From c407023f2df7666655e76644e1739338b71c3b1d Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 21 Jun 2023 17:54:53 +0200 Subject: [PATCH 01/25] linux: 4.14.318 -> 4.14.319 (cherry picked from commit 93c6573133bc24d85b1ba8f2e74bee6451a8a2d8) --- pkgs/os-specific/linux/kernel/linux-4.14.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/linux-4.14.nix b/pkgs/os-specific/linux/kernel/linux-4.14.nix index 2c2daa7a6783..a41e15e863df 100644 --- a/pkgs/os-specific/linux/kernel/linux-4.14.nix +++ b/pkgs/os-specific/linux/kernel/linux-4.14.nix @@ -3,7 +3,7 @@ with lib; buildLinux (args // rec { - version = "4.14.318"; + version = "4.14.319"; # modDirVersion needs to be x.y.z, will automatically add .0 if needed modDirVersion = versions.pad 3 version; @@ -13,6 +13,6 @@ buildLinux (args // rec { src = fetchurl { url = "mirror://kernel/linux/kernel/v4.x/linux-${version}.tar.xz"; - sha256 = "1g0i68q7xjcjqigwza60i8rqhxsd1l86czqnjv5312lvg5z34fn6"; + sha256 = "1y8zp9jkyid4g857nfm7xhsya3d9vx2dni8l7ishn2gl087pb95c"; }; } // (args.argsOverride or {})) From 606d9b0b44a139fa06d23fe8a263fb0a7c71446c Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 21 Jun 2023 17:55:00 +0200 Subject: [PATCH 02/25] linux: 4.19.286 -> 4.19.287 (cherry picked from commit 0557763fc6faa87b00469cab51a8667f9d5016be) --- pkgs/os-specific/linux/kernel/linux-4.19.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/linux-4.19.nix b/pkgs/os-specific/linux/kernel/linux-4.19.nix index fcb6bd671a74..147c8f1396f7 100644 --- a/pkgs/os-specific/linux/kernel/linux-4.19.nix +++ b/pkgs/os-specific/linux/kernel/linux-4.19.nix @@ -3,7 +3,7 @@ with lib; buildLinux (args // rec { - version = "4.19.286"; + version = "4.19.287"; # modDirVersion needs to be x.y.z, will automatically add .0 if needed modDirVersion = versions.pad 3 version; @@ -13,6 +13,6 @@ buildLinux (args // rec { src = fetchurl { url = "mirror://kernel/linux/kernel/v4.x/linux-${version}.tar.xz"; - sha256 = "1788a68fbga03nkgbvai2bi89v826915829727j4zcilyc21b127"; + sha256 = "0wracrahi4qm6klsd9bnlwwdcaqbclx2mqc5d7vbvxxzfn69nsi8"; }; } // (args.argsOverride or {})) From 1156bd992b8047c9f0e0fe4197cd8db1aeec9ebe Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 21 Jun 2023 17:55:05 +0200 Subject: [PATCH 03/25] linux: 5.10.184 -> 5.10.185 (cherry picked from commit 9b063660201564e0e27f5b6bcfc1e038eabfc8af) --- pkgs/os-specific/linux/kernel/linux-5.10.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/linux-5.10.nix b/pkgs/os-specific/linux/kernel/linux-5.10.nix index 99724c8a526b..a94a85fd02a3 100644 --- a/pkgs/os-specific/linux/kernel/linux-5.10.nix +++ b/pkgs/os-specific/linux/kernel/linux-5.10.nix @@ -3,7 +3,7 @@ with lib; buildLinux (args // rec { - version = "5.10.184"; + version = "5.10.185"; # modDirVersion needs to be x.y.z, will automatically add .0 if needed modDirVersion = versions.pad 3 version; @@ -13,6 +13,6 @@ buildLinux (args // rec { src = fetchurl { url = "mirror://kernel/linux/kernel/v5.x/linux-${version}.tar.xz"; - sha256 = "0219qv9rxg4fi7w2s0s9y7ggral40wm2riis58hmg80z3nybxabp"; + sha256 = "143hghmj4lxiyavndvdmwg5mig8s2i4ffrmd8zwqqwy8ipn641i8"; }; } // (args.argsOverride or {})) From 38579806cb5d7b71f2678aa97c0d0916b473b6a8 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 21 Jun 2023 17:55:10 +0200 Subject: [PATCH 04/25] linux: 5.15.117 -> 5.15.118 (cherry picked from commit 00b1db98acc7238f37b6bb4889ecca20853fd001) --- pkgs/os-specific/linux/kernel/linux-5.15.