diff --git a/.github/workflows/check-nix-format.yml b/.github/workflows/check-format.yml similarity index 80% rename from .github/workflows/check-nix-format.yml rename to .github/workflows/check-format.yml index 8c35196e4944..ca3da602575b 100644 --- a/.github/workflows/check-nix-format.yml +++ b/.github/workflows/check-format.yml @@ -1,7 +1,4 @@ -# NOTE: Formatting with the RFC-style nixfmt command is not yet stable. -# See https://github.com/NixOS/rfcs/pull/166. - -name: Check that Nix files are formatted +name: Check that files are formatted on: pull_request_target: @@ -14,7 +11,7 @@ jobs: uses: ./.github/workflows/get-merge-commit.yml nixos: - name: nixfmt-check + name: fmt-check runs-on: ubuntu-24.04 needs: get-merge-commit if: needs.get-merge-commit.outputs.mergedSha @@ -27,13 +24,13 @@ jobs: with: extra_nix_config: sandbox = true - - name: Check that Nix files are formatted + - name: Check that files are formatted run: | # Note that it's fine to run this on untrusted code because: # - There's no secrets accessible here # - The build is sandboxed if ! nix-build ci -A fmt.check; then - echo "Some Nix files are not properly formatted" + echo "Some files are not properly formatted" echo "Please format them by going to the Nixpkgs root directory and running one of:" echo " nix-shell --run treefmt" echo " nix develop --command treefmt" diff --git a/.github/workflows/check-nixf-tidy.yml b/.github/workflows/check-nixf-tidy.yml deleted file mode 100644 index 1bb43c746bc5..000000000000 --- a/.github/workflows/check-nixf-tidy.yml +++ /dev/null @@ -1,132 +0,0 @@ -name: Check changed Nix files with nixf-tidy (experimental) - -on: - pull_request_target: - types: [opened, synchronize, reopened, edited] - -permissions: {} - -jobs: - nixos: - name: exp-nixf-tidy-check - runs-on: ubuntu-24.04 - if: "!contains(github.event.pull_request.title, '[skip treewide]')" - steps: - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - with: - ref: refs/pull/${{ github.event.pull_request.number }}/merge - # Fetches the merge commit and its parents - fetch-depth: 2 - - - name: Checking out target branch - run: | - target=$(mktemp -d) - targetRev=$(git rev-parse HEAD^1) - git worktree add "$target" "$targetRev" - echo "targetRev=$targetRev" >> "$GITHUB_ENV" - echo "target=$target" >> "$GITHUB_ENV" - - - name: Get Nixpkgs revision for nixf - run: | - # pin to a commit from nixpkgs-unstable to avoid e.g. building nixf - # from staging - # This should not be a URL, because it would allow PRs to run arbitrary code in CI! - rev=$(jq -r .rev ci/pinned-nixpkgs.json) - echo "url=https://github.com/NixOS/nixpkgs/archive/$rev.tar.gz" >> "$GITHUB_ENV" - - - uses: cachix/install-nix-action@526118121621777ccd86f79b04685a9319637641 # v31 - with: - extra_nix_config: sandbox = true - nix_path: nixpkgs=${{ env.url }} - - - name: Install nixf and jq - # provided jq is incompatible with our expression - run: "nix-env -f '' -iAP nixf jq" - - - name: Check that Nix files pass nixf-tidy - run: | - # Filtering error messages we don't like - nixf_wrapper(){ - nixf-tidy --variable-lookup < "$1" | jq -r ' - [ - "sema-escaping-with" - ] - as $ignored_errors|[.[]|select(.sname as $s|$ignored_errors|index($s)|not)] - ' - } - - failedFiles=() - - # Don't report errors to file overview - # to avoid duplicates when editing title and description - if [[ "${{ github.event.action }}" == 'edited' ]] && [[ -z "${{ github.event.edited.changes.base }}" ]]; then - DONT_REPORT_ERROR=1 - else - DONT_REPORT_ERROR= - fi - # TODO: Make this more parallel - - # Loop through all Nix files touched by the PR - while readarray -d '' -n 2 entry && (( ${#entry[@]} != 0 )); do - type=${entry[0]} - file=${entry[1]} - case $type in - A*) - source="" - dest=$file - ;; - M*) - source=$file - dest=$file - ;; - C*|R*) - source=$file - read -r -d '' dest - ;; - *) - echo "Ignoring file $file with type $type" - continue - esac - - if [[ -n "$source" ]] && [[ "$(nixf_wrapper ${{ env.target }}/"$source")" != '[]' ]] 2>/dev/null; then - echo "Ignoring file $file because it doesn't pass nixf-tidy in the target commit" - echo # insert blank line - else - nixf_report="$(nixf_wrapper "$dest")" - if [[ "$nixf_report" != '[]' ]]; then - echo "$dest doesn't pass nixf-tidy. Reported by nixf-tidy:" - errors=$(echo "$nixf_report" | jq -r --arg dest "$dest" ' - def getLCur: "line=" + (.line+1|tostring) + ",col=" + (.column|tostring); - def getRCur: "endLine=" + (.line+1|tostring) + ",endColumn=" + (.column|tostring); - def getRange: "file=\($dest)," + (.lCur|getLCur) + "," + (.rCur|getRCur); - def getBody: . as $top|(.range|getRange) + ",title="+ .sname + "::" + - (.message|sub("{}" ; ($top.args.[]|tostring))); - def getNote: "\n::notice " + (.|getBody); - def getMessage: "::error " + (.|getBody) + (if (.notes|length)>0 then - ([.notes.[]|getNote]|add) else "" end); - .[]|getMessage - ') - if [[ -z "$DONT_REPORT_ERROR" ]]; then - echo "$errors" - else - # just print in plain text - echo "${errors/::/}" - echo # add one empty line - fi - failedFiles+=("$dest") - fi - fi - done < <(git diff -z --name-status ${{ env.targetRev }} -- '*.nix') - - if [[ -n "$DONT_REPORT_ERROR" ]]; then - echo "Edited the PR but didn't change the base branch, only the description/title." - echo "Not reporting errors again to avoid duplication." - echo # add one empty line - fi - - if (( "${#failedFiles[@]}" > 0 )); then - echo "Some new/changed Nix files don't pass nixf-tidy." - echo "See ${{ github.event.pull_request.html_url }}/files for reported errors." - echo "If you believe this is a false positive, ping @Aleksanaa and @inclyc in this PR." - exit 1 - fi diff --git a/.github/workflows/editorconfig-v2.yml b/.github/workflows/editorconfig-v2.yml deleted file mode 100644 index 68d780f2190f..000000000000 --- a/.github/workflows/editorconfig-v2.yml +++ /dev/null @@ -1,52 +0,0 @@ -name: "Checking EditorConfig v2" - -on: - pull_request_target: - -permissions: {} - -jobs: - get-merge-commit: - uses: ./.github/workflows/get-merge-commit.yml - - tests: - name: editorconfig-check - runs-on: ubuntu-24.04 - needs: get-merge-commit - if: "needs.get-merge-commit.outputs.mergedSha && !contains(github.event.pull_request.title, '[skip treewide]')" - steps: - - name: Get list of changed files from PR - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - run: | - gh api \ - repos/${{ github.repository }}/pulls/${{ github.event.number }}/files --paginate \ - | jq '.[] | select(.status != "removed") | .filename' \ - > "$HOME/changed_files" - - - name: print list of changed files - run: | - cat "$HOME/changed_files" - - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - with: - ref: ${{ needs.get-merge-commit.outputs.mergedSha }} - - - name: Get Nixpkgs revision for editorconfig-checker - run: | - # Pin to a commit from nixpkgs-unstable to avoid building from e.g. staging. - # This should not be a URL, because it would allow PRs to run arbitrary code in CI! - rev=$(jq -r .rev ci/pinned-nixpkgs.json) - echo "url=https://github.com/NixOS/nixpkgs/archive/$rev.tar.gz" >> "$GITHUB_ENV" - - - uses: cachix/install-nix-action@526118121621777ccd86f79b04685a9319637641 # v31 - with: - nix_path: nixpkgs=${{ env.url }} - - - name: Checking EditorConfig - run: | - < "$HOME/changed_files" nix-shell -p editorconfig-checker --run 'xargs -r editorconfig-checker -disable-indent-size' - - - if: ${{ failure() }} - run: | - echo "::error :: Hey! It looks like your changes don't follow our