition"; binaryName = "firefox-devedition"; - version = "154.0b10"; + version = "155.0b4"; applicationName = "Firefox Developer Edition"; requireSigning = false; branding = "browser/branding/aurora"; src = fetchurl { url = "mirror://mozilla/devedition/releases/${version}/source/firefox-${version}.source.tar.xz"; - sha512 = "e2275579e4769a0690010d8fbba528a0e347d86f0dc981d1702b3e627d9c73f3fd7399d3e618c514bf6a3c0059fa3aa5a29f9cdec802e52955a03b1122ca8d39"; + sha512 = "d2b58b520393848c110714537aec2c71d1244d7439c8c62e85bf123a3f3ade3db8a31617c242d9803306f1655237666948aaa55b780f8743ab57fc406a6ea906"; }; # buildMozillaMach sets MOZ_APP_REMOTINGNAME during configuration, but From e994d43b162958321314520227213ef61d8629bb Mon Sep 17 00:00:00 2001 From: jopejoe1 Date: Fri, 28 Aug 2026 07:59:18 +0000 Subject: [PATCH 30/48] firefox-beta-unwrapped: 155.0b4 -> 155.0b5 (cherry picked from commit 2fc917c86f22b3a125e2dd6e50ea59a16ce648e3) --- .../networking/browsers/firefox/packages/firefox-beta.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/networking/browsers/firefox/packages/firefox-beta.nix b/pkgs/applications/networking/browsers/firefox/packages/firefox-beta.nix index cbea4f9af1ed..8a03e06626a9 100644 --- a/pkgs/applications/networking/browsers/firefox/packages/firefox-beta.nix +++ b/pkgs/applications/networking/browsers/firefox/packages/firefox-beta.nix @@ -10,11 +10,11 @@ buildMozillaMach rec { pname = "firefox-beta"; binaryName = "firefox-beta"; - version = "155.0b4"; + version = "155.0b5"; applicationName = "Firefox Beta"; src = fetchurl { url = "mirror://mozilla/firefox/releases/${version}/source/firefox-${version}.source.tar.xz"; - sha512 = "6c1536924b955f856bc629cdf563ab9d4a87058fac7acf8db008bfe5a1f19defd004116bb3673fd23b62e1e00ca21acbcc7153d85dfa522eb3def6c85065b01b"; + sha512 = "30b4b84c80057a992e763b8f967c65f46308324fd41c0307c9302e262e6428c379861ccd9ce52dde15d0dc3f4410b95a8c047ea7e5af9d90e60e7bb57ee59137"; }; meta = { From 63214324e8376ba88f10d56ff817159da9f65325 Mon Sep 17 00:00:00 2001 From: jopejoe1 Date: Fri, 28 Aug 2026 07:59:21 +0000 Subject: [PATCH 31/48] firefox-devedition-unwrapped: 155.0b4 -> 155.0b5 (cherry picked from commit 8925c0d13b6d3f17ec7a3f9106ae627794d3b49e) --- .../browsers/firefox/packages/firefox-devedition.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/networking/browsers/firefox/packages/firefox-devedition.nix b/pkgs/applications/networking/browsers/firefox/packages/firefox-devedition.nix index 4b541f399eae..449995dd3620 100644 --- a/pkgs/applications/networking/browsers/firefox/packages/firefox-devedition.nix +++ b/pkgs/applications/networking/browsers/firefox/packages/firefox-devedition.nix @@ -10,13 +10,13 @@ buildMozillaMach rec { pname = "firefox-devedition"; binaryName = "firefox-devedition"; - version = "155.0b4"; + version = "155.0b5"; applicationName = "Firefox Developer Edition"; requireSigning = false; branding = "browser/branding/aurora"; src = fetchurl { url = "mirror://mozilla/devedition/releases/${version}/source/firefox-${version}.source.tar.xz"; - sha512 = "d2b58b520393848c110714537aec2c71d1244d7439c8c62e85bf123a3f3ade3db8a31617c242d9803306f1655237666948aaa55b780f8743ab57fc406a6ea906"; + sha512 = "8e9ccc65a8cd6640171d4891fe8d01435cd524cee8164a5829429df827bcc2b49c3b7e6a092aaf5bfa48140d7f40f6c9cb371af48a7321132ea6ee5da0af08e3"; }; # buildMozillaMach sets MOZ_APP_REMOTINGNAME during configuration, but From 007faa4743c5dea7ed3be69073c24cdfd8a09d94 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 2 Jul 2026 09:23:16 +0000 Subject: [PATCH 32/48] rekor-cli: 1.5.2 -> 1.5.3 (cherry picked from commit a0b5f2b36ef3d4f66cd478bdfd9f1fd6b9569711) --- pkgs/tools/security/rekor/default.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/tools/security/rekor/default.nix b/pkgs/tools/security/rekor/default.nix index 4e080f972acd..056791a8e7b9 100644 --- a/pkgs/tools/security/rekor/default.nix +++ b/pkgs/tools/security/rekor/default.nix @@ -15,13 +15,13 @@ let }: buildGoModule rec { inherit pname; - version = "1.5.2"; + version = "1.5.3"; src = fetchFromGitHub { owner = "sigstore"; repo = "rekor"; rev = "v${version}"; - hash = "sha256-imtdI8nWII2l24FgWXVU0LKg4hYmZHi6DGzenoEfOgA="; + hash = "sha256-GSap3ipl+S7fqm3UX8HJFrLao/5mLG2r7rvSCstmNRk="; # populate values that require us to use git. By doing this in postFetch we # can delete .git afterwards and maintain better reproducibility of the src. leaveDotGit = true; @@ -34,7 +34,7 @@ let ''; }; - vendorHash = "sha256-QxIw3rGTntNpLNhLZq9G6OiuTd+UbjA5B60TYBqFiSY="; + vendorHash = "sha256-kWVuSOVigDEIOteIERIDDlOJmN7NGRMWdRIhtr4qCdY="; nativeBuildInputs = [ installShellFiles ]; From 1f00199a26f4b2b6736a93be0be763771b57284d Mon Sep 17 00:00:00 2001 From: liberodark Date: Fri, 28 Aug 2026 10:31:46 +0200 Subject: [PATCH 33/48] tachyon: add riscv64-linux support (cherry picked from commit 8fc3c3a8caa534abb244f01d94f678c2b011d33f) --- pkgs/by-name/ta/tachyon/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/ta/tachyon/package.nix b/pkgs/by-name/ta/tachyon/package.nix index 23a06adda1db..f18bf083cd27 100644 --- a/pkgs/by-name/ta/tachyon/package.nix +++ b/pkgs/by-name/ta/tachyon/package.nix @@ -46,6 +46,8 @@ stdenv.mkDerivation rec { "linux-arm" else if stdenv.hostPlatform.system == "armv7l-linux" then "linux-arm" + else if stdenv.hostPlatform.system == "riscv64-linux" then + "linux-arm" else if stdenv.hostPlatform.system == "aarch64-darwin" then "macosx" else if stdenv.hostPlatform.system == "x86_64-darwin" then From 95c92c62b0d17ec19289636d72028d4f9242f398 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 20 Aug 2026 21:05:20 +0000 Subject: [PATCH 34/48] rekor-cli: 1.5.3 -> 1.5.4 (cherry picked from commit fe6e99ed0ab9db0f77f965e8ed86269e2e6ca0a6) --- pkgs/tools/security/rekor/default.