Merge release-26.05 into staging-nixos-26.05

This commit is contained in:
nixpkgs-ci[bot]
2026-09-20 00:32:53 +00:00
committed by GitHub
149 changed files with 4106 additions and 4993 deletions

View File

@@ -10100,6 +10100,12 @@
githubId = 2041764;
name = "Andreas Wendleder";
};
goobertony = {
github = "goobertony";
email = "tonygameing@proton.me";
githubId = 133613491;
name = "Tonii Bittersweet";
};
goodrone = {
email = "goodrone@gmail.com";
github = "goodrone";

View File

@@ -270,7 +270,7 @@ in
popd
'';
restartTriggers = lib.optional (!cfg.mutableConfig) [ printerConfig ];
restartTriggers = lib.optionals (!cfg.mutableConfig) [ printerConfig ];
serviceConfig = {
ExecStart = "${cfg.package}/bin/klippy ${klippyArgs} ${cfg.configDir}/printer.cfg";

View File

@@ -16,6 +16,7 @@ let
getExe
literalExpression
optional
optionals
attrValues
mapAttrs
;
@@ -158,7 +159,7 @@ in
"LOG_LEVEL=${cfg.logLevel}"
"PHX_SERVER=true"
]
++ optional cfg.selfhosted [ "RUN_CONTEXT=selfhosted" ]
++ optionals cfg.selfhosted [ "RUN_CONTEXT=selfhosted" ]
++ optional (!isNull config.time.timeZone) "TZ=${config.time.timeZone}"
++ attrValues (mapAttrs (name: value: name + "=" + toString value) cfg.extraConfig);
EnvironmentFile = optional (cfg.secretsFile != null) cfg.secretsFile;

View File

@@ -16,7 +16,7 @@ let
mapAttrs'
splitString
toUpper
optional
optionals
optionalAttrs
nameValuePair
;
@@ -145,7 +145,7 @@ in
LoadCredential = [
"RESTIC_PASSWORD_FILE:${cfg.passwordFile}"
]
++ optional (cfg.repositoryFile != null) [ "RESTIC_REPOSITORY:${cfg.repositoryFile}" ];
++ optionals (cfg.repositoryFile != null) [ "RESTIC_REPOSITORY:${cfg.repositoryFile}" ];
};
environment =
let

View File

@@ -152,7 +152,7 @@ in
startCLIList
++ lib.optionals (cfg.prometheusConfig != { }) [ "-promscrape.config=${prometheusConfigYml}" ]
);
LoadCredential = lib.optional (cfg.remoteWrite.basicAuthPasswordFile != null) [
LoadCredential = lib.optionals (cfg.remoteWrite.basicAuthPasswordFile != null) [
"remote_write_basic_auth_password:${cfg.remoteWrite.basicAuthPasswordFile}"
];
};

View File

@@ -133,7 +133,7 @@ in
# if data_dir is a list, the actual path will in in the `path` attribute of each item
# see https://garagehq.deuxfleurs.fr/documentation/reference-manual/configuration/#data_dir
++ lib.optional (lib.isList data_dir) (map (item: item.path) data_dir)
++ lib.optional (lib.isString data_dir) [ data_dir ]
++ lib.optionals (lib.isString data_dir) [ data_dir ]
);
isDefault = lib.hasPrefix "/var/lib/garage";
isDefaultStateDirectory = lib.any isDefault paths;

View File

@@ -1578,7 +1578,7 @@ in
SystemCallFilter = [
"~@cpu-emulation @debug @keyring @mount @obsolete @privileged @setuid"
]
++ optional cfg.enableQuicBPF [ "bpf" ];
++ optionals cfg.enableQuicBPF [ "bpf" ];
};
};

View File

@@ -271,7 +271,7 @@ in
"~CAP_SYS_BOOT"
"~CAP_NET_ADMIN"
]
++ lib.lists.optional (!cfg.allowCgiUser) [
++ lib.lists.optionals (!cfg.allowCgiUser) [
"~CAP_SETGID"
"~CAP_SETUID"
];
@@ -279,7 +279,7 @@ in
SystemCallFilter = [
"~@cpu-emulation @debug @keyring @mount @obsolete"
]
++ lib.lists.optional (!cfg.allowCgiUser) [ "@privileged @setuid" ];
++ lib.lists.optionals (!cfg.allowCgiUser) [ "@privileged @setuid" ];
};
};

View File

@@ -295,7 +295,7 @@ stdenv.mkDerivation (
dontConfigure = true;
noDumpEnvVars = true;
stripExclude = lib.optional hasVsceSign [
stripExclude = lib.optionals hasVsceSign [
# vsce-sign is a single executable application built with Node.js, and it becomes non-functional if stripped
"lib/vscode/resources/app/node_modules/@vscode/vsce-sign/bin/vsce-sign"
];

View File

@@ -185,7 +185,7 @@ mkDerivation rec {
"-DQGIS_MACAPP_BUNDLE=0" # Don't copy Qt into bundle; we fix paths in postFixup
"-DSQLITE3_INCLUDE_DIR=${sqlite.dev}/include" # FindSqlite3.cmake incorrectly assumes framework
]
++ lib.optional withServer [
++ lib.optionals withServer [
"-DWITH_SERVER=True"
"-DQGIS_CGIBIN_SUBDIR=${placeholder "out"}/lib/cgi-bin"
]

View File

@@ -190,7 +190,7 @@ stdenv.mkDerivation rec {
"-DSQLITE3_INCLUDE_DIR=${sqlite.dev}/include"
"-DUSE_OPENCL=OFF"
]
++ lib.optional withServer [
++ lib.optionals withServer [
"-DWITH_SERVER=True"
"-DQGIS_CGIBIN_SUBDIR=${placeholder "out"}/lib/cgi-bin"
]

View File

@@ -84,8 +84,8 @@ rec {
thunderbird = thunderbird-latest;
thunderbird-latest = common {
version = "155.0";
sha512 = "fe0247ac50d2741a49517fabe729dc990a66e7044f450e4fe6871b663096bcd15f22ed83eea0557106d38eee34e464fead5a7567d0906995ff2a945fae64b60c";
version = "156.0";
sha512 = "8fd524f9d622f007e9bd5e8bcc440f185427a928a04d3aae14fc476e011ff1c15b68607292624ea4c4e4d596722193dda88e233cdfb6bbf5d05bd180870532ba";
updateScript = callPackage ./update.nix {
attrPath = "thunderbirdPackages.thunderbird-latest";

View File

@@ -162,10 +162,10 @@ buildGoModule (finalAttrs: {
++ [
./rdpclient.patch
]
++ lib.optional (lib.versionOlder version "18.8.0") [
++ lib.optionals (lib.versionOlder version "18.8.0") [
./0001-fix-add-nix-path-to-exec-env.patch
]
++ lib.optional (lib.versionAtLeast version "18.8.0") [
++ lib.optionals (lib.versionAtLeast version "18.8.0") [
./0001-fix-add-nix-path-to-exec-env-reexec.patch
];

View File

@@ -192,7 +192,7 @@ stdenv.mkDerivation {
license =
with lib.licenses;
[ mit ]
++ lib.optional enableVCVRack [
++ lib.optionals enableVCVRack [
gpl3Plus
cc-by-nc-40
unfreeRedistributable

View File

@@ -69,7 +69,7 @@ stdenv.mkDerivation (finalAttrs: {
(lib.cmakeBool "STOP_BUILD_ON_WARNING" stdenv.hostPlatform.isLinux)
(lib.cmakeBool "INSTALL_VENDORED_LIBS" false)
]
++ lib.optional (stdenv.hostPlatform != stdenv.buildPlatform) [
++ lib.optionals (stdenv.hostPlatform != stdenv.buildPlatform) [
# Fix (RiscV) cross-compilation
# See https://github.com/apache/orc/issues/2334
(lib.cmakeFeature "HAS_PRE_1970_EXITCODE" "0")

View File

@@ -2,6 +2,7 @@
stdenv,
lib,
fetchurl,
fetchpatch,
fetchFromGitHub,
fixDarwinDylibNames,
apache-orc,
@@ -95,6 +96,16 @@ stdenv.mkDerivation (finalAttrs: {
sourceRoot = "${finalAttrs.src.name}/cpp";
patches = [
# Fix flaky test racing on (not) waiting for azurite
# https://github.com/apache/arrow/pull/50878
(fetchpatch {
url = "https://github.com/apache/arrow/commit/e6a89be6c7cc537b04844796bd84ac8240942050.patch";
hash = "sha256-hB2ebq6a64FPBZeg7aS+tSZZIzhFs3w9A3n2NK+/ob8=";
})
];
patchFlags = [ "-p2" ];
# versions are all taken from
# https://github.com/apache/arrow/blob/apache-arrow-${version}/cpp/thirdparty/versions.txt
@@ -316,7 +327,16 @@ stdenv.mkDerivation (finalAttrs: {
''
runHook preInstallCheck
ctest -L unittest --exclude-regex '^(${lib.concatStringsSep "|" disabledTests})$'
ctestArgs=(
-L unittest
--exclude-regex '^(${lib.concatStringsSep "|" disabledTests})$'
)
# Match ci/scripts/cpp_test.sh to fight flakiness.
# https://github.com/apache/arrow/issues/40121
ctestArgs+=(--repeat until-pass:3)
ctest "''${ctestArgs[@]}"
runHook postInstallCheck
'';

View File

@@ -21,7 +21,7 @@ stdenv.mkDerivation (finalAttrs: {
# upstream repo includes a build/ directory
cmakeBuildDir = "_build";
cmakeFlags = lib.optional asLibrary [
cmakeFlags = lib.optionals asLibrary [
"-DBUILD_SHARED_LIBS=ON"
];

View File

@@ -16,7 +16,7 @@
buildNpmPackage (finalAttrs: {
pname = "aurral";
version = "2.9.0";
version = "2.9.1";
__structuredAttrs = true;
@@ -24,7 +24,7 @@ buildNpmPackage (finalAttrs: {
owner = "lklynet";
repo = "aurral";
tag = "v${finalAttrs.version}";
hash = "sha256-pwk+efWL0dfvKiobRmGXgPtvunpRDOVbtxohbJamVqY=";
hash = "sha256-HiOcDvp+ZZozWPEoou0UJFsZAoql89q2WVZaj7fgVrs=";
};
# Specifies files to package leveraging npm & nix hooks. Not used by upstream.

