diff --git a/ci/github-script/bot.js b/ci/github-script/bot.js index 8e0043d5505c..684e3e33179a 100644 --- a/ci/github-script/bot.js +++ b/ci/github-script/bot.js @@ -395,6 +395,13 @@ module.exports = async ({ github, context, core, dry }) => { pull_number, per_page: 100, }) + + // label llm-assisted PRs accordingly + const assistedByPattern = /Assisted-by: (?!nix-init)/i + evalLabels['llm-assisted'] = prCommits.some((c) => + assistedByPattern.test(c.commit.message), + ) + const commitSubjects = prCommits.map( (c) => c.commit.message.split('\n')[0], ) diff --git a/doc/hooks/check-phase-thread-limit-hook.section.md b/doc/hooks/check-phase-thread-limit-hook.section.md new file mode 100644 index 000000000000..0adc0d309c47 --- /dev/null +++ b/doc/hooks/check-phase-thread-limit-hook.section.md @@ -0,0 +1,24 @@ +# checkPhaseThreadLimitHook {#setup-hook-check-phase-thread-limit} + +This hook defaults a variety of environment variables known +to control thread counts to 1. Many of these otherwise default +to `$(nproc)`, which causes massive overloads on build machines +if nix build jobs and build cores are already tuned to fully utilize +compute capacity of a builder without additional parallelism. + +Currently sets the following environment variables: +- [`OMP_NUM_THREADS`](https://www.openmp.org/spec-html/5.0/openmpse50.html) +- [`OPENBLAS_NUM_THREADS`](https://github.com/OpenMathLib/OpenBLAS/blob/e7b45174355edec1f04de1cabcf5ca6a98ea7fbc/USAGE.md#how-can-i-use-openblas-in-multi-threaded-applications) +- [`MKL_NUM_THREADS`](https://www.intel.com/content/www/us/en/docs/onemkl/developer-guide-linux/2023-0/mkl-domain-num-threads.html) +- [`BLIS_NUM_THREADS`](https://github.com/flame/blis/blob/b8b75b4e19459f5d618b57aa814ca38b1d82eb82/docs/Multithreading.md#specifying-multithreading) +- `VECLIB_MAXIMUM_THREADS`: Only affects darwin, see [`man 7 Accelerate`](https://manp.gs/mac/7/Accelerate) +- [`NUMBA_NUM_THREADS`](https://numba.readthedocs.io/en/stable/reference/envvars.html#threading-control) +- [`NUMEXPR_NUM_THREADS`](https://numexpr.readthedocs.io/en/latest/user_guide.html#threadpool-configuration) + +The `NIX_CHECK_PHASE_DEFAULT_NUM_THREADS` environment variable +can be used to override the default thread count limit. +`dontLimitCheckPhaseThreads = true;` can be used to disable +thread limiting on an individual package. + +This hook will not attempt to override already existing +definitions for thread count environment variables. diff --git a/doc/hooks/index.md b/doc/hooks/index.md index bac8306ff10e..d6a470f506e3 100644 --- a/doc/hooks/index.md +++ b/doc/hooks/index.md @@ -13,6 +13,7 @@ aws-c-common.section.md bmake.section.md breakpoint.section.md cernlib.section.md +check-phase-thread-limit-hook.section.md cmake.section.md desktop-file-utils.section.md gdk-pixbuf.section.md diff --git a/doc/redirects.json b/doc/redirects.json index de13226671e4..edc4696b1821 100644 --- a/doc/redirects.json +++ b/doc/redirects.json @@ -2809,6 +2809,10 @@ "setup-hook-mpi-check": [ "index.html#setup-hook-mpi-check" ], + "setup-hook-check-phase-thread-limit": [ + "index.html#setup-hook-check-phase-thread-limit", + "index.html#setup-hook-omp-check" + ], "ninja": [ "index.html#ninja" ], diff --git a/nixos/modules/module-list.nix b/nixos/modules/module-list.nix index 6134fee6a1ab..05183e91e7b5 100644 --- a/nixos/modules/module-list.nix +++ b/nixos/modules/module-list.nix @@ -327,6 +327,7 @@ ./programs/sysdig.nix ./programs/system-config-printer.nix ./programs/systemtap.nix + ./programs/tack.nix ./programs/tcpdump.nix ./programs/television.nix ./programs/throne.nix diff --git a/nixos/modules/programs/tack.nix b/nixos/modules/programs/tack.nix new file mode 100644 index 000000000000..6b39c72bda4e --- /dev/null +++ b/nixos/modules/programs/tack.nix @@ -0,0 +1,26 @@ +{ + config, + lib, + pkgs, + ... +}: +let + cfg = config.programs.tack; +in +{ + options.programs.tack = { + enable = lib.mkEnableOption "tack, flake-like toml nix pins"; + + package = lib.mkPackageOption pkgs "tack" { }; + + nixConfTokens = lib.mkEnableOption "tack reading access tokens from nix.conf (significantly improves comparison speed)"; + }; + + config = lib.mkIf cfg.enable { + environment.systemPackages = [ cfg.package ]; + + environment.sessionVariables = lib.mkIf cfg.nixConfTokens { + TACK_NIX_CONF_TOKENS = "1"; + }; + }; +} diff --git a/nixos/modules/services/networking/netbird.nix b/nixos/modules/services/networking/netbird.nix index d7514f2360d3..c96be69162cf 100644 --- a/nixos/modules/services/networking/netbird.nix +++ b/nixos/modules/services/networking/netbird.nix @@ -340,7 +340,8 @@ in substitute ${cfg.ui.package}/share/applications/netbird.desktop \ "$out/share/applications/${mkBin "netbird"}.desktop" \ --replace-fail 'Name=Netbird' "Name=NetBird @ ${client.service.name}" \ - --replace-fail 'Icon=netbird' "Icon=${cfg.ui.package}/share/pixmaps/netbird.png" + --replace-fail 'Icon=netbird' "Icon=${cfg.ui.package}/share/icons/hicolor/256x256/apps/netbird.png" \ + --replace-fail 'Exec=netbird-ui' "Exec=${mkBin "netbird-ui"}" '') ]; }; diff --git a/nixos/modules/virtualisation/incus.nix b/nixos/modules/virtualisation/incus.nix index 466e359c3147..a6557373db0c 100644 --- a/nixos/modules/virtualisation/incus.nix +++ b/nixos/modules/virtualisation/incus.nix @@ -434,6 +434,8 @@ in ] ++ lib.optionals (cfg.useACMEHost != null) [ "acme-${cfg.useACMEHost}.service" ]; + stopIfChanged = lib.mkIf cfg.softDaemonRestart false; + serviceConfig = { ExecStart = "${cfg.package}/bin/incusd --group incus-admin"; ExecStartPost = "${cfg.package}/bin/incusd waitready --timeout=${cfg.startTimeout}"; @@ -492,6 +494,7 @@ in # restarting this service will affect instances restartIfChanged = false; + stopIfChanged = false; serviceConfig = { ExecStart = "${incus-startup} start"; diff --git a/nixos/tests/zfs.nix b/nixos/tests/zfs.nix index fc5eb975226c..9a5669b04fcb 100644 --- a/nixos/tests/zfs.nix +++ b/nixos/tests/zfs.nix @@ -121,90 +121,82 @@ let }; }; - testScript = - { nodes, ... }: - let - samba = nodes.machine.specialisation.samba.configuration.system.build.toplevel; - encryption = nodes.machine.specialisation.encryption.configuration.system.build.toplevel; - forcepool = nodes.machine.specialisation.forcepool.configuration.system.build.toplevel; - in - # python - '' - machine.wait_for_unit("multi-user.target") - machine.succeed( - "zpool status", - "parted --script /dev/vdb mklabel msdos", - "parted --script /dev/vdb -- mkpart primary 1024M -1s", - "parted --script /dev/vdc mklabel msdos", - "parted --script /dev/vdc -- mkpart primary 1024M -1s", - ) + testScript = '' + machine.wait_for_unit("multi-user.target") + machine.succeed( + "zpool status", + "parted --script /dev/vdb mklabel msdos", + "parted --script /dev/vdb -- mkpart primary 1024M -1s", + "parted --script /dev/vdc mklabel msdos", + "parted --script /dev/vdc -- mkpart primary 1024M -1s", + ) - with subtest("sharesmb works"): - machine.succeed( - "zpool create rpool /dev/vdb1", - "zfs create -o mountpoint=legacy rpool/root", - # shared datasets cannot have legacy mountpoint - "zfs create rpool/shared_smb", - "${samba}/bin/switch-to-configuration boot", - "sync", - ) - machine.crash() - machine.wait_for_unit("multi-user.target") - machine.succeed("zfs set sharesmb=on rpool/shared_smb") - machine.succeed( - "smbclient -gNL localhost | grep rpool_shared_smb", - "umount /tmp/mnt", - "zpool destroy rpool", - ) + with subtest("sharesmb works"): + machine.succeed( + "zpool create rpool /dev/vdb1", + "zfs create -o mountpoint=legacy rpool/root", + # shared datasets cannot have legacy mountpoint + "zfs create rpool/shared_smb", + "bootctl set-default nixos-generation-1-specialisation-samba.conf", + "sync", + ) + machine.crash() + machine.wait_for_unit("multi-user.target") + machine.succeed("zfs set sharesmb=on rpool/shared_smb") + machine.succeed( + "smbclient -gNL localhost | grep rpool_shared_smb", + "umount /tmp/mnt", + "zpool destroy rpool", + ) - with subtest("encryption works"): - machine.succeed( - 'echo password | zpool create -O mountpoint=legacy ' - + "-O encryption=aes-256-gcm -O keyformat=passphrase automatic /dev/vdb1", - "zpool create -O mountpoint=legacy manual /dev/vdc1", - "echo otherpass | zfs create " - + "-o encryption=aes-256-gcm -o keyformat=passphrase manual/encrypted", - "zfs create -o encryption=aes-256-gcm -o keyformat=passphrase " - + "-o keylocation=http://localhost/zfskey manual/httpkey", - "${encryption}/bin/switch-to-configuration boot", - "sync", - "zpool export automatic", - "zpool export manual", - ) - machine.crash() - machine.start() - machine.wait_for_console_text("Starting password query on") - machine.send_console("password\n") - machine.wait_for_unit("multi-user.target") - machine.succeed( - "zfs get -Ho value keystatus manual/encrypted | grep -Fx unavailable", - "echo otherpass | zfs load-key manual/encrypted", - "systemctl start manual-encrypted.mount", - "zfs load-key manual/httpkey", - "systemctl start manual-httpkey.mount", - "umount /automatic /manual/encrypted /manual/httpkey /manual", - "zpool destroy automatic", - "zpool destroy manual", - ) + with subtest("encryption works"): + machine.succeed( + 'echo password | zpool create -O mountpoint=legacy ' + + "-O encryption=aes-256-gcm -O keyformat=passphrase automatic /dev/vdb1", + "zpool create -O mountpoint=legacy manual /dev/vdc1", + "echo otherpass | zfs create " + + "-o encryption=aes-256-gcm -o keyformat=passphrase manual/encrypted", + "zfs create -o encryption=aes-256-gcm -o keyformat=passphrase " + + "-o keylocation=http://localhost/zfskey manual/httpkey", + "bootctl set-default nixos-generation-1-specialisation-encryption.conf", + "sync", + "zpool export automatic", + "zpool export manual", + ) + machine.crash() + machine.start() + machine.wait_for_console_text("Starting password query on") + machine.send_console("password\n") + machine.wait_for_unit("multi-user.target") + machine.succeed( + "zfs get -Ho value keystatus manual/encrypted | grep -Fx unavailable", + "echo otherpass | zfs load-key manual/encrypted", + "systemctl start manual-encrypted.mount", + "zfs load-key manual/httpkey", + "systemctl start manual-httpkey.mount", + "umount /automatic /manual/encrypted /manual/httpkey /manual", + "zpool destroy automatic", + "zpool destroy manual", + ) - with subtest("boot.zfs.forceImportAll works"): - machine.succeed( - "rm /etc/hostid", - "zgenhostid deadcafe", - "zpool create forcepool /dev/vdb1 -O mountpoint=legacy", - "${forcepool}/bin/switch-to-configuration boot", - "rm /etc/hostid", - "sync", - ) - machine.crash() - machine.wait_for_unit("multi-user.target") - machine.fail("zpool import forcepool") - machine.succeed( - "systemctl start forcepool.mount", - "mount | grep forcepool", - ) - '' - + extraTest; + with subtest("boot.zfs.forceImportAll works"): + machine.succeed( + "rm /etc/hostid", + "zgenhostid deadcafe", + "zpool create forcepool /dev/vdb1 -O mountpoint=legacy", + "bootctl set-default nixos-generation-1-specialisation-forcepool.conf", + "rm /etc/hostid", + "sync", + ) + machine.crash() + machine.wait_for_unit("multi-user.target") + machine.fail("zpool import forcepool") + machine.succeed( + "systemctl start forcepool.mount", + "mount | grep forcepool", + ) + '' + + extraTest; }; diff --git a/pkgs/applications/graphics/inkscape/default.nix b/pkgs/applications/graphics/inkscape/default.nix index 7a5b12418a12..ccea323f700b 100644 --- a/pkgs/applications/graphics/inkscape/default.nix +++ b/pkgs/applications/graphics/inkscape/default.nix @@ -103,6 +103,14 @@ stdenv.mkDerivation (finalAttrs: { # Fix path to ps2pdf binary inherit ghostscript; }) + # https://gitlab.com/inkscape/inkscape/-/merge_requests/7919 + (fetchpatch { + name = "fix-build-poppler-26.05.0"; + url = "https://gitlab.com/inkscape/inkscape/-/commit/98828255aa0c1212329236b3ff4ac7f41efb4a67.patch"; + hash = "sha256-ujUl0SxZyb/TyJRmq1ETNn5W8lDDNn3JqHQQQPU5klA="; + }) + # https://gitlab.com/inkscape/inkscape/-/merge_requests/7968 + ./fix-build-poppler-26.06.0.patch ]; postPatch = '' diff --git a/pkgs/applications/graphics/inkscape/fix-build-poppler-26.06.0.patch b/pkgs/applications/graphics/inkscape/fix-build-poppler-26.06.0.patch new file mode 100644 index 000000000000..e9af942188db --- /dev/null +++ b/pkgs/applications/graphics/inkscape/fix-build-poppler-26.06.0.patch @@ -0,0 +1,487 @@ +From 35a470d9cbff50467cc700bc17ab2c4e8f5cf0bc Mon Sep 17 00:00:00 2001 +From: KrIr17 +Date: Mon, 8 Jun 2026 20:16:32 +0200 +Subject: [PATCH] Fix Building with Poppler 26.06.0 + +- pdfparser: Some `const PDFRectangle *` to `const PDFRectangle &` [1] +- pdfparser: Some `const GfxColor *` to `const GfxColor &` [2] +- pdf-utils: Add a `getRect(const PDFRectangle &)` alongside `getRect(const + PDFRectangle *)` +- poppler-cairo-font-engine: `getKey()` now returns std::string and not + char[], so change `strcmp` to `std::string(...).compare(...)` [3] +- poppler-utils: `obj->dictGetKey()` etc. were removed; use + `obj->dict()->getKey()` instead (these have also existed in poppler + since the beginning, so shouldn't break any old poppler) [4,5] +- svg-builder: `convertGfxColor` now takes `const GfxColor &` as input. + A convenience function taking `const GfxColor *` (for older poppler) + now calls the new one after confirming `color` is a valid pointer +- svg-builder: `_addStopToGradient` now takes `const GfxColor &` as + input. This was used only in `convertGfxColor` and therefore doesn't + need a helper function for compatibility +- testfiles pdf-utils-test: `` to `<*.h>` (see e3eb1210) +- testfiles pdf-utils-test: Some `const PDFRectangle *` + to `const PDFRectangle &` [1] + +Fixes https://gitlab.com/inkscape/inkscape/-/work_items/6210 + +Upstream Commits: + +[1] https://gitlab.freedesktop.org/poppler/poppler/-/commit/d50a4510 +[2] https://gitlab.freedesktop.org/poppler/poppler/-/commit/0f94f530 +[3] https://gitlab.freedesktop.org/poppler/poppler/-/commit/a3de7f8a +[4] https://gitlab.freedesktop.org/poppler/poppler/-/commit/bb13b0f5 +[5] https://gitlab.freedesktop.org/poppler/poppler/-/commit/8ae0f8e7 +--- + src/extension/internal/pdfinput/pdf-input.cpp | 14 +++++- + .../internal/pdfinput/pdf-parser.cpp | 45 ++++++++++--------- + src/extension/internal/pdfinput/pdf-parser.h | 4 +- + src/extension/internal/pdfinput/pdf-utils.cpp | 5 +++ + src/extension/internal/pdfinput/pdf-utils.h | 1 + + .../pdfinput/poppler-cairo-font-engine.cpp | 2 +- + .../pdfinput/poppler-transition-api.h | 16 +++++++ + .../internal/pdfinput/poppler-utils.cpp | 20 +++++---- + .../internal/pdfinput/svg-builder.cpp | 36 +++++++++------ + src/extension/internal/pdfinput/svg-builder.h | 3 +- + testfiles/src/pdf-utils-test.cpp | 7 +-- + 11 files changed, 100 insertions(+), 53 deletions(-) + +diff --git a/src/extension/internal/pdfinput/pdf-input.cpp b/src/extension/internal/pdfinput/pdf-input.cpp +index aa4285b01d..dc5394c3d8 100644 +--- a/src/extension/internal/pdfinput/pdf-input.cpp ++++ b/src/extension/internal/pdfinput/pdf-input.cpp +@@ -820,7 +820,11 @@ PdfInput::add_builder_page(std::shared_ptrpdf_doc, SvgBuilder *builder, + } + + // Apply crop settings ++#if POPPLER_CHECK_VERSION(26, 2, 0) ++ std::optional clipToBox; ++#else + _POPPLER_CONST PDFRectangle *clipToBox = nullptr; ++#endif + + if (crop_to == "media-box") { + clipToBox = page->getMediaBox(); +@@ -834,8 +838,16 @@ PdfInput::add_builder_page(std::shared_ptrpdf_doc, SvgBuilder *builder, + clipToBox = page->getArtBox(); + } + ++ std::optional cropBox; ++#if POPPLER_CHECK_VERSION(26, 2, 0) ++ cropBox = clipToBox; ++#else ++ if (clipToBox) { ++ cropBox = *clipToBox; ++ } ++#endif + // Create parser (extension/internal/pdfinput/pdf-parser.h) +- auto pdf_parser = PdfParser(pdf_doc, builder, page, clipToBox); ++ auto pdf_parser = PdfParser(pdf_doc, builder, page, cropBox); + + // Set up approximation precision for parser. Used for converting Mesh Gradients into tiles. + if ( color_delta <= 0.0 ) { +diff --git a/src/extension/internal/pdfinput/pdf-parser.cpp b/src/extension/internal/pdfinput/pdf-parser.cpp +index b336c48ce3..86fc51b1f2 100644 +--- a/src/extension/internal/pdfinput/pdf-parser.cpp ++++ b/src/extension/internal/pdfinput/pdf-parser.cpp +@@ -43,6 +43,7 @@ + #include + #include + #include ++#include + #include + #include + #include +@@ -264,7 +265,7 @@ GfxPatch blankPatch() + //------------------------------------------------------------------------ + + PdfParser::PdfParser(std::shared_ptr pdf_doc, Inkscape::Extension::Internal::SvgBuilder *builderA, Page *page, +- _POPPLER_CONST PDFRectangle *cropBox) ++ const std::optional &cropBox) + : _pdf_doc(pdf_doc) + , xref(pdf_doc->getXRef()) + , builder(builderA) +@@ -307,8 +308,8 @@ PdfParser::PdfParser(std::shared_ptr pdf_doc, Inkscape::Extension::Inter + builder->setMargins(getRect(page->getTrimBox()) * scale, + getRect(page->getArtBox()) * scale, + getRect(page->getBleedBox()) * scale); +- if (cropBox && getRect(cropBox) != page_box) { +- builder->cropPage(getRect(cropBox) * scale); ++ if (cropBox && getRect(*cropBox) != page_box) { ++ builder->cropPage(getRect(*cropBox) * scale); + } + + saveState(); +@@ -331,7 +332,7 @@ PdfParser::PdfParser(XRef *xrefA, Inkscape::Extension::Internal::SvgBuilder *bui + , printCommands(false) + , res(new GfxResources(xref, resDict, nullptr)) + , // start the resource stack +- state(new GfxState(72, 72, box, 0, false)) ++ state(new _POPPLER_GFX_STATE(72, 72, *box, 0, false)) + , fontChanged(gFalse) + , clip(clipNone) + , ignoreUndef(0) +@@ -964,7 +965,7 @@ void PdfParser::opSetFillGray(Object args[], int /*numArgs*/) + state->setFillPattern(nullptr); + state->setFillColorSpace(_POPPLER_CONSUME_UNIQPTR_ARG(std::make_unique())); + color.c[0] = dblToCol(args[0].getNum()); +- state->setFillColor(&color); ++ state->_POPPLER_SET_FILL_COLOR(color); + builder->updateStyle(state); + } + +@@ -976,7 +977,7 @@ void PdfParser::opSetStrokeGray(Object args[], int /*numArgs*/) + state->setStrokePattern(nullptr); + state->setStrokeColorSpace(_POPPLER_CONSUME_UNIQPTR_ARG(std::make_unique())); + color.c[0] = dblToCol(args[0].getNum()); +- state->setStrokeColor(&color); ++ state->_POPPLER_SET_STROKE_COLOR(color); + builder->updateStyle(state); + } + +@@ -991,7 +992,7 @@ void PdfParser::opSetFillCMYKColor(Object args[], int /*numArgs*/) + for (i = 0; i < 4; ++i) { + color.c[i] = dblToCol(args[i].getNum()); + } +- state->setFillColor(&color); ++ state->_POPPLER_SET_FILL_COLOR(color); + builder->updateStyle(state); + } + +@@ -1005,7 +1006,7 @@ void PdfParser::opSetStrokeCMYKColor(Object args[], int /*numArgs*/) + for (int i = 0; i < 4; ++i) { + color.c[i] = dblToCol(args[i].getNum()); + } +- state->setStrokeColor(&color); ++ state->_POPPLER_SET_STROKE_COLOR(color); + builder->updateStyle(state); + } + +@@ -1019,7 +1020,7 @@ void PdfParser::opSetFillRGBColor(Object args[], int /*numArgs*/) + for (int i = 0; i < 3; ++i) { + color.c[i] = dblToCol(args[i].getNum()); + } +- state->setFillColor(&color); ++ state->_POPPLER_SET_FILL_COLOR(color); + builder->updateStyle(state); + } + +@@ -1032,7 +1033,7 @@ void PdfParser::opSetStrokeRGBColor(Object args[], int /*numArgs*/) { + for (int i = 0; i < 3; ++i) { + color.c[i] = dblToCol(args[i].getNum()); + } +- state->setStrokeColor(&color); ++ state->_POPPLER_SET_STROKE_COLOR(color); + builder->updateStyle(state); + } + +@@ -1048,7 +1049,7 @@ void PdfParser::opSetFillColorSpace(Object args[], int numArgs) + GfxColor color; + colorSpace->getDefaultColor(&color); + state->setFillColorSpace(_POPPLER_CONSUME_UNIQPTR_ARG(colorSpace)); +- state->setFillColor(&color); ++ state->_POPPLER_SET_FILL_COLOR(color); + builder->updateStyle(state); + } else { + error(errSyntaxError, getPos(), "Bad color space (fill)"); +@@ -1069,7 +1070,7 @@ void PdfParser::opSetStrokeColorSpace(Object args[], int numArgs) + GfxColor color; + colorSpace->getDefaultColor(&color); + state->setStrokeColorSpace(_POPPLER_CONSUME_UNIQPTR_ARG(colorSpace)); +- state->setStrokeColor(&color); ++ state->_POPPLER_SET_STROKE_COLOR(color); + builder->updateStyle(state); + } else { + error(errSyntaxError, getPos(), "Bad color space (stroke)"); +@@ -1089,7 +1090,7 @@ void PdfParser::opSetFillColor(Object args[], int numArgs) { + for (i = 0; i < numArgs; ++i) { + color.c[i] = dblToCol(args[i].getNum()); + } +- state->setFillColor(&color); ++ state->_POPPLER_SET_FILL_COLOR(color); + builder->updateStyle(state); + } + +@@ -1106,7 +1107,7 @@ void PdfParser::opSetStrokeColor(Object args[], int numArgs) { + for (i = 0; i < numArgs; ++i) { + color.c[i] = dblToCol(args[i].getNum()); + } +- state->setStrokeColor(&color); ++ state->_POPPLER_SET_STROKE_COLOR(color); + builder->updateStyle(state); + } + +@@ -1127,7 +1128,7 @@ void PdfParser::opSetFillColorN(Object args[], int numArgs) { + color.c[i] = dblToCol(args[i].getNum()); + } + } +- state->setFillColor(&color); ++ state->_POPPLER_SET_FILL_COLOR(color); + builder->updateStyle(state); + } + if (auto pattern = lookupPattern(&(args[numArgs - 1]), state)) { +@@ -1146,7 +1147,7 @@ void PdfParser::opSetFillColorN(Object args[], int numArgs) { + color.c[i] = dblToCol(args[i].getNum()); + } + } +- state->setFillColor(&color); ++ state->_POPPLER_SET_FILL_COLOR(color); + builder->updateStyle(state); + } + } +@@ -1170,7 +1171,7 @@ void PdfParser::opSetStrokeColorN(Object args[], int numArgs) { + color.c[i] = dblToCol(args[i].getNum()); + } + } +- state->setStrokeColor(&color); ++ state->_POPPLER_SET_STROKE_COLOR(color); + builder->updateStyle(state); + } + if (auto pattern = lookupPattern(&(args[numArgs - 1]), state)) { +@@ -1189,7 +1190,7 @@ void PdfParser::opSetStrokeColorN(Object args[], int numArgs) { + color.c[i] = dblToCol(args[i].getNum()); + } + } +- state->setStrokeColor(&color); ++ state->_POPPLER_SET_STROKE_COLOR(color); + builder->updateStyle(state); + } + } +@@ -1673,7 +1674,7 @@ void PdfParser::doFunctionShFill1(GfxFunctionShading *shading, + + // use the center color + shading->getColor(xM, yM, &fillColor); +- state->setFillColor(&fillColor); ++ state->_POPPLER_SET_FILL_COLOR(fillColor); + + // fill the rectangle + state->moveTo(x0 * matrix[0] + y0 * matrix[2] + matrix[4], +@@ -1799,7 +1800,7 @@ void PdfParser::gouraudFillTriangle(double x0, double y0, GfxColor *color0, + } + } + if (i == nComps || depth == maxDepths[pdfGouraudTriangleShading-1]) { +- state->setFillColor(color0); ++ state->_POPPLER_SET_FILL_COLOR(*color0); + state->moveTo(x0, y0); + state->lineTo(x1, y1); + state->lineTo(x2, y2); +@@ -1877,7 +1878,7 @@ void PdfParser::fillPatch(_POPPLER_CONST GfxPatch *patch, int nComps, int depth) + color.c[i] = GfxColorComp(patch->color[0][0].c[i]); + } + if (i == nComps || depth == maxDepths[pdfPatchMeshShading-1]) { +- state->setFillColor(&color); ++ state->_POPPLER_SET_FILL_COLOR(color); + state->moveTo(patch->x[0][0], patch->y[0][0]); + state->curveTo(patch->x[0][1], patch->y[0][1], + patch->x[0][2], patch->y[0][2], +diff --git a/src/extension/internal/pdfinput/pdf-parser.h b/src/extension/internal/pdfinput/pdf-parser.h +index 098ff26e26..29dd259167 100644 +--- a/src/extension/internal/pdfinput/pdf-parser.h ++++ b/src/extension/internal/pdfinput/pdf-parser.h +@@ -113,8 +113,8 @@ struct OpHistoryEntry { + class PdfParser { + public: + +- // Constructor for regular output. +- PdfParser(std::shared_ptr pdf_doc, SvgBuilder *builderA, Page *page, _POPPLER_CONST PDFRectangle *cropBox); ++ // Constructor for regular output. ++ PdfParser(std::shared_ptr pdf_doc, SvgBuilder *builderA, Page *page, const std::optional &cropBox); + // Constructor for a sub-page object. + PdfParser(XRef *xrefA, SvgBuilder *builderA, Dict *resDict, _POPPLER_CONST PDFRectangle *box); + +diff --git a/src/extension/internal/pdfinput/pdf-utils.cpp b/src/extension/internal/pdfinput/pdf-utils.cpp +index 22e5df62c8..3aa6c02d3c 100644 +--- a/src/extension/internal/pdfinput/pdf-utils.cpp ++++ b/src/extension/internal/pdfinput/pdf-utils.cpp +@@ -133,6 +133,11 @@ Geom::Rect getRect(_POPPLER_CONST PDFRectangle *box) + return Geom::Rect(box->x1, box->y1, box->x2, box->y2); + } + ++Geom::Rect getRect(const PDFRectangle &box) ++{ ++ return Geom::Rect(box.x1, box.y1, box.x2, box.y2); ++} ++ + Geom::PathVector getPathV(GfxPath *path) + { + if (!path) { +diff --git a/src/extension/internal/pdfinput/pdf-utils.h b/src/extension/internal/pdfinput/pdf-utils.h +index d259a8c2f7..30e9b5bf86 100644 +--- a/src/extension/internal/pdfinput/pdf-utils.h ++++ b/src/extension/internal/pdfinput/pdf-utils.h +@@ -59,6 +59,7 @@ private: + }; + + Geom::Rect getRect(_POPPLER_CONST PDFRectangle *box); ++Geom::Rect getRect(_POPPLER_CONST PDFRectangle &box); + Geom::PathVector getPathV(GfxPath *gPath); + + #endif /* PDF_UTILS_H */ +diff --git a/src/extension/internal/pdfinput/poppler-cairo-font-engine.cpp b/src/extension/internal/pdfinput/poppler-cairo-font-engine.cpp +index 19ebd26693..39ce22af38 100644 +--- a/src/extension/internal/pdfinput/poppler-cairo-font-engine.cpp ++++ b/src/extension/internal/pdfinput/poppler-cairo-font-engine.cpp +@@ -713,7 +713,7 @@ CairoType3Font *CairoType3Font::create(GfxFont *gfxFont, PDFDoc *doc, CairoFontE + codeToGID[i] = 0; + if (charProcs && (name = enc[i])) { + for (int j = 0; j < charProcs->getLength(); j++) { +- if (strcmp(name, charProcs->getKey(j)) == 0) { ++ if (std::string(charProcs->getKey(j)).compare(name) == 0) { + codeToGID[i] = j; + } + } +diff --git a/src/extension/internal/pdfinput/poppler-transition-api.h b/src/extension/internal/pdfinput/poppler-transition-api.h +index d69829d512..23550a3068 100644 +--- a/src/extension/internal/pdfinput/poppler-transition-api.h ++++ b/src/extension/internal/pdfinput/poppler-transition-api.h +@@ -15,6 +15,22 @@ + #include + #include + ++#if POPPLER_CHECK_VERSION(26, 6, 0) ++#define _POPPLER_GET_GRAY(color, gray) getGray(color, gray) ++#define _POPPLER_GET_RGB(color, rgb) getRGB(color, rgb) ++#define _POPPLER_GET_CMYK(color, cmyk) getCMYK(color, cmyk) ++#define _POPPLER_SET_FILL_COLOR(color) setFillColor(color) ++#define _POPPLER_SET_STROKE_COLOR(color) setStrokeColor(color) ++#define _POPPLER_GFX_STATE(h, v, Rect, rotateA, upsideDown) GfxState(h, v, Rect, rotateA, upsideDown) ++#else ++#define _POPPLER_GET_GRAY(color, gray) getGray(&color, gray) ++#define _POPPLER_GET_RGB(color, rgb) getRGB(&color, rgb) ++#define _POPPLER_GET_CMYK(color, cmyk) getCMYK(&color, cmyk) ++#define _POPPLER_SET_FILL_COLOR(color) setFillColor(&color) ++#define _POPPLER_SET_STROKE_COLOR(color) setStrokeColor(&color) ++#define _POPPLER_GFX_STATE(h, v, Rect, rotateA, upsideDown) GfxState(h, v, &Rect, rotateA, upsideDown) ++#endif ++ + #if POPPLER_CHECK_VERSION(26, 2, 0) + #define _POPPLER_WMODE GfxFont::WritingMode + #define _POPPLER_WMODE_HORIZONTAL GfxFont::WritingMode::Horizontal +diff --git a/src/extension/internal/pdfinput/poppler-utils.cpp b/src/extension/internal/pdfinput/poppler-utils.cpp +index 2338dbe2d9..66dcf85e1d 100644 +--- a/src/extension/internal/pdfinput/poppler-utils.cpp ++++ b/src/extension/internal/pdfinput/poppler-utils.cpp +@@ -196,15 +196,17 @@ void InkFontDict::hashFontObject1(const Object *obj, FNVHash *h) + hashFontObject1(&obj2, h); + } + break; +- case objDict: +- h->hash('d'); +- n = obj->dictGetLength(); +- h->hash((char *)&n, sizeof(int)); +- for (i = 0; i < n; ++i) { +- p = obj->dictGetKey(i); +- h->hash(p, (int)strlen(p)); +- const Object &obj2 = obj->dictGetValNF(i); +- hashFontObject1(&obj2, h); ++ case objDict: { ++ h->hash('d'); ++ auto objdict = obj->getDict(); ++ n = objdict->getLength(); ++ h->hash((char *)&n, sizeof(int)); ++ for (i = 0; i < n; ++i) { ++ auto p = std::string(objdict->getKey(i)); ++ h->hash(p.c_str(), p.length()); ++ const Object &obj2 = objdict->getValNF(i); ++ hashFontObject1(&obj2, h); ++ } + } + break; + case objStream: +diff --git a/src/extension/internal/pdfinput/svg-builder.cpp b/src/extension/internal/pdfinput/svg-builder.cpp +index 3dfdfbbed4..bf7ccf1a8b 100644 +--- a/src/extension/internal/pdfinput/svg-builder.cpp ++++ b/src/extension/internal/pdfinput/svg-builder.cpp +@@ -392,7 +392,15 @@ static std::string svgConvertGfxRGB(GfxRGB *color) + return svgConvertRGBToText(r, g, b); + } + +-std::string SvgBuilder::convertGfxColor(const GfxColor *color, GfxColorSpace *space) ++// for poppler < 26.06.0 ++std::string SvgBuilder::convertGfxColor(const GfxColor *color, GfxColorSpace *space) { ++ if (!color) { ++ return ""; ++ } ++ return convertGfxColor(*color, space); ++} ++ ++std::string SvgBuilder::convertGfxColor(const GfxColor &color, GfxColorSpace *space) + { + std::string icc = ""; + switch (space->getMode()) { +@@ -419,7 +427,7 @@ std::string SvgBuilder::convertGfxColor(const GfxColor *color, GfxColorSpace *sp + Inkscape::CSSOStringStream icc_color; + icc_color << rgb_color << " icc-color(" << icc; + for (int i = 0; i < space->getNComps(); ++i) { +- icc_color << ", " << colToDbl((*color).c[i]); ++ icc_color << ", " << colToDbl((color).c[i]); + } + icc_color << ");"; + return icc_color.str(); +@@ -1204,7 +1212,7 @@ gchar *SvgBuilder::_createGradient(GfxShading *shading, const Geom::Affine pat_m + /** + * \brief Adds a stop with the given properties to the gradient's representation + */ +-void SvgBuilder::_addStopToGradient(Inkscape::XML::Node *gradient, double offset, GfxColor *color, GfxColorSpace *space, ++void SvgBuilder::_addStopToGradient(Inkscape::XML::Node *gradient, double offset, GfxColor &color, GfxColorSpace *space, + double opacity) + { + Inkscape::XML::Node *stop = _xml_doc->createElement("svg:stop"); +@@ -1255,8 +1263,8 @@ bool SvgBuilder::_addGradientStops(Inkscape::XML::Node *gradient, GfxShading *sh + if (!svgGetShadingColor(shading, 0.0, &stop1) || !svgGetShadingColor(shading, 1.0, &stop2)) { + return false; + } else { +- _addStopToGradient(gradient, 0.0, &stop1, space, 1.0); +- _addStopToGradient(gradient, 1.0, &stop2, space, 1.0); ++ _addStopToGradient(gradient, 0.0, stop1, space, 1.0); ++ _addStopToGradient(gradient, 1.0, stop2, space, 1.0); + } + } else if (type == _POPPLER_FUNCTION_TYPE_STITCHING) { + auto stitchingFunc = static_cast<_POPPLER_CONST StitchingFunction*>(func); +@@ -1269,7 +1277,7 @@ bool SvgBuilder::_addGradientStops(Inkscape::XML::Node *gradient, GfxShading *sh + // Add stops from all the stitched functions + GfxColor prev_color, color; + svgGetShadingColor(shading, bounds[0], &prev_color); +- _addStopToGradient(gradient, bounds[0], &prev_color, space, 