Merge master into staging-nixos

This commit is contained in:
nixpkgs-ci[bot]
2026-08-01 12:23:02 +00:00
committed by GitHub
188 changed files with 1936 additions and 1374 deletions

View File

@@ -27291,6 +27291,12 @@
githubId = 285829;
keys = [ { fingerprint = "09BE 3BAE 8D55 D4CD 8579 285A 9675 EAC3 4897 E6E2"; } ];
};
stzx = {
name = "Stzx";
github = "Stzx";
githubId = 19950702;
email = "silence.m@hotmail.com";
};
SubhrajyotiSen = {
email = "subhrajyoti12@gmail.com";
github = "SubhrajyotiSen";

View File

@@ -87,12 +87,6 @@ let
"network.target"
];
# We wait for the udev events queue to empty in the *hope* that the
# devices needed here become available. This is terribly broken and
# essentially no better than a random sleep().
# FIXME: use .device units dependecies instead.
serviceConfig.ExecStartPre = "-${lib.getExe' pkgs.systemd "udevadm"} settle --timeout=180";
unitConfig = {
# Avoid default dependencies like "basic.target", which prevents ifstate from starting before luks is unlocked.
DefaultDependencies = "no";
@@ -193,6 +187,13 @@ in
ExecStart = "${lib.getExe cfg.package} --config ${
config.environment.etc."ifstate/ifstate.yaml".source
} apply";
# We wait for the udev events queue to empty in the *hope* that the
# devices needed here become available. This is terribly broken and
# essentially no better than a random sleep(). Same below for initrd.
# FIXME: use .device units dependecies instead.
ExecStartPre = "-${lib.getExe' config.systemd.package "udevadm"} settle --timeout=180";
# because oneshot services do not have a timeout by default
TimeoutStartSec = "2min";
};
@@ -294,6 +295,8 @@ in
} apply";
# because oneshot services do not have a timeout by default
TimeoutStartSec = "2min";
# See comment on non-initrd service above
ExecStartPre = "-${lib.getExe' config.boot.initrd.systemd.package "udevadm"} settle --timeout=180";
};
};
};

View File

@@ -218,7 +218,7 @@ in
}
];
networking.firewall.allowedTCPPorts = lib.optional cfg.openFirewall cfg.port;
networking.firewall.allowedTCPPorts = lib.optional cfg.openFirewall (lib.toInt cfg.env.PORT);
systemd.tmpfiles.settings."10-librechat"."${cfg.dataDir}".d = {
mode = "0755";

View File

@@ -259,7 +259,27 @@ in
options.systemd = {
package = mkPackageOption pkgs "systemd" { };
package = mkPackageOption pkgs "systemd" { } // {
# audit 4.2 rejects overlong values (max 15 bytes) for the kernel comm.
# systemd attempts to send the full 19 bytes of "systemd-update-utmp",
# and the systemd-update-utmp service fails to start. this patch shortens
# the kernel comm entry to "update-utmp".
# TODO: revert on staging when updating to audit 4.2.1
# original commit: https://github.com/linux-audit/audit-userspace/commit/d7ea98263ebdb974b383a4057856a5ec339776fc
# switch to truncate: https://github.com/linux-audit/audit-userspace/commit/d7ea98263ebdb974b383a4057856a5ec339776fc
# systemd pr: https://github.com/systemd/systemd/pull/43144
apply =
pkg:
pkg.overrideAttrs (prevAttrs: {
patches = prevAttrs.patches or [ ] ++ [
(pkgs.fetchpatch {
name = "systemd-update-utmp-shorten-comm.patch";
url = "https://github.com/systemd/systemd/commit/b8968c492108506952ab2748c4a44ce32fc9477c.patch";
hash = "sha256-d0rMssj1+cDw3+KOk8ecjqIIuBhjDixIH+7MJfC+I+M=";
})
];
});
};
enableStrictShellChecks = mkEnableOption "" // {
description = ''

View File

@@ -31,6 +31,6 @@
assert ("Latitude: 12.345000°" in whereAmI), f"Incorrect latitude in:\n{whereAmI}"
assert ("Longitude: -67.890000°" in whereAmI), f"Incorrect longitude in:\n{whereAmI}"
assert ("Altitude: 123.450000 meters" in whereAmI), f"Incorrect altitude in:\n{whereAmI}"
assert ("Accuracy: 1000.000000 meters" in whereAmI), f"Incorrect accuracy in:\n{whereAmI}"
assert ("Accuracy: 1000 meters" in whereAmI), f"Incorrect accuracy in:\n{whereAmI}"
'';
}

View File

@@ -43,10 +43,15 @@ pkgs.lib.listToAttrs (
meta = { };
nodes.machine =
{ pkgs, lib, ... }:
{
config,
pkgs,
lib,
...
}:
let
script = ''
${lib.getExe' pkgs.systemd "udevadm"} settle --timeout=180
${lib.getExe' config.boot.initrd.systemd.package "udevadm"} settle --timeout=180
ip link
if ${lib.optionalString predictable "!"} ip link show eth0; then
echo Success

View File

@@ -460,19 +460,17 @@ in
nodes.machine = common;
testScript =
let
oldVersion = "222";
in
# python
''
machine.succeed("mount -o remount,rw /boot")
def switch():
# Replace version inside sd-boot with something older. See magic[] string in systemd src/boot/efi/boot.c
# Replace version inside sd-boot with something older. See SD_MAGIC in systemd src/boot/boot.c
# Note: the sed replacement has to be length-preserving, because section length matters.
machine.succeed(
"""
r"""
find /boot -iname '*boot*.efi' -print0 | \
xargs -0 -I '{}' sed -i 's/#### LoaderInfo: systemd-boot .* ####/#### LoaderInfo: systemd-boot ${oldVersion} ####/' '{}'
xargs -0 -I '{}' sed -i 's/#### LoaderInfo: systemd-boot [0-9]\(.*\) ####/#### LoaderInfo: systemd-boot 0\1 ####/' '{}'
"""
)
return machine.succeed("/run/current-system/bin/switch-to-configuration boot 2>&1")

View File

@@ -10,13 +10,12 @@
}:
let
zig = zig_0_16;
mkModule =
{
pname,
version,
src,
zig,
zigDeps,
}:
stdenv.mkDerivation (finalAttrs: {
@@ -24,10 +23,11 @@ let
pname
version
src
zig
zigDeps
;
nativeBuildInputs = [ zig ] ++ lib.optionals stdenv.hostPlatform.isDarwin [ xcbuild ];
nativeBuildInputs = [ finalAttrs.zig ] ++ lib.optionals stdenv.hostPlatform.isDarwin [ xcbuild ];
env.EMACS_INCLUDE_DIR = "${emacs}/include";
@@ -67,8 +67,9 @@ melpaBuild (finalAttrs: {
hash = "sha256-upIcL4wf2zAc3/3QeERF619nSDml2wEZCOl6/XOaT3E=";
};
# this can be put into mkModule, but we put it here to ease user overrideAttrs
zigDeps = zig.fetchDeps {
# these can be put into mkModule, but we put them here to ease user overrideAttrs
zig = zig_0_16;
zigDeps = finalAttrs.zig.fetchDeps {
inherit (finalAttrs) src pname version;
fetchAll = true;
hash = "sha256-NcNp0FnMy6FfZ63+pwiTRCmJ8FIovJEOhNvxVr1+uSQ=";
@@ -91,6 +92,7 @@ melpaBuild (finalAttrs: {
inherit (finalAttrs)
version
src
zig
zigDeps
;
};

View File

@@ -12,22 +12,22 @@ vscode-utils.buildVscodeMarketplaceExtension {
sources = {
"x86_64-linux" = {
arch = "linux-x64";
hash = "sha256-YB+PtOdmsNfDuWl1U5g2HxnaXTmWBOnInVwoAcc2rwk=";
hash = "sha256-aEcYKsmZstFbSNybBLwtsrQu2P3cXeUSx+bb/fX52p4=";
};
"aarch64-linux" = {
arch = "linux-arm64";
hash = "sha256-K6KjMMJHqwTlwHZuINHSSXG5R99b8w4SRkXcCBtf0d4=";
hash = "sha256-2B9jbLjYp2Dj+cqECeX7gCfB34Yoy8o3jTdzLd7ZLbc=";
};
"aarch64-darwin" = {
arch = "darwin-arm64";
hash = "sha256-D7bHjKOvaJj98vuPW53kHieGYIXOLft4OkpuG0AX9Rc=";
hash = "sha256-TGX0gaKZcvEWYz+Z/1tVTaE+6xbcTRR+Tb7JHVSAXkc=";
};
};
in
{
name = "ruff";
publisher = "charliermarsh";
version = "2026.62.0";
version = "2026.68.0";
}
// sources.${stdenvNoCC.hostPlatform.system}
or (throw "Unsupported system ${stdenvNoCC.hostPlatform.system}");

View File

@@ -1508,12 +1508,12 @@
"vendorHash": "sha256-8p6dJwGyTK+qtgplSLtIRKxnNAQAgHfs4z/EsBcg/iY="
},
"yandex-cloud_yandex": {
"hash": "sha256-0155GXJMfoCnyqaJiF5SJIA1Qz1q2AYe/BB0AYODG/0=",
"hash": "sha256-0jUqljsSnNctu+5XPQGF6OE+BBZLbRoKxZLbe4/toRs=",
"homepage": "https://registry.terraform.io/providers/yandex-cloud/yandex",
"owner": "yandex-cloud",
"repo": "terraform-provider-yandex",
"rev": "v0.218.0",
"rev": "v0.220.0",
"spdx": "MPL-2.0",
"vendorHash": "sha256-FfZvuC/XXhKS03E+l4/9KCLSwx+uTP1LzywckZqX6pA="
"vendorHash": "sha256-ZRElns36b4n5LaIIA6Snfxj15LXSVnf6o/H7lyJw3h0="
}
}

View File

@@ -27,13 +27,13 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "apache-orc";
version = "2.3.0";
version = "2.3.1";
src = fetchFromGitHub {
owner = "apache";
repo = "orc";
tag = "v${finalAttrs.version}";
hash = "sha256-QQdRzwmUF1Qwxg53kJv1Q6yFuHqSrLYwUxKt+6wK9Hs=";
hash = "sha256-5pY81SM7BALjPL0e7Iov2QbMcUDd3lNC/99U9yiDKfQ=";
};
patches = [
@@ -43,11 +43,6 @@ stdenv.mkDerivation (finalAttrs: {
# <store path>/bin/ld: <store path>/lib/libabsl_raw_hash-set.so.2601.0.0:
# error adding symbols: DSO missing from command line
./cmake-link-abseil.patch
# Protobuf 34 adds `[[nodiscard]]` to several serialization functions. In
# order to avoid these warnings causing build failures, we add handling for
# this failure case.
./protobuf34-nodiscard.patch
];
nativeBuildInputs = [
@@ -66,7 +61,7 @@ stdenv.mkDerivation (finalAttrs: {
cmakeFlags = [
(lib.cmakeFeature "CMAKE_BUILD_TYPE" "Release")
(lib.cmakeBool "BUILD_JAVA" false)
(lib.cmakeBool "STOP_BUILD_ON_WARNING" stdenv.hostPlatform.isLinux)
(lib.cmakeBool "STOP_BUILD_ON_WARNING" false)
(lib.cmakeBool "INSTALL_VENDORED_LIBS" false)
]
++ lib.optional (stdenv.hostPlatform != stdenv.buildPlatform) [

View File

@@ -1,15 +0,0 @@
diff --git a/c++/src/ColumnWriter.cc b/c++/src/ColumnWriter.cc
index 9cdbae0709..d049e91bb1 100644
--- a/c++/src/ColumnWriter.cc
+++ b/c++/src/ColumnWriter.cc
@@ -212,7 +212,9 @@
}
}
// write row index to output stream
- rowIndex->SerializeToZeroCopyStream(indexStream.get());
+ if (!rowIndex->SerializeToZeroCopyStream(indexStream.get())) {
+ throw std::logic_error("Failed to write index stream.");
+ }
// construct row index stream
proto::Stream stream;

View File

@@ -42,6 +42,7 @@ stdenv.mkDerivation (finalAttrs: {
cmakeFlags = [
(lib.cmakeBool "ASSIMP_BUILD_ASSIMP_TOOLS" true)
(lib.cmakeBool "ASSIMP_BUILD_TESTS" finalAttrs.finalPackage.doCheck)
(lib.cmakeBool "ASSIMP_WARNINGS_AS_ERRORS" false)
];
# Some matrix tests fail on non-86_64-linux:

View File

@@ -30,13 +30,13 @@
}:
stdenv.mkDerivation (finalAttrs: {
pname = "audit";
version = "4.1.4";
version = "4.2";
src = fetchFromGitHub {
owner = "linux-audit";
repo = "audit-userspace";
tag = "v${finalAttrs.version}";
hash = "sha256-GdJ9nzlDAdOazOHH/YWuEoELrJh+G5ZJUKwIqAKAzpo=";
hash = "sha256-poldhsF+ccutCxK7KE/gYpxa1x3wUQJWoCwU6pGFj6A=";
};
postPatch = ''
@@ -165,7 +165,7 @@ stdenv.mkDerivation (finalAttrs: {
meta = {
homepage = "https://people.redhat.com/sgrubb/audit/";
description = "Audit Library";
changelog = "https://github.com/linux-audit/audit-userspace/releases/tag/v4.1.2";
changelog = "https://github.com/linux-audit/audit-userspace/releases/tag/${finalAttrs.src.tag}";
license = lib.licenses.gpl2Plus;
maintainers = with lib.maintainers; [ grimmauld ];
teams = [ lib.teams.security-review ];

View File

@@ -12,18 +12,18 @@
}:
let
pname = "beeper";
version = "4.2.985";
version = "4.3.0";
inherit (stdenv.hostPlatform) system;
sources = {
x86_64-linux = fetchurl {
url = "https://beeper-desktop.download.beeper.com/builds/Beeper-${version}-x86_64.AppImage";
hash = "sha256-oWJdpZL+Q8/jaI/WJfgXUisPASuvHkxU6rOeJkedHSM=";
hash = "sha256-/DJmQMQGzZFnONjQZ9fr9NDtGv9Kg8jF8aBzAOUyCUg=";
};
aarch64-linux = fetchurl {
url = "https://beeper-desktop.download.beeper.com/builds/Beeper-${version}-arm64.AppImage";
hash = "sha256-rY302fiRG2c6dwZ+a8e43DjDUklfR0j78XTixhPkvwY=";
hash = "sha256-zZIbcE78XcXremyWjs3jsiBRTwP24y45CfZHJym8MhQ=";
};
};

View File

@@ -20,7 +20,7 @@ let
lib.concatStringsSep "\n\n" extraCertificateStrings
);
version = "3.125";
version = "3.126";
meta = {
homepage = "https://firefox-source-docs.mozilla.org/security/nss/runbooks/rootstore.html#root-store-consumers";
description = "Bundle of X.509 certificates of public Certificate Authorities (CA)";
@@ -52,7 +52,7 @@ stdenv.mkDerivation {
"https://hg-edge.mozilla.org/projects/nss/raw-file/${tag}/${file}"
"https://raw.githubusercontent.com/nss-dev/nss/refs/tags/${tag}/${file}"
];
hash = "sha256-5XkSgI2u97Kw+k3yzPF+R66vJsg5o4+Fx2AD66/YZr0=";
hash = "sha256-gbfyV2MzouNg5nP5Etewt6dl2DbHMQA+NIpGysXTcZg=";
};
unpackPhase = ''

View File

@@ -9,13 +9,13 @@
stdenv.mkDerivation rec {
pname = "catch2";
version = "3.15.2";
version = "3.15.3";
src = fetchFromGitHub {
owner = "catchorg";
repo = "Catch2";
tag = "v${version}";
hash = "sha256-Fb8dnuaKQwLxYmGDZy38ZsCKk6RwE4PSidD1xmnb1rU=";
hash = "sha256-ZuH3tUWNklq0bKp0Yu9w3L5FNsQwUxe6lyGBv4M6U1E=";
};
patches = lib.optionals stdenv.cc.isClang [

View File

@@ -5,7 +5,7 @@
}:
php.buildComposerProject2 (finalAttrs: {
pname = "civicrm-core";
version = "6.16.1";
version = "6.16.2";
__structuredAttrs = true;
strictDeps = true;
dontUnpack = false;
@@ -14,10 +14,10 @@ php.buildComposerProject2 (finalAttrs: {
owner = "civicrm";
repo = "civicrm-core";
tag = finalAttrs.version;
hash = "sha256-T56hljO656dwXccSlJjGzdHlYfqMUe3Mqzr/xSF/fHE=";
hash = "sha256-aIjQ0d/JseuHQKrph5dD8juUnZa/Krh9L6vN4GUqncE=";
};
vendorHash = "sha256-PTDBSTm7C4ygF/YqV1pnHrjzfJ/Kqud1ICq1ObaledQ=";
vendorHash = "sha256-cuePs/kZx+cpCvG8r9eDmccyEFfL7G9zfD5tpzD5CJE=";
installPhase = ''
runHook preInstall

View File

@@ -6,11 +6,11 @@
buildGraalvmNativeImage (finalAttrs: {
pname = "clj-kondo";
version = "2026.05.25";
version = "2026.07.24";
src = fetchurl {
url = "https://github.com/clj-kondo/clj-kondo/releases/download/v${finalAttrs.version}/clj-kondo-${finalAttrs.version}-standalone.jar";
sha256 = "sha256-SzrfsIHUW+KzZITesZ9aS00Gx7S4hekLsXXdjQJJxLM=";
sha256 = "sha256-QUZkiURBeuv0qxELNRhFw8MudP0m026IpZ8axG922Qg=";
};
extraNativeImageBuildArgs = [

View File

@@ -15,12 +15,12 @@
stdenv.mkDerivation (finalAttrs: {
pname = "clojure";
version = "1.12.5.1654";
version = "1.12.5.1664";
src = fetchurl {
# https://github.com/clojure/brew-install/releases
url = "https://github.com/clojure/brew-install/releases/download/${finalAttrs.version}/clojure-tools-${finalAttrs.version}.tar.gz";
hash = "sha256-3IbMVrw3L87we9h/RGk+60thz19ENHiDh4Nk0Dtfs0I=";
hash = "sha256-d91oaJSAdK3Mk+g6eW+OjxWhqSvLG5AC1xX9IhDkdvM=";
};
nativeBuildInputs = [

View File

@@ -1,18 +1,18 @@
{
"version": "3.13.10",
"version": "3.14.7",
"vscodeVersion": "1.128.0",
"sources": {
"x86_64-linux": {
"url": "https://downloads.cursor.com/production/4f02290ccd9304f0e6bf8ee85f6e9106f02ac1f7/linux/x64/Cursor-3.13.10-x86_64.AppImage",
"hash": "sha256-pZq2rQnIbFLejOkK2y0GZEVRmuNKZvI+oxaviK/vpXQ="
"url": "https://downloads.cursor.com/production/a758f2241ca99fecf380180b6cbdbbce0f1f42cf/linux/x64/Cursor-3.14.7-x86_64.AppImage",
"hash": "sha256-+nvthb0R7tvAH9t1cd4BqIrcjq16Sy2VycLWovjB2wg="
},
"aarch64-linux": {
"url": "https://downloads.cursor.com/production/4f02290ccd9304f0e6bf8ee85f6e9106f02ac1f7/linux/arm64/Cursor-3.13.10-aarch64.AppImage",
"hash": "sha256-fqQbQZqOAXxumAErlKK+1Z19mY3GitfVAwy6vNePcZA="
"url": "https://downloads.cursor.com/production/a758f2241ca99fecf380180b6cbdbbce0f1f42cf/linux/arm64/Cursor-3.14.7-aarch64.AppImage",
"hash": "sha256-jkZyayWZ/gpHuyCjzI+RePOr4GWt2rJwkCGf4dXC1Yk="
},
"aarch64-darwin": {
"url": "https://downloads.cursor.com/production/4f02290ccd9304f0e6bf8ee85f6e9106f02ac1f7/darwin/arm64/Cursor-darwin-arm64.dmg",
"hash": "sha256-d/bdi67FN3BBjIG5GI+O2GtYUeHLKW0iZRjOGxwuS0o="
"url": "https://downloads.cursor.com/production/a758f2241ca99fecf380180b6cbdbbce0f1f42cf/darwin/arm64/Cursor-darwin-arm64.dmg",
"hash": "sha256-mn8km5Jxswh2cKUh78tcv3+qpvgPFFffRfe0YjgiWgo="
}
}
}