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/tools/security/rekor/default.nix b/pkgs/tools/security/rekor/default.nix index 056791a8e7b9..b5706a81fb77 100644 --- a/pkgs/tools/security/rekor/default.nix +++ b/pkgs/tools/security/rekor/default.nix @@ -15,13 +15,13 @@ let }: buildGoModule rec { inherit pname; - version = "1.5.3"; + version = "1.5.4"; src = fetchFromGitHub { owner = "sigstore"; repo = "rekor"; rev = "v${version}"; - hash = "sha256-GSap3ipl+S7fqm3UX8HJFrLao/5mLG2r7rvSCstmNRk="; + hash = "sha256-fF48pfbQAHk81aJ4zXDpkY7u5zFmgpr/Fg44kvlmtng="; # populate values that require us to use git. By doing this in postFetch we # can delete .git afterwards and maintain better reproducibility of the src. leaveDotGit = true; @@ -34,7 +34,7 @@ let ''; }; - vendorHash = "sha256-kWVuSOVigDEIOteIERIDDlOJmN7NGRMWdRIhtr4qCdY="; + vendorHash = "sha256-XN+wyWDPep8bdvPMsQFv6I/ULf4cE2/t2NfEFyzE+aE="; nativeBuildInputs = [ installShellFiles ]; From b72c81de0251f2611ca856e98a6fa67d4c2f2a24 Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Tue, 25 Aug 2026 22:57:12 +0200 Subject: [PATCH 35/48] perfetto: init at 58.2 (cherry picked from commit 8f01e9c9eff49d80c4b379e977bbd0e2437e2c1e) --- pkgs/by-name/pe/perfetto/package.nix | 352 +++++++++++++++++++++++++++ 1 file changed, 352 insertions(+) create mode 100644 pkgs/by-name/pe/perfetto/package.nix diff --git a/pkgs/by-name/pe/perfetto/package.nix b/pkgs/by-name/pe/perfetto/package.nix new file mode 100644 index 000000000000..87258b56da60 --- /dev/null +++ b/pkgs/by-name/pe/perfetto/package.nix @@ -0,0 +1,352 @@ +{ + lib, + stdenv, + cctools, + cmake, + fetchFromGitHub, + fetchpatch2, + gn, + ninja, + nix-update-script, + pkg-config, + protobuf, + python3, + re2, + sqlite, + zlib, + zstd, + testers, + validatePkgConfig, + versionCheckHook, +}: + +let + inherit (stdenv.hostPlatform) isStatic isDarwin extensions; + libName = "libperfetto${if isStatic then ".a" else extensions.sharedLibrary}"; + + buildInputs = [ + protobuf + re2 + sqlite + zlib + zstd + ]; + + # pkg-config module name -> perfetto_use_system_* GN arg suffix + systemLibs = builtins.listToAttrs ( + builtins.map (drv: { + name = "${ + if builtins.hasAttr "pkgConfigModules" drv.meta then + (builtins.head drv.meta.pkgConfigModules) + else + drv.pname + }"; + value = drv.pname; + }) buildInputs + ); + systemModules = toString (lib.attrNames systemLibs); + + # Serialize Nix values into GN values, cf. + # https://gn.googlesource.com/gn/+/main/docs/language.md + toGnValue = + value: + if lib.isBool value then + lib.boolToString value + else if lib.isInt value then + toString value + else if lib.isString value then + ''"${lib.escape [ "\"" "$" "\\" ] value}"'' + else + throw "Unsupported type for GN value: ${lib.generators.toPretty { } value}"; + toGnFlags = lib.mapAttrsToList (name: value: "${name}=${toGnValue value}"); + + commonGnFlags = { + is_debug = false; + is_system_compiler = true; + is_clang = stdenv.cc.isClang; + monolithic_binaries = isStatic; + perfetto_use_pkgconfig = true; + use_custom_libcxx = false; + } + // lib.concatMapAttrs (_: gnName: { "perfetto_use_system_${gnName}" = true; }) systemLibs; +in +stdenv.mkDerivation (finalAttrs: { + pname = "perfetto"; + version = "58.2"; + + __structuredAttrs = true; + strictDeps = true; + + src = fetchFromGitHub { + owner = "google"; + repo = "perfetto"; + tag = "v${finalAttrs.version}"; + hash = "sha256-Ipr86zH0iGjMzz9ZM3QEvtA6FlAN4lhkiDgySSeNj5c="; + }; + + patches = [ + # TODO: remove once included in a next release + (fetchpatch2 { + url = "https://github.com/google/perfetto/commit/e698e3903870da0317511334ee21d3ae830ecd66.patch?full_index=1"; + hash = "sha256-L3/xAz1dc3KDZLs7nt7F945ZuvexyWlA9x0YqRNjdIo="; + }) + (fetchpatch2 { + url = "https://github.com/google/perfetto/commit/5739344741e4b881952a2786f67355eefe0a2c8d.patch?full_index=1"; + hash = "sha256-AplecRNDDLGpbYC6zg2Ie0LrX+0MBxodTC72SP6SSl8="; + }) + ]; + # Upstream includes its own tooling to download its deps, we have to disable it to make it use the ones from the PATH. + postPatch = '' + echo '#!/usr/bin/env python3' > tools/install-build-deps + substituteInPlace tools/run_buildtools_binary.py \ + --replace-fail "and sys_name == 'freebsd'" "" + + substituteInPlace gn/standalone/toolchain/BUILD.gn \ + --replace-fail 'default_output_extension = ".so"' 'default_output_extension = "${extensions.sharedLibrary}"' + ''; + + nativeBuildInputs = [ + gn + ninja + pkg-config + protobuf + python3 + validatePkgConfig + ] + ++ lib.optional isDarwin cctools.libtool; + + inherit buildInputs; + + gnFlags = toGnFlags ( + commonGnFlags + // (lib.optionalAttrs (!isStatic) { + extra_ldflags = "-Wl,-rpath,${placeholder "out"}/lib"; + }) + ); + + ninjaFlags = [ + "tracebox" + "traced" + "traced_probes" + "perfetto" + ]; + + dontUseNinjaInstall = true; + installPhase = '' + runHook preInstall + + install -Dt $out/bin perfetto traced traced_probes tracebox + ${lib.optionalString (!isStatic) "install -Dt $out/lib ${libName}"} + + runHook postInstall + ''; + + nativeInstallCheckInputs = [ + versionCheckHook + ]; + doInstallCheck = true; + + passthru = { + updateScript = nix-update-script { }; + + sdk = ( + stdenv.mkDerivation { + pname = "perfetto-sdk"; + inherit (finalAttrs) + src + version + patches + postPatch + nativeBuildInputs + ; + propagatedBuildInputs = buildInputs; + + __structuredAttrs = true; + strictDeps = true; + outputs = [ + "out" + "dev" + ]; + + dontUseGnConfigure = true; + configurePhase = '' + runHook preConfigure + + python3 tools/gen_amalgamated --quiet --system_buildtools --sdk cpp --output sdk/perfetto \ + --gn_args ${ + lib.escapeShellArg ( + toString ( + toGnFlags ( + commonGnFlags + // { + enable_perfetto_ipc = true; + enable_perfetto_pcre2 = false; + enable_perfetto_re2 = true; + enable_perfetto_zlib = true; + enable_perfetto_zstd = true; + is_perfetto_build_generator = true; + is_perfetto_embedder = true; + perfetto_amalgamated_sdk = true; + perfetto_enable_git_rev_version_header = true; + } + ) + ) + ) + } + + runHook postConfigure + ''; + + dontUseNinjaBuild = true; + buildPhase = '' + runHook preBuild + + $CXX $CXXFLAGS -std=c++17 -fPIC -O2 -DNDEBUG $($PKG_CONFIG --cflags ${systemModules}) -c sdk/perfetto.cc -o perfetto.o + ${ + if isStatic then + "$AR rcs" + else + "$CXX $CXXFLAGS $LDFLAGS $($PKG_CONFIG --libs ${systemModules}) ${ + if isDarwin then "-dynamiclib -install_name $out/lib/" else "-shared -lpthread -Wl,-soname," + }${libName} -o" + } ${libName} perfetto.o + + runHook postBuild + ''; + + dontUseNinjaInstall = true; + installPhase = '' + runHook preInstall + + install -Dm${if isStatic then "644" else "755"} ${libName} -t $out/lib + install -Dm644 sdk/perfetto.h -t $out/include + + mkdir -p $out/lib/pkgconfig + cat -> $out/lib/pkgconfig/perfetto.pc << EOF + prefix=$out + exec_prefix=\''${prefix} + libdir=\''${exec_prefix}/lib + includedir=\''${prefix}/include + + Name: perfetto + Description: Perfetto tracing SDK (amalgamated C++ distribution) + Version: ${finalAttrs.version} + Cflags: -I\''${includedir} + Libs: -L\''${libdir} -lperfetto + Requires.private: ${systemModules} + EOF + + runHook postInstall + ''; + + meta = { + inherit (finalAttrs.meta) + homepage + changelog + license + maintainers + platforms + ; + description = "Perfetto tracing SDK (amalgamated C++ distribution)"; + pkgConfigModules = [ "perfetto" ]; + }; + } + ); + + tests = { + pkg-config = testers.hasPkgConfigModules { + package = finalAttrs.finalPackage.sdk; + }; + + examples = ( + stdenv.mkDerivation { + pname = "perfetto-sdk-examples"; + inherit (finalAttrs) src version; + + sourceRoot = "${finalAttrs.src.name}/examples/sdk"; + + __structuredAttrs = true; + strictDeps = true; + + postPatch = '' + substituteInPlace CMakeLists.txt --replace-fail "$( + printf '\n%s\n%s\n' \ + 'include_directories(../../sdk)' \ + 'add_library(perfetto STATIC ../../sdk/perfetto.cc)' + )" "$( + printf '\n%s\n%s\n%s\n' \ + 'find_package(PkgConfig REQUIRED)' \ + 'pkg_check_modules(PERFETTO REQUIRED IMPORTED_TARGET perfetto)' \ + 'add_library(perfetto ALIAS PkgConfig::PERFETTO)' + )" + ''; + + nativeBuildInputs = [ + cmake + pkg-config + ]; + buildInputs = [ + finalAttrs.finalPackage.sdk + ]; + + # The CMakeLists.txt file does not define an install target. + installPhase = '' + runHook preInstall + + find . -maxdepth 1 -type f -executable -exec install -Dt $out/bin {} + + + runHook postInstall + ''; + doInstallCheck = true; + nativeInstallCheckInputs = [ finalAttrs.finalPackage ]; + installCheckPhase = '' + runHook preInstallCheck + + find $out/bin -maxdepth 1 -type f -executable -not -name example_system_wide -print0 | + while LC_ALL=C IFS= read -rd "" bin; do + echo "Running $bin" + "$bin" + done + + export PERFETTO_PRODUCER_SOCK_NAME=$TMPDIR/producer.sock + export PERFETTO_CONSUMER_SOCK_NAME=$TMPDIR/consumer.sock + + traced & tracedPid=$! + until [[ -e $PERFETTO_PRODUCER_SOCK_NAME && -e $PERFETTO_CONSUMER_SOCK_NAME ]]; do sleep 0.2; done + + timeout 60 $out/bin/example_system_wide & examplePid=$! + + # wait until the example has connected and registered track_event + for _ in $(seq 100); do + if perfetto --query | grep -q example_system_wide; then break; fi + sleep 0.2 + done + perfetto --query | grep -q example_system_wide # fail loudly instead of hanging + + perfetto -c /dev/stdin --txt -o $TMPDIR/trace <<'EOF' + buffers: { size_kb: 4096 } + data_sources: { config { name: "track_event" } } + duration_ms: 2000 + EOF + + wait $examplePid + kill $tracedPid + [ -s $TMPDIR/trace ] + + runHook postInstallCheck + ''; + } + ); + }; + }; + + meta = { + description = "Client-side tracing, profiling, and analysis for complex software systems"; + homepage = "https://perfetto.dev/"; + changelog = "https://github.com/google/perfetto/releases/tag/v${finalAttrs.version}"; + license = lib.licenses.asl20; + maintainers = with lib.maintainers; [ aduh95 ]; + mainProgram = "perfetto"; + platforms = lib.platforms.unix; + }; +}) From 244e41ca470de35279a5c6095e4ed457a15d1db2 Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Sun, 19 Jul 2026 00:37:58 +0200 Subject: [PATCH 36/48] tart: 2.30.6 -> 2.36.0 (cherry picked from commit 73dcefbbee92bffffe816fb65034eb01800c54c1) --- pkgs/by-name/ta/tart/package.nix | 18 +++++++++--------- 1 file changed, 9 insertions(+), 9 deletions(-) diff --git a/pkgs/by-name/ta/tart/package.nix b/pkgs/by-name/ta/tart/package.nix index e01a60ea1fe4..f43b6d263222 100644 --- a/pkgs/by-name/ta/tart/package.nix +++ b/pkgs/by-name/ta/tart/package.nix @@ -10,15 +10,15 @@ enableSoftnet ? false, softnet, nix-update-script, - versionCheckHook, + testers, }: stdenvNoCC.mkDerivation (finalAttrs: { pname = "tart"; - version = "2.30.6"; + version = "2.36.0"; src = fetchurl { - url = "https://github.com/cirruslabs/tart/releases/download/${finalAttrs.version}/tart.tar.gz"; - hash = "sha256-wepqDaJp1oRjGqEVrXUM/JO5gfAKc12AUkZUbfwwdx0="; + url = "https://github.com/openai/tart/releases/download/${finalAttrs.version}/tart.tar.gz"; + hash = "sha256-xyqKuNeKZJih5CaIsaHsbFEs5GyjWjo74TDD3hRAx+g="; }; sourceRoot = "."; @@ -39,16 +39,16 @@ stdenvNoCC.mkDerivation (finalAttrs: { runHook postInstall ''; - nativeInstallCheckInputs = [ - versionCheckHook - ]; - doInstallCheck = true; passthru.updateScript = nix-update-script { }; + passthru.tests.version = testers.testVersion { + inherit (finalAttrs) version; + package = finalAttrs.finalPackage; + }; meta = { description = "macOS and Linux VMs on Apple Silicon to use in CI and other automations"; homepage = "https://tart.run"; - license = lib.licenses.fairsource09; + license = lib.licenses.fsl11Asl20; maintainers = with lib.maintainers; [ emilytrau aduh95 From 48fa2a6e099913cea0cb2d00b35ae43644ebf7b2 Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Fri, 28 Aug 2026 16:45:33 +0200 Subject: [PATCH 37/48] corepack: 0.35.0 -> 0.36.0 (cherry picked from commit a636a7b9e0c44959d1e8627ecbfd9c1f922a79ff) --- pkgs/by-name/co/corepack/missing-hashes.json | 82 ++++++++++---------- pkgs/by-name/co/corepack/package.nix | 6 +- 2 files changed, 44 insertions(+), 