Merge release-26.05 into staging-nixos-26.05

This commit is contained in:
nixpkgs-ci[bot]
2026-08-13 00:24:26 +00:00
committed by GitHub
39 changed files with 806 additions and 350 deletions

View File

@@ -50,7 +50,7 @@ in
only the hosts listed in {var}`dataDir`/remote_hosts.cfg will be allowed to
connect.
See also: <https://boinc.berkeley.edu/wiki/Controlling_BOINC_remotely#Remote_access>
See also: <https://github.com/BOINC/boinc/wiki/Controlling_BOINC_remotely#remote-access>
'';
};

View File

@@ -1,10 +1,10 @@
{
"chromium": {
"version": "151.0.7922.108",
"version": "151.0.7922.137",
"chromedriver": {
"version": "151.0.7922.109",
"hash_darwin": "sha256-VzMu90gOs02icI3PgvpNYXeE5c0QjCVB9CpM287roZo=",
"hash_darwin_aarch64": "sha256-5djEbPAayOVr8hr2VfXvlU4W6F+Kd/wiCt5NvQtgoOY="
"version": "151.0.7922.138",
"hash_darwin": "sha256-SW+gKW+GuPwVrJwFdFw6WmECOVXzfRT6tWCIRHoYrok=",
"hash_darwin_aarch64": "sha256-qUVhQo3JTPU5MP0RkVSAyk3iQTy/MWvE7Kab1BoI+Vg="
},
"deps": {
"depot_tools": {
@@ -21,8 +21,8 @@
"DEPS": {
"src": {
"url": "https://chromium.googlesource.com/chromium/src.git",
"rev": "4744b886309d987d292e43232776d2206cccb13d",
"hash": "sha256-1i2IAA5sXyMPBzh6xOIY3CllEDtIS9Buk8Z2Vm1JnYw=",
"rev": "8f5d36bc16f57115aeeff34baf4ad6aa964d509c",
"hash": "sha256-OSqLGAnfiGRVC4RRMnjXFx0JvKh2qY+9zlf2xJZT19Q=",
"recompress": true
},
"src/third_party/clang-format/script": {
@@ -657,8 +657,8 @@
},
"src/third_party/skia": {
"url": "https://skia.googlesource.com/skia.git",
"rev": "86bb2f25f46f4d620b4a26e738f59a9b6c22d2eb",
"hash": "sha256-tnUcFuwWtw0uGNIsU38M54V1MAYFs7/2yjP9Cs1fEHo="
"rev": "66cca05ab345fb894cc80ed412e2fa79f687f5d9",
"hash": "sha256-lDMn7ReDCdGKGmypIZszE29DWGFebJemFPluKZYeg7k="
},
"src/third_party/smhasher/src": {
"url": "https://chromium.googlesource.com/external/smhasher.git",
@@ -827,8 +827,8 @@
},
"src/v8": {
"url": "https://chromium.googlesource.com/v8/v8.git",
"rev": "20ad8d002c17ccc7ccfbefc6c4dcf1242fe80921",
"hash": "sha256-J2dblSPMoZTpotDpuPp6beRYv+KtCirqNxEGEQKpqcQ="
"rev": "00c2754b59cf5f79b323950c63b07cfb1a8377d4",
"hash": "sha256-dXWiFX049YVnrtNdEznEiwT8lDyGJn9BEehB2yhCxqI="
},
"src/agents/shared": {
"url": "https://chromium.googlesource.com/chromium/agents.git",
@@ -838,7 +838,7 @@
}
},
"ungoogled-chromium": {
"version": "151.0.7922.108",
"version": "151.0.7922.137",
"deps": {
"depot_tools": {
"rev": "94e89b10b92cc9d6e58fc8d1b6474b7d29e8a114",
@@ -850,16 +850,16 @@
"hash": "sha256-T2LdISIkp8fcUli5ZetTqrESBAc7coJhWdJv7I+o9kk="
},
"ungoogled-patches": {
"rev": "151.0.7922.108-1",
"hash": "sha256-EhnX4fkuKTTIF6wztKWitrjNzKUf36fAnr7lUkJqJtQ="
"rev": "151.0.7922.137-1",
"hash": "sha256-QIkhRquVqD22P1UBJ+Qv0LEI118v7PDt3hQCIl1ScQ4="
},
"npmHash": "sha256-pF0JtwFpPC4/fodbhSJnQKkczA9WlDg4VqEAy9aDVLg="
},
"DEPS": {
"src": {
"url": "https://chromium.googlesource.com/chromium/src.git",
"rev": "4744b886309d987d292e43232776d2206cccb13d",
"hash": "sha256-1i2IAA5sXyMPBzh6xOIY3CllEDtIS9Buk8Z2Vm1JnYw=",
"rev": "8f5d36bc16f57115aeeff34baf4ad6aa964d509c",
"hash": "sha256-OSqLGAnfiGRVC4RRMnjXFx0JvKh2qY+9zlf2xJZT19Q=",
"recompress": true
},
"src/third_party/clang-format/script": {
@@ -1494,8 +1494,8 @@
},
"src/third_party/skia": {
"url": "https://skia.googlesource.com/skia.git",
"rev": "86bb2f25f46f4d620b4a26e738f59a9b6c22d2eb",
"hash": "sha256-tnUcFuwWtw0uGNIsU38M54V1MAYFs7/2yjP9Cs1fEHo="
"rev": "66cca05ab345fb894cc80ed412e2fa79f687f5d9",
"hash": "sha256-lDMn7ReDCdGKGmypIZszE29DWGFebJemFPluKZYeg7k="
},
"src/third_party/smhasher/src": {
"url": "https://chromium.googlesource.com/external/smhasher.git",
@@ -1664,8 +1664,8 @@
},
"src/v8": {
"url": "https://chromium.googlesource.com/v8/v8.git",
"rev": "20ad8d002c17ccc7ccfbefc6c4dcf1242fe80921",
"hash": "sha256-J2dblSPMoZTpotDpuPp6beRYv+KtCirqNxEGEQKpqcQ="
"rev": "00c2754b59cf5f79b323950c63b07cfb1a8377d4",
"hash": "sha256-dXWiFX049YVnrtNdEznEiwT8lDyGJn9BEehB2yhCxqI="
},
"src/agents/shared": {
"url": "https://chromium.googlesource.com/chromium/agents.git",

View File

@@ -4,26 +4,35 @@
fetchurl,
libxshmfence,
stdenv,
writeShellScript,
nix-update,
jq,
nix,
common-updater-scripts,
}:
let
inherit (stdenv.hostPlatform) system;
throwSystem = throw "ferdium: arch ${system} not supported";
arch =
{
x86_64-linux = "amd64";
aarch64-linux = "arm64";
}
."${stdenv.hostPlatform.system}" or (throw "Unsupported system: ${stdenv.hostPlatform.system}");
.${system} or throwSystem;
hash =
{
amd64-linux_hash = "sha256-1jXo8MMk2EEkLo0n4ICmGJteKProLYKkMF//g63frHs=";
arm64-linux_hash = "sha256-jYDGVZhL0bswowm1H/4aa35lNJalil6ymV34NQM5Gfc=";
x86_64-linux = "sha256-ODQKFjBa2riJY26aPaAfLzuCyLYkB5oYSxIE28nMmwY=";
aarch64-linux = "sha256-CYHoTw6JUyU63iTd9tAbfWVnb48WcZgGtjthqnlAD8I=";
}
."${arch}-linux_hash";
.${system} or throwSystem;
in
mkFranzDerivation rec {
pname = "ferdium";
name = "Ferdium";
version = "7.1.1";
version = "7.1.2";
src = fetchurl {
url = "https://github.com/ferdium/ferdium-app/releases/download/v${version}/Ferdium-linux-${version}-${arch}.deb";
inherit hash;
@@ -31,9 +40,21 @@ mkFranzDerivation rec {
extraBuildInputs = [ libxshmfence ];
passthru = {
updateScript = ./update.sh;
};
passthru.updateScript = writeShellScript "update-ferdium" ''
${lib.getExe nix-update} ferdium --no-src --override-filename pkgs/applications/networking/instant-messengers/ferdium/default.nix
latestVersion=$(nix eval --raw --file . ferdium.version)
if [[ "$latestVersion" == "$UPDATE_NIX_OLD_VERSION" ]]; then
exit 0
fi
for system in x86_64-linux aarch64-linux; do
hash=$(${lib.getExe nix} store prefetch-file --json \
"$(nix eval --raw --file . ferdium.src.url --argstr system "$system")" \
| ${lib.getExe jq} --raw-output .hash)
${lib.getExe' common-updater-scripts "update-source-version"} \
ferdium "$latestVersion" "$hash" --system="$system" \
--ignore-same-version --ignore-same-hash
done
'';
meta = {
description = "All your services in one place built by the community";

