Manual staging-next -> staging merge (#557137)

This commit is contained in:
John Ericson
2026-08-27 16:50:55 -04:00
committed by GitHub
58 changed files with 1811 additions and 1146 deletions

View File

@@ -91,6 +91,10 @@ with lib.maintainers;
shortName = "Blockchains";
};
boot-security = {
github = "boot-security";
};
budgie = {
members = [
bobby285271

View File

@@ -23,6 +23,8 @@ in
services."AmneziaVPN" = {
wantedBy = [ "multi-user.target" ];
path = with pkgs; [
gawk
iptables
procps
iproute2
sudo

View File

@@ -853,28 +853,28 @@
}
},
"ungoogled-chromium": {
"version": "151.0.7922.173",
"version": "152.0.7977.64",
"deps": {
"depot_tools": {
"rev": "94e89b10b92cc9d6e58fc8d1b6474b7d29e8a114",
"hash": "sha256-2kfg2f5lamTyq0BMEt5LGuc4BW07Zx+Z9hZCErTVuUs="
"rev": "38c391feba5fb96812f9028da12413ffc39df394",
"hash": "sha256-yOd+k4GJ/unOVCm2Fj1oDHOMKV87CuBO/z0li3owNQk="
},
"gn": {
"version": "0-unstable-2026-06-29",
"rev": "1d86777e7f2562a86ecea77d1809ac4f82bb5bfe",
"hash": "sha256-T2LdISIkp8fcUli5ZetTqrESBAc7coJhWdJv7I+o9kk="
"version": "0-unstable-2026-07-23",
"rev": "641ace93dd9560e75e7add0d08f77b446fbb3b78",
"hash": "sha256-ovLx6KaORdXqnWgbsGEty10k2CHuCmTk3yEqy5//ovk="
},
"ungoogled-patches": {
"rev": "151.0.7922.173-1",
"hash": "sha256-m7Wp64ns06DXbjMcLT9Dz6WBBqBGCPkrCuveYZ/VqZ4="
"rev": "152.0.7977.64-1",
"hash": "sha256-9esE3TgtKiwwFL5pu87aEQznelMVtNXBslggYAJTEbc="
},
"npmHash": "sha256-pF0JtwFpPC4/fodbhSJnQKkczA9WlDg4VqEAy9aDVLg="
},
"DEPS": {
"src": {
"url": "https://chromium.googlesource.com/chromium/src.git",
"rev": "a96602f30358e9b5d256a0464e7e4d4bec223004",
"hash": "sha256-uumIVSzf318Xd1JB9jESXgpLxXlrvMDclOzSFQqweZ8=",
"rev": "506c834ecceaa943c5f41e6cfe7f68acb5c45346",
"hash": "sha256-KEr9nzF55+c8Rvvay3SZjcWMDWVGTyv1f5Pjv3ckl3E=",
"recompress": true
},
"src/third_party/clang-format/script": {
@@ -884,13 +884,13 @@
},
"src/third_party/compiler-rt/src": {
"url": "https://chromium.googlesource.com/external/github.com/llvm/llvm-project/compiler-rt.git",
"rev": "57d6af57c374757d67349eaf85b41efc3c603bd3",
"hash": "sha256-9nnW5gittMng5VvDiMrd2Q7rstZqgd+uhx9+k/W3XMY="
"rev": "e1c9323385b40780f574f440a8a9ad83855712b0",
"hash": "sha256-oxGL+ct1z5S9wduYINjiZrjJx1HlAJjyMPEoDyhIfvo="
},
"src/third_party/libc++/src": {
"url": "https://chromium.googlesource.com/external/github.com/llvm/llvm-project/libcxx.git",
"rev": "5abc7f839700f0f17338434e1c1c6a8c87c00c11",
"hash": "sha256-vT1km7JgVpotDoNK+ae1gplSHcwrVNLsv/QAFUrDsIM="
"rev": "b16984ce99c702355a5b2b4c52574e82cec41fb9",
"hash": "sha256-ZVgUAi5rYj17N3nAEvLQXZLCxnmvxIo2RpJ3geTSyWQ="
},
"src/third_party/libc++abi/src": {
"url": "https://chromium.googlesource.com/external/github.com/llvm/llvm-project/libcxxabi.git",
@@ -899,13 +899,13 @@
},
"src/third_party/libunwind/src": {
"url": "https://chromium.googlesource.com/external/github.com/llvm/llvm-project/libunwind.git",
"rev": "6de9f6eebca9aefbb32383a92baa9bf0f59f1457",
"hash": "sha256-o0MSKm65+hFyUO4CZkzoozt1Lup+/1JYmV9FEXCnD0Q="
"rev": "b2ff0e6b9ac002918d7a9ce982eee88dcc27a450",
"hash": "sha256-VK9w68Im896xi4cymhtfvh7xdRJZB78YEvUYyxqBu48="
},
"src/third_party/llvm-libc/src": {
"url": "https://chromium.googlesource.com/external/github.com/llvm/llvm-project/libc.git",
"rev": "265cc6a83652bac5cb8ceb59741bc288ebe6b312",
"hash": "sha256-yFp/1m0tPdMZAExu88DphqTklb2fVC2pLSE7SPU13aI="
"rev": "3ea89f4304312567e31a8eb45e0737577e65b676",
"hash": "sha256-g8ZtRI0yazHgli0/TMz/SeAJ5SoMZdir+/29GFQAczM="
},
"src/chrome/test/data/perf/canvas_bench": {
"url": "https://chromium.googlesource.com/chromium/canvas_bench.git",
@@ -924,18 +924,18 @@
},
"src/docs/website": {
"url": "https://chromium.googlesource.com/website.git",
"rev": "18d64b46a208ab5432e2a9a44f700ece50e8cc3e",
"hash": "sha256-OxAlqEh0+yldlU5XQorwFtocTLJ0AjYRO8xwjN8PxyQ="
"rev": "e9dfa88cee41c025709e79164ceb0758cfe76a67",
"hash": "sha256-mWAwegdaC7LEOYN5Y/xcJBv4R9dInK4VW35/U8rn7Wg="
},
"src/media/cdm/api": {
"url": "https://chromium.googlesource.com/chromium/cdm.git",
"rev": "33c977516b3dfe5b065bc298aa74175e1999ab51",
"hash": "sha256-GsaRxLnsz1jrFZ3m5tv65d1dioG23uJnmfa+WD7XcFc="
"rev": "d6c4e1ea4c8fc3dcd98ac3ab5a981f63067223a4",
"hash": "sha256-DnDeyVG+uEDBg4tA84rMBhLXy9hSpP8CX8f7Y34jLLg="
},
"src/net/third_party/quiche/src": {
"url": "https://quiche.googlesource.com/quiche.git",
"rev": "4729ceb221725bb52c6f4d48229d9c3ba059c36e",
"hash": "sha256-ekGYdv1AiQLPGxN16hpJBn/jhtVrmZPcunO4wNRjSog="
"rev": "1ba0d99a5c2fec4f4dbb7f98f251b05dcf4e2968",
"hash": "sha256-odzVQD9WyldgAv8QRvXABKaSLy1DL6DRhdVQSer4HVM="
},
"src/testing/libfuzzer/fuzzers/wasm_corpus": {
"url": "https://chromium.googlesource.com/v8/fuzzer_wasm_corpus.git",
@@ -944,8 +944,8 @@
},
"src/third_party/angle": {
"url": "https://chromium.googlesource.com/angle/angle.git",
"rev": "a17d6c8e92696bc78bcbdaf56fc197ebd0cc1fde",
"hash": "sha256-lz8BqENfeHI31L1EOHWlCcE+tANVwuZVrqVDYXMjqQU="
"rev": "736ed80c7552a4b267bd54a282b971aa4555cb3e",
"hash": "sha256-3ZCIFT7j944HWPOiADQa88TQZctLej5vbrBFA/FwyHw="
},
"src/third_party/angle/third_party/glmark2/src": {
"url": "https://chromium.googlesource.com/external/github.com/glmark2/glmark2",
@@ -959,13 +959,13 @@
},
"src/third_party/angle/third_party/VK-GL-CTS/src": {
"url": "https://chromium.googlesource.com/external/github.com/KhronosGroup/VK-GL-CTS",
"rev": "06ae3bf12ae573de7144c5935505993a07fe69d3",
"hash": "sha256-8HV3ieJS3P5cfAhVtJ+4bo2B6kR1wseO+qwhuAG8O5M="
"rev": "3b7cbad78e93bcda20ccf68efae2d71695dd0f65",
"hash": "sha256-bPgrkZ3my/tl+H2/YuAxmn83svPSw4l6lnz8zGHQtuk="
},
"src/third_party/anonymous_tokens/src": {
"url": "https://chromium.googlesource.com/external/github.com/google/anonymous-tokens.git",
"rev": "f5499d91ee1b8ab56b6d110e8e9a0d94c0a6eca7",
"hash": "sha256-hKdtDbVKC4v0BFsuGouG/6f/4VK8M0yIMCPxHWw1ESk="
"rev": "e07c92bc81cfd4203e6158cac115fc44c27b31b8",
"hash": "sha256-NY/RkTCl/7KBJuIS6pa3sjdgyccWDrSfrUwBqWgL/4I="
},
"src/third_party/aria-practices/src": {
"url": "https://chromium.googlesource.com/external/github.com/w3c/aria-practices.git",
@@ -984,23 +984,23 @@
},
"src/third_party/dav1d/libdav1d": {
"url": "https://chromium.googlesource.com/external/github.com/videolan/dav1d.git",
"rev": "77ef66354d76a3c8aa4b11cde8093294fce23b0f",
"hash": "sha256-YYFY2OYumhE7WMDr7DNfr+drqQAoNJRiYepbdRjhNRM="
"rev": "54706fc6bc0cdecab7e9593974a4039cc038fca7",
"hash": "sha256-L3a9MmPWJlxmRa19glWDLvkXHev5oiM5/fxtKOBPMxI="
},
"src/third_party/dawn": {
"url": "https://dawn.googlesource.com/dawn.git",
"rev": "29256ad98530582b82d1d6b76bae8354f1565e74",
"hash": "sha256-7fh6g+xTrmqa1flbs2NTdiQiaj8N3LShIx3GeqqbZq0="
"rev": "571752c9cb3ed36a3194854374984427794c4dda",
"hash": "sha256-YMgRmVMXo1Ra5M034zij/ik/1aHpb3veK4VWsKHIwhI="
},
"src/third_party/dawn/third_party/glfw3/src": {
"url": "https://chromium.googlesource.com/external/github.com/glfw/glfw",
"rev": "ed6452b13c76f7b4da216a9952bc7837aeb0f031",
"hash": "sha256-bKhh53IG5k5UPEUbcjY5+Xv+/H/qnNdoW9CFWffozkA="
"rev": "463cf73610d911e8eff95ae345143137cf610be4",
"hash": "sha256-+WG+0KALV10B+1hOJzyiU4azlJIej/F5DtqtSkEN040="
},
"src/third_party/dawn/third_party/directx-shader-compiler/src": {
"url": "https://chromium.googlesource.com/external/github.com/microsoft/DirectXShaderCompiler",
"rev": "02e491eb019766b866bcf09c427365713353841b",
"hash": "sha256-h70zf9zCWHxbdBloRETQBQJRDdF/zYVEE0wj2Iav5y8="
"rev": "1f8a14aecd4f2f25991fa9f7aad6c320fea91409",
"hash": "sha256-nesLgajCiFHwb2TKwzlCERFb6wOkwqpMT5z6nzj2Q9Y="
},
"src/third_party/dawn/third_party/directx-headers/src": {
"url": "https://chromium.googlesource.com/external/github.com/microsoft/DirectX-Headers",
@@ -1019,13 +1019,23 @@
},
"src/third_party/dawn/third_party/webgpu-cts": {
"url": "https://chromium.googlesource.com/external/github.com/gpuweb/cts",
"rev": "663ea46471861e51f6a320e078a1fe39bf7f623e",
"hash": "sha256-yPgQhVgy3atQtqBi/FPOMeZqoEyGOpSID4Fhh3zSLRE="
"rev": "499044af47ec2717e06e644d0943e6fcdb3f3538",
"hash": "sha256-M8TWqKdqoiZ01vbDpcRyPWIOaBPCPdSSflxcIpbYjFA="
},
"src/third_party/dawn/third_party/webgpu-headers/src": {
"url": "https://chromium.googlesource.com/external/github.com/webgpu-native/webgpu-headers",
"rev": "a11ef4462405c4506ad7284e5b1edeff2750bb54",
"hash": "sha256-gEoyN14mN1Pkym/d4LtBe5hwV+3K+Ln3OXJVMfXf9lI="
"rev": "b3f67b89929c133403fd95638be4ef96b56ddca0",
"hash": "sha256-pLsvlbh1BCEtfQNejm2XilpelZmNg1/NuLq0agIGqQI="
},
"src/third_party/disarm/src": {
"url": "https://chromium.googlesource.com/external/github.com/aengelke/disarm.git",
"rev": "2d13d3f410a52daff1c5d8ef07d623332f372560",
"hash": "sha256-uQC4EhF4ytsGzc5B0uaQKDmuVIGiPDPbY275yIeyWVE="
},
"src/third_party/fadec/src": {
"url": "https://chromium.googlesource.com/external/github.com/aengelke/fadec.git",
"rev": "c9f78f532b9004de278489019ab2c6c28ae9746e",
"hash": "sha256-+4xVWPOeXrf8tgEQicoMKzBbz5XMB1H7sBfOBfwiDvs="
},
"src/third_party/highway/src": {
"url": "https://chromium.googlesource.com/external/github.com/google/highway.git",
@@ -1044,13 +1054,13 @@
},
"src/third_party/boringssl/src": {
"url": "https://boringssl.googlesource.com/boringssl.git",
"rev": "29e593e29165df578ab778269a1f04da2055c32f",
"hash": "sha256-141WOYj1OLfQmrs7otUnwJmvGKnt0O3T3rH9q0exOZ0="
"rev": "572a4c68475d284b34675f45ddbb9c158ef3c2ae",
"hash": "sha256-gW+Ksd/boITK5ZTDIwhIgPAdPQNi8MvP7ru6qMdtorI="
},
"src/third_party/breakpad/breakpad": {
"url": "https://chromium.googlesource.com/breakpad/breakpad.git",
"rev": "9aebd3d8ef5a246deb2c929b5666aaba160ebce6",
"hash": "sha256-dIEFfTWa/GazNcCY3gigcxPCljN8IFKaKhYhgqWaBm0="
"rev": "69e9aada412e81575a95d0d94f4592fe1b8dfc15",
"hash": "sha256-v0Qw8nlXR6Dnkbt7I0Fe7HKv9mtf/9h0xl4HaCHPJjA="
},
"src/third_party/cast_core/public/src": {
"url": "https://chromium.googlesource.com/cast_core/public",
@@ -1059,8 +1069,8 @@
},
"src/third_party/catapult": {
"url": "https://chromium.googlesource.com/catapult.git",
"rev": "c7282e69291240dbee993364a340934982443334",
"hash": "sha256-kYmzjsjMDj96QBwpvZagsqsibouMx/q3UkuMFJd1jt4="
"rev": "d810008022eeaefcbea50393ea5baa0930b27047",
"hash": "sha256-H2CpevfSmr6suNHkkO97u0Nmu1n3g9v36ea+M8JPpZo="
},
"src/third_party/ced/src": {
"url": "https://chromium.googlesource.com/external/github.com/google/compact_enc_det.git",
@@ -1094,28 +1104,28 @@
},
"src/third_party/cros_system_api": {
"url": "https://chromium.googlesource.com/chromiumos/platform2/system_api.git",
"rev": "14884f726cc15dfacbcde0f0aa7fd3fe8f44ba7e",
"hash": "sha256-MTqcRpDJNltx2Jed4wn9L9vy7Oi+uMAzQlZhHIdh6UU="
"rev": "54e5484f94e59fdc31e7821293692a8bb47f88a3",
"hash": "sha256-TUW8y9as37owHYgg4mTs9ZUmZ4G+N1Njtrs6eyY5MDU="
},
"src/third_party/crossbench": {
"url": "https://chromium.googlesource.com/crossbench.git",
"rev": "09cc246dd2b3697225e8ee277628b9e890e37adb",
"hash": "sha256-qHmQ9+kQ0C0IcqJJox2eN3WSZyKPdt7FCMccrBVrN80="
"rev": "eb6e4790f4fc6f2f66a20aba07de9a58985db46b",
"hash": "sha256-kEMKNDP57Q3m2eBjb0McScZTxrFpLTIE/9dSAupTOJ4="
},
"src/third_party/crossbench-web-tests": {
"url": "https://chromium.googlesource.com/chromium/web-tests.git",
"rev": "b5fd07ef7b048d8cf8cc59856db939173c4bb83e",
"hash": "sha256-RC70rVFobg5NY8IU0bwd0taDZht9qVfDW7FuR0gnys0="
"rev": "92d748acb154cb58c76ad1d509378d5aa8669755",
"hash": "sha256-vh6uX1jXhxDgqfXnme/nh8W+O4Qq+Fx33lSQ08LNunM="
},
"src/third_party/depot_tools": {
"url": "https://chromium.googlesource.com/chromium/tools/depot_tools.git",
"rev": "94e89b10b92cc9d6e58fc8d1b6474b7d29e8a114",
"hash": "sha256-2kfg2f5lamTyq0BMEt5LGuc4BW07Zx+Z9hZCErTVuUs="
"rev": "38c391feba5fb96812f9028da12413ffc39df394",
"hash": "sha256-yOd+k4GJ/unOVCm2Fj1oDHOMKV87CuBO/z0li3owNQk="
},
"src/third_party/devtools-frontend/src": {
"url": "https://chromium.googlesource.com/devtools/devtools-frontend",
"rev": "3edf00b60c60c9248990a39a702ca4882809fe06",
"hash": "sha256-14qm+rI536GCqNkd9umSpJ9JoXf/47wuknJsVUb3ty0="
"rev": "941348cf79c423892e1c7c219091a7103d18a68b",
"hash": "sha256-/b+NCAr1jRJd/Uq4Cf5aO/yTdNP00ImIWuSJ4aP+TEw="
},
"src/third_party/dom_distiller_js/dist": {
"url": "https://chromium.googlesource.com/chromium/dom-distiller/dist.git",
@@ -1129,8 +1139,8 @@
},
"src/third_party/eigen3/src": {
"url": "https://chromium.googlesource.com/external/gitlab.com/libeigen/eigen.git",
"rev": "3fccdcd589b11da58e5e5d87c9f1f537c7c642f6",
"hash": "sha256-4cXU5J7LBAMxnqC9GyX85dcuL7pNJPCl4jpCpmzQOWE="
"rev": "d53ac33805ba0a23fa139adaf24227fb6707e6fa",
"hash": "sha256-+s/4HVUzKJR5OVcoxwiEzB8F89lov24g0HBPg3tp9Xs="
},
"src/third_party/farmhash/src": {
"url": "https://chromium.googlesource.com/external/github.com/google/farmhash.git",
@@ -1149,8 +1159,8 @@
},
"src/third_party/ffmpeg": {
"url": "https://chromium.googlesource.com/chromium/third_party/ffmpeg.git",
"rev": "ad41607c61898cf7150e0fb20fe4bbabd44922a3",
"hash": "sha256-41qpsOTedB51WMzzHXDiXA19OIzA7wG/Qgbz6IkmWpk="
"rev": "2b68d2babae73714846961fb0ee47e3b3d2e39a9",
"hash": "sha256-Bl8lAM5sHLZ9BHSIaWr5+P/8s014SXsgSmdLya5gd64="
},
"src/third_party/flac": {
"url": "https://chromium.googlesource.com/chromium/deps/flac.git",
@@ -1164,8 +1174,8 @@
},
"src/third_party/fontconfig/src": {
"url": "https://chromium.googlesource.com/external/fontconfig.git",
"rev": "d62c2ab268d1679335daa8fb0ea6970f35224a76",
"hash": "sha256-Oo4ewK86dbEkO5EXyGWvdmsPHa8Wk1BHQah784vIem0="
"rev": "b707078e6e8bb6fd115e2080e69b3194c05e4f1c",
"hash": "sha256-8kCxPpJgVtZryhtTUG/36oo8mlDiKmWALGUxMDQ+wOQ="
},
"src/third_party/fp16/src": {
"url": "https://chromium.googlesource.com/external/github.com/Maratyszcza/FP16.git",
@@ -1179,8 +1189,8 @@
},
"src/third_party/freetype/src": {
"url": "https://chromium.googlesource.com/chromium/src/third_party/freetype2.git",
"rev": "12f5eb32aedb3e27d47c22b0447dc4363703ed94",
"hash": "sha256-CXkHYz+xFSnClEjLqE5WlJQriHrdRZ/P7/15AtUiFCw="
"rev": "656cb777798fa420a13faba3758779e9ed6c4798",
"hash": "sha256-i1X/ETNJTAL3A5pOiUcZRYpqjhPvZIm8FG1HMQreW6g="
},
"src/third_party/fxdiv/src": {
"url": "https://chromium.googlesource.com/external/github.com/Maratyszcza/FXdiv.git",
@@ -1189,13 +1199,13 @@
},
"src/third_party/harfbuzz/src": {
"url": "https://chromium.googlesource.com/external/github.com/harfbuzz/harfbuzz.git",
"rev": "511df88b82e697cd2a0f1f0635787aa0b18bddbb",
"hash": "sha256-wEOux4PN+3/IhTp55bTGjkQEl0I5VoQ/NWrkdzTWiKg="
"rev": "28f4dc622fef010dab12f4275ac195b5d4a4a704",
"hash": "sha256-wqycfs0TITlLu0iJICjAqSX82u8LGrr/NaZ+pgPvycs="
},
"src/third_party/ink/src": {
"url": "https://chromium.googlesource.com/external/github.com/google/ink.git",
"rev": "e959d434fa1e4965c72799b80c1431f1e9ad2dcd",
"hash": "sha256-t5cO3YKV6FiLrp+Av4tnDhfcBAfP4sATGJW4BmBu0+Q="
"rev": "e781093cb91ad22a666f1880f5122fe2ed30ecfd",
"hash": "sha256-j9FIfGrrNEQB3wI2zMvjUksLBEdx8yrVf1NAbJSyjAI="
},
"src/third_party/instrumented_libs": {
"url": "https://chromium.googlesource.com/chromium/third_party/instrumented_libraries.git",
@@ -1209,8 +1219,8 @@
},
"src/third_party/oak/src": {
"url": "https://chromium.googlesource.com/external/github.com/project-oak/oak.git",
"rev": "96c00a6c99ac382f3f3a8f376bc7a70890d1adaa",
"hash": "sha256-+ouwII+i5CbWoJ3NAxQPmczofzkPwtZTtjIPaXyyXt8="
"rev": "e6c31df79a45e4ad6e25a85872622822c48d7e66",
"hash": "sha256-O8eRirwsYi68wydxhy/+KD6IFmMmmNq/EPnJTJZFjvs="
},
"src/third_party/ots/src": {
"url": "https://chromium.googlesource.com/external/github.com/khaledhosny/ots.git",
