From d49a4c10ceba6dc6e6557c735fbde99dd21bb1b6 Mon Sep 17 00:00:00 2001 From: WilliButz Date: Tue, 19 Sep 2023 14:34:49 +0200 Subject: [PATCH 01/37] nginxModules.njs: 0.7.10 -> 0.8.1 --- pkgs/servers/http/nginx/modules.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/servers/http/nginx/modules.nix b/pkgs/servers/http/nginx/modules.nix index 498119877940..13c8bd7e7c75 100644 --- a/pkgs/servers/http/nginx/modules.nix +++ b/pkgs/servers/http/nginx/modules.nix @@ -508,8 +508,8 @@ let self = { name = "njs"; src = fetchhg { url = "https://hg.nginx.org/njs"; - rev = "0.7.10"; - sha256 = "sha256-/yKzY+BUFxLk8bWo+mqKfRVRsC2moe+WvhaRYIGdr6Y="; + rev = "0.8.1"; + sha256 = "sha256-bFHrcA1ROMwYf+s0EWOXzkru6wvfRLvjvN8BV/r2tMc="; name = "nginx-njs"; }; From 02f0dc8cfff494b59cc3431cd86b9a9cf636a275 Mon Sep 17 00:00:00 2001 From: "Markus S. Wamser" Date: Sun, 23 Jul 2023 21:55:54 +0200 Subject: [PATCH 02/37] grocy: add package option apply review from @SuperSandro2000 Co-authored-by: Sandro --- nixos/modules/services/web-apps/grocy.nix | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/nixos/modules/services/web-apps/grocy.nix b/nixos/modules/services/web-apps/grocy.nix index 688367cafaf5..ba9e67f7ee2c 100644 --- a/nixos/modules/services/web-apps/grocy.nix +++ b/nixos/modules/services/web-apps/grocy.nix @@ -8,6 +8,8 @@ in { options.services.grocy = { enable = mkEnableOption (lib.mdDoc "grocy"); + package = mkPackageOptionMD pkgs "grocy" { }; + hostName = mkOption { type = types.str; description = lib.mdDoc '' @@ -135,7 +137,7 @@ in { services.nginx = { enable = true; virtualHosts."${cfg.hostName}" = mkMerge [ - { root = "${pkgs.grocy}/public"; + { root = "${cfg.package}/public"; locations."/".extraConfig = '' rewrite ^ /index.php; ''; From efeecdd66bb9527326e3abb9c614f598a1ff6b40 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 29 Sep 2023 14:28:59 +0000 Subject: [PATCH 03/37] libpsm2: 11.2.230 -> 12.0.1 --- pkgs/os-specific/linux/libpsm2/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/os-specific/linux/libpsm2/default.nix b/pkgs/os-specific/linux/libpsm2/default.nix index 683448cbe41b..0dab09de4c1c 100644 --- a/pkgs/os-specific/linux/libpsm2/default.nix +++ b/pkgs/os-specific/linux/libpsm2/default.nix @@ -2,7 +2,7 @@ stdenv.mkDerivation rec { pname = "libpsm2"; - version = "11.2.230"; + version = "12.0.1"; preConfigure= '' export UDEVDIR=$out/etc/udev @@ -30,7 +30,7 @@ stdenv.mkDerivation rec { owner = "intel"; repo = "opa-psm2"; rev = "PSM2_${version}"; - sha256 = "sha256-dMfGq067TqstGAWNSZZaZCwvChTyPUsvaPVjFGGzp64="; + sha256 = "sha256-MzocxY+X2a5rJvTo+gFU0U10YzzazR1IxzgEporJyhI="; }; postInstall = '' From 8e7b0531fa2e370641f05dcf550222605f2cf34b Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Mon, 2 Oct 2023 18:52:40 +0200 Subject: [PATCH 04/37] python311Packages.alexapy: 1.27.1 -> 1.27.2 Diff: https://gitlab.com/keatontaylor/alexapy/-/compare/refs/tags/v1.27.1...1.27.2 Changelog: https://gitlab.com/keatontaylor/alexapy/-/blob/refs/tags/v1.27.2/CHANGELOG.md --- pkgs/development/python-modules/alexapy/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/alexapy/default.nix b/pkgs/development/python-modules/alexapy/default.nix index e0326ded4b68..2d4d1bcd6bed 100644 --- a/pkgs/development/python-modules/alexapy/default.nix +++ b/pkgs/development/python-modules/alexapy/default.nix @@ -19,7 +19,7 @@ buildPythonPackage rec { pname = "alexapy"; - version = "1.27.1"; + version = "1.27.2"; format = "pyproject"; disabled = pythonOlder "3.10"; @@ -28,7 +28,7 @@ buildPythonPackage rec { owner = "keatontaylor"; repo = "alexapy"; rev = "refs/tags/v${version}"; - hash = "sha256-pMTVZ2iE/a1yNsWhmxkIQFkl18x06ZLjslj8hjKVBEA="; + hash = "sha256-tSIgpYMAs/ZndcP5uFouWWfHo5jeBLKB7lgYZ9wSht8="; }; pythonRelaxDeps = [ From 7ed04801ba75405d3bcb3850478f7faff78088c6 Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Mon, 2 Oct 2023 18:54:32 +0200 Subject: [PATCH 05/37] python311Packages.alexapy: 1.27.2 -> 1.27.3 Diff: https://gitlab.com/keatontaylor/alexapy/-/compare/refs/tags/v1.27.2...1.27.3 Changelog: https://gitlab.com/keatontaylor/alexapy/-/blob/refs/tags/v1.27.3/CHANGELOG.md --- pkgs/development/python-modules/alexapy/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/alexapy/default.nix b/pkgs/development/python-modules/alexapy/default.nix index 2d4d1bcd6bed..9e66cda3e149 100644 --- a/pkgs/development/python-modules/alexapy/default.nix +++ b/pkgs/development/python-modules/alexapy/default.nix @@ -19,7 +19,7 @@ buildPythonPackage rec { pname = "alexapy"; - version = "1.27.2"; + version = "1.27.3"; format = "pyproject"; disabled = pythonOlder "3.10"; @@ -28,7 +28,7 @@ buildPythonPackage rec { owner = "keatontaylor"; repo = "alexapy"; rev = "refs/tags/v${version}"; - hash = "sha256-tSIgpYMAs/ZndcP5uFouWWfHo5jeBLKB7lgYZ9wSht8="; + hash = "sha256-uywcJvZRd2ipg6Zh91/IOiesOOU21TZfHeeM0NMwd0Y="; }; pythonRelaxDeps = [ From 634ca1e9ce2bf39ae435480f1aa53e8b10258a46 Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Mon, 2 Oct 2023 18:54:48 +0200 Subject: [PATCH 06/37] python311Packages.alexapy: 1.27.3 -> 1.27.4 Diff: https://gitlab.com/keatontaylor/alexapy/-/compare/refs/tags/v1.27.3...v1.27.4 Changelog: https://gitlab.com/keatontaylor/alexapy/-/blob/refs/tags/v1.27.4/CHANGELOG.md --- pkgs/development/python-modules/alexapy/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/alexapy/default.nix b/pkgs/development/python-modules/alexapy/default.nix index 9e66cda3e149..bb49f93dc61b 100644 --- a/pkgs/development/python-modules/alexapy/default.nix +++ b/pkgs/development/python-modules/alexapy/default.nix @@ -19,7 +19,7 @@ buildPythonPackage rec { pname = "alexapy"; - version = "1.27.3"; + version = "1.27.4"; format = "pyproject"; disabled = pythonOlder "3.10"; @@ -28,7 +28,7 @@ buildPythonPackage rec { owner = "keatontaylor"; repo = "alexapy"; rev = "refs/tags/v${version}"; - hash = "sha256-uywcJvZRd2ipg6Zh91/IOiesOOU21TZfHeeM0NMwd0Y="; + hash = "sha256-Z7h6VX4cwcepo0Kxq9GdHv+XFNg/0s/OhJ/iHubhovs="; }; pythonRelaxDeps = [ From 3c850146ee8728f77db29bfa6554baec2d033300 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Tue, 3 Oct 2023 09:40:33 +0000 Subject: [PATCH 07/37] python310Packages.textdistance: 4.5.0 -> 4.6.0 --- pkgs/development/python-modules/textdistance/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/textdistance/default.nix b/pkgs/development/python-modules/textdistance/default.nix index 5b50bd0a3ad0..56492ac13d5e 100644 --- a/pkgs/development/python-modules/textdistance/default.nix +++ b/pkgs/development/python-modules/textdistance/default.nix @@ -2,11 +2,11 @@ buildPythonPackage rec { pname = "textdistance"; - version = "4.5.0"; + version = "4.6.0"; src = fetchPypi { inherit pname version; - hash = "sha256-Nk1D9PZjV0JmLj5s9TcqhoWUFshKPJsu+dZtRPWkOFw="; + hash = "sha256-cyxQMVzU7pRjg4ZDzxnWkiEwLDYDHqpgcMMMwKpdqMo="; }; # There aren't tests From 6608f1624a8dd9d001de8fc24baa9a2d929b0e82 Mon Sep 17 00:00:00 2001 From: Mario Rodas Date: Wed, 4 Oct 2023 04:20:00 +0000 Subject: [PATCH 08/37] terraform: 1.5.7 -> 1.6.0 Diff: https://github.com/hashicorp/terraform/compare/v1.5.7...v1.6.0 Changelog: https://github.com/hashicorp/terraform/blob/v1.6.0/CHANGELOG.md --- .../applications/networking/cluster/terraform/default.nix | 8 ++++---- pkgs/top-level/all-packages.nix | 2 +- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/pkgs/applications/networking/cluster/terraform/default.nix b/pkgs/applications/networking/cluster/terraform/default.nix index a13dbfb54363..e6c122a53910 100644 --- a/pkgs/applications/networking/cluster/terraform/default.nix +++ b/pkgs/applications/networking/cluster/terraform/default.nix @@ -53,7 +53,7 @@ let "Tool for building, changing, and versioning infrastructure"; homepage = "https://www.terraform.io/"; changelog = "https://github.com/hashicorp/terraform/blob/v${version}/CHANGELOG.md"; - license = licenses.mpl20; + license = licenses.bsl11; maintainers = with maintainers; [ Chili-Man babariviere @@ -167,9 +167,9 @@ rec { mkTerraform = attrs: pluggable (generic attrs); terraform_1 = mkTerraform { - version = "1.5.7"; - hash = "sha256-pIhwJfa71/gW7lw/KRFBO4Q5Z5YMcTt3r9kD25k8cqM="; - vendorHash = "sha256-lQgWNMBf+ioNxzAV7tnTQSIS840XdI9fg9duuwoK+U4="; + version = "1.6.0"; + hash = "sha256-R1phgtGn9hyNqa0wR1zY9uThTJSIj7TuK5ekXx48QP0="; + vendorHash = "sha256-V7S+IzHfBhIHo0xCvHJ75gOmvVbJd2k8XBdvLG1dcsc="; patches = [ ./provider-path-0_15.patch ]; passthru = { inherit plugins; diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index fb1e6b072d3a..6831319a645c 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -41320,7 +41320,7 @@ with pkgs; termpdfpy = python3Packages.callPackage ../applications/misc/termpdf.py { }; - inherit (callPackage ../applications/networking/cluster/terraform { }) + inherit (callPackage ../applications/networking/cluster/terraform { buildGoModule = buildGo121Module; }) mkTerraform terraform_1 terraform_plugins_test From 9fca3a8208f75a3e00fb98338484ddce2143ab7d Mon Sep 17 00:00:00 2001 From: Gaetan Lepage Date: Fri, 22 Sep 2023 13:56:33 +0200 Subject: [PATCH 09/37] python310Packages.numpyro: 0.13.0 -> 0.13.2 --- .../python-modules/numpyro/default.nix | 15 +++++++++++---- 1 file changed, 11 insertions(+), 4 deletions(-) diff --git a/pkgs/development/python-modules/numpyro/default.nix b/pkgs/development/python-modules/numpyro/default.nix index f301fdac7be9..612be673dbc1 100644 --- a/pkgs/development/python-modules/numpyro/default.nix +++ b/pkgs/development/python-modules/numpyro/default.nix @@ -9,19 +9,20 @@ , tqdm , funsor , pytestCheckHook -, tensorflow-probability +# TODO: uncomment when tensorflow-probability gets fixed. +# , tensorflow-probability }: buildPythonPackage rec { pname = "numpyro"; - version = "0.13.0"; + version = "0.13.2"; format = "setuptools"; disabled = pythonOlder "3.9"; src = fetchPypi { inherit version pname; - hash = "sha256-n+5K6fZlatKkXGVxzKcVhmP5XNuJeeM+GcCJ1Kh/WMk="; + hash = "sha256-Um8LFVGAlMeOaN9uMwycHJzqEnTaxp8FYXIk+m2VTug="; }; propagatedBuildInputs = [ @@ -35,7 +36,8 @@ buildPythonPackage rec { nativeCheckInputs = [ funsor pytestCheckHook - tensorflow-probability + # TODO: uncomment when tensorflow-probability gets fixed. + # tensorflow-probability ]; pythonImportsCheck = [ @@ -62,6 +64,11 @@ buildPythonPackage rec { "test_model_transformation" ]; + # TODO: remove when tensorflow-probability gets fixed. + disabledTestPaths = [ + "test/test_distributions.py" + ]; + meta = with lib; { description = "Library for probabilistic programming with NumPy"; homepage = "https://num.pyro.ai/"; From 538098877296e8038fa99a1089092e90512d6841 Mon Sep 17 00:00:00 2001 From: Maksym Balatsko Date: Thu, 5 Oct 2023 00:25:58 -0700 Subject: [PATCH 10/37] python3Packages.iisignature: init at 0.24 --- .../python-modules/iisignature/default.nix | 39 +++++++++++++++++++ pkgs/top-level/python-packages.nix | 2 + 2 files changed, 41 insertions(+) create mode 100644 pkgs/development/python-modules/iisignature/default.nix diff --git a/pkgs/development/python-modules/iisignature/default.nix b/pkgs/development/python-modules/iisignature/default.nix new file mode 100644 index 000000000000..1ddfd05b5326 --- /dev/null +++ b/pkgs/development/python-modules/iisignature/default.nix @@ -0,0 +1,39 @@ +{ lib +, buildPythonPackage +, fetchPypi +, setuptools +, wheel +, numpy +}: + +buildPythonPackage rec { + pname = "iisignature"; + version = "0.24"; + pyproject = true; + + src = fetchPypi { + inherit pname version; + hash = "sha256-C5MUxui4BIf68yMZH7NZhq1CJuhrDGfPCjspObaVucY="; + }; + + nativeBuildInputs = [ + setuptools + wheel + ]; + + propagatedBuildInputs = [ + numpy + ]; + + # PyPI tarball has no tests + doCheck = false; + + pythonImportsCheck = [ "iisignature" ]; + + meta = with lib; { + description = "Iterated integral signature calculations"; + homepage = "https://pypi.org/project/iisignature"; + license = licenses.mit; + maintainers = with maintainers; [ mbalatsko ]; + }; +} diff --git a/pkgs/top-level/python-packages.nix b/pkgs/top-level/python-packages.nix index 67ad8fc444a7..95a4be6aa7f3 100644 --- a/pkgs/top-level/python-packages.nix +++ b/pkgs/top-level/python-packages.nix @@ -5204,6 +5204,8 @@ self: super: with self; { inherit (pkgs) igraph; }; + iisignature = callPackage ../development/python-modules/iisignature { }; + ijson = callPackage ../development/python-modules/ijson { }; ilua = callPackage ../development/python-modules/ilua { }; From e4e2febd72a303341d8b8d2c38278ef1dfc8fa41 