From a198dfd0b9647d9bbdea454f75686034b14910d3 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Tue, 29 Sep 2026 00:20:28 +0200 Subject: [PATCH] Revert "gixy: 0.1.21 -> 0.2.54, switch upstream to maintained gixy-ng fork" --- maintainers/maintainer-list.nix | 6 -- pkgs/by-name/gi/gixy/package.nix | 90 +++++++++++-------- pkgs/by-name/gi/gixy/python3.13-compat.patch | 25 ++++++ .../python-modules/ngxparse/default.nix | 36 -------- pkgs/top-level/python-packages.nix | 2 - 5 files changed, 76 insertions(+), 83 deletions(-) create mode 100644 pkgs/by-name/gi/gixy/python3.13-compat.patch delete mode 100644 pkgs/development/python-modules/ngxparse/default.nix diff --git a/maintainers/maintainer-list.nix b/maintainers/maintainer-list.nix index 5a6785f8da13..356b6ef2a6c7 100644 --- a/maintainers/maintainer-list.nix +++ b/maintainers/maintainer-list.nix @@ -7900,12 +7900,6 @@ email = "email@dvdznf.xyz"; matrix = "@dvdznf:gitter.im"; }; - dvershinin = { - email = "ciapnz@gmail.com"; - github = "dvershinin"; - githubId = 250071; - name = "Danila Vershinin"; - }; dvn0 = { email = "devan@informatics.coop"; keys = [ { fingerprint = "E0F4 87C6 6298 7353 A7D0 E997 8203 BD5C 41D8 29DF"; } ]; diff --git a/pkgs/by-name/gi/gixy/package.nix b/pkgs/by-name/gi/gixy/package.nix index ef5621e9ffc8..0eacc0d501d9 100644 --- a/pkgs/by-name/gi/gixy/package.nix +++ b/pkgs/by-name/gi/gixy/package.nix @@ -1,69 +1,81 @@ { lib, - python3, fetchFromGitHub, + fetchpatch2, + python3, nginx, }: -python3.pkgs.buildPythonApplication rec { - pname = "gixy-ng"; - version = "0.2.54"; +let + python = python3.override { + self = python; + packageOverrides = self: super: { + pyparsing = super.pyparsing.overridePythonAttrs rec { + version = "2.4.7"; + src = fetchFromGitHub { + owner = "pyparsing"; + repo = "pyparsing"; + rev = "pyparsing_${version}"; + sha256 = "14pfy80q2flgzjcx8jkracvnxxnr59kjzp3kdm5nh232gk1v6g6h"; + }; + nativeBuildInputs = [ super.setuptools ]; + }; + }; + }; +in +python.pkgs.buildPythonApplication rec { + pname = "gixy"; + version = "0.1.21"; pyproject = true; - # Fetching from GitHub because the PyPI sdist is missing the tests + # fetching from GitHub because the PyPi source is missing the tests src = fetchFromGitHub { - owner = "dvershinin"; + owner = "yandex"; repo = "gixy"; - tag = "v${version}"; - hash = "sha256-HVH3oyL9UXXnfBw0RosCprsrj2iE+f/R5aHYWZ3/WK0="; + rev = "v${version}"; + sha256 = "sha256-Ak2UTP0gDKoac/rR2h1XCUKld1b41O466ogZNQ1yQN0="; }; - build-system = with python3.pkgs; [ setuptools ]; + patches = [ + # Migrate tests to pytest + # https://github.com/yandex/gixy/pull/146 + (fetchpatch2 { + name = "migrate-tests-to-pytest.patch"; + url = "https://github.com/yandex/gixy/compare/6f68624a7540ee51316651bda656894dc14c9a3e...b1c6899b3733b619c244368f0121a01be028e8c2.diff?full_index=1"; + hash = "sha256-qIKKTC65ewZqiKiNLcaglKEdFh0SBZMJgIvY41/7WUc="; + }) + ./python3.13-compat.patch + ]; - dependencies = with python3.pkgs; [ - ngxparse - jinja2 + build-system = [ python.pkgs.setuptools ]; + + dependencies = with python.pkgs; [ + cached-property configargparse + pyparsing + jinja2 + six ]; - nativeCheckInputs = with python3.pkgs; [ pytestCheckHook ]; + nativeCheckInputs = [ python.pkgs.pytestCheckHook ]; - disabledTestPaths = [ - # Requires the optional `redoctor` backend (gixy-ng[deep]), not packaged - "tests/plugins/test_redos_analyzer.py" - ]; - - disabledTests = [ - # Exits early without `redoctor`; fixed upstream in 3b7969e - "test_cli_main_runs_with_plugin_options" - # Asserts the pre-3.14 TypeError wording; fixed upstream in ead00fe - "test_in_operator_on_none_raises_typeerror" - ]; - - pythonImportsCheck = [ "gixy" ]; + pythonRemoveDeps = [ "argparse" ]; passthru = { inherit (nginx.passthru) tests; }; meta = { - description = "Nginx configuration static analyzer focused on security"; + description = "Nginx