View File

@@ -7,6 +7,7 @@
libGL,
libGLU,
libx11,
expat,
}:
stdenv.mkDerivation (finalAttrs: {
@@ -26,9 +27,14 @@ stdenv.mkDerivation (finalAttrs: {
boost
libGL
libGLU
expat
]
++ lib.optional stdenv.hostPlatform.isLinux libx11;
cmakeFlags = [
(lib.cmakeBool "USE_EXTERNAL_EXPAT" true)
];
meta = {
homepage = "https://github.com/coin3d/coin";
description = "High-level, retained-mode toolkit for effective 3D graphics development";

View File

@@ -5,6 +5,7 @@
fetchFromGitHub,
just,
libcosmicAppHook,
autoAddDriverRunpath,
nixosTests,
nix-update-script,
}:
@@ -30,6 +31,7 @@ rustPlatform.buildRustPackage (finalAttrs: {
just
libcosmicAppHook
rustPlatform.bindgenHook
autoAddDriverRunpath # for GPU monitoring
];
dontUseJustBuild = true;

View File

@@ -15,11 +15,11 @@
stdenv.mkDerivation (finalAttrs: {
pname = "dash";
version = "0.5.13.4";
version = "0.5.13.5";
src = fetchurl {
url = "http://gondor.apana.org.au/~herbert/dash/files/dash-${finalAttrs.version}.tar.gz";
hash = "sha256-0Q39Qc2lkWVWDbOcqRXCxKdjb/8EKB2NLfd62Sx1Pis=";
hash = "sha256-QAkBAaKkkfE+kB09SOkEFPJmNGKLm//zX/VANjwien0=";
};
strictDeps = true;

View File

@@ -9,16 +9,16 @@
buildGoModule (finalAttrs: {
pname = "dgraph";
version = "25.3.8";
version = "25.4.0";
src = fetchFromGitHub {
owner = "dgraph-io";
repo = "dgraph";
tag = "v${finalAttrs.version}";
hash = "sha256-RrOlJVkekZ3xWGtjc013YyCycJmlPowVzqrttnZD8BI=";
hash = "sha256-77uhpDyQhAbeQVGbAB2ZX1YATA5qAk8l5Y7PWhoJm9E=";
};
vendorHash = "sha256-gD91KGWLqd6a7YkqQSeW1eS2MQI+1/RbI5X1/Xwrz90=";
vendorHash = "sha256-Kr4qeoLsqK7qV7OMAvaY7fbzsxaP6bm9bdUZlmQYAug=";
doCheck = false;

View File

@@ -17,15 +17,15 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "dioxus-cli";
version = "0.7.9";
version = "0.7.10";
src = fetchCrate {
pname = "dioxus-cli";
version = finalAttrs.version;
hash = "sha256-tLMtUlohSJt3okdJh+ARweQNGmzj/vYiNl8iZhDbSAc=";
hash = "sha256-kPzo5zRSVs46SjiDRKpKxca8kPcWUgqc/LMKQsk0sC8=";
};
cargoHash = "sha256-h5wkxHP8ehZLHqcUsro08/dpqSPnPuBbZuUGG8i4nBc=";
cargoHash = "sha256-cvBVIkIqBjXFifYNpL2DqZpQcBaX/59Xw0ZJKUvUcIs=";
buildFeatures = [
"no-downloads"
]

View File

@@ -7,13 +7,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "doctest";
version = "2.5.2";
version = "2.5.3";
src = fetchFromGitHub {
owner = "doctest";
repo = "doctest";
tag = "v${finalAttrs.version}";
hash = "sha256-4jW6xPFCFxk1l47EkSUVojhycrtluPhOc5Adf/25R7M=";
hash = "sha256-+/IEISqN9HdaCJ0udLVUitOUziLvF/D3POecZMoXuho=";
};
nativeBuildInputs = [ cmake ];

View File

@@ -9,11 +9,11 @@
stdenv.mkDerivation (finalAttrs: {
pname = "ethtool";
version = "7.0";
version = "7.1";
src = fetchurl {
url = "mirror://kernel/software/network/ethtool/ethtool-${finalAttrs.version}.tar.xz";
hash = "sha256-Zgv5clp4cTQ6DSMgaKdjT7z7abbC+O/0VYJ/rvsM0WI=";
hash = "sha256-TXjCbtwCVbyS9LmVtf1mEI11/5Zu1GlPYCWm03C8JJY=";
};
nativeBuildInputs = [

View File

@@ -12,7 +12,7 @@
let
pname = "expresslrs-configurator";
version = "1.8.2";
version = "1.8.3";
installPath = "share/${pname}";
resourcesPath = "${installPath}/resources";
in
@@ -22,7 +22,7 @@ stdenv.mkDerivation {
src = fetchzip {
url = "https://github.com/ExpressLRS/ExpressLRS-Configurator/releases/download/v${version}/${pname}-${version}.zip";
stripRoot = false;
hash = "sha256-fVERT1JkXYwEqP0UJZZxT8AgkEMRzlvSqWPM4Zo9KXU=";
hash = "sha256-KoT9YoeAkYrr9FIS7+Lm1CafTNwvV+jLTYYHziCVvrs=";
};
nativeBuildInputs = [

View File

@@ -0,0 +1,111 @@
{
lib,
stdenvNoCC,
fetchFromGitHub,
gitUpdater,
jdupes,
sassc,
themeVariants ? [ ], # default: blue
colorVariants ? [ ], # default: all
sizeVariants ? [ ], # default: standard
tweaks ? [ ],
}:
let
pname = "fluent-gtk-theme";
in
lib.checkListOfEnum "${pname}: theme variants"
[
"default"
"purple"
"pink"
"red"
"orange"
"yellow"
"green"
"teal"
"grey"
"all"
]
themeVariants
lib.checkListOfEnum
"${pname}: color variants"
[
"standard"
"light"
"dark"
]
colorVariants
lib.checkListOfEnum
"${pname}: size variants"
[
"standard"
"compact"
]
sizeVariants
lib.checkListOfEnum
"${pname}: tweaks"
[
"solid"
"float"
"round"
"blur"
"noborder"
"square"
]
tweaks
stdenvNoCC.mkDerivation
(finalAttrs: {
inherit pname;
version = "2025-04-17";
src = fetchFromGitHub {
owner = "vinceliuice";
repo = "fluent-gtk-theme";
rev = finalAttrs.version;
hash = "sha256-AaFj9lG9lWg0a0ksJ0ufoUpsunR3uDhcdb7oSrvAmPI=";
};
nativeBuildInputs = [
jdupes
sassc
];
postPatch = ''
patchShebangs install.sh
sed -i '/"$THEME_DIR\/gtk-2.0/d' install.sh
'';
installPhase = ''
runHook preInstall
name= HOME="$TMPDIR" ./install.sh \
${lib.optionalString (themeVariants != [ ]) "--theme " + toString themeVariants} \
${lib.optionalString (colorVariants != [ ]) "--color " + toString colorVariants} \
${lib.optionalString (sizeVariants != [ ]) "--size " + toString sizeVariants} \
${lib.optionalString (tweaks != [ ]) "--tweaks " + toString tweaks} \
--icon nixos \
--dest $out/share/themes
jdupes --quiet --link-soft --recurse $out/share
runHook postInstall
'';
passthru.updateScript = gitUpdater { };
meta = {
description = "Fluent design gtk theme";
changelog = "https://github.com/vinceliuice/Fluent-gtk-theme/releases/tag/${finalAttrs.version}";
homepage = "https://github.com/vinceliuice/Fluent-gtk-theme";
license = lib.licenses.gpl3Only;
platforms = lib.platforms.unix;
maintainers = with lib.maintainers; [
luftmensch-luftmensch
romildo
stzx
];
};
})

View File

@@ -13,13 +13,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "fluidsynth";
version = "2.5.5";
version = "2.5.6";
src = fetchFromGitHub {
owner = "FluidSynth";
repo = "fluidsynth";
tag = "v${finalAttrs.version}";
hash = "sha256-WEzOYHtPIUkPZu3v4dWcCh3dOJUyG1xRxDuoSXqiGbk=";
hash = "sha256-q4NdfemCprYEYCrKlHumeRM8TyNz8eJcFM18EsB0p0c=";
fetchSubmodules = true;
};
@@ -52,6 +52,7 @@ stdenv.mkDerivation (finalAttrs: {
];
meta = {
changelog = "https://github.com/FluidSynth/fluidsynth/blob/${finalAttrs.src.tag}/doc/wiki/ChangeLog.md";
description = "Real-time software synthesizer based on the SoundFont 2 specifications";
homepage = "https://www.fluidsynth.org";
license = lib.licenses.lgpl21Plus;

View File

@@ -19,16 +19,16 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "flying-carpet";
version = "9.0.10";
version = "10.0.2";
src = fetchFromGitHub {
owner = "spieglt";
repo = "FlyingCarpet";
tag = "v${finalAttrs.version}";
hash = "sha256-7yGU4HCuP8/6UC1J6fNA5CpppJGGhS/ywThXRToDTqo=";
hash = "sha256-38gPXTP+WAZ43oVhgYEFy0lD41uV4JxlNktiD+tJOu0=";
};
cargoHash = "sha256-/Z+0hdQ1H9R7FMLunGT5WgQKFY0b0b6gzrR2CNMe2II=";
cargoHash = "sha256-WZ93Gk2n8GJox7I4o/McC0AgrBh6CZAJFcXWvALk9TM=";
nativeBuildInputs = [
cargo-tauri.hook

View File

@@ -0,0 +1,13 @@
diff --git a/data/meson.build b/data/meson.build
index 2591e6a..dc1bd8d 100644
--- a/data/meson.build
+++ b/data/meson.build
@@ -69,7 +69,7 @@ if get_option('enable-backend')
if systemd.found()
sysusers_dir = systemd.get_variable(pkgconfig: 'sysusersdir')
else
- sysusers_dir = '/usr/lib/sysusers.d'
+ sysusers_dir = join_paths(get_option('prefix'), 'usr/lib/sysusers.d')
endif
configure_file(output: 'geoclue-sysusers.conf',
input: 'geoclue-sysusers.conf.in',

View File

@@ -29,7 +29,7 @@
stdenv.mkDerivation (finalAttrs: {
pname = "geoclue";
version = "2.7.2";
version = "2.8.1";
outputs = [
"out"
@@ -42,11 +42,12 @@ stdenv.mkDerivation (finalAttrs: {
owner = "geoclue";
repo = "geoclue";
tag = finalAttrs.version;
hash = "sha256-LwL1WtCdHb/NwPr3/OLISwaAwplhJwiZT9vUdX29Bbs=";
hash = "sha256-CyZhUMAa2vMUi61sL+gGBZFxGo0lu7Cm68fTjcbblTg=";
};
patches = [
./add-option-for-installation-sysconfdir.patch
./fix-sysusers_dir.patch
];
separateDebugInfo = true;

View File

@@ -71,18 +71,22 @@ stdenv.mkDerivation (finalAttrs: {
checkPhase =
let
excludedTests =
lib.optionals stdenv.hostPlatform.isDarwin [
"mock-log"
]
++ [
"logging" # works around segfaults for now
]
++ lib.optionals (stdenv.hostPlatform.isPower64 && stdenv.hostPlatform.isBigEndian) [
# CHECK_STREQ failed: symbol == "non_inline_func" ((/build/source/build/symbolize_unittest+0x1000b840) vs. non_inline_func)
# TestWithPCInsideNonInlineFunction doesn't use TEST(), so can't exclude via GTEST_FILTER
"symbolize"
];
excludedTests = [
"logging" # works around segfaults for now
]
++ lib.optionals stdenv.hostPlatform.isGnu [
# Test appears to make strong assumptions about compiler optimizations
# that appear to be broken under GCC 16.
"stacktrace"
]
++ lib.optionals stdenv.hostPlatform.isDarwin [
"mock-log"
]
++ lib.optionals (stdenv.hostPlatform.isPower64 && stdenv.hostPlatform.isBigEndian) [
# CHECK_STREQ failed: symbol == "non_inline_func" ((/build/source/build/symbolize_unittest+0x1000b840) vs. non_inline_func)
# TestWithPCInsideNonInlineFunction doesn't use TEST(), so can't exclude via GTEST_FILTER
"symbolize"
];
excludedTestsRegex = lib.optionalString (
excludedTests != [ ]
) "(${lib.concatStringsSep "|" excludedTests})";

View File

@@ -11,11 +11,11 @@
version ?
# This is a workaround for update-source-version to be able to update this
let
_version = "0-unstable-2026-04-01";
_version = "0-unstable-2026-05-27";
in
_version,
rev ? "6e8dcdebbadf4f8aa75e6a4b6e0bdf89dce1513a",
hash ? "sha256-BTPD8WM1pVAMkFDlHekMdWFGyf63KdhKkKwsqikqoBQ=",
rev ? "3357c4f51b1a9e676378c695dd9c7e9911c35ee6",
hash ? "sha256-/1A+DkzAQj2zGPe/A/G0Z3VrYJXUxq4Hd/+d/o5p3G8=",
}:
stdenv.mkDerivation {

View File

@@ -40,13 +40,13 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "graphviz";
version = "14.1.2";
version = "15.1.0";
src = fetchFromGitLab {
owner = "graphviz";
repo = "graphviz";
tag = finalAttrs.version;
hash = "sha256-LkyiKl0ulS9ujEdVLfyeoc4CtjITd6CAc35IUtlHSfw=";
hash = "sha256-5v/ib8hwqHrJLs+jvDGvg0aJiKIt8ipXEd1EUzew7XU=";
};
nativeBuildInputs = [

View File

@@ -22,7 +22,7 @@ stdenv.mkDerivation (finalAttrs: {
# Fix build on i686 by not trying to build AVX2 code
# Submitted upstream: https://github.com/HdrHistogram/HdrHistogram_c/pull/143
${if stdenv.hostPlatform.isi686 then "patches" else null} = [
patches = [
./no-avx2-i386.patch
];

View File

@@ -4,6 +4,8 @@
fetchFromGitHub,
meson,
ninja,
pkg-config,
json_c,
}:
stdenv.mkDerivation (finalAttrs: {
@@ -17,11 +19,27 @@ stdenv.mkDerivation (finalAttrs: {
hash = "sha256-OC6wXBCIW4XznWG0zzxRK3BzWMVK2Jq/gTL36sJV1PE=";
};
outputs = [
"out"
"tools"
];
nativeBuildInputs = [
meson
ninja
pkg-config
];
buildInputs = [
json_c
];
# sscregistrygen is only compiled when json-c is available and meson doesn't install it
postInstall = ''
mkdir -p $tools/bin
install -Dm755 tools/sscregistrygen $tools/bin/sscregistrygen
'';
meta = {
description = "Daemon to communicate with Qualcomm DSPs";
homepage = "https://github.com/linux-msm/hexagonrpc";

View File

@@ -15,7 +15,7 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "hk";
version = "1.51.0";
version = "1.53.0";
__structuredAttrs = true;
@@ -23,10 +23,10 @@ rustPlatform.buildRustPackage (finalAttrs: {
owner = "jdx";
repo = "hk";
tag = "v${finalAttrs.version}";
hash = "sha256-kCmujjvh2CACLrzqFal1CFc7RMzECBYsQ4W3ZnJGRV0=";
hash = "sha256-O9D5gpkLEiA7yotDehsCu6qdYKBaUCmGZjVPETiZXzA=";
};
cargoHash = "sha256-hICexfvE0swz+g/9r/vR/sG2DUAK5Fj0lDTrkuWujok=";
cargoHash = "sha256-4y4wg24yN9lTZvg4SgTZcYSVwIaPowTJ4jj3P09FHjE=";
nativeBuildInputs = [
installShellFiles

View File

@@ -67,35 +67,15 @@
assert libXtSupport -> libX11Support;
assert libraqmSupport -> freetypeSupport;
let
arch =
if stdenv.hostPlatform.system == "i686-linux" then
"i686"
else if
stdenv.hostPlatform.system == "x86_64-linux" || stdenv.hostPlatform.system == "x86_64-darwin"
then
"x86-64"
else if stdenv.hostPlatform.system == "armv7l-linux" then
"armv7l"
else if
stdenv.hostPlatform.system == "aarch64-linux" || stdenv.hostPlatform.system == "aarch64-darwin"
then
"aarch64"
else if stdenv.hostPlatform.system == "powerpc64le-linux" then
"ppc64le"
else
null;
in
stdenv.mkDerivation (finalAttrs: {
pname = "imagemagick";
version = "7.1.2-27";
version = "7.1.2-29";
src = fetchFromGitHub {
owner = "ImageMagick";
repo = "ImageMagick";
tag = finalAttrs.version;
hash = "sha256-QCC2CO2zkhwlEWymwF739uSNuS7QCqqGIJnF/LtYzVc=";
hash = "sha256-gVp6eAXLl11KhtcpZ4hPeurCRHtRhhrAggJi7PatQ+M=";
};
outputs = [
@@ -113,7 +93,7 @@ stdenv.mkDerivation (finalAttrs: {
"MVDelegate=${lib.getExe' coreutils "mv"}"
"RMDelegate=${lib.getExe' coreutils "rm"}"
"--with-frozenpaths"
(lib.withFeatureAs (arch != null) "gcc-arch" arch)
"--with-gcc-arch=generic"
(lib.withFeature librsvgSupport "rsvg")
(lib.withFeature librsvgSupport "pango")
(lib.withFeature liblqr1Support "lqr")

View File

@@ -2,6 +2,7 @@
lib,
stdenv,
fetchFromGitHub,
fetchpatch,
autoreconfHook,
# By default, jemalloc puts a je_ prefix onto all its symbols on OSX, which
# then stops downstream builds (mariadb in particular) from detecting it. This
@@ -59,6 +60,16 @@ stdenv.mkDerivation (finalAttrs: {
# A (longer) patch addressing the failure posted upstream at:
# https://github.com/jemalloc/jemalloc/pull/2954
./skip-extent-test-with-prof-active.patch
# the nonstandard `std::__throw_bad_alloc` is no longer exposed in gcc 16.
# this makes it conditional on exceptions and defers to either
# `throw std::bad_alloc()` or `std::terminate` as appropriate.
# https://github.com/jemalloc/jemalloc/pull/2900
(fetchpatch {
name = "jemalloc-dont-use-nonstandard-throw-bad-alloc.patch";
url = "https://github.com/jemalloc/jemalloc/commit/1a15fe33a48c52bfe26ea83e49f0d317a47da3ea.patch";
hash = "sha256-pL9fo8UMSbFlHCo3LFFkw0qBsdrVHcEJIkLutZYa2Yg=";
})
];
nativeBuildInputs = [

View File

@@ -69,6 +69,7 @@ rustPlatform.buildRustPackage (finalAttrs: {
installShellCompletion --cmd jj \
--bash <(COMPLETE=bash ${jj}) \
--fish <(COMPLETE=fish ${jj}) \
--nushell <(${jj} util completion nushell) \
--zsh <(COMPLETE=zsh ${jj})
'';

View File

@@ -42,16 +42,16 @@ let
in
rustPlatform.buildRustPackage rec {
pname = "liana";
version = "14.0"; # keep in sync with lianad
version = "15.0"; # keep in sync with lianad
src = fetchFromGitHub {
owner = "wizardsardine";
repo = "liana";
tag = "v${version}";
hash = "sha256-1d+icjk1NamlvEx4Xb1Ao4d1hb/t5aBwho+yCtHF9y4=";
hash = "sha256-mRBhpf4Risuq4TQ1y/5lWTOxN2RMHcZ2SC2BpbsOdhA=";
};
cargoHash = "sha256-9CWJIRby6QWJmkYSHj2lFfEj0plX5iWxsdQs5sYww7Q=";
cargoHash = "sha256-Mr6YOK7d6pfFliaiw2Mjj5wJvPk+6yH892uS7ksd4YU=";
nativeBuildInputs = [
pkg-config

