diff --git a/nixos/modules/security/wrappers/default.nix b/nixos/modules/security/wrappers/default.nix index 907b6ac01b21..7cc3a4f8e4b2 100644 --- a/nixos/modules/security/wrappers/default.nix +++ b/nixos/modules/security/wrappers/default.nix @@ -361,16 +361,19 @@ in ###### wrappers consistency checks system.checks = lib.singleton ( - pkgs.runCommandLocal "ensure-all-wrappers-paths-exist" + pkgs.runCommandLocal "ensure-wrapper-integrity" { - nativeBuildInputs = [ pkgs.libcap-text-verifier ]; + nativeBuildInputs = [ + pkgs.libcap-text-verifier + pkgs.file + ]; preferLocalBuild = true; } '' # make sure we produce output mkdir -p $out - echo -n "Checking that Nix store paths of all wrapped programs exist... " + echo -n "Checking that Nix store paths of all wrapped programs exist and are ELF executables... " ${lib.toShellVar "wrappers" (lib.mapAttrs (n: v: v.source) wrappers)} for name in "''${!wrappers[@]}"; do path="''${wrappers[$name]}" @@ -382,6 +385,15 @@ in test -t 1 && echo -ne '\033[0m' exit 1 fi + magic=$(file --mime --brief --dereference "$path") + if ! [[ "$magic" =~ application/x-executable || "$magic" =~ application/x-pie-executable ]]; then + test -t 1 && echo -ne '\033[1;31m' + echo "FAIL" + echo "The target executable $path is not an ELF! This is a security risk." + echo "Script wrappers (e.g. bash or python) are commonly susceptible to dangerous env var injections." + test -t 1 && echo -ne '\033[0m' + exit 1 + fi done echo "OK" diff --git a/nixos/modules/services/networking/rpcbind.nix b/nixos/modules/services/networking/rpcbind.nix index 8436ebb23658..f16d44af4816 100644 --- a/nixos/modules/services/networking/rpcbind.nix +++ b/nixos/modules/services/networking/rpcbind.nix @@ -5,8 +5,6 @@ ... }: -with lib; - { ###### interface @@ -15,8 +13,8 @@ with lib; services.rpcbind = { - enable = mkOption { - type = types.bool; + enable = lib.mkOption { + type = lib.types.bool; default = false; description = '' Whether to enable `rpcbind`, an ONC RPC directory service @@ -32,29 +30,34 @@ with lib; ###### implementation - config = mkIf config.services.rpcbind.enable { - environment.systemPackages = [ pkgs.rpcbind ]; + config = lib.mkMerge [ + (lib.mkIf config.services.rpcbind.enable { + environment.systemPackages = [ pkgs.rpcbind ]; - systemd.packages = [ pkgs.rpcbind ]; + systemd.packages = [ pkgs.rpcbind ]; - systemd.services.rpcbind = { - wantedBy = [ "multi-user.target" ]; - # rpcbind performs a check for /var/run/rpcbind.lock at startup - # and will crash if /var/run isn't present. In the stock NixOS - # var.conf tmpfiles configuration file, /var/run is symlinked to - # /run, so rpcbind can enter a race condition in which /var/run - # isn't symlinked yet but tries to interact with the path, so - # controlling the order explicitly here ensures that rpcbind can - # start successfully. The `wants` instead of `requires` should - # avoid creating a strict/brittle dependency. - wants = [ "systemd-tmpfiles-setup.service" ]; - after = [ "systemd-tmpfiles-setup.service" ]; - }; + systemd.services.rpcbind = { + wantedBy = [ "multi-user.target" ]; + # rpcbind performs a check for /var/run/rpcbind.lock at startup + # and will crash if /var/run isn't present. In the stock NixOS + # var.conf tmpfiles configuration file, /var/run is symlinked to + # /run, so rpcbind can enter a race condition in which /var/run + # isn't symlinked yet but tries to interact with the path, so + # controlling the order explicitly here ensures that rpcbind can + # start successfully. The `wants` instead of `requires` should + # avoid creating a strict/brittle dependency. + wants = [ "systemd-tmpfiles-setup.service" ]; + after = [ "systemd-tmpfiles-setup.service" ]; + }; + }) - users.users.rpc = { - group = "nogroup"; - uid = config.ids.uids.rpc; - }; - }; + { + users.users.rpc = { + enable = config.services.rpcbind.enable; + group = "nogroup"; + uid = config.ids.uids.rpc; + }; + } + ]; } diff --git a/nixos/modules/virtualisation/qemu-vm.nix b/nixos/modules/virtualisation/qemu-vm.nix index d8f6e3be665e..40f9db9b7107 100644 --- a/nixos/modules/virtualisation/qemu-vm.nix +++ b/nixos/modules/virtualisation/qemu-vm.nix @@ -337,7 +337,7 @@ let ${if share.writable then "--writeback" else "--readonly"} \ --sandbox=none \ --seccomp=none \ - --cache=always \ + --cache=${share.cache} \ --no-announce-submounts \ --translate-uid=host:65534:0:1 \ --translate-gid=host:65534:0:1 \ @@ -595,6 +595,23 @@ in options.writable = lib.mkEnableOption "" // { description = "Whether the directory is writable on the host and guest."; }; + options.cache = mkOption { + type = types.enum [ + "auto" + "always" + "metadata" + "never" + ]; + default = "auto"; + description = '' + Cache policy for the virtiofs daemon. + + For details refer to the [virtiofsd documentation](https://virtio-fs.gitlab.io/virtiofsd/doc/virtiofsd/passthrough/enum.CachePolicy.html). + + Effective on Linux hosts only. + Ignored when using VirtFS (9P) (the default on non-Linux hosts). + ''; + }; } ); default = { }; @@ -1238,6 +1255,7 @@ in # Always mount this to /nix/.ro-store because we never want to actually # write to the host Nix Store. target = "/nix/.ro-store"; + cache = mkIf useVirtiofs "always"; }; xchg = { source = ''"$TMPDIR"/xchg''; diff --git a/nixos/tests/all-tests.nix b/nixos/tests/all-tests.nix index a1ab5a2d4acd..b92bd580594a 100644 --- a/nixos/tests/all-tests.nix +++ b/nixos/tests/all-tests.nix @@ -1575,6 +1575,7 @@ in qemu-firmware = runTestOn [ "x86_64-linux" ] ./qemu-firmware.nix; qemu-vm-external-disk-image = runTest ./qemu-vm-external-disk-image.nix; qemu-vm-restrictnetwork = handleTest ./qemu-vm-restrictnetwork.nix { }; + qemu-vm-shared-directories = runTest ./qemu-vm-shared-directories.nix; qemu-vm-store = runTest ./qemu-vm-store.nix; qemu-vm-volatile-root = runTest ./qemu-vm-volatile-root.nix; qgis = handleTest ./qgis.nix { package = pkgs.qgis; }; diff --git a/nixos/tests/qemu-vm-shared-directories.nix b/nixos/tests/qemu-vm-shared-directories.nix new file mode 100644 index 000000000000..e4286f3d95bb --- /dev/null +++ b/nixos/tests/qemu-vm-shared-directories.nix @@ -0,0 +1,56 @@ +{ + config, + lib, + ... +}: +{ + name = "qemu-vm-shared-directories"; + + meta.maintainers = with lib.maintainers; [ + fricklerhandwerk + ]; + + meta.platforms = lib.platforms.linux; + + nodes = lib.listToAttrs ( + map + (policy: { + name = policy; + value.virtualisation.sharedDirectories.test = { + source = "/tmp/${policy}"; + target = "/mnt/test"; + cache = policy; + writable = true; + }; + }) + [ + "never" + "metadata" + "auto" + "always" + ] + ); + + testScript = '' + import os + + for policy in ${with builtins; toJSON (attrNames config.nodes)}: + os.makedirs(f"/tmp/{policy}", exist_ok=True) + with open(f"/tmp/{policy}/hello.txt", "w") as f: + f.write("before") + + start_all() + + for machine, policy in [${ + lib.concatMapStringsSep ", " (p: ''(${p}, "${p}")'') (builtins.attrNames config.nodes) + }]: + with subtest(f"cache={policy} propagates host file changes to the guest as expected"): + machine.succeed("grep before /mnt/test/hello.txt") + with open(f"/tmp/{policy}/hello.txt", "w") as