44 deletions(-) diff --git a/pkgs/by-name/co/corepack/missing-hashes.json b/pkgs/by-name/co/corepack/missing-hashes.json index 24c6f2418318..9633db8ffb5a 100644 --- a/pkgs/by-name/co/corepack/missing-hashes.json +++ b/pkgs/by-name/co/corepack/missing-hashes.json @@ -1,45 +1,45 @@ { - "@esbuild/aix-ppc64@npm:0.28.0": "bedc005d10511c3ee50a02edbb380d3134d34f038cb2638257cb9344aa399276e672c44f7e7eb395a96ccc843e0a5903eb0349f22be30af49ae338ed222d5662", - "@esbuild/android-arm64@npm:0.28.0": "76fa5b984e742b96e427749530e4e973b8da60950163c2dbd766c75ed4f616b7f06d08f01d5b6bd06b6a25cf59b27c3519a4ba343792003b5fcadf463b3d6575", - "@esbuild/android-arm@npm:0.28.0": "b1e649f838c94ebac74e1c10561f010608f7226c0e444b4e178546cf6295bd46d691c52542bbe01598004e638bf9d75ed688b85b6ae31df55f2e2194482733ff", - "@esbuild/android-x64@npm:0.28.0": "9b611b9099d552e755d7b6b28dc39c26aad759ceb9379761a0bf2dfe6077c2437aea784152aefc711166b55c4159f03e6e2f39c1c71ffb923c5ef75c93f7282b", - "@esbuild/darwin-arm64@npm:0.28.0": "09ecf7709c8d86f35624fa9d3475ccb3d1beb9704ddfd71b71adcefc23c3aa8ab95263542bbca52cb0d50f23cf831f468968978969184e1da00dc84cd8c61953", - "@esbuild/darwin-x64@npm:0.28.0": "ba5ab146a8542f093bbe752fe85402894da18b304ae1f08eb455a864f124c61e1e03f8ad18c28eb2b9c1bd930c54dc773ad32b7ab4c7d7eb31f7be04451e74f4", - "@esbuild/freebsd-arm64@npm:0.28.0": "8c05cebfefb0c9f481b52ce8b0290d0e5f6fda17939e27d60d6440c00312a5a10b82ca6e8ddbc19c9a1a2973282c9393958b8ace0512741d76429465d3bdb415", - "@esbuild/freebsd-x64@npm:0.28.0": "da4a620d46b73b610dccfa8c80d110175bb207e0a6bd1bfa96f98d427b3d14bbe54096ccdabaf10fb189a21f6555f7721737106d30ff12933c08ef1aee7adac0", - "@esbuild/linux-arm64@npm:0.28.0": "589f88f21542ff9822fee3f6130051f19e19ec6714abc48d39795b201585c4f0e8dac42ec10a3e61521a4ad499abad5b3a8a8424d871ff5f464b86ba1bae8a65", - "@esbuild/linux-arm@npm:0.28.0": "429f4d7b938f2b72884f472bd9288c91899cacb4bf9c61df293dbe9e3c0368cc1700171cf86c3051df9e6ebdc8c1366db6a573995d327f156de63fd28a23e3a7", - "@esbuild/linux-ia32@npm:0.28.0": "45fcf60da75745f20ec6d98914de1dbb6bd97231a3d9fa1861a47ae43eb7db23780696530d17d68ee55693d189672b763cbdb9d0ad1ee5429ee9c7168a23dce8", - "@esbuild/linux-loong64@npm:0.28.0": "d7a5710068e5909661f48c276d82c836b9b6131076e550c83d83e63db3f2538ecd3a3694dcbf8129bb773f7ca580b2fbef38ec15b9028d246cbc0e77a1a5946c", - "@esbuild/linux-mips64el@npm:0.28.0": "1aa72c485a56cf432748b8e0527e86a88deda0574e13d914dbe657dc2878ecc8b441783bd6c1582c0359b5a33d30216c0c94b3c9c17e5ca975fe6aa4b80aaa2c", - "@esbuild/linux-ppc64@npm:0.28.0": "306bf03b0f6fd738bf74d9dfb23b8937227521b832fd901994600691b1f1fadb698a67a9990713b72ca1114715f82f0df35877281945e81b824ed437bf432742", - "@esbuild/linux-riscv64@npm:0.28.0": "c09c0f0ada23a3e55767586f3a341958c071d0b9adfe5460986e5e69f7397dfe2e37e2896a1c61092cececa929241d37f19b75ed608f5f00d535cd3b24c4ef1f", - "@esbuild/linux-s390x@npm:0.28.0": "40a939574f16362a5c9f1f82c20a8d82686efcf5f77e4b6c7e5c05bdcc596d8ce2ca188e6e7fa4772d4167bd18da630a3a3b3b70aa28308d3a9d1d48ff112feb", - "@esbuild/linux-x64@npm:0.28.0": "cde673ae0b9945bdc665c68b2df7ebe39d37bcd388c8e607ed4d369e7b6123ecdf3d1feb097ae13403d83c15952cb952d16f96146fa1a52405f09ec0e438d0f6", - "@esbuild/netbsd-arm64@npm:0.28.0": "c9738a8c3cfb817d9fbb46aa52fa532a0a74dc6d7d4e260e1eb8fd0acf729208932ce7f43e2c2dbf6cb1ca21f5db55f329936f81ae871953ff0e67e42d8eb362", - "@esbuild/netbsd-x64@npm:0.28.0": "c0be9ca72b5c18279e02e63a17a7fef428395f48fc1e0e251622c3cfe8a70b15cfb0bb814d355318917461a4e20d11723b837f6e4d1f1c0ce44e915ff80b3047", - "@esbuild/openbsd-arm64@npm:0.28.0": "fda84f2526cb29d943047f68e725c688e4a89ebcbc224e19ddc3479509783cd254e581b19c8fad1a28e55e193512f37842252f36b06b3df2c005a0dbca0a0d84", - "@esbuild/openbsd-x64@npm:0.28.0": "7a67881986611c0b851c246c2ccdb445ecc5e587c70efae0165cd963d149ebfec3a7b6820338cf38dc70cee95fbd17e80dcb636c7f1de113c9a85dfe867a0d97", - "@esbuild/openharmony-arm64@npm:0.28.0": "8cd175332efcedc6b69a980410426cbb7c76ed264f28cbf16cc807938e29f39c03353901179a88655377c39db1860d9df5c76294f2624a2db75b387334e9baa3", - "@esbuild/sunos-x64@npm:0.28.0": "99820c945c05651182afe4ec5a1bad80790775acefa403f25ad48ed9638efc573f3bf6fabdd273556854c609990a8a0c8fda7b140edabe3322d6a3ea77734d9c", - "@esbuild/win32-arm64@npm:0.28.0": "84314f636841e4568e4960e4ee50e66c5d4d74fc274d256f3c903904186014bed197316c8bedb3c38f9855ca8ad9c4ecc1c6e64df4c40ea6cd5f4cb7739ab66c", - "@esbuild/win32-ia32@npm:0.28.0": "41296dae0b5e74ca689460cd510cb88df7b92d0c027130c373138e09847dd48eb685c2c825f36337a7bff7c6eceba2cb75b7f4f76d78e140504159a59e2feb89", - "@esbuild/win32-x64@npm:0.28.0": "f2d53b57cb338ddf0bbfb5eb64dc95bd0b686817eee8ab2307085c04f18e1d9d5b27e1b74f327cd46a8f246e3df9fc6ee9158ab9977255b7d4a511d438e411de", - "@rolldown/binding-android-arm64@npm:1.0.1": "47696e8b2ccd0f243f742353bd59ab6ba9730c139d26761ca273800236a022466caafb6b28def7cda5309cee464fe4fabb8d7d356453f794c91c6c4a60cc3d20", - "@rolldown/binding-darwin-arm64@npm:1.0.1": "fff9883fa91eae1f5d40b3ef2608fb0bae33d3b178e886627bd7b6e4a621fddf7db6afdd8435b57f0f85b56fdfe84b2a299eea39ed50bfd1683df5da2d5603bd", - "@rolldown/binding-darwin-x64@npm:1.0.1": "ab8fdfd5cb08ffa6c01c5fd7ba5866a57a81f0cb129dae21ad8260a57bf166684475964fee1209c20a522d57d16c6d95ee4c29936371deb2ae40abe73ab2d1c4", - "@rolldown/binding-freebsd-x64@npm:1.0.1": "c43d4f0a46a9bf1ec23474bd38369080e1e69168385241555958f78103c602ba892008848ad6a7ff0fc77a5c3dd535e5fd74f8b32e2da64a2d65fc8001df5564", - "@rolldown/binding-linux-arm-gnueabihf@npm:1.0.1": "594c3e1bc4e16cc5ff5901c320f2bd84a3e613cd8581ae488650cca022350e3d7cceeb6bd831c4dabe74d2541a6c355ae7f99d08ed018443c75f6cd08fc92059", - "@rolldown/binding-linux-arm64-gnu@npm:1.0.1": "78b4c350ec41e385ac0f5b5cb07fdc4f1660e6ef7615f17c18589f309bff4e9423dc738a18e5ee662c2a58e951688976e7941a749a25a36aeec7a8971cf77448", - "@rolldown/binding-linux-arm64-musl@npm:1.0.1": "1c3abd853331b4a21a6aed91be19c7efecf47fed12e332a2209218e8bed0ab613f6cdbe531ced73e54ca79833fb3333ab5a111fb9f9557877a44187bca097f5c", - "@rolldown