From 0565c966047ffa8a76f9a1baf5b3bdcab037ce7c Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 4 Feb 2026 00:28:07 +0000 Subject: [PATCH 001/175] libmysofa: 1.3.3 -> 1.3.4 --- pkgs/by-name/li/libmysofa/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/li/libmysofa/package.nix b/pkgs/by-name/li/libmysofa/package.nix index b32265cc07a7..ae140ada101d 100644 --- a/pkgs/by-name/li/libmysofa/package.nix +++ b/pkgs/by-name/li/libmysofa/package.nix @@ -8,13 +8,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "libmysofa"; - version = "1.3.3"; + version = "1.3.4"; src = fetchFromGitHub { owner = "hoene"; repo = "libmysofa"; rev = "v${finalAttrs.version}"; - hash = "sha256-jvib1hGPJEY2w/KjlD7iTtRy1s8LFG+Qhb2d6xdpUyc="; + hash = "sha256-gP/RjKzMx8JIYcyiivBGvy3kIdwHMEKY6abssyVUKNQ="; }; outputs = [ From 0b7b35fa8bc0334a3ae556246a19401c90e54254 Mon Sep 17 00:00:00 2001 From: whispers Date: Sun, 3 May 2026 20:22:47 -0400 Subject: [PATCH 002/175] systemtap-unwrapped: 5.4 -> 5.5 Log: https://sourceware.org/git/?p=systemtap.git;a=shortlog;h=refs/tags/release-5.5 --- .../sy/systemtap-unwrapped/package.nix | 11 +- .../systemtap-elaborate-fix-32bit-build.patch | 102 ------------------ 2 files changed, 2 insertions(+), 111 deletions(-) delete mode 100644 pkgs/by-name/sy/systemtap-unwrapped/systemtap-elaborate-fix-32bit-build.patch diff --git a/pkgs/by-name/sy/systemtap-unwrapped/package.nix b/pkgs/by-name/sy/systemtap-unwrapped/package.nix index afad124fb852..df7790f47cc0 100644 --- a/pkgs/by-name/sy/systemtap-unwrapped/package.nix +++ b/pkgs/by-name/sy/systemtap-unwrapped/package.nix @@ -12,21 +12,14 @@ stdenv.mkDerivation (finalAttrs: { pname = "systemtap"; - version = "5.4"; + version = "5.5"; src = fetchgit { url = "git://sourceware.org/git/systemtap.git"; rev = "release-${finalAttrs.version}"; - hash = "sha256-11ecQFiBaWOZcbS5Qqf/41heiJM1wSttx0eMoVQImZc="; + hash = "sha256-olN98hjIYZmQvI7Fn1v5ZwRl7yaCAPRGr2g33oMq7VQ="; }; - patches = lib.optionals stdenv.hostPlatform.is32bit [ - # Fix 32bit build - # https://sourceware.org/git/?p=systemtap.git;a=commit;h=94efb7c4eb02de0e3565cb165b53963602d3dcb6 - # does not apply with fetchpatch because of gitweb encoding issues - ./systemtap-elaborate-fix-32bit-build.patch - ]; - nativeBuildInputs = [ pkg-config cpio diff --git a/pkgs/by-name/sy/systemtap-unwrapped/systemtap-elaborate-fix-32bit-build.patch b/pkgs/by-name/sy/systemtap-unwrapped/systemtap-elaborate-fix-32bit-build.patch deleted file mode 100644 index 34a23577dbdb..000000000000 --- a/pkgs/by-name/sy/systemtap-unwrapped/systemtap-elaborate-fix-32bit-build.patch +++ /dev/null @@ -1,102 +0,0 @@ -From 94efb7c4eb02de0e3565cb165b53963602d3dcb6 Mon Sep 17 00:00:00 2001 -From: Sergei Trofimovich -Date: Sun, 30 Nov 2025 20:58:01 +0000 -Subject: [PATCH] elaborate.cxx: fix 32-bit build - -Without the change the build fails on i686-linux as: - - elaborate.cxx:5119:33: error: - format '%ld' expects argument of type 'long int', - but argument 2 has type 'int64_t' {aka 'long long int'} [-Werror=format=] - 5119 | session.print_warning (_F("Collapsing unresolved @define to %ld [stapprobes]", value), e->tok); - | ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ---- - elaborate.cxx | 2 +- - po/cs.po | 2 +- - po/en.po | 2 +- - po/fr.po | 2 +- - po/pl.po | 2 +- - po/systemtap.pot | 2 +- - 6 files changed, 6 insertions(+), 6 deletions(-) - -diff --git a/elaborate.cxx b/elaborate.cxx -index 93ecffa1a..3ad3614e7 100644 ---- a/elaborate.cxx -+++ b/elaborate.cxx -@@ -5116,7 +5116,7 @@ const_folder::visit_defined_op (defined_op* e) - // Don't be greedy... we'll only collapse one at a time so type - // resolution can have another go at it. - relaxed_p = false; -- session.print_warning (_F("Collapsing unresolved @define to %ld [stapprobes]", value), e->tok); -+ session.print_warning (_F("Collapsing unresolved @define to %lld [stapprobes]", (long long)value), e->tok); - literal_number* n = new literal_number (value); - n->tok = e->tok; - n->visit (this); -diff --git a/po/cs.po b/po/cs.po -index df6412772..92fdef7ad 100644 ---- a/po/cs.po -+++ b/po/cs.po -@@ -2039,7 +2039,7 @@ msgstr "Zahazuji kontrolu '@defined' bez vedlejších účinků " - - #: elaborate.cxx:5119 - #, fuzzy, c-format --msgid "Collapsing unresolved @define to %ld [stapprobes]" -+msgid "Collapsing unresolved @define to %lld [stapprobes]" - msgstr "Zahazuji kontrolu '@defined' bez vedlejších účinků " - - #: elaborate.cxx:5127 -diff --git a/po/en.po b/po/en.po -index 8847639e8..1db2292bd 100644 ---- a/po/en.po -+++ b/po/en.po -@@ -2050,7 +2050,7 @@ msgstr "" - - #: elaborate.cxx:5119 - #, c-format --msgid "Collapsing unresolved @define to %ld [stapprobes]" -+msgid "Collapsing unresolved @define to %lld [stapprobes]" - msgstr "" - - #: elaborate.cxx:5127 -diff --git a/po/fr.po b/po/fr.po -index b8677707b..55e409919 100644 ---- a/po/fr.po -+++ b/po/fr.po -@@ -2090,7 +2090,7 @@ msgstr "" - - #: elaborate.cxx:5119 - #, c-format --msgid "Collapsing unresolved @define to %ld [stapprobes]" -+msgid "Collapsing unresolved @define to %lld [stapprobes]" - msgstr "" - - #: elaborate.cxx:5127 -diff --git a/po/pl.po b/po/pl.po -index e3b6700ee..0b35880c1 100644 ---- a/po/pl.po -+++ b/po/pl.po -@@ -1977,7 +1977,7 @@ msgstr "" - - #: elaborate.cxx:5119 - #, c-format --msgid "Collapsing unresolved @define to %ld [stapprobes]" -+msgid "Collapsing unresolved @define to %lld [stapprobes]" - msgstr "" - - #: elaborate.cxx:5127 -diff --git a/po/systemtap.pot b/po/systemtap.pot -index 32ddb2290..4ec0d9a8c 100644 ---- a/po/systemtap.pot -+++ b/po/systemtap.pot -@@ -1973,7 +1973,7 @@ msgstr "" - - #: elaborate.cxx:5119 - #, c-format --msgid "Collapsing unresolved @define to %ld [stapprobes]" -+msgid "Collapsing unresolved @define to %lld [stapprobes]" - msgstr "" - - #: elaborate.cxx:5127 --- -2.52.0 - From ea774ba3fa66d616f779b1e21cc9ccef4b6cdbd3 Mon Sep 17 00:00:00 2001 From: whispers Date: Sun, 3 May 2026 20:22:47 -0400 Subject: [PATCH 003/175] libsystemtap: 5.3 -> 5.5 Log: https://sourceware.org/git/?p=systemtap.git;a=shortlog;h=refs/tags/release-5.5 --- pkgs/by-name/li/libsystemtap/package.nix | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/by-name/li/libsystemtap/package.nix b/pkgs/by-name/li/libsystemtap/package.nix index 4fc1b26b34b0..21be558c3915 100644 --- a/pkgs/by-name/li/libsystemtap/package.nix +++ b/pkgs/by-name/li/libsystemtap/package.nix @@ -7,14 +7,14 @@ elfutils, }: -stdenv.mkDerivation { +stdenv.mkDerivation (finalAttrs: { pname = "libsystemtap"; - version = "5.3"; + version = "5.5"; src = fetchgit { url = "git://sourceware.org/git/systemtap.git"; - rev = "release-5.3"; - hash = "sha256-W9iJ+hyowqgeq1hGcNQbvPfHpqY0Yt2W/Ng/4p6asxc="; + rev = "release-${finalAttrs.version}"; + hash = "sha256-olN98hjIYZmQvI7Fn1v5ZwRl7yaCAPRGr2g33oMq7VQ="; }; dontBuild = true; @@ -43,4 +43,4 @@ stdenv.mkDerivation { badPlatforms = elfutils.meta.badPlatforms or [ ]; maintainers = [ lib.maintainers.workflow ]; }; -} +}) From b3a0b192711280d0f077c1b2da4795f3700c331d Mon Sep 17 00:00:00 2001 From: Justin Lovinger Date: Mon, 11 May 2026 22:51:20 +0000 Subject: [PATCH 004/175] geoclue2: 2.7.2 -> 2.8.1 --- nixos/tests/geoclue2.nix | 2 +- pkgs/by-name/ge/geoclue2/fix-sysusers_dir.patch | 13 +++++++++++++ pkgs/by-name/ge/geoclue2/package.nix | 5 +++-- 3 files changed, 17 insertions(+), 3 deletions(-) create mode 100644 pkgs/by-name/ge/geoclue2/fix-sysusers_dir.patch diff --git a/nixos/tests/geoclue2.nix b/nixos/tests/geoclue2.nix index 0a2f311c286f..0b836c5699c2 100644 --- a/nixos/tests/geoclue2.nix +++ b/nixos/tests/geoclue2.nix @@ -31,6 +31,6 @@ assert ("Latitude: 12.345000°" in whereAmI), f"Incorrect latitude in:\n{whereAmI}" assert ("Longitude: -67.890000°" in whereAmI), f"Incorrect longitude in:\n{whereAmI}" assert ("Altitude: 123.450000 meters" in whereAmI), f"Incorrect altitude in:\n{whereAmI}" - assert ("Accuracy: 1000.000000 meters" in whereAmI), f"Incorrect accuracy in:\n{whereAmI}" + assert ("Accuracy: 1000 meters" in whereAmI), f"Incorrect accuracy in:\n{whereAmI}" ''; } diff --git a/pkgs/by-name/ge/geoclue2/fix-sysusers_dir.patch b/pkgs/by-name/ge/geoclue2/fix-sysusers_dir.patch new file mode 100644 index 000000000000..4759d88a5813 --- /dev/null +++ b/pkgs/by-name/ge/geoclue2/fix-sysusers_dir.patch @@ -0,0 +1,13 @@ +diff --git a/data/meson.build b/data/meson.build +index 2591e6a..dc1bd8d 100644 +--- a/data/meson.build ++++ b/data/meson.build +@@ -69,7 +69,7 @@ if get_option('enable-backend') + if systemd.found() + sysusers_dir = systemd.get_variable(pkgconfig: 'sysusersdir') + else +- sysusers_dir = '/usr/lib/sysusers.d' ++ sysusers_dir = join_paths(get_option('prefix'), 'usr/lib/sysusers.d') + endif + configure_file(output: 'geoclue-sysusers.conf', + input: 'geoclue-sysusers.conf.in', diff --git a/pkgs/by-name/ge/geoclue2/package.nix b/pkgs/by-name/ge/geoclue2/package.nix index 95fb94098f4c..52db14252d4b 100644 --- a/pkgs/by-name/ge/geoclue2/package.nix +++ b/pkgs/by-name/ge/geoclue2/package.nix @@ -29,7 +29,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "geoclue"; - version = "2.7.2"; + version = "2.8.1"; outputs = [ "out" @@ -42,11 +42,12 @@ stdenv.mkDerivation (finalAttrs: { owner = "geoclue"; repo = "geoclue"; tag = finalAttrs.version; - hash = "sha256-LwL1WtCdHb/NwPr3/OLISwaAwplhJwiZT9vUdX29Bbs="; + hash = "sha256-CyZhUMAa2vMUi61sL+gGBZFxGo0lu7Cm68fTjcbblTg="; }; patches = [ ./add-option-for-installation-sysconfdir.patch + ./fix-sysusers_dir.patch ]; nativeBuildInputs = [ From ba1857095fd6fb35fabdafe858fe855773568d0d Mon Sep 17 00:00:00 2001 From: zinzilulo <214774502+zinzilulo@users.noreply.github.com> Date: Sun, 17 May 2026 00:32:10 +0100 Subject: [PATCH 005/175] gmp: enable assembly for aarch64-darwin --- pkgs/development/libraries/gmp/6.x.nix | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/pkgs/development/libraries/gmp/6.x.nix b/pkgs/development/libraries/gmp/6.x.nix index e55838d4216b..4020a4fe61bd 100644 --- a/pkgs/development/libraries/gmp/6.x.nix +++ b/pkgs/development/libraries/gmp/6.x.nix @@ -69,8 +69,7 @@ let ++ optional (stdenv.hostPlatform.isDarwin && stdenv.hostPlatform.is64bit) "ABI=64" # to build a .dll on windows, we need --disable-static + --enable-shared # see https://gmplib.org/manual/Notes-for-Particular-Systems.html - ++ optional (!withStatic && stdenv.hostPlatform.isPE) "--disable-static --enable-shared" - ++ optional (stdenv.hostPlatform.isDarwin && stdenv.hostPlatform.isAarch64) "--disable-assembly"; + ++ optional (!withStatic && stdenv.hostPlatform.isPE) "--disable-static --enable-shared"; doCheck = true; # not cross; From 32c3bbd5b688955ebb06931c8f38caecd03d4ddc Mon Sep 17 00:00:00 2001 From: whispers Date: Thu, 11 Jun 2026 23:00:26 -0400 Subject: [PATCH 006/175] sourceHighlight: patch to fix build with gcc 16 The `ranges` name in the test here conflicts with the `namespace std::ranges { }` from GCC 16, causing this test to fail to build with "error: reference to 'ranges' is ambiguous". To avoid this, we simply rename the variable. --- ...gcc16-disambiguate-regex-ranges-test.patch | 57 +++++++++++++++++++ pkgs/by-name/so/sourceHighlight/package.nix | 5 ++ 2 files changed, 62 insertions(+) create mode 100644 pkgs/by-name/so/sourceHighlight/gcc16-disambiguate-regex-ranges-test.patch diff --git a/pkgs/by-name/so/sourceHighlight/gcc16-disambiguate-regex-ranges-test.patch b/pkgs/by-name/so/sourceHighlight/gcc16-disambiguate-regex-ranges-test.patch new file mode 100644 index 000000000000..2008304ca948 --- /dev/null +++ b/pkgs/by-name/so/sourceHighlight/gcc16-disambiguate-regex-ranges-test.patch @@ -0,0 +1,57 @@ +diff --git a/lib/tests/test_regexranges_main.cpp b/lib/tests/test_regexranges_main.cpp +index 567d79230c..e28bba47e5 100644 +--- a/lib/tests/test_regexranges_main.cpp ++++ b/lib/tests/test_regexranges_main.cpp +@@ -12,26 +12,26 @@ + using namespace std; + using namespace srchilite; + +-RegexRanges ranges; ++RegexRanges regexRanges; + + void check_range_regex(const string &s, bool expectedTrue = true) { + cout << "checking " << s << endl; + if (expectedTrue) +- assertTrue(ranges.addRegexRange(s)); ++ assertTrue(regexRanges.addRegexRange(s)); + else +- assertFalse(ranges.addRegexRange(s)); ++ assertFalse(regexRanges.addRegexRange(s)); + } + + void check_match(const string &line, const string &expected = "") { + cout << "searching inside " << line; + const boost::regex *matched = 0; + if (expected != "") { +- matched = ranges.matches(line); ++ matched = regexRanges.matches(line); + assertTrue(matched != 0); + assertEquals(expected, matched->str()); + cout << " found " << *matched << endl; + } else { +- assertTrue(ranges.matches(line) == 0); ++ assertTrue(regexRanges.matches(line) == 0); + cout << " not found" << endl; + } + } +@@ -39,9 +39,9 @@ + void check_in_range(const string &s, bool expectedTrue = true) { + cout << "checking " << s << "... "; + if (expectedTrue) { +- assertTrue(ranges.isInRange(s)); ++ assertTrue(regexRanges.isInRange(s)); + } else { +- assertFalse(ranges.isInRange(s)); ++ assertFalse(regexRanges.isInRange(s)); + } + cout << expectedTrue << endl; + } +@@ -57,7 +57,7 @@ + check_range_regex("{notclosed"); + + // reset regular expressions +- ranges.clear(); ++ regexRanges.clear(); + + check_range_regex("/// foo"); + check_range_regex("/// bar"); diff --git a/pkgs/by-name/so/sourceHighlight/package.nix b/pkgs/by-name/so/sourceHighlight/package.nix index 07eb5ac9f8d5..4f8099afee7f 100644 --- a/pkgs/by-name/so/sourceHighlight/package.nix +++ b/pkgs/by-name/so/sourceHighlight/package.nix @@ -37,6 +37,11 @@ stdenv.mkDerivation rec { url = "https://git.savannah.gnu.org/cgit/src-highlite.git/patch/?id=ab9fe5cb9b85c5afab94f2a7f4b6d7d473c14ee9"; hash = "sha256-wmSLgLnLuFE+IC6AjxzZp/HEnaOCS1VfY2cac0T7Y+w="; }) + + # GCC 16 detects ambiguity in the `ranges` name in a test (conflicts with + # `namespace std::range { }` from GCC), so we rename the variable to + # disambiguate. + ./gcc16-disambiguate-regex-ranges-test.patch ] ++ lib.optionals stdenv.cc.isClang [ # Adds compatibility with C++17 by removing the `register` storage class specifier. From 14700de3afdcead99fa2d71d0b7af934e2d97a77 Mon Sep 17 00:00:00 2001 From: whispers Date: Wed, 1 Jul 2026 22:10:28 -0400 Subject: [PATCH 007/175] onetbb: never treat warnings as fatal onetbb often triggers compiler warnings upstream, and works around them in an ad-hoc, per version manner: https://github.com/uxlfoundation/oneTBB/commit/88482f5f1a122896336d19bbeed84af8773c2e9f https://github.com/uxlfoundation/oneTBB/commit/bdbec2060633e28b6b0e2f89e39297cf89b63e8c we encountered this failing while preparing for a gcc 16 upgrade in Nixpkgs, and the same issue came up for gcc 15 and similar (#446139). it is likely to come up again, as -Werror is extremely susceptible to compiler and library changes (though onetbb admittedly has few dependencies). additionally, while it may be useful for upstream onetbb, it seems to provide little value to us downstream; we just end up working around it. thus, we never treat warnings as errors by disabling upstream's cmake flag for this purpose. --- pkgs/by-name/on/onetbb/package.nix | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/on/onetbb/package.nix b/pkgs/by-name/on/onetbb/package.nix index c5aac8e1963a..de2f382d2517 100644 --- a/pkgs/by-name/on/onetbb/package.nix +++ b/pkgs/by-name/on/onetbb/package.nix @@ -76,6 +76,9 @@ stdenv.mkDerivation (finalAttrs: { cmakeFlags = [ (lib.cmakeBool "TBB_DISABLE_HWLOC_AUTOMATIC_SEARCH" false) + # Treating compiler errors as warnings creates churn each compiler update, + # and provides little utility to us downstream. + (lib.cmakeBool "TBB_STRICT" false) (lib.cmakeBool "TBB_TEST" finalAttrs.finalPackage.doCheck) ] ++ lib.optionals stdenv.hostPlatform.isDarwin [ @@ -83,10 +86,6 @@ stdenv.mkDerivation (finalAttrs: { ]; env = { - # Fix build with modern gcc - # In member function 'void std::__atomic_base<_IntTp>::store(__int_type, std::memory_order) [with _ITp = bool]', - NIX_CFLAGS_COMPILE = lib.optionalString stdenv.cc.isGNU "-Wno-error=stringop-overflow"; - # Fix undefined reference errors with version script under LLVM. NIX_LDFLAGS = lib.optionalString ( stdenv.cc.bintools.isLLVM && lib.versionAtLeast stdenv.cc.bintools.version "17" From c4df48e4e22af2fa166c129edfeec07c5f7b4a42 Mon Sep 17 00:00:00 2001 From: whispers Date: Sat, 4 Jul 2026 00:25:31 -0400 Subject: [PATCH 008/175] glog: disable optimization-dependent stacktrace test This test fails under GCC 16. It appears to be because it makes assumptions that certain compiler optimizations do not occur. It clearly is compiler-specific and tries to work around specific compiler optimizations upstream. In particular, an analysis of the test https://github.com/google/glog/blob/53d58e4531c7c90f71ddab503d915e027432447a/src/stacktrace_unittest.cc#L218 shows that it would be very plausible/correct for GCC to place labels such that the `INIT_ADDRESS_RANGE` macro has `start` and `end` labels that have the same address. While the functions are labeled NOINLINE, interprocedural analysis could *plausibly* produce this result. While we are not completely certain that this is the case, it seems likely that this is not a genuine issue and just a questionable test. --- pkgs/by-name/gl/glog/package.nix | 28 ++++++++++++++++------------ 1 file changed, 16 insertions(+), 12 deletions(-) diff --git a/pkgs/by-name/gl/glog/package.nix b/pkgs/by-name/gl/glog/package.nix index cfe37529d3b3..cf34a44394ab 100644 --- a/pkgs/by-name/gl/glog/package.nix +++ b/pkgs/by-name/gl/glog/package.nix @@ -69,18 +69,22 @@ stdenv.mkDerivation (finalAttrs: { checkPhase = let - excludedTests = - lib.optionals stdenv.hostPlatform.isDarwin [ - "mock-log" - ] - ++ [ - "logging" # works around segfaults for now - ] - ++ lib.optionals (stdenv.hostPlatform.isPower64 && stdenv.hostPlatform.isBigEndian) [ - # CHECK_STREQ failed: symbol == "non_inline_func" ((/build/source/build/symbolize_unittest+0x1000b840) vs. non_inline_func) - # TestWithPCInsideNonInlineFunction doesn't use TEST(), so can't exclude via GTEST_FILTER - "symbolize" - ]; + excludedTests = [ + "logging" # works around segfaults for now + ] + ++ lib.optionals stdenv.hostPlatform.isGnu [ + # Test appears to make strong assumptions about compiler optimizations + # that appear to be broken under GCC 16. + "stacktrace" + ] + ++ lib.optionals stdenv.hostPlatform.isDarwin [ + "mock-log" + ] + ++ lib.optionals (stdenv.hostPlatform.isPower64 && stdenv.hostPlatform.isBigEndian) [ + # CHECK_STREQ failed: symbol == "non_inline_func" ((/build/source/build/symbolize_unittest+0x1000b840) vs. non_inline_func) + # TestWithPCInsideNonInlineFunction doesn't use TEST(), so can't exclude via GTEST_FILTER + "symbolize" + ]; excludedTestsRegex = lib.optionalString ( excludedTests != [ ] ) "(${lib.concatStringsSep "|" excludedTests})"; From 3259398327131f38738e0971c8eca677f2df24de Mon Sep 17 00:00:00 2001 From: whispers Date: Sun, 5 Jul 2026 18:53:22 -0400 Subject: [PATCH 009/175] libtiff: 4.7.1 -> 4.7.2 changes: https://libtiff.gitlab.io/libtiff/releases/v4.7.2.html diff: https://gitlab.com/libtiff/libtiff/-/compare/v4.7.1...v4.7.2 --- pkgs/by-name/li/libtiff/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/li/libtiff/package.nix b/pkgs/by-name/li/libtiff/package.nix index 66f679f6c677..eb0aa4320537 100644 --- a/pkgs/by-name/li/libtiff/package.nix +++ b/pkgs/by-name/li/libtiff/package.nix @@ -37,13 +37,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "libtiff"; - version = "4.7.1"; + version = "4.7.2"; src = fetchFromGitLab { owner = "libtiff"; repo = "libtiff"; rev = "v${finalAttrs.version}"; - hash = "sha256-UiC6s86i7UavW86EKm74oPVlEacvoKmwW7KETjpnNaI="; + hash = "sha256-60Lpg5WRfWMzlOoOUA+C6KLlYIZ+3BjXidOVqv4M2GA="; }; patches = [ From fd40d7c13450209aa06bd4c95e316898a64498d0 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 6 Jul 2026 13:48:29 +0000 Subject: [PATCH 010/175] openexr: 3.4.11 -> 3.4.13 --- pkgs/development/libraries/openexr/3.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/libraries/openexr/3.nix b/pkgs/development/libraries/openexr/3.nix index a989e883a2b3..511d7bb1a344 100644 --- a/pkgs/development/libraries/openexr/3.nix +++ b/pkgs/development/libraries/openexr/3.nix @@ -13,13 +13,13 @@ stdenv.mkDerivation rec { pname = "openexr"; - version = "3.4.11"; + version = "3.4.13"; src = fetchFromGitHub { owner = "AcademySoftwareFoundation"; repo = "openexr"; rev = "v${version}"; - hash = "sha256-5dx2tag6XyuJfNfJgc68X+VWKXaHOL3M7ZJEQbQwFDA="; + hash = "sha256-uzeppRB8vpTjAuqlpvoTehdGL/ng1rTm7kbYdaQHKUw="; }; outputs = [ From d066489411b1a54f4243fe9b816dd0c06f1b7c70 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 7 Jul 2026 01:25:23 +0000 Subject: [PATCH 011/175] doctest: 2.5.2 -> 2.5.3 --- pkgs/by-name/do/doctest/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/do/doctest/package.nix b/pkgs/by-name/do/doctest/package.nix index cbea1dcba749..32c16d2592d5 100644 --- a/pkgs/by-name/do/doctest/package.nix +++ b/pkgs/by-name/do/doctest/package.nix @@ -7,13 +7,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "doctest"; - version = "2.5.2"; + version = "2.5.3"; src = fetchFromGitHub { owner = "doctest"; repo = "doctest"; tag = "v${finalAttrs.version}"; - hash = "sha256-4jW6xPFCFxk1l47EkSUVojhycrtluPhOc5Adf/25R7M="; + hash = "sha256-+/IEISqN9HdaCJ0udLVUitOUziLvF/D3POecZMoXuho="; }; nativeBuildInputs = [ cmake ]; From d14289b44548ffacf8503650acd977a307cb2c6d Mon Sep 17 00:00:00 2001 From: whispers Date: Wed, 8 Jul 2026 08:13:49 -0400 Subject: [PATCH 012/175] xvfb: 21.1.23 -> 21.1.24, drop rebuild avoidance announcement: https://lists.x.org/archives/xorg-announce/2026-July/003718.html advisory: https://lists.x.org/archives/xorg-announce/2026-July/003716.html --- pkgs/by-name/xv/xvfb/package.nix | 9 +-------- 1 file changed, 1 insertion(+), 8 deletions(-) diff --git a/pkgs/by-name/xv/xvfb/package.nix b/pkgs/by-name/xv/xvfb/package.nix index 17cc2e9418ca..934fade5a795 100644 --- a/pkgs/by-name/xv/xvfb/package.nix +++ b/pkgs/by-name/xv/xvfb/package.nix @@ -38,14 +38,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "xvfb"; - # TODO: commented out for rebuild avoidance after xorg-server update. revert - # on staging. - # inherit (xorg-server) src version; - version = "21.1.23"; - src = fetchurl { - url = "mirror://xorg/individual/xserver/xorg-server-${finalAttrs.version}.tar.xz"; - hash = "sha256-45gy5WF9ra8HL9+fDhnl0uHCoTYHrCgLrBq6n4/hRjQ="; - }; + inherit (xorg-server) src version; strictDeps = true; From 5526f30e5aced751a1c48f11d9114d9749b0e0ec Mon Sep 17 00:00:00 2001 From: ajs124 Date: Thu, 9 Jul 2026 11:19:52 +0200 Subject: [PATCH 013/175] tzdata: 2026b -> 2026c https://lists.iana.org/hyperkitty/list/tz-announce@iana.org/thread/NVHSX2PAQIT44U5FCCEVNJJYXQMMTJSA/ --- pkgs/by-name/tz/tzdata/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/tz/tzdata/package.nix b/pkgs/by-name/tz/tzdata/package.nix index ad04029c4b80..75cb3cc49134 100644 --- a/pkgs/by-name/tz/tzdata/package.nix +++ b/pkgs/by-name/tz/tzdata/package.nix @@ -8,16 +8,16 @@ stdenv.mkDerivation (finalAttrs: { pname = "tzdata"; - version = "2026b"; + version = "2026c"; srcs = [ (fetchurl { url = "https://data.iana.org/time-zones/releases/tzdata${finalAttrs.version}.tar.gz"; - hash = "sha256-EUVD2fGaa/61vKQ2hq6hc9OHVaPbHy7sESZHrpLG9UQ="; + hash = "sha256-5KF4pEd/PQ6nfMMYKP9yqjj+/41hqhPn6Z4ULp2QK+Q="; }) (fetchurl { url = "https://data.iana.org/time-zones/releases/tzcode${finalAttrs.version}.tar.gz"; - hash = "sha256-N+nthCf101IcIvxY4pPL+wQ9cO7fEAOHCzPzY/Yco0Q="; + hash = "sha256-sc/8Os5MTHzQ77ovet2G7D0LedpIvPA1gmcf08j+rOg="; }) ]; From 35bc5963173e21d180dcc5b710bfa529de227a31 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 11 Jul 2026 04:54:39 +0000 Subject: [PATCH 014/175] systemd: 261 -> 261.1 --- pkgs/os-specific/linux/systemd/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/systemd/default.nix b/pkgs/os-specific/linux/systemd/default.nix index eab1a27055ec..b683f04df4ce 100644 --- a/pkgs/os-specific/linux/systemd/default.nix +++ b/pkgs/os-specific/linux/systemd/default.nix @@ -203,13 +203,13 @@ let in stdenv.mkDerivation (finalAttrs: { inherit pname; - version = "261"; + version = "261.1"; src = fetchFromGitHub { owner = "systemd"; repo = "systemd"; tag = "v${finalAttrs.version}"; - hash = "sha256-6IB1ZEQqQ0impwBhCaLZAEgMVkVFU61JDVlGotxNzGQ="; + hash = "sha256-4iOitWGdRmGgJjEXGWtq2lEhPtGguma+qrjTShrps2g="; }; # PATCH POLICY From 9508ddad2bc47296254da425127ff1b2d9b4c9c9 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 11 Jul 2026 09:57:44 +0000 Subject: [PATCH 015/175] fontconfig: 2.18.1 -> 2.18.2 --- pkgs/development/libraries/fontconfig/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/libraries/fontconfig/default.nix b/pkgs/development/libraries/fontconfig/default.nix index c30fc7de65e5..ef66147699a4 100644 --- a/pkgs/development/libraries/fontconfig/default.nix +++ b/pkgs/development/libraries/fontconfig/default.nix @@ -17,7 +17,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "fontconfig"; - version = "2.18.1"; + version = "2.18.2"; outputs = [ "bin" @@ -30,7 +30,7 @@ stdenv.mkDerivation (finalAttrs: { # ref: https://github.com/NixOS/nixpkgs/pull/401037#discussion_r2055430206 src = fetchurl { url = "https://gitlab.freedesktop.org/api/v4/projects/890/packages/generic/fontconfig/${finalAttrs.version}/fontconfig-${finalAttrs.version}.tar.xz"; - hash = "sha256-IwDz2/pyU7OkT0/uzbyN+kXd5dws+3H86vMfOUy0EDE="; + hash = "sha256-z45ldu8EhMFQeb2vd82cUcRk31NlgUraTT7nMx6jHrU="; }; nativeBuildInputs = [ From df13b3e4a4813eb24ebf7a43824505f7a63120d8 Mon Sep 17 00:00:00 2001 From: Clara Engler Date: Thu, 9 Jul 2026 19:36:47 +0200 Subject: [PATCH 016/175] libressl: Actually utilize cacert This commit adds a libressl patch that makes LibreSSL to actually use the cacert bundle we supply, as there was an upstream CMake bug that lead CMake to ignore custom paths to CI bundles. --- pkgs/by-name/li/libressl/default.nix | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/pkgs/by-name/li/libressl/default.nix b/pkgs/by-name/li/libressl/default.nix index 08f7090b6ca1..388012be7dbf 100644 --- a/pkgs/by-name/li/libressl/default.nix +++ b/pkgs/by-name/li/libressl/default.nix @@ -139,6 +139,13 @@ let url = "https://github.com/libressl/portable/commit/a15ea0710398eaeed3be53cf643e80a1e80c981d.patch"; hash = "sha256-Mlf4SrGCCqALQicbGtmVGdkdfcE8DEGYkOuVyG2CozM="; }; + + # https://github.com/libressl/portable/issues/1295 + # https://github.com/libressl/portable/pull/1303 + tls-default-ca-patch = fetchpatch { + url = "https://github.com/libressl/portable/commit/c85e07d0d68129fc1b1c9039b266099c8d735c3d.patch"; + hash = "sha256-oNL3v8Ef1HrayXn+/3T4UhHLJos8eVMlqebVyaxnWVo="; + }; in { # 4.2 was released October 2025 and will become unsupported on October 22, @@ -148,6 +155,7 @@ in hash = "sha256-bVwvWFg1iOp5H0yGRQBAcdAN+lVKW/eIoAbKHrWr1ws="; patches = [ common-cmake-install-full-dirs-patch + tls-default-ca-patch ]; }; @@ -156,5 +164,8 @@ in libressl_4_3 = generic { version = "4.3.2"; hash = "sha256-7fAa7iTGXWnmqe/LnUS82mgv+dTzu72V55Th36kIR7U="; + patches = [ + tls-default-ca-patch + ]; }; } From f186affb81e3a868e0b703c94b39e5756ec6957a Mon Sep 17 00:00:00 2001 From: Clara Engler Date: Sat, 11 Jul 2026 12:18:23 +0200 Subject: [PATCH 017/175] libressl: Test for cacert binary match This commit adds an installCheckPhase that grep's for a binary match inside the result, in order to verify that our own CA store is actually honored. --- pkgs/by-name/li/libressl/default.nix | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/pkgs/by-name/li/libressl/default.nix b/pkgs/by-name/li/libressl/default.nix index 388012be7dbf..dd409c5bfe9f 100644 --- a/pkgs/by-name/li/libressl/default.nix +++ b/pkgs/by-name/li/libressl/default.nix @@ -100,6 +100,17 @@ let moveToOutput "share/man/man1/nc.1.gz" "$nc" ''; + doInstallCheck = true; + installCheckPhase = '' + runHook preInstallCheck + + # Check whether the build target actually contains our cacert. + # A simple binary match for the path is enough. + grep "${cacert}/etc/ssl/certs/ca-bundle.crt" $out/lib/*libtls* + + runHook postInstallCheck + ''; + meta = { description = "Free TLS/SSL implementation"; homepage = "https://www.libressl.org"; From 5614859b5ae42fe612f0bf24a47e08d2076c09a5 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 11 Jul 2026 13:02:20 +0000 Subject: [PATCH 018/175] graphviz-nox: 14.1.2 -> 15.1.0 --- pkgs/by-name/gr/graphviz/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/gr/graphviz/package.nix b/pkgs/by-name/gr/graphviz/package.nix index f5686e0274d3..1ecd084a70c5 100644 --- a/pkgs/by-name/gr/graphviz/package.nix +++ b/pkgs/by-name/gr/graphviz/package.nix @@ -39,13 +39,13 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "graphviz"; - version = "14.1.2"; + version = "15.1.0"; src = fetchFromGitLab { owner = "graphviz"; repo = "graphviz"; tag = finalAttrs.version; - hash = "sha256-LkyiKl0ulS9ujEdVLfyeoc4CtjITd6CAc35IUtlHSfw="; + hash = "sha256-5v/ib8hwqHrJLs+jvDGvg0aJiKIt8ipXEd1EUzew7XU="; }; nativeBuildInputs = [ From d88eb9f1717da48ae255788838d782ec4d0de63c Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Sat, 11 Jul 2026 10:28:20 -0400 Subject: [PATCH 019/175] findutils: 4.10.0 -> 4.11.0 Changelog: https://cgit.git.savannah.gnu.org/cgit/findutils.git/tree/NEWS?h=v4.11.0 --- pkgs/tools/misc/findutils/default.nix | 14 +- ...loat-h-tests-port-to-C23-PowerPC-GCC.patch | 225 ------------------ 2 files changed, 5 insertions(+), 234 deletions(-) delete mode 100644 pkgs/tools/misc/findutils/gnulib-float-h-tests-port-to-C23-PowerPC-GCC.patch diff --git a/pkgs/tools/misc/findutils/default.nix b/pkgs/tools/misc/findutils/default.nix index 7a849b55db32..5e2d0fbe6f3c 100644 --- a/pkgs/tools/misc/findutils/default.nix +++ b/pkgs/tools/misc/findutils/default.nix @@ -13,24 +13,19 @@ stdenv.mkDerivation (finalAttrs: { pname = "findutils"; - version = "4.10.0"; + version = "4.11.0"; src = fetchurl { url = "mirror://gnu/findutils/findutils-${finalAttrs.version}.tar.xz"; - sha256 = "sha256-E4fgtn/yR9Kr3pmPkN+/cMFJE5Glnd/suK5ph4nwpPU="; + sha256 = "sha256-v9GcsGzHHzNS1WfpAoTYzawCrIl3S76t8LUzsMEUMv0="; }; postPatch = '' - substituteInPlace xargs/xargs.c --replace 'char default_cmd[] = "echo";' 'char default_cmd[] = "${coreutils}/bin/echo";' + substituteInPlace xargs/xargs.c --replace 'char default_cmd[] = "echo";' 'char default_cmd[] = "${lib.getExe' coreutils "echo"}";' ''; patches = [ ./no-install-statedir.patch - - # Fixes test-float failure on ppc64 with C23 - # https://lists.gnu.org/archive/html/bug-gnulib/2025-07/msg00021.html - # Multiple upstream commits squashed with adjustments, see header - ./gnulib-float-h-tests-port-to-C23-PowerPC-GCC.patch ]; nativeBuildInputs = [ updateAutotoolsGnuConfigScriptsHook ]; @@ -53,7 +48,7 @@ stdenv.mkDerivation (finalAttrs: { configureFlags = [ # "sort" need not be on the PATH as a run-time dep, so we need to tell # configure where it is. Covers the cross and native case alike. - "SORT=${coreutils}/bin/sort" + "SORT=${lib.getExe' coreutils "sort"}" "--localstatedir=/var/cache" ]; @@ -86,6 +81,7 @@ stdenv.mkDerivation (finalAttrs: { meta = { homepage = "https://www.gnu.org/software/findutils/"; + changelog = "https://cgit.git.savannah.gnu.org/cgit/findutils.git/tree/NEWS?h=v${finalAttrs.version}"; description = "GNU Find Utilities, the basic directory searching utilities of the GNU operating system"; longDescription = '' The GNU Find Utilities are the basic directory searching diff --git a/pkgs/tools/misc/findutils/gnulib-float-h-tests-port-to-C23-PowerPC-GCC.patch b/pkgs/tools/misc/findutils/gnulib-float-h-tests-port-to-C23-PowerPC-GCC.patch deleted file mode 100644 index 5eb610a1c2c6..000000000000 --- a/pkgs/tools/misc/findutils/gnulib-float-h-tests-port-to-C23-PowerPC-GCC.patch +++ /dev/null @@ -1,225 +0,0 @@ -Applied the following incremental gnulib commits: - -- 55a366a06fbd98bf13adc531579e3513cee97a32 -- 65ed9d3b24ad09fd61d326c83e7f1b05f6e9d65f -- ce8e9de0bf34bc63dffc67ab384334c509175f64 -- 6164b4cb0887b5331a4e64449107decd37d32735 - -With adjustments specific to the structure & differences in findutils: - -- gnulib code is split across gl/lib and gnulib-tests -- float.in.h seems old, lacking blocks for standards C11 and up. Relevant code for LDBL_NORM_MAX was added. -- A Makefile.in is used for the test flags instead of the fancy automake modules - in the upstream gnulib project, so we add -lm to the float test there. - Surrounding texts in this file are slightly different in every project. ---- -diff '--color=auto' -ruN a/gl/lib/float.c b/gl/lib/float.c ---- a/gl/lib/float.c 2024-01-01 21:35:38.000000000 +0100 -+++ b/gl/lib/float.c 2026-01-02 16:11:07.508755119 +0100 -@@ -22,7 +22,7 @@ - - #if (defined _ARCH_PPC || defined _POWER) && (defined _AIX || defined __linux__) && (LDBL_MANT_DIG == 106) && defined __GNUC__ - const union gl_long_double_union gl_LDBL_MAX = -- { { DBL_MAX, DBL_MAX / (double)134217728UL / (double)134217728UL } }; -+ { { DBL_MAX, DBL_MAX / 0x1p53 } }; - #elif defined __i386__ - const union gl_long_double_union gl_LDBL_MAX = - { { 0xFFFFFFFF, 0xFFFFFFFF, 32766 } }; -diff '--color=auto' -ruN a/gl/lib/float.in.h b/gl/lib/float.in.h ---- a/gl/lib/float.in.h 2024-01-01 21:35:38.000000000 +0100 -+++ b/gl/lib/float.in.h 2026-01-02 16:13:56.571684867 +0100 -@@ -111,44 +111,38 @@ - # define LDBL_MAX_10_EXP 4932 - #endif - --/* On AIX 7.1 with gcc 4.2, the values of LDBL_MIN_EXP, LDBL_MIN, LDBL_MAX are -- wrong. -- On Linux/PowerPC with gcc 4.4, the value of LDBL_MAX is wrong. */ --#if (defined _ARCH_PPC || defined _POWER) && defined _AIX && (LDBL_MANT_DIG == 106) && defined __GNUC__ -+/* On PowerPC with gcc 15 when using __ibm128 long double, the value of -+ LDBL_MIN_EXP, LDBL_MIN, LDBL_MAX, and LDBL_NORM_MAX are wrong. */ -+#if ((defined _ARCH_PPC || defined _POWER) && LDBL_MANT_DIG == 106 \ -+ && defined __GNUC__) - # undef LDBL_MIN_EXP - # define LDBL_MIN_EXP DBL_MIN_EXP - # undef LDBL_MIN_10_EXP - # define LDBL_MIN_10_EXP DBL_MIN_10_EXP - # undef LDBL_MIN - # define LDBL_MIN 2.22507385850720138309023271733240406422e-308L /* DBL_MIN = 2^-1022 */ --#endif --#if (defined _ARCH_PPC || defined _POWER) && (defined _AIX || defined __linux__) && (LDBL_MANT_DIG == 106) && defined __GNUC__ - # undef LDBL_MAX --/* LDBL_MAX is represented as { 0x7FEFFFFF, 0xFFFFFFFF, 0x7C8FFFFF, 0xFFFFFFFF }. -- It is not easy to define: -- #define LDBL_MAX 1.79769313486231580793728971405302307166e308L -- is too small, whereas -- #define LDBL_MAX 1.79769313486231580793728971405302307167e308L -- is too large. Apparently a bug in GCC decimal-to-binary conversion. -- Also, I can't get values larger than -- #define LDBL63 ((long double) (1ULL << 63)) -- #define LDBL882 (LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63) -- #define LDBL945 (LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63) -- #define LDBL1008 (LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63 * LDBL63) -- #define LDBL_MAX (LDBL1008 * 65535.0L + LDBL945 * (long double) 9223372036821221375ULL + LDBL882 * (long double) 4611686018427387904ULL) -- which is represented as { 0x7FEFFFFF, 0xFFFFFFFF, 0x7C8FFFFF, 0xF8000000 }. -- So, define it like this through a reference to an external variable -+/* LDBL_MAX is 2**1024 - 2**918, represented as: { 0x7FEFFFFF, 0xFFFFFFFF, -+ 0x7C9FFFFF, 0xFFFFFFFF }. -+ -+ Do not write it as a constant expression, as GCC would likely treat -+ that as infinity due to the vagaries of this platform's funky arithmetic. -+ Instead, define it through a reference to an external variable. -+ Like the following, but using a union to avoid type mismatches: - -- const double LDBL_MAX[2] = { DBL_MAX, DBL_MAX / (double)134217728UL / (double)134217728UL }; -+ const double LDBL_MAX[2] = { DBL_MAX, DBL_MAX / 0x1p53 }; - extern const long double LDBL_MAX; - -- or through a pointer cast -+ The following alternative would not work as well when GCC is optimizing: -+ -+ #define LDBL_MAX (*(long double const *) (double[]) -+ { DBL_MAX, DBL_MAX / 0x1p53 }) - -- #define LDBL_MAX \ -- (*(const long double *) (double[]) { DBL_MAX, DBL_MAX / (double)134217728UL / (double)134217728UL }) -+ The following alternative would require GCC 6 or later: - -- Unfortunately, this is not a constant expression, and the latter expression -- does not work well when GCC is optimizing.. */ -+ #define LDBL_MAX __builtin_pack_longdouble (DBL_MAX, DBL_MAX / 0x1p53) -+ -+ Unfortunately none of the alternatives are constant expressions. */ - # if !GNULIB_defined_long_double_union - union gl_long_double_union - { -@@ -159,6 +153,8 @@ - # endif - extern const union gl_long_double_union gl_LDBL_MAX; - # define LDBL_MAX (gl_LDBL_MAX.ld) -+# undef LDBL_NORM_MAX -+# define LDBL_NORM_MAX LDBL_MAX - #endif - - /* On IRIX 6.5, with cc, the value of LDBL_MANT_DIG is wrong. -@@ -179,6 +175,35 @@ - # endif - #endif - -+/* On PowerPC platforms, 'long double' has a double-double representation. -+ Up to ISO C 17, this was outside the scope of ISO C because it can represent -+ numbers with mantissas of the form 1.<52 bits><52 bits>, such as -+ 1.0L + 4.94065645841246544176568792868221e-324L = 1 + 2^-1074; see -+ ISO C 17 § 5.2.4.2.2.(3). -+ In ISO C 23, wording has been included that makes this 'long double' -+ representation compliant; see ISO C 23 § 5.2.5.3.3.(8)-(9). In this setting, -+ numbers with mantissas of the form 1.<52 bits><52 bits> are -+ called "unnormalized". And since LDBL_EPSILON must be normalized (per -+ ISO C 23 § 5.2.5.3.3.(33)), it must be 2^-105. */ -+#if defined __powerpc__ && LDBL_MANT_DIG == 106 -+# undef LDBL_EPSILON -+# define LDBL_EPSILON 2.46519032881566189191165176650870696773e-32L /* 2^-105 */ -+#endif -+ -+/* ============================ ISO C23 support ============================ */ -+ -+/* 'long double' properties */ -+ -+#ifndef LDBL_NORM_MAX -+# ifdef __LDBL_NORM_MAX__ -+# define LDBL_NORM_MAX __LDBL_NORM_MAX__ -+# else -+# define LDBL_NORM_MAX LDBL_MAX -+# endif -+#endif -+ -+/* ================================= Other ================================= */ -+ - #if @REPLACE_ITOLD@ - /* Pull in a function that fixes the 'int' to 'long double' conversion - of glibc 2.7. */ -diff '--color=auto' -ruN a/gnulib-tests/Makefile.in b/gnulib-tests/Makefile.in ---- a/gnulib-tests/Makefile.in 2024-06-01 18:18:09.000000000 +0200 -+++ b/gnulib-tests/Makefile.in 2026-01-02 15:56:12.645625323 +0100 -@@ -1172,7 +1172,7 @@ - ../gl/lib/libgnulib.a libtests.a $(am__DEPENDENCIES_1) - test_float_SOURCES = test-float.c - test_float_OBJECTS = test-float.$(OBJEXT) --test_float_LDADD = $(LDADD) -+test_float_LDADD = $(LDADD) -lm - test_float_DEPENDENCIES = libtests.a ../gl/lib/libgnulib.a libtests.a \ - ../gl/lib/libgnulib.a libtests.a $(am__DEPENDENCIES_1) - test_fnmatch_SOURCES = test-fnmatch.c -diff '--color=auto' -ruN a/gnulib-tests/test-float.c b/gnulib-tests/test-float.c ---- a/gnulib-tests/test-float.c 2024-05-27 21:48:37.000000000 +0200 -+++ b/gnulib-tests/test-float.c 2026-01-02 16:15:21.261123584 +0100 -@@ -59,6 +59,8 @@ - - /* ------------------------------------------------------------------------- */ - -+#include -+ - #include "fpucw.h" - #include "macros.h" - -@@ -295,6 +297,44 @@ - - /* -------------------- Check macros for 'long double' -------------------- */ - -+static int -+test_isfinitel (long double volatile x) -+{ -+ if (x != x) -+ return 0; -+ long double volatile zero = x * 0; -+ return zero == 0; -+} -+ -+/* Return X after normalization. This makes a difference on platforms -+ where long double can represent unnormalized values. For example, -+ suppose x = 1 + 2**-106 on PowerPC with IBM long double where -+ FLT_RADIX = 2, LDBL_MANT_DIG = 106, and LDBL_EPSILON = 2**-105. -+ Then 1 < x < 1 + LDBL_EPSILON, and normalize_long_double (x) returns 1. */ -+static long double -+normalize_long_double (long double volatile x) -+{ -+ if (FLT_RADIX == 2 && test_isfinitel (x)) -+ { -+ int xexp; -+ long double volatile -+ frac = frexpl (x, &xexp), -+ significand = frac * pow2l (LDBL_MANT_DIG), -+ normalized_significand = truncl (significand), -+ normalized_x = normalized_significand * pow2l (xexp - LDBL_MANT_DIG); -+ -+ /* The test_isfinitel defends against PowerPC with IBM long double, -+ which fritzes out near LDBL_MAX. */ -+ if (test_isfinitel (normalized_x)) -+ x = normalized_x; -+ } -+ else -+ { -+ /* Hope that X is already normalized. */ -+ } -+ return x; -+} -+ - static void - test_long_double (void) - { -@@ -354,11 +394,14 @@ - for (n = 0; n <= 2 * LDBL_MANT_DIG; n++) - { - volatile long double half_n = pow2l (- n); /* 2^-n */ -- volatile long double x = me - half_n; -+ volatile long double x = normalize_long_double (me - half_n); - if (x < me) - ASSERT (x <= 1.0L); - } - } -+ -+ /* Check the value of LDBL_NORM_MAX. */ -+ ASSERT (LDBL_NORM_MAX == normalize_long_double (LDBL_MAX)); - } - - int From 12babd1e2a87b0eb1147e4dc3acf69707dfd5b91 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 12 Jul 2026 01:31:48 +0000 Subject: [PATCH 020/175] libsodium: 1.0.22-unstable-2026-04-16 -> 1.0.22-unstable-2026-07-08 --- pkgs/by-name/li/libsodium/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/li/libsodium/package.nix b/pkgs/by-name/li/libsodium/package.nix index 3fc91abaf0ca..4b27cbb4c759 100644 --- a/pkgs/by-name/li/libsodium/package.nix +++ b/pkgs/by-name/li/libsodium/package.nix @@ -9,13 +9,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "libsodium"; - version = "1.0.22-unstable-2026-04-16"; + version = "1.0.22-unstable-2026-07-08"; src = fetchFromGitHub { owner = "jedisct1"; repo = "libsodium"; - rev = "33cc75ab1565d9dcbe808354191bd572ad6b64d0"; - hash = "sha256-8kS9FBoaFaJOjH7XZc8IG3GaQaUiYD/awQOhs7j0n1Y="; + rev = "77a422c85a3b8b487de50c811b38d18394831ba6"; + hash = "sha256-Ahka2PnrmYvTLjZMzik5mFsxhDpMLRMKT/I5ftUb0Xc="; }; outputs = [ From cbd66b68e2eeebccd29d17927e5e3e51397e7cf7 Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Sun, 12 Jul 2026 11:41:40 +0200 Subject: [PATCH 021/175] libffiReal: 3.7.0 -> 3.7.1 --- pkgs/by-name/li/libffiReal/package.nix | 7 ++----- 1 file changed, 2 insertions(+), 5 deletions(-) diff --git a/pkgs/by-name/li/libffiReal/package.nix b/pkgs/by-name/li/libffiReal/package.nix index 3ccee9419fc5..be10e7392350 100644 --- a/pkgs/by-name/li/libffiReal/package.nix +++ b/pkgs/by-name/li/libffiReal/package.nix @@ -13,13 +13,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "libffi"; - version = "3.7.0"; + version = "3.7.1"; src = fetchurl { url = with finalAttrs; "https://github.com/libffi/libffi/releases/download/v${version}/${pname}-${version}.tar.gz"; - hash = "sha256-IlXFpjjftRv2fCChKnu3DRf+senqurrAX1VzFG9YZDY="; + hash = "sha256-1emmY43b0lE921RRjrZ+S75vpwe8wBwQ9iEvCgiNgZ0="; }; # Note: this package is used for bootstrapping fetchurl, and thus @@ -32,9 +32,6 @@ stdenv.mkDerivation (finalAttrs: { ./freebsd-tsan-pthread.patch ]; - # To workaround https://github.com/libffi/libffi/issues/993, we empty the test file: - postPatch = lib.optionalString stdenv.hostPlatform.isDarwin "echo 'int main (void) { return 0; }' > testsuite/libffi.call/i128-1.c"; - strictDeps = true; outputs = [ "out" From 5964572d17730bf5569fcc11926928298fd05efc Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Sun, 12 Jul 2026 11:43:44 +0200 Subject: [PATCH 022/175] libffiReal: add aduh95 as maintainer --- pkgs/by-name/li/libffiReal/package.