1.0); ++ _addStopToGradient(gradient, bounds[0], prev_color, space, 1.0); + for ( int i = 0 ; i < num_funcs ; i++ ) { + svgGetShadingColor(shading, bounds[i + 1], &color); + // Add stops +@@ -1279,14 +1287,14 @@ bool SvgBuilder::_addGradientStops(Inkscape::XML::Node *gradient, GfxShading *sh + expE = (bounds[i + 1] - bounds[i])/expE; // approximate exponential as a single straight line at x=1 + if (encode[2*i] == 0) { // normal sequence + auto offset = (bounds[i + 1] - expE) / max_bound; +- _addStopToGradient(gradient, offset, &prev_color, space, 1.0); ++ _addStopToGradient(gradient, offset, prev_color, space, 1.0); + } else { // reflected sequence + auto offset = (bounds[i] + expE) / max_bound; +- _addStopToGradient(gradient, offset, &color, space, 1.0); ++ _addStopToGradient(gradient, offset, color, space, 1.0); + } + } + } +- _addStopToGradient(gradient, bounds[i + 1] / max_bound, &color, space, 1.0); ++ _addStopToGradient(gradient, bounds[i + 1] / max_bound, color, space, 1.0); + prev_color = color; + } + } else { // Unsupported function type +diff --git a/src/extension/internal/pdfinput/svg-builder.h b/src/extension/internal/pdfinput/svg-builder.h +index c4b217f58e..348f3a2ce3 100644 +--- a/src/extension/internal/pdfinput/svg-builder.h ++++ b/src/extension/internal/pdfinput/svg-builder.h +@@ -186,7 +186,7 @@ private: + // Pattern creation + gchar *_createPattern(GfxPattern *pattern, GfxState *state, bool is_stroke=false); + gchar *_createGradient(GfxShading *shading, const Geom::Affine pat_matrix, bool for_shading = false); +- void _addStopToGradient(Inkscape::XML::Node *gradient, double offset, GfxColor *color, GfxColorSpace *space, ++ void _addStopToGradient(Inkscape::XML::Node *gradient, double offset, GfxColor &color, GfxColorSpace *space, + double opacity); + bool _addGradientStops(Inkscape::XML::Node *gradient, GfxShading *shading, + _POPPLER_CONST Function *func); +@@ -239,6 +239,7 @@ private: + static bool _attrEqual(Inkscape::XML::Node *a, Inkscape::XML::Node *b, char const *attr); + + // Colors ++ std::string convertGfxColor(const GfxColor &color, GfxColorSpace *space); + std::string convertGfxColor(const GfxColor *color, GfxColorSpace *space); + std::string _getColorProfile(cmsHPROFILE hp); + diff --git a/pkgs/applications/networking/browsers/chromium/info.json b/pkgs/applications/networking/browsers/chromium/info.json index 33f308b23834..35362f5c1598 100644 --- a/pkgs/applications/networking/browsers/chromium/info.json +++ b/pkgs/applications/networking/browsers/chromium/info.json @@ -1,10 +1,10 @@ { "chromium": { - "version": "150.0.7871.124", + "version": "150.0.7871.128", "chromedriver": { - "version": "150.0.7871.125", - "hash_darwin": "sha256-HJTBS6eRmAsxrn7WW4hCxMCXdzn+1PYz1W0uZHJ38yk=", - "hash_darwin_aarch64": "sha256-VCgkc6MeMPbt0F2ZVTJNn9yJbSYNhy1zr8KzPVaVi0I=" + "version": "150.0.7871.129", + "hash_darwin": "sha256-jeDZ/6nFKOc9XyAA1marZ/KVaxsQPznTP1/UhXoDapY=", + "hash_darwin_aarch64": "sha256-CtfrqG/AeXCg7Sl6LoidM+OhYvBWkRJoAxv3g68wqUw=" }, "deps": { "depot_tools": { @@ -21,8 +21,8 @@ "DEPS": { "src": { "url": "https://chromium.googlesource.com/chromium/src.git", - "rev": "9261fd0a595ac4964ea84e6bd4a025c1173a2ffa", - "hash": "sha256-YKkZfxFZ7mitD6YqJZW+NQByq71UVb0jCFIBXj0SyzU=", + "rev": "81891e5ca708047763816c778216799ef14c66cb", + "hash": "sha256-lGHZZ2xIih+TaH145CZwEwyXsM1ZQWwqXsIQjWQ/jvk=", "recompress": true }, "src/third_party/clang-format/script": { @@ -827,8 +827,8 @@ }, "src/v8": { "url": "https://chromium.googlesource.com/v8/v8.git", - "rev": "209c9cea0db17d8caf23e9d2c7de08c351609744", - "hash": "sha256-3jUyRERu1r+Fl2uSAaRchV2L99XLp8XO9DHctk0lMjY=" + "rev": "2b2f69158528fdd9d86b778cfcc2d0a1c4f8c59f", + "hash": "sha256-bqzCZSpKdXgKv3O1I7ck1PEXCa/2jBT7hpBEKW0LgTA=" }, "src/agents/shared": { "url": "https://chromium.googlesource.com/chromium/agents.git", @@ -838,7 +838,7 @@ } }, "ungoogled-chromium": { - "version": "150.0.7871.124", + "version": "150.0.7871.128", "deps": { "depot_tools": { "rev": "f4fadaf6a5ba1bced9d3d9021060667b563bf583", @@ -850,16 +850,16 @@ "hash": "sha256-/1A+DkzAQj2zGPe/A/G0Z3VrYJXUxq4Hd/+d/o5p3G8=" }, "ungoogled-patches": { - "rev": "150.0.7871.124-1", - "hash": "sha256-3dwDG3YuX/l5bOLcC3lICM2qmGnwVAPPJraDRaHZSe8=" + "rev": "150.0.7871.128-1", + "hash": "sha256-GxSsGTC68IEMPt85RLBCVDT0dTl7ZVVPc8o4vxc50H8=" }, "npmHash": "sha256-pF0JtwFpPC4/fodbhSJnQKkczA9WlDg4VqEAy9aDVLg=" }, "DEPS": { "src": { "url": "https://chromium.googlesource.com/chromium/src.git", - "rev": "9261fd0a595ac4964ea84e6bd4a025c1173a2ffa", - "hash": "sha256-YKkZfxFZ7mitD6YqJZW+NQByq71UVb0jCFIBXj0SyzU=", + "rev": "81891e5ca708047763816c778216799ef14c66cb", + "hash": "sha256-lGHZZ2xIih+TaH145CZwEwyXsM1ZQWwqXsIQjWQ/jvk=", "recompress": true }, "src/third_party/clang-format/script": { @@ -1664,8 +1664,8 @@ }, "src/v8": { "url": "https://chromium.googlesource.com/v8/v8.git", - "rev": "209c9cea0db17d8caf23e9d2c7de08c351609744", - "hash": "sha256-3jUyRERu1r+Fl2uSAaRchV2L99XLp8XO9DHctk0lMjY=" + "rev": "2b2f69158528fdd9d86b778cfcc2d0a1c4f8c59f", + "hash": "sha256-bqzCZSpKdXgKv3O1I7ck1PEXCa/2jBT7hpBEKW0LgTA=" }, "src/agents/shared": { "url": "https://chromium.googlesource.com/chromium/agents.git", diff --git a/pkgs/applications/office/libreoffice/default.nix b/pkgs/applications/office/libreoffice/default.nix index 75880b33f528..74eeadee0ef3 100644 --- a/pkgs/applications/office/libreoffice/default.nix +++ b/pkgs/applications/office/libreoffice/default.nix @@ -397,6 +397,34 @@ stdenv.mkDerivation (finalAttrs: { # Don't detect Qt paths from qmake, so our patched-in onese are used ./dont-detect-qt-paths-from-qmake.patch + + # Fix build with Poppler 26.02 + (fetchpatch2 { + url = "https://gitlab.archlinux.org/archlinux/packaging/packages/libreoffice-still/-/raw/25.8.7-2/fix_build_with_poppler_26.02.0.patch"; + hash = "sha256-IInhSoqTemDITB+AtkvVa9eGbodTbUGSpMMpC9N/mmg="; + }) + # Fix build with Poppler 26.04 + (fetchpatch2 { + url = "https://gitlab.archlinux.org/archlinux/packaging/packages/libreoffice-still/-/raw/25.8.7-2/fix_build_with_poppler_26.04.0.patch"; + hash = "sha256-I9owj/NTCTi6ISszuasH410NLlhunPn/Ig22tenu8tw="; + }) + # Fix build with Poppler 26.05 + (fetchpatch2 { + url = "https://gitlab.archlinux.org/archlinux/packaging/packages/libreoffice-still/-/raw/25.8.7-2/fix_build_with_poppler_26.05.0.patch"; + hash = "sha256-7wdiciTf/LrTk0MibBBYGliWRCvK1rtTGESgH7db1I4="; + }) + # Fix build with Poppler 26.06 + (fetchpatch2 { + url = "https://gitlab.archlinux.org/archlinux/packaging/packages/libreoffice-still/-/raw/25.8.7-3/fix_build_with_poppler_26.06.0.patch"; + hash = "sha256-j66IsrzaqQ55MRVzhlw25guuoDtxx1D4XeJsBhgWP2c="; + }) + ] + ++ lib.optionals (variant != "fresh") [ + # Fix build with Poppler 26.01 + (fetchpatch2 { + url = "https://gitlab.archlinux.org/archlinux/packaging/packages/libreoffice-still/-/raw/25.8.7-2/fix_build_with_poppler_26.01.0.patch"; + hash = "sha256-5JTTvJFIV5MG0Gz7y46wAr3q9tWdSVoZ9TJQlMJVqBc="; + }) ] ++ lib.optionals (variant != "collabora" && variant != "collabora-coda") [ # Revert part of https://github.com/LibreOffice/core/commit/6f60670877208612b5ea320b3677480ef6508abb that broke zlib linking diff --git a/pkgs/build-support/build-mozilla-mach/153-cbindgen-0.29.4-compat.patch b/pkgs/build-support/build-mozilla-mach/153-cbindgen-0.29.4-compat.patch new file mode 100644 index 000000000000..84238f025fc6 --- /dev/null +++ b/pkgs/build-support/build-mozilla-mach/153-cbindgen-0.29.4-compat.patch @@ -0,0 +1,36 @@ +commit c4aab1ba6aadd6985fcd271679d2118f094ec876 +Author: Emilio Cobos Álvarez +Date: Tue Jun 9 22:04:44 2026 +0000 + + Bug 2046162 - Remove some redundant pub qualifiers. r=gfx-reviewers,aosmond + + The enum is not public so this doesn't change behavior but a patch I'm + working on in cbindgen gets a bit confused with this. + + Differential Revision: https://phabricator.services.mozilla.com/D305678 + +diff --git a/gfx/wr/webrender/src/texture_cache.rs b/gfx/wr/webrender/src/texture_cache.rs +index e14c26bd3190..77e1f3a312ac 100644 +--- a/gfx/wr/webrender/src/texture_cache.rs ++++ b/gfx/wr/webrender/src/texture_cache.rs +@@ -273,9 +273,9 @@ enum BudgetType { + } + + impl BudgetType { +- pub const COUNT: usize = 7; ++ const COUNT: usize = 7; + +- pub const VALUES: [BudgetType; BudgetType::COUNT] = [ ++ const VALUES: [BudgetType; BudgetType::COUNT] = [ + BudgetType::SharedColor8Linear, + BudgetType::SharedColor8Nearest, + BudgetType::SharedColor8Glyphs, +@@ -285,7 +285,7 @@ impl BudgetType { + BudgetType::Standalone, + ]; + +- pub const PRESSURE_COUNTERS: [usize; BudgetType::COUNT] = [ ++ const PRESSURE_COUNTERS: [usize; BudgetType::COUNT] = [ + profiler::ATLAS_COLOR8_LINEAR_PRESSURE, + profiler::ATLAS_COLOR8_NEAREST_PRESSURE, + profiler::ATLAS_COLOR8_GLYPHS_PRESSURE, diff --git a/pkgs/build-support/build-mozilla-mach/default.nix b/pkgs/build-support/build-mozilla-mach/default.nix index 963fe1edbe75..a91060148cba 100644 --- a/pkgs/build-support/build-mozilla-mach/default.nix +++ b/pkgs/build-support/build-mozilla-mach/default.nix @@ -343,6 +343,11 @@ buildStdenv.mkDerivation { # https://bugzilla.mozilla.org/show_bug.cgi?id=1985509 ./140-bindgen-string-view.patch ] + ++ lib.optionals (lib.versionAtLeast version "140" && lib.versionOlder version "140.13") [ + # https://github.com/mozilla/cbindgen/issues/1165 + # https://bugzilla.mozilla.org/show_bug.cgi?id=2046162 + ./153-cbindgen-0.29.4-compat.patch + ] ++ extraPatches; postPatch = '' diff --git a/pkgs/by-name/aw/aws-c-http/package.nix b/pkgs/by-name/aw/aws-c-http/package.nix index 01b333b01b35..9f0fd8c16f04 100644 --- a/pkgs/by-name/aw/aws-c-http/package.nix +++ b/pkgs/by-name/aw/aws-c-http/package.nix @@ -14,13 +14,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "aws-c-http"; # nixpkgs-update: no auto update - version = "0.10.4"; + version = "0.11.0"; src = fetchFromGitHub { owner = "awslabs"; repo = "aws-c-http"; rev = "v${finalAttrs.version}"; - hash = "sha256-t9PoxOjgV9qLris+C18SaEwXodBGcgK591LZl0dajxU="; + hash = "sha256-SCdZfGIIHU6f0OArygZm0yY0wE6Hdx/JWvHZcK1DQOw="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/aw/aws-c-io/package.nix b/pkgs/by-name/aw/aws-c-io/package.nix index 590195761664..960d79c9a43d 100644 --- a/pkgs/by-name/aw/aws-c-io/package.nix +++ b/pkgs/by-name/aw/aws-c-io/package.nix @@ -12,13 +12,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "aws-c-io"; # nixpkgs-update: no auto update - version = "0.22.0"; + version = "0.27.2"; src = fetchFromGitHub { owner = "awslabs"; repo = "aws-c-io"; rev = "v${finalAttrs.version}"; - hash = "sha256-NOEjXk4s/FV4CdmyXOr4Oh2y+pFNrUMP/Sy+X+fVQc4="; + hash = "sha256-0vzuSvJ/4you0YYnizjctKP5AcLm5sJieDOSCHwm1HM="; }; nativeBuildInputs = [ cmake ]; diff --git a/pkgs/by-name/bl/blackfire/package.nix b/pkgs/by-name/bl/blackfire/package.nix index 0205b58df2db..7396607f951c 100644 --- a/pkgs/by-name/bl/blackfire/package.nix +++ b/pkgs/by-name/bl/blackfire/package.nix @@ -11,7 +11,7 @@ stdenv.mkDerivation rec { pname = "blackfire"; - version = "2026.6.1"; + version = "2026.7.0"; src = passthru.sources.${stdenv.hostPlatform.system} @@ -60,19 +60,19 @@ stdenv.mkDerivation rec { sources = { "x86_64-linux" = fetchurl { url = "https://packages.blackfire.io/debian/pool/any/main/b/blackfire/blackfire_${version}_amd64.deb"; - hash = "sha256-doeqXoS0B7AyzyhkLB9wUC6iuD0c2KIhAIEPeYaDC5E="; + hash = "sha256-GzhcK+7NrQEP48XFmOQ9PVrvvsUzrCy/VRcshTSic9E="; }; "i686-linux" = fetchurl { url = "https://packages.blackfire.io/debian/pool/any/main/b/blackfire/blackfire_${version}_i386.deb"; - hash = "sha256-bQWhiSw9/gGyGoLEyz6BHaRPNLxuqouiobBMfB5ytYk="; + hash = "sha256-F6U7YHSBE5Ogie2yBSGGUKt0XsE8jogKi2GP28H1Eeo="; }; "aarch64-linux" = fetchurl { url = "https://packages.blackfire.io/debian/pool/any/main/b/blackfire/blackfire_${version}_arm64.deb"; - hash = "sha256-B+rhmnM2sVICVLDcYq2OEp402Wz6kywCRqeS95Vdzlw="; + hash = "sha256-eDJAjd/5omgUJ6sw5kCqxu7Ok2AYei/WGlXV96Ynd/U="; }; "aarch64-darwin" = fetchurl { url = "https://packages.blackfire.io/blackfire/${version}/blackfire-darwin_arm64.pkg.tar.gz"; - hash = "sha256-Ofs9raAtx/duS8dXWfvjKGzhJr3j9+gkH8lP/VLfnkE="; + hash = "sha256-xzWw6us+9/r8lMMHZTgE++rX7ZZShAL7L7fOneALA4Q="; }; "x86_64-darwin" = fetchurl { url = "https://packages.blackfire.io/blackfire/${version}/blackfire-darwin_amd64.pkg.tar.gz"; diff --git a/pkgs/by-name/bl/blackfire/php-probe.nix b/pkgs/by-name/bl/blackfire/php-probe.nix index d6eedd99df7a..51181437257b 100644 --- a/pkgs/by-name/bl/blackfire/php-probe.nix +++ b/pkgs/by-name/bl/blackfire/php-probe.nix @@ -16,57 +16,57 @@ let phpMajor = lib.versions.majorMinor php.version; inherit (stdenv.hostPlatform) system; - version = "2026.5.0"; + version = "2026.7.0"; hashes = { "x86_64-linux" = { system = "amd64"; hash = { - "8.1" = "sha256-FQzmRL1Dk4HBnrfbfOclDWGvqflFXTUMK8b1NLIb880="; - "8.2" = "sha256-e2+hVsoBXt8gURRvGC4bgAkLpB1GriefokAjFFUuO8c="; - "8.3" = "sha256-C/NsbJ8XlkBPlZ0lPeNL4SWxfVWSLxvQYDxTVf2PfyA="; - "8.4" = "sha256-gqEV9thI/oe38/dyrGZxhPtv4+ufzMDXJL0zgt8IbOA="; - "8.5" = "sha256-kw57CBFOcRpaToXD/V2veXjcQnVaM3uTLC3tgrKyNzc="; + "8.1" = "sha256-fs1zJkObPMoG6hta2fCOO6UI79nkqoKGNN7S92NSf0c="; + "8.2" = "sha256-UITSNAWSQfo2CNldoXOEETqk1sDEhExp0bLDHR8GNQo="; + "8.3" = "sha256-MPg6lGEt1t5y+fiXDATHeutgaSH0o0boTjTLGqliyTQ="; + "8.4" = "sha256-yIYdl+IZzk1sJTg5Z5KU8o1MNFwUK46DNUPkdGWPmpM="; + "8.5" = "sha256-Zrr1Rk4dcRTxUNowmWAWxxwhBaCXCxXMOGYrJfp6HHA="; }; }; "i686-linux" = { system = "i386"; hash = { - "8.1" = "sha256-Cccapa4s6Wvo/MOjReCbbJY4H1HNe5uF8Fe4UX8ftFs="; - "8.2" = "sha256-1k8m4Mram806XIbR4x0Kf6IH7rvhbLbaqPgM9v1SHS4="; - "8.3" = "sha256-Si0boOO5BRDKARZbAbPPrxRIaUjwViQLepZ5tNvkjGk="; - "8.4" = "sha256-BOjlJy48fS2SWK28Lcd9/MVhciDEaBJe6mRIhTa9JhI="; - "8.5" = "sha256-OBySA7eGI+YqvMnsOlr7p6RznqYq7DJptnYjhMfqk2Q="; + "8.1" = "sha256-akPwQdmUplIG0o7uNXuPBrv1QTG4ulXMD+E9FFf8cdc="; + "8.2" = "sha256-o2T8WLXk5N21Z2kLZnHiyoy/A3I9cqwY/ezlEpD3LOo="; + "8.3" = "sha256-FqWzbE8o9IsmTfeS46ZLawdq8I+ttRU2bUIeruzDNO8="; + "8.4" = "sha256-x8zmKWdffLPL1FIpEtnK1pio6Pdj2gacwTjhm5FUASQ="; + "8.5" = "sha256-l3Sb3ONIURDikQhfhxbAABwVFZtSQf+R8z3z82Dwz7Q="; }; }; "aarch64-linux" = { system = "arm64"; hash = { - "8.1" = "sha256-Od+c9X4yg4xW9aAI0x1CacUNp7PdJl1KRIi++m4DLY8="; - "8.2" = "sha256-ZI2n0lXkwUg8BvpjdhqHz1F3Z7dlX+oGv6IsjRVzzWA="; - "8.3" = "sha256-6NMvylxdwPpbmIN5EDVcBuplP2kEQDyY+fD23k89k48="; - "8.4" = "sha256-356ECFSrqu5kJX/qP+SNtKl7bsGGD/ROJd9vgEX5wSM="; - "8.5" = "sha256-z7GMQ9wqIr2/BKi3G2Wf3cZBtU/ZC+uKMcbnmYfmm8w="; + "8.1" = "sha256-rBKmlBuI7Wj4HbcaBEgB21OFmPgYKiLapswcuxGVWp4="; + "8.2" = "sha256-H3B3e4zP+DSL8XkpaMZ6yhp18TJJrE38SQlc9N7QaKo="; + "8.3" = "sha256-Cwm69608MEkmqgJMJCTEY4+1DHCMkawjDYb1eZD2U4c="; + "8.4" = "sha256-M8y5VoaIHTsJEcYA61oK7Ks6oFCqlCzvo/uQbJM12pU="; + "8.5" = "sha256-rNsy+IPEnxqH9pP99sM9mMX7K1ZzhRJQx9BuJkEvUD0="; }; }; "aarch64-darwin" = { system = "arm64"; hash = { - "8.1" = "sha256-vlb6HCz9KqSL+bSuVixiHVgVVkEAuCaoR7ww0/ZSdR8="; - "8.2" = "sha256-3XVHonZ7UW3LENuKgywyZ5q3Mo/6XBhnbiuARRGqPAg="; - "8.3" = "sha256-Dw+L0Bo/6BeFi+w3sm5kekR0mXoMUcsCuEksCdFpVA0="; - "8.4" = "sha256-i5R+vUn08yNWvPaJGRRHBPAbpxdqDmvPq3l9NPCuqxg="; - "8.5" = "sha256-vyBbyS8Y1mD+zFO01bMbim8Riq45+ns9YA4k41KQup8="; + "8.1" = "sha256-Ou54kb3vhRK9ZP35ixc3cuXC0s9B6yOMoxS8QWn8GH4="; + "8.2" = "sha256-Xx9h61zzDI4dA7G6nqJA7lgd1TzmhQmvuFVhVRVFHz8="; + "8.3" = "sha256-/EM1fAYaEHtBnN4ElnCaA6RvcYMjhx5nhsmA/Lxx3jI="; + "8.4" = "sha256-W5A+WAJ9MNX4Zkmhu0v5k1KQvVtSJn60JpRvVuFD98Q="; + "8.5" = "sha256-GpvF7cgcTXLguwQCj0vOwtn7EbUQYqolzt7JPr8RtCM="; }; }; "x86_64-darwin" = { system = "amd64"; hash = { - "8.1" = "sha256-0xf09E58+kOGZbfpUeaCNdeeJx/Sv4QazfgcdV3Fqho="; - "8.2" = "sha256-BU3INTjuVXJ+WB16Q/6I1I5y0k+7sR158vKOiuh6H4w="; - "8.3" = "sha256-TBTuabrEpQR7ff+ULjZCD99a1xX4KNjTWlMQTJ1l6NU="; - "8.4" = "sha256-45R0CrE6MZ4RU4HslaF5/jbMOz32fCMnzj8R1F9tu34="; - "8.5" = "sha256-40+kki7h6DLQemLyoKOSdd8hmQXJE+Yt4rcC4V706vs="; + "8.1" = "sha256-bRoTC959irVHSTbMmBEQPw2O5ecoMj4zJK+a5AT1i7M="; + "8.2" = "sha256-6DGh0Ajlxt6L7acen3171gfyUajmb9k6fAY+h56BZCI="; + "8.3" = "sha256-KhZ5KD+9lCC+4bSVZPfkvWpWgRmOZ9iL87NfQ/YMWzw="; + "8.4" = "sha256-DRU0I60T9ZvIHYU82qbHFmEQwn3Vrp/MGmhiKzOm3og="; + "8.5" = "sha256-LrGek8mg9tBhccLGBKeokKsiYSxitxE+MP9sya3H4aY="; }; }; }; diff --git a/pkgs/by-name/bl/blas/package.nix b/pkgs/by-name/bl/blas/package.nix index 01ad1839c339..c0023957bcea 100644 --- a/pkgs/by-name/bl/blas/package.nix +++ b/pkgs/by-name/bl/blas/package.nix @@ -3,6 +3,7 @@ stdenv, lapack-reference, openblas, + checkPhaseThreadLimitHook, isILP64 ? false, blasProvider ? openblas, }: @@ -186,6 +187,10 @@ stdenv.mkDerivation { "dev" ]; + propagatedNativeBuildInputs = [ + checkPhaseThreadLimitHook + ]; + meta = (blasProvider'.meta or { }) // { description = "${lib.getName blasProvider} with just the BLAS C and FORTRAN ABI"; }; diff --git a/pkgs/by-name/bl/blis/package.nix b/pkgs/by-name/bl/blis/package.nix index 0002f7c3c3ee..b8bb979f41c3 100644 --- a/pkgs/by-name/bl/blis/package.nix +++ b/pkgs/by-name/bl/blis/package.nix @@ -5,6 +5,12 @@ perl, python3, + # sets BLIS_NUM_THREADS and OMP_NUM_THREADS for packages + # invoking blis during checkPhase/installCheckPhase to + # avoid overloading builders with excessive parallelism + # See also: https://github.com/flame/blis/blob/b8b75b4e19459f5d618b57aa814ca38b1d82eb82/docs/Multithreading.md#specifying-multithreading + checkPhaseThreadLimitHook, + # Enable BLAS interface with 64-bit integer width. blas64 ? false, @@ -36,6 +42,10 @@ stdenv.mkDerivation (finalAttrs: { python3 ]; + propagatedNativeBuildInputs = [ + checkPhaseThreadLimitHook + ]; + doCheck = true; enableParallelBuilding = true; diff --git a/pkgs/by-name/c-/c-ares/package.nix b/pkgs/by-name/c-/c-ares/package.nix index 4e7a3b2e97ba..393f42dd7e2f 100644 --- a/pkgs/by-name/c-/c-ares/package.nix +++ b/pkgs/by-name/c-/c-ares/package.nix @@ -18,12 +18,12 @@ stdenv.mkDerivation rec { pname = "c-ares"; - version = "1.34.6"; + version = "1.34.8"; src = fetchurl { # Note: tag name varies in some versions, e.g. v1.30.0, c-ares-1_17_0. url = "https://github.com/c-ares/c-ares/releases/download/v${version}/c-ares-${version}.tar.gz"; - hash = "sha256-kS3XzDs+innFL9f7nA9Ozwqqc+Re/aiAJmotbia4TvU="; + hash = "sha256-wiK21oEJb5RE0sSGPSwRdAGeJ8rMoKSlwRTTbdfXv3g="; }; outputs = [ diff --git a/pkgs/by-name/ca/cacert/package.nix b/pkgs/by-name/ca/cacert/package.nix index 8dd727f6ded3..df6b082a92bc 100644 --- a/pkgs/by-name/ca/cacert/package.nix +++ b/pkgs/by-name/ca/cacert/package.nix @@ -20,7 +20,7 @@ let lib.concatStringsSep "\n\n" extraCertificateStrings ); - version = "3.123"; + version = "3.125"; meta = { homepage = "https://firefox-source-docs.mozilla.org/security/nss/runbooks/rootstore.html#root-store-consumers"; description = "Bundle of X.509 certificates of public Certificate Authorities (CA)"; @@ -52,7 +52,7 @@ stdenv.mkDerivation { "https://hg-edge.mozilla.org/projects/nss/raw-file/${tag}/${file}" "https://raw.githubusercontent.com/nss-dev/nss/refs/tags/${tag}/${file}" ]; - hash = "sha256-dxMO+RITdyhEVh+9OqMdQTslwqx/V2/qO8O7/375NIk="; + hash = "sha256-5XkSgI2u97Kw+k3yzPF+R66vJsg5o4+Fx2AD66/YZr0="; }; unpackPhase = '' diff --git a/pkgs/by-name/ca/cargo-auditable/builder.nix b/pkgs/by-name/ca/cargo-auditable/builder.nix index 348ff29ef61a..a865d352943b 100644 --- a/pkgs/by-name/ca/cargo-auditable/builder.nix +++ b/pkgs/by-name/ca/cargo-auditable/builder.nix @@ -16,11 +16,14 @@ lib.extendMkDerivation { auditable ? true, hash ? "", cargoHash ? "", + passthru ? { }, ... }: { inherit auditable pname; + __structuredAttrs = true; + src = fetchFromGitHub { owner = "rust-secure-code"; repo = "cargo-auditable"; @@ -39,13 +42,28 @@ lib.extendMkDerivation { # https://github.com/rust-secure-code/cargo-auditable/issues/235 "--skip=test_proc_macro" "--skip=test_self_hosting" - ]; + ] + # TODO: Clean up on `staging`. + ++ + lib.optionals + ( + stdenv.hostPlatform.isMusl + || stdenv.hostPlatform.isAarch32 + || stdenv.hostPlatform.isDarwin + || stdenv.hostPlatform.isMsvc + ) + [ + # Expects `linker = "rust-lld"` to work. + "--skip=test_bare_linker" + ]; postInstall = '' installManPage cargo-auditable/cargo-auditable.1 ''; - passthru.bootstrap = auditable-bootstrap; + passthru = passthru // { + bootstrap = auditable-bootstrap; + }; meta = { description = "Tool to make production Rust binaries auditable"; diff --git a/pkgs/by-name/ca/cargo-auditable/package.nix b/pkgs/by-name/ca/cargo-auditable/package.nix index b74e0abbd515..064df430d374 100644 --- a/pkgs/by-name/ca/cargo-auditable/package.nix +++ b/pkgs/by-name/ca/cargo-auditable/package.nix @@ -2,6 +2,7 @@ buildPackages, callPackage, makeRustPlatform, + nix-update-script, }: let # Need to use the build platform rustc and Cargo so that @@ -18,9 +19,9 @@ let auditable-bootstrap = bootstrap; }; - version = "0.7.2"; - hash = "sha256-hR6PjTOps8JSM7UbfGlCoZmmwtWExVqYwh4lxDiFWdc="; - cargoHash = "sha256-JEfnUJ9J6Xak3AOCwQCnu+v+3Wl3QbXX20qVFWB6040="; + version = "0.7.5"; + hash = "sha256-0VONJCv/msLcGenItWMLJ7DH79RTD6vsU9gX/nphh1g="; + cargoHash = "sha256-/iAYib+xDQSJ8B559/V7b994ErSUGsPSDx64jFF5B6I="; # cargo-auditable cannot be built with cargo-auditable until cargo-auditable is built bootstrap = auditableBuilder { @@ -32,4 +33,5 @@ in auditableBuilder { inherit version hash cargoHash; auditable = true; + passthru.updateScript = nix-update-script { }; } diff --git a/pkgs/by-name/ch/checkPhaseThreadLimitHook/hook.sh b/pkgs/by-name/ch/checkPhaseThreadLimitHook/hook.sh new file mode 100644 index 000000000000..1b610b631d84 --- /dev/null +++ b/pkgs/by-name/ch/checkPhaseThreadLimitHook/hook.sh @@ -0,0 +1,32 @@ +setupThreadLimit() { + # Limit number of threads used during checks. Default is "all cores". + # Using all cores causes high load on builders if checks are executed with NIX_BUILD_CORE parallelism. + # This gets even worse if multiple builds are scheduled on the same machine, potentially growing O(n^3) without explicit core limits. + + # global value to override all of these at once + NIX_CHECK_PHASE_DEFAULT_NUM_THREADS="${NIX_CHECK_PHASE_DEFAULT_NUM_THREADS:-1}" + + thread_vars=( + OMP_NUM_THREADS + OPENBLAS_NUM_THREADS + MKL_NUM_THREADS + BLIS_NUM_THREADS + VECLIB_MAXIMUM_THREADS + NUMBA_NUM_THREADS + NUMEXPR_NUM_THREADS + ) + + echo "setting known thread variables to default: $NIX_CHECK_PHASE_DEFAULT_NUM_THREADS" + for var in "${thread_vars[@]}"; do + export "$var=${!var:-$NIX_CHECK_PHASE_DEFAULT_NUM_THREADS}" + printf " %s=%s" "$var" "${!var}" + done + printf "\n" +} + + +if [[ -z "${dontLimitCheckPhaseThreads-}" ]]; then + echo "Using checkPhaseThreadLimitHook" + preCheckHooks+=('setupThreadLimit') + preInstallCheckHooks+=('setupThreadLimit') +fi diff --git a/pkgs/by-name/ch/checkPhaseThreadLimitHook/package.nix b/pkgs/by-name/ch/checkPhaseThreadLimitHook/package.nix new file mode 100644 index 000000000000..6bd9bda7135a --- /dev/null +++ b/pkgs/by-name/ch/checkPhaseThreadLimitHook/package.nix @@ -0,0 +1,15 @@ +{ + lib, + makeSetupHook, +}: + +makeSetupHook { + name = "check-phase-thread-limit-hook"; + + __structuredAttrs = true; + + meta = { + license = lib.licenses.mit; + maintainers = with lib.maintainers; [ grimmauld ]; + }; +} ./hook.sh diff --git a/pkgs/by-name/cm/cmake/package.nix b/pkgs/by-name/cm/cmake/package.nix index 3f099d56c7f9..327c593e6522 100644 --- a/pkgs/by-name/cm/cmake/package.nix +++ b/pkgs/by-name/cm/cmake/package.nix @@ -50,11 +50,11 @@ stdenv.mkDerivation (finalAttrs: { + lib.optionalString isMinimalBuild "-minimal" + lib.optionalString cursesUI "-cursesUI" + lib.optionalString qt5UI "-qt5UI"; - version = "4.1.2"; + version = "4.1.6"; src = fetchurl { url = "https://cmake.org/files/v${lib.versions.majorMinor finalAttrs.version}/cmake-${finalAttrs.version}.tar.gz"; - hash = "sha256-ZD8EGCt7oyOrMfUm94UTT7ecujGIqFIgbvBHP+4oKhU="; + hash = "sha256-UTOEifT7rjWgpptZQW9RLcnHVxKXWaSHxHsz39IVUg4="; }; patches = [ diff --git a/pkgs/by-name/cu/curlMinimal/fix-wakeup-consumption.patch b/pkgs/by-name/cu/curlMinimal/fix-wakeup-consumption.patch deleted file mode 100644 index 0bc04b60bb87..000000000000 --- a/pkgs/by-name/cu/curlMinimal/fix-wakeup-consumption.patch +++ /dev/null @@ -1,32 +0,0 @@ -From 2a2104f3cff44bb28bb570a093be52bbeeed8f23 Mon Sep 17 00:00:00 2001 -From: Stefan Eissing -Date: Mon, 11 May 2026 14:56:04 +0200 -Subject: [PATCH] event: fix wakeup consumption - -The events on a multi wakeup socketpair were only consumed via -curl_multi_poll()/curl_multi_wait() but not in event based processing on -a curl_multi_socket() call. That led to busy loops as reported in - -Fixes #21547 -Reported-by: Earnestly on github -Closes #21549 ---- - lib/multi.c | 5 +++++ - 1 file changed, 5 insertions(+) - -diff --git a/lib/multi.c b/lib/multi.c -index be32740a7097..5e84133f13fd 100644 ---- a/lib/multi.c -+++ b/lib/multi.c -@@ -2703,6 +2703,11 @@ static CURLMcode multi_runsingle(struct Curl_multi *multi, - Curl_uint32_bset_remove(&multi->dirty, data->mid); - - if(data == multi->admin) { -+#ifdef ENABLE_WAKEUP -+ /* Consume any pending wakeup signals before processing. -+ * This is necessary for event based processing. See #21547 */ -+ (void)Curl_wakeup_consume(multi->wakeup_pair, TRUE); -+#endif - #ifdef USE_RESOLV_THREADED - Curl_async_thrdd_multi_process(multi); - #endif diff --git a/pkgs/by-name/cu/curlMinimal/package.nix b/pkgs/by-name/cu/curlMinimal/package.nix index dc50ca16529f..41cd5bfad64d 100644 --- a/pkgs/by-name/cu/curlMinimal/package.nix +++ b/pkgs/by-name/cu/curlMinimal/package.nix @@ -6,6 +6,8 @@ perl, nixosTests, autoreconfHook, + buildPackages, + runtimeShellPackage, brotliSupport ? false, brotli, c-aresSupport ? false, @@ -82,9 +84,12 @@ assert ]) > 1 ); +let + isCross = !lib.systems.equals stdenv.buildPlatform stdenv.hostPlatform; +in stdenv.mkDerivation (finalAttrs: { pname = "curl"; - version = "8.20.0"; + version = "8.21.0"; src = fetchurl { urls = [ @@ -93,16 +98,9 @@ stdenv.mkDerivation (finalAttrs: { builtins.replaceStrings [ "." ] [ "_" ] finalAttrs.version }/curl-${finalAttrs.version}.tar.xz" ]; - hash = "sha256-Y/4twUi6DOromSLvg49+XJRicsLni3xZ+rS3nTziuJY="; + hash = "sha256-qhtmpw6s6D3GJFCHRWRsCK5WHeUSq0A63/uTrIf8cuY="; }; - patches = [ - # https://github.com/curl/curl/commit/2a2104f3cff44bb28bb570a093be52bbeeed8f23 - # According to , this fixes - # a performance regression, causing high CPU usage - ./fix-wakeup-consumption.patch - ]; - # this could be accomplished by updateAutotoolsGnuConfigScriptsHook, but that causes infinite recursion # necessary for FreeBSD code path in configure postPatch = '' @@ -248,7 +246,20 @@ stdenv.mkDerivation (finalAttrs: { ln $out/lib/libcurl${stdenv.hostPlatform.extensions.sharedLibrary} $out/lib/libcurl-gnutls${stdenv.hostPlatform.extensions.sharedLibrary} ln $out/lib/libcurl${stdenv.hostPlatform.extensions.sharedLibrary} $out/lib/libcurl-gnutls${stdenv.hostPlatform.extensions.sharedLibrary}.4 ln $out/lib/libcurl${stdenv.hostPlatform.extensions.sharedLibrary} $out/lib/libcurl-gnutls${stdenv.hostPlatform.extensions.sharedLibrary}.4.4.0 + '' + # The wcurl shell script found in `''${!outputBin}/bin`, is located in the + # source along with all the scripts patched in `postPatch` above. + # `patchShebangs` at that stage causes the host intended wcurl script to get + # the buildPlatform's runtimeShell shebang, instead of the hostPlatform's. To + # make sure this doesn't happen we disallow it, and fix it above in the + # postInstall, and also with the conditional hostPlatform's + # runtimeShellPackage added in buildInputs. + + lib.optionalString isCross '' + patchShebangs --update --host "''${!outputBin}/bin" ''; + outputChecks.bin.disallowedReferences = lib.optional isCross buildPackages.runtimeShellPackage; + outputChecks.out.disallowedReferences = lib.optional isCross buildPackages.runtimeShellPackage; + buildInputs = lib.optional isCross runtimeShellPackage; passthru = let diff --git a/pkgs/by-name/cy/cyrus-imapd/package.nix b/pkgs/by-name/cy/cyrus-imapd/package.nix index 8e95b5a449a5..0d777e1251bd 100644 --- a/pkgs/by-name/cy/cyrus-imapd/package.nix +++ b/pkgs/by-name/cy/cyrus-imapd/package.nix @@ -66,13 +66,13 @@ }: stdenv.mkDerivation (finalAttrs: { pname = "cyrus-imapd"; - version = "3.12.2"; + version = "3.12.3"; src = fetchFromGitHub { owner = "cyrusimap"; repo = "cyrus-imapd"; tag = "cyrus-imapd-${finalAttrs.version}"; - hash = "sha256-zPEaxETzG4Aj8JYP/aZpN2xXrD+O22io/HzI4LK+s/o="; + hash = "sha256-2HTrFjFlFFqF1TWtClPSOJSCgmomjSgEU7o2UPgd/Cs="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/df/dftd4/package.nix b/pkgs/by-name/df/dftd4/package.nix index 47bdd3495224..3167f58ca71f 100644 --- a/pkgs/by-name/df/dftd4/package.nix +++ b/pkgs/by-name/df/dftd4/package.nix @@ -82,10 +82,6 @@ stdenv.mkDerivation (finalAttrs: { app/tester.py ''; - preCheck = '' - export OMP_NUM_THREADS=2 - ''; - meta = { description = "Generally Applicable Atomic-Charge Dependent London Dispersion Correction"; mainProgram = "dftd4"; diff --git a/pkgs/by-name/el/elpa/package.nix b/pkgs/by-name/el/elpa/package.nix index 170f03f697e8..650d59f93de4 100644 --- a/pkgs/by-name/el/elpa/package.nix +++ b/pkgs/by-name/el/elpa/package.nix @@ -116,9 +116,6 @@ stdenv.mkDerivation (finalAttrs: { preCheck = '' #patchShebangs ./ - # Run dual threaded - export OMP_NUM_THREADS=2 - # Reduce test problem sizes export TEST_FLAGS="1500 50 16" ''; diff --git a/pkgs/by-name/er/ergoscf/package.nix b/pkgs/by-name/er/ergoscf/package.nix index 9514bb89f1e4..59ccb179b2bd 100644 --- a/pkgs/by-name/er/ergoscf/package.nix +++ b/pkgs/by-name/er/ergoscf/package.nix @@ -39,7 +39,6 @@ stdenv.mkDerivation (finalAttrs: { "-lblas" "-llapack" ]; - OMP_NUM_THREADS = 2; # required for check phase }; enableParallelBuilding = true; diff --git a/pkgs/by-name/ev/evcc/package.nix b/pkgs/by-name/ev/evcc/package.nix index 89a475328079..3b14b2c3110f 100644 --- a/pkgs/by-name/ev/evcc/package.nix +++ b/pkgs/by-name/ev/evcc/package.nix @@ -17,16 +17,16 @@ }: let - version = "0.311.1"; + version = "0.312.0"; src = fetchFromGitHub { owner = "evcc-io"; repo = "evcc"; tag = version; - hash = "sha256-dxP28NPW+V30XIzh2w++Glrb2xfZ0tpp4H+qOM13yt8="; + hash = "sha256-GUHKrjCGm9LRQX5INdzSMPBV19FtaV8DTN3HIEUrxR4="; }; - vendorHash = "sha256-Eh07T9FAoeoUfhJsK6DPmwE2rJX55Ijzp4ydxJc8/bQ="; + vendorHash = "sha256-x4iwvzf7iv6TyLEkTnqztDQrBD+3lT1yycB7yTD4xO4="; commonMeta = { license = lib.licenses.mit; diff --git a/pkgs/by-name/ex/expat/package.nix b/pkgs/by-name/ex/expat/package.nix index 78ff9e9253b0..72459e1c2ac6 100644 --- a/pkgs/by-name/ex/expat/package.nix +++ b/pkgs/by-name/ex/expat/package.nix @@ -18,7 +18,7 @@ # files. let - version = "2.8.1"; + version = "2.8.2"; tag = "R_${lib.replaceStrings [ "." ] [ "_" ] version}"; in stdenv.mkDerivation (finalAttrs: { @@ -29,7 +29,7 @@ stdenv.mkDerivation (finalAttrs: { url = with finalAttrs; "https://github.com/libexpat/libexpat/releases/download/${tag}/${pname}-${version}.tar.xz"; - hash = "sha256-ELGV7ngWCpCDiBgKj+NgPU6aEvR1X79fOBayOp11DaA="; + hash = "sha256-OtibhYjmZEvU5JmBSA1IshKJ7rvNTwoaSvscKfmbarQ="; }; strictDeps = true; diff --git a/pkgs/by-name/fo/forgejo/generic.nix b/pkgs/by-name/fo/forgejo/generic.nix index 413b070c3143..ec5555d62af9 100644 --- a/pkgs/by-name/fo/forgejo/generic.nix +++ b/pkgs/by-name/fo/forgejo/generic.nix @@ -12,6 +12,7 @@ bash, brotli, buildGoModule, + coreutils, fetchpatch, forgejo, git, @@ -79,6 +80,9 @@ buildGoModule rec { git openssh writableTmpDirAsHomeHook + ] + ++ lib.optionals (lib.versionAtLeast version "16") [ + coreutils ]; patches = [ @@ -116,6 +120,23 @@ buildGoModule rec { # TestRunHookPrePostReceive (cmd/hook_test.go) needs .git to pass git init + '' + # Unlike NixOS, the Nix build sandbox has no /usr/bin/env and we + # can't just create it, so Forgejo trying to execute git hooks + # that have #!