/binding-linux-ppc64-gnu@npm:1.0.1": "fa0e84291d5b15e729ad7345efe25317a57b7e57592903bb69cf851fefcb9996d5bee1f3992741cb6dc7d69cbb60cf5fb55762d77e8b67ced356b965d04242a4", - "@rolldown/binding-linux-s390x-gnu@npm:1.0.1": "a3e8baf077c063943743926807a3aa3a8beafb13738e849f2873bb585a65156134fe10201cd85dfe159d8f7f0b4ca75417c6581f5e8958a0b9d9330ea03942ae", - "@rolldown/binding-linux-x64-gnu@npm:1.0.1": "ba3919ec184935b8583d288bb6308003eaa56ba120acc6aaa3803891c45d335b28bd193aaf16bf3b2b013ae5c0be8f80922c527a2902dcae976f6a1f6718a713", - "@rolldown/binding-linux-x64-musl@npm:1.0.1": "c537717d76a6eb60889ed700575b48f32ba443314587e0617b5e364f3d204fbaaa5e990ec6b62b192226b4c5b9bb780b62bbbe64be2ccb60ecce6fb233123f9c", - "@rolldown/binding-openharmony-arm64@npm:1.0.1": "5d140313e75fa95556cd1b0de06b662b7c28af3c094640934017f58141de3648ed00064d7412e1f67a39c5a40ba023d6adcd584f2eaa45b6a1cbf912da52abda", - "@rolldown/binding-wasm32-wasi@npm:1.0.1": "078f9af1c6aba8c6c687cd5ccc10e93ff60de4e0297dafaa3f9c081cbaa603c029b9feb2fad0b2b3a8ffb82dad6bdb111e73e66082f09ea7a6e7e68e39304105", - "@rolldown/binding-win32-arm64-msvc@npm:1.0.1": "453ba3fe5629f25c444059988d14e0b5691df2a2607433f8674374eb5cf2e0e11345d33676f7d1a79fe1d819ab7685d96afe95582a465540a6b0af2fb4d4808a", - "@rolldown/binding-win32-x64-msvc@npm:1.0.1": "8eb2a1fa72497d1c5d947c0ecca6e13e37f065e2953f4be26a6a6b681b5eb3b51cd160ea0aca3fbaf565f4170f009951054adaf79bf24497d904d57ec703ae74", + "@esbuild/aix-ppc64@npm:0.28.2": "532f5b55262aef55e92cc60014f5dbb016122d84c85a5369d715035f1d18e47d916a292cb63673e52aca3c463b3829ad6adb257d5f7d7228a6fb55ed144fdf00", + "@esbuild/android-arm64@npm:0.28.2": "3cac1f07c479ac5fc35406e208189734c997253a1cbce64112549ce766ae884f10ea5b2bcddf9932c8f8f61f7eb7904c74f49444c4e58d1bf9e76d389227a26c", + "@esbuild/android-arm@npm:0.28.2": "e72d53f09d78b28cff55dbafb5635fa1c9327047cff9218991be2869f2adcfbee9d405109b66411ca2b6501273002ed2c41e2c82c985aec72b4dd6ddc755090f", + "@esbuild/android-x64@npm:0.28.2": "a42c252316c4750d622781e313065bff9da6924a98fba8e9e70aacd043387bc445115bf2d0dfa8176253ab7033e40597114b86c5794135aef9d96bfe2058e799", + "@esbuild/darwin-arm64@npm:0.28.2": "eaddd98934ea667dd0573a87376a77ed38d5256e8976a9f9d2612c22d795b08dc08015fe5b57dccca67b91578a7defd27bad1864a6feb4b39e1773dd837033a6", + "@esbuild/darwin-x64@npm:0.28.2": "7e10c00ebd47ae17987f09f0c95e7a98306f9fff19277d9755e2d808c4a83055a624e9c71b8672dac4373effb0f20f3548e877a2f2b44af4de0af72c036cdb0a", + "@esbuild/freebsd-arm64@npm:0.28.2": "f17cdd3604a23e9dcb486a80fd4f197f57d9870e78d9c2b255a0b74bff3c624b4811dd9b18db0be43543c99d503069b51932c16dc70d001672f8117905f3e514", + "@esbuild/freebsd-x64@npm:0.28.2": "e01ca12c86ff619cd3eae254ace2c8ce49d11cd879a2e77db1cc4e4b1419f84c8f9e887e6607f41349169fa23825c3406559547b95b2fef3f422658f028da4aa", + "@esbuild/linux-arm64@npm:0.28.2": "2a9c1a66a43bfcf36105f7dac5f9c169237b3b18463d822d7278c52b8414483e66f9ea669f8c49dab39af2dd91dfefa8c93943fc7e91c770d44dda09f6824923", + "@esbuild/linux-arm@npm:0.28.2": "5a913524b3b36063d37af3757f8b74f3b8528c82949c6595dd2a951650d5b69f04552362c3e32b546e851e84129df2a311815844efbf37b60dae47f92374c998", + "@esbuild/linux-ia32@npm:0.28.2": "e68de896188c417a0582117919b1bed47b2b235358ed1836fb8c17a214afb178d4f54dbdbe724eed990d8d2d2c1c391088cfd6637cdd0432062d2c3981b49213", + "@esbuild/linux-loong64@npm:0.28.2": "1adac09caf8ba573fa2fd4eaa34e720e439df0d17d2805d5c57fcafc01ab9e94a14d3457eafbe306629cd027028dafacc77e25a4f2730ae0602664ef5ef92695", + "@esbuild/linux-mips64el@npm:0.28.2": "6ce3422c183387a9126138f11d8143cdb94056658e4c007168e7801d5bda1947500fc9b6f671416e68e13afb762033021ec76b16fbdb9d75730593784d5b0229", + "@esbuild/linux-ppc64@npm:0.28.2": "4d772c34b72c5a5f35635204dd630ea560fc5a4ac06c5c0de247472adb8e6cfa170da0de9cc02421608d6c36463826097ea5630c2d66964ef4d49b3e7d918b62", + "@esbuild/linux-riscv64@npm:0.28.2": "3b2c61ec50b9af8079e72ba68cd130aa67113bbb039ae0bd07451ab34ca07cbfdc7175fea4ed3b8918fbce36f5a49056d8c1683f36e66aa3d884f4eb0159c116", + "@esbuild/linux-s390x@npm:0.28.2": "ee2520a6dee59461cd71f94b5ffbf238283e850defdfe4c25cdee3600e8c728f88d886233d92f3cac2371f647cb519a62af30899848ff0a9e4df3525a85d00b5", + "@esbuild/linux-x64@npm:0.28.2": "5e2ebf6534f2eaba70d67906aedc59ae84d763b07af9738a2a45adb44bd51ec2298dc94d2447e9d60dee8f6e2d58e137bd0f7e53435436f123bda1cfcf2fd0ce", + "@esbuild/netbsd-arm64@npm:0.28.2": "f4559f1abcb85732d71b6f123555eec54373cabfc2ed7c4d56ea9c10b6c262d30f1a1867ddb55e1b6f77414ee85594768e3d243f9d57eec09c72b67d6a37cd4c", + "@esbuild/netbsd-x64@npm:0.28.2": "852010db3be0e867a556f156f9fea93f33d9bf2b53164a584d212cbb972fda18b6f094f7886f08b68c66958909dccf3ef33e5f70cfe6cc71cc17ee3a92015ad0", + "@esbuild/openbsd-arm64@npm:0.28.2": "cc528c9b126d8aa3633faf07f796b9e380d85d309f5499d3f075a9da86a60a2a61c73f42dcdb5577442a4d9af07d22ed7f6b844665c1f6373a15730c75b68c90", + "@esbuild/openbsd-x64@npm:0.28.2": "ede88d45016e3dd3c77a49657c5608feb1331bcf1e0b7bfb2bfd87d07b687e5d687ffce962ac7e55a5a29b83e5824c91611406e3cd9317b6efed53b6e8f442bc", + "@esbuild/openharmony-arm64@npm:0.28.2": "7b8b3c8baf73151a473878b9d40fdd87f86bee4a9b28325f4f0ece236a0f98fad7b393d1b5f12268b7c122fbcfb3872c1467cabd4745cf8698a78b60241138cc", + "@esbuild/sunos-x64@npm:0.28.2": "f70b672bb0c8179d92e87077fcfea60b0971f8071830f574c85ef1706a6770deaa31f28adf3c1a08506403e9735d81a4e28e5d2ad1c3cbc15af2433112dceb4b", + "@esbuild/win32-arm64@npm:0.28.2": "9aa6841164e80b4d77fd267a9cd160be46586ea561fcb6d99507989856682dbdc007ab2d3c320787ea50ec0a2c1802395dc6c3cd4b254eb5ddac8a3a7705c319", + "@esbuild/win32-ia32@npm:0.28.2": "51d216d2a9cdc1ae2407ac88c4ea02be5b5cc9c618cfd846946b5691f9513de762e6a718222c3de02b14426b4939e040c98de7d424994837bed6ecbb1347b9ff", + "@esbuild/win32-x64@npm:0.28.2": "b109c1080e6ff5fcd9da0c61a6915d296837702234609b737284c01c38cc3a245caa351702da27114ae9cd17c4a577a5674375c4138269f63a578e46f6686066", + "@rolldown/binding-android-arm64@npm:1.0.3": "35e2b7f9e54c526cee5433351b0ef376dd1657d8a6eecf00512dec4720bb02594268bf8d3b661