Merge release-26.05 into staging-nixos-26.05

This commit is contained in:
nixpkgs-ci[bot]
2026-09-02 00:29:47 +00:00
committed by GitHub
23 changed files with 812 additions and 725 deletions

View File

@@ -272,7 +272,15 @@ let
If it does, write the ignore patterns to the rest API.
*/
+ lib.optionalString ((conf_type == "dirs") && (new_cfg.ignorePatterns != null)) ''
curl -d '{"ignore": ${builtins.toJSON new_cfg.ignorePatterns}}' -X POST ${s.ignoreAddress}?folder=${lib.strings.escapeURL new_cfg.id}
curl -d ${
lib.pipe new_cfg.ignorePatterns [
(patterns: {
ignore = patterns;
})
builtins.toJSON
lib.escapeShellArg
]
} -X POST ${s.ignoreAddress}?folder=${lib.strings.escapeURL new_cfg.id}
''
))
(lib.concatStringsSep "\n")

View File

@@ -13,7 +13,8 @@ let
# Only placeholders reach the world-readable Nix store; the install
# script substitutes the real secrets at runtime.
dbConfig =
cfg.database
# `engine` is MySQL-only; omit for other drivers
(if cfg.database.driver == "mysql" then cfg.database else removeAttrs cfg.database [ "engine" ])
// optionalAttrs (cfg.databasePasswordFile != null) {
password = "@databasePassword@";
};
@@ -138,36 +139,84 @@ in
};
database = mkOption {
type =
with types;
attrsOf (oneOf [
str
bool
int
]);
type = types.submodule {
freeformType =
with types;
attrsOf (oneOf [
str
bool
int
]);
options = {
driver = mkOption {
type = types.str;
default = "mysql";
description = "Database driver; i.e. MySQL, MariaDB...";
};
host = mkOption {
type = types.str;
default = "localhost";
description = "Database server hostname.";
};
port = mkOption {
type = types.port;
default = 3306;
description = "Database connection port; defaults to 3306 with MySQL.";
};
database = mkOption {
type = types.str;
default = "flarum";
description = "Database name.";
};
username = mkOption {
type = types.str;
default = "flarum";
description = "Username for database server access.";
};
password = mkOption {
type = types.str;
default = "";
description = "Password for database server access.";
};
charset = mkOption {
type = types.str;
default = "utf8mb4";
description = "Character encoding for the database.";
};
collation = mkOption {
type = types.str;
default = "utf8mb4_unicode_ci";
description = "Character collation for database sorting and comparison.";
};
prefix = mkOption {
type = types.str;
default = "";
description = "Table prefix; useful for sharing a database with other services.";
};
strict = mkOption {
type = types.bool;
default = false;
description = "Enable strict SQL mode.";
};
engine = mkOption {
type = types.str;
default = "InnoDB";
description = "Storage engine for new tables; MySQL-only.";
};
prefix_indexes = mkOption {
type = types.bool;
default = true;
description = "Apply table prefix to database index names.";
};
};
};
default = { };
description = ''
MySQL database parameters.
WARNING: A `password` set here is stored world-readable in the
Nix store. Use {option}`databasePasswordFile` instead.
'';
default = {
# the database driver; i.e. MySQL; MariaDB...
driver = "mysql";
# the host of the connection; localhost in most cases unless using an external service
host = "localhost";
# the name of the database in the instance
database = "flarum";
# database username
username = "flarum";
# database password
password = "";
# the prefix for the tables; useful if you are sharing the same database with another service
prefix = "";
# the port of the connection; defaults to 3306 with MySQL
port = 3306;
strict = false;
};
};
databasePasswordFile = mkOption {
@@ -291,8 +340,13 @@ in
before = [ "phpfpm-flarum.service" ];
requires = [ "mysql.service" ];
after = [ "mysql.service" ];
restartTriggers = [
cfg.package
configPhpFile
];
serviceConfig = {
Type = "oneshot";
RemainAfterExit = true;
User = cfg.user;
Group = cfg.group;
# The secret-filled install config is staged in /tmp

View File

@@ -103,6 +103,9 @@ in
];
ignorePatterns = [
"notB"
# Just test that an apostrophe doesn't break the curl config
# commands. See: https://github.com/NixOS/nixpkgs/issues/554744
"apostrophe'"
];
};
};