/usr/bin/env as shebang fails with: + # + # To /build/repos44353414/user2/repo1.wiki.git + # ! [remote rejected] fda09356fb8b1da00546f764933f9dacda1b44ea -> master (pre-receive hook declined) + # error: failed to push some refs to '/build/repos44353414/user2/repo1.wiki.git' + # - remote: fatal: cannot exec '/build/appdata2719412950/home/hooks/pre-receive': No such file or directory + # + # We also can't just call patchShebangs because the hooks are + # created just in time by the test suite. Patching the source of + # the hooks after go build but before go test is oddly enough + # the least invasive hack to have those tests pass. + + lib.optionalString (lib.versionAtLeast version "16") '' + substituteInPlace modules/git/hook_generate.go \ + --replace-fail "#!/usr/bin/env" "#!${lib.getExe' coreutils "env"}" ''; checkFlags = @@ -124,6 +145,11 @@ buildGoModule rec { "TestPassword" # requires network: api.pwnedpasswords.com "TestCaptcha" # requires network: hcaptcha.com "TestDNSUpdate" # requires network: release.forgejo.org + ] + ++ lib.optionals (lib.versionAtLeast version "16") [ + "TestMigrateRepository" # requires network: codeberg.org + ] + ++ [ "TestMigrateWhiteBlocklist" # requires network: gitlab.com (DNS) "TestURLAllowedSSH/Pushmirror_URL" # requires network git.gay (DNS) "TestBleveDeleteIssue" # Known Flake-y https://github.com/NixOS/nixpkgs/issues/509878 diff --git a/pkgs/by-name/fo/forgejo/lts.nix b/pkgs/by-name/fo/forgejo/lts.nix deleted file mode 120000 index 8d225ed3269a..000000000000 --- a/pkgs/by-name/fo/forgejo/lts.nix +++ /dev/null @@ -1 +0,0 @@ -package.nix \ No newline at end of file diff --git a/pkgs/by-name/fo/forgejo/lts.nix b/pkgs/by-name/fo/forgejo/lts.nix new file mode 100644 index 000000000000..6c4609ae7b43 --- /dev/null +++ b/pkgs/by-name/fo/forgejo/lts.nix @@ -0,0 +1,11 @@ +import ./generic.nix { + version = "15.0.5"; + hash = "sha256-S+x/YEfQrYIzHLnZ7LDLnkMYVN3TajwS7SHydM8uMPQ="; + npmDepsHash = "sha256-BZSYjEsjUqMYWu3EUP+K35hqSOniv8Y6ek5bEC2vTPg="; + vendorHash = "sha256-00QiJ8W76FdG96fmsIRLkaYlMQTZoIRmRd/qYGyPuig="; + lts = true; + nixUpdateExtraArgs = [ + "--override-filename" + "pkgs/by-name/fo/forgejo/lts.nix" + ]; +} diff --git a/pkgs/by-name/fo/forgejo/package.nix b/pkgs/by-name/fo/forgejo/package.nix index 474e72baff85..a192df6c43b6 100644 --- a/pkgs/by-name/fo/forgejo/package.nix +++ b/pkgs/by-name/fo/forgejo/package.nix @@ -1,9 +1,9 @@ import ./generic.nix { - version = "15.0.5"; - hash = "sha256-S+x/YEfQrYIzHLnZ7LDLnkMYVN3TajwS7SHydM8uMPQ="; - npmDepsHash = "sha256-BZSYjEsjUqMYWu3EUP+K35hqSOniv8Y6ek5bEC2vTPg="; - vendorHash = "sha256-00QiJ8W76FdG96fmsIRLkaYlMQTZoIRmRd/qYGyPuig="; - lts = true; + version = "16.0.0"; + hash = "sha256-BZawFbrtcxftX4/Yk32aoVRQ6Kg+k1FhN9IoH6dxvVY="; + npmDepsHash = "sha256-UhivpUqNJvc3zHxdRVAWT9x68jG1KnQa8yS4KkL2W5g="; + vendorHash = "sha256-cb6f7ZX3pG95EEZotGXn6+YUJN59SFNVHFTejFJ6y28="; + lts = false; nixUpdateExtraArgs = [ "--override-filename" "pkgs/by-name/fo/forgejo/package.nix" diff --git a/pkgs/by-name/fr/freeipmi/package.nix b/pkgs/by-name/fr/freeipmi/package.nix index f8dccc9f2844..90131d86d1ca 100644 --- a/pkgs/by-name/fr/freeipmi/package.nix +++ b/pkgs/by-name/fr/freeipmi/package.nix @@ -10,12 +10,12 @@ }: stdenv.mkDerivation (finalAttrs: { - version = "1.6.17"; + version = "1.6.18"; pname = "freeipmi"; src = fetchurl { url = "mirror://gnu/freeipmi/freeipmi-${finalAttrs.version}.tar.gz"; - sha256 = "sha256-Fng9EPqiiEenlczgv4be6qcrj75x0fDcEQHROmtQHsE="; + sha256 = "sha256-gJiyOCADitCqOavw+aAS4kaD04TZ+R52CssqaLRl4P4="; }; postPatch = lib.optionalString stdenv.cc.isClang '' diff --git a/pkgs/by-name/fr/freerdp/package.nix b/pkgs/by-name/fr/freerdp/package.nix index 0c702c87a2d6..ec44e94242d8 100644 --- a/pkgs/by-name/fr/freerdp/package.nix +++ b/pkgs/by-name/fr/freerdp/package.nix @@ -70,13 +70,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "freerdp"; - version = "3.27.1"; + version = "3.29.0"; src = fetchFromGitHub { owner = "FreeRDP"; repo = "FreeRDP"; tag = finalAttrs.version; - hash = "sha256-4U3QC1hka+qTQ0F7GqKPiMVwkkFeJvbjNtom5A7V/Sg="; + hash = "sha256-LTRV1vRTMR8015iFXZIEjz6ApN5kg1+T2nGZWJ873zY="; }; postPatch = '' diff --git a/pkgs/by-name/gd/gdal/package.nix b/pkgs/by-name/gd/gdal/package.nix index b8800268e3b7..0c686129dc89 100644 --- a/pkgs/by-name/gd/gdal/package.nix +++ b/pkgs/by-name/gd/gdal/package.nix @@ -3,6 +3,7 @@ stdenv, callPackage, fetchFromGitHub, + fetchpatch, useMinimalFeatures ? false, useArmadillo ? (!useMinimalFeatures), @@ -92,6 +93,31 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-sD/ZAOvMWK2+AGw6wgziDsheH+hwUwhd7i2f65cjFKg="; }; + patches = [ + # Fix build against Poppler >= 26.06 (not yet backported to the 3.12.x branch upstream) + # https://github.com/OSGeo/gdal/issues/14714 + (fetchpatch { + name = "0001- poppler-add-compatibility-with-future-26.06.patch"; + url = "https://github.com/OSGeo/gdal/commit/cbad3ef7824dcad235e95581127dbc4df696d6d3.patch"; + hash = "sha256-tJsUcBorYDF0eNzKMHDc+qUvovlIQ7WrRsePbmKmIT8="; + }) + (fetchpatch { + name = "0002-poppler-add-compatibility-with-future-26.06-continuation.patch"; + url = "https://github.com/OSGeo/gdal/commit/b3f839f2515b023e4a7cf099b7ce1626ccb24eac.patch"; + hash = "sha256-XtYUjulIiOknIE5e7AcRCThPvmSLP0QRbONUBF+KTxE="; + }) + (fetchpatch { + name = "0003-pdf-fix-build-against-latest-poppler.patch"; + url = "https://github.com/OSGeo/gdal/commit/581a86960d68e426b50384ed6e45ecb935f0f2a1.patch"; + hash = "sha256-VsOq+lQ6QhXKHFOeqdGFXRmtFR90FOJyTdYK5NFgB5U="; + }) + (fetchpatch { + name = "0004-pdf-fix-build-against-poppler-26.05.99dev.patch"; + url = "https://github.com/OSGeo/gdal/commit/7b8b8de28bbd200b0fd3b09147fdc68b5bf5ce20.patch"; + hash = "sha256-BxWMpiUwM3h7Vo9vxJ4H4A8aQfE3jcSRfRYwaLw/60w="; + }) + ]; + nativeBuildInputs = [ bison cmake diff --git a/pkgs/by-name/gd/gdb/package.nix b/pkgs/by-name/gd/gdb/package.nix index 95769211d8c2..b7aef9c38772 100644 --- a/pkgs/by-name/gd/gdb/package.nix +++ b/pkgs/by-name/gd/gdb/package.nix @@ -5,7 +5,6 @@ # Build time fetchurl, - fetchpatch, pkg-config, perl, texinfo, @@ -68,11 +67,11 @@ in stdenv.mkDerivation (finalAttrs: { inherit pname; - version = "17.1"; + version = "17.2"; src = fetchurl { url = "mirror://gnu/gdb/gdb-${finalAttrs.version}.tar.xz"; - hash = "sha256-FJlvX3TJ9o9aVD/cRbyngAIH+R+SrupsLnkYIsfG2HY="; + hash = "sha256-HANsDXLks9H7XJTIhjKt1vnXb018TS6nk8EqnxmjIow="; }; postPatch = @@ -90,17 +89,6 @@ stdenv.mkDerivation (finalAttrs: { patches = [ ./debug-info-from-env.patch - - (fetchurl { - name = "musl.patch"; - url = "https://inbox.sourceware.org/gdb-patches/20260324164527.1446549-2-sunilkumar.dora@windriver.com/raw"; - hash = "sha256-FC4DDVS4wtE/HXtbUqvkxu9+e7nE3DYi1zIuQP9yQO8="; - }) - (fetchpatch { - name = "musl-aarch64.patch"; - url = "https://sourceware.org/git/?p=binutils-gdb.git;a=patch;h=1ccc3f6a2e28fa1f3357826374cba165b3ba3ff7"; - hash = "sha256-Q2oTo2b+9yNN3PSsxqgxV4/9/05uFE/JMLe1CPs9Y7I="; - }) ] ++ optionals stdenv.hostPlatform.isDarwin [ ./darwin-target-match.patch diff --git a/pkgs/by-name/gn/gnutar/acl-2.4.0-name-conflicts.patch b/pkgs/by-name/gn/gnutar/acl-2.4.0-name-conflicts.patch new file mode 100644 index 000000000000..c871551bc772 --- /dev/null +++ b/pkgs/by-name/gn/gnutar/acl-2.4.0-name-conflicts.patch @@ -0,0 +1,85 @@ +diff --git a/src/xattrs.c b/src/xattrs.c +index 86a7e59cbc..c872ae308d 100644 +--- a/src/xattrs.c ++++ b/src/xattrs.c +@@ -139,13 +139,13 @@ + #ifdef HAVE_POSIX_ACLS + + /* acl-at wrappers, TODO: move to gnulib in future? */ +-static acl_t acl_get_file_at (int, const char *, acl_type_t); +-static int acl_set_file_at (int, const char *, acl_type_t, acl_t); ++static acl_t tar_acl_get_file_at (int, const char *, acl_type_t); ++static int tar_acl_set_file_at (int, const char *, acl_type_t, acl_t); + static int file_has_acl_at (int, char const *, struct stat const *); +-static int acl_delete_def_file_at (int, char const *); ++static int tar_acl_delete_def_file_at (int, char const *); + +-/* acl_get_file_at */ +-#define AT_FUNC_NAME acl_get_file_at ++/* tar_acl_get_file_at */ ++#define AT_FUNC_NAME tar_acl_get_file_at + #define AT_FUNC_RESULT acl_t + #define AT_FUNC_FAIL (acl_t)NULL + #define AT_FUNC_F1 acl_get_file +@@ -159,8 +159,8 @@ + #undef AT_FUNC_POST_FILE_PARAM_DECLS + #undef AT_FUNC_POST_FILE_ARGS + +-/* acl_set_file_at */ +-#define AT_FUNC_NAME acl_set_file_at ++/* tar_acl_set_file_at */ ++#define AT_FUNC_NAME tar_acl_set_file_at + #define AT_FUNC_F1 acl_set_file + #define AT_FUNC_POST_FILE_PARAM_DECLS , acl_type_t type, acl_t acl + #define AT_FUNC_POST_FILE_ARGS , type, acl +@@ -170,8 +170,8 @@ + #undef AT_FUNC_POST_FILE_PARAM_DECLS + #undef AT_FUNC_POST_FILE_ARGS + +-/* acl_delete_def_file_at */ +-#define AT_FUNC_NAME acl_delete_def_file_at ++/* tar_acl_delete_def_file_at */ ++#define AT_FUNC_NAME tar_acl_delete_def_file_at + #define AT_FUNC_F1 acl_delete_def_file + #define AT_FUNC_POST_FILE_PARAM_DECLS + #define AT_FUNC_POST_FILE_ARGS +@@ -299,10 +299,10 @@ + /* No "default" IEEE 1003.1e ACL set for directory. At this moment, + FILE_NAME may already have inherited default acls from parent + directory; clean them up. */ +- if (acl_delete_def_file_at (chdir_fd, file_name)) ++ if (tar_acl_delete_def_file_at (chdir_fd, file_name)) + WARNOPT (WARN_XATTR_WRITE, + (0, errno, +- _("acl_delete_def_file_at: Cannot drop default POSIX ACLs " ++ _("tar_acl_delete_def_file_at: Cannot drop default POSIX ACLs " + "for file '%s'"), + file_name)); + return; +@@ -316,11 +316,11 @@ + return; + } + +- if (acl_set_file_at (chdir_fd, file_name, type, acl) == -1) ++ if (tar_acl_set_file_at (chdir_fd, file_name, type, acl) == -1) + /* warn even if filesystem does not support acls */ + WARNOPT (WARN_XATTR_WRITE, + (0, errno, +- _ ("acl_set_file_at: Cannot set POSIX ACLs for file '%s'"), ++ _ ("tar_acl_set_file_at: Cannot set POSIX ACLs for file '%s'"), + file_name)); + + acl_free (acl); +@@ -357,10 +357,10 @@ + char *val = NULL; + acl_t acl; + +- if (!(acl = acl_get_file_at (parentfd, file_name, type))) ++ if (!(acl = tar_acl_get_file_at (parentfd, file_name, type))) + { + if (errno != ENOTSUP) +- call_arg_warn ("acl_get_file_at", file_name); ++ call_arg_warn ("tar_acl_get_file_at", file_name); + return; + } + diff --git a/pkgs/by-name/gn/gnutar/package.nix b/pkgs/by-name/gn/gnutar/package.nix index 51344245c45f..f887901e2761 100644 --- a/pkgs/by-name/gn/gnutar/package.nix +++ b/pkgs/by-name/gn/gnutar/package.nix @@ -24,9 +24,17 @@ stdenv.mkDerivation (finalAttrs: { sha256 = "sha256-TWL/NzQux67XSFNTI5MMfPlKz3HDWRiCsmp+pQ8+3BY="; }; - # GNU tar fails to link libiconv even though the configure script detects it. - # https://savannah.gnu.org/bugs/index.php?64441 - patches = [ ./link-libiconv.patch ]; + patches = [ + # GNU tar fails to link libiconv even though the configure script detects it. + # https://savannah.gnu.org/bugs/index.php?64441 + ./link-libiconv.patch + + # acl 2.4.0 adds functions that have name conflicts with internal + # (`static`) functions from GNU tar. we prefix `tar_` to these names to + # avoid this, matching the approach from + # https://lists.gnu.org/archive/html/bug-tar/2026-06/msg00013.html + ./acl-2.4.0-name-conflicts.patch + ]; # gnutar tries to call into gettext between `fork` and `exec`, # which is not safe on darwin. diff --git a/pkgs/by-name/go/google-chrome/package.nix b/pkgs/by-name/go/google-chrome/package.nix index a262b9f96d01..1a63064b22f6 100644 --- a/pkgs/by-name/go/google-chrome/package.nix +++ b/pkgs/by-name/go/google-chrome/package.nix @@ -179,11 +179,11 @@ let linux = stdenvNoCC.mkDerivation (finalAttrs: { inherit pname meta passthru; - version = "150.0.7871.124"; + version = "150.0.7871.128"; src = fetchurl { url = "https://dl.google.com/linux/chrome/deb/pool/main/g/google-chrome-stable/google-chrome-stable_${finalAttrs.version}-1_amd64.deb"; - hash = "sha256-TGNqvSrB9vMXb1K7QBCqN9ErWsBMQNyp6rEZksHHXNw="; + hash = "sha256-g+1ZyFh467j6U5FevnBmyvxY0cBMHJVElIbm+dmaHvs="; }; # With strictDeps on, some shebangs were not being patched correctly @@ -289,11 +289,11 @@ let darwin = stdenvNoCC.mkDerivation (finalAttrs: { inherit pname meta passthru; - version = "150.0.7871.125"; + version = "150.0.7871.129"; src = fetchurl { - url = "http://dl.google.com/release2/chrome/kjpfr4hhda65lyoxi6u4o42bke_150.0.7871.125/GoogleChrome-150.0.7871.125.dmg"; - hash = "sha256-ulMe+AP65d9VB2O7vhLnSX+dUfC7XqWd4GaOEQXGBac="; + url = "http://dl.google.com/release2/chrome/ggb3e3myl2poiiaqd2bbvqlrqa_150.0.7871.129/GoogleChrome-150.0.7871.129.dmg"; + hash = "sha256-ym9rF6yrGMSibQDM4gKlAbOsIHnV1tPxyNq9KNLnR0I="; }; dontPatch = true; diff --git a/pkgs/by-name/gr/greenx/package.nix b/pkgs/by-name/gr/greenx/package.nix index c08356a17058..fb360c6728b8 100644 --- a/pkgs/by-name/gr/greenx/package.nix +++ b/pkgs/by-name/gr/greenx/package.nix @@ -34,10 +34,6 @@ stdenv.mkDerivation (finalAttrs: { # Uses a hacky python setup run by cmake, which is hard to get running doCheck = false; - preCheck = '' - export OMP_NUM_THREADS=2 - ''; - meta = { description = "Library for Green’s function based electronic structure theory calculations"; license = [ lib.licenses.asl20 ]; diff --git a/pkgs/by-name/im/imagemagick/package.nix b/pkgs/by-name/im/imagemagick/package.nix index 27f0acd0d16f..5f41fb32d203 100644 --- a/pkgs/by-name/im/imagemagick/package.nix +++ b/pkgs/by-name/im/imagemagick/package.nix @@ -88,13 +88,13 @@ in stdenv.mkDerivation (finalAttrs: { pname = "imagemagick"; - version = "7.1.2-24"; + version = "7.1.2-27"; src = fetchFromGitHub { owner = "ImageMagick"; repo = "ImageMagick"; tag = finalAttrs.version; - hash = "sha256-oSH0dsQ3cuFNYJIIr6LHbv82FbFxxcmkjQ5csTNsYCA="; + hash = "sha256-QCC2CO2zkhwlEWymwF739uSNuS7QCqqGIJnF/LtYzVc="; }; outputs = [ @@ -206,7 +206,7 @@ stdenv.mkDerivation (finalAttrs: { meta = { homepage = "http://www.imagemagick.org/"; - changelog = "https://github.com/ImageMagick/Website/blob/main/ChangeLog.md"; + changelog = "https://github.com/ImageMagick/Website/blob/main/docs/changelog/index.md"; description = "Software suite to create, edit, compose, or convert bitmap images"; pkgConfigModules = [ "ImageMagick" diff --git a/pkgs/by-name/io/ioquake3/package.nix b/pkgs/by-name/io/ioquake3/package.nix index 59fcc1e7a882..d10726ced535 100644 --- a/pkgs/by-name/io/ioquake3/package.nix +++ b/pkgs/by-name/io/ioquake3/package.nix @@ -20,6 +20,7 @@ mumble, unstableGitUpdater, bc, + buildPackages, }: stdenv.mkDerivation (finalAttrs: { @@ -33,6 +34,11 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-OszPRlS5NTvajDZhtGw2wa275O8YodkIgiBz3POouYs="; }; + makeFlags = [ + "ARCH=${stdenv.hostPlatform.parsed.cpu.name}" + "NO_STRIP=1" + ]; + nativeBuildInputs = [ copyDesktopItems makeBinaryWrapper @@ -55,6 +61,8 @@ stdenv.mkDerivation (finalAttrs: { mumble ]; + depsBuildBuild = [ buildPackages.stdenv.cc ]; + enableParallelBuilding = true; preConfigure = '' diff --git a/pkgs/by-name/jq/jq/CVE-2026-32316.patch b/pkgs/by-name/jq/jq/CVE-2026-32316.patch deleted file mode 100644 index 29d08c9adcd7..000000000000 --- a/pkgs/by-name/jq/jq/CVE-2026-32316.patch +++ /dev/null @@ -1,49 +0,0 @@ -From e47e56d226519635768e6aab2f38f0ab037c09e5 Mon Sep 17 00:00:00 2001 -From: itchyny -Date: Thu, 12 Mar 2026 20:28:43 +0900 -Subject: [PATCH] Fix heap buffer overflow in `jvp_string_append` and - `jvp_string_copy_replace_bad` - -In `jvp_string_append`, the allocation size `(currlen + len) * 2` could -overflow `uint32_t` when `currlen + len` exceeds `INT_MAX`, causing a small -allocation followed by a large `memcpy`. - -In `jvp_string_copy_replace_bad`, the output buffer size calculation -`length * 3 + 1` could overflow `uint32_t`, again resulting in a small -allocation followed by a large write. - -Add overflow checks to both functions to return an error for strings -that would exceed `INT_MAX` in length. Fixes CVE-2026-32316. ---- - src/jv.c | 11 ++++++++++- - 1 file changed, 10 insertions(+), 1 deletion(-) - -diff --git a/src/jv.c b/src/jv.c -index 722a539391..2a62b48419 100644 ---- a/src/jv.c -+++ b/src/jv.c -@@ -1114,7 +1114,12 @@ static jv jvp_string_copy_replace_bad(const char* data, uint32_t length) { - const char* end = data + length; - const char* i = data; - -- uint32_t maxlength = length * 3 + 1; // worst case: all bad bytes, each becomes a 3-byte U+FFFD -+ // worst case: all bad bytes, each becomes a 3-byte U+FFFD -+ uint64_t maxlength = (uint64_t)length * 3 + 1; -+ if (maxlength >= INT_MAX) { -+ return jv_invalid_with_msg(jv_string("String too long")); -+ } -+ - jvp_string* s = jvp_string_alloc(maxlength); - char* out = s->data; - int c = 0; -@@ -1174,6 +1179,10 @@ static uint32_t jvp_string_remaining_space(jvp_string* s) { - static jv jvp_string_append(jv string, const char* data, uint32_t len) { - jvp_string* s = jvp_string_ptr(string); - uint32_t currlen = jvp_string_length(s); -+ if ((uint64_t)currlen + len >= INT_MAX) { -+ jv_free(string); -+ return jv_invalid_with_msg(jv_string("String too long")); -+ } - - if (jvp_refcnt_unshared(string.u.ptr) && - jvp_string_remaining_space(s) >= len) { diff --git a/pkgs/by-name/jq/jq/CVE-2026-33947.patch b/pkgs/by-name/jq/jq/CVE-2026-33947.patch deleted file mode 100644 index 9f31fd82b057..000000000000 --- a/pkgs/by-name/jq/jq/CVE-2026-33947.patch +++ /dev/null @@ -1,66 +0,0 @@ -From fb59f1491058d58bdc3e8dd28f1773d1ac690a1f Mon Sep 17 00:00:00 2001 -From: itchyny -Date: Mon, 13 Apr 2026 11:23:40 +0900 -Subject: [PATCH] Limit path depth to prevent stack overflow - -Deeply nested path arrays can cause unbounded recursion in -`jv_setpath`, `jv_getpath`, and `jv_delpaths`, leading to -stack overflow. Add a depth limit of 10000 to match the -existing `tojson` depth limit. This fixes CVE-2026-33947. ---- - src/jv_aux.c | 21 +++++++++++++++++++++ - 2 files changed, 46 insertions(+) - -diff --git a/src/jv_aux.c b/src/jv_aux.c -index 018f380b10..fd5ff96684 100644 ---- a/src/jv_aux.c -+++ b/src/jv_aux.c -@@ -365,6 +365,10 @@ static jv jv_dels(jv t, jv keys) { - return t; - } - -+#ifndef MAX_PATH_DEPTH -+#define MAX_PATH_DEPTH (10000) -+#endif -+ - jv jv_setpath(jv root, jv path, jv value) { - if (jv_get_kind(path) != JV_KIND_ARRAY) { - jv_free(value); -@@ -372,6 +376,12 @@ jv jv_setpath(jv root, jv path, jv value) { - jv_free(path); - return jv_invalid_with_msg(jv_string("Path must be specified as an array")); - } -+ if (jv_array_length(jv_copy(path)) > MAX_PATH_DEPTH) { -+ jv_free(value); -+ jv_free(root); -+ jv_free(path); -+ return jv_invalid_with_msg(jv_string("Path too deep")); -+ } - if (!jv_is_valid(root)){ - jv_free(value); - jv_free(path); -@@ -424,6 +434,11 @@ jv jv_getpath(jv root, jv path) { - jv_free(path); - return jv_invalid_with_msg(jv_string("Path must be specified as an array")); - } -+ if (jv_array_length(jv_copy(path)) > MAX_PATH_DEPTH) { -+ jv_free(root); -+ jv_free(path); -+ return jv_invalid_with_msg(jv_string("Path too deep")); -+ } - if (!jv_is_valid(root)) { - jv_free(path); - return root; -@@ -502,6 +517,12 @@ jv jv_delpaths(jv object, jv paths) { - jv_free(elem); - return err; - } -+ if (jv_array_length(jv_copy(elem)) > MAX_PATH_DEPTH) { -+ jv_free(object); -+ jv_free(paths); -+ jv_free(elem); -+ return jv_invalid_with_msg(jv_string("Path too deep")); -+ } - jv_free(elem); - } - if (jv_array_length(jv_copy(paths)) == 0) { diff --git a/pkgs/by-name/jq/jq/CVE-2026-33948.patch b/pkgs/by-name/jq/jq/CVE-2026-33948.patch deleted file mode 100644 index 5b6497e1469d..000000000000 --- a/pkgs/by-name/jq/jq/CVE-2026-33948.patch +++ /dev/null @@ -1,45 +0,0 @@ -From 6374ae0bcdfe33a18eb0ae6db28493b1f34a0a5b Mon Sep 17 00:00:00 2001 -From: itchyny -Date: Mon, 13 Apr 2026 08:46:11 +0900 -Subject: [PATCH] Fix NUL truncation in the JSON parser - -This fixes CVE-2026-33948. ---- - src/util.c | 8 +------- - tests/shtest | 6 ++++++ - 2 files changed, 7 insertions(+), 7 deletions(-) - -diff --git a/src/util.c b/src/util.c -index fdfdb96d88..80d65fc808 100644 ---- a/src/util.c -+++ b/src/util.c -@@ -312,13 +312,7 @@ static int jq_util_input_read_more(jq_util_input_state *state) { - if (p != NULL) - state->current_line++; - -- if (p == NULL && state->parser != NULL) { -- /* -- * There should be no NULs in JSON texts (but JSON text -- * sequences are another story). -- */ -- state->buf_valid_len = strlen(state->buf); -- } else if (p == NULL && feof(state->current_input)) { -+ if (p == NULL && feof(state->current_input)) { - size_t i; - - /* -diff --git a/tests/shtest b/tests/shtest -index cb88745277..370f7b7c69 100755 ---- a/tests/shtest -+++ b/tests/shtest -@@ -880,4 +880,10 @@ $JQ -nf $d/prog.jq 2> $d/out && { - } - diff $d/out $d/expected - -+# CVE-2026-33948: No NUL truncation in the JSON parser -+if printf '{}\x00{}' | $JQ >/dev/null 2> /dev/null; then -+ printf 'Error expected but jq exited successfully\n' 1>&2 -+ exit 1 -+fi -+ - exit 0 diff --git a/pkgs/by-name/jq/jq/CVE-2026-39979.patch b/pkgs/by-name/jq/jq/CVE-2026-39979.patch deleted file mode 100644 index cc0c3d17f77f..000000000000 --- a/pkgs/by-name/jq/jq/CVE-2026-39979.patch +++ /dev/null @@ -1,27 +0,0 @@ -From 2f09060afab23fe9390cce7cb860b10416e1bf5f Mon Sep 17 00:00:00 2001 -From: itchyny -Date: Mon, 13 Apr 2026 11:04:52 +0900 -Subject: [PATCH] Fix out-of-bounds read in jv_parse_sized() - -This fixes CVE-2026-39979. - -Co-authored-by: Mattias Wadman ---- - src/jv_parse.c | 3 ++- - 1 file changed, 2 insertions(+), 1 deletion(-) - -diff --git a/src/jv_parse.c b/src/jv_parse.c -index aa2054cc09..56847b5eaa 100644 ---- a/src/jv_parse.c -+++ b/src/jv_parse.c -@@ -893,8 +893,9 @@ jv jv_parse_sized_custom_flags(const char* string, int length, int flags) { - - if (!jv_is_valid(value) && jv_invalid_has_msg(jv_copy(value))) { - jv msg = jv_invalid_get_msg(value); -- value = jv_invalid_with_msg(jv_string_fmt("%s (while parsing '%s')", -+ value = jv_invalid_with_msg(jv_string_fmt("%s (while parsing '%.*s')", - jv_string_value(msg), -+ length, - string)); - jv_free(msg); - } diff --git a/pkgs/by-name/jq/jq/CVE-2026-40164.patch b/pkgs/by-name/jq/jq/CVE-2026-40164.patch deleted file mode 100644 index 483316f64b4b..000000000000 --- a/pkgs/by-name/jq/jq/CVE-2026-40164.patch +++ /dev/null @@ -1,87 +0,0 @@ -From 0c7d133c3c7e37c00b6d46b658a02244fdd3c784 Mon Sep 17 00:00:00 2001 -From: itchyny -Date: Mon, 13 Apr 2026 08:53:26 +0900 -Subject: [PATCH] Randomize hash seed to mitigate hash collision DoS attacks - -The hash function used a fixed seed, allowing attackers to craft colliding keys -and cause O(n^2) object parsing performance. Initialize the seed from a random -source at process startup to prevent the attack. This fixes CVE-2026-40164. - -Co-authored-by: Asaf Meizner ---- - configure.ac | 2 ++ - src/jv.c | 34 ++++++++++++++++++++++++++++++++-- - 2 files changed, 34 insertions(+), 2 deletions(-) - -diff --git a/configure.ac b/configure.ac -index 5dac42655a..f7067a4341 100644 ---- a/configure.ac -+++ b/configure.ac -@@ -149,6 +149,8 @@ AC_CHECK_MEMBER([struct tm.tm_gmtoff], [AC_DEFINE([HAVE_TM_TM_GMT_OFF],1,[Define - AC_CHECK_MEMBER([struct tm.__tm_gmtoff], [AC_DEFINE([HAVE_TM___TM_GMT_OFF],1,[Define to 1 if the system has the __tm_gmt_off field in struct tm])], - [], [[#include ]]) - AC_FIND_FUNC([setlocale], [c], [#include ], [0,0]) -+AC_FIND_FUNC([arc4random], [c], [#include ], []) -+AC_FIND_FUNC([getentropy], [c], [#include ], [0, 0]) - - dnl Figure out if we have the pthread functions we actually need - AC_FIND_FUNC_NO_LIBS([pthread_key_create], [], [#include ], [NULL, NULL]) -diff --git a/src/jv.c b/src/jv.c -index 2a62b48419..607ac174f7 100644 ---- a/src/jv.c -+++ b/src/jv.c -@@ -40,6 +40,10 @@ - #include - #include - #include -+#include -+#include -+#include -+#include - - #include "jv_alloc.h" - #include "jv.h" -@@ -1206,7 +1210,33 @@ static jv jvp_string_append(jv string, const char* data, uint32_t len) { - } - } - --static const uint32_t HASH_SEED = 0x432A9843; -+static uint32_t hash_seed; -+static pthread_once_t hash_seed_once = PTHREAD_ONCE_INIT; -+ -+static void jvp_hash_seed_init(void) { -+ uint32_t seed; -+#if defined(HAVE_ARC4RANDOM) -+ seed = arc4random(); -+#elif defined(HAVE_GETENTROPY) -+ if (getentropy(&seed, sizeof(seed)) != 0) -+ seed = (uint32_t)getpid() ^ (uint32_t)time(NULL); -+#else -+ int fd = open("/dev/urandom", O_RDONLY); -+ if (fd >= 0) { -+ if (read(fd, &seed, sizeof(seed)) != 4) -+ seed = (uint32_t)getpid() ^ (uint32_t)time(NULL); -+ close(fd); -+ } else { -+ seed = (uint32_t)getpid() ^ (uint32_t)time(NULL); -+ } -+#endif -+ hash_seed = seed; -+} -+ -+static uint32_t jvp_hash_seed(void) { -+ pthread_once(&hash_seed_once, jvp_hash_seed_init); -+ return hash_seed; -+} - - static uint32_t rotl32 (uint32_t x, int8_t r){ - return (x << r) | (x >> (32 - r)); -@@ -1225,7 +1255,7 @@ static uint32_t jvp_string_hash(jv jstr) { - int len = (int)jvp_string_length(str); - const int nblocks = len / 4; - -- uint32_t h1 = HASH_SEED; -+ uint32_t h1 = jvp_hash_seed(); - - const uint32_t c1 = 0xcc9e2d51; - const uint32_t c2 = 0x1b873593; diff --git a/pkgs/by-name/jq/jq/musl.patch b/pkgs/by-name/jq/jq/musl.patch deleted file mode 100644 index 3632899882e7..000000000000 --- a/pkgs/by-name/jq/jq/musl.patch +++ /dev/null @@ -1,31 +0,0 @@ -From 63e9449a8142ce30c83fcd7e9396e5de9843774e Mon Sep 17 00:00:00 2001 -From: Alyssa Ross -Date: Thu, 3 Jul 2025 11:00:13 +0200 -Subject: [PATCH] jq.test: drop non-portable %F test - -%F is a non-portable GNU extension, not supported by all strptime -implementations (for example musl's). - -Link: https://github.com/jqlang/jq/pull/3365 ---- - tests/jq.test | 4 ---- - 1 file changed, 4 deletions(-) - -diff --git a/tests/jq.test b/tests/jq.test -index 4ecf72f..6bfb6f8 100644 ---- a/tests/jq.test -+++ b/tests/jq.test -@@ -1848,10 +1848,6 @@ try ["OK", strflocaltime({})] catch ["KO", .] - "2015-03-05T23:51:47Z" - [[2015,2,5,23,51,47,4,63],1425599507] - --[strptime("%FT%T")|(.,mktime)] --"2025-06-07T08:09:10" --[[2025,5,7,8,9,10,6,157],1749283750] -- - # Check day-of-week and day of year computations - # (should trip an assert if this fails) - last(range(365 * 67)|("1970-03-01T01:02:03Z"|strptime("%Y-%m-%dT%H:%M:%SZ")|mktime) + (86400 * .)|strftime("%Y-%m-%dT%H:%M:%SZ")|strptime("%Y-%m-%dT%H:%M:%SZ")) --- -2.49.0 - diff --git a/pkgs/by-name/jq/jq/package.nix b/pkgs/by-name/jq/jq/package.nix index 31633d27ba03..e6a28fc5248d 100644 --- a/pkgs/by-name/jq/jq/package.nix +++ b/pkgs/by-name/jq/jq/package.nix @@ -14,12 +14,12 @@ stdenv.mkDerivation (finalAttrs: { pname = "jq"; - version = "1.8.1"; + version = "1.8.2"; # Note: do not use fetchpatch or fetchFromGitHub to keep this package available in __bootPackages src = fetchurl { url = "https://github.com/jqlang/jq/releases/download/jq-${finalAttrs.version}/jq-${finalAttrs.version}.tar.gz"; - hash = "sha256-K+ZOcSnOyxHVkGKQ66EK9pT7nj5/n8IIoxHcM8qDfrA="; + hash = "sha256-cbjW6PX+gfbG0NEQ44kiUfbOdu0JWr0xXibm4Rk6868="; }; outputs = [ @@ -30,15 +30,7 @@ stdenv.mkDerivation (finalAttrs: { "out" ]; - patches = [ - ./musl.patch - ./CVE-2026-32316.patch - ./CVE-2026-33947.patch - ./CVE-2026-33948.patch - ./CVE-2026-39979.patch - ./CVE-2026-40164.patch - ] - ++ lib.optionals stdenv.hostPlatform.is32bit [ + patches = lib.optionals stdenv.hostPlatform.is32bit [ # needed because epoch conversion test here is right at the end of 32 bit integer space # See also: https://github.com/jqlang/jq/blob/859a8073ee8a21f2133154eea7c2bd5e0d60837f/tests/optional.test#L15-L18 # "-D_TIME_BITS=64 -D_FILE_OFFSET_BITS=64" would be preferrable, but breaks with dynamic linking, diff --git a/pkgs/by-name/kr/krb5/CVE-2026-11850.patch b/pkgs/by-name/kr/krb5/CVE-2026-11850.patch new file mode 100644 index 000000000000..3c7dde29df3f --- /dev/null +++ b/pkgs/by-name/kr/krb5/CVE-2026-11850.patch @@ -0,0 +1,33 @@ +From 2a5fd83d4436583f2ddc0e193269a4d800ee45c4 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Sebasti=C3=A1n=20Alba?