View File

@@ -1,12 +0,0 @@
#!/usr/bin/env nix-shell
#!nix-shell -i bash -p git bash curl jq nix-update
set -xe
dirname="$(dirname "$0")"
latestTag=$(curl https://api.github.com/repos/ferdium/ferdium-app/releases/latest | jq -r ".tag_name")
latestVersion="$(expr $latestTag : 'v\(.*\)')"
nix-update --version "$latestVersion" --system aarch64-linux --override-filename "$dirname/default.nix" ferdium
nix-update --version skip --system x86_64-linux --override-filename "$dirname/default.nix" ferdium

View File

@@ -77,8 +77,8 @@ rec {
thunderbird = thunderbird-latest;
thunderbird-latest = common {
version = "153.0.1";
sha512 = "d69e6c8fd32742cf21752f27bac918eb2234989ae19ca36b5cfd131213c356924d3d48ef9d54c3a256cf5139eb7c38be5f1d1bd9cd2ee7ffccf12b953f3f5d2a";
version = "153.0.2";
sha512 = "870d7073919a6dd6357ed0f2caea11ce4374123f4bb99e599ae33956dfe81d1f7cb4b1ef77f85315d843816f9b714d33e71ae355e095a6c7d577b5dea2946844";
updateScript = callPackage ./update.nix {
attrPath = "thunderbirdPackages.thunderbird-latest";

View File

@@ -6,10 +6,10 @@
}:
let
pname = "archon-lite";
version = "9.4.36";
version = "9.5.0";
src = fetchurl {
url = "https://github.com/RPGLogs/Uploaders-archon-lite/releases/download/v${version}/archon-lite-v${version}.AppImage";
hash = "sha256-th48nSDIi2iugtiqjgkI7/QZtBq+BRQjRs1pKweDArI=";
hash = "sha256-ZuALgVtqsYtvnSq8hkJL4A+i4UaEpk+2L3bpSEXrhRM=";
};
extracted = appimageTools.extractType2 { inherit pname version src; };
@@ -20,13 +20,12 @@ appimageTools.wrapType2 {
extraInstallCommands = ''
mkdir -p $out/share/applications
mkdir -p $out/share/icons/hicolor/512x512/apps
cp -r ${extracted}/usr/share/icons/hicolor/512x512/apps/'Archon App Lite.png' $out/share/icons/hicolor/512x512/apps/archon-lite.png
cp -r ${extracted}/usr/share/icons/hicolor/512x512/apps/archon-lite.png $out/share/icons/hicolor/512x512/apps/archon-lite.png
chmod -R +w $out/share/
test ! -e $out/share/icons/hicolor/0x0 # check for regression of https://github.com/electron-userland/electron-builder/issues/5294
cp ${extracted}/'Archon App Lite.desktop' $out/share/applications/archon-lite.desktop
cp ${extracted}/archon-lite.desktop $out/share/applications/archon-lite.desktop
substituteInPlace $out/share/applications/archon-lite.desktop \
--replace-fail "Exec=AppRun --no-sandbox" "Exec=archon-lite" \
--replace-fail "Icon=Archon App Lite" "Icon=archon-lite"
--replace-fail "Exec=AppRun --no-sandbox" "Exec=archon-lite"
'';
passthru.updateScript = nix-update-script { };

View File

@@ -13,7 +13,7 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "arti";
version = "2.5.0";
version = "2.5.1";
src = fetchFromGitLab {
domain = "gitlab.torproject.org";
@@ -21,7 +21,7 @@ rustPlatform.buildRustPackage (finalAttrs: {
owner = "core";
repo = "arti";
tag = "arti-v${finalAttrs.version}";
hash = "sha256-jOCFXlBI2xAzgpb7Fa8ap53SpDF6kcRGYnBXcu3vpk4=";
hash = "sha256-fPobYu2ADTeIwpeXyxQKh5yr1zw+yMQfqTkiZMMd8YY=";
};
# Working around a bug in cargo that appears with cargo-auditable, see
@@ -32,7 +32,7 @@ rustPlatform.buildRustPackage (finalAttrs: {
'';
buildAndTestSubdir = "crates/arti";
cargoHash = "sha256-JK6ubp697jZ98ErNrZdFe0mXIez3lUZ5SmAHkyD97WQ=";
cargoHash = "sha256-+JQ+SkRLyLl4RUq69nIUn1zJ/DmYpVEICQO5o85FsNw=";
nativeBuildInputs = lib.optionals stdenv.hostPlatform.isLinux [ pkg-config ];

File diff suppressed because it is too large Load Diff

View File

@@ -5,17 +5,17 @@
}:
php.buildComposerProject2 (finalAttrs: {
pname = "baikal";
version = "0.11.1";
version = "0.12.1";
src = fetchFromGitHub {
owner = "sabre-io";
repo = "Baikal";
tag = finalAttrs.version;
hash = "sha256-+rOaPgVD5q2LoTXG3PM2x9EyOExt7CRPU+HQouwgaqI=";
hash = "sha256-gouksOoh+QocfyN5FS2Fz0DPjR0IM2dFqvtfTZA7C9Y=";
};
# It doesn't provide a composer.lock file, we have to generate manually.
composerLock = ./composer.lock;
vendorHash = "sha256-QE8i59MP24BdZjzzgQVfTuhL4v9l60KxpKj4+lkdomE=";
vendorHash = "sha256-s4ePm6gH7Xid+qkvVqumJrDFz/7HuoCeaeN5bgdQOMY=";
meta = {
description = "Lightweight CalDAV+CardDAV server that offers an extensive web interface with easy management of users, address books and calendars";

View File

@@ -8,15 +8,15 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "cargo-shear";
version = "1.13.3";
version = "1.13.4";
src = fetchCrate {
pname = "cargo-shear";
version = finalAttrs.version;
hash = "sha256-Qaq3nBZZR0biG5kVL15zhI8GwLEWBNzgeD3rHeZZOeU=";
hash = "sha256-bTTNiDWkbyjxFo59Hkeah23lQEGiuH5Xrm6z7SUNtoQ=";
};
cargoHash = "sha256-3YMdOCCK+rVx0XZfBqiMAw+aep1TBU5Ok6//c433h4o=";
cargoHash = "sha256-Mhxrcc9ErTYIV+yuIROuMdhbxrFdZZ2yAAXK0WRWcRI=";
env = {
# https://github.com/Boshen/cargo-shear/blob/v1.6.2/src/lib.rs#L51-L54