View File

@@ -8,16 +8,16 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "lianad";
version = "14.0"; # keep in sync with liana
version = "15.0"; # keep in sync with liana
src = fetchFromGitHub {
owner = "wizardsardine";
repo = "liana";
rev = "v${finalAttrs.version}";
hash = "sha256-1d+icjk1NamlvEx4Xb1Ao4d1hb/t5aBwho+yCtHF9y4=";
hash = "sha256-mRBhpf4Risuq4TQ1y/5lWTOxN2RMHcZ2SC2BpbsOdhA=";
};
cargoHash = "sha256-9CWJIRby6QWJmkYSHj2lFfEj0plX5iWxsdQs5sYww7Q=";
cargoHash = "sha256-Mr6YOK7d6pfFliaiw2Mjj5wJvPk+6yH892uS7ksd4YU=";
buildInputs = [ udev ];

View File

@@ -32,13 +32,13 @@
}:
stdenv.mkDerivation (finalAttrs: {
pname = "libapparmor";
version = "5.0.1";
version = "5.0.2";
src = fetchFromGitLab {
owner = "apparmor";
repo = "apparmor";
tag = "v${finalAttrs.version}";
hash = "sha256-y5r8X7Cpwp7TSsKYXNoAeyy0MbgxLSW8gNtLsIvKP8c=";
hash = "sha256-Kuc5Nrz4iq5MC5AOcJL9Sb54DWNKlEk3b3DW0vpgSZg=";
};
sourceRoot = "${finalAttrs.src.name}/libraries/libapparmor";

View File

@@ -7,6 +7,9 @@
swig,
testers,
nix-update-script,
linuxHeaders,
python3Packages,
withPython ? false,
}:
stdenv.mkDerivation (finalAttrs: {
@@ -28,12 +31,24 @@ stdenv.mkDerivation (finalAttrs: {
'';
strictDeps = true;
__structuredAttrs = true;
enableParallelBuilding = true;
nativeBuildInputs = [
autoreconfHook
pkg-config
swig
]
++ lib.optionals withPython [
python3Packages.python # m4
];
buildInputs = lib.optionals withPython [
python3Packages.python
];
nativeCheckInputs = lib.optionals withPython [
python3Packages.pythonImportsCheckHook
];
outputs = [
@@ -43,13 +58,15 @@ stdenv.mkDerivation (finalAttrs: {
];
configureFlags = [
"--without-python"
(lib.withFeature withPython "python")
"--with-capability_header='${linuxHeaders}/include/linux/capability.h'" # required to link bindings
];
passthru = {
updateScript = nix-update-script { };
tests = {
pkg-config = testers.testMetaPkgConfig finalAttrs.finalPackage;
python = python3Packages.libcap_ng;
};
};
@@ -57,7 +74,18 @@ stdenv.mkDerivation (finalAttrs: {
# see https://github.com/stevegrubb/libcap-ng?tab=readme-ov-file#note-to-distributions
doCheck = true;
pythonImportsCheck = [
"capng"
];
preCheck = ''
patchShebangs bindings/test bindings/python3/test
'';
meta = {
broken =
# m4 python include script fails if cpu bit depth is different across build/host architectures
withPython && (stdenv.hostPlatform.parsed.cpu.bits != stdenv.buildPlatform.parsed.cpu.bits);
changelog = "https://people.redhat.com/sgrubb/libcap-ng/ChangeLog";
description = "Library for working with POSIX capabilities";
homepage = "https://people.redhat.com/sgrubb/libcap-ng/";

View File

@@ -34,7 +34,8 @@ stdenv.mkDerivation (finalAttrs: {
patches = [
./nix-store-date.patch
]
++ lib.optionals (!stdenv.hostPlatform.isDarwin) [
# GCC 16's unused variable analysis is more advanced than previous
# versions, and detects that these variables are unused.
# https://github.com/wolfcw/libfaketime/pull/528

View File

@@ -13,13 +13,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "libffi";
version = "3.7.0";
version = "3.7.1";
src = fetchurl {
url =
with finalAttrs;
"https://github.com/libffi/libffi/releases/download/v${version}/${pname}-${version}.tar.gz";
hash = "sha256-IlXFpjjftRv2fCChKnu3DRf+senqurrAX1VzFG9YZDY=";
hash = "sha256-1emmY43b0lE921RRjrZ+S75vpwe8wBwQ9iEvCgiNgZ0=";
};
# Note: this package is used for bootstrapping fetchurl, and thus
@@ -32,9 +32,6 @@ stdenv.mkDerivation (finalAttrs: {
./freebsd-tsan-pthread.patch
];
# To workaround https://github.com/libffi/libffi/issues/993, we empty the test file:
postPatch = lib.optionalString stdenv.hostPlatform.isDarwin "echo 'int main (void) { return 0; }' > testsuite/libffi.call/i128-1.c";
strictDeps = true;
outputs = [
"out"
@@ -94,7 +91,7 @@ stdenv.mkDerivation (finalAttrs: {
'';
homepage = "http://sourceware.org/libffi/";
license = lib.licenses.mit;
maintainers = [ ];
maintainers = with lib.maintainers; [ aduh95 ];
platforms = lib.platforms.all;
pkgConfigModules = [ "libffi" ];
};

View File

@@ -0,0 +1,59 @@
commit bfdf7b0b7b62f4463451a7d5f8408cec75520dca
Author: NIIBE Yutaka <gniibe@fsij.org>
Date: Thu Jun 25 10:53:29 2026 +0900
tests: Skip a test when !HAVE_LONG_DOUBLE_WIDER.
* configure.ac (AC_TYPE_LONG_DOUBLE_WIDER): New.
* tests/t-printf.c (check_large_float): Fix a typo.
[!HAVE_LONG_DOUBLE_WIDER]: Skip the LDBL_MAX test.
--
GnuPG-bug-id: 8309
Signed-off-by: NIIBE Yutaka <gniibe@fsij.org>
diff --git a/configure.ac b/configure.ac
index e9abe0d..7871769 100644
--- a/configure.ac
+++ b/configure.ac
@@ -276,6 +276,7 @@ AC_C_CONST
AC_CHECK_SIZEOF(int)
AC_CHECK_SIZEOF(long)
AC_CHECK_SIZEOF(long long)
+AC_TYPE_LONG_DOUBLE_WIDER
GNUPG_FUNC_MKDIR_TAKES_ONE_ARG
diff --git a/tests/t-printf.c b/tests/t-printf.c
index 6cbd03f..b0a3f3f 100644
--- a/tests/t-printf.c
+++ b/tests/t-printf.c
@@ -449,7 +449,7 @@ check_large_float (void)
errno, strerror (errno));
}
else if (verbose)
- show ("format \"%%.100f\" with DBL_MAX: ->%s<-\n", buf2);
+ show ("format \"%%.101f\" with DBL_MAX: ->%s<-\n", buf2);
if (strcmp (buf, buf2))
fail ("format \"%%.100f\" does not match \"%%.101f\"\n" );
@@ -469,6 +469,7 @@ check_large_float (void)
show ("format \"%%.100Lf\" with DBL_MAX: ->%s<-\n", buf);
gpgrt_free (buf);
+# ifdef HAVE_LONG_DOUBLE_WIDER
ld = LDBL_MAX;
buf = gpgrt_bsprintf ("%.100Lf\n", ld);
if (buf)
@@ -478,6 +479,10 @@ check_large_float (void)
else if (verbose)
show ("format \"%%.100Lf\" with LDBL_MAX failed as expected\n");
gpgrt_free (buf);
+# else
+ if (verbose)
+ show ("LDBL_MAX == DBL_MAX - skipping LDBL_MAX test\n");
+# endif
#endif /*HAVE_LONG_DOUBLE*/
}

View File

@@ -1,6 +1,7 @@
{
stdenv,
lib,
autoreconfHook,
buildPackages,
fetchurl,
gettext,
@@ -32,6 +33,12 @@ stdenv.mkDerivation (
hash = "sha256-eoVBPyvDVPT4qoMrcYrxIuSJZeng65AS7mWcE8Y4XJM=";
};
patches = [
# Fixes t-printf test on platforms where LDBL_MAX == DBL_MAX (armhf, ppc64)
# Upstream's git forge doesn't seem to have a nice way to download it :/
./libgpg-error-tests-skip-a-test-when-not-HAVE_LONG_DOUBLE_WIDER.patch
];
postPatch = ''
sed '/BUILD_TIMESTAMP=/s/=.*/=1970-01-01T00:01+0000/' -i ./configure
''
@@ -39,6 +46,17 @@ stdenv.mkDerivation (
# so add one for FreeBSD.
+ lib.optionalString (stdenv.hostPlatform.system == "x86_64-freebsd") ''
cp ${./lock-obj-pub.x86_64-unknown-freebsd.h} src/syscfg/lock-obj-pub.freebsd.h
''
# Fails on powerpc64-linux
# https://lists.gnupg.org/pipermail/gnupg-users/2026-July/068440.html
+ lib.optionalString (stdenv.hostPlatform.isPower64 && stdenv.hostPlatform.isBigEndian) ''
substituteInPlace tests/t-printf.c \
--replace-fail \
'# ifdef HAVE_LONG_DOUBLE_WIDER' \
'# if 0' \
--replace-fail \
'show ("LDBL_MAX == DBL_MAX - skipping LDBL_MAX test\n")' \
'show ("LDBL_MAX is weird on this platform - skipping LDBL_MAX test\n")'
'';
hardeningDisable = [ "strictflexarrays3" ];
@@ -58,7 +76,10 @@ stdenv.mkDerivation (
# If architecture-dependent MO files aren't available, they're generated
# during build, so we need gettext for cross-builds.
depsBuildBuild = [ buildPackages.stdenv.cc ];
nativeBuildInputs = [ gettext ];
nativeBuildInputs = [
autoreconfHook # HAVE_LONG_DOUBLE_WIDER patch changes configure.ac
gettext
];
postConfigure =
# For some reason, /bin/sh on OpenIndiana leads to this at the end of the

View File

@@ -8,13 +8,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "libmysofa";
version = "1.3.3";
version = "1.3.4";
src = fetchFromGitHub {
owner = "hoene";
repo = "libmysofa";
rev = "v${finalAttrs.version}";
hash = "sha256-jvib1hGPJEY2w/KjlD7iTtRy1s8LFG+Qhb2d6xdpUyc=";
hash = "sha256-gP/RjKzMx8JIYcyiivBGvy3kIdwHMEKY6abssyVUKNQ=";
};
outputs = [

View File

@@ -100,6 +100,17 @@ let
moveToOutput "share/man/man1/nc.1.gz" "$nc"
'';
doInstallCheck = true;
installCheckPhase = ''
runHook preInstallCheck
# Check whether the build target actually contains our cacert.
# A simple binary match for the path is enough.
grep "${cacert}/etc/ssl/certs/ca-bundle.crt" $out/lib/*libtls*
runHook postInstallCheck
'';
meta = {
description = "Free TLS/SSL implementation";
homepage = "https://www.libressl.org";
@@ -139,6 +150,13 @@ let
url = "https://github.com/libressl/portable/commit/a15ea0710398eaeed3be53cf643e80a1e80c981d.patch";
hash = "sha256-Mlf4SrGCCqALQicbGtmVGdkdfcE8DEGYkOuVyG2CozM=";
};
# https://github.com/libressl/portable/issues/1295
# https://github.com/libressl/portable/pull/1303
tls-default-ca-patch = fetchpatch {
url = "https://github.com/libressl/portable/commit/c85e07d0d68129fc1b1c9039b266099c8d735c3d.patch";
hash = "sha256-oNL3v8Ef1HrayXn+/3T4UhHLJos8eVMlqebVyaxnWVo=";
};
in
{
# 4.2 was released October 2025 and will become unsupported on October 22,
@@ -148,6 +166,7 @@ in
hash = "sha256-bVwvWFg1iOp5H0yGRQBAcdAN+lVKW/eIoAbKHrWr1ws=";
patches = [
common-cmake-install-full-dirs-patch
tls-default-ca-patch
];
};
@@ -156,5 +175,8 @@ in
libressl_4_3 = generic {
version = "4.3.2";
hash = "sha256-7fAa7iTGXWnmqe/LnUS82mgv+dTzu72V55Th36kIR7U=";
patches = [
tls-default-ca-patch
];
};
}

View File

@@ -9,13 +9,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "libsodium";
version = "1.0.22-unstable-2026-04-16";
version = "1.0.22-unstable-2026-07-08";
src = fetchFromGitHub {
owner = "jedisct1";
repo = "libsodium";
rev = "33cc75ab1565d9dcbe808354191bd572ad6b64d0";
hash = "sha256-8kS9FBoaFaJOjH7XZc8IG3GaQaUiYD/awQOhs7j0n1Y=";
rev = "77a422c85a3b8b487de50c811b38d18394831ba6";
hash = "sha256-Ahka2PnrmYvTLjZMzik5mFsxhDpMLRMKT/I5ftUb0Xc=";
};
outputs = [

View File

@@ -19,11 +19,11 @@
stdenv.mkDerivation (finalAttrs: {
pname = "libssh";
version = "0.12.0";
version = "0.12.1";
src = fetchurl {
url = "https://www.libssh.org/files/${lib.versions.majorMinor finalAttrs.version}/libssh-${finalAttrs.version}.tar.xz";
hash = "sha256-Gmr0JNgyfl7t705f5/W5JCJt1hesnz3oDyF9gqNqcSE=";
hash = "sha256-05Qa8KLXjV2C7Xo2mI6RM5lDEvA1uWWabkP42zloeEw=";
};
outputs = [

View File

@@ -51,6 +51,18 @@ stdenv.mkDerivation (finalAttrs: {
url = "https://salsa.debian.org/debian/libssh2/-/raw/1d4906e6ebe85a9da2931ba33677ead96a61f07f/debian/patches/libssh-unconst-backport.patch";
hash = "sha256-jc01Fb70GbaD9+RYeSjRaLFBtKLiMPTMuXas21aC0Ag=";
})
# https://github.com/libssh2/libssh2/issues/1925#issuecomment-4938515829
(fetchurl {
name = "CVE-2026-58050.patch";
url = "https://raw.githubusercontent.com/JuliaPackaging/Yggdrasil/9404aa5dd96c945a790c425a5f49af19ed2a93b0/L/LibSSH2/LibSSH2%401.11/bundled/patches/CVE-2026-58050-3449752.patch";
hash = "sha256-BZ1ewZgrroev2gkJwdoHCMFJK4wiRmA/Y4tzwaQqBd8=";
})
(fetchurl {
name = "CVE-2026-58051.patch";
url = "https://github.com/JuliaPackaging/Yggdrasil/raw/9404aa5dd96c945a790c425a5f49af19ed2a93b0/L/LibSSH2/LibSSH2%401.11/bundled/patches/CVE-2026-58051-a9758da.patch";
hash = "sha256-fduXIH02uwzqWV2RDidZmaDBy51V8yuC4XKlGYacjxg=";
})
];
# this could be accomplished by updateAutotoolsGnuConfigScriptsHook, but that causes infinite recursion
@@ -83,6 +95,5 @@ stdenv.mkDerivation (finalAttrs: {
homepage = "https://www.libssh2.org";
platforms = lib.platforms.all;
license = lib.licenses.bsd3;
maintainers = with lib.maintainers; [ SuperSandro2000 ];
};
})

View File

@@ -7,14 +7,14 @@
elfutils,
}:
stdenv.mkDerivation {
stdenv.mkDerivation (finalAttrs: {
pname = "libsystemtap";
version = "5.3";
version = "5.5";
src = fetchgit {
url = "git://sourceware.org/git/systemtap.git";
rev = "release-5.3";
hash = "sha256-W9iJ+hyowqgeq1hGcNQbvPfHpqY0Yt2W/Ng/4p6asxc=";
rev = "release-${finalAttrs.version}";
hash = "sha256-olN98hjIYZmQvI7Fn1v5ZwRl7yaCAPRGr2g33oMq7VQ=";
};
dontBuild = true;
@@ -43,4 +43,4 @@ stdenv.mkDerivation {
badPlatforms = elfutils.meta.badPlatforms or [ ];
maintainers = [ lib.maintainers.workflow ];
};
}
})

View File

@@ -37,13 +37,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "libtiff";
version = "4.7.1";
version = "4.7.2";
src = fetchFromGitLab {
owner = "libtiff";
repo = "libtiff";
rev = "v${finalAttrs.version}";
hash = "sha256-UiC6s86i7UavW86EKm74oPVlEacvoKmwW7KETjpnNaI=";
hash = "sha256-60Lpg5WRfWMzlOoOUA+C6KLlYIZ+3BjXidOVqv4M2GA=";
};
patches = [

View File

@@ -5,8 +5,8 @@
}:
callPackage ./generic.nix {
version = "4.1.0";
hash = "sha256-TA1uka13So8URttw+JJVdKIL+IonkhIQSc0IfraXpIM=";
version = "4.2.0";
hash = "sha256-Xz5W5zYPNlASPyc1/Sz2O1LONdxpUkg1hgzKdax/3ag=";
patches = [
# Fixes the build with GCC 14 on aarch64.

View File

@@ -6,8 +6,8 @@
}:
callPackage ./generic.nix {
version = "3.6.6";
hash = "sha256-+PW41/c8M/Yz0EVWM4Gt4HTNBMUTU5MayaKVZ+upLIo=";
version = "3.6.7";
hash = "sha256-t1ZPeFA3ftKaEIaXQ7RXZEsiOAYK4KSSm55SFr9g17A=";
patches = [
# Fixes the build with GCC 14 on aarch64.