View File

@@ -74,6 +74,7 @@ py.pkgs.buildPythonApplication rec {
--replace-fail 'prompt-toolkit>=3.0.24,<3.0.52' 'prompt-toolkit>=3.0.24' \
--replace-fail 'ruamel_yaml>=0.15.0,<=0.19.1' 'ruamel_yaml>=0.15.0' \
--replace-fail 'ruamel_yaml_clib>=0.2.0,<=0.2.15' 'ruamel_yaml_clib>=0.2.0' \
--replace-fail 'urllib3>=1.25.4,<=2.6.3' 'urllib3>=1.25.4' \
--replace-fail 'wcwidth<0.3.0' 'wcwidth>=0.3.0'
substituteInPlace requirements-base.txt \

View File

@@ -13,13 +13,13 @@
stdenvNoCC.mkDerivation (finalAttrs: {
pname = "bitsnpicas";
version = "2.2";
version = "2.2.2";
src = fetchFromGitHub {
owner = "kreativekorp";
repo = "bitsnpicas";
tag = "v${finalAttrs.version}";
hash = "sha256-TIpnefPLHgKXJfBhrYbYG+/kpHjWpk/VrJvu1LKHf4o=";
hash = "sha256-+LmAav7E5boKNVby4YusSqNGt4PSSnefxsF10O8/deo=";
};
nativeBuildInputs = [

View File

@@ -8,16 +8,16 @@
php83.buildComposerProject2 (finalAttrs: {
pname = "bookstack";
version = "26.05.4";
version = "26.05.5";
src = fetchFromGitHub {
owner = "bookstackapp";
repo = "bookstack";
tag = "v${finalAttrs.version}";
hash = "sha256-DDjJZehRUf1GP19S+RqhqZSSGOMF/SzItt2GFXi4+1U=";
hash = "sha256-9E0hewzzN4prXUOrokIY6vDZUttv1HpPEd2/sLc0mhM=";
};
vendorHash = "sha256-Ioth8Kp5fx4iwfy0p7N8xE0L41oWcp+ATfhmq3PUYyY=";
vendorHash = "sha256-usRZ70uiD54jlXkKcikvkNmFQbw7/r9F9Dg3QN/gdts=";
passthru = {
phpPackage = php83;

View File

@@ -42,7 +42,7 @@ stdenv.mkDerivation (finalAttrs: {
perl
];
cmakeFlags = lib.optional (!stdenv.hostPlatform.isx86) [
cmakeFlags = lib.optionals (!stdenv.hostPlatform.isx86) [
"-DCMAKE_CXX_FLAGS=-I${finalAttrs.src}/third_party"
];

View File

@@ -14,13 +14,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "bubblewrap";
version = "0.11.2";
version = "0.12.0";
src = fetchFromGitHub {
owner = "containers";
repo = "bubblewrap";
rev = "v${finalAttrs.version}";
hash = "sha256-MUjJMhJ8Q9sYQyGqA7zfMutYjMSZNmEHXs2H3WN4mbE=";
hash = "sha256-VnhJ5bej3/GTHcU8+AkyR7f3J0KKDuoc94SFxo4grhk=";
};
outputs = [
@@ -54,7 +54,7 @@ stdenv.mkDerivation (finalAttrs: {
changelog = "https://github.com/containers/bubblewrap/releases/tag/${finalAttrs.src.rev}";
description = "Unprivileged sandboxing tool";
homepage = "https://github.com/containers/bubblewrap";
license = lib.licenses.lgpl2Plus;
license = lib.licenses.lgpl21Plus;
maintainers = with lib.maintainers; [ dotlambda ];
platforms = lib.platforms.linux;
mainProgram = "bwrap";

View File

@@ -116,11 +116,11 @@ stdenv.mkDerivation rec {
);
NIX_CFLAGS_COMPILE = toString (
[ ]
++ lib.optional stdenv.cc.isGNU [
++ lib.optionals stdenv.cc.isGNU [
# Fix build with gcc15
"-std=gnu17"
]
++ lib.optional stdenv.cc.isClang [
++ lib.optionals stdenv.cc.isClang [
"-Wno-error=implicit-function-declaration"
]
);

View File

@@ -4,10 +4,13 @@
makeWrapper,
fetchzip,
nix-update-script,
nodejs,
testers,
nodejs-slim,
writableTmpDirAsHomeHook,
versionCheckHook,
}:
let
inherit (stdenvNoCC.hostPlatform.node) arch platform;
in
stdenvNoCC.mkDerivation (finalAttrs: {
pname = "copilot-language-server";
version = "1.495.0";
@@ -23,24 +26,44 @@ stdenvNoCC.mkDerivation (finalAttrs: {
];
buildInputs = [
nodejs
nodejs-slim
];
installPhase = ''
runHook preInstall
mkdir -p $out/share/copilot-language-server
cp -r ./* $out/share/copilot-language-server/
server=$out/share/copilot-language-server
makeWrapper ${lib.getExe nodejs} $out/bin/copilot-language-server \
mkdir -p $server
cp -r ./* $server/
find "$server/node_modules/@github" -mindepth 1 -maxdepth 1 \
\( -name 'copilot-linux-*' -o -name 'copilot-darwin-*' -o -name 'copilot-win32-*' \) \
! -name "copilot-${platform}-${arch}" -exec rm -rf {} +
find "$server/bin" "$server/compiled" -mindepth 1 -maxdepth 1 ! -name "${platform}" -exec rm -rf {} +
find "$server/bin/${platform}" "$server/compiled/${platform}" -mindepth 1 -maxdepth 1 ! -name "${arch}" -exec rm -rf {} +
find "$server/policy-templates" -mindepth 1 -maxdepth 1 ! -name "${platform}" -exec rm -rf {} +
find "$server" -name '*.map' -delete
makeWrapper ${lib.getExe nodejs-slim} $out/bin/copilot-language-server \
--add-flags $out/share/copilot-language-server/main.js
runHook postInstall
'';
doInstallCheck = true;
nativeInstallCheckInputs = [
writableTmpDirAsHomeHook
versionCheckHook
];
# uv_os_homedir returned ENOENT (no such file or directory)
versionCheckKeepEnvironment = lib.optionals stdenvNoCC.hostPlatform.isDarwin [ "HOME" ];
passthru = {
updateScript = nix-update-script { };
tests.version = testers.testVersion { package = finalAttrs.finalPackage; };
};
meta = {
@@ -54,6 +77,11 @@ stdenvNoCC.mkDerivation (finalAttrs: {
shortName = "GitHub Copilot License";
url = "https://github.com/customer-terms/github-copilot-product-specific-terms";
};
sourceProvenance = with lib.sourceTypes; [
binaryNativeCode # prebuild directory
binaryBytecode # WASM files
obfuscatedCode # minified JavaScript
];
mainProgram = "copilot-language-server";
platforms = [
"x86_64-linux"

View File

@@ -30,7 +30,7 @@ stdenv.mkDerivation (finalAttrs: {
for script in $(grep -lr '^#!/usr/bin/env python3$'); do patchShebangs $script; done
'';
configureFlags = lib.optional enableTruecolor [ "--enable-truecolor" ];
configureFlags = lib.optionals enableTruecolor [ "--enable-truecolor" ];
nativeBuildInputs = [
autoreconfHook

View File

@@ -60,7 +60,7 @@ rustPlatform.buildRustPackage (finalAttrs: {
buildFeatures = [
"cli"
]
++ lib.optional withServer [
++ lib.optionals withServer [
"server"
];

View File

@@ -89,7 +89,7 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "curl";
version = "8.21.0";
version = "8.22.0";
src = fetchurl {
urls = [
@@ -98,7 +98,7 @@ stdenv.mkDerivation (finalAttrs: {
builtins.replaceStrings [ "." ] [ "_" ] finalAttrs.version
}/curl-${finalAttrs.version}.tar.xz"
];
hash = "sha256-qhtmpw6s6D3GJFCHRWRsCK5WHeUSq0A63/uTrIf8cuY=";
hash = "sha256-9+866KIuUh8omAP+k1Q+tkwym1iqc6niJN/ZFaKl9Pc=";
};
# this could be accomplished by updateAutotoolsGnuConfigScriptsHook, but that causes infinite recursion
@@ -113,28 +113,17 @@ stdenv.mkDerivation (finalAttrs: {
#
# Where the host has no shell at all, `patchShebangs --host` finds nothing
# and leaves the shebang as shipped, which is the best available answer.
#
# TODO: take the first branch unconditionally --- in the spirit of strictDeps,
# it is good to always be defensive rather than do something unnecessarily
# that we can only get away with when build == host.
+ (
if isCross then
''
local f flag
for f in scripts/*; do
if [[ "$f" == scripts/wcurl ]]; then
flag=--host
else
flag=--build
fi
patchShebangs "$flag" "$f"
done
''
else
''
patchShebangs scripts
''
);
+ ''
local f flag
for f in scripts/*; do
if [[ "$f" == scripts/wcurl ]]; then
flag=--host
else
flag=--build
fi
patchShebangs "$flag" "$f"
done
'';
outputs = [
"bin"
@@ -289,13 +278,7 @@ stdenv.mkDerivation (finalAttrs: {
# Some hosts have no shell for the scripts to point at: MinGW is the one in
# tree, where `bash` is marked unsupported because it needs a POSIX layer. We
# cannot patch shebangs in that case.
#
# TODO: drop the isCross part of the condition --- in the spirit of
# `strictDeps` it is good to have the dep (when it is available), even if it
# is gratuitous in the `build = host` case.
buildInputs = lib.optional (
isCross && lib.meta.availableOn stdenv.hostPlatform runtimeShellPackage
) runtimeShellPackage;
buildInputs = lib.optional (lib.meta.availableOn stdenv.hostPlatform runtimeShellPackage) runtimeShellPackage;
passthru =
let

View File

@@ -17,7 +17,7 @@ stdenv.mkDerivation {
strictDeps = true;
env.NIX_CFLAGS_COMPILE = toString (
lib.optional stdenv.cc.isGNU [
lib.optionals stdenv.cc.isGNU [
# Required with newer GCC
"-Wno-error=stringop-overflow"
]

View File

@@ -125,6 +125,7 @@ python.pkgs.buildPythonApplication rec {
./ignore_links.patch
# https://salsa.debian.org/reproducible-builds/diffoscope/-/merge_requests/166
./fix-tests-with-zipdetails-4.006.patch
./radare2.patch
];
postPatch = ''
@@ -156,11 +157,7 @@ python.pkgs.buildPythonApplication rec {
# docx2txt <- makes tests broken:
# > FAILED tests/comparators/test_docx.py::test_diff - IndexError: list index out of range
# > FAILED tests/comparators/test_docx.py::test_compare_non_existing - AssertionError
# radare2
# > FAILED tests/comparators/test_elf_decompiler.py::test_ghidra_diff - IndexError: list index out of range
# > FAILED tests/comparators/test_elf_decompiler.py::test_radare2_diff - AssertionError
# > FAILED tests/comparators/test_macho_decompiler.py::test_ghidra_diff - assert 0 == 1
# > FAILED tests/comparators/test_macho_decompiler.py::test_radare2_diff - AssertionError
# radare2 (the exact output of the r2 version debian ships is expected, and our more recent version has a slightly different one)
#
# We filter automatically all packages for the host platform (some dependencies are not supported on Darwin, aarch64, etc.).
# Packages which are marked broken for a platform are not automatically filtered to avoid accidentally removing them without noticing it.