View File

@@ -7,7 +7,7 @@
stdenv.mkDerivation {
pname = "carps-cups";
version = "unstable-2018-03-05";
version = "0-unstable-2018-03-05";
src = fetchFromGitHub {
owner = "ondrej-zary";
@@ -35,8 +35,8 @@ stdenv.mkDerivation {
meta = {
description = "CUPS Linux drivers for Canon printers";
homepage = "https://www.canon.com/";
license = lib.licenses.gpl3Plus;
homepage = "https://github.com/ondrej-zary/carps-cups";
license = lib.licenses.gpl3Only;
broken = stdenv.hostPlatform.isDarwin;
maintainers = with lib.maintainers; [
ewok

View File

@@ -0,0 +1,60 @@
{
lib,
rustPlatform,
fetchFromGitHub,
pkg-config,
libdrm,
versionCheckHook,
nix-update-script,
}:
rustPlatform.buildRustPackage (finalAttrs: {
pname = "cyan-skillfish-governor-smu";
version = "0.4.12";
__structuredAttrs = true;
src = fetchFromGitHub {
owner = "filippor";
repo = "cyan-skillfish-governor";
tag = "v${finalAttrs.version}";
hash = "sha256-yer2MlLnj9lx2cEBeYqAktbx0BqQEK/eFPiga5gXCr8=";
};
cargoHash = "sha256-zlAVGLGnub2Gc0Bkzb5GU9NBAJ2YWLhIG8JOa+1wHx8=";
nativeBuildInputs = [ pkg-config ];
buildInputs = [ libdrm ];
env.CYAN_SKILLFISH_GOVERNOR_VERSION = finalAttrs.version;
postInstall = ''
install -Dm755 scripts/cyan-skillfish-performance-mode \
$out/bin/cyan-skillfish-performance-mode
install -Dm644 com.cyanskillfish.Governor.conf \
$out/share/dbus-1/system.d/com.cyanskillfish.Governor.conf
install -Dm644 default-config.toml \
$out/share/cyan-skillfish-governor-smu/default-config.toml
'';
nativeInstallCheckInputs = [
versionCheckHook
];
doInstallCheck = true;
passthru = {
updateScript = nix-update-script { };
};
meta = {
description = "SMU-based GPU governor for the AMD Cyan Skillfish APU (ASRock BC-250)";
homepage = "https://github.com/filippor/cyan-skillfish-governor";
changelog = "https://github.com/filippor/cyan-skillfish-governor/releases/tag/${finalAttrs.src.tag}";
license = lib.licenses.mit;
platforms = [ "x86_64-linux" ];
maintainers = with lib.maintainers; [ liberodark ];
mainProgram = "cyan-skillfish-governor-smu";
};
})