f: + f.write("after") + if policy == "always": + always.succeed("grep before /mnt/test/hello.txt") + else: + machine.succeed("grep after /mnt/test/hello.txt") + ''; +} diff --git a/pkgs/applications/networking/cluster/terraform-providers/providers.json b/pkgs/applications/networking/cluster/terraform-providers/providers.json index c2a7bc6c26bd..556f0ec0ca70 100644 --- a/pkgs/applications/networking/cluster/terraform-providers/providers.json +++ b/pkgs/applications/networking/cluster/terraform-providers/providers.json @@ -535,11 +535,11 @@ "vendorHash": "sha256-JEPUJRuVkvZe6XEQWAe++4eUGE8/q3kMzr85LLR9qsE=" }, "hashicorp_azuread": { - "hash": "sha256-mEYEZIztDjyqWSJFoJPXtV0E9YikumtwGVtZA4Jfw3U=", + "hash": "sha256-dS5MlFTNQ1vMbOK5bW7VgeU+dPLONnN7jTobWMKwtw8=", "homepage": "https://registry.terraform.io/providers/hashicorp/azuread", "owner": "hashicorp", "repo": "terraform-provider-azuread", - "rev": "v3.9.0", + "rev": "v3.10.0", "spdx": "MPL-2.0", "vendorHash": null }, @@ -634,13 +634,13 @@ "vendorHash": "sha256-GyuSdDpsOqd1ntwAm09AKCoxeFOLhXo0jPTTxYZC+vg=" }, "hashicorp_local": { - "hash": "sha256-qntV0gfxEVV24gqiVOvUai+pai4vvU+KtLmLBqOBQbY=", + "hash": "sha256-oq1Nc03xfoDajrj0CVAO41embDGQ5cKJ8QbUZfaJv/M=", "homepage": "https://registry.terraform.io/providers/hashicorp/local", "owner": "hashicorp", "repo": "terraform-provider-local", - "rev": "v2.9.0", + "rev": "v2.9.1", "spdx": "MPL-2.0", - "vendorHash": "sha256-qvJSzqGUHw1/Lu4XO7LWssA+TN8pCyTbzh6t1bz+y1g=" + "vendorHash": "sha256-CukYk/fYz/7NSo4B92ZM04Wkbtiobq7kETMXPvgs4mg=" }, "hashicorp_nomad": { "hash": "sha256-O3dtOB+irsUeDq1yXxfqDSyz2jfPXS1UgiL+B4RFsW4=", diff --git a/pkgs/by-name/ai/aider-chat/add-vector-store-search-error.patch b/pkgs/by-name/ai/aider-chat/add-vector-store-search-error.patch new file mode 100644 index 000000000000..76394dd4bde6 --- /dev/null +++ b/pkgs/by-name/ai/aider-chat/add-vector-store-search-error.patch @@ -0,0 +1,11 @@ +diff --git a/aider/exceptions.py b/aider/exceptions.py +--- a/aider/exceptions.py ++++ b/aider/exceptions.py +@@ -49,6 +49,7 @@ + ExInfo("ServiceUnavailableError", True, "The API provider's servers are down or overloaded."), + ExInfo("UnprocessableEntityError", True, None), + ExInfo("UnsupportedParamsError", True, None), ++ ExInfo("VectorStoreSearchError", False, None), + ExInfo( + "Timeout", + True, diff --git a/pkgs/by-name/ai/aider-chat/package.nix b/pkgs/by-name/ai/aider-chat/package.nix index f81abd03ec89..cb33860f3073 100644 --- a/pkgs/by-name/ai/aider-chat/package.nix +++ b/pkgs/by-name/ai/aider-chat/package.nix @@ -173,6 +173,11 @@ let url = "https://github.com/Aider-AI/aider/commit/38716cc5a2621499c50454aa77ee379aa2b0c590.patch"; hash = "sha256-uDIUHbauAmzCfaqx6aswnkUHcmgJi4X2OdMPyn4NeYU="; }) + + # litellm >= 1.101.0 exports the new VectorStoreSearchError exception at + # top level, which trips the strict audit in LiteLLMExceptions._load() + # (same failure mode as the two patches above) + ./add-vector-store-search-error.patch ]; disabledTestPaths = [ diff --git a/pkgs/by-name/an/antigravity-cli/package.nix b/pkgs/by-name/an/antigravity-cli/package.nix index b85c46b5d762..83889ebbc360 100644 --- a/pkgs/by-name/an/antigravity-cli/package.nix +++ b/pkgs/by-name/an/antigravity-cli/package.nix @@ -6,8 +6,8 @@ versionCheckHook, }: let - version = "1.2.9"; - buildId = "6237955799515136"; + version = "1.2.16"; + buildId = "5594158052802560"; wholeVersion = "${version}-${buildId}"; throwSystem = throw "Unsupported system: ${stdenvNoCC.hostPlatform.system}"; @@ -15,15 +15,15 @@ let sourceData = { x86_64-linux = fetchurl { url = "https://storage.googleapis.com/antigravity-public/antigravity-cli/${wholeVersion}/linux-x64/cli_linux_x64.tar.gz"; - hash = "sha256-TleXrQChVKEkYr0V7a6mMFRAE8q5fj/6kjUz7qCj284="; + hash = "sha256-1CR0MOBM69vhypPZzLSDzS89rrTNsKzlpxzRMOC9q4Q="; }; aarch64-linux = fetchurl { url = "https://storage.googleapis.com/antigravity-public/antigravity-cli/${wholeVersion}/linux-arm/cli_linux_arm64.tar.gz"; - hash = "sha256-bq1XoRRtIy6SYTl82dfHpfwgiFlGcuMJbPyezyS8F2c="; + hash = "sha256-ptJp0nZOVjarK82nO3jFh/6dAOrXZ6o5dFdCKVhe4NM="; }; aarch64-darwin = fetchurl { url = "https://storage.googleapis.com/antigravity-public/antigravity-cli/${wholeVersion}/darwin-arm/cli_mac_arm64.tar.gz"; - hash = "sha256-7kPA1JzN4giRClGq9AObYIM+KkYdq0U5F+mK2PF70U4="; + hash = "sha256-l7A+o+kJFuDIpJ7ephVAb47GkEfd4XIopHjBhURF0yo="; }; }; in diff --git a/pkgs/by-name/az/azure-cli/extensions-manual.nix b/pkgs/by-name/az/azure-cli/extensions-manual.nix index b4d83d80b028..350f95d5fb60 100644 --- a/pkgs/by-name/az/azure-cli/extensions-manual.nix +++ b/pkgs/by-name/az/azure-cli/extensions-manual.nix @@ -174,9 +174,9 @@ confcom = mkAzExtension rec { pname = "confcom"; - version = "2.1.1"; + version = "2.3.0"; url = "https://azcliprod.blob.core.windows.net/cli-extensions/confcom-${version}-py3-none-any.whl"; - hash = "sha256-e8nZmjSoEuU3mjQdFfQlHjHuglNk/YTgVmj40+A40E8="; + hash = "sha256-HJ9AlRjBZoYEbuiT19N1UYrHoMzYDKS/NKyLoxhut10="; description = "Microsoft Azure Command-Line Tools Confidential Container Security Policy Generator Extension"; nativeBuildInputs = [ autoPatchelfHook ]; buildInputs = [ openssl ]; diff --git a/pkgs/by-name/ca/cargo-insta/package.nix b/pkgs/by-name/ca/cargo-insta/package.nix index 0a5e2cbf29ac..0af71db732c5 100644 --- a/pkgs/by-name/ca/cargo-insta/package.nix +++ b/pkgs/by-name/ca/cargo-insta/package.nix @@ -8,16 +8,16 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "cargo-insta"; - version = "1.48.0"; + version = "1.49.0"; src = fetchFromGitHub { owner = "mitsuhiko"; repo = "insta"; tag = finalAttrs.version; - hash = "sha256-xIveukm1BsvY6z6bCsV4L9RZGIalspFEYFthE4hCaH8="; + hash = "sha256-mw+qpTc+J6xjirjxRAhbIF0Nw/lkpnEtTaIxDOWqFmc="; }; - cargoHash = "sha256-OlCNm4N+cLreN7iR25cD06vsGnE+IWo5T15h3I6tCa8="; + cargoHash = "sha256-s1BLfuBOfjuP+TnmPC9h5OnUCSLGA0TCZrn8Qb/ZCk8="; nativeCheckInputs = [ # used by test_binary_accept_missing_old_binary diff --git a/pkgs/by-name/co/conduit/package.nix b/pkgs/by-name/co/conduit/package.nix index bd2e23fdca72..7f36ac55f470 100644 --- a/pkgs/by-name/co/conduit/package.nix +++ b/pkgs/by-name/co/conduit/package.nix @@ -15,7 +15,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "conduit"; - version = "0.9.8"; + version = "0.9.9"; __structuredAttrs = true; strictDeps = true; @@ -25,7 +25,7 @@ stdenv.mkDerivation (finalAttrs: { repo = "conduit"; tag = "v${finalAttrs.version}"; fetchSubmodules = true; - hash = "sha256-uGHOz15jv8RHM2JTuJpzppMBKCqMqoWX7w0QZqJ+h8c="; + hash = "sha256-l3fBK20AqNmdOfFtZ+wburekv/+A1VGSQM+V47h/DBI="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/di/diffutils/package.nix b/pkgs/by-name/di/diffutils/package.nix index ad36dd91eed9..7fba0dc6df86 100644 --- a/pkgs/by-name/di/diffutils/package.nix +++ b/pkgs/by-name/di/diffutils/package.nix @@ -72,8 +72,10 @@ stdenv.mkDerivation (finalAttrs: { # "pr" need not be on the PATH as a run-time dep, so we need to tell # configure where it is. Covers the cross and native case alike. lib.optional (coreutils != null) "PR_PROGRAM=${coreutils}/bin/pr" - ++ lib.optionals (stdenv.buildPlatform != stdenv.hostPlatform) [ + ++ lib.optionals (stdenv.buildPlatform != stdenv.hostPlatform && stdenv.hostPlatform.isGnu) [ "gl_cv_func_getopt_gnu=yes" + ] + ++ lib.optionals (stdenv.buildPlatform != stdenv.hostPlatform) [ "gl_cv_func_strcasecmp_works=yes" ]; diff --git a/pkgs/by-name/en/engelsystem/package.nix b/pkgs/by-name/en/engelsystem/package.nix index e7c0a2bfd77f..b9b7547e8265 100644 --- a/pkgs/by-name/en/engelsystem/package.nix +++ b/pkgs/by-name/en/engelsystem/package.nix @@ -11,25 +11,25 @@ php.buildComposerProject2 (finalAttrs: { pname = "engelsystem"; - version = "3.7.0"; + version = "3.7.1"; src = fetchFromGitHub { owner = "engelsystem"; repo = "engelsystem"; tag = "v${finalAttrs.version}"; - hash = "sha256-hnTkeSqxkvO2Prop0VaBAV/4opr46wjEaJ5ptd5zQ34="; + hash = "sha256-G3Ejj/Hcxfd394sOlLy0Xk/CjKbJnTyUPQn5mNLH31I="; }; inherit php; composerNoDev = true; composerStrictValidation = false; - vendorHash = "sha256-oGpgtkX0UVSdVceQ8pD3PuGBITifQzaMIb4QRdc7WeY="; + vendorHash = "sha256-Q1Vr8AywDAI6Apb4ShyV6DhSV3Fm0rX6X0uXlnO3CZo="; yarnOfflineCache = fetchYarnDeps { pname = "${finalAttrs.pname}-yarn-deps"; yarnLock = "${finalAttrs.src}/yarn.lock"; - hash = "sha256-IMg1AoqCiQEvMHeqXgonIY2J0nmBHLW2Drz/Vb0rD48="; + hash = "sha256-FRwmsnRsTVphSFurgaLcfNlNvxcC8fTR79G8r6RGB5A="; }; strictDeps = true; diff --git a/pkgs/by-name/fs/fscan/package.nix b/pkgs/by-name/fs/fscan/package.nix index 35e62016dc78..1fe4156c87ae 100644 --- a/pkgs/by-name/fs/fscan/package.nix +++ b/pkgs/by-name/fs/fscan/package.nix @@ -6,13 +6,13 @@ buildGoModule (finalAttrs: { pname = "fscan"; - version = "2.2.1"; + version = "2.2.2"; src = fetchFromGitHub { owner = "shadow1ng"; repo = "fscan"; tag = "v${finalAttrs.version}"; - hash = "sha256-awg6YqZyhlt04JobZXZx/PYuw2X7gsYKWb8480ymcN8="; + hash = "sha256-P3zgmjlBZCmeJxYy5SRPC9Bvl9O03LUJoeAFYhp8tGA="; }; vendorHash = "sha256-IlGHY0KbYsy/5Yz11XhkcS9yS8byY3vhPZiTwnJM6/Q="; diff --git a/pkgs/by-name/fu/fulcrum/package.nix b/pkgs/by-name/fu/fulcrum/package.nix index 4c3ac6fc6ba8..96e9bdcdd920 100644 --- a/pkgs/by-name/fu/fulcrum/package.nix +++ b/pkgs/by-name/fu/fulcrum/package.nix @@ -13,13 +13,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "fulcrum"; - version = "2.1.2"; + version = "2.1.3"; src = fetchFromGitHub { owner = "cculianu"; repo = "Fulcrum"; tag = "v${finalAttrs.version}"; - hash = "sha256-a2i6tG2PFV0nXmy5Hx17Brwe/hRSpFs3DKtEB1uy/Wk="; + hash = "sha256-bqT2KBZKVPykRZ4/EsV3idzSkcj+1Fh59ODUJ3Zs0po="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/gi/gitlab-ci-verify/package.nix b/pkgs/by-name/gi/gitlab-ci-verify/package.nix index 398e5ce36f3b..7dd741d5d395 100644 --- a/pkgs/by-name/gi/gitlab-ci-verify/package.nix +++ b/pkgs/by-name/gi/gitlab-ci-verify/package.nix @@ -9,7 +9,7 @@ buildGoModule (finalAttrs: { pname = "gitlab-ci-verify"; - version = "2.11.8"; + version = "2.11.9"; __structuredAttrs = true; __darwinAllowLocalNetworking = true; @@ -17,7 +17,7 @@ buildGoModule (finalAttrs: { owner = "timo-reymann"; repo = "gitlab-ci-verify"; tag = "v${finalAttrs.version}"; - hash = "sha256-/HzVfaRBPfG+YjHHzwE5ROYBjR+8Lqxusku7l46oXaM="; + hash = "sha256-91MLZji9AKlHb6G/Qs0t8QTFD5D57bFROrAyI5NWKGU="; fetchSubmodules = true; leaveDotGit = true; postFetch = '' @@ -28,7 +28,7 @@ buildGoModule (finalAttrs: { ''; }; - vendorHash = "sha256-o7NL6Ijh+ZEUhEYlzypM0KPh8XtMXeTzB9VBB7bPlco="; + vendorHash = "sha256-5QtbZt4qg10aoznIILokaJbQx2tTTIKaNbc08i5G5GU="; ldflags = [ "-s" diff --git a/pkgs/by-name/he/herdr/package.nix b/pkgs/by-name/he/herdr/package.nix index b94140bb115e..760d1bc769ad 100644 --- a/pkgs/by-name/he/herdr/package.nix +++ b/pkgs/by-name/he/herdr/package.nix @@ -13,7 +13,7 @@ }: rustPlatform.buildRustPackage (finalAttrs: { pname = "herdr"; - version = "0.9.1"; + version = "0.9.3"; __structuredAttrs = true; @@ -21,10 +21,10 @@ rustPlatform.buildRustPackage (finalAttrs: { owner = "herdrdev"; repo = "herdr"; tag = "v${finalAttrs.version}"; - hash = "sha256-N6+kprfWRyh0AkAiopkGsNXUGGORyPVFHEaDHCpGQs8="; + hash = "sha256-uu452Xe23pSvFk7w7fKPjiaqY5QenUIljao2SFAxpc0="; }; - cargoHash = "sha256-1VAmsDE3zeU0wMVQKleQcd/zq8/k/oor8tasrsRQfeY="; + cargoHash = "sha256-+gTWtEheyuI59yf2PqRbcbcFIW+/cYb7zZ2mPv2VN0Y="; zigDeps = zig_0_16.fetchDeps { inherit (finalAttrs) pname version; diff --git a/pkgs/by-name/je/jenkins/package.nix b/pkgs/by-name/je/jenkins/package.nix index 1799e66d9777..ddebf75132c3 100644 --- a/pkgs/by-name/je/jenkins/package.nix +++ b/pkgs/by-name/je/jenkins/package.nix @@ -18,14 +18,14 @@ stdenvNoCC.mkDerivation (finalAttrs: { pname = "jenkins"; - version = "2.568.3"; + version = "2.580.1"; strictDeps = true; __structuredAttrs = true; src = fetchurl { url = "https://get.jenkins.io/war-stable/${finalAttrs.version}/jenkins.war"; - hash = "sha256-zNv9zq3oNInjQoWk1XwSE0/+oKCcogBiKC5YDL+l8J4="; + hash = "sha256-OTvyR2NS3XJlGf0fks5m6sfSPAk25pZ0ILcXBgxMQNA="; }; nativeBuildInputs = [ makeWrapper ]; diff --git a/pkgs/by-name/ku/kubectl-cnpg/package.nix b/pkgs/by-name/ku/kubectl-cnpg/package.nix index eb6a000dd6f2..6cb80600dd92 100644 --- a/pkgs/by-name/ku/kubectl-cnpg/package.nix +++ b/pkgs/by-name/ku/kubectl-cnpg/package.nix @@ -6,16 +6,16 @@ buildGoModule (finalAttrs: { pname = "kubectl-cnpg"; - version = "1.30.0"; + version = "1.30.1"; src = fetchFromGitHub { owner = "cloudnative-pg"; repo = "cloudnative-pg"; rev = "v${finalAttrs.version}"; - hash = "sha256-UHgllbD2eNBVYrF5nPZhethZIyyBkEji1xf0okGshoI="; + hash = "sha256-ZtIUtp4KwSxpqh97Hi9/8MnZfH3sGj3gNa0bwHF0FhM="; }; - vendorHash = "sha256-Eh057tW8NTCNVtgyeY4A+Cc8wQbRDpUYDFmj4l+pn8o="; + vendorHash = "sha256-ep8BezbZ/BM+s50v/sly+HotA9IHosHS6w3el0i4dps="; subPackages = [ "cmd/kubectl-cnpg" ]; diff --git a/pkgs/by-name/li/libslirp/package.nix b/pkgs/by-name/li/libslirp/package.nix index 2ab732529544..d531927e1799 100644 --- a/pkgs/by-name/li/libslirp/package.nix +++ b/pkgs/by-name/li/libslirp/package.nix @@ -10,14 +10,14 @@ stdenv.mkDerivation (finalAttrs: { pname = "libslirp"; - version = "4.9.3"; + version = "4.9.5"; src = fetchFromGitLab { domain = "gitlab.freedesktop.org"; owner = "slirp"; repo = "libslirp"; tag = "v${finalAttrs.version}"; - hash = "sha256-Spr3dO5ehuUlzx3EnJi8najANWOirwQcTsWTVRVXYuY="; + hash = "sha256-iWu3/Klsm8e9MH147BJhn9Vqyneq5ROqPvll1cnieL0="; }; separateDebugInfo = true; diff --git a/pkgs/by-name/lu/luwen/package.nix b/pkgs/by-name/lu/luwen/package.nix index 706f584d8d59..a91d05c01838 100644 --- a/pkgs/by-name/lu/luwen/package.nix +++ b/pkgs/by-name/lu/luwen/package.nix @@ -6,21 +6,21 @@ }: rustPlatform.buildRustPackage (finalAttrs: { pname = "luwen"; - version = "0.9.0"; + version = "0.10.0"; __structuredAttrs = true; src = fetchFromGitHub { owner = "tenstorrent"; repo = "luwen"; tag = "v${finalAttrs.version}"; - hash = "sha256-pc/7G9YxBTg2uYn47ONxI7zsfdK3Ex4zndLASRtDQyk="; + hash = "sha256-J0SvCBsDi3GMvnwqgqGMUDvrSO+baznDhsfuvF44Ens="; }; nativeBuildInputs = [ protobuf ]; - cargoHash = "sha256-2ibAZnfv++eyCB57F0uD7XFJ3MP9SnAApOn6uelo3Po="; + cargoHash = "sha256-vEuVxBGIJAyc8POy3EPTzTK5g5SE3QDZcnTnAb3b5k0="; meta = { description = "Tenstorrent