From f56f864b8a168115bf14e94435fd96a3a51d2bac Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Thu, 25 May 2023 23:06:51 +0200 Subject: [PATCH 01/26] python311Packages.trio-asyncio: disable failing test Disabled a failing test, that has not been updated with Python 3.11 in mind. (cherry picked from commit d4c62fe65ed0fb736009d372dadeb7379bc8a911) --- pkgs/development/python-modules/trio-asyncio/default.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkgs/development/python-modules/trio-asyncio/default.nix b/pkgs/development/python-modules/trio-asyncio/default.nix index 127da2d4766f..3585e2519918 100644 --- a/pkgs/development/python-modules/trio-asyncio/default.nix +++ b/pkgs/development/python-modules/trio-asyncio/default.nix @@ -6,6 +6,7 @@ , sniffio , pytest-trio , pytestCheckHook +, pythonAtLeast , pythonOlder }: @@ -49,6 +50,10 @@ buildPythonPackage rec { "tests/python" # tries to import internal API test.test_asyncio ]; + disabledTests = lib.optionals (pythonAtLeast "3.11") [ + "test_run_task" + ]; + pythonImportsCheck = [ "trio_asyncio" ]; From 4fdd46c83730f2afdb8250b449b8af912a1d7f98 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 13 Jun 2023 21:03:42 +0000 Subject: [PATCH 02/26] sympa: 6.2.70 -> 6.2.72 (cherry picked from commit e624b4f1ae8c2adf3d374eaae6c76f54dc9ced17) --- pkgs/servers/mail/sympa/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/mail/sympa/default.nix b/pkgs/servers/mail/sympa/default.nix index 7e409934fad0..5d29f6fbb536 100644 --- a/pkgs/servers/mail/sympa/default.nix +++ b/pkgs/servers/mail/sympa/default.nix @@ -61,13 +61,13 @@ let in stdenv.mkDerivation rec { pname = "sympa"; - version = "6.2.70"; + version = "6.2.72"; src = fetchFromGitHub { owner = "sympa-community"; repo = pname; rev = version; - sha256 = "sha256-/gaJ17IwB6ZC7OT9gxA5uUhTAHXeqsEh/x4AzAARups="; + sha256 = "sha256-8G6MxpqVa3E5J/68E7tljcXF4w7OmNkI0nJwsgxJE28="; }; configureFlags = [ From d5f9620d069df8f0c0843c9bbb2b19a8bccdbefd Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 28 Jun 2023 21:10:03 +0200 Subject: [PATCH 03/26] linux: 4.14.319 -> 4.14.320 (cherry picked from commit 9abe1bb6824bf6d70f03ed91d8e6003c52f6457b) --- pkgs/os-specific/linux/kernel/linux-4.14.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/linux-4.14.nix b/pkgs/os-specific/linux/kernel/linux-4.14.nix index a41e15e863df..5d759c36acfe 100644 --- a/pkgs/os-specific/linux/kernel/linux-4.14.nix +++ b/pkgs/os-specific/linux/kernel/linux-4.14.nix @@ -3,7 +3,7 @@ with lib; buildLinux (args // rec { - version = "4.14.319"; + version = "4.14.320"; # modDirVersion needs to be x.y.z, will automatically add .0 if needed modDirVersion = versions.pad 3 version; @@ -13,6 +13,6 @@ buildLinux (args // rec { src = fetchurl { url = "mirror://kernel/linux/kernel/v4.x/linux-${version}.tar.xz"; - sha256 = "1y8zp9jkyid4g857nfm7xhsya3d9vx2dni8l7ishn2gl087pb95c"; + sha256 = "09bn18jvazkc55bqdjbxy8fbca7vjhi9xl2h02w0sq3f1jf6g0pd"; }; } // (args.argsOverride or {})) From 8c9701e52bb2d15cbc240b0305e76f48a674f2eb Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 28 Jun 2023 21:10:10 +0200 Subject: [PATCH 04/26] linux: 4.19.287 -> 4.19.288 (cherry picked from commit 2e27cec09322fc5e79c514adc2a32c22d4913e3b) --- pkgs/os-specific/linux/kernel/linux-4.19.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/linux-4.19.nix b/pkgs/os-specific/linux/kernel/linux-4.19.nix index 147c8f1396f7..47c8cc9cbe05 100644 --- a/pkgs/os-specific/linux/kernel/linux-4.19.nix +++ b/pkgs/os-specific/linux/kernel/linux-4.19.nix @@ -3,7 +3,7 @@ with lib; buildLinux (args // rec { - version = "4.19.287"; + version = "4.19.288"; # modDirVersion needs to be x.y.z, will automatically add .0 if needed modDirVersion = versions.pad 3 version; @@ -13,6 +13,6 @@ buildLinux (args // rec { src = fetchurl { url = "mirror://kernel/linux/kernel/v4.x/linux-${version}.tar.xz"; - sha256 = "0wracrahi4qm6klsd9bnlwwdcaqbclx2mqc5d7vbvxxzfn69nsi8"; + sha256 = "1sz3jp6kx0axdwp0wsq903q1090rbav9d12m5128335m8p2d1srk"; }; } // (args.argsOverride or {})) From 4700983ddc3c5cdc8a1e3a6df082bb287f4cfc23 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 28 Jun 2023 21:10:15 +0200 Subject: [PATCH 05/26] linux: 5.10.185 -> 5.10.186 (cherry picked from commit 52f402477b6964b113ac30bd121aaadb7f1a321c) --- pkgs/os-specific/linux/kernel/linux-5.10.