Merge master into staging-nixos

This commit is contained in:
nixpkgs-ci[bot]
2025-11-23 00:21:44 +00:00
committed by GitHub
190 changed files with 2126 additions and 1919 deletions

View File

@@ -46,7 +46,7 @@ module.exports = async ({ github, context, core, dry }) => {
name: 'maintainers',
})
).data.artifacts[0]
if (!artifact) continue
if (!artifact || artifact.expired) continue
await artifactClient.downloadArtifact(artifact.id, {
findBy: {
@@ -152,6 +152,8 @@ module.exports = async ({ github, context, core, dry }) => {
})
).data
log('author', pull_request.user?.login)
const maintainers = await getMaintainerMap(pull_request.base.ref)
const merge_bot_eligible = await handleMerge({
@@ -607,7 +609,7 @@ module.exports = async ({ github, context, core, dry }) => {
).data.artifacts[0]
// If the artifact is not available, the next iteration starts at the beginning.
if (artifact) {
if (artifact && !artifact.expired) {
stats.artifacts++
const { downloadPath } = await artifactClient.downloadArtifact(

View File

@@ -14,7 +14,7 @@ async function handleReviewers({
const pull_number = pull_request.number
const requested_reviewers = new Set(
pull_request.requested_reviewers.map(({ login }) => login),
pull_request.requested_reviewers.map(({ login }) => login.toLowerCase()),
)
log(
'reviewers - requested_reviewers',
@@ -22,7 +22,7 @@ async function handleReviewers({
)
const existing_reviewers = new Set(
reviews.map(({ user }) => user?.login).filter(Boolean),
reviews.map(({ user }) => user?.login.toLowerCase()).filter(Boolean),
)
log(
'reviewers - existing_reviewers',
@@ -43,9 +43,11 @@ async function handleReviewers({
const users = new Set([
...(await Promise.all(
maintainers.map(async (id) => (await getUser(id)).login),
maintainers.map(async (id) => (await getUser(id)).login.toLowerCase()),
)),
...owners.filter((handle) => handle && !handle.includes('/')),
...owners
.filter((handle) => handle && !handle.includes('/'))
.map((handle) => handle.toLowerCase()),
])
log('reviewers - users', Array.from(users).join(', '))
@@ -60,14 +62,14 @@ async function handleReviewers({
const team_members = new Set(
(await Promise.all(Array.from(teams, getTeamMembers)))
.flat(1)
.map(({ login }) => login),
.map(({ login }) => login.toLowerCase()),
)
log('reviewers - team_members', Array.from(team_members).join(', '))
const new_reviewers = users
.union(team_members)
// We can't request a review from the author.
.difference(new Set([pull_request.user?.login]))
.difference(new Set([pull_request.user?.login.toLowerCase()]))
log('reviewers - new_reviewers', Array.from(new_reviewers).join(', '))
// Filter users to repository collaborators. If they're not, they can't be requested

View File

@@ -9,7 +9,12 @@ let
vteInitSnippet = ''
# Show current working directory in VTE terminals window title.
# Supports both bash and zsh, requires interactive shell.
. ${pkgs.vte-gtk4}/etc/profile.d/vte.sh
. ${
pkgs.vte.override {
withApp = false;
gtkVersion = null;
}
}/etc/profile.d/vte.sh
'';
in

View File

@@ -1123,6 +1123,7 @@
./services/networking/chisel-server.nix
./services/networking/cjdns.nix
./services/networking/clatd.nix
./services/networking/cloudflare-ddns.nix
./services/networking/cloudflare-dyndns.nix
./services/networking/cloudflare-warp.nix
./services/networking/cloudflared.nix

View File

@@ -19,7 +19,7 @@ let
mode ? "r",
trail ? "",
}:
lib.optionalString (hasAttr path etc) "${mode} ${config.environment.etc.${path}.source}${trail},";
lib.optionalString (hasAttr path etc) "${config.environment.etc.${path}.source}${trail} ${mode},";
in
if isAttrs arg then go arg else go { path = arg; };
in
@@ -93,19 +93,19 @@ in
];
"abstractions/base" = ''
include "${pkgs.apparmor-profiles}/etc/apparmor.d/abstractions/base"
r ${pkgs.stdenv.cc.libc}/share/locale/**,
r ${pkgs.stdenv.cc.libc}/share/locale.alias,
r ${config.i18n.glibcLocales}/lib/locale/locale-archive,
${pkgs.stdenv.cc.libc}/share/locale/** r,
${pkgs.stdenv.cc.libc}/share/locale.alias r,
${config.i18n.glibcLocales}/lib/locale/locale-archive r,
${etcRule "localtime"}
r ${pkgs.tzdata}/share/zoneinfo/**,
r ${pkgs.stdenv.cc.libc}/share/i18n/**,
${pkgs.tzdata}/share/zoneinfo/** r,
${pkgs.stdenv.cc.libc}/share/i18n/** r,
'';
"abstractions/bash" = ''
include "${pkgs.apparmor-profiles}/etc/apparmor.d/abstractions/bash"
# bash inspects filesystems at startup
# and /etc/mtab is linked to /proc/mounts
r @{PROC}/mounts,
@{PROC}/mounts r,
# system-wide bash configuration
''
@@ -296,8 +296,8 @@ in
# looking up users by name or id, groups by name or id, hosts by name
# or IP, etc. These operations may be performed through files, dns,
# NIS, NIS+, LDAP, hesiod, wins, etc. Allow them all here.
mr ${getLib pkgs.nss}/lib/libnss_*.so*,
mr ${getLib pkgs.nss}/lib64/libnss_*.so*,
${getLib pkgs.nss}/lib/libnss_*.so* mr,
${getLib pkgs.nss}/lib64/libnss_*.so* mr,
''
+ lib.concatMapStringsSep "\n" etcRule [
"group"
@@ -463,11 +463,11 @@ in
include "${pkgs.apparmor-profiles}/etc/apparmor.d/abstractions/ssl_certs"
# For the NixOS module: security.acme
r /var/lib/acme/*/cert.pem,
r /var/lib/acme/*/chain.pem,
r /var/lib/acme/*/fullchain.pem,
/var/lib/acme/*/cert.pem r,
/var/lib/acme/*/chain.pem r,
/var/lib/acme/*/fullchain.pem r,
r /etc/pki/tls/certs/,
/etc/pki/tls/certs/ r,
''
+ lib.concatMapStringsSep "\n" etcRule [
@@ -510,8 +510,8 @@ in
];
"abstractions/ssl_keys" = ''
# security.acme NixOS module
r /var/lib/acme/*/full.pem,
r /var/lib/acme/*/key.pem,
/var/lib/acme/*/full.pem r,
/var/lib/acme/*/key.pem r,
'';
"abstractions/vulkan" = ''
include "${pkgs.apparmor-profiles}/etc/apparmor.d/abstractions/vulkan"

View File

@@ -179,47 +179,33 @@ in
services.xserver.displayManager.lightdm.enable = false;
users.users.gdm = {
name = "gdm";
uid = config.ids.uids.gdm;
group = "gdm";
description = "GDM user";
};
users.users = lib.mkMerge [
{
gdm = {
name = "gdm";
uid = config.ids.uids.gdm;
group = "gdm";
description = "GDM user";
};
users.users.gdm-greeter = {
isSystemUser = true;
uid = 60578;
group = "gdm";
home = "/run/gdm";
};
gdm-greeter = {
isSystemUser = true;
uid = 60578;
group = "gdm";
home = "/run/gdm";
};
}
users.users.gdm-greeter-1 = {
isSystemUser = true;
uid = 60579;
group = "gdm";
home = "/run/gdm-1";
};
users.users.gdm-greeter-2 = {
isSystemUser = true;
uid = 60580;
group = "gdm";
home = "/run/gdm-2";
};
users.users.gdm-greeter-3 = {
isSystemUser = true;
uid = 60581;
group = "gdm";
home = "/run/gdm-3";
};
users.users.gdm-greeter-4 = {
isSystemUser = true;
uid = 60582;
group = "gdm";
home = "/run/gdm-4";
};
(lib.genAttrs' [ 1 2 3 4 ] (
i:
lib.nameValuePair "gdm-greeter-${toString i}" {
isSystemUser = true;
uid = 60578 + i;
group = "gdm";
home = "/run/gdm-${toString i}";
}
))
];
users.groups.gdm.gid = config.ids.gids.gdm;

View File

@@ -22,9 +22,8 @@ in
description = ''
Path to a file containing the Cloudflare API authentication token.
The file content should be in the format `CLOUDFLARE_API_TOKEN=YOUR_SECRET_TOKEN`.
The service user `${cfg.user}` needs read access to this file.
The service user needs read access to this file.
Ensure permissions are secure (e.g., `0400` or `0440`) and ownership is appropriate
(e.g., `owner = root`, `group = ${cfg.group}`).
Using `CLOUDFLARE_API_TOKEN` is preferred over the deprecated `CF_API_TOKEN`.
'';
example = "/run/secrets/cloudflare-ddns-token";
@@ -324,4 +323,7 @@ in
};
};
};
meta.maintainers = with lib.maintainers; [
shokerplz
];
}

View File

@@ -401,40 +401,40 @@ in
];
security.apparmor.policies."bin.mumble-server".profile = ''
abi <abi/4.0>,
include <tunables/global>
${cfg.package}/bin/{mumble-server,.mumble-server-wrapped} {
profile ${cfg.package}/bin/{mumble-server,.mumble-server-wrapped} {
include <abstractions/base>
include <abstractions/nameservice>
include <abstractions/ssl_certs>
include "${pkgs.apparmorRulesFromClosure { name = "mumble-server"; } cfg.package}"
pix ${cfg.package}/bin/.mumble-server-wrapped,
${cfg.package}/bin/.mumble-server-wrapped pix,
r ${config.environment.etc."os-release".source},
r ${config.environment.etc."lsb-release".source},
owner rwk ${cfg.stateDir}/murmur.sqlite,
owner rw ${cfg.stateDir}/murmur.sqlite-journal,
owner r ${cfg.stateDir}/,
r /run/murmur/murmurd.pid,
r /run/murmur/murmurd.ini,
r ${configFile},
''
+ lib.optionalString cfg.logToFile ''
rw /var/log/murmur/murmurd.log,
''
+ lib.optionalString (cfg.sslCert != null) ''
r ${cfg.sslCert},
''
+ lib.optionalString (cfg.sslKey != null) ''
r ${cfg.sslKey},
''
+ lib.optionalString (cfg.sslCa != null) ''
r ${cfg.sslCa},
''
+ lib.optionalString (cfg.dbus != null) ''
dbus bus=${cfg.dbus}
''
+ ''
${config.environment.etc."os-release".source} r,
${config.environment.etc."lsb-release".source} r,
owner ${cfg.stateDir}/murmur.sqlite rwk,
owner ${cfg.stateDir}/murmur.sqlite-journal rw,
owner ${cfg.stateDir}/ r,
/run/murmur/murmurd.pid r,
/run/murmur/murmurd.ini r,
${configFile} r,
${lib.optionalString cfg.logToFile ''
/var/log/murmur/murmurd.log rw,
''}
${lib.optionalString (cfg.sslCert != null) ''
${cfg.sslCert} r,
''}
${lib.optionalString (cfg.sslKey != null) ''
${cfg.sslKey} r,
''}
${lib.optionalString (cfg.sslCa != null) ''
${cfg.sslCa} r,
''}
${lib.optionalString (cfg.dbus != null) ''
dbus bus=${cfg.dbus},
''}
include if exists <local/bin.mumble-server>
}
'';
};

View File

@@ -65,6 +65,7 @@ in
StateDirectory = "nginx-sso";
WorkingDirectory = "/var/lib/nginx-sso";
RuntimeDirectory = "nginx-sso";
RuntimeDirectoryMode = "0700"; # Contains secrets
ExecStart = ''
${lib.getExe cfg.package} \
--config ${configPath} \