system interface tools"; diff --git a/pkgs/by-name/ma/material-symbols/package.nix b/pkgs/by-name/ma/material-symbols/package.nix index e6cf43b8c55a..fb45becbb8db 100644 --- a/pkgs/by-name/ma/material-symbols/package.nix +++ b/pkgs/by-name/ma/material-symbols/package.nix @@ -7,13 +7,13 @@ }: stdenvNoCC.mkDerivation { pname = "material-symbols"; - version = "4.0.0-unstable-2026-06-12"; + version = "4.0.0-unstable-2026-09-25"; src = fetchFromGitHub { owner = "google"; repo = "material-design-icons"; - rev = "5d5d1fdd5476f3df3749e9fb872e32021ec7a750"; - hash = "sha256-e0bxJpehssgnxigSgPt9qxMrKRZcvlVDyLu5DY6MkTA="; + rev = "bd8cb85bd4bad964fe6918f79665bb40c3a8efef"; + hash = "sha256-JKGFoq2iZ1xzDGuxZERmDAP57+L75NltsLEc/l9+yd8="; sparseCheckout = [ "variablefont" ]; }; diff --git a/pkgs/by-name/no/node-core-utils/package.nix b/pkgs/by-name/no/node-core-utils/package.nix index 091781f0678e..4234a2eb47cc 100644 --- a/pkgs/by-name/no/node-core-utils/package.nix +++ b/pkgs/by-name/no/node-core-utils/package.nix @@ -9,16 +9,16 @@ buildNpmPackage (finalAttrs: { pname = "node-core-utils"; - version = "7.2.1"; + version = "7.3.1"; src = fetchFromGitHub { owner = "nodejs"; repo = "node-core-utils"; tag = "v${finalAttrs.version}"; - hash = "sha256-5RY4hXGbGyyUptDZhNIO/cDm7c4w4JaWLUfqRppJsp8="; + hash = "sha256-JvZ6/S9QYDPMrPsCAET1Q6P8gwblDyDpKicsYulUg4Y="; }; - npmDepsHash = "sha256-UTGun+Rt0wMCCtCjYzhYYLw9Y0XqEV93PuXnDwIg59k="; + npmDepsHash = "sha256-aE8KH+BQUu8D20DBvWJmr8RWCa85bHjAWEDNZ8l2okg="; dontNpmBuild = true; dontNpmPrune = true; diff --git a/pkgs/by-name/oa/oauth2l/package.nix b/pkgs/by-name/oa/oauth2l/package.nix index 654e560f468e..61300fb377b2 100644 --- a/pkgs/by-name/oa/oauth2l/package.nix +++ b/pkgs/by-name/oa/oauth2l/package.nix @@ -7,13 +7,13 @@ buildGoModule (finalAttrs: { pname = "oauth2l"; - version = "1.3.5"; + version = "1.3.6"; src = fetchFromGitHub { owner = "google"; repo = "oauth2l"; rev = "v${finalAttrs.version}"; - hash = "sha256-oRiR5x+9AGFeua4DvtNJQQ9DeuPSiNT6zUI91h4FdaI="; + hash = "sha256-d7TqolbWVoOw8caTyyPTW0S5AbC6YayDh/2LsjhB+SI="; }; vendorHash = null; diff --git a/pkgs/by-name/re/reaper/package.nix b/pkgs/by-name/re/reaper/package.nix index 7416c611b782..1f4ecf15feec 100644 --- a/pkgs/by-name/re/reaper/package.nix +++ b/pkgs/by-name/re/reaper/package.nix @@ -40,17 +40,17 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "reaper"; - version = "7.79"; + version = "7.81"; src = fetchurl { url = url_for_platform finalAttrs.version stdenv.hostPlatform.qemuArch; hash = if stdenv.hostPlatform.isDarwin then - "sha256-JJPOo81hBdhLvwJxAoDXPqihGfBjcBUnc0g3Z/rehgI=" + "sha256-z3ym5rqsymPBNbKdfifrqC2KSuRnwOR/VpGBSKc91iQ=" else { - x86_64-linux = "sha256-pCC0f8WhvvK6bsv0k3u2ewlDM/Daoxjf5wLV/NqjiEY="; - aarch64-linux = "sha256-5kQrlvyKsTxBErhcPH1niS7mKDuIP7dOPG2JoRYWcr4="; + x86_64-linux = "sha256-1WVIaKD08xowslG1T//DLKmsV42ZgV6HwAkD1Ln3iLk="; + aarch64-linux = "sha256-Bb/IVY1uundgUBytGvl9MtUZ5l7TWCbaw0MUIwYvBb4="; } .${stdenv.hostPlatform.system}; }; diff --git a/pkgs/by-name/ro/roon-server/package.nix b/pkgs/by-name/ro/roon-server/package.nix index 5eef70809318..2383cf8dcf4d 100644 --- a/pkgs/by-name/ro/roon-server/package.nix +++ b/pkgs/by-name/ro/roon-server/package.nix @@ -16,7 +16,7 @@ stdenv, }: let - version = "2.71.1683"; + version = "2.73.1696"; urlVersion = builtins.replaceStrings [ "." ] [ "0" ] version; in stdenv.mkDerivation { @@ -25,7 +25,7 @@ stdenv.mkDerivation { src = fetchurl { url = "https://download.roonlabs.com/updates/production/RoonServer_linuxx64_${urlVersion}.tar.bz2"; - hash = "sha256-z/8rORTsDUhgh2hfep62jMVeAvX/c5HW4vBkVnvhcQc="; + hash = "sha256-BD8qBJCsmpx24k003t5QXC658p3ofOSZtQCZHKOypvg="; }; dontConfigure = true; diff --git a/pkgs/by-name/rq/rqlite/package.nix b/pkgs/by-name/rq/rqlite/package.nix index 23f2e2227a5d..87a50140c2ef 100644 --- a/pkgs/by-name/rq/rqlite/package.nix +++ b/pkgs/by-name/rq/rqlite/package.nix @@ -12,13 +12,13 @@ buildGoModule ( in { pname = "rqlite"; - version = "10.3.6"; + version = "10.5.1"; src = fetchFromGitHub { owner = "rqlite"; repo = "rqlite"; tag = "v${finalAttrs.version}"; - hash = "sha256-ePOEmCXlkaAzWI8pWUohhnf5/1UAOqvAwfNZZ6UyXPI="; + hash = "sha256-XVAhhYhnRebtkJWqrXGRIPa0W5A36M92nSKGITnPt1s="; }; vendorHash = "sha256-TgmFYhUUC391JA2Na7k+fUlhSIABMmBQjyJsB5326VI="; diff --git a/pkgs/by-name/ru/ruff/package.nix b/pkgs/by-name/ru/ruff/package.nix index 427a3adacaae..40b9ffbd359f 100644 --- a/pkgs/by-name/ru/ruff/package.nix +++ b/pkgs/by-name/ru/ruff/package.nix @@ -16,7 +16,7 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "ruff"; - version = "0.16.8"; + version = "0.16.10"; __structuredAttrs = true; @@ -24,12 +24,12 @@ rustPlatform.buildRustPackage (finalAttrs: { owner = "astral-sh"; repo = "ruff"; tag = finalAttrs.version; - hash = "sha256-vfyEulokZqx5VyQA3jlKhQhgr/flLIGHcgC7CeegGl0="; + hash = "sha256-k06KqlFRQju6bDbZboPaqEqzWY0Fw3BBKmzb8Vk4G24="; }; cargoBuildFlags = [ "--package=ruff" ]; - cargoHash = "sha256-aX9Vu1egtvloe9dspXHR0Amc0mEuWG67EAOQU2b3oM0="; + cargoHash = "sha256-rwI+8VxGo7W5ol6FfhKaxRjogbwx6tcYlHEgEuMJXCs="; nativeBuildInputs = [ installShellFiles ]; diff --git a/pkgs/by-name/se/servo/package.nix b/pkgs/by-name/se/servo/package.nix index 1f2b79ea74b1..907d8d3da0f3 100644 --- a/pkgs/by-name/se/servo/package.nix +++ b/pkgs/by-name/se/servo/package.nix @@ -101,6 +101,19 @@ rustPlatform.buildRustPackage (finalAttrs: { for mozjs_dir in $cargoDepsCopy/*/mozjs_*/; do cp Cargo.lock $mozjs_dir done + '' + + lib.optionalString stdenv.hostPlatform.isDarwin '' + # The nix cc wrapper prints a warning to stderr when it receives a `--target` + # that differs from its default one. + # cc-rs probes whether a flag is supported by compiling a test file and + # treats any stderr output as unsupported, so every `flag_if_supported` + # flag is silently dropped, including `-fno-rtti` for mozjs-sys jsglue: + # https://github.com/servo/mozjs/blob/de3c7bdc1178274c31bedccf60ae04a3ff5c0619/mozjs-sys/build.rs#L572 + # https://github.com/rust-lang/cc-rs/blob/c619f08c5f270c3f153fd3bce20540d2422d1356/src/lib.rs#L1748 + # Compiling jsglue with RTTI while SpiderMonkey is built without results + # in a linker error. + substituteInPlace $cargoDepsCopy/*/cc-1.