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/by-name/li/libffiReal/package.nix b/pkgs/by-name/li/libffiReal/package.nix index be10e7392350..069f6508d0ce 100644 --- a/pkgs/by-name/li/libffiReal/package.nix +++ b/pkgs/by-name/li/libffiReal/package.nix @@ -91,7 +91,7 @@ stdenv.mkDerivation (finalAttrs: { ''; homepage = "http://sourceware.org/libffi/"; license = lib.licenses.mit; - maintainers = [ ]; + maintainers = with lib.maintainers; [ aduh95 ]; platforms = lib.platforms.all; pkgConfigModules = [ "libffi" ]; }; From 6204aa2983578ae637ad0d4a52eb5a8aca97a12b Mon Sep 17 00:00:00 2001 From: Sergei Trofimovich Date: Sun, 12 Jul 2026 19:41:42 +0100 Subject: [PATCH 023/175] ethtool: 7.0 -> 7.1 Changes: https://git.kernel.org/pub/scm/network/ethtool/ethtool.git/log/?h=v7.1 --- pkgs/by-name/et/ethtool/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/et/ethtool/package.nix b/pkgs/by-name/et/ethtool/package.nix index bd0c1320e711..5c3e2421f418 100644 --- a/pkgs/by-name/et/ethtool/package.nix +++ b/pkgs/by-name/et/ethtool/package.nix @@ -9,11 +9,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "ethtool"; - version = "7.0"; + version = "7.1"; src = fetchurl { url = "mirror://kernel/software/network/ethtool/ethtool-${finalAttrs.version}.tar.xz"; - hash = "sha256-Zgv5clp4cTQ6DSMgaKdjT7z7abbC+O/0VYJ/rvsM0WI="; + hash = "sha256-TXjCbtwCVbyS9LmVtf1mEI11/5Zu1GlPYCWm03C8JJY="; }; nativeBuildInputs = [ From 55781a05ed00e68a43223952cf8f98c28b5ec170 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 13 Jul 2026 22:27:21 +0000 Subject: [PATCH 024/175] gn: 0-unstable-2026-04-01 -> 0-unstable-2026-05-27 --- pkgs/by-name/gn/gn/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/gn/gn/package.nix b/pkgs/by-name/gn/gn/package.nix index f640662eedf4..3488f91204fd 100644 --- a/pkgs/by-name/gn/gn/package.nix +++ b/pkgs/by-name/gn/gn/package.nix @@ -11,11 +11,11 @@ version ? # This is a workaround for update-source-version to be able to update this let - _version = "0-unstable-2026-04-01"; + _version = "0-unstable-2026-05-27"; in _version, - rev ? "6e8dcdebbadf4f8aa75e6a4b6e0bdf89dce1513a", - hash ? "sha256-BTPD8WM1pVAMkFDlHekMdWFGyf63KdhKkKwsqikqoBQ=", + rev ? "3357c4f51b1a9e676378c695dd9c7e9911c35ee6", + hash ? "sha256-/1A+DkzAQj2zGPe/A/G0Z3VrYJXUxq4Hd/+d/o5p3G8=", }: stdenv.mkDerivation { From 60451d9fcf5531a68fa146555189a5782f1289e6 Mon Sep 17 00:00:00 2001 From: klea Date: Tue, 14 Jul 2026 17:28:43 +0000 Subject: [PATCH 025/175] sox: fix version scheme --- pkgs/by-name/so/sox/package.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/by-name/so/sox/package.nix b/pkgs/by-name/so/sox/package.nix index ff27759ea250..87aca6e24e06 100644 --- a/pkgs/by-name/so/sox/package.nix +++ b/pkgs/by-name/so/sox/package.nix @@ -38,7 +38,7 @@ stdenv.mkDerivation { pname = "sox"; - version = "unstable-2021-05-09"; + version = "14.4.2-unstable-2021-05-09"; src = fetchgit { # not really needed, but when this src was updated from `fetchurl -> From df0809760cafcbb215f566f33227560605a6a3e4 Mon Sep 17 00:00:00 2001 From: klea Date: Tue, 14 Jul 2026 17:40:27 +0000 Subject: [PATCH 026/175] sox: Remove src.name since going trough staging --- pkgs/by-name/so/sox/package.nix | 4 ---- 1 file changed, 4 deletions(-) diff --git a/pkgs/by-name/so/sox/package.nix b/pkgs/by-name/so/sox/package.nix index 87aca6e24e06..264599cddbc3 100644 --- a/pkgs/by-name/so/sox/package.nix +++ b/pkgs/by-name/so/sox/package.nix @@ -41,10 +41,6 @@ stdenv.mkDerivation { version = "14.4.2-unstable-2021-05-09"; src = fetchgit { - # not really needed, but when this src was updated from `fetchurl -> - # fetchgit`, we spared the mass rebuild by changing this `name` and - # therefor merge this to `master` and not to `staging`. - name = "source"; url = "https://git.code.sf.net/p/sox/code"; rev = "42b3557e13e0fe01a83465b672d89faddbe65f49"; hash = "sha256-9cpOwio69GvzVeDq79BSmJgds9WU5kA/KUlAkHcpN5c="; From af253c905aa77ac05f4c4b220ad3753f13017a93 Mon Sep 17 00:00:00 2001 From: Grimmauld Date: Tue, 14 Jul 2026 20:08:51 +0200 Subject: [PATCH 027/175] libapparmor: 5.0.1 -> 5.0.2 --- pkgs/by-name/li/libapparmor/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/li/libapparmor/package.nix b/pkgs/by-name/li/libapparmor/package.nix index e7411cc092ce..66c68b1a0620 100644 --- a/pkgs/by-name/li/libapparmor/package.nix +++ b/pkgs/by-name/li/libapparmor/package.nix @@ -32,13 +32,13 @@ }: stdenv.mkDerivation (finalAttrs: { pname = "libapparmor"; - version = "5.0.1"; + version = "5.0.2"; src = fetchFromGitLab { owner = "apparmor"; repo = "apparmor"; tag = "v${finalAttrs.version}"; - hash = "sha256-y5r8X7Cpwp7TSsKYXNoAeyy0MbgxLSW8gNtLsIvKP8c="; + hash = "sha256-Kuc5Nrz4iq5MC5AOcJL9Sb54DWNKlEk3b3DW0vpgSZg="; }; sourceRoot = "${finalAttrs.src.name}/libraries/libapparmor"; From 50d878deeef7da3125f8eed14efbffee1a402403 Mon Sep 17 00:00:00 2001 From: klea Date: Tue, 14 Jul 2026 18:15:03 +0000 Subject: [PATCH 028/175] sox: use finalAttrs --- pkgs/by-name/so/sox/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/so/sox/package.nix b/pkgs/by-name/so/sox/package.nix index 264599cddbc3..b85d62ad34a2 100644 --- a/pkgs/by-name/so/sox/package.nix +++ b/pkgs/by-name/so/sox/package.nix @@ -36,7 +36,7 @@ libpulseaudio, }: -stdenv.mkDerivation { +stdenv.mkDerivation (finalAttrs: { pname = "sox"; version = "14.4.2-unstable-2021-05-09"; @@ -90,4 +90,4 @@ stdenv.mkDerivation { license = if enableAMR then lib.licenses.unfree else lib.licenses.gpl2Plus; platforms = lib.platforms.unix; }; -} +}) From 5dbb5ece48b017ffd495930c7a8e8289c0a4f527 Mon Sep 17 00:00:00 2001 From: OPNA2608 Date: Tue, 14 Jul 2026 22:32:36 +0200 Subject: [PATCH 029/175] libgpg-error: Fix t-printf test on some platforms, patch around failures on others powerpc64-linux: Our current GCC is 15.x, project sets no C standard so C23 gets used. long double stuff has always been weirder on this platform, and GCC's C23 further messed with the LDBL_* values. --- ...test-when-not-HAVE_LONG_DOUBLE_WIDER.patch | 59 +++++++++++++++++++ pkgs/by-name/li/libgpg-error/package.nix | 23 +++++++- 2 files changed, 81 insertions(+), 1 deletion(-) create mode 100644 pkgs/by-name/li/libgpg-error/libgpg-error-tests-skip-a-test-when-not-HAVE_LONG_DOUBLE_WIDER.patch diff --git a/pkgs/by-name/li/libgpg-error/libgpg-error-tests-skip-a-test-when-not-HAVE_LONG_DOUBLE_WIDER.patch b/pkgs/by-name/li/libgpg-error/libgpg-error-tests-skip-a-test-when-not-HAVE_LONG_DOUBLE_WIDER.patch new file mode 100644 index 000000000000..083fb8672f56 --- /dev/null +++ b/pkgs/by-name/li/libgpg-error/libgpg-error-tests-skip-a-test-when-not-HAVE_LONG_DOUBLE_WIDER.patch @@ -0,0 +1,59 @@ +commit bfdf7b0b7b62f4463451a7d5f8408cec75520dca +Author: NIIBE Yutaka +Date: Thu Jun 25 10:53:29 2026 +0900 + + tests: Skip a test when !HAVE_LONG_DOUBLE_WIDER. + + * configure.ac (AC_TYPE_LONG_DOUBLE_WIDER): New. + * tests/t-printf.c (check_large_float): Fix a typo. + [!HAVE_LONG_DOUBLE_WIDER]: Skip the LDBL_MAX test. + + -- + + GnuPG-bug-id: 8309 + Signed-off-by: NIIBE Yutaka + +diff --git a/configure.ac b/configure.ac +index e9abe0d..7871769 100644 +--- a/configure.ac ++++ b/configure.ac +@@ -276,6 +276,7 @@ AC_C_CONST + AC_CHECK_SIZEOF(int) + AC_CHECK_SIZEOF(long) + AC_CHECK_SIZEOF(long long) ++AC_TYPE_LONG_DOUBLE_WIDER + + GNUPG_FUNC_MKDIR_TAKES_ONE_ARG + +diff --git a/tests/t-printf.c b/tests/t-printf.c +index 6cbd03f..b0a3f3f 100644 +--- a/tests/t-printf.c ++++ b/tests/t-printf.c +@@ -449,7 +449,7 @@ check_large_float (void) + errno, strerror (errno)); + } + else if (verbose) +- show ("format \"%%.100f\" with DBL_MAX: ->%s<-\n", buf2); ++ show ("format \"%%.101f\" with DBL_MAX: ->%s<-\n", buf2); + + if (strcmp (buf, buf2)) + fail ("format \"%%.100f\" does not match \"%%.101f\"\n" ); +@@ -469,6 +469,7 @@ check_large_float (void) + show ("format \"%%.100Lf\" with DBL_MAX: ->%s<-\n", buf); + gpgrt_free (buf); + ++# ifdef HAVE_LONG_DOUBLE_WIDER + ld = LDBL_MAX; + buf = gpgrt_bsprintf ("%.100Lf\n", ld); + if (buf) +@@ -478,6 +479,10 @@ check_large_float (void) + else if (verbose) + show ("format \"%%.100Lf\" with LDBL_MAX failed as expected\n"); + gpgrt_free (buf); ++# else ++ if (verbose) ++ show ("LDBL_MAX == DBL_MAX - skipping LDBL_MAX test\n"); ++# endif + + #endif /*HAVE_LONG_DOUBLE*/ + } diff --git a/pkgs/by-name/li/libgpg-error/package.nix b/pkgs/by-name/li/libgpg-error/package.nix index c086abb3c806..1c6d8590da60 100644 --- a/pkgs/by-name/li/libgpg-error/package.nix +++ b/pkgs/by-name/li/libgpg-error/package.nix @@ -1,6 +1,7 @@ { stdenv, lib, + autoreconfHook, buildPackages, fetchurl, gettext, @@ -32,6 +33,12 @@ stdenv.mkDerivation ( hash = "sha256-eoVBPyvDVPT4qoMrcYrxIuSJZeng65AS7mWcE8Y4XJM="; }; + patches = [ + # Fixes t-printf test on platforms where LDBL_MAX == DBL_MAX (armhf, ppc64) + # Upstream's git forge doesn't seem to have a nice way to download it :/ + ./libgpg-error-tests-skip-a-test-when-not-HAVE_LONG_DOUBLE_WIDER.patch + ]; + postPatch = '' sed '/BUILD_TIMESTAMP=/s/=.*/=1970-01-01T00:01+0000/' -i ./configure '' @@ -39,6 +46,17 @@ stdenv.mkDerivation ( # so add one for FreeBSD. + lib.optionalString (stdenv.hostPlatform.system == "x86_64-freebsd") '' cp ${./lock-obj-pub.x86_64-unknown-freebsd.h} src/syscfg/lock-obj-pub.freebsd.h + '' + # Fails on powerpc64-linux + # https://lists.gnupg.org/pipermail/gnupg-users/2026-July/068440.html + + lib.optionalString (stdenv.hostPlatform.isPower64 && stdenv.hostPlatform.isBigEndian) '' + substituteInPlace tests/t-printf.c \ + --replace-fail \ + '# ifdef HAVE_LONG_DOUBLE_WIDER' \ + '# if 0' \ + --replace-fail \ + 'show ("LDBL_MAX == DBL_MAX - skipping LDBL_MAX test\n")' \ + 'show ("LDBL_MAX is weird on this platform - skipping LDBL_MAX test\n")' ''; hardeningDisable = [ "strictflexarrays3" ]; @@ -58,7 +76,10 @@ stdenv.mkDerivation ( # If architecture-dependent MO files aren't available, they're generated # during build, so we need gettext for cross-builds. depsBuildBuild = [ buildPackages.stdenv.cc ]; - nativeBuildInputs = [ gettext ]; + nativeBuildInputs = [ + autoreconfHook # HAVE_LONG_DOUBLE_WIDER patch changes configure.ac + gettext + ]; postConfigure = # For some reason, /bin/sh on OpenIndiana leads to this at the end of the From 351218832216acf809d37bc92dde583eb6e03c41 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 14 Jul 2026 20:39:33 +0000 Subject: [PATCH 030/175] yara: 4.5.6 -> 4.5.7 --- pkgs/by-name/ya/yara/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ya/yara/package.nix b/pkgs/by-name/ya/yara/package.nix index b0f598fe6f1e..6a78cef1c4e4 100644 --- a/pkgs/by-name/ya/yara/package.nix +++ b/pkgs/by-name/ya/yara/package.nix @@ -19,13 +19,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "yara"; - version = "4.5.6"; + version = "4.5.7"; src = fetchFromGitHub { owner = "VirusTotal"; repo = "yara"; tag = "v${finalAttrs.version}"; - hash = "sha256-vzYH56BC0Stb2I4U5VzxA0xG46xZkWmbTIC6BtzeNQ8="; + hash = "sha256-4PK/GU02mcgMSkFllqGZ7zmswQb8b6bkfEWLoCGHo3E="; }; nativeBuildInputs = [ From 26482ee87c2bf3518c64a6d65c2c388eb99d91da Mon Sep 17 00:00:00 2001 From: Will Fancher Date: Tue, 14 Jul 2026 02:32:42 -0400 Subject: [PATCH 031/175] nixos/tests/systemd-boot: Preserve length in sed --- nixos/tests/systemd-boot.nix | 10 ++++------ 1 file changed, 4 insertions(+), 6 deletions(-) diff --git a/nixos/tests/systemd-boot.nix b/nixos/tests/systemd-boot.nix index f36d3870f98e..020644db86a8 100644 --- a/nixos/tests/systemd-boot.nix +++ b/nixos/tests/systemd-boot.nix @@ -460,19 +460,17 @@ in nodes.machine = common; testScript = - let - oldVersion = "222"; - in # python '' machine.succeed("mount -o remount,rw /boot") def switch(): - # Replace version inside sd-boot with something older. See magic[] string in systemd src/boot/efi/boot.c + # Replace version inside sd-boot with something older. See SD_MAGIC in systemd src/boot/boot.c + # Note: the sed replacement has to be length-preserving, because section length matters. machine.succeed( - """ + r""" find /boot -iname '*boot*.efi' -print0 | \ - xargs -0 -I '{}' sed -i 's/#### LoaderInfo: systemd-boot .* ####/#### LoaderInfo: systemd-boot ${oldVersion} ####/' '{}' + xargs -0 -I '{}' sed -i 's/#### LoaderInfo: systemd-boot [0-9]\(.*\) ####/#### LoaderInfo: systemd-boot 0\1 ####/' '{}' """ ) return machine.succeed("/run/current-system/bin/switch-to-configuration boot 2>&1") From dbd0f87198dc2b9d61997027a4ca1f689f89f0b7 Mon Sep 17 00:00:00 2001 From: Andrew Marshall Date: Wed, 15 Jul 2026 09:27:46 -0400 Subject: [PATCH 032/175] spirv-tools: backport fix for crash on newer Vulkan See https://github.com/KhronosGroup/SPIRV-Tools/issues/6712 Notably, this fixes `blender --factory-startup --gpu-backend vulkan` crashing on startup. --- pkgs/by-name/sp/spirv-tools/package.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkgs/by-name/sp/spirv-tools/package.nix b/pkgs/by-name/sp/spirv-tools/package.nix index 16a2bdef93e7..97b842561e42 100644 --- a/pkgs/by-name/sp/spirv-tools/package.nix +++ b/pkgs/by-name/sp/spirv-tools/package.nix @@ -29,6 +29,11 @@ stdenv.mkDerivation (finalAttrs: { url = "https://github.com/KhronosGroup/SPIRV-Tools/commit/2ec8457ab33d539b6f1fecc998360c0b8b05ed4f.diff"; hash = "sha256-YHbYBwXMm4rTKpmMW6I3LUafhA4RuNUdXqUBUAXwXpE="; }) + + (fetchpatch { + url = "https://github.com/KhronosGroup/SPIRV-Tools/commit/0db9162641d9709c63c92a13e66fd88905180e89.diff"; + hash = "sha256-eoS35Zxb+frQTTTNCaZ4TV/QZjaK45mW1OzzIlXQ1C0="; + }) ] # The cmake options are sufficient for turning on static building, but not # for disabling shared building, just trim the shared lib from the CMake From 4893b4e92dbd3858eae5624f290ec49512dcbdf8 Mon Sep 17 00:00:00 2001 From: whispers Date: Wed, 15 Jul 2026 14:29:43 -0400 Subject: [PATCH 033/175] rust: 1.97.0 -> 1.97.1 blog: https://blog.rust-lang.org/releases/1.97.1 changelog: https://github.com/rust-lang/rust/blob/1.97.1/RELEASES.md diff: https://github.com/rust-lang/rust/compare/1.97.0...1.97.1 --- pkgs/development/compilers/rust/1_97.nix | 40 ++++++++++++------------ 1 file changed, 20 insertions(+), 20 deletions(-) diff --git a/pkgs/development/compilers/rust/1_97.nix b/pkgs/development/compilers/rust/1_97.nix index 3105bef9f841..6e5d5f81c8d3 100644 --- a/pkgs/development/compilers/rust/1_97.nix +++ b/pkgs/development/compilers/rust/1_97.nix @@ -50,8 +50,8 @@ let in import ./default.nix { - rustcVersion = "1.97.0"; - rustcSha256 = "sha256-HAhV2JgqD7HQMhtgVLVbcy07HRfIRoQet/0Ks3vydvg="; + rustcVersion = "1.97.1"; + rustcSha256 = "sha256-YiwrQpxTy/3A3TpR0DVU6RzWPr7BkSwfVwlkDN/vGp0="; llvmSharedForBuild = llvmSharedFor pkgsBuildBuild; llvmSharedForHost = llvmSharedFor pkgsBuildHost; @@ -65,27 +65,27 @@ import ./default.nix # Note: the version MUST be the same version that we are building. Upstream # ensures that each released compiler can compile itself: # https://github.com/NixOS/nixpkgs/pull/351028#issuecomment-2438244363 - bootstrapVersion = "1.97.0"; + bootstrapVersion = "1.97.1"; # fetch hashes by running `print-hashes.sh ${bootstrapVersion}` bootstrapHashes = { - i686-unknown-linux-gnu = "d066e5dd59c15fc1c793173d53b41719162de4470b5c34041a8bc664542df375"; - x86_64-unknown-linux-gnu = "eb89b20287153391c49ebcdb7fd91b683a12438d129bfb92eadcc495545af3a7"; - x86_64-unknown-linux-musl = "675bb2d574efc64da0563a9cb70cc017560394c5938e04c92987cad383299e8d"; - arm-unknown-linux-gnueabihf = "180e487a1f7abaeda374b942d369dd7faa4364b1267629d48552d9a17a5bc4ab"; - armv7-unknown-linux-gnueabihf = "2f9dfd76694efcf391f6d4947e97be17d1f469c9e989ed194660ddd85877ca60"; - aarch64-unknown-linux-gnu = "70fb01b4894d56fad34c260ce63aee647589be57a26ab33730110d8228cbcf02"; - aarch64-unknown-linux-musl = "28efcf4ee31235eb5f7820dadba46400ab9dbbb030719e7a2ab284b02c8cbf82"; - x86_64-apple-darwin = "3dc9ad8ec35a9f0acd2c5ae2c80c36baf5c7010423bf339ca55709fc995885d4"; - aarch64-apple-darwin = "c2e6a5ef480f5715ae9874188c1fa749b6a6f90d8d911f5a3a5d768f0ac70427"; - powerpc64-unknown-linux-gnu = "62c9f9b7887505fc4dcda40784469f23909657d245e53025a7a8124b016d6631"; - powerpc64le-unknown-linux-gnu = "a8d3f487d07cebc48ce03ad66a970a5f5138a5c1e7c7cec12fb9b6e47a24bf1a"; - powerpc64le-unknown-linux-musl = "09fee3b9ede1e94ff6c3bad3918dc231be909c74bb182e0acd583c03a9f1df5f"; - riscv64gc-unknown-linux-gnu = "be239392f7112f6a81f20c9e715d5743319a8b773592e027ad800d73527d8fae"; - s390x-unknown-linux-gnu = "fee699e31d0a0034f46669c473e61a88af6734f8c5902d77329ac236fcd9b538"; - loongarch64-unknown-linux-gnu = "37ad9d55b98cc680a2d75c7184e6457b632ce82690a56be7a2044e32c91176ce"; - loongarch64-unknown-linux-musl = "bfba202bae252ac372026171d9bc98e5eb80578d576546f56e8aee2e9d64ecf0"; - x86_64-unknown-freebsd = "77101232e3769395e99c0e663d2c8beb3d4127857945cf7c812c1886ba823b8f"; + i686-unknown-linux-gnu = "914c2702deada0b9cf1d64bb3495d76e55cb3eba07d508472dde8b55a93e3759"; + x86_64-unknown-linux-gnu = "b4cdbc7cc6b0ee0a2666b1872769fdb2ad8393b28b63952f6493b4b400e4832b"; + x86_64-unknown-linux-musl = "40dbea28193cf2b488cf3e4a89274ccfb60efa50883f19917a382f84fd05bdc4"; + arm-unknown-linux-gnueabihf = "ba62fe07ad85b507907705a14adc1e8bc258de5f6177ba41d77bbff9f469a4ce"; + armv7-unknown-linux-gnueabihf = "e89c5e33aaddc6ef56857000c9117875c2997e9a1a500bd7b16277c9874b002f"; + aarch64-unknown-linux-gnu = "2f2496c70bd336a66a4c8baf2d303ba161f3552f192444c3639ba903c7c1e2c5"; + aarch64-unknown-linux-musl = "c5f45b5c6eb7f8fdb277c54c08402b7c931516740fbd4eccc26ba148f7cd5d57"; + x86_64-apple-darwin = "5f4c84d2bcce7983468642855a45fc4978fba1324cfdd1ea0b182face3ab4ffa"; + aarch64-apple-darwin = "cbd14c36f039f6f11f38148a6295d8234d18ddf20bea53031c86f119423a8b26"; + powerpc64-unknown-linux-gnu = "2b507d5eb9b5c4c041b50e93e069db56d094f02e6df103dc74c016155141bfae"; + powerpc64le-unknown-linux-gnu = "ff524eef5a59d801df09ccad5cdaf9ea1f0a07d75cbed2a7e9f013a9eb76a3c1"; + powerpc64le-unknown-linux-musl = "15630f33fbea2dd9661f8482b6c612da271549aba40401444aaa53650e646b9b"; + riscv64gc-unknown-linux-gnu = "59bec35d8febb2ab918fa41cffbaa5b07146a63bdc33f029ff756d70a3151ece"; + s390x-unknown-linux-gnu = "808268af9e880d41b8cb32b242e38c9bd3ea7aba6409b02fbffa0fbc5370c538"; + loongarch64-unknown-linux-gnu = "d5a925962854730ae7641420d8337af93988ea4ff47b503a856ec53776c87841"; + loongarch64-unknown-linux-musl = "3fb653299d228e3e0726afb179b07dd10a51a2ecc3cdfcd740011b1d8420ca97"; + x86_64-unknown-freebsd = "77866a4c449bcccb40e9d6712bf3eb899d29018ed8e841fd9d8d59370751f152"; }; selectRustPackage = pkgs: pkgs.rust_1_97; From 50e42b2d6c84d54f0c40d88eb4e54c171549d87a Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 16 Jul 2026 00:31:08 +0000 Subject: [PATCH 034/175] xsimd: 14.2.0 -> 14.3.0 --- pkgs/by-name/xs/xsimd/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/xs/xsimd/package.nix b/pkgs/by-name/xs/xsimd/package.nix index 1b9e1f3e4788..61df52e4d87a 100644 --- a/pkgs/by-name/xs/xsimd/package.nix +++ b/pkgs/by-name/xs/xsimd/package.nix @@ -8,13 +8,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "xsimd"; - version = "14.2.0"; + version = "14.3.0"; src = fetchFromGitHub { owner = "xtensor-stack"; repo = "xsimd"; tag = finalAttrs.version; - hash = "sha256-BTiN4B3//wlB3nmOoluM/7bL7J7YIBp5afih9zUP1yw="; + hash = "sha256-0m9gUDCgGh58lf9uPp1Obw4rsqWEL1RffWYB6s315p0="; }; # strictDeps raises the chance that xsimd will be able to be cross compiled From 33f1076b16c9ee1ffe9e8b7c667b231e1cd2620d Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 16 Jul 2026 00:59:04 +0000 Subject: [PATCH 035/175] fluidsynth: 2.5.5 -> 2.5.6 --- pkgs/by-name/fl/fluidsynth/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/fl/fluidsynth/package.nix b/pkgs/by-name/fl/fluidsynth/package.nix index d292b8ac7a60..2516e6884814 100644 --- a/pkgs/by-name/fl/fluidsynth/package.nix +++ b/pkgs/by-name/fl/fluidsynth/package.nix @@ -13,13 +13,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "fluidsynth"; - version = "2.5.5"; + version = "2.5.6"; src = fetchFromGitHub { owner = "FluidSynth"; repo = "fluidsynth"; tag = "v${finalAttrs.version}"; - hash = "sha256-WEzOYHtPIUkPZu3v4dWcCh3dOJUyG1xRxDuoSXqiGbk="; + hash = "sha256-q4NdfemCprYEYCrKlHumeRM8TyNz8eJcFM18EsB0p0c="; fetchSubmodules = true; }; From 68a131f652e821c0f26995927e686448b590bfda Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Wed, 15 Jul 2026 20:32:27 -0700 Subject: [PATCH 036/175] fluidsync: add meta.changelog --- pkgs/by-name/fl/fluidsynth/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/fl/fluidsynth/package.nix b/pkgs/by-name/fl/fluidsynth/package.nix index 2516e6884814..13b0587b9f22 100644 --- a/pkgs/by-name/fl/fluidsynth/package.nix +++ b/pkgs/by-name/fl/fluidsynth/package.nix @@ -52,6 +52,7 @@ stdenv.mkDerivation (finalAttrs: { ]; meta = { + changelog = "https://github.com/FluidSynth/fluidsynth/blob/${finalAttrs.src.tag}/doc/wiki/ChangeLog.md"; description = "Real-time software synthesizer based on the SoundFont 2 specifications"; homepage = "https://www.fluidsynth.org"; license = lib.licenses.lgpl21Plus; From 0b99f61e568d0f6712ebb3982610a5dd8b7cc3a1 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sandro=20J=C3=A4ckel?= Date: Thu, 16 Jul 2026 16:06:19 +0200 Subject: [PATCH 037/175] python314Packages.filelock: add another timeout sensitive test file --- pkgs/development/python-modules/filelock/default.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/development/python-modules/filelock/default.nix b/pkgs/development/python-modules/filelock/default.nix index 80810b707766..e30569bb833d 100644 --- a/pkgs/development/python-modules/filelock/default.nix +++ b/pkgs/development/python-modules/filelock/default.nix @@ -41,6 +41,7 @@ buildPythonPackage rec { "tests/test_virtualenv.py" # Very prone to timeouts on busy machines "tests/test_filelock.py" + "tests/test_read_write.py" ]; meta = { From 4c4644e487e28df2400e148cba2858e1f18659f7 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sandro=20J=C3=A4ckel?= Date: Thu, 16 Jul 2026 17:08:14 +0200 Subject: [PATCH 038/175] python314Packages.sh: ignore timing sensitive tests --- pkgs/development/python-modules/sh/default.nix | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/pkgs/development/python-modules/sh/default.nix b/pkgs/development/python-modules/sh/default.nix index 4f473cfb0268..797847b527fb 100644 --- a/pkgs/development/python-modules/sh/default.nix +++ b/pkgs/development/python-modules/sh/default.nix @@ -38,7 +38,9 @@ buildPythonPackage rec { "test_unicode_path" # fails to import itself after modifying the environment "test_environment" - # timing sensitive through usage of sleep(1) and signal handling + # timing sensitive due to strict timeouts + "test_done_callback_no_deadlock" + "test_timeout_overstep" ] ++ lib.optionals stdenv.hostPlatform.isDarwin [ # Disable tests that fail on Darwin sandbox From 0e0204bf39e5ef1f4baffa97d15d338a9ae04df9 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Thu, 16 Jul 2026 16:30:29 -0700 Subject: [PATCH 039/175] python3Packages.faust-cchardet: 2.1.19 -> 2.1.20 Diff: https://github.com/faust-streaming/cChardet/compare/v2.1.19...v2.1.20 Changelog: https://github.com/faust-streaming/cChardet/blob/v2.1.20/CHANGES.rst --- .../python-modules/faust-cchardet/default.nix | 17 +++++++++++------ 1 file changed, 11 insertions(+), 6 deletions(-) diff --git a/pkgs/development/python-modules/faust-cchardet/default.nix b/pkgs/development/python-modules/faust-cchardet/default.nix index 6691f8e74791..29ce8f863728 100644 --- a/pkgs/development/python-modules/faust-cchardet/default.nix +++ b/pkgs/development/python-modules/faust-cchardet/default.nix @@ -3,16 +3,16 @@ buildPythonPackage, fetchFromGitHub, cython, + packaging, pkgconfig, setuptools, - wheel, pytestCheckHook, python, }: buildPythonPackage rec { pname = "faust-cchardet"; - version = "2.1.19"; + version = "2.1.20"; pyproject = true; src = fetchFromGitHub { @@ -20,14 +20,19 @@ buildPythonPackage rec { repo = "cChardet"; tag = "v${version}"; fetchSubmodules = true; - hash = "sha256-yY6YEhXC4S47rxnkKAta4m16IVGn7gkHSt056bYOYJ4="; + hash = "sha256-MeRX/g38c+q2jiTtEhUpaGYf+5tkhexRGuIG0PdUGvI="; }; - nativeBuildInputs = [ + postPatch = '' + substituteInPlace pyproject.toml \ + --replace-fail "packaging<26" packaging + ''; + + build-system = [ cython + packaging pkgconfig setuptools - wheel ]; postFixup = '' @@ -41,7 +46,7 @@ buildPythonPackage rec { nativeCheckInputs = [ pytestCheckHook ]; meta = { - changelog = "https://github.com/faust-streaming/cChardet/blob/${src.rev}/CHANGES.rst"; + changelog = "https://github.com/faust-streaming/cChardet/blob/${src.tag}/CHANGES.rst"; description = "High-speed universal character encoding detector"; mainProgram = "cchardetect"; homepage = "https://github.com/faust-streaming/cChardet"; From 64b0e245396b1617a2a859945d3ca9085785a74e Mon Sep 17 00:00:00 2001 From: whispers Date: Thu, 16 Jul 2026 20:30:14 -0400 Subject: [PATCH 040/175] apache-orc: 2.3.0 -> 2.3.1 changelog: https://orc.apache.org/news/2026/07/16/ORC-2.3.1/ --- pkgs/by-name/ap/apache-orc/package.nix | 11 +++-------- .../ap/apache-orc/protobuf34-nodiscard.patch | 15 --------------- 2 files changed, 3 insertions(+), 23 deletions(-) delete mode 100644 pkgs/by-name/ap/apache-orc/protobuf34-nodiscard.patch diff --git a/pkgs/by-name/ap/apache-orc/package.nix b/pkgs/by-name/ap/apache-orc/package.nix index 42d546715507..215823a668ac 100644 --- a/pkgs/by-name/ap/apache-orc/package.nix +++ b/pkgs/by-name/ap/apache-orc/package.nix @@ -27,13 +27,13 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "apache-orc"; - version = "2.3.0"; + version = "2.3.1"; src = fetchFromGitHub { owner = "apache"; repo = "orc"; tag = "v${finalAttrs.version}"; - hash = "sha256-QQdRzwmUF1Qwxg53kJv1Q6yFuHqSrLYwUxKt+6wK9Hs="; + hash = "sha256-5pY81SM7BALjPL0e7Iov2QbMcUDd3lNC/99U9yiDKfQ="; }; patches = [ @@ -43,11 +43,6 @@ stdenv.mkDerivation (finalAttrs: { # /bin/ld: /lib/libabsl_raw_hash-set.so.2601.0.0: # error adding symbols: DSO missing from command line ./cmake-link-abseil.patch - - # Protobuf 34 adds `[[nodiscard]]` to several serialization functions. In - # order to avoid these warnings causing build failures, we add handling for - # this failure case. - ./protobuf34-nodiscard.patch ]; nativeBuildInputs = [ @@ -66,7 +61,7 @@ stdenv.mkDerivation (finalAttrs: { cmakeFlags = [ (lib.cmakeFeature "CMAKE_BUILD_TYPE" "Release") (lib.cmakeBool "BUILD_JAVA" false) - (lib.cmakeBool "STOP_BUILD_ON_WARNING" stdenv.hostPlatform.isLinux) + (lib.cmakeBool "STOP_BUILD_ON_WARNING" false) (lib.cmakeBool "INSTALL_VENDORED_LIBS" false) ] ++ lib.optional (stdenv.hostPlatform != stdenv.buildPlatform) [ diff --git a/pkgs/by-name/ap/apache-orc/protobuf34-nodiscard.patch b/pkgs/by-name/ap/apache-orc/protobuf34-nodiscard.patch deleted file mode 100644 index 643b7da2aeca..000000000000 --- a/pkgs/by-name/ap/apache-orc/protobuf34-nodiscard.patch +++ /dev/null @@ -1,15 +0,0 @@ -diff --git a/c++/src/ColumnWriter.cc b/c++/src/ColumnWriter.cc -index 9cdbae0709..d049e91bb1 100644 ---- a/c++/src/ColumnWriter.cc -+++ b/c++/src/ColumnWriter.cc -@@ -212,7 +212,9 @@ - } - } - // write row index to output stream -- rowIndex->SerializeToZeroCopyStream(indexStream.get()); -+ if (!rowIndex->SerializeToZeroCopyStream(indexStream.get())) { -+ throw std::logic_error("Failed to write index stream."); -+ } - - // construct row index stream - proto::Stream stream; From 36077ec8f885d97b4c106c6aa41522884184788b Mon Sep 17 00:00:00 2001 From: Tom Hunze Date: Fri, 17 Jul 2026 12:05:50 +0200 Subject: [PATCH 041/175] python3Packages.rf-protocols: remove dependency on prek prek is a Git hook manager, similar to pre-commit. It's not needed for running the tests. Having prek as a dependency of rf-protocol causes prek to have >1000 reverse dependencies via home-assistant, which is undesirable as this requires each prek update to go through a staging cycle, see e.g. [1]. `$out` stays the same after this change, minus store path differences. [1] https://github.com/NixOS/nixpkgs/pull/539683 --- pkgs/development/python-modules/rf-protocols/default.nix | 2 -- 1 file changed, 2 deletions(-) diff --git a/pkgs/development/python-modules/rf-protocols/default.nix b/pkgs/development/python-modules/rf-protocols/default.nix index 49fc6ce5e5d6..6830639ae52b 100644 --- a/pkgs/development/python-modules/rf-protocols/default.nix +++ b/pkgs/development/python-modules/rf-protocols/default.nix @@ -2,7 +2,6 @@ lib, buildPythonPackage, fetchFromGitHub, - prek, pyprojectVersionPatchHook, pytest-asyncio, pytestCheckHook, @@ -33,7 +32,6 @@ buildPythonPackage (finalAttrs: { ]; nativeCheckInputs = [ - prek pytest-asyncio pytestCheckHook ]; From 007ea29d17cdd15d65c3641489c4992153e3eabc Mon Sep 17 00:00:00 2001 From: K900 Date: Fri, 17 Jul 2026 15:19:15 +0300 Subject: [PATCH 042/175] mbedtls: 3.6.6 -> 3.6.7 --- pkgs/by-name/mb/mbedtls/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/mb/mbedtls/package.nix b/pkgs/by-name/mb/mbedtls/package.nix index 3bf8e310d0ba..bbf792d60a32 100644 --- a/pkgs/by-name/mb/mbedtls/package.nix +++ b/pkgs/by-name/mb/mbedtls/package.nix @@ -6,8 +6,8 @@ }: callPackage ./generic.nix { - version = "3.6.6"; - hash = "sha256-+PW41/c8M/Yz0EVWM4Gt4HTNBMUTU5MayaKVZ+upLIo="; + version = "3.6.7"; + hash = "sha256-t1ZPeFA3ftKaEIaXQ7RXZEsiOAYK4KSSm55SFr9g17A="; patches = [ # Fixes the build with GCC 14 on aarch64. From 67204887a8063f488e9077aa4c9da7946d9de780 Mon Sep 17 00:00:00 2001 From: K900 Date: Fri, 17 Jul 2026 15:19:20 +0300 Subject: [PATCH 043/175] mbedtls_4: 4.1.0 -> 4.2.0 --- pkgs/by-name/mb/mbedtls/4.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/mb/mbedtls/4.nix b/pkgs/by-name/mb/mbedtls/4.nix index bc20e80be986..82e5db2fd732 100644 --- a/pkgs/by-name/mb/mbedtls/4.nix +++ b/pkgs/by-name/mb/mbedtls/4.nix @@ -5,8 +5,8 @@ }: callPackage ./generic.nix { - version = "4.1.0"; - hash = "sha256-TA1uka13So8URttw+JJVdKIL+IonkhIQSc0IfraXpIM="; + version = "4.2.0"; + hash = "sha256-Xz5W5zYPNlASPyc1/Sz2O1LONdxpUkg1hgzKdax/3ag="; patches = [ # Fixes the build with GCC 14 on aarch64. From 781c3e5b32880fe0c40fc3c8772ce4c32dd8e81f Mon Sep 17 00:00:00 2001 From: FliegendeWurst Date: Fri, 17 Jul 2026 15:04:03 +0200 Subject: [PATCH 044/175] systemtap-unwrapped: enable __structuredAttrs, strictDeps --- pkgs/by-name/sy/systemtap-unwrapped/package.nix | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/sy/systemtap-unwrapped/package.nix b/pkgs/by-name/sy/systemtap-unwrapped/package.nix index afad124fb852..5abcf9b6d235 100644 --- a/pkgs/by-name/sy/systemtap-unwrapped/package.nix +++ b/pkgs/by-name/sy/systemtap-unwrapped/package.nix @@ -8,12 +8,16 @@ cpio, elfutils, python3, + bashNonInteractive, }: stdenv.mkDerivation (finalAttrs: { pname = "systemtap"; version = "5.4"; + __structuredAttrs = true; + strictDeps = true; + src = fetchgit { url = "git://sourceware.org/git/systemtap.git"; rev = "release-${finalAttrs.version}"; @@ -30,14 +34,15 @@ stdenv.mkDerivation (finalAttrs: { nativeBuildInputs = [ pkg-config cpio + gettext python3 python3.pkgs.setuptools ]; buildInputs = [ boost elfutils - gettext python3 + bashNonInteractive ]; enableParallelBuilding = true; From b8849050c9063d723bde55e220c2834871f1063e Mon Sep 17 00:00:00 2001 From: K900 Date: Fri, 17 Jul 2026 20:31:33 +0300 Subject: [PATCH 045/175] hdrhistogram_c: unconditionalize patch --- pkgs/by-name/hd/hdrhistogram_c/package.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/by-name/hd/hdrhistogram_c/package.nix b/pkgs/by-name/hd/hdrhistogram_c/package.nix index d8f02e4b540e..3ebcbe73e089 100644 --- a/pkgs/by-name/hd/hdrhistogram_c/package.nix +++ b/pkgs/by-name/hd/hdrhistogram_c/package.nix @@ -22,7 +22,7 @@ stdenv.mkDerivation (finalAttrs: { # Fix build on i686 by not trying to build AVX2 code # Submitted upstream: https://github.com/HdrHistogram/HdrHistogram_c/pull/143 - ${if stdenv.hostPlatform.isi686 then "patches" else null} = [ + patches = [ ./no-avx2-i386.patch ]; From 9652e1332dde25759901369a315c665da85fb214 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Sat, 18 Jul 2026 11:17:44 +0200 Subject: [PATCH 046/175] cacert: 3.125 -> 3.126 https://github.com/mozilla/nss/blob/master/doc/rst/releases/nss_3_126.rst --- pkgs/by-name/ca/cacert/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ca/cacert/package.nix b/pkgs/by-name/ca/cacert/package.nix index df6b082a92bc..c4052964cd91 100644 --- a/pkgs/by-name/ca/cacert/package.nix +++ b/pkgs/by-name/ca/cacert/package.nix @@ -20,7 +20,7 @@ let lib.concatStringsSep "\n\n" extraCertificateStrings ); - version = "3.125"; + version = "3.126"; meta = { homepage = "https://firefox-source-docs.mozilla.org/security/nss/runbooks/rootstore.html#root-store-consumers"; description = "Bundle of X.509 certificates of public Certificate Authorities (CA)"; @@ -52,7 +52,7 @@ stdenv.mkDerivation { "https://hg-edge.mozilla.org/projects/nss/raw-file/${tag}/${file}" "https://raw.githubusercontent.com/nss-dev/nss/refs/tags/${tag}/${file}" ]; - hash = "sha256-5XkSgI2u97Kw+k3yzPF+R66vJsg5o4+Fx2AD66/YZr0="; + hash = "sha256-gbfyV2MzouNg5nP5Etewt6dl2DbHMQA+NIpGysXTcZg="; }; unpackPhase = '' From d3ea2a3180dab2b836565a2136cf3c0788ca80ef Mon Sep 17 00:00:00 2001 From: Doron Behar Date: Sat, 18 Jul 2026 21:49:07 +0300 Subject: [PATCH 047/175] python3Packages.matplotlib: 3.11.0 -> 3.11.1 Changelog: https://github.com/matplotlib/matplotlib/releases/tag/v3.11.1 --- pkgs/development/python-modules/matplotlib/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/matplotlib/default.nix b/pkgs/development/python-modules/matplotlib/default.nix index ab1d363fc6ab..eb6e218d354c 100644 --- a/pkgs/development/python-modules/matplotlib/default.nix +++ b/pkgs/development/python-modules/matplotlib/default.nix @@ -69,13 +69,13 @@ let in buildPythonPackage (finalAttrs: { - version = "3.11.0"; + version = "3.11.1"; pname = "matplotlib"; pyproject = true; src = fetchPypi { inherit (finalAttrs) pname version; - hash = "sha256-aMDHvgGzDcyjY4k09/WR33NAEjXL2/DRqxxx59t/i1c="; + hash = "sha256-aWR9tXRpQceT1uRFpM00kyP/uH2cyVjCrYSmWbSDLTA="; }; env.XDG_RUNTIME_DIR = "/tmp"; From be8bc646d4426b513e034388760ab826ac81aef7 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Sat, 18 Jul 2026 17:11:35 -0700 Subject: [PATCH 048/175] python3Packages.multipart: 1.3.1 -> 2.0.0 Diff: https://github.com/defnull/multipart/compare/v1.3.1...v2.0.0 Changelog: https://github.com/defnull/multipart/blob/v2.0.0/CHANGELOG.rst --- pkgs/development/python-modules/multipart/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/multipart/default.nix b/pkgs/development/python-modules/multipart/default.nix index 1d02c7d6a0c3..6d94dca60bcc 100644 --- a/pkgs/development/python-modules/multipart/default.nix +++ b/pkgs/development/python-modules/multipart/default.nix @@ -8,14 +8,14 @@ buildPythonPackage rec { pname = "multipart"; - version = "1.3.1"; + version = "2.0.0"; pyproject = true; src = fetchFromGitHub { owner = "defnull"; repo = "multipart"; tag = "v${version}"; - hash = "sha256-kLiOK6ovW3ki1CONXVQZCJw/U3K1AoR6rrmJUstwZOw="; + hash = "sha256-1/G8qUnY7i5OvxkTSebC2pae9lzzfvnozJSVVylqB7w="; }; build-system = [ flit-core ]; From 80d7920bddf598391f6321de783d8c1dcac9df3b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Sat, 18 Jul 2026 17:17:26 -0700 Subject: [PATCH 049/175] python3Packages.multipart: use finalAttrs --- pkgs/development/python-modules/multipart/default.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/development/python-modules/multipart/default.nix b/pkgs/development/python-modules/multipart/default.nix index 6d94dca60bcc..439de00b98cc 100644 --- a/pkgs/development/python-modules/multipart/default.nix +++ b/pkgs/development/python-modules/multipart/default.nix @@ -6,7 +6,7 @@ pytestCheckHook, }: -buildPythonPackage rec { +buildPythonPackage (finalAttrs: { pname = "multipart"; version = "2.0.0"; pyproject = true; @@ -14,7 +14,7 @@ buildPythonPackage rec { src = fetchFromGitHub { owner = "defnull"; repo = "multipart"; - tag = "v${version}"; + tag = "v${finalAttrs.version}"; hash = "sha256-1/G8qUnY7i5OvxkTSebC2pae9lzzfvnozJSVVylqB7w="; }; @@ -25,10 +25,10 @@ buildPythonPackage rec { pythonImportsCheck = [ "multipart" ]; meta = { - changelog = "https://github.com/defnull/multipart/blob/${src.tag}/CHANGELOG.rst"; + changelog = "https://github.com/defnull/multipart/blob/${finalAttrs.src.tag}/CHANGELOG.rst"; description = "Parser for multipart/form-data"; homepage = "https://github.com/defnull/multipart"; license = lib.licenses.mit; maintainers = with lib.maintainers; [ dotlambda ]; }; -} +}) From eaaeed2a57e7161933d7f059e9c11c9c770d2095 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 19 Jul 2026 23:08:13 +0000 Subject: [PATCH 050/175] prek: 0.4.4 -> 0.4.10 --- pkgs/by-name/pr/prek/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/pr/prek/package.nix b/pkgs/by-name/pr/prek/package.nix index 886b6b5b971a..7b71f7d03b61 100644 --- a/pkgs/by-name/pr/prek/package.nix +++ b/pkgs/by-name/pr/prek/package.nix @@ -13,16 +13,16 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "prek"; - version = "0.4.4"; + version = "0.4.10"; src = fetchFromGitHub { owner = "j178"; repo = "prek"; tag = "v${finalAttrs.version}"; - hash = "sha256-PAEmRQ5Vro83fkegOWsdY59U7WAQxBPSEalzxZV6K4o="; + hash = "sha256-tTr/Aob6jP1YL+n5vGkUkByew73WdP3mqLW5Lci1gNM="; }; - cargoHash = "sha256-EmlR6Lmt5XR0uS/y3FqY5yGNeVBSdtLtEGH9jZLcP2o="; + cargoHash = "sha256-He55uH7t7NI5sYgowujqCMK5yjhC2F+8ZLxKG6TLjYY="; nativeBuildInputs = [ installShellFiles From ac882579e91f7a5cf2476a817c7f45b0d66fe697 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 20 Jul 2026 13:11:18 +0000 Subject: [PATCH 051/175] dash: 0.5.13.4 -> 0.5.13.5 --- pkgs/by-name/da/dash/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/da/dash/package.nix b/pkgs/by-name/da/dash/package.nix index ada4d8812cb9..3e4a5241711a 100644 --- a/pkgs/by-name/da/dash/package.nix +++ b/pkgs/by-name/da/dash/package.nix @@ -15,11 +15,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "dash"; - version = "0.5.13.4"; + version = "0.5.13.5"; src = fetchurl { url = "http://gondor.apana.org.au/~herbert/dash/files/dash-${finalAttrs.version}.tar.gz"; - hash = "sha256-0Q39Qc2lkWVWDbOcqRXCxKdjb/8EKB2NLfd62Sx1Pis="; + hash = "sha256-QAkBAaKkkfE+kB09SOkEFPJmNGKLm//zX/VANjwien0="; }; strictDeps = true; From 7bb08865d00b8d6baed82ac149561f10fb43552b Mon Sep 17 00:00:00 2001 From: FliegendeWurst Date: Mon, 20 Jul 2026 17:42:37 +0200 Subject: [PATCH 052/175] thrift: set meta.downloadPage --- pkgs/by-name/th/thrift/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/th/thrift/package.nix b/pkgs/by-name/th/thrift/package.nix index 319c2413d96a..a15e63e7a8c5 100644 --- a/pkgs/by-name/th/thrift/package.nix +++ b/pkgs/by-name/th/thrift/package.nix @@ -111,6 +111,7 @@ stdenv.mkDerivation (finalAttrs: { description = "Library for scalable cross-language services"; mainProgram = "thrift"; homepage = "https://thrift.apache.org/"; + downloadPage = "https://github.com/apache/thrift"; license = lib.licenses.asl20; platforms = lib.platforms.linux ++ lib.platforms.darwin; maintainers = with lib.maintainers; [ bjornfor ]; From 5cf2644c4f842a634750bf2c2b49c74ab2e8f5f6 Mon Sep 17 00:00:00 2001 From: FliegendeWurst Date: Mon, 20 Jul 2026 17:42:37 +0200 Subject: [PATCH 053/175] thrift: fix cross build --- pkgs/by-name/th/thrift/package.nix | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/th/thrift/package.nix b/pkgs/by-name/th/thrift/package.nix index a15e63e7a8c5..f8b400534acd 100644 --- a/pkgs/by-name/th/thrift/package.nix +++ b/pkgs/by-name/th/thrift/package.nix @@ -12,6 +12,7 @@ bison, flex, ctestCheckHook, + buildPackages, static ? stdenv.hostPlatform.isStatic, }: @@ -26,6 +27,12 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-gGAO+D0A/hEoHMm6OvRBc1Mks9y52kfd0q/Sg96pdW4="; }; + postPatch = lib.optionalString (!finalAttrs.finalPackage.doCheck) '' + # Compiling the tests doesn't work for cross builds. + substituteInPlace lib/py/CMakeLists.txt \ + --replace-fail 'COMMAND ''${THRIFT_COMPILER} --gen py test/test_thrift_file/TestServer.thrift' "" + ''; + # Workaround to make the Python wrapper not drop this package: # pythonFull.buildEnv.override { extraLibs = [ thrift ]; } pythonPath = [ ]; @@ -35,7 +42,7 @@ stdenv.mkDerivation (finalAttrs: { cmake flex pkg-config - (python3.withPackages ( + (buildPackages.python3.withPackages ( ps: with ps; [ @@ -74,7 +81,9 @@ stdenv.mkDerivation (finalAttrs: { # FIXME: Fails to link in static mode with undefined reference to # `boost::unit_test::unit_test_main(bool (*)(), int, char**)' - (lib.cmakeBool "BUILD_TESTING" (!static)) + (lib.cmakeBool "BUILD_TESTING" finalAttrs.finalPackage.doCheck) + # Building tutorials requires running thrift. + (lib.cmakeBool "BUILD_TUTORIALS" (stdenv.buildPlatform.canExecute stdenv.hostPlatform)) ]; disabledTests = [ From 7d3875618f9a72d16f920a2aa5b0ff30f99e24aa Mon Sep 17 00:00:00 2001 From: whispers Date: Mon, 20 Jul 2026 10:50:54 -0400 Subject: [PATCH 054/175] minimal-boostrap.mes: use vendored ldexpl.c this was initially introduced in #494801 but accidentally reverted in #519568. --- pkgs/os-specific/linux/minimal-bootstrap/mes/libc.nix | 11 ++++------- 1 file changed, 4 insertions(+), 7 deletions(-) diff --git a/pkgs/os-specific/linux/minimal-bootstrap/mes/libc.nix b/pkgs/os-specific/linux/minimal-bootstrap/mes/libc.nix index edf1a2f15640..b2165a74a30e 100644 --- a/pkgs/os-specific/linux/minimal-bootstrap/mes/libc.nix +++ b/pkgs/os-specific/linux/minimal-bootstrap/mes/libc.nix @@ -8,7 +8,6 @@ in ln-boot, mes, buildPlatform, - fetchurl, }: let pname = "mes-libc"; @@ -24,18 +23,16 @@ let sources = sourcesJson."