configuration static analyzer"; mainProgram = "gixy"; longDescription = '' - Gixy is a static analyzer for nginx configurations. Its main - goal is to detect security misconfigurations and to automate - the discovery of common flaws (HTTP response splitting, host - spoofing on virtual-host dispatch, alias-traversal "off-by- - slash", missing add_header inheritance, weak SSL/TLS ciphers, - and more). - - Tracks the actively-maintained gixy-ng distribution on PyPI; - the binary remains `gixy'. + Gixy is a tool to analyze Nginx configuration. + The main goal of Gixy is to prevent security misconfiguration and automate flaw detection. ''; - homepage = "https://gixy.getpagespeed.com/"; - changelog = "https://github.com/dvershinin/gixy/blob/v${version}/CHANGELOG.md"; + homepage = "https://github.com/yandex/gixy"; + sourceProvenance = [ lib.sourceTypes.fromSource ]; license = lib.licenses.mpl20; - maintainers = with lib.maintainers; [ dvershinin ]; + maintainers = [ ]; platforms = lib.platforms.unix; }; } diff --git a/pkgs/by-name/gi/gixy/python3.13-compat.patch b/pkgs/by-name/gi/gixy/python3.13-compat.patch new file mode 100644 index 000000000000..c7265461ffad --- /dev/null +++ b/pkgs/by-name/gi/gixy/python3.13-compat.patch @@ -0,0 +1,25 @@ +diff --git a/gixy/core/sre_parse/sre_parse.py b/gixy/core/sre_parse/sre_parse.py +index df69044..f90c795 100644 +--- a/gixy/core/sre_parse/sre_parse.py ++++ b/gixy/core/sre_parse/sre_parse.py +@@ -14,7 +14,7 @@ from __future__ import print_function + + """Internal support module for sre""" + +-from sre_constants import * ++from gixy.core.sre_parse.sre_constants import * + + SPECIAL_CHARS = ".\\[{()*+?^$|" + REPEAT_CHARS = "*+?{" +diff --git a/tests/plugins/test_simply.py b/tests/plugins/test_simply.py +index 1a33c63..7d5a32f 100644 +--- a/tests/plugins/test_simply.py ++++ b/tests/plugins/test_simply.py +@@ -5,6 +5,7 @@ from os import path + import json + + from ..utils import * ++from gixy.formatters.base import BaseFormatter + from gixy.core.manager import Manager as Gixy + from gixy.core.plugins_manager import PluginsManager + from gixy.core.config import Config diff --git a/pkgs/development/python-modules/ngxparse/default.nix b/pkgs/development/python-modules/ngxparse/default.nix deleted file mode 100644 index 3e919eb6063b..000000000000 --- a/pkgs/development/python-modules/ngxparse/default.nix +++ /dev/null @@ -1,36 +0,0 @@ -{ - lib, - buildPythonPackage, - fetchFromGitHub, - setuptools, - pytestCheckHook, -}: - -buildPythonPackage rec { - pname = "ngxparse"; - version = "0.5.16"; - pyproject = true; - - # Fetching from GitHub because the PyPI sdist is missing the test fixtures - src = fetchFromGitHub { - owner = "dvershinin"; - repo = "crossplane"; - tag = "v${version}"; - hash = "sha256-gXzVjY89YjppneR9Vuce+V+RKIcbIBEvLeAoI54ZegM="; - }; - - build-system = [ setuptools ]; - - nativeCheckInputs = [ pytestCheckHook ]; - - # The ngxparse distribution ships its importable module as `crossplane` - # (it's a drop-in replacement for the upstream nginxinc/crossplane). - pythonImportsCheck = [ "crossplane" ]; - - meta = { - description = "Reliable and fast NGINX configuration file parser (maintained fork of crossplane)"; - homepage = "https://github.com/dvershinin/crossplane"; - license = lib.licenses.asl20; - maintainers = with lib.maintainers; [ dvershinin ]; - }; -} diff --git a/pkgs/top-level/python-packages.nix b/pkgs/top-level/python-packages.nix index 43667b6d07dc..ef18a7b2f4d5 100644 --- a/pkgs/top-level/python-packages.nix +++ b/pkgs/top-level/python-packages.nix @@ -12075,8 +12075,6 @@ self: super: with self; { nglview = callPackage ../development/python-modules/nglview { }; - ngxparse = callPackage ../development/python-modules/ngxparse { }; - nh3 = callPackage ../development/python-modules/nh3 { }; nhc = callPackage ../development/python-modules/nhc { };