View File

@@ -585,23 +585,23 @@ in
include "${cfg.package.apparmor}/bin.transmission-daemon"
'';
security.apparmor.includes."local/bin.transmission-daemon" = ''
r ${config.systemd.services.transmission.environment.CURL_CA_BUNDLE},
${config.systemd.services.transmission.environment.CURL_CA_BUNDLE} r,
owner rw ${cfg.home}/${settingsDir}/**,
rw ${cfg.settings.download-dir}/**,
owner ${cfg.home}/${settingsDir}/** rw,
${cfg.settings.download-dir}/** rw,
${optionalString cfg.settings.incomplete-dir-enabled ''
rw ${cfg.settings.incomplete-dir}/**,
${cfg.settings.incomplete-dir}/** rw,
''}
${optionalString cfg.settings.watch-dir-enabled ''
r${optionalString cfg.settings.trash-original-torrent-files "w"} ${cfg.settings.watch-dir}/**,
${cfg.settings.watch-dir}/** r${optionalString cfg.settings.trash-original-torrent-files "w"},
''}
profile dirs {
rw ${cfg.settings.download-dir}/**,
${cfg.settings.download-dir}/** rw,
${optionalString cfg.settings.incomplete-dir-enabled ''
rw ${cfg.settings.incomplete-dir}/**,
${cfg.settings.incomplete-dir}/** rw,
''}
${optionalString cfg.settings.watch-dir-enabled ''
r${optionalString cfg.settings.trash-original-torrent-files "w"} ${cfg.settings.watch-dir}/**,
${cfg.settings.watch-dir}/** r${optionalString cfg.settings.trash-original-torrent-files "w"},
''}
}
@@ -612,12 +612,12 @@ in
# any existing profile for script-torrent-done-filename
# FIXME: to be tested as I'm not sure it works well with NoNewPrivileges=
# https://gitlab.com/apparmor/apparmor/-/wikis/AppArmorStacking#seccomp-and-no_new_privs
px ${cfg.settings.script-torrent-done-filename} -> &@{dirs},
${cfg.settings.script-torrent-done-filename} px -> &@{dirs},
''
}
${optionalString (cfg.webHome != null) ''
r ${cfg.webHome}/**,
${cfg.webHome}/** r,
''}
'';
};

View File

@@ -207,15 +207,18 @@ in
environment.systemPackages = [ cfg.package ];
security.apparmor.policies."bin.miniflux".profile = ''
abi <abi/4.0>,
include <tunables/global>
${cfg.package}/bin/miniflux {
profile ${cfg.package}/bin/miniflux {
include <abstractions/base>
include <abstractions/nameservice>
include <abstractions/ssl_certs>
include <abstractions/golang>
include "${pkgs.apparmorRulesFromClosure { name = "miniflux"; } cfg.package}"
r ${cfg.package}/bin/miniflux,
rw /run/miniflux/**,
${cfg.package}/bin/miniflux r,
/run/miniflux/** rw,
include if exists <local/bin.miniflux>
}
'';
};

View File

@@ -27,7 +27,7 @@ in
# automatically and that 'systemd-shutdown' runs our script.
machine.wait_for_unit("multi-user.target")
# .shutdown() would wait for the machine to power off
machine.succeed("systemctl poweroff")
machine.execute("systemctl poweroff", check_return=False)
# Message printed by systemd-shutdown
machine.wait_for_console_text("Unmounting '/oldroot'")
machine.wait_for_console_text("${msg}")

View File

@@ -7,6 +7,7 @@
python3,
zbar,
enableQt ? true,
enablePythonEcdsa ? false,
callPackage,
qtwayland,
}:
@@ -22,15 +23,25 @@ let
in
python3.pkgs.buildPythonApplication rec {
pname = "electrum";
version = "4.6.0";
format = "setuptools";
version = "4.6.2";
pyproject = true;
src = fetchurl {
url = "https://download.electrum.org/${version}/Electrum-${version}.tar.gz";
hash = "sha256-aQqZXyfqFgc1j2r836eaaayOmSzDijHlYXmF+OBw418=";
hash = "sha256-ZrwzAeeMNrs6KzLGDg5oBF7E+GGLYCVczO6R18TKRuE=";
};
build-system = [ protobuf ] ++ lib.optionals enableQt [ wrapQtAppsHook ];
build-system = with python3.pkgs; [
setuptools
];
nativeBuildInputs = [
protobuf
python3.pkgs.pythonRelaxDepsHook
]
++ lib.optionals enableQt [
wrapQtAppsHook
];
buildInputs = lib.optional (stdenv.hostPlatform.isLinux && enableQt) qtwayland;
dependencies =
@@ -56,18 +67,31 @@ python3.pkgs.buildPythonApplication rec {
electrum-ecc
# plugins
ledger-bitcoin
cbor2
pyserial
]
++ lib.optionals enablePythonEcdsa [
# enablePythonEcdsa gates plugins known to pull in python-ecdsa, which we
# avoid by default due to CVE-2024-23342.
ckcc-protocol
keepkey
trezor
bitbox02
cbor2
pyserial
]
++ lib.optionals enableQt [
pyqt6
qdarkstyle
];
pythonRelaxDeps = [
"attrs"
"dnspython"
];
pythonRemoveDeps = [
"protobuf"
];
checkInputs =
with python3.pkgs;
lib.optionals enableQt [
@@ -77,7 +101,11 @@ python3.pkgs.buildPythonApplication rec {
"tests/test_qml_types.py"
];
postPatch =
postPatch = ''
# Upstream tarball omits regenerated protobuf bindings in some releases.
protoc --python_out=. electrum/paymentrequest.proto
''
+ (
if enableQt then
''
substituteInPlace ./electrum/qrscanner.py \
@@ -86,7 +114,8 @@ python3.pkgs.buildPythonApplication rec {
else
''
sed -i '/qdarkstyle/d' contrib/requirements/requirements.txt
'';
''
);
postInstall = lib.optionalString stdenv.hostPlatform.isLinux ''
substituteInPlace $out/share/applications/electrum.desktop \
@@ -98,7 +127,15 @@ python3.pkgs.buildPythonApplication rec {
wrapQtApp $out/bin/electrum
'';
preFixup = ''
makeWrapperArgs+=(--prefix PYTHONPATH : ${python3.pkgs.protobuf}/${python3.sitePackages})
''
+ lib.optionalString enableQt ''
qtWrapperArgs+=(--prefix PYTHONPATH : ${python3.pkgs.protobuf}/${python3.sitePackages})
'';
nativeCheckInputs = with python3.pkgs; [
protobuf
pytestCheckHook
pyaes
pycryptodomex
@@ -108,6 +145,7 @@ python3.pkgs.buildPythonApplication rec {
# avoid homeless-shelter error in tests
preCheck = ''
export PYTHONPATH=${python3.pkgs.protobuf}/${python3.sitePackages}:$PYTHONPATH
export HOME="$(mktemp -d)"
'';

View File

@@ -63,13 +63,13 @@
"vendorHash": "sha256-QWBzQXx/dzWZr9dn3LHy8RIvZL1EA9xYqi7Ppzvju7g="
},
"auth0_auth0": {
"hash": "sha256-Hxvk8TTTF+zFgbtnlQ36Ksw1jHlegVnFTbh+xuV1FEs=",
"hash": "sha256-J2fMZBWbLL4hEPTqN7aKrqSOPQPA11NGZ/yILZQot1Q=",
"homepage": "https://registry.terraform.io/providers/auth0/auth0",
"owner": "auth0",
"repo": "terraform-provider-auth0",
"rev": "v1.35.0",
"rev": "v1.36.0",
"spdx": "MPL-2.0",
"vendorHash": "sha256-+laQm8vbuf1WmUVovdD1qvWWJd65W9fzHzINFVPtRh4="
"vendorHash": "sha256-2UfA1QHpVgRKi6PtZ5cHHuO4m5cN6KWlLt3hmPca6HY="
},
"aviatrixsystems_aviatrix": {
"hash": "sha256-V1JRVOMHQu5KlPFw7q/qZuHlJjdVSQotI9w7s88v8GM=",
@@ -1030,13 +1030,13 @@
"vendorHash": "sha256-ofzbDmivXgH1i1Gjhpyp0bk3FDs5SnxwoRuNAWyMqyI="
},
"opentelekomcloud_opentelekomcloud": {
"hash": "sha256-gwHugaLKjLIp7LHHbo4F25P3ncgjGavKYcIfSjXs7KM=",
"hash": "sha256-dKeoICBZca/IayPwX8HedPl+HgemC9IHPzzKlI8281Y=",
"homepage": "https://registry.terraform.io/providers/opentelekomcloud/opentelekomcloud",
"owner": "opentelekomcloud",
"repo": "terraform-provider-opentelekomcloud",
"rev": "v1.36.52",
"rev": "v1.36.53",
"spdx": "MPL-2.0",
"vendorHash": "sha256-0RE5ZqB16JPoFPZYgwupNyYZiXQnC3Sq4f+CLNjD6BM="
"vendorHash": "sha256-JH7wPgkGKEUBOgv09sz4rfJm+RJQwy3Z2dqHxrF8lZU="
},
"opsgenie_opsgenie": {
"hash": "sha256-Y67kcg/ovvZc22l1CBz0Mqu7DAIit5F0jQNfQrl2EGI=",

View File

@@ -175,21 +175,22 @@ stdenv.mkDerivation (finalAttrs: {
postInstall = ''
mkdir $apparmor
cat >$apparmor/bin.transmission-daemon <<EOF
abi <abi/4.0>,
include <tunables/global>
$out/bin/transmission-daemon {
profile $out/bin/transmission-daemon {
include <abstractions/base>
include <abstractions/nameservice>
include <abstractions/ssl_certs>
include "${apparmorRules}"
r @{PROC}/sys/kernel/random/uuid,
r @{PROC}/sys/vm/overcommit_memory,
r @{PROC}/@{pid}/environ,
r @{PROC}/@{pid}/mounts,
rwk /tmp/tr_session_id_*,
@{PROC}/sys/kernel/random/uuid r,
@{PROC}/sys/vm/overcommit_memory r,
@{PROC}/@{pid}/environ r,
@{PROC}/@{pid}/mounts r,
/tmp/tr_session_id_* rwk,
r $out/share/transmission/public_html/**,
$out/share/transmission/public_html/** r,
include <local/bin.transmission-daemon>
include if exists <local/bin.transmission-daemon>
}
EOF
install -Dm0444 -t $out/share/icons ../qt/icons/transmission.svg

View File

@@ -774,6 +774,7 @@ rec {
# On Darwin, the debug symbols are in a separate directory.
"./bin/test_binary1.dSYM/Contents/Info.plist"
"./bin/test_binary1.dSYM/Contents/Resources/DWARF/test_binary1"
"./bin/test_binary1.dSYM/Contents/Resources/Relocations/${stdenv.hostPlatform.rust.platform.arch}/test_binary1.yml"
];
};