View File

@@ -1,28 +1,27 @@
{
"@rolldown/binding-android-arm64@npm:1.0.0-rc.17": "7c821eb984e2dd03b05979be3116d927326a1752e7d04462f6c78721fc47fb33d1a584e8c739b181dbfb5c28170541d05f775ada38e81bb685e43d03d974abe3",
"@rolldown/binding-darwin-arm64@npm:1.0.0-rc.17": "ddedec6840b8e32b7c45a4afe9d797bb24ea74ef222a1b443161045f0b53ec3a5752b108552fe6c99182e2553dd53498d96d3b30551cd3f1e8057559f23b1ed7",
"@rolldown/binding-darwin-x64@npm:1.0.0-rc.17": "b66ce82e3162261c045027b3aa061cd735c9b1395e77756e06b973f8d0e4256247ddfdb7ee8134363dfcd9d83e665b647b45b666a65c8454babdee19f6d57b40",
"@rolldown/binding-freebsd-x64@npm:1.0.0-rc.17": "87b9045771edda717c7d66df105bba2c22c88214254eae48d54ca641f79b4558c2d1ae3db27d8e36b230728263d539c5f6e03e895dbed6e08afa495f634eb42d",
"@rolldown/binding-linux-arm-gnueabihf@npm:1.0.0-rc.17": "43e60168d359a5edae352d948a6515c40a8e047fef7541693cbf18a09d80076efb9308a804c5ea7f645883f8f6b7b43e0e14ea677df63fb4016a55ba6f63b947",
"@rolldown/binding-linux-arm64-gnu@npm:1.0.0-rc.17": "d6bfe49089d598886e8c9c92e45240a2404e9594c4abc25f303c8655b859e0f0b67c18947e23177ccc5fb81c9b22a1bd32f2ed052531cc41491b4261ed728342",
"@rolldown/binding-linux-arm64-musl@npm:1.0.0-rc.17": "be5459bf78de0931993158783af8e349a68d03610876eb131f48fa51414a45683047cd9b4ad7631f385fedc9bb89677e8d12e874104a038b63932aaa1d7bceb3",
"@rolldown/binding-linux-ppc64-gnu@npm:1.0.0-rc.17": "e36194c8a39afc6522ca71c2ebf4c038792bf2c0141da76e8a385bebdda077a52f95ece9bd0a3818d5c0023e7e8ce708566d42ecd2ff31296a26a41ed6847aa4",
"@rolldown/binding-linux-s390x-gnu@npm:1.0.0-rc.17": "288ce91c69b13e37b2106fcfb663a981aba9de65d3bb4d3cd8c17b9e8193f3de44d08d1201c4d3a18fdeec5a89256d5b3b4d5bb913ff023cb577c403f8889917",
"@rolldown/binding-linux-x64-gnu@npm:1.0.0-rc.17": "d532e43e02e0a84c71ff9be34791d7b32b71786bac4921f9e4f92da39a7d5daeabeb4188c7cc088a8a80ab0691dcf1cc9d414396ce7ff6a970b1374e033df8f6",
"@rolldown/binding-linux-x64-musl@npm:1.0.0-rc.17": "56aecbe0a2aeaedd558c62a5057a7f915ecada0528a27b5edd80478d948c3645104a56c88121c71edefe9a6af7500f053724103099a90764eb8b84c3ee1f9536",
"@rolldown/binding-openharmony-arm64@npm:1.0.0-rc.17": "cc7a806e106f4c0d24400af42155b8b396f712e25d76e13b033895b3b635e21edb2246d3c8592c86989c7aaae1ded1708d36516472555bbed3ccaffc939403a4",
"@rolldown/binding-wasm32-wasi@npm:1.0.0-rc.17": "e6fb0aff901de475a4874af6b0473b396bf1bddf6cbb9acbdb6d4c9318ab2fa3e09d80435ecaeb7866b03effea79c57db9a271b5c720007341949e06828c8385",
"@rolldown/binding-win32-arm64-msvc@npm:1.0.0-rc.17": "d3724ce9f4117d28f903ae1bfc34e3a3efac853691577e511cef91259eb8355dc24f2f27a832bbbd9ad3323dc1b0c3ddbdc4c791ae2a6dd5e5b0c9051384d4d0",
"@rolldown/binding-win32-x64-msvc@npm:1.0.0-rc.17": "6f4a348202955f74481ccf1c0ec5fa96671507353b6a7f680b920c773f0dda4ebd46c1561428efcefacb9b4d279cd550c80a79fa261f8db173b527ae9a671eca",
"lightningcss-android-arm64@npm:1.32.0": "1cb326ad39dcb02cf9f45025c167b6900e3a04b08f5149d3c5ee26054b00d08db3736fb69183a6c3ed1cb32dddd148608c784b6631b4777623f7dd0c032c392d",
"lightningcss-darwin-arm64@npm:1.32.0": "da954d0c215d0e95f15a92c8717f871017586e1332b98fd40e96196571d2fd3d51a727dc530768afee9f6a04da210510740574dd0c8dbf2ecced79e5996f1a06",
"lightningcss-darwin-x64@npm:1.32.0": "b1d298c9173f839e8447d1917ed8bc5ab098ed0fc4e4b419d36ac5afe8b27bf21cb47d00a35c3d2edadcac598086e9b4f26c992a809d79f9681d6865a230d79e",
"lightningcss-freebsd-x64@npm:1.32.0": "0eb59f6acf2fcdc944c921b0ac2a16ee803452b9438f573ad6bc41be00040b791ed698698ed5c06f98ef43a6fed0a54987ba3a88da204de9978db2fca96a4a65",
"lightningcss-linux-arm-gnueabihf@npm:1.32.0": "7d1ea43986d2370a90cefc920dac3e041e0d19445cc4fdaf244644b57b6937588d7c3a464c31440617231f55a6dad79744cf707912e05f3b46a1694abb5b4e00",
"lightningcss-linux-arm64-gnu@npm:1.32.0": "f01ede75f41480a164d18338fa46d9fccdb4a821717174ce848ff8b2aa4badba4f1d331deb3ebec3ee2f0eb95bfa2e35f54877f371427b04e6f36a4783aa1414",
"lightningcss-linux-arm64-musl@npm:1.32.0": "38d373f99768f1c5ab6a9c87e1c0ec45eccdb3fe4d216dd5cd06629648c4b0689570ad4e89285d490662cde1790cd36e6b3d176c14e5e31f6869c604aa2df820",
"lightningcss-linux-x64-gnu@npm:1.32.0": "0a1433d46a4a010f87b615c3fa43725a456bae259858a2c927899cbf93074f0ae40f49901bf6af6daa30a4d169c86f594f6341fd775bf7b59293b8d7947b81c5",
"lightningcss-linux-x64-musl@npm:1.32.0": "a6f48ccc30a73d30563c7b61856d1fd6a8812ce62b1bee797f227e06612df70aab4ccd1908552952f77ca7ff2a51019f62d14ae5310ca67311635eeec55d3a9e",
"lightningcss-win32-arm64-msvc@npm:1.32.0": "a919be7fb298c1102bccf18b6f83d54946adfac70ab2ac9c95e4ae38ded76d8f530215b0bcda4d38df4ffc40a70abe3afd91d01d35fd122e7d119ed0e46972d0",
"lightningcss-win32-x64-msvc@npm:1.32.0": "5b8d3431aadbdc40a0a7eae32f2415e4f28b547af1a1cd5b35a35d67f772a89492c7fa03e9fc88ce804b14f5f88e412e49fff40d1b0aad67177de815c434207e"
"@rolldown/binding-android-arm64@npm:1.2.3": "5181b7152d6b6d20e219fa5a3dc57d258c146f1e41d4c1441482b134a29096d104002cb28f5762029556285c781d829ba67a6fdce842a7ecdae2f9b12ab3bc24",
"@rolldown/binding-darwin-arm64@npm:1.2.3": "7ff0488b1b7acc8ae6c8e20b15811b221226000ae8560ac2334f28ca07adf1da6a088804d67cf35c4884779113ab34858043b6fff93f7579fb41675aa22bb685",
"@rolldown/binding-darwin-x64@npm:1.2.3": "6b09cf6781128651bca9bbe2ea1f9de129a64717e191c7245140c0a12185498b03e248b0b4028d7dd92f98c22dc282bc44d544edb79a9508c94723d865b966ed",
"@rolldown/binding-freebsd-x64@npm:1.2.3": "e52524ae9120e6da7cf85bac985a50ba9c9714aaa34ebfdafb421d94b543de410217a11364ff048acdead2f8c7df24cc17a0dfef4f6f2ccc21e0bd1ad9f32eac",
"@rolldown/binding-linux-arm-gnueabihf@npm:1.2.3": "bd27b41ad476b6de2455108b857a627b1df0f47eb885205a9a06a60ea670cffe8b366be89acea13cbc7a55b387331509bcfef2cfad0cb25faa0c1db450e9dbb3",
"@rolldown/binding-linux-arm64-gnu@npm:1.2.3": "cf5bd6b0064274cc49f0b720da71672783a5e0cd4820dde5f3475bdcc228c3315791f597d5a75b5ae9d8ddde41d2c81ad67cc6a99c5ae49039fffb54cfcbc764",
"@rolldown/binding-linux-arm64-musl@npm:1.2.3": "740ebdac1f806a279f4128f99060e44d6cc4f00a9bed1dc70637aab53d785e96be7a1876a74202268bf73cc3a425aa1f1550da2f86872bbf49cbd46edf09b6d3",
"@rolldown/binding-linux-ppc64-gnu@npm:1.2.3": "704536b8de2c6d680153874fb57016c1284d297d87b166a696e53f1af1d9d0176cfc578252b588d7e59849309d71d638f73c6163c3c0714335e8993b8ff2d97f",
"@rolldown/binding-linux-s390x-gnu@npm:1.2.3": "a29de0fad1238e97e7700e3df3762872493d0557977ee9e15eacb9f9d3c9c0f29b110d858881eb4bfbf9b43f939bb61687bb33760f52ccb3acad2e998f66a283",
"@rolldown/binding-linux-x64-gnu@npm:1.2.3": "a048e32713eae7513d0f68ad675087bc86ed57493d59cb9920bb10f2ad567adbe9fa3e82e786705d2cb26d820ff98b48cd13abcc069e7044a593de4b8b795a9d",
"@rolldown/binding-linux-x64-musl@npm:1.2.3": "0b73be9ae16942651c9060ffdc2146677151a496159ca301701174aed4400e27eda8de078f649efd670da3ba208b0429c0130bf627d37c77ff3f23d97c78f6aa",
"@rolldown/binding-openharmony-arm64@npm:1.2.3": "5bf6288cbc11e96fdd9dae69dad2828535df0da14ed64373bc80f813b1098f61e7320e6448c36bc573cbd9119cd6855a7e13e76cf5bbab42d9d1586a8a499647",
"@rolldown/binding-win32-arm64-msvc@npm:1.2.3": "7a1dbc749f69f50cdf71804bfe8e6af8880b5d9f5c7f8d2e9fb5d1d8702e74b09471b6bbc1bb81051812f187298404c5f46d4bcbf92682a4d0e9a37d850fbed8",
"@rolldown/binding-win32-x64-msvc@npm:1.2.3": "5281bbfe23a6ef1938400ea0e1803293b54364489cf1b43d49d9fc346d0f258cec237cc112ceb8539190d7fa12913f6ef749a75b655c8b5bb95ed1ab4830c4e7",
"lightningcss-android-arm64@npm:1.33.0": "46c40a0474a7a9ddcdc33e0ea634912894a9360b6ba6f2bc42f1a817d16992784d2fe6f421d293a90ea94fb481503e27fdc54f0540de0b41d7028fe9e9c9e56a",
"lightningcss-darwin-arm64@npm:1.33.0": "398b770e33f66db9e4c14e4a45d0e93fa59644bd29ce5082de79ee9560a5946321ac55e896aa7fb3f177d218bef3f2dca530e209a857f0f066bf3296f5dc0742",
"lightningcss-darwin-x64@npm:1.33.0": "132bdab8f7b66dc99730f1ccfcb882880e411420e3f9ca764c348c686112d75962d5d7e928f3bbce7088c1be168d00ea8d722fd909033b807eef191b5a2832c0",
"lightningcss-freebsd-x64@npm:1.33.0": "05001395776e994ea1254dcc2613f06b44458ba33769e3a1679a0f577e43632af378cc1582f3bd1cb36e480d237066a371bc04233d6c84f8e2fe9979ab4a4032",
"lightningcss-linux-arm-gnueabihf@npm:1.33.0": "d0f6d993846992cf6db80f2992d0b89ffddd65a8260bbe6a1534bde28510bcfa214e8831df9ccfef5ede006a6368de1649e1d96a3e122169286647b704e08f5f",
"lightningcss-linux-arm64-gnu@npm:1.33.0": "278a5c553e15ed7645d3e83a3b1515060e98a8742b7008af28d610d6495a09368e73ed8b90bcb537b37249bfc2446ef5b9614b3626222f25153c538909488548",
"lightningcss-linux-arm64-musl@npm:1.33.0": "7aa2a2ef42e8c713e6e8eb947bf64d5272c6fdbfca7b4eb3adde555357652be27cc0d84d6fef6266543c2d303943a4c4472679d1e258458119b159f0ca868ffe",
"lightningcss-linux-x64-gnu@npm:1.33.0": "fa57a09af3340dc5f11fdbff820fbb7b08e306e69350a500b523c88f54c1e3a40b3785fed6043d69e2e18bacd4b72410518c9b817ee987c704a80851d9201e45",
"lightningcss-linux-x64-musl@npm:1.33.0": "4b0cad846f8fbe4ec321a45ef9c0d02cf4277980ac34dcfc7b422b34381e7cb11512819401b01bf029d10aa0fb8a35906ce850ba38d9f43605917ccc9b0b5d4a",
"lightningcss-win32-arm64-msvc@npm:1.33.0": "5e4b58d7a41fe3c37ce2af7b1a95c3722a6064a84fb6286ba2cf1106651223403b5a5863ecd3eb8fb9732480e612e30d786b859329391b0197dffc88ca18c953",
"lightningcss-win32-x64-msvc@npm:1.33.0": "7beb4c8580f9ea45fea6d92a8de42f706c4935b2ca68f4f5163a2bd9f6ed1574f7e53686e4927883078b07a4063a9fffdc4b41968568354259066c7a70c156a4"
}

