From a090aae6c103b8ab8d14c51d2fc8d79da27f97fb Mon Sep 17 00:00:00 2001 From: SandaruKasa Date: Sat, 18 Jul 2026 20:45:42 +0300 Subject: [PATCH 1/4] libaom: 3.12.1 -> 3.14.1 Changelog: https://aomedia.googlesource.com/aom/+/refs/tags/v3.14.1/CHANGELOG --- pkgs/by-name/li/libaom/outputs.patch | 25 +++++++++++++------------ pkgs/by-name/li/libaom/package.nix | 4 ++-- 2 files changed, 15 insertions(+), 14 deletions(-) diff --git a/pkgs/by-name/li/libaom/outputs.patch b/pkgs/by-name/li/libaom/outputs.patch index 7b34338403f2..d7a6cafba539 100644 --- a/pkgs/by-name/li/libaom/outputs.patch +++ b/pkgs/by-name/li/libaom/outputs.patch @@ -1,8 +1,8 @@ -diff --git a/build/cmake/aom_install.cmake b/build/cmake/aom_install.cmake -index 0bd2bf035..5cf5acea8 100644 ---- a/build/cmake/aom_install.cmake -+++ b/build/cmake/aom_install.cmake -@@ -42,8 +42,8 @@ macro(setup_aom_install_targets) +diff --git a/cmake/aom_install.cmake b/cmake/aom_install.cmake +index a8f6d64361..c5223462ed 100644 +--- a/cmake/aom_install.cmake ++++ b/cmake/aom_install.cmake +@@ -45,8 +45,8 @@ macro(setup_aom_install_targets) -DAOM_ROOT=${AOM_ROOT} -DCMAKE_INSTALL_PREFIX=${CMAKE_INSTALL_PREFIX} -DCMAKE_INSTALL_BINDIR=${CMAKE_INSTALL_BINDIR} @@ -11,9 +11,9 @@ index 0bd2bf035..5cf5acea8 100644 + -DCMAKE_INSTALL_FULL_INCLUDEDIR=${CMAKE_INSTALL_FULL_INCLUDEDIR} + -DCMAKE_INSTALL_FULL_LIBDIR=${CMAKE_INSTALL_FULL_LIBDIR} -DCMAKE_PROJECT_NAME=${CMAKE_PROJECT_NAME} + -DCMAKE_THREAD_LIBS_INIT=${CMAKE_THREAD_LIBS_INIT} -DCONFIG_MULTITHREAD=${CONFIG_MULTITHREAD} - -DCONFIG_TUNE_VMAF=${CONFIG_TUNE_VMAF} -@@ -84,12 +84,12 @@ macro(setup_aom_install_targets) +@@ -115,13 +115,13 @@ macro(setup_aom_install_targets) # Setup the install rules. install() will automatically prepend # CMAKE_INSTALL_PREFIX to relative paths install(FILES ${AOM_INSTALL_INCS} @@ -23,6 +23,7 @@ index 0bd2bf035..5cf5acea8 100644 - DESTINATION "${CMAKE_INSTALL_LIBDIR}/pkgconfig") + DESTINATION "${CMAKE_INSTALL_FULL_LIBDIR}/pkgconfig") install(TARGETS ${AOM_INSTALL_LIBS};${AOM_INSTALL_BINS} + EXPORT "${AOM_TARGETS_EXPORT_NAME}" - RUNTIME DESTINATION "${CMAKE_INSTALL_BINDIR}" - LIBRARY DESTINATION "${CMAKE_INSTALL_LIBDIR}" - ARCHIVE DESTINATION "${CMAKE_INSTALL_LIBDIR}") @@ -31,12 +32,12 @@ index 0bd2bf035..5cf5acea8 100644 + ARCHIVE DESTINATION "${CMAKE_INSTALL_FULL_LIBDIR}") endif() endmacro() -diff --git a/build/cmake/pkg_config.cmake b/build/cmake/pkg_config.cmake -index e8fff2e77..b8a73aad4 100644 ---- a/build/cmake/pkg_config.cmake -+++ b/build/cmake/pkg_config.cmake +diff --git a/cmake/pkg_config.cmake b/cmake/pkg_config.cmake +index ad3cf77009..1b46040cd1 100644 +--- a/cmake/pkg_config.cmake ++++ b/cmake/pkg_config.cmake @@ -11,8 +11,8 @@ - cmake_minimum_required(VERSION 3.5) + cmake_minimum_required(VERSION 3.16) set(REQUIRED_ARGS "AOM_ROOT" "AOM_CONFIG_DIR" "CMAKE_INSTALL_PREFIX" - "CMAKE_INSTALL_BINDIR" "CMAKE_INSTALL_INCLUDEDIR" diff --git a/pkgs/by-name/li/libaom/package.nix b/pkgs/by-name/li/libaom/package.nix index c8296dd90fb8..739ac4320eaa 100644 --- a/pkgs/by-name/li/libaom/package.nix +++ b/pkgs/by-name/li/libaom/package.nix @@ -23,11 +23,11 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "libaom"; - version = "3.12.1"; + version = "3.14.1"; src = fetchzip { url = "https://aomedia.googlesource.com/aom/+archive/v${finalAttrs.version}.tar.gz"; - hash = "sha256-AAS6wfq4rZ4frm6+gwKoIS3+NVzPhhfW428WXJQ2tQ8="; + hash = "sha256-ddMrDkWV5jUbpPGKsMQl7s4r43205WbBtCEYtZNgwAM="; stripRoot = false; }; From c5898aaf4154cffe9fd936307c8c8b5911102ec5 Mon Sep 17 00:00:00 2001 From: SandaruKasa Date: Sat, 18 Jul 2026 20:50:26 +0300 Subject: [PATCH 2/4] libaom: strictDeps, __structuredAttrs --- pkgs/by-name/li/libaom/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/li/libaom/package.nix b/pkgs/by-name/li/libaom/package.nix index 739ac4320eaa..9dfe847d606a 100644 --- a/pkgs/by-name/li/libaom/package.nix +++ b/pkgs/by-name/li/libaom/package.nix @@ -96,6 +96,9 @@ stdenv.mkDerivation (finalAttrs: { ln -s $static $out ''; + __structuredAttrs = true; + strictDeps = true; + outputs = [ "out" "bin" From 2aef6e14b531d263160f63eb678c652da3c2db2c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Vladim=C3=ADr=20=C4=8Cun=C3=A1t?= Date: Tue, 22 Sep 2026 15:57:25 +0200 Subject: [PATCH 3/4] libaom: 3.14.1 -> 3.15.0 https://aomedia.googlesource.com/aom/+/refs/tags/v3.15.0 Fixes: CVE-2026-56209 CVE-2026-13906 --- pkgs/by-name/li/libaom/package.nix | 28 ++++++++++++---------------- 1 file changed, 12 insertions(+), 16 deletions(-) diff --git a/pkgs/by-name/li/libaom/package.nix b/pkgs/by-name/li/libaom/package.nix index 9dfe847d606a..6af569faf2b2 100644 --- a/pkgs/by-name/li/libaom/package.nix +++ b/pkgs/by-name/li/libaom/package.nix @@ -23,25 +23,16 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "libaom"; - version = "3.14.1"; + version = "3.15.0"; src = fetchzip { url = "https://aomedia.googlesource.com/aom/+archive/v${finalAttrs.version}.tar.gz"; - hash = "sha256-ddMrDkWV5jUbpPGKsMQl7s4r43205WbBtCEYtZNgwAM="; + hash = "sha256-TixZQP06TEZPtpHvWVOEagzHtXW9hqXWweO2yimBDG4="; stripRoot = false; }; patches = [ ./outputs.patch - ] - ++ lib.optionals (!stdenv.hostPlatform.isDarwin) [ - # This patch defines `_POSIX_C_SOURCE`, which breaks system headers - # on Darwin. - (fetchurl { - name = "musl.patch"; - url = "https://gitweb.gentoo.org/repo/gentoo.git/plain/media-libs/libaom/files/libaom-3.4.0-posix-c-source-ftello.patch?id=50c7c4021e347ee549164595280cf8a23c960959"; - hash = "sha256-6+u7GTxZcSNJgN7D+s+XAVwbMnULufkTcQ0s7l+Ydl0="; - }) ]; nativeBuildInputs = [ @@ -54,11 +45,16 @@ stdenv.mkDerivation (finalAttrs: { propagatedBuildInputs = lib.optional enableVmaf libvmaf; - env = lib.optionalAttrs stdenv.hostPlatform.isFreeBSD { - # This can be removed when we switch to libcxx from llvm 20 - # https://github.com/llvm/llvm-project/pull/122361 - NIX_CFLAGS_COMPILE = "-D_XOPEN_SOURCE=700"; - }; + env = + lib.optionalAttrs stdenv.hostPlatform.isFreeBSD { + # This can be removed when we switch to libcxx from llvm 20 + # https://github.com/llvm/llvm-project/pull/122361 + NIX_CFLAGS_COMPILE = "-D_XOPEN_SOURCE=700"; + } + // lib.optionalAttrs stdenv.hostPlatform.isLinux { + # _POSIX_C_SOURCE breaks system headers on Darwin; it's required on musl + NIX_CFLAGS_COMPILE = "-D_POSIX_C_SOURCE=200112L"; + }; preConfigure = '' # build uses `git describe` to set the build version From 99db7938f54a64d95ce56a885082c507486db31c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Vladim=C3=ADr=20=C4=8Cun=C3=A1t?= Date: Wed, 23 Sep 2026 08:28:03 +0200 Subject: [PATCH 4/4] libaom: fixup outputs in *.cmake Now libheif builds for me with this atop nixpkgs master. --- pkgs/by-name/li/libaom/package.nix | 3 +++ 1 file changed, 3 insertions(+) diff --git a/pkgs/by-name/li/libaom/package.nix b/pkgs/by-name/li/libaom/package.nix index 6af569faf2b2..c8cf959b9bf0 100644 --- a/pkgs/by-name/li/libaom/package.nix +++ b/pkgs/by-name/li/libaom/package.nix @@ -87,6 +87,9 @@ stdenv.mkDerivation (finalAttrs: { postFixup = '' moveToOutput lib/libaom.a "$static" + substituteInPlace "$dev"/lib/cmake/*/*.cmake \ + --replace-quiet "$out/lib/libaom.a" "$static/lib/libaom.a" \ + --replace-quiet "$"'{_IMPORT_PREFIX}/include' "$dev/include" '' + lib.optionalString stdenv.hostPlatform.isStatic '' ln -s $static $out