editorconfig settings. Read https://editorconfig.org/#download to configure your editor so you never see this error again." diff --git a/.github/workflows/keep-sorted.yml b/.github/workflows/keep-sorted.yml deleted file mode 100644 index ec2237f52bd9..000000000000 --- a/.github/workflows/keep-sorted.yml +++ /dev/null @@ -1,41 +0,0 @@ -name: Check that files are sorted - -on: - pull_request_target: - types: [opened, synchronize, reopened] - -permissions: {} - -jobs: - get-merge-commit: - uses: ./.github/workflows/get-merge-commit.yml - - nixos: - name: keep-sorted - runs-on: ubuntu-24.04 - needs: get-merge-commit - if: "needs.get-merge-commit.outputs.mergedSha && !contains(github.event.pull_request.title, '[skip treewide]')" - steps: - - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 - with: - ref: ${{ needs.get-merge-commit.outputs.mergedSha }} - - - name: Get Nixpkgs revision for keep-sorted - run: | - # Pin to a commit from nixpkgs-unstable to avoid e.g. building nixfmt from staging. - # This should not be a URL, because it would allow PRs to run arbitrary code in CI! - rev=$(jq -r .rev ci/pinned-nixpkgs.json) - echo "url=https://github.com/NixOS/nixpkgs/archive/$rev.tar.gz" >> "$GITHUB_ENV" - - - uses: cachix/install-nix-action@526118121621777ccd86f79b04685a9319637641 # v31 - with: - extra_nix_config: sandbox = true - nix_path: nixpkgs=${{ env.url }} - - - name: Install keep-sorted - run: "nix-env -f '' -iAP keep-sorted jq" - - - name: Check that Nix files are sorted - shell: bash - run: | - git ls-files | xargs keep-sorted --mode lint | jq --raw-output '.[] | "Please make sure any new entries in \(.path) are sorted alphabetically."' diff --git a/ci/OWNERS b/ci/OWNERS index 5dbe009276a1..5dcc5941eab5 100644 --- a/ci/OWNERS +++ b/ci/OWNERS @@ -15,7 +15,7 @@ # CI /.github/workflows @NixOS/Security @Mic92 @zowoq @infinisil -/.github/workflows/check-nix-format.yml @infinisil +/.github/workflows/check-format.yml @infinisil /.github/workflows/nixpkgs-vet.yml @infinisil @philiptaron /.github/workflows/codeowners-v2.yml @infinisil /ci @infinisil @philiptaron @NixOS/Security diff --git a/ci/default.nix b/ci/default.nix index 67f59d61bfd4..9d0fff7d119a 100644 --- a/ci/default.nix +++ b/ci/default.nix @@ -44,10 +44,19 @@ let # By default it's info, which is too noisy since we have many unmatched files settings.on-unmatched = "debug"; + programs.keep-sorted.enable = true; + # This uses nixfmt-rfc-style underneath, # the default formatter for Nix code. # See https://github.com/NixOS/nixfmt programs.nixfmt.enable = true; + + settings.formatter.editorconfig-checker = { + command = "${pkgs.lib.getExe pkgs.editorconfig-checker}"; + options = [ "-disable-indent-size" ]; + includes = [ "*" ]; + priority = 1; + }; }; fs = pkgs.lib.fileset; nixFilesSrc = fs.toSource { diff --git a/ci/eval/compare/default.nix b/ci/eval/compare/default.nix index 04676476f4b2..7b677c6d01f3 100644 --- a/ci/eval/compare/default.nix +++ b/ci/eval/compare/default.nix @@ -3,6 +3,7 @@ jq, runCommand, writeText, + python3, ... }: { @@ -125,18 +126,59 @@ let in runCommand "compare" { - nativeBuildInputs = [ jq ]; + nativeBuildInputs = [ + jq + (python3.withPackages ( + ps: with ps; [ + numpy + pandas + scipy + ] + )) + + ]; maintainers = builtins.toJSON maintainers; passAsFile = [ "maintainers" ]; + env = { + BEFORE_DIR = "${beforeResultDir}"; + AFTER_DIR = "${afterResultDir}"; + }; } '' mkdir $out cp ${changed-paths} $out/changed-paths.json - jq -r -f ${./generate-step-summary.jq} < ${changed-paths} > $out/step-summary.md + + if jq -e '(.attrdiff.added | length == 0) and (.attrdiff.removed | length == 0)' "${changed-paths}" > /dev/null; then + # Chunks have changed between revisions + # We cannot generate a