View File

@@ -15,6 +15,16 @@
windows,
}:
let
interpolateString =
s:
if lib.isList s then
lib.concatMapStringsSep " " (s: "${s}") (lib.filter (s: s != null) s)
else if s == null then
""
else
"${s}";
in
lib.extendMkDerivation {
constructDrv = stdenv.mkDerivation;
@@ -23,6 +33,7 @@ lib.extendMkDerivation {
"cargoUpdateHook"
"cargoLock"
"useFetchCargoVendor"
"RUSTFLAGS"
];
extendDrvArgs =
@@ -77,11 +88,19 @@ lib.extendMkDerivation {
assert lib.warnIf (args ? useFetchCargoVendor)
"buildRustPackage: `useFetchCargoVendor` is non‐optional and enabled by default as of 25.05, remove it"
true;
{
env = {
PKG_CONFIG_ALLOW_CROSS = if stdenv.buildPlatform != stdenv.hostPlatform then 1 else 0;
RUST_LOG = logLevel;
RUSTFLAGS =
lib.optionalString (
stdenv.hostPlatform.isDarwin && buildType == "debug"
) "-C split-debuginfo=packed "
# Workaround the existing RUSTFLAGS specified as a list.
+ interpolateString (args.RUSTFLAGS or "");
}
// args.env or { };
lib.optionalAttrs (stdenv.hostPlatform.isDarwin && buildType == "debug") {
RUSTFLAGS = "-C split-debuginfo=packed " + (args.RUSTFLAGS or "");
}
// {
cargoDeps =
if cargoVendorDir != null then
null
@@ -143,15 +162,6 @@ lib.extendMkDerivation {
patches = cargoPatches ++ patches;
PKG_CONFIG_ALLOW_CROSS = if stdenv.buildPlatform != stdenv.hostPlatform then 1 else 0;
postUnpack = ''
eval "$cargoDepsHook"
export RUST_LOG=${logLevel}
''
+ (args.postUnpack or "");
configurePhase =
args.configurePhase or ''
runHook preConfigure

View File

@@ -1,6 +1,8 @@
cargoSetupPostUnpackHook() {
echo "Executing cargoSetupPostUnpackHook"
eval "${cargoDepsHook-}"
# Some cargo builds include build hooks that modify their own vendor
# dependencies. This copies the vendor directory into the build tree and makes
# it writable. If we're using a tarball, the unpackFile hook already handles

View File

@@ -0,0 +1,38 @@
{
stdenvNoCC,
fetchurl,
lib,
}:
stdenvNoCC.mkDerivation {
pname = "7-segment-font";
version = "3.0-unstable-2025-06-03";
src = fetchurl {
url = "https://torinak.com/font/7segment.ttf";
hash = "sha256-zIjaEGDLR9ad192GH9pIU6/A3ZGAuR0oF3ZB3Ew3Xbs=";
};
dontUnpack = true;
installPhase = ''
runHook preInstall
install -Dm444 "$src" "$out/share/fonts/truetype/7segment.ttf"
runHook postInstall
'';
meta = {
description = "Font that imitates classic seven-segment LCD and LED displays";
longDescription = ''
A font that imitates classic seven-segment LCD and LED displays.
Beside digits, it contains Latin letters and some symbols constructed from segments,
with separate dot and colon as used in calculators and digital clocks.
'';
homepage = "https://torinak.com/font/7-segment";
downloadPage = "https://torinak.com/font/7-segment";
license = lib.licenses.ofl;
maintainers = with lib.maintainers; [ elfenermarcell ];
platforms = lib.platforms.all;
};
}

View File

@@ -19,12 +19,12 @@ let
in
buildNpmPackage rec {
pname = "antimatter-dimensions";
version = "0-unstable-2025-09-17";
version = "0-unstable-2025-11-20";
src = fetchFromGitHub {
owner = "IvarK";
repo = "AntimatterDimensionsSourceCode";
rev = "8b5a34c1211df7cb35969dc8e5d402b0b28b7589";
hash = "sha256-ptyLpGtHHhsPBS//LpuO327uXPqQWTs1DLGjcsrvZtw=";
rev = "8ae221fcb07db667b3d04114c2b977175966611d";
hash = "sha256-IseAfEz+nSzY2XD15HbJWeLmYFMvAYO33bPItXJCy58=";
};
nativeBuildInputs = [
copyDesktopItems

View File

@@ -11,13 +11,13 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "ast-grep";
version = "0.39.9";
version = "0.40.0";
src = fetchFromGitHub {
owner = "ast-grep";
repo = "ast-grep";
tag = finalAttrs.version;
hash = "sha256-OzDx1/U4uZuMGanTaDi1Bu3ueMaf83jJIqy+20+cX0g=";
hash = "sha256-tbN8MiesWWIHew5/2STNhXu+3eXjMLRrcm8+9cZf+tM=";
};
# error: linker `aarch64-linux-gnu-gcc` not found
@@ -25,7 +25,7 @@ rustPlatform.buildRustPackage (finalAttrs: {
rm .cargo/config.toml
'';
cargoHash = "sha256-YtukqwUvpAQf8Dxf0rhowylt8h1VhN9PcnF+QiB8WmA=";
cargoHash = "sha256-+wetHwdURcNPLa9TGZmS4HlyYcQHSpLnXbrNXS/JckM=";
nativeBuildInputs = [ installShellFiles ];

View File

@@ -2,7 +2,6 @@
lib,
stdenv,
fetchurl,
fetchpatch,
meson,
ninja,
pkg-config,
@@ -29,7 +28,7 @@
stdenv.mkDerivation rec {
pname = "at-spi2-core";
version = "2.58.0";
version = "2.58.1";
outputs = [
"out"
@@ -39,18 +38,9 @@ stdenv.mkDerivation rec {
src = fetchurl {
url = "mirror://gnome/sources/at-spi2-core/${lib.versions.majorMinor version}/at-spi2-core-${version}.tar.xz";
hash = "sha256-390zANong6IZaf+t4oiYF/t8GQak75JJfrpllps9q1o=";
hash = "sha256-fzdKajjNcP9LMsnToDEL+oBNlG/tTJ5pp9SfrNy5Xpw=";
};
# TODO apply unconditionally on rebuild
patches = lib.optionals stdenv.isDarwin [
(fetchpatch {
name = "timersub.patch";
url = "https://github.com/GNOME/at-spi2-core/commit/02108ea1b96db0189b2d4a9eceb843e1f13b7bdf.diff";
hash = "sha256-pVBhawfRnJoXmovl9CAmzh+YWJkbvlOVrCs8XanjP00=";
})
];
nativeBuildInputs = [
glib
meson

View File

@@ -26,8 +26,8 @@ let
prompt-toolkit = prev.prompt-toolkit.overridePythonAttrs (prev: rec {
version = "3.0.51";
src = prev.src.override {
inherit version;
hash = "sha256-kxoWLjsn/JDIbxtIux+yxSjCdhR15XycBt4TMRx7VO0=";
tag = version;
hash = "sha256-pNYmjAgnP9nK40VS/qvPR3g+809Yra2ISASWJDdQKrU=";
};
});
python-dateutil = prev.python-dateutil.overridePythonAttrs (prev: rec {
@@ -73,14 +73,14 @@ let
in
py.pkgs.buildPythonApplication rec {
pname = "awscli2";
version = "2.31.11"; # N.B: if you change this, check if overrides are still up-to-date
version = "2.31.39"; # N.B: if you change this, check if overrides are still up-to-date
pyproject = true;
src = fetchFromGitHub {
owner = "aws";
repo = "aws-cli";
tag = version;
hash = "sha256-JyTL3q8MMKSKbNiJvBL3u7vpUNFt9rp2Ueh8mL9FRkM=";
hash = "sha256-IuOamzLmnU3wIhgQIsWbU6GSRM2XLv0eH0gezp9IHNA=";
};
postPatch = ''

View File

@@ -10,22 +10,22 @@
stdenv.mkDerivation (finalAttrs: {
pname = "bluez-headers";
version = "5.83";
version = "5.84";
# This package has the source, because of the emulatorAvailable check in the
# bluez function args, that causes an infinite recursion with Python on cross
# builds.
src = fetchurl {
url = "mirror://kernel/linux/bluetooth/bluez-${finalAttrs.version}.tar.xz";
hash = "sha256-EIUi2QnSIFgTmb/sk9qrYgNVOc7vPdo+eZcHhcY70kw=";
hash = "sha256-W6c9Aw97AAh9Z4ALDjIWAa7A+JKCfHLlosg5DYyIaxE=";
};
dontConfigure = true;
dontBuild = true;
installPhase = ''
mkdir -p $out/include/bluetooth
cp -v lib/*.h "$out/include/bluetooth/"
mkdir -p $out/include/
cp -rv lib/* "$out/include/"
'';
meta = {

View File

@@ -4,12 +4,11 @@
fetchFromGitHub,
fetchpatch,
cmake,
python3Packages,
staticOnly ? stdenv.hostPlatform.isStatic,
testers,
}:
# ?TODO: there's also python lib in there
stdenv.mkDerivation (finalAttrs: {
pname = "brotli";
version = "1.1.0";
@@ -54,7 +53,10 @@ stdenv.mkDerivation (finalAttrs: {
cp ../docs/*.3 $out/share/man/man3/
'';
passthru.tests.pkg-config = testers.testMetaPkgConfig finalAttrs.finalPackage;
passthru.tests = {
pkg-config = testers.testMetaPkgConfig finalAttrs.finalPackage;
python = python3Packages.brotli;
};
meta = with lib; {
homepage = "https://github.com/google/brotli";

View File

@@ -11,16 +11,16 @@
rustPlatform.buildRustPackage rec {
pname = "cargo-binstall";
version = "1.16.0";
version = "1.16.1";
src = fetchFromGitHub {
owner = "cargo-bins";
repo = "cargo-binstall";
tag = "v${version}";
hash = "sha256-zJUTwmmF/yEZwAI9R+Kau+eqB/MMqs05BoZkzR6B1VY=";
hash = "sha256-NqpYd/K95yTxT5WFTUURk3eS7aV4FY9J7VZCqKQBHNg=";
};
cargoHash = "sha256-T2pIWKLJhLXZAaRjWSJGbwhQwSf5j1Qem0evVbQeoWM=";
cargoHash = "sha256-lFK89J7GNqU5tcNdse7LWYdUj5y30Vkowv1/o1SjwZ4=";
nativeBuildInputs = [
pkg-config

View File

@@ -29,7 +29,7 @@ buildGoModule (finalAttrs: {
homepage = "https://github.com/favonia/cloudflare-ddns";
mainProgram = "ddns";
license = licenses.asl20;
maintainers = [ ];
maintainers = with lib.maintainers; [ shokerplz ];
platforms = platforms.unix ++ platforms.darwin;
};
})

View File

@@ -8,17 +8,17 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "codebook";
version = "0.3.18";
version = "0.3.20";
src = fetchFromGitHub {
owner = "blopker";
repo = "codebook";
tag = "v${finalAttrs.version}";
hash = "sha256-KRygy6YC7W7V0TFarKSnCS9Ww3M8q3xJvg925aolLmM=";
hash = "sha256-lsjP230lgQDOLmU4fWR4oUyQ4P2hH5YB9ZvC8ZjeFf0=";
};
buildAndTestSubdir = "crates/codebook-lsp";
cargoHash = "sha256-HAJglGtOy+OMZoB50Uz5vrf8IXqBKMMO/Hr9Lcry2+Q=";
cargoHash = "sha256-ifs3C2nNDv3pXq4hfCtBS455Sj4FVz7VEoR5LQIUHFQ=";
CARGO_PROFILE_RELEASE_LTO = "fat";
CARGO_PROFILE_RELEASE_CODEGEN_UNITS = "1";

View File

@@ -20,14 +20,14 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "cosmic-applets";
version = "1.0.0-beta.6";
version = "1.0.0-beta.7";
# nixpkgs-update: no auto update
src = fetchFromGitHub {
owner = "pop-os";
repo = "cosmic-applets";
tag = "epoch-${finalAttrs.version}";
hash = "sha256-eWyFLaBvs/vQCsQgQwLNgATl/wxjtT5545hfi3xZmAg=";
hash = "sha256-4cQ3MFV2l75ZTMkc4lri48hPE21os6xygr3MDP7RSEA=";
};
cargoHash = "sha256-XOA5yREoQHGxPI9PVYd2UsaHRCIfbb3Tkr1eovqIIow=";