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/linux-5.10.nix b/pkgs/os-specific/linux/kernel/linux-5.10.nix index a94a85fd02a3..f550778eac90 100644 --- a/pkgs/os-specific/linux/kernel/linux-5.10.nix +++ b/pkgs/os-specific/linux/kernel/linux-5.10.nix @@ -3,7 +3,7 @@ with lib; buildLinux (args // rec { - version = "5.10.185"; + version = "5.10.186"; # modDirVersion needs to be x.y.z, will automatically add .0 if needed modDirVersion = versions.pad 3 version; @@ -13,6 +13,6 @@ buildLinux (args // rec { src = fetchurl { url = "mirror://kernel/linux/kernel/v5.x/linux-${version}.tar.xz"; - sha256 = "143hghmj4lxiyavndvdmwg5mig8s2i4ffrmd8zwqqwy8ipn641i8"; + sha256 = "1qqv91r13akgik1q4jybf8czskxxizk6lpv4rsvjn9sx2dm2jq0y"; }; } // (args.argsOverride or {})) From f92172c917c434e7b9e0844ddfed3f30234740c5 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 28 Jun 2023 21:10:23 +0200 Subject: [PATCH 06/26] linux: 5.15.118 -> 5.15.119 (cherry picked from commit 624ea64be10ab8bc7ca81612b7cd4be5192e6130) --- pkgs/os-specific/linux/kernel/linux-5.15.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/linux-5.15.nix b/pkgs/os-specific/linux/kernel/linux-5.15.nix index c25fdecffa37..2eb629ab6446 100644 --- a/pkgs/os-specific/linux/kernel/linux-5.15.nix +++ b/pkgs/os-specific/linux/kernel/linux-5.15.nix @@ -3,7 +3,7 @@ with lib; buildLinux (args // rec { - version = "5.15.118"; + version = "5.15.119"; # modDirVersion needs to be x.y.z, will automatically add .0 if needed modDirVersion = versions.pad 3 version; @@ -13,6 +13,6 @@ buildLinux (args // rec { src = fetchurl { url = "mirror://kernel/linux/kernel/v5.x/linux-${version}.tar.xz"; - sha256 = "1cxm7s19l2f38chxrlvx7crvqcygmc77rhsc3lfx3m84vgdg8ssf"; + sha256 = "1kygpqf6sgkrwg77sv01di23c3n3rn5d44g8k5apx5106pys19bs"; }; } // (args.argsOverride or { })) From b3e78d6c218ac4c60460041f5fe5240483f5a800 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 28 Jun 2023 21:10:29 +0200 Subject: [PATCH 07/26] linux: 5.4.248 -> 5.4.249 (cherry picked from commit 540219fde7a27f67988de9b1d7ff08301b0cf73b) --- pkgs/os-specific/linux/kernel/linux-5.4.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/linux-5.4.nix b/pkgs/os-specific/linux/kernel/linux-5.4.nix index c5d708ff6d99..99205ad33962 100644 --- a/pkgs/os-specific/linux/kernel/linux-5.4.nix +++ b/pkgs/os-specific/linux/kernel/linux-5.4.nix @@ -3,7 +3,7 @@ with lib; buildLinux (args // rec { - version = "5.4.248"; + version = "5.4.249"; # modDirVersion needs to be x.y.z, will automatically add .0 if needed modDirVersion = versions.pad 3 version; @@ -13,6 +13,6 @@ buildLinux (args // rec { src = fetchurl { url = "mirror://kernel/linux/kernel/v5.x/linux-${version}.tar.xz"; - sha256 = "0d9yn51rg59k39h0w6wmvjqz9n7najm9x8yb79rparbcwwrd3gis"; + sha256 = "079mylc5j7hk5xn59q3z2xydyh88pq7yipn67x3y7nvf5i35hm6w"; }; } // (args.argsOverride or {})) From ac8d0d30ecb3b718a6db42858bc1d10e7139f370 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 28 Jun 2023 21:10:35 +0200 Subject: [PATCH 08/26] linux: 6.1.35 -> 6.1.36 (cherry picked from commit 5c5284f1a247b9c60434635268a94dab022d3c79) --- pkgs/os-specific/linux/kernel/linux-6.1.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/linux-6.1.nix b/pkgs/os-specific/linux/kernel/linux-6.1.nix index b3d7132ca905..0d14248c5fe1 100644 --- a/pkgs/os-specific/linux/kernel/linux-6.1.nix +++ b/pkgs/os-specific/linux/kernel/linux-6.1.nix @@ -3,7 +3,7 @@ with lib; buildLinux (args // rec { - version = "6.1.35"; + version = "6.1.36"; # modDirVersion needs to be x.y.z, will automatically add .0 if needed modDirVersion = versions.pad 3 version; @@ -13,6 +13,6 @@ buildLinux (args // rec { src = fetchurl { url = "mirror://kernel/linux/kernel/v6.x/linux-${version}.tar.xz"; - sha256 = "1b16pk0b45k1q53nzbwv6wh0aqn160b1kip8scywf3axpi1q2dmy"; + sha256 = "0szyiah4avicqvlmadjxyh3i9b0xi9ipqjg1qrqgzf9h1wq0xjnq"; }; } // (args.argsOverride or { })) From 91095a9f9d1759051b455712638cca8b2efae78a Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 28 Jun 2023 21:10:41 +0200 Subject: [PATCH 09/26] linux: 6.3.9 -> 6.3.10 (cherry picked from commit c94a1a1f2708c9c5d289d64664e70e3b4903ae8b) --- pkgs/os-specific/linux/kernel/linux-6.3.