View File

@@ -9,10 +9,10 @@
buildMozillaMach rec {
pname = "firefox";
version = "154.0.1";
version = "155.0";
src = fetchurl {
url = "mirror://mozilla/firefox/releases/${version}/source/firefox-${version}.source.tar.xz";
sha512 = "9141e34978c2ecbe1b267b3cc63136142625734618e67cbbbf6536e1427af66d01f19851200eba0db7c715991f39e7d5d0200abb9e2cd7c15d58a8a411b1b412";
sha512 = "24292681924edb9f0494eb77a7b19994039abbc3a8c0ba304f0e472b49a943838565723de983bc8ef08e019971e02a3014c8d241bb88c645a06a625c8ace0d6a";
};
meta = {

View File

@@ -3,24 +3,24 @@
let
pname = "brave";
version = "1.93.138";
version = "1.94.117";
allArchives = {
aarch64-linux = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-browser_${version}_arm64.deb";
hash = "sha256-WWXn2Q2axhh9/KU67v6wf4vmRRXuYmJHbNmyOvvvg9c=";
hash = "sha256-4LTeb3BOBv+oRzC409UmSnFQDC3XRtKWmkPUcHOTkuM=";
};
x86_64-linux = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-browser_${version}_amd64.deb";
hash = "sha256-zxiy1EPwZyQeE2YkhMS5Uj8T/wibofwnyI9nkRWGrJ8=";
hash = "sha256-ZAAX6ZNZS0ogFRjDfmyAoWo4NbXckswHY7Amfh3skyQ=";
};
aarch64-darwin = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-v${version}-darwin-arm64.zip";
hash = "sha256-UdT5CHZM4VZbT81gkF4i+4aXVADXtU+M1kfv2rqYcjw=";
hash = "sha256-OHPEARZoRW1/svXUTP+5rWTyNu6xOYisBkSJy+Z4Vzo=";
};
x86_64-darwin = {
url = "https://github.com/brave/brave-browser/releases/download/v${version}/brave-v${version}-darwin-x64.zip";
hash = "sha256-r3/7HA5VIszSDvvdDs8mjM/HVtqMDHwcJ+0dbmijcro=";
hash = "sha256-1CSLU2aM1076Yl1sp8w/TSpKiqHMJ6F7qICX7/bO8+E=";
};
};

View File

@@ -23,13 +23,13 @@
}:
stdenv.mkDerivation (finalAttrs: {
pname = "buildbox";
version = "1.4.18";
version = "1.4.21";
src = fetchFromGitLab {
owner = "BuildGrid";
repo = "buildbox/buildbox";
tag = finalAttrs.version;
hash = "sha256-HQws9hgCop77+WzJ/EnSD0C8WPgFuAky+GIgGRxU744=";
hash = "sha256-Kg7aiVeOMA+hke481r0btUpzk/K0h7qA9l6DuLR+OAM=";
};
nativeBuildInputs = [

View File

@@ -20,7 +20,7 @@
stdenv.mkDerivation (finalAttrs: {
pname = "exiv2";
version = "0.28.8";
version = "0.28.9";
outputs = [
"out"
@@ -34,7 +34,7 @@ stdenv.mkDerivation (finalAttrs: {
owner = "exiv2";
repo = "exiv2";
tag = "v${finalAttrs.version}";
hash = "sha256-9Qe+lNBO24qQyKDXe7RMCqoDa61iha2QFhRpLJlCSMo=";
hash = "sha256-ESRiiBBckGIhnhSOMmcF/m1PYi2sLGv1xxE0b22nl5M=";
};
nativeBuildInputs = [