View File

@@ -11,17 +11,17 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "cosmic-applibrary";
version = "1.0.0-beta.6";
version = "1.0.0-beta.7";
# nixpkgs-update: no auto update
src = fetchFromGitHub {
owner = "pop-os";
repo = "cosmic-applibrary";
tag = "epoch-${finalAttrs.version}";
hash = "sha256-1c1ndBpF3PQ0XUBhQDcUTCvraaa/gMuPeTiS735BAGg=";
hash = "sha256-G8zH66v5YLqF8p1WhCBnXeI2ac3igGCAFJTvgeTTCUE=";
};
cargoHash = "sha256-CX1/6fXL63P1J6yjvFKd91WqSf4+mf+GOtX1O9fHfgg=";
cargoHash = "sha256-s+Q8hj8/dqwGpCq87BWTtk/PmAg55cMI/KLL96SaqUo=";
nativeBuildInputs = [
just

View File

@@ -13,7 +13,7 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "cosmic-bg";
version = "1.0.0-beta.6";
version = "1.0.0-beta.7";
# nixpkgs-update: no auto update
src = fetchFromGitHub {

View File

@@ -20,17 +20,17 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "cosmic-comp";
version = "1.0.0-beta.6";
version = "1.0.0-beta.7";
# nixpkgs-update: no auto update
src = fetchFromGitHub {
owner = "pop-os";
repo = "cosmic-comp";
tag = "epoch-${finalAttrs.version}";
hash = "sha256-JC11Y5Ow3cOHoZ/hVSczIOVKzXT+vPKieHVZW07TQcc=";
hash = "sha256-qE+m/LEe1ky+7A4PAzQrhZyguRsCID7IFwCx/yriYQE=";
};
cargoHash = "sha256-3F4cR7qj5KA0Y7V5F2UNeOWW6CxoSAlbH5mxR8REOCc=";
cargoHash = "sha256-xaA0qwOxT/RNyUXOazJeO8oVR5pzxW15KFZ+IrWsL5o=";
separateDebugInfo = true;

View File

@@ -16,14 +16,14 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "cosmic-edit";
version = "1.0.0-beta.6";
version = "1.0.0-beta.7";
# nixpkgs-update: no auto update
src = fetchFromGitHub {
owner = "pop-os";
repo = "cosmic-edit";
tag = "epoch-${finalAttrs.version}";
hash = "sha256-sZTv1iUbzC9AYXgWqIWqpjZgJez45LS2cl+p1ZhvhnE=";
hash = "sha256-V3O4ktSJ1cLAgtFvHqzX0AanJdir/HfqdvgCiHINyxg=";
};
cargoHash = "sha256-ELQrRDTNAX5eWWjsmWfg8BCKnaM+tqncS2O4jA3N9W8=";

View File

@@ -12,14 +12,14 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "cosmic-files";
version = "1.0.0-beta.6";
version = "1.0.0-beta.7";
# nixpkgs-update: no auto update
src = fetchFromGitHub {
owner = "pop-os";
repo = "cosmic-files";
tag = "epoch-${finalAttrs.version}";
hash = "sha256-k7Y3j1h1C9guJetTYay7zCY8IF3r1LQu+WwhSkx8y8E=";
hash = "sha256-6r2HBxp7sZ79MKZoONXmopKea2unqZ91xaq4l6QiE9w=";
};
cargoHash = "sha256-L3a3gtqW5Zjufom8NDeklKe6rOnzd8sEaCPIVGsOqWM=";

View File

@@ -19,20 +19,20 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "cosmic-greeter";
version = "1.0.0-beta.6";
version = "1.0.0-beta.7";
# nixpkgs-update: no auto update
src = fetchFromGitHub {
owner = "pop-os";
repo = "cosmic-greeter";
tag = "epoch-${finalAttrs.version}";
hash = "sha256-9nZ8e6xocz8HfTwTeHpYOi/ptljhhEENnbmnD/DeLEI=";
hash = "sha256-r/xhJR3xtLxPusMUKzS2PGsS51m1jfoxZByJWcXLaoY=";
};
cargoHash = "sha256-4yRBgFrH4RBpuvChTED+ynx+PyFumoT2Z+R1gXxF4Xc=";
env = {
VERGEN_GIT_COMMIT_DATE = "2025-11-12";
VERGEN_GIT_COMMIT_DATE = "2025-11-20";
VERGEN_GIT_SHA = finalAttrs.src.tag;
};

View File

@@ -9,7 +9,7 @@
}:
stdenvNoCC.mkDerivation (finalAttrs: {
pname = "cosmic-icons";
version = "1.0.0-beta.6";
version = "1.0.0-beta.7";
# nixpkgs-update: no auto update
src = fetchFromGitHub {

View File

@@ -16,17 +16,17 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "cosmic-idle";
version = "1.0.0-beta.6";
version = "1.0.0-beta.7";
# nixpkgs-update: no auto update
src = fetchFromGitHub {
owner = "pop-os";
repo = "cosmic-idle";
tag = "epoch-${finalAttrs.version}";
hash = "sha256-dRvcow+rZ4sJV6pBxRIw6SCmU3aXP9uVKtFEJ9vozzI=";
hash = "sha256-qVrcMI7sr0mWyYW1fM6oP/6qKEhlqqyQ/WiJaWfCQPU=";
};
cargoHash = "sha256-iFR0kFyzawlXrWItzFQbG/tKGd3Snwk/0LYkPzCkJUQ=";
cargoHash = "sha256-vfuhXT/MJHchJdW+3GPuvZbYVdClpsbNfOzLKWW4LPY=";
nativeBuildInputs = [
just

View File

@@ -14,7 +14,7 @@
}:
rustPlatform.buildRustPackage (finalAttrs: {
pname = "cosmic-initial-setup";
version = "1.0.0-beta.6";
version = "1.0.0-beta.7";
# nixpkgs-update: no auto update
src = fetchFromGitHub {

View File

@@ -11,17 +11,17 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "cosmic-launcher";
version = "1.0.0-beta.6";
version = "1.0.0-beta.7";
# nixpkgs-update: no auto update
src = fetchFromGitHub {
owner = "pop-os";
repo = "cosmic-launcher";
tag = "epoch-${finalAttrs.version}";
hash = "sha256-zLZJbf7LuGXnDd4F6ReS6BB6yvkvPOq0OOXZbKZJdec=";
hash = "sha256-lVNvmpiShkdT+VZMxV1bvYyC17edaepwlkmOvNMng8k=";
};
cargoHash = "sha256-2kkKPU4iEsInLwJyEyJ15/T1pVfDsKD69DISGilNWws=";
cargoHash = "sha256-pHW7kBbEQ8P9Ugkgzn1olSlMCeetuNQ2jMJyEteoeIo=";
nativeBuildInputs = [
just
@@ -51,7 +51,7 @@ rustPlatform.buildRustPackage (finalAttrs: {
cosmic-autologin-noxwayland
;
};
passthru.updateScript = nix-update-script {
updateScript = nix-update-script {
extraArgs = [
"--version"
"unstable"

View File

@@ -12,7 +12,7 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "cosmic-notifications";
version = "1.0.0-beta.6";
version = "1.0.0-beta.7";
# nixpkgs-update: no auto update
src = fetchFromGitHub {

View File

@@ -13,14 +13,14 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "cosmic-osd";
version = "1.0.0-beta.6";
version = "1.0.0-beta.7";
# nixpkgs-update: no auto update
src = fetchFromGitHub {
owner = "pop-os";
repo = "cosmic-osd";
tag = "epoch-${finalAttrs.version}";
hash = "sha256-5GrYWrg/trnzk5gtelVUPmtm3MWiTyqaq6QIGadr3t8=";
hash = "sha256-gAmsLScFKgs2bUf0c4NuP2Zuuz+vz8Y7w4uQtKzXSRo=";
};
cargoHash = "sha256-cpNp/by8TU2lbb2d3smxUr48mTSLnoPXseiRZScwSXI=";

View File

@@ -11,14 +11,14 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "cosmic-panel";
version = "1.0.0-beta.6";
version = "1.0.0-beta.7";
# nixpkgs-update: no auto update
src = fetchFromGitHub {
owner = "pop-os";
repo = "cosmic-panel";
tag = "epoch-${finalAttrs.version}";
hash = "sha256-u3jRjDNwF3QY4R/I99C5Ko34wtmX4ZqhnXnUbrk+iac=";
hash = "sha256-gvEHieM8osGyRrkeE8gEOPduTv3y3KgoZ2YhFgW5qp8=";
};
cargoHash = "sha256-ZkjXZrcA4qKHSjEOxj7+j10PxJw/du8B2Mee2fxPJxs=";

View File

@@ -18,14 +18,14 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "cosmic-player";
version = "1.0.0-beta.6";
version = "1.0.0-beta.7";
# nixpkgs-update: no auto update
src = fetchFromGitHub {
owner = "pop-os";
repo = "cosmic-player";
tag = "epoch-${finalAttrs.version}";
hash = "sha256-TiD1gQ44Oqm0qWmZsIcFBG4fjmlr4LWaAMjOx+ulOcE=";
hash = "sha256-RNDc+NCih1bsdqa4DCOrtiKPsdVaQ6fvj9VGQAoNri8=";
};
cargoHash = "sha256-ST/04USAIHvySOoKvh5EPCDlUOjHxbiRFouLunaleKw=";

View File

@@ -12,7 +12,7 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "cosmic-randr";
version = "1.0.0-beta.6";
version = "1.0.0-beta.7";
# nixpkgs-update: no auto update
src = fetchFromGitHub {

View File

@@ -6,11 +6,12 @@
just,
pkg-config,
nixosTests,
nix-update-script,
}:
rustPlatform.buildRustPackage (finalAttrs: {
pname = "cosmic-screenshot";
version = "1.0.0-beta.6";
version = "1.0.0-beta.7";
# nixpkgs-update: no auto update
src = fetchFromGitHub {
@@ -38,13 +39,23 @@ rustPlatform.buildRustPackage (finalAttrs: {
"target/${stdenv.hostPlatform.rust.cargoShortTarget}"
];
passthru.tests = {
inherit (nixosTests)
cosmic
cosmic-autologin
cosmic-noxwayland
cosmic-autologin-noxwayland
;
passthru = {
tests = {
inherit (nixosTests)
cosmic
cosmic-autologin
cosmic-noxwayland
cosmic-autologin-noxwayland
;
};
updateScript = nix-update-script {
extraArgs = [
"--version"
"unstable"
"--version-regex"
"epoch-(.*)"
];
};
};
meta = with lib; {

View File

@@ -7,11 +7,12 @@
dbus,
stdenv,
nixosTests,
nix-update-script,
}:
rustPlatform.buildRustPackage (finalAttrs: {
pname = "cosmic-session";
version = "1.0.0-beta.6";
version = "1.0.0-beta.7";
# nixpkgs-update: no auto update
src = fetchFromGitHub {
@@ -60,6 +61,14 @@ rustPlatform.buildRustPackage (finalAttrs: {
cosmic-autologin-noxwayland
;
};
updateScript = nix-update-script {
extraArgs = [
"--version"
"unstable"
"--version-regex"
"epoch-(.*)"
];
};
};
meta = {

View File

@@ -11,18 +11,19 @@
udev,
openssl,
nixosTests,
nix-update-script,
}:
rustPlatform.buildRustPackage (finalAttrs: {
pname = "cosmic-settings-daemon";
version = "1.0.0-beta.6";
version = "1.0.0-beta.7";
# nixpkgs-update: no auto update
src = fetchFromGitHub {
owner = "pop-os";
repo = "cosmic-settings-daemon";
tag = "epoch-${finalAttrs.version}";
hash = "sha256-WLZJx8FwseCD7hHU60+HekNBxUE6B/6HRhP8oqokTNI=";
hash = "sha256-w+k0x+9GlbAEZshfwIcO6I8hVhHdARJn/CA7QBDOVCo=";
};
postPatch = ''
@@ -50,13 +51,23 @@ rustPlatform.buildRustPackage (finalAttrs: {
dontCargoInstall = true;
passthru.tests = {
inherit (nixosTests)
cosmic
cosmic-autologin
cosmic-noxwayland
cosmic-autologin-noxwayland
;
passthru = {
tests = {
inherit (nixosTests)
cosmic
cosmic-autologin
cosmic-noxwayland
cosmic-autologin-noxwayland
;
};
updateScript = nix-update-script {
extraArgs = [
"--version"
"unstable"
"--version-regex"
"epoch-(.*)"
];
};
};
meta = {