@@ -1219,8 +1229,8 @@
},
"src/third_party/libgav1/src": {
"url": "https://chromium.googlesource.com/codecs/libgav1.git",
"rev": "9b9ac8689588b245fb1ab6ce5a61c0aaaf81dc91",
"hash": "sha256-g2fM5AD6x7njzy6mEQVetru7IYbVj7urLaNZBISSJwc="
"rev": "c1deec657b32b911920c78e078cfd089faa77200",
"hash": "sha256-HV9Ob0UywJcJD9+crmPmZmx8rJMomJQU0KZbCxBg5Ww="
},
"src/third_party/googletest/src": {
"url": "https://chromium.googlesource.com/external/github.com/google/googletest.git",
@@ -1239,13 +1249,13 @@
},
"src/third_party/nlohmann_json/src": {
"url": "https://chromium.googlesource.com/external/github.com/nlohmann/json.git",
"rev": "75d9166a68355d2cd5a98bfd1a75a3a3dae8f071",
"hash": "sha256-t+ygFLws+E4D0Avia7swt4wruaDFaAT6shN6tl92q8k="
"rev": "3565f40229515411177c196ec912a06307802ed6",
"hash": "sha256-kngBPCN5i+5kzJ95pJ5vY2RLa9P4JYs4e+7Qn3QWsc4="
},
"src/third_party/jsoncpp/source": {
"url": "https://chromium.googlesource.com/external/github.com/open-source-parsers/jsoncpp.git",
"rev": "b5ab350ff38ed25fa5b6e0dc30820f2215cad345",
"hash": "sha256-VvHdQkp7JZrcWca513oLG8sa+NOjW12Z6hi0cVHCMsQ="
"rev": "edc01ab10f52135ec80e3589b6b4e0a9c65b27fd",
"hash": "sha256-mdQo7AiS3DzTF8CqCRT9oL60AzGLQCFng7KUFaFEBIM="
},
"src/third_party/leveldatabase/src": {
"url": "https://chromium.googlesource.com/external/leveldb.git",
@@ -1254,18 +1264,18 @@
},
"src/third_party/libFuzzer/src": {
"url": "https://chromium.googlesource.com/external/github.com/llvm/llvm-project/compiler-rt/lib/fuzzer.git",
"rev": "4b46c0ed586f91aa1ad9b5ebbcad907c9dd956e5",
"hash": "sha256-xXHjGaNlp47bZnTOVZcwNrb1O16MSMJg9YE7AFSfGWY="
"rev": "3f386be62e362fa50284ebd24262966f1a93798e",
"hash": "sha256-vQBWi+4ynPBhZma/2+ApbhT9tbOCd8U+QrabC8GnqKQ="
},
"src/third_party/fuzztest/src": {
"url": "https://chromium.googlesource.com/external/github.com/google/fuzztest.git",
"rev": "1a18c86d947c25ff2b73562a90d41a2207e8cba9",
"hash": "sha256-e3YahhYNt/y30uEPhHMvbz7tIve14ciYdM3sO56cRYg="
"rev": "239bf6cc1ffcbad7d5c96e3b836b474654cbf96c",
"hash": "sha256-h268YPbMTgr5zd0bhTh1Xj/BcCxBhDD60o6+oelW/BQ="
},
"src/third_party/domato/src": {
"url": "https://chromium.googlesource.com/external/github.com/googleprojectzero/domato.git",
"rev": "053714bccbda79cf76dac3fee48ab2b27f21925e",
"hash": "sha256-fYxoA0fxKe9U23j+Jp0MWj4m7RfsRpM0XjF6/yOhX1I="
"rev": "fadff396cc45d521cc594d3e2396e27e887b1963",
"hash": "sha256-5hs+IRwCYA4hSKMzJ9NjW1DSW5YZN5bcHEcNAnfAfac="
},
"src/third_party/libaddressinput/src": {
"url": "https://chromium.googlesource.com/external/libaddressinput.git",
@@ -1274,13 +1284,13 @@
},
"src/third_party/libaom/source/libaom": {
"url": "https://aomedia.googlesource.com/aom.git",
"rev": "b973895c4c1e93f770433258ece300344f744964",
"hash": "sha256-6w66nlUkL88c3M7YB6I7nLYwpBxbjbfqcmmrrueN8/8="
"rev": "d08a82575de50dc99f3b3d324e7b8304836fe0ef",
"hash": "sha256-32WklYoVgBiMxnY+2nOckwmKjZBKZtgwKBmStoO8y/Q="
},
"src/third_party/crabbyavif/src": {
"url": "https://chromium.googlesource.com/external/github.com/webmproject/CrabbyAvif.git",
"rev": "ef606847911d4968b80f778135d3528bf4041b74",
"hash": "sha256-yThyl7Ec0JqxBWRqZ2C9euw3RVrky1lLt1YONBJTnRI="
"rev": "61f5abadda7b179f90e557fed6ae7a3d78bd8231",
"hash": "sha256-N9YwO68d3CXPje43fWs9CoO5Sc3wIULta7n8cp+2Efs="
},
"src/third_party/nearby/src": {
"url": "https://chromium.googlesource.com/external/github.com/google/nearby-connections.git",
@@ -1364,8 +1374,8 @@
},
"src/third_party/libphonenumber/src": {
"url": "https://chromium.googlesource.com/external/libphonenumber.git",
"rev": "5f4c9f039934e2d56fb71c17bdf43d4ceb78fdbf",
"hash": "sha256-350wPwBWEgBDiAttVFPR9NC30JKtiqGeMZ9sMXjWlXY="
"rev": "eee81630a337b9045c6db4577cf60bb1a2c6cbd1",
"hash": "sha256-voK+aAFzFGTXg6UVprNiD5Mbh6hW75EKbtzqIjPsxI0="
},
"src/third_party/libprotobuf-mutator/src": {
"url": "https://chromium.googlesource.com/external/github.com/google/libprotobuf-mutator.git",
@@ -1389,8 +1399,8 @@
},
"src/third_party/libvpx/source/libvpx": {
"url": "https://chromium.googlesource.com/webm/libvpx.git",
"rev": "91bba32d5cebc0c132bafa78f937643aa41bb7e5",
"hash": "sha256-YK/TbAjNjsyWlvk2z+X2GbcVk16JWGEwAoEnwYsFxeQ="
"rev": "ade52487a37ef76a0f209bd39bea9fe67d6db4c4",
"hash": "sha256-Ke28x3c0Ssg2GFfHmFlfW8fex3jSuBcN0e6PXzH0b5g="
},
"src/third_party/libwebm/source": {
"url": "https://chromium.googlesource.com/webm/libwebm.git",
@@ -1404,8 +1414,8 @@
},
"src/third_party/libyuv": {
"url": "https://chromium.googlesource.com/libyuv/libyuv.git",
"rev": "8aeb3a9ca36341a640528e59b34b5d641080dca8",
"hash": "sha256-FGl0xK7ooaRFzFBxuV6oOu3h1x2b/myLLO2En3xgVCk="
"rev": "26e56be0f984af3dae4d0c0ab7a0bac8ac20e1b0",
"hash": "sha256-Ievf2MXM7VX9+R85N3i2W+1jZSbt5mvy1SCNc0iqJYw="
},
"src/third_party/lss": {
"url": "https://chromium.googlesource.com/linux-syscall-support.git",
@@ -1422,6 +1432,11 @@
"rev": "9d21b5cb5896c0cde186b54d430131f9f537104c",
"hash": "sha256-uzdoA4yBp3ZIHYtW/OsxfNwxtxKFo+V9jx3u3MEkrV8="
},
"src/third_party/pipewire/src": {
"url": "https://chromium.googlesource.com/external/gitlab.freedesktop.org/pipewire/pipewire.git",
"rev": "b741e0c74f5436f0c925f7741140db0efd32cf4e",
"hash": "sha256-sxS6+LtvpEWCKoKLDUSYkW4+rrcIXPjWPBglReIDh/k="
},
"src/third_party/nasm": {
"url": "https://chromium.googlesource.com/chromium/deps/nasm.git",
"rev": "525a09a813be0f75b646ee93fc2a31c27b87d722",
@@ -1454,13 +1469,13 @@
},
"src/third_party/pdfium": {
"url": "https://pdfium.googlesource.com/pdfium.git",
"rev": "c01585b18e5b7492a5ecfc9b179af023a560455e",
"hash": "sha256-wU8qxIM8ktbrmTCe4wGB9Hfl643BHcJrByNTLXRmd5k="
"rev": "8f3e90282ef137adf7d380079c3178b24407104a",
"hash": "sha256-4OhJcWZJ3UC/Mf4DJNzLLYQtrw0y0suO/wy0d1GYP4w="
},
"src/third_party/perfetto": {
"url": "https://chromium.googlesource.com/external/github.com/google/perfetto.git",
"rev": "ec4b996c753b3e301b183736f54566239b0df68d",
"hash": "sha256-2tv43yeasCuUgr4JnTz58x31Zq4M56xJUozp8uZVbTI="
"rev": "9c7ce42050379be8c24a270f395e00c7347965cb",
"hash": "sha256-wbHdFhzbOP98IOQnXyUWDQtjt/nOD4VABSyvErhLBI4="
},
"src/third_party/protobuf-javascript/src": {
"url": "https://chromium.googlesource.com/external/github.com/protocolbuffers/protobuf-javascript",
@@ -1494,13 +1509,13 @@
},
"src/third_party/ruy/src": {
"url": "https://chromium.googlesource.com/external/github.com/google/ruy.git",
"rev": "2af88863614a8298689cc52b1a47b3fcad7be835",
"hash": "sha256-4To1BMUgzj2/sV7USN9W0CgHnpRmaktEspfhwWWeVBc="
"rev": "2264753777198e4393fb83c44c693462d57a2be1",
"hash": "sha256-ZzkeS9ujkcFxtBQW+IWLXUYBF79N2jBw1CLyyn70/64="
},
"src/third_party/search_engines_data/resources": {
"url": "https://chromium.googlesource.com/external/search_engines_data.git",
"rev": "b4f28b2133e46ebbb5483ea53d9cd4b533594531",
"hash": "sha256-KAMu3FteZgN8nmj1rToFbiLNM/CPfU+9AJ84poMSkmI="
"rev": "cf814b5cc732a437b4ee636f1c7907f8f1ced51a",
"hash": "sha256-koTwcthcJn3a4XH+rY+E3z4uvWbv+1yuX9qkcqu5t5A="
},
"src/third_party/sframe/src": {
"url": "https://chromium.googlesource.com/external/github.com/cisco/sframe",
@@ -1509,8 +1524,8 @@
},
"src/third_party/skia": {
"url": "https://skia.googlesource.com/skia.git",
"rev": "7ad44b72c93c242f96f2563edb566439fe816c0a",
"hash": "sha256-hCMg8otfjZU/zzlLZT4ywLFAU1HbXymSTqr7BfQcu5E="
"rev": "b6d106297ff9ef2ff8094033695d045e87775581",
"hash": "sha256-sun/P/JVhTKfRwmVK5dgnz8UZEFnQoyXZZS6PN5z9us="
},
"src/third_party/smhasher/src": {
"url": "https://chromium.googlesource.com/external/smhasher.git",
@@ -1524,8 +1539,8 @@
},
"src/third_party/sqlite/src": {
"url": "https://chromium.googlesource.com/chromium/deps/sqlite.git",
"rev": "fc121d7d03cd6cbf499ec06a5112b263471b1181",
"hash": "sha256-hf9PxQhXEKT49GbkFYCvRPBT0Qu+hDnDpebI92yO1Oo="
"rev": "0a5fe1b18a5b651b6c4c90d397e3d0b8061f73fb",
"hash": "sha256-y+lJK8Qi22KUcYyY62x9xCXej85on9e0FxySaMNSYPY="
},
"src/third_party/swiftshader": {
"url": "https://swiftshader.googlesource.com/SwiftShader.git",
@@ -1539,23 +1554,23 @@
},
"src/third_party/tflite/src": {
"url": "https://chromium.googlesource.com/external/github.com/tensorflow/tensorflow.git",
"rev": "66fe77c30816f9c0a503fb9f2f12fdb56c6eee76",
"hash": "sha256-1m9caGzYfg1ISFzra6BEDhWEHkmqMrzo0P1mvf6JfT8="
"rev": "7bedf2e94aff6ca62150d74fd40aa63cb73c6583",
"hash": "sha256-Uv1SbtjalHt7XLAcvOfiycgepDrEK8/JdpD3GPK1MNo="
},
"src/third_party/litert/src": {
"url": "https://chromium.googlesource.com/external/github.com/google-ai-edge/LiteRT.git",
"rev": "ee121300b37b49cd4f9942c0f1256936aa9e611a",
"hash": "sha256-D4lNgq9YvCuajK2qfHVJzQ54BPShna0EkTEDw43J5/g="
"rev": "1ae23176dd5d3a43e35961d8236d5adda7f8c0a1",
"hash": "sha256-xcCqZA8BKZG/TV/fAUAWPOoZwSQkRDATlhE6A05PyX0="
},
"src/third_party/vulkan-deps": {
"url": "https://chromium.googlesource.com/vulkan-deps",
"rev": "285f3b19c49c06a71994a664567418504d5367d9",
"hash": "sha256-UZ6eGC1Zwx3ysDeTa1YPnjQ29GuDDqxfbvQsPFSQsvc="
"rev": "9bf18397113dbdc7adf4f76408df7f79d4ad141a",
"hash": "sha256-ol8SSAFHrEfsKWUmg64klpFFXIlZU4gyibENmzZD454="
},
"src/third_party/glslang/src": {
"url": "https://chromium.googlesource.com/external/github.com/KhronosGroup/glslang",
"rev": "ce138e2c2d6992b31ff4cd2e955904637785a881",
"hash": "sha256-zJ+612mODx6ptEWXzf1Q1WFSlgSTEoWaXlD07v1Z1yI="
"rev": "8292684e941bf22583b257bd9dfe47daccacb665",
"hash": "sha256-1D971MPCHr8vnj31IFUwe1s+X3UAabxYUQ1Cd/VyqDA="
},
"src/third_party/spirv-cross/src": {
"url": "https://chromium.googlesource.com/external/github.com/KhronosGroup/SPIRV-Cross",
@@ -1564,43 +1579,43 @@
},
"src/third_party/spirv-headers/src": {
"url": "https://chromium.googlesource.com/external/github.com/KhronosGroup/SPIRV-Headers",
"rev": "daa093dd29aab8cbb6562b808370562f56e399fb",
"hash": "sha256-2xYphq6uMRlPaaaVSiwqPrWRkCfyOMjeJcWewRja/WY="
"rev": "29981f65241605e08b0ede4cfeb999fe3b723c6a",
"hash": "sha256-tGY4H3+5p9M5LBK/xxRdMT9CX+qq3e7fPkaftnpjU9I="
},
"src/third_party/spirv-tools/src": {
"url": "https://chromium.googlesource.com/external/github.com/KhronosGroup/SPIRV-Tools",
"rev": "d5bbf95d87dd6d2694fbf09acfb42a00c93575e8",
"hash": "sha256-VGq4LDVzCj2KG14YIio//kE0/d3fUyuaPb4pg/GbsXc="
"rev": "a665e21f3061f34064b39937cf00fe8d8769f4ef",
"hash": "sha256-4m/xdMk/r4C5zdU/CZzdoXtRN0MWs8pN5QUPI5Ej3+w="
},
"src/third_party/vulkan-headers/src": {
"url": "https://chromium.googlesource.com/external/github.com/KhronosGroup/Vulkan-Headers",
"rev": "d2d8ded679e53c9f27c0c7a18750e661745886eb",
"hash": "sha256-d/3CSWsu5ttwLlG4bSnJ+47vvQSkZVeKSjhEP139rn0="
"rev": "d314eae73fdc90847bb8304a86ee7c6a8ee023b6",
"hash": "sha256-YU51vfV/8vQqVTngS2SRHKXpgxU/5IJ+jAT5pcYUcpw="
},
"src/third_party/vulkan-loader/src": {
"url": "https://chromium.googlesource.com/external/github.com/KhronosGroup/Vulkan-Loader",
"rev": "0d210fdf88a81b0e833096079f73dda477da62f8",
"hash": "sha256-FTv0TIZhWNhczuzq5/H09P4e61JkrrRQTcYOBvt7vDU="
"rev": "59a70594de4559fd3aed73fe8ac2d6c48ca002d4",
"hash": "sha256-M/gm3fkCcFZJyslWCO/v2DzuavTOfvvKvx+0bNihEqs="
},
"src/third_party/vulkan-tools/src": {
"url": "https://chromium.googlesource.com/external/github.com/KhronosGroup/Vulkan-Tools",
"rev": "b7ae55b37cda76d16368c302f37cb0c7ea2f8409",
"hash": "sha256-FADvu38L8F52pGlC0kDRlqaN4FnIlgLggv2hsQ5YuqU="
"rev": "286299bb6b732e4b22771cfb9d7d421542d40501",
"hash": "sha256-kbySCu2c5nh6icnPQV6qplfg1gHFnGPEYOG6G6TG8EU="
},
"src/third_party/vulkan-utility-libraries/src": {
"url": "https://chromium.googlesource.com/external/github.com/KhronosGroup/Vulkan-Utility-Libraries",
"rev": "ba450228e2ebb4059f8a7d4bb36610464e2f0741",
"hash": "sha256-gETVlFG3sj/sp+0SA4nY4HwVPpk129MIstMrM2fUlnM="
"rev": "e9585c3e3d41ab608ee3b098ce4721d357308fc8",
"hash": "sha256-WcSiUe3vB7zUO0vpqcVJkKqhnZXz76ApWaoMO49efXg="
},
"src/third_party/vulkan-validation-layers/src": {
"url": "https://chromium.googlesource.com/external/github.com/KhronosGroup/Vulkan-ValidationLayers",
"rev": "cf9b84986ad6f29b73e781be7e55535adfe3b680",
"hash": "sha256-xKCChjPpLlWoiWLt2H+t6VmE3brl2P+Y3fTZausO8Ps="
"rev": "11079f041fa85ec27c40c4ef2d63531138a2ab98",
"hash": "sha256-1lG6shUQRKXtojLHwfZD6gDz5yVnNoVp6BHMyUz70Co="
},
"src/third_party/vulkan_memory_allocator": {
"url": "https://chromium.googlesource.com/external/github.com/GPUOpen-LibrariesAndSDKs/VulkanMemoryAllocator.git",
"rev": "7e55b011e16182fc349149abbd3aaf3b1db46421",
"hash": "sha256-fOnFkcQDEGIe5yB507qnP9nA1LBBPFblncNiJ8JxAwI="
"rev": "82a9d47e4f9d91f0e32d2b6acd9714fcee1933a0",
"hash": "sha256-cllZTX7WHoVNugE0efOfY71y8BJg+8w/MI9EDHaVswM="
},
"src/third_party/wayland/src": {
"url": "https://chromium.googlesource.com/external/anongit.freedesktop.org/git/wayland/wayland.git",
@@ -1629,13 +1644,13 @@
},
"src/third_party/webgl/src": {
"url": "https://chromium.googlesource.com/external/khronosgroup/webgl.git",
"rev": "216b10fafd3f6a900c715a8c758a4c7f9883b030",
"hash": "sha256-Aax2hr/9Zq6Avk+TMU1OMBLGshUL6hyRTX6eoOQesqM="
"rev": "064aaf18207438d4f6dd10c98b02b25778257b7f",
"hash": "sha256-1B0qHufnOreV7z6TAQggfX5l8TeLq2NgQg0a5Cr0Q3M="
},
"src/third_party/webgpu-cts/src": {
"url": "https://chromium.googlesource.com/external/github.com/gpuweb/cts.git",
"rev": "663ea46471861e51f6a320e078a1fe39bf7f623e",
"hash": "sha256-yPgQhVgy3atQtqBi/FPOMeZqoEyGOpSID4Fhh3zSLRE="
"rev": "499044af47ec2717e06e644d0943e6fcdb3f3538",
"hash": "sha256-M8TWqKdqoiZ01vbDpcRyPWIOaBPCPdSSflxcIpbYjFA="
},
"src/third_party/webpagereplay": {
"url": "https://chromium.googlesource.com/webpagereplay.git",
@@ -1649,13 +1664,13 @@
},
"src/third_party/webrtc": {
"url": "https://webrtc.googlesource.com/src.git",
"rev": "f20ebb8adbf4fa781830e4384c61f732bd28a217",
"hash": "sha256-r6slVo1WGITEXqyu8iMrV6Pyo3giJkxBbrmJdGLooRc="
"rev": "6f37672d358475cd17544121a12494da454d85fb",
"hash": "sha256-c0h6bD8zNZbacnOgRei+yVB+5+AvfglW+eQDNZU945M="
},
"src/third_party/wuffs/src": {
"url": "https://skia.googlesource.com/external/github.com/google/wuffs-mirror-release-c.git",
"rev": "50869df0ea703b4f41b238bfe26aec6ec9c86889",
"hash": "sha256-V7inWJqH7Q4Ac/ZB//7XHrpgfAYUPBxWBerBem6Q/Kk="
"rev": "7411f488fe2e2c205c3d3b3d28638b7356522930",
"hash": "sha256-AMuAaCbNJYnSeac1B1IRSUh4rlE2KphT04/Ak4Pig5M="
},
"src/third_party/weston/src": {
"url": "https://chromium.googlesource.com/external/anongit.freedesktop.org/git/wayland/weston.git",
@@ -1664,8 +1679,8 @@
},
"src/third_party/xnnpack/src": {
"url": "https://chromium.googlesource.com/external/github.com/google/XNNPACK.git",
"rev": "4b7c368f5e48d9292c5834593c2f83e66b55ce83",
"hash": "sha256-EJ118E6awFO+yW8FkzlaBWVCkwduK1X/j/Evuzka+8k="
"rev": "09c4a9137f3a19b053dc45724a62f4f73ec7746a",
"hash": "sha256-eoS9qQ1hOJJBw6RQ2mTyRQb/AaAj8XnFbtqPpAb99y4="
},
"src/third_party/libei/src": {
"url": "https://chromium.googlesource.com/external/gitlab.freedesktop.org/libinput/libei.git",
@@ -1679,13 +1694,13 @@
},
"src/v8": {
"url": "https://chromium.googlesource.com/v8/v8.git",
"rev": "4b407bc23f23059b1019cde542601c2cf8f70eb2",
"hash": "sha256-TB1A+iIyZOdlbHvim1JOaXOf9uQnoAYqbUL2+PFKUcs="
"rev": "6aacaf6256a069ee455142333b7d38cad1c8d6e0",
"hash": "sha256-1NX4HP/BIJ6bWxoF42K89X8ADHuHjA5akkOL/WkIeME="
},
"src/agents/shared": {
"url": "https://chromium.googlesource.com/chromium/agents.git",
"rev": "aa733bca85501395a2854a1e86084aa707704c3e",
"hash": "sha256-SORAKZ5ZVaXH8FuajaVa7mRM4VIvmmKlDXYzyy1iqlU="
"rev": "559f135fc214d637f85174c6be7010804e31f1e5",
"hash": "sha256-/PhF9Pc8wPx+TLABd3yD218TfEatBySazVci1Wc+9e4="
}
}
}