View File

@@ -16,19 +16,19 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "dokieli";
version = "0-unstable-2026-05-08";
version = "0-unstable-2026-08-10";
src = fetchFromGitHub {
owner = "dokieli";
repo = "dokieli";
rev = "f0372663098582c0310c9e16918a55cf000fbaf1";
hash = "sha256-jpIQcE1GdjvEsk6HPxjdFLbrxGWvVCaaG7T08HdMj7Y=";
rev = "c23e80e4fe54a2ad20f36a9f21a0987f5e3e4505";
hash = "sha256-ZwK+MxrTodDvvJuQCIhcDkluor4ri856m/WhcVRwfzo=";
};
missingHashes = ./missing-hashes.json;
offlineCache = yarn-berry.fetchYarnBerryDeps {
inherit (finalAttrs) src missingHashes;
hash = "sha256-SEoYmh7oHmJrVhShOjRyaClyQxW9S96GCI3ggRkW+6U=";
hash = "sha256-AqmUWgVDksQeBKcC8mpq1xgQ5NcHTjX/YSgm9J+feBs=";
};
buildPhase = ''
@@ -78,10 +78,10 @@ stdenv.mkDerivation (finalAttrs: {
meta = {
description = "Clientside editor for decentralised article publishing, annotations and social interactions";
homepage = "https://github.com/linkeddata/dokieli";
license = with lib.licenses; [
cc-by-40
mit
homepage = "https://github.com/dokieli/dokieli";
license = lib.licenses.AND [
lib.licenses.asl20
lib.licenses.cc-by-40
];
platforms = lib.platforms.all;
maintainers = with lib.maintainers; [ shogo ];

View File

@@ -7,16 +7,16 @@
buildNpmPackage (finalAttrs: {
pname = "freifunk-meshviewer";
version = "13.1.0";
version = "13.2.0";
src = fetchFromGitHub {
owner = "freifunk";
repo = "meshviewer";
tag = "v${finalAttrs.version}";
sha256 = "sha256-u9lX7B402KFOHyaReyg3f5rDYDshbO/lyMYo7XxgJR8=";
sha256 = "sha256-ni5Ln9K+Bqq88oi+nwOyCqibJz3TesVreHDWEec6Xzk=";
};
npmDepsHash = "sha256-BaFtFdOu+WArH75nPtasSpecdGjMxTchFcF+K7krNpM=";
npmDepsHash = "sha256-gdGaJSwT5EYcrL/VBId4c6VFmyEbQ9v2LEJP1jc8yO8=";
installPhase = ''
mkdir -p $out/share/freifunk-meshviewer/

View File

@@ -197,6 +197,9 @@ stdenv.mkDerivation (finalAttrs: {
# We can generate it ourselves.
rm -f man/gnome-shell.1
rm data/theme/gnome-shell-{light,dark}.css
substituteInPlace meson.build subprojects/extensions-app/meson.build \
--replace-fail "gjs = find_program('gjs')" "gjs = find_program('${lib.getExe gjs}')"
'';
preInstall = ''
@@ -253,6 +256,8 @@ stdenv.mkDerivation (finalAttrs: {
};
};
strictDeps = true;
meta = {
description = "Core user interface for the GNOME 3 desktop";
homepage = "https://gitlab.gnome.org/GNOME/gnome-shell";

View File

@@ -9,20 +9,20 @@
}:
buildGoModule (finalAttrs: {
pname = "go-hass-agent";
version = "14.11.0";
version = "14.15.1";
src = fetchFromGitHub {
owner = "joshuar";
repo = "go-hass-agent";
tag = "v${finalAttrs.version}";
hash = "sha256-mC/Y1z2kudBZOEQU5S17ROx3iHPpDGGSkUJe7MMb/iE=";
hash = "sha256-lUn9abWF/dgh0LcxP3zDt/y1jQbWMaGk2A4WncpWVvk=";
};
vendorHash = "sha256-Xz7u8SSlxlDB5HbKMbm1xVYrtp1/zy2yBgoWS3NcTew=";
vendorHash = "sha256-8xhzFjyrlH6ORUjRaracR5vs9b4fUMIr5kztX+gPnNM=";
npmDeps = fetchNpmDeps {
inherit (finalAttrs) src;
hash = "sha256-LwOVVVGWufQ+Q3jiv0H9lf7zg3R9fXvvAlLiUWqtmZs=";
hash = "sha256-WoQ8VTJbPNbBwPQz9tf25AcN852RIVcyamzdTruUOuQ=";
};
overrideModAttrs = oldAttrs: {

View File

@@ -10,13 +10,13 @@
buildGoModule (finalAttrs: {
pname = "gocatcli";
version = "1.2.1";
version = "1.3.1";
src = fetchFromGitHub {
owner = "deadc0de6";
repo = "gocatcli";
tag = "v${finalAttrs.version}";
hash = "sha256-MUOyxDdU5xCQ7mQpNP1sS1zKGe/6/bqN1sSu5JqW36o=";
hash = "sha256-1aAzwwHKST08PIqp1jewx5E+unSXeIRCkJ45XqVd53g=";
};
vendorHash = "sha256-Zp9m0v/F4AJ9b3GH3/SoZx1jijHGR854f8KhhcIPjS8=";

View File

@@ -8,13 +8,13 @@
buildGoModule (finalAttrs: {
pname = "golds";
version = "0.8.4";
version = "0.8.5";
src = fetchFromGitHub {
owner = "go101";
repo = "golds";
tag = "v${finalAttrs.version}";
hash = "sha256-Jt0Q6Ie1HSqRs4+zlmNOXlSMXfWu0nSIOjglduq4FUE=";
hash = "sha256-WYjNvpNT5vuiHqo6TWE+uhptG4fke3eaKkJbeNIwwoU=";
};
# nixpkgs is not using the go distpack archive and missing a VERSION file in the source