View File

@@ -57,11 +57,11 @@ let
in
stdenv.mkDerivation (finalAttrs: {
pname = "musl";
version = "1.2.5";
version = "1.2.6";
src = fetchurl {
url = "https://musl.libc.org/releases/musl-${finalAttrs.version}.tar.gz";
sha256 = "qaEYu+hNh2TaDqDSizqz+uhHf8fkCF2QECuFlvx8deQ=";
hash = "sha256-1YX9O2E8ZhUfwySejtRPdwIMtebB5jWmFtP5+CRgUSo=";
};
enableParallelBuilding = true;
@@ -85,27 +85,15 @@ stdenv.mkDerivation (finalAttrs: {
sha256 = "0hfadrycb60sm6hb6by4ycgaqc9sgrhh42k39v8xpmcvdzxrsq2n";
})
(fetchurl {
name = "CVE-2025-26519_0.patch";
url = "https://www.openwall.com/lists/musl/2025/02/13/1/1";
hash = "sha256-CJb821El2dByP04WXxPCCYMOcEWnXLpOhYBgg3y3KS4=";
name = "CVE-2026-6042";
url = "https://www.openwall.com/lists/musl/2026/04/03/2/1";
hash = "sha256-RE+nDlLKFY+31LrVYGN3kLv49y6AuC//hA3Wb6gwkeM=";
})
(fetchurl {
name = "CVE-2025-26519_1.patch";
url = "https://www.openwall.com/lists/musl/2025/02/13/1/2";
hash = "sha256-BiD87k6KTlLr4ep14rUdIZfr2iQkicBYaSTq+p6WBqE=";
name = "CVE-2026-40200.patch";
url = "https://www.openwall.com/lists/musl/2026/04/10/3/1";
hash = "sha256-HuKfZPnKjorXw0l3nWYf9rUhJqJ1ddNYaYE1elLEBvs=";
})
# required for systemd user namespacing and oomd to work correctly on musl
# drop next release
# https://git.musl-libc.org/cgit/musl/commit/?id=fde29c04adbab9d5b081bf6717b5458188647f1c
./stdio-skip-empty-iovec-when-buffering-is-disabled.patch
# Backport addition of statx fields needed by systemd
./statx.patch
# Backport addition of statx attrs needed by systemd
./statx-attr.patch
# Backport even more statx stuff for systemd
./statx-linux-6.11.patch
# Backport addition of renameat2 syscall wrapper needed by systemd
./renameat2.patch
];
env = {

View File

@@ -1,55 +0,0 @@
From 05ce67fea99ca09cd4b6625cff7aec9cc222dd5a Mon Sep 17 00:00:00 2001
From: Tony Ambardar <tony.ambardar@gmail.com>
Date: Mon, 6 May 2024 20:28:32 -0700
Subject: add renameat2 linux syscall wrapper
This syscall is available since Linux 3.15 and also implemented in
glibc from version 2.28. It is commonly used in filesystem or security
contexts.
Constants RENAME_NOREPLACE, RENAME_EXCHANGE, RENAME_WHITEOUT are
guarded by _GNU_SOURCE as with glibc.
---
include/stdio.h | 7 +++++++
src/linux/renameat2.c | 11 +++++++++++
2 files changed, 18 insertions(+)
create mode 100644 src/linux/renameat2.c
diff --git a/include/stdio.h b/include/stdio.h
index cb858618..4ea4c170 100644
--- a/include/stdio.h
+++ b/include/stdio.h
@@ -158,6 +158,13 @@ char *ctermid(char *);
#define L_ctermid 20
#endif
+#if defined(_GNU_SOURCE)
+#define RENAME_NOREPLACE (1 << 0)
+#define RENAME_EXCHANGE (1 << 1)
+#define RENAME_WHITEOUT (1 << 2)
+
+int renameat2(int, const char *, int, const char *, unsigned);
+#endif
#if defined(_XOPEN_SOURCE) || defined(_GNU_SOURCE) \
|| defined(_BSD_SOURCE)
diff --git a/src/linux/renameat2.c b/src/linux/renameat2.c
new file mode 100644
index 00000000..b8060388
--- /dev/null
+++ b/src/linux/renameat2.c
@@ -0,0 +1,11 @@
+#define _GNU_SOURCE
+#include <stdio.h>
+#include "syscall.h"
+
+int renameat2(int oldfd, const char *old, int newfd, const char *new, unsigned flags)
+{
+#ifdef SYS_renameat
+ if (!flags) return syscall(SYS_renameat, oldfd, old, newfd, new);
+#endif
+ return syscall(SYS_renameat2, oldfd, old, newfd, new, flags);
+}
--
cgit v1.2.1

View File

@@ -1,35 +0,0 @@
From cbf1c7b605d979bb7fdde8b8e6a66acdba18c6b0 Mon Sep 17 00:00:00 2001
From: Rich Felker <dalias@aerifal.cx>
Date: Wed, 24 Apr 2024 13:26:03 -0400
Subject: add missing STATX_ATTR_* macros omitted when statx was added
commit b817541f1cfd38e4b81257b3215e276ea9d0fc61 added statx and the
mask constant macros, but not the stx_attributes[_mask] ones.
---
include/sys/stat.h | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/include/sys/stat.h b/include/sys/stat.h
index 6690192d..57d640d7 100644
--- a/include/sys/stat.h
+++ b/include/sys/stat.h
@@ -121,6 +121,16 @@ int lchmod(const char *, mode_t);
#define STATX_BTIME 0x800U
#define STATX_ALL 0xfffU
+#define STATX_ATTR_COMPRESSED 0x4
+#define STATX_ATTR_IMMUTABLE 0x10
+#define STATX_ATTR_APPEND 0x20
+#define STATX_ATTR_NODUMP 0x40
+#define STATX_ATTR_ENCRYPTED 0x800
+#define STATX_ATTR_AUTOMOUNT 0x1000
+#define STATX_ATTR_MOUNT_ROOT 0x2000
+#define STATX_ATTR_VERITY 0x100000
+#define STATX_ATTR_DAX 0x200000
+
struct statx_timestamp {
int64_t tv_sec;
uint32_t tv_nsec, __pad;
--
cgit v1.2.1

View File

@@ -1,49 +0,0 @@
From fcdff46a3203400e08a2264c34b3c7fb62bf6969 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?J=2E=20Neusch=C3=A4fer?= <j.neuschaefer@gmx.net>
Date: Thu, 24 Oct 2024 01:19:30 +0200
Subject: statx: add Linux 6.11 fields/constants
As of Linux 6.11, these fields and mask macros have been added to
include/uapi/linux/stat.h.
---
include/sys/stat.h | 10 +++++++++-
1 file changed, 9 insertions(+), 1 deletion(-)
diff --git a/include/sys/stat.h b/include/sys/stat.h
index c924ce2f..4f7dc2b1 100644
--- a/include/sys/stat.h
+++ b/include/sys/stat.h
@@ -123,6 +123,8 @@ int lchmod(const char *, mode_t);
#define STATX_MNT_ID 0x1000U
#define STATX_DIOALIGN 0x2000U
#define STATX_MNT_ID_UNIQUE 0x4000U
+#define STATX_SUBVOL 0x8000U
+#define STATX_WRITE_ATOMIC 0x10000U
#define STATX_ATTR_COMPRESSED 0x4
#define STATX_ATTR_IMMUTABLE 0x10
@@ -133,6 +135,7 @@ int lchmod(const char *, mode_t);
#define STATX_ATTR_MOUNT_ROOT 0x2000
#define STATX_ATTR_VERITY 0x100000
#define STATX_ATTR_DAX 0x200000
+#define STATX_ATTR_WRITE_ATOMIC 0x400000
struct statx_timestamp {
int64_t tv_sec;
@@ -164,7 +167,12 @@ struct statx {
uint32_t stx_dio_mem_align;
uint32_t stx_dio_offset_align;
uint64_t stx_subvol;
- uint64_t __pad1[11];
+ uint32_t stx_atomic_write_unit_min;
+ uint32_t stx_atomic_write_unit_max;
+ uint32_t stx_atomic_write_segments_max;
+ uint32_t __pad1[1];
+ uint64_t __pad2[9];
+
};
int statx(int, const char *__restrict, int, unsigned, struct statx *__restrict);
--
cgit v1.2.1

View File

@@ -1,39 +0,0 @@
From 23ab04a8630225371455d5f4538fd078665bb646 Mon Sep 17 00:00:00 2001
From: Rich Felker <dalias@aerifal.cx>
Date: Fri, 13 Sep 2024 17:21:17 -0400
Subject: statx: add new struct statx fields and corresponding mask macros
---
include/sys/stat.h | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git a/include/sys/stat.h b/include/sys/stat.h
index 57d640d7..0c10dc21 100644
--- a/include/sys/stat.h
+++ b/include/sys/stat.h
@@ -120,6 +120,9 @@ int lchmod(const char *, mode_t);
#define STATX_BASIC_STATS 0x7ffU
#define STATX_BTIME 0x800U
#define STATX_ALL 0xfffU
+#define STATX_MNT_ID 0x1000U
+#define STATX_DIOALIGN 0x2000U
+#define STATX_MNT_ID_UNIQUE 0x4000U
#define STATX_ATTR_COMPRESSED 0x4
#define STATX_ATTR_IMMUTABLE 0x10
@@ -157,7 +160,11 @@ struct statx {
uint32_t stx_rdev_minor;
uint32_t stx_dev_major;
uint32_t stx_dev_minor;
- uint64_t __pad1[14];
+ uint64_t stx_mnt_id;
+ uint32_t stx_dio_mem_align;
+ uint32_t stx_dio_offet_align;
+ uint64_t stx_subvol;
+ uint64_t __pad1[11];
};
int statx(int, const char *__restrict, int, unsigned, struct statx *__restrict);
--
cgit v1.2.1

View File

@@ -1,31 +0,0 @@
From fde29c04adbab9d5b081bf6717b5458188647f1c Mon Sep 17 00:00:00 2001
From: Casey Connolly <kcxt@postmarketos.org>
Date: Wed, 23 Apr 2025 15:06:48 +0200
Subject: stdio: skip empty iovec when buffering is disabled
When buffering on a FILE is disabled we still send both iovecs, even
though the first one is always empty. Clean things up by skipping the
empty iovec instead.
---
src/stdio/__stdio_write.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/src/stdio/__stdio_write.c b/src/stdio/__stdio_write.c
index d2d89475..5356553d 100644
--- a/src/stdio/__stdio_write.c
+++ b/src/stdio/__stdio_write.c
@@ -11,6 +11,11 @@ size_t __stdio_write(FILE *f, const unsigned char *buf, size_t len)
size_t rem = iov[0].iov_len + iov[1].iov_len;
int iovcnt = 2;
ssize_t cnt;
+
+ if (!iov->iov_len) {
+ iov++;
+ iovcnt--;
+ }
for (;;) {
cnt = syscall(SYS_writev, f->fd, iov, iovcnt);
if (cnt == rem) {
--
cgit v1.2.1

View File

@@ -0,0 +1,17 @@
Description: Add libnetsnmpaget link to libnetsnmptrapd
Causes a linking issue otherwise
Author: Craig Small <csmall@debian.org>
Reviewed-by: Craig Small <csmall@debian.org>
Last-Update: 2023-08-19
---
--- a/apps/Makefile.in
+++ b/apps/Makefile.in
@@ -237,7 +237,7 @@
$(LINK) ${CFLAGS} -o $@ snmppcap.$(OSUFFIX) ${LDFLAGS} ${USEAGENTLIBS} ${LIBS} -lpcap
libnetsnmptrapd.$(LIB_EXTENSION)$(LIB_VERSION): $(LLIBTRAPD_OBJS)
- $(LIB_LD_CMD) $@ ${LLIBTRAPD_OBJS} $(MIBLIB) $(MYSQL_LIBS) $(USELIBS) $(PERLLDOPTS_FOR_LIBS) $(LDFLAGS)
+ $(LIB_LD_CMD) $@ ${LLIBTRAPD_OBJS} $(MIBLIB) $(MYSQL_LIBS) $(USELIBS) $(USEAGENTLIBS) $(PERLLDOPTS_FOR_LIBS) $(LDFLAGS)
$(RANLIB) $@
snmpinforminstall:

View File

@@ -29,6 +29,11 @@ stdenv.mkDerivation (finalAttrs: {
hash = "sha256-FnB3GfgzGEpLcoNdrDWa4YgSOwa15CgXwAeQ19wThL8=";
};
patches = [
# https://salsa.debian.org/debian/net-snmp/-/blob/master/debian/patches/makefile_trap_needs_agent, vendored because of Anubis
./link-error.patch
];
outputs = [
"bin"
"out"

View File

@@ -21,7 +21,7 @@ stdenv.mkDerivation (finalAttrs: {
# Determine version and revision from:
# https://sourceforge.net/p/netpbm/code/HEAD/log/?path=/advanced
pname = "netpbm";
version = "11.15.1";
version = "11.15.3";
outputs = [
"bin"
@@ -31,8 +31,8 @@ stdenv.mkDerivation (finalAttrs: {
src = fetchsvn {
url = "https://svn.code.sf.net/p/netpbm/code/advanced";
rev = "5227";
sha256 = "sha256-Lr02cu7OAPv+wjKjPkA0wyZ0VvurUuCf5IJXjmCAE0I=";
rev = "5264";
sha256 = "sha256-5G2OitW25ZNsdBcVkKfLpFJWjTm9VcB3ca0QllOSugI=";
};
nativeBuildInputs = [

View File

@@ -7,13 +7,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "nextvi";
version = "7.0";
version = "7.1";
src = fetchFromGitHub {
owner = "kyx0r";
repo = "nextvi";
tag = finalAttrs.version;
hash = "sha256-corF/cPmkCkpqg2UVLrMHL33pgp3ffBohbQzq95b+Ws=";
hash = "sha256-2GvSnTV+NUACDvJq0WtpvoQpDBlPmrYBWjKsMHpVB+s=";
};
nativeBuildInputs = [ installShellFiles ];

View File

@@ -16,13 +16,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "nvc";
version = "1.22.0";
version = "1.22.1";
src = fetchFromGitHub {
owner = "nickg";
repo = "nvc";
tag = "r${finalAttrs.version}";
hash = "sha256-Z8N4TskOak7tU3Kp5BfUahoXsP/LnCLx5mhAuXwG7qI=";
hash = "sha256-FA9GzfwsQRI3OOJQ54H8+JbgVtIz2F4xncVDUHRzgRA=";
};
nativeBuildInputs = [

View File

@@ -76,6 +76,9 @@ stdenv.mkDerivation (finalAttrs: {
cmakeFlags = [
(lib.cmakeBool "TBB_DISABLE_HWLOC_AUTOMATIC_SEARCH" false)
# Treating compiler errors as warnings creates churn each compiler update,
# and provides little utility to us downstream.
(lib.cmakeBool "TBB_STRICT" false)
(lib.cmakeBool "TBB_TEST" finalAttrs.finalPackage.doCheck)
]
++ lib.optionals stdenv.hostPlatform.isDarwin [
@@ -83,10 +86,6 @@ stdenv.mkDerivation (finalAttrs: {
];
env = {
# Fix build with modern gcc
# In member function 'void std::__atomic_base<_IntTp>::store(__int_type, std::memory_order) [with _ITp = bool]',
NIX_CFLAGS_COMPILE = lib.optionalString stdenv.cc.isGNU "-Wno-error=stringop-overflow";
# Fix undefined reference errors with version script under LLVM.
NIX_LDFLAGS = lib.optionalString (
stdenv.cc.bintools.isLLVM && lib.versionAtLeast stdenv.cc.bintools.version "17"

View File

@@ -25,8 +25,6 @@
buildPackages,
gobject-introspection,
testers,
# TODO: Clean up on `staging`.
llvmPackages,
}:
stdenv.mkDerivation (finalAttrs: {
@@ -60,10 +58,6 @@ stdenv.mkDerivation (finalAttrs: {
++ lib.optionals withIntrospection [
gi-docgen
gobject-introspection
]
# TODO: Clean up on `staging`.
++ lib.optionals stdenv.hostPlatform.isDarwin [
llvmPackages.lld
];
buildInputs = [
@@ -89,17 +83,8 @@ stdenv.mkDerivation (finalAttrs: {
];
# Fontconfig error: Cannot load default config file
env = {
FONTCONFIG_FILE = makeFontsConf {
fontDirectories = [ freefont_ttf ];
};
}
// lib.optionalAttrs stdenv.hostPlatform.isDarwin {
# workaround for ld64 hardening issue
#
# TODO: Clean up on `staging`
CC_LD = "lld";
OBJC_LD = "lld";
env.FONTCONFIG_FILE = makeFontsConf {
fontDirectories = [ freefont_ttf ];
};
# Run-time dependency gi-docgen found: NO (tried pkgconfig and cmake)

View File

@@ -100,6 +100,7 @@ pythonPackages.buildPythonApplication (finalAttrs: {
"redis"
"torch"
"zxing-cpp"
"zxing-cpp"
# requested by maintainer
"imap-tools"
"ocrmypdf"

View File

@@ -27,13 +27,13 @@
let
pname = "plezy";
version = "2.10.0";
version = "2.11.0";
src = fetchFromGitHub {
owner = "edde746";
repo = "plezy";
tag = version;
hash = "sha256-82OPOad3ti+5Eec8U3vEJaAE12+ViQb+P7ZhMhEplL8=";
hash = "sha256-nv2hYuPZEUkmcM7sVzmcKZm17CHjxmEWlXLdCPKFXU0=";
};
simdutf = fetchurl {
@@ -146,7 +146,7 @@ let
src = fetchurl {
url = "https://github.com/edde746/plezy/releases/download/${version}/plezy-macos.dmg";
hash = "sha256-lwO34G2w4hAju06z3/HwI3Tq7dHhgWZD4HxShby8OYg=";
hash = "sha256-cqanTS+PSsdtg9AF/yiVezq8ydgNfVdXEN8DHRLByM8=";
};
nativeBuildInputs = [

View File

@@ -14,18 +14,18 @@
}:
buildGo127Module (finalAttrs: {
pname = "pocket-id";
version = "2.11.0";
version = "2.12.0";
src = fetchFromGitHub {
owner = "pocket-id";
repo = "pocket-id";
tag = "v${finalAttrs.version}";
hash = "sha256-keib2ebju6hKlH1XJQRBmXwxBsUnVZOIs+djvYkXYqU=";
hash = "sha256-n9yqZs8RlgJk+NByRJ7a+HRY4YkQNNH7xY02BSy/RhE=";
};
sourceRoot = "${finalAttrs.src.name}/backend";
vendorHash = "sha256-/5lXAnb2FHeGBgrpU4Jpt2KX+sgGyYH61odppTaulbs=";
vendorHash = "sha256-BGIF9ZhPAJrUvX1cahe3EyWM3QLIfkkZaChaBign7io=";
env.CGO_ENABLED = 0;
ldflags = [
@@ -67,7 +67,7 @@ buildGo127Module (finalAttrs: {
inherit (finalAttrs) pname version src;
pnpm = pnpm_10;
fetcherVersion = 4;
hash = "sha256-aJq5yLeeHY7zlOgSr1bOJCL8e1HBwCmoL7nTD2a06tg=";
hash = "sha256-iXWR3idBiafZXCrt1M7UCJQJsA+IL2AU6pRJI7MdY1E=";
};
env.BUILD_OUTPUT_PATH = "dist";
@@ -107,6 +107,7 @@ buildGo127Module (finalAttrs: {
marcusramberg
tmarkus
ymstnt
esch
];
platforms = lib.platforms.unix;
};

View File

@@ -0,0 +1,34 @@
diff --git a/CMakePresets.json b/CMakePresets.json
index d12d71eb5..d337e7339 100644
--- a/CMakePresets.json
+++ b/CMakePresets.json
@@ -9,11 +9,7 @@
{
"name": "base",
"hidden": true,
- "binaryDir": "${sourceDir}/build/build_${presetName}",
- "cacheVariables": {
- "CMAKE_C_COMPILER": "clang",
- "CMAKE_CXX_COMPILER": "clang++"
- }
+ "binaryDir": "${sourceDir}/build/build_${presetName}"
},
{
"name": "native",
diff --git a/lib/CMakePresets.json b/lib/CMakePresets.json
index 12d797b87..92196d931 100644
--- a/lib/CMakePresets.json
+++ b/lib/CMakePresets.json
@@ -19,11 +19,7 @@
{
"name": "libs",
"displayName": "Vendored LLVM + support libraries (clang)",
- "inherits": "libs-base",
- "cacheVariables": {
- "CMAKE_C_COMPILER": "clang",
- "CMAKE_CXX_COMPILER": "clang++"
- }
+ "inherits": "libs-base"
},
{
"name": "libs-windows-x86-64",