= +Date: Wed, 8 Apr 2026 18:32:25 -0400 +Subject: [PATCH] Prevent read overrun in libkdb_ldap + +In berval2tl_data(), reject inputs of length less than 2 to prevent an +integer underflow and subsequent read overrun. (The security impact +is negligible as the attacker would have to control the KDB LDAP +server.) + +[ghudson@mit.edu: wrote commit message] + +ticket: 9206 (new) +tags: pullup +target_version: 1.22-next +--- + plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c | 3 +++ + 1 file changed, 3 insertions(+) + +diff --git a/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c b/src/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c +index 418d253d17..9aa68bacd7 100644 +--- a/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c ++++ b/plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c +@@ -80,6 +80,9 @@ getstringtime(krb5_timestamp); + krb5_error_code + berval2tl_data(struct berval *in, krb5_tl_data **out) + { ++ if (in->bv_len < 2) ++ return EINVAL; ++ + *out = (krb5_tl_data *) malloc (sizeof (krb5_tl_data)); + if (*out == NULL) + return ENOMEM; diff --git a/pkgs/by-name/kr/krb5/package.nix b/pkgs/by-name/kr/krb5/package.nix index c4e35061d41a..4e97e9867190 100644 --- a/pkgs/by-name/kr/krb5/package.nix +++ b/pkgs/by-name/kr/krb5/package.nix @@ -44,6 +44,8 @@ stdenv.mkDerivation (finalAttrs: { }; patches = [ + # https://github.com/krb5/krb5/pull/1505 + ./CVE-2026-11850.patch # https://github.com/krb5/krb5/pull/1506 ./CVE-2026-40355-and-CVE-2026-40356.patch ] diff --git a/pkgs/by-name/ld/ldns/package.nix b/pkgs/by-name/ld/ldns/package.nix index 4078cdfd5372..f40ea684be96 100644 --- a/pkgs/by-name/ld/ldns/package.nix +++ b/pkgs/by-name/ld/ldns/package.nix @@ -11,11 +11,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "ldns"; - version = "1.9.0"; + version = "1.9.2"; src = fetchurl { url = "https://www.nlnetlabs.nl/downloads/ldns/ldns-${finalAttrs.version}.tar.gz"; - sha256 = "sha256-q67tKFj76oSk65gz4Z59IzgMwPPZtlSLlivkInb/3LM="; + sha256 = "sha256-tST6IZlLboNCAM64wn8bhL2lmC/jVwbwWBlsB525TV0="; }; postPatch = '' diff --git a/pkgs/by-name/le/lerc/package.nix b/pkgs/by-name/le/lerc/package.nix index 9cf5725679dd..7765b5e8b9a6 100644 --- a/pkgs/by-name/le/lerc/package.nix +++ b/pkgs/by-name/le/lerc/package.nix @@ -10,7 +10,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "lerc"; - version = "4.1.0"; + version = "4.1.1"; outputs = [ "out" @@ -21,7 +21,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "esri"; repo = "lerc"; tag = "v${finalAttrs.version}"; - hash = "sha256-+X30DQuq2oT/sTe8usUaNK1V+UTNvXJW7IAJVIr8m78="; + hash = "sha256-YTNIydQLCBzsuvPWA6qnOkOIPf9JlByJdNHkTevE7Z0="; }; # Required to get the freebsd-ports patch to apply. diff --git a/pkgs/by-name/li/libadwaita/package.nix b/pkgs/by-name/li/libadwaita/package.nix index 8f289c6e4977..fdad6431655b 100644 --- a/pkgs/by-name/li/libadwaita/package.nix +++ b/pkgs/by-name/li/libadwaita/package.nix @@ -23,7 +23,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "libadwaita"; - version = "1.9.1"; + version = "1.9.2"; outputs = [ "out" @@ -37,7 +37,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "GNOME"; repo = "libadwaita"; tag = finalAttrs.version; - hash = "sha256-Oy3WcsymNbbmAacm5hEOrorI1wKXjSp063mh4jCJRAE="; + hash = "sha256-XKKjnZz4CII6w9fKFptPK3aTNa5eMfyE7rcerbgaDco="; }; depsBuildBuild = [ diff --git a/pkgs/by-name/li/libarchive/package.nix b/pkgs/by-name/li/libarchive/package.nix index 8f9f756a2ee9..fe81d018859c 100644 --- a/pkgs/by-name/li/libarchive/package.nix +++ b/pkgs/by-name/li/libarchive/package.nix @@ -32,13 +32,13 @@ assert xarSupport -> libxml2 != null; stdenv.mkDerivation (finalAttrs: { pname = "libarchive"; - version = "3.8.7"; + version = "3.8.8"; src = fetchFromGitHub { owner = "libarchive"; repo = "libarchive"; rev = "v${finalAttrs.version}"; - hash = "sha256-LpD+lE+0PZi/3nYDVPXhBQL9A7mvqelOzRLskVtg9Y0="; + hash = "sha256-l8xh+z6lP7VnxMIf9tfoSByerjwN6Z4dE3JNA9zS3LM="; }; outputs = [ diff --git a/pkgs/by-name/li/libevent/package.nix b/pkgs/by-name/li/libevent/package.nix index fd8da373bf01..d220a63c4963 100644 --- a/pkgs/by-name/li/libevent/package.nix +++ b/pkgs/by-name/li/libevent/package.nix @@ -14,11 +14,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "libevent"; - version = "2.1.12"; + version = "2.1.13"; src = fetchurl { url = "https://github.com/libevent/libevent/releases/download/release-${finalAttrs.version}-stable/libevent-${finalAttrs.version}-stable.tar.gz"; - sha256 = "1fq30imk8zd26x8066di3kpc5zyfc5z6frr3zll685zcx4dxxrlj"; + hash = "sha256-9+k4O4wLqoG2h+W17swBvu+vGxm2QVHZXtYWR/56MVw="; }; patches = [ diff --git a/pkgs/by-name/li/libheif/package.nix b/pkgs/by-name/li/libheif/package.nix index 42171d469f5a..940c3015dfb5 100644 --- a/pkgs/by-name/li/libheif/package.nix +++ b/pkgs/by-name/li/libheif/package.nix @@ -24,7 +24,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "libheif"; - version = "1.23.0"; + version = "1.23.1"; outputs = [ "bin" @@ -38,7 +38,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "strukturag"; repo = "libheif"; rev = "v${finalAttrs.version}"; - hash = "sha256-+LbYwDSxixy4TaraUCN2LiCnn32dkMppCA8EOFXbvtg="; + hash = "sha256-o+gQCv/lpRx+IaqpjHACh8ysgl/N4Mo/9zbAI/cnWas="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/li/libidn/package.nix b/pkgs/by-name/li/libidn/package.nix index d36eedac8fe9..071b7f08f15d 100644 --- a/pkgs/by-name/li/libidn/package.nix +++ b/pkgs/by-name/li/libidn/package.nix @@ -8,11 +8,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "libidn"; - version = "1.43"; + version = "1.44"; src = fetchurl { url = "mirror://gnu/libidn/libidn-${finalAttrs.version}.tar.gz"; - sha256 = "sha256-vcZiwS0EGyU50OY486bnQRMM2zOmRO80lpY6RDSC0WQ="; + sha256 = "sha256-SZYIurOmVlCg6lKIjBOo3uvj9xQI4xms2exS4C6xOVk="; }; outputs = [ @@ -30,6 +30,7 @@ stdenv.mkDerivation (finalAttrs: { passthru.tests.pkg-config = testers.testMetaPkgConfig finalAttrs.finalPackage; meta = { + changelog = "https://codeberg.org/libidn/libidn/src/tag/v${finalAttrs.version}/NEWS"; homepage = "https://www.gnu.org/software/libidn/"; description = "Library for internationalized domain names"; diff --git a/pkgs/by-name/li/libreswan/package.nix b/pkgs/by-name/li/libreswan/package.nix index 2295de6ae0d1..ae17e04d0078 100644 --- a/pkgs/by-name/li/libreswan/package.nix +++ b/pkgs/by-name/li/libreswan/package.nix @@ -51,11 +51,11 @@ in stdenv.mkDerivation rec { pname = "libreswan"; - version = "5.3.1"; + version = "5.3.2"; src = fetchurl { url = "https://download.libreswan.org/libreswan-${version}.tar.gz"; - hash = "sha256-4/DlHYtkK/aTpqjMbx5ip2TP9BgKAjvzx+QtQ6Yt/p4="; + hash = "sha256-+5GK+gu5K9BDDB2oYe+AaIZNJdchMN8MYweh+dp2EIg="; }; strictDeps = true; diff --git a/pkgs/by-name/li/librsvg/package.nix b/pkgs/by-name/li/librsvg/package.nix index 333015e1927c..297c1a0eae32 100644 --- a/pkgs/by-name/li/librsvg/package.nix +++ b/pkgs/by-name/li/librsvg/package.nix @@ -50,7 +50,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "librsvg"; - version = "2.62.1"; + version = "2.62.3"; outputs = [ "out" @@ -62,13 +62,13 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "mirror://gnome/sources/librsvg/${lib.versions.majorMinor finalAttrs.version}/librsvg-${finalAttrs.version}.tar.xz"; - hash = "sha256-tByoQgYkL93YJqK/djSNfN9SwQUMv6BguGboGiUhRcM="; + hash = "sha256-frRJsnIqdoAhNW9m3+4yAsIptU7U5qcM5AwJDpf/FvI="; }; cargoDeps = rustPlatform.fetchCargoVendor { inherit (finalAttrs) src; name = "librsvg-deps-${finalAttrs.version}"; - hash = "sha256-Px7H2Z4ShCCuZNskuKj427lE9dvIc6xRo8R1S4fK+ZQ="; + hash = "sha256-9ubfIl9R2BdcAWn7i050KBbb4cMdlakvrKdnjpZCQjA="; dontConfigure = true; }; diff --git a/pkgs/by-name/li/libssh2/package.nix b/pkgs/by-name/li/libssh2/package.nix index 71ed533d7a74..1e987379f73c 100644 --- a/pkgs/by-name/li/libssh2/package.nix +++ b/pkgs/by-name/li/libssh2/package.nix @@ -26,6 +26,31 @@ stdenv.mkDerivation (finalAttrs: { patches = [ # https://github.com/libssh2/libssh2/commit/256d04b60d80bf1190e96b0ad1e91b2174d744b1 ./CVE-2026-7598.patch + + (fetchurl { + name = "CVE-2025-15661.patch"; + url = "https://salsa.debian.org/debian/libssh2/-/raw/1d4906e6ebe85a9da2931ba33677ead96a61f07f/debian/patches/CVE-2025-15661.patch"; + hash = "sha256-Rz6i/881CbObUDcZbcPlgVPaKizSp6ZRTdmJNJ9HLHE="; + }) + + (fetchurl { + name = "CVE-2026-55199.patch"; + url = "https://salsa.debian.org/debian/libssh2/-/raw/1d4906e6ebe85a9da2931ba33677ead96a61f07f/debian/patches/CVE-2026-55199.patch"; + hash = "sha256-AFZa5kohha62aE0if5ckmAdJ0TZNcjfP32yDznoEhNo="; + }) + + (fetchurl { + name = "CVE-2026-55200.patch"; + url = "https://salsa.debian.org/debian/libssh2/-/raw/1d4906e6ebe85a9da2931ba33677ead96a61f07f/debian/patches/CVE-2026-55200.patch"; + hash = "sha256-wCAglr8BsBWIhnh3SiFeyKzZmIp8rC5MVfFgoEzp/hE="; + }) + + # necessary for the fix for CVE-2026-15661 + (fetchurl { + name = "libssh-unconst-backport.patch"; + url = "https://salsa.debian.org/debian/libssh2/-/raw/1d4906e6ebe85a9da2931ba33677ead96a61f07f/debian/patches/libssh-unconst-backport.patch"; + hash = "sha256-jc01Fb70GbaD9+RYeSjRaLFBtKLiMPTMuXas21aC0Ag="; + }) ]; # this could be accomplished by updateAutotoolsGnuConfigScriptsHook, but that causes infinite recursion diff --git a/pkgs/by-name/li/libtpms/0001-fix-march-x86-64-v4.patch b/pkgs/by-name/li/libtpms/0001-fix-march-x86-64-v4.patch new file mode 100644 index 000000000000..7feb37e0c417 --- /dev/null +++ b/pkgs/by-name/li/libtpms/0001-fix-march-x86-64-v4.patch @@ -0,0 +1,17 @@ +https://github.com/stefanberger/libtpms/pull/588 + +diff --git a/src/tpm2/AlgorithmTests.c b/src/tpm2/AlgorithmTests.c +index eca917d0..8cbc749b 100644 +--- a/src/tpm2/AlgorithmTests.c ++++ b/src/tpm2/AlgorithmTests.c +@@ -197,8 +197,8 @@ TestSMAC( + //*** MakeIv() + // Internal function to make the appropriate IV depending on the mode. + static UINT32 MakeIv(TPM_ALG_ID mode, // IN: symmetric mode +- UINT32 size, // IN: block size of the algorithm +- BYTE* iv // OUT: IV to fill in ++ UINT32 size, // IN: block size of the algorithm ++ volatile BYTE* iv // OUT: IV to fill in; 'volatile' for gcc15 + ) + { + BYTE i; diff --git a/pkgs/by-name/li/libtpms/package.nix b/pkgs/by-name/li/libtpms/package.nix index f658b8d23f6c..b793bb798f54 100644 --- a/pkgs/by-name/li/libtpms/package.nix +++ b/pkgs/by-name/li/libtpms/package.nix @@ -19,6 +19,8 @@ stdenv.mkDerivation (finalAttrs: { sha256 = "sha256-UhEpq5f/FT5DmtzQBe/Si414mOq+D4glikgRNK60GKQ="; }; + patches = [ ./0001-fix-march-x86-64-v4.patch ]; + hardeningDisable = [ "strictflexarrays3" ]; nativeBuildInputs = [ diff --git a/pkgs/by-name/li/libxfont_2/package.nix b/pkgs/by-name/li/libxfont_2/package.nix index 9f1dbea7359e..0156515019d1 100644 --- a/pkgs/by-name/li/libxfont_2/package.nix +++ b/pkgs/by-name/li/libxfont_2/package.nix @@ -15,7 +15,7 @@ }: stdenv.mkDerivation (finalAttrs: { pname = "libxfont_2"; - version = "2.0.7"; + version = "2.0.8"; outputs = [ "out" @@ -24,7 +24,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "mirror://xorg/individual/lib/libXfont2-${finalAttrs.version}.tar.xz"; - hash = "sha256-i3uC/eukh2m2lDPo4/u5hKX2vzaLDV9Hq+7EnePljvs="; + hash = "sha256-9VbA4Qk6TmkRzJC8SxBtIBkC7hh/10ryBv8WL35qJNU="; }; strictDeps = true; diff --git a/pkgs/by-name/li/libxi/package.nix b/pkgs/by-name/li/libxi/package.nix index 3cbac22c36f3..0475ba395175 100644 --- a/pkgs/by-name/li/libxi/package.nix +++ b/pkgs/by-name/li/libxi/package.nix @@ -12,7 +12,7 @@ }: stdenv.mkDerivation (finalAttrs: { pname = "libxi"; - version = "1.8.2"; + version = "1.8.3"; outputs = [ "out" @@ -23,7 +23,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "mirror://xorg/individual/lib/libXi-${finalAttrs.version}.tar.xz"; - hash = "sha256-0OBVXlPW4hFOq/pEImuhYtJwhQGiXhjZnPs1wJTGwQQ="; + hash = "sha256-etYAVvAa9PeGz+k7OncHRHcRYm/I2iY3vscakECbq+U="; }; strictDeps = true; diff --git a/pkgs/by-name/li/linux-pam/package.nix b/pkgs/by-name/li/linux-pam/package.nix index 5e1fdfd4a7ce..0da213b857c0 100644 --- a/pkgs/by-name/li/linux-pam/package.nix +++ b/pkgs/by-name/li/linux-pam/package.nix @@ -3,6 +3,7 @@ stdenv, buildPackages, fetchFromGitHub, + fetchpatch, flex, db4, gettext, @@ -33,18 +34,25 @@ stdenv.mkDerivation (finalAttrs: { pname = "linux-pam"; - version = "1.7.1"; + version = "1.7.2"; src = fetchFromGitHub { owner = "linux-pam"; repo = "linux-pam"; tag = "v${finalAttrs.version}"; - hash = "sha256-kANcwxifQz2tYPSrSBSFiYNTm51Gr10L/zroCqm8ZHQ="; - + hash = "sha256-V3XQqolinh+MqUefMDYJF9zP4fBJTHc7YKN+NEGjx1g="; }; __structuredAttrs = true; + patches = [ + (fetchpatch { + name = "secure-opendir-fix-error-handling.patch"; + url = "https://github.com/linux-pam/linux-pam/commit/dd62bac17221911106de165607c6925ea54b18d1.patch?full_index=1"; + hash = "sha256-ddgDYdVfdXfTaMFV1hO3RJX9w1NHmE7yi3PxsHOdpvY="; + }) + ]; + # patching unix_chkpwd is required as the nix store entry does not have the necessary bits postPatch = '' substituteInPlace modules/module-meson.build \ @@ -104,6 +112,7 @@ stdenv.mkDerivation (finalAttrs: { (lib.mesonEnable "nis" false) (lib.mesonBool "xtests" false) (lib.mesonBool "examples" false) + (lib.mesonOption "vendordir" "${placeholder "out"}/etc") ] # warning: slower execution due to debug makes VM tests fail! ++ lib.optional debugMode (lib.mesonBool "pam-debug" true); diff --git a/pkgs/by-name/ll/llhttp/package.nix b/pkgs/by-name/ll/llhttp/package.nix index 6f9115c07dc4..4487a4518360 100644 --- a/pkgs/by-name/ll/llhttp/package.nix +++ b/pkgs/by-name/ll/llhttp/package.nix @@ -11,13 +11,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "llhttp"; - version = "9.4.1"; + version = "9.4.2"; src = fetchFromGitHub { owner = "nodejs"; repo = "llhttp"; tag = "release/v${finalAttrs.version}"; - hash = "sha256-eQoOsJ3lIIGSIfC4atkbUqCAYzCzs5kzTihYaI4jqz0="; + hash = "sha256-LS8HS8CnXJ3X8WlIvtxBLc0h1wLL/HmTqZWHlvBjTEo="; }; outputs = [ diff --git a/pkgs/by-name/mc/mctc-lib/package.nix b/pkgs/by-name/mc/mctc-lib/package.nix index 3473b3dbaa7e..4f0dd9397d0d 100644 --- a/pkgs/by-name/mc/mctc-lib/package.nix +++ b/pkgs/by-name/mc/mctc-lib/package.nix @@ -10,6 +10,7 @@ pkg-config, python3, jonquil, + checkPhaseThreadLimitHook, }: assert ( @@ -43,6 +44,7 @@ stdenv.mkDerivation (finalAttrs: { gfortran pkg-config python3 + checkPhaseThreadLimitHook ] ++ lib.optionals (buildType == "meson") [ meson @@ -61,10 +63,6 @@ stdenv.mkDerivation (finalAttrs: { doCheck = true; - preCheck = '' - export OMP_NUM_THREADS=2 - ''; - postPatch = '' patchShebangs --build config/install-mod.py ''; diff --git a/pkgs/by-name/me/merve/package.nix b/pkgs/by-name/me/merve/package.nix index e8a210d551e6..066ac8fd351d 100644 --- a/pkgs/by-name/me/merve/package.nix +++ b/pkgs/by-name/me/merve/package.nix @@ -26,16 +26,14 @@ stdenv.mkDerivation (finalAttrs: { cmakeFlags = [ (lib.cmakeBool "BUILD_SHARED_LIBS" (!static)) (lib.cmakeBool "MERVE_TESTING" finalAttrs.finalPackage.doCheck) - (lib.cmakeBool "MERVE_USE_SIMDUTF" true) - ]; + ] + ++ lib.optional (simdutf != null) (lib.cmakeBool "MERVE_USE_SIMDUTF" true); nativeBuildInputs = [ cmake validatePkgConfig ]; - buildInputs = [ - simdutf - ]; + buildInputs = lib.optional (simdutf != null) simdutf; checkInputs = [ gtest ]; diff --git a/pkgs/by-name/mi/mimir/package.nix b/pkgs/by-name/mi/mimir/package.nix index a78589f6a584..95b85faa5aff 100644 --- a/pkgs/by-name/mi/mimir/package.nix +++ b/pkgs/by-name/mi/mimir/package.nix @@ -7,13 +7,13 @@ }: buildGoModule (finalAttrs: { pname = "mimir"; - version = "3.0.7"; + version = "3.0.8"; src = fetchFromGitHub { rev = "mimir-${finalAttrs.version}"; owner = "grafana"; repo = "mimir"; - hash = "sha256-Hw7TiUyTXZ/CKT4jeyWYVQM4EY/DbwBtaTEebNHonGs="; + hash = "sha256-1TMnO/M8gT46gQYsOqZ6f1kU22jHsSS/d3MdKCjt3Nc="; }; vendorHash = null; @@ -67,7 +67,6 @@ buildGoModule (finalAttrs: { maintainers = with lib.maintainers; [ happysalada bryanhonof - adamcstephens ]; }; }) diff --git a/pkgs/by-name/mk/mkl/package.nix b/pkgs/by-name/mk/mkl/package.nix index f9e1dda4e7ab..31b724759e8a 100644 --- a/pkgs/by-name/mk/mkl/package.nix +++ b/pkgs/by-name/mk/mkl/package.nix @@ -8,6 +8,11 @@ _7zz, cctools, validatePkgConfig, + # sets MKL_NUM_THREADS for packages + # invoking mkl during checkPhase/installCheckPhase to + # avoid overloading builders with excessive parallelism + # See also: https://www.intel.com/content/www/us/en/docs/onemkl/developer-guide-linux/2023-0/mkl-domain-num-threads.html + checkPhaseThreadLimitHook, enableStatic ? stdenv.hostPlatform.isStatic, }: @@ -86,6 +91,10 @@ stdenvNoCC.mkDerivation ( [ rpmextract ] ); + propagatedNativeBuildInputs = [ + checkPhaseThreadLimitHook + ]; + buildPhase = if stdenvNoCC.hostPlatform.isDarwin then '' diff --git a/pkgs/by-name/mo/mopac/package.nix b/pkgs/by-name/mo/mopac/package.nix index c5e5dacccb9b..c70b46ded59c 100644 --- a/pkgs/by-name/mo/mopac/package.nix +++ b/pkgs/by-name/mo/mopac/package.nix @@ -39,10 +39,6 @@ stdenv.mkDerivation (finalAttrs: { doCheck = true; - preCheck = '' - export OMP_NUM_THREADS=2 - ''; - meta = { description = "Semiempirical quantum chemistry"; homepage = "https://github.com/openmopac/mopac"; diff --git a/pkgs/by-name/mo/motioneye/package.nix b/pkgs/by-name/mo/motioneye/package.nix index 7a5ee72311ef..a947a722d8c1 100644 --- a/pkgs/by-name/mo/motioneye/package.nix +++ b/pkgs/by-name/mo/motioneye/package.nix @@ -2,31 +2,21 @@ lib, python3Packages, fetchFromGitHub, - fetchpatch, + versionCheckHook, }: python3Packages.buildPythonApplication rec { pname = "motioneye"; - version = "0.43.1"; + version = "0.44.0"; pyproject = true; src = fetchFromGitHub { owner = "motioneye-project"; repo = "motioneye"; tag = version; - hash = "sha256-ckOgYmOP5irjNutcC3FMZPBexn/CldG0UtFZ+tPYNJ4="; + hash = "sha256-4sXttSSkmMgsoZb7PXEXXh8KNORTSmqq4lYp3JBDmPo="; }; - patches = [ - # fix pytest - # https://github.com/motioneye-project/motioneye/pull/3271 - (fetchpatch { - url = "https://github.com/motioneye-project/motioneye/commit/41c0727e2872af1b758743c41b529e76dcac6f84.patch"; - hash = "sha256-0zDveoAN1T0SuCob0U/9GEGTh7pj2CXH/j4YrjO0VE0="; - includes = [ "conftest.py" ]; - }) - ]; - build-system = with python3Packages; [ setuptools ]; @@ -38,16 +28,24 @@ python3Packages.buildPythonApplication rec { pillow pycurl tornado + argon2-cffi ]; nativeCheckInputs = with python3Packages; [ pytestCheckHook ]; + nativeInstallCheckInputs = [ + versionCheckHook + ]; + pythonImportsCheck = [ "motioneye" ]; + versionCheckProgram = "${placeholder "out"}/bin/meyectl"; + versionCheckProgramArg = "-v"; + meta = { description = "Web frontend for the motion daemon"; homepage = "https://github.com/motioneye-project/motioneye"; diff --git a/pkgs/by-name/mp/mpb/package.nix b/pkgs/by-name/mp/mpb/package.nix index eb001a94446d..f92f7bfeeadf 100644 --- a/pkgs/by-name/mp/mpb/package.nix +++ b/pkgs/by-name/mp/mpb/package.nix @@ -59,8 +59,6 @@ stdenv.mkDerivation (finalAttrs: { doCheck = true; - preCheck = "export OMP_NUM_THREADS=2"; - meta = { description = "MIT Photonic-Bands: computation of photonic band structures in periodic media"; homepage = "https://mpb.readthedocs.io/en/latest/"; diff --git a/pkgs/by-name/mp/mpiCheckPhaseHook/mpi-check-hook.sh b/pkgs/by-name/mp/mpiCheckPhaseHook/mpi-check-hook.sh index be2203951c0f..139dc932366f 100644 --- a/pkgs/by-name/mp/mpiCheckPhaseHook/mpi-check-hook.sh +++ b/pkgs/by-name/mp/mpiCheckPhaseHook/mpi-check-hook.sh @@ -72,8 +72,5 @@ setupMpiCheck() { export HWLOC_XMLFILE="@topology@" ;; esac - - # Limit number of OpenMP threads. Default is "all cores". - export OMP_NUM_THREADS=1 } diff --git a/pkgs/by-name/mp/mpiCheckPhaseHook/package.nix b/pkgs/by-name/mp/mpiCheckPhaseHook/package.nix index c771e87376fa..88a8bc90abd2 100644 --- a/pkgs/by-name/mp/mpiCheckPhaseHook/package.nix +++ b/pkgs/by-name/mp/mpiCheckPhaseHook/package.nix @@ -1,7 +1,7 @@ { - callPackage, makeSetupHook, stdenv, + checkPhaseThreadLimitHook, }: makeSetupHook { @@ -11,4 +11,8 @@ makeSetupHook { iface = if stdenv.hostPlatform.isDarwin then "lo0" else "lo"; topology = ./topology.xml; }; + + propagatedNativeBuildInputs = [ + checkPhaseThreadLimitHook + ]; } ./mpi-check-hook.sh diff --git a/pkgs/by-name/mu/multicharge/package.nix b/pkgs/by-name/mu/multicharge/package.nix index b4fcbe0cf512..a6192b7993db 100644 --- a/pkgs/by-name/mu/multicharge/package.nix +++ b/pkgs/by-name/mu/multicharge/package.nix @@ -71,10 +71,6 @@ stdenv.mkDerivation (finalAttrs: { patchShebangs --build config/install-mod.py ''; - preCheck = '' - export OMP_NUM_THREADS=2 - ''; - meta = { description = "Electronegativity equilibration model for atomic partial charges"; mainProgram = "multicharge"; diff --git a/pkgs/by-name/na/nasm/package.nix b/pkgs/by-name/na/nasm/package.nix index 5b611b57591c..9babb2241495 100644 --- a/pkgs/by-name/na/nasm/package.nix +++ b/pkgs/by-name/na/nasm/package.nix @@ -9,23 +9,20 @@ stdenv.mkDerivation (finalAttrs: { pname = "nasm"; - version = "3.01"; + version = "3.02"; src = fetchurl { url = "https://www.nasm.us/pub/nasm/releasebuilds/${finalAttrs.version}/nasm-${finalAttrs.version}.tar.xz"; - hash = "sha256-tzJMvobnZ7ZfJvRn7YsSrYDhJOPMuJB2hVyY5Dqe3dQ="; + hash = "sha256-hzNuulO0rP6RdCSrXVANKwBU2fUUjTXCJzzPLPtxLw0="; }; patches = [ - # Backport patches fixing nasm with gcc 15 and musl (and other?) platforms - # https://github.com/netwide-assembler/nasm/issues/169 + # Backport the fix for https://github.com/netwide-assembler/nasm/issues/203 + # buffer overflow. (fetchpatch { - url = "https://github.com/netwide-assembler/nasm/commit/44e89ba9b650b5e1533bca43682e167f51a3511f.patch"; - hash = "sha256-zVeMFhoSY/HGYr4meIWBgt5Unq1fA8lM6h1Cl5fpbxo="; - }) - (fetchpatch { - url = "https://github.com/netwide-assembler/nasm/commit/746e7c9efa37cec9a44d84a1e96b8c38f385cc1f.patch"; - hash = "sha256-aXVS70O/wUkW8xtkwF7uwrQfTgGcNvxHrtGC0sjIPto="; + name = "output-oob-fix.patch"; + url = "https://github.com/netwide-assembler/nasm/commit/8890d723d0aa9ed1a790e2ce1c55eee8dfa0cf94.patch"; + hash = "sha256-m03+bhKTgKlqeRLGZIy6GO5BTPIJ3r398VQrtN4waaw="; }) ]; diff --git a/pkgs/by-name/pi/picgo/package.nix b/pkgs/by-name/pi/picgo/package.nix index 6692f1434b70..e751fa0e7c50 100644 --- a/pkgs/by-name/pi/picgo/package.nix +++ b/pkgs/by-name/pi/picgo/package.nix @@ -6,7 +6,7 @@ pnpm_10, fetchPnpmDeps, pnpmConfigHook, - electron_40, + electron_41, makeWrapper, copyDesktopItems, makeDesktopItem, @@ -18,20 +18,20 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "picgo"; - version = "2.5.3"; + version = "3.0.0"; src = fetchFromGitHub { owner = "Molunerfinn"; repo = "PicGo"; tag = "v${finalAttrs.version}"; - hash = "sha256-4Ih7PPBo6scJoUS8yTAR0iyG5vxNc/c0CCw5FGaIbHM="; + hash = "sha256-ruTgNgZsjpdu2Cc2Q4HxPdoQHUww1UTbvLazglaz75c="; }; pnpmDeps = fetchPnpmDeps { inherit (finalAttrs) version src; inherit pnpm; pname = "picgo"; - hash = "sha256-tILvWDoHAN5XT1F/cJYgfeMzowuO/fhiughI+0FvHzc="; + hash = "sha256-IAuTtI0Ljm4+xCeMGIQAf7lK37CQ6qf7PJsksLIti7Q="; fetcherVersion = 3; # lockfileVersion 9.0 corresponds to fetcherVersion 3 }; @@ -56,6 +56,17 @@ stdenv.mkDerivation (finalAttrs: { runHook postBuild ''; + postBuild = '' + cp -r src/renderer/public/. dist_electron/renderer/ + + # Renderer assets are loaded from a file:// URL, so root-relative paths like + # /squareLogo.png resolve to the filesystem root. Copy the renderer public assets + # next to index.html and rewrite those references to relative paths. + # https://github.com/Molunerfinn/PicGo/blob/dev/src/renderer/components/independent-window/mini/picgo-mini-page.tsx + substituteInPlace dist_electron/renderer/assets/mini-*.js \ + --replace-fail '"/squareLogo.png"' '"./squareLogo.png"' + ''; + installPhase = '' runHook preInstall @@ -73,10 +84,20 @@ stdenv.mkDerivation (finalAttrs: { # Create startup script mkdir -p $out/bin - makeWrapper ${lib.getExe electron_40} $out/bin/picgo \ + # PicGo uses app.isPackaged to decide whether it is running in development mode. + # With the nixpkgs Electron wrapper the executable is still the generic electron + # binary, so app.isPackaged is false unless we force the packaged code path. + # https://github.com/Molunerfinn/PicGo/blob/4d92ca199b7afead168785d7375a525ca156b25f/src/main/utils/env.ts#L17-L22 + + # ELECTRON_FORCE_IS_PACKAGED makes PicGo use its production resource path, + # but with the nixpkgs Electron wrapper process.resourcesPath points to Electron + # itself, so point PicGo at the installed public assets + makeWrapper ${lib.getExe electron_41} $out/bin/picgo \ + --add-flags "--class=picgo" \ --add-flags "$out/lib/picgo/.launcher.cjs" \ - --add-flags "--name picgo" \ --set NODE_ENV production \ + --set ELECTRON_FORCE_IS_PACKAGED 1 \ + --set STATIC_PATH "$out/lib/picgo/public" \ --set-default ELECTRON_OZONE_PLATFORM_HINT auto \ --chdir "$out/lib/picgo" diff --git a/pkgs/by-name/pi/pipewire/package.nix b/pkgs/by-name/pi/pipewire/package.nix index 7a9de59f709d..3929f392ee6a 100644 --- a/pkgs/by-name/pi/pipewire/package.nix +++ b/pkgs/by-name/pi/pipewire/package.nix @@ -90,7 +90,7 @@ in stdenv.mkDerivation (finalAttrs: { pname = "pipewire"; - version = "1.6.5"; + version = "1.6.6"; outputs = [ "out" @@ -106,7 +106,7 @@ stdenv.mkDerivation (finalAttrs: { owner = "pipewire"; repo = "pipewire"; tag = finalAttrs.version; - hash = "sha256-ui5VTbSiobHmPUHW4jLguoeMWaKT4f2eTqdo3ZGgvNI="; + hash = "sha256-pyZozhJomFT4QkJv/NKkXpbknmVxjv8hCxZV6RcIHmE="; }; patches = [ diff --git a/pkgs/by-name/pi/pixman/package.nix b/pkgs/by-name/pi/pixman/package.nix index 367fa018c860..f9e469ede120 100644 --- a/pkgs/by-name/pi/pixman/package.nix +++ b/pkgs/by-name/pi/pixman/package.nix @@ -6,6 +6,7 @@ ninja, pkg-config, libpng, + checkPhaseThreadLimitHook, glib, # just passthru # for passthru.tests @@ -46,6 +47,7 @@ stdenv.mkDerivation (finalAttrs: { meson ninja pkg-config + checkPhaseThreadLimitHook __flattenIncludeHackHook ]; @@ -61,11 +63,6 @@ stdenv.mkDerivation (finalAttrs: { "-Dneon=disabled" ]; - preConfigure = '' - # https://gitlab.freedesktop.org/pixman/pixman/-/issues/62 - export OMP_NUM_THREADS=$((NIX_BUILD_CORES > 184 ? 184 : NIX_BUILD_CORES)) - ''; - enableParallelBuilding = true; doCheck = !stdenv.hostPlatform.isDarwin; diff --git a/pkgs/by-name/pm/pmtiles/darwin-sandbox-fix.patch b/pkgs/by-name/pm/pmtiles/darwin-sandbox-fix.patch deleted file mode 100644 index b390d492467c..000000000000 --- a/pkgs/by-name/pm/pmtiles/darwin-sandbox-fix.patch +++ /dev/null @@ -1,20 +0,0 @@ ---- vendor/modernc.org/libc/honnef.co/go/netdb/netdb.go -+++ vendor/modernc.org/libc/honnef.co/go/netdb/netdb.go -@@ -696,7 +696,7 @@ func init() { - // Load protocols - data, err := ioutil.ReadFile("/etc/protocols") - if err != nil { -- if !os.IsNotExist(err) { -+ if !os.IsNotExist(err) && !os.IsPermission(err) { - panic(err) - } - -@@ -732,7 +732,7 @@ func init() { - // Load services - data, err = ioutil.ReadFile("/etc/services") - if err != nil { -- if !os.IsNotExist(err) { -+ if !os.IsNotExist(err) && !os.IsPermission(err) { - panic(err) - } - diff --git a/pkgs/by-name/pm/pmtiles/package.nix b/pkgs/by-name/pm/pmtiles/package.nix index 4f25c65c0d68..eb155ef71e56 100644 --- a/pkgs/by-name/pm/pmtiles/package.nix +++ b/pkgs/by-name/pm/pmtiles/package.nix @@ -5,23 +5,16 @@ }: buildGoModule (finalAttrs: { pname = "pmtiles"; - version = "1.30.0"; + version = "1.31.1"; src = fetchFromGitHub { owner = "protomaps"; repo = "go-pmtiles"; tag = "v${finalAttrs.version}"; - hash = "sha256-7Xkkna85ls5kRelar2DMf+U/4tCa9up/H+uuDJTXJr8="; + hash = "sha256-Hx20rNKmoxryD+/GClJpbXvjta6TUzaHJIRCu1f+lRU="; }; - vendorHash = "sha256-UzpyvWsfbzYTngMdWU+fgZj/yQvSfJzhFWpFRsD24GE="; - - overrideModAttrs = old: { - # https://gitlab.com/cznic/libc/-/merge_requests/10 - postBuild = '' - patch -p0 < ${./darwin-sandbox-fix.patch} - ''; - }; + vendorHash = "sha256-0u/04mpqhpRideIf8eOzgC7ZWNp4P2c2ssQvyWlcD4M="; ldflags = [ "-s" diff --git a/pkgs/by-name/py/pyfa/package.nix b/pkgs/by-name/py/pyfa/package.nix index 034254572c8a..3a75269e3d9d 100644 --- a/pkgs/by-name/py/pyfa/package.nix +++ b/pkgs/by-name/py/pyfa/package.nix @@ -11,7 +11,7 @@ copyDesktopItems, }: let - version = "2.67.0"; + version = "2.68.0"; in python3Packages.buildPythonApplication rec { inherit version; @@ -22,7 +22,7 @@ python3Packages.buildPythonApplication rec { owner = "pyfa-org"; repo = "Pyfa"; tag = "v${version}"; - hash = "sha256-LS8KW6dZe/CYdA1LvZlq1vL8YllnDZkD9WEEDOToY1M="; + hash = "sha256-obx4YG75XxpdlaFlmFmkXdkazHERhm5boOzSx7zDRQs="; }; desktopItems = [ diff --git a/pkgs/by-name/qe/qemu/package.nix b/pkgs/by-name/qe/qemu/package.nix index 31515f58d636..38b38b905da8 100644 --- a/pkgs/by-name/qe/qemu/package.nix +++ b/pkgs/by-name/qe/qemu/package.nix @@ -140,11 +140,11 @@ stdenv.mkDerivation (finalAttrs: { + lib.optionalString nixosTestRunner "-for-vm-tests" + lib.optionalString toolsOnly "-utils" + lib.optionalString userOnly "-user"; - version = "10.2.2"; + version = "10.2.4"; src = fetchurl { url = "https://download.qemu.org/qemu-${finalAttrs.version}.tar.xz"; - hash = "sha256-eEspb/KcFBeqcjI6vLLS6pq5dxck9Xfc14XDsE8h4XY="; + hash = "sha256-ghtUW5LxZeV93cysUHfXbU1DaiJllbiBOtWTBrv9B0Y="; }; depsBuildBuild = [ diff --git a/pkgs/by-name/ra/rancher/package.nix b/pkgs/by-name/ra/rancher/package.nix index 95def8ed13e3..45268d278ed5 100644 --- a/pkgs/by-name/ra/rancher/package.nix +++ b/pkgs/by-name/ra/rancher/package.nix @@ -6,13 +6,13 @@ buildGoModule (finalAttrs: { pname = "rancher"; - version = "2.14.1"; + version = "2.14.2"; src = fetchFromGitHub { owner = "rancher"; repo = "cli"; tag = "v${finalAttrs.version}"; - hash = "sha256-EbcO5JJ8Ny3HwCUchiQaJd7wy2FzxAsZZldfe5/xnB4="; + hash = "sha256-SysEf7oe85htpwi2xy3Em82WuV+sTZCy2OlxoZLshYc="; }; env.CGO_ENABLED = 0; @@ -25,7 +25,7 @@ buildGoModule (finalAttrs: { "-static" ]; - vendorHash = "sha256-X7osjginDVz4a+fx0gXrFm+0DP6hbObOlByFJOOs3is="; + vendorHash = "sha256-sDSblZzRZ3StEMBeJbx2+hsSTKkuU3ixgLqR7vLfp3A="; postInstall = '' mv $out/bin/cli $out/bin/rancher diff --git a/pkgs/by-name/ra/rauthy/package.nix b/pkgs/by-name/ra/rauthy/package.nix index 5ace4bf53030..9a2c7d6912ca 100644 --- a/pkgs/by-name/ra/rauthy/package.nix +++ b/pkgs/by-name/ra/rauthy/package.nix @@ -8,20 +8,20 @@ nix-update-script, perl, wasm-pack, - wasm-bindgen-cli_0_2_121, + wasm-bindgen-cli_0_2_126, binaryen, lld, rust-jemalloc-sys-unprefixed, }: rustPlatform.buildRustPackage (finalAttrs: { pname = "rauthy"; - version = "0.35.2"; + version = "0.36.0"; src = fetchFromGitHub { owner = "sebadob"; repo = "rauthy"; tag = "v${finalAttrs.version}"; - hash = "sha256-onwNtlz2FP01aYr/T3Y3KK3CJHKsBBOF6vCfWKrdyRE="; + hash = "sha256-ctc80gG36O4viHrFcG3RSrr8wnwD3YZD0eyauS9JCPA="; }; nativeBuildInputs = [ @@ -30,7 +30,7 @@ rustPlatform.buildRustPackage (finalAttrs: { nodejs npmHooks.npmConfigHook perl - wasm-bindgen-cli_0_2_121 + wasm-bindgen-cli_0_2_126 wasm-pack ]; @@ -40,10 +40,10 @@ rustPlatform.buildRustPackage (finalAttrs: { npmDeps = fetchNpmDeps { src = "${finalAttrs.src}/frontend"; - hash = "sha256-w3x+dUfmJ4H82wX87C3UHEJ5Ls4v6lsn7kKOxvRJY8g="; + hash = "sha256-3bLzlGbC1i8TOYNi/SAVqIb8bsK0IhDTGr65rVWU5XY="; }; - cargoHash = "sha256-oUc8aMsI3i0WM5/tP/ro93GgkjaDjBdYcgpxiKDvtJ4="; + cargoHash = "sha256-lkD2Yd15VuQT+OmMttea0KBWOnhwvRBN6aS1DVR0Heg="; preBuild = '' pushd src/wasm-modules diff --git a/pkgs/by-name/rs/rsync/package.nix b/pkgs/by-name/rs/rsync/package.nix index a102ff36cc15..2a6cdd676a9f 100644 --- a/pkgs/by-name/rs/rsync/package.nix +++ b/pkgs/by-name/rs/rsync/package.nix @@ -37,7 +37,7 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-vYjPgvplPaMjFPsikTZAfFyQ+A0XWNj0sJF2eHfY+pY="; }; - patches = lib.optionals (stdenv.hostPlatform.isDarwin) [ + patches = [ # Fixes test failure on darwin (fetchpatch { url = "https://github.com/RsyncProject/rsync/commit/e1c5f0e93a75dd45f32f3b92ba221ef158ac2e5f.patch"; diff --git a/pkgs/by-name/ru/rust-cbindgen/package.nix b/pkgs/by-name/ru/rust-cbindgen/package.nix index 88bb855e800b..c6e5427f80c2 100644 --- a/pkgs/by-name/ru/rust-cbindgen/package.nix +++ b/pkgs/by-name/ru/rust-cbindgen/package.nix @@ -14,16 +14,16 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "rust-cbindgen"; - version = "0.29.3"; + version = "0.29.4"; src = fetchFromGitHub { owner = "mozilla"; repo = "cbindgen"; rev = "v${finalAttrs.version}"; - hash = "sha256-d0rY7Sk37s8HEZlQq9Sbjj1P+DgygD0Yjx8cXlFKEIA="; + hash = "sha256-leeHOwpzXuzg2cTjXehBnCsS+dvU4eIIFtWKeCee20U="; }; - cargoHash = "sha256-UeierkQpfCiB5ES9ZW9hO+0AcI9Ip8qSJ/Nd+I1xrmQ="; + cargoHash = "sha256-f6YoDoiVoh0BVPYHFO1FsdI4OCsF+LY72QaD57StdIQ="; nativeCheckInputs = [ cmake diff --git a/pkgs/by-name/sc/scribus/package.nix b/pkgs/by-name/sc/scribus/package.nix index ea6dbf56309e..d8a55eb8e7d3 100644 --- a/pkgs/by-name/sc/scribus/package.nix +++ b/pkgs/by-name/sc/scribus/package.nix @@ -3,6 +3,7 @@ cairo, cmake, cups, + fetchpatch, fetchurl, fontconfig, freetype, @@ -39,11 +40,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "scribus"; - version = "1.7.2"; + version = "1.7.3"; src = fetchurl { url = "mirror://sourceforge/scribus/scribus-devel/scribus-${finalAttrs.version}.tar.xz"; - hash = "sha256-nY4RzGusLNlsVTnvvXGSIv9/cOHBhZcogNn7MFHhONA="; + hash = "sha256-iC7lXKRJfALE4F8wrMaJ6h9IXC6AI8nrKT9RwsW+Bq0="; }; nativeBuildInputs = [ @@ -96,6 +97,32 @@ stdenv.mkDerivation (finalAttrs: { cmakeFlags = [ (lib.cmakeBool "WANT_GRAPHICSMAGICK" true) ]; + patches = [ + (fetchpatch { + name = "fix-build-with-poppler-26.05.0.patch"; + url = "https://github.com/scribusproject/scribus/commit/14a287fc1db2a44abfe1743260554447b31b4adf.patch"; + hash = "sha256-bhxnyL5zWVCjkfkW67CPykLW/uqDP+n3djnRKGMyhjw="; + }) + (fetchpatch { + # required for the next patch to apply cleanly + url = "https://github.com/scribusproject/scribus/commit/3aed8aa40d01d1affd2b55b107b48878d4b06eab.patch"; + includes = [ "scribus/plugins/import/pdf/importpdf.cpp" ]; + hash = "sha256-tiGXGW8CnG0Tj5YaimngelvNvO3CCSa5eXc3bSKJD54="; + }) + (fetchpatch { + name = "fix-build-with-poppler-26.06.0.patch"; + url = "https://github.com/scribusproject/scribus/commit/2b9405a00a96a09e0183190ddc9f83d44963d4e0.patch"; + hash = "sha256-4v+Ba+JODwNg4YLmwpFeBfIxk1j+RcZdtznPFeQ+H+w="; + }) + ]; + + postPatch = '' + # revert non-whitespace changes made by the second patch, i.e., + # https://github.com/scribusproject/scribus/commit/3aed8aa40d01d1affd2b55b107b48878d4b06eab + substituteInPlace scribus/plugins/import/pdf/importpdf.cpp \ + --replace-fail 'QSizeF()' '"Custom"' + ''; + preFixup = '' qtWrapperArgs+=( --prefix XDG_DATA_DIRS : "${gsettings-desktop-schemas}/share/gsettings-schemas/${gsettings-desktop-schemas.name}" diff --git a/pkgs/by-name/sh/shaarli/package.nix b/pkgs/by-name/sh/shaarli/package.nix index 5af74ae6e02f..bf4b91ac53bc 100644 --- a/pkgs/by-name/sh/shaarli/package.nix +++ b/pkgs/by-name/sh/shaarli/package.nix @@ -2,15 +2,16 @@ lib, stdenv, fetchurl, + unzip, }: stdenv.mkDerivation (finalAttrs: { pname = "shaarli"; - version = "0.16.1"; + version = "0.16.3"; src = fetchurl { - url = "https://github.com/shaarli/Shaarli/releases/download/v${finalAttrs.version}/shaarli-v${finalAttrs.version}-full.tar.gz"; - sha256 = "sha256-SK9J8w8cekxiWBhz/Zp5pOfHgndfEEN5/Kcf6lXJBmA="; + url = "https://github.com/shaarli/Shaarli/releases/download/v${finalAttrs.version}/shaarli-v${finalAttrs.version}-full.zip"; + sha256 = "sha256-qGZ/11NiQLp1Kj2ybDpmnM9YuwMsJbA8r2Juhys2JLQ="; }; outputs = [ @@ -18,6 +19,8 @@ stdenv.mkDerivation (finalAttrs: { "doc" ]; + nativeBuildInputs = [ unzip ]; + patchPhase = '' substituteInPlace index.php \ --replace "new ConfigManager();" "new ConfigManager(getenv('SHAARLI_CONFIG'));" diff --git a/pkgs/by-name/si/signal-cli/deps.json b/pkgs/by-name/si/signal-cli/deps.json new file mode 100644 index 000000000000..7a97697e3831 --- /dev/null +++ b/pkgs/by-name/si/signal-cli/deps.json @@ -0,0 +1,854 @@ +{ + "!comment": "This is a nixpkgs Gradle dependency lockfile. For more details, refer to the Gradle section in the nixpkgs manual.", + "!version": 1, + "https://build-artifacts.signal.org": { + "libraries/maven/org/signal#libsignal-client/0.96.3": { + "jar": "sha256-Z9uYCI4uREB6XguuCv4dkOYzUX8iCZ/pvZYyax5g7e8=", + "module": "sha256-YRfX76VAxM76fJNya4AABAzKemh2fjCZFK+uP8NxIEc=", + "pom": "sha256-zgXDL0gNXa6zF1QyoFdUcAZ44UTTZiv+biEOqhH7gNQ=" + } + }, + "https://plugins.gradle.org/m2": { + "com/github/openjson#openjson/1.0.13": { + "jar": "sha256-fUGEz4kfNZ7nIJWkzhy5zY88Z2Z23+cW6on6tNDm6VM=", + "pom": "sha256-bH6VO09at9+Uppnum6jk7NneKghLcombV2R6I3WJhqg=" + }, + "com/google/code/gson#gson-parent/2.11.0": { + "pom": "sha256-issfO3Km8CaRasBzW62aqwKT1Sftt7NlMn3vE6k2e3o=" + }, + "com/google/code/gson#gson/2.11.0": { + "jar": "sha256-V5KNblpu3rKr03cKj5W6RNzkXzsjt6ncKzCcWBVSp4s=", + "pom": "sha256-wOVHvqmYiI5uJcWIapDnYicryItSdTQ90sBd7Wyi42A=" + }, + "com/google/errorprone#error_prone_annotations/2.27.0": { + "jar": "sha256-JMkjNyxY410LnxagKJKbua7cd1IYZ8J08r0HNd9bofU=", + "pom": "sha256-TKWjXWEjXhZUmsNG0eNFUc3w/ifoSqV+A8vrJV6k5do=" + }, + "com/google/errorprone#error_prone_parent/2.27.0": { + "pom": "sha256-+oGCnQSVWd9pJ/nJpv1rvQn4tQ5tRzaucsgwC2w9dlQ=" + }, + "org/graalvm/buildtools#graalvm-reachability-metadata/1.1.4": { + "jar": "sha256-XpBnpBN2KBw1S0rKAeQca/LdXinwnNHRoxn7Bd/Lz7M=", + "module": "sha256-XJS9cV2yYZwZN7I7Z6LvX0yaP5+0HNyWaFuB0vkbEp4=", + "pom": "sha256-QQggaIBXhhCBLsrE9gAPdGSI+fDM/DS6+F5koXR5aG4=" + }, + "org/graalvm/buildtools#native-gradle-plugin/1.1.4": { + "jar": "sha256-KahlTAhJJSmPoZmli+g5NXitajz/QSwM7Raii6cfSK4=", + "module": "sha256-4I887jCwORt5609RZp0PnHvhxrxd5btp52XmFkFPCaw=", + "pom": "sha256-+xTOUZ1sEzVn/f3wQRxVmxxDSq8QUeMqDETSSi2Ax1o=" + }, + "org/graalvm/buildtools#utils/1.1.4": { + "jar": "sha256-pCd1lX+eRCSKmUOEHbHl5OYr7Qx4Yg6Tvl3UPMlVrdg=", + "module": "sha256-MYABUNF78ObERX4EXTamANDzHh0BRkRegpw9xWzPTOU=", + "pom": "sha256-rt82QOjPhUY4hHVMuUWjzc4J8I2P8sujpdUs9z/ijSY=" + }, + "org/graalvm/buildtools/native#org.graalvm.buildtools.native.gradle.plugin/1.1.4": { + "pom": "sha256-t+b6IIdqZaR/CkU4dt+4Y3SQm3M++ryIqdh/1wL9VcY=" + }, + "org/gradle/kotlin#gradle-kotlin-dsl-plugins/6.5.2": { + "jar": "sha256-O/9KBwDhyBXRlEifB7ugbLGQ6PKbdz03z+43rI1cdkQ=", + "module": "sha256-MVnFQXhFqWmTx4nULexDVwf7uEiXnP0R0LgzBZ5RIKM=", + "pom": "sha256-ctVO1m6jP6+UKCNRwxAZ4S59fpIOpnpRbL4ODWdBA0M=" + }, + "org/gradle/kotlin/kotlin-dsl#org.gradle.kotlin.kotlin-dsl.gradle.plugin/6.5.2": { + "pom": "sha256-5aavF7WFYNdGyrQseV/jpCoevkBQ5VpPANjPVM8x8eo=" + }, + "org/jetbrains#annotations/13.0": { + "jar": "sha256-rOKhDcji1f00kl7KwD5JiLLA+FFlDJS4zvSbob0RFHg=", + "pom": "sha256-llrrK+3/NpgZvd4b96CzuJuCR91pyIuGN112Fju4w5c=" + }, + "org/jetbrains/kotlin#abi-tools-api/2.3.0": { + "jar": "sha256-QBe8wfXTKFsX5rYiDRakaMhxWTDw35Y5bXZLV/Cm02U=", + "pom": "sha256-qJIhRAlxhudUjXFH3I3O1eYOMGnUY1ulUe8uV3WrmAk=" + }, + "org/jetbrains/kotlin#fus-statistics-gradle-plugin/2.3.0": { + "module": "sha256-d8IDSG/XkrWAVyBp5cRC0YDA7wVbpzRQXaKNGX7BL/c=", + "pom": "sha256-k8/rFUWRw3AengQ1C9AF0ZVqmuZHFH1vsqfFeD4fkJo=" + }, + "org/jetbrains/kotlin#fus-statistics-gradle-plugin/2.3.0/gradle813": { + "jar": "sha256-D+cv3G5RvisnSw5kuEQB9SUDavsgYWKkRYIU8R6614c=" + }, + "org/jetbrains/kotlin#kotlin-assignment/2.3.0": { + "module": "sha256-ljRPGdjxnqpbxEHjP2UB9+c9o8el1X1EvHwW6qRXVls=", + "pom": "sha256-GqwiGC0snJVP/8FrV2Xq0jjiAw9HhIctRrxfOcozll0=" + }, + "org/jetbrains/kotlin#kotlin-assignment/2.3.0/gradle813": { + "jar": "sha256-PKIayHkWchdbgnPemV8CTzWZLfAwCijCdUnPd3DMnOY=" + }, + "org/jetbrains/kotlin#kotlin-build-statistics/2.3.0": { + "jar": "sha256-Z3hVlwDnLXZOniTZWPFuwMx152t1s4FMK83hRKYnT04=", + "pom": "sha256-QTkKXrIxFJOxpFubOXLDoL8dqEfoRaNKtoQKr0EmTeI=" + }, + "org/jetbrains/kotlin#kotlin-build-tools-api/2.3.0": { + "jar": "sha256-xsCc8oU0VySfcHyGOCESQJ1aVfULa4Vouk9TDdAD/tw=", + "pom": "sha256-FzTIvg4nFXJ3AkW01gbOW7iBbosNHA9+euEcEMLKF1s=" + }, + "org/jetbrains/kotlin#kotlin-compiler-runner/2.3.0": { + "jar": "sha256-hwl38pYFQ2xesiV7nI5dZPMoLyqI7e5FRNNOxF8Wpqc=", + "pom": "sha256-ov8zZnin9TpEOSv8bFK2gS7dxz5AghyQfyomQWeeDrs=" + }, + "org/jetbrains/kotlin#kotlin-daemon-client/2.3.0": { + "jar": "sha256-sr5naIyvEaE41a4M4SNTga2asN25OVqwb42EagtGYBc=", + "pom": "sha256-teLnTuXC+I/Qi/g+7GRx9rvKeqEhWYgCtsMsVuhwYCY=" + }, + "org/jetbrains/kotlin#kotlin-gradle-plugin-annotations/2.3.0": { + "jar": "sha256-/HKYw2tF820WUscDuraT9f6bEVmOzZrH7J/f6IptsPA=", + "pom": "sha256-aQhDRFhvUkNNH7tRZmlgr/uHbGQ+gIYkXrgLpeREm7U=" + }, + "org/jetbrains/kotlin#kotlin-gradle-plugin-api/2.3.0": { + "module": "sha256-BQ8eECIJAOR6MIkd1c/qg3pl27sNmjyxuFKRq6MmykE=", + "pom": "sha256-GeTwq/tcvwEdJZP1ZRV8jr9FkvMAhhS6LtsEinhRF10=" + }, + "org/jetbrains/kotlin#kotlin-gradle-plugin-api/2.3.0/gradle813": { + "jar": "sha256-yh6tFJqMj0G6YKg5qDsjw6BiJ8RsYhJMUb6ZkDXerDE=" + }, + "org/jetbrains/kotlin#kotlin-gradle-plugin-idea-proto/2.3.0": { + "jar": "sha256-epBQPJ14f5vNLBd25MxSfrneeRLvecbJWPEwWi0cQ7o=", + "pom": "sha256-2bCOHuM4pjRhSanQIY+FHuPUfYu3fWEDJg8qhyauUl4=" + }, + "org/jetbrains/kotlin#kotlin-gradle-plugin-idea/2.3.0": { + "jar": "sha256-lS5zlI4qINOYwmuHprtwzPZkGPuvFSfDUVsYjqnUvWA=", + "module": "sha256-kRUvrqO8DJTbZtPLWKrh2+rXyGC1dk5nsgC01N9M6rk=", + "pom": "sha256-BLSVrgZj7a3aSEBkZKzTlDGjysez6OjAlLdplu1BSaA=" + }, + "org/jetbrains/kotlin#kotlin-gradle-plugin/2.3.0": { + "module": "sha256-vbMts6ongF80eewDPsY9PMq+sTuInYbavadCu+9TwJo=", + "pom": "sha256-h4cnvyGoOtrYnU5giEhN2/OfaoSpQoAiGm4cL4hBMD4=" + }, + "org/jetbrains/kotlin#kotlin-gradle-plugin/2.3.0/gradle813": { + "jar": "sha256-Os+X1zolgbAyhz+on1Z1DTazt21A1pLZg58kZ92uTWk=" + }, + "org/jetbrains/kotlin#kotlin-gradle-plugins-bom/2.3.0": { + "module": "sha256-/9anNzSypS+3Yz8WOVRL43HgYpxR2X+h5fteqTQ6Fwk=", + "pom": "sha256-cYYJKmnzaIQyxcCsuQtKZx/Y7oANhP5YT66P1TO6v4o=" + }, + "org/jetbrains/kotlin#kotlin-klib-commonizer-api/2.3.0": { + "jar": "sha256-m6V9kaveq5rNWIoUtfQiCbmWRMU0Ft/56X7LS/l/Ukg=", + "pom": "sha256-zTHw7NqCplEi/8alXehxE5S2GEtRRAK34RkZGqgJGoI=" + }, + "org/jetbrains/kotlin#kotlin-native-utils/2.3.0": { + "jar": "sha256-7kvygz0Q5fN90haoMSn1nzx8vvXrrBMPcGZIOXCMgLc=", + "pom": "sha256-Rp6PYB/b34kP+ozXSOEQcCqkUxu7KbZOXnUD8O/lDZA=" + }, + "org/jetbrains/kotlin#kotlin-sam-with-receiver/2.3.0": { + "module": "sha256-DCD2gdNvSnmRYiFYCYkpF5TmVlgvlJwGed+kNKAm9so=", + "pom": "sha256-DILmEXpGNhvUzF5iZV8rgC8Q9LfZJWpjaD0DSv0MDUM=" + }, + "org/jetbrains/kotlin#kotlin-sam-with-receiver/2.3.0/gradle813": { + "jar": "sha256-r8iTlKUrUu8Lp6gpakJi0NOoo850CRXYfXE7CgFhMpg=" + }, + "org/jetbrains/kotlin#kotlin-stdlib/2.3.0": { + "jar": "sha256-iHWHyRcTJQrVL+FK2RZtBCwzg1BJiQ6UN/NV/8WhlbE=", + "module": "sha256-CRCoo7aWD8eSxFxWqR18Oj8mKG8DKVVUtRnP83h1baI=", + "pom": "sha256-TVJW0+SETmVrDKQF9jUNbyF5XCQ3WzRSUmxUZ92ZtaI=" + }, + "org/jetbrains/kotlin#kotlin-tooling-core/2.3.0": { + "jar": "sha256-NnFCeBKZvA+RIMHe7A5ik0oa+ep/AaqpxaU1TcXY19k=", + "pom": "sha256-tQ6FtLEYwSIjge0c67K6lqfeLdrtti3aZ9SuBqGiXTc=" + }, + "org/jetbrains/kotlin#kotlin-util-io/2.3.0": { + "jar": "sha256-HJEgPyfnO5aI3f4aiAIyjTXrcPpV9eE96ttyHnj5KqQ=", + "pom": "sha256-hvmuNH2YfMwY2aEJ7tLlVDvjj/SMgdUtKMf6HyBarK8=" + }, + "org/jetbrains/kotlin#kotlin-util-klib-metadata/2.3.0": { + "jar": "sha256-JZjCbDTMXGnrAEc0Y+lQrmfpuAln9DoBg8Vn7eZqlxc=", + "pom": "sha256-4EB9YmkdWjQWFh/YNztNt0o714bxtILghGGXUQL58+s=" + }, + "org/jetbrains/kotlin#kotlin-util-klib/2.3.0": { + "jar": "sha256-ZLugCZZqAoGG2e5waw3ID+phwK5usXJe0dfXDvIrUuE=", + "pom": "sha256-lzWjPLZJg7qg0S3AyOGTSw5VLmvMh2chrFWKmCKFC/4=" + }, + "org/jetbrains/kotlinx#kotlinx-coroutines-bom/1.8.0": { + "pom": "sha256-Ejnp2+E5fNWXE0KVayURvDrOe2QYQuQ3KgiNz6i5rVU=" + }, + "org/jetbrains/kotlinx#kotlinx-coroutines-core-jvm/1.8.0": { + "jar": "sha256-mGCQahk3SQv187BtLw4Q70UeZblbJp8i2vaKPR9QZcU=", + "module": "sha256-/2oi2kAECTh1HbCuIRd+dlF9vxJqdnlvVCZye/dsEig=", + "pom": "sha256-pWM6vVNGfOuRYi2B8umCCAh3FF4LduG3V4hxVDSIXQs=" + } + }, + "https://repo.maven.apache.org/maven2": { + "ch/qos/logback#logback-classic/1.5.32": { + "jar": "sha256-LUz1ktt4vi3k1hQENML+wXDcsWoJ6Mi3sgfb9eMbhIo=", + "pom": "sha256-0jsnLnBXYPg1cRB2RB5qipsS7QkA4bphigzWvPehYmo=" + }, + "ch/qos/logback#logback-core/1.5.32": { + "jar": "sha256-apBNV3jQ42GpaS+cvmixsGIK4PPtouwu0JECdVvwNsQ=", + "pom": "sha256-Hzk8RBRFhWm1O1LrMpe/6GGwAGb1nW0rq/In62XaP7g=" + }, + "ch/qos/logback#logback-parent/1.5.32": { + "pom": "sha256-Cyy+YG4Jm4sADCr14AeTb7OVXQzl5rsIbamyPUjFa6w=" + }, + "com/fasterxml#oss-parent/70": { + "pom": "sha256-JsqO1vgsnS7XzTIpgQW7ZcD52JnbYXV6CXQVhvqTpjk=" + }, + "com/fasterxml#oss-parent/75": { + "pom": "sha256-/LvxwYyQR+aRfThPIGTiG0Klj8hfsFI6ni4BXv98YZ0=" + }, + "com/fasterxml#oss-parent/79": { + "pom": "sha256-kga33Wf7E4A2V2w9/KlHoqjz4sTS2cHy0d6lGbOk2uE=" + }, + "com/fasterxml/jackson#jackson-base/2.20.2": { + "pom": "sha256-2h3M8cF7Sx/XPEiKaRH93ekBcrRvgbbdbUchrAgzDfQ=" + }, + "com/fasterxml/jackson#jackson-base/2.21.5": { + "pom": "sha256-T04r6gD/5XX17AVMB6T7w0wZVdhjXAGj6IATvyxx3v8=" + }, + "com/fasterxml/jackson#jackson-bom/2.20.2": { + "pom": "sha256-izQ6yh3LT3KLlMxzgxmYMOPTorDQdzQ3h+7iIAkYtB4=" + }, + "com/fasterxml/jackson#jackson-bom/2.21.5": { + "pom": "sha256-V/4i3sZZ3gZVNX+tBYLvfIsv5aiQam8f8by70eRVSEY=" + }, + "com/fasterxml/jackson#jackson-parent/2.20": { + "pom": "sha256-tDt/XGLoaxZPrnCuF9aRHF22B5mvAQVzYK/aguSEW+U=" + }, + "com/fasterxml/jackson#jackson-parent/2.21": { + "pom": "sha256-OFHfYn+utGiHuVYQRjC3Sou7X33iLpdM8VmC4g4Dc94=" + }, + "com/fasterxml/jackson/core#jackson-annotations/2.21": { + "jar": "sha256-U8oIX0oVD3A/SeGqvZNb0DtD4eo9VdE1Q4KSryLO9Ws=", + "module": "sha256-yuj/7OwzKLbsuxOOJ0IY8v4cdymg6CTaVZJogQCVrUQ=", + "pom": "sha256-ccrFOSFR4qUozJoJF58KM0F58FxS+OWWz1jd8Suyfys=" + }, + "com/fasterxml/jackson/core#jackson-core/2.21.5": { + "jar": "sha256-tktYdBYrUDoOWKj3dYJm6N2fkb9J46Wa4LX0dYmiMbc=", + "module": "sha256-3hE/RTHe9Q/rEr4E5wdKj3b18+8pDPiGuQCGpOJ0Uw8=", + "pom": "sha256-N2IPWbeJFti+VjAcczhNFdVFwOIXQxvG0Seo2IDfQH0=" + }, + "com/fasterxml/jackson/core#jackson-databind/2.21.5": { + "jar": "sha256-UHQYwPr9OLKyz7cEUhYw2mE6jkzIOBGVpvQYAXiD4sA=", + "module": "sha256-kg4qAhGjH1TS5+Tv/cWA0Cw0Eqb+/bYyqAVOYMR1g4E=", + "pom": "sha256-cu7sNq3UbNfRhf7YkmXNuXp/wFzzQTzipZRA7+GCOhI=" + }, + "com/fasterxml/jackson/module#jackson-module-kotlin/2.20.2": { + "module": "sha256-Vanis/UbE12fJ1AW8Sw+LgXpvJU0HK6xm0OdwgiQLeU=", + "pom": "sha256-AMlp5rd3mENZlpq8S/xARCK4i5DNq9HAcxgcY/mJvaE=" + }, + "com/fasterxml/jackson/module#jackson-module-kotlin/2.21.5": { + "jar": "sha256-b0W75DRFjSrR9eoWxqv2fnq+o3Syya5Wic9N0nwWyLk=", + "module": "sha256-Gp94BEdljdtH7J19zGCXmqsqWyXw6QKUaFPdKSvYhYE=", + "pom": "sha256-IYgSf4943/3K9k2pWd1VHksQeFrMFH7zPs8Upnnwp4w=" + }, + "com/github/hypfvieh#dbus-java-core/5.0.0": { + "jar": "sha256-rZddGhfTd43evWMePZ1TNylKqRW8Zf3m6Qh9kHKbu0U=", + "pom": "sha256-kZVCUw1wZlye6aHC1WawY+UG8HX4PKS2WdJzgtRqmCw=" + }, + "com/github/hypfvieh#dbus-java-parent/5.0.0": { + "pom": "sha256-JOztFYLZsqw/LEJOicGjOVFfeVDboq1g332ROxm1Sp8=" + }, + "com/github/hypfvieh#dbus-java-transport-native-unixsocket/5.0.0": { + "jar": "sha256-73CHSWg0ATmnCQO9CL+m5OzrnoEd+Jp4psixZAYS4Gc=", + "pom": "sha256-1Zlx25oLNZhsn5NsEWw36LDGAnKVVzxylFuMlmhQcGA=" + }, + "com/github/javaparser#javaparser-core/3.28.0": { + "jar": "sha256-04UteEYcAmAuub/BXp/CGtfHZeYBOhttWAml0OfbUwk=", + "pom": "sha256-AT3fG+ys6FufJLgMmS7rbxAh+3V7cL/DTR7DfXhMLXc=" + }, + "com/github/javaparser#javaparser-parent/3.28.0": { + "pom": "sha256-+VPXzvj60JpPGaC/ZedxYZK0gm9yV8E5NDpolMyadaI=" + }, + "com/github/javaparser#javaparser-symbol-solver-core/3.28.0": { + "jar": "sha256-972ddcZpd9iIiFH3XcAxOXJ05z+W5TUkcu3UzTpWp5A=", + "pom": "sha256-4BVvMJm4gti9fjIKfcdET6b/RxDX5z8VATjAKn34xrU=" + }, + "com/github/turasa#core-network/2.15.3_unofficial_149": { + "jar": "sha256-GVPQRIGhzTYHRqEcaJXSARmNG2dwK7c+jZ8sEiNmSYM=", + "module": "sha256-3IoBIylLsNuZ3gQBfDOJLAjw//nJNdWuAkeBg+4DPus=", + "pom": "sha256-T3cziZ6ojUK0il3be2EtOOR9DU8oMo82ShskFwSY+WE=" + }, + "com/github/turasa#models-jvm/2.15.3_unofficial_149": { + "jar": "sha256-yV3+jIv1k0OgOZC6aaNpyyCHky+9SjkFCkOzNyd59Sk=", + "module": "sha256-+RfD6IfyqLwwx4yiC3vPKvIOiFxVJ2dMHopXGCjEemo=", + "pom": "sha256-nAda2RUTEPd4TpPCycdR/yurrgzRMti2nJLYUnx1luU=" + }, + "com/github/turasa#serialization/2.15.3_unofficial_149": { + "jar": "sha256-5VYS8h0X+L1msDFGToRfe3QysgDk/28ybOHiPvOLpSM=", + "module": "sha256-LZ++GNTTVHtkSQU+F1Yh74aWiDfxu4hX0BACHV/pfbU=", + "pom": "sha256-+6K9tLA0ZipVh4S2X2m3qzs8Mr52q4hr/FBqwwcZO3k=" + }, + "com/github/turasa#signal-network/2.15.3_unofficial_149": { + "jar": "sha256-iyDpWzrUxD9kCjvy9VaiY8ke4KpvEmcVvLbSowF9rrE=", + "module": "sha256-eac61/Ch79ZmYlUGEmIOp5hiQmyeZ374skjFi0ePiGQ=", + "pom": "sha256-lFMmHnKp5HNFchDoNPxMS9Rsm0CSSaiocNq3u2hKlIA=" + }, + "com/github/turasa#signal-service-java/2.15.3_unofficial_149": { + "jar": "sha256-QvbDo11PUhrjNSCtKUQqVY09E6GeYpu6WilT+sZ9L/U=", + "module": "sha256-2zEraXZG7IwGUZrXewbCSjyqzfbX6fKWByaIt4zF4rw=", + "pom": "sha256-OgvLg26yJT3roGS7C4drZtWsUAxsMPuwzKSQ11wmc8Q=" + }, + "com/github/turasa#util-jvm/2.15.3_unofficial_149": { + "jar": "sha256-HTaxo8hwGL2Fs9lArKYyRwvwIVlbyulA/ZGWw04Muyk=", + "module": "sha256-8w78BIIXxZ8DXn/c+KzjD3BDltmozX/HIywBS6dg+iA=", + "pom": "sha256-IKLxLIQGAFLIj7Y95zkE2+Kc9Ve/NZlO5My/dMFNhFo=" + }, + "com/google/code/findbugs#jsr305/3.0.2": { + "jar": "sha256-dmrSoHg/JoeWLIrXTO7MOKKLn3Ki0IXuQ4t4E+ko0Mc=", + "pom": "sha256-GYidvfGyVLJgGl7mRbgUepdGRIgil2hMeYr+XWPXjf4=" + }, + "com/google/zxing#core/3.5.4": { + "jar": "sha256-cd5diTQbX89d2J2n9E6E2CXQ4ITN8+x3yaviaw8M6xM=", + "pom": "sha256-UCxzaK6GnxVCjAIKJDLuyd3nQ2RU8+3RgW4NSz0GCb8=" + }, + "com/google/zxing#zxing-parent/3.5.4": { + "pom": "sha256-kTPzIthhAcXEeMCOo9ZzTcN2Qjk33asaoqBqriT8hck=" + }, + "com/googlecode/libphonenumber#libphonenumber-parent/9.0.29": { + "pom": "sha256-amuQI9baLP2WrZ0ugPWmkOfNDMHMYbWHMiUQyvnovRY=" + }, + "com/googlecode/libphonenumber#libphonenumber/9.0.29": { + "jar": "sha256-iXojv+gJRWucprYCUCVyqEtJvllmyx/YTlzwYaQc8T8=", + "pom": "sha256-4qEa8ABS0pGPgasf+JwEGZFZeDfK4gwJ1eTfn0Hrzwo=" + }, + "com/squareup/okhttp3#okhttp-jvm/5.3.2": { + "jar": "sha256-x3H0gHW3Y/bDIgVeIRKalLfeTB+vP49YrOMgsMlRejA=", + "module": "sha256-ORMM9gZSgNkN4ugnNQwxcLtV6y9INcK0QW87g7Hxq4U=", + "pom": "sha256-ruhxl7v7LXQktiQdMA6wy/+xhEycqwEpyuU5BAizP6Q=" + }, + "com/squareup/okhttp3#okhttp/5.3.2": { + "module": "sha256-C3d0IDpza10i/EW1IuySe74skEh91YZbZOV+AGBeRxE=", + "pom": "sha256-+Uc3LE3YSPdSrvaDfRUXRhxETB1Dr1rrFebyvXN7sHI=" + }, + "com/squareup/okio#okio-jvm/3.17.0": { + "jar": "sha256-OxPcw+FXMEfC1Qf8T3/LC7DLzZ05XaIdIOCUBuLNanM=", + "module": "sha256-1GF9DfcfIC5ymUcYSOYl9PNtf6ZNRsNQP3Cs9IIaRd4=", + "pom": "sha256-5ORCN6ZvQJG8D1sdWiu+IorAFKs8D5GM1vwCujGZkDA=" + }, + "com/squareup/okio#okio/3.17.0": { + "module": "sha256-PYeNuf/U6VnDD5qDZqiMItAB6bMkN419vu2YVo5+xVk=", + "pom": "sha256-FbSDHoT1ylLdN8HW4XCaKQfi6bwqnD6hPyggMd4MATU=" + }, + "com/squareup/wire#wire-runtime-jvm/6.0.0-alpha02": { + "jar": "sha256-dQqiqsnpI7Y4i1f+zFPFJtEO/uhoOVrH8VzLuV94FSA=", + "module": "sha256-mLRXK8G/PDEj5lOHxkYpr1BeQQeJdtZygo71l5cJlAw=", + "pom": "sha256-fWuyHez24oAAzN6RTj6AJ+Sa4MNuTZrbsgcDqxKugaA=" + }, + "com/squareup/wire#wire-runtime/6.0.0-alpha02": { + "module": "sha256-EgFXlZrcntramsxPM2l+3FUoDqZ3MTGKuus7MJRoGzo=", + "pom": "sha256-JxFKk5Op37EvYvU/Pb9CRUe4ddIvz1peKmkOj0LWXZ8=" + }, + "com/zaxxer#HikariCP/7.0.2": { + "jar": "sha256-8eYS+ic0W+MQeoVDHoqK6yBcFTZKsvLUEeQKnXuwgJU=", + "pom": "sha256-ZiqH+ASHvom9dyliE+kRCP+fAe0NmpD5pOISY8xJ5z4=" + }, + "io/arrow-kt#arrow-annotations-jvm/2.2.2.1": { + "jar": "sha256-V55raRj6s6LOT+e3LXCv3vccQJfvB1yk/F2wMpc7kEA=", + "module": "sha256-EsNzuLIrQ7fnnLPyF7/WtvHM9B7lvS51z7prFEDK9HQ=", + "pom": "sha256-4vrKrahBDAmKID58t5iVMXRhN5dw/j3znaOfFcgH9ys=" + }, + "io/arrow-kt#arrow-annotations/2.2.2.1": { + "module": "sha256-0JQTXNuiLXTe4MctHeaFAHjrzlCCmMvfSj6dN6eJjZQ=", + "pom": "sha256-G7/oX7mOYOsZBHor/xK+VzWdyia3va0URotWtsvFTtM=" + }, + "io/arrow-kt#arrow-atomic-jvm/2.2.2.1": { + "jar": "sha256-S9oD1SinT/drIVSHr6s2HvkDjeX+9mnen3XjN/Y9l44=", + "module": "sha256-yN3jFWY3MIV8nDOkSQLqMm4TbXZE3VHLHwnE+zTCv2w=", + "pom": "sha256-F8C1h2O9LCPGGOM/MF9fJOG+pSj1CvaOgtEGSuywMaM=" + }, + "io/arrow-kt#arrow-atomic/2.2.2.1": { + "module": "sha256-kVHMV4FDxDU/1F+gbny9LvmXyHzpLFuTkXGBiotywuk=", + "pom": "sha256-LxSQL/12IrFe9NZD7rocf+V6LrjMATkU5tFna6B9krU=" + }, + "io/arrow-kt#arrow-core-jvm/2.2.2.1": { + "jar": "sha256-DH+vrBdQj1xQVxt7dzAniFLpKPCQaIOTbnB9RSCktVc=", + "module": "sha256-MXX0GfC1fcHdMdSESI+31w+wimKNPvbDrC+1sXe71Yg=", + "pom": "sha256-AN4Y0ehHJsrEJsfDFoX5JVwOtvyD0bCZDB56Z0ImNX0=" + }, + "io/arrow-kt#arrow-core/2.2.2.1": { + "module": "sha256-hktiARNmym+gj0Qcrse0T9lGwx8cCeqzScYMTlAC4BU=", + "pom": "sha256-8HTTq1WSVo4wjPUF/K4ykjGQNIioSmZM95Hs71s6Olw=" + }, + "io/arrow-kt#arrow-exception-utils-jvm/2.2.2.1": { + "jar": "sha256-vVm56Lk+MAa7LIhJvTkjjg6VWf0sBTJniYNkTlb/rRY=", + "module": "sha256-OY6xnMIycagVqT84kE2sheosnhAVOtzhqN4khWaZFSQ=", + "pom": "sha256-ehnPK3/gbvdI8U1xfD2BUFjlwoeHMf+JHnGOI9E4mLA=" + }, + "io/arrow-kt#arrow-exception-utils/2.2.2.1": { + "module": "sha256-r62Oft9NktlM2UgFTzLjR7u5iX9p7rL2aaU4vkHfjIc=", + "pom": "sha256-Aot7flSQbazNShygcX9VJ7OO7PVwkYcvomNtOalY/yE=" + }, + "io/micronaut#micronaut-aop/5.0.0": { + "jar": "sha256-1IzQri+poyz77boKoSzuygoXI7GGzVE5UeX/Nmt2lmk=", + "module": "sha256-UoO3liL6GYHoec6A6937z/xHmZWRWZY7UHf45EazHXU=", + "pom": "sha256-l0ih0nvmMHw+kazEmB96S+UtaoxJ8lGamjXckvfOARA=" + }, + "io/micronaut#micronaut-context-propagation/5.0.0": { + "jar": "sha256-Fh6+vyyQxAjPD+qL2yxNXd3jjL7Kx5zRuX3eU0lm1Qk=", + "module": "sha256-YVViXEtE1qvG3azt4PILdHS372XEFZk6MIJbb3088MU=", + "pom": "sha256-QOgRBRIyl5nFsY8tbpL/FbymyTIhnMRw5FNMIGH4LgI=" + }, + "io/micronaut#micronaut-context/5.0.0": { + "jar": "sha256-F6tD1MvBRoHQ9KX7COFbcVk+gC5DoaPybvieomIFERI=", + "module": "sha256-TGi4p/arx2dAyxt4TGN//UHxt6KSCKHSluVBX+BHDhI=", + "pom": "sha256-TY+USvABnVHO8hPqcqEjBF/vFbAWMs7kjlwmPLcuXkc=" + }, + "io/micronaut#micronaut-core-bom/5.0.0": { + "module": "sha256-ZaTaCACq3qfCp42ZpWmjjSrkZWt1mdwYhGvyoCEGYwo=", + "pom": "sha256-sZ8bWNiQf3lbEi9S8jnthA1GZVgh9dtiT3F7iQSfm70=" + }, + "io/micronaut#micronaut-core-bom/5.0.0-RC1": { + "module": "sha256-PpKFzu+hS8HPJp9k+fD0/GngN8OyMPusodTos0yi+pE=", + "pom": "sha256-FxjMY4S4zJmcrS0Pjv/qPx/0KHSKo0e8xRMCPWdS8Mg=" + }, + "io/micronaut#micronaut-core-processor/5.0.0": { + "jar": "sha256-ikm1QvGGDiCjbt95t4Oij4UQCp754vqUSPPXBsnE/yc=", + "module": "sha256-baLQMKEuvEgLHX21IVzWtZxDBswQQGnAYMIYT1vF8kY=", + "pom": "sha256-lhqE5V14AUcpcixdJ/wxYUvoWtG2ZLSNKHB05gitLLU=" + }, + "io/micronaut#micronaut-core-reactive/5.0.0": { + "jar": "sha256-AqMv4g1+4d/doW55UKTYTWiZfphmmqrA44mETBafXx8=", + "module": "sha256-JHzevL2AVrzkAI3czC/2UHOJw5UsHRDuZrPo/vVRK3E=", + "pom": "sha256-nRC1eUw0tQF21wsskU4+6v6PE87MmhtSrZOb8K2RIsY=" + }, + "io/micronaut#micronaut-core/5.0.0": { + "jar": "sha256-5xKb3Frw/k2ClPq0lM3rRX0VroSc6zlJlM+zD4iCtOs=", + "module": "sha256-w2IS6kOlI46vrqCTnP1sqF9r8i+nOI00TifMOlHY/xE=", + "pom": "sha256-jp06Z2Bg4fPJbiIz/6CMX2zw3ack+H2fxapMWEM8FgU=" + }, + "io/micronaut#micronaut-http/5.0.0": { + "jar": "sha256-3XUR+VYxn0UdxdpNsxmjPVImY1Avwfq4JeTtRz+hoaY=", + "module": "sha256-acAJ9pJKPMzuqF8S/0Jd5f1r88b/wGEHBlxdPqct8m0=", + "pom": "sha256-nTdqfBovQB+ZWX2bpw1Q5FoaP36lmQths682XxMKaQw=" + }, + "io/micronaut#micronaut-inject-java/5.0.0": { + "jar": "sha256-T/BNemK+KI7Q0DJvm0WnU0Z6gw3mEXFzoh3B5HgDTwc=", + "module": "sha256-kpdhseDPlVAMUlKNwdwvh17Z24RJK8wnvggb/JcZbWY=", + "pom": "sha256-UM0aEc18zGc7/EwEyFO1CfF5/fuyQHcrhkSWyS3UHK0=" + }, + "io/micronaut#micronaut-inject/5.0.0": { + "jar": "sha256-sck0Ih0qONTmWeLQyFTTdFYs6gMaJvwIajvQxQbGm3A=", + "module": "sha256-s/I5lQe6yddKj7K7ehRdz/7fdqfxzndCx0KpUnozhts=", + "pom": "sha256-hQhx/DtuFrxyUpuLEI8zFBxXoO79kj+GelpZYDl8IUQ=" + }, + "io/micronaut/jsonschema#micronaut-json-schema-annotations/2.0.1": { + "jar": "sha256-iHr1JUEAn0TBXA+/Y+IWlJzFB/Z7EX4ZvgQevzbrYr0=", + "module": "sha256-sLfhN3AbOOvudZBT1I67rnenvmdv8qRl8kRyRqS5TFo=", + "pom": "sha256-R8WgFumUPxCnODGyUzcvcDw3D8G+mgfp8BUsUbYKxdo=" + }, + "io/micronaut/jsonschema#micronaut-json-schema-common/2.0.1": { + "jar": "sha256-XUU+z22WKL4ahisvPC4fKnDmw2KgycQD0ykDKeUV3wA=", + "module": "sha256-llEIwNin5eMP5wi4Jb5LyfHO3mmTRg5rTTrXN74ZhR4=", + "pom": "sha256-3Wk8HTaHrtVVOBMOBhSvDTkySr/09A9UYE27ZxttpuI=" + }, + "io/micronaut/jsonschema#micronaut-json-schema-processor/2.0.1": { + "jar": "sha256-om9wJdkAhO5yUawNKEB5zLLuGMY7ypEIgyX+7UfLlIo=", + "module": "sha256-oeHlFZPMINo8ntAHVwpJ/hlMQ5ssElM2IWUXzY1Z5aY=", + "pom": "sha256-cgIW2IbOMcXVxTGbDVWdHu2hsJJL/gbrmLC4kijC9PI=" + }, + "io/micronaut/sourcegen#micronaut-sourcegen-bom/2.0.0-M2": { + "module": "sha256-HCzSFvbWP1fpc2gw+VmCIV1CDnWua29rmyimztj+loY=", + "pom": "sha256-VGVSbOR2mapYr/sSCIJ4UPTVODdCzRZ1eBmcdSWYiB4=" + }, + "io/micronaut/sourcegen#micronaut-sourcegen-bom/2.0.0-RC4": { + "module": "sha256-VgAwFTmtRjcLDmwI1VomKQAf2fat+yP+xdfTZBPlSD4=", + "pom": "sha256-Vv4MtBOkrsH4lmFlX+H+4NqoucTvt3jDFFJwBo4V+Es=" + }, + "io/micronaut/sourcegen#micronaut-sourcegen-bytecode-writer/2.0.0-RC4": { + "jar": "sha256-Y7kV1I8d5/95gM1FcCMnq/2h3qrJsKsrUkagID+MeQg=", + "module": "sha256-nqSNgTeJ5c7IcY4nCzpKbI5jbfbJ7f2NvzyMSYUoXGc=", + "pom": "sha256-oOq+O5elro2dCbwMkoXWY1Y6JJbRI1gTpjpF3a/Nnfs=" + }, + "io/micronaut/sourcegen#micronaut-sourcegen-model/2.0.0-RC4": { + "jar": "sha256-nDStr46JhllSxi6+AT7neHejQX8aB6IylIs3KMvTO9o=", + "module": "sha256-abwSJXZKzWjNKNiSrPyNiz/Pzjq+qFmkfmBJREUNMUs=", + "pom": "sha256-6Fy2wtY1KbwTw1u1JEsPNFgWLjfamBidubkwuisYdwQ=" + }, + "io/netty#netty-bom/4.2.12.Final": { + "pom": "sha256-Sx6sh5HJMaM9ni+4wINDJVLPh0adtBm30kNBeONPBww=" + }, + "io/netty#netty-bom/4.2.13.Final": { + "pom": "sha256-Ua8kiRxINeMj5A2UFn+S5VdF50mA3VzogSX4xDvu7sQ=" + }, + "io/projectreactor#reactor-core/3.7.12": { + "jar": "sha256-R0+Uyr5f2oh3FHUh83x5HJXva0qd1Z5Ymm3cwhsNjjk=", + "module": "sha256-ih9ZHRPYKCVKZ74MYP2RUM/peChuHD/gyjJtj0zt43Y=", + "pom": "sha256-3bsLjzNnW6WK33ko9yLVlDz245K1hKViWmNe6gHzrjI=" + }, + "io/reactivex/rxjava3#rxjava/3.1.12": { + "jar": "sha256-GAikM+9V3MKWVSPlEquRSl0NcnIoomg+11WdfMz0Tjc=", + "module": "sha256-2jn02k/u133+ELmAnVyysvO0Ra6nG2nhUjKkJpiThzs=", + "pom": "sha256-chJrr7gKEse1WFJNCRkj5pYSODxHQay34Aw1ybBUazQ=" + }, + "io/reactivex/rxjava3#rxkotlin/3.0.1": { + "jar": "sha256-wULjRgtnasUdngQVIXOkTkaalf4iAmT94Ob7OGU6/2Q=", + "pom": "sha256-KP1OBbCB8DwkCRBhAD7uHNuKdwQwgB7bYzyk3DFAZz0=" + }, + "jakarta/annotation#jakarta.annotation-api/2.1.1": { + "jar": "sha256-X2X9r0JO7itV4diCupuzdr6T+wmze4CL5uIuiFHJCf4=", + "pom": "sha256-r2UOyh3huYdBAGrNglB+RAjP/t0v7jOg6kY9YVCNt+w=" + }, + "jakarta/inject#jakarta.inject-api/2.0.1": { + "jar": "sha256-99yYBi/M8UEmq7dRtk+rEsMSVm6MvchINZi//OqTr3w=", + "pom": "sha256-5/1yMuljB6V1sklMk2fWjPQ+yYJEqs48zCPhdz/6b9o=" + }, + "net/sourceforge/argparse4j#argparse4j-root/0.9.0": { + "pom": "sha256-DI3Upx1v56PEi8TZZZSOEiYNIe1ld+6lnINZ7UTQqq0=" + }, + "net/sourceforge/argparse4j#argparse4j/0.9.0": { + "jar": "sha256-nrO1QEMDi8ERvw4VqPaYlSRPkuPCvCgAFYV4ynEfYRc=", + "pom": "sha256-Kq9zGx348ZhSWMUgKnwcBhfw6ScVs11c1ILBgKq7BLU=" + }, + "org/apache/groovy#groovy-bom/5.0.4": { + "module": "sha256-HslyzxmAv/g2b6bW0VPimiE7b2Vs6DHIZtKu0kZzcrQ=", + "pom": "sha256-9OFcmq8LR4OcfogcpOo/MFWk1Am/9CFx0C/IMRD9zts=" + }, + "org/apache/groovy#groovy-bom/5.0.6": { + "module": "sha256-WvAjs4vXBXsmj4en1c3XQnv4qOKVwzTKn5N8AbcsOdA=", + "pom": "sha256-rV1LU+Fh5lN6/lfclqZgjLNols+3M8qpl+m+KNWatU4=" + }, + "org/apiguardian#apiguardian-api/1.1.2": { + "jar": "sha256-tQlEisUG1gcxnxglN/CzXXEAdYLsdBgyofER5bW3Czg=", + "module": "sha256-4IAoExN1s1fR0oc06aT7QhbahLJAZByz7358fWKCI/w=", + "pom": "sha256-MjVQgdEJCVw9XTdNWkO09MG3XVSemD71ByPidy5TAqA=" + }, + "org/bouncycastle#bcprov-jdk18on/1.84": { + "jar": "sha256-ZNbFphIfzZJxUt0YLL7Tmv4P2mQalw2bzAycsYWLJzE=", + "pom": "sha256-znq7SpG6XSpz/fF6PfR2LjYFoDksx5g+8vGuFs04TMM=" + }, + "org/checkerframework#checker-qual/3.53.0": { + "jar": "sha256-fKACgV2S+teelms3XC7nsrS/lTAkvJpdXgxZ3xP/Wvg=", + "module": "sha256-EZ1p1BNJeDzB69OSskth1vOAhgFHqAsohbj3/KOrE78=", + "pom": "sha256-+V5qT1/V1tXFLK7Z5kup0mpYq3H2VxLrq03qtPR46Mg=" + }, + "org/eclipse/ee4j#project/1.0.6": { + "pom": "sha256-Tn2DKdjafc8wd52CQkG+FF8nEIky9aWiTrkHZ3vI1y0=" + }, + "org/eclipse/ee4j#project/1.0.7": { + "pom": "sha256-IFwDmkLLrjVW776wSkg+s6PPlVC9db+EJg3I8oIY8QU=" + }, + "org/graalvm/buildtools#junit-platform-native/1.1.4": { + "jar": "sha256-awt9Zk7WMDhj4kgUEWWMZEuwRNqKypkWAPNjIZW9U2A=", + "module": "sha256-1cQqHZkROq4o/V8T9pRZAcaK493smv35dbZmU92iSYk=", + "pom": "sha256-lZyCqHco7Hxe4I/Co5dBfN34LmCO/rnjMoriPPWKNhI=" + }, + "org/jetbrains#annotations/13.0": { + "jar": "sha256-rOKhDcji1f00kl7KwD5JiLLA+FFlDJS4zvSbob0RFHg=", + "pom": "sha256-llrrK+3/NpgZvd4b96CzuJuCR91pyIuGN112Fju4w5c=" + }, + "org/jetbrains#annotations/23.0.0": { + "jar": "sha256-ew8ZckCCy/y8ZuWr6iubySzwih6hHhkZM+1DgB6zzQU=", + "pom": "sha256-yUkPZVEyMo3yz7z990P1P8ORbWwdEENxdabKbjpndxw=" + }, + "org/jetbrains/kotlin#kotlin-assignment-compiler-plugin-embeddable/2.3.0": { + "jar": "sha256-1D+qszfzaY6NrOZSXSzXwq66ewNZOEhYZBZP5wLnM70=", + "pom": "sha256-UttpIUdRA18/LYUvJDCC5x566wenFs2eCHskuYJ6Uio=" + }, + "org/jetbrains/kotlin#kotlin-bom/2.3.20": { + "pom": "sha256-/Xh6DvTZY/qdKlGniMoyLNO3F8sDrPnZ5BlNZ21cwS8=" + }, + "org/jetbrains/kotlin#kotlin-bom/2.3.21": { + "pom": "sha256-lQcEutBMUUNlbPyh0sV08l/K2crDOQWrIqV+n997/Yg=" + }, + "org/jetbrains/kotlin#kotlin-build-tools-api/2.3.0": { + "jar": "sha256-xsCc8oU0VySfcHyGOCESQJ1aVfULa4Vouk9TDdAD/tw=", + "pom": "sha256-FzTIvg4nFXJ3AkW01gbOW7iBbosNHA9+euEcEMLKF1s=" + }, + "org/jetbrains/kotlin#kotlin-build-tools-compat/2.3.0": { + "jar": "sha256-AJST4crwTIKF8f7RV7uraINV2wTS3q7E9aD5tjX4ZuU=", + "pom": "sha256-ayMWTiKBY/1j+Bf7LF3ifW6cNAO3Y8y6BoBYTyF/jjI=" + }, + "org/jetbrains/kotlin#kotlin-build-tools-impl/2.3.0": { + "jar": "sha256-k6Xo/7EACAHIMqhisjvZdm9ETm9sGFwysftXh3+1zqM=", + "pom": "sha256-AKelPNgr5ws234oCI6Wrhhoqb/txnZt3M3XId8idugQ=" + }, + "org/jetbrains/kotlin#kotlin-compiler-embeddable/2.3.0": { + "jar": "sha256-jb2IL6WMPRfmg6JzkCiDFfi0kPjj47G+TcPigNN+KFo=", + "pom": "sha256-zOmxEfIRZgxcRTk+dI30aVC2HAEUfgdzttxxnui7d6g=" + }, + "org/jetbrains/kotlin#kotlin-compiler-runner/2.3.0": { + "jar": "sha256-hwl38pYFQ2xesiV7nI5dZPMoLyqI7e5FRNNOxF8Wpqc=", + "pom": "sha256-ov8zZnin9TpEOSv8bFK2gS7dxz5AghyQfyomQWeeDrs=" + }, + "org/jetbrains/kotlin#kotlin-daemon-client/2.3.0": { + "jar": "sha256-sr5naIyvEaE41a4M4SNTga2asN25OVqwb42EagtGYBc=", + "pom": "sha256-teLnTuXC+I/Qi/g+7GRx9rvKeqEhWYgCtsMsVuhwYCY=" + }, + "org/jetbrains/kotlin#kotlin-daemon-embeddable/2.3.0": { + "jar": "sha256-ObywLYwpOqZ4VUyLSdf/hGVwIXCSg8YYbjpAgGr5vRA=", + "pom": "sha256-TI3aucQLMNAbhc/qHxd31zUlybcWQ+YlDGV2/H0fwRI=" + }, + "org/jetbrains/kotlin#kotlin-reflect/1.6.10": { + "jar": "sha256-MnesECrheq0QpVq+x1/1aWyNEJeQOWQ0tJbnUIeFQgM=", + "pom": "sha256-V5BVJCdKAK4CiqzMJyg/a8WSWpNKBGwcxdBsjuTW1ak=" + }, + "org/jetbrains/kotlin#kotlin-reflect/2.1.21": { + "jar": "sha256-vNdaNspK2OBhFyFO2Af43qL+YaceB/kcoU9DNQJLhGM=", + "pom": "sha256-7XngK/COxxXsvNHi16RTYteqfDP5LvZ15t+kpJMbzF8=" + }, + "org/jetbrains/kotlin#kotlin-reflect/2.2.20": { + "jar": "sha256-ggkIOkp8TkdtmEKweDCPqWqW8Hpr2Z8F81hu4TKJqyY=", + "pom": "sha256-TidHQGbbg/uixZB0KJunEr6MhRV83guQUCmkRcJ19bo=" + }, + "org/jetbrains/kotlin#kotlin-reflect/2.3.0": { + "jar": "sha256-cU30voGVRf9N4fNqohg+DeqUtMjN98op6ciZGbrzY2I=", + "pom": "sha256-89F2jvL7UxBIPb6R4w6fo2x7Pi/e5pRaCLujEBQtKcE=" + }, + "org/jetbrains/kotlin#kotlin-reflect/2.3.21": { + "jar": "sha256-M+N9nfqGx6Kas06XW19KEoe0WIeGEQUfNIVlIiDBoss=", + "pom": "sha256-fjwv5c80lKm0dSVYDDjDXEPW42guagsvVllU4Zpy1jk=" + }, + "org/jetbrains/kotlin#kotlin-sam-with-receiver-compiler-plugin-embeddable/2.3.0": { + "jar": "sha256-QOPhi7jFUjLuZSXOV9F7hl5WcosFK/DBDnvsHQhJmMo=", + "pom": "sha256-BnzIEOCaYeFufoe1Kk3WR+FfYLd+PaDRsVPz+A7r8wM=" + }, + "org/jetbrains/kotlin#kotlin-script-runtime/2.3.0": { + "jar": "sha256-24JpYTcdZgUxjZxOS/zb+slMOgiSzcq9VSJIcP6tV/E=", + "pom": "sha256-20CN5tumaQeVvFOkoPhbM8en1qzLZ94ZAmQPr1QfL1s=" + }, + "org/jetbrains/kotlin#kotlin-scripting-common/2.3.0": { + "jar": "sha256-QlK3gs2lP8v9lTuQrwMlDiGX/+9uVavZsKLkj5Pv8lM=", + "pom": "sha256-9AuKrV3x68riUJLMM7hpP6Qw5TRCC6Wup/AGsvMrQw4=" + }, + "org/jetbrains/kotlin#kotlin-scripting-compiler-embeddable/2.3.0": { + "jar": "sha256-ZxRdvqkxlNuyJT4vNaCp/ngBfCy84+zbSx/0P/9HGNU=", + "pom": "sha256-FjR61xI8BuiaUu+twxjZaick9UqBx+xZTA1ALh8eZFk=" + }, + "org/jetbrains/kotlin#kotlin-scripting-compiler-impl-embeddable/2.3.0": { + "jar": "sha256-MsdCfxBeYtT07/MDXaHkKAsndxvkrWFDuoZV0Yh3IM0=", + "pom": "sha256-TPG5v5rmnHbz6nWnhW3GbeRGeKfHQXFa6cFdtA7Nfv0=" + }, + "org/jetbrains/kotlin#kotlin-scripting-jvm/2.3.0": { + "jar": "sha256-NpM+uDYZqKZeBB36m2ktNOB9V8b9Yv43HIu/BYgL7Ec=", + "pom": "sha256-qemsNTtIBUA7A3spmZpUnxvESATniVnYT/sbwzBF8kc=" + }, + "org/jetbrains/kotlin#kotlin-stdlib-jdk7/2.2.20": { + "jar": "sha256-O9Juy20Sl4xcTgtB92yf9VH6wqXmJoQnqdKgzfilrZE=", + "pom": "sha256-Cukeav/wZg79os8CjFvbnnoehn4Z3CyOuuiaglcUOOI=" + }, + "org/jetbrains/kotlin#kotlin-stdlib-jdk7/2.3.21": { + "jar": "sha256-4iQ6usK+1uC0e+GLK3/hwbTPakMUgDU9zUnR7TXzEZk=", + "pom": "sha256-9C/BJB/KFDNPapkO2sek90UqHwLGl9hVo/z47eUfAV0=" + }, + "org/jetbrains/kotlin#kotlin-stdlib-jdk8/2.2.20": { + "jar": "sha256-wxQXeTXY3C7ah5UHEX8l1t5W9sV+3plBaxTNYiu54J0=", + "pom": "sha256-NditbBnaV6t00h7YHdxYSZt8GwAlEbXoUgANuwxYq64=" + }, + "org/jetbrains/kotlin#kotlin-stdlib-jdk8/2.3.21": { + "jar": "sha256-YwkZKSRr66hrX7KwIKb10G4BaTqWC1ilmVnIcTZnmRw=", + "pom": "sha256-0ri51knL28+yHpHLU7TaRt000i11eo+IwdFlADD4IOs=" + }, + "org/jetbrains/kotlin#kotlin-stdlib/2.2.21": { + "jar": "sha256-ZVij0jPaVqIJNLMhWfnbX4btWBbvCY94osIj3Gq7ed0=", + "module": "sha256-v7xlfd06jjfkyK1BeWjV6wsLFxyfzkj5YsKtMu5DTCE=", + "pom": "sha256-zzH5IxlsY67ezQpXwkJpvTcCpOR8C/C9ZLWtpd5SInI=" + }, + "org/jetbrains/kotlin#kotlin-stdlib/2.3.0": { + "jar": "sha256-iHWHyRcTJQrVL+FK2RZtBCwzg1BJiQ6UN/NV/8WhlbE=", + "module": "sha256-CRCoo7aWD8eSxFxWqR18Oj8mKG8DKVVUtRnP83h1baI=", + "pom": "sha256-TVJW0+SETmVrDKQF9jUNbyF5XCQ3WzRSUmxUZ92ZtaI=" + }, + "org/jetbrains/kotlin#kotlin-stdlib/2.3.20": { + "jar": "sha256-CuElBKUEDrrzdwOQhINCDRpWJN0dk/NXZl+Md8hIoB4=", + "module": "sha256-9Os0T8TR46KK4WwIbsPkL1I3O0ZtQwgYL7OG45LA76M=", + "pom": "sha256-yDwC2afi6VRzBJHDPC8dwDwnZi4ntWbsK0TS0Bhjm5g=" + }, + "org/jetbrains/kotlin#kotlin-stdlib/2.3.21": { + "jar": "sha256-b2TqxzbblDTdaSW0pRi50dFxd2UjIMN5Fs+bo859fXo=", + "module": "sha256-e06ksiQrsXektKu2PD89hXMx1A01hl42/MPbZm7BAXQ=", + "pom": "sha256-PgtI2qFNxz+AKdjZ4V7TKUA3fK97kVUQ+I0zIZs1AYY=" + }, + "org/jetbrains/kotlin#kotlin-tooling-core/2.3.0": { + "jar": "sha256-NnFCeBKZvA+RIMHe7A5ik0oa+ep/AaqpxaU1TcXY19k=", + "pom": "sha256-tQ6FtLEYwSIjge0c67K6lqfeLdrtti3aZ9SuBqGiXTc=" + }, + "org/jetbrains/kotlinx#kotlinx-coroutines-bom/1.10.2": { + "pom": "sha256-+vDGU45T3cBJmmNmTY52PCFlgLLhjnIsy98bQxpq/iY=" + }, + "org/jetbrains/kotlinx#kotlinx-coroutines-bom/1.8.0": { + "pom": "sha256-Ejnp2+E5fNWXE0KVayURvDrOe2QYQuQ3KgiNz6i5rVU=" + }, + "org/jetbrains/kotlinx#kotlinx-coroutines-core-jvm/1.10.2": { + "jar": "sha256-XKF1s43zMf1kFVs1zYyuElH6nuNpcJs21C4KKIzM4/0=", + "module": "sha256-6eSnS02/4PXr7tiNSfNUbD7DCJQZsg5SUEAxNcLGTFM=", + "pom": "sha256-ZY9Xa5bIMuc4JAatsZfWTY4ul94Q6W36NwDez6KmDe8=" + }, + "org/jetbrains/kotlinx#kotlinx-coroutines-core-jvm/1.8.0": { + "jar": "sha256-mGCQahk3SQv187BtLw4Q70UeZblbJp8i2vaKPR9QZcU=", + "module": "sha256-/2oi2kAECTh1HbCuIRd+dlF9vxJqdnlvVCZye/dsEig=", + "pom": "sha256-pWM6vVNGfOuRYi2B8umCCAh3FF4LduG3V4hxVDSIXQs=" + }, + "org/jetbrains/kotlinx#kotlinx-coroutines-core/1.10.2": { + "module": "sha256-j+JUF35xGnzRijwG2CQvzpRfQcLMoT3BmzOuQqVDUBY=", + "pom": "sha256-UZ2lQACW80YqTa6AeDrQUEE9S8gex65T+udq7wzL7Uw=" + }, + "org/jetbrains/kotlinx#kotlinx-serialization-bom/1.9.0": { + "pom": "sha256-bX/zZcDvHNN2+1SxoWyAoh7Vj+tGwz80ULbPIuKxNT0=" + }, + "org/jetbrains/kotlinx#kotlinx-serialization-core-jvm/1.9.0": { + "jar": "sha256-Hwr6FyEQ5FpyMe8bRK6P2Eweuv+W8/w61o74xIEgtZw=", + "module": "sha256-cMh+MWGSq3cpqmOZIgKQ98jZ/dTZNC3J+cDkKFarNG0=", + "pom": "sha256-hxkNQ05icv7WBa8PztFfa8CC2KVQQMUZjm1LLWovysI=" + }, + "org/jetbrains/kotlinx#kotlinx-serialization-core/1.9.0": { + "module": "sha256-jNEYEwvyIIAgKeI5l0oz0nL00COlYQ9Vfs5rD4mV+J8=", + "pom": "sha256-lTt2Dcs2Ooqgz+X5GMPd0SRmh4XZGKw/QAsZGZasrJ0=" + }, + "org/jetbrains/kotlinx#kotlinx-serialization-json-jvm/1.9.0": { + "jar": "sha256-2UzDTK45JGoa90/aY/nEgSzhIhbvZB1fo7u7U5ppItg=", + "module": "sha256-u634x2urP82I/ORbO7tj37FIfzgCHhvdg7+5MQ735po=", + "pom": "sha256-azQzwqqesmYo26vxbJYzTKqzD24HcQ0Q7n+HkGznMN0=" + }, + "org/jetbrains/kotlinx#kotlinx-serialization-json/1.9.0": { + "module": "sha256-T8E+xBK3uaIToX39qjNkV4Ab4W/BZa2GsLcxT9CW5ww=", + "pom": "sha256-mUGX39Wqub9VhVbCFW/eIoK6b8OtR/RmoIznk1zPR2Q=" + }, + "org/jspecify#jspecify/1.0.0": { + "jar": "sha256-H61ua+dVd4Hk0zcp1Jrhzcj92m/kd7sMxozjUer9+6s=", + "module": "sha256-0wfKd6VOGKwe8artTlu+AUvS9J8p4dL4E+R8J4KDGVs=", + "pom": "sha256-zauSmjuVIR9D0gkMXi0N/oRllg43i8MrNYQdqzJEM6Y=" + }, + "org/junit#junit-bom/5.12.2": { + "module": "sha256-3nCsXZGlJlbYiQptI7ngTZm5mxoEAlMN7K1xvzGyc14=", + "pom": "sha256-zvgP7IZFT2gGv7DfJGabXG8y4styhTnqhZ9H39ybvBc=" + }, + "org/junit#junit-bom/5.13.4": { + "module": "sha256-6Vkoj94bGwUNm8CC/HhniRKNpdKFMJFGj8pQQQS99AA=", + "pom": "sha256-16CKmbJQLwu2jNTh+YTwv2kySqogi9D3M2bAP8NUikI=" + }, + "org/junit#junit-bom/5.14.1": { + "module": "sha256-J4rLEczJmYaUIkOG+W+0lBoi7bQstEbJLg8fMwFLa0g=", + "pom": "sha256-AbAd+jZlULQKxXYFSKfXKLYQnRfEUeg4ZNHl4M6GLJQ=" + }, + "org/junit#junit-bom/5.14.2": { + "module": "sha256-XSb0RAOSMm3SSDz0kBQ+6hSV1QlUWaC5ZRp7GzjiTr8=", + "pom": "sha256-7S3MeFW9RgvMyTob8Mli5jtWb/fY8d7Q8fJZO6gYOq8=" + }, + "org/junit#junit-bom/6.0.3": { + "module": "sha256-KA48NIVfKhPeJBIZN+TPl+S565IG5g+JHk8KHPDnq6E=", + "pom": "sha256-plW2pdwA0b68kfsrFcDH6K6snWvc+HlZVQU3DidTAoc=" + }, + "org/junit#junit-bom/6.1.0": { + "module": "sha256-SCB/lc3sO/tc5sy/GNUqzlHoFfIRBp3BbgKDslWmTZo=", + "pom": "sha256-97Zl5dVzsBr21DTT0kUKpbdBtoPz8QFy8etEo9DQrAw=" + }, + "org/junit/jupiter#junit-jupiter-api/6.1.0": { + "jar": "sha256-UPl+uADC6Ij6ojegb1oO9EX67VVn+ZTawMK50niprSA=", + "module": "sha256-HQFsKC2GuCGvWz2zd7cJrZI4tUyJSzMjzRsj6lMSl9Y=", + "pom": "sha256-000J8MyNqqQOMC26REEyf8BF+gvV39qC0ho3IBj3i4c=" + }, + "org/junit/jupiter#junit-jupiter-engine/6.1.0": { + "jar": "sha256-6nB7lkcIRhmg/JEc77JQN1QNWLKAD46tH8aiuvWLHaU=", + "module": "sha256-qxcPpDeU24cKcgzDt6LWdi3MRXcyjv2vizCOaNLH79E=", + "pom": "sha256-h+13EyLIt6c55oZct+WGTqwoj9IL1qP8Vjtiov8sSVo=" + }, + "org/junit/jupiter#junit-jupiter-params/6.1.0": { + "jar": "sha256-uYfuoyBRhadvNlmjnmdQPLe2gti3vgO+S5+StxDw7sA=", + "module": "sha256-evPVYvC8fWUmA2HlcT5vzVVQuZcqGA1vxM2itoJM4pc=", + "pom": "sha256-ZOXfB1ZYuUmh2lSyEp6jHOY87fodJTEHWgBxlJnOwEY=" + }, + "org/junit/jupiter#junit-jupiter/6.1.0": { + "jar": "sha256-pOQgtcboFwMjtMXJeuNbyg1iC+n5z+NwBoIPU5MfJ6M=", + "module": "sha256-Kl2tWs4texVUiGguY6LrDxS7YA+fbx+75B3QGylMZ0g=", + "pom": "sha256-Rme8comEZvz6eQGJJmuiXGtmrV4WpOVgJgM5euWn4q0=" + }, + "org/junit/platform#junit-platform-commons/6.1.0": { + "jar": "sha256-HZBGqxfsftr7C8eUXS5Z1xgP/08oxzS4I7UQAedp9xs=", + "module": "sha256-eVv++8OD8DMoadK4AUJSK65GKjkFu6ntSbe8NcQf64A=", + "pom": "sha256-yRmWB2BYBu8YXQT9RpVRsrShUQos6twHTbRBvXf23TY=" + }, + "org/junit/platform#junit-platform-console/6.1.0": { + "jar": "sha256-cV8uVNOeAu3XbDPpNDQcBWJ2mVXprXaCiYYj5zSFpyk=", + "module": "sha256-obRGaDj076z3f8NAAbDnxSjTZdzMGW0zY1QoLmvVPo8=", + "pom": "sha256-ODuHmTEMX+hxRcdwAJLsq0DlIOtPTZSC3NlhkiqkFhU=" + }, + "org/junit/platform#junit-platform-engine/6.1.0": { + "jar": "sha256-P7a+dsJqsPlP4ITj/Qo54dJeIhKZKaYbKb2AoFK5PqU=", + "module": "sha256-OnbyFfpzfJbOlycTqva0UYePpzOVX/IbDNao+I3LIhI=", + "pom": "sha256-NgVWdVmFVdSVuvtVezXukYzbF2pnUxALABtO7thfJsU=" + }, + "org/junit/platform#junit-platform-launcher/6.1.0": { + "jar": "sha256-CZXm7SRNZhlsvaAZ4vh5UE0LSJce2unMPepGobMcA3c=", + "module": "sha256-f4PRJdcb5Z4JVD1LUGn6h9jKchyqQ9FKq+gm+x2xuME=", + "pom": "sha256-on93QpSA4V22Cwlf21lfULa6VylfIqXCZEuo1BitM54=" + }, + "org/junit/platform#junit-platform-reporting/6.1.0": { + "jar": "sha256-a86yu3Wlsyd0vqp8UgIBuGNGPPki8vKwtkkqhQrwaos=", + "module": "sha256-HobUo5++HvkQt6CVbojmWmpXWXTQDzI5cT+5YlYIrts=", + "pom": "sha256-y0RrbNMT/taDX15Xub4mmC5t9ppLwjBccgZqKijXZ+8=" + }, + "org/opentest4j#opentest4j/1.3.0": { + "jar": "sha256-SOLfY2yrZWPO1k3N/4q7I1VifLI27wvzdZhoLd90Lxs=", + "module": "sha256-SL8dbItdyU90ZSvReQD2VN63FDUCSM9ej8onuQkMjg0=", + "pom": "sha256-m/fP/EEPPoNywlIleN+cpW2dQ72TfjCUhwbCMqlDs1U=" + }, + "org/opentest4j/reporting#open-test-reporting-tooling-spi/0.2.5": { + "jar": "sha256-3yN7aIR2N3R/C/24j6nN2ccsyFVQ+tDEHdszhppcpRY=", + "module": "sha256-1gOJ6EFNKYeZvTC0VcGx84dyH9C+PbvQl0XlgPLfV00=", + "pom": "sha256-CaKK5rBgdxKv76Y2iNyEZaReTXUUB9xRT9hYrYCmizs=" + }, + "org/ow2#ow2/1.5.1": { + "pom": "sha256-Mh3bt+5v5PU96mtM1tt0FU1r+kI5HB92OzYbn0hazwU=" + }, + "org/ow2/asm#asm-analysis/9.9.1": { + "jar": "sha256-YmC//I7ACN0bcTcCx5lOLJTRiKPaW++ehyeKFt9qdSI=", + "pom": "sha256-NiF+gtimATTPIQ+A63bdrllVkcYIXKuBa1qhDOmfy6A=" + }, + "org/ow2/asm#asm-commons/9.9.1": { + "jar": "sha256-wjGeAUznGZ8rf31W1ruZGGMWjD9LbNbJ9UKkk37374g=", + "pom": "sha256-3vcPp9Oku3FmC8ZhUjMpV5pLwxzMlsQtOlw7n3amtkk=" + }, + "org/ow2/asm#asm-tree/9.9.1": { + "jar": "sha256-DzVVCWtyC4ILusqwtRVYm+4CAL7gmb2hTFYXOK6De6E=", + "pom": "sha256-Z/7kRrpRKHEwBzjw+Vb2GlAKhS9oYf9w8KPHvwwPpAU=" + }, + "org/ow2/asm#asm-util/9.9.1": { + "jar": "sha256-xeu76vaBJq8JS0L6SAD1m8RBOr0C2Vua761yLNJX4gc=", + "pom": "sha256-Unlp0IpNdfm9r5y/ODfphpaimJC8AX2V/Kb/gQ8NcEw=" + }, + "org/ow2/asm#asm/9.9.1": { + "jar": "sha256-bzgoohXJIAWaXvovtVwjPWxU7FytypnOGxvdEAd8fd0=", + "pom": "sha256-rKaN7pui9s2Q/95yjv3H4+v89Z8/Qfv+JI0tAdW4Zq8=" + }, + "org/reactivestreams#reactive-streams/1.0.4": { + "jar": "sha256-91yll3ibPaxY9hhXuawuEDSmj6Zy2zUFWo+0UJ4yXyg=", + "pom": "sha256-VLoj2HotQ4VAyZ74eUoIVvxXOiVrSYZ4KDw8Z+8Yrag=" + }, + "org/slf4j#jul-to-slf4j/2.0.18": { + "jar": "sha256-y7fRqqqehx6xoGWUq9kRv5cCcVKXbt8e3DFb51I5IE4=", + "pom": "sha256-6ujg/72LMfqPimENYtOHtOEClbp00OFNZkBFYLdNgpU=" + }, + "org/slf4j#slf4j-api/2.0.17": { + "jar": "sha256-e3UdlSBhlU1av+1xgcH2RdM2CRtnmJFZHWMynGIuuDI=", + "pom": "sha256-FQxAKH987NwhuTgMqsmOkoxPM8Aj22s0jfHFrJdwJr8=" + }, + "org/slf4j#slf4j-api/2.0.18": { + "jar": "sha256-RFCP0VdlAGiMeQsZCs3Rb+xPjHmj4LkAr9cFA88FX1U=", + "pom": "sha256-bCx/LAJ3TMK3thn70t94c82tKXGJJuRHVLh/cNHrQ8s=" + }, + "org/slf4j#slf4j-bom/2.0.17": { + "pom": "sha256-940ntkK0uIbrg5/BArXNn+fzDzdZn/5oGFvk4WCQMek=" + }, + "org/slf4j#slf4j-bom/2.0.18": { + "pom": "sha256-khmqtgFXUSbE5m4TMesrDGwXozCsTVoH480R1YCgwS0=" + }, + "org/slf4j#slf4j-parent/2.0.17": { + "pom": "sha256-lc1x6FLf2ykSbli3uTnVfsKy5gJDkYUuC1Rd7ggrvzs=" + }, + "org/slf4j#slf4j-parent/2.0.18": { + "pom": "sha256-CziWvtrSye2Wl+3L6h2gxUzSOKcjWDqBNYqDv7eC6fo=" + }, + "org/sonatype/oss#oss-parent/7": { + "pom": "sha256-tR+IZ8kranIkmVV/w6H96ne9+e9XRyL+kM5DailVlFQ=" + }, + "org/xerial#sqlite-jdbc/3.53.1.0": { + "jar": "sha256-KKzuz8yVNWRb0Z+piDhXA8e4mYLBUGpoVfWUK0Ay7KY=", + "pom": "sha256-lwYjDFkjTyp0poFWvg4Ye7HJuJu5uSRvy+igLiFQgQM=" + }, + "tools/jackson#jackson-base/3.1.3": { + "pom": "sha256-M4J2vKjCLBfdyIhDyV1YQnTHvFIR0m1aLo0yzV+D+PI=" + }, + "tools/jackson#jackson-bom/3.1.3": { + "pom": "sha256-9aDcUnRCPNLH+McXoAG6ttstsNhAFT42JevJ3pWM804=" + }, + "tools/jackson/core#jackson-core/3.1.3": { + "jar": "sha256-6F3tJfddjavveqCfwVXvYW8Kl+lr72YV96eADCp2xu8=", + "module": "sha256-wLkCEBQsEYaXC2kYu5CaNYBgdj90eizpfp0q3hPYBnQ=", + "pom": "sha256-jHa/0hRqfSDDjZfj3DhlgR0aVeKY7AdXJEcWo0lBQls=" + }, + "tools/jackson/core#jackson-databind/3.1.3": { + "jar": "sha256-rt3yRi1Hg6Gxb2/x4kJYKnbt2czWm2tjhpBcZaTsYHc=", + "module": "sha256-gIsco9hZZK4LF2cd2oLRA4nisIw0VihOjQuew5+Sl3E=", + "pom": "sha256-lHy/Pv9RkmVG1EqgddXxtM8uL5o4UkqJLZWpJPU4W+8=" + } + } +} diff --git a/pkgs/by-name/si/signal-cli/libsignal-jni.nix b/pkgs/by-name/si/signal-cli/libsignal-jni.nix new file mode 100644 index 000000000000..a64a6a045f6e --- /dev/null +++ b/pkgs/by-name/si/signal-cli/libsignal-jni.nix @@ -0,0 +1,76 @@ +{ + lib, + stdenv, + fetchFromGitHub, + rustPlatform, + cmake, + pkg-config, + protobuf, + perl, + jdk, + gitMinimal, + llvmPackages, +}: + +rustPlatform.buildRustPackage (finalAttrs: { + pname = "libsignal-jni"; + version = "0.96.3"; + + src = fetchFromGitHub { + owner = "signalapp"; + repo = "libsignal"; + tag = "v${finalAttrs.version}"; + hash = "sha256-FOppsfocUvUfWa6AfBPOxAnntGJkzTbnPwqMzzbHnWQ="; + }; + + cargoHash = "sha256-wsXlCpNwO+E6rVNaD2R51Mi0sZUv2lhllGxDxzyptYA="; + + nativeBuildInputs = [ + cmake + pkg-config + protobuf + perl # needed by boring-sys/BoringSSL + jdk # for JNI headers + gitMinimal # needed by boring-sys build script + ]; + + LIBCLANG_PATH = "${llvmPackages.libclang.lib}/lib"; + + # bindgen needs to find C headers (stdlib.h etc.) + # On Linux, libc headers are in a separate .dev output; on Darwin they + # come from the SDK and libclang already knows where to find them. + BINDGEN_EXTRA_CLANG_ARGS = + if stdenv.hostPlatform.isDarwin then + "-isystem ${llvmPackages.libclang.lib}/lib/clang/${lib.versions.major llvmPackages.libclang.version}/include" + else + "-isystem ${stdenv.cc.libc.dev}/include -isystem ${llvmPackages.libclang.lib}/lib/clang/${lib.versions.major llvmPackages.libclang.version}/include"; + + buildAndTestSubdir = "rust/bridge/jni"; + + cargoBuildFlags = [ + "-p" + "libsignal-jni" + ]; + + RUSTFLAGS = "--cfg aes_armv8 --cfg tokio_unstable"; + + env = { + BORING_BSSL_SOURCE_EXTERNAL = "0"; + }; + + installPhase = '' + runHook preInstall + mkdir -p $out/lib + find target -name "libsignal_jni${stdenv.hostPlatform.extensions.sharedLibrary}" | head -1 | while read f; do + install -Dm755 "$f" "$out/lib/$(basename "$f")" + done + runHook postInstall + ''; + + meta = { + description = "Signal Protocol JNI native library"; + homepage = "https://github.com/signalapp/libsignal"; + license = lib.licenses.agpl3Only; + platforms = lib.platforms.unix; + }; +}) diff --git a/pkgs/by-name/si/signal-cli/package.nix b/pkgs/by-name/si/signal-cli/package.nix index 150f56c2b132..c375bdaf5de4 100644 --- a/pkgs/by-name/si/signal-cli/package.nix +++ b/pkgs/by-name/si/signal-cli/package.nix @@ -1,77 +1,130 @@ { - stdenvNoCC, + stdenv, lib, - fetchurl, + fetchFromGitHub, makeWrapper, + gradle_9, openjdk25_headless, libmatthew_java, dbus, dbus_java, + callPackage, versionCheckHook, + signal-cli, + writeShellApplication, + curl, + nix-update, }: -stdenvNoCC.mkDerivation (finalAttrs: { +let + gradle = gradle_9; + libsignal-jni = callPackage ./libsignal-jni.nix { jdk = openjdk25_headless; }; +in +stdenv.mkDerivation (finalAttrs: { pname = "signal-cli"; - version = "0.14.2"; + version = "0.14.6"; - # Building from source would be preferred, but is much more involved. - src = fetchurl { - url = "https://github.com/AsamK/signal-cli/releases/download/v${finalAttrs.version}/signal-cli-${finalAttrs.version}.tar.gz"; - hash = "sha256-riu8b8ZomoqyPVfmN9fpzbtDQpN72xtU1M9rVkDfHg0="; + src = fetchFromGitHub { + owner = "AsamK"; + repo = "signal-cli"; + tag = "v${finalAttrs.version}"; + hash = "sha256-VJ+/0CvfgtE6VHFeTLKAswTWrnyAL7AYrfCYVJpXDaE="; }; - buildInputs = lib.optionals stdenvNoCC.hostPlatform.isLinux [ + nativeBuildInputs = [ + gradle + makeWrapper + ]; + + buildInputs = lib.optionals stdenv.hostPlatform.isLinux [ libmatthew_java dbus dbus_java ]; - nativeBuildInputs = [ makeWrapper ]; + + mitmCache = gradle.fetchDeps { + pkg = signal-cli; + data = ./deps.json; + }; + + __darwinAllowLocalNetworking = true; + + # Use the JDK for building + gradleFlags = [ + "-Dfile.encoding=utf-8" + "-Dorg.gradle.java.home=${openjdk25_headless}" + ]; + + gradleBuildTask = "installDist"; + + preGradleUpdate = '' + gradle assemble + ''; + + # Tests require network access and a running signal server + doCheck = false; installPhase = '' runHook preInstall - mkdir -p $out - cp -r lib $out/ - install -Dm755 bin/signal-cli -t $out/bin + + mkdir -p $out/lib $out/bin + + cp build/install/signal-cli/lib/* $out/lib/ + cp ${libsignal-jni}/lib/* $out/lib/ + '' + + lib.optionalString stdenv.hostPlatform.isLinux '' + makeWrapper ${openjdk25_headless}/bin/java $out/bin/signal-cli \ + --set JAVA_HOME "${openjdk25_headless}" \ + --add-flags "--enable-native-access=ALL-UNNAMED" \ + --add-flags "-classpath '$out/lib/*:${libmatthew_java}/lib/jni'" \ + --add-flags "-Djava.library.path=$out/lib:${libmatthew_java}/lib/jni:${dbus_java}/share/java/dbus" \ + --add-flags "org.asamk.signal.Main" + '' + + lib.optionalString stdenv.hostPlatform.isDarwin '' + makeWrapper ${openjdk25_headless}/bin/java $out/bin/signal-cli \ + --set JAVA_HOME "${openjdk25_headless}" \ + --add-flags "--enable-native-access=ALL-UNNAMED" \ + --add-flags "-classpath '$out/lib/*'" \ + --add-flags "-Djava.library.path=$out/lib" \ + --add-flags "org.asamk.signal.Main" '' - + ( - if stdenvNoCC.hostPlatform.isLinux then - '' - makeWrapper ${openjdk25_headless}/bin/java $out/bin/signal-cli \ - --set JAVA_HOME "${openjdk25_headless}" \ - --add-flags "-classpath '$out/lib/*:${libmatthew_java}/lib/jni'" \ - --add-flags "-Djava.library.path=${libmatthew_java}/lib/jni:${dbus_java}/share/java/dbus:$out/lib" \ - --add-flags "org.asamk.signal.Main" - '' - else - '' - wrapProgram $out/bin/signal-cli \ - --prefix PATH : ${lib.makeBinPath [ openjdk25_headless ]} \ - --set JAVA_HOME ${openjdk25_headless} - '' - ) + '' runHook postInstall ''; - # Execution in the macOS (10.13) sandbox fails with - # dyld: Library not loaded: /System/Library/Frameworks/Cocoa.framework/Versions/A/Cocoa - # Referenced from: /nix/store/5ghc2l65p8jcjh0bsmhahd5m9k5p8kx0-zulu1.8.0_121-8.20.0.5/bin/java - # Reason: no suitable image found. Did find: - # /System/Library/Frameworks/Cocoa.framework/Versions/A/Cocoa: file system sandbox blocked stat() - # /System/Library/Frameworks/Cocoa.framework/Versions/A/Cocoa: file system sandbox blocked stat() - # /nix/store/in41dz8byyyz4c0w132l7mqi43liv4yr-stdenv-darwin/setup: line 1310: 2231 Abort trap: 6 signal-cli --version - doInstallCheck = stdenvNoCC.hostPlatform.isLinux; + doInstallCheck = true; nativeInstallCheckInputs = [ versionCheckHook ]; + passthru = { + updateScript = lib.getExe (writeShellApplication { + name = "signal-cli-update"; + runtimeInputs = [ + curl + nix-update + ]; + text = '' + nix-update signal-cli + nix-update signal-cli.passthru.libsignal-jni --version "$(curl --silent --location https://github.com/AsamK/signal-cli/raw/v"$(nix-instantiate --raw --eval -A signal-cli.version)"/libsignal-version)" + ''; + }); + libsignal-jni = libsignal-jni; + }; + meta = { homepage = "https://github.com/AsamK/signal-cli"; description = "Command-line and dbus interface for communicating with the Signal messaging service"; mainProgram = "signal-cli"; changelog = "https://github.com/AsamK/signal-cli/blob/v${finalAttrs.version}/CHANGELOG.md"; - sourceProvenance = with lib.sourceTypes; [ binaryBytecode ]; + sourceProvenance = with lib.sourceTypes; [ + fromSource + binaryBytecode + ]; license = lib.licenses.gpl3; - maintainers = [ lib.maintainers.klea ]; - platforms = lib.platforms.all; + maintainers = [ + lib.maintainers.klea + lib.maintainers.akosseres + ]; + platforms = lib.platforms.unix; }; }) diff --git a/pkgs/by-name/so/socat/package.nix b/pkgs/by-name/so/socat/package.nix index 40f1308046a3..40cf1ef10dcc 100644 --- a/pkgs/by-name/so/socat/package.nix +++ b/pkgs/by-name/so/socat/package.nix @@ -11,11 +11,11 @@ stdenv.mkDerivation rec { pname = "socat"; - version = "1.8.1.1"; + version = "1.8.1.3"; src = fetchurl { url = "http://www.dest-unreach.org/socat/download/socat-${version}.tar.bz2"; - hash = "sha256-Xrxja39CcFP5iAZpZSFlOmFMfgZGSRA1PL9U4jJ63Bs="; + hash = "sha256-JbxkdikrLmFCIJicd7C2/Kh7slJdl0ezGmY5sftgJBg="; }; postPatch = '' diff --git a/pkgs/by-name/sp/spirv-headers/package.nix b/pkgs/by-name/sp/spirv-headers/package.nix index 95a5f55b4cf2..a88a1750f180 100644 --- a/pkgs/by-name/sp/spirv-headers/package.nix +++ b/pkgs/by-name/sp/spirv-headers/package.nix @@ -2,6 +2,7 @@ lib, stdenv, fetchFromGitHub, + fetchpatch, cmake, }: @@ -16,6 +17,15 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-aYKFJxRDoY/Cor8gYVoR/YSyXWSNtcRG0HK8BZH0Ztk="; }; + patches = [ + # Backport new predicated load/store instructions, needed by spirv-llvm-translator + # Not in any tagged releases yet, should exist in the next release after 1.4.350.1. + (fetchpatch { + url = "https://github.com/KhronosGroup/SPIRV-Headers/commit/b8a32968473ce852a809b9de5f04f02a5a9dfa78.patch"; + hash = "sha256-59jmN28ifEhAxySXCpuGZ62jo1WVsRPnVosK8X4yrjM="; + }) + ]; + nativeBuildInputs = [ cmake ]; meta = { diff --git a/pkgs/by-name/sp/spirv-llvm-translator/package.nix b/pkgs/by-name/sp/spirv-llvm-translator/package.nix index ce8f31de261d..b86f3424f750 100644 --- a/pkgs/by-name/sp/spirv-llvm-translator/package.nix +++ b/pkgs/by-name/sp/spirv-llvm-translator/package.nix @@ -1,6 +1,7 @@ { lib, stdenv, + srcOnly, fetchFromGitHub, fetchpatch, cmake, @@ -16,6 +17,11 @@ let llvmMajor = lib.versions.major llvm.version; versions = { + "22" = rec { + version = "22.1.3"; + rev = "v${version}"; + hash = "sha256-u/OytBH9LgAyGF9PX+5lmAbGPQ7iVv52w8mwQ+6fi/s="; + }; "21" = rec { version = "21.1.0"; rev = "v${version}"; @@ -79,7 +85,7 @@ stdenv.mkDerivation { "-DLLVM_SPIRV_BUILD_EXTERNAL=YES" # RPATH of binary /nix/store/.../bin/llvm-spirv contains a forbidden reference to /build/ "-DCMAKE_SKIP_BUILD_RPATH=ON" - "-DLLVM_EXTERNAL_SPIRV_HEADERS_SOURCE_DIR=${spirv-headers.src}" + "-DLLVM_EXTERNAL_SPIRV_HEADERS_SOURCE_DIR=${srcOnly spirv-headers}" ] ++ lib.optional ( lib.toInt llvmMajor >= 19 diff --git a/pkgs/by-name/ta/tack/package.nix b/pkgs/by-name/ta/tack/package.nix new file mode 100644 index 000000000000..6b4d448cb70b --- /dev/null +++ b/pkgs/by-name/ta/tack/package.nix @@ -0,0 +1,43 @@ +{ + lib, + rustPlatform, + fetchFromGitHub, + nix-update-script, +}: +rustPlatform.buildRustPackage (finalAttrs: { + pname = "tack"; + version = "1.0.0"; + src = fetchFromGitHub { + owner = "manic-systems"; + repo = "tack"; + tag = "v${finalAttrs.version}"; + hash = "sha256-KhJb0NWLhj8AkD8uWEbXt179YlFLemk0OgOltw4jEk8="; + }; + + __structuredAttrs = true; + strictDeps = true; + + cargoHash = "sha256-3vDMM5uTsmRso6McH/b3+RpjeKjhgQm9V1piBrnSRjk="; + + prePatch = '' + rm .cargo/config.toml + ''; + + doInstallCheck = true; + + passthru.updateScript = nix-update-script { }; + + meta = { + homepage = "https://github.com/manic-systems/tack"; + description = "flake-like toml nix pins, lazily fetched and transformed"; + mainProgram = "tack"; + license = [ lib.licenses.eupl12 ]; + maintainers = with lib.maintainers; [ + amaanq + atagen + faukah + max + NotAShelf + ]; + }; +}) diff --git a/pkgs/by-name/ut/util-linux/package.nix b/pkgs/by-name/ut/util-linux/package.nix index 0c9c7542a23c..f11d004bb0cf 100644 --- a/pkgs/by-name/ut/util-linux/package.nix +++ b/pkgs/by-name/ut/util-linux/package.nix @@ -43,11 +43,11 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "util-linux" + lib.optionalString isMinimal "-minimal"; - version = "2.42"; + version = "2.42.2"; src = fetchurl { url = "mirror://kernel/linux/utils/util-linux/v${lib.versions.majorMinor finalAttrs.version}/util-linux-${finalAttrs.version}.tar.xz"; - hash = "sha256-NFKyYLuqd11udJrDuyIRF4UAP8H0RJcAJcjaJt+nWOk="; + hash = "sha256-A6BdOt+WAu8Sjy2gW4SzIFzmDDUeVzfANw90AAZ5zoo="; }; # Note: fetchpatch/fetchpatch2 cause infinite recursion with util-linuxMinimal. @@ -57,38 +57,6 @@ stdenv.mkDerivation (finalAttrs: { # which isn't valid on NixOS (and a compatibility link on most other modern # distros anyway). ./rtcwake-search-PATH-for-shutdown.patch - - # Fix compile of 2.42+ on Darwin. - # https://lore.kernel.org/util-linux/CAEUYr6ZjVX1bd-xcBGtFN_ZYwQnXDYsw7d1-7sTpF2BbgfrR+g@mail.gmail.com/T/#u - # Different fix than originally proposed; we just don't compile that file on Darwin now and the previous patch was able to be reverted. - # See: https://github.com/util-linux/util-linux/commit/6ccf20d2fd8e45eed70bd1b915c0d16f646bf133 - (fetchurl { - name = "pidfd-utils-linux-only.patch"; - url = "https://github.com/util-linux/util-linux/commit/afdade4a3d8e4e6070343c5576470c575719b81f.patch"; - hash = "sha256-EnHsIhU6jaS4Qm+kQMP2an7Ay08nKbIO0MbU7Y2pwkU="; - }) - - # Musl does not define AT_HANDLE_FID, hard-code it if left undefined. - # https://github.com/util-linux/util-linux/pull/4203 - (fetchurl { - name = "fix-musl-nsenter.patch"; - url = "https://github.com/util-linux/util-linux/commit/000aff333e5c3a23967280cb0d6451fbbfc9c91b.patch"; - hash = "sha256-6K3jRr2RsAfHnweBOlMn2F0h8hD3xjZobJ1pSlCQHw8="; - }) - - # `script` is broken with options after non-option args and has new memory leaks - # https://lore.kernel.org/util-linux/adi3573O-5gr9m2q@per.namespace.at/T/#t - # https://github.com/util-linux/util-linux/pull/4201 - (fetchurl { - name = "script-fix-backwards-compat.patch"; - url = "https://github.com/util-linux/util-linux/commit/70507ab9eaed10b8dd77b77d4ea25c11ee726bed.patch"; - hash = "sha256-PpFtv8XOK36npCVSvdgKcxGQmkJtgdyMmlN+4yQuWS8="; - }) - (fetchurl { - name = "script-fix-memory-leaks.patch"; - url = "https://github.com/util-linux/util-linux/commit/2f1c12a49500ca7ed9c3d5e80664c1622925456b.patch"; - hash = "sha256-9ZwA6sZwM1rQDoxV5x1KHLWxsFpI5CGWJqubtdEHj/I="; - }) ]; # We separate some of the utilities into their own outputs. This diff --git a/pkgs/by-name/wa/wannier90/package.nix b/pkgs/by-name/wa/wannier90/package.nix index 2a8996daf779..321c34e4e0e7 100644 --- a/pkgs/by-name/wa/wannier90/package.nix +++ b/pkgs/by-name/wa/wannier90/package.nix @@ -73,9 +73,6 @@ stdenv.mkDerivation (finalAttrs: { doCheck = true; checkInputs = [ python3 ]; checkTarget = [ "test-serial" ]; - preCheck = '' - export OMP_NUM_THREADS=4 - ''; enableParallelBuilding = true; diff --git a/pkgs/by-name/xl/xla/package.nix b/pkgs/by-name/xl/xla/package.nix index 597a12a23400..af2dbedb57c7 100644 --- a/pkgs/by-name/xl/xla/package.nix +++ b/pkgs/by-name/xl/xla/package.nix @@ -235,6 +235,9 @@ in runHook postInstall ''; }; + + requiredSystemFeatures = [ "big-parallel" ]; + meta = { description = "Machine learning compiler for GPUs, CPUs, and ML accelerators"; homepage = "https://github.com/openxla/xla"; diff --git a/pkgs/development/compilers/go/1.26.nix b/pkgs/development/compilers/go/1.26.nix index 242fa4c91de8..b9c04a91729c 100644 --- a/pkgs/development/compilers/go/1.26.nix +++ b/pkgs/development/compilers/go/1.26.nix @@ -25,11 +25,11 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "go"; - version = "1.26.4"; + version = "1.26.5"; src = fetchurl { url = "https://go.dev/dl/go${finalAttrs.version}.src.tar.gz"; - hash = "sha256-T2aKMvv8ETLmqIH7lowvHa2mMUkqM5IRc1+7JVpCYC0="; + hash = "sha256-SVvkvIcXasVnOS5bQRar2YRm0z17SdQedkzMaXay3EI="; }; strictDeps = true; diff --git a/pkgs/development/compilers/llvm/common/libclc/default.nix b/pkgs/development/compilers/llvm/common/libclc/default.nix index 62a8dff18ec3..69350a9d3834 100644 --- a/pkgs/development/compilers/llvm/common/libclc/default.nix +++ b/pkgs/development/compilers/llvm/common/libclc/default.nix @@ -97,7 +97,7 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ llvm ]; strictDeps = true; - postInstall = '' + postInstall = lib.optionalString (lib.versionOlder finalAttrs.version "22.1") '' install -Dt $dev/bin prepare_builtins ''; diff --git a/pkgs/development/compilers/llvm/common/openmp/default.nix b/pkgs/development/compilers/llvm/common/openmp/default.nix index a08376522d9e..0b971ea1d0ef 100644 --- a/pkgs/development/compilers/llvm/common/openmp/default.nix +++ b/pkgs/development/compilers/llvm/common/openmp/default.nix @@ -19,7 +19,7 @@ ompdSupport ? true, ompdGdbSupport ? ompdSupport, getVersionFile, - fetchpatch, + checkPhaseThreadLimitHook, }: assert lib.assertMsg (ompdGdbSupport -> ompdSupport) "OMPD GDB support requires OMPD support!"; @@ -60,6 +60,10 @@ stdenv.mkDerivation (finalAttrs: { lit ]; + propagatedNativeBuildInputs = [ + checkPhaseThreadLimitHook + ]; + buildInputs = [ llvm ] diff --git a/pkgs/development/interpreters/python/cpython/3.14/hacl-static-ldeps-for-static-modules.patch b/pkgs/development/interpreters/python/cpython/3.14/hacl-static-ldeps-for-static-modules.patch deleted file mode 100644 index 8501ab38a940..000000000000 --- a/pkgs/development/interpreters/python/cpython/3.14/hacl-static-ldeps-for-static-modules.patch +++ /dev/null @@ -1,50 +0,0 @@ -From ee1b8479cff97ca7e5ed4d51d6aa24ccb47deb8b