${arch}.linux.gcc"; inherit (sources) libtcc1_SOURCES libc_gnu1_SOURCES libc_gnu2_SOURCES; - ldexpl = fetchurl { - url = "https://gitlab.com/janneke/mes/-/raw/c837abed8edb341d4e56913729fbe9803b4de47c/lib/math/ldexpl.c"; - hash = "sha256-3QoFZZIqVmlMUosEqOdYIMEHzYgQ7GJ7Hz0Bf/1iIig="; - }; - # Concatenate all source files into a convenient bundle # "gcc" variants of source files (eg. "lib/linux/x86-mes-gcc") can also be # compiled by tinycc # # Passing this many arguments is too much for kaem so we need to split # the operation in two - firstLibc = libc_gnu1_SOURCES + " ${ldexpl}"; + # + # We also vendor a copy of ldexpl. We do not `fetchurl` it as the mes GitLab + # often has force pushes and links are thus unstable. + firstLibc = libc_gnu1_SOURCES + " " + ./ldexpl.c; lastLibc = libc_gnu2_SOURCES; in kaem.runCommand "${pname}-${version}" From 572bf8abb5d7a93705ecdf2834f0bd7d675c7e95 Mon Sep 17 00:00:00 2001 From: whispers Date: Mon, 20 Jul 2026 14:35:26 -0400 Subject: [PATCH 055/175] libssh2: patch CVE-2026-58050 and CVE-2026-58051 patch source: https://github.com/libssh2/libssh2/issues/1925#issuecomment-4938515829 Fixes: CVE-2026-58050, CVE-2026-58051 --- pkgs/by-name/li/libssh2/package.nix | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/pkgs/by-name/li/libssh2/package.nix b/pkgs/by-name/li/libssh2/package.nix index 7a48067d111d..cbe3942ae80e 100644 --- a/pkgs/by-name/li/libssh2/package.nix +++ b/pkgs/by-name/li/libssh2/package.nix @@ -51,6 +51,18 @@ stdenv.mkDerivation (finalAttrs: { url = "https://salsa.debian.org/debian/libssh2/-/raw/1d4906e6ebe85a9da2931ba33677ead96a61f07f/debian/patches/libssh-unconst-backport.patch"; hash = "sha256-jc01Fb70GbaD9+RYeSjRaLFBtKLiMPTMuXas21aC0Ag="; }) + + # https://github.com/libssh2/libssh2/issues/1925#issuecomment-4938515829 + (fetchurl { + name = "CVE-2026-58050.patch"; + url = "https://raw.githubusercontent.com/JuliaPackaging/Yggdrasil/9404aa5dd96c945a790c425a5f49af19ed2a93b0/L/LibSSH2/LibSSH2%401.11/bundled/patches/CVE-2026-58050-3449752.patch"; + hash = "sha256-BZ1ewZgrroev2gkJwdoHCMFJK4wiRmA/Y4tzwaQqBd8="; + }) + (fetchurl { + name = "CVE-2026-58051.patch"; + url = "https://github.com/JuliaPackaging/Yggdrasil/raw/9404aa5dd96c945a790c425a5f49af19ed2a93b0/L/LibSSH2/LibSSH2%401.11/bundled/patches/CVE-2026-58051-a9758da.patch"; + hash = "sha256-fduXIH02uwzqWV2RDidZmaDBy51V8yuC4XKlGYacjxg="; + }) ]; # this could be accomplished by updateAutotoolsGnuConfigScriptsHook, but that causes infinite recursion From b2aab90a9cfcb16849ed41b5a5f8a2f8e220d194 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 20 Jul 2026 19:26:36 +0000 Subject: [PATCH 056/175] srt: 1.5.5 -> 1.5.6 --- pkgs/by-name/sr/srt/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/sr/srt/package.nix b/pkgs/by-name/sr/srt/package.nix index d02efdc3d4e6..6dc2f322e407 100644 --- a/pkgs/by-name/sr/srt/package.nix +++ b/pkgs/by-name/sr/srt/package.nix @@ -9,13 +9,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "srt"; - version = "1.5.5"; + version = "1.5.6"; src = fetchFromGitHub { owner = "Haivision"; repo = "srt"; rev = "v${finalAttrs.version}"; - sha256 = "sha256-hOkLlmtF9dKqXZTjAeBntkkg5WsmsZN6DKhyakoIF1k="; + sha256 = "sha256-fdgj6URuMaem+ZVy7D8Hnf2Ev1HindevdvX0xyxCL4M="; }; nativeBuildInputs = [ cmake ]; From fb6f0040bafdb77272a8b0ab329664c3c0abc5e3 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Mon, 20 Jul 2026 13:00:15 -0700 Subject: [PATCH 057/175] python3Packages.aiohttp: 3.14.1 -> 3.14.2 Diff: https://github.com/aio-libs/aiohttp/compare/v3.14.1...v3.14.2 Changelog: https://docs.aiohttp.org/en/v3.14.2/changes.html --- pkgs/development/python-modules/aiohttp/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/aiohttp/default.nix b/pkgs/development/python-modules/aiohttp/default.nix index 4ba9d761e447..d06eff93da90 100644 --- a/pkgs/development/python-modules/aiohttp/default.nix +++ b/pkgs/development/python-modules/aiohttp/default.nix @@ -48,14 +48,14 @@ buildPythonPackage (finalAttrs: { pname = "aiohttp"; - version = "3.14.1"; + version = "3.14.2"; pyproject = true; src = fetchFromGitHub { owner = "aio-libs"; repo = "aiohttp"; tag = "v${finalAttrs.version}"; - hash = "sha256-OJSLv/NfVrKESZqNr51FJUzLRz7wLMRdGoNjKC5EhlI="; + hash = "sha256-gpAYbANSlUZoB0lATEP2N288GxlF8/GzD7bEW1AkHZw="; }; postPatch = '' From ca13224dfbe825588a167658fecab2524be513d8 Mon Sep 17 00:00:00 2001 From: Sergei Trofimovich Date: Mon, 20 Jul 2026 22:46:14 +0100 Subject: [PATCH 058/175] netpbm: 11.15.1 -> 11.15.3 --- pkgs/by-name/ne/netpbm/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ne/netpbm/package.nix b/pkgs/by-name/ne/netpbm/package.nix index 4d338fb84d4c..99e5e3b373ed 100644 --- a/pkgs/by-name/ne/netpbm/package.nix +++ b/pkgs/by-name/ne/netpbm/package.nix @@ -21,7 +21,7 @@ stdenv.mkDerivation (finalAttrs: { # Determine version and revision from: # https://sourceforge.net/p/netpbm/code/HEAD/log/?path=/advanced pname = "netpbm"; - version = "11.15.1"; + version = "11.15.3"; outputs = [ "bin" @@ -31,8 +31,8 @@ stdenv.mkDerivation (finalAttrs: { src = fetchsvn { url = "https://svn.code.sf.net/p/netpbm/code/advanced"; - rev = "5227"; - sha256 = "sha256-Lr02cu7OAPv+wjKjPkA0wyZ0VvurUuCf5IJXjmCAE0I="; + rev = "5264"; + sha256 = "sha256-5G2OitW25ZNsdBcVkKfLpFJWjTm9VcB3ca0QllOSugI="; }; nativeBuildInputs = [ From f5248277bd62385ec41d139c3fa67ba2e51c5628 Mon Sep 17 00:00:00 2001 From: whispers Date: Thu, 11 Jun 2026 21:46:21 -0400 Subject: [PATCH 059/175] jemalloc: add patch to fix build under gcc 16 jemalloc used the nonstandard `std::__throw_bad_alloc`, which is no longer visible in GCC 16. this upstream patch makes it conditional on exceptions and defers to either `throw std::bad_alloc()` or `std::terminate` as appropriate, and fixes the build. --- pkgs/by-name/je/jemalloc/package.nix | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/pkgs/by-name/je/jemalloc/package.nix b/pkgs/by-name/je/jemalloc/package.nix index 3529c01c83cf..6aa346468eed 100644 --- a/pkgs/by-name/je/jemalloc/package.nix +++ b/pkgs/by-name/je/jemalloc/package.nix @@ -2,6 +2,7 @@ lib, stdenv, fetchFromGitHub, + fetchpatch, autoreconfHook, # By default, jemalloc puts a je_ prefix onto all its symbols on OSX, which # then stops downstream builds (mariadb in particular) from detecting it. This @@ -59,6 +60,16 @@ stdenv.mkDerivation (finalAttrs: { # A (longer) patch addressing the failure posted upstream at: # https://github.com/jemalloc/jemalloc/pull/2954 ./skip-extent-test-with-prof-active.patch + + # the nonstandard `std::__throw_bad_alloc` is no longer exposed in gcc 16. + # this makes it conditional on exceptions and defers to either + # `throw std::bad_alloc()` or `std::terminate` as appropriate. + # https://github.com/jemalloc/jemalloc/pull/2900 + (fetchpatch { + name = "jemalloc-dont-use-nonstandard-throw-bad-alloc.patch"; + url = "https://github.com/jemalloc/jemalloc/commit/1a15fe33a48c52bfe26ea83e49f0d317a47da3ea.patch"; + hash = "sha256-pL9fo8UMSbFlHCo3LFFkw0qBsdrVHcEJIkLutZYa2Yg="; + }) ]; nativeBuildInputs = [ From 2709d6b4f480169cc6a5dc91f79dbc3430e13e3d Mon Sep 17 00:00:00 2001 From: Sigmanificient Date: Tue, 21 Jul 2026 01:29:16 +0200 Subject: [PATCH 060/175] python3Packages.feedgen: migrate to pyproject --- pkgs/development/python-modules/feedgen/default.nix | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/feedgen/default.nix b/pkgs/development/python-modules/feedgen/default.nix index d1562d73e2e4..ff53a955c9dd 100644 --- a/pkgs/development/python-modules/feedgen/default.nix +++ b/pkgs/development/python-modules/feedgen/default.nix @@ -2,6 +2,7 @@ lib, buildPythonPackage, fetchPypi, + setuptools, python-dateutil, lxml, }: @@ -9,14 +10,16 @@ buildPythonPackage rec { pname = "feedgen"; version = "1.0.0"; - format = "setuptools"; + pyproject = true; src = fetchPypi { inherit pname version; hash = "sha256-2b1Rw7XpVqKlKZjDcIxNLHKfL8wxEYjh5dO5cmOTVGo="; }; - propagatedBuildInputs = [ + build-system = [ setuptools ]; + + dependencies = [ python-dateutil lxml ]; From f6c466042e0c3989b48b1388690996c2c9be15da Mon Sep 17 00:00:00 2001 From: Sigmanificient Date: Tue, 21 Jul 2026 01:32:09 +0200 Subject: [PATCH 061/175] python3Packages.feedgen: use finalAttrs --- pkgs/development/python-modules/feedgen/default.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/development/python-modules/feedgen/default.nix b/pkgs/development/python-modules/feedgen/default.nix index ff53a955c9dd..d490ae84722b 100644 --- a/pkgs/development/python-modules/feedgen/default.nix +++ b/pkgs/development/python-modules/feedgen/default.nix @@ -7,13 +7,13 @@ lxml, }: -buildPythonPackage rec { +buildPythonPackage (finalAttrs: { pname = "feedgen"; version = "1.0.0"; pyproject = true; src = fetchPypi { - inherit pname version; + inherit (finalAttrs) pname version; hash = "sha256-2b1Rw7XpVqKlKZjDcIxNLHKfL8wxEYjh5dO5cmOTVGo="; }; @@ -37,4 +37,4 @@ buildPythonPackage rec { ]; maintainers = with lib.maintainers; [ casey ]; }; -} +}) From 8741663b371389fdc1423bd6c0eefc36a673b149 Mon Sep 17 00:00:00 2001 From: Sigmanificient Date: Tue, 21 Jul 2026 01:32:46 +0200 Subject: [PATCH 062/175] python3Packages.feedgen: enable tests --- pkgs/development/python-modules/feedgen/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/feedgen/default.nix b/pkgs/development/python-modules/feedgen/default.nix index d490ae84722b..6f8e4440ab0f 100644 --- a/pkgs/development/python-modules/feedgen/default.nix +++ b/pkgs/development/python-modules/feedgen/default.nix @@ -5,6 +5,7 @@ setuptools, python-dateutil, lxml, + pytestCheckHook, }: buildPythonPackage (finalAttrs: { @@ -24,8 +25,7 @@ buildPythonPackage (finalAttrs: { lxml ]; - # No tests in archive - doCheck = false; + nativeCheckInputs = [ pytestCheckHook ]; meta = { description = "Python module to generate ATOM feeds, RSS feeds and Podcasts"; From 52325bf86527dda6ca551e1881f9437aaa83574e Mon Sep 17 00:00:00 2001 From: Sigmanificient Date: Tue, 21 Jul 2026 01:37:27 +0200 Subject: [PATCH 063/175] python3Packages.fields: migrate to pyproject --- pkgs/development/python-modules/fields/default.nix | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pkgs/development/python-modules/fields/default.nix b/pkgs/development/python-modules/fields/default.nix index fa15f987657e..065949f88545 100644 --- a/pkgs/development/python-modules/fields/default.nix +++ b/pkgs/development/python-modules/fields/default.nix @@ -2,18 +2,21 @@ buildPythonPackage, lib, fetchPypi, + setuptools, }: buildPythonPackage rec { pname = "fields"; version = "5.0.0"; - format = "setuptools"; + pyproject = true; src = fetchPypi { inherit pname version; hash = "sha256-MdSqA9jUTjXfE8Qx3jUTaZfwR6kkpZfYT3vCCeG+Vyc="; }; + build-system = [ setuptools ]; + pythonImportsCheck = [ "fields" ]; meta = { From 72dfbeef2f500405853cd0fb996777281f01ef54 Mon Sep 17 00:00:00 2001 From: Sigmanificient Date: Tue, 21 Jul 2026 01:37:51 +0200 Subject: [PATCH 064/175] python3Packages.fields: use finalAttrs --- pkgs/development/python-modules/fields/default.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/development/python-modules/fields/default.nix b/pkgs/development/python-modules/fields/default.nix index 065949f88545..432f2b9f0791 100644 --- a/pkgs/development/python-modules/fields/default.nix +++ b/pkgs/development/python-modules/fields/default.nix @@ -5,13 +5,13 @@ setuptools, }: -buildPythonPackage rec { +buildPythonPackage (finalAttrs: { pname = "fields"; version = "5.0.0"; pyproject = true; src = fetchPypi { - inherit pname version; + inherit (finalAttrs) pname version; hash = "sha256-MdSqA9jUTjXfE8Qx3jUTaZfwR6kkpZfYT3vCCeG+Vyc="; }; @@ -25,4 +25,4 @@ buildPythonPackage rec { license = lib.licenses.bsd2; maintainers = [ lib.maintainers.sheepforce ]; }; -} +}) From 951e50ec2b3a74ec32032a7625f2d7fb5bc4d229 Mon Sep 17 00:00:00 2001 From: Sigmanificient Date: Tue, 21 Jul 2026 01:41:30 +0200 Subject: [PATCH 065/175] python3Packges.fields: mark tests as disabled --- pkgs/development/python-modules/fields/default.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/development/python-modules/fields/default.nix b/pkgs/development/python-modules/fields/default.nix index 432f2b9f0791..2f6a7c9f1305 100644 --- a/pkgs/development/python-modules/fields/default.nix +++ b/pkgs/development/python-modules/fields/default.nix @@ -19,6 +19,8 @@ buildPythonPackage (finalAttrs: { pythonImportsCheck = [ "fields" ]; + doCheck = false; # Argument(s) {'path'} are declared in the hookimpl but can not be found in the hookspec + meta = { description = "Container class boilerplate killer"; homepage = "https://github.com/ionelmc/python-fields"; From 4e2d29b83e12867c1501fa1d7dff0542ee6fdb60 Mon Sep 17 00:00:00 2001 From: zowoq <59103226+zowoq@users.noreply.github.com> Date: Tue, 21 Jul 2026 12:09:01 +1000 Subject: [PATCH 066/175] Revert "python3Packages.pyobjc-framework-Cocoa: work around `ld64` hardening issue" This reverts commit 13f5d58519e3052a97c71d8d1d63a700eb133cb4. --- .../python-modules/pyobjc-framework-Cocoa/default.nix | 9 --------- 1 file changed, 9 deletions(-) diff --git a/pkgs/development/python-modules/pyobjc-framework-Cocoa/default.nix b/pkgs/development/python-modules/pyobjc-framework-Cocoa/default.nix index 31fec380115c..f6af5aca2f54 100644 --- a/pkgs/development/python-modules/pyobjc-framework-Cocoa/default.nix +++ b/pkgs/development/python-modules/pyobjc-framework-Cocoa/default.nix @@ -5,9 +5,6 @@ lib, pyobjc-core, setuptools, - # TODO: Clean up on `staging`. - stdenv, - llvmPackages, }: buildPythonPackage rec { @@ -28,10 +25,6 @@ buildPythonPackage rec { nativeBuildInputs = [ darwin.DarwinTools # sw_vers - ] - # TODO: Clean up on `staging`. - ++ lib.optionals stdenv.hostPlatform.isDarwin [ - llvmPackages.lld ]; # See https://github.com/ronaldoussoren/pyobjc/pull/641. Unfortunately, we @@ -50,8 +43,6 @@ buildPythonPackage rec { "-I${darwin.libffi.dev}/include" "-Wno-error=unused-command-line-argument" ]; - # TODO: Clean up on `staging`. - env.NIX_CFLAGS_LINK = "-fuse-ld=lld"; pythonImportsCheck = [ "Cocoa" From 5b28e90f97ef01e14859bef4e3d8fa07534ea522 Mon Sep 17 00:00:00 2001 From: zowoq <59103226+zowoq@users.noreply.github.com> Date: Tue, 21 Jul 2026 12:09:23 +1000 Subject: [PATCH 067/175] Revert "pango: fix build on darwin" This reverts commit e00f711fb217048d938c5583a59d100b4c1d6b44. --- pkgs/by-name/pa/pango/package.nix | 19 ++----------------- 1 file changed, 2 insertions(+), 17 deletions(-) diff --git a/pkgs/by-name/pa/pango/package.nix b/pkgs/by-name/pa/pango/package.nix index 90028c86166a..ccb3082f70f6 100644 --- a/pkgs/by-name/pa/pango/package.nix +++ b/pkgs/by-name/pa/pango/package.nix @@ -25,8 +25,6 @@ buildPackages, gobject-introspection, testers, - # TODO: Clean up on `staging`. - llvmPackages, }: stdenv.mkDerivation (finalAttrs: { @@ -60,10 +58,6 @@ stdenv.mkDerivation (finalAttrs: { ++ lib.optionals withIntrospection [ gi-docgen gobject-introspection - ] - # TODO: Clean up on `staging`. - ++ lib.optionals stdenv.hostPlatform.isDarwin [ - llvmPackages.lld ]; buildInputs = [ @@ -89,17 +83,8 @@ stdenv.mkDerivation (finalAttrs: { ]; # Fontconfig error: Cannot load default config file - env = { - FONTCONFIG_FILE = makeFontsConf { - fontDirectories = [ freefont_ttf ]; - }; - } - // lib.optionalAttrs stdenv.hostPlatform.isDarwin { - # workaround for ld64 hardening issue - # - # TODO: Clean up on `staging` - CC_LD = "lld"; - OBJC_LD = "lld"; + env.FONTCONFIG_FILE = makeFontsConf { + fontDirectories = [ freefont_ttf ]; }; # Run-time dependency gi-docgen found: NO (tried pkgconfig and cmake) From 9da838c81aba8fb132f07223d1274be6aaca28aa Mon Sep 17 00:00:00 2001 From: zowoq <59103226+zowoq@users.noreply.github.com> Date: Tue, 21 Jul 2026 12:12:46 +1000 Subject: [PATCH 068/175] Revert "tk: fix build on darwin" This reverts commit 80748a6ce4444826c0fa3deb3c23aab7d88563eb. --- pkgs/development/libraries/tk/generic.nix | 19 +++---------------- 1 file changed, 3 insertions(+), 16 deletions(-) diff --git a/pkgs/development/libraries/tk/generic.nix b/pkgs/development/libraries/tk/generic.nix index 7088a60468cc..65270be3e345 100644 --- a/pkgs/development/libraries/tk/generic.nix +++ b/pkgs/development/libraries/tk/generic.nix @@ -9,8 +9,6 @@ zlib, patches ? [ ], enableAqua ? stdenv.hostPlatform.isDarwin, - # TODO: Clean up on `staging`. - llvmPackages, ... }: @@ -76,10 +74,6 @@ tcl.mkTclDerivation { ++ lib.optionals (lib.versionAtLeast tcl.version "9.0") [ # Only used to detect the presence of zlib. Could be replaced with a stub. zip - ] - # TODO: Clean up on `staging`. - ++ lib.optionals stdenv.hostPlatform.isDarwin [ - llvmPackages.lld ]; buildInputs = lib.optionals (lib.versionAtLeast tcl.version "9.0") [ zlib @@ -95,16 +89,9 @@ tcl.mkTclDerivation { inherit tcl; - env = - lib.optionalAttrs (lib.versionOlder tcl.version "8.6") { - NIX_CFLAGS_COMPILE = "-std=gnu17"; - } - // lib.optionalAttrs stdenv.hostPlatform.isDarwin { - # workaround for ld64 hardening issue - # - # TODO: Clean up on `staging` - NIX_CFLAGS_COMPILE = "-fuse-ld=lld"; - }; + env = lib.optionalAttrs (lib.versionOlder tcl.version "8.6") { + NIX_CFLAGS_COMPILE = "-std=gnu17"; + }; passthru = rec { inherit (tcl) release version; From 2698646a86aa3c5a33f4718baa472559d8d35554 Mon Sep 17 00:00:00 2001 From: zowoq <59103226+zowoq@users.noreply.github.com> Date: Tue, 21 Jul 2026 12:13:03 +1000 Subject: [PATCH 069/175] Revert "gst_all_1.gst-plugins-bad: only set NIX_CLAGS_LINK on darwin" This reverts commit 3aa415b2f4736271edd90b696054a4c179d189c3. --- pkgs/development/libraries/gstreamer/bad/default.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/development/libraries/gstreamer/bad/default.nix b/pkgs/development/libraries/gstreamer/bad/default.nix index 46b703ddfd34..743c769e2047 100644 --- a/pkgs/development/libraries/gstreamer/bad/default.nix +++ b/pkgs/development/libraries/gstreamer/bad/default.nix @@ -415,7 +415,7 @@ stdenv.mkDerivation (finalAttrs: { hardeningDisable = [ "format" ]; # TODO: Clean up on `staging`. - env.NIX_CFLAGS_LINK = lib.optionalString stdenv.hostPlatform.isDarwin "-fuse-ld=lld"; + env.NIX_CFLAGS_LINK = "-fuse-ld=lld"; doCheck = false; # fails 20 out of 58 tests, expensive From 16477632da77c1bb7469dbeb24298c7420d9bb2a Mon Sep 17 00:00:00 2001 From: zowoq <59103226+zowoq@users.noreply.github.com> Date: Tue, 21 Jul 2026 12:13:08 +1000 Subject: [PATCH 070/175] Revert "gst_all_1.gst-plugins-bad: work around `ld64` hardening issue" This reverts commit 9315b841a7c7ee27b2be453a641ee79b76eddf5c. --- pkgs/development/libraries/gstreamer/bad/default.nix | 9 --------- 1 file changed, 9 deletions(-) diff --git a/pkgs/development/libraries/gstreamer/bad/default.nix b/pkgs/development/libraries/gstreamer/bad/default.nix index 743c769e2047..463e73d32190 100644 --- a/pkgs/development/libraries/gstreamer/bad/default.nix +++ b/pkgs/development/libraries/gstreamer/bad/default.nix @@ -112,8 +112,6 @@ guiSupport ? false, gst-plugins-bad, apple-sdk_gstreamer, - # TODO: Clean up on `staging`. - llvmPackages, }: stdenv.mkDerivation (finalAttrs: { @@ -158,10 +156,6 @@ stdenv.mkDerivation (finalAttrs: { ] ++ lib.optionals (gst-plugins-base.waylandEnabled && stdenv.hostPlatform.isLinux) [ wayland-scanner - ] - # TODO: Clean up on `staging`. - ++ lib.optionals stdenv.hostPlatform.isDarwin [ - llvmPackages.lld ]; buildInputs = [ @@ -414,9 +408,6 @@ stdenv.mkDerivation (finalAttrs: { # that trip up clang with format security enabled. hardeningDisable = [ "format" ]; - # TODO: Clean up on `staging`. - env.NIX_CFLAGS_LINK = "-fuse-ld=lld"; - doCheck = false; # fails 20 out of 58 tests, expensive preFixup = '' From c11900eff6cde8c37c971bab012a648896a4f28b Mon Sep 17 00:00:00 2001 From: zowoq <59103226+zowoq@users.noreply.github.com> Date: Tue, 21 Jul 2026 12:13:36 +1000 Subject: [PATCH 071/175] Revert "qt5.qtmultimedia: work around `ld64` hardening issue" This reverts commit dd698b325b7eb0a8e68fe84d8c2b37da6848db74. --- .../libraries/qt-5/modules/qtmultimedia.nix | 12 +----------- 1 file changed, 1 insertion(+), 11 deletions(-) diff --git a/pkgs/development/libraries/qt-5/modules/qtmultimedia.nix b/pkgs/development/libraries/qt-5/modules/qtmultimedia.nix index b26a201bb38f..f10ef301ebef 100644 --- a/pkgs/development/libraries/qt-5/modules/qtmultimedia.nix +++ b/pkgs/development/libraries/qt-5/modules/qtmultimedia.nix @@ -9,8 +9,6 @@ gst_all_1, libpulseaudio, wayland, - # TODO: Clean up on `staging`. - llvmPackages, }: qtModule { @@ -19,13 +17,7 @@ qtModule { qtbase qtdeclarative ]; - nativeBuildInputs = [ - pkg-config - ] - # TODO: Clean up on `staging`. - ++ lib.optionals stdenv.hostPlatform.isDarwin [ - llvmPackages.lld - ]; + nativeBuildInputs = [ pkg-config ]; buildInputs = with gst_all_1; [ @@ -46,7 +38,5 @@ qtModule { qmakeFlags = [ "GST_VERSION=1.0" ]; env = lib.optionalAttrs (stdenv.hostPlatform.isDarwin) { NIX_LDFLAGS = "-lobjc"; - # TODO: Clean up on `staging`. - NIX_CFLAGS_LINK = "-fuse-ld=lld"; }; } From 9a9c68153820826b77744fa337b6de099246776e Mon Sep 17 00:00:00 2001 From: zowoq <59103226+zowoq@users.noreply.github.com> Date: Tue, 21 Jul 2026 12:13:52 +1000 Subject: [PATCH 072/175] Revert "qt6.qtmultimedia: work around `ld64` hardening issue" This reverts commit ca8fd57b703868486e559dad418e9160d1fba32f. --- .../libraries/qt-6/modules/qtmultimedia/default.nix | 12 +----------- 1 file changed, 1 insertion(+), 11 deletions(-) diff --git a/pkgs/development/libraries/qt-6/modules/qtmultimedia/default.nix b/pkgs/development/libraries/qt-6/modules/qtmultimedia/default.nix index b8151df0358d..50829d0b0ef7 100644 --- a/pkgs/development/libraries/qt-6/modules/qtmultimedia/default.nix +++ b/pkgs/development/libraries/qt-6/modules/qtmultimedia/default.nix @@ -24,19 +24,11 @@ libunwind, orc, pkgsBuildBuild, - # TODO: Clean up on `staging`. - llvmPackages, }: qtModule { pname = "qtmultimedia"; - nativeBuildInputs = [ - pkg-config - ] - # TODO: Clean up on `staging`. - ++ lib.optionals stdenv.hostPlatform.isDarwin [ - llvmPackages.lld - ]; + nativeBuildInputs = [ pkg-config ]; buildInputs = [ ffmpeg ] @@ -80,8 +72,6 @@ qtModule { env = { NIX_CFLAGS_COMPILE = lib.optionalString stdenv.hostPlatform.isDarwin "-include AudioToolbox/AudioToolbox.h"; - # TODO: Clean up on `staging`. - NIX_CFLAGS_LINK = lib.optionalString stdenv.hostPlatform.isDarwin "-fuse-ld=lld"; NIX_LDFLAGS = lib.optionalString stdenv.hostPlatform.isDarwin "-framework AudioToolbox"; }; } From 88a69da533047536c1166180861acaa391057c9b Mon Sep 17 00:00:00 2001 From: zowoq <59103226+zowoq@users.noreply.github.com> Date: Tue, 21 Jul 2026 12:14:03 +1000 Subject: [PATCH 073/175] Revert "qt6.qtdeclarative: work around `ld64` hardening issue" This reverts commit e8042ddc4329e82b132d8bbf991507ca0d9bbf98. --- .../libraries/qt-6/modules/qtdeclarative/default.nix | 9 --------- 1 file changed, 9 deletions(-) diff --git a/pkgs/development/libraries/qt-6/modules/qtdeclarative/default.nix b/pkgs/development/libraries/qt-6/modules/qtdeclarative/default.nix index dde1935940c8..cfcdb5f6c59a 100644 --- a/pkgs/development/libraries/qt-6/modules/qtdeclarative/default.nix +++ b/pkgs/development/libraries/qt-6/modules/qtdeclarative/default.nix @@ -11,8 +11,6 @@ pkgsBuildBuild, replaceVars, fetchpatch, - # TODO: Clean up on `staging`. - llvmPackages, }: qtModule { @@ -29,8 +27,6 @@ qtModule { nativeBuildInputs = lib.optionals stdenv.hostPlatform.isDarwin [ darwin.sigtool - # TODO: Clean up on `staging`. - llvmPackages.lld ]; patches = [ @@ -73,11 +69,6 @@ qtModule { "-DQt6QmlTools_DIR=${pkgsBuildBuild.qt6.qtdeclarative}/lib/cmake/Qt6QmlTools" ]; - env = lib.optionalAttrs (stdenv.hostPlatform.isDarwin) { - # TODO: Clean up on `staging`. - NIX_CFLAGS_LINK = "-fuse-ld=lld"; - }; - meta.maintainers = with lib.maintainers; [ nickcao outfoxxed From 737bea02912e74362cb257b1254d97b2a9823d53 Mon Sep 17 00:00:00 2001 From: klea Date: Tue, 21 Jul 2026 10:27:45 +0000 Subject: [PATCH 074/175] imagemagick: Generic GCC arch The architectures for `x86_64` and `aarch64` have been deprecated. [This comment](https://github.com/NixOS/nixpkgs/pull/195766#issuecomment-1478981292) suggests doing so, and I've found that `--with-gcc-arch=generic` is already used, whilst `--without-gcc-arch` isn't used. --- pkgs/by-name/im/imagemagick/package.nix | 22 +--------------------- 1 file changed, 1 insertion(+), 21 deletions(-) diff --git a/pkgs/by-name/im/imagemagick/package.nix b/pkgs/by-name/im/imagemagick/package.nix index 918d97c640fa..8a49dde61858 100644 --- a/pkgs/by-name/im/imagemagick/package.nix +++ b/pkgs/by-name/im/imagemagick/package.nix @@ -67,26 +67,6 @@ assert libXtSupport -> libX11Support; assert libraqmSupport -> freetypeSupport; -let - arch = - if stdenv.hostPlatform.system == "i686-linux" then - "i686" - else if - stdenv.hostPlatform.system == "x86_64-linux" || stdenv.hostPlatform.system == "x86_64-darwin" - then - "x86-64" - else if stdenv.hostPlatform.system == "armv7l-linux" then - "armv7l" - else if - stdenv.hostPlatform.system == "aarch64-linux" || stdenv.hostPlatform.system == "aarch64-darwin" - then - "aarch64" - else if stdenv.hostPlatform.system == "powerpc64le-linux" then - "ppc64le" - else - null; -in - stdenv.mkDerivation (finalAttrs: { pname = "imagemagick"; version = "7.1.2-27"; @@ -113,7 +93,7 @@ stdenv.mkDerivation (finalAttrs: { "MVDelegate=${lib.getExe' coreutils "mv"}" "RMDelegate=${lib.getExe' coreutils "rm"}" "--with-frozenpaths" - (lib.withFeatureAs (arch != null) "gcc-arch" arch) + "--with-gcc-arch=generic" (lib.withFeature librsvgSupport "rsvg") (lib.withFeature librsvgSupport "pango") (lib.withFeature liblqr1Support "lqr") From bdd41cf25ff46202d27f60e979c6311c70e47067 Mon Sep 17 00:00:00 2001 From: whispers Date: Tue, 21 Jul 2026 09:00:42 -0400 Subject: [PATCH 075/175] spidermonkey_140: 140.11.0 -> 140.13.0 https://github.com/mozilla-firefox/firefox/commits/FIREFOX_140_13_0esr_RELEASE/js/src/build https://github.com/mozilla-firefox/firefox/commits/FIREFOX_140_13_0esr_RELEASE/build Security advisories: - 140.12.0: https://www.mozilla.org/en-US/security/advisories/mfsa2026-58/ - 140.13.0: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/ Fixes: CVE-2026-12315, CVE-2026-15718, CVE-2026-16355, CVE-2026-16363, CVE-2026-16368, CVE-2026-16369 --- pkgs/development/interpreters/spidermonkey/140.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/interpreters/spidermonkey/140.nix b/pkgs/development/interpreters/spidermonkey/140.nix index 49908ebc35ef..b42f3db4901a 100644 --- a/pkgs/development/interpreters/spidermonkey/140.nix +++ b/pkgs/development/interpreters/spidermonkey/140.nix @@ -1,4 +1,4 @@ import ./common.nix { - version = "140.11.0"; - hash = "sha512-0GrbPvTeEyTj1hhy1w3jGrCKwBPzOQNUm+0oxuvMW03ulLs2OIKCwZNdd9GlZAefOtvwjWu4AoSomcuz2GEwDA=="; + version = "140.13.0"; + hash = "sha512-k3pBA9ccXh5L8FGCFyn26nC1wY1ESTCkh2lcwj10cSoBNARySPasAjBeAb7LcFQmpVudiXOfAqAe2gHs9bwn8Q=="; } From 19c05bc5b549b436bd25fcd136d3af9d0bc964dc Mon Sep 17 00:00:00 2001 From: whispers Date: Tue, 21 Jul 2026 09:39:16 -0400 Subject: [PATCH 076/175] libssh2: remove SuperSandro2000 as maintainer https://github.com/NixOS/nixpkgs/pull/543937#pullrequestreview-4745170669 --- pkgs/by-name/li/libssh2/package.nix | 1 - 1 file changed, 1 deletion(-) diff --git a/pkgs/by-name/li/libssh2/package.nix b/pkgs/by-name/li/libssh2/package.nix index cbe3942ae80e..4237f6d421fa 100644 --- a/pkgs/by-name/li/libssh2/package.nix +++ b/pkgs/by-name/li/libssh2/package.nix @@ -95,6 +95,5 @@ stdenv.mkDerivation (finalAttrs: { homepage = "https://www.libssh2.org"; platforms = lib.platforms.all; license = lib.licenses.bsd3; - maintainers = with lib.maintainers; [ SuperSandro2000 ]; }; }) From b360de16fc47a7d445f13d4b82449085339aa9ff Mon Sep 17 00:00:00 2001 From: Redvers Davies Date: Sat, 11 Jul 2026 19:01:49 +0000 Subject: [PATCH 077/175] ponyc: 0.64.0 -> 0.67.0 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Upstream ponyc has made two significant changes since our last update: 1. Removal of the ability to use an external linker. 2. Moving from make to cmake for build. Previously we had relied on being able to call gcc as an external wrapper, which would take care of all of the /nix/store linking paths, selecting the correct dynamic linker etc etc… Now that the wrapper isn't available anymore, we have modified the embedded linker to read the flags from nix's environment. Assisted-By: Opus 4.8 --- pkgs/by-name/po/ponyc/cmake-presets.patch | 34 ++ .../po/ponyc/disable-networking-tests.patch | 95 ++++-- .../po/ponyc/disable-process-tests.patch | 26 -- pkgs/by-name/po/ponyc/fix-darwin-build.patch | 13 - pkgs/by-name/po/ponyc/gencshim-pony-cc.patch | 61 ++++ .../by-name/po/ponyc/genexe-pony-linker.patch | 174 +++++++++-- pkgs/by-name/po/ponyc/nix-codegen.patch | 291 ++++++++++++++++++ pkgs/by-name/po/ponyc/package.nix | 143 ++++----- 8 files changed, 679 insertions(+), 158 deletions(-) create mode 100644 pkgs/by-name/po/ponyc/cmake-presets.patch delete mode 100644 pkgs/by-name/po/ponyc/disable-process-tests.patch delete mode 100644 pkgs/by-name/po/ponyc/fix-darwin-build.patch create mode 100644 pkgs/by-name/po/ponyc/gencshim-pony-cc.patch create mode 100644 pkgs/by-name/po/ponyc/nix-codegen.patch diff --git a/pkgs/by-name/po/ponyc/cmake-presets.patch b/pkgs/by-name/po/ponyc/cmake-presets.patch new file mode 100644 index 000000000000..f8ee564f7a09 --- /dev/null +++ b/pkgs/by-name/po/ponyc/cmake-presets.patch @@ -0,0 +1,34 @@ +diff --git a/CMakePresets.json b/CMakePresets.json +index d12d71eb5..d337e7339 100644 +--- a/CMakePresets.json ++++ b/CMakePresets.json +@@ -9,11 +9,7 @@ + { + "name": "base", + "hidden": true, +- "binaryDir": "${sourceDir}/build/build_${presetName}", +- "cacheVariables": { +- "CMAKE_C_COMPILER": "clang", +- "CMAKE_CXX_COMPILER": "clang++" +- } ++ "binaryDir": "${sourceDir}/build/build_${presetName}" + }, + { + "name": "native", +diff --git a/lib/CMakePresets.json b/lib/CMakePresets.json +index 12d797b87..92196d931 100644 +--- a/lib/CMakePresets.json ++++ b/lib/CMakePresets.json +@@ -19,11 +19,7 @@ + { + "name": "libs", + "displayName": "Vendored LLVM + support libraries (clang)", +- "inherits": "libs-base", +- "cacheVariables": { +- "CMAKE_C_COMPILER": "clang", +- "CMAKE_CXX_COMPILER": "clang++" +- } ++ "inherits": "libs-base" + }, + { + "name": "libs-windows-x86-64", diff --git a/pkgs/by-name/po/ponyc/disable-networking-tests.patch b/pkgs/by-name/po/ponyc/disable-networking-tests.patch index 2bf7d15a58b4..fccafa80b7ed 100644 --- a/pkgs/by-name/po/ponyc/disable-networking-tests.patch +++ b/pkgs/by-name/po/ponyc/disable-networking-tests.patch @@ -1,41 +1,80 @@ -From c1283b82daff94ebac21fc20cb8df0b05aa080f8 Mon Sep 17 00:00:00 2001 -From: Morgan Jones -Date: Fri, 22 May 2026 23:06:52 -0700 -Subject: [PATCH] net: disable networking tests - ---- - packages/net/_test.pony | 18 ------------------ - 1 file changed, 18 deletions(-) - diff --git a/packages/net/_test.pony b/packages/net/_test.pony -index 1d7b2d6f..69cbeea6 100644 +index 081ce67a0..99942c05e 100644 --- a/packages/net/_test.pony +++ b/packages/net/_test.pony -@@ -20,24 +20,6 @@ actor \nodoc\ Main is TestList +@@ -26,14 +26,14 @@ actor \nodoc\ Main is TestList + + fun tag tests(test: PonyTest) => // Tests below function across all systems and are listed alphabetically +- test(_TestDNSBroadcastIP4) +- test(_TestDNSBroadcastIP6) +- test(_TestDNSUnresolvableEmpty) +- test(_TestMulticastIP4) +- test(_TestMulticastIP6) +- test(_TestNetAddressIP6Scope) +- test(_TestNetAddressNameRoundTripIP4) +- test(_TestNetAddressNameRoundTripIP6) ++// test(_TestDNSBroadcastIP4) ++// test(_TestDNSBroadcastIP6) ++// test(_TestDNSUnresolvableEmpty) ++// test(_TestMulticastIP4) ++// test(_TestMulticastIP6) ++// test(_TestNetAddressIP6Scope) ++// test(_TestNetAddressNameRoundTripIP4) ++// test(_TestNetAddressNameRoundTripIP6) test(_TestOsIpString) + test(_TestSocketResultDecoder) test(_TestTCPConnectionFailed) -- test(_TestTCPExpect) -- test(_TestTCPExpectOverBufferSize) -- test(_TestTCPExpectSetToZero) -- test(_TestTCPMute) -- test(_TestTCPProxy) -- test(_TestTCPUnmute) -- test(_TestTCPWritev) -- -- // Tests below exclude windows and are listed alphabetically -- ifdef not windows then -- test(_TestTCPConnectionToClosedServerFailed) -- test(_TestTCPThrottle) +@@ -48,36 +48,36 @@ actor \nodoc\ Main is TestList + test(_TestTCPThrottle) + test(_TestTCPUnmute) + test(_TestTCPWritev) +- test(_TestUDPEmptyDatagramDelivered) ++// test(_TestUDPEmptyDatagramDelivered) + test(_TestUDPListenFailure) +- test(_TestUDPOversizedDatagramTruncated) +- test(_TestUDPUndersizedDatagramDelivered) +- test(_TestUDPZeroSizeReadBufferDelivers) ++// test(_TestUDPOversizedDatagramTruncated) ++// test(_TestUDPUndersizedDatagramDelivered) ++// test(_TestUDPZeroSizeReadBufferDelivers) + test(_TestUnicastIP6Loopback) + + // The deterministic send-failure trigger (send to broadcast without + // SO_BROADCAST -> EACCES/WSAEACCES) is verified on linux and windows. +- ifdef linux or windows then +- test(_TestUDPCloseOnSendFailure) - end -- -- // Tests below exclude osx and are listed alphabetically ++// ifdef linux or windows then ++// test(_TestUDPCloseOnSendFailure) ++// end + + // Tests below run only on linux and are listed alphabetically +- ifdef linux then +- test(_TestBroadcastReceive) +- end ++// ifdef linux then ++// test(_TestBroadcastReceive) ++// end + + // Tests below exclude osx and are listed alphabetically - ifdef not osx then - test(_TestBroadcast) - end ++// ifdef not osx then ++// test(_TestBroadcast) ++// end + + // Tests below exclude osx and bsd and are listed alphabetically. + // They read IPv4 multicast options back with getsockopt_u32, which + // expects a 4-byte value; osx and bsd return these options as a 1-byte + // u_char, so the read-back fails there regardless of correctness. +- ifdef (not osx) and (not bsd) then +- test(_TestMulticastSockopt) +- end ++// ifdef (not osx) and (not bsd) then ++// test(_TestMulticastSockopt) ++// end class \nodoc\ _TestPing is UDPNotify let _h: TestHelper --- -2.53.0 - diff --git a/pkgs/by-name/po/ponyc/disable-process-tests.patch b/pkgs/by-name/po/ponyc/disable-process-tests.patch deleted file mode 100644 index e4ee0656655b..000000000000 --- a/pkgs/by-name/po/ponyc/disable-process-tests.patch +++ /dev/null @@ -1,26 +0,0 @@ -From 77d703b11d298f6be88b04f7e8ca85de139e82be Mon Sep 17 00:00:00 2001 -From: Morgan Jones -Date: Mon, 5 May 2025 20:34:02 -0700 -Subject: [PATCH] process: disable KillLongRunningChild test - ---- - packages/process/_test.pony | 3 ++- - 1 file changed, 2 insertions(+), 1 deletion(-) - -diff --git a/packages/process/_test.pony b/packages/process/_test.pony -index fe9fdb04..756588f9 100644 ---- a/packages/process/_test.pony -+++ b/packages/process/_test.pony -@@ -18,7 +18,8 @@ actor \nodoc\ Main is TestList - test(_TestChdir) - test(_TestExpect) - test(_TestFileExecCapabilityIsRequired) -- test(_TestKillLongRunningChild) -+ // (@booxter/@numinit) Appears to be flaky. -+ // test(_TestKillLongRunningChild) - test(_TestLongRunningChild) - test(_TestNonExecutablePathResultsInExecveError) - test(_TestPrintvOrdering) --- -2.47.0 - diff --git a/pkgs/by-name/po/ponyc/fix-darwin-build.patch b/pkgs/by-name/po/ponyc/fix-darwin-build.patch deleted file mode 100644 index 47d99cfb9242..000000000000 --- a/pkgs/by-name/po/ponyc/fix-darwin-build.patch +++ /dev/null @@ -1,13 +0,0 @@ -diff --git a/src/libponyc/codegen/genexe.cc b/src/libponyc/codegen/genexe.cc -index 3f0348eaa1..76b03030bf 100644 ---- a/src/libponyc/codegen/genexe.cc -+++ b/src/libponyc/codegen/genexe.cc -@@ -308,7 +308,7 @@ - snprintf(ld_cmd, ld_len, - "%s -execute -arch %.