199917bdd286d4370bf3c3461b08eb74f0eae77bd13585e260a", + "@rolldown/binding-darwin-arm64@npm:1.0.3": "7e7d168d091053100a785c0240d6d6134039bf0fb7a658624fa33426b148e9b8131d1690729b32a7b1e65329879c15601b7afd576e149ca6feb6302c530ed860", + "@rolldown/binding-darwin-x64@npm:1.0.3": "0721c045d1446138e49dca250c8716c1b2eb4f1595bf1226a2c273befa063f91c4623e4cd5d338e969626e4281541b958c4a3d4649c0c553da0ec42292450a8d", + "@rolldown/binding-freebsd-x64@npm:1.0.3": "faa48a73ac1b1a4af8ed7b67932a59b62f139d76f21d1ccbe5efb5ab8a5a61e1f5de0b5d9367a9ecd8759bdab3aa1734aefd2214bbe2cfc4b0cb119f6e5391da", + "@rolldown/binding-linux-arm-gnueabihf@npm:1.0.3": "fab607d7639bf6d3393f6e0da0c9680e2d357b550abc50d7dc60cd45e25c788cddee38deac074d9c987e22532d83dcd8a76564710654663bd65622a190548c72", + "@rolldown/binding-linux-arm64-gnu@npm:1.0.3": "a067fc8d80a6af88893010abb55d697221afa8f9d3f468082bc759305f2decbf16f8655a5313e6e608d1b2f103d28922607290ab85d575b78930bc9daa777204", + "@rolldown/binding-linux-arm64-musl@npm:1.0.3": "b1264d8302780c991260991733cf156c1ed43fed66fce60e5a265577aced196b92907cfcbe8d3262621b8e08106f1f555743c601fe60676c08ffae0edd821128", + "@rolldown/binding-linux-ppc64-gnu@npm:1.0.3": "82f33061f5003b99bac68a0637bf7665f6fb2b22cfc025e4d7762afefe703af2acc1cd2df8ff07bb000b0eecd3e59959992481a5b03794604af090eaa843c70f", + "@rolldown/binding-linux-s390x-gnu@npm:1.0.3": "a6a3811352aa5db6a793879bf405bb98eaeca06cfd1aae959a9ed70db39b28e0a022ca50524cdd26d0447fa7b9c5ef913281cf543f816ac6e3ea6b6d620af88a", + "@rolldown/binding-linux-x64-gnu@npm:1.0.3": "13ece4e580f022a1a70031da2036448097bc38d040d1e87ee81cffd9e1ab8b64673e92843718470e3d07ea664171dc2c20d766cbafbb0ca8774e3c4f0b122c7d", + "@rolldown/binding-linux-x64-musl@npm:1.0.3": "6beeffe835e820679868021e01fb629fe124813911dd625bd3d24b1592450c06131b360e284396aca04798e6a85f988917ea00e95b3ea087a32a45441bad3235", + "@rolldown/binding-openharmony-arm64@npm:1.0.3": "f8e8352edde4d2345e3e360bb050915daf0d9ee4c491024a08e56088801994f2cbdf0152f81115a089c1870863e6384135765126114cf8481933bc15678e1dde", + "@rolldown/binding-wasm32-wasi@npm:1.0.3": "3f73081fc41cbd8c117183fecb0f491a71278472c0640b54e57a3a6705005f54d7997c610244d2ff651d5d688a20596ab1119e3dccf607f59fdea4ec0621da49", + "@rolldown/binding-win32-arm64-msvc@npm:1.0.3": "a29f05721b276acdeb7f00b43b9c6241f9c4cc60b820d6b9217d205cfd0ee66a82a29da501e60163c66ce7cc8cb6362f88933b466dea66e3219b38d15954873e", + "@rolldown/binding-win32-x64-msvc@npm:1.0.3": "d6afa484d89c9479561a0621709dfc9737584515f87e96fa74f7d153bbde74f81b6ba7aac92187189ffb4dd1795fa152c596a04ae9a41ffab7437babc5a15838", "lightningcss-android-arm64@npm:1.32.0": "1cb326ad39dcb02cf9f45025c167b6900e3a04b08f5149d3c5ee26054b00d08db3736fb69183a6c3ed1cb32dddd148608c784b6631b4777623f7dd0c032c392d", "lightningcss-darwin-arm64@npm:1.32.0": "da954d0c215d0e95f15a92c8717f871017586e1332b98fd40e96196571d2fd3d51a727dc530768afee9f6a04da210510740574dd0c8dbf2ecced79e5996f1a06", "lightningcss-darwin-x64@npm:1.32.0": "b1d298c9173f839e8447d1917ed8bc5ab098ed0fc4e4b419d36ac5afe8b27bf21cb47d00a35c3d2edadcac598086e9b4f26c992a809d79f9681d6865a230d79e", diff --git a/pkgs/by-name/co/corepack/package.nix b/pkgs/by-name/co/corepack/package.nix index 721dd6134500..2186a8651d51 100644 --- a/pkgs/by-name/co/corepack/package.nix +++ b/pkgs/by-name/co/corepack/package.nix @@ -15,13 +15,13 @@ let in stdenvNoCC.mkDerivation (finalAttrs: { pname = "corepack"; - version = "0.35.0"; + version = "0.36.0"; src = fetchFromGitHub { owner = "nodejs"; repo = "corepack"; tag = "v${finalAttrs.version}"; - hash = "sha256-VgiQ4k6HiRxemtizItL0zkTDpgTnL0ScfSOfgjMpokI="; + hash = "sha256-oa/4Zjw1UIOt/mTPiBGSKhokDMoBMwhrKi7l3qcKqkI="; }; nativeBuildInputs = [ @@ -40,7 +40,7 @@ stdenvNoCC.mkDerivation (finalAttrs: { missingHashes src ; - hash = "sha256-Q7vUJrFUr8ZbDdaMZq8fnJFfIgEFYkHQiUoo2xILaKo="; + hash = "sha256-LAzlLQUmjdxg/NNHgCwVK499RM6p/8csrHow6UAMJUY="; }; postPatch = '' From 8ebe3f8a7397ed5ddd5ac0189b7c4ee9ee2ac9d3 Mon Sep 17 00:00:00 2001 From: "Adam C. Stephens" Date: Fri, 28 Aug 2026 10:21:53 -0400 Subject: [PATCH 38/48] beamPackages.elixir_1_20: 1.20.3 -> 1.20.4 Changelog: https://github.com/elixir-lang/elixir/releases/tag/v1.20.4 (cherry picked from commit e5dfc50fe7912fc99e39421f48d03656f16f168b) --- pkgs/development/interpreters/elixir/1.20.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/interpreters/elixir/1.20.nix b/pkgs/development/interpreters/elixir/1.20.nix index 73108fed86f0..22d2279d095b 100644 --- a/pkgs/development/interpreters/elixir/1.20.nix +++ b/pkgs/development/interpreters/elixir/1.20.nix @@ -1,6 +1,6 @@ import ./generic-builder.nix { - version = "1.20.3"; - hash = "sha256-60DlK+yocWcKnxcOtUOkRO69scaY35AADoKFCCF6QfQ="; + version = "1.20.4"; + hash = "sha256-Z/lAmD3wyiTnX2e7n2gHELkTpZ3AgGSjqNmvDxCH91g="; # https://hexdocs.pm/elixir/1.20.3/compatibility-and-deprecations.html#between-elixir-and-erlang-otp minimumOTPVersion = "27"; maximumOTPVersion = "29"; From eb51b86de12a849499f2c206dcbd7e8bd8a582de Mon Sep 17 00:00:00 2001 From: "Adam C. Stephens" Date: Fri, 28 Aug 2026 10:22:25 -0400 Subject: [PATCH 39/48] beamPackages.elixir_1_19: 1.19.5 -> 1.19.6 Changelog: https://github.com/elixir-lang/elixir/releases/tag/v1.19.6 (cherry picked from commit 9c10a49b425caa96b29e9070936a6b14239e40d2) --- pkgs/development/interpreters/elixir/1.19.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/interpreters/elixir/1.19.nix b/pkgs/development/interpreters/elixir/1.19.nix index 48694f1dc661..bcf0508f189e 100644 --- a/pkgs/development/interpreters/elixir/1.19.nix +++ b/pkgs/development/interpreters/elixir/1.19.nix @@ -1,6 +1,6 @@ import ./generic-builder.nix { - version = "1.19.5"; - hash = "sha256-ph7zu0F5q+/QZcsVIwpdU1icN84Rn3nIVpnRelpRIMQ="; + version = "1.19.6"; + hash = "sha256-IpC1w3vKCKvEtmYqeYScChNWL7RXn/PjypUnLQt7IZc="; # https://hexdocs.pm/elixir/1.19.5/compatibility-and-deprecations.html#between-elixir-and-erlang-otp minimumOTPVersion = "26"; maximumOTPVersion = "28"; From 044f8ed32d3ae84cc0331ebc5b5e778a9f556920 Mon Sep 17 00:00:00 2001 From: "Adam C. Stephens" Date: Fri, 28 Aug 2026 10:23:06 -0400 Subject: [PATCH 40/48] beamPackages.elixir_1_18: 1.18.4 -> 1.18.5 Changelog: https://github.com/elixir-lang/elixir/releases/tag/v1.18.5 (cherry picked from commit 6f8d036c58b3d45b8c88f0091b4e316c6ed713ee) --- pkgs/development/interpreters/elixir/1.18.