View File

@@ -28,14 +28,14 @@ let
in
rustPlatform.buildRustPackage (finalAttrs: {
pname = "cosmic-settings";
version = "1.0.0-beta.6";
version = "1.0.0-beta.7";
# nixpkgs-update: no auto update
src = fetchFromGitHub {
owner = "pop-os";
repo = "cosmic-settings";
tag = "epoch-${finalAttrs.version}";
hash = "sha256-mE5zcFBFHBLisxrBJRYC0C33MrW5dG0DyzKPJ5kgT1c=";
hash = "sha256-CIY7SAS6WCn41mM+MpKaCm08cfnVIqFl+/t5u5717Lw=";
};
cargoHash = "sha256-Su+yAQLr3Us8YNU8z83XO1UDjjOY3SCGnkmwGaIGFho=";

View File

@@ -15,14 +15,14 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "cosmic-store";
version = "1.0.0-beta.6";
version = "1.0.0-beta.7";
# nixpkgs-update: no auto update
src = fetchFromGitHub {
owner = "pop-os";
repo = "cosmic-store";
tag = "epoch-${finalAttrs.version}";
hash = "sha256-uY+W1FqhAMUe7X9j9G8YP+GCcbjzRvGyRxn4BW8o0Zg=";
hash = "sha256-6Qn9+kwuiArxTHpN410gy+7bKXBwv87OPPDMatAYr38=";
};
cargoHash = "sha256-nJLowAuWvj5JfmPyExQyfCJ9pqNJ0OdzPPku9z7RDWc=";

View File

@@ -15,14 +15,14 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "cosmic-term";
version = "1.0.0-beta.6";
version = "1.0.0-beta.7";
# nixpkgs-update: no auto update
src = fetchFromGitHub {
owner = "pop-os";
repo = "cosmic-term";
tag = "epoch-${finalAttrs.version}";
hash = "sha256-O2vUdwHP+BgOsBu9dcx34WPFGsVXbG7enxMT7dRiq5o=";
hash = "sha256-kyswCFnor2tg64BodSwiRYqzjxRN6r7zqm2z/egmX1I=";
};
cargoHash = "sha256-7+1tvJ/B+YITI5XXr1A+jlRRNRoNZ1ZsGeeAfGPT/00=";

View File

@@ -7,7 +7,7 @@
stdenvNoCC.mkDerivation (finalAttrs: {
pname = "cosmic-wallpapers";
version = "1.0.0-beta.6";
version = "1.0.0-beta.7";
# nixpkgs-update: no auto update
src = fetchFromGitHub {

View File

@@ -14,17 +14,17 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "cosmic-workspaces-epoch";
version = "1.0.0-beta.6";
version = "1.0.0-beta.7";
# nixpkgs-update: no auto update
src = fetchFromGitHub {
owner = "pop-os";
repo = "cosmic-workspaces-epoch";
tag = "epoch-${finalAttrs.version}";
hash = "sha256-WHMOA7fNPIAwaQmzqyo+XlBYl+13cz0LrRpT0GUa8Vs=";
hash = "sha256-7iOiVrMHpE5oG/qIH0DIgBeHEEm0x7HIDLv64FFs300=";
};
cargoHash = "sha256-BE6s2dmbgXlFXrtd8b9k2LltLnegLzWbIUlaEQvv+5o=";
cargoHash = "sha256-7BdyHz66A+QhJY0haohaQiNkhpmX9rqIW9gD8E4Q7Qg=";
separateDebugInfo = true;

View File

@@ -3,24 +3,41 @@
buildGoModule,
fetchFromGitHub,
callPackage,
installShellFiles,
nixosTests,
stdenv,
}:
buildGoModule rec {
pname = "croc";
version = "10.3.0";
version = "10.3.1";
src = fetchFromGitHub {
owner = "schollz";
repo = "croc";
rev = "v${version}";
hash = "sha256-5mxrfYAR4kTy9hdbsC7wFdroHf68dknPH3mq4KXG36Y=";
hash = "sha256-oNk4ReqteTeWKjsmVPC2yVRv1A9WN9jUbiT40flfM+o=";
};
vendorHash = "sha256-xEF1vjYQaeDYxcC3FTgR0zCFqvziNIrJVpJJT4o1cVU=";
subPackages = [ "." ];
nativeBuildInputs = [
installShellFiles
];
postInstall = ''
installShellCompletion --cmd croc \
--bash src/install/bash_autocomplete \
''
+ lib.optionalString (stdenv.buildPlatform.canExecute stdenv.hostPlatform) ''
--fish <($out/bin/croc generate-fish-completion) \
''
+ ''
--zsh src/install/zsh_autocomplete
'';
passthru = {
tests = {
local-relay = callPackage ./test-local-relay.nix { };

View File

@@ -10,13 +10,13 @@
buildGoModule (finalAttrs: {
pname = "cue";
version = "0.15.0";
version = "0.15.1";
src = fetchFromGitHub {
owner = "cue-lang";
repo = "cue";
tag = "v${finalAttrs.version}";
hash = "sha256-yyvIjaOElEHR75o+DgVOG1EklXaWGdjvv15iMvfbkeA=";
hash = "sha256-0DxJK5S1uWR5MbI8VzUxQv+YTwIIm1yK77Td+Qf278I=";
};
vendorHash = "sha256-ivFw62+pg503EEpRsdGSQrFNah87RTUrRXUSPZMFLG4=";

View File

@@ -10,8 +10,8 @@
libtiff,
pam,
dbus,
enableSystemd ? lib.meta.availableOn stdenv.hostPlatform systemd,
systemd,
enableSystemd ? lib.meta.availableOn stdenv.hostPlatform systemdLibs,
systemdLibs,
acl,
gmp,
darwin,
@@ -76,7 +76,7 @@ stdenv.mkDerivation rec {
dbus
acl
]
++ lib.optional enableSystemd systemd;
++ lib.optional enableSystemd systemdLibs;
propagatedBuildInputs = [ gmp ];

View File

@@ -1,27 +0,0 @@
From 7e91f24c73256af59ac9061c41b73a184c4690aa Mon Sep 17 00:00:00 2001
From: Stefan Eissing <stefan@eissing.org>
Date: Mon, 3 Nov 2025 15:07:57 +0100
Subject: [PATCH] cw-out: fix EAGAIN handling on pause
The interim CURLE_AGAIN result was not always converted to a
CURLE_OK and then caused write callers to report a failure.
Fixes #19334
Reported-by: pennae on github
Closes #19338
---
lib/cw-out.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/lib/cw-out.c b/lib/cw-out.c
index 1f4031649267..9c0a36e7e5e2 100644
--- a/lib/cw-out.c
+++ b/lib/cw-out.c
@@ -302,6 +302,7 @@ static CURLcode cw_out_buf_flush(struct cw_out_ctx *ctx,
&consumed);
if(result && (result != CURLE_AGAIN))
return result;
+ result = CURLE_OK;
if(consumed) {
if(consumed == curlx_dyn_len(&cwbuf->b)) {

View File

@@ -86,7 +86,7 @@ assert
stdenv.mkDerivation (finalAttrs: {
pname = "curl";
version = "8.16.0";
version = "8.17.0";
src = fetchurl {
urls = [
@@ -95,17 +95,9 @@ stdenv.mkDerivation (finalAttrs: {
builtins.replaceStrings [ "." ] [ "_" ] finalAttrs.version
}/curl-${finalAttrs.version}.tar.xz"
];
hash = "sha256-QMjN28tsxiUcA96kI6Ryps6kA3vmVLpc9d7G6y0i/x0=";
hash = "sha256-lV9ucprWs1ZiYOj+9oYg52ujwxrPChhSRBahhaz3eZI=";
};
patches = [
# Bug introduced in curl@fa915b (8.16.0) https://github.com/curl/curl/issues/19334 Paused
# HTTP/2 transfers will return the wrong errors and trash the whole
# transfer. Remove this patch once curl is updated to 8.17.0 which will be
# released on the 5th November 2025.
./fix-h2-paused-transfers.patch
];
# this could be accomplished by updateAutotoolsGnuConfigScriptsHook, but that causes infinite recursion
# necessary for FreeBSD code path in configure
postPatch = ''

View File

@@ -27,13 +27,13 @@ assert useVulkan -> withExamples;
stdenv.mkDerivation rec {
pname = "dav1d";
version = "1.5.1";
version = "1.5.2";
src = fetchFromGitHub {
owner = "videolan";
repo = "dav1d";
rev = version;
hash = "sha256-qcs9QoZ/uWEQ8l1ChZ8nYctZnnWJ0VvCw1q2rEktC9g=";
hash = "sha256-rxRO5EWjrOUsCYXd2rDDhfcEZbfSuMfjujRAHTqUYhI=";
};
outputs = [

View File

@@ -25,9 +25,9 @@
withDocs ? withIntrospection,
}:
stdenv.mkDerivation rec {
stdenv.mkDerivation (finalAttrs: {
pname = "dconf";
version = "0.40.0";
version = "0.49.0";
outputs = [
"out"
@@ -37,8 +37,8 @@ stdenv.mkDerivation rec {
++ lib.optional withDocs "devdoc";
src = fetchurl {
url = "mirror://gnome/sources/${pname}/${lib.versions.majorMinor version}/${pname}-${version}.tar.xz";
sha256 = "0cs5nayg080y8pb9b7qccm1ni8wkicdmqp1jsgc22110r6j24zyg";
url = "mirror://gnome/sources/dconf/${lib.versions.majorMinor finalAttrs.version}/dconf-${finalAttrs.version}.tar.xz";
sha256 = "FqR+SaWBVtu5ZXjhcIMlKZ5MGe6pvhKNW9Ev0JY9bDY=";
};
nativeBuildInputs = [
@@ -79,15 +79,13 @@ stdenv.mkDerivation rec {
!stdenv.hostPlatform.isAarch32 && !stdenv.hostPlatform.isAarch64 && !stdenv.hostPlatform.isDarwin;
postPatch = ''
chmod +x meson_post_install.py tests/test-dconf.py
patchShebangs meson_post_install.py
patchShebangs tests/test-dconf.py
chmod +x tests/test-dconf.py tests/shellcheck.sh
patchShebangs tests/test-dconf.py tests/shellcheck.sh
'';
passthru = {
updateScript = gnome.updateScript {
packageName = pname;
versionPolicy = "odd-unstable";
packageName = "dconf";
};
tests = { inherit (nixosTests) dconf; };
};
@@ -103,4 +101,4 @@ stdenv.mkDerivation rec {
teams = [ teams.gnome ];
mainProgram = "dconf";
};
}
})

View File

@@ -14,7 +14,7 @@
ocamlPackages.buildDunePackage rec {
pname = "docfd";
version = "12.0.0";
version = "12.1.0";
minimalOCamlVersion = "5.1";
@@ -22,7 +22,7 @@ ocamlPackages.buildDunePackage rec {
owner = "darrenldl";
repo = "docfd";
rev = version;
hash = "sha256-Tb5J9FgI2JBpl5oejWRT3ixzt7kufnM+Xy6DdiB9s98=";
hash = "sha256-fDvjnqAH0ALP1im34vxmXtO7kst0G/iPu3VLLBas5YI=";
};
# Compatibility with nottui ≥ 0.4