*s " - "-o %s %s %s %s " -- "-L/Library/Developer/CommandLineTools/SDKs/MacOSX.sdk/usr/lib -lSystem %s -platform_version macos '" STR(PONY_OSX_PLATFORM) "' '0.0.0'", -+ "-L\"${SDKROOT:-${DEVELOPER_DIR:-@apple-sdk@}/Platforms/MacOSX.platform/Developer/SDKs/MacOSX.sdk}/usr/lib\" -lSystem %s -platform_version macos '" STR(PONY_OSX_PLATFORM) "' '0.0.0'", - linker, (int)arch_len, c->opt->triple, file_exe, file_o, - lib_args, ponyrt, sanitizer_arg - ); diff --git a/pkgs/by-name/po/ponyc/gencshim-pony-cc.patch b/pkgs/by-name/po/ponyc/gencshim-pony-cc.patch new file mode 100644 index 000000000000..8340ca6d893b --- /dev/null +++ b/pkgs/by-name/po/ponyc/gencshim-pony-cc.patch @@ -0,0 +1,61 @@ +diff --git a/src/libponyc/codegen/gencshim.cc b/src/libponyc/codegen/gencshim.cc +index a1722ad01a22..db742c6adaa5 100644 +--- a/src/libponyc/codegen/gencshim.cc ++++ b/src/libponyc/codegen/gencshim.cc +@@ -7,6 +7,7 @@ + #include "../ast/stringtab.h" + #include "paths.h" + #include "ponyassert.h" ++#include "nix.h" + + #ifdef _MSC_VER + # pragma warning(push) +@@ -307,8 +308,11 @@ static const char* find_macos_sdk_include(pass_opt_t* opt) + pclose(f); + } + ++ // Fall back to the Nix apple-sdk when xcrun is unavailable, mirroring the ++ // link side in genexe.cc. The unversioned MacOSX.sdk symlink keeps this ++ // independent of the SDK version. + const char* fallback = +- "/Library/Developer/CommandLineTools/SDKs/MacOSX.sdk/usr/include"; ++ "@apple-sdk@/Platforms/MacOSX.platform/Developer/SDKs/MacOSX.sdk/usr/include"; + + if(dir_exists(fallback)) + { +@@ -349,6 +353,25 @@ static bool push_isystem(pass_opt_t* opt, std::vector& args, + } + + ++/* ++ Add the Nix header search directories (see nix.h) as -internal-isystem ++ entries. push_isystem skips any directory that doesn't exist, so a partial ++ toolchain degrades gracefully. ++*/ ++static bool add_nix_include_dirs(pass_opt_t* opt, ++ std::vector& args, errors_t* errors) ++{ ++ std::vector dirs; ++ nix_collect_include_dirs(opt->strtab, dirs); ++ ++ bool any = false; ++ for(size_t i = 0; i < dirs.size(); i++) ++ any |= push_isystem(opt, args, errors, "-internal-isystem", dirs[i], ""); ++ ++ return any; ++} ++ ++ + // System include directories for the target, derived from the same sysroot + // the embedded linker uses — hand-rolled like LLD rather than driven through + // clang's Driver, so the headers the shim compiles against stay consistent +@@ -488,6 +511,9 @@ static bool add_system_include_args(pass_opt_t* opt, const char* sysroot, + any |= push_isystem(opt, args, errors, "-internal-externc-isystem", + sysroot, "/usr/include"); + ++ if(sysroot[0] == '\0') ++ any |= add_nix_include_dirs(opt, args, errors); ++ + // Per-directory skipping is right (multiarch and /usr/local are + // legitimately absent on many systems), but an explicit --sysroot that + // yields nothing at all deserves a direct answer, like the macOS branch diff --git a/pkgs/by-name/po/ponyc/genexe-pony-linker.patch b/pkgs/by-name/po/ponyc/genexe-pony-linker.patch index 39fa7a117f19..c7567b998f14 100644 --- a/pkgs/by-name/po/ponyc/genexe-pony-linker.patch +++ b/pkgs/by-name/po/ponyc/genexe-pony-linker.patch @@ -1,26 +1,158 @@ -From ac4b2a65f997f7f779b9c63dbe683ba10a26fc7f Mon Sep 17 00:00:00 2001 -From: Morgan Jones -Date: Fri, 22 May 2026 23:58:29 -0700 -Subject: [PATCH] genexe: take PONY_LINKER into account - ---- - src/libponyc/codegen/genexe.cc | 3 +++ - 1 file changed, 3 insertions(+) - diff --git a/src/libponyc/codegen/genexe.cc b/src/libponyc/codegen/genexe.cc -index 48f97578..5b9f36f1 100644 +index 826d69f0bcba..897afba953bb 100644 --- a/src/libponyc/codegen/genexe.cc +++ b/src/libponyc/codegen/genexe.cc -@@ -1448,6 +1448,9 @@ static bool link_exe(compile_t* c, ast_t* program, - { - errors_t* errors = c->opt->check.errors; +@@ -22,6 +22,7 @@ LLD_HAS_DRIVER(wasm) + #include "../type/lookup.h" + #include "../../libponyrt/mem/pool.h" + #include "ponyassert.h" ++#include "nix.h" + #include -+ if(c->opt->linker == NULL) -+ c->opt->linker = getenv("PONY_LINKER"); + #include +@@ -38,6 +39,8 @@ LLD_HAS_DRIVER(wasm) + # include + #endif + ++static bool dir_has_arch_libc_crt(const char* dir, uint16_t target_machine); + - // Use embedded LLD for Linux, macOS, and Windows targets unless --linker - // escape hatch is specified. Sanitizer builds fall back to the system - // compiler driver for native compilation since sanitizer runtime libraries --- -2.53.0 - + #if defined(PONY_SANITIZER) + // Generated at configure time (top-level CMakeLists.txt, PONY_SANITIZERS_ENABLED + // block): the sanitizer runtime link fragment captured from the compiler driver. +@@ -965,6 +968,9 @@ static bool link_exe_lld_elf(compile_t* c, ast_t* program, + + program_lib_build_args_embedded(program, c->opt); + ++ std::vector env_libdirs; ++ nix_collect_link_libdirs(c->opt->strtab, env_libdirs); ++ + const char* sys_triple = system_triple(c->opt); + bool is_freebsd = target_is_freebsd(c->opt->triple); + bool is_dragonfly = target_is_dragonfly(c->opt->triple); +@@ -996,7 +1002,11 @@ static bool link_exe_lld_elf(compile_t* c, ast_t* program, + return false; + } + +- const char* dynlinker = dynamic_linker_path(c); ++ // Prefer a Nix-provided ELF interpreter (baked default or environment); ++ // fall back to the built-in FHS search when none is configured. ++ const char* dynlinker = nix_dynamic_linker(c->opt->strtab); ++ if(dynlinker[0] == '\0') ++ dynlinker = dynamic_linker_path(c); + if(!c->opt->staticbin && dynlinker == NULL) + { + errorf(errors, NULL, +@@ -1009,10 +1019,23 @@ static bool link_exe_lld_elf(compile_t* c, ast_t* program, + const char* libc_crt_dir = find_libc_crt_dir(sysroot, sys_triple, + target_machine, c->opt->strtab); + if(libc_crt_dir == NULL) ++ { ++ for(size_t i = 0; i < env_libdirs.size(); i++) ++ { ++ if(dir_has_arch_libc_crt(env_libdirs[i], target_machine)) ++ { ++ libc_crt_dir = env_libdirs[i]; ++ break; ++ } ++ } ++ } ++ if(libc_crt_dir == NULL) + { + errorf(errors, NULL, + "could not find a libc crt startup object (crt1.o or crt0.o) " +- "matching target architecture '%s' in sysroot '%s'", ++ "matching target architecture '%s' in sysroot '%s'\n" ++ " On NixOS systems, set PONY_LINK_LIBDIRS to the directory holding " ++ "the arch-matching libc startup object (crt1.o or crt0.o).", + c->opt->triple, sysroot); + return false; + } +@@ -1305,6 +1328,21 @@ static bool link_exe_lld_elf(compile_t* c, ast_t* program, + } + } + ++/* ++ Add /nix/store lib directories to the embedded linker args ++*/ ++ for(size_t i = 0; i < env_libdirs.size(); i++) ++ { ++ snprintf(buf, sizeof(buf), "-L%s", env_libdirs[i]); ++ args.push_back(stringtab(c->opt->strtab, buf)); ++ ++ if(!c->opt->staticbin) ++ { ++ args.push_back("-rpath"); ++ args.push_back(env_libdirs[i]); ++ } ++ } ++ + // Standard system library fallback paths. The paths above cover + // distro-specific locations (libc_crt_dir, gcc_lib_dir, etc.) but miss + // common install locations like /usr/local/lib (where libraries built +@@ -1732,9 +1770,10 @@ static const char* find_macos_sdk_path(strtable_t* strtab) + pclose(f); + } + +- // Hardcoded fallback. ++ // Fall back to the Nix apple-sdk when xcrun is unavailable. The unversioned ++ // MacOSX.sdk symlink keeps this independent of the SDK version. + const char* fallback = +- "/Library/Developer/CommandLineTools/SDKs/MacOSX.sdk/usr/lib"; ++ "@apple-sdk@/Platforms/MacOSX.platform/Developer/SDKs/MacOSX.sdk/usr/lib"; + + struct stat st; + if(stat(fallback, &st) == 0 && S_ISDIR(st.st_mode)) +@@ -1947,6 +1986,31 @@ static bool link_exe_lld_macho(compile_t* c, ast_t* program, + } + } + ++/* ++ Add /nix/store lib directories to the embedded Mach-O linker args, mirroring ++ the ELF path. On NixOS the C++ standard library, buildInputs and user FFI ++ libraries live under /nix/store, not in the SDK's usr/lib or the Homebrew and ++ /usr/local fallbacks above. nix_collect_link_libdirs() (see nix.h) gathers ++ them from the baked PONY_NIX_LINK_LIBDIRS default, the PONY_LINK_LIBDIRS / ++ NIX_LDFLAGS env vars, and the cc-wrapper's $NIX_CC/nix-support/cc-ldflags ++ (which carries the -L path on Darwin). Without this, ++ `use "lib:c++" if osx` (as used by pony-compiler) fails to link with ++ "library not found for -lc++". ++*/ ++ std::vector env_libdirs; ++ nix_collect_link_libdirs(c->opt->strtab, env_libdirs); ++ for(size_t i = 0; i < env_libdirs.size(); i++) ++ { ++ snprintf(buf, sizeof(buf), "-L%s", env_libdirs[i]); ++ args.push_back(stringtab(c->opt->strtab, buf)); ++ ++ if(!c->opt->staticbin) ++ { ++ args.push_back("-rpath"); ++ args.push_back(env_libdirs[i]); ++ } ++ } ++ + // Object file. + args.push_back(file_o); + +@@ -2417,3 +2481,21 @@ bool genexe(compile_t* c, ast_t* program) + + return true; + } ++ ++// Does `dir` hold a libc startup object (crt1.o / crt0.o) whose ELF machine ++// matches the target? Used to pick the crt directory out of the Nix libdirs ++// gathered by nix_collect_link_libdirs(). ++static bool dir_has_arch_libc_crt(const char* dir, uint16_t target_machine) ++{ ++ static const char* sentinels[] = { "crt1.o", "crt0.o" }; ++ char buf[PATH_MAX]; ++ ++ for(size_t j = 0; j < sizeof(sentinels) / sizeof(sentinels[0]); j++) ++ { ++ snprintf(buf, sizeof(buf), "%s/%s", dir, sentinels[j]); ++ if(file_exists(buf) && elf_matches_target(buf, target_machine)) ++ return true; ++ } ++ ++ return false; ++} diff --git a/pkgs/by-name/po/ponyc/nix-codegen.patch b/pkgs/by-name/po/ponyc/nix-codegen.patch new file mode 100644 index 000000000000..f56bc8cdba15 --- /dev/null +++ b/pkgs/by-name/po/ponyc/nix-codegen.patch @@ -0,0 +1,291 @@ +diff --git a/src/libponyc/codegen/nix.h b/src/libponyc/codegen/nix.h +new file mode 100644 +index 000000000000..b1368f222b91 +--- /dev/null ++++ b/src/libponyc/codegen/nix.h +@@ -0,0 +1,47 @@ ++#ifndef CODEGEN_NIX_H ++#define CODEGEN_NIX_H ++ ++#include "../ast/stringtab.h" ++ ++#include ++ ++/* ++ Nix/NixOS toolchain path discovery for the embedded LLD linker (genexe.cc) ++ and the embedded clang C-shim compiler (gencshim.cc). ++ ++ On Nix there is no FHS layout: no /usr/lib, no /lib64/ld-linux-*.so, no ++ /usr/include. The libc, libgcc, C++ runtime, buildInputs and user FFI ++ libraries all live under /nix/store, and their locations reach the compiler ++ through baked-in defaults (the -DPONY_NIX_* macros set at configure time) and ++ the cc-wrapper environment (NIX_LDFLAGS, NIX_CFLAGS_COMPILE, ++ $NIX_CC/nix-support/*). These helpers gather those paths so the embedded ++ tools link and compile without a wrapper script. ++ ++ On a plain non-Nix build every source is empty, so the collectors append ++ nothing and behaviour is unchanged. ++*/ ++ ++// Library search directories for the linker, in priority order: ++// PONY_NIX_LINK_LIBDIRS (baked default), PONY_LINK_LIBDIRS, NIX_LDFLAGS, ++// NIX_LDFLAGS_BEFORE, $NIX_CC/nix-support {orig-libc, cc-ldflags}. ++// Directories are interned into `strtab` and appended to `dirs`; existing ++// entries are left in place. ++void nix_collect_link_libdirs(strtable_t* strtab, ++ std::vector& dirs); ++ ++// Header search directories for the C-shim compiler, in priority order: ++// PONY_NIX_INCLUDE_DIRS (baked default), PONY_INCLUDE_DIRS, ++// NIX_CFLAGS_COMPILE, $NIX_CC/nix-support/libc-cflags. ++// Directories are interned into `strtab` and appended to `dirs`; existing ++// entries are left in place. ++void nix_collect_include_dirs(strtable_t* strtab, ++ std::vector& dirs); ++ ++// The ELF dynamic linker (interpreter) path, in priority order: ++// PONY_DYNAMIC_LINKER, PONY_NIX_DYNAMIC_LINKER (baked default), ++// $NIX_CC/nix-support/dynamic-linker. ++// Returns "" (never NULL) when none is configured, so the caller can test the ++// first byte and fall back to the built-in FHS search. ++const char* nix_dynamic_linker(strtable_t* strtab); ++ ++#endif +diff --git a/src/libponyc/codegen/nix.cc b/src/libponyc/codegen/nix.cc +new file mode 100644 +index 000000000000..eddfd7833103 +--- /dev/null ++++ b/src/libponyc/codegen/nix.cc +@@ -0,0 +1,220 @@ ++#include "nix.h" ++ ++#include "../ast/stringtab.h" ++ ++#include ++#include ++#include ++#include ++ ++#ifndef PATH_MAX ++# define PATH_MAX 4096 ++#endif ++ ++/* ++ The baked-in Nix defaults. package.nix passes each of these through ++ -DPONY_NIX_*="..." in NIX_CFLAGS_COMPILE at configure time, capturing the ++ cc-wrapper's libc/libgcc/pcre2/openssl lib dirs, the ELF interpreter and the ++ libc/gcc include dirs. They are empty strings on a plain source build, which ++ disables every Nix-specific path below. ++*/ ++#ifndef PONY_NIX_LINK_LIBDIRS ++# define PONY_NIX_LINK_LIBDIRS "" ++#endif ++#ifndef PONY_NIX_DYNAMIC_LINKER ++# define PONY_NIX_DYNAMIC_LINKER "" ++#endif ++#ifndef PONY_NIX_INCLUDE_DIRS ++# define PONY_NIX_INCLUDE_DIRS "" ++#endif ++ ++/* ++ Split `s` into tokens on any delimiter character in `delims`, interning each ++ token into `strtab` and appending it to `toks`. A token that would overflow ++ the buffer is dropped whole rather than truncated to a wrong path. ++*/ ++static void tokenize(const char* s, const char* delims, strtable_t* strtab, ++ std::vector& toks) ++{ ++ if(s == NULL || s[0] == '\0') ++ return; ++ ++ char buf[PATH_MAX]; ++ size_t len = 0; ++ bool overflow = false; ++ for(const char* p = s; ; p++) ++ { ++ // The '\0' test is first so strchr is never asked to match the terminator. ++ if(*p == '\0' || strchr(delims, *p) != NULL) ++ { ++ if(len > 0 && !overflow) ++ { ++ buf[len] = '\0'; ++ toks.push_back(stringtab(strtab, buf)); ++ } ++ len = 0; ++ overflow = false; ++ if(*p == '\0') ++ break; ++ } ++ else if(len < sizeof(buf) - 1) ++ { ++ buf[len++] = *p; ++ } ++ else ++ { ++ overflow = true; ++ } ++ } ++} ++ ++/* ++ Interpret a whitespace-separated linker-flag string (NIX_LDFLAGS, ++ $NIX_CC/nix-support/cc-ldflags) for library directories, handling the joined ++ -L, the separated -L , and -rpath / -rpath-link forms. ++ ++ This is how /nix/store libraries (and directories injected by pkg-config) are ++ found where other distros would look in /usr/lib and the like. ++*/ ++static void append_ldflags_dirs(const char* flags, strtable_t* strtab, ++ std::vector& dirs) ++{ ++ std::vector toks; ++ tokenize(flags, " \t\n\r", strtab, toks); ++ ++ for(size_t i = 0; i < toks.size(); i++) ++ { ++ const char* t = toks[i]; ++ if(strncmp(t, "-L", 2) == 0) ++ { ++ if(t[2] != '\0') ++ dirs.push_back(stringtab(strtab, t + 2)); ++ else if(i + 1 < toks.size()) ++ dirs.push_back(toks[++i]); ++ } ++ else if(strcmp(t, "-rpath") == 0 || strcmp(t, "-rpath-link") == 0) ++ { ++ if(i + 1 < toks.size()) ++ dirs.push_back(toks[++i]); ++ } ++ } ++} ++ ++/* ++ Interpret a whitespace-separated compiler-flag string (NIX_CFLAGS_COMPILE, ++ $NIX_CC/nix-support/libc-cflags) for header search directories, handling the ++ joined -I, the separated -I , and -isystem / -idirafter / -iquote ++ forms. This covers directories injected by pkg-config too. ++*/ ++static void append_cflags_include_dirs(const char* flags, strtable_t* strtab, ++ std::vector& dirs) ++{ ++ std::vector toks; ++ tokenize(flags, " \t\n\r", strtab, toks); ++ ++ for(size_t i = 0; i < toks.size(); i++) ++ { ++ const char* t = toks[i]; ++ if(strcmp(t, "-isystem") == 0 || strcmp(t, "-idirafter") == 0 || ++ strcmp(t, "-iquote") == 0 || strcmp(t, "-I") == 0) ++ { ++ if(i + 1 < toks.size()) ++ dirs.push_back(toks[++i]); ++ } ++ else if(strncmp(t, "-I", 2) == 0 && t[2] != '\0') ++ { ++ dirs.push_back(stringtab(strtab, t + 2)); ++ } ++ } ++} ++ ++/* ++ Read $NIX_CC/nix-support/ into `out`, trimming trailing whitespace. ++ Returns false if the file is missing, empty, or so long it would be ++ truncated -- acting on a partial flag string would be worse than ignoring it. ++*/ ++static bool read_nix_support_file(const char* nix_cc, const char* name, ++ char* out, size_t outsz) ++{ ++ char path[PATH_MAX]; ++ snprintf(path, sizeof(path), "%s/nix-support/%s", nix_cc, name); ++ ++ FILE* f = fopen(path, "rb"); ++ if(f == NULL) ++ return false; ++ ++ size_t n = fread(out, 1, outsz - 1, f); ++ // If the buffer filled and the file still has bytes, the content was ++ // truncated; reject it rather than acting on a partial flag string. ++ bool truncated = (n == outsz - 1) && (fgetc(f) != EOF); ++ fclose(f); ++ if(truncated) ++ return false; ++ out[n] = '\0'; ++ ++ while(n > 0 && (out[n - 1] == '\n' || out[n - 1] == '\r' || ++ out[n - 1] == ' ' || out[n - 1] == '\t')) ++ out[--n] = '\0'; ++ ++ return n > 0; ++} ++ ++void nix_collect_link_libdirs(strtable_t* strtab, ++ std::vector& dirs) ++{ ++ tokenize(PONY_NIX_LINK_LIBDIRS, ":", strtab, dirs); ++ tokenize(getenv("PONY_LINK_LIBDIRS"), ":", strtab, dirs); ++ append_ldflags_dirs(getenv("NIX_LDFLAGS"), strtab, dirs); ++ append_ldflags_dirs(getenv("NIX_LDFLAGS_BEFORE"), strtab, dirs); ++ ++ const char* nix_cc = getenv("NIX_CC"); ++ if(nix_cc == NULL || nix_cc[0] == '\0') ++ return; ++ ++ char buf[PATH_MAX]; ++ if(read_nix_support_file(nix_cc, "orig-libc", buf, sizeof(buf))) ++ { ++ char libdir[PATH_MAX]; ++ snprintf(libdir, sizeof(libdir), "%s/lib", buf); ++ dirs.push_back(stringtab(strtab, libdir)); ++ } ++ ++ if(read_nix_support_file(nix_cc, "cc-ldflags", buf, sizeof(buf))) ++ append_ldflags_dirs(buf, strtab, dirs); ++} ++ ++void nix_collect_include_dirs(strtable_t* strtab, ++ std::vector& dirs) ++{ ++ tokenize(PONY_NIX_INCLUDE_DIRS, ":", strtab, dirs); ++ tokenize(getenv("PONY_INCLUDE_DIRS"), ":", strtab, dirs); ++ append_cflags_include_dirs(getenv("NIX_CFLAGS_COMPILE"), strtab, dirs); ++ ++ const char* nix_cc = getenv("NIX_CC"); ++ if(nix_cc != NULL && nix_cc[0] != '\0') ++ { ++ char cflags[PATH_MAX * 4]; ++ if(read_nix_support_file(nix_cc, "libc-cflags", cflags, sizeof(cflags))) ++ append_cflags_include_dirs(cflags, strtab, dirs); ++ } ++} ++ ++const char* nix_dynamic_linker(strtable_t* strtab) ++{ ++ const char* dl = getenv("PONY_DYNAMIC_LINKER"); ++ if(dl != NULL && dl[0] != '\0') ++ return stringtab(strtab, dl); ++ ++ if(PONY_NIX_DYNAMIC_LINKER[0] != '\0') ++ return stringtab(strtab, PONY_NIX_DYNAMIC_LINKER); ++ ++ const char* nix_cc = getenv("NIX_CC"); ++ if(nix_cc != NULL && nix_cc[0] != '\0') ++ { ++ char buf[PATH_MAX]; ++ if(read_nix_support_file(nix_cc, "dynamic-linker", buf, sizeof(buf))) ++ return stringtab(strtab, buf); ++ } ++ ++ return ""; ++} +diff --git a/src/libponyc/CMakeLists.txt b/src/libponyc/CMakeLists.txt +index f4e3e42ef48f..4a477e306ac1 100644 +--- a/src/libponyc/CMakeLists.txt ++++ b/src/libponyc/CMakeLists.txt +@@ -27,6 +27,7 @@ add_library(libponyc STATIC + codegen/gendesc.c + codegen/gencshim.cc + codegen/genexe.cc ++ codegen/nix.cc + codegen/genexpr.c + codegen/genfun.c + codegen/genheader.c diff --git a/pkgs/by-name/po/ponyc/package.nix b/pkgs/by-name/po/ponyc/package.nix index 3d01332e124f..d46d5dcb16c3 100644 --- a/pkgs/by-name/po/ponyc/package.nix +++ b/pkgs/by-name/po/ponyc/package.nix @@ -7,14 +7,11 @@ cmake, coreutils, libxml2, - lto ? true, - makeWrapper, openssl, pcre2, pony-corral, python3, zlib, - # Not really used for anything real, just at build time. git, replaceVars, which, @@ -25,13 +22,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "ponyc"; - version = "0.64.0"; + version = "0.67.0"; src = fetchFromGitHub { owner = "ponylang"; repo = "ponyc"; tag = finalAttrs.version; - hash = "sha256-CdsfJO+7y7nvlDdCXdWRB4vmP9pB1Jz5CVwJuha+yds="; + hash = "sha256-9X2xaQ5nCV/sTL3WjXNDswIfNhlwgfV4/X70p1zTd2U="; fetchSubmodules = true; }; @@ -53,7 +50,6 @@ stdenv.mkDerivation (finalAttrs: { nativeBuildInputs = [ cmake - makeWrapper which python3 git @@ -64,23 +60,36 @@ stdenv.mkDerivation (finalAttrs: { buildInputs = [ libxml2 + openssl + pcre2 z3 zlib ]; patches = [ + ./cmake-presets.patch # Sandbox disallows network access, so disabling problematic networking tests ./disable-networking-tests.patch - ./disable-process-tests.patch - - # Take PONY_LINKER into account - ./genexe-pony-linker.patch + # Adds codegen/nix.cc + nix.h (the Nix toolchain-path helpers shared by the + # embedded linker and C-shim compiler) and wires them into libponyc's + # CMakeLists. Platform-independent, so applied verbatim everywhere. + ./nix-codegen.patch ] - ++ lib.optionals stdenv.hostPlatform.isDarwin [ - (replaceVars ./fix-darwin-build.patch { - inherit apple-sdk; - }) - ]; + ++ ( + let + # These patch the embedded LLD/clang codegen and reference the macOS SDK + # via @apple-sdk@; substitute it on Darwin, apply verbatim elsewhere (the + # placeholder sits in macOS-only code that other platforms never compile). + sdkPatches = [ + ./gencshim-pony-cc.patch + ./genexe-pony-linker.patch + ]; + in + if stdenv.hostPlatform.isDarwin then + map (p: replaceVars p { inherit apple-sdk; }) sdkPatches + else + sdkPatches + ); postUnpack = '' mkdir -p $NIX_BUILD_TOP/deps @@ -88,8 +97,6 @@ stdenv.mkDerivation (finalAttrs: { tar -C "$googletest" -cf $NIX_BUILD_TOP/deps/googletest-$googletestRev.tar . ''; - dontConfigure = true; - postPatch = '' substituteInPlace packages/process/_test.pony \ --replace-fail '"/bin/' '"${coreutils}/bin/' \ @@ -105,8 +112,7 @@ stdenv.mkDerivation (finalAttrs: { ''; # We do not concern ourselves with darwin as the ponyc compiler - # has logic which overrides this environmental variable in this - # case. + # has logic which overrides this environment variable. env.arch = if stdenv.hostPlatform.isx86_64 then "x86-64" @@ -118,32 +124,41 @@ stdenv.mkDerivation (finalAttrs: { this may result in crashes on incompatible CPUs! '' "native"; - preBuild = '' - extraFlags=(build_flags=-j$NIX_BUILD_CORES) - '' - + lib.optionalString stdenv.hostPlatform.isLinux '' - export PONY_LINKER="$CC" - '' - + lib.optionalString stdenv.hostPlatform.isDarwin '' - export PONY_LINKER=ld - '' - + lib.optionalString stdenv.hostPlatform.isAarch64 '' - # See this relnote about building on Raspbian: - # https://github.com/ponylang/ponyc/blob/0.46.0/.release-notes/0.45.2.md - extraFlags+=(pic_flag=-fPIC) - '' - + '' - make libs "''${extraFlags[@]}" - make configure "''${extraFlags[@]}" + # Bake the Nix link/include paths into the compiler before it is built. + preConfigure = + lib.optionalString stdenv.hostPlatform.isLinux '' + libcDir=$(dirname "$($CC -print-file-name=crt1.o)") + gccDir=$(dirname "$($CC -print-libgcc-file-name)") + gccSharedDir=$(dirname "$($CC -print-file-name=libgcc_s.so)") + dynamicLinker=$(cat "$NIX_CC/nix-support/dynamic-linker") + libcIncDir="$(cat "$NIX_CC/nix-support/orig-libc-dev")/include" + # pcre2 and openssl are baked into the compiler's link path so an installed + # ponyc can link `use "regex"` (pcre2) and `use "net/ssl"` (openssl) + # programs without a wrapper — this replaces the old wrapProgram PONYPATH. + export NIX_CFLAGS_COMPILE="$NIX_CFLAGS_COMPILE -DPONY_NIX_LINK_LIBDIRS=\"$libcDir:$gccDir:$gccSharedDir:${lib.getLib pcre2}/lib:${lib.getLib openssl}/lib\" -DPONY_NIX_DYNAMIC_LINKER=\"$dynamicLinker\" -DPONY_NIX_INCLUDE_DIRS=\"$libcIncDir:$gccDir/include:$gccDir/include-fixed\"" + '' + + lib.optionalString stdenv.hostPlatform.isDarwin '' + # Bake pcre2/openssl into the compiler's link path so an installed ponyc can + # link `use "regex"` / `use "net/ssl"` without a wrapper; libc and the C++ + # standard library come from the SDK (via xcrun / apple-sdk) at link time. + export NIX_CFLAGS_COMPILE="$NIX_CFLAGS_COMPILE -DPONY_NIX_LINK_LIBDIRS=\"${lib.getLib pcre2}/lib:${lib.getLib openssl}/lib\"" + ''; + + # Upstream drives the build through CMakePresets (which fix the binaryDir and + # compiler), so we bypass the cmake setup hook's configurePhase and invoke the + # presets directly rather than fight its flags. + configurePhase = '' + runHook preConfigure + cmake -DJOBS=$NIX_BUILD_CORES -P lib/build-libs.cmake + cmake --preset release + runHook postConfigure ''; - enableParallelBuilding = true; - - makeFlags = [ - "PONYC_VERSION=${finalAttrs.version}" - "prefix=${placeholder "out"}" - ] - ++ lib.optionals stdenv.hostPlatform.isDarwin ([ "bits=64" ] ++ lib.optional (!lto) "lto=no"); + buildPhase = '' + runHook preBuild + cmake --build --preset release --parallel $NIX_BUILD_CORES + runHook postBuild + ''; env.NIX_CFLAGS_COMPILE = toString [ "-Wno-error=redundant-move" @@ -152,35 +167,21 @@ stdenv.mkDerivation (finalAttrs: { doCheck = true; - enableParallelChecking = true; - nativeCheckInputs = [ procps ]; - installPhase = '' - makeArgs=(config=release prefix=$out) - '' - + lib.optionalString stdenv.hostPlatform.isDarwin '' - makeArgs+=(bits=64) - '' - + lib.optionalString (stdenv.hostPlatform.isDarwin && !lto) '' - makeArgs+=(lto=no) - '' - + '' - make "''${makeArgs[@]}" install - wrapProgram $out/bin/ponyc \ - --prefix PATH ":" "${stdenv.cc}/bin" \ - --set-default CC "$CC" \ - --set-default PONY_LINKER "$PONY_LINKER" \ - --prefix PONYPATH : "${ - lib.makeLibraryPath [ - pcre2 - openssl - (placeholder "out") - ] - }" + checkPhase = '' + runHook preCheck + ctest --preset release -L ci-core -j$NIX_BUILD_CORES + runHook postCheck ''; - # Stripping breaks linking for ponyc + installPhase = '' + runHook preInstall + cmake --install build/build_release --prefix=$out + runHook postInstall + ''; + + # Stripping breaks linking for ponyc. dontStrip = true; passthru = { @@ -189,17 +190,19 @@ stdenv.mkDerivation (finalAttrs: { }; meta = { - description = "Pony is an Object-oriented, actor-model, capabilities-secure, high performance programming language"; + description = "Object-oriented, actor-model, capabilities-secure, high performance programming language"; homepage = "https://www.ponylang.io"; license = lib.licenses.bsd2; + mainProgram = "ponyc"; maintainers = with lib.maintainers; [ kamilchm redvers numinit ]; + # Intel macOS (x86_64-darwin) is intentionally unsupported; only Apple + # Silicon is supported on Darwin. platforms = [ "x86_64-linux" - "x86_64-darwin" "aarch64-linux" "aarch64-darwin" ]; From 7973bd606a8925d4fff6b22879cd954e0b44ae10 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 21 Jul 2026 12:59:44 +0000 Subject: [PATCH 078/175] libssh: 0.12.0 -> 0.12.1 https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/ Fixes: CVE-2026-15370: Stack buffer overflow in SFTP server longname construction CVE-2026-59842: Information disclosure via short GSSAPI Curve25519 public key CVE-2026-59843: Denial of service via zero advertised channel packet size CVE-2026-59844: Denial of service via oversized SFTP read length CVE-2026-59845: Denial of service via unchecked ProxyCommand fork() failure CVE-2026-59846: Information disclosure via ProxyCommand %r username expansion CVE-2026-59847: Integrity downgrade via OpenSSL AES-GCM tag verification CVE-2026-59848: Denial of service via SFTP responses with unknown request IDs CVE-2026-59849: Denial of service via automatic certificate authentication loop CVE-2026-59850: Use-after-free via data callbacks on closed channels CVE-2026-59851: Authentication bypass via missing GSSAPI principal check --- pkgs/by-name/li/libssh/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/li/libssh/package.nix b/pkgs/by-name/li/libssh/package.nix index 2c786b504b1a..b8a4ef7a8f92 100644 --- a/pkgs/by-name/li/libssh/package.nix +++ b/pkgs/by-name/li/libssh/package.nix @@ -19,11 +19,11 @@ stdenv.mkDerivation (finalAttrs: { pname = "libssh"; - version = "0.12.0"; + version = "0.12.1"; src = fetchurl { url = "https://www.libssh.org/files/${lib.versions.majorMinor finalAttrs.version}/libssh-${finalAttrs.version}.tar.xz"; - hash = "sha256-Gmr0JNgyfl7t705f5/W5JCJt1hesnz3oDyF9gqNqcSE="; + hash = "sha256-05Qa8KLXjV2C7Xo2mI6RM5lDEvA1uWWabkP42zloeEw="; }; outputs = [ From a4973ac2d498d79c8c205f120e3ebfc3b1357226 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Wed, 22 Jul 2026 09:42:35 +0000 Subject: [PATCH 079/175] valkey: 9.1.0 -> 9.1.1 --- pkgs/by-name/va/valkey/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/va/valkey/package.nix b/pkgs/by-name/va/valkey/package.nix index 558f37808261..3bc7d80bb2e4 100644 --- a/pkgs/by-name/va/valkey/package.nix +++ b/pkgs/by-name/va/valkey/package.nix @@ -24,13 +24,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "valkey"; - version = "9.1.0"; + version = "9.1.1"; src = fetchFromGitHub { owner = "valkey-io"; repo = "valkey"; rev = finalAttrs.version; - hash = "sha256-RMZz83fycpOTPWB1dIXU0/hdh4ZGC+6JhCws8htAQ5E="; + hash = "sha256-wGHlPQ2JPxGTaJRJ9Siz3Q3eKdlo5z1tQpSFs9xZMbI="; }; patches = lib.optional useSystemJemalloc ./use_system_jemalloc.patch; From d2cff906ccda0f0d676331e0d1b8a9b6e5df713e Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Wed, 22 Jul 2026 14:52:36 +0200 Subject: [PATCH 080/175] unbound: 1.25.1 -> 1.25.2 https://github.com/NLnetLabs/unbound/releases/tag/release-1.25.2 Fixes: CVE-2026-14586, CVE-2026-32665, CVE-2026-40691, CVE-2026-41637, CVE-2026-42955, CVE-2026-44621, CVE-2026-44687, CVE-2026-44690, CVE-2026-46582, CVE-2026-50045, CVE-2026-50046, CVE-2026-50243, CVE-2026-50248, CVE-2026-50251, CVE-2026-50252, CVE-2026-52863, CVE-2026-54478, CVE-2026-55708, CVE-2026-55717, CVE-2026-55973, CVE-2026-55990, CVE-2026-55991, CVE-2026-56416, CVE-2026-56444 --- pkgs/by-name/un/unbound/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/un/unbound/package.nix b/pkgs/by-name/un/unbound/package.nix index b2b52eadbb27..a90eb0b1d364 100644 --- a/pkgs/by-name/un/unbound/package.nix +++ b/pkgs/by-name/un/unbound/package.nix @@ -63,13 +63,13 @@ assert lib.assertMsg ( ) "unbound: withDoQ requires OpenSSL with QUIC support (OpenSSL >= 3.5)"; stdenv.mkDerivation (finalAttrs: { pname = "unbound"; - version = "1.25.1"; + version = "1.25.2"; src = fetchFromGitHub { owner = "NLnetLabs"; repo = "unbound"; tag = "release-${finalAttrs.version}"; - hash = "sha256-1PXnxCPxoB5IrVBQIsrxiWAq+IoH7Ma9T1TTJsoTJc4="; + hash = "sha256-zt0JpVmct7w6ay+p8CdH6SGt/rL/v//e7K3MT8KZfOY="; }; outputs = [ From 311df0ada36e8a4e090081f975accad7f20e6c6f Mon Sep 17 00:00:00 2001 From: whoomee Date: Mon, 13 Jul 2026 11:23:14 +0200 Subject: [PATCH 081/175] gstreamer: 1.28.4 -> 1.28.5 --- pkgs/development/libraries/gstreamer/bad/default.nix | 4 ++-- pkgs/development/libraries/gstreamer/base/default.nix | 4 ++-- pkgs/development/libraries/gstreamer/core/default.nix | 4 ++-- pkgs/development/libraries/gstreamer/devtools/default.nix | 5 ++--- pkgs/development/libraries/gstreamer/ges/default.nix | 4 ++-- pkgs/development/libraries/gstreamer/good/default.nix | 4 ++-- pkgs/development/libraries/gstreamer/libav/default.nix | 4 ++-- pkgs/development/libraries/gstreamer/rtsp-server/default.nix | 4 ++-- pkgs/development/libraries/gstreamer/ugly/default.nix | 4 ++-- 9 files changed, 18 insertions(+), 19 deletions(-) diff --git a/pkgs/development/libraries/gstreamer/bad/default.nix b/pkgs/development/libraries/gstreamer/bad/default.nix index 46b703ddfd34..4cda8c7b251c 100644 --- a/pkgs/development/libraries/gstreamer/bad/default.nix +++ b/pkgs/development/libraries/gstreamer/bad/default.nix @@ -118,7 +118,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "gst-plugins-bad"; - version = "1.28.4"; + version = "1.28.5"; outputs = [ "out" @@ -127,7 +127,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "https://gstreamer.freedesktop.org/src/gst-plugins-bad/gst-plugins-bad-${finalAttrs.version}.tar.xz"; - hash = "sha256-MytzIPMMYPLVlBRG0DudBeN4HywlYb776IcYvXd/Dkc="; + hash = "sha256-2K9V+u8pWMGoZjdRR17kb1Fkh3z02MWRPqkG7xgK63E="; }; patches = [ diff --git a/pkgs/development/libraries/gstreamer/base/default.nix b/pkgs/development/libraries/gstreamer/base/default.nix index 8b779a923226..ab1e504eb70f 100644 --- a/pkgs/development/libraries/gstreamer/base/default.nix +++ b/pkgs/development/libraries/gstreamer/base/default.nix @@ -52,7 +52,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "gst-plugins-base"; - version = "1.28.4"; + version = "1.28.5"; outputs = [ "out" @@ -63,7 +63,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "https://gstreamer.freedesktop.org/src/gst-plugins-base/gst-plugins-base-${finalAttrs.version}.tar.xz"; - hash = "sha256-qJiv1XZhcrAEnmeBVY4GiQmL+HudgrhGxlLlccAdYNg="; + hash = "sha256-d28ZIo+R/SW79U2YUFl+FYUH9ZSHKlK5toFOJCm0Pqo="; }; __structuredAttrs = true; diff --git a/pkgs/development/libraries/gstreamer/core/default.nix b/pkgs/development/libraries/gstreamer/core/default.nix index 35151386097a..bb50a0e7b186 100644 --- a/pkgs/development/libraries/gstreamer/core/default.nix +++ b/pkgs/development/libraries/gstreamer/core/default.nix @@ -42,7 +42,7 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "gstreamer"; - version = "1.28.4"; + version = "1.28.5"; outputs = [ "bin" @@ -54,7 +54,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "https://gstreamer.freedesktop.org/src/gstreamer/gstreamer-${finalAttrs.version}.tar.xz"; - hash = "sha256-9a3H6PRIwQJgs7JaoQHJ1UBnTI2aVMK3eobQTys7UN0="; + hash = "sha256-pan3g4CbF6jrd09KdpWyy4y6axVSASmQb4fq8w5/hGk="; }; depsBuildBuild = [ diff --git a/pkgs/development/libraries/gstreamer/devtools/default.nix b/pkgs/development/libraries/gstreamer/devtools/default.nix index e856bd59b233..e1e8cf9e4637 100644 --- a/pkgs/development/libraries/gstreamer/devtools/default.nix +++ b/pkgs/development/libraries/gstreamer/devtools/default.nix @@ -2,7 +2,6 @@ lib, stdenv, fetchurl, - fetchpatch, cairo, meson, ninja, @@ -28,7 +27,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "gst-devtools"; - version = "1.28.4"; + version = "1.28.5"; outputs = [ "out" @@ -37,7 +36,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "https://gstreamer.freedesktop.org/src/gst-devtools/gst-devtools-${finalAttrs.version}.tar.xz"; - hash = "sha256-EdTxGIY506l2IDkGW7t7LDCbeo7Mb6Su0SJFVovwDbM="; + hash = "sha256-dFkEXbMdbkRgC8vgEdySV1AmiHDnuQ9+ego69KIcCeU="; }; cargoDeps = rustPlatform.fetchCargoVendor { diff --git a/pkgs/development/libraries/gstreamer/ges/default.nix b/pkgs/development/libraries/gstreamer/ges/default.nix index e41fa069923b..005a3f90c3a9 100644 --- a/pkgs/development/libraries/gstreamer/ges/default.nix +++ b/pkgs/development/libraries/gstreamer/ges/default.nix @@ -23,7 +23,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "gst-editing-services"; - version = "1.28.4"; + version = "1.28.5"; outputs = [ "out" @@ -32,7 +32,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "https://gstreamer.freedesktop.org/src/gst-editing-services/gst-editing-services-${finalAttrs.version}.tar.xz"; - hash = "sha256-b361Xlhxjd5bWGn2Ge2Q6/Owz6A3bBacG4P8dzgRkUo="; + hash = "sha256-0C+d99108qUCQ6b6XjJ8+71cEhKc57bnPXDAhTJJGog="; }; separateDebugInfo = true; diff --git a/pkgs/development/libraries/gstreamer/good/default.nix b/pkgs/development/libraries/gstreamer/good/default.nix index 6d0dd4edbdaf..50385e3a620e 100644 --- a/pkgs/development/libraries/gstreamer/good/default.nix +++ b/pkgs/development/libraries/gstreamer/good/default.nix @@ -80,7 +80,7 @@ assert raspiCameraSupport -> hostSupportsRaspiCamera; stdenv.mkDerivation (finalAttrs: { pname = "gst-plugins-good"; - version = "1.28.4"; + version = "1.28.5"; outputs = [ "out" @@ -89,7 +89,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "https://gstreamer.freedesktop.org/src/gst-plugins-good/gst-plugins-good-${finalAttrs.version}.tar.xz"; - hash = "sha256-yCXqc3xZzqDkoMQdojiARf9d0y0WIiCsk6eoLuSgTmE="; + hash = "sha256-WLRdJKHXeznXu32czG4tdrvyhhiZjDNcFj8Y5vlKkyQ="; }; patches = [ diff --git a/pkgs/development/libraries/gstreamer/libav/default.nix b/pkgs/development/libraries/gstreamer/libav/default.nix index ecff969ca150..92c906d4c1a9 100644 --- a/pkgs/development/libraries/gstreamer/libav/default.nix +++ b/pkgs/development/libraries/gstreamer/libav/default.nix @@ -19,7 +19,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "gst-libav"; - version = "1.28.4"; + version = "1.28.5"; outputs = [ "out" @@ -28,7 +28,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "https://gstreamer.freedesktop.org/src/gst-libav/gst-libav-${finalAttrs.version}.tar.xz"; - hash = "sha256-vRel3yh0p6WLy697lAIjN5rZYTYk246teD2wPnS7kEs="; + hash = "sha256-RShUZWBW8LFlEaHZrU8mef9eWofIn5DPfuXewAXdseQ="; }; separateDebugInfo = true; diff --git a/pkgs/development/libraries/gstreamer/rtsp-server/default.nix b/pkgs/development/libraries/gstreamer/rtsp-server/default.nix index b71da6b03adb..5fdb31e1ddd8 100644 --- a/pkgs/development/libraries/gstreamer/rtsp-server/default.nix +++ b/pkgs/development/libraries/gstreamer/rtsp-server/default.nix @@ -19,7 +19,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "gst-rtsp-server"; - version = "1.28.4"; + version = "1.28.5"; outputs = [ "out" @@ -28,7 +28,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "https://gstreamer.freedesktop.org/src/gst-rtsp-server/gst-rtsp-server-${finalAttrs.version}.tar.xz"; - hash = "sha256-v7Z4BUK/DUAnNiMq6ubFoblDxEV3W/QDBby4bKcHBaA="; + hash = "sha256-fhn93rEmG+vD7Dl4V/7dXHcSm2arUniP2trQURdWYiU="; }; separateDebugInfo = true; diff --git a/pkgs/development/libraries/gstreamer/ugly/default.nix b/pkgs/development/libraries/gstreamer/ugly/default.nix index 279dbb12b173..b524bc2fac7f 100644 --- a/pkgs/development/libraries/gstreamer/ugly/default.nix +++ b/pkgs/development/libraries/gstreamer/ugly/default.nix @@ -27,7 +27,7 @@ stdenv.mkDerivation (finalAttrs: { pname = "gst-plugins-ugly"; - version = "1.28.4"; + version = "1.28.5"; outputs = [ "out" @@ -36,7 +36,7 @@ stdenv.mkDerivation (finalAttrs: { src = fetchurl { url = "https://gstreamer.freedesktop.org/src/gst-plugins-ugly/gst-plugins-ugly-${finalAttrs.version}.tar.xz"; - hash = "sha256-VIbNFFxa9DJZ/TfKylnQSOKmfdsHCC6o9Q7w8CqF+KU="; + hash = "sha256-DvTPnDyaXndqbKjRkKMYYzkbaBmAJSFDuCKymqgx4SA="; }; separateDebugInfo = true; From cda27cc0cbd024fef01d74a22147c9cb27699f5d Mon Sep 17 00:00:00 2001 From: whoomee Date: Wed, 22 Jul 2026 15:02:31 +0200 Subject: [PATCH 082/175] python3Packages.gst-python: 1.28.4 -> 1.28.5 --- pkgs/development/python-modules/gst-python/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/gst-python/default.nix b/pkgs/development/python-modules/gst-python/default.nix index 45c25c2550a6..1934d3a14ea6 100644 --- a/pkgs/development/python-modules/gst-python/default.nix +++ b/pkgs/development/python-modules/gst-python/default.nix @@ -21,7 +21,7 @@ buildPythonPackage rec { pname = "gst-python"; - version = "1.28.4"; + version = "1.28.5"; pyproject = false; @@ -32,7 +32,7 @@ buildPythonPackage rec { src = fetchurl { url = "https://gstreamer.freedesktop.org/src/gst-python/gst-python-${version}.tar.xz"; - hash = "sha256-xOs4JyC0RD+4AaU0GN/wvUzXR4cW1c7Uk1BKZ1tNCf0="; + hash = "sha256-CsRhtXALl2aZiqaGQ5BkyvWMpP2vhI39R3tadwCxdsw="; }; patches = [ From b240a809a85bc19828b5b947f0438d1db87a4a39 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Wed, 22 Jul 2026 10:17:10 -0700 Subject: [PATCH 083/175] python3Packages.mistune: 3.3.3 -> 3.3.4 Diff: https://github.com/lepture/mistune/compare/v3.3.3...v3.3.4 Changelog: https://github.com/lepture/mistune/blob/v3.3.4/docs/changes.rst --- pkgs/development/python-modules/mistune/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/mistune/default.nix b/pkgs/development/python-modules/mistune/default.nix index c1d564dbab7b..ad9fd2bd3d7a 100644 --- a/pkgs/development/python-modules/mistune/default.nix +++ b/pkgs/development/python-modules/mistune/default.nix @@ -8,14 +8,14 @@ buildPythonPackage (finalAttrs: { pname = "mistune"; - version = "3.3.3"; + version = "3.3.4"; pyproject = true; src = fetchFromGitHub { owner = "lepture"; repo = "mistune"; tag = "v${finalAttrs.version}"; - hash = "sha256-AAOpQ3GMEifMVM1SaT5zVltIshAQt5SYqCtIvdjy20M="; + hash = "sha256-7N1Kz2lN6GyDVKUhuGrEkbinV8Vpc4aahal/7KhnIXo="; }; build-system = [ setuptools ]; From e7fc5f592978ec4cdc98ef5198c40693aa8844ab Mon Sep 17 00:00:00 2001 From: Sergei Trofimovich Date: Wed, 22 Jul 2026 22:37:16 +0100 Subject: [PATCH 084/175] libtool: 2.5.4 -> 2.6.2 Changes: https://lists.gnu.org/archive/html/info-gnu/2026-07/msg00003.html --- pkgs/development/tools/misc/libtool/libtool2.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/tools/misc/libtool/libtool2.nix b/pkgs/development/tools/misc/libtool/libtool2.nix index f087e49b13a8..43bc3f4e4852 100644 --- a/pkgs/development/tools/misc/libtool/libtool2.nix +++ b/pkgs/development/tools/misc/libtool/libtool2.nix @@ -15,11 +15,11 @@ stdenv.mkDerivation rec { pname = "libtool"; - version = "2.5.4"; + version = "2.6.2"; src = fetchurl { url = "mirror://gnu/libtool/${pname}-${version}.tar.gz"; - sha256 = "sha256-2o67LOTc9GuQCY2vliz/po9LT2LqYPeY0O8Skp7eat8="; + hash = "sha256-JK2zqprgNccPq6NEr1fXMhXriSgQRa9sfM0wd1H4sL8="; }; outputs = [ From 75eca02672c5bae157b63971690528ec5ff5620c Mon Sep 17 00:00:00 2001 From: Sergei Trofimovich Date: Wed, 22 Jul 2026 22:40:53 +0100 Subject: [PATCH 085/175] libmicrohttpd: 1.0.5 -> 1.0.6 --- pkgs/development/libraries/libmicrohttpd/1.0.