*/src/lib.rs \ + --replace-fail '"--target={clang_target}"' '"--target=${stdenv.hostPlatform.config}"' ''; # set `HOME` to a temp dir for write access @@ -130,8 +143,6 @@ rustPlatform.buildRustPackage (finalAttrs: { yasm ]; - env.UV_PYTHON = customPython.interpreter; - buildInputs = [ fontconfig freetype @@ -153,23 +164,28 @@ rustPlatform.buildRustPackage (finalAttrs: { vulkan-loader ]; - env.NIX_CFLAGS_COMPILE = toString ( - [ - # mozjs-sys fails with: - # cc1plus: error: '-Wformat-security' ignored without '-Wformat' - "-Wno-error=format-security" - ] - ++ lib.optionals stdenv.hostPlatform.isDarwin [ - "-I${lib.getInclude stdenv.cc.libcxx}/include/c++/v1" - ] - ); + env = { + UV_PYTHON = customPython.interpreter; + + NIX_CFLAGS_COMPILE = toString ( + [ + # mozjs-sys fails with: + # cc1plus: error: '-Wformat-security' ignored without '-Wformat' + "-Wno-error=format-security" + ] + ++ lib.optionals stdenv.hostPlatform.isDarwin [ + "-I${lib.getInclude stdenv.cc.libcxx}/include/c++/v1" + ] + ); + }; # copy resources into `$out` to be used during runtime - # link runtime libraries postFixup = '' mkdir -p $out/resources cp -r ./resources $out/ - + '' + # link runtime libraries + + lib.optionalString stdenv.hostPlatform.isLinux '' wrapProgram $out/bin/servoshell \ --prefix LD_LIBRARY_PATH : ${runtimePaths} ''; @@ -180,8 +196,6 @@ rustPlatform.buildRustPackage (finalAttrs: { }; meta = { - # undefined libmozjs_sys symbols during linking - broken = stdenv.hostPlatform.isDarwin; changelog = "https://github.com/servo/servo/releases/tag/${finalAttrs.src.tag}"; description = "Embeddable, independent, memory-safe, modular, parallel web rendering engine"; homepage = "https://servo.org"; diff --git a/pkgs/by-name/si/silverbullet/package.nix b/pkgs/by-name/si/silverbullet/package.nix index b445e8420889..869105dadb39 100644 --- a/pkgs/by-name/si/silverbullet/package.nix +++ b/pkgs/by-name/si/silverbullet/package.nix @@ -9,13 +9,13 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "silverbullet"; - version = "2.11.0"; + version = "2.11.1"; src = fetchFromGitHub { owner = "silverbulletmd"; repo = "silverbullet"; rev = finalAttrs.version; - hash = "sha256-aEqmvxtWzvXM8Cv8YrHK9o0G2jlbeqqahAveKr6M+Ps="; + hash = "sha256-+8q0gQ4pRdGHPE7woH/+cteLoUQ5qhEIGI+AhwkXN5E="; }; cargoHash = "sha256-t2RDrdZsCMReDGUUu3r59OAosZNY3TMlvjo/uM2xL8g="; @@ -30,7 +30,7 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "silverbullet-frontend"; inherit (finalAttrs) version src; - npmDepsHash = "sha256-EseKAqUJbpIAfJhG1hNlvLgMie/jsXbbVqwea8bEuJQ="; + npmDepsHash = "sha256-IALStufO5TwhQbkIgSqwTYcQAL7Q+vmLDjlVYzMTyCA="; patches = [ (replaceVars ./override-version.patch { inherit (finalAttrs) version; }) diff --git a/pkgs/by-name/te/texlyre/package.nix b/pkgs/by-name/te/texlyre/package.nix index e6177983f10b..c931b775ac4c 100644 --- a/pkgs/by-name/te/texlyre/package.nix +++ b/pkgs/by-name/te/texlyre/package.nix @@ -13,16 +13,16 @@ buildNpmPackage (finalAttrs: { pname = "texlyre"; - version = "0.12.0"; + version = "0.13.0"; src = fetchFromGitHub { owner = "TeXlyre"; repo = "texlyre"; tag = "v${finalAttrs.version}"; - hash = "sha256-lMXnlH54V2DEDV23TCSebh+xCzTZHqy5PtIj1FYbRWA="; + hash = "sha256-oYt+DG8lTAOY8MEZsJw2nkg7LGE/hEY7nw5UT9EQfZU="; }; - npmDepsHash = "sha256-Dvw4RSEWlTJfrNL+pgMsX1a0yihM+bKnRqFqeSSR454="; + npmDepsHash = "sha256-MlxMej9huxgC73FUG8iifkxUnJHFWS9y50NaZ4C+aBE="; postPatch = '' sed -i 's/"version": ".*"/"version": "${finalAttrs.version}"/' package.json @@ -71,12 +71,12 @@ buildNpmPackage (finalAttrs: { updateScript = ./update.sh; drawioEmbed = stdenvNoCC.mkDerivation (finalAttrs: { pname = "drawio-embed"; - version = "31.4.4"; + version = "31.6.1"; src = fetchFromGitHub { owner = "TeXlyre"; repo = "drawio-embed-mirror"; tag = "v${finalAttrs.version}"; - hash = "sha256-RcaoHnzXJq5ayL6e7vWPECjNbavDvKcRbLmToxsyz8E="; + hash = "sha256-lcttcu7N61ZoKGQgUPn7l7yRF8MXmO0tD9uzJ1V9Z94="; }; dontBuild = true; installPhase = "cp -a . $out"; diff --git a/pkgs/by-name/th/throttled/package.nix b/pkgs/by-name/th/throttled/package.nix index 4d8736e28d0c..216073bde8c3 100644 --- a/pkgs/by-name/th/throttled/package.nix +++ b/pkgs/by-name/th/throttled/package.nix @@ -2,63 +2,59 @@ lib, stdenv, fetchFromGitHub, - gobject-introspection, python3Packages, pciutils, - wrapGAppsNoGuiHook, + versionCheckHook, }: stdenv.mkDerivation (finalAttrs: { pname = "throttled"; - version = "0.11"; + version = "0.12.2"; src = fetchFromGitHub { owner = "erpalma"; repo = "throttled"; - rev = "v${finalAttrs.version}"; - sha256 = "sha256-+3ktDkr5hvOfHcch4+mjgJqcuw24UgWTkJqTyDQumyk="; + tag = "v${finalAttrs.version}"; + hash = "sha256-hwnJO9KEDOizpGcb9NYHYHoEEHKa3PkLt76cKpwgEUs="; }; - nativeBuildInputs = [ - gobject-introspection - python3Packages.wrapPython - wrapGAppsNoGuiHook - ]; + nativeBuildInputs = [ python3Packages.wrapPython ]; - pythonPath = with python3Packages; [ - configparser - dbus-python - pygobject3 - ]; + pythonPath = [ python3Packages.dbus-fast ]; - # The upstream unit both assumes the install location, and tries to run in a virtualenv + # The upstream unit assumes the /opt/throttled venv install location postPatch = '' - sed -e 's|ExecStart=.*|ExecStart=${placeholder "out"}/bin/throttled.py|' -i systemd/throttled.service + substituteInPlace systemd/throttled.service \ + --replace-fail '/opt/throttled/venv/bin/throttled' \ + '${placeholder "out"}/bin/throttled.py' - substituteInPlace throttled.py --replace "'setpci'" "'${pciutils}/bin/setpci'" + substituteInPlace throttled.py --replace-fail "'setpci'" "'${lib.getExe' pciutils "setpci"}'" ''; installPhase = '' runHook preInstall + install -D -m755 -t $out/bin throttled.py - install -D -t $out/bin throttled.py mmio.py + install -D -m644 -t $out/${python3Packages.python.sitePackages} mmio.py throttled_version.py install -D -m644 -t $out/etc etc/* install -D -m644 -t $out/lib/systemd/system systemd/* + runHook postInstall ''; - dontWrapGApps = true; - - preFixup = '' - makeWrapperArgs+=("''${gappsWrapperArgs[@]}") - ''; - postFixup = "wrapPythonPrograms"; + nativeInstallCheckInputs = [ versionCheckHook ]; + doInstallCheck = true; + env.PYTHONDONTWRITEBYTECODE = "1"; + versionCheckKeepEnvironment = "PYTHONDONTWRITEBYTECODE"; + meta = { description = "Fix for Intel CPU throttling issues"; homepage = "https://github.com/erpalma/throttled"; + changelog = "https://github.com/erpalma/throttled/releases/tag/${finalAttrs.src.tag}"; license = lib.licenses.mit; + mainProgram = "throttled.py"; platforms = [ "x86_64-linux" ]; maintainers = [ ]; }; diff --git a/pkgs/by-name/to/tombi/package.nix b/pkgs/by-name/to/tombi/package.nix index f488c823fbaf..6753e994a974 100644 --- a/pkgs/by-name/to/tombi/package.nix +++ b/pkgs/by-name/to/tombi/package.nix @@ -9,7 +9,7 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "tombi"; - version = "1.5.2"; + version = "1.7.1"; __structuredAttrs = true; @@ -17,7 +17,7 @@ rustPlatform.buildRustPackage (finalAttrs: { owner = "tombi-toml"; repo = "tombi"; tag = "v${finalAttrs.version}"; - hash = "sha256-HMAyzISP/q+eBAPPg/8FHa6eQ4xbA8sHne1dm+veUyo="; + hash = "sha256-eeBtmMrkDWOADw7FMLLD8hYq5WYg/aFyATtYIMFYFk0="; }; # Tests relies on the presence of network @@ -26,7 +26,7 @@ rustPlatform.buildRustPackage (finalAttrs: { "--package" "tombi-cli" ]; - cargoHash = "sha256-9x7Qesl6OsiN79b1MqP5BMF/0VOymER57ijwHzs0Taw="; + cargoHash = "sha256-YJLhWIwB3Y8836Rq4ahRzBSnhp7bH8w2/oXfRVTOPXg="; postPatch = '' substituteInPlace Cargo.toml \ diff --git a/pkgs/by-name/ut/ut2004/data.nix b/pkgs/by-name/ut/ut2004/data.nix new file mode 100644 index 000000000000..05117acd2b9a --- /dev/null +++ b/pkgs/by-name/ut/ut2004/data.nix @@ -0,0 +1,50 @@ +{ + fetchurl, + lib, + libarchive, + stdenv, + unshield, + ut2004Packages, +}: + +stdenv.mkDerivation (finalAttrs: { + name = "ut2004-data"; + + __structuredAttrs = true; + strictDeps = true; + + nativeBuildInputs = [ + libarchive + unshield + ]; + + unpackPhase = '' + runHook preUnpack + + mkdir cabs + bsdtar -xvf "${ut2004Packages.image}/ut2004.iso" -C cabs --strip-components 1 'Disk?