View File

@@ -0,0 +1,26 @@
Fix comparing ELF objects when r2 is in PATH
https://github.com/radareorg/radare2/issues/21201 renamed the "offset" key of
the json output diffoscope uses to "addr". As a result running diffoscope on an
ELF object results in this error:
KeyError: 'offset'
This patch does not include the modifications to the test suite required to
submit it upstream.
Upstream issue: https://salsa.debian.org/reproducible-builds/diffoscope/-/work_items/432
diff --git a/diffoscope/comparators/decompile.py b/diffoscope/comparators/decompile.py
index bf85deb9..f6a5564f 100644
--- a/diffoscope/comparators/decompile.py
+++ b/diffoscope/comparators/decompile.py
@@ -242,6 +242,9 @@ class AsmFunction(File):
@property
def offset(self):
+ if "addr" in self.data_dict:
+ return self.data_dict["addr"]
+ # backward compat with r2 version < 5.9.0
return self.data_dict["offset"]
@property

View File

@@ -18,7 +18,7 @@
# files.
let
version = "2.8.3";
version = "2.8.4";
tag = "R_${lib.replaceStrings [ "." ] [ "_" ] version}";
in
stdenv.mkDerivation (finalAttrs: {
@@ -29,7 +29,7 @@ stdenv.mkDerivation (finalAttrs: {
url =
with finalAttrs;
"https://github.com/libexpat/libexpat/releases/download/${tag}/${pname}-${version}.tar.xz";
hash = "sha256-9iVt+QyQZ3PTRNoIRAK30+TyLtQbGlnJiQmKg9PqDIU=";
hash = "sha256-ZWrhzI2jtOpRO7TiVPM+YkOTgITA7GI52oczdrCZhac=";
};
strictDeps = true;

View File

@@ -25,7 +25,7 @@ stdenv.mkDerivation {
hash = "sha256-2NUE/zaFoGwkZxgvVCYXxToiL23aVUFwFNlQzEq9GEc=";
};
makeFlags = lib.optional stdenv.hostPlatform.isDarwin [ "CC=cc" ];
makeFlags = lib.optionals stdenv.hostPlatform.isDarwin [ "CC=cc" ];
meta = {
description = "Cozy fireplace in your terminal";

View File

@@ -13,13 +13,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "fluidsynth";
version = "2.5.3";
version = "2.5.6";
src = fetchFromGitHub {
owner = "FluidSynth";
repo = "fluidsynth";
tag = "v${finalAttrs.version}";
hash = "sha256-k8IHS6Mh1b1iMSuBg3svlf7A2dsg6VHEKqlDhvyJnbo=";
hash = "sha256-q4NdfemCprYEYCrKlHumeRM8TyNz8eJcFM18EsB0p0c=";
fetchSubmodules = true;
};

View File

@@ -19,13 +19,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "flycast";
version = "2.6";
version = "2.7";
src = fetchFromGitHub {
owner = "flyinghead";
repo = "flycast";
tag = "v${finalAttrs.version}";
hash = "sha256-Lq6Oj+U4mpwNlL/t3ZB9gjE5NAVQyhdvBwLUGu1C+j0=";
hash = "sha256-8qGAoMQ7hF1HFx7m+CuhxX+IG7L4fk1XQkKUYZODGmA=";
fetchSubmodules = true;
};

View File

@@ -80,7 +80,7 @@ buildGoModule (finalAttrs: {
"-X 'github.com/caddyserver/caddy/v2.CustomVersion=FrankenPHP ${finalAttrs.version} PHP ${phpUnwrapped.version} Caddy'"
# pie mode is only available with pkgsMusl, it also automatically add -buildmode=pie to $GOFLAGS
]
++ (lib.optional pieBuild [ "-static-pie" ]);
++ (lib.optionals pieBuild [ "-static-pie" ]);
preBuild = ''
export CGO_CFLAGS="$(${phpConfig} --includes)"

View File

@@ -0,0 +1,33 @@
From 75acad3e1c9937f2b10330d563c4fa3e6c902d21 Mon Sep 17 00:00:00 2001
From: "Eric S. Raymond" <esr@thyrsus.com>
Date: Wed, 4 Mar 2026 18:49:49 -0500
Subject: [PATCH] [CVE-2026-23868] Avoid potentuial double-free on weird
images.
(cherry picked from commit f5b7267aed3665ef025c13823e454170d031c106)
---
gifalloc.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/gifalloc.c b/gifalloc.c
index 47c653930f6d..479c6c5a21bd 100644
--- a/gifalloc.c
+++ b/gifalloc.c
@@ -349,6 +349,14 @@ SavedImage *GifMakeSavedImage(GifFileType *GifFile,
* aliasing problems.
*/
+ /* Null out aliased pointers before any allocations
+ * so that FreeLastSavedImage won't free CopyFrom's
+ * data if an allocation fails partway through. */
+ sp->ImageDesc.ColorMap = NULL;
+ sp->RasterBits = NULL;
+ sp->ExtensionBlocks = NULL;
+ sp->ExtensionBlockCount = 0;
+
/* first, the local color map */
if (CopyFrom->ImageDesc.ColorMap != NULL) {
sp->ImageDesc.ColorMap = GifMakeMapObject(
--
2.54.0

View File

@@ -0,0 +1,37 @@
From 88a2df92422b0aa5e52e75c5214d60080714abd7 Mon Sep 17 00:00:00 2001
From: Anthony Hurtado <amhurtado@protonmail.com>
Date: Mon, 1 Jun 2026 15:40:48 -0500
Subject: [PATCH] Fix CVE-2026-26740: heap OOB write in EGifGCBToSavedExtension
EGifGCBToSavedExtension calls EGifGCBToExtension which unconditionally
writes 4 bytes into ep->Bytes without checking ep->ByteCount. If the
extension block was allocated with fewer than 4 bytes, this results in
a heap buffer overflow.
The read-side counterpart DGifExtensionToGCB already validates that
GifExtensionLength == 4 before reading. Add the symmetric check on
the write side: return GIF_ERROR when ep->ByteCount < 4.
Signed-off-by: Anthony Hurtado <amhurtado@pm.me>
(cherry picked from commit 061605081115bbfd7019bafc119a13b6f17fcf25)
---
egif_lib.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/egif_lib.c b/egif_lib.c
index 152686828680..8160560a4ab6 100644
--- a/egif_lib.c
+++ b/egif_lib.c
@@ -678,6 +678,9 @@ int EGifGCBToSavedExtension(const GraphicsControlBlock *GCB,
ExtensionBlock *ep =
&GifFile->SavedImages[ImageIndex].ExtensionBlocks[i];
if (ep->Function == GRAPHICS_EXT_FUNC_CODE) {
+ if (ep->ByteCount < 4) {
+ return GIF_ERROR;
+ }
EGifGCBToExtension(GCB, ep->Bytes);
return GIF_OK;
}
--
2.54.0

View File

@@ -18,6 +18,8 @@ stdenv.mkDerivation (finalAttrs: {
patches = [
./CVE-2021-40633.patch
./CVE-2025-31344.patch
./CVE-2026-23868.patch
./CVE-2026-26740.patch
]
++ lib.optionals stdenv.hostPlatform.isMinGW [
# Build dll libraries.

View File

@@ -180,7 +180,7 @@ let
linux = stdenvNoCC.mkDerivation (finalAttrs: {
inherit pname meta;
version = "153.0.8010.47";
version = "153.0.8010.52";
src =
let
@@ -195,8 +195,8 @@ let
url = "https://dl.google.com/linux/chrome/deb/pool/main/g/google-chrome-stable/google-chrome-stable_${finalAttrs.version}-1_${debArch}.deb";
hash =
{
amd64 = "sha256-oybe/eVN4vHA1G2L9La18/dvDIl70wsgsCUJcTmgW94=";
arm64 = "sha256-DEyVf0gz2ab4HkwzXEEpwowPmHfh5SA2/XYuygrfTbI=";
amd64 = "sha256-KeDkta8BITkV/9t/TkmhGVbcX8WRFlyFr4aI3N/5B6w=";
arm64 = "sha256-5aHWRq9ZRWiUHjph57jt3Gk/dpt/Fmh0xx9yycuAYWU=";
}
.${debArch};
};
@@ -306,11 +306,11 @@ let
darwin = stdenvNoCC.mkDerivation (finalAttrs: {
inherit pname meta;
version = "153.0.8010.48";
version = "153.0.8010.53";
src = fetchurl {
url = "https://dl.google.com/release2/chrome/ad6l2piroiqtckdm7rwkc6givuyq_153.0.8010.48/GoogleChrome-153.0.8010.48.dmg";
hash = "sha256-FgoOxuBiUAFk3X9iBHxlWFsNcO/PU95ObKTTuWLPnpo=";
url = "https://dl.google.com/release2/chrome/advkfamzjrpin7rbc7pzjxz6wkuq_153.0.8010.53/GoogleChrome-153.0.8010.53.dmg";
hash = "sha256-Hi/sZoZ16hdmIdGlpbEQ7DmhmwqxblE9mzgkHLMgN2w=";
};
dontPatch = true;