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/libraries/libmicrohttpd/1.0.nix b/pkgs/development/libraries/libmicrohttpd/1.0.nix index 138f80ca444c..9248819673c6 100644 --- a/pkgs/development/libraries/libmicrohttpd/1.0.nix +++ b/pkgs/development/libraries/libmicrohttpd/1.0.nix @@ -1,10 +1,10 @@ { callPackage, fetchurl }: callPackage ./generic.nix rec { - version = "1.0.5"; + version = "1.0.6"; src = fetchurl { url = "mirror://gnu/libmicrohttpd/libmicrohttpd-${version}.tar.gz"; - hash = "sha256-tG0A9Y76b0l7l9LngsTuZjAdQS3dhV3TBoUYs6LNPqI="; + hash = "sha256-u1z8rfxS29XrUS1uKZXgNhNRwz6XqHq6Qm06Snumz3A="; }; } From 6096796a2be65fe166f7f538d93f390ca2beda4a Mon Sep 17 00:00:00 2001 From: "Adam C. Stephens" Date: Wed, 22 Jul 2026 23:12:57 -0400 Subject: [PATCH 086/175] musl: 1.2.5 -> 1.2.6 --- pkgs/by-name/mu/musl/package.nix | 28 +++------- pkgs/by-name/mu/musl/renameat2.patch | 55 ------------------- pkgs/by-name/mu/musl/statx-attr.patch | 35 ------------ pkgs/by-name/mu/musl/statx-linux-6.11.patch | 49 ----------------- pkgs/by-name/mu/musl/statx.patch | 39 ------------- ...pty-iovec-when-buffering-is-disabled.patch | 31 ----------- 6 files changed, 8 insertions(+), 229 deletions(-) delete mode 100644 pkgs/by-name/mu/musl/renameat2.patch delete mode 100644 pkgs/by-name/mu/musl/statx-attr.patch delete mode 100644 pkgs/by-name/mu/musl/statx-linux-6.11.patch delete mode 100644 pkgs/by-name/mu/musl/statx.patch delete mode 100644 pkgs/by-name/mu/musl/stdio-skip-empty-iovec-when-buffering-is-disabled.patch diff --git a/pkgs/by-name/mu/musl/package.nix b/pkgs/by-name/mu/musl/package.nix index 4e9ce959c31e..3df1b2289934 100644 --- a/pkgs/by-name/mu/musl/package.nix +++ b/pkgs/by-name/mu/musl/package.nix @@ -57,11 +57,11 @@ let in stdenv.mkDerivation (finalAttrs: { pname = "musl"; - version = "1.2.5"; + version = "1.2.6"; src = fetchurl { url = "https://musl.libc.org/releases/musl-${finalAttrs.version}.tar.gz"; - sha256 = "qaEYu+hNh2TaDqDSizqz+uhHf8fkCF2QECuFlvx8deQ="; + hash = "sha256-1YX9O2E8ZhUfwySejtRPdwIMtebB5jWmFtP5+CRgUSo="; }; enableParallelBuilding = true; @@ -85,27 +85,15 @@ stdenv.mkDerivation (finalAttrs: { sha256 = "0hfadrycb60sm6hb6by4ycgaqc9sgrhh42k39v8xpmcvdzxrsq2n"; }) (fetchurl { - name = "CVE-2025-26519_0.patch"; - url = "https://www.openwall.com/lists/musl/2025/02/13/1/1"; - hash = "sha256-CJb821El2dByP04WXxPCCYMOcEWnXLpOhYBgg3y3KS4="; + name = "CVE-2026-6042"; + url = "https://www.openwall.com/lists/musl/2026/04/03/2/1"; + hash = "sha256-RE+nDlLKFY+31LrVYGN3kLv49y6AuC//hA3Wb6gwkeM="; }) (fetchurl { - name = "CVE-2025-26519_1.patch"; - url = "https://www.openwall.com/lists/musl/2025/02/13/1/2"; - hash = "sha256-BiD87k6KTlLr4ep14rUdIZfr2iQkicBYaSTq+p6WBqE="; + name = "CVE-2026-40200.patch"; + url = "https://www.openwall.com/lists/musl/2026/04/10/3/1"; + hash = "sha256-HuKfZPnKjorXw0l3nWYf9rUhJqJ1ddNYaYE1elLEBvs="; }) - # required for systemd user namespacing and oomd to work correctly on musl - # drop next release - # https://git.musl-libc.org/cgit/musl/commit/?id=fde29c04adbab9d5b081bf6717b5458188647f1c - ./stdio-skip-empty-iovec-when-buffering-is-disabled.patch - # Backport addition of statx fields needed by systemd - ./statx.patch - # Backport addition of statx attrs needed by systemd - ./statx-attr.patch - # Backport even more statx stuff for systemd - ./statx-linux-6.11.patch - # Backport addition of renameat2 syscall wrapper needed by systemd - ./renameat2.patch ]; env = { diff --git a/pkgs/by-name/mu/musl/renameat2.patch b/pkgs/by-name/mu/musl/renameat2.patch deleted file mode 100644 index 22416191d20c..000000000000 --- a/pkgs/by-name/mu/musl/renameat2.patch +++ /dev/null @@ -1,55 +0,0 @@ -From 05ce67fea99ca09cd4b6625cff7aec9cc222dd5a Mon Sep 17 00:00:00 2001 -From: Tony Ambardar -Date: Mon, 6 May 2024 20:28:32 -0700 -Subject: add renameat2 linux syscall wrapper - -This syscall is available since Linux 3.15 and also implemented in -glibc from version 2.28. It is commonly used in filesystem or security -contexts. - -Constants RENAME_NOREPLACE, RENAME_EXCHANGE, RENAME_WHITEOUT are -guarded by _GNU_SOURCE as with glibc. ---- - include/stdio.h | 7 +++++++ - src/linux/renameat2.c | 11 +++++++++++ - 2 files changed, 18 insertions(+) - create mode 100644 src/linux/renameat2.c - -diff --git a/include/stdio.h b/include/stdio.h -index cb858618..4ea4c170 100644 ---- a/include/stdio.h -+++ b/include/stdio.h -@@ -158,6 +158,13 @@ char *ctermid(char *); - #define L_ctermid 20 - #endif - -+#if defined(_GNU_SOURCE) -+#define RENAME_NOREPLACE (1 << 0) -+#define RENAME_EXCHANGE (1 << 1) -+#define RENAME_WHITEOUT (1 << 2) -+ -+int renameat2(int, const char *, int, const char *, unsigned); -+#endif - - #if defined(_XOPEN_SOURCE) || defined(_GNU_SOURCE) \ - || defined(_BSD_SOURCE) -diff --git a/src/linux/renameat2.c b/src/linux/renameat2.c -new file mode 100644 -index 00000000..b8060388 ---- /dev/null -+++ b/src/linux/renameat2.c -@@ -0,0 +1,11 @@ -+#define _GNU_SOURCE -+#include -+#include "syscall.h" -+ -+int renameat2(int oldfd, const char *old, int newfd, const char *new, unsigned flags) -+{ -+#ifdef SYS_renameat -+ if (!flags) return syscall(SYS_renameat, oldfd, old, newfd, new); -+#endif -+ return syscall(SYS_renameat2, oldfd, old, newfd, new, flags); -+} --- -cgit v1.2.1 - diff --git a/pkgs/by-name/mu/musl/statx-attr.patch b/pkgs/by-name/mu/musl/statx-attr.patch deleted file mode 100644 index 50c2a16d433c..000000000000 --- a/pkgs/by-name/mu/musl/statx-attr.patch +++ /dev/null @@ -1,35 +0,0 @@ -From cbf1c7b605d979bb7fdde8b8e6a66acdba18c6b0 Mon Sep 17 00:00:00 2001 -From: Rich Felker -Date: Wed, 24 Apr 2024 13:26:03 -0400 -Subject: add missing STATX_ATTR_* macros omitted when statx was added - -commit b817541f1cfd38e4b81257b3215e276ea9d0fc61 added statx and the -mask constant macros, but not the stx_attributes[_mask] ones. ---- - include/sys/stat.h | 10 ++++++++++ - 1 file changed, 10 insertions(+) - -diff --git a/include/sys/stat.h b/include/sys/stat.h -index 6690192d..57d640d7 100644 ---- a/include/sys/stat.h -+++ b/include/sys/stat.h -@@ -121,6 +121,16 @@ int lchmod(const char *, mode_t); - #define STATX_BTIME 0x800U - #define STATX_ALL 0xfffU - -+#define STATX_ATTR_COMPRESSED 0x4 -+#define STATX_ATTR_IMMUTABLE 0x10 -+#define STATX_ATTR_APPEND 0x20 -+#define STATX_ATTR_NODUMP 0x40 -+#define STATX_ATTR_ENCRYPTED 0x800 -+#define STATX_ATTR_AUTOMOUNT 0x1000 -+#define STATX_ATTR_MOUNT_ROOT 0x2000 -+#define STATX_ATTR_VERITY 0x100000 -+#define STATX_ATTR_DAX 0x200000 -+ - struct statx_timestamp { - int64_t tv_sec; - uint32_t tv_nsec, __pad; --- -cgit v1.2.1 - diff --git a/pkgs/by-name/mu/musl/statx-linux-6.11.patch b/pkgs/by-name/mu/musl/statx-linux-6.11.patch deleted file mode 100644 index 6e5564a06ef9..000000000000 --- a/pkgs/by-name/mu/musl/statx-linux-6.11.patch +++ /dev/null @@ -1,49 +0,0 @@ -From fcdff46a3203400e08a2264c34b3c7fb62bf6969 Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?J=2E=20Neusch=C3=A4fer?= -Date: Thu, 24 Oct 2024 01:19:30 +0200 -Subject: statx: add Linux 6.11 fields/constants - -As of Linux 6.11, these fields and mask macros have been added to -include/uapi/linux/stat.h. ---- - include/sys/stat.h | 10 +++++++++- - 1 file changed, 9 insertions(+), 1 deletion(-) - -diff --git a/include/sys/stat.h b/include/sys/stat.h -index c924ce2f..4f7dc2b1 100644 ---- a/include/sys/stat.h -+++ b/include/sys/stat.h -@@ -123,6 +123,8 @@ int lchmod(const char *, mode_t); - #define STATX_MNT_ID 0x1000U - #define STATX_DIOALIGN 0x2000U - #define STATX_MNT_ID_UNIQUE 0x4000U -+#define STATX_SUBVOL 0x8000U -+#define STATX_WRITE_ATOMIC 0x10000U - - #define STATX_ATTR_COMPRESSED 0x4 - #define STATX_ATTR_IMMUTABLE 0x10 -@@ -133,6 +135,7 @@ int lchmod(const char *, mode_t); - #define STATX_ATTR_MOUNT_ROOT 0x2000 - #define STATX_ATTR_VERITY 0x100000 - #define STATX_ATTR_DAX 0x200000 -+#define STATX_ATTR_WRITE_ATOMIC 0x400000 - - struct statx_timestamp { - int64_t tv_sec; -@@ -164,7 +167,12 @@ struct statx { - uint32_t stx_dio_mem_align; - uint32_t stx_dio_offset_align; - uint64_t stx_subvol; -- uint64_t __pad1[11]; -+ uint32_t stx_atomic_write_unit_min; -+ uint32_t stx_atomic_write_unit_max; -+ uint32_t stx_atomic_write_segments_max; -+ uint32_t __pad1[1]; -+ uint64_t __pad2[9]; -+ - }; - - int statx(int, const char *__restrict, int, unsigned, struct statx *__restrict); --- -cgit v1.2.1 - diff --git a/pkgs/by-name/mu/musl/statx.patch b/pkgs/by-name/mu/musl/statx.patch deleted file mode 100644 index fd08b5303cbb..000000000000 --- a/pkgs/by-name/mu/musl/statx.patch +++ /dev/null @@ -1,39 +0,0 @@ -From 23ab04a8630225371455d5f4538fd078665bb646 Mon Sep 17 00:00:00 2001 -From: Rich Felker -Date: Fri, 13 Sep 2024 17:21:17 -0400 -Subject: statx: add new struct statx fields and corresponding mask macros - ---- - include/sys/stat.h | 9 ++++++++- - 1 file changed, 8 insertions(+), 1 deletion(-) - -diff --git a/include/sys/stat.h b/include/sys/stat.h -index 57d640d7..0c10dc21 100644 ---- a/include/sys/stat.h -+++ b/include/sys/stat.h -@@ -120,6 +120,9 @@ int lchmod(const char *, mode_t); - #define STATX_BASIC_STATS 0x7ffU - #define STATX_BTIME 0x800U - #define STATX_ALL 0xfffU -+#define STATX_MNT_ID 0x1000U -+#define STATX_DIOALIGN 0x2000U -+#define STATX_MNT_ID_UNIQUE 0x4000U - - #define STATX_ATTR_COMPRESSED 0x4 - #define STATX_ATTR_IMMUTABLE 0x10 -@@ -157,7 +160,11 @@ struct statx { - uint32_t stx_rdev_minor; - uint32_t stx_dev_major; - uint32_t stx_dev_minor; -- uint64_t __pad1[14]; -+ uint64_t stx_mnt_id; -+ uint32_t stx_dio_mem_align; -+ uint32_t stx_dio_offet_align; -+ uint64_t stx_subvol; -+ uint64_t __pad1[11]; - }; - - int statx(int, const char *__restrict, int, unsigned, struct statx *__restrict); --- -cgit v1.2.1 - diff --git a/pkgs/by-name/mu/musl/stdio-skip-empty-iovec-when-buffering-is-disabled.patch b/pkgs/by-name/mu/musl/stdio-skip-empty-iovec-when-buffering-is-disabled.patch deleted file mode 100644 index 68fbb526b2c5..000000000000 --- a/pkgs/by-name/mu/musl/stdio-skip-empty-iovec-when-buffering-is-disabled.patch +++ /dev/null @@ -1,31 +0,0 @@ -From fde29c04adbab9d5b081bf6717b5458188647f1c Mon Sep 17 00:00:00 2001 -From: Casey Connolly -Date: Wed, 23 Apr 2025 15:06:48 +0200 -Subject: stdio: skip empty iovec when buffering is disabled - -When buffering on a FILE is disabled we still send both iovecs, even -though the first one is always empty. Clean things up by skipping the -empty iovec instead. ---- - src/stdio/__stdio_write.c | 5 +++++ - 1 file changed, 5 insertions(+) - -diff --git a/src/stdio/__stdio_write.c b/src/stdio/__stdio_write.c -index d2d89475..5356553d 100644 ---- a/src/stdio/__stdio_write.c -+++ b/src/stdio/__stdio_write.c -@@ -11,6 +11,11 @@ size_t __stdio_write(FILE *f, const unsigned char *buf, size_t len) - size_t rem = iov[0].iov_len + iov[1].iov_len; - int iovcnt = 2; - ssize_t cnt; -+ -+ if (!iov->iov_len) { -+ iov++; -+ iovcnt--; -+ } - for (;;) { - cnt = syscall(SYS_writev, f->fd, iov, iovcnt); - if (cnt == rem) { --- -cgit v1.2.1 - From a453e9151ef80e33920c732fc6bdc05c94066ac8 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Andr=C3=A9=20Silva?= Date: Tue, 21 Jul 2026 09:06:28 +0100 Subject: [PATCH 087/175] python3Packages.numpy_2: fix for test failure on i686 --- pkgs/development/python-modules/numpy/2.nix | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/pkgs/development/python-modules/numpy/2.nix b/pkgs/development/python-modules/numpy/2.nix index 80bfe85db35a..1c713aa89257 100644 --- a/pkgs/development/python-modules/numpy/2.nix +++ b/pkgs/development/python-modules/numpy/2.nix @@ -2,6 +2,7 @@ lib, stdenv, fetchFromGitHub, + fetchpatch, python, pythonAtLeast, buildPythonPackage, @@ -52,6 +53,16 @@ buildPythonPackage (finalAttrs: { hash = "sha256-IriSrnGAZHvJ7m97s12BydNQZDZunCVtRgj/iSgw5Vc="; }; + patches = [ + # Fix for test failure on i686. Remove with next release. + # Upstream report: https://github.com/numpy/numpy/issues/32060 + # Upstream PR: https://github.com/numpy/numpy/pull/32064 + (fetchpatch { + url = "https://github.com/numpy/numpy/commit/0e1dce62e27f79be9d6552487787a19b7f95cfbf.patch"; + hash = "sha256-mQjf6y/mLSgx9+G70/r9U3VJg5zIrl/6ANQhpP2LGmg="; + }) + ]; + postPatch = '' # remove needless reference to full Python path stored in built wheel substituteInPlace numpy/meson.build \ From 5fe66fcffe54ab89c77ed4ad9186989127aa382d Mon Sep 17 00:00:00 2001 From: Alex James Date: Sun, 12 Jul 2026 02:36:11 -0500 Subject: [PATCH 088/175] haskell.compiler.ghc984Binary: workaround com.apple.provenance xattr This is taken from #413450. --- pkgs/development/compilers/ghc/9.8.4-binary.nix | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/pkgs/development/compilers/ghc/9.8.4-binary.nix b/pkgs/development/compilers/ghc/9.8.4-binary.nix index 90f7d1f56170..50fb1be83bfa 100644 --- a/pkgs/development/compilers/ghc/9.8.4-binary.nix +++ b/pkgs/development/compilers/ghc/9.8.4-binary.nix @@ -324,6 +324,15 @@ stdenv.mkDerivation { # calls install-strip ... dontBuild = true; + # GHC tries to remove xattrs when installing to work around Gatekeeper + # (see https://gitlab.haskell.org/ghc/ghc/-/issues/17418). This step normally + # succeeds in nixpkgs because xattrs are not allowed in the store, but it + # can fail when a file has the `com.apple.provenance` xattr, and it can’t be + # modified (such as target of the symlink to `libiconv.dylib`). + # The `com.apple.provenance` xattr is a new feature of macOS as of macOS 13. + # See: https://eclecticlight.co/2023/03/13/ventura-has-changed-app-quarantine-with-a-new-xattr/ + makeFlags = lib.optionals stdenv.buildPlatform.isDarwin [ "XATTR=/does-not-exist" ]; + # Patch scripts to include runtime dependencies in $PATH. postInstall = '' for i in "$out/bin/"*; do From 05c36f66d6c1abc43fe925fb40b439dde6425f29 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 24 Jul 2026 12:36:01 +0000 Subject: [PATCH 089/175] clj-kondo: 2026.05.25 -> 2026.07.24 --- pkgs/by-name/cl/clj-kondo/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/cl/clj-kondo/package.nix b/pkgs/by-name/cl/clj-kondo/package.nix index 36c66478b6f8..756f50175c15 100644 --- a/pkgs/by-name/cl/clj-kondo/package.nix +++ b/pkgs/by-name/cl/clj-kondo/package.nix @@ -6,11 +6,11 @@ buildGraalvmNativeImage (finalAttrs: { pname = "clj-kondo"; - version = "2026.05.25"; + version = "2026.07.24"; src = fetchurl { url = "https://github.com/clj-kondo/clj-kondo/releases/download/v${finalAttrs.version}/clj-kondo-${finalAttrs.version}-standalone.jar"; - sha256 = "sha256-SzrfsIHUW+KzZITesZ9aS00Gx7S4hekLsXXdjQJJxLM="; + sha256 = "sha256-QUZkiURBeuv0qxELNRhFw8MudP0m026IpZ8axG922Qg="; }; extraNativeImageBuildArgs = [ From 12f115452cd0c5172083faf965fe49da3f42b768 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Fri, 24 Jul 2026 15:52:52 +0200 Subject: [PATCH 090/175] python3Packages.httpcore2: 2.5.0 -> 2.9.1 https://github.com/pydantic/httpx2/blob/v2.9.1/src/httpcore2/CHANGELOG.md --- pkgs/development/python-modules/httpcore2/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/httpcore2/default.nix b/pkgs/development/python-modules/httpcore2/default.nix index fb4b68102f82..f87ae1db2a26 100644 --- a/pkgs/development/python-modules/httpcore2/default.nix +++ b/pkgs/development/python-modules/httpcore2/default.nix @@ -29,14 +29,14 @@ buildPythonPackage (finalAttrs: { pname = "httpcore2"; - version = "2.5.0"; + version = "2.9.1"; pyproject = true; src = fetchFromGitHub { owner = "pydantic"; repo = "httpx2"; tag = "v${finalAttrs.version}"; - hash = "sha256-vIWAUjHPyafbeeUc2OvGpkiOoTj1fTniRnQiKSdkm6s="; + hash = "sha256-3kghDQMYksF9a4sFGajzNfGPOjdX1OiMwv7rH/fbmM0="; }; postPatch = '' From 232cf6b9db521ef4cdbef40f6f0266e710c80170 Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Fri, 24 Jul 2026 16:04:23 +0200 Subject: [PATCH 091/175] python3Packages.httpx2: 2.5.0 -> 2.9.1 https://github.com/pydantic/httpx2/blob/v2.9.1/src/httpx2/CHANGELOG.md --- pkgs/development/python-modules/httpx2/default.nix | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) diff --git a/pkgs/development/python-modules/httpx2/default.nix b/pkgs/development/python-modules/httpx2/default.nix index 33ae69aa41fc..a92c7ccb868d 100644 --- a/pkgs/development/python-modules/httpx2/default.nix +++ b/pkgs/development/python-modules/httpx2/default.nix @@ -24,14 +24,17 @@ pygments, rich, socksio, + wsproto, zstandard, # tests chardet, pytestCheckHook, pytest-trio, + starlette, trustme, uvicorn, + websockets, # reverse deps httpx2, @@ -39,14 +42,14 @@ buildPythonPackage (finalAttrs: { pname = "httpx2"; - version = "2.5.0"; + version = "2.9.1"; pyproject = true; src = fetchFromGitHub { owner = "pydantic"; repo = "httpx2"; tag = "v${finalAttrs.version}"; - hash = "sha256-vIWAUjHPyafbeeUc2OvGpkiOoTj1fTniRnQiKSdkm6s="; + hash = "sha256-3kghDQMYksF9a4sFGajzNfGPOjdX1OiMwv7rH/fbmM0="; }; postPatch = '' @@ -75,6 +78,7 @@ buildPythonPackage (finalAttrs: { ]; http2 = [ h2 ]; socks = [ socksio ]; + ws = [ wsproto ]; zstd = lib.optionals (pythonOlder "3.14") [ zstandard ]; }; @@ -89,10 +93,11 @@ buildPythonPackage (finalAttrs: { nativeCheckInputs = [ chardet pytestCheckHook - # pytest-httpbin pytest-trio + (starlette.overridePythonAttrs { doCheck = false; }) trustme uvicorn + websockets ] ++ lib.concatAttrValues finalAttrs.passthru.optional-dependencies; From 61e6dad91eda3f6d1aba30a288792d6680ce7e7d Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sandro=20J=C3=A4ckel?= Date: Sun, 24 May 2026 01:44:51 +0200 Subject: [PATCH 092/175] python314Packages.psycopg.c: nuke libpq.dev refs in cython files We do not want to rely on development headers at runtime if we do not need to. Before: 243.72 MiB After: 223.54 MiB --- pkgs/development/python-modules/psycopg/default.nix | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/pkgs/development/python-modules/psycopg/default.nix b/pkgs/development/python-modules/psycopg/default.nix index 724a8287ea09..4e4200f9adba 100644 --- a/pkgs/development/python-modules/psycopg/default.nix +++ b/pkgs/development/python-modules/psycopg/default.nix @@ -4,6 +4,8 @@ buildPythonPackage, fetchFromGitHub, fetchurl, + nukeReferences, + python, replaceVars, # build @@ -78,12 +80,17 @@ let nativeBuildInputs = [ libpq.pg_config + nukeReferences ]; buildInputs = [ libpq ]; + postInstall = '' + nuke-refs $out/${python.sitePackages}/psycopg_c/{pq.c,_psycopg.c} + ''; + # tested in psycopg doCheck = false; From 6862cf855ece91ec64c600ef8ec5c3298453ec28 Mon Sep 17 00:00:00 2001 From: whispers Date: Fri, 3 Jul 2026 23:50:20 -0400 Subject: [PATCH 093/175] assimp: never treat warnings as fatal assimp sometimes has warnings that are triggered by new compiler or library versions. since assimp builds with -Werror by default, this requires workaround in Nixpkgs until they cut a release. this is the case with unused variable warnings in GCC 16. instead of dealing with this, we simply disable -Werror via the cmake flag it offers to do so. --- pkgs/by-name/as/assimp/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/as/assimp/package.nix b/pkgs/by-name/as/assimp/package.nix index 24769c4a231c..cdf66afdb6bd 100644 --- a/pkgs/by-name/as/assimp/package.nix +++ b/pkgs/by-name/as/assimp/package.nix @@ -42,6 +42,7 @@ stdenv.mkDerivation (finalAttrs: { cmakeFlags = [ (lib.cmakeBool "ASSIMP_BUILD_ASSIMP_TOOLS" true) (lib.cmakeBool "ASSIMP_BUILD_TESTS" finalAttrs.finalPackage.doCheck) + (lib.cmakeBool "ASSIMP_WARNINGS_AS_ERRORS" false) ]; # Some matrix tests fail on non-86_64-linux: From 838f68584abad7848141efddee08d0347832e40f Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Fri, 24 Jul 2026 11:49:04 -0700 Subject: [PATCH 094/175] python3Packages.aiohttp: 3.14.2 -> 3.14.3 Diff: https://github.com/aio-libs/aiohttp/compare/v3.14.2...v3.14.3 Changelog: https://docs.aiohttp.org/en/v3.14.3/changes.html --- pkgs/development/python-modules/aiohttp/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/aiohttp/default.nix b/pkgs/development/python-modules/aiohttp/default.nix index d06eff93da90..d94a6bd4688c 100644 --- a/pkgs/development/python-modules/aiohttp/default.nix +++ b/pkgs/development/python-modules/aiohttp/default.nix @@ -48,14 +48,14 @@ buildPythonPackage (finalAttrs: { pname = "aiohttp"; - version = "3.14.2"; + version = "3.14.3"; pyproject = true; src = fetchFromGitHub { owner = "aio-libs"; repo = "aiohttp"; tag = "v${finalAttrs.version}"; - hash = "sha256-gpAYbANSlUZoB0lATEP2N288GxlF8/GzD7bEW1AkHZw="; + hash = "sha256-n8LH34N9V2Smqc23q/49gqRbP0U1glJAYiyPEGFtEmM="; }; postPatch = '' From 7f6b809aa5cda12b67d54bfcbfbc2a7c278d6f85 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Fri, 24 Jul 2026 11:50:11 -0700 Subject: [PATCH 095/175] python3Packages.yarl: 1.24.2 -> 1.24.5 Diff: https://github.com/aio-libs/yarl/compare/v1.24.2...v1.24.5 Changelog: https://github.com/aio-libs/yarl/blob/v1.24.5/CHANGES.rst --- pkgs/development/python-modules/yarl/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/yarl/default.nix b/pkgs/development/python-modules/yarl/default.nix index ba29a36fff8f..3c725169879e 100644 --- a/pkgs/development/python-modules/yarl/default.nix +++ b/pkgs/development/python-modules/yarl/default.nix @@ -18,14 +18,14 @@ buildPythonPackage rec { pname = "yarl"; - version = "1.24.2"; + version = "1.24.5"; pyproject = true; src = fetchFromGitHub { owner = "aio-libs"; repo = "yarl"; tag = "v${version}"; - hash = "sha256-GEe2GDXmqsQgWB0UxPZVMdSco3j2JYHg9BU9M6oqynw="; + hash = "sha256-2Uqn1TwfH375CBIveEpsco4dDNrhxHwX8wIP8dKhh/M="; }; build-system = [ From 5e3b18898a5e5457060cc458eb8e3abcd70a1118 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Fri, 24 Jul 2026 11:51:13 -0700 Subject: [PATCH 096/175] python3Packages.yarl: use finalAttrs --- pkgs/development/python-modules/yarl/default.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/development/python-modules/yarl/default.nix b/pkgs/development/python-modules/yarl/default.nix index 3c725169879e..b2e5642a9cc6 100644 --- a/pkgs/development/python-modules/yarl/default.nix +++ b/pkgs/development/python-modules/yarl/default.nix @@ -16,7 +16,7 @@ pytestCheckHook, }: -buildPythonPackage rec { +buildPythonPackage (finalAttrs: { pname = "yarl"; version = "1.24.5"; pyproject = true; @@ -24,7 +24,7 @@ buildPythonPackage rec { src = fetchFromGitHub { owner = "aio-libs"; repo = "yarl"; - tag = "v${version}"; + tag = "v${finalAttrs.version}"; hash = "sha256-2Uqn1TwfH375CBIveEpsco4dDNrhxHwX8wIP8dKhh/M="; }; @@ -61,10 +61,10 @@ buildPythonPackage rec { pythonImportsCheck = [ "yarl" ]; meta = { - changelog = "https://github.com/aio-libs/yarl/blob/${src.tag}/CHANGES.rst"; + changelog = "https://github.com/aio-libs/yarl/blob/${finalAttrs.src.tag}/CHANGES.rst"; description = "Yet another URL library"; homepage = "https://github.com/aio-libs/yarl"; license = lib.licenses.asl20; maintainers = with lib.maintainers; [ dotlambda ]; }; -} +}) From dbce7bdf5feef17adcfa0af7b4d8bedde5f7fe98 Mon Sep 17 00:00:00 2001 From: SandaruKasa Date: Fri, 24 Jul 2026 21:55:48 +0300 Subject: [PATCH 097/175] ffmpeg: remove-references-to cuda llvm --- pkgs/development/libraries/ffmpeg/generic.nix | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/pkgs/development/libraries/ffmpeg/generic.nix b/pkgs/development/libraries/ffmpeg/generic.nix index 96166235a309..d19172328330 100644 --- a/pkgs/development/libraries/ffmpeg/generic.nix +++ b/pkgs/development/libraries/ffmpeg/generic.nix @@ -819,9 +819,10 @@ stdenv.mkDerivation ( toStrip = map placeholder (lib.remove "data" finalAttrs.outputs) # We want to keep references to the data dir. ++ lib.optional (stdenv.hostPlatform != stdenv.buildPlatform) buildPackages.stdenv.cc + ++ lib.optional withCudaLLVM buildPackages.clang.cc ++ lib.optional withMetal xcode; in - "remove-references-to ${lib.concatStringsSep " " (map (o: "-t ${o}") toStrip)} config.h"; + "remove-references-to ${lib.concatMapStringsSep " " (o: "-t ${o}") toStrip} config.h"; strictDeps = true; From c7010daad2adde95d4887e36e28347bcb0475edf Mon Sep 17 00:00:00 2001 From: Aliaksandr Date: Tue, 23 Jun 2026 19:07:11 +0300 Subject: [PATCH 098/175] zxing-cpp: add qweered to maintainers --- pkgs/by-name/zx/zxing-cpp/package.nix | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/zx/zxing-cpp/package.nix b/pkgs/by-name/zx/zxing-cpp/package.nix index 684152b4d73c..1f9a2f42f289 100644 --- a/pkgs/by-name/zx/zxing-cpp/package.nix +++ b/pkgs/by-name/zx/zxing-cpp/package.nix @@ -57,7 +57,10 @@ stdenv.mkDerivation (finalAttrs: { formats. ''; license = lib.licenses.asl20; - maintainers = with lib.maintainers; [ lukegb ]; + maintainers = with lib.maintainers; [ + lukegb + qweered + ]; platforms = lib.platforms.unix; }; }) From 2f81259e5680f75c73b8177f5818c6fc544dddfc Mon Sep 17 00:00:00 2001 From: Aliaksandr Date: Tue, 23 Jun 2026 19:07:11 +0300 Subject: [PATCH 099/175] zxing-cpp: 2.3.0 -> 3.0.2 --- pkgs/by-name/zx/zxing-cpp/package.nix | 10 +++++++-- .../python-modules/zxing-cpp/default.nix | 22 +++++++++++++++---- 2 files changed, 26 insertions(+), 6 deletions(-) diff --git a/pkgs/by-name/zx/zxing-cpp/package.nix b/pkgs/by-name/zx/zxing-cpp/package.nix index 1f9a2f42f289..182630f30259 100644 --- a/pkgs/by-name/zx/zxing-cpp/package.nix +++ b/pkgs/by-name/zx/zxing-cpp/package.nix @@ -6,25 +6,31 @@ python3, stdenv, libzint, + pkg-config, + stb, }: stdenv.mkDerivation (finalAttrs: { pname = "zxing-cpp"; - version = "2.3.0"; + version = "3.0.2"; src = fetchFromGitHub { owner = "zxing-cpp"; repo = "zxing-cpp"; tag = "v${finalAttrs.version}"; - hash = "sha256-e3nSxjg8p+1DEUbZOh4C2zfnA6iGhNJMPiIe2oJEbRo="; + hash = "sha256-ZtjvHBnuPJkc9kU998jH7IPlX3jF/RGtLNWDzsb0v4A="; }; + strictDeps = true; + nativeBuildInputs = [ cmake + pkg-config ]; buildInputs = [ libzint + stb ]; cmakeFlags = [ diff --git a/pkgs/development/python-modules/zxing-cpp/default.nix b/pkgs/development/python-modules/zxing-cpp/default.nix index 35c96d1fa444..47e30e3667a2 100644 --- a/pkgs/development/python-modules/zxing-cpp/default.nix +++ b/pkgs/development/python-modules/zxing-cpp/default.nix @@ -6,16 +6,17 @@ pillow, pybind11, libzxing-cpp, + pyprojectVersionPatchHook, pytestCheckHook, libzint, }: -buildPythonPackage rec { +buildPythonPackage { pname = "zxing-cpp"; - inherit (libzxing-cpp) src version meta; + inherit (libzxing-cpp) src version; pyproject = true; - sourceRoot = "${src.name}/wrappers/python"; + sourceRoot = "${libzxing-cpp.src.name}/wrappers/python"; # we don't need pybind11 in the root environment # https://pybind11.readthedocs.io/en/stable/installing.html#include-with-pypi @@ -25,7 +26,7 @@ buildPythonPackage rec { substituteInPlace setup.py \ --replace-fail "cfg = 'Debug' if self.debug else 'Release'" "cfg = 'Release'" \ - --replace-fail " '-DVERSION_INFO=' + self.distribution.get_version()]" " '-DVERSION_INFO=' + self.distribution.get_version(), '-DZXING_DEPENDENCIES=LOCAL', '-DZXING_USE_BUNDLED_ZINT=OFF']" + --replace-fail "f'-DPython_EXECUTABLE={sys.executable}'," "f'-DPython_EXECUTABLE={sys.executable}', '-DZXING_DEPENDENCIES=LOCAL', '-DZXING_USE_BUNDLED_ZINT=OFF'," ''; dontUseCmakeConfigure = true; @@ -39,6 +40,7 @@ buildPythonPackage rec { nativeBuildInputs = [ cmake + pyprojectVersionPatchHook ]; buildInputs = [ libzint ]; @@ -51,4 +53,16 @@ buildPythonPackage rec { enabledTestPaths = [ "test.py" ]; pythonImportsCheck = [ "zxingcpp" ]; + + meta = { + inherit (libzxing-cpp.meta) + homepage + changelog + description + longDescription + license + maintainers + platforms + ; + }; } From c5481d89f4cf59cf31778df354243fe40b6bdfeb Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sandro=20J=C3=A4ckel?= Date: Fri, 24 Jul 2026 22:30:12 +0200 Subject: [PATCH 100/175] paperless-ngx: relax zxing-cpp dependency --- pkgs/by-name/pa/paperless-ngx/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/pa/paperless-ngx/package.nix b/pkgs/by-name/pa/paperless-ngx/package.nix index 16b687473ea1..9d30558c2bcc 100644 --- a/pkgs/by-name/pa/paperless-ngx/package.nix +++ b/pkgs/by-name/pa/paperless-ngx/package.nix @@ -122,6 +122,7 @@ pythonPackages.buildPythonApplication (finalAttrs: { "scikit-learn" "tika-client" "tqdm" + "zxing-cpp" # requested by maintainer "imap-tools" "ocrmypdf" From 2dc0d42192388dff951eed8d89d427471c599668 Mon Sep 17 00:00:00 2001 From: Grimmauld Date: Sat, 25 Jul 2026 08:53:33 +0200 Subject: [PATCH 101/175] audit: 4.1.4 -> 4.2 Release notes: https://github.com/linux-audit/audit-userspace/releases/tag/v4.2 Diff: https://github.com/linux-audit/audit-userspace/compare/v4.1.4...v4.2 --- pkgs/by-name/au/audit/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/au/audit/package.nix b/pkgs/by-name/au/audit/package.nix index 3b2389e7843c..657e74647d6f 100644 --- a/pkgs/by-name/au/audit/package.nix +++ b/pkgs/by-name/au/audit/package.nix @@ -30,13 +30,13 @@ }: stdenv.mkDerivation (finalAttrs: { pname = "audit"; - version = "4.1.4"; + version = "4.2"; src = fetchFromGitHub { owner = "linux-audit"; repo = "audit-userspace"; tag = "v${finalAttrs.version}"; - hash = "sha256-GdJ9nzlDAdOazOHH/YWuEoELrJh+G5ZJUKwIqAKAzpo="; + hash = "sha256-poldhsF+ccutCxK7KE/gYpxa1x3wUQJWoCwU6pGFj6A="; }; postPatch = '' @@ -165,7 +165,7 @@ stdenv.mkDerivation (finalAttrs: { meta = { homepage = "https://people.redhat.com/sgrubb/audit/"; description = "Audit Library"; - changelog = "https://github.com/linux-audit/audit-userspace/releases/tag/v4.1.2"; + changelog = "https://github.com/linux-audit/audit-userspace/releases/tag/${finalAttrs.src.tag}"; license = lib.licenses.gpl2Plus; maintainers = with lib.maintainers; [ grimmauld ]; teams = [ lib.teams.security-review ]; From d8f639ff89d9b709c1d2925955ccd0593ec9b7db Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 25 Jul 2026 12:35:51 +0000 Subject: [PATCH 102/175] s2n-tls: 1.7.2 -> 1.7.6 --- pkgs/by-name/s2/s2n-tls/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/s2/s2n-tls/package.nix b/pkgs/by-name/s2/s2n-tls/package.nix index 8f55fddaa3bc..dbcdb1db532d 100644 --- a/pkgs/by-name/s2/s2n-tls/package.nix +++ b/pkgs/by-name/s2/s2n-tls/package.nix @@ -9,13 +9,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "s2n-tls"; - version = "1.7.2"; + version = "1.7.6"; src = fetchFromGitHub { owner = "aws"; repo = "s2n-tls"; tag = "v${finalAttrs.version}"; - hash = "sha256-oqWTcUGutEn5cOggiY1yPUlVWiHYKjnwBCCrEeWYn0A="; + hash = "sha256-ujKVtVioQP7RNyQ3hGVCNGanOpYlzTecerTdrsVtlUo="; }; nativeBuildInputs = [ cmake ]; From aa7a3b1c68b1992f1541d950a5b9490af73b327d Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 25 Jul 2026 15:50:42 +0000 Subject: [PATCH 103/175] javaPackages.compiler.openjdk21: 21.0.12+2 -> 21.0.12+8 --- pkgs/development/compilers/openjdk/21/source.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/compilers/openjdk/21/source.json b/pkgs/development/compilers/openjdk/21/source.json index e394396960d8..6e896ae41dfe 100644 --- a/pkgs/development/compilers/openjdk/21/source.json +++ b/pkgs/development/compilers/openjdk/21/source.json @@ -1,6 +1,6 @@ { - "hash": "sha256-5QWicPXWUyP1VkmTDIOjIgu9NXkB27nvtgUbrL+mSxg=", + "hash": "sha256-XxD5Tn5dMwirOoESCsza1dPvcgMF795Uh8YgaGUli1g=", "owner": "openjdk", "repo": "jdk21u", - "rev": "refs/tags/jdk-21.0.12+2" + "rev": "refs/tags/jdk-21.0.12+8" } From 44d362d5a61e4a7aa5dbbf2c06262ff335beba80 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 25 Jul 2026 16:36:43 +0000 Subject: [PATCH 104/175] linuxHeaders: 7.0 -> 7.1 --- pkgs/os-specific/linux/kernel-headers/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/kernel-headers/default.nix b/pkgs/os-specific/linux/kernel-headers/default.nix index 25f45e0ebc12..e5952533eb02 100644 --- a/pkgs/os-specific/linux/kernel-headers/default.nix +++ b/pkgs/os-specific/linux/kernel-headers/default.nix @@ -157,13 +157,13 @@ in linuxHeaders = let - version = "7.0"; + version = "7.1"; in makeLinuxHeaders { inherit version; src = fetchurl { url = "mirror://kernel/linux/kernel/v${lib.versions.major version}.x/linux-${version}.tar.xz"; - hash = "sha256-u39tgLOHx1e30Uu5MCj8uQ95PFwNNnc27oFaEAs4kfA="; + hash = "sha256-aR9EeX++eQ3IoyFgTJJwh1Jq0nttZJkl1g+O7QolZKA="; }; patches = [ ./no-relocs.patch # for building x86 kernel headers on non-ELF platforms From c249d818530c629aa1bb63d047cd64eed32002e9 Mon Sep 17 00:00:00 2001 From: whispers Date: Wed, 1 Jul 2026 07:48:05 -0400 Subject: [PATCH 105/175] usrsctp: make unused-but-set-variable non-fatal for gcc 16 since usrsctp builds with -Werror by default, and gcc 16's unused variable analysis is better than previous versions, this causes a build failure. a fix for this particular variable has been submitted upstream, but this is sufficient in the interim. --- pkgs/by-name/us/usrsctp/package.nix | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pkgs/by-name/us/usrsctp/package.nix b/pkgs/by-name/us/usrsctp/package.nix index 760e0f5a70d7..a5342203305a 100644 --- a/pkgs/by-name/us/usrsctp/package.nix +++ b/pkgs/by-name/us/usrsctp/package.nix @@ -38,6 +38,11 @@ stdenv.mkDerivation (finalAttrs: { nativeBuildInputs = [ cmake ]; + # GCC 16's unused variable analysis is more advanced, leading to a build + # failure since usrsctp builds with -Werror. + # https://github.com/sctplab/usrsctp/pull/744 + cmakeFlags = [ (lib.cmakeFeature "CMAKE_C_FLAGS" "-Wno-error=unused-but-set-variable") ]; + # https://github.com/sctplab/usrsctp/issues/662 postPatch = '' substituteInPlace usrsctplib/CMakeLists.txt \ From 67073b57ac26a416b100adaf17fde2a412da9d8f Mon Sep 17 00:00:00 2001 From: OPNA2608 Date: Sun, 26 Jul 2026 15:55:03 +0200 Subject: [PATCH 106/175] python3Packages.anyio: Disable test_keyboard_interrupt_does_not_resume_test Times out when run on a 21yo machine. --- pkgs/development/python-modules/anyio/default.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/development/python-modules/anyio/default.nix b/pkgs/development/python-modules/anyio/default.nix index 278a5e4de9b4..616b07091526 100644 --- a/pkgs/development/python-modules/anyio/default.nix +++ b/pkgs/development/python-modules/anyio/default.nix @@ -92,6 +92,8 @@ buildPythonPackage rec { # 3 second timeout expired "test_keyboardinterrupt_during_test" "test_dynamic_async_fixture_access_does_not_hang" + # 5 second timeout expires on weak hardware + "test_keyboard_interrupt_does_not_resume_test" # racy with high thread count, see https://github.com/NixOS/nixpkgs/issues/448125 "test_multiple_threads" From 4c7fe7e3ca7432578fb992ad58dcb076a80ed287 Mon Sep 17 00:00:00 2001 From: matthewcroughan Date: Sun, 26 Jul 2026 15:11:35 +0100 Subject: [PATCH 107/175] qrtr: 0-unstable-2025-03-01 -> 1.2 --- pkgs/by-name/qr/qrtr/package.nix | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/qr/qrtr/package.nix b/pkgs/by-name/qr/qrtr/package.nix index 355b8ce4fbc8..240dde537cdf 100644 --- a/pkgs/by-name/qr/qrtr/package.nix +++ b/pkgs/by-name/qr/qrtr/package.nix @@ -3,21 +3,21 @@ lib, fetchFromGitHub, meson, - cmake, pkg-config, systemd, ninja, + nix-update-script, }: stdenv.mkDerivation (finalAttrs: { pname = "qrtr"; - version = "0-unstable-2025-03-01"; + version = "1.2"; src = fetchFromGitHub { owner = "linux-msm"; repo = "qrtr"; - rev = "5923eea97377f4a3ed9121b358fd919e3659db7b"; - hash = "sha256-iHjF/2SQsvB/qC/UykNITH/apcYSVD+n4xA0S/rIfnM="; + tag = "v${finalAttrs.version}"; + hash = "sha256-plVPR3BKtMLSVgTK8TPFbt5vuo9ZovEGz6qJzUZ33G4="; }; nativeBuildInputs = [ @@ -30,6 +30,8 @@ stdenv.mkDerivation (finalAttrs: { installFlags = [ "prefix=$(out)" ]; + passthru.updateScript = nix-update-script { }; + meta = { maintainers = with lib.maintainers; [ matthewcroughan ]; description = "QMI IDL compiler"; From f1d2364ed16930b2357729ab8e2c898c7eee0652 Mon Sep 17 00:00:00 2001 From: Michael Daniels Date: Sun, 26 Jul 2026 11:45:24 -0400 Subject: [PATCH 108/175] coreutils: security patches Fixes CVE-2026-56391, CVE-2026-56392, NIXPKGS-2026-2271, and issue 545665 --- .../tools/misc/coreutils/CVE-2026-56391.patch | 45 +++++++++++++++ .../tools/misc/coreutils/CVE-2026-56392.patch | 57 +++++++++++++++++++ pkgs/tools/misc/coreutils/default.nix | 5 ++ 3 files changed, 107 insertions(+) create mode 100644 pkgs/tools/misc/coreutils/CVE-2026-56391.patch create mode 100644 pkgs/tools/misc/coreutils/CVE-2026-56392.patch diff --git a/pkgs/tools/misc/coreutils/CVE-2026-56391.patch b/pkgs/tools/misc/coreutils/CVE-2026-56391.patch new file mode 100644 index 000000000000..04f8d0506a13 --- /dev/null +++ b/pkgs/tools/misc/coreutils/CVE-2026-56391.patch @@ -0,0 +1,45 @@ +From d64e35a8a4c0e4608321433e0d84d917e4e36371 Mon Sep 17 00:00:00 2001 +From: Paul Eggert +Date: Tue, 28 Apr 2026 11:25:00 -0700 +Subject: [PATCH] uniq: fix read overrun with -w +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Problem reported by Michał Majchrowicz. +* src/uniq.c (find_field): Fix typo. +* tests/uniq/uniq.pl (add_z_variants): Test for the bug. +--- + src/uniq.c | 4 ++-- + tests/uniq/uniq.pl | 3 +++ + 2 files changed, 5 insertions(+), 2 deletions(-) + +diff --git a/src/uniq.c b/src/uniq.c +index 30463598a5..5834596f98 100644 +--- a/src/uniq.c ++++ b/src/uniq.c +@@ -285,8 +285,8 @@ find_field (struct linebuffer const *line, idx_t *plen) + else + { + char *ep = lp; +- for (idx_t i = check_chars; 0 < i && lp < lim; i--) +- ep += mcel_scan (lp, lim).len; ++ for (idx_t i = check_chars; 0 < i && ep < lim; i--) ++ ep += mcel_scan (ep, lim).len; + len = ep - lp; + } + +diff --git a/tests/uniq/uniq.pl b/tests/uniq/uniq.pl +index b558fb3ee2..0df7ec62d7 100755 +--- a/tests/uniq/uniq.pl ++++ b/tests/uniq/uniq.pl +@@ -234,6 +234,9 @@ ($) + " - 'separate'\n" . + " - 'both'\n" . + "Try '$prog --help' for more information.\n"}], ++ # Test for read buffer overrun. ++ do { my $longline = "\360\237\230\200" . "A" x 255 . "\n"; ++ ['146', '-w256', {IN => $longline x 2}, {OUT => $longline}] }, + ); + + # Locale related tests diff --git a/pkgs/tools/misc/coreutils/CVE-2026-56392.patch b/pkgs/tools/misc/coreutils/CVE-2026-56392.patch new file mode 100644 index 000000000000..8838ea5134c1 --- /dev/null +++ b/pkgs/tools/misc/coreutils/CVE-2026-56392.patch @@ -0,0 +1,57 @@ +From b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?P=C3=A1draig=20Brady?= +Date: Tue, 28 Apr 2026 20:33:10 +0100 +Subject: [PATCH] unexpand: fix heap overflow +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +* src/unexpand.c (unexpand): Use xinmalloc() to gracefully +handle overflow. Also use the runtime locale specific MB_CUR_MAX +rather than the worst case MB_LEN_MAX. +* tests/unexpand/mb.sh: Add a test case that fails in a default +glibc build with either MB_CUR_MAX or MB_LEN_MAX. +* NEWS: Mention the bug fix. +Reported by Michał Majchrowicz. +--- + src/unexpand.c | 2 +- + tests/unexpand/mb.sh | 8 ++++++++ + 3 files changed, 9 insertions(+), 1 deletion(-) + +diff --git a/src/unexpand.c b/src/unexpand.c +index 3cbff1b129..c859c17a3e 100644 +--- a/src/unexpand.c ++++ b/src/unexpand.c +@@ -131,7 +131,7 @@ unexpand (void) + /* The worst case is a non-blank character, then one blank, then a + tab stop, then MAX_COLUMN_WIDTH - 1 blanks, then a non-blank; so + allocate MAX_COLUMN_WIDTH bytes to store the blanks. */ +- pending_blank = ximalloc (max_column_width * sizeof (char) * MB_LEN_MAX); ++ pending_blank = xinmalloc (max_column_width, MB_CUR_MAX); + + while (true) + { +diff --git a/tests/unexpand/mb.sh b/tests/unexpand/mb.sh +index 76a2679035..076a1c1ae5 100755 +--- a/tests/unexpand/mb.sh ++++ b/tests/unexpand/mb.sh +@@ -17,6 +17,7 @@ + + . "${srcdir=.}/tests/init.sh"; path_prepend_ ./src + print_ver_ unexpand printf ++getlimits_ + + test "$LOCALE_FR_UTF8" != none || skip_ "French UTF-8 locale not available" + export LC_ALL="$LOCALE_FR_UTF8" +@@ -161,4 +162,11 @@ EOF + unexpand -a ./in ./in > out || fail=1 + compare exp out > /dev/null 2>&1 || fail=1 + ++# Ensure overflow is handed gracefully ++# coreutils v9.11 induced a buffer overflow with mb_mul=4 (or 16). ++for mb_mul in 4 6; do ++ printf ' \n' | unexpand -t $(expr $SIZE_MAX / $mb_mul + 1) 2>err; ret=$? ++ test "$ret" = 1 || test "$ret" = 0 || { cat err; fail=1; } ++done ++ + Exit $fail diff --git a/pkgs/tools/misc/coreutils/default.nix b/pkgs/tools/misc/coreutils/default.nix index 639f10ab32e0..778bd11c0440 100644 --- a/pkgs/tools/misc/coreutils/default.nix +++ b/pkgs/tools/misc/coreutils/default.nix @@ -52,6 +52,11 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-OUAk7aCllVIXztqc0SAeZdyPo6opwpURNaSVIdV8PMM="; }; + patches = [ + ./CVE-2026-56391.patch + ./CVE-2026-56392.patch + ]; + postPatch = '' # The test tends to fail on btrfs, f2fs and maybe other unusual filesystems. sed '2i echo Skipping dd sparse test && exit 77' -i ./tests/dd/sparse.sh From 862cf2c919fb4597914cafbe15265defb8857852 Mon Sep 17 00:00:00 2001 From: Ethan Carter Edwards Date: Sun, 26 Jul 2026 16:20:26 -0400 Subject: [PATCH 109/175] qdl: modernize Signed-off-by: Ethan Carter Edwards --- pkgs/by-name/qd/qdl/package.nix | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/pkgs/by-name/qd/qdl/package.nix b/pkgs/by-name/qd/qdl/package.nix index bea86693c187..84d97af3948b 100644 --- a/pkgs/by-name/qd/qdl/package.nix +++ b/pkgs/by-name/qd/qdl/package.nix @@ -10,6 +10,7 @@ libzip, cmocka, ninja, + versionCheckHook, nix-update-script, }: @@ -17,6 +18,9 @@ stdenv.mkDerivation (finalAttrs: { pname = "qdl"; version = "2.7.1"; + __structuredAttrs = true; + strictDeps = true; + src = fetchFromGitHub { owner = "linux-msm"; repo = "qdl"; @@ -56,6 +60,9 @@ stdenv.mkDerivation (finalAttrs: { enableParallelBuilding = true; + nativeInstallCheckInputs = [ versionCheckHook ]; + doInstallCheck = true; + passthru.updateScript = nix-update-script { }; meta = { From 2349def73196e4c2470a5866df3e6907a06a568f Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sun, 26 Jul 2026 21:20:29 +0000 Subject: [PATCH 110/175] catch2_3: 3.15.2 -> 3.15.3 --- pkgs/by-name/ca/catch2_3/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ca/catch2_3/package.nix b/pkgs/by-name/ca/catch2_3/package.nix index a00e75d4a29f..381fead86e88 100644 --- a/pkgs/by-name/ca/catch2_3/package.nix +++ b/pkgs/by-name/ca/catch2_3/package.nix @@ -9,13 +9,13 @@ stdenv.mkDerivation rec { pname = "catch2"; - version = "3.15.2"; + version = "3.15.3"; src = fetchFromGitHub { owner = "catchorg"; repo = "Catch2"; tag = "v${version}"; - hash = "sha256-Fb8dnuaKQwLxYmGDZy38ZsCKk6RwE4PSidD1xmnb1rU="; + hash = "sha256-ZuH3tUWNklq0bKp0Yu9w3L5FNsQwUxe6lyGBv4M6U1E="; }; patches = lib.optionals stdenv.cc.isClang [ From d5b6cbf90ba4855f853151482127eea8b9cfa3c8 Mon Sep 17 00:00:00 2001 From: Randy Eckenrode Date: Sun, 26 Jul 2026 11:49:46 -0400 Subject: [PATCH 111/175] llvmPackages_{18,19,20,21}.compiler-rt: backport santizier fix for Linux Linux dropped `linux/scc.h` from Linux 7.1, which breaks building compiler-rt when sanitizers enabled. Upstream fixed this for LLVM 23. This PR cherry-picks the fix for the other LLVM packages in Nixpkgs. --- .../compilers/llvm/common/compiler-rt/default.