View File

@@ -1,41 +1,80 @@
From c1283b82daff94ebac21fc20cb8df0b05aa080f8 Mon Sep 17 00:00:00 2001
From: Morgan Jones <me@numin.it>
Date: Fri, 22 May 2026 23:06:52 -0700
Subject: [PATCH] net: disable networking tests
---
packages/net/_test.pony | 18 ------------------
1 file changed, 18 deletions(-)
diff --git a/packages/net/_test.pony b/packages/net/_test.pony
index 1d7b2d6f..69cbeea6 100644
index 081ce67a0..99942c05e 100644
--- a/packages/net/_test.pony
+++ b/packages/net/_test.pony
@@ -20,24 +20,6 @@ actor \nodoc\ Main is TestList
@@ -26,14 +26,14 @@ actor \nodoc\ Main is TestList
fun tag tests(test: PonyTest) =>
// Tests below function across all systems and are listed alphabetically
- test(_TestDNSBroadcastIP4)
- test(_TestDNSBroadcastIP6)
- test(_TestDNSUnresolvableEmpty)
- test(_TestMulticastIP4)
- test(_TestMulticastIP6)
- test(_TestNetAddressIP6Scope)
- test(_TestNetAddressNameRoundTripIP4)
- test(_TestNetAddressNameRoundTripIP6)
+// test(_TestDNSBroadcastIP4)
+// test(_TestDNSBroadcastIP6)
+// test(_TestDNSUnresolvableEmpty)
+// test(_TestMulticastIP4)
+// test(_TestMulticastIP6)
+// test(_TestNetAddressIP6Scope)
+// test(_TestNetAddressNameRoundTripIP4)
+// test(_TestNetAddressNameRoundTripIP6)
test(_TestOsIpString)
test(_TestSocketResultDecoder)
test(_TestTCPConnectionFailed)
- test(_TestTCPExpect)
- test(_TestTCPExpectOverBufferSize)
- test(_TestTCPExpectSetToZero)
- test(_TestTCPMute)
- test(_TestTCPProxy)
- test(_TestTCPUnmute)
- test(_TestTCPWritev)
-
- // Tests below exclude windows and are listed alphabetically
- ifdef not windows then
- test(_TestTCPConnectionToClosedServerFailed)
- test(_TestTCPThrottle)
@@ -48,36 +48,36 @@ actor \nodoc\ Main is TestList
test(_TestTCPThrottle)
test(_TestTCPUnmute)
test(_TestTCPWritev)
- test(_TestUDPEmptyDatagramDelivered)
+// test(_TestUDPEmptyDatagramDelivered)
test(_TestUDPListenFailure)
- test(_TestUDPOversizedDatagramTruncated)
- test(_TestUDPUndersizedDatagramDelivered)
- test(_TestUDPZeroSizeReadBufferDelivers)
+// test(_TestUDPOversizedDatagramTruncated)
+// test(_TestUDPUndersizedDatagramDelivered)
+// test(_TestUDPZeroSizeReadBufferDelivers)
test(_TestUnicastIP6Loopback)
// The deterministic send-failure trigger (send to broadcast without
// SO_BROADCAST -> EACCES/WSAEACCES) is verified on linux and windows.
- ifdef linux or windows then
- test(_TestUDPCloseOnSendFailure)
- end
-
- // Tests below exclude osx and are listed alphabetically
+// ifdef linux or windows then
+// test(_TestUDPCloseOnSendFailure)
+// end
// Tests below run only on linux and are listed alphabetically
- ifdef linux then
- test(_TestBroadcastReceive)
- end
+// ifdef linux then
+// test(_TestBroadcastReceive)
+// end
// Tests below exclude osx and are listed alphabetically
- ifdef not osx then
- test(_TestBroadcast)
- end
+// ifdef not osx then
+// test(_TestBroadcast)
+// end
// Tests below exclude osx and bsd and are listed alphabetically.
// They read IPv4 multicast options back with getsockopt_u32, which
// expects a 4-byte value; osx and bsd return these options as a 1-byte
// u_char, so the read-back fails there regardless of correctness.
- ifdef (not osx) and (not bsd) then
- test(_TestMulticastSockopt)
- end
+// ifdef (not osx) and (not bsd) then
+// test(_TestMulticastSockopt)
+// end
class \nodoc\ _TestPing is UDPNotify
let _h: TestHelper
--
2.53.0

View File

@@ -1,26 +0,0 @@
From 77d703b11d298f6be88b04f7e8ca85de139e82be Mon Sep 17 00:00:00 2001
From: Morgan Jones <me@numin.it>
Date: Mon, 5 May 2025 20:34:02 -0700
Subject: [PATCH] process: disable KillLongRunningChild test
---
packages/process/_test.pony | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/packages/process/_test.pony b/packages/process/_test.pony
index fe9fdb04..756588f9 100644
--- a/packages/process/_test.pony
+++ b/packages/process/_test.pony
@@ -18,7 +18,8 @@ actor \nodoc\ Main is TestList
test(_TestChdir)
test(_TestExpect)
test(_TestFileExecCapabilityIsRequired)
- test(_TestKillLongRunningChild)
+ // (@booxter/@numinit) Appears to be flaky.
+ // test(_TestKillLongRunningChild)
test(_TestLongRunningChild)
test(_TestNonExecutablePathResultsInExecveError)
test(_TestPrintvOrdering)
--
2.47.0

View File

@@ -1,13 +0,0 @@
diff --git a/src/libponyc/codegen/genexe.cc b/src/libponyc/codegen/genexe.cc
index 3f0348eaa1..76b03030bf 100644
--- a/src/libponyc/codegen/genexe.cc
+++ b/src/libponyc/codegen/genexe.cc
@@ -308,7 +308,7 @@
snprintf(ld_cmd, ld_len,
"%s -execute -arch %.*s "
"-o %s %s %s %s "
- "-L/Library/Developer/CommandLineTools/SDKs/MacOSX.sdk/usr/lib -lSystem %s -platform_version macos '" STR(PONY_OSX_PLATFORM) "' '0.0.0'",
+ "-L\"${SDKROOT:-${DEVELOPER_DIR:-@apple-sdk@}/Platforms/MacOSX.platform/Developer/SDKs/MacOSX.sdk}/usr/lib\" -lSystem %s -platform_version macos '" STR(PONY_OSX_PLATFORM) "' '0.0.0'",
linker, (int)arch_len, c->opt->triple, file_exe, file_o,
lib_args, ponyrt, sanitizer_arg
);

View File

@@ -0,0 +1,61 @@
diff --git a/src/libponyc/codegen/gencshim.cc b/src/libponyc/codegen/gencshim.cc
index a1722ad01a22..db742c6adaa5 100644
--- a/src/libponyc/codegen/gencshim.cc
+++ b/src/libponyc/codegen/gencshim.cc
@@ -7,6 +7,7 @@
#include "../ast/stringtab.h"
#include "paths.h"
#include "ponyassert.h"
+#include "nix.h"
#ifdef _MSC_VER
# pragma warning(push)
@@ -307,8 +308,11 @@ static const char* find_macos_sdk_include(pass_opt_t* opt)
pclose(f);
}
+ // Fall back to the Nix apple-sdk when xcrun is unavailable, mirroring the
+ // link side in genexe.cc. The unversioned MacOSX.sdk symlink keeps this
+ // independent of the SDK version.
const char* fallback =
- "/Library/Developer/CommandLineTools/SDKs/MacOSX.sdk/usr/include";
+ "@apple-sdk@/Platforms/MacOSX.platform/Developer/SDKs/MacOSX.sdk/usr/include";
if(dir_exists(fallback))
{
@@ -349,6 +353,25 @@ static bool push_isystem(pass_opt_t* opt, std::vector<const char*>& args,
}
+/*
+ Add the Nix header search directories (see nix.h) as -internal-isystem
+ entries. push_isystem skips any directory that doesn't exist, so a partial
+ toolchain degrades gracefully.
+*/
+static bool add_nix_include_dirs(pass_opt_t* opt,
+ std::vector<const char*>& args, errors_t* errors)
+{
+ std::vector<const char*> dirs;
+ nix_collect_include_dirs(opt->strtab, dirs);
+
+ bool any = false;
+ for(size_t i = 0; i < dirs.size(); i++)
+ any |= push_isystem(opt, args, errors, "-internal-isystem", dirs[i], "");
+
+ return any;
+}
+
+
// System include directories for the target, derived from the same sysroot
// the embedded linker uses — hand-rolled like LLD rather than driven through
// clang's Driver, so the headers the shim compiles against stay consistent
@@ -488,6 +511,9 @@ static bool add_system_include_args(pass_opt_t* opt, const char* sysroot,
any |= push_isystem(opt, args, errors, "-internal-externc-isystem",
sysroot, "/usr/include");
+ if(sysroot[0] == '\0')
+ any |= add_nix_include_dirs(opt, args, errors);
+
// Per-directory skipping is right (multiarch and /usr/local are
// legitimately absent on many systems), but an explicit --sysroot that
// yields nothing at all deserves a direct answer, like the macOS branch

View File

@@ -1,26 +1,158 @@
From ac4b2a65f997f7f779b9c63dbe683ba10a26fc7f Mon Sep 17 00:00:00 2001
From: Morgan Jones <me@numin.it>
Date: Fri, 22 May 2026 23:58:29 -0700
Subject: [PATCH] genexe: take PONY_LINKER into account
---
src/libponyc/codegen/genexe.cc | 3 +++
1 file changed, 3 insertions(+)
diff --git a/src/libponyc/codegen/genexe.cc b/src/libponyc/codegen/genexe.cc
index 48f97578..5b9f36f1 100644
index 826d69f0bcba..897afba953bb 100644
--- a/src/libponyc/codegen/genexe.cc
+++ b/src/libponyc/codegen/genexe.cc
@@ -1448,6 +1448,9 @@ static bool link_exe(compile_t* c, ast_t* program,
{
errors_t* errors = c->opt->check.errors;
@@ -22,6 +22,7 @@ LLD_HAS_DRIVER(wasm)
#include "../type/lookup.h"
#include "../../libponyrt/mem/pool.h"
#include "ponyassert.h"
+#include "nix.h"
#include <string.h>
+ if(c->opt->linker == NULL)
+ c->opt->linker = getenv("PONY_LINKER");
#include <llvm/Support/raw_ostream.h>
@@ -38,6 +39,8 @@ LLD_HAS_DRIVER(wasm)
# include <llvm/TargetParser/Triple.h>
#endif
+static bool dir_has_arch_libc_crt(const char* dir, uint16_t target_machine);
+
// Use embedded LLD for Linux, macOS, and Windows targets unless --linker
// escape hatch is specified. Sanitizer builds fall back to the system
// compiler driver for native compilation since sanitizer runtime libraries
--
2.53.0
#if defined(PONY_SANITIZER)
// Generated at configure time (top-level CMakeLists.txt, PONY_SANITIZERS_ENABLED
// block): the sanitizer runtime link fragment captured from the compiler driver.
@@ -965,6 +968,9 @@ static bool link_exe_lld_elf(compile_t* c, ast_t* program,
program_lib_build_args_embedded(program, c->opt);
+ std::vector<const char*> env_libdirs;
+ nix_collect_link_libdirs(c->opt->strtab, env_libdirs);
+
const char* sys_triple = system_triple(c->opt);
bool is_freebsd = target_is_freebsd(c->opt->triple);
bool is_dragonfly = target_is_dragonfly(c->opt->triple);
@@ -996,7 +1002,11 @@ static bool link_exe_lld_elf(compile_t* c, ast_t* program,
return false;
}
- const char* dynlinker = dynamic_linker_path(c);
+ // Prefer a Nix-provided ELF interpreter (baked default or environment);
+ // fall back to the built-in FHS search when none is configured.
+ const char* dynlinker = nix_dynamic_linker(c->opt->strtab);
+ if(dynlinker[0] == '\0')
+ dynlinker = dynamic_linker_path(c);
if(!c->opt->staticbin && dynlinker == NULL)
{
errorf(errors, NULL,
@@ -1009,10 +1019,23 @@ static bool link_exe_lld_elf(compile_t* c, ast_t* program,
const char* libc_crt_dir = find_libc_crt_dir(sysroot, sys_triple,
target_machine, c->opt->strtab);
if(libc_crt_dir == NULL)
+ {
+ for(size_t i = 0; i < env_libdirs.size(); i++)
+ {
+ if(dir_has_arch_libc_crt(env_libdirs[i], target_machine))
+ {
+ libc_crt_dir = env_libdirs[i];
+ break;
+ }
+ }
+ }
+ if(libc_crt_dir == NULL)
{
errorf(errors, NULL,
"could not find a libc crt startup object (crt1.o or crt0.o) "
- "matching target architecture '%s' in sysroot '%s'",
+ "matching target architecture '%s' in sysroot '%s'\n"
+ " On NixOS systems, set PONY_LINK_LIBDIRS to the directory holding "
+ "the arch-matching libc startup object (crt1.o or crt0.o).",
c->opt->triple, sysroot);
return false;
}
@@ -1305,6 +1328,21 @@ static bool link_exe_lld_elf(compile_t* c, ast_t* program,
}
}
+/*
+ Add /nix/store lib directories to the embedded linker args
+*/
+ for(size_t i = 0; i < env_libdirs.size(); i++)
+ {
+ snprintf(buf, sizeof(buf), "-L%s", env_libdirs[i]);
+ args.push_back(stringtab(c->opt->strtab, buf));
+
+ if(!c->opt->staticbin)
+ {
+ args.push_back("-rpath");
+ args.push_back(env_libdirs[i]);
+ }
+ }
+
// Standard system library fallback paths. The paths above cover
// distro-specific locations (libc_crt_dir, gcc_lib_dir, etc.) but miss
// common install locations like /usr/local/lib (where libraries built
@@ -1732,9 +1770,10 @@ static const char* find_macos_sdk_path(strtable_t* strtab)
pclose(f);
}
- // Hardcoded fallback.
+ // Fall back to the Nix apple-sdk when xcrun is unavailable. The unversioned
+ // MacOSX.sdk symlink keeps this independent of the SDK version.
const char* fallback =
- "/Library/Developer/CommandLineTools/SDKs/MacOSX.sdk/usr/lib";
+ "@apple-sdk@/Platforms/MacOSX.platform/Developer/SDKs/MacOSX.sdk/usr/lib";
struct stat st;
if(stat(fallback, &st) == 0 && S_ISDIR(st.st_mode))
@@ -1947,6 +1986,31 @@ static bool link_exe_lld_macho(compile_t* c, ast_t* program,
}
}
+/*
+ Add /nix/store lib directories to the embedded Mach-O linker args, mirroring
+ the ELF path. On NixOS the C++ standard library, buildInputs and user FFI
+ libraries live under /nix/store, not in the SDK's usr/lib or the Homebrew and
+ /usr/local fallbacks above. nix_collect_link_libdirs() (see nix.h) gathers
+ them from the baked PONY_NIX_LINK_LIBDIRS default, the PONY_LINK_LIBDIRS /
+ NIX_LDFLAGS env vars, and the cc-wrapper's $NIX_CC/nix-support/cc-ldflags
+ (which carries the -L<libc++> path on Darwin). Without this,
+ `use "lib:c++" if osx` (as used by pony-compiler) fails to link with
+ "library not found for -lc++".
+*/
+ std::vector<const char*> env_libdirs;
+ nix_collect_link_libdirs(c->opt->strtab, env_libdirs);
+ for(size_t i = 0; i < env_libdirs.size(); i++)
+ {
+ snprintf(buf, sizeof(buf), "-L%s", env_libdirs[i]);
+ args.push_back(stringtab(c->opt->strtab, buf));
+
+ if(!c->opt->staticbin)
+ {
+ args.push_back("-rpath");
+ args.push_back(env_libdirs[i]);
+ }
+ }
+
// Object file.
args.push_back(file_o);
@@ -2417,3 +2481,21 @@ bool genexe(compile_t* c, ast_t* program)
return true;
}
+
+// Does `dir` hold a libc startup object (crt1.o / crt0.o) whose ELF machine
+// matches the target? Used to pick the crt directory out of the Nix libdirs
+// gathered by nix_collect_link_libdirs().
+static bool dir_has_arch_libc_crt(const char* dir, uint16_t target_machine)
+{
+ static const char* sentinels[] = { "crt1.o", "crt0.o" };
+ char buf[PATH_MAX];
+
+ for(size_t j = 0; j < sizeof(sentinels) / sizeof(sentinels[0]); j++)
+ {
+ snprintf(buf, sizeof(buf), "%s/%s", dir, sentinels[j]);
+ if(file_exists(buf) && elf_matches_target(buf, target_machine))
+ return true;
+ }
+
+ return false;
+}