View File

@@ -23,6 +23,7 @@
dtach,
openssl,
bash,
fetchpatch,
gdb,
man,
git,
@@ -42,6 +43,13 @@ stdenv.mkDerivation (finalAttrs: {
hash = "sha256-S0MUu/HCAp/feTY35se7FcGxcw0ivpqgSAPJjFu8RG8=";
};
patches = [
(fetchpatch {
url = "https://github.com/notmuch/notmuch/commit/f5e58cdb9b93b10ac32379b36b452532a32b8ece.patch";
hash = "sha256-x+WHarE752IQzic/CTT26YuSi5Oox3lcQJP1FYNR6AE=";
})
];
nativeBuildInputs = [
pkg-config
doxygen # (optional) api docs

View File

@@ -94,7 +94,7 @@ rec {
};
# Eventually, switch to an updateScript without versionPrefix hardcoded...
thunderbird-esr = thunderbird-140;
thunderbird-esr = thunderbird-153;
thunderbird-153 = common {
applicationName = "Thunderbird ESR";

View File

@@ -0,0 +1,59 @@
--- a/service/server/CMakeLists.txt
+++ b/service/server/CMakeLists.txt
@@ -341,56 +341,6 @@
)
endif()
-# install non-linked dependencies
-if(WIN32)
- find_package(awg-windows REQUIRED)
- list(APPEND CONAN_EXECS $<TARGET_FILE:amnezia::awg-windows>)
-
- find_package(wintun REQUIRED)
- list(APPEND CONAN_BINS $<TARGET_FILE:zx2c4::wintun>)
-
- list(APPEND CONAN_BINS $<TARGET_FILE:OpenSSL::SSL> $<TARGET_FILE:OpenSSL::Crypto>)
-else()
- find_package(awg-go REQUIRED)
- list(APPEND CONAN_EXECS $<TARGET_FILE:amnezia::awg-go>)
-endif()
-
-find_package(openvpn REQUIRED)
-list(APPEND CONAN_EXECS $<TARGET_FILE:openvpn::openvpn>)
-
-find_package(tun2socks REQUIRED)
-list(APPEND CONAN_EXECS $<TARGET_FILE:xjasonlyu::tun2socks>)
-
-find_package(v2ray-rules-dat REQUIRED)
-list(APPEND CONAN_BINS ${GEOSITE_DAT_PATH} ${GEOIP_DAT_PATH})
-
-add_custom_command(TARGET ${PROJECT} POST_BUILD
- COMMAND ${CMAKE_COMMAND} -E copy_if_different
- ${CONAN_EXECS} ${CONAN_BINS}
- "$<TARGET_FILE_DIR:${PROJECT}>"
-)
-if(WIN32)
- # using PERMISSIONS on Windows appends read-only flag
- # to the files so just omit it for it
- install(FILES ${CONAN_EXECS}
- DESTINATION ${CMAKE_INSTALL_BINDIR}
- COMPONENT AmneziaVPN
- )
-else()
- install(FILES ${CONAN_EXECS}
- DESTINATION ${CMAKE_INSTALL_BINDIR}
- COMPONENT AmneziaVPN
- PERMISSIONS
- OWNER_READ OWNER_EXECUTE
- GROUP_READ GROUP_EXECUTE
- WORLD_READ WORLD_EXECUTE
- )
-endif()
-install(FILES ${CONAN_BINS}
- DESTINATION ${CMAKE_INSTALL_BINDIR}
- COMPONENT AmneziaVPN
-)
-
# install drivers
if (WIN32)
find_package(tap-windows6 REQUIRED)

View File

@@ -2,69 +2,66 @@
lib,
stdenv,
fetchFromGitHub,
fetchpatch,
fetchurl,
cmake,
pkg-config,
kdePackages,
qt6,
libsecret,
amneziawg-go,
openvpn,
shadowsocks-rust,
cloak-pt,
wireguard-tools,
libssh,
zlib,
openssl,
tun2socks,
xray,
nix-update-script,
bash,
v2ray-rules-dat,
runtimeShell,
callPackage,
nix-update-script,
}:
let
amneziawg' = amneziawg-go.overrideAttrs (
finalAttrs: prevAttrs: {
name = "amneziawg-go";
version = "0.2.16";
# These helper versions are part of upstream's runtime compatibility contract.
# Even minor updates can break VPN connections without failing the build.
amneziawg-go-pinned = amneziawg-go.overrideAttrs (
finalAttrs: _: {
version = "3.0.1";
src = fetchFromGitHub {
owner = "amnezia-vpn";
repo = "amneziawg-go";
tag = "v${finalAttrs.version}";
hash = "sha256-JGmWMPVgereSZmdHUHC7ZqWCwUNfxfj3xBf/XDDHhpo=";
hash = "sha256-wtjUJSTDWWgJLedyQPlPa+TtOztciyDWIbyZ24N5ELM=";
};
vendorHash = "sha256-ZO8sLOaEY3bii9RSxzXDTCcwlsQEYmZDI+X1WPXbE9c=";
vendorHash = "sha256-Y2dCwlKMVLrkzDcNKyCPxFJwMbCA2mQKkakvzwbamCY=";
}
);
tun2socks' = tun2socks.overrideAttrs (
finalAttrs: prevAttrs: {
pname = "tun2socks";
version = "2.5.2-c8f8cb5";
tun2socks-pinned = tun2socks.overrideAttrs (
finalAttrs: _: {
version = "2.6.0";
src = fetchFromGitHub {
owner = "xjasonlyu";
repo = "tun2socks";
rev = "c8f8cb5caf6796039a08d3ebad5354767795628b";
hash = "sha256-VF8Mm323w0dwhXyFAJVi67BWepury59sVq1+DDzBjU8=";
tag = "v${finalAttrs.version}";
hash = "sha256-ec4M107BE6MCnW/uz9S83JYJtY9tsQQXDFL98h951DA=";
};
vendorHash = "sha256-fHwr/Hnqufgi3D93GLxd5lqNetJswWvQ0+MqPq3QxV4=";
vendorHash = "sha256-YAAdyV2p/Ci9RzgVWYXBwR/ctERSQ8SPK7AbwRuUJiI=";
ldflags = [
"-w"
"-s"
"-X github.com/xjasonlyu/tun2socks/v2/internal/version.Version=v${finalAttrs.version}"
"-X github.com/xjasonlyu/tun2socks/v2/internal/version.GitCommit=v${finalAttrs.version}"
];
}
);
amnezia-xray = callPackage ./xray-lib.nix { };
# Amnezia Gateway (AGW) public keys for premium server list verification.
# These PEM-formatted RSA public keys are hardcoded in the upstream binary
# and used to verify signatures on server list responses from the AGW service.
# The original values were extracted from the upstream linux binary using
# `strings` command, as they are not present in any public source files.
# Newlines are escaped (\n -> \\n) to prevent Makefile generation failures
# during build when these variables are exported via preConfigure.
# These build-time values are not published in the source repository and
# were extracted from the official 5.0.0.5 Linux binary.
dev-agw-public-key = lib.replaceStrings [ "\n" ] [ "\\n" ] (builtins.readFile ./dev_agw_public_key);
dev-agw-endpoint = "http://gw.dev.amzsvc.com:80/";
dev-s3-endpoint = "https://s3.eu-north-1.amazonaws.com/amnezia-dev/";
@@ -74,14 +71,20 @@ let
);
prod-s3-endpoint = lib.concatStringsSep ", " [
"https://s3.eu-north-1.amazonaws.com/amnezia/"
"https://amnzstrg01.blob.core.windows.net/lambda-list/"
"https://storage.googleapis.com/lambda-list/"
"https://amnzstrg01.blob.core.windows.net/lambda-list/"
"https://objectstorage.eu-zurich-1.oraclecloud.com/n/zrhfyaq6qxvh/b/lambda-list/o/"
];
fallback-s3-endpoint = lib.concatStringsSep ", " [
"https://storage.mwsapis.ru/lambda-list/"
"https://46.8.209.252/lambda-list/"
];
free-v2-endpoint = "13.248.139.44";
prem-v1-endpoint = "52.223.54.40";
in
stdenv.mkDerivation (finalAttrs: {
pname = "amnezia-vpn";
version = "4.8.21.0";
version = "5.0.0.5";
__structuredAttrs = true;
@@ -89,89 +92,126 @@ stdenv.mkDerivation (finalAttrs: {
owner = "amnezia-vpn";
repo = "amnezia-client";
tag = finalAttrs.version;
hash = "sha256-xNmbXLl+71DhzbGdSobkV1aYbj1XqC9A/3VPjDLsF7A=";
hash = "sha256-knQgGyNkOV9CX1I0hJ8xEMRENBV35E2DwWUOgby3iUo=";
fetchSubmodules = true;
# Preserve VCS metadata needed by the build before .git is removed.
postCheckout = ''
git -C "$out" rev-parse --short HEAD > "$out/.git-revision"
git -C "$out" show -s --format=%ct HEAD > "$out/.source-date-epoch"
'';
};
# Runtime helpers are referenced through their immutable Nix store paths.
patches = [ ./disable-conan-runtime-bundling.patch ];
postPatch = ''
# Conan performs network dependency resolution during CMake configuration.
substituteInPlace CMakeLists.txt \
--replace-fail "\''${CMAKE_SOURCE_DIR}/cmake/recipes_bootstrap.cmake" "" \
--replace-fail "\''${CMAKE_SOURCE_DIR}/cmake/conan_provider.cmake" ""
# Read the revision captured by postCheckout into upstream's GIT_COMMIT_HASH.
substituteInPlace client/CMakeLists.txt \
--replace-fail 'git rev-parse --short HEAD' '"''${CMAKE_COMMAND}" -E cat "''${CMAKE_SOURCE_DIR}/.git-revision"'
# Upstream expects these helper executables next to the application binaries.
substituteInPlace client/core/utils/utilities.cpp \
--replace-fail 'Utils::executable("openvpn", true)' 'Utils::executable("${openvpn}/bin/openvpn", false)' \
--replace-fail 'Utils::usrExecutable("wg-quick")' 'Utils::executable("${wireguard-tools}/bin/wg-quick", false)' \
--replace-fail 'Utils::executable("tun2socks", true)' 'Utils::executable("${tun2socks-pinned}/bin/tun2socks", false)'
substituteInPlace client/platforms/linux/daemon/wireguardutilslinux.cpp \
--replace-fail 'm_tunnel.start(appPath.filePath("../../client/bin/wireguard-go"), wgArgs);' 'm_tunnel.start("${amneziawg'}/bin/amneziawg-go", wgArgs);'
substituteInPlace client/utilities.cpp \
--replace-fail 'return Utils::executable("../../client/bin/openvpn", true);' 'return Utils::executable("${openvpn}/bin/openvpn", false);' \
--replace-fail 'return Utils::executable("../../client/bin/tun2socks", true);' 'return Utils::executable("${tun2socks'}/bin/tun2socks", false);' \
--replace-fail 'return Utils::usrExecutable("wg-quick");' 'return Utils::executable("${wireguard-tools}/bin/wg-quick", false);'
substituteInPlace client/protocols/openvpnovercloakprotocol.cpp \
--replace-fail 'return Utils::executable(QString("/ck-client"), true);' 'return Utils::executable(QString("${cloak-pt}/bin/ck-client"), false);'
substituteInPlace client/protocols/shadowsocksvpnprotocol.cpp \
--replace-fail 'return Utils::executable(QString("/ss-local"), true);' 'return Utils::executable(QString("${shadowsocks-rust}/bin/sslocal"), false);'
substituteInPlace client/configurators/openvpn_configurator.cpp \
--replace-fail ".arg(qApp->applicationDirPath());" ".arg(\"$out/libexec\");" \
--replace-fail "int nVersion = 1;" "int nVersion = 0;"
substituteInPlace client/ui/qautostart.cpp \
--replace-fail "/usr/share/pixmaps/AmneziaVPN.png" "AmneziaVPN"
# https://github.com/amnezia-vpn/amnezia-client/pull/2372
substituteInPlace client/ui/systemtray_notificationhandler.cpp \
--replace-fail 'm_systemTrayIcon.show();' ''' \
--replace-fail 'setTrayState(Vpn::ConnectionState::Disconnected);' 'setTrayState(Vpn::ConnectionState::Disconnected); m_systemTrayIcon.show();'
--replace-fail 'QDir appPath(QCoreApplication::applicationDirPath());' "" \
--replace-fail 'appPath.filePath("amneziawg-go")' 'QString::fromUtf8("${amneziawg-go-pinned}/bin/amneziawg-go")'
# nixpkgs' libssh CMake config exports "ssh", while Conan exports "ssh::ssh".
substituteInPlace client/cmake/3rdparty.cmake \
--replace-fail 'list(APPEND LIBS ssh::ssh)' 'list(APPEND LIBS ssh)'
# The resolver script is installed in libexec instead of beside the GUI binary.
substituteInPlace client/core/configurators/openVpnConfigurator.cpp \
--replace-fail '.arg(qApp->applicationDirPath()))' ".arg(\"$out/libexec\"))"
substituteInPlace client/platforms/linux/daemon/linuxfirewall.cpp \
--replace-fail 'QStringLiteral("/bin/bash")' 'QStringLiteral("${runtimeShell}")'
# Use a stable PATH lookup so autostart does not point at the hidden Qt wrapper.
substituteInPlace client/ui/utils/qAutoStart.cpp \
--replace-fail '/usr/share/pixmaps/AmneziaVPN.png' 'AmneziaVPN' \
--replace-fail '"Exec=" << appPath()' '"Exec=AmneziaVPN --autostart"'
# The tray icon must be initialized before it is shown.
substituteInPlace client/ui/utils/systemTrayNotificationHandler.cpp \
--replace-fail 'm_systemTrayIcon.show();' "" \
--replace-fail 'setTrayState(Vpn::ConnectionState::Disconnected);' $'setTrayState(Vpn::ConnectionState::Disconnected);\n m_systemTrayIcon.show();'
# Upstream does not set a window icon on Linux.
substituteInPlace client/main.cpp \
--replace-fail '#include "version.h"' $'#include "version.h"\n#include <QIcon>' \
--replace-fail 'app.setApplicationDisplayName(APPLICATION_NAME);' $'app.setApplicationDisplayName(APPLICATION_NAME);\n app.setWindowIcon(QIcon::fromTheme("AmneziaVPN"));'
substituteInPlace deploy/installer/config/AmneziaVPN.desktop.in \
--replace-fail "/usr/share/pixmaps/AmneziaVPN.png" "$out/share/icons/hicolor/512x512/apps/AmneziaVPN.png"
substituteInPlace deploy/data/linux/AmneziaVPN.service \
--replace-fail "ExecStart=/opt/AmneziaVPN/service/AmneziaVPN-service.sh" "ExecStart=$out/bin/AmneziaVPN-service" \
--replace-fail "Environment=LD_LIBRARY_PATH=/opt/AmneziaVPN/client/lib" ""
substituteInPlace client/cmake/3rdparty.cmake \
--replace-fail 'set(LIBSSH_LIB_PATH "''${LIBSSH_ROOT_DIR}/linux/x86_64/libssh.a")' 'set(LIBSSH_LIB_PATH "${libssh}/lib/libssh.so")' \
--replace-fail 'set(ZLIB_LIB_PATH "''${LIBSSH_ROOT_DIR}/linux/x86_64/libz.a")' 'set(ZLIB_LIB_PATH "${zlib}/lib/libz.so")' \
--replace-fail 'set(OPENSSL_INCLUDE_DIR "''${OPENSSL_ROOT_DIR}/linux/include")' 'set(OPENSSL_INCLUDE_DIR "${openssl.dev}/include")' \
--replace-fail 'set(OPENSSL_LIB_SSL_PATH "''${OPENSSL_ROOT_DIR}/linux/x86_64/libssl.a")' 'set(OPENSSL_LIB_SSL_PATH "${openssl.out}/lib/libssl.so")' \
--replace-fail 'set(OPENSSL_LIB_CRYPTO_PATH "''${OPENSSL_ROOT_DIR}/linux/x86_64/libcrypto.a")' 'set(OPENSSL_LIB_CRYPTO_PATH "${openssl.out}/lib/libcrypto.so")' \
--replace-fail 'set(OPENSSL_USE_STATIC_LIBS TRUE)' 'set(OPENSSL_USE_STATIC_LIBS FALSE)'
# Xray otherwise looks for geoip.dat and geosite.dat beside the service binary.
substituteInPlace service/server/xray.cpp \
--replace-fail 'qDebug() << "Xray::startXray()";' $'qDebug() << "Xray::startXray()";\n qputenv("XRAY_LOCATION_ASSET", QByteArrayLiteral("${v2ray-rules-dat}/share/v2ray"));'
# Link the Nix-built bindings directly instead of using a Conan package.
substituteInPlace service/server/CMakeLists.txt \
--replace-fail 'set(OPENSSL_INCLUDE_DIR "''${OPENSSL_ROOT_DIR}/linux/include")' 'set(OPENSSL_INCLUDE_DIR "${openssl.dev}/include")' \
--replace-fail 'set(OPENSSL_LIB_CRYPTO_PATH "''${OPENSSL_ROOT_DIR}/linux/x86_64/libcrypto.a")' 'set(OPENSSL_LIB_CRYPTO_PATH "${openssl.out}/lib/libcrypto.so")' \
--replace-fail 'set(OPENSSL_USE_STATIC_LIBS TRUE)' 'set(OPENSSL_USE_STATIC_LIBS FALSE)' \
--replace-fail 'set(AMNEZIA_XRAY_LIB_PATH "''${AMNEZIA_XRAY_ROOT_DIR}/linux/x86_64/amnezia_xray.a")' 'set(AMNEZIA_XRAY_LIB_PATH "${amnezia-xray}/lib/amnezia_xray.a")' \
--replace-fail 'set(AMNEZIA_XRAY_INCLUDE_DIR "''${AMNEZIA_XRAY_ROOT_DIR}/linux/x86_64")' 'set(AMNEZIA_XRAY_INCLUDE_DIR "${amnezia-xray}/include")'
--replace-fail 'find_package(amnezia-xray-bindings REQUIRED)' 'target_include_directories(''${PROJECT} PRIVATE "${amnezia-xray}/include")' \
--replace-fail 'amnezia::xray-bindings' '"${amnezia-xray}/lib/libamnezia_xray.a"'
substituteInPlace deploy/data/linux/AmneziaVPN.desktop \
--replace-fail 'Icon=/usr/share/pixmaps/AmneziaVPN.png' 'Icon=AmneziaVPN'
substituteInPlace deploy/data/linux/AmneziaVPN.service \
--replace-fail 'ExecStart=/opt/AmneziaVPN/bin/AmneziaVPN-service' "ExecStart=$out/bin/AmneziaVPN-service"
substituteInPlace deploy/data/linux/update-resolv-conf.sh \
--replace-fail '#!/usr/bin/env bash' '#!${runtimeShell}'
'';
strictDeps = true;
nativeBuildInputs = [
cmake
kdePackages.qttools
kdePackages.wrapQtAppsHook
pkg-config
qt6.wrapQtAppsHook
];
buildInputs = [
bash
kdePackages.qt5compat
kdePackages.qtbase
kdePackages.qtdeclarative
kdePackages.qtremoteobjects
kdePackages.qtsvg
libsecret
qt6.qtbase
qt6.qttools
libssh
openssl
];
# These environment variables are baked into the binary at build time.
# They configure which Amnezia Gateway servers and S3 endpoints the client
# uses for fetching verified server lists (premium functionality).
# These values are baked into the binary at build time. In addition to the
# AGW key and storage endpoints, the two legacy API markers are required to
# classify imported Free v2 and Premium v1 configurations correctly.
preConfigure = ''
# Use the commit timestamp for reproducible __DATE__ and CMake timestamps.
export SOURCE_DATE_EPOCH="$(< .source-date-epoch)"
export DEV_AGW_PUBLIC_KEY="${dev-agw-public-key}"
export DEV_AGW_ENDPOINT="${dev-agw-endpoint}"
export DEV_S3_ENDPOINT="${dev-s3-endpoint}"
export PROD_AGW_PUBLIC_KEY="${prod-agw-public-key}"
export PROD_S3_ENDPOINT="${prod-s3-endpoint}"
export FALLBACK_S3_ENDPOINT="${fallback-s3-endpoint}"
export FREE_V2_ENDPOINT="${free-v2-endpoint}"
export PREM_V1_ENDPOINT="${prem-v1-endpoint}"
'';
installPhase = ''
runHook preInstall
install -Dm555 client/AmneziaVPN service/server/AmneziaVPN-service -t $out/bin/
install -Dm555 ../deploy/data/linux/client/bin/update-resolv-conf.sh -t $out/libexec/
install -Dm444 ../AppDir/AmneziaVPN.desktop -t $out/share/applications/
install -Dm444 ../deploy/data/linux/AmneziaVPN.png -t $out/share/icons/hicolor/512x512/apps
install -Dm555 ../deploy/data/linux/update-resolv-conf.sh -t $out/libexec/
install -Dm444 ../deploy/data/linux/AmneziaVPN.desktop -t $out/share/applications/
install -Dm444 ../deploy/data/linux/AmneziaVPN.png -t $out/share/icons/hicolor/512x512/apps/
install -Dm444 ../deploy/data/linux/AmneziaVPN.service -t $out/lib/systemd/system/
runHook postInstall
@@ -185,7 +225,7 @@ stdenv.mkDerivation (finalAttrs: {
description = "Amnezia VPN Client";
downloadPage = "https://amnezia.org/en/downloads";
homepage = "https://github.com/amnezia-vpn/amnezia-client";
license = lib.licenses.gpl3;
license = lib.licenses.gpl3Only;
mainProgram = "AmneziaVPN";
maintainers = with lib.maintainers; [ sund3RRR ];
platforms = lib.platforms.linux;

View File

@@ -1,20 +1,20 @@
{
fetchFromGitHub,
buildGo126Module,
buildGoModule,
}:
buildGo126Module rec {
buildGoModule rec {
pname = "amnezia-xray";
version = "1.1.0";
version = "1.3.0";
src = fetchFromGitHub {
owner = "amnezia-vpn";
repo = "amnezia-xray-bindings";
tag = "v${version}";
hash = "sha256-HZ6qHHDMev8FoOIplWAaPOlCSfikpgKClvbxl+877S0=";
hash = "sha256-kGtRw5Ic/++1ehwLToZ96WfC3ULp+DIsPYArqjL06ck=";
};
vendorHash = "sha256-ac+wJrwdTtLFJG+Ka1Ksb1P+3lI7sFwCh4Nr5+fPgq0=";
vendorHash = "sha256-JAHpQUMQT6tJKwGld0QCobDxgLVujA4KHkhOLXHS65w=";
env.CGO_ENABLED = 1;
@@ -30,7 +30,7 @@ buildGo126Module rec {
installPhase = ''
runHook preInstall
install -Dm444 build/amnezia_xray.a -t $out/lib/
install -Dm444 build/amnezia_xray.a $out/lib/libamnezia_xray.a
install -Dm444 build/amnezia_xray.h -t $out/include/
runHook postInstall

View File

@@ -7,13 +7,13 @@
stdenvNoCC.mkDerivation {
pname = "ananicy-rules-cachyos";
version = "0-unstable-2026-08-05";
version = "0-unstable-2026-08-24";
src = fetchFromGitHub {
owner = "CachyOS";
repo = "ananicy-rules";
rev = "489dd6c929d17e4f6a374746ebfce9fa7bd5a3d1";
hash = "sha256-FVN689V2b6lNu15Nx7TJsn+DqukhFZDL8ebtplFdYNs=";
rev = "0502a45a0eb7bf5ddf2689cba63bfff8673da4bc";
hash = "sha256-7V0StPvWmbx/GKdxQ1+5rnulo9hQzQEiKoaSVstBwz0=";
};
dontConfigure = true;

View File

@@ -12,16 +12,16 @@
}:
rustPlatform.buildRustPackage (finalAttrs: {
pname = "arnis";
version = "3.0.0";
version = "3.1.0";
src = fetchFromGitHub {
owner = "louis-e";
repo = "arnis";
tag = "v${finalAttrs.version}";
hash = "sha256-mdBicZIHonfVs2r6eNRNdpr8saZ54k1m0czWRqBYvq4=";
hash = "sha256-BS+kzgVE3DnFrV1V5FQuKG0cytbFhcLZdJbXNPAvcmc=";
};
cargoHash = "sha256-G0lEKjF9xNF4zs/+yf/8fvZTRZOH6IGud0tpEB86IXE=";
cargoHash = "sha256-h8dy4ZdQFY8tYS9fuV4p6FM0IrFFWgJrhM5Dd8L96Yc=";
nativeBuildInputs = [
cargo-tauri.hook