View File

@@ -179,7 +179,7 @@ let
linux = stdenvNoCC.mkDerivation (finalAttrs: {
inherit pname meta passthru;
version = "151.0.7922.108";
version = "151.0.7922.137";
src =
let
@@ -194,8 +194,8 @@ let
url = "https://dl.google.com/linux/chrome/deb/pool/main/g/google-chrome-stable/google-chrome-stable_${finalAttrs.version}-1_${debArch}.deb";
hash =
{
amd64 = "sha256-v7bm00UFXrSBpQ20IyVvonMs4BD3haVsMn4hOmOO/e8=";
arm64 = "sha256-I/XSe+atb11pwcEbYC1O0lqEmc/foRw8pHmtC1goVJk=";
amd64 = "sha256-5tq/BEz5zQJ5z+hu+kMWgsGL/AbQYznOBVqqh66HFyc=";
arm64 = "sha256-0Omn4kXbMG80PWYw5NSs14JcUysN91wG0iWMgyFoD6E=";
}
.${debArch};
};
@@ -300,11 +300,11 @@ let
darwin = stdenvNoCC.mkDerivation (finalAttrs: {
inherit pname meta passthru;
version = "151.0.7922.109";
version = "151.0.7922.138";
src = fetchurl {
url = "http://dl.google.com/release2/chrome/cy2fmmk4db26pfgaa3nc5udp2i_151.0.7922.109/GoogleChrome-151.0.7922.109.dmg";
hash = "sha256-CqLJP/LSSX6lKkqBqYCbcIy9GLJGVGVmzH8pHYEsJoU=";
url = "http://dl.google.com/release2/chrome/guybfazgqqaxifu4eaufmhd2i4_151.0.7922.138/GoogleChrome-151.0.7922.138.dmg";
hash = "sha256-9iXev++hJo/uFY/UnR1NRijIdVy6ARAyiDt4rLUFdvU=";
};
dontPatch = true;

View File

@@ -0,0 +1,14 @@
diff --git a/go.mod b/go.mod
index fe507b4678693915f275648ff052c2d2d859f4cc..aeb7e04795d9527edd1c4c100a870b38f4de538c 100644
--- a/go.mod
+++ b/go.mod
@@ -104 +104 @@ require (
- github.com/yuin/goldmark v1.7.13 // indirect
+ github.com/yuin/goldmark v1.7.17 // indirect
diff --git a/go.sum b/go.sum
index 1c56fd543ca070281c9c23e83a3387b16cf3dac3..9cc1bcb4a0fac0eb2e366a9b438da16d6cd13428 100644
--- a/go.sum
+++ b/go.sum
@@ -217,0 +218,2 @@ github.com/yuin/goldmark v1.7.13/go.mod h1:ip/1k0VRfGynBgxOz0yCqHrbZXhcjxyuS66Br
+github.com/yuin/goldmark v1.7.17 h1:p36OVWwRb246iHxA/U4p8OPEpOTESm4n+g+8t0EE5uA=
+github.com/yuin/goldmark v1.7.17/go.mod h1:ip/1k0VRfGynBgxOz0yCqHrbZXhcjxyuS66Brc7iBKg=

View File

@@ -8,16 +8,21 @@
buildGoModule (finalAttrs: {
pname = "goshs";
version = "2.0.8";
version = "2.1.5";
src = fetchFromGitHub {
owner = "patrickhener";
owner = "goshs-labs";
repo = "goshs";
tag = "v${finalAttrs.version}";
hash = "sha256-xGV9Sr+IAkGrDv6Qz2mgDS6vL9oBj9l7AuZ13SW91FE=";
hash = "sha256-mVgBY1QhQ+tDQnfangqylNeCbBJTSJaM0y7vZ95BU3Y=";
};
vendorHash = "sha256-3+MGBaFWmMf2gDiZhYUxHFNmEfD/Xr1lNddlA5FQLUE=";
vendorHash = "sha256-LLYgb0DIFx97+ZXOlQc4yVdjjiw7ebXx76hADfWnlkw=";
patches = [
# No upstream fix yet; remove when updating to a release that uses goldmark 1.7.17 or later.
./CVE-2026-5160.patch
];
ldflags = [ "-s" ];
@@ -43,7 +48,7 @@ buildGoModule (finalAttrs: {
meta = {
description = "Simple, yet feature-rich web server written in Go";
homepage = "https://goshs.de";
changelog = "https://github.com/patrickhener/goshs/releases/tag/${finalAttrs.src.rev}";
changelog = "https://github.com/goshs-labs/goshs/releases/tag/v${finalAttrs.version}";
license = lib.licenses.mit;
maintainers = with lib.maintainers; [
fab

View File

@@ -0,0 +1,23 @@
diff --git a/kitty/key_names.py b/kitty/key_names.py
index 1c4ce3487..00d767d45 100644
--- a/kitty/key_names.py
+++ b/kitty/key_names.py
@@ -59,17 +59,7 @@ if is_macos:
else:
def load_libxkb_lookup() -> LookupFunc:
import ctypes
- for suffix in ('.0', ''):
- with suppress(Exception):
- lib = ctypes.CDLL(f'libxkbcommon.so{suffix}')
- break
- else:
- from ctypes.util import find_library
- lname = find_library('xkbcommon')
- if lname is None:
- raise RuntimeError('Failed to find libxkbcommon')
- lib = ctypes.CDLL(lname)
-
+ lib = ctypes.CDLL('@libxkbcommon@')
f = lib.xkb_keysym_from_name
f.argtypes = [ctypes.c_char_p, ctypes.c_int]
f.restype = ctypes.c_int

View File

@@ -2,6 +2,7 @@
lib,
stdenv,
fetchFromGitHub,
replaceVars,
python3Packages,
libunistring,
harfbuzz,
@@ -50,21 +51,21 @@
with python3Packages;
buildPythonApplication rec {
pname = "kitty";
version = "0.47.0";
version = "0.48.2";
pyproject = false;
src = fetchFromGitHub {
owner = "kovidgoyal";
repo = "kitty";
tag = "v${version}";
hash = "sha256-QI+h7LSpJ5VYae3XdwDhKmpLqEGpmSulXP/mTop3gio=";
hash = "sha256-qNgVPpvMm8Y/nbBjVvWVuZ954ZXIuWmXhldP3w8MBhU=";
};
goModules =
(buildGo126Module {
pname = "kitty-go-modules";
inherit src version;
vendorHash = "sha256-ZEiIGHj30h3l7mfJkOrPDTMI/GBtf/QDiG/lrqceggg=";
vendorHash = "sha256-BZudfNfREwNrgalaimC5Lp+UIdFS+jHFLl9mEXcHYMI=";
}).goModules;
buildInputs = [
@@ -142,6 +143,9 @@ buildPythonApplication rec {
# OSError: master_fd is in error condition
./disable-test_ssh_bootstrap_with_different_launchers.patch
(replaceVars ./libxkbcommon-runtime-path.patch {
libxkbcommon = "${lib.getLib libxkbcommon}/lib/libxkbcommon.so.0";
})
];
hardeningDisable = [
@@ -152,6 +156,7 @@ buildPythonApplication rec {
env = {
CGO_ENABLED = 0;
GOFLAGS = "-trimpath";
GOTOOLCHAIN = "local";
};
configurePhase = ''
@@ -243,6 +248,9 @@ buildPythonApplication rec {
+ ''
# These depend on files that are not available in the sandbox
rm tools/utils/machine_id/api_test.go
# These depend on cgroups and other resources that don't work as the tests expect in the sandbox
rm kitty_tests/child.py
'';
checkPhase = ''