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/linux-5.15.nix b/pkgs/os-specific/linux/kernel/linux-5.15.nix index fbf157cd0f92..c25fdecffa37 100644 --- a/pkgs/os-specific/linux/kernel/linux-5.15.nix +++ b/pkgs/os-specific/linux/kernel/linux-5.15.nix @@ -3,7 +3,7 @@ with lib; buildLinux (args // rec { - version = "5.15.117"; + version = "5.15.118"; # modDirVersion needs to be x.y.z, will automatically add .0 if needed modDirVersion = versions.pad 3 version; @@ -13,6 +13,6 @@ buildLinux (args // rec { src = fetchurl { url = "mirror://kernel/linux/kernel/v5.x/linux-${version}.tar.xz"; - sha256 = "17r3yyy4yzxyi4n1ri3sb42m9y1vnn4dcc0zli04n00f7hgk7a59"; + sha256 = "1cxm7s19l2f38chxrlvx7crvqcygmc77rhsc3lfx3m84vgdg8ssf"; }; } // (args.argsOverride or { })) From df0dedac5e30002044c2c6a4475647d7a05e9979 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 21 Jun 2023 17:55:14 +0200 Subject: [PATCH 05/25] linux: 5.4.247 -> 5.4.248 (cherry picked from commit bf2aa164604966cc2c22bf607c5e224dfb2dda7a) --- pkgs/os-specific/linux/kernel/linux-5.4.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/linux-5.4.nix b/pkgs/os-specific/linux/kernel/linux-5.4.nix index 8db48e56cbe7..c5d708ff6d99 100644 --- a/pkgs/os-specific/linux/kernel/linux-5.4.nix +++ b/pkgs/os-specific/linux/kernel/linux-5.4.nix @@ -3,7 +3,7 @@ with lib; buildLinux (args // rec { - version = "5.4.247"; + version = "5.4.248"; # modDirVersion needs to be x.y.z, will automatically add .0 if needed modDirVersion = versions.pad 3 version; @@ -13,6 +13,6 @@ buildLinux (args // rec { src = fetchurl { url = "mirror://kernel/linux/kernel/v5.x/linux-${version}.tar.xz"; - sha256 = "1mzyzxfsqp085qx17wp9xz7z4w79kks0jpdba7mx8k9i097hs09k"; + sha256 = "0d9yn51rg59k39h0w6wmvjqz9n7najm9x8yb79rparbcwwrd3gis"; }; } // (args.argsOverride or {})) From 179fdbe697e06561efe97b8588e9599d90ac5e0d Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 21 Jun 2023 17:55:19 +0200 Subject: [PATCH 06/25] linux: 6.1.34 -> 6.1.35 (cherry picked from commit a90ca2ad2b521f759ba8d7a5af79ad1395639071) --- pkgs/os-specific/linux/kernel/linux-6.1.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/linux-6.1.nix b/pkgs/os-specific/linux/kernel/linux-6.1.nix index 41b957669e8c..b3d7132ca905 100644 --- a/pkgs/os-specific/linux/kernel/linux-6.1.nix +++ b/pkgs/os-specific/linux/kernel/linux-6.1.nix @@ -3,7 +3,7 @@ with lib; buildLinux (args // rec { - version = "6.1.34"; + version = "6.1.35"; # modDirVersion needs to be x.y.z, will automatically add .0 if needed modDirVersion = versions.pad 3 version; @@ -13,6 +13,6 @@ buildLinux (args // rec { src = fetchurl { url = "mirror://kernel/linux/kernel/v6.x/linux-${version}.tar.xz"; - sha256 = "00yniq1smlckp18k3bf6bzys8d7wfbrkdwhikz2fycc0pyy7qvxj"; + sha256 = "1b16pk0b45k1q53nzbwv6wh0aqn160b1kip8scywf3axpi1q2dmy"; }; } // (args.argsOverride or { })) From a7d0b45a47f11578eaa40e931d07afdb4f9732b4 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 21 Jun 2023 17:55:23 +0200 Subject: [PATCH 07/25] linux: 6.3.8 -> 6.3.9 (cherry picked from commit 1b038dbb7a74ec550b91233ed22f7df2a8400a98) --- pkgs/os-specific/linux/kernel/linux-6.3.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/linux-6.3.nix b/pkgs/os-specific/linux/kernel/linux-6.3.nix index b7b5923d6bb5..e6778222b004 100644 --- a/pkgs/os-specific/linux/kernel/linux-6.3.nix +++ b/pkgs/os-specific/linux/kernel/linux-6.3.nix @@ -3,7 +3,7 @@ with lib; buildLinux (args // rec { - version = "6.3.8"; + version = "6.3.9"; # modDirVersion needs to be x.y.z, will automatically add .0 if needed modDirVersion = versions.pad 3 version; @@ -13,6 +13,6 @@ buildLinux (args // rec { src = fetchurl { url = "mirror://kernel/linux/kernel/v6.x/linux-${version}.tar.xz"; - sha256 = "0m89safyzi0rklsqvii5vkg92rdmvnl4lvyk6m648bhf4lhx88s3"; + sha256 = "0gmi55hhdw1f1qyvd04v17x596yh8wis42vmcd8vhymik49z5v21"; }; } // (args.argsOverride or { })) From d8ede83f1c7ad4531bf7cadbcb65fb7b8006c117 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 21 Jun 2023 17:55:35 +0200 Subject: [PATCH 08/25] linux-rt_5_10: 5.10.78-rt55 -> 5.10.184-rt90 (cherry picked from commit 5fcaa94255cc52c0039a16253ab5663301c5ee25) --- pkgs/os-specific/linux/kernel/linux-rt-5.10.