View File

@@ -2,10 +2,12 @@
rustPlatform,
lib,
fetchFromGitHub,
glib-networking,
openssl,
pkg-config,
perl,
webkitgtk_4_1,
wrapGAppsHook3,
stdenv,
nix-update-script,
}:
@@ -29,11 +31,15 @@ rustPlatform.buildRustPackage (finalAttrs: {
nativeBuildInputs = [
perl
pkg-config
]
++ lib.optionals stdenv.hostPlatform.isLinux [
wrapGAppsHook3
];
buildInputs = [
openssl
]
++ lib.optionals stdenv.hostPlatform.isLinux [
glib-networking
webkitgtk_4_1
];

View File

@@ -21,7 +21,7 @@
buildGoModule (finalAttrs: {
pname = "grafana";
version = "13.0.7";
version = "13.0.9";
subPackages = [
"pkg/cmd/grafana"
@@ -33,7 +33,7 @@ buildGoModule (finalAttrs: {
owner = "grafana";
repo = "grafana";
rev = "v${finalAttrs.version}";
hash = "sha256-Akb3ZhfYqwaXnhB6o+gbGfibflBYRDMUNvXQzwGXab0=";
hash = "sha256-VUPn7EN3dzoJdRpKUKF57n3wsxnXND/hXGQ0FdWswLs=";
};
patches = [
@@ -55,12 +55,12 @@ buildGoModule (finalAttrs: {
# Since this is not a dependency attribute the buildPackages has to be specified.
offlineCache = buildPackages.yarn-berry_4-fetcher.fetchYarnBerryDeps {
inherit (finalAttrs) src missingHashes patches;
hash = "sha256-0rmQGRgu22Yxm3Vlr2YKrGjU1xxePadByH/HGqubSVM=";
hash = "sha256-3p9EYboa6ilguJ+cqmcBfnYfe6L/LqZk0hI7ix1hQBM=";
};
disallowedRequisites = [ finalAttrs.offlineCache ];
vendorHash = "sha256-iYC96mt2Zy/yHRj1sYncvOc5P4zVAv3bk3Bq733UMDw=";
vendorHash = "sha256-XT9bVwF/crVpPzodQaGtvCYr9+1BBy1SYhC81EI+UsI=";
# Grafana seems to just set it to the latest version available
# nowadays.

View File

@@ -88,13 +88,13 @@ in
stdenv.mkDerivation (finalAttrs: {
pname = "imagemagick";
version = "7.1.2-30";
version = "7.1.2-31";
src = fetchFromGitHub {
owner = "ImageMagick";
repo = "ImageMagick";
tag = finalAttrs.version;
hash = "sha256-s2MC/14rNfbuOTI7xVNqr+YN2MobZ/EMnq0hxkJVAj8=";
hash = "sha256-RQpvpWSEMIIGIDLk5X9BwsWgD0AKPBgJ2m9dSipq8Lc=";
};
outputs = [

View File

@@ -42,11 +42,11 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "kid3";
version = "3.9.7";
version = "3.10.1";
src = fetchurl {
url = "mirror://kde/stable/kid3/${finalAttrs.version}/kid3-${finalAttrs.version}.tar.xz";
hash = "sha256-+c/u99Td3nitiXiHbLNSWEOjAlBPVHwiXpwiyB1xB2A=";
hash = "sha256-Agw1fHTDnJMUNbSedAkyjQt/baVJG1jC9zLtcjbqmkU=";
};
nativeBuildInputs = [

View File

@@ -42,9 +42,9 @@ stdenv.mkDerivation (finalAttrs: {
"man"
];
configureFlags = lib.optional withSystemd [ "--with-systemd" ];
configureFlags = lib.optionals withSystemd [ "--with-systemd" ];
makeFlags = lib.optional withSystemd [ "unitdir=$(out)/lib/systemd/system" ];
makeFlags = lib.optionals withSystemd [ "unitdir=$(out)/lib/systemd/system" ];
doCheck = true;

View File

@@ -8,11 +8,11 @@
let
pname = "ledger-live-desktop";
version = "4.19.0";
version = "4.19.1";
src = fetchurl {
url = "https://download.live.ledger.com/${pname}-${version}-linux-x86_64.AppImage";
hash = "sha256-8D2ErfvFQTuRUdodo7CjhQwVsvz5qfmlzs3LpPEG8+M=";
hash = "sha256-zPaMkbU36HwcMUHy9nrocCOJfZ4k/CXj/3gd4BZUV0M=";
};
appimageContents = appimageTools.extractType2 {

View File

@@ -15,14 +15,14 @@
}:
stdenv.mkDerivation (finalAttrs: {
version = "1.1.1";
version = "1.1.2";
pname = "libde265";
src = fetchFromGitHub {
owner = "strukturag";
repo = "libde265";
tag = "v${finalAttrs.version}";
hash = "sha256-ZHfPC86oylqt2bwWMJRWVjdMEEmX6UOKR7XkR0HPyok=";
hash = "sha256-dXUkSGviRfQkWacxMpH2vyLiSMvsetFw6ncrTW1SZaQ=";
};
nativeBuildInputs = [

View File

@@ -24,7 +24,7 @@
stdenv.mkDerivation (finalAttrs: {
pname = "libheif";
version = "1.23.2";
version = "1.23.4";
outputs = [
"bin"
@@ -38,7 +38,7 @@ stdenv.mkDerivation (finalAttrs: {
owner = "strukturag";
repo = "libheif";
rev = "v${finalAttrs.version}";
hash = "sha256-fqz2BfdcnnR5tylKcxM1xESoTRh5WgqvgdsBLJcnySU=";
hash = "sha256-bxN3YB/nKjrsHa/dM3sTAnWR+wOHk5a6ku6NF+8moQ0=";
};
nativeBuildInputs = [

View File

@@ -17,7 +17,7 @@
stdenv.mkDerivation (finalAttrs: {
pname = "libopenmpt";
version = "0.8.6";
version = "0.8.9";
outputs = [
"out"
@@ -27,7 +27,7 @@ stdenv.mkDerivation (finalAttrs: {
src = fetchurl {
url = "https://lib.openmpt.org/files/libopenmpt/src/libopenmpt-${finalAttrs.version}+release.autotools.tar.gz";
hash = "sha256-yqL6lZ44n0N02eLfOvXGM0UsEt2ARCy6LonLf/K5PFs=";
hash = "sha256-186E/QXWhsS89mr0Dq6Fevo3FELbYO7aP4dL1s9vwxg=";
};
enableParallelBuilding = true;

View File

@@ -145,7 +145,7 @@ rustPlatform.buildRustPackage (finalAttrs: {
"url_preview"
"zstd_compression"
]
++ lib.optional enableJemalloc [
++ lib.optionals enableJemalloc [
"jemalloc"
"jemalloc_conf"
]

View File

@@ -0,0 +1,34 @@
{
lib,
buildGoModule,
fetchFromGitHub,
nix-update-script,
}:
buildGoModule (finalAttrs: {
pname = "meowfetch";
version = "1.0.1";
__structuredAttrs = true;
src = fetchFromGitHub {
owner = "faynopi";
repo = "meowfetch";
tag = "v${finalAttrs.version}";
hash = "sha256-5nUogUYc25FPQKY9oIU2bmOpgWN8bCoxEhRJQfEZOcM=";
};
vendorHash = "sha256-PnkXXNr+kIige1YB/vEG+sYI0X/rr+6Gtcnb0rW4YK0=";
ldflags = [ "-s" ];
passthru.updateScript = nix-update-script { };
meta = {
description = "Minimal system information fetcher program written in go";
homepage = "https://github.com/faynopi/meowfetch";
changelog = "https://github.com/faynopi/meowfetch/releases/tag/${finalAttrs.src.tag}";
license = lib.licenses.mit;
maintainers = with lib.maintainers; [ goobertony ];
mainProgram = "meowfetch";
};
})

View File

@@ -0,0 +1,60 @@
{
lib,
stdenvNoCC,
fetchFromGitHub,
makeWrapper,
nix-update-script,
bashNonInteractive,
gawk,
sox,
}:
stdenvNoCC.mkDerivation (finalAttrs: {
pname = "mimir-sleep";
version = "2.0.0";
src = fetchFromGitHub {
owner = "FraioVeio";
repo = "mimir";
tag = finalAttrs.version;
hash = "sha256-TahlhXE5BWGGL2AKmgiAdruUkNgQSId/QwoJEfplHCc=";
};
strictDeps = true;
__structuredAttrs = true;
nativeBuildInputs = [ makeWrapper ];
buildInputs = [ bashNonInteractive ];
dontBuild = true;
installPhase = ''
runHook preInstall
install -Dm755 mimir.sh "$out/bin/mimir"
install -Dm444 -t "$out/share/mimir" mimir/esleep1.wav mimir/esleep2.wav
patchShebangs "$out/bin/mimir"
wrapProgram "$out/bin/mimir" \
--prefix PATH : ${
lib.makeBinPath [
gawk
sox
]
}
runHook postInstall
'';
passthru.updateScript = nix-update-script { };
meta = {
description = "Drop-in `sleep` replacement that plays soothing sound effects while your computer is asleep";
homepage = "https://github.com/FraioVeio/mimir";
changelog = "https://github.com/FraioVeio/mimir/releases/tag/${finalAttrs.src.tag}";
license = lib.licenses.mit;
maintainers = with lib.maintainers; [ fraioveio ];
platforms = lib.platforms.unix;
mainProgram = "mimir";
};
})

View File

@@ -17,7 +17,7 @@ stdenv.mkDerivation {
strictDeps = true;
env.NIX_CFLAGS_COMPILE = toString (
lib.optional stdenv.cc.isGNU [
lib.optionals stdenv.cc.isGNU [
# Required with newer GCC
"-Wstringop-overflow=0"
]

View File

@@ -92,7 +92,7 @@ stdenv.mkDerivation rec {
"-Wno-dev"
]
++ lib.optional stdenv.hostPlatform.isDarwin "-DBoost_USE_MULTITHREADED=OFF"
++ lib.optional trezorSupport [
++ lib.optionals trezorSupport [
"-DUSE_DEVICE_TREZOR=ON"
];

View File

@@ -104,7 +104,7 @@ stdenv.mkDerivation rec {
cmakeFlags = [
"-DARCH=default"
]
++ lib.optional trezorSupport [
++ lib.optionals trezorSupport [
# fix build on recent gcc versions
"-DCMAKE_CXX_FLAGS=-fpermissive"
];