View File

@@ -20,7 +20,7 @@
stdenv.mkDerivation (finalAttrs: {
pname = "libgsf";
version = "1.14.55";
version = "1.14.58";
outputs = [
"out"
@@ -32,7 +32,7 @@ stdenv.mkDerivation (finalAttrs: {
owner = "GNOME";
repo = "libgsf";
tag = "LIBGSF_${lib.replaceString "." "_" finalAttrs.version}";
hash = "sha256-lx/FgF4X0aLtUFRaX69gX9J7w9ZlO0A1xoVg9Fgvtfo=";
hash = "sha256-0QQas3AsH46OOCSuezoBSeIQSilaenl50stpNwNJsKc=";
};
postPatch = ''

View File

@@ -0,0 +1,37 @@
From dcb079931a929880518015794d709f93651154ca Mon Sep 17 00:00:00 2001
From: Ginger <ginger@gingershaped.computer>
Date: Tue, 11 Aug 2026 15:59:26 -0400
Subject: [PATCH 1/2] fix(backport): SEC28
(cherry picked from commit 49a8f6f53b6f86ed6abb8952843cb3a38c530ada)
---
src/service/threepid/mod.rs | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/src/service/threepid/mod.rs b/src/service/threepid/mod.rs
index dcc0b58ab..bda80f82e 100644
--- a/src/service/threepid/mod.rs
+++ b/src/service/threepid/mod.rs
@@ -112,6 +112,10 @@ pub async fn send_validation_email<Template: MessageTemplate>(
// If a validation session already exists for this client secret, we can either
// reuse it with a new token or return early because it's already valid.
| Some(session) => {
+ if session.email != recipient.email {
+ return Err!(Request(InvalidParam("Wrong email for session.")));
+ }
+
match session.validation_state {
| ValidationState::Validated => {
// If the existing session is already valid, don't send an email.
@@ -119,7 +123,7 @@ pub async fn send_validation_email<Template: MessageTemplate>(
},
| ValidationState::Pending(ref mut token) => {
// Check ratelimiting for the target address.
- if self.ratelimiter.check_key(&recipient.email).is_err() {
+ if self.ratelimiter.check_key(&session.email).is_err() {
return Err(Error::BadRequest(
ErrorKind::LimitExceeded { retry_after: None },
"You're sending emails too fast, try again in a few minutes.",
--
2.55.0

View File

@@ -0,0 +1,132 @@
From a00a615799bc55bc093a6298735732565aa2b566 Mon Sep 17 00:00:00 2001
From: Ginger <ginger@gingershaped.computer>
Date: Tue, 11 Aug 2026 16:35:24 -0400
Subject: [PATCH 2/2] fix(backport): SEC26
Reviewed-By: timedout <git@nexy7574.co.uk>
Reviewed-By: Ginger <ginger@gingershaped.computer>
(cherry picked from commit 700fbe472d4a8385b96f870256bfc00f9a15f809)
---
src/api/server/event_auth.rs | 27 ++++++++++-----------------
src/api/server/state.rs | 13 ++++++++++++-
src/api/server/state_ids.rs | 13 ++++++++++++-
3 files changed, 34 insertions(+), 19 deletions(-)
diff --git a/src/api/server/event_auth.rs b/src/api/server/event_auth.rs
index a9019e8e7..433e18f46 100644
--- a/src/api/server/event_auth.rs
+++ b/src/api/server/event_auth.rs
@@ -1,12 +1,9 @@
use std::{borrow::Borrow, iter::once};
use axum::extract::State;
-use conduwuit::{Err, Error, Result, info, utils::stream::ReadyExt};
+use conduwuit::{Err, Result, Event, info, utils::stream::ReadyExt};
use futures::StreamExt;
-use ruma::{
- RoomId,
- api::{client::error::ErrorKind, federation::authorization::get_event_authorization},
-};
+use ruma::api::federation::authorization::get_event_authorization;
use super::AccessCheck;
use crate::Ruma;
@@ -42,25 +39,21 @@ pub(crate) async fn get_event_authorization_route(
return Err!(Request(NotFound("This server is not participating in that room.")));
}
- let event = services
+ // The event must be in the room we just authorised access to
+ if !services
.rooms
.timeline
- .get_pdu_json(&body.event_id)
+ .get_pdu(&body.event_id)
.await
- .map_err(|_| Error::BadRequest(ErrorKind::NotFound, "Event not found."))?;
-
- let room_id_str = event
- .get("room_id")
- .and_then(|val| val.as_str())
- .ok_or_else(|| Error::bad_database("Invalid event in database."))?;
-
- let room_id = <&RoomId>::try_from(room_id_str)
- .map_err(|_| Error::bad_database("Invalid room_id in event in database."))?;
+ .is_ok_and(|pdu| pdu.room_id_or_hash() == body.room_id)
+ {
+ return Err!(Request(NotFound("Event not found.")));
+ }
let auth_chain = services
.rooms
.auth_chain
- .event_ids_iter(room_id, once(body.event_id.borrow()))
+ .event_ids_iter(&body.room_id, once(body.event_id.borrow()))
.ready_filter_map(Result::ok)
.filter_map(|id| async move { services.rooms.timeline.get_pdu_json(&id).await.ok() })
.then(|pdu| services.sending.convert_to_outgoing_federation_event(pdu))
diff --git a/src/api/server/state.rs b/src/api/server/state.rs
index 5e1ad8ca2..05a008b74 100644
--- a/src/api/server/state.rs
+++ b/src/api/server/state.rs
@@ -1,7 +1,7 @@
use std::{borrow::Borrow, iter::once};
use axum::extract::State;
-use conduwuit::{Err, Result, at, err, info, utils::IterStream};
+use conduwuit::{Err, Event, Result, at, err, info, utils::IterStream};
use futures::{FutureExt, StreamExt, TryStreamExt};
use ruma::{OwnedEventId, api::federation::event::get_room_state};
@@ -24,6 +24,17 @@ pub(crate) async fn get_room_state_route(
.check()
.await?;
+ // The event must be in the room we just authorised access to
+ if !services
+ .rooms
+ .timeline
+ .get_pdu(&body.event_id)
+ .await
+ .is_ok_and(|pdu| pdu.room_id_or_hash() == body.room_id)
+ {
+ return Err!(Request(NotFound("Event not found.")));
+ }
+
if !services
.rooms
.state_cache
diff --git a/src/api/server/state_ids.rs b/src/api/server/state_ids.rs
index c9dea3116..206f3efc5 100644
--- a/src/api/server/state_ids.rs
+++ b/src/api/server/state_ids.rs
@@ -1,7 +1,7 @@
use std::{borrow::Borrow, iter::once};
use axum::extract::State;
-use conduwuit::{Err, Result, at, err, info};
+use conduwuit::{Err, Event, Result, at, err, info};
use futures::{StreamExt, TryStreamExt};
use ruma::{OwnedEventId, api::federation::event::get_room_state_ids};
@@ -25,6 +25,17 @@ pub(crate) async fn get_room_state_ids_route(
.check()
.await?;
+ // The event must be in the room we just authorised access to
+ if !services
+ .rooms
+ .timeline
+ .get_pdu(&body.event_id)
+ .await
+ .is_ok_and(|pdu| pdu.room_id_or_hash() == body.room_id)
+ {
+ return Err!(Request(NotFound("Event not found.")));
+ }
+
if !services
.rooms
.state_cache
--
2.55.0

View File

@@ -52,6 +52,8 @@ rustPlatform.buildRustPackage (finalAttrs: {
patches = [
./0001-fix-backport-SEC10.patch
./0002-fix-backport-SEC28.patch
./0003-fix-backport-SEC26.patch
];
nativeBuildInputs = [

View File

@@ -9,13 +9,13 @@
stdenvNoCC.mkDerivation (finalAttrs: {
pname = "microcode-intel";
version = "20260512";
version = "20260811";
src = fetchFromGitHub {
owner = "intel";
repo = "Intel-Linux-Processor-Microcode-Data-Files";
tag = "microcode-${finalAttrs.version}";
hash = "sha256-hJfuxnHxHAxoTFAdgzontCl2pl5ad222I8BGyHO+MxQ=";
hash = "sha256-8BvyFsBeL9tRutY6J2DotvVbKrKb3LUBro5MLO+egrg=";
};
nativeBuildInputs = [ libarchive ];