Mon Sep 17 00:00:00 2001 -From: Ihar Hrachyshka -Date: Sat, 21 Mar 2026 18:34:50 -0400 -Subject: [PATCH] gh-146264: Use static HACL deps for static module builds - ---- - .../next/Build/2026-03-21-18-51-31.gh-issue-146264.Q9Ej4m.rst | 3 +++ - configure | 2 +- - configure.ac | 2 +- - 3 files changed, 5 insertions(+), 2 deletions(-) - create mode 100644 Misc/NEWS.d/next/Build/2026-03-21-18-51-31.gh-issue-146264.Q9Ej4m.rst - -diff --git a/Misc/NEWS.d/next/Build/2026-03-21-18-51-31.gh-issue-146264.Q9Ej4m.rst b/Misc/NEWS.d/next/Build/2026-03-21-18-51-31.gh-issue-146264.Q9Ej4m.rst -new file mode 100644 -index 00000000000..1fdafe56043 ---- /dev/null -+++ b/Misc/NEWS.d/next/Build/2026-03-21-18-51-31.gh-issue-146264.Q9Ej4m.rst -@@ -0,0 +1,3 @@ -+Fix static module builds on non-WASI targets by linking HACL dependencies as -+static libraries when ``MODULE_BUILDTYPE=static``, preventing duplicate -+``_Py_LibHacl_*`` symbol errors at link time. -diff --git a/configure b/configure -index 23f24d51c79..db5c861f601 100755 ---- a/configure -+++ b/configure -@@ -33009,7 +33009,7 @@ fi - - { printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking for HACL* library linking type" >&5 - printf %s "checking for HACL* library linking type... " >&6; } --if test "$ac_sys_system" = "WASI"; then -+if test "$ac_sys_system" = "WASI" || test "$MODULE_BUILDTYPE" = "static"; then - LIBHACL_LDEPS_LIBTYPE=STATIC - { printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: static" >&5 - printf "%s\n" "static" >&6; } -diff --git a/configure.ac b/configure.ac -index 635fce3f2e6..59166d63e63 100644 ---- a/configure.ac -+++ b/configure.ac -@@ -8171,7 +8171,7 @@ AC_SUBST([LIBHACL_BLAKE2_SIMD256_OBJS]) - # HACL*-based cryptographic primitives - - AC_MSG_CHECKING([for HACL* library linking type]) --if test "$ac_sys_system" = "WASI"; then -+if test "$ac_sys_system" = "WASI" || test "$MODULE_BUILDTYPE" = "static"; then - LIBHACL_LDEPS_LIBTYPE=STATIC - AC_MSG_RESULT([static]) - else --- -2.53.0 - diff --git a/pkgs/development/interpreters/python/cpython/default.nix b/pkgs/development/interpreters/python/cpython/default.nix index 88e234d40cf9..dd984d488b00 100644 --- a/pkgs/development/interpreters/python/cpython/default.nix +++ b/pkgs/development/interpreters/python/cpython/default.nix @@ -133,7 +133,6 @@ let getLib optionals optionalString - replaceStrings ; withLibxcrypt = @@ -428,15 +427,6 @@ stdenv.mkDerivation (finalAttrs: { # backport fix for https://github.com/python/cpython/issues/95855 ./platform-triplet-detection.patch ] - ++ optionals (pythonAtLeast "3.14" && pythonOlder "3.15") [ - # https://github.com/python/cpython/issues/146264 - # https://github.com/python/cpython/pull/146265 - ./3.14/hacl-static-ldeps-for-static-modules.patch - ] - ++ optionals (version == "3.13.10" || version == "3.14.1") [ - # https://github.com/python/cpython/issues/142218 - ./${lib.versions.majorMinor version}/gh-142218.patch - ] ++ optionals (stdenv.hostPlatform.isMinGW) ( let # https://src.fedoraproject.org/rpms/mingw-python3 diff --git a/pkgs/development/interpreters/python/default.nix b/pkgs/development/interpreters/python/default.nix index 53e73fa79c49..c8d9b5940083 100644 --- a/pkgs/development/interpreters/python/default.nix +++ b/pkgs/development/interpreters/python/default.nix @@ -20,10 +20,10 @@ sourceVersion = { major = "3"; minor = "13"; - patch = "13"; + patch = "14"; suffix = ""; }; - hash = "sha256-Krkf9AF4PMymT3XRDIgulXvf1g4r9acvhCF5Nym3inE="; + hash = "sha256-Y55DJDxiCjCPloIT354A8vj2IzL3rbqnp+65eDBXxpA="; }; }; @@ -79,10 +79,10 @@ sourceVersion = { major = "3"; minor = "14"; - patch = "4"; + patch = "6"; suffix = ""; }; - hash = "sha256-2SPFEwPjjiSRNvwb3zVo1W7LAyFO/e9IUWF209f6rvg="; + hash = "sha256-FDsd3e+uw70uIeO4ObNKK3+5hCJyiDxXZCDWBenzDGM="; inherit passthruFun; }; diff --git a/pkgs/development/interpreters/python/mk-python-derivation.nix b/pkgs/development/interpreters/python/mk-python-derivation.nix index 6dd3651bfa30..bc44a7de7178 100644 --- a/pkgs/development/interpreters/python/mk-python-derivation.nix +++ b/pkgs/development/interpreters/python/mk-python-derivation.nix @@ -48,6 +48,8 @@ let optionalString removePrefix stringLength + all + seq ; leftPadName = @@ -263,10 +265,10 @@ lib.extendMkDerivation { checkDrv = attrName: drv: - if (isPythonModule drv) && (isMismatchedPython drv) then throwMismatch attrName drv else drv; + if isPythonModule drv && isMismatchedPython drv then throwMismatch attrName drv else true; in - attrName: map (checkDrv attrName); + attrName: inputs: seq (all (checkDrv attrName) inputs) inputs; isBootstrapInstallPackage = isBootstrapInstallPackage' (finalAttrs.pname or null); diff --git a/pkgs/development/libraries/acl/default.nix b/pkgs/development/libraries/acl/default.nix index 9bba05fd90bf..99b12db67122 100644 --- a/pkgs/development/libraries/acl/default.nix +++ b/pkgs/development/libraries/acl/default.nix @@ -13,11 +13,11 @@ stdenv.mkDerivation rec { pname = "acl"; - version = "2.3.2"; + version = "2.4.0"; src = fetchurl { url = "mirror://savannah/acl/acl-${version}.tar.gz"; - hash = "sha256-XyvbrWKXB6p9hcYj+ZSqih0t7FWnPeUgW6wL9gWKL3w="; + hash = "sha256-c8hTw9ROH2k+WpaphvG9GdPQ2sLH1FPnlhd3dLxOX2o="; }; outputs = [ diff --git a/pkgs/development/libraries/attr/default.nix b/pkgs/development/libraries/attr/default.nix index f2e057a33058..10891ece56a8 100644 --- a/pkgs/development/libraries/attr/default.nix +++ b/pkgs/development/libraries/attr/default.nix @@ -12,11 +12,11 @@ stdenv.mkDerivation rec { pname = "attr"; - version = "2.5.2"; + version = "2.6.0"; src = fetchurl { url = "mirror://savannah/attr/attr-${version}.tar.gz"; - sha256 = "sha256-Ob9nRS+kHQlIwhl2AQU/SLPXigKTiXNDMqYwmmgMbIc="; + hash = "sha256-1C+jdFExgLtIyxGkZpb0iCQOUST/HmrYiwq/9waYVhI="; }; outputs = [ @@ -29,11 +29,6 @@ stdenv.mkDerivation rec { nativeBuildInputs = [ gettext ]; - # tools/attr.c: Add missing libgen.h include for basename(3) - # Fixes compilation issue with musl and modern C99 compilers. - # See: https://bugs.gentoo.org/926294 - patches = [ ./musl.patch ]; - postPatch = '' for script in install-sh include/install-sh; do patchShebangs $script diff --git a/pkgs/development/libraries/attr/musl.patch b/pkgs/development/libraries/attr/musl.patch deleted file mode 100644 index 818161f15243..000000000000 --- a/pkgs/development/libraries/attr/musl.patch +++ /dev/null @@ -1,27 +0,0 @@ -From 8a80d895dfd779373363c3a4b62ecce5a549efb2 Mon Sep 17 00:00:00 2001 -From: "Haelwenn (lanodan) Monnier" -Date: Sat, 30 Mar 2024 10:17:10 +0100 -Subject: tools/attr.c: Add missing libgen.h include for basename(3) - -Fixes compilation issue with musl and modern C99 compilers. - -See: https://bugs.gentoo.org/926294 ---- - tools/attr.c | 1 + - 1 file changed, 1 insertion(+) - -diff --git a/tools/attr.c b/tools/attr.c -index f12e4af..6a3c1e9 100644 ---- a/tools/attr.c -+++ b/tools/attr.c -@@ -28,6 +28,7 @@ - #include - #include - #include -+#include - - #include - --- -cgit v1.1 - diff --git a/pkgs/development/libraries/ffmpeg/default.nix b/pkgs/development/libraries/ffmpeg/default.nix index 5baddb0c34e2..ba90e4832369 100644 --- a/pkgs/development/libraries/ffmpeg/default.nix +++ b/pkgs/development/libraries/ffmpeg/default.nix @@ -30,8 +30,8 @@ let hash = "sha256-DjmW5LeI9OJmPeIh61znAns4+kolxwKguEvKawgxy8I="; }; v8 = { - version = "8.1.1"; - hash = "sha256-WPGfjTZjsgpR5QiANRWF4g6LF2ejGzFQUrLjhzw9cfQ="; + version = "8.1.2"; + hash = "sha256-wJ3c8VVo/tK84K7bKYs/UWcln4mSO+tf/w5NLNjKhiI="; }; in diff --git a/pkgs/development/libraries/libxml2/default.nix b/pkgs/development/libraries/libxml2/default.nix index af86f01f877d..b19728125580 100644 --- a/pkgs/development/libraries/libxml2/default.nix +++ b/pkgs/development/libraries/libxml2/default.nix @@ -61,6 +61,13 @@ let tag = "v${packages.libxml2.version}"; hash = "sha256-fDntZDyITs223by8n7ueOXiO7yyzshtANoWbY0+yeqo="; }; + extraPatches = [ + (fetchpatch { + name = "CVE-2026-11979.patch"; + url = "https://gitlab.gnome.org/GNOME/libxml2/-/commit/c2e233fc1b341685fc99621b2768b503f777a72e.patch"; + hash = "sha256-s7hnAW7r4fbb95WnFHhUMZbMJzTynV7umKIqc7Kdp/Q="; + }) + ]; extraMeta = { maintainers = with lib.maintainers; [ jtojnar diff --git a/pkgs/development/libraries/openssl/default.nix b/pkgs/development/libraries/openssl/default.nix index 13d4d2b5358a..7b9a221cc2d1 100644 --- a/pkgs/development/libraries/openssl/default.nix +++ b/pkgs/development/libraries/openssl/default.nix @@ -506,8 +506,8 @@ in }; openssl_3_6 = common { - version = "3.6.2"; - hash = "sha256-qvUaH+BkOE+BHa6utOxNznNA7IvYkwJ+7mdq8x6DoE8="; + version = "3.6.3"; + hash = "sha256-JDqGZJz28j7rai/yRW4J5dd92QGKVNPZawxr3Wumx/E="; patches = [ # Support for NIX_SSL_CERT_FILE, motivation: diff --git a/pkgs/development/libraries/poppler/default.nix b/pkgs/development/libraries/poppler/default.nix index 686d4a3715e3..5e5d94f2aa34 100644 --- a/pkgs/development/libraries/poppler/default.nix +++ b/pkgs/development/libraries/poppler/default.nix @@ -4,6 +4,7 @@ fetchurl, fetchFromGitLab, cairo, + clang-tools, cmake, boost, curl, @@ -55,13 +56,13 @@ let domain = "gitlab.freedesktop.org"; owner = "poppler"; repo = "test"; - rev = "9d5011815a14c157ba25bb160187842fb81579a5"; - hash = "sha256-sA5f235IJpzzzHqpwHM3zCZC2Yh0ztA6PZa84j/6tfY="; + rev = "f0068e9c530017ad811d1f28b95f9b7f59264e37"; + hash = "sha256-Xf8duSh0r1o09b5BKB7mBvzrMfXYlzTuTOuK2ZCeItc="; }; in stdenv.mkDerivation (finalAttrs: { pname = "poppler-${suffix}"; - version = "25.10.0"; # beware: updates often break cups-filters build, check scribus too! + version = "26.06.0"; # beware: updates often break cups-filters build, check scribus too! outputs = [ "out" @@ -70,7 +71,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "https://poppler.freedesktop.org/poppler-${finalAttrs.version}.tar.xz"; - hash = "sha256-a16btk2rsVeHoU2xZ1KRx6+vk4dDjMk6T7f2rsTub+A="; + hash = "sha256-TLTlo9yMte7HUciiPIuhn2H5be3AzQfSruawyOLPa6Q="; }; nativeBuildInputs = [ @@ -81,6 +82,13 @@ stdenv.mkDerivation (finalAttrs: { ] ++ lib.optionals (!minimal) [ glib # for glib-mkenums + ] + ++ lib.optionals stdenv.cc.isClang [ + # Pick up the `clang-scan-deps` wrapper for CMake; see: + # + # * + # * + clang-tools ]; buildInputs = [ @@ -129,18 +137,22 @@ stdenv.mkDerivation (finalAttrs: { (mkFlag qt5Support "QT5") (mkFlag qt6Support "QT6") (mkFlag gpgmeSupport "GPGME") - ] - ++ lib.optionals finalAttrs.finalPackage.doCheck [ - "-DTESTDATADIR=${testData}" ]; disallowedReferences = lib.optional finalAttrs.finalPackage.doCheck testData; dontWrapQtApps = true; - # Workaround #54606 - preConfigure = lib.optionalString stdenv.hostPlatform.isDarwin '' - sed -i -e '1i cmake_policy(SET CMP0025 NEW)' CMakeLists.txt - ''; + preConfigure = + lib.optionalString finalAttrs.finalPackage.doCheck '' + # The test data directory needs to be writable during the test phase. + mkdir -p $TMPDIR/testdata + cp -r --no-preserve=mode ${testData}/* $TMPDIR/testdata + cmakeFlagsArray+=(-DTESTDATADIR=$TMPDIR/testdata) + '' + + lib.optionalString stdenv.hostPlatform.isDarwin '' + # Workaround #54606 + sed -i -e '1i cmake_policy(SET CMP0025 NEW)' CMakeLists.txt + ''; # Work around gpgme trying to write to $HOME during qt5 and qt6 tests: preCheck = lib.optionalString gpgmeSupport '' diff --git a/pkgs/development/libraries/science/chemistry/simple-dftd3/default.nix b/pkgs/development/libraries/science/chemistry/simple-dftd3/default.nix index 1310bf160d8b..ce76e5c599d3 100644 --- a/pkgs/development/libraries/science/chemistry/simple-dftd3/default.nix +++ b/pkgs/development/libraries/science/chemistry/simple-dftd3/default.nix @@ -64,9 +64,6 @@ stdenv.mkDerivation rec { ]; doCheck = true; - preCheck = '' - export OMP_NUM_THREADS=2 - ''; meta = { description = "Reimplementation of the DFT-D3 program"; diff --git a/pkgs/development/libraries/science/chemistry/tblite/default.nix b/pkgs/development/libraries/science/chemistry/tblite/default.nix index bd40a12cea03..db3734562e15 100644 --- a/pkgs/development/libraries/science/chemistry/tblite/default.nix +++ b/pkgs/development/libraries/science/chemistry/tblite/default.nix @@ -88,10 +88,6 @@ stdenv.mkDerivation rec { doCheck = buildType == "meson"; - preCheck = '' - export OMP_NUM_THREADS=2 - ''; - meta = { description = "Light-weight tight-binding framework"; mainProgram = "tblite"; diff --git a/pkgs/development/libraries/science/math/openblas/default.nix b/pkgs/development/libraries/science/math/openblas/default.nix index 7e34c047f1a5..79677623f776 100644 --- a/pkgs/development/libraries/science/math/openblas/default.nix +++ b/pkgs/development/libraries/science/math/openblas/default.nix @@ -4,6 +4,11 @@ fetchFromGitHub, fetchpatch, cmake, + # sets OPENBLAS_NUM_THREADS and OMP_NUM_THREADS for packages + # invoking openblas during checkPhase/installCheckPhase to + # avoid overloading builders with excessive parallelism + # See also: https://github.com/OpenMathLib/OpenBLAS/blob/e7b45174355edec1f04de1cabcf5ca6a98ea7fbc/USAGE.md#how-can-i-use-openblas-in-multi-threaded-applications + checkPhaseThreadLimitHook, # Most packages depending on openblas expect integer width to match # pointer width, but some expect to use 32-bit integers always # (for compatibility with reference BLAS). @@ -232,6 +237,10 @@ stdenv.mkDerivation (finalAttrs: { cmake ]; + propagatedNativeBuildInputs = [ + checkPhaseThreadLimitHook + ]; + buildInputs = lib.optional (stdenv.cc.isClang && config.USE_OPENMP) openmp; depsBuildBuild = [ diff --git a/pkgs/development/python-modules/asgiref/default.nix b/pkgs/development/python-modules/asgiref/default.nix index 727587c610cd..516fb48f8b5f 100644 --- a/pkgs/development/python-modules/asgiref/default.nix +++ b/pkgs/development/python-modules/asgiref/default.nix @@ -5,22 +5,25 @@ fetchFromGitHub, pytest-asyncio, pytestCheckHook, + setuptools, typing-extensions, }: -buildPythonPackage rec { - version = "3.11.0"; +buildPythonPackage (finalAttrs: { + version = "3.11.1"; pname = "asgiref"; - format = "setuptools"; + pyproject = true; src = fetchFromGitHub { owner = "django"; repo = "asgiref"; - tag = version; - hash = "sha256-2ZaUIWGF5cQVNj95b7WiKGsn2wYsoJmJ/CfPhIEZdjc="; + tag = finalAttrs.version; + hash = "sha256-Mhnaowgv5a+O2hN0ZSdtdhCBQx8HoKSwtRC3gHodgKY="; }; - propagatedBuildInputs = [ typing-extensions ]; + build-system = [ setuptools ]; + + dependencies = [ typing-extensions ]; nativeCheckInputs = [ pytestCheckHook @@ -34,10 +37,10 @@ buildPythonPackage rec { pythonImportsCheck = [ "asgiref" ]; meta = { - changelog = "https://github.com/django/asgiref/blob/${src.tag}/CHANGELOG.txt"; + changelog = "https://github.com/django/asgiref/blob/${finalAttrs.src.tag}/CHANGELOG.txt"; description = "Reference ASGI adapters and channel layers"; homepage = "https://github.com/django/asgiref"; license = lib.licenses.bsd3; - maintainers = [ ]; + maintainers = with lib.maintainers; [ miniharinn ]; }; -} +}) diff --git a/pkgs/development/python-modules/astropy/default.nix b/pkgs/development/python-modules/astropy/default.nix index 639e234acbb0..94376d603d5e 100644 --- a/pkgs/development/python-modules/astropy/default.nix +++ b/pkgs/development/python-modules/astropy/default.nix @@ -143,10 +143,6 @@ buildPythonPackage rec { preCheck = '' export HOME="$(mktemp -d)" - export OMP_NUM_THREADS=$(( $NIX_BUILD_CORES / 4 )) - if [ $OMP_NUM_THREADS -eq 0 ]; then - export OMP_NUM_THREADS=1 - fi # See https://github.com/astropy/astropy/issues/17649 and see # --hypothesis-profile=ci pytest flag below. diff --git a/pkgs/development/python-modules/beets/default.nix b/pkgs/development/python-modules/beets/default.nix index e0eb7ef3f293..b915dd3f15eb 100644 --- a/pkgs/development/python-modules/beets/default.nix +++ b/pkgs/development/python-modules/beets/default.nix @@ -59,6 +59,7 @@ aacgain, beautifulsoup4, chromaprint, + dbus-python, discogs-client, ffmpeg, flac, @@ -88,6 +89,7 @@ extraNativeBuildInputs ? [ ], # tests + doCheck ? true, pytestCheckHook, pytest-cov-stub, pytest-factoryboy, @@ -194,6 +196,8 @@ buildPythonPackage (finalAttrs: { ] ++ finalAttrs.finalPackage.passthru.plugins.wrapperBins; + inherit doCheck; + __darwinAllowLocalNetworking = true; disabledTestPaths = @@ -275,7 +279,11 @@ buildPythonPackage (finalAttrs: { bench.testPaths = [ ]; bpd = { }; bpm.testPaths = [ ]; - bpsync.testPaths = [ ]; + bpsync = { + # plugin retired: https://github.com/beetbox/beets/issues/3862. + deprecated = true; + testPaths = [ ]; + }; bucket = { }; chroma = { propagatedBuildInputs = [ pyacoustid ]; @@ -288,10 +296,15 @@ buildPythonPackage (finalAttrs: { propagatedBuildInputs = [ requests ]; testPaths = [ ]; }; - discogs.propagatedBuildInputs = [ - discogs-client - requests - ]; + discogs = { + propagatedBuildInputs = [ + discogs-client + requests + ]; + singlePluginTest.config = { + user_token = "test"; + }; + }; duplicates.testPaths = [ ]; edit = { }; embedart = { @@ -334,7 +347,10 @@ buildPythonPackage (finalAttrs: { testPaths = [ ]; }; limit = { }; - listenbrainz = { }; + listenbrainz.singlePluginTest.config = { + token = "test"; + username = "test"; + }; loadext = { propagatedBuildInputs = [ requests ]; testPaths = [ ]; @@ -348,7 +364,10 @@ buildPythonPackage (finalAttrs: { mbsubmit = { }; mbsync = { }; mbpseudo = { }; - metasync.testPaths = [ ]; + metasync = { + propagatedBuildInputs = [ dbus-python ]; + testPaths = [ ]; + }; missing.testPaths = [ ]; mpdstats.propagatedBuildInputs = [ mpd2 ]; mpdupdate = { @@ -363,11 +382,14 @@ buildPythonPackage (finalAttrs: { plexupdate = { }; random = { }; replace = { }; - replaygain.wrapperBins = [ - aacgain - ffmpeg - mp3gain - ]; + replaygain = { + singlePluginTest.config.backend = "gstreamer"; + wrapperBins = [ + aacgain + ffmpeg + mp3gain + ]; + }; rewrite.testPaths = [ ]; scrub.testPaths = [ ]; smartplaylist = { }; @@ -375,7 +397,10 @@ buildPythonPackage (finalAttrs: { propagatedBuildInputs = [ soco ]; testPaths = [ ]; }; - spotify = { }; + spotify.singlePluginTest.setup = '' + mkdir -p $HOME/.config/beets + echo '{"access_token":"test"}' > $HOME/.config/beets/spotify_token.json + ''; subsonicplaylist = { propagatedBuildInputs = [ requests ]; testPaths = [ ]; @@ -384,7 +409,7 @@ buildPythonPackage (finalAttrs: { substitute = { testPaths = [ ]; }; - tidal = { }; + tidal.propagatedBuildInputs = [ requests-oauthlib ]; the = { }; titlecase.propagatedBuildInputs = [ titlecase ]; thumbnails = { @@ -416,23 +441,24 @@ buildPythonPackage (finalAttrs: { lib.throwIf (finalAttrs.finalPackage.passthru.plugins.builtins.${plugName}.deprecated or false) "beets evaluation error: Plugin ${plugName} was enabled in pluginOverrides, but it has been removed. Remove the override to fix evaluation." ) pluginOverrides; - all = - lib.mapAttrs - ( - n: a: - { - name = n; - enable = !disableAllPlugins; - builtin = false; - propagatedBuildInputs = [ ]; - testPaths = [ "test/plugins/test_${n}.py" ]; - wrapperBins = [ ]; - } - // a - ) - ( - lib.recursiveUpdate finalAttrs.finalPackage.passthru.plugins.base finalAttrs.finalPackage.passthru.plugins.overrides - ); + all = lib.pipe finalAttrs.finalPackage.passthru.plugins.base [ + (base: lib.recursiveUpdate base finalAttrs.finalPackage.passthru.plugins.overrides) + (lib.mapAttrs ( + n: a: + lib.recursiveUpdate { + name = n; + enable = !disableAllPlugins; + builtin = false; + propagatedBuildInputs = [ ]; + singlePluginTest = { + config = { }; + setup = ""; + }; + testPaths = [ "test/plugins/test_${n}.py" ]; + wrapperBins = [ ]; + } a + )) + ]; enabled = lib.filterAttrs (_: p: p.enable) finalAttrs.finalPackage.passthru.plugins.all; disabled = lib.filterAttrs (_: p: !p.enable) finalAttrs.finalPackage.passthru.plugins.all; disabledTestPaths = lib.flatten ( @@ -443,23 +469,6 @@ buildPythonPackage (finalAttrs: { ); }; tests = { - gstreamer = - runCommand "beets-gstreamer-test" - { - meta.timeout = 60; - } - '' - set -euo pipefail - export HOME=$(mktemp -d) - mkdir $out - - cat << EOF > $out/config.yaml - replaygain: - backend: gstreamer - EOF - - ${finalAttrs.finalPackage}/bin/beet -c $out/config.yaml > /dev/null - ''; with-new-builtin-plugin = finalAttrs.finalPackage.overrideAttrs ( newAttrs: oldAttrs: { postPatch = (oldAttrs.postPatch or "") + '' @@ -497,7 +506,66 @@ buildPythonPackage (finalAttrs: { -c $out/config.yaml \ mpdstats --help 2> $out/mpdstats-help-stderr || true ''; - }; + } + # Build and start beets once for each supported built-in plugin. Keeping the + # plugins isolated makes missing optional dependencies visible. + // lib.pipe finalAttrs.finalPackage.passthru.plugins.all [ + # Deprecated plugins are not useful regression targets. + (lib.filterAttrs (_: pluginAttrs: !(pluginAttrs.deprecated or false))) + (lib.concatMapAttrs ( + pluginName: pluginAttrs: + let + testConfig = { + plugins = [ pluginName ]; + } + # Some plugins do not accept an empty attribute set as config. + // lib.optionalAttrs (pluginAttrs.singlePluginTest.config != { }) { + ${pluginName} = pluginAttrs.singlePluginTest.config; + }; + beetsWithSinglePlugin = beets.override { + disableAllPlugins = true; + pluginOverrides = { + ${pluginName}.enable = true; + }; + # The runCommand below is the relevant check; avoid running + # the full upstream test suite once per plugin. NOTE that + # testing whether any plugin's `testPaths` is incorrect, is + # done for all plugins via the `beets-minimal` derivation. + doCheck = false; + }; + in + { + "with-single-plugin-${pluginName}" = beetsWithSinglePlugin; + "single-plugin-${pluginName}" = runCommand "beets-single-plugin-${pluginName}-test" { } '' + set -euo pipefail + export HOME=$(mktemp -d) + ${pluginAttrs.singlePluginTest.setup} + mkdir $out + + cat <<'EOF' > $out/config.yaml + ${lib.generators.toYAML { } testConfig} + EOF + + status=0 + ${lib.getExe beetsWithSinglePlugin} \ + -c "$out/config.yaml" \ + --help > "$out/stdout" 2> "$out/stderr" || status=$? + + # beet exits successfully when a plugin fails to load, so its + # stderr must also be checked for the diagnostic. + if (( status != 0 )) || grep -Fq "error loading plugin" "$out/stderr"; then + { + printf '%s\n' '----- stdout -----' + cat "$out/stdout" + printf '%s\n' '----- stderr -----' + cat "$out/stderr" + } >&2 + exit 1 + fi + ''; + } + )) + ]; }; meta = { @@ -509,6 +577,7 @@ buildPythonPackage (finalAttrs: { doronbehar lovesegfault pjones + staticdev ]; platforms = lib.platforms.linux ++ lib.platforms.darwin; mainProgram = "beet"; diff --git a/pkgs/development/python-modules/cfn-lint/default.nix b/pkgs/development/python-modules/cfn-lint/default.nix index 70a2968acfe8..a14902531efa 100644 --- a/pkgs/development/python-modules/cfn-lint/default.nix +++ b/pkgs/development/python-modules/cfn-lint/default.nix @@ -74,6 +74,8 @@ buildPythonPackage rec { "test/integration/test_quickstart_templates.py::TestQuickStartTemplates::test_templates" "test/integration/test_quickstart_templates_non_strict.py::TestQuickStartTemplates::test_module_integration" "test/integration/test_quickstart_templates_non_strict.py::TestQuickStartTemplates::test_templates" + "test/integration/test_good_templates.py::TestQuickStartTemplates::test_module_integration" + "test/integration/test_good_templates.py::TestQuickStartTemplates::test_templates" ]; pythonImportsCheck = [ "cfnlint" ]; diff --git a/pkgs/development/python-modules/django/5.nix b/pkgs/development/python-modules/django/5.nix index 273b61da19c9..74dff79704f1 100644 --- a/pkgs/development/python-modules/django/5.nix +++ b/pkgs/development/python-modules/django/5.nix @@ -41,14 +41,14 @@ buildPythonPackage rec { pname = "django"; - version = "5.2.15"; + version = "5.2.16"; pyproject = true; src = fetchFromGitHub { owner = "django"; repo = "django"; tag = version; - hash = "sha256-K9yFHr3IkVNMqoeumESszVlju2fW2r8hS8z6M2OdVpE="; + hash = "sha256-DZa3OkqnrgXp1A/HerKYdUdanvi5jxHndo1DV4RVs0M="; }; patches = [ diff --git a/pkgs/development/python-modules/django/6.nix b/pkgs/development/python-modules/django/6.nix index 4b6e54569b85..b6cb92b964e9 100644 --- a/pkgs/development/python-modules/django/6.nix +++ b/pkgs/development/python-modules/django/6.nix @@ -42,7 +42,7 @@ buildPythonPackage (finalAttrs: { pname = "django"; - version = "6.0.6"; + version = "6.0.7"; pyproject = true; disabled = pythonOlder "3.12"; @@ -51,7 +51,7 @@ buildPythonPackage (finalAttrs: { owner = "django"; repo = "django"; tag = finalAttrs.version; - hash = "sha256-hLnTqY64PfaGJ1JJccrxYms41Jp4E4pVq6rmrtFpESE="; + hash = "sha256-B28twwEGLcXV0TlQxgRhNBiKhwJd+5f7sL35SkHAkRY="; }; patches = [ diff --git a/pkgs/development/python-modules/dogpile-cache/default.nix b/pkgs/development/python-modules/dogpile-cache/default.nix index ebea5ee74068..42bfe3fae843 100644 --- a/pkgs/development/python-modules/dogpile-cache/default.nix +++ b/pkgs/development/python-modules/dogpile-cache/default.nix @@ -7,9 +7,7 @@ pytestCheckHook, mako, decorator, - stdenv, stevedore, - typing-extensions, }: buildPythonPackage rec { @@ -28,7 +26,6 @@ buildPythonPackage rec { dependencies = [ decorator stevedore - typing-extensions ]; nativeCheckInputs = [ @@ -37,24 +34,11 @@ buildPythonPackage rec { pytestCheckHook ]; - disabledTestPaths = lib.optionals stdenv.hostPlatform.isLinux [ + disabledTestPaths = [ # flaky "tests/cache/test_dbm_backend.py" - ]; - - disabledTests = lib.optionals stdenv.hostPlatform.isDarwin [ - # AssertionError: != 'some value 1' - "test_expire_override" - # flaky - "test_get_value_plus_created_long_create" - "test_get_value_plus_created_registry_safe_cache_quick" - "test_get_value_plus_created_registry_safe_cache_slow" - "test_get_value_plus_created_registry_unsafe_cache" - "test_quick" - "test_region_set_get_value" - "test_region_set_multiple_values" - "test_return_while_in_progress" - "test_slow" + # timing sensitive + "tests/test_lock.py::ConcurrencyTest" ]; meta = { diff --git a/pkgs/development/python-modules/geometric/default.nix b/pkgs/development/python-modules/geometric/default.nix index ec1553e164ab..08301b669d5c 100644 --- a/pkgs/development/python-modules/geometric/default.nix +++ b/pkgs/development/python-modules/geometric/default.nix @@ -28,10 +28,6 @@ buildPythonPackage rec { six ]; - preCheck = '' - export OMP_NUM_THREADS=2 - ''; - nativeCheckInputs = [ pytestCheckHook ]; meta = { diff --git a/pkgs/development/python-modules/idna/default.nix b/pkgs/development/python-modules/idna/default.nix index 9d4cbee7e5a1..c6c917852319 100644 --- a/pkgs/development/python-modules/idna/default.nix +++ b/pkgs/development/python-modules/idna/default.nix @@ -8,14 +8,14 @@ buildPythonPackage rec { pname = "idna"; - version = "3.13"; + version = "3.15"; pyproject = true; src = fetchFromGitHub { owner = "kjd"; repo = "idna"; tag = "v${version}"; - hash = "sha256-D72KUEwiFA/LdU/xE3sN+Abc6NpAsIlGSdB07V1nk68="; + hash = "sha256-z3Nd834inihGzquCAmejUQvRcM0Yn/VmMcWQP3oh4ak="; }; build-system = [ flit-core ]; diff --git a/pkgs/development/python-modules/imread/default.nix b/pkgs/development/python-modules/imread/default.nix index a26b89fb2b02..bc0934f5bd7c 100644 --- a/pkgs/development/python-modules/imread/default.nix +++ b/pkgs/development/python-modules/imread/default.nix @@ -49,7 +49,6 @@ buildPythonPackage rec { preCheck = '' cd $TMPDIR export HOME=$TMPDIR - export OMP_NUM_THREADS=1 ''; meta = { diff --git a/pkgs/development/python-modules/joblib/default.nix b/pkgs/development/python-modules/joblib/default.nix index 2474439fc910..b4b9c7bf2217 100644 --- a/pkgs/development/python-modules/joblib/default.nix +++ b/pkgs/development/python-modules/joblib/default.nix @@ -5,6 +5,14 @@ pythonAtLeast, stdenv, + # sets various thread limit env vars for packages + # invoking joblib during checkPhase/installCheckPhase to + # avoid overloading builders with excessive parallelism + # See also: + # https://github.com/joblib/joblib/blob/b030e4e1ed6a227c0e587c31b266c03b3b692372/joblib/_parallel_backends.py#L59-L67 + # https://github.com/joblib/joblib/blob/b030e4e1ed6a227c0e587c31b266c03b3b692372/joblib/_parallel_backends.py#L221-L248 + checkPhaseThreadLimitHook, + # build-system setuptools, @@ -40,6 +48,14 @@ buildPythonPackage rec { threadpoolctl ]; + propagatedNativeBuildInputs = [ + checkPhaseThreadLimitHook + ]; + + # joblib expects to set thread limits itself while checking for propagation of thread limit environment variables. + # Setting these via checkPhaseThreadLimitHook on joblib itself causes tests to fail, but we do want the hook to propagate. + dontLimitCheckPhaseThreads = true; + enabledTestPaths = [ "joblib/test" ]; disabledTests = [ diff --git a/pkgs/development/python-modules/joserfc/default.nix b/pkgs/development/python-modules/joserfc/default.nix index 342a93b6bd00..a31a8bc44e94 100644 --- a/pkgs/development/python-modules/joserfc/default.nix +++ b/pkgs/development/python-modules/joserfc/default.nix @@ -16,14 +16,14 @@ buildPythonPackage rec { pname = "joserfc"; - version = "1.6.1"; + version = "1.6.9"; pyproject = true; src = fetchFromGitHub { owner = "authlib"; repo = "joserfc"; tag = version; - hash = "sha256-druh7ybcQBjTxUFMVLUwknw/aa/fyrUdS4ftS/ftYeA="; + hash = "sha256-Ge1r34GVmpJ9h5GtRkPd0mkV7HuLf7D31ikuPAnpkuY="; }; build-system = [ setuptools ]; diff --git a/pkgs/development/python-modules/jq/default.nix b/pkgs/development/python-modules/jq/default.nix index 01c93b61a9fe..39fc694fa546 100644 --- a/pkgs/development/python-modules/jq/default.nix +++ b/pkgs/development/python-modules/jq/default.nix @@ -38,6 +38,7 @@ buildPythonPackage rec { disabledTests = [ # tries to match exact error text, fails with jq 1.8 "test_value_error_is_raised_if_program_is_invalid" + "test_value_error_is_raised_if_input_cannot_be_processed_by_program" ]; pythonImportsCheck = [ "jq" ]; diff --git a/pkgs/development/python-modules/mistune/default.nix b/pkgs/development/python-modules/mistune/default.nix index 8cdfa4023ded..99f3922ee0fa 100644 --- a/pkgs/development/python-modules/mistune/default.nix +++ b/pkgs/development/python-modules/mistune/default.nix @@ -8,14 +8,14 @@ buildPythonPackage rec { pname = "mistune"; - version = "3.2.1"; + version = "3.3.2"; pyproject = true; src = fetchFromGitHub { owner = "lepture"; repo = "mistune"; tag = "v${version}"; - hash = "sha256-8AEEh/SWAk/Esq0jAoZGLw1FIQUw6C5Xq8CgnI2fjv0="; + hash = "sha256-uyOJFtDvVn0Y3VypphOXsSW3pX5XVCcfQ7dtFiL/5qY="; }; build-system = [ setuptools ]; diff --git a/pkgs/development/python-modules/mypy/default.nix b/pkgs/development/python-modules/mypy/default.nix index bbbbb99d5e96..9040eab9ebf8 100644 --- a/pkgs/development/python-modules/mypy/default.nix +++ b/pkgs/development/python-modules/mypy/default.nix @@ -13,8 +13,10 @@ types-psutil, types-setuptools, - # propagates + # nativeBuildInputs + propagates librt, + + # propagates mypy-extensions, tomli, typing-extensions, @@ -50,6 +52,10 @@ buildPythonPackage rec { rev-prefix = "v"; }; + nativeBuildInputs = [ + librt + ]; + build-system = [ mypy-extensions pathspec diff --git a/pkgs/development/python-modules/numba/default.nix b/pkgs/development/python-modules/numba/default.nix index 506f0e10dfd6..014c8da0f02c 100644 --- a/pkgs/development/python-modules/numba/default.nix +++ b/pkgs/development/python-modules/numba/default.nix @@ -9,6 +9,12 @@ # nativeBuildInputs setuptools, + # sets NUMBA_NUM_THREADS and OMP_NUM_THREADS for packages + # invoking numba during checkPhase/installCheckPhase to + # avoid overloading builders with excessive parallelism + # See also: https://numba.readthedocs.io/en/stable/reference/envvars.html#threading-control + checkPhaseThreadLimitHook, + # dependencies llvmlite, numpy, @@ -114,6 +120,10 @@ buildPythonPackage (finalAttrs: { writableTmpDirAsHomeHook ]; + propagatedNativeBuildInputs = [ + checkPhaseThreadLimitHook + ]; + # https://github.com/NixOS/nixpkgs/issues/255262 preCheck = '' cd $out diff --git a/pkgs/development/python-modules/numexpr/default.nix b/pkgs/development/python-modules/numexpr/default.nix index f4b552c108ec..39c0a4e673af 100644 --- a/pkgs/development/python-modules/numexpr/default.nix +++ b/pkgs/development/python-modules/numexpr/default.nix @@ -3,8 +3,14 @@ buildPythonPackage, fetchPypi, numpy, + pytest-run-parallel, pytestCheckHook, setuptools, + # sets NUMEXPR_NUM_THREADS and OMP_NUM_THREADS for packages + # invoking numexpr during checkPhase/installCheckPhase to + # avoid overloading builders with excessive parallelism + # See also: https://numexpr.readthedocs.io/en/latest/user_guide.html#threadpool-configuration + checkPhaseThreadLimitHook, }: buildPythonPackage rec { @@ -29,7 +35,17 @@ buildPythonPackage rec { ln -s ${numpy.cfg} site.cfg ''; - nativeCheckInputs = [ pytestCheckHook ]; + nativeCheckInputs = [ + pytest-run-parallel + pytestCheckHook + ]; + + propagatedNativeBuildInputs = [ + checkPhaseThreadLimitHook + ]; + + # tests check for OMP_NUM_THREADS application and complete quick enough + env.dontLimitCheckPhaseThreads = 1; preCheck = '' pushd $out diff --git a/pkgs/development/python-modules/numpy/1.nix b/pkgs/development/python-modules/numpy/1.nix index 4fc274257916..c1c9cb2bed6e 100644 --- a/pkgs/development/python-modules/numpy/1.nix +++ b/pkgs/development/python-modules/numpy/1.nix @@ -18,6 +18,8 @@ blas, lapack, + checkPhaseThreadLimitHook, + # Reverse dependency sage, @@ -93,7 +95,6 @@ buildPythonPackage (finalAttrs: { # see https://github.com/OpenMathLib/OpenBLAS/issues/2993 preConfigure = '' sed -i 's/-faltivec//' numpy/distutils/system_info.py - export OMP_NUM_THREADS=$((NIX_BUILD_CORES > 64 ? 