View File

@@ -35,24 +35,6 @@
nixosTests,
}:
let
qt6' = qt6.overrideScope (
self: super: {
# Fix for: https://github.com/NixOS/nixpkgs/issues/526825
# reported upstream at: https://github.com/musescore/MuseScore/issues/33015
qtdeclarative = super.qtdeclarative.overrideAttrs (
new: old: {
patches = old.patches ++ [
(fetchpatch {
url = "https://github.com/qt/qtdeclarative/commit/9d4d376726a6ce15c429128dc65b927e411e40da.patch";
hash = "sha256-XhfliF5wZuN4/E55f8hfipIRjxBe9V7vL1cgn5p4xqA=";
})
];
}
);
}
);
in
stdenv.mkDerivation (finalAttrs: {
pname = "musescore";
version = "4.7.4";
@@ -124,8 +106,8 @@ stdenv.mkDerivation (finalAttrs: {
nativeBuildInputs = [
cmake
qt6'.qttools
qt6'.wrapQtAppsHook
qt6.qttools
qt6.wrapQtAppsHook
ninja
pkg-config
]
@@ -138,12 +120,12 @@ stdenv.mkDerivation (finalAttrs: {
buildInputs = [
flac
freetype
qt6'.qt5compat
qt6'.qtbase
qt6'.qtdeclarative
qt6'.qtnetworkauth
qt6'.qtscxml
qt6'.qtsvg
qt6.qt5compat
qt6.qtbase
qt6.qtdeclarative
qt6.qtnetworkauth
qt6.qtscxml
qt6.qtsvg
lame
libjack2
libogg
@@ -160,7 +142,7 @@ stdenv.mkDerivation (finalAttrs: {
]
++ lib.optionals stdenv.hostPlatform.isLinux [
alsa-lib
qt6'.qtwayland
qt6.qtwayland
];
# Put the default, `$prefix/lib` directory to look for ffmpeg shared objects,

View File

@@ -27,20 +27,20 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "n8n";
version = "2.37.10";
version = "2.39.6";
src = fetchFromGitHub {
owner = "n8n-io";
repo = "n8n";
tag = "n8n@${finalAttrs.version}";
hash = "sha256-cEWwXiyBLiZ8MgH5OKe0+hgd9ooYZTDQIuS4Dq0nKos=";
hash = "sha256-fmo0xL6IF6J+D5ZamkoBXyZ4Q8s3l5MeBWaXc39OsTU=";
};
pnpmDeps = fetchPnpmDeps {
inherit (finalAttrs) pname version src;
pnpm = pnpm_11;
fetcherVersion = 4;
hash = "sha256-T1axKjZT1I8NjXFV8hAKSYa+zCl/Fpyzz2DGM+cmkLQ=";
hash = "sha256-yL95w+Jd5I5R6r/qNihvAJ4MX2LMyS9ICZzJnLxHR4s=";
};
nativeBuildInputs = [

View File

@@ -19,16 +19,16 @@ let
in
rustPlatform.buildRustPackage (finalAttrs: {
pname = "npins";
version = "0.4.1";
version = "0.4.2";
src = fetchFromGitHub {
owner = "andir";
repo = "npins";
tag = finalAttrs.version;
sha256 = "sha256-XzJaDf5tlrYGTMJ+eS9hH9l79S4JA8h2KfbvKHF14xY=";
sha256 = "sha256-toAQj3cO6dhfm6FnK0a0mbj+VBaADCsNZNi1PMuJnFQ=";
};
cargoHash = "sha256-Fiku3UULsm6HL1skjJA/UiW9VRFRWbnXULQFBiVDCJ0=";
cargoHash = "sha256-Ee/QN1Jro78mzwcRWerpZu8Gsj2mkddHBrKUXGGoIQU=";
nativeBuildInputs = [ makeWrapper ];

View File

@@ -2,21 +2,24 @@
lib,
buildGoModule,
fetchFromGitHub,
nix-update-script,
versionCheckHook,
}:
buildGoModule (finalAttrs: {
pname = "nuclei";
version = "3.8.0";
version = "3.11.1";
__structuredAttrs = true;
src = fetchFromGitHub {
owner = "projectdiscovery";
repo = "nuclei";
tag = "v${finalAttrs.version}";
hash = "sha256-jzXV9QBpeH26nrViHdKR6Id7Dkdl0Ob1r71RhorCJvM=";
hash = "sha256-iXeMYiri3gwfjXnWgSgGOtcXFqZynSzGXnVIM6hOH5Y=";
};
vendorHash = "sha256-dxyyaletTVud6p81QzOsitw7m4yAZG3r1ZoEb2vQqOY=";
vendorHash = "sha256-N7Oj55t5PO17sRkxafbG4UsejjpLBVAoSC5t0R2tD1k=";
proxyVendor = true; # hash mismatch between Linux and Darwin
@@ -24,10 +27,7 @@ buildGoModule (finalAttrs: {
nativeInstallCheckInputs = [ versionCheckHook ];
ldflags = [
"-w"
"-s"
];
ldflags = [ "-s" ];
# Test files are not part of the release tarball
doCheck = false;
@@ -36,6 +36,8 @@ buildGoModule (finalAttrs: {
versionCheckProgramArg = "-version";
passthru.updateScript = nix-update-script { };
meta = {
description = "Tool for configurable targeted scanning";
longDescription = ''

View File

@@ -8,13 +8,13 @@
withJitSealloc ? !(stdenv.hostPlatform.isPower64 && stdenv.hostPlatform.isAbiElfv1),
}:
stdenv.mkDerivation rec {
stdenv.mkDerivation (finalAttrs: {
pname = "pcre2";
version = "10.46";
version = "10.48";
src = fetchurl {
url = "https://github.com/PhilipHazel/pcre2/releases/download/pcre2-${version}/pcre2-${version}.tar.bz2";
hash = "sha256-FfvFq6a+7gsXrssEYCrjlDI5OroevY45t8q/fbiDKZ8=";
url = "https://github.com/PCRE2Project/pcre2/releases/download/pcre2-${finalAttrs.version}/pcre2-${finalAttrs.version}.tar.bz2";
hash = "sha256-tsaP3286wxOItQqon/D8ScAMmHwW57UUZJHRIAPyyO0=";
};
nativeBuildInputs = [ updateAutotoolsGnuConfigScriptsHook ];
@@ -24,6 +24,7 @@ stdenv.mkDerivation rec {
"--enable-pcre2-32"
# only enable jit on supported platforms which excludes Apple Silicon, see https://github.com/zherczeg/sljit/issues/51
"--enable-jit=${if stdenv.hostPlatform.isS390x then "no" else "auto"}"
"--disable-symvers"
]
# fix pcre jit in systemd units that set MemoryDenyWriteExecute=true like gitea
++ lib.optional withJitSealloc "--enable-jit-sealloc";
@@ -43,6 +44,7 @@ stdenv.mkDerivation rec {
meta = {
homepage = "https://www.pcre.org/";
changelog = "https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-${finalAttrs.version}";
description = "Perl Compatible Regular Expressions";
license = lib.licenses.bsd3;
maintainers = with lib.maintainers; [ ttuegel ];
@@ -53,6 +55,6 @@ stdenv.mkDerivation rec {
"libpcre2-16"
"libpcre2-32"
];
identifiers.cpeParts = lib.meta.cpeFullVersionWithVendor "pcre" version;
identifiers.cpeParts = lib.meta.cpeFullVersionWithVendor "pcre" finalAttrs.version;
};
}
})

View File

@@ -2,6 +2,7 @@
lib,
stdenv,
fetchurl,
fetchpatch,
gettext,
libsepol,
libselinux,
@@ -20,6 +21,16 @@ stdenv.mkDerivation (finalAttrs: {
hash = "sha256-BU5B7AOXMaXua3l6jguNbjRu4dCpusLyUttIwj+aixs=";
};
patches = [
# https://nvd.nist.gov/vuln/detail/CVE-2026-19079
(fetchpatch {
name = "CVE-2026-19079.patch";
url = "https://github.com/SELinuxProject/selinux/commit/a556538c2d5d2583273e025b45c02651fef47679.patch";
stripLen = 1;
hash = "sha256-na/4xfW1R5VwvwHTUHXSs23pOD8Z/ClbBET+oxJe+uA=";
})
];
postPatch = ''
# Fix install references
substituteInPlace po/Makefile \

View File

@@ -17,7 +17,7 @@ stdenv.mkDerivation (finalAttrs: {
strictDeps = true;
env.NIX_CFLAGS_COMPILE = toString (
lib.optional stdenv.cc.isGNU [
lib.optionals stdenv.cc.isGNU [
# Required with newer GCC
"-Wno-error=stringop-overflow"
]

View File

@@ -88,7 +88,7 @@ stdenv.mkDerivation (finalAttrs: {
"HOSTARCH=${hostarch}"
"ARCH=${hostarch}"
]
++ lib.optional stdenv.hostPlatform.isAarch64 [
++ lib.optionals stdenv.hostPlatform.isAarch64 [
# aarch64 is special for GNU-EFI, see BUILDING.txt
"GNUEFI_ARM64_TARGET_SUPPORT=y"
];

View File

@@ -100,7 +100,7 @@ buildDotnetModule rec {
"Ryujinx"
];
makeWrapperArgs = lib.optional stdenv.hostPlatform.isLinux [
makeWrapperArgs = lib.optionals stdenv.hostPlatform.isLinux [
# Without this Ryujinx fails to start on wayland. See https://github.com/Ryujinx/Ryujinx/issues/2714
"--set SDL_VIDEODRIVER x11"
];

View File

@@ -74,7 +74,7 @@ stdenv.mkDerivation (finalAttrs: {
"-lpthread"
"--export-all-symbols"
]
++ lib.optional (!static && stdenv.hostPlatform.isMinGW) [ "--out-implib,libs7dll.a" ]
++ lib.optionals (!static && stdenv.hostPlatform.isMinGW) [ "--out-implib,libs7dll.a" ]
++ lib.optional withArb "-lflint"
++ lib.optionals withGMP [
"-lgmp"