View File

@@ -26,14 +26,14 @@ let
);
in
stdenv.mkDerivation (finalAttrs: {
version = "0.10.0.post2";
version = "0.10.0.post3";
pname = "dolfinx";
src = fetchFromGitHub {
owner = "fenics";
repo = "dolfinx";
tag = "v${finalAttrs.version}";
hash = "sha256-Q1dQkDU6kfP5LFS0UwPwsff2hcHLAa3ZOk/hG0gGAbs=";
hash = "sha256-YsFya92lz9Twc1PsSLGj6tJNvKb+MQfpmN/qOFxbe34=";
};
preConfigure = ''

View File

@@ -1,7 +1,7 @@
{ mkDprintPlugin }:
mkDprintPlugin {
description = "Biome (JS/TS) wrapper plugin";
hash = "sha256-6UIeTsS5ovtH79gP4PGn0ePttqr4Vuo+RgXTk+jSZjE=";
hash = "sha256-V8lXwGRWGvl/g2kjqL8Ei1N7V0nuTP2WcLFWJvC7D+A=";
initConfig = {
configExcludes = [ "**/node_modules" ];
configKey = "biome";
@@ -16,6 +16,6 @@ mkDprintPlugin {
};
pname = "dprint-plugin-biome";
updateUrl = "https://plugins.dprint.dev/dprint/biome/latest.json";
url = "https://plugins.dprint.dev/biome-0.11.4.wasm";
version = "0.11.4";
url = "https://plugins.dprint.dev/biome-0.11.6.wasm";
version = "0.11.6";
}

View File

@@ -7,20 +7,20 @@
buildGoModule rec {
pname = "ecspresso";
version = "2.6.3";
version = "2.6.4";
src = fetchFromGitHub {
owner = "kayac";
repo = "ecspresso";
tag = "v${version}";
hash = "sha256-ZruQx2Nm/1An9yGNhQ/2Kbah4eSFBD/pp3c6WZIBGXA=";
hash = "sha256-7Lli3PQZDmMBzgVbHy8ayweK+yn23IVqPTI6M+Un5i0=";
};
subPackages = [
"cmd/ecspresso"
];
vendorHash = "sha256-oq2BOzSHwAq/gNBknwm1LXUKu+est/kjM1jlVBvQZbg=";
vendorHash = "sha256-UkfkCEyHwxOEEVcxtsMdeRuJhQqW3vLHEDf8+O82zs4=";
ldflags = [
"-s"

View File

@@ -33,14 +33,14 @@ let
in
python.pkgs.buildPythonApplication rec {
pname = "esphome";
version = "2025.10.5";
version = "2025.11.0";
pyproject = true;
src = fetchFromGitHub {
owner = "esphome";
repo = "esphome";
tag = version;
hash = "sha256-o40zMoqgjBpkn80dUvr7mJQ/EtmIHEI/cf/E+wbBPOw=";
hash = "sha256-ezyuV9PcZ5SsJc5viyV+8n+pW8k0SV2bXr+JPVkOdus=";
};
patches = [
@@ -64,10 +64,6 @@ python.pkgs.buildPythonApplication rec {
pythonRemoveDeps = [
"esptool"
"platformio"
# esp-idf v5.1 uses esp-idf-kconfig instead:
# https://github.com/espressif/esp-idf/blob/release/v5.1/tools/requirements/requirements.core.txt#L15
# Can be removed once this pr is released: https://github.com/esphome/esphome/pull/11210
"kconfiglib"
];
postPatch = ''
@@ -82,6 +78,7 @@ python.pkgs.buildPythonApplication rec {
dependencies = with python.pkgs; [
aioesphomeapi
argcomplete
bleak
cairosvg
click
colorama
@@ -137,7 +134,10 @@ python.pkgs.buildPythonApplication rec {
pytest-mock
pytestCheckHook
]
++ [ versionCheckHook ];
++ [
git
versionCheckHook
];
disabledTestPaths = [
# platformio builds; requires networking for dependency resolution
@@ -172,6 +172,9 @@ python.pkgs.buildPythonApplication rec {
"test_upload_using_esptool_with_file_path"
# AssertionError: Expected 'run_external_command' to have been called once. Called 0 times.
"test_run_platformio_cli_sets_environment_variables"
# Expects a full git clone
"test_clang_tidy_mode_full_scan"
"test_clang_tidy_mode_targeted_scan"
];
versionCheckProgramArg = "--version";

View File

@@ -9,13 +9,13 @@
stdenv.mkDerivation rec {
pname = "exfatprogs";
version = "1.2.9";
version = "1.3.0";
src = fetchFromGitHub {
owner = "exfatprogs";
repo = "exfatprogs";
rev = version;
sha256 = "sha256-EENBlf5beuLJ++N7YThxzz2I/FXzb02by3KOUPOuEV4=";
sha256 = "sha256-2kD2ZENAyhApYHs6+NNYkxfLj5fw/cIHRUhw0UnQx04=";
};
nativeBuildInputs = [

View File

@@ -10,16 +10,16 @@
buildNpmPackage rec {
pname = "firebase-tools";
version = "14.24.1";
version = "14.26.0";
src = fetchFromGitHub {
owner = "firebase";
repo = "firebase-tools";
tag = "v${version}";
hash = "sha256-eXADtJFQWC5Qf013fkJ4AdukyaKlc5Rorys/jNG9f+E=";
hash = "sha256-rtLjvD7HYqc2acteeBZEnFqMkAK3f5/5X8hgwPVMv+k=";
};
npmDepsHash = "sha256-m5Rz2JH9e/rJ4tKwNiiZb7wnOmeMDxYuUrVx6QZy25w=";
npmDepsHash = "sha256-BqMXNV0sSfy+hitq4Ngv1OrYgC/vyqZCG39S0HMJh4o=";
# No more package-lock.json in upstream src
postPatch = ''

View File

@@ -13,13 +13,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "fluidsynth";
version = "2.5.0";
version = "2.5.1";
src = fetchFromGitHub {
owner = "FluidSynth";
repo = "fluidsynth";
tag = "v${finalAttrs.version}";
hash = "sha256-ouPCbXg9vgxSAHsReC7dmF1cstQZ1HaUoWcLChE35Hk=";
hash = "sha256-gTkW2X7fcmxJwYf13Yma6cBigz4sbsb99dBSYTDlcyY=";
fetchSubmodules = true;
};

View File

@@ -13,16 +13,16 @@
buildNpmPackage (finalAttrs: {
pname = "gemini-cli";
version = "0.17.0";
version = "0.17.1";
src = fetchFromGitHub {
owner = "google-gemini";
repo = "gemini-cli";
tag = "v${finalAttrs.version}";
hash = "sha256-pJveHjguNl8J67zu6O867iM/JlXM9VTAokIQYHvxUYs=";
hash = "sha256-zfORrAMVozHiUawWiy3TMT+pjEaRJ/DrHeDFPJiCp38=";
};
npmDepsHash = "sha256-SVjUt8xoBtuZJa0mUfZCf/XXxc8OxDU7FG8ZYPTM3j4=";
npmDepsHash = "sha256-dKaKRuHzvNJgi8LP4kKsb68O5k2MTqblQ+7cjYqLqs0=";
nativeBuildInputs = [
jq

View File

@@ -9,13 +9,13 @@
python3.pkgs.buildPythonApplication rec {
pname = "gi-docgen";
version = "2025.4";
version = "2025.5";
format = "other";
src = fetchurl {
url = "mirror://gnome/sources/gi-docgen/${lib.versions.major version}/gi-docgen-${version}.tar.xz";
hash = "sha256-Zshl1Fn+vfteQHiojfBhg2IMPpH3JtHcYI2I7jYFUm4=";
hash = "sha256-JXmjP/h7Yi0Q0QLJG30OzlBjQLcONNu2UiFj4WyQrKM=";
};
depsBuildBuild = [

View File

@@ -17,11 +17,11 @@
stdenv.mkDerivation rec {
pname = "gsettings-desktop-schemas";
version = "49.0";
version = "49.1";
src = fetchurl {
url = "mirror://gnome/sources/${pname}/${lib.versions.major version}/${pname}-${version}.tar.xz";
hash = "sha256-kSkFzEU4KIikdwLtEQHGsI69ASKjKmfZQKuBFqlsUg0=";
hash = "sha256-d3p/g9XlqAdrm/gJyyQQGxsbqcIwI148PejhOWjtDmM=";
};
strictDeps = true;

View File

@@ -18,13 +18,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "haguichi";
version = "1.5.2";
version = "1.5.3";
src = fetchFromGitHub {
owner = "ztefn";
repo = "haguichi";
tag = finalAttrs.version;
hash = "sha256-IEcBCiPU9NPrAbTCnONraeVb/Nlq/u4fsEZX+Vd1DiY=";
hash = "sha256-cVM8VbW8aFq9fXFiVfGhkIhyqSXG2zyB3HyA5tTEDVY=";
};
postPatch = ''

View File

@@ -43,11 +43,11 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "haproxy";
version = "3.2.8";
version = "3.2.9";
src = fetchurl {
url = "https://www.haproxy.org/download/${lib.versions.majorMinor finalAttrs.version}/src/haproxy-${finalAttrs.version}.tar.gz";
hash = "sha256-RnA/uUcg+SzOKwgEmkDZF2liA3umdohcVaVr2dYl58I=";
hash = "sha256-5mDRQbKQGfTRmHhbCDTMPpyW787rgHwv/y/JNb0zVMI=";
};
buildInputs = [

View File

@@ -6,13 +6,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "hwdata";
version = "0.400";
version = "0.401";
src = fetchFromGitHub {
owner = "vcrhonek";
repo = "hwdata";
rev = "v${finalAttrs.version}";
hash = "sha256-X3LL3PZjEiGrkntegcSWNW2Wsx/IpdTowSVp/F4ov+E=";
hash = "sha256-2NZwylrUfnzA0aE+xlVZ7QCpCzfW9DwGzRVHirt0TRU=";
};
doCheck = false; # this does build machine-specific checks (e.g. enumerates PCI bus)

View File

@@ -71,16 +71,18 @@ stdenv.mkDerivation rec {
postInstall = ''
mkdir $apparmor
cat >$apparmor/bin.ping <<EOF
$out/bin/ping {
abi <abi/4.0>,
include <tunables/global>
profile $out/bin/ping {
include <abstractions/base>
include <abstractions/consoles>
include <abstractions/nameservice>
include "${apparmorRulesFromClosure { name = "ping"; } [ stdenv.cc.libc ]}"
include <local/bin.ping>
capability net_raw,
network inet raw,
network inet6 raw,
mr $out/bin/ping,
include if exists <local/bin.ping>
}
EOF
'';

View File

@@ -9,13 +9,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "iso-codes";
version = "4.18.0";
version = "4.19.0";
src = fetchurl {
url =
with finalAttrs;
"https://salsa.debian.org/iso-codes-team/iso-codes/-/archive/v${version}/${pname}-v${version}.tar.gz";
hash = "sha256-UR9nv0tRqnfxfEWtv/UzJCtQ8eNw/kmlcGtjQZAvrIc=";
hash = "sha256-SxQ6iR/rfRu2TkT+PvJT7za6EYXR0SnBQlM43G5G4n0=";
};
nativeBuildInputs = [

View File

@@ -7,14 +7,14 @@
python3Packages.buildPythonApplication rec {
pname = "kolla";
version = "20.3.0";
version = "21.0.0";
pyproject = true;
src = fetchFromGitHub {
owner = "openstack";
repo = "kolla";
tag = version;
hash = "sha256-DLoQkI2cWaH+LYA97/ramOb2bAeZ8kRX386QX8WEivI=";
hash = "sha256-wbVaPIvn4jPcb+h5yKhLDmvT6/widfSX2iV+2KNW8pM=";
};
postPatch = ''