View File

@@ -0,0 +1,291 @@
diff --git a/src/libponyc/codegen/nix.h b/src/libponyc/codegen/nix.h
new file mode 100644
index 000000000000..b1368f222b91
--- /dev/null
+++ b/src/libponyc/codegen/nix.h
@@ -0,0 +1,47 @@
+#ifndef CODEGEN_NIX_H
+#define CODEGEN_NIX_H
+
+#include "../ast/stringtab.h"
+
+#include <vector>
+
+/*
+ Nix/NixOS toolchain path discovery for the embedded LLD linker (genexe.cc)
+ and the embedded clang C-shim compiler (gencshim.cc).
+
+ On Nix there is no FHS layout: no /usr/lib, no /lib64/ld-linux-*.so, no
+ /usr/include. The libc, libgcc, C++ runtime, buildInputs and user FFI
+ libraries all live under /nix/store, and their locations reach the compiler
+ through baked-in defaults (the -DPONY_NIX_* macros set at configure time) and
+ the cc-wrapper environment (NIX_LDFLAGS, NIX_CFLAGS_COMPILE,
+ $NIX_CC/nix-support/*). These helpers gather those paths so the embedded
+ tools link and compile without a wrapper script.
+
+ On a plain non-Nix build every source is empty, so the collectors append
+ nothing and behaviour is unchanged.
+*/
+
+// Library search directories for the linker, in priority order:
+// PONY_NIX_LINK_LIBDIRS (baked default), PONY_LINK_LIBDIRS, NIX_LDFLAGS,
+// NIX_LDFLAGS_BEFORE, $NIX_CC/nix-support {orig-libc, cc-ldflags}.
+// Directories are interned into `strtab` and appended to `dirs`; existing
+// entries are left in place.
+void nix_collect_link_libdirs(strtable_t* strtab,
+ std::vector<const char*>& dirs);
+
+// Header search directories for the C-shim compiler, in priority order:
+// PONY_NIX_INCLUDE_DIRS (baked default), PONY_INCLUDE_DIRS,
+// NIX_CFLAGS_COMPILE, $NIX_CC/nix-support/libc-cflags.
+// Directories are interned into `strtab` and appended to `dirs`; existing
+// entries are left in place.
+void nix_collect_include_dirs(strtable_t* strtab,
+ std::vector<const char*>& dirs);
+
+// The ELF dynamic linker (interpreter) path, in priority order:
+// PONY_DYNAMIC_LINKER, PONY_NIX_DYNAMIC_LINKER (baked default),
+// $NIX_CC/nix-support/dynamic-linker.
+// Returns "" (never NULL) when none is configured, so the caller can test the
+// first byte and fall back to the built-in FHS search.
+const char* nix_dynamic_linker(strtable_t* strtab);
+
+#endif
diff --git a/src/libponyc/codegen/nix.cc b/src/libponyc/codegen/nix.cc
new file mode 100644
index 000000000000..eddfd7833103
--- /dev/null
+++ b/src/libponyc/codegen/nix.cc
@@ -0,0 +1,220 @@
+#include "nix.h"
+
+#include "../ast/stringtab.h"
+
+#include <limits.h>
+#include <stdio.h>
+#include <stdlib.h>
+#include <string.h>
+
+#ifndef PATH_MAX
+# define PATH_MAX 4096
+#endif
+
+/*
+ The baked-in Nix defaults. package.nix passes each of these through
+ -DPONY_NIX_*="..." in NIX_CFLAGS_COMPILE at configure time, capturing the
+ cc-wrapper's libc/libgcc/pcre2/openssl lib dirs, the ELF interpreter and the
+ libc/gcc include dirs. They are empty strings on a plain source build, which
+ disables every Nix-specific path below.
+*/
+#ifndef PONY_NIX_LINK_LIBDIRS
+# define PONY_NIX_LINK_LIBDIRS ""
+#endif
+#ifndef PONY_NIX_DYNAMIC_LINKER
+# define PONY_NIX_DYNAMIC_LINKER ""
+#endif
+#ifndef PONY_NIX_INCLUDE_DIRS
+# define PONY_NIX_INCLUDE_DIRS ""
+#endif
+
+/*
+ Split `s` into tokens on any delimiter character in `delims`, interning each
+ token into `strtab` and appending it to `toks`. A token that would overflow
+ the buffer is dropped whole rather than truncated to a wrong path.
+*/
+static void tokenize(const char* s, const char* delims, strtable_t* strtab,
+ std::vector<const char*>& toks)
+{
+ if(s == NULL || s[0] == '\0')
+ return;
+
+ char buf[PATH_MAX];
+ size_t len = 0;
+ bool overflow = false;
+ for(const char* p = s; ; p++)
+ {
+ // The '\0' test is first so strchr is never asked to match the terminator.
+ if(*p == '\0' || strchr(delims, *p) != NULL)
+ {
+ if(len > 0 && !overflow)
+ {
+ buf[len] = '\0';
+ toks.push_back(stringtab(strtab, buf));
+ }
+ len = 0;
+ overflow = false;
+ if(*p == '\0')
+ break;
+ }
+ else if(len < sizeof(buf) - 1)
+ {
+ buf[len++] = *p;
+ }
+ else
+ {
+ overflow = true;
+ }
+ }
+}
+
+/*
+ Interpret a whitespace-separated linker-flag string (NIX_LDFLAGS,
+ $NIX_CC/nix-support/cc-ldflags) for library directories, handling the joined
+ -L<dir>, the separated -L <dir>, and -rpath / -rpath-link <dir> forms.
+
+ This is how /nix/store libraries (and directories injected by pkg-config) are
+ found where other distros would look in /usr/lib and the like.
+*/
+static void append_ldflags_dirs(const char* flags, strtable_t* strtab,
+ std::vector<const char*>& dirs)
+{
+ std::vector<const char*> toks;
+ tokenize(flags, " \t\n\r", strtab, toks);
+
+ for(size_t i = 0; i < toks.size(); i++)
+ {
+ const char* t = toks[i];
+ if(strncmp(t, "-L", 2) == 0)
+ {
+ if(t[2] != '\0')
+ dirs.push_back(stringtab(strtab, t + 2));
+ else if(i + 1 < toks.size())
+ dirs.push_back(toks[++i]);
+ }
+ else if(strcmp(t, "-rpath") == 0 || strcmp(t, "-rpath-link") == 0)
+ {
+ if(i + 1 < toks.size())
+ dirs.push_back(toks[++i]);
+ }
+ }
+}
+
+/*
+ Interpret a whitespace-separated compiler-flag string (NIX_CFLAGS_COMPILE,
+ $NIX_CC/nix-support/libc-cflags) for header search directories, handling the
+ joined -I<dir>, the separated -I <dir>, and -isystem / -idirafter / -iquote
+ <dir> forms. This covers directories injected by pkg-config too.
+*/
+static void append_cflags_include_dirs(const char* flags, strtable_t* strtab,
+ std::vector<const char*>& dirs)
+{
+ std::vector<const char*> toks;
+ tokenize(flags, " \t\n\r", strtab, toks);
+
+ for(size_t i = 0; i < toks.size(); i++)
+ {
+ const char* t = toks[i];
+ if(strcmp(t, "-isystem") == 0 || strcmp(t, "-idirafter") == 0 ||
+ strcmp(t, "-iquote") == 0 || strcmp(t, "-I") == 0)
+ {
+ if(i + 1 < toks.size())
+ dirs.push_back(toks[++i]);
+ }
+ else if(strncmp(t, "-I", 2) == 0 && t[2] != '\0')
+ {
+ dirs.push_back(stringtab(strtab, t + 2));
+ }
+ }
+}
+
+/*
+ Read $NIX_CC/nix-support/<name> into `out`, trimming trailing whitespace.
+ Returns false if the file is missing, empty, or so long it would be
+ truncated -- acting on a partial flag string would be worse than ignoring it.
+*/
+static bool read_nix_support_file(const char* nix_cc, const char* name,
+ char* out, size_t outsz)
+{
+ char path[PATH_MAX];
+ snprintf(path, sizeof(path), "%s/nix-support/%s", nix_cc, name);
+
+ FILE* f = fopen(path, "rb");
+ if(f == NULL)
+ return false;
+
+ size_t n = fread(out, 1, outsz - 1, f);
+ // If the buffer filled and the file still has bytes, the content was
+ // truncated; reject it rather than acting on a partial flag string.
+ bool truncated = (n == outsz - 1) && (fgetc(f) != EOF);
+ fclose(f);
+ if(truncated)
+ return false;
+ out[n] = '\0';
+
+ while(n > 0 && (out[n - 1] == '\n' || out[n - 1] == '\r' ||
+ out[n - 1] == ' ' || out[n - 1] == '\t'))
+ out[--n] = '\0';
+
+ return n > 0;
+}
+
+void nix_collect_link_libdirs(strtable_t* strtab,
+ std::vector<const char*>& dirs)
+{
+ tokenize(PONY_NIX_LINK_LIBDIRS, ":", strtab, dirs);
+ tokenize(getenv("PONY_LINK_LIBDIRS"), ":", strtab, dirs);
+ append_ldflags_dirs(getenv("NIX_LDFLAGS"), strtab, dirs);
+ append_ldflags_dirs(getenv("NIX_LDFLAGS_BEFORE"), strtab, dirs);
+
+ const char* nix_cc = getenv("NIX_CC");
+ if(nix_cc == NULL || nix_cc[0] == '\0')
+ return;
+
+ char buf[PATH_MAX];
+ if(read_nix_support_file(nix_cc, "orig-libc", buf, sizeof(buf)))
+ {
+ char libdir[PATH_MAX];
+ snprintf(libdir, sizeof(libdir), "%s/lib", buf);
+ dirs.push_back(stringtab(strtab, libdir));
+ }
+
+ if(read_nix_support_file(nix_cc, "cc-ldflags", buf, sizeof(buf)))
+ append_ldflags_dirs(buf, strtab, dirs);
+}
+
+void nix_collect_include_dirs(strtable_t* strtab,
+ std::vector<const char*>& dirs)
+{
+ tokenize(PONY_NIX_INCLUDE_DIRS, ":", strtab, dirs);
+ tokenize(getenv("PONY_INCLUDE_DIRS"), ":", strtab, dirs);
+ append_cflags_include_dirs(getenv("NIX_CFLAGS_COMPILE"), strtab, dirs);
+
+ const char* nix_cc = getenv("NIX_CC");
+ if(nix_cc != NULL && nix_cc[0] != '\0')
+ {
+ char cflags[PATH_MAX * 4];
+ if(read_nix_support_file(nix_cc, "libc-cflags", cflags, sizeof(cflags)))
+ append_cflags_include_dirs(cflags, strtab, dirs);
+ }
+}
+
+const char* nix_dynamic_linker(strtable_t* strtab)
+{
+ const char* dl = getenv("PONY_DYNAMIC_LINKER");
+ if(dl != NULL && dl[0] != '\0')
+ return stringtab(strtab, dl);
+
+ if(PONY_NIX_DYNAMIC_LINKER[0] != '\0')
+ return stringtab(strtab, PONY_NIX_DYNAMIC_LINKER);
+
+ const char* nix_cc = getenv("NIX_CC");
+ if(nix_cc != NULL && nix_cc[0] != '\0')
+ {
+ char buf[PATH_MAX];
+ if(read_nix_support_file(nix_cc, "dynamic-linker", buf, sizeof(buf)))
+ return stringtab(strtab, buf);
+ }
+
+ return "";
+}
diff --git a/src/libponyc/CMakeLists.txt b/src/libponyc/CMakeLists.txt
index f4e3e42ef48f..4a477e306ac1 100644
--- a/src/libponyc/CMakeLists.txt
+++ b/src/libponyc/CMakeLists.txt
@@ -27,6 +27,7 @@ add_library(libponyc STATIC
codegen/gendesc.c
codegen/gencshim.cc
codegen/genexe.cc
+ codegen/nix.cc
codegen/genexpr.c
codegen/genfun.c
codegen/genheader.c

View File

@@ -7,14 +7,11 @@
cmake,
coreutils,
libxml2,
lto ? true,
makeWrapper,
openssl,
pcre2,
pony-corral,
python3,
zlib,
# Not really used for anything real, just at build time.
git,
replaceVars,
which,
@@ -25,13 +22,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "ponyc";
version = "0.64.0";
version = "0.67.0";
src = fetchFromGitHub {
owner = "ponylang";
repo = "ponyc";
tag = finalAttrs.version;
hash = "sha256-CdsfJO+7y7nvlDdCXdWRB4vmP9pB1Jz5CVwJuha+yds=";
hash = "sha256-9X2xaQ5nCV/sTL3WjXNDswIfNhlwgfV4/X70p1zTd2U=";
fetchSubmodules = true;
};
@@ -53,7 +50,6 @@ stdenv.mkDerivation (finalAttrs: {
nativeBuildInputs = [
cmake
makeWrapper
which
python3
git
@@ -64,23 +60,36 @@ stdenv.mkDerivation (finalAttrs: {
buildInputs = [
libxml2
openssl
pcre2
z3
zlib
];
patches = [
./cmake-presets.patch
# Sandbox disallows network access, so disabling problematic networking tests
./disable-networking-tests.patch
./disable-process-tests.patch
# Take PONY_LINKER into account
./genexe-pony-linker.patch
# Adds codegen/nix.cc + nix.h (the Nix toolchain-path helpers shared by the
# embedded linker and C-shim compiler) and wires them into libponyc's
# CMakeLists. Platform-independent, so applied verbatim everywhere.
./nix-codegen.patch
]
++ lib.optionals stdenv.hostPlatform.isDarwin [
(replaceVars ./fix-darwin-build.patch {
inherit apple-sdk;
})
];
++ (
let
# These patch the embedded LLD/clang codegen and reference the macOS SDK
# via @apple-sdk@; substitute it on Darwin, apply verbatim elsewhere (the
# placeholder sits in macOS-only code that other platforms never compile).
sdkPatches = [
./gencshim-pony-cc.patch
./genexe-pony-linker.patch
];
in
if stdenv.hostPlatform.isDarwin then
map (p: replaceVars p { inherit apple-sdk; }) sdkPatches
else
sdkPatches
);
postUnpack = ''
mkdir -p $NIX_BUILD_TOP/deps
@@ -88,8 +97,6 @@ stdenv.mkDerivation (finalAttrs: {
tar -C "$googletest" -cf $NIX_BUILD_TOP/deps/googletest-$googletestRev.tar .
'';
dontConfigure = true;
postPatch = ''
substituteInPlace packages/process/_test.pony \
--replace-fail '"/bin/' '"${coreutils}/bin/' \
@@ -105,8 +112,7 @@ stdenv.mkDerivation (finalAttrs: {
'';
# We do not concern ourselves with darwin as the ponyc compiler
# has logic which overrides this environmental variable in this
# case.
# has logic which overrides this environment variable.
env.arch =
if stdenv.hostPlatform.isx86_64 then
"x86-64"
@@ -118,32 +124,41 @@ stdenv.mkDerivation (finalAttrs: {
this may result in crashes on incompatible CPUs!
'' "native";
preBuild = ''
extraFlags=(build_flags=-j$NIX_BUILD_CORES)
''
+ lib.optionalString stdenv.hostPlatform.isLinux ''
export PONY_LINKER="$CC"
''
+ lib.optionalString stdenv.hostPlatform.isDarwin ''
export PONY_LINKER=ld
''
+ lib.optionalString stdenv.hostPlatform.isAarch64 ''
# See this relnote about building on Raspbian:
# https://github.com/ponylang/ponyc/blob/0.46.0/.release-notes/0.45.2.md
extraFlags+=(pic_flag=-fPIC)
''
+ ''
make libs "''${extraFlags[@]}"
make configure "''${extraFlags[@]}"
# Bake the Nix link/include paths into the compiler before it is built.
preConfigure =
lib.optionalString stdenv.hostPlatform.isLinux ''
libcDir=$(dirname "$($CC -print-file-name=crt1.o)")
gccDir=$(dirname "$($CC -print-libgcc-file-name)")
gccSharedDir=$(dirname "$($CC -print-file-name=libgcc_s.so)")
dynamicLinker=$(cat "$NIX_CC/nix-support/dynamic-linker")
libcIncDir="$(cat "$NIX_CC/nix-support/orig-libc-dev")/include"
# pcre2 and openssl are baked into the compiler's link path so an installed
# ponyc can link `use "regex"` (pcre2) and `use "net/ssl"` (openssl)
# programs without a wrapper — this replaces the old wrapProgram PONYPATH.
export NIX_CFLAGS_COMPILE="$NIX_CFLAGS_COMPILE -DPONY_NIX_LINK_LIBDIRS=\"$libcDir:$gccDir:$gccSharedDir:${lib.getLib pcre2}/lib:${lib.getLib openssl}/lib\" -DPONY_NIX_DYNAMIC_LINKER=\"$dynamicLinker\" -DPONY_NIX_INCLUDE_DIRS=\"$libcIncDir:$gccDir/include:$gccDir/include-fixed\""
''
+ lib.optionalString stdenv.hostPlatform.isDarwin ''
# Bake pcre2/openssl into the compiler's link path so an installed ponyc can
# link `use "regex"` / `use "net/ssl"` without a wrapper; libc and the C++
# standard library come from the SDK (via xcrun / apple-sdk) at link time.
export NIX_CFLAGS_COMPILE="$NIX_CFLAGS_COMPILE -DPONY_NIX_LINK_LIBDIRS=\"${lib.getLib pcre2}/lib:${lib.getLib openssl}/lib\""
'';
# Upstream drives the build through CMakePresets (which fix the binaryDir and
# compiler), so we bypass the cmake setup hook's configurePhase and invoke the
# presets directly rather than fight its flags.
configurePhase = ''
runHook preConfigure
cmake -DJOBS=$NIX_BUILD_CORES -P lib/build-libs.cmake
cmake --preset release
runHook postConfigure
'';
enableParallelBuilding = true;
makeFlags = [
"PONYC_VERSION=${finalAttrs.version}"
"prefix=${placeholder "out"}"
]
++ lib.optionals stdenv.hostPlatform.isDarwin ([ "bits=64" ] ++ lib.optional (!lto) "lto=no");
buildPhase = ''
runHook preBuild
cmake --build --preset release --parallel $NIX_BUILD_CORES
runHook postBuild
'';
env.NIX_CFLAGS_COMPILE = toString [
"-Wno-error=redundant-move"
@@ -152,35 +167,21 @@ stdenv.mkDerivation (finalAttrs: {
doCheck = true;
enableParallelChecking = true;
nativeCheckInputs = [ procps ];
installPhase = ''
makeArgs=(config=release prefix=$out)
''
+ lib.optionalString stdenv.hostPlatform.isDarwin ''
makeArgs+=(bits=64)
''
+ lib.optionalString (stdenv.hostPlatform.isDarwin && !lto) ''
makeArgs+=(lto=no)
''
+ ''
make "''${makeArgs[@]}" install
wrapProgram $out/bin/ponyc \
--prefix PATH ":" "${stdenv.cc}/bin" \
--set-default CC "$CC" \
--set-default PONY_LINKER "$PONY_LINKER" \
--prefix PONYPATH : "${
lib.makeLibraryPath [
pcre2
openssl
(placeholder "out")
]
}"
checkPhase = ''
runHook preCheck
ctest --preset release -L ci-core -j$NIX_BUILD_CORES
runHook postCheck
'';
# Stripping breaks linking for ponyc
installPhase = ''
runHook preInstall
cmake --install build/build_release --prefix=$out
runHook postInstall
'';
# Stripping breaks linking for ponyc.
dontStrip = true;
passthru = {
@@ -189,14 +190,17 @@ stdenv.mkDerivation (finalAttrs: {
};
meta = {
description = "Pony is an Object-oriented, actor-model, capabilities-secure, high performance programming language";
description = "Object-oriented, actor-model, capabilities-secure, high performance programming language";
homepage = "https://www.ponylang.io";
license = lib.licenses.bsd2;
mainProgram = "ponyc";
maintainers = with lib.maintainers; [
kamilchm
redvers
numinit
];
# Intel macOS (x86_64-darwin) is intentionally unsupported; only Apple
# Silicon is supported on Darwin.
platforms = [
"x86_64-linux"
"aarch64-linux"

View File

@@ -48,11 +48,11 @@ let
in
stdenvNoCC.mkDerivation (finalAttrs: {
pname = "PortfolioPerformance";
version = "0.86.0";
version = "0.86.1";
src = fetchurl {
url = "https://github.com/buchen/portfolio/releases/download/${finalAttrs.version}/PortfolioPerformance-${finalAttrs.version}-linux.gtk.x86_64.tar.gz";
hash = "sha256-7qSWHlHKIzqHO5iCbi+y0+u7OoIC9tUYL1e0mpAHAWM=";
hash = "sha256-iTHtIuSVapNc5ZckIIfDXYpMP2PiYLV8JojuqQ9nl9E=";
};
nativeBuildInputs = [

View File

@@ -13,16 +13,16 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "prek";
version = "0.4.4";
version = "0.4.10";
src = fetchFromGitHub {
owner = "j178";
repo = "prek";
tag = "v${finalAttrs.version}";
hash = "sha256-PAEmRQ5Vro83fkegOWsdY59U7WAQxBPSEalzxZV6K4o=";
hash = "sha256-tTr/Aob6jP1YL+n5vGkUkByew73WdP3mqLW5Lci1gNM=";
};
cargoHash = "sha256-EmlR6Lmt5XR0uS/y3FqY5yGNeVBSdtLtEGH9jZLcP2o=";
cargoHash = "sha256-He55uH7t7NI5sYgowujqCMK5yjhC2F+8ZLxKG6TLjYY=";
nativeBuildInputs = [
installShellFiles

View File

@@ -10,6 +10,7 @@
libzip,
cmocka,
ninja,
versionCheckHook,
nix-update-script,
}:
@@ -17,6 +18,9 @@ stdenv.mkDerivation (finalAttrs: {
pname = "qdl";
version = "2.7.1";
__structuredAttrs = true;
strictDeps = true;
src = fetchFromGitHub {
owner = "linux-msm";
repo = "qdl";
@@ -56,6 +60,9 @@ stdenv.mkDerivation (finalAttrs: {
enableParallelBuilding = true;
nativeInstallCheckInputs = [ versionCheckHook ];
doInstallCheck = true;
passthru.updateScript = nix-update-script { };
meta = {

View File

@@ -3,21 +3,21 @@
lib,
fetchFromGitHub,
meson,
cmake,
pkg-config,
systemd,
ninja,
nix-update-script,
}:
stdenv.mkDerivation (finalAttrs: {
pname = "qrtr";
version = "0-unstable-2025-03-01";
version = "1.2";
src = fetchFromGitHub {
owner = "linux-msm";
repo = "qrtr";
rev = "5923eea97377f4a3ed9121b358fd919e3659db7b";
hash = "sha256-iHjF/2SQsvB/qC/UykNITH/apcYSVD+n4xA0S/rIfnM=";
tag = "v${finalAttrs.version}";
hash = "sha256-plVPR3BKtMLSVgTK8TPFbt5vuo9ZovEGz6qJzUZ33G4=";
};
nativeBuildInputs = [
@@ -30,11 +30,13 @@ stdenv.mkDerivation (finalAttrs: {
installFlags = [ "prefix=$(out)" ];
passthru.updateScript = nix-update-script { };
meta = {
maintainers = with lib.maintainers; [ matthewcroughan ];
description = "QMI IDL compiler";
homepage = "https://github.com/linux-msm/qrtr";
license = lib.licenses.bsd3;
platforms = lib.platforms.aarch64;
platforms = [ "aarch64-linux" ];
};
})

View File

@@ -14,12 +14,12 @@
}:
buildGo126Module (finalAttrs: {
pname = "qui";
version = "1.23.0";
version = "1.24.0";
src = fetchFromGitHub {
owner = "autobrr";
repo = "qui";
tag = "v${finalAttrs.version}";
hash = "sha256-RprALTd610Krh1q5yr0HIbNwb8TDbUvgbFfMMrsJT+E=";
hash = "sha256-xtYHIM1xYg92EwHndpuSRSdg8aAjNc3xaBo+Uu6Zsf4=";
};
qui-web = stdenvNoCC.mkDerivation (finalAttrs': {
@@ -44,7 +44,7 @@ buildGo126Module (finalAttrs: {
;
pnpm = pnpm_11;
fetcherVersion = 4;
hash = "sha256-aty/BRc3WqdnN3yynH4EbyledU3NtKu9E+3vP4KAdsk=";
hash = "sha256-ajnOwiMBpNesn+4F+lNpdWO7VgK7O99xITVz4NjVWTE=";
};
postBuild = ''
@@ -56,7 +56,7 @@ buildGo126Module (finalAttrs: {
'';
});
vendorHash = "sha256-6DX2s/y5nHYI5Jz2zs+ROGM+xk4K5yTwEwGkNiYhlcc=";
vendorHash = "sha256-GxpYkRsPUVbVK8oKwwGM+AGNvfzT2pdUadX+pAmr7Bk=";
preBuild = ''
cp -r ${finalAttrs.qui-web}/* web/dist

View File

@@ -9,13 +9,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "s2n-tls";
version = "1.7.2";
version = "1.7.6";
src = fetchFromGitHub {
owner = "aws";
repo = "s2n-tls";
tag = "v${finalAttrs.version}";
hash = "sha256-oqWTcUGutEn5cOggiY1yPUlVWiHYKjnwBCCrEeWYn0A=";
hash = "sha256-ujKVtVioQP7RNyQ3hGVCNGanOpYlzTecerTdrsVtlUo=";
};
nativeBuildInputs = [ cmake ];