View File

@@ -35,7 +35,7 @@ stdenv.mkDerivation (finalAttrs: {
};
# Only unvendor miniaudio on non-Darwin as Darwin cannot build the miniaudio package.
patches = lib.optional (!stdenv.hostPlatform.isDarwin) [
patches = lib.optionals (!stdenv.hostPlatform.isDarwin) [
# Not upstreamble in the near future, see https://github.com/SFML/SFML/pull/3555
./unvendor-miniaudio.patch
];

View File

@@ -8,16 +8,16 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "shaperglot-cli";
version = "1.2.1";
version = "1.2.2";
src = fetchFromGitHub {
owner = "googlefonts";
repo = "shaperglot";
tag = "v${finalAttrs.version}";
hash = "sha256-g8f8Q2DvYNvm8i6S+9K/jhhUiuGw366dht0Khx3/INg=";
hash = "sha256-VVxOkJ6a5UhQvSCswbgeRCLUEOzAbPhHuhJJAr1VvKA=";
};
cargoHash = "sha256-ivl3Zq0HRn4yP9JKfbjSaaERjbQ3SAEWhHk6toFp8dE=";
cargoHash = "sha256-WOIYg/QlWEk1StmudlPjpit/cKMkPtqLtf0BhPWQeg8=";
cargoBuildFlags = [
"--package=shaperglot-cli"

View File

@@ -18,7 +18,7 @@ rustPlatform.buildRustPackage {
cargoHash = "sha256-RgRmbQVZK/4U37CO8AjNQOqR/SXvL1TQU03LX7LnqPY=";
buildFeatures = lib.optional withCitation [ "citation" ];
buildFeatures = lib.optionals withCitation [ "citation" ];
meta = {
description = "Language server to enable word completion and snippets for Helix editor";

View File

@@ -72,7 +72,7 @@ stdenv.mkDerivation (finalAttrs: {
"-DCMAKE_INSTALL_INCLUDEDIR=include"
]
++ lib.optional (gpuBackend == "cuda") "-DSPLA_GPU_BACKEND=CUDA"
++ lib.optional (gpuBackend == "rocm") [ "-DSPLA_GPU_BACKEND=ROCM" ];
++ lib.optionals (gpuBackend == "rocm") [ "-DSPLA_GPU_BACKEND=ROCM" ];
preFixup = ''
substituteInPlace $out/lib/cmake/SPLA/SPLASharedTargets-release.cmake \

View File

@@ -4,21 +4,29 @@
buildGoModule,
fetchFromGitHub,
installShellFiles,
makeWrapper,
versionCheckHook,
withQemu ? false,
qemu,
}:
buildGoModule (finalAttrs: {
pname = "talosctl";
version = "1.13.7";
version = "1.13.9";
src = fetchFromGitHub {
owner = "siderolabs";
repo = "talos";
tag = "v${finalAttrs.version}";
hash = "sha256-KT8ln7i3YkNS8GzMeNo+7ENXL5jAc+ZgyVL+7Ke4NDE=";
hash = "sha256-I+FygHLeNQKy0OV6yaWMbVwJ/TxLl8KCncX2ICulCbU=";
};
vendorHash = "sha256-8v4xJT4HfE3tTFPPxXeqKMHNE/kKUVGE73flW17zXKM=";
vendorHash = "sha256-Ep24y1ehD1s5/6uxiufwvTKt4XBp/GmrDE2xnTuVIK8=";
postPatch = lib.optionalString withQemu ''
substituteInPlace pkg/provision/providers/qemu/arch.go \
--replace-fail '/opt/homebrew' '${lib.getLib qemu}'
'';
ldflags = [
"-s"
@@ -33,14 +41,19 @@ buildGoModule (finalAttrs: {
subPackages = [ "cmd/talosctl" ];
nativeBuildInputs = [ installShellFiles ];
nativeBuildInputs = [ installShellFiles ] ++ lib.optionals withQemu [ makeWrapper ];
postInstall = lib.optionalString (stdenv.buildPlatform.canExecute stdenv.hostPlatform) ''
installShellCompletion --cmd talosctl \
--bash <($out/bin/talosctl completion bash) \
--fish <($out/bin/talosctl completion fish) \
--zsh <($out/bin/talosctl completion zsh)
'';
postInstall =
lib.optionalString (stdenv.buildPlatform.canExecute stdenv.hostPlatform) ''
installShellCompletion --cmd talosctl \
--bash <($out/bin/talosctl completion bash) \
--fish <($out/bin/talosctl completion fish) \
--zsh <($out/bin/talosctl completion zsh)
''
+ lib.optionalString withQemu ''
wrapProgram $out/bin/talosctl \
--suffix PATH : ${lib.makeBinPath [ qemu ]}
'';
doCheck = false; # no tests

View File

@@ -0,0 +1,66 @@
{
lib,
rustPlatform,
fetchFromGitHub,
nix-update-script,
pkg-config,
wrapGAppsHook3,
webkitgtk_4_1,
xdotool,
gtk3,
cairo,
pango,
gdk-pixbuf,
glib,
libsoup_3,
openssl,
glib-networking,
nss,
}:
rustPlatform.buildRustPackage (finalAttrs: {
pname = "tesla_auth";
version = "0.15.0";
__structuredAttrs = true;
src = fetchFromGitHub {
owner = "adriankumpf";
repo = "tesla_auth";
tag = "v${finalAttrs.version}";
hash = "sha256-nidbHxvvvmL0PAh+nNLlYBYM5riGdt4pL4w4UxdEdV0=";
};
cargoHash = "sha256-TkqxzB6ufCFbibVCFM4dI2ZNQpGneNNR7j73YTgI+hE=";
nativeBuildInputs = [
pkg-config
wrapGAppsHook3
];
buildInputs = [
webkitgtk_4_1
xdotool
gtk3
cairo
pango
gdk-pixbuf
glib
libsoup_3
openssl
glib-networking
nss
];
env.STATIC_VCRUNTIME_NO_BUILD = "1";
passthru.updateScript = nix-update-script { };
meta = {
description = "Securely generate API tokens for third-party access to your Tesla";
homepage = "https://github.com/adriankumpf/tesla_auth";
license = lib.licenses.mit;
mainProgram = "tesla_auth";
maintainers = with lib.maintainers; [ brianmay ];
};
})

View File

@@ -25,8 +25,8 @@ stdenv.mkDerivation (finalAttrs: {
buildInputs = lib.optionals withQt [ libsForQt5.qtbase ] ++ lib.optionals withCurses ncurses;
cmakeFlags =
lib.optional withQt [ "-DQT=ON" ]
++ lib.optional withCurses [
lib.optionals withQt [ "-DQT=ON" ]
++ lib.optionals withCurses [
"-DCURSES=ON"
"-DQT=OFF"
];

View File

@@ -43,7 +43,10 @@ let
meta = {
description = "Hierarchical note taking application with focus on building large personal knowledge bases";
homepage = "https://triliumnotes.org/";
license = lib.licenses.agpl3Plus;
license = with lib.licenses; [
agpl3Plus # trilium code
unfree # ckeditor5-premium-features dependency, which is part of the prebuilt binary
];
sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ];
maintainers = with lib.maintainers; [
eliandoran

View File

@@ -56,7 +56,10 @@ stdenv.mkDerivation {
meta = {
description = "Hierarchical note taking application with focus on building large personal knowledge bases";
homepage = "https://github.com/TriliumNext/Notes";
license = lib.licenses.agpl3Plus;
license = with lib.licenses; [
agpl3Plus # trilium code
unfree # ckeditor5-premium-features dependency, which is part of the prebuilt binary
];
sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ];
platforms = [
"x86_64-linux"

View File

@@ -0,0 +1,80 @@
From 286dd3ff41526b582ef48830de239dffbaa61f90 Mon Sep 17 00:00:00 2001
From: Karel Zak <kzak@redhat.com>
Date: Thu, 3 Sep 2026 12:17:14 +0200
Subject: [PATCH] nsenter: close cgroup.procs fd after join to prevent
authority leak [CVE-2026-78408]
The --join-cgroup option opens the target's cgroup.procs while running
as root and writes nsenter's own PID to migrate itself. The descriptor
was left open across subsequent namespace transitions, credential drops
(setgroups/setgid/setuid) and execve().
The kernel performs cgroup migration permission checks using the
credentials captured at open time (file->f_cred). An open cgroup.procs
descriptor therefore carries the opener's migration authority regardless
of later privilege changes. A program executed inside the target
namespace inherits root's cgroup migration capability even when running
as an unprivileged user with no capabilities.
Fix this by:
- closing the temporary /proc/PID/cgroup fd after reading the path
- adding O_CLOEXEC to the cgroup.procs open as defense in depth
- closing cgroup_procs_fd immediately after the self-migration write
- initializing the temporary cgroup fd to -1 instead of 0 to avoid
accidentally closing stdin via open_target_fd()
The descriptor has no legitimate use after the single migration write.
Introduced-by: b40650b71a74 ("nsenter: add option -c to join the cgroup of target process")
References: b0cf1cf0d255 ("nsenter: close cgroup.procs fd after join to prevent authority leak")
Signed-off-by: Karel Zak <kzak@redhat.com>
(cherry picked from commit afe067c979b9ba2cbe856f7c6411210120ea62aa)
---
sys-utils/nsenter.c | 11 ++++++++---
1 file changed, 8 insertions(+), 3 deletions(-)
diff --git a/sys-utils/nsenter.c b/sys-utils/nsenter.c
index 62ef366d430..f449c65d2b4 100644
--- a/sys-utils/nsenter.c
+++ b/sys-utils/nsenter.c
@@ -466,7 +466,7 @@ static int get_ns_ino(const char *path, ino_t *ino)
static void open_cgroup_procs(void)
{
char *buf = NULL, *path = NULL, *p;
- int cgroup_fd = 0;
+ int cgroup_fd = -1;
char fdpath[PATH_MAX];
open_target_fd(&cgroup_fd, "cgroup", optarg);
@@ -474,6 +474,8 @@ static void open_cgroup_procs(void)
if (read_all_alloc(cgroup_fd, &buf) < 1)
err(EXIT_FAILURE, _("failed to get cgroup path"));
+ close(cgroup_fd);
+
p = strtok(buf, "\n");
if (p)
path = strrchr(p, ':');
@@ -483,7 +485,7 @@ static void open_cgroup_procs(void)
snprintf(fdpath, sizeof(fdpath), _PATH_SYS_CGROUP "/%s/cgroup.procs", path);
- if ((cgroup_procs_fd = open(fdpath, O_WRONLY | O_APPEND)) < 0)
+ if ((cgroup_procs_fd = open(fdpath, O_WRONLY | O_APPEND | O_CLOEXEC)) < 0)
err(EXIT_FAILURE, _("failed to open cgroup.procs"));
free(buf);
@@ -923,8 +925,11 @@ int main(int argc, char *argv[])
}
// Join into the target cgroup
- if (cgroup_procs_fd >= 0)
+ if (cgroup_procs_fd >= 0) {
join_into_cgroup();
+ close(cgroup_procs_fd);
+ cgroup_procs_fd = -1;
+ }
if (uid_gid_fd >= 0) {
struct stat st;