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/linux-6.3.nix b/pkgs/os-specific/linux/kernel/linux-6.3.nix index e6778222b004..9a5d1ad8e5c4 100644 --- a/pkgs/os-specific/linux/kernel/linux-6.3.nix +++ b/pkgs/os-specific/linux/kernel/linux-6.3.nix @@ -3,7 +3,7 @@ with lib; buildLinux (args // rec { - version = "6.3.9"; + version = "6.3.10"; # modDirVersion needs to be x.y.z, will automatically add .0 if needed modDirVersion = versions.pad 3 version; @@ -13,6 +13,6 @@ buildLinux (args // rec { src = fetchurl { url = "mirror://kernel/linux/kernel/v6.x/linux-${version}.tar.xz"; - sha256 = "0gmi55hhdw1f1qyvd04v17x596yh8wis42vmcd8vhymik49z5v21"; + sha256 = "1qs6rmh0hk47rmz30fhjj3g7bqrz19w1ldyv6fyiq6djja3avag0"; }; } // (args.argsOverride or { })) From 9c0a91e181669da7f168d331d9be65618fab871d Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 28 Jun 2023 21:11:42 +0200 Subject: [PATCH 10/26] linux/hardened/patches/4.14: 4.14.317-hardened1 -> 4.14.319-hardened1 (cherry picked from commit bd33b62b991bb9517c049f2d2ae8d14020033f70) --- pkgs/os-specific/linux/kernel/hardened/patches.json | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/hardened/patches.json b/pkgs/os-specific/linux/kernel/hardened/patches.json index 48cf3595dbc1..5c849d5b8e06 100644 --- a/pkgs/os-specific/linux/kernel/hardened/patches.json +++ b/pkgs/os-specific/linux/kernel/hardened/patches.json @@ -2,12 +2,12 @@ "4.14": { "patch": { "extra": "-hardened1", - "name": "linux-hardened-4.14.317-hardened1.patch", - "sha256": "11jfmfanziq1k96147ddsavs1jaf201gsxpfm9i2qkz6jqrmqrsn", - "url": "https://github.com/anthraxx/linux-hardened/releases/download/4.14.317-hardened1/linux-hardened-4.14.317-hardened1.patch" + "name": "linux-hardened-4.14.319-hardened1.patch", + "sha256": "1dz59az2k1lg5csx70p4nb634cv57b7ij554hkvln7bp6m9cm1ga", + "url": "https://github.com/anthraxx/linux-hardened/releases/download/4.14.319-hardened1/linux-hardened-4.14.319-hardened1.patch" }, - "sha256": "0c1wy0m0jnjpc6scrw1y97wsg2d18vb1bi31i1qzlxvgmrd8zwlc", - "version": "4.14.317" + "sha256": "1y8zp9jkyid4g857nfm7xhsya3d9vx2dni8l7ishn2gl087pb95c", + "version": "4.14.319" }, "4.19": { "patch": { From 4a68febb0ff8c1fbb25d907ab4c1e21b8a58a5dc Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 28 Jun 2023 21:12:34 +0200 Subject: [PATCH 11/26] linux/hardened/patches/4.19: 4.19.285-hardened1 -> 4.19.287-hardened1 (cherry picked from commit ead6ae067d94f0994dcaa7853d95aab1128f36f1) --- pkgs/os-specific/linux/kernel/hardened/patches.json | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/hardened/patches.json b/pkgs/os-specific/linux/kernel/hardened/patches.json index 5c849d5b8e06..a5e7b696d7c8 100644 --- a/pkgs/os-specific/linux/kernel/hardened/patches.json +++ b/pkgs/os-specific/linux/kernel/hardened/patches.json @@ -12,12 +12,12 @@ "4.19": { "patch": { "extra": "-hardened1", - "name": "linux-hardened-4.19.285-hardened1.patch", - "sha256": "183q8c6jxss5q9vp1vvi3l233s0jf0lbn5sylavwzgdjm5anbjdr", - "url": "https://github.com/anthraxx/linux-hardened/releases/download/4.19.285-hardened1/linux-hardened-4.19.285-hardened1.patch" + "name": "linux-hardened-4.19.287-hardened1.patch", + "sha256": "1my4j6i549xw2zzbxnbaarby7584ysy4l1xgw3x8cc848l2m1iqp", + "url": "https://github.com/anthraxx/linux-hardened/releases/download/4.19.287-hardened1/linux-hardened-4.19.287-hardened1.patch" }, - "sha256": "05nwivdk4w939vrrbn5p2yai1rz7kxqa4bl5f3n6d867b59pg8da", - "version": "4.19.285" + "sha256": "0wracrahi4qm6klsd9bnlwwdcaqbclx2mqc5d7vbvxxzfn69nsi8", + "version": "4.19.287" }, "5.10": { "patch": { From ab4a3ec5a7cb336ab195590713a9ebfefe620d64 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 28 Jun 2023 21:13:00 +0200 Subject: [PATCH 12/26] linux/hardened/patches/5.10: 5.10.183-hardened1 -> 5.10.185-hardened1 (cherry picked from commit 15cf6dd4e39e83887f452dcc9f5ff14a90aa4db0) --- pkgs/os-specific/linux/kernel/hardened/patches.json | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/hardened/patches.json b/pkgs/os-specific/linux/kernel/hardened/patches.json index a5e7b696d7c8..5e9f3787dd8d 100644 --- a/pkgs/os-specific/linux/kernel/hardened/patches.json +++ b/pkgs/os-specific/linux/kernel/hardened/patches.json @@ -22,12 +22,12 @@ "5.10": { "patch": { "extra": "-hardened1", - "name": "linux-hardened-5.10.183-hardened1.patch", - "sha256": "13rpr4bgvm6zi7vpf2syxbixgbzcyqz774xil4ffyzi8zqcnbz8s", - "url": "https://github.com/anthraxx/linux-hardened/releases/download/5.10.183-hardened1/linux-hardened-5.10.183-hardened1.patch" + "name": "linux-hardened-5.10.185-hardened1.patch", + "sha256": "05abqsbsr6mjj0yxwwwf2hwsxd3z3jj2wkj0frd1ygb06njkvpjz", + "url": "https://github.com/anthraxx/linux-hardened/releases/download/5.10.185-hardened1/linux-hardened-5.10.185-hardened1.patch" }, - "sha256": "06b1nlwaqs7g3323zxp1bxfilqpbj700x591vqa9dx6a6p39g520", - "version": "5.10.183" + "sha256": "143hghmj4lxiyavndvdmwg5mig8s2i4ffrmd8zwqqwy8ipn641i8", + "version": "5.10.185" }, "5.15": { "patch": { From 22bdb2db5e3c216f5d6f1faa150cb087c41e35fe Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 28 Jun 2023 21:14:03 +0200 Subject: [PATCH 13/26] linux/hardened/patches/5.15: 5.15.116-hardened1 -> 5.15.118-hardened1 (cherry picked from commit 8346a0e03c962a52625b9c89ecd673464877cfb7) --- pkgs/os-specific/linux/kernel/hardened/patches.json | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/hardened/patches.json b/pkgs/os-specific/linux/kernel/hardened/patches.json index 5e9f3787dd8d..c165ea909f4f 100644 --- a/pkgs/os-specific/linux/kernel/hardened/patches.json +++ b/pkgs/os-specific/linux/kernel/hardened/patches.json @@ -32,12 +32,12 @@ "5.15": { "patch": { "extra": "-hardened1", - "name": "linux-hardened-5.15.116-hardened1.patch", - "sha256": "0bg4yjix7n22r2q97rcrc5svggkczap98ljq3b11688nfjnxbgbp", - "url": "https://github.com/anthraxx/linux-hardened/releases/download/5.15.116-hardened1/linux-hardened-5.15.116-hardened1.patch" + "name": "linux-hardened-5.15.118-hardened1.patch", + "sha256": "07knyxmb0j2bf117md2glyyqj892n4p4jq2ahd8s90fp0x8g6z9a", + "url": "https://github.com/anthraxx/linux-hardened/releases/download/5.15.118-hardened1/linux-hardened-5.15.118-hardened1.patch" }, - "sha256": "16hpdqlkz2g2pjcml7j55yfym6nbp0zg8f2r969wq9jkpg8wj5zn", - "version": "5.15.116" + "sha256": "1cxm7s19l2f38chxrlvx7crvqcygmc77rhsc3lfx3m84vgdg8ssf", + "version": "5.15.118" }, "5.4": { "patch": { From 59e50c01d7d7b7d567824f95f186985d07868082 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 28 Jun 2023 21:14:56 +0200 Subject: [PATCH 14/26] linux/hardened/patches/5.4: 5.4.246-hardened1 -> 5.4.248-hardened1 (cherry picked from commit 8af3229fca60ba300aae88c8e195523a05f0827a) --- pkgs/os-specific/linux/kernel/hardened/patches.json | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/hardened/patches.json b/pkgs/os-specific/linux/kernel/hardened/patches.json index c165ea909f4f..443939f9eab3 100644 --- a/pkgs/os-specific/linux/kernel/hardened/patches.json +++ b/pkgs/os-specific/linux/kernel/hardened/patches.json @@ -42,12 +42,12 @@ "5.4": { "patch": { "extra": "-hardened1", - "name": "linux-hardened-5.4.246-hardened1.patch", - "sha256": "07i8g34r9f6fjnx8bxikydik42s5nyp95q6rfl3rq48q418jd766", - "url": "https://github.com/anthraxx/linux-hardened/releases/download/5.4.246-hardened1/linux-hardened-5.4.246-hardened1.patch" + "name": "linux-hardened-5.4.248-hardened1.patch", + "sha256": "0zd1s6xxpv6j2hmm56x4pg9dxakrmkf29x3vv6pjq3hmcp8ihs4s", + "url": "https://github.com/anthraxx/linux-hardened/releases/download/5.4.248-hardened1/linux-hardened-5.4.248-hardened1.patch" }, - "sha256": "1snrgvpqpmc0d4aphq8flsmlcjjx9kgknymjlrmazl4ghl57jf09", - "version": "5.4.246" + "sha256": "0d9yn51rg59k39h0w6wmvjqz9n7najm9x8yb79rparbcwwrd3gis", + "version": "5.4.248" }, "6.1": { "patch": { From 857d441cd013eac3533c252d7af2fc6c0b3f8254 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 28 Jun 2023 21:15:03 +0200 Subject: [PATCH 15/26] linux/hardened/patches/6.1: 6.1.33-hardened1 -> 6.1.35-hardened1 (cherry picked from commit 469e88115c85de122a921281bae77734766d1337) --- pkgs/os-specific/linux/kernel/hardened/patches.json | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/hardened/patches.json b/pkgs/os-specific/linux/kernel/hardened/patches.json index 443939f9eab3..81623497aaa1 100644 --- a/pkgs/os-specific/linux/kernel/hardened/patches.json +++ b/pkgs/os-specific/linux/kernel/hardened/patches.json @@ -52,11 +52,11 @@ "6.1": { "patch": { "extra": "-hardened1", - "name": "linux-hardened-6.1.33-hardened1.patch", - "sha256": "1mfimfs9v6a852vrpckr9v0hlbqy34c3lj5fj50m7m8x25qsin5a", - "url": "https://github.com/anthraxx/linux-hardened/releases/download/6.1.33-hardened1/linux-hardened-6.1.33-hardened1.patch" + "name": "linux-hardened-6.1.35-hardened1.patch", + "sha256": "0s9ld5dnzxyizm8bdv4dc8lh3yfqv45hd65k0sc4swlnb1k96dxb", + "url": "https://github.com/anthraxx/linux-hardened/releases/download/6.1.35-hardened1/linux-hardened-6.1.35-hardened1.patch" }, - "sha256": "1kfj7mi3n2lfaw4spz5cbvcl1md038figabyg80fha3kxal6nzdq", - "version": "6.1.33" + "sha256": "1b16pk0b45k1q53nzbwv6wh0aqn160b1kip8scywf3axpi1q2dmy", + "version": "6.1.35" } } From 384061cd1e8d453386e3ad3939880d1e34c3f066 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 28 Jun 2023 21:15:15 +0200 Subject: [PATCH 16/26] linux/hardened/patches/6.3: init at 6.3.1-hardened1 (cherry picked from commit 325188d713c6a45049e472a9f860ce76f6878358) --- pkgs/os-specific/linux/kernel/hardened/patches.json | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/pkgs/os-specific/linux/kernel/hardened/patches.json b/pkgs/os-specific/linux/kernel/hardened/patches.json index 81623497aaa1..cc093f220046 100644 --- a/pkgs/os-specific/linux/kernel/hardened/patches.json +++ b/pkgs/os-specific/linux/kernel/hardened/patches.json @@ -58,5 +58,15 @@ }, "sha256": "1b16pk0b45k1q53nzbwv6wh0aqn160b1kip8scywf3axpi1q2dmy", "version": "6.1.35" + }, + "6.3": { + "patch": { + "extra": "-hardened1", + "name": "linux-hardened-6.3.1-hardened1.patch", + "sha256": "0wlp6azlkj9xbkwxyari28ixini0jvw2dl653i7ns4l27p0gmayx", + "url": "https://github.com/anthraxx/linux-hardened/releases/download/6.3.1-hardened1/linux-hardened-6.3.1-hardened1.patch" + }, + "sha256": "0aizkgwdmdjrgab67yjfaqcmvfh7wb3b3mdq9qfxpq6mlys0yqkq", + "version": "6.3.1" } } From bbce10106f1be853b59bb7dcd017468de8c74e6b Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 28 Jun 2023 21:19:26 +0200 Subject: [PATCH 17/26] linux_5_15: apply patch to fix amdgpu Closes #240017 (cherry picked from commit f193e0b8207e36fb3c6cc647fd441c11c6d22b98) --- pkgs/os-specific/linux/kernel/patches.nix | 8 ++++++++ pkgs/top-level/linux-kernels.nix | 1 + 2 files changed, 9 insertions(+) diff --git a/pkgs/os-specific/linux/kernel/patches.nix b/pkgs/os-specific/linux/kernel/patches.nix index 972235c7f852..2b46be2199a8 100644 --- a/pkgs/os-specific/linux/kernel/patches.nix +++ b/pkgs/os-specific/linux/kernel/patches.nix @@ -66,4 +66,12 @@ hash = "sha256-DYPWgraXPNeFkjtuDYkFXHnCJ4yDewrukM2CCAqC2BE="; }; }; + + fix-amdgpu-5_15 = { + name = "fix-amdgpu-crash"; + patch = fetchpatch { + url = "https://lore.kernel.org/stable/20230628111636.23300-1-mario.limonciello@amd.com/raw"; + sha256 = "sha256-eAzy+bMiOJwzssOuvrMu7gmmV3PZezaDuVwwx7zNt6M="; + }; + }; } diff --git a/pkgs/top-level/linux-kernels.nix b/pkgs/top-level/linux-kernels.nix index 217859245c81..38b2e901ed36 100644 --- a/pkgs/top-level/linux-kernels.nix +++ b/pkgs/top-level/linux-kernels.nix @@ -154,6 +154,7 @@ in { kernelPatches = [ kernelPatches.bridge_stp_helper kernelPatches.request_key_helper + kernelPatches.fix-amdgpu-5_15 ]; }; From f906c8acfeb6809035b3f6c97827e299ead39b5f Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 28 Jun 2023 21:23:00 +0200 Subject: [PATCH 18/26] linux_6_3_hardened: expose package (cherry picked from commit 0b4e493e58bf92b9784f5c0d562489364d0733e7) --- nixos/tests/kernel-generic.nix | 1 + pkgs/top-level/all-packages.nix | 2 ++ pkgs/top-level/linux-kernels.nix | 2 ++ 3 files changed, 5 insertions(+) diff --git a/nixos/tests/kernel-generic.nix b/nixos/tests/kernel-generic.nix index 3e74554de339..82d9118c6fb1 100644 --- a/nixos/tests/kernel-generic.nix +++ b/nixos/tests/kernel-generic.nix @@ -31,6 +31,7 @@ let linux_5_10_hardened linux_5_15_hardened linux_6_1_hardened + linux_6_3_hardened linux_testing; }; diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index e9a5d6d82ff7..72a48bb61b1e 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -27046,6 +27046,8 @@ with pkgs; linux_5_15_hardened = linuxKernel.kernels.linux_5_15_hardened; linuxPackages_6_1_hardened = linuxKernel.packages.linux_6_1_hardened; linux_6_1_hardened = linuxKernel.kernels.linux_6_1_hardened; + linuxPackages_6_3_hardened = linuxKernel.packages.linux_6_3_hardened; + linux_6_3_hardened = linuxKernel.kernels.linux_6_3_hardened; # Hardkernel (Odroid) kernels. linuxPackages_hardkernel_latest = linuxKernel.packageAliases.linux_hardkernel_latest; diff --git a/pkgs/top-level/linux-kernels.nix b/pkgs/top-level/linux-kernels.nix index 38b2e901ed36..40a8ff3020c5 100644 --- a/pkgs/top-level/linux-kernels.nix +++ b/pkgs/top-level/linux-kernels.nix @@ -271,6 +271,7 @@ in { linux_5_10_hardened = hardenedKernelFor kernels.linux_5_10 { }; linux_5_15_hardened = hardenedKernelFor kernels.linux_5_15 { }; linux_6_1_hardened = hardenedKernelFor kernels.linux_6_1 { }; + linux_6_3_hardened = hardenedKernelFor kernels.linux_6_3 { }; } // lib.optionalAttrs config.allowAliases { linux_4_9 = throw "linux 4.9 was removed because it will reach its end of life within 22.11"; @@ -625,6 +626,7 @@ in { linux_5_10_hardened = recurseIntoAttrs (hardenedPackagesFor kernels.linux_5_10 { }); linux_5_15_hardened = recurseIntoAttrs (hardenedPackagesFor kernels.linux_5_15 { }); linux_6_1_hardened = recurseIntoAttrs (hardenedPackagesFor kernels.linux_6_1 { }); + linux_6_3_hardened = recurseIntoAttrs (packagesFor kernels.linux_6_3_hardened); linux_zen = recurseIntoAttrs (packagesFor kernels.linux_zen); linux_lqx = recurseIntoAttrs (packagesFor kernels.linux_lqx); From facf40aabe267335ddec3370d7213e2ee8d93113 Mon Sep 17 00:00:00 2001 From: archer-65 Date: Tue, 11 Apr 2023 12:37:02 +0200 Subject: [PATCH 19/26] lieer: 1.3 -> 1.4 (cherry picked from commit 593a8d9c81021348dd6594ca55e2b0a65998d8e0) --- pkgs/applications/networking/lieer/default.