View File

@@ -0,0 +1,44 @@
{
lib,
callPackage,
rustPlatform,
fetchFromGitHub,
capnproto,
autopen,
}:
rustPlatform.buildRustPackage (finalAttrs: {
pname = "autopen";
version = "0.2.0";
src = fetchFromGitHub {
owner = "emilazy";
repo = "autopen";
tag = "v${finalAttrs.version}";
hash = "sha256-7/uAwpNNQByKAjrpr6R40dkVWg5t15bqLD4KJNT53wI=";
};
cargoHash = "sha256-baV0suVBCgV/gFnAD5uo6fpfQg/CYreyFgsiEGTmH3A=";
nativeBuildInputs = [
capnproto
];
useNextest = true;
cargoTestFlags = [ "--max-fail=all" ];
strictDeps = true;
__structuredAttrs = true;
meta = {
description = "Cryptographic signing tool with an object‐capability interface";
homepage = "https://github.com/emilazy/autopen";
license = lib.licenses.blueOak100;
sourceProvenance = [ lib.sourceTypes.fromSource ];
teams = [ lib.teams.boot-security ];
mainProgram = "autopen";
platforms = lib.platforms.unix;
};
})

View File

@@ -9,7 +9,7 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "badness";
version = "0.16.0";
version = "0.20.0";
__structuredAttrs = true;
@@ -17,10 +17,10 @@ rustPlatform.buildRustPackage (finalAttrs: {
owner = "jolars";
repo = "badness";
tag = "v${finalAttrs.version}";
hash = "sha256-3aGxmn7H+OHJbjsLn3P6FxkXYGSe5xJoRGw/pkkQApM=";
hash = "sha256-sYJncBf3BvGhYRBWJ4hs/KUCI1GL1AbyA/dDBmE9hjs=";
};
cargoHash = "sha256-S0npMUULDwkMgl8z8W8vunL+E9ZMlfQk5P/8f3bgo0Y=";
cargoHash = "sha256-Vxk64GnwJdK+snTHsaneZbORqm/s8WF+uRr9tuDVoBs=";
nativeBuildInputs = [
installShellFiles

View File

@@ -13,17 +13,17 @@
}:
rustPlatform.buildRustPackage (finalAttrs: {
pname = "bichon";
version = "2.0.1";
version = "2.0.2";
__structuredAttrs = true;
src = fetchFromGitHub {
owner = "rustmailer";
repo = "bichon";
tag = finalAttrs.version;
hash = "sha256-pL/1W51x9ZqUHLLzdLUpb54crvhG8JhDqJu47CRZAd4=";
hash = "sha256-0RBMkm5qUnc18JLJ3mRcLgtk9YjKsrMJCmaRat/7wUo=";
};
cargoHash = "sha256-R2gegIZJDr2Xu8VjOiUlPIkG4JXnyFLjMoU1gcSNcEk=";
cargoHash = "sha256-F2zuAh9mPdpZUAHvbRTPN0bTTaaBI77goEIjgjkfMXc=";
pnpmDeps = fetchPnpmDeps {
inherit (finalAttrs) pname version src;

View File

@@ -15,7 +15,7 @@
rustPlatform.buildRustPackage (finalAttrs: {
pname = "eilmeldung";
version = "1.7.2";
version = "1.7.3";
__structuredAttrs = true;
@@ -23,10 +23,10 @@ rustPlatform.buildRustPackage (finalAttrs: {
owner = "christo-auer";
repo = "eilmeldung";
tag = finalAttrs.version;
hash = "sha256-QCGtuf1XSLpWr72GYUsz20JllWHNJ7Q4cAtNTywi4JM=";
hash = "sha256-gwkb2CZxaZaKpI2TafFyyfmerjdOjE0rYLu72SLhmI0=";
};
cargoHash = "sha256-8ICcVeL/wFcrWbdmvu3HVHVsts9541ZkBtxDamLjcok=";
cargoHash = "sha256-8UfVvSoWfN30G6GN2s3QMAG1pDEgIVTyL/l+ickiU5s=";
nativeBuildInputs = [
pkg-config

View File

@@ -9,16 +9,16 @@
}:
buildGoModule (finalAttrs: {
pname = "fluxcd-operator-mcp";
version = "0.58.0";
version = "0.58.1";
src = fetchFromGitHub {
owner = "controlplaneio-fluxcd";
repo = "flux-operator";
tag = "v${finalAttrs.version}";
hash = "sha256-2+/60Hp1OGvVJtFUFom1ax4ALdxXOoevEXt9oyUjazI=";
hash = "sha256-XGjRP9JvEpuVNKcErTKmKi4TGBADpbI1DDXYDd0Bbb4=";
};
vendorHash = "sha256-uTj6P6UZtfFf7jBrRZMWJ3HObiSR/tPlFICk6Cw12WQ=";
vendorHash = "sha256-9iDxoWnizmTQ4FqxjlGPQO8Au2FxIdcgggtP+3dTOaU=";
ldflags = [
"-s"

View File

@@ -14,7 +14,7 @@
stdenvNoCC.mkDerivation (finalAttrs: {
pname = "folia-major";
version = "0.6.19";
version = "0.7.0";
strictDeps = true;
__structuredAttrs = true;
@@ -23,12 +23,12 @@ stdenvNoCC.mkDerivation (finalAttrs: {
owner = "chthollyphile";
repo = "folia-major";
tag = "v${finalAttrs.version}";
hash = "sha256-H515DVSwMEz/2DyST3D55KaoBWJX1UX4on7im849J3k=";
hash = "sha256-vVWE4k5GDyGuv20rLjR4DNMN+A6qyBNzUyJYNvAZo64=";
};
npmDeps = fetchNpmDeps {
inherit (finalAttrs) src;
hash = "sha256-7MIjM/US39wW+Xk6soMZuKdmL7KOONXcA6zIGGJ45CA=";
hash = "sha256-N4sD1R921+1lviUBbgRejqm4Angb/XIpBFm8cuUP8Zc=";
};
nativeBuildInputs = [

View File

@@ -14,8 +14,9 @@
wayland,
git,
xdg-utils,
makeWrapper,
makeBinaryWrapper,
writableTmpDirAsHomeHook,
testers,
versionCheckHook,
nix-update-script,
}:
@@ -34,8 +35,7 @@ rustPlatform.buildRustPackage (finalAttrs: {
cargoHash = "sha256-L/UXaXC1zymbNfv7SGmOYSvUy/767mAWqL+3jwJwWcE=";
cargoDepsName = finalAttrs.pname;
# Disable upstream's rustflags overrides to avoid linker and CPU target issues
postPatch = ''
rm .cargo/config.toml
'';
@@ -43,7 +43,7 @@ rustPlatform.buildRustPackage (finalAttrs: {
nativeBuildInputs = [
pkg-config
desktop-file-utils
makeWrapper
makeBinaryWrapper
];
buildInputs = [
@@ -114,16 +114,27 @@ rustPlatform.buildRustPackage (finalAttrs: {
nativeInstallCheckInputs = [ versionCheckHook ];
versionCheckProgramArg = "--version";
passthru.updateScript = nix-update-script {
extraArgs = [
"--version-regex=^v([0-9]+[.][0-9]+[.][0-9]+)$"
];
passthru = {
updateScript = nix-update-script {
extraArgs = [
"--version-regex=^v([0-9]+[.][0-9]+[.][0-9]+)$"
"--use-github-releases"
];
};
tests.version = testers.testVersion {
package = finalAttrs.finalPackage;
};
};
meta = {
description = "Fast, resource-efficient Git GUI written in Rust";
longDescription = ''
GitComet is a Git graphical client built with Rust and the gpui
toolkit, using gix as its Git implementation.
'';
homepage = "https://gitcomet.dev";
changelog = "https://github.com/Auto-Explore/GitComet/releases/tag/v${finalAttrs.version}";
# ofl covers the bundled font assets.
license = with lib.licenses; [
agpl3Only
ofl

View File

@@ -11,13 +11,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "labwc-menu-generator";
version = "0.2.0-unstable-2026-08-15";
version = "0.2.0-unstable-2026-08-21";
src = fetchFromGitHub {
owner = "labwc";
repo = "labwc-menu-generator";
rev = "ae466068ffaea10d10819d993b012da9e27a169a";
hash = "sha256-mzBgqmpMLq3VTn9gkbEkH3jHMsDBWZ/XnWUFIcOo28s=";
rev = "b31ae37532d77e638e27e8a3f3a4865ca5ccab71";
hash = "sha256-iKaHQdpYGG0gk9uWh2NPFhn/LEw6Bu1tgbvVqGZdWNA=";
};
nativeBuildInputs = [

View File

@@ -2,10 +2,7 @@
lib,
stdenv,
fetchFromGitHub,
fetchpatch,
autoreconfHook,
autoconf,
automake,
cmake,
pkg-config,
utf8cpp,
libtool,
@@ -16,19 +13,17 @@
stdenv.mkDerivation rec {
pname = "lttoolbox";
version = "3.7.6";
version = "3.8.2";
src = fetchFromGitHub {
owner = "apertium";
repo = "lttoolbox";
tag = "v${version}";
hash = "sha256-T92TEhrWwPYW8e49rc0jfM0C3dmNYtuexhO/l5s+tQ0=";
hash = "sha256-g9mWHd9MzVKg/6zF7Fh7owFM3uX9vOQzX0IkrEzr5LY=";
};
nativeBuildInputs = [
autoreconfHook
autoconf
automake
cmake
pkg-config
utf8cpp
libtool
@@ -40,12 +35,19 @@ stdenv.mkDerivation rec {
buildFlags = [
"CPPFLAGS=-I${utf8cpp}/include/utf8cpp"
];
cmakeFlags = [
];
# Workaround based on
# https://github.com/NixOS/nixpkgs/issues/144170#issuecomment-1423195220
# for https://github.com/apertium/lttoolbox/issues/207
preInstall = ''
sed -i.tmp 's,[$$]{\(exec_\)*prefix}//nix/store,/nix/store,' ./lttoolbox.pc
rm ./lttoolbox.pc.tmp
'';
nativeCheckInputs = [ python3 ];
doCheck = true;
checkPhase = ''
python3 tests/run_tests.py
'';
meta = {
description = "Finite state compiler, processor and helper tools used by apertium";

View File

@@ -10,16 +10,16 @@
buildGoModule (finalAttrs: {
pname = "nak";
version = "0.20.3";
version = "0.20.6";
src = fetchFromGitHub {
owner = "fiatjaf";
repo = "nak";
tag = "v${finalAttrs.version}";
hash = "sha256-mgmeAodINFqIKXCnozKChU3jRLR/J5gCGlctzW6PkSI=";
hash = "sha256-RNKKkYc6PN/BbYqwUkRWg3o3lzQHg1NONvfqGxQ6t10=";
};
vendorHash = "sha256-hS3YOuz6nx0K4EtUBfJsLAUHDHqe/hSB/mRVeThBnuI=";
vendorHash = "sha256-J1prpdOX2wXfPOkJ/GYetW3Agz5pUeyAj4zBplz4xRw=";
ldflags = [
"-s"

View File

@@ -7,13 +7,13 @@
buildGoModule (finalAttrs: {
pname = "nats-server";
version = "2.14.5";
version = "2.14.6";
src = fetchFromGitHub {
owner = "nats-io";
repo = "nats-server";
rev = "v${finalAttrs.version}";
hash = "sha256-rsbvFUJcprWEZx0SPfIr+M0IyyCYbDncBLenOBniumM=";
hash = "sha256-k6iKQenlbb2TwWFt87MqnlskfX8F+Ett4QCQ8ZmMCLk=";
};
vendorHash = "sha256-VB4x100hSSsY6fqODuIefanzchOHlfyfJrNSJUea42U=";

View File

@@ -22,9 +22,9 @@ let
phome = "$out/lib/olympus";
# The following variables are to be updated by the update script.
version = "26.07.27.01";
buildId = "5729"; # IMPORTANT: This line is matched with regex in update.sh.
rev = "27b8912f014cebb985a9216efef82f1cfe0eb016";
version = "26.08.24.03";
buildId = "5805"; # IMPORTANT: This line is matched with regex in update.sh.
rev = "2b7016e4f59fcaf8feafb16f8ff83acd3d814ac6";
in
buildDotnetModule {
pname = "olympus-unwrapped";
@@ -37,7 +37,7 @@ buildDotnetModule {
owner = "EverestAPI";
repo = "Olympus";
fetchSubmodules = true; # Required. See upstream's README.
hash = "sha256-XLP0OOI+qb10pZ135BBVw9MI4s7fFIEmXJVgKbxW6oA=";
hash = "sha256-aKp0QMQfnwwV2IOorHZM+qYBx0K3AAbnyrGkv2iSWHY=";
};
nativeBuildInputs = [

View File

@@ -8,16 +8,16 @@
buildGoModule rec {
pname = "omnictl";
version = "1.10.0";
version = "1.10.5";
src = fetchFromGitHub {
owner = "siderolabs";
repo = "omni";
rev = "v${version}";
hash = "sha256-9hzNQfAGVZlMxLg5n2zFmCqeYJmss2PxpSV+KIgX29g=";
hash = "sha256-UV106G6B2ygT83zUe5C8HrS1/TLixZtmyI4OGqqAUfY=";
};
vendorHash = "sha256-3a0Sqlmsl0FlvKl9vm13qpwFdj1mjOgMKkqjt1d+XIY=";
vendorHash = "sha256-02wymmQpzojZej+v5lhZ3SDXwVq3l6Wr64fIKp8L6vk=";
ldflags = [
"-s"

View File

@@ -54,13 +54,13 @@ in
stdenv.mkDerivation (finalAttrs: {
pname = "open-vm-tools";
version = "13.0.5";
version = "13.1.0";
src = fetchFromGitHub {
owner = "vmware";
repo = "open-vm-tools";
tag = "stable-${finalAttrs.version}";
hash = "sha256-N0z7OpJP8ubYOeb0KHEQkITlWkKP04rpm79VXRnCe0I=";
hash = "sha256-XDIgWp6imGVFrodDAncTKh4ohGkTQKulAw5AC4iQ/zc=";
};
sourceRoot = "${finalAttrs.src.name}/open-vm-tools";

View File

@@ -26,6 +26,7 @@
libvorbis,
libzip,
makeWrapper,
makeBinaryWrapper,
nlohmann_json,
openssl,
pkg-config,
@@ -88,6 +89,7 @@ stdenv.mkDerivation (finalAttrs: {
pkg-config
unzip
makeWrapper
makeBinaryWrapper
versionCheckHook
];
@@ -124,14 +126,64 @@ stdenv.mkDerivation (finalAttrs: {
(lib.cmakeBool "DOWNLOAD_OPENSFX" false)
(lib.cmakeBool "DOWNLOAD_TITLE_SEQUENCES" false)
(lib.cmakeBool "DISABLE_DISCORD_RPC" (!withDiscordRpc))
]
++ lib.optionals stdenv.hostPlatform.isDarwin [
(lib.cmakeBool "MACOS_USE_DEPENDENCIES" false)
(lib.cmakeBool "MACOS_BUNDLE" true)
];
postUnpack = ''
mkdir -p $sourceRoot/data/{object,sequence}
unzip -o ${finalAttrs.passthru.assets.objects} -d $sourceRoot/data/object
unzip -o ${finalAttrs.passthru.assets.openmusic} -d $sourceRoot/data
unzip -o ${finalAttrs.passthru.assets.opensfx} -d $sourceRoot/data
unzip -o ${finalAttrs.passthru.assets.title-sequences} -d $sourceRoot/data/sequence
export OPENRCT2_ASSETS_DIR=$sourceRoot/${if stdenv.hostPlatform.isDarwin then "build" else "data"}
mkdir -p $OPENRCT2_ASSETS_DIR/{object,sequence}
unzip -o ${finalAttrs.passthru.assets.objects} -d $OPENRCT2_ASSETS_DIR/object
unzip -o ${finalAttrs.passthru.assets.openmusic} -d $OPENRCT2_ASSETS_DIR
unzip -o ${finalAttrs.passthru.assets.opensfx} -d $OPENRCT2_ASSETS_DIR
unzip -o ${finalAttrs.passthru.assets.title-sequences} -d $OPENRCT2_ASSETS_DIR/sequence
''
+ lib.optionalString stdenv.hostPlatform.isDarwin ''
printf '%s' "${finalAttrs.passthru.assets.objects.url}" > $sourceRoot/build/object/objects.zip.zipversion
printf '%s' "${finalAttrs.passthru.assets.title-sequences.url}" > $sourceRoot/build/sequence/title-sequences.zip.zipversion
printf '%s' "${finalAttrs.passthru.assets.opensfx.url}" > $sourceRoot/build/opensound.zip.zipversion
printf '%s' "${finalAttrs.passthru.assets.openmusic.url}" > $sourceRoot/build/openmusic.zip.zipversion
'';
postPatch = lib.optionalString stdenv.hostPlatform.isDarwin ''
# MACOS_BUNDLE (to build a .APP) is tied to MACOS_USE_DEPENDENCIES by default.
# Decouple the two variables so that we can use resources downloaded from Nix.
sed -i \
-e 's/^CMAKE_DEPENDENT_OPTION(MACOS_BUNDLE.*/option(MACOS_BUNDLE "Build macOS application bundle (OpenRCT2.app)" ON)/' \
-e '/"MACOS_USE_DEPENDENCIES; NOT DISABLE_GUI" OFF)/d' \
CMakeLists.txt
sed -i '/^if (MACOS_USE_DEPENDENCIES)$/i include(cmake/download.cmake)' CMakeLists.txt
# Clang 21 on Nixpkgs will provide a broken Foundation module, as of now.
# The Apple Obj-C modules requested are not explicitly required, so drop them.
substituteInPlace src/{openrct2,openrct2-ui}/CmakeLists.txt \
--replace-fail '-x objective-c++ -fmodules' \
'-x objective-c++'
# `fixup_bundle` will inherit mismatched dependencies relative to compilation.
# Hence, disable `fixup_bundle` for Darwin builds.
substituteInPlace src/openrct2-ui/CMakeLists.txt \
--replace-fail 'fixup_bundle(''${CMAKE_BINARY_DIR}/''${MACOS_APP_NAME} \"\" \"\")' \
'# fixup_bundle disabled for Nix builds'
# sdl2-compat is the default for SDL2 in Nixpkgs, which has issues on Darwin.
# Set OpenGL as the default renderer in Darwin to bypass them.
substituteInPlace src/openrct2/config/Config.cpp \
--replace-fail 'DrawingEngine::SoftwareWithHardwareDisplay, Enum_DrawingEngine)' \
'DrawingEngine::OpenGL, Enum_DrawingEngine)'
# Wrapping with --rct*-data-path will not work on Darwin for OpenRCT2.app.
# This simply sets that data path as the default in source, if defined.
${lib.optionalString (rct1Path != null) ''
substituteInPlace src/openrct2/config/Config.cpp \
--replace-fail 'GetString("rct1_path", "")' 'GetString("rct1_path", "${rct1Path}")'
''}
${lib.optionalString (rct2Path != null) ''
substituteInPlace src/openrct2/config/Config.cpp \
--replace-fail 'GetString("rct2_path", "")' 'GetString("rct2_path", "${rct2Path}")'
''}
'';
preConfigure =
@@ -147,11 +199,21 @@ stdenv.mkDerivation (finalAttrs: {
doInstallCheck = true;
postInstall = ''
wrapProgram $out/bin/openrct2 \
${lib.optionalString (rct1Path != null) "--add-flags '--rct1-data-path=\"${rct1Path}\"'"} \
${lib.optionalString (rct2Path != null) "--add-flags '--rct2-data-path=\"${rct2Path}\"'"}
'';
postInstall =
if stdenv.hostPlatform.isDarwin then
''
mkdir -p $out/{Applications,bin,share}
cp -R OpenRCT2.app $out/Applications/
makeBinaryWrapper $out/Applications/OpenRCT2.app/Contents/MacOS/openrct2 $out/bin/openrct2
cp openrct2-cli $out/bin/openrct2-cli
ln -s $out/Applications/OpenRCT2.app/Contents/Resources $out/share/openrct2
''
else
''
wrapProgram $out/bin/openrct2 \
${lib.optionalString (rct1Path != null) "--add-flags '--rct1-data-path=\"${rct1Path}\"'"} \
${lib.optionalString (rct2Path != null) "--add-flags '--rct2-data-path=\"${rct2Path}\"'"}
'';
meta = {
description = "Open source re-implementation of RollerCoaster Tycoon 2";
@@ -181,9 +243,10 @@ stdenv.mkDerivation (finalAttrs: {
maintainers = with lib.maintainers; [
keenanweaver
kylerisse
schrobingus
];
mainProgram = "openrct2";
platforms = lib.platforms.linux;
platforms = lib.platforms.linux ++ lib.platforms.darwin;
sourceProvenance = with lib.sourceTypes; [ fromSource ];
};
})

View File

@@ -46,13 +46,13 @@ let
in
buildDotnetModule (finalAttrs: {
pname = "pixieditor";
version = "2.1.1.5";
version = "2.1.2.2";
src = fetchFromGitHub {
owner = "PixiEditor";
repo = "PixiEditor";
tag = finalAttrs.version;
hash = "sha256-XtDcAnMgNc4Su2hj5OV2SP+LFIAMSfH8h2LLw+VbHok=";
hash = "sha256-k2dwz1VcXGs0Sh/6nc8Q3bs/dpsHiTnqRbXaGJojBz4=";
fetchSubmodules = true;
};
@@ -184,5 +184,7 @@ buildDotnetModule (finalAttrs: {
"aarch64-linux"
"aarch64-darwin"
];
# Temporary disable until the missing DeviceId.Mac missing dependecy get's solved
badPlatforms = [ "aarch64-darwin" ];
};
})

View File

@@ -16,13 +16,13 @@
stdenv.mkDerivation (finalAttrs: {
pname = "podofo";
version = "1.1.1";
version = "1.1.2";
src = fetchFromGitHub {
owner = "podofo";
repo = "podofo";
rev = finalAttrs.version;
hash = "sha256-y+3nOynd0xJRF14XA1oK2smL6irCfaFrJ8rvxJS6b8M=";
hash = "sha256-DnFmqbGpeACwpib+my1Np4USBA6SBmG6QWmscOSqN5k=";
};
outputs = [