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/linux-rt-5.10.nix b/pkgs/os-specific/linux/kernel/linux-rt-5.10.nix index cd8ed2a17572..65a4462bbb35 100644 --- a/pkgs/os-specific/linux/kernel/linux-rt-5.10.nix +++ b/pkgs/os-specific/linux/kernel/linux-rt-5.10.nix @@ -6,7 +6,7 @@ , ... } @ args: let - version = "5.10.78-rt55"; # updated by ./update-rt.sh + version = "5.10.184-rt90"; # updated by ./update-rt.sh branch = lib.versions.majorMinor version; kversion = builtins.elemAt (lib.splitString "-" version) 0; in buildLinux (args // { @@ -17,14 +17,14 @@ in buildLinux (args // { src = fetchurl { url = "mirror://kernel/linux/kernel/v5.x/linux-${kversion}.tar.xz"; - sha256 = "03q5lrv8gr9hnm7984pxi9kwsvxrn21qwykj60amisi2wac6r05y"; + sha256 = "0219qv9rxg4fi7w2s0s9y7ggral40wm2riis58hmg80z3nybxabp"; }; kernelPatches = let rt-patch = { name = "rt"; patch = fetchurl { url = "mirror://kernel/linux/kernel/projects/rt/${branch}/older/patch-${version}.patch.xz"; - sha256 = "1wcw682r238qi5jgn5zk9m6j2506p9ypfax13bzhjfyjzz3h98kp"; + sha256 = "1cyxlc229j23yqgl65h3hgv51x76h1pppcn6ihicvc50vv7h5mjk"; }; }; in [ rt-patch ] ++ kernelPatches; From 92d3b5dd791375d107b90c1b621fa44349ceb950 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Wed, 21 Jun 2023 17:55:53 +0200 Subject: [PATCH 09/25] linux_latest-libre: 19331 -> 19337 (cherry picked from commit 786896e22900d7b5c4904997365333e83865defc) --- pkgs/os-specific/linux/kernel/linux-libre.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/linux-libre.nix b/pkgs/os-specific/linux/kernel/linux-libre.nix index 3202519f86b1..0681df9ceb31 100644 --- a/pkgs/os-specific/linux/kernel/linux-libre.nix +++ b/pkgs/os-specific/linux/kernel/linux-libre.nix @@ -1,8 +1,8 @@ { stdenv, lib, fetchsvn, linux , scripts ? fetchsvn { url = "https://www.fsfla.org/svn/fsfla/software/linux-libre/releases/branches/"; - rev = "19331"; - sha256 = "063xjwhsmjm4zfcj9ivlx10nr3f36adw1aqp8dyasq83jqbwbfhd"; + rev = "19337"; + sha256 = "1ps7f7dfxjsl6xj6fiz5nw01an44aqsjmfmjzs8y2h0jpb7il9s5"; } , ... }: From f4de13cf145be27c37294a2881958f3f24ba4abe Mon Sep 17 00:00:00 2001 From: Franz Pletz Date: Wed, 21 Jun 2023 13:48:35 +0200 Subject: [PATCH 10/25] prometheus: 2.42.0 -> 2.44.0 (cherry picked from commit b7c57a09232495e6e73feae34881e24adbc66942) --- pkgs/servers/monitoring/prometheus/default.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/servers/monitoring/prometheus/default.nix b/pkgs/servers/monitoring/prometheus/default.nix index 0abdb97a5421..72f0aa71a702 100644 --- a/pkgs/servers/monitoring/prometheus/default.nix +++ b/pkgs/servers/monitoring/prometheus/default.nix @@ -32,10 +32,10 @@ }: let - version = "2.42.0"; + version = "2.44.0"; webUiStatic = fetchurl { url = "https://github.com/prometheus/prometheus/releases/download/v${version}/prometheus-web-ui-${version}.tar.gz"; - sha256 = "sha256-QOnt8YZkq+/cmoaI8ZOrVbgVh5MnaKpDBVtPTckl4+A="; + sha256 = "sha256-4FNW78V5bQWbTwmaEpvKaB5f/+uYqXjf0F+FONZq5c4="; }; in buildGoModule rec { @@ -48,10 +48,10 @@ buildGoModule rec { owner = "prometheus"; repo = "prometheus"; rev = "v${version}"; - sha256 = "sha256-UwowidKKn3fp2z/MSbwESpl2E4IIioEC0oV1QRE7ViQ="; + sha256 = "sha256-JCEJQ0GjP0jxyQudmgo2krjxXmsOFSwzh9Cm1XsrFZo="; }; - vendorSha256 = "sha256-wUniz7E9l/5ldgPHo+wZkKaZuAH5kvjT0VDl4qkcoNs="; + vendorSha256 = "sha256-dR69FWhiT5FLQjZ1G0uf2QPCu9nEp2YkRjrkP1a/948="; excludedPackages = [ "documentation/prometheus-mixin" ]; From 0c0832b6f801589cfcd9501bff40fff0c0eb28ab Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Vladim=C3=ADr=20=C4=8Cun=C3=A1t?