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/pkgs/development/compilers/llvm/common/compiler-rt/default.nix b/pkgs/development/compilers/llvm/common/compiler-rt/default.nix index 12e989a2b0d5..1967905462da 100644 --- a/pkgs/development/compilers/llvm/common/compiler-rt/default.nix +++ b/pkgs/development/compilers/llvm/common/compiler-rt/default.nix @@ -107,6 +107,12 @@ stdenv.mkDerivation (finalAttrs: { url = "https://github.com/llvm/llvm-project/commit/59978b21ad9c65276ee8e14f26759691b8a65763.patch"; hash = "sha256-ys5SMLfO3Ay9nCX9GV5yRCQ6pLsseFu/ZY6Xd6OL4p0="; relative = "compiler-rt"; + }) + # Linux removed `linux/scc.h`, which breaks building compiler-rt. Upstream LLVM has fixed it in LLVM 22 and 23. + ++ lib.optional (lib.strings.versionOlder (lib.versions.major release_version) "22") (fetchpatch { + url = "https://github.com/llvm/llvm-project/commit/3dc4fd6dd41100f051a63642f449b16324389c96.patch?full_index=1"; + hash = "sha256-Av6CN95XjdUagIKh3AAjD0UK8r01fDz0cD0BLjZ70dg="; + relative = "compiler-rt"; }); nativeBuildInputs = [ From 465aa74425d28f11bcc285a0c45d078c38331639 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Sun, 26 Jul 2026 21:45:28 -0700 Subject: [PATCH 112/175] imagemagick: 7.1.2-27 -> 7.1.2-28 Diff: https://github.com/ImageMagick/ImageMagick/compare/7.1.2-27...7.1.2-28 Changelog: https://github.com/ImageMagick/Website/blob/main/docs/changelog/index.md --- pkgs/by-name/im/imagemagick/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/im/imagemagick/package.nix b/pkgs/by-name/im/imagemagick/package.nix index 918d97c640fa..742d5ac06493 100644 --- a/pkgs/by-name/im/imagemagick/package.nix +++ b/pkgs/by-name/im/imagemagick/package.nix @@ -89,13 +89,13 @@ in stdenv.mkDerivation (finalAttrs: { pname = "imagemagick"; - version = "7.1.2-27"; + version = "7.1.2-28"; src = fetchFromGitHub { owner = "ImageMagick"; repo = "ImageMagick"; tag = finalAttrs.version; - hash = "sha256-QCC2CO2zkhwlEWymwF739uSNuS7QCqqGIJnF/LtYzVc="; + hash = "sha256-CO1FZJy3rAoyw8WSmXIzmTIjC3iHJc5JxmSNCVZ3TPo="; }; outputs = [ From 6b15470f3c7de5ff88a4ef68a3e44926b27ee2c1 Mon Sep 17 00:00:00 2001 From: Grimmauld Date: Mon, 27 Jul 2026 13:52:12 +0200 Subject: [PATCH 113/175] libcap_ng: enable structuredAttrs --- pkgs/by-name/li/libcap_ng/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/li/libcap_ng/package.nix b/pkgs/by-name/li/libcap_ng/package.nix index 60fc8e308c1c..fd7a59d34cd5 100644 --- a/pkgs/by-name/li/libcap_ng/package.nix +++ b/pkgs/by-name/li/libcap_ng/package.nix @@ -28,6 +28,7 @@ stdenv.mkDerivation (finalAttrs: { ''; strictDeps = true; + __structuredAttrs = true; enableParallelBuilding = true; nativeBuildInputs = [ From a7bd1086d028c0523e9eddb22c26331538162fc8 Mon Sep 17 00:00:00 2001 From: Grimmauld Date: Mon, 27 Jul 2026 13:46:36 +0200 Subject: [PATCH 114/175] libcap_ng: support building python bindings --- pkgs/by-name/li/libcap_ng/package.nix | 28 ++++++++++++++++++++++++++- 1 file changed, 27 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/li/libcap_ng/package.nix b/pkgs/by-name/li/libcap_ng/package.nix index fd7a59d34cd5..17dd86606054 100644 --- a/pkgs/by-name/li/libcap_ng/package.nix +++ b/pkgs/by-name/li/libcap_ng/package.nix @@ -7,6 +7,9 @@ swig, testers, nix-update-script, + linuxHeaders, + python3Packages, + withPython ? false, }: stdenv.mkDerivation (finalAttrs: { @@ -35,6 +38,17 @@ stdenv.mkDerivation (finalAttrs: { autoreconfHook pkg-config swig + ] + ++ lib.optionals withPython [ + python3Packages.python # m4 + ]; + + buildInputs = lib.optionals withPython [ + python3Packages.python + ]; + + nativeCheckInputs = lib.optionals withPython [ + python3Packages.pythonImportsCheckHook ]; outputs = [ @@ -44,7 +58,8 @@ stdenv.mkDerivation (finalAttrs: { ]; configureFlags = [ - "--without-python" + (lib.withFeature withPython "python") + "--with-capability_header='${linuxHeaders}/include/linux/capability.h'" # required to link bindings ]; passthru = { @@ -58,7 +73,18 @@ stdenv.mkDerivation (finalAttrs: { # see https://github.com/stevegrubb/libcap-ng?tab=readme-ov-file#note-to-distributions doCheck = true; + pythonImportsCheck = [ + "capng" + ]; + + preCheck = '' + patchShebangs bindings/test bindings/python3/test + ''; + meta = { + broken = + # m4 python include script fails if cpu bit depth is different across build/host architectures + withPython && (stdenv.hostPlatform.parsed.cpu.bits != stdenv.buildPlatform.parsed.cpu.bits); changelog = "https://people.redhat.com/sgrubb/libcap-ng/ChangeLog"; description = "Library for working with POSIX capabilities"; homepage = "https://people.redhat.com/sgrubb/libcap-ng/"; From 6432c4c6cc163a4bb8d8b314c01ccaef2133ff93 Mon Sep 17 00:00:00 2001 From: Grimmauld Date: Mon, 27 Jul 2026 13:47:22 +0200 Subject: [PATCH 115/175] python3Packages.libcap_ng: init at 0.9.3 --- pkgs/by-name/li/libcap_ng/package.nix | 1 + pkgs/top-level/python-packages.nix | 13 +++++++++++++ 2 files changed, 14 insertions(+) diff --git a/pkgs/by-name/li/libcap_ng/package.nix b/pkgs/by-name/li/libcap_ng/package.nix index 17dd86606054..e0935f44c6dc 100644 --- a/pkgs/by-name/li/libcap_ng/package.nix +++ b/pkgs/by-name/li/libcap_ng/package.nix @@ -66,6 +66,7 @@ stdenv.mkDerivation (finalAttrs: { updateScript = nix-update-script { }; tests = { pkg-config = testers.testMetaPkgConfig finalAttrs.finalPackage; + python = python3Packages.libcap_ng; }; }; diff --git a/pkgs/top-level/python-packages.nix b/pkgs/top-level/python-packages.nix index 2b5a87b09493..5749cb1f22d1 100644 --- a/pkgs/top-level/python-packages.nix +++ b/pkgs/top-level/python-packages.nix @@ -9210,6 +9210,19 @@ self: super: with self; { libbs = callPackage ../development/python-modules/libbs { }; + libcap_ng = callPackage ( + { + python, + pythonImportsCheckHook, + }@python3Packages: + toPythonModule ( + pkgs.libcap_ng.override { + withPython = true; + inherit python3Packages; + } + ) + ) { }; + libcloud = callPackage ../development/python-modules/libcloud { }; libcomps = lib.pipe pkgs.libcomps [ From 2cd3018868fd4766b709b5b65c1c18adbf06076d Mon Sep 17 00:00:00 2001 From: Gerhard Schwanzer Date: Mon, 27 Jul 2026 16:21:55 +0200 Subject: [PATCH 116/175] python3Packages.datamodel-code-generator: 0.68.1 -> 0.71.0 Update to the latest stable release, which rejects unsafe customBasePath values before generating Python imports. https://redirect.github.com/koxudaxi/datamodel-code-generator/releases/tag/0.71.0 Assisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol) --- .../python-modules/datamodel-code-generator/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/datamodel-code-generator/default.nix b/pkgs/development/python-modules/datamodel-code-generator/default.nix index f7d11b92ee19..e542fbc0acbb 100644 --- a/pkgs/development/python-modules/datamodel-code-generator/default.nix +++ b/pkgs/development/python-modules/datamodel-code-generator/default.nix @@ -36,14 +36,14 @@ buildPythonPackage rec { pname = "datamodel-code-generator"; - version = "0.68.1"; + version = "0.71.0"; pyproject = true; src = fetchFromGitHub { owner = "koxudaxi"; repo = "datamodel-code-generator"; tag = version; - hash = "sha256-fYnI7S4FJ927qZXyAsWQzxhLTrcpscYqJunmcSt/gkk="; + hash = "sha256-0vh/iynZzmMzvdUXNScb+JWANdSrzPLT1qt+jyKleg4="; }; pythonRelaxDeps = [ From afcf24882de58fbc28111b71c13d5a5ae5deeccf Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Mon, 27 Jul 2026 15:05:31 +0000 Subject: [PATCH 117/175] shogihome: 1.28.0 -> 1.28.1 --- pkgs/by-name/sh/shogihome/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/sh/shogihome/package.nix b/pkgs/by-name/sh/shogihome/package.nix index f3a90eb4da32..99d5fca47885 100644 --- a/pkgs/by-name/sh/shogihome/package.nix +++ b/pkgs/by-name/sh/shogihome/package.nix @@ -22,16 +22,16 @@ let in buildNpmPackage (finalAttrs: { pname = "shogihome"; - version = "1.28.0"; + version = "1.28.1"; src = fetchFromGitHub { owner = "sunfish-shogi"; repo = "shogihome"; tag = "v${finalAttrs.version}"; - hash = "sha256-icFWpyfdnm0wIkTVa2ijcnBcDmxrutV38vN3/8AY4cg="; + hash = "sha256-En2tH9AFBdhZsHoy/uiHf4RO3+gFkfwHnZAyDJ7FcoE="; }; - npmDepsHash = "sha256-SSpw8bBbf6saWwR3ZpqMrbrdjDJTCeARBAlHO65O+Zc="; + npmDepsHash = "sha256-9O/PQAGv0xg6dKgFHjErYTnaM2PxyUIZk8auiReSo2Q="; postPatch = '' substituteInPlace package.json \ From faf17b1ac0e1b5592dabdacb333201f252688b14 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Mon, 27 Jul 2026 12:17:09 -0700 Subject: [PATCH 118/175] imagemagick: 7.1.2-28 -> 7.1.2-29 Diff: https://github.com/ImageMagick/ImageMagick/compare/7.1.2-28...7.1.2-29 Changelog: https://github.com/ImageMagick/Website/blob/main/docs/changelog/index.md --- pkgs/by-name/im/imagemagick/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/im/imagemagick/package.nix b/pkgs/by-name/im/imagemagick/package.nix index 742d5ac06493..498a8d8327c5 100644 --- a/pkgs/by-name/im/imagemagick/package.nix +++ b/pkgs/by-name/im/imagemagick/package.nix @@ -89,13 +89,13 @@ in stdenv.mkDerivation (finalAttrs: { pname = "imagemagick"; - version = "7.1.2-28"; + version = "7.1.2-29"; src = fetchFromGitHub { owner = "ImageMagick"; repo = "ImageMagick"; tag = finalAttrs.version; - hash = "sha256-CO1FZJy3rAoyw8WSmXIzmTIjC3iHJc5JxmSNCVZ3TPo="; + hash = "sha256-gVp6eAXLl11KhtcpZ4hPeurCRHtRhhrAggJi7PatQ+M="; }; outputs = [ From 761e0ecefb74895fb72f55b1efc4388eb2a03b3c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Robert=20Sch=C3=BCtz?= Date: Mon, 27 Jul 2026 12:37:41 -0700 Subject: [PATCH 119/175] python3Packages.pyturbojpeg: 2.4.0 -> 2.5.0 Diff: https://github.com/lilohuang/PyTurboJPEG/compare/v2.4.0...v2.5.0 Changelog: https://github.com/lilohuang/PyTurboJPEG/releases/tag/v2.5.0 --- pkgs/development/python-modules/pyturbojpeg/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/pyturbojpeg/default.nix b/pkgs/development/python-modules/pyturbojpeg/default.nix index 6845b412256f..eefb5318b3e0 100644 --- a/pkgs/development/python-modules/pyturbojpeg/default.nix +++ b/pkgs/development/python-modules/pyturbojpeg/default.nix @@ -13,14 +13,14 @@ buildPythonPackage (finalAttrs: { pname = "pyturbojpeg"; - version = "2.4.0"; + version = "2.5.0"; pyproject = true; src = fetchFromGitHub { owner = "lilohuang"; repo = "PyTurboJPEG"; tag = "v${finalAttrs.version}"; - hash = "sha256-LgUPcRBRjqKhg0SLaZiRG8/QoJxShSvAAmQsuHwfoZM="; + hash = "sha256-sZB0BzgrA0I3GHtu5Z6cWpMQcE5Lqkvwix0ztbrWj3g="; }; patches = [ From 85a7c427304f92ae549192d17e069e4e5bebbec2 Mon Sep 17 00:00:00 2001 From: K900 Date: Wed, 29 Jul 2026 14:43:35 +0300 Subject: [PATCH 120/175] net-snmp: import Debian patch to fix link error --- pkgs/by-name/ne/net-snmp/link-error.patch | 17 +++++++++++++++++ pkgs/by-name/ne/net-snmp/package.nix | 5 +++++ 2 files changed, 22 insertions(+) create mode 100644 pkgs/by-name/ne/net-snmp/link-error.patch diff --git a/pkgs/by-name/ne/net-snmp/link-error.patch b/pkgs/by-name/ne/net-snmp/link-error.patch new file mode 100644 index 000000000000..a8a00193b9a8 --- /dev/null +++ b/pkgs/by-name/ne/net-snmp/link-error.patch @@ -0,0 +1,17 @@ +Description: Add libnetsnmpaget link to libnetsnmptrapd + Causes a linking issue otherwise +Author: Craig Small +Reviewed-by: Craig Small +Last-Update: 2023-08-19 +--- +--- a/apps/Makefile.in ++++ b/apps/Makefile.in +@@ -237,7 +237,7 @@ + $(LINK) ${CFLAGS} -o $@ snmppcap.$(OSUFFIX) ${LDFLAGS} ${USEAGENTLIBS} ${LIBS} -lpcap + + libnetsnmptrapd.$(LIB_EXTENSION)$(LIB_VERSION): $(LLIBTRAPD_OBJS) +- $(LIB_LD_CMD) $@ ${LLIBTRAPD_OBJS} $(MIBLIB) $(MYSQL_LIBS) $(USELIBS) $(PERLLDOPTS_FOR_LIBS) $(LDFLAGS) ++ $(LIB_LD_CMD) $@ ${LLIBTRAPD_OBJS} $(MIBLIB) $(MYSQL_LIBS) $(USELIBS) $(USEAGENTLIBS) $(PERLLDOPTS_FOR_LIBS) $(LDFLAGS) + $(RANLIB) $@ + + snmpinforminstall: diff --git a/pkgs/by-name/ne/net-snmp/package.nix b/pkgs/by-name/ne/net-snmp/package.nix index 0022ccdb2050..dba3135a0ed1 100644 --- a/pkgs/by-name/ne/net-snmp/package.nix +++ b/pkgs/by-name/ne/net-snmp/package.nix @@ -29,6 +29,11 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-FnB3GfgzGEpLcoNdrDWa4YgSOwa15CgXwAeQ19wThL8="; }; + patches = [ + # https://salsa.debian.org/debian/net-snmp/-/blob/master/debian/patches/makefile_trap_needs_agent, vendored because of Anubis + ./link-error.patch + ]; + outputs = [ "bin" "out" From f9ebb12ba5b065834901a50493e5ff462e5d4da8 Mon Sep 17 00:00:00 2001 From: Antoine du Hamel Date: Wed, 29 Jul 2026 20:35:45 +0200 Subject: [PATCH 121/175] nodejs_24: 24.18.0 -> 24.18.1 --- pkgs/development/web/nodejs/v24.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/web/nodejs/v24.nix b/pkgs/development/web/nodejs/v24.nix index 3388b484ebe8..262990f1826e 100644 --- a/pkgs/development/web/nodejs/v24.nix +++ b/pkgs/development/web/nodejs/v24.nix @@ -29,8 +29,8 @@ let [ ]; in buildNodejs { - version = "24.18.0"; - sha256 = "e94afde24db08e0c564ee7110a2d5aab51ee0059382c9fd8233c54eec47b28f9"; + version = "24.18.1"; + sha256 = "86d40d594bbdfcf69009a62fdf43cb19ae72b6cb5822d2bdd8349c5a1b2fa628"; patches = ( if (stdenv.hostPlatform.emulatorAvailable buildPackages) then From 4e34283c2ebaf906175a08b8595bd82881940d1b Mon Sep 17 00:00:00 2001 From: Tom Hunze Date: Wed, 29 Jul 2026 00:38:27 +0200 Subject: [PATCH 122/175] gcc13: fix build with linux 7.1 headers Linux 7.1 removed `linux/scc.h`. For GCC 14 and higher, there have already been releases with the fix. Hydra: https://hydra.nixos.org/build/339623513 --- pkgs/development/compilers/gcc/patches/default.nix | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/pkgs/development/compilers/gcc/patches/default.nix b/pkgs/development/compilers/gcc/patches/default.nix index 02bf294db332..c9ff40d8de57 100644 --- a/pkgs/development/compilers/gcc/patches/default.nix +++ b/pkgs/development/compilers/gcc/patches/default.nix @@ -108,6 +108,18 @@ optionals noSysDirs ( ## 2. Patches relevant on specific platforms #################################### +## Linux + +# Linux 7.1 removed `linux/scc.h`. +# For GCC 14 and higher, there have already been releases with the fix. +++ optional (is13 && targetPlatform.isLinux) (fetchpatch { + name = "libsanitizer-fix-with-linux-7.1-headers.patch"; + url = "https://github.com/llvm/llvm-project/commit/3dc4fd6dd41100f051a63642f449b16324389c96.patch"; + relative = "compiler-rt/lib"; + extraPrefix = "libsanitizer/"; + hash = "sha256-UYekGGOkYdBNJEp48QFPFadf3wPFJZL2t3D+iwUeGJA="; +}) + ## Darwin # Here we apply patches by Iains (https://github.com/iains) From 693e3bc4155787b03d2e36523b43da32b268305c Mon Sep 17 00:00:00 2001 From: whispers Date: Wed, 29 Jul 2026 15:55:04 -0400 Subject: [PATCH 123/175] nixos/systemd: patch to avoid update-utmp failure with audit 4.2 audit 4.2 rejects overlong values (max 15 bytes) for the kernel comm. systemd attempts to send the full 19 bytes of "systemd-update-utmp", and the systemd-update-utmp service fails to start. this was changed to truncate instead of reject in audit 4.2.1, but until we can take the mass rebuild on staging, we fetch the systemd patch which shortens "systemd-update-utmp" to "update-utmp". this is in the nixos module as `apply` instead of part of the systemd package as that would be a larger rebuild and would delay other fixes making their way to master. --- nixos/modules/system/boot/systemd.nix | 22 +++++++++++++++++++++- 1 file changed, 21 insertions(+), 1 deletion(-) diff --git a/nixos/modules/system/boot/systemd.nix b/nixos/modules/system/boot/systemd.nix index acfb213b98e0..10dd33eac8c2 100644 --- a/nixos/modules/system/boot/systemd.nix +++ b/nixos/modules/system/boot/systemd.nix @@ -259,7 +259,27 @@ in options.systemd = { - package = mkPackageOption pkgs "systemd" { }; + package = mkPackageOption pkgs "systemd" { } // { + # audit 4.2 rejects overlong values (max 15 bytes) for the kernel comm. + # systemd attempts to send the full 19 bytes of "systemd-update-utmp", + # and the systemd-update-utmp service fails to start. this patch shortens + # the kernel comm entry to "update-utmp". + # TODO: revert on staging when updating to audit 4.2.1 + # original commit: https://github.com/linux-audit/audit-userspace/commit/d7ea98263ebdb974b383a4057856a5ec339776fc + # switch to truncate: https://github.com/linux-audit/audit-userspace/commit/d7ea98263ebdb974b383a4057856a5ec339776fc + # systemd pr: https://github.com/systemd/systemd/pull/43144 + apply = + pkg: + pkg.overrideAttrs (prevAttrs: { + patches = prevAttrs.patches or [ ] ++ [ + (pkgs.fetchpatch { + name = "systemd-update-utmp-shorten-comm.patch"; + url = "https://github.com/systemd/systemd/commit/b8968c492108506952ab2748c4a44ce32fc9477c.patch"; + hash = "sha256-d0rMssj1+cDw3+KOk8ecjqIIuBhjDixIH+7MJfC+I+M="; + }) + ]; + }); + }; enableStrictShellChecks = mkEnableOption "" // { description = '' From 7134f7833162492b54ded68294b7305fad28ca65 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 30 Jul 2026 04:08:58 +0000 Subject: [PATCH 124/175] snip: 0.22.0 -> 0.24.1 --- pkgs/by-name/sn/snip/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/sn/snip/package.nix b/pkgs/by-name/sn/snip/package.nix index f890bd12d9f1..7b67e08b6572 100644 --- a/pkgs/by-name/sn/snip/package.nix +++ b/pkgs/by-name/sn/snip/package.nix @@ -7,13 +7,13 @@ buildGoModule (finalAttrs: { pname = "snip"; - version = "0.22.0"; + version = "0.24.1"; src = fetchFromGitHub { owner = "edouard-claude"; repo = "snip"; tag = "v${finalAttrs.version}"; - hash = "sha256-y88ZHg29Z/QBZk8YWXp287Rel7DpPESYAlbqt5hj1nc="; + hash = "sha256-17vAgwuOrDN81+XKa2vn60T9RyZktOoF2xfF/RE+BNw="; }; vendorHash = "sha256-2MxFZqjNuLzcuu+bsLyOyHIakCxh7j0FUx8LsjZRhrY="; From 81d18adeab0ac68d5095d8516632e934cea6044f Mon Sep 17 00:00:00 2001 From: Oleksii Filonenko Date: Thu, 30 Jul 2026 15:46:03 +0000 Subject: [PATCH 125/175] hk: 1.51.0 -> 1.53.0 --- pkgs/by-name/hk/hk/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/hk/hk/package.nix b/pkgs/by-name/hk/hk/package.nix index f0d97b585f7d..8f299b7757a3 100644 --- a/pkgs/by-name/hk/hk/package.nix +++ b/pkgs/by-name/hk/hk/package.nix @@ -15,7 +15,7 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "hk"; - version = "1.51.0"; + version = "1.53.0"; __structuredAttrs = true; @@ -23,10 +23,10 @@ rustPlatform.buildRustPackage (finalAttrs: { owner = "jdx"; repo = "hk"; tag = "v${finalAttrs.version}"; - hash = "sha256-kCmujjvh2CACLrzqFal1CFc7RMzECBYsQ4W3ZnJGRV0="; + hash = "sha256-O9D5gpkLEiA7yotDehsCu6qdYKBaUCmGZjVPETiZXzA="; }; - cargoHash = "sha256-hICexfvE0swz+g/9r/vR/sG2DUAK5Fj0lDTrkuWujok="; + cargoHash = "sha256-4y4wg24yN9lTZvg4SgTZcYSVwIaPowTJ4jj3P09FHjE="; nativeBuildInputs = [ installShellFiles From c55edd53fb8bb13b3f166e021ed1a3cf341e350f Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 30 Jul 2026 16:43:13 +0000 Subject: [PATCH 126/175] python3Packages.environ-config: 24.1.0 -> 26.1.0 --- pkgs/development/python-modules/environ-config/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/environ-config/default.nix b/pkgs/development/python-modules/environ-config/default.nix index 06e82efea86c..ff5975aba463 100644 --- a/pkgs/development/python-modules/environ-config/default.nix +++ b/pkgs/development/python-modules/environ-config/default.nix @@ -12,14 +12,14 @@ }: buildPythonPackage rec { pname = "environ-config"; - version = "24.1.0"; + version = "26.1.0"; pyproject = true; src = fetchFromGitHub { repo = "environ-config"; owner = "hynek"; tag = version; - hash = "sha256-XiJNLQgKhf9hXQfIMsfiEaHx7IHaExhphpYfOBgIT+s="; + hash = "sha256-baj61mS4rSLMngrAdmSwupN/2ewo/GDwbZqFTr8fVuE="; }; build-system = [ From 99b0a7f2fadefd2d961db918bf5fd42ab604d457 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 30 Jul 2026 16:57:05 +0000 Subject: [PATCH 127/175] stevenblack-blocklist: 3.16.99 -> 3.16.102 --- pkgs/by-name/st/stevenblack-blocklist/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/st/stevenblack-blocklist/package.nix b/pkgs/by-name/st/stevenblack-blocklist/package.nix index 3dc5aeebce6e..d70d9763d26e 100644 --- a/pkgs/by-name/st/stevenblack-blocklist/package.nix +++ b/pkgs/by-name/st/stevenblack-blocklist/package.nix @@ -6,13 +6,13 @@ }: stdenvNoCC.mkDerivation (finalAttrs: { pname = "stevenblack-blocklist"; - version = "3.16.99"; + version = "3.16.102"; src = fetchFromGitHub { owner = "StevenBlack"; repo = "hosts"; tag = finalAttrs.version; - hash = "sha256-IZaEcG/u1zgJBxXc2Dyx0gxzpnmWQQ5NUyOrDBLiOXk="; + hash = "sha256-TzFQ0aOcIgdNHD7pmrMkdcv+V9ZNzqXnSOm4wBaLtwI="; }; outputs = [ From 8db7f5701d9078fc48d93bd44784bbac42ddd37b Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 30 Jul 2026 18:39:03 +0000 Subject: [PATCH 128/175] dgraph: 25.3.8 -> 25.4.0 --- pkgs/by-name/dg/dgraph/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/dg/dgraph/package.nix b/pkgs/by-name/dg/dgraph/package.nix index b2f4a1100b9c..e6eab01aa6f6 100644 --- a/pkgs/by-name/dg/dgraph/package.nix +++ b/pkgs/by-name/dg/dgraph/package.nix @@ -9,16 +9,16 @@ buildGoModule (finalAttrs: { pname = "dgraph"; - version = "25.3.8"; + version = "25.4.0"; src = fetchFromGitHub { owner = "dgraph-io"; repo = "dgraph"; tag = "v${finalAttrs.version}"; - hash = "sha256-RrOlJVkekZ3xWGtjc013YyCycJmlPowVzqrttnZD8BI="; + hash = "sha256-77uhpDyQhAbeQVGbAB2ZX1YATA5qAk8l5Y7PWhoJm9E="; }; - vendorHash = "sha256-gD91KGWLqd6a7YkqQSeW1eS2MQI+1/RbI5X1/Xwrz90="; + vendorHash = "sha256-Kr4qeoLsqK7qV7OMAvaY7fbzsxaP6bm9bdUZlmQYAug="; doCheck = false; From 5fe0cfac84303a20cf486f88f6b42de90e76bd5e Mon Sep 17 00:00:00 2001 From: oeilvert Date: Fri, 31 Jul 2026 03:44:59 +0900 Subject: [PATCH 129/175] nixos/librechat: fix undefined cfg.port in openFirewall option The openFirewall option referenced the non-existent cfg.port, causing evaluation to fail with an 'attribute port missing' error whenever it was set to true. Use cfg.env.PORT instead, which is where the actual listen port is stored. Assisted-by: Claude (Sonnet 5) --- nixos/modules/services/web-apps/librechat.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/nixos/modules/services/web-apps/librechat.nix b/nixos/modules/services/web-apps/librechat.nix index 932f81404af3..87dbb08823c9 100644 --- a/nixos/modules/services/web-apps/librechat.nix +++ b/nixos/modules/services/web-apps/librechat.nix @@ -218,7 +218,7 @@ in } ]; - networking.firewall.allowedTCPPorts = lib.optional cfg.openFirewall cfg.port; + networking.firewall.allowedTCPPorts = lib.optional cfg.openFirewall (lib.toInt cfg.env.PORT); systemd.tmpfiles.settings."10-librechat"."${cfg.dataDir}".d = { mode = "0755"; From e582e42fe8f9e4ad6e09cbe202bc958f06dfbd20 Mon Sep 17 00:00:00 2001 From: kilianar Date: Fri, 31 Jul 2026 08:03:36 +0200 Subject: [PATCH 130/175] portfolio: 0.86.0 -> 0.86.1 https://github.com/portfolio-performance/portfolio/releases/tag/0.86.1 --- pkgs/by-name/po/portfolio/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/po/portfolio/package.nix b/pkgs/by-name/po/portfolio/package.nix index a6f456284a49..21dcea6107ca 100644 --- a/pkgs/by-name/po/portfolio/package.nix +++ b/pkgs/by-name/po/portfolio/package.nix @@ -48,11 +48,11 @@ let in stdenvNoCC.mkDerivation (finalAttrs: { pname = "PortfolioPerformance"; - version = "0.86.0"; + version = "0.86.1"; src = fetchurl { url = "https://github.com/buchen/portfolio/releases/download/${finalAttrs.version}/PortfolioPerformance-${finalAttrs.version}-linux.gtk.x86_64.tar.gz"; - hash = "sha256-7qSWHlHKIzqHO5iCbi+y0+u7OoIC9tUYL1e0mpAHAWM="; + hash = "sha256-iTHtIuSVapNc5ZckIIfDXYpMP2PiYLV8JojuqQ9nl9E="; }; nativeBuildInputs = [ From 7410277e3a18e3da04aed3122ee3254f5747dc8a Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 31 Jul 2026 06:36:05 +0000 Subject: [PATCH 131/175] vscode-extensions.charliermarsh.ruff: 2026.62.0 -> 2026.68.0 --- .../vscode/extensions/charliermarsh.ruff/default.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/applications/editors/vscode/extensions/charliermarsh.ruff/default.nix b/pkgs/applications/editors/vscode/extensions/charliermarsh.ruff/default.nix index 80c7a5e9e731..df082efe8b47 100644 --- a/pkgs/applications/editors/vscode/extensions/charliermarsh.ruff/default.nix +++ b/pkgs/applications/editors/vscode/extensions/charliermarsh.ruff/default.nix @@ -12,22 +12,22 @@ vscode-utils.buildVscodeMarketplaceExtension { sources = { "x86_64-linux" = { arch = "linux-x64"; - hash = "sha256-YB+PtOdmsNfDuWl1U5g2HxnaXTmWBOnInVwoAcc2rwk="; + hash = "sha256-aEcYKsmZstFbSNybBLwtsrQu2P3cXeUSx+bb/fX52p4="; }; "aarch64-linux" = { arch = "linux-arm64"; - hash = "sha256-K6KjMMJHqwTlwHZuINHSSXG5R99b8w4SRkXcCBtf0d4="; + hash = "sha256-2B9jbLjYp2Dj+cqECeX7gCfB34Yoy8o3jTdzLd7ZLbc="; }; "aarch64-darwin" = { arch = "darwin-arm64"; - hash = "sha256-D7bHjKOvaJj98vuPW53kHieGYIXOLft4OkpuG0AX9Rc="; + hash = "sha256-TGX0gaKZcvEWYz+Z/1tVTaE+6xbcTRR+Tb7JHVSAXkc="; }; }; in { name = "ruff"; publisher = "charliermarsh"; - version = "2026.62.0"; + version = "2026.68.0"; } // sources.${stdenvNoCC.hostPlatform.system} or (throw "Unsupported system ${stdenvNoCC.hostPlatform.system}"); From 534556a807ea66566a8e93dd4b839de600d9a776 Mon Sep 17 00:00:00 2001 From: Grimmauld Date: Fri, 31 Jul 2026 08:49:35 +0200 Subject: [PATCH 132/175] python3Packages.libcap_ng: fix passthru.tests.python reported in https://github.com/NixOS/nixpkgs/pull/546283#issuecomment-5135118615 --- pkgs/top-level/python-packages.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/top-level/python-packages.nix b/pkgs/top-level/python-packages.nix index 4fe892cb7ea8..b4e88c3d9b3c 100644 --- a/pkgs/top-level/python-packages.nix +++ b/pkgs/top-level/python-packages.nix @@ -9216,6 +9216,7 @@ self: super: with self; { { python, pythonImportsCheckHook, + libcap_ng, # for python3Packages.libcap_ng.tests.python passthru }@python3Packages: toPythonModule ( pkgs.libcap_ng.override { From d0995d75555efd115cbf539a1107129742050b56 Mon Sep 17 00:00:00 2001 From: tea Date: Fri, 31 Jul 2026 10:36:57 +0200 Subject: [PATCH 133/175] cosmic-monitor: enable GPU monitoring --- pkgs/by-name/co/cosmic-monitor/package.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/by-name/co/cosmic-monitor/package.nix b/pkgs/by-name/co/cosmic-monitor/package.nix index 5606bf8d0da3..120673e3306b 100644 --- a/pkgs/by-name/co/cosmic-monitor/package.nix +++ b/pkgs/by-name/co/cosmic-monitor/package.nix @@ -5,6 +5,7 @@ fetchFromGitHub, just, libcosmicAppHook, + autoAddDriverRunpath, nixosTests, nix-update-script, }: @@ -30,6 +31,7 @@ rustPlatform.buildRustPackage (finalAttrs: { just libcosmicAppHook rustPlatform.bindgenHook + autoAddDriverRunpath # for GPU monitoring ]; dontUseJustBuild = true; From 75568a3200c13e4edac864516dba4257df311dda Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Vladim=C3=ADr=20=C4=8Cun=C3=A1t?= Date: Fri, 31 Jul 2026 13:22:46 +0200 Subject: [PATCH 134/175] llvmPackages_22.compiler-rt: improve conditional precision In case of 22 the upstream commit is https://github.com/llvm/llvm-project/commit/9b722024f1be0a5238147ec28ae45f0990a853ac (which reaches tags 22.1.5+, by github.com UI) Practical issue solved by this is most pkgsRocm based on 22.0.0: https://hydra.nixos.org/build/339955996/nixlog/3/tail --- pkgs/development/compilers/llvm/common/compiler-rt/default.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/development/compilers/llvm/common/compiler-rt/default.nix b/pkgs/development/compilers/llvm/common/compiler-rt/default.nix index 1967905462da..567462e3eba6 100644 --- a/pkgs/development/compilers/llvm/common/compiler-rt/default.nix +++ b/pkgs/development/compilers/llvm/common/compiler-rt/default.nix @@ -109,7 +109,7 @@ stdenv.mkDerivation (finalAttrs: { relative = "compiler-rt"; }) # Linux removed `linux/scc.h`, which breaks building compiler-rt. Upstream LLVM has fixed it in LLVM 22 and 23. - ++ lib.optional (lib.strings.versionOlder (lib.versions.major release_version) "22") (fetchpatch { + ++ lib.optional (lib.strings.versionOlder version "22.1.5") (fetchpatch { url = "https://github.com/llvm/llvm-project/commit/3dc4fd6dd41100f051a63642f449b16324389c96.patch?full_index=1"; hash = "sha256-Av6CN95XjdUagIKh3AAjD0UK8r01fDz0cD0BLjZ70dg="; relative = "compiler-rt"; From 4e89bd7ccc506587d00451aaee1ba8f5423b73a3 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Vladim=C3=ADr=20=C4=8Cun=C3=A1t?= Date: Fri, 31 Jul 2026 13:36:38 +0200 Subject: [PATCH 135/175] libfaketime: fixup darwin build The patch only applies to the newer version. I really hope that darwin will be able to update soon-ish... --- pkgs/by-name/li/libfaketime/package.nix | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/pkgs/by-name/li/libfaketime/package.nix b/pkgs/by-name/li/libfaketime/package.nix index 7bbd192325aa..1e9667b83fba 100644 --- a/pkgs/by-name/li/libfaketime/package.nix +++ b/pkgs/by-name/li/libfaketime/package.nix @@ -34,7 +34,8 @@ stdenv.mkDerivation (finalAttrs: { patches = [ ./nix-store-date.patch - + ] + ++ lib.optionals (!stdenv.hostPlatform.isDarwin) [ # GCC 16's unused variable analysis is more advanced than previous # versions, and detects that these variables are unused. # https://github.com/wolfcw/libfaketime/pull/528 From 4145ba7dfde33bb693b7aee7e819e27517a235fa Mon Sep 17 00:00:00 2001 From: dramforever Date: Fri, 31 Jul 2026 19:41:00 +0800 Subject: [PATCH 136/175] nixos/ifstate: Fix systemd package references pkgs.systemd does not respect config.systemd.package and config.boot.initrd.systemd.package overrides. Fix references to the systemd package to ensure that the udevadm used is copied into the initrd. While we're at it, fix the non-initrd reference to systemd as well. --- nixos/modules/services/networking/ifstate.nix | 15 +++++++++------ 1 file changed, 9 insertions(+), 6 deletions(-) diff --git a/nixos/modules/services/networking/ifstate.nix b/nixos/modules/services/networking/ifstate.nix index ef44463ba9cf..a1aeeda26b8c 100644 --- a/nixos/modules/services/networking/ifstate.nix +++ b/nixos/modules/services/networking/ifstate.nix @@ -87,12 +87,6 @@ let "network.target" ]; - # We wait for the udev events queue to empty in the *hope* that the - # devices needed here become available. This is terribly broken and - # essentially no better than a random sleep(). - # FIXME: use .device units dependecies instead. - serviceConfig.ExecStartPre = "-${lib.getExe' pkgs.systemd "udevadm"} settle --timeout=180"; - unitConfig = { # Avoid default dependencies like "basic.target", which prevents ifstate from starting before luks is unlocked. DefaultDependencies = "no"; @@ -193,6 +187,13 @@ in ExecStart = "${lib.getExe cfg.package} --config ${ config.environment.etc."ifstate/ifstate.yaml".source } apply"; + + # We wait for the udev events queue to empty in the *hope* that the + # devices needed here become available. This is terribly broken and + # essentially no better than a random sleep(). Same below for initrd. + # FIXME: use .device units dependecies instead. + ExecStartPre = "-${lib.getExe' config.systemd.package "udevadm"} settle --timeout=180"; + # because oneshot services do not have a timeout by default TimeoutStartSec = "2min"; }; @@ -294,6 +295,8 @@ in } apply"; # because oneshot services do not have a timeout by default TimeoutStartSec = "2min"; + # See comment on non-initrd service above + ExecStartPre = "-${lib.getExe' config.boot.initrd.systemd.package "udevadm"} settle --timeout=180"; }; }; }; From 60be170a3a6693186e1472d594188147c2fa7dc1 Mon Sep 17 00:00:00 2001 From: dramforever Date: Fri, 31 Jul 2026 19:42:53 +0800 Subject: [PATCH 137/175] nixos/tests/predictable-interface-names: Fix systemd reference pkgs.systemd does not respect config.systemd.package and config.boot.initrd.systemd.package overrides. Fix references to the systemd package to ensure that the udevadm used is copied into the initrd. --- nixos/tests/predictable-interface-names.nix | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/nixos/tests/predictable-interface-names.nix b/nixos/tests/predictable-interface-names.nix index 6282c433bae7..f1f0f80fea0e 100644 --- a/nixos/tests/predictable-interface-names.nix +++ b/nixos/tests/predictable-interface-names.nix @@ -43,10 +43,15 @@ pkgs.lib.listToAttrs ( meta = { }; nodes.machine = - { pkgs, lib, ... }: + { + config, + pkgs, + lib, + ... + }: let script = '' - ${lib.getExe' pkgs.systemd "udevadm"} settle --timeout=180 + ${lib.getExe' config.boot.initrd.systemd.package "udevadm"} settle --timeout=180 ip link if ${lib.optionalString predictable "!"} ip link show eth0; then echo Success From 61847bbf3b5db147ff43e306e98ba52fec4bc53b Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 31 Jul 2026 12:36:58 +0000 Subject: [PATCH 138/175] wastebin: 3.7.0 -> 3.7.1 --- pkgs/by-name/wa/wastebin/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/wa/wastebin/package.nix b/pkgs/by-name/wa/wastebin/package.nix index f4b5d79b2eaf..5a58c2eaeae4 100644 --- a/pkgs/by-name/wa/wastebin/package.nix +++ b/pkgs/by-name/wa/wastebin/package.nix @@ -10,16 +10,16 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "wastebin"; - version = "3.7.0"; + version = "3.7.1"; src = fetchFromGitHub { owner = "matze"; repo = "wastebin"; rev = finalAttrs.version; - hash = "sha256-uWr2xJjWcm0WmOB6eD2pdzUch7HSk9KdHV31FoYHr0E="; + hash = "sha256-HwJlulSvhqBIrV3Dk/kpDj4+yEsX6gOA4kzWzpRPfbE="; }; - cargoHash = "sha256-m5cO3J4LryO+pS991DkS+4J6dw8ltP9sJR88FVGdsdw="; + cargoHash = "sha256-+p+EM5ggCpuEo/cEwjcdjJd8HahCwpn8QGdmRjJIijA="; nativeBuildInputs = [ pkg-config From 041d0576a2a5f27b294f44a215c885944298c856 Mon Sep 17 00:00:00 2001 From: Stzx Date: Fri, 31 Jul 2026 20:41:24 +0800 Subject: [PATCH 139/175] Revert "fluent-gtk-theme: remove" This reverts commit 1f5996fd40228f5958b40022af6dcc60a568ddd5. --- pkgs/by-name/fl/fluent-gtk-theme/package.nix | 111 +++++++++++++++++++ pkgs/top-level/aliases.nix | 1 - 2 files changed, 111 insertions(+), 1 deletion(-) create mode 100644 pkgs/by-name/fl/fluent-gtk-theme/package.nix diff --git a/pkgs/by-name/fl/fluent-gtk-theme/package.nix b/pkgs/by-name/fl/fluent-gtk-theme/package.nix new file mode 100644 index 000000000000..5bbc44052e29 --- /dev/null +++ b/pkgs/by-name/fl/fluent-gtk-theme/package.nix @@ -0,0 +1,111 @@ +{ + lib, + stdenvNoCC, + fetchFromGitHub, + gitUpdater, + gtk-engine-murrine, + jdupes, + sassc, + themeVariants ? [ ], # default: blue + colorVariants ? [ ], # default: all + sizeVariants ? [ ], # default: standard + tweaks ? [ ], +}: + +let + pname = "fluent-gtk-theme"; +in +lib.checkListOfEnum "${pname}: theme variants" + [ + "default" + "purple" + "pink" + "red" + "orange" + "yellow" + "green" + "teal" + "grey" + "all" + ] + themeVariants + lib.checkListOfEnum + "${pname}: color variants" + [ + "standard" + "light" + "dark" + ] + colorVariants + lib.checkListOfEnum + "${pname}: size variants" + [ + "standard" + "compact" + ] + sizeVariants + lib.checkListOfEnum + "${pname}: tweaks" + [ + "solid" + "float" + "round" + "blur" + "noborder" + "square" + ] + tweaks + + stdenvNoCC.mkDerivation + (finalAttrs: { + inherit pname; + version = "2025-04-17"; + + src = fetchFromGitHub { + owner = "vinceliuice"; + repo = "fluent-gtk-theme"; + rev = finalAttrs.version; + hash = "sha256-AaFj9lG9lWg0a0ksJ0ufoUpsunR3uDhcdb7oSrvAmPI="; + }; + + nativeBuildInputs = [ + jdupes + sassc + ]; + + propagatedUserEnvPkgs = [ gtk-engine-murrine ]; + + postPatch = '' + patchShebangs install.sh + ''; + + installPhase = '' + runHook preInstall + + name= HOME="$TMPDIR" ./install.sh \ + ${lib.optionalString (themeVariants != [ ]) "--theme " + toString themeVariants} \ + ${lib.optionalString (colorVariants != [ ]) "--color " + toString colorVariants} \ + ${lib.optionalString (sizeVariants != [ ]) "--size " + toString sizeVariants} \ + ${lib.optionalString (tweaks != [ ]) "--tweaks " + toString tweaks} \ + --icon nixos \ + --dest $out/share/themes + + jdupes --quiet --link-soft --recurse $out/share + + runHook postInstall + ''; + + passthru.updateScript = gitUpdater { }; + + meta = { + description = "Fluent design gtk theme"; + changelog = "https://github.com/vinceliuice/Fluent-gtk-theme/releases/tag/${finalAttrs.version}"; + homepage = "https://github.com/vinceliuice/Fluent-gtk-theme"; + license = lib.licenses.gpl3Only; + platforms = lib.platforms.unix; + maintainers = with lib.maintainers; [ + luftmensch-luftmensch + romildo + ]; + }; + }) diff --git a/pkgs/top-level/aliases.nix b/pkgs/top-level/aliases.nix index 8136fbc74b0d..f000038c4cb2 100644 --- a/pkgs/top-level/aliases.nix +++ b/pkgs/top-level/aliases.nix @@ -836,7 +836,6 @@ mapAliases { fltk13-minimal = warnAlias "'fltk13-minimal' has been renamed to 'fltk_1_3-minimal'" fltk_1_3-minimal; # Added 2026-01-14 fltk14 = warnAlias "'fltk14' has been renamed to 'fltk_1_4'" fltk_1_4; # Added 2026-01-14 fltk14-minimal = warnAlias "'fltk14-minimal' has been renamed to 'fltk_1_4-minimal'" fltk_1_4-minimal; # Added 2026-01-14 - fluent-gtk-theme = throw "'fluent-gtk-theme' has been removed because it depended on 'gtk-engine-murrine', which was removed because it was unmaintained upstream and depended on GTK 2."; # Added 2026-07-22 flut-renamer = throw "flut-renamer is unmaintained and has been removed"; # Added 2025-08-26 flutter324 = throw "flutter324 has been removed because it isn't updated anymore, and no packages in nixpkgs use it. If you still need it, use flutter.mkFlutter to get a custom version"; # Added 2025-10-28 flutter326 = throw "flutter326 has been removed because it isn't updated anymore, and no packages in nixpkgs use it. If you still need it, use flutter.mkFlutter to get a custom version"; # Added 2025-06-08 From d359b87f406ce467635d56bba2d5f415979d5bf0 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 31 Jul 2026 12:55:51 +0000 Subject: [PATCH 140/175] terramate: 0.17.1 -> 0.17.2 --- pkgs/by-name/te/terramate/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/te/terramate/package.nix b/pkgs/by-name/te/terramate/package.nix index 02fdbf1f698c..17d35e3375ad 100644 --- a/pkgs/by-name/te/terramate/package.nix +++ b/pkgs/by-name/te/terramate/package.nix @@ -7,16 +7,16 @@ buildGoModule (finalAttrs: { pname = "terramate"; - version = "0.17.1"; + version = "0.17.2"; src = fetchFromGitHub { owner = "terramate-io"; repo = "terramate"; rev = "v${finalAttrs.version}"; - hash = "sha256-jdhOuaSFcq3bw9cX+IJN233x4o76shMfZQDmyUiTWO4="; + hash = "sha256-NoQLxvby0sUA/tcyfJUMuNQukfQINS+v1oJDS0+ehJ0="; }; - vendorHash = "sha256-tjAsA8rxFE4zINc0Dpm2/5PpJ6BGYJiz059dBKCKsck="; + vendorHash = "sha256-vmweLyq9lr2V4ou2mzVnIaI8p63D9c0IVLKo8vYLm54="; # required for version info nativeBuildInputs = [ git ]; From d783e134c8ea967290507b3d057e50304a06de6e Mon Sep 17 00:00:00 2001 From: Stzx Date: Fri, 31 Jul 2026 20:54:04 +0800 Subject: [PATCH 141/175] fluent-gtk-theme: remove GTK2 --- pkgs/by-name/fl/fluent-gtk-theme/package.nix | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/fl/fluent-gtk-theme/package.nix b/pkgs/by-name/fl/fluent-gtk-theme/package.nix index 5bbc44052e29..2e76fe206f32 100644 --- a/pkgs/by-name/fl/fluent-gtk-theme/package.nix +++ b/pkgs/by-name/fl/fluent-gtk-theme/package.nix @@ -3,7 +3,6 @@ stdenvNoCC, fetchFromGitHub, gitUpdater, - gtk-engine-murrine, jdupes, sassc, themeVariants ? [ ], # default: blue @@ -73,10 +72,10 @@ lib.checkListOfEnum "${pname}: theme variants" sassc ]; - propagatedUserEnvPkgs = [ gtk-engine-murrine ]; - postPatch = '' patchShebangs install.sh + + sed -i '/"$THEME_DIR\/gtk-2.0/d' install.sh ''; installPhase = '' From 59337efb367b8fbbadbff8a89ac7a9798343690c Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 31 Jul 2026 14:21:23 +0000 Subject: [PATCH 142/175] clojure: 1.12.5.1654 -> 1.12.5.1664 --- pkgs/by-name/cl/clojure/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/cl/clojure/package.nix b/pkgs/by-name/cl/clojure/package.nix index 5e6ee69fd55c..15540c124036 100644 --- a/pkgs/by-name/cl/clojure/package.nix +++ b/pkgs/by-name/cl/clojure/package.nix @@ -15,12 +15,12 @@ stdenv.mkDerivation (finalAttrs: { pname = "clojure"; - version = "1.12.5.1654"; + version = "1.12.5.1664"; src = fetchurl { # https://github.com/clojure/brew-install/releases url = "https://github.com/clojure/brew-install/releases/download/${finalAttrs.version}/clojure-tools-${finalAttrs.version}.tar.gz"; - hash = "sha256-3IbMVrw3L87we9h/RGk+60thz19ENHiDh4Nk0Dtfs0I="; + hash = "sha256-d91oaJSAdK3Mk+g6eW+OjxWhqSvLG5AC1xX9IhDkdvM="; }; nativeBuildInputs = [ From 01e6b20722599fa01219db9744ee732a72ff548d Mon Sep 17 00:00:00 2001 From: Angel J <78835633+iamanaws@users.noreply.github.com> Date: Fri, 31 Jul 2026 07:29:57 -0700 Subject: [PATCH 143/175] signal-desktop: 8.18.0 -> 8.21.0 --- .../signal-desktop/chromium-149-llvm-22.patch | 30 ++++ .../si/signal-desktop/libsignal-node.nix | 8 +- pkgs/by-name/si/signal-desktop/package.nix | 26 +-- .../replace-apple-emoji-with-noto-emoji.patch | 10 +- pkgs/by-name/si/signal-desktop/ringrtc.nix | 6 +- .../si/signal-desktop/webrtc-sources.json | 170 +++++++++--------- pkgs/by-name/si/signal-desktop/webrtc.nix | 48 ++--- 7 files changed, 164 insertions(+), 134 deletions(-) create mode 100644 pkgs/by-name/si/signal-desktop/chromium-149-llvm-22.patch diff --git a/pkgs/by-name/si/signal-desktop/chromium-149-llvm-22.patch b/pkgs/by-name/si/signal-desktop/chromium-149-llvm-22.patch new file mode 100644 index 000000000000..256073872316 --- /dev/null +++ b/pkgs/by-name/si/signal-desktop/chromium-149-llvm-22.patch @@ -0,0 +1,30 @@ +diff --git a/build/config/compiler/BUILD.gn b/build/config/compiler/BUILD.gn +index f977c9fed76e6f50c50351ca22128e8c8c8897b1..81460f3591b734f3354a6f9ac7bb0990e5b28889 100644 +--- a/build/config/compiler/BUILD.gn ++++ b/build/config/compiler/BUILD.gn +@@ -589,7 +589,7 @@ config("compiler") { + # Flags for diagnostics. + cflags += [ "-fcolor-diagnostics" ] + if (!is_win) { +- cflags += [ "-fdiagnostics-show-inlining-chain" ] ++ cflags += [ ] + } else { + # Combine after https://github.com/llvm/llvm-project/pull/192241 + cflags += [ "/clang:-fdiagnostics-show-inlining-chain" ] +@@ -1911,7 +1911,7 @@ config("clang_warning_suppression") { + # See also: https://crbug.com/40891132#comment10 + ubsan_hardening("c_array_bounds") { + sanitizer = "array-bounds" +- condition = !