View File

@@ -0,0 +1,35 @@
From a323dddbcd1ed05a10e7e870b3e1a48b4ed44a43 Mon Sep 17 00:00:00 2001
From: Karel Zak <kzak@redhat.com>
Date: Wed, 2 Sep 2026 13:32:27 +0200
Subject: [PATCH] libmount: add missing fileutils.h include to hook_idmap.c
The hook_idmap.c uses RESOLVE_NO_SYMLINKS (added by commit fb8e26535)
but does not include fileutils.h, which provides the fallback #define
for this constant.
On Fedora (glibc 2.40+), this is masked because glibc's
<bits/fcntl-linux.h> transitively includes <linux/openat2.h>, which
defines RESOLVE_NO_SYMLINKS. On Ubuntu (and other distros with older
glibc), <fcntl.h> does not pull in openat2.h, so the build fails:
hook_idmap.c:335:33: error: 'RESOLVE_NO_SYMLINKS' undeclared
Fixes: fb8e26535 ("libmount: pin source path with openat2() for restricted users")
Signed-off-by: Karel Zak <kzak@redhat.com>
(cherry picked from commit 7e2e010874b10b3aabdc3c4c844c9ffc46a4a374)
---
libmount/src/hook_idmap.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/libmount/src/hook_idmap.c b/libmount/src/hook_idmap.c
index 77494e29810..2c697b17154 100644
--- a/libmount/src/hook_idmap.c
+++ b/libmount/src/hook_idmap.c
@@ -23,6 +23,7 @@
#include "strutils.h"
#include "all-io.h"
+#include "fileutils.h"
#include "namespace.h"
#include "mountP.h"

View File

@@ -43,11 +43,11 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "util-linux" + lib.optionalString isMinimal "-minimal";
version = "2.42.2";
version = "2.42.3";
src = fetchurl {
url = "mirror://kernel/linux/utils/util-linux/v${lib.versions.majorMinor finalAttrs.version}/util-linux-${finalAttrs.version}.tar.xz";
hash = "sha256-A6BdOt+WAu8Sjy2gW4SzIFzmDDUeVzfANw90AAZ5zoo=";
hash = "sha256-Zqx8DnJSeOsrA54xBPLJERk0HZQbQbrHooXGlflAvVc=";
};
# Note: fetchpatch/fetchpatch2 cause infinite recursion with util-linuxMinimal.
@@ -57,6 +57,14 @@ stdenv.mkDerivation (finalAttrs: {
# which isn't valid on NixOS (and a compatibility link on most other modern
# distros anyway).
./rtcwake-search-PATH-for-shutdown.patch
# Build fix. Can be removed in 2.42.4 (or newer).
# https://github.com/util-linux/util-linux/commit/a323dddbcd1ed05a10e7e870b3e1a48b4ed44a43
./libmount-build-fix.patch
# Fixes incomplete security fix in 2.42.3:
# https://github.com/util-linux/util-linux/commit/286dd3ff41526b582ef48830de239dffbaa61f90
./CVE-2026-78408.patch
];
# We separate some of the utilities into their own outputs. This

View File

@@ -24,13 +24,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "valkey";
version = "9.1.1";
version = "9.1.2";
src = fetchFromGitHub {
owner = "valkey-io";
repo = "valkey";
rev = finalAttrs.version;
hash = "sha256-wGHlPQ2JPxGTaJRJ9Siz3Q3eKdlo5z1tQpSFs9xZMbI=";
hash = "sha256-Lq5AqrLKILnsaOdAgWeeukPNF7KerB17R1mUOZjOsUg=";
};
patches = lib.optional useSystemJemalloc ./use_system_jemalloc.patch;

View File

@@ -22,13 +22,13 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "vencord";
version = "1.15.5";
version = "1.15.6";
src = fetchFromGitHub {
owner = "Vendicated";
repo = "Vencord";
tag = "v${finalAttrs.version}";
hash = "sha256-AiZjrbx2A3NMkbyKJBGiCB/zq7fIvWlhpAAcyPrtT7Q=";
hash = "sha256-bsTw8F6bBJFZWzOYV84VMtrMMj0fHId9BKCxrFUQYxM=";
};
patches = [ ./fix-deps.patch ];

View File

@@ -29,11 +29,6 @@
"version": "4.1.0",
"hash": "sha256-pM9WXvxZI3SS89CGVjxqtAyZyfyiZQzW0UnNCDiQrQA="
},
{
"pname": "Microsoft.CSharp",
"version": "4.7.0",
"hash": "sha256-Enknv2RsFF68lEPdrf5M+BpV1kHoLTVRApKUwuk/pj0="
},
{
"pname": "Microsoft.Extensions.DependencyInjection.Abstractions",
"version": "10.0.8",
@@ -59,30 +54,10 @@
"version": "0.9.21",
"hash": "sha256-zlfkByJBFn3SRHyAaOXHmk7lUc0HZtdsMrtisqx2zOo="
},
{
"pname": "Microsoft.NETCore.Platforms",
"version": "2.1.2",
"hash": "sha256-gYQQO7zsqG+OtN4ywYQyfsiggS2zmxw4+cPXlK+FB5Q="
},
{
"pname": "Microsoft.NETCore.Platforms",
"version": "3.1.0",
"hash": "sha256-cnygditsEaU86bnYtIthNMymAHqaT/sf9Gjykhzqgb0="
},
{
"pname": "Microsoft.Win32.Registry",
"version": "4.7.0",
"hash": "sha256-+jWCwRqU/J/jLdQKDFm93WfIDrDMXMJ984UevaQMoi8="
},
{
"pname": "Microsoft.Win32.SystemEvents",
"version": "4.7.0",
"hash": "sha256-GHxnD1Plb32GJWVWSv0Y51Kgtlb+cdKgOYVBYZSgVF4="
},
{
"pname": "Newtonsoft.Json",
"version": "13.0.1",
"hash": "sha256-K2tSVW4n4beRPzPu3rlVaBEMdGvWSv/3Q1fxaDh4Mjo="
"version": "10.0.10",
"hash": "sha256-WURA2NISoZzDBDMH7YnJcc/iI47inqJJtHMj40HhVJE="
},
{
"pname": "Newtonsoft.Json",
@@ -91,13 +66,13 @@
},
{
"pname": "NLog",
"version": "6.1.3",
"hash": "sha256-s0sxfQ1tiWRSFVh/m/eIzEe4+ZgT02e9GZiwDAi7xp4="
"version": "6.1.4",
"hash": "sha256-76h0KhYh0B6NDrkV5MHhv8SqUSvhTF6CFKsao5nRBbQ="
},
{
"pname": "runtime.native.System.Data.SqlClient.sni",
"version": "4.7.0",
"hash": "sha256-cj0+BpmoibwOWj2wNXwONJeTGosmFwhD349zPjNaBK0="
"version": "4.4.0",
"hash": "sha256-fqYLXAyMXfKXKx1A+E62vt2fiJOyfR+m3wMbULy/lpc="
},
{
"pname": "runtime.win-arm64.runtime.native.System.Data.SqlClient.sni",
@@ -119,11 +94,6 @@
"version": "2.1.3",
"hash": "sha256-lUTFK7OBtiXU1gyROax4GXDRvNj3aqgGlZZvicc37VQ="
},
{
"pname": "SixLabors.ImageSharp",
"version": "3.1.11",
"hash": "sha256-MlRF+3SGfahbsB1pZGKMOrsfUCx//hCo7ECrXr03DpA="
},
{
"pname": "SixLabors.ImageSharp",
"version": "3.1.12",
@@ -136,8 +106,8 @@
},
{
"pname": "SourceGear.sqlite3",
"version": "3.50.4.5",
"hash": "sha256-yPOyLiK4QoTfE3IED0hFl1JJYjmt8RBB3fp1a1CwvqE="
"version": "3.53.4",
"hash": "sha256-PrKw/AkB++CbeDloscGwAurHh4BT/kfTCed9ImgBDZo="
},
{
"pname": "Stub.System.Data.SQLite.Core.NetStandard",
@@ -146,24 +116,14 @@
},
{
"pname": "System.CodeDom",
"version": "10.0.8",
"hash": "sha256-BePlDeK617FVuzguexH5RnBDyapaN/zY47lpV/3nzyw="
"version": "10.0.10",
"hash": "sha256-xmuoa7ejwrNsha6hXLm0zsagGrUsoCe8Dd+5xFiNWvI="
},
{
"pname": "System.CodeDom",
"version": "4.7.0",
"hash": "sha256-4lO4CQyyqvwSG/EtNsRTQsbwyiY5pr225kAQXvlDkNE="
},
{
"pname": "System.Collections.Immutable",
"version": "5.0.0",
"hash": "sha256-GdwSIjLMM0uVfE56VUSLVNgpW0B//oCeSFj8/hSlbM8="
},
{
"pname": "System.Collections.Immutable",
"version": "6.0.0",
"hash": "sha256-DKEbpFqXCIEfqp9p3ezqadn5b/S1YTk32/EQK+tEScs="
},
{
"pname": "System.ComponentModel.Annotations",
"version": "4.7.0",
@@ -176,8 +136,8 @@
},
{
"pname": "System.Data.SqlClient",
"version": "4.8.1",
"hash": "sha256-SrhZIjgbS7XpFHsydxRBs8zu0qbgGLkdtvP0PBORv6A="
"version": "4.9.1",
"hash": "sha256-jsjLF1pojTAIlyOfinZLWcwOxUKjV5LUHGjAtOYt7aM="
},
{
"pname": "System.Data.SQLite",
@@ -194,66 +154,26 @@
"version": "1.0.119",
"hash": "sha256-upgcZ/YGVNT7kl+oZ/4fsLVourVef/8xpLQjk+J9+7w="
},
{
"pname": "System.Diagnostics.DiagnosticSource",
"version": "10.0.8",
"hash": "sha256-WUukX2DEBYxDiJVcGosDMfq16sarrbDGtzq7p5WC7EE="
},
{
"pname": "System.Drawing.Common",
"version": "4.7.0",
"hash": "sha256-D3qG+xAe78lZHvlco9gHK2TEAM370k09c6+SQi873Hk="
"version": "10.0.10",
"hash": "sha256-kHJHgIhFa9+HN86in89Y2NDxy5Cz/r2sSOguFQhXKt0="
},
{
"pname": "System.Management",
"version": "10.0.8",
"hash": "sha256-q0aaBuL/OblJw7vq+yxjWiUJuT5Hi6rfqebsgcHxb9E="
},
{
"pname": "System.Memory",
"version": "4.5.4",
"hash": "sha256-3sCEfzO4gj5CYGctl9ZXQRRhwAraMQfse7yzKoRe65E="
"version": "10.0.10",
"hash": "sha256-FAyMQ6ouxpt5/tdVv62lNp/3hiUbV8uAI4YoKMmj2oE="
},
{
"pname": "System.Reactive",
"version": "6.1.0",
"hash": "sha256-zACYoZmKxHo0qKY8FOVa7jIsw7dN7WjdXdRRV95qY2Y="
},
{
"pname": "System.Reflection.Metadata",
"version": "5.0.0",
"hash": "sha256-Wo+MiqhcP9dQ6NuFGrQTw6hpbJORFwp+TBNTq2yhGp8="
},
{
"pname": "System.Reflection.Metadata",
"version": "6.0.0",
"hash": "sha256-VJHXPjP05w6RE/Swu8wa2hilEWuji3g9bl/6lBMSC/Q="
},
{
"pname": "System.Reflection.MetadataLoadContext",
"version": "6.0.0",
"hash": "sha256-82aeU8c4rnYPLL3ba1ho1fxfpYQt5qrSK5e6ES+OTsY="
},
{
"pname": "System.Runtime.CompilerServices.Unsafe",
"version": "4.5.2",
"hash": "sha256-8eUXXGWO2LL7uATMZye2iCpQOETn2jCcjUhG6coR5O8="
},
{
"pname": "System.Runtime.CompilerServices.Unsafe",
"version": "5.0.0",
"hash": "sha256-neARSpLPUzPxEKhJRwoBzhPxK+cKIitLx7WBYncsYgo="
},
{
"pname": "System.Runtime.CompilerServices.Unsafe",
"version": "6.0.0",
"hash": "sha256-bEG1PnDp7uKYz/OgLOWs3RWwQSVYm+AnPwVmAmcgp2I="
},
{
"pname": "System.Security.AccessControl",
"version": "4.7.0",
"hash": "sha256-/9ZCPIHLdhzq7OW4UKqTsR0O93jjHd6BRG1SRwgHE1g="
},
{
"pname": "System.Security.Cryptography.ProtectedData",
"version": "4.7.0",
@@ -264,21 +184,6 @@
"version": "4.7.0",
"hash": "sha256-BGgXMLUi5rxVmmChjIhcXUxisJjvlNToXlyaIbUxw40="
},
{
"pname": "System.Security.Principal.Windows",
"version": "4.7.0",
"hash": "sha256-rWBM2U8Kq3rEdaa1MPZSYOOkbtMGgWyB8iPrpIqmpqg="
},
{
"pname": "System.Text.Encoding.CodePages",
"version": "4.5.1",
"hash": "sha256-PIhkv59IXjyiuefdhKxS9hQfEwO9YWRuNudpo53HQfw="
},
{
"pname": "System.Threading.Tasks.Extensions",
"version": "4.5.4",
"hash": "sha256-owSpY8wHlsUXn5xrfYAiu847L6fAKethlvYx97Ri1ng="
},
{
"pname": "System.Windows.Extensions",
"version": "4.7.0",