View File

@@ -0,0 +1,213 @@
diff --git a/src/controllers/UIController.py b/src/controllers/UIController.py
index ea30505..d4cf90c 100644
--- a/src/controllers/UIController.py
+++ b/src/controllers/UIController.py
@@ -39,7 +39,7 @@ class UIController:
# Override in the pane class
compat_hw = ['RM100', 'RM102', 'RM110', 'RM02A', 'RM03A', 'RM12A']
xochitl_versions = [
- '^[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+$',
+ r'^[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+$',
'^Parabola.*']
# Set to True to keep enabled for backups
diff --git a/src/model/document.py b/src/model/document.py
index 57ea53a..979c72a 100644
--- a/src/model/document.py
+++ b/src/model/document.py
@@ -823,7 +823,7 @@ class Document(GenericNotebookType):
iface = 'usb0'
# Is the interface active?
- cmd = "/sbin/ifconfig {} | grep -q '10\.11\.99\.1'; echo $?".format(iface)
+ cmd = r"/sbin/ifconfig {} | grep -q '10\.11\.99\.1'; echo $?".format(iface)
out, err = self.model.run_cmd(cmd)
iface_active = False
if '0' == out.strip():
diff --git a/src/model/generic_notebook_type.py b/src/model/generic_notebook_type.py
index 0c78adf..f4d9d2e 100644
--- a/src/model/generic_notebook_type.py
+++ b/src/model/generic_notebook_type.py
@@ -36,7 +36,7 @@ class GenericNotebookType:
@classmethod
def get_sanitized_name(cls, name):
- sanitized = re.sub('[\/\\\!\@\#\$\%\^\&\*\~\|\:\;\?\`\’\“\'\"]',
+ sanitized = re.sub(r'[\/\\\!\@\#\$\%\^\&\*\~\|\:\;\?\`\’\“\'\"]',
'_',
name)
return sanitized
diff --git a/src/model/rcu.py b/src/model/rcu.py
index aa3034f..fc5d479 100644
--- a/src/model/rcu.py
+++ b/src/model/rcu.py
@@ -309,7 +309,7 @@ class RCU:
'FreeBSD': 'cd "{}" && ./imx_usb.fbsd12'.format(recoverydir),
'Linux': 'cd "{}" && ./imx_usb.linux'.format(recoverydir),
'Darwin': 'cd "{}" && ./imx_usb.mac'.format(recoverydir),
- 'Windows': 'cd /d "{}" && .\imx_usb.win10'.format(recoverydir)
+ 'Windows': r'cd /d "{}" && .\imx_usb.win10'.format(recoverydir)
}
plat = platform.system()
@@ -774,7 +774,7 @@ class RCU:
# Find safe templates, disable the rest. Safe ones (as is
# currently supported) must exist as either .svg or .png.
searchpath = Template.syspathpfx
- cmd = 'cd "{}" && ls *.svg *.png | sed "s/\.svg//g" | sed "s/\.png//g"'.format(searchpath)
+ cmd = r'cd "{}" && ls *.svg *.png | sed "s/\.svg//g" | sed "s/\.png//g"'.format(searchpath)
out, err = self.run_cmd(cmd)
passing_templates = set(out.strip().splitlines())
diff --git a/src/model/text_handler.py b/src/model/text_handler.py
index 75833a8..a6b5b51 100644
--- a/src/model/text_handler.py
+++ b/src/model/text_handler.py
@@ -132,26 +132,26 @@ class BlockManager:
('^# ', ParagraphStyle.HEADING),
('^## ', ParagraphStyle.HEADING2),
# Asterisk bullets
- ('^\* ', ParagraphStyle.BULLET),
- ('^ \* ', ParagraphStyle.BULLET2),
- ('^\* \[ \] ', ParagraphStyle.CHECKBOX),
- ('^\* \[X\] ', ParagraphStyle.CHECKBOX_CHECKED),
- ('^\* \[x\] ', ParagraphStyle.CHECKBOX_CHECKED),
- ('^ \* \[ \] ', ParagraphStyle.CHECKBOX2),
- ('^ \* \[X\] ', ParagraphStyle.CHECKBOX2_CHECKED),
- ('^ \* \[x\] ', ParagraphStyle.CHECKBOX2_CHECKED),
+ (r'^\* ', ParagraphStyle.BULLET),
+ (r'^ \* ', ParagraphStyle.BULLET2),
+ (r'^\* \[ \] ', ParagraphStyle.CHECKBOX),
+ (r'^\* \[X\] ', ParagraphStyle.CHECKBOX_CHECKED),
+ (r'^\* \[x\] ', ParagraphStyle.CHECKBOX_CHECKED),
+ (r'^ \* \[ \] ', ParagraphStyle.CHECKBOX2),
+ (r'^ \* \[X\] ', ParagraphStyle.CHECKBOX2_CHECKED),
+ (r'^ \* \[x\] ', ParagraphStyle.CHECKBOX2_CHECKED),
# Hyphen bullets
- ('^\- ', ParagraphStyle.BULLET),
- ('^ \- ', ParagraphStyle.BULLET2),
- ('^\- \[ \] ', ParagraphStyle.CHECKBOX),
- ('^\- \[X\] ', ParagraphStyle.CHECKBOX_CHECKED),
- ('^\- \[x\] ', ParagraphStyle.CHECKBOX_CHECKED),
- ('^ \- \[ \] ', ParagraphStyle.CHECKBOX2),
- ('^ \- \[X\] ', ParagraphStyle.CHECKBOX2_CHECKED),
- ('^ \- \[x\] ', ParagraphStyle.CHECKBOX2_CHECKED),
+ (r'^\- ', ParagraphStyle.BULLET),
+ (r'^ \- ', ParagraphStyle.BULLET2),
+ (r'^\- \[ \] ', ParagraphStyle.CHECKBOX),
+ (r'^\- \[X\] ', ParagraphStyle.CHECKBOX_CHECKED),
+ (r'^\- \[x\] ', ParagraphStyle.CHECKBOX_CHECKED),
+ (r'^ \- \[ \] ', ParagraphStyle.CHECKBOX2),
+ (r'^ \- \[X\] ', ParagraphStyle.CHECKBOX2_CHECKED),
+ (r'^ \- \[x\] ', ParagraphStyle.CHECKBOX2_CHECKED),
# Numbers
- ('^[0-9]+\. ', ParagraphStyle.NUMBER),
- ('^ [0-9]+\. ', ParagraphStyle.NUMBER2)
+ (r'^[0-9]+\. ', ParagraphStyle.NUMBER),
+ (r'^ [0-9]+\. ', ParagraphStyle.NUMBER2)
]
for t in style_table:
pat = re.compile(t[0])
@@ -168,7 +168,7 @@ class BlockManager:
# Currently, these are 1:1 with Markdown format tags, but
# that might not always be the case! (2026-01)
# ***value***, **value**, or *value*
- pattern = '(\*\*\*.*?\*\*\*|\*\*.*?\*\*|\*.*?\*)'
+ pattern = r'(\*\*\*.*?\*\*\*|\*\*.*?\*\*|\*.*?\*)'
ret = re.split(pattern, line)
# no empty ones
for ri in ret:
diff --git a/src/panes/notebooks/pane.py b/src/panes/notebooks/pane.py
index 50d8eaa..6fb137f 100644
--- a/src/panes/notebooks/pane.py
+++ b/src/panes/notebooks/pane.py
@@ -82,11 +82,11 @@ class NotebooksPane(UIController):
ui_filename = Path(adir / bdir / 'notebooks.ui')
xochitl_versions = [
- '^[1-2]\.[0-9]+\.[0-9]+\.[0-9]+$',
- '^3\.[0-4]\.[0-9]+\.[0-9]+$',
- '^3\.[0-9]\.[0-9]\.[0-9]+$',
- '^3\.1[0-9]\.[0-9]\.[0-9]+$',
- '^3\.2[0-7]\.[0-9]\.[0-9]+$'
+ r'^[1-2]\.[0-9]+\.[0-9]+\.[0-9]+$',
+ r'^3\.[0-4]\.[0-9]+\.[0-9]+$',
+ r'^3\.[0-9]\.[0-9]\.[0-9]+$',
+ r'^3\.1[0-9]\.[0-9]\.[0-9]+$',
+ r'^3\.2[0-7]\.[0-9]\.[0-9]+$'
]
cli_args = [('--list-documents', True, None, 'list documents by ID, Name, and Timestamp'),
diff --git a/src/panes/splash/pane.py b/src/panes/splash/pane.py
index b0fcc7f..f9e36f5 100644
--- a/src/panes/splash/pane.py
+++ b/src/panes/splash/pane.py
@@ -82,11 +82,11 @@ class SplashPane(UIController):
}
xochitl_versions = [
- '^[1-2]\.[0-9]+\.[0-9]+\.[0-9]+$',
- '^3\.[0-4]\.[0-9]+\.[0-9]+$',
- '^3\.[0-9]\.[0-9]\.[0-9]+$',
- '^3\.1[0-9]\.[0-9]\.[0-9]+$',
- '^3\.2[0-7]\.[0-9]\.[0-9]+$'
+ r'^[1-2]\.[0-9]+\.[0-9]+\.[0-9]+$',
+ r'^3\.[0-4]\.[0-9]+\.[0-9]+$',
+ r'^3\.[0-9]\.[0-9]\.[0-9]+$',
+ r'^3\.1[0-9]\.[0-9]\.[0-9]+$',
+ r'^3\.2[0-7]\.[0-9]\.[0-9]+$'
]
@classmethod
@@ -193,9 +193,9 @@ class SplashPane(UIController):
ver = self.model.device_info['osver']
cmd = 'cd ' + self.device_sys_path + ' && ' \
+ '(for f in *.png.bak; do ' \
- + '(yes n | cp -i \"\$f\" \"' \
- + local_path + '/\${f%.bak}.system_' + ver + '\") && ' \
- + '(yes n | cp -i \"\${f%.bak}\" \"' + local_path +'/\${f%.bak}.user\"); ' \
+ + r'(yes n | cp -i "\$f" "' \
+ + local_path + r'/\${f%.bak}.system_' + ver + '\") && ' \
+ + r'(yes n | cp -i "\${f%.bak}" "' + local_path +r'/\${f%.bak}.user"); ' \
+ 'done)'
out, err = self.model.run_cmd('bash -c "' + cmd + '"')
if len(err):
@@ -477,7 +477,7 @@ class SplashPane(UIController):
carousel_bak_exists = True if '0' == carousel_bak_exists else False
# Load the carousel images into the list
- cmd = '\ls {}/carousel/'.format(self.device_sys_path)
+ cmd = r'\ls {}/carousel/'.format(self.device_sys_path)
out, err = self.model.run_cmd(cmd)
out = out.strip().splitlines()
if len(err):
diff --git a/src/panes/templates/pane.py b/src/panes/templates/pane.py
index 352595a..b0ccc9d 100644
--- a/src/panes/templates/pane.py
+++ b/src/panes/templates/pane.py
@@ -47,11 +47,11 @@ class TemplatesPane(UIController):
ui_filename = Path(adir / bdir / 'templates.ui')
xochitl_versions = [
- '^[1-2]\.[0-9]+\.[0-9]+\.[0-9]+$',
- '^3\.[0-4]\.[0-9]+\.[0-9]+$',
- '^3\.[0-9]\.[0-9]\.[0-9]+$',
- '^3\.1[0-9]\.[0-9]\.[0-9]+$',
- '^3\.2[0-7]\.[0-9]\.[0-9]+$'
+ r'^[1-2]\.[0-9]+\.[0-9]+\.[0-9]+$',
+ r'^3\.[0-4]\.[0-9]+\.[0-9]+$',
+ r'^3\.[0-9]\.[0-9]\.[0-9]+$',
+ r'^3\.1[0-9]\.[0-9]\.[0-9]+$',
+ r'^3\.2[0-7]\.[0-9]\.[0-9]+$'
]
@classmethod
@@ -479,7 +479,7 @@ class TemplatesController:
# This is duplicated from generic_notebook_type.py. Since it's
# only used once, here, for templates -- easier to just copy.
def get_sanitized_name(template):
- return re.sub('[\/\\\!\@\#\$\%\^\&\*\~\|\:\;\?\`\’\“\'\"]',
+ return re.sub(r'[\/\\\!\@\#\$\%\^\&\*\~\|\:\;\?\`\’\“\'\"]',
'_',
template.get_pretty_name_with_orient() + '.rmt')

View File

@@ -0,0 +1,29 @@
diff --git a/src/panes/about/pane.py b/src/panes/about/pane.py
index 5e3a456..df2dfe0 100644
--- a/src/panes/about/pane.py
+++ b/src/panes/about/pane.py
@@ -31,6 +31,7 @@ from PySide6.QtCore import Qt, QByteArray, QUrl, QSize, \
from PySide6.QtGui import QIcon
from PySide6.QtWidgets import QMessageBox
import urllib.request
+import ssl
import hashlib
import certifi # PyInstaller pickup (should be auto-used by urllib)
@@ -159,14 +160,14 @@ class AboutPane(UIController):
log.info('checking for updates')
self.window.checkupdates_pushButton.setEnabled(False)
with urllib.request.urlopen(type(self).update_url,
- cafile=certifi.where()) as response:
+ context=ssl.create_default_context(cafile=certifi.where())) as response:
self.remote_version_body = response.read(100)
def check_for_compat(self, progress_callback=lambda x: ()):
log.info('checking for compat')
self.window.checkcompat_pushButton.setEnabled(False)
with urllib.request.urlopen(type(self).compat_url,
- cafile=certifi.where()) as response:
+ context=ssl.create_default_context(cafile=certifi.where())) as response:
self.remote_compat_body = response.read(10000)
def finished_check_for_updates(self, show_mb=True, \

View File

@@ -1,140 +0,0 @@
diff '--color=auto' -ruN a/src/model/transport.py b/src/model/transport.py
--- a/src/model/transport.py 2025-08-27 17:12:23.761436314 +0200
+++ b/src/model/transport.py 2025-08-27 17:17:35.723006746 +0200
@@ -105,7 +105,6 @@
MSG_NAMES,
)
from paramiko.compress import ZlibCompressor, ZlibDecompressor
-from paramiko.dsskey import DSSKey
from paramiko.ed25519key import Ed25519Key
from paramiko.kex_curve25519 import KexCurve25519
from paramiko.kex_gex import KexGex, KexGexSHA256
@@ -117,7 +116,6 @@
from paramiko.message import Message
from paramiko.packet import Packetizer, NeedRekeyException
from paramiko.primes import ModulusPack
-from paramiko.py3compat import string_types, long, byte_ord, b, input, PY2
from paramiko.rsakey import RSAKey
from paramiko.ecdsakey import ECDSAKey
from paramiko.server import ServerInterface
@@ -128,7 +126,7 @@
ChannelException,
ProxyCommandFailure,
)
-from paramiko.util import retry_on_signal, ClosingContextManager, clamp_value
+from paramiko.util import ClosingContextManager, clamp_value
# for thread cleanup
@@ -192,7 +190,6 @@
"ecdsa-sha2-nistp384",
"ecdsa-sha2-nistp521",
"ssh-rsa",
- "ssh-dss",
)
_preferred_kex = (
"ecdh-sha2-nistp256",
@@ -273,8 +270,6 @@
_key_info = {
"ssh-rsa": RSAKey,
"ssh-rsa-cert-v01@openssh.com": RSAKey,
- "ssh-dss": DSSKey,
- "ssh-dss-cert-v01@openssh.com": DSSKey,
"ecdsa-sha2-nistp256": ECDSAKey,
"ecdsa-sha2-nistp256-cert-v01@openssh.com": ECDSAKey,
"ecdsa-sha2-nistp384": ECDSAKey,
@@ -396,7 +391,7 @@
self.active = False
self.hostname = None
- if isinstance(sock, string_types):
+ if isinstance(sock, str):
# convert "host:port" into (host, port)
hl = sock.split(":", 1)
self.hostname = hl[0]
@@ -419,7 +414,7 @@
sock = socket.socket(af, socket.SOCK_STREAM)
sock.settimeout(1)
try:
- retry_on_signal(lambda: sock.connect((hostname, port)))
+ sock.connect((hostname, port))
except socket.error as e:
reason = str(e)
else:
@@ -542,7 +537,7 @@
"""
Returns a string representation of this object, for debugging.
"""
- id_ = hex(long(id(self)) & xffffffff)
+ id_ = hex(int(id(self)) & xffffffff)
out = "<paramiko.Transport at {}".format(id_)
if not self.active:
out += " (unconnected)"
@@ -749,11 +744,11 @@
as a server, the host key is used to sign certain packets during the
SSH2 negotiation, so that the client can trust that we are who we say
we are. Because this is used for signing, the key must contain private
- key info, not just the public half. Only one key of each type (RSA or
- DSS) is kept.
+ key info, not just the public half. Only one key of each type (i.e.
+ RSA) is kept.
:param .PKey key:
- the host key to add, usually an `.RSAKey` or `.DSSKey`.
+ the host key to add, usually an `.RSAKey`.
"""
self.server_key_dict[key.get_name()] = key
@@ -763,7 +758,7 @@
client, this method will return the negotiated host key. If only one
type of host key was set with `add_server_key`, that's the only key
that will ever be returned. But in cases where you have set more than
- one type of host key (for example, an RSA key and a DSS key), the key
+ one type of host key (for example, an RSA key and another key), the key
type will be negotiated by the client, and this method will return the
key of the type agreed on. If the host key has not been negotiated
yet, ``None`` is returned. In client mode, the behavior is undefined.
@@ -1123,7 +1118,7 @@
m = Message()
m.add_byte(cMSG_IGNORE)
if byte_count is None:
- byte_count = (byte_ord(os.urandom(1)) % 32) + 10
+ byte_count = (os.urandom(1) % 32) + 10
m.add_bytes(os.urandom(byte_count))
self._send_user_message(m)
@@ -1802,7 +1797,7 @@
def stop_thread(self):
self.active = False
self.packetizer.close()
- if PY2:
+ if False:
# Original join logic; #520 doesn't appear commonly present under
# Python 2.
while self.is_alive() and self is not threading.current_thread():
@@ -1909,7 +1904,7 @@
m = Message()
m.add_mpint(self.K)
m.add_bytes(self.H)
- m.add_byte(b(id))
+ m.add_byte(id.encode("utf8"))
m.add_bytes(self.session_id)
# Fallback to SHA1 for kex engines that fail to specify a hex
# algorithm, or for e.g. transport tests that don't run kexinit.
@@ -2037,14 +2032,14 @@
# active=True occurs before the thread is launched, to avoid a race
_active_threads.append(self)
- tid = hex(long(id(self)) & xffffffff)
+ tid = hex(int(id(self)) & xffffffff)
if self.server_mode:
self._log(DEBUG, "starting thread (server mode): {}".format(tid))
else:
self._log(DEBUG, "starting thread (client mode): {}".format(tid))
try:
try:
- self.packetizer.write_all(b(self.local_version + "\r\n"))
+ self.packetizer.write_all((self.local_version + "\r\n").encode("utf8"))
self._log(
DEBUG,
"Local version/idstring: {}".format(self.local_version),