Mon Sep 17 00:00:00 2001 From: Maksym Balatsko Date: Thu, 5 Oct 2023 00:27:54 -0700 Subject: [PATCH 11/37] python3Packages.esig: init at 0.9.8.3 --- .../python-modules/esig/default.nix | 60 +++++++++++++++++++ pkgs/top-level/python-packages.nix | 2 + 2 files changed, 62 insertions(+) create mode 100644 pkgs/development/python-modules/esig/default.nix diff --git a/pkgs/development/python-modules/esig/default.nix b/pkgs/development/python-modules/esig/default.nix new file mode 100644 index 000000000000..f0183917c2c6 --- /dev/null +++ b/pkgs/development/python-modules/esig/default.nix @@ -0,0 +1,60 @@ +{ lib +, buildPythonPackage +, fetchPypi +, cmake +, ninja +, oldest-supported-numpy +, scikit-build +, setuptools +, numpy +, iisignature +, boost +}: + +buildPythonPackage rec { + pname = "esig"; + version = "0.9.8.3"; + pyproject = true; + + src = fetchPypi { + inherit pname version; + hash = "sha256-BGZaJSrpNSwZMHBYFDmDVPZOtgam/EVyh5Y5FAB8e1o="; + }; + + buildInputs = [ + boost + ]; + + dontUseCmakeConfigure = true; + + nativeBuildInputs = [ + cmake + ninja + oldest-supported-numpy + scikit-build + setuptools + ]; + + propagatedBuildInputs = [ + numpy + ]; + + passthru.optional-dependencies = { + iisignature = [ + iisignature + ]; + }; + + # PyPI tarball has no tests + doCheck = false; + + pythonImportsCheck = [ "esig" ]; + + meta = with lib; { + description = "This package provides \"rough path\" tools for analysing vector time series"; + homepage = "https://github.com/datasig-ac-uk/esig"; + changelog = "https://github.com/datasig-ac-uk/esig/blob/release/CHANGELOG"; + license = licenses.gpl3Only; + maintainers = with maintainers; [ mbalatsko ]; + }; +} diff --git a/pkgs/top-level/python-packages.nix b/pkgs/top-level/python-packages.nix index 95a4be6aa7f3..bbba31d98082 100644 --- a/pkgs/top-level/python-packages.nix +++ b/pkgs/top-level/python-packages.nix @@ -3551,6 +3551,8 @@ self: super: with self; { es-client = callPackage ../development/python-modules/es-client { }; + esig = callPackage ../development/python-modules/esig { }; + espeak-phonemizer = callPackage ../development/python-modules/espeak-phonemizer { }; esphome-dashboard-api = callPackage ../development/python-modules/esphome-dashboard-api { }; From e66ba395c4cd8afddf50cec33f11af635695f8c7 Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Thu, 5 Oct 2023 09:47:20 +0200 Subject: [PATCH 12/37] python310Packages.textdistance: add changelog to meta --- .../python-modules/textdistance/default.nix | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/textdistance/default.nix b/pkgs/development/python-modules/textdistance/default.nix index 56492ac13d5e..cc36960c952a 100644 --- a/pkgs/development/python-modules/textdistance/default.nix +++ b/pkgs/development/python-modules/textdistance/default.nix @@ -1,4 +1,7 @@ -{ lib, buildPythonPackage, fetchPypi }: +{ lib +, buildPythonPackage +, fetchPypi +}: buildPythonPackage rec { pname = "textdistance"; @@ -12,11 +15,14 @@ buildPythonPackage rec { # There aren't tests doCheck = false; - pythonImportsCheck = [ "textdistance" ]; + pythonImportsCheck = [ + "textdistance" + ]; meta = with lib; { description = "Python library for comparing distance between two or more sequences"; homepage = "https://github.com/life4/textdistance"; + changelog = "https://github.com/life4/textdistance/releases/tag/${version}"; license = licenses.mit; maintainers = with maintainers; [ ]; }; From 43e2f8dcbdcebcb30af8454ae8e4780e77585454 Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Thu, 5 Oct 2023 09:49:18 +0200 Subject: [PATCH 13/37] python310Packages.textdistance: add format - disable on unsupported Python releases --- pkgs/development/python-modules/textdistance/default.nix | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/pkgs/development/python-modules/textdistance/default.nix b/pkgs/development/python-modules/textdistance/default.nix index cc36960c952a..2c2d5ee23adf 100644 --- a/pkgs/development/python-modules/textdistance/default.nix +++ b/pkgs/development/python-modules/textdistance/default.nix @@ -1,11 +1,15 @@ { lib , buildPythonPackage , fetchPypi +, pythonOlder }: buildPythonPackage rec { pname = "textdistance"; version = "4.6.0"; + format = "setuptools"; + + disabled = pythonOlder "3.7"; src = fetchPypi { inherit pname version; From b17c0fc96aee62110080956d00367e28d1e7b117 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Christina=20S=C3=B8rensen?= Date: Thu, 5 Oct 2023 15:55:49 +0200 Subject: [PATCH 14/37] kitty: 0.30.0 -> 0.30.1 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Signed-off-by: Christina Sørensen --- pkgs/applications/terminal-emulators/kitty/default.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/applications/terminal-emulators/kitty/default.nix b/pkgs/applications/terminal-emulators/kitty/default.nix index 1c1f87e1a407..f120b5290ec1 100644 --- a/pkgs/applications/terminal-emulators/kitty/default.nix +++ b/pkgs/applications/terminal-emulators/kitty/default.nix @@ -29,20 +29,20 @@ with python3Packages; buildPythonApplication rec { pname = "kitty"; - version = "0.30.0"; + version = "0.30.1"; format = "other"; src = fetchFromGitHub { owner = "kovidgoyal"; repo = "kitty"; rev = "refs/tags/v${version}"; - hash = "sha256-M6qFkeUp2rBudO2PiLN2VSrmut68c9mjjUr07WEX9VY="; + hash = "sha256-zjXwiRo6Jw3K0iDf05f04MCtg1qKABah7x07CwvW0/0="; }; goModules = (buildGoModule { pname = "kitty-go-modules"; inherit src version; - vendorHash = "sha256-53Y2S/P2fWT9STZFTdlkESxHNpoAggifZJ0+WXCzbkU="; + vendorHash = "sha256-KDqzcJbI2f91wlrjVWgUmut4nhXA/rO9q5q3FaDWnfc="; }).goModules; buildInputs = [ From ea920c499a1c5d8ee07fc6fa4732de54952e33e0 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 5 Oct 2023 16:42:08 +0000 Subject: [PATCH 15/37] python310Packages.parver: 0.4 -> 0.5 --- pkgs/development/python-modules/parver/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/parver/default.nix b/pkgs/development/python-modules/parver/default.nix index d69a9a54e501..b18d7db34766 100644 --- a/pkgs/development/python-modules/parver/default.nix +++ b/pkgs/development/python-modules/parver/default.nix @@ -13,12 +13,12 @@ buildPythonPackage rec { pname = "parver"; - version = "0.4"; + version = "0.5"; format = "pyproject"; src = fetchPypi { inherit pname version; - hash = "sha256-1KPbuTxTNz7poLoFXkhYxEFpsgS5EuSdAD6tlduam8o="; + hash = "sha256-uf3h5ruc6fB+COnEvqjYglxeeOGKAFLQLgK/lRfrR3c="; }; nativeBuildInputs = [ From 440959cbbc3e68fa0cdedf15efcf80e27f00b2ce Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Thu, 5 Oct 2023 18:57:00 +0200 Subject: [PATCH 16/37] python311Packages.alexapy: update changelog entry --- pkgs/development/python-modules/alexapy/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/alexapy/default.nix b/pkgs/development/python-modules/alexapy/default.nix index bb49f93dc61b..2aeebd0239f7 100644 --- a/pkgs/development/python-modules/alexapy/default.nix +++ b/pkgs/development/python-modules/alexapy/default.nix @@ -20,7 +20,7 @@ buildPythonPackage rec { pname = "alexapy"; version = "1.27.4"; - format = "pyproject"; + pyproject = true; disabled = pythonOlder "3.10"; @@ -64,7 +64,7 @@ buildPythonPackage rec { meta = with lib; { description = "Python Package for controlling Alexa devices (echo dot, etc) programmatically"; homepage = "https://gitlab.com/keatontaylor/alexapy"; - changelog = "https://gitlab.com/keatontaylor/alexapy/-/blob/${src.rev}/CHANGELOG.md"; + changelog = "https://gitlab.com/keatontaylor/alexapy/-/blob/v${version}/CHANGELOG.md"; license = licenses.asl20; maintainers = with maintainers; [ fab ]; }; From 7a38549748580452148e6f08e55be27d5e816208 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 5 Oct 2023 18:11:31 +0000 Subject: [PATCH 17/37] python310Packages.django-reversion: 5.0.5 -> 5.0.6 --- pkgs/development/python-modules/django-reversion/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/django-reversion/default.nix b/pkgs/development/python-modules/django-reversion/default.nix index e85e89e2b6c9..8dd590611c99 100644 --- a/pkgs/development/python-modules/django-reversion/default.nix +++ b/pkgs/development/python-modules/django-reversion/default.nix @@ -7,14 +7,14 @@ buildPythonPackage rec { pname = "django-reversion"; - version = "5.0.5"; + version = "5.0.6"; format = "setuptools"; disabled = pythonOlder "3.7"; src = fetchPypi { inherit pname version; - hash = "sha256-JTxpGwpOC+He7Atiw4yfu3W25aj9gdO1iib0YTWXAQY="; + hash = "sha256-buJalwcN2hTz4IK4uZm/vstKnwgv8fhR40TQVqGMk0w="; }; propagatedBuildInputs = [ From 09325d24b685a3ab5507dc906ab4019696d33d59 Mon Sep 17 00:00:00 2001 From: edef Date: Wed, 4 Oct 2023 19:16:06 +0000 Subject: [PATCH 18/37] nixos/security/wrappers: use musl rather than glibc and explicitly unset insecure env vars This mitigates CVE-2023-4911, crucially without a mass-rebuild. We drop insecure environment variables explicitly, including glibc-specific ones, since musl doesn't do this by default. Change-Id: I591a817e6d4575243937d9ccab51c23a96bed6f9 --- nixos/modules/security/wrappers/default.nix | 23 +++++++++- nixos/modules/security/wrappers/wrapper.c | 49 +++++++++++++++++++++ nixos/modules/security/wrappers/wrapper.nix | 4 +- 3 files changed, 73 insertions(+), 3 deletions(-) diff --git a/nixos/modules/security/wrappers/default.nix b/nixos/modules/security/wrappers/default.nix index ad65f80bb2ca..a8bb0650b11a 100644 --- a/nixos/modules/security/wrappers/default.nix +++ b/nixos/modules/security/wrappers/default.nix @@ -5,8 +5,29 @@ let parentWrapperDir = dirOf wrapperDir; - securityWrapper = sourceProg : pkgs.callPackage ./wrapper.nix { + # This is security-sensitive code, and glibc vulns happen from time to time. + # musl is security-focused and generally more minimal, so it's a better choice here. + # The dynamic linker is still a fairly complex piece of code, and the wrappers are + # quite small, so linking it statically is more appropriate. + securityWrapper = sourceProg : pkgs.pkgsStatic.callPackage ./wrapper.nix { inherit sourceProg; + + # glibc definitions of insecure environment variables + # + # We extract the single header file we need into its own derivation, + # so that we don't have to pull full glibc sources to build wrappers. + # + # They're taken from pkgs.glibc so that we don't have to keep as close + # an eye on glibc changes. Not every relevant variable is in this header, + # so we maintain a slightly stricter list in wrapper.c itself as well. + unsecvars = lib.overrideDerivation (pkgs.srcOnly pkgs.glibc) + ({ name, ... }: { + name = "${name}-unsecvars"; + installPhase = '' + mkdir $out + cp sysdeps/generic/unsecvars.h $out + ''; + }); }; fileModeType = diff --git a/nixos/modules/security/wrappers/wrapper.c b/nixos/modules/security/wrappers/wrapper.c index 2cf1727a31c8..cf19c7a4aa45 100644 --- a/nixos/modules/security/wrappers/wrapper.c +++ b/nixos/modules/security/wrappers/wrapper.c @@ -17,6 +17,9 @@ #include #include +// imported from glibc +#include "unsecvars.h" + #ifndef SOURCE_PROG #error SOURCE_PROG should be defined via preprocessor commandline #endif @@ -151,9 +154,55 @@ static int make_caps_ambient(const char *self_path) { return 0; } +// These are environment variable aliases for glibc tunables. +// This list shouldn't grow further, since this is a legacy mechanism. +// Any future tunables are expected to only be accessible through GLIBC_TUNABLES. +// +// They are not included in the glibc-provided UNSECURE_ENVVARS list, +// since any SUID executable ignores them. This wrapper also serves +// executables that are merely granted ambient capabilities, rather than +// being SUID, and hence don't run in secure mode. We'd like them to +// defend those in depth as well, so we clear these explicitly. +// +// Except for MALLOC_CHECK_ (which is marked SXID_ERASE), these are all +// marked SXID_IGNORE (ignored in secure mode), so even the glibc version +// of this wrapper would leave them intact. +#define UNSECURE_ENVVARS_TUNABLES \ + "MALLOC_CHECK_\0" \ + "MALLOC_TOP_PAD_\0" \ + "MALLOC_PERTURB_\0" \ + "MALLOC_MMAP_THRESHOLD_\0" \ + "MALLOC_TRIM_THRESHOLD_\0" \ + "MALLOC_MMAP_MAX_\0" \ + "MALLOC_ARENA_MAX\0" \ + "MALLOC_ARENA_TEST\0" + int main(int argc, char **argv) { ASSERT(argc >= 1); + int debug = getenv(wrapper_debug) != NULL; + + // Drop insecure environment variables explicitly + // + // glibc does this automatically in SUID binaries, but we'd like to cover this: + // + // a) before it gets to glibc + // b) in