(is_asan && target_cpu == "x86") ++ condition = false + + # Because we've enabled array-bounds sanitizing we also want to suppress + # the related warning about "unsafe-buffer-usage-in-static-sized-array", +@@ -1925,6 +1925,7 @@ ubsan_hardening("c_array_bounds") { + # `NOTREACHED()` at the end of such functions. + ubsan_hardening("return") { + sanitizer = "return" ++ condition = false + } + + config("rustc_revision") { diff --git a/pkgs/by-name/si/signal-desktop/libsignal-node.nix b/pkgs/by-name/si/signal-desktop/libsignal-node.nix index b37ef4709c4a..989b0d9288fc 100644 --- a/pkgs/by-name/si/signal-desktop/libsignal-node.nix +++ b/pkgs/by-name/si/signal-desktop/libsignal-node.nix @@ -15,23 +15,23 @@ }: rustPlatform.buildRustPackage (finalAttrs: { pname = "libsignal-node"; - version = "0.96.3"; + version = "0.97.3"; src = fetchFromGitHub { owner = "signalapp"; repo = "libsignal"; tag = "v${finalAttrs.version}"; - hash = "sha256-FOppsfocUvUfWa6AfBPOxAnntGJkzTbnPwqMzzbHnWQ="; + hash = "sha256-mRhArmrrbnAfj4JS4OqWA+FEC57Sf/BEqb95KL3JXp0="; }; - cargoHash = "sha256-wsXlCpNwO+E6rVNaD2R51Mi0sZUv2lhllGxDxzyptYA="; + cargoHash = "sha256-obv5XcGD4kkgTPShszxJRTFsOeig9UWyxdE8cyjbsCY="; npmRoot = "node"; npmDeps = fetchNpmDeps { name = "${finalAttrs.pname}-npm-deps"; inherit (finalAttrs) version src; sourceRoot = "${finalAttrs.src.name}/${finalAttrs.npmRoot}"; - hash = "sha256-p8udihRlXMTnG4BT60D2VlI7D/O3eHV/zCS7ucpeuO4="; + hash = "sha256-jTyEnJBEuL8RXT29VYsRW797FPgINm8BvVBmt3m13EA="; }; nativeBuildInputs = [ diff --git a/pkgs/by-name/si/signal-desktop/package.nix b/pkgs/by-name/si/signal-desktop/package.nix index be16d0a387f6..8425fa03dbdd 100644 --- a/pkgs/by-name/si/signal-desktop/package.nix +++ b/pkgs/by-name/si/signal-desktop/package.nix @@ -9,7 +9,7 @@ fetchPnpmDeps, pnpmConfigHook, pnpmBuildHook, - electron_42, + electron_43, python3, makeWrapper, callPackage, @@ -34,7 +34,7 @@ assert lib.warnIf (commandLineArgs != "") let nodejs = nodejs_24; pnpm = pnpm_11; - electron = electron_42; + electron = electron_43; libsignal-node = callPackage ./libsignal-node.nix { inherit nodejs; }; signal-sqlcipher = callPackage ./signal-sqlcipher.nix { @@ -45,13 +45,13 @@ let webrtc = callPackage ./webrtc.nix { }; ringrtc = callPackage ./ringrtc.nix { inherit webrtc; }; - version = "8.18.0"; + version = "8.21.0"; src = fetchFromGitHub { owner = "signalapp"; repo = "Signal-Desktop"; tag = "v${version}"; - hash = "sha256-fynCFGmch3UecT5esNfVVlf0+xDrCdCBGw2HMMqBzWw="; + hash = "sha256-RuGq8ygiZewKqtKQattlqU0pcMMlgdFOJAhmN4J/8Tw="; # Emoji font files will be added in `postFetch` if `withAppleEmojis` is enabled. They # are fetched separately below. postFetch = '' @@ -77,18 +77,13 @@ let pname src version - postPatch pnpmWorkspaces ; inherit pnpm; fetcherVersion = 4; - hash = "sha256-bWNs5W2NPk55Sm7UqwWvXU7bY+AXzevU3o2ji23HxtU="; + hash = "sha256-1n+u0mcZJwjkdKmNY6KE6tk6/UPYuya5WqLrKRJimGw="; }; - postPatch = '' - rm sticker-creator/pnpm-lock.yaml - ''; - strictDeps = true; nativeBuildInputs = [ nodejs @@ -190,13 +185,13 @@ stdenv.mkDerivation (finalAttrs: { ; inherit pnpm; fetcherVersion = 4; - hash = "sha256-bWNs5W2NPk55Sm7UqwWvXU7bY+AXzevU3o2ji23HxtU="; + hash = "sha256-1n+u0mcZJwjkdKmNY6KE6tk6/UPYuya5WqLrKRJimGw="; }; env = { ELECTRON_SKIP_BINARY_DOWNLOAD = "1"; SIGNAL_ENV = "production"; - SOURCE_DATE_EPOCH = 1783606680; + SOURCE_DATE_EPOCH = 1785418091; }; preBuild = '' @@ -259,6 +254,13 @@ stdenv.mkDerivation (finalAttrs: { popd test -f node_modules/@signalapp/windows-ucv/dist/index.js + # @signalapp/types is required at runtime by preload.wrapper.js, but its + # output is normally produced by the prepare script. + pushd packages/types + pnpm run build + popd + test -f node_modules/@signalapp/types/dist/index.std.cjs + cp -r ${electron.dist} electron-dist chmod -R u+w electron-dist cp -r ${sticker-creator} sticker-creator/dist diff --git a/pkgs/by-name/si/signal-desktop/replace-apple-emoji-with-noto-emoji.patch b/pkgs/by-name/si/signal-desktop/replace-apple-emoji-with-noto-emoji.patch index 2b3e50b13af0..71e0b5bd0167 100644 --- a/pkgs/by-name/si/signal-desktop/replace-apple-emoji-with-noto-emoji.patch +++ b/pkgs/by-name/si/signal-desktop/replace-apple-emoji-with-noto-emoji.patch @@ -2,13 +2,13 @@ diff --git a/app/AssetService.main.ts b/app/AssetService.main.ts index a4a21b5bb..3d5ab1eb0 100644 --- a/app/AssetService.main.ts +++ b/app/AssetService.main.ts -@@ -34,7 +34,6 @@ const OPTIONAL_ASSETS = new Map([]); +@@ -34,7 +34,2 @@ const OPTIONAL_ASSETS = new Map([]); - if (!process.mas) { - LOCAL_ASSETS.add('fonts/emoji.woff2'); +-if (!process.mas) { +- LOCAL_ASSETS.add('fonts/emoji.woff2'); - OPTIONAL_ASSETS.set('optional-fonts/emoji-large.woff2', 'emoji-font.woff2'); - } - +-} +- export class AssetService { diff --git a/app/protocol_filter.node.ts b/app/protocol_filter.node.ts index 17c68f0a4..4ed359de6 100644 diff --git a/pkgs/by-name/si/signal-desktop/ringrtc.nix b/pkgs/by-name/si/signal-desktop/ringrtc.nix index c981eb2b9a2d..a1e31cb4f6cb 100644 --- a/pkgs/by-name/si/signal-desktop/ringrtc.nix +++ b/pkgs/by-name/si/signal-desktop/ringrtc.nix @@ -19,16 +19,16 @@ let in rustPlatform.buildRustPackage (finalAttrs: { pname = "ringrtc"; - version = "2.69.4"; + version = "2.70.0"; src = fetchFromGitHub { owner = "signalapp"; repo = "ringrtc"; tag = "v${finalAttrs.version}"; - hash = "sha256-z/9Y9rrlH4yziEVAXrCmkmP42hdDm3frGJnL1O/qOqg="; + hash = "sha256-5RPX1SZhVJaSIDjdY2IvInwSI4YHs0y7TK1b9ixaeZc="; }; - cargoHash = "sha256-a6CEUVW1HXqgIp/S+4Ype83N3QtNCBrutiEepHNW5pY="; + cargoHash = "sha256-tztNtAGYHp+Kh98efwtt51yhRwhqDKeT06Q4B/HrHfQ="; preConfigure = '' # Check for matching webrtc version diff --git a/pkgs/by-name/si/signal-desktop/webrtc-sources.json b/pkgs/by-name/si/signal-desktop/webrtc-sources.json index 5ed34c7a02f6..26f75df52a12 100644 --- a/pkgs/by-name/si/signal-desktop/webrtc-sources.json +++ b/pkgs/by-name/si/signal-desktop/webrtc-sources.json @@ -1,25 +1,25 @@ { "src": { "args": { - "hash": "sha256-kdRUqYFKsEbAR0u4btQc995vtbN+FVcei19PgTf1DyA=", + "hash": "sha256-icy7lsgHBofHMJg6Eo2jxkuo9vHVw6P8TXsti2416bg=", "owner": "signalapp", "repo": "webrtc", - "tag": "7778c" + "tag": "7871d" }, "fetcher": "fetchFromGitHub" }, "src/build": { "args": { - "hash": "sha256-XmuuR4mLcaoAPCr82ka6ldtE4OmYFmXlWjNaP/wM2BQ=", - "rev": "dd54dd5186566a13bda647123c22540666b12ace", + "hash": "sha256-jY47j4gsrzQpNnQsTtb01CUMisejfqPgVsOyWLyI7iA=", + "rev": "d296a9fec6186f2c109758c7d3f93cbef936dfc3", "url": "https://chromium.googlesource.com/chromium/src/build" }, "fetcher": "fetchFromGitiles" }, "src/buildtools": { "args": { - "hash": "sha256-BvGCdJ3EgUZX6MC3jf86YNl4LzUxpxiptCEBv3bqBIo=", - "rev": "95ed44cf5f06dbb5861030b91c9db9ccb4316762", + "hash": "sha256-1xi58KhE/oErrrYnP/YKkWeA3dLfPtcTwbKcn6jr13o=", + "rev": "17495e454aae81b581e8b3caccbb53054509b280", "url": "https://chromium.googlesource.com/chromium/src/buildtools" }, "fetcher": "fetchFromGitiles" @@ -35,40 +35,40 @@ }, "src/testing": { "args": { - "hash": "sha256-tUh/eOrf71OjndY6p6IOJ5MFJUnuisDGWXJzsHHyrHs=", - "rev": "629b7bb6055714e23d8125bf790cfc8d94a94159", + "hash": "sha256-xUfuaftEKZr6GwBtZfAUW/uRkU1f+pJBdiFpGnJQPms=", + "rev": "5c19204b6395adfad25f83bbbd56439af9f86f7f", "url": "https://chromium.googlesource.com/chromium/src/testing" }, "fetcher": "fetchFromGitiles" }, "src/third_party": { "args": { - "hash": "sha256-sLMCkUCadVZIX5bTVovDd5tPn0ZB/CH/d0tQic8lEQg=", - "rev": "4923971b35e39f6bd9be8bc19c4680785a15c80d", + "hash": "sha256-BDOKJiCeO8g3gtSJYK1ZMKymq63BJX1L5EeWpvfCFFM=", + "rev": "7c92732938de0ef7e28f5da231994723f938f407", "url": "https://chromium.googlesource.com/chromium/src/third_party" }, "fetcher": "fetchFromGitiles" }, "src/third_party/boringssl/src": { "args": { - "hash": "sha256-OIaU7GoHYKq1ZyPaW/gLSKNq1ipw5nAgjqcPIFXtGwE=", - "rev": "8dce4fd20ab7e768c0a5103edc1d8cb7e54366ba", + "hash": "sha256-7pKQHAQ218OiuuSNsm1ZRUvUcft7QzUG++xH3y8fR9o=", + "rev": "f91f1447397c6719f9774dfb8e67329378e1f3d3", "url": "https://boringssl.googlesource.com/boringssl.git" }, "fetcher": "fetchFromGitiles" }, "src/third_party/breakpad/breakpad": { "args": { - "hash": "sha256-igcX5XwacIwoGbqIcZKwlJYpRWl9Uc32WdpXyHO7UVA=", - "rev": "8be0e3114685fcc1589561067282edf75ea1259a", + "hash": "sha256-JzGeACM7hXKhjFVFoeHqs9HfqDLm2OyWtjhU5lyKuFs=", + "rev": "6d017fa2c0c440f914385bb794fd88de90fef736", "url": "https://chromium.googlesource.com/breakpad/breakpad.git" }, "fetcher": "fetchFromGitiles" }, "src/third_party/catapult": { "args": { - "hash": "sha256-f57wYazKyGrjfzcQ7EVqwIG8p+bHLGK0Qb/tZERxwY8=", - "rev": "5a34891efa6e41c8aca8842386b8ee528963ffdf", + "hash": "sha256-XYufVvzOXD4voZUWUvumQQqLNsx9sy0QmQzNzrgNEWg=", + "rev": "2852bb7e91e4995502ffb72b7ed21412ee157914", "url": "https://chromium.googlesource.com/catapult.git" }, "fetcher": "fetchFromGitiles" @@ -83,8 +83,8 @@ }, "src/third_party/clang-format/script": { "args": { - "hash": "sha256-f+BbQ6xIubloSzx/MhPSZ8ymCskmS+9+epDGtPjZqXc=", - "rev": "c2725e0622e1a86d55f14514f2177a39efea4a0e", + "hash": "sha256-Cm6BOOlEyD0kdYxMSmk6Fj1Dnfs3zCzXsm+BOXgBme0=", + "rev": "6eddfb5ec5f92127a531eda66c568d3a11e7ec11", "url": "https://chromium.googlesource.com/external/github.com/llvm/llvm-project/clang/tools/clang-format.git" }, "fetcher": "fetchFromGitiles" @@ -99,16 +99,16 @@ }, "src/third_party/compiler-rt/src": { "args": { - "hash": "sha256-ay0gzhNjAah27LQd/i0ex6EcHEdqpsWBT9Tw510coRM=", - "rev": "bb7645f5e11c9c1d719a890fcb09ccfaaa14580f", + "hash": "sha256-PjH+E+6knLw0YSM7XpoC2taCkh89GQX1EDiviO4ZPPM=", + "rev": "b7f9fa6b211b362d3ca07ab2043419ebaf75d1d0", "url": "https://chromium.googlesource.com/external/github.com/llvm/llvm-project/compiler-rt.git" }, "fetcher": "fetchFromGitiles" }, "src/third_party/cpuinfo/src": { "args": { - "hash": "sha256-LnLtCMMRg+DwB7MijBdt/tmCKD/zN5y2oTgXlYw3hTg=", - "rev": "7607ca500436b37ad23fb8d18614bec7796b68a7", + "hash": "sha256-/QsOjDik0TnH3FnK7LOwsJkvX+O+2DRFX4eF3MxD3fc=", + "rev": "ea6b9f1bb6e1001d8b21574d5bc78ddef62e499d", "url": "https://chromium.googlesource.com/external/github.com/pytorch/cpuinfo.git" }, "fetcher": "fetchFromGitiles" @@ -123,24 +123,24 @@ }, "src/third_party/dav1d/libdav1d": { "args": { - "hash": "sha256-iKq6TYscIBK4ydv+0msNV3tcs82Ljk5ZNr954Qv2lII=", - "rev": "d69235dd804b24c04ed05639cffcc912cd6cfd75", + "hash": "sha256-uR6zXz1Nk75mKzw1M/MvcD33iV7SbVbncD08yhKdEm0=", + "rev": "1718ff9aded99f0a89f5c7940d6afb8948301e33", "url": "https://chromium.googlesource.com/external/github.com/videolan/dav1d.git" }, "fetcher": "fetchFromGitiles" }, "src/third_party/depot_tools": { "args": { - "hash": "sha256-r/mmibfbCBpV9reVbHc/S7FKffrtE729y2Mot/JsHgc=", - "rev": "ce1ebad2c35c9387186f01d77edeea28a254c955", + "hash": "sha256-/edPeYK0WF7AmfaTG2uC9ZFWE7DPn+NUs1tgnR3RzFs=", + "rev": "2f9bc10799af5aeb4a0ed903742ad69bb1d0ef75", "url": "https://chromium.googlesource.com/chromium/tools/depot_tools.git" }, "fetcher": "fetchFromGitiles" }, "src/third_party/eigen3/src": { "args": { - "hash": "sha256-/nzzcoJ87L7EVsRfAeok3UbxNKQeAWOFjmwZ3TYmGmI=", - "rev": "002229ce470065878afb7c2f6f96d22c9a9b7ba0", + "hash": "sha256-YjyAr1sTLF6zlNw9G0RL5kBApmRRYsHpUet3sCCsf14=", + "rev": "fc0f148ab491bf36378c5d527d8f6669ccf21b07", "url": "https://chromium.googlesource.com/external/gitlab.com/libeigen/eigen.git" }, "fetcher": "fetchFromGitiles" @@ -155,8 +155,8 @@ }, "src/third_party/ffmpeg": { "args": { - "hash": "sha256-JHAicFKBvtkwmZPRBKYPT6JVqYqF8hyXxU0H7kfgCBs=", - "rev": "b5e18fb9da84e26ceef30d4e4886696bf59337c0", + "hash": "sha256-41qpsOTedB51WMzzHXDiXA19OIzA7wG/Qgbz6IkmWpk=", + "rev": "ad41607c61898cf7150e0fb20fe4bbabd44922a3", "url": "https://chromium.googlesource.com/chromium/third_party/ffmpeg.git" }, "fetcher": "fetchFromGitiles" @@ -187,16 +187,16 @@ }, "src/third_party/freetype/src": { "args": { - "hash": "sha256-H5RzBFYWIp/QYKyeBM2wfuX7FvXHPbhCAp7qne5Zvhw=", - "rev": "99b479dc34728936b006679a31e12b8cf432fc55", + "hash": "sha256-QOUIW1p9bh7v100iQn8aPq601bNHz+UDA4esd10nQk0=", + "rev": "7e0e56f84fd53cf38378d33c8fc8f92d12ab9ac6", "url": "https://chromium.googlesource.com/chromium/src/third_party/freetype2.git" }, "fetcher": "fetchFromGitiles" }, "src/third_party/fuzztest/src": { "args": { - "hash": "sha256-0Fk2W4rS1xB6YcXsDbrMfmZUfMxNlGz29xRcBHZbijA=", - "rev": "dc327134097700121e4ecd6e1d54d1d0a832a18d", + "hash": "sha256-nKdSzMuvjgYEP2sbP5/S5yzrT3FL6OsKMbC/uAsUybo=", + "rev": "36a7acd1a4445a722803cd2d41bcf878ec2831ca", "url": "https://chromium.googlesource.com/external/github.com/google/fuzztest.git" }, "fetcher": "fetchFromGitiles" @@ -219,8 +219,8 @@ }, "src/third_party/google_benchmark/src": { "args": { - "hash": "sha256-GfqY2d+Nd7ovNrXxzTRm/AYWj7GuxIO6FawzUEzwOVA=", - "rev": "188e8278990a9069ffc84441cb5a024fd0bede37", + "hash": "sha256-M8QkA8+bckoRjlcVneYXNetmPEWEvmWy/mca5JA40Ho=", + "rev": "8abf1e701fbd88c8170f48fe0558247e2e5f8e7d", "url": "https://chromium.googlesource.com/external/github.com/google/benchmark.git" }, "fetcher": "fetchFromGitiles" @@ -235,8 +235,8 @@ }, "src/third_party/grpc/src": { "args": { - "hash": "sha256-LQrig9/ceXS1LclfN9b9DoAvwltIA1R5fSpmHTmaN8s=", - "rev": "5e9fb9cbfb12a10ff9c16fbc360328d224b838d6", + "hash": "sha256-XzKPeOHb7yf0CZdz2/P5CwUiEi5Cquiqqj8nBQ+xkqI=", + "rev": "05ffa9265bd5f4846a5e3dc46d91ba739ad17ef6", "url": "https://chromium.googlesource.com/external/github.com/grpc/grpc.git" }, "fetcher": "fetchFromGitiles" @@ -249,34 +249,34 @@ }, "fetcher": "fetchFromGitiles" }, - "src/third_party/harfbuzz-ng/src": { + "src/third_party/harfbuzz/src": { "args": { - "hash": "sha256-jQZElINbJgiVj1IHhkrtBCL5jGYzZrjJkO7gt+bgMA4=", - "rev": "6f4c5cec306d31e6822303f5ba248a14293d588e", + "hash": "sha256-tSap704OcadjsEUx+K1bTCrqvluH2F0oFW6Aio+Wgn4=", + "rev": "b90b89feb9aad05065b2edfb10aaa969b164275a", "url": "https://chromium.googlesource.com/external/github.com/harfbuzz/harfbuzz.git" }, "fetcher": "fetchFromGitiles" }, "src/third_party/icu": { "args": { - "hash": "sha256-hKIzBQVs4C/QJ4BdP3DTm6au9hq8BE0kG1VphtbtHVE=", - "rev": "b4aae6832c06df9d538d41b249403cf0678f16b4", + "hash": "sha256-rNErsn11FZUh8GXAl7jK+NyLHIKrQR3LuoM1qFFGtmM=", + "rev": "3859e64eed5d34544b27fbcab0ac1685ce83df3c", "url": "https://chromium.googlesource.com/chromium/deps/icu.git" }, "fetcher": "fetchFromGitiles" }, "src/third_party/instrumented_libs": { "args": { - "hash": "sha256-8kokdsnn5jD9KgM/6g0NuITBbKkGXWEM4BMr1nCrfdU=", - "rev": "69015643b3f68dbd438c010439c59adc52cac808", + "hash": "sha256-5cb9qhSEzb941pF5HH0Br+x9wEH7MiGwQttvErb2mZo=", + "rev": "e8cb570a9a2ee9128e2214c73417ad2a3c47780b", "url": "https://chromium.googlesource.com/chromium/third_party/instrumented_libraries.git" }, "fetcher": "fetchFromGitiles" }, "src/third_party/jsoncpp/source": { "args": { - "hash": "sha256-bSLNcoYBz3QCt5VuTR056V9mU2PmBuYBa0W6hFg2m8Q=", - "rev": "42e892d96e47b1f6e29844cc705e148ec4856448", + "hash": "sha256-q+DOwkjRlHacgfWf5UVY02aqfnKK9M/1YRBX6aMce9g=", + "rev": "d4d072177213b117fb81d4cfda140de090616161", "url": "https://chromium.googlesource.com/external/github.com/open-source-parsers/jsoncpp.git" }, "fetcher": "fetchFromGitiles" @@ -291,16 +291,16 @@ }, "src/third_party/libaom/source/libaom": { "args": { - "hash": "sha256-uO+zjmt0g5m780WR823UJ0AmQA+dfVFOjPChTLAciTM=", - "rev": "f3dddebddd0dba76fbfb97b96b6336bcf1d3a30c", + "hash": "sha256-qvwmcnA3dls89y4Uy79c2Lt0W5iT6ASD/MKS5LLzO/A=", + "rev": "c213343c8d32bcae729fe09fcba16e1f371cb23b", "url": "https://aomedia.googlesource.com/aom.git" }, "fetcher": "fetchFromGitiles" }, "src/third_party/libc++/src": { "args": { - "hash": "sha256-7O/X2JW8ghkPTjmFZmT9cgG3Ui5zk3gUb436KlPww34=", - "rev": "7ab65651aed6802d2599dcb7a73b1f82d5179d05", + "hash": "sha256-vT1km7JgVpotDoNK+ae1gplSHcwrVNLsv/QAFUrDsIM=", + "rev": "5abc7f839700f0f17338434e1c1c6a8c87c00c11", "url": "https://chromium.googlesource.com/external/github.com/llvm/llvm-project/libcxx.git" }, "fetcher": "fetchFromGitiles" @@ -315,64 +315,64 @@ }, "src/third_party/libgav1/src": { "args": { - "hash": "sha256-gisU0p0HDL7Po/ZXIIZVOTnxnOuVvSE/FYo9DaEUFfo=", - "rev": "40f58ed32ff39071c3f2a51056dbc49a070af0dc", + "hash": "sha256-6/zMaX2DPSKpsaqirhrgi3nL/88Qr2VXacmyL5IyJ3U=", + "rev": "66ac17620652635392f6ab24065c77b035e281c9", "url": "https://chromium.googlesource.com/codecs/libgav1.git" }, "fetcher": "fetchFromGitiles" }, "src/third_party/libjpeg_turbo": { "args": { - "hash": "sha256-KGeB/lTjhm8DQBDZVSPENvZEGSHeLTkviJrYsFh5vEM=", - "rev": "d1f5f2393e0d51f840207342ae86e55a86443288", + "hash": "sha256-wor4RTF3/5BFL9EWcGEofY+M4HN2+/KJUaOY+u86K5Q=", + "rev": "640f254ad0fa03f6b1f29f89b7dd9366f2f6e533", "url": "https://chromium.googlesource.com/chromium/deps/libjpeg_turbo.git" }, "fetcher": "fetchFromGitiles" }, "src/third_party/libpfm4/src": { "args": { - "hash": "sha256-6YaPJcI6Qk0F1Dv5evfFq3MVSsBpsQ7sIreSuHZmOUo=", - "rev": "41878eab48c50bb9ec5f741a013e971bb5a9dff2", + "hash": "sha256-t4LMG38GksMEM5DktyJ0qLUX1biXErQ57MaMtd7hoeo=", + "rev": "977a25bb3dfe45f653a6cee71ffaae9a92fc3095", "url": "https://chromium.googlesource.com/external/git.code.sf.net/p/perfmon2/libpfm4.git" }, "fetcher": "fetchFromGitiles" }, "src/third_party/libsrtp": { "args": { - "hash": "sha256-xC//VEFrI94nCkyLnRa6uQ+hJQqe41v0Qjm4LJ7K84I=", - "rev": "e8383771af8aa4096f5bcfe3743a5ea128f88a9a", + "hash": "sha256-6tIbthIcUw58AgaNzvSenZPp/e5vHVTp5K2bpPF+Zg0=", + "rev": "cd5d177bf1fde755ddb4c7f0d9ff7693f8b49e5e", "url": "https://chromium.googlesource.com/chromium/deps/libsrtp.git" }, "fetcher": "fetchFromGitiles" }, "src/third_party/libunwind/src": { "args": { - "hash": "sha256-miwz3+/fq+7Ohsn8J6xrLsQn/VqyezS9vZO9XzEuZZA=", - "rev": "db838d918570d4e381ecf9f5cc70a0098c9c2cd6", + "hash": "sha256-EuaVSYiR7qrlYqBR0UqdWCvwdzJSn0RS2wC/lnP19AE=", + "rev": "d6c7a21e978f0adaa43accaad53bc64f0b64f6ec", "url": "https://chromium.googlesource.com/external/github.com/llvm/llvm-project/libunwind.git" }, "fetcher": "fetchFromGitiles" }, "src/third_party/libvpx/source/libvpx": { "args": { - "hash": "sha256-8vej9g9+L73eOIuXZNfOWe6pV/cNr4JZOihZUtRxbFA=", - "rev": "3fce57ecc905d95a4619f33d09851d68c5a88663", + "hash": "sha256-fCwegoFUwDg5/tGBH4SlO3YeAR2wkYgIoajXVtt0eYk=", + "rev": "31af37b1bd2774d11a932c1cd9a3849328375f64", "url": "https://chromium.googlesource.com/webm/libvpx.git" }, "fetcher": "fetchFromGitiles" }, "src/third_party/libyuv": { "args": { - "hash": "sha256-DW7PuRqA1x0K8/uJbxBJ4Cn9YEPFhZ9vhuGVVyGKK98=", - "rev": "30809ff64a9ca5e45f86439c0d474c2d3eef3d05", + "hash": "sha256-Bq9LM+9sdFzKzbTzrW2cloSOFUhCfyvYqwBweIhiDQI=", + "rev": "de63bd90f4396313f864ad58b65279e7894451a9", "url": "https://chromium.googlesource.com/libyuv/libyuv.git" }, "fetcher": "fetchFromGitiles" }, "src/third_party/llvm-libc/src": { "args": { - "hash": "sha256-nrd+E7LRTclF/Qa3wBvlutJ/wbLQKr73LOBk9k0qFOI=", - "rev": "adccc443070c58badd6414fd9a4380ca8c78e7c4", + "hash": "sha256-NaQb2UvNqIL4LL5PSshRRMKWdXFjWPnf2YJpVegGtag=", + "rev": "be95a36286a288c9437f5ed991720ccece1a6391", "url": "https://chromium.googlesource.com/external/github.com/llvm/llvm-project/libc.git" }, "fetcher": "fetchFromGitiles" @@ -387,16 +387,16 @@ }, "src/third_party/nasm": { "args": { - "hash": "sha256-0KsHYi76IaVNwk0dBhem2AnUXd9PpeS+jUsY+zPmeJ8=", - "rev": "45252858722aad12e545819b2d0f370eb865431b", + "hash": "sha256-uC6bGxSdz1V2SXIQjMsDd6555b3gAPN1Y0ZQtWoqDww=", + "rev": "525a09a813be0f75b646ee93fc2a31c27b87d722", "url": "https://chromium.googlesource.com/chromium/deps/nasm.git" }, "fetcher": "fetchFromGitiles" }, "src/third_party/neon_2_sse/src": { "args": { - "hash": "sha256-4OzG4wIPwnKbFD9LG+stxHt5O4qB85ZIXVeSrNqDAyM=", - "rev": "662a85912e8f86ec808f9b15ce77f8715ba53316", + "hash": "sha256-ydHSMPJS+axvW7KIR/9SLWNFq/lP67dpg9Yt7shLCng=", + "rev": "ed59be8546632d5126ff69c87122ae5de20ffe4f", "url": "https://chromium.googlesource.com/external/github.com/intel/ARM_NEON_2_x86_SSE.git" }, "fetcher": "fetchFromGitiles" @@ -411,8 +411,8 @@ }, "src/third_party/perfetto": { "args": { - "hash": "sha256-ZDQsBVFq9TgGGf5r2vv8nsHvFy03NM+SkbaXPoa345Q=", - "rev": "40b1342aa7bd47d9c963c3617fd98ec1551528f9", + "hash": "sha256-2RXnxNmF5ZSWs7H4slVVTSLh9bfQMMfMRrELVZUN/Vo=", + "rev": "82ad4b69cbaf64e26c639061b1712756a9cc5e20", "url": "https://chromium.googlesource.com/external/github.com/google/perfetto.git" }, "fetcher": "fetchFromGitiles" @@ -427,8 +427,8 @@ }, "src/third_party/pthreadpool/src": { "args": { - "hash": "sha256-Es9QNblzo5b+x4K7myQJwIiUKvqyP16QExWPhGqqDO8=", - "rev": "9003ee6c137cea3b94161bd5c614fb43be523ee1", + "hash": "sha256-4EHJzZT+Gbhs8SkOhjSvDIPEqIQU93oJmtF3c/T+qjw=", + "rev": "02460584c6092e527c8b89f7df4de143d70e801f", "url": "https://chromium.googlesource.com/external/github.com/google/pthreadpool.git" }, "fetcher": "fetchFromGitiles" @@ -449,26 +449,34 @@ }, "fetcher": "fetchFromGitiles" }, + "src/third_party/sframe/src": { + "args": { + "hash": "sha256-bw+6ycUpnFZJhtXFUzr7XTOljNrs+7oFdVY+LN0Rqek=", + "rev": "b14090904433bed0d4ec3f875b9b39f3e0555930", + "url": "https://chromium.googlesource.com/external/github.com/cisco/sframe" + }, + "fetcher": "fetchFromGitiles" + }, "src/third_party/tflite/src": { "args": { - "hash": "sha256-nvU3p6TzEqBkDtZEoxCZGPsQA0oZNJID8raqHBDS0ko=", - "rev": "8fd527849069a358ad6c2980b9a9b34a53c53717", + "hash": "sha256-eSqaWXtzZ4Bi9ilaJYGdZamzUjmo+AtDZ9KeZhsc/fY=", + "rev": "999d49c10046e240cd5366d349d3a5f6af16a0d4", "url": "https://chromium.googlesource.com/external/github.com/tensorflow/tensorflow.git" }, "fetcher": "fetchFromGitiles" }, "src/third_party/xnnpack/src": { "args": { - "hash": "sha256-vOUwMXZJbYxTGPpdD5uc9ATfPIpThCDHV/YTlWN0ajw=", - "rev": "97f3177fd836fff03b48a886bb130591866ad7ca", + "hash": "sha256-uw3r5g5rWamlFubBkXDb4KRx3hkOAoQyFo8l95GYGZI=", + "rev": "56ac34b3f45fae2eca1f32584f7f0b279be2cf1f", "url": "https://chromium.googlesource.com/external/github.com/google/XNNPACK.git" }, "fetcher": "fetchFromGitiles" }, "src/tools": { "args": { - "hash": "sha256-PDjcHq8BTDLD6OsYFfvjw8ffmam/4YSx8SF0G/NvebY=", - "rev": "f363a79871a91f36322e845e3134e2f04e1fc18a", + "hash": "sha256-Et9KyslSik7y5v2Jzai/vpxogpT0RlZ5b+u7/VwHc28=", + "rev": "8e4d26ef387bfa4c07e66dd1c7399c3d53ef1451", "url": "https://chromium.googlesource.com/chromium/src/tools" }, "fetcher": "fetchFromGitiles" diff --git a/pkgs/by-name/si/signal-desktop/webrtc.nix b/pkgs/by-name/si/signal-desktop/webrtc.nix index 9f6465a4e84b..4fb2a9066d3c 100644 --- a/pkgs/by-name/si/signal-desktop/webrtc.nix +++ b/pkgs/by-name/si/signal-desktop/webrtc.nix @@ -86,42 +86,32 @@ stdenv.mkDerivation (finalAttrs: { alsa-lib ]; - patches = [ - # https://github.com/NixOS/nixpkgs/blob/8e689a91c5b4e47b57dee488dd7e319cc704eb9d/pkgs/applications/networking/browsers/chromium/common.nix#L604-L612 - # clang++: error: unknown argument: '-fsanitize-ignore-for-ubsan-feature=array-bounds' - (fetchpatch { - name = "chromium-146-revert-Update-fsanitizer=array-bounds-config.patch"; - # https://chromium-review.googlesource.com/c/chromium/src/+/7539408 - url = "https://chromium.googlesource.com/chromium/src/+/acb47d9a6b56c4889a2ed4216e9968cfc740086c^!?format=TEXT"; - decode = "base64 -d"; - revert = true; - hash = "sha256-WZsN2qm6lX121bDf7SoN75flXtCTmPPpwtHK0ayjkPc="; - }) + env = { + BUILD_CC = "$CC_FOR_BUILD"; + BUILD_CXX = "$CXX_FOR_BUILD"; + BUILD_AR = "$AR_FOR_BUILD"; + BUILD_NM = "$NM_FOR_BUILD"; + NIX_CFLAGS_COMPILE = lib.optionalString stdenv.hostPlatform.isLinux "-Wno-changes-meaning"; + }; - # https://github.com/NixOS/nixpkgs/blob/8e689a91c5b4e47b57dee488dd7e319cc704eb9d/pkgs/applications/networking/browsers/chromium/common.nix#L620-L623 + patches = [ # clang++: error: unknown argument: '-fno-lifetime-dse' ./chromium-147-llvm-22.patch - # https://github.com/NixOS/nixpkgs/blob/8e689a91c5b4e47b57dee488dd7e319cc704eb9d/pkgs/applications/networking/browsers/chromium/common.nix#L624-L644 + # Keep in sync with Chromium's LLVM 22 compatibility patches. + # clang++: error: unknown argument: '-fdiagnostics-show-inlining-chain' + # clang++: error: unknown argument: '-fsanitize-ignore-for-ubsan-feature=array-bounds' # clang++: error: unknown argument: '-fsanitize-ignore-for-ubsan-feature=return' + ./chromium-149-llvm-22.patch + + # ninja: error: 'ar', needed by 'obj/third_party/protobuf/libprotoc_lib.a', + # missing and no known rule to make it (fetchpatch { - name = "chromium-148-revert-build-Add--fsanitizer=return-config.patch"; - # https://chromium-review.googlesource.com/c/chromium/src/+/7629257 - url = "https://chromium.googlesource.com/chromium/src/+/99ba1f5302f9433efdb4df302cb7b7de56c72e4c^!?format=TEXT"; + name = "chromium-150-backport-build--Omit-ar-from-inputs-when-resolved-via--PATH.patch"; + # https://chromium-review.googlesource.com/c/chromium/src/+/7904982 + url = "https://chromium.googlesource.com/chromium/src/+/60f987d8d5f7272793a40290d060b8f50933f825^!?format=TEXT"; decode = "base64 -d"; - revert = true; - hash = "sha256-/qzzxwTdPMwIdsqD/G02S7kKHCj3QxECL+g1WYEaWmU="; - }) - # ERROR Unresolved dependencies. - # //apps:apps(//build/toolchain/linux/unbundle:default) - # needs //build/config/compiler:sanitize_return(//build/toolchain/linux/unbundle:default) - (fetchpatch { - name = "chromium-148-revert-build-Enable--fsanitizer=return-config.patch"; - # https://chromium-review.googlesource.com/c/chromium/src/+/7629258 - url = "https://chromium.googlesource.com/chromium/src/+/9357bfbea03753fe52264c9ec36abe74f48cfef5^!?format=TEXT"; - decode = "base64 -d"; - revert = true; - hash = "sha256-14fTHNh3vGsf4KgeH8uLX+aK3lrjK0VKd1dfK1g7r0I="; + hash = "sha256-MryWxSwBxSIONhl3X1cDxTWwNWy8a4yt/sqkrueSUNs="; }) ]; From 7ed6b9d5d439bea8ecf1bdea4f133ae957d446d0 Mon Sep 17 00:00:00 2001 From: HigherOrderLogic <73709188+HigherOrderLogic@users.noreply.github.com> Date: Fri, 31 Jul 2026 15:11:37 +0000 Subject: [PATCH 144/175] dioxus-cli: 0.7.9 -> 0.7.10 --- pkgs/by-name/di/dioxus-cli/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/di/dioxus-cli/package.nix b/pkgs/by-name/di/dioxus-cli/package.nix index ce34b458922b..746f686683a2 100644 --- a/pkgs/by-name/di/dioxus-cli/package.nix +++ b/pkgs/by-name/di/dioxus-cli/package.nix @@ -17,15 +17,15 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "dioxus-cli"; - version = "0.7.9"; + version = "0.7.10"; src = fetchCrate { pname = "dioxus-cli"; version = finalAttrs.version; - hash = "sha256-tLMtUlohSJt3okdJh+ARweQNGmzj/vYiNl8iZhDbSAc="; + hash = "sha256-kPzo5zRSVs46SjiDRKpKxca8kPcWUgqc/LMKQsk0sC8="; }; - cargoHash = "sha256-h5wkxHP8ehZLHqcUsro08/dpqSPnPuBbZuUGG8i4nBc="; + cargoHash = "sha256-cvBVIkIqBjXFifYNpL2DqZpQcBaX/59Xw0ZJKUvUcIs="; buildFeatures = [ "no-downloads" ] From 1b65f5f2a1fa7114623e4a679a077a05284dfa16 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 31 Jul 2026 15:51:14 +0000 Subject: [PATCH 145/175] talhelper: 3.1.14 -> 3.1.15 --- pkgs/by-name/ta/talhelper/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ta/talhelper/package.nix b/pkgs/by-name/ta/talhelper/package.nix index a064b76d8a62..2641eec0b996 100644 --- a/pkgs/by-name/ta/talhelper/package.nix +++ b/pkgs/by-name/ta/talhelper/package.nix @@ -9,13 +9,13 @@ buildGoModule (finalAttrs: { pname = "talhelper"; - version = "3.1.14"; + version = "3.1.15"; src = fetchFromGitHub { owner = "budimanjojo"; repo = "talhelper"; tag = "v${finalAttrs.version}"; - hash = "sha256-vFI7xKnxEoqNcBKW+FSNXHNz6g1pb2zq0eiAc5AbcQA="; + hash = "sha256-1jvUf/YsCdj/zJ+BoIv+52CobScWMlc+hIHUN9VPN04="; }; vendorHash = "sha256-mXM7c6T5qcAHez5QrmxFmGE0DLyL2RADIFTdrQaH2GQ="; From b3dddddd68de25ba409f1abdc549fa4c672cf8fd Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 31 Jul 2026 15:56:42 +0000 Subject: [PATCH 146/175] civicrm: 6.16.1 -> 6.16.2 --- pkgs/by-name/ci/civicrm/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ci/civicrm/package.nix b/pkgs/by-name/ci/civicrm/package.nix index b2e80c642a92..0d2fbef7b174 100644 --- a/pkgs/by-name/ci/civicrm/package.nix +++ b/pkgs/by-name/ci/civicrm/package.nix @@ -5,7 +5,7 @@ }: php.buildComposerProject2 (finalAttrs: { pname = "civicrm-core"; - version = "6.16.1"; + version = "6.16.2"; __structuredAttrs = true; strictDeps = true; dontUnpack = false; @@ -14,10 +14,10 @@ php.buildComposerProject2 (finalAttrs: { owner = "civicrm"; repo = "civicrm-core"; tag = finalAttrs.version; - hash = "sha256-T56hljO656dwXccSlJjGzdHlYfqMUe3Mqzr/xSF/fHE="; + hash = "sha256-aIjQ0d/JseuHQKrph5dD8juUnZa/Krh9L6vN4GUqncE="; }; - vendorHash = "sha256-PTDBSTm7C4ygF/YqV1pnHrjzfJ/Kqud1ICq1ObaledQ="; + vendorHash = "sha256-cuePs/kZx+cpCvG8r9eDmccyEFfL7G9zfD5tpzD5CJE="; installPhase = '' runHook preInstall From eee8e3f4570a84fe66caa433445de037dd2d2bb5 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 31 Jul 2026 17:24:05 +0000 Subject: [PATCH 147/175] expresslrs-configurator: 1.8.2 -> 1.8.3 --- pkgs/by-name/ex/expresslrs-configurator/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ex/expresslrs-configurator/package.nix b/pkgs/by-name/ex/expresslrs-configurator/package.nix index 11d43e3febc5..af5177cf5685 100644 --- a/pkgs/by-name/ex/expresslrs-configurator/package.nix +++ b/pkgs/by-name/ex/expresslrs-configurator/package.nix @@ -12,7 +12,7 @@ let pname = "expresslrs-configurator"; - version = "1.8.2"; + version = "1.8.3"; installPath = "share/${pname}"; resourcesPath = "${installPath}/resources"; in @@ -22,7 +22,7 @@ stdenv.mkDerivation { src = fetchzip { url = "https://github.com/ExpressLRS/ExpressLRS-Configurator/releases/download/v${version}/${pname}-${version}.zip"; stripRoot = false; - hash = "sha256-fVERT1JkXYwEqP0UJZZxT8AgkEMRzlvSqWPM4Zo9KXU="; + hash = "sha256-KoT9YoeAkYrr9FIS7+Lm1CafTNwvV+jLTYYHziCVvrs="; }; nativeBuildInputs = [ From 6ef6a0303d1f9fb0f7c8894793affcc0bb7e8a1d Mon Sep 17 00:00:00 2001 From: Austin Eschweiler Date: Fri, 31 Jul 2026 13:50:41 -0500 Subject: [PATCH 148/175] pocket-id: 2.11.0 -> 2.12.0 --- pkgs/by-name/po/pocket-id/package.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/po/pocket-id/package.nix b/pkgs/by-name/po/pocket-id/package.nix index 8168c2ed9549..f277b4114f8d 100644 --- a/pkgs/by-name/po/pocket-id/package.nix +++ b/pkgs/by-name/po/pocket-id/package.nix @@ -14,18 +14,18 @@ }: buildGo127Module (finalAttrs: { pname = "pocket-id"; - version = "2.11.0"; + version = "2.12.0"; src = fetchFromGitHub { owner = "pocket-id"; repo = "pocket-id"; tag = "v${finalAttrs.version}"; - hash = "sha256-keib2ebju6hKlH1XJQRBmXwxBsUnVZOIs+djvYkXYqU="; + hash = "sha256-n9yqZs8RlgJk+NByRJ7a+HRY4YkQNNH7xY02BSy/RhE="; }; sourceRoot = "${finalAttrs.src.name}/backend"; - vendorHash = "sha256-/5lXAnb2FHeGBgrpU4Jpt2KX+sgGyYH61odppTaulbs="; + vendorHash = "sha256-BGIF9ZhPAJrUvX1cahe3EyWM3QLIfkkZaChaBign7io="; env.CGO_ENABLED = 0; ldflags = [ @@ -67,7 +67,7 @@ buildGo127Module (finalAttrs: { inherit (finalAttrs) pname version src; pnpm = pnpm_10; fetcherVersion = 4; - hash = "sha256-aJq5yLeeHY7zlOgSr1bOJCL8e1HBwCmoL7nTD2a06tg="; + hash = "sha256-iXWR3idBiafZXCrt1M7UCJQJsA+IL2AU6pRJI7MdY1E="; }; env.BUILD_OUTPUT_PATH = "dist"; From 3f0fdbd52d93b672298ef370540945e218ddb6e2 Mon Sep 17 00:00:00 2001 From: Austin Eschweiler Date: Fri, 31 Jul 2026 13:52:24 -0500 Subject: [PATCH 149/175] pocket-id: add esch to maintainers --- pkgs/by-name/po/pocket-id/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/po/pocket-id/package.nix b/pkgs/by-name/po/pocket-id/package.nix index f277b4114f8d..c10b14930880 100644 --- a/pkgs/by-name/po/pocket-id/package.nix +++ b/pkgs/by-name/po/pocket-id/package.nix @@ -107,6 +107,7 @@ buildGo127Module (finalAttrs: { marcusramberg tmarkus ymstnt + esch ]; platforms = lib.platforms.unix; }; From 955ba5281f998413510b6297e390b988fccbf1ea Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 31 Jul 2026 20:35:12 +0000 Subject: [PATCH 150/175] nextvi: 7.0 -> 7.1 --- pkgs/by-name/ne/nextvi/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ne/nextvi/package.nix b/pkgs/by-name/ne/nextvi/package.nix index 16ecd75d1520..6f1c4b6d37a1 100644 --- a/pkgs/by-name/ne/nextvi/package.nix +++ b/pkgs/by-name/ne/nextvi/package.nix @@ -7,13 +7,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "nextvi"; - version = "7.0"; + version = "7.1"; src = fetchFromGitHub { owner = "kyx0r"; repo = "nextvi"; tag = finalAttrs.version; - hash = "sha256-corF/cPmkCkpqg2UVLrMHL33pgp3ffBohbQzq95b+Ws="; + hash = "sha256-2GvSnTV+NUACDvJq0WtpvoQpDBlPmrYBWjKsMHpVB+s="; }; nativeBuildInputs = [ installShellFiles ]; From f614e4bb2d0cc1fdef44d57dd1f9db8a5d3f323b Mon Sep 17 00:00:00 2001 From: BatteredBunny Date: Sat, 1 Aug 2026 01:05:37 +0300 Subject: [PATCH 151/175] plezy: 2.10.0 -> 2.11.0 --- pkgs/by-name/pl/plezy/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/pl/plezy/package.nix b/pkgs/by-name/pl/plezy/package.nix index ec92821157cd..9ac41d7d0bcd 100644 --- a/pkgs/by-name/pl/plezy/package.nix +++ b/pkgs/by-name/pl/plezy/package.nix @@ -27,13 +27,13 @@ let pname = "plezy"; - version = "2.10.0"; + version = "2.11.0"; src = fetchFromGitHub { owner = "edde746"; repo = "plezy"; tag = version; - hash = "sha256-82OPOad3ti+5Eec8U3vEJaAE12+ViQb+P7ZhMhEplL8="; + hash = "sha256-nv2hYuPZEUkmcM7sVzmcKZm17CHjxmEWlXLdCPKFXU0="; }; simdutf = fetchurl { @@ -146,7 +146,7 @@ let src = fetchurl { url = "https://github.com/edde746/plezy/releases/download/${version}/plezy-macos.dmg"; - hash = "sha256-lwO34G2w4hAju06z3/HwI3Tq7dHhgWZD4HxShby8OYg="; + hash = "sha256-cqanTS+PSsdtg9AF/yiVezq8ydgNfVdXEN8DHRLByM8="; }; nativeBuildInputs = [ From fb96139603f7e82a948ece76632302ec76ed8f6a Mon Sep 17 00:00:00 2001 From: Gaetan Lepage Date: Sat, 1 Aug 2026 00:04:30 +0000 Subject: [PATCH 152/175] python3Packages.trafilatura: 2.1.0 -> 2.2.0 Diff: https://github.com/adbar/trafilatura/compare/v2.1.0...v2.2.0 Changelog: https://github.com/adbar/trafilatura/blob/v2.2.0/HISTORY.md --- .../python-modules/trafilatura/default.nix | 24 +++++++------------ 1 file changed, 9 insertions(+), 15 deletions(-) diff --git a/pkgs/development/python-modules/trafilatura/default.nix b/pkgs/development/python-modules/trafilatura/default.nix index 9feb0e285720..034c72ea69c2 100644 --- a/pkgs/development/python-modules/trafilatura/default.nix +++ b/pkgs/development/python-modules/trafilatura/default.nix @@ -16,12 +16,14 @@ urllib3, # tests + addBinToPathHook, pytestCheckHook, + versionCheckHook, }: buildPythonPackage (finalAttrs: { pname = "trafilatura"; - version = "2.1.0"; + version = "2.2.0"; pyproject = true; __structuredAttrs = true; @@ -29,23 +31,11 @@ buildPythonPackage (finalAttrs: { owner = "adbar"; repo = "trafilatura"; tag = "v${finalAttrs.version}"; - hash = "sha256-hSeJH+8JX8QC3zHMZ3+M2H0C3xI+BCvLnSo/Ih1wUQw="; + hash = "sha256-U6sqUuPQZiv7VMCJ5lLJ3qqdEBq60J82nHHlGdCOyX4="; }; - postPatch = - # nixify path to the trafilatura binary in the test suite - '' - substituteInPlace tests/cli_tests.py \ - --replace-fail \ - 'trafilatura_bin = "trafilatura"' \ - 'trafilatura_bin = "${placeholder "out"}/bin/trafilatura"' - ''; - build-system = [ setuptools ]; - pythonRelaxDeps = [ - "lxml" - ]; dependencies = [ certifi charset-normalizer @@ -56,7 +46,11 @@ buildPythonPackage (finalAttrs: { urllib3 ]; - nativeCheckInputs = [ pytestCheckHook ]; + nativeCheckInputs = [ + addBinToPathHook # tests need to execute the trafilatura binary + pytestCheckHook + versionCheckHook + ]; disabledTests = [ # Disable tests that require an internet connection From ac1af7ea79ed248f59397b39ea3a0fa76924f50b Mon Sep 17 00:00:00 2001 From: Gaetan Lepage Date: Sat, 1 Aug 2026 00:24:26 +0000 Subject: [PATCH 153/175] python3Packages.pure-magic-rs: 0.3.3 -> 0.4.3 Diff: https://github.com/qjerome/magic-rs/compare/pure-magic-v0.3.3...pure-magic-rs-v0.4.3 --- .../python-modules/pure-magic-rs/default.nix | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/pkgs/development/python-modules/pure-magic-rs/default.nix b/pkgs/development/python-modules/pure-magic-rs/default.nix index 34353e6503fb..0f2f70b11575 100644 --- a/pkgs/development/python-modules/pure-magic-rs/default.nix +++ b/pkgs/development/python-modules/pure-magic-rs/default.nix @@ -8,13 +8,14 @@ buildPythonPackage (finalAttrs: { pname = "pure-magic-rs"; - version = "0.3.3"; + version = "0.4.3"; pyproject = true; + __structuredAttrs = true; src = fetchFromGitHub { owner = "qjerome"; repo = "magic-rs"; - tag = "pure-magic-v${finalAttrs.version}"; + tag = "pure-magic-rs-v${finalAttrs.version}"; hash = "sha256-cvCAiZSyB+9tNydfco9YGU5NA6Ja/SCsVeYJvuKitGo="; }; @@ -30,7 +31,9 @@ buildPythonPackage (finalAttrs: { maturinBuildHook ]; - nativeCheckInputs = [ pytestCheckHook ]; + nativeCheckInputs = [ + pytestCheckHook + ]; pythonImportsCheck = [ "pure_magic_rs" ]; @@ -39,6 +42,5 @@ buildPythonPackage (finalAttrs: { homepage = "https://github.com/qjerome/magic-rs"; license = lib.licenses.gpl3Only; maintainers = with lib.maintainers; [ fab ]; - mainProgram = "pure-magic-rs"; }; }) From 9b344f1e9488e3f5c0d5f535c0a1e84009df4422 Mon Sep 17 00:00:00 2001 From: Vinicius Deolindo Date: Fri, 31 Jul 2026 18:00:54 -0300 Subject: [PATCH 154/175] jujutsu: add `nushell` completions --- pkgs/by-name/ju/jujutsu/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/ju/jujutsu/package.nix b/pkgs/by-name/ju/jujutsu/package.nix index c8da060e028f..6fcc3e67be88 100644 --- a/pkgs/by-name/ju/jujutsu/package.nix +++ b/pkgs/by-name/ju/jujutsu/package.nix @@ -69,6 +69,7 @@ rustPlatform.buildRustPackage (finalAttrs: { installShellCompletion --cmd jj \ --bash <(COMPLETE=bash ${jj}) \ --fish <(COMPLETE=fish ${jj}) \ + --nushell <(${jj} util completion nushell) \ --zsh <(COMPLETE=zsh ${jj}) ''; From 81f9bba8b09f66044be8a5c05612e237636b1766 Mon Sep 17 00:00:00 2001 From: Vinicius Deolindo Date: Fri, 31 Jul 2026 21:43:06 -0300 Subject: [PATCH 155/175] starship: add `nushell` completions --- pkgs/by-name/st/starship/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/st/starship/package.nix b/pkgs/by-name/st/starship/package.nix index 877f887a9569..d24d03b9a61d 100644 --- a/pkgs/by-name/st/starship/package.nix +++ b/pkgs/by-name/st/starship/package.nix @@ -43,6 +43,7 @@ rustPlatform.buildRustPackage (finalAttrs: { installShellCompletion --cmd starship \ --bash <(${emulator} $out/bin/starship completions bash) \ --fish <(${emulator} $out/bin/starship completions fish) \ + --nushell <(${emulator} $out/bin/starship completions nushell) \ --zsh <(${emulator} $out/bin/starship completions zsh) '' ); From 376264ed871f6cee0d7d4063123202366694850e Mon Sep 17 00:00:00 2001 From: Vinicius Deolindo Date: Fri, 31 Jul 2026 21:43:14 -0300 Subject: [PATCH 156/175] zoxide: add `nushell` completions --- pkgs/by-name/zo/zoxide/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/zo/zoxide/package.nix b/pkgs/by-name/zo/zoxide/package.nix index 8e8eec5f254f..a9c71b308d18 100644 --- a/pkgs/by-name/zo/zoxide/package.nix +++ b/pkgs/by-name/zo/zoxide/package.nix @@ -62,6 +62,7 @@ rustPlatform.buildRustPackage (finalAttrs: { installShellCompletion --cmd zoxide \ --bash contrib/completions/zoxide.bash \ --fish contrib/completions/zoxide.fish \ + --nushell contrib/completions/zoxide.nu \ --zsh contrib/completions/_zoxide ''; From 7eba92554cf8d34c132ffd17e00281790a6b567d Mon Sep 17 00:00:00 2001 From: Adib Hanna Date: Fri, 31 Jul 2026 19:50:43 -0500 Subject: [PATCH 157/175] zennotes-desktop: 2.19.0 -> 2.20.2 --- pkgs/by-name/ze/zennotes-desktop/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/ze/zennotes-desktop/package.nix b/pkgs/by-name/ze/zennotes-desktop/package.nix index 781b64ddb7d8..8712f4d89f91 100644 --- a/pkgs/by-name/ze/zennotes-desktop/package.nix +++ b/pkgs/by-name/ze/zennotes-desktop/package.nix @@ -13,14 +13,14 @@ buildNpmPackage (finalAttrs: { pname = "zennotes-desktop"; - version = "2.19.0"; - npmDepsHash = "sha256-z1njt74VvEpxO75bprGD3/eUsv1gH2GPIz6Svye+WYg="; + version = "2.20.2"; + npmDepsHash = "sha256-xm9VdnjAxeCi/wyD/otqlv0ioqb53eORcELoyPY7PK8="; src = fetchFromGitHub { owner = "ZenNotes"; repo = "zennotes"; tag = "v${finalAttrs.version}"; - hash = "sha256-pf90wkUMIJ9wGM8JzkTWv/CipJc0cBzeSozhKdGPCGw="; + hash = "sha256-t2VCOSpdpfRIEuck3kiJ9SWcnQzYEHbPDDRhnX2l0+k="; }; npmWorkspace = "apps/desktop"; From 7abb13d34e4616a15bd42acc61cdde33f874cb59 Mon Sep 17 00:00:00 2001 From: Stzx Date: Sat, 1 Aug 2026 09:25:46 +0800 Subject: [PATCH 158/175] maintainers: add stzx --- maintainers/maintainer-list.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/maintainers/maintainer-list.nix b/maintainers/maintainer-list.nix index 6501b3cbcadc..dcc2c6cf7d6d 100644 --- a/maintainers/maintainer-list.nix +++ b/maintainers/maintainer-list.nix @@ -27284,6 +27284,12 @@ githubId = 285829; keys = [ { fingerprint = "09BE 3BAE 8D55 D4CD 8579 285A 9675 EAC3 4897 E6E2"; } ]; }; + stzx = { + name = "Stzx"; + github = "Stzx"; + githubId = 19950702; + email = "silence.m@hotmail.com"; + }; SubhrajyotiSen = { email = "subhrajyoti12@gmail.com"; github = "SubhrajyotiSen"; From f8d6e92260573ea87c24c17eeb3030c2adaa1848 Mon Sep 17 00:00:00 2001 From: Stzx Date: Sat, 1 Aug 2026 09:33:33 +0800 Subject: [PATCH 159/175] fluent-gtk-theme: add maintainer stzx --- pkgs/by-name/fl/fluent-gtk-theme/package.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/by-name/fl/fluent-gtk-theme/package.nix b/pkgs/by-name/fl/fluent-gtk-theme/package.nix index 2e76fe206f32..291ff8b304b3 100644 --- a/pkgs/by-name/fl/fluent-gtk-theme/package.nix +++ b/pkgs/by-name/fl/fluent-gtk-theme/package.nix @@ -105,6 +105,7 @@ lib.checkListOfEnum "${pname}: theme variants" maintainers = with lib.maintainers; [ luftmensch-luftmensch romildo + stzx ]; }; }) From 531718e98f4ea379f5b0da66a4b3869ea59eb13a Mon Sep 17 00:00:00 2001 From: Benedikt Ritter Date: Sat, 1 Aug 2026 09:23:12 +0200 Subject: [PATCH 160/175] nextcloudPackages: update apps --- pkgs/servers/nextcloud/packages/32.json | 12 ++++++------ pkgs/servers/nextcloud/packages/33.json | 12 ++++++------ pkgs/servers/nextcloud/packages/34.json | 12 ++++++------ 3 files changed, 18 insertions(+), 18 deletions(-) diff --git a/pkgs/servers/nextcloud/packages/32.json b/pkgs/servers/nextcloud/packages/32.json index a3384180070a..7fad4fdedad2 100644 --- a/pkgs/servers/nextcloud/packages/32.json +++ b/pkgs/servers/nextcloud/packages/32.json @@ -190,9 +190,9 @@ ] }, "integration_deepl": { - "hash": "sha256-RHYxxZw/2/uDdZdf8kGYgGBlBi1rfgXUtTtr9lgr/20=", - "url": "https://github.com/nextcloud-releases/integration_deepl/releases/download/v2.2.0/integration_deepl-v2.2.0.tar.gz", - "version": "2.2.0", + "hash": "sha256-PMK1Z3oFVkN8WtgySidCLnp+SZ3xHkPfzI2xVBfBm/k=", + "url": "https://github.com/nextcloud-releases/integration_deepl/releases/download/v2.3.0/integration_deepl-v2.3.0.tar.gz", + "version": "2.3.0", "description": "Deepl integration providing an translations through deepl.com with Nextcloud\n\nThis app integrates with [Nextcloud Assistant](https://apps.nextcloud.com/apps/assistant) to offer translation services We recommend to install Assistant additionally and activate Deepl as translation provider in the Artifical Intelligence admin settings.