View File

@@ -8,64 +8,36 @@
nix-update-script,
gitMinimal,
makeWrapper,
writableTmpDirAsHomeHook,
}:
let
# tests which assume network access in some form
disabledTests = [
"Test_runCreateRunnerFile"
"Test_ping"
# The following tests were introduced in 9.x with the inclusion of act
# the pkgs/by-name/ac/act/package.nix just sets doCheck = false;
# Requires running Docker daemon
"TestDocker"
"TestJobExecutor"
"TestRunContext_PrepareJobContainer/Overlapping"
"TestRunExec"
"TestRunner"
"Test_validateCmd"
# Docker network request for image
"TestImageExistsLocally"
"TestStepDockerMain"
# Reaches out to different websites
"TestFindGitRemoteURL"
"TestGitFindRef"
"TestClone"
"TestCloneIfRequired"
"TestActionCache"
"TestRunContext_GetGitHubContext"
"TestSetJobResult_SkipsBannerInChildReusableWorkflow"
# These tests rely on outbound IP address
# requires network
"TestHandler"
"TestHandler_gcCache"
# Timeouts
"TestRunJob_WithConnectionFromCommandOptions"
"TestClone"
"TestRunner_ReusableWorkflowGitHubInstance"
]
++ lib.optionals stdenv.hostPlatform.isDarwin [
# Uses docker-specific options, unsupported on Darwin
"TestMergeJobOptions"
# listen tcp 127.0.0.1:0: bind: operation not permitted
"TestNewClient"
# httptest: failed to listen on a port: listen tcp6 [::1]:0: bind: operation not permitted
"TestNewEndpointHonoursTLSEnv"
];
in
buildGoModule (finalAttrs: {
pname = "forgejo-runner";
version = "12.13.2";
version = "13.1.0";
src = fetchFromGitea {
domain = "code.forgejo.org";
owner = "forgejo";
repo = "runner";
rev = "v${finalAttrs.version}";
hash = "sha256-6i87t8LXYYXyQ8UzyUiEOvQ+9wuRz4xeUBivk0VJ0S4=";
hash = "sha256-0LVia4B9n2zuuHDGFnBVM1mrbI7XBhMfy25kRSN5/WQ=";
};
vendorHash = "sha256-du7fXehcxZ70Lsr5VCkz646G0Us/XwM4Sl98HXimoao=";
vendorHash = "sha256-2QwltVOR6MJO8rLNgktN1ulvP0YrnqQorNnfJXzRmJs=";
nativeBuildInputs = [ makeWrapper ];
@@ -79,13 +51,26 @@ buildGoModule (finalAttrs: {
ldflags = [
"-s"
"-w"
"-X code.forgejo.org/forgejo/runner/v12/internal/pkg/ver.version=${finalAttrs.src.rev}"
"-X code.forgejo.org/forgejo/runner/v13/internal/pkg/ver.version=${finalAttrs.src.rev}"
];
checkFlags = [
"-skip ${lib.concatStringsSep "|" disabledTests}"
];
# Upstream offers '-args -features "-"' as go test flag to skip tests that require either lxc or docker.
# Unfortunately, we cannot use this without patching buildGoModule, as -args passes the remainder of the
# command line to the test binary, and checkFlags are templated between go test and $dir, causing $dir (e.g.
# ./...) to be discarded, which in turn causes all tests to be skipped.
# TODO: Make our buildGoModule (go/module.nix) template $dir before checkFlags to allow use of -arg
# https://code.forgejo.org/forgejo/runner/pulls/1591
# https://pkg.go.dev/cmd/go/internal/test#:~:text=%2Dargs
preCheck = ''
substituteInPlace testutils/test_main.go \
--replace-fail 'TestFeatureDocker: {},' '// TestFeatureDocker: {},' \
--replace-fail 'TestFeatureLXC: {},' '// TestFeatureLXC: {},'
'';
postInstall = ''
# Fix up go-specific executable naming derived from package name, upstream
# also calls it `forgejo-runner`
@@ -98,7 +83,10 @@ buildGoModule (finalAttrs: {
ln -s $out/bin/forgejo-runner $out/bin/act_runner
'';
nativeCheckInputs = [ gitMinimal ];
nativeCheckInputs = [
gitMinimal
writableTmpDirAsHomeHook
];
doInstallCheck = true;
nativeInstallCheckInputs = [ versionCheckHook ];

View File

@@ -9,16 +9,16 @@
buildGoModule (finalAttrs: {
pname = "gost";
version = "3.2.6";
version = "3.3.0";
src = fetchFromGitHub {
owner = "go-gost";
repo = "gost";
tag = "v${finalAttrs.version}";
hash = "sha256-zq9UrzXbKVraqq8eGY5XOHOMdpfuOog5V17+wh9vwIc=";
hash = "sha256-+g8YjOuH1WKfEYPLbrKB2YIHnY7HXJv0rQfxiL/jdQI=";
};
vendorHash = "sha256-LbmGYV85+JmiLlJhdozAyzWIql4QxpHj2C4hjo+PT1k=";
vendorHash = "sha256-lEPJpOXyPiMbFEbVlMGdhBGRYj5JTx2zun7YmX19r4k=";
# Based on ldflags in upstream's .goreleaser.yaml
ldflags = [
@@ -31,6 +31,9 @@ buildGoModule (finalAttrs: {
# i/o timeout
doCheck = !stdenv.hostPlatform.isDarwin;
# Skip e2e tests that require a Docker daemon.
excludedPackages = [ "tests/e2e" ];
doInstallCheck = true;
nativeInstallCheckInputs = [ versionCheckHook ];