/*.cab' 'Disk?/*.hdr' + unshield -d data x cabs/data1.cab + + runHook postUnpack + ''; + + installPhase = '' + runHook preInstall + + mv data $out + + runHook preInstall + ''; + + meta = { + description = "Unreal Tournament 2004 CD content provided by OldUnreal"; + homepage = "https://oldunreal.com/downloads/ut2004/"; + license = lib.licenses.unfree; + maintainers = with lib.maintainers; [ corps-fini ]; + platforms = [ + "aarch64-linux" + "x86_64-linux" + ]; + sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ]; + }; +}) diff --git a/pkgs/by-name/ut/ut2004/game.nix b/pkgs/by-name/ut/ut2004/game.nix new file mode 100644 index 000000000000..5592495bc96d --- /dev/null +++ b/pkgs/by-name/ut/ut2004/game.nix @@ -0,0 +1,173 @@ +{ + autoPatchelfHook, + copyDesktopItems, + fetchurl, + imagemagick, + lib, + libGL, + libarchive, + makeDesktopItem, + openal, + sdl3, + stdenv, + ut2004Packages, +}: + +let + gameData = ut2004Packages.data; + patch-version = "3374-preview-23"; + systemDir = + { + aarch64-linux = "SystemARM64"; + x86_64-linux = "System"; + } + .${stdenv.hostPlatform.system} or (throw "Unsupported platform: ${stdenv.hostPlatform.system}"); +in +stdenv.mkDerivation (finalAttrs: { + pname = "ut2004"; + version = patch-version; + + __structuredAttrs = true; + strictDeps = true; + + src = fetchurl { + url = "https://github.com/OldUnreal/UT2004Patches/releases/download/${patch-version}/OldUnreal-UT2004Patch3374-Linux-094b94dc.tar.bz2"; + hash = "sha256-F56kPIgxv/FHAFhQzTc8DsK3Dc9vhBwhCcFSXvEa1NM="; + }; + + buildInputs = [ + gameData + libGL + openal + sdl3 + ]; + + nativeBuildInputs = [ + autoPatchelfHook + copyDesktopItems + imagemagick + libarchive + ]; + + unpackPhase = '' + runHook preUnpack + + # Install files to their (relative) final location. + # https://github.com/OldUnreal/FullGameInstallers/blob/748525188b80f47138f19af6c8c6899230cb214e/Linux/install-ut2004.sh#L2087-L2155. + mkdir -p ut2004/System + + for folder in Animations Benchmark ForceFeedback Help KarmaData Maps Music StaticMeshes Textures Web; do + cp --no-preserve=mode -vrs ${gameData}/"All_$folder" ut2004/"$folder" + done + + cp --no-preserve=mode -vrs ${gameData}/English_Manual ut2004/Manual + cp --no-preserve=mode -vrs ${gameData}/English_Sounds_Speech_System_Help/Sounds ut2004 + cp --no-preserve=mode -vrs ${gameData}/English_Sounds_Speech_System_Help/Speech ut2004 + + cp --no-preserve=mode -vrs ${gameData}/All_UT2004.EXE/* ut2004/System + cp --no-preserve=mode -vrs ${gameData}/English_Sounds_Speech_System_Help/Help/* ut2004/Help + cp --no-preserve=mode -vrs ${gameData}/English_Sounds_Speech_System_Help/System/* ut2004/System + cp --no-preserve=mode -vrs ${gameData}/US_License.int ut2004/System + + # Patch. + bsdtar --unlink-first -xf "$src" -C ut2004 + + # Remove files superseded by the patch. + # https://github.com/OldUnreal/FullGameInstallers/blob/748525188b80f47138f19af6c8c6899230cb214e/Linux/install-ut2004.sh#L2169-L2194 + rm -v -- ut2004/System/{StreamLineFX,XVoting}.u + + # Remove windows files. + # https://github.com/OldUnreal/FullGameInstallers/blob/748525188b80f47138f19af6c8c6899230cb214e/Linux/install-ut2004.sh#L2087-L2155. + rm -v -- ut2004/System/*.bat + rm -v -- ut2004/System/*.dll + rm -v -- ut2004/System/*.exe + + # Remove unused architectures. + if [ "${systemDir}" != System ]; then + rm -v -- ut2004/System/*.so + rm -v -- ut2004/System/{UT2004,ut2004-bin,ut2004-bin-amd64} + rm -v -- ut2004/System/{UCC,ucc-bin,ucc-bin-amd64} + fi + for dir in SystemARM64 SystemPPC64LE; do + if [ "${systemDir}" != "$dir" ]; then + rm -rfv -- ut2004/"$dir" + fi + done + + # Use system dependencies. + rm -v -- ut2004/${systemDir}/libopenal.so.1 + rm -v -- ut2004/${systemDir}/libopenal.so.1.* + rm -v -- ut2004/${systemDir}/libSDL3.so.0 + rm -v -- ut2004/${systemDir}/libSDL3.so.0.* + + # Make icons. + # identify Unreal.ico + # Unreal.ico[0] ICO 48x48 48x48+0+0 4-bit sRGB 0.000u 0:00.000 + # Unreal.ico[1] ICO 32x32 32x32+0+0 4-bit sRGB 0.000u 0:00.000 + # Unreal.ico[2] ICO 16x16 16x16+0+0 4-bit sRGB 0.000u 0:00.000 + # Unreal.ico[3] ICO 48x48 48x48+0+0 8-bit sRGB 0.000u 0:00.000 + # Unreal.ico[4] ICO 32x32 32x32+0+0 8-bit sRGB 0.000u 0:00.000 + # Unreal.ico[5] ICO 16x16 16x16+0+0 8-bit sRGB 0.000u 0:00.000 + # Unreal.ico[6] ICO 48x48 48x48+0+0 8-bit sRGB 0.000u 0:00.000 + # Unreal.ico[7] ICO 32x32 32x32+0+0 8-bit sRGB 24070B 0.000u 0:00.000 + icon_src=ut2004/Help/Unreal.ico + mkdir -p icons/hicolor/{16x16,32x32,48x48} + magick -background none "$icon_src[5]" icons/hicolor/16x16/ut2004.png + magick -background none "$icon_src[7]" icons/hicolor/32x32/ut2004.png + magick -background none "$icon_src[6]" icons/hicolor/48x48/ut2004.png + + runHook postUnpack + ''; + + installPhase = '' + runHook preInstall + + # Install game data. + mkdir -p "$out"/opt + mv ut2004 "$out"/opt + + # Install icons. + mkdir -p "$out"/share + mv icons "$out"/share + + # Install binaries. + mkdir -p "$out"/bin + ln -s "$out"/opt/ut2004/${systemDir}/ut2004-bin "$out"/bin/ut2004 + ln -s "$out"/opt/ut2004/${systemDir}/ucc-bin "$out"/bin/ut2004-ucc + + runHook postInstall + ''; + + appendRunpaths = [ + "${placeholder "out"}/opt/ut2004/System" + ]; + + desktopItems = [ + (makeDesktopItem { + name = "ut2004"; + desktopName = "Unreal Tournament 2004"; + comment = "Unreal Tournament 2004 with OldUnreal patch ${patch-version}"; + exec = "ut2004"; + icon = "ut2004"; + categories = [ "Game" ]; + }) + ]; + + meta = { + description = "First-person arena shooter"; + longDescription = '' + Unreal Tournament 2004 with OldUnreal patch ${patch-version}. + Pin ut2004Packages.image to avoid downloading the disc image when build tools are updated (for example libarchive) at the cost of extra disk space. + To save disk space, pin ut2004Packages.data instead of ut2004Packages.image to avoid downloading the disc image when the patch is updated. + ''; + homepage = "https://oldunreal.com/downloads/ut2004/"; + license = lib.licenses.unfree; + maintainers = with lib.maintainers; [ corps-fini ]; + mainProgram = "ut2004"; + platforms = [ + "aarch64-linux" + "x86_64-linux" + ]; + sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ]; + }; +}) diff --git a/pkgs/by-name/ut/ut2004/image.nix b/pkgs/by-name/ut/ut2004/image.nix new file mode 100644 index 000000000000..ed82a8326f49 --- /dev/null +++ b/pkgs/by-name/ut/ut2004/image.nix @@ -0,0 +1,40 @@ +{ + fetchurl, + lib, + stdenvNoCC, +}: + +stdenvNoCC.mkDerivation (finalAttrs: { + name = "ut2004-image"; + + src = fetchurl { + urls = [ + "https://files.oldunreal.net/UT2004.ISO" + "https://files2.oldunreal.net/UT2004.ISO" + "https://files3.oldunreal.net/UT2004.ISO" + ]; + hash = "sha256-Q+kYKuILy8D29FiP7mwbM2wmHxRlQDEYoZc7CbGiJUE="; + }; + + dontUnpack = true; + + installPhase = '' + runHook preInstall + + install -D $src $out/ut2004.iso + + runHook postInstall + ''; + + meta = { + description = "Unreal Tournament 2004 CD image provided by OldUnreal"; + homepage = "https://oldunreal.com/downloads/ut2004/"; + license = lib.licenses.unfree; + maintainers = with lib.maintainers; [ corps-fini ]; + platforms = [ + "aarch64-linux" + "x86_64-linux" + ]; + sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ]; + }; +}) diff --git a/pkgs/by-name/ut/ut2004/package.nix b/pkgs/by-name/ut/ut2004/package.nix new file mode 100644 index 000000000000..c8ef28de5614 --- /dev/null +++ b/pkgs/by-name/ut/ut2004/package.nix @@ -0,0 +1,3 @@ +{ ut2004Packages }: + +ut2004Packages.game diff --git a/pkgs/by-name/ut/ut2004/packages.nix b/pkgs/by-name/ut/ut2004/packages.nix new file mode 100644 index 000000000000..4a57e1792a11 --- /dev/null +++ b/pkgs/by-name/ut/ut2004/packages.nix @@ -0,0 +1,10 @@ +{ + lib, + newScope, +}: + +lib.makeScope newScope (self: { + image = self.callPackage ./image.nix { }; + data = self.callPackage ./data.nix { }; + game = self.callPackage ./game.nix { }; +}) diff --git a/pkgs/by-name/vi/victoriametrics/package.nix b/pkgs/by-name/vi/victoriametrics/package.nix index 4bbb48639808..c57e0e2cc8ac 100644 --- a/pkgs/by-name/vi/victoriametrics/package.nix +++ b/pkgs/by-name/vi/victoriametrics/package.nix @@ -24,7 +24,8 @@ buildGo127Module (finalAttrs: { }; vendorHash = null; - env.CGO_ENABLED = 0; + # cgo enabled to work around https://github.com/VictoriaMetrics/VictoriaMetrics/issues/11683 + env.CGO_ENABLED = 1; subPackages = lib.optionals withServer [ diff --git a/pkgs/by-name/wa/wastebin/package.nix b/pkgs/by-name/wa/wastebin/package.nix index 6e00e9b415f5..71bcec3ca17d 100644 --- a/pkgs/by-name/wa/wastebin/package.nix +++ b/pkgs/by-name/wa/wastebin/package.nix @@ -10,16 +10,16 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "wastebin"; - version = "3.7.2"; + version = "3.8.0"; src = fetchFromGitHub { owner = "matze"; repo = "wastebin"; rev = finalAttrs.version; - hash = "sha256-IzrwFiLJfvFKHdYaDmaYYwdBUlQed9WEy/7OBvlAUTQ="; + hash = "sha256-ybKa6ZkQek9S0Zjz/lRODzjWvzTTu+PtfMrnYu+Nzrs="; }; - cargoHash = "sha256-tq2Hc5CAp5Cp6AYS/NGb0HEtvm+lH8qak+M8toksDF4="; + cargoHash = "sha256-hdu+t3xdS7KYcos6N1EkygCoAdaUOowldb0NGEOPtSQ="; nativeBuildInputs = [ pkg-config diff --git a/pkgs/by-name/we/webkitgtk_6_0/package.nix b/pkgs/by-name/we/webkitgtk_6_0/package.nix index 925c2df29d72..71d9fa3be1d0 100644 --- a/pkgs/by-name/we/webkitgtk_6_0/package.nix +++ b/pkgs/by-name/we/webkitgtk_6_0/package.nix @@ -72,6 +72,7 @@ withLibsecret ? true, systemdSupport ? lib.meta.availableOn clangStdenv.hostPlatform systemdLibs, testers, + directoryListingUpdater, fetchpatch, }: @@ -82,7 +83,7 @@ in # https://webkitgtk.org/2024/10/04/webkitgtk-2.46.html recommends building with clang. clangStdenv.mkDerivation (finalAttrs: { pname = "webkitgtk"; - version = "2.54.0"; + version = "2.54.1"; name = "webkitgtk-${finalAttrs.version}+abi=${abiVersion}"; outputs = [ @@ -97,7 +98,7 @@ clangStdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "https://webkitgtk.org/releases/webkitgtk-${finalAttrs.version}.tar.xz"; - hash = "sha256-hG/RnM7brh2/6QTybb8taKgAozpQyvKtUiLI3LPyVoI="; + hash = "sha256-6gu7AtvbxZaHSk5601tmZFs+CiMr0OQIHeXtkusKOX0="; }; patches = lib.optionals clangStdenv.hostPlatform.isLinux [ @@ -114,15 +115,6 @@ clangStdenv.mkDerivation (finalAttrs: { hash = "sha256-MgaSpXq9l6KCLQdQyel6bQFHG53l3GY277WePpYXdjA="; name = "fix_ftbfs_riscv64.patch"; }) - - # Fix https://bugs.webkit.org/show_bug.cgi?id=322394 - # Upstream PR: https://github.com/WebKit/WebKit/pull/74512 - # Fetching the patch vendored by gnome-build-meta because the upstream - # patch doesn't apply. - (fetchpatch { - url = "https://gitlab.gnome.org/GNOME/gnome-build-meta/-/raw/7e4afe649fa1acbe9203004ad8fe1749c26e619d/patches/webkitgtk/main-thread.patch"; - hash = "sha256-Dm6Yytt4mQy7qxSWiudGBqfQUVJRhNAc1n+o/NMR1cg="; - }) ]; nativeBuildInputs = [ @@ -261,7 +253,10 @@ clangStdenv.mkDerivation (finalAttrs: { requiredSystemFeatures = [ "big-parallel" ]; - passthru.tests.pkg-config = testers.testMetaPkgConfig finalAttrs.finalPackage; + passthru = { + tests.pkg-config = testers.testMetaPkgConfig finalAttrs.finalPackage; + updateScript = directoryListingUpdater { }; + }; meta = { description = "Web content rendering engine, GTK port"; diff --git a/pkgs/development/python-modules/astropy-helpers/default.nix b/pkgs/development/python-modules/astropy-helpers/default.nix index f0938e83a7ab..2b0539e5cf73 100644 --- a/pkgs/development/python-modules/astropy-helpers/default.nix +++ b/pkgs/development/python-modules/astropy-helpers/default.nix @@ -3,6 +3,7 @@ buildPythonPackage, fetchFromGitHub, setuptools, + pkg-resources-backport, }: buildPythonPackage rec { @@ -22,7 +23,10 @@ buildPythonPackage rec { ./python-imp.patch ]; - build-system = [ setuptools ]; + build-system = [ + setuptools + pkg-resources-backport + ]; pythonImportsCheck = [ "astropy_helpers" ]; diff --git a/pkgs/development/python-modules/awsiotpythonsdk/default.nix b/pkgs/development/python-modules/awsiotpythonsdk/default.nix index fe2062ff4b63..a413c43669a6 100644 --- a/pkgs/development/python-modules/awsiotpythonsdk/default.nix +++ b/pkgs/development/python-modules/awsiotpythonsdk/default.nix @@ -7,14 +7,14 @@ buildPythonPackage (finalAttrs: { pname = "awsiotpythonsdk"; - version = "1.6.1"; + version = "1.6.2"; pyproject = true; src = fetchFromGitHub { owner = "aws"; repo = "aws-iot-device-sdk-python"; tag = "v${finalAttrs.version}"; - hash = "sha256-AppoO/9OZxcGUUivbV++pr0QfDLrteSO3cRMj8Gvmk8="; + hash = "sha256-attzolHwUbAc6JBVmG0i16lwf3i6K1n/TufgnJgT1U0="; }; postPatch = '' diff --git a/pkgs/development/python-modules/boto3-stubs/default.nix b/pkgs/development/python-modules/boto3-stubs/default.nix index 506a8718cd69..f4d1c1b98b87 100644 --- a/pkgs/development/python-modules/boto3-stubs/default.nix +++ b/pkgs/development/python-modules/boto3-stubs/default.nix @@ -358,13 +358,13 @@ buildPythonPackage (finalAttrs: { pname = "boto3-stubs"; - version = "1.43.107"; + version = "1.43.108"; pyproject = true; src = fetchPypi { pname = "boto3_stubs"; inherit (finalAttrs) version; - hash = "sha256-+MPGb7uDgyVMTnbfcWS4MBdPVPQKdAZqtjjd7rBynWM="; + hash = "sha256-oe0ptMeVdWjmJh/DbUxZAlwASZeiKejwGUDCBfISjko="; }; build-system = [ setuptools ]; diff --git a/pkgs/development/python-modules/cuda-cccl/default.nix b/pkgs/development/python-modules/cuda-cccl/default.nix index 92785a0ea478..fc6d067b7a45 100644 --- a/pkgs/development/python-modules/cuda-cccl/default.nix +++ b/pkgs/development/python-modules/cuda-cccl/default.nix @@ -30,7 +30,7 @@ buildPythonPackage.override { stdenv = cudaPackages.backendStdenv; } (finalAttrs: { pname = "cuda-cccl"; - version = "1.2.0"; + version = "1.2.1"; pyproject = true; __structuredAttrs = true; @@ -38,7 +38,7 @@ buildPythonPackage.override { stdenv = cudaPackages.backendStdenv; } (finalAttrs owner = "NVIDIA"; repo = "cccl"; tag = "python-${finalAttrs.version}"; - hash = "sha256-0Qsf3l9VvSxYVVWQG0ST7S33s7LdsNyWoV6Q2f0Ru6o="; + hash = "sha256-GyZD6YGqZNS3HDuhv0Y286LtisqqxHLr8SlGee5rXlw="; }; sourceRoot = "${finalAttrs.src.name}/python/cuda_cccl"; diff --git a/pkgs/development/python-modules/disposable-email-domains/default.nix b/pkgs/development/python-modules/disposable-email-domains/default.nix index 