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/applications/networking/lieer/default.nix b/pkgs/applications/networking/lieer/default.nix index 51fc9c8e898c..fa0867b641b1 100644 --- a/pkgs/applications/networking/lieer/default.nix +++ b/pkgs/applications/networking/lieer/default.nix @@ -2,17 +2,17 @@ python3Packages.buildPythonApplication rec { pname = "lieer"; - version = "1.3"; + version = "1.4"; src = fetchFromGitHub { owner = "gauteh"; repo = "lieer"; rev = "v${version}"; - sha256 = "12sl7d381l1gjaam419xc8gxmsprxf0hgksz1f974qmmijvr02bh"; + sha256 = "sha256-2LujfvsxMHHmYjYOnLJaLdSlzDeej+ehUr4YfVe903U="; }; propagatedBuildInputs = with python3Packages; [ - notmuch + notmuch2 oauth2client google-api-python-client tqdm From 148b24b80933f56735fde160df5e93f3970affa7 Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Fri, 30 Jun 2023 11:10:19 +0200 Subject: [PATCH 20/26] lieer: add format - equalize content (cherry picked from commit 9e111b2820c3b6ec887999401fb826a82deacf8f) --- pkgs/applications/networking/lieer/default.nix | 13 ++++++++++--- 1 file changed, 10 insertions(+), 3 deletions(-) diff --git a/pkgs/applications/networking/lieer/default.nix b/pkgs/applications/networking/lieer/default.nix index fa0867b641b1..26ecf043a4d5 100644 --- a/pkgs/applications/networking/lieer/default.nix +++ b/pkgs/applications/networking/lieer/default.nix @@ -1,13 +1,17 @@ -{ lib, fetchFromGitHub, python3Packages }: +{ lib +, fetchFromGitHub +, python3Packages +}: python3Packages.buildPythonApplication rec { pname = "lieer"; version = "1.4"; + format = "setuptools"; src = fetchFromGitHub { owner = "gauteh"; repo = "lieer"; - rev = "v${version}"; + rev = "refs/tags/v${version}"; sha256 = "sha256-2LujfvsxMHHmYjYOnLJaLdSlzDeej+ehUr4YfVe903U="; }; @@ -21,7 +25,10 @@ python3Packages.buildPythonApplication rec { # no tests doCheck = false; - pythonImportsCheck = [ "lieer" ]; + + pythonImportsCheck = [ + "lieer" + ]; meta = with lib; { description = "Fast email-fetching and two-way tag synchronization between notmuch and GMail"; From e2563c1f36755b68281c3c6555ccf3a022f54ee2 Mon Sep 17 00:00:00 2001 From: Vincent Laporte Date: Fri, 30 Jun 2023 06:48:15 +0200 Subject: [PATCH 21/26] =?UTF-8?q?coq:=208.17.0=20=E2=86=92=208.17.1?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit (cherry picked from commit 002ffb885a6b62e3ee2073145722fe616bf07757) --- pkgs/applications/science/logic/coq/default.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/applications/science/logic/coq/default.nix b/pkgs/applications/science/logic/coq/default.nix index 81fab07ecbf8..2b8d294ed1fd 100644 --- a/pkgs/applications/science/logic/coq/default.nix +++ b/pkgs/applications/science/logic/coq/default.nix @@ -54,6 +54,7 @@ let "8.16.0".sha256 = "sha256-3V6kL9j2rn5FHBxq1mtmWWTZS9X5cAyvtUsS6DaM+is="; "8.16.1".sha256 = "sha256-n7830+zfZeyYHEOGdUo57bH6bb2/SZs8zv8xJhV+iAc="; "8.17.0".sha256 = "sha256-TGwm7S6+vkeZ8cidvp8pkiAd9tk008jvvPvYgfEOXhM="; + "8.17.1".sha256 = "sha256-x+RwkbxMg9aR0L3WSCtpIz8jwA5cJA4tXAtHMZb20y4="; }; releaseRev = v: "V${v}"; fetched = import ../../../../build-support/coq/meta-fetch/default.nix From be72ee53de3664759c7e136d8aa3bb37711ffe16 Mon Sep 17 00:00:00 2001 From: sternenseemann Date: Thu, 29 Jun 2023 00:03:41 +0200 Subject: [PATCH 22/26] doc/haskell: document {enable,disable}*Profiling functions (cherry picked from commit 064b70ed59b77f4b06be6c54b23e90f54b94b189) --- doc/languages-frameworks/haskell.section.md | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/doc/languages-frameworks/haskell.section.md b/doc/languages-frameworks/haskell.section.md index a36843c97c61..d0d5fe4cb424 100644 --- a/doc/languages-frameworks/haskell.section.md +++ b/doc/languages-frameworks/haskell.section.md @@ -998,6 +998,18 @@ benchmark component. `dontCoverage drv` : Sets the `doCoverage` argument to `false` for `drv`. +`enableExecutableProfiling drv` +: Sets the `enableExecutableProfiling` argument to `true` for `drv`. + +`disableExecutableProfiling drv` +: Sets the `enableExecutableProfiling` argument to `false` for `drv`. + +`enableLibraryProfiling drv` +: Sets the `enableLibraryProfiling` argument to `true` for `drv`. + +`disableLibraryProfiling drv` +: Sets the `enableLibraryProfiling` argument to `false` for `drv`. + #### Library functions in the Haskell package sets {#haskell-package-set-lib-functions} Some library functions depend on packages from the Haskell package sets. Thus they are From 29a268989a4d4e20fcbc41be790e4990667bdf1b Mon Sep 17 00:00:00 2001 From: sternenseemann Date: Thu, 29 Jun 2023 00:04:15 +0200 Subject: [PATCH 23/26] doc/haskell: FAQ entry on changing profiling settings globally This is actually relatively complicated to achieve, since it involves overriding GHC on