File diff suppressed because it is too large Load Diff

View File

@@ -14,23 +14,23 @@
let
node = nodejs_24;
electron = electron_42;
dotnet = dotnetCorePackages.dotnet_9;
dotnet = dotnetCorePackages.dotnet_10;
in
buildNpmPackage (finalAttrs: {
pname = "vrcx";
version = "2026.07.18";
version = "2026.09.16";
src = fetchFromGitHub {
repo = "VRCX";
owner = "vrcx-team";
tag = "v${finalAttrs.version}";
hash = "sha256-gmCS1M77CTJLWb+SR42kghtGxJuPZDRADKZS14Tx9Y8=";
hash = "sha256-CNO3Ur8xp77QN+HCexCpGX+QdAKM76YOSWOG3ZHT1g0=";
};
nodejs = node;
makeCacheWritable = true;
npmFlags = [ "--ignore-scripts" ];
npmDepsHash = "sha256-YwhRYpPcGwswf3OC3n1zFoSADOPkI5sTlaQN+fDe8sI=";
npmDepsHash = "sha256-fFuqtISueODEFzuqWWL3aG4DWbrq2G4dHsXi3RWByjY=";
nativeBuildInputs = [
makeWrapper
@@ -48,11 +48,13 @@ buildNpmPackage (finalAttrs: {
runHook preBuild
env PLATFORM=linux npm exec vite build src
node ./src-electron/patch-package-version.js
npm exec electron-builder -- --dir \
node ./build-scripts/patch-package-version.js
npm exec electron-builder -- \
--config electron-builder.config.js \
--dir \
-c.electronDist=${electron.dist} \
-c.electronVersion=${electron.version}
node ./src-electron/patch-node-api-dotnet.js
node ./build-scripts/patch-node-api-dotnet.js
runHook postBuild
'';

View File

@@ -35,7 +35,7 @@ stdenv.mkDerivation (finalAttrs: {
(lib.cmakeFeature "CMAKE_INSTALL_LIBDIR" "lib")
(lib.cmakeFeature "CMAKE_INSTALL_INCLUDEDIR" "include")
]
++ lib.optional finalAttrs.finalPackage.doCheck [
++ lib.optionals finalAttrs.finalPackage.doCheck [
# vtkBool does not accept TRUE, we have to use STRING "ON"
(lib.cmakeFeature "BUILD_TESTING" "ON")
];

View File

@@ -238,7 +238,7 @@ effectiveBuildPythonApplication rec {
"--with-pam"
"--with-vsock"
]
++ lib.optional withNvenc [
++ lib.optionals withNvenc [
"--with-nvenc"
"--with-nvjpeg_encoder"
];

View File

@@ -0,0 +1,49 @@
diff --git a/dist/source/as-promise/index.js b/dist/source/as-promise/index.js
index 9575c09d653037596ddf945afccedbbc672c4ee6..4560ce3bdcfdca11b7eaeaba1ff83a28f7a0caac 100644
--- a/dist/source/as-promise/index.js
+++ b/dist/source/as-promise/index.js
@@ -30,6 +30,7 @@ function asPromise(normalizedOptions) {
let globalRequest;
let globalResponse;
const emitter = new events_1.EventEmitter();
+ let promiseSettled = false;
const promise = new PCancelable((resolve, reject, onCancel) => {
const makeRequest = (retryCount) => {
const request = new core_1.default(undefined, normalizedOptions);
@@ -37,7 +38,10 @@ function asPromise(normalizedOptions) {
request._noPipe = true;
onCancel(() => request.destroy());
onCancel.shouldReject = false;
- onCancel(() => reject(new types_1.CancelError(request)));
+ onCancel(() => {
+ promiseSettled = true;
+ reject(new types_1.CancelError(request))
+ });
globalRequest = request;
request.once('response', async (response) => {
var _a;
@@ -118,12 +122,14 @@ function asPromise(normalizedOptions) {
return;
}
globalResponse = response;
+ promiseSettled = true;
resolve(request.options.resolveBodyOnly ? response.body : response);
});
const onError = (error) => {
if (promise.isCanceled) {
return;
}
+ promiseSettled = true;
const { options } = request;
if (error instanceof types_1.HTTPError && !options.throwHttpErrors) {
const { response } = error;
@@ -135,6 +141,9 @@ function asPromise(normalizedOptions) {
request.once('error', onError);
const previousBody = request.options.body;
request.once('retry', (newRetryCount, error) => {
+ if (promiseSettled) {
+ return;
+ }
var _a, _b;
if (previousBody === ((_a = error.request) === null || _a === void 0 ? void 0 : _a.options.body) && is_1.default.nodeStream((_b = error.request) === null || _b === void 0 ? void 0 : _b.options.body)) {
onError(error);

View File

@@ -1,5 +1,7 @@
{
fetchFromGitHub,
unzip,
zip,
lib,
pkgs,
nodejs,
@@ -35,6 +37,8 @@ stdenv.mkDerivation (finalAttrs: {
nativeBuildInputs = [
nodejs
yarn
unzip
zip
];
strictDeps = true;
@@ -43,6 +47,19 @@ stdenv.mkDerivation (finalAttrs: {
buildPhase = ''
runHook preBuild
(
# Remove when Yarn updates or removes the `got` dependency
# https://github.com/yarnpkg/berry/issues/7245#issuecomment-5538874542
GOT_CACHE_PATH=$(printf '%s' $(pwd)/.yarn/cache/got-npm-11.8.2-c1eb105458-*.zip)
cd $(mktemp -d)
unzip $GOT_CACHE_PATH -d .
rm $GOT_CACHE_PATH
patch -p1 -d node_modules/got < ${./got-npm-11.8.2.patch}
zip -Xr got-patched.zip node_modules
mv got-patched.zip $GOT_CACHE_PATH
)
yarn workspace @yarnpkg/cli build:cli
runHook postBuild
'';

View File

@@ -12,7 +12,7 @@
}:
let
versions = import ./versions.nix;
versions = import ./versions.nix { inherit stdenv; };
buildIsHost = lib.systems.equals stdenv.buildPlatform stdenv.hostPlatform;
buildIsTarget = lib.systems.equals stdenv.buildPlatform stdenv.targetPlatform;
hostIsTarget = lib.systems.equals stdenv.hostPlatform stdenv.targetPlatform;

Some files were not shown because too many files have changed in this diff Show More