= Date: Wed, 21 Jun 2023 18:36:55 +0200 Subject: [PATCH 11/25] knot-resolver: respect doInstallCheck even in wrapper The main point is to avoid it when cross-compiling. (cherry picked from commit 962e2323a2d9e0d61b9c26e0a1fbef26028ebe1a) --- pkgs/servers/dns/knot-resolver/default.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/servers/dns/knot-resolver/default.nix b/pkgs/servers/dns/knot-resolver/default.nix index ed64f6b791f4..d893c10d142b 100644 --- a/pkgs/servers/dns/knot-resolver/default.nix +++ b/pkgs/servers/dns/knot-resolver/default.nix @@ -116,7 +116,7 @@ wrapped-full = runCommand unwrapped.name allowSubstitutes = false; inherit (unwrapped) meta; } - '' + ('' mkdir -p "$out"/bin makeWrapper '${unwrapped}/bin/kresd' "$out"/bin/kresd \ --set LUA_PATH "$LUA_PATH" \ @@ -125,10 +125,10 @@ wrapped-full = runCommand unwrapped.name ln -sr '${unwrapped}/share' "$out"/ ln -sr '${unwrapped}/lib' "$out"/ # useful in NixOS service ln -sr "$out"/{bin,sbin} - + '' + lib.optionalString unwrapped.doInstallCheck '' echo "Checking that 'http' module loads, i.e. lua search paths work:" echo "modules.load('http')" > test-http.lua echo -e 'quit()' | env -i "$out"/bin/kresd -a 127.0.0.1#53535 -c test-http.lua - ''; + ''); in result From 2c778d768b26ed247398021d9026c350a88e47b6 Mon Sep 17 00:00:00 2001 From: Moritz 'e1mo' Fromm Date: Thu, 22 Jun 2023 17:40:29 +0200 Subject: [PATCH 12/25] bird: 2.13 -> 2.13.1 > When a case statement in filter had an empty branch, it crashed BIRD. This bug > applies to versions 2.13 and 2.0.12. Version 2.0.11 is not affected. > Also we fixed a bug in BGP Roles manifesting when the other party sent no > capabilities at all. https://trubka.network.cz/pipermail/bird-users/2023-June/017034.html (cherry picked from commit 0ed1db3ee52c42adb38b23751cf895e48915cf2f) --- pkgs/servers/bird/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/bird/default.nix b/pkgs/servers/bird/default.nix index a918c5c00262..0c1b366178f1 100644 --- a/pkgs/servers/bird/default.nix +++ b/pkgs/servers/bird/default.nix @@ -2,11 +2,11 @@ stdenv.mkDerivation rec { pname = "bird"; - version = "2.13"; + version = "2.13.1"; src = fetchurl { url = "ftp://bird.network.cz/pub/bird/${pname}-${version}.tar.gz"; - hash = "sha256-jYlePjEYgOnvuIi0OGy+wvfhi/uDNOjUyMp8Q0EJJjg="; + hash = "sha256-l7uNV76bxQg+K1ZkFtJ+MUFihWoSynx34gLkZ9INQIA="; }; nativeBuildInputs = [ flex bison ]; From d5c8bb81439c82ccfcc784b610fc281ba4cbee68 Mon Sep 17 00:00:00 2001 From: Alyssa Ross Date: Tue, 6 Jun 2023 12:34:22 +0000 Subject: [PATCH 13/25] vmTools: download debs from snapshot URLs The deb files we want are no longer available in the Debian mirrors, so we need to download them from the snapshots we download the package lists from. This makes it possible to build the os-prober NixOS test again. (cherry picked from commit 64bfa05b36ae13bb94327bb9154afdf4d7bfbdf7) --- pkgs/build-support/vm/default.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/build-support/vm/default.nix b/pkgs/build-support/vm/default.nix index 403bc9b1d2da..5cc107d2c4a8 100644 --- a/pkgs/build-support/vm/default.nix +++ b/pkgs/build-support/vm/default.nix @@ -1018,7 +1018,7 @@ rec { url = "https://snapshot.debian.org/archive/debian/20221126T084953Z/dists/buster/main/binary-i386/Packages.xz"; hash = "sha256-n9JquhtZgxw3qr9BX0MQoY3ZTIHN0dit+iru3DC31UY="; }; - urlPrefix = "mirror://debian"; + urlPrefix = "https://snapshot.debian.org/archive/debian/20221126T084953Z"; packages = commonDebianPackages; }; @@ -1029,7 +1029,7 @@ rec { url = "https://snapshot.debian.org/archive/debian/20221126T084953Z/dists/buster/main/binary-amd64/Packages.xz"; hash = "sha256-YukIIB3u87jgp9oudwklsxyKVKjSL618wFgDSXiFmjU="; }; - urlPrefix = "mirror://debian"; + urlPrefix = "https://snapshot.debian.org/archive/debian/20221126T084953Z"; packages = commonDebianPackages; }; @@ -1040,7 +1040,7 @@ rec { url = "https://snapshot.debian.org/archive/debian/20230131T034648Z/dists/bullseye/main/binary-i386/Packages.xz"; hash = "sha256-z9eG7RlvelEnZAaeCfIO+XxTZVL3d+zTA7ShU43l/pw="; }; - urlPrefix = "mirror://debian"; + urlPrefix = "https://snapshot.debian.org/archive/debian/20230131T034648Z"; packages = commonDebianPackages; }; @@ -1051,7 +1051,7 @@ rec { url = "https://snapshot.debian.org/archive/debian/20230131T034648Z/dists/bullseye/main/binary-amd64/Packages.xz"; hash = "sha256-mz0eCWdn6uWt40OxsSPheHzEnMeLE52yR/vpb48/VF0="; }; - urlPrefix = "mirror://debian"; + urlPrefix = "https://snapshot.debian.org/archive/debian/20230131T034648Z"; packages = commonDebianPackages; }; }; From a5aed449e373e5db7cb09a49ba3ca715f05d7a0d Mon Sep 17 00:00:00 2001 From: Alyssa Ross Date: Sun, 11 Jun 2023 19:13:48 +0000 Subject: [PATCH 14/25] nixosTests.os-prober: fix filesystem for Debian Debian's e2fsprogs does not understand the metadata_csum_seed ext4 feature, which our e2fsprogs enables by default, so we have to disable it. (cherry picked from commit ee0c8cd15cd4ef5c3cf2292dc7c760de5e709eac) --- nixos/tests/os-prober.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/nixos/tests/os-prober.nix b/nixos/tests/os-prober.nix index 8f3e2494047c..0f7b723d5b3b 100644 --- a/nixos/tests/os-prober.nix +++ b/nixos/tests/os-prober.nix @@ -8,7 +8,7 @@ let ${parted}/bin/parted --script /dev/vda mklabel msdos ${parted}/sbin/parted --script /dev/vda -- mkpart primary ext2 1M -1s mkdir /mnt - ${e2fsprogs}/bin/mkfs.ext4 /dev/vda1 + ${e2fsprogs}/bin/mkfs.ext4 -O '^metadata_csum_seed' /dev/vda1 ${util-linux}/bin/mount -t ext4 /dev/vda1 /mnt if test -e /mnt/.debug; then From 804da1417535b60c040bf7938ae6f357a9991b25 Mon Sep 17 00:00:00 2001 From: Alyssa Ross Date: Tue, 20 Jun 2023 10:20:37 +0000 Subject: [PATCH 15/25] nixosTests.os-prober: add missing kbd extra dep (cherry picked from commit d48e365ff604796ecfd970bc6bc3a7546d8b0a12) --- nixos/tests/os-prober.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/nixos/tests/os-prober.nix b/nixos/tests/os-prober.nix index 0f7b723d5b3b..22e720824c80 100644 --- a/nixos/tests/os-prober.nix +++ b/nixos/tests/os-prober.nix @@ -83,6 +83,8 @@ in { docbook5 docbook_xsl_ns grub2 + kbd + kbd.dev kmod.dev libarchive libarchive.dev From fc6ae812cb032bda1587c86f33c7b54a3f5a11fb Mon Sep 17 00:00:00 2001 From: Jelle Besseling Date: Thu, 22 Jun 2023 16:44:30 +0200 Subject: [PATCH 16/25] vault: set coredump ulimit to 0 (cherry picked from commit 53a3ddfab88c4e45be8fe4d69f70fa11672c2c90) --- nixos/modules/services/security/vault.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/nixos/modules/services/security/vault.nix b/nixos/modules/services/security/vault.nix index 7b9e31a8d990..18d981cdb0d2 100644 --- a/nixos/modules/services/security/vault.nix +++ b/nixos/modules/services/security/vault.nix @@ -221,6 +221,7 @@ in ProtectHome = "read-only"; AmbientCapabilities = "cap_ipc_lock"; NoNewPrivileges = true; + LimitCORE = 0; KillSignal = "SIGINT"; TimeoutStopSec = "30s"; Restart = "on-failure"; From 3f6833a1eca469aba7711c36101ee65d46de6b7b Mon Sep 17 00:00:00 2001 From: Mario Rodas Date: Wed, 21 Jun 2023 04:20:00 +0000 Subject: [PATCH 17/25] terraform: 1.5.0 -> 1.5.1 Diff: https://github.com/hashicorp/terraform/compare/v1.5.0...v1.5.1 Changelog: https://github.com/hashicorp/terraform/blob/v1.5.1/CHANGELOG.md (cherry picked from commit cf4f8ce0ee9cb1a4fcb6e2cdaf122765bbdcfd99) --- pkgs/applications/networking/cluster/terraform/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/networking/cluster/terraform/default.nix