\n\nThis app also integrates with the translation API of Nextcloud server to offer translation services without Assistant. Currently this is available in Text and Talk.\n\nTo run translations and any other Task Processing tasks synchronously, run the following command in a background process (10 is the interval in seconds when the process should relaunch to use the latest php changes):\n\n```sh\nset -e; while true; do occ background-job:worker -v -t 10 \"OC\\TaskProcessing\\SynchronousBackgroundJob\"; done\n```\n\n## Ethical AI Rating\n### Rating: 🔴\n\nNegative:\n* the software for training and inferencing of this model is proprietary, limiting running it locally or training by yourself\n* the trained model is not freely available, so the model can not be ran on-premises\n* the training data is not freely available, limiting the ability of external parties to check and correct for bias or optimise the model’s performance and CO2 usage.\n\nLearn more about the Nextcloud Ethical AI Rating [in our blog](https://nextcloud.com/blog/nextcloud-ethical-ai-rating/).", "homepage": "https://github.com/nextcloud/integration_deepl", "licenses": [ @@ -310,9 +310,9 @@ ] }, "phonetrack": { - "hash": "sha256-bt/R1kZiTa9pWruKsAU01ni1d0AIy7vAOvIF8zwRhhw=", - "url": "https://github.com/julien-nc/phonetrack/releases/download/v1.3.1/phonetrack-1.3.1.tar.gz", - "version": "1.3.1", + "hash": "sha256-cinP3WFja6QjJYlQZcTKayHTheLjvnKY9s+CIJWKlcQ=", + "url": "https://github.com/julien-nc/phonetrack/releases/download/v1.3.2/phonetrack-1.3.2.tar.gz", + "version": "1.3.2", "description": "# PhoneTrack Nextcloud application\n\n📱 PhoneTrack is a Nextcloud application to track and store mobile device's locations.\n\n🗺 It receives information from mobile phone's logging apps and displays it dynamically on a map.\n\n🌍 Help us to translate this app on [PhoneTrack Crowdin project](https://crowdin.com/project/phonetrack).\n\n⚒ Check out other ways to help in the [contribution guidelines](https://gitlab.com/eneiluj/phonetrack-oc/blob/master/CONTRIBUTING.md).\n\nHow to use PhoneTrack :\n\n- Create a tracking session.\n- Give the logging link\\* to the mobile devices. Choose the [logging method](https://github.com/julien-nc/phonetrack/blob/main/doc/user.md#logging-methods) you prefer.\n- Watch the session's devices location in real time (or not) in PhoneTrack or share it with public pages.\n\n(\\*) Don't forget to set the device name in the link (rather than in the logging app settings). Replace \"yourname\" with the desired device name.\nSetting the device name in logging app settings only works with Owntracks, Traccar and OpenGTS.\n\nOn PhoneTrack main page, while watching a session, you can :\n\n- 📍 Display location history\n- ⛛ Filter points\n- ✎ Manually edit/add/delete points\n- ✎ Edit devices (rename, change colour/shape, move to another session)\n- ⛶ Define geofencing zones for devices\n- ⚇ Define proximity alerts for device pairs\n- 🖧 Share a session to other Nextcloud users or with a public link (read-only)\n- 🔗 Generate public share links with optional restrictions (filters, device name, last positions only, geofencing simplification)\n- 🖫 Import/export a session in GPX format (one file with one track per device or one file per device)\n- 🗠 Display sessions statistics\n- 🔒 [Reserve a device name](https://github.com/julien-nc/phonetrack/blob/main/doc/user.md#device-name-reservation) to make sure only authorized user can log with this name\n- 🗓 Toggle session auto export and auto purge (daily/weekly/monthly)\n- ◔ Choose what to do when point number quota is reached (block logging or delete oldest point)\n\nPublic page and public filtered page work like main page except there is only one session displayed, everything is read-only and there is no need to be logged in.\n\nThis app is under development.\n\n## Install\n\nSee the [AdminDoc](https://gitlab.com/eneiluj/phonetrack-oc/wikis/admindoc) for installation details.\n\nCheck [CHANGELOG](https://gitlab.com/eneiluj/phonetrack-oc/blob/master/CHANGELOG.md#change-log) file to see what's new and what's coming in next release.\n\nCheck [AUTHORS](https://gitlab.com/eneiluj/phonetrack-oc/blob/master/AUTHORS.md#authors) file to see complete list of authors.\n\n## Known issues\n\n- PhoneTrack **now works** with Nextcloud group restriction activated. See [admindoc](https://github.com/julien-nc/phonetrack/blob/main/doc/admin.md#issue-with-phonetrack-restricted-to-some-groups-in-nextcloud).\n\nAny feedback will be appreciated.\n\n\n\n## Donation\n\nI develop this app during my free time.\n\n* [Donate with Paypal](https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_button_id=66PALMY8SF5JE) (you don't need a paypal account)\n* [Donate with Liberapay : ![Donate using Liberapay](https://liberapay.com/assets/widgets/donate.svg)](https://liberapay.com/eneiluj/donate)", "homepage": "https://github.com/julien-nc/phonetrack", "licenses": [ diff --git a/pkgs/servers/nextcloud/packages/33.json b/pkgs/servers/nextcloud/packages/33.json index d604950ceeb5..e46944447184 100644 --- a/pkgs/servers/nextcloud/packages/33.json +++ b/pkgs/servers/nextcloud/packages/33.json @@ -190,9 +190,9 @@ ] }, "integration_deepl": { - "hash": "sha256-RHYxxZw/2/uDdZdf8kGYgGBlBi1rfgXUtTtr9lgr/20=", - "url": "https://github.com/nextcloud-releases/integration_deepl/releases/download/v2.2.0/integration_deepl-v2.2.0.tar.gz", - "version": "2.2.0", + "hash": "sha256-PMK1Z3oFVkN8WtgySidCLnp+SZ3xHkPfzI2xVBfBm/k=", + "url": "https://github.com/nextcloud-releases/integration_deepl/releases/download/v2.3.0/integration_deepl-v2.3.0.tar.gz", + "version": "2.3.0", "description": "Deepl integration providing an translations through deepl.com with Nextcloud\n\nThis app integrates with [Nextcloud Assistant](https://apps.nextcloud.com/apps/assistant) to offer translation services We recommend to install Assistant additionally and activate Deepl as translation provider in the Artifical Intelligence admin settings.\n\nThis app also integrates with the translation API of Nextcloud server to offer translation services without Assistant. Currently this is available in Text and Talk.\n\nTo run translations and any other Task Processing tasks synchronously, run the following command in a background process (10 is the interval in seconds when the process should relaunch to use the latest php changes):\n\n```sh\nset -e; while true; do occ background-job:worker -v -t 10 \"OC\\TaskProcessing\\SynchronousBackgroundJob\"; done\n```\n\n## Ethical AI Rating\n### Rating: 🔴\n\nNegative:\n* the software for training and inferencing of this model is proprietary, limiting running it locally or training by yourself\n* the trained model is not freely available, so the model can not be ran on-premises\n* the training data is not freely available, limiting the ability of external parties to check and correct for bias or optimise the model’s performance and CO2 usage.\n\nLearn more about the Nextcloud Ethical AI Rating [in our blog](https://nextcloud.com/blog/nextcloud-ethical-ai-rating/).", "homepage": "https://github.com/nextcloud/integration_deepl", "licenses": [ @@ -310,9 +310,9 @@ ] }, "phonetrack": { - "hash": "sha256-bt/R1kZiTa9pWruKsAU01ni1d0AIy7vAOvIF8zwRhhw=", - "url": "https://github.com/julien-nc/phonetrack/releases/download/v1.3.1/phonetrack-1.3.1.tar.gz", - "version": "1.3.1", + "hash": "sha256-cinP3WFja6QjJYlQZcTKayHTheLjvnKY9s+CIJWKlcQ=", + "url": "https://github.com/julien-nc/phonetrack/releases/download/v1.3.2/phonetrack-1.3.2.tar.gz", + "version": "1.3.2", "description": "# PhoneTrack Nextcloud application\n\n📱 PhoneTrack is a Nextcloud application to track and store mobile device's locations.\n\n🗺 It receives information from mobile phone's logging apps and displays it dynamically on a map.\n\n🌍 Help us to translate this app on [PhoneTrack Crowdin project](https://crowdin.com/project/phonetrack).\n\n⚒ Check out other ways to help in the [contribution guidelines](https://gitlab.com/eneiluj/phonetrack-oc/blob/master/CONTRIBUTING.md).\n\nHow to use PhoneTrack :\n\n- Create a tracking session.\n- Give the logging link\\* to the mobile devices. Choose the [logging method](https://github.com/julien-nc/phonetrack/blob/main/doc/user.md#logging-methods) you prefer.\n- Watch the session's devices location in real time (or not) in PhoneTrack or share it with public pages.\n\n(\\*) Don't forget to set the device name in the link (rather than in the logging app settings). Replace \"yourname\" with the desired device name.\nSetting the device name in logging app settings only works with Owntracks, Traccar and OpenGTS.\n\nOn PhoneTrack main page, while watching a session, you can :\n\n- 📍 Display location history\n- ⛛ Filter points\n- ✎ Manually edit/add/delete points\n- ✎ Edit devices (rename, change colour/shape, move to another session)\n- ⛶ Define geofencing zones for devices\n- ⚇ Define proximity alerts for device pairs\n- 🖧 Share a session to other Nextcloud users or with a public link (read-only)\n- 🔗 Generate public share links with optional restrictions (filters, device name, last positions only, geofencing simplification)\n- 🖫 Import/export a session in GPX format (one file with one track per device or one file per device)\n- 🗠 Display sessions statistics\n- 🔒 [Reserve a device name](https://github.com/julien-nc/phonetrack/blob/main/doc/user.md#device-name-reservation) to make sure only authorized user can log with this name\n- 🗓 Toggle session auto export and auto purge (daily/weekly/monthly)\n- ◔ Choose what to do when point number quota is reached (block logging or delete oldest point)\n\nPublic page and public filtered page work like main page except there is only one session displayed, everything is read-only and there is no need to be logged in.\n\nThis app is under development.\n\n## Install\n\nSee the [AdminDoc](https://gitlab.com/eneiluj/phonetrack-oc/wikis/admindoc) for installation details.\n\nCheck [CHANGELOG](https://gitlab.com/eneiluj/phonetrack-oc/blob/master/CHANGELOG.md#change-log) file to see what's new and what's coming in next release.\n\nCheck [AUTHORS](https://gitlab.com/eneiluj/phonetrack-oc/blob/master/AUTHORS.md#authors) file to see complete list of authors.\n\n## Known issues\n\n- PhoneTrack **now works** with Nextcloud group restriction activated. See [admindoc](https://github.com/julien-nc/phonetrack/blob/main/doc/admin.md#issue-with-phonetrack-restricted-to-some-groups-in-nextcloud).\n\nAny feedback will be appreciated.\n\n\n\n## Donation\n\nI develop this app during my free time.\n\n* [Donate with Paypal](https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_button_id=66PALMY8SF5JE) (you don't need a paypal account)\n* [Donate with Liberapay : ![Donate using Liberapay](https://liberapay.com/assets/widgets/donate.svg)](https://liberapay.com/eneiluj/donate)", "homepage": "https://github.com/julien-nc/phonetrack", "licenses": [ diff --git a/pkgs/servers/nextcloud/packages/34.json b/pkgs/servers/nextcloud/packages/34.json index db603b4ebe44..7556d95e2540 100644 --- a/pkgs/servers/nextcloud/packages/34.json +++ b/pkgs/servers/nextcloud/packages/34.json @@ -190,9 +190,9 @@ ] }, "integration_deepl": { - "hash": "sha256-RHYxxZw/2/uDdZdf8kGYgGBlBi1rfgXUtTtr9lgr/20=", - "url": "https://github.com/nextcloud-releases/integration_deepl/releases/download/v2.2.0/integration_deepl-v2.2.0.tar.gz", - "version": "2.2.0", + "hash": "sha256-PMK1Z3oFVkN8WtgySidCLnp+SZ3xHkPfzI2xVBfBm/k=", + "url": "https://github.com/nextcloud-releases/integration_deepl/releases/download/v2.3.0/integration_deepl-v2.3.0.tar.gz", + "version": "2.3.0", "description": "Deepl integration providing an translations through deepl.com with Nextcloud\n\nThis app integrates with [Nextcloud Assistant](https://apps.nextcloud.com/apps/assistant) to offer translation services We recommend to install Assistant additionally and activate Deepl as translation provider in the Artifical Intelligence admin settings.\n\nThis app also integrates with the translation API of Nextcloud server to offer translation services without Assistant. Currently this is available in Text and Talk.\n\nTo run translations and any other Task Processing tasks synchronously, run the following command in a background process (10 is the interval in seconds when the process should relaunch to use the latest php changes):\n\n```sh\nset -e; while true; do occ background-job:worker -v -t 10 \"OC\\TaskProcessing\\SynchronousBackgroundJob\"; done\n```\n\n## Ethical AI Rating\n### Rating: 🔴\n\nNegative:\n* the software for training and inferencing of this model is proprietary, limiting running it locally or training by yourself\n* the trained model is not freely available, so the model can not be ran on-premises\n* the training data is not freely available, limiting the ability of external parties to check and correct for bias or optimise the model’s performance and CO2 usage.\n\nLearn more about the Nextcloud Ethical AI Rating [in our blog](https://nextcloud.com/blog/nextcloud-ethical-ai-rating/).", "homepage": "https://github.com/nextcloud/integration_deepl", "licenses": [ @@ -310,9 +310,9 @@ ] }, "phonetrack": { - "hash": "sha256-bt/R1kZiTa9pWruKsAU01ni1d0AIy7vAOvIF8zwRhhw=", - "url": "https://github.com/julien-nc/phonetrack/releases/download/v1.3.1/phonetrack-1.3.1.tar.gz", - "version": "1.3.1", + "hash": "sha256-cinP3WFja6QjJYlQZcTKayHTheLjvnKY9s+CIJWKlcQ=", + "url": "https://github.com/julien-nc/phonetrack/releases/download/v1.3.2/phonetrack-1.3.2.tar.gz", + "version": "1.3.2", "description": "# PhoneTrack Nextcloud application\n\n📱 PhoneTrack is a Nextcloud application to track and store mobile device's locations.\n\n🗺 It receives information from mobile phone's logging apps and displays it dynamically on a map.\n\n🌍 Help us to translate this app on [PhoneTrack Crowdin project](https://crowdin.com/project/phonetrack).\n\n⚒ Check out other ways to help in the [contribution guidelines](https://gitlab.com/eneiluj/phonetrack-oc/blob/master/CONTRIBUTING.md).\n\nHow to use PhoneTrack :\n\n- Create a tracking session.\n- Give the logging link\\* to the mobile devices. Choose the [logging method](https://github.com/julien-nc/phonetrack/blob/main/doc/user.md#logging-methods) you prefer.\n- Watch the session's devices location in real time (or not) in PhoneTrack or share it with public pages.\n\n(\\*) Don't forget to set the device name in the link (rather than in the logging app settings). Replace \"yourname\" with the desired device name.\nSetting the device name in logging app settings only works with Owntracks, Traccar and OpenGTS.\n\nOn PhoneTrack main page, while watching a session, you can :\n\n- 📍 Display location history\n- ⛛ Filter points\n- ✎ Manually edit/add/delete points\n- ✎ Edit devices (rename, change colour/shape, move to another session)\n- ⛶ Define geofencing zones for devices\n- ⚇ Define proximity alerts for device pairs\n- 🖧 Share a session to other Nextcloud users or with a public link (read-only)\n- 🔗 Generate public share links with optional restrictions (filters, device name, last positions only, geofencing simplification)\n- 🖫 Import/export a session in GPX format (one file with one track per device or one file per device)\n- 🗠 Display sessions statistics\n- 🔒 [Reserve a device name](https://github.com/julien-nc/phonetrack/blob/main/doc/user.md#device-name-reservation) to make sure only authorized user can log with this name\n- 🗓 Toggle session auto export and auto purge (daily/weekly/monthly)\n- ◔ Choose what to do when point number quota is reached (block logging or delete oldest point)\n\nPublic page and public filtered page work like main page except there is only one session displayed, everything is read-only and there is no need to be logged in.\n\nThis app is under development.\n\n## Install\n\nSee the [AdminDoc](https://gitlab.com/eneiluj/phonetrack-oc/wikis/admindoc) for installation details.\n\nCheck [CHANGELOG](https://gitlab.com/eneiluj/phonetrack-oc/blob/master/CHANGELOG.md#change-log) file to see what's new and what's coming in next release.\n\nCheck [AUTHORS](https://gitlab.com/eneiluj/phonetrack-oc/blob/master/AUTHORS.md#authors) file to see complete list of authors.\n\n## Known issues\n\n- PhoneTrack **now works** with Nextcloud group restriction activated. See [admindoc](https://github.com/julien-nc/phonetrack/blob/main/doc/admin.md#issue-with-phonetrack-restricted-to-some-groups-in-nextcloud).\n\nAny feedback will be appreciated.\n\n\n\n## Donation\n\nI develop this app during my free time.\n\n* [Donate with Paypal](https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_button_id=66PALMY8SF5JE) (you don't need a paypal account)\n* [Donate with Liberapay : ![Donate using Liberapay](https://liberapay.com/assets/widgets/donate.svg)](https://liberapay.com/eneiluj/donate)", "homepage": "https://github.com/julien-nc/phonetrack", "licenses": [ From 0c27cbdd5cee49da38d4720be1b6a037df622517 Mon Sep 17 00:00:00 2001 From: Benedikt Ritter Date: Sat, 1 Aug 2026 09:28:52 +0200 Subject: [PATCH 161/175] nextcloudPackages: add pantry --- pkgs/servers/nextcloud/packages/32.json | 10 ++++++++++ pkgs/servers/nextcloud/packages/33.json | 10 ++++++++++ pkgs/servers/nextcloud/packages/34.json | 10 ++++++++++ pkgs/servers/nextcloud/packages/nextcloud-apps.json | 1 + 4 files changed, 31 insertions(+) diff --git a/pkgs/servers/nextcloud/packages/32.json b/pkgs/servers/nextcloud/packages/32.json index 7fad4fdedad2..afcfa4a94e7e 100644 --- a/pkgs/servers/nextcloud/packages/32.json +++ b/pkgs/servers/nextcloud/packages/32.json @@ -309,6 +309,16 @@ "agpl" ] }, + "pantry": { + "hash": "sha256-kPldsAVbpoJ+6kMWmh70j3HBTlzZibtbyr5tvT0ZcaA=", + "url": "https://github.com/chenasraf/nextcloud-pantry/releases/download/v0.24.0/pantry-v0.24.0.tar.gz", + "version": "0.24.0", + "description": "Pantry helps households stay organized in Nextcloud.\n\n- **Houses** group members and their shared data. A person can belong to multiple houses and switch between them freely.\n- **Checklists** support recurring items (e.g. milk every week) that automatically reappear when due. Share lists with the whole household so everyone knows what to pick up.\n- **Photo boards** let you keep shared reference photos organized in folders — the right brand of dog food, a favorite recipe card, a product label, and so on.\n- **Notes wall** gives the household a lightweight shared space for reminders, pinned messages, and quick notes with customizable colors.\n- **Notifications** keep everyone in the loop when photos are uploaded or notes are added or edited.\n\nAll data is scoped to a house; members only see the houses they belong to.\n\nPantry also has companion apps for mobile and desktop that let you manage your lists, photos and notes on the go and keep everything in sync with your Nextcloud instance.\n\n**Companion apps:** Android ([Google Play](https://play.google.com/store/apps/details?id=dev.casraf.pantry), [F-Droid](https://f-droid.org/en/packages/dev.casraf.pantry/)) | iOS/macOS ([App Store](https://apps.apple.com/us/app/pantry-for-nextcloud/id6762161619))", + "homepage": "https://github.com/chenasraf/nextcloud-pantry", + "licenses": [ + "agpl" + ] + }, "phonetrack": { "hash": "sha256-cinP3WFja6QjJYlQZcTKayHTheLjvnKY9s+CIJWKlcQ=", "url": "https://github.com/julien-nc/phonetrack/releases/download/v1.3.2/phonetrack-1.3.2.tar.gz", diff --git a/pkgs/servers/nextcloud/packages/33.json b/pkgs/servers/nextcloud/packages/33.json index e46944447184..2d698afffcae 100644 --- a/pkgs/servers/nextcloud/packages/33.json +++ b/pkgs/servers/nextcloud/packages/33.json @@ -309,6 +309,16 @@ "agpl" ] }, + "pantry": { + "hash": "sha256-kPldsAVbpoJ+6kMWmh70j3HBTlzZibtbyr5tvT0ZcaA=", + "url": "https://github.com/chenasraf/nextcloud-pantry/releases/download/v0.24.0/pantry-v0.24.0.tar.gz", + "version": "0.24.0", + "description": "Pantry helps households stay organized in Nextcloud.\n\n- **Houses** group members and their shared data. A person can belong to multiple houses and switch between them freely.\n- **Checklists** support recurring items (e.g. milk every week) that automatically reappear when due. Share lists with the whole household so everyone knows what to pick up.\n- **Photo boards** let you keep shared reference photos organized in folders — the right brand of dog food, a favorite recipe card, a product label, and so on.\n- **Notes wall** gives the household a lightweight shared space for reminders, pinned messages, and quick notes with customizable colors.\n- **Notifications** keep everyone in the loop when photos are uploaded or notes are added or edited.\n\nAll data is scoped to a house; members only see the houses they belong to.\n\nPantry also has companion apps for mobile and desktop that let you manage your lists, photos and notes on the go and keep everything in sync with your Nextcloud instance.\n\n**Companion apps:** Android ([Google Play](https://play.google.com/store/apps/details?id=dev.casraf.pantry), [F-Droid](https://f-droid.org/en/packages/dev.casraf.pantry/)) | iOS/macOS ([App Store](https://apps.apple.com/us/app/pantry-for-nextcloud/id6762161619))", + "homepage": "https://github.com/chenasraf/nextcloud-pantry", + "licenses": [ + "agpl" + ] + }, "phonetrack": { "hash": "sha256-cinP3WFja6QjJYlQZcTKayHTheLjvnKY9s+CIJWKlcQ=", "url": "https://github.com/julien-nc/phonetrack/releases/download/v1.3.2/phonetrack-1.3.2.tar.gz", diff --git a/pkgs/servers/nextcloud/packages/34.json b/pkgs/servers/nextcloud/packages/34.json index 7556d95e2540..fbf4bb205f2d 100644 --- a/pkgs/servers/nextcloud/packages/34.json +++ b/pkgs/servers/nextcloud/packages/34.json @@ -309,6 +309,16 @@ "agpl" ] }, + "pantry": { + "hash": "sha256-kPldsAVbpoJ+6kMWmh70j3HBTlzZibtbyr5tvT0ZcaA=", + "url": "https://github.com/chenasraf/nextcloud-pantry/releases/download/v0.24.0/pantry-v0.24.0.tar.gz", + "version": "0.24.0", + "description": "Pantry helps households stay organized in Nextcloud.\n\n- **Houses** group members and their shared data. A person can belong to multiple houses and switch between them freely.\n- **Checklists** support recurring items (e.g. milk every week) that automatically reappear when due. Share lists with the whole household so everyone knows what to pick up.\n- **Photo boards** let you keep shared reference photos organized in folders — the right brand of dog food, a favorite recipe card, a product label, and so on.\n- **Notes wall** gives the household a lightweight shared space for reminders, pinned messages, and quick notes with customizable colors.\n- **Notifications** keep everyone in the loop when photos are uploaded or notes are added or edited.\n\nAll data is scoped to a house; members only see the houses they belong to.\n\nPantry also has companion apps for mobile and desktop that let you manage your lists, photos and notes on the go and keep everything in sync with your Nextcloud instance.\n\n**Companion apps:** Android ([Google Play](https://play.google.com/store/apps/details?id=dev.casraf.pantry), [F-Droid](https://f-droid.org/en/packages/dev.casraf.pantry/)) | iOS/macOS ([App Store](https://apps.apple.com/us/app/pantry-for-nextcloud/id6762161619))", + "homepage": "https://github.com/chenasraf/nextcloud-pantry", + "licenses": [ + "agpl" + ] + }, "phonetrack": { "hash": "sha256-cinP3WFja6QjJYlQZcTKayHTheLjvnKY9s+CIJWKlcQ=", "url": "https://github.com/julien-nc/phonetrack/releases/download/v1.3.2/phonetrack-1.3.2.tar.gz", diff --git a/pkgs/servers/nextcloud/packages/nextcloud-apps.json b/pkgs/servers/nextcloud/packages/nextcloud-apps.json index af5d73fe8b4d..2e13179282ea 100644 --- a/pkgs/servers/nextcloud/packages/nextcloud-apps.json +++ b/pkgs/servers/nextcloud/packages/nextcloud-apps.json @@ -35,6 +35,7 @@ , "oidc_login": "agpl3Only" , "onlyoffice": "asl20" , "phonetrack": "agpl3Plus" +, "pantry": "agpl3Plus" , "polls": "agpl3Plus" , "previewgenerator": "agpl3Plus" , "qownnotesapi": "agpl3Plus" From 104bfcda76e65b98e6a0dec08f6a568fcf423689 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 1 Aug 2026 07:47:50 +0000 Subject: [PATCH 162/175] lianad: 14.0 -> 15.0 --- pkgs/by-name/li/lianad/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/li/lianad/package.nix b/pkgs/by-name/li/lianad/package.nix index 9930dde43f7a..7716079c5e3d 100644 --- a/pkgs/by-name/li/lianad/package.nix +++ b/pkgs/by-name/li/lianad/package.nix @@ -8,16 +8,16 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "lianad"; - version = "14.0"; # keep in sync with liana + version = "15.0"; # keep in sync with liana src = fetchFromGitHub { owner = "wizardsardine"; repo = "liana"; rev = "v${finalAttrs.version}"; - hash = "sha256-1d+icjk1NamlvEx4Xb1Ao4d1hb/t5aBwho+yCtHF9y4="; + hash = "sha256-mRBhpf4Risuq4TQ1y/5lWTOxN2RMHcZ2SC2BpbsOdhA="; }; - cargoHash = "sha256-9CWJIRby6QWJmkYSHj2lFfEj0plX5iWxsdQs5sYww7Q="; + cargoHash = "sha256-Mr6YOK7d6pfFliaiw2Mjj5wJvPk+6yH892uS7ksd4YU="; buildInputs = [ udev ]; From 4cd0c3dbfd5fcae1d25a57034aa67f4ef1efd694 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 1 Aug 2026 07:49:48 +0000 Subject: [PATCH 163/175] liana: 14.0 -> 15.0 --- pkgs/by-name/li/liana/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/li/liana/package.nix b/pkgs/by-name/li/liana/package.nix index 454696a2791b..5685bed1d2be 100644 --- a/pkgs/by-name/li/liana/package.nix +++ b/pkgs/by-name/li/liana/package.nix @@ -42,16 +42,16 @@ let in rustPlatform.buildRustPackage rec { pname = "liana"; - version = "14.0"; # keep in sync with lianad + version = "15.0"; # keep in sync with lianad src = fetchFromGitHub { owner = "wizardsardine"; repo = "liana"; tag = "v${version}"; - hash = "sha256-1d+icjk1NamlvEx4Xb1Ao4d1hb/t5aBwho+yCtHF9y4="; + hash = "sha256-mRBhpf4Risuq4TQ1y/5lWTOxN2RMHcZ2SC2BpbsOdhA="; }; - cargoHash = "sha256-9CWJIRby6QWJmkYSHj2lFfEj0plX5iWxsdQs5sYww7Q="; + cargoHash = "sha256-Mr6YOK7d6pfFliaiw2Mjj5wJvPk+6yH892uS7ksd4YU="; nativeBuildInputs = [ pkg-config From f61dc483711e5a8fcb68dd7522b9ec18d1df68da Mon Sep 17 00:00:00 2001 From: K900 Date: Sat, 1 Aug 2026 11:00:44 +0300 Subject: [PATCH 164/175] qui: 1.23.0 -> 1.24.0 --- pkgs/by-name/qu/qui/package.nix | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/pkgs/by-name/qu/qui/package.nix b/pkgs/by-name/qu/qui/package.nix index bdbf019d1f29..4c99a0ee9f18 100644 --- a/pkgs/by-name/qu/qui/package.nix +++ b/pkgs/by-name/qu/qui/package.nix @@ -14,12 +14,12 @@ }: buildGo126Module (finalAttrs: { pname = "qui"; - version = "1.23.0"; + version = "1.24.0"; src = fetchFromGitHub { owner = "autobrr"; repo = "qui"; tag = "v${finalAttrs.version}"; - hash = "sha256-RprALTd610Krh1q5yr0HIbNwb8TDbUvgbFfMMrsJT+E="; + hash = "sha256-xtYHIM1xYg92EwHndpuSRSdg8aAjNc3xaBo+Uu6Zsf4="; }; qui-web = stdenvNoCC.mkDerivation (finalAttrs': { @@ -44,7 +44,7 @@ buildGo126Module (finalAttrs: { ; pnpm = pnpm_11; fetcherVersion = 4; - hash = "sha256-aty/BRc3WqdnN3yynH4EbyledU3NtKu9E+3vP4KAdsk="; + hash = "sha256-ajnOwiMBpNesn+4F+lNpdWO7VgK7O99xITVz4NjVWTE="; }; postBuild = '' @@ -56,7 +56,7 @@ buildGo126Module (finalAttrs: { ''; }); - vendorHash = "sha256-6DX2s/y5nHYI5Jz2zs+ROGM+xk4K5yTwEwGkNiYhlcc="; + vendorHash = "sha256-GxpYkRsPUVbVK8oKwwGM+AGNvfzT2pdUadX+pAmr7Bk="; preBuild = '' cp -r ${finalAttrs.qui-web}/* web/dist From 16c0cd5ab31d394fd5d71c04f8be04ed229450d8 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 1 Aug 2026 08:04:49 +0000 Subject: [PATCH 165/175] terraform-providers.yandex-cloud_yandex: 0.218.0 -> 0.220.0 --- .../networking/cluster/terraform-providers/providers.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/applications/networking/cluster/terraform-providers/providers.json b/pkgs/applications/networking/cluster/terraform-providers/providers.json index 01bdd3cb9422..076d8bf84d7c 100644 --- a/pkgs/applications/networking/cluster/terraform-providers/providers.json +++ b/pkgs/applications/networking/cluster/terraform-providers/providers.json @@ -1508,12 +1508,12 @@ "vendorHash": "sha256-8p6dJwGyTK+qtgplSLtIRKxnNAQAgHfs4z/EsBcg/iY=" }, "yandex-cloud_yandex": { - "hash": "sha256-0155GXJMfoCnyqaJiF5SJIA1Qz1q2AYe/BB0AYODG/0=", + "hash": "sha256-0jUqljsSnNctu+5XPQGF6OE+BBZLbRoKxZLbe4/toRs=", "homepage": "https://registry.terraform.io/providers/yandex-cloud/yandex", "owner": "yandex-cloud", "repo": "terraform-provider-yandex", - "rev": "v0.218.0", + "rev": "v0.220.0", "spdx": "MPL-2.0", - "vendorHash": "sha256-FfZvuC/XXhKS03E+l4/9KCLSwx+uTP1LzywckZqX6pA=" + "vendorHash": "sha256-ZRElns36b4n5LaIIA6Snfxj15LXSVnf6o/H7lyJw3h0=" } } From b9fd5dee6ace7f73c50d292ffda4946e38a62945 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 1 Aug 2026 08:06:37 +0000 Subject: [PATCH 166/175] nvc: 1.22.0 -> 1.22.1 --- pkgs/by-name/nv/nvc/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/nv/nvc/package.nix b/pkgs/by-name/nv/nvc/package.nix index 7de8ea30d51f..a4aded1c7d37 100644 --- a/pkgs/by-name/nv/nvc/package.nix +++ b/pkgs/by-name/nv/nvc/package.nix @@ -16,13 +16,13 @@ stdenv.mkDerivation (finalAttrs: { pname = "nvc"; - version = "1.22.0"; + version = "1.22.1"; src = fetchFromGitHub { owner = "nickg"; repo = "nvc"; tag = "r${finalAttrs.version}"; - hash = "sha256-Z8N4TskOak7tU3Kp5BfUahoXsP/LnCLx5mhAuXwG7qI="; + hash = "sha256-FA9GzfwsQRI3OOJQ54H8+JbgVtIz2F4xncVDUHRzgRA="; }; nativeBuildInputs = [ From 6bc461fa522f5bbbacb414721d7537d8aac30497 Mon Sep 17 00:00:00 2001 From: Marien Zwart Date: Sat, 1 Aug 2026 17:47:55 +1000 Subject: [PATCH 167/175] emacs.pkgs.ghostel: further ease overrideAttrs of local bumps Even with the changes from https://github.com/NixOS/nixpkgs/commit/99800dd6b5955e2955848a9e0bbf95c899ccf814, local bumps break if they need a different version of Zig, like the upgrade from Zig 0.15 to 0.16 in https://github.com/NixOS/nixpkgs/commit/78f9fbc2273f534abe17222a5319b616ba946e47. Fix this by using finalAttrs for zig too, so it can be overridden along with src and zigDeps. --- .../manual-packages/ghostel/package.nix | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) diff --git a/pkgs/applications/editors/emacs/elisp-packages/manual-packages/ghostel/package.nix b/pkgs/applications/editors/emacs/elisp-packages/manual-packages/ghostel/package.nix index 91d7269be058..803ef6ee12b3 100644 --- a/pkgs/applications/editors/emacs/elisp-packages/manual-packages/ghostel/package.nix +++ b/pkgs/applications/editors/emacs/elisp-packages/manual-packages/ghostel/package.nix @@ -10,13 +10,12 @@ }: let - zig = zig_0_16; - mkModule = { pname, version, src, + zig, zigDeps, }: stdenv.mkDerivation (finalAttrs: { @@ -24,10 +23,11 @@ let pname version src + zig zigDeps ; - nativeBuildInputs = [ zig ] ++ lib.optionals stdenv.hostPlatform.isDarwin [ xcbuild ]; + nativeBuildInputs = [ finalAttrs.zig ] ++ lib.optionals stdenv.hostPlatform.isDarwin [ xcbuild ]; env.EMACS_INCLUDE_DIR = "${emacs}/include"; @@ -67,8 +67,9 @@ melpaBuild (finalAttrs: { hash = "sha256-upIcL4wf2zAc3/3QeERF619nSDml2wEZCOl6/XOaT3E="; }; - # this can be put into mkModule, but we put it here to ease user overrideAttrs - zigDeps = zig.fetchDeps { + # these can be put into mkModule, but we put them here to ease user overrideAttrs + zig = zig_0_16; + zigDeps = finalAttrs.zig.fetchDeps { inherit (finalAttrs) src pname version; fetchAll = true; hash = "sha256-NcNp0FnMy6FfZ63+pwiTRCmJ8FIovJEOhNvxVr1+uSQ="; @@ -91,6 +92,7 @@ melpaBuild (finalAttrs: { inherit (finalAttrs) version src + zig zigDeps ; }; From e3000cae3e8e5d68805b4b49d5f7d743d138161a Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 1 Aug 2026 09:26:41 +0000 Subject: [PATCH 168/175] ulid: 2.1.1 -> 2.1.2 --- pkgs/by-name/ul/ulid/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/ul/ulid/package.nix b/pkgs/by-name/ul/ulid/package.nix index dce41f939ec0..7175df47e525 100644 --- a/pkgs/by-name/ul/ulid/package.nix +++ b/pkgs/by-name/ul/ulid/package.nix @@ -7,13 +7,13 @@ buildGoModule (finalAttrs: { pname = "ulid"; - version = "2.1.1"; + version = "2.1.2"; src = fetchFromGitHub { owner = "oklog"; repo = "ulid"; tag = "v${finalAttrs.version}"; - hash = "sha256-kPNLaZMGwGc7ngPCivf/n4Bis219yOkGAaa6mt7+yTY="; + hash = "sha256-J4+O+1pQPAr+ieHBocT/AQ9kjmcU40RqRKMrS4qQxfc="; }; vendorHash = "sha256-s1YkEwFxE1zpUUCgwOAl8i6/9HB2rcGG+4kqnixTit0="; From 69d3715286395b14992870477577081ef84df4af Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 1 Aug 2026 09:33:09 +0000 Subject: [PATCH 169/175] beeper: 4.2.985 -> 4.3.0 --- pkgs/by-name/be/beeper/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/be/beeper/package.nix b/pkgs/by-name/be/beeper/package.nix index 34d47709b99e..0678725f2fe9 100644 --- a/pkgs/by-name/be/beeper/package.nix +++ b/pkgs/by-name/be/beeper/package.nix @@ -12,18 +12,18 @@ }: let pname = "beeper"; - version = "4.2.985"; + version = "4.3.0"; inherit (stdenv.hostPlatform) system; sources = { x86_64-linux = fetchurl { url = "https://beeper-desktop.download.beeper.com/builds/Beeper-${version}-x86_64.AppImage"; - hash = "sha256-oWJdpZL+Q8/jaI/WJfgXUisPASuvHkxU6rOeJkedHSM="; + hash = "sha256-/DJmQMQGzZFnONjQZ9fr9NDtGv9Kg8jF8aBzAOUyCUg="; }; aarch64-linux = fetchurl { url = "https://beeper-desktop.download.beeper.com/builds/Beeper-${version}-arm64.AppImage"; - hash = "sha256-rY302fiRG2c6dwZ+a8e43DjDUklfR0j78XTixhPkvwY="; + hash = "sha256-zZIbcE78XcXremyWjs3jsiBRTwP24y45CfZHJym8MhQ="; }; }; From 46469d8283eca468d3b4508c4b934c9013b65a26 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 1 Aug 2026 09:59:52 +0000 Subject: [PATCH 170/175] temporal-cli: 1.8.1 -> 1.8.2 --- pkgs/by-name/te/temporal-cli/package.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/by-name/te/temporal-cli/package.nix b/pkgs/by-name/te/temporal-cli/package.nix index 770420fa4da9..67d60755c1e2 100644 --- a/pkgs/by-name/te/temporal-cli/package.nix +++ b/pkgs/by-name/te/temporal-cli/package.nix @@ -11,13 +11,13 @@ buildGoModule (finalAttrs: { pname = "temporal-cli"; - version = "1.8.1"; + version = "1.8.2"; src = fetchFromGitHub { owner = "temporalio"; repo = "cli"; tag = "v${finalAttrs.version}"; - hash = "sha256-RswHPnaWN3bLerhttVb/3G//cyz9Fr+x/B4h+/SSSqA="; + hash = "sha256-OBdWQLPFvXAsbjNv/Tq+75IUl31XVtpgJVCQdHQqdBw="; }; vendorHash = "sha256-9lO9uhy1n85QYyoh27cKhdlcuL4GT98aCNWwe8tOwoQ="; From a449f1ae651ad6128c532b7a4689015c0279fdee Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 1 Aug 2026 10:27:30 +0000 Subject: [PATCH 171/175] flying-carpet: 9.0.10 -> 10.0.2 --- pkgs/by-name/fl/flying-carpet/package.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/by-name/fl/flying-carpet/package.nix b/pkgs/by-name/fl/flying-carpet/package.nix index d4cc33651216..2ceef4e10577 100644 --- a/pkgs/by-name/fl/flying-carpet/package.nix +++ b/pkgs/by-name/fl/flying-carpet/package.nix @@ -19,16 +19,16 @@ rustPlatform.buildRustPackage (finalAttrs: { pname = "flying-carpet"; - version = "9.0.10"; + version = "10.0.2"; src = fetchFromGitHub { owner = "spieglt"; repo = "FlyingCarpet"; tag = "v${finalAttrs.version}"; - hash = "sha256-7yGU4HCuP8/6UC1J6fNA5CpppJGGhS/ywThXRToDTqo="; + hash = "sha256-38gPXTP+WAZ43oVhgYEFy0lD41uV4JxlNktiD+tJOu0="; }; - cargoHash = "sha256-/Z+0hdQ1H9R7FMLunGT5WgQKFY0b0b6gzrR2CNMe2II="; + cargoHash = "sha256-WZ93Gk2n8GJox7I4o/McC0AgrBh6CZAJFcXWvALk9TM="; nativeBuildInputs = [ cargo-tauri.hook From 8dad48e06a7df8861b7ccb6ba05fbddff4270174 Mon Sep 17 00:00:00 2001 From: adisbladis Date: Sat, 1 Aug 2026 12:41:55 +0200 Subject: [PATCH 172/175] hexagonrpc: add tools output with sscregistrygen `sscregistrygen` is used to create (sensor) registry files. Put into a separate tools output to not pollute the closures of devices not needing this. --- pkgs/by-name/he/hexagonrpc/package.nix | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/pkgs/by-name/he/hexagonrpc/package.nix b/pkgs/by-name/he/hexagonrpc/package.nix index fd21a813f146..dc0346b868ef 100644 --- a/pkgs/by-name/he/hexagonrpc/package.nix +++ b/pkgs/by-name/he/hexagonrpc/package.nix @@ -4,6 +4,8 @@ fetchFromGitHub, meson, ninja, + pkg-config, + json_c, }: stdenv.mkDerivation (finalAttrs: { @@ -17,11 +19,27 @@ stdenv.mkDerivation (finalAttrs: { hash = "sha256-OC6wXBCIW4XznWG0zzxRK3BzWMVK2Jq/gTL36sJV1PE="; }; + outputs = [ + "out" + "tools" + ]; + nativeBuildInputs = [ meson ninja + pkg-config ]; + buildInputs = [ + json_c + ]; + + # sscregistrygen is only compiled when json-c is available and meson doesn't install it + postInstall = '' + mkdir -p $tools/bin + install -Dm755 tools/sscregistrygen $tools/bin/sscregistrygen + ''; + meta = { description = "Daemon to communicate with Qualcomm DSPs"; homepage = "https://github.com/linux-msm/hexagonrpc"; From 3d21f57997155dc91d20de9b2b9ba75a5ee8e819 Mon Sep 17 00:00:00 2001 From: matthewcroughan Date: Sat, 1 Aug 2026 12:05:48 +0100 Subject: [PATCH 173/175] qrtr: limit lib.platforms to aarch64-linux --- pkgs/by-name/qr/qrtr/package.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/by-name/qr/qrtr/package.nix b/pkgs/by-name/qr/qrtr/package.nix index 240dde537cdf..a777ba779e5a 100644 --- a/pkgs/by-name/qr/qrtr/package.nix +++ b/pkgs/by-name/qr/qrtr/package.nix @@ -37,6 +37,6 @@ stdenv.mkDerivation (finalAttrs: { description = "QMI IDL compiler"; homepage = "https://github.com/linux-msm/qrtr"; license = lib.licenses.bsd3; - platforms = lib.platforms.aarch64; + platforms = [ "aarch64-linux" ]; }; }) From e1060cde30ae73d0ce2f3aedcd1c2e6ace6486a6 Mon Sep 17 00:00:00 2001 From: Grimmauld Date: Sat, 1 Aug 2026 13:00:34 +0200 Subject: [PATCH 174/175] coin3d: unvendor expat closes #544607 Using the ancient vendored `expat` 2.2.10 from 2020-10-03 is a security nightmare. It also recently started exploding due to symbol collisions with the significantly newer expat used in python3, crashing FreeCAD. Co-authored-by: Patrick Lawrence --- pkgs/by-name/co/coin3d/package.nix | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/pkgs/by-name/co/coin3d/package.nix b/pkgs/by-name/co/coin3d/package.nix index c5faea3690d1..e6631df9b49d 100644 --- a/pkgs/by-name/co/coin3d/package.nix +++ b/pkgs/by-name/co/coin3d/package.nix @@ -7,6 +7,7 @@ libGL, libGLU, libx11, + expat, }: stdenv.mkDerivation (finalAttrs: { @@ -26,9 +27,14 @@ stdenv.mkDerivation (finalAttrs: { boost libGL libGLU + expat ] ++ lib.optional stdenv.hostPlatform.isLinux libx11; + cmakeFlags = [ + (lib.cmakeBool "USE_EXTERNAL_EXPAT" true) + ]; + meta = { homepage = "https://github.com/coin3d/coin"; description = "High-level, retained-mode toolkit for effective 3D graphics development"; From 9291b15f286675ea3f22ea88b511e07540c685a1 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Sat, 1 Aug 2026 11:23:12 +0000 Subject: [PATCH 175/175] code-cursor: 3.13.10 -> 3.14.7 --- pkgs/by-name/co/code-cursor/sources.json | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/pkgs/by-name/co/code-cursor/sources.json b/pkgs/by-name/co/code-cursor/sources.json index f4501132e62a..74861cfc60c6 100644 --- a/pkgs/by-name/co/code-cursor/sources.json +++ b/pkgs/by-name/co/code-cursor/sources.json @@ -1,18 +1,18 @@ { - "version": "3.13.10", + "version": "3.14.7", "vscodeVersion": "1.128.0", "sources": { "x86_64-linux": { - "url": "https://downloads.cursor.com/production/4f02290ccd9304f0e6bf8ee85f6e9106f02ac1f7/linux/x64/Cursor-3.13.10-x86_64.AppImage", - "hash": "sha256-pZq2rQnIbFLejOkK2y0GZEVRmuNKZvI+oxaviK/vpXQ=" + "url": "https://downloads.cursor.com/production/a758f2241ca99fecf380180b6cbdbbce0f1f42cf/linux/x64/Cursor-3.14.7-x86_64.AppImage", + "hash": "sha256-+nvthb0R7tvAH9t1cd4BqIrcjq16Sy2VycLWovjB2wg=" }, "aarch64-linux": { - "url": "https://downloads.cursor.com/production/4f02290ccd9304f0e6bf8ee85f6e9106f02ac1f7/linux/arm64/Cursor-3.13.10-aarch64.AppImage", - "hash": "sha256-fqQbQZqOAXxumAErlKK+1Z19mY3GitfVAwy6vNePcZA=" + "url": "https://downloads.cursor.com/production/a758f2241ca99fecf380180b6cbdbbce0f1f42cf/linux/arm64/Cursor-3.14.7-aarch64.AppImage", + "hash": "sha256-jkZyayWZ/gpHuyCjzI+RePOr4GWt2rJwkCGf4dXC1Yk=" }, "aarch64-darwin": { - "url": "https://downloads.cursor.com/production/4f02290ccd9304f0e6bf8ee85f6e9106f02ac1f7/darwin/arm64/Cursor-darwin-arm64.dmg", - "hash": "sha256-d/bdi67FN3BBjIG5GI+O2GtYUeHLKW0iZRjOGxwuS0o=" + "url": "https://downloads.cursor.com/production/a758f2241ca99fecf380180b6cbdbbce0f1f42cf/darwin/arm64/Cursor-darwin-arm64.dmg", + "hash": "sha256-mn8km5Jxswh2cKUh78tcv3+qpvgPFFffRfe0YjgiWgo=" } } }