View File

@@ -0,0 +1,408 @@
diff --git a/src/model/transport.py b/src/model/transport.py
index 0c2ee16..91f7c8f 100644
--- a/src/model/transport.py
+++ b/src/model/transport.py
@@ -55,7 +55,6 @@ from cryptography.hazmat.primitives.ciphers import algorithms, Cipher, modes
import paramiko
from paramiko import util
from paramiko.auth_handler import AuthHandler
-from paramiko.ssh_gss import GSSAuth
from paramiko.channel import Channel
from paramiko.common import (
xffffffff,
@@ -105,19 +104,15 @@ from paramiko.common import (
MSG_NAMES,
)
from paramiko.compress import ZlibCompressor, ZlibDecompressor
-from paramiko.dsskey import DSSKey
from paramiko.ed25519key import Ed25519Key
from paramiko.kex_curve25519 import KexCurve25519
-from paramiko.kex_gex import KexGex, KexGexSHA256
-from paramiko.kex_group1 import KexGroup1
-from paramiko.kex_group14 import KexGroup14, KexGroup14SHA256
+from paramiko.kex_gex import KexGexSHA256
+from paramiko.kex_group14 import KexGroup14SHA256
from paramiko.kex_group16 import KexGroup16SHA512
from paramiko.kex_ecdh_nist import KexNistp256, KexNistp384, KexNistp521
-from paramiko.kex_gss import KexGSSGex, KexGSSGroup1, KexGSSGroup14
from paramiko.message import Message
from paramiko.packet import Packetizer, NeedRekeyException
from paramiko.primes import ModulusPack
-from paramiko.py3compat import string_types, long, byte_ord, b, input, PY2
from paramiko.rsakey import RSAKey
from paramiko.ecdsakey import ECDSAKey
from paramiko.server import ServerInterface
@@ -128,7 +123,7 @@ from paramiko.ssh_exception import (
ChannelException,
ProxyCommandFailure,
)
-from paramiko.util import retry_on_signal, ClosingContextManager, clamp_value
+from paramiko.util import ClosingContextManager, clamp_value
# for thread cleanup
@@ -192,7 +187,6 @@ class Transport(threading.Thread, ClosingContextManager):
"ecdsa-sha2-nistp384",
"ecdsa-sha2-nistp521",
"ssh-rsa",
- "ssh-dss",
)
_preferred_kex = (
"ecdh-sha2-nistp256",
@@ -201,17 +195,9 @@ class Transport(threading.Thread, ClosingContextManager):
"diffie-hellman-group16-sha512",
"diffie-hellman-group-exchange-sha256",
"diffie-hellman-group14-sha256",
- "diffie-hellman-group-exchange-sha1",
- "diffie-hellman-group14-sha1",
- "diffie-hellman-group1-sha1",
)
if KexCurve25519.is_available():
_preferred_kex = ("curve25519-sha256@libssh.org",) + _preferred_kex
- _preferred_gsskex = (
- "gss-gex-sha1-toWM5Slw5Ew8Mqkay+al2g==",
- "gss-group14-sha1-toWM5Slw5Ew8Mqkay+al2g==",
- "gss-group1-sha1-toWM5Slw5Ew8Mqkay+al2g==",
- )
_preferred_compression = ("none",)
_cipher_info = {
@@ -273,8 +259,6 @@ class Transport(threading.Thread, ClosingContextManager):
_key_info = {
"ssh-rsa": RSAKey,
"ssh-rsa-cert-v01@openssh.com": RSAKey,
- "ssh-dss": DSSKey,
- "ssh-dss-cert-v01@openssh.com": DSSKey,
"ecdsa-sha2-nistp256": ECDSAKey,
"ecdsa-sha2-nistp256-cert-v01@openssh.com": ECDSAKey,
"ecdsa-sha2-nistp384": ECDSAKey,
@@ -286,15 +270,9 @@ class Transport(threading.Thread, ClosingContextManager):
}
_kex_info = {
- "diffie-hellman-group1-sha1": KexGroup1,
- "diffie-hellman-group14-sha1": KexGroup14,
- "diffie-hellman-group-exchange-sha1": KexGex,
"diffie-hellman-group-exchange-sha256": KexGexSHA256,
"diffie-hellman-group14-sha256": KexGroup14SHA256,
"diffie-hellman-group16-sha512": KexGroup16SHA512,
- "gss-group1-sha1-toWM5Slw5Ew8Mqkay+al2g==": KexGSSGroup1,
- "gss-group14-sha1-toWM5Slw5Ew8Mqkay+al2g==": KexGSSGroup14,
- "gss-gex-sha1-toWM5Slw5Ew8Mqkay+al2g==": KexGSSGex,
"ecdh-sha2-nistp256": KexNistp256,
"ecdh-sha2-nistp384": KexNistp384,
"ecdh-sha2-nistp521": KexNistp521,
@@ -319,8 +297,6 @@ class Transport(threading.Thread, ClosingContextManager):
sock,
default_window_size=DEFAULT_WINDOW_SIZE,
default_max_packet_size=DEFAULT_MAX_PACKET_SIZE,
- gss_kex=False,
- gss_deleg_creds=True,
disabled_algorithms=None,
):
"""
@@ -362,12 +338,6 @@ class Transport(threading.Thread, ClosingContextManager):
:param int default_max_packet_size:
sets the default max packet size on the transport. (defaults to
32768)
- :param bool gss_kex:
- Whether to enable GSSAPI key exchange when GSSAPI is in play.
- Default: ``False``.
- :param bool gss_deleg_creds:
- Whether to enable GSSAPI credential delegation when GSSAPI is in
- play. Default: ``True``.
:param dict disabled_algorithms:
If given, must be a dictionary mapping algorithm type to an
iterable of algorithm identifiers, which will be disabled for the
@@ -388,15 +358,13 @@ class Transport(threading.Thread, ClosingContextManager):
.. versionchanged:: 1.15
Added the ``default_window_size`` and ``default_max_packet_size``
arguments.
- .. versionchanged:: 1.15
- Added the ``gss_kex`` and ``gss_deleg_creds`` kwargs.
.. versionchanged:: 2.6
Added the ``disabled_algorithms`` kwarg.
"""
self.active = False
self.hostname = None
- if isinstance(sock, string_types):
+ if isinstance(sock, str):
# convert "host:port" into (host, port)
hl = sock.split(":", 1)
self.hostname = hl[0]
@@ -419,7 +387,7 @@ class Transport(threading.Thread, ClosingContextManager):
sock = socket.socket(af, socket.SOCK_STREAM)
sock.settimeout(1)
try:
- retry_on_signal(lambda: sock.connect((hostname, port)))
+ sock.connect((hostname, port))
except socket.error as e:
reason = str(e)
else:
@@ -448,16 +416,6 @@ class Transport(threading.Thread, ClosingContextManager):
self.host_key_type = None
self.host_key = None
- # GSS-API / SSPI Key Exchange
- self.use_gss_kex = gss_kex
- # This will be set to True if GSS-API Key Exchange was performed
- self.gss_kex_used = False
- self.kexgss_ctxt = None
- self.gss_host = None
- if self.use_gss_kex:
- self.kexgss_ctxt = GSSAuth("gssapi-keyex", gss_deleg_creds)
- self._preferred_kex = self._preferred_gsskex + self._preferred_kex
-
# state used during negotiation
self.kex_engine = None
self.H = None
@@ -542,7 +500,7 @@ class Transport(threading.Thread, ClosingContextManager):
"""
Returns a string representation of this object, for debugging.
"""
- id_ = hex(long(id(self)) & xffffffff)
+ id_ = hex(int(id(self)) & xffffffff)
out = "<paramiko.Transport at {}".format(id_)
if not self.active:
out += " (unconnected)"
@@ -585,40 +543,6 @@ class Transport(threading.Thread, ClosingContextManager):
"""
return SecurityOptions(self)
- def set_gss_host(self, gss_host, trust_dns=True, gssapi_requested=True):
- """
- Normalize/canonicalize ``self.gss_host`` depending on various factors.
-
- :param str gss_host:
- The explicitly requested GSS-oriented hostname to connect to (i.e.
- what the host's name is in the Kerberos database.) Defaults to
- ``self.hostname`` (which will be the 'real' target hostname and/or
- host portion of given socket object.)
- :param bool trust_dns:
- Indicates whether or not DNS is trusted; if true, DNS will be used
- to canonicalize the GSS hostname (which again will either be
- ``gss_host`` or the transport's default hostname.)
- (Defaults to True due to backwards compatibility.)
- :param bool gssapi_requested:
- Whether GSSAPI key exchange or authentication was even requested.
- If not, this is a no-op and nothing happens
- (and ``self.gss_host`` is not set.)
- (Defaults to True due to backwards compatibility.)
- :returns: ``None``.
- """
- # No GSSAPI in play == nothing to do
- if not gssapi_requested:
- return
- # Obtain the correct host first - did user request a GSS-specific name
- # to use that is distinct from the actual SSH target hostname?
- if gss_host is None:
- gss_host = self.hostname
- # Finally, canonicalize via DNS if DNS is trusted.
- if trust_dns and gss_host is not None:
- gss_host = socket.getfqdn(gss_host)
- # And set attribute for reference later.
- self.gss_host = gss_host
-
def start_client(self, event=None, timeout=None):
"""
Negotiate a new SSH2 session as a client. This is the first step after
@@ -749,11 +673,11 @@ class Transport(threading.Thread, ClosingContextManager):
as a server, the host key is used to sign certain packets during the
SSH2 negotiation, so that the client can trust that we are who we say
we are. Because this is used for signing, the key must contain private
- key info, not just the public half. Only one key of each type (RSA or
- DSS) is kept.
+ key info, not just the public half. Only one key of each type (i.e.
+ RSA) is kept.
:param .PKey key:
- the host key to add, usually an `.RSAKey` or `.DSSKey`.
+ the host key to add, usually an `.RSAKey`.
"""
self.server_key_dict[key.get_name()] = key
@@ -763,7 +687,7 @@ class Transport(threading.Thread, ClosingContextManager):
client, this method will return the negotiated host key. If only one
type of host key was set with `add_server_key`, that's the only key
that will ever be returned. But in cases where you have set more than
- one type of host key (for example, an RSA key and a DSS key), the key
+ one type of host key (for example, an RSA key and another key), the key
type will be negotiated by the client, and this method will return the
key of the type agreed on. If the host key has not been negotiated
yet, ``None`` is returned. In client mode, the behavior is undefined.
@@ -1123,7 +1047,7 @@ class Transport(threading.Thread, ClosingContextManager):
m = Message()
m.add_byte(cMSG_IGNORE)
if byte_count is None:
- byte_count = (byte_ord(os.urandom(1)) % 32) + 10
+ byte_count = (os.urandom(1)[0] % 32) + 10
m.add_bytes(os.urandom(byte_count))
self._send_user_message(m)
@@ -1238,11 +1162,6 @@ class Transport(threading.Thread, ClosingContextManager):
username="",
password=None,
pkey=None,
- gss_host=None,
- gss_auth=False,
- gss_kex=False,
- gss_deleg_creds=True,
- gss_trust_dns=True,
):
"""
Negotiate an SSH2 session, and optionally verify the server's host key
@@ -1273,40 +1192,17 @@ class Transport(threading.Thread, ClosingContextManager):
:param .PKey pkey:
a private key to use for authentication, if you want to use private
key authentication; otherwise ``None``.
- :param str gss_host:
- The target's name in the kerberos database. Default: hostname
- :param bool gss_auth:
- ``True`` if you want to use GSS-API authentication.
- :param bool gss_kex:
- Perform GSS-API Key Exchange and user authentication.
- :param bool gss_deleg_creds:
- Whether to delegate GSS-API client credentials.
- :param gss_trust_dns:
- Indicates whether or not the DNS is trusted to securely
- canonicalize the name of the host being connected to (default
- ``True``).
:raises: `.SSHException` -- if the SSH2 negotiation fails, the host key
supplied by the server is incorrect, or authentication fails.
-
- .. versionchanged:: 2.3
- Added the ``gss_trust_dns`` argument.
"""
if hostkey is not None:
self._preferred_keys = [hostkey.get_name()]
- self.set_gss_host(
- gss_host=gss_host,
- trust_dns=gss_trust_dns,
- gssapi_requested=gss_kex or gss_auth,
- )
-
self.start_client()
# check host key if we were given one
- # If GSS-API Key Exchange was performed, we are not required to check
- # the host key.
- if (hostkey is not None) and not gss_kex:
+ if hostkey is not None:
key = self.get_remote_server_key()
if (
key.get_name() != hostkey.get_name()
@@ -1330,18 +1226,8 @@ class Transport(threading.Thread, ClosingContextManager):
DEBUG, "Host key verified ({})".format(hostkey.get_name())
)
- if (pkey is not None) or (password is not None) or gss_auth or gss_kex:
- if gss_auth:
- self._log(
- DEBUG, "Attempting GSS-API auth... (gssapi-with-mic)"
- ) # noqa
- self.auth_gssapi_with_mic(
- username, self.gss_host, gss_deleg_creds
- )
- elif gss_kex:
- self._log(DEBUG, "Attempting GSS-API auth... (gssapi-keyex)")
- self.auth_gssapi_keyex(username)
- elif pkey is not None:
+ if (pkey is not None) or (password is not None):
+ if pkey is not None:
self._log(DEBUG, "Attempting public-key auth...")
self.auth_publickey(username, pkey)
else:
@@ -1668,55 +1554,6 @@ class Transport(threading.Thread, ClosingContextManager):
return self.auth_interactive(username, handler, submethods)
- def auth_gssapi_with_mic(self, username, gss_host, gss_deleg_creds):
- """
- Authenticate to the Server using GSS-API / SSPI.
-
- :param str username: The username to authenticate as
- :param str gss_host: The target host
- :param bool gss_deleg_creds: Delegate credentials or not
- :return: list of auth types permissible for the next stage of
- authentication (normally empty)
- :raises: `.BadAuthenticationType` -- if gssapi-with-mic isn't
- allowed by the server (and no event was passed in)
- :raises:
- `.AuthenticationException` -- if the authentication failed (and no
- event was passed in)
- :raises: `.SSHException` -- if there was a network error
- """
- if (not self.active) or (not self.initial_kex_done):
- # we should never try to authenticate unless we're on a secure link
- raise SSHException("No existing session")
- my_event = threading.Event()
- self.auth_handler = AuthHandler(self)
- self.auth_handler.auth_gssapi_with_mic(
- username, gss_host, gss_deleg_creds, my_event
- )
- return self.auth_handler.wait_for_response(my_event)
-
- def auth_gssapi_keyex(self, username):
- """
- Authenticate to the server with GSS-API/SSPI if GSS-API kex is in use.
-
- :param str username: The username to authenticate as.
- :returns:
- a list of auth types permissible for the next stage of
- authentication (normally empty)
- :raises: `.BadAuthenticationType` --
- if GSS-API Key Exchange was not performed (and no event was passed
- in)
- :raises: `.AuthenticationException` --
- if the authentication failed (and no event was passed in)
- :raises: `.SSHException` -- if there was a network error
- """
- if (not self.active) or (not self.initial_kex_done):
- # we should never try to authenticate unless we're on a secure link
- raise SSHException("No existing session")
- my_event = threading.Event()
- self.auth_handler = AuthHandler(self)
- self.auth_handler.auth_gssapi_keyex(username, my_event)
- return self.auth_handler.wait_for_response(my_event)
-
def set_log_channel(self, name):
"""
Set the channel for this transport's logging. The default is
@@ -1802,7 +1639,7 @@ class Transport(threading.Thread, ClosingContextManager):
def stop_thread(self):
self.active = False
self.packetizer.close()
- if PY2:
+ if False:
# Original join logic; #520 doesn't appear commonly present under
# Python 2.
while self.is_alive() and self is not threading.current_thread():
@@ -1909,7 +1746,7 @@ class Transport(threading.Thread, ClosingContextManager):
m = Message()
m.add_mpint(self.K)
m.add_bytes(self.H)
- m.add_byte(b(id))
+ m.add_byte(id.encode("utf8"))
m.add_bytes(self.session_id)
# Fallback to SHA1 for kex engines that fail to specify a hex
# algorithm, or for e.g. transport tests that don't run kexinit.
@@ -2044,7 +1881,7 @@ class Transport(threading.Thread, ClosingContextManager):
self._log(DEBUG, "starting thread (client mode): {}".format(tid))
try:
try:
- self.packetizer.write_all(b(self.local_version + "\r\n"))
+ self.packetizer.write_all((self.local_version + "\r\n").encode("utf8"))
self._log(
DEBUG,
"Local version/idstring: {}".format(self.local_version),
@@ -2264,7 +2101,6 @@ class Transport(threading.Thread, ClosingContextManager):
self.clear_to_send.clear()
finally:
self.clear_to_send_lock.release()
- self.gss_kex_used = False
self.in_kex = True
if self.server_mode:
mp_required_prefix = "diffie-hellman-group-exchange-sha"

View File

@@ -19,7 +19,7 @@
}:
python3Packages.buildPythonApplication rec {
pname = "rcu";
version = "5.1.0";
version = "5.1.1";
pyproject = false;
@@ -27,7 +27,7 @@ python3Packages.buildPythonApplication rec {
let
src-tarball = requireFile {
name = "rcu-${version}-source.tar.gz";
hash = "sha256-s5cqUu2hJEHpLVUwTbNYLQCNXMjv0vFGzQb041+XEqA=";
hash = "sha256-6O2WULD4QAq20ax67gcr8DoNWehoIoFc1LGXFxROTLA=";
url = "https://www.davisr.me/projects/rcu/";
meta = {
# `requireFile` sets `lib.licenses.unfree` by default
@@ -41,8 +41,19 @@ python3Packages.buildPythonApplication rec {
ln -s ${src-tarball} $out/src
'';
# RCU officially targets older dependency versions. We apply these patches to
# keep the application working securely with the modern nixpkgs environment.
# These compatibility patches have been submitted upstream to the RCU developer via email.
#
# - Port-to-paramiko-5.x.patch: RCU vendors an old `transport.py` from paramiko.
# This patch removes references to GSSAPI and SHA-1 Key Exchanges that were dropped in paramiko 5.0.0.
# - Fix-urllib-cafile.patch: Replaces the `cafile` kwarg in urllib (removed in Python 3.10) with an ssl context to fix the updater.
# - Fix-Python-SyntaxWarnings.patch: Converts regex strings with invalid escapes to raw strings to fix Python 3.12+ warnings.
# Without this patch, these invalid escape sequences will become hard SyntaxErrors in Python 3.16.
patches = [
./Port-to-paramiko-4.x.patch
./Port-to-paramiko-5.x.patch
./Fix-urllib-cafile.patch
./Fix-Python-SyntaxWarnings.patch
];
postPatch = ''

View File

@@ -11,7 +11,7 @@ let
owner = "jhaals";
repo = "yopass";
tag = version;
hash = "sha256-YZeSGcQcAsOmIwhhVpGN7bxlNGsWIJNAwUBxJM/7314=";
hash = "sha256-QGa6T0XNQaYIKyhGSnBNMjEaJk9JgEldxdv974lMtBU=";
};
website = callPackage ./website.nix { inherit src version; };
@@ -23,7 +23,7 @@ buildGoModule (finalAttrs: {
__structuredAttrs = true;
strictDeps = true;
vendorHash = "sha256-mR17QPGZNJ9Vx6y6mExvZDKReVxdUif8aQ6VMfKVgcM=";
vendorHash = "sha256-CFo/rI6M7pbjVK0AtL92UyehNgobfWkw61tDNvqpCLY=";
nativeBuildInputs = [ makeBinaryWrapper ];

View File

@@ -16,7 +16,7 @@ stdenv.mkDerivation (finalAttrs: {
yarnOfflineCache = fetchYarnDeps {
yarnLock = "${finalAttrs.src}/yarn.lock";
hash = "sha256-x3ouozoDreaeeqoh8osXOqEYphy6vTalLMjQt5vowkg=";
hash = "sha256-/SHl/U/iVdzF+PojOFdO3z/yX4uuts438DKQcycn8Ik=";
};
nativeBuildInputs = [

View File

@@ -21,13 +21,13 @@
stdenv.mkDerivation rec {
pname = "pcmanfm-qt";
version = "2.4.0";
version = "2.4.1";
src = fetchFromGitHub {
owner = "lxqt";
repo = "pcmanfm-qt";
rev = version;
hash = "sha256-KgYirooKoiUUkzEFsOScTZt/s1OTBLIjAYlW/Q0RQTk=";
hash = "sha256-c3DLzaTcdfWWnsjrYV552zNAHIfE/oF3mmQ73kjQXA0=";
};
nativeBuildInputs = [

View File

@@ -1,6 +1,7 @@
{
callPackage,
fetchurl,
fetchpatch,
...
}@args:
@@ -17,8 +18,30 @@ callPackage ./generic.nix (
hash = "sha256-kcuPphdxxjwmLvtVMFm3x61nV6+lhXr2Jl5LC9wqFKU=";
};
# Backport of upstream check-in `fd06472ef41e1d73`; see the patch.
patches = [
# Cygwin wants the DLL in `bin` and an import library,
# `libtcl8.6.dll.a`, in `lib`; that is what `tclConfig.sh` describes
# when it says `-L${libdir} -ltcl8.6`. This branch's `unix` build
# system builds no import library at all, so nothing can link against
# Tcl. Upstream fixed that on 9.0 and never backported it.
#
# https://core.tcl-lang.org/tcl/tktview/17960b80db
#
# `decode` renames the path: 9.0 has `unix/configure.ac` where this
# branch still has `unix/configure.in`. The hunks themselves apply as
# they are. `includes` drops the rest of the check-in: the generated
# `unix/configure`, which `autoreconfHook` rebuilds anyway, and a
# `changes.md` entry that has no counterpart here.
(fetchpatch {
url = "https://github.com/tcltk/tcl/commit/1685fee268dcf1334b015840d873366a3cd8d237.patch";
decode = "sed -e 's|configure[.]ac|configure.in|g'";
includes = [
"unix/tcl.m4"
"unix/configure.in"
];
hash = "sha256-SWZuY4NvN9z9ka+TTICbCxPZHzhV/8JYDRPI/Vhc/8o=";
})
# Backport of upstream check-in `fd06472ef41e1d73`; see the patch.
./8.6-windows-disable-tzdata.patch
];
}