b/pkgs/applications/networking/cluster/terraform/default.nix index 10f6c744cc3e..6995ee8f1c4d 100644 --- a/pkgs/applications/networking/cluster/terraform/default.nix +++ b/pkgs/applications/networking/cluster/terraform/default.nix @@ -166,8 +166,8 @@ rec { mkTerraform = attrs: pluggable (generic attrs); terraform_1 = mkTerraform { - version = "1.5.0"; - hash = "sha256-QLCmA4u0br9EyQ244VcpLW5GkZm+bhq2/vvxSbYolCY="; + version = "1.5.1"; + hash = "sha256-dqnJGIoUJP37Z77TR2RBxP94Hx3AZbx90m8z1FoYdw0="; vendorHash = "sha256-tfCfJj39VP+P4qhJTpEIAi4XB+6VYtVKkV/bTrtnFA0="; patches = [ ./provider-path-0_15.patch ]; passthru = { From 3e3d5555d5f6c5c229b2d0b91eb8cd96d442e8eb Mon Sep 17 00:00:00 2001 From: Yaya Date: Thu, 22 Jun 2023 09:43:38 +0000 Subject: [PATCH 18/25] element-{web,desktop}: v1.11.33 -> v1.11.34 https://github.com/vector-im/element-web/releases/tag/v1.11.34 https://github.com/vector-im/element-desktop/releases/tag/v1.11.34 (cherry picked from commit 4bd44c052130331db06e153b1dcc7bebfa9c7eb8) --- .../networking/instant-messengers/element/pin.nix | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/applications/networking/instant-messengers/element/pin.nix b/pkgs/applications/networking/instant-messengers/element/pin.nix index 1ffed54cda37..989a0ddb43bf 100644 --- a/pkgs/applications/networking/instant-messengers/element/pin.nix +++ b/pkgs/applications/networking/instant-messengers/element/pin.nix @@ -1,9 +1,9 @@ { - "version" = "1.11.33"; + "version" = "1.11.34"; "hashes" = { - "desktopSrcHash" = "2rDGVoWxzpdHTo+KS9jZUUscPqv+EkuOv9ElZoVq9F4="; - "desktopYarnHash" = "09qcp69jgl5dcwhpvwcx8q60m2xr1paq0dih8a3zyjydrq9kggda"; - "webSrcHash" = "eAmLnAKbRGQl2NtFmtwRKXozy9V3WzsMQ5Rd5flXSEM="; - "webYarnHash" = "0x7dns0wjdyxyhdg136sn4g3amqim2490qksbaczalgymx4g1k53"; + "desktopSrcHash" = "rq8PdRP290MLBuw8h67Zw86Ee62l1VYGNW4Ph7XGVSQ="; + "desktopYarnHash" = "1ry6w9n91ma8s461rj32g11li0gpn8s65mrw2wkj8k0na52qpx57"; + "webSrcHash" = "28GQiU8h72kD5w5QwOOPxX2Ti0Kv+GVBDDUQYtG0bZ8="; + "webYarnHash" = "1x7vlc0iqqw8jp6yha54lyk9wglpidm4p32wwgifc8vzqjr9a2ii"; }; } From f9fbabde528f4132dde6c3c1a1801b0f8f083e87 Mon Sep 17 00:00:00 2001 From: datafoo <34766150+datafoo@users.noreply.github.com> Date: Fri, 23 Jun 2023 09:19:52 +0200 Subject: [PATCH 19/25] vscode-extensions.dbaeumer.vscode-eslint: 2.4.0 -> 2.4.2 (cherry picked from commit 43ea039eb24a57db4d76516a5771c12a6649386e) --- pkgs/applications/editors/vscode/extensions/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/applications/editors/vscode/extensions/default.nix b/pkgs/applications/editors/vscode/extensions/default.nix index bd4a5a49c237..1a6541c0226d 100644 --- a/pkgs/applications/editors/vscode/extensions/default.nix +++ b/pkgs/applications/editors/vscode/extensions/default.nix @@ -807,8 +807,8 @@ let mktplcRef = { name = "vscode-eslint"; publisher = "dbaeumer"; - version = "2.4.0"; - sha256 = "sha256-7MUQJkLPOF3oO0kpmfP3bWbS3aT7J0RF7f74LW55BQs="; + version = "2.4.2"; + sha256 = "sha256-eIjaiVQ7PNJUtOiZlM+lw6VmW07FbMWPtY7UoedWtbw="; }; meta = { changelog = "https://marketplace.visualstudio.com/items/dbaeumer.vscode-eslint/changelog"; From a6ef7c3299be99a37db59c1c362f9f1150449962 Mon Sep 17 00:00:00 2001 From: Charlotte Van Petegem Date: Fri, 23 Jun 2023 10:21:15 +0200 Subject: [PATCH 20/25] mu: 1.10.3 -> 1.10.4 https://github.com/djcb/mu/releases/tag/v1.10.4 (cherry picked from commit de1467e7b6e44389d91c2d87704ebe3aec367d02) --- pkgs/tools/networking/mu/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/tools/networking/mu/default.nix b/pkgs/tools/networking/mu/default.nix index 891a42ae1cdc..8ea4a628f87d 100644 --- a/pkgs/tools/networking/mu/default.nix +++ b/pkgs/tools/networking/mu/default.nix @@ -14,13 +14,13 @@ stdenv.mkDerivation rec { pname = "mu"; - version = "1.10.3"; + version = "1.10.4"; src = fetchFromGitHub { owner = "djcb"; repo = "mu"; rev = "v${version}"; - hash = "sha256-AqIPdKdNKLnAHIlqgs8zzm7j+iwNvDFWslvp8RjQPnI="; + hash = "sha256-vwStqrw/fPYUpBhBsLX0MPXtBtP5LwU0AYmUbP+Ywgo="; }; postPatch = '' From a2257dd58c3e125c0ccd120fe65a126673021540 Mon Sep 17 00:00:00 2001 From: Maximilian Bosch Date: Fri, 23 Jun 2023 13:57:29 +0200 Subject: [PATCH 21/25] grafana: 9.5.3 -> 9.5.5, fix CVE-2023-3128 ChangeLog: https://github.com/grafana/grafana/releases/tag/v9.5.5 https://grafana.com/blog/2023/06/22/grafana-security-release-for-cve-2023-3128/?pg=graf&plcmt=top-promo-banner --- pkgs/servers/monitoring/grafana/default.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/servers/monitoring/grafana/default.nix b/pkgs/servers/monitoring/grafana/default.nix index 33590dd04f3f..b8890bdb647e 100644 --- a/pkgs/servers/monitoring/grafana/default.nix +++ b/pkgs/servers/monitoring/grafana/default.nix @@ -2,7 +2,7 @@ buildGoModule rec { pname = "grafana"; - version = "9.5.3"; + version = "9.5.5"; excludedPackages = [ "alert_webhook_listener" "clean-swagger" "release_publisher" "slow_proxy" "slow_proxy_mac" "macaron" "devenv" ]; @@ -10,12 +10,12 @@ buildGoModule rec { rev = "v${version}"; owner = "grafana"; repo = "grafana"; - hash = "sha256-b9FkyDEidM7n+eY9IlZT9vysphe4CW5vGXYn9M5BIJM="; + hash = "sha256-e3ltyd5jp2p7SK3vUTfBia/PrHpN2FFeHXeHlkXhsKg="; }; srcStatic = fetchurl { url = "https://dl.grafana.com/oss/release/grafana-${version}.linux-amd64.tar.gz"; - hash = "sha256-PfdRPMQrEaTwg9wWeyJo6I9HuQX6sxl1JbT9CTixnyc="; + hash = "sha256-P6jlUiWtt+Wx80MiNhWz87x0E4cZTiiByAZPQ5yQFcw="; }; vendorHash = "sha256-E9Qdsk691+laPrQQnYBIwxAIbXh7wxB0G2e/Vp+4x98="; From 599abeacaabe6b51077f3b96aeb2733ff8a422fd Mon Sep 17 00:00:00 2001 From: Raito Bezarius Date: Thu, 22 Jun 2023 18:29:52 +0200 Subject: [PATCH 22/25] linux_testing: 6.4-rc6 -> 6.4-rc7 https://lwn.net/Articles/935082/ (cherry picked from commit 4fa45e42782ee3897406f8bf75ac896360bcad68) --- pkgs/os-specific/linux/kernel/linux-testing.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel/linux-testing.nix b/pkgs/os-specific/linux/kernel/linux-testing.nix index deb48cea78d4..4e1c34d6ae4b 100644 --- a/pkgs/os-specific/linux/kernel/linux-testing.nix +++ b/pkgs/os-specific/linux/kernel/linux-testing.nix @@ -3,7 +3,7 @@ with lib; buildLinux (args // rec { - version = "6.4-rc6"; + version = "6.4-rc7"; extraMeta.branch = lib.versions.majorMinor version; # modDirVersion needs to be x.y.z, will always add .0 @@ -11,7 +11,7 @@ buildLinux (args // rec { src = fetchzip { url = "https://git.kernel.org/torvalds/t/linux-${version}.tar.gz"; - hash = "sha256-gJSVjuYoA5k7XuxRirS/ac770ZfXqIUvI7BUPwxvN1g="; + hash = "sha256-UDhLrKe8yMvmWbS19Xt1G3SQpAUWyKrfV3v1MJ5Vep8="; }; # Should the testing kernels ever be built on Hydra? From 8f67e71d201ef6254050505fc3590d29dde54ee6 Mon Sep 17 00:00:00 2001 From: Alyssa Ross Date: Wed, 21 Jun 2023 19:04:10 +0000 Subject: [PATCH 23/25] pkgsStatic.libargon2: fix build By default, LIBRARIES includes both $(LIB_SH) (the shared library), and $(LIB_ST) (the static library). (cherry picked from commit d6660fa81bb6c14c2b6565ccada1b459ae25d9df) --- pkgs/development/libraries/libargon2/default.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/development/libraries/libargon2/default.nix b/pkgs/development/libraries/libargon2/default.nix index 4eb28fb02fe2..ae9ba47cdc3f 100644 --- a/pkgs/development/libraries/libargon2/default.nix +++ b/pkgs/development/libraries/libargon2/default.nix @@ -29,6 +29,8 @@ stdenv.mkDerivation rec { "ARGON2_VERSION=${version}" "LIBRARY_REL=lib" "PKGCONFIG_REL=lib" + ] ++ lib.optionals stdenv.hostPlatform.isStatic [ + "LIBRARIES=$(LIB_ST)" ]; meta = with lib; { From 2990b099f4dd9fc7ab2ec5cc7c7cd65264291cb7 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Na=C3=AFm=20Favier?