View File

@@ -23,7 +23,7 @@
stdenv.mkDerivation (finalAttrs: {
pname = "libadwaita";
version = "1.8.0";
version = "1.8.1";
outputs = [
"out"
@@ -37,7 +37,7 @@ stdenv.mkDerivation (finalAttrs: {
owner = "GNOME";
repo = "libadwaita";
tag = finalAttrs.version;
hash = "sha256-neF7nt7x3QhSsWuWGouqniFlDHw1Soco7Dpzhy15gWE=";
hash = "sha256-9CcmzwQYZZc6dZAv6x90Od4lrRcYZIejzPgm6S1vz/U=";
};
depsBuildBuild = [

View File

@@ -9,18 +9,18 @@
# TODO: factorize here some other common paths
# that may emerge from use cases.
baseRules ? [
"r $path"
"r $path/etc/**"
"mr $path/share/**"
"$path r"
"$path/etc/** r"
"$path/share/** mr"
# Note that not all libraries are prefixed with "lib",
# eg. glibc-2.30/lib/ld-2.30.so
"mr $path/lib/**.so*"
"mr $path/lib64/**.so*"
"$path/lib/**.so* mr"
"$path/lib64/**.so* mr"
# eg. glibc-2.30/lib/gconv/gconv-modules
"r $path/lib/**"
"r $path/lib64/**"
"$path/lib/** r"
"$path/lib64/** r"
# Internal executables
"ixr $path/libexec/**"
"$path/libexec/** ixr"
],
name ? "",
}:

View File

@@ -3,6 +3,7 @@
lib,
buildPackages,
fetchurl,
fetchpatch,
runtimeShell,
pkgsBuildHost,
usePam ? !isStatic,
@@ -28,11 +29,11 @@ assert usePam -> pam != null;
stdenv.mkDerivation rec {
pname = "libcap";
version = "2.76";
version = "2.77";
src = fetchurl {
url = "mirror://kernel/linux/libs/security/linux-privs/libcap2/${pname}-${version}.tar.xz";
hash = "sha256-Yp2kqymQDQ9/zDYicHN0MRmSX9cRyZoWibv1ybQMjm8=";
hash = "sha256-iXvBi0Svwmxw54zq09uzHhVKzCS+4IWloJB5qI2/b1I=";
};
outputs = [
@@ -73,6 +74,13 @@ stdenv.mkDerivation rec {
"LIBCSTATIC=yes"
];
patches = [
(fetchpatch {
url = "https://git.kernel.org/pub/scm/libs/libcap/libcap.git/patch/?id=d628b3bfe40338d4efff6b0ae50f250a0eb884c7";
hash = "sha256-Eiv/BOJZkduL+hOEJd8K1LQd9wvOeCKchE2GaLcerVc=";
})
];
postPatch = ''
patchShebangs ./progs/mkcapshdoc.sh
@@ -86,11 +94,6 @@ stdenv.mkDerivation rec {
--replace 'lib_prefix=$(exec_prefix)' "lib_prefix=$lib" \
--replace 'inc_prefix=$(prefix)' "inc_prefix=$dev" \
--replace 'man_prefix=$(prefix)' "man_prefix=$doc"
''
+ lib.optionalString withGo ''
# disable cross compilation for artifacts which are run as part of the build
substituteInPlace go/Makefile \
--replace-fail '$(GO) run' 'GOOS= GOARCH= $(GO) run'
'';
installFlags = [ "RAISE_SETFCAP=no" ];

View File

@@ -11,13 +11,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "libdeflate";
version = "1.24";
version = "1.25";
src = fetchFromGitHub {
owner = "ebiggers";
repo = "libdeflate";
rev = "v${finalAttrs.version}";
hash = "sha256-IaXXm9VrZ0Pgb3yTh1fPKkifJDvCxvCfTH08Sdho0Ko=";
hash = "sha256-2TiV3kmFs9j4aYetoYeWg3+MoZ542/0zaD0hwn9b8ZA=";
};
cmakeFlags = [

View File

@@ -16,11 +16,11 @@
stdenv.mkDerivation rec {
pname = "libdrm";
version = "2.4.127";
version = "2.4.128";
src = fetchurl {
url = "https://dri.freedesktop.org/${pname}/${pname}-${version}.tar.xz";
hash = "sha256-BRrrPlQqV2IQGP/EQ/sIjdabeO7wzkgItgTOD+rJ9H8=";
hash = "sha256-O7NduHAMKgtWnyxnKaU/VJV4aFazEIVMjeV3gqIr3aw=";
};
outputs = [

View File

@@ -117,30 +117,9 @@ let
};
in
{
libressl_4_0 = generic {
version = "4.0.1";
hash = "sha256-IClLh3eMJidIk4Y5Q8hjWJebSZ03tJl31r+Gj3tZfL0=";
# Fixes build on loongarch64
# https://github.com/libressl/portable/pull/1146
patches = [
(fetchpatch {
name = "0100-ALT-basic-loongarch64-support.patch";
url = "https://git.altlinux.org/gears/L/LibreSSL.git?p=LibreSSL.git;a=blob_plain;f=patches/0100-ALT-basic-loongarch64-support.patch;hb=70ddea860b8b62531bd3968bf4d7a5c4b7086776";
stripLen = 2;
extraPrefix = "";
postFetch = ''
substituteInPlace "$out" \
--replace-fail "a//dev/null" "/dev/null"
'';
hash = "sha256-dEdtmHHiR7twAqgebXv1Owle/KYCak71NhDCp0PdseU=";
})
common-cmake-install-full-dirs-patch
];
};
libressl_4_1 = generic {
version = "4.1.1";
hash = "sha256-x/96fWddX1dzCUDlzP8dvi3NW3QFtTl+D3/9ZqXtVnk=";
version = "4.1.2";
hash = "sha256-+6Ti+ip/UjBt96OJlwoQ6YuX6w7bKZqf252/SZmcYeE=";
# Fixes build on loongarch64
# https://github.com/libressl/portable/pull/1184
postPatch = ''
@@ -158,8 +137,8 @@ in
};
libressl_4_2 = generic {
version = "4.2.0";
hash = "sha256-D326RNfLjfjVPyz78ZVSVLwSjgCJWV8aui+s+u6ECLI=";
version = "4.2.1";
hash = "sha256-bVwvWFg1iOp5H0yGRQBAcdAN+lVKW/eIoAbKHrWr1ws=";
patches = [
common-cmake-install-full-dirs-patch
];

View File

@@ -2,7 +2,6 @@
lib,
stdenv,
fetchurl,
fetchpatch,
pkg-config,
meson,
ninja,
@@ -50,7 +49,7 @@
stdenv.mkDerivation (finalAttrs: {
pname = "librsvg";
version = "2.61.2";
version = "2.61.3";
outputs = [
"out"
@@ -62,23 +61,13 @@ stdenv.mkDerivation (finalAttrs: {
src = fetchurl {
url = "mirror://gnome/sources/librsvg/${lib.versions.majorMinor finalAttrs.version}/librsvg-${finalAttrs.version}.tar.xz";
hash = "sha256-RkTYNiPdYcxEecKzw3Lh2isoFVLryQA1yNGsUC6x3AA=";
hash = "sha256-pW0sgNdErS8nGPhd9Gb+cdJP8fm8Pl71iL3k1+h4FfI=";
};
patches = [
(fetchpatch {
# https://gitlab.gnome.org/GNOME/librsvg/-/merge_requests/1149
# libxml 2.15+ requires adjustments to error handling
# remove next librsvg release
url = "https://gitlab.gnome.org/GNOME/librsvg/-/commit/6663df8e9aec323f0c124e97a7c7447a90c67c4a.patch";
hash = "sha256-+iyRvxVMxSCW0IIizXXheBFytwhBtU4cyJNTBebCOSg=";
})
];
cargoDeps = rustPlatform.fetchCargoVendor {
inherit (finalAttrs) src;
name = "librsvg-deps-${finalAttrs.version}";
hash = "sha256-OZspQg9ryDNILUZMiB77vIF0uGCMyVe7blX5BJk102k=";
hash = "sha256-5uNkjfZhETuG8Sjw66zapYXOj4dgz9Ziry2kAV+pvZQ=";
dontConfigure = true;
};

View File

@@ -3,15 +3,16 @@
stdenv,
fetchurl,
perl,
gitUpdater,
}:
stdenv.mkDerivation rec {
version = "0.15.3";
version = "0.15.5";
pname = "liburcu";
src = fetchurl {
url = "https://lttng.org/files/urcu/userspace-rcu-${version}.tar.bz2";
hash = "sha256-Jmh+yE4+EUdZRUyISgir6ved7AmwQYld30xF7BUKy20=";
hash = "sha256-sveHqKg1EsMlmecc2rzFExRklHuCAUiWvRFBOy14LeE=";
};
outputs = [
@@ -27,6 +28,11 @@ stdenv.mkDerivation rec {
preCheck = "patchShebangs tests/unit";
doCheck = true;
passthru.updateScript = gitUpdater {
url = "https://git.lttng.org/userspace-rcu.git";
rev-prefix = "v";
};
meta = {
description = "Userspace RCU (read-copy-update) library";
homepage = "https://lttng.org/urcu";

View File

@@ -2,6 +2,7 @@
lib,
stdenv,
fetchFromGitHub,
fetchpatch,
cmake,
valgrind,
testers,
@@ -18,6 +19,14 @@ stdenv.mkDerivation (finalAttrs: {
hash = "sha256-/dG1n59SKBaEBg72pAWltAtVmJ2cXxlFFhP+klrkTos=";
};
patches = [
(fetchpatch {
name = "CVE-2025-62813.patch";
url = "https://github.com/lz4/lz4/commit/f64efec011c058bd70348576438abac222fe6c82.patch";
hash = "sha256-qOvK0A3MGX14WdhThV7m4G6s+ZMP6eA/07A2BY5nesY=";
})
];
nativeBuildInputs = [
cmake
];

View File

@@ -14,17 +14,17 @@
}:
buildGoModule rec {
pname = "mautrix-slack";
version = "25.10";
tag = "v0.2510.0";
version = "25.11";
tag = "v0.2511.0";
src = fetchFromGitHub {
owner = "mautrix";
repo = "slack";
tag = tag;
hash = "sha256-PeSE7WKFSSxZyyG9TJmYeCzHY3bPvkHZ5l+mLzr8tS8=";
inherit tag;
hash = "sha256-9f+GL0eziA2Z9qFXY9VRwj6PK0jUm4bo90pJEuNR1IY=";
};
vendorHash = "sha256-9MsHRU2EqMTWEMVraJ/6/084X5yx3zzSdxP8zSYFJ1E=";
vendorHash = "sha256-djNvUIlJuWqqREV3tYmEe9yolKymhuzA0jsp714qfOQ=";
buildInputs = lib.optional (!withGoolm) olm;
tags = lib.optional withGoolm "goolm";

View File

@@ -2,6 +2,7 @@
lib,
stdenv,
fetchFromGitHub,
fetchpatch2,
nix,
rustPlatform,
installShellFiles,
@@ -22,6 +23,14 @@ rustPlatform.buildRustPackage rec {
cargoHash = "sha256-wvTixSVHXglJM+nBMulZNZKF8pZfNd2G8Z+1PlAWmpk=";
patches = [
(fetchpatch2 {
name = "fix-rust-1.91-tests.patch";
url = "https://github.com/rust-lang/mdBook/commit/841c68d05e763b031524a2b4d679f033cd15e64c.patch?full_index=1";
hash = "sha256-KDQhmFX2TWamtdyssFL69MP3vg9LABb+bF8/7vaFsew=";
})
];
nativeBuildInputs = [ installShellFiles ];
postInstall = lib.optionalString (stdenv.buildPlatform.canExecute stdenv.hostPlatform) ''

