From e64237c6873637e9fcb0276ab384ee5484a2df57 Mon Sep 17 00:00:00 2001 From: Danila Vershinin Date: Mon, 28 Sep 2026 17:00:40 +0700 Subject: [PATCH 1/3] maintainers: add dvershinin Assisted-by: Claude Code (Claude Opus 5.5) --- maintainers/maintainer-list.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/maintainers/maintainer-list.nix b/maintainers/maintainer-list.nix index 923a945becb7..e3115d106340 100644 --- a/maintainers/maintainer-list.nix +++ b/maintainers/maintainer-list.nix @@ -7491,6 +7491,12 @@ email = "email@dvdznf.xyz"; matrix = "@dvdznf:gitter.im"; }; + dvershinin = { + email = "ciapnz@gmail.com"; + github = "dvershinin"; + githubId = 250071; + name = "Danila Vershinin"; + }; dvn0 = { email = "git@dvn.me"; github = "dvn0"; From a735fa0084cfdfbdaf77c67e0b21f15b5b425e46 Mon Sep 17 00:00:00 2001 From: Danila Vershinin Date: Mon, 28 Sep 2026 17:00:42 +0700 Subject: [PATCH 2/3] python3Packages.ngxparse: init at 0.5.16 Assisted-by: Claude Code (Claude Opus 5.5) --- .../python-modules/ngxparse/default.nix | 36 +++++++++++++++++++ pkgs/top-level/python-packages.nix | 2 ++ 2 files changed, 38 insertions(+) create mode 100644 pkgs/development/python-modules/ngxparse/default.nix diff --git a/pkgs/development/python-modules/ngxparse/default.nix b/pkgs/development/python-modules/ngxparse/default.nix new file mode 100644 index 000000000000..3e919eb6063b --- /dev/null +++ b/pkgs/development/python-modules/ngxparse/default.nix @@ -0,0 +1,36 @@ +{ + lib, + buildPythonPackage, + fetchFromGitHub, + setuptools, + pytestCheckHook, +}: + +buildPythonPackage rec { + pname = "ngxparse"; + version = "0.5.16"; + pyproject = true; + + # Fetching from GitHub because the PyPI sdist is missing the test fixtures + src = fetchFromGitHub { + owner = "dvershinin"; + repo = "crossplane"; + tag = "v${version}"; + hash = "sha256-gXzVjY89YjppneR9Vuce+V+RKIcbIBEvLeAoI54ZegM="; + }; + + build-system = [ setuptools ]; + + nativeCheckInputs = [ pytestCheckHook ]; + + # The ngxparse distribution ships its importable module as `crossplane` + # (it's a drop-in replacement for the upstream nginxinc/crossplane). + pythonImportsCheck = [ "crossplane" ]; + + meta = { + description = "Reliable and fast NGINX configuration file parser (maintained fork of crossplane)"; + homepage = "https://github.com/dvershinin/crossplane"; + license = lib.licenses.asl20; + maintainers = with lib.maintainers; [ dvershinin ]; + }; +} diff --git a/pkgs/top-level/python-packages.nix b/pkgs/top-level/python-packages.nix index f4ff36be4137..2c6a1611631c 100644 --- a/pkgs/top-level/python-packages.nix +++ b/pkgs/top-level/python-packages.nix @@ -11214,6 +11214,8 @@ self: super: with self; { nglview = callPackage ../development/python-modules/nglview { }; + ngxparse = callPackage ../development/python-modules/ngxparse { }; + nh3 = callPackage ../development/python-modules/nh3 { }; nhc = callPackage ../development/python-modules/nhc { }; From 5a2375490ce8e914c25b01ea0c8cec63f47700ac Mon Sep 17 00:00:00 2001 From: Danila Vershinin Date: Mon, 28 Sep 2026 17:00:44 +0700 Subject: [PATCH 3/3] gixy: 0.1.21 -> 0.2.54, switch upstream to maintained gixy-ng fork Assisted-by: Claude Code (Claude Opus 5.5) --- pkgs/by-name/gi/gixy/package.nix | 90 +++++++++----------- pkgs/by-name/gi/gixy/python3.13-compat.patch | 25 ------ 2 files changed, 39 insertions(+), 76 deletions(-) delete mode 100644 pkgs/by-name/gi/gixy/python3.13-compat.patch diff --git a/pkgs/by-name/gi/gixy/package.nix b/pkgs/by-name/gi/gixy/package.nix index 0eacc0d501d9..ef5621e9ffc8 100644 --- a/pkgs/by-name/gi/gixy/package.nix +++ b/pkgs/by-name/gi/gixy/package.nix @@ -1,81 +1,69 @@ { lib, - fetchFromGitHub, - fetchpatch2, python3, + fetchFromGitHub, nginx, }: -let - python = python3.override { - self = python; - packageOverrides = self: super: { - pyparsing = super.pyparsing.overridePythonAttrs rec { - version = "2.4.7"; - src = fetchFromGitHub { - owner = "pyparsing"; - repo = "pyparsing"; - rev = "pyparsing_${version}"; - sha256 = "14pfy80q2flgzjcx8jkracvnxxnr59kjzp3kdm5nh232gk1v6g6h"; - }; - nativeBuildInputs = [ super.setuptools ]; - }; - }; - }; -in -python.pkgs.buildPythonApplication rec { - pname = "gixy"; - version = "0.1.21"; +python3.pkgs.buildPythonApplication rec { + pname = "gixy-ng"; + version = "0.2.54"; pyproject = true; - # fetching from GitHub because the PyPi source is missing the tests + # Fetching from GitHub because the PyPI sdist is missing the tests src = fetchFromGitHub { - owner = "yandex"; + owner = "dvershinin"; repo = "gixy"; - rev = "v${version}"; - sha256 = "sha256-Ak2UTP0gDKoac/rR2h1XCUKld1b41O466ogZNQ1yQN0="; + tag = "v${version}"; + hash = "sha256-HVH3oyL9UXXnfBw0RosCprsrj2iE+f/R5aHYWZ3/WK0="; }; - patches = [ - # Migrate tests to pytest - # https://github.com/yandex/gixy/pull/146 - (fetchpatch2 { - name = "migrate-tests-to-pytest.patch"; - url = "https://github.com/yandex/gixy/compare/6f68624a7540ee51316651bda656894dc14c9a3e...b1c6899b3733b619c244368f0121a01be028e8c2.diff?full_index=1"; - hash = "sha256-qIKKTC65ewZqiKiNLcaglKEdFh0SBZMJgIvY41/7WUc="; - }) - ./python3.13-compat.patch - ]; + build-system = with python3.pkgs; [ setuptools ]; - build-system = [ python.pkgs.setuptools ]; - - dependencies = with python.pkgs; [ - cached-property - configargparse - pyparsing + dependencies = with python3.pkgs; [ + ngxparse jinja2 - six + configargparse ]; - nativeCheckInputs = [ python.pkgs.pytestCheckHook ]; + nativeCheckInputs = with python3.pkgs; [ pytestCheckHook ]; - pythonRemoveDeps = [ "argparse" ]; + disabledTestPaths = [ + # Requires the optional `redoctor` backend (gixy-ng[deep]), not packaged + "tests/plugins/test_redos_analyzer.py" + ]; + + disabledTests = [ + # Exits early without `redoctor`; fixed upstream in 3b7969e + "test_cli_main_runs_with_plugin_options" + # Asserts the pre-3.14 TypeError wording; fixed upstream in ead00fe + "test_in_operator_on_none_raises_typeerror" + ]; + + pythonImportsCheck = [ "gixy" ]; passthru = { inherit (nginx.passthru) tests; }; meta = { - description = "Nginx configuration static analyzer"; + description = "Nginx configuration static analyzer focused on security"; mainProgram = "gixy"; longDescription = '' - Gixy is a tool to analyze Nginx configuration. - The main goal of Gixy is to prevent security misconfiguration and automate flaw detection. + Gixy is a static analyzer for nginx configurations. Its main + goal is to detect security misconfigurations and to automate + the discovery of common flaws (HTTP response splitting, host + spoofing on virtual-host dispatch, alias-traversal "off-by- + slash", missing add_header inheritance, weak SSL/TLS ciphers, + and more). + + Tracks the actively-maintained gixy-ng distribution on PyPI; + the binary remains `gixy'. ''; - homepage = "https://github.com/yandex/gixy"; - sourceProvenance = [ lib.sourceTypes.fromSource ]; + homepage = "https://gixy.getpagespeed.com/"; + changelog = "https://github.com/dvershinin/gixy/blob/v${version}/CHANGELOG.md"; license = lib.licenses.mpl20; - maintainers = [ ]; + maintainers = with lib.maintainers; [ dvershinin ]; platforms = lib.platforms.unix; }; } diff --git a/pkgs/by-name/gi/gixy/python3.13-compat.patch b/pkgs/by-name/gi/gixy/python3.13-compat.patch deleted file mode 100644 index c7265461ffad..000000000000 --- a/pkgs/by-name/gi/gixy/python3.13-compat.patch +++ /dev/null @@ -1,25 +0,0 @@ -diff --git a/gixy/core/sre_parse/sre_parse.py b/gixy/core/sre_parse/sre_parse.py -index df69044..f90c795 100644 ---- a/gixy/core/sre_parse/sre_parse.py -+++ b/gixy/core/sre_parse/sre_parse.py -@@ -14,7 +14,7 @@ from __future__ import print_function - - """Internal support module for sre""" - --from sre_constants import * -+from gixy.core.sre_parse.sre_constants import * - - SPECIAL_CHARS = ".\\[{()*+?^$|" - REPEAT_CHARS = "*+?{" -diff --git a/tests/plugins/test_simply.py b/tests/plugins/test_simply.py -index 1a33c63..7d5a32f 100644 ---- a/tests/plugins/test_simply.py -+++ b/tests/plugins/test_simply.py -@@ -5,6 +5,7 @@ from os import path - import json - - from ..utils import * -+from gixy.formatters.base import BaseFormatter - from gixy.core.manager import Manager as Gixy - from gixy.core.plugins_manager import PluginsManager - from gixy.core.config import Config