1ae2b137caf7..2944a38fdaa0 100644 --- a/pkgs/development/python-modules/disposable-email-domains/default.nix +++ b/pkgs/development/python-modules/disposable-email-domains/default.nix @@ -8,7 +8,7 @@ buildPythonPackage (finalAttrs: { pname = "disposable-email-domains"; - version = "0.0.242"; + version = "0.0.272"; pyproject = true; __structuredAttrs = true; @@ -16,7 +16,7 @@ buildPythonPackage (finalAttrs: { src = fetchPypi { pname = "disposable_email_domains"; inherit (finalAttrs) version; - hash = "sha256-nQyqKT6x72UgI/1HeWD/9bl16IHPH286ZGk9Mr2LEto="; + hash = "sha256-qB7Cr2PN4tj90mrWp5zazAXQb/sWfz4ySSKkQ4zen2c="; }; build-system = [ diff --git a/pkgs/development/python-modules/iamdata/default.nix b/pkgs/development/python-modules/iamdata/default.nix index b4cdbb0db95d..0c82c258f573 100644 --- a/pkgs/development/python-modules/iamdata/default.nix +++ b/pkgs/development/python-modules/iamdata/default.nix @@ -8,14 +8,14 @@ buildPythonPackage (finalAttrs: { pname = "iamdata"; - version = "0.1.202610011"; + version = "0.1.202610031"; pyproject = true; src = fetchFromGitHub { owner = "cloud-copilot"; repo = "iam-data-python"; tag = "v${finalAttrs.version}"; - hash = "sha256-wWSTLmp3jc7SiuefXUKPXLlOiIXgqtG1puaBkh/fr34="; + hash = "sha256-x3AUWiWjXLYl/lLpMPBqc/Vyh8CZzZJSQHElLhutIXc="; }; __darwinAllowLocalNetworking = true; diff --git a/pkgs/development/python-modules/jupyter-docprovider/default.nix b/pkgs/development/python-modules/jupyter-docprovider/default.nix index 5f96d8e010f1..5589acdb03f7 100644 --- a/pkgs/development/python-modules/jupyter-docprovider/default.nix +++ b/pkgs/development/python-modules/jupyter-docprovider/default.nix @@ -14,14 +14,14 @@ buildPythonPackage (finalAttrs: { pname = "jupyter-docprovider"; - version = "3.0.3"; + version = "3.0.4"; pyproject = true; __structuredAttrs = true; src = fetchPypi { pname = "jupyter_docprovider"; inherit (finalAttrs) version; - hash = "sha256-bY6eQ5XdTj2WLM3oyN9s8pmnPQsMNbvlZKn+YaeVtWY="; + hash = "sha256-yO49NbuaWAOFZBPkR7G5vYDOF7J6xtLaYj4cpER/LIw="; }; build-system = [ diff --git a/pkgs/development/python-modules/mhcflurry/default.nix b/pkgs/development/python-modules/mhcflurry/default.nix index c83aee4678b2..d8f9f2d27455 100644 --- a/pkgs/development/python-modules/mhcflurry/default.nix +++ b/pkgs/development/python-modules/mhcflurry/default.nix @@ -29,7 +29,7 @@ buildPythonPackage (finalAttrs: { pname = "mhcflurry"; - version = "2.3.8"; + version = "2.3.13"; pyproject = true; __structuredAttrs = true; @@ -37,7 +37,7 @@ buildPythonPackage (finalAttrs: { owner = "openvax"; repo = "mhcflurry"; tag = finalAttrs.version; - hash = "sha256-W9tNI1MC1SJ5RUT/Ahc/NOycU7p04+MeKazt+G8e3qg="; + hash = "sha256-G0lgTdeBVE1+ZTAJyP8XpYLkTZoKQGs2h/pVVkxsGOA="; }; build-system = [ @@ -118,6 +118,10 @@ buildPythonPackage (finalAttrs: { # (`#!/usr/bin/env python3` shebang) "test_eval_paper_figures_external_predictors_adds_columns" + # Flaky: relies on `os.utime(path, None)` producing a strictly newer mtime than a file + # written just before, which fails with coarse filesystem timestamps (seen on aarch64-linux) + "test_interrupted_dual_format_calibration_loads_the_newer_file" + # Release tooling: requires the source tree to be a git checkout "test_brev_postprocess_archive_includes_release_holdout" "test_deploy_creates_draft_noninteractively_with_release_notes" diff --git a/pkgs/development/python-modules/mypy-boto3/default.nix b/pkgs/development/python-modules/mypy-boto3/default.nix index a9e736b8ed66..c3aabb1f4cc1 100644 --- a/pkgs/development/python-modules/mypy-boto3/default.nix +++ b/pkgs/development/python-modules/mypy-boto3/default.nix @@ -311,8 +311,8 @@ in "sha256-CavBKgp+dEMR2poR+bG2PgZb+wX1zlNmuOyJsV3LfVM="; mypy-boto3-cognito-idp = - buildMypyBoto3Package "cognito-idp" "1.43.83" - "sha256-M48OOjCyaCfwjFOIkxhae9E7ZOVf+1MeikfNqsxtuOY="; + buildMypyBoto3Package "cognito-idp" "1.43.108" + "sha256-eHDyQQSd8cgHsQrAbWL9dRSDgCFyQ14pejbIl7fe4d4="; mypy-boto3-cognito-sync = buildMypyBoto3Package "cognito-sync" "1.43.0" @@ -571,8 +571,8 @@ in "sha256-wf3aeGNU4zu7+6Y3ajm2y8gqRcVaWkZHk/QVK2/1TW0="; mypy-boto3-glue = - buildMypyBoto3Package "glue" "1.43.106" - "sha256-pp5S3LCMmBwXzr2Gqj7cPlVTT4bD5U1w4LvmwTckzIA="; + buildMypyBoto3Package "glue" "1.43.108" + "sha256-U3Q3+vxDO30yAzQuKypqcXuCl0UKEilMm0ZCUweU3+M="; mypy-boto3-grafana = buildMypyBoto3Package "grafana" "1.43.11" "sha256-XJOSLyL1+uEweZ9zER7IhH3DFLaLtpJKvuRIn8Ri+P4="; @@ -874,8 +874,8 @@ in "sha256-5AqWiNGz9jemWb8dZkuGQXxPXIruMdDWcoRzbT+ZGro="; mypy-boto3-mediapackagev2 = - buildMypyBoto3Package "mediapackagev2" "1.43.101" - "sha256-s7g2wMW/bOBSKKe7q0S7cSgWnHWNVYO46PQREUAqkZc="; + buildMypyBoto3Package "mediapackagev2" "1.43.108" + "sha256-Hb05g605ESaacKl15tTze8j8r9pDgMu5+e5xI7/qLHI="; mypy-boto3-mediastore = buildMypyBoto3Package "mediastore" "1.43.0" @@ -1038,8 +1038,8 @@ in "sha256-A8/WYxFn06rUXtcIHsKfs7HxvOBges0wDGskm31NIyw="; mypy-boto3-pinpoint-sms-voice-v2 = - buildMypyBoto3Package "pinpoint-sms-voice-v2" "1.43.90" - "sha256-5Rakqq71ubU/k3/AhzIjCh6o9pkBAdzTT//33Xe6o94="; + buildMypyBoto3Package "pinpoint-sms-voice-v2" "1.43.108" + "sha256-5oAvQe+OTzfBAMyP3Mp/hFcF5rAuy2hXdhX+s43FtuU="; mypy-boto3-pipes = buildMypyBoto3Package "pipes" "1.43.0" diff --git a/pkgs/development/python-modules/publicsuffixlist/default.nix b/pkgs/development/python-modules/publicsuffixlist/default.nix index bc4ed18d6ac1..7ae28c1a1797 100644 --- a/pkgs/development/python-modules/publicsuffixlist/default.nix +++ b/pkgs/development/python-modules/publicsuffixlist/default.nix @@ -11,12 +11,12 @@ buildPythonPackage (finalAttrs: { pname = "publicsuffixlist"; - version = "1.0.2.20260925"; + version = "1.0.2.20261002"; pyproject = true; src = fetchPypi { inherit (finalAttrs) pname version; - hash = "sha256-K6zWHIs2H/P6oR+YSjVU8qMEcyeQlGfLnL06Ep2AZfg="; + hash = "sha256-PYFP9esMpLuKLJ1+n9ApSFqc12EQp/N9rTm1k26HZMw="; }; postPatch = '' diff --git a/pkgs/development/tools/pnpm/default.nix b/pkgs/development/tools/pnpm/default.nix index 2f1e42419e25..6789c094cf3c 100644 --- a/pkgs/development/tools/pnpm/default.nix +++ b/pkgs/development/tools/pnpm/default.nix @@ -53,9 +53,9 @@ let hash = "sha256-QKMlFaJVB/jyJt+74lOA4vBTlEwuzGTAwcuYtBy7ke8="; }; "12" = { - version = "12.3.4"; - srcHash = "sha256-EAF5ZeABBX4Wdn08OVria9zKcTIJ8i9EIjb9gsaCAo4="; - cargoHash = "sha256-I54W1Ig6mn3/BsBiL5qc8aUZmSY2IGEY2QSXG0V1W1w="; + version = "12.9.0"; + srcHash = "sha256-lcs9nh9GIKfy5QYabUCj/pIpePAjLeeKBlu4UKm8zgM="; + cargoHash = "sha256-NGefDu4dGMC2RGrTPeYBuRrG+Gb8jnx9+SbyK8WPd9E="; }; }; diff --git a/pkgs/development/tools/pnpm/generic-rust.nix b/pkgs/development/tools/pnpm/generic-rust.nix index e0fc23def387..97338a80de6c 100644 --- a/pkgs/development/tools/pnpm/generic-rust.nix +++ b/pkgs/development/tools/pnpm/generic-rust.nix @@ -34,6 +34,12 @@ rustPlatform.buildRustPackage (finalAttrs: { makeWrapper ]; + postPatch = '' + # upstream duplicates some sources in .cargo/config.toml + # that's also defined in Cargo.toml, cargo fails with duplicate definitions + sed -i '/# >>> pnpm-managed cargo sources >>>/,/# <<< pnpm-managed cargo sources <<