View File

@@ -1,11 +1,11 @@
{
"packageVersion": "154.0.1-3",
"packageVersion": "155.0-1",
"source": {
"rev": "154.0.1-3",
"hash": "sha256-IPV+/5NCyoLYaRD5N6bu4doI6R4yxs4cBw8UrJP3E4U="
"rev": "155.0-1",
"hash": "sha256-LPLkMuKnEHJ+jYF5LnitnOzHaokDdRIyxZegWKEJ2wo="
},
"firefox": {
"version": "154.0.1",
"hash": "sha512-kUHjSXjC7L4bJns8xjE2FCYlc0YY5ny7v2U24UJ69m0B8ZhRIA66DbfHFZkfOefV0CAKu54s18FdWKikEbG0Eg=="
"version": "155.0",
"hash": "sha512-JCkmgZJO258ElOt3p7GZlAOau8OowLowTw5HK0mpQ4OFZXI96YO8jvCOAZlx4CowFMjSQbuIxkWgamJcis4Nag=="
}
}

View File

@@ -4,6 +4,7 @@
buildDotnetModule,
dotnetCorePackages,
nix-update-script,
stdenv,
versionCheckHook,
}:
@@ -29,6 +30,12 @@ buildDotnetModule (finalAttrs: {
doCheck = true;
testProjectFile = "Tests/Tests.fsproj";
# __darwinAllowLocalNetworking is not working with IPv4-mapped IPv6.
# See: https://github.com/NixOS/nix/pull/11270#issuecomment-3936740134
dotnetTestFlags = lib.optionals stdenv.hostPlatform.isDarwin [
"--environment"
"DOTNET_SYSTEM_NET_DISABLEIPV6=1"
];
nugetDeps = ./deps.json;

View File

@@ -19,13 +19,13 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "minizinc-ide";
version = "2.10.0";
version = "2.10.1";
src = fetchFromGitHub {
owner = "MiniZinc";
repo = "MiniZincIDE";
rev = finalAttrs.version;
hash = "sha256-BJpxzgvT+ujwHYiV+jrHXl5nJKXC9jzbNs3rfsI1HUU=";
hash = "sha256-/+wiQK4tlaYISiQEhsd02tv/2e1c1JYSyrOqGOdhvO0=";
fetchSubmodules = true;
};

View File

@@ -3,6 +3,7 @@
stdenv,
fetchFromGitHub,
fetchpatch,
unstableGitUpdater,
meson,
ninja,
pkg-config,
@@ -10,13 +11,13 @@
stdenv.mkDerivation {
pname = "rlottie";
version = "0.2-unstable-2026-08-11";
version = "0.2-unstable-2026-09-01";
src = fetchFromGitHub {
owner = "Samsung";
repo = "rlottie";
rev = "27f2f23ece8a98f3e0a870e2c125faaac37e8904";
hash = "sha256-wEcdPKmS0f6C0A/Rg7vsZGoRi2Uv1EmA31BR2EmIlGg=";
rev = "25648aef19187b3f87f4d9420b8d761453ad4630";
hash = "sha256-sLjunpnQh1HCy5VLB8EpCTaGuBRPGCLhDovTzAAjAK0=";
};
nativeBuildInputs = [
@@ -34,6 +35,10 @@ stdenv.mkDerivation {
stdenv.hostPlatform.isDarwin && stdenv.hostPlatform.isAarch64
) "-U__ARM_NEON__";
passthru.updateScript = unstableGitUpdater {
tagPrefix = "v";
};
meta = {
homepage = "https://github.com/Samsung/rlottie";
description = "Platform independent standalone c++ library for rendering vector based animations and art in realtime";

View File

@@ -19,14 +19,14 @@ assert selinuxSupport -> lib.meta.availableOn stdenv.hostPlatform libselinux;
stdenv.mkDerivation (finalAttrs: {
pname = "uutils-coreutils";
version = "0.10.0";
version = "0.11.0";
__structuredAttrs = true;
src = fetchFromGitHub {
owner = "uutils";
repo = "coreutils";
tag = finalAttrs.version;
hash = "sha256-bqMrYVFa21Tu3t2Y5na9gFYr6AkklSnszbX8vKxI4gg=";
hash = "sha256-ghOUqC5U7L16k7mFxtgNeQssA/OU9MJ6fIK2G17QrhI=";
};
# error: linker `aarch64-linux-gnu-gcc` not found
@@ -36,7 +36,7 @@ stdenv.mkDerivation (finalAttrs: {
cargoDeps = rustPlatform.fetchCargoVendor {
inherit (finalAttrs) pname src version;
hash = "sha256-7ROe9xrFcaXWYxoe9lfAfZxDxPcrETU8Mcj2HsdoqpA=";
hash = "sha256-b9J6BnwnM/4I5xUkkUPTPzTVfDQ+Cfc7KqTLuZpFvu0=";
};
buildInputs = lib.optionals selinuxSupport [