64 : NIX_BUILD_CORES)) ''; preBuild = '' @@ -110,6 +111,10 @@ buildPythonPackage (finalAttrs: { typing-extensions ]; + propagatedNativeBuildInputs = [ + checkPhaseThreadLimitHook + ]; + preCheck = '' cd "$out" ''; diff --git a/pkgs/development/python-modules/numpy/2.nix b/pkgs/development/python-modules/numpy/2.nix index 67c60475fd5f..5e0c15993a56 100644 --- a/pkgs/development/python-modules/numpy/2.nix +++ b/pkgs/development/python-modules/numpy/2.nix @@ -19,6 +19,8 @@ coreutils, lapack, + checkPhaseThreadLimitHook, + # Reverse dependency sage, @@ -86,12 +88,8 @@ buildPythonPackage (finalAttrs: { ] ++ lib.optionals (!stdenv.buildPlatform.canExecute stdenv.hostPlatform) [ mesonEmulatorHook ]; - # we default openblas to build with 64 threads - # if a machine has more than 64 threads, it will segfault - # see https://github.com/OpenMathLib/OpenBLAS/issues/2993 preConfigure = '' sed -i 's/-faltivec//' numpy/distutils/system_info.py - export OMP_NUM_THREADS=$((NIX_BUILD_CORES > 64 ? 64 : NIX_BUILD_CORES)) ''; buildInputs = [ @@ -113,6 +111,10 @@ buildPythonPackage (finalAttrs: { typing-extensions ]; + propagatedNativeBuildInputs = [ + checkPhaseThreadLimitHook + ]; + preCheck = '' pushd $out # For numpy-config executable to be available during tests diff --git a/pkgs/development/python-modules/oslo-i18n/default.nix b/pkgs/development/python-modules/oslo-i18n/default.nix index 3cad5136d858..50fd28dcb0c5 100644 --- a/pkgs/development/python-modules/oslo-i18n/default.nix +++ b/pkgs/development/python-modules/oslo-i18n/default.nix @@ -41,8 +41,8 @@ buildPythonPackage rec { runHook preCheck stestr run -e <(echo " - # test counts warnings which no longer matches in python 3.11 - oslo_i18n.tests.test_message.MessageTestCase.test_translate_message_bad_translation + # list is not deduped + oslo_i18n.tests.test_gettextutils.GettextTest.test_get_available_languages ") runHook postCheck diff --git a/pkgs/development/python-modules/paho-mqtt/default.nix b/pkgs/development/python-modules/paho-mqtt/default.nix index b0ea0015bb42..1d71451e962b 100644 --- a/pkgs/development/python-modules/paho-mqtt/default.nix +++ b/pkgs/development/python-modules/paho-mqtt/default.nix @@ -3,9 +3,11 @@ stdenv, buildPythonPackage, fetchFromGitHub, + fetchpatch, hatchling, openssl, pytestCheckHook, + writableTmpDirAsHomeHook, }: let @@ -28,10 +30,13 @@ buildPythonPackage rec { hash = "sha256-VMq+WTW+njK34QUUTE6fR2j2OmHxVzR0wrC92zYb1rY="; }; - postPatch = '' - substituteInPlace tests/ssl/gen.sh \ - --replace-fail "c_rehash certs" "#c_rehash certs" - ''; + patches = [ + (fetchpatch { + name = "generate-ssl-certs-in-a-test-fixture.patch"; + url = "https://github.com/eclipse-paho/paho.mqtt.python/pull/931.diff"; + hash = "sha256-A7rWwpR4PnCi77F1VqsQKHBxHNrdeHgmVM6BGMeUpjs="; + }) + ]; build-system = [ hatchling @@ -40,6 +45,7 @@ buildPythonPackage rec { nativeCheckInputs = [ openssl pytestCheckHook + writableTmpDirAsHomeHook ]; __darwinAllowLocalNetworking = true; @@ -51,10 +57,6 @@ buildPythonPackage rec { # paho.mqtt not in top-level dir to get caught by this export PYTHONPATH=".:$PYTHONPATH" - - pushd tests/ssl - HOME="$(mktemp -d)" ./gen.sh - popd ''; disabledTests = [ diff --git a/pkgs/development/python-modules/pillow/default.nix b/pkgs/development/python-modules/pillow/default.nix index e2c0b2eb75ad..e19a87b695eb 100644 --- a/pkgs/development/python-modules/pillow/default.nix +++ b/pkgs/development/python-modules/pillow/default.nix @@ -42,14 +42,14 @@ buildPythonPackage rec { pname = "pillow"; - version = "12.2.0"; + version = "12.3.0"; pyproject = true; src = fetchFromGitHub { owner = "python-pillow"; repo = "pillow"; tag = version; - hash = "sha256-7w6FbZLTAoUMvLtSPvafk3wSRv8TrkAAfgZ/dfu3HpA="; + hash = "sha256-kmUlgR+f75Y8DAKKPdEbchLLgg0m95oyVP53WTQni88="; }; build-system = [ diff --git a/pkgs/development/python-modules/pyarrow/default.nix b/pkgs/development/python-modules/pyarrow/default.nix index 9f4366c6685d..51841a10d6fc 100644 --- a/pkgs/development/python-modules/pyarrow/default.nix +++ b/pkgs/development/python-modules/pyarrow/default.nix @@ -134,6 +134,12 @@ buildPythonPackage rec { "pyarrow/tests/test_udf.py::test_scalar_input" "pyarrow/tests/test_udf.py::test_scalar_udf_context" "pyarrow/tests/test_udf.py::test_udf_array_unary" + # CSV pickle mismatches + "pyarrow/tests/test_csv.py::TestThreadedStreamingCSVRead::test_invalid_row_handler[" + "pyarrow/tests/test_csv.py::TestThreadedStreamingCSVRead::test_row_number_offset_in_errors" + "pyarrow/tests/test_csv.py::TestThreadedStreamingCSVRead::test_row_number_offset_in_errors" + # Does not raise NotImplementedError + "pyarrow/tests/test_table.py::test_table_group_by_first" ] ++ lib.optionals stdenv.hostPlatform.isDarwin [ # Requires loopback networking. diff --git a/pkgs/development/python-modules/pycurl/default.nix b/pkgs/development/python-modules/pycurl/default.nix index 49be840bf8f9..c7c32e9e20d3 100644 --- a/pkgs/development/python-modules/pycurl/default.nix +++ b/pkgs/development/python-modules/pycurl/default.nix @@ -4,19 +4,21 @@ buildPythonPackage, isPyPy, fetchFromGitHub, - fetchpatch, + fetchpatch2, curl, openssl, bottle, pytestCheckHook, flaky, flask, + numpy, + websockets, setuptools, }: buildPythonPackage rec { pname = "pycurl"; - version = "7.45.6"; + version = "7.46.0"; pyproject = true; disabled = isPyPy; # https://github.com/pycurl/pycurl/issues/208 @@ -25,21 +27,14 @@ buildPythonPackage rec { owner = "pycurl"; repo = "pycurl"; tag = "REL_${lib.replaceStrings [ "." ] [ "_" ] version}"; - hash = "sha256-M4rO0CaI2SmjdJVS7hWnJZrL72WvayB4aKn707KoNiQ="; + hash = "sha256-F40bJ7TYFK2dVkDJGGxl7XV46fKmjwvUYYulcwGL6hk="; }; patches = [ - # curl 8.16 compatibility - (fetchpatch { - url = "https://github.com/pycurl/pycurl/commit/eb7f52eeef85feb6c117678d52803050bbdd7bc8.patch"; - hash = "sha256-hdwazS7R9duuMd/7S3SNAxVcToo3GhtyWu/1Q6qTMYc="; - }) - # curl 8.17+ compatibility - # https://github.com/pycurl/pycurl/pull/909 - (fetchpatch { - name = "pycurl-8.17.0-compat.patch"; - url = "https://github.com/pycurl/pycurl/commit/ea92e3ca230a3ff3d464cb6816102fa157177aca.patch"; - hash = "sha256-kmlsG0SFfS9FdRNp8pPgudcWK6hSyD9x5oAedZLgBcY="; + (fetchpatch2 { + name = "pycurl-curl-8.21.0-ws-support.patch"; + url = "https://github.com/pycurl/pycurl/commit/c78fd8aba82e2f8037275063138eaa7706c111af.diff?full_index=1"; + hash = "sha256-EBXgGiaMtXTsgJOOrzzZFJ7Q/ofAlc4zuipoEpfdFqU="; }) ]; @@ -64,6 +59,8 @@ buildPythonPackage rec { bottle flaky flask + numpy + websockets pytestCheckHook ]; @@ -90,24 +87,15 @@ buildPythonPackage rec { "test_libcurl_ssl_gnutls" # AssertionError: assert 'crypto' in ['curl'] "test_ssl_in_static_libs" - # https://github.com/pycurl/pycurl/issues/819 - "test_multi_socket_select" - ] - ++ lib.optionals stdenv.hostPlatform.isDarwin [ - # https://github.com/pycurl/pycurl/issues/729 - "test_easy_pause_unpause" - "test_multi_socket_action" + # expected socketp to be None again after unassign() + "test_clear_via_assign_none_inside_callback_resets_socketp" + "test_multi_unassign_inside_socket_callback" ] ++ lib.optionals (stdenv.hostPlatform.isDarwin && stdenv.hostPlatform.isAarch64) [ # Fatal Python error: Segmentation fault "cadata_test" ]; - disabledTestPaths = [ - # https://github.com/pycurl/pycurl/issues/856 - "tests/multi_test.py" - ]; - meta = { description = "Python Interface To The cURL library"; homepage = "http://pycurl.io/"; diff --git a/pkgs/development/python-modules/pygobject/3.nix b/pkgs/development/python-modules/pygobject/3.nix index b912d6b04bb8..c728dbbbd82c 100644 --- a/pkgs/development/python-modules/pygobject/3.nix +++ b/pkgs/development/python-modules/pygobject/3.nix @@ -17,7 +17,7 @@ buildPythonPackage rec { pname = "pygobject"; - version = "3.56.2"; + version = "3.56.3"; outputs = [ "out" @@ -28,7 +28,7 @@ buildPythonPackage rec { src = fetchurl { url = "mirror://gnome/sources/pygobject/${lib.versions.majorMinor version}/pygobject-${version}.tar.gz"; - hash = "sha256-uBYJiWlUQIHenuztuUrWrFnHfk1XH+cFHxi+vOwHQxM="; + hash = "sha256-EnYOSg49BLbrleBveifjYsgm1WfqYTNzqSwAO2xw0tY="; }; depsBuildBuild = [ pkg-config ]; diff --git a/pkgs/development/python-modules/pyscf/default.nix b/pkgs/development/python-modules/pyscf/default.nix index 9028317762b5..8444a005e775 100644 --- a/pkgs/development/python-modules/pyscf/default.nix +++ b/pkgs/development/python-modules/pyscf/default.nix @@ -61,7 +61,6 @@ buildPythonPackage { preCheck = '' # Set config used by tests to ensure reproducibility echo 'pbc_tools_pbc_fft_engine = "NUMPY"' > pyscf/pyscf_config.py - export OMP_NUM_THREADS=1 ulimit -s 20000 export PYSCF_CONFIG_FILE=$(pwd)/pyscf/pyscf_config.py ''; diff --git a/pkgs/development/python-modules/qutip/default.nix b/pkgs/development/python-modules/qutip/default.nix index 89e77b995785..aa968f51180d 100644 --- a/pkgs/development/python-modules/qutip/default.nix +++ b/pkgs/development/python-modules/qutip/default.nix @@ -62,7 +62,6 @@ buildPythonPackage (finalAttrs: { # This is due to the Cython-compiled modules not being in the correct location # of the source tree. preCheck = '' - export OMP_NUM_THREADS=$NIX_BUILD_CORES mkdir -p test && cd test ''; diff --git a/pkgs/development/python-modules/scikit-learn/default.nix b/pkgs/development/python-modules/scikit-learn/default.nix index b48f5a5d8f72..bf50ab0b7a63 100644 --- a/pkgs/development/python-modules/scikit-learn/default.nix +++ b/pkgs/development/python-modules/scikit-learn/default.nix @@ -116,7 +116,6 @@ buildPythonPackage rec { preCheck = '' cd $TMPDIR export HOME=$TMPDIR - export OMP_NUM_THREADS=1 ''; pythonImportsCheck = [ "sklearn" ]; diff --git a/pkgs/development/python-modules/scipy/default.nix b/pkgs/development/python-modules/scipy/default.nix index cdecd986e4ef..30999320f1e8 100644 --- a/pkgs/development/python-modules/scipy/default.nix +++ b/pkgs/development/python-modules/scipy/default.nix @@ -190,11 +190,6 @@ buildPythonPackage (finalAttrs: { ''; preCheck = '' - export OMP_NUM_THREADS=$(( $NIX_BUILD_CORES / 4 )) - if [ $OMP_NUM_THREADS -eq 0 ]; then - export OMP_NUM_THREADS=1 - fi - cd $out ''; diff --git a/pkgs/development/python-modules/tornado/default.nix b/pkgs/development/python-modules/tornado/default.nix index 4327db46ac9e..2cd462786b20 100644 --- a/pkgs/development/python-modules/tornado/default.nix +++ b/pkgs/development/python-modules/tornado/default.nix @@ -18,16 +18,16 @@ urllib3, }: -buildPythonPackage rec { +buildPythonPackage (finalAttrs: { pname = "tornado"; - version = "6.5.4"; + version = "6.5.7"; pyproject = true; src = fetchFromGitHub { owner = "tornadoweb"; repo = "tornado"; - tag = "v${version}"; - hash = "sha256-d6lKg8yrQqaCeKxdPjQNzv7Nc23U/v8d5x3sE3trRM4="; + tag = "v${finalAttrs.version}"; + hash = "sha256-iE0Tf95zmPoZJhw7FDLzTmv8HaWds3ZU5xzZSMvxFH4="; }; build-system = [ setuptools ]; @@ -63,9 +63,10 @@ buildPythonPackage rec { }; meta = { + changelog = "https://www.tornadoweb.org/en/stable/releases/${finalAttrs.src.tag}.html"; description = "Web framework and asynchronous networking library"; homepage = "https://www.tornadoweb.org/"; license = lib.licenses.asl20; maintainers = [ ]; }; -} +}) diff --git a/pkgs/development/tools/analysis/radare2/default.nix b/pkgs/development/tools/analysis/radare2/default.nix index 0819a899a1dd..2a5f4b29e7ed 100644 --- a/pkgs/development/tools/analysis/radare2/default.nix +++ b/pkgs/development/tools/analysis/radare2/default.nix @@ -25,6 +25,7 @@ vte, xxhash, zlib, + zydis, useX11 ? false, rubyBindings ? false, luaBindings ? false, @@ -40,8 +41,8 @@ let sdb = fetchFromGitHub { owner = "radareorg"; repo = "sdb"; - tag = "2.4.2"; # https://github.com/radareorg/radare2/blob/master/subprojects/sdb.wrap - hash = "sha256-JN27SkDqHtX83d1CPUF9hbVKwE/dwhDgn5MlCX9RPrc="; + tag = "2.4.6"; # https://github.com/radareorg/radare2/blob/master/subprojects/sdb.wrap + hash = "sha256-5DuHC5uL4gXBJPGW2awDq/5Ufdi1RoEJnm+eAU3X8S4="; }; qjs = fetchFromGitHub { @@ -53,13 +54,13 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "radare2"; - version = "6.1.4"; + version = "6.1.8"; src = fetchFromGitHub { owner = "radare"; repo = "radare2"; tag = finalAttrs.version; - hash = "sha256-3MwBtjR3XQMhbJHnD30OVedUEKcje5jDPszNynkGCT8="; + hash = "sha256-Gh+W0vWsIscbew1u5cuOXWC20azCxYuA7D+qVTkfEN0="; }; mesonFlags = [ @@ -69,6 +70,7 @@ stdenv.mkDerivation (finalAttrs: { (lib.mesonBool "use_sys_openssl" true) (lib.mesonBool "use_sys_xxhash" true) (lib.mesonBool "use_sys_zip" true) + (lib.mesonBool "use_sys_zydis" true) (lib.mesonBool "use_sys_zlib" true) (lib.mesonOption "r2_gittap" finalAttrs.version) ]; @@ -97,6 +99,7 @@ stdenv.mkDerivation (finalAttrs: { perl readline zlib + zydis ] ++ lib.optionals useX11 [ gtkdialog diff --git a/pkgs/development/web/nodejs/nodejs.nix b/pkgs/development/web/nodejs/nodejs.nix index 0b07ab24a688..2b8d3d51efaa 100644 --- a/pkgs/development/web/nodejs/nodejs.nix +++ b/pkgs/development/web/nodejs/nodejs.nix @@ -144,7 +144,7 @@ let ); useSharedNBytes = lib.versionAtLeast version (if majorVersion == 24 then "24.14.0" else "25.5"); useSharedLief = lib.versionAtLeast version "25.6"; - useSharedMerve = lib.versionAtLeast version (if majorVersion == 24 then "24.14.0" else "25.6.1"); + useSharedMerve = lib.versionAtLeast version (if majorVersion == "24" then "24.14.0" else "25.6.1"); useSharedSQLite = lib.versionAtLeast version "22.5"; useSharedTemporal = majorVersion == "26"; useSharedZstd = lib.versionAtLeast version "22.15"; @@ -190,7 +190,8 @@ let inherit nbytes; }) // (lib.optionalAttrs useSharedMerve { - inherit merve; + # Merve cannot be built with simdutf_6, and upstream also disables simdutf support on the 24.x branch + merve = if majorVersion == "24" then (merve.override { simdutf = null; }) else merve; }) // (lib.optionalAttrs useSharedZstd { inherit zstd; @@ -347,9 +348,7 @@ let dontDisableStatic = true; - configureScript = writeScript "nodejs-configure" '' - exec ${python.executable} configure.py "$@" - ''; + configureScript = "${python.interpreter} configure.py"; # In order to support unsupported cross configurations, we copy some intermediate executables # from a native build and replace all the build-system tools with a script which simply touches @@ -518,12 +517,6 @@ let "test-tick-processor-arguments" "test-set-raw-mode-reset-signal" ] - # Apple SDK update broke something related to those tests, so skipping them for now - ++ lib.optionals (majorVersion == "24" && stdenv.hostPlatform.isDarwin) [ - "test-worker-track-unmanaged-fds" - "test-esm-import-meta-main-eval" - "test-worker-debug" - ] # These network/fetch/inspector tests fail on riscv64 ++ lib.optionals (majorVersion == "24" && stdenv.hostPlatform.isRiscV64) [ "test-fetch" @@ -684,6 +677,9 @@ let done ''; + # reduces build time from ~90 to ~15 minutes on hydra + requiredSystemFeatures = [ "big-parallel" ]; + passthru.tests = { version = testers.testVersion { package = self; diff --git a/pkgs/development/web/nodejs/v24.nix b/pkgs/development/web/nodejs/v24.nix index 914ab1479370..3388b484ebe8 100644 --- a/pkgs/development/web/nodejs/v24.nix +++ b/pkgs/development/web/nodejs/v24.nix @@ -9,10 +9,16 @@ }: let - buildNodejs = callPackage ./nodejs.nix { - inherit openssl; - python = python3; - }; + buildNodejs = callPackage ./nodejs.nix ( + { + inherit openssl; + python = python3; + } + // lib.optionalAttrs stdenv.hostPlatform.isDarwin { + # libcxx21 makes FD tracking unreliable on Darwin. Pinning to libcxx20: + stdenv = buildPackages.llvmPackages_20.libcxxStdenv; + } + ); gypPatches = if stdenv.buildPlatform.isDarwin then @@ -23,8 +29,8 @@ let [ ]; in buildNodejs { - version = "24.16.0"; - sha256 = "2ff84a6de70b6165290111b0fc656ded1ad207a799816fe720cc7c31232df30f"; + version = "24.18.0"; + sha256 = "e94afde24db08e0c564ee7110a2d5aab51ee0059382c9fd8233c54eec47b28f9"; patches = ( if (stdenv.hostPlatform.emulatorAvailable buildPackages) then @@ -56,13 +62,6 @@ buildNodejs { ./use-correct-env-in-tests.patch ./bin-sh-node-run-v22.patch ./use-nix-codesign.patch - - # Patch for nghttp2 1.69 support - (fetchpatch2 { - url = "https://github.com/nodejs/node/commit/4a32c00fb8dbe55c3bcf9ef43343968c9fe449e6.diff?full_index=1"; - hash = "sha256-pex8ruwa4b/vWvfGA+nyN3JJP8NOturmwAQe4Rkd6nU="; - excludes = [ "tools/nix/*" ]; - }) ] ++ gypPatches ++ lib.optionals (!stdenv.buildPlatform.isDarwin) [ diff --git a/pkgs/os-specific/linux/minimal-bootstrap/gnugrep/static.nix b/pkgs/os-specific/linux/minimal-bootstrap/gnugrep/static.nix index 69f8dadd22ab..749d2d68e8a5 100644 --- a/pkgs/os-specific/linux/minimal-bootstrap/gnugrep/static.nix +++ b/pkgs/os-specific/linux/minimal-bootstrap/gnugrep/static.nix @@ -78,5 +78,4 @@ bash.runCommand "${pname}-${version}" # Install make -j $NIX_BUILD_CORES install-strip - rm $out/bin/{egrep,fgrep} '' diff --git a/pkgs/os-specific/linux/zfs/2_3.nix b/pkgs/os-specific/linux/zfs/2_3.nix index bf6701cc0ff8..34e173e12d78 100644 --- a/pkgs/os-specific/linux/zfs/2_3.nix +++ b/pkgs/os-specific/linux/zfs/2_3.nix @@ -16,7 +16,7 @@ callPackage ./generic.nix args { kernelMaxSupportedMajorMinor = "7.0"; # this package should point to the latest release. - version = "2.3.7"; + version = "2.3.8"; tests = { inherit (nixosTests.zfs) series_2_3; @@ -30,5 +30,5 @@ callPackage ./generic.nix args { amarshall ]; - hash = "sha256-67Yo5bAJP3dXC94xybrC4xhwz7pGtrp0MUT9P6OInog="; + hash = "sha256-qNBInNRpWrmImcermSHC0emYmnnjNvxWj3QnGtA6SUg="; } diff --git a/pkgs/os-specific/linux/zfs/2_4.nix b/pkgs/os-specific/linux/zfs/2_4.nix index 80d3cb8e8487..7de7664f4dff 100644 --- a/pkgs/os-specific/linux/zfs/2_4.nix +++ b/pkgs/os-specific/linux/zfs/2_4.nix @@ -16,7 +16,7 @@ callPackage ./generic.nix args { kernelMaxSupportedMajorMinor = "7.0"; # this package should point to the latest release. - version = "2.4.2"; + version = "2.4.3"; extraPatches = [ # https://github.com/openzfs/zfs/issues/18366 @@ -39,5 +39,5 @@ callPackage ./generic.nix args { amarshall ]; - hash = "sha256-OqsKHzyFjjyX8CoajDGydY4TbuQqMA37PIaEOL+vDug="; + hash = "sha256-I1wLbstr0cFiGsyynP9kJ9ATRp/2b+fnnsdz0up+IzM="; } diff --git a/pkgs/os-specific/linux/zfs/generic.nix b/pkgs/os-specific/linux/zfs/generic.nix index 1dc98829da38..ea017985f78e 100644 --- a/pkgs/os-specific/linux/zfs/generic.nix +++ b/pkgs/os-specific/linux/zfs/generic.nix @@ -4,7 +4,6 @@ let lib, stdenv, fetchFromGitHub, - fetchpatch2, autoreconfHook269, util-linux, nukeReferences, @@ -100,12 +99,7 @@ let inherit rev hash; }; - patches = - extraPatches - ++ lib.optional (kernel != null && lib.versionOlder kernel.version "5.14") (fetchpatch2 { - url = "https://github.com/openzfs/zfs/commit/58c8dc5f6926eb96903a3f38b141e8998ef9261b.patch?full_index=1"; - hash = "sha256-eYkMhHsHBA9MKXnB/GuHpuv44g1SCGV5Or0InPBeNkU="; - }); + patches = extraPatches; postPatch = optionalString buildKernel '' diff --git a/pkgs/os-specific/linux/zfs/unstable.nix b/pkgs/os-specific/linux/zfs/unstable.nix index f72e792a16c0..dfc43de1c33e 100644 --- a/pkgs/os-specific/linux/zfs/unstable.nix +++ b/pkgs/os-specific/linux/zfs/unstable.nix @@ -16,14 +16,14 @@ callPackage ./generic.nix args { # IMPORTANT: Always use a tagged release candidate or commits from the # zfs--staging branch, because this is tested by the OpenZFS # maintainers. - version = "2.4.2"; + version = "2.4.3"; # rev = ""; tests = { inherit (nixosTests.zfs) unstable; }; - hash = "sha256-OqsKHzyFjjyX8CoajDGydY4TbuQqMA37PIaEOL+vDug="; + hash = "sha256-I1wLbstr0cFiGsyynP9kJ9ATRp/2b+fnnsdz0up+IzM="; extraLongDescription = '' This is "unstable" ZFS, and will usually be a pre-release version of ZFS. diff --git a/pkgs/tools/compression/gzip/CVE-2026-41991.patch b/pkgs/tools/compression/gzip/CVE-2026-41991.patch new file mode 100644 index 000000000000..657d8553bcd2 --- /dev/null +++ b/pkgs/tools/compression/gzip/CVE-2026-41991.patch @@ -0,0 +1,52 @@ +From 4e6f8b24ab823146ab8776f0b7fe486ab34d4269 Mon Sep 17 00:00:00 2001 +From: Paul Eggert +Date: Thu, 16 Apr 2026 12:11:44 -0700 +Subject: gzexe: use -C if lacking mktemp +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +(Problem reported by Michał Majchrowicz.) +* gzexe.in: If mktemp is needed but not installed, +use ‘set -C’ to avoid a race when creating a temporary file. +* zdiff.in: Use the same pattern here, even though the old +code was probably OK anyway. +--- + gzexe.in | 1 + + zdiff.in | 7 +++---- + 2 files changed, 4 insertions(+), 4 deletions(-) + +diff --git a/gzexe.in b/gzexe.in +index ea4ef94..f3d46cc 100644 +--- a/gzexe.in ++++ b/gzexe.in +@@ -127,6 +127,7 @@ for i do + tmp=`mktemp "${dir}gzexeXXXXXXXXX"` + else + tmp=${dir}gzexe$$ ++ (umask 77; set -C; > "$tmp") + fi && { cp -p "$file" "$tmp" 2>/dev/null || cp "$file" "$tmp"; } || { + res=$? + printf >&2 '%s\n' "$0: cannot copy $file" +diff --git a/zdiff.in b/zdiff.in +index 289e466..53266df 100644 +--- a/zdiff.in ++++ b/zdiff.in +@@ -156,12 +156,11 @@ case $file2 in + *) TMPDIR=/tmp/;; + esac + if command -v mktemp >/dev/null 2>&1; then +- tmp=`mktemp "${TMPDIR}zdiffXXXXXXXXX"` || +- exit 2 ++ tmp=`mktemp "${TMPDIR}zdiffXXXXXXXXX"` + else +- set -C + tmp=${TMPDIR}zdiff$$ +- fi ++ (umask 77; set -C; > "$tmp") ++ fi && + 'gzip' -cdfq -- "$file2" > "$tmp" || exit 2 + gzip_status=$( + exec 4>&1 +-- +cgit v1.2.3 diff --git a/pkgs/tools/compression/gzip/CVE-2026-41992.patch b/pkgs/tools/compression/gzip/CVE-2026-41992.patch new file mode 100644 index 000000000000..f7576a2b7872 --- /dev/null +++ b/pkgs/tools/compression/gzip/CVE-2026-41992.patch @@ -0,0 +1,35 @@ +From 63dbf6b3b9e6e781df1a6a64e609b10e23969681 Mon Sep 17 00:00:00 2001 +From: Paul Eggert +Date: Wed, 15 Apr 2026 12:00:17 -0700 +Subject: gzip: don’t mishandle .lzh after .Z +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Problem reported by Michał Majchrowicz. +* unlzh.c (read_c_len): Clear left and right when n == 0. +--- + unlzh.c | 6 ++++++ + 1 file changed, 6 insertions(+) + +(limited to 'unlzh.c') + +diff --git a/unlzh.c b/unlzh.c +index 3320196..a6cf109 100644 +--- a/unlzh.c ++++ b/unlzh.c +@@ -232,6 +232,12 @@ read_c_len () + c = getbits(CBIT); + for (i = 0; i < NC; i++) c_len[i] = 0; + for (i = 0; i < 4096; i++) c_table[i] = c; ++ ++ /* Needed in case LEFT and RIGHT are reused from a previous ++ LZW decompression. It may be overkill to clear all of both ++ arrays, but nobody has had time to analyze this carefully. */ ++ memzero(left, (2 * NC - 1) * sizeof *left); ++ memzero(right, (2 * NC - 1) * sizeof *left); + } else { + i = 0; + while (i < n) { +-- +cgit v1.3 diff --git a/pkgs/tools/compression/gzip/default.nix b/pkgs/tools/compression/gzip/default.nix index 446e5fab0af8..6aafcf6481df 100644 --- a/pkgs/tools/compression/gzip/default.nix +++ b/pkgs/tools/compression/gzip/default.nix @@ -25,6 +25,11 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-Aae4gb0iC/32Ffl7hxj4C9/T9q3ThbmT3Pbv0U6MCsY="; }; + patches = [ + ./CVE-2026-41991.patch + ./CVE-2026-41992.patch + ]; + outputs = [ "out" "man" diff --git a/pkgs/tools/package-management/lix/common-lix.nix b/pkgs/tools/package-management/lix/common-lix.nix index d5277055efd2..fdd550e8c8d1 100644 --- a/pkgs/tools/package-management/lix/common-lix.nix +++ b/pkgs/tools/package-management/lix/common-lix.nix @@ -39,6 +39,7 @@ assert lib.assertMsg ( darwin, doxygen, editline, + fetchpatch2, flex, git, gtest, @@ -127,16 +128,24 @@ let substitute $inputPath $out --replace-fail @deps@ "$(cat ${deps})" ''; - # https://github.com/NixOS/nixpkgs/pull/525953 backported a performance patch - # that /somehow/ breaks Lix unit tests. - # FIXME revert when the patch is gone in curl drv + # curl 8.21.0 /somehow/ breaks Lix unit tests. + # See https://github.com/NixOS/nixpkgs/issues/534713 + # FIXME remove once fixed curl-fixed = curl.overrideAttrs ( { patches ? [ ], ... }: { - patches = lib.filter (patch: !lib.strings.hasSuffix "fix-wakeup-consumption.patch" patch) patches; + patches = patches ++ [ + # See https://github.com/curl/curl/commit/2a2104f3cff44bb28bb570a093be52bbeeed8f23 + (fetchpatch2 { + name = "fix-wakeup-consumption-revert.patch"; + url = "https://github.com/curl/curl/commit/2a2104f3cff44bb28bb570a093be52bbeeed8f23.patch"; + hash = "sha256-dkwr1ZaR7XB408JxeIKhuHxJrlwf3J01jL6lnOLXo1I="; + revert = true; + }) + ]; } ); in diff --git a/pkgs/tools/package-management/nix/modular/tests/functional/package.nix b/pkgs/tools/package-management/nix/modular/tests/functional/package.nix index b8bf89d99f7f..597c89f08c4d 100644 --- a/pkgs/tools/package-management/nix/modular/tests/functional/package.nix +++ b/pkgs/tools/package-management/nix/modular/tests/functional/package.nix @@ -73,14 +73,6 @@ mkMesonDerivation (finalAttrs: { echo $PWD | grep tests/functional ''; - # Test contains invocation of `script` broken by util-linux regression: - # https://github.com/util-linux/util-linux/commit/70507ab9eaed10b8dd77b77d4ea25c11ee726bed - preCheck = - assert util-linux.version == "2.42"; - '' - echo "exit 77" > ../json.sh - ''; - mesonCheckFlags = [ "--print-errorlogs" ]; diff --git a/pkgs/tools/text/gnused/default.nix b/pkgs/tools/text/gnused/default.nix index 6effd6d9f41d..7f1cfe514425 100644 --- a/pkgs/tools/text/gnused/default.nix +++ b/pkgs/tools/text/gnused/default.nix @@ -8,11 +8,11 @@ stdenv.mkDerivation rec { pname = "gnused"; - version = "4.9"; + version = "4.10"; src = fetchurl { url = "mirror://gnu/sed/sed-${version}.tar.xz"; - sha256 = "sha256-biJrcy4c1zlGStaGK9Ghq6QteYKSLaelNRljHSSXUYE="; + sha256 = "sha256-uOchgrLslqNXTimYxHt6qmTMIM4ADY6awxPMB87PKMc="; }; outputs = [ diff --git a/pkgs/top-level/aliases.nix b/pkgs/top-level/aliases.nix index 3f1c9c5e6f23..9554fbc038a0 100644 --- a/pkgs/top-level/aliases.nix +++ b/pkgs/top-level/aliases.nix @@ -1629,6 +1629,7 @@ mapAliases { openjfx23 = throw "OpenJFX 23 was removed as it has reached its end of life"; # Added 2025-11-04 openjfx24 = throw "OpenJFX 24 was removed as it has reached its end of life"; # Added 2025-10-04 openmodelica = throw "'openmodelica' has been removed as it was unmaintained in nixpkgs and depends on insecure&unmtaintained qtwebkit"; # Added 2026-04-26 + openmpCheckPhaseHook = warnAlias "'openmpCheckPhaseHook' has been renamed to 'checkPhaseThreadLimitHook' to reflect its handling of all known thread-limiting mechanisms during check phase" checkPhaseThreadLimitHook; # Added 2026-07-09 openmw-tes3mp = throw "'openmw-tes3mp' has been removed due to lack of maintenance upstream"; # Added 2025-08-30 openssl_3_0 = throw "'openssl_3_0' has been renamed to/replaced by 'openssl_3'"; # Converted to throw 2025-10-27 opensycl = throw "'opensycl' has been renamed to/replaced by 'adaptivecpp'"; # Converted to throw 2025-10-27 diff --git a/pkgs/top-level/perl-packages.nix b/pkgs/top-level/perl-packages.nix index dfc6aad91108..d6568a86883c 100644 --- a/pkgs/top-level/perl-packages.nix +++ b/pkgs/top-level/perl-packages.nix @@ -18255,10 +18255,10 @@ with self; JavaScriptMinifierXS = buildPerlPackage { pname = "JavaScript-Minifier-XS"; - version = "0.15"; + version = "0.16"; src = fetchurl { - url = "mirror://cpan/authors/id/G/GT/GTERMARS/JavaScript-Minifier-XS-0.15.tar.gz"; - hash = "sha256-XZsDT1jwtv9bZGR708WpzgWypw7e4zn7wxc67nR8wFA="; + url = "mirror://cpan/authors/id/G/GT/GTERMARS/JavaScript-Minifier-XS-0.16.tar.gz"; + hash = "sha256-dQNOh2k568PdSM4uuvBgRLBu1XqzoYY/BT+VDphNmVQ="; }; buildInputs = [ TestDiagINC ]; meta = {