View File

@@ -20,220 +20,215 @@
...
}:
let
baseInterp = stdenv.mkDerivation (finalAttrs: {
pname = "tcl";
inherit version src;
stdenv.mkDerivation (finalAttrs: {
pname = "tcl";
inherit version src;
outputs = [
"out"
"man"
];
outputs = [
"out"
"man"
];
setOutputFlags = false;
setOutputFlags = false;
inherit patches;
inherit patches;
postPatch = ''
substituteInPlace library/clock.tcl \
--replace-fail "/usr/share/zoneinfo" "${tzdata}/share/zoneinfo" \
--replace-fail "/usr/share/lib/zoneinfo" "" \
--replace-fail "/usr/lib/zoneinfo" "" \
--replace-fail "/usr/local/etc/zoneinfo" ""
postPatch = ''
substituteInPlace library/clock.tcl \
--replace-fail "/usr/share/zoneinfo" "${tzdata}/share/zoneinfo" \
--replace-fail "/usr/share/lib/zoneinfo" "" \
--replace-fail "/usr/lib/zoneinfo" "" \
--replace-fail "/usr/local/etc/zoneinfo" ""
''
# A shared Cygwin build tries to configure the windows build system
# to separately build these DLLs so it can load them later. That's
# not gonna work for us --- in Nixpkgs this would need to be a
# separate derivation with a separate wrapped C compiler --- so
# let's just drop this for now.
#
# Matching just the recursive `make` and not the whole `( cd ...; ... )`
# around it: 8.6 writes that without inner spaces and 9.0 with, and the
# part we care about is the same either way.
+ lib.optionalString stdenv.hostPlatform.isCygwin ''
substituteInPlace unix/Makefile.in \
--replace-fail "\''${MAKE} winextensions" true
''
+ extraPatch;
# The default hook is the newest autoconf that works for every tree we
# regenerate, 8.6's 2.59-era `configure.in` included.
nativeBuildInputs = [
autoreconfHook
]
++ lib.optionals (lib.versionAtLeast version "9.0") [
# Only used to detect the presence of zlib. Could be replaced with a stub.
zip
]
# In the windows build, `install-msgs` (and `install-tzdata`, but
# we don't do that) are done via TCL not via shell. This is for
# the sake of the "build = host = windows" case; we are merely
# doing build = unix, host = windows, where the old shell way would
# have worked.
++ lib.optionals (stdenv.hostPlatform.isWindows && stdenv.buildPlatform != stdenv.hostPlatform) [
buildPackages.tcl
];
buildInputs = [
bashNonInteractive
]
++ lib.optionals (lib.versionAtLeast version "9.0") [
zlib
];
strictDeps = true;
# Windows has its own build system under `win`, autoconf like the one under
# `unix` but with its own `Makefile.in` and a smaller set of options. Cygwin
# is not Windows for this purpose: it is POSIX enough for the `unix` one.
preAutoreconf = ''
cd ${if stdenv.hostPlatform.isWindows then "win" else "unix"}
'';
# No `--install`: there is no automake here, and letting `autoreconf`
# regenerate `aclocal.m4` would lose the `tcl.m4` the build depends on.
autoreconfFlags = "--force --verbose";
configureFlags = [
"tcl_cv_sys_version=${stdenv.hostPlatform.uname.system}"
# During cross compilation, the tcl build system assumes that libc
# functions are broken if it cannot test if they are broken or not and
# then causes a link error on static platforms due to symbol conflict.
# These functions are *checks notes* strtoul and strstr. These are
# never broken on modern platforms!
"tcl_cv_strtod_unbroken=ok"
"tcl_cv_strtoul_unbroken=ok"
"tcl_cv_strstr_unbroken=ok"
# Note: using $out instead of $man to prevent a runtime dependency on $man.
"--mandir=${placeholder "out"}/share/man"
# Don't install tzdata because NixOS already has a more up-to-date copy.
"--with-tzdata=no"
]
++ lib.optionals (lib.versionOlder version "9.0") [
# Enabled is the default pre-9.0, but we don't want to leave
# anything to chance. 9.0 and later the option is gone and
# threads are always enabled.
"--enable-threads"
]
++ lib.optionals (lib.versionAtLeast version "9.0") [
# By default, tcl libraries get zipped and embedded into libtcl*.so,
# which gets `zipfs mount`ed at runtime. This is fragile (for example
# stripping the .so removes the zip trailer), so we install them as
# traditional files.
# This might make tcl slower to start from slower storage on cold cache,
# however according to my benchmarks on fast storage and warm cache
# tcl built with --disable-zipfs actually starts in half the time.
"--disable-zipfs"
]
++ lib.optionals (!stdenv.hostPlatform.isWindows) [
# Does not exist in the `win` build system.
"--enable-man-symlinks"
]
++ lib.optional stdenv.hostPlatform.is64bit "--enable-64bit";
# https://core.tcl-lang.org/thread/tktview/30e201c7111a438e2fe6aadc9d733b954874cbb9
env = lib.optionalAttrs (lib.versionAtLeast version "9.0") { ZIPFS_BUILD = 0; };
buildFlags = lib.optionals stdenv.hostPlatform.isStatic [
# Don't use the default Make target for static,
# since it builds shared libraries for bundled packages.
"binaries"
"libraries"
"doc"
];
makeFlags = lib.optionals stdenv.hostPlatform.isStatic [
"INSTALL_PACKAGE_TARGETS="
];
enableParallelBuilding = true;
allowedImpureDLLs = lib.optionals stdenv.hostPlatform.isCygwin [ "USER32.dll" ];
postInstall =
let
exeExtension = stdenv.hostPlatform.extensions.executable;
dllExtension = stdenv.hostPlatform.extensions.sharedLibrary;
staticExtension = stdenv.hostPlatform.extensions.staticLibrary;
# The `win` build system drops the dot from the version when naming
# files, so `tclsh86.exe` rather than `tclsh8.6`.
infix =
if stdenv.hostPlatform.isWindows then lib.replaceStrings [ "." ] [ "" ] release else release;
# On PE platforms --- Mingw and Cygwin alike --- the DLL lives in
# `bin` and the thing one links against is the import library in
# `lib`, so that is what the unversioned name should point at.
#
# The import library is always `lib`-prefixed, even where the DLL
# is not: Tcl 9 names its Cygwin DLL the way that platform does,
# `cygtcl9.0.dll`, and 9.0's Cygwin `SHLIB_LD` in `unix/tcl.m4`
# rewrites `cyg%.dll` to `lib%.dll.a` for the import library.
linkExtension =
if stdenv.hostPlatform.isWindows || stdenv.hostPlatform.isCygwin then
"${dllExtension}.a"
else
dllExtension;
in
''
# A shared Cygwin build tries to configure the windows build system
# to separately build these DLLs so it can load them later. That's
# not gonna work for us --- in Nixpkgs this would need to be a
# separate derivation with a separate wrapped C compiler --- so
# let's just drop this for now.
#
# Matching just the recursive `make` and not the whole `( cd ...; ... )`
# around it: 8.6 writes that without inner spaces and 9.0 with, and the
# part we care about is the same either way.
+ lib.optionalString stdenv.hostPlatform.isCygwin ''
substituteInPlace unix/Makefile.in \
--replace-fail "\''${MAKE} winextensions" true
make install-private-headers
ln -s $out/bin/tclsh${infix}${exeExtension} $out/bin/tclsh${exeExtension}
if [[ -e $out/lib/libtcl${infix}${staticExtension} ]]; then
ln -s $out/lib/libtcl${infix}${staticExtension} $out/lib/libtcl${staticExtension}
fi
''
+ extraPatch;
nativeBuildInputs = [
autoreconfHook
]
++ lib.optionals (lib.versionAtLeast version "9.0") [
# Only used to detect the presence of zlib. Could be replaced with a stub.
zip
]
# In the windows build, `install-msgs` (and `install-tzdata`, but
# we don't do that) are done via TCL not via shell. This is for
# the sake of the "build = host = windows" case; we are merely
# doing build = unix, host = windows, where the old shell way would
# have worked.
++ lib.optionals (stdenv.hostPlatform.isWindows && stdenv.buildPlatform != stdenv.hostPlatform) [
buildPackages.tcl
];
buildInputs = [
bashNonInteractive
]
++ lib.optionals (lib.versionAtLeast version "9.0") [
zlib
];
strictDeps = true;
# Windows has its own build system under `win`, autoconf like the one under
# `unix` but with its own `Makefile.in` and a smaller set of options. Cygwin
# is not Windows for this purpose: it is POSIX enough for the `unix` one.
preAutoreconf = ''
cd ${if stdenv.hostPlatform.isWindows then "win" else "unix"}
+ lib.optionalString (!stdenv.hostPlatform.isStatic) ''
ln -s $out/lib/libtcl${infix}${linkExtension} $out/lib/libtcl${linkExtension}
'';
# No `--install`: there is no automake here, and letting `autoreconf`
# regenerate `aclocal.m4` would lose the `tcl.m4` the build depends on.
autoreconfFlags = "--force --verbose";
__structuredAttrs = true;
configureFlags = [
"tcl_cv_sys_version=${stdenv.hostPlatform.uname.system}"
# During cross compilation, the tcl build system assumes that libc
# functions are broken if it cannot test if they are broken or not and
# then causes a link error on static platforms due to symbol conflict.
# These functions are *checks notes* strtoul and strstr. These are
# never broken on modern platforms!
"tcl_cv_strtod_unbroken=ok"
"tcl_cv_strtoul_unbroken=ok"
"tcl_cv_strstr_unbroken=ok"
# Note: using $out instead of $man to prevent a runtime dependency on $man.
"--mandir=${placeholder "out"}/share/man"
# Don't install tzdata because NixOS already has a more up-to-date copy.
"--with-tzdata=no"
]
++ lib.optionals (lib.versionOlder version "9.0") [
# Enabled is the default pre-9.0, but we don't want to leave
# anything to chance. 9.0 and later the option is gone and
# threads are always enabled.
"--enable-threads"
]
++ lib.optionals (lib.versionAtLeast version "9.0") [
# By default, tcl libraries get zipped and embedded into libtcl*.so,
# which gets `zipfs mount`ed at runtime. This is fragile (for example
# stripping the .so removes the zip trailer), so we install them as
# traditional files.
# This might make tcl slower to start from slower storage on cold cache,
# however according to my benchmarks on fast storage and warm cache
# tcl built with --disable-zipfs actually starts in half the time.
"--disable-zipfs"
]
++ lib.optionals (!stdenv.hostPlatform.isWindows) [
# Does not exist in the `win` build system.
"--enable-man-symlinks"
]
++ lib.optional stdenv.hostPlatform.is64bit "--enable-64bit";
# https://core.tcl-lang.org/thread/tktview/30e201c7111a438e2fe6aadc9d733b954874cbb9
env = lib.optionalAttrs (lib.versionAtLeast version "9.0") { ZIPFS_BUILD = 0; };
buildFlags = lib.optionals stdenv.hostPlatform.isStatic [
# Don't use the default Make target for static,
# since it builds shared libraries for bundled packages.
"binaries"
"libraries"
"doc"
];
makeFlags = lib.optionals stdenv.hostPlatform.isStatic [
"INSTALL_PACKAGE_TARGETS="
];
enableParallelBuilding = true;
allowedImpureDLLs = lib.optionals stdenv.hostPlatform.isCygwin [ "USER32.dll" ];
postInstall =
let
exeExtension = stdenv.hostPlatform.extensions.executable;
dllExtension = stdenv.hostPlatform.extensions.sharedLibrary;
staticExtension = stdenv.hostPlatform.extensions.staticLibrary;
# The `win` build system drops the dot from the version when naming
# files, so `tclsh86.exe` rather than `tclsh8.6`.
infix =
if stdenv.hostPlatform.isWindows then lib.replaceStrings [ "." ] [ "" ] release else release;
# On Cygwin, shared libs are in the bin directory. TODO dedup
# with this other packages, consider doing the same or Mingw.
# See #431820.
linkDir = if !stdenv.hostPlatform.isStatic && stdenv.hostPlatform.isCygwin then "bin" else "lib";
linkExtension = if stdenv.hostPlatform.isWindows then "${dllExtension}.a" else dllExtension;
# Tcl 9 names its Cygwin DLL the way that platform does, `cygtcl9.0.dll`;
# 8.6 called it `libtcl8.6.dll`. See the Cygwin `SHLIB_LD` in 9.0's
# `unix/tcl.m4`, which rewrites `cyg%.dll` to `lib%.dll` for the import
# library. Only the DLL is affected, not the static or import library.
dllPrefix =
if stdenv.hostPlatform.isCygwin && lib.versionAtLeast version "9.0" then "cyg" else "lib";
in
''
make install-private-headers
ln -s $out/bin/tclsh${infix}${exeExtension} $out/bin/tclsh${exeExtension}
if [[ -e $out/lib/libtcl${infix}${staticExtension} ]]; then
ln -s $out/lib/libtcl${infix}${staticExtension} $out/lib/libtcl${staticExtension}
fi
''
+ lib.optionalString (!stdenv.hostPlatform.isStatic) ''
ln -s $out/${linkDir}/${dllPrefix}tcl${infix}${linkExtension} $out/lib/libtcl${linkExtension}
'';
__structuredAttrs = true;
meta = {
description = "Tcl scripting language";
homepage = "https://www.tcl.tk/";
license = lib.licenses.tcltk;
platforms = lib.platforms.all;
maintainers = with lib.maintainers; [ agbrooks ];
};
passthru =
let
libPrefix = "tcl${release}";
in
{
inherit release version libPrefix;
isTcl9 = lib.versions.major version == "9";
libdir = "lib/${libPrefix}";
tclPackageHook = callPackage (
{ buildPackages }:
makeSetupHook {
name = "tcl-package-hook";
propagatedBuildInputs = [ buildPackages.makeBinaryWrapper ];
meta = {
inherit (finalAttrs.meta) maintainers platforms;
license = lib.licenses.mit;
};
} ./tcl-package-hook.sh
) { };
tclRequiresCheckHook = callPackage (
{ buildPackages }:
makeSetupHook {
name = "tcl-requires-check-hook";
propagatedBuildInputs = [ buildPackages.makeBinaryWrapper ];
meta = {
inherit (finalAttrs.meta) maintainers platforms;
license = lib.licenses.mit;
};
} ./tcl-requires-check-hook.sh
) { };
# verify that Tcl's clock library can access tzdata
tests.tzdata = runCommand "${finalAttrs.pname}-test-tzdata" { } ''
${baseInterp}/bin/tclsh <(echo "set t [clock scan {2004-10-30 05:00:00} \
-format {%Y-%m-%d %H:%M:%S} \
-timezone :America/New_York]") > $out
'';
};
});
mkTclDerivation = callPackage ./mk-tcl-derivation.nix { tcl = baseInterp; };
in
baseInterp.overrideAttrs (self: {
passthru = self.passthru // {
inherit mkTclDerivation;
meta = {
description = "Tcl scripting language";
homepage = "https://www.tcl.tk/";
license = lib.licenses.tcltk;
platforms = lib.platforms.all;
maintainers = with lib.maintainers; [ agbrooks ];
};
passthru =
let
libPrefix = "tcl${release}";
in
{
inherit release version libPrefix;
isTcl9 = lib.versions.major version == "9";
libdir = "lib/${libPrefix}";
tclPackageHook = callPackage (
{ buildPackages }:
makeSetupHook {
name = "tcl-package-hook";
propagatedBuildInputs = [ buildPackages.makeBinaryWrapper ];
meta = {
inherit (finalAttrs.meta) maintainers platforms;
license = lib.licenses.mit;
};
} ./tcl-package-hook.sh
) { };
tclRequiresCheckHook = callPackage (
{ buildPackages }:
makeSetupHook {
name = "tcl-requires-check-hook";
propagatedBuildInputs = [ buildPackages.makeBinaryWrapper ];
meta = {
inherit (finalAttrs.meta) maintainers platforms;
license = lib.licenses.mit;
};
} ./tcl-requires-check-hook.sh
) { };
# verify that Tcl's clock library can access tzdata
tests.tzdata = runCommand "${finalAttrs.pname}-test-tzdata" { } ''
${finalAttrs.finalPackage}/bin/tclsh <(echo "set t [clock scan {2004-10-30 05:00:00} \
-format {%Y-%m-%d %H:%M:%S} \
-timezone :America/New_York]") > $out
'';
mkTclDerivation = callPackage ./mk-tcl-derivation.nix { tcl = finalAttrs.finalPackage; };
};
})

View File

@@ -4,17 +4,21 @@
fetchFromGitHub,
bash,
cmake,
pkg-config,
cfitsio,
curl,
libusb1,
kmod,
zlib,
boost,
libev,
libnova,
curl,
libtheora,
libxisf,
libjpeg,
gsl,
fftw,
rtl-sdr-librtlsdr,
gtest,
udevCheckHook,
versionCheckHook,
@@ -23,38 +27,42 @@
stdenv.mkDerivation (finalAttrs: {
pname = "indilib";
version = "2.2.0";
version = "2.2.4.2";
src = fetchFromGitHub {
owner = "indilib";
repo = "indi";
rev = "v${finalAttrs.version}";
hash = "sha256-XTb+etafMRTP/Arb087s+kZoqFT50RT1fpVDeHaGdmY=";
hash = "sha256-DISO8UHrH0cjXe+xTAOdFRce61tOk0SS/CAdsen9cXA=";
};
nativeBuildInputs = [
cmake
pkg-config
];
nativeInstallCheckInputs = [
versionCheckHook
udevCheckHook
];
buildInputs = [
curl
cfitsio
libev
libusb1
zlib
boost
libnova
libjpeg
gsl
cfitsio
curl
fftw
gsl
libev
libjpeg
libnova
libtheora
libusb1
libxisf
rtl-sdr-librtlsdr
zlib
];
cmakeFlags = [
"-DFIX_WARNINGS=OFF" # disable Werror, which can break the build on newer compilers
"-DCMAKE_INSTALL_LIBDIR=lib"
"-DUDEVRULES_INSTALL_DIR=lib/udev/rules.d"
]

View File

@@ -41,13 +41,13 @@
}:
let
thirdparty_version = "2.2.0";
thirdparty_version = "2.2.4";
fxload = libusb1.override { withExamples = true; };
src-3rdparty = fetchFromGitHub {
owner = "indilib";
repo = "indi-3rdparty";
rev = "v${thirdparty_version}";
hash = "sha256-JGDaRlKYgHADMC3C2kiRmTqoL0dHuJKXiUVAYknQsGA=";
hash = "sha256-knmu+ARLvbEQqRfwXYogYkfD8j5QCKy4V8YMIeEjMbU=";
};
buildIndi3rdParty =

View File

@@ -10,14 +10,14 @@
buildPythonPackage rec {
pname = "metaflow";
version = "2.19.16";
version = "2.19.22";
pyproject = true;
src = fetchFromGitHub {
owner = "Netflix";
repo = "metaflow";
tag = version;
hash = "sha256-A3r93vmWwpbdVXsaiY4Oo+LRjlkXCT8wpOTlNgQNxL0=";
hash = "sha256-e7mYwMKBc1IUpnlg3B6KDwYwA34mw0m0kTvAA3fJFA0=";
};
build-system = [

View File

@@ -3,47 +3,46 @@
stdenv,
fetchFromSourcehut,
}:
{
# : string
pname,
# : string
version,
# : string
sha256,
# : string
description,
# : list Maintainer
maintainers,
# : license
license ? lib.licenses.isc,
# : string
owner ? "~humm",
# : string
rev ? "v${version}",
}:
let
manDir = "${placeholder "out"}/share/man";
src = fetchFromSourcehut {
inherit owner rev sha256;
repo = pname;
};
in
stdenv.mkDerivation {
inherit pname version src;
makeFlags = [
"MAN_DIR=${manDir}"
lib.extendMkDerivation {
constructDrv = stdenv.mkDerivation;
excludeDrvArgNames = [
"sha256"
"description"
"maintainers"
"license"
"owner"
"rev"
];
dontBuild = true;
meta = {
inherit description license maintainers;
inherit (src.meta) homepage;
platforms = lib.platforms.all;
};
extendDrvArgs =
finalAttrs:
{
sha256,
description,
maintainers,
license ? lib.licenses.isc,
owner ? "~humm",
rev ? "v${finalAttrs.version}",
meta ? { },
...
}:
let
manDir = "${placeholder "out"}/share/man";
src = fetchFromSourcehut {
inherit owner rev sha256;
repo = finalAttrs.pname;
};
in
{
inherit src;
makeFlags = [
"MAN_DIR=${manDir}"
];
dontBuild = true;
meta = {
inherit description license maintainers;
inherit (src.meta) homepage;
platforms = lib.platforms.all;
}
// meta;
};
}

View File

@@ -4,176 +4,162 @@
cleanPackaging,
fetchurl,
nix-update-script,
pkg-config,
}:
{
# : string
pname,
# : string
version,
# : string
sha256 ? lib.fakeSha256,
# : drv | null
manpages ? null,
# : string
description,
# : list Platform
platforms ? lib.platforms.all,
# : list string
outputs ? [
"bin"
"lib"
"dev"
"doc"
"out"
],
# TODO(Profpatsch): automatically infer most of these
# : list string
configureFlags,
# : string
postConfigure ? null,
# mostly for moving and deleting files from the build directory
# : lines
postInstall,
# : list Maintainer
maintainers ? [ ],
# : passthru arguments (e.g. tests)
passthru ? { },
# : attributes to be merged into meta
broken ? false,
}:
let
# File globs that can always be deleted
commonNoiseFiles = [
".gitignore"
"Makefile"
"INSTALL"
"configure"
"patch-for-solaris"
"src/**/*"
"tools/**/*"
"package/**/*"
"config.mak"
lib.extendMkDerivation {
constructDrv = stdenv.mkDerivation;
excludeDrvArgNames = [
"sha256"
"manpages"
];
# File globs that should be moved to $doc
commonMetaFiles = [
"COPYING"
"AUTHORS"
"NEWS"
"CHANGELOG"
"README"
"README.*"
"DCO"
"CONTRIBUTING"
];
in
stdenv.mkDerivation {
inherit pname version;
src = fetchurl {
url = "https://skarnet.org/software/${pname}/${pname}-${version}.tar.gz";
inherit sha256;
};
outputs =
if manpages == null then
outputs
else
assert (
lib.assertMsg (!lib.elem "man" outputs)
"If you pass `manpages` to `skawarePackages.buildPackage`, you cannot have a `man` output already!"
);
# insert as early as possible, but keep the first element
if lib.length outputs > 0 then
[
(lib.head outputs)
"man"
]
++ lib.tail outputs
else
[ "man" ];
dontDisableStatic = true;
enableParallelBuilding = true;
configureFlags =
configureFlags
++ [
"--enable-absolute-paths"
# We assume every nix-based cross target has urandom.
# This might not hold for e.g. BSD.
"--with-sysdep-devurandom=yes"
(if stdenv.hostPlatform.isDarwin then "--disable-shared" else "--enable-shared")
]
# On darwin, the target triplet from -dumpmachine includes version number,
# but skarnet.org software uses the triplet to test binary compatibility.
# Explicitly setting target ensures code can be compiled against a skalibs
# binary built on a different version of darwin.
# http://www.skarnet.org/cgi-bin/archive.cgi?1:mss:623:heiodchokfjdkonfhdph
++ (lib.optional stdenv.hostPlatform.isDarwin "--build=${stdenv.hostPlatform.system}");
inherit postConfigure;
makeFlags = lib.optionals stdenv.cc.isClang [
"AR=${stdenv.cc.targetPrefix}ar"
"RANLIB=${stdenv.cc.targetPrefix}ranlib"
];
# TODO(Profpatsch): ensure that there is always a $doc output!
postInstall = ''
echo "Cleaning & moving common files"
${
cleanPackaging.commonFileActions {
noiseFiles = commonNoiseFiles;
docFiles = commonMetaFiles;
}
} $doc/share/doc/${pname}
${
if manpages == null then
''echo "no manpages for this package"''
else
''
echo "copying manpages"
cp -vr ${manpages} $man
''
}
${postInstall}
'';
postFixup = ''
${cleanPackaging.checkForRemainingFiles}
'';
passthru = {
updateScript = nix-update-script {
extraArgs = [
"--url"
"https://github.com/skarnet/${pname}"
"--override-filename"
"pkgs/development/skaware-packages/${pname}/default.nix"
extendDrvArgs =
finalAttrs:
{
sha256 ? lib.fakeSha256,
manpages ? null,
meta ? { },
outputs ? [
"bin"
"lib"
"dev"
"doc"
"out"
],
nativeBuildInputs ? [ ],
configureFlags,
passthru ? { },
...
}@args:
let
# File globs that can always be deleted
commonNoiseFiles = [
".gitignore"
"Makefile"
"INSTALL"
"configure"
"patch-for-solaris"
"src/**/*"
"tools/**/*"
"package/**/*"
"config.mak"
"*.pc"
];
# File globs that should be moved to $doc
commonMetaFiles = [
"COPYING"
"AUTHORS"
"NEWS"
"CHANGELOG"
"README"
"README.*"
"DCO"
"CONTRIBUTING"
];
libraryOutput = if lib.elem "lib" outputs then "lib" else "out";
in
{
src = fetchurl {
url = "https://skarnet.org/software/${finalAttrs.pname}/${finalAttrs.pname}-${finalAttrs.version}.tar.gz";
inherit sha256;
};
outputs =
if manpages == null then
outputs
else
assert (
lib.assertMsg (!lib.elem "man" outputs)
"If you pass `manpages` to `skawarePackages.buildPackage`, you cannot have a `man` output already!"
);
if lib.length outputs > 0 then
[
(lib.head outputs)
"man"
]
++ lib.tail outputs
else
[ "man" ];
dontDisableStatic = true;
enableParallelBuilding = true;
nativeBuildInputs = [ pkg-config ] ++ nativeBuildInputs;
configureFlags =
configureFlags
++ [
"--enable-absolute-paths"
# We assume every Nix-based cross target has urandom.
# This might not hold for e.g. BSD.
"--with-sysdep-devurandom=yes"
(if stdenv.hostPlatform.isDarwin then "--disable-shared" else "--enable-shared")
# Use pkg-config
"--with-pkgconfig=pkg-config"
"--enable-pkgconfig"
]
# On Darwin, the target triplet from -dumpmachine includes version number,
# but skarnet.org software uses the triplet to test binary compatibility.
# Explicitly setting target ensures code can be compiled against a skalibs
# binary built on a different version of Darwin.
# http://www.skarnet.org/cgi-bin/archive.cgi?1:mss:623:heiodchokfjdkonfhdph
++ (lib.optional stdenv.hostPlatform.isDarwin "--build=${stdenv.hostPlatform.system}");
makeFlags = lib.optionals stdenv.cc.isClang [
"AR=${stdenv.cc.targetPrefix}ar"
"RANLIB=${stdenv.cc.targetPrefix}ranlib"
];
postInstall = ''
echo "Cleaning & moving common files"
${
cleanPackaging.commonFileActions {
noiseFiles = commonNoiseFiles;
docFiles = commonMetaFiles;
}
} $doc/share/doc/${finalAttrs.pname}
${
if manpages == null then
''echo "no manpages for this package"''
else
''
echo "copying manpages"
cp -vr ${manpages} $man
''
}
${args.postInstall or ""}
'';
postFixup = ''
if [ -d "$dev/lib/pkgconfig" ]; then
for pc in "$dev"/lib/pkgconfig/*.pc; do
sed -i "s|^libdir=.*|libdir=${placeholder libraryOutput}/lib|" "$pc"
if ! grep -q '^Libs.private:' "$pc"; then
sed -i "/^Libs:/a Libs.private: -L${placeholder libraryOutput}/lib" "$pc"
fi
done
fi
${cleanPackaging.checkForRemainingFiles}
'';
passthru = {
updateScript = nix-update-script {
extraArgs = [
"--url"
"https://github.com/skarnet/${finalAttrs.pname}"
"--override-filename"
"pkgs/development/skaware-packages/${finalAttrs.pname}/default.nix"
];
};
}
// passthru
// (if manpages == null then { } else { inherit manpages; });
meta = {
homepage = "https://skarnet.org/software/${finalAttrs.pname}/";
platforms = lib.platforms.all;
license = lib.licenses.isc;
maintainers =
with lib.maintainers;
[
pmahoney
Profpatsch
qyliss
]
++ (meta.maintainers or [ ]);
}
// meta;
};
}
// passthru
// (if manpages == null then { } else { inherit manpages; });
meta = {
homepage = "https://skarnet.org/software/${pname}/";
inherit broken description platforms;
license = lib.licenses.isc;
maintainers =
with lib.maintainers;
[
pmahoney
Profpatsch
qyliss
]
++ maintainers;
};
}

View File

@@ -28,7 +28,7 @@ skawarePackages.buildPackage {
maintainers = [ lib.maintainers.sternenseemann ];
};
description = "Small scripting language, to be used in place of a shell in non-interactive scripts";
meta.description = "Small scripting language, to be used in place of a shell in non-interactive scripts";
outputs = [
"bin"
@@ -37,17 +37,17 @@ skawarePackages.buildPackage {
"doc"
"out"
];
buildInputs = [ skalibs ];
# TODO: nsss support
configureFlags = [
"--libdir=\${lib}/lib"
"--dynlibdir=\${lib}/lib"
"--bindir=\${bin}/bin"
"--includedir=\${dev}/include"
"--libdir=${placeholder "lib"}/lib"
"--dynlibdir=${placeholder "out"}/lib"
"--libexecdir=${placeholder "lib"}/libexec"
"--bindir=${placeholder "bin"}/bin"
"--includedir=${placeholder "dev"}/include"
"--pkgconfdir=${placeholder "dev"}/lib/pkgconfig"
"--with-sysdeps=${skalibs.lib}/lib/skalibs/sysdeps"
"--with-include=${skalibs.dev}/include"
"--with-lib=${skalibs.lib}/lib"
"--with-dynlib=${skalibs.lib}/lib"
];
postInstall = ''
@@ -70,11 +70,10 @@ skawarePackages.buildPackage {
-Wall -Wpedantic \
-D "EXECLINEB_PATH()=\"$bin/bin/.execlineb-wrapped\"" \
-D "EXECLINE_BIN_PATH()=\"$bin/bin\"" \
-I "${skalibs.dev}/include" \
-L "${skalibs.lib}/lib" \
$(pkg-config --cflags libskarnet) \
-o "$bin/bin/execlineb" \
${./execlineb-wrapper.c} \
-lskarnet
$(pkg-config --libs libskarnet)
'';
# Write an execline script.