View File

@@ -10,11 +10,11 @@
}:
stdenv.mkDerivation rec {
pname = "worldpainter";
version = "2.27.0";
version = "2.27.1";
src = fetchurl {
url = "https://www.worldpainter.net/files/worldpainter_${version}.tar.gz";
hash = "sha256-UY2KB6IUlv35wEG9PNU5gWvV5L6KsEiUvJEpqWXSBSA=";
hash = "sha256-w+sT1C4eeidVTNyS5q8tnHQgQ+frJSL0+A//XbbYNcY=";
};
nativeBuildInputs = [

View File

@@ -15,18 +15,24 @@
fmt,
alcotest,
crowbar,
ppx_expect,
}:
buildDunePackage (finalAttrs: {
pname = "cohttp";
version = if lib.versionAtLeast ocaml.version "4.13" then "6.2.1" else "5.3.1";
minimalOCamlVersion = "4.08";
version =
if lib.versionAtLeast ocaml.version "5.2" then
"6.3.0"
else if lib.versionAtLeast ocaml.version "4.13" then
"6.2.1"
else
"5.3.1";
src = fetchurl {
url = "https://github.com/mirage/ocaml-cohttp/releases/download/v${finalAttrs.version}/cohttp-${finalAttrs.version}.tbz";
hash =
{
"6.3.0" = "sha256-MRMPaKnwpc2NcbVfBCRW5tNb+LeranGrbXvX29tgeyQ=";
"6.2.1" = "sha256-ZQgCR3Y0QtHcPNkGeLgjO3mHcvA2rIHNHqreH11mpl8=";
"5.3.1" = "sha256-9eJz08Lyn/R71+Ftsj4fPWzQGkC+ACCJhbxDTIjUV2s=";
}
@@ -34,7 +40,7 @@ buildDunePackage (finalAttrs: {
};
postPatch = ''
substituteInPlace cohttp/src/dune --replace 'bytes base64' 'base64'
substituteInPlace cohttp/src/dune --replace-warn 'bytes base64' 'base64'
'';
buildInputs = [
@@ -61,8 +67,8 @@ buildDunePackage (finalAttrs: {
fmt
alcotest
]
++ lib.optionals (lib.versionOlder finalAttrs.version "6.0.0") [
crowbar
++ [
(if lib.versionOlder finalAttrs.version "6.0.0" then crowbar else ppx_expect)
];
meta = {

View File

@@ -10,6 +10,7 @@
alcotest,
ca-certs,
eio_main,
ppx_expect,
tls-eio,
}:
@@ -37,6 +38,7 @@ buildDunePackage {
alcotest
ca-certs
eio_main
ppx_expect
tls-eio
];

View File

@@ -1,7 +1,6 @@
{
buildDunePackage,
cohttp,
ppx_expect,
}:
buildDunePackage {
@@ -13,8 +12,6 @@ buildDunePackage {
minimalOCamlVersion = "5.1";
propagatedBuildInputs = [ ppx_expect ];
meta = cohttp.meta // {
description = "CoHTTP implementation using the Lwt concurrency library";
};

View File

@@ -9,6 +9,7 @@
js_of_ocaml-lwt,
nodejs,
lwt_ppx,
ppx_expect,
}:
buildDunePackage {
@@ -29,6 +30,7 @@ buildDunePackage {
checkInputs = [
nodejs
lwt_ppx
ppx_expect
];
meta = cohttp-lwt.meta // {

View File

@@ -4,6 +4,7 @@
cohttp-lwt-unix,
http,
lwt,
ppx_expect,
}:
buildDunePackage (finalAttrs: {
@@ -15,7 +16,10 @@ buildDunePackage (finalAttrs: {
lwt
];
checkInputs = [ cohttp-lwt-unix ];
checkInputs = [
cohttp-lwt-unix
ppx_expect
];
doCheck = true;
meta = cohttp.meta // {

View File

@@ -1,4 +1,8 @@
{ buildDunePackage, cohttp }:
{
buildDunePackage,
cohttp,
ppx_expect,
}:
buildDunePackage {
pname = "cohttp-top";
@@ -7,6 +11,7 @@ buildDunePackage {
propagatedBuildInputs = [ cohttp ];
doCheck = true;
checkInputs = [ ppx_expect ];
meta = cohttp.meta // {
description = "CoHTTP toplevel pretty printers for HTTP types";

View File

@@ -84,6 +84,9 @@ buildPythonPackage rec {
];
};
# test suite starts a real localhost server; hangs without this on darwin
__darwinAllowLocalNetworking = true;
nativeCheckInputs = [
cachetools
orjson