= Date: Fri, 23 Jun 2023 20:12:19 +0200 Subject: [PATCH 24/25] nixos/syncthing: fix escaping (cherry picked from commit 9a9ded1675b9cba302c50ee1d0616199cc4bc321) --- nixos/modules/services/networking/syncthing.nix | 6 +++--- nixos/tests/syncthing-init.nix | 5 +++-- 2 files changed, 6 insertions(+), 5 deletions(-) diff --git a/nixos/modules/services/networking/syncthing.nix b/nixos/modules/services/networking/syncthing.nix index 3d41fe4013ea..69b45eb02d1d 100644 --- a/nixos/modules/services/networking/syncthing.nix +++ b/nixos/modules/services/networking/syncthing.nix @@ -55,9 +55,9 @@ let # generate the new config by merging with the NixOS config options new_cfg=$(printf '%s\n' "$old_cfg" | ${pkgs.jq}/bin/jq -c '. * { - "devices": (${builtins.toJSON devices}${optionalString (cfg.devices == {} || ! cfg.overrideDevices) " + .devices"}), - "folders": (${builtins.toJSON folders}${optionalString (cfg.folders == {} || ! cfg.overrideFolders) " + .folders"}) - } * ${builtins.toJSON cfg.extraOptions}') + "devices": ('${escapeShellArg (builtins.toJSON devices)}'${optionalString (cfg.devices == {} || ! cfg.overrideDevices) " + .devices"}), + "folders": ('${escapeShellArg (builtins.toJSON folders)}'${optionalString (cfg.folders == {} || ! cfg.overrideFolders) " + .folders"}) + } * '${escapeShellArg (builtins.toJSON cfg.extraOptions)}) # send the new config curl -X PUT -d "$new_cfg" ${cfg.guiAddress}/rest/config diff --git a/nixos/tests/syncthing-init.nix b/nixos/tests/syncthing-init.nix index fcd90739e6a5..5102c0127832 100644 --- a/nixos/tests/syncthing-init.nix +++ b/nixos/tests/syncthing-init.nix @@ -1,6 +1,7 @@ import ./make-test-python.nix ({ lib, pkgs, ... }: let testId = "7CFNTQM-IMTJBHJ-3UWRDIU-ZGQJFR6-VCXZ3NB-XUH3KZO-N52ITXR-LAIYUAU"; + testName = "testDevice foo'bar"; in { name = "syncthing-init"; @@ -9,12 +10,12 @@ in { nodes.machine = { services.syncthing = { enable = true; - devices.testDevice = { + devices.${testName} = { id = testId; }; folders.testFolder = { path = "/tmp/test"; - devices = [ "testDevice" ]; + devices = [ testName ]; }; extraOptions.gui.user = "guiUser"; }; From 52288cfe00404952ab0d70d7efb2739ade8dddb0 Mon Sep 17 00:00:00 2001 From: Pol Dellaiera Date: Fri, 23 Jun 2023 18:00:59 +0200 Subject: [PATCH 25/25] pkgs/top-level/release: allow nodejs 16.20.1 to be cached on Hydra temporarily (cherry picked from commit 4968ffb38a8b24db4891dc10b3defee1430afe25) --- pkgs/development/web/nodejs/v16.nix | 3 +++ pkgs/top-level/release.nix | 2 +- 2 files changed, 4 insertions(+), 1 deletion(-) diff --git a/pkgs/development/web/nodejs/v16.nix b/pkgs/development/web/nodejs/v16.nix index 71e853cfb05d..8b480d4440e8 100644 --- a/pkgs/development/web/nodejs/v16.nix +++ b/pkgs/development/web/nodejs/v16.nix @@ -10,6 +10,9 @@ let in buildNodejs { inherit enableNpm; + # If you do upgrade here, please update in pkgs/top-level/release.nix + # the permitted insecure version to ensure it gets cached for our users + # and backport this to stable release (23.05). version = "16.20.1"; sha256 = "sha256-g+AzgeJx8aVhkYjnrqnYXZt+EvW+KijOt41ySe0it/E="; patches = [ diff --git a/pkgs/top-level/release.nix b/pkgs/top-level/release.nix index 6df315817048..99dc1f048ea6 100644 --- a/pkgs/top-level/release.nix +++ b/pkgs/top-level/release.nix @@ -25,7 +25,7 @@ # and it will be too much painful for our users to recompile them # for no real reason. # Remove them for 23.11. - "nodejs-16.20.0" + "nodejs-16.20.1" "openssl-1.1.1u" ]; }; }