performance comparison + { + echo + echo "# Performance comparison" + echo + echo "This compares the performance of this branch against its pull request base branch (e.g., 'master')" + echo + echo "For further help please refer to: [ci/README.md](https://github.com/NixOS/nixpkgs/blob/master/ci/README.md)" + echo + } >> $out/step-summary.md + + python3 ${./cmp-stats.py} >> $out/step-summary.md + + else + # Package chunks are the same in both revisions + # We can use the to generate a performance comparison + { + echo + echo "# Performance Comparison" + echo + echo "Performance stats were skipped because the package sets differ between the two revisions." + echo + echo "For further help please refer to: [ci/README.md](https://github.com/NixOS/nixpkgs/blob/master/ci/README.md)" + } >> $out/step-summary.md + fi + + jq -r -f ${./generate-step-summary.jq} < ${changed-paths} >> $out/step-summary.md cp "$maintainersPath" "$out/maintainers.json" - - # TODO: Compare eval stats '' diff --git a/ci/eval/default.nix b/ci/eval/default.nix index 8537084b1bd5..639e75ec4211 100644 --- a/ci/eval/default.nix +++ b/ci/eval/default.nix @@ -9,6 +9,7 @@ nixVersions, jq, sta, + python3, }: let @@ -270,6 +271,7 @@ let runCommand writeText supportedSystems + python3 ; }; diff --git a/pkgs/applications/networking/browsers/misc/widevine-cdm.nix b/pkgs/applications/networking/browsers/misc/widevine-cdm.nix deleted file mode 100644 index a5e7bc2f1b40..000000000000 --- a/pkgs/applications/networking/browsers/misc/widevine-cdm.nix +++ /dev/null @@ -1,35 +0,0 @@ -{ - lib, - stdenv, - fetchzip, -}: - -stdenv.mkDerivation rec { - pname = "widevine-cdm"; - version = "4.10.2830.0"; - - src = fetchzip { - url = "https://dl.google.com/widevine-cdm/${version}-linux-x64.zip"; - hash = "sha256-XDnsan1ulnIK87Owedb2s9XWLzk1K2viGGQe9LN/kcE="; - stripRoot = false; - }; - - installPhase = '' - runHook preInstall - - install -vD manifest.json $out/share/google/chrome/WidevineCdm/manifest.json - install -vD LICENSE.txt $out/share/google/chrome/WidevineCdm/LICENSE.txt - install -vD libwidevinecdm.so $out/share/google/chrome/WidevineCdm/_platform_specific/linux_x64/libwidevinecdm.so - - runHook postInstall - ''; - - meta = with lib; { - description = "Widevine CDM"; - homepage = "https://www.widevine.com"; - sourceProvenance = with sourceTypes; [ binaryNativeCode ]; - license = licenses.unfree; - maintainers = with maintainers; [ jlamur ]; - platforms = [ "x86_64-linux" ]; - }; -} diff --git a/pkgs/build-support/fetchurl/default.nix b/pkgs/build-support/fetchurl/default.nix index e4a70743334b..88b3eb172141 100644 --- a/pkgs/build-support/fetchurl/default.nix +++ b/pkgs/build-support/fetchurl/default.nix @@ -215,7 +215,7 @@ stdenvNoCC.mkDerivation ( # If set, prefer the content-addressable mirrors # (http://tarballs.nixos.org) over the original URLs. - preferHashedMirrors = true; + preferHashedMirrors = false; # New-style output content requirements. inherit (hash_) outputHashAlgo outputHash; diff --git a/pkgs/by-name/wi/widevine-cdm/aarch64-linux.nix b/pkgs/by-name/wi/widevine-cdm/aarch64-linux.nix new file mode 100644 index 000000000000..f8ce102acdda --- /dev/null +++ b/pkgs/by-name/wi/widevine-cdm/aarch64-linux.nix @@ -0,0 +1,49 @@ +{ + lib, + stdenv, + fetchurl, + fetchFromGitHub, + squashfsTools, + python3, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "widevine-cdm"; + version = "${finalAttrs.lacrosVersion}-${builtins.substring 0 7 finalAttrs.widevineInstaller.rev}"; + lacrosVersion = "120.0.6098.0"; + + widevineInstaller = fetchFromGitHub { + owner = "AsahiLinux"; + repo = "widevine-installer"; + rev = "7a3928fe1342fb07d96f61c2b094e3287588958b"; + sha256 = "sha256-XI1y4pVNpXS+jqFs0KyVMrxcULOJ5rADsgvwfLF6e0Y="; + }; + + src = fetchurl { + url = "https://commondatastorage.googleapis.com/chromeos-localmirror/distfiles/chromeos-lacros-arm64-squash-zstd-${finalAttrs.lacrosVersion}"; + hash = "sha256-OKV8w5da9oZ1oSGbADVPCIkP9Y0MVLaQ3PXS3ZBLFXY="; + }; + + nativeBuildInputs = [ + squashfsTools + python3 + ]; + + unpackPhase = '' + unsquashfs -q $src 'WidevineCdm/*' + python3 $widevineInstaller/widevine_fixup.py squashfs-root/WidevineCdm/_platform_specific/cros_arm64/libwidevinecdm.so libwidevinecdm.so + cp squashfs-root/WidevineCdm/manifest.json . + cp squashfs-root/WidevineCdm/LICENSE LICENSE.txt + ''; + + # Accoring to widevine-installer: "Hack because Chromium hardcodes a check for this right now..." + postInstall = '' + install -vD manifest.json "$out/share/google/chrome/WidevineCdm/manifest.json" + install -vD LICENSE.txt "$out/share/google/chrome/WidevineCdm/License.txt" + install -vD libwidevinecdm.so "$out/share/google/chrome/WidevineCdm/_platform_specific/linux_arm64/libwidevinecdm.so" + mkdir -p "$out/share/google/chrome/WidevineCdm/_platform_specific/linux_x64" + touch "$out/share/google/chrome/WidevineCdm/_platform_specific/linux_x64/libwidevinecdm.so" + ''; + + meta = import ./meta.nix lib; +}) diff --git a/pkgs/by-name/wi/widevine-cdm/meta.nix b/pkgs/by-name/wi/widevine-cdm/meta.nix new file mode 100644 index 000000000000..0361d3ee1da5 --- /dev/null +++ b/pkgs/by-name/wi/widevine-cdm/meta.nix @@ -0,0 +1,12 @@ +lib: { + description = "Widevine CDM"; + homepage = "https://www.widevine.com"; + sourceProvenance = with lib.sourceTypes; [ binaryNativeCode ]; + license = lib.licenses.unfree; + maintainers = with lib.maintainers; [ jlamur ]; + platforms = lib.map (lib.removeSuffix ".nix") ( + lib.filter (name: name != "meta.nix" && name != "package.nix") ( + builtins.attrNames (builtins.readDir ./.) + ) + ); +} diff --git a/pkgs/by-name/wi/widevine-cdm/package.nix b/pkgs/by-name/wi/widevine-cdm/package.nix new file mode 100644 index 000000000000..bae718940d20 --- /dev/null +++ b/pkgs/by-name/wi/widevine-cdm/package.nix @@ -0,0 +1,13 @@ +{ + lib, + stdenv, + callPackage, +}: + +let + targets = lib.genAttrs [ + "aarch64-linux" + "x86_64-linux" + ] (name: ./. + "/${name}.nix"); +in +callPackage (targets."${stdenv.hostPlatform.system}" or targets.x86_64-linux) { inherit stdenv; } diff --git a/pkgs/by-name/wi/widevine-cdm/x86_64-linux.nix b/pkgs/by-name/wi/widevine-cdm/x86_64-linux.nix new file mode 100644 index 000000000000..00c1b625c32d --- /dev/null +++ b/pkgs/by-name/wi/widevine-cdm/x86_64-linux.nix @@ -0,0 +1,28 @@ +{ + lib, + stdenv, + fetchzip, +}: + +stdenv.mkDerivation (finalAttrs: { + pname = "widevine-cdm"; + version = "4.10.2891.0"; + + src = fetchzip { + url = "https://dl.google.com/widevine-cdm/${finalAttrs.version}-linux-x64.zip"; + hash = "sha256-ZO6FmqJUnB9VEJ7caJt58ym8eB3/fDATri3iOWCULRI="; + stripRoot = false; + }; + + installPhase = '' + runHook preInstall + + install -vD manifest.json $out/share/google/chrome/WidevineCdm/manifest.json + install -vD LICENSE.txt $out/share/google/chrome/WidevineCdm/LICENSE.txt + install -vD libwidevinecdm.so $out/share/google/chrome/WidevineCdm/_platform_specific/linux_x64/libwidevinecdm.so + + runHook postInstall + ''; + + meta = import ./meta.nix lib; +}) diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index 21bd77e5e152..f5357cbe12eb 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -21158,8 +21158,6 @@ with pkgs; aitrack = libsForQt5.callPackage ../applications/misc/aitrack { }; - widevine-cdm = callPackage ../applications/networking/browsers/misc/widevine-cdm.nix { }; - tidal-dl = python3Packages.callPackage ../tools/audio/tidal-dl { }; tubekit = callPackage ../applications/networking/cluster/tubekit/wrapper.nix { };