View File

@@ -17,14 +17,14 @@
python3Packages.buildPythonApplication (finalAttrs: {
pname = "polychromatic";
version = "0.9.7";
version = "0.9.8";
pyproject = false;
src = fetchFromGitHub {
owner = "polychromatic";
repo = "polychromatic";
tag = "v${finalAttrs.version}";
hash = "sha256-2Uo6/74o+cSQQsYsE+7nVDsetnaYjQzL8xkJhUN3E2o=";
hash = "sha256-5+7u99+fwDXg3s32QyjLO7X0irw5wY7pUDvT6sSv5nA=";
};
postPatch = ''

View File

@@ -14,14 +14,14 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "radicle-ci-broker";
version = "0.30.0";
version = "0.31.0";
src = fetchFromRadicle {
seed = "seed.radicle.dev";
repo = "zwTxygwuz5LDGBq255RA2CbNGrz8";
node = "z6MkgEMYod7Hxfy9qCvDv5hYHkZ4ciWmLFgfvm3Wn1b2w2FV";
tag = "v${finalAttrs.version}";
hash = "sha256-30+s//C9uMpGgA976RRduHmnmF6YEYmmG+V5P/1TYhA=";
hash = "sha256-yY2ke4JBAn0ZTaZ7HV8GCPF5Yqj1j+7GvjFXQQVM3ME=";
leaveDotGit = true;
postFetch = ''
git -C $out rev-parse --short HEAD > $out/.git_head
@@ -29,7 +29,7 @@ rustPlatform.buildRustPackage (finalAttrs: {
'';
};
cargoHash = "sha256-9DzdeJcjl8IpmDR+kXdbEHrGi/5e9P26HsZJ9OPZRSA=";
cargoHash = "sha256-+XB2+k18gWEO7tpsQK+ua133PcZ0mxV+txle7VutXIk=";
postPatch = ''
substituteInPlace build.rs \

View File

@@ -62,6 +62,11 @@ stdenv.mkDerivation (finalAttrs: {
gst_all_1.gst-plugins-ugly
];
postPatch = ''
substituteInPlace meson.build \
--replace-fail "gjs = find_program('gjs', 'gjs-console')" "gjs = find_program('${lib.getExe gjs}')"
'';
# See https://github.com/NixOS/nixpkgs/issues/31168
postInstall = ''
for file in $out/libexec/org.gnome.NautilusPreviewer
@@ -77,6 +82,8 @@ stdenv.mkDerivation (finalAttrs: {
};
};
strictDeps = true;
meta = {
homepage = "https://gitlab.gnome.org/GNOME/sushi";
changelog = "https://gitlab.gnome.org/GNOME/sushi/-/blob/${finalAttrs.version}/NEWS?ref_type=tags";

View File

@@ -1,44 +0,0 @@
{
lib,
buildPythonPackage,
fetchFromGitHub,
pytestCheckHook,
cryptography,
nibabel,
numpy,
pydicom,
simpleitk,
}:
buildPythonPackage rec {
pname = "pymedio";
version = "0.2.14";
format = "setuptools";
src = fetchFromGitHub {
owner = "jcreinhold";
repo = "pymedio";
tag = "v${version}";
hash = "sha256-x3CHoWASDrUoCXfj73NF+0Y/3Mb31dK2Lh+o4OD9ryk=";
};
propagatedBuildInputs = [ numpy ];
nativeCheckInputs = [
pytestCheckHook
cryptography
nibabel
pydicom
simpleitk
];
pythonImportsCheck = [ "pymedio" ];
meta = {
description = "Read medical image files into Numpy arrays";
homepage = "https://github.com/jcreinhold/pymedio";
changelog = "https://github.com/jcreinhold/pymedio/blob/v${version}/HISTORY.rst";
license = lib.licenses.mit;
maintainers = with lib.maintainers; [ bcdarwin ];
};
}

View File

@@ -18,7 +18,7 @@
buildPythonPackage (finalAttrs: {
pname = "python-statemachine";
version = "3.2.0";
version = "3.2.1";
pyproject = true;
__structuredAttrs = true;
@@ -26,7 +26,7 @@ buildPythonPackage (finalAttrs: {
src = fetchPypi {
pname = "python_statemachine";
inherit (finalAttrs) version;
hash = "sha256-RLmMubsQgYke9u+pB8gh0FyuUxSiuZcT5W1Wqcli3gg=";
hash = "sha256-3/NmgsqwC6f3l+AevdkMTbssLgD+fPzJ+Sb2PFAmZQc=";
};
build-system = [ hatchling ];

View File

@@ -453,7 +453,6 @@
"python3Packages.pylance",
"python3Packages.pymanopt",
"python3Packages.pymc",
"python3Packages.pymedio",
"python3Packages.pymoo",
"python3Packages.pyotb",
"python3Packages.pypasser",

View File

@@ -18,7 +18,7 @@ in
buildLinux (
args
// rec {
version = "7.1.5";
version = "7.1.8";
pname = "linux-zen";
modDirVersion = lib.versions.pad 3 "${version}-${suffix}";
isZen = true;
@@ -27,7 +27,7 @@ buildLinux (
owner = "zen-kernel";
repo = "zen-kernel";
rev = "v${version}-${suffix}";
sha256 = "11d3c2hx2py6fy6qj0dqk2w392m144wjrfg5ldfh93x9mp4ffhjd";
sha256 = "0gnbx1r0hpsws2r9wq55szmbrkimbh0wvrj2b3df4y82sxkg91z4";
};
# This is based on the following source:

View File

@@ -9,11 +9,11 @@
callPackage ../nginx/generic.nix args rec {
pname = "angie";
version = "1.11.8";
version = "1.12.1";
src = fetchurl {
url = "https://download.angie.software/files/angie-${version}.tar.gz";
hash = "sha256-hJiXx495w7BNA1d440mTqSGI5r0sDDuozjrV6xUF69M=";
hash = "sha256-X08gO+Kspv4gdwtInHIORuUdM35SEGXn5HK2HiTj0vU=";
};
configureFlags = lib.optionals withAcme [

View File

@@ -432,6 +432,7 @@ mapAliases {
pyliblo = throw "pyliblo is unmaintained upstream and was removed from nixpkgs. Please use pyliblo3 instead"; # added 2025-06-23
pylit = throw "'pylit' has been removed as it was broken and unmaintained upstream"; # Added 2025-11-29
pymc3 = throw "'pymc3' has been renamed to/replaced by 'pymc'"; # Converted to throw 2025-10-29
pymedio = throw "pymedio was removed, as it is archived since 2025 in upstream. The modules 'dicom-numpy' and 'simpleitk' can be used as alternatives."; # added 2026-09-11
pymelcloud = throw "'pymelcloud' has been renamed to/replaced by 'python-melcloud'"; # Converted to throw 2025-10-29
PyMVGLive = throw "'PyMVGLive' has been renamed to/replaced by 'pymvglive'"; # Converted to throw 2025-10-29
pymyq = throw "'pymyq' has been renamed to/replaced by 'python-myq'"; # Converted to throw 2025-10-29

View File

@@ -14484,8 +14484,6 @@ self: super: with self; {
pymediaroom = callPackage ../development/python-modules/pymediaroom { };
pymedio = callPackage ../development/python-modules/pymedio { };
pymee = callPackage ../development/python-modules/pymee { };
pymeeus = callPackage ../development/python-modules/pymeeus { };