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/interpreters/elixir/1.18.nix b/pkgs/development/interpreters/elixir/1.18.nix index 20779a12fcdd..12180f1ab732 100644 --- a/pkgs/development/interpreters/elixir/1.18.nix +++ b/pkgs/development/interpreters/elixir/1.18.nix @@ -1,6 +1,6 @@ import ./generic-builder.nix { - version = "1.18.4"; - hash = "sha256-PwogI+HfRXy5M7Xn/KyDjm5vUquTBoGxliSV0A2AwSA="; + version = "1.18.5"; + hash = "sha256-C7RXBjZZbdSgz4jdoOCKv8xfM95ChrYjXIIS/ahX+3Y="; # https://hexdocs.pm/elixir/1.18.0/compatibility-and-deprecations.html#between-elixir-and-erlang-otp minimumOTPVersion = "25"; } From 9b0eb58f73bad7d19008ae3256c533a1cbbc3f66 Mon Sep 17 00:00:00 2001 From: Defelo Date: Fri, 28 Aug 2026 18:14:24 +0000 Subject: [PATCH 41/48] radicle-node: 1.10.1 -> 1.10.2 Changelog: https://radicle.network/nodes/seed.radicle.dev/rad:z3gqcJUoA1n9HaHKufZs5FCSGazv5/tree/CHANGELOG.md (cherry picked from commit ffc3e33e210f02959bc35edbaa528e738c540932) --- pkgs/by-name/ra/radicle-node/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ra/radicle-node/package.nix b/pkgs/by-name/ra/radicle-node/package.nix index a1b450ae3617..57693efa42b3 100644 --- a/pkgs/by-name/ra/radicle-node/package.nix +++ b/pkgs/by-name/ra/radicle-node/package.nix @@ -15,9 +15,9 @@ xdg-utils, versionCheckHook, - version ? "1.10.1", - srcHash ? "sha256-F+64o9z/al0iaLFyQHAYk/3jjf5T0FdgqaU3nEWIheg=", - cargoHash ? "sha256-TLffetbkVwIbUDoI+96T99+lfYu2SIpGtwC0DbuJXnU=", + version ? "1.10.2", + srcHash ? "sha256-dlF1aoWqqGsSCTarT/8xl/WH8Hs9vAlk0BSQoGj1TR0=", + cargoHash ? "sha256-X+/SWtRToZHjJ1Eha3bbYNYAzEvJdX4bAOrl5G5vYU8=", updateScript ? ./update.sh, }: From 57f65e318576f42d8b15b53f89e76cb17896bf81 Mon Sep 17 00:00:00 2001 From: Defelo Date: Fri, 28 Aug 2026 18:14:40 +0000 Subject: [PATCH 42/48] radicle-node-unstable: 1.10.1 -> 1.10.2 Changelog: https://radicle.network/nodes/seed.radicle.dev/rad:z3gqcJUoA1n9HaHKufZs5FCSGazv5/tree/CHANGELOG.md (cherry picked from commit 738c90e975a9f7aceda8f276905c45094e237289) --- pkgs/by-name/ra/radicle-node/unstable.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ra/radicle-node/unstable.nix b/pkgs/by-name/ra/radicle-node/unstable.nix index e4b98a70f3be..5f5a451c5c94 100644 --- a/pkgs/by-name/ra/radicle-node/unstable.nix +++ b/pkgs/by-name/ra/radicle-node/unstable.nix @@ -1,8 +1,8 @@ { radicle-node }: radicle-node.override { - version = "1.10.1"; - srcHash = "sha256-F+64o9z/al0iaLFyQHAYk/3jjf5T0FdgqaU3nEWIheg="; - cargoHash = "sha256-TLffetbkVwIbUDoI+96T99+lfYu2SIpGtwC0DbuJXnU="; + version = "1.10.2"; + srcHash = "sha256-dlF1aoWqqGsSCTarT/8xl/WH8Hs9vAlk0BSQoGj1TR0="; + cargoHash = "sha256-X+/SWtRToZHjJ1Eha3bbYNYAzEvJdX4bAOrl5G5vYU8="; updateScript = ./update-unstable.sh; } From e2adcc81df804a7ac44f8975d9b232f193ddaf8b Mon Sep 17 00:00:00 2001 From: Hythera <87016780+Hythera@users.noreply.github.com> Date: Thu, 27 Aug 2026 22:05:03 +0200 Subject: [PATCH 43/48] librewolf-unwrapped: 154.0.1-2 -> 154.0.1-3 diff: https://librewolf.dev/librewolf/source/compare/154.0.1-2...154.0.1-3 (cherry picked from commit ad1e50ed00a2499b95f011e45f2e973c05b2f96a) --- pkgs/by-name/li/librewolf-unwrapped/src.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/li/librewolf-unwrapped/src.json b/pkgs/by-name/li/librewolf-unwrapped/src.json index 4445eca55ee4..a71744ec77d5 100644 --- a/pkgs/by-name/li/librewolf-unwrapped/src.json +++ b/pkgs/by-name/li/librewolf-unwrapped/src.json @@ -1,8 +1,8 @@ { - "packageVersion": "154.0.1-2", + "packageVersion": "154.0.1-3", "source": { - "rev": "154.0.1-2", - "hash": "sha256-cwPJzF9kvbVGAB8lBJSTCoP26k1EKQUKGbngsKmdtt0=" + "rev": "154.0.1-3", + "hash": "sha256-IPV+/5NCyoLYaRD5N6bu4doI6R4yxs4cBw8UrJP3E4U=" }, "firefox": { "version": "154.0.1", From 8b6a7577cb68942cc99a8a95baaf68702f001a1b Mon Sep 17 00:00:00 2001 From: Jappie3 Date: Fri, 28 Aug 2026 20:45:19 +0200 Subject: [PATCH 44/48] dovecot: 2.4.4 -> 2.4.5 (cherry picked from commit e00ab80292bb48173cf884876c878d005c9bb2ff) --- pkgs/by-name/do/dovecot/fix-lua-build.patch | 28 --------------------- pkgs/by-name/do/dovecot/package.nix | 5 ++-- 2 files changed, 2 insertions(+), 31 deletions(-) delete mode 100644 pkgs/by-name/do/dovecot/fix-lua-build.patch diff --git a/pkgs/by-name/do/dovecot/fix-lua-build.patch b/pkgs/by-name/do/dovecot/fix-lua-build.patch deleted file mode 100644 index 23d2dcb9bcd3..000000000000 --- a/pkgs/by-name/do/dovecot/fix-lua-build.patch +++ /dev/null @@ -1,28 +0,0 @@ -diff --git a/src/auth/Makefile.am b/src/auth/Makefile.am -index 7474e76fb6..e7fc4aad0f 100644 ---- a/src/auth/Makefile.am -+++ b/src/auth/Makefile.am -@@ -21,12 +21,11 @@ LUA_LIB = - AUTH_LUA_LIBS = - AUTH_LUA_LDADD = - if HAVE_LUA -- -+AUTH_LUA_LDADD += $(LUA_LIBS) - if AUTH_LUA_PLUGIN - LUA_LIB += libauthdb_lua.la - else - AUTH_LUA_LIBS += $(LIBDOVECOT_LUA) --AUTH_LUA_LDADD += $(LUA_LIBS) - endif - endif - -@@ -200,7 +199,7 @@ endif - endif - - if HAVE_LUA --auth_libs += $(LIBDOVECOT_LUA) $(LUA_LIBS) -+auth_libs += $(LIBDOVECOT_LUA) - endif - - if AUTH_LUA_PLUGIN - diff --git a/pkgs/by-name/do/dovecot/package.nix b/pkgs/by-name/do/dovecot/package.nix index aae29eb5e8fd..f347a23e3573 100644 --- a/pkgs/by-name/do/dovecot/package.nix +++ b/pkgs/by-name/do/dovecot/package.nix @@ -1,9 +1,8 @@ import ./generic.nix { - version = "2.4.4"; - hash = "sha256-vy0R8TWQQ3BSOyTtWoa65CYgUfsJqkIU6QfnnzaqrI4="; + version = "2.4.5"; + hash = "sha256-oZ9wmfsKSr54DB9NebRl+atuDrCL3johkskY6M1Hxmg="; patches = _: [ # Fix loading extended modules. ./load-extended-modules.patch - ./fix-lua-build.patch ]; } From dd9df3bdf4ed047bf3cb980d34bce2f656f287ff Mon Sep 17 00:00:00 2001 From: Jappie3 Date: Fri, 28 Aug 2026 20:45:19 +0200 Subject: [PATCH 45/48] dovecot_pigeonhole: 2.4.4 -> 2.4.5 (cherry picked from commit 0b1eed78e426afeeb14715ba8443e93225a77551) --- pkgs/by-name/do/dovecot_pigeonhole/generic.nix | 2 ++ pkgs/by-name/do/dovecot_pigeonhole/package.nix | 4 ++-- 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/do/dovecot_pigeonhole/generic.nix b/pkgs/by-name/do/dovecot_pigeonhole/generic.nix index 29367dd72364..9c844d4ffed8 100644 --- a/pkgs/by-name/do/dovecot_pigeonhole/generic.nix +++ b/pkgs/by-name/do/dovecot_pigeonhole/generic.nix @@ -11,6 +11,7 @@ fetchzip, dovecot, openssl, + pkg-config, libstemmer, perl, python3, @@ -45,6 +46,7 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ dovecot openssl + pkg-config ] ++ lib.optional (isCurrent && stdenv.hostPlatform.isDarwin) libstemmer ++ lib.optionals withLDAP [ diff --git a/pkgs/by-name/do/dovecot_pigeonhole/package.nix b/pkgs/by-name/do/dovecot_pigeonhole/package.nix index 6ac3253e96bb..59cc7980116a 100644 --- a/pkgs/by-name/do/dovecot_pigeonhole/package.nix +++ b/pkgs/by-name/do/dovecot_pigeonhole/package.nix @@ -1,12 +1,12 @@ import ./generic.nix { - version = "2.4.4"; + version = "2.4.5"; url = { version, dovecotMajorMinor, }: "https://pigeonhole.dovecot.org/releases/${dovecotMajorMinor}/dovecot-pigeonhole-${version}.tar.gz"; - hash = "sha256-KZjV0aSDGNJCmEaovaeUy4P8rQQFHBBk5E3vWL3MqNw="; + hash = "sha256-pDvpoE9SRoOB0Nh3cczsILc4N7fnPzpFvfr2+cKZR4M="; patches = fetchpatch: [ # https://github.com/NixOS/nixpkgs/pull/388463#issuecomment-3066016707 (fetchpatch { From a16dfe2b9bcb5215f21dd27bb44cbde6fd27733d Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 18 Aug 2026 00:50:13 +0000 Subject: [PATCH 46/48] radicle-explorer: 0-unstable-2026-07-29 -> 0-unstable-2026-08-12 (cherry picked from commit 700d2bcd6d1553f4fd68366755e05b751a6e256d) --- pkgs/by-name/ra/radicle-explorer/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ra/radicle-explorer/package.nix b/pkgs/by-name/ra/radicle-explorer/package.nix index b142b8e46858..0a8771981f0e 100644 --- a/pkgs/by-name/ra/radicle-explorer/package.nix +++ b/pkgs/by-name/ra/radicle-explorer/package.nix @@ -23,13 +23,13 @@ in buildNpmPackage (finalAttrs: { pname = "radicle-explorer"; - version = "0-unstable-2026-07-29"; + version = "0-unstable-2026-08-12"; src = fetchFromRadicle { seed = "seed.radicle.dev"; repo = "z4V1sjrXqjvFdnCUbxPFqd5p4DtH5"; - rev = "427cece9850944d30f0d49ccd016f98dacd77d75"; - hash = "sha256-FC78GCaC8IcBtXDRotYcaw040cggGWnrI2lgnWLwU68="; + rev = "ab514fe0d477c7cf7e0d5f24b63e302e755f98cf"; + hash = "sha256-PGnOVKj1R5fWGeDJJJW0U0qdTBV5SHoY/VLtzFPg/Tw="; }; npmDepsHash = "sha256-L/JOhI7KVXNDGHzk8RVNNcd8hHL+I7YKVg8sZyRSBtA="; From 3107f15bd94eb6ea454f144d3f3e0cb8fc1e89fa Mon Sep 17 00:00:00 2001 From: Defelo Date: Fri, 28 Aug 2026 17:32:10 +0000 Subject: [PATCH 47/48] radicle-explorer: 0-unstable-2026-08-12 -> 0-unstable-2026-08-28 (cherry picked from commit fcc16f4147d29974dba4d172f8f6de5534e66179) --- pkgs/by-name/ra/radicle-explorer/package.nix | 28 +++----------------- 1 file changed, 4 insertions(+), 24 deletions(-) diff --git a/pkgs/by-name/ra/radicle-explorer/package.nix b/pkgs/by-name/ra/radicle-explorer/package.nix index 0a8771981f0e..6119e25766b0 100644 --- a/pkgs/by-name/ra/radicle-explorer/package.nix +++ b/pkgs/by-name/ra/radicle-explorer/package.nix @@ -2,44 +2,24 @@ lib, buildNpmPackage, fetchFromRadicle, - fetchFromGitHub, writers, _experimental-update-script-combinators, unstableGitUpdater, nix-update-script, }: -let - # radicle-explorer bundles these freely available Emoji assets, but does not - # redistribute them. - twemojiAssets = fetchFromGitHub { - owner = "twitter"; - repo = "twemoji"; - tag = "v14.0.2"; - hash = "sha256-YoOnZ5uVukzi/6bLi22Y8U5TpplPzB7ji42l+/ys5xI="; - meta.license = [ lib.licenses.cc-by-40 ]; - }; -in - buildNpmPackage (finalAttrs: { pname = "radicle-explorer"; - version = "0-unstable-2026-08-12"; + version = "0-unstable-2026-08-28"; src = fetchFromRadicle { seed = "seed.radicle.dev"; repo = "z4V1sjrXqjvFdnCUbxPFqd5p4DtH5"; - rev = "ab514fe0d477c7cf7e0d5f24b63e302e755f98cf"; - hash = "sha256-PGnOVKj1R5fWGeDJJJW0U0qdTBV5SHoY/VLtzFPg/Tw="; + rev = "60fd9a12880c35b4feda9e25528e9822e2a35829"; + hash = "sha256-R8rnVh/NVdt1AB6SXKsYYtVPqV4AgRqiEtP4Ti2xwXY="; }; - npmDepsHash = "sha256-L/JOhI7KVXNDGHzk8RVNNcd8hHL+I7YKVg8sZyRSBtA="; - - postPatch = '' - patchShebangs --build ./scripts - : >scripts/install-twemoji-assets - - cp -r "${twemojiAssets}/assets/svg" public/twemoji - ''; + npmDepsHash = "sha256-m+md3XIjn4SpZ3vp5STDFAKU3QSs0maFUm3Ll5DLghc="; preBuild = '' if [[ $configFile ]]; then From e9e8c922fa973b43aa5b72c5d136c74efd75efaa Mon Sep 17 00:00:00 2001 From: Defelo Date: Fri, 28 Aug 2026 19:43:18 +0000 Subject: [PATCH 48/48] radicle-httpd: 0.27.0 -> 0.28.0 Changelog: https://radicle.network/nodes/seed.radicle.dev/rad:z4V1sjrXqjvFdnCUbxPFqd5p4DtH5/tree/CHANGELOG.md (cherry picked from commit 86b8cc615e3d11ea24361df93d9551c03a2ad2f2) --- pkgs/by-name/ra/radicle-httpd/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ra/radicle-httpd/package.nix b/pkgs/by-name/ra/radicle-httpd/package.nix index a99d688469b9..464f9659c59b 100644 --- a/pkgs/by-name/ra/radicle-httpd/package.nix +++ b/pkgs/by-name/ra/radicle-httpd/package.nix @@ -15,7 +15,7 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "radicle-httpd"; - version = "0.27.0"; + version = "0.28.0"; env.RADICLE_VERSION = finalAttrs.version; @@ -29,10 +29,10 @@ rustPlatform.buildRustPackage (finalAttrs: { "/Cargo.toml" "/Cargo.lock" ]; - hash = "sha256-OJrHV5WdFNzoYrOkqpN1ctrJDB3JTJhH54q/C6IV9ZU="; + hash = "sha256-D15u6aU6lKch/bEa1J6PBntb42NMHWYChIgprbJM+4M="; }; - cargoHash = "sha256-FjYhw27pAX9Tilgm/Tg18Vkv4/K5kEFJAbhv1mDY0rg="; + cargoHash = "sha256-z/ddTzoitMOsfndleM8Wu2sOn156ZTg8w/3/AJYw8wE="; nativeBuildInputs = [ asciidoctor