e.g. aarch64-darwin, so the FAQ entry seems warranted. It's also a good exercise to me, since it demonstrates some problems with the overriding infrastructure, i.e. that it has a tendency to inherit the pkgs fixpoint from prev. An example of this problem is https://github.com/NixOS/nixpkgs/issues/235960, but it has different manifestations as well. Awareness of this will also help writing the other sections on overriding. How complicated it is, seems to be further incentive to go ahead with https://github.com/NixOS/nixpkgs/pull/239548 as well. (cherry picked from commit 7b9460b29635d166d4124386e9eb609e55e2590f) --- doc/languages-frameworks/haskell.section.md | 118 ++++++++++++++++++++ 1 file changed, 118 insertions(+) diff --git a/doc/languages-frameworks/haskell.section.md b/doc/languages-frameworks/haskell.section.md index d0d5fe4cb424..105ad9e8dbb4 100644 --- a/doc/languages-frameworks/haskell.section.md +++ b/doc/languages-frameworks/haskell.section.md @@ -1084,6 +1084,124 @@ covered in the old [haskell4nix docs](https://haskell4nix.readthedocs.io/). If you feel any important topic is not documented at all, feel free to comment on the issue linked above. +### How to enable or disable profiling builds globally? {#haskell-faq-override-profiling} + +By default, Nixpkgs builds a profiling version of each Haskell library. The +exception to this rule are some platforms where it is disabled due to concerns +over output size. You may want to… + +* …enable profiling globally so that you can build a project you are working on + with profiling ability giving you insight in the time spent across your code + and code you depend on using [GHC's profiling feature][profiling]. + +* …disable profiling (globally) to reduce the time spent building the profiling + versions of libraries which a significant amount of build time is spent on + (although they are not as expensive as the “normal” build of a Haskell library). + +::: {.note} +The method described below affects the build of all libraries in the +respective Haskell package set as well as GHC. If your choices differ from +Nixpkgs' default for your (host) platform, you will lose the ability to +substitute from the official binary cache. + +If you are concerned about build times and thus want to disable profiling, it +probably makes sense to use `haskell.lib.compose.disableLibraryProfiling` (see +[](#haskell-trivial-helpers)) on the packages you are building locally while +continuing to substitute their dependencies and GHC. +::: + +Since we need to change the profiling settings for the desired Haskell package +set _and_ GHC (as the core libraries like `base`, `filepath` etc. are bundled +with GHC), it is recommended to use overlays for Nixpkgs to change them. +Since the interrelated parts, i.e. the package set and GHC, are connected +via the Nixpkgs fixpoint, we need to modify them both in a way that preserves +their connection (or else we'd have to wire it up again manually). This is +achieved by changing GHC and the package set in seperate overlays to prevent +the package set from pulling in GHC from `prev`. + +The result is two overlays like the ones shown below. Adjustable parts are +annotated with comments, as are any optional or alternative ways to achieve +the desired profiling settings without causing too many rebuilds. + + + +```nix +let + # Name of the compiler and package set you want to change. If you are using + # the default package set `haskellPackages`, you need to look up what version + # of GHC it currently uses (note that this is subject to change). + ghcName = "ghc92"; + # Desired new setting + enableProfiling = true; +in + +[ + # The first overlay modifies the GHC derivation so that it does or does not + # build profiling versions of the core libraries bundled with it. It is + # recommended to only use such an overlay if you are enabling profiling on a + # platform that doesn't by default, because compiling GHC from scratch is + # quite expensive. + (final: prev: + let + inherit (final) lib; + in + + { + haskell = lib.recursiveUpdate prev.haskell { + compiler.${ghcName} = prev.haskell.compiler.${ghcName}.override { + # Unfortunately, the GHC setting is named differently for historical reasons + enableProfiledLibs = enableProfiling; + }; + }; + }) + + (final: prev: + let + inherit (final) lib; + haskellLib = final.haskell.lib.compose; + in + + { + haskell = lib.recursiveUpdate prev.haskell { + packages.${ghcName} = prev.haskell.packages.