View File

@@ -24,16 +24,16 @@ let
in
buildNpmPackage (finalAttrs: {
pname = "shogihome";
version = "1.28.0";
version = "1.28.1";
src = fetchFromGitHub {
owner = "sunfish-shogi";
repo = "shogihome";
tag = "v${finalAttrs.version}";
hash = "sha256-icFWpyfdnm0wIkTVa2ijcnBcDmxrutV38vN3/8AY4cg=";
hash = "sha256-En2tH9AFBdhZsHoy/uiHf4RO3+gFkfwHnZAyDJ7FcoE=";
};
npmDepsHash = "sha256-SSpw8bBbf6saWwR3ZpqMrbrdjDJTCeARBAlHO65O+Zc=";
npmDepsHash = "sha256-9O/PQAGv0xg6dKgFHjErYTnaM2PxyUIZk8auiReSo2Q=";
postPatch = ''
substituteInPlace package.json \

View File

@@ -0,0 +1,30 @@
diff --git a/build/config/compiler/BUILD.gn b/build/config/compiler/BUILD.gn
index f977c9fed76e6f50c50351ca22128e8c8c8897b1..81460f3591b734f3354a6f9ac7bb0990e5b28889 100644
--- a/build/config/compiler/BUILD.gn
+++ b/build/config/compiler/BUILD.gn
@@ -589,7 +589,7 @@ config("compiler") {
# Flags for diagnostics.
cflags += [ "-fcolor-diagnostics" ]
if (!is_win) {
- cflags += [ "-fdiagnostics-show-inlining-chain" ]
+ cflags += [ ]
} else {
# Combine after https://github.com/llvm/llvm-project/pull/192241
cflags += [ "/clang:-fdiagnostics-show-inlining-chain" ]
@@ -1911,7 +1911,7 @@ config("clang_warning_suppression") {
# See also: https://crbug.com/40891132#comment10
ubsan_hardening("c_array_bounds") {
sanitizer = "array-bounds"
- condition = !(is_asan && target_cpu == "x86")
+ condition = false
# Because we've enabled array-bounds sanitizing we also want to suppress
# the related warning about "unsafe-buffer-usage-in-static-sized-array",
@@ -1925,6 +1925,7 @@ ubsan_hardening("c_array_bounds") {
# `NOTREACHED()` at the end of such functions.
ubsan_hardening("return") {
sanitizer = "return"
+ condition = false
}
config("rustc_revision") {

View File

@@ -15,23 +15,23 @@
}:
rustPlatform.buildRustPackage (finalAttrs: {
pname = "libsignal-node";
version = "0.96.3";
version = "0.97.3";
src = fetchFromGitHub {
owner = "signalapp";
repo = "libsignal";
tag = "v${finalAttrs.version}";
hash = "sha256-FOppsfocUvUfWa6AfBPOxAnntGJkzTbnPwqMzzbHnWQ=";
hash = "sha256-mRhArmrrbnAfj4JS4OqWA+FEC57Sf/BEqb95KL3JXp0=";
};
cargoHash = "sha256-wsXlCpNwO+E6rVNaD2R51Mi0sZUv2lhllGxDxzyptYA=";
cargoHash = "sha256-obv5XcGD4kkgTPShszxJRTFsOeig9UWyxdE8cyjbsCY=";
npmRoot = "node";
npmDeps = fetchNpmDeps {
name = "${finalAttrs.pname}-npm-deps";
inherit (finalAttrs) version src;
sourceRoot = "${finalAttrs.src.name}/${finalAttrs.npmRoot}";
hash = "sha256-p8udihRlXMTnG4BT60D2VlI7D/O3eHV/zCS7ucpeuO4=";
hash = "sha256-jTyEnJBEuL8RXT29VYsRW797FPgINm8BvVBmt3m13EA=";
};
nativeBuildInputs = [

View File

@@ -9,7 +9,7 @@
fetchPnpmDeps,
pnpmConfigHook,
pnpmBuildHook,
electron_42,
electron_43,
python3,
makeWrapper,
callPackage,
@@ -34,7 +34,7 @@ assert lib.warnIf (commandLineArgs != "")
let
nodejs = nodejs_24;
pnpm = pnpm_11;
electron = electron_42;
electron = electron_43;
libsignal-node = callPackage ./libsignal-node.nix { inherit nodejs; };
signal-sqlcipher = callPackage ./signal-sqlcipher.nix {
@@ -45,13 +45,13 @@ let
webrtc = callPackage ./webrtc.nix { };
ringrtc = callPackage ./ringrtc.nix { inherit webrtc; };
version = "8.18.0";
version = "8.21.0";
src = fetchFromGitHub {
owner = "signalapp";
repo = "Signal-Desktop";
tag = "v${version}";
hash = "sha256-fynCFGmch3UecT5esNfVVlf0+xDrCdCBGw2HMMqBzWw=";
hash = "sha256-RuGq8ygiZewKqtKQattlqU0pcMMlgdFOJAhmN4J/8Tw=";
# Emoji font files will be added in `postFetch` if `withAppleEmojis` is enabled. They
# are fetched separately below.
postFetch = ''
@@ -77,18 +77,13 @@ let
pname
src
version
postPatch
pnpmWorkspaces
;
inherit pnpm;
fetcherVersion = 4;
hash = "sha256-bWNs5W2NPk55Sm7UqwWvXU7bY+AXzevU3o2ji23HxtU=";
hash = "sha256-1n+u0mcZJwjkdKmNY6KE6tk6/UPYuya5WqLrKRJimGw=";
};
postPatch = ''
rm sticker-creator/pnpm-lock.yaml
'';
strictDeps = true;
nativeBuildInputs = [
nodejs
@@ -190,13 +185,13 @@ stdenv.mkDerivation (finalAttrs: {
;
inherit pnpm;
fetcherVersion = 4;
hash = "sha256-bWNs5W2NPk55Sm7UqwWvXU7bY+AXzevU3o2ji23HxtU=";
hash = "sha256-1n+u0mcZJwjkdKmNY6KE6tk6/UPYuya5WqLrKRJimGw=";
};
env = {
ELECTRON_SKIP_BINARY_DOWNLOAD = "1";
SIGNAL_ENV = "production";
SOURCE_DATE_EPOCH = 1783606680;
SOURCE_DATE_EPOCH = 1785418091;
};
preBuild = ''
@@ -259,6 +254,13 @@ stdenv.mkDerivation (finalAttrs: {
popd
test -f node_modules/@signalapp/windows-ucv/dist/index.js
# @signalapp/types is required at runtime by preload.wrapper.js, but its
# output is normally produced by the prepare script.
pushd packages/types
pnpm run build
popd
test -f node_modules/@signalapp/types/dist/index.std.cjs
cp -r ${electron.dist} electron-dist
chmod -R u+w electron-dist
cp -r ${sticker-creator} sticker-creator/dist

View File

@@ -2,13 +2,13 @@ diff --git a/app/AssetService.main.ts b/app/AssetService.main.ts
index a4a21b5bb..3d5ab1eb0 100644
--- a/app/AssetService.main.ts
+++ b/app/AssetService.main.ts
@@ -34,7 +34,6 @@ const OPTIONAL_ASSETS = new Map<string, string>([]);
@@ -34,7 +34,2 @@ const OPTIONAL_ASSETS = new Map<string, string>([]);
if (!process.mas) {
LOCAL_ASSETS.add('fonts/emoji.woff2');
-if (!process.mas) {
- LOCAL_ASSETS.add('fonts/emoji.woff2');
- OPTIONAL_ASSETS.set('optional-fonts/emoji-large.woff2', 'emoji-font.woff2');
}
-}
-
export class AssetService {
diff --git a/app/protocol_filter.node.ts b/app/protocol_filter.node.ts
index 17c68f0a4..4ed359de6 100644

View File

@@ -19,16 +19,16 @@ let
in
rustPlatform.buildRustPackage (finalAttrs: {
pname = "ringrtc";
version = "2.69.4";
version = "2.70.0";
src = fetchFromGitHub {
owner = "signalapp";
repo = "ringrtc";
tag = "v${finalAttrs.version}";
hash = "sha256-z/9Y9rrlH4yziEVAXrCmkmP42hdDm3frGJnL1O/qOqg=";
hash = "sha256-5RPX1SZhVJaSIDjdY2IvInwSI4YHs0y7TK1b9ixaeZc=";
};
cargoHash = "sha256-a6CEUVW1HXqgIp/S+4Ype83N3QtNCBrutiEepHNW5pY=";
cargoHash = "sha256-tztNtAGYHp+Kh98efwtt51yhRwhqDKeT06Q4B/HrHfQ=";
preConfigure = ''
# Check for matching webrtc version