View File

@@ -56,6 +56,13 @@ stdenv.mkDerivation rec {
postPatch = ''
sed -i -e '/ARCHFLAGS=/s:=.*:=:' configure
''
# Only ppc64le baseline guarantees AltiVec, no configure option to disable it so just make checks never signal success.
# AltiVec code also fails without disabling new compiler warnings:
# quant_non_intra.c:72:42: error: initialization of '__vector unsigned short *' {aka '__vector(8) short unsigned int *'} from incompatible pointer type 'uint16_t *' {aka 'short unsigned int *'} [-Wincompatible-pointer-types]
+ lib.optionalString (!(stdenv.hostPlatform.isPower64 && stdenv.hostPlatform.isLittleEndian)) ''
substituteInPlace configure \
--replace-fail 'have_altivec=true' 'have_altivec=false'
'';
enableParallelBuilding = true;

View File

@@ -6,7 +6,7 @@
cmake,
pkg-config,
which,
ffmpeg_7,
ffmpeg,
fftw,
frei0r,
libdv,
@@ -25,6 +25,7 @@
cudaSupport ? config.cudaSupport,
cudaPackages ? { },
enableJackrack ? stdenv.hostPlatform.isLinux,
gdk-pixbuf,
glib,
ladspa-sdk,
ladspaPlugins,
@@ -40,13 +41,13 @@
stdenv.mkDerivation rec {
pname = "mlt";
version = "7.32.0";
version = "7.34.1";
src = fetchFromGitHub {
owner = "mltframework";
repo = "mlt";
tag = "v${version}";
hash = "sha256-8T5FXXGs7SxL6nD+R1Q/0Forsdp5Xux4S3VLvgqXzw8=";
hash = "sha256-zdfjl4ZrdmX445hYx2CoKj1NuXQslQpTC5m96zPrZes=";
# The submodule contains glaxnimate code, since MLT uses internally some functions defined in glaxnimate.
# Since glaxnimate is not available as a library upstream, we cannot remove for now this dependency on
# submodules until upstream exports glaxnimate as a library: https://gitlab.com/mattbas/glaxnimate/-/issues/545
@@ -71,8 +72,9 @@ stdenv.mkDerivation rec {
];
buildInputs = [
(opencv4.override { inherit ffmpeg_7; })
ffmpeg_7
gdk-pixbuf
(opencv4.override { inherit ffmpeg; })
ffmpeg
fftw
frei0r
libdv
@@ -118,9 +120,18 @@ stdenv.mkDerivation rec {
++ lib.optionals enablePython [
"-DSWIG_PYTHON=ON"
]
++ lib.optionals (qt != null) [
"-DMOD_QT${lib.versions.major qt.qtbase.version}=ON"
"-DMOD_GLAXNIMATE${if lib.versions.major qt.qtbase.version == "5" then "" else "_QT6"}=ON"
++ lib.optionals (qt == null) [
"-DMOD_QT6=OFF"
]
++ lib.optionals (qt != null && lib.versions.major qt.qtbase.version == "5") [
"-DMOD_QT=ON"
"-DMOD_QT6=OFF"
"-DMOD_GLAXNIMATE=ON"
]
++ lib.optionals (qt != null && lib.versions.major qt.qtbase.version == "6") [
"-DMOD_QT6=ON"
"-DMOD_QT=OFF"
"-DMOD_GLAXNIMATE_QT6=ON"
];
preFixup = ''
@@ -137,7 +148,7 @@ stdenv.mkDerivation rec {
'';
passthru = {
ffmpeg = ffmpeg_7;
inherit ffmpeg;
};
passthru.updateScript = gitUpdater {

View File

@@ -11,13 +11,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "munge";
version = "0.5.16";
version = "0.5.17";
src = fetchFromGitHub {
owner = "dun";
repo = "munge";
rev = "munge-${finalAttrs.version}";
sha256 = "sha256-fv42RMUAP8Os33/iHXr70i5Pt2JWZK71DN5vFI3q7Ak=";
sha256 = "sha256-MfxED81P4ipdP4fuxwmpNrAeej3ZH+qiHIt5bSrct1o=";
};
nativeBuildInputs = [

View File

@@ -17,19 +17,19 @@
stdenv.mkDerivation (finalAttrs: {
pname = "n8n";
version = "1.118.2";
version = "1.119.2";
src = fetchFromGitHub {
owner = "n8n-io";
repo = "n8n";
tag = "n8n@${finalAttrs.version}";
hash = "sha256-2mcQ2hMYGydqpP4hqppqdEwB1WxM8J6taWQwoA1MN7Y=";
hash = "sha256-vf2cjTwjN6gbLNtpjyj6X5XSlytH64TbXyqSvqi3E6k=";
};
pnpmDeps = pnpm_10.fetchDeps {
inherit (finalAttrs) pname version src;
fetcherVersion = 2;
hash = "sha256-pBF4usm5Gd+sygf2uZAovpGnEFlywVg2KToMiUSfyZI=";
hash = "sha256-0Dhw0VFIuANOa8Oq8eI1YeUQhuGBO+t56ywUlx8Z2jM=";
};
nativeBuildInputs = [

View File

@@ -8,11 +8,11 @@
stdenv.mkDerivation rec {
pname = "nspr";
version = "4.37";
version = "4.38.2";
src = fetchurl {
url = "mirror://mozilla/nspr/releases/v${version}/src/nspr-${version}.tar.gz";
hash = "sha256-X5NE7Q4xhVvTj4izPJ2auU9wzlR+8yE+SI0VIPYYQPo=";
hash = "sha256-5Akvrqt3vcmzLbERPkIVlI7naOJsRmbbO1pgs18skQU=";
};
patches = [

View File

@@ -52,13 +52,13 @@ in
stdenv.mkDerivation (finalAttrs: {
pname = "odamex";
version = "11.1.1";
version = "11.2.0";
src = fetchFromGitHub {
owner = "odamex";
repo = "odamex";
tag = finalAttrs.version;
hash = "sha256-UUUavIaU65vU80Bp2cVjHg8IubpA6qMqZmDYvTDjfEw=";
hash = "sha256-f9st852Sqmdmb/qNP1ioBY9MApt9Ruw8dBjkkyGM5Qs=";
fetchSubmodules = true;
};

View File

@@ -8,18 +8,18 @@
buildGoModule (finalAttrs: {
pname = "parca-agent";
version = "0.43.0";
version = "0.44.0";
src = fetchFromGitHub {
owner = "parca-dev";
repo = "parca-agent";
tag = "v${finalAttrs.version}";
hash = "sha256-xIe3s/7/raZuunR+Gx/icLHhT5VUNhcfBGbTqHybxu4=";
hash = "sha256-RSVeb40KQA/F8tj329Vis4pSVsJL9PlA69iA+RJwdt8=";
fetchSubmodules = true;
};
proxyVendor = true;
vendorHash = "sha256-UQnIGTZQOgPWqJcc75pyaMFh8P8JKvtvlGneo5F3NEM=";
vendorHash = "sha256-98Ndx9eIVIJA9Zox/9fQ80MZwVjuAtInRWbFncQRz/4=";
buildInputs = [
stdenv.cc.libc.static

View File

@@ -9,13 +9,13 @@
buildGoModule rec {
pname = "pgweb";
version = "0.16.2";
version = "0.17.0";
src = fetchFromGitHub {
owner = "sosedoff";
repo = "pgweb";
rev = "v${version}";
hash = "sha256-gZK8+H3dBMzSVyE96E7byihKMR4+1YlVFZJtCTGUZwI=";
hash = "sha256-3UWld72AN504+Bo8aIY31qMO1xIRL3MXG5ImzMeSoU8=";
};
postPatch = ''
@@ -23,7 +23,7 @@ buildGoModule rec {
rm -f pkg/client/{client,dump}_test.go
'';
vendorHash = "sha256-Jpvf6cST3kBvYzCQLoJ1fijUC/hP1ouptd2bQZ1J/Lo=";
vendorHash = "sha256-7gfziA+rKwS6u63I6DaA2Fi/wvtr1rAJupSNJZB72dU=";
ldflags = [
"-s"

View File

@@ -7,13 +7,13 @@
buildGoModule {
pname = "pkgsite";
version = "0-unstable-2025-11-13";
version = "0-unstable-2025-11-20";
src = fetchFromGitHub {
owner = "golang";
repo = "pkgsite";
rev = "28eed86815232e48f5e757569fcd061f858142d4";
hash = "sha256-de6aDMNOE+N6OWwHD2p6jjuX2z0d6eKZeAYgatuJLgk=";
rev = "84333735ffe124f7bd904805fd488b93841de49f";
hash = "sha256-XYySnVvnNZr1tg46AoYBsmeT5y/StByWcQhnNOdoLJo=";
};
vendorHash = "sha256-Zv9kyBGLicSJlWD0/wv6ggteA+DttOb18/P5s91tJxE=";

View File

@@ -14,16 +14,16 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "rebels-in-the-sky";
version = "1.1.2";
version = "1.1.3";
src = fetchFromGitHub {
owner = "ricott1";
repo = "rebels-in-the-sky";
tag = "v${finalAttrs.version}";
hash = "sha256-37sStLh2gZm5aV2czvV7lU+aCUyed8/ZKPRUb02AQQw=";
hash = "sha256-F7UsJ5EJDuDlre/UBUcHR3zNk3cvlpPsOYPsAy/n8MI=";
};
cargoHash = "sha256-qj9Utd8mICP7Ulx86PWNusV/7OvfaI4u3qvbp69kYP0=";
cargoHash = "sha256-+OavpkMn2bQMLK7J3dzW0MnxVKdmpPoibpQG4cC4EvQ=";
patches = lib.optionals (!withRadio) [
./disable-radio.patch

View File

@@ -9,13 +9,13 @@
# redumper is using C++ modules, this requires latest C++20 compiler and build tools
llvmPackages.libcxxStdenv.mkDerivation (finalAttrs: {
pname = "redumper";
version = "657";
version = "664";
src = fetchFromGitHub {
owner = "superg";
repo = "redumper";
tag = "b${finalAttrs.version}";
hash = "sha256-dkdG00nbnHSC8xC6540KJmTDnEohLQfHpvYzc5dS6tk=";
hash = "sha256-fc3M6Pim+x/UwHOWZDp3yjLx7ajcNaIfYgamskwPDSA=";
};
nativeBuildInputs = [
@@ -24,6 +24,8 @@ llvmPackages.libcxxStdenv.mkDerivation (finalAttrs: {
llvmPackages.clang-tools
];
env.NIX_CFLAGS_COMPILE = "-isystem ${llvmPackages.libcxx.dev}/include/c++/v1";
# https://github.com/superg/redumper/blob/main/.github/workflows/cmake.yml
cmakeFlags = [
"-DCMAKE_BUILD_WITH_INSTALL_RPATH=ON"

View File

@@ -50,16 +50,16 @@ let
in
rustPlatform.buildRustPackage (finalAttrs: {
pname = "rio";
version = "0.2.35";
version = "0.2.36";
src = fetchFromGitHub {
owner = "raphamorim";
repo = "rio";
tag = "v${finalAttrs.version}";
hash = "sha256-KQC8I/XBZ7uBEug5QNxmNbPom0MY10fprO4iCxgLtps=";
hash = "sha256-c/+agFoGRB+kvVSUo5+yc1LlSvLsgD5J1yk2ufDRgc4=";
};
cargoHash = "sha256-Xq387L6V7BlL7jad1liH7qEhD4T5t8N+POTCG1oZ9xU=";
cargoHash = "sha256-KITGepJC6luNwA7ypGDjajLtmBx5faV2ruJ0aXyrFVo=";
nativeBuildInputs = [
rustPlatform.bindgenHook

View File

@@ -1,14 +0,0 @@
--- a/setup.cfg
+++ b/setup.cfg
@@ -67,11 +67,6 @@ console_scripts =
SCons.Tool.docbook = *.*
-[options.data_files]
-. = scons.1
- scons-time.1
- sconsign.1
-
[sdist]
dist_dir=build/dist

Some files were not shown because too many files have changed in this diff Show More