${ghcName}.override { + overrides = hfinal: hprev: { + mkDerivation = args: hprev.mkDerivation (args // { + # Since we are forcing our ideas upon mkDerivation, this change will + # affect every package in the package set. + enableLibraryProfiling = enableProfiling; + + # To actually use profiling on an executable, executable profiling + # needs to be enabled for the executable you want to profile. You + # can either do this globally or… + enableExecutableProfiling = enableProfiling; + }); + + # …only for the package that contains an executable you want to profile. + # That saves on unnecessary rebuilds for packages that you only depend + # on for their library, but also contain executables (e.g. pandoc). + my-executable = haskellLib.enableExecutableProfiling hprev.my-executable; + + # If you are disabling profiling to save on build time, but want to + # retain the ability to substitute from the binary cache. Drop the + # override for mkDerivation above and instead have an override like + # this for the specific packages you are building locally and want + # to make cheaper to build. + my-library = haskellLib.disableLibraryProfiling hprev.my-library; + }; + }; + }; + }) +] +``` + + + [Stackage]: https://www.stackage.org [cabal-project-files]: https://cabal.readthedocs.io/en/latest/cabal-project.html [cabal2nix]: https://github.com/nixos/cabal2nix From 41249bb13fbeb7a3d0d07c89e971785b2c0dbbfc Mon Sep 17 00:00:00 2001 From: sternenseemann Date: Fri, 30 Jun 2023 01:16:55 +0200 Subject: [PATCH 24/26] haskellPackages.streamly-lmdb: obtain deps from haskell fixpoint This will make the package work in non-default haskell package sets. The issue was introduced in a1a4c4d6296ec93e72dac23df6965681e384af74. Resolves #240512. (cherry picked from commit 1c9d518cb68960748e7784d655f75d3b89337597) --- pkgs/development/haskell-modules/configuration-common.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/development/haskell-modules/configuration-common.nix b/pkgs/development/haskell-modules/configuration-common.nix index cc416469b064..a82d0bdc33c5 100644 --- a/pkgs/development/haskell-modules/configuration-common.nix +++ b/pkgs/development/haskell-modules/configuration-common.nix @@ -426,7 +426,7 @@ self: super: { streamly-lmdb = super.streamly-lmdb.override { streamly = assert (builtins.compareVersions pkgs.haskellPackages.streamly.version "0.9.0" < 0); - pkgs.haskellPackages.streamly_0_9_0; + self.streamly_0_9_0; }; # base bound From 2847fac7f4f0d614ba9efd624eb93c2da8173898 Mon Sep 17 00:00:00 2001 From: sternenseemann Date: Fri, 30 Jun 2023 01:25:55 +0200 Subject: [PATCH 25/26] haskellPackages.streamly-lmdb: drop obsolete override cabal2nix can figure this connection out by itself. (cherry picked from commit f413132a8737af2c40d47b0c8ddcbe458e502f55) --- pkgs/development/haskell-modules/configuration-nix.nix | 3 --- 1 file changed, 3 deletions(-) diff --git a/pkgs/development/haskell-modules/configuration-nix.nix b/pkgs/development/haskell-modules/configuration-nix.nix index 8002144ec30e..6b636d11a05e 100644 --- a/pkgs/development/haskell-modules/configuration-nix.nix +++ b/pkgs/development/haskell-modules/configuration-nix.nix @@ -910,9 +910,6 @@ self: super: builtins.intersectAttrs super { # Pass the correct libarchive into the package. streamly-archive = super.streamly-archive.override { archive = pkgs.libarchive; }; - # Pass the correct lmdb into the package. - streamly-lmdb = super.streamly-lmdb.override { lmdb = pkgs.lmdb; }; - hlint = overrideCabal (drv: { postInstall = '' install -Dm644 data/hlint.1 -t "$out/share/man/man1" From 77ad9cde842ecb872bef8cc0de063ebd238736e7 Mon Sep 17 00:00:00 2001 From: Mario Rodas Date: Wed, 28 Jun 2023 04:20:00 +0000 Subject: [PATCH 26/26] terraform: 1.5.1 -> 1.5.2 Diff: https://github.com/hashicorp/terraform/compare/v1.5.1...v1.5.2 Changelog: https://github.com/hashicorp/terraform/blob/v1.5.2/CHANGELOG.md (cherry picked from commit 5aa7c26001fd8578c2a65f45b858015dd5f7b2b2) --- pkgs/applications/networking/cluster/terraform/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/networking/cluster/terraform/default.nix b/pkgs/applications/networking/cluster/terraform/default.nix index 6995ee8f1c4d..111ec28dfaab 100644 --- a/pkgs/applications/networking/cluster/terraform/default.nix +++ b/pkgs/applications/networking/cluster/terraform/default.nix @@ -166,8 +166,8 @@ rec { mkTerraform = attrs: pluggable (generic attrs); terraform_1 = mkTerraform { - version = "1.5.1"; - hash = "sha256-dqnJGIoUJP37Z77TR2RBxP94Hx3AZbx90m8z1FoYdw0="; + version = "1.5.2"; + hash = "sha256-Ri2nWLjPPBINXyPIQSbnd1L+t7QLgXiTOgqX8Dk/rXg="; vendorHash = "sha256-tfCfJj39VP+P4qhJTpEIAi4XB+6VYtVKkV/bTrtnFA0="; patches = [ ./provider-path-0_15.patch ]; passthru = {