View File

@@ -9,8 +9,8 @@ skawarePackages.buildPackage {
version = "0.1.8.2";
sha256 = "sha256-zhrgFJtqV6NPYIIY/WGBqmqmgTXKwvTZMbW0F7By4kQ=";
description = "mdev-compatible Linux hotplug manager daemon";
platforms = lib.platforms.linux;
meta.description = "mdev-compatible Linux hotplug manager daemon";
meta.platforms = lib.platforms.linux;
outputs = [
"bin"
@@ -19,10 +19,16 @@ skawarePackages.buildPackage {
"doc"
];
buildInputs = [ skalibs ];
configureFlags = [
"--libdir=${placeholder "out"}/lib"
"--dynlibdir=${placeholder "out"}/lib"
"--libexecdir=${placeholder "out"}/libexec"
"--bindir=${placeholder "bin"}/bin"
"--includedir=${placeholder "dev"}/include"
"--pkgconfdir=${placeholder "dev"}/lib/pkgconfig"
"--with-sysdeps=${skalibs.lib}/lib/skalibs/sysdeps"
"--with-include=${skalibs.dev}/include"
"--with-lib=${skalibs.lib}/lib"
];
postInstall = ''

View File

@@ -5,18 +5,18 @@ skawarePackages.buildPackage {
version = "0.2.1.3";
sha256 = "sha256-FNpESoNtJLaihvrIilAr2qKWpNMo8J1Sl1aK07PgJoU=";
description = "Implementation of a subset of the pwd.h, group.h and shadow.h family of functions";
meta.description = "Implementation of a subset of the pwd.h, group.h and shadow.h family of functions";
buildInputs = [ skalibs ];
# TODO: nsss support
configureFlags = [
"--libdir=\${lib}/lib"
"--dynlibdir=\${lib}/lib"
"--bindir=\${bin}/bin"
"--includedir=\${dev}/include"
"--libdir=${placeholder "lib"}/lib"
"--dynlibdir=${placeholder "out"}/lib"
"--libexecdir=${placeholder "lib"}/libexec"
"--bindir=${placeholder "bin"}/bin"
"--includedir=${placeholder "dev"}/include"
"--pkgconfdir=${placeholder "dev"}/lib/pkgconfig"
"--with-sysdeps=${skalibs.lib}/lib/skalibs/sysdeps"
"--with-include=${skalibs.dev}/include"
"--with-lib=${skalibs.lib}/lib"
"--with-dynlib=${skalibs.lib}/lib"
];
postInstall = ''

View File

@@ -5,7 +5,7 @@ skawarePackages.buildPackage {
version = "2.4.1.3";
sha256 = "sha256-+enetGSMVQeoSFVINkvRxW2r2jlLye4tfxy7FqA2zXY=";
description = "Suite of DNS client programs and libraries for Unix systems";
meta.description = "Suite of DNS client programs and libraries for Unix systems";
outputs = [
"bin"
@@ -15,16 +15,16 @@ skawarePackages.buildPackage {
"out"
];
buildInputs = [ skalibs ];
configureFlags = [
"--libdir=\${lib}/lib"
"--libexecdir=\${lib}/libexec"
"--dynlibdir=\${lib}/lib"
"--bindir=\${bin}/bin"
"--includedir=\${dev}/include"
"--libdir=${placeholder "lib"}/lib"
"--dynlibdir=${placeholder "out"}/lib"
"--libexecdir=${placeholder "lib"}/libexec"
"--bindir=${placeholder "bin"}/bin"
"--includedir=${placeholder "dev"}/include"
"--pkgconfdir=${placeholder "dev"}/lib/pkgconfig"
"--with-sysdeps=${skalibs.lib}/lib/skalibs/sysdeps"
"--with-include=${skalibs.dev}/include"
"--with-lib=${skalibs.lib}/lib"
"--with-dynlib=${skalibs.lib}/lib"
];
postInstall = ''

View File

@@ -13,8 +13,8 @@ skawarePackages.buildPackage {
version = "1.2.0.2";
sha256 = "sha256-b60BTaFiwMgZJBl8V9FuGnXBM7NKIOQjQxobdB6Qex0=";
description = "Set of minimalistic tools used to create a s6-based init system, including a /sbin/init binary, on a Linux kernel";
platforms = lib.platforms.linux;
meta.description = "Set of minimalistic tools used to create a s6-based init system, including a /sbin/init binary, on a Linux kernel";
meta.platforms = lib.platforms.linux;
outputs = [
"bin"
@@ -22,20 +22,20 @@ skawarePackages.buildPackage {
"doc"
"out"
];
buildInputs = [
skalibs
execline
s6
];
configureFlags = [
"--bindir=\${bin}/bin"
"--includedir=\${dev}/include"
"--libdir=${placeholder "out"}/lib"
"--dynlibdir=${placeholder "out"}/lib"
"--libexecdir=${placeholder "out"}/libexec"
"--bindir=${placeholder "bin"}/bin"
"--includedir=${placeholder "dev"}/include"
"--pkgconfdir=${placeholder "dev"}/lib/pkgconfig"
"--with-sysdeps=${skalibs.lib}/lib/skalibs/sysdeps"
"--with-include=${skalibs.dev}/include"
"--with-include=${execline.dev}/include"
"--with-include=${s6.dev}/include"
"--with-lib=${skalibs.lib}/lib"
"--with-lib=${s6.out}/lib"
"--with-lib=${execline.lib}/lib"
"--with-dynlib=${skalibs.lib}/lib"
"--with-dynlib=${execline.lib}/lib"
"--with-dynlib=${s6.out}/lib"
];
# See ../s6-rc/default.nix for an explanation

View File

@@ -10,8 +10,8 @@ skawarePackages.buildPackage {
version = "2.6.4.1";
sha256 = "sha256-FuGltaK0qYZ0tKlxlhKtt5WI48IMQIM2AnjqOPLTISk=";
description = "Set of minimalistic Linux-specific system utilities";
platforms = lib.platforms.linux;
meta.description = "Set of minimalistic Linux-specific system utilities";
meta.platforms = lib.platforms.linux;
outputs = [
"bin"
@@ -20,17 +20,20 @@ skawarePackages.buildPackage {
"out"
];
buildInputs = [
skalibs
execline
];
# TODO: nsss support
configureFlags = [
"--bindir=\${bin}/bin"
"--includedir=\${dev}/include"
"--libdir=${placeholder "out"}/lib"
"--dynlibdir=${placeholder "out"}/lib"
"--libexecdir=${placeholder "out"}/libexec"
"--bindir=${placeholder "bin"}/bin"
"--includedir=${placeholder "dev"}/include"
"--pkgconfdir=${placeholder "dev"}/lib/pkgconfig"
"--with-sysdeps=${skalibs.lib}/lib/skalibs/sysdeps"
"--with-include=${skalibs.dev}/include"
"--with-include=${execline.dev}/include"
"--with-lib=${skalibs.lib}/lib"
"--with-lib=${execline.lib}/lib"
"--with-dynlib=${skalibs.lib}/lib"
"--with-dynlib=${execline.lib}/lib"
];
postInstall = ''

View File

@@ -36,7 +36,7 @@ skawarePackages.buildPackage {
maintainers = [ lib.maintainers.sternenseemann ];
};
description = "Suite of small networking utilities for Unix systems";
meta.description = "Suite of small networking utilities for Unix systems";
outputs = [
"bin"
@@ -45,34 +45,25 @@ skawarePackages.buildPackage {
"doc"
"out"
];
buildInputs = [
skalibs
execline
s6
s6-dns
]
++ lib.optional sslSupportEnabled sslLibs.${sslSupport};
# TODO: nsss support
configureFlags = [
"--libdir=\${lib}/lib"
"--libexecdir=\${lib}/libexec"
"--dynlibdir=\${lib}/lib"
"--bindir=\${bin}/bin"
"--includedir=\${dev}/include"
"--libdir=${placeholder "lib"}/lib"
"--dynlibdir=${placeholder "out"}/lib"
"--libexecdir=${placeholder "lib"}/libexec"
"--bindir=${placeholder "bin"}/bin"
"--includedir=${placeholder "dev"}/include"
"--pkgconfdir=${placeholder "dev"}/lib/pkgconfig"
"--with-sysdeps=${skalibs.lib}/lib/skalibs/sysdeps"
"--with-include=${skalibs.dev}/include"
"--with-include=${execline.dev}/include"
"--with-include=${s6.dev}/include"
"--with-include=${s6-dns.dev}/include"
"--with-lib=${skalibs.lib}/lib"
"--with-lib=${execline.lib}/lib"
"--with-lib=${s6.out}/lib"
"--with-lib=${s6-dns.lib}/lib"
"--with-dynlib=${skalibs.lib}/lib"
"--with-dynlib=${execline.lib}/lib"
"--with-dynlib=${s6.out}/lib"
"--with-dynlib=${s6-dns.lib}/lib"
]
++ (lib.optionals sslSupportEnabled [
"--enable-ssl=${sslSupport}"
"--with-include=${lib.getDev sslLibs.${sslSupport}}/include"
"--with-lib=${lib.getLib sslLibs.${sslSupport}}/lib"
"--with-dynlib=${lib.getLib sslLibs.${sslSupport}}/lib"
]);
++ lib.optional sslSupportEnabled "--enable-ssl=${sslSupport}";
postInstall = ''
# remove all s6 executables from build directory

View File

@@ -17,7 +17,7 @@ skawarePackages.buildPackage {
maintainers = [ lib.maintainers.somasis ];
};
description = "Set of tiny general Unix utilities optimized for simplicity and small size";
meta.description = "Set of tiny general Unix utilities optimized for simplicity and small size";
outputs = [
"bin"
@@ -26,13 +26,16 @@ skawarePackages.buildPackage {
"out"
];
buildInputs = [ skalibs ];
configureFlags = [
"--bindir=\${bin}/bin"
"--includedir=\${dev}/include"
"--libdir=${placeholder "out"}/lib"
"--dynlibdir=${placeholder "out"}/lib"
"--libexecdir=${placeholder "out"}/libexec"
"--bindir=${placeholder "bin"}/bin"
"--includedir=${placeholder "dev"}/include"
"--pkgconfdir=${placeholder "dev"}/lib/pkgconfig"
"--with-sysdeps=${skalibs.lib}/lib/skalibs/sysdeps"
"--with-include=${skalibs.dev}/include"
"--with-lib=${skalibs.lib}/lib"
"--with-dynlib=${skalibs.lib}/lib"
];
postInstall = ''

View File

@@ -21,8 +21,8 @@ skawarePackages.buildPackage {
maintainers = [ lib.maintainers.qyliss ];
};
description = "Service manager for s6-based systems";
platforms = lib.platforms.unix;
meta.description = "Service manager for s6-based systems";
meta.platforms = lib.platforms.unix;
outputs = [
# "bin" "lib"
@@ -30,23 +30,20 @@ skawarePackages.buildPackage {
"dev"
"doc"
];
buildInputs = [
skalibs
execline
s6
];
configureFlags = [
"--libdir=\${out}/lib"
"--libexecdir=\${out}/libexec"
"--dynlibdir=\${out}/lib"
"--bindir=\${out}/bin"
"--includedir=\${dev}/include"
"--libdir=${placeholder "out"}/lib"
"--dynlibdir=${placeholder "out"}/lib"
"--libexecdir=${placeholder "out"}/libexec"
"--bindir=${placeholder "out"}/bin"
"--includedir=${placeholder "dev"}/include"
"--pkgconfdir=${placeholder "dev"}/lib/pkgconfig"
"--with-sysdeps=${skalibs.lib}/lib/skalibs/sysdeps"
"--with-include=${skalibs.dev}/include"
"--with-include=${execline.dev}/include"
"--with-include=${s6.dev}/include"
"--with-lib=${skalibs.lib}/lib"
"--with-lib=${execline.lib}/lib"
"--with-lib=${s6.out}/lib"
"--with-dynlib=${skalibs.lib}/lib"
"--with-dynlib=${execline.lib}/lib"
"--with-dynlib=${s6.out}/lib"
];
# s6-rc-compile generates built-in service definitions containing

View File

@@ -18,7 +18,7 @@ skawarePackages.buildPackage {
maintainers = [ lib.maintainers.sternenseemann ];
};
description = "skarnet.org's small & secure supervision software suite";
meta.description = "skarnet.org's small & secure supervision software suite";
# NOTE lib: cannot split lib from bin at the moment,
# since some parts of lib depend on executables in bin.
@@ -30,20 +30,20 @@ skawarePackages.buildPackage {
"doc"
];
buildInputs = [
skalibs
execline
];
# TODO: nsss support
configureFlags = [
"--libdir=\${out}/lib"
"--libexecdir=\${out}/libexec"
"--dynlibdir=\${out}/lib"
"--bindir=\${out}/bin"
"--includedir=\${dev}/include"
"--libdir=${placeholder "out"}/lib"
"--dynlibdir=${placeholder "out"}/lib"
"--libexecdir=${placeholder "out"}/libexec"
"--bindir=${placeholder "out"}/bin"
"--includedir=${placeholder "dev"}/include"
"--pkgconfdir=${placeholder "dev"}/lib/pkgconfig"
"--with-sysdeps=${skalibs.lib}/lib/skalibs/sysdeps"
"--with-include=${skalibs.dev}/include"
"--with-include=${execline.dev}/include"
"--with-lib=${skalibs.lib}/lib"
"--with-lib=${execline.lib}/lib"
"--with-dynlib=${skalibs.lib}/lib"
"--with-dynlib=${execline.lib}/lib"
];
postInstall = ''

View File

@@ -5,7 +5,7 @@ skawarePackages.buildPackage {
version = "2.10.0.3";
sha256 = "0ka6n5rnxd5sn5lycarf596d5wlak5s535zqqlz0rnhdcnpb105p";
description = "Set of general-purpose C programming libraries";
meta.description = "Set of general-purpose C programming libraries";
outputs = [
"lib"
@@ -15,11 +15,13 @@ skawarePackages.buildPackage {
];
configureFlags = [
"--libdir=${placeholder "lib"}/lib"
"--dynlibdir=${placeholder "out"}/lib"
"--libexecdir=${placeholder "lib"}/libexec"
"--includedir=${placeholder "dev"}/include"
"--pkgconfdir=${placeholder "dev"}/lib/pkgconfig"
# assume /dev/random works
"--enable-force-devr"
"--libdir=\${lib}/lib"
"--dynlibdir=\${lib}/lib"
"--includedir=\${dev}/include"
"--sysdepdir=\${lib}/lib/skalibs/sysdeps"
# Empty the default path, which would be "/usr/bin:bin".
# It would be set when PATH is empty. This hurts hermeticity.

View File

@@ -10,7 +10,7 @@ skawarePackages.buildPackage {
version = "2.15.1.0";
sha256 = "sha256-+ckF50k1xv6RHH40Tj6J1fvSAUwaBGULUksVzptWNdE=";
description = "Set of general-purpose C programming libraries";
meta.description = "Set of general-purpose C programming libraries";
outputs = [
"lib"
@@ -20,11 +20,13 @@ skawarePackages.buildPackage {
];
configureFlags = [
"--libdir=${placeholder "lib"}/lib"
"--dynlibdir=${placeholder "out"}/lib"
"--libexecdir=${placeholder "lib"}/libexec"
"--includedir=${placeholder "dev"}/include"
"--pkgconfdir=${placeholder "dev"}/lib/pkgconfig"
# assume /dev/random works
"--enable-force-devr"
"--libdir=\${lib}/lib"
"--dynlibdir=\${lib}/lib"
"--includedir=\${dev}/include"
"--sysdepdir=\${lib}/lib/skalibs/sysdeps"
# Empty the default path, which would be "/usr/bin:bin".
# It would be set when PATH is empty. This hurts hermeticity.

View File

@@ -9,26 +9,26 @@ skawarePackages.buildPackage {
version = "0.0.8.0";
sha256 = "sha256-GjllM2YqxwvCsKC4xlYW/6f6IBUIhZMA67mtM82mEC0=";
description = "HTTP 1.1 webserver, serving static files and CGI/NPH";
meta.description = "HTTP 1.1 webserver, serving static files and CGI/NPH";
outputs = [
"bin"
"lib"
"out"
"dev"
"doc"
"out"
];
buildInputs = [ skalibs ];
configureFlags = [
"--libdir=\${lib}/lib"
"--libexecdir=\${lib}/libexec"
"--dynlibdir=\${lib}/lib"
"--bindir=\${bin}/bin"
"--includedir=\${dev}/include"
"--libdir=${placeholder "lib"}/lib"
"--dynlibdir=${placeholder "out"}/lib"
"--libexecdir=${placeholder "lib"}/libexec"
"--bindir=${placeholder "bin"}/bin"
"--includedir=${placeholder "dev"}/include"
"--pkgconfdir=${placeholder "dev"}/lib/pkgconfig"
"--with-sysdeps=${skalibs.lib}/lib/skalibs/sysdeps"
"--with-include=${skalibs.dev}/include"
"--with-lib=${skalibs.lib}/lib"
"--with-dynlib=${skalibs.lib}/lib"
# we set sysconfdir to /etc here to allow tipidee-config
# to look in the global paths for its configs.
@@ -45,5 +45,5 @@ skawarePackages.buildPackage {
mv examples $doc/share/doc/tipidee/examples
'';
broken = stdenv.hostPlatform.isDarwin;
meta.broken = stdenv.hostPlatform.isDarwin;
}

View File

@@ -5,17 +5,18 @@ skawarePackages.buildPackage {
version = "0.1.3.4";
sha256 = "sha256-EtzBAq1qyB+BrsxJUHM9uU81CBlHBUubFHPKxckIELw=";
description = "Secure utmpx and wtmp implementation";
meta.description = "Secure utmpx and wtmp implementation";
buildInputs = [ skalibs ];
configureFlags = [
"--libdir=\${lib}/lib"
"--dynlibdir=\${lib}/lib"
"--bindir=\${bin}/bin"
"--includedir=\${dev}/include"
"--libdir=${placeholder "lib"}/lib"
"--dynlibdir=${placeholder "out"}/lib"
"--libexecdir=${placeholder "lib"}/libexec"
"--bindir=${placeholder "bin"}/bin"
"--includedir=${placeholder "dev"}/include"
"--pkgconfdir=${placeholder "dev"}/lib/pkgconfig"
"--with-sysdeps=${skalibs.lib}/lib/skalibs/sysdeps"
"--with-include=${skalibs.dev}/include"
"--with-lib=${skalibs.lib}/lib"
"--with-dynlib=${skalibs.lib}/lib"
];
postInstall = ''

View File

@@ -9,21 +9,15 @@
stdenv.mkDerivation (finalAttrs: {
pname = "amneziawg";
version = "3.1.20260812";
version = "3.1.20260827";
src = fetchFromGitHub {
owner = "amnezia-vpn";
repo = "amneziawg-linux-kernel-module";
tag = "v${finalAttrs.version}";
hash = "sha256-dJ7Au4J8iPlphSzTa3Gol/LMlroroSc2IUmXZfjA0k8=";
hash = "sha256-jRpYf3J6lVWgo+TNOz1Np27RAYc6Ap22Iu9T2NM0lyU=";
};
patches = [
# Compatibility fixes for kernel 7.1.5+, 7.2
# Submitted upstream: https://github.com/amnezia-vpn/amneziawg-linux-kernel-module/pull/194
./sk-715.patch
];
sourceRoot = "${finalAttrs.src.name}/src";
hardeningDisable = [ "pic" ];
nativeBuildInputs = kernel.moduleBuildDependencies;

View File

@@ -1,115 +0,0 @@
diff --git a/compat/compat.h b/compat/compat.h
index 3be1113..f5437cc 100644
--- a/compat/compat.h
+++ b/compat/compat.h
@@ -1444,4 +1444,23 @@ static inline void __compat_chacha20_crypt(struct chacha_state *state,
#endif
+/*
+* API break in 7.2, backported to 7.1.5 but no other stable series
+* https://github.com/torvalds/linux/commit/2cba193628fe523cee6dd61938db2c4563ce15a9
+* https://github.com/torvalds/linux/commit/944bfc1b1c6fe9417668006aae7124886bcca038
+*/
+#if LINUX_VERSION_CODE < KERNEL_VERSION(7, 1, 5)
+#include <net/udp_tunnel.h>
+#define setup_udp_tunnel_sock(net, sk, sock_cfg) setup_udp_tunnel_sock(net, sk->sk_socket, sock_cfg)
+#define udp_tunnel_sock_release(sk) udp_tunnel_sock_release(sk->sk_socket)
+#endif
+
+/*
+* WQ_PERCPU introduced in 6.18, not passing it is deprecated and causes a splat in 7.2
+* https://github.com/torvalds/linux/commit/21c05ca88a548ca1353cbef189c97d4f03b90692
+*/
+#if LINUX_VERSION_CODE < KERNEL_VERSION(6, 18, 0)
+#define WQ_PERCPU 0
+#endif
+
#endif /* _WG_COMPAT_H */
diff --git a/device.c b/device.c
index c8f4312..011e718 100644
--- a/device.c
+++ b/device.c
@@ -379,7 +379,7 @@ static int wg_newlink(struct net_device *dev,
#endif
wg->handshake_receive_wq = alloc_workqueue("wg-kex-%s",
- WQ_CPU_INTENSIVE | WQ_FREEZABLE, 0, dev->name);
+ WQ_CPU_INTENSIVE | WQ_FREEZABLE | WQ_PERCPU, 0, dev->name);
if (!wg->handshake_receive_wq)
goto err_free_tstats;
@@ -389,7 +389,7 @@ static int wg_newlink(struct net_device *dev,
goto err_destroy_handshake_receive;
wg->packet_crypt_wq = alloc_workqueue("wg-crypt-%s",
- WQ_CPU_INTENSIVE | WQ_MEM_RECLAIM, 0, dev->name);
+ WQ_CPU_INTENSIVE | WQ_MEM_RECLAIM | WQ_PERCPU, 0, dev->name);
if (!wg->packet_crypt_wq)
goto err_destroy_handshake_send;
diff --git a/netlink.c b/netlink.c
index b1da877..28f1efa 100644
--- a/netlink.c
+++ b/netlink.c
@@ -172,8 +172,8 @@ static inline int parse_ipv4_prefix(const char *prefix_str, struct ipv4_prefix *
if (slash - prefix_str >= INET_ADDRSTRLEN)
return -EINVAL;
- strncpy(addr_str, prefix_str, slash - prefix_str);
- addr_str[slash - prefix_str] = '\0';
+ // strscpy count includes null terminator
+ strscpy(addr_str, prefix_str, slash - prefix_str + 1);
ret = kstrtoint(slash + 1, 10, &prefix->prefix_len);
if (ret < 0)
@@ -231,8 +231,8 @@ static inline int parse_ipv6_prefix(const char *prefix_str, struct ipv6_prefix *
if (slash - prefix_str >= INET6_ADDRSTRLEN)
return -EINVAL;
- strncpy(addr_str, prefix_str, slash - prefix_str);
- addr_str[slash - prefix_str] = '\0';
+ // strscpy count includes null terminator
+ strscpy(addr_str, prefix_str, slash - prefix_str + 1);
ret = kstrtoint(slash + 1, 10, &prefix->prefix_len);
if (ret < 0)
diff --git a/socket.c b/socket.c
index 24bf1ab..a84bdb2 100644
--- a/socket.c
+++ b/socket.c
@@ -375,7 +375,7 @@ static void sock_free(struct sock *sock)
if (unlikely(!sock))
return;
sk_clear_memalloc(sock);
- udp_tunnel_sock_release(sock->sk_socket);
+ udp_tunnel_sock_release(sock);
}
static void set_sock_opts(struct socket *sock)
@@ -429,14 +429,14 @@ retry:
goto out;
}
set_sock_opts(new4);
- setup_udp_tunnel_sock(net, new4, &cfg);
+ setup_udp_tunnel_sock(net, new4->sk, &cfg);
#if IS_ENABLED(CONFIG_IPV6)
if (ipv6_mod_enabled()) {
port6.local_udp_port = inet_sk(new4->sk)->inet_sport;
ret = udp_sock_create(net, &port6, &new6);
if (ret < 0) {
- udp_tunnel_sock_release(new4);
+ udp_tunnel_sock_release(new4->sk);
if (ret == -EADDRINUSE && !port && retries++ < 100)
goto retry;
pr_err("%s: Could not create IPv6 socket\n",
@@ -444,7 +444,7 @@ retry:
goto out;
}
set_sock_opts(new6);
- setup_udp_tunnel_sock(net, new6, &cfg);
+ setup_udp_tunnel_sock(net, new6->sk, &cfg);
}
#endif