View File

@@ -1,25 +1,25 @@
{
"src": {
"args": {
"hash": "sha256-kdRUqYFKsEbAR0u4btQc995vtbN+FVcei19PgTf1DyA=",
"hash": "sha256-icy7lsgHBofHMJg6Eo2jxkuo9vHVw6P8TXsti2416bg=",
"owner": "signalapp",
"repo": "webrtc",
"tag": "7778c"
"tag": "7871d"
},
"fetcher": "fetchFromGitHub"
},
"src/build": {
"args": {
"hash": "sha256-XmuuR4mLcaoAPCr82ka6ldtE4OmYFmXlWjNaP/wM2BQ=",
"rev": "dd54dd5186566a13bda647123c22540666b12ace",
"hash": "sha256-jY47j4gsrzQpNnQsTtb01CUMisejfqPgVsOyWLyI7iA=",
"rev": "d296a9fec6186f2c109758c7d3f93cbef936dfc3",
"url": "https://chromium.googlesource.com/chromium/src/build"
},
"fetcher": "fetchFromGitiles"
},
"src/buildtools": {
"args": {
"hash": "sha256-BvGCdJ3EgUZX6MC3jf86YNl4LzUxpxiptCEBv3bqBIo=",
"rev": "95ed44cf5f06dbb5861030b91c9db9ccb4316762",
"hash": "sha256-1xi58KhE/oErrrYnP/YKkWeA3dLfPtcTwbKcn6jr13o=",
"rev": "17495e454aae81b581e8b3caccbb53054509b280",
"url": "https://chromium.googlesource.com/chromium/src/buildtools"
},
"fetcher": "fetchFromGitiles"
@@ -35,40 +35,40 @@
},
"src/testing": {
"args": {
"hash": "sha256-tUh/eOrf71OjndY6p6IOJ5MFJUnuisDGWXJzsHHyrHs=",
"rev": "629b7bb6055714e23d8125bf790cfc8d94a94159",
"hash": "sha256-xUfuaftEKZr6GwBtZfAUW/uRkU1f+pJBdiFpGnJQPms=",
"rev": "5c19204b6395adfad25f83bbbd56439af9f86f7f",
"url": "https://chromium.googlesource.com/chromium/src/testing"
},
"fetcher": "fetchFromGitiles"
},
"src/third_party": {
"args": {
"hash": "sha256-sLMCkUCadVZIX5bTVovDd5tPn0ZB/CH/d0tQic8lEQg=",
"rev": "4923971b35e39f6bd9be8bc19c4680785a15c80d",
"hash": "sha256-BDOKJiCeO8g3gtSJYK1ZMKymq63BJX1L5EeWpvfCFFM=",
"rev": "7c92732938de0ef7e28f5da231994723f938f407",
"url": "https://chromium.googlesource.com/chromium/src/third_party"
},
"fetcher": "fetchFromGitiles"
},
"src/third_party/boringssl/src": {
"args": {
"hash": "sha256-OIaU7GoHYKq1ZyPaW/gLSKNq1ipw5nAgjqcPIFXtGwE=",
"rev": "8dce4fd20ab7e768c0a5103edc1d8cb7e54366ba",
"hash": "sha256-7pKQHAQ218OiuuSNsm1ZRUvUcft7QzUG++xH3y8fR9o=",
"rev": "f91f1447397c6719f9774dfb8e67329378e1f3d3",
"url": "https://boringssl.googlesource.com/boringssl.git"
},
"fetcher": "fetchFromGitiles"
},
"src/third_party/breakpad/breakpad": {
"args": {
"hash": "sha256-igcX5XwacIwoGbqIcZKwlJYpRWl9Uc32WdpXyHO7UVA=",
"rev": "8be0e3114685fcc1589561067282edf75ea1259a",
"hash": "sha256-JzGeACM7hXKhjFVFoeHqs9HfqDLm2OyWtjhU5lyKuFs=",
"rev": "6d017fa2c0c440f914385bb794fd88de90fef736",
"url": "https://chromium.googlesource.com/breakpad/breakpad.git"
},
"fetcher": "fetchFromGitiles"
},
"src/third_party/catapult": {
"args": {
"hash": "sha256-f57wYazKyGrjfzcQ7EVqwIG8p+bHLGK0Qb/tZERxwY8=",
"rev": "5a34891efa6e41c8aca8842386b8ee528963ffdf",
"hash": "sha256-XYufVvzOXD4voZUWUvumQQqLNsx9sy0QmQzNzrgNEWg=",
"rev": "2852bb7e91e4995502ffb72b7ed21412ee157914",
"url": "https://chromium.googlesource.com/catapult.git"
},
"fetcher": "fetchFromGitiles"
@@ -83,8 +83,8 @@
},
"src/third_party/clang-format/script": {
"args": {
"hash": "sha256-f+BbQ6xIubloSzx/MhPSZ8ymCskmS+9+epDGtPjZqXc=",
"rev": "c2725e0622e1a86d55f14514f2177a39efea4a0e",
"hash": "sha256-Cm6BOOlEyD0kdYxMSmk6Fj1Dnfs3zCzXsm+BOXgBme0=",
"rev": "6eddfb5ec5f92127a531eda66c568d3a11e7ec11",
"url": "https://chromium.googlesource.com/external/github.com/llvm/llvm-project/clang/tools/clang-format.git"
},
"fetcher": "fetchFromGitiles"
@@ -99,16 +99,16 @@
},
"src/third_party/compiler-rt/src": {
"args": {
"hash": "sha256-ay0gzhNjAah27LQd/i0ex6EcHEdqpsWBT9Tw510coRM=",
"rev": "bb7645f5e11c9c1d719a890fcb09ccfaaa14580f",
"hash": "sha256-PjH+E+6knLw0YSM7XpoC2taCkh89GQX1EDiviO4ZPPM=",
"rev": "b7f9fa6b211b362d3ca07ab2043419ebaf75d1d0",
"url": "https://chromium.googlesource.com/external/github.com/llvm/llvm-project/compiler-rt.git"
},
"fetcher": "fetchFromGitiles"
},
"src/third_party/cpuinfo/src": {
"args": {
"hash": "sha256-LnLtCMMRg+DwB7MijBdt/tmCKD/zN5y2oTgXlYw3hTg=",
"rev": "7607ca500436b37ad23fb8d18614bec7796b68a7",
"hash": "sha256-/QsOjDik0TnH3FnK7LOwsJkvX+O+2DRFX4eF3MxD3fc=",
"rev": "ea6b9f1bb6e1001d8b21574d5bc78ddef62e499d",
"url": "https://chromium.googlesource.com/external/github.com/pytorch/cpuinfo.git"
},
"fetcher": "fetchFromGitiles"
@@ -123,24 +123,24 @@
},
"src/third_party/dav1d/libdav1d": {
"args": {
"hash": "sha256-iKq6TYscIBK4ydv+0msNV3tcs82Ljk5ZNr954Qv2lII=",
"rev": "d69235dd804b24c04ed05639cffcc912cd6cfd75",
"hash": "sha256-uR6zXz1Nk75mKzw1M/MvcD33iV7SbVbncD08yhKdEm0=",
"rev": "1718ff9aded99f0a89f5c7940d6afb8948301e33",
"url": "https://chromium.googlesource.com/external/github.com/videolan/dav1d.git"
},
"fetcher": "fetchFromGitiles"
},
"src/third_party/depot_tools": {
"args": {
"hash": "sha256-r/mmibfbCBpV9reVbHc/S7FKffrtE729y2Mot/JsHgc=",
"rev": "ce1ebad2c35c9387186f01d77edeea28a254c955",
"hash": "sha256-/edPeYK0WF7AmfaTG2uC9ZFWE7DPn+NUs1tgnR3RzFs=",
"rev": "2f9bc10799af5aeb4a0ed903742ad69bb1d0ef75",
"url": "https://chromium.googlesource.com/chromium/tools/depot_tools.git"
},
"fetcher": "fetchFromGitiles"
},
"src/third_party/eigen3/src": {
"args": {
"hash": "sha256-/nzzcoJ87L7EVsRfAeok3UbxNKQeAWOFjmwZ3TYmGmI=",
"rev": "002229ce470065878afb7c2f6f96d22c9a9b7ba0",
"hash": "sha256-YjyAr1sTLF6zlNw9G0RL5kBApmRRYsHpUet3sCCsf14=",
"rev": "fc0f148ab491bf36378c5d527d8f6669ccf21b07",
"url": "https://chromium.googlesource.com/external/gitlab.com/libeigen/eigen.git"
},
"fetcher": "fetchFromGitiles"
@@ -155,8 +155,8 @@
},
"src/third_party/ffmpeg": {
"args": {
"hash": "sha256-JHAicFKBvtkwmZPRBKYPT6JVqYqF8hyXxU0H7kfgCBs=",
"rev": "b5e18fb9da84e26ceef30d4e4886696bf59337c0",
"hash": "sha256-41qpsOTedB51WMzzHXDiXA19OIzA7wG/Qgbz6IkmWpk=",
"rev": "ad41607c61898cf7150e0fb20fe4bbabd44922a3",
"url": "https://chromium.googlesource.com/chromium/third_party/ffmpeg.git"
},
"fetcher": "fetchFromGitiles"
@@ -187,16 +187,16 @@
},
"src/third_party/freetype/src": {
"args": {
"hash": "sha256-H5RzBFYWIp/QYKyeBM2wfuX7FvXHPbhCAp7qne5Zvhw=",
"rev": "99b479dc34728936b006679a31e12b8cf432fc55",
"hash": "sha256-QOUIW1p9bh7v100iQn8aPq601bNHz+UDA4esd10nQk0=",
"rev": "7e0e56f84fd53cf38378d33c8fc8f92d12ab9ac6",
"url": "https://chromium.googlesource.com/chromium/src/third_party/freetype2.git"
},
"fetcher": "fetchFromGitiles"
},
"src/third_party/fuzztest/src": {
"args": {
"hash": "sha256-0Fk2W4rS1xB6YcXsDbrMfmZUfMxNlGz29xRcBHZbijA=",
"rev": "dc327134097700121e4ecd6e1d54d1d0a832a18d",
"hash": "sha256-nKdSzMuvjgYEP2sbP5/S5yzrT3FL6OsKMbC/uAsUybo=",
"rev": "36a7acd1a4445a722803cd2d41bcf878ec2831ca",
"url": "https://chromium.googlesource.com/external/github.com/google/fuzztest.git"
},
"fetcher": "fetchFromGitiles"
@@ -219,8 +219,8 @@
},
"src/third_party/google_benchmark/src": {
"args": {
"hash": "sha256-GfqY2d+Nd7ovNrXxzTRm/AYWj7GuxIO6FawzUEzwOVA=",
"rev": "188e8278990a9069ffc84441cb5a024fd0bede37",
"hash": "sha256-M8QkA8+bckoRjlcVneYXNetmPEWEvmWy/mca5JA40Ho=",
"rev": "8abf1e701fbd88c8170f48fe0558247e2e5f8e7d",
"url": "https://chromium.googlesource.com/external/github.com/google/benchmark.git"
},
"fetcher": "fetchFromGitiles"
@@ -235,8 +235,8 @@
},
"src/third_party/grpc/src": {
"args": {
"hash": "sha256-LQrig9/ceXS1LclfN9b9DoAvwltIA1R5fSpmHTmaN8s=",
"rev": "5e9fb9cbfb12a10ff9c16fbc360328d224b838d6",
"hash": "sha256-XzKPeOHb7yf0CZdz2/P5CwUiEi5Cquiqqj8nBQ+xkqI=",
"rev": "05ffa9265bd5f4846a5e3dc46d91ba739ad17ef6",
"url": "https://chromium.googlesource.com/external/github.com/grpc/grpc.git"
},
"fetcher": "fetchFromGitiles"
@@ -249,34 +249,34 @@
},
"fetcher": "fetchFromGitiles"
},
"src/third_party/harfbuzz-ng/src": {
"src/third_party/harfbuzz/src": {
"args": {
"hash": "sha256-jQZElINbJgiVj1IHhkrtBCL5jGYzZrjJkO7gt+bgMA4=",
"rev": "6f4c5cec306d31e6822303f5ba248a14293d588e",
"hash": "sha256-tSap704OcadjsEUx+K1bTCrqvluH2F0oFW6Aio+Wgn4=",
"rev": "b90b89feb9aad05065b2edfb10aaa969b164275a",
"url": "https://chromium.googlesource.com/external/github.com/harfbuzz/harfbuzz.git"
},
"fetcher": "fetchFromGitiles"
},
"src/third_party/icu": {
"args": {
"hash": "sha256-hKIzBQVs4C/QJ4BdP3DTm6au9hq8BE0kG1VphtbtHVE=",
"rev": "b4aae6832c06df9d538d41b249403cf0678f16b4",
"hash": "sha256-rNErsn11FZUh8GXAl7jK+NyLHIKrQR3LuoM1qFFGtmM=",
"rev": "3859e64eed5d34544b27fbcab0ac1685ce83df3c",
"url": "https://chromium.googlesource.com/chromium/deps/icu.git"
},
"fetcher": "fetchFromGitiles"
},
"src/third_party/instrumented_libs": {
"args": {
"hash": "sha256-8kokdsnn5jD9KgM/6g0NuITBbKkGXWEM4BMr1nCrfdU=",
"rev": "69015643b3f68dbd438c010439c59adc52cac808",
"hash": "sha256-5cb9qhSEzb941pF5HH0Br+x9wEH7MiGwQttvErb2mZo=",
"rev": "e8cb570a9a2ee9128e2214c73417ad2a3c47780b",
"url": "https://chromium.googlesource.com/chromium/third_party/instrumented_libraries.git"
},
"fetcher": "fetchFromGitiles"
},
"src/third_party/jsoncpp/source": {
"args": {
"hash": "sha256-bSLNcoYBz3QCt5VuTR056V9mU2PmBuYBa0W6hFg2m8Q=",
"rev": "42e892d96e47b1f6e29844cc705e148ec4856448",
"hash": "sha256-q+DOwkjRlHacgfWf5UVY02aqfnKK9M/1YRBX6aMce9g=",
"rev": "d4d072177213b117fb81d4cfda140de090616161",
"url": "https://chromium.googlesource.com/external/github.com/open-source-parsers/jsoncpp.git"
},
"fetcher": "fetchFromGitiles"
@@ -291,16 +291,16 @@
},
"src/third_party/libaom/source/libaom": {
"args": {
"hash": "sha256-uO+zjmt0g5m780WR823UJ0AmQA+dfVFOjPChTLAciTM=",
"rev": "f3dddebddd0dba76fbfb97b96b6336bcf1d3a30c",
"hash": "sha256-qvwmcnA3dls89y4Uy79c2Lt0W5iT6ASD/MKS5LLzO/A=",
"rev": "c213343c8d32bcae729fe09fcba16e1f371cb23b",
"url": "https://aomedia.googlesource.com/aom.git"
},
"fetcher": "fetchFromGitiles"
},
"src/third_party/libc++/src": {
"args": {
"hash": "sha256-7O/X2JW8ghkPTjmFZmT9cgG3Ui5zk3gUb436KlPww34=",
"rev": "7ab65651aed6802d2599dcb7a73b1f82d5179d05",
"hash": "sha256-vT1km7JgVpotDoNK+ae1gplSHcwrVNLsv/QAFUrDsIM=",
"rev": "5abc7f839700f0f17338434e1c1c6a8c87c00c11",
"url": "https://chromium.googlesource.com/external/github.com/llvm/llvm-project/libcxx.git"
},
"fetcher": "fetchFromGitiles"
@@ -315,64 +315,64 @@
},
"src/third_party/libgav1/src": {
"args": {
"hash": "sha256-gisU0p0HDL7Po/ZXIIZVOTnxnOuVvSE/FYo9DaEUFfo=",
"rev": "40f58ed32ff39071c3f2a51056dbc49a070af0dc",
"hash": "sha256-6/zMaX2DPSKpsaqirhrgi3nL/88Qr2VXacmyL5IyJ3U=",
"rev": "66ac17620652635392f6ab24065c77b035e281c9",
"url": "https://chromium.googlesource.com/codecs/libgav1.git"
},
"fetcher": "fetchFromGitiles"
},
"src/third_party/libjpeg_turbo": {
"args": {
"hash": "sha256-KGeB/lTjhm8DQBDZVSPENvZEGSHeLTkviJrYsFh5vEM=",
"rev": "d1f5f2393e0d51f840207342ae86e55a86443288",
"hash": "sha256-wor4RTF3/5BFL9EWcGEofY+M4HN2+/KJUaOY+u86K5Q=",
"rev": "640f254ad0fa03f6b1f29f89b7dd9366f2f6e533",
"url": "https://chromium.googlesource.com/chromium/deps/libjpeg_turbo.git"
},
"fetcher": "fetchFromGitiles"
},
"src/third_party/libpfm4/src": {
"args": {
"hash": "sha256-6YaPJcI6Qk0F1Dv5evfFq3MVSsBpsQ7sIreSuHZmOUo=",
"rev": "41878eab48c50bb9ec5f741a013e971bb5a9dff2",
"hash": "sha256-t4LMG38GksMEM5DktyJ0qLUX1biXErQ57MaMtd7hoeo=",
"rev": "977a25bb3dfe45f653a6cee71ffaae9a92fc3095",
"url": "https://chromium.googlesource.com/external/git.code.sf.net/p/perfmon2/libpfm4.git"
},
"fetcher": "fetchFromGitiles"
},
"src/third_party/libsrtp": {
"args": {
"hash": "sha256-xC//VEFrI94nCkyLnRa6uQ+hJQqe41v0Qjm4LJ7K84I=",
"rev": "e8383771af8aa4096f5bcfe3743a5ea128f88a9a",
"hash": "sha256-6tIbthIcUw58AgaNzvSenZPp/e5vHVTp5K2bpPF+Zg0=",
"rev": "cd5d177bf1fde755ddb4c7f0d9ff7693f8b49e5e",
"url": "https://chromium.googlesource.com/chromium/deps/libsrtp.git"
},
"fetcher": "fetchFromGitiles"
},
"src/third_party/libunwind/src": {
"args": {
"hash": "sha256-miwz3+/fq+7Ohsn8J6xrLsQn/VqyezS9vZO9XzEuZZA=",
"rev": "db838d918570d4e381ecf9f5cc70a0098c9c2cd6",
"hash": "sha256-EuaVSYiR7qrlYqBR0UqdWCvwdzJSn0RS2wC/lnP19AE=",
"rev": "d6c7a21e978f0adaa43accaad53bc64f0b64f6ec",
"url": "https://chromium.googlesource.com/external/github.com/llvm/llvm-project/libunwind.git"
},
"fetcher": "fetchFromGitiles"
},
"src/third_party/libvpx/source/libvpx": {
"args": {
"hash": "sha256-8vej9g9+L73eOIuXZNfOWe6pV/cNr4JZOihZUtRxbFA=",
"rev": "3fce57ecc905d95a4619f33d09851d68c5a88663",
"hash": "sha256-fCwegoFUwDg5/tGBH4SlO3YeAR2wkYgIoajXVtt0eYk=",
"rev": "31af37b1bd2774d11a932c1cd9a3849328375f64",
"url": "https://chromium.googlesource.com/webm/libvpx.git"
},
"fetcher": "fetchFromGitiles"
},
"src/third_party/libyuv": {
"args": {
"hash": "sha256-DW7PuRqA1x0K8/uJbxBJ4Cn9YEPFhZ9vhuGVVyGKK98=",
"rev": "30809ff64a9ca5e45f86439c0d474c2d3eef3d05",
"hash": "sha256-Bq9LM+9sdFzKzbTzrW2cloSOFUhCfyvYqwBweIhiDQI=",
"rev": "de63bd90f4396313f864ad58b65279e7894451a9",
"url": "https://chromium.googlesource.com/libyuv/libyuv.git"
},
"fetcher": "fetchFromGitiles"
},
"src/third_party/llvm-libc/src": {
"args": {
"hash": "sha256-nrd+E7LRTclF/Qa3wBvlutJ/wbLQKr73LOBk9k0qFOI=",
"rev": "adccc443070c58badd6414fd9a4380ca8c78e7c4",
"hash": "sha256-NaQb2UvNqIL4LL5PSshRRMKWdXFjWPnf2YJpVegGtag=",
"rev": "be95a36286a288c9437f5ed991720ccece1a6391",
"url": "https://chromium.googlesource.com/external/github.com/llvm/llvm-project/libc.git"
},
"fetcher": "fetchFromGitiles"
@@ -387,16 +387,16 @@
},
"src/third_party/nasm": {
"args": {
"hash": "sha256-0KsHYi76IaVNwk0dBhem2AnUXd9PpeS+jUsY+zPmeJ8=",
"rev": "45252858722aad12e545819b2d0f370eb865431b",
"hash": "sha256-uC6bGxSdz1V2SXIQjMsDd6555b3gAPN1Y0ZQtWoqDww=",
"rev": "525a09a813be0f75b646ee93fc2a31c27b87d722",
"url": "https://chromium.googlesource.com/chromium/deps/nasm.git"
},
"fetcher": "fetchFromGitiles"
},
"src/third_party/neon_2_sse/src": {
"args": {
"hash": "sha256-4OzG4wIPwnKbFD9LG+stxHt5O4qB85ZIXVeSrNqDAyM=",
"rev": "662a85912e8f86ec808f9b15ce77f8715ba53316",
"hash": "sha256-ydHSMPJS+axvW7KIR/9SLWNFq/lP67dpg9Yt7shLCng=",
"rev": "ed59be8546632d5126ff69c87122ae5de20ffe4f",
"url": "https://chromium.googlesource.com/external/github.com/intel/ARM_NEON_2_x86_SSE.git"
},
"fetcher": "fetchFromGitiles"
@@ -411,8 +411,8 @@
},
"src/third_party/perfetto": {
"args": {
"hash": "sha256-ZDQsBVFq9TgGGf5r2vv8nsHvFy03NM+SkbaXPoa345Q=",
"rev": "40b1342aa7bd47d9c963c3617fd98ec1551528f9",
"hash": "sha256-2RXnxNmF5ZSWs7H4slVVTSLh9bfQMMfMRrELVZUN/Vo=",
"rev": "82ad4b69cbaf64e26c639061b1712756a9cc5e20",
"url": "https://chromium.googlesource.com/external/github.com/google/perfetto.git"
},
"fetcher": "fetchFromGitiles"
@@ -427,8 +427,8 @@
},
"src/third_party/pthreadpool/src": {
"args": {
"hash": "sha256-Es9QNblzo5b+x4K7myQJwIiUKvqyP16QExWPhGqqDO8=",
"rev": "9003ee6c137cea3b94161bd5c614fb43be523ee1",
"hash": "sha256-4EHJzZT+Gbhs8SkOhjSvDIPEqIQU93oJmtF3c/T+qjw=",
"rev": "02460584c6092e527c8b89f7df4de143d70e801f",
"url": "https://chromium.googlesource.com/external/github.com/google/pthreadpool.git"
},
"fetcher": "fetchFromGitiles"
@@ -449,26 +449,34 @@
},
"fetcher": "fetchFromGitiles"
},
"src/third_party/sframe/src": {
"args": {
"hash": "sha256-bw+6ycUpnFZJhtXFUzr7XTOljNrs+7oFdVY+LN0Rqek=",
"rev": "b14090904433bed0d4ec3f875b9b39f3e0555930",
"url": "https://chromium.googlesource.com/external/github.com/cisco/sframe"
},
"fetcher": "fetchFromGitiles"
},
"src/third_party/tflite/src": {
"args": {
"hash": "sha256-nvU3p6TzEqBkDtZEoxCZGPsQA0oZNJID8raqHBDS0ko=",
"rev": "8fd527849069a358ad6c2980b9a9b34a53c53717",
"hash": "sha256-eSqaWXtzZ4Bi9ilaJYGdZamzUjmo+AtDZ9KeZhsc/fY=",
"rev": "999d49c10046e240cd5366d349d3a5f6af16a0d4",
"url": "https://chromium.googlesource.com/external/github.com/tensorflow/tensorflow.git"
},
"fetcher": "fetchFromGitiles"
},
"src/third_party/xnnpack/src": {
"args": {
"hash": "sha256-vOUwMXZJbYxTGPpdD5uc9ATfPIpThCDHV/YTlWN0ajw=",
"rev": "97f3177fd836fff03b48a886bb130591866ad7ca",
"hash": "sha256-uw3r5g5rWamlFubBkXDb4KRx3hkOAoQyFo8l95GYGZI=",
"rev": "56ac34b3f45fae2eca1f32584f7f0b279be2cf1f",
"url": "https://chromium.googlesource.com/external/github.com/google/XNNPACK.git"
},
"fetcher": "fetchFromGitiles"
},
"src/tools": {
"args": {
"hash": "sha256-PDjcHq8BTDLD6OsYFfvjw8ffmam/4YSx8SF0G/NvebY=",
"rev": "f363a79871a91f36322e845e3134e2f04e1fc18a",
"hash": "sha256-Et9KyslSik7y5v2Jzai/vpxogpT0RlZ5b+u7/VwHc28=",
"rev": "8e4d26ef387bfa4c07e66dd1c7399c3d53ef1451",
"url": "https://chromium.googlesource.com/chromium/src/tools"
},
"fetcher": "fetchFromGitiles"

View File

@@ -86,42 +86,32 @@ stdenv.mkDerivation (finalAttrs: {
alsa-lib
];
patches = [
# https://github.com/NixOS/nixpkgs/blob/8e689a91c5b4e47b57dee488dd7e319cc704eb9d/pkgs/applications/networking/browsers/chromium/common.nix#L604-L612
# clang++: error: unknown argument: '-fsanitize-ignore-for-ubsan-feature=array-bounds'
(fetchpatch {
name = "chromium-146-revert-Update-fsanitizer=array-bounds-config.patch";
# https://chromium-review.googlesource.com/c/chromium/src/+/7539408
url = "https://chromium.googlesource.com/chromium/src/+/acb47d9a6b56c4889a2ed4216e9968cfc740086c^!?format=TEXT";
decode = "base64 -d";
revert = true;
hash = "sha256-WZsN2qm6lX121bDf7SoN75flXtCTmPPpwtHK0ayjkPc=";
})
env = {
BUILD_CC = "$CC_FOR_BUILD";
BUILD_CXX = "$CXX_FOR_BUILD";
BUILD_AR = "$AR_FOR_BUILD";
BUILD_NM = "$NM_FOR_BUILD";
NIX_CFLAGS_COMPILE = lib.optionalString stdenv.hostPlatform.isLinux "-Wno-changes-meaning";
};
# https://github.com/NixOS/nixpkgs/blob/8e689a91c5b4e47b57dee488dd7e319cc704eb9d/pkgs/applications/networking/browsers/chromium/common.nix#L620-L623
patches = [
# clang++: error: unknown argument: '-fno-lifetime-dse'
./chromium-147-llvm-22.patch
# https://github.com/NixOS/nixpkgs/blob/8e689a91c5b4e47b57dee488dd7e319cc704eb9d/pkgs/applications/networking/browsers/chromium/common.nix#L624-L644
# Keep in sync with Chromium's LLVM 22 compatibility patches.
# clang++: error: unknown argument: '-fdiagnostics-show-inlining-chain'
# clang++: error: unknown argument: '-fsanitize-ignore-for-ubsan-feature=array-bounds'
# clang++: error: unknown argument: '-fsanitize-ignore-for-ubsan-feature=return'
./chromium-149-llvm-22.patch
# ninja: error: 'ar', needed by 'obj/third_party/protobuf/libprotoc_lib.a',
# missing and no known rule to make it
(fetchpatch {
name = "chromium-148-revert-build-Add--fsanitizer=return-config.patch";
# https://chromium-review.googlesource.com/c/chromium/src/+/7629257
url = "https://chromium.googlesource.com/chromium/src/+/99ba1f5302f9433efdb4df302cb7b7de56c72e4c^!?format=TEXT";
name = "chromium-150-backport-build--Omit-ar-from-inputs-when-resolved-via--PATH.patch";
# https://chromium-review.googlesource.com/c/chromium/src/+/7904982
url = "https://chromium.googlesource.com/chromium/src/+/60f987d8d5f7272793a40290d060b8f50933f825^!?format=TEXT";
decode = "base64 -d";
revert = true;
hash = "sha256-/qzzxwTdPMwIdsqD/G02S7kKHCj3QxECL+g1WYEaWmU=";
})
# ERROR Unresolved dependencies.
# //apps:apps(//build/toolchain/linux/unbundle:default)
# needs //build/config/compiler:sanitize_return(//build/toolchain/linux/unbundle:default)
(fetchpatch {
name = "chromium-148-revert-build-Enable--fsanitizer=return-config.patch";
# https://chromium-review.googlesource.com/c/chromium/src/+/7629258
url = "https://chromium.googlesource.com/chromium/src/+/9357bfbea03753fe52264c9ec36abe74f48cfef5^!?format=TEXT";
decode = "base64 -d";
revert = true;
hash = "sha256-14fTHNh3vGsf4KgeH8uLX+aK3lrjK0VKd1dfK1g7r0I=";
hash = "sha256-MryWxSwBxSIONhl3X1cDxTWwNWy8a4yt/sqkrueSUNs=";
})
];

View File

@@ -7,13 +7,13 @@
buildGoModule (finalAttrs: {
pname = "snip";
version = "0.22.0";
version = "0.24.1";
src = fetchFromGitHub {
owner = "edouard-claude";
repo = "snip";
tag = "v${finalAttrs.version}";
hash = "sha256-y88ZHg29Z/QBZk8YWXp287Rel7DpPESYAlbqt5hj1nc=";
hash = "sha256-17vAgwuOrDN81+XKa2vn60T9RyZktOoF2xfF/RE+BNw=";
};
vendorHash = "sha256-2MxFZqjNuLzcuu+bsLyOyHIakCxh7j0FUx8LsjZRhrY=";

View File

@@ -0,0 +1,57 @@
diff --git a/lib/tests/test_regexranges_main.cpp b/lib/tests/test_regexranges_main.cpp
index 567d79230c..e28bba47e5 100644
--- a/lib/tests/test_regexranges_main.cpp
+++ b/lib/tests/test_regexranges_main.cpp
@@ -12,26 +12,26 @@
using namespace std;
using namespace srchilite;
-RegexRanges ranges;
+RegexRanges regexRanges;
void check_range_regex(const string &s, bool expectedTrue = true) {
cout << "checking " << s << endl;
if (expectedTrue)
- assertTrue(ranges.addRegexRange(s));
+ assertTrue(regexRanges.addRegexRange(s));
else
- assertFalse(ranges.addRegexRange(s));
+ assertFalse(regexRanges.addRegexRange(s));
}
void check_match(const string &line, const string &expected = "") {
cout << "searching inside " << line;
const boost::regex *matched = 0;
if (expected != "") {
- matched = ranges.matches(line);
+ matched = regexRanges.matches(line);
assertTrue(matched != 0);
assertEquals(expected, matched->str());
cout << " found " << *matched << endl;
} else {
- assertTrue(ranges.matches(line) == 0);
+ assertTrue(regexRanges.matches(line) == 0);
cout << " not found" << endl;
}
}
@@ -39,9 +39,9 @@
void check_in_range(const string &s, bool expectedTrue = true) {
cout << "checking " << s << "... ";
if (expectedTrue) {
- assertTrue(ranges.isInRange(s));
+ assertTrue(regexRanges.isInRange(s));
} else {
- assertFalse(ranges.isInRange(s));
+ assertFalse(regexRanges.isInRange(s));
}
cout << expectedTrue << endl;
}
@@ -57,7 +57,7 @@
check_range_regex("{notclosed");
// reset regular expressions
- ranges.clear();
+ regexRanges.clear();
check_range_regex("/// foo");
check_range_regex("/// bar");

Some files were not shown because too many files have changed in this diff Show More