binaries that are only granted ambient capabilities by the wrapper, + // but don't run with an altered effective UID/GID, nor directly gain + // capabilities themselves, and thus don't run in secure mode. + // + // We're using musl, which doesn't drop environment variables in secure mode, + // and we'd also like glibc-specific variables to be covered. + // + // If we don't explicitly unset them, it's quite easy to just set LD_PRELOAD, + // have it passed through to the wrapped program, and gain privileges. + for (char *unsec = UNSECURE_ENVVARS_TUNABLES UNSECURE_ENVVARS; *unsec; unsec = strchr(unsec, 0) + 1) { + if (debug) { + fprintf(stderr, "unsetting %s\n", unsec); + } + unsetenv(unsec); + } + // Read the capabilities set on the wrapper and raise them in to // the ambient set so the program we're wrapping receives the // capabilities too! diff --git a/nixos/modules/security/wrappers/wrapper.nix b/nixos/modules/security/wrappers/wrapper.nix index aec43412404e..da2fca98d5c5 100644 --- a/nixos/modules/security/wrappers/wrapper.nix +++ b/nixos/modules/security/wrappers/wrapper.nix @@ -1,4 +1,4 @@ -{ stdenv, linuxHeaders, sourceProg, debug ? false }: +{ stdenv, unsecvars, linuxHeaders, sourceProg, debug ? false }: # For testing: # $ nix-build -E 'with import {}; pkgs.callPackage ./wrapper.nix { parentWrapperDir = "/run/wrappers"; debug = true; }' stdenv.mkDerivation { @@ -16,6 +16,6 @@ stdenv.mkDerivation { dontStrip = debug; installPhase = '' mkdir -p $out/bin - $CC $CFLAGS ${./wrapper.c} -o $out/bin/security-wrapper + $CC $CFLAGS ${./wrapper.c} -I${unsecvars} -o $out/bin/security-wrapper ''; } From 41544a6e04f06182b7fd75729121e260c74fb477 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Thu, 5 Oct 2023 22:29:20 +0000 Subject: [PATCH 19/37] python310Packages.google-cloud-container: 2.31.0 -> 2.32.0 --- .../python-modules/google-cloud-container/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/google-cloud-container/default.nix b/pkgs/development/python-modules/google-cloud-container/default.nix index a79c74b3de08..2ee87fac60c2 100644 --- a/pkgs/development/python-modules/google-cloud-container/default.nix +++ b/pkgs/development/python-modules/google-cloud-container/default.nix @@ -13,14 +13,14 @@ buildPythonPackage rec { pname = "google-cloud-container"; - version = "2.31.0"; + version = "2.32.0"; format = "setuptools"; disabled = pythonOlder "3.7"; src = fetchPypi { inherit pname version; - hash = "sha256-PGrG29a5tq41hn8zzJWdAy4Dju1O5ZPYhZ+CcsBraAY="; + hash = "sha256-aU+42neWNlPhxw+mCSi0oR+vjh8VgKOQJQU6PhvM5t4="; }; propagatedBuildInputs = [ From 55384de7da9c3840fa9c2bc2bc8e61034777d02b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Stanis=C5=82aw=20Pitucha?= Date: Fri, 6 Oct 2023 09:45:07 +1100 Subject: [PATCH 20/37] libsmi: fix missing declaration for new clang --- pkgs/development/libraries/libsmi/default.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/pkgs/development/libraries/libsmi/default.nix b/pkgs/development/libraries/libsmi/default.nix index 9b71a91efed2..14139d849dc7 100644 --- a/pkgs/development/libraries/libsmi/default.nix +++ b/pkgs/development/libraries/libsmi/default.nix @@ -9,6 +9,8 @@ stdenv.mkDerivation rec { sha256 = "1lslaxr2qcj6hf4naq5n5mparfhmswsgq4wa7zm2icqvvgdcq6pj"; }; + env.NIX_CFLAGS_COMPILE = "-std=gnu90"; + meta = with lib; { description = "A Library to Access SMI MIB Information"; homepage = "https://www.ibr.cs.tu-bs.de/projects/libsmi/index.html"; From cfaec23b23d9660eaa704a157693d0314f8de195 Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 6 Oct 2023 00:22:07 +0000 Subject: [PATCH 21/37] python310Packages.junos-eznc: 2.6.7 -> 2.6.8 --- pkgs/development/python-modules/junos-eznc/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/junos-eznc/default.nix b/pkgs/development/python-modules/junos-eznc/default.nix index d50dd571764b..e6499c5196d1 100644 --- a/pkgs/development/python-modules/junos-eznc/default.nix +++ b/pkgs/development/python-modules/junos-eznc/default.nix @@ -22,7 +22,7 @@ buildPythonPackage rec { pname = "junos-eznc"; - version = "2.6.7"; + version = "2.6.8"; format = "setuptools"; disabled = pythonOlder "3.7"; @@ -31,7 +31,7 @@ buildPythonPackage rec { owner = "Juniper"; repo = "py-junos-eznc"; rev = "refs/tags/${version}"; - hash = "sha256-+hGybznip5RpJm89MLg9JO4B/y50OIdgtmV2FIpZShU="; + hash = "sha256-5xZjuU2U3BodAMQiWZIJ27AZiAwoMm4yJ4qr3DjMd9o="; }; postPatch = '' From 588d774bc96328e8568e1c278dff1edc3ad6156b Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 6 Oct 2023 02:09:20 +0000 Subject: [PATCH 22/37] python310Packages.magic-filter: 1.0.11 -> 1.0.12 --- pkgs/development/python-modules/magic-filter/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/magic-filter/default.nix b/pkgs/development/python-modules/magic-filter/default.nix index bf85abee73c8..e9d2fb8b8696 100644 --- a/pkgs/development/python-modules/magic-filter/default.nix +++ b/pkgs/development/python-modules/magic-filter/default.nix @@ -8,7 +8,7 @@ buildPythonPackage rec { pname = "magic-filter"; - version = "1.0.11"; + version = "1.0.12"; format = "pyproject"; disabled = pythonOlder "3.7"; @@ -17,7 +17,7 @@ buildPythonPackage rec { owner = "aiogram"; repo = "magic-filter"; rev = "refs/tags/v${version}"; - hash = "sha256-mfSq47UWOLyEDkAsdHsJuVl/rJ4KgiGPpDL7qSKEfws="; + hash = "sha256-MSYIZ/bzngRu6mG3EGblUotSCA+6bi+l3EymFA8NRZA="; }; nativeBuildInputs = [ From 4f4086ab6af903f49d79592a6d067519ae1eb10b Mon Sep 17 00:00:00 2001 From: "R. Ryantm" Date: Fri, 6 Oct 2023 02:58:04 +0000 Subject: [PATCH 23/37] wch-isp: 0.2.5 -> 0.3.0 --- pkgs/development/embedded/wch-isp/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/embedded/wch-isp/default.nix b/pkgs/development/embedded/wch-isp/default.nix index a08afa5729af..4bc2e0615724 100644 --- a/pkgs/development/embedded/wch-isp/default.nix +++ b/pkgs/development/embedded/wch-isp/default.nix @@ -2,13 +2,13 @@ stdenv.mkDerivation rec { pname = "wch-isp"; - version = "0.2.5"; + version = "0.3.0"; src = fetchFromGitHub { owner = "jmaselbas"; repo = pname; rev = "v${version}"; - hash = "sha256-JF1g2Qb1gG93lSaDQvltT6jCYk/dKntsIJPkQXYUvX4="; + hash = "sha256-cbQJgHZAdSfzRsf/srMlRd+QgGUPpP5r3kBTNCgINDw="; }; nativeBuildInputs = [ pkg-config ]; From fc096a6d9cd3736df7ea1ce9b369ccfeedf07746 Mon Sep 17 00:00:00 2001 From: Bobby Rong Date: Fri, 6 Oct 2023 11:40:20 +0800 Subject: [PATCH 24/37] nixosTests.gnome-flashback: Fix eval The option `nodes.machine.environment.variables.XDG_CONFIG_DIRS' is defined multiple times while it's expected to be unique. --- nixos/modules/services/x11/desktop-managers/gnome.nix | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/nixos/modules/services/x11/desktop-managers/gnome.nix b/nixos/modules/services/x11/desktop-managers/gnome.nix index a5c7cb16b9d3..ce8f2548a5ad 100644 --- a/nixos/modules/services/x11/desktop-managers/gnome.nix +++ b/nixos/modules/services/x11/desktop-managers/gnome.nix @@ -307,10 +307,9 @@ in gnome-flashback ] ++ map gnome-flashback.mkSystemdTargetForWm flashbackWms; - # gnome-panel needs these for menu applet - environment.sessionVariables.XDG_DATA_DIRS = [ "${pkgs.gnome.gnome-flashback}/share" ]; - # TODO: switch to sessionVariables (resolve conflict) - environment.variables.XDG_CONFIG_DIRS = [ "${pkgs.gnome.gnome-flashback}/etc/xdg" ]; + environment.systemPackages = with pkgs.gnome; [ + gnome-flashback + ]; }) (mkIf serviceCfg.core-os-services.enable { From bdd178b581e74b53a9e4480bb7f842578178373d Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Fri, 6 Oct 2023 08:04:52 +0200 Subject: [PATCH 25/37] checkov: 2.5.4 -> 2.5.6 Diff: https://github.com/bridgecrewio/checkov/compare/refs/tags/2.5.4...2.5.6 Changelog: https://github.com/bridgecrewio/checkov/releases/tag/2.5.6 --- pkgs/development/tools/analysis/checkov/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/tools/analysis/checkov/default.nix b/pkgs/development/tools/analysis/checkov/default.nix index e4ef7b483497..11332fc835f6 100644 --- a/pkgs/development/tools/analysis/checkov/default.nix +++ b/pkgs/development/tools/analysis/checkov/default.nix @@ -22,14 +22,14 @@ with py.pkgs; buildPythonApplication rec { pname = "checkov"; - version = "2.5.4"; + version = "2.5.6"; format = "setuptools"; src = fetchFromGitHub { owner = "bridgecrewio"; repo = pname; rev = "refs/tags/${version}"; - hash = "sha256-Rp1Q486vbgZmWcxQNy1esRYl0HRWQonicNP0bYdqPtc="; + hash = "sha256-X+JEhoFKT+nxgxABojC8jZiGp8bubJWi0qWNfU9kwDc="; }; patches = [ From 61a4911e6886884dc1ec80b80ccb615bfe5dd93f Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Fri, 6 Oct 2023 08:07:25 +0200 Subject: [PATCH 26/37] memray: 1.9.1 -> 1.10.0 Changelog: https://github.com/bloomberg/memray/releases/tag/1.10.0 --- pkgs/development/tools/memray/default.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/development/tools/memray/default.nix b/pkgs/development/tools/memray/default.nix index 438383ef8633..1a7fb2a91dcc 100644 --- a/pkgs/development/tools/memray/default.nix +++ b/pkgs/development/tools/memray/default.nix @@ -8,13 +8,13 @@ python3.pkgs.buildPythonApplication rec { pname = "memray"; - version = "1.9.1"; + version = "1.10.0"; format = "setuptools"; src = fetchFromGitHub { owner = "bloomberg"; repo = pname; - rev = "refs/tags/v${version}"; + rev = "refs/tags/${version}"; hash = "sha256-DaJ1Hhg7q4ckA5feUx0twOsmy28v5aBBCTUAkn43xAo="; }; @@ -66,6 +66,6 @@ python3.pkgs.buildPythonApplication rec { license = licenses.asl20; maintainers = with maintainers; [ fab ]; platforms = platforms.linux; - changelog = "https://github.com/bloomberg/memray/releases/tag/v${version}"; + changelog = "https://github.com/bloomberg/memray/releases/tag/${version}"; }; } From 794774b837b7c7cda86ab3da9458da272314478f Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Fri, 6 Oct 2023 08:08:34 +0200 Subject: [PATCH 27/37] python311Packages.pyfibaro: 0.7.4 -> 0.7.5 Diff: https://github.com/rappenze/pyfibaro/compare/refs/tags/0.7.4...0.7.5 Changelog: https://github.com/rappenze/pyfibaro/releases/tag/0.7.5 --- pkgs/development/python-modules/pyfibaro/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/pyfibaro/default.nix b/pkgs/development/python-modules/pyfibaro/default.nix index 534181c6e4df..b1a38f11f6ac 100644 --- a/pkgs/development/python-modules/pyfibaro/default.nix +++ b/pkgs/development/python-modules/pyfibaro/default.nix @@ -11,7 +11,7 @@ buildPythonPackage rec { pname = "pyfibaro"; - version = "0.7.4"; + version = "0.7.5"; format = "pyproject"; disabled = pythonOlder "3.9"; @@ -20,7 +20,7 @@ buildPythonPackage rec { owner = "rappenze"; repo = pname; rev = "refs/tags/${version}"; - hash = "sha256-Z+JWwu40ober/9RNG9DLqlOlQyPwlAO3LhLnpr+4dL8="; + hash = "sha256-hllYxPPbLu3dpjHwXfIvTMW0LWtcglTVfN7youZaXTw="; }; nativeBuildInputs = [ From d6da67d4c9cf5942a4f9bf64aa8c60ec91ccf5db Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Fri, 6 Oct 2023 08:09:12 +0200 Subject: [PATCH 28/37] python311Packages.whodap: 0.1.9 -> 0.1.10 Diff: https://github.com/pogzyb/whodap/compare/refs/tags/v0.1.9...v0.1.10 Changelog: https://github.com/pogzyb/whodap/releases/tag/v0.1.10 --- pkgs/development/python-modules/whodap/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/whodap/default.nix b/pkgs/development/python-modules/whodap/default.nix index a666d0a156b5..a322c327b230 100644 --- a/pkgs/development/python-modules/whodap/default.nix +++ b/pkgs/development/python-modules/whodap/default.nix @@ -9,7 +9,7 @@ buildPythonPackage rec { pname = "whodap"; - version = "0.1.9"; + version = "0.1.10"; format = "setuptools"; disabled = pythonOlder "3.8"; @@ -18,7 +18,7 @@ buildPythonPackage rec { owner = "pogzyb"; repo = pname; rev = "refs/tags/v${version}"; - hash = "sha256-0Wxx33AO9g4ACAUwkFkLo2AemK7PxXvZXWgHpu+E96c="; + hash = "sha256-5XDTl8NPrYWs7gPTJRDVCiZN3cWQ53/ojhJivBPHUL0="; }; propagatedBuildInputs = [ From 9c8e91a6203338ceecf3dccfed7059f7ff30eeda Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Fri, 6 Oct 2023 08:13:39 +0200 Subject: [PATCH 29/37] python310Packages.django-reversion: add changelog to meta --- pkgs/development/python-modules/django-reversion/default.nix | 1 + 1 file changed, 1 insertion(+) diff --git a/pkgs/development/python-modules/django-reversion/default.nix b/pkgs/development/python-modules/django-reversion/default.nix index 8dd590611c99..2559cc1fbf5c 100644 --- a/pkgs/development/python-modules/django-reversion/default.nix +++ b/pkgs/development/python-modules/django-reversion/default.nix @@ -31,6 +31,7 @@ src = fetchPypi { meta = with lib; { description = "An extension to the Django web framework that provides comprehensive version control facilities"; homepage = "https://github.com/etianen/django-reversion"; + changelog = "https://github.com/etianen/django-reversion/blob/v${version}/CHANGELOG.rst"; license = licenses.bsd3; maintainers = with maintainers; [ ]; }; From 7e75e4954b0d1cc14a921f1a1e921f1cde3a46a6 Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Fri, 6 Oct 2023 08:18:58 +0200 Subject: [PATCH 30/37] python311Packages.camel-converter: 3.0.2 -> 3.0.3 Diff: https://github.com/sanders41/camel-converter/compare/refs/tags/v3.0.2...v3.0.3 Changelog: https://github.com/sanders41/camel-converter/releases/tag/v3.0.3 --- pkgs/development/python-modules/camel-converter/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/camel-converter/default.nix b/pkgs/development/python-modules/camel-converter/default.nix index cc9c345d3fb0..176c49819dbf 100644 --- a/pkgs/development/python-modules/camel-converter/default.nix +++ b/pkgs/development/python-modules/camel-converter/default.nix @@ -9,7 +9,7 @@ buildPythonPackage rec { pname = "camel-converter"; - version = "3.0.2"; + version = "3.0.3"; format = "pyproject"; disabled = pythonOlder "3.8"; @@ -18,7 +18,7 @@ buildPythonPackage rec { owner = "sanders41"; repo = pname; rev = "refs/tags/v${version}"; - hash = "sha256-XKtWR9dmSMfqkJYUHDQtWBLG3CHrbrI5lNtPUTShmBE="; + hash = "sha256-0sNb1zg8cnDjQQnStfe1k8uB1GpmNtd/VwqSqTcLmj0="; }; postPatch = '' From 8bf81e231ccbdd5112455128e4ddcb384b720cec Mon Sep 17 00:00:00 2001 From: Fabian Affolter Date: Fri, 6 Oct 2023 08:20:12 +0200 Subject: [PATCH 31/37] python311Packages.garth: 0.4.37 -> 0.4.38 --- pkgs/development/python-modules/garth/default.nix | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pkgs/development/python-modules/garth/default.nix b/pkgs/development/python-modules/garth/default.nix index 92ce1294388e..45ba76913a32 100644 --- a/pkgs/development/python-modules/garth/default.nix +++ b/pkgs/development/python-modules/garth/default.nix @@ -12,14 +12,14 @@ buildPythonPackage rec { pname = "garth"; - version = "0.4.37"; + version = "0.4.38"; format = "pyproject"; disabled = pythonOlder "3.9"; src = fetchPypi { inherit pname version; - hash = "sha256-7mq661cW67EvvJ1s2W5Ybw+oiDz9vdmmt/ljt/llIoo="; + hash = "sha256-c+wSXADcgl7DpJJxGUus3oA4v+DmjGwjKfp0tJbcxb8="; }; nativeBuildInputs = [ From 4b58af2fcb4199e8d4e36584701cd6eac0e0b78f Mon Sep 17 00:00:00 2001 From: David Knaack Date: Mon, 25 Sep 2023 15:06:51 +0200 Subject: [PATCH 32/37] gitoxide: 0.29.0 -> 0.30.0 --- pkgs/applications/version-management/gitoxide/default.nix | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pkgs/applications/version-management/gitoxide/default.nix b/pkgs/applications/version-management/gitoxide/default.nix index 21f4d870894e..64efc4731a17 100644 --- a/pkgs/applications/version-management/gitoxide/default.nix +++ b/pkgs/applications/version-management/gitoxide/default.nix @@ -13,16 +13,16 @@ rustPlatform.buildRustPackage rec { pname = "gitoxide"; - version = "0.29.0"; + version = "0.30.0"; src = fetchFromGitHub { owner = "Byron"; repo = "gitoxide"; rev = "v${version}"; - hash = "sha256-Ry5QvOoj4iSQZr1O+Y6qSHzhmm77nbkLjCcdPOhxR18="; + hash = "sha256-VJZwNLFePUNIRHEyiEr1tiLaB2tuL6Ah81LNuM/1H14="; }; - cargoHash = "sha256-WZctsAxGojrGufF8CwUiw1xWzn9qVZUphDE3KmGTGy4="; + cargoHash = "sha256-vEp0wLxmmmv33oRO7eOxOoOsV87/7DQ8db5RUfqUb88="; nativeBuildInputs = [ cmake pkg-config ]; From 190a819ecb16f39f349dbb34b7f50527c56e86c0 Mon Sep 17 00:00:00 2001 From: Bobby Rong Date: Fri, 6 Oct 2023 16:04:24 +0800 Subject: [PATCH 33/37] nixosTests.gnome-flashback: Ensure gnome-flashback-media-keys starts --- nixos/tests/gnome-flashback.nix | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/nixos/tests/gnome-flashback.nix b/nixos/tests/gnome-flashback.nix index 876d36477c1a..3e59e3fc0340 100644 --- a/nixos/tests/gnome-flashback.nix +++ b/nixos/tests/gnome-flashback.nix @@ -49,9 +49,10 @@ import ./make-test-python.nix ({ pkgs, lib, ...} : { assert "alice" in machine.succeed("getfacl -p /dev/snd/timer") with subtest("Wait for Metacity"): - machine.wait_until_succeeds( - "pgrep metacity" - ) + machine.wait_until_succeeds("pgrep metacity") + + with subtest("Regression test for #233920"): + machine.wait_until_succeeds("pgrep -fa gnome-flashback-media-keys") machine.sleep(20) machine.screenshot("screen") ''; From 256c518a8a810375141737012b1e6c89a76dcc0a Mon Sep 17 00:00:00 2001 From: Arthur Gautier Date: Thu, 5 Oct 2023 12:33:18 -0700 Subject: [PATCH 34/37] dpdk: fixup shared compilation Dpdk build will default to static linking of its libraries if `default_library` option is not specified. When shared is expected, we should explicitely set the `default_library` option to `shared`. This saves 586MB on the derivation output size: ``` 95M /nix/store/qydxxmcnh1w8yz58n36345kg3siimqip-dpdk-22.11.1 681M /nix/store/pxvc5r3jvba1i96cma36akr7cnvnac3w-dpdk-22.11.1 ``` --- pkgs/os-specific/linux/dpdk/default.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pkgs/os-specific/linux/dpdk/default.nix b/pkgs/os-specific/linux/dpdk/default.nix index 78acb45bb3c7..c3bd0c64a4ba 100644 --- a/pkgs/os-specific/linux/dpdk/default.nix +++ b/pkgs/os-specific/linux/dpdk/default.nix @@ -68,7 +68,7 @@ in stdenv.mkDerivation rec { ] # kni kernel driver is currently not compatble with 5.11 ++ lib.optional (mod && kernel.kernelOlder "5.11") "-Ddisable_drivers=kni" - ++ lib.optional (!shared) "-Ddefault_library=static" + ++ [(if shared then "-Ddefault_library=shared" else "-Ddefault_library=static")] ++ lib.optional (machine != null) "-Dmachine=${machine}" ++ lib.optional mod "-Dkernel_dir=${kernel.dev}/lib/modules/${kernel.modDirVersion}/build" ++ lib.optional (withExamples != []) "-Dexamples=${builtins.concatStringsSep "," withExamples}"; From d6ac2df61db7d814513b58132a8c1c4c297a0125 Mon Sep 17 00:00:00 2001 From: Doron Behar Date: Thu, 5 Oct 2023 12:30:13 +0300 Subject: [PATCH 35/37] python3.pkgs.astropy: 5.3.3 -> 5.3.4 --- .../python-modules/astropy/default.nix | 19 +++++++------------ 1 file changed, 7 insertions(+), 12 deletions(-) diff --git a/pkgs/development/python-modules/astropy/default.nix b/pkgs/development/python-modules/astropy/default.nix index 8ee70bf64044..0a70e40e9e8a 100644 --- a/pkgs/development/python-modules/astropy/default.nix +++ b/pkgs/development/python-modules/astropy/default.nix @@ -26,25 +26,15 @@ buildPythonPackage rec { pname = "astropy"; - version = "5.3.3"; + version = "5.3.4"; format = "pyproject"; disabled = pythonOlder "3.8"; # according to setup.cfg src = fetchPypi { inherit pname version; - hash = "sha256-AzDfn116IlQ2fpuM9EJVuhBwsGEjGIxqcu3BgEk/k7s="; + hash = "sha256-1JD34vqsLMwBySRCAtYpFUJZr4qXkQTO2J3ErOTm8dg="; }; - patches = [ - # Fixes running tests in parallel issue - # https://github.com/astropy/astropy/issues/15316. Fix from - # https://github.com/astropy/astropy/pull/15327 - (fetchpatch { - url = "https://github.com/astropy/astropy/commit/1042c0fb06a992f683bdc1eea2beda0b846ed356.patch"; - hash = "sha256-bApAcGBRrJ94thhByoYvdqw2e6v77+FmTfgmGcE6MMk="; - }) - ]; - # Relax cython dependency to allow this to build, upstream only doesn't # support cython 3 as of writing. See: # https://github.com/astropy/astropy/issues/15315 @@ -85,6 +75,11 @@ buildPythonPackage rec { pythonImportsCheck = [ "astropy" ]; + disabledTests = [ + # May fail due to parallelism, see: + # https://github.com/astropy/astropy/issues/15441 + "TestUnifiedOutputRegistry" + ]; meta = { description = "Astronomy/Astrophysics library for Python"; From b68f1972fb05fa8a40746636f8cfd95dc92b8c20 Mon Sep 17 00:00:00 2001 From: Phillip Seeber Date: Fri, 6 Oct 2023 11:32:51 +0200 Subject: [PATCH 36/37] qcelemental: 0.25.1 -> 0.26.0 --- .../development/python-modules/qcelemental/default.nix | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/pkgs/development/python-modules/qcelemental/default.nix b/pkgs/development/python-modules/qcelemental/default.nix index 7b12781ba160..9ac348304e5e 100644 --- a/pkgs/development/python-modules/qcelemental/default.nix +++ b/pkgs/development/python-modules/qcelemental/default.nix @@ -6,22 +6,26 @@ , numpy , pint , pydantic +, poetry-core , pytestCheckHook , pythonOlder }: buildPythonPackage rec { pname = "qcelemental"; - version = "0.25.1"; - format = "setuptools"; + version = "0.26.0"; + + pyproject = true; disabled = pythonOlder "3.7"; src = fetchPypi { inherit pname version; - hash = "sha256-4+DlP+BH0UdWcYRBBApdc3E18L2zPvsdY6GTW5WCGnQ="; + hash = "sha256-oU6FEM2/2mRe8UYcGv0C77WZMRcz27pfg/zR1haKbd0="; }; + nativeBuildInputs = [ poetry-core ]; + propagatedBuildInputs = [ networkx numpy From 736884108d45daa6c41f123c6b318043a2c33ee1 Mon Sep 17 00:00:00 2001 From: Tom Fitzhenry Date: Fri, 6 Oct 2023 21:36:48 +1100 Subject: [PATCH 37/37] sgt-puzzles: rename all "sgtpuzzles" -> "sgt-puzzles" nixpkgs currently mixes sgtpuzzles/sgt-puzzles across filenames, packages, tests. This inconsistency is frequently annoying. Let's unify on "sgt-puzzles", on the basis that: * "sgt-puzzles" is the package filename. * Alpine/FreeBSD/Debian use "sgt-puzzles". No other distro uses "sgtpuzzles". https://repology.org/project/sgt-puzzles/versions --- nixos/tests/all-tests.nix | 2 +- nixos/tests/{sgtpuzzles.nix => sgt-puzzles.nix} | 4 ++-- pkgs/games/sgt-puzzles/default.nix | 6 +++--- pkgs/top-level/all-packages.nix | 7 +++++-- 4 files changed, 11 insertions(+), 8 deletions(-) rename nixos/tests/{sgtpuzzles.nix => sgt-puzzles.nix} (92%) diff --git a/nixos/tests/all-tests.nix b/nixos/tests/all-tests.nix index c221835f9a6a..9c9030469007 100644 --- a/nixos/tests/all-tests.nix +++ b/nixos/tests/all-tests.nix @@ -714,7 +714,7 @@ in { service-runner = handleTest ./service-runner.nix {}; sftpgo = runTest ./sftpgo.nix; sfxr-qt = handleTest ./sfxr-qt.nix {}; - sgtpuzzles = handleTest ./sgtpuzzles.nix {}; + sgt-puzzles = handleTest ./sgt-puzzles.nix {}; shadow = handleTest ./shadow.nix {}; shadowsocks = handleTest ./shadowsocks {}; shattered-pixel-dungeon = handleTest ./shattered-pixel-dungeon.nix {}; diff --git a/nixos/tests/sgtpuzzles.nix b/nixos/tests/sgt-puzzles.nix similarity index 92% rename from nixos/tests/sgtpuzzles.nix rename to nixos/tests/sgt-puzzles.nix index b8d25d42d312..4c5210bfce77 100644 --- a/nixos/tests/sgtpuzzles.nix +++ b/nixos/tests/sgt-puzzles.nix @@ -1,6 +1,6 @@ import ./make-test-python.nix ({ pkgs, ...} : { - name = "sgtpuzzles"; + name = "sgt-puzzles"; meta = with pkgs.lib.maintainers; { maintainers = [ tomfitzhenry ]; }; @@ -14,7 +14,7 @@ import ./make-test-python.nix ({ pkgs, ...} : services.xserver.enable = true; environment.systemPackages = with pkgs; [ - sgtpuzzles + sgt-puzzles ]; }; diff --git a/pkgs/games/sgt-puzzles/default.nix b/pkgs/games/sgt-puzzles/default.nix index a161d8d68ef7..8173fb5fe1d2 100644 --- a/pkgs/games/sgt-puzzles/default.nix +++ b/pkgs/games/sgt-puzzles/default.nix @@ -60,15 +60,15 @@ stdenv.mkDerivation rec { ''; passthru = { - tests.sgtpuzzles = nixosTests.sgtpuzzles; - updateScript = writeScript "update-sgtpuzzles" '' + tests.sgt-puzzles = nixosTests.sgt-puzzles; + updateScript = writeScript "update-sgt-puzzles" '' #!/usr/bin/env nix-shell #!nix-shell -i bash -p curl pcre common-updater-scripts set -eu -o pipefail version="$(curl -sI 'https://www.chiark.greenend.org.uk/~sgtatham/puzzles/puzzles.tar.gz' | grep -Fi Location: | pcregrep -o1 'puzzles-([0-9a-f.]*).tar.gz')" - update-source-version sgtpuzzles "$version" + update-source-version sgt-puzzles "$version" ''; }; diff --git a/pkgs/top-level/all-packages.nix b/pkgs/top-level/all-packages.nix index faa6d3e35a8c..51eb556ff498 100644 --- a/pkgs/top-level/all-packages.nix +++ b/pkgs/top-level/all-packages.nix @@ -38476,12 +38476,15 @@ with pkgs; sfrotz = callPackage ../games/sfrotz { }; - sgtpuzzles = callPackage ../games/sgt-puzzles { }; + sgt-puzzles = callPackage ../games/sgt-puzzles { }; - sgtpuzzles-mobile = callPackage ../games/sgt-puzzles { + sgt-puzzles-mobile = callPackage ../games/sgt-puzzles { isMobile = true; }; + sgtpuzzles = throw "sgtpuzzles has been renamed to sgt-puzzles."; # 2023-10-06 + sgtpuzzles-mobile = throw "sgtpuzzles-mobile has been renamed to sgt-puzzles-mobile."; # 2023-10-06 + shattered-pixel-dungeon = callPackage ../games/shattered